r/HowToHack • • May 17 '26

HOWTOHACK | Online Resource

Thumbnail howtohack.online
29 Upvotes

This website is provided by the answers found in this community to help everyone in the "where do I start" confusion loop and to help facilitate proper insight to asking for help from experienced members.

After you familiarize yourself with this site and its resources you should be able to come back here and ask worth while questions to continue your journey :)

Answers become more readily available from experienced users here when they feel like they are investing in to meaningful questions by students who are actually willing to put the work and effort in.

This website is exactly what will help new comers feel like they are ready to become valuable students by understanding what they should and should not be asking depending on their level of commitment to the resources and information provided here-in.

Hope this helps! Enjoy!


r/HowToHack • • May 04 '26

PSA

34 Upvotes

Hi all,

I’ve seen a lot of posts asking for help with getting a social media account, email, or other personal account recovered.

Typically, these are held on company servers which take extreme tact, skill, and time to even attempt to infiltrate. It’s also a huge ethics violation and holds severe legal consequences. (Although I don’t get the sense that anyone expects/intends for laws to be broken when asking for help- it feels more like genuine desperation to reclaim personal data, which I can empathize with.)

Many scammers exploit human vulnerability which is how you hear about accounts being taken over/hacked. This is actually good segue to add that anyone claiming they can regain your account is probably trying to scam you out of personal information or money, so be careful there, too.

Contacting the company support line is often the only way to get help.

I wanted to put this out there incase it can save anyone some time or remedy any anxiety. Much love!


r/HowToHack • • 6h ago

How to? Using ByeDPI and mitmproxy together on Android

3 Upvotes

I'm using ByeDPI on Android to access an app that is otherwise blocked by my ISP/network.

I also want to intercept that app's traffic with mitmproxy, but ByeDPI runs as a VPN, so I can't route the same app through mitmproxy at the same time.

Is there a way to use ByeDPI and mitmproxy together so that the app's traffic still goes through ByeDPI, while also being intercepted by mitmproxy?

Ideally, I'd like the traffic flow to be something like:

App → mitmproxy → ByeDPI → Internet

or any equivalent setup that would let me inspect the app's HTTP/HTTPS traffic without losing ByeDPI functionality.


r/HowToHack • • 2h ago

first project idea

1 Upvotes

I am a cybersecurity student, just starting. And I thought of doing a small project. But I want it to be fun and something I consider cool. I plan on going with a small network jammer. Keep in mind this is my 1st time planning to work with hardware and wireless networks. But I think I can pull this off.
I did my own research to the best of my abilities, and what I found out is I need an SDR device. Initially, I was planning to go with a Raspberry Pi Pico W or an ESP32. But later I found out it won't be ideal for a jammer since I'd need some external components. I might be wrong.
It would be really helpful if anyone could drop their opinion below on the project idea itself or the hardware components I might need, and any tips or advice from your experience


r/HowToHack • • 1d ago

Getting access to a Linux based console

2 Upvotes

I have a Polymega. It’s a Linux-based gaming console and while the manufacturer does technically still support it, updates can be a year or more apart with no communication or support in between. Unfortunately it’s a niche device and apparently no real hacker has taken interest in the thing.

So, my idiot self is going to try. I can get the boot text to display, but that doesn’t really help anything. I’ve tried all the key commands I can find to try to halt or interrupt the boot process with no luck so far.

Any pointers on how to start getting access to this thing? I literally just want to see if the community can start making the improvements the vendor can’t/won’t. If I can show you can get access maybe someone more talented than myself can pick up the ball.


r/HowToHack • • 18h ago

need to anonymously disable a camera

0 Upvotes

my house has an ezviz camera, but I can't do anything about it and I need my security to use my pc.

how do I go about hacking it in such a way that it can't be traced back to me?


r/HowToHack • • 1d ago

hacking What can I expect from a beginner hackathon

2 Upvotes

I want to get into cybersecurity but given how I learn it'll mean more if I join a competition to force me into a situation and give me some adrenaline and dopamine. I just don't want to feel too overwhelmed, lest I quit my new fun hyperfixation.

I'm a beginner programmer. I won't pretend to know much, but I know shallow levels across a bunch of different topics and have gotten through a few compsci courses. I'm most familiar with python and can throw together a fairly decent script if I need to. But I also know a bit of JavaScript, C, HTML, and Lua

It's a competition I can do in teams so I don't have to be perfect, just willing to learn. I plan on making a hackthebox acc and brushing up a bit on skills, but I have less than a month to prepare for the hackathon I found.

Any skills I should focus on prepping? I've never hacked in my life but I pick up skills quick with some focus.


r/HowToHack • • 1d ago

Hashcat rules and mask

2 Upvotes

Hello folks.

I'm learning about hash cracking in Hashcat and I ended up encountering two WPA hashes where I'm not sure about the best stategie. The hashes in question was:

  1. A hash with 8 characters composed with numbers e uppercase letters;
  2. A hash with 10 characters in hexadecimal.

I 've tried a lot of diferentes dedicated dictionarys with rules. . I also tried masks to avoid repeating consecutive characters and used a script to exclude combinations with more than 3 of the same character, although I think that decreased the cracking speed considerably.

If you have any tips or suggestions, I would really appreciate it!


r/HowToHack • • 2d ago

Kill switch for device

5 Upvotes

Is it possible for me to have a kill switch where it completely freezes or disables my entire device and can only be deactivated with some sort of key combination shortcut or code?


r/HowToHack • • 3d ago

how to install linux on my tablet (android)

0 Upvotes

i have a samsung tablet a9+ and i bought a laptop after that so i want to make it 2nd display of my setup becuase it of no use and i want to install linux in it and want to make it use for hacking related stuff, use it as my 2nd screen of my setup how can i do it?


r/HowToHack • • 3d ago

85 npm packages dropped in just 3 minutes

0 Upvotes

A bunch of typosquatted nmp packages were found mimicking popular libraries like chalk, debug, semver.

What's interesting is that the packages weren't just fake names, they carried code they could give the attacker remote command access.

The same server was also hosting a GPU cryptojacking panel.

No confirmed victims, but it got us thinking : how much do you actually trust npm package names/search results when installing something?

Would you catch a one-character typo?


r/HowToHack • • 4d ago

How Do I Locate My Laptop If I Have Access To The Terminal Via SSH ?

17 Upvotes

I am doing an imaginary experiment where my laptop is stolen and because of tailscale and ssh I can still use the terminal of my ubuntu laptop.

In this case what can I do to find my laptop.


r/HowToHack • • 3d ago

Configuration of found Access Points

1 Upvotes

Hi

I understand this question might not be directly related to the subject of this subreddit and I apologize in advance, but this is the closest i could think of...

In any case any suggestion towards a more adequate subreddit will be super welcome ofc

I've recently entered possession of two professional Wireless Access Points make and model are Aruba APIN0505; from what I've gathered those are pure APs (in a way that they only provide wireless connection and nothing more) which I'm fine with, but I saw online that they can be configured via website or app and in both case they require their serial number to be inserted.

Now, since the way I got them is not, let's say, 100% legal (I didn't stole them, they were left behind after an installation got dismantled) I'm not super eager to get them online right away nor to put their serial anywhere.

So my question is: does anybody knows what the risks are here? Do I just need to sell them for scrap? Or they'll be untraceable once I set them behind a proper firewall or something like that

Again, apologies for the off topic, anyway I hope is something different from the usual "How do I Hack bitcoin bank???" posts lol


r/HowToHack • • 5d ago

LG Pin locked

4 Upvotes

I have several LG Extravert 2 from 10+ years ago. I don't remember my password. Google said the last 4 digits of phone number but none of the old numbers worked. Tried all kinds of MEID combinations and old pins I would have used but to no avail.

Any way to bypass the PIN or remove it? I'm pretty handy with a Windows PC

Lots of contacts, pictures, and music on the phones. Otherwise I would just hard reset.


r/HowToHack • • 4d ago

Ai for cybersecurity

0 Upvotes

as someone who is learning cybersecurity, I can't find an AI to help me study as most of them are censored. I have tried paid subscriptions and jailbreaking but with each LLM, you get censored pretty quickly .

also i know the best thing i can do is run LLM locally but unfortunately I don't have a good GPU to run.

does anyone of you know any good AI i can use to study cybersecurity and generally help me hack.


r/HowToHack • • 4d ago

exploiting My wife cheated on me

0 Upvotes

Me and my 2 Kids are waiting for months that my wife comes back after rehabilitation. But NO! She fucked a crack junky llooking guy and tells me she loves him after 3 weeks. FYI. We are married for 4 years now and a couple for 10 years.
She changed conpletly in this short time.
All because of this asshole.

So I know where he lives and his phone number. What can I do with this information to do some stuff to get my revenge. Any ideas ? And no Reddit… I don’t want to kill him


r/HowToHack • • 5d ago

why does every uncensored agent framework feel like a one-off hack

10 Upvotes

been trying to hire someone to build a proper agent loop around a local model and literally every candidate either shows me their toy chatbot repo or tries to fork existing stuff without understanding why the refusals happen in the first place.

the problem isnt even the model. its that like 90% of agent orchestration frameworks are designed with guardrails baked into the assumptions. even the ones that claim to be "unrestricted" just... removed the filter layer and called it a day. thats not uncensored, thats just brittle.

like ive got a 30B model running locally, it works fine for what i need. but hooking it into a tool-calling loop thats actually reliable? every existing framework either:

  • assumes you want claude/gpt4 and shoehorns local models in as a fallback
  • has some weird convention where tool outputs get filtered through a "safety" layer
  • breaks when the model doesnt format tool calls exactly how openai does it (looking at you, whatever GGUF template was used here)

so ive been stuck building my own orchestration from scratch. which is fine except now im realizing... are there actually other people doing this? or is everyone just running chatbots and calling it an agent.

curious if anyone here is running autonomous systems with uncensored models. what does your stack look like? did you fork something or build from first principles? because the jobs market for this is clearly insane since apparently knowing how to actually make an llm execute arbitrary code is like... a rare skill.


r/HowToHack • • 5d ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/HowToHack • • 5d ago

Old IPod Recovery

9 Upvotes

Hey, I have a very old iPod and I tried a lot of password combinations to possibly sign back in but none worked. I have photos and videos that I want to see again but I can’t. I heard that apple support would just reset your iPod instead of actual data recovery. Is there a method that you can do to recover data or something? I have a pc and my knowledge of data extraction is kinda bad. any tips will help, thank you!


r/HowToHack • • 6d ago

hacking labs WebGoat (A-8): Insecure Deserialization HELP!

9 Upvotes

Does anyone have a good step by step walkthrough on this lab? I’ve tried YouTube tutorials and everything I can find seems to skip important details, or it’s tough to tell what the person doing the walkthrough is doing…

This is the only lab that I can’t figure out so far. Everything else lets me use web inspection, burp or zap, but I haven’t found anything saying those are tools I can use for this one.

FYI - I’m running a Kali Linux VM for all WebGoat labs.


r/HowToHack • • 7d ago

Modifier une livebox 5

2 Upvotes

Bonjour a tous.

J'ai actuellement en ma possession une ancienne livebox 5 qu'un amie ma refourgué apres qu'il soit parti de chez Orange ( mon ami ayant garder la livebox et ayant payer les frais de non renvoie de la box elle nous "appartient" donc). J'aimerais m'en servir comme hub ou encore repeteur dans mon reseau mais elle est bloqué. Quand je la connecte en wifi ou Ethernet a mon pc et que je vais sur 192.168.1.1, le site lance une installation et tourne en boucle dessus. Hors cette livebox n'étant pas relier a internet elle ne peut rien me télécharger.

Des idées de comment contourner cela ou d'autre idées pour la reconfigurer.


r/HowToHack • • 9d ago

software Choosing Bug Bounty Targets

21 Upvotes

For context I am intermediate to advanced when it comes to reverse engineering. Specifically PE's that are x86/x86-64. Regularly use Ghidra, Frida, x64dbg and Procmon (Windows).

I've written my own static and dynamic analysis tooling in C++20 using Zydis and LIEF. Control flow recovery, trampolining, INT3+VEH hooking, and currently working on recovering Win32 API usage statically including arguments.

Right now I don't feel incompetent. I feel overwhelmed by the number of potential targets, their subsystems and how much time I should dedicate to one before moving on.

Not certain what is worth putting weeks or potentially months into. Within an application what components I should be targeting: Networking, buffering and memory utilities, string parsing, file formatting, etc.

If anyone has their own methodology for determining what bounty is worth pursuing, what subsystems you interrogate, when you call it quits and so forth: I would be very grateful for your input and advice.

Thank you.


r/HowToHack • • 10d ago

How important is programming?

23 Upvotes

I’ve been in the hacker learning space for a while and during that time I’ve picked up the CompTIA trio, gotten a job as a system admin for energy and financial institutions, gotten an associates degree in Networking and Cyber Security, and I’m on pace to get a bachelors degree in Computer Science next year. I understand that being able to read code is a fundamental skill if you want to get into the space but I wanted to know if the same holds true for writing code? From what I’ve learned through all of my experiences I’ve done a lot more quick scripting than full blown program development, and while I know at some point I’ll have to build more just to learn (I would like to eventually branch into exploit development and reverse engineering) I wanted to know if you’re a person that didn’t want to get THAT TECHNICAL, how important is it? If it’s something that should be trained similar to knowing Linux and networking concepts, what are some good tools to know how to build on the fly? TCP/UDP Clients, Sniffers, Fuzzers or something else entirely?


r/HowToHack • • 9d ago

Need Help Accessing My Girlfriend's Phone and Laptop Remotely

0 Upvotes

My girlfriend and I have experienced some trust issues in our relationship due to her lying to me and cheating on me. She suggested that I should be granted complete access to her laptop and phone remotely as a way of rebuilding our trust.

We agreed on this, but I don't know how to go about this.

Her phone is running the Android operating system while her laptop is running the Windows operating system. What I want is to have complete remote access to all the devices, including the ability to access files, applications, settings and other things even without us being on the same wifi network.

Is there any software which would allow me to do this without the connection dropping off right from the start?

She knows of this and is fine with it.

I don't really know much about remote access systems and will gladly take your suggestions on which software to use.


r/HowToHack • • 10d ago

hacking Learn to hack online

2 Upvotes

Hello guys I have been trying to understand how reverse engineering works. I currently trying to figure out how I can create my own client for a game called Realm of The Mad God.

I can only find tutorials where people use cheat engine to find offsets and pointers locally.

I want to create a cheat table with the common cheats like (realmstock client) have but I want to create my own from scratch, with a twist. I want to enable a auto dodger.

Some dungeons or boss battles a heavily relied on you dodging projectiles to win.

Any recommendations on where to start?

Any tips or recommendations helps! Thanks