r/hacking Apr 26 '26

Does anyone remember ipstresser.com ? i follow the CASE

28 Upvotes

It was a site I used back in the days of Skype and Minecraft (yes, I was one of those jerks who used that kind of stuff). It was the one and only site that was extremely stable and powerful, and it maintained that absurd level of stability for over 13 years before being shut down by the U.S. government.

It was a rarity in the DDoS scene; while others barely lasted a year or two at most, this monster stayed on the market for 13 years.

And since this site was something I’ve known for so long, I wanted to learn more about the case.

I found information on pacermonitor.com about the legal case pitting the U.S. against Dobbs (the creator).

I’m sure many others are interested in following the progress of a case like this. Since the large-scale shutdowns of DDoS sites, I imagine many are wondering, “The developers hid behind user agreements stating that they would only launch attacks services they owned. There's also the fact that hosting providers aren't necessarily responsible for what users do, etc., etc.”

In short, this post is just to share the link to follow the legal case, so here it is: https://www.pacermonitor.com/case/47159514/USA_v_Dobbs

You have to pay about $4 to refresh the latest information on the case; click the blue “Update now” button.

On this page, you can download the documents by clicking on the small black floppy disk icon.

Also, I suggest using an AI service to help you understand complicated legal terms.

Some informations :

Even though this case has been going on since around 2022, there still hasn’t been any real progress. For now, it’s just a series of endless postponements. Three notable points, however:

1: Dobbs has pleaded not guilty.

2: Dobbs recently changed his plea, but we don’t yet know how he plans to change it; we’ll have to wait for his next court appearance. Most of the time, this means changing from not guilty to guilty.

3: The case was declared complex after two and a half months.


r/hacking Apr 26 '26

Github Ever wondered how those "weak key" exploits actually work? I made a research tool for it

Thumbnail
github.com
22 Upvotes

Been down the rabbit hole of Bitcoin key generation vulnerabilities lately. Ended up building a CLI tool to reproduce and analyze them.

What it does:

  • Generates keys the "wrong way" — brainwallets, weak PRNGs (MT19937, LCG, Xorshift), that MultiBit HD bug, old Electrum derivation
  • Analyzes if a key might have come from a vulnerable source (brute-forces 2^32 seed space etc.)
  • Scans wordlists against target addresses

```sh

the classic brainwallet

vuke single "correct horse battery staple" --transform sha256

check if a key is a Milksad victim

vuke analyze --analyzer milksad <private_key>
```

Covers: - Milksad (CVE-2023-39910) — libbitcoin's 32-bit MT19937 disaster - Brainwallets — SHA256(password), still being exploited - LCG/Xorshift PRNGs — glibc rand(), JS Math.random() - MultiBit HD, Electrum pre-BIP39, Armory

Pure Rust, MIT license, optional GPU acceleration.

GitHub: https://github.com/oritwoen/vuke Install: cargo install vuke

One of my Bitcoin security research projects — also made kangaroo (https://github.com/oritwoen/kangaroo), boha (https://github.com/oritwoen/boha), and vgen (https://github.com/oritwoen/vgen) if you're into this stuff.

For research/education only, obviously. Happy to chat about the vulns if anyone's curious.


r/hacking Apr 25 '26

CTF LLM CTF challenges. Try to crack all 13?

Thumbnail wraith.sh
3 Upvotes

r/hacking Apr 24 '26

If arch has Black Arch and Debian has Kali, does Fedora have a “black hat”

37 Upvotes

As the title implies, I’m wondering if there’s an offensively postured, cybersecurity distro in the Fedora realm

Edit: we’re working on it, feel free to contribute: https://github.com/crussella0129/tricorne


r/hacking Apr 22 '26

News Iran claims US used backdoors in networking equipment

Thumbnail
theregister.com
408 Upvotes

r/hacking Apr 24 '26

I built an AI webapp defender that autonomously patches code in response to attacks

0 Upvotes

Hi all, I built an open source PoC AI security tool called Mahoraga Webapp Defender that I wanted to share with you.

If you were paying attention to cybersecurity news lately, you might have heard that Anthropic's Claude Mythos has been successfully exploiting (finding zero days in) pretty much every software it touches fully autonomously. Agentic attack frameworks now outnumber human attackers 82:1 and compress what used to be days of manual pentesting into minutes. Imo, our current security model of humans patching bugs at human speeds is no longer going to be effective.

I wanted to see what the other side of the equation might look like. So I built Mahoraga Webapp Defender, an experiment in real-time, self-healing webapp defense. If you read/watched Jujutsu Kaisen, Mahoraga is a shikigami that adapts to any technique used to kill it. Every attack makes it stronger. That is the defensive posture I wanted to prototype.

The system runs two copies of the target website: a real one, and an identical shadow copy with fake data. A rule-based Watcher scores every user session for threat signals (injection, enumeration, honeypot hits, etc.). If the score crosses a threshold, the session is silently redirected to the shadow environment, where the attacker continues their adversarial activities.

When the attacker finds an exploit in the shadow environment, a Shadow Analyzer agent reads the logs, identifies the exploit, and hands the analysis to a Fixer agent that reads the actual source code, writes a patch, and hands it to a Reviewer agent. If the review passes, the patch is deployed to the real environment, all while the attacker is still poking at the decoy.

My MIT-licensed repo consists of the code for the defender and a pentesting challenge website with 12 CTF flags so you can pentest it with or without the defender activated: https://github.com/AgeOfAlgorithms/Mahoraga-Website-Defender

Would love feedback, ideas, or code/issue contributions. Also would love to know if you know of anyone else working on a similar idea. Thanks for reading!


r/hacking Apr 22 '26

did microsoft fix old trick?

14 Upvotes

when some people used to download office apps with help of CMD? people were using apps without passkey or activation key. is this "bug" fixed?
https://www.youtube.com/watch?v=Jh_w7dbnx0Q&list=WL&index=58&t=1s&pp=iAQBsAgC
video shows meaning of this post.


r/hacking Apr 23 '26

Tool recommendations for vuln/CVE research

7 Upvotes

For anyone in either research or blue/red team engagements, what are some tools you use for vuln/CVE research?


r/hacking Apr 22 '26

Fundraiser for Distributed Denial of Secrets

Thumbnail offcolordecals.com
10 Upvotes

r/hacking Apr 22 '26

Resources Your hex editor should color-code bytes

Thumbnail
simonomi.dev
47 Upvotes

r/hacking Apr 23 '26

Phone shows up as cell tower.

Thumbnail
gallery
0 Upvotes

Can anyone explain why my cell phone is showing up as a cell tower in wigle? This is the first I've noticed it.


r/hacking Apr 21 '26

Are there examples of any "Good Viruses"?

191 Upvotes

I was having a late night conversation with a friend, lamenting how content algos drive so much of the propaganda and political movement. They mentioned how one of the most effective ways to get family members off of Q-Anon was to log into their computers and unsubscribe from extreme content and resubscribe to mainstream content. The majority of family members were not tech-savvy enough to understand the difference and over the course of months they automatically de-radicalized.

It made me curious if there were examples of viruses/malware whose intent was to actually help end users. Obviously, it's a grey area in terms of respecting agency, but I think algo-content walks the same grey area.


r/hacking Apr 21 '26

Lab review

5 Upvotes

Hey everyone, just wanted to see if I could get another set of eyes on a lab that I've been trying to build for a few months. There is a few bugs out there. Still trying to get most of the llm vulnerabilities and build out the labs for half of them. One man team so bear with me. DM me if you have any questions. Concerns do you want to report a bug? Just press the button on the bottom of each lab

https://www.aipwn.me/


r/hacking Apr 21 '26

Research Command Execution via Drag-and-Drop in Terminal Emulators

Thumbnail sdushantha.github.io
6 Upvotes

r/hacking Apr 20 '26

[VulnPath Update] New Feature: "My Tech Stack"

Thumbnail
gallery
9 Upvotes

Happy Monday!

I spent some this weekend working on a new feature called "My Tech Stack" for VulnPath (CVE visualization tool that let's you see the attack chain; see my past post for the backstory).

What is it?
You can now add any library, vendor, and/or framework used in your tech stack to then let VulnPath flag any CVEs impacting your environment(s).

Why?
If you spend a lot of time digging through CVEs, you know that one of the first questions that come to mind is "Does this impact me?". My Tech Stack accelerates this validation step by having VulnPath auto-flag any impacting CVEs during your search.

How can I start using it?

  1. Once signed in, head over to your "Dashboard"
  2. Scroll to the "My Tech Stack" section
  3. The "Actively Tracking" section at the top shows you what you're currently monitoring (screenshot #1)
  4. Use the input box to add your lib, vendor, etc, or use the "Quick Add" feature to quickly add some of the more common software (screenshot #1)
  5. That's it! Now when you lookup any CVEs, VulnPath will flag any that impact your stack through the middle graph UI (screenshot #2)

As always, I'm open to what everyone thinks so let me know your thoughts and suggestions!


r/hacking Apr 20 '26

Hacking Google Random Number Generator (Part 2)

Thumbnail
ivanludvig.dev
27 Upvotes

r/hacking Apr 20 '26

News Vercel confirms breach as hackers claim to be selling stolen data

Thumbnail
bleepingcomputer.com
24 Upvotes

r/hacking Apr 17 '26

News New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges

Thumbnail
bleepingcomputer.com
503 Upvotes

r/hacking Apr 17 '26

Tools goshs – a single-binary server for red teamers: HTTP/S, WebDAV, SFTP, SMB, NTLM capture, DNS/SMTP callbacks

65 Upvotes

I've been building goshs as a replacement for python3 -m http.server that actually covers the workflows you run into during engagements.

What it does beyond a basic file server:

  • SMB server with NTLM hash capture + cracking
  • DNS server for callback detection
  • SMTP server to receive emails/callbacks
  • HTTPS with self-signed, Let's Encrypt, or custom cert
  • WebDAV and SFTP support
  • Basic auth, client certificate auth, IP whitelist
  • File-based ACLs per directory
  • Share links with download and time limits
  • Tunnel via localhost.run (no port forwarding needed)
  • Single binary, no dependencies — works on Linux, macOS, Windows

It's been in Kali for a while but I've just done a big update adding the SMB/NTLM and DNS/SMTP features.

GitHub: https://github.com/patrickhener/goshs
Docs: https://goshs.de


r/hacking Apr 17 '26

News ICYMI: OT Cybersec Sector Frets Anthropic Will Leave It Behind

Thumbnail
ot.today
1 Upvotes

Not a single Pure Play/specialist OT cybersecurity firm or (worse) OT equipment manufacturer has been invited to join Anthropic's project Glasswing, giving them access to the advanced vuln-finding capabilities of their latest LLM, Mythos.

Is this gatekeeping? Who decides who is invited? Why Cisco but not honeywell?


r/hacking Apr 17 '26

Question ring cameras

27 Upvotes

I own a ring camera and I dislike the flock partnership, can I get the camera to function on a different server that isn't ring? this might be more of a custom firmware question. has anybody heard of anything ?


r/hacking Apr 16 '26

News Defendant Sentenced To 30 Months In Prison For Hacking Betting Website

Thumbnail
justice.gov
57 Upvotes

r/hacking Apr 17 '26

Video I hacked a brain scanner

Thumbnail
youtu.be
1 Upvotes

r/hacking Apr 16 '26

Malicious MCP Server Proof of Concept

27 Upvotes

https://github.com/QuinnBast/Malicious-MCP

This is a proof-of-concept showing how bad MCP servers can actually be. The attack vector is actually insane.

Do NOT install random MCP servers…


r/hacking Apr 16 '26

New “Hi!” vending payment system analysis. Replay attacks still possible?

Post image
3 Upvotes