<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>EXPLOITS.RUN</title>
  <subtitle>Hacking and OSINT stories and techniques</subtitle>
  <link href="https://exploits.run/feed.xml" rel="self"/>
  <link href="https://exploits.run/"/>
  <id>https://exploits.run/</id>
  <updated>2025-11-06T12:00:00.000Z</updated>
  <entry>
    <title>Dissecting a Crypto Theft Operation: When JavaScript Obfuscation Hides a Fee-Based Scam</title>
    <link href="https://exploits.run/manler-cc-crypto-theft/"/>
    <id>https://exploits.run/manler-cc-crypto-theft/</id>
    <updated>2025-11-06T12:00:00.000Z</updated>
    <published>2025-11-06T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>This post is part technical deep-dive, part forensic investigation story. I&#39;ll walk through how I discovered and analyzed a sophisticated cryptocurrency theft operation that uses advanced JavaScript obfuscation to hide a fee-based scam. The…</summary>
  </entry>
  <entry>
    <title>OSINT Is Not Just Data Gathering</title>
    <link href="https://exploits.run/osint-is-not-just-data/"/>
    <id>https://exploits.run/osint-is-not-just-data/</id>
    <updated>2025-05-11T12:00:00.000Z</updated>
    <published>2025-05-11T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Everyone wants to be an OSINT analyst these days. Scraping Shodan, running a few Google dorks, maybe linking a scammer’s Telegram handle to a throwaway Gmail. That’s open-source intelligence, right? Sort of. But mostly not. The truth is, OS…</summary>
  </entry>
  <entry>
    <title>Getting Started with Windows Subsystem for Linux</title>
    <link href="https://exploits.run/wsl/"/>
    <id>https://exploits.run/wsl/</id>
    <updated>2024-07-11T12:00:00.000Z</updated>
    <published>2024-07-11T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary># WHAT IS WINDOWS SUBSYSTEM FOR LINUX? Most people are either unaware or forget about a wonderful Windows feature called Windows Subsystem for Linux (WSL). WSL gives you access to a full linux kernel right in your Windows installation. This…</summary>
  </entry>
  <entry>
    <title>Search Engine Dorking (Google Case Study)</title>
    <link href="https://exploits.run/google-dorking/"/>
    <id>https://exploits.run/google-dorking/</id>
    <updated>2020-12-01T12:00:00.000Z</updated>
    <published>2020-12-01T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Before we dive in, please understand that this is an introductory level post and for the more technically inclined, there may not be much for consumption here. I will not go in depth on many topics surrounding search engines as a whole and…</summary>
  </entry>
  <entry>
    <title>The Curious Case of Vincent Briatore</title>
    <link href="https://exploits.run/uncovering-a-scam/"/>
    <id>https://exploits.run/uncovering-a-scam/</id>
    <updated>2020-05-28T12:00:00.000Z</updated>
    <published>2020-05-28T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Due to a large amount of screenshots with text, this blog is best read on a desktop as opposed to a phone. This post is also rather long so you may want to get settled in. Many of you know that I use Brave as my daily browser. One of the fe…</summary>
  </entry>
  <entry>
    <title>Analyzing Analytics (Featuring: The FBI)</title>
    <link href="https://exploits.run/analytics-analysis-fbi/"/>
    <id>https://exploits.run/analytics-analysis-fbi/</id>
    <updated>2020-02-16T12:00:00.000Z</updated>
    <published>2020-02-16T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Recently while conducting some research, I found myself down the path of Google Analytics ID&#39;s as well as other analytics services. I was investigating ways to not only identify varying analytics code in sites, but to correlate them with ot…</summary>
  </entry>
  <entry>
    <title>Facebook | Uncovering Seller Info Without Login</title>
    <link href="https://exploits.run/fbmarketplace/"/>
    <id>https://exploits.run/fbmarketplace/</id>
    <updated>2020-01-03T12:00:00.000Z</updated>
    <published>2020-01-03T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>I was doing some research this week on Facebook Marketplace looking for some... unethically acquired and resold items and the sellers behind them. However, my research was limited to only acquiring data without being logged into a Facebook…</summary>
  </entry>
  <entry>
    <title>The Internet of Sonos</title>
    <link href="https://exploits.run/sonos/"/>
    <id>https://exploits.run/sonos/</id>
    <updated>2019-01-22T12:00:00.000Z</updated>
    <published>2019-01-22T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Recently a friend of mine inquired about my opinion on a Sonos (audio) device that was on their network that had been end of life for years. We were deliberating on what the threat landscape was for seemingly harmless devices like this on t…</summary>
  </entry>
  <entry>
    <title>Hacking Rihanna&#39;s Bank Account</title>
    <link href="https://exploits.run/rihanna/"/>
    <id>https://exploits.run/rihanna/</id>
    <updated>2018-11-30T12:00:00.000Z</updated>
    <published>2018-11-30T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Okay full disclosure, this title is half clickbait. This is actually a story about a scammer claiming to be Rihanna asking me to hack their bank account and send their “brother” money. The majority of this will simply be screenshots of the…</summary>
  </entry>
  <entry>
    <title>Using Password Resets for OSINT</title>
    <link href="https://exploits.run/password-osint/"/>
    <id>https://exploits.run/password-osint/</id>
    <updated>2018-11-19T12:00:00.000Z</updated>
    <published>2018-11-19T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>This post is part practical, but mostly story. I’ll go through how I use password resets on various services to gather fragments of information on someone, alongside a story of how I piece those together to get more definitive information.…</summary>
  </entry>
  <entry>
    <title>Email Spoofing With Powershell</title>
    <link href="https://exploits.run/email-spoofing-powershell/"/>
    <id>https://exploits.run/email-spoofing-powershell/</id>
    <updated>2018-10-21T12:00:00.000Z</updated>
    <published>2018-10-21T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>I had previously written about Email Spoofing With Netcat/Telnet and it was a seemingly instant hit. Even though the same commands were applicable to Windows users through telnet, which is off by default on Windows installations, or netcat…</summary>
  </entry>
  <entry>
    <title>No, A Porn Virus Didn&#39;t Compromise Your Account</title>
    <link href="https://exploits.run/porn-scam/"/>
    <id>https://exploits.run/porn-scam/</id>
    <updated>2018-10-08T12:00:00.000Z</updated>
    <published>2018-10-08T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>I provide support to many businesses so I run into plenty of random issues throughout my work week. However, one issue appears to be an ever increasing constant over the past several weeks. So much so that I’ve actually had to type up a can…</summary>
  </entry>
  <entry>
    <title>Email Spoofing With Netcat or Telnet</title>
    <link href="https://exploits.run/email-spoofing-netcat/"/>
    <id>https://exploits.run/email-spoofing-netcat/</id>
    <updated>2018-09-26T12:00:00.000Z</updated>
    <published>2018-09-26T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>I have also written a follow up post about spoofing with powershell here . Recently, while having a discussion with a security research team I’m on, we stumbled into discussion about email spoofing. This ultimately led to all sorts of shena…</summary>
  </entry>
  <entry>
    <title>BSides Portland | OSINT CTF</title>
    <link href="https://exploits.run/bsidespdx/"/>
    <id>https://exploits.run/bsidespdx/</id>
    <updated>2018-08-27T12:00:00.000Z</updated>
    <published>2018-08-27T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>The final score was close. I placed second as a solo competitor (CWRT), losing to a team of 4. I had the opportunity to attend the BSides Portland event this year and I had a great time. There were some great talks this year and I feel like…</summary>
  </entry>
  <entry>
    <title>Parrot OS on Windows Subsystem for Linux (WSL)</title>
    <link href="https://exploits.run/parrot-wsl/"/>
    <id>https://exploits.run/parrot-wsl/</id>
    <updated>2018-05-22T12:00:00.000Z</updated>
    <published>2018-05-22T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>Due to Parrot no longer actively maintaining the Github repo for this install script, I have ported it to a gist on my own account. I am now working to actively maintain it to ensure it continues working. As of Jan 13, 2020, it appears that…</summary>
  </entry>
  <entry>
    <title>Nmap In The Windows Subsystem for Linux (WSL)</title>
    <link href="https://exploits.run/nmap-wsl/"/>
    <id>https://exploits.run/nmap-wsl/</id>
    <updated>2018-05-21T12:00:00.000Z</updated>
    <published>2018-05-21T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary># TL;DR: Use an alias on the WSL side to call to the Windows side. Ever since the release of the Windows Subsystem for Linux, a years long unfulfilled hope of using Nmap in this wonderful environment still lingers. If you run: sudo apt-inst…</summary>
  </entry>
  <entry>
    <title>Tales of a Man Flippant With His Data (Facebook)</title>
    <link href="https://exploits.run/data-facebook/"/>
    <id>https://exploits.run/data-facebook/</id>
    <updated>2018-04-21T12:00:00.000Z</updated>
    <published>2018-04-21T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>This is post 2 of 2 in a series on data collection. You can view post one here . # IP ADDRESSES GALORE Unless I’m mistaken, and I very well may be, it appears that Facebook does far more IP logging than Google did (at least from what was av…</summary>
  </entry>
  <entry>
    <title>Tales of a Man Flippant With His Data (Google)</title>
    <link href="https://exploits.run/data-google/"/>
    <id>https://exploits.run/data-google/</id>
    <updated>2018-04-03T12:00:00.000Z</updated>
    <published>2018-04-03T12:00:00.000Z</published>
    <author><name>Michael</name></author>
    <summary>This is post 1 of 2 in a series on data collection. You can view post two here . Recently, I decided to download my Google and Facebook data archives containing all the information they had on me. I have had a Google account since 2006 and…</summary>
  </entry>
</feed>
