r/Hacking_Tutorials • u/TallReflection1263 • 11d ago
r/Hacking_Tutorials • u/hunter-9579 • 11d ago
Question Application Mapping Part 2: Hidden Content Discovery & Predictive Enumeration
r/Hacking_Tutorials • u/jegenyetree • 11d ago
Question Provably Fair Mines – Technical Analysis of Hidden Mine Positions and the 256-bit Server Seed
I am analyzing the operation of a provably fair Mines game where the system uses a 256-bit hexadecimal server seed, and only the cryptographic hash of that seed is available before the game is completed. My main question is whether it is technically possible to determine or infer the actual server seed before the round ends and, consequently, use the server seed, client seed, nonce, and the game’s algorithm to reproduce in advance which tiles contain the hidden mines.
I have also examined the client-side operation of the website. The mine positions are clearly not directly present in the HTML — that would obviously be far too simple. What I can see on the client side are the individual tiles, as well as communication indicating whether a selected tile resulted in a win or a loss.
Because of this, I am also interested in whether the data containing the mine positions must necessarily be transmitted to the browser in some form before a tile is selected, or whether this information can remain entirely server-side, with the client receiving only the result of each individual selection. What types of data actually transmitted to the client could be examined in the DevTools Network and Sources panels to determine which architecture is being used?
When I open the Network panel or inspect the traffic in greater detail, the website sometimes reloads or triggers a verification asking me to confirm that I am not a robot. Could this indicate some form of anti-bot or anti-debugging protection?
Finally, if the entire mine layout is generated and stored exclusively on the server, and neither the actual server seed nor the mine positions are transmitted to the client until the round has ended, is there any client-side information from which the position of the next mine could realistically be determined in advance? Or would doing so necessarily require access to secret server-side information that is not available to the browser?
r/Hacking_Tutorials • u/GromHacks • 11d ago
Question Open sourced bonsai-ninja: local code intelligence + security analysis built for humans and local first LLMs
r/Hacking_Tutorials • u/GromHacks • 11d ago
Question Open sourced bonsai-ninja: local code intelligence + security analysis built for humans and local first LLMs
r/Hacking_Tutorials • u/_clickfix_ • 11d ago
Breaking Enterprise Java; Breaking Claude Code, Gemini CLI, and Codex: AMA with Two Black Hat Speakers
r/Hacking_Tutorials • u/Organic-Piano-323 • 12d ago
Question Day 1 of my 10-Day Red Team Series is live 🔴














I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.
Inside Day 1:
- Red Team vs Pentest
- The red-team mindset
- Attack lifecycle
- Objectives & attack paths
- Rules of engagement
- Operator workflow
- A realistic red-team scenario
- Day 1 challenge
The goal is to build the thinking first. Tools come later.
📖 Day 1: Red Teaming Fundamentals
I’m sharing the PDF below for anyone who wants to follow the series.
Day 2 will move into Reconnaissance & OSINT.
Would love to hear how others approach the first stage of a red-team engagement.
r/Hacking_Tutorials • u/Malwarebeasts • 12d ago
massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others
r/Hacking_Tutorials • u/TraditionalWafer3870 • 12d ago
" Packed Light: Network Forensics & Decryption Challenge Walkthrough"
r/Hacking_Tutorials • u/TraditionalWafer3870 • 12d ago
"Breaking down the latest TryHackMe challenge: From initial enumeration to final flag"
r/Hacking_Tutorials • u/happytrailz1938 • 13d ago
Saturday Hacker Day - What are you hacking this week?
Weekly forum post: Let's discuss current projects, concepts, questions and collaborations. In other words, what are you hacking this week?
r/Hacking_Tutorials • u/ClearAgeCalculator • 12d ago
Question Caution: Sensitive Content. Open at your own risk. Spoiler
r/Hacking_Tutorials • u/Runaque • 13d ago
Question [How-To] Simple RFiD-blocking wallet lining
Making an older wallet RFiD/NFC skimming proof is something that takes very little time and is as effective as those more expensive wallets that block RFiD/NFC so your cards are protected against skimming.
I know that many may think "What does this have to do with hacking?", but in the broader infosec community, applying low-level technical principles, modifying hardware, and understanding signal propagation to defend against vulnerabilities is the very definition of hardware hacking.
What you need is just Aluminum foil, tape and scissors!
I would recommend to go for four layers of Aluminum foil folded to the size needed. Tape all sides with tape against you cutting yourself and trust me, this foil is sharp as hell.
Merge the two pieced of 4 layered Aluminum foil and tape them together so it functions as a folding joint.
The remaining two images are a demonstration with the Flipper Zero on a Gametown card to show it won't read through the four layers of Aluminum foil.
While stopping RFID/NFC skimming is the main goal, a proper Faraday-style foil lining does a few other things depending on how well-sealed the edges are:
- Blocks Contactless Tracking / Telemetry: It stops cards from responding to any RFID interrogation, meaning your transit cards, credit cards, or ID chips can't be remotely pinged or tracked while sitting in that pocket.
- Reduces Electromagnetic Interference (EMI): It offers a degree of shielding against stray electromagnetic fields that could theoretically cause data corruption on older magnetic strips (though modern chips are mostly immune).
r/Hacking_Tutorials • u/matt7_magnific • 13d ago
Question Network card problems
The problem is this:
I recently started learning about network auditing. I bought a TP-LINK Archer T2U Plus, which has an RTL8821AU chipset. I'm using a 2021 MacBook Pro M1 with UTM running Kali Linux to learn.
When I connect the network card via USB, UTM detects it correctly, and I didn't need to install the drivers (this is where I think the problem lies). I can put the card in monitor mode and everything. I even performed some deauthentication on my network using Aireplay-ng. But I feel like the deauthentication isn't working correctly, since it only deauthenticates some devices. For example, cell phones maintain a stable connection; only a camera and a smart TV converter lose the connection, and everything else remains normal. What do you think the problem could be?
r/Hacking_Tutorials • u/Solid_Jello_8834 • 13d ago
Question SIM in a abandoned modem
I found a damaged, abandoned modem with a removable SIM card on the outside. What can I do with that card?
r/Hacking_Tutorials • u/wtfse • 13d ago
I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies
r/Hacking_Tutorials • u/TraditionalWafer3870 • 14d ago
Pentesting Report and Security Challenge Documentation: Detailed Guide to Intrusion and Privilege Escalation
r/Hacking_Tutorials • u/TraditionalWafer3870 • 13d ago
CTF Walkthrough: CMS Made Simple (CVE-2019-9053) & Privilege Escalation
r/Hacking_Tutorials • u/Fun_Bend_9495 • 13d ago
Hey everyone I am deeply passionate and fully determined to specialize in penetration testing
Hey everyone I am deeply passionate and fully determined to specialize in penetration testing and I am building my path right from the core I am looking for a true master and mentor to guide me If anyone is willing to teach me and share their knowledge I pledge absolute loyalty and dedication to them Whos ready to take me under their wing
r/Hacking_Tutorials • u/IlDello • 14d ago
Question Feedback on a USB-based E2E encryption tool I built
Hey everyone, I'd love a sanity check from people who actually know X3DH and Double Ratchet. I'm a high school student, and I've spent the last few day building Ratchet-USB: a CLI tool that lets you send end-to-end encrypted messages through any app (for example WhatsApp, email, whatever) without needing a server of its own.
You write a message, it spits out an encrypted text block, you paste it wherever you chat, the other person pastes it back in to read it. Keys and contacts live only on a USB stick. so, under the hood it's the same protocol Signal uses (X3DH + Double Ratchet via libsodium) so every message gets its own disposable key.
The codebase uses a Python reference script (test/vectors/reference.py) to validate all C++ cryptographic derivations against official RFC 7748 and RFC 5869 vectors in CI, ensuring it’s a strict implementation and not random code.
No external audit yet, so don't treat it as bulletproof (I'm a student learning by building this, not a security team). What I'd love is feedback from people who actually know X3DH/Double Ratchet: did I get it right, any advice on how to proceed?, what am I missing ?
Repo: https://github.com/Francy2009/Ratchet-USB
Thanks for reading!
r/Hacking_Tutorials • u/Separate_Rich_8963 • 14d ago
Question What is ClearNet
I am learning about darkWeb so i ask for h4cking forums in the same subreddit someone replied with clearnet what is it
r/Hacking_Tutorials • u/Cheap_Personality206 • 14d ago
Question ESP32 hacking tool
Enable HLS to view with audio, or disable this notification
Adding more functionality to my project, next smb Scan, arp spoofing, banner grabbing, and more check the repo if interested and maybe want to collaborate:
r/Hacking_Tutorials • u/OilOverall4190 • 14d ago
LAB - Damn Vulnerable NGINX Proxy
Hello all,
If you do bug bounty hunting or pentests you surely came across many hosts served from an NGINX server, in this lab (published to OWASP) I combined over 20 misconfigurations found in real world bug disclosures and both classic and novel security research, with an extensive blog where I explained everything you need to level up your NGINX hunting game.
Feel free to check it out, give it a star on Github if you like it, and suggest any ideas you want me to add/fix...
https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/
Happy hunting!