Cybersecurity-Projects/PROJECTS/beginner
CarterPerez-dev fd54dfcc4a docs(marshalsea): M8 - the learn folder, opening on the breach that was not one
Five documents per repository convention.

01-CONCEPTS.md opens with the Equifax debunk, because leading with a correction
is the strongest available demonstration that this repo checks its claims.
CVE-2017-5638 is OGNL expression injection, NVD CWE-755, CISA KEV CWE-20. Four
primary sources opened and text-searched (GAO-18-559, House Oversight, Equifax's
own release, the DOJ indictment) and "deserialization" appears in none of them.
The ASF published the correction 2017-09-14 and it lost to a three-day timing
coincidence with CVE-2017-9805. The twelve-item wrong-claims table closes the
chapter.

Honest impact numbers only: 69 of 1,653 CISA KEV entries are CWE-502, seventh
most common, 34.8% with known ransomware use against a 20.1% baseline. No
aggregate dollar figure, because none is credible.

Every transcript in the track was produced by execution, not recall. That
included discovering that ERB#def_method does not prepend its wrapper, it
inserts before the first non-comment line, so the payload's leading "#" is
forging the magic encoding comment a real compiled template carries. The first
draft described the wrapping wrong and the container corrected it.

README: the scanner figures were pre-taxonomy-fix and stale. Re-measured on
ruby:4.0-slim today: 124 ungated to 28 reachable, 142 unanalysable, not
119/29/135. Test and gate counts moved to 268 and 79, both measured rather
than carried forward.
2026-07-31 19:56:22 -04:00
..
base64-tool Update DEMO.md 2026-04-28 18:01:21 -04:00
c2-beacon chore(deps): bump starlette in /PROJECTS/beginner/c2-beacon/backend 2026-06-04 17:25:29 +00:00
caesar-cipher chore: add demos for projects, update haskell-reverse-proxy modules, refresh siem assets 2026-04-26 23:12:48 -04:00
canary-token-generator style(canary): format config_test.go with golines (max-len 80) 2026-07-19 03:18:17 -04:00
deserialization-gadget-lab docs(marshalsea): M8 - the learn folder, opening on the breach that was not one 2026-07-31 19:56:22 -04:00
dns-lookup chore: add demos for projects, update haskell-reverse-proxy modules, refresh siem assets 2026-04-26 23:12:48 -04:00
firewall-rule-engine feat: sbom generator & vulnerability matcher + docstrings across 6 projects 2026-04-08 23:53:40 -04:00
hash-cracker cracked 2026-05-23 05:01:01 -04:00
keylogger Update README.md 2026-06-02 09:16:11 -04:00
linux-cis-hardening-auditor cracked 2026-05-23 05:01:01 -04:00
linux-ebpf-security-tracer add: AGPL 3.0 license files to hash-cracker, ebpf tracer, dlp scanner 2026-04-11 05:56:43 -04:00
metadata-scrubber-tool chore(deps): bump pypdf in /PROJECTS/beginner/metadata-scrubber-tool 2026-07-26 10:56:50 +00:00
network-traffic-analyzer ci(network-traffic-analyzer): drop ruff preview to keep lint green across versions 2026-07-19 03:18:03 -04:00
simple-port-scanner cracked 2026-05-23 05:01:01 -04:00
simple-vulnerability-scanner Delete PROJECTS/beginner/simple-vulnerability-scanner/hf_readme.gif 2026-07-19 23:26:24 -04:00
steganography-multi-tool docs(crypha): add learn/ track and surface the built project (M9) 2026-07-19 03:06:49 -04:00
systemd-persistence-scanner chore: add demos for projects, update haskell-reverse-proxy modules, refresh siem assets 2026-04-26 23:12:48 -04:00