<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TheXero</title><link>https://www.thexero.co.uk/</link><description>Recent content on TheXero</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 18 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.thexero.co.uk/index.xml" rel="self" type="application/rss+xml"/><item><title>Open Wi-Fi Got Encrypted. Here's Why Your Rogue AP Still Works.</title><link>https://www.thexero.co.uk/wifi/open-wi-fi-got-encrypted/</link><pubDate>Sat, 18 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/open-wi-fi-got-encrypted/</guid><description>So you&amp;rsquo;re sitting in your local café, laptop open, and you connect to the free Wi-Fi. No password. No fuss. Job done. But underneath that seamless experience, someone — maybe someone like you — could historically be passively sniffing every single unencrypted byte you&amp;rsquo;re sending over the air.</description></item><item><title>Wireless Adapter Recommendations for Pentesters in 2025</title><link>https://www.thexero.co.uk/wifi/wifiadapters2025/</link><pubDate>Sat, 13 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/wifiadapters2025/</guid><description>One of the most common questions I still receive is: &amp;ldquo;What WiFi adapter should I use for pentesting?&amp;rdquo; Over the last 13 years, I have tested a very wide range of adapters, the good, the bad and some ugly. In this post, I will walk through my 2025 recommendations, discuss the modes that matter for pentesting, and explain how to get your adapter operational under Kali Linux.</description></item><item><title>Hacking Hidden WiFi Networks</title><link>https://www.thexero.co.uk/wifi/hidden-wifi/</link><pubDate>Sat, 14 Jun 2025 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/hidden-wifi/</guid><description>Hidden SSIDs are one of those security measures that feel effective but provide almost no real protection against a determined attacker. Here&amp;rsquo;s why — and exactly how they&amp;rsquo;re defeated.
Why Hidden SSIDs Exist (and Why They Don&amp;rsquo;t Help) When a network administrator hides an SSID, the access point stops broadcasting its name in beacon frames.</description></item><item><title>Wireless Pivots: How Trusted Networks Become Invisible Threat Vectors</title><link>https://www.thexero.co.uk/wifi/wireless-pivots/</link><pubDate>Sat, 31 May 2025 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/wireless-pivots/</guid><description>Even the most secure wireless deployments — including EAP-TLS with client certificate validation — can become entry points when endpoints are exploited in less secure environments. Here&amp;rsquo;s how wireless pivots work, and why your mobile devices may be betraying you.</description></item><item><title>Cohort 1 Wrap-Up: Thank You and What's Next</title><link>https://www.thexero.co.uk/blog/cohort-1-wrapup/</link><pubDate>Thu, 24 Apr 2025 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/cohort-1-wrapup/</guid><description>We wrapped up Cohort 1 of the WiFi Attacks Specialist course last week and I wanted to take a moment to say thank you to everyone who joined.
Twelve participants came in with varying backgrounds — some were seasoned pentesters looking to sharpen their wireless skills, others were newer to the field but hungry to learn.</description></item><item><title>EAP-TLS Security: How Attackers Exploit Enterprise Wi-Fi Vulnerabilities</title><link>https://www.thexero.co.uk/wifi/breaking-eap-tls/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/breaking-eap-tls/</guid><description>TL;DR – EAP-TLS Wi-Fi Authentication in a Nutshell EAP-TLS provides strong mutual authentication using client/server digital certificates. The process includes a multi-step handshake to establish a secure session. Key vulnerabilities include username disclosure and weak certificate validation. Misconfigured devices are more often exploited than the network infrastructure.</description></item><item><title>The Evolution of Wi-Fi Security: From WEP to WPA3</title><link>https://www.thexero.co.uk/wifi/evolution-of-wifi-security-from-wep-to-wpa3/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/evolution-of-wifi-security-from-wep-to-wpa3/</guid><description>TL;DR – Evolution of Wi-Fi Security: WEP was the first Wi-Fi security protocol but was quickly broken due to weak encryption and IV reuse. WPA introduced TKIP and better key management but still relied on the insecure RC4 cipher. WPA2 replaced TKIP with AES (CCMP), vastly improving encryption strength—though WPA2-PSK remained vulnerable to offline attacks.</description></item><item><title>Understanding Authentication in Enterprise Wi-Fi (Part 1)</title><link>https://www.thexero.co.uk/wifi/enterprise-wi-fi-security/</link><pubDate>Sat, 10 Aug 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/enterprise-wi-fi-security/</guid><description>TL;DR – Enterprise Wi-Fi Authentication Explained Enterprise Wi-Fi networks rely on the Extensible Authentication Protocol (EAP) to manage secure client access. EAP acts as a flexible framework that supports various authentication methods:
EAP-TLS provides top-tier security using mutual certificate-based authentication but requires PKI.</description></item><item><title>802.11 Wi-Fi Explained: Control &amp; Data Frames (Wireless Packets Part 2)</title><link>https://www.thexero.co.uk/wifi/understanding-wireless-packets-part2/</link><pubDate>Mon, 22 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/understanding-wireless-packets-part2/</guid><description>TL;DR – Control and Data Frames in 802.11 Wi-Fi Control frames manage the coordination of transmissions (e.g., ACK, RTS/CTS, Block ACK), ensuring smooth traffic flow and collision avoidance.
Block ACK improves efficiency by acknowledging multiple frames at once, reducing overhead in high-throughput environments.</description></item><item><title>802.11 Wi-Fi Explained: MAC Frame Structure (Wireless Packets Part 1)</title><link>https://www.thexero.co.uk/wifi/wireless-packets-part1/</link><pubDate>Sat, 13 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/wireless-packets-part1/</guid><description>TL;DR – 802.11 MAC Frame Explained The MAC frame is the foundation of Wi-Fi communication, defining how data is transmitted across the wireless medium.
The Frame Control field defines type (Management, Control, Data, Extension), subtype, and critical flags like encryption (PMF), power-saving mode, and retries.</description></item><item><title>Understanding Protected Management Frames - Part 2</title><link>https://www.thexero.co.uk/wifi/understanding-pmf-part2/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/understanding-pmf-part2/</guid><description>Before diving into the main content, let&amp;rsquo;s quickly recap the essentials of Protected Management Frames (PMF).
What are Protected Management Frames (PMF)? Protected Management Frames (PMF) provide enhanced protection for various management frames in Wi-Fi networks, which are critical for the proper functioning of Wi-Fi communications.</description></item><item><title>Understanding Protected Management Frames</title><link>https://www.thexero.co.uk/wifi/understanding-pmf/</link><pubDate>Sun, 23 Jun 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/understanding-pmf/</guid><description>Understanding Protected Management Frames (PMF) in Wi-Fi Before delving into Protected Management Frames (PMF), it&amp;rsquo;s essential to understand what management frames are and their role in Wi-Fi communication.
What Are Management Frames? In Wi-Fi, management frames are crucial for establishing and maintaining wireless communication.</description></item><item><title>PMKIDHunter — Fast PMKID Capture Script</title><link>https://www.thexero.co.uk/tools/pmkidhunter/</link><pubDate>Sun, 10 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/pmkidhunter/</guid><description>A lightweight Python wrapper that automates the full PMKID capture-to-crack workflow using hcxdumptool and hashcat. No client required — just the target BSSID, your interface, and a wordlist.
Requirements 1 sudo apt install hcxdumptool hcxtools hashcat Usage 1 python3 pmkidhunter.py -i wlan0mon -b AA:BB:CC:DD:EE:FF -w /usr/share/wordlists/rockyou.</description></item><item><title>Building a Compact XOR Encoder for Shellcode: A Step-by-Step Assembly Guide</title><link>https://www.thexero.co.uk/blog/building-a-compact-xor-encoder/</link><pubDate>Thu, 12 Nov 2020 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/building-a-compact-xor-encoder/</guid><description>If you&amp;rsquo;ve been through the Worldmail exploit write-up or spent any time developing shellcode, you&amp;rsquo;ve run into bad characters. NULL bytes that kill your TCP connection. Characters that get mangled by string functions before they ever reach your buffer. Values that simply don&amp;rsquo;t survive the journey from your machine to the target.</description></item><item><title>Worldmail IMAP Exploit: Writing a Public SEH Buffer Overflow From Scratch</title><link>https://www.thexero.co.uk/exploit-development/worldmail-exploit/</link><pubDate>Sat, 09 May 2020 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/exploit-development/worldmail-exploit/</guid><description>If the stack-based buffer overflow is where exploit development starts, Structured Exception Handler overflows are where it gets more interesting. The primitive is similar — overflow a buffer, control execution — but the path from crash to shell is a few steps longer, and the constraints are tighter.</description></item><item><title>Abusing The Stack</title><link>https://www.thexero.co.uk/exploit-development/abusing-the-stack/</link><pubDate>Sun, 26 Apr 2020 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/exploit-development/abusing-the-stack/</guid><description>Stack-based buffer overflows are the foundational technique of Windows exploit development. If you&amp;rsquo;ve never written one, this is the right place to start. We&amp;rsquo;ll go from a crash all the way to popping a shell.
The Target For this walkthrough, we&amp;rsquo;re using a deliberately vulnerable Windows application.</description></item><item><title>Corelan Advanced Exploit Development Review: Is It Worth It?</title><link>https://www.thexero.co.uk/blog/corelan-advanced-exploit-development/</link><pubDate>Sat, 07 Dec 2019 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/corelan-advanced-exploit-development/</guid><description>People had warned me. &amp;ldquo;It&amp;rsquo;s 9am to 9pm,&amp;rdquo; they said. &amp;ldquo;You won&amp;rsquo;t sleep much.&amp;rdquo; They weren&amp;rsquo;t wrong.
Three days of Corelan Advanced Exploit Development in Sydney — one of the most well-regarded exploit development courses in the industry. If you&amp;rsquo;re considering it and wondering whether it&amp;rsquo;s worth the time, the money, and the sleep deprivation, here&amp;rsquo;s an honest breakdown of everything covered.</description></item><item><title>nullsploit: A Custom Python Exploitation Framework Built From Scratch</title><link>https://www.thexero.co.uk/tools/nullsploit-engine/</link><pubDate>Fri, 03 May 2019 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/nullsploit-engine/</guid><description>Metasploit is great. It&amp;rsquo;s also a black box that a lot of people use without ever thinking about what&amp;rsquo;s happening underneath.
nullsploit exists for the opposite reason — to build an exploitation framework from scratch, understand every moving part, and end up with something that&amp;rsquo;s genuinely useful for demonstrating the impact of unpatched vulnerabilities to clients who need to see it to believe it.</description></item><item><title>Penetration Testing in Social Housing: My Interview With Housing Technology Magazine</title><link>https://www.thexero.co.uk/blog/housing-technology-interview/</link><pubDate>Thu, 28 Sep 2017 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/housing-technology-interview/</guid><description>Housing providers hold a significant amount of sensitive personal data — tenant records, financial information, maintenance histories — and increasingly rely on digital systems to deliver critical services. Cybersecurity in this sector doesn&amp;rsquo;t always get the attention it deserves.
Housing Technology magazine asked me to share my thoughts on what housing providers should be considering when it comes to cybersecurity and data protection.</description></item><item><title>Advisory: LDAPS Service Heap Memory Corruption Vulnerability - Symantec Encryption Management Server &lt; 3.3.2 MP12</title><link>https://www.thexero.co.uk/advisories/sems-heap-memory-corruption/</link><pubDate>Tue, 07 Jun 2016 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/advisories/sems-heap-memory-corruption/</guid><description>Note: LDAPS Service Heap Memory Corruption vulnerability in SEMS &amp;lt;= 3.3.2 MP12 allowing for reads to from or writes to a memory location outside the buffer&amp;rsquo;s intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.</description></item><item><title>Advisory: Local Privilege Escalation - Symantec Encryption Management Server &lt; 3.3.2 MP12</title><link>https://www.thexero.co.uk/advisories/sems-privesc/</link><pubDate>Tue, 07 Jun 2016 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/advisories/sems-privesc/</guid><description>Note: Local Privilege Escalation vulnerability in SEMS &amp;lt;= 3.3.2 MP12 allowing for escalations of privileges to that of the root superuser.
Summary The tomcat users on an affected Symantec Encryption Management Server (SEMS) is susceptible to privilege escalation vulnerability resulting an gaining root privileges.</description></item><item><title>Advisory: OS Command Injection in Symantec Encryption Management Server &lt; 3.3.2 MP12</title><link>https://www.thexero.co.uk/advisories/sems-command-exec/</link><pubDate>Tue, 07 Jun 2016 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/advisories/sems-command-exec/</guid><description>Note: OS Command Injection vulnerability allows command execution on the underlying operating system.
Summary The management console for Symantec Encryption Management Server (SEMS) is susceptible to potential OS command execution vulnerability.
Affected Versions Symantec Encryption Management Server &amp;lt;= 3.3.2 MP11 CVSSv3 Score 9.</description></item><item><title>ConScan v1.2: Username Disclosure and Brute-Force Added to Concrete5 Scanner</title><link>https://www.thexero.co.uk/blog/conscan-updated/</link><pubDate>Sat, 07 Jun 2014 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/conscan-updated/</guid><description>ConScan has been updated. If you&amp;rsquo;ve been using the Concrete5 black-box scanner since its initial release last October, version 1.2 adds two features that meaningfully expand what the tool can do against a target.
What&amp;rsquo;s new in v1.2
Username disclosure — ConScan can now enumerate valid usernames on a target Concrete5 installation.</description></item><item><title>ConScan v1.2: Username Disclosure and Brute-Force Added to Concrete5 Scanner</title><link>https://www.thexero.co.uk/tools/conscan-updated/</link><pubDate>Sat, 07 Jun 2014 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/conscan-updated/</guid><description>ConScan has been updated. If you&amp;rsquo;ve been using the Concrete5 black-box scanner since its initial release last October, version 1.2 adds two features that meaningfully expand what the tool can do against a target.
What&amp;rsquo;s new in v1.2
Username disclosure — ConScan can now enumerate valid usernames on a target Concrete5 installation.</description></item><item><title>Teaching Exploit Development at BSides London 2014: What I Learned From My First Workshop</title><link>https://www.thexero.co.uk/blog/bsides-london-exploit-development/</link><pubDate>Sun, 04 May 2014 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/bsides-london-exploit-development/</guid><description>BSides London 2014 was a milestone for me. Not because of the conference itself — though it was great — but because it was the first time I&amp;rsquo;d stood in front of a room full of people I&amp;rsquo;d never met and tried to teach them something I genuinely cared about.</description></item><item><title>ConScan: A Black-Box Vulnerability Scanner for Concrete5 CMS</title><link>https://www.thexero.co.uk/tools/concrete5-cms-vulnerability-scanner/</link><pubDate>Sat, 26 Oct 2013 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/concrete5-cms-vulnerability-scanner/</guid><description>Web application pentests almost always involve a CMS. WordPress, Drupal, Joomla — the big names have decent tooling. But spend enough time in this space and you&amp;rsquo;ll run into less common platforms that don&amp;rsquo;t have the same coverage. When you do, you&amp;rsquo;re either doing everything manually or building something yourself.</description></item><item><title>Security Advisory: Stored XSS in DEXs PM System WordPress Plugin v1.0.1</title><link>https://www.thexero.co.uk/advisories/dexs-pm-system-vulnerability/</link><pubDate>Mon, 14 Oct 2013 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/advisories/dexs-pm-system-vulnerability/</guid><description>Note: Stored XSS vulnerability in the DEXs PM System WordPress plugin v1.0.1 allows attackers to inject malicious JavaScript via the message subject field with potential for full WordPress admin compromise.
Summary WordPress plugin vulnerabilities are one of those areas where a bit of curiosity during downtime can turn into a real finding.</description></item><item><title>SSL Private Key Password Cracker: A Tool Born From a Real Engagement</title><link>https://www.thexero.co.uk/tools/ssl-private-key-password-cracker/</link><pubDate>Sat, 31 Aug 2013 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/ssl-private-key-password-cracker/</guid><description>Real pentesting doesn&amp;rsquo;t always look like the tutorials. Sometimes you&amp;rsquo;re mid-engagement, digging through an exposed directory, and you find something that makes you stop and think: that really shouldn&amp;rsquo;t be here.
That&amp;rsquo;s exactly what happened here.
The scenario
During a client engagement, an undisclosed directory was discovered on an HTTP server — the kind of thing that only shows up if you&amp;rsquo;re thorough with your enumeration.</description></item><item><title>HTTP Enum: Automated HTTP Enumeration and Web Server Fingerprinting Tool</title><link>https://www.thexero.co.uk/tools/http-enum/</link><pubDate>Mon, 15 Apr 2013 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/http-enum/</guid><description>Web server enumeration is one of those tasks that every pentester does, but almost nobody enjoys doing manually. Checking HTTP methods, looking for enabled WebDAV, hunting for server-status pages, poking at FrontPage Extensions — it&amp;rsquo;s repetitive, time-consuming, and easy to miss something when you&amp;rsquo;re doing it by hand across multiple targets.</description></item><item><title>Bypassing ASLR: Techniques for Exploit Developers Who've Hit the Wall</title><link>https://www.thexero.co.uk/blog/bypass-aslr/</link><pubDate>Sun, 15 Apr 2012 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/blog/bypass-aslr/</guid><description>So you&amp;rsquo;ve worked through the stack overflow. You&amp;rsquo;ve got EIP control. You&amp;rsquo;ve confirmed your shellcode executes cleanly in the lab. Then you take that exploit and point it at something compiled with modern protections — and it falls apart.
Welcome to ASLR.</description></item><item><title>TFTP Fuzzer: Finding Vulnerabilities in UDP-Based Protocols with Python</title><link>https://www.thexero.co.uk/tools/tftp-fuzzer/</link><pubDate>Sun, 25 Mar 2012 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/tftp-fuzzer/</guid><description>Most people learning pentesting focus on TCP. Makes sense — HTTP, FTP, SMB, that&amp;rsquo;s where a lot of the action is. But UDP protocols are a different beast, and they&amp;rsquo;re often overlooked. That&amp;rsquo;s exactly why they&amp;rsquo;re interesting.
What is TFTP and why should you care?</description></item><item><title>FTP Fuzzer: How I Found Real Bugs in FTP Servers with This Python Tool</title><link>https://www.thexero.co.uk/tools/ftp-fuzzer/</link><pubDate>Fri, 27 Jan 2012 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/tools/ftp-fuzzer/</guid><description>If you want to find vulnerabilities in software, fuzzing is one of your best friends.
The idea is simple: you throw a massive amount of unexpected, malformed, or just plain weird input at an application and watch what breaks. No source code required.</description></item><item><title>WiFi Episode 5: How to Uncover Hidden WiFi Networks and Crack WEP</title><link>https://www.thexero.co.uk/wifi/episode-5/</link><pubDate>Sun, 14 Nov 2010 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/episode-5/</guid><description>Hidden SSIDs come up constantly in conversations about WiFi security. The idea is straightforward: if your network isn&amp;rsquo;t broadcasting its name, attackers can&amp;rsquo;t find it. Problem solved.
Except it isn&amp;rsquo;t. Not even close.
A hidden SSID is what&amp;rsquo;s sometimes called security through obscurity — the belief that concealment is a substitute for actual security controls.</description></item><item><title>WiFi Episode 4: WEP ARP Amplification — Cracking WEP Faster</title><link>https://www.thexero.co.uk/wifi/episode-4/</link><pubDate>Fri, 29 Oct 2010 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/episode-4/</guid><description>If you&amp;rsquo;ve worked through Episode 2 and Episode 3, you can already crack WEP. The question this episode answers is: how do you do it faster?
IV generation rate is the bottleneck in every WEP attack. You need enough IVs for aircrack-ng to do its thing, and how quickly you collect them depends entirely on how much traffic you can force the AP to generate.</description></item><item><title>WiFi Episode 3: How to Bypass WEP Shared Key Authentication</title><link>https://www.thexero.co.uk/wifi/episode-3/</link><pubDate>Sun, 19 Sep 2010 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/episode-3/</guid><description>If you&amp;rsquo;ve watched Episode 2, you know how to crack a WEP network using the clientless ARP replay attack. Good. Now let&amp;rsquo;s talk about what happens when you run into a WEP network that doesn&amp;rsquo;t behave the same way.
WEP networks can be configured with one of two authentication methods: Open Authentication or Shared Key Authentication (SKA).</description></item><item><title>WiFi Episode 2: How to Crack WEP Encryption (Including Clientless Networks)</title><link>https://www.thexero.co.uk/wifi/episode-2/</link><pubDate>Fri, 10 Sep 2010 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/episode-2/</guid><description>WEP is dead. Has been for years. The cryptography is fundamentally broken — not &amp;ldquo;weak with a long enough password&amp;rdquo; broken, but mathematically impossible to secure broken. No configuration, no complexity, no passphrase length fixes it.
And yet. It still shows up.</description></item><item><title>WiFi Episode 1: How to Hack WPA and WPA2 Personal Networks (The Basics)</title><link>https://www.thexero.co.uk/wifi/episode-1/</link><pubDate>Sun, 29 Aug 2010 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/wifi/episode-1/</guid><description>Every wireless pentester has to start somewhere. This is that somewhere.
Before you worry about WPA3, enterprise attacks, rogue APs, or EAP-TLS — you need to genuinely understand why WPA2 Personal is fundamentally broken by design. Not just that it can be cracked.</description></item><item><title>About</title><link>https://www.thexero.co.uk/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.thexero.co.uk/about/</guid><description>About Toby Reynolds I&amp;rsquo;m a penetration tester. I develop exploits. I&amp;rsquo;m a wireless security expert and trainer. I have more than ten years of hands-on research experience. I&amp;rsquo;ve spent years studying protocols. I’ve also explored binaries and wireless stacks. This site is where I share what I&amp;rsquo;ve learned.</description></item></channel></rss>