We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

Joined December 2011
304 Photos and videos
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฎ๐Ÿฐ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ This is why we can't have nice things... ๐Ÿชฒ ๐—๐˜‚๐—ฝ๐˜†๐˜๐—ฒ๐—ฟ ๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ ๐—š๐—ฎ๐˜๐—ฒ๐˜„๐—ฎ๐˜† Another great write-up from the elttam team. As always, itโ€™s well explained, with enough details to understand both the issue and the process they followed to get there. I also like this one because it shows how something that looks โ€œonlyโ€ like user-controlled configuration can become a much bigger issue once it reaches Kubernetes and privileged execution paths. elttam.com/blog/jupyter-enteโ€ฆ. ๐Ÿค– ๐— ๐—ฒ๐—ฎ๐˜€๐˜‚๐—ฟ๐—ถ๐—ป๐—ด ๐—Ÿ๐—Ÿ๐— ๐˜€โ€™ ๐—ถ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜ ๐—ผ๐—ป ๐—ก-๐—ฑ๐—ฎ๐˜† ๐—ฒ๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐˜€ How much time do models need to create exploits for N-day vulnerabilities? A really interesting comparison of Anthropic modelsโ€™ efficiency at building exploits for known vulnerabilities. Another signal, if you needed one, that your time-to-patch needs to shrink dramatically. red.anthropic.com/2026/n-dayโ€ฆ. ๐ŸŽ† ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€๐—ถ๐—ป๐—ด ๐—ฎ ๐Ÿฏ ๐—น๐—ฎ๐˜†๐—ฒ๐—ฟ ๐—ฆ๐—ฉ๐—š ๐˜€๐—ฎ๐—ป๐—ถ๐˜๐—ถ๐˜‡๐—ฒ๐—ฟ: ๐—ฆ๐˜๐—ผ๐—ฟ๐—ฒ๐—ฑ ๐—ซ๐—ฆ๐—ฆ ๐—ถ๐—ป ๐— ๐—ผ๐˜‡๐—ถ๐—น๐—น๐—ฎ Some great content that reads like a course in application security: what was happening, why it was wrong, how to fix it, and the impact of the fix. I especially like the part where the sanitizer is called, but the sanitized output is not actually used. Itโ€™s such a good example of why code review is not about spotting the function name you want to see. You need to follow the data and check that the thing being validated or sanitized is the thing that gets stored or rendered. profile-chi-jade.vercel.app/โ€ฆ. โš’๏ธ ๐—›๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐˜„๐—ถ๐˜๐—ต ๐—”.๐—œ. ๐—ณ๐—ผ๐—ฟ $๐Ÿฑ๐Ÿฌ๐Ÿฌ,๐Ÿฌ๐Ÿฌ๐Ÿฌ How much time and effort should you invest in a bug bounty target? This post gives a pretty good answer. Itโ€™s not just โ€œuse AI and bugs fall outโ€. Itโ€™s more about building a process around a hard target, mapping a huge attack surface, collecting the right inputs, and using AI to help scale parts of the work. A great write-up if youโ€™re interested in how people find vulnerabilities in targets where the easy bugs disappeared a long time ago. brutecat.com/articles/hackinโ€ฆ. ๐Ÿค– ๐—ฆ๐˜๐—ฎ๐˜๐—ฒ๐—บ๐—ฒ๐—ป๐˜ ๐—ผ๐—ป ๐˜๐—ต๐—ฒ ๐—จ๐—ฆ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ฑ๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐˜๐—ผ ๐˜€๐˜‚๐˜€๐—ฝ๐—ฒ๐—ป๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜๐—ผ ๐—™๐—ฎ๐—ฏ๐—น๐—ฒ ๐Ÿฑ ๐—ฎ๐—ป๐—ฑ ๐— ๐˜†๐˜๐—ต๐—ผ๐˜€ ๐Ÿฑ Well, well, well, if it isnโ€™t the consequences of your actions... After marketing Mythos as powerful enough to need special access and safeguards, Anthropic has now been asked to suspend access to Fable and Mythos for foreign nationals, including foreign-national Anthropic employees. They complied by blocking access to all customers. Any geopolitical AI expert probably had a busy weekend. anthropic.com/news/fable-mytโ€ฆ. ๐Ÿ—ž๏ธ ๐—Ÿ๐—ฎ๐˜€๐˜ ๐˜„๐—ฒ๐—ฒ๐—ธ @๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ฒ๐—ฟ๐—Ÿ๐—ฎ๐—ฏ I spent the week working on new content and updating our Security Code Review in Golang for Developers Training (pentesterlab.com/live-trainiโ€ฆ) for an upcoming private session.
8
1,030
PentesterLab retweeted
Thanks to @PentesterLab for sending the stickers so quickly โ€” shipped after just one day Also, huge thanks for @Hacker0x01 For PentesterLab Pro license . Really appreciated! #stickers #AppSec
1
3
1,413
PentesterLab retweeted
I just completed @Pentesterlab's Essential Badge!!! one step at a time
2
1
17
2,021
PentesterLab retweeted
Thanks to @PentesterLab , i received the stickers. These are amazing! #stickers #AppSec
1
1
9
1,747
PentesterLab retweeted
Specially thanks to @PentesterLab @snyff
1
4
1,127
A surprising number of people learn web security before they learn how the web works. We've added 4 new labs to our Web Fundamentals badge: ๐Ÿ’ป Client-side code ๐Ÿ–ฅ๏ธServer-side code ๐Ÿ—„๏ธ Databases ๐Ÿ”‘ Sessions No hacking required. Just the foundations.
1
3
26
1,477
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฎ๐Ÿฏ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Golang and Weak Skill Scanners ๐Ÿ”ย ๐—Ÿ๐—ฒ๐˜โ€™๐˜€ ๐˜๐—ฎ๐—น๐—ธ ๐—ฎ๐—ฏ๐—ผ๐˜‚๐˜ ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐—ฟ๐—ฒ๐—ฎ๐˜€๐—ผ๐—ป๐—ถ๐—ป๐—ด A cryptographic look at the encrypted reasoning blobs that get passed back and forth when using the OpenAI and Anthropic APIs. I like this because it does what good security research should do: explain why the mechanism exists, build realistic threat models around it, and then actually test them instead of stopping at speculation:ย blog.cryptographyengineeringโ€ฆ. ๐Ÿ‘ย ๐—š๐—ผ๐—น๐—ฎ๐—ป๐—ด ๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ฟ๐—ฒ๐˜ƒ๐—ถ๐—ฒ๐˜„ ๐—ป๐—ผ๐˜๐—ฒ๐˜€ ๐—œ๐—œ Once again, elttam delivers! Iโ€™m a huge fan of little programming-language gotchas because they give you an edge as a code reviewer. These are exactly the kinds of details that turn "looks fine" into "wait, what actually happens here?". If youโ€™re writing or reviewing Go, make sure you read this one:ย elttam.com/blog/golang-code-โ€ฆ. ๐Ÿค–ย ๐—ง๐—ต๐—ฒ ๐˜€๐—ผ๐—ฟ๐—ฟ๐˜† ๐˜€๐˜๐—ฎ๐˜๐—ฒ ๐—ผ๐—ณ ๐˜€๐—ธ๐—ถ๐—น๐—น ๐—ฑ๐—ถ๐˜€๐˜๐—ฟ๐—ถ๐—ฏ๐˜‚๐˜๐—ถ๐—ผ๐—ป Trail of Bits bypassed multiple scanners with the kind of tricks every supply-chain security person should already be worried about: hidden files, bytecode, prompt injection, and "trust me bro" explanations. The good news is that they published the skills on GitHub, so get ready for vendors to claim they can now detect them all:ย blog.trailofbits.com/2026/06โ€ฆ. ๐Ÿ—ž๏ธ ๐—Ÿ๐—ฎ๐˜€๐˜ ๐˜„๐—ฒ๐—ฒ๐—ธ @๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ฒ๐—ฟ๐—Ÿ๐—ฎ๐—ฏ Last week, we released 5 new labs in ourย JavaScript Sandbox Escape badge (pentesterlab.com/badges/javaโ€ฆ). Make sure you check them out!
1
7
1,636
If you are in Belgium ๐Ÿ‡ง๐Ÿ‡ช and want some stickers: pentesterlab.com/stickers/beโ€ฆ
3
1,477
PentesterLab retweeted
Thank you @PentesterLab I love the stickers, kisses from France ๐Ÿ˜š
1
1
6
2,029
PentesterLab retweeted
merci @PentesterLab :))) j'aime trop les insectes
3
21
2,736
PentesterLab retweeted
๐Ÿ“ข Competition alert! Find our awesome @MalwareVillage team at @BSidesVancouver and play our new CTF (PANIC) ๐Ÿ‘พ The winner of each difficulty level will win a free 1-Month subscription to @PentesterLab! ๐Ÿฅณ A huge thank you to @PentesterLab for the collab ๐Ÿค
1
2
10
1,924
PentesterLab retweeted
I just completed @Pentesterlab's Essential Badge!!!
1
7
2,108
PentesterLab retweeted
Thank you @PentesterLab for the stickers, Greetings from france
1
11
2,283
Merci beaucoup @PentesterLab !!! Super content de mes magnifiques stickers ๐Ÿ˜‰
1
2
14
3,002
PentesterLab retweeted
May 28
Received and put on my Mac ! Thanks @PentesterLab
1
2
9
4,759
๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฎ๐Ÿญ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ A great week to look into AI-assisted tooling โš’๏ธ ๐—ฒ๐˜ƒ๐—ถ๐—น๐˜€๐—ผ๐—ฐ๐—ธ๐—ฒ๐˜ / ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜ An 8-stage vulnerability-discovery agent based on Cloudflare's Project Glasswing. github.com/evilsocket/audit. ๐Ÿค– ๐—”๐˜‚๐˜๐—ผ๐—ป๐—ผ๐—บ๐—ผ๐˜‚๐˜€ ๐—ณ๐˜‚๐˜‡๐˜‡๐—ถ๐—ป๐—ด ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜‚๐—ป๐—ฑ๐—ฒ๐—ฟ ๐—Ÿ๐—Ÿ๐—  ๐˜€๐˜‚๐—ฝ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ผ๐—ป Using LLMs to autonomously build and operate fuzzing harnesses cert.pl/en/posts/2026/05/autโ€ฆ. ๐Ÿ’ฐ ๐—ฆ๐˜๐˜‚๐—ฏ๐—ญ๐—ฒ๐—ฟ๐—ผ: $๐Ÿญ๐Ÿฐ๐Ÿด,๐Ÿฏ๐Ÿฏ๐Ÿณ ๐—ฅ๐—–๐—˜ ๐—ถ๐—ป ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฃ๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐˜๐—ถ๐—ผ๐—ป A really interesting write-up, mostly in terms of investment and automation some hunters put into their target. brutecat.com/articles/googleโ€ฆ.
13
57
3,987
PentesterLab retweeted
Just completed @PentesterLabโ€™s HTTP Badge. Learned how to: send raw HTTP requests with curl work with headers, cookies & methods understand URL encoding & parameter pollution upload files & manipulate request bodies send XML / JSON / YAML requests and more....
1
2
12
4,154
If you are in France ๐Ÿ‡ซ๐Ÿ‡ท and want some stickers: pentesterlab.com/stickers/frโ€ฆ
6
6
41
8,463
PentesterLab retweeted
A huge thank you to @PentesterLab for donating 4x free month trials for our @MalwareVillage CTF at @BSidesDublin! Winners announced at 5:15PM Dublin Local Time.
1
14
2,662