Welcome to PenTesticles.com
Hello, and welcome to PenTesticles.com. I have finally gotten around to writing a few blog posts and shall be slowly unleashing them upon the world. Any comments welcome and feedback positive or...
View ArticleReal-life Challenges in Social Engineering as a Penetration Tester
BackgroundRecently, I’ve been lucky enough to get to work with some interesting clients who’ve wanted some quite openly scoped social engineering tests. It’s not something I do on a really regular...
View ArticlePHUKDs - An Oldie but a Goodie!
A topic I’ve wanted to blog about for a while is the use of PHUKDs as an attack vector in Penetration testing. Firstly, I’d like to discuss the background of how these devices work and why they have...
View ArticleSID de-duplication
On the 3rd November 2009, Sysinternals retired ‘NewSID’, a utility that changes a computers machine Security Identifier (machine SID), but why? I still see people cloning virtual machines as a stardard...
View ArticleFacebook and Google Installed on my Windows 7 Machine?
As a fairly utilitarian Windows user, I like to have my machine stripped down with a lot of bells and whistles turned off. Especially all the hindrances, I mean 'simplifying features' that Microsoft...
View ArticleEaster Egg in Burp Suite 1.4.01
After an impromptu iMessage from a hacking bud (poojinky), just as I was closing up burp for the day after an epic web app test; my day was made a bit more amusing. There may be more, but there is at...
View ArticleIntroductions, Automation and Simplification
Ok, so time to introduce myself, I'm Ben (bdpuk) I've been a tester for over 5 years and like every other tester out there I spend much more time reading blogs than writing them. This is hopefully...
View ArticleInstalling BT5 from CLI on Machines Running NVidia Graphics Cards with No...
The following blog post has been created to bring together a lot of information (some of which you may already know) pertaining to installing BackTrack 5 successfully onto systems that have NVidia...
View ArticleThe Awkward Sophomore Blog Post - The (first) NMAP Post
I'm back, the other nut from this ballsy pair (that'll be the last time I make those jokes I promise). So where were we? (We were here if you missed the previous post) We had a network range,...
View ArticleBSides London 2012
Recently, both Ben and I were lucky enough to get our grubby mitts on some BSides tickets, which turned out to be a mixed bag, but was still a very worthwhile and well organised event. Overall, it was...
View ArticleInteresting Directives in php.ini (for Pen Testers and Devs)
For those of you not overly familiar with PHP; php.ini is where you define your settings. As a penetration tester, you should be used to seeing the symptoms of these settings either not being set or...
View ArticleMS SQL - Useful Stored Procedures for SQL Injection and Ports Info.
The following post lists and describes various useful stored procedures and port information for MS SQL. The information is relevant for all versions unless stated (there may be a couple of mistakes,...
View ArticleWe Have the Port Scans, what now?
It's been a while, I hope you're good. I'm fine thanks, busy as sin but isn't that always the way? So where did we leave off? From reading back through my previous post, we'd scanned our little guts...
View ArticleHackArmoury.com - A Pentesticles Project!
Recently, we at Pentesticles took over the ownership and full development of HackArmoury.com. So, I thought it was time to write a blog post about it and speak a bit about what it does, how to use it...
View ArticlePaulDotCom Interview
A big thanks to Paul and Mike and Larry (and Carlos) for having us on the show, we really enjoyed it. Apologies for being a bit up-tight in places, but we're British, it's what we do. And, for the...
View ArticleProxying 3G iPhone Data
Hey! It's been a while, I promised you guys that I'd do this more often and I've failed you and for that I am sorry (well sort of). So today I'm taking a break from automation to talk to you lovely...
View ArticleDe-duping multiple interface nessus results with sed.
A bit of a mouthful and not that useful for most, but this is saving me headaches left, right and centre at the moment (and is dead simple).It's always an issue when testing a network that you can run...
View ArticleWhat You Need To Know to Become a Penetration Tester
It really has been a long time since I last posted. This post is more of an essay, so it may be a TL;DR for some, but hopefully a there is some good information for those who wish to break into...
View ArticlePenetration Testing: You’re Doing it Wrong (?) – Part One
Sexual innuendos aside, I've wanted to write an article about the unspoken thoughts of penetration testers (at least my own and the great testers I've been lucky enough to work with) for quite some...
View ArticleWhen Two Worlds Collide: Why InfoSec Professionals Hate Recruiters
In honesty, I’ve never been overly fond of recruiters, stemming from my early days in the industry being duped into long journeys for interviews that were totally inappropriate, so the recruiter could...
View ArticleBounties Bug Me (A Little)
The popularity of Bug Bounties has grown hugely over the last 3-5 years, with start-ups taking advantage of eager VCs and Angel investors who want a piece of the ‘Cyber’ pie. As this niche market has...
View ArticleWhat Finnish School Children Can Teach The InfoSec Community
One of the plagues (in my humble opinion) within the InfoSec Community is compartmentalised thinking. We put different areas of our organisations into boxes and turn paradigms into silos. The...
View Article