PentesterLab's Avatar

PentesterLab

@pentesterlab.com.bsky.social

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

668 Followers  |  0 Following  |  69 Posts  |  Joined: 11.11.2024  |  1.0267

Latest posts by pentesterlab.com on Bluesky

Preview
DeepWiki | AI documentation you can talk to, for every repo DeepWiki provides up-to-date documentation you can talk to, for every repo in the world. Think Deep Research for GitHub - powered by Devin.

The past few weeks have been quiet, but weโ€™re back!

๐Ÿ› ๏ธ deepwiki.com
๐Ÿ› ๏ธ github.com/AsyncFuncAI/...
๐Ÿชฒ blog.trailofbits.com/2025/04/23/h...
๐Ÿ› ๏ธ github.com/quarkslab/pr...
๐Ÿ›ก๏ธ hdm.io/decks/Charti...

04.05.2025 22:37 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Your face when you realize your next security code review is on a Clojure codebase...

20.04.2025 23:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748) We know what youโ€™re waiting for - this isnโ€™t it. Today, weโ€™re back with more tales of our adventures in Kenticoโ€™s Xperience CMS. Due to itโ€™s wide usage, the type of solution, and the types of enterpri...

Articles worth reading discovered last week:

๐Ÿชฒ labs.watchtowr.com/xss-to-rce-b...
๐Ÿงฉ gist.github.com/Panya/990b45...

#PentesterLabWeekly

06.04.2025 21:54 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.

Two great pieces of content for this week:

๐Ÿชฒ www.wiz.io/blog/ingress...
๐Ÿชฒ zhero-web-sec.github.io/research-and...

#PentesterLabWeekly

30.03.2025 21:33 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
!exploitable Episode Three - Devfile Adventures ยท Doyensec's Blog !exploitable Episode Three - Devfile Adventures

โ€ผ๏ธ blog.doyensec.com/2025/03/18/e...
๐Ÿ“จ workos.com/blog/samlstorm
๐Ÿ›ค๏ธ projectdiscovery.io/blog/discour...
โ˜‘๏ธ labs.watchtowr.com/by-executive...
โค๏ธ tmpout.sh/4/
๐Ÿ—ผ labs.watchtowr.com/bypassing-au...โ€จโ€จ

Get our weekly news direct to your mailbox: pentesterlab.substack.com

23.03.2025 22:00 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If people spent as much time actually learning hacking as they do optimizing how to learn hacking, theyโ€™d be a lot better at it. Just start. Break things. Learn. Repeat.

20.03.2025 09:18 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PentesterLab: Learn with our Golang Code Review Badge The Golang Code Review Badge is our badge dedicated to code review in Golang. It covers the discovery of weaknesses and vulnerabilities using source code review.

We just released 3 new labs in our Golang Code Review Badge:

pentesterlab.com/badges/golan...

#golang

16.03.2025 22:51 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

What a week! SAML&Ruby, PHP&XXE and so much more!

๐Ÿ“จ github.blog/security/sig...
๐Ÿง‘๐Ÿปโ€๐Ÿ’ป seeinglogic.com/posts/visual...
๐Ÿคฏ swarm.ptsecurity.com/impossible-x...
๐Ÿ˜ป scrapco.de/blog/analysi...

More details in our blog: pentesterlab.com/blog/researc...

#PentesterLabWeekly

16.03.2025 22:21 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image 12.03.2025 21:51 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttamNew Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttam elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.

Articles worth reading discovered last week:

๐Ÿ’Ž www.elttam.com/blog/rails-s...
๏นŸ afine.com/understandin...
๐Ÿชฒ slcyber.io/blog/sitecor...

For more details, check out our blog:
pentesterlab.com/blog/researc...

09.03.2025 22:19 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PentesterLab: API Badge The API badge is our set of exercises created to help you learn API testing. The first few challenges are based on challenges you already solved to get you more confident with API testing and review your knowledge and methodology. Then, harder challenges are provided to get you to the next level.

Want to prove your API hacking skills?

Earn the PentesterLab API badge!

Hands-on labs designed to test and improve your ability to find and exploit API vulnerabilities.


https://pentesterlab.com/badges/api

02.03.2025 04:47 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How AI-Generated Code Is Changing Secure Code Review Learn how AI-generated code impacts secure code review and application security. Discover why AI excels at catching common vulnerabilities but needs human expertise for complex bugs.

AI-generated code is reshaping secure code reviewโ€”fewer trivial bugs, but more hidden threats.

Read more in our new blog post:

pentesterlab.com/blog/secure-...

What do you think?

24.02.2025 22:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2). Tags:Article - Article - Web - mXSS Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)

Articles worth reading discovered last week:

๐Ÿ“š mizu.re/post/explori...
โ˜๏ธ devanshbatham.hashnode.dev/fragility-of...
๐Ÿซ™ www.wiz.io/blog/nvidia-...
๐Ÿ www.reversinglabs.com/blog/rl-iden...
๐ŸŽฅ brutecat.com/articles/lea...

17.02.2025 02:58 โ€” ๐Ÿ‘ 7    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
I Donโ€™t Want My Devs to Become Hackers! - PentesterLab's Blog Discover why encouraging developers to learn ethical hacking boosts security, reduces bugs, and fosters a proactive security culture in your organization.

Think teaching devs to hack is risky?

In reality, a bit of hacking knowledge helps them spot vulnerabilities early and build stronger apps.

Discover why having devs with a 'hacker mindset' is a win for security:

pentesterlab.com/blog/why-dev...

13.02.2025 18:21 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PentesterLab: Learn with our API Badge The API badge is our set of exercises created to help you learn API testing. The first few challenges are based on challenges you already solved to get you more confident with API testing and review y...

๐Ÿšจ Just launched: Two brand-new API Mass Assignment labs!

Ready to level up your #API hacking skills? Dive into realistic scenarios & learn how to exploit hidden parameters:

1๏ธโƒฃ API Mass Assignment 01
2๏ธโƒฃ API Mass Assignment 02

pentesterlab.com/badges/api/

03.02.2025 22:57 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Common OAuth Vulnerabilities ยท Doyensec's Blog Common OAuth Vulnerabilities

Articles worth reading discovered last week:

๐Ÿค blog.doyensec.com/2025/01/30/o...
โ˜ ๏ธ www.feistyduck.com/newsletter/i...
๐Ÿ“š pathonproject.com/zb/?871f0933...

And as always, itโ€™s in our blog: pentesterlab.com/blog/researc...

#PentesterLabWeekly

02.02.2025 21:50 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™m excited to share that in a few weeks Iโ€™ll be heading to the US for a series of talks and workshops focused on security code review and JWTโ€”and Iโ€™ll be bringing some
@pentesterlab.com swag along too!

29.01.2025 23:33 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Learn Web Pentesting: Invariants and Feedback Loops Learn Web Pentesting techniques by leveraging invariants and short feedback loops to efficiently crack MongoDB IDOR and enhance your security skills.

Invariants + Short Feedback Loops = your secret weapon ๐Ÿ›ก๏ธ in web hacking & exploit dev! โ€จโ€จ

Validate assumptions locally, iterate fast โšก, and say goodbye to endless 10-minute test cycles โฑ๏ธ.โ€จ

Master these two techniques and watch your productivity skyrocket ๐Ÿš€ :

pentesterlab.com/blog/invaria...

28.01.2025 23:17 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Minimal Changes Vulnerability Testing: Why Less is More in Security Discover how a systematic, minimal-change approach to vulnerability testing can expose weaknesses that full-exploitation attempts often overlook. By making only small, essential adjustments, you reduc...

Jumping straight into โ€œfull exploitationโ€ can lead to confusion and missed bugs.

Instead, focus on minimal, incremental changes to isolate vulnerabilities. Itโ€™s a simple shift that reduces false negatives and clarifies which step triggers the bug.

pentesterlab.com/blog/minimal...

27.01.2025 21:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Reverse Engineering Call Of Duty Anti-Cheat Iโ€™ve been reversing Black Ops Cold War for a while now, and Iโ€™ve finally decided to share my research regarding the user-mode anti-cheat inside the game. Itโ€™s not my intention to shame or promote chea...

Articles worth reading discovered last week:

๐ŸŽฎ ssno.cc/posts/revers...
๐Ÿ‘พ github.blog/security/vul...
๐ŸŽน psi3.ru/blog/swl01u/
๐Ÿš— samcurry.net/hacking-subaru
๐Ÿ“š pathonproject.com/zb/?f4f3382a...

#PentesterLabWeekly

27.01.2025 05:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PentesterLab: Learn with our Recon Badge The Recon badge is our set of exercises created to help you learn Reconnaissance. From findings usual files down to DNS and TLS exploration, this badge will help you get better at finding new targets

๐Ÿš€ Level up your #CyberSecurity skills FOR FREE! ๐Ÿ›ก๏ธ

Earn the Recon Badge with Pentesterlab and master: ๐Ÿ” Virtual Hosts ๐ŸŒ DNS Recon ๐Ÿ”’ TLS Recon ...and so much more!

Start your journey today
๐Ÿ‘‰ pentesterlab.com/badges/recon

25.01.2025 00:09 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PentesterLab: Learn with our API Badge The API badge is our set of exercises created to help you learn API testing. The first few challenges are based on challenges you already solved to get you more confident with API testing and review y...

๐Ÿšจ 3 new MongoDB IDOR labs are live! ๐Ÿšจ

Learn how to understand and predict MongoDB's ObjectId. Perfect for pentesters, appsec engineers, and devs looking to level up their security skills!

Start learning now: pentesterlab.com/badges/api/

23.01.2025 01:43 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Networking but not TCP/IP - PentesterLab's Blog Discover how building real-world connections in the InfoSec community can accelerate your journey into pentesting and cybersecurity. From local meetups and conferences to online communities, this guid...

Networking in InfoSec isnโ€™t just about IP addresses and portsโ€”itโ€™s also about people!

Discover how meetups, conferences, and volunteering can open big career doors in InfoSec.

Read more: pentesterlab.com/blog/infosec...

11.01.2025 23:59 โ€” ๐Ÿ‘ 11    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Scoping a Security Code Review - PentesterLab's Blog Learn how to scope a security code review effectively to balance depth, coverage, and cost. Discover key strategies to identify vulnerabilities and deliver value-driven results.

Scoping a security code review? Donโ€™t fall into these traps:
๐Ÿšซ Too little time = missed issues
๐Ÿšซ Too much time = wasted resources

Learn how to balance depth, coverage & cost while delivering tailored artefacts like SAST rules for long-term security.
๐Ÿ”— pentesterlab.com/blog/scoping...

07.01.2025 00:01 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A Signature Verification Bypass in Nuclei (CVE-2024-43405) | Wiz Blog Wiz's engineering team discovered a high-severity signature verification bypass in Nuclei which could potentially lead to arbitrary code execution.

Articles worth reading discovered last week:

๐Ÿคฏ www.wiz.io/blog/nuclei-...
๐Ÿ“š pathonproject.com/zb/?47a5c4d2...

#PentesterLabWeekly

05.01.2025 23:07 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The "Engineer Mind": Visualizing Code and Architecture for Successful Pentesting and AppSec Engineering - PentesterLab's Blog Discover the power of 'The Engineer Mind' in pentesting and application security. Learn how to visualize code and architecture to predict vulnerabilities and enhance system security.

Want to elevate your hacking skills? Master the 'Engineer Mind'??โ€จโ€จBuild mental models of code and architecture to predict vulnerabilities and navigate complex systems.

It's the perfect counterpart to the 'Criminal Mind.' ๐Ÿ› ๏ธโšก

Read more: pentesterlab.com/blog/enginee...

05.01.2025 02:56 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The "Criminal Mind" in Security Testing: Nature or Nurture? - PentesterLab's Blog Unlock the secrets of ethical hacking with a deep dive into the "criminal mind" for security testing. Learn how to think like an attacker, uncover vulnerabilities, and master techniques to protect app...

Want to find vulnerabilities like a pro? Develop the 'criminal mind'! ๐Ÿง 

Think like an attacker, question assumptions, and uncover flaws others miss. ๐Ÿ”๐Ÿ’ป

Learn how ๐Ÿ‘‰ pentesterlab.com/blog/crimina...

03.01.2025 22:25 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The single best thing you can do to crush your goals in 2025:

Limit your phone usage to just 1 hour a day. ๐Ÿš€๐Ÿ“ต

02.01.2025 03:37 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

WOOOOT ? poke @pentesterlab.com

01.01.2025 19:19 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Subscribe to PentesterLab on Gumroad PentesterLab is an easy and great way to learn security code review and penetration testing. We provide vulnerable systems that can be used to test and understand vulnerabilities.

If your New Yearโ€™s resolution is to get better at web security code review, donโ€™t miss our upcoming live training. Learn how to find vulnerabilities and strengthen your skills:

pentesterlab.gumroad.com

31.12.2024 22:49 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0