👉 Boost your thinking and skills in information security: https://boosty.to/kiberdruzhinnik
Hello! My name is Konstantin Romanov, and I've been in information security for over 9 years. My journey has included reverse engineering, digital forensics, AppSec/DevSecOps, GenAi redteaming, information security business partnerships—and it's still ongoing.
This channel isn't just videos; it's my public logbook. Here I analyze real-life cases, hone my skills, and share knowledge that can be useful to both beginners and current professionals.
Subscribe if you want to grow in information security together—consciously, consistently, and effectively.
Try harder.
Let's look at an average Linux machine and CVE-2024-53677 in Apache Struts, which allows us to upload an arbitrary JSP file to the server and execute arbitrary code. Privilege escalation is achieved via GTFOBins. We'll be following the official walkthrough from TheCyberGeek.
Machine Solution: https://app.hackthebox.com/machines/S...
Text walkthrough: https://blog.kiberdruzhinnik.ru/2025/...
Announcements on the Telegram channel: https://t.me/kiberdruzhinnik
Support with a boost: https://boosty.to/kiberdruzhinnik
My resources:
https://boosty.to/kiberdruzhinnik
/ @kiberdruzhinnik
https://rutube.ru/channel/35510579/
https://blog.kiberdruzhinnik.ru