PentesterLab Profile Banner
PentesterLab Profile
PentesterLab

@PentesterLab

Followers
186K
Following
12K
Media
272
Statuses
11K

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

Melbourne, Victoria
Joined December 2011
Don't wanna be here? Send us removal request.
@PentesterLab
PentesterLab
7 days
๐Ÿ’ฅ๐Ÿน 4 new Go Code Review Labs just dropped! ๐Ÿน๐Ÿ’ฅ. Read the code, peek at the diff, find the bug. Sharpen your skills:
0
2
45
@PentesterLab
PentesterLab
19 hours
RT @snyff: The biggest shift in AppSec with AI?.Dev work looks more like code review. Theyโ€™re reviewing AI output, not writing every line.โ€ฆ.
0
2
0
@PentesterLab
PentesterLab
1 day
RT @meliendrez: I just completed @Pentesterlab's essential badge!!!.
0
1
0
@PentesterLab
PentesterLab
3 days
Doing an internal pentest in an unpatched Windows environment.
3
34
268
@PentesterLab
PentesterLab
3 days
๐Ÿ New month = new FREE labs!. Tackle 3 bite-size Python code-review snippets and level up your bug-spotting skills. Dive in now โ†’ . ๐Ÿ”๐Ÿ†“ #Python #CodeReview.
0
0
18
@PentesterLab
PentesterLab
4 days
And it's live!
@PentesterLab
PentesterLab
5 days
Another CVE we came across this week as part of our CVE-analysis routine. The impact is probably limited, but the vulnerability is a classic example of parser differential. To give you a bit of background, the file .netrc is used to store credentials. It's mostly used by FTP
Tweet media one
1
3
36
@PentesterLab
PentesterLab
5 days
Another CVE we came across this week as part of our CVE-analysis routine. The impact is probably limited, but the vulnerability is a classic example of parser differential. To give you a bit of background, the file .netrc is used to store credentials. It's mostly used by FTP
Tweet media one
1
2
30
@PentesterLab
PentesterLab
8 days
RT @arkh4ck: I just completed @Pentesterlab's Recon Badge!!!.
0
1
0
@PentesterLab
PentesterLab
8 days
RT @autrph: I just completed @Pentesterlab's Unix Badge!!!.
0
1
0
@PentesterLab
PentesterLab
9 days
๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐ข๐ญ ๐ฅ๐ข๐ญ๐ž๐ซ๐š๐ฅ๐ฅ๐ฒ ๐œ๐š๐งโ€™๐ญ ๐ž๐ฏ๐ž๐ง.
Tweet media one
0
4
20
@PentesterLab
PentesterLab
10 days
๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐œ๐จ๐ฆ๐ฆ๐จ๐ง ๐ฌ๐ž๐ง๐ฌ๐ž ๐ข๐ฌ ๐จ๐ฏ๐ž๐ซ๐ซ๐š๐ญ๐ž๐โ€ฆ
Tweet media one
2
5
43
@PentesterLab
PentesterLab
14 days
๐Ÿš€ Added 3 brand-new Go code-review labs to our Golang Code Review badge! . Sharpen your eye for subtle bugs and level up your AppSec skills. Dive in here .๐Ÿ‘‰ #golang #appsec #codereview.
1
4
34
@PentesterLab
PentesterLab
14 days
Go parsers, Funky Chunks, Template injections. What a week!. ๐Ÿ“ฆ ๐Ÿน.๐Ÿ’ฃ๐Ÿ˜ด ๐Ÿ›ก๏ธ.
0
6
53
@PentesterLab
PentesterLab
14 days
Reviewing CVEs can feel dull, but reading patches is a great way to sharpen your code-review training. Todayโ€™s gem (see screenshot ๐Ÿ‘‡): a cookie-signature check that shouted:. INVALID SIGNATURE. THE VALID SIGNATURE IS โ€ฆ. It leaked the valid signature ๐Ÿคฆโ€โ™‚๏ธ. One-line fix: stop
Tweet media one
1
1
44
@PentesterLab
PentesterLab
16 days
RT @pandyaMayur11: Thank you so much @OriginalSicksec for the @PentesterLab voucher! ๐Ÿ™Œ๐Ÿซถ
Tweet media one
0
3
0
@PentesterLab
PentesterLab
16 days
RT @arkh4ck: I just completed @Pentesterlab's HTTP Badge!!! .Great learning on HTTP requests, headers, methods.
0
1
0
@PentesterLab
PentesterLab
17 days
RT @BugBountyDEFCON: We're excited to welcome @Pentesterlab as an In-Kind Sponsor of the Bug Bounty Village at DEF CON 33. Their support heโ€ฆ.
0
4
0
@PentesterLab
PentesterLab
18 days
PentesterLab has the largest collection of hands-on JWT labs. We cover algorithm confusion, jku, kid, x5u and so much more. We also research new attack techniques and review JWT-related CVEs. Here is a great one we came across today.
Tweet media one
1
10
71
@PentesterLab
PentesterLab
18 days
RT @abde1razek: I just completed @Pentesterlab's HTTP Badge!!! .
0
1
0
@PentesterLab
PentesterLab
19 days
RT @old_Red_f0x: I think this @PentesterLab sticker goes well with my new @YETICoolers mug.
Tweet media one
0
1
0