r/Hacking_Tutorials

Released v1.6.0 of my ESP32 Wi-Fi pentest tool — now with RTL8188EU USB adapter support + BLE toolkit + Network Analysis

Hey everyone, just shipped v1.6.0 of WifiPhisher for ESP32, my open-source Wi-Fi security testing firmware for ESP32-family boards (Evil Twin, Karma, deauther, on-device handshake/PMKID cracking, all from a web UI hosted on the device itself).

This release is one of the bigger ones so far:

  • USB Wi-Fi adapter support (new) — added a from-scratch driver for the RTL8188EU USB dongle, so on S2/S3/C5/C6/Cardputer boards with USB-OTG you can now sniff and inject from an external adapter, not just the onboard radio.
  • BLE toolkit (new) — BLE device identification, a BLE sniffer, and BLE spam attacks.
  • Network discovery & port scanner (new) — subnet host discovery, mDNS/Bonjour and SSDP/UPnP discovery, plus a TCP Connect/SYN port scanner, all built in.
  • Aircrack is a lot faster — swapped the generic mbedTLS crypto path for the native primitives already compiled into the Wi-Fi stack, which cut RAM usage and pushed handshake/PMKID verification to ~3 keys/sec on-device.
  • Smarter deauther — it now tracks per-client ACKs to stop wasting airtime on clients that already dropped off, filters targets by RSSI, and auto-aligns the SoftAP channel to a single selected target.
  • Evil Twin reliability fixes — clean task shutdown (no more hangs) and fixed 5GHz target detection.
  • UI polish — WPS column in the scanner, and a reworked admin dashboard (screenshot below).

Flash it straight from the browser here, no toolchain needed: https://espwifiphisher.alexxdal.com/

Source, full changelog and build instructions: https://github.com/Alexxdal/WifiPhisher

▲ 7 r/Hacking_Tutorials+2 crossposts

Cybersecurity roadmap for beginners

If I had to start cybersecurity again, I wouldn't jump straight into pentesting or collect a bunch of certs.

I'd go:

Networking → Linux → Windows → Python → Security basics → Labs → Specialize

Learn networking properly first. Understand what actually happens when you open a website, how DNS works, what TCP does, how ports and services work.

Then get comfortable with Linux and Windows. Use the terminal. Break things. Read logs. Set up VMs.

After that, start doing actual security work: Nmap, Wireshark, Burp, SIEMs, basic vulnerability analysis, CTFs, home labs.

Then pick a path:

  • SOC / Blue Team
  • Pentesting
  • DFIR
  • Malware Analysis
  • Cloud Security
  • AppSec

The mistake I see most often is trying to learn all of cybersecurity at once.

Pick one direction and go deep.

What would you change in this roadmap?

reddit.com
▲ 14 r/Hacking_Tutorials+2 crossposts

I made a free step-by-step guide for building a SOC home lab (Windows + Linux + Sysmon + Wazuh + attack simulations)

Put together a hands-on PDF for anyone trying to break into SOC/blue team work but stuck on theory with no practical lab experience.

Covers the whole build: isolated VM network, Windows and Linux endpoints, Sysmon telemetry, PowerShell logging, deploying Wazuh as the SIEM, connecting agents, and five safe attack simulation exercises (failed logins, encoded PowerShell, process creation, network connections, file drops).

Then it goes into the actual analyst work: a 10-step investigation workflow, a full practical investigation with an answer key, detection rule writing, an incident response playbook, and an incident report template.

Free download, no signup wall: from codelivly telegram channel

If you want to go further after this, I also put together a full SOC Analyst L1-L2-L3 bundle here: https://resources.codelivly.com/product/soc-analyst-the-complete-l1-l2-l3/

Happy to answer questions if anyone gets stuck on the Wazuh setup or Sysmon config.

I have couple problems...

First when I captured the handshakes I ssh into the PWNAGOTCHI handshake folder but it shows empty. But pwnagotchi says it captured my wifi so.im trying to find it on my cLI. Where do I look??? In the command line..

I was able to find it under the GUI under handshakes.dl. and downloads as pcap file. And from there I'm completely lost. And don't know how to crack it. How would I get it from my windows to kali. To use hashcat. Any good tutorials videos I could watch. I'm more of a visual learner.

reddit.com
u/Short-Fold-9364 — 1 day ago

Can you guyz recommend some best laptop for ethical hacking under 70k i research alot on it I found the best laptop for me is that Asus tuf a 15 but it's currently not in my budget so what can I do i have to start the practice on Linux too nd currently I'm an clg student so i get student discount to

I want to buy an laptop under 70k in offline market the price of asus tuf a 15 3050 is 1.27lahks or in flipkart around 90k nd in Amazon 73 but currently not ordered on this place so according to you guys which is better for me?

reddit.com
u/CurrentOwn753 — 3 days ago

tiktok denuncia

secondo voi se denuncio un profilo tiktok che posta gossip che mi ha tirato in mezzo scrivendo fatti miei personali, la polizia puo fare qualcosa?

reddit.com
u/rosanna627 — 2 days ago

Need some input

Been testing a web app where the usual stuff hasn’t gone anywhere. No obvious injection, auth issues, or easy misconfigurations.

There’s one weird behavior I can’t quite explain though.

How do you guys usually approach a target when the obvious attack surface is basically dead? Looking for some real-world ideas from people who’ve been in this situation.

reddit.com
u/Organic-Piano-323 — 3 days ago

[Help] Laptop and phone are hacked

My laptop and phone are hacked and they are access to remotely. I need someone who can help fix the vulnerabilities and check devices for any issues. I’m willing to pay for it.

reddit.com
u/crsquare-reddy — 3 days ago
▲ 178 r/Hacking_Tutorials+31 crossposts

The Seal, Harwich

I was jumped by a group of three men who shouted homophobic slurs at me near their pickup truck outside of The Seal pub in Harwich. Message me if you witnessed the incident or if you have any information.

reddit.com
u/ChadThunderconch — 5 days ago

Where to begin?

Hello! A long time lurker here.

I have just graduated School and I have to choose my field. Computer (specifically software) is my liking. So realistically, the options boiled down to AI, Software dev and Cybersec. Without Going in details, I decided Cybersecurity (Specifically, "Cyber security, Blockchain and IoT") and I have a few questions.

One, Where do I begin? Obviously, the classes don't start until late september to early october. I have time, But I love cybersecurity and tinkering stuff and I decided to look into it.

Two, Is Cybersecurity really stable? I mean, I didn't choose AI or Software Dev because both of them are unstable. Given the rise of AI, my hunch tells me that the AI would be used in attacks? that should mean that Cybersecurity must be booming? And the fact that we are talking about Security, I don't think that Security would be replaced with an AI, will it?

Three, The Course I took teaches Blockchain and IoT, Do we really use it in cybersecurity? are they related?

Four, are there any communities online that I can join? Perhaps a newsletter?

Thank you for your time.

So

reddit.com
u/SultanGreat — 3 days ago
▲ 682 r/Hacking_Tutorials+5 crossposts

massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others

Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.

infostealers.com
u/Malwarebeasts — 6 days ago
▲ 91 r/Hacking_Tutorials+5 crossposts

Notes I wish someone had handed me when I started in security

When I started learning cybersecurity, my notes were everywhere. Random Google Docs. Half-finished PDFs. Screenshots with no context. Bookmarks I never revisited. Nothing connected. Nothing made sense when I came back to it.

So I rebuilt everything as an Obsidian vault — structured as a proper learning path from absolute basics to advanced topics.

What's inside right now:

Networking fundamentals (OSI, TCP/IP, ports, protocols)

Operating systems & Linux basics

Security fundamentals (CIA triad, threats, risk)

Web application security (OWASP Top 10, common vulns)

Cryptography basics (symmetric/asymmetric, hashing, PKI)

SOC / Blue Team / Red Team concepts

Incident response fundamentals

Malware analysis basics

Cloud security intro

Cheat sheets and command references I actually use

The part I didn't expect: Everything is interlinked using Obsidian's graph view. So instead of flat notes, you get a proper knowledge map — click through related concepts as you're learning, and it actually connects.

It's now published as a live site too (built with Quartz), so you can browse it like a proper handbook instead of just a folder of markdown files.

I'm still actively adding to it — if you spot gaps or want a topic added, let me know. Hoping this saves someone the same scattered-notes chaos I went through.

Repo: https://github.com/priyanshu-rawa/Cybersecurity-Handbook
Live site: https://cybersecurity-handbook-lake.vercel.app

Would appreciate a star if this ends up being useful for your learning too 🙏

u/Efficient-Two-2794 — 5 days ago