<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>The Foundry Blog | TrustFoundry</title>
    <link>https://trustfoundry.net/blog</link>
    <description>Original security research, vulnerability disclosures, and technical deep-dives from the TrustFoundry penetration testing team.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Apr 2025 12:00:00 GMT</lastBuildDate>
    <atom:link href="https://trustfoundry.net/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Make Deployment Systems Tier 0 Again: Pentesting PDQ Deploy and Inventory</title>
      <link>https://trustfoundry.net/blog/pentesting-pdq-deploy-and-inventory</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/pentesting-pdq-deploy-and-inventory</guid>
      <pubDate>Wed, 30 Apr 2025 12:00:00 GMT</pubDate>
      <dc:creator>Toby Jackson</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>Deep dive into penetration testing PDQ Deploy and Inventory: why deployment systems are critical Tier 0 assets that require dedicated security attention.</description>
    </item>
    <item>
      <title>Fare Play: See the Movie for Free by Kerberoasting Service Tickets Through an AS-REPRoastable User</title>
      <link>https://trustfoundry.net/blog/kerberoasting-as-reproastable-user</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/kerberoasting-as-reproastable-user</guid>
      <pubDate>Fri, 04 Apr 2025 12:00:00 GMT</pubDate>
      <dc:creator>Thomas Fieber</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>Kerberos ticket abuse remains a significant security issue for organizations using Active Directory. Exploring real-world Kerberoasting attack chains through AS-REP roastable accounts.</description>
    </item>
    <item>
      <title>Browser Exploitation Basics: Explaining the addrof and fakeobj Primitives</title>
      <link>https://trustfoundry.net/blog/browser-exploitation-addrof-fakeobj</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/browser-exploitation-addrof-fakeobj</guid>
      <pubDate>Fri, 28 Mar 2025 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>Explaining the fundamental primitives behind JavaScript engine exploitation, addrof and fakeobj, and why they matter for understanding browser security vulnerabilities.</description>
    </item>
    <item>
      <title>Spot the Bug Challenge 2</title>
      <link>https://trustfoundry.net/blog/spot-the-bug-challenge-2</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/spot-the-bug-challenge-2</guid>
      <pubDate>Fri, 21 Mar 2025 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>Test your vulnerability-spotting skills with our second Spot the Bug challenge.</description>
    </item>
    <item>
      <title>Spot the Bug Challenge 1</title>
      <link>https://trustfoundry.net/blog/spot-the-bug-challenge-1</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/spot-the-bug-challenge-1</guid>
      <pubDate>Wed, 12 Mar 2025 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>Can you spot the security vulnerability? Our first interactive Spot the Bug challenge for security professionals.</description>
    </item>
    <item>
      <title>BurpSuite&apos;s New AI Features: Are they as AI-mazing as they sound!?</title>
      <link>https://trustfoundry.net/blog/burpsuite-ai-features</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/burpsuite-ai-features</guid>
      <pubDate>Mon, 03 Mar 2025 12:00:00 GMT</pubDate>
      <dc:creator>Toby Jackson</dc:creator>
      <category>Web &amp; App Security</category>
      <description>An honest look at BurpSuite&apos;s new AI-powered features and whether they live up to the hype for penetration testers.</description>
    </item>
    <item>
      <title>A Mere Mortal&apos;s Introduction to JIT Vulnerabilities in JavaScript Engines</title>
      <link>https://trustfoundry.net/blog/jit-vulnerabilities-javascript-engines</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/jit-vulnerabilities-javascript-engines</guid>
      <pubDate>Tue, 14 Jan 2025 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>An accessible introduction to Just-in-Time compilation vulnerabilities in JavaScript engines and their relevance to browser security.</description>
    </item>
    <item>
      <title>Harnessing Blockchain for Secure and Transparent Elections</title>
      <link>https://trustfoundry.net/blog/harnessing-blockchain-for-secure-and-transparent-elections</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/harnessing-blockchain-for-secure-and-transparent-elections</guid>
      <pubDate>Mon, 06 Jan 2025 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Career &amp; Company</category>
      <description>Exploring how blockchain technology can be applied to create more secure and transparent election systems.</description>
    </item>
    <item>
      <title>Enumerating Access for AWS Temporary Credentials</title>
      <link>https://trustfoundry.net/blog/enumerating-access-for-aws-temporary-credentials</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/enumerating-access-for-aws-temporary-credentials</guid>
      <pubDate>Tue, 17 Dec 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Cloud</category>
      <description>Techniques for enumerating the access and permissions associated with AWS temporary credentials during penetration tests.</description>
    </item>
    <item>
      <title>A Practical Guide to Confidential Computing</title>
      <link>https://trustfoundry.net/blog/practical-guide-confidential-computing</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/practical-guide-confidential-computing</guid>
      <pubDate>Wed, 11 Dec 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Cloud</category>
      <description>A practical overview of confidential computing — what it is, how it works, and why it matters for securing sensitive workloads in the cloud.</description>
    </item>
    <item>
      <title>Prompt Injection: Stopping Attacks at the Source</title>
      <link>https://trustfoundry.net/blog/prompt-injection-stopping-attacks-at-the-source</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/prompt-injection-stopping-attacks-at-the-source</guid>
      <pubDate>Wed, 18 Sep 2024 12:00:00 GMT</pubDate>
      <dc:creator>Ethan Finn</dc:creator>
      <category>Web &amp; App Security</category>
      <description>A deep dive into prompt injection vulnerabilities in AI/LLM applications and strategies for mitigating them at the source.</description>
    </item>
    <item>
      <title>Understanding Active Directory Certificate Services: A Focus on ESC1 and ESC8</title>
      <link>https://trustfoundry.net/blog/understanding-active-directory-certificate-services-esc1-esc8</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/understanding-active-directory-certificate-services-esc1-esc8</guid>
      <pubDate>Mon, 19 Aug 2024 12:00:00 GMT</pubDate>
      <dc:creator>Thomas Fieber</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>A focused look at Active Directory Certificate Services misconfigurations, specifically the ESC1 and ESC8 attack vectors.</description>
    </item>
    <item>
      <title>A Quick Introduction to postMessage XSS</title>
      <link>https://trustfoundry.net/blog/a-quick-introduction-to-postmessage-xss</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/a-quick-introduction-to-postmessage-xss</guid>
      <pubDate>Tue, 30 Jul 2024 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Web &amp; App Security</category>
      <description>An introduction to cross-site scripting vulnerabilities via the postMessage API and how to identify and exploit them.</description>
    </item>
    <item>
      <title>Firefox Sandbox Vulnerability Research: Introduction and Environment Setup</title>
      <link>https://trustfoundry.net/blog/firefox-sandbox-vulnerability-research</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/firefox-sandbox-vulnerability-research</guid>
      <pubDate>Thu, 11 Apr 2024 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>Setting up a research environment for Firefox sandbox vulnerability research, covering the tools and techniques needed to get started.</description>
    </item>
    <item>
      <title>Preparing for a Technical Interview as a Penetration Tester</title>
      <link>https://trustfoundry.net/blog/preparing-for-a-technical-interview-as-a-penetration-tester</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/preparing-for-a-technical-interview-as-a-penetration-tester</guid>
      <pubDate>Thu, 04 Apr 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Career &amp; Company</category>
      <description>Practical advice and tips for preparing for technical interviews in the penetration testing field.</description>
    </item>
    <item>
      <title>A Comprehensive Guide To HTTP Security Headers</title>
      <link>https://trustfoundry.net/blog/comprehensive-guide-to-http-security-headers</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/comprehensive-guide-to-http-security-headers</guid>
      <pubDate>Thu, 21 Mar 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Web &amp; App Security</category>
      <description>A thorough guide to HTTP security headers, what they do, and how to implement them to protect web applications.</description>
    </item>
    <item>
      <title>BurpSuite Certified Practitioner Exam Review</title>
      <link>https://trustfoundry.net/blog/burpsuite-certified-practitioner-exam-review</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/burpsuite-certified-practitioner-exam-review</guid>
      <pubDate>Thu, 14 Mar 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Career &amp; Company</category>
      <description>A review of the BurpSuite Certified Practitioner exam, including preparation tips and what to expect.</description>
    </item>
    <item>
      <title>Securing Session Cookies</title>
      <link>https://trustfoundry.net/blog/securing-session-cookies</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/securing-session-cookies</guid>
      <pubDate>Thu, 07 Mar 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Web &amp; App Security</category>
      <description>Best practices for securing session cookies in web applications, covering flags, attributes, and common pitfalls.</description>
    </item>
    <item>
      <title>Making the most out of your penetration test</title>
      <link>https://trustfoundry.net/blog/making-the-most-out-of-your-penetration-test</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/making-the-most-out-of-your-penetration-test</guid>
      <pubDate>Thu, 29 Feb 2024 12:00:00 GMT</pubDate>
      <dc:creator>Alex Archondakis</dc:creator>
      <category>Career &amp; Company</category>
      <description>How to maximize the value of your penetration test engagement, from scoping to remediation.</description>
    </item>
    <item>
      <title>Writing an exploit for CVE-2021-4034</title>
      <link>https://trustfoundry.net/blog/writing-an-exploit-for-cve-2021-4034</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/writing-an-exploit-for-cve-2021-4034</guid>
      <pubDate>Fri, 04 Mar 2022 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>A walkthrough of writing an exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in Polkit&apos;s pkexec.</description>
    </item>
    <item>
      <title>Did default SameSite:Lax put the nail in the coffin for CSRF? Mostly, but not always!</title>
      <link>https://trustfoundry.net/blog/did-default-samesitelax-put-the-nail-in-the-coffin-for-csrf</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/did-default-samesitelax-put-the-nail-in-the-coffin-for-csrf</guid>
      <pubDate>Wed, 16 Feb 2022 12:00:00 GMT</pubDate>
      <dc:creator>Tyler Rosonke</dc:creator>
      <category>Web &amp; App Security</category>
      <description>Examining whether the default SameSite=Lax cookie attribute has eliminated CSRF vulnerabilities, and the edge cases where it hasn&apos;t.</description>
    </item>
    <item>
      <title>Writing Basic Offensive Tooling in Nim</title>
      <link>https://trustfoundry.net/blog/writing-basic-offensive-tooling-in-nim</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/writing-basic-offensive-tooling-in-nim</guid>
      <pubDate>Mon, 01 Mar 2021 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>An introduction to using the Nim programming language for developing basic offensive security tools.</description>
    </item>
    <item>
      <title>A Brief Introduction to Semgrep (Part 1)</title>
      <link>https://trustfoundry.net/blog/a-brief-introduction-to-semgrep-part-1</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/a-brief-introduction-to-semgrep-part-1</guid>
      <pubDate>Thu, 29 Oct 2020 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>Part 1 of our introduction to Semgrep, covering the basics of this lightweight static analysis tool for security-focused code review.</description>
    </item>
    <item>
      <title>A Brief Introduction to Semgrep (Part 2)</title>
      <link>https://trustfoundry.net/blog/a-brief-introduction-to-semgrep-part-2</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/a-brief-introduction-to-semgrep-part-2</guid>
      <pubDate>Thu, 29 Oct 2020 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>Part 2 of our introduction to Semgrep, a lightweight static analysis tool for finding bugs and enforcing code standards.</description>
    </item>
    <item>
      <title>Preparing for an Application Penetration Test</title>
      <link>https://trustfoundry.net/blog/preparing-for-an-application-penetration-test</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/preparing-for-an-application-penetration-test</guid>
      <pubDate>Wed, 05 Aug 2020 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>A guide for organizations on how to prepare for an application penetration test to ensure the best results.</description>
    </item>
    <item>
      <title>Passwords are dead? Long live WebAuthn!</title>
      <link>https://trustfoundry.net/blog/passwords-are-dead-long-live-webauthn</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/passwords-are-dead-long-live-webauthn</guid>
      <pubDate>Fri, 14 Feb 2020 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Web &amp; App Security</category>
      <description>An exploration of WebAuthn and the FIDO2 standard as a modern replacement for password-based authentication.</description>
    </item>
    <item>
      <title>Introduction to Triaging Fuzzer-Generated Crashes</title>
      <link>https://trustfoundry.net/blog/introduction-to-triaging-fuzzer-generated-crashes</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/introduction-to-triaging-fuzzer-generated-crashes</guid>
      <pubDate>Wed, 22 Jan 2020 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>A practical introduction to triaging crashes generated by fuzzers, covering tools and techniques for root cause analysis.</description>
    </item>
    <item>
      <title>Scanning At Scale: Burp Suite Enterprise Edition</title>
      <link>https://trustfoundry.net/blog/scanning-at-scale-burp-suite-enterprise-edition</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/scanning-at-scale-burp-suite-enterprise-edition</guid>
      <pubDate>Tue, 15 Oct 2019 12:00:00 GMT</pubDate>
      <dc:creator>Bucky Spires</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>A review of Burp Suite Enterprise Edition and its capabilities for scaling web application security scanning.</description>
    </item>
    <item>
      <title>The Top 8 Burp Suite Extensions That I Use to Hack Web Sites</title>
      <link>https://trustfoundry.net/blog/top-8-burp-suite-extensions</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/top-8-burp-suite-extensions</guid>
      <pubDate>Tue, 01 Oct 2019 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>A curated list of the top 8 Burp Suite extensions for web application penetration testing.</description>
    </item>
    <item>
      <title>Using Iodine for DNS Tunneling C2 to Bypass Egress Filtering</title>
      <link>https://trustfoundry.net/blog/using-iodine-for-dns-tunneling-c2</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/using-iodine-for-dns-tunneling-c2</guid>
      <pubDate>Mon, 12 Aug 2019 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>How to use Iodine for DNS tunneling to establish command and control channels that bypass egress filtering.</description>
    </item>
    <item>
      <title>Basic ROP Techniques and Tricks</title>
      <link>https://trustfoundry.net/blog/basic-rop-techniques-and-tricks</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/basic-rop-techniques-and-tricks</guid>
      <pubDate>Thu, 18 Jul 2019 12:00:00 GMT</pubDate>
      <dc:creator>Josiah Pierce</dc:creator>
      <category>Exploit Development</category>
      <description>An introduction to Return-Oriented Programming (ROP) techniques and tricks for binary exploitation.</description>
    </item>
    <item>
      <title>CVE-2019-7629: RCE in an Open Source MUD Client</title>
      <link>https://trustfoundry.net/blog/cve-2019-7629-rce-in-an-open-source-mud-client</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/cve-2019-7629-rce-in-an-open-source-mud-client</guid>
      <pubDate>Mon, 18 Feb 2019 12:00:00 GMT</pubDate>
      <dc:creator>Nick Fox</dc:creator>
      <category>Exploit Development</category>
      <description>Disclosure and analysis of CVE-2019-7629, a remote code execution vulnerability in an open source MUD client.</description>
    </item>
    <item>
      <title>Customer Survey Results</title>
      <link>https://trustfoundry.net/blog/2018-customer-survey-results</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/2018-customer-survey-results</guid>
      <pubDate>Mon, 28 Jan 2019 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>Results from our 2018 customer satisfaction survey and insights into what our clients value most.</description>
    </item>
    <item>
      <title>Bypassing WAFs with JSON Unicode Escape Sequences</title>
      <link>https://trustfoundry.net/blog/bypassing-wafs-with-json-unicode-escape-sequences</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/bypassing-wafs-with-json-unicode-escape-sequences</guid>
      <pubDate>Thu, 20 Dec 2018 12:00:00 GMT</pubDate>
      <dc:creator>Tyler Rosonke</dc:creator>
      <category>Web &amp; App Security</category>
      <description>Techniques for bypassing Web Application Firewalls using JSON Unicode escape sequences to smuggle payloads.</description>
    </item>
    <item>
      <title>JWT Hacking 101</title>
      <link>https://trustfoundry.net/blog/jwt-hacking-101</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/jwt-hacking-101</guid>
      <pubDate>Fri, 08 Dec 2017 12:00:00 GMT</pubDate>
      <dc:creator>Tyler Rosonke</dc:creator>
      <category>Web &amp; App Security</category>
      <description>An introduction to JSON Web Token security, common vulnerabilities, and exploitation techniques.</description>
    </item>
    <item>
      <title>HoneyPi – An easy honeypot for a Raspberry Pi</title>
      <link>https://trustfoundry.net/blog/honeypi-easy-honeypot-raspberry-pi</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/honeypi-easy-honeypot-raspberry-pi</guid>
      <pubDate>Tue, 22 Aug 2017 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>How to set up a simple and effective honeypot using a Raspberry Pi for network intrusion detection.</description>
    </item>
    <item>
      <title>EXE Hijacking in Git Bash for Windows</title>
      <link>https://trustfoundry.net/blog/exe-hijacking-git-bash-windows</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/exe-hijacking-git-bash-windows</guid>
      <pubDate>Sun, 30 Oct 2016 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>Demonstrating EXE hijacking vulnerabilities in Git Bash for Windows and their security implications.</description>
    </item>
    <item>
      <title>What is DLL Hijacking?</title>
      <link>https://trustfoundry.net/blog/what-is-dll-hijacking</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/what-is-dll-hijacking</guid>
      <pubDate>Wed, 19 Oct 2016 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>An explanation of DLL hijacking attacks, how they work, and how to defend against them.</description>
    </item>
    <item>
      <title>Referer Redirection and Its Inconspicuous Danger</title>
      <link>https://trustfoundry.net/blog/referer-redirection-inconspicuous-danger</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/referer-redirection-inconspicuous-danger</guid>
      <pubDate>Tue, 23 Aug 2016 12:00:00 GMT</pubDate>
      <dc:creator>Tyler Rosonke</dc:creator>
      <category>Web &amp; App Security</category>
      <description>An analysis of referer-based open redirection vulnerabilities and why they are more dangerous than they appear.</description>
    </item>
    <item>
      <title>Cross-Site Request Forgery Cheat Sheet</title>
      <link>https://trustfoundry.net/blog/cross-site-request-forgery-cheat-sheet</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/cross-site-request-forgery-cheat-sheet</guid>
      <pubDate>Sun, 03 Apr 2016 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Web &amp; App Security</category>
      <description>A comprehensive cheat sheet for Cross-Site Request Forgery (CSRF) attacks, covering techniques and defenses.</description>
    </item>
    <item>
      <title>Can&apos;t Hack a Hacker: Reverse Engineering a Discovered ATM Skimmer</title>
      <link>https://trustfoundry.net/blog/reverse-engineering-a-discovered-atm-skimmer</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/reverse-engineering-a-discovered-atm-skimmer</guid>
      <pubDate>Thu, 31 Mar 2016 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Tooling &amp; Tradecraft</category>
      <description>Reverse engineering an ATM skimmer discovered in the wild, analyzing its hardware and data exfiltration methods.</description>
    </item>
    <item>
      <title>Shells in Your Serial – Exploiting Java Deserialization on JBoss</title>
      <link>https://trustfoundry.net/blog/exploiting-java-deserialization-on-jboss</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/exploiting-java-deserialization-on-jboss</guid>
      <pubDate>Wed, 18 Nov 2015 12:00:00 GMT</pubDate>
      <dc:creator>Nick Fox</dc:creator>
      <category>Exploit Development</category>
      <description>Exploiting Java deserialization vulnerabilities on JBoss application servers to achieve remote code execution.</description>
    </item>
    <item>
      <title>Practical Guide to exploiting the unquoted service path vulnerability in Windows</title>
      <link>https://trustfoundry.net/blog/unquoted-service-path-vulnerability-windows</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/unquoted-service-path-vulnerability-windows</guid>
      <pubDate>Thu, 10 Sep 2015 12:00:00 GMT</pubDate>
      <dc:creator>Matt South</dc:creator>
      <category>Windows &amp; Active Directory</category>
      <description>A practical walkthrough of exploiting unquoted service path vulnerabilities in Windows for privilege escalation.</description>
    </item>
    <item>
      <title>Browser URL Encoding Decoding and XSS</title>
      <link>https://trustfoundry.net/blog/browser-url-encoding-decoding-and-xss</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/browser-url-encoding-decoding-and-xss</guid>
      <pubDate>Mon, 20 Apr 2015 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Web &amp; App Security</category>
      <description>Understanding browser URL encoding and decoding behavior and its implications for cross-site scripting attacks.</description>
    </item>
    <item>
      <title>Exploiting .NET Padding Oracle Attack MS10-070 (CVE-2010-3332) and Bypassing Microsoft&apos;s Workaround</title>
      <link>https://trustfoundry.net/blog/exploiting-net-padding-oracle-ms10-070</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/exploiting-net-padding-oracle-ms10-070</guid>
      <pubDate>Mon, 20 Apr 2015 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Exploit Development</category>
      <description>Exploiting the .NET padding oracle vulnerability (MS10-070 / CVE-2010-3332) and demonstrating how to bypass Microsoft&apos;s initial workaround.</description>
    </item>
    <item>
      <title>TrustFoundry at TriKC 0x01</title>
      <link>https://trustfoundry.net/blog/trustfoundry-at-trikc-0x01</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/trustfoundry-at-trikc-0x01</guid>
      <pubDate>Sun, 09 Nov 2014 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>TrustFoundry&apos;s participation at the TriKC 0x01 security conference in Kansas City.</description>
    </item>
    <item>
      <title>TrustFoundry at BlackHat USA 2014</title>
      <link>https://trustfoundry.net/blog/trustfoundry-at-blackhat-usa-2014</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/trustfoundry-at-blackhat-usa-2014</guid>
      <pubDate>Sun, 20 Jul 2014 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>TrustFoundry&apos;s experience at BlackHat USA 2014.</description>
    </item>
    <item>
      <title>Building a Presentation Recording Setup</title>
      <link>https://trustfoundry.net/blog/building-a-presentation-recording-setup</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/building-a-presentation-recording-setup</guid>
      <pubDate>Tue, 17 Jun 2014 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>How we built a presentation recording setup for capturing security talks and training content.</description>
    </item>
    <item>
      <title>Is Security Worth it?</title>
      <link>https://trustfoundry.net/blog/is-security-worth-it</link>
      <guid isPermaLink="true">https://trustfoundry.net/blog/is-security-worth-it</guid>
      <pubDate>Mon, 21 Apr 2014 12:00:00 GMT</pubDate>
      <dc:creator>Alex Lauerman</dc:creator>
      <category>Career &amp; Company</category>
      <description>A discussion on the value proposition of investing in cybersecurity and why it matters for businesses of all sizes.</description>
    </item>
  </channel>
</rss>
