1. X
  2. PentesterLab
Log inSign up
PentesterLab
11K posts
Image
user avatar
PentesterLab
@PentesterLab
Don’t just learn tools and payloads. Learn why vulnerabilities exist. Hands-on web hacking, security code review, and real-world CVE labs.
Melbourne, Victoria
pentesterlab.com
Joined December 2011
0
Following
206K
Followers
RepliesRepliesArticlesArticlesMediaMedia
  • Pinned
    user avatar
    PentesterLab
    @PentesterLab
    Jun 30, 2025
    💥🐹 4 new Go Code Review Labs just dropped! 🐹💥 Read the code, peek at the diff, find the bug. Sharpen your skills:
    Image
    pentesterlab.com
    PentesterLab: Learn with our Golang Code Review Badge
    The Golang Code Review Badge is our badge dedicated to code review in Golang. It covers the discovery of weaknesses and vulnerabilities using source code review.
    33K
  • user avatar
    PentesterLab
    @PentesterLab
    Jul 31
    A dev added return; in front of eval() so user input "can't execute." PHP hoists class declarations at compile time... Declare a class the app autoloads later, and your constructor runs. return; stops statements. It doesn't stop declarations. 💥RCE💥 New lab, based on
    Image
    pentesterlab.com
    PentesterLab: PHP eval() Class Hoisting RCE
    This challenge covers an unauthenticated remote code execution reproducing MantisBT CVE-2026-49273: a value is validated with eval('return; ...'), but PHP hoists class declarations past the return;...
    5.9K
  • user avatar
    PentesterLab
    @PentesterLab
    Jul 27
    First @PentesterLab webinar this week on the impact of AI on offensive security:
    Image
    us06web.zoom.us
    Welcome! You are invited to join a webinar: The Uneven Impact of AI on Offensive Security. After...
    I recently ran a poll on LinkedIn and X asking which areas of offensive security will be most impacted by AI. The results have been interesting, but I don't think they tell the whole story. In this...
    7K
  • user avatar
    PentesterLab
    @PentesterLab
    Jul 27
    Article cover image
    Article
    Research Worth Reading - Week 30, 2026
    The agents are playing Prison Break this week. We also have two very cool exploit chains and a question I keep coming back to: is AI going to make exploit chains more complex? 🤖 OpenAI and Hugging...
    5.8K
  • user avatar
    PentesterLab
    @PentesterLab
    Jul 22
    How much intelligence does this patch reveal? In a public repository, a security patch can also become the advisory. As LLMs make vulnerability reconstruction cheaper, maintainers may need to consider not only whether a fix works, but what it reveals. New article from
    user avatar
    Louis Nyffenegger
    @snyff
    Jul 22
    How much intelligence does this patch reveal? Once a security patch lands in a public repository, it can become the advisory. LLMs are making it dramatically cheaper to reconstruct vulnerabilities from commits before defenders have deployed the fix. pentesterlab.com/blog/bletchley…
    6.8K
  • See @PentesterLab's full profile

    Sign up
    Log in

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement