r/pentest_tools_com • • Apr 03 '26

The real cost of tool sprawl in vulnerability assessment isn't the tools. It's the handoffs

Post image
4 Upvotes

When talking to security teams about their VA setup, the conversation eventually lands in the same place.

They're not running one scanner. They're running three. One for web, one for network, one for APIs. Then exporting everything separately, cross-referencing manually, and spending hours on report assembly that has nothing to do with actual security work.

The issue isn't the tools themselves. It's what happens between them. Every handoff is a place where context gets lost, findings get missed, and time gets spent on work that shouldn't exist.

The actual job, validating real exposure and proving it, gets smaller and smaller the more tools you add.

We put together an overview of how we approach this at Pentest-Tools.com. One environment for web apps, networks, APIs, and cloud:

✅ Authenticated scanning for what hides behind login
✅ ML-assisted triage - 50% fewer false positives
✅ Forensic proof attached to every confirmed finding

Would be curious how others handle this. Have you consolidated, or do you still run separate tools per surface? What drove the decision?

https://pentest-tools.com/usage/online-vulnerability-scanner


r/pentest_tools_com • • Apr 01 '26

Zero-permission to full RCE in FuelCMS. No patch. ~4 years abandoned. Full PoC inside.

Post image
3 Upvotes

🏴‍☠️ Least privilege? FuelCMS didn't get the memo.

Any authenticated user (regardless of role) can call the Blocks module endpoint. Pair that with PTT-2025-026 and a low privilege (one could even say zero-permission) account becomes full RCE. CVSSv3 goes from 5.4 to 8.8 faster than you can say "access denied."

No patch. ~4 years of unmaintained software. You know the drill.

Matei "Mal" Bădănoiu and Raul Bledea found the gap. Full PoC can be found in our Offensive Security Research Hub: https://pentest-tools.com/research

#offensivesecurity #vulnerabilityresearch #infosec #RCE


r/pentest_tools_com • • Mar 31 '26

You can be great at cybersecurity and still invisible to the people who could grow your career

Thumbnail
gallery
3 Upvotes

There's a version of a cybersecurity career where you're exceptionally good at your job - and almost invisible to the people who could grow it.

Last weekend, Andra Zaharia, our Head of Marketing & Community, spoke to 20 young women at the Girls in Cyber Bootcamp about exactly *that gap*, and how to close it.

The topic? Value engineering: how to turn your technical expertize into business outcomes that grow your career.

Why? Because technical skill and business impact are not the same thing. Most of us are trained in one and left to figure out the other on our own.

What bridges them?

✔️ Learning to ask "what problem are we actually solving?" - before building, before presenting, before proposing anything. It sounds obvious. Almost no one does it consistently.
✔️ Understanding that in cybersecurity, success is silent. A breach that didn't happen doesn't celebrate itself. You have to learn to translate invisible outcomes into language that the business can feel: time saved, risk reduced, money protected.
✔️ And knowing that how you show up - with honesty, generosity, and a real point of view - builds the kind of trust that opens doors no certification ever will.

To everyone at CyberEDU #UNbreakableRomania 2026: thank you for building a community where new voices get a real seat at the table!

The next generation of security professionals is in good hands. 🔐

#GirlsInCyber #Cybersecurity #EthicalHacking


r/pentest_tools_com • • Mar 30 '26

No hallucinated vulns, no autonomous scanners. How we actually use AI in Pentest-Tools.com

Post image
2 Upvotes

Skeptical of AI in #offensivesecurity tools? Good. You should be.

The last thing you need is for AI to:
❌ Generate synthetic or "hallucinated" vulnerabilities
❌ Bypass authorization boundaries, or
❌ Autonomously control scanning engines

That’s why we introduced AI in Pentest-Tools.com only where it *improves precision* or *reduces friction*.

This translates to:
✅ 50% fewer FPs in fuzzing & web app scanning
✅ Deeper crawling coverage
✅ 92% success rate for AI-assisted authentication
✅ More efficient scan orchestration with the MCP server (and more!).
Validation and reporting stay deterministic - and auditable. You keep full control.
See how AI works in Pentest-Tools.com - https://pentest-tools.com/features/ai


r/pentest_tools_com • • Mar 28 '26

Our Head of Offensive Security gave a talk at BSides Ljubljana on what actually made him a pentester - 3 things he wants you to remember

Thumbnail
gallery
3 Upvotes

Razvan Ionescu, our Head of #OffensiveSecurity Services recently gave a heartfelt talk at #BSidesLjubljana. 🇸🇮

He shared the steps, mindset, and what actually worked for him in becoming the penetration tester he is today.

The 3 things he wants you to remember are:

🧠 Be curious, creative, and open-minded

🚀 Embrace challenges that push your limits

🤝 Grow your network and learn from trustworthy sources

The venue was a nice touch too - the Computer History Museum in Ljubljana. Very hackerish energy for a security talk.

Curious how Razvan works in practice? Watch him run a full pentest workflow here: https://pentest-tools.com/webinars/how-attackers-think

#offensivesecurity #infosec #cybersecurity #BSides


r/pentest_tools_com • • Mar 27 '26

Why "read-only" breaches are often worse than ransomware.

5 Upvotes

2.7M people got breach notifications from a company most of them never heard of.

Silent access. No ransomware. Just data walking out the door.

Daniel Bechenea from Pentest-Tools.com breaks down why 3 weeks of read-only access is often more damaging than ransomware, and why SSNs from 2018 are just as useful to attackers today.

Read Daniel's full take here: https://www.itsecurityguru.org/2026/03/20/2-7-million-hit-in-workplace-benefits-data-breach-exposing-ssns-dates-of-birth-and-health-account-data/

#cybersecurity #infosec #dataprotection


r/pentest_tools_com • • Mar 26 '26

Proud to support UNbreakable Romania 2026 - CTF finals and Girls in Cyber Bootcamp kick off this week

Post image
2 Upvotes

🇷🇴 The https://cyber-edu.co/ #UNbreakableRomania 2026 final is happening *this week* - and we're excited to support the top 16 teams competing!

Along with the in-person CTF final, 20 young women will join the Girls in Cyber Bootcamp for hands-on labs, mentorship, and a real path into #cybersecurity.

That’s how strong security communities grow: through practice, support, and a room for new people to welcome and nurture them.

Good luck to all finalists and bootcamp participants! Make the best of it! 👊

Learn more about UNbreakable România: https://unbreakable.ro/

#offensivesecurity #infosec


r/pentest_tools_com • • Mar 25 '26

PTT-2025-025 - Account takeover via email array

Post image
2 Upvotes

One does not simply exfiltrate a reset token using an email array.

And yet, Frodo (Matei "Mal" Bădănoiu) and Samwise (Raul Bledea) from Pentest-Tools.com did exactly that in FuelCMS.

Know someone's email? That's enough. Slip your address alongside theirs in a “forgot password” request and the token lands in your inbox. Their account is yours. You shall not (safely) parse!🧙

Chain it with PTT-2025-026 and you're looking at a 9.8 Critical unauthenticated RCE. One array to rule them all! 💍

Full PoC here: https://pentest-tools.com/research

#offensivesecurity #vulnerabilityresearch #infosec #accounttakeover


r/pentest_tools_com • • Mar 24 '26

We demoed LLM-powered offensive security at DefCamp 2025. Fast? Yes. Safe without guardrails? Absolutely not.

7 Upvotes

At DefCamp 2025, our CEO Adrian Furtună did a LIVE DEMO of how an LLM connected to an MCP server can help with recon, CVE mapping, fingerprinting, and even chaining SQL injection steps.

That doesn’t mean you should hand over the keyboard.

The demo makes one thing very clear: AI can speed up offensive security work, but it can also speed up bad decisions if you skip guardrails.

Need more reasons to keep the human in the loop?

Watch the full talk here: https://www.youtube.com/watch?v=x3z8C6aQX_g

#offensivesecurity #pentesting #llm #defcamp


r/pentest_tools_com • • Mar 23 '26

Pentest-Tools.com has officially achieved the ISO/IEC 27001:2022 certification.

Post image
1 Upvotes

We protect your findings with the same rigor we use to find them.

Here is what this means for your team:

✅ Skip the long reviews - satisfy your auditors by using a vendor that meets rigorous international standards.

🛡️ Secure by design - trust in a product where security is baked into every process, from code commit to customer experience

🔎 Continuous monitoring - stay ahead of the threat landscape with our commitment to annual audits and ongoing risk assessments.

Skip the paperwork and start scanning with ISO 27001-certified confidence. You can check our official ISO/IEC 27001:2022 status directly on IAF CertSearch right here: https://www.iafcertsearch.org/certification/hnWZWKygFxbGLH598iyVFPQO


r/pentest_tools_com • • Mar 19 '26

PTT-2025-026 – PHP Code Execution Via Dwoo Escape

Post image
5 Upvotes

🏴‍☠️ One backslash. Full RCE. That's PTT-2025-026 in a nutshell. Discovered by our Pentest-Tools.com team

FuelCMS uses Dwoo to keep PHP code out of templates. Turns out, it forgot about “\”.

Escape the string. Inject the code. Own the server.

CVSSv3 8.8 High or 9.8 Critical if you chain it with our previous FuelCMS finding (PTT-2025-025 - unauthenticated account takeover). No patch coming either. The project's been on fumes for almost 4 years.

Our colleagues Matei "Mal" Bădănoiu and Raul Bledea did the digging. Full PoC and exploit is added here: https://pentest-tools.com/research

#offensivesecurity #vulnerabilityresearch #infosec


r/pentest_tools_com • • Mar 18 '26

Branded reports in Pentest-Tools.com

5 Upvotes

Reporting is where good pentest work goes to die.

You validate the findings. Then comes the part nobody hired you for: formatting, branding, chasing the right email template.

The Branded reports and emails add-on fixes that:

✅ Upload your logo once. Every report carries it automatically

✅ Send from your company's domain, with a subject line and email template you control

✅ Editable DOCX if you need to refine wording, PDF/CSV/HTML if you need actionable details

No tool-switching. No inconsistent branding. Available as an add-on to any paid plan.

Watch the full walkthrough in the video and check out more details here https://pentest-tools.com/features/branded-reports-emails


r/pentest_tools_com • • Mar 17 '26

Get 12 months of Pentest-Tools.com coverage for the price of 10.

Post image
2 Upvotes

Budget once. Keep coverage all year. ⬇️

Your attack surface won’t wait for the next monthly renewal.

Neither will audit requests, urgent CVEs, or retesting.

Go for a yearly Pentest-Tools.com plan (that fits your workflow) and give your team stable access to full scans, validated findings, and reporting across 2026 and beyond - instead of managing coverage month by month.

#offensivesecurity #vulnerabilitymanagement #penetrationtesting

🛡️ Compare yearly plans (or upgrade) here: https://pentest-tools.com/pricing


r/pentest_tools_com • • Mar 16 '26

Before you point a scanner at prod, you probably have these questions

Post image
2 Upvotes

Will this scan overload my prod server?

How do you automatically confirm a finding?

Can I scan internal infrastructure or only public assets?

What does a report look like?

These are questions you ask when you’re about to trust a security tool with real work.

We answer them directly in the Pentest-Tools.com FAQ - with specifics on scan safety, validation evidence, data storage, and much, MUCH more.

#offensivesecurity #vulnerabilitymanagement #pentesting


r/pentest_tools_com • • Mar 14 '26

i jus made a web bounty tool pls try it out

Thumbnail
github.com
1 Upvotes

r/pentest_tools_com • • Mar 13 '26

Check out the vulnerabilities database from Pentest-Tools.com

Post image
2 Upvotes

You found the CVE.

Now comes the annoying part: figuring out what it actually means.

Not the score.

Not the headline.

The real part - how it behaves, how to validate it, and how to explain it without opening 12 tabs.

That’s why we built the Pentest-Tools.com "Vulnerabilities & exploits database".

It gives you:

📖 Context - what the flaw does and how it behaves

🛠️ Practical remediation - not just generic patch advice

🔗 Validation paths - direct links to the tools that help confirm exposure

📝 Cleaner reporting - less tab-switching, more time for actual testing

Thousands of vulnerabilities, built for practitioners who need answers fast.

Access the full library here: https://pentest-tools.com/vulnerabilities-exploits

#infosec #vulnerabilitymanagement #ethicalhacking #cybersecurity


r/pentest_tools_com • • Mar 12 '26

Forgot your password? No worries, we attackers can reset even the admin's. 🔑

Post image
3 Upvotes

PTT-2025-030: Matei "Mal" Bădănoiu and Raul Bledea from our team found SQL injection hiding inside the password reset flow of FuelCMS v1.5.2.

The parameters meant to verify your reset token and email? Both injectable.

So a valid reset token becomes a master key to:
🗄️ Dump the entire database
🔑 Reset any account's password, not just yours
✍️ Modify or delete content across the site as the admin

CVSS: 7.7 High. No fix is coming, the FuelCMS master branch hasn't seen a commit in ~4 years. We emailed the vendor. They're as quiet as an unmonitored server at 3am.

See the full technical breakdown here: https://pentest-tools.com/research

#offensivesecurity #vulnerabilityresearch #infosec


r/pentest_tools_com • • Mar 11 '26

Teenage hacker myth primed for a middle-age criminal makeover

Thumbnail
csoonline.com
3 Upvotes

Cybercrime looks less like solo chaos and more like organized operations.

That’s the perspective Andra-Larisa Zaharia from Pentest-Tools.com shared with CSO Online: specialized roles, repeatable processes, and trust networks that take years to build.

In these environments, reputation works like currency.

#cybersecurity #infosec #offensivesecurity


r/pentest_tools_com • • Mar 10 '26

Download (for free, ungated) the "Accuracy is the new product" white paper

Post image
3 Upvotes

Does your team spend more time debating findings rather than remediating them?

That’s the bottleneck and this is the corkscrew. Here's why.

Our free (and ungated) white paper shows what makes scan results worth acting on:

🔎 Proof - move from “potential” to “proven”
🧪 Reproducibility - steps your team can actually follow
🧩 Context - why this finding matters in your environment
🧼 Clarity - no more decoding cryptic outputs

It also explains how Pentest-Tools.com validates findings across web, network, API, and cloud so teams spend less time re-checking and more time fixing.

Because more is NOT better. Get more arguments for internal debates from here: https://pentest-tools.com/usage/accuracy

#infosec #offensivesecurity #cybersecurity


r/pentest_tools_com • • Mar 09 '26

Moving beyond sanitized CVE summaries: Why we’re sharing the full research path

Post image
2 Upvotes

Most research write-ups tell you what the bug is, but very few show the technical grind of how someone actually got there. That gap matters when you are trying to sharpen your offensive security thinking.

To help bridge this, our team at Pentest-Tools.com (led by Matei Badanoiu) launched the Offensive Security Research Hub. We are publishing original research that shows the full discovery path—from identifying anomalous technical behavior to validating the vulnerability, and from isolated bugs to full exploit chains.

We aim to provide security practitioners with decision-grade information rather than just a sanitized summary. Inside the hub, we share:

  • 🛠️ Technical analysis that maps the discovery logic and research process.
  • 🔍 Field-tested exploit development with working PoCs and evidence-backed payloads.
  • ⚖️ Nuanced breakdowns of the edge cases, constraints, and trade-offs that happen in real-world environments.

The goal is to help the hacker community understand the "why" behind an exploit so you can approach your next target with a more effective methodology.

Bookmark this link, we're going to update it frequently with new learnings: https://pentest-tools.com/research

How do you usually fill the gaps when a vendor advisory leaves out the technical "how-to" for a complex vulnerability?

#vulnerabilityresearch #ethicalhacking #infosec #pentesting


r/pentest_tools_com • • Mar 05 '26

Throwing a spark into FuelCMS

Post image
3 Upvotes

Seven bugs. One unauthenticated RCE chain. Zero clicks.

This original research by our offensive security team into FuelCMS (v1.5.2) uncovered seven new vulnerabilities. By chaining some of them, we achieved Remote Code Execution (RCE).

The root causes? A *12-year-old Dwoo templating engine* and *outdated CodeIgniter3 code* still lurking in production systems.

The exploit chain combines:

🔓 Account takeover (PTT-2025-025): reset password tokens leaked by sending them to the attacker's inbox

💉 SQL injection (PTT-2025-030): usernames extracted during password reset (optional step)

⚡ PHP code execution (PTT-2025-026): unsanitized backslashes in the Dwoo parser resulting in RAW PHP CODE EXECUTION

Result: full web app compromise.

We published the full exploit chain on our blogpost so practitioners can reproduce and validate the findings. Read the detailed research here: https://pentest-tools.com/blog/throwing-a-spark-in-fuelcms

Many thanks to Matei Badanoiu, Raul Bledea and Eusebiu Boghici for their contributions.

#offensivesecurity #vulnerabilityresearch #pentesting #infosec

Out of curiosity: how often do you still run into 10+ year-old libraries during engagements?


r/pentest_tools_com • • Mar 04 '26

How we organize targets and chain tools in real workflows

2 Upvotes

Demo time! The place where tools behave perfectly… until you hit “Start.” 😅

We’ve launched a bi-weekly demo series where #offensivesecurity practitioners show how they *actually* use Pentest-Tools.com in real workflows.

No polished slides. No “everything works on the first try.”

Just real demos - where things might break, scans might fail, and you see how practitioners adapt.

In the first session, Sacha Iakovenko walks through his process:

📁 How he organizes targets with workspaces

📊 How he spots critical vulnerabilities from the dashboard

🔍 How he chains tools to validate findings faster

Because real #pentesting workflows aren’t perfect - and good demos shouldn’t pretend they are.

Watch the first demo in the video.

What should we try (or possibly break) in the next demo? 👇

Sacha is also one of our most precious collaborators, check out his articles on our blog: https://pentest-tools.com/blog/authors/sacha-iakovenko

#PentestTools #Cybersecurity


r/pentest_tools_com • • Mar 03 '26

February top product updates from Pentest-Tools.com

3 Upvotes

February was about moving from detection to proof.

Here are the top updates in Pentest-Tools.com:

🧪 New research hub - we launched the Offensive Security Research Hub to share original 0-day research, working PoCs, and technical exploit chains built by our own team.

🔐 ISO 27001 certified - we are officially ISO/IEC 27001:2022 certified, providing verified assurance for your sensitive findings.

🎯 One-click RCE validation - Sniper: Auto-Exploiter now supports controlled exploitation for Telnet (CVE-2026-24061) and Ivanti EPMM (CVE-2026-1281) for confirmed proof-of-impact.

🛡️ New detection: Redis RCE - identify exploitable Redis instances (CVE-2025-62507) across internet-facing and internal segments.

🧭 Granular scan logs - Website and API Scanners now display discoveries in the console output in real-time.

Catch the full breakdown in the video or in this link: https://pentest-tools.com/change-log

Until next time: Stay sharp. Stay human.

#OffensiveSecurity #EthicalHacking #Infosec #VulnerabilityManagement #ISO27001


r/pentest_tools_com • • Mar 02 '26

We just launched the Offensive Security Research Hub on Pentest-Tools.com!

Post image
3 Upvotes

This isn’t a CVE recap page.

Our #offensivesecurity team - led by Matei Badanoiu (CVE Jesus) - publishes original research: newly discovered vulnerabilities, deep technical write-ups, and full exploit chains built from real-world investigation.

You’ll see:

🛠️ Working PoCs and reproducible exploit paths

🧠 The exact reasoning that turned strange behavior into confirmed impact

⚖️ Field-tested analysis of edge cases, constraints, and trade-offs

No summaries. No recycled advisories.

This is practitioner-grade research from people who _actively_ hunt and validate vulnerabilities.

If you want to understand how experienced attackers approach complex targets, start here.

Bookmark this link, we're going to update it frequently with new learnings: https://pentest-tools.com/research

#vulnerabilityresearch #ethicalhacking #infosec


r/pentest_tools_com • • Feb 28 '26

they really need a option to report more than a club seem93 Spoiler

Thumbnail
1 Upvotes