home.social

#pentesters — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pentesters, aggregated by home.social.

  1. 😱 In just one week, over 500,000 people learned how to use #OSINT to prepare for physical #intrusions!

    ⛓️‍💥 With several years of experience in physical security audits, Sylvain Hajri, CEO of Epieos, shared his expertise during his interview on #Underscore_ , the leading French #IT and #hacking talk show hosted by #Micode.

    Watch the full video here ( 🇨🇵 and 🇺🇲 versions available):
    👉 youtube.com/watch?v=L7dnmHnJbw\_channel=Underscore\_

    🥷 This video, it’s an excellent way for #pentesters and #cybersecurity professionals to educate those around them, both individuals and organizations, about what #redteams are and how they operate.

  2. 😱 In just one week, over 500,000 people learned how to use #OSINT to prepare for physical #intrusions!

    ⛓️‍💥 With several years of experience in physical security audits, Sylvain Hajri, CEO of Epieos, shared his expertise during his interview on #Underscore_ , the leading French #IT and #hacking talk show hosted by #Micode.

    Watch the full video here ( 🇨🇵 and 🇺🇲 versions available):
    👉 youtube.com/watch?v=L7dnmHnJbw\_channel=Underscore\_

    🥷 This video, it’s an excellent way for #pentesters and #cybersecurity professionals to educate those around them, both individuals and organizations, about what #redteams are and how they operate.

  3. 😱 In just one week, over 500,000 people learned how to use #OSINT to prepare for physical #intrusions!

    ⛓️‍💥 With several years of experience in physical security audits, Sylvain Hajri, CEO of Epieos, shared his expertise during his interview on #Underscore_ , the leading French #IT and #hacking talk show hosted by #Micode.

    Watch the full video here ( 🇨🇵 and 🇺🇲 versions available):
    👉 youtube.com/watch?v=L7dnmHnJbw\_channel=Underscore\_

    🥷 This video, it’s an excellent way for #pentesters and #cybersecurity professionals to educate those around them, both individuals and organizations, about what #redteams are and how they operate.

  4. 😱 In just one week, over 500,000 people learned how to use #OSINT to prepare for physical #intrusions!

    ⛓️‍💥 With several years of experience in physical security audits, Sylvain Hajri, CEO of Epieos, shared his expertise during his interview on #Underscore_ , the leading French #IT and #hacking talk show hosted by #Micode.

    Watch the full video here ( 🇨🇵 and 🇺🇲 versions available):
    👉 youtube.com/watch?v=L7dnmHnJbw\_channel=Underscore\_

    🥷 This video, it’s an excellent way for #pentesters and #cybersecurity professionals to educate those around them, both individuals and organizations, about what #redteams are and how they operate.

  5. 😱 In just one week, over 500,000 people learned how to use #OSINT to prepare for physical #intrusions!

    ⛓️‍💥 With several years of experience in physical security audits, Sylvain Hajri, CEO of Epieos, shared his expertise during his interview on #Underscore_ , the leading French #IT and #hacking talk show hosted by #Micode.

    Watch the full video here ( 🇨🇵 and 🇺🇲 versions available):
    👉 youtube.com/watch?v=L7dnmHnJbw\_channel=Underscore\_

    🥷 This video, it’s an excellent way for #pentesters and #cybersecurity professionals to educate those around them, both individuals and organizations, about what #redteams are and how they operate.

  6. #pentesters : What are some gripes you have with Burp and/or Caido?

  7. Really excited to be presenting Faction at @phreaknic 25! If you're tired of writing
    #pentest
    reports and wish to collaborate more with your fellow
    #pentesters
    then check out my talk 5:00pm - 5:30pm on Friday Nov. 8 🚀

    #appsec
    #redteam
    #cybersecurity
    #hacking

  8. ran ptf on the kali ai lab box after inaging and doing timeshift incremental backups - the python venv is kind of confusing, it used to be basic and straightforward, now it is a bit more involved #ptf #install it all #standards committee #pentesters framework github

  9. #Hacking is not just #OldSchool tooling and techniques. Modern #MobileApps are a fun target for #ReverseEngineers and #Pentesters alike. A fundamental tool to properly hack mobile apps is @fridadotre by @oleavr.

    We continue our tour of my @github projects with my humble contributions to this field:
    github.com/0xdea/frida-scripts

    For a well-maintained project that includes some of my #Frida scripts, check out #Brida by @apps3c and Piergiovanni Cipolloni:
    github.com/federicodotta/Brida

    And even after many years, if you search for well-crafted Frida scripts to bypass certificate pinning or root detection, there’s a very good chance that you’ll stumble upon the work of some of my colleagues… Very proud of my team at @hnsec!

  10. #Hacking is not just #OldSchool tooling and techniques. Modern #MobileApps are a fun target for #ReverseEngineers and #Pentesters alike. A fundamental tool to properly hack mobile apps is @fridadotre by @oleavr.

    We continue our tour of my @github projects with my humble contributions to this field:
    github.com/0xdea/frida-scripts

    For a well-maintained project that includes some of my #Frida scripts, check out #Brida by @apps3c and Piergiovanni Cipolloni:
    github.com/federicodotta/Brida

    And even after many years, if you search for well-crafted Frida scripts to bypass certificate pinning or root detection, there’s a very good chance that you’ll stumble upon the work of some of my colleagues… Very proud of my team at @hnsec!

  11. #Hacking is not just #OldSchool tooling and techniques. Modern #MobileApps are a fun target for #ReverseEngineers and #Pentesters alike. A fundamental tool to properly hack mobile apps is @fridadotre by @oleavr.

    We continue our tour of my @github projects with my humble contributions to this field:
    github.com/0xdea/frida-scripts

    For a well-maintained project that includes some of my #Frida scripts, check out #Brida by @apps3c and Piergiovanni Cipolloni:
    github.com/federicodotta/Brida

    And even after many years, if you search for well-crafted Frida scripts to bypass certificate pinning or root detection, there’s a very good chance that you’ll stumble upon the work of some of my colleagues… Very proud of my team at @hnsec!

  12. #Hacking is not just #OldSchool tooling and techniques. Modern #MobileApps are a fun target for #ReverseEngineers and #Pentesters alike. A fundamental tool to properly hack mobile apps is @fridadotre by @oleavr.

    We continue our tour of my @github projects with my humble contributions to this field:
    github.com/0xdea/frida-scripts

    For a well-maintained project that includes some of my #Frida scripts, check out #Brida by @apps3c and Piergiovanni Cipolloni:
    github.com/federicodotta/Brida

    And even after many years, if you search for well-crafted Frida scripts to bypass certificate pinning or root detection, there’s a very good chance that you’ll stumble upon the work of some of my colleagues… Very proud of my team at @hnsec!

  13. #Hacking is not just #OldSchool tooling and techniques. Modern #MobileApps are a fun target for #ReverseEngineers and #Pentesters alike. A fundamental tool to properly hack mobile apps is @fridadotre by @oleavr.

    We continue our tour of my @github projects with my humble contributions to this field:
    github.com/0xdea/frida-scripts

    For a well-maintained project that includes some of my #Frida scripts, check out #Brida by @apps3c and Piergiovanni Cipolloni:
    github.com/federicodotta/Brida

    And even after many years, if you search for well-crafted Frida scripts to bypass certificate pinning or root detection, there’s a very good chance that you’ll stumble upon the work of some of my colleagues… Very proud of my team at @hnsec!

  14. I'm happy to be here and after thinking about attending a security test course I decided to focus on creating a #GNU #Linux #Debian #distro which is focused on #security for #sysadmins #developers #pentesters and #artists called #procyberian #ProcyberianSystemsDistribution and then now let's say #happhacking !

    github.com/procyberian is our home for our projects ! #github

    Thanks !

  15. I'm happy to be here and after thinking about attending a security test course I decided to focus on creating a #GNU #Linux #Debian #distro which is focused on #security for #sysadmins #developers #pentesters and #artists called #procyberian #ProcyberianSystemsDistribution and then now let's say #happhacking !

    github.com/procyberian is our home for our projects ! #github

    Thanks !

  16. I'm happy to be here and after thinking about attending a security test course I decided to focus on creating a #GNU #Linux #Debian #distro which is focused on #security for #sysadmins #developers #pentesters and #artists called #procyberian #ProcyberianSystemsDistribution and then now let's say #happhacking !

    github.com/procyberian is our home for our projects ! #github

    Thanks !

  17. I'm happy to be here and after thinking about attending a security test course I decided to focus on creating a #GNU #Linux #Debian #distro which is focused on #security for #sysadmins #developers #pentesters and #artists called #procyberian #ProcyberianSystemsDistribution and then now let's say #happhacking !

    github.com/procyberian is our home for our projects ! #github

    Thanks !

  18. I'm happy to be here and after thinking about attending a security test course I decided to focus on creating a #GNU #Linux #Debian #distro which is focused on #security for #sysadmins #developers #pentesters and #artists called #procyberian #ProcyberianSystemsDistribution and then now let's say #happhacking !

    github.com/procyberian is our home for our projects ! #github

    Thanks !

  19. With the new #opensource tool Swagger Jacker, #pentesters can automate analysis of response codes for each #API defined route, streamline manual testing capabilities with #curl command creation, and gather #endpoint routes.

    #OSINT #pentestingtool #infosec

    bfx.social/48pEAmY

  20. Hey, #appsec and #pentesters ! how many of you use automated report-writing tools for security assessments and what do you use?

  21. Auditing #API endpoints after discovering a public hosted specification file is no small feat for #pentesters. Enter the new #opensource tool from Tony West (@un4gi_io), Swagger Jacker. He’ll walk you through how to use this new #pentesting tool in our next #BFLive training session. 🔨

    bfx.social/4156hyN

    And afterwards, we’ll be doing a quick #AMA with Tony in our #Discord server, which you can join at the link! It’s an active group consisting of 1600+ #infosec community members.

    discord.com/invite/redsec

  22. Question for all #pentesters : Assume you have got access to user's Home directory via a exploit which allows you to read the file if you know the file name. What files would you like to read?

    #appsec #infosec

  23. The Weird, Big-Money World of Cybercrime Writing Contests - The competitions, which are held on Russian-language cybercrime forums, offer prize money... - wired.com/story/hacking-contes #security/cyberattacksandhacks #security/securitynews #pentesters #security

  24. I actually did useful #InfoSec work today. Picked apart a “Free Security Scan!” report tossed at us by an irate client.

    I really wish cheap-ass “#pentesters” would learn to recognize distro-maintained versions of major packages. I do not need a list of the scores of CVE’s for httpd that have been mitigated by ASF since RedHat bumped the nominal version of their custom-patched package. Scans like that just make people angry at their lazy sysadmins. Who are not in fact being lazy.

  25. Building detailed maps of web applications and their supporting #JavaScript code and files is paramount to #vulnerability discovery in #offensivesecurity testing.

    But for #pentesters, discovering the deepest, darkest secrets in JavaScript can be like mining for gold, sifting through copious amounts of extraneous information to find the smallest bits of criticality that expose weak points in applications. Knowing where to turn for the latest and greatest JavaScript mining tool developments is worth its weight in gold for #offsec practitioners needing to constantly increase efficiency and efficacy in web application penetration testing.

    See how the #opensource tool jsluice can help during the next #BFLive #ToolTalk, featuring @tomnomnom.

    bfx.social/3PQ85I2

  26. Jsluice is the newest tool from Tom Hudson, and in this month's #ToolTalk #BFLive event, he'll show you how to get the most from this #opensource, Go package and command-line tool used for extracting URLs, paths, secrets, and other interesting data from #JavaScript source code. This is a must-watch for #pentesters.

    bfx.social/3PQ85I2

  27. Have you added CloudFoxable to your playground #AWS account? This tool by @sethsec is built to help #pentesters with AWS #Cloud testing, while showcasing CloudFox’s capabilities that help locate latent #attackpaths. It is inspired by #CloudGoat, flaws.cloud, and #Metasploitable. bfx.social/43T4dtK

  28. Have you added CloudFoxable to your playground #AWS account? This tool by @sethsec is built to help #pentesters with AWS #Cloud testing, while showcasing CloudFox’s capabilities that help locate latent #attackpaths. It is inspired by #CloudGoat, flaws.cloud, and #Metasploitable. bfx.social/43T4dtK

  29. Have you added CloudFoxable to your playground #AWS account? This tool by @sethsec is built to help #pentesters with AWS #Cloud testing, while showcasing CloudFox’s capabilities that help locate latent #attackpaths. It is inspired by #CloudGoat, flaws.cloud, and #Metasploitable. bfx.social/43T4dtK

  30. Have you added CloudFoxable to your playground #AWS account? This tool by @sethsec is built to help #pentesters with AWS #Cloud testing, while showcasing CloudFox’s capabilities that help locate latent #attackpaths. It is inspired by #CloudGoat, flaws.cloud, and #Metasploitable. bfx.social/43T4dtK

  31. Have you added CloudFoxable to your playground #AWS account? This tool by @sethsec is built to help #pentesters with AWS #Cloud testing, while showcasing CloudFox’s capabilities that help locate latent #attackpaths. It is inspired by #CloudGoat, flaws.cloud, and #Metasploitable. bfx.social/43T4dtK

  32. What the Vuln is a new technical #livestream series where in each episode our #offensivesecurity experts and #hackers deep dive and zero-in on one specific vulnerability that plagues organizations – from origins and technical components to how #pentesters can find and exploit the #vulnerability.

    The first episode of our series explored Zimbra, and you can read the technical walkthrough of that #exploit here 👇

    bfx.social/3lUL75U

  33. Brazil seizing Flipper Zero shipments to prevent use in crime

    #Flipper #Zero is a portable multi-function cybersecurity tool that allows #pentesters and #hacking enthusiasts to tinker with a wide range of hardware by supporting #RFID emulation, digital access #key #cloning, #radio communications, #NFC, #infrared, #Bluetooth, and more.

    Flipper Zero has gained a reputation from users who showcased its hacking capabilities on social media to perform illegal activities such as unlocking cars, changing gas pump prices, intercepting and storing remote control signals, opening garage doors, and more.

    Although the device does not use hardware that is illegal or impossible to find elsewhere, its market success fueled a wave of negative media attention that portrayed it as a risk to society.

    bleepingcomputer.com/news/secu

  34. Hey #pentesters and #redteamers

    Is there any cyber conference worth attending in Europe?

  35. Hey #pentesters and #redteamers

    Is there any cyber conference worth attending in Europe?

  36. Hey #pentesters and #redteamers

    Is there any cyber conference worth attending in Europe?

  37. Hey #pentesters and #redteamers

    Is there any cyber conference worth attending in Europe?

  38. We have open mid-level and senior pentest roles for the SensePost team in the UK, NL and ZA. You can apply here jobs.za.orangecyberdefense.com or just DM me.

    We think it’s a nice place to work. A hacker culture. Research time for all analysts. Tons of internal learning. Deep care for everyone backed up by a low single digit hacker/manager ratio. Unheard of NPS scored from our customers (84 for 2022). Lots of training and conference opportunities.

    #hiring #hackers #pentesters #uk #nl #za #sensepost