#pentest

2026-02-05
I sat through way too many #pentest interviews where the candidates had no clue about the fundamentals of web security, like the Same-Origin Policy.

If you want to make a career of finding flaws in (web)apps, do yourself a favor and read @b0rk's HTTP zine:

https://wizardzines.com/comics/same-origin-policy/
2026-02-04

VulNyx Misconfigured Writeup

A Step-by-Step Walkthrough of Enumerating AD Services and Gaining Administrator Access on the Misconfigured Machine
thecybercraft.medium.com/vulny

#writeup #ctf #infosec #cybersecurity #pentest #vm

VulNyx Misconfigured Writeup
PH4NTXM PROJECTPH4NTXMPROJECT
2026-02-04

@nullcoreproject has some goodies coming for all of us, co-developed by PH4NTXM.

A project focused on security, privacy, and adversarial-resilient systems.

Details soon. A free version will be available soon for everyone to test, audit, and experiment with.

👀 Stay tuned, the news will be exciting!

Who Let The Dogs Out 🐾ashed@mastodon.ml
2026-02-02

Сканер для обнаружения уязвимостей (NTLM relay)

#infosec #software #git #ad #pentest #relay

github.com/depthsecurity/Relay

* Сканирует по SMB, LDAP/S, MSSQL, HTTP/S, RPC, WinRM;
* Находит WebDAV WebClient, CVE-2025-33073 (NTLM reflection), NTLMv1 + PrinterBug, PetitPotam и т.п.;
* Поддерживает аудит всего домена;
* Составляет список таргетов для `ntlmrelayx` и другого ПО;
* Сохраняет отчет в plaintext/JSON/CSV/Markdown.

Статья в блоге: depthsecurity.com/blog/introdu

2026-02-01

Et si 2026 sonnait la mort du pentest ? Ça m'embêterait parce que c'est mon métier...

Depuis le début de l'année, je me suis penché sur son avenir. Entre les outils IA qui promettent des pentests automatisés, l'inquiétude pour les juniors qui arrivent sur le marché, et les outils qui vont potentiellement me faciliter la vie, j'ai posé mes réflexions dans un article.

Spoiler : le pentest n'est pas mort. Mais il va changer.

y0no.fr/posts/le-pentest-est-i

#infosec #pentest #llm

2026-02-01

🔎 Một kỹ sư backend muốn thực hành phân tích bảo mật ứng dụng (web/mobile) miễn phí! 🎯 Cần 2‑3 dự án có môi trường test, không phải production. Ưu tiên phương pháp black‑box, cung cấp báo cáo rủi ro chi tiết, sau đó xoá mọi dữ liệu. DM nếu quan tâm! #cybersecurity #pentest #securitytesting #bảo_mật #kiểm_thử #ứng_dụng

reddit.com/r/SaaS/comments/1qt

2026-01-31

Как я создал свой сканер и пришёл к выплатам на багбаунти

Привет, Хабр! Сегодня хочу поделиться историей о том, как желание автоматизировать рутинную работу привело меня к созданию собственного инструмента FullMute и, как следствие, к первым серьезным выплатам на платформах bug bounty. Как многие начинающие исследователи, я начал с хаотичного ручного поиска уязвимостей: проверял заголовки, искал известные пути к админкам, пытался угадать версии CMS. Это было неэффективно, медленно и сильно зависело от везения. Мне нужен был «компас», который бы проводил первоначальную разведку за меня и давал четкие цели для атаки. Так родилась идея FullMute.

habr.com/ru/articles/991392/

#pentest #scanner #python #bugbounty

2026-01-31

📢 Affaire Coalfire: 600 000 $ pour deux pentesters arrêtés à tort en Iowa
📝 Selon Ars Technica (Dan Goodin), Dallas County (Iowa) a accepté, cinq jours avant l’ouverture d’un procès, de verse...
📖 cyberveille : cyberveille.ch/posts/2026-01-3
🌐 source : arstechnica.com/security/2026/
#Iowa #pentest #Cyberveille

Stefano Marinellistefano@bsd.cafe
2026-01-30

RE: mastodon.bsd.cafe/@stefano/115

Luckily, many of my clients are intelligent and well-prepared people. Needless to say, that email, before making me laugh, had already made the client laugh. He immediately thought he was dealing with people who were great at marketing but had little technical skill.
I presented my theory on software engineering, but he immediately tore it apart, declaring himself extremely skeptical. In his opinion, it is more likely to be a technique to lower our defenses and then try to sell us "security products" after a "pentest full of flaws". Or simply sheer incompetence.

Anyway, their connection hasn't any open ports. So they can pentest anything they want to, as long as they want to.

#IT #SysAdmin #HorrorStories #PenTest

2026-01-30

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint List and exfiltrate files using Google Drive or Microsoft SharePoint Document.

github.com/looCiprian/GC2-sheet

#infosec #cybersecurity #redteam #pentest #threatintel #dfir

Cliff Barbiercliffb_infosec
2026-01-29

The Coalfire Labs physical ordeal is finally over.

Over 6 years after being falsely arrested, maliciously prosecuted, and publicly defamed by a Sheriff who wanted to get into a political power struggle with the state judicial branch, there is a civil settlement.

arstechnica.com/security/2026/

Assured Security Consultantsassured@infosec.exchange
2026-01-29

Celebrating 100 security assessments, over 1000 findings, and over 2000 pages of pentest reports in 2025!
assured.se/posts/100-security-
#pentest #cybersecurity

2026-01-29

This project maintains a list of binaries natively available in Proxmox VE that can be leveraged by adversaries during red team operations

lolprox.yxz.red

#infosec #cybersecurity #redteam #pentest

Le site de Korbenkorben.info@web.brid.gy
2026-01-26

CertRadar - Espionnez l'infra cachée de vos concurrents (légalement)

fed.brid.gy/r/https://korben.i

<p>Vos concurrents vous cachent des choses. Enfin, j'crois ^^</p>
<p>Leur infrastructure secrète, leurs projets en cours, leurs lancements prévus... Et pourtant, une bonne partie de tout ça est en fait visible si on sait où regarder...</p>
<p>Comment ? Grâce aux logs <strong>Certificate Transparency</strong>, c'est-à-dire les registres publics où les autorités de certification reconnues par les navigateurs enregistrent les certificats SSL qu'elles émettent.</p>
<p>Du coup, quand une boîte prépare un nouveau service sur staging.secret-project.example.com, hop, le certificat SSL est enregistré dans les logs CT et devient visible pour qui sait chercher. Et c'est exactement à ça que sert
<a href="https://certradar.net/">CertRadar</a>
, un outil gratuit qui va fouiller ces logs pour vous.</p>
<p>Perso j'adore ce genre d'outil pour le pentest et la veille concurrentielle. Vous tapez un domaine et bam, vous récupérez une bonne partie des sous-domaines qui ont eu un certificat SSL. Y'a de quoi faire pleurer un admin sys qui pensait que son serveur de dev était bien planqué !</p>
<p>CertRadar propose plusieurs modules. Le <strong>Cert Log Search</strong> qui est le coeur du truc, fouille les logs CT pour trouver les certificats émis pour un domaine. Le <strong>TLS Scanner</strong> analyse la config TLS de n'importe quel serveur (versions supportées, ciphers, tout ça). Le <strong>Header Search</strong> inspecte les en-têtes HTTP. Y'a aussi un <strong>RDAP Lookup</strong> pour les infos
2026-01-26

Custom Google search engine dedicated to IT security & hacking stuff. Over 240 high-quality sources.

github.com/Print3M/Google-Hack

#infosec #cybersecurity #redteam #pentest #threatintel #malware #bugbounty

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst