#pentester — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pentester, aggregated by home.social.
-
Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.
-
Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.
-
can anyone advise good methods to cope with the nagging feeling that the customer i'm chatting with is really just the output of an #llm. i'm most triggered by "you are absolutely correct" and my "excellent observations" and similar sycophantic compliments. i never thought i'd miss the denial and passive anger of traditional vendor responses...
-
can anyone advise good methods to cope with the nagging feeling that the customer i'm chatting with is really just the output of an #llm. i'm most triggered by "you are absolutely correct" and my "excellent observations" and similar sycophantic compliments. i never thought i'd miss the denial and passive anger of traditional vendor responses...
-
An honsest question to the #pentester crowd out there. When you write up a report, do you include everything you tried, or only the findings you came across and verified. I had a discussion today with someone new who nearly had me fire them as a client, and now I'm curious. We resolved our differences, but his initial reaction pissed me off and now I'm curious how others handle things.
One tidbit - there was no mention of chained vulnerabilities in the report. The reason? There were no exploitable vulnerabilities that we could chain off of! There's a lot more, but that was a taste of how it started.
-
An honsest question to the #pentester crowd out there. When you write up a report, do you include everything you tried, or only the findings you came across and verified. I had a discussion today with someone new who nearly had me fire them as a client, and now I'm curious. We resolved our differences, but his initial reaction pissed me off and now I'm curious how others handle things.
One tidbit - there was no mention of chained vulnerabilities in the report. The reason? There were no exploitable vulnerabilities that we could chain off of! There's a lot more, but that was a taste of how it started.
-
Schon verkauft, danke!
Mag wer meinen kaum benutzen Flipper Zero abkaufen? Kommt einiges an Zubehör mit. Ebay mag mich den nicht verkaufen lassen.
Does anyone (in Germany) want to buy off my barely used flipper zero? Comes with stuff. Ebay doesn't like to sell it.
ESP32 crhismettal backpack, RPi Zero chrismettal backpack (no/kein rpi), DrB0rk NRF24 backpack, OVP
Preis/Price: 200 Euros
#FlipperZero #Flohmarkt #Fleamarket #ToSell #pentester #pleaseBoost
-
Schon verkauft, danke!
Mag wer meinen kaum benutzen Flipper Zero abkaufen? Kommt einiges an Zubehör mit. Ebay mag mich den nicht verkaufen lassen.
Does anyone (in Germany) want to buy off my barely used flipper zero? Comes with stuff. Ebay doesn't like to sell it.
ESP32 crhismettal backpack, RPi Zero chrismettal backpack (no/kein rpi), DrB0rk NRF24 backpack, OVP
Preis/Price: 200 Euros
#FlipperZero #Flohmarkt #Fleamarket #ToSell #pentester #pleaseBoost
-
HydraPWK: distribución Linux para pruebas de pentesting https://blog.elhacker.net/2025/11/hydrapwk-distribucion-linux-para-pentester-debian-kali.html #pentester #hacking #debian #distro #kali
-
HydraPWK: distribución Linux para pruebas de pentesting https://blog.elhacker.net/2025/11/hydrapwk-distribucion-linux-para-pentester-debian-kali.html #pentester #hacking #debian #distro #kali
-
El lado del mal - ¿Se puede reemplazar a un Pentester con un Agente de IA basado en LLMs? Cómo realizar ataques completos a redes complejas con agentes de Inteligencia Artificial https://www.elladodelmal.com/2025/05/se-puede-reemplazar-un-pentester-con-un.html #AI #IA #Pentesting #Hacking #LLM #Pentester #MCP #AgenticAI #RedTeam
-
El lado del mal - ¿Se puede reemplazar a un Pentester con un Agente de IA basado en LLMs? Cómo realizar ataques completos a redes complejas con agentes de Inteligencia Artificial https://www.elladodelmal.com/2025/05/se-puede-reemplazar-un-pentester-con-un.html #AI #IA #Pentesting #Hacking #LLM #Pentester #MCP #AgenticAI #RedTeam
-
Who says that #AI isn't helping people in real-life situations?
Consider yourself a bad #hacker, breaking in a company #SharePoint server. With #Microsoft #CoPilot, you're able to determine recent #pentesting reports, plain text #passwords and other crucial information for your attack right away. As if you get direct help by an insider. Amazing.
If you find an interesting sensitive file you don't have reading permission for, you can ask CoPilot to show it to you, overriding all the #security permission measures. Even better: this is not even logged as a file access. No need to clean up afterward.
Exactly the software you will need for your work. #Pentester and attackers could not have asked for a better tool. Your victims will pay for this handy service themselves. Great to get that kind of important support by Microsoft. 😉
Read about that on: https://www.pentestpartners.com/security-blog/exploiting-copilot-ai-for-sharepoint/
-
Who says that #AI isn't helping people in real-life situations?
Consider yourself a bad #hacker, breaking in a company #SharePoint server. With #Microsoft #CoPilot, you're able to determine recent #pentesting reports, plain text #passwords and other crucial information for your attack right away. As if you get direct help by an insider. Amazing.
If you find an interesting sensitive file you don't have reading permission for, you can ask CoPilot to show it to you, overriding all the #security permission measures. Even better: this is not even logged as a file access. No need to clean up afterward.
Exactly the software you will need for your work. #Pentester and attackers could not have asked for a better tool. Your victims will pay for this handy service themselves. Great to get that kind of important support by Microsoft. 😉
Read about that on: https://www.pentestpartners.com/security-blog/exploiting-copilot-ai-for-sharepoint/
-
El lado del mal - Offensive Security: Máster Online en Seguridad Ofensiva del Campus Internacional de Seguridad 2025/2026 (última oportunidad) https://www.elladodelmal.com/2025/03/offensive-security-master-online-en.html #Ciberseguridad #RedTeam #Pentest #Pentesting #Pentester #Master #Formación #OffensiveSecurity
-
El lado del mal - Offensive Security: Máster Online en Seguridad Ofensiva del Campus Internacional de Seguridad 2025/2026 (última oportunidad) https://www.elladodelmal.com/2025/03/offensive-security-master-online-en.html #Ciberseguridad #RedTeam #Pentest #Pentesting #Pentester #Master #Formación #OffensiveSecurity
-
CISA pen-tester says 100-strong red team binned after DOGE canceled contract – Source: go.theregister.com https://ciso2ciso.com/cisa-pen-tester-says-100-strong-red-team-binned-after-doge-canceled-contract-source-go-theregister-com/ #rssfeedpostgeneratorecho #TheRegisterSecurity #CyberSecurityNews #TheRegister #pentester
-
CISA pen-tester says 100-strong red team binned after DOGE canceled contract – Source: go.theregister.com https://ciso2ciso.com/cisa-pen-tester-says-100-strong-red-team-binned-after-doge-canceled-contract-source-go-theregister-com/ #rssfeedpostgeneratorecho #TheRegisterSecurity #CyberSecurityNews #TheRegister #pentester
-
Formation en français, siouplè! 🧐🩵🥐
La voilà! Une formation de deux jours est conçu pour les débutants en sécurité possédant des connaissances de base en IT, qui repartiront avec des compétences immédiatement applicables. ✨🤩
https://nsec.io/training/2025-adoptez-la-mentalite-dun-pentester--formation-pratique-de-deux-jours/
-
Formation en français, siouplè! 🧐🩵🥐
La voilà! Une formation de deux jours est conçu pour les débutants en sécurité possédant des connaissances de base en IT, qui repartiront avec des compétences immédiatement applicables. ✨🤩
https://nsec.io/training/2025-adoptez-la-mentalite-dun-pentester--formation-pratique-de-deux-jours/
-
Done, but... just out of curiosity.
Should Pentester cleanup after themself?
Like, delete all Accounts (they may have created) or remove E-Mail Forwarders from Printers and other Systems?
Please retoot to reach more people.
-
Done, but... just out of curiosity.
Should Pentester cleanup after themself?
Like, delete all Accounts (they may have created) or remove E-Mail Forwarders from Printers and other Systems?
Please retoot to reach more people.
-
OFFAT: OFFensive API Tester OWASP https://blog.elhacker.net/2025/01/offat-offensive-api-tester-owasp.html #pentester #hacking #owasp #api
-
OFFAT: OFFensive API Tester OWASP https://blog.elhacker.net/2025/01/offat-offensive-api-tester-owasp.html #pentester #hacking #owasp #api
-
El lado del mal - BootCamp "Especialista en Ciberseguridad" con garantía de empleo y becas: 10 de Febrero (sólo 4 plazas) https://www.elladodelmal.com/2025/01/bootcamp-especialista-en-ciberseguridad.html #ciberseguridad #bootcamp #formación #empleo #pentester
-
El lado del mal - BootCamp "Especialista en Ciberseguridad" con garantía de empleo y becas: 10 de Febrero (sólo 4 plazas) https://www.elladodelmal.com/2025/01/bootcamp-especialista-en-ciberseguridad.html #ciberseguridad #bootcamp #formación #empleo #pentester
-
Für #Pentester und Sicherheitsforscher: #KaliLinux 2024.4 mit 14 neuen Tools | Security https://www.heise.de/news/Fuer-Pentester-und-Sicherheitsforscher-Kali-Linux-2024-4-mit-14-neuen-Tools-10203399.html #PenTesting #Linux :tux:
-
Für #Pentester und Sicherheitsforscher: #KaliLinux 2024.4 mit 14 neuen Tools | Security https://www.heise.de/news/Fuer-Pentester-und-Sicherheitsforscher-Kali-Linux-2024-4-mit-14-neuen-Tools-10203399.html #PenTesting #Linux :tux:
-
J'ai regardé une vidéo récemment, le gars disait avoir "plein d'adresses IP à disposition". Pour faire des tests, faire tourner des bots. Et je me demande comment ça marche ? Combien ça coûte ? Qui lui fournit ce service ?
-
J'ai regardé une vidéo récemment, le gars disait avoir "plein d'adresses IP à disposition". Pour faire des tests, faire tourner des bots. Et je me demande comment ça marche ? Combien ça coûte ? Qui lui fournit ce service ?
-
El lado del mal - The Art of Pentesting: El nuevo libro de 0xWord para formarse como pentester https://www.elladodelmal.com/2024/10/the-art-of-pentesting-el-nuevo-libro-de.html #pentest #pentesting #pentester #hacking #ciberseguridad #redteam
-
El lado del mal - The Art of Pentesting: El nuevo libro de 0xWord para formarse como pentester https://www.elladodelmal.com/2024/10/the-art-of-pentesting-el-nuevo-libro-de.html #pentest #pentesting #pentester #hacking #ciberseguridad #redteam
-
2024 OWASP AppSec Days Singapore - Oct 1 Training
Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.
The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.
Register to attend these training courses and more now by visiting our website ➡️ https://owaspappsecdayssingapore2.rsvpify.com/?securityToken=NxxB8ikF85MpaSmrzi8bXPS2500nadDT
-
2024 OWASP AppSec Days Singapore - Oct 1 Training
Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.
The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.
Register to attend these training courses and more now by visiting our website ➡️ https://owaspappsecdayssingapore2.rsvpify.com/?securityToken=NxxB8ikF85MpaSmrzi8bXPS2500nadDT
-
Great read from Matt Bessey about many of the problems with using #GraphQL. I remember stumbling across permission/authorization issues for an android app that allowed me to view sensitive information for other users. The issue was definitely related to how GraphQL allowed so much through. If I had been a better #pentester, I'm sure I could have found many more problems.
-
Great read from Matt Bessey about many of the problems with using #GraphQL. I remember stumbling across permission/authorization issues for an android app that allowed me to view sensitive information for other users. The issue was definitely related to how GraphQL allowed so much through. If I had been a better #pentester, I'm sure I could have found many more problems.
-
We are on the lookout for a #pentester! 👩💻
Join the Offensive Security team in the Cybersecurity Service for the European Union institutions, bodies, offices and agencies. Help provide cybersecurity services to more than 90 European Union institutions, bodies, offices and agencies!
Check out the #vacancy and apply by 11 June 👉 https://europa.eu/!TrgXXk
-
We are on the lookout for a #pentester! 👩💻
Join the Offensive Security team in the Cybersecurity Service for the European Union institutions, bodies, offices and agencies. Help provide cybersecurity services to more than 90 European Union institutions, bodies, offices and agencies!
Check out the #vacancy and apply by 11 June 👉 https://europa.eu/!TrgXXk
-
hello everyone.
In today's article, we introduce the arp protocol,
and we discover the devices on the network with a sample coding we have written.https://denizhalil.com/2024/05/04/python-scapy-arp-discovery/
#network #arp #python #programming #cybersecurity #arpdiscover #networksecurity #pentester
-
Write-up for the second HTB Sherlock!
https://blog.cyberethical.me/htb-sherlock-bumblebee
#CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #hackthebox #grepping #sqlite
-
Write-up for the second HTB Sherlock!
https://blog.cyberethical.me/htb-sherlock-bumblebee
#CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #hackthebox #grepping #sqlite
-
Starting a new series of write-ups! I'd like to cover all Sherlocks from HackTheBox over next months, so stay tune!
Sherlocks are investigative challenges that test defensive security skills. I encourage you to try them out if you like digital forensics, incident response, post-breach analysis and malware analysis!
https://blog.cyberethical.me/htb-sherlock-meerkat
#CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #dfir #soc
-
Starting a new series of write-ups! I'd like to cover all Sherlocks from HackTheBox over next months, so stay tune!
Sherlocks are investigative challenges that test defensive security skills. I encourage you to try them out if you like digital forensics, incident response, post-breach analysis and malware analysis!
https://blog.cyberethical.me/htb-sherlock-meerkat
#CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #dfir #soc
-
🎉 Finally, it's here - the most humble experience in weeks dissected for my readers - enjoy!
🔗 https://blog.cyberethical.me/htb-cyber-apocalypse-forensics-oblique-final
#CyberEthical #CyberKnowledge #CyberSecurity #forensics #malwareanalysis #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #reverseengineering
-
🎉 Finally, it's here - the most humble experience in weeks dissected for my readers - enjoy!
🔗 https://blog.cyberethical.me/htb-cyber-apocalypse-forensics-oblique-final
#CyberEthical #CyberKnowledge #CyberSecurity #forensics #malwareanalysis #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #reverseengineering
-
SnoopGod #Linux: The Cybersecurity #Distro Like #Kali Linux
A modern fork of Blackbuntu for #pentester peeps is here!
-
SnoopGod #Linux: The Cybersecurity #Distro Like #Kali Linux
A modern fork of Blackbuntu for #pentester peeps is here!
-
El lado del mal - Máster Online de Seguridad Ofensiva 2024-2025 con Certificación OSCP Offensive Security para ser Pentester https://www.elladodelmal.com/2024/01/master-online-de-seguridad-ofensiva.html #Master #OCSP #Pentesting #Pentester #Ciberseguridad #Formacion