<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cyberah</title><link>https://cyberah-blog.pages.dev/en/</link><description>Recent content on Cyberah</description><generator>Hugo</generator><language>en</language><copyright>2026 Cyberah</copyright><lastBuildDate>Thu, 23 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cyberah-blog.pages.dev/en/index.xml" rel="self" type="application/rss+xml"/><item><title>How I Found a Remote Code Execution Vulnerability in the Database Restore Function - CVE-2026-40484</title><link>https://cyberah-blog.pages.dev/en/cve/cve-2026-40484/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/cve/cve-2026-40484/</guid><description>A deep technical analysis of how I found this vulnerability from scratch all the way to receiving the CVE ID.</description></item><item><title>What is Active Directory?</title><link>https://cyberah-blog.pages.dev/en/notes/active-directory/what-is-ad/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/notes/active-directory/what-is-ad/</guid><description>Introduction to Active Directory structure and authentication protocols</description></item><item><title>Attack Active Directory</title><link>https://cyberah-blog.pages.dev/en/notes/active-directory/ad-attacks/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/notes/active-directory/ad-attacks/</guid><description>The most common Active Directory attacks used in red team engagements</description></item><item><title>Lateral Movement in AD Networks</title><link>https://cyberah-blog.pages.dev/en/notes/active-directory/lateral-movement/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/notes/active-directory/lateral-movement/</guid><description>Lateral movement techniques for pivoting between machines in Active Directory environments</description></item><item><title>BloodHound — Mapping Attack Paths</title><link>https://cyberah-blog.pages.dev/en/notes/active-directory/bloodhound/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/notes/active-directory/bloodhound/</guid><description>Using BloodHound to discover shortest attack paths to Domain Admin</description></item><item><title>Blog Statistics</title><link>https://cyberah-blog.pages.dev/en/stats/</link><pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/stats/</guid><description>A comprehensive overview of Cyberah&amp;#39;s content — articles, activity, and most-read</description></item><item><title>Hall of Fame</title><link>https://cyberah-blog.pages.dev/en/hall-of-fame/</link><pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/hall-of-fame/</guid><description>Contributors to Cyberah — ranked by number of articles published</description></item><item><title>About Me</title><link>https://cyberah-blog.pages.dev/en/about/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/about/</guid><description>Ayham Othman — Cyberah | Penetration Tester, Security Researcher, Trainer &amp;amp; Speaker</description></item><item><title>CVE Analysis — Log4Shell Pattern: A JNDI Injection Deep Dive</title><link>https://cyberah-blog.pages.dev/en/cve/cve-2024-log4shell-analysis/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/cve/cve-2024-log4shell-analysis/</guid><description>Deep technical analysis of JNDI Injection vulnerability patterns — discovery, exploitation, and defense</description></item><item><title>Privacy Policy</title><link>https://cyberah-blog.pages.dev/en/privacy/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/privacy/</guid><description>Cyberah blog privacy policy</description></item><item><title>Python for Hackers — Basics to Real Tools</title><link>https://cyberah-blog.pages.dev/en/programming/python-for-hackers/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/programming/python-for-hackers/</guid><description>A practical guide to learning Python from a cybersecurity perspective — writing recon tools, scanners, and exploitation scripts</description></item><item><title>Terms of Use</title><link>https://cyberah-blog.pages.dev/en/terms/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/terms/</guid><description>Cyberah blog terms of use</description></item><item><title>The Complete Nmap Guide — Beginner to Pro</title><link>https://cyberah-blog.pages.dev/en/tools/nmap-complete-guide/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/tools/nmap-complete-guide/</guid><description>Everything you need to know about Nmap: basic scanning, NSE scripts, firewall evasion, and advanced techniques</description></item><item><title>TryHackMe — Startup | Full Writeup</title><link>https://cyberah-blog.pages.dev/en/writeups/thm/thm-startup/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/writeups/thm/thm-startup/</guid><description>Detailed walkthrough for TryHackMe Startup room — FTP Anonymous, RCE via File Upload, Privilege Escalation via Cron</description></item><item><title>Web Penetration Testing Methodology — Zero to Pwned</title><link>https://cyberah-blog.pages.dev/en/notes/methodology-web-pentest/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://cyberah-blog.pages.dev/en/notes/methodology-web-pentest/</guid><description>A comprehensive methodological guide for web application penetration testing, from reconnaissance to final report</description></item></channel></rss>