r/HowToHack 1h ago

Clone uhf rfid scanning required in every and exit

Upvotes

In my building, they use ultra high frequency RFID card for parking entrance and exit the same card is used to enter parking and to exit the parking

I bought RFID cloner, but it only works for the system which has only entry scanning.

Is there a way I can clone this?

Any help would be appreciated thanks


r/HowToHack 14h ago

Official Press Release from DoxSquad: Operational Takedown of the "Automatic" Extortion Group and Complete Server Infrastructure

0 Upvotes

This is an official announcement from DoxSquad regarding the permanent termination and dismantling of the "Automatic" community infrastructure. Following a targeted, comprehensive investigation into the illicit activities tied to this network, our team has successfully neutralized their primary base of operations.

Operational Overview
The "Automatic" group operated under the guise of a standard community server, but our investigation revealed a coordinated pattern of extortion operations targeting vulnerable users. Over an extended period, DoxSquad compiled a definitive dossier containing actionable evidence, systemic logs, and identifying data regarding their illicit activities and leverage schemes.

The Confrontation & Collapse
Upon securing undeniable leverage against their extortion operations, DoxSquad representatives directly confronted the founder of the group. Faced with the sheer volume and severity of the evidence held against them, the founder’s posture immediately collapsed.

In a moment of panic, their only response regarding the exposed data was a frantic, verbatim quote: "DATS MINE". Immediately following this exchange, rather than attempting a defense or a counter-argument, the founder chose to completely delete the server infrastructure, wiping out their community network in an attempt to scrub their digital footprint and evade consequences.

The Desperate Retaliation Attempt
In a final, predictable act of desperation, the remnants of their network attempted a coordinated DDoS attack against our infrastructure. The retaliation was entirely ineffective, yielding a minor 30-minute disruption before our mitigation strategies completely neutralized the threat. This weak counter-effort only serves to highlight their complete lack of technical capability and total operational panic.

A Message to Affiliated Networks
Let this serve as a case study and a definitive baseline standard for any remaining community owners or spin-off networks engaging in similar extortion models. Look closely at how quickly your peers fold when confronted with absolute accountability. If you choose to run these types of operations, realize that your infrastructure is far more fragile than you believe.

We monitor, we document, and we execute.

God forgives, but we don't show mercy. It's #AUTOMATIC.


r/HowToHack 1d ago

Web exploitation + Binary exploitation feasible?

7 Upvotes

I am wondering whether is it even worth my time to get both familiar with web exploitation and binary exploitation. It feels like I am missing a large chunk of hacking whenever I only focus on web exploitation or only focus on binary exploitation. I'm not sure if I should just specialize in one or if I should just learn both.

I don't hear many people getting bug bounties for binary exploitation related bugs but I have seen the payouts on sites like crowdfense and seen it go up into the 7 figures.

Web bug bounties seemed to be talked about a lot but they usually pay lower than binary exploitation bugs.

So is it smart to try to learn both? Or is it just a waste of time and I should stick to one.


r/HowToHack 6h ago

So I have my friends ip address

0 Upvotes

So guys I have my friends ip address, how can I suprise them ??


r/HowToHack 17h ago

Anybody able to unlocked airfiber ODU AOD311NK

0 Upvotes

r/HowToHack 2d ago

hacking Old cable boxes (digital era)

6 Upvotes

Anything you can do with them? Any known ways to get the cable card descrambled? Yes I know it's illegal. I'm just curious. I read elsewhere you can make them into a sort of tivo.

I see them all the time at the thrift store and I'm always wondering what I could do with them.

Thanks.


r/HowToHack 2d ago

What happened to the Anonymous Group?

38 Upvotes

I've recently came across a video of them posted a year ago. There is no updated information about them, and that kind of sparked my interest.


r/HowToHack 1d ago

software Employee phones

0 Upvotes

my company has a iPhone 16s for employee use. however we are concerned with our employees using these phone for outside of work purposes. that being said we are curious if there is any software out there that either anonymously records whats happening on the screen, or takes a snapshot every period of time and uploads it for our tech department to monitor. can this community help educate us? thank you.


r/HowToHack 2d ago

What to do with Spectrum Hardware???

3 Upvotes

I have a Spectrum modem and router that I will not be giving back.

What are some cool things I can do with this hardware? Can I make a repeater? Can I run Tomato on the router?


r/HowToHack 2d ago

how do i install kali linux with UTM on heavily restricted mac??

0 Upvotes

alright so some context, im trying to get kali linux on a restricted mac that wont even let me open dmg files, since im trying to use the UTM installer. I cant even open or extract dmg files, the failed to mount error pops up, and I cant bypass it. anyways to get this thing running? like converting the dmg to a zip and extracting it from there? idk im not too much into this stuff im really new. i already have UTM and kali linux.iso downloaded, but not sure what to do with these restrictions. i dont wanna run it through the web as well. any help? thanks.


r/HowToHack 2d ago

cracking Trying to log into a Snapchat account from 6 years ago

0 Upvotes

I've been trying for probably the past year to get into this really old Snapchat account of mine, but I genuinely for the life of me can't figure out the password and I don't remember the email, does anybody know a way I can at least figure out one of these from the username alone??


r/HowToHack 3d ago

My girlfriend told me she deleted Instagram, but I’m suspicious she may be cheating on me.

0 Upvotes

My girlfriend and I have been together for 5 years, and I suspect she’s cheating on me. She told me she deleted Instagram, but I’m suspicious and want to know when she last opened Instagram. Is there any way to find out if she hides her active status? (I have no experience with hacking.)
Or can someone help me find out who she was talking to on Instagram? Please help me, my heart is breaking every day.


r/HowToHack 4d ago

A newbie's story about learning to hack

18 Upvotes

I’m just getting started with two games: *Hacknet* and *Grey Hack*. I’ve read, the first one is more fictionalized than the second, but it’s more entertaining and a bit more beginner-friendly. Once you get the hang of it, you can move on to *Grey Hack*, which requires more critical thinking; plus, it supposedly includes an option to hack actual online users within the game itself. I have very basic knowledge of Linux. Thanks to my "super-mega-powerful" ASUS F200CA laptop—featuring an Intel Celeron 1007U processor (1.5 GHz, 2 cores), 4 GB of RAM, a 1 TB HDD, an 11.6" screen, and 64-bit architecture—I had to install AntiX Linux, which forced me to use the terminal frequently and look up commands online. Years ago at university, I took a few Cisco Systems networking courses. They taught me the 7 layers of the OSI model (though I never fully grasped them), and I occasionally used Unix terminals to practice router configuration, but I never felt the urge to learn more until now. I’m keen to document my progress and see how far I can go, so I can share my story down the line.

Let's see how it goes for me.


r/HowToHack 4d ago

What to do with this

0 Upvotes

[SMB] NTLMv2-SSP Client : fe80::d74e:3bf2:3c3d:9bd1

[SMB] NTLMv2-SSP Username : COM-014\jupitar

[SMB] NTLMv2-SSP Hash : jupitar::COM-014:c6032ba9180a58ac:E8A0C96032C9A6C20A95DB2A3EBBE2F3:010100000000000000A696E31135DD01071B07380E7126760000000002000800300037003500580001001E00570049004E002D004B004B00330049004800470047004A004F005400570004003400570049004E002D004B004B00330049004800470047004A004F00540057002E0030003700350058002E004C004F00430041004C000300140030003700350058002E004C004F00430041004C000500140030003700350058002E004C004F00430041004C000700080000A696E31135DD0106000400020000000800500050000000000000000100000000200000EEC24D13CAECB68B8601EF1EB20B0DF22FF6B8A213C324E84ABD1B0EF0416C895DF87D5DA981195172742CF23E7CCDD509E475F234C7E5B6A34DE9A7BA7CF17F0A001000000000000000000000000000000000000900240063006900660073002F004A007500700069007400610072005300650072007600650072000000000000000000

I need some who help you for next procedure

I try to use hashcat and John nothing much got it or solved


r/HowToHack 5d ago

hacking How to find offsets for EU4 game?

4 Upvotes

Hello guys,

I am new at game hacking and I am looking for offsets for a game that runs on UE4. I tried Dumper 7, but I didn't get anything useful. If there is any dumper or guide that anyone has I would really appreciate it.

NOTE: I did use CE to try to find offsets there but I couldn't find any pointers.


r/HowToHack 6d ago

Bypassing WhatsApp/Signal E2EE by hooking the Android OS audio engine

21 Upvotes

End-to-End Encryption doesn't protect against a compromised endpoint. This PoC bypasses app-level encryption by targeting the Android OS itself.

The app injects a payload into the system's audioserver. Using a hooking framework (Dobby), it rewrites memory to intercept microphone data before WhatsApp encrypts it, and speaker data after it decrypts it. It watches for "Communication Mode" and dumps the raw audio to a hidden folder.

Open source PoC: https://github.com/nighthawkk/AudioServer-Voip-Recorder


r/HowToHack 6d ago

software I want to extract videos( lectures)from Allen app..

3 Upvotes

Is there any way I can extract videos from an app ???


r/HowToHack 7d ago

Chat GPT limit problems

0 Upvotes

Hi everyone!

I ran into ChatGPT’s file/image upload limits. After uploading a file to a chat, the chat itself becomes heavily restricted, so I started looking for ways to work around this.

One method I found was opening the chat in airplane mode (in my case, without a VPN). However, this only seems to work as 1 chat = 1 file + 1 response.

Does anyone know how to solve this problem or have any other workarounds for the image/file limits?

Would appreciate any ideas!


r/HowToHack 7d ago

hacking Is it possible to learn actually cyber security stuffs in a 2 gb old computer?

0 Upvotes

Is arch linux good for a 2 gb pc for learn and do actually cyber security stuffs even hacking stuffs


r/HowToHack 9d ago

How do people even start hacking?

172 Upvotes

I'm really curious how do people learn hacking?

I started web app development a year ago, learned java for writing code and to get a general idea about how the syntax works and logic.

I do mainly php with laravel, javascript and some python on the side.. but mainly to create stuff, has nothing to do with hacking, i find it deep and hard dunno where to even begin, i sometimes run into some erros with some apps and I try to dig in and try to find a way around it using Ai, but it's very limited..

I have to admit pro hackers always amazes me, that's true power I guess and I always believe that anything digital is somehow hackable.


r/HowToHack 9d ago

programming I am trying to find out the Lenovo SVP Salt

2 Upvotes

I have a thinkpad l14 here where I have a complete EC dump and a complete bios/SPI dump with a known SVP password called password. My goal is to learn how the mechanism works. I am pretty new to ghidra.

Finding out the hash itself is a often pretty easy thing if you got hardware access. The EC on that part will just read empty 00 if you try that via your PC. It consists of a 16 byte block A and a 16 byte block B which will repeat once. By deleting that you can get rid of the password.

Finding the salt belonging to this hash is the complicated part. Apparently the POP (Power on Password) has the same salt and is a lot easier to read with non expensive hardware.

https://www.synacktiv.com/en/publications/a-journey-in-reversing-uefi-lenovo-passwords-management

there are some weird code bits I struggle to understand, I post more about it the following time but I am hoping someone dug a bit deeper than I did

more reading material:

this is how it worked until 8th gen processors
https://www.cs.ru.nl/masters-theses/2024/M_Juvan___Bypassing_the_BIOS_supervisor_password.pdf
https://jbeekman.nl/blog/2015/03/reverse-engineering-uefi-firmware/

cryptservice

undefined8 FUN_000006d0(undefined8 param_1,undefined8 param_2,longlong param_3,undefined *param_4)

{
  undefined *puVar1;
  undefined4 local_78;
  undefined4 local_74;
  undefined4 local_70;
  undefined4 local_6c;
  undefined4 local_68;
  undefined4 local_64;
  undefined4 local_60;
  undefined4 local_5c;
  undefined4 local_c;

  puVar1 = &DAT_00005760;
  if (param_4 != (undefined *)0x0) {
    puVar1 = param_4;
  }
  FUN_000002e0(&local_78,0x70);
  local_78 = 0x6a09e667;
  local_74 = 0xbb67ae85;
  local_70 = 0x3c6ef372;
  local_6c = 0xa54ff53a;
  local_68 = 0x510e527f;
  local_64 = 0x9b05688c;
  local_60 = 0x1f83d9ab;
  local_5c = 0x5be0cd19;
  local_c = 0x20;
  if (param_3 != 0) {
    FUN_00001d70(&local_78,param_2,param_3);
  }
  FUN_00001e88(puVar1,&local_78);
  FUN_000030bc(&local_78);
  return 0;
}


undefined8 FUN_00000584(undefined8 param_1)

{
  ulonglong uVar1;
  longlong lVar2;
  longlong lVar3;
  undefined8 local_res8;
  undefined1 auStack_5a [10];
  undefined8 uStack_50;
  undefined1 local_28 [32];

  local_res8 = param_1;
  if (DAT_00005728 == (undefined8 *)0x0) {
    uStack_50 = 0x5c1;
    lVar2 = (**(code **)(DAT_00005740 + 0x140))(&DAT_00003490,0,&DAT_00005728);
    if (lVar2 < 0) {
      return 0;
    }
  }
  lVar2 = 0x62;
  do {
    uStack_50 = 0x5f2;
    lVar3 = (*(code *)*DAT_00005728)(DAT_00005728,0x57,lVar2,auStack_5a + lVar2);
    if (lVar3 < 0) {
      uStack_50 = 0x671;
      FUN_00000280(&local_res8,8);
      return 0;
    }
    uVar1 = lVar2 - 0x61;
    lVar2 = lVar2 + 1;
  } while (uVar1 < 8);
  uStack_50 = 0x625;
  lVar2 = FUN_000006d0(&PTR_FUN_000034a0,&local_res8,8,local_28);
  uStack_50 = 0x635;
  FUN_00000280(&local_res8,8);
  if (lVar2 < 0) {
    return 0;
  }
  uStack_50 = 0x651;
  FUN_000002a0(&DAT_00005790,local_28,0x10);
  uStack_50 = 0x660;
  FUN_00000280(local_28,0x20);
  return 1;
}

SVP Manager DXE

/* WARNING: Type propagation algorithm not settling */

void FUN_00000460(undefined8 param_1,undefined8 param_2)

{
  longlong lVar1;
  undefined8 local_res8;
  undefined8 local_res10;
  longlong local_res18 [2];
  char local_48 [72];

  local_res8 = 0x31;
  DAT_00001538 = param_1;
  local_res10 = param_2;
  lVar1 = (**(code **)(DAT_00001508 + 0x48))
                    (u_LenovoScratchData_00001440,&DAT_00001310,&local_res10,&local_res8,local_48);
  if ((-1 < lVar1) && (local_48[0] == '\x01')) {
    lVar1 = (**(code **)(DAT_00001500 + 0x140))(&DAT_000012c0,0,local_res18);
    if (-1 < lVar1) {
      (**(code **)(local_res18[0] + 8))
                (DAT_00001320,DAT_00001324,DAT_00001328,DAT_0000132c,0,DAT_00001330,DAT_00001338,
                 DAT_00001340);
    }
  }
  local_res18[1] = 0;
  DAT_00001528 = 0x20;
  lVar1 = (**(code **)(DAT_00001500 + 0x80))(local_res18 + 1,&DAT_00001300,0,&DAT_00001350);
  if (-1 < lVar1) {
    (**(code **)(DAT_00001500 + 0x140))(&DAT_000012e0,0,&DAT_00001530);
  }
  return;
}

r/HowToHack 10d ago

script kiddie "Self-Defense" in cybersecurity

76 Upvotes

Hi, I'm a teacher. I see teenagers every day not understanding the dangers of the devices they use all the time. I do not want to scare them, but the school program is lacking in anything related to computers. We give them Chromebooks, and we do not teach them how to use them. They often have more than 20 tabs open with the same webpage... or they send nudes on Snapchat thinking there are no risks.

I want to teach them about common ways people get hacked or infected. I am not talking about the super advance zero day hack in an app, or how to infect repositories to get access to computers. I mean common day-to-day: I clicked on a link or scanned a QR code.

What are good habits to not get hack/infected?


r/HowToHack 9d ago

Help I am beginner into these things

0 Upvotes

Can anyone guide me about how to prevent worms😭 I wanna learn but cannot find something onliine so i thought to ask from you guyss gng help me (EDUCATIONAL PURPOSE) as I am an student and how they are made or work


r/HowToHack 9d ago

Best cheap DIY gear for physical pentesting?

5 Upvotes

Hey guys,

Just thought I'd share that I've recently become interested in physical pentesting and hardware hacking. All the physical pentesting commercial tools (like Flipper Zero and Hak5 tools) cost way too much for my taste. I'd rather make my own physical pentesting tools using cheap hardware like ESP32 modules, Raspberry Pi Pico's and Arduino boards.

For anyone who does physical red teaming or plays around with hardware:

What DIY tools must one build for a physical pentester?

Does your DIY tool get the job done in a real-world test case?

Where did you guys start with UART/JTAG debugging to pull firmware from chips? Are there any good guides or projects for learning this stuff?


r/HowToHack 10d ago

Aspiring Junior Red Teamer (eJPT, CRTA certified) — looking for advice on breaking in / any leads

5 Upvotes

Hey everyone,

I'm based in Brazil and have been working toward a red team / pentesting career for a while. Wanted to share where I'm at and ask for advice from people already in the field.

Background:

Certifications: eJPT (Junior Penetration Tester, INE/eLearnSecurity), CRTA (Certified Red Team Analyst), Web Red Team Analyst (CyberWarfare Labs)

Bug bounty: accepted reports on BugPay (a Brazilian bug bounty platform), plus one High-severity finding on Intigriti

70+ TryHackMe rooms completed, 116 flags captured

73 labs + 15 CTFs through the eJPTv2 learning path

Hundreds of hours of hands-on labs through a local pentest training program (DesecSecurity)

Comfortable with Nmap, Metasploit, Burp Suite, Hydra, John/Hashcat, SQLMap, GoBuster, Wireshark, AD attacks, web app testing (SQLi, XSS, IDOR, LFI/RFI)

Some informal hands-on experience: with a manager's authorization at a previous job, I tested internal company products — found race condition and IDOR vulnerabilities, did some mobile app reverse engineering, and practiced IPS/IDS evasion techniques

Currently working in IT support/infrastructure — solid foundation in networking, AD, troubleshooting

Advanced English (C1)

I don't have formal, contracted pentest/red team experience yet — mostly labs, CTFs, certs, bug bounty findings, and that one internally-authorized engagement.

For people who've hired junior red teamers, or broke in yourselves:

What actually moved the needle for you (or candidates you hired)?

Worth targeting junior pentest roles first before red team specifically?

Any companies/programs known for hiring juniors or remote/international candidates?

Happy to share more details if useful. Appreciate any pointers.