<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/xjpw70rcnlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/)
[link] (https://i.redd.it/xjpw70rcnlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/)
I did the unthinkable and made a pentesting toolkit that works on iPhone!
https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/
https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/
<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/033p44ienlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/)
[link] (https://i.redd.it/033p44ienlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/)
Is Penetration Testing Financially Stable in the Long Run?
https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/
<!-- SC_OFF -->I’m at the very beginning of my journey into penetration testing, and I keep hearing mixed opinions about its financial stability as a career. Some people say the competition is fierce, stable positions are hard to get, and the income isn’t always worth the amount of effort required. I’ve also read that bug bounty programs aren’t as lucrative as many influencers make them seem, and relying on them for a consistent income can be unrealistic. From your perspective as an experienced penetration tester (or someone working in offensive security), do you think it’s worth continuing in this field if one of my main motivations is passion combined with the expectation of a financially rewarding career? I’d appreciate honest insights about what the real job market looks like and whether pen testing is still a viable long-term career option. <!-- SC_ON --> submitted by /u/n42- (https://www.reddit.com/user/n42-)
[link] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/) [comments] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/)
https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/
<!-- SC_OFF -->I’m at the very beginning of my journey into penetration testing, and I keep hearing mixed opinions about its financial stability as a career. Some people say the competition is fierce, stable positions are hard to get, and the income isn’t always worth the amount of effort required. I’ve also read that bug bounty programs aren’t as lucrative as many influencers make them seem, and relying on them for a consistent income can be unrealistic. From your perspective as an experienced penetration tester (or someone working in offensive security), do you think it’s worth continuing in this field if one of my main motivations is passion combined with the expectation of a financially rewarding career? I’d appreciate honest insights about what the real job market looks like and whether pen testing is still a viable long-term career option. <!-- SC_ON --> submitted by /u/n42- (https://www.reddit.com/user/n42-)
[link] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/) [comments] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/)
PenTest GPT
https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/
<!-- SC_OFF -->I am wondering if PenTest GPT is actually helpful, or if it is just another version of ChatGPT. Anyone has experience using it? <!-- SC_ON --> submitted by /u/turaoo (https://www.reddit.com/user/turaoo)
[link] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/)
https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/
<!-- SC_OFF -->I am wondering if PenTest GPT is actually helpful, or if it is just another version of ChatGPT. Anyone has experience using it? <!-- SC_ON --> submitted by /u/turaoo (https://www.reddit.com/user/turaoo)
[link] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/)
Google Cloud Partner API Credentials Found in Public Repo
Hey everyone,Continue reading on Medium »
Read more...
Hey everyone,Continue reading on Medium »
Read more...
Medium
Google Cloud Partner API Credentials Found in Public Repo
Hey everyone,
Active Directory Enumeration – ADWS
https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2025/08/12/active-directory-enumeration-adws/) [comments] (https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/)
https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2025/08/12/active-directory-enumeration-adws/) [comments] (https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/)
ChromeAlone: A Chromium Browser Implant Framework
https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/
submitted by /u/bouncyhat (https://www.reddit.com/user/bouncyhat)
[link] (https://github.com/praetorian-inc/chromealone) [comments] (https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/)
https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/
submitted by /u/bouncyhat (https://www.reddit.com/user/bouncyhat)
[link] (https://github.com/praetorian-inc/chromealone) [comments] (https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/)
Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/)
https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/)
CARTE tips?
https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/
<!-- SC_OFF -->Hi everyone. I will be attending the CARTE exam soon. any tips or stuff I should know before doing the exam? I can't seem to find a lot of reviews on the internet about this certification. I did CARTP (not the exam) so I have those enumeration notes ready as well. I heard it's a messy environment on purpose so wondering how that will play out. How did you find the exam? How long did you take it to complete? Let me know :) Thanks! <!-- SC_ON --> submitted by /u/SilverAd2716 (https://www.reddit.com/user/SilverAd2716)
[link] (https://www.alteredsecurity.com/carte-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/)
https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/
<!-- SC_OFF -->Hi everyone. I will be attending the CARTE exam soon. any tips or stuff I should know before doing the exam? I can't seem to find a lot of reviews on the internet about this certification. I did CARTP (not the exam) so I have those enumeration notes ready as well. I heard it's a messy environment on purpose so wondering how that will play out. How did you find the exam? How long did you take it to complete? Let me know :) Thanks! <!-- SC_ON --> submitted by /u/SilverAd2716 (https://www.reddit.com/user/SilverAd2716)
[link] (https://www.alteredsecurity.com/carte-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/)
My 100 Hour Rule for Bug Bounty !
https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5
https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5
In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…Continue reading on Medium » (https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5)
Google Cloud Partner API Credentials Found in Public Repo
https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5
https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5
Hey everyone,Continue reading on Medium » (https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5)
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been…Continue reading on Medium »
Read more...
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been…Continue reading on Medium »
Read more...
Medium
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been sanitized…
Understanding DOM-Based XSS in Acronis Promo Page: A Deep Dive
Exploring How to Detect and Exploit DOM-Based XSSContinue reading on T3CH »
Read more...
Exploring How to Detect and Exploit DOM-Based XSSContinue reading on T3CH »
Read more...
Medium
Understanding DOM-Based XSS in Acronis Promo Page: A Deep Dive
Exploring How to Detect and Exploit DOM-Based XSS
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
https://medium.com/@eclipsedmarauder/from-shodan-to-securing-government-systems-bfla-stored-xss-write-up-ab3bfd4e703d?source=rss------bug_bounty-5
https://medium.com/@eclipsedmarauder/from-shodan-to-securing-government-systems-bfla-stored-xss-write-up-ab3bfd4e703d?source=rss------bug_bounty-5