Testing Lab
Resources Blog

Testing Lab

Keep up to date with the latest offensive security news, knowledge, and resources.
The Human Touch in the Era of AI: Why Pentesting Still Needs a Human in the Loop

The Human Touch in the Era of AI: Why Pentesting Still Needs a Human in the Loop

AI accelerates pentesting but human judgement close the gap. See how two real engagements turned quiet banners and a single timestamp into critical findings.
Cracking NTLMv1 SSP With Rainbow Tables

Cracking NTLMv1 SSP With Rainbow Tables

Step-by-step walkthrough of cracking NTLMv1-SSP hashes with rainbow tables, including how to coerce auth, disable ESS, recover NT hashes, and remediate.
Vulnerability Hunting a Retired App Part 2 - From File Write to SYSTEM

Vulnerability Hunting a Retired App Part 2 - From File Write to SYSTEM

Discover how an unsanitized file write endpoint in Omega Enterprise Gateway escalates to SYSTEM-level code execution and what dead code reveals about real-world security bugs.
Context Is The Attack Surface

Context Is The Attack Surface

A successful prompt hack looks like your system working correctly for someone else. The mechanism that makes this possible is the same one you’re paying for.
Axios Got Backdoored Through a Trusted Account. Your CI/CD Pipeline Has the Same Problem.

Axios Got Backdoored Through a Trusted Account. Your CI/CD Pipeline Has the Same Problem.

The Axios supply chain attack exposed why dependency scanning fails against credential compromise. Learn how attackers backdoor popular packages and what your penetration tests are missing.
Popping Printers: How Your MFPs Are Handing Attackers Domain Admin

Popping Printers: How Your MFPs Are Handing Attackers Domain Admin

Multifunction printers silently store domain credentials, expose unauthenticated management interfaces, and sit on flat networks. Learn how attackers exploit MFPs to achieve domain admin in minutes.
1 2 3 4 5