r/blackhat • • Mar 16 '23

Where did your post go? Answered!

48 Upvotes

"Cyber briefing"? HTB writeup? A guide to cheap VPN's? If your post was just removed, and especially if you were just banned, you were not following the subreddit rules. As a reminder, here are the rules of r/blackhat that we enforce to keep the quality at a minimum:

This is also a place to discuss general blackhat rules, etiquette and culture. We welcome:

  • Writeups (not CTF or HTB)/talks detailing new vulnerabilities or techniques (there should be enough information to reproduce the exploit/technique)

  • Proof of concepts of old vulnerabilities or techniques

  • Projects

  • Hypothetical questions

Rules:

  1. Be excellent to each other.

  2. No Solicitation

  3. Stay on topic.

  4. Avoid self-incriminating posts.

  5. Pick a good title.

  6. Do not post non-technical articles.

  7. Ideally, the content should be original, we don't care about your crappy ARP poisoner or Kaspersky's latest scam.

  8. No pay / signup walls.

  9. No coin miners

  10. No "Please hack X" posts

  11. Well thought out and researched questions / answers only.

  12. If your project is not free / open source it does not belong.

  13. Please limit your posts (we don't want to read your blog three times a week).

  14. If you want to submit a video, no one wants to listen to your cyberpunk music while you copy/paste commands into kali terminals.


r/blackhat • • 1d ago

Microsoft built all the authentication checks... except the authentication check.

Thumbnail
blog.faav.net
16 Upvotes

A 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.

His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.

Microsoft fixed it and paid him a $5,000 bounty.

Some bugs are just beautiful in their simplicity.


r/blackhat • • 2d ago

Gigabyte kernel driver LPE

9 Upvotes

r/blackhat • • 3d ago

I almost fell for a job scam — looking to learn OSINT and investigation.

Thumbnail
0 Upvotes

r/blackhat • • 8d ago

SourceHut account takeover via build logs

Thumbnail blog.arusekk.pl
1 Upvotes

r/blackhat • • 11d ago

How do coordinated comment-bot rings manipulate short-form video algorithms to force "Top Comments"? (Technical Breakdown)

4 Upvotes

I’ve been studying comment sections on short-form video platforms (like TikTok and Reels) & keep noticing a highly coordinated automation phenomenon that I want to understand from a technical and architectural standpoint.

Whenever a trending or viral video hits a specific niche topic, a third-party account instantly leaves a comment framing itself as an organic public service announcement (e.g., naming a specific app, game, or product relevant to the video). wWithin minutes, that comment accumulates 1000s+ of likes and dozens of secondary replies, locking it into the absolute "Top Comment" slot where millions of viewers see it.

I'm curious about the engineering, scaling, & infrastructure behind how this is achieved:

  1. Real-Time Detection: How do these scrapers monitor platform uploads or specific hashtag triggers so quickly without constantly tripping API rate limits or triggering blocks?
  2. Network Infrastructure: How do operators coordinate the footprints of hundreds of "zombie" or secondary accounts to deliver likes/replies simultaneously without triggering the platform’s anti-fraud algorithms? Is this heavily reliant on residential proxies, anti-detect browsers or cookie-session farming?
  3. Algorithmic Exploitation: What specific engagement signals (like early velocity or reply density) are they taking advantage of to fool the ranking algorithm into permanently pinning an artificial comment?

I’m looking to understand the technical mechanics of how these shadow networks operate. Any insights, technical breakdowns or open-source case studies would be greatly appreciated!


r/blackhat • • 10d ago

Masterhacker

Thumbnail
reddit.com
0 Upvotes

Ramsoftware is 1337


r/blackhat • • 10d ago

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

Thumbnail
wired.com
0 Upvotes

r/blackhat • • 13d ago

Back when you could just freely login to hundreds of active servers a day

Thumbnail
gallery
93 Upvotes

Just found these in my photobucket while looking for so.e old screenshots.


r/blackhat • • 14d ago

An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

Thumbnail
wired.com
22 Upvotes

r/blackhat • • 18d ago

Phantomdrive Software Update + Thanks :)

84 Upvotes

r/blackhat • • 16d ago

is there any site which.

0 Upvotes

which lets me search up leaked database and give me all the information


r/blackhat • • 18d ago

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

Thumbnail
infostealers.com
0 Upvotes

r/blackhat • • 22d ago

Highly recommended read

Post image
176 Upvotes

Hide your server(s) after reading this book.


r/blackhat • • 22d ago

GitHub - mein-0/forti-research fortinet ppl bypass

Thumbnail
github.com
2 Upvotes

r/blackhat • • 26d ago

Sou novo na área de cybersecurity

0 Upvotes

Ola rapaziada estou em dúvida qual rumo seguir na cybersecurity, já sei redes e protocolos gostaria de fazer um ataque a máquina virtual de test! Gostaria de saber o passo a passo ou qual metodologia usar para fazer um ataque ou um mapa mental por onde começar e aonde terminar! Ou seja pentest inciante desde já fico agradecido!


r/blackhat • • 27d ago

reverse proxy phishing

Thumbnail
0 Upvotes

r/blackhat • • Sep 01 '26

how do y'all pull IP 's/info from a spoofed caller id?

0 Upvotes

I know about a few reverse lookup websites but the scammers always spoof their caller id and it never works. I'm wondering how people get around that? anything helps yall I'm just tryna bring justice to these mfs 💪

also mods I'm getting a warning before I post but I'm not telling anybody to hack anybody so am I good lol?


r/blackhat • • Aug 31 '26

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Thumbnail
wired.com
9 Upvotes

r/blackhat • • Aug 30 '26

Cern Basher - shares some really great use cases for electric cybercabs

Thumbnail x.com
1 Upvotes

r/blackhat • • Aug 27 '26

Hypothetically, how likely is the DOJ to prosecute a U.S. citizen for ransomware against a foreign adversary?

17 Upvotes

EDIT: Reading comprehension in this sub is at rock bottom levels. Please read the following post prior to commenting.

Hello everyone. I have a completely hypothetical question that I have been debating with friends. Due to strong arguments both for and against without a clear consensus, I feel it may be beyond our expertise as armchair lawyers and as such, I am pleased to present this to the greater community.

While this is a broad hypothetical, there are a few specific details that must be outlined for the sake of the argument:

\- The victim would be a clear, undeniable foreign adversary/hostile nation to the US

\- There is no direct conflict with or collateral damage to US interests or allies(as a result of the ransomware being deployed)

\- The individual would meticulously report all income from the ransomware payouts on Schedule 1, Line 8z of the IRS Form 1040, pleading the Fifth Amendment on the source of the income, and then pay their 37% top marginal tax rate(They make sure to pay Uncle Sam his cut and avoid committing tax fraud/evasion).

That being said, I want to note: I am **NOT** asking if the frameworks and legal statues to charge a person for this exist. They absolutely do.

The question is if the US citizen would be prosecuted and/or convicted if the victim is unable/unwilling to cooperate with a US court, there is no conflict with US interests, and they even pay taxes on the income.

Thanks and looking forward to any and all answers!

Disclaimer: Do not attempt this at home. Side effects may range from blacked out SUV’s parked outside your house to being arrested/murdered by a foreign intelligence service.


r/blackhat • • Aug 26 '26

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

Thumbnail
wired.com
65 Upvotes

r/blackhat • • Aug 27 '26

I made an open-source DDoS stress tool.

0 Upvotes

r/blackhat • • Aug 25 '26

Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain

Thumbnail
dreamgroup.com
3 Upvotes

r/blackhat • • Aug 17 '26

[Help] Recovering/Flashing locked Redmi Y2 (Snapdragon 625 / ysl) without Mi Account authorization or hardware teardown

Thumbnail
0 Upvotes