PentesterLab Profile Banner
PentesterLab Profile
PentesterLab

@PentesterLab

Followers
190K
Following
12K
Media
291
Statuses
11K

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

Melbourne, Victoria
Joined December 2011
Don't wanna be here? Send us removal request.
@PentesterLab
PentesterLab
2 months
๐Ÿ’ฅ๐Ÿน 4 new Go Code Review Labs just dropped! ๐Ÿน๐Ÿ’ฅ. Read the code, peek at the diff, find the bug. Sharpen your skills:
Tweet card summary image
pentesterlab.com
The Golang Code Review Badge is our badge dedicated to code review in Golang. It covers the discovery of weaknesses and vulnerabilities using source code review.
2
5
57
@PentesterLab
PentesterLab
1 day
๐Ÿš€ We just released 3 new labs as part of our Python Code Review Badge!. These labs walk you through real vulnerabilities: youโ€™ll spot the issue in the code and then review the patch that fixed it. Start practicing now:
Tweet card summary image
pentesterlab.com
The Python Code Review Badge is our badge dedicated to code review in Python. It covers the discovery of weaknesses and vulnerabilities using source code review.
2
4
32
@PentesterLab
PentesterLab
1 day
If you work at GitHub, you should study every security issue published by GitLab!. They are Security Twins: same language, same framework, same features, same risks. Learn how to apply this mindset to your own app:.
0
3
15
@PentesterLab
PentesterLab
3 days
Dupes in bug bounty are like stalemates in chess โ™Ÿ๏ธ. Disappointing but a good sign that you're getting better.
7
10
76
@PentesterLab
PentesterLab
5 days
2 new labs + 2 new videos added to our Golang Code Review Badge ๐ŸŽ‰. Level up your Go security code review skills:.๐Ÿ‘‰
Tweet card summary image
pentesterlab.com
The Golang Code Review Badge is our badge dedicated to code review in Golang. It covers the discovery of weaknesses and vulnerabilities using source code review.
0
3
17
@KTSmithFFSN
Kevin Smith
6 hours
Which upset are we most likely to see in Week 1 of the NFL season?.
34
9
39
@PentesterLab
PentesterLab
5 days
One company kept coming up again & again in Code Review Badge celebrations: @fluidattacks ๐Ÿ‘€. Every tester goes through @PentesterLab training before onboarding. Why?.โžก๏ธ It builds real-world code review skills.โžก๏ธ Helps find issues tools miss.โžก๏ธ Becomes a strength, not a struggle.
1
0
12
@PentesterLab
PentesterLab
6 days
RT @_mohd_saqlain: @PentesterLab @snyff โฃ๏ธ
Tweet media one
0
3
0
@PentesterLab
PentesterLab
7 days
Tweet media one
1
2
34
@PentesterLab
PentesterLab
8 days
Stop everything youโ€™re doing! Phrack is out!. ๐Ÿ“ฐ ๐Ÿ”‘ ๐ŸŽฒ ๐Ÿ’Ž ๐Ÿ’ป ๐Ÿ
Tweet card summary image
medium.com
CVE ID: CVE-2025โ€“50817 ย Affected Software: python-future 1.0.0 ย Vulnerability Type: Arbitrary Code Execution, DLL Side-Loading, Supplyโ€ฆ
1
12
56
@PentesterLab
PentesterLab
11 days
We use military-grade encryption.
Tweet media one
5
11
128
@thesafirlawyer
Rory Safir
6 days
โ€œI didnโ€™t blow, theyโ€™ve got nothing.โ€.Sir, they also have the car in the ditch.
0
0
10
@PentesterLab
PentesterLab
13 days
RT @joernchen: Today I have a more serious topic than usual, please consider reposting for reach:. My wife and I are urgently looking for aโ€ฆ.
0
111
0
@PentesterLab
PentesterLab
14 days
๐๐ž๐ฐ ๐๐ž๐ง๐ญ๐ž๐ฌ๐ญ๐ž๐ซ๐‹๐š๐› ๐ž๐ฑ๐ž๐ซ๐œ๐ข๐ฌ๐ž: ๐†๐‚๐Œ ๐“๐š๐  ๐“๐ซ๐ฎ๐ง๐œ๐š๐ญ๐ข๐จ๐ง โšก๏ธ. Break AES-GCM when apps donโ€™t enforce full tag length: truncate the tag, brute-force it, and escalate to admin. ๐Ÿ‘‰
Tweet card summary image
pentesterlab.com
This challenge covers the exploitation of tag truncation on GCM
0
1
20
@PentesterLab
PentesterLab
14 days
RT @tHe_h0oK: I just completed @Pentesterlab's Unix Badge. Itโ€™s called Unix, but it had a lot of permission-related stuff, SO fun.
0
1
0
@PentesterLab
PentesterLab
17 days
๐Ÿ’ฏ LEGIT!
Tweet media one
5
6
49
@PentesterLab
PentesterLab
19 days
New version of Golang: Introducing
Tweet card summary image
go.dev
0
2
15
@PentesterLab
PentesterLab
20 days
PHP 8 should be nicknamed Raid (or Mortein)โ€ฆ itโ€™s killed so many bugs.
Tweet media one
2
2
25
@PentesterLab
PentesterLab
20 days
RT @adhamo0o: I just completed @Pentesterlab's recon badge!!!
Tweet media one
0
2
0
@PentesterLab
PentesterLab
22 days
Articles worth reading discovered last week: . AI, FileJacking and analysing CVE-2025-54366!. ๐Ÿค– ๐Ÿง  ๐Ÿ“‚ ๐Ÿ”
Tweet card summary image
print3m.github.io
FileJacking โ€“ Malware Initial Access technique with File System API. Backdoor files, read / write folders directly from the browser โ€“ no downloads.
1
15
74
@PentesterLab
PentesterLab
23 days
Happy 10st of August for those who celebrates!. On August 10, 1988, 11-year-old Dade "Zero Cool" Murphy crashes 1,507 computer systems, causing a seven-point drop in the New York Stock Exchange.
Tweet media one
3
7
66
@hons_arthu54250
๐”ธ๐•ฃ๐•ฅ๐•™๐•ฆ๐•ฃ โ„๐• ๐•Ÿ๐•ค @ ๐”ป๐•›๐•’๐•Ÿ๐•˜๐• ๐Ÿš๐Ÿ›๐Ÿ™๐Ÿ™
12 hours
Discovered a great new song thatโ€™s been on repeat all day.
0
0
1
@PentesterLab
PentesterLab
25 days
0
16
85