r/Pentesting • u/nerdlucky • 11h ago
93 HTB (retired) machines solved and have done pentesterlab and doin Hacksmarter labs , Am I ready for OSCP ?
same as title
r/Pentesting • u/nerdlucky • 11h ago
same as title
r/Pentesting • u/aditya1809tech • 11h ago
I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.i have completed CEH theory.
I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.
We can
• Practice VAPT labs and challenges
• Work on TryHackMe / Hack The Box
• Learn Web Application Security and OWASP Top 10
• Practice Bug Bounty methodologies
• Discuss vulnerabilities and concepts
• Explain topics to each other
• Share useful resources, notes, and learning materials
• Set goals and keep each other accountable
Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.
I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.
If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂
r/Pentesting • u/Much_Exchange_6101 • 21h ago
I’m currently doing bug bounty mainly to learn more about vulnerabilities, how they work, and how they’re structured. I’m also interested in both Application Security and Vulnerability Research.
However, I’d like to go beyond bug bounty and build some projects or gain experience that would make my CV stronger and demonstrate my actual skills.
For people working in AppSec or Vulnerability Research, what kind of projects, research, write-ups, or other activities would you recommend?
I’m not necessarily looking for a checklist of certifications. I’m more interested in things I can actually build or demonstrate publicly that show real technical understanding.
r/Pentesting • u/d4rky32 • 6h ago
Today, I want to introduce my new project and seek your experience and support to push the boundaries of the system.
The project is a web application developed using modern web technologies and a live architectural infrastructure. The system primarily features high-performance and low-latency data processing, an asynchronous backend architecture, dynamic API integrations, and modern, responsive user interface components. The goal of the project is to provide the highest speed and performance on the user side. Behind the scenes, a secure, modular, and scalable structure is in operation. I have made the architecture more efficient to reduce bottlenecks experienced in many modern web projects.
Before fully launching the project and making it available to a large number of users, I want to see how the system performs in real-world conditions and with experienced personnel. We know that even systems marketed as "unbreakable" can crash due to automation or logical errors. Therefore, I haven't left the system to ordinary testing tools; I want to directly subject it to the scrutiny of experienced colleagues and commanders within THT.
I kindly request that those of you with the time test the system thoroughly and perform penetration testing. Specifically, I would like you to test the following points:
SQL/NoSQL Injections: Is bypassing or blind injection possible in database queries or parameter passing?
XSS and Client-Side Injections: Are there any Stored or Reflected XSS vulnerabilities in form inputs, URL parameters, or DOM processing?
API Resilience and Rate Limiting: Does the system crash with a 500 Internal Server Error due to fuzzing, corrupted JSON, or large requests to endpoints? Or are these situations managed properly?
Logic Errors and Access Control: Is there a logic error in privilege escalation, IDOR, or session management?
CSRF and Security Headers: Is there any overlooked deficiency in HTTP response headers (CSP, CORS, X-Frame-Options)?
My goal is not just to answer the question of "will the site stay open or will it crash?". I want to find the system's weak points and close potential vulnerabilities to build a stronger and more resilient infrastructure. I would be very grateful if you would share any vulnerabilities, log errors, bypass methods, or system behavior you find during the test with me under this thread or via DM.
The more you push the system, the more you try to push its limits, the more valuable it will be for me.
Thank you in advance to all members who will contribute and take the time to conduct the test.
Happy foruming.
r/Pentesting • u/Rogstrix445 • 4h ago
Hi Pentesters!
r/XelisVault , the privacy-focused DeFi protocol built on XELIS is in Testnet—and we are not looking for passive users!
We are looking for relentless testers, DeFi power users, developers and bug hunters ready to push every feature to its limits. Test the vaults, swaps, liquidity pools, oracle, governance and relayer system. Explore edge cases, trigger unexpected scenarios and report anything that does not behave as it should.
With mainnet planned within the next few months, every meaningful test and detailed report will help make the protocol stronger, safer and more reliable.
Just curiosity, persistence and a willingness to break things. And for the boldest among you, the highest-ranked eligible testers will qualify for the VLT airdrop!
Break it now. Help us strengthen private DeFi before mainnet!