Quantcast
Channel: PenTesticles
Browsing latest articles
Browse All 22 View Live

Welcome to PenTesticles.com

Hello, and welcome to PenTesticles.com. I have finally gotten around to writing a few blog posts and shall be slowly unleashing them upon the world. Any comments welcome and feedback positive or...

View Article


Real-life Challenges in Social Engineering as a Penetration Tester

BackgroundRecently, I’ve been lucky enough to get to work with some interesting clients who’ve wanted some quite openly scoped social engineering tests. It’s not something I do on a really regular...

View Article


PHUKDs - An Oldie but a Goodie!

A topic I’ve wanted to blog about for a while is the use of PHUKDs as an attack vector in Penetration testing. Firstly, I’d like to discuss the background of how these devices work and why they have...

View Article

SID de-duplication

On the 3rd November 2009, Sysinternals retired ‘NewSID’, a utility that changes a computers machine Security Identifier (machine SID), but why? I still see people cloning virtual machines as a stardard...

View Article

Facebook and Google Installed on my Windows 7 Machine?

As a fairly utilitarian Windows user, I like to have my machine stripped down with a lot of bells and whistles turned off. Especially all the hindrances, I mean 'simplifying features' that Microsoft...

View Article


Easter Egg in Burp Suite 1.4.01

After an impromptu iMessage from a hacking bud (poojinky), just as I was closing up burp for the day after an epic web app test; my day was made a bit more amusing. There may be more, but there is at...

View Article

Introductions, Automation and Simplification

Ok, so time to introduce myself, I'm Ben (bdpuk) I've been a tester for over 5 years and like every other tester out there I spend much more time reading blogs than writing them. This is hopefully...

View Article

Installing BT5 from CLI on Machines Running NVidia Graphics Cards with No...

The following blog post has been created to bring together a lot of information (some of which you may already know) pertaining to installing BackTrack 5 successfully onto systems that have NVidia...

View Article


The Awkward Sophomore Blog Post - The (first) NMAP Post

I'm back, the other nut from this ballsy pair (that'll be the last time I make those jokes I promise). So where were we? (We were here if you missed the previous post) We had a network range,...

View Article


BSides London 2012

Recently, both Ben and I were lucky enough to get our grubby mitts on some BSides tickets, which turned out to be a mixed bag, but was still a very worthwhile and well organised event. Overall, it was...

View Article

Interesting Directives in php.ini (for Pen Testers and Devs)

For those of you not overly familiar with PHP; php.ini is where you define your settings. As a penetration tester, you should be used to seeing the symptoms of these settings either not being set or...

View Article

MS SQL - Useful Stored Procedures for SQL Injection and Ports Info.

The following post lists and describes various useful stored procedures and port information for MS SQL. The information is relevant for all versions unless stated (there may be a couple of mistakes,...

View Article

We Have the Port Scans, what now?

It's been a while, I hope you're good. I'm fine thanks, busy as sin but isn't that always the way? So where did we leave off? From reading back through my previous post, we'd scanned our little guts...

View Article


HackArmoury.com - A Pentesticles Project!

Recently, we at Pentesticles took over the ownership and full development of HackArmoury.com. So, I thought it was time to write a blog post about it and speak a bit about what it does, how to use it...

View Article

PaulDotCom Interview

A big thanks to Paul and Mike and Larry (and Carlos) for having us on the show, we really enjoyed it. Apologies for being a bit up-tight in places, but we're British, it's what we do. And, for the...

View Article


Proxying 3G iPhone Data

Hey! It's been a while, I promised you guys that I'd do this more often and I've failed you and for that I am sorry (well sort of). So today I'm taking a break from automation to talk to you lovely...

View Article

De-duping multiple interface nessus results with sed.

A bit of a mouthful and not that useful for most, but this is saving me headaches left, right and centre at the moment (and is dead simple).It's always an issue when testing a network that you can run...

View Article


What You Need To Know to Become a Penetration Tester

It really has been a long time since I last posted. This post is more of an essay, so it may be a TL;DR for some, but hopefully a there is some good information for those who wish to break into...

View Article

Penetration Testing: You’re Doing it Wrong (?) – Part One

Sexual innuendos aside, I've wanted to write an article about the unspoken thoughts of penetration testers (at least my own and the great testers I've been lucky enough to work with) for quite some...

View Article

When Two Worlds Collide: Why InfoSec Professionals Hate Recruiters

In honesty, I’ve never been overly fond of recruiters, stemming from my early days in the industry being duped into long journeys for interviews that were totally inappropriate, so the recruiter could...

View Article

Bounties Bug Me (A Little)

The popularity of Bug Bounties has grown hugely over the last 3-5 years, with start-ups taking advantage of eager VCs and Angel investors who want a piece of the ‘Cyber’ pie. As this niche market has...

View Article


What Finnish School Children Can Teach The InfoSec Community

One of the plagues (in my humble opinion) within the InfoSec Community is compartmentalised thinking. We put different areas of our organisations into boxes and turn paradigms into silos. The...

View Article

Browsing latest articles
Browse All 22 View Live


Latest Images