<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0x_welsh</title><description>Systems engineering, reverse engineering, and offensive security research. Kernel internals, binary exploitation, and web security.</description><link>https://welsh.co.ke/</link><item><title>Advent of CTF 2025: Day 1 - The Mission Begins</title><link>https://welsh.co.ke/posts/advent-of-ctf-2025-day-1-mission-begins/</link><guid isPermaLink="true">https://welsh.co.ke/posts/advent-of-ctf-2025-day-1-mission-begins/</guid><description>A beginner-friendly cryptography challenge involving multi-step encoding conversion using CyberChef to decode binary data into the final flag.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Advent of CTF 2025: Day 2 - The First Strike</title><link>https://welsh.co.ke/posts/advent-of-ctf-2025-day-2-first-strike/</link><guid isPermaLink="true">https://welsh.co.ke/posts/advent-of-ctf-2025-day-2-first-strike/</guid><description>Network forensics challenge analyzing FTP traffic to identify compromised credentials during a Krampus Syndicate intrusion attempt.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Advent of CTF 2025: Day 3 - Syndicate Infrastructure</title><link>https://welsh.co.ke/posts/advent-of-ctf-2025-day-3-syndicate-infrastructure/</link><guid isPermaLink="true">https://welsh.co.ke/posts/advent-of-ctf-2025-day-3-syndicate-infrastructure/</guid><description>Advanced DNS reconnaissance challenge involving SPF and DKIM record analysis to uncover hidden infrastructure used by the Krampus Syndicate.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Advent of CTF 2025: Day 4 - The Elf&apos;s Wager</title><link>https://welsh.co.ke/posts/advent-of-ctf-2025-day-4-elfs-wager/</link><guid isPermaLink="true">https://welsh.co.ke/posts/advent-of-ctf-2025-day-4-elfs-wager/</guid><description>Reverse engineering challenge involving static analysis of a stripped ELF binary with anti-debugging measures and XOR-based authentication.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Advent of CTF 2025: Day 5 - Kramazon</title><link>https://welsh.co.ke/posts/advent-of-ctf-2025-day-5-kramazon/</link><guid isPermaLink="true">https://welsh.co.ke/posts/advent-of-ctf-2025-day-5-kramazon/</guid><description>Web exploitation challenge targeting a malicious e-commerce platform with cookie manipulation and privilege escalation vulnerabilities.</description><pubDate>Mon, 22 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Binary Whisper: Beginner Binary Analysis Walkthrough</title><link>https://welsh.co.ke/posts/binary-whisper-binary-analysis/</link><guid isPermaLink="true">https://welsh.co.ke/posts/binary-whisper-binary-analysis/</guid><description>A friendly, step-by-step writeup of the Binary Whisper challenge using basic static analysis and a tiny XOR decode script.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Building a Custom ELF Loader from Scratch, in C</title><link>https://welsh.co.ke/posts/building-a-custom-elf-loader-in-c/</link><guid isPermaLink="true">https://welsh.co.ke/posts/building-a-custom-elf-loader-in-c/</guid><description>You type ./program and the kernel loads it. Here&apos;s how that works: we build a userspace ELF loader in ~300 lines of C that maps PT_LOAD segments, builds a stack by hand, and jumps to the entry point.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Building My First Multiboot Toy Kernel (x86, C + Assembly)</title><link>https://welsh.co.ke/posts/building-my-first-multiboot-toy-kernel-x86-c-assembly/</link><guid isPermaLink="true">https://welsh.co.ke/posts/building-my-first-multiboot-toy-kernel-x86-c-assembly/</guid><description>How I built a 32-bit freestanding toy kernel that boots through GRUB, enters C cleanly, and now handles CPU exceptions through GDT+IDT setup.</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Building Welsh Motorhub&apos;s Buyer Request Funnel</title><link>https://welsh.co.ke/posts/building-welsh-motorhub-buyer-request-funnel/</link><guid isPermaLink="true">https://welsh.co.ke/posts/building-welsh-motorhub-buyer-request-funnel/</guid><description>How I built a request-driven car marketplace flow in Kenya: buyer privacy, dealer offer limits, WhatsApp routing, and admin controls.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>C from the trenches: breaking the stack</title><link>https://welsh.co.ke/posts/c-from-the-trenches-breaking-the-stack/</link><guid isPermaLink="true">https://welsh.co.ke/posts/c-from-the-trenches-breaking-the-stack/</guid><description>A deep dive into how C handles memory and how we can use buffer overflows to hijack program execution.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Copy Fail: CVE-2026-31431 (TryHackMe)</title><link>https://welsh.co.ke/posts/cve-2026-31431-copy-fail/</link><guid isPermaLink="true">https://welsh.co.ke/posts/cve-2026-31431-copy-fail/</guid><description>Exploit copy-fail, a kernel LPE that corrupts any file&apos;s page cache to gain root in seconds.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate></item><item><title>Easy Elf (reversing.kr)</title><link>https://welsh.co.ke/posts/easy-elf-reversing-kr/</link><guid isPermaLink="true">https://welsh.co.ke/posts/easy-elf-reversing-kr/</guid><description>Find the password that makes the binary print `Correct!`.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Introduction to Web Services and APIs</title><link>https://welsh.co.ke/posts/introduction-to-web-services-and-apis-pt1/</link><guid isPermaLink="true">https://welsh.co.ke/posts/introduction-to-web-services-and-apis-pt1/</guid><description>Web Services vs APIs, what&apos;s the difference? In this post, I break down XML-RPC, JSON-RPC, SOAP, REST and more with real code examples</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Mastering Syscall-Level Reversing pt1</title><link>https://welsh.co.ke/posts/mastering-syscall-level-reversing/</link><guid isPermaLink="true">https://welsh.co.ke/posts/mastering-syscall-level-reversing/</guid><description>A Deep Dive into Operating System Interactions; Why Syscall-Level Matters</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Mastering Syscall-Level Reversing pt2; The Art of Unhooking &amp; Direct Syscalls</title><link>https://welsh.co.ke/posts/mastering-syscall-level-reversing-pt2/</link><guid isPermaLink="true">https://welsh.co.ke/posts/mastering-syscall-level-reversing-pt2/</guid><description>The hook is the problem</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Mini-Readelf: Gluing It All Together</title><link>https://welsh.co.ke/posts/mini-readelf-gluing-it-all-together/</link><guid isPermaLink="true">https://welsh.co.ke/posts/mini-readelf-gluing-it-all-together/</guid><description>The capstone. Four parts of pieces, headers, sections, symbols, relocations, joined into one tool that reads any ELF. The only new mechanic is the sh_link chain: offset into a table that holds offsets into a table that holds strings.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate></item><item><title>n8n CVE-2025-68613: When Workflow Automation Goes Wrong</title><link>https://welsh.co.ke/posts/n8n-cve-2025-68613-expression-injection/</link><guid isPermaLink="true">https://welsh.co.ke/posts/n8n-cve-2025-68613-expression-injection/</guid><description>A comprehensive look at CVE-2025-68613 in n8n - how expression injection can lead to remote code execution and what you can do to protect yourself.</description><pubDate>Thu, 25 Dec 2025 00:00:00 GMT</pubDate></item><item><title>NahamCon Winter CTF 2025: Crypto Challenge Writeups</title><link>https://welsh.co.ke/posts/nahamcon-winter-ctf-2025-crypto-writeups/</link><guid isPermaLink="true">https://welsh.co.ke/posts/nahamcon-winter-ctf-2025-crypto-writeups/</guid><description>Comprehensive writeups for the cryptography challenges from NahamCon Winter CTF 2025, featuring Linear Lines affine cipher analysis and practical solving techniques.</description><pubDate>Fri, 19 Dec 2025 00:00:00 GMT</pubDate></item><item><title>NahamCon Winter CTF 2025: Mobile Security Challenge Writeups</title><link>https://welsh.co.ke/posts/nahamcon-winter-ctf-2025-mobile-writeups/</link><guid isPermaLink="true">https://welsh.co.ke/posts/nahamcon-winter-ctf-2025-mobile-writeups/</guid><description>Detailed writeups for mobile security challenges from NahamCon Winter CTF 2025, covering Android APK reverse engineering, vulnerability analysis, and exploitation techniques.</description><pubDate>Fri, 19 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Parsing ELF Binaries in C</title><link>https://welsh.co.ke/posts/parsing-elf-binaries-in-c/</link><guid isPermaLink="true">https://welsh.co.ke/posts/parsing-elf-binaries-in-c/</guid><description>The first step to actually understanding what runs on your machine: read an ELF file yourself. No libelf, no readelf — just mmap and pointer casts. I walk the header and section table of a real binary, and diff my output against the tools that already exist.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Relocations: How PIE Binaries Fix Their Addresses</title><link>https://welsh.co.ke/posts/relocations-how-pie-binaries-fix-their-addresses/</link><guid isPermaLink="true">https://welsh.co.ke/posts/relocations-how-pie-binaries-fix-their-addresses/</guid><description>A PIE binary can&apos;t write final addresses because ASLR moves it. The linker leaves placeholders and the loader patches them after mapping. That&apos;s a relocation: R_X86_64_RELATIVE, GLOB_DAT and JUMP_SLOT.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Static Analysis of ELF x86 Binary - RootMe Challenge</title><link>https://welsh.co.ke/posts/rootme-elf-x86-0-protection/</link><guid isPermaLink="true">https://welsh.co.ke/posts/rootme-elf-x86-0-protection/</guid><description>Systematic reverse engineering approach for unprotected ELF binaries using static analysis techniques and Ghidra decompilation</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title>ret2win</title><link>https://welsh.co.ke/posts/rop-emporium-ret2win/</link><guid isPermaLink="true">https://welsh.co.ke/posts/rop-emporium-ret2win/</guid><description>Today, we are going to break down ret2win, a classic binary exploitation challenge from ROP Emporium.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Symbol Tables: What Function Names Actually Are</title><link>https://welsh.co.ke/posts/symbol-tables-what-function-names-actually-are/</link><guid isPermaLink="true">https://welsh.co.ke/posts/symbol-tables-what-function-names-actually-are/</guid><description>Function names in a binary are just entries in a table. Two tables actually: .symtab and .dynsym. Here&apos;s what each is for, how the struct works, and how to resolve a name from an address.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The Go Shebang: Scripting Without the Compile-Run Friction</title><link>https://welsh.co.ke/posts/the-go-shebang-scripting-without-the-compile-run-friction/</link><guid isPermaLink="true">https://welsh.co.ke/posts/the-go-shebang-scripting-without-the-compile-run-friction/</guid><description>In traditional Unix Scripting, the `#!` (shebang) tells the kernel which interpreter to use for the file. For Go, which is a compiled language, this is technically a lie. By using a wrapper, you can treat `.go` files as executable scripts that compile and run on the fly.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Cloud Security Pitfalls - TryHackMe Writeup</title><link>https://welsh.co.ke/posts/tryhackme-cloud-security-pitfalls-writeup/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-cloud-security-pitfalls-writeup/</guid><description>A friendly, SOC-focused walkthrough of cloud migration risks, shared responsibility, logging challenges, and practical monitoring takeaways.</description><pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Understanding the Cyber Kill Chain - TryHackMe Writeup</title><link>https://welsh.co.ke/posts/tryhackme-cyber-kill-chain-writeup/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-cyber-kill-chain-writeup/</guid><description>A comprehensive walkthrough of TryHackMe&apos;s Cyber Kill Chain room, exploring each phase of cyber attacks from reconnaissance to actions on objectives, plus a real-world analysis of the Target data breach.</description><pubDate>Sun, 28 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Django CVE-2025-64459: ORM Query Injection Explained</title><link>https://welsh.co.ke/posts/tryhackme-django-cve-2025-64459/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-django-cve-2025-64459/</guid><description>A friendly walkthrough of Django CVE-2025-64459 - understanding and exploiting ORM query parameter injection vulnerabilities in web applications.</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate></item><item><title>cURL Exploitation - Hoperation Eggsploit TryHackMe</title><link>https://welsh.co.ke/posts/tryhackme-exploitation-with-curl-hoperation-eggsploit/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-exploitation-with-curl-hoperation-eggsploit/</guid><description>A hands-on walkthrough of TryHackMe&apos;s cURL exploitation room - learning HTTP requests, POST data, cookies, sessions, and brute force attacks from the command line.</description><pubDate>Fri, 26 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Probably Just Fine - TryHackMe First Shift CTF Writeup</title><link>https://welsh.co.ke/posts/tryhackme-first-shift-ctf-probably-just-fine/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-first-shift-ctf-probably-just-fine/</guid><description>A step-by-step SOC investigation through TryHackMe&apos;s First Shift CTF scenario, covering threat intel lookups, file hash analysis, and report-driven attribution insights.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Mastering Obfuscation Principles - TryHackMe Writeup</title><link>https://welsh.co.ke/posts/tryhackme-obfuscation-principles-writeup/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-obfuscation-principles-writeup/</guid><description>A comprehensive guide to understanding obfuscation techniques for malware evasion, from basic concatenation to advanced control flow manipulation. Learn how attackers hide their code and how defenders can spot these techniques.</description><pubDate>Wed, 31 Dec 2025 00:00:00 GMT</pubDate></item><item><title>TryHackMe: Passwords - A Cracking Christmas</title><link>https://welsh.co.ke/posts/tryhackme-passwords-cracking-christmas/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-passwords-cracking-christmas/</guid><description>A comprehensive walkthrough of the TryHackMe Passwords room, exploring password-based encryption attacks and defensive strategies during the holiday season.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate></item><item><title>TryHackMe: Web Attack Forensics - Drone Alone</title><link>https://welsh.co.ke/posts/tryhackme-web-attack-forensics-drone-alone/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-web-attack-forensics-drone-alone/</guid><description>A comprehensive blue team investigation walkthrough of the TryHackMe Web Attack Forensics room, analyzing malicious web activity and command injection attacks using Splunk.</description><pubDate>Tue, 16 Dec 2025 00:00:00 GMT</pubDate></item><item><title>x86 Architecture for Malware Analysis - TryHackMe Writeup</title><link>https://welsh.co.ke/posts/tryhackme-x86-architecture-overview-writeup/</link><guid isPermaLink="true">https://welsh.co.ke/posts/tryhackme-x86-architecture-overview-writeup/</guid><description>A comprehensive guide to x86 CPU architecture fundamentals essential for malware reverse engineering. Learn about registers, memory layout, and stack operations that form the foundation of system exploitation.</description><pubDate>Mon, 01 Jan 2024 00:00:00 GMT</pubDate></item><item><title>What Happens When You Remove the Lies From a Trading Backtest? 860 Strategy Configurations on 22 Years of EURUSD</title><link>https://welsh.co.ke/posts/what-happens-when-you-remove-the-lies-from-a-trading-backtest/</link><guid isPermaLink="true">https://welsh.co.ke/posts/what-happens-when-you-remove-the-lies-from-a-trading-backtest/</guid><description>I built a backtesting engine where look-ahead bias, optimistic fills and unreproducible results are structurally impossible — then ran 860 EMA crossover and RSI configurations across 23 years of daily EURUSD. The honest verdict: the most popular strategies in retail trading are zombies.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Why C still matters for Reverse Engineering</title><link>https://welsh.co.ke/posts/why-c-still-matters-in-reverse-engineering/</link><guid isPermaLink="true">https://welsh.co.ke/posts/why-c-still-matters-in-reverse-engineering/</guid><description>C is still the GOAT of reverse engineering</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>