Pentest & Hacking Ético
8 stories from across the Canverly network in Pentest & Hacking Ético.
SQL Injection in Practice: Exploiting, Detecting and Mitigating in a Controlled Lab
Hands-on SQLi demo with sqlmap in your own lab, focused on defensive detection and parameterized fixes that actually hold up against product…
Web Pentesting From Scratch: Building a Safe Lab with DVWA, Juice Shop and Burp Suite
Hands-on guide to building an isolated web pentest lab with DVWA, Juice Shop and Burp Suite configured under clear legal and safety rules.
Exploring File Upload Vulnerabilities Without Breaking the Law
How to bypass upload validations in your own lab, map the bug classes, and harden webservers against RCE via malicious file.
SSRF Demystified: Exploiting Cloud Metadata in a Local AWS Lab
Ethical SSRF reproduction against IMDS using LocalStack, with real payloads, simulated credential theft and definitive mitigation via IMDSv2…
Red Team 101: How Pentests Differ from Real Adversarial Operations
A pentest is not a red team. Learn scope, ROE, objectives, and why ethical discipline defines whether an adversarial engagement actually del…
REST and GraphQL API Pentest: Technical Checklist for Legal Bug Bounty
Hands-on methodology for testing REST and GraphQL APIs in authorized programs, focused on IDOR, authentication bypass and malicious introspe…
Modern XSS: DOM, Stored and Reflected With Real Examples in a Test Lab
Three XSS flavors dissected in a sandbox with payloads, exploitation flow, and mitigations via strict CSP, Trusted Types and DOMPurify sanit…
Advanced Nmap: NSE Scripts for Internal Recon in a Simulated Corporate Lab
How to get real value out of NSE for authorized enumeration on simulated internal networks, with script examples, output parsing, and pentes…