Practical security research, tutorials and analysis from PentestMag.
Membership
If you are eager to explore the possibilities of interacting with the Windows API using Python, then you are in the right place. This article may be your gateway to unlocking the potential of invoking Windows API functions using Python. According to official Python documentation, ctypes is a foreign function library for Python. It provides C-compatible data
Bartek Adach
Membership
Introduction Penetration testing is driven mainly by a deep passion for understanding the inner mechanisms of systems and overcoming built-in limitations, and offers a captivating journey into cybersecurity. As a passionate pen-tester (and Red Team manager...), my experience in this field has been marked by unique challenges and fascinating discoveries, espe
Bartek Adach
Membership
Abstract The use of open-source is rapidly increasing for the software development process, which gives rise to the cyber attack known as ”Dependency Confusion”. This attack is carried out by exploiting the vulnerability of the package management system to insert malicious code into the software supply chain of the organization. Traditional methods of detect
Bartek Adach
Membership
AuthorsPranali Phadtare, Soummya Kulkarni, Shruthi Shunmugom M About UsIBM PTC is a proficient internal Security Test Team responsible for vulnerability assessment & ethicalhacking of web, mobile applications & infrastructure. Abstract HTTP/2 is an upgraded version of the HTTP 1.1 protocol. HTTP/2 provides various considerable refinements in terms of perform
Bartek Adach
Membership
INTRODUCTION Open source intelligence, commonly known as OSINT, refers to the process of collecting, processing and analyzing information from publicly available sources in order to generate actionable information that can be used for concrete actions, also known as actionable intelligence. OSINT involves various types of data from multiple sources, such as
Bartek Adach
Membership
Not all sensible data is exposed on the Internet through the IP transport layer. Some particular data are transmitted using radio waves or frequencies that are needed for specific types of attacks for this new perimeter, much different considering our normal ethical hacker activities (we cannot use NMAP for example in order to do first analysis based on the
Bartek Adach
Membership
Victoria Walters and Yu Cai, Michigan Technological University The progress we've seen in Artificial Intelligence (AI) over recent years has been truly remarkable. Generative, cognitive, and conversational AI have found extensive applications and are already in widespread use. As we explore the integration of AI into penetration testing, utilizing tools like
Bartek Adach
Membership
What is a Penetration Test? A penetration test (also known as a pen test) is a simulated attack on an IT system, network, or application to identify vulnerabilities and weaknesses that could be exploited by malicious actors. During a penetration test, a trained and authorized test team will attempt to exploit security weaknesses in the system to gain unautho
Bartek Adach
Membership
This revolutionary AI tool could help mission critical organizations develop and strengthen their cyber threat assessment and resiliency. Introduction The United States Intelligence Community (USIC) faces an ever-evolving landscape of cyber threats. In this high-stakes environment, it is crucial for intelligence agencies to stay ahead of emerging risks. Open
Jacek Stankiewicz
Membership
Introduction Performing pentests in APIs for many is a complex task, especially in some cases that do not have documentation to facilitate testing, thus having to perform a black box test that may or may not bring significant results. In addition, doubts arise about tools and methods that can be used to test an API, mainly because it contains different types
Jacek Stankiewicz
Membership
As per Rapid’s 4th annual State of APIs Report, 70% of developers indicate they will increase API usage this year, while 63% note that they utilized APIs more in 2022 than they did the previous year. With growing API adaption, there has been an increase in vulnerabilities seen with the production APIs. APIs have become a popular target for attackers. Designi
Jacek Stankiewicz
Membership
In the world of mobile app development, APIs play a crucial role in enabling developers to integrate various services into their apps. By using APIs, developers can quickly and easily access a wide range of functionalities without having to create them from scratch. However, with the increasing use of APIs, the security risks associated with them have also r
Jacek Stankiewicz
Membership
AuthorsChaitanya S Rao, Arpitha S About UsIBM PTC is a proficient internal Security Test Team responsible for vulnerability assessment and ethical hacking of web, mobile applications and infrastructure. Introduction:As the world becomes increasingly digitized, security has become an increasingly important issue. Businesses and organizations need to look for
Jacek Stankiewicz
Membership
Abstract: The use of blockchain technology in supply chains has the potential to significantly enhance the security and resilience of supply chains against cyber threats. This paper explores the fundamentals of blockchain technology for supply chain management, potential security attacks in blockchain-based supply chains, and the security of smart contracts
Jacek Stankiewicz
Membership
Abstract: SASE (Secure Access Service Edge) is a comprehensive solution that aims to improve the security of an organization's network by providing centralized and cloud-based security services. This solution streamlines access to resources and enhances the security of the network edge. SASE is important because it helps organizations cope with the challenge
Bartek Adach
Membership
CI/CD falls under the category of DevOps, which is formed by amalgamating both practices of continuous integration and continuous delivery. The main purpose of continuous integration and continuous delivery, i.e., CI/CD, is to automate almost all the human intervention that is being performed manually, which was a prerequisite to opt for new code. But now, w
Bartek Adach
Membership
by prof. Volker Skwarek, [email protected] In this interview, ChatGPT is challenged with the general subject of penetration testing. I wanted to know more about ChatGPT’s knowledge about pentesting and how far it would guide me with precise procedures for testing. Last but not least, I also wanted to know a little more about ChatGPT. The answers were s
Bartek Adach
Membership
Airgeddon is a popular, free, and open-source wireless security auditing tool that helps penetration testers locate and exploit vulnerabilities in wireless networks. It is available for download from GitHub. Airgeddon runs on Kali Linux and other Debian-based distributions. To use Airgeddon, first ensure that your wireless card is compatible. Next, identify
Bartek Adach
Membership
An interesting question came up the other day: can a penetration tester use ChatGPT in a meaningful way to accomplish particular tasks? In general, the primary use case presented for ChatGPT in penetration testing is to assist with things like crafting compelling phishing emails or fake profiles for websites or social media. I wanted to see if something more
Bartek Adach
Membership
[PenTest Magazine]: Hello Dinesh! It means a lot to us that you agreed to the interview! Would you like to introduce yourself to our readers? [Dinesh Sharma]: Hi! First of all, thank you so much for giving me this opportunity to interact with this amazing audience. It’s me, Dinesh. If you are a regular reader of the PenTest Magazine, then you may have come a
Dinesh sharma
Membership
by Andrea Cavallini Exploit is the goal that an attacker has in order to compromise a system, a service or an infrastructure. Finding a vulnerability and trying to exploit it in a specific context or perimeter is one of the cyber criminal’s major activities, with various methodologies used to get a breach or a leak for a compromise. Controlling a compromised
[STAFF MEMBER]
Membership
by Rausson Gouveia Hello everyone, I'm here to talk a little bit about a type of tool used in cyberattacks, called the Remote Access RAT Trojan, a tool used by virtually all hackers. But what would a RAT be? A RAT is a malicious program that remotely accesses devices, such as cell phones, computers and systems, used for downloading, uploading files, terminal
[STAFF MEMBER]
Membership
by Saad Babar Scapy is a powerful Python-based packet manipulation tool that allows you to dissect, send, and construct network packets. It provides a library of Python classes and functions that you can use to create and operate packets. It also includes a command-line interface that allows you to interact with the tool using simple commands and scripts. Sc
Saad Babar
Membership
by Jill Kamperides About the Author Jill is a Manager at OCD Tech, a Boston-based cybersecurity consulting firm. She oversees the firm’s IT Advisory Services and has a strong focus in penetration testing, having earned her GPEN certification in 2020. She’s conducted numerous assessments, the most common of which have been penetration tests of Active Director
Bruno Zwierz