PentesterLab

10.9K posts

PentesterLab banner
PentesterLab

PentesterLab

@PentesterLab

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

Melbourne, Victoria Joined Aralฤฑk 2011
0 Following200.8K Followers
Pinned Tweet
PentesterLab
PentesterLab@PentesterLabยท
๐Ÿ’ฅ๐Ÿน 4 new Go Code Review Labs just dropped! ๐Ÿน๐Ÿ’ฅ Read the code, peek at the diff, find the bug. Sharpen your skills: pentesterlab.com/badges/golang-โ€ฆ
English
5
9
83
28.1K
PentesterLab retweeted
Yakup Erdem รœnal
Yakup Erdem รœnal@callmeyakubiยท
Back in the day I used to do code reviews to actually learn stuffโ€ฆ now Iโ€™m just doing them like quick little brain teasers ๐Ÿ˜„ Big shoutout to @PentesterLab for keeping my puzzle game strong.
English
0
1
6
2.3K
PentesterLab retweeted
coffeefiend52
coffeefiend52@coffeefiend52ยท
I just completed @Pentesterlab's Golang Code Review Badge!!!
English
3
1
18
2K
PentesterLab retweeted
Louis Nyffenegger
Louis Nyffenegger@snyffยท
I spent last week, this week-end and the start of this week working on a redesign of @PentesterLab 's website. Aiming for something a bit more modern... Let me know what you think!
English
3
1
18
3K
PentesterLab retweeted
PentesterLab retweeted
Ahmed Ehab
Ahmed Ehab@HeBo117ยท
@AhmedMo15851348 ุฎุจุฑุชูƒ ููŠ ุงู„ web dev ู‡ุชูˆูุฑ ุนู„ูŠูƒ ูˆู‚ุช ูƒุจูŠุฑ ุงู„ ejpt ุจุฏุงูŠุฉ ูƒูˆูŠุณู‡ ู„ูˆ ุญุงุจุจ ุชุณุฑุน ุงู„ุฏู†ูŠุง ู…ู…ูƒู† ุชุดุชุฑูƒ ููŠ @PentesterLab ู„ูˆ ุชู‚ุฏุฑ ู‡ูŠุฎุชุตุฑ ุนู„ูŠูƒ ูˆู‚ุช ุฃูƒุจุฑ
ุงู„ุนุฑุจูŠุฉ
2
1
11
2.9K
PentesterLab
PentesterLab@PentesterLabยท
A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password. Why? Longer SHA-256 nonce + bcrypt truncation at 72 bytes. A nice example of why secure systems are about composition, not just stronger primitives. pentesterlab.com/blog/freshrss-โ€ฆ
English
0
12
63
19.8K
PentesterLab
PentesterLab@PentesterLabยท
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฌ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ A great mix of content this week! ๐Ÿ”’ ๐—œ๐—ฟ๐—ผ๐—ป๐—–๐˜‚๐—ฟ๐˜๐—ฎ๐—ถ๐—ป: ๐—” ๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ผ๐—ป๐—ฎ๐—น ๐—”๐—œ ๐—”๐˜€๐˜€๐—ถ๐˜€๐˜๐—ฎ๐—ป๐˜ ๐—•๐˜‚๐—ถ๐—น๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—š๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐—จ๐—ฝ Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: provos.org/p/ironcurtain-โ€ฆ. ๐Ÿšฅ ๐—บ๐—ถ๐˜๐—บ๐—ฝ๐—ฟ๐—ผ๐˜…๐˜† ๐—ณ๐—ผ๐—ฟ ๐—ณ๐˜‚๐—ป ๐—ฎ๐—ป๐—ฑ ๐—ฝ๐—ฟ๐—ผ๐—ณ๐—ถ๐˜: ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ฐ๐—ฒ๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€ ๐—ผ๐—ณ ๐—”๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฟ๐—ฎ๐—ณ๐—ณ๐—ถ๐—ฐ A write-up on how to use mitmproxy: synacktiv.com/en/publicationโ€ฆ. โœจ ๐—ง๐—ต๐—ฒ ๐— ๐—–๐—ฃ ๐—”๐˜‚๐˜๐—ต๐—ก/๐—ญ ๐—ก๐—ถ๐—ด๐—ต๐˜๐—บ๐—ฎ๐—ฟ๐—ฒ A reminder of the mess AuthN/Z with MCP is: blog.doyensec.com/2026/03/05/mcpโ€ฆ. ๐Ÿ˜Ž ๐—ฉ๐—ถ๐—ฏ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฅ๐—ฎ๐—ฑ๐—ฎ๐—ฟ A cool little project to track the security issues created by vibe coding: vibe-radar-ten.vercel.app. โ›“๏ธโ€๐Ÿ’ฅ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ถ๐—ป ๐—ฝ๐—ฎ๐—ฐ๐Ÿฐ๐—ท Another issue with a library leveragining JWT: codeant.ai/security-reseaโ€ฆ.
English
0
4
23
3K
PentesterLab retweeted
Ilias
Ilias@EliotGeoยท
I just completed @Pentesterlab's Recon Badge!!!
English
1
1
14
3.2K
PentesterLab retweeted
Louis Nyffenegger
Louis Nyffenegger@snyffยท
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars. vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days. pentesterlab.com/blog/what-you-โ€ฆ
English
1
12
52
7.1K
PentesterLab
PentesterLab@PentesterLabยท
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿต, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Mostly AI... ๐Ÿ’ป ๐—•๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—•๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ผ๐—ฟ๐˜ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—ด๐—ฒ ๐—ผ๐—ณ ๐—Ÿ๐—ก๐—” Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-portโ€ฆ. ๐ŸชŸ ๐Ÿญ๐Ÿฌ๐Ÿฌ+ ๐—ž๐—ฒ๐—ฟ๐—ป๐—ฒ๐—น ๐—•๐˜‚๐—ด๐˜€ ๐—ถ๐—ป ๐Ÿฏ๐Ÿฌ ๐——๐—ฎ๐˜†๐˜€ Behind the (impressive) result, the methodology is probably the most important. Make sure you read between the lines: substack.com/home/post/p-18โ€ฆ. โ›ˆ๏ธ ๐˜ƒ๐—ถ๐—ป๐—ฒ๐˜…๐˜: ๐—ฉ๐—ถ๐—ฏ๐—ฒ-๐—›๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—–๐—น๐—ผ๐˜‚๐—ฑ๐—ณ๐—น๐—ฎ๐—ฟ๐—ฒ'๐˜€ ๐—ฉ๐—ถ๐—ฏ๐—ฒ-๐—–๐—ผ๐—ฑ๐—ฒ๐—ฑ ๐—ก๐—ฒ๐˜…๐˜.๐—ท๐˜€ ๐—ฅ๐—ฒ๐—ฝ๐—น๐—ฎ๐—ฐ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ It's raining bugs in the cloud. A great example of agent capabilities on a never-seen-before target: hacktron.ai/blog/hacking-cโ€ฆ.
English
1
2
28
2.9K
PentesterLab retweeted
Paulo Cauca
Paulo Cauca@paulocaucaยท
I just completed @Pentesterlab's Unix Badge!!!
English
0
1
18
4.8K