# pulsesecurity.co.nz > AI-optimized mirror of pulsesecurity.co.nz containing 50 pages totalling 22,150 words of clean markdown content, structured data, and semantic HTML. Original source: https://pulsesecurity.co.nz/. Last updated: 2026-06-13T19:34:26.021Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [**Pulse Security** is a specialist information security consultancy.](/content/site-root.html): Technical Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Infrastructure, Digital Forensics, Incident Response (488 words) ## Articles & Blog Posts - [Adrian Hayes Principal Consultant](/content/team/index.html): Technical Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Infrastructure, Digital Forensics, Incident Response (321 words) - [articles/ducati-696-part2/index.html](/content/articles/ducati-696-part2/index.html) (1 words) - [advisories/zerotier-private-network-access/index.html](/content/advisories/zerotier-private-network-access/index.html) (1 words) - [advisories/aspnetboilerplate-jwt/index.html](/content/advisories/aspnetboilerplate-jwt/index.html) (1 words) - [articles/some-tailscale-tricks/index.html](/content/articles/some-tailscale-tricks/index.html) (1 words) - [articles/dotnet-padding-oracles/index.html](/content/articles/dotnet-padding-oracles/index.html) (1 words) - [articles/ducati-696-canbus/index.html](/content/articles/ducati-696-canbus/index.html) (1 words) - [articles/portable-pivoting/index.html](/content/articles/portable-pivoting/index.html) (1 words) - [articles/orm-sqli/index.html](/content/articles/orm-sqli/index.html) (1 words) - [advisories/gocd-multiple-vulnerabilities/index.html](/content/advisories/gocd-multiple-vulnerabilities/index.html) (1 words) - [advisories/aws-bastion-logger-bypass/index.html](/content/advisories/aws-bastion-logger-bypass/index.html) (1 words) - [articles/postgres-sqli/index.html](/content/articles/postgres-sqli/index.html) (1 words) - [articles/el-injection-waf-bypass/index.html](/content/articles/el-injection-waf-bypass/index.html) (1 words) - [articles/docker-rootkits/index.html](/content/articles/docker-rootkits/index.html) (1 words) - [articles/automated-security-wins/index.html](/content/articles/automated-security-wins/index.html) (1 words) - [advisories/linux-kernel-4-9-tcpsocketsuaf.html](/content/advisories/linux-kernel-4-9-tcpsocketsuaf.html) (1 words) - [articles/breaking-sqlserver-rand/index.html](/content/articles/breaking-sqlserver-rand/index.html) (1 words) - [articles/tpm-sniffing/index.html](/content/articles/tpm-sniffing/index.html) (1 words) - [advisories/atftpd-multiple-vulnerabilities/index.html](/content/advisories/atftpd-multiple-vulnerabilities/index.html) (1 words) - [articles/office365-audit/index.html](/content/articles/office365-audit/index.html) (1 words) - [Summary](/content/articles/samesite-lax-csrf/index.html): Default `SameSite` settings are not the same as `SameSite: Lax` set explicitly. TLDR? A two-minute window from when a cookie is issued is open to exploit CSR... (1,358 words) - [articles/ducati-can-bus/index.html](/content/articles/ducati-can-bus/index.html) (1 words) - [advisories/pihole-v3-3-vulns.html](/content/advisories/pihole-v3-3-vulns.html) (1 words) - [Background](/content/articles/hybrid-assessment/index.html): Hybrid Security Assessment - A collaborative, research-based approach to security assurance (2,310 words) - [CSRF - Account Import from CSV file](/content/advisories/kanboard/index.html): Kanboard 1.2.7 Multiple Vulnerabilities (1,096 words) - [Sourcemaps](/content/articles/javascript-from-sourcemaps/index.html): Using Sourcemaps to retrieve the original JavaScript code (1,112 words) - [Vulnerability Overview](/content/advisories/adyen-magento2-vulnerabilities/index.html): Adyen Payment Magento2 Plugin - Multiple Vulnerabilities (936 words) - [The Business Stuff](/content/articles/2021-summary/index.html): The pandemic maxed out our work-from-home stats, we forgot to cancel our coffee subscription and ended up hoarding Havana beans by accident, we hacked many b... (1,294 words) - [inet_csk_listen_stop GPF](/content/advisories/linux-kernel-4-9-inetcsklistenstop-gpf.html): Linux Kernel 4.9 - inet_csk_listen_stop GPF (900 words) - [Strong passwords - Phrases not Cases, yo](/content/articles/three-things/index.html): 2019 was a fun year for us at Pulse. We researched, we shelled, we reported. There were jobs that were hard, and this post is going look at a few things that... (1,603 words) - [SAML Authentication Bypass](/content/advisories/weblogic-saml-vulnerabilities/index.html): Oracle Weblogic - Multiple SAML Vulnerabilities (608 words) - [Bypassing Time-Based One Time Password (TOTP) Multi-Factor Authentication](/content/articles/totp-bruting/index.html): In this post I'll show you a neat party trick that can let you easily bypass Time-Based One Time Password (TOTP) multi-factor authentication, and often withi... (1,308 words) - [Proof of concept](/content/advisories/cve2018-8118/index.html): Microsoft Internet Explorer Hyperlink Memory Corruption (CVE-2018-8118) (265 words) - [Introduction](/content/articles/r-shells/index.html): Can you tell me how to get shells on OpenCPU... (895 words) - [parse\_arguments OOB Read](/content/advisories/rsyncd-parse_argument-oob-read/index.html): Rsync Daemon - parse_arguments Out-Of-Bounds Read (424 words) - [ManageEngine OpManager – Multiple Authenticated RCE Vulnerabilities](/content/advisories/manageengine-opmanager-rce/index.html): Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities (914 words) - [Details](/content/advisories/gopandoc-filter-rce/index.html): Go-pandoc - LUA filter remote code execution (538 words) - [Privilege Escalation](/content/advisories/phusion-passenger-priv-esc/index.html): Phusion Passenger chown() race privilege escalation (CVE-2018-12029) (710 words) - [TL;DR](/content/articles/login-security-controls/index.html): Authentication design for websites is tricky business, and we’re finding more and more websites are falling behind the times. Let’s talk user login design an... (1,196 words) - [Privilege Escalation](/content/advisories/nm-vpnc-privesc/index.html): Network Manager VPN - Privilege Escalation (397 words) - [Details](/content/advisories/wikijs-stored-xss/index.html): Wiki.js - Stored cross-site scripting through template injection (323 words) - [Proof of Concept](/content/advisories/cve20188563/index.html): Microsoft DirectX Memory Corruption (CVE-2018-8563) (325 words) - [Date Released](/content/advisories/atlassian-id-username-enumeration/index.html): Atlassian - id.atlassian.com Username Enumeration (534 words) - [Details](/content/advisories/untitled-goose-game-deserialization/index.html): Untitled Goose Game - Insecure Save Game Deserialization - Code Execution (345 words) - [Proof of Concept](/content/advisories/cve20180932/index.html): Microsoft Edge / Internet Explorer SVG Memory Corruption (CVE-2018-0932) (266 words) - [MicroK8s Privilege Escalation Vulnerability](/content/advisories/microk8s-privilege-escalation/index.html): MicroK8s <= v1.15.2 - Privilege Escalation to Root (CVE-2019-15789) (406 words) - [Penetration Testing](/content/articles/pentest-vs-redteam/index.html): Penetration testing or red teaming. The differences, which to choose and why. (798 words) - [Proof-of-Concept](/content/advisories/cve20188249/index.html): Microsoft Internet Explorer EnterBlock Memory Corruption (CVE-2018-8249) (273 words) - [Summary of CVE Advisories](/content/sitemap-xml.html) (186 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives