PentestMag Library

Articles

Practical security research, tutorials and analysis from PentestMag.

105 articles found · Showing 73–96

Membership

Unlocking the Power: Python for Windows API

If you are eager to explore the possibilities of interacting with the Windows API using Python, then you are in the right place. This article may be your gateway to unlocking the potential of invoking Windows API functions using Python. According to official Python documentation, ctypes is a foreign function library for Python. It provides C-compatible data

Bartek Adach

Membership

Navigating AWS Cloud Security: Insights from a Red Team Manager

Introduction Penetration testing is driven mainly by a deep passion for understanding the inner mechanisms of systems and overcoming built-in limitations, and offers a captivating journey into cybersecurity. As a passionate pen-tester (and Red Team manager...), my experience in this field has been marked by unique challenges and fascinating discoveries, espe

Bartek Adach

Membership

Good, Bad and the Ugly of HTTP/2

AuthorsPranali Phadtare, Soummya Kulkarni, Shruthi Shunmugom M About UsIBM PTC is a proficient internal Security Test Team responsible for vulnerability assessment & ethicalhacking of web, mobile applications & infrastructure. Abstract HTTP/2 is an upgraded version of the HTTP 1.1 protocol. HTTP/2 provides various considerable refinements in terms of perform

Bartek Adach

Membership

How to Integrate Artificial Intelligence on Audio Files into Offensive Security Workflows

INTRODUCTION Open source intelligence, commonly known as OSINT, refers to the process of collecting, processing and analyzing information from publicly available sources in order to generate actionable information that can be used for concrete actions, also known as actionable intelligence. OSINT involves various types of data from multiple sources, such as

Bartek Adach

Membership

SDR - Starting with Signal Hacking

Not all sensible data is exposed on the Internet through the IP transport layer. Some particular data are transmitted using radio waves or frequencies that are needed for specific types of attacks for this new perimeter, much different considering our normal ethical hacker activities (we cannot use NMAP for example in order to do first analysis based on the

Bartek Adach

Membership

Exploring the Boundaries: Legal and Ethical Considerations of Generative Artificial Intelligence in Penetration Testing and the CFAA

Victoria Walters and Yu Cai, Michigan Technological University The progress we've seen in Artificial Intelligence (AI) over recent years has been truly remarkable. Generative, cognitive, and conversational AI have found extensive applications and are already in widespread use. As we explore the integration of AI into penetration testing, utilizing tools like

Bartek Adach

Membership

Penetration Test Need-To-Know

What is a Penetration Test? A penetration test (also known as a pen test) is a simulated attack on an IT system, network, or application to identify vulnerabilities and weaknesses that could be exploited by malicious actors. During a penetration test, a trained and authorized test team will attempt to exploit security weaknesses in the system to gain unautho

Bartek Adach

Membership

Could OpenAI's ChatGPT be a game-changer for United States intelligence agencies?

This revolutionary AI tool could help mission critical organizations develop and strengthen their cyber threat assessment and resiliency. Introduction The United States Intelligence Community (USIC) faces an ever-evolving landscape of cyber threats. In this high-stakes environment, it is crucial for intelligence agencies to stay ahead of emerging risks. Open

Jacek Stankiewicz

Membership

Methodology and tools used in API Testing Introduction

Introduction Performing pentests in APIs for many is a complex task, especially in some cases that do not have documentation to facilitate testing, thus having to perform a black box test that may or may not bring significant results. In addition, doubts arise about tools and methods that can be used to test an API, mainly because it contains different types

Jacek Stankiewicz

Membership

API Security Common Mistakes

As per Rapid’s 4th annual State of APIs Report, 70% of developers indicate they will increase API usage this year, while 63% note that they utilized APIs more in 2022 than they did the previous year. With growing API adaption, there has been an increase in vulnerabilities seen with the production APIs. APIs have become a popular target for attackers. Designi

Jacek Stankiewicz

Membership

Android APIs Hacking

In the world of mobile app development, APIs play a crucial role in enabling developers to integrate various services into their apps. By using APIs, developers can quickly and easily access a wide range of functionalities without having to create them from scratch. However, with the increasing use of APIs, the security risks associated with them have also r

Jacek Stankiewicz

Membership

ChatGPT for Pentesters

AuthorsChaitanya S Rao, Arpitha S About UsIBM PTC is a proficient internal Security Test Team responsible for vulnerability assessment and ethical hacking of web, mobile applications and infrastructure. Introduction:As the world becomes increasingly digitized, security has become an increasingly important issue. Businesses and organizations need to look for

Jacek Stankiewicz

Membership

The Role Of Blockchain Technology In Supply Chains Against Cyber Threats

Abstract: The use of blockchain technology in supply chains has the potential to significantly enhance the security and resilience of supply chains against cyber threats. This paper explores the fundamentals of blockchain technology for supply chain management, potential security attacks in blockchain-based supply chains, and the security of smart contracts

Jacek Stankiewicz

Membership

The Role of Secure Access Service Edge in Cybersecurity

Abstract: SASE (Secure Access Service Edge) is a comprehensive solution that aims to improve the security of an organization's network by providing centralized and cloud-based security services. This solution streamlines access to resources and enhances the security of the network edge. SASE is important because it helps organizations cope with the challenge

Bartek Adach

Membership

Top 6 CI/CD Security Best Practices to Follow

CI/CD falls under the category of DevOps, which is formed by amalgamating both practices of continuous integration and continuous delivery. The main purpose of continuous integration and continuous delivery, i.e., CI/CD, is to automate almost all the human intervention that is being performed manually, which was a prerequisite to opt for new code. But now, w

Bartek Adach

Membership

Chatting with Rachael (ChatGPT) about Pentesting

by prof. Volker Skwarek, [email protected] In this interview, ChatGPT is challenged with the general subject of penetration testing. I wanted to know more about ChatGPT’s knowledge about pentesting and how far it would guide me with precise procedures for testing. Last but not least, I also wanted to know a little more about ChatGPT. The answers were s

Bartek Adach

Membership

WiFi Hacking with Airgeddon on Kali Linux

Airgeddon is a popular, free, and open-source wireless security auditing tool that helps penetration testers locate and exploit vulnerabilities in wireless networks. It is available for download from GitHub. Airgeddon runs on Kali Linux and other Debian-based distributions. To use Airgeddon, first ensure that your wireless card is compatible. Next, identify

Bartek Adach

Membership

Is ChatGPT Useful for Penetration Testing?

An interesting question came up the other day: can a penetration tester use ChatGPT in a meaningful way to accomplish particular tasks? In general, the primary use case presented for ChatGPT in penetration testing is to assist with things like crafting compelling phishing emails or fake profiles for websites or social media. I wanted to see if something more

Bartek Adach

Membership

Let me tell you one secret - nothing can be 100% secure - An Interview with Dinesh Sharma

[PenTest Magazine]: Hello Dinesh! It means a lot to us that you agreed to the interview! Would you like to introduce yourself to our readers? [Dinesh Sharma]: Hi! First of all, thank you so much for giving me this opportunity to interact with this amazing audience. It’s me, Dinesh. If you are a regular reader of the PenTest Magazine, then you may have come a

Dinesh sharma

Membership

ESXi - VM exploited with Python

by Andrea Cavallini Exploit is the goal that an attacker has in order to compromise a system, a service or an infrastructure. Finding a vulnerability and trying to exploit it in a specific context or perimeter is one of the cyber criminal’s major activities, with various methodologies used to get a breach or a leak for a compromise. Controlling a compromised

[STAFF MEMBER]

Membership

RAT: Trojan Access Remote

by Rausson Gouveia Hello everyone, I'm here to talk a little bit about a type of tool used in cyberattacks, called the Remote Access RAT Trojan, a tool used by virtually all hackers. But what would a RAT be? A RAT is a malicious program that remotely accesses devices, such as cell phones, computers and systems, used for downloading, uploading files, terminal

[STAFF MEMBER]

Membership

What is Scapy?

by Saad Babar Scapy is a powerful Python-based packet manipulation tool that allows you to dissect, send, and construct network packets. It provides a library of Python classes and functions that you can use to create and operate packets. It also includes a command-line interface that allows you to interact with the tool using simple commands and scripts. Sc

Saad Babar

Membership

Windows Privilege Escalation: The Concepts of Hijacking Execution Flow

by Jill Kamperides About the Author Jill is a Manager at OCD Tech, a Boston-based cybersecurity consulting firm. She oversees the firm’s IT Advisory Services and has a strong focus in penetration testing, having earned her GPEN certification in 2020. She’s conducted numerous assessments, the most common of which have been penetration tests of Active Director

Bruno Zwierz