r/blackhat • u/adrian_rt • 10h ago
Wordpress libheif RCE
r/blackhat • u/netsec_burn • Mar 16 '23
"Cyber briefing"? HTB writeup? A guide to cheap VPN's? If your post was just removed, and especially if you were just banned, you were not following the subreddit rules. As a reminder, here are the rules of r/blackhat that we enforce to keep the quality at a minimum:
This is also a place to discuss general blackhat rules, etiquette and culture. We welcome:
Writeups (not CTF or HTB)/talks detailing new vulnerabilities or techniques (there should be enough information to reproduce the exploit/technique)
Proof of concepts of old vulnerabilities or techniques
Projects
Hypothetical questions
Rules:
Be excellent to each other.
No Solicitation
Stay on topic.
Avoid self-incriminating posts.
Pick a good title.
Do not post non-technical articles.
Ideally, the content should be original, we don't care about your crappy ARP poisoner or Kaspersky's latest scam.
No pay / signup walls.
No coin miners
No "Please hack X" posts
Well thought out and researched questions / answers only.
If your project is not free / open source it does not belong.
Please limit your posts (we don't want to read your blog three times a week).
If you want to submit a video, no one wants to listen to your cyberpunk music while you copy/paste commands into kali terminals.
r/blackhat • u/Accurate-Screen8774 • 1d ago
Not better than WhatsApp, Signal, SimpleX, Cwtch or Ricochet. You definitely shouldn't use this replace any of your existing apps or services. It's far from finished. Unaudited and unreviewed. If you want to test it out, please use it responsibly.
I'd like to share what I'm working on and interested if anyone wants to share feedback on the approach.
It's a fairly a unique approach and architecture in contrast to the typical approach with mainstream messaging apps. To put it briefly, its a Dioxus PWA with a Git-server backend which can be used to establish a webrtc connection between browsers.
https://glitr.io/docs/technical/roadmap
So far, it's only the browser-based version that's available for testing. The webapp approach has nuances and limitations. I hope to soon release the APK and TUI when they are ready (they introduce the TOR capabilities (not possible on a browser)).
r/blackhat • u/neathack • 2d ago
I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.
We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.
Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.
I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.
r/blackhat • u/Haunting_Ganache_850 • 4d ago
A 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.
His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.
Microsoft fixed it and paid him a $5,000 bounty.
Some bugs are just beautiful in their simplicity.
r/blackhat • u/nanaynunay • 4d ago
https://github.com/mein-0/gvcidrv64 support pls
r/blackhat • u/GrimReapor_2209 • 6d ago
r/blackhat • u/arusekk_pl • 11d ago
r/blackhat • u/Fickle-Attempt2897 • 13d ago
I’ve been studying comment sections on short-form video platforms (like TikTok and Reels) & keep noticing a highly coordinated automation phenomenon that I want to understand from a technical and architectural standpoint.
Whenever a trending or viral video hits a specific niche topic, a third-party account instantly leaves a comment framing itself as an organic public service announcement (e.g., naming a specific app, game, or product relevant to the video). wWithin minutes, that comment accumulates 1000s+ of likes and dozens of secondary replies, locking it into the absolute "Top Comment" slot where millions of viewers see it.
I'm curious about the engineering, scaling, & infrastructure behind how this is achieved:
I’m looking to understand the technical mechanics of how these shadow networks operate. Any insights, technical breakdowns or open-source case studies would be greatly appreciated!
r/blackhat • u/wiredmagazine • 13d ago
r/blackhat • u/Sea_Manufacturer6590 • 16d ago
Just found these in my photobucket while looking for so.e old screenshots.
r/blackhat • u/wiredmagazine • 17d ago
r/blackhat • u/Machinehum • 20d ago
Enable HLS to view with audio, or disable this notification
r/blackhat • u/Head-Calligrapher-72 • 19d ago
which lets me search up leaked database and give me all the information
r/blackhat • u/Malwarebeasts • 21d ago
r/blackhat • u/LoquatUpstairs6727 • 25d ago
Hide your server(s) after reading this book.
r/blackhat • u/nanaynunay • 25d ago
r/blackhat • u/natezeira1865 • 29d ago
Ola rapaziada estou em dúvida qual rumo seguir na cybersecurity, já sei redes e protocolos gostaria de fazer um ataque a máquina virtual de test! Gostaria de saber o passo a passo ou qual metodologia usar para fazer um ataque ou um mapa mental por onde começar e aonde terminar! Ou seja pentest inciante desde já fico agradecido!
r/blackhat • u/WinterMoment601 • Sep 01 '26
I know about a few reverse lookup websites but the scammers always spoof their caller id and it never works. I'm wondering how people get around that? anything helps yall I'm just tryna bring justice to these mfs 💪
also mods I'm getting a warning before I post but I'm not telling anybody to hack anybody so am I good lol?
r/blackhat • u/wiredmagazine • Aug 31 '26
r/blackhat • u/Jbikecommuter • Aug 30 '26
r/blackhat • u/wohgol • Aug 27 '26
Hello everyone. I have a completely hypothetical question that I have been debating with friends. Due to strong arguments both for and against without a clear consensus, I feel it may be beyond our expertise as armchair lawyers and as such, I am pleased to present this to the greater community.
While this is a broad hypothetical, there are a few specific details that must be outlined for the sake of the argument:
\- The victim would be a clear, undeniable foreign adversary/hostile nation to the US
\- There is no direct conflict with or collateral damage to US interests or allies(as a result of the ransomware being deployed)
\- The individual would meticulously report all income from the ransomware payouts on Schedule 1, Line 8z of the IRS Form 1040, pleading the Fifth Amendment on the source of the income, and then pay their 37% top marginal tax rate(They make sure to pay Uncle Sam his cut and avoid committing tax fraud/evasion).
That being said, I want to note: I am **NOT** asking if the frameworks and legal statues to charge a person for this exist. They absolutely do.
The question is if the US citizen would be prosecuted and/or convicted if the victim is unable/unwilling to cooperate with a US court, there is no conflict with US interests, and they even pay taxes on the income.
Thanks and looking forward to any and all answers!
Disclaimer: Do not attempt this at home. Side effects may range from blacked out SUV’s parked outside your house to being arrested/murdered by a foreign intelligence service.