<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cybertuz</title><link>https://cybertuz.com/</link><description>Recent content on Cybertuz</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 27 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybertuz.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Privacy &amp; Cookie Policy</title><link>https://cybertuz.com/privacy-policy/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>https://cybertuz.com/privacy-policy/</guid><description>&lt;p&gt;&lt;em&gt;Last updated: 27 September 2026&lt;/em&gt;&lt;/p&gt;&#10;&lt;p&gt;This page explains what personal data this blog processes, why, and what rights&#10;you have under the EU General Data Protection Regulation (GDPR) and the Italian&#10;privacy law (D.Lgs. 196/2003).&lt;/p&gt;&#10;&lt;h2 id="data-controller"&gt;Data controller &lt;a class="anchor" href="#data-controller" aria-label="link"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;The data controller is the author of this blog, &lt;strong&gt;Cybertuz&lt;/strong&gt;.&#10;Contact: &lt;a href="mailto:adrian@cybertuz.com"&gt;adrian@cybertuz.com&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>About</title><link>https://cybertuz.com/about/</link><pubDate>Sun, 03 Dec 2023 16:56:02 +0000</pubDate><guid>https://cybertuz.com/about/</guid><description>&lt;h2 id="welcome-to-cybertuz-blog"&gt;Welcome to Cybertuz blog! &lt;a class="anchor" href="#welcome-to-cybertuz-blog" aria-label="link"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Hi! I’m Cybertuz, a passionate cybersecurity expert dedicated to uncovering and understanding the complexities of technology and digital security. Through this blog, I share my latest findings on new vulnerabilities, insightful research, and the ever-evolving landscape of cybersecurity.&lt;/p&gt;</description></item><item><title>Contact</title><link>https://cybertuz.com/contact/</link><pubDate>Sun, 03 Dec 2023 16:56:02 +0000</pubDate><guid>https://cybertuz.com/contact/</guid><description>&lt;div class="code-block"&gt;&#10; &lt;div class="code-head"&gt;&lt;span class="lang"&gt;console&lt;/span&gt;&lt;button class="copy" type="button" data-label="copy" data-done="copied!"&gt;copy&lt;/button&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-console" data-lang="console"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="gp"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="nv"&gt;$CONTACT&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="go"&gt;adrian@cybertuz.com&#10;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Want to report something, discuss a vulnerability or collaborate on some research?&#10;Write me at &lt;a href="mailto:adrian@cybertuz.com"&gt;adrian@cybertuz.com&lt;/a&gt;: I&amp;rsquo;ll try to reply as soon as possible.&lt;/p&gt;</description></item><item><title>Unlock SSH access on Bobcat Miner 300</title><link>https://cybertuz.com/unlock-ssh-access-on-bobcat-miner-300/</link><pubDate>Sat, 04 Jun 2022 16:18:00 +0000</pubDate><guid>https://cybertuz.com/unlock-ssh-access-on-bobcat-miner-300/</guid><description>&lt;h2 id="introduction"&gt;Introduction &lt;a class="anchor" href="#introduction" aria-label="link"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt; unfortunately, the bobcat company have patched the &amp;ldquo;exploit&amp;rdquo; described in this article. Also, they patched mine remotely and I have no more access. But before that I have done a copy of all the O.S. file of the device, so I was able to the try to crack the root password. I have tried whit haschat whit a big Wordlist, I did not succeed, probably it is a Chinese word.. I  will make some more study on this device, and a new blog post in the future, or maybe I will just publicly release all the file that I extracted from the device.&lt;/p&gt;</description></item><item><title>CRLF Injection - Sercomm VD625 CVE-2021-27132</title><link>https://cybertuz.com/crlf-injection-sercomm-vd625-cve-2021-27132/</link><pubDate>Thu, 25 Feb 2021 16:09:00 +0000</pubDate><guid>https://cybertuz.com/crlf-injection-sercomm-vd625-cve-2021-27132/</guid><description>&lt;p&gt;An issue was discovered in &lt;strong&gt;Sercomm AGCOMBO VD625-Smart Modem&lt;/strong&gt; - Firmware version: &lt;strong&gt;AGSOT_2.1.0&lt;/strong&gt;, there is a &lt;strong&gt;CRLF Injection&lt;/strong&gt; vulnerability via the header field &amp;ldquo;&lt;strong&gt;Content-Disposition&lt;/strong&gt;&amp;rdquo;.&lt;/p&gt;&#10;&lt;p&gt;The Sercomm AGCOMBO VD625-Smart Modem is a &lt;strong&gt;CPE&lt;/strong&gt; (Customer-premises equipment) made by Sercomm for the various &lt;strong&gt;ISPs&lt;/strong&gt; (Internet service providers). The device in which the vulnerability was found is the one for &lt;strong&gt;TIM&lt;/strong&gt; (Telecom Italia).&lt;/p&gt;</description></item></channel></rss>