r/HowToHack May 17 '26

HOWTOHACK | Online Resource

Thumbnail howtohack.online
18 Upvotes

This website is provided by the answers found in this community to help everyone in the "where do I start" confusion loop and to help facilitate proper insight to asking for help from experienced members.

After you familiarize yourself with this site and its resources you should be able to come back here and ask worth while questions to continue your journey :)

Answers become more readily available from experienced users here when they feel like they are investing in to meaningful questions by students who are actually willing to put the work and effort in.

This website is exactly what will help new comers feel like they are ready to become valuable students by understanding what they should and should not be asking depending on their level of commitment to the resources and information provided here-in.

Hope this helps! Enjoy!


r/HowToHack May 04 '26

PSA

31 Upvotes

Hi all,

I’ve seen a lot of posts asking for help with getting a social media account, email, or other personal account recovered.

Typically, these are held on company servers which take extreme tact, skill, and time to even attempt to infiltrate. It’s also a huge ethics violation and holds severe legal consequences. (Although I don’t get the sense that anyone expects/intends for laws to be broken when asking for help- it feels more like genuine desperation to reclaim personal data, which I can empathize with.)

Many scammers exploit human vulnerability which is how you hear about accounts being taken over/hacked. This is actually good segue to add that anyone claiming they can regain your account is probably trying to scam you out of personal information or money, so be careful there, too.

Contacting the company support line is often the only way to get help.

I wanted to put this out there incase it can save anyone some time or remedy any anxiety. Much love!


r/HowToHack 8h ago

I'm confused with this overthewire bandit level.

2 Upvotes

In overthewire level 16-17, I used nmap to list all the open ports and check which on was running a service by connect to it. When I connected to the only possible port, its gave an ouput and the the end it said "Read Block R" and was waiting for my input so I gave it the current password, but noting was returned and instead a KEYUPDATE message came through and I was allowed to give my input again. And each time I entered the password it returned the same KEYUPDATE message.

Then when I entered something deliberately wrong, it said "Wrong!" and ended the connection.

But the main confusion began when I saw write up about this challenge and all of them were pasting the password and it returned a ssh key.

So, I went over to chatgpt and it also initially told me to perform the steps that I did, and I again did it so I could paste the actual outputs.

Then chatgpt told me to pipe the password using cat, like this:
cat /etc/bandit_pass/bandit16 | openssl s_client -quiet -connect localhost:31790

and it worked.

It also worked when I executed this: openssl s_client -quiet -connect localhost:31790, and paste the password.

But doesnt work when I remove the -quite flag.

I dont understand.

Can you guys help out? Also, is there an easy to read version of the nmap and nc commands, I find their man pages a bit too dense and their tldr pages feel inadequate,


r/HowToHack 18h ago

exploitation HirePro Proctoring: Continuous Recording or Event-Based Screenshots?

2 Upvotes

I have a theory about how HirePro handles proctoring and wanted to know if anyone has looked into this before.

Does HirePro's screen-sharing feed capture screenshots only when JavaScript raises a flag (tab switch, focus loss, fullscreen exit, etc.), or does it capture screenshots continuously at around 1–2 FPS and analyze them for abnormalities?

Handling both webcam feeds and screen-recording feeds for 300+ students over a 1–2 hour assessment seems computationally expensive, so I'm curious how they scale this in practice.

I also inspected the HirePro browser extension and found that its code appears to primarily disable other extensions, re-enable them after the assessment, and report if any extensions are forcefully turned back on. I didn't find any webcam or screen-monitoring logic in the extension itself.

Has anyone analyzed HirePro's architecture or worked on a similar proctoring system? What is the most likely approach being used here?


r/HowToHack 8h ago

Want to get into hacking.

0 Upvotes

Hello everybody, I really want to get into hacking and cybersecurity. I made this post seeking help from users who are into hacking and have some experience to tell me a pathway and how I should start my hacking journey, and give me some advice. I am always curious about new knowledge.


r/HowToHack 1d ago

hacking Help accessing data on medical implant

9 Upvotes

So i've been trying to find any kind of resources but to no avail. I have a loop recorder (i can get the model no. Later) implanted in my chest for heart monitoring, i know it is recording data 24/7 and i have a router that sends of the data to my cardiologist when i pass by.

I imagine this data is encrypted, but I want to be able to access this data myself and if possible create a way i can monitor it with a visual rep. Long story short, why bother getting a fitbit to see my heartrate when i have a literal heart implant thats significantly more accurate.

I'm new to this side of thinhs as usually im the guy that builds the tech, and someone else makes it work. Any help in this regard would be hugely appreciated.


r/HowToHack 1d ago

script kiddie Can I learn hacking from a phone

0 Upvotes

Ive never been in a financial position to afford a PC, but I have a nothing 3a. Can I hack from my phone alone?


r/HowToHack 2d ago

HELP!!!!

0 Upvotes

Hi there, I hope you are all doing well.

I am conducting a black-box penetration test of an Android application that my company owns, which allows users to search for the name associated with a phone number. I have already bypassed SSL pinning, rooted the test device, reversed the application's AES/CBC encryption, and built a Frida RPC interface that encrypts requests and decrypts responses exactly as the application does. I also hooked the application before encryption to capture the original JSON requests, identified the available request types, and can modify and replay encrypted requests while inspecting the plaintext responses. At this point, I feel like I have reached a dead end and I'm not sure what the next step should be. My ultimate goal is to understand how the backend communicates with its database and how the requested information is retrieved.

I really want a help or an advice that can lead me to another way to reach my goal. thanks


r/HowToHack 2d ago

I need your help

0 Upvotes

my controlling mother has put my phone on “assisted living“ where i cannot even access chrom or safarI. the only reason I am on here is that Reddit headquarters on Google Maps has its website be this. I just need my phone password to change it back, did I mention that I never knew it, I wasn’t supposed to know it, and I know my screen time limit.


r/HowToHack 3d ago

How to alter location reports in EV?

6 Upvotes

My controlling parents are tracking my EV through an app. I cannot disconnect the EV from the app because of my parents but I want to know if I could possibly alter the route or location history that it shows in the app.

Its for my safety so I'd like suggestions on how to do something like that.


r/HowToHack 3d ago

software New to posting I hope someone can help

0 Upvotes

I just learned of a software called balena etcher and was wondering if anyone could give a little guidance on what can be done with this software.


r/HowToHack 3d ago

software Want to know how my Hostel Wifi caps my bandwidth?

0 Upvotes

I am staying in an hostel and it restricts the wifi speed in residential areas to 10mbps, we access our wifi with credentials for which we need to register using our email and we get our credentials mailed.
Each time we turn on the WiFi we need to use browser to connect to wifi using our username and password. Generally after connecting to wifi we get a captive wifi page in mobile or use browser in laptop to access prontonetworks.com to enter our credentials only then we get our wifi.
Can someone explain how this works.
Thank you


r/HowToHack 4d ago

cracking Why hasn’t anyone figured out how to run the PS5 operating system and PS5 games directly on a gaming PC?

5 Upvotes

I’ve been thinking about this from a technical perspective.

The PS5 uses an AMD x86-64 CPU and an RDNA-based GPU, so at a high level, its hardware is not completely alien compared with a modern gaming PC. We also regularly see highly advanced DRM protections on PC games being bypassed, including Denuvo and newer hypervisor-based protection methods.

So why has nobody publicly managed to create something like this?

Boot Windows normally

Reboot into a PS5 environment

Run the actual PS5 system software

Install and run PS5 games directly using PC hardware

I understand that simply copying the PS5 firmware would not be enough. The system would also need to reproduce the PS5’s secure boot process, hypervisor, custom hardware interfaces, memory architecture, drivers, encryption, game licensing and possibly console authentication.

But is the main limitation really that the hardware is too different, or is it mostly because nobody has fully reverse-engineered and recreated the required environment yet?

In theory, couldn’t a custom hypervisor present virtual PS5 hardware to the original PS5 operating system, translate GPU and storage operations to normal PC hardware and run the genuine PS5 software as a guest system?

I’m not asking for piracy instructions. I’m interested in the technical and architectural reasons this has not become a real public project, especially when other extremely complex DRM and virtualization systems have already been defeated.

Has anyone researched this seriously? What is the biggest blocker:

Secure boot and cryptographic keys?

Custom PS5 hardware and undocumented devices?

GPU and driver compatibility?

PSN authentication?

Legal risk and lack of developer interest?

Performance overhead?

Something else entirely?

I’d especially like to hear from people familiar with console security, hypervisors, FreeBSD, reverse engineering or emulator development.


r/HowToHack 4d ago

Trying to reverse engineer the appsflyer sdk event send

6 Upvotes

I am trying to send custom in-app events using the SDK endpoint instead of the S2S endpoint to send events for games that have disabled their S2S endpoint. What I have accomplished so far:

- I have successfully decrypted the SDK event sending payload using Frida.

- I have successfully extracted the key used to encrypt the payload.

What is going wrong:

There is a checksum in the payload that I haven't been able to reverse engineer yet.

Each game uses a separate endpoint (not a big deal, to be honest).

The server raises a 400 error when trying to send the encrypted payload.

I need help to further finish my project:

- Any ideas on how to bypass the server's 400 error while sending events with any identifiers I want, or an easy way to understand how the checksum works.

Please comment anything you might need to offer help, and I will send it.


r/HowToHack 4d ago

Need Advise

0 Upvotes

Hello there. Today morning a friend of mine called and said what did you post on our friends group on messenger. I was really shocked because i barely post any stuff. Now the messages were screenshot of someone winning thousands of dollars doing Mr beast challenge which i had no idea off. Now here is the strange thing i already had 2 step verification enabled. So my account shouldn't be abled to be hacked so easily. And when i was seeing my phone, it was literally sending the same screenshots of that challenge to literally everyone in my Facebook especially in my Facebook group around 4 am. Now after me and my wife literally not only removed access around all other device except my own phone but also we changed password of Instagram, Facebook and google altogether. And also i didn't keep the passwords written on my google note either this time. So basically no chance also i made double sure that my 2 step verification was also on. But STILL EVEN AFTER THAT i receive messages from my friend especially from GROUP MESSAGES that they saw the text. Now these are the old groups in which those messages were sent which means the ones that were sent that i saw i deleted it all and apologized for the inconvenience but the recent chat were from very old groups that i were part off which were also sent around 4am time. Now my question is how come more old groups gets keeping resurfacing with those screenshots even tho i managed to changed everything? I checked whether my PC was hacked or not. But nada nothing not anywhere any attempts or logged in from unknown devices were shown. Please i need your expert opinion regarding this important matter?


r/HowToHack 5d ago

exploitation Concerning amount of flip flopping answers online regarding sim cloning.

0 Upvotes

I am reading that just with the phone number, ICCID, PUK, and factory default pin found in SIM card packaging is sufficient for cloning a sim.

Reading more about Ki codes and how this could be accessible from data breaches is concerning. I don’t want to have to factory reset my device and get a new sim I just need to know realistically as I worry someone has my SIM card info (not physical card but the packaging numbers and barcode). I can pull up how the Ki is found from matching other numbers from other databases.

I’ve watched hours of YouTube videos and read hours of articles and past Reddit posts and cannot get a clear answer. Some saying you can clone it and some saying not. It’s terrifying that if my sim was cloned that I wouldn’t even have a way of finding out.

For once and for all can we please establish whether or not thsi is possible with someone’s sim? I’ve been asking Google AI and they are saying it is through multiple methods. What is the deal given someone has the SIM card info but not the physical sim?


r/HowToHack 5d ago

hacking Need help finding out who is behind a fake profile

0 Upvotes

Someone created a fake profile pretending to be my partner on a German Dating Platform, and I need to find out who is behind it. My partner claims that it’s not him, but I have reasons to doubt it and I’m also wondering whether his ex could be involved.
I’d like to know if there are any ways to trace the account, find connected information, or gather evidence that could help identify the person responsible.
Any advice would be appreciated.


r/HowToHack 5d ago

How to dump standoff 2?

5 Upvotes

eu ja tentei dumpar jogos como standoff 2, codm, mas não achei a il2cpp nem a metadata, como eu faço?


r/HowToHack 5d ago

Wanted to bypass isp login page for 192.168.1.1 router using kali how to do it?

0 Upvotes

r/HowToHack 6d ago

cracking been trying to crack this keepass db hash, for some reason john and hashcat are not recognising it

6 Upvotes

even when using --format=KeePass for john and the appropriate flags for hashcat. I'm not saying it's not cracking, it's not even starting the crack, i have no idea why it's not recognising the hash


r/HowToHack 6d ago

How to crack Wpa2/3 password ?

0 Upvotes

Hi guys my dad has been really weird recently and has been changing the wifi password daily to the point where it is annoying. He constantly suspects that whenever I am in my room alone I am playing games which is a bit stupid but alright.

If anyone knows how to find wifi passwords without resetting/ scanning a QR code would be much appreciated


r/HowToHack 6d ago

Pokemon go spoofing

0 Upvotes

Hi I’m looking to start spoofing I’ve done it back in like 2018 but was a lot simpler then 😂
I’ve got a pc so I can jailbreak the iPad I’m going to use i just don’t know the logistics like what’s the best apps and what won’t give me any mall where so if anyone can help me out I’d really appreciate it I’m sick off people trying to low ball me for regionals and i just wanna compete my Dexs


r/HowToHack 7d ago

How do I create a manual-map console injector?

4 Upvotes

How do I create a C++ console application that injects a DLL using the manual map method—specifically, one that automatically finds the target application and injects the DLL into it?


r/HowToHack 8d ago

exploit Is it possible to unlock bootloader and flash a modified kernel without complete factory reset? [Android14]

4 Upvotes

Body is same as title, actually the root question is that is it possible for a sideloaded app to have kernel level access on android 14 without complete factory reset of device.


r/HowToHack 9d ago

Question about gadgets

5 Upvotes

Anyone got any cheap gadget tutorials so I can make a little toolkit to learn?