# Shubham Chaskar > Hacker, Developer ## Posts - [A simple Data Exfiltration!](https://shubhamchaskar.com/excel-magic/): Yes, another XXE attack but with the help of a Microsoft Excel file. Without any further due, let’s get started! XXE Attack: I precisely copied what is XXE from the internet and pasted it in my previous blog post, “A journey from XML External Entity (XXE) to NTLM hashes!“. If you want to know about it, then head over to the blog post mentioned above. It is 10 minutes fun read! 🙂 Microsoft excel: You can do some exciting things with Microsoft excel while hacking, but what stands out for me the most is XXE. An excel file is just... - [A journey from XML External Entity (XXE) to NTLM hashes!](https://shubhamchaskar.com/xxe-to-ntlm/): We will start this blog post with an XML External Entity attack. Furthermore, we will discuss how I was able to capture NTLM v2 hashes using responder and evil-ssdp with the help of that XXE vulnerability. XXE Attack: There is a web security vulnerability that allows an attacker to mess with an application’s XML processing. A remote attacker can often interact with servers or back-end systems that the application can access and view files on the application server’s filesystem. The browser and server exchange data using the XML format in some applications. To process XML data on the server, these... - [Any Account Takeover Through Privilege Escalation](https://shubhamchaskar.com/ato-through-pe/): Hello, I was eagerly waiting to share this with you! 🙂 Due to the two reasons. It’s Account Takeover And I wanted to tell you, “How Important is to revisit your old target to pwn the new features!” I have already shared one of the write-up on Privilege Escalation on Facebook’s product! If you haven’t read that yet you can check here. There are always questions in every newcomer’s mind, “This program is old. All great hackers have already participated, how can I get a bug in this product”? The answer is, “There are new features that are added to... - [Vertical Privilege Escalation in Facebook's Workplace!](https://shubhamchaskar.com/vpe-facebook-workplace/): Hello, I’m Shubham and I have decided to share my finding on one of Facebook’s products “Workplace”! More about Workplace! Workplace is a communication tool that connects everyone in your company, even if they’re working remotely. Use familiar features such as Groups, Chat, Rooms, and live video broadcasting to get people talking and working together. Let’s discuss Privilege Escalation. What is it? Impact? Privilege escalation happens when a malicious user exploits a bug, design flaw, or configuration error in an application or operating system to gain elevated access to resources that should normally be unavailable to that user. Attackers start... ## Pages - [Sample Page](https://shubhamchaskar.com/sample-page/): This is an example page. It’s different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most people start with an About page that introduces them to potential site visitors. It might say something like this: Hi there! I’m a bike messenger by day, aspiring actor by night, and this is my website. I live in Los Angeles, have a great dog named Jack, and I like piña coladas. (And gettin’ caught in the rain.) …or something like this: The XYZ Doohickey Company was founded in 1971,... - [Privacy Policy](https://shubhamchaskar.com/privacy-policy/): Who we are Our website address is: https://shubhamchaskar.com Comments When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment. Media If you upload images to... - [Sample Page](https://shubhamchaskar.com/sample-page-2/): This is an example page. It’s different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most people start with an About page that introduces them to potential site visitors. It might say something like this: Hi there! I’m a bike messenger by day, aspiring actor by night, and this is my website. I live in Los Angeles, have a great dog named Jack, and I like piña coladas. (And gettin’ caught in the rain.) …or something like this: The XYZ Doohickey Company was founded in 1971,... - [Faq](https://shubhamchaskar.com/faq/): What is the difference between a vulnerability scan and a penetration test? A vulnerability scan is an automated process that uses tools to detect common security weaknesses across your systems, applications, or networks. While it can quickly provide a list of potential issues, it often generates false positives and does not validate how these issues could actually be exploited. A penetration test, on the other hand, goes far beyond automated scanning. It involves skilled security professionals manually analyzing your environment, exploiting vulnerabilities, and chaining them together to demonstrate real-world attack scenarios. This helps you understand not just what vulnerabilities exist,... - [Contact](https://shubhamchaskar.com/contact/): CONTACT Let's talk? It's all about the humans behind a brand and those experiencing it, br we're right there. In the middle performance quick. Send Message Δ Our Email info@shubhamchaskar.com Address India Phone +1 504-899-8221+1 504-899-8287 - [Blog](https://shubhamchaskar.com/blog/) - [Portfolio Dark](https://shubhamchaskar.com/): Welcome Hi I’m Shubham PentesterRed TeamerExploit Crafter My Resume My Expertise What I Do Pentesting I perform in-depth penetration testing across applications, networks, and infrastructure, simulating attacker techniques to uncover security flaws before real threats exploit them. Red Teaming I execute adversary emulation to mimic advanced threat actors, testing not only technical defenses but also detection and response, delivering true resilience insights for organizations. Secure Code Review I analyze application source code line by line, identifying hidden security bugs, logic flaws, and insecure practices, ensuring software is secure, maintainable, and compliant. Recent Work Look at my portfolio and give me... - [Workbook](https://shubhamchaskar.com/workbook/): Internet is vast! Sometimes you can lose a good article, a tip, or even a small bypass. We have decided to collaborate and collect most of the content available on the internet and learn from them! The project started by ninad mathpati and I joined later to help and learn from the available resources. We are more than happy if you use the workbook for your learning. And you can always come back to us for any help! Press the button below to see how the infosec community is learning 🙂  This Workbook is maintained by the below contributors and... [comment]: # (Generated by Hostinger Tools Plugin)