<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://pgj11.com/</id><title>Peter Gabaldon</title><subtitle>Hacking, Security Researching, Pentesting/Ethical Hacking, Operating Systems...</subtitle> <updated>2026-08-16T07:21:19+02:00</updated> <author> <name>Pedro Gabaldón Juliá</name> <uri>https://pgj11.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://pgj11.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://pgj11.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Pedro Gabaldón Juliá </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>FortiGate Symlink Persistence Method</title><link href="https://pgj11.com/posts/FortiGate-Symlink-Attack/" rel="alternate" type="text/html" title="FortiGate Symlink Persistence Method" /><published>2026-02-10T00:00:00+01:00</published> <updated>2026-08-13T22:39:11+02:00</updated> <id>https://pgj11.com/posts/FortiGate-Symlink-Attack/</id> <content type="text/html" src="https://pgj11.com/posts/FortiGate-Symlink-Attack/" /> <author> <name>Pedro Gabaldón Juliá</name> </author> <category term="FortiGate" /> <category term="VPN" /> <category term="Symlink" /> <category term="Persistence" /> <category term="CVE-2025-68686" /> <summary>Analysis and Exploitation of FortiGate Symlink Persistence Method Background📚 Around April 2025 Fortinet started warning customers that a Threat Actor (TA) continued to have remote read-only access to filesystem after patching FortiGates (FGT) units. This was achieved by a path in the VPN-SSL. Basically, requesting some route (we will see it later in the post) in the VPN-SSL, it allowed to a...</summary> </entry> <entry><title>FortiGate VPN-SSL Honeypot</title><link href="https://pgj11.com/posts/FortiGate-VPN-SSL-Honeypot/" rel="alternate" type="text/html" title="FortiGate VPN-SSL Honeypot" /><published>2025-08-02T00:00:00+02:00</published> <updated>2026-08-13T22:39:11+02:00</updated> <id>https://pgj11.com/posts/FortiGate-VPN-SSL-Honeypot/</id> <content type="text/html" src="https://pgj11.com/posts/FortiGate-VPN-SSL-Honeypot/" /> <author> <name>Pedro Gabaldón Juliá</name> </author> <category term="FortiGate" /> <category term="VPN" /> <category term="Honeypot" /> <summary>FortiGate VPN-SSL Honeypot The following blog post contains an example of running and configuring the FortiGate VPN-SSL Honeypot project. This project can be found in Github here: https://github.com/PeterGabaldon/Fortigate.VPN-SSL.Honeypot Description and Capabilities A deception honeypot that mimics FortiGate VPN-SSL devices to trap brute force attempts, detect deliberately exfiltrated ...</summary> </entry> <entry><title>Bypass Azure Admin Approval Mode for User Consent Workflow When Enumerating</title><link href="https://pgj11.com/posts/Bypass-Azure-Admin-Approval-Mode-Enumeration/" rel="alternate" type="text/html" title="Bypass Azure Admin Approval Mode for User Consent Workflow When Enumerating" /><published>2024-10-11T00:00:00+02:00</published> <updated>2026-08-13T22:39:11+02:00</updated> <id>https://pgj11.com/posts/Bypass-Azure-Admin-Approval-Mode-Enumeration/</id> <content type="text/html" src="https://pgj11.com/posts/Bypass-Azure-Admin-Approval-Mode-Enumeration/" /> <author> <name>Pedro Gabaldón Juliá</name> </author> <category term="Windows security" /> <category term="Azure" /> <category term="Microsoft" /> <summary>Bypass Azure Admin Approval Mode for User Consent Workflow When Enumerating In this short blog post we will see a trick/technique to enumerate an Azure environment when the User App Consent Workflow is blocked and it is necessary to request permission to an administrator. After the administrator approves the consent the user can user the application. When this mode is set an we attempt to enu...</summary> </entry> <entry><title>Finding TeamViewer 0days - Part III</title><link href="https://pgj11.com/posts/Finding-TeamViewer-0days-Part-3/" rel="alternate" type="text/html" title="Finding TeamViewer 0days - Part III" /><published>2024-10-04T00:00:00+02:00</published> <updated>2026-08-13T22:39:11+02:00</updated> <id>https://pgj11.com/posts/Finding-TeamViewer-0days-Part-3/</id> <content type="text/html" src="https://pgj11.com/posts/Finding-TeamViewer-0days-Part-3/" /> <author> <name>Pedro Gabaldón Juliá</name> </author> <category term="Windows security" /> <category term="TeamViewer" /> <summary>Finding TeamViewer 0days. Part 3: Putting it all together. PARTY TIME :)! Now comes the interesting part. I am sorry about the two last lazy parts, but I wanted to explain the whole process :). Because I had spoiled you, we already know that TV is not filtering the parameter sent by the client to ask for the driver installation nor signature check, etc. So the idea that we will review in thi...</summary> </entry> <entry><title>Finding TeamViewer 0days - Part II</title><link href="https://pgj11.com/posts/Finding-TeamViewer-0days-Part-2/" rel="alternate" type="text/html" title="Finding TeamViewer 0days - Part II" /><published>2024-10-04T00:00:00+02:00</published> <updated>2026-08-13T22:39:11+02:00</updated> <id>https://pgj11.com/posts/Finding-TeamViewer-0days-Part-2/</id> <content type="text/html" src="https://pgj11.com/posts/Finding-TeamViewer-0days-Part-2/" /> <author> <name>Pedro Gabaldón Juliá</name> </author> <category term="Windows security" /> <category term="TeamViewer" /> <summary>Finding TeamViewer 0days. Part 2: Reversing the Authentication Protocol I started reversing the client in order to find how the authentication was being made. I will skip this whole part as I finally ended understanding the authentication method revering the service. Reversing the client was a tedious task because of Overlapped I/O, multiple threads handling it, CFG and so on. This conducted ...</summary> </entry> </feed>
