DARINORCold Lab

// Writing

The Best Exploits Are Boring

By
2 min read
Offensive security#offensive-security#red-teaming

Every writeup that gets shared around is a novel zero-day in a parser nobody's heard of. Every real engagement I've run ends the same way: a reused credential, an over-permissioned service account, and a route nobody thought to close. None of it is exciting. All of it works.

The primitives that keep showing up

  • Credentials reused across "isolated" environments that share a directory service somewhere upstream.
  • Service accounts scoped for convenience during setup and never revisited.
  • Internal endpoints exposed because a load balancer rule was copy-pasted from a public-facing one.
  • Trust boundaries that exist on a diagram but not in an ACL.

Individually, none of these are a finding worth a CVE. Chained, they're a full compromise. And each link in the chain leaves evidence you can read without any scanner: a pinned certificate that expired, a cert issued by an internal CA nobody recognizes, a fingerprint that doesn't match the one in the runbook. The X.509 Certificate Decoder dumps a PEM cert's subject, issuer, SANs, and fingerprints in your browser — paste the chain from the load balancer nobody re-checked and read exactly what it trusts.

Why this matters more than the zero-day narrative

If your threat model is "sophisticated novel exploit," you'll spend your budget on the wrong things — bug bounty triage for exotic memory corruption, while the actual path in is a jump box with a shared password from 2019.

The craft in offensive security isn't finding the impossible bug. It's noticing that three unremarkable, individually-accepted risks compose into one that isn't. Defense has to think the same way: audit the chain, not just the links.

The attacker doesn't need a zero-day. They need you to have stopped looking at the boring stuff.