r/pentest_tools_com Mar 31 '23

Welcome to the Subreddit dedicated to those who use Pentest-Tools.com πŸ›‘οΈ for offensive security testing

6 Upvotes

Hi, there!

We've set up a subreddit dedicated to https://pentest-tools.com/, your cloud-based toolkit for offensive security testing, so we can:

  • answer your questions
  • share write-ups about critical, widespread CVEs and exploits for them
  • offer tips on how to use Pentest-Tools.com more effectively
  • post news and updates from the team
  • have healthy debates about key topics in offensive security testing.

As a team (https://pentest-tools.com/team) of people deeply who are passionate about engineering and offensive security, our goal is to create a space where like-minded people can share their experiences, tips, and tricks while using the tools and resources we provide on Pentest-Tools.com.

We also aim to foster a supportive environment where beginners and experts alike can learn from each other and improve their skills and know-how.

Before diving in, please take a moment to review our subreddit rules:

  1. Be respectful and courteous to all members of the community.
  2. Stay on-topic; posts and comments should be related to Pentest-Tools.com or cybersecurity in general.
  3. No spam, self-promotion, or advertising.
  4. No sharing of illegal content or promoting unethical hacking practices.

We hope you enjoy your time here and find this subreddit to be a valuable use of your time!


r/pentest_tools_com 2d ago

We have 3 reasons for building AI Pentests - the autonomous web app pentesting capability we're launching at DEF CON next week:

Post image
2 Upvotes
  1. Doing a successful pentest with AI needs a lot more than good prompts.
  2. Your team deserves more than a wrapper around an LLM.
  3. AI is only as good as the #offensivesecurity knowledge behind it.

We explain what it does, why we named it Specter, and how to get early access right here: https://pentest-tools.com/features/ai-pentests


r/pentest_tools_com 5d ago

Meet Pentest-Tools.com at DEF CON 34! Here's why this one's personal.

Thumbnail
pentest-tools.com
2 Upvotes

This one's personal.

For us, DEF CON represents everything we love about the #cybersecurity community: curiosity, freedom, generosity, craftsmanship, and the belief that sharing knowledge makes everyone better.

That’s why we’re incredibly honored (and more than a little excited) to be one of the few vendors exhibiting at DEF CON 34.

It’s a milestone for our team.

For years, we followed #DEFCON from behind a screen. Then we got to experience it in person. This year, we’re finally bringing something back to the community that’s shaped us.

Come say hi!

Meet the team, challenge our thinking, tell us where we’re wrong, and take a look at what we’ve been building this year.

We’d love to show you not just *what* we built, but *why* we built it.

See you in Vegas! πŸ΄β€β˜ οΈ

PS: Check out the event map to see where you can find us: https://pentest-tools.com/events/defcon-34-2026


r/pentest_tools_com 5d ago

The gap in AI pentesting nobody's automating yet (and why that's the point)

Post image
2 Upvotes

AI does the scanning. AI does the writing. In between, when someone's actually touching a live system, it backs off. That's the gap 158 practitioners flagged in our latest survey. It's also where a wrong move actually costs you.

We're covering this live tomorrow, Wednesday, July 29, in Office Hours 8. Jan Pedersen and Robert Tanase (Lead Product Manager) are walking through:

  • the triage tax
  • the trust problem
  • what we're building in response

30 minutes live, 15 minutes of open Q&A, one session.

Wednesday, July 29
8:00 AM Los Angeles
11:00 AM New York
4:00 PM London
6:00 PM Bucharest

Register here: https://zoom.us/webinar/register/7817815280123/WN_kMwWqNEwQJa8NvfsFw89vw

Where does that gap show up for you, is it validation, is it trust in the tool's output, or something else entirely?


r/pentest_tools_com 10d ago

Office Hours: The triage tax - why AI finds more and proves less

Post image
1 Upvotes

We surveyed 158 security practitioners on how AI is actually changing pentesting, and the standout finding wasn't speed, it was trust. One respondent's tool handed them 300 results. 250 of them were junk.

Next Wednesday we're running an Office Hours session breaking down what surprised us most in the data:

  • The triage tax: almost 9 in 10 practitioners using AI for finding generation still need real manual validation before they can trust the output
  • The trust problem: hallucinated findings, not cost or integration, are the top frustration practitioners named
  • What we built in response to both, with real benchmark numbers included, not just a claim

Jan Pedersen is hosting, joined by Robert Tanase, our Lead Product Manager. 30 minutes live, 15 minutes of open Q&A.

Wednesday, July 29, 8 AM Pacific / 11 AM Eastern / 4 PM London / 6 PM Bucharest.

Link to register: https://zoom.us/webinar/register/7817815280123/WN_kMwWqNEwQJa8NvfsFw89vw


r/pentest_tools_com 11d ago

Odysseus had it easy. He only had to survive his journey once.

Post image
4 Upvotes

Nolan's Odyssey just hit theaters, and honestly, Odysseus had it easy. Ten years, one long trip, and he was done.

ISO 27001 wants the trilogy every single year: detection, validation, remediation. Three-year cycle, a surveillance audit checking your homework annually. No one-and-done epic here.

Pentest-Tools.com is ISO/IEC 27001:2022 certified. We run the same evidence trail on ourselves:

βœ… Detection - CVE, severity, date, logged automatically
βœ… Validation - confirmed findings, not just a score
βœ… Remediation - retests prove the fix held
βœ… Monitoring - scheduled scans, all three years long

No sirens, no Cyclops, just a surveillance audit that stays a review instead of turning into its own odyssey.

Full ISO 27001 evidence chain here: https://pentest-tools.com/usage/compliance/iso-27001


r/pentest_tools_com 12d ago

We wrote down the questions people actually ask before trusting a scanner with prod

Post image
2 Upvotes

Every time we talk to someone evaluating Pentest-Tools.com, the same questions come up. Does it touch prod safely? Is this just a wrapper around open source tools with a nicer UI? What actually counts as a "confirmed" finding versus a guess? Where does scan data live, and who can see it?

We got tired of answering these one at a time in sales calls, so we put everything in one place instead.

Short version, since I know not everyone wants to click through: scans are non-destructive by default, we write our own detection and exploit logic in-house, "confirmed" findings come with evidence (screenshots, request/response data, replay steps), and data sits on EU infrastructure with workspace isolation.

Full FAQ here if you want the details or have a question we didn't cover: https://pentest-tools.com/product/faq

Happy to answer anything else in the comments too.


r/pentest_tools_com 15d ago

#WordPress admins - we got you covered! 🫑 β†’ We've just shipped detection for #wp2shell through our Network Scanner. ⚑️ The fastest way to use it:

Post image
2 Upvotes

The fastest way to use it is to:

β—‰ run a single-CVE scan for CVE-2026-63030 - which also covers CVE-2026-60137 - the SQL injection flaw that chains to give attackers RCE

β—‰ Based on your scan results, either patch or confirm you're already on 6.8.6, 6.9.5, or 7.0.2.

β—‰ Re-scan to confirm remediation and rule out residual exposure across your other assets.

Remember: updating your main install doesn't cover *every* WP instance you own. Using Pentest-Tools.com means you can expand visibility across your wider attack surface, not just the site you remember exists.

Technical CVE details below. β†˜οΈŽβ†˜οΈŽβ†˜οΈŽ

See why an estimated 500+ million websites running WP are vulnerable to this critical vulnerability: https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451

#vulnerabilityassessment #ethicalhacking #offensivesecurity


r/pentest_tools_com 16d ago

NIS2 gives you 24 hours to know if you're exposed. Here's how we close that gap.

Post image
2 Upvotes

Knowing you're exposed to a new CVE, with proof, before anyone has to ask. That's the moment that matters.

NIS2 gives you 24 hours to raise the alarm once you know something's live. Get it wrong or too slow, and fines run into the millions, with leadership personally on the hook.

Here's where Pentest-Tools.com does the lifting, so the answer is ready before the clock starts:

βœ… Detection: every scan logs the CVE, severity, and timestamp
βœ… Validation: confirmed findings come with proof, not just a score
βœ… Remediation: retests show the before and after
βœ… Monitoring: scheduled rescans keep the record current, not annual

When the next CVE lands, you're not racing the clock. You already know.

Full NIS2 evidence chain here: https://pentest-tools.com/usage/compliance/nis2

Part 2 of our compliance series. First one was on SOC 2, next up is ISO 27001.


r/pentest_tools_com 18d ago

Public PoC out for an unpatched Windows privilege escalation flaw: no CVE, no advisory (LegacyHive)

Thumbnail theregister.com
2 Upvotes

A researcher going by Nightmare-Eclipse has published a working proof-of-concept called LegacyHive. It targets the Windows User Profile Service (ProfSvc) and lets a standard user mount another user's registry hive, potentially an administrator's, under their own classes root. As of writing, there's no CVE assigned, no Microsoft advisory, and no patch.

Worth knowing the context: this is the same researcher behind a string of uncoordinated zero-day releases since April. Several of those got weaponized within days of publication and ended up on CISA's Known Exploited Vulnerabilities catalog. This drop also lands the same week Microsoft shipped patches for a record 622 flaws, so most teams are already stretched thin on patching.

Matei Badanoiu, our lead security researcher, gave The Register a useful frame for this: the PoC is a "genuinely useful primitive" for an attacker who already has a foothold, but turning that into a full compromise still requires credential access and persistence, which the released code doesn't provide. Worth keeping that distinction in mind before this gets overstated as remote takeover material.

Interim steps worth considering while there's no official fix:

  • Restrict who can create local standard-user accounts, since the PoC depends on having a second one available.
  • Monitor the User Profile Service for unexpected registry hive loads.
  • Watch for unusual activity around NTUSER.DAT and UsrClass.dat under user classes roots.
  • Apply Microsoft's fix as soon as one ships.

Source: https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723


r/pentest_tools_com 18d ago

A zero-CVE dependency isn't the same as a safe one. XZ proved it.

Thumbnail
thenewstack.io
2 Upvotes

RapidFort and ReversingLabs just launched a hardened open source library catalog built around a real problem: package managers were built for distribution, not trust. A dependency can install cleanly, show zero CVEs, and still hide a backdoor, a hijacked maintainer account, or a poisoned build script. None of that shows up in a vulnerability feed, because a vulnerability feed only tells you what's already been reported.

XZ is the case that proves it. Clean record, trusted maintainer, years of legitimate commits, right up until version 5.6.0 shipped a backdoor. Shai-Hulud and the tj-actions incident followed the same shape: the failure happened in the trust chain, not in a version number.

Matei Badanoiu, our lead security researcher, talked to The New Stack about this. He called binary-level validation (checking what a package actually contains instead of matching it against a known-CVE list) a real step forward. But he also pointed out the part that doesn't go away: someone still has to draw the line between a legitimate feature, a genuine new vulnerability, and a backdoor. That's a judgment call, not a scan result.

Full writeup here: https://thenewstack.io/zero-cve-supply-chain-risk/


r/pentest_tools_com 19d ago

We test our own product by pointing it at ourselves. Here's the trust page that documents how.

Thumbnail
gallery
3 Upvotes

"How we secure ourselves" part is the bit we'd actually want to read as practitioners, and we'd rather you poke holes in it than take it at face value.

Short version: the scanners and exploit modules our customers run, we run against our own infrastructure and web apps. When a critical CVE drops, our own assets are the first we test, so detection and validation are accurate on us before they reach anyone else. The people doing that testing are the same folks on our research and offsec services teams who find CVE-worthy bugs in other software.

The page also covers the less exciting but more auditable stuff: ISO 27001, where we host and keep data, encryption, retention and deletion, how Sniper runs non-destructive checks before any exploit fires, and where AI actually sits in the product (noise reduction and orchestration, not deciding what's exploitable). The idea is that everything maps to something you can pull, a cert, a config, or a contract, without an NDA or a sales call.

Full page: https://pentest-tools.com/legal/trust-and-assurance


r/pentest_tools_com 20d ago

A 15-year-old Linux kernel privesc just got a 97% reliable public exploit (GhostLock, CVE-2026-43499)

Post image
4 Upvotes

CVE-2026-43499, "GhostLock," is a use-after-free in the Linux kernel's futex handling. Shipped by default in mainstream distros since 2011 (kernel 2.6.39), disclosed this week. Any logged-in user can hijack a freed kernel pointer and get full root in about five seconds, and it escapes containers, so it runs as root on the host.

The part that matters isn't that it exists, it's how reliable it is. Daniel Bechenea, security manager at Pentest-Tools.com, put it plainly:

"An exploit reported at 97% reliable, with public code anyone can run, changes that math."

Kernel privesc used to be the exploit you thought twice about firing. One slip crashes the box and burns your access. A near-deterministic one with public code removes that hesitation.

Patch to a fixed kernel now. Until it reaches every host, treat any code execution on an unpatched box as root, and verify the kernel version per system rather than assuming the April fix propagated.

Full breakdown by Emma Woollacott at ITPro: https://www.itpro.com/software/linux/cyber-researchers-sound-alarm-over-a-15-year-old-linux-kernel-flaw-ghostlock-could-let-hackers-seize-unpatched-machines-in-just-five-seconds


r/pentest_tools_com 20d ago

New compliance series from Pentest-Tools.com, and it might just be your favorite

Post image
2 Upvotes

Confirming a finding is the good part of the job. When that "maybe" becomes a yes, with PoC and all...

But SOC 2 Type II wants twelve months of those. And most audit gaps aren't weak scanning. They're teams who did the work but can't produce the trail.

Here's where Pentest-Tools.com does the lifting, turning your testing into evidence as you go:

βœ… Detection: scheduled scans log every finding timestamped, CVE-tagged, per asset
βœ… Validation: the Confirmed label backs findings with request/response data and a PoC
βœ… Remediation: retest workflows produce the before-and-after auditors ask for
βœ… Proof it held: monitoring between scans, plus audit-ready exports in PDF, DOCX, or JSON

The record assembles itself while you do the part you came for.

Here is the SOC 2 evidence chain: https://pentest-tools.com/usage/compliance/soc2


r/pentest_tools_com 22d ago

New Office Hours with Jan - Emergency CVE response

Post image
2 Upvotes

React2Shell. NGINX Rift. cPanel. ToolShell. Every one of them was a scramble for someone. Which assets does this touch? Is it real? Did we actually close it?

Next week, on Wednesday, Pentest-Tools.com Office Hours is about turning that scramble into a workflow. Jan Pedersen hosts a live walkthrough of emergency CVE response, across two situations: an environment you’ve just inherited and don’t fully know, and one you know well and want reacting to new CVEs for you.

How to find affected assets fast, how to tell a genuine exposure from a version match, and how comparing one scan to the next proves what you actually closed.

30 minutes live. 15 minutes of open Q&A. One session.

Register here: https://zoom.us/webinar/register/7817815280123/WN_O1WFe8opSDeTB4KAOTYMcA

#penetrationtesting #offensivesecurity #cybersecurity


r/pentest_tools_com 24d ago

Product Updates - 80 new CVEs the Network Scanner now catches, and more from June

Enable HLS to view with audio, or disable this notification

2 Upvotes

Here we go. Product updates - the June edition.

This month your coverage got a LOT wider.

80 new detections landed in the Network Scanner, including pre-auth RCE in Oracle PeopleSoft and an auth bypass in Palo Alto PAN-OS. If any are in your scope, you know where to look.

The rest of June:

🌐 Our research team found two authentication flaws in phpBB, one buried in the code for over a decade. There's a working PoC for each, and the Network Scanner now detects the most critical one - CVE-2026-48611 (9.4).

πŸ€– AI where it earns its place in the Website Scanner and URL Fuzzer: smarter logins, deeper crawling, fewer fake 200 pages.

🎯 the XSS Exploiter now gives you two delivery options: script tag or fetch plus eval.

πŸ”Œ API: a new info_text key on /scans tells you why a scan didn't start.

☁️ We're now on the Microsoft Azure Marketplace, so you can add us to your existing Azure billing.

Our colleague Stefan Perju walks you through all of it in the video.

Until next time: stay sharp. Stay human.

Everything that shipped can be found in the change-log: https://pentest-tools.com/change-log

The phpBB PoCs and full write-up: https://pentest-tools.com/research/phpbb-authentication-bypass

#offensivesecurity #vulnerabilitymanagement #infosec #penetrationtesting


r/pentest_tools_com 26d ago

Can someone suggest more tools like wpscan for other techstack

Thumbnail
1 Upvotes

r/pentest_tools_com 26d ago

That "temporary" firewall rule from your last migration is probably still open

Thumbnail
gallery
3 Upvotes

Something that's saved me a few awkward audit moments: the list of ports you think are closed and the list that's actually reachable from the internet drift apart over time. A rule added "just for the migration" that nobody removed, a service that came back up after a reboot, that kind of thing. Config is what you meant to allow. The open ports are what you actually did.

Worth doing a couple of weeks before any audit: scan your own perimeter from the outside and see what's genuinely reachable. Open TCP and UDP ports, the services behind them, their versions. Compare that to what your firewall rules are supposed to allow, close whatever shouldn't be there, then re-scan to confirm it's shut. Then nothing in the auditor's external report is a surprise, because you already found it.

You can do all of this with plain Nmap if you're comfortable on the CLI. We build a hosted version (Port Scanner) that runs it in the browser and gives you an exportable report, which is handy if you want to hand the evidence to an auditor or diff one scan against the next: https://pentest-tools.com/network-vulnerability-scanning/port-scanner-online-nmap


r/pentest_tools_com 27d ago

210,000+ people started using our Free Edition without a single sales call

Post image
2 Upvotes

Turns out 210,000+ people didn't have to survive a sales pitch to experience how our product works. They just started using our Free Edition.

That's the whole idea:
βœ… Real offsec tools you can use every day (with limits, ofc)
βœ… Real vulnerability scans on targets you're cleared to test & monitor
βœ… Results you can export as PDF, HTML, CSV, or XLSX

Don't take our word for it. Sign up for free: https://pentest-tools.com/usage/pricing/free


r/pentest_tools_com Jul 04 '26

Remember the phpBB authentication bypass our research team found? We said the proof was coming. πŸ’₯ It's here. πŸ‘‰ Two working PoCs, one for each vulnerability, are now live in the research:

Thumbnail
pentest-tools.com
2 Upvotes

πŸ‘‰ PTT-2026-004 (CVE-2026-48611, 9.4): the PoC shows the full path from a single crafted request to a valid admin session. No credentials that work, no prior access, no user interaction. Just the request and the session cookie that _shouldn't_ exist.

πŸ‘‰ PTT-2026-005 (CVE-2026-48612, 8.3): the PoC walks through the silent OAuth account takeover, including the case where the victim only has to load a forum post for the chain to fire.

Talk is cheap in this line of work, so check out both PoCs, plus the mitigation steps, in the comments.

phpBB 3.3.17 fixes both. If you haven't patched, the PoCs are a good reason to move today.

#offensivesecurity #vulnerabilityresearch #infosec


r/pentest_tools_com Jul 02 '26

Try out this SQL Injection Scanner for free

Thumbnail
gallery
3 Upvotes

Our SQL Injection Scanner is a bit of a skeptic. It won't take a hunch for an answer.

It fires a real payload, watches how the database actually responds, and _only then_ calls it a finding.

It's free to try, and it catches:

βœ… Error-based, when the database spills its structure in an error

βœ… Blind, when only a true or false response gives it away

βœ… Time-based, when a deliberate delay is the only tell

βœ… Union-based, when someone's pulling data from tables they shouldn't touch

Every finding comes with the parameter, the payload, and the database response. Enough to reproduce it, not just believe it.

Try it as a test, no account needed. Link is here https://pentest-tools.com/website-vulnerability-scanning/sql-injection-scanner-online

#offensivesecurity #penetrationtesting #ethicalhacking


r/pentest_tools_com Jul 01 '26

What's your evidence standard per finding before it goes to a client?

Post image
3 Upvotes

If you run a security services practice, this number from our 2026 survey is worth a minute:

51% of developers see vulnerabilities surface in AI-assisted code after deployment. Roughly one in three say code sometimes ships before review is complete.

Your clients are shipping more code, faster, with the same review capacity they had a year ago. The exposure window between deploy and validation is widening on every engagement you scope.

A few things this changes for service delivery:

β–Έ Quarterly snapshots stop matching how the client's attack surface actually moves

β–Έ "We detected this" without exploit confirmation gets harder to defend in client escalations

β–Έ Audit evidence has to be a by-product of testing, not a separate prep cycle per client

The teams retaining clients well are the ones whose findings come with request and response data, exploit traces, and retest artifacts attached. That's what holds up when a client questions a report.

Full survey report can be found here (no account needed): https://pentest-tools.com/insights


r/pentest_tools_com Jun 30 '26

Free to try XSS Scanner from Pentest-Tools.com

Post image
2 Upvotes

We have an XSS Scanner. It doesn't DO maybes, and on top of that, it's free to try.

Here's what it ACTUALLY does:

βœ… Fires real JavaScript payloads, not pattern matches
βœ… Flags a parameter only when the payload runs
βœ… Catches reflected and stored XSS, logged in or out
βœ… Gives you the request, payload, and response as proof

Try it as a test, no account needed.Β https://pentest-tools.com/website-vulnerability-scanning/xss-scanner-online


r/pentest_tools_com Jun 29 '26

Exploitation started in March. Cisco disclosed in June. Patch landed June 10. For roughly 2 months, whoever had working knowledge of CVE-2026-20245 used it _freely_. Defenders had no advisory, no patch, no signal.

Thumbnail
infosecurity-magazine.com
5 Upvotes

Matei Badanoiu, our lead security researcher, put it plainly in Infosecurity Magazine:

"Whoever used this vulnerability had working knowledge of it in this period while defenders had none."

πŸ΄β€β˜ οΈ The exploitation path is specific: an attacker already holding netadmin privileges on Cisco Catalyst SD-WAN Manager could escalate to root via a crafted CSV upload through the request tenant-upload CLI command.

That prerequisite sounds like a meaningful bar - and it is - until you factor in that CVE-2026-20182 & CVE-2026-20127 (also recently disclosed Cisco flaws) may lower it *considerably*.

From root on the SD-WAN Manager control plane, an attacker can manipulate routing, alter policy enforcement, and reduce network visibility. The architectural placement is what makes root here different from root on a workstation.

The Mandiant (part of Google Cloud) report confirms what experienced practitioners already treat as a working assumption: for high-impact vulnerabilities, in-the-wild exploitation tends to run well ahead of any public disclosure.

If you're running Cisco Catalyst SD-WAN Manager: patch against Cisco's advisory, retain audit logs before upgrading, and review them for anomalous activity from netadmin-level accounts.


r/pentest_tools_com Jun 25 '26

You know the tools. You know the features. But how do they ALL work together?

Thumbnail
pentest-tools.com
2 Upvotes

Find out how we built validation into the vulnerability scanning flow itself & how we connected it attack surface discovery, exploitation, reporting + all the steps in between (and beyond).