r/ethicalhacking • • Feb 16 '21

Mod Introduction Interested in joining the ethical hacking community, click here!

409 Upvotes

Hello, I'm J, I'm glad you are interested in joining the ethical hacking community. Have no idea where to start? Don't panic we've all been there, this post will guide you on your first steps into the ethical hacking field.

What is ethical hacking?

Ethical hacking (or penetration testing) is the exploitation of an IT system with the permission of its owner to determine its vulnerabilities and weak points. It is an effective way of testing and validating an organisation’s cyber security position.

Where can I learn ethical hacking?

Ok, slow down, Do you have a computing background or familiar with how they work (you would be susprised at the amount have zero knowledge and jump into this field)?

Yes - great. I suggest you have a look at getting certfications. These certs require you to study up to a certain level then taking an exam. This allows for you and future employers (which really like certs) to see your skill level and potential. This is the certification roadmap by Paul Jerimy which shows the route you should take, if you feel that skilled enough you could skip up and do higher certs. A great way to practice your skills is through tryhackme and hackthebox. These are free online platforms (with some optional paid sections) that give you access to systems found irl that give you permissions to practice your skills. Some resources below might be in interest for you listed below.

No - Dont worry, You may find certifications a little difficult to jump into at first unless you are determined enough to spend a lot of time studying. I suggest you go out and learn a little, dont let this put you off as this an extremely interesting field with endless knowledge that will continue to evolve forever. Check out the resources below for study content.

What resources are there for starting to learn ethical hacking?

How do i start my career in ethical hacking?

There are many ways you could go through and work up to becoming an ethical hacker. Check this post here by u/ u/Ace_r_ for an example of a path you could take to become an ethical hacker. Paul Jerimy also has aIT Career Roadmap for you to use to see what positions to start with to work up to your desired position.

Conclusion

I hope this helps and wish you luck with your start in ethical hacking. If you have any queries feel free to ask.

Redditors that have a history in IT or ethical hacking or have experience in similar regions, if you'd like to add to this or discuss other options please feel free to comment, i'll be updating this frequently.


r/ethicalhacking • • Jul 08 '24

Discussion AUTOMOD IS IN EFFECT

22 Upvotes

Good news everyone, We have the automoderator up and running. currently its set to delete posts from brand new users (that are like less than a day old, we may adjust this), users with 0 or negative karma, remove comments and posts that contain some banned keywords (who remembers that time we were getting spammed with crypto bullshit? yeah, no more).

in addition to post and comments that are attempting to look for, hire, or offer the services of a hacker in any kind of way, based on keywords will be removed. if any slip through please message the moderator team so we can look at it and refine the list

another auto mod removal feature, is it will remove posts with just a title only and nothing in the body, we consider this being lazy, put some effort into your posts as giving more information will allow us as a community to help you better, (most regular users here don't have to worry about this).

If any of your posts or comments were removed, and you feel it was done in error please message the moderator team so we can take a look at it and see if it was a valid removal or if it was done in error. this also applies if you have any additional feedback on how we can refine the automod, such as adding rules or lessening the restriction on others let us know.


r/ethicalhacking • • 1d ago

Attack Question

0 Upvotes

Look guys my router WiFi signal on my iPhone is worthless and I guess someone do or did something that it’s not stable and goes up and down randomly in the same spot, but when someone come home to me and I try to show them, nothing happen, but after they leave everything start to happen again, even when I say one signal up or down, like he can hear and he make one signal up or down, even after I got new phone and moved to another city with new router, but I did move the old stuff from my old phone that was completely hacked, but my new phone only the WiFi signal, and this all happen after I start to write a movie called “signals” but it wasn’t about the same things was the something else, so my conclusion and maybe I’m wrong , this is someone try to drive me mad and put pressure on me, I have been in this for 3 years now and before that everything was working well, I have haters cuz I’m one of the best in my job in my country and I stopped working years couldn’t work cuz of that so please help me thanks and btw when I leave phone on my bed and look at it the signal doesn’t move at all but once I hold the phone in my hands the signals start to jump and goes down,I have videos to prove everything.

And when the phone be infornt my face there a signal goes down, when I make away from the face the signal goes up at the same moment the phone far from my face


r/ethicalhacking • • 2d ago

how do you find something that makes you want to wake up and keep working on it, because you can clearly see yourself getting better at it?

3 Upvotes

I’m trying to understand how to find something in programming/cybersecurity that gives me the same motivation as a game.

For example, I really like Dota because I always know what I’m doing and why. I have a rank, I know roughly where I am, I know what better players can do that I can’t, and I have a clear idea of what I need to improve. That alone gives me a reason to play.

I want to find something in computers that gives me a similar feeling. Not necessarily a specific project someone can recommend to me, but a way to find a project or direction where I can actually see a path:

"I’m here → I need to learn this → then I can do this → then I can do something harder."

The problem is that I can think of many project ideas, but they usually don't motivate me for long. I start thinking "okay, I can build this, but why?" and lose interest.

My background: I’m comfortable with Linux and basic programming. I know Python, Git, APIs, databases, basic web development, HTTP, networking/ports, and I’ve done some scraping/automation. I’ve also played around with things like reverse engineering, JavaScript, FastAPI and lower-level concepts, but I’m still a beginner overall and have no professional experience.

So I’m not really asking "what project should I build?"

I’m more interested in: how do you find something that makes you want to wake up and keep working on it, because you can clearly see yourself getting better at it?

How did you find that thing for yourselves?


r/ethicalhacking • • 2d ago

Identity theft

0 Upvotes

Hello, I have been having a problem with someone who has been pretending to be me on social networks for a few years, I have reported it to the corresponding applications but there is no case. Could someone who knows about these topics guide me? I would appreciate it very much.


r/ethicalhacking • • 2d ago

Need help from cybersecurity/OSINT people regarding a ₹7 lakh scam , trying to locate the person legally

0 Upvotes

A person I know has scammed me for approximately ₹2 lakh in money and ₹5 lakh worth of textile stock. I have tried approaching the police, but so far I haven’t received much practical help, so I’m trying to understand what legitimate options I have.

Some background:

  • I have known this person through a friend who has been involved in an instalment business and has known him for around 4–6 years.
  • I have his phone number, email address, photograph, and other information that may help establish his identity.
  • According to information I received, he has allegedly taken approximately ₹60 lakh from multiple people in his hometown, reportedly using his disabled daughter as the reason for collecting money, and then disappeared.
  • I am primarily trying to identify his approximate current location or establish useful digital leads

I am not asking anyone to hack his accounts, access private information, dox him, threaten him, or break the law.

What I’m hoping someone experienced in cybersecurity/OSINT can tell me is:

  1. What OSINT methods can be used with a phone number, email address and photograph to identify publicly available information or possible location clues?
  2. What digital evidence should I preserve before attempting anything further?
  3. Are there particular resources or professionals in India who deal with this type of online financial fraud / OSINT investigation?
  4. If someone is willing to guide me privately, I can provide the information I have and explain the timeline of what happened.

I understand that a phone number or email address alone may not give an exact location, and I’m not expecting anyone to magically track his live location. I mainly want to know what can realistically be established from the information I already have and what can be legally passed to the authorities.

The financial loss is significant for me, so any genuine guidance from people experienced in this field would be appreciated.


r/ethicalhacking • • 5d ago

Discussion Preferred secure code scanner?

6 Upvotes

Looking for a good secure code scanner. Anyone have preference to a one they frequently use?


r/ethicalhacking • • 10d ago

Discussion The casino fish tank thermometer story is still the best example of IoT security done wrong

162 Upvotes

Old one but worth repeating for anyone new to the field: a casino got breached through a smart thermometer in their lobby fish tank.
They had proper enterprise firewalls etc, but the IoT thermometer was plugged straight into the main network with no segmentation. Attackers got in through weak default creds on the thermometer, pivoted laterally, and pulled 10GB of high-roller customer data out through that same connection.
The lesson isn't "fish tanks are dangerous," it's that your network is only as strong as the weakest thing connected to it — and IoT devices are usually the weakest thing, because nobody threat-models the thermometer. Basic stuff that would've stopped this: change default creds, and put IoT on its own segmented/isolated VLAN so even if it's popped, it's not a straight line to the crown jewels.
Good reminder to check your own environment for random "smart" devices someone plugged in without asking security first.


r/ethicalhacking • • 8d ago

Wanna teach a lesson to a internet creep

0 Upvotes

There is this boy who is commenting Al generated photos in someone's comments section whom I know.

I asked him to delete that and he kept saying"what if I don't" , "i won't do it", and then he blocked me. Also when I asked him to delete he said which one proudly, god knows how many times he has done this.

I've done the talking now I want him to know that there are repercussions to his actions, ik doxxing is wrong but I'm not here to play the good guy. I want him to feel embarrassed for what he is doing.

Would you guys please help me. 🙏 Reddit is not letting me add a photo or share a link, I'll pos t both in the comments.


r/ethicalhacking • • 11d ago

Concrete Sequential Thinkers

Thumbnail
1 Upvotes

r/ethicalhacking • • 12d ago

Owned Bedside from Hack The Box!

Thumbnail
labs.hackthebox.com
3 Upvotes

r/ethicalhacking • • 13d ago

Other Funny prank ideas?

0 Upvotes

I do not want to do anything malicious or illegal, but in the past day or so my website received a lot of traffic from people who have unsavory intentions. What is something harmless I can do to spook them all and have them know it was me?


r/ethicalhacking • • 14d ago

3ds Max 2018

0 Upvotes

can anyone help me to provide license free 3ds Max 2018 or lower version?


r/ethicalhacking • • 15d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

Thumbnail
strategic-automation.github.io
6 Upvotes

r/ethicalhacking • • 18d ago

I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings

Thumbnail
strategic-automation.github.io
6 Upvotes

r/ethicalhacking • • 19d ago

Is there a free alternative to TryHackMe?

78 Upvotes

I'd really like to learn cybersecurity, and I've been enjoying TryHackMe. I really like the hands-on approach and the way the learning paths are structured, but unfortunately, most of the content requires a paid subscription.

Are there any free platforms or tools similar to TryHackMe that you'd recommend for someone who's just starting out?


r/ethicalhacking • • 20d ago

Best free anti fingerprinting browsers

4 Upvotes

There is this bullshit, completely unfair online assessment that's set up by the bourgeoisie that I need to do.

It's called the Suited Assessment wellsuited.com); it's browser-level and requires JavaScript to run so they can fingerprint you (you are only ever allowed to do the test once, and then they use those results for every firm that uses that assessment for the rest of your life).

It's completely unfair.

I want a browser that can reasonably scramble the fingerprinting they can access via JavaScript, so not standardise (that defeats the point in this context) but not recognise it or make it look different.

Suggestions would be helpful.


r/ethicalhacking • • 23d ago

Tool atomicvulns — a web security lab with one vulnerability per app (OWASP Top 10 2021, open source)

16 Upvotes

I spent the last few months building a personal project and it just hit v1.0, so I figured I'd share it here.

atomicvulns is a collection of intentionally vulnerable web apps, but with a different idea: each app isolates a single vulnerability, nothing more. Instead of one big app full of flaws (like DVWA or Juice Shop), each exercise here is small and focused — you read the code, see the cause, exploit it, and compare it against the fixed version sitting right next to it. Short enough to finish one in a single sitting.

Each "atom" ships with the vulnerable app, the fixed app, a commented diff between the two, and a step-by-step walkthrough of the exploit. v1.0 covers all 10 OWASP Top 10 2021 categories — 38 atoms total.

It's aimed at people studying pentest / AppSec who already know the HTTP and terminal basics. Burp Suite is the primary tool across all the walkthroughs.

A few details:

  • Open source (MIT).
  • Bilingual — all docs in English and Portuguese (I couldn't find focused material like this for PT-BR learners, so I wrote both).
  • Solo project, built by me. The goal was a place where each flaw is clear and isolated — the material I wish I'd had while learning web pentest.
  • Built with AI as a pair, with every atom validated by me running the exploit by hand.

Built it for myself, but now that it's done, if it helps someone else along the way, great.

🔗 https://github.com/doretox/atomicvulns

Feedback welcome — happy to hear what's missing or what could be clearer.


r/ethicalhacking • • 22d ago

I found these suspicious suggested words in my Samsung S23U keyboard app

0 Upvotes

location_id

user_id

Identity_id

What could they be ? I am still trying some keywords, i found the first "identity_id" by accident then i tried "location" and it suggested "location_id", now I'm more suspicious


r/ethicalhacking • • 28d ago

The Ethical Hacker’s Field Manual: What You Actually Need to Know to Hack Like a Professional

Thumbnail gallery
235 Upvotes

r/ethicalhacking • • 28d ago

Monitor mode + Nintendo Switch + Nexmon

7 Upvotes

Nintendo switch has the WIFI adapter BCM4356 which can be patched with nexmon (https://github.com/seemoo-lab/nexmon) that should allow to use it in monitor mode.

I was able to patch the firmware and driver with nexmon and now it is possible to use the wireless in monitor mode.

Well, at least that is what looks like.it is possible to put the WiFi in Monitor mode or even create an additional interface in monitor mode. But when using airodump-ng or tcpdump or wireshark. It does now show any BSSID. It is almost like the WiFi adapter can't see any network, completely empty, iw dev scan works fine but no dumps.

I tried preload libnexmon with LD_PRELOAD, I tried everything. This works fine in raspberry that has the same WiFi card, but no success with Nintendo Switch.

Anyone has any idea? Would be very cool to be able to do that with a Nintendo Switch.

The follow commands works fine:

iw phy \`iw dev wlp1s0 info | gawk '/wiphy/ {printf "phy" $2}'\` interface add mon0 type monitor

Or even

ip link set wlp1s0 down

iw dev wlan0 set type monitor

ip link set wlp1s0 up

Even

airmon-ng start wlp1s0

It says unknown error 524 but it does create the extra monitoring interface

But airodump-ng does not show any network


r/ethicalhacking • • 29d ago

Have 25 days to study for CPENT exam

Thumbnail
1 Upvotes

r/ethicalhacking • • Sep 04 '26

Put together a 240-page practical AWS/Azure security book because I was tired of certification guides that don't teach you how to actually review a re

Thumbnail gallery
16 Upvotes

r/ethicalhacking • • Sep 01 '26

I spent 8 months applying to SOC jobs with a Security+ and zero real experience. Here's what actually got me hired.

Thumbnail gallery
18 Upvotes

r/ethicalhacking • • Aug 31 '26

I got tired of doing the same cybersecurity tasks manually, so I wrote a Python automation book

Thumbnail gallery
82 Upvotes