Find the latest Webinar content from the Sprocket Testing Team.
Resources Blog

Juan Pablo Gomez Postigo

Blogs by Juan Pablo Gomez Postigo
Tenant Enumeration is Back
Dec 10, 2025

Tenant Enumeration is Back

Microsoft's soft patch didn't kill tenant enumeration. Attackers have new ways to map cloud infrastructure. Learn how modern Azure and Microsoft 365 enumeration techniques work, why they're back, and what defenders should do next.
Lost in Transliteration: Hidden Passwords in a Multilingual World
Sep 04, 2025

Lost in Transliteration: Hidden Passwords in a Multilingual World

Sprocket Security Senior Penetration Tester examines how transliteration and language backgrounds shape password creation, adding complexity for both users and attackers in his 2025 CypherCon talk.
I Love Lucee: Building Lucee Extensions for Remote Code Execution
Mar 15, 2024

I Love Lucee: Building Lucee Extensions for Remote Code Execution

During the past few assessments, Sprocket has encountered improperly configured instances of Lucee 5 and 4. This blog post will detail a straightforward method to execute remote code after acquiring administrative access to a Lucee login panel.
Discovering wp-admin.php URLs in Wordpress With GravityForms
Apr 05, 2023

Discovering wp-admin.php URLs in Wordpress With GravityForms

By targeting a specific endpoint and passing in a random string, GravityForms will prompt users to authenticate first. This results in the unauthenticated user being redirected to the obscured administrative login page for /wp-admin.