GeistHaus
log in · sign up

https://alexbilz.com/index.xml

rss
25 posts
Polling state
Status active
Last polled May 19, 2026 05:20 UTC
Next poll May 20, 2026 04:03 UTC
Poll interval 86400s
ETag "7574d8b5b433a9cdf12a88432542438e-ssl-df"

Posts

Legal Disclosure

Information in accordance with Section 5 TMG:

Alexander Bilz

Christoph von Schmid Str. 18

https://www.alexbilz.com/legal/
Compliance as Code: Auditing Large-Scale GCP Environments with InSpec/CINC
Auditing Google Cloud Platform (GCP) environments at scale presents unique challenges for security teams. This comprehensive guide introduces InSpec as the definitive solution for automated, continuous compliance. Get instant access to the open-source InSpec profile I maintain, and implement a streamlined, infrastructure-as-code approach to GCP governance and security validation.
https://www.alexbilz.com/post/2025-11-18-auditing-gcp-with-inspec/
About
about Alexander Bilz
https://www.alexbilz.com/about/
Harvesting Passwords From Cisco Configs Posted on Online Community Forums
An article about why sharing your Cisco running config file on public support forums may be dangerous. It starts with a general introduction to secrets found in running configs, highlights the process of harvesting configs using metagoofil and decrypting the password hashes.
https://www.alexbilz.com/post/2024-05-30-harvesting-passwords-from-cisco-configs/
Enumerating SMB Shares With smbscan: A hands-on guide
A wee writeup about the SMB enumeration tool smbscan, which I had recently discovered on GitHub. The post introduces SMB, highlights the functionality of smbscan, and provides practical insights for uncovering hidden shares, finding sensitive files and auditing permissions.
https://www.alexbilz.com/post/2023-09-03-introduction-to-smbscan/
Who's watching you? Security Analysis of the LSC 1080P IP Camera from Action
A wee writeup of a security analysis of an LSC 1080P IP Camera sold by Action. The posts summarise multiple vulnerabilities we could identify including weak encryption of passwords, lack of authentication and inappropriate hardware hardening.
https://www.alexbilz.com/post/2023-01-06-action-lsc-1080/
SQL Injection Vulnerability in ChurchCRM (CVE-2021-41965)
A wee writeup of an SQL injection vulnerability I had found within the open-source ChurchCRM CRM software. This vulnerability allows logged-in users to completely compromise the database.
https://www.alexbilz.com/post/2022-05-14-cve-2021-41965/
Cracking NTLM Hashes on Google Cloud's Nvidia Tesla T4 GPU
In this post I will explain how I used a Nvidia Tesla T4 GPU rented from Google Cloud Platform to crack NTLM hashes using hashcat and John the Ripper at blazing speeds.
https://www.alexbilz.com/post/google-cloud-password-cracking/
Russian Railway (РЖД) API Documentation
In this post I will present an API Documentation of the РЖД I had documented over at Postmans documenter and give an example how Python can be used to query data about Russian Railways.
https://www.alexbilz.com/post/rzd-api-documentation/
Unofficial Abertay University Latex Templates
An introduction to a set of LaTeX templates I had created as part of my graduate course at Abertay University.
https://www.alexbilz.com/post/2021-01-13-abertay-latex-templates/
Yet Another Aviation Database!?
In this post, I will talk about the pros and cons of data available by openflights.org and present an travelhackingtool.com
https://www.alexbilz.com/post/yet-another-aviation-database/
Installing PostGIS on Uberspace 7
In this tutorial I will show you how those can a PostGIS stack on Uberspace.
https://www.alexbilz.com/post/2020-08-18-install-postgis-on-uberspace/
Repairing a Canon Scanfront 220p with a disk boot failure

I recently got myself a Canon ScanFront 220p Scanner to empower my efforts to quickly digitalize a huge amount of documents, which I’d carefully accumulated through the past couple of years. While my scanner, which I got for 42 € of eBay Kleinanzeigen was from a technical point in great conditions, I know it had one “minor” software issue: It wouldn’t boot.

https://www.alexbilz.com/post/2020-06-01-repair_canon_scanfront_220p/
Finding multi-stop flights using Neo4j & Python 🐍 Part #2

In this blog-post, I’d like to give you a first introduction on how we can search for flights using Python and the Kiwi API. Excited? Let’s get started💻🖱️.

https://www.alexbilz.com/post/2018-05-04-finding-multi-stop-flights-using-neo4j-python-f09f908d-part-2/
Finding multi-stop flights using Neo4j & Python 🐍 Part #1

As you’d probably figured out by now, traveling is a big passion of Markus and mine. However, as students, our travel budget has some serious constraints.

https://www.alexbilz.com/post/2018-05-01-finding-multi-stop-flights-using-neo4j-python-f09f908d-part-1/