PentesterLab (@pentesterlab) 's Twitter Profile
PentesterLab

@pentesterlab

We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!

ID: 438070214

linkhttps://www.pentesterlab.com/ calendar_today16-12-2011 04:32:30

10,10K Tweet

180,180K Followers

0 Following

PentesterLab (@pentesterlab) 's Twitter Profile Photo

PentesterLab has the largest collection of hands-on JWT labs. We cover algorithm confusion, jku, kid, x5u and so much more. We also research new attack techniques and review JWT-related CVEs. Here is a great one we came across today...

PentesterLab has the largest collection of hands-on JWT labs. We cover algorithm confusion, jku, kid, x5u and so much more.

We also research new attack techniques and review JWT-related CVEs.

Here is a great one we came across today...
Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

We're excited to welcome @Pentesterlab as an In-Kind Sponsor of the Bug Bounty Village at DEF CON 33. Their support helps us create a space for hackers to connect, learn, and push boundaries. #BugBounty #DEFCON #BBV #BugBountyVillage

PentesterLab (@pentesterlab) 's Twitter Profile Photo

Reviewing CVEs can feel dull, but reading patches is a great way to sharpen your code-review training. Todayโ€™s gem (see screenshot ๐Ÿ‘‡): a cookie-signature check that shouted: INVALID SIGNATURE. THE VALID SIGNATURE IS โ€ฆ It leaked the valid signature ๐Ÿคฆโ€โ™‚๏ธ One-line fix: stop

Reviewing CVEs can feel dull, but reading patches is a great way to sharpen your code-review training.

Todayโ€™s gem (see screenshot ๐Ÿ‘‡): a cookie-signature check that shouted:

INVALID SIGNATURE. THE VALID SIGNATURE IS โ€ฆ

It leaked the valid signature ๐Ÿคฆโ€โ™‚๏ธ

One-line fix: stop
PentesterLab (@pentesterlab) 's Twitter Profile Photo

Go parsers, Funky Chunks, Template injections... What a week! ๐Ÿ“ฆ w4ke.info/2025/06/18/funโ€ฆ ๐Ÿนblog.trailofbits.com/2025/06/17/uneโ€ฆ ๐Ÿ’ฃlabs.watchtowr.com/is-b-for-backdโ€ฆ ๐Ÿ˜ด tantosec.com/blog/2025/06/iโ€ฆ ๐Ÿ›ก๏ธ

PentesterLab (@pentesterlab) 's Twitter Profile Photo

๐Ÿš€ Added 3 brand-new Go code-review labs to our Golang Code Review badge! Sharpen your eye for subtle bugs and level up your AppSec skills. Dive in here ๐Ÿ‘‰ pentesterlab.com/badges/golang-โ€ฆ #golang #appsec #codereview

PentesterLab (@pentesterlab) 's Twitter Profile Photo

๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐œ๐จ๐ฆ๐ฆ๐จ๐ง ๐ฌ๐ž๐ง๐ฌ๐ž ๐ข๐ฌ ๐จ๐ฏ๐ž๐ซ๐ซ๐š๐ญ๐ž๐โ€ฆ

๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐œ๐จ๐ฆ๐ฆ๐จ๐ง ๐ฌ๐ž๐ง๐ฌ๐ž ๐ข๐ฌ ๐จ๐ฏ๐ž๐ซ๐ซ๐š๐ญ๐ž๐โ€ฆ
PentesterLab (@pentesterlab) 's Twitter Profile Photo

๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐ข๐ญ ๐ฅ๐ข๐ญ๐ž๐ซ๐š๐ฅ๐ฅ๐ฒ ๐œ๐š๐งโ€™๐ญ ๐ž๐ฏ๐ž๐ง.

๐‰๐š๐ฏ๐š๐’๐œ๐ซ๐ข๐ฉ๐ญ: ๐›๐ž๐œ๐š๐ฎ๐ฌ๐ž ๐ข๐ญ ๐ฅ๐ข๐ญ๐ž๐ซ๐š๐ฅ๐ฅ๐ฒ ๐œ๐š๐งโ€™๐ญ ๐ž๐ฏ๐ž๐ง.
PentesterLab (@pentesterlab) 's Twitter Profile Photo

Another CVE we came across this week as part of our CVE-analysis routine. The impact is probably limited, but the vulnerability is a classic example of parser differential. To give you a bit of background, the file .netrc is used to store credentials. It's mostly used by FTP

Another CVE we came across this week as part of our CVE-analysis routine. 

The impact is probably limited, but the vulnerability is a classic example of parser differential.

To give you a bit of background, the file .netrc is used to store credentials. It's mostly used by FTP
PentesterLab (@pentesterlab) 's Twitter Profile Photo

๐Ÿ New month = new FREE labs! Tackle 3 bite-size Python code-review snippets and level up your bug-spotting skills. Dive in now โ†’ pentesterlab.com/my/progress#onโ€ฆ ๐Ÿ”๐Ÿ†“ #Python #CodeReview

Louis Nyffenegger (@snyff) 's Twitter Profile Photo

The biggest shift in AppSec with AI? Dev work looks more like code review. Theyโ€™re reviewing AI output, not writing every line. Old โ€œwrite secure codeโ€ training isnโ€™t enough. You need to teach them to spot bugs like a reviewer. ๐Ÿ‘‰ pentesterlab.com/live-training/