Sign in

PentesterLab

@pentesterlab.com
747 followers 0 following 138 posts

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

PostsRepliesMedia
PentesterLab @pentesterlab.com · 28/04/2026
New badge: JavaScript Sandbox Escape! The first 4 labs are live. If you ship anything that evaluates untrusted or model-generated JavaScript, this badge is for you: pentesterlab.com/badges/javas...
pentesterlab.com
PentesterLab: Learn with our JavaScript Sandbox Escaping
This badge covers JavaScript sandbox escape vulnerabilities. From prototype chain navigation and Function constructor abuse to vm module escapes, static-eval bypasses, real-world CVEs, and advanced pr...
044
PentesterLab @pentesterlab.com · 29/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟯, 𝟮𝟬𝟮𝟲 Only one entry but definitely worth reading! ☁️ 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗺𝗺𝗮𝗻𝗱 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 𝗶𝗻 𝗚𝗼𝗼𝗴𝗹𝗲 𝗖𝗹𝗼𝘂𝗱 𝘄𝗶𝘁𝗵 𝗦𝗶𝗻𝗴𝗹𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆 𝗗𝗲𝗹𝗲𝘁𝗶𝗼𝗻 This one is a real tour de force: flatt.tech/research/pos....
flatt.tech
Remote Command Execution in Google Cloud with Single Directory Deletion
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...
021
Reposted by PentesterLab
Dominique Righetto @righettod.eu · 26/03/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation). #appsec #appsecurity
121
PentesterLab @pentesterlab.com · 22/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟮, 𝟮𝟬𝟮𝟲 AI doing research, AI killing CTF 🤖 𝗧𝗲𝘀𝘁𝗶𝗻𝗴 𝗔𝗜 𝗳𝗼𝗿 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵: 𝟰 𝗔𝗽𝗽𝗿𝗼𝗮𝗰𝗵𝗲𝘀 & 𝗪𝗵𝗲𝗿𝗲 𝗜 𝗙𝗮𝗶𝗹𝗲𝗱 If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.
xclow3n.github.io
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n
Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs — 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...
142
Reposted by PentesterLab
Dominique Righetto @righettod.eu · 14/03/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation): #appsec #appsecurity
Example of execution.
111
PentesterLab @pentesterlab.com · 10/03/2026
A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password. Why? Longer SHA-256 nonce + bcrypt truncation at 72 bytes. A nice example of why secure systems are about composition, not just stronger primitives. pentesterlab.com/blog/freshrs...
pentesterlab.com
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...
095
PentesterLab @pentesterlab.com · 08/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟬, 𝟮𝟬𝟮𝟲 A great mix of content this week! 🔒 𝗜𝗿𝗼𝗻𝗖𝘂𝗿𝘁𝗮𝗶𝗻: 𝗔 𝗣𝗲𝗿𝘀𝗼𝗻𝗮𝗹 𝗔𝗜 𝗔𝘀𝘀𝗶𝘀𝘁𝗮𝗻𝘁 𝗕𝘂𝗶𝗹𝘁 𝗦𝗲𝗰𝘂𝗿𝗲 𝗳𝗿𝗼𝗺 𝘁𝗵𝗲 𝗚𝗿𝗼𝘂𝗻𝗱 𝗨𝗽 Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....
141
PentesterLab @pentesterlab.com · 01/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟵, 𝟮𝟬𝟮𝟲 Mostly AI... 💻 𝗕𝗿𝗼𝘄𝘀𝗲𝗿-𝗕𝗮𝘀𝗲𝗱 𝗣𝗼𝗿𝘁 𝗦𝗰𝗮𝗻𝗻𝗶𝗻𝗴 𝗶𝗻 𝘁𝗵𝗲 𝗔𝗴𝗲 𝗼𝗳 𝗟𝗡𝗔 Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
wiki.notveg.ninja
Browser-Based Port Scanning in the Age of LNA
123
PentesterLab @pentesterlab.com · 28/02/2026
6 new code review labs just dropped 🚀 +3 for JavaScript Code Review +3 for Python Code Review JS: pentesterlab.com/badges/javas... Python: pentesterlab.com/badges/pytho...
pentesterlab.com
PentesterLab: Learn with our JavaScript Code Review
The JavaScript Code Review Badge is our badge dedicated to security code review in JavaScript. It covers the discovery of weaknesses and vulnerabilities using source code review.
052
Reposted by PentesterLab
Kirushan Rasendran @kirushan.com · 28/02/2026
As I mentioned last week I ordered some books (which got delivered this week) CVE ARCHEOLOGIST'S FIELD GUIDE by Louis Nyffenegger @pentesterlab.com
CVE Archeologist's field guide
Methodology and Lessons from 10 Vulnerability Analyses 
Written by Louis Nyffenegger
111
PentesterLab @pentesterlab.com · 22/02/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟴, 𝟮𝟬𝟮𝟲 Java x2, Go, JWT and a sprinkling of AI 🦫 𝗖𝗧𝗙𝘁𝗶𝗺𝗲.𝗼𝗿𝗴 / 𝗷𝘂𝘀𝘁𝗖𝗧𝗙 [*] 𝟮𝟬𝟮𝟬 / 𝗚𝗼-𝗳𝘀 / 𝗪𝗿𝗶𝘁𝗲𝘂𝗽 A cool Golang quirk via an unintended CTF solution ctftime.org/writeup/25852.
ctftime.org
CTFtime.org / justCTF [*] 2020 / Go-fs / Writeup
CTF writeups, Go-fs
110
PentesterLab @pentesterlab.com · 16/02/2026
New lab: CVE-2026-24895 — FrankenPHP Path Confusion RCE (Unicode) People think "lowercase it" is harmless. In Unicode it’s not. Case folding can do weird mappings (Turkish i, Kelvin sign…), and sometimes worse: UTF-8 byte length changes. Hands-on lab: pentesterlab.com/exercises/cv...
030
PentesterLab @pentesterlab.com · 16/02/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟳, 𝟮𝟬𝟮𝟲 Parser Differential, TypeScript and AI 👇
131
PentesterLab @pentesterlab.com · 08/02/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟲, 𝟮𝟬𝟮𝟲 Busy week! AI, AI, AI and the death of Flash! 🤖 𝗦𝗲𝗺𝗴𝗿𝗲𝗽'𝘀 𝗔𝗴𝗲𝗻𝘁 𝗦𝗸𝗶𝗹𝗹𝘀 Semgrep released a set of agent skills worth looking into: github.com/semgrep/skills.
github.com
GitHub - semgrep/skills: A collection of skills for AI coding agents from Semgrep
A collection of skills for AI coding agents from Semgrep - semgrep/skills
141
Reposted by PentesterLab
Dominique Righetto @righettod.eu · 02/02/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com and Claude. 🔬 For the regular expression "[A-z]": In a character class [X-Y], it matches all characters with ASCII codes from X to Y inclusive. So [A-z] means all ASCII characters from 65 (A) to 122 (z). #appsec #appsecurity
Execution of the POC performed.
141
PentesterLab @pentesterlab.com · 06/02/2026
MORE LABS IN OUR JAVASCRIPT CODE REVIEW BADGE: pentesterlab.com/badges/javas...
021
PentesterLab @pentesterlab.com · 02/02/2026
Research Worth Reading - Week 5, 2026 Bugs EVERYWHERE….
101
PentesterLab @pentesterlab.com · 21/01/2026
🔥 CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg. Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes. Write-up + fix: pentesterlab.com/blog/cve-202...
pentesterlab.com
CVE-2026-23993: JWT authentication bypass in HarbourJwt via “unknown alg”
I didn't know Harbour even existed as a language when I found this bug. The fun part is that I also ...
066
PentesterLab @pentesterlab.com · 18/01/2026
Research Worth Reading Week 03/2026 Claude RedTeam, Claude Hacking, Claude Skills...Is it Claude week? 🤖 AI models are showing a greater ability to find and exploit vulnerabilities The latest Claude models are getting noticeably better at hacking: red.anthropic.com/2026/cyber-t...
red.anthropic.com
AI Models on Realistic Cyber Ranges \ red.anthropic.com
110
PentesterLab @pentesterlab.com · 06/01/2026
Happy New Year! Research Worth Reading Week 01/2026! 💧 Cross-Site ETag Length Leak An amazing CTF write-up on XS Leaks. Make sure you also read the unintended solution linked at the bottom of the page: blog.arkark.dev/2025/12/26/e...
blog.arkark.dev
Cross-Site ETag Length Leak | XS-Spin Blog
A novel XS-Leak technique that turns ETag length differences into a cross-site oracle via 431 errors and History API.
121
Reposted by PentesterLab
Codebender_Cate @codebendercate.com · 01/01/2026
A surprise from @pentesterlab.com
061
PentesterLab @pentesterlab.com · 21/12/2025
Research Worth Reading Week 51/2025 A quieter week that perfectly fits the two deep dives! 📚 ORM Leaking More Than You Joined For The latest opus in Elttam's posts on ORM leaks, including some semgrep rules and a reference to my blog post on the subject: www.elttam.com/blog/leaking...
elttam.com
ORM Leaking More Than You Joined For - elttamORM Leaking More Than You Joined For - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.
110
PentesterLab @pentesterlab.com · 14/12/2025
Research Worth Reading Week 50/2025: SAML bypasses & LLM-assisted crash triage. 🔒 The Fragile Lock: Novel Bypasses for SAML Authentication Ruby SAML falls again. An extraordinary exploit by the PortSwigger team: portswigger.net/research/the...
portswigger.net
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
211
Reposted by PentesterLab
Dominique Righetto @righettod.eu · 13/12/2025
🧑‍🎓 Learning of the day for me thanks to: - @pentesterlab.com for the presentation of the behavior and the code review lab. - ChatGPT for the detailed explanation. #appsec #appsecurity #python
Example of execution.
121
Reposted by PentesterLab
mXgarweg @michaelxg.bsky.social · 14/12/2025
I just completed @pentesterlab.com 's Recon Badge!!!
011
PentesterLab @pentesterlab.com · 09/12/2025
Welcome back to Slytherin! 🐍 We just released 3 new labs in our python^w Slytherin code review badge: real CVEs, sneaky bugs, and plenty of chances to sharpen your dark code arts.. Grab your wand here: pentesterlab.com/badges/pytho...
pentesterlab.com
PentesterLab: Learn with our Python Code Review Badge
The Python Code Review Badge is our badge dedicated to code review in Python. It covers the discovery of weaknesses and vulnerabilities using source code review.
021
PentesterLab @pentesterlab.com · 07/12/2025
Research Worth Reading Week 49/2025: ⏰ Introducing constant-time support for LLVM to protect cryptographic code Trail of Bits explains their work on adding constant-time support to LLVM so that compiled cryptographic code remains constant-time: blog.trailofbits.com/2025/12/02/i...
blog.trailofbits.com
Introducing constant-time support for LLVM to protect cryptographic code
Trail of Bits developed constant-time coding support for LLVM that prevents compilers from breaking cryptographic implementations vulnerable to timing attacks, introducing the __builtin_ct_select fami...
100
PentesterLab @pentesterlab.com · 27/11/2025
Black Friday at @pentesterlab.com 🧨 For a limited time: 🔒 1 year of PRO for $146.52 🎓 Student special: 3 months PRO for $25.99 Hands-on labs. Real CVEs. Security code review training used by real AppSec & pentest teams. ⏰ Offer ends 2 Dec 2025, 23:59:59 UTC 👉 pentesterlab.com/pro
023
PentesterLab @pentesterlab.com · 21/11/2025
Added 3 new Java CVEs to our Java Code Review Badge! Now at 64 real-world labs to sharpen your Java code review skills. Try them here: pentesterlab.com/badges/java-... More CVEs coming soon 👀🔥
pentesterlab.com
PentesterLab: Learn with our Java Code Review Badge
The Java Code Review Badge is our badge dedicated to code review in Java. It covers the discovery of weaknesses and vulnerabilities using source code review.
022
PentesterLab @pentesterlab.com · 16/11/2025
Articles worth reading discovered last week: 📲 security.googleblog.com/2025/11/rust... 📸 www.pixnapping.com 🧩 www.praetorian.com/blog/how-i-f... 🤖 buganizer.cc/hacking-gemi...
security.googleblog.com
Rust in Android: move fast and fix things
Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in ...
001
Reposted by PentesterLab
Jason Danner @jpdanner.com · 07/11/2025
😂 @pentesterlab.com #Kawaiicon @kawaiicon.bsky.social
121
PentesterLab @pentesterlab.com · 09/11/2025
Research to read this week: Android, Django, MCP… 🤖 knifecoat.com/Posts/Runtim... 🐍 www.endorlabs.com/learn/critic... 🌽 googleprojectzero.blogspot.com/2025/11/defe... 🤖 medium.com/@kulkan-secu... 🧑🏻‍💻 words.filippo.io/claude-debug... #PentesterLabWeekly
knifecoat.com
Runtime Android Object Instrumentation - KnifeCoat
Intro This year I have been doing quite a bit Android userland analysis. Android is a wonderful platform to work on, great decompiler support (JEB), easy access to rooted devices (unless you buy NA l…
011
Reposted by PentesterLab
Jason Danner @jpdanner.com · 07/11/2025
Don't just look at bad code Know what good looks like! @pentesterlab.com #Kawaiicon @kawaiicon.bsky.social
111
PentesterLab @pentesterlab.com · 02/11/2025
Articles worth reading discovered last week: Passports, WIFI and AI-SAST! 🛂 blog.trailofbits.com/2025/10/31/t... 🛜 pulsesecurity.co.nz/articles/byp... 🧠 parsiya.net/blog/wtf-is-...
blog.trailofbits.com
The cryptography behind electronic passports
This blog post describes how electronic passports work, the threats within their threat model, and how they protect against those threats using cryptography. It also discusses the implications of usin...
065
Reposted by PentesterLab
Zoltan Madarassy @loltan.bsky.social · 30/10/2025
Yeah @nastystereo.com I think you and @pentesterlab.com would get along just fine collabbing. 👀
121
Reposted by PentesterLab
🦝 Pepper Raccoon: Trash Priestess 🦝 @pepperraccoon.com · 30/10/2025
Upgrading the designer bag with a necessary accessory @pentesterlab.com
Remove before shell keychain on a michael kors handbag
0191
PentesterLab @pentesterlab.com · 28/10/2025
🚨 New labs just dropped! 3 new Python Code Review labs are now live on PentesterLab 🐍 Learn to spot subtle bugs and insecure patterns by reading real Python code. 🎯 pentesterlab.com/badges/python-code-review #Python #AppSec #CodeReview #PentesterLab
pentesterlab.com
PentesterLab: Learn with our Python Code Review Badge
The Python Code Review Badge is our badge dedicated to code review in Python. It covers the discovery of weaknesses and vulnerabilities using source code review.
032
Reposted by PentesterLab
Christian @xntrik.wtf · 19/10/2025
Really awesome preso from @snyff.pentesterlab.com @pentesterlab.com over at BSides Perth. Jam packed with patterns, approaches, tips and tricks to level up finding bugs in code. #bsides #bsidesperth
132
PentesterLab @pentesterlab.com · 04/05/2025
The past few weeks have been quiet, but we’re back! 🛠️ deepwiki.com 🛠️ github.com/AsyncFuncAI/... 🪲 blog.trailofbits.com/2025/04/23/h... 🛠️ github.com/quarkslab/pr... 🛡️ hdm.io/decks/Charti...
deepwiki.com
DeepWiki | AI documentation you can talk to, for every repo
DeepWiki provides up-to-date documentation you can talk to, for every repo in the world. Think Deep Research for GitHub - powered by Devin.
053
PentesterLab @pentesterlab.com · 21/04/2025
Your face when you realize your next security code review is on a Clojure codebase...
110
PentesterLab @pentesterlab.com · 06/04/2025
Articles worth reading discovered last week: 🪲 labs.watchtowr.com/xss-to-rce-b... 🧩 gist.github.com/Panya/990b45... #PentesterLabWeekly
labs.watchtowr.com
XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748)
We know what you’re waiting for - this isn’t it. Today, we’re back with more tales of our adventures in Kentico’s Xperience CMS. Due to it’s wide usage, the type of solution, and the types of enterpri...
021
PentesterLab @pentesterlab.com · 30/03/2025
Two great pieces of content for this week: 🪲 www.wiz.io/blog/ingress... 🪲 zhero-web-sec.github.io/research-and... #PentesterLabWeekly
wiz.io
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
043
PentesterLab @pentesterlab.com · 23/03/2025
‼️ blog.doyensec.com/2025/03/18/e... 📨 workos.com/blog/samlstorm 🛤️ projectdiscovery.io/blog/discour... ☑️ labs.watchtowr.com/by-executive... ❤️ tmpout.sh/4/ 🗼 labs.watchtowr.com/bypassing-au...

 Get our weekly news direct to your mailbox: pentesterlab.substack.com
blog.doyensec.com
!exploitable Episode Three - Devfile Adventures · Doyensec's Blog
!exploitable Episode Three - Devfile Adventures
020
PentesterLab @pentesterlab.com · 20/03/2025
If people spent as much time actually learning hacking as they do optimizing how to learn hacking, they’d be a lot better at it. Just start. Break things. Learn. Repeat.
030
PentesterLab @pentesterlab.com · 16/03/2025
We just released 3 new labs in our Golang Code Review Badge: pentesterlab.com/badges/golan... #golang
pentesterlab.com
PentesterLab: Learn with our Golang Code Review Badge
The Golang Code Review Badge is our badge dedicated to code review in Golang. It covers the discovery of weaknesses and vulnerabilities using source code review.
033
PentesterLab @pentesterlab.com · 16/03/2025
What a week! SAML&Ruby, PHP&XXE and so much more! 📨 github.blog/security/sig... 🧑🏻‍💻 seeinglogic.com/posts/visual... 🤯 swarm.ptsecurity.com/impossible-x... 😻 scrapco.de/blog/analysi... More details in our blog: pentesterlab.com/blog/researc... #PentesterLabWeekly
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
032
PentesterLab @pentesterlab.com · 12/03/2025
053
PentesterLab @pentesterlab.com · 09/03/2025
Articles worth reading discovered last week: 💎 www.elttam.com/blog/rails-s... ﹟ afine.com/understandin... 🪲 slcyber.io/blog/sitecor... For more details, check out our blog: pentesterlab.com/blog/researc...
elttam.com
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttamNew Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.
020
PentesterLab @pentesterlab.com · 02/03/2025
Want to prove your API hacking skills? Earn the PentesterLab API badge! Hands-on labs designed to test and improve your ability to find and exploit API vulnerabilities. pentesterlab.com/badges/api
pentesterlab.com
PentesterLab: API Badge
The API badge is our set of exercises created to help you learn API testing. The first few challenges are based on challenges you already solved to get you more confident with API testing and review your knowledge and methodology. Then, harder challenges are provided to get you to the next level.
030
PentesterLab @pentesterlab.com · 24/02/2025
AI-generated code is reshaping secure code review—fewer trivial bugs, but more hidden threats. Read more in our new blog post: pentesterlab.com/blog/secure-... What do you think?
pentesterlab.com
How AI-Generated Code Is Changing Secure Code Review
Learn how AI-generated code impacts secure code review and application security. Discover why AI excels at catching common vulnerabilities but needs human expertise for complex bugs.
001