<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://anirudh958.github.io/</id><title>Anirudh958</title><subtitle>Security posts and write ups.</subtitle> <updated>2026-08-23T23:17:07+05:30</updated> <author> <name>Anirudh_Gupta</name> <uri>https://anirudh958.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://anirudh958.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://anirudh958.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Anirudh_Gupta </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Linux Privilege Escalation: From Dirty COW to RefluXFS — How Low-Privilege Shells Become Root</title><link href="https://anirudh958.github.io/posts/linux-privilege-escalation-deep-dive/" rel="alternate" type="text/html" title="Linux Privilege Escalation: From Dirty COW to RefluXFS — How Low-Privilege Shells Become Root" /><published>2026-08-23T10:00:00+05:30</published> <updated>2026-08-23T23:16:48+05:30</updated> <id>https://anirudh958.github.io/posts/linux-privilege-escalation-deep-dive/</id> <content type="text/html" src="https://anirudh958.github.io/posts/linux-privilege-escalation-deep-dive/" /> <author> <name>Anirudh_Gupta</name> </author> <category term="Cybersecurity" /> <category term="Linux" /> <summary>A hands-on tour of Linux privilege escalation — SUID, capabilities, race conditions, and kernel memory bugs explained through 16 famous LPE CVEs, from Dirty COW and Dirty Pipe to PwnKit, Januscape, and RefluXFS.</summary> </entry> <entry><title>XSS2Shell: How a WordPress Login Page XSS Chains Its Way to Remote Code Execution (CVE-2026-64638)</title><link href="https://anirudh958.github.io/posts/Xss2Shell/" rel="alternate" type="text/html" title="XSS2Shell: How a WordPress Login Page XSS Chains Its Way to Remote Code Execution (CVE-2026-64638)" /><published>2026-08-12T10:00:00+05:30</published> <updated>2026-08-12T10:00:00+05:30</updated> <id>https://anirudh958.github.io/posts/Xss2Shell/</id> <content type="text/html" src="https://anirudh958.github.io/posts/Xss2Shell/" /> <author> <name>Anirudh_Gupta</name> </author> <category term="Cybersecurity" /> <category term="Web Security" /> <summary>XSS2Shell (CVE-2026-64638) explained: how a parser-disagreement XSS on the WordPress login page chains through the REST API and a fake plugin to achieve full Remote Code Execution.</summary> </entry> <entry><title>TryHackMe Beach Bar Walkthrough: Boot2Root via YAML Deserialization</title><link href="https://anirudh958.github.io/posts/beach-bar-tryhackme-walkthrough/" rel="alternate" type="text/html" title="TryHackMe Beach Bar Walkthrough: Boot2Root via YAML Deserialization" /><published>2026-08-01T10:00:00+05:30</published> <updated>2026-08-02T00:33:09+05:30</updated> <id>https://anirudh958.github.io/posts/beach-bar-tryhackme-walkthrough/</id> <content type="text/html" src="https://anirudh958.github.io/posts/beach-bar-tryhackme-walkthrough/" /> <author> <name>Anirudh_Gupta</name> </author> <category term="Walkthrough" /> <category term="Pentesting" /> <summary>TryHackMe Beach Bar walkthrough: DJ credentials in page source, YAML deserialization RCE for the user flag, and the root flag leaked in a process command line.</summary> </entry> <entry><title>JWT Security Deep Dive: How JSON Web Tokens Work, Why They Break, and How Attackers Exploit Them</title><link href="https://anirudh958.github.io/posts/jwt-security-deep-dive/" rel="alternate" type="text/html" title="JWT Security Deep Dive: How JSON Web Tokens Work, Why They Break, and How Attackers Exploit Them" /><published>2026-07-21T10:00:00+05:30</published> <updated>2026-08-23T22:26:47+05:30</updated> <id>https://anirudh958.github.io/posts/jwt-security-deep-dive/</id> <content type="text/html" src="https://anirudh958.github.io/posts/jwt-security-deep-dive/" /> <author> <name>Anirudh_Gupta</name> </author> <category term="Cybersecurity" /> <category term="Web Security" /> <summary>A comprehensive guide to JSON Web Tokens, covering how they work, common vulnerabilities, and how attackers exploit weak implementations.</summary> </entry> <entry><title>The Current State of Agentic Pentesting</title><link href="https://anirudh958.github.io/posts/the-current-state-of-agentic-pentesting/" rel="alternate" type="text/html" title="The Current State of Agentic Pentesting" /><published>2026-05-15T10:00:00+05:30</published> <updated>2026-08-23T22:26:47+05:30</updated> <id>https://anirudh958.github.io/posts/the-current-state-of-agentic-pentesting/</id> <content type="text/html" src="https://anirudh958.github.io/posts/the-current-state-of-agentic-pentesting/" /> <author> <name>Anirudh_Gupta</name> </author> <category term="Cybersecurity" /> <category term="Pentesting" /> <summary>A practical analysis of agentic pentesting capabilities, current tools, operational risks, guardrails, and the continuing need for human oversight.</summary> </entry> </feed>
