Better API Endpoint Enumeration: Testing for the #1 OWASP Security Vuln
Broken Access Controls is at the top of the OWASP Top 10. The difficulty is finding each instance to test. Learn 3 ways to enumerate API endpoints thoroughly.
Broken Access Controls is at the top of the OWASP Top 10. The difficulty is finding each instance to test. Learn 3 ways to enumerate API endpoints thoroughly.
Principal Penetration Tester Andrew Trexler takes us step-by-step through the process of rooting a Google Pixel for mobile application pentesting.
Principal Pentester Scottie Cole continues his NetExec series with nxcdb, the database that automatically stores key info like hosts and creds while you hack.
Enumerating webpages during an internal network pentest can be a large task, but GoWitness makes it easy to focus on high value webpages. Learn how it works.
Nathan Anderson continues his Physical Social Engineering and Red Team series with the final step: looting. Learn what shows value to stakeholders in reports.
Endpoint security detects many malicious files created with pentest tools, but pentesters can sometimes bypass this by rebuilding source code. Learn how here.
BloodHound’s Community Edition has everything a penetration tester needs to enumerate relationships in a domain in order to gain more access, even Domain Admin.
With current local privilege escalation exploits like Copy Fail and Dirty Frag active in the wild, harden your defenses to halt attacks even before patching.
Now that CrackMapExec is no more, how is a pentester to rapidly test credentials, enumerate assets, spray passwords, and more? Learn the basics of NetExec here.
Ryan Chaplin wondered what it would take to bypass ChatGPT’s open-source model security restrictions to allow AI to hack his website. See how he did it here.
Raxis Lead Penetration Tester Nathan Anderson continues our Cool Tool Series with SCP for data exfiltration on internal network pentests and red teams.
Jason Taylor brings highlights reptyr in our Cool Tools series, showing how to take a long-running process, like an Nmap scan, and move it to a new screen.
67 posts in How To.