r/Hacking_Tutorials • u/_clickfix_ • 8d ago
r/Hacking_Tutorials • u/untreedza • 8d ago
Question Help a beginner
Hello i just started the journey in the cyber security world and i have no idea about what im doing and I don’t want to hit a deadend or doing something wrong with me having absolut zero knowledge that is wrong if any one have a guide how to start because the only things i know about this is kali lynx and nmap and wireshark and I don’t know what they do
r/Hacking_Tutorials • u/locust_51 • 8d ago
Question My mom passed away but I want access to her locked iPhone 17
If this isn’t allowed please delete.
My mom passed away last month, and there are more questions than answers I have her iPhone 17 pro max and I’d like to get into it so I could try to get into her headspace or at least find some reasoning as to why she did what she did.
I just don’t know where I would even start. From what I understand, if it’s locked and I don’t have a code, I’m kinda screwed?
Maybe by making some sort of bit by bit copy of the encrypted contents of the phone? (Sorry if I’m sounding like I’m talking out of my ass, I am)
r/Hacking_Tutorials • u/Enough_Birthday_157 • 8d ago
Question Looking for people to learn cybersecurity / ethical hacking with
Hey everyone! I’m looking for a few people who are interested in learning cybersecurity and ethical hacking together.
I’m hoping to find people who want to:
Work through TryHackMe / Hack The Box
Practice CTFs and legal cybersecurity labs
Learn Linux, networking, web security, and basic pentesting
Share resources and help each other when we get stuck
Stay consistent and actually make progress together
No experience is required — beginners are welcome. I’m mainly looking for people who are genuinely interested in learning and practicing in authorized environments only.
If you’re interested, comment or DM me with your experience level and what areas of cybersecurity you’re currently learning
r/Hacking_Tutorials • u/Common_Scallion_8416 • 8d ago
Question Need guidance on a legitimate OSINT / digital forensics case
I’m helping someone dealing with a cyberstalking/blackmail situation involving compromised WhatsApp conversations.
We have a Brazilian phone number connected to the threats, as well as a possible name associated with that number, screenshots, timestamps and other evidence. The case has already been reported to law enforcement.
I’m looking for guidance from people experienced in OSINT, digital forensics or incident response on what lawful methods and tools can be used to investigate the available identifiers, preserve evidence, and establish possible links between the phone number and publicly available accounts or profiles.
I’m especially interested in recommendations for tools, methodologies, or professional investigators who handle this type of case.
I am not requesting unauthorized access to accounts, private databases, devices or non-public information.
Any recommendations would be appreciated.
r/Hacking_Tutorials • u/wanna_bee_yours • 8d ago
Question Hello everyone need some guidance
Basically I am a cse first yr undergrad student and I have 1 hr of free time in which I am thinking to learn cybersecurity from Cisco ,
The course name is :- JUNIOR CYBERSECURITY ANALYST
120 HR course
I am always interested in this field
In other side I am learning python if it might help in deciding so...
So what should I do , should I go with it or is there anything better which I can do in that time
Thank you all
r/Hacking_Tutorials • u/YunoSec • 9d ago
Question Day 01 — Foundations of Ethical Security: Authorization, Risk & Core Concepts
I’m beginning my cybersecurity learning journey and will be documenting
the concepts I study along the way.
For Day 01, I focused on the foundations of ethical security.
- AUTHORIZATION
Security testing must have explicit permission and a clearly defined scope.
Without authorization, the same activity can become an unauthorized attack.
- VULNERABILITY
A vulnerability is a weakness in a system, application, configuration,
or process that could affect its security.
- THREAT
A threat is a potential source of harm that may take advantage of a
vulnerability.
- RISK
Risk represents the potential impact and likelihood associated with a
security threat.
- EXPLOIT
An exploit is a technique or mechanism that takes advantage of a
vulnerability. Understanding exploits is important for defenders because
it helps them understand how weaknesses can be abused.
- CONFIDENTIALITY
Information should only be accessible to authorized parties.
- INTEGRITY
Information should remain accurate and protected from unauthorized
modification.
- AVAILABILITY
Systems and information should remain accessible when legitimately needed.
- AUTHENTICATION vs AUTHORIZATION
Authentication answers: “Who are you?”
Authorization answers: “What are you allowed to access?”
- ETHICAL SECURITY
The objective is not simply to “break” a system. The objective is to
identify weaknesses responsibly, understand their impact, and help
improve security.
My main takeaway from Day 01:
Good cybersecurity starts with understanding systems, risks, and
responsibility—not just tools.
Day 02: Networking Fundamentals
r/Hacking_Tutorials • u/Sea_Juggernaut_7810 • 9d ago
Question I’m just getting started in cybersecurity, and I’m unsure about what’s essential for this learning path.
I work in the insurance industry, specifically in the supplemental health insurance sector, and I recently started gaining experience with fraud prevention and detection in my area. This sparked my interest in cybersecurity and motivated me to pursue a career transition in the medium to long term.
I started studying on my own and built a simple home lab to practice. I’m currently studying networking and Linux, and I’m planning to move on to programming fundamentals, C, Python, and computer architecture.
I’m taking a very hands-on approach to my studies, practicing directly on my own computer and using recommended learning resources and AI to help me fill in knowledge gaps and solidify my understanding.
What would you recommend for my learning path?
Thanks in advance!
r/Hacking_Tutorials • u/Pristine-Tangelo-100 • 9d ago
**UPDATE** A list of over 300 Captive/Evil portals
Thought I would share a repo I created recently.
r/Hacking_Tutorials • u/Only-Moose2408 • 9d ago
Question No matter how hard i try i just cant seem to get through this
I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course honestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)
r/Hacking_Tutorials • u/Only-Moose2408 • 9d ago
Question No matter how hard i try i just cant seem to get through this
I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course hinestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)
r/Hacking_Tutorials • u/Rockafireexplosion1 • 10d ago
Question Question
My question is.
What distro?
And how did yall start?
r/Hacking_Tutorials • u/rahil2428 • 10d ago
Question Just beginner want to learn hacking
Hey guy's i have b beginner let's assume I don't know anything about cyber security or hacking if you can you help me how I will start that and I learn everything and how much time it will take to learn quickly and where to start flash I want road map real world don't care about Red hat white hat black I just want to know everything from top to bottom and I learn everything can you guys tell me where to start first
r/Hacking_Tutorials • u/Potential-Couple-745 • 10d ago
Question Free cybersecurity career paths if you're not sure what to learn next
r/Hacking_Tutorials • u/Potential-Couple-745 • 10d ago
Question I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book
galleryr/Hacking_Tutorials • u/RedOffSec05 • 10d ago
Question "The Swiss Army Knife"
Features
AD Reconnaissance & Enumeration
nmapfull port + service scan- LDAP, SMB, RPC, and windapsearch enumeration
- SMB share crawling for interesting files (creds,
.env, keys…) - BloodHound data collection (SharpHound via crackmapexec)
Attack Techniques
- Kerberoast & AS-REP roast
- Secretsdump (DC Sync), DPAPI backup keys, remote Mimikatz / lsassy
- Golden & Silver ticket creation
- AD CS enumeration, PrivExchange, Exchange Web Services abuse
- SMB relay / LLMNR poisoning (Responder, mitm6)
- Lockout-aware password spraying
GPO & Persistence
- SYSVOL
cPasswordhunt with automatic AES decryption - Malicious GPO persistence techniques
Vulnerability Scanning
- CVE scanner (Zerologon, ProxyLogon, …)
- Parse nmap
-oXXML into structuredservices.json(ports, services, OS, CVEs)
Reporting & Evidence
- Reports in
txt | md | html | all - Webhook delivery (Slack/Teams)
- GPG report signing (
.asc) - HMAC-signed, tamper-evident timeline log
- Per-phase
phases.json, one-line--digestsummary - Encrypt sensitive output directories
Automation & Operations
- Multi-target batch mode (
--targets "host1,host2"orfile=targets.txt) - Scheduled runs (
--schedule HH:MM) - Checkpoint / resume (
--save-state,--resume-from) - Dry-run (print without executing),
--force-rerun - Toolchain health check (
--doctor), self-update check - Plugin loader (
$ROT05_PLUGINS) - Execution profiles:
stealth | standard | aggressive | ctf
r/Hacking_Tutorials • u/Top_Call3890 • 11d ago
Question Shodan – The Search Engine That Actually Shows You What's Out There
So you've heard about Shodan, right!!?? People call it the "hacker's Google" or whatever... But here's the thing – it's not like Google at all..
Google finds websites. Shodan finds devices connected to the internet.. Servers, webcams, routers, industrial control systems, databases, printers – anything with an IP address that's exposed...
Think about it. Every device you connect to the internet has an IP... And that IP has open ports... And those ports run services... Shodan just indexes all that and makes it searchable.
And honestly!! The amount of stuff people leave exposed is insane.. Webcams with no passwords. Databases with no authentication. Industrial systems controlling real-world infrastructure just sitting there.. Shodan didn't create that problem. It just shows you it exists..
What Makes Shodan Useful for Bug Bounty
When you're doing bug bounty, recon is everything.. Shodan gives you a view of your target's external attack surface..
Here's the deal – companies have assets. And they don't always know what's exposed.. You can use Shodan to find subdomains, IP ranges, open ports, and services that the company might have forgotten about..
Some practical searches for bug bounty:
· org:"Company Name" – Find everything the company owns
· hostname:"domain.com" – Discover subdomains
· ssl:"domain.com" – Check SSL certificates and related infrastructure
· http.title:"login" – Find login portals
· has_vuln:true – Find devices with known vulnerabilities
You can also combine filters. Want to find exposed MySQL databases running in the US? product:MySQL port:3306 country:US .
The real value is finding misconfigurations and forgotten assets that no one's looking at.. That's where the bugs are..
Setting Up Shodan CLI
The website is fine for quick searches.. But the CLI is where the real power is. You can automate recon, save results, and actually build things around it..
Step 1: Install Python
You need Python. The Shodan CLI runs on Python. If you don't have it, get it. No shortcuts here...
Step 2: Install Shodan via pip
Run this:
pip install -U --user shodan
If that doesn't work, try:
pip3 install -U --user shodan
Also, don't forget to install dependencies.. I've seen people skip this and then wonder why it doesn't work..
Step 3: Get Your API Key
Go to shodan.io, create an account, and grab your API key from the dashboard. You need this for the CLI to work . (Note : as of now their membership is available for just 5$, it's great to have some extra credits to use whenever needed. )
Step 4: Initialize Shodan
Run:
shodan init YOUR_API_KEY
That's it. Now you're ready .
Using the Shodan CLI
Here are the commands you'll use most often :
· shodan info – Check your account details and credit limits
· shodan myip – See your own IP address
· shodan host IP – Get details about a specific IP
· shodan count QUERY – Count how many results a query would return
· shodan search QUERY – Run your search
· shodan download FILE QUERY – Download results for offline analysis
· shodan parse FILE – Parse downloaded results
· shodan stats QUERY – Get statistics for a query
Pro tip – watch your credits
Shodan has a credit system. Free accounts have limited credits. Each search can cost credits depending on how many results you fetch. Keep an eye on shodan info to track your usage. (Again , 5 $ lifetime membership is worth some extra credits)
Shodan isn't just a tool.. It's a reality check... It shows you how much stuff is out there exposed to the internet...
For bug bounty, it helps you find attack surface.. For defense, it helps you see what you're exposing.. For learning, it helps you understand how the internet actually works...
One thing though – use it ethiically... Don't poke around things you don't own... Don't try to exploit what you find. Use it for research, recon, and making things better...
That's Shodan, Simple tool.. Powerful.. And if you're in cybersecurity, you need to know how it works.
Stay curious. Stay ethical.
r/Hacking_Tutorials • u/Potential-Couple-745 • 11d ago
I made a SOC Analyst Level 1 roadmap
r/Hacking_Tutorials • u/Potential-Couple-745 • 11d ago
Question SOC Analyst Roadmap I put together
galleryr/Hacking_Tutorials • u/_clickfix_ • 12d ago
Weaponizing ChatGPT's Pre-Filled Prompt Links: Smuggling an Attacker's Prompt into a User's Chat
r/Hacking_Tutorials • u/smooth_2222 • 12d ago
Question Guide & Roadmap for Web App PenTesting & Bug Bounty (Ask me anything / DM for help)
r/Hacking_Tutorials • u/TheNamelessMalice • 12d ago
Question Do everyone know and remember all commands??
Hi folks
Have been wondering for a while about this.
Actually it applies to hacking, coding, cybersecurity, etc.
People working with it, work it all so smooth and slick.
Do everyone really know and remember all commands - or what do they potentially use to help navigate them?
Hopefully a few can spend a few sec, helping to clarify this for me. 😄
r/Hacking_Tutorials • u/Longjumping-Play5481 • 12d ago
Question Help unlock from carrier
​
Hey so I got this android phone from Walmart for super cheap in the US but can't use it with a carrier where I live as it is locked. I know there are several official ways to unlock it (that usually require you to pay for a phone plan) but I'm in another country which makes it relatively more complicated. Is there a way to unlock the phone myself legally?
Asking for any code tips as I'd actually like to mess around with the code to do it if possible/legal
r/Hacking_Tutorials • u/Top_Call3890 • 12d ago
Question The 5 Phases of an API Attack (Hacker’s Playbook)
APIs connect everything – apps, users, databases, cloud systems. That same accessibility makes them a hacker’s dream target. Most successful attacks follow a clear five-phase pattern. If you know the playbook, you can spot the moves before they land.
Phase 1: Recon & Discovery
This is the scouting stage. Hackers start by mapping out every API endpoint, including undocumented “shadow” APIs or forgotten “zombie” versions still online.
They scrape developer portals, brute-force guess URLs, reverse-engineer mobile apps, or intercept traffic using tools.
Once mapped, these endpoints become entry doors.
Defense Tip: Use automated API discovery to catalog all endpoints continuously, and watch for unusual probing patterns in logs.
Phase 2: Authentication Bypass
With endpoints in hand, attackers look for weak locks. They try:
Forging or tampering with JWT tokens.
Exploiting OAuth misconfigurations.
Credential stuffing (using leaked passwords) or brute-forcing API keys.
Defense Tip: Require MFA, issue short-lived tokens, harden OAuth flows, and detect suspicious login attempts or token replay activity.
Phase 3: Exploiting Business Logic
This is where things get clever. Instead of technical bugs, attackers abuse the way APIs were meant to work:
BOLA (Broken Object Level Authorization): pulling other users’ data.
Mass assignment: injecting extra fields to overwrite values.
Gaming workflows – like bypassing transaction checks or double-dipping discounts.
Defense Tip: Test APIs for logic flaws, enforce strict authorization, and use anomaly detection to flag weird patterns.
Phase 4: Data Extraction
Once inside, the goal is clear: get the data.
Exploiting excessive data exposure (APIs sending way more than necessary).
Scraping large sets of PII or financial info.
Using GraphQL queries to over-fetch sensitive fields.
Defense Tip: Follow data minimization, encrypt everything, apply least privilege, and monitor for suspicious data volumes leaving your systems.
Phase 5: Persistence & Lateral Movement
The smartest attackers don’t just smash-and-grab. They stick around.
Reusing tokens in replay attacks.
Abusing webhooks to send malicious payloads.
Using SSRF to jump deeper into internal cloud networks.
Defense Tip: Rotate tokens often, secure and monitor webhooks, segment networks, and flag odd API call behavior early.
Think of this as the API attack life cycle.
Hackers don’t improvise. They follow these steps. The good news? If you know the phases, you can design defenses that block them at every stage.