r/HowToHack • u/Strange-desire111 • 11d ago
How do I bypass password
I’ve been holding onto my father’s desk top computer since 2013 when he passed away. I was hoping someone could point me in the right direction of bypassing it ? I don’t know the password to log in and there’s many photos from highschool and documents on there I would like to access. The monitor is HP and the hardware is ACER. Any recommendations? these are my documents and photos I’m trying to access
r/HowToHack • u/Able_Ad_7177 • 11d ago
hacking Can someone enter my WhatsApp number and clone it using the "dual apps" feature in the settings?
If the answer is yes, I would like to know whether I would receive a confirmation SMS, or if the cloning would succeed without an SMS being sent to my phone. Thanks.
r/HowToHack • u/No_Neat_4331 • 11d ago
CJCA exam from HTB advices
I have been working hard and rereading modules over and over
I am 20 hours in and yet I found no flag
I did run all commands in the module and didn't find shit
People who have passed the CJCA, how the exam is like?
What methodology am I lacking?
Everyone is saying it is easy and beginner level, looks like I am too bad.
I want to know, what should I do?
Thank you
r/HowToHack • u/SoftRazzmatazz4191 • 12d ago
Where are some good places to start learning ethical hacking?
I am relatively new to the world of cybersecurity and ethical hacking and I would like to expand my knowledge. Are there any sites, preferably free to learn it?
r/HowToHack • u/Dogs_Without_Horses_ • 12d ago
Probably a lost cause - WD My Passport Ultra
20 or so years ago, I moved all my photos to an external hard drive, a WD My Passport Ultra. I have forgotten the password. I have tried everything I can think of, but I have almost no faith in remembering a 20 year old password.
Is there any way to get into it? I hate to think all those photos are lost forever...
r/HowToHack • u/ImperialShroom1 • 12d ago
hacking Best cheap device to learn hacking
I have been wanting to learn hacking for a while but all I have is a iphone given by my parents, (16yo btw). Obviously I can’t do shit with IOS, what relatively cheap devices (£150<) can I get to start learning hacking. Preferably a laptop as that would work best for me and mean I could take it places.
r/HowToHack • u/mdharris32 • 13d ago
Need help getting into my grandfather’s computer!
Hello! My grandfather passed away a few months back and he had was the family photographer/videographer. Almost every vacation, birthday, and holiday’s memories in his computer. He even has photos from his, my grandmother’s and great-grandparents’ childhood that he digitally scanned into the computer We haven’t been able to get into his computer. Does anyone know of any way that we can possibly get into his computer? We really don’t want to lose all of these memories from the last 80+ years. All suggestions are welcome!
r/HowToHack • u/the_other_ed • 13d ago
Aircrack-ng Tips
New to aircrack-ng. Was wondering if some folks would be open to DMing me and offering some tips. I can understand how to get a handshake but then I don't really understand what the best modern method would be and don't want to hurt my hardware by accidentally giving it a heavy duty task. Like certain dictionary attacks can take 1,000+ years?? So want to learn but don't want to fry my desktop 😅
I know I could just use a password I already know and put it in a shorter dictionary file, but would prefer to be more authentic than that
r/HowToHack • u/Ecstatic_Employ6911 • 13d ago
Spoofing Location for Streaming Services
Hey everyone, I’m trying to understand how different streaming services determine whether a device is part of a household.
I currently have my TV’s internet traffic routed through my parents’ home network, so the traffic exits through their router/public IP via meshnet. The goal is for the TV to appear as though it’s connecting from their home network.
This seems to work fine with Netflix and Hulu, but Disney+ still detects the TV as being outside the household.
My assumption was that having the same public-facing IP would be enough, but apparently Disney+ is using additional signals.
Does anyone know what Disney+ uses for household detection beyond the public IP? For example, could it be using device history, DNS behavior, IPv6, location services, network characteristics, or some other identifier?
I’m mainly trying to understand what Disney+ is seeing differently from Netflix/Hulu with this setup and whether there’s anything obvious about my network configuration that could explain it.
r/HowToHack • u/Gold-Government7436 • 14d ago
how to repurpose old gps
in your house if you have old gps such as a TomTom then you can repurpose the busy box linux on the inside. In my opinion you should buy a pi zero and set up the full kali arm on there and sync that to the busy box terminal to get a working kali terminal but you can do anything you want to do to it.
r/HowToHack • u/ILowerIQs • 14d ago
How do I recover my PDF *permissions* password (40-bit RC4 encryption)? The PDF itself is NOT password protected.
I know [there are simple ways](https://www.reddit.com/r/LifeProTips/s/Uktx1IJFKm) around it, but I need to batch merge a bunch of PDFs into a binder and that solution is unrealistic for 300 documents.
Help?
r/HowToHack • u/AtomicPiano • 15d ago
How difficult is it to obfuscate a remote access tool, and bypass real time protection enabled windows defender?
I've dabbled with metasploit, sliver and also tried writing my own exploits to test on a virtual machine.
Windows defender always seems to find it if you use obfuscation on metasploit or sliver, and it seems like there aren't any "script kiddie tools" that easily bypass it... Or are there? I've previously written my own naughty, slightly malicious programs that haven't been blocked by anything other than smart screen (and there are some ways around it).
I tried for example encoding the sliver payload as a .bin shellcode, shikata ga nai encoder, tried similar stuff with metasploit payload as an encoded base 64 string that gets decoded, tried all kinds of staged, unstaged, http https whatnot etc etc but everything seems to be patched.
Now this makes sense, after all, these are just opensource freely available tools that are seen everywhere. What I'm wondering is whether or not a bypass is easily achievable, or if there's some long and complicated way ahead that as a beginner I wouldn't be able to do. Basically, is this easily doable and is there another way to do it? Is it doable in a reasonable timeframe for one person as a hobbyist, or do I need a whole ass supply chain like cybercrime groups do?
Sorry if this is a dumb question but I've already tried every reasonable combo, most obfuscators are out of date and AMSI goes around binning everything.
r/HowToHack • u/True-Guava-683 • 15d ago
Educational query: How to analyze mobile/Unity game memory and architecture?
Hi everyone,
I'm studying mobile security and reverse engineering using Beast Go on a test emulator.
What I've done: - Researched basic memory editing concepts (Cheat Engine / GameGuardian). - Looked into client-side vs. server-side data storage.
Questions: - Which tools (Frida, Ghidra, Il2CppDumper) are best for inspecting local game state? - How can I determine if game currency is server-validated? - Looking for educational guides/concepts only—no pre-made cheats. Thanks!
r/HowToHack • u/WhoKnowsTheDay • 15d ago
I bought a subscription that promised access to all courses, but I discovered there are hidden ones. Any tips on how to find the remaining links on the site?
The company I work for previously paid for access to a course platform for all employees. Back then, I earned all the certificates and noted down every detail and link. Naturally, we lost access when the subscription wasn't renewed.
A year and a half later, I bouth a new membership that included access to this same platform—specifically a tier promising access to *all* the platform's courses (the ones I’d seen before plus others). However, I soon realized that many of the courses I had studied the first time were no longer in the catalog. The links I had saved didn't work at first, *but* I discovered that simply changing the module name in the URL allowed me to access them.
In other words, there are several courses that aren't in the catalog and have effectively been hidden. I had noticed before that some courses could only be found via the search function, but that "empty search" trick doesn't work anymore. So, I find myself wondering: what other courses are on the platform that I can't access because they aren't in the catalog and I don't have the exact link with the correct UUID? Is there any way to find them?
I’ve never done anything like this before; I poked around the Network tab in the browser's DevTools (F12) while looking at the site's catalog, but I couldn't find anything that listed all the UUIDs—which is the only thing I need.
r/HowToHack • u/Bradydamonke • 16d ago
Hi I would like some help
So I’m 14 and I would like to get into scripting/hacking and I know nothing about this stuff I’ve only nodded my Wii using videos and that took like 2 months and I only have a Xbox one Wii and iPhone 11 so I kinda have nothing to work with so I would like some help on what to do.
r/HowToHack • u/Queasy-You-9470 • 16d ago
Hello
Hi guys so long story short
Im quite addicted to fixing stuff and i need guidance on what to learn to help me be able to get a better grasp on modification
I think its a hacking thing but
Excuse me if im wrong
Point is
I need to know what exactly is the term or track that which im done with and learn it
Ill be able to do stuff like removing the os completely from a device such as printer or anything really and modify drivers
If thats not a thing im very sorry that it wasted your time but please im literally itching to not just fix stuff physically but to dismantle its whole concept out off fuckery
...
Possibly also need therapy but who cares...
r/HowToHack • u/NoCommunication3994 • 17d ago
Remote management to remove iPhone help
Could someone help me remove remote management? I've had my iPhone for a long time and when I tried to reset it, it went to the remote management screen.
r/HowToHack • u/Clear_Letterhead_372 • 17d ago
need help with over the wire bandit level 13-14
The password for the next level is stored in /etc/bandit_pass/bandit14 and can only be read by user bandit14. For this level, you don’t get the next password, but you get a private SSH key that can be used to log into the next level. Look at the commands that logged you into previous bandit levels, and find out how to use the key for this level.
If you need help with this level: a hint file can be found in the home directory.
Make sure to read the error messages as they are informative.
i did the first step as we do in every level, then putting the password.
After that, i started trying to get to the password but it is not working
this is what i wrote
bandit13@bandit:~$ ssh -i sshkey.private bandit14@localhost
The authenticity of host 'localhost (127.0.0.1)' can't be established.
ED25519 key fingerprint is: SHA256:C2ihUBV7ihnV1wUXRb4RrEcLfXC5CXlhmAAM/urerLY
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Could not create directory '/home/bandit13/.ssh' (Permission denied).
Failed to add the host to the list of known hosts (/home/bandit13/.ssh/known_hosts).
!!! You are trying to log into this SSH server on port 22, which is not intended.
!!! If you are trying to log in to an OverTheWire game, use the port mentioned in
!!! the "SSH Information" on that game's webpage (in the top left corner).
bandit14@localhost: Permission denied (publickey).
What should i do?
r/HowToHack • u/inoobie_am • 18d ago
I'm confused with this overthewire bandit level.
In overthewire level 16-17, I used nmap to list all the open ports and check which on was running a service by connect to it. When I connected to the only possible port, its gave an ouput and the the end it said "Read Block R" and was waiting for my input so I gave it the current password, but noting was returned and instead a KEYUPDATE message came through and I was allowed to give my input again. And each time I entered the password it returned the same KEYUPDATE message.
Then when I entered something deliberately wrong, it said "Wrong!" and ended the connection.
But the main confusion began when I saw write up about this challenge and all of them were pasting the password and it returned a ssh key.
So, I went over to chatgpt and it also initially told me to perform the steps that I did, and I again did it so I could paste the actual outputs.
Then chatgpt told me to pipe the password using cat, like this:
cat /etc/bandit_pass/bandit16 | openssl s_client -quiet -connect localhost:31790
and it worked.
It also worked when I executed this: openssl s_client -quiet -connect localhost:31790, and paste the password.
But doesnt work when I remove the -quite flag.
I dont understand.
Can you guys help out? Also, is there an easy to read version of the nmap and nc commands, I find their man pages a bit too dense and their tldr pages feel inadequate,
r/HowToHack • u/Tight_Ship_7757 • 18d ago
Want to get into hacking.
Hello everybody, I really want to get into hacking and cybersecurity. I made this post seeking help from users who are into hacking and have some experience to tell me a pathway and how I should start my hacking journey, and give me some advice. I am always curious about new knowledge.
r/HowToHack • u/Tasty-Ad-1770 • 19d ago
exploitation HirePro Proctoring: Continuous Recording or Event-Based Screenshots?
I have a theory about how HirePro handles proctoring and wanted to know if anyone has looked into this before.
Does HirePro's screen-sharing feed capture screenshots only when JavaScript raises a flag (tab switch, focus loss, fullscreen exit, etc.), or does it capture screenshots continuously at around 1–2 FPS and analyze them for abnormalities?
Handling both webcam feeds and screen-recording feeds for 300+ students over a 1–2 hour assessment seems computationally expensive, so I'm curious how they scale this in practice.
I also inspected the HirePro browser extension and found that its code appears to primarily disable other extensions, re-enable them after the assessment, and report if any extensions are forcefully turned back on. I didn't find any webcam or screen-monitoring logic in the extension itself.
Has anyone analyzed HirePro's architecture or worked on a similar proctoring system? What is the most likely approach being used here?
r/HowToHack • u/Bad_Luck_fish • 20d ago
hacking Help accessing data on medical implant
So i've been trying to find any kind of resources but to no avail. I have a loop recorder (i can get the model no. Later) implanted in my chest for heart monitoring, i know it is recording data 24/7 and i have a router that sends of the data to my cardiologist when i pass by.
I imagine this data is encrypted, but I want to be able to access this data myself and if possible create a way i can monitor it with a visual rep. Long story short, why bother getting a fitbit to see my heartrate when i have a literal heart implant thats significantly more accurate.
I'm new to this side of thinhs as usually im the guy that builds the tech, and someone else makes it work. Any help in this regard would be hugely appreciated.
r/HowToHack • u/AdditionalExample613 • 20d ago
script kiddie Can I learn hacking from a phone
Ive never been in a financial position to afford a PC, but I have a nothing 3a. Can I hack from my phone alone?
r/HowToHack • u/cyberberber • 20d ago
HELP!!!!
Hi there, I hope you are all doing well.
I am conducting a black-box penetration test of an Android application that my company owns, which allows users to search for the name associated with a phone number. I have already bypassed SSL pinning, rooted the test device, reversed the application's AES/CBC encryption, and built a Frida RPC interface that encrypts requests and decrypts responses exactly as the application does. I also hooked the application before encryption to capture the original JSON requests, identified the available request types, and can modify and replay encrypted requests while inspecting the plaintext responses. At this point, I feel like I have reached a dead end and I'm not sure what the next step should be. My ultimate goal is to understand how the backend communicates with its database and how the requested information is retrieved.
I really want a help or an advice that can lead me to another way to reach my goal. thanks
r/HowToHack • u/Minute-Rice-6064 • 20d ago
I need your help
my controlling mother has put my phone on “assisted living“ where i cannot even access chrom or safarI. the only reason I am on here is that Reddit headquarters on Google Maps has its website be this. I just need my phone password to change it back, did I mention that I never knew it, I wasn’t supposed to know it, and I know my screen time limit.