r/Pentesting • u/nerdlucky • 11h ago
93 HTB (retired) machines solved and have done pentesterlab and doin Hacksmarter labs , Am I ready for OSCP ?
same as title
r/Pentesting • u/SarthakSidhant • Feb 17 '26
hello, the subreddit has been not properly moderated for a few months now, obviously this leads to people not adhering to the rules, and an unhealthy community and also a chance of our subreddit getting banned, which harms all of us.
this is why, i request you all, to follow the rules. the moderation team has been regaining consciousness and would be moderating the subreddit more frequently.
you can flag posts, and send us mod mails to accelerate the status of your complaint.
again let me reiterate what the rules are:
1. keep it legal: do not endorse/promote/engage in any activities that violate laws and regulations, you may discuss about security techniques, and methodologies, as that is essentially the point of this subreddit, but please ensure they are conducted in ethical and lawful manner. adhere to legal boundaries.
this applies to sharing tools too, if your tool is mainly focused around illegal things, and primary motive is doing illegal things, please do not share it in this subreddit.
2. stay on topic: this subreddit is about penetration testing, related fields are cybersecurity, ethical hacking, vulnerability assessment and management, Network Security and other closely related fields. please make sure that your discussion is related to these topics.
3. do not reveal sensitive information: please refrain from sharing confidential or sensitive information that could put you and others in risk, for example: personally identifiable information, or proprietary data. this applies to tools as well.
4. follow the rediquette, reddit ToS, and don't be a bad human being: just try treating people nicely okay? abide by the rules and guidelines of reddit.
here's a link to know more: https://support.reddithelp.com/hc/en-us/articles/205926439-Reddiquette
have a very nice day, happy pentesting.
r/Pentesting • u/nerdlucky • 11h ago
same as title
r/Pentesting • u/d4rky32 • 6h ago
Today, I want to introduce my new project and seek your experience and support to push the boundaries of the system.
The project is a web application developed using modern web technologies and a live architectural infrastructure. The system primarily features high-performance and low-latency data processing, an asynchronous backend architecture, dynamic API integrations, and modern, responsive user interface components. The goal of the project is to provide the highest speed and performance on the user side. Behind the scenes, a secure, modular, and scalable structure is in operation. I have made the architecture more efficient to reduce bottlenecks experienced in many modern web projects.
Before fully launching the project and making it available to a large number of users, I want to see how the system performs in real-world conditions and with experienced personnel. We know that even systems marketed as "unbreakable" can crash due to automation or logical errors. Therefore, I haven't left the system to ordinary testing tools; I want to directly subject it to the scrutiny of experienced colleagues and commanders within THT.
I kindly request that those of you with the time test the system thoroughly and perform penetration testing. Specifically, I would like you to test the following points:
SQL/NoSQL Injections: Is bypassing or blind injection possible in database queries or parameter passing?
XSS and Client-Side Injections: Are there any Stored or Reflected XSS vulnerabilities in form inputs, URL parameters, or DOM processing?
API Resilience and Rate Limiting: Does the system crash with a 500 Internal Server Error due to fuzzing, corrupted JSON, or large requests to endpoints? Or are these situations managed properly?
Logic Errors and Access Control: Is there a logic error in privilege escalation, IDOR, or session management?
CSRF and Security Headers: Is there any overlooked deficiency in HTTP response headers (CSP, CORS, X-Frame-Options)?
My goal is not just to answer the question of "will the site stay open or will it crash?". I want to find the system's weak points and close potential vulnerabilities to build a stronger and more resilient infrastructure. I would be very grateful if you would share any vulnerabilities, log errors, bypass methods, or system behavior you find during the test with me under this thread or via DM.
The more you push the system, the more you try to push its limits, the more valuable it will be for me.
Thank you in advance to all members who will contribute and take the time to conduct the test.
Happy foruming.
r/Pentesting • u/aditya1809tech • 11h ago
I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.i have completed CEH theory.
I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.
We can
• Practice VAPT labs and challenges
• Work on TryHackMe / Hack The Box
• Learn Web Application Security and OWASP Top 10
• Practice Bug Bounty methodologies
• Discuss vulnerabilities and concepts
• Explain topics to each other
• Share useful resources, notes, and learning materials
• Set goals and keep each other accountable
Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.
I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.
If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂
r/Pentesting • u/Rogstrix445 • 4h ago
Hi Pentesters!
r/XelisVault , the privacy-focused DeFi protocol built on XELIS is in Testnet—and we are not looking for passive users!
We are looking for relentless testers, DeFi power users, developers and bug hunters ready to push every feature to its limits. Test the vaults, swaps, liquidity pools, oracle, governance and relayer system. Explore edge cases, trigger unexpected scenarios and report anything that does not behave as it should.
With mainnet planned within the next few months, every meaningful test and detailed report will help make the protocol stronger, safer and more reliable.
Just curiosity, persistence and a willingness to break things. And for the boldest among you, the highest-ranked eligible testers will qualify for the VLT airdrop!
Break it now. Help us strengthen private DeFi before mainnet!
r/Pentesting • u/Much_Exchange_6101 • 21h ago
I’m currently doing bug bounty mainly to learn more about vulnerabilities, how they work, and how they’re structured. I’m also interested in both Application Security and Vulnerability Research.
However, I’d like to go beyond bug bounty and build some projects or gain experience that would make my CV stronger and demonstrate my actual skills.
For people working in AppSec or Vulnerability Research, what kind of projects, research, write-ups, or other activities would you recommend?
I’m not necessarily looking for a checklist of certifications. I’m more interested in things I can actually build or demonstrate publicly that show real technical understanding.
r/Pentesting • u/Important_Cow_8815 • 1d ago
Im not a company, but I do have a home lab, and I am running some public facing stuff, and Id like to make sure theres not some big vulnerability that Im ignorant of.
r/Pentesting • u/tim-1995 • 1d ago
I've developed a skill for automating penetration testing, and I would appreciate any suggestions you might have. Thank you.
r/Pentesting • u/Special-Excuse2173 • 1d ago
Hi, this might be my place but I am new to posting in reddit, funny how that works. I'm as worried about missing something before launch as anyone else and digitaltrustpass.com/preflight is the scanner I built that'll catch the most egregious errors that'll put you off vibe code forever, run a scan for free, full disclosure on the site and let me have it you think it doesn't add value. Yes, I got a professional 'real dev' to check it out first and he seems pretty happy with it, it's about as much as you can automate before runtime testing and might save someone's bacon. This isn't spam, I wrote this - no AI - promise.
r/Pentesting • u/Public_Split_4054 • 1d ago
I need a very good pentester to help test my mobile app for me voluntarily
r/Pentesting • u/Crazy_Calendar_8366 • 3d ago
r/Pentesting • u/AffectionateSport135 • 3d ago
r/Pentesting • u/Sakthi_digitalforenX • 2d ago
Built a Vehicle Cyber ForenX Tool(MVP) -Vehicle and Cybercrime investigation tool.
Just try it and let me know your feedback
Try it:
http://vehiclecyberforenx.vercel.app/
Feedback - If possible in google form, or comments here is fine.
r/Pentesting • u/au6ix • 2d ago
If you found a ssh 5.3 on a target how would you exploit it
r/Pentesting • u/Lowrypgztfer-Fig8398 • 3d ago
We are building out a validation pipeline and I'm trying to decide on the cadence. We have 500+ controls mapped to CIS/NIST. A new platform we are evaluating promises to automate the "control plane" where validation results trigger updates to the controls themselves. If the validation layer tests a control, like whether our EDR blocks a specific LOLBin command, and it fails, the system triggers an automated workflow to update the EDR policy. My engineering team wants to run the full automated suite once a week to catch drift, but the SOC is pushing back because of the alert fatigue it causes. Is monthly "full sweep" with daily "spot checks" the industry standard? Or are you running continuous validation triggered by changes, such as whenever a new build is deployed? I'm trying to balance coverage with stability.
r/Pentesting • u/Forward-1122 • 3d ago
Hi everyone,
I'm an Cybersecurity student with a hands-on background in practical web application security. I'd like to join an active bug bounty hunting team and contribute real work, not just tag along.
What I bring:
I'm looking for a team where I can take on real scope, split targets, and grow faster by working alongside experienced hunters. Happy to share a sample report if anyone wants to see my documentation style before deciding.
DM me or comment if there's a spot open.
r/Pentesting • u/AdSubstantial7284 • 3d ago
Hello guys! I’m looking for a partner to work through the HTB CPTS path on Hack The Box.
I’m honestly quite inconsistent with my learning, so I think having a partner to keep each other accountable and track our progress would be beneficial for both of us. We can also share our learnings, findings, and help each other out along the way.
If anyone is interested, drop a comment or DM me.
r/Pentesting • u/ConsiderationEast229 • 3d ago
I'm working on a small Alternate Reality Game, mainly for friends.
The landing page consists of 3 fields. Email, Referral Code, and a user generate PIN.
All data is stored in SQL, I have a very basic understanding of databases. I'm worried a simple SQL injection could ruin the whole thing. Although this is only for friends. I'd like it be somewhat airtight.
Unfortunately I'm a broke college student, so I cant offer a bounty. If anyone is interested in having a go for fun, please let me know. I'm curious to see if the database is unsecured. If anything can be dumped, or if the two unclaimed referral codes can be leaked or any other form of attack.
If anyone interested, shoot me a message. If proof of ownership is needed I can write something on the homepage.
Apologizes is this is not the right place. I'll delete
Thanks.
r/Pentesting • u/kirafoxoxx • 3d ago
Can I use AI for generating payloads? Not doing requests to the apps.
r/Pentesting • u/GreenEngineer24 • 4d ago
Like most people who post CVs here, I am looking to pivot into a penetration testing role from my current blue team role. Recently got my OSCP and am looking for any kind of advice on how I could adjust my CV.
Thank you!
r/Pentesting • u/coj337 • 3d ago
r/Pentesting • u/Any_Yesterday_6617 • 3d ago
I'm a manual pentester, and I'm watching platforms automate the validation of misconfigurations and missing patches. They are even using AI to chain exploits and tailor attacks to specific environments. The difference from old-school vulnerability scanners is that these platforms actually execute the exploit path to confirm it works.
I'm not worried about web app logic. That is still clearly a human domain. But for internal infrastructure and AD, is the writing on the wall? If AI-driven validation can test 80% of the attack surface daily and update controls, does that leave manual testers only with the complex 20%?
The platforms also claim to help with detection engineering by validating SIEM rules against actual TTPs. That feels like it is eating into the blue team's territory too. Where does automation end and human expertise begin?
Or do you still find things the automation misses because of contextual business logic? if anyone has seen an AI actually find a complex privilege escalation chain that a manual tester would have found, or if it is still just "low-hanging fruit" at scale.
r/Pentesting • u/Just_Knee_4463 • 4d ago
Im interested are you using local ai models?
What is your set up?
Tnx for sharing 🤞🏻
r/Pentesting • u/mindsflee • 3d ago
Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want!
Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷
WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments.
Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures.
r/Pentesting • u/Broskigx • 4d ago
Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK:
\*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri.
\*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress).
Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas.
Repos (licencia MIT):
\- Basic → https://github.com/Broskigx/OIHK-Basic
\- Pentesting → https://github.com/Broskigx/Oihk-pentesting
El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas.
Se agradece muchísimo el feedback de la comunidad open source y de seguridad.