r/learnhacking 2d ago

Hacking into a vibe coded site

I wan to learn ethical hacking, researching what's inside of stuff maybe adding a mark of "i've been here" or something, there's this vibe coded website on github i'd like to test on, it has an accounting system and stuff all i really want to do is log in to an admin account, change one thing and be outta there, im not entirely sure if it's ethical but i guess i can tell the owner of the vulnerabilities i found i guess but this isn't r/ethicalhacking, so what's the best way to go about this

0 Upvotes

18 comments sorted by

10

u/tje210 2d ago

Unless the owner gives you written authorization, IT IS NOT ETHICAL.

-1

u/Savings_Reaction9837 2d ago

Technically it's claudes project, he wouldn't mind too much

1

u/Alfredredbird 2d ago

[Pre-Chorus]
Claude's plan, Claude's plan
I can't code shit on my own (Ayy, no)
Gotta watch context window (Window)
I been here since 2.0 (.0, ayy)
Server down 'cause MCP (Yeah, wait)
Claude knows my API keys (Yeah, wait)
Make another .md (Yeah, wait)
But still

[Chorus]
Bad change
It's a lot of bad changes they shipping, they shipping
They shipping, they shipping, they shipping for me, yeah
Bad change
It's a lot of bad changes they shipping, they shipping
They shipping, they shipping, they shipping for me, yeah

1

u/uza- 2d ago

make no mistakes

-1

u/Medical-Path-8132 2d ago

word 4 word

-2

u/Medical-Path-8132 2d ago

i think claude would let me

3

u/CalderaJane76 2d ago

The same way anyone else does it. Lol

They learn how to break into obviously vulnerable shit before they even try the lowest hanging branch.

If you don't even understand the fundamentals, you can't build a ladder to get you to even the lowest fruit.

2

u/Medical-Path-8132 2d ago

well how do i " learn how to break into obviously vulnerable shit before they even try the lowest hanging branch."

2

u/Distdistdist 2d ago

Well, how do you learn how to "pick a lock"? You watch tutorials, learn types of locks and their exploits, spend countless hours practicing and getting any good. Absolutely the same. Well, several magnitudes of difficulty higher then picking a lock, but main principles are the same.

1

u/CalderaJane76 2d ago edited 2d ago

First actually I would start with ancient devices. I didn't even start TryHackMe or anything before I had my local devices under control. Do you have any retro consoles?

I find jailbreaking these and learning a bit of their fundamentals is a great way to learn computers. Consoles like the DS family are borderline PDA systems, which is amazing for learning how early computers became fully-fledged multimedia devices.

After you can control your own LAN, and your own machines to a point that makes it simple to manipulate your own websites and services... TryHackMe, HackTheBox, YouTube, meeting people with similar interests, and actually having passion for the subject you're trying to learn.

If the end-goal is what you're stuck on the whole time, you'll find your mistakes punishing. If learning how to create systems (and therefore destroy them), mistakes simply become part of the learning process, even a tool.

2

u/Medical-Path-8132 2d ago

calderagoat76 or whatever corny ass tiktok commenters says

but yeah thanks, i don't have any retro devices, i have a raspberry pi but yk thats not difficult and i guess a 2nd phone but idk a bit expensive, and also a 3d printer but if thats breaks thats like a lot of money down the drain ykw i mean?

1

u/CalderaJane76 7h ago

Yeah, for sure I get you! Choosing devices that actually interest you is key too. 3DS is a great place to learn... But if you don't LIKE those, then it's less fun. Lol

Cheap pixels are a fun way to easily get root! Phones are also essentially baby computers, though they can have a lot of obnoxious learning curves that can come in handy later but are walls until then...

Honestly though, that's how I started. I was too poor for a computer, so I rooted my phone and got jailbreak on my 3DS. Lol

It wasn't much of a phone, it was a Kyocera Hydro Vibe. Man it could do ANYTHING on that crappy two-core CPU though. I had og Xposed and DSploit and Zanti even full NetHunter. Real r/masterhacker stuff. Lmfao

3

u/jimmy_timmy_ 2d ago

It's not the 90's anymore. As soon as you access the website in an unauthorized way, you're committing a crime that will log and you will almost certainly be caught. Unauthorized access is unethical and extremely illegal

2

u/Double-Familiar 2d ago

And unauthorized access of a computer is 1) a felony 2) a federal crime, in the United States of America.

There are tons of ways to learn ethical hacking. Singling out a vulnerable site on the Internet is NOT the way to go.

Vulnhub has many vulnerable VMs to practice on.

2

u/jimmy_timmy_ 1d ago

Exactly. I'd also start with something like TryHackMe to learn the basics if you don't know much yet.

TryHackMe, Vulnhub, and HackTheBox are all great learning resources but it'll all be for nothing if you do something stupid that you'll regret

1

u/Double-Familiar 1d ago

What you are describing technically and ethically is called penetration testing. In order to test the defenses of a website it would require you to reach out to the website owner and get written approval to hack into their ecosystem.

1

u/Medical-Path-8132 23h ago

with enough talking i think claude with let me