Find the latest Webinar content from the Sprocket Testing Team.
Resources Blog

Juan Pablo Gomez Postigo

Blogs by Juan Pablo Gomez Postigo
Tenant Enumeration is Dead

Tenant Enumeration is Dead

Microsoft has fully patched the ACS metadata endpoint that powered tenant domain enumeration. Learn what the original technique was, why it's gone, and how azmap.dev now combines DKIM lookups, MX brute-force, and Graph API to still surface tenant names and related domains.
Please Show Your Work: Bypassing JavaScript Proof-of-Work CAPTCHAs

Please Show Your Work: Bypassing JavaScript Proof-of-Work CAPTCHAs

Understanding how SiteGround’s proof-of-work CAPTCHA silently disrupts automated WordPress security scans and how to work around it.
Tenant Enumeration is Back

Tenant Enumeration is Back

Microsoft's soft patch didn't kill tenant enumeration. Attackers have new ways to map cloud infrastructure. Learn how modern Azure and Microsoft 365 enumeration techniques work, why they're back, and what defenders should do next.
Lost in Transliteration: Hidden Passwords in a Multilingual World

Lost in Transliteration: Hidden Passwords in a Multilingual World

Sprocket Security Senior Penetration Tester examines how transliteration and language backgrounds shape password creation, adding complexity for both users and attackers in his 2025 CypherCon talk.
I Love Lucee: Building Lucee Extensions for Remote Code Execution

I Love Lucee: Building Lucee Extensions for Remote Code Execution

During the past few assessments, Sprocket has encountered improperly configured instances of Lucee 5 and 4. This blog post will detail a straightforward method to execute remote code after acquiring administrative access to a Lucee login panel.
Discovering wp-admin.php URLs in Wordpress With GravityForms

Discovering wp-admin.php URLs in Wordpress With GravityForms

By targeting a specific endpoint and passing in a random string, GravityForms will prompt users to authenticate first. This results in the unauthenticated user being redirected to the obscured administrative login page for /wp-admin.