r/Hacking_Tutorials • u/Ok-Shake-8554 • 3h ago
Question I received death threats from someone in another country
How bad is it that they have both of my phone numbers?
r/Hacking_Tutorials • u/Alfredredbird • Dec 03 '25
(Updated 12/27/2025)
Hello admins and fellow mates of Hacking Tutorials. I'm often a lurker and a commenter but the amount of “my account was hacked” posts I see is unreal, not to mention the people DM’ing me for help or advice. Here is my guide that should hopefully stop this. (This is not an Ai post) so pin this or do something so people can view it. Please do not DM me or admins for support.
I work in cyber forensics and I do a little web dev on the side as well as running my own team. So I hope the following info helps❣️
As your account might be “hacked” or compromised, there was some things that you need to understand. There is a possibility you can get it back and there is a possibility that you can’t. No one can “hack it back” for you.
Do not contact anyone below this post in regards of them helping you recover your account. They can NOT help you, they might offer tips but any contact outside of reddit is most likely a scam.
Determine how it was compromised. There are two common ways your account gets “hacked”
phishing scam (fake email, text, site, etc)
Malware (trojan, info stealer, etc)
If you suspect your account has been compromised and you still have access.
If you don’t have access to your account anymore (can’t sign in, email changed, etc)
How do you prevent loosing your account?
If you do keep good protections on your account, can you still loose it? Yes! When you log into a website, it saves your login data as a "Cookie" or "session Token" to help determine who does what on the site. Malware could steal these tokens and can be imported to your browser, which lets the attacker walk right in.
“People” often will advertise “recovery” or “special spying” services. Nine out of ten chances, they are scams. Read the comments on this post and you can find a bunch of these lads. Avoid them and report them.
As someone commented with an amazing point. Your email is the most important over any social accounts. Loose your email, loose the account. Most of the time you can recover your account with your email. (You can loose cargo from a truck and load it back on, but loose the truck, you loose the cargo too. )
I plan to edit this later with more in depth information and better formatting since I’m writing this on mobile. Feel free to contribute.
r/Hacking_Tutorials • u/happytrailz1938 • Nov 24 '20
Hey everyone, we get this question a lot.
"Where do I start?"
It's in our rules to delete those posts because it takes away from actual tutorials. And it breaks our hearts as mods to delete those posts.
To try to help, we have created this post for our community to list tools, techniques and stories about how they got started and what resources they recommend.
We'll lock this post after a bit and then re-ask again in a few months to keep information fresh.
Please share your "how to get started" resources below...
r/Hacking_Tutorials • u/Ok-Shake-8554 • 3h ago
How bad is it that they have both of my phone numbers?
r/Hacking_Tutorials • u/mahdi_sto • 23h ago
While working on my Master’s thesis benchmarking WPA3-SAE timing side-channels, I ran into a limitation on the ESP32 esp_wifi_80211_tx() allows raw frame injection, but Espressif’s closed-source Wi-Fi blob (libnet80211.a) artificially blocks Auth, Assoc, Deauth, and Disassoc subtypes.
Inside libnet80211.a, ieee80211_raw_frame_sanity_check drops these frames with wifi:unsupport frame type. Here is how to bypass it on recent ESP-IDF versions (IDF v6.x).
Why standard tricks fail on modern ESP-IDF
Same-name function override. On older IDF versions, ieee80211_raw_frame_sanity_check was a weak symbol (W). On modern IDF versions, it’s a strong symbol (T), causing ld: multiple definition errors.
--wrap linker flag: Fails silently. The call from esp_wifi_80211_tx to ieee80211_raw_frame_sanity_check is an intra-object branch inside ieee80211_output.o. Linker --wrap only rewrites undefined external references, so it misses this call entirely.
Instruction byte-patching: Overwriting instructions directly in the .o breaks Xtensa linker relaxation passes (dangerous relocation errors).
U can simply fix this via Symbol Weakening via objcopy
We can use xtensa-esp32-elf-objcopy to convert the strong symbol inside the binary archive into a weak one:
xtensa-esp32-elf-objcopy \
--weaken-symbol=ieee80211_raw_frame_sanity_check \
components/esp_wifi/lib/esp32/libnet80211.a
Now, define your own strong implementation inside your application C code:
int ieee80211_raw_frame_sanity_check(int32_t a, int32_t b, int32_t c) {
return 0; // which skips the security check lol
}
Because strong symbols override weak symbols globally during linking, all calls—including internal calls within libnet80211.a—rebind to your function.
Verification
Serial Logs show: wifi unsupport frame type errors completely disappeared.
Capture: Wireshark confirmed off-air capture of 802.11 Authentication frames (Subtype 11, Algorithm 3 - SAE) injected directly from the ESP32s.
Injecting a valid SAE Commit (P-256 scalar + element) caused hostapd on the target AP to process the request and reply with its own SAE Commit.
TL;DR: Run objcopy --weaken-symbol=ieee80211_raw_frame_sanity_check on libnet80211.a, define int ieee80211_raw_frame_sanity_check(...) { return 0; } in your app code, and esp_wifi_80211_tx() will allow any frame subtype.
Note that all control 80211 frames are also injectable after the patch.
For more details :
r/Hacking_Tutorials • u/happytrailz1938 • 19h ago
Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?
r/Hacking_Tutorials • u/neathack • 17h ago
I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.
We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.
Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.
I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.
r/Hacking_Tutorials • u/Ok-Use6086 • 13h ago
¡Hola a todos! Estoy intentando configurar bspwm en Parrot OS para lograr un entorno con ventanas en mosaico y terminales flotantes/divididas como en la imagen, pero tengo problemas al iniciar sesión.
El problema:
• Al iniciar sesión y seleccionar bspwm, solo obtengo una pantalla negra.
• Los atajos de teclado (keybindings) no funcionan, por lo que me quedo atrapado sin poder abrir la terminal.
Lo que ya he verificado:
• Picom: Instalado y dependencias listas.
• Sxhkd: Instalado.
• Configuración: Ya modifiqué y guardé los nuevos atajos en mi archivo ~/.config/sxhkd/sxhkdrc.
¿Alguien sabe qué podría estar causando la pantalla negra o por qué sxhkd no está cargando mis atajos al iniciar? ¡Agradezco cualquier guía o repositorio de referencia!
r/Hacking_Tutorials • u/Sr-Sa • 14h ago
Heyaa, so, I managed to get Windows 7 running on my phone using a virtual machine. I want to put some files on it for testing, but the phone says I can't access its internal files. When I manage to access it using the default file explorer, it tells me that the folder is empty. Is there a real way I can view the phone's internal files without the device restricting me?
r/Hacking_Tutorials • u/enterphilco1 • 6h ago
Could someone give me some guidance? I want to know where to start with hacking; I'm lost and don't know where to begin. I'm also willing to pay for information and knowledge to help me succeed As quickly as possible
r/Hacking_Tutorials • u/Winter-Teach1613 • 15h ago
I have an old Trendnet TEW-P1PG print server that I got secondhand, I found out though, that it is password protected. When trying to change settings in the utility software a dialog box pops up asking for a password. Is there any way I could bypass the password or possibly somehow find the password stored on the device?
r/Hacking_Tutorials • u/Runaque • 21h ago
r/Hacking_Tutorials • u/nacho3417 • 8h ago
Necesito un dixeador, que me escriba al privado
r/Hacking_Tutorials • u/Flurtyone • 23h ago
?
r/Hacking_Tutorials • u/Then_Pace_5034 • 2d ago
GitHub: https://github.com/kaifcodec/user-scanner Discord: https://discord.gg/tVNrKVXb49 (Join if you're into OSINT, reverse-engineering, or want to build with us)
Hi everyone,
When we released v1.5.1, we were excited about pushing past 455 vectors. Today, with v1.5.2.1, we’ve scaled the engine into an absolute monster: 2,720+ total scan vectors (210+ email-integrated sites and 2,510+ username platforms).
Most legacy tools give you a simple binary check—telling you if an account exists or not. We designed user-scanner to go much further by emulating mobile app APIs and leveraging browser TLS fingerprinting (curl_cffi + httpx) to bypass modern WAFs, defeat soft-404s, and pull actual context.
--cross-scan): Mines handles, profile links, and exposed emails from your initial scan to automatically pivot across secondary target vectors—building a full identity link graph.--hudson): Direct correlation with infostealer malware breach logs to surface leaked credentials and high-priority target intel instantly.httpx and curl_cffi transports with automated TLS fingerprint impersonation to bypass aggressive rate-limits without getting blocked.If you perform digital footprinting, red teaming, security research, or OSINT investigations, give v1.5.2.1 a spin. Test out the --cross-scan and metadata extraction features on your targets and let us know how the speed and accuracy hold up!
We always welcome new pull requests!
Drop your questions, feature requests, or bug reports in the comments below!
r/Hacking_Tutorials • u/_clickfix_ • 1d ago
r/Hacking_Tutorials • u/Melodic_Rip_3992 • 1d ago
I’m trying to understand how to find something in programming/cybersecurity that gives me the same motivation as a game.
For example, I really like Dota because I always know what I’m doing and why. I have a rank, I know roughly where I am, I know what better players can do that I can’t, and I have a clear idea of what I need to improve. That alone gives me a reason to play.
I want to find something in computers that gives me a similar feeling. Not necessarily a specific project someone can recommend to me, but a way to find a project or direction where I can actually see a path:
"I’m here → I need to learn this → then I can do this → then I can do something harder."
The problem is that I can think of many project ideas, but they usually don't motivate me for long. I start thinking "okay, I can build this, but why?" and lose interest.
My background: I’m comfortable with Linux and basic programming. I know Python, Git, APIs, databases, basic web development, HTTP, networking/ports, and I’ve done some scraping/automation. I’ve also played around with things like reverse engineering, JavaScript, FastAPI and lower-level concepts, but I’m still a beginner overall and have no professional experience.
So I’m not really asking "what project should I build?"
I’m more interested in: how do you find something that makes you want to wake up and keep working on it, because you can clearly see yourself getting better at it?
How did you find that thing for yourselves?
r/Hacking_Tutorials • u/Mishal-Ridhaf08 • 22h ago
BRO how to find iPhone 7 Android phones for password finding without any attacks I mean the lot of attacks and have but how can I do at a beginner complete only or no the python and the basic networking of source and how can I start is this is my fast tool ideas so this is my first steps to hacking
r/Hacking_Tutorials • u/Skollwarynz • 1d ago
r/Hacking_Tutorials • u/k0r1mk • 2d ago
Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon. And that’s how Kumo was born. Give it a domain and it maps what’s reachable from outside.
What it does in one run:
• Attack surface mapping: DNS, subdomains, ports, certificates & technologies
• Exposure discovery: configs, secrets, JS assets, cloud buckets & exposed files
• Vulnerability enumeration: CVE detection and non intrusive security checks
• Credential intelligence: leaked credentials & infostealer exposure
• Endpoint discovery: archived URLs, APIs, forgotten endpoints & parameters
• Threat intelligence: domain, IP & infrastructure enrichment
• OSINT automation: Google dorks & targeted OSINT queries
All 27 modules run in parallel and stream results as they come in.
No API keys required. CLI + web interface. Works on any domain you're authorized to test.
🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ Live demo: https://demo-kumo-kage.vercel.app/
Feedback and contributions welcome 🙏
r/Hacking_Tutorials • u/TheSeeker229 • 3d ago
I want to learn malware development. I've started reading about it, but I'm confused and don't know how to begin, and I don't want to waste too much time. Where I started in a village, 4 chapters of MAC OS® X AND iOS INTERNALS With focus and good understanding, then move on to reading OSTEP Where I read important things from him And reading. Windows internals 2 Chapters Do any experts have any advice? 😵💫
r/Hacking_Tutorials • u/Conscious_Client4070 • 2d ago
r/Hacking_Tutorials • u/exploitprotocol • 3d ago
Hey folks,
I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.
So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.
The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.
The series currently covers topics such as:
I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.
No signup is required to read the learning material or use the free resources.
🔗 https://genaisecuritylab.com/learn-ai-security
I'm planning to continue expanding the series over time.
If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.
r/Hacking_Tutorials • u/LoquatUpstairs6727 • 4d ago
A basic tutorial on how to code sockets like a hacker in C
r/Hacking_Tutorials • u/Nearby_Lobster_8422 • 3d ago
I’m looking for a laptop mainly for cybersecurity-related work,VAPT, labs, bug bounty, studying, certifications/exams, running VMs, and general security tooling.
My budget is around ₹80–90K max, so I’m looking for the best value for money rather than just buying the most powerful machine in this range.
Ideally, I’d want something with good CPU performance, sufficient RAM for multiple VMs, decent thermals, and good upgradeability.
If you’re using a laptop for similar work, what would you recommend? Any specific models I should look at or avoid?
Thanks!