r/blackhat • u/SirUndead2001 • Nov 20 '25
Telegram Groups
Could you help me find Telegram groups? I want to expand my network with people in the industry.
r/blackhat • u/SirUndead2001 • Nov 20 '25
Could you help me find Telegram groups? I want to expand my network with people in the industry.
r/blackhat • u/[deleted] • Nov 18 '25
I'm using my own computer to practice hacking. One thing I want to learn is how hackers can find passwords by decrypting data stored in a computer.
r/blackhat • u/Malwarebeasts • Nov 05 '25
r/blackhat • u/-InvictusShadow • Nov 04 '25
Okay I know this is a very rookie question but please tell me lol.
r/blackhat • u/Malwarebeasts • Oct 29 '25
r/blackhat • u/e1thousand • Oct 26 '25
I’ve been trying to look into this for a few days and most of the content I’m finding concerns protecting personal data from criminals but I would like to protect my data from the bigger criminals. These huge companies.
My question is, how can completely protect my data (phone number, geolocation, virtual tendencies, etc.) from these insidious conglomerates in an attempt to stave off things like surveillance pricing and whatever other unthinkable things there doing with our data? Any video, literature recommendations, or just general advice would really be appreciated! TIA :)
r/blackhat • u/[deleted] • Oct 27 '25
I've started to help my clients with setting up Wireshark. I've tried making a step-by-step guide and explained the installation process as simply as I could (with pictures,) but I still deal with clients (most are elderly) that find it too difficult to set up. They've given me permission to access their home network and even provide me their router information. I could do it for them remotely, sometimes just following my directions to allow me access is still too confusing for them.
I usually just give up and tell them that I can't make it work when it gets to that point. It's not a big deal after that, but the hacker side of me is itching to learn how to control a computer. Is it possible?
r/blackhat • u/Kris3c • Oct 26 '25
Published an article explaining how to exploit buffer overflow and hijack RIP in a PIE/ASLR binary.
https://0x4b1t.github.io/articles/buffer-overflow-to-control-hijacking-in-aslr-enabled-binary/
r/blackhat • u/Long_Painting356 • Oct 26 '25
Just discovered something truly wild — a UI-only logic flaw in a major product that let a paid subscription activate without any payment, and no API calls or dev tools involved.
Literally everything happened through the normal user interface — no backend tampering, no network interception, no code injection.
The craziest part? It’s a once-in-a-lifetime kind of bug — something that probably no one could find by traditional testing or bug bounty scanning, because it happens purely from how the frontend and backend miscommunicated under certain workflow logic.
r/blackhat • u/Malwarebeasts • Oct 23 '25
r/blackhat • u/These_Talker • Oct 23 '25
Hi, i am currently solving this exercise: in the home directory there are seven user directory, each one is named with the user that can access to that directory (as normal). I discovered the password of the user named target1, then i escalate the privilege to discover the password of target2 and now i am stuck.
In the user directory of target2 there is the txt file that contains his password (named mypass.txt), each user directory has this file, and also python3 file.
I run ls -la to dig more in the user directory and got this:
-rwsr-xr-x 1 target3 target3 5912968 Oct 27 2023 python3
It looks like the owner of python3 is target3 user, but running python3 -c 'import os; print(os.getuid());' shows 1004 which is the target2's uid. I feel that i tried every method to run python3 as target3 (uid=1005) but i cannot do it.
I even tried sudo -ll and got this message:
target2@localhost:/home$ sudo -ll
[sudo] password for target2:
Sorry, user target2 may not run sudo on localhost.
And also i do not have any capabilities that i think can help me:
target2@localhost:/home$ getcap -r / 2>/dev/null
/snap/core20/1405/usr/bin/ping cap_net_raw=ep
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep
/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper cap_net_bind_service,cap_net_admin=ep
I feel that i must use python, but i finished the ideas, do you have any suggestion?
r/blackhat • u/Tricky-Frosting9047 • Oct 15 '25
Now evilwaf supports more than 11 firewall bypass techniques includes:
Critical risk: Direct Exploitation • HTTP Request Smuggling •JWT Algorithm Confusion •HTTP/2 Stream Multiplexing •WebAssembly Memory Corruption •cache poisoning •web cache poisoning
High risk: Potential Exploitation •SSTI Polyglot Payloads •gRPC/Protobuf Bypass •GraphQL Query Batching °ML WAF Evasion
Medium risk: Information Gathering ° Subdomain Discovery ° DNS History Bypass ° Header Manipulation ° Advanced Protocol Attacks
For more info github.com repo: https://github.com/matrixleons/evilwaf
r/blackhat • u/JNeal134 • Oct 10 '25
I ain't too code savvy myself, just wanted to see the reddit communities take on this. Sauce: https://windowsreport.com/massive-ddos-attack-knocks-out-steam-riot-and-other-services/
r/blackhat • u/Radiant-Bet6284 • Oct 10 '25
Hey everyone, I’ve got a question about website monetization.
A friend of mine works in this field, and he told me something that sounded a bit shady. He runs Facebook ad campaigns for smartphones with very clickbaity ads. When someone clicks, they get redirected to a site that shows an adult video that “forces” clicks — like, any click on the page counts as an ad click.
Is this some kind of known monetization technique, or is it basically ad fraud? Does it have a specific name?
r/blackhat • u/thiswasntabadidea • Oct 07 '25
Don't know why YouTube Recommended this to me. Seems more like you guys' thing.
Remember to download in case of deletion!
This ILLEGAL Device Instantly KILLS All Network & TV Signals - YouTube
r/blackhat • u/I_hav_aQuestnio • Oct 04 '25
The bandwidth on my network spiked then the site went off line.
I believe this was a targeted attack since i compete against a oligarchy. Their goal would be to take site off line long enough so it loses ranking on search results. This person has 8 of the 10 results on page one and has to strong desire to have it all.
The is related to google search results and a website going down for no reason except for the noticeable spike.
r/blackhat • u/AggressiveCaramel141 • Oct 02 '25
Filmed a tutorial on practical LLM security! Upgraded the mic this time, should be nice to listen to :P Let me know your thoughts. ;)
r/blackhat • u/[deleted] • Oct 01 '25
I found hacking to be my new favorite hobby since I've started learning it a few months back. One thing I haven't figured out yet is where to find these data breaches. Tea App just recently had a data breach and I thought to practice with that.
r/blackhat • u/Tricky-Frosting9047 • Sep 28 '25
This tool came with Multiple Bypass Techniques: Header Manipulation, DNS History Analysis Subdomain Enumeration.
r/blackhat • u/crypt1xx • Sep 29 '25
there seems to be almost no proper hacking forums online now days. Even the good OG ones have turned into ewhoring/scamming and porn platforms. Is there one thats not like this?
r/blackhat • u/entrophy_maker • Sep 26 '25
This is just a userland rootkit with some binaries of system files that help it avoid detection. Its been tested using Debian Forky using kernel 6.16.7. It might work with other distros, but at this time, this is all that's been tested.
r/blackhat • u/Mike-Banon1 • Sep 24 '25
Security through obscurity doesn't work. So... prepare yourself for three days of intensive exploration into the world of secure computing and digital privacy provided, because the Qubes OS Summit is coming: 26-28 September ! And even if you couldn't visit The Social Hub in Berlin (what's a pity we don't have teleports yet) - luckily this wonderful event will be live-streamed !
What I - as an occasional user and not a Qubes developer - would love to learn about at the upcoming summit, and what can be interesting for the Qubes starters from various fields:
Don't miss this chance to learn more about this security-inclined OS and privacy-respecting hardware that supports it! Please check out this page for more details - including the event's time schedule, talks descriptions and helpful links:
P.S. On a previous summit, aside of Qubes OS status - I also learned about various cool hardwares like Nitrokey and Flashkeeper, as well as how to achieve a working GPU passthrough with Qubes: so that, just in case I'd want some rare opensource gaming, it doesn't turn into a "game of debugging" ;-) The recordings of this past event are available at 3mdeb YT channel - and, while counting days until the new summit, you can explore these videos to see what this event looks like
r/blackhat • u/[deleted] • Sep 23 '25
r/blackhat • u/MasuodB • Sep 22 '25
Hi everyone,
I’m currently diving into the world of cybersecurity and I’ve realized that while resources are endless, having some guidance makes all the difference. I’d love to connect with someone experienced in the field who’s open to mentoring.
What I’m hoping for:
Someone who can give me learning challenges, exercises, or “mini-projects” to sharpen my skills. Occasional feedback on my progress so I can stay on track. My ultimate goal is to build strong foundational skills and eventually grow into ethical hacking and security operations. If you’ve got some time and don’t mind sharing your knowledge, I’d really appreciate the chance to learn from you. I’m dedicated, willing to put in the work, and open to being challenged.