PentesterLab

@pentesterlab.com

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฏ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Only one entry but definitely worth reading! โ˜๏ธ ๐—ฅ๐—ฒ๐—บ๐—ผ๐˜๐—ฒ ๐—–๐—ผ๐—บ๐—บ๐—ฎ๐—ป๐—ฑ ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฆ๐—ถ๐—ป๐—ด๐—น๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐——๐—ฒ๐—น๐—ฒ๐˜๐—ถ๐—ผ๐—ป This one is a real tour de force: flatt.tech/research/pos....

Remote Command Execution in Google Cloud with Single Directory Deletion

Introduction Hello, Iโ€™m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...

flatt.tech

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฎ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ AI doing research, AI killing CTF ๐Ÿค– ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—”๐—œ ๐—ณ๐—ผ๐—ฟ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต: ๐Ÿฐ ๐—”๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฎ๐—ฐ๐—ต๐—ฒ๐˜€ & ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—œ ๐—™๐—ฎ๐—ถ๐—น๐—ฒ๐—ฑ If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.

Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n

Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs โ€” 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...

xclow3n.github.io

A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password. Why? Longer SHA-256 nonce + bcrypt truncation at 72 bytes. A nice example of why secure systems are about composition, not just stronger primitives. pentesterlab.com/blog/freshrs...

How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit

As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...

pentesterlab.com

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฌ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ A great mix of content this week! ๐Ÿ”’ ๐—œ๐—ฟ๐—ผ๐—ป๐—–๐˜‚๐—ฟ๐˜๐—ฎ๐—ถ๐—ป: ๐—” ๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ผ๐—ป๐—ฎ๐—น ๐—”๐—œ ๐—”๐˜€๐˜€๐—ถ๐˜€๐˜๐—ฎ๐—ป๐˜ ๐—•๐˜‚๐—ถ๐—น๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—š๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐—จ๐—ฝ Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿต, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Mostly AI... ๐Ÿ’ป ๐—•๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—•๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ผ๐—ฟ๐˜ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—ด๐—ฒ ๐—ผ๐—ณ ๐—Ÿ๐—ก๐—” Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....

Browser-Based Port Scanning in the Age of LNA

wiki.notveg.ninja

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿด, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Java x2, Go, JWT and a sprinkling of AI ๐Ÿฆซ ๐—–๐—ง๐—™๐˜๐—ถ๐—บ๐—ฒ.๐—ผ๐—ฟ๐—ด / ๐—ท๐˜‚๐˜€๐˜๐—–๐—ง๐—™ [*] ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฌ / ๐—š๐—ผ-๐—ณ๐˜€ / ๐—ช๐—ฟ๐—ถ๐˜๐—ฒ๐˜‚๐—ฝ A cool Golang quirk via an unintended CTF solution ctftime.org/writeup/25852.

CTFtime.org / justCTF [*] 2020 / Go-fs / Writeup

CTF writeups, Go-fs

ctftime.org

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿณ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Parser Differential, TypeScript and AI ๐Ÿ‘‡

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿฒ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ Busy week! AI, AI, AI and the death of Flash! ๐Ÿค– ๐—ฆ๐—ฒ๐—บ๐—ด๐—ฟ๐—ฒ๐—ฝ'๐˜€ ๐—”๐—ด๐—ฒ๐—ป๐˜ ๐—ฆ๐—ธ๐—ถ๐—น๐—น๐˜€ Semgrep released a set of agent skills worth looking into: github.com/semgrep/skills.

GitHub - semgrep/skills: A collection of skills for AI coding agents from Semgrep

A collection of skills for AI coding agents from Semgrep - semgrep/skills

github.com

Research Worth Reading Week 51/2025 A quieter week that perfectly fits the two deep dives! ๐Ÿ“š ORM Leaking More Than You Joined For The latest opus in Elttam's posts on ORM leaks, including some semgrep rules and a reference to my blog post on the subject: www.elttam.com/blog/leaking...

ORM Leaking More Than You Joined For - elttamORM Leaking More Than You Joined For - elttam

elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.

elttam.com

Welcome back to Slytherin! ๐Ÿ We just released 3 new labs in our python^w Slytherin code review badge: real CVEs, sneaky bugs, and plenty of chances to sharpen your dark code arts.. Grab your wand here: pentesterlab.com/badges/pytho...

PentesterLab: Learn with our Python Code Review Badge

The Python Code Review Badge is our badge dedicated to code review in Python. It covers the discovery of weaknesses and vulnerabilities using source code review.

pentesterlab.com

Research Worth Reading Week 49/2025: โฐ Introducing constant-time support for LLVM to protect cryptographic code Trail of Bits explains their work on adding constant-time support to LLVM so that compiled cryptographic code remains constant-time: blog.trailofbits.com/2025/12/02/i...

Introducing constant-time support for LLVM to protect cryptographic code

Trail of Bits developed constant-time coding support for LLVM that prevents compilers from breaking cryptographic implementations vulnerable to timing attacks, introducing the __builtin_ct_select fami...

blog.trailofbits.com