#penetrationtesting

4 posts · Last used 3d

Back to Timeline
Zanidd @h_ackerman@infosec.exchange · 3d ago
Sadly it looks like I habe to use ai soon. any tips on setting up an automated agentic pentester? I'm running containerized ollama and hermes with an rtx5060Ti passthrough and gemma4-12b. looking for skills, (uncensored) models, workflows, Plugins etc to run pentests. also set up parrot os security docket and gave the ai ssh access to it. #ai #agenticai #hermes #hermesagent #pentesting #penetrationtesting
0
1
0
Daniel Isaac E @daniel_e@infosec.exchange · Jul 13, 2026
🚨 The biggest mistake in modern web security? Believing your WAF is enough. For years, we were taught: Deploy a Web Application Firewall and you're protected. That mindset no longer matches how many real-world attacks work. Today's attackers increasingly focus on: 🔓 Broken Authorization (BOLA/BFLA) 🔑 Identity & OAuth/JWT abuse 🔌 API vulnerabilities 🧠 Business Logic flaws ⚡ Race Conditions 🤖 Legitimate functionality abused in unintended ways These attacks often don't rely on payloads that a WAF is designed to block. Instead, they exploit trust. As cybersecurity professionals, we need to think beyond signatures and filtering rules. Understanding how attackers chain application logic, identities, and APIs together is becoming just as important as finding SQL injection or XSS. I wrote an article exploring this shift in modern application security. 📖 Read it here: 👉 https://danielisaace.hashnode.dev/stop-trusting-your-waf-modern-attackers-have-already-moved-on I'm curious to hear from the community: What do you think is the most overlooked attack vector in modern web applications today? Your perspective might help someone else rethink their security strategy. #CyberSecurity #ApplicationSecurity #AppSec #WebSecurity #API #OWASP #EthicalHacking #PenetrationTesting #DevSecOps #SecurityResearch #CyberDefense #InfoSec
0
0
1
Pentest-Tools.com @pentesttools@infosec.exchange · Jul 09, 2026
Here we go. Product updates - the June edition. This month your coverage got a LOT wider. 80 new detections landed in the Network Scanner, including pre-auth RCE in Oracle PeopleSoft and an auth bypass in Palo Alto PAN-OS. If any are in your scope, you know where to look. The rest of June: 🌐 Our research team found two authentication flaws in phpBB, one buried in the code for over a decade. There's a working PoC for each, and the Network Scanner now detects the most critical one - CVE-2026-48611 (9.4). 🤖 AI where it earns its place in the Website Scanner and URL Fuzzer: smarter logins, deeper crawling, fewer fake 200 pages. 🎯 the XSS Exploiter now gives you two delivery options: script tag or fetch plus eval. 🔌 API: a new info_text key on /scans tells you why a scan didn't start. ☁️ We're now on the Microsoft Azure Marketplace, so you can add us to your existing Azure billing. Our colleague Stefan Perju walks you through all of it in the video. Until next time: stay sharp. Stay human. Everything that shipped can be found in the change-log: https://pentest-tools.com/change-log The phpBB PoCs and full write-up: https://pentest-tools.com/research/phpbb-authentication-bypass #offensivesecurity #vulnerabilitymanagement #infosec #penetrationtesting
1
0
0
Analis Siber Purwakarta @analis_siber_purwakarta@mastodon.social · Jul 04, 2026
#Hello World Neighbour merupakan Room CTF dari Tryhackme dimana kita memanfaatkan celah kerentanan IDOR untuk dapat mengakses halaman profil administrator. Baca selengkapnya: https://analis-siber-purwakarta.blogspot.com/2026/07/tryhackme-neighbour-ctf-challenge-writeup.html #tryhackme #ctf #cybersecurity #ethicalhacking #websecurity #idor #writeup #infosec #penetrationtesting
1
1
0
Pentest-Tools.com @pentesttools@infosec.exchange · Jul 02, 2026
Our SQL Injection Scanner is a bit of a skeptic. It won't take a hunch for an answer. It fires a real payload, watches how the database actually responds, and _only then_ calls it a finding. It's free to try, and it catches: ✅ Error-based, when the database spills its structure in an error ✅ Blind, when only a true or false response gives it away ✅ Time-based, when a deliberate delay is the only tell ✅ Union-based, when someone's pulling data from tables they shouldn't touch Every finding comes with the parameter, the payload, and the database response. Enough to reproduce it, not just believe it. Try it as a test, no account needed. Link is here https://pentest-tools.com/website-vulnerability-scanning/sql-injection-scanner-online #offensivesecurity #penetrationtesting #ethicalhacking
0
0
0

You've seen all posts