home.social

#pentesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pentesting, aggregated by home.social.

fetched live
  1. was haltet Ihr von #pentesting durch eine #KI an der eigenen Software in einer Sandbox?

  2. 🌐 WEB SECURITY TESTING ROADMAP

    From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.

    ⚡ Learn the process. Test responsibly. Build secure.

    #WebSecurity #CyberSecurity #Pentesting #InfoSec #AppSec

  3. 🌐 WEB SECURITY TESTING ROADMAP

    From HTTP & reconnaissance to authentication, access control, APIs and reporting. 🔍🛡️ A practical path for understanding how modern web applications are tested and secured.

    ⚡ Learn the process. Test responsibly. Build secure.

    #WebSecurity #CyberSecurity #Pentesting #InfoSec #AppSec

  4. 🔍 What happens after you book a pentest?

    From scoping and testing to reporting, remediation, and retesting, here’s what to expect from the full process. 🔐

    👉 7asecurity.com/blog/2026/08/wh

  5. 🛡️ METASPLOIT CHEAT SHEET

    Metasploit is one of the most powerful and widely used penetration testing frameworks. 💻⚡ From exploit modules and payloads to auxiliary tools, sessions and post-exploitation, understanding its structure is an essential skill for security professionals.

    This cheat sheet covers the core Metasploit concepts and commands you need to navigate the framework, configure modules and work efficiently inside msfconsole. 🔐🚀

    ⚠️ For cybersecurity education and authorized security testing only.

    💬 Comment “METASPLOIT” if you want more cybersecurity cheat sheets.

    #Metasploit #CyberSecurity #Pentesting #EthicalHacking #CyberKid

  6. 🛡️ METASPLOIT CHEAT SHEET

    Metasploit is one of the most powerful and widely used penetration testing frameworks. 💻⚡ From exploit modules and payloads to auxiliary tools, sessions and post-exploitation, understanding its structure is an essential skill for security professionals.

    This cheat sheet covers the core Metasploit concepts and commands you need to navigate the framework, configure modules and work efficiently inside msfconsole. 🔐🚀

    ⚠️ For cybersecurity education and authorized security testing only.

    💬 Comment “METASPLOIT” if you want more cybersecurity cheat sheets.

    #Metasploit #CyberSecurity #Pentesting #EthicalHacking #CyberKid

  7. 🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡

    Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉

    ⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻

    ⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥

    #StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking

  8. 🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡

    Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉

    ⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻

    ⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥

    #StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking

  9. #introduction

    Final-year CS student pivoting hard into offensive security. Currently working through the TryHackMe Jr Pentester path and learning Burp Suite properly instead of clicking buttons and
    hoping.

    Also grinding DSA in Java, which I am worse at than I'd like.

    Here to learn from people who actually do this for a living. Posting writeups, dumb questions, and things I got wrong.

    #infosec #pentesting #ctf #linux #cybersecurity #introduction

  10. #introduction

    Final-year CS student pivoting hard into offensive security. Currently working through the TryHackMe Jr Pentester path and learning Burp Suite properly instead of clicking buttons and
    hoping.

    Also grinding DSA in Java, which I am worse at than I'd like.

    Here to learn from people who actually do this for a living. Posting writeups, dumb questions, and things I got wrong.

    #infosec #pentesting #ctf #linux #cybersecurity #introduction

  11. Sucks that I’m not at #defcon, but I’m making up for it by semi-impromptu tutoring some people in #pentesting, so I guess that all works out :)

  12. Sucks that I’m not at #defcon, but I’m making up for it by semi-impromptu tutoring some people in #pentesting, so I guess that all works out :)

  13. 🛡️ Exploit Database — Top Exploits by Category

    Explore some of the most important vulnerabilities across major Exploit-DB categories, with CVE references, vulnerability types, and impact explained in one visual guide.

    💬 Comment “EXPLOIT” if you want more cybersecurity cheat sheets like this.

    #CyberSecurity #ExploitDB #InfoSec #SecurityResearch #Pentesting

  14. 🛡️ Exploit Database — Top Exploits by Category

    Explore some of the most important vulnerabilities across major Exploit-DB categories, with CVE references, vulnerability types, and impact explained in one visual guide.

    💬 Comment “EXPLOIT” if you want more cybersecurity cheat sheets like this.

    #CyberSecurity #ExploitDB #InfoSec #SecurityResearch #Pentesting

  15. Are we just drawing a line in the sand and writing up APIs that just have a static key in the header for insufficient auth? Or are we still giving people a break? I go back and forth.

    #pentesting

  16. Are we just drawing a line in the sand and writing up APIs that just have a static key in the header for insufficient auth? Or are we still giving people a break? I go back and forth.

    #pentesting

  17. 🛡️ Not all pentest services are the same.

    🔍 Learn which security assessment fits your situation—from web apps and cloud to AI, code audits, and internal testing.

    👉 7asecurity.com/blog/2026/07/pe

  18. Została wydana nowa wersja NetHydra 1.1.0 „leopard”. NetHydra (poprzednio: HydraPWK) to dystrybucja Linux oparta na Debianie testowym, przeznaczona głównie do testów... linuxiarze.pl/nethydra-1-1-0/ #linux #debian #pentesting

  19. Została wydana nowa wersja NetHydra 1.1.0 „leopard”. NetHydra (poprzednio: HydraPWK) to dystrybucja Linux oparta na Debianie testowym, przeznaczona głównie do testów... linuxiarze.pl/nethydra-1-1-0/ #linux #debian #pentesting

  20. VulNyx CTF War Writeup

    The War machine is an easy-level Windows system that runs on a Tomcat web server with unsecured credentials. By using an upload function, we can gain a foothold on the system. After that, we can escalate our privileges by exploiting the SeImpersonatePrivilege, which enables us to become the root user and capture the flag.

    thecybercraft.medium.com/vulny

    #ctf #pentesting #cybersecurity #tomcat #infosec

  21. The OSI model is not just for networking. It is also a great way to understand cybersecurity threats across the different layers of the OSI model 😎👇

    Find high-res pdf books with all my cybersecurity infographics at study-notes.org

    #cybersecurity #infosec #pentesting #itsecurity #technology

  22. 🐛 Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

    📝 Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoin...

    isc.sans.edu/diary/rss/33188

    📰 SANS Internet Storm Center, InfoCON: green

    #Pentesting #InfoSec

  23. 🐛 Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

    📝 Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoin...

    isc.sans.edu/diary/rss/33188

    📰 SANS Internet Storm Center, InfoCON: green

    #Pentesting #InfoSec

  24. SSH (Secure Shell) - Attacks and Best Practices by Compass Security
    - Recon & Info Leakage
    - Authentication, CAs, MFA & FIDO2
    - Port Forwarding / Tunneling, Agent Forwarding
    - Hardening, Post-Quantum Crypto, Auditing & more

    youtube.com/watch?v=Q3nk5H1mtvw

    #infosec #pentesting #redteam #blueteam

  25. SSH (Secure Shell) - Attacks and Best Practices by Compass Security
    - Recon & Info Leakage
    - Authentication, CAs, MFA & FIDO2
    - Port Forwarding / Tunneling, Agent Forwarding
    - Hardening, Post-Quantum Crypto, Auditing & more

    youtube.com/watch?v=Q3nk5H1mtvw

    #infosec #pentesting #redteam #blueteam

  26. Master SMB enumeration with SMBMap! Learn how to scan shares, map permissions, use Pass-the-Hash, and execute commands in this complete guide & cheat sheet. 🚀

    Read more: denizhalil.com/2023/10/27/smbm

    #SMBMap #Pentesting #Cybersecurity

  27. Netcat is one of those Linux tools networking and security people keep coming back to. It can open TCP/UDP connections, test ports reachability, move data between systems, and create quick listeners or reverse shells.

    Here are some practical Netcat commands worth knowing 😎👇

    Find high-res pdf ebooks with all my Linux related infographics at study-notes.org

    #linux #cybersecurity #infosec #kalilinux #pentesting

  28. #AdversaryToolDemo
    Adversary Village at @defcon 34!
    Dhruva Goyal, Founder of Bugbase, and Sitaraman Subramanian, Co-Founder & CTO of Bugbase, will demonstrate “Hands-On Autonomous Pentesting with Pentest Copilot” on 8 Aug 2026 at the Adversary Village Hands-on Activity Stage.
    Adversary Village schedule:
    adversaryvillage.org/adversary
    More info on the session and speakers: adversaryvillage.org/adversary
    adversaryvillage.org/adversary
    #AdversaryVillage #DEFCON34
    #AdversaryToolDemo #Pentesting #AutonomousSecurity
    #AIAgents #AdversaryTactics

  29. #AdversaryToolDemo
    Adversary Village at @defcon 34!
    Dhruva Goyal, Founder of Bugbase, and Sitaraman Subramanian, Co-Founder & CTO of Bugbase, will demonstrate “Hands-On Autonomous Pentesting with Pentest Copilot” on 8 Aug 2026 at the Adversary Village Hands-on Activity Stage.
    Adversary Village schedule:
    adversaryvillage.org/adversary
    More info on the session and speakers: adversaryvillage.org/adversary
    adversaryvillage.org/adversary
    #AdversaryVillage #DEFCON34
    #AdversaryToolDemo #Pentesting #AutonomousSecurity
    #AIAgents #AdversaryTactics

  30. Sadly it looks like I habe to use ai soon.

    any tips on setting up an automated agentic pentester?

    I'm running containerized ollama and hermes with an rtx5060Ti passthrough and gemma4-12b.

    looking for skills, (uncensored) models, workflows, Plugins etc to run pentests.

    also set up parrot os security docket and gave the ai ssh access to it.

    #ai #agenticai #hermes #hermesagent #pentesting #penetrationtesting

  31. Released BashCoreV, a tiny Buildroot‑based Linux micro‑VM for fast IT & security practice.

    ~100 MB ISO, 2 s boot, ~300 MB RAM, Linux 6.19.
    Includes essential networking, diagnostics and scripting tools.
    Lightweight, disposable, perfect for labs and learning.

    Repo: github.com/bashcore/bashcorev

    #linux #buildroot #vm #infosec #pentesting #virtualbox #minimalism

  32. We kept getting asked the same handful of questions before people would trust us with a scan against prod.

    So we answered them properly instead of one at a time on sales calls.

    Non-destructive by default. Our own detection engines, not a wrapper around someone else's open source tools. Findings come with evidence, not just a severity label. Data stays on EU infrastructure, workspaces isolated.

    Full FAQ: pentest-tools.com/product/faq

    #offensivesecurity #pentesting

  33. The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home.

    Our sponsor Aikido Security asked 400 security and engineering leaders what's actually broken in security testing, and whether AI fixes it or makes it worse. The answers are in the State of AI in Pentesting 2026.

    A solid resource ahead of @defcon 34!

    aikido.dev/state-of-ai-pentest

    #appsec #pentesting #aisecurity #DEFCON34 #DEFCON

  34. #Pentesting reizt dich und du willst es lernen? Beim HackHERthon vom 07.–09.09.2026 in Berlin kannst du dich ausprobieren – ohne Leistungsdruck, mit Fokus auf Teamarbeit und persönlicher Weiterentwicklung. Unser Kollege und Deutschland bester Pentester Cass Rebellin unterstützt dich an Tag 1 im Capture‑the‑Flag-Wettbewerb. Tage 2–3 drehen sich um kreative Problemlösung.
    Kostenfrei, inklusiv und offen für alle, die sich als Frau identifizieren – von Einsteigerin bis Profi! Unsere Expertinnen und Experten sind vor Ort und teilen Tools, Methoden und Mindset aus echten Einsätzen.
    Jetzt Platz sichern: hisolutions.com/hackherthon
    #CTF #HackHERthon #WomenInTech #CyberSecurity