We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

Joined December 2011
304 Photos and videos
PentesterLab retweeted
Thanks to @PentesterLab for sending the stickers so quickly โ€” shipped after just one day Also, huge thanks for @Hacker0x01 For PentesterLab Pro license . Really appreciated! #stickers #AppSec
1
3
1,296
PentesterLab retweeted
I just completed @Pentesterlab's Essential Badge!!! one step at a time
2
1
17
1,896
PentesterLab retweeted
Thanks to @PentesterLab , i received the stickers. These are amazing! #stickers #AppSec
1
1
9
1,596
PentesterLab retweeted
Specially thanks to @PentesterLab @snyff
1
4
1,121
A surprising number of people learn web security before they learn how the web works. We've added 4 new labs to our Web Fundamentals badge: ๐Ÿ’ป Client-side code ๐Ÿ–ฅ๏ธServer-side code ๐Ÿ—„๏ธ Databases ๐Ÿ”‘ Sessions No hacking required. Just the foundations.
1
3
26
1,472
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฎ๐Ÿฏ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Golang and Weak Skill Scanners ๐Ÿ”ย ๐—Ÿ๐—ฒ๐˜โ€™๐˜€ ๐˜๐—ฎ๐—น๐—ธ ๐—ฎ๐—ฏ๐—ผ๐˜‚๐˜ ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐—ฟ๐—ฒ๐—ฎ๐˜€๐—ผ๐—ป๐—ถ๐—ป๐—ด A cryptographic look at the encrypted reasoning blobs that get passed back and forth when using the OpenAI and Anthropic APIs. I like this because it does what good security research should do: explain why the mechanism exists, build realistic threat models around it, and then actually test them instead of stopping at speculation:ย blog.cryptographyengineeringโ€ฆ. ๐Ÿ‘ย ๐—š๐—ผ๐—น๐—ฎ๐—ป๐—ด ๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ฟ๐—ฒ๐˜ƒ๐—ถ๐—ฒ๐˜„ ๐—ป๐—ผ๐˜๐—ฒ๐˜€ ๐—œ๐—œ Once again, elttam delivers! Iโ€™m a huge fan of little programming-language gotchas because they give you an edge as a code reviewer. These are exactly the kinds of details that turn "looks fine" into "wait, what actually happens here?". If youโ€™re writing or reviewing Go, make sure you read this one:ย elttam.com/blog/golang-code-โ€ฆ. ๐Ÿค–ย ๐—ง๐—ต๐—ฒ ๐˜€๐—ผ๐—ฟ๐—ฟ๐˜† ๐˜€๐˜๐—ฎ๐˜๐—ฒ ๐—ผ๐—ณ ๐˜€๐—ธ๐—ถ๐—น๐—น ๐—ฑ๐—ถ๐˜€๐˜๐—ฟ๐—ถ๐—ฏ๐˜‚๐˜๐—ถ๐—ผ๐—ป Trail of Bits bypassed multiple scanners with the kind of tricks every supply-chain security person should already be worried about: hidden files, bytecode, prompt injection, and "trust me bro" explanations. The good news is that they published the skills on GitHub, so get ready for vendors to claim they can now detect them all:ย blog.trailofbits.com/2026/06โ€ฆ. ๐Ÿ—ž๏ธ ๐—Ÿ๐—ฎ๐˜€๐˜ ๐˜„๐—ฒ๐—ฒ๐—ธ @๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ฒ๐—ฟ๐—Ÿ๐—ฎ๐—ฏ Last week, we released 5 new labs in ourย JavaScript Sandbox Escape badge (pentesterlab.com/badges/javaโ€ฆ). Make sure you check them out!
1
7
1,632
If you are in Belgium ๐Ÿ‡ง๐Ÿ‡ช and want some stickers: pentesterlab.com/stickers/beโ€ฆ
3
1,475
PentesterLab retweeted
Thank you @PentesterLab I love the stickers, kisses from France ๐Ÿ˜š
1
1
6
2,026
PentesterLab retweeted
merci @PentesterLab :))) j'aime trop les insectes
3
21
2,733
PentesterLab retweeted
๐Ÿ“ข Competition alert! Find our awesome @MalwareVillage team at @BSidesVancouver and play our new CTF (PANIC) ๐Ÿ‘พ The winner of each difficulty level will win a free 1-Month subscription to @PentesterLab! ๐Ÿฅณ A huge thank you to @PentesterLab for the collab ๐Ÿค
1
2
10
1,922
PentesterLab retweeted
I just completed @Pentesterlab's Essential Badge!!!
1
7
2,103
PentesterLab retweeted
Thank you @PentesterLab for the stickers, Greetings from france
1
11
2,281
Merci beaucoup @PentesterLab !!! Super content de mes magnifiques stickers ๐Ÿ˜‰
1
2
14
3,000
PentesterLab retweeted
May 28
Received and put on my Mac ! Thanks @PentesterLab
1
2
9
4,757
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฎ๐Ÿญ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ A great week to look into AI-assisted tooling โš’๏ธ ๐—ฒ๐˜ƒ๐—ถ๐—น๐˜€๐—ผ๐—ฐ๐—ธ๐—ฒ๐˜ / ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜ An 8-stage vulnerability-discovery agent based on Cloudflare's Project Glasswing. github.com/evilsocket/audit. ๐Ÿค– ๐—”๐˜‚๐˜๐—ผ๐—ป๐—ผ๐—บ๐—ผ๐˜‚๐˜€ ๐—ณ๐˜‚๐˜‡๐˜‡๐—ถ๐—ป๐—ด ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜‚๐—ป๐—ฑ๐—ฒ๐—ฟ ๐—Ÿ๐—Ÿ๐—  ๐˜€๐˜‚๐—ฝ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ผ๐—ป Using LLMs to autonomously build and operate fuzzing harnesses cert.pl/en/posts/2026/05/autโ€ฆ. ๐Ÿ’ฐ ๐—ฆ๐˜๐˜‚๐—ฏ๐—ญ๐—ฒ๐—ฟ๐—ผ: $๐Ÿญ๐Ÿฐ๐Ÿด,๐Ÿฏ๐Ÿฏ๐Ÿณ ๐—ฅ๐—–๐—˜ ๐—ถ๐—ป ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฃ๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐˜๐—ถ๐—ผ๐—ป A really interesting write-up, mostly in terms of investment and automation some hunters put into their target. brutecat.com/articles/googleโ€ฆ.
13
57
3,982
PentesterLab retweeted
Just completed @PentesterLabโ€™s HTTP Badge. Learned how to: send raw HTTP requests with curl work with headers, cookies & methods understand URL encoding & parameter pollution upload files & manipulate request bodies send XML / JSON / YAML requests and more....
1
2
12
4,151
If you are in France ๐Ÿ‡ซ๐Ÿ‡ท and want some stickers: pentesterlab.com/stickers/frโ€ฆ
6
6
41
8,462
PentesterLab retweeted
A huge thank you to @PentesterLab for donating 4x free month trials for our @MalwareVillage CTF at @BSidesDublin! Winners announced at 5:15PM Dublin Local Time.
1
14
2,661
PentesterLab retweeted
The lab was awesome, glad to have the privilege to showcase it on my channel! Thank you for the shoutout @PentesterLab ๐Ÿ”ฅ
If you want to check what our latest JavaScript Sandbox Escape labs cover, make sure you watch this video from @zerodaygym : youtube.com/watch?v=P7naqW18โ€ฆ
5
17
6,904