إنتقل إلى المحتوى الرئيسي

8 مقالات موسومة بـ "Pentest"

Tests d'intrusion, méthodologie, outils.

عرض كل الوسوم

AWS penetration testing: what you may test, and what gets you banned

· 8 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: AWS permits customer security testing of eight service categories — including EC2, RDS, Lambda, API Gateway and CloudFront — without prior approval, on resources you own. Denial of service, and anything touching another tenant or AWS's own infrastructure, remains forbidden and requires a separate process. Your customer's permission is still mandatory: AWS's policy is not authorisation to test somebody else's account.

Débuter en test d'intrusion en 2026 : le chemin réaliste, sans folklore

· 4 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Le test d'intrusion attire beaucoup, en partie pour de bonnes raisons — un métier utile, technique, bien payé — en partie pour de mauvaises, entretenues par les vidéos où quelqu'un « hacke le Pentagone » en trois minutes. Cet article donne un chemin réaliste pour devenir pentester junior en 2026, sans mythes ni raccourcis.

OWASP Top 10 en pratique : cinq erreurs qui compromettent une application web

· 4 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Le OWASP Top 10 est utile parce qu'il classe les erreurs, pas parce qu'il les invente. Voici les cinq erreurs qui reviennent dans presque toutes les missions de pentest web que nous menons — avec des requêtes réelles et le code qui les corrige. Aucune n'est neuve. Toutes sont encore là.

Where to practise hacking legally (and what will get you arrested)

· 8 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: practise on systems you own, on deliberately vulnerable machines in your own lab, on platforms built for it, or inside a bug bounty program's stated scope. Everything else — including a single scan of a company you do not have written permission to test — is a criminal offence in most countries, regardless of intent or damage.

What is Kali Linux, and should a beginner use it?

· 7 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: Kali Linux is a Debian-based distribution that ships around 600 preinstalled security tools. It is legal to download and use, it is excellent as a disposable testing machine, and it is a poor choice as your everyday operating system. Learn Linux on Ubuntu or Debian; run Kali in a virtual machine for the work.

How to become a penetration tester in 2026: the realistic path

· 8 دقائق قراءة
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: expect 12 to 24 months from zero. Learn networking, Linux, Windows and Active Directory, and Python first — then attack techniques. Most people are hired on demonstrated work: a home lab, a handful of documented engagements against legal targets, and one report a stranger can read. A degree is not required; the ability to write is.