<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://mrdarkroot.github.io/</id><title>Duy Tran</title><subtitle>My personal notes on security research,hacking, pentesting,read code.</subtitle> <updated>2026-06-19T01:56:45+00:00</updated> <author> <name>MrDarkRoot</name> <uri>https://mrdarkroot.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://mrdarkroot.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://mrdarkroot.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 MrDarkRoot </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>CVE-2026-11571: Unauthenticated Sensitive Information Exposure in Everest Forms</title><link href="https://mrdarkroot.github.io/posts/cve-2026-11571-everest-forms-sensitive-information-exposure/" rel="alternate" type="text/html" title="CVE-2026-11571: Unauthenticated Sensitive Information Exposure in Everest Forms" /><published>2026-06-19T14:30:00+00:00</published> <updated>2026-06-19T01:23:49+00:00</updated> <id>https://mrdarkroot.github.io/posts/cve-2026-11571-everest-forms-sensitive-information-exposure/</id> <content type="text/html" src="https://mrdarkroot.github.io/posts/cve-2026-11571-everest-forms-sensitive-information-exposure/" /> <author> <name>MrDarkRoot</name> </author> <category term="Security Research" /> <category term="WordPress" /> <summary>Technical analysis of CVE-2026-11571, an unauthenticated sensitive information exposure vulnerability in Everest Forms caused by residual public CSV artifacts.</summary> </entry> <entry><title>CVE-2026-11855: Unauthenticated Stored XSS in Simple Membership</title><link href="https://mrdarkroot.github.io/posts/cve-2026-11855-simple-membership-stored-xss/" rel="alternate" type="text/html" title="CVE-2026-11855: Unauthenticated Stored XSS in Simple Membership" /><published>2026-06-15T14:00:00+00:00</published> <updated>2026-06-17T12:53:11+00:00</updated> <id>https://mrdarkroot.github.io/posts/cve-2026-11855-simple-membership-stored-xss/</id> <content type="text/html" src="https://mrdarkroot.github.io/posts/cve-2026-11855-simple-membership-stored-xss/" /> <author> <name>MrDarkRoot</name> </author> <category term="Security Research" /> <category term="WordPress" /> <summary>Technical analysis of CVE-2026-11855, an unauthenticated stored cross-site scripting vulnerability in the Simple Membership WordPress plugin.</summary> </entry> <entry><title>Write-up: Cyber Kill Chain (TryHackMe) — biusa_mrdarkroot</title><link href="https://mrdarkroot.github.io/posts/cyber-kill-chain-writeup/" rel="alternate" type="text/html" title="Write-up: Cyber Kill Chain (TryHackMe) — biusa_mrdarkroot" /><published>2025-10-24T17:00:00+00:00</published> <updated>2025-10-24T17:00:00+00:00</updated> <id>https://mrdarkroot.github.io/posts/cyber-kill-chain-writeup/</id> <content type="text/html" src="https://mrdarkroot.github.io/posts/cyber-kill-chain-writeup/" /> <author> <name>MrDarkRoot</name> </author> <category term="CTF" /> <category term="Writeup" /> <category term="Cyber Kill Chain" /> <summary>Xin chào Jekyll 👋 Bài viết này tổng hợp toàn bộ nội dung từ phòng TryHackMe: Cyber Kill Chain, bao gồm giải thích chi tiết 7 giai đoạn của mô hình Lockheed Martin Cyber Kill Chain, cùng các ví dụ và biện pháp phòng chống tương ứng. Tác giả: biusa_mrdarkroot 🪶 Room Summary Phòng Cyber Kill Chain trên TryHackMe giúp người học hiểu rõ cách thức một cuộc tấn công mạng diễn ra theo từng giai đo...</summary> </entry> <entry><title>Lxd Priv Esc Writeup</title><link href="https://mrdarkroot.github.io/posts/lxd-priv-esc-writeup/" rel="alternate" type="text/html" title="Lxd Priv Esc Writeup" /><published>2025-10-20T00:00:00+00:00</published> <updated>2026-06-16T12:49:10+00:00</updated> <id>https://mrdarkroot.github.io/posts/lxd-priv-esc-writeup/</id> <content type="text/html" src="https://mrdarkroot.github.io/posts/lxd-priv-esc-writeup/" /> <author> <name>MrDarkRoot</name> </author> <summary>“Write-up: LXD Privilege Escalation — Theory, Risks &amp;amp; Defenses (Safe)” date: 2025-10-20 14:00:00 +0700 categories: [Security, Writeup] tags: [lxd, privilege-escalation, hardening, linux, defense] Hello Jekyll Author: biusa_mrdarkroot Short summary: This write-up explains the theory behind a known LXD-based privilege escalation class, describes risks and indicators of abuse, and — m...</summary> </entry> <entry><title>Write-up:Hacking with powershell (TryHackMe)</title><link href="https://mrdarkroot.github.io/posts/powershell-writeup/" rel="alternate" type="text/html" title="Write-up:Hacking with powershell (TryHackMe)" /><published>2025-10-17T13:00:00+00:00</published> <updated>2026-06-16T12:43:40+00:00</updated> <id>https://mrdarkroot.github.io/posts/powershell-writeup/</id> <content type="text/html" src="https://mrdarkroot.github.io/posts/powershell-writeup/" /> <author> <name>MrDarkRoot</name> </author> <category term="CTF" /> <category term="Writeup" /> <category term="Windows" /> <category term="PowerShell" /> <summary>Hello Jekyll This write-up summarizes the PowerShell room exercises and solutions. Author: biusa_mrdarkroot We explore PowerShell basics, Windows enumeration using PowerShell, and scripting challenges that help automate enumeration tasks. Objectives In this room we’ll cover: What PowerShell is and how it works Basic PowerShell cmdlets and patterns Windows enumeration using PowerSh...</summary> </entry> </feed>
