The reconnaissance methods that help security professionals map attack surfaces before a single exploit is launched.Continue reading on InfoSec-Writes Up » (https://medium.com/infosec-writes-up/10-recon-techniques-every-pentester-should-master-2c299d3e2826?source=rss------bug_bounty-5)
Seeking Advice (Red-Teaming)
https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/
<!-- SC_OFF -->Hi everyone, I'm a recent graduate who just started my first pentesting job, and my long-term goal has always been to work in red teaming, especially low-level work like malware development. I have some programming experience (mainly C and other languages. I live in a country where red team positions are very limited. So far I have eJPT, eWAPTX, OSCP, and CRTP, and I'm taking CWES soon. My original plan was to go for CRTO next. However, after talking to people in the field, many suggested that specializing in web or mobile security offers better career opportunities pay, and long-term growth even globally (since I might be moving) Some also said that red teaming isn't what most people imagine and that relatively few companies actually need dedicated red team operations. For those who work (or have worked) in red teaming, do you think it's still worth pursuing, or would you recommend focusing on web/mobile security instead? Thanks in advance for your advice! <!-- SC_ON --> submitted by /u/LowLifeNumber-7 (https://www.reddit.com/user/LowLifeNumber-7)
[link] (https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/) [comments] (https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/)
https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/
<!-- SC_OFF -->Hi everyone, I'm a recent graduate who just started my first pentesting job, and my long-term goal has always been to work in red teaming, especially low-level work like malware development. I have some programming experience (mainly C and other languages. I live in a country where red team positions are very limited. So far I have eJPT, eWAPTX, OSCP, and CRTP, and I'm taking CWES soon. My original plan was to go for CRTO next. However, after talking to people in the field, many suggested that specializing in web or mobile security offers better career opportunities pay, and long-term growth even globally (since I might be moving) Some also said that red teaming isn't what most people imagine and that relatively few companies actually need dedicated red team operations. For those who work (or have worked) in red teaming, do you think it's still worth pursuing, or would you recommend focusing on web/mobile security instead? Thanks in advance for your advice! <!-- SC_ON --> submitted by /u/LowLifeNumber-7 (https://www.reddit.com/user/LowLifeNumber-7)
[link] (https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/) [comments] (https://www.reddit.com/r/Pentesting/comments/1utlnso/seeking_advice_redteaming/)
Thinking about pivoting from Cloud Infra/API/AppSec to IoT security. What would I be in for and how should I approach?
https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/
<!-- SC_OFF -->Howdy folks! I apologize for the lengthy of this post. I havent written it yet, but I've been told I frequently write novels when asking questions due to the amount of context I add and trying to answer those types of questions before I receive them. I graduated with a CS degree about 3 years ago and currently work for an automotive company doing security testing. Without going into too much detail, each person on the team generally works on either systems within a vehicle or systems that communicate with the vehicle externally. I work on the latter. Typically this is APIs and Cloud infrastructure, but I occasionally get to work on aspects that are in the vehicle, like WiFi connectivity and BLE. However, we have someone who specialized in that wireless communication so they typically handle it. Anyway, I have ADHD, which affects my life in several different ways. One of which is that I get burnt out about once a year. Typically mid-late summer and early fall, so around this time lol. The other is that when I want to do/learn something, I tend to jump into the ocean head first and find my way up for air before I drown. Typically this works for me, I end up building aspects of a system that I'm trying to understand, which can take a long time when I know nothing, but usually gives me a better understanding and appreciation when I finish. The ADHD is also probably a contributing reason to my novel-length writing and my interesting in something new. For the last year or so, I've been really fascinated by the wireless work that our specialist does, and the hardware hacking our embedded team does, and I've wanted to learn more about it. In addition, while i don't think AI will ever fully take our jobs, as I think really thorough and good security testing at the end of the day requires some human ingenuity and trust, sometimes mgmt doesn't think that. And mgmt is the one hiring you so, their opinion matters more than mine. Given some of the direction we are being given from mgmt, which somewhat feels like those doom posts about people being asked to train an AI to take their own job, and my interest in this other side of product/application security really holding my interest, I felt now would be a good time to start diving in. To me it also makes sense that the job security may be better/more resilient to the AI doom mindset, even though I know the process of actually obtaining that kind of role is extremely difficult. Anyway, somehow this world is both larger than I imagined, and exactly as massive as I imagined, and I'm getting somewhat overwhelmed and would like some direction and maybe a reality check if I need it (I'm sure I do). Right now I'm working my way through Bare Metal C in both C and Zig without the STM IDE so I can have the "thrilling" experience of linking the libraries, making the build file, flashing, reading serial, etc. myself instead of having the IDE do everything. I am using the HAL right now though. I also am looking st the Practical IoT Hacking book which seems to tackle so, so many concepts that I'm trying to learn, but I'm concerned that if I go straight into breaking stuff without really learning the underlying systems and protocols, the only real difference between the book and throwing stuff at a wall would be someone is telling me which wall to throw and and which rock. Also concerned about at which point I'll need to spend considerable time learning about EE (which I have no background in). Ain't taken physics in many years so I'll have to relearn all the basic electrical physics and circuitry for that. The purpose is I feel I could be more effective at attacking and securing these kinds of things if I acquired a low level understanding of how they work and why
https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/
<!-- SC_OFF -->Howdy folks! I apologize for the lengthy of this post. I havent written it yet, but I've been told I frequently write novels when asking questions due to the amount of context I add and trying to answer those types of questions before I receive them. I graduated with a CS degree about 3 years ago and currently work for an automotive company doing security testing. Without going into too much detail, each person on the team generally works on either systems within a vehicle or systems that communicate with the vehicle externally. I work on the latter. Typically this is APIs and Cloud infrastructure, but I occasionally get to work on aspects that are in the vehicle, like WiFi connectivity and BLE. However, we have someone who specialized in that wireless communication so they typically handle it. Anyway, I have ADHD, which affects my life in several different ways. One of which is that I get burnt out about once a year. Typically mid-late summer and early fall, so around this time lol. The other is that when I want to do/learn something, I tend to jump into the ocean head first and find my way up for air before I drown. Typically this works for me, I end up building aspects of a system that I'm trying to understand, which can take a long time when I know nothing, but usually gives me a better understanding and appreciation when I finish. The ADHD is also probably a contributing reason to my novel-length writing and my interesting in something new. For the last year or so, I've been really fascinated by the wireless work that our specialist does, and the hardware hacking our embedded team does, and I've wanted to learn more about it. In addition, while i don't think AI will ever fully take our jobs, as I think really thorough and good security testing at the end of the day requires some human ingenuity and trust, sometimes mgmt doesn't think that. And mgmt is the one hiring you so, their opinion matters more than mine. Given some of the direction we are being given from mgmt, which somewhat feels like those doom posts about people being asked to train an AI to take their own job, and my interest in this other side of product/application security really holding my interest, I felt now would be a good time to start diving in. To me it also makes sense that the job security may be better/more resilient to the AI doom mindset, even though I know the process of actually obtaining that kind of role is extremely difficult. Anyway, somehow this world is both larger than I imagined, and exactly as massive as I imagined, and I'm getting somewhat overwhelmed and would like some direction and maybe a reality check if I need it (I'm sure I do). Right now I'm working my way through Bare Metal C in both C and Zig without the STM IDE so I can have the "thrilling" experience of linking the libraries, making the build file, flashing, reading serial, etc. myself instead of having the IDE do everything. I am using the HAL right now though. I also am looking st the Practical IoT Hacking book which seems to tackle so, so many concepts that I'm trying to learn, but I'm concerned that if I go straight into breaking stuff without really learning the underlying systems and protocols, the only real difference between the book and throwing stuff at a wall would be someone is telling me which wall to throw and and which rock. Also concerned about at which point I'll need to spend considerable time learning about EE (which I have no background in). Ain't taken physics in many years so I'll have to relearn all the basic electrical physics and circuitry for that. The purpose is I feel I could be more effective at attacking and securing these kinds of things if I acquired a low level understanding of how they work and why
they work that way. If I work top down too low, I may eventually need to start working bottom up to understand better where I am. Though I know that maybe its unnecessary for my goals, and I don't want to invest that much time if it won't be helpful to me. Based on where I'm at and what I'm trying to do, any recommendations for a good path to follow? Am I on the right one or should I pivot? I eventually need to tackle a lot of this Wireless stuff (BLE, RFID/NFC, Cellular, WiFi, Zigbee, Matter, etc), how should that be handled? How can I keep my scope narrow enough to not be overwhelmed but also broad enough to be effective? Dont want to go back to college or spend a ton of money, I know there's gotta be plenty of brilliant free resources for this stuff. TL;DR: Currently work in Cloud Infra/API security testing. Want to learn/pivot to IoT and embedded security both for work purposes and personal interest/enjoyment. What's a good methodology for going about it and what to focus on to avoid burnout and being overwhelmed? All advice is appreciated, and more than happy to answer any questions or concerns. Thank you! <!-- SC_ON --> submitted by /u/Few-Excitement-91 (https://www.reddit.com/user/Few-Excitement-91)
[link] (https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/)
[link] (https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uu4f9m/thinking_about_pivoting_from_cloud_infraapiappsec/)
Does PRET full support Python 3?
https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/
<!-- SC_OFF -->PRET was written in Python2.7 but they have updated the code base but i tired using it it's not working properly, so does anyone still have issues with it? And is there any alternative tool similar to PRET? Update:- There is no issue in code itself, the ported version is correct. <!-- SC_ON --> submitted by /u/Dependent-Access-796 (https://www.reddit.com/user/Dependent-Access-796)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/)
https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/
<!-- SC_OFF -->PRET was written in Python2.7 but they have updated the code base but i tired using it it's not working properly, so does anyone still have issues with it? And is there any alternative tool similar to PRET? Update:- There is no issue in code itself, the ported version is correct. <!-- SC_ON --> submitted by /u/Dependent-Access-796 (https://www.reddit.com/user/Dependent-Access-796)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuewy6/does_pret_full_support_python_3/)
Macbook for Pentesting?
https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/
<!-- SC_OFF -->Hola amigos! Anyone in this group using the macbook with M chips for pentesting or cybersecurity related tasks? I want to know if it suits me well.. What Issues I might face while going with the M chip for pentesting? What issues (compatibility issues) can happen when using a virtual machine like kali,parrot with paralells/VMware fusion/UTM? Should I go with x86 laptops? Anyone ever felt ,buying Arm chip was a mistake? Any information related to this would be fine. ▪️ I am choosing the mac mainly because of the battery backup, easy to carry ,while it looks value for money for me. ▪️I had another choice that is ThinkPad x1 carbon but it still have less battery backup (than macbook) and looks a bit expensive. Its my first post ever! so please help this noob😇, Sorry if this is a duplicate post. Thanks in advance🙌 Please don't down vote 🥲 (sorry for my bad english) <!-- SC_ON --> submitted by /u/aesthreatics (https://www.reddit.com/user/aesthreatics)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/
<!-- SC_OFF -->Hola amigos! Anyone in this group using the macbook with M chips for pentesting or cybersecurity related tasks? I want to know if it suits me well.. What Issues I might face while going with the M chip for pentesting? What issues (compatibility issues) can happen when using a virtual machine like kali,parrot with paralells/VMware fusion/UTM? Should I go with x86 laptops? Anyone ever felt ,buying Arm chip was a mistake? Any information related to this would be fine. ▪️ I am choosing the mac mainly because of the battery backup, easy to carry ,while it looks value for money for me. ▪️I had another choice that is ThinkPad x1 carbon but it still have less battery backup (than macbook) and looks a bit expensive. Its my first post ever! so please help this noob😇, Sorry if this is a duplicate post. Thanks in advance🙌 Please don't down vote 🥲 (sorry for my bad english) <!-- SC_ON --> submitted by /u/aesthreatics (https://www.reddit.com/user/aesthreatics)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuh97s/macbook_for_pentesting/)
As someone who wants to get into VAPT what am i supposed to showcase in my github??
https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/
submitted by /u/Loud_Balance_334 (https://www.reddit.com/user/Loud_Balance_334)
[link] (https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/)
https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/
submitted by /u/Loud_Balance_334 (https://www.reddit.com/user/Loud_Balance_334)
[link] (https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uujxar/as_someone_who_wants_to_get_into_vapt_what_am_i/)
hELLO world
https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/
<!-- SC_OFF -->This is my first reddit post. Let's conquer the world <!-- SC_ON --> submitted by /u/HumorSenior837 (https://www.reddit.com/user/HumorSenior837)
[link] (https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/)
https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/
<!-- SC_OFF -->This is my first reddit post. Let's conquer the world <!-- SC_ON --> submitted by /u/HumorSenior837 (https://www.reddit.com/user/HumorSenior837)
[link] (https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uum5mx/hello_world/)
Can Autonomous Pentesting tools detect BOLAs and Business logic Vulnerabilites in IRL?
https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/
<!-- SC_OFF -->I've been seeing a ton of buzz lately about autonomous/agentic pentesting tools (AI agents, multi-agent systems, etc.) supposedly crushing BOLA (Broken Object Level Authorization), IDOR variants, and business logic flaws that traditional automated scanners always miss. Things like privilege escalation across users, workflow bypasses, cart manipulation, etc. Is this legit IRL in 2026, or just hype? <!-- SC_ON --> submitted by /u/SeaLordVanguard (https://www.reddit.com/user/SeaLordVanguard)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/)
https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/
<!-- SC_OFF -->I've been seeing a ton of buzz lately about autonomous/agentic pentesting tools (AI agents, multi-agent systems, etc.) supposedly crushing BOLA (Broken Object Level Authorization), IDOR variants, and business logic flaws that traditional automated scanners always miss. Things like privilege escalation across users, workflow bypasses, cart manipulation, etc. Is this legit IRL in 2026, or just hype? <!-- SC_ON --> submitted by /u/SeaLordVanguard (https://www.reddit.com/user/SeaLordVanguard)
[link] (https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuq7bk/can_autonomous_pentesting_tools_detect_bolas_and/)
PHANTOMPRINT – Passive hybrid fingerprinting engine: identify OS/browser/device without sending a single packet
https://www.reddit.com/r/Pentesting/comments/1uuwr5o/phantomprint_passive_hybrid_fingerprinting_engine/
https://www.reddit.com/r/Pentesting/comments/1uuwr5o/phantomprint_passive_hybrid_fingerprinting_engine/
Bug bounties or Machines?
https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/
<!-- SC_OFF -->I apologize in advance for lacking brevity but I typed this out during my mid day existential lunch break crisis. I have worked on a two pentesting assignments in the last 2.5 years, with decent findings (all web application focused)… a lot of it has been self teaching as I go so I have major imposter syndrome. No certs but I have a master’s in cybersecurity as well as some quality findings from these assignments, one of which I lead (mainly due to staffing shortages). For maximizing future career opportunities, I’m conflicted if I should go down the hole of pentesting which includes network enumeration, AD, etc… or if I should hone my craft at web applications first (I know I need to at least get familiar with it all) I have been worried about AI’s effectiveness at web application testing thus my goal was to deepen my skills beyond just web apps but I feel conflicted time wise… Currently pursuing HTBs pen test course with the end goal of going for the OSCP or maybe even the CPTS.
However I also want to spend my time doing real world tests like bug bounties that I could put on my resumé but outside of my main job, getting through HTB’s modules takes most of my time. I understand as a pentester you are always managing different hats but right now I feel like my efforts are split and want to make sure I’m not taking any wrong steps that would diminish my job prospects in the future, especially as AI is evolving at such a quick rate. With all this being said, in the current and near future climate, should I prioritize my web app skills and search for bug bounties or should I broaden my skills and attempt various boxes on HTB (or other websites) in prep for certs? Any input from the vets out there will be much appreciated. Thank you again for reading through my brain dump. <!-- SC_ON --> submitted by /u/Lopsided-Barnacle-28 (https://www.reddit.com/user/Lopsided-Barnacle-28)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/)
https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/
<!-- SC_OFF -->I apologize in advance for lacking brevity but I typed this out during my mid day existential lunch break crisis. I have worked on a two pentesting assignments in the last 2.5 years, with decent findings (all web application focused)… a lot of it has been self teaching as I go so I have major imposter syndrome. No certs but I have a master’s in cybersecurity as well as some quality findings from these assignments, one of which I lead (mainly due to staffing shortages). For maximizing future career opportunities, I’m conflicted if I should go down the hole of pentesting which includes network enumeration, AD, etc… or if I should hone my craft at web applications first (I know I need to at least get familiar with it all) I have been worried about AI’s effectiveness at web application testing thus my goal was to deepen my skills beyond just web apps but I feel conflicted time wise… Currently pursuing HTBs pen test course with the end goal of going for the OSCP or maybe even the CPTS.
However I also want to spend my time doing real world tests like bug bounties that I could put on my resumé but outside of my main job, getting through HTB’s modules takes most of my time. I understand as a pentester you are always managing different hats but right now I feel like my efforts are split and want to make sure I’m not taking any wrong steps that would diminish my job prospects in the future, especially as AI is evolving at such a quick rate. With all this being said, in the current and near future climate, should I prioritize my web app skills and search for bug bounties or should I broaden my skills and attempt various boxes on HTB (or other websites) in prep for certs? Any input from the vets out there will be much appreciated. Thank you again for reading through my brain dump. <!-- SC_ON --> submitted by /u/Lopsided-Barnacle-28 (https://www.reddit.com/user/Lopsided-Barnacle-28)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvf87g/bug_bounties_or_machines/)
submitted by /u/Shoddy-Pay8867 (https://www.reddit.com/user/Shoddy-Pay8867)
[link] (https://github.com/haruu77g/phantomprint) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuwr5o/phantomprint_passive_hybrid_fingerprinting_engine/)
[link] (https://github.com/haruu77g/phantomprint) [comments] (https://www.reddit.com/r/Pentesting/comments/1uuwr5o/phantomprint_passive_hybrid_fingerprinting_engine/)
HephaestusGuard - Pentesting pipeline 100% open-source
https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/
<!-- SC_OFF -->I built a pentesting orchestrator that integrates Nmap, Nikto, OpenVAS and Metasploit into a single pipeline. It's free, open-source, and perfect for SMEs and pentesters with limited budgets. Features: 📡 Nmap (network discovery) 🌐 Nikto (web scanning) 🔍 OpenVAS (vulnerability assessment) 💣 Metasploit (service enumeration) 📊 Real-time web dashboard ⚙️ YAML configuration 🐳 Docker orchestration 💰 100% free (MIT license) GitHub: https://github.com/rafajimenezdev/hephaestusguard Perfect for: SMEs without big security budgets Independent pentesters Students Automation enthusiasts Contributions welcome! 🙌 <!-- SC_ON --> submitted by /u/rafajimenezdev (https://www.reddit.com/user/rafajimenezdev)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/)
https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/
<!-- SC_OFF -->I built a pentesting orchestrator that integrates Nmap, Nikto, OpenVAS and Metasploit into a single pipeline. It's free, open-source, and perfect for SMEs and pentesters with limited budgets. Features: 📡 Nmap (network discovery) 🌐 Nikto (web scanning) 🔍 OpenVAS (vulnerability assessment) 💣 Metasploit (service enumeration) 📊 Real-time web dashboard ⚙️ YAML configuration 🐳 Docker orchestration 💰 100% free (MIT license) GitHub: https://github.com/rafajimenezdev/hephaestusguard Perfect for: SMEs without big security budgets Independent pentesters Students Automation enthusiasts Contributions welcome! 🙌 <!-- SC_ON --> submitted by /u/rafajimenezdev (https://www.reddit.com/user/rafajimenezdev)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvo5y6/hephaestusguard_pentesting_pipeline_100_opensource/)
CPENT from EC Council
https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/
<!-- SC_OFF -->I have just finished CEH and don’t feel that I have a lot pratical knowledge about cybersecurity.
Can someone that finished CPEN provide some feedback, how was it and is it worth or not. <!-- SC_ON --> submitted by /u/Just_Knee_4463 (https://www.reddit.com/user/Just_Knee_4463)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/)
https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/
<!-- SC_OFF -->I have just finished CEH and don’t feel that I have a lot pratical knowledge about cybersecurity.
Can someone that finished CPEN provide some feedback, how was it and is it worth or not. <!-- SC_ON --> submitted by /u/Just_Knee_4463 (https://www.reddit.com/user/Just_Knee_4463)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/)
D-Link DIR-825 H/W Version J3 Any 3rd party firmware
https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/
<!-- SC_OFF -->Hey sup guys, i just recently bought a router of D-Link DIR-825 J3 H/W Version, any 3rd party firmware to flash and use it for wifi pentesting. <!-- SC_ON --> submitted by /u/V01DL0RD_1 (https://www.reddit.com/user/V01DL0RD_1)
[link] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/)
https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/
<!-- SC_OFF -->Hey sup guys, i just recently bought a router of D-Link DIR-825 J3 H/W Version, any 3rd party firmware to flash and use it for wifi pentesting. <!-- SC_ON --> submitted by /u/V01DL0RD_1 (https://www.reddit.com/user/V01DL0RD_1)
[link] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/)
CRTP exam
https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/
<!-- SC_OFF -->I'm about to finish CRTP course from altered security I want to be overprepared for the exam therefore currently i'm playing rooms on hack the box I'm asking about the exam structure, all i know is i have 24 hours to compromise the forest or domain and 48 hours to write report and i know i should get 70 points of 100 How many machine are there? How many domain? Is it a simulation to the labs in the course or harder? Do i need to study something extra or course content attacks is enough I don't know a lot of things honestly i need help <!-- SC_ON --> submitted by /u/Left-Efficiency6514 (https://www.reddit.com/user/Left-Efficiency6514)
[link] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/)
https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/
<!-- SC_OFF -->I'm about to finish CRTP course from altered security I want to be overprepared for the exam therefore currently i'm playing rooms on hack the box I'm asking about the exam structure, all i know is i have 24 hours to compromise the forest or domain and 48 hours to write report and i know i should get 70 points of 100 How many machine are there? How many domain? Is it a simulation to the labs in the course or harder? Do i need to study something extra or course content attacks is enough I don't know a lot of things honestly i need help <!-- SC_ON --> submitted by /u/Left-Efficiency6514 (https://www.reddit.com/user/Left-Efficiency6514)
[link] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/)
Где найти первый опыт?
https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/
<!-- SC_OFF -->Всем привет!
я горю мыслью работать в безопасности и чуток проанализировав рынок, выяснил , что в основном все начинают с soc аналитика
где нынче найти норм стажировки или вакансии на это место?
я готов хоть бесплатно, дайте только опыт <!-- SC_ON --> submitted by /u/Radiant-Strength-448 (https://www.reddit.com/user/Radiant-Strength-448)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/)
https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/
<!-- SC_OFF -->Всем привет!
я горю мыслью работать в безопасности и чуток проанализировав рынок, выяснил , что в основном все начинают с soc аналитика
где нынче найти норм стажировки или вакансии на это место?
я готов хоть бесплатно, дайте только опыт <!-- SC_ON --> submitted by /u/Radiant-Strength-448 (https://www.reddit.com/user/Radiant-Strength-448)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/)
LF Red Team Testers
https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/
<!-- SC_OFF -->Looking for tester for my Red Teaming tool that can run tests against - LLMs, Agents, Chatbots and MCP Servers. RedPlayer1.ai (http://redplayer1.ai/) Need some feedback and beta testers. Break it or let me know what could be better. <!-- SC_ON --> submitted by /u/DWDURB (https://www.reddit.com/user/DWDURB)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/)
https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/
<!-- SC_OFF -->Looking for tester for my Red Teaming tool that can run tests against - LLMs, Agents, Chatbots and MCP Servers. RedPlayer1.ai (http://redplayer1.ai/) Need some feedback and beta testers. Break it or let me know what could be better. <!-- SC_ON --> submitted by /u/DWDURB (https://www.reddit.com/user/DWDURB)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/)
Roadmap for penetration
https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/
<!-- SC_OFF -->Guys I want to learn penetration (hacking) I've learned network+ and Linux essential already what should I do next? Use tryhackme? Or ceh? Kali Linux? Actuve directory? Security+?bash scripting? Wireshark? What? Please give me a roadmap guys <!-- SC_ON --> submitted by /u/Full_Unit9235 (https://www.reddit.com/user/Full_Unit9235)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/)
https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/
<!-- SC_OFF -->Guys I want to learn penetration (hacking) I've learned network+ and Linux essential already what should I do next? Use tryhackme? Or ceh? Kali Linux? Actuve directory? Security+?bash scripting? Wireshark? What? Please give me a roadmap guys <!-- SC_ON --> submitted by /u/Full_Unit9235 (https://www.reddit.com/user/Full_Unit9235)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/)
Analysis of Spreadtrum Longcheer chipsets
https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/
<!-- SC_OFF -->This report details a systemic security failure affecting millions of budget Android devices deployed across Latin America. The vulnerability is not a single software bug but a deliberate supply chain deception orchestrated by ODM Longcheer and SoC vendor Unisoc, facilitated by OEM Motorola. The core issue involves a hardcoded fscrypt provisioning bypass triggered by LCD ID lcd_td4168 and key 56ef134d... that allows the distribution of fraudulent security updates. These updates spoof the security patch level claiming "April 2026" while running vulnerable binaries from "March 2026", masking critical flaws like CVE-2021-39658 ismsEx, CVE-2022-38694 BootROM, and exported backdoors in com.spreadtrum.sgps. This architecture creates a permanent attack surface that facilitates active financial fraud PIX hijacking, surveillance, and enterprise network compromise in the Latin American region, where these devices dominate the market. The Attack Chain: "Silent Rescue" The risk is compounded by a chain of vulnerabilities that work in concert: Hardware Root Unpatchable: CVE-2022-38694 in the Unisoc BootROM allows permanent bypass of Secure Boot via physical USB access. Public tools spd_dump exist. Remote Entry Network: CVE-2025-31718 Modem RCE allows remote code execution via rogue cell towers IMSI catchers, common in urban LATAM centers. Privilege Escalation Zero-Permission: CVE-2021-39658 ismsEx service allows any app to send SMS or modify system properties without permissions, bypassing Android 2FA. System Backdoors Exported Components: com.spreadtrum.sgps exposes location tracking and system controls via dialer codes _#_#2266#_#_. Payload Delivery Silent Installers: Pre-installed system apps com.dti.amx Digital Turbine and com.inmobi.installer hold INSTALL_PACKAGES, allowing silent installation of banking trojans e.g., PixRevolution without user consent. The Cover-Up FOTA Spoofing: The fscrypt bypass injects a fake ro.build.version.security_patch string, tricking users, banks, and MDM systems into believing the device is secure. Critical Risk to Latin America LATAM The impact on Latin America is disproportionate and severe due to market dynamics and reliance on mobile finance. A. Market Dominance of Vulnerable Devices Ubiquity: Unisoc T606/T616 chipsets power the best-selling budget devices in the region Motorola Moto G04s, G24, Infinix, Tecno. Search results confirm Unisoc's aggressive expansion in LATAM, with over 100 5G devices deployed in the region by 2025. Demographic Impact: These devices are the primary computing tool for unbanked and underbanked populations who rely exclusively on smartphones for government aid, commerce, and banking. B. Direct Threat to Financial Infrastructure PIX & Billetera Móvil Active Exploitation: The PixRevolution trojan identified March 2026 actively hijacks PIX instant payments in Brazil by overlaying fake screens and diverting funds in real-time. The Enabler: The vulnerabilities in this report ismsEx SMS bypass, INSTALL_PACKAGES silent installer, exported SGPS location tracking provide the perfect infrastructure for such malware to operate undetected. 2FA Bypass: CVE-2021-39658 allows malware to read or intercept SMS verification codes without permission, rendering traditional 2FA useless for banking apps. C. Enterprise & Supply Chain Risk MDM Evasion: Corporate Mobile Device Management MDM systems rely on the security_patch string to enforce compliance. The FOTA spoofing mechanism ensures that compromised devices report "Compliant" status while running vulnerable firmware, allowing them to bypass corporate security gates. Data Exfiltration: The com.motorola.bach.modemstats service with READ_LOGS and MANAGE_NETWORK_POLICY can be weaponized to exfiltrate corporate data over hidden backchannels that ignore data usage limits. D. The "Fake Patch"
https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/
<!-- SC_OFF -->This report details a systemic security failure affecting millions of budget Android devices deployed across Latin America. The vulnerability is not a single software bug but a deliberate supply chain deception orchestrated by ODM Longcheer and SoC vendor Unisoc, facilitated by OEM Motorola. The core issue involves a hardcoded fscrypt provisioning bypass triggered by LCD ID lcd_td4168 and key 56ef134d... that allows the distribution of fraudulent security updates. These updates spoof the security patch level claiming "April 2026" while running vulnerable binaries from "March 2026", masking critical flaws like CVE-2021-39658 ismsEx, CVE-2022-38694 BootROM, and exported backdoors in com.spreadtrum.sgps. This architecture creates a permanent attack surface that facilitates active financial fraud PIX hijacking, surveillance, and enterprise network compromise in the Latin American region, where these devices dominate the market. The Attack Chain: "Silent Rescue" The risk is compounded by a chain of vulnerabilities that work in concert: Hardware Root Unpatchable: CVE-2022-38694 in the Unisoc BootROM allows permanent bypass of Secure Boot via physical USB access. Public tools spd_dump exist. Remote Entry Network: CVE-2025-31718 Modem RCE allows remote code execution via rogue cell towers IMSI catchers, common in urban LATAM centers. Privilege Escalation Zero-Permission: CVE-2021-39658 ismsEx service allows any app to send SMS or modify system properties without permissions, bypassing Android 2FA. System Backdoors Exported Components: com.spreadtrum.sgps exposes location tracking and system controls via dialer codes _#_#2266#_#_. Payload Delivery Silent Installers: Pre-installed system apps com.dti.amx Digital Turbine and com.inmobi.installer hold INSTALL_PACKAGES, allowing silent installation of banking trojans e.g., PixRevolution without user consent. The Cover-Up FOTA Spoofing: The fscrypt bypass injects a fake ro.build.version.security_patch string, tricking users, banks, and MDM systems into believing the device is secure. Critical Risk to Latin America LATAM The impact on Latin America is disproportionate and severe due to market dynamics and reliance on mobile finance. A. Market Dominance of Vulnerable Devices Ubiquity: Unisoc T606/T616 chipsets power the best-selling budget devices in the region Motorola Moto G04s, G24, Infinix, Tecno. Search results confirm Unisoc's aggressive expansion in LATAM, with over 100 5G devices deployed in the region by 2025. Demographic Impact: These devices are the primary computing tool for unbanked and underbanked populations who rely exclusively on smartphones for government aid, commerce, and banking. B. Direct Threat to Financial Infrastructure PIX & Billetera Móvil Active Exploitation: The PixRevolution trojan identified March 2026 actively hijacks PIX instant payments in Brazil by overlaying fake screens and diverting funds in real-time. The Enabler: The vulnerabilities in this report ismsEx SMS bypass, INSTALL_PACKAGES silent installer, exported SGPS location tracking provide the perfect infrastructure for such malware to operate undetected. 2FA Bypass: CVE-2021-39658 allows malware to read or intercept SMS verification codes without permission, rendering traditional 2FA useless for banking apps. C. Enterprise & Supply Chain Risk MDM Evasion: Corporate Mobile Device Management MDM systems rely on the security_patch string to enforce compliance. The FOTA spoofing mechanism ensures that compromised devices report "Compliant" status while running vulnerable firmware, allowing them to bypass corporate security gates. Data Exfiltration: The com.motorola.bach.modemstats service with READ_LOGS and MANAGE_NETWORK_POLICY can be weaponized to exfiltrate corporate data over hidden backchannels that ignore data usage limits. D. The "Fake Patch"