We care about
your security.

Nethemba is a leading Slovak IT security firm especialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.

We care about
your security.

Nethemba is a leading Slovak IT security firm especialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.

BLOG

Discovery of CVE-2022-24833

When on a security audit for a client it was discovered that a key component – the open-source private paste service PrivateBin contained a previously undocumented flaw. Cross-site-scripting is nothing new. I actually feel there must be prehistoric cave paintings and markings somewhere in the world containing some variation of <script>alert(1)</script>. Although XSS payloads embedded […]

Read More

Facebook

Nethemba
Nethemba5 days ago
A Flagship Smartphone With Kill Switches? Meet the Murena-Powered HIROH Phone

A premium smartphone running de-Googled /e/OS, complete with hardware kill switches.
Nethemba
Nethemba6 days ago
#43 ColddBox (Try Hack Me) (Easy) (30-Minute Challenge)

Finally we have a challenge box - thanks to Rick for this one. The goal is to root this 70 minute box in only 30.
My attempt at ColddBox on THM which is rated 'Easy'.

Nethemba
#43 ColddBox (Try Hack Me) (Easy) (30-Minute Challenge)
Finally we have a challenge box - thanks to Rick for this one. The goal is to root this 70 minute box in only 30.My attempt at ColddBox on THM which is rated...
Nethemba
Nethemba1 week ago
#41 Racetrack Bank (Try Hack Me) (Hard) Join The Race...

A great race condition here which we exploit with Burpsuite Intruder. We then dive into a Node.js RCE and finish with a cronjob hijack.

Nethemba
#41 Racetrack Bank (Try Hack Me) (Hard) Join The Race...
A great race condition here which we exploit with Burpsuite Intruder. We then dive into a Node.js RCE and finish with a cronjob hijack. My attempt at Racetra...