← Intel
Oct 6, 2026 · HackerOnStreet

My three months in Pen testing: job tasks I was performing

I have been working in pen testing for a long time, where I was doing multiple tasks. Here is what I was doing, and you can be here My three months in Pen testing: job tasks I was performing I have been working in pen testing for a long

three monthsthree months penthreemonthspentestingjobtasksperformingportal
My three months in Pen testing: job tasks I was performing

I have been working in pen testing for a long time, where I was doing multiple tasks. Here is what I was doing, and you can be here


My three months in Pen testing: job tasks I was performing

I have been working in pen testing for a long time, where I was doing multiple tasks. Here is what I was doing, and you can be here

i was sitting, and my HR and other staff asked me to Share The information regarding my work. The Email WAS

1*q2CvvF9Who0BqByevqoKuA

1)1st Month Progress

  1. Word on Dialer install & reports: some directory issues were opened in the Vicidial report to the Lahore Server team.
  2. Found issue reports related to web applications, including Vicidial website check issues; opened files and reported back to the team. Found multiple issues in the official portal report.
  3. Collected all subdomains for dialers and scanned for bugs and open issue which can be identified by an ordinary person and lead to organization assert damages. each domains which was accessed on my ipadres scan assert scanning nad reported
  4. Proper Unauthorized Scanning based on available data at that time, also manually testing for XSS, SQL INJECTION IDOR’S Types of bugs.
  5. Api Testing: 50+ api endpoints for the *** portal using multiple methods; issues were timely reported to relevant teams after api. And reported an issue with JWT tokens(with a temporary JWT token, an attacker or any person can log in without a Google account).
  6. Find publicly exposed information on the internet, report back to teams, and also make sure that any other information is available and request its removal from the internet.

1) 2nd Month Progress

  1. API Testing: 50+ api endpoints for the *** portal using multiple methods; issues were timely reported to relevant teams after api. And reported an issue with JWT tokens(with a temporary JWT token, an attacker or anyone can log in without a Google account)
  2. All domains that get early access were set up for scanning and dark web monitoring.
  3. Start working on Dark web monitoring scanning. Daily-based scanning: this scanning is performed by self daily or every 3 days.
  4. Develop an attack surface management system for all of our subdomains that can collect all types of Logs Authorize and unauthorize file downloads from users. This allows us to collect logs from php related website including the dialer (IP address, IP details, etc.)

1) 3ed Month Progress

  1. In ending on my 3rd month I collaborate with some of developers who was managing php related all service we have been using science login provide after that i realize dev team Who are working on web portal related to php related stacks are lacking due to Some of plugins which they have been using science long time we got updated after updating portal nad checking for there update we have found many issue.
  2. Collect domain and their information: ***, ***, ***, and other websites.
  3. Dark web monitoring, including Telegram groups and resources like https://combolist.co/ that have publicly available data and can be harmful to us, is continuously under strict monitoring due to a lack of resources.
  4. In line with the Lahore team developers recently regarding apps that are using PHP Laravel or similar to this, in response I get we have handed over all to Asif Sir.
  5. Create a VPN for Deep Testing; it allows me to see network requests and request which are going to other places also, and we also need to shift to one Vpn where I can manage all logs and systems Internal Logs Which

Based on three months’ work record, I was performing the following.

Pentesting Dashboard / Flask Development, CVE Research and PoCs, Heartbleed Verification, JWT Security Testing, WHMCS / *** Auditing, ViciDial / Vicibox Setup and Troubleshooting, AIL Framework / Lacus Deployment, Redis / KVrocks Troubleshooting, Nmap / Nuclei / ProjectDiscovery Workflows, Network / Wi-Fi Traffic Monitoring, Apache / HTTP Security Log Analysis, SQL Injection Testing, XSS Testing, WordPress Vulnerability Testing, VPN / Linux Networking, SSH / Server Administration, Hosting / Server Capacity Planning, Bulk IP / ASM Scanning, Security Monitoring / SOC Pipeline Development, Linux / Python / Node.js Troubleshooting

ASM Tracking System

A) New feature: Centralized SOC Log Management (planned/proposed)

  • One place to collect logs from all openSUSE hosts (cross-version compatible)
  • Track file downloads by user + source IP
  • Detect tool usage from external sources
  • Nav tracking subsection: page views/clicks, ETag-based fingerprinting, client-side header collection, and detecting devtools/automated tool access (not literal command execution)

B) Testing/findings already done on Dialer360

  • Reviewed the “portal” section — found it exposes which tech stack is in use on the page route, which could help an attacker find public exploits later
  • Light security testing on the official website and client portal area
  • Did not test the live server/portal itself (caused an outage/service suspension + delays last time)
  • Dated note: Jun 2, 2026, 6:50 AM (PKT)
  • Recommendation: staging portals should be IP-restricted or .htaccess password-protected

Now The Big part comes:

I have completed 3 month lets see if they can make me permanent. Did I learn one thing

Answer: barely any. I just learned about Zabbix. Old companies, most of them are using Zabbix nad Promitious + Gerafana wHICH is sane.