Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Fully remote + outside the US?
https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/

<!-- SC_OFF -->It seems the general consensus on other cyber subreddits* is that (1) fully remote + (2) outside the US pretty rare for a cybersecurity job (mostly for legal + data compliance issues). However, I was wondering if this could be an exception for pentesting jobs? Because I would assume most malicious hacking attempts are from abroad, it seems it would make sense for pentesters to be abroad. edit: to work for a US-based company, and also I am a US citizen. <!-- SC_ON --> submitted by /u/KimchiFitness (https://www.reddit.com/user/KimchiFitness)
[link] (https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/)
The state of pentesting in 2025
https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/

<!-- SC_OFF -->Hello everyone, I am writing this post because I need more advice on what the absolute hell im doing wrong. My qualifications include - B.S in Cybersecurity - OSCP - CRTO - Two pending CVE's (One I am already listed on a company site for) - 2 years of professional experience as a SOC Analyst - 4 years experience as a SOC Analyst intern - Was a part of a statewide cybersecurity initiative as a red team operator over a span of 4 days (prep was about 2 months) and was the sole member of the red teams to get an award. - 2 POC exploits on github for random CVE's and 1 for a crummy shellcode loader i made for CRTO I seriously can't land a pentesting job/find one now I haven't applied for and its killing me. I feel so overqualified and underpaid in my current role as a SOC analyst that its depressing me (60k annually). I've been working through portswigger courses in the meantime with Burp Pro trying to get the BSCP in a month or two but I feel im due for a new job at this point. My current company has done nothing with me to utilize my skills and my other peers at work who started when I did are upset about them not getting moved to different roles as management keeps hiring externally and mentors I've expressed these issues to have stated it is 100% bad management. So instead of sitting around and feeling sorry for myself what else can I do?!?! I know the job market is "bad' right now but I only really see those kind of posts from people who are trying to break into IT/Cybersec. I feel with pentesting there just arent any jobs out there for someone at my level example is I live in the DMV area i'll find a job that fits my qualifications perfect then i see "TS/SCI with full scope poly required" or one without clearance as in "Pentesting 10 years must be proficient in every technology and programming language for 90k annually" Any advice is appreciated. <!-- SC_ON --> submitted by /u/Netmond (https://www.reddit.com/user/Netmond)
[link] (https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/)
<!-- SC_OFF -->Just published a new post on Medium for anyone grinding through OSCP prep. “OSCP Exam Success: 5 Must-Know Commands and Tools Every Pentester Should Master” — a quick guide to the commands that saved me time and stress during the exam, and that I still use in real-world pentests. <!-- SC_ON --> submitted by /u/Anezaneo (https://www.reddit.com/user/Anezaneo)
[link] (https://infosecwriteups.com/oscp-exam-success-5-must-know-commands-and-tools-every-pentester-should-master-c65523e38cc1) [comments] (https://www.reddit.com/r/Pentesting/comments/1mkvnk8/5_commands_that_really_helped_me_during_my_oscp/)
Web Applications vs. Cloud
https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/

<!-- SC_OFF -->From what I've seen the majority of the pentesting work seems to be web apps. Do you think with the rapid growth and adoption of cloud, cloud penetration testing will overtake it in terms of volume of work and demand? Or will web remain the most sought after? <!-- SC_ON --> submitted by /u/Sad-Mountain-2031 (https://www.reddit.com/user/Sad-Mountain-2031)
[link] (https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/)
Server-Side Request Forgery (SSRF — OWASP A10): A Complete Guide to Hacking and Bug Bounties

Learn how SSRF allows an attacker to access the internal network, read cloud metadata, and escalate privileges.Continue reading on Medium »
Read more...
DNSSEC Explained

A practical guide to understanding DNSSEC, the bodyguard of DNS, what it is, how it works, and why it’s a big deal in securing DNS records.Continue reading on Zero2Root »
Read more...
Learn how SSRF allows an attacker to access the internal network, read cloud metadata, and escalate privileges.Continue reading on Medium » (https://medium.com/@jpablo13/server-side-request-forgery-ssrf-owasp-a10-a-complete-guide-to-hacking-and-bug-bounties-0b8f0825f83c?source=rss------bug_bounty-5)
A practical guide to understanding DNSSEC, the bodyguard of DNS, what it is, how it works, and why it’s a big deal in securing DNS records.Continue reading on Zero2Root » (https://medium.com/zero2root/dnssec-explained-2e76ef993984?source=rss------bug_bounty-5)
Underpayment and opportunities
https://www.reddit.com/r/Pentesting/comments/1mlcboe/underpayment_and_opportunities/

<!-- SC_OFF -->I work for an American company that pays me around $40,000 per year. I'm mid-level, have some Offsec certifications, published CVEs, and am extremely responsible in my work, including many side tasks. I'm not a security genius, but I do a good job and feel like I'm important to the team. The point is: they pay much less because I'm a foreigner. I understand the idea of paying foreigners less; it makes sense: the company pays less, we make a profit on currency exchange, and both sides benefit. I recently received an offer from another company that will pay me a similar salary, but in my home country. I'm considering it because this company is huge and will greatly enhance my professional experience and resume. In this case, I'm considering making a counteroffer (I don't know if this is common in the US) to my current company, and I want to raise the bar significantly. I researched and found that a Mid Pentester in the US makes around $70,000 to $100,000 per year, so I would ask for something around that. Does this range make sense? Or are there really 40K salaries for this level, and am I deluding myself? I think the chances are they'll simply say, "Nah, we will find another pentester" are high. I said that I know that my importance to the team is significant and that my departure would give them a little work for them, but I'm far from irreplaceable. Another point, the increases would be smaller working locally, even though you are underpaid in the US. Another point, future increases would be smaller locally (because of the currency). So, any thoughts? Should I just accept this new learning opportunity? Should I try this counteroffer? Is asking for 70K as a foreigner too expensive? <!-- SC_ON --> submitted by /u/w00f4r (https://www.reddit.com/user/w00f4r)
[link] (https://www.reddit.com/r/Pentesting/comments/1mlcboe/underpayment_and_opportunities/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mlcboe/underpayment_and_opportunities/)