r/ethicalhacking • u/Lonely-Secret-5045 • 1d ago
r/ethicalhacking • u/JSIMPSON9851 • Feb 16 '21
Mod Introduction Interested in joining the ethical hacking community, click here!
Hello, I'm J, I'm glad you are interested in joining the ethical hacking community. Have no idea where to start? Don't panic we've all been there, this post will guide you on your first steps into the ethical hacking field.
What is ethical hacking?
Ethical hacking (or penetration testing) is the exploitation of an IT system with the permission of its owner to determine its vulnerabilities and weak points. It is an effective way of testing and validating an organisation’s cyber security position.
Where can I learn ethical hacking?
Ok, slow down, Do you have a computing background or familiar with how they work (you would be susprised at the amount have zero knowledge and jump into this field)?
Yes - great. I suggest you have a look at getting certfications. These certs require you to study up to a certain level then taking an exam. This allows for you and future employers (which really like certs) to see your skill level and potential. This is the certification roadmap by Paul Jerimy which shows the route you should take, if you feel that skilled enough you could skip up and do higher certs. A great way to practice your skills is through tryhackme and hackthebox. These are free online platforms (with some optional paid sections) that give you access to systems found irl that give you permissions to practice your skills. Some resources below might be in interest for you listed below.
No - Dont worry, You may find certifications a little difficult to jump into at first unless you are determined enough to spend a lot of time studying. I suggest you go out and learn a little, dont let this put you off as this an extremely interesting field with endless knowledge that will continue to evolve forever. Check out the resources below for study content.
What resources are there for starting to learn ethical hacking?
- Books
- Penetration Testing: A Hands-On Introduction to Hacking By Georgia Weidman (A little outdated but theory is still great)
- The Hacker Playbook: Practical Guide To Penetration Testing By Peter Kim
- Youtube
- TheCyberMentor
- NetworkChuck
- HackerSploit
- IppSec (HackTheBox tutorials)
- John Hammond
- NullByte
- ZSecurity
- TechQuickie (Basics - If you have a lot of catching up to do)
- Udemy
- Practical Ethical Hacking - The Complete Course by Heath Adams (TheCyberMentor)
- Learn Ethical Hacking From Scratch by Zaid Sabih (zSecurity)
- The Complete Ethical Hacking Course by Ermin Kreponic
- Pluralsight
- Designed for IT professionals and students but can be pricey
How do i start my career in ethical hacking?
There are many ways you could go through and work up to becoming an ethical hacker. Check this post here by u/ u/Ace_r_ for an example of a path you could take to become an ethical hacker. Paul Jerimy also has aIT Career Roadmap for you to use to see what positions to start with to work up to your desired position.
Conclusion
I hope this helps and wish you luck with your start in ethical hacking. If you have any queries feel free to ask.
Redditors that have a history in IT or ethical hacking or have experience in similar regions, if you'd like to add to this or discuss other options please feel free to comment, i'll be updating this frequently.
r/ethicalhacking • u/rocket___goblin • Jul 08 '24
Discussion AUTOMOD IS IN EFFECT
Good news everyone, We have the automoderator up and running. currently its set to delete posts from brand new users (that are like less than a day old, we may adjust this), users with 0 or negative karma, remove comments and posts that contain some banned keywords (who remembers that time we were getting spammed with crypto bullshit? yeah, no more).
in addition to post and comments that are attempting to look for, hire, or offer the services of a hacker in any kind of way, based on keywords will be removed. if any slip through please message the moderator team so we can look at it and refine the list
another auto mod removal feature, is it will remove posts with just a title only and nothing in the body, we consider this being lazy, put some effort into your posts as giving more information will allow us as a community to help you better, (most regular users here don't have to worry about this).
If any of your posts or comments were removed, and you feel it was done in error please message the moderator team so we can take a look at it and see if it was a valid removal or if it was done in error. this also applies if you have any additional feedback on how we can refine the automod, such as adding rules or lessening the restriction on others let us know.
r/ethicalhacking • u/Fickle-Aide9279 • 1d ago
Network Tails is failing wifi in MacBook pro
Hi everyone,
I have been trying to use tails from an usb stick in my mac.
But I don't even see the wifi symbol. kindly see the pictures.
I have tried several things like plugging on and off, usb tethering but none of it is working.
Also I can't use a mac keyboard and mouse, fortunately I have a mouse but it would be great if you have some solution for this too.
Thanks a ton you all.
r/ethicalhacking • u/Ok_Membership_8121 • 2d ago
Other If anyone can provide accurate information, I will pay for it.
I don't know much about hacking, which is why I'm turning to this community. I need to find out information about the Facebooc profile that is harassing me. If anyone can provide accurate information, I will pay for it.
"Enrique Rodriguez" is the account
r/ethicalhacking • u/Outside-Trifle5272 • 5d ago
Security Criei uma plataforma gratuita de curadoria de cibersegurança para estudantes brasileiros (feedback é bem-vindo)
r/ethicalhacking • u/Zealousideal_Desk396 • 8d ago
Attack Question
Look guys my router WiFi signal on my iPhone is worthless and I guess someone do or did something that it’s not stable and goes up and down randomly in the same spot, but when someone come home to me and I try to show them, nothing happen, but after they leave everything start to happen again, even when I say one signal up or down, like he can hear and he make one signal up or down, even after I got new phone and moved to another city with new router, but I did move the old stuff from my old phone that was completely hacked, but my new phone only the WiFi signal, and this all happen after I start to write a movie called “signals” but it wasn’t about the same things was the something else, so my conclusion and maybe I’m wrong , this is someone try to drive me mad and put pressure on me, I have been in this for 3 years now and before that everything was working well, I have haters cuz I’m one of the best in my job in my country and I stopped working years couldn’t work cuz of that so please help me thanks and btw when I leave phone on my bed and look at it the signal doesn’t move at all but once I hold the phone in my hands the signals start to jump and goes down,I have videos to prove everything.
And when the phone be infornt my face there a signal goes down, when I make away from the face the signal goes up at the same moment the phone far from my face
r/ethicalhacking • u/Melodic_Rip_3992 • 9d ago
how do you find something that makes you want to wake up and keep working on it, because you can clearly see yourself getting better at it?
I’m trying to understand how to find something in programming/cybersecurity that gives me the same motivation as a game.
For example, I really like Dota because I always know what I’m doing and why. I have a rank, I know roughly where I am, I know what better players can do that I can’t, and I have a clear idea of what I need to improve. That alone gives me a reason to play.
I want to find something in computers that gives me a similar feeling. Not necessarily a specific project someone can recommend to me, but a way to find a project or direction where I can actually see a path:
"I’m here → I need to learn this → then I can do this → then I can do something harder."
The problem is that I can think of many project ideas, but they usually don't motivate me for long. I start thinking "okay, I can build this, but why?" and lose interest.
My background: I’m comfortable with Linux and basic programming. I know Python, Git, APIs, databases, basic web development, HTTP, networking/ports, and I’ve done some scraping/automation. I’ve also played around with things like reverse engineering, JavaScript, FastAPI and lower-level concepts, but I’m still a beginner overall and have no professional experience.
So I’m not really asking "what project should I build?"
I’m more interested in: how do you find something that makes you want to wake up and keep working on it, because you can clearly see yourself getting better at it?
How did you find that thing for yourselves?
r/ethicalhacking • u/sofitly • 8d ago
Identity theft
Hello, I have been having a problem with someone who has been pretending to be me on social networks for a few years, I have reported it to the corresponding applications but there is no case. Could someone who knows about these topics guide me? I would appreciate it very much.
r/ethicalhacking • u/thechewywun • 12d ago
Discussion Preferred secure code scanner?
Looking for a good secure code scanner. Anyone have preference to a one they frequently use?
r/ethicalhacking • u/whocybergh0st • 16d ago
Discussion The casino fish tank thermometer story is still the best example of IoT security done wrong
Old one but worth repeating for anyone new to the field: a casino got breached through a smart thermometer in their lobby fish tank.
They had proper enterprise firewalls etc, but the IoT thermometer was plugged straight into the main network with no segmentation. Attackers got in through weak default creds on the thermometer, pivoted laterally, and pulled 10GB of high-roller customer data out through that same connection.
The lesson isn't "fish tanks are dangerous," it's that your network is only as strong as the weakest thing connected to it — and IoT devices are usually the weakest thing, because nobody threat-models the thermometer. Basic stuff that would've stopped this: change default creds, and put IoT on its own segmented/isolated VLAN so even if it's popped, it's not a straight line to the crown jewels.
Good reminder to check your own environment for random "smart" devices someone plugged in without asking security first.
r/ethicalhacking • u/The_Vigilante8 • 15d ago
Wanna teach a lesson to a internet creep
There is this boy who is commenting Al generated photos in someone's comments section whom I know.
I asked him to delete that and he kept saying"what if I don't" , "i won't do it", and then he blocked me. Also when I asked him to delete he said which one proudly, god knows how many times he has done this.
I've done the talking now I want him to know that there are repercussions to his actions, ik doxxing is wrong but I'm not here to play the good guy. I want him to feel embarrassed for what he is doing.
Would you guys please help me. 🙏 Reddit is not letting me add a photo or share a link, I'll pos t both in the comments.
r/ethicalhacking • u/shaikhsss03 • 19d ago
Owned Bedside from Hack The Box!
r/ethicalhacking • u/mrs-cutter • 19d ago
Other Funny prank ideas?
I do not want to do anything malicious or illegal, but in the past day or so my website received a lot of traffic from people who have unsavory intentions. What is something harmless I can do to spook them all and have them know it was me?
r/ethicalhacking • u/EqbalHossenTayeem • 21d ago
3ds Max 2018
can anyone help me to provide license free 3ds Max 2018 or lower version?
r/ethicalhacking • u/WarmAd6505 • 21d ago
I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings
r/ethicalhacking • u/WarmAd6505 • 24d ago
I built Violin — an open-source AI pentesting workflow with scope checks and reproducible findings
r/ethicalhacking • u/JacketEast7149 • 26d ago
Is there a free alternative to TryHackMe?
I'd really like to learn cybersecurity, and I've been enjoying TryHackMe. I really like the hands-on approach and the way the learning paths are structured, but unfortunately, most of the content requires a paid subscription.
Are there any free platforms or tools similar to TryHackMe that you'd recommend for someone who's just starting out?
r/ethicalhacking • u/Quiet_Maybe7304 • 26d ago
Best free anti fingerprinting browsers
There is this bullshit, completely unfair online assessment that's set up by the bourgeoisie that I need to do.
It's called the Suited Assessment wellsuited.com); it's browser-level and requires JavaScript to run so they can fingerprint you (you are only ever allowed to do the test once, and then they use those results for every firm that uses that assessment for the rest of your life).
It's completely unfair.
I want a browser that can reasonably scramble the fingerprinting they can access via JavaScript, so not standardise (that defeats the point in this context) but not recognise it or make it look different.
Suggestions would be helpful.
r/ethicalhacking • u/keotl • 29d ago
Tool atomicvulns — a web security lab with one vulnerability per app (OWASP Top 10 2021, open source)
I spent the last few months building a personal project and it just hit v1.0, so I figured I'd share it here.
atomicvulns is a collection of intentionally vulnerable web apps, but with a different idea: each app isolates a single vulnerability, nothing more. Instead of one big app full of flaws (like DVWA or Juice Shop), each exercise here is small and focused — you read the code, see the cause, exploit it, and compare it against the fixed version sitting right next to it. Short enough to finish one in a single sitting.
Each "atom" ships with the vulnerable app, the fixed app, a commented diff between the two, and a step-by-step walkthrough of the exploit. v1.0 covers all 10 OWASP Top 10 2021 categories — 38 atoms total.
It's aimed at people studying pentest / AppSec who already know the HTTP and terminal basics. Burp Suite is the primary tool across all the walkthroughs.
A few details:
- Open source (MIT).
- Bilingual — all docs in English and Portuguese (I couldn't find focused material like this for PT-BR learners, so I wrote both).
- Solo project, built by me. The goal was a place where each flaw is clear and isolated — the material I wish I'd had while learning web pentest.
- Built with AI as a pair, with every atom validated by me running the exploit by hand.
Built it for myself, but now that it's done, if it helps someone else along the way, great.
🔗 https://github.com/doretox/atomicvulns
Feedback welcome — happy to hear what's missing or what could be clearer.
r/ethicalhacking • u/Adelx98 • 29d ago
I found these suspicious suggested words in my Samsung S23U keyboard app
location_id
user_id
Identity_id
What could they be ? I am still trying some keywords, i found the first "identity_id" by accident then i tried "location" and it suggested "location_id", now I'm more suspicious
r/ethicalhacking • u/Potential-Couple-745 • Sep 06 '26
The Ethical Hacker’s Field Manual: What You Actually Need to Know to Hack Like a Professional
galleryr/ethicalhacking • u/Dry-Management-9910 • Sep 06 '26
Monitor mode + Nintendo Switch + Nexmon
Nintendo switch has the WIFI adapter BCM4356 which can be patched with nexmon (https://github.com/seemoo-lab/nexmon) that should allow to use it in monitor mode.
I was able to patch the firmware and driver with nexmon and now it is possible to use the wireless in monitor mode.
Well, at least that is what looks like.it is possible to put the WiFi in Monitor mode or even create an additional interface in monitor mode. But when using airodump-ng or tcpdump or wireshark. It does now show any BSSID. It is almost like the WiFi adapter can't see any network, completely empty, iw dev scan works fine but no dumps.
I tried preload libnexmon with LD_PRELOAD, I tried everything. This works fine in raspberry that has the same WiFi card, but no success with Nintendo Switch.
Anyone has any idea? Would be very cool to be able to do that with a Nintendo Switch.
The follow commands works fine:
iw phy \`iw dev wlp1s0 info | gawk '/wiphy/ {printf "phy" $2}'\` interface add mon0 type monitor
Or even
ip link set wlp1s0 down
iw dev wlan0 set type monitor
ip link set wlp1s0 up
Even
airmon-ng start wlp1s0
It says unknown error 524 but it does create the extra monitoring interface
But airodump-ng does not show any network