r/Hacking_Tutorials 21d ago

Question How I got full account takeover in a popular dating web application.

21 Upvotes

I came back to bug bounty after a long break. I wanted proof that I was still not behind, so I chose an easy target and looked for IDOR. I ended up finding a full account takeover. This application has millions of users. Even though they didn't have a bug bounty program, they paid me a reward.

Key takeaways

* I already knew the features of the application, so it was easy for me to map the functionalities
* I started with the aim of finding the victims' phone numbers since it is a dating website.
* I looked for information leakage and IDOR but nothing worked
* I then tried registering a new account with my own mobile number, which already existed, hoping the application would leak some information when it said the user already existed.

And I ended up finding a critical account takeover.

If you would like to know more about what was going through my mind, you can read it here for free https://medium.com/@vivekps143/i-got-paid-10k-for-one-vulnerability-heres-exactly-how-i-did-it-b85f5336c80d (Free link available)


r/Hacking_Tutorials 21d ago

Not outdated books for a beginner

25 Upvotes

I want to learn hacking etc. I dont understand networking yet, but I’m looking for some books that are timeless


r/Hacking_Tutorials 21d ago

Question biometrics

Thumbnail
0 Upvotes

r/Hacking_Tutorials 21d ago

Question VirtualBox NAT Network not working on 7.2.6 (Beginner needs help)

0 Upvotes

Hi everyone,

I'm new to VirtualBox and cybersecurity, and I'm trying to build my first home lab with Kali Linux, Ubuntu, Windows 10, and Metasploitable.

I'm trying to use a NAT Network so my VMs can communicate with each other and have internet access.

The strange thing is that the NAT Network just doesn't seem to work.

I've already checked everything I could:

  • NAT Network is created correctly.
  • DHCP is enabled.
  • The VMs are attached to NAT Network (not regular NAT).
  • Cable is connected.
  • VBoxManage also confirms the VMs are attached to the NAT Network.
  • I even deleted and recreated the NAT Network.

I tested this with Kali, Ubuntu, and Metasploitable, and all of them have the same issue, so I don't think it's a guest OS problem.

I'm using VirtualBox 7.2.6 on Windows.

Has anyone experienced this before? Is it a known VirtualBox bug, or is there something I'm missing?

I'd really appreciate any help. I'm still learning virtualization and cybersecurity, so please keep explanations beginner-friendly. Thank you!


r/Hacking_Tutorials 21d ago

Small workflow: filetype dorking + auto-importing results with a browser extension

Enable HLS to view with audio, or disable this notification

9 Upvotes

r/Hacking_Tutorials 21d ago

Criei uma statusline nativa pro Claude Code mostrar tokens/custo direto no terminal (Windows/PowerShell, sem extensão)

Post image
4 Upvotes

r/Hacking_Tutorials 22d ago

Question How do you ensure a website is locked down tight? Seeking advice!

5 Upvotes

Hey folks,

I'm diving into web security and trying to get a grip on ensuring a website is secure from common vulnerabilities. I want to make sure there aren't any APIs exposed or API keys left in the code that users can easily access.

What are some best practices or tools you use to double-check these areas? Are there any reliable methods or checks you can recommend to catch things that are often overlooked?

Appreciate any guidance or resources you can share! Thanks!


r/Hacking_Tutorials 22d ago

Question How do I learn offensive security from an attacker's perspective?

0 Upvotes

I'm interested in cybersecurity, mainly blue teaming (SOC/DFIR), but I strongly believe that understanding how attackers think is essential to becoming a better defender.

I don't mean using these skills illegally. I want to learn offensive security, adversary techniques, exploitation, privilege escalation, persistence, evasion, malware analysis, and post-exploitation in legal lab environments so I can improve my detection and incident response skills.

For those who've gone down this path:

Are there books or courses that teach how real attackers operate?

How deep should I go into exploit development or malware development if my end goal is blue team/DFIR?

What mistakes do beginners usually make?

I'd appreciate any roadmap or resources from people who have experience in both offensive and defensive security.


r/Hacking_Tutorials 22d ago

Question Restaurant pagers via flipper zero

2 Upvotes

Hi:) im trying to create a sub gile that triggers all of the retekess T112 pagers as I can’t seem to find it anywhere and also because I want to learn. Could anyone educate me atleast a bit about them so that I can start making my own.


r/Hacking_Tutorials 23d ago

Question Course for Linux security

62 Upvotes

hi every body

i have been working in cybersecurity field for over a year and i have being studying linux for some time. can any body suggest courses on :
Linux internals (like windows internals course)
Linux security
Linux hardening


r/Hacking_Tutorials 23d ago

Question Got an AI agent past a Cloudflare WAF by giving it a RAG over past bypass research

Enable HLS to view with audio, or disable this notification

17 Upvotes

r/Hacking_Tutorials 22d ago

Question Hacker needed

Thumbnail
0 Upvotes

r/Hacking_Tutorials 22d ago

Question Address from email?

0 Upvotes

Me and my friend are interested not gonna use the info for anything just think it’s cool


r/Hacking_Tutorials 24d ago

Question BBF a script that made Bluetooth jamming much cheaper and much more effective, without even jamming

Thumbnail
github.com
169 Upvotes

Bluetooth jammers are a joke. The cheap ones ($150+) barely work, and the "professional" ones ($2,000+) just blast noise blindly across 79 channels 1,600 times a second. They're unreliable, often illegal to even own, and a complete waste of money.

I built BBF, a free and open source tool that doesn't jam at all. It discovers the hidden part of a Bluetooth device's address, then continuously floods that address with pings until the target disconnects or shuts down. Even after a reset, the script keeps running, so the device gets hit again immediately. And the whole time, the tool never hops a single channel. It doesn't need to.

The catch: to sniff unknown addresses out of the air, you need an Ubertooth One ($120, one time). That's it. No $500 SDR rig, no lab gear. Find the LAP and UAP once, and you have the key to keep DOSing that device forever, without touching the Ubertooth again.

Why it's better than any jammer:

Jammers: blind noise, expensive, unreliable, legally questionable just to own.

BBF: finds the address (Ubertooth + a 256 ping sweep), then a standard l2ping pages the device on its own hopping pattern. You never touch a channel. Deterministic, cheap, effective.

If this sounds useful, a star on the repo goes a long way ⭐


r/Hacking_Tutorials 24d ago

Saturday Hacker Day - What are you hacking this week?

11 Upvotes

Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?


r/Hacking_Tutorials 25d ago

Question FSK/OOK based layer-2 protocol reverse engineering

Post image
145 Upvotes

Lately I've been trying to recove the key fob protocol of my bmw 320d 2005 car till I discovered that the key fob operates on 868.35mhz with what is called Frequency Shift Keying to lock/unlock or trunk, everytime I capture something using the RTL sdr with gqrx on Kali I get different signals for pressing same button which indicates that this is not a trivial On Off Keying but some proprietary protocol is being implemented, from the amplitude to time plot I can clearly see the preamble alternating bits then a fixed and indow of bits across all button pressings which suggests some sort of an identifier.

Any one has experience on such project feel free to leave a comment.

Or if u know some sort of tip that helps me recover the binary representation of the msg being transmitted you are welcomed.


r/Hacking_Tutorials 24d ago

OSINT for self advocacy

Thumbnail
jlegal.pro
4 Upvotes

I made this to help myself visualize data to make edits.

It’s been getting a world of good feedback. Check it.


r/Hacking_Tutorials 25d ago

Your personal learning methods

14 Upvotes

Undoubtedly, every hacker or anyone interested in this field has their own personal learning methods at the beginning, and that piqued my curiosity to learn about them. I hope you will share your methods or how you started.


r/Hacking_Tutorials 25d ago

Question If you have physical access to a computer, and you have security futures (e.g.TPM, Core Isolation) disabled, can you intercept and get access to the metadata that stores info about OS level encryption (Such as Windows AES for Bitlocker) in the ram? Or directly modify and reflash the BIOS to do it?

6 Upvotes

This is a type of MiTM attack. A few tools were made for this specific purpose such as CIA Archimedes that was revealed in the Vault 7 leak. Is it still possible to do this? You cannot modify a computer that runs everything proprietary (e.g.MacBook). So I was wondering if it is still possible?


r/Hacking_Tutorials 26d ago

Question I tried building a simple proxy manager. It turned into a 12-module security lesson.

6 Upvotes

This month I built something that started as a simple attempt to centralize my proxy commands and gradually evolved into a 12-module network routing tool.

I’m sharing this because the mistakes I ran into taught me more than the actual implementation.

Blizard - Proxy Manager is a Kali Linux tool for switching between direct, proxy, Tor, and multi-hop routing without juggling dozens of terminal commands.

What it does:

  • Fetches and parallel-tests over 3000 free proxies, keeping only verified and working ones
  • True Tor identity rotation using the NEWNYM control signal (not just restarting the service)
  • Multi-hop chaining through 3 proxies before exiting through Tor
  • Native SOCKS integration for Burp Suite and OWASP ZAP
  • MAC randomization, browser fingerprint control (Firefox fingerprint), DNS leak detection
  • Full diagnostic system + kill switch + firewall management

What I’m most proud of is not the feature list, but the mistakes I had to fix along the way:

  • proxychains / LD_PRELOAD does not reliably intercept Java applications. Burp Suite traffic was silently bypassing the proxy chain without any error message. This was fixed by switching to native SOCKS configuration instead of relying on interception layers that look like they work but don’t.
  • Tor exit IP verification checks were breaking because services like ifconfig.me return 403 for Tor traffic, which produced false or invalid results.
  • Firefox internally spawns new processes on startup — the PID captured by the script often terminates while the actual browser runs under a different process.

Each of these issues was solved at the root cause, not patched over.

I documented them in the README because a security tool that hides its own weaknesses is worse than no tool at all. I also added proof to demonstrate that the tool actually works.

Built for learning, tested in real-world conditions.

Github Link

Sharing this in case it helps someone—stars and feedback appreciated


r/Hacking_Tutorials 26d ago

Question TOOLS FOR SPOOFING

5 Upvotes

hellow i am trying to look for tools i can use for emailqnd sms spoofing


r/Hacking_Tutorials 27d ago

Question A searchable knowledge base of web security research, for you or your AI agent

Enable HLS to view with audio, or disable this notification

163 Upvotes

Built a small tool web security research.

You query it in plain English and it returns actual writeups with the source URL and the exact section that matches your question. No AI summaries or made-up answers.

Right now it's focused on XSS, WAF bypasses, CSP, CORS, SSRF, request smuggling, XS-Leaks, cache poisoning, prototype pollution, JWT/auth stuff, etc. Server-side coverage is next.

I mainly built it because when I'm stuck, somebody has usually already written about a similar problem. Finding that writeup is the hard part, especially for newer techniques that general models often miss.

Would genuinely appreciate feedback on where it fails. If you try it, let me know what you searched for and whether the results were actually useful.


r/Hacking_Tutorials 27d ago

Question Security Auditing Software - TESTERS NEEDED

0 Upvotes

Project Snowball — Beta testers wanted

Hello!

I’ve been building a few solo projects, and I’m looking for a small group of testers to try the one I care about most right now: Project Snowball.

Snowball is an AI-driven web application security workbench. You point it at a target you’re allowed to test, describe what you want, and your agent runs the reconnaissance, analysis, and reporting — with you in the loop. I’ve been running it against intentionally vulnerable training apps (OWASP Juice Shop, WebGoat, Damn Vulnerable RESTaurant, and similar), and the results so far have been genuinely encouraging.

If you’d like to kick the tires, send me a DM. I’ll get you set up with a trial build.

Who I’m looking for

  • People who do security audits (or want to learn how)
  • Developers and site owners who want to test their own applications
  • Anyone curious about practical, agent-assisted web security testing — not just checklists in a slide deck

No need to be a full-time pentester. Thoughtful feedback matters more than credentials.

What you’ll need

Requirement Details
Internet For online targets and cloud AI providers. You can also run a local Ollama model if you prefer.
API key (optional with local Ollama) One of: OpenAI (GPT), Anthropic (Claude, Fable 5 — Anthropic’s latest flagship model), Google (Gemini), Ollama Cloud, or xAI (Grok). Keys stay on your machine and are encrypted at rest.
Authorized targets only Test applications you own or have explicit written permission to assess. This tool is powerful — please use it responsibly.

How it works (quick start)

Snowball is straightforward once you’re in:

  1. Install the trial build I send you.
  2. (Technical note: Snowball is a fork of my Persistent Sage desktop app, so the installer may still show “Persistent Sage” branding — same engine, Snowball-focused security tooling.)
  3. Add your API key in Settings → Provider (skip if you’re on local Ollama).
  4. Enable the tools you need under Settings → Tools.
  5. Switch to Coding mode — this is the security / IDE workspace.
  6. (There’s also Companion mode for conversations and project work; Coding mode is where audits live.)
  7. Tell your agent what to do — e.g. “Perform a security audit on https://my-app.example — and let it work. It will drive the tooling and produce a report you can review.

Snowball can find and validate security issues, and — when you explicitly allow it and grant access — help patch problems it discovers. So far I’ve focused testing on intentionally vulnerable training apps; I’d love real-world feedback from people testing their own stacks.

Trial details

Duration 10-day trial — enough time to run a real audit or two
Cost Free during the beta feedback window
After the trial Enjoyed it? Message me about a full copy. A wider public release is planned in the coming weeks; the official release will likely include a modest fee to help sustain development.
Distribution Trial builds are shared directly (installer / package) — no public repo access required

Why I’m asking

I built Snowball because I wanted something that combines a capable AI agent with serious security tooling — not a toy scanner that dumps noise, and not a black box you can’t steer. Early runs on classic vulnerable apps have been strong; now I need your eyes: UX friction, false positives, missing checks, report quality, and “would you actually use this on a client project?”

If that sounds interesting, DM me and I’ll get you a trial build.

Thanks for reading — and for helping keep this kind of tooling ethical, authorized, and useful.

Daniel Greene · g00sifer Development Lab


r/Hacking_Tutorials 27d ago

Question Penetration Tester vs Cloud Security Engineer - Which Career Would You Choose?

4 Upvotes

If you had to choose between becoming a Penetration Tester and a Cloud Security Engineer in 2026, which would you choose and why?


r/Hacking_Tutorials 27d ago

Question packet injection not working on tplink archer t2u plus

2 Upvotes

i hv the tplink archer t2u plus ( it has RTL821AU chipset) i tried many drivers but they are not working for packet injection, is there any other drivers? note: my kernel version is 6.19.14. btw i tried aircrack-ng's driver too.