<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>All on Hello Friend</title>
		<link>https://neo-society.eu/categories/all/</link>
		<description>Recent content in All on Hello Friend</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
			<copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
		
		
			<lastBuildDate>Sat, 15 Aug 2026 14:15:53 +0200</lastBuildDate>
		
			<atom:link href="https://neo-society.eu/categories/all/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Poo-Prolab HTB</title>
				<link>https://neo-society.eu/posts/2026/08/poo-prolab-htb/</link>
				<pubDate>Sat, 15 Aug 2026 14:15:53 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/08/poo-prolab-htb/</guid>
				<description>&lt;p&gt;Waiting screen.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Linkwarden</title>
				<link>https://neo-society.eu/posts/2026/08/linkwarden/</link>
				<pubDate>Sat, 15 Aug 2026 01:36:51 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/08/linkwarden/</guid>
				<description>&lt;h1 id=&#34;fix-duplicate-tags-in-linkwarden&#34;&gt;Fix duplicate tags in linkwarden&lt;/h1&gt;&#xA;&lt;h2 id=&#34;linkwardenlinkwarden520&#34;&gt;&lt;a href=&#34;https://github.com/linkwarden/linkwarden/issues/520&#34;&gt;linkwarden/linkwarden#520&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;I recently deployed &lt;a href=&#34;https://linkwarden.app/&#34;&gt;Linkwarden&lt;/a&gt; in my homelab stack. After giving access to a few friends, we noticed that tags were getting duplicated whenever someone added an existing tag to a link created by someone else. This is a known, still-unfixed issue on GitHub (#520).&lt;/p&gt;&#xA;&lt;h2 id=&#34;simple-and-quick-fix&#34;&gt;Simple and quick fix&lt;/h2&gt;&#xA;&lt;p&gt;The script below merges duplicate tags directly in the database it keeps the oldest tag, reassigns all links to it, and removes the duplicates:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Dante-Prolab HTB</title>
				<link>https://neo-society.eu/posts/2026/08/dante-prolab-htb/</link>
				<pubDate>Fri, 14 Aug 2026 00:15:27 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/08/dante-prolab-htb/</guid>
				<description>&lt;h1 id=&#34;finally-pwned&#34;&gt;Finally pwned&lt;/h1&gt;&#xA;&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;&#xA;&lt;p&gt;Dante Pro Lab is a great environment that mix both Linux and Windows Operating Systems. It&amp;rsquo;s permit to practice &lt;strong&gt;Enumeration&lt;/strong&gt;, &lt;strong&gt;Exploit Development&lt;/strong&gt;, &lt;strong&gt;Lateral Movement&lt;/strong&gt;, &lt;strong&gt;Privilege Escalation&lt;/strong&gt;, &lt;strong&gt;Web Application Attacks&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;synopsis&#34;&gt;Synopsis&lt;/h2&gt;&#xA;&lt;p&gt;Dante LLC have enlisted your services to audit their network. The company has not undergone a comprehensive penetration test in the past, and want to reduce their technical debt. They are concerned that any actual breach could lead to a loss of earnings and reputation damage.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Crowdsec</title>
				<link>https://neo-society.eu/posts/2026/08/crowdsec/</link>
				<pubDate>Sun, 09 Aug 2026 00:19:13 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/08/crowdsec/</guid>
				<description>&lt;h2 id=&#34;waiting-room&#34;&gt;Waiting room&lt;/h2&gt;&#xA;&lt;p&gt;I installed crowdsec to protect my endpoint. here i will document some intersting thing we can see on the dashboard, the blocklist I use limited to 3 beacause I use the free plan. And obviously the stack I personally use. I will show my grafana dashboard to, and explain how it works.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://neo-society.eu/img/test.gif&#34; alt=&#34;crowdsec&#34;&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>OpenCTI Tropic Trooper</title>
				<link>https://neo-society.eu/posts/2026/08/opencti-tropic-trooper/</link>
				<pubDate>Sat, 01 Aug 2026 16:33:21 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/08/opencti-tropic-trooper/</guid>
				<description>&lt;p&gt;A multinational technology company has been the target of several cyberattacks over the past few months. The attackers have successfully stolen sensitive intellectual property and disrupted the company&amp;rsquo;s operations. A threat advisory report about similar attacks has been shared, and as a analyst, I have to identify the tactics, techniques, and procedures (TTPs) being used by the threat group and gather as much information as possible about their identity and motive.&lt;/p&gt;</description>
			</item>
			<item>
				<title>HTB Cyber Apocalypse CTF 2026</title>
				<link>https://neo-society.eu/posts/2026/07/htb-cyber-apocalypse-ctf-2026/</link>
				<pubDate>Wed, 29 Jul 2026 23:14:45 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/07/htb-cyber-apocalypse-ctf-2026/</guid>
				<description>&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;&#xA;&lt;p&gt;Two friends of mine told me about this CTF, and I was curious to test my OSINT skills against it, I have to admit I was a bit disappointed. Even the medium-difficulty OSINT challenges felt quite easy, which was surprising coming from HTB.&lt;/p&gt;&#xA;&lt;p&gt;That said, we finished 805th/6,743 teams (out of 12,695 participants total), not a small CTF by any means, so overall we were pretty happy with the result, even though we still have a long way to go.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Osint</title>
				<link>https://neo-society.eu/posts/2026/07/osint/</link>
				<pubDate>Wed, 01 Jul 2026 17:33:58 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/07/osint/</guid>
				<description>&lt;p&gt;Big things on their way, Osint industries CTF writeup, Osint Fr too, personnal osint projects, with maltego and open source tools.. I didn&amp;rsquo;t write everything yet, and I have to anonymise some things..&lt;/p&gt;</description>
			</item>
			<item>
				<title>Osint Letter</title>
				<link>https://neo-society.eu/posts/2026/04/osint-letter/</link>
				<pubDate>Sat, 25 Apr 2026 22:52:13 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/04/osint-letter/</guid>
				<description>&lt;p&gt;This challenge begins with two provided images. Our objective is twofold: first, to identify the postal code visible on the envelope, and second, to determine the full name of the individual mentioned in the accompanying note, along with their age.&lt;/p&gt;&#xA;&lt;p&gt;We have a note too, and notice this is in french.&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code class=&#34;language-note&#34; data-lang=&#34;note&#34;&gt;Mon cher Édouard,&#xA;&#xA;Aujourd&amp;#39;hui, en rangeant le grenier chez mes grands-parents, je suis tombée sur cette vieille coupure de journal. Ton arrière-grand-père n&amp;#39;avait même pas l&amp;#39;âge de passer le permis quand il s&amp;#39;est distingué ce jour-là. Le benjamin de l&amp;#39;équipe, et certainement pas le moins courageux.&#xA;&#xA;Il serait si fier de te voir sur l&amp;#39;eau à ton tour.&#xA;&#xA;Avec toute mon affection,&#xA;Audette&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;img src=&#34;https://neo-society.eu/img/letter.png&#34; alt=&#34;c&#34;&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>GOAD-Mini</title>
				<link>https://neo-society.eu/posts/2026/04/goad-mini/</link>
				<pubDate>Mon, 06 Apr 2026 22:25:49 +0200</pubDate>
				<guid>https://neo-society.eu/posts/2026/04/goad-mini/</guid>
				<description>&lt;h1 id=&#34;what-is-it&#34;&gt;What is it?&lt;/h1&gt;&#xA;&lt;p&gt;GOAD or Game Of Active Directory, is an open source project created by &lt;strong&gt;Mayfly&lt;/strong&gt; (Orange Cyberdefense). It provides a intentionally vulnerable Active Directory lab environment designed for practicing pentest techniques in a legal and controlled setting.&lt;/p&gt;&#xA;&lt;p&gt;It covers a wide range of AD attack scenarios: enumeration, ACL abuse, Kerberos attacks, ADCS, NTLM relay, and much more.&lt;/p&gt;&#xA;&lt;p&gt;Several lab sizes are available, from the minimal 2-VM MINILAB to the full GOAD with 5 VMs across 3 domains.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Aircrack-ng</title>
				<link>https://neo-society.eu/posts/2026/02/aircrack-ng/</link>
				<pubDate>Sat, 28 Feb 2026 10:13:11 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2026/02/aircrack-ng/</guid>
				<description>&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Last Updated 2026-02-28&#xA;Here, I&amp;#39;m explaining how I solved my issues. &#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;why-&#34;&gt;Why ?&lt;/h2&gt;&#xA;&lt;p&gt;This project is a direct continuation of my Wifijammer experiments. I have a strong interest in wireless communications and protocols like Wi-Fi and BLE, which drives me to test these vulnerabilities firsthand.&lt;/p&gt;&#xA;&lt;p&gt;Moving forward, I plan to explore more advanced attacks and further deepen my understanding of these protocols to better comprehend how modern wireless security layers interact.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Radio Communications Security</title>
				<link>https://neo-society.eu/posts/2026/01/radio-communications-security/</link>
				<pubDate>Sun, 25 Jan 2026 20:30:48 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2026/01/radio-communications-security/</guid>
				<description>&lt;p&gt;&lt;strong&gt;Wireless Security Auditing.&lt;/strong&gt; &lt;a href=&#34;https://github.com/vv4lheim/Master-Secom/blob/main/SECOM-2.pdf&#34;&gt;&lt;strong&gt;See PDF Report&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This report explores the vulnerabilities of IoT devices through SDR techniques. Conducted at Sorbonne University, the project addresses the inherent risks of radio communications, where signals propagate in open space, making them susceptible to interception and jamming.&lt;/p&gt;&#xA;&lt;p&gt;The study utilizes a Raspberry Pi platform equipped with RTL-SDR and PlutoSDR hardware to analyze devices operating on various frequencies. Key experiments include:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Replay Attacks&lt;/strong&gt;: Intercepting and re-emitting fixed codes to control smart plugs and roller shutters using tools like 433Utils and URH.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;False Data Injection Attacks&lt;/strong&gt;: Manipulating weather station displays by injecting forged temperature frames.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Advanced Signal Analysis&lt;/strong&gt;: Moving to the 2.442 GHz band to reverse-engineer drone communications using GNU Radio, which involved bypassing XOR encryption and calculating CRC to retrieve a hidden flag.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The project demonstrates that many consumer IoT devices remain fragile due to the use of simple modulations (ASK/OOK) and the absence of protective mechanisms such as rolling codes or robust encryption.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Reverse Hardware Engineering</title>
				<link>https://neo-society.eu/posts/2026/01/reverse-hardware-engineering/</link>
				<pubDate>Mon, 19 Jan 2026 22:06:02 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2026/01/reverse-hardware-engineering/</guid>
				<description>&lt;p&gt;&lt;strong&gt;STM32F4 Firmware Extraction &amp;amp; Protocol Analysis.&lt;/strong&gt; &lt;a href=&#34;https://github.com/vv4lheim/Master-Reverse-Hardware/blob/main/Reverse_HARD.pdf&#34;&gt;&lt;strong&gt;See PDF Report&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;project-description&#34;&gt;Project Description&lt;/h3&gt;&#xA;&lt;p&gt;This project focused on hardware reverse engineering and the study of embedded systems. We dissected an STM32F4-based device to understand its internal logic and communication:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Firmware Extraction&lt;/strong&gt;: Interfaced with the STM32F4 microcontroller via debug ports to successfully dump the internal memory and retrieve the binary payload.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Protocol Analysis&lt;/strong&gt;: Identified and decoded TLV (Type-Length-Value) command structures used by the firmware to exchange data with external peripherals.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Wifi beaconing</title>
				<link>https://neo-society.eu/posts/2025/12/wifi-beaconing/</link>
				<pubDate>Sat, 27 Dec 2025 22:11:55 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2025/12/wifi-beaconing/</guid>
				<description>&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Maj 2026-02-01&#xA;I&amp;#39;ll post the full code on GitHub with more technical details. &#xA;Here, I&amp;#39;m explaining how I solved my issues. &#xA;I&amp;#39;m learning to use aircrack so, &#xA;I will not implement deauthentication to not lost my time.&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;hr&gt;&#xA;&lt;h3 id=&#34;wireless-security-research--80211&#34;&gt;Wireless Security Research : 802.11&lt;/h3&gt;&#xA;&lt;p&gt;I wanted to learn the basics of WiFi network attacks, so I started experimenting with deauthentication and beaconing. Beaconing is interesting because it relies on user interaction. I enjoy creating personalized clones that mimic real-world services; for example, it was fun rebuilding a fake Moodle login page for a French university. After using Aircrack-ng for deauthentication, I decided to focus less on the attack itself and more on improving the realism of my phishing pages. My next steps are to link these fake Access Points (APs) to the pages and implement a small DNS service to redirect all connections to the correct authentication portal.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Reverse Software Engineering</title>
				<link>https://neo-society.eu/posts/2025/12/reverse-software-engineering/</link>
				<pubDate>Sat, 20 Dec 2025 18:06:05 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2025/12/reverse-software-engineering/</guid>
				<description>&lt;p&gt;&lt;strong&gt;Deep binary analysis of Command &amp;amp; Control components and malicious documents.&lt;/strong&gt; &lt;a href=&#34;https://github.com/vv4lheim/Master-Reverse-Software/blob/main/Reverse.pdf&#34;&gt;&lt;strong&gt;See PDF Report&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;project-description&#34;&gt;Project Description&lt;/h3&gt;&#xA;&lt;p&gt;This project focused on software reverse engineering and the study of complex infection chains. I dissected malicious components to understand their internal mechanics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Binary Analysis:&lt;/strong&gt; Used &lt;code&gt;Ghidra&lt;/code&gt; and &lt;code&gt;Binary Ninja&lt;/code&gt; to reverse-engineer a &lt;strong&gt;C2&lt;/strong&gt; component, analyzing its communication mechanisms and persistence capabilities.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Malicious Document Analysis:&lt;/strong&gt; Investigated compromised &lt;code&gt;XLS&lt;/code&gt; and &lt;code&gt;PDF&lt;/code&gt; files, including macro flow analysis to identify execution vectors.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Infection Chains:&lt;/strong&gt; Reconstructed the complete attack lifecycle, from document delivery to the execution of the final payload.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h3 id=&#34;added-value--professional-objectives&#34;&gt;Added Value &amp;amp; Professional Objectives&lt;/h3&gt;&#xA;&lt;p&gt;This experience allowed me to develop a rigorous approach to &lt;strong&gt;static analysis&lt;/strong&gt; and a deep understanding of malicious software architectures:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Pentest</title>
				<link>https://neo-society.eu/posts/2025/09/pentest/</link>
				<pubDate>Sat, 27 Sep 2025 17:54:12 +0100</pubDate>
				<guid>https://neo-society.eu/posts/2025/09/pentest/</guid>
				<description>&lt;p&gt;&lt;strong&gt;Penetration testing on a simulated enterprise infrastructure.&lt;/strong&gt; &lt;a href=&#34;https://github.com/vv4lheim/Master-Pentest/blob/main/Pentest.pdf&#34;&gt;&lt;strong&gt;See PDF Report&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;project-description&#34;&gt;Project Description&lt;/h3&gt;&#xA;&lt;p&gt;This project, conducted at &lt;strong&gt;Sorbonne University&lt;/strong&gt;, consisted of a comprehensive penetration testing exercise on &lt;strong&gt;Windows&lt;/strong&gt; and &lt;strong&gt;Linux&lt;/strong&gt; environments, including web application audits. I applied a rigorous end-to-end methodology:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Reconnaissance &amp;amp; Scanning: Used &lt;code&gt;Nmap&lt;/code&gt; for network mapping and service discovery.&lt;/li&gt;&#xA;&lt;li&gt;Web Analysis: Performed fuzzing and application penetration testing using &lt;code&gt;Burp Suite&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;Exploitation: Executed brute-force attacks via &lt;code&gt;Hydra&lt;/code&gt;, researched CVEs on &lt;code&gt;ExploitDB&lt;/code&gt;, and performed exploitation with &lt;code&gt;Metasploit&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;Reporting: Authored a detailed audit report covering vulnerabilities, impact analysis, and remediation recommendations.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h3 id=&#34;added-value--professional-objectives&#34;&gt;Added Value &amp;amp; Professional Objectives&lt;/h3&gt;&#xA;&lt;p&gt;This experience allowed me to consolidate a strong foundation for my cybersecurity career:&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
