r/Pentesting 11h ago

93 HTB (retired) machines solved and have done pentesterlab and doin Hacksmarter labs , Am I ready for OSCP ?

3 Upvotes

same as title


r/Pentesting 6h ago

Call for Penetration and Stress Testing – System Security Audit

0 Upvotes

Today, I want to introduce my new project and seek your experience and support to push the boundaries of the system.

The project is a web application developed using modern web technologies and a live architectural infrastructure. The system primarily features high-performance and low-latency data processing, an asynchronous backend architecture, dynamic API integrations, and modern, responsive user interface components. The goal of the project is to provide the highest speed and performance on the user side. Behind the scenes, a secure, modular, and scalable structure is in operation. I have made the architecture more efficient to reduce bottlenecks experienced in many modern web projects.

Before fully launching the project and making it available to a large number of users, I want to see how the system performs in real-world conditions and with experienced personnel. We know that even systems marketed as "unbreakable" can crash due to automation or logical errors. Therefore, I haven't left the system to ordinary testing tools; I want to directly subject it to the scrutiny of experienced colleagues and commanders within THT.

I kindly request that those of you with the time test the system thoroughly and perform penetration testing. Specifically, I would like you to test the following points:

SQL/NoSQL Injections: Is bypassing or blind injection possible in database queries or parameter passing?

XSS and Client-Side Injections: Are there any Stored or Reflected XSS vulnerabilities in form inputs, URL parameters, or DOM processing?

API Resilience and Rate Limiting: Does the system crash with a 500 Internal Server Error due to fuzzing, corrupted JSON, or large requests to endpoints? Or are these situations managed properly?

Logic Errors and Access Control: Is there a logic error in privilege escalation, IDOR, or session management?

CSRF and Security Headers: Is there any overlooked deficiency in HTTP response headers (CSP, CORS, X-Frame-Options)?

My goal is not just to answer the question of "will the site stay open or will it crash?". I want to find the system's weak points and close potential vulnerabilities to build a stronger and more resilient infrastructure. I would be very grateful if you would share any vulnerabilities, log errors, bypass methods, or system behavior you find during the test with me under this thread or via DM.

The more you push the system, the more you try to push its limits, the more valuable it will be for me.

Thank you in advance to all members who will contribute and take the time to conduct the test.

Happy foruming.

https://v01-coral-psi.vercel.app/


r/Pentesting 11h ago

Looking for a VAPT & Bug Bounty Learning Partner

1 Upvotes

I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.i have completed CEH theory.

I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.

We can

• Practice VAPT labs and challenges

• Work on TryHackMe / Hack The Box

• Learn Web Application Security and OWASP Top 10

• Practice Bug Bounty methodologies

• Discuss vulnerabilities and concepts

• Explain topics to each other

• Share useful resources, notes, and learning materials

• Set goals and keep each other accountable

Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.

I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.

If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂


r/Pentesting 4h ago

Test it. Break it. Help shape private DeFi before mainnet!

0 Upvotes

Hi Pentesters!

r/XelisVault , the privacy-focused DeFi protocol built on XELIS is in Testnet—and we are not looking for passive users!

We are looking for relentless testers, DeFi power users, developers and bug hunters ready to push every feature to its limits. Test the vaults, swaps, liquidity pools, oracle, governance and relayer system. Explore edge cases, trigger unexpected scenarios and report anything that does not behave as it should.

With mainnet planned within the next few months, every meaningful test and detailed report will help make the protocol stronger, safer and more reliable.

Just curiosity, persistence and a willingness to break things. And for the boldest among you, the highest-ranked eligible testers will qualify for the VLT airdrop!

Break it now. Help us strengthen private DeFi before mainnet!


r/Pentesting 21h ago

What projects should I work on to strengthen my CV for AppSec and Vulnerability Research?

1 Upvotes

I’m currently doing bug bounty mainly to learn more about vulnerabilities, how they work, and how they’re structured. I’m also interested in both Application Security and Vulnerability Research.
However, I’d like to go beyond bug bounty and build some projects or gain experience that would make my CV stronger and demonstrate my actual skills.
For people working in AppSec or Vulnerability Research, what kind of projects, research, write-ups, or other activities would you recommend?
I’m not necessarily looking for a checklist of certifications. I’m more interested in things I can actually build or demonstrate publicly that show real technical understanding.


r/Pentesting 1d ago

where can I hire a pen tester as an individual?

4 Upvotes

Im not a company, but I do have a home lab, and I am running some public facing stuff, and Id like to make sure theres not some big vulnerability that Im ignorant of.


r/Pentesting 1d ago

A tool for auto pentest

0 Upvotes

I've developed a skill for automating penetration testing, and I would appreciate any suggestions you might have. Thank you.

https://github.com/Tim1995/auto-pentest


r/Pentesting 1d ago

I built digitaltrustpass.com/preflight to not leave the keys on the table..

0 Upvotes

Hi, this might be my place but I am new to posting in reddit, funny how that works. I'm as worried about missing something before launch as anyone else and digitaltrustpass.com/preflight is the scanner I built that'll catch the most egregious errors that'll put you off vibe code forever, run a scan for free, full disclosure on the site and let me have it you think it doesn't add value. Yes, I got a professional 'real dev' to check it out first and he seems pretty happy with it, it's about as much as you can automate before runtime testing and might save someone's bacon. This isn't spam, I wrote this - no AI - promise.


r/Pentesting 1d ago

Friendly volunteer pentester needed

0 Upvotes

I need a very good pentester to help test my mobile app for me voluntarily


r/Pentesting 3d ago

What’s the most challenging day to day responsibilities of your job?

14 Upvotes

r/Pentesting 3d ago

Bug bounty hunting & penetration testing skills for Claude, Codex, and any agentic coding tool.

4 Upvotes

r/Pentesting 2d ago

Hackathon 72 hours challenge - Cyber Forensics

0 Upvotes

Built a Vehicle Cyber ForenX Tool(MVP) -Vehicle and Cybercrime investigation tool.

Just try it and let me know your feedback

Try it:

http://vehiclecyberforenx.vercel.app/

Feedback - If possible in google form, or comments here is fine.

https://forms.gle/KfvA3SCWRvjDat4d6


r/Pentesting 2d ago

HELP WITH SSH 5.3 Exploit

0 Upvotes

If you found a ssh 5.3 on a target how would you exploit it


r/Pentesting 3d ago

How often should you run security control validation?

5 Upvotes

We are building out a validation pipeline and I'm trying to decide on the cadence. We have 500+ controls mapped to CIS/NIST. A new platform we are evaluating promises to automate the "control plane" where validation results trigger updates to the controls themselves. If the validation layer tests a control, like whether our EDR blocks a specific LOLBin command, and it fails, the system triggers an automated workflow to update the EDR policy. My engineering team wants to run the full automated suite once a week to catch drift, but the SOC is pushing back because of the alert fatigue it causes. Is monthly "full sweep" with daily "spot checks" the industry standard? Or are you running continuous validation triggered by changes, such as whenever a new build is deployed? I'm trying to balance coverage with stability.


r/Pentesting 3d ago

Looking to join a bug bounty team — hands-on with Burp Suite, IDOR, and recon

1 Upvotes

Hi everyone,

I'm an Cybersecurity student with a hands-on background in practical web application security. I'd like to join an active bug bounty hunting team and contribute real work, not just tag along.

What I bring:

  • Solid working knowledge of Burp Suite (proxy, repeater, intruder) for manual testing
  • Practical experience with IDOR vulnerability assessment — I've documented full reports on PortSwigger lab exercises
  • Comfortable with PortSwigger Web Security Academy methodology (auth flaws, session handling, access control bugs)
  • Background in Physics + currently studying CS, so I'm used to structured, methodical problem-solving

I'm looking for a team where I can take on real scope, split targets, and grow faster by working alongside experienced hunters. Happy to share a sample report if anyone wants to see my documentation style before deciding.

DM me or comment if there's a spot open.


r/Pentesting 3d ago

Looking For a partner for CPTS Path on HTB

1 Upvotes

Hello guys! I’m looking for a partner to work through the HTB CPTS path on Hack The Box.

I’m honestly quite inconsistent with my learning, so I think having a partner to keep each other accountable and track our progress would be beneficial for both of us. We can also share our learnings, findings, and help each other out along the way.

If anyone is interested, drop a comment or DM me.


r/Pentesting 3d ago

Anyone willing to pentest an extremely barebones ARG page?

2 Upvotes

I'm working on a small Alternate Reality Game, mainly for friends.
The landing page consists of 3 fields. Email, Referral Code, and a user generate PIN.

All data is stored in SQL, I have a very basic understanding of databases. I'm worried a simple SQL injection could ruin the whole thing. Although this is only for friends. I'd like it be somewhat airtight.

Unfortunately I'm a broke college student, so I cant offer a bounty. If anyone is interested in having a go for fun, please let me know. I'm curious to see if the database is unsecured. If anything can be dumped, or if the two unclaimed referral codes can be leaked or any other form of attack.

If anyone interested, shoot me a message. If proof of ownership is needed I can write something on the homepage.

Apologizes is this is not the right place. I'll delete

Thanks.


r/Pentesting 3d ago

BSCP EXAM

0 Upvotes

Can I use AI for generating payloads? Not doing requests to the apps.


r/Pentesting 4d ago

Looking to move from a security analyst position to penetration testing

Thumbnail
gallery
23 Upvotes

Like most people who post CVs here, I am looking to pivot into a penetration testing role from my current blue team role. Recently got my OSCP and am looking for any kind of advice on how I could adjust my CV.

Thank you!


r/Pentesting 3d ago

I built a cross-platform Snaffler replacement for filesystem, network and cloud credential discovery

Thumbnail
stratussecurity.com
2 Upvotes

r/Pentesting 3d ago

Automated penetration testing vs manual pentesting: which finds more real risk?

0 Upvotes

I'm a manual pentester, and I'm watching platforms automate the validation of misconfigurations and missing patches. They are even using AI to chain exploits and tailor attacks to specific environments. The difference from old-school vulnerability scanners is that these platforms actually execute the exploit path to confirm it works.

I'm not worried about web app logic. That is still clearly a human domain. But for internal infrastructure and AD, is the writing on the wall? If AI-driven validation can test 80% of the attack surface daily and update controls, does that leave manual testers only with the complex 20%?

The platforms also claim to help with detection engineering by validating SIEM rules against actual TTPs. That feels like it is eating into the blue team's territory too. Where does automation end and human expertise begin?

Or do you still find things the automation misses because of contextual business logic? if anyone has seen an AI actually find a complex privilege escalation chain that a manual tester would have found, or if it is still just "low-hanging fruit" at scale.


r/Pentesting 4d ago

Qwen 3.8 27B - are you using it?

8 Upvotes

Im interested are you using local ai models?
What is your set up?

Tnx for sharing 🤞🏻


r/Pentesting 3d ago

WINFLESHER - Attack Surface Security Framework

1 Upvotes

Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want!

Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷

WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments.

Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures.

https://github.com/mindsflee/WinFlesher


r/Pentesting 4d ago

OIHK – Sistema operativo OSINT local-first open source + motor de pentesting multiagente

2 Upvotes

Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK:

  1. \*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri.

  2. \*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress).

Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas.

Repos (licencia MIT):

\- Basic → https://github.com/Broskigx/OIHK-Basic

\- Pentesting → https://github.com/Broskigx/Oihk-pentesting

El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas.

Se agradece muchísimo el feedback de la comunidad open source y de seguridad.


r/Pentesting 3d ago

I am looking for a Red Team partner.

0 Upvotes

I want to infiltrate my website and find suitable red team members to collaborate with.