Skip to content
Canverly
Sign in
Network category

Pentest & Hacking Ético

8 stories from across the Canverly network in Pentest & Hacking Ético.

Basilisk OffSec

SQL Injection in Practice: Exploiting, Detecting and Mitigating in a Controlled Lab

Hands-on SQLi demo with sqlmap in your own lab, focused on defensive detection and parameterized fixes that actually hold up against product…

Basilisk OffSec

Web Pentesting From Scratch: Building a Safe Lab with DVWA, Juice Shop and Burp Suite

Hands-on guide to building an isolated web pentest lab with DVWA, Juice Shop and Burp Suite configured under clear legal and safety rules.

Basilisk OffSec

Exploring File Upload Vulnerabilities Without Breaking the Law

How to bypass upload validations in your own lab, map the bug classes, and harden webservers against RCE via malicious file.

Basilisk OffSec

SSRF Demystified: Exploiting Cloud Metadata in a Local AWS Lab

Ethical SSRF reproduction against IMDS using LocalStack, with real payloads, simulated credential theft and definitive mitigation via IMDSv2…

Basilisk OffSec

Red Team 101: How Pentests Differ from Real Adversarial Operations

A pentest is not a red team. Learn scope, ROE, objectives, and why ethical discipline defines whether an adversarial engagement actually del…

Basilisk OffSec

REST and GraphQL API Pentest: Technical Checklist for Legal Bug Bounty

Hands-on methodology for testing REST and GraphQL APIs in authorized programs, focused on IDOR, authentication bypass and malicious introspe…

Basilisk OffSec

Modern XSS: DOM, Stored and Reflected With Real Examples in a Test Lab

Three XSS flavors dissected in a sandbox with payloads, exploitation flow, and mitigations via strict CSP, Trusted Types and DOMPurify sanit…

Basilisk OffSec

Advanced Nmap: NSE Scripts for Internal Recon in a Simulated Corporate Lab

How to get real value out of NSE for authorized enumeration on simulated internal networks, with script examples, output parsing, and pentes…