Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
CPENT from EC Council
https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/

<!-- SC_OFF -->I have just finished CEH and don’t feel that I have a lot pratical knowledge about cybersecurity.
Can someone that finished CPEN provide some feedback, how was it and is it worth or not. <!-- SC_ON --> submitted by /u/Just_Knee_4463 (https://www.reddit.com/user/Just_Knee_4463)
[link] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uvoxjp/cpent_from_ec_council/)
D-Link DIR-825 H/W Version J3 Any 3rd party firmware
https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/

<!-- SC_OFF -->Hey sup guys, i just recently bought a router of D-Link DIR-825 J3 H/W Version, any 3rd party firmware to flash and use it for wifi pentesting. <!-- SC_ON --> submitted by /u/V01DL0RD_1 (https://www.reddit.com/user/V01DL0RD_1)
[link] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uw2cq0/dlink_dir825_hw_version_j3_any_3rd_party_firmware/)
CRTP exam
https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/

<!-- SC_OFF -->I'm about to finish CRTP course from altered security I want to be overprepared for the exam therefore currently i'm playing rooms on hack the box I'm asking about the exam structure, all i know is i have 24 hours to compromise the forest or domain and 48 hours to write report and i know i should get 70 points of 100 How many machine are there? How many domain? Is it a simulation to the labs in the course or harder? Do i need to study something extra or course content attacks is enough I don't know a lot of things honestly i need help <!-- SC_ON --> submitted by /u/Left-Efficiency6514 (https://www.reddit.com/user/Left-Efficiency6514)
[link] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uweaah/crtp_exam/)
Где найти первый опыт?
https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/

<!-- SC_OFF -->Всем привет!
я горю мыслью работать в безопасности и чуток проанализировав рынок, выяснил , что в основном все начинают с soc аналитика
где нынче найти норм стажировки или вакансии на это место?
я готов хоть бесплатно, дайте только опыт <!-- SC_ON --> submitted by /u/Radiant-Strength-448 (https://www.reddit.com/user/Radiant-Strength-448)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwg136/%D0%B3%D0%B4%D0%B5_%D0%BD%D0%B0%D0%B9%D1%82%D0%B8_%D0%BF%D0%B5%D1%80%D0%B2%D1%8B%D0%B9_%D0%BE%D0%BF%D1%8B%D1%82/)
LF Red Team Testers
https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/

<!-- SC_OFF -->Looking for tester for my Red Teaming tool that can run tests against - LLMs, Agents, Chatbots and MCP Servers. RedPlayer1.ai (http://redplayer1.ai/) Need some feedback and beta testers. Break it or let me know what could be better. <!-- SC_ON --> submitted by /u/DWDURB (https://www.reddit.com/user/DWDURB)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwpyrd/lf_red_team_testers/)
Roadmap for penetration
https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/

<!-- SC_OFF -->Guys I want to learn penetration (hacking) I've learned network+ and Linux essential already what should I do next? Use tryhackme? Or ceh? Kali Linux? Actuve directory? Security+?bash scripting? Wireshark? What? Please give me a roadmap guys <!-- SC_ON --> submitted by /u/Full_Unit9235 (https://www.reddit.com/user/Full_Unit9235)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxsxv/roadmap_for_penetration/)
Analysis of Spreadtrum Longcheer chipsets
https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/

<!-- SC_OFF -->This report details a systemic security failure affecting millions of budget Android devices deployed across Latin America. The vulnerability is not a single software bug but a deliberate supply chain deception orchestrated by ODM Longcheer and SoC vendor Unisoc, facilitated by OEM Motorola. The core issue involves a hardcoded fscrypt provisioning bypass triggered by LCD ID lcd_td4168 and key 56ef134d... that allows the distribution of fraudulent security updates. These updates spoof the security patch level claiming "April 2026" while running vulnerable binaries from "March 2026", masking critical flaws like CVE-2021-39658 ismsEx, CVE-2022-38694 BootROM, and exported backdoors in com.spreadtrum.sgps. This architecture creates a permanent attack surface that facilitates active financial fraud PIX hijacking, surveillance, and enterprise network compromise in the Latin American region, where these devices dominate the market. The Attack Chain: "Silent Rescue" The risk is compounded by a chain of vulnerabilities that work in concert: Hardware Root Unpatchable: CVE-2022-38694 in the Unisoc BootROM allows permanent bypass of Secure Boot via physical USB access. Public tools spd_dump exist. Remote Entry Network: CVE-2025-31718 Modem RCE allows remote code execution via rogue cell towers IMSI catchers, common in urban LATAM centers. Privilege Escalation Zero-Permission: CVE-2021-39658 ismsEx service allows any app to send SMS or modify system properties without permissions, bypassing Android 2FA. System Backdoors Exported Components: com.spreadtrum.sgps exposes location tracking and system controls via dialer codes _#_#2266#_#_. Payload Delivery Silent Installers: Pre-installed system apps com.dti.amx Digital Turbine and com.inmobi.installer hold INSTALL_PACKAGES, allowing silent installation of banking trojans e.g., PixRevolution without user consent. The Cover-Up FOTA Spoofing: The fscrypt bypass injects a fake ro.build.version.security_patch string, tricking users, banks, and MDM systems into believing the device is secure. Critical Risk to Latin America LATAM The impact on Latin America is disproportionate and severe due to market dynamics and reliance on mobile finance. A. Market Dominance of Vulnerable Devices Ubiquity: Unisoc T606/T616 chipsets power the best-selling budget devices in the region Motorola Moto G04s, G24, Infinix, Tecno. Search results confirm Unisoc's aggressive expansion in LATAM, with over 100 5G devices deployed in the region by 2025. Demographic Impact: These devices are the primary computing tool for unbanked and underbanked populations who rely exclusively on smartphones for government aid, commerce, and banking. B. Direct Threat to Financial Infrastructure PIX & Billetera Móvil Active Exploitation: The PixRevolution trojan identified March 2026 actively hijacks PIX instant payments in Brazil by overlaying fake screens and diverting funds in real-time. The Enabler: The vulnerabilities in this report ismsEx SMS bypass, INSTALL_PACKAGES silent installer, exported SGPS location tracking provide the perfect infrastructure for such malware to operate undetected. 2FA Bypass: CVE-2021-39658 allows malware to read or intercept SMS verification codes without permission, rendering traditional 2FA useless for banking apps. C. Enterprise & Supply Chain Risk MDM Evasion: Corporate Mobile Device Management MDM systems rely on the security_patch string to enforce compliance. The FOTA spoofing mechanism ensures that compromised devices report "Compliant" status while running vulnerable firmware, allowing them to bypass corporate security gates. Data Exfiltration: The com.motorola.bach.modemstats service with READ_LOGS and MANAGE_NETWORK_POLICY can be weaponized to exfiltrate corporate data over hidden backchannels that ignore data usage limits. D. The "Fake Patch"
Deception False Security: Users receive notifications stating "Security Update Installed," but the underlying binaries dated March 18, 2026 remain vulnerable. This erodes trust in the Android ecosystem and leaves users exposed to known exploits. Regulatory Violation: This practice likely violates consumer protection laws in Mexico, Brazil, and the EU, as it constitutes a material misrepresentation of product security. <!-- SC_ON --> submitted by /u/Acceptable-County443 (https://www.reddit.com/user/Acceptable-County443)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/)
What should every beginner include in a penetration testing report?
https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/

<!-- SC_OFF -->A penetration test is not complete when the vulnerability is found. The real value comes from explaining the risk clearly enough for the client to fix it. A beginner report should include: Scope and methodology Affected asset Clear vulnerability description Evidence and reproduction steps Risk severity Business impact Remediation guidance Retest status Which section do beginners usually underestimate the most: evidence, impact, or remediation? <!-- SC_ON --> submitted by /u/redfoxsecurity (https://www.reddit.com/user/redfoxsecurity)
[link] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/)
When -1 Becomes a Heap Write: A libtiff TIFFReadAndRealloc() Vulnerability

How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruptionContinue reading on Medium »
Read more...
One postMessage Was Enough to Break a Trust Boundary (CSRF)

Most bug bounty discoveries don’t begin with an advanced exploit. No SQL Injection. No authentication bypass. No complex exploit chain…Continue reading on Medium »
Read more...
When Your Own Automated Scanners Start Lying to You

In cybersecurity, we are taught to trust our tools. We unleash powerful crawlers like Katana or automated scanners inside Burp Suite, grab…Continue reading on Medium »
Read more...
Agentic AI CyberSecurity Arsenal | 33 FREE Local AI Tools for Cyber Defense

Exploring CyberSentinel AI: A Fully Local AI Security Platform for Modern Security TeamsContinue reading on Medium »
Read more...
Smali By bithowl: Chapter 2 Why Every Android Hacker Needs Smali

(“The Code You See Isn’t Always the Code That Runs”)Continue reading on Medium »
Read more...
How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruptionContinue reading on Medium » (https://medium.com/@aleens09/when-1-becomes-a-heap-write-a-libtiff-tiffreadandrealloc-vulnerability-b7e241e7731e?source=rss------bug_bounty-5)
Most bug bounty discoveries don’t begin with an advanced exploit.
No SQL Injection.
No authentication bypass.
No complex exploit chain…Continue reading on Medium » (https://medium.com/@RootXSec/one-postmessage-was-enough-to-break-a-trust-boundary-csrf-8adeb40315ac?source=rss------bug_bounty-5)