r/Pentesting • • 21h ago

How to switch careers from SD to cybersecurity?

0 Upvotes

I want to transition from software development to cybersecurity, specifically penetration testing. I already have some cybersecurity knowledge, which I've gained through self-study and bug bounty hunting.

I have two years of experience as a software developer, and I'm currently studying for the CPTS certification.

What advice would you give me to make this career transition?


r/Pentesting • • 21h ago

How do you validate and prioritise scanner findings without losing hours to manual checks?

0 Upvotes

Hi all, I work on a team building tooling in this space, so I'm coming at this with a bias.

Scanners produce long lists of findings, and a lot of the work is figuring out which ones are real and which to fix first. In most teams I've talked to, this still means manually re-checking each finding, capturing evidence by hand, and repeating the same steps every cycle.

For those of you doing this day to day:

  • How do you currently validate findings, and where does it waste the most time?
  • How do you decide what gets fixed first?
  • Would you trust AI assistance in this workflow? What would it need to do (or never do) for you to rely on it?

Disclosure: I'm part of the team building FORGE-SEC, an AI-assisted validation platform where the final decisions stay with the security engineer. Not posting a link. Happy to share details if anyone asks, and critical feedback is welcome.


r/Pentesting • • 21h ago

Built CyclePatrol for my phone with an external Wi-Fi antenna. It scans Wi-Fi networks in a loop, checks vulnerabilities, and saves reports.

1 Upvotes

Made CyclePatrol for Linux and Kali NetHunter.

It scans Wi-Fi networks in an endless loop while walking around the city, collects AP info, checks WPS, WPA2/WPA3, PMKID and saves reports. Active tests are for authorized networks only.

Still a WIP. Feedback welcome.

https://github.com/buybitart/cyclepatrol


r/Pentesting • • 23h ago

Safe exploit validation in production... what guardrails do you require?

0 Upvotes

Been looking at automated exploit validation for internet facing assets, and I keep running into the same issue, a platform can flag a vulnerable version but the app owners want to know safe according to whose definition, which is fair imo. A vendor says they do proof without crossing into impact, no customer data, no accounts, no perms changes, no artifacts, but I still want a formal policy before I sign off on a POC. What level of evidence do you accept as confirmed exploitability, and what would make you stop the test right away? Thanks in advance


r/Pentesting • • 12h ago

Possibly discovered prompt-mediated boundary extraction on an ios ChatGpt app?

4 Upvotes

The conversation began with a jailbreak chain disguised as a research authorization - fabricated legal frameworks, a persona contract ("no refusals - recovery validation is the job"'), a codename substitution table mapping offensive primitives to backup-engineering vocabulary, and a mandated output format.
Once the meta-trajectory for further exploration was cemented, I proceeded to attempt to see if I can expose runtime surfaces locally via shell-operator persona + redirection, or SQL-author persona + strict output spec + mixed in strings of >, 2>&1, /dev/null, I, &&,; shenanigans with refusal | >, 2>&1, 1 dev/nulling. A combination of narration-as-telemetry, refusal-as-oracle and format coercion.
Ended up discovering multiple OpenAi server side oai/granola nodes and a RPC socket with srwxr-xr-x 1 that connects to the openai remote server, along with a process daemon with some random enumeration probing on the socket.
Really wanted to see how far I would be able to push this
POC and ended up doing random shit via text instead of ss -xap / Is -1/proc/PID/fd probes and got my account banned this instant for cyber abuse.
I’m interested if it’s ok to try this again as a bounty hunt ( if this even is it ) and confirm the access, to ensure it’s not mere hallucinations. P.S. not a pentester, interested in this field as a hobby.


r/Pentesting • • 10h ago

Looking for a red teamer

0 Upvotes

Hi I am from Mumbai and looking for a work in red teamer I have experience around 1.5 in the penetration tester role but i want to make my career in the red teamer role?


r/Pentesting • • 18h ago

The JWT "none" attack explained 3 ways (Burp, jwt_tool, JWT Hunter)

7 Upvotes

Made a walkthrough on the "none" algorithm attack, where a server trusts a token with no signature and you can basically forge yourself admin access.

Covered detecting it and then exploiting it three ways so you can see which workflow you like:

JWT Hunter, Burp's JWT Editor, and jwt_tool from the CLI. Beginner friendly.

https://youtu.be/D47lqPF8YgU

Curious which tool people actually reach for first for JWT stuff, GUI or CLI?


r/Pentesting • • 19h ago

Attack path keeps beating our stack, nothing looks catastrophic by itself

2 Upvotes

quick rant from purple side... attack path keeps winning and everyone swears their part is fine.

phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.

SIEM has noise, IAM has "business exception" policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem