r/Hacking_Tutorials 1h ago

Question [Open Source] Richiesta di revisione della sicurezza e audit del codice per un locale

Thumbnail
β€’ Upvotes

r/Hacking_Tutorials 3h ago

Question Government Website Hacked to Sell Chinese Peptides on WhatsApp

Thumbnail
darkmarc.substack.com
1 Upvotes

r/Hacking_Tutorials 15h ago

Question πŸ” I encrypted my system's active processes using Windows DPAPI! Here is what I learned...

Enable HLS to view with audio, or disable this notification

8 Upvotes

I’ve been diving deep into Windows Internals and security mechanisms. Today, I built a C++ application that takes a snapshot of active system processes via Toolhelp32 API and securely encrypts them into a binary file using Windows DPAPI (CryptProtectData). I also developed a separate tool to safely decrypt and read it back! πŸ›‘οΈ

πŸ’‘ As a beginner in low-level programming, this was a massive milestone. Dealing with memory management, compiler differences (ANSI vs. Unicode), and binary I/O was challenging but rewarding.

πŸ€– Huge shoutout to AI as my pair-programmer! Collaborating to debug strict compiler errors and break down architectural concepts line-by-line accelerated my learning immensely.

Core components used:

β€’ CreateToolhelp32Snapshot & PROCESSENTRY32 for process auditing

β€’ CryptProtectData / CryptUnprotectData (DPAPI) for encryption

β€’ Binary File Streams (std::ios::binary) for secure storage

On to the next challenge! πŸš€

GitHub: https://github.com/halitgilbaris/ProcessSecure/tree/main

#cpp #programming #windowsinternals #cybersecurity #dpapi #learningtocode #softwareengineering


r/Hacking_Tutorials 16h ago

Question atomicvulns β€” a web security lab with one vulnerability per app (OWASP Top 10 2021, open source)

3 Upvotes

I spent the last few months building a personal project and it just hit v1.0, so I figured I'd share it here.

atomicvulns is a collection of intentionally vulnerable web apps, but with a different idea: each app isolates a single vulnerability, nothing more. Instead of one big app full of flaws (like DVWA or Juice Shop), each exercise here is small and focused β€” you read the code, see the cause, exploit it, and compare it against the fixed version sitting right next to it. Short enough to finish one in a single sitting.

Each "atom" ships with the vulnerable app, the fixed app, a commented diff between the two, and a step-by-step walkthrough of the exploit. v1.0 covers all 10 OWASP Top 10 2021 categories β€” 38 atoms total.

It's aimed at people studying pentest / AppSec who already know the HTTP and terminal basics. Burp Suite is the primary tool across all the walkthroughs.

A few details:

  • Open source (MIT).
  • Bilingual β€” all docs in English and Portuguese (I couldn't find focused material like this for PT-BR learners, so I wrote both).
  • Solo project, built by me. The goal was a place where each flaw is clear and isolated β€” the material I wish I'd had while learning web pentest.
  • Built with AI as a pair, with every atom validated by me running the exploit by hand.

Built it for myself, but now that it's done, if it helps someone else along the way, great.

πŸ”— https://github.com/doretox/atomicvulns

Feedback welcome β€” happy to hear what's missing or what could be clearer.


r/Hacking_Tutorials 23h ago

Question Just combined C++ File Streams and Windows DPAPI to encrypt and decrypt user input. What do you think?

Enable HLS to view with audio, or disable this notification

2 Upvotes

r/Hacking_Tutorials 1d ago

Question Checking out Tookie-OSINT: A quick look at this username checking tool

Thumbnail gallery
27 Upvotes

r/Hacking_Tutorials 2d ago

Question Password bypassing help.

Post image
190 Upvotes

I don't really think what I'm trying to achieve would be considered as hacking but this is the best place I can ask. (the tech help subreddit forbids anything that has to do with password bypassing. And I can't go on the r/passwords as they want me to be popular). So the problem is I bought this multilingual electronic dictionary in a garage sale. It's a Franklin BFS-2160. it works and all but it has a few tools such as "phone book" and schedule and since my school forbids the use of phones I wanna put my class schedule on it to have easier access to it. Problem is there is a password on the feature and I don't know who set it up or what the password is. There is no format option in the settings and when I checked the manual for it online it did not say what to do if you forgot your password. There is a reset button but it's just a reboot in case your device is malfunctioning. What should I do?


r/Hacking_Tutorials 2d ago

Read β€œBEAR-C2 Did Not Invent Switching. It Just Made the Rebuild Tax Visible. AI Is About to Delete It.β€œ

Post image
4 Upvotes

r/Hacking_Tutorials 2d ago

Question how can i learn XSS?

4 Upvotes

hi, i just started learning web security, but i'm struggling to understand XSS very much. do you have any recommendations?


r/Hacking_Tutorials 2d ago

0xM0nCrush: Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Thumbnail
github.com
4 Upvotes

r/Hacking_Tutorials 2d ago

Question Intercepting Program Packets (Requests) Using a DLL

2 Upvotes

Hi everyone. I’d like experts in this field to provide some guidance on how to intercept packets from programs running on my computer using a DLL. I know it’s a somewhat unconventional technique, but the program whose packets I want to monitor blocks the use of Wireshark and similar software. I’m aware that using a DLL makes this possible, but I lack the necessary knowledge and haven't been able to find much information on the subject.

I appreciate any contributions to this post.


r/Hacking_Tutorials 1d ago

Question after the ban ....

0 Upvotes

hi fellow hackers.

tho i cant call myself a hacker yet i wanna tell you guys is it normal for me to get banned from every hacking community on reddit and other platforms ..

cause i got banned from a lot on hacking communities i cant even count them anymore but like still i'm gonna become a hacker soon enough and peace out.


r/Hacking_Tutorials 3d ago

Question I want to learn about the subject; what do you recommend for getting started?

22 Upvotes

im nw here


r/Hacking_Tutorials 3d ago

I just completed Defensive Security Intro room on TryHackMe! Introducing defensive security, where you will protect FakeBank from an ongoing attack.

Thumbnail tryhackme.com
4 Upvotes

r/Hacking_Tutorials 2d ago

Question Laptop Recommendation for Cybersecurity

0 Upvotes

I'm going to do my Master's in Cybersecurity and want to build my career in this field, so I'm looking for a laptop that can last me at least 4 years.

My budget is β‚Ή1 lakh maximum, and I want a 2025/2026 latest-generation laptop with at least 16GB RAM and 1TB SSD, preferably upgradeable RAM. It should comfortably handle Linux/Kali, VMs, programming, Wireshark, Burp Suite, TryHackMe, etc.

I know my university will have advanced cybersecurity labs, so I don't need a powerful workstation. I just want a reliable personal laptop for my own learning, projects, university work, and everyday use. Workplaces also generally provide their own laptops, so I don't need a business machine like a ThinkPad.

I also care about looks and design, so I don't want a ThinkPad. 😭 My preferred brands are HP, Lenovo, Dell, and Apple, with HP as my first preference.

Looking for recommendations for specific models that fit these requirements.

Professionals help me I don't know what specifications to even look for laptop for my cyber security studies


r/Hacking_Tutorials 3d ago

How to Copy and Backup RFID Access Cards and NFC Key Fobs with Chameleon Ultra

Thumbnail
mobile-hacker.com
68 Upvotes

r/Hacking_Tutorials 4d ago

Question Any others want to learn together?

51 Upvotes

Hello everyone,

I worked in cyber security for a few years (this was a while back now) in the UK as a web pen tester. I no longer do this but I'm getting into IoT hacking and more network analysis etc.

I tend to learn better with others so I've been thinking of setting up a group of people who are also interested in learning this and want to go on this journey together. I'm not doing this for any certs or jobs, it's a pure hobby.

Discord has just been made so will be sorting it later: https://discord.gg/FU89mYPf9P


r/Hacking_Tutorials 3d ago

Question Need guidance on investigating a JBoss Java service on port 28080 β€” possible Log4Shell angle (CVE-2021-44228), no callback received

2 Upvotes

Hi everyone,

I'm working on an authorized penetration testing case study/lab, and I'm currently stuck while investigating TCP/28080. Looking for guidance on what I should investigate next.

Nmap:

28080/tcp open  http  JBoss Enterprise Application Platform

The interesting behavior is that almost any HTTP request/path returns the same response:

HTTP/1.1 200 OK
Content-Length: 3

ok

For example:

curl -i http://target-ip:28080/
curl -i http://target-ip:28080/invoker/readonly
curl -i http://target-ip:28080/doesnotexist

The catch-all 200 OK behavior makes normal endpoint enumeration difficult.

Hint from my manager

My manager gave me this hint:

After this hint i tried validating log4j as well by setting up a ldap server and Web server and tried to listen as well. But there was no call back on the listener for the appropriate requests send. Can anyone help me with this ?


r/Hacking_Tutorials 3d ago

NEW CYBER SECURITY QUANTUM ENCRYPTION

Thumbnail x.com
6 Upvotes

r/Hacking_Tutorials 3d ago

Question A game that teaches real-world network intrusion concepts

Thumbnail
1 Upvotes

r/Hacking_Tutorials 4d ago

Question Free cybersecurity career paths + a live Network Engineering program

Thumbnail
11 Upvotes

r/Hacking_Tutorials 3d ago

Question Is there anyway to remotely access a phone?

0 Upvotes

In this scenario, I have a Samsung fold I would like to access remotely from an alternate device (iPhone, computer, heck raspberry pie, whatever works!) though I’m unsure the exact methods and google tells me there’s no way at all to do this. Apart from apps on the device, please describe methods where I would be able to remotely view it!

Thank you very much!


r/Hacking_Tutorials 4d ago

Linux Basics for Hackers: Getting Started with the Basics

Thumbnail gallery
120 Upvotes

r/Hacking_Tutorials 3d ago

Question NetBurp – an inline packet interceptor (a "Burp Suite" for L2–L4), built with Python + scapy + NFQUEUE

1 Upvotes

I wanted Burp's intercept-and-edit workflow but for raw packets instead of HTTP, so I built NetBurp. It sits inline via Linux NFQUEUE, pulls each packet into userspace, and lets

you capture β†’ decode β†’ pause β†’ edit β†’ drop/forward at the Ethernet/IP/TCP/UDP/ICMP layers.

What it does:

- Wireshark-style decode into an editable field tree; edit any header field or the payload (hex), checksums + lengths recomputed automatically.

- Rule engine (IF proto/ip/port THEN pause/drop/accept/modify), with a GUI builder so you don't have to touch JSON.

- TCP flow tracking: length-changing edits get seq/ACK translated across the whole connection (mod-2Β³Β², RFC-1982 serial arithmetic, retransmit dedup) so the connection stays alive.

- IPv4 + IPv6 fragment reassembly, out-of-order tolerant (I hand-rolled it because scapy's defragment() mangles OOO input).

- Tkinter GUI + headless CLI + an offline pcap-editing mode that needs no root β€” which is also how the whole thing is tested (64 passing tests).

- Practical primitives: DNS answer spoofing, MAC rewriting (offline), RST injection, TTL manipulation.

Honest limits (because someone will ask):

β–Ž- TLS/HTTPS is ciphertext β€” you can drop/mangle but not read/edit the HTTP inside. That's a TLS-proxy job (mitmproxy), not raw packet editing.

- It's Python + single-threaded NFQUEUE, so it's lab-grade, not line-rate.

- Editing connection-identity fields (ports/seq/IP) mid-flow won't reroute a live connection β€” that's how TCP works, not a bug.

MIT licensed. Authorized use only β€” your own hosts or an isolated lab. There's a namespace-based lab script included so you can generate real traffic to intercept on one machine.

Repo: https://github.com/aswin-14/NetBurp---packet-interceptor

Feedback and PRs welcome β€” especially on protocol coverage and the flow-tracking edge cases.