Posts

Showing posts from June, 2025

MikroTik Bridge VLAN Filtering – Full Setup Tutorial for Secure Your Network

  MikroTik Bridge VLAN Filtering – Full Explanation with Configuration Bridge VLAN Filtering in MikroTik is essential when you're managing VLANs (Virtual LANs) using hardware offloading for high performance (using a bridge instead of a router). It's the modern and efficient method for VLAN management in RouterOS 6.41+ and RouterOS v7 . 🔐 What is Bridge VLAN Filtering? Bridge VLAN filtering allows you to isolate or segment traffic on different VLANs through one bridge interface , applying VLAN rules per-port efficiently. 🧱 Key Concepts for VLAN Filtering: Bridge: Logical switch combining multiple interfaces. VLAN: Virtual separation of Layer 2 domains. PVID (Port VLAN ID): Used for untagged incoming traffic. Tagged: Traffic with VLAN ID. Untagged: Plain Ethernet traffic. ✅ Example Scenario for the Mikrotik Configuration.  If We have: ether1 as uplink to trunk (to switch or another router) ether2 for VLAN 10 ether3 for VLAN 20 ?...

Apache Tomcat Upload Exploitation (Step-by-Step Guide)

Image
  Apache Tomcat Upload Exploitation (Step-by-Step Guide) 🎥 Watch the demonstration here : https://youtu.be/P8nlsRdKzT8 If you’re diving into web exploitation or pentesting Apache Tomcat servers, upload-based exploitation is one of the key techniques to understand. This method targets weak configurations where Tomcat allows file uploads (such as WAR files) that can be executed on the server—leading to Remote Code Execution (RCE) . In this blog post, we’ll walk through Apache Tomcat Upload Exploitation with clear steps and explanations. Whether you're learning ethical hacking or creating educational content, this walkthrough is a practical hands-on example. 🔧 Requirements Kali Linux or any attacker machine Apache Tomcat server (target) Valid Tomcat credentials (default or stolen) Metasploit (optional, but useful) ✅ Step 1: Access the Tomcat Manager Panel Tomcat’s web interface usually runs on: http://<target-ip>:8180/manager/html If credentials are know...