<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse Engineering on MeteSec</title><link>https://metesec.com/tags/reverse-engineering/</link><description>Recent content in Reverse Engineering on MeteSec</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>metesec@outlook.com (Mete Demirci)</managingEditor><webMaster>metesec@outlook.com (Mete Demirci)</webMaster><copyright>© 2026 Mete Demirci</copyright><lastBuildDate>Thu, 27 Aug 2026 00:01:00 +0200</lastBuildDate><atom:link href="https://metesec.com/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>Living Off the Vault: From ‘I’m Staff’ to Breaking Custom Cryptography</title><link>https://metesec.com/posts/living-off-the-vault/</link><pubDate>Thu, 27 Aug 2026 00:01:00 +0200</pubDate><author>metesec@outlook.com (Mete Demirci)</author><guid>https://metesec.com/posts/living-off-the-vault/</guid><description>&lt;p class="article-lead"&gt;It started with a chatbot. It ended with an enterprise password vault decrypted without its master password. Everything in between involved an FTP jail escape, an Electron AppImage, a native Node.js add-on and a custom cipher that collapsed under its own mathematics.&lt;/p&gt;
&lt;p&gt;I recently worked through OffSec&amp;rsquo;s &lt;strong&gt;Living Off the Vault&lt;/strong&gt; challenge, and it had one of the strangest technical progressions I have seen in a lab so far.&lt;/p&gt;
&lt;p&gt;The first page looked like a normal support portal. A few stages later, I was analyzing an affine substitution box and using the application&amp;rsquo;s own native encryption primitive against it.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://metesec.com/posts/living-off-the-vault/featured.png"/></item><item><title>Following the Evidence Through OffSec's Dune Phantom</title><link>https://metesec.com/posts/following-the-evidence-through-dune-phantom/</link><pubDate>Wed, 26 Aug 2026 22:00:00 +0200</pubDate><author>metesec@outlook.com (Mete Demirci)</author><guid>https://metesec.com/posts/following-the-evidence-through-dune-phantom/</guid><description>&lt;p class="article-lead"&gt;Four investigations. Four completely different environments. One lesson that kept returning: follow the evidence, not the loudest alert.&lt;/p&gt;
&lt;p&gt;Over the last few weeks, I worked through OffSec&amp;rsquo;s &lt;strong&gt;Dune Phantom&lt;/strong&gt; challenge series.&lt;/p&gt;
&lt;p&gt;I considered writing four separate walkthroughs. Instead, I wanted to capture the investigation as a single story—because what made the series memorable was not any individual answer. It was how radically the environment changed from one week to the next while the investigative method stayed the same.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://metesec.com/posts/following-the-evidence-through-dune-phantom/featured.png"/></item></channel></rss>