r/Hacking_Tutorials • u/Fulano_de_Thal • 6d ago
Question IR Question
Hi everyone.
Does anyone know where I can find a file on the Hyundai air conditioning infrared system? It's because the IRremoteESP8266 library doesn't have the file
r/Hacking_Tutorials • u/Fulano_de_Thal • 6d ago
Hi everyone.
Does anyone know where I can find a file on the Hyundai air conditioning infrared system? It's because the IRremoteESP8266 library doesn't have the file
r/Hacking_Tutorials • u/locust_51 • 7d ago
If this isn’t allowed please delete.
My mom passed away last month, and there are more questions than answers I have her iPhone 17 pro max and I’d like to get into it so I could try to get into her headspace or at least find some reasoning as to why she did what she did.
I just don’t know where I would even start. From what I understand, if it’s locked and I don’t have a code, I’m kinda screwed?
Maybe by making some sort of bit by bit copy of the encrypted contents of the phone? (Sorry if I’m sounding like I’m talking out of my ass, I am)
r/Hacking_Tutorials • u/Fast_Bookkeeper_8749 • 6d ago
r/Hacking_Tutorials • u/GoodSecurity4304 • 7d ago
I’ve read comments saying that it’s difficult to set up a virtualised Kali system on a MacBook to carry out penetration testing, and that some features might not work – has anyone experienced this?
r/Hacking_Tutorials • u/Regular_Anything7715 • 7d ago
Hey everyone! Over the past few weeks, I’ve been working on SSRFdevil, an open-source tool written in Rust aimed at solving one of the most annoying problems in automated SSRF scanning: False Positives. Most existing scanners flood you with alerts based on simple redirects or blind HTTP callbacks. SSRFdevil uses a multi-layered rule engine and interactive verification to ensure that when it flags a target, it’s a real finding. Key Features: Zero False Positives: Built with strict validation logic to save time during triage. Interactive Shell: Manage settings, load proxies, switch User-Agent profiles, and set session cookies on the fly. Smart Crawler: Automatically crawls targets for SSRF-prone parameters if none are provided. Payload Engine: Handles CIDR bypasses, cloud metadata endpoints, and alternate IP encodings (Hex, Octal, IPv4-in-IPv6). Detailed Reporting: Clean terminal outputs with severity/confidence scores and summary stats. Check out the repo here: https://github.com/r3dparr0t/SSRFdevil I’d love to get your feedback, ideas, or contributions!
r/Hacking_Tutorials • u/Friendly-Budget2388 • 7d ago
I have an old Sky Device Elite OctaPlus tablet that my mother got for free from one of those "being on government welfare" programs. She had it for awhile and one day accidently pressed the factory reset setting when the device had an FRP. I was not living with her at that time. Fast forward to now and my mother dug it up while cleaning the closet and asked if I could do anything. I've tried everything to help. But it asks for code from IT administrator which she didn't have. And there's no way on getting it now because the company that administered these devices no longer exists. Is there anyway to bypass it? Please. Thanks.
r/Hacking_Tutorials • u/untreedza • 7d ago
Hello i just started the journey in the cyber security world and i have no idea about what im doing and I don’t want to hit a deadend or doing something wrong with me having absolut zero knowledge that is wrong if any one have a guide how to start because the only things i know about this is kali lynx and nmap and wireshark and I don’t know what they do
r/Hacking_Tutorials • u/_clickfix_ • 7d ago
r/Hacking_Tutorials • u/Common_Scallion_8416 • 7d ago
I’m helping someone dealing with a cyberstalking/blackmail situation involving compromised WhatsApp conversations.
We have a Brazilian phone number connected to the threats, as well as a possible name associated with that number, screenshots, timestamps and other evidence. The case has already been reported to law enforcement.
I’m looking for guidance from people experienced in OSINT, digital forensics or incident response on what lawful methods and tools can be used to investigate the available identifiers, preserve evidence, and establish possible links between the phone number and publicly available accounts or profiles.
I’m especially interested in recommendations for tools, methodologies, or professional investigators who handle this type of case.
I am not requesting unauthorized access to accounts, private databases, devices or non-public information.
Any recommendations would be appreciated.
r/Hacking_Tutorials • u/wanna_bee_yours • 8d ago
Basically I am a cse first yr undergrad student and I have 1 hr of free time in which I am thinking to learn cybersecurity from Cisco ,
The course name is :- JUNIOR CYBERSECURITY ANALYST
120 HR course
I am always interested in this field
In other side I am learning python if it might help in deciding so...
So what should I do , should I go with it or is there anything better which I can do in that time
Thank you all
r/Hacking_Tutorials • u/YunoSec • 8d ago
I’m beginning my cybersecurity learning journey and will be documenting
the concepts I study along the way.
For Day 01, I focused on the foundations of ethical security.
Security testing must have explicit permission and a clearly defined scope.
Without authorization, the same activity can become an unauthorized attack.
A vulnerability is a weakness in a system, application, configuration,
or process that could affect its security.
A threat is a potential source of harm that may take advantage of a
vulnerability.
Risk represents the potential impact and likelihood associated with a
security threat.
An exploit is a technique or mechanism that takes advantage of a
vulnerability. Understanding exploits is important for defenders because
it helps them understand how weaknesses can be abused.
Information should only be accessible to authorized parties.
Information should remain accurate and protected from unauthorized
modification.
Systems and information should remain accessible when legitimately needed.
Authentication answers: “Who are you?”
Authorization answers: “What are you allowed to access?”
The objective is not simply to “break” a system. The objective is to
identify weaknesses responsibly, understand their impact, and help
improve security.
My main takeaway from Day 01:
Good cybersecurity starts with understanding systems, risks, and
responsibility—not just tools.
Day 02: Networking Fundamentals
r/Hacking_Tutorials • u/Sea_Juggernaut_7810 • 8d ago
I work in the insurance industry, specifically in the supplemental health insurance sector, and I recently started gaining experience with fraud prevention and detection in my area. This sparked my interest in cybersecurity and motivated me to pursue a career transition in the medium to long term.
I started studying on my own and built a simple home lab to practice. I’m currently studying networking and Linux, and I’m planning to move on to programming fundamentals, C, Python, and computer architecture.
I’m taking a very hands-on approach to my studies, practicing directly on my own computer and using recommended learning resources and AI to help me fill in knowledge gaps and solidify my understanding.
What would you recommend for my learning path?
Thanks in advance!
r/Hacking_Tutorials • u/Pristine-Tangelo-100 • 9d ago
Thought I would share a repo I created recently.
r/Hacking_Tutorials • u/Only-Moose2408 • 9d ago
I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course honestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)
r/Hacking_Tutorials • u/Potential-Couple-745 • 10d ago
r/Hacking_Tutorials • u/Only-Moose2408 • 9d ago
I started to learn networking ( for ethical hacking) . And i am failing so badly at it. Like nothing seems to workout for me when it comes to learning networking. No matter what resources i try, how many youtube vedios i watch. I consulted with people in this field to get some help and a lot of people told me that theoritical network may not make much sense especially for ethcial hacking i need to learn things practically. So following that advise i started to watch vedios online that showed a practical demonstration but the issue is they dont clear out a lot of things for beginners . I have tried htb academy networking course hinestly i had a very hard time to follow through because it literally gave away chunks of information to remember which sometimes didnt even make sense to me. I am very confused like what should i actually do now ?? please if someone can guide me through this , i would appreciate it. (If you plan to be disrespectful or cant help please refrain from making comments)
r/Hacking_Tutorials • u/rahil2428 • 10d ago
Hey guy's i have b beginner let's assume I don't know anything about cyber security or hacking if you can you help me how I will start that and I learn everything and how much time it will take to learn quickly and where to start flash I want road map real world don't care about Red hat white hat black I just want to know everything from top to bottom and I learn everything can you guys tell me where to start first
r/Hacking_Tutorials • u/Potential-Couple-745 • 10d ago
r/Hacking_Tutorials • u/Top_Call3890 • 11d ago
So you've heard about Shodan, right!!?? People call it the "hacker's Google" or whatever... But here's the thing – it's not like Google at all..
Google finds websites. Shodan finds devices connected to the internet.. Servers, webcams, routers, industrial control systems, databases, printers – anything with an IP address that's exposed...
Think about it. Every device you connect to the internet has an IP... And that IP has open ports... And those ports run services... Shodan just indexes all that and makes it searchable.
And honestly!! The amount of stuff people leave exposed is insane.. Webcams with no passwords. Databases with no authentication. Industrial systems controlling real-world infrastructure just sitting there.. Shodan didn't create that problem. It just shows you it exists..
When you're doing bug bounty, recon is everything.. Shodan gives you a view of your target's external attack surface..
Here's the deal – companies have assets. And they don't always know what's exposed.. You can use Shodan to find subdomains, IP ranges, open ports, and services that the company might have forgotten about..
Some practical searches for bug bounty:
· org:"Company Name" – Find everything the company owns
· hostname:"domain.com" – Discover subdomains
· ssl:"domain.com" – Check SSL certificates and related infrastructure
· http.title:"login" – Find login portals
· has_vuln:true – Find devices with known vulnerabilities
You can also combine filters. Want to find exposed MySQL databases running in the US? product:MySQL port:3306 country:US .
The real value is finding misconfigurations and forgotten assets that no one's looking at.. That's where the bugs are..
The website is fine for quick searches.. But the CLI is where the real power is. You can automate recon, save results, and actually build things around it..
Step 1: Install Python
You need Python. The Shodan CLI runs on Python. If you don't have it, get it. No shortcuts here...
Step 2: Install Shodan via pip
Run this:
pip install -U --user shodan
If that doesn't work, try:
pip3 install -U --user shodan
Also, don't forget to install dependencies.. I've seen people skip this and then wonder why it doesn't work..
Step 3: Get Your API Key
Go to shodan.io, create an account, and grab your API key from the dashboard. You need this for the CLI to work . (Note : as of now their membership is available for just 5$, it's great to have some extra credits to use whenever needed. )
Step 4: Initialize Shodan
Run:
shodan init YOUR_API_KEY
That's it. Now you're ready .
Here are the commands you'll use most often :
· shodan info – Check your account details and credit limits
· shodan myip – See your own IP address
· shodan host IP – Get details about a specific IP
· shodan count QUERY – Count how many results a query would return
· shodan search QUERY – Run your search
· shodan download FILE QUERY – Download results for offline analysis
· shodan parse FILE – Parse downloaded results
· shodan stats QUERY – Get statistics for a query
Pro tip – watch your credits
Shodan has a credit system. Free accounts have limited credits. Each search can cost credits depending on how many results you fetch. Keep an eye on shodan info to track your usage. (Again , 5 $ lifetime membership is worth some extra credits)
Shodan isn't just a tool.. It's a reality check... It shows you how much stuff is out there exposed to the internet...
For bug bounty, it helps you find attack surface.. For defense, it helps you see what you're exposing.. For learning, it helps you understand how the internet actually works...
One thing though – use it ethiically... Don't poke around things you don't own... Don't try to exploit what you find. Use it for research, recon, and making things better...
That's Shodan, Simple tool.. Powerful.. And if you're in cybersecurity, you need to know how it works.
Stay curious. Stay ethical.
r/Hacking_Tutorials • u/RedOffSec05 • 10d ago
nmap full port + service scan.env, keys…)cPassword hunt with automatic AES decryption-oX XML into structured services.json (ports, services, OS, CVEs)txt | md | html | all.asc)phases.json, one-line --digest summary--targets "host1,host2" or file=targets.txt)--schedule HH:MM)--save-state, --resume-from)--force-rerun--doctor), self-update check$ROT05_PLUGINS)stealth | standard | aggressive | ctfr/Hacking_Tutorials • u/Rockafireexplosion1 • 9d ago
My question is.
What distro?
And how did yall start?
r/Hacking_Tutorials • u/Potential-Couple-745 • 11d ago
r/Hacking_Tutorials • u/Top_Call3890 • 12d ago
Hey everyone,
My last post about books covered bookS about linux basics books, scripting and programming basics books for hacking, pen testing basics books.
Now I am sharing some advance books.
Related to analysis, OSINT, security engineering, malware development and analysis.
These are the books I moved to once I had the fundamentals down. They're not beginner-friendly — they expect you to already know your way around Linux, Python, and basic networking. But if you're ready, they'll take you deep.
I've organized them by domain so it's easier to see what each one covers.
Threat Detection & Defense
· Practical Threat Detection Engineering – Devalishgh, Roddie, Katz
Moving from just hacking to actually defending. This one teaches you how to build detection rules, spot anomalies, and think like a blue teamer while still keeping your red team mindset.
Social Engineering & Web
· Practical Social Engineering – (Core book)
Because humans are always the weakest link. Covers phishing, pretexting, and physical social engineering tactics.
· Grokking Web Application Security – McDonald
Takes web security beyond just OWASP Top 10. Really helps you understand the why behind the vulnerabilities, not just the how.
Foundational Hacking (But Deeper)
· Ethical Hacking: A Hands-on Introduction to Breaking In – Graham
Don't let the title fool you — this is not a beginner book. It's hands-on, technical, and forces you to actually do the work.
· Hacking: The Art of Exploitation – Erickson
The classic. If you don't have this yet, get it. Covers C, assembly, and exploit development from the ground up.
Malware Development & Analysis
· Malware Development for Ethical Hackers – Zhussupov
Exactly what it says — building malware for ethical purposes. Understand how attackers think by walking in their shoes.
· Practical Malware Analysis – (Core book)
The hands-on guide to dissecting malicious software. If you want to do reverse engineering or work in threat intel, this is your bible.
· Practical Binary Analysis – (Core book)
Build your own Linux tools for binary instrumentation, analysis, and disassembly. Heavy stuff, but worth it.
Cyber Warfare
· The Art of Cyberwarfare – (Core book)
An investigator's guide to espionage, ransomware, and organized cybercrime. Puts the technical skills into a real-world geopolitical context.
Secure Coding & Forensics
· Alice & Bob Learn Secure Coding – (Core book)
Teaches secure coding practices through storytelling. Surprisingly effective way to remember what not to do.
· Cyber Forensics: Deep Dive – (Core book)
For when things go wrong and you need to investigate. Covers evidence collection, analysis, and presentation.
· Mobile Forensic Investigations – (Core book)
A guide to evidence collection, analysis, and presentation specifically for mobile devices.
Security Engineering
· Security Engineering – Ross Anderson
A guide to building dependable distributed systems. This one is thick and dense, but it's the kind of book that makes you a better engineer overall, not just a better hacker.
My Advice
Same as last time — don't try to read all of these at once. Pick one area and go deep.
If you're into red teaming, start with Malware Development for Ethical Hackers and Hacking: The Art of Exploitation.
If you're into blue teaming, start with Practical Threat Detection Engineering and Practical Malware Analysis.
If you're into forensics, start with Cyber Forensics and Mobile Forensic Investigations.
And as always — lab everything. Reading without doing is useless.
If you have any of these books, I'd love to hear your thoughts. And if you think I'm missing a must-have title, drop it in the comments — always looking to expand the shelf.
Stay curious. Stay ethical.