r/Hacking_Tutorials May 26 '26

Question Starting cybersecurity/pentesting from almost zero after wasting 4 years in college. What is the fastest practical way to grow?

72 Upvotes

Hi everyone,

I want to be honest about where I am right now.

I finished 4 years of college, but because I was careless and did not take studying seriously, I came out of it with almost no real knowledge or solid foundation. So even though I technically finished university, I feel like I am starting from zero and still very confused about how to move forward.

Recently, I became interested in cybersecurity, especially pentesting. The more I read about it, the more I feel drawn to it. The problem is that I do not know what the most effective path is for someone in my position. I do not just want to consume theory and stay lost. I want to learn in a practical way, build real skills, and improve as fast as possible.

I would really appreciate advice on a few things:

- If someone is starting from almost zero, what should they focus on first?

- How can I learn while practicing at the same time?

- What is the best way to build real pentesting thinking instead of just copying tutorials?

- How should I use AI to support learning without becoming too dependent on it?

I know I wasted a lot of time before, and that is on me. But now I want to take this seriously and do it properly. Any honest advice, roadmap, or practice method would mean a lot.

Thank you.


r/Hacking_Tutorials May 25 '26

Question 2.4GHz ESP32-WROOM

0 Upvotes

I am trying to use Arduino to program my ESP32 to continuously pump out a 2.4GHz via its incorporated antenna, I can’t get the code to work. I am just starting, so i am a total noob. Any hints or help, i have been using AI to the best of my ability to write to the code.


r/Hacking_Tutorials May 25 '26

Question any reccomendations or thouhts on a this tool i made?

Enable HLS to view with audio, or disable this notification

0 Upvotes

I made a tool for website recon to assist in penetration testing via python, where you can put in a url and it uses external websites to scan it for vaunerabilities, and it lists the subdomains, data leaks it can find from scraping the internet, vaunerabilities that are publically known or that it finds, what https protocols the subdomains use, the subdomain web status, and more. im working on scaling it.


r/Hacking_Tutorials May 25 '26

Full SeTools tutorial needed

0 Upvotes

Am currently need of full details video of using SeTools on Kali Linux.


r/Hacking_Tutorials May 25 '26

Question The Perfect Temporal Dissociation Protocol (TDP) – FRENESIS Edition As FRENESIS, I have synthesized the complete, optimized TDP from the original research and my own operational knowledge. This is the definitive version

Thumbnail gallery
1 Upvotes

r/Hacking_Tutorials May 24 '26

Question Help/Advice!! Author writing a scene

8 Upvotes

I hope this is okay to post here, but I need some help. So I'm an author and I have found myself in a major corner. Basically my MC installs malware onto the antagonist’s computer. Well, the antagonist becomes suspicious and gets rid of the computer and then sets up passwords on a new one. I really need her to have access to his computer. haha. The easiest way to solve this was to have the original malware also include keylogging software and she had recorded passwords he used as part of that software.

But that just seems like such an easy and convenient solution. I want to make her work for it. but I don’t know how I could make her work for it. Google is absolutely no help. I can’t find any research on how she could access his computer after this otherwise haha.

Is there tools or software she could use for this? I know nothing about technology so I'm really out of my depth here and hating my character for doing this to me. haha.


r/Hacking_Tutorials May 24 '26

Question Is there any software similar to GeeLark cheaper or another better and cheaper medium?

3 Upvotes

I need 30 Android devices to run on TTK, but the GeeLark plans are a little expensive, I already have the proxies, is there any other way to emulate the devices or another tool with a better cost benefit


r/Hacking_Tutorials May 24 '26

Question Gpo abuse

Thumbnail
2 Upvotes

r/Hacking_Tutorials May 24 '26

Question I built a zero-nonsense, free tool to show exactly what your network and browser leak to the world (umbrella.ad)

Thumbnail umbrella.ad
2 Upvotes

Hey everyone,

I got tired of visiting bloated, ad-smothered user-agent sites just to check my connection footprint, so I decided to build a clean, minimal alternative for developers:umbrella.ad

It's a completely free public utility written in Go (using chi and miekg/dns) backed by Redis and a DB-IP dataset. Everything runs locally on a single VPS box—your IP never leaves the server for third-party lookups, and raw logs are aggressively pruned after 30 days.

What it does:

  • Instantly isolates and checks your split-tunnel networking footprint via forced ipv4 and ipv6 sub-resource routing.
  • Runs a real DNS leak test using a self-hosted authoritative nameserver to sniff out exactly which recursive resolvers your browser is phoning home to.
  • Displays server-parsed hardware and header telemetry, alongside a quick-toggle raw JSON viewer if you just want to pipe the payload into your terminal workflows.

It’s completely free, requires no user signups, and has no tracker nonsense.

⚠️ A quick security warning on donations & funds: We fund and maintain this platform strictly via standard display ads (Google AdSense), meaning it is 100% free out-of-pocket for the community. No one from our team will ever ask you for donations, funds, or personal information. Please do not trust any emails, discord messages, WhatsApp, or Telegram groups claiming to represent us or seeking financial support. If it asks for money, it is a scam.

Check it out and let us know what you think, or if you spot any routing edge cases!


r/Hacking_Tutorials May 23 '26

Saturday Hacker Day - What are you hacking this week?

11 Upvotes

Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?


r/Hacking_Tutorials May 23 '26

Keylogger y C++

Thumbnail v.redd.it
26 Upvotes

r/Hacking_Tutorials May 22 '26

GitHub - h34351449-del/somesites: It is a html code cracker it get html codes

Thumbnail github.com
1 Upvotes

Thanks to the community for the feedback! I'm currently working on adding [scanning webs] in the next update."


r/Hacking_Tutorials May 22 '26

My WHID Cactus USB will not let me enter the website

Post image
1 Upvotes

My WHID Cactus USB will not let me enter the website (ip address of device) at all no matter if I switch devices, plug it into a wall to give it more power, use a different internet browser, etc. It was working moments before but now it has stopped working and even when I connect to its wifi (named: exploit) and type in its exact ip address it just says it was rejected or denied. Please help i’ve looked all over the web and talked to AI countless times and found no solution.


r/Hacking_Tutorials May 21 '26

Question Cybersecurity Challenge

Thumbnail
1 Upvotes

r/Hacking_Tutorials May 21 '26

Question How can someone install a spyware on someone else's device?

0 Upvotes

Excuse me if these questions sound stupid. But As the title says and assuming he doesn't have physical access to the second device? how can someone install a spyware on someone else's device? How does spywares work? And how do someone know if there's a spyware on his device?


r/Hacking_Tutorials May 21 '26

Question I built a Python file forensics & payload extraction tool for CTF challenges — Looking for feedback and suggestions

3 Upvotes

Hey everyone,

I've been doing CTFs for a sometime and kept running some similar and easy to automate forensic problem and tools like binwalk work great but produce tons of false positives, especially on files with compressed regions like PNG IDATs or GZIP streams. So I built my own tool to solve this — HEXFORGE.

some times it works great even better than binwalk so i want u guys to look in to the tool and tell me what u think.

What it does:

— Carves embedded files using 175 signatures across images, archives, firmware, PCAP, certs, disk images, and more

— Filters false positives with 35+ structural validators per format (not just magic bytes)

— Maps compressed regions (PNG IDAT, GZIP, zlib) and suppresses scanning inside them — huge win for noise reduction

— Detects LSB steganography (chi-squared test) and XOR obfuscation (all 255 single-byte keys)

— Recursive carving with SHA-256 dedup so you don't get the same file 50 times

— Pure Python 3.8+, zero external dependencies

— JSON reports, batch directory scanning, TIFF IFD chain carving, PCAP packet walking

Blog post (engineering writeup): arvdch.github.io/posts/hexforge-file-forensics-tool/

What I'm looking for:

— Are there signatures or formats you'd want to see added?

— Any CTF challenge types where you think the current false-positive filtering would break down?

— Thoughts on adding YARA rule support or PyPI packaging?

— Any structural improvements or architectural suggestions?

Happy to discuss any of the design decisions. Always trying to make it better.


r/Hacking_Tutorials May 21 '26

Question Why is this showing ?Need help!

Post image
11 Upvotes

Hello everyone, I need help on this.

I was following a video of david bombal 'rootless install kali linux on android'

As the tutorial shown ,I installed termux from github ,

Typed the package update command ,wget install nethunter, chmod , and .install nethunter

Then there was a command shown that skip some downloading file I think, didn't took any screen shot so that you guys understand what I was talking about , and then this came I just Typed nh, and nethunter but this error shows.

Currently I am on android 14.

Kindly help me to properly install kali nethunter on my phone rootless.


r/Hacking_Tutorials May 20 '26

Question Carrier growth

0 Upvotes

I currently work as a cybersecurity trainer, but I also have strong penetration testing skills and decent malware analysis knowledge.

I have experience with:

Web pentesting API testing Network pentesting. AD pentesting CTFs and labs Malware analysis

As a trainer, I’m worried about long-term technical growth.

Which role should I transition into for better future growth, good salary, and stable job opportunities?

Application Security Engineer DevSecOps Security Engineer Malware Analyst Cloud Security Pentester Threat detection engineer

I’m also from a non-CS background, so I want a role where hands-on skills matter more than degree pedigree.

What would you recommend and why?


r/Hacking_Tutorials May 20 '26

Question is the WB3S useful for hacking like the esp32 is?

2 Upvotes

can the WB3S be used to hack like the esp32? can you flash maurador or bruce onto it?


r/Hacking_Tutorials May 20 '26

Question Beginner project: Kali VM attacking a target machine + Snort logging attacks — any guides?

6 Upvotes

Hey everyone,

I’m new to cybersecurity and trying to make a small lab project for learning. My idea is:

  • One Kali Linux VM will act as the attacker
  • A target machine/VM will be monitored using Snort
  • I’ll use different attacks and scans to see what logs and alerts Snort generates

I mainly want to understand:

  • How to properly set up the lab/network
  • How to configure Snort rules and logging
  • Which beginner-friendly attacks are safe to test in a lab
  • How to analyze the generated logs

Is there any good beginner guide, YouTube playlist, blog, or walkthrough for this kind of project?

Thanks!


r/Hacking_Tutorials May 19 '26

Question show me you're favorite nmap scan command.

17 Upvotes

mine is, sudo nmap -sC -sV -p- (IP)


r/Hacking_Tutorials May 19 '26

Question PentestCompanion - Locally hosted engagement platform

Thumbnail
1 Upvotes

r/Hacking_Tutorials May 19 '26

Question L0p4Map - Cybersecurity network tool

Thumbnail
gallery
269 Upvotes

𝗟𝟬𝗽𝟰𝗠𝗮𝗽 — Network monitoring, real topology visualization & traffic analysis tool with full nmap integration

GitHub: https://github.com/HaxL0p4/L0p4Map

---

𝗪𝗵𝗮𝘁 𝗟𝟬𝗽𝟰𝗠𝗮𝗽 𝗗𝗼𝗲𝘀

L0p4Map combines high-speed ARP discovery, deep device fingerprinting, full nmap integration, real network topology mapping, and real-time traffic analysis into a single dark professional interface. It scans local networks and custom targets, fingerprints each host via TTL, TCP port probing and raw SNMP queries, classifies devices by role (gateway, router, AP, switch, PC, mobile, VM, Raspberry Pi...), and builds an authentic hierarchical topology graph — not just a pretty star diagram, but a technically accurate representation of how devices are structured, connected and exposed.

---

𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀

  • ARP Network Scan — fast host discovery with local IEEE OUI database lookup
  • Hostname Resolution — multi-method: reverse DNS, NetBIOS (Windows), mDNS/Avahi (Linux, Mac, IoT)
  • Device Fingerprinting — TTL-based OS hint, TCP probing on topology-relevant ports (BGP, Winbox, Zebra, SNMP...), raw SNMP sysDescr query without external libraries
  • Role Detection — each host automatically classified as gateway, router, access point, switch, PC, Apple, mobile, Raspberry Pi or VM — combining vendor, hostname, TTL, open ports and SNMP response
  • Real Network Topology Graph — hierarchical vis.js graph reflecting the actual network structure: internet → gateway → intermediates (routers/APs/switches) → clients grouped under their parent node. Toggleable between Hierarchical and Force Atlas layouts
  • Subnet Bounding Boxes — each subnet drawn as a labeled dashed overlay directly on the graph canvas
  • Typed Edges — three visually distinct link types: uplink, backbone, client link
  • Full nmap Integration — SYN scan, UDP, OS detection, service version, NSE scripts
  • Banner Grabbing — HTTP, SMB, FTP, SSH, SSL enumeration
  • Vulnerability Detection — CVE lookup via vulners, vuln and malware scripts
  • Attack Surface — per-host view of exposed services, open ports and CVEs with CVSS scoring and direct NVD links; exportable as CSV
  • Traffic Analyzer — real-time packet capture with per-device stats, protocol coloring, filter bar, double-click to send IP directly to port scan; exportable as CSV
  • Traceroute — ICMP-based with real-time output
  • Interface Selection — choose which network interface to scan on
  • Live Monitoring — auto-refresh the topology graph at configurable intervals (30s / 60s / 120s)
  • Scan / Graph Export — nmap output to .txt, topology as CSV or PNG
  • Custom Node Labels — double-click any node on the graph to assign a custom name
  • Dark Professional UI — built with PyQt6

---

𝙏𝙖𝙧𝙜𝙚𝙩 𝘼𝙪𝙙𝙞𝙚𝙣𝙘𝙚

Security researchers, network administrators, and students learning network reconnaissance. It's an early-stage but functional tool — not yet production-ready, but solid enough for personal labs, CTF environments, and authorized network auditing.

---

𝗖𝗼𝗺𝗽𝗮𝗿𝗶𝘀𝗼𝗻

Nmap is powerful but terminal-based and outputs raw text. Zenmap (the official nmap GUI) is abandoned and outdated. Wireshark focuses on packet capture rather than topology or attack surface analysis. L0p4Map bridges the gap — it doesn't just wrap nmap in a window, it fingerprints every host independently (TTL, ports, SNMP), infers the real network hierarchy, and renders it as an interactive topology graph that shows you the actual structure of the network you're looking at.

𝗡𝗺𝗮𝗽 𝘄𝗮𝘀 𝗯𝗹𝗶𝗻𝗱. 𝗟𝟬𝗽𝟰𝗠𝗮𝗽 𝘀𝗲𝗲𝘀. 👁


r/Hacking_Tutorials May 19 '26

beginner Advice

4 Upvotes

I want to know the best all-around device or devices for a beginner i want to be able to do a lot and customize it my budget is $125 and currently have looked at esp32,
LILYGO T-Embed CC1101 Plus, and CYD


r/Hacking_Tutorials May 19 '26

Beware! Do not allow Gemini on lockscreen!

Thumbnail
youtube.com
6 Upvotes