<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ethersec</title><description>Cybersecurity learner documenting my journey through digital threats, security concepts, and real world cases.</description><link>https://ethersec.pages.dev/</link><language>en-us</language><item><title>Streaming Platform Geolocation Bypass Attempt</title><link>https://ethersec.pages.dev/blog/streaming-geolocation-bypass/</link><guid isPermaLink="true">https://ethersec.pages.dev/blog/streaming-geolocation-bypass/</guid><description>A fun little experiment: bypassing a streaming platform&apos;s geo-restriction with an X-Forwarded-For header.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>web</category><category>burpsuite</category><category>geolocation</category><category>bypass</category></item><item><title>PicoCTF 2026 Write-up: 6 Challenges from the General Skills Category</title><link>https://ethersec.pages.dev/blog/picoctf-2026-general-skills/</link><guid isPermaLink="true">https://ethersec.pages.dev/blog/picoctf-2026-general-skills/</guid><description>From the Bytemancy series to Failure Failure and Absolute Nano — picoCTF 2026 General Skills solutions.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>picoctf</category><category>ctf</category><category>writeup</category><category>pwntools</category><category>privilege-escalation</category></item><item><title>picoCTF 2026 — Web Exploitation Write-Up</title><link>https://ethersec.pages.dev/blog/picoctf-2026-web-exploitation/</link><guid isPermaLink="true">https://ethersec.pages.dev/blog/picoctf-2026-web-exploitation/</guid><description>Secret Box, No FA and ORDER ORDER — detailed solutions for three picoCTF 2026 web exploitation challenges.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>picoctf</category><category>ctf</category><category>writeup</category><category>web</category><category>sql-injection</category><category>2fa</category></item><item><title>Vulnerability Analysis in My Own Lab: Nessus and Metasploitable</title><link>https://ethersec.pages.dev/blog/nessus-ve-metasploitable-zafiyet-analizi/</link><guid isPermaLink="true">https://ethersec.pages.dev/blog/nessus-ve-metasploitable-zafiyet-analizi/</guid><description>Scanning Metasploitable with Nessus on an isolated lab network and reviewing the findings like an analyst.</description><pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate><category>nessus</category><category>vulnerability-management</category><category>metasploitable</category><category>lab</category></item><item><title>React2Shell (CVE-2025-55182): How I Analyzed a Critical 10.0 Vulnerability</title><link>https://ethersec.pages.dev/blog/react2shell-cve-2025-55182/</link><guid isPermaLink="true">https://ethersec.pages.dev/blog/react2shell-cve-2025-55182/</guid><description>Exploiting the CVSS 10.0 React2Shell vulnerability hands-on in a TryHackMe room and explaining the deserialization logic.</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate><category>cve</category><category>rce</category><category>react</category><category>deserialization</category><category>tryhackme</category></item></channel></rss>