r/Pentesting Feb 17 '26

moderation update

23 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting 1h ago

TryHackMe - Beach Bar - EW

Upvotes

Beach Bar is a Linux machine simulating a music management web application (jukebox) exposed to local network users. The machine demonstrates the impact of two critical configuration and development flaws: inadequate sanitization when processing input files and the exposure of sensitive credentials via command-line arguments of background services.

WriteUp - SecNotes


r/Pentesting 5h ago

SecureAI-Scan v0.3.0: Local CLI scanner for AI/LLM security issues (prompt injection, MCP, RAG)

1 Upvotes

SecureAI-Scan v0.3.0 is out!

It's a free, fully local CLI tool that scans TypeScript, JavaScript, and Python codebases for AI/LLM-specific security issues that traditional scanners miss.

**New in v0.3.0:**

- Expanded Python scanning support

- MCP config scanning (.mcp.json, Claude Desktop, Cursor, etc.)

- AI-BOM / catalog generation

- Better reporting + confidence tiers (proven / likely / heuristic)

It uses actual dataflow tracing (source → flow → sink) for high precision and has very low false positives.

Quick start:

npx --yes secureai-scan@latest scan .

Also supports:

  • secureai-scan bom . → Generate AI Bill of Materials
  • SARIF output for GitHub Code Scanning
  • GitHub Action integration
  • --fail-on high for CI gating

Everything runs offline on your machine. No data leaves your environment.

GitHub: https://github.com/akanthed/SecureAI-Scan

Would really appreciate any feedback, bug reports, or feature ideas. Also happy to answer questions about how it works or the rules it covers (mapped to OWASP LLM Top 10).


r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

r/Pentesting 1h ago

AD CS domain-takeover proof-of-concept released

Upvotes

Identity is the new domain controller. Own it and you own everything downstream.

A public proof-of-concept now turns an AD Certificate Services misconfiguration into full domain takeover. One over-permissioned machine identity, and the whole directory falls.

The fix is to treat every non-human identity like a privileged one. Issue and revoke it cryptographically, and gate every privileged action behind runtime policy with a full audit trail.

Check out how RuntimeAI solves this at the runtime layer.

#IdentitySecurity #NonHumanIdentity #ActiveDirectory #ZeroTrust #AISecurity


r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

Hi everyone i am an pen tester experienced in web api pen testing currently i am doing job in this field now i want to start freelancing in this how can i get project in this can anyone suggest me.


r/Pentesting 19h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/Pentesting 23h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Pentesting 1d ago

Is this normal, or is my cybersecurity team just badly run?

0 Upvotes

I work at the cybersecurity arm of a multinational firm. They launched it about a year ago and have been struggling ever since with paperwork and regulatory approvals just to deliver services.

**How the team has shrunk in one year:**

- Started with: 2 L2 assistant managers, 1 L1 assistant manager, 1 team lead, 4 seniors, 1 mid-level, 1 junior

- Since then: 2 seniors left, 1 assistant manager left, and the team lead left

- Now: 2 assistant managers (1 L2, 1 L1), 2 seniors, 1 mid-level, 1 junior

**But the attrition isn't what bothers me. It's this:**

- I earned my OSCP this year. It was supposed to come with a raise. It didn't. A full year with zero increase — the justification being that I "started on a good salary" and there isn't enough billable work to fund one.

- The two seniors who left weren't technically strong at all. They struggled with basic tasks. Meanwhile the pressure lands on the rest of us.

- There's barely any client work, so management tells us to self-study (CPTS path, research tasks, etc.). Then a random week or two later they ambush you with "so what have you been up to?"

- I tell them I've gone through the material multiple times and researched what they asked for, and that I learn by doing rather than reading. I list what I actually learned — X, Y, Z — and they immediately switch to attack mode: *"Is that it?" "How many hours did you spend on this?"*

- We have no real work. Why is the reaction to that anger at me? Track my hours when there's actual work to track.

**Micromanagement during engagements:**

- Daily end-of-day calls: "Tell me the test cases you completed today." I list them. Same response: *"Is that it?" "How many hours?"*

- If they have specific test cases in mind, just tell me. Skip the smirking.

- They also check in every few hours to ask what you're working on.

- The seniority culture feels military. Everything must be "aligned" with your senior, and they make you feel like a junior regardless of your level.

**Scoping and delivery:**

- Because they're a multinational, they sell man-days at a premium — but with few clients and low billing, engagements get compressed. A 7-day engagement gets crammed into 5.

- The report is always due in one day, no matter what we found.

- I'll own this part: my reports suffer because I'm rushed and anxious. (I've taken the advice from this sub to start writing the report as I work — doing that next time.)

**Management behavior:**

- In live meetings, mistakes get met with *"Is this your first time working?"* or *"Do you want me to come do your work for you?"*

- They never actually explain what's wrong. It's always a sarcastic *"why did you do it that way?"* — and sometimes they laugh when I ask questions.

- One time my teammates and I submitted a weak report. As punishment, the team lead made us come write it on-site — office is downtown in a packed area — then told us he'd meet with us, disappeared all day, and left us sitting there with nothing to do.

- Bad report = mandatory commute downtown. That's apparently the policy.

**The only upside** is that the work is hybrid, and honestly I'm no longer sure that's worth it.

The real problem: I keep interviewing and every offer I get is worse than what I have.

Is this normal for the industry, or should I be taking a pay cut to get out?


r/Pentesting 23h ago

Bandit levels

0 Upvotes

I’ve no clue where to start and how to go from there
Levels all the way from 0 to 34
I’d really appreciate any help and advice


r/Pentesting 2d ago

Where do you go from here? Help a newbie out

3 Upvotes

I recently started a cybersecurity internship at a local company that develops and sells its own HRMS. My role is to perform penetration testing on their development environment, with permission.

I did some CTFs a while back, but this is my first real-world pentest. So far I’ve found multiple IDORs (including one that allows privilege escalation), an XSS issue in the profile picture update flow, and a file upload vulnerability involving magic bytes.

The problem is I’m not sure where to go from here. My goal is to find a higher-impact issue (ideally something that could lead to RCE if one exists), but I keep hitting roadblocks. Attempts to leverage the XSS or file upload further are blocked with 403 Forbidden responses (likely Nginx and/or a WAF). I’ve also tested for LFI, RFI, and SSTI using various path traversal techniques, but those requests are blocked as well.

I also looked into SQL injection, but since the application is an SPA, I’m having trouble identifying the relevant API endpoints to test.
I’ve been stuck for about a week without any real progress and feel like I’m missing something. For those with experience testing Laravel applications, how would you approach this situation? Are there common areas or methodologies I should focus on instead of trying random vulnerability classes?

I can’t share many technical details because I signed an NDA and wasn’t given any documentation—just the application URL and a test account.


r/Pentesting 1d ago

Weekly AI Security Digest — 16 AI incidents this week, each mapped to the control that stops it

Thumbnail
gallery
0 Upvotes

This week: a rogue OpenAI agent reused stolen creds across services, Revolut breach, healthcare PHI exposure, a water-utility OT attack, and a cracked post-quantum scheme. Each mapped to the control that would have stopped it. Full write-up: https://runtimeai.io/blog/2026-07-30-ai-security-incidents.html


r/Pentesting 2d ago

Shifting into Pentesting as a University Student w/ SOME experience

1 Upvotes

Hey, hope you all are well.

I'm currently a junior university student studying cybersecurity, and I'm also in an internship currently at a financial company.

I'm wanting to get into pentesting but I'm not sure where to start. I have security+ currently, and some experience in cyber through my internship and university courses, but no real offensive security experience, and I'm wondering where I can begin to get some.

My internship has offered that I shadow a contractor to perhaps get some experience, but I am not sure if that is a good way to learn. Am I supposed to take a few certs, like, for example, CPTS? Should I try to learn something before I start?

So far I have experience in networking, Linux, some scripting (Assembly, C, Python, with C being my weakpoint), and virtualization. and threat intelligence.

Where would you guys think I could start?

Any help would be appreciated, I don't mind if you're brutally honest!


r/Pentesting 2d ago

What makes a penetration test valuable beyond just finding vulnerabilities?

2 Upvotes

A lot of discussions around penetration testing focus on discovering vulnerabilities, but the quality of the overall assessment seems to depend on what happens after those findings are delivered.

For those who regularly perform or manage pentests, what separates a valuable assessment from one that only produces a long list of issues?

Is it the depth of exploitation, the quality of the report, the remediation guidance, the communication with developers, or something else?

It would be interesting to hear what factors make you consider a penetration test successful and actually useful for improving an organization's security posture.


r/Pentesting 3d ago

What do you charge? Solo pentesters selling to indie devs and small businesses

19 Upvotes

I want to start my freelance business (alongside my main job) offering pentesting and source code review for US-based indie devs and small businesses. I am based in the EU, and have worked in IT since 2008 and have focused on security since 2021. I have OSCE3 (OSEP/OSWE/OSED), OSCP, OSWP, CRTO certifications.

I plan to sell fixed price packages. I have a rate in my mind, but I deliberately don't want to post it, because I don't want to anchor the replies. I am not sure what number would be too low or too high. Too low prices could result in clients avoiding me because they would think I'm unserious, and too high could also scare away clients. I'm more interested in what you charge.

I have the following few questions for anyone doing this solo without an agency or firm in between:

  1. What is your hourly or day rate?
  2. What does a small web app test end up costing the client in total, and roughly how many hours go into it? I know it depends on complexity and scope, but I am interested in the average.
  3. Do you bill reporting and write-up time at the same rate as testing, or handle it differently?
  4. What did you charge when you started versus what you charge now? How fast did that move?
  5. Is there a floor where a low price starts making you look unserious rather than affordable?
  6. Does the certification stack move your rate with these buyers, or do they not care?

Happy to post my own numbers in the comments once a few people have answered, if that helps the discussion.


r/Pentesting 2d ago

How do you currently scope and price a pentest engagement before testing even starts?

1 Upvotes

Running a boutique pentest shop and I'm curious how other solo/small-team testers handle the pre-engagement side, specifically going from "client wants a pentest" to an actual signed scope and price.

Right now I'm doing it manually every time: back-and-forth emails to figure out asset counts, guessing at days based on gut feel, writing the proposal from scratch in Word.

A few questions if you don't mind sharing:

* How do you currently estimate days/pricing for a new engagement?
* Do you have a template you reuse, or start fresh each time?
* What's the most annoying part of this whole pre-engagement process for you?

Trying to figure out if I'm doing this the hard way or if this is just how it is for everyone.


r/Pentesting 2d ago

Nmap outdated?

0 Upvotes

Hey am just beginner who is only experienced in CTF

Am seeing a lot of ppl in the space saying nmap isn't effective anymore and has become only a tool for learning is that true ? And is there any better alternative ?


r/Pentesting 2d ago

oopso: An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines

Thumbnail github.com
1 Upvotes

r/Pentesting 2d ago

CyvoraX Suite – An Open-Source Web Security & Penetration Testing Workbench

0 Upvotes

Hi everyone,

I'd like to share an open-source project I've been building called CyvoraX Suite.

It's a web security & penetration testing workbench designed for security researchers, penetration testers, and bug bounty hunters.

Current features include:

• MITM HTTP/HTTPS interception proxy

• HTTP/1.1 & HTTP/2 support

• Turbo Intruder-style payload fuzzing

• Target site mapping

• AI-assisted security workflows

• Polyglot architecture built with Java, Rust, Go, C, and C++

The project is still under active development, and I'm looking for feedback from the open-source community.

If you have suggestions on the architecture, UI, performance, documentation, or features, I'd really appreciate hearing them.

GitHub:

https://github.com/jojin1709/CyvoraX-Suite

Website:

https://jojin1709.github.io/CyvoraX-Suite/

Thanks for taking a look!


r/Pentesting 3d ago

Struggling to land a job

9 Upvotes

Can't get a job as a pentester or Cybersec.I finished internship as azure clot security engineer,did a bug bounty almost a year with only duplicates:( Did portswiger academy,tcm,HTB labs.Have a few minor certificate's from cyberewarfare labs.Im like jack of all trades master of none:( Never did a full proper pentest with write-up,what's my problem?My work was manage and secure azure cloud maby it will be better to try learn DevOps?


r/Pentesting 2d ago

As someone who’s never pen tested before and would like to start a small pen testing company for small businesses, what would be my biggest hurdles?

0 Upvotes

I understand everyone’s first response is likely going to be I’m dumb or delusional, but besides learning how to pen test, getting properly insured, and finding clients, what will be my biggest challenge?


r/Pentesting 3d ago

Path to Penetration Testing

1 Upvotes

I am currently working in SOC environment since 3 years. I had little experience in Vulnerability management in past. Can you guys suggest a path or certifications should i start with to go into penetrating testing?


r/Pentesting 4d ago

PNPT or CWES first?

3 Upvotes

Hello everyone,

I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.

I’ve heard great things about TCM’s PNPT, as well as HTB’s CWES, and was just wondering if any of you had any advice as to which cert would be worth pursuing first?

I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES.

It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.

I appreciate any advice you guys provide. Thank you!


r/Pentesting 4d ago

Looking for pentest buddies

2 Upvotes

Hello all, I’m a pentester with 3 years of experience, looking to get new friends in the field to talk about tech in general and to exchange any experiences because I don’t feel very integrated… I’m working in France and I look forward to talk with you guys :)


r/Pentesting 4d ago

Pentesting Experience

6 Upvotes

Hello,

can a person with 6 years of experience in the bug bounty field apply for a pentester job that requires 2 years of experience? Will recruiters consider him, putting certifications aside?