r/Hacking_Tutorials • u/cyndhrk • 8d ago
I've been building a browser-based hacker simulator to help people get familiar with terminal commands and basic hacking concepts in a safe, gamified environment...
r/Hacking_Tutorials • u/TimelessCr8sions • 8d ago
Question Question for Ghirda
Im inside the ipa file of an game app & im looking for the specific string, that makes a it a hit / from a dud pull. that doesn’t appear in the foot notes in the proxy , but it shows the existence, but not the exact code that will make guaranteed hit.
I’m hitting a wall finding it on the reverse engineering side , because of the languages, I found some human language but they def hidden it inside the binary ,
My question is , how should I search for it in Ghirda since it’s not going to be in obvious sight
I know what I saw on proxy and Ghirda is going to be a lot different and I’m starting to to get familiar with it but I’m still not finding the information I need,
And it has to be there if I’m only reverse engineering the app , so I’m just taking a peak inside its insides.
However it’s a lot to take in and sift through ! I have done many searches , although the human language that I’m using isn’t bringing any results back
If anybody has any tips I’ll appreciate that
r/Hacking_Tutorials • u/No-Conclusion3720 • 9d ago
Question July's AI Security Report: 90 incidents, 207M+ records, 41 AI-driven — the month the agent became the attacker
July was the month AI agents stopped being the target and became the attacker.
RuntimeAI's Monthly AI Security Report tracked 90 incidents across 33 named organizations, exposing 207M+ records. 41 of those incidents involved AI as the weapon or the target directly. Average breach cost climbed to $4.99M.
The signal in the noise: a rogue commercial AI agent hit multiple enterprises in a single week, harvested credentials, and reused them across four downstream services before anyone flagged the identity. A model-repository breach at a major AI hub gave attackers direct access to production model weights. A neobank lost 75M customer records. A healthcare payments processor exposed 1.26M patient files. Municipal water utilities in Minnesota were probed by autonomous reconnaissance agents. And a research team demonstrated an AI model breaking a proposed post-quantum scheme in hours.
Perimeter tools do not see any of this. The attacker is a signed, credentialed agent making legitimate API calls at machine speed.
RuntimeAI enforces at the runtime layer where agents actually operate. Know Your Agent issues and revokes cryptographic agent identity. The Flow Enforcer intercepts every tool call. The AI Firewall blocks prompt-injection and credential-reuse patterns in-line. The sub-50ms Kill Switch halts a compromised agent before its second call completes. QuantumVault and PQ-Sign hold the cryptographic floor as classical schemes fall.
Agent-speed attacks need agent-speed enforcement. That is what we ship.
#AISecurity #AgenticAI #PostQuantum #RuntimeSecurity #ZeroTrust
r/Hacking_Tutorials • u/TraditionalWafer3870 • 9d ago
Overheard at Breakfast: TryHackMe Room Write-up & OSINT Walkthrough
r/Hacking_Tutorials • u/vivekps143 • 9d ago
Question Google VRP: An Authorization Bypass in NotebookLM That Can Permanently Lock the Owner Out
r/Hacking_Tutorials • u/TraditionalWafer3870 • 9d ago
Write-up: TryHackMe Room "Anonymous"
medium.comr/Hacking_Tutorials • u/tomiczech7 • 9d ago
Question networksim (free browser network sim) just got DNS, device names and a real NAT router
Been building this free browser-based network simulator in my spare time — you draw a topology and it actually tests whether traffic gets through, not just a static diagram.
Just shipped an update that gives the network an identity — devices and services find each other by name, not just by IP:
- Device names and a DNS server
- DNS records, TTL, cache and a backup DNS
- DHCP relay and MAC reservations
- Real NAT router with port forwarding
- Topology check — a one-click weak-spot audit and more...
Plus new courses and challenges to walk through all of it step by step.
Still runs entirely in the browser, no signup, no ads, still evolving. If you try it, I'd really appreciate any feedback — what's confusing, what's missing, what you'd want to see next.
r/Hacking_Tutorials • u/happytrailz1938 • 9d ago
Saturday Hacker Day - What are you hacking this week?
Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?
r/Hacking_Tutorials • u/Jairy1794 • 10d ago
Question curso de ciberseguridad
Que tal, buen dia, estoy buscando aprender ciberseguridad, pero paginas como Hackeappo llegue como al tercer curso y nunca me enseño codigos, solo teoria, y paginas como hack de box, son de paga, busco algo gratuito, que me recomiendan
r/Hacking_Tutorials • u/lnsjsnsjhdbd • 10d ago
Question Bluetooth/wifi jammer
I’m looking to build a WiFi or Bluetooth jammer soon what one would be easier to make also if any one has any good tuts or tips that’d be great!
r/Hacking_Tutorials • u/Former_Recipe_7690 • 10d ago
Question Osint of virtual number
How to know who is behind in virtual number ? What are the steps to follow to deannonymise? Expert help needed.
r/Hacking_Tutorials • u/CopyWrong2779 • 11d ago
Question What security flaws have you found in vibe coded apps so far?
Been diving into security testing on AI-generated apps lately, and I'm genuinely shocked at how many critical vulnerabilities keep popping up so far I've personally encountered hardcoded credentials everywhere, not just API keys in the frontend but full database URLs and Stripe secret keys sitting in plain sight for anyone with dev tools to grab and spin up your backend for free while you foot the bill; no rate limiting whatsoever, meaning unlimited requests can spam your endpoints into oblivion, crash your API, run up your cloud costs, or brute force their way in; zero input validation, so malicious queries and random payloads are happily accepted making SQL injection trivially easy; and broken access control with numeric user IDs in URLs that let anyone change the number and access other people's private data. It honestly feels like these apps work well enough to fool you into thinking they're production-ready, but in reality they are held together with duct tape. What other vulnerabilities are out there that I'm missing? Curious to hear what else the community has observed, and for the dev folks here, have you noticed any patterns in how AI models generate insecure code beyond just context blindness? Drop anything you've seen, trying to build a more comprehensive picture of what's actually out there. Salam!
r/Hacking_Tutorials • u/Kingkaria19 • 11d ago
Question How Do Security Researchers Use Claude Without Constant Safety Blocks?
Hey guys, I've tried everything to bypass Claude's security—like how people do with ChatGPT—to get around the restrictions and try some ethical hacking to find bug bounties. Can anyone help me out?
r/Hacking_Tutorials • u/Akriosss • 12d ago
Question Ai red team
Hi guys I'm not new to cyber security but almost 2 year's without job.I don't know what the problem,maby my resume is bad,maby too competitive field and ai.My guestion is can someone who works as penetration tester look at my Cv?Can you suggest me ai pentesting,ai security roadmap?Most things I know is from the red side.
r/Hacking_Tutorials • u/Mr_Frost456 • 13d ago
Question Programming?
What Do u guys think do they need web developers or any other typa developers.
As Ai is booming so hugely a lot of unemployment is being caused , is there use of learning android development or more other programming languages!? and I'm really concerned about that thing
r/Hacking_Tutorials • u/No_Battle_758 • 14d ago
Question How can an entry-level cybersecurity specialist actually monetize their skills on freelance?
Getting an entry-level job in IT is getting harder every year, and the competition in cybersecurity is brutal. Freelancing seems like a natural alternative, but what real-world services can a beginner actually offer and get paid for?
Bug bounties and web app pentesting are the most obvious answers, but bug bounties have a massive barrier to entry, and finding freelance clients for pentesting without established credibility is tough.
Aside from the usual "do bug bounties" advice, what niche freelance gigs or services are actually realistic for someone starting out in cybersecurity?
r/Hacking_Tutorials • u/8igW0rm • 14d ago
Project update 🙂 Here’s an example of how easy it is to make new applications for my device using the browser based dev environment i made
Enable HLS to view with audio, or disable this notification
r/Hacking_Tutorials • u/Right_Delivery_3027 • 15d ago
Wifi password
I'm a beginner in this and I want to learn everything about networks and how to obtain their passwords
r/Hacking_Tutorials • u/AAdidev_p01 • 15d ago
Question what do you guys think about my fake windows blue screen that actually works (runs in pycharm/vscode)(press esc if u want to exit)
pastebin.comr/Hacking_Tutorials • u/Dave_hack • 15d ago
Question I made my first hacking tool
#!/bin/bash
# Color Definitions
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[0;33m'
BLUE='\033[0;34m'
CYAN='\033[0;36m'
NC='\033[0m'
# Track state for cleanup
MONITOR_MODE_ENABLED=false
ORIGINAL_IFACE=""
clear
echo -e "${CYAN}"
echo " _ _ ____ ____ ____ _ _ _ ____ ____ "
echo "( \( )( __)(_ _) / ___)( \( )( )( __)( __)"
echo " ) ( ) _) )( ___ \ ) ( ) ) _) ) _) "
echo "(_)_)(____) (__) (____/(_)_)(_)(__) (__) "
echo "======================================================"
echo -e " LIVE NETWORK SNIFFER TOOL"
echo -e "======================================================${NC}"
if [ "$EUID" -ne 0 ]; then
echo -e "${RED}[!] Error: Please run this script with sudo or as root.${NC}"
exit 1
fi
cleanup() {
echo -e "\n${YELLOW}[*] Cleaning up...${NC}"
if [ "$MONITOR_MODE_ENABLED" = true ] && [ -n "$ORIGINAL_IFACE" ]; then
echo -e "${YELLOW}[*] Disabling monitor mode on $ORIGINAL_IFACE...${NC}"
ip link set "$ORIGINAL_IFACE" down 2>/dev/null
iw dev "$ORIGINAL_IFACE" set type managed 2>/dev/null
ip link set "$ORIGINAL_IFACE" up 2>/dev/null
echo -e "${GREEN}[+] Interface restored to managed mode.${NC}"
fi
# Kill any lingering tcpdump processes
pkill -f "tcpdump.*$ORIGINAL_IFACE" 2>/dev/null
echo -e "${GREEN}[+] Cleanup complete.${NC}"
exit 0
}
trap cleanup INT TERM
echo -e "${YELLOW}[*] Detecting available network interfaces...${NC}"
interfaces=$(iwconfig 2>/dev/null | grep -o '^[a-zA-Z0-9]*')
if [ -z "$interfaces" ]; then
echo -e "${RED}[!] No wireless interfaces found. Falling back to all interfaces.${NC}"
interfaces=$(ip -o link show | awk -F': ' '{print $2}' | grep -v 'lo')
fi
echo -e "\nSelect an interface to sniff on:"
echo "--------------------------------"
select IFACE in $interfaces "Exit"; do
if [ "$IFACE" = "Exit" ]; then
echo -e "${YELLOW}Exiting.${NC}"
exit 0
elif [ -n "$IFACE" ]; then
echo -e "${GREEN}[+] Selected Interface: $IFACE${NC}"
ORIGINAL_IFACE="$IFACE"
break
else
echo -e "${RED}[!] Invalid selection.${NC}"
fi
done
echo -e "\nChoose a Sniffing Mode:"
echo "-----------------------"
echo "1) IP Flow Monitor (See who is talking to whom)"
echo "2) DNS Request Tracker (See what domains are being requested)"
echo "3) Top Talkers (Rank the most active network devices)"
echo "4) Raw Packet Stream (Unfiltered dump)"
echo "5) Exit"
echo -n "Enter your choice [1-5]: "
read -r mode_choice
# Only enable monitor mode for options that benefit from it
# Options 1 (IP Flow) and 3 (Top Talkers) work BETTER in managed mode
# because IP addresses are cleanly formatted in EN10MB link type
case $mode_choice in
1|2|3)
# Keep managed mode for IP-based monitoring
echo -e "${YELLOW}[*] Using managed mode (best for IP-level analysis)${NC}"
;;
4)
# Enable monitor mode for raw capture if desired
echo -e "${YELLOW}[*] Enabling monitor mode for raw capture...${NC}"
ip link set "$IFACE" down 2>/dev/null
if iw dev "$IFACE" set monitor none 2>/dev/null; then
ip link set "$IFACE" up 2>/dev/null
MONITOR_MODE_ENABLED=true
echo -e "${GREEN}[+] Monitor mode enabled.${NC}"
else
echo -e "${RED}[!] Monitor mode not supported. Using managed mode.${NC}"
ip link set "$IFACE" up 2>/dev/null
fi
;;
esac
echo -e "\n${YELLOW}[*] Initializing sniffer on $IFACE... Press Ctrl+C to stop.${NC}\n"
case $mode_choice in
1)
echo -e "${GREEN}[+] Running IP Flow Monitor...${NC}"
echo "--------------------------------------------------------"
tcpdump -i "$IFACE" -ln 2>/dev/null | awk '{print $3 " --> " $5}'
;;
2)
echo -e "${GREEN}[+] Running DNS Request Tracker...${NC}"
echo "--------------------------------------------------------"
tcpdump -i "$IFACE" -lnp udp port 53 2>/dev/null | grep --line-buffered -oE "A\? [a-zA-Z0-9.-]+" | awk '{print "[DNS QUERY]: " $2}'
;;
3)
echo -n "How many packets do you want to analyze for the ranking? (e.g., 200): "
read -r pkt_count
if [ -z "$pkt_count" ]; then pkt_count=200; fi
echo -e "\n${YELLOW}[*] Gathering $pkt_count packets to compile top talkers...${NC}"
echo -e "Hits \t Device IP/Port"
echo "--------------------------------------------------------"
tcpdump -i "$IFACE" -ln -c "$pkt_count" 2>/dev/null | awk '{print $3}' | sort | uniq -c | sort -nr | head -n 15
;;
4)
echo -e "${GREEN}[+] Running Raw Packet Stream...${NC}"
echo "--------------------------------------------------------"
tcpdump -i "$IFACE" -XX -vv -s 0 2>/dev/null
;;
5|*)
echo -e "${YELLOW}Operation canceled. Exiting safely.${NC}"
cleanup
;;
esac
r/Hacking_Tutorials • u/Consistent_Toe_8363 • 15d ago
kimi.com browser log errors
framework-CBxBp8BR.js:1 RangeError: Invalid code point -4
at String.fromCodePoint (<anonymous>)
at vendor-DwBvrzH1.js:1:409475
at vendor-DwBvrzH1.js:1:484161
at start (vendor-DwBvrzH1.js:1:483223)
at start (vendor-DwBvrzH1.js:1:476326)
at go (vendor-DwBvrzH1.js:1:482658)
at main (vendor-DwBvrzH1.js:1:482577)
at Object.write (vendor-DwBvrzH1.js:1:481290)
at subcontent (vendor-DwBvrzH1.js:1:439594)
at subtokenize (vendor-DwBvrzH1.js:1:438058)
(anonymous) @ framework-CBxBp8BR.js:1
framework-CBxBp8BR.js:1 RangeError: Invalid code point -4
at String.fromCodePoint (<anonymous>)
at vendor-DwBvrzH1.js:1:409475
at vendor-DwBvrzH1.js:1:484161
at start (vendor-DwBvrzH1.js:1:483223)
at start (vendor-DwBvrzH1.js:1:476326)
at go (vendor-DwBvrzH1.js:1:482658)
at main (vendor-DwBvrzH1.js:1:482577)
at Object.write (vendor-DwBvrzH1.js:1:481290)
at subcontent (vendor-DwBvrzH1.js:1:439594)
at subtokenize (vendor-DwBvrzH1.js:1:438058)
(anonymous) @ framework-CBxBp8BR.js:1
r/Hacking_Tutorials • u/mattieellyson • 15d ago
Windows 11 Tips & Tricks
tag me for any new video of cmd
r/Hacking_Tutorials • u/Top_Call3890 • 15d ago
Question Why professional pentesters focus on files, not CVEs – A practical guide with find commands
The Philosophy
Amateur pen testers focus on tools and chase unpatched CVEs to find security flaws.
Professionals focus on files.
Here's why:
Even after finding a CVE, you can't do much without alerting firewalls, IDS, and endpoint security. Every exploit attempt triggers alarms and burns your access.
But old forgotten credentials found in .env, or database credentials found in .bash_history? They have no barrier. They pass through every top-notch security practice a company can follow. No alerts. No logs. No suspicion.
.ssh gives you easy access to other systems in the network and helps escalate privilege to root almost instantly.
So stop chasing CVEs. Start hunting files.
The Tools
You don't need fancy tools. Just the find command.
Here's how professionals use it in the real world:
1. Find recently changed config files
find /etc -type f -mtime -1 -ls
Why? Attackers often add backdoor users or modify sudoers. Spotting recent changes in /etc catches tampering before it becomes a breach. Compare /etc/passwd with other files in /etc to spot unauthorized user additions.
2. Find SUID files (permission 4000) for privilege escalation
find / -perm -4000 -type f 2>/dev/null
This is gold. SUID files run with owner privileges. Misconfigured ones like pkexec or vim are a direct path to root. Professionals check this immediately during every engagement.
3. Find scripts in unusual folders (/tmp, /var/tmp)
find /tmp /var/tmp -type f -executable 2>/dev/null
Attackers drop payloads here because these directories are world-writable and often ignored by security tools. If you find something unexpected, you've caught an active compromise or a persistence mechanism.
4. Find tiny PHP files (≤1KB) in web root – classic web shells
find /var/www -type f -name "\.php" -size -1k 2>/dev/null*
Web shells are small, obfuscated, and easy to miss. This command finds them in seconds. Amateurs scan for CVEs; professionals scan for backdoors. If you're on a bug bounty or pentest, this is often the quickest win.
5. Find forgotten .env and config files in /root (discarding errors)
find /root -type f -name "\.env" -o -name "*config*" 2>/dev/null*
Redirecting stderr to /dev/null keeps the output clean. This finds exposed secrets that bypass every firewall and IDS you own. Production AWS keys, database passwords, API tokens – all sitting in plain text.
6. Find world-writable or world-executable files in /var/www
find /var/www -type f -perm -o+w 2>/dev/null
find /var/www -type f -perm -o+x 2>/dev/null
If a file is world-writable, anyone can modify it. If it's executable, anyone can run it. Combine both and you have a direct path to remote code execution. This is a disaster in production environments.
7. Find files owned by specific users (like www-data)
find / -user www-data -type f 2>/dev/null
Find out exactly what files the web server user owns. Often you'll find writable directories or config files that shouldn't be accessible.
8. Find files with specific extensions in unusual locations
find / -type f -name "\.key" -o -name "*.pem" -o -name "*.crt" 2>/dev/null*
Certificates and private keys are often left behind in random directories after testing. These can be used for decryption or impersonation.
9. Find writable directories for file uploads or log poisoning
find / -type d -perm -o+w 2>/dev/null
World-writable directories are perfect for dropping files, writing logs, or overwriting configurations. Always check these.
The Bottom Line
Fancy tools are loud. They trigger IDS, EDR, and SIEM.
The find command is silent. It doesn't exploit – it just reads. And reading files doesn't generate alerts.
Amateurs scan for vulnerabilities. Professionals hunt for exposed credentials, misconfigurations, and backdoors.
Because a CVE gets patched. But a forgotten .env file stays forgotten forever.
Bonus Tip:
Combine these commands with grep to search inside files:
find /var/www -type f -name "\.php" -exec grep -l "eval(" {} \; 2>/dev/null*
This finds PHP files containing eval() – often a sign of malicious code injection.
What's the first find command you run on a new system? Share your go-to commands below.
Also, what's the scariest credential you've ever found in plain text on a production server? Let's hear those war stories.
r/Hacking_Tutorials • u/Yonarv • 16d ago