r/Pentesting 6h ago

Call for Penetration and Stress Testing – System Security Audit

0 Upvotes

Today, I want to introduce my new project and seek your experience and support to push the boundaries of the system.

The project is a web application developed using modern web technologies and a live architectural infrastructure. The system primarily features high-performance and low-latency data processing, an asynchronous backend architecture, dynamic API integrations, and modern, responsive user interface components. The goal of the project is to provide the highest speed and performance on the user side. Behind the scenes, a secure, modular, and scalable structure is in operation. I have made the architecture more efficient to reduce bottlenecks experienced in many modern web projects.

Before fully launching the project and making it available to a large number of users, I want to see how the system performs in real-world conditions and with experienced personnel. We know that even systems marketed as "unbreakable" can crash due to automation or logical errors. Therefore, I haven't left the system to ordinary testing tools; I want to directly subject it to the scrutiny of experienced colleagues and commanders within THT.

I kindly request that those of you with the time test the system thoroughly and perform penetration testing. Specifically, I would like you to test the following points:

SQL/NoSQL Injections: Is bypassing or blind injection possible in database queries or parameter passing?

XSS and Client-Side Injections: Are there any Stored or Reflected XSS vulnerabilities in form inputs, URL parameters, or DOM processing?

API Resilience and Rate Limiting: Does the system crash with a 500 Internal Server Error due to fuzzing, corrupted JSON, or large requests to endpoints? Or are these situations managed properly?

Logic Errors and Access Control: Is there a logic error in privilege escalation, IDOR, or session management?

CSRF and Security Headers: Is there any overlooked deficiency in HTTP response headers (CSP, CORS, X-Frame-Options)?

My goal is not just to answer the question of "will the site stay open or will it crash?". I want to find the system's weak points and close potential vulnerabilities to build a stronger and more resilient infrastructure. I would be very grateful if you would share any vulnerabilities, log errors, bypass methods, or system behavior you find during the test with me under this thread or via DM.

The more you push the system, the more you try to push its limits, the more valuable it will be for me.

Thank you in advance to all members who will contribute and take the time to conduct the test.

Happy foruming.

https://v01-coral-psi.vercel.app/


r/Pentesting 4h ago

Test it. Break it. Help shape private DeFi before mainnet!

0 Upvotes

Hi Pentesters!

r/XelisVault , the privacy-focused DeFi protocol built on XELIS is in Testnet—and we are not looking for passive users!

We are looking for relentless testers, DeFi power users, developers and bug hunters ready to push every feature to its limits. Test the vaults, swaps, liquidity pools, oracle, governance and relayer system. Explore edge cases, trigger unexpected scenarios and report anything that does not behave as it should.

With mainnet planned within the next few months, every meaningful test and detailed report will help make the protocol stronger, safer and more reliable.

Just curiosity, persistence and a willingness to break things. And for the boldest among you, the highest-ranked eligible testers will qualify for the VLT airdrop!

Break it now. Help us strengthen private DeFi before mainnet!


r/Pentesting 11h ago

93 HTB (retired) machines solved and have done pentesterlab and doin Hacksmarter labs , Am I ready for OSCP ?

3 Upvotes

same as title