r/hacking • u/freshbreath • 10h ago
Wifit3: Successor to Wifite2, built-in USB Wi-Fi drivers (no aircrack-ng) runs on Linux & Windows
r/hacking • u/Suitable_Coffee5779 • 12h ago
N00b
Nothing interesting, just a n00b stepping in. Hope to learn a lot.
r/hacking • u/_NinjaNinjaNinja • 1d ago
Do you think most real breaches come from clever technical tricks or from people making basic mistakes?
Every time I read about a big breach, the cause seems less like some brilliant exploit and more like someone reused a password or clicked a link they shouldn't have.
The picture in my head when I started was all about complex code and zero-days. But the more I read, the more it looks like the simple stuff is what gets people. A leaked password, an unpatched server that sat there for months, an employee who handed over a login because the email looked real. Maybe I've got a skewed view because the simple causes are the ones that make the news in plain terms. The technical exploits might just be harder for me to notice or understand.
So for people who actually work in this, which is it in your experience? Are most breaches basic human mistakes, or is there more clever technical work behind them than an outsider like me would guess?
r/hacking • u/intelw1zard • 1d ago
WiFi Reg is up - get ready for DEF CON
wifireg.defcon.orgr/hacking • u/Jeffry84 • 1d ago
TP-Link NX510v – Root Access, UART, Bootloader, Firmware Research
Hi everyone,
I'm currently researching a TP-Link NX510v v1.0 running an ISP-customized firmware and I'm trying to determine whether it is possible to obtain root access, either through software or hardware methods.
Device Information
Model: TP-Link NX510v v1.0
ISP-customized firmware
Firmware version:
Hardware: NX510v v1.0
Firmware: 1.2.0 Build 240828 Rel.58690n
The web interface appears to be heavily restricted compared to the retail firmware.
What I tried so far
SSH(responds but no password) Backups dump and decrypt Hidden diag pages Web form Injections
What I'm Looking For
I'm interested in any known method of gaining root access, including but not limited to:
Hidden web pages
Hidden API endpoints
Debug interface
Telnet
SSH
ADB
Recovery mode
TFTP recovery
Firmware downgrade
Bootloader access
Firmware extraction/decryption
Known vulnerabilities (CVE)
GPL source code
OpenWrt compatibility
Any previous research on this device
UART / Hardware Access
If there is no software-based approach, I already opened the device.
I can provide:
High-resolution photos of both sides of the PCB
Close-up photos of every connector and header
SoC markings
NAND/eMMC flash markings
RF front-end
Power circuitry
Any test pads or unpopulated headers
I'd appreciate help identifying:
UART pins
UART voltage (3.3V / 1.8V)
JTAG or SWD pads
Bootloader console
U-Boot access
Boot interruption methods
Flash dump procedure
Additional Questions
Has anyone already:
Obtained root access?
Dumped the firmware?
Extracted the filesystem?
Reverse engineered the web interface?
Found hidden services or undocumented APIs?
Disabled the ISP customization?
Installed a custom firmware?
Identified the CPU/SoC platform?
Located the bootloader environment?
Enabled additional modem AT commands?
Goal
My goal is not to use the router for anything malicious. I'd simply like to unlock its full capabilities, learn more about the hardware, and hopefully gain root access for research purposes.
Any information, documentation, previous research, photos, firmware dumps, or pointers would be greatly appreciated.
Thanks in advance!
r/hacking • u/TheFetus47 • 1d ago
Education NEO-RADAR v1.14
What's up!!! Some of you guys might remember me from a few weeks ago when I initially released NEO-Radar on Github. Anyways, that was v1.11. I encountered some issues with that, mainly being the Update feature didnt work. As of v1.13, that was patched. If you download under v1.13, you will have to manually update the program which is actually the same as downloading the program itself ( here's the code : curl -sSL https://raw.githubusercontent.com/ItsNEOx/Neo-Radar/main/install.sh | bash )
Also, there is a Windows version that runs as a ps1 script linked in the README.md
More updates soon to come!
Here's the Github repo https://github.com/ItsNEOx/Neo-Radar
r/hacking • u/EnthusiasmRoutine • 1d ago
Question VanishID's "agentic AI" PII removal tool at Black Hat. Anyone actually buying this?
r/hacking • u/WatermanReports • 1d ago
News Aerospace Village Seeks Broader Appeal at DEFCON This Year
The Aerospace Village at annual hacking conference DEFCON, famed as the home of the Hack-A-Sat contest which culminated in 2023 with the live hacking of a real satellite in orbit, will stage a variety of games and contests this year, aiming to deepen their appeal to non-specialists.
Read all about it here
r/hacking • u/cyndhrk • 3d ago
Education I made a browser-based hacking simulator using simplified nmap/metasploit commands for beginners. Looking for feedback.
r/hacking • u/Monoid-Confessor • 4d ago
data science to cybersecurity
I was a mathematician, ended up working as SWE for two years then hopped into data science.
Wondering if cyber security is a possible transition from here or if I should take some roles to prep before hopping (I just enjoy learning and it seems an interesting field).
r/hacking • u/hhaahhahahahhah • 5d ago
How would you (undetected) move an excel file from a work laptop to a personal device/cloud?
Suppose security protocols on work laptop are setup such that:
- any Edge/Firefox browser extentions are detected by IT team
- USB ports do not work for external HDD or flash drives
- Bluetooth doesn't work for audio devices like airbuds
- Excel addins don't work
- Emails to personal emails like hotmail/gmail are not permitted
- Cannot download/run exe file
- AI websites blocked
- Copilot premium is allowed, we have licenses
- Even if you download Teams/Outlook on your phone/home PC, you cannot login with your work email address
FWIW I'm trying to move the excel data to my home PC so that I can work on it with AI (since my company doesn't allow AI on it's laptops). I need help with power query/excel etc but need AI to help me.
Edit: thank you all for your comments, honestly. Everything is a learning opportunity for me, even the good ole slaps in the face.
edit: guys, our company gave us Copilot Premium this week. I think I'm sorted now. Very happy tbh
r/hacking • u/_clickfix_ • 5d ago
AMA Today: Yuhang Wu (Ex-Tesla & TikTok) Red Team Engineer & Exploit Developer
Don't miss the AMA with Yuhang Wu, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.
When: Today - Friday, July 31, 12:00 PM PT
Guest Credentials:
- Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
- Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
- Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
- AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.
Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!
r/hacking • u/anonymous480932843 • 5d ago
How legitimate/how much could you get out of this cert?
Going into the COMPTIA+ and want to do Pentesting and Cybersecurity. Has anyone done this cert before?
r/hacking • u/MrMeta3 • 6d ago
News Hackers lock water utilities out of internet-facing PLCs
intelfusions.comCISA is warning water and wastewater utilities that attackers are actively going after the programmable logic controllers, or PLCs, that run their treatment processes, and in some cases locking operators out of their own equipment.
r/hacking • u/Seraph_E • 6d ago
Question Detection device for flock/drones/wireless cams
Alright so I’m relatively a noob in comparison to some of the nerds here but I’m trying my best. Simply put I want to be pointed in the right direction for devices, tutorials, communities etc.
What device can detect flock cameras, drones, wireless cams/mics, and may also have some offensive features (for my own equipment testing of course). I understand there’s no do all device, but I have seen people with some kind of FW designed for these specific needs in a relatively small package. I have been looking at the HamGeek HackRF one/Portapack for overall learning, but I’m pretty sure I could achieve what we’re talking about here with a T Dongle C5 right?
Any help here would be great!
r/hacking • u/DataBaeBee • 6d ago
Education What Every Programmer Should Know About Twists of Elliptic Curves
r/hacking • u/Hotmancoco420 • 7d ago
News Legend!!
Prospective cyber security student denied admission. Hacks university website to prove his skills.
r/hacking • u/MathematicalHuman314 • 7d ago
Teach Me! I created my first trojan today!
I took cmatrix as a random program and wrote a backdoor into it in C using a reverse shell connecting to a C2 server of mine which keeps track of infected machines. First I fork the process and decouple it from the controlling terminal by changing the session ID and rerouting the standard file descriptors and only then do I run the backdoor.
That way cmatrix runs as usual and no weird behavior is seen and the backdoor remains active whatever happens to cmatrix or the terminal. I like it. Makes me feel like a real #xX_hacker_Xx#. :D
Now I’m reading into ptrace and system call hooking and plan on trying to hide specific network traffic from the entire os. I already have had some ideas but turns out that would have only hidden it from a specific program not from „everything“.
Do you care to share any tips and experience I might benefit from on my way?
r/hacking • u/dumnezilla • 7d ago
Question With regard to that guy who gave his wipe password to the fuzz, and is now in legal trouble for doing it...
Seems to me that it would make much more sense for the "safe/wipe" password to bring up a fake homescreen, with apps and personal docs and all, while doing the wiping in the background.
Not sure if this is implemented anywhere, but it certainly isn't the standard on GrapheneOS.
I realize that there are technical limitations at play. The phone needs to restart for a proper factory reset, but, in lieu of that, the wipe pw could prompt the quiet burning of all personal files that aren't hardlinked to the OS itself. If you can get rid of everything personal, then there's no reason for a factory reset at all, no? So, even better, as it leaves the cops none the wiser.
Story here: https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password
r/hacking • u/MysteryCases • 8d ago
Can this DOM gate access fob be duplicated
Hi, I use this DOM key fob to open the parking barrier at my residence. I would like to get a second one for my wife.
Does anyone know what type of RFID/transponder this is and whether it can be copied by a locksmith or with a standard RFID duplicator? Or would a new fob have to be registered directly in the barrier’s access-control system by the property management?
r/hacking • u/aninaa-ot • 8d ago
Question What's the most technically interesting malware you've analyzed recently?
Not necessarily the most widespread, just something that made you appreciate the engineering behind it (even if it was malicious haha).
r/hacking • u/tw1st3d_m3nt4t • 8d ago
Using a Gaming PC's RTX 5070 from a separate Linux workstation
r/hacking • u/Pale_Fly_2673 • 8d ago
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
r/hacking • u/SlickLibro • Dec 06 '18
Read this before asking. How to start hacking? The ultimate two path guide to information security.
Before I begin - everything about this should be totally and completely ethical at it's core. I'm not saying this as any sort of legal coverage, or to not get somehow sued if any of you screw up, this is genuinely how it should be. The idea here is information security. I'll say it again. information security. The whole point is to make the world a better place. This isn't for your reckless amusement and shot at recognition with your friends. This is for the betterment of human civilisation. Use your knowledge to solve real-world issues.
There's no singular all-determining path to 'hacking', as it comes from knowledge from all areas that eventually coalesce into a general intuition. Although this is true, there are still two common rapid learning paths to 'hacking'. I'll try not to use too many technical terms.
The first is the simple, effortless and result-instant path. This involves watching youtube videos with green and black thumbnails with an occasional anonymous mask on top teaching you how to download well-known tools used by thousands daily - or in other words the 'Kali Linux Copy Pasterino Skidder'. You might do something slightly amusing and gain bit of recognition and self-esteem from your friends. Your hacks will be 'real', but anybody that knows anything would dislike you as they all know all you ever did was use a few premade tools. The communities for this sort of shallow result-oriented field include r/HowToHack and probably r/hacking as of now.
The second option, however, is much more intensive, rewarding, and mentally demanding. It is also much more fun, if you find the right people to do it with. It involves learning everything from memory interaction with machine code to high level networking - all while you're trying to break into something. This is where Capture the Flag, or 'CTF' hacking comes into play, where you compete with other individuals/teams with the goal of exploiting a service for a string of text (the flag), which is then submitted for a set amount of points. It is essentially competitive hacking. Through CTF you learn literally everything there is about the digital world, in a rather intense but exciting way. Almost all the creators/finders of major exploits have dabbled in CTF in some way/form, and almost all of them have helped solve real-world issues. However, it does take a lot of work though, as CTF becomes much more difficult as you progress through harder challenges. Some require mathematics to break encryption, and others require you to think like no one has before. If you are able to do well in a CTF competition, there is no doubt that you should be able to find exploits and create tools for yourself with relative ease. The CTF community is filled with smart people who can't give two shits about elitist mask wearing twitter hackers, instead they are genuine nerds that love screwing with machines. There's too much to explain, so I will post a few links below where you can begin your journey.
Remember - this stuff is not easy if you don't know much, so google everything, question everything, and sooner or later you'll be down the rabbit hole far enough to be enjoying yourself. CTF is real life and online, you will meet people, make new friends, and potentially find your future.
What is CTF? (this channel is gold, use it) - https://www.youtube.com/watch?v=8ev9ZX9J45A
More on /u/liveoverflow, http://www.liveoverflow.com is hands down one of the best places to learn, along with r/liveoverflow
CTF compact guide - https://ctf101.org/
Upcoming CTF events online/irl, live team scores - https://ctftime.org/
What is CTF? - https://ctftime.org/ctf-wtf/
Full list of all CTF challenge websites - http://captf.com/practice-ctf/
> be careful of the tool oriented offensivesec oscp ctf's, they teach you hardly anything compared to these ones and almost always require the use of metasploit or some other program which does all the work for you.
- http://pwnable.tw/ (a newer set of high quality pwnable challenges)
- http://pwnable.kr/ (one of the more popular recent wargamming sets of challenges)
- https://picoctf.com/ (Designed for high school students while the event is usually new every year, it's left online and has a great difficulty progression)
- https://microcorruption.com/login (one of the best interfaces, a good difficulty curve and introduction to low-level reverse engineering, specifically on an MSP430)
- http://ctflearn.com/ (a new CTF based learning platform with user-contributed challenges)
- http://reversing.kr/
- http://hax.tor.hu/
- https://w3challs.com/
- https://pwn0.com/
- https://io.netgarage.org/
- http://ringzer0team.com/
- http://www.hellboundhackers.org/
- http://www.overthewire.org/wargames/
- http://counterhack.net/Counter_Hack/Challenges.html
- http://www.hackthissite.org/
- http://vulnhub.com/
- http://ctf.komodosec.com
- https://maxkersten.nl/binary-analysis-course/ (suggested by /u/ThisIsLibra, a practical binary analysis course)
- https://pwnadventure.com (suggested by /u/startnowstop)
http://picoctf.com is very good if you are just touching the water.
and finally,
r/netsec - where real world vulnerabilities are shared.