#pentest

2026-01-16

PowerShell collector for adding SCCM attack paths to BloodHound with OpenGraph🕵️‍♂️

github.com/SpecterOps/ConfigMa

#infosec #cybersecurity #redteam #pentest #opensource

2026-01-15

netaskari.substack.com/p/china

Pause for a second to imagine the ungodly mess that must be the interconnected information systems of all the public entities in #china . Just thinking about it makes me shiver...

I'm impressed the way they seem to have enacted some kind of perpetual #pentest at the scale of all their institutions. This is clearly NOT the way it works in my country.

The approach of the pentester to security initially made me smile : let's improve our security by pentesting more pedagogically. But after some thought, it could actually be very efficient. If you give information systems a grade depending on how easy it was to pop them, managers can use it to suck up to their superiors, justify promotion etc...

This COULD actually have a positive impact... or trigger the most absurd behaviors, hard to say.

Aditya Telangeadityatelange
2026-01-15

Making Dynamic Instrumentation Accessible with Frida UI

adityatelange.in/blog/ui-for-f

Simulationsbeobachteralice@c3d2.social
2026-01-15

Vertraut ihr einem Staat der Redundanzkabel über dieselbe Strecke führt?

Sorry, aber man fragt sich echt ob es nicht besser ist, wenn #Vulkangruppe`n Lücken aufdecken, statt das irgendwann mal ECHTE Terroristen dieser Dilettantismus an Sicherheitsarchitektur in Deutschland ausnutzen ...

#Kritis #Pentest #RedTeaming

Chema Alonso :verified:chemaalonso@ioc.exchange
2026-01-15

El lado del mal - Código de Rebajas de Enero 2026 en 0xWord: Cupón REBAJAS2026 y descuentos con Tempos de MyPublicInbox elladodelmal.com/2026/01/codig #Rebajas #0xWord #Libros #CálicoElectrónico #Ciberseguridad #Hacking #Forensic #Pentest #Pentesting

2026-01-14

🔌 Did you know? RF Swift can run totally disconnected! Perfect for classified environments 🔒 rfswift.io/docs/air-gapped-ins 🚀
#RF #Hacking #pentest #lab #disconnected #air-gapped #classified

2026-01-14

EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running🕵️‍♂️

github.com/TwoSevenOneT/EDRSta

#infosec #cybersecurity #redteam #pentest #edr #opensource

2026-01-14

🤯🎊 RF Swift v0.6.5-rc4 is HERE!

🔥 Dynamic container management
📹 Session recording
⚙️ Live bindings/caps/cgroups/ports
🐳 Container upgrade system

PLUS: Complete docs for ALL commands! 📖

🌐 rfswift.io
📚 rfswift.io/docs/commands/

🚀🎉 #RFSwift #SDR #Radio #Hacking #pentest #ham #pro

2026-01-14

"Phát hiện lỗ hổng bảo mật nghiêm trọng tại lab Pentest: Endpoint GraphQL lộ thông tin nhạy cảm do introspection được bật công khai. Kẻ tấn công có thể truy vấn trường username/password qua getUser(id) mà không cần xác thực. Demo: Truy vấn id=1 thu được thông tin admin → chiếm quyền điều khiển & xóa người dùng. Cảnh báo rủi ro khi triển khai GraphQL thiếu kiểm soát!

#GraphQL #Security #Pentest #WebSecurity #BảoMật #BảoMậtMạng #LỗHổng"

dev.to/travondatrack/lab-accid

քʏʀǟȶɛɮɛǟʀɖpyratebeard@harbour.cafe
2026-01-13

🛜🍍📟

new toy arrived today, the hak5 wifi pineapple pager. of course i had to get it in yellow!

#hacktheplanet #wifipineapple #wifipineapplepager #security #pentest #hacking

photograph of a yellow wifi pineapple pager from hak5
2026-01-13

An explanation on how inconsistencies in SAML XML parsers enable signature-wrapping and canonicalization attacks that let attackers bypass authentication in Ruby and PHP libraries🕵️‍♂️

portswigger.net/research/the-f

#infosec #cybersecurity #pentest #redteam #web #xml #bugbounty

Chema Alonso :verified:chemaalonso@ioc.exchange
2026-01-13

El lado del mal - Máster Online de Inteligencia Artificial Aplicada a la Ciberseguridad: 3 de Marzo 2026 elladodelmal.com/2026/01/maste #IA #AI #Master #Ciberseguridad #InteligenciaArtificial #Pentest #hardening #Formación #Curso #Online

PH4NTXM PROJECTPH4NTXMPROJECT
2026-01-12

PH4NTXM 1.4 — “Event Horizon” summary!

• 🧨 Nuke kernel enforces irreversible shutdown
• 🧠 Active RAM seeding poisons memory analysis
• 🎙️ Kernel-level mic, camera & audio lockdown
• 🌐 Live TCP timing & network behavior randomization
• 🧬 Continuous fingerprint instability across boots
• 🌑 Midnight theme + ISO slimmed to ~1.7 GB

Direct Download:
🔗 sourceforge.net/projects/ph4nt

PH4NTXM PROJECTPH4NTXMPROJECT
2026-01-12

PH4NTXM 1.4 — “Event Horizon” is LIVE.

This release eliminates the idea of a safe boundary.
Memory is actively corrupted, shutdown paths collapse into destruction, and no execution state is allowed to survive its own observation.

Cross the horizon and causality breaks:
no persistence, no recovery, no proof.

Download: ph4ntxmproject.github.io/

PH4NTXM PROJECTPH4NTXMPROJECT
2026-01-11

PH4NTXM 1.4 is in final stress testing — and it’s holding strong.

Right now the system is being pushed through hostile conditions:
identity rotation, network mutation, panic reboots, RAM-only services, and kernel-level hardening under load.

So far, it’s behaving exactly how it was designed to:
stable, disposable, and hard to pin down.
We’re on track for a release tomorrow.

PH4NTXM PROJECTPH4NTXMPROJECT
2026-01-11

PH4NTXM 1.4

This is the shell.
Everything else is an illusion.

What would you type first?
If you know the commands, you know what to do.

PH4NTXM PROJECTPH4NTXMPROJECT
2026-01-11

PH4NTXM 1.4 — EVENT HORIZON

One frame from the next generation.
In a while will be released, get ready to put your hands on the most ghost-like operating system!

Who Let The Dogs Out 🐾ashed@mastodon.ml
2026-01-11

Пентест сетевых протоколов и Wi-Fi и защита. 3 полезных совета.

#pentest #scan #waybackMachine #burp

- Обнаружить скрытые эндпоинты и параметры через Wayback Machine + автокраулинг: найти старые версии страниц, API-эндпоинты, бэкапы и забытые параметры.

```sh
waybackurls target.example.com | grep "?" | sort -u | tee params.txt
gf xss params.txt | anew potential_xss.txt # httpx + nuclei для проверки
```

- Автопроверка IDOR/BOLA с заменой параметров в Burp Suite: перехват запросов, смена ID/токенов на значения из других аккаунтов и проверка доступа.

- Burp: Send to Intruder → Positions на ID/user_id → Payloads: список ID из reconnaissance → Attack (Sniper) → Сортировка по Length/Status - поиск различий.

- Поиск уязвимостей в JS-файлах + извлечение секретов: парсинг JavaScript на эндпоинты, секреты (API-ключи, токены) и потенциальные XSS/SSTI.

```sh
cat app.js | jsluice urls | sort -u
cat app.js | secretfinder -reg "AKIA[0-9A-Z]{16}" # LinkFinder + grep
```

This is probably the easiest way to perform reverse DNS lookups over IP address ranges using the built-in tool getent and bash brace expansion:

getent hosts 130.59.{20,31}.{0..255}

Useful if you are on a system/container with limited tools.

#pentest #dns #linux

Output of the command showing multiple IP addresses and their hostnames assigned via reverse DNS entries.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst