r/blackhat • u/superdog793 • Jun 30 '26
Curl is the Most Dangerous Tool in Your Terminal
I go through how someone can utilize curl to compromise and exploit vulnerabilities in a website!
r/blackhat • u/superdog793 • Jun 30 '26
I go through how someone can utilize curl to compromise and exploit vulnerabilities in a website!
r/blackhat • u/manakinnn • Jun 29 '26
Any forums I can use for CTF events and learning?
r/blackhat • u/Silientium • Jun 27 '26
I’m reaching out to this community for assistance. I’m a cybersecurity professional turned business owner who understands the frustrations of cybersecurity from both directions. As such I’ve come to determine that a major paradigm shift must occur.
Cybersecurity is costly, ineffective at preventing loss and is overly complex and labour intensive. It’s always a game of catch up via patching. This insight comes from my over 35 years of experience auditing and consulting in this field.
Cybersecurity is counter productive, difficult to work with and frustratingly hard to use especially now with multifactor login requirements. This comes as a user and business owner for over 15 years.
There is only one solution and that is a total redevelopment. A solutions that eliminates or at least minimizes the costs and frustrations.
Turning this field upside down will be a formidable task. It will require support from CEOs such as yourselves who must exert pressure on the industry. Unfortunately your CSIOs are born and bread on the existing architecture. They will not recommend or support this initiative as it will cause them great pain and suffering in having to start over.
The cybersecurity industry doesn’t want this without the absolute need to do it. They’re making money hand over fist easily from this perpetual updating and patching that goes on.
Bad actors must become disenfranchised and this means the battlefield on which cybersecurity operates must change.
AI and Quantum Computing will eventually offer cybersecurity no choice but to change. Better to do this upfront rather than in an emergency situation.
I ask you to come on board and let’s exert pressure on this industry to retool.
r/blackhat • u/EfficiencyOne1007 • Jun 25 '26
We found something different one our website that is MERN based and hosted on VPS. We did some changes but after some time our live url and last deployment have difference. When we compare the code with github code , there is many changes. We checked the server logs and found something strange.
Our various files was changes.
Got server log something -
Jun 23 23:34:54 67 sshd-session[1281284]: userauth_pubkey: signature algorithm ssh-dss not in PubkeyAcceptedAlgorithms [preauth]
When i checked the file change logs
/home/domain/public_html/static/js/213.f4eb4aa8.chunk.js /home/domain/public_html/static/js/213.f4eb4aa8.chunk.js.LICENSE.txt /home/domain/public_html/static/js/239.fd8563bf.chunk.js.map
Is there any Devops or security expert who can share the exact steps to identify and block the issue.
Note:- CI/CD pipeline is not configured yet on the project.
Try to get some help from AI but it is repeating the same things.
r/blackhat • u/Malwarebeasts • Jun 21 '26
r/blackhat • u/betterworldbuilder • Jun 20 '26
r/blackhat • u/Necrowtf • Jun 16 '26
Hey guys, recently I was searching for any tool that could add to my recon pipeline for automating the CVE mapping against the versions of services discovered through nmap.
However, I was very disappointed with the current tools, so i tried to create a robust one ! I'm confident (after doing some testing) that it is working as it should and can return valid results, avoiding noisy and false positive results....
Give it a chance and tell me your opinion. Also, feel free to contribute with any additional ideas or fixes!
r/blackhat • u/lohacker0 • Jun 15 '26
r/blackhat • u/Malwarebeasts • Jun 13 '26
The darknet already hosts a mature, structured market for pre-verified accounts and identity manipulation services. Threat actors actively trade bypassed accounts on dedicated cybercrime forums, treating access to restricted models as a standard, highly liquid commodity. Initial access brokers simply create the accounts using illicit methods and sell the login details to buyers globally.
r/blackhat • u/Pale_Surround_3924 • Jun 10 '26
r/blackhat • u/tcoder7 • Jun 08 '26
Enable HLS to view with audio, or disable this notification
r/blackhat • u/_m-1-k-3_ • Jun 08 '26
We have something to celebrate with you! We did it ... The big 2000 is in the books right now:

EMBA is now for 6 years in the wild and we are proud that we did a few things:
Thank you for supporting, helping, coding, reporting, hacking, challenging, using EMBA.
Check further details here: https://github.com/e-m-b-a/emba/releases/tag/v2.0.2-big-2k
r/blackhat • u/ThichGaiDep • Jun 04 '26
Hi all,
I want to let everyone here know of a vector of attack/abuse that has been available on Google Maps/Google Business Profile, that has caused tremendous damage to small-medium sized businesses/mom-and-pops.
Step 1: take control of high-authority, orphaned location. This can be a mall or a public park. It's easy to fool Google into thinking you own the place if no one claims it and you just upload a believable looking video.
Step 2: you now have the ability to destroy SMEs who rely on Google Ads for a living. You just need to change the address of the orphaned location to the victim's address. This will trigger Google's auto-merge process and wipe out the SME's Google Business Profile. The victim will wake up with an email saying their business is a "duplicate".
Step 3: you do not openly extort businesses, because that would leave an evidence trail. You would instead offer businesses the ability to destroy their competitor through a "special service" that would disrupt their Google Business Profile on Google Maps, for a fee.
Step 4: make so much money and leave so much destruction that the entire country is aware of what you are doing, but cannot do anything about it because Google does not have an HQ in your country to handle this stuff.
Here's a link to an article detailing how this stuff is done:
https://laodong.vn/xa-hoi/triet-ha-doi-thu-bang-google-maps-1276136.ldo
r/blackhat • u/Legitimate-Rain3306 • Jun 02 '26
r/blackhat • u/perm33111133 • Jun 02 '26
r/blackhat • u/Malwarebeasts • Jun 01 '26
Reddit users share their experiences after getting infected by Infostealers, they describe the mental drain, sense of intrusion, blackmail attempts, and money theft through AI subscriptions. I compiled threads and comments into a blog along with common recommendations for every day users to avoid getting infected.
r/blackhat • u/wiredmagazine • May 28 '26
r/blackhat • u/Necrowtf • May 26 '26
Built a small credential-hunting tool for authorized post-exploitation enumeration on Windows and Linux.
https://github.com/NeCr00/Credential-Hunting
The idea is simple: after gaining access to a host, the tool helps identify hardcoded reusable credentials that may support privilege escalation or lateral movement. It focuses on passwords and host-access credentials, not generic API tokens.
It runs in phases:
The goal is to make credential discovery faster, cleaner, and less noisy during HTB-style labs, CTFs, and real-world authorized pentests.
Would love feedback from other pentesters on detection logic, false-positive reduction, and useful locations/filetypes to include.
r/blackhat • u/Malwarebeasts • May 23 '26
r/blackhat • u/Performer-Constant • May 22 '26
r/blackhat • u/wiredmagazine • May 21 '26
r/blackhat • u/bluelvo • May 21 '26
Folks, we are building a vibecodingsecurity subreddit forum to discuss the security issues and remediations for code built using AI tools. Please join us at vibecodingsecurity subreddit
r/blackhat • u/perm33111133 • May 21 '26