Question for pentesters
https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/
<!-- SC_OFF -->I'd like to know which distro you use for your pentests ? Kali, parrot, Debian,...? Is it in a VM or as your main OS ? <!-- SC_ON --> submitted by /u/Adventurous_Day_6939 (https://www.reddit.com/user/Adventurous_Day_6939)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/)
https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/
<!-- SC_OFF -->I'd like to know which distro you use for your pentests ? Kali, parrot, Debian,...? Is it in a VM or as your main OS ? <!-- SC_ON --> submitted by /u/Adventurous_Day_6939 (https://www.reddit.com/user/Adventurous_Day_6939)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9o3si/question_for_pentesters/)
ISA/IEC 62443 Cybersecurity Certificate Program
https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/
<!-- SC_OFF -->Hi ,
I am not sure this is the right forum or not to ask this question or not.
Could anybody please tell me about this certification (https://www.isa.org/certification/certificate-programs/isa-iec-62443-cybersecurity-certificate-program) ? Is this useful to pursue or not ? Thanks. <!-- SC_ON --> submitted by /u/babula2018 (https://www.reddit.com/user/babula2018)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/)
https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/
<!-- SC_OFF -->Hi ,
I am not sure this is the right forum or not to ask this question or not.
Could anybody please tell me about this certification (https://www.isa.org/certification/certificate-programs/isa-iec-62443-cybersecurity-certificate-program) ? Is this useful to pursue or not ? Thanks. <!-- SC_ON --> submitted by /u/babula2018 (https://www.reddit.com/user/babula2018)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9pzkv/isaiec_62443_cybersecurity_certificate_program/)
Launching: Digital Footprint OSINT Tool β Track Social Presence, Discover Domains, Find Contacts
https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/
<!-- SC_OFF -->Hey everyone! If you're into cybersecurity, ethical hacking, OSINT (Open Source Intelligence), or just want to analyze someone's digital footprint β you're going to love this tool! π₯ I'm excited to share a new open-source project I built:
Digital-Footprint-OSINT-Tool Github: https://github.com/Hamed233/Digital-Footprint-OSINT-Tool <!-- SC_ON --> submitted by /u/hamedessamdev (https://www.reddit.com/user/hamedessamdev)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/)
https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/
<!-- SC_OFF -->Hey everyone! If you're into cybersecurity, ethical hacking, OSINT (Open Source Intelligence), or just want to analyze someone's digital footprint β you're going to love this tool! π₯ I'm excited to share a new open-source project I built:
Digital-Footprint-OSINT-Tool Github: https://github.com/Hamed233/Digital-Footprint-OSINT-Tool <!-- SC_ON --> submitted by /u/hamedessamdev (https://www.reddit.com/user/hamedessamdev)
[link] (https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k9qa6d/launching_digital_footprint_osint_tool_track/)
GraphQL API hacking Series for bug hunters 01
Understanding GraphQL and Its Security ImplicationsContinue reading on Medium Β»
Read more...
Understanding GraphQL and Its Security ImplicationsContinue reading on Medium Β»
Read more...
Medium
GraphQL API hacking Series for Bug Hunters Part 01
Understanding GraphQL and Its Security Implications
JWT, Meet Me Outside: How I Decoded, Re-Signed, and Owned the App
Hey there!πContinue reading on InfoSec Write-ups Β»
Read more...
Hey there!πContinue reading on InfoSec Write-ups Β»
Read more...
Medium
π§ JWT, Meet Me Outside: How I Decoded, Re-Signed, and Owned the App ππ₯
Hey there!π
How I Earned $8947 bounty for Remote Code Execution via a Hijacked GitHub Module
Continue reading on Medium Β»
Read more...
Continue reading on Medium Β»
Read more...
Medium
How I Earned $8947 π°bounty for Remote Code Execution via a Hijacked GitHub Module
Earlier this year, I discovered a High severity Remote Code Execution (RCE) vulnerability affecting a big company (referred to as Redacted for confidentiality). Through a combination of myβ¦
POC β CVE-2025β29306 FOXCMS /images/index.html Code Execution Vulnerability
OverviewContinue reading on Medium Β»
Read more...
OverviewContinue reading on Medium Β»
Read more...
Medium
POCβββCVE-2025β29306 FOXCMS /images/index.html Code Execution Vulnerability
Overview
How I Earned $8947 bounty for Remote Code Execution via a Hijacked GitHub Module
https://nvk0x.medium.com/how-i-earned-8947-bounty-for-remote-code-execution-via-a-hijacked-github-module-91c4a4b63255?source=rss------bug_bounty-5
https://nvk0x.medium.com/how-i-earned-8947-bounty-for-remote-code-execution-via-a-hijacked-github-module-91c4a4b63255?source=rss------bug_bounty-5
POCβββCVE-2025β29306 FOXCMS /images/index.html Code Execution Vulnerability
https://medium.com/@verylazytech/poc-cve-2025-29306-foxcms-images-index-html-code-execution-vulnerability-0c4db3905fd0?source=rss------bug_bounty-5
https://medium.com/@verylazytech/poc-cve-2025-29306-foxcms-images-index-html-code-execution-vulnerability-0c4db3905fd0?source=rss------bug_bounty-5
OverviewContinue reading on Medium Β» (https://medium.com/@verylazytech/poc-cve-2025-29306-foxcms-images-index-html-code-execution-vulnerability-0c4db3905fd0?source=rss------bug_bounty-5)
Simple Tips for Bug Bounty Beginners: Content Spoofing via HTML Injection
NOTE: Make sure to test only on sites where it is allowed to test and carefully read and follow the guidelines for testing on the site.Continue reading on Medium Β»
Read more...
NOTE: Make sure to test only on sites where it is allowed to test and carefully read and follow the guidelines for testing on the site.Continue reading on Medium Β»
Read more...
Medium
Simple Tips for Bug Bounty Beginners: Content Spoofing via HTML Injection
NOTE: Make sure to test only on sites where it is allowed to test and carefully read and follow the guidelines for testing on the site.
The $2500 bug: Remote Code Execution via Supply Chain Attack
Hey there!πContinue reading on Medium Β»
Read more...
Hey there!πContinue reading on Medium Β»
Read more...
Medium
π΅ The $2500 bug: Remote Code Execution via Supply Chain Attack
Hey there!π
Exploiting a Referer Header for Open Redirect
Hello Everyone!Continue reading on Medium Β»
Read more...
Hello Everyone!Continue reading on Medium Β»
Read more...
Medium
Exploiting a Referer Header for Open Redirect
Hello Everyone!
I Hijacked Accounts in 10 Minutes (IDOR Bug)
How I Found a Critical IDOR ATO Exploit in HackerOne (2025)Continue reading on Medium Β»
Read more...
How I Found a Critical IDOR ATO Exploit in HackerOne (2025)Continue reading on Medium Β»
Read more...
Medium
I Hijacked Accounts in 10 Minutes (IDOR Bug)
How I Found a Critical IDOR ATO Exploit in HackerOne (2025)
# Walkthrough: VulnHub Machine β Ted 1 (Full Root Access)
β οΈ Disclaimer: This write-up is created purely for educational purposes. The testing was performed in a controlled lab environment on aβ¦Continue reading on Medium Β»
Read more...
β οΈ Disclaimer: This write-up is created purely for educational purposes. The testing was performed in a controlled lab environment on aβ¦Continue reading on Medium Β»
Read more...
Medium
# Walkthrough: VulnHub Machine β Ted (Full Root Access)
β οΈ Disclaimer: This write-up is created purely for educational purposes. The testing was performed in a controlled lab environment on aβ¦
Scrapling - An Undetectable, Powerful, Flexible, High-Performance Python Library That Makes Web Scraping Simple And Easy Again!
http://www.kitploit.com/2025/04/scrapling-undetectable-powerful.html
http://www.kitploit.com/2025/04/scrapling-undetectable-powerful.html
Dealing with failing web scrapers due to anti-bot protections or website changes? Meet Scrapling. Scrapling is a high-performance (https://www.kitploit.com/search/label/Performance), intelligent web scraping library for Python that automatically adapts to website changes while significantly outperforming popular alternatives. For both beginners and experts, Scrapling provides powerful features while maintaining simplicity. >> from scrapling.defaults import Fetcher, AsyncFetcher, StealthyFetcher, PlayWrightFetcher
# Fetch websites' source under the radar!
>> page = StealthyFetcher.fetch('https://example.com', headless=True, network_idle=True)
>> print(page.status)
200
>> products = page.css('.product', auto_save=True) # Scrape data that survives website design changes!
>> # Later, if the website structure changes, pass `auto_match=True`
>> products = page.css('.product', auto_match=True) # and Scrapling still finds them!
Key Features Fetch websites as you prefer with async support HTTP Requests: Fast and stealthy HTTP requests with the Fetcher class. Dynamic Loading & Automation: Fetch dynamic websites with the PlayWrightFetcher class through your real browser, Scrapling's stealth mode, Playwright's Chrome browser, or NSTbrowser (https://app.nstbrowser.io/r/1vO5e5)'s browserless! Anti-bot Protections Bypass: Easily bypass protections with StealthyFetcher and PlayWrightFetcher classes. Adaptive Scraping π Smart Element Tracking: Relocate elements after website changes, using an intelligent similarity system and integrated storage. π― Flexible Selection: CSS selectors, XPath selectors, filters-based search, text search, regex search and more. π Find Similar Elements: Automatically locate elements similar to the element you found! π§ Smart Content Scraping: Extract data from multiple websites without specific selectors using Scrapling powerful features. High Performance π Lightning Fast: Built from the ground up with performance in mind, outperforming most popular Python scraping libraries. π Memory Efficient: Optimized data structures for minimal memory footprint. β‘ Fast JSON serialization: 10x faster than standard library. Developer Friendly π οΈ Powerful Navigation API: Easy DOM traversal in all directions. 𧬠Rich Text Processing: All strings have built-in regex, cleaning methods, and more. All elements' attributes are optimized dictionaries that takes less memory than standard dictionaries with added methods. π Auto Selectors Generation: Generate robust short and full CSS/XPath selectors for any element. π Familiar API: Similar to Scrapy/BeautifulSoup and the same pseudo-elements used in Scrapy. π Type hints: Complete type/doc-strings coverage for future-proofing and best autocompletion support. Getting Started from scrapling.fetchers import Fetcher
fetcher = Fetcher(auto_match=False)
# Do http GET request to a web page and create an Adaptor instance
page = fetcher.get('https://quotes.toscrape.com/', stealthy_headers=True)
# Get all text content from all HTML tags in the page except `script` and `style` tags
page.get_all_text(ignore_tags=('script', 'style'))
# Get all quotes elements, any of these methods will return a list of strings directly (TextHandlers)
quotes = page.css('.quote .text::text') # CSS selector
quotes = page.xpath('//span[@class="text"]/text()') # XPath
quotes = page.css('.quote').css('.text::text') # Chained selectors
quotes = [element.text for element in page.css('.quote .text')] # Slower than bulk query above
# Get the first quote element
quote = page.css_first('.quote') # same as page.css('.quote').first or page.css('.quote')[0]
# Tired of selectors? Use find_all/find
# Get all 'div' HTML tags that one of its 'class' values is 'quote'
quotes = page.find_all('div', {'class': 'quote'})
# Same as
quotes = page.find_all('div', class_='quote')
quotes = page.find_all(['div'], class_='quote')
quotes = page.find_all(class_='quote') # and so on...
# Working with elements
# Fetch websites' source under the radar!
>> page = StealthyFetcher.fetch('https://example.com', headless=True, network_idle=True)
>> print(page.status)
200
>> products = page.css('.product', auto_save=True) # Scrape data that survives website design changes!
>> # Later, if the website structure changes, pass `auto_match=True`
>> products = page.css('.product', auto_match=True) # and Scrapling still finds them!
Key Features Fetch websites as you prefer with async support HTTP Requests: Fast and stealthy HTTP requests with the Fetcher class. Dynamic Loading & Automation: Fetch dynamic websites with the PlayWrightFetcher class through your real browser, Scrapling's stealth mode, Playwright's Chrome browser, or NSTbrowser (https://app.nstbrowser.io/r/1vO5e5)'s browserless! Anti-bot Protections Bypass: Easily bypass protections with StealthyFetcher and PlayWrightFetcher classes. Adaptive Scraping π Smart Element Tracking: Relocate elements after website changes, using an intelligent similarity system and integrated storage. π― Flexible Selection: CSS selectors, XPath selectors, filters-based search, text search, regex search and more. π Find Similar Elements: Automatically locate elements similar to the element you found! π§ Smart Content Scraping: Extract data from multiple websites without specific selectors using Scrapling powerful features. High Performance π Lightning Fast: Built from the ground up with performance in mind, outperforming most popular Python scraping libraries. π Memory Efficient: Optimized data structures for minimal memory footprint. β‘ Fast JSON serialization: 10x faster than standard library. Developer Friendly π οΈ Powerful Navigation API: Easy DOM traversal in all directions. 𧬠Rich Text Processing: All strings have built-in regex, cleaning methods, and more. All elements' attributes are optimized dictionaries that takes less memory than standard dictionaries with added methods. π Auto Selectors Generation: Generate robust short and full CSS/XPath selectors for any element. π Familiar API: Similar to Scrapy/BeautifulSoup and the same pseudo-elements used in Scrapy. π Type hints: Complete type/doc-strings coverage for future-proofing and best autocompletion support. Getting Started from scrapling.fetchers import Fetcher
fetcher = Fetcher(auto_match=False)
# Do http GET request to a web page and create an Adaptor instance
page = fetcher.get('https://quotes.toscrape.com/', stealthy_headers=True)
# Get all text content from all HTML tags in the page except `script` and `style` tags
page.get_all_text(ignore_tags=('script', 'style'))
# Get all quotes elements, any of these methods will return a list of strings directly (TextHandlers)
quotes = page.css('.quote .text::text') # CSS selector
quotes = page.xpath('//span[@class="text"]/text()') # XPath
quotes = page.css('.quote').css('.text::text') # Chained selectors
quotes = [element.text for element in page.css('.quote .text')] # Slower than bulk query above
# Get the first quote element
quote = page.css_first('.quote') # same as page.css('.quote').first or page.css('.quote')[0]
# Tired of selectors? Use find_all/find
# Get all 'div' HTML tags that one of its 'class' values is 'quote'
quotes = page.find_all('div', {'class': 'quote'})
# Same as
quotes = page.find_all('div', class_='quote')
quotes = page.find_all(['div'], class_='quote')
quotes = page.find_all(class_='quote') # and so on...
# Working with elements