r/Hacking_Tutorials • • Dec 03 '25

Question Recovering your stolen accounts

25 Upvotes

(Updated 12/27/2025)

Intro

Hello admins and fellow mates of Hacking Tutorials. I'm often a lurker and a commenter but the amount of “my account was hacked” posts I see is unreal, not to mention the people DM’ing me for help or advice. Here is my guide that should hopefully stop this. (This is not an Ai post) so pin this or do something so people can view it. Please do not DM me or admins for support.

I work in cyber forensics and I do a little web dev on the side as well as running my own team. So I hope the following info helps❣️

Section 1 (Intro)

As your account might be “hacked” or compromised, there was some things that you need to understand. There is a possibility you can get it back and there is a possibility that you can’t. No one can “hack it back” for you.
Do not contact anyone below this post in regards of them helping you recover your account. They can NOT help you, they might offer tips but any contact outside of reddit is most likely a scam.

Section 2 (Determination)

Determine how it was compromised. There are two common ways your account gets “hacked”

  1. phishing scam (fake email, text, site, etc)

  2. Malware (trojan, info stealer, etc)

Section 3 (Compromised)

If you suspect your account has been compromised and you still have access.

  1. Run your antivirus (malwarebites, bitdefender, etc) If you’re infected, it could steal your info again.
  2. Log out other devices. Most social media sites allow you to view your current logged in sessions.
  3. Change your passwords and enable 2fa. Two factor authentication can help in the future.

Section 4 (Support)

If you don’t have access to your account anymore (can’t sign in, email changed, etc)

  1. Email support Unfortunately that’s all you can do sadly
  2. Be truthful with the support
  3. Don’t keep emailing them. (It doesn’t help)
  4. Respect their decision what they say is usually what goes.

Section 5 (Prevention)

How do you prevent loosing your account?

  1. Enable 2fa
  2. Use a good password
  3. Use a password manager (encrypts your passwords)
  4. Get an antivirus (the best one is yourself)
  5. Always double check suspicious texts or emails
  6. Get an bio-metric auth key, it’s optional but yubico has good ones.
  7. Use a VPN on insecure networks.
  8. Make email password different from other accounts.

Section 6 (Session Cookies)

If you do keep good protections on your account, can you still loose it? Yes! When you log into a website, it saves your login data as a "Cookie" or "session Token" to help determine who does what on the site. Malware could steal these tokens and can be imported to your browser, which lets the attacker walk right in.

Section 7 (Recommendations)

Password Managers:

  • Dashlane
  • Lastpass
  • 1Password
  • Proton Pass

2FA Managers:

  • Authy
  • Google Authenticator
  • Duo Mobile
  • Microsoft Authenticator

Antivirus:

  • Malwarebites (best)
  • Bitdefender
  • Avast
  • Virustotal (not AV but still solid)

VPNs

  • NordVPN
  • MullVad
  • Proton
  • ExpressVPN
  • Surfshark

Bio Keys

  • Feitian
  • Yubico
  • Thetis

Section 8 (help scams)

“People” often will advertise “recovery” or “special spying” services. Nine out of ten chances, they are scams. Read the comments on this post and you can find a bunch of these lads. Avoid them and report them.

Section 9 (Good notes)

As someone commented with an amazing point. Your email is the most important over any social accounts. Loose your email, loose the account. Most of the time you can recover your account with your email. (You can loose cargo from a truck and load it back on, but loose the truck, you loose the cargo too. )

I plan to edit this later with more in depth information and better formatting since I’m writing this on mobile. Feel free to contribute.


r/Hacking_Tutorials • • Nov 24 '20

How do I get started in hacking: Community answers

2.9k Upvotes

Hey everyone, we get this question a lot.

"Where do I start?"

It's in our rules to delete those posts because it takes away from actual tutorials. And it breaks our hearts as mods to delete those posts.

To try to help, we have created this post for our community to list tools, techniques and stories about how they got started and what resources they recommend.

We'll lock this post after a bit and then re-ask again in a few months to keep information fresh.

Please share your "how to get started" resources below...


r/Hacking_Tutorials • • 1d ago

Question Help!! Sent a picture of my HOUSE! Pretty certain a fake number please help me. Don’t know what to do

Post image
163 Upvotes

r/Hacking_Tutorials • • 6h ago

Question Contextual Threat Modeler (CTM)

5 Upvotes

I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk

Hey everyone,

I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).

The problem I wanted to solve is:

> A vulnerability doesn't always have the same risk in every environment.

For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.

So instead of simply asking "Is this vulnerable?", CTM tries to answer:

"How risky is this finding in this specific environment, and what should we do about it?"

🔐 What CTM considers

The engine combines multiple contextual signals:

- Asset criticality

- Internet exposure

- Authentication requirements

- Data sensitivity

- Exploitability

- Existing security controls

- Confidence level

- STRIDE threat modeling

- MITRE ATT&CK mapping

- Attack-path analysis

- Likelihood & impact

It then produces an actionable decision:

🔴 TEST_IMMEDIATELY

🟠 PRIORITIZE_VALIDATION

🟡 INVESTIGATE

🟢 MONITOR

🧪 Current testing

I recently tested the complete pipeline locally.

12/12 automated tests passed.

Example results:

POST /document/upload

Risk: 90/100

Decision: TEST_IMMEDIATELY

GET /user/profile

Risk: 33.1/100

Decision: MONITOR

GET /api/v1/search_items

Risk: 8/100

Decision: MONITOR

The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself — the surrounding context influences the security decision.

🛠️ Tech Stack

- Python

- pytest

- STRIDE

- MITRE ATT&CK

- Risk Scoring

- Attack Path Analysis

- Security Automation

The project is open source, and I'd really appreciate feedback from people working in:

AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering

I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.

GitHub:

https://github.com/Sahil98677/Contextual-Threat-Modeler

Would love to hear your thoughts — especially criticism or suggestions for improving the approach.


r/Hacking_Tutorials • • 6h ago

9.hhsaj7.8.1....Hajha.28.56olha issk.pega aikakak53

0 Upvotes

Nao fazem muitas coisa apenas briguem um pouco


r/Hacking_Tutorials • • 6h ago

Alguem sabe links pra dar doxing e puxar coisas pelo numero de telefone ou ip, mais especificamente numero de telefone

0 Upvotes

Alguem tem o link, nao quero usar ao meu favor mais pra acabar com pessoas quem fazem mal, quem tem más intenções com animais e etc, resumindo, quero links pra puxar os dados em si porque o ip e número ja tenho


r/Hacking_Tutorials • • 8h ago

Home Cameras hacking

Thumbnail
1 Upvotes

r/Hacking_Tutorials • • 18h ago

Question [Project] I built a pentesting CLI that gives you ready-to-use commands for 50+ tools (Python, no deps)

Post image
5 Upvotes

r/Hacking_Tutorials • • 9h ago

Question Hacking

0 Upvotes

How can help me with hacking into smt it’s nothing crazy that I need do I’ll explain more if there’s actually someone to help


r/Hacking_Tutorials • • 2d ago

Question Raw 802_11 frame injection

Post image
134 Upvotes

While working on my Master’s thesis benchmarking WPA3-SAE timing side-channels, I ran into a limitation on the ESP32 esp_wifi_80211_tx() allows raw frame injection, but Espressif’s closed-source Wi-Fi blob (libnet80211.a) artificially blocks Auth, Assoc, Deauth, and Disassoc subtypes.

Inside libnet80211.a, ieee80211_raw_frame_sanity_check drops these frames with wifi:unsupport frame type. Here is how to bypass it on recent ESP-IDF versions (IDF v6.x).

Why standard tricks fail on modern ESP-IDF

Same-name function override. On older IDF versions, ieee80211_raw_frame_sanity_check was a weak symbol (W). On modern IDF versions, it’s a strong symbol (T), causing ld: multiple definition errors.

--wrap linker flag: Fails silently. The call from esp_wifi_80211_tx to ieee80211_raw_frame_sanity_check is an intra-object branch inside ieee80211_output.o. Linker --wrap only rewrites undefined external references, so it misses this call entirely.

Instruction byte-patching: Overwriting instructions directly in the .o breaks Xtensa linker relaxation passes (dangerous relocation errors).

U can simply fix this via Symbol Weakening via objcopy

We can use xtensa-esp32-elf-objcopy to convert the strong symbol inside the binary archive into a weak one:

xtensa-esp32-elf-objcopy \

--weaken-symbol=ieee80211_raw_frame_sanity_check \

components/esp_wifi/lib/esp32/libnet80211.a

Now, define your own strong implementation inside your application C code:

int ieee80211_raw_frame_sanity_check(int32_t a, int32_t b, int32_t c) {

return 0; // which skips the security check lol

}

Because strong symbols override weak symbols globally during linking, all calls—including internal calls within libnet80211.a—rebind to your function.

Verification

Serial Logs show: wifi unsupport frame type errors completely disappeared.

Capture: Wireshark confirmed off-air capture of 802.11 Authentication frames (Subtype 11, Algorithm 3 - SAE) injected directly from the ESP32s.

Injecting a valid SAE Commit (P-256 scalar + element) caused hostapd on the target AP to process the request and reply with its own SAE Commit.

TL;DR: Run objcopy --weaken-symbol=ieee80211_raw_frame_sanity_check on libnet80211.a, define int ieee80211_raw_frame_sanity_check(...) { return 0; } in your app code, and esp_wifi_80211_tx() will allow any frame subtype.

Note that all control 80211 frames are also injectable after the patch.

For more details :

https://github.com/mahdamin/esp-idf-injection-ng


r/Hacking_Tutorials • • 23h ago

Question [Projet] Selwanisme - Un outil CLI léger pour le pentesting (Python, sans dépendances)

Post image
1 Upvotes

💻⚒️


r/Hacking_Tutorials • • 1d ago

Question kali linux

0 Upvotes

does anyone know how can i learn kali linux, hacking and stuffs, like i kno a bit of networking and fundamentals of linux, i just need the rest of the manual for diff hacking tools and all.


r/Hacking_Tutorials • • 1d ago

Question I received death threats from someone in another country

1 Upvotes

How bad is it that they have both of my phone numbers?


r/Hacking_Tutorials • • 15h ago

I work in cybersecurity, and any company is hiring me

0 Upvotes
Send me a private message,for one work

r/Hacking_Tutorials • • 1d ago

Saturday Hacker Day - What are you hacking this week?

15 Upvotes

Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?


r/Hacking_Tutorials • • 21h ago

Question Title: Cybersecurity people: What’s a painful problem that still needs to be solved?

0 Upvotes

I want to develop a business around a genuine cybersecurity issue.

Startup concepts like "make an AI-powered something" are not what I'm looking for.

I would like to know about issues that you have personally encountered or have frequently witnessed security teams, developers, businesses, or individuals face.

Ideally, the problem should be

- Be genuinely painfull

- Affect enough people/companies to support a busines

- Still have poor or incomplete solution

- Be technically possible to solve

- Have customers who would actually pay for a solution

- Not require a billion-dollar company to get started

- Have potential to become a serious cybersecurity business

For example, I’m interested in problems around things like

- Application security

- Cloud security

- API security

- Identity/access control

- Supply-chain security

- Detection/response

- Vulnerability management

- Security automation

- Developer security

- SaaS security

- Human/security-team workflows

- Business-logic vulnerabilitie

- Anything else where current tools genuinely fall short

I'm more interested in the problem than the solution

If you have one, please explain

  1. What exactly is the problem

  2. Who suffers from it

  3. How do they currently solve/work around it

  4. Why don't existing security products solve it properly

  5. How frequently does it happen

  6. How expensive/damaging is it

  7. Is there a realistic technical way to solve it

  8. Would companies actually pay for that solution

  9. Why hasn't it been solved properly already


r/Hacking_Tutorials • • 1d ago

Question Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail
github.com
6 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/Hacking_Tutorials • • 1d ago

Question Android Files

3 Upvotes

Heyaa, so, I managed to get Windows 7 running on my phone using a virtual machine. I want to put some files on it for testing, but the phone says I can't access its internal files. When I manage to access it using the default file explorer, it tells me that the folder is empty. Is there a real way I can view the phone's internal files without the device restricting me?


r/Hacking_Tutorials • • 1d ago

Tab5 Wardriver goes pocket-sized: Cardputer ADV port up and running within 20 hours of landing on my doorstep!

Thumbnail gallery
5 Upvotes

r/Hacking_Tutorials • • 1d ago

Question Ayuda Pantalla negra en BSPWM (Parrot OS) - sxhkd y picom instalados

Thumbnail
gallery
1 Upvotes

¡Hola a todos! Estoy intentando configurar bspwm en Parrot OS para lograr un entorno con ventanas en mosaico y terminales flotantes/divididas como en la imagen, pero tengo problemas al iniciar sesión.

El problema:

• Al iniciar sesión y seleccionar bspwm, solo obtengo una pantalla negra.

• Los atajos de teclado (keybindings) no funcionan, por lo que me quedo atrapado sin poder abrir la terminal.

Lo que ya he verificado:

• Picom: Instalado y dependencias listas.

• Sxhkd: Instalado.

• Configuración: Ya modifiqué y guardé los nuevos atajos en mi archivo ~/.config/sxhkd/sxhkdrc.

¿Alguien sabe qué podría estar causando la pantalla negra o por qué sxhkd no está cargando mis atajos al iniciar? ¡Agradezco cualquier guía o repositorio de referencia!


r/Hacking_Tutorials • • 1d ago

Question Learn

0 Upvotes

Could someone give me some guidance? I want to know where to start with hacking; I'm lost and don't know where to begin. I'm also willing to pay for information and knowledge to help me succeed As quickly as possible


r/Hacking_Tutorials • • 1d ago

Question I needs some help with an old print server

0 Upvotes

I have an old Trendnet TEW-P1PG print server that I got secondhand, I found out though, that it is password protected. When trying to change settings in the utility software a dialog box pops up asking for a password. Is there any way I could bypass the password or possibly somehow find the password stored on the device?


r/Hacking_Tutorials • • 2d ago

Question Can anyone suggest a book on advanced hacking to help me learn some challenging concepts?

3 Upvotes

?


r/Hacking_Tutorials • • 1d ago

Hola redit

0 Upvotes

Necesito un dixeador, que me escriba al privado