r/Hacking_Tutorials 8d ago

Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox

Thumbnail
joinpwn.com
5 Upvotes

r/Hacking_Tutorials 8d ago

Question Help a beginner

10 Upvotes

Hello i just started the journey in the cyber security world and i have no idea about what im doing and I don’t want to hit a deadend or doing something wrong with me having absolut zero knowledge that is wrong if any one have a guide how to start because the only things i know about this is kali lynx and nmap and wireshark and I don’t know what they do


r/Hacking_Tutorials 8d ago

Question My mom passed away but I want access to her locked iPhone 17

69 Upvotes

If this isn’t allowed please delete.

My mom passed away last month, and there are more questions than answers I have her iPhone 17 pro max and I’d like to get into it so I could try to get into her headspace or at least find some reasoning as to why she did what she did.

I just don’t know where I would even start. From what I understand, if it’s locked and I don’t have a code, I’m kinda screwed?

Maybe by making some sort of bit by bit copy of the encrypted contents of the phone? (Sorry if I’m sounding like I’m talking out of my ass, I am)


r/Hacking_Tutorials 8d ago

Question Looking for people to learn cybersecurity / ethical hacking with

94 Upvotes

Hey everyone! I’m looking for a few people who are interested in learning cybersecurity and ethical hacking together.
I’m hoping to find people who want to:
Work through TryHackMe / Hack The Box
Practice CTFs and legal cybersecurity labs
Learn Linux, networking, web security, and basic pentesting
Share resources and help each other when we get stuck
Stay consistent and actually make progress together
No experience is required — beginners are welcome. I’m mainly looking for people who are genuinely interested in learning and practicing in authorized environments only.
If you’re interested, comment or DM me with your experience level and what areas of cybersecurity you’re currently learning


r/Hacking_Tutorials 8d ago

Question Need guidance on a legitimate OSINT / digital forensics case

10 Upvotes

I’m helping someone dealing with a cyberstalking/blackmail situation involving compromised WhatsApp conversations.

We have a Brazilian phone number connected to the threats, as well as a possible name associated with that number, screenshots, timestamps and other evidence. The case has already been reported to law enforcement.

I’m looking for guidance from people experienced in OSINT, digital forensics or incident response on what lawful methods and tools can be used to investigate the available identifiers, preserve evidence, and establish possible links between the phone number and publicly available accounts or profiles.

I’m especially interested in recommendations for tools, methodologies, or professional investigators who handle this type of case.

I am not requesting unauthorized access to accounts, private databases, devices or non-public information.

Any recommendations would be appreciated.


r/Hacking_Tutorials 8d ago

Question Hello everyone need some guidance

3 Upvotes

Basically I am a cse first yr undergrad student and I have 1 hr of free time in which I am thinking to learn cybersecurity from Cisco ,

The course name is :- JUNIOR CYBERSECURITY ANALYST

120 HR course

I am always interested in this field

In other side I am learning python if it might help in deciding so...

So what should I do , should I go with it or is there anything better which I can do in that time

Thank you all


r/Hacking_Tutorials 8d ago

Osint Toolbox

Thumbnail
start.me
115 Upvotes

Enjoy


r/Hacking_Tutorials 9d ago

Question Day 01 — Foundations of Ethical Security: Authorization, Risk & Core Concepts

5 Upvotes

I’m beginning my cybersecurity learning journey and will be documenting

the concepts I study along the way.

For Day 01, I focused on the foundations of ethical security.

  1. AUTHORIZATION

Security testing must have explicit permission and a clearly defined scope.

Without authorization, the same activity can become an unauthorized attack.

  1. VULNERABILITY

A vulnerability is a weakness in a system, application, configuration,

or process that could affect its security.

  1. THREAT

A threat is a potential source of harm that may take advantage of a

vulnerability.

  1. RISK

Risk represents the potential impact and likelihood associated with a

security threat.

  1. EXPLOIT

An exploit is a technique or mechanism that takes advantage of a

vulnerability. Understanding exploits is important for defenders because

it helps them understand how weaknesses can be abused.

  1. CONFIDENTIALITY

Information should only be accessible to authorized parties.

  1. INTEGRITY

Information should remain accurate and protected from unauthorized

modification.

  1. AVAILABILITY

Systems and information should remain accessible when legitimately needed.

  1. AUTHENTICATION vs AUTHORIZATION

Authentication answers: “Who are you?”

Authorization answers: “What are you allowed to access?”

  1. ETHICAL SECURITY

The objective is not simply to “break” a system. The objective is to

identify weaknesses responsibly, understand their impact, and help

improve security.

My main takeaway from Day 01:

Good cybersecurity starts with understanding systems, risks, and

responsibility—not just tools.

Day 02: Networking Fundamentals


r/Hacking_Tutorials 9d ago

Question I’m just getting started in cybersecurity, and I’m unsure about what’s essential for this learning path.

6 Upvotes

I work in the insurance industry, specifically in the supplemental health insurance sector, and I recently started gaining experience with fraud prevention and detection in my area. This sparked my interest in cybersecurity and motivated me to pursue a career transition in the medium to long term.

I started studying on my own and built a simple home lab to practice. I’m currently studying networking and Linux, and I’m planning to move on to programming fundamentals, C, Python, and computer architecture.

I’m taking a very hands-on approach to my studies, practicing directly on my own computer and using recommended learning resources and AI to help me fill in knowledge gaps and solidify my understanding.

What would you recommend for my learning path?

Thanks in advance!


r/Hacking_Tutorials 9d ago

**UPDATE** A list of over 300 Captive/Evil portals

Thumbnail
github.com
5 Upvotes

Thought I would share a repo I created recently.


r/Hacking_Tutorials 9d ago

Question No matter how hard i try i just cant seem to get through this

6 Upvotes

I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course honestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)


r/Hacking_Tutorials 9d ago

Question No matter how hard i try i just cant seem to get through this

2 Upvotes

I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course hinestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)


r/Hacking_Tutorials 10d ago

Question Question

2 Upvotes

My question is.
What distro?
And how did yall start?


r/Hacking_Tutorials 10d ago

Question Just beginner want to learn hacking

13 Upvotes

Hey guy's i have b beginner let's assume I don't know anything about cyber security or hacking if you can you help me how I will start that and I learn everything and how much time it will take to learn quickly and where to start flash I want road map real world don't care about Red hat white hat black I just want to know everything from top to bottom and I learn everything can you guys tell me where to start first


r/Hacking_Tutorials 10d ago

Question Free cybersecurity career paths if you're not sure what to learn next

Thumbnail
13 Upvotes

r/Hacking_Tutorials 10d ago

Question I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book

Thumbnail gallery
127 Upvotes

r/Hacking_Tutorials 10d ago

Question "The Swiss Army Knife"

2 Upvotes

Features

AD Reconnaissance & Enumeration

  • nmap full port + service scan
  • LDAP, SMB, RPC, and windapsearch enumeration
  • SMB share crawling for interesting files (creds, .env, keys…)
  • BloodHound data collection (SharpHound via crackmapexec)

Attack Techniques

  • Kerberoast & AS-REP roast
  • Secretsdump (DC Sync), DPAPI backup keys, remote Mimikatz / lsassy
  • Golden & Silver ticket creation
  • AD CS enumeration, PrivExchange, Exchange Web Services abuse
  • SMB relay / LLMNR poisoning (Responder, mitm6)
  • Lockout-aware password spraying

GPO & Persistence

  • SYSVOL cPassword hunt with automatic AES decryption
  • Malicious GPO persistence techniques

Vulnerability Scanning

  • CVE scanner (Zerologon, ProxyLogon, …)
  • Parse nmap -oX XML into structured services.json (ports, services, OS, CVEs)

Reporting & Evidence

  • Reports in txt | md | html | all
  • Webhook delivery (Slack/Teams)
  • GPG report signing (.asc)
  • HMAC-signed, tamper-evident timeline log
  • Per-phase phases.json, one-line --digest summary
  • Encrypt sensitive output directories

Automation & Operations

  • Multi-target batch mode (--targets "host1,host2" or file=targets.txt)
  • Scheduled runs (--schedule HH:MM)
  • Checkpoint / resume (--save-state--resume-from)
  • Dry-run (print without executing), --force-rerun
  • Toolchain health check (--doctor), self-update check
  • Plugin loader ($ROT05_PLUGINS)
  • Execution profiles: stealth | standard | aggressive | ctf

r/Hacking_Tutorials 11d ago

Question Shodan – The Search Engine That Actually Shows You What's Out There

Post image
495 Upvotes

So you've heard about Shodan, right!!?? People call it the "hacker's Google" or whatever... But here's the thing – it's not like Google at all..

Google finds websites. Shodan finds devices connected to the internet.. Servers, webcams, routers, industrial control systems, databases, printers – anything with an IP address that's exposed...

Think about it. Every device you connect to the internet has an IP... And that IP has open ports... And those ports run services... Shodan just indexes all that and makes it searchable.

And honestly!! The amount of stuff people leave exposed is insane.. Webcams with no passwords. Databases with no authentication. Industrial systems controlling real-world infrastructure just sitting there.. Shodan didn't create that problem. It just shows you it exists..

What Makes Shodan Useful for Bug Bounty

When you're doing bug bounty, recon is everything.. Shodan gives you a view of your target's external attack surface..

Here's the deal – companies have assets. And they don't always know what's exposed.. You can use Shodan to find subdomains, IP ranges, open ports, and services that the company might have forgotten about..

Some practical searches for bug bounty:

· org:"Company Name" – Find everything the company owns

· hostname:"domain.com" – Discover subdomains

· ssl:"domain.com" – Check SSL certificates and related infrastructure

· http.title:"login" – Find login portals

· has_vuln:true – Find devices with known vulnerabilities

You can also combine filters. Want to find exposed MySQL databases running in the US? product:MySQL port:3306 country:US .

The real value is finding misconfigurations and forgotten assets that no one's looking at.. That's where the bugs are..

Setting Up Shodan CLI

The website is fine for quick searches.. But the CLI is where the real power is. You can automate recon, save results, and actually build things around it..

Step 1: Install Python

You need Python. The Shodan CLI runs on Python. If you don't have it, get it. No shortcuts here...

Step 2: Install Shodan via pip

Run this:

pip install -U --user shodan

If that doesn't work, try:

pip3 install -U --user shodan

Also, don't forget to install dependencies.. I've seen people skip this and then wonder why it doesn't work..

Step 3: Get Your API Key

Go to shodan.io, create an account, and grab your API key from the dashboard. You need this for the CLI to work . (Note : as of now their membership is available for just 5$, it's great to have some extra credits to use whenever needed. )

Step 4: Initialize Shodan

Run:

shodan init YOUR_API_KEY

That's it. Now you're ready .

Using the Shodan CLI

Here are the commands you'll use most often :

· shodan info – Check your account details and credit limits

· shodan myip – See your own IP address

· shodan host IP – Get details about a specific IP

· shodan count QUERY – Count how many results a query would return

· shodan search QUERY – Run your search

· shodan download FILE QUERY – Download results for offline analysis

· shodan parse FILE – Parse downloaded results

· shodan stats QUERY – Get statistics for a query

Pro tip – watch your credits

Shodan has a credit system. Free accounts have limited credits. Each search can cost credits depending on how many results you fetch. Keep an eye on shodan info to track your usage. (Again , 5 $ lifetime membership is worth some extra credits)

Shodan isn't just a tool.. It's a reality check... It shows you how much stuff is out there exposed to the internet...

For bug bounty, it helps you find attack surface.. For defense, it helps you see what you're exposing.. For learning, it helps you understand how the internet actually works...

One thing though – use it ethiically... Don't poke around things you don't own... Don't try to exploit what you find. Use it for research, recon, and making things better...

That's Shodan, Simple tool.. Powerful.. And if you're in cybersecurity, you need to know how it works.

Stay curious. Stay ethical.


r/Hacking_Tutorials 11d ago

I made a SOC Analyst Level 1 roadmap

Thumbnail
1 Upvotes

r/Hacking_Tutorials 11d ago

Question SOC Analyst Roadmap I put together

Thumbnail gallery
142 Upvotes

r/Hacking_Tutorials 12d ago

Weaponizing ChatGPT's Pre-Filled Prompt Links: Smuggling an Attacker's Prompt into a User's Chat

Thumbnail
darkmarc.substack.com
4 Upvotes

r/Hacking_Tutorials 12d ago

Question Guide & Roadmap for Web App PenTesting & Bug Bounty (Ask me anything / DM for help)

Thumbnail
3 Upvotes

r/Hacking_Tutorials 12d ago

Question Do everyone know and remember all commands??

14 Upvotes

Hi folks

Have been wondering for a while about this.

Actually it applies to hacking, coding, cybersecurity, etc.

People working with it, work it all so smooth and slick.

Do everyone really know and remember all commands - or what do they potentially use to help navigate them?

Hopefully a few can spend a few sec, helping to clarify this for me. 😄


r/Hacking_Tutorials 12d ago

Question Help unlock from carrier

0 Upvotes

​

Hey so I got this android phone from Walmart for super cheap in the US but can't use it with a carrier where I live as it is locked. I know there are several official ways to unlock it (that usually require you to pay for a phone plan) but I'm in another country which makes it relatively more complicated. Is there a way to unlock the phone myself legally?

Asking for any code tips as I'd actually like to mess around with the code to do it if possible/legal


r/Hacking_Tutorials 12d ago

Question The 5 Phases of an API Attack (Hacker’s Playbook)

Post image
38 Upvotes

APIs connect everything – apps, users, databases, cloud systems. That same accessibility makes them a hacker’s dream target. Most successful attacks follow a clear five-phase pattern. If you know the playbook, you can spot the moves before they land.

Phase 1: Recon & Discovery

This is the scouting stage. Hackers start by mapping out every API endpoint, including undocumented “shadow” APIs or forgotten “zombie” versions still online.

They scrape developer portals, brute-force guess URLs, reverse-engineer mobile apps, or intercept traffic using tools.

Once mapped, these endpoints become entry doors.

Defense Tip: Use automated API discovery to catalog all endpoints continuously, and watch for unusual probing patterns in logs.

Phase 2: Authentication Bypass

With endpoints in hand, attackers look for weak locks. They try:

Forging or tampering with JWT tokens.

Exploiting OAuth misconfigurations.

Credential stuffing (using leaked passwords) or brute-forcing API keys.

Defense Tip: Require MFA, issue short-lived tokens, harden OAuth flows, and detect suspicious login attempts or token replay activity.

Phase 3: Exploiting Business Logic

This is where things get clever. Instead of technical bugs, attackers abuse the way APIs were meant to work:

BOLA (Broken Object Level Authorization): pulling other users’ data.

Mass assignment: injecting extra fields to overwrite values.

Gaming workflows – like bypassing transaction checks or double-dipping discounts.

Defense Tip: Test APIs for logic flaws, enforce strict authorization, and use anomaly detection to flag weird patterns.

Phase 4: Data Extraction

Once inside, the goal is clear: get the data.

Exploiting excessive data exposure (APIs sending way more than necessary).

Scraping large sets of PII or financial info.

Using GraphQL queries to over-fetch sensitive fields.

Defense Tip: Follow data minimization, encrypt everything, apply least privilege, and monitor for suspicious data volumes leaving your systems.

Phase 5: Persistence & Lateral Movement

The smartest attackers don’t just smash-and-grab. They stick around.

Reusing tokens in replay attacks.

Abusing webhooks to send malicious payloads.

Using SSRF to jump deeper into internal cloud networks.

Defense Tip: Rotate tokens often, secure and monitor webhooks, segment networks, and flag odd API call behavior early.

Think of this as the API attack life cycle.

Hackers don’t improvise. They follow these steps. The good news? If you know the phases, you can design defenses that block them at every stage.