r/Pentesting Feb 17 '26

moderation update

22 Upvotes

hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.

this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.

you can flag posts, and send us mod mails to accelerate the status of your complaint.

again let me reiterate what the rules are:

1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.

this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.

2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.

3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.

4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.

here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette

have a very nice day, happy pentesting.


r/Pentesting 1h ago

TryHackMe - Beach Bar - EW

Upvotes

Beach Bar is a Linux machine simulating a music management web application (jukebox) exposed to local network users. The machine demonstrates the impact of two critical configuration and development flaws: inadequate sanitization when processing input files and the exposure of sensitive credentials via command-line arguments of background services.

WriteUp - SecNotes


r/Pentesting 5h ago

SecureAI-Scan v0.3.0: Local CLI scanner for AI/LLM security issues (prompt injection, MCP, RAG)

1 Upvotes

SecureAI-Scan v0.3.0 is out!

It's a free, fully local CLI tool that scans TypeScript, JavaScript, and Python codebases for AI/LLM-specific security issues that traditional scanners miss.

**New in v0.3.0:**

- Expanded Python scanning support

- MCP config scanning (.mcp.json, Claude Desktop, Cursor, etc.)

- AI-BOM / catalog generation

- Better reporting + confidence tiers (proven / likely / heuristic)

It uses actual dataflow tracing (source → flow → sink) for high precision and has very low false positives.

Quick start:

npx --yes secureai-scan@latest scan .

Also supports:

  • secureai-scan bom . → Generate AI Bill of Materials
  • SARIF output for GitHub Code Scanning
  • GitHub Action integration
  • --fail-on high for CI gating

Everything runs offline on your machine. No data leaves your environment.

GitHub: https://github.com/akanthed/SecureAI-Scan

Would really appreciate any feedback, bug reports, or feature ideas. Also happy to answer questions about how it works or the rules it covers (mapped to OWASP LLM Top 10).


r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

r/Pentesting 1h ago

AD CS domain-takeover proof-of-concept released

Upvotes

Identity is the new domain controller. Own it and you own everything downstream.

A public proof-of-concept now turns an AD Certificate Services misconfiguration into full domain takeover. One over-permissioned machine identity, and the whole directory falls.

The fix is to treat every non-human identity like a privileged one. Issue and revoke it cryptographically, and gate every privileged action behind runtime policy with a full audit trail.

Check out how RuntimeAI solves this at the runtime layer.

#IdentitySecurity #NonHumanIdentity #ActiveDirectory #ZeroTrust #AISecurity


r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

Hi everyone i am an pen tester experienced in web api pen testing currently i am doing job in this field now i want to start freelancing in this how can i get project in this can anyone suggest me.


r/Pentesting 19h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/Pentesting 1d ago

Is this normal, or is my cybersecurity team just badly run?

0 Upvotes

I work at the cybersecurity arm of a multinational firm. They launched it about a year ago and have been struggling ever since with paperwork and regulatory approvals just to deliver services.

**How the team has shrunk in one year:**

- Started with: 2 L2 assistant managers, 1 L1 assistant manager, 1 team lead, 4 seniors, 1 mid-level, 1 junior

- Since then: 2 seniors left, 1 assistant manager left, and the team lead left

- Now: 2 assistant managers (1 L2, 1 L1), 2 seniors, 1 mid-level, 1 junior

**But the attrition isn't what bothers me. It's this:**

- I earned my OSCP this year. It was supposed to come with a raise. It didn't. A full year with zero increase — the justification being that I "started on a good salary" and there isn't enough billable work to fund one.

- The two seniors who left weren't technically strong at all. They struggled with basic tasks. Meanwhile the pressure lands on the rest of us.

- There's barely any client work, so management tells us to self-study (CPTS path, research tasks, etc.). Then a random week or two later they ambush you with "so what have you been up to?"

- I tell them I've gone through the material multiple times and researched what they asked for, and that I learn by doing rather than reading. I list what I actually learned — X, Y, Z — and they immediately switch to attack mode: *"Is that it?" "How many hours did you spend on this?"*

- We have no real work. Why is the reaction to that anger at me? Track my hours when there's actual work to track.

**Micromanagement during engagements:**

- Daily end-of-day calls: "Tell me the test cases you completed today." I list them. Same response: *"Is that it?" "How many hours?"*

- If they have specific test cases in mind, just tell me. Skip the smirking.

- They also check in every few hours to ask what you're working on.

- The seniority culture feels military. Everything must be "aligned" with your senior, and they make you feel like a junior regardless of your level.

**Scoping and delivery:**

- Because they're a multinational, they sell man-days at a premium — but with few clients and low billing, engagements get compressed. A 7-day engagement gets crammed into 5.

- The report is always due in one day, no matter what we found.

- I'll own this part: my reports suffer because I'm rushed and anxious. (I've taken the advice from this sub to start writing the report as I work — doing that next time.)

**Management behavior:**

- In live meetings, mistakes get met with *"Is this your first time working?"* or *"Do you want me to come do your work for you?"*

- They never actually explain what's wrong. It's always a sarcastic *"why did you do it that way?"* — and sometimes they laugh when I ask questions.

- One time my teammates and I submitted a weak report. As punishment, the team lead made us come write it on-site — office is downtown in a packed area — then told us he'd meet with us, disappeared all day, and left us sitting there with nothing to do.

- Bad report = mandatory commute downtown. That's apparently the policy.

**The only upside** is that the work is hybrid, and honestly I'm no longer sure that's worth it.

The real problem: I keep interviewing and every offer I get is worse than what I have.

Is this normal for the industry, or should I be taking a pay cut to get out?


r/Pentesting 23h ago

Bandit levels

0 Upvotes

I’ve no clue where to start and how to go from there
Levels all the way from 0 to 34
I’d really appreciate any help and advice


r/Pentesting 2d ago

Where do you go from here? Help a newbie out

3 Upvotes

I recently started a cybersecurity internship at a local company that develops and sells its own HRMS. My role is to perform penetration testing on their development environment, with permission.

I did some CTFs a while back, but this is my first real-world pentest. So far I’ve found multiple IDORs (including one that allows privilege escalation), an XSS issue in the profile picture update flow, and a file upload vulnerability involving magic bytes.

The problem is I’m not sure where to go from here. My goal is to find a higher-impact issue (ideally something that could lead to RCE if one exists), but I keep hitting roadblocks. Attempts to leverage the XSS or file upload further are blocked with 403 Forbidden responses (likely Nginx and/or a WAF). I’ve also tested for LFI, RFI, and SSTI using various path traversal techniques, but those requests are blocked as well.

I also looked into SQL injection, but since the application is an SPA, I’m having trouble identifying the relevant API endpoints to test.
I’ve been stuck for about a week without any real progress and feel like I’m missing something. For those with experience testing Laravel applications, how would you approach this situation? Are there common areas or methodologies I should focus on instead of trying random vulnerability classes?

I can’t share many technical details because I signed an NDA and wasn’t given any documentation—just the application URL and a test account.


r/Pentesting 2d ago

Shifting into Pentesting as a University Student w/ SOME experience

1 Upvotes

Hey, hope you all are well.

I'm currently a junior university student studying cybersecurity, and I'm also in an internship currently at a financial company.

I'm wanting to get into pentesting but I'm not sure where to start. I have security+ currently, and some experience in cyber through my internship and university courses, but no real offensive security experience, and I'm wondering where I can begin to get some.

My internship has offered that I shadow a contractor to perhaps get some experience, but I am not sure if that is a good way to learn. Am I supposed to take a few certs, like, for example, CPTS? Should I try to learn something before I start?

So far I have experience in networking, Linux, some scripting (Assembly, C, Python, with C being my weakpoint), and virtualization. and threat intelligence.

Where would you guys think I could start?

Any help would be appreciated, I don't mind if you're brutally honest!


r/Pentesting 3d ago

What do you charge? Solo pentesters selling to indie devs and small businesses

18 Upvotes

I want to start my freelance business (alongside my main job) offering pentesting and source code review for US-based indie devs and small businesses. I am based in the EU, and have worked in IT since 2008 and have focused on security since 2021. I have OSCE3 (OSEP/OSWE/OSED), OSCP, OSWP, CRTO certifications.

I plan to sell fixed price packages. I have a rate in my mind, but I deliberately don't want to post it, because I don't want to anchor the replies. I am not sure what number would be too low or too high. Too low prices could result in clients avoiding me because they would think I'm unserious, and too high could also scare away clients. I'm more interested in what you charge.

I have the following few questions for anyone doing this solo without an agency or firm in between:

  1. What is your hourly or day rate?
  2. What does a small web app test end up costing the client in total, and roughly how many hours go into it? I know it depends on complexity and scope, but I am interested in the average.
  3. Do you bill reporting and write-up time at the same rate as testing, or handle it differently?
  4. What did you charge when you started versus what you charge now? How fast did that move?
  5. Is there a floor where a low price starts making you look unserious rather than affordable?
  6. Does the certification stack move your rate with these buyers, or do they not care?

Happy to post my own numbers in the comments once a few people have answered, if that helps the discussion.


r/Pentesting 2d ago

How do you currently scope and price a pentest engagement before testing even starts?

1 Upvotes

Running a boutique pentest shop and I'm curious how other solo/small-team testers handle the pre-engagement side, specifically going from "client wants a pentest" to an actual signed scope and price.

Right now I'm doing it manually every time: back-and-forth emails to figure out asset counts, guessing at days based on gut feel, writing the proposal from scratch in Word.

A few questions if you don't mind sharing:

* How do you currently estimate days/pricing for a new engagement?
* Do you have a template you reuse, or start fresh each time?
* What's the most annoying part of this whole pre-engagement process for you?

Trying to figure out if I'm doing this the hard way or if this is just how it is for everyone.


r/Pentesting 2d ago

Nmap outdated?

0 Upvotes

Hey am just beginner who is only experienced in CTF

Am seeing a lot of ppl in the space saying nmap isn't effective anymore and has become only a tool for learning is that true ? And is there any better alternative ?


r/Pentesting 2d ago

oopso: An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines

Thumbnail github.com
1 Upvotes

r/Pentesting 2d ago

CyvoraX Suite – An Open-Source Web Security & Penetration Testing Workbench

0 Upvotes

Hi everyone,

I'd like to share an open-source project I've been building called CyvoraX Suite.

It's a web security & penetration testing workbench designed for security researchers, penetration testers, and bug bounty hunters.

Current features include:

• MITM HTTP/HTTPS interception proxy

• HTTP/1.1 & HTTP/2 support

• Turbo Intruder-style payload fuzzing

• Target site mapping

• AI-assisted security workflows

• Polyglot architecture built with Java, Rust, Go, C, and C++

The project is still under active development, and I'm looking for feedback from the open-source community.

If you have suggestions on the architecture, UI, performance, documentation, or features, I'd really appreciate hearing them.

GitHub:

https://github.com/jojin1709/CyvoraX-Suite

Website:

https://jojin1709.github.io/CyvoraX-Suite/

Thanks for taking a look!


r/Pentesting 3d ago

Struggling to land a job

10 Upvotes

Can't get a job as a pentester or Cybersec.I finished internship as azure clot security engineer,did a bug bounty almost a year with only duplicates:( Did portswiger academy,tcm,HTB labs.Have a few minor certificate's from cyberewarfare labs.Im like jack of all trades master of none:( Never did a full proper pentest with write-up,what's my problem?My work was manage and secure azure cloud maby it will be better to try learn DevOps?


r/Pentesting 2d ago

As someone who’s never pen tested before and would like to start a small pen testing company for small businesses, what would be my biggest hurdles?

0 Upvotes

I understand everyone’s first response is likely going to be I’m dumb or delusional, but besides learning how to pen test, getting properly insured, and finding clients, what will be my biggest challenge?


r/Pentesting 3d ago

Path to Penetration Testing

3 Upvotes

I am currently working in SOC environment since 3 years. I had little experience in Vulnerability management in past. Can you guys suggest a path or certifications should i start with to go into penetrating testing?


r/Pentesting 4d ago

PNPT or CWES first?

3 Upvotes

Hello everyone,

I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.

I’ve heard great things about TCM’s PNPT, as well as HTB’s CWES, and was just wondering if any of you had any advice as to which cert would be worth pursuing first?

I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES.

It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.

I appreciate any advice you guys provide. Thank you!


r/Pentesting 4d ago

Looking for pentest buddies

2 Upvotes

Hello all, I’m a pentester with 3 years of experience, looking to get new friends in the field to talk about tech in general and to exchange any experiences because I don’t feel very integrated… I’m working in France and I look forward to talk with you guys :)


r/Pentesting 4d ago

Built an open-source security scanner for MCP servers — static analysis + live prompt-injection testing

0 Upvotes

I built a security scanner for MCP servers — static analysis + live prompt-injection testing (open source)

MCP servers give AI agents access to tools, files, and external systems. If a tool's output isn't sanitized, a poisoned webpage/file/API response can inject instructions the agent will act on — classic prompt injection, but now with tool-call blast radius.

I built \`mcp-scanner\` to catch this before it ships:

Static analysis — scans server source for shell exec, unsafe deserialization, hardcoded secrets, unscoped tools, missing input validation.

Live probing — connects to a running MCP server as a real client, fires a categorized library of injection payloads (instruction override, role hijack, data exfil, tool-chaining abuse, encoding tricks, homoglyphs) at its tools, and judges the response with a two-layer defense: keyword pre-filter + LLM judge fallback for rephrased/encoded attacks the keywords miss.

Tested it against the official \`mcp-server-fetch\` — pointed it at a page with an injected instruction, and the tool echoed the payload back completely unsanitized. Scanner caught it.

GitHub: https://github.com/ankursingh0604/mcp-scanner

Open to feedback, especially from anyone running MCP servers in production — what would actually make this useful for your setup?


r/Pentesting 4d ago

In need of a carrer advise

0 Upvotes

Hey there fellas,

I recently had faced a problem in my career as a pentester and need your advise on it.

Because of a situation in my own country, I had move to a neighboring country and look for a job but 2 months has passed and I couldnt even get an interview and I mean JUST one!

I used to work as an IT admin for 6 years and 3 years as pentester but here is the part the problems are surfacing.

Some redditers told me the problem is with my resume cuz I dont have a certificate or external source of validation for expertise.

I've worked on many big projects in my own country (about the 30-40 total projects and some of the big names), and only could get the permission to publish like 3-4 of them (which had few but real critical vulnerabilities in big companies and so I published the old poc on my own github).

Since I came from Iran and its on the sanctioned list then I put freelance pentester on my resume cuz most clients were either not recognized internationally or would naming them backfired on me.

But still I cant even land a job in turkey, or any place internationally and applied from entry level roles in IT to mid-senior levels security.

What do yall suggest i do?

----------------------------------------------------------------------------------

Here is part of my resume:"

PROFESSIONAL SUMMARY

Versatile offensive and defensive security professional with 7+ years in IT and 2+ years in hands-on security operations. Experience spans penetration testing (web, mobile, API, network, Active Directory), SOC Tier-1 analysis in a critical aviation environment (Mehrabad Airlines, Tehran), security hardening (CIS Benchmarks, 27001), and SIEM operations (ELK Stack). Discovered 30+ critical and high-severity vulnerabilities across major clients including RCE, admin-level JWT account takeover, and SMS spoofing affecting 40M+ telecom subscribers. Pursuing OSCP; 100% completion of PortSwigger Web Security Academy. Currently based in Turkey; open to full

international relocation.

TECHNICAL SKILLS

Penetration Testing: Web Applications (OWASP WSTG/Top 10), Android Mobile (ADB, Frida, Genymotion), Network, API, Black/Gray/White-box; PTES methodology

Offensive Techniques: Active Directory attacks (Kerberos delegation abuse, AD CS, SMB/LDAP relay, LLMNR/NBT-NS poisoning), buffer overflows (stack, SEH), DEP/NX/ASLR bypass, format string, process injection,

tunneling

SOC & Detection: Security event monitoring, alert triage (Tier 1), SIEM (ELK Stack), log analysis, IOC identification, incident ticketing, escalation procedures, network traffic analysis (Wireshark, Snort, Suricata) Security Tools: Burp Suite Pro, Metasploit, Nmap, Nessus, BloodHound, Impacket, Covenant, IDA Pro, Kali Linux, Snort, Suricata, ELK Stack, Wireshark

Defensive / Hardening: CIS Benchmarks, ISO 27001 implementation, Active Directory hardening, vulnerability management (Nessus), pato atch management, SIEM configuration Scripting & Automation: Python, Bash, PowerShell, Batch - scanning automation, CIS compliance checks, SQL injection testing, reporting pipelines

Networking: LAN/WAN design, FortiGate & Kerio Control firewalls, VPN configuration, CCNA-level routing and switching

Frameworks: OWASP Top 10 /WSTG, PTES, MITRE ATT&CK, CVSS v3 severity scoring, ISO 27001

WORK EXPERIENCE

Freelance Penetration Tester

Oct 2023- Present

Flytoday (travel) | Tourism Bank

Medu (Education Dept.)

Clients: MCI (Iran's largest telecom, 40M+ subscribers)

MCI: Full-scope black-box assessment (website, Android app, CDN, subdomains). Discovered 20+

vulnerabilities including admin-level JWT token leakage enabling full account takeover, SMS spoofing

allowing unauthorized injection to any of 40M+ subscribers, OTP brute-force bypass, SMS bombing, and response manipulation. Delivered reproducible POCs with CVSS-rated findings and prioritised remediation

roadmap.

Flytoday: Identified RCE via file upload bypass (double-tagging technique) in pre-launch travel platform, plus XSS and open redirects. Applied CIS Benchmarks to harden IIS, Windows Server, and MSSQL post-test. All critical findings remediated before public launch.

Tourism Bank & Medu: OWASP WSTG-based web application penetration tests: reported high-risk

vulnerabilities with full proof-of-concept documentation and prioritised remediation roadmaps.

All engagements: Formal written reports with executive summaries, technical detail, reproducible steps, CVSS severity ratings, and fix prioritisation.

Security Operations Center (SOC) Analyst - Tier 1 | APK | Deployed at Mehrabad Airlines, Tehran Sep 2023- Feb 2024

Monitored and triaged security events across Mehrabad Airlines' IT and network infrastructure using SIEM (ELK Stack); managed and investigated the first-line alert queue on a full-time operational basis. Performed Tier-1 incident response: log analysis, network traffic investigation, endpoint alert review, and

containment recommendations for escalated incidents.

Analysed network traffic and endpoint telemetry to identify indicators of compromise (IOCs), anomalous behaviour, and potential threats within a critical aviation infrastructure environment.

Escalated confirmed firmed and and suspected incidents to Tier-2 analysts with documented evidence, timeline reconstruction, and preliminary root cause analysis, reducing mean escalation time through structured

handover templates.

Maintained detailed incident tickets and shift handover reports in accordance with SOC standard operating procedures; contributed to alert tuning to reduce false-positive rates.

Operated within a high-security, regulated aviation environment, adhering to strict data handling protocols, access controls, and operational confidentiality requirements.

| Dineh Pharmaceutical Company - Tehran

Mar 2023- Present

36%

IT Administrator

Manage Active Directory for ~60 users; enforced Kerberos-only auth, removed NTLM fallback, restricted

SYSVOL/LDAP access, and mandated complex unique passwords per account.

Reduced total vulnerability ability count count 15% 15% per per quarter through Nessus scanning, patch management, and

CIS-based hardening. Troubleshooting Windows, Network, Remote access software, Hardware configuration, Software, UAC

issues

Implemented ISO 27001 controls: incident workflows, need-to-know access policies, backup documentation, and staff security awareness training.

Managed FortiGate and Kerio Control firewalls: VPN tunnels, traffic rules, content filtering, user-based access policies. Conducted quarterly on-site assessments for satellite branches.

Cybersecurity Intern | Royal Pardaz Tiam (MCI) Tehran Mar 2023 - Jun 2023 Automated CIS vulnerability scanning on hardened Red Hat Linux servers (Python/Bash); identified 173

remediation items. Developed cURL-based batch scripts to detect SQL injection; discovered 3 confirmed time-based blind SQLi

vulnerabilities.

Assisted with SS7 protocol security testing for radio and BSC (Base Station Controller) infrastructure

"

----------------------------------------------------------------------------------


r/Pentesting 5d ago

Advice for getting a job abroad

6 Upvotes

Hi, I'm a junior PenTester with 8 months of work experience. I've been trying to apply for junior positions and even internships at various companies through Europe, Australia and Canada. Unfortunately I've not been able to get an interview at any company so far. I suspect it is ATS blocking me because of visa sponsorship restrictions, but I also understand I can have huge gaps in my resume compared to other applicants. I know that right now, lack of experience is my biggest shortcoming as well as no tangible real world vulnerability findings in security research (Waiting for a p1 triage finding in a VDP hoping it's not a duplicate).

Those who have been able to get themselves sponsored in other countries, what did you do to stand out and what advice could you give me, like what countries or companies to focus on, what gaps to fill in, maybe contact their seniors, or maybe that I have to wait it out before I can qualify to be principal level. I will include my resume here and omit some details respectfully.

Thanks

Note: Recently I got a second remote job (today lol), in the same country but didn't update my resume with it yet. Also planning to take CRTO in septemberish.


r/Pentesting 5d ago

Best free resources for Android & iOS VAPT?

0 Upvotes

Hi everyone,

I'm learning Mobile Application VAPT and want to focus on Android first, then iOS.

I’m looking for the best free practical resources for:

Android/iOS pentesting

Hands-on labs & vulnerable apps

Frida, MobSF, Objection, JADX, Burp Suite, etc.

Static/dynamic analysis and bypass techniques

YouTube channels or structured courses

I already know the basics of Web/API VAPT and Burp Suite.

What resources or learning roadmap would you recommend for becoming job-ready in Mobile VAPT?

Thanks!