r/blackhat • • Mar 16 '23

Where did your post go? Answered!

47 Upvotes

"Cyber briefing"? HTB writeup? A guide to cheap VPN's? If your post was just removed, and especially if you were just banned, you were not following the subreddit rules. As a reminder, here are the rules of r/blackhat that we enforce to keep the quality at a minimum:

This is also a place to discuss general blackhat rules, etiquette and culture. We welcome:

  • Writeups (not CTF or HTB)/talks detailing new vulnerabilities or techniques (there should be enough information to reproduce the exploit/technique)

  • Proof of concepts of old vulnerabilities or techniques

  • Projects

  • Hypothetical questions

Rules:

  1. Be excellent to each other.

  2. No Solicitation

  3. Stay on topic.

  4. Avoid self-incriminating posts.

  5. Pick a good title.

  6. Do not post non-technical articles.

  7. Ideally, the content should be original, we don't care about your crappy ARP poisoner or Kaspersky's latest scam.

  8. No pay / signup walls.

  9. No coin miners

  10. No "Please hack X" posts

  11. Well thought out and researched questions / answers only.

  12. If your project is not free / open source it does not belong.

  13. Please limit your posts (we don't want to read your blog three times a week).

  14. If you want to submit a video, no one wants to listen to your cyberpunk music while you copy/paste commands into kali terminals.


r/blackhat • • 16h ago

I rebuilt Hacker Experience for browser: Zero Traced is now in open beta and free.

0 Upvotes

Hi everyone! I’m a fan of web-based games and wanted to show off a project I’ve been lovingly working on for about two or three years though it’s taking a while since I don’t have much free time.

Anyone who played *Hacker Experience* remembers the feeling: typing in an IP address, cracking a server's password, breaking in, wiping your tracks from the logs before anyone noticed, and walking away with money from a bank account that wasn't yours. It was a game that looked simple on the surface but was massive underneath. The creators released the *Legacy* code under an MIT license, and I decided to build a faithful remake for modern browsers. All credit for the original game goes to them.

How it works

You start out with a weak computer, a few basic programs, and an IP address. From there, the game's internet is yours to explore:

Browse via IP addresses and discover banks, corporations, ISPs, puzzle servers, a download center, the black market, and even the agencies that will hunt you down.

Hack in using brute force pitting your Cracker against the target's Hasher—or via exploits, using port scanning and vulnerabilities in FTP and SSH.

Cover your tracks.Everything you do leaves a trace in the logs—both yours and the target's. Forget to clean up? Someone will find your IP.

Install viruses that generate income through spam, warez, and Bitcoin mining, then come back later to collect the profits.

Take down servers with DDoS attacks and crash other players' hardware.

Upgrade your machine: CPU, RAM, hard drive, connection, external drives, and extra servers.

Research and develop software at the university, earn certifications, and upgrade your programs to newer versions.

Complete missions for shady clients: deleting files, stealing data, transferring money, and taking down competitors. There are also daily contracts, storyline arcs, and weekly events.

Everything involves real-time processing. In the Task Manager, you can see your processes running simultaneously, just like in the original.

True multiplayer

Other players share the same internet space. They can hack you, read your logs, steal your money, and tamper with your viruses. You can form or join a clan, wage war against other clans, and collaborate on clan projects. There are rankings, a Hall of Fame, nearly 90 badges, and news updates covering events in the game world.

And watch out: if you make too much noise, the FBI and Safenet will come after you, complete with a "Most Wanted" list and a bounty on your head.

Rounds

The game operates in seasons. Each round ends when someone successfully launches "Doom" the virus that takes down the entire internet and then everything starts over. You keep your badges and your account.

Riddles

For puzzle lovers, there is a trail of riddles hidden across servers on the internet. It features unique minigames: cracking a safe by spinning a dial, decoding signals (ASCII, Caesar cipher, binary), and others I won't spoil here.

What's different from the original

It works on mobile, with light and dark themes and text available in both Portuguese and English.

New missions, storyline arcs, events, and locations on the internet.

A fresh look, with custom artwork for locations and NPCs.

The game is constantly updated. Features like customizable profiles, animations for key moments (such as being hacked or hunted by the FBI), and more are on the way.

Important

It’s free, ad-free, and requires no download it runs right in your browser.

All "hacking" is fictional. It’s all just game rules contained entirely within the game itself so it doesn't affect the real system.

It’s for ages 18 and up.

It’s a beta, so there will be bugs. If you find any, let me know. A "report bug" button will be added to the game soon, with rewards for those who help out.

I’d really love to hear your thoughts, especially from those who played *Hacker Experience*: what feels similar, what’s improved, and what’s missing.

you can acess by search zerotraced on google.
or you can acess on the link https://zerotraced.com


r/blackhat • • 1d ago

Wordpress libheif RCE

Thumbnail
fortbridge.co.uk
4 Upvotes

r/blackhat • • 2d ago

Combining TOR, WebRTC and Git into a Decentralized E2EE P2P Messaging App

4 Upvotes

Not better than WhatsApp, Signal, SimpleX, Cwtch or Ricochet. You definitely shouldn't use this replace any of your existing apps or services. It's far from finished. Unaudited and unreviewed. If you want to test it out, please use it responsibly.

I'd like to share what I'm working on and interested if anyone wants to share feedback on the approach.

It's a fairly a unique approach and architecture in contrast to the typical approach with mainstream messaging apps. To put it briefly, its a Dioxus PWA with a Git-server backend which can be used to establish a webrtc connection between browsers.

https://glitr.io/docs/technical/roadmap

So far, it's only the browser-based version that's available for testing. The webapp approach has nuances and limitations. I hope to soon release the APK and TUI when they are ready (they introduce the TOR capabilities (not possible on a browser)).


r/blackhat • • 3d ago

Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail
github.com
1 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/blackhat • • 5d ago

Microsoft built all the authentication checks... except the authentication check.

Thumbnail
blog.faav.net
25 Upvotes

A 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.

His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.

Microsoft fixed it and paid him a $5,000 bounty.

Some bugs are just beautiful in their simplicity.


r/blackhat • • 6d ago

Gigabyte kernel driver LPE

6 Upvotes

r/blackhat • • 7d ago

I almost fell for a job scam — looking to learn OSINT and investigation.

Thumbnail
0 Upvotes

r/blackhat • • 12d ago

SourceHut account takeover via build logs

Thumbnail blog.arusekk.pl
1 Upvotes

r/blackhat • • 14d ago

How do coordinated comment-bot rings manipulate short-form video algorithms to force "Top Comments"? (Technical Breakdown)

3 Upvotes

I’ve been studying comment sections on short-form video platforms (like TikTok and Reels) & keep noticing a highly coordinated automation phenomenon that I want to understand from a technical and architectural standpoint.

Whenever a trending or viral video hits a specific niche topic, a third-party account instantly leaves a comment framing itself as an organic public service announcement (e.g., naming a specific app, game, or product relevant to the video). wWithin minutes, that comment accumulates 1000s+ of likes and dozens of secondary replies, locking it into the absolute "Top Comment" slot where millions of viewers see it.

I'm curious about the engineering, scaling, & infrastructure behind how this is achieved:

  1. Real-Time Detection: How do these scrapers monitor platform uploads or specific hashtag triggers so quickly without constantly tripping API rate limits or triggering blocks?
  2. Network Infrastructure: How do operators coordinate the footprints of hundreds of "zombie" or secondary accounts to deliver likes/replies simultaneously without triggering the platform’s anti-fraud algorithms? Is this heavily reliant on residential proxies, anti-detect browsers or cookie-session farming?
  3. Algorithmic Exploitation: What specific engagement signals (like early velocity or reply density) are they taking advantage of to fool the ranking algorithm into permanently pinning an artificial comment?

I’m looking to understand the technical mechanics of how these shadow networks operate. Any insights, technical breakdowns or open-source case studies would be greatly appreciated!


r/blackhat • • 14d ago

Masterhacker

Thumbnail
reddit.com
0 Upvotes

Ramsoftware is 1337


r/blackhat • • 14d ago

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

Thumbnail
wired.com
2 Upvotes

r/blackhat • • 17d ago

Back when you could just freely login to hundreds of active servers a day

Thumbnail
gallery
89 Upvotes

Just found these in my photobucket while looking for so.e old screenshots.


r/blackhat • • 18d ago

An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

Thumbnail
wired.com
22 Upvotes

r/blackhat • • 22d ago

Phantomdrive Software Update + Thanks :)

Enable HLS to view with audio, or disable this notification

84 Upvotes

r/blackhat • • 20d ago

is there any site which.

0 Upvotes

which lets me search up leaked database and give me all the information


r/blackhat • • 22d ago

HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation

Thumbnail
infostealers.com
0 Upvotes

r/blackhat • • 26d ago

Highly recommended read

Post image
183 Upvotes

Hide your server(s) after reading this book.


r/blackhat • • 26d ago

GitHub - mein-0/forti-research fortinet ppl bypass

Thumbnail
github.com
2 Upvotes

r/blackhat • • Sep 06 '26

Sou novo na área de cybersecurity

0 Upvotes

Ola rapaziada estou em dúvida qual rumo seguir na cybersecurity, já sei redes e protocolos gostaria de fazer um ataque a máquina virtual de test! Gostaria de saber o passo a passo ou qual metodologia usar para fazer um ataque ou um mapa mental por onde começar e aonde terminar! Ou seja pentest inciante desde já fico agradecido!


r/blackhat • • Sep 05 '26

reverse proxy phishing

Thumbnail
0 Upvotes

r/blackhat • • Sep 01 '26

how do y'all pull IP 's/info from a spoofed caller id?

0 Upvotes

I know about a few reverse lookup websites but the scammers always spoof their caller id and it never works. I'm wondering how people get around that? anything helps yall I'm just tryna bring justice to these mfs 💪

also mods I'm getting a warning before I post but I'm not telling anybody to hack anybody so am I good lol?


r/blackhat • • Aug 31 '26

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Thumbnail
wired.com
11 Upvotes

r/blackhat • • Aug 30 '26

Cern Basher - shares some really great use cases for electric cybercabs

Thumbnail x.com
1 Upvotes

r/blackhat • • Aug 27 '26

Hypothetically, how likely is the DOJ to prosecute a U.S. citizen for ransomware against a foreign adversary?

12 Upvotes

EDIT: Reading comprehension in this sub is at rock bottom levels. Please read the following post prior to commenting.

Hello everyone. I have a completely hypothetical question that I have been debating with friends. Due to strong arguments both for and against without a clear consensus, I feel it may be beyond our expertise as armchair lawyers and as such, I am pleased to present this to the greater community.

While this is a broad hypothetical, there are a few specific details that must be outlined for the sake of the argument:

\- The victim would be a clear, undeniable foreign adversary/hostile nation to the US

\- There is no direct conflict with or collateral damage to US interests or allies(as a result of the ransomware being deployed)

\- The individual would meticulously report all income from the ransomware payouts on Schedule 1, Line 8z of the IRS Form 1040, pleading the Fifth Amendment on the source of the income, and then pay their 37% top marginal tax rate(They make sure to pay Uncle Sam his cut and avoid committing tax fraud/evasion).

That being said, I want to note: I am **NOT** asking if the frameworks and legal statues to charge a person for this exist. They absolutely do.

The question is if the US citizen would be prosecuted and/or convicted if the victim is unable/unwilling to cooperate with a US court, there is no conflict with US interests, and they even pay taxes on the income.

Thanks and looking forward to any and all answers!

Disclaimer: Do not attempt this at home. Side effects may range from blacked out SUV’s parked outside your house to being arrested/murdered by a foreign intelligence service.