home.social

#pentester — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pentester, aggregated by home.social.

fetched live
  1. Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷‍♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.

    #getfedihired #fedihired

  2. Hello Fedi! My employer went through my #PostCovid time with me. Now that I'm back to work full time, they suddenly decided to let me go. 🤷‍♀️ I'm a #pentester with 5 years of experience in the field, before that 3 years of software dev in the #infosec field as well. Got a Bsc. in Computer Sience with emphasis on infosec and networke systems. In my #homelab I'm selfhosting on #proxmox and #k8s. I've been daily driving #linux for the past 20 years, first #gentoo, then #fedora. I'm pretty good with it, but no certs. I'm looking to continue in #offensivesecurity, but would be happy to pivot into infra/network or any other adventure given it's interessting or a good cause. Happy to invest in my skillset. Hybrid in north-eastern #Switzerland fully remote anywhere else.

    #getfedihired #fedihired

  3. can anyone advise good methods to cope with the nagging feeling that the customer i'm chatting with is really just the output of an #llm. i'm most triggered by "you are absolutely correct" and my "excellent observations" and similar sycophantic compliments. i never thought i'd miss the denial and passive anger of traditional vendor responses...

    #pentester

  4. can anyone advise good methods to cope with the nagging feeling that the customer i'm chatting with is really just the output of an #llm. i'm most triggered by "you are absolutely correct" and my "excellent observations" and similar sycophantic compliments. i never thought i'd miss the denial and passive anger of traditional vendor responses...

    #pentester

  5. An honsest question to the #pentester crowd out there. When you write up a report, do you include everything you tried, or only the findings you came across and verified. I had a discussion today with someone new who nearly had me fire them as a client, and now I'm curious. We resolved our differences, but his initial reaction pissed me off and now I'm curious how others handle things.

    One tidbit - there was no mention of chained vulnerabilities in the report. The reason? There were no exploitable vulnerabilities that we could chain off of! There's a lot more, but that was a taste of how it started.

  6. An honsest question to the #pentester crowd out there. When you write up a report, do you include everything you tried, or only the findings you came across and verified. I had a discussion today with someone new who nearly had me fire them as a client, and now I'm curious. We resolved our differences, but his initial reaction pissed me off and now I'm curious how others handle things.

    One tidbit - there was no mention of chained vulnerabilities in the report. The reason? There were no exploitable vulnerabilities that we could chain off of! There's a lot more, but that was a taste of how it started.

  7. Schon verkauft, danke!

    Mag wer meinen kaum benutzen Flipper Zero abkaufen? Kommt einiges an Zubehör mit. Ebay mag mich den nicht verkaufen lassen.

    Does anyone (in Germany) want to buy off my barely used flipper zero? Comes with stuff. Ebay doesn't like to sell it.

    ESP32 crhismettal backpack, RPi Zero chrismettal backpack (no/kein rpi), DrB0rk NRF24 backpack, OVP

    Preis/Price: 200 Euros

    #FlipperZero #Flohmarkt #Fleamarket #ToSell #pentester #pleaseBoost

  8. Schon verkauft, danke!

    Mag wer meinen kaum benutzen Flipper Zero abkaufen? Kommt einiges an Zubehör mit. Ebay mag mich den nicht verkaufen lassen.

    Does anyone (in Germany) want to buy off my barely used flipper zero? Comes with stuff. Ebay doesn't like to sell it.

    ESP32 crhismettal backpack, RPi Zero chrismettal backpack (no/kein rpi), DrB0rk NRF24 backpack, OVP

    Preis/Price: 200 Euros

    #FlipperZero #Flohmarkt #Fleamarket #ToSell #pentester #pleaseBoost

  9. El lado del mal - ¿Se puede reemplazar a un Pentester con un Agente de IA basado en LLMs? Cómo realizar ataques completos a redes complejas con agentes de Inteligencia Artificial elladodelmal.com/2025/05/se-pu #AI #IA #Pentesting #Hacking #LLM #Pentester #MCP #AgenticAI #RedTeam

  10. El lado del mal - ¿Se puede reemplazar a un Pentester con un Agente de IA basado en LLMs? Cómo realizar ataques completos a redes complejas con agentes de Inteligencia Artificial elladodelmal.com/2025/05/se-pu #AI #IA #Pentesting #Hacking #LLM #Pentester #MCP #AgenticAI #RedTeam

  11. Who says that #AI isn't helping people in real-life situations?

    Consider yourself a bad #hacker, breaking in a company #SharePoint server. With #Microsoft #CoPilot, you're able to determine recent #pentesting reports, plain text #passwords and other crucial information for your attack right away. As if you get direct help by an insider. Amazing.

    If you find an interesting sensitive file you don't have reading permission for, you can ask CoPilot to show it to you, overriding all the #security permission measures. Even better: this is not even logged as a file access. No need to clean up afterward.

    Exactly the software you will need for your work. #Pentester and attackers could not have asked for a better tool. Your victims will pay for this handy service themselves. Great to get that kind of important support by Microsoft. 😉

    Read about that on: pentestpartners.com/security-b

    #LLM #fail #backdoor #pentesting

  12. Who says that #AI isn't helping people in real-life situations?

    Consider yourself a bad #hacker, breaking in a company #SharePoint server. With #Microsoft #CoPilot, you're able to determine recent #pentesting reports, plain text #passwords and other crucial information for your attack right away. As if you get direct help by an insider. Amazing.

    If you find an interesting sensitive file you don't have reading permission for, you can ask CoPilot to show it to you, overriding all the #security permission measures. Even better: this is not even logged as a file access. No need to clean up afterward.

    Exactly the software you will need for your work. #Pentester and attackers could not have asked for a better tool. Your victims will pay for this handy service themselves. Great to get that kind of important support by Microsoft. 😉

    Read about that on: pentestpartners.com/security-b

    #LLM #fail #backdoor #pentesting

  13. Formation en français, siouplè! 🧐🩵🥐

    La voilà! Une formation de deux jours est conçu pour les débutants en sécurité possédant des connaissances de base en IT, qui repartiront avec des compétences immédiatement applicables. ✨🤩

    nsec.io/training/2025-adoptez-

    #infosec #devops #pentester #hacking #ctf #mtl

  14. Formation en français, siouplè! 🧐🩵🥐

    La voilà! Une formation de deux jours est conçu pour les débutants en sécurité possédant des connaissances de base en IT, qui repartiront avec des compétences immédiatement applicables. ✨🤩

    nsec.io/training/2025-adoptez-

    #infosec #devops #pentester #hacking #ctf #mtl

  15. Done, but... just out of curiosity.

    Should Pentester cleanup after themself?

    Like, delete all Accounts (they may have created) or remove E-Mail Forwarders from Printers and other Systems?

    Please retoot to reach more people.

    #security #pentest #pentester #fedihelp #redteam

  16. Done, but... just out of curiosity.

    Should Pentester cleanup after themself?

    Like, delete all Accounts (they may have created) or remove E-Mail Forwarders from Printers and other Systems?

    Please retoot to reach more people.

    #security #pentest #pentester #fedihelp #redteam

  17. J'ai regardé une vidéo récemment, le gars disait avoir "plein d'adresses IP à disposition". Pour faire des tests, faire tourner des bots. Et je me demande comment ça marche ? Combien ça coûte ? Qui lui fournit ce service ?

    #Sysadmin #Pentester #RedTeam

  18. J'ai regardé une vidéo récemment, le gars disait avoir "plein d'adresses IP à disposition". Pour faire des tests, faire tourner des bots. Et je me demande comment ça marche ? Combien ça coûte ? Qui lui fournit ce service ?

    #Sysadmin #Pentester #RedTeam

  19. 2024 OWASP AppSec Days Singapore - Oct 1 Training

    Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.

    The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.

    Register to attend these training courses and more now by visiting our website ➡️ owaspappsecdayssingapore2.rsvp

    #Singapore #OWASP #AppSec #InfoSec #PenTester #Devsec

  20. 2024 OWASP AppSec Days Singapore - Oct 1 Training

    Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.

    The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.

    Register to attend these training courses and more now by visiting our website ➡️ owaspappsecdayssingapore2.rsvp

    #Singapore #OWASP #AppSec #InfoSec #PenTester #Devsec

  21. Great read from Matt Bessey about many of the problems with using #GraphQL. I remember stumbling across permission/authorization issues for an android app that allowed me to view sensitive information for other users. The issue was definitely related to how GraphQL allowed so much through. If I had been a better #pentester, I'm sure I could have found many more problems.

    bessey.dev/blog/2024/05/24/why

  22. Great read from Matt Bessey about many of the problems with using #GraphQL. I remember stumbling across permission/authorization issues for an android app that allowed me to view sensitive information for other users. The issue was definitely related to how GraphQL allowed so much through. If I had been a better #pentester, I'm sure I could have found many more problems.

    bessey.dev/blog/2024/05/24/why

  23. We are on the lookout for a #pentester! 👩‍💻

    Join the Offensive Security team in the Cybersecurity Service for the European Union institutions, bodies, offices and agencies. Help provide cybersecurity services to more than 90 European Union institutions, bodies, offices and agencies!

    Check out the #vacancy and apply by 11 June 👉 europa.eu/!TrgXXk

  24. We are on the lookout for a #pentester! 👩‍💻

    Join the Offensive Security team in the Cybersecurity Service for the European Union institutions, bodies, offices and agencies. Help provide cybersecurity services to more than 90 European Union institutions, bodies, offices and agencies!

    Check out the #vacancy and apply by 11 June 👉 europa.eu/!TrgXXk

  25. Starting a new series of write-ups! I'd like to cover all Sherlocks from HackTheBox over next months, so stay tune!

    Sherlocks are investigative challenges that test defensive security skills. I encourage you to try them out if you like digital forensics, incident response, post-breach analysis and malware analysis!

    blog.cyberethical.me/htb-sherl

    #CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #dfir #soc

  26. Starting a new series of write-ups! I'd like to cover all Sherlocks from HackTheBox over next months, so stay tune!

    Sherlocks are investigative challenges that test defensive security skills. I encourage you to try them out if you like digital forensics, incident response, post-breach analysis and malware analysis!

    blog.cyberethical.me/htb-sherl

    #CyberEthical #CyberKnowledge #CyberSecurity #hacking #pentesting #pentester #infosec #ethicalhacking #whitehat #dfir #soc

  27. SnoopGod #Linux: The Cybersecurity #Distro Like #Kali Linux

    A modern fork of Blackbuntu for #pentester peeps is here!

    snoopgod.com/download/

  28. SnoopGod #Linux: The Cybersecurity #Distro Like #Kali Linux

    A modern fork of Blackbuntu for #pentester peeps is here!

    snoopgod.com/download/