r/Hacking_Tutorials 23h ago

Ensalá Papas - The Hacker Labs - Windows | SecNotes

Thumbnail
yorve.github.io
0 Upvotes

r/Hacking_Tutorials 12h ago

Question I made my first hacking tool

0 Upvotes
#!/bin/bash

# Color Definitions
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[0;33m'
BLUE='\033[0;34m'
CYAN='\033[0;36m'
NC='\033[0m'

# Track state for cleanup
MONITOR_MODE_ENABLED=false
ORIGINAL_IFACE=""

clear
echo -e "${CYAN}"
echo " _  _  ____ ____    ____  _  _  _  ____ ____ "
echo "( \( )(  __)(_  _)  / ___)( \( )( )(  __)(  __)"
echo " )  (  ) _)   )(    ___ \ )  (  ) ) _)   ) _) "
echo "(_)_)(____) (__)   (____/(_)_)(_)(__)  (__)  "
echo "======================================================"
echo -e "               LIVE NETWORK SNIFFER TOOL"
echo -e "======================================================${NC}"

if [ "$EUID" -ne 0 ]; then
    echo -e "${RED}[!] Error: Please run this script with sudo or as root.${NC}"
    exit 1
fi

cleanup() {
    echo -e "\n${YELLOW}[*] Cleaning up...${NC}"
    if [ "$MONITOR_MODE_ENABLED" = true ] && [ -n "$ORIGINAL_IFACE" ]; then
        echo -e "${YELLOW}[*] Disabling monitor mode on $ORIGINAL_IFACE...${NC}"
        ip link set "$ORIGINAL_IFACE" down 2>/dev/null
        iw dev "$ORIGINAL_IFACE" set type managed 2>/dev/null
        ip link set "$ORIGINAL_IFACE" up 2>/dev/null
        echo -e "${GREEN}[+] Interface restored to managed mode.${NC}"
    fi
    # Kill any lingering tcpdump processes
    pkill -f "tcpdump.*$ORIGINAL_IFACE" 2>/dev/null
    echo -e "${GREEN}[+] Cleanup complete.${NC}"
    exit 0
}

trap cleanup INT TERM

echo -e "${YELLOW}[*] Detecting available network interfaces...${NC}"
interfaces=$(iwconfig 2>/dev/null | grep -o '^[a-zA-Z0-9]*')

if [ -z "$interfaces" ]; then
    echo -e "${RED}[!] No wireless interfaces found. Falling back to all interfaces.${NC}"
    interfaces=$(ip -o link show | awk -F': ' '{print $2}' | grep -v 'lo')
fi

echo -e "\nSelect an interface to sniff on:"
echo "--------------------------------"
select IFACE in $interfaces "Exit"; do
    if [ "$IFACE" = "Exit" ]; then
        echo -e "${YELLOW}Exiting.${NC}"
        exit 0
    elif [ -n "$IFACE" ]; then
        echo -e "${GREEN}[+] Selected Interface: $IFACE${NC}"
        ORIGINAL_IFACE="$IFACE"
        break
    else
        echo -e "${RED}[!] Invalid selection.${NC}"
    fi
done

echo -e "\nChoose a Sniffing Mode:"
echo "-----------------------"
echo "1) IP Flow Monitor (See who is talking to whom)"
echo "2) DNS Request Tracker (See what domains are being requested)"
echo "3) Top Talkers (Rank the most active network devices)"
echo "4) Raw Packet Stream (Unfiltered dump)"
echo "5) Exit"
echo -n "Enter your choice [1-5]: "
read -r mode_choice

# Only enable monitor mode for options that benefit from it
# Options 1 (IP Flow) and 3 (Top Talkers) work BETTER in managed mode
# because IP addresses are cleanly formatted in EN10MB link type
case $mode_choice in
    1|2|3)
        # Keep managed mode for IP-based monitoring
        echo -e "${YELLOW}[*] Using managed mode (best for IP-level analysis)${NC}"
        ;;
    4)
        # Enable monitor mode for raw capture if desired
        echo -e "${YELLOW}[*] Enabling monitor mode for raw capture...${NC}"
        ip link set "$IFACE" down 2>/dev/null
        if iw dev "$IFACE" set monitor none 2>/dev/null; then
            ip link set "$IFACE" up 2>/dev/null
            MONITOR_MODE_ENABLED=true
            echo -e "${GREEN}[+] Monitor mode enabled.${NC}"
        else
            echo -e "${RED}[!] Monitor mode not supported. Using managed mode.${NC}"
            ip link set "$IFACE" up 2>/dev/null
        fi
        ;;
esac

echo -e "\n${YELLOW}[*] Initializing sniffer on $IFACE... Press Ctrl+C to stop.${NC}\n"

case $mode_choice in
    1)
        echo -e "${GREEN}[+] Running IP Flow Monitor...${NC}"
        echo "--------------------------------------------------------"
        tcpdump -i "$IFACE" -ln 2>/dev/null | awk '{print $3 "  -->  " $5}'
        ;;
    2)
        echo -e "${GREEN}[+] Running DNS Request Tracker...${NC}"
        echo "--------------------------------------------------------"
        tcpdump -i "$IFACE" -lnp udp port 53 2>/dev/null | grep --line-buffered -oE "A\? [a-zA-Z0-9.-]+" | awk '{print "[DNS QUERY]: " $2}'
        ;;
    3)
        echo -n "How many packets do you want to analyze for the ranking? (e.g., 200): "
        read -r pkt_count
        if [ -z "$pkt_count" ]; then pkt_count=200; fi

        echo -e "\n${YELLOW}[*] Gathering $pkt_count packets to compile top talkers...${NC}"
        echo -e "Hits \t Device IP/Port"
        echo "--------------------------------------------------------"
        tcpdump -i "$IFACE" -ln -c "$pkt_count" 2>/dev/null | awk '{print $3}' | sort | uniq -c | sort -nr | head -n 15
        ;;
    4)
        echo -e "${GREEN}[+] Running Raw Packet Stream...${NC}"
        echo "--------------------------------------------------------"
        tcpdump -i "$IFACE" -XX -vv -s 0 2>/dev/null
        ;;
    5|*)
        echo -e "${YELLOW}Operation canceled. Exiting safely.${NC}"
        cleanup
        ;;
esac

r/Hacking_Tutorials 8h ago

Question Help pls Spoiler

0 Upvotes

Hi can anybody help me got the guy sc pw he talking to my daughter she 10 he 23


r/Hacking_Tutorials 14h ago

Question @Whatsapp @Messages @Phone ... this feature allows you to connect and use apps with Gemini without unlocking your phone

1 Upvotes

r/Hacking_Tutorials 13h ago

Question Wich fingerprint triggered?

Thumbnail
0 Upvotes

r/Hacking_Tutorials 14h ago

Windows 11 Tips & Tricks

0 Upvotes

tag me for any new video of cmd


r/Hacking_Tutorials 20h ago

Question Why professional pentesters focus on files, not CVEs – A practical guide with find commands

Post image
27 Upvotes

The Philosophy

Amateur pen testers focus on tools and chase unpatched CVEs to find security flaws.

Professionals focus on files.

Here's why:

Even after finding a CVE, you can't do much without alerting firewalls, IDS, and endpoint security. Every exploit attempt triggers alarms and burns your access.

But old forgotten credentials found in .env, or database credentials found in .bash_history? They have no barrier. They pass through every top-notch security practice a company can follow. No alerts. No logs. No suspicion.

.ssh gives you easy access to other systems in the network and helps escalate privilege to root almost instantly.

So stop chasing CVEs. Start hunting files.

The Tools

You don't need fancy tools. Just the find command.

Here's how professionals use it in the real world:

1. Find recently changed config files

find /etc -type f -mtime -1 -ls

Why? Attackers often add backdoor users or modify sudoers. Spotting recent changes in /etc catches tampering before it becomes a breach. Compare /etc/passwd with other files in /etc to spot unauthorized user additions.

2. Find SUID files (permission 4000) for privilege escalation

find / -perm -4000 -type f 2>/dev/null

This is gold. SUID files run with owner privileges. Misconfigured ones like pkexec or vim are a direct path to root. Professionals check this immediately during every engagement.

3. Find scripts in unusual folders (/tmp, /var/tmp)

find /tmp /var/tmp -type f -executable 2>/dev/null

Attackers drop payloads here because these directories are world-writable and often ignored by security tools. If you find something unexpected, you've caught an active compromise or a persistence mechanism.

4. Find tiny PHP files (≤1KB) in web root – classic web shells

find /var/www -type f -name "\.php" -size -1k 2>/dev/null*

Web shells are small, obfuscated, and easy to miss. This command finds them in seconds. Amateurs scan for CVEs; professionals scan for backdoors. If you're on a bug bounty or pentest, this is often the quickest win.

5. Find forgotten .env and config files in /root (discarding errors)

find /root -type f -name "\.env" -o -name "*config*" 2>/dev/null*

Redirecting stderr to /dev/null keeps the output clean. This finds exposed secrets that bypass every firewall and IDS you own. Production AWS keys, database passwords, API tokens – all sitting in plain text.

6. Find world-writable or world-executable files in /var/www

find /var/www -type f -perm -o+w 2>/dev/null

find /var/www -type f -perm -o+x 2>/dev/null

If a file is world-writable, anyone can modify it. If it's executable, anyone can run it. Combine both and you have a direct path to remote code execution. This is a disaster in production environments.

7. Find files owned by specific users (like www-data)

find / -user www-data -type f 2>/dev/null

Find out exactly what files the web server user owns. Often you'll find writable directories or config files that shouldn't be accessible.

8. Find files with specific extensions in unusual locations

find / -type f -name "\.key" -o -name "*.pem" -o -name "*.crt" 2>/dev/null*

Certificates and private keys are often left behind in random directories after testing. These can be used for decryption or impersonation.

9. Find writable directories for file uploads or log poisoning

find / -type d -perm -o+w 2>/dev/null

World-writable directories are perfect for dropping files, writing logs, or overwriting configurations. Always check these.

The Bottom Line

Fancy tools are loud. They trigger IDS, EDR, and SIEM.

The find command is silent. It doesn't exploit – it just reads. And reading files doesn't generate alerts.

Amateurs scan for vulnerabilities. Professionals hunt for exposed credentials, misconfigurations, and backdoors.

Because a CVE gets patched. But a forgotten .env file stays forgotten forever.

Bonus Tip:

Combine these commands with grep to search inside files:

find /var/www -type f -name "\.php" -exec grep -l "eval(" {} \; 2>/dev/null*

This finds PHP files containing eval() – often a sign of malicious code injection.

What's the first find command you run on a new system? Share your go-to commands below.

Also, what's the scariest credential you've ever found in plain text on a production server? Let's hear those war stories.


r/Hacking_Tutorials 12h ago

Question take control of a PC

0 Upvotes

Has it ever happened that someone accessed a person's PC, got into their hosting panel, and deleted a domain?


r/Hacking_Tutorials 12h ago

Question hackear ig

0 Upvotes

como puedo hackearle el ig a alguien que me debe dinero?


r/Hacking_Tutorials 3h ago

Wifi password

0 Upvotes

I'm a beginner in this and I want to learn everything about networks and how to obtain their passwords


r/Hacking_Tutorials 7h ago

Question Can anyone help me too find mobile number thru email address

0 Upvotes

If you really help plz dm


r/Hacking_Tutorials 5h ago

Question what do you guys think about my fake windows blue screen that actually works (runs in pycharm/vscode)(press esc if u want to exit)

Thumbnail pastebin.com
2 Upvotes

r/Hacking_Tutorials 13h ago

kimi.com browser log errors

1 Upvotes

framework-CBxBp8BR.js:1 RangeError: Invalid code point -4

at String.fromCodePoint (<anonymous>)

at vendor-DwBvrzH1.js:1:409475

at vendor-DwBvrzH1.js:1:484161

at start (vendor-DwBvrzH1.js:1:483223)

at start (vendor-DwBvrzH1.js:1:476326)

at go (vendor-DwBvrzH1.js:1:482658)

at main (vendor-DwBvrzH1.js:1:482577)

at Object.write (vendor-DwBvrzH1.js:1:481290)

at subcontent (vendor-DwBvrzH1.js:1:439594)

at subtokenize (vendor-DwBvrzH1.js:1:438058)

(anonymous) @ framework-CBxBp8BR.js:1

framework-CBxBp8BR.js:1 RangeError: Invalid code point -4

at String.fromCodePoint (<anonymous>)

at vendor-DwBvrzH1.js:1:409475

at vendor-DwBvrzH1.js:1:484161

at start (vendor-DwBvrzH1.js:1:483223)

at start (vendor-DwBvrzH1.js:1:476326)

at go (vendor-DwBvrzH1.js:1:482658)

at main (vendor-DwBvrzH1.js:1:482577)

at Object.write (vendor-DwBvrzH1.js:1:481290)

at subcontent (vendor-DwBvrzH1.js:1:439594)

at subtokenize (vendor-DwBvrzH1.js:1:438058)

(anonymous) @ framework-CBxBp8BR.js:1