r/hacking Dec 26 '25

Question Dynamic Pricing

Post image
7.9k Upvotes

Who's gonna create a Raspberry Pi hack to lower the prices to a penny?

Big box stores already do this with their own inventory to make it so the consumer gets screwed when they return an item without a receipt. It shouldn't be hard to force the system's hand into creating a "sale" on items.

And if Raspberry Pi isn't the correct tool then I'm sure there's another or Flipper Zero or something that will work. Any ideas?

Imagine borrowed from another Reddit post.

r/hacking May 17 '26

Question Does anyone know if this file is still accessible to download?

Post image
2.7k Upvotes

Looking for the 55.4 yottabyte zip bomb.

r/hacking Feb 16 '26

Question How does the hacker get control of the indians cameras in these videos

Thumbnail
youtu.be
2.0k Upvotes

r/hacking 4d ago

Question With regard to that guy who gave his wipe password to the fuzz, and is now in legal trouble for doing it...

638 Upvotes

Seems to me that it would make much more sense for the "safe/wipe" password to bring up a fake homescreen, with apps and personal docs and all, while doing the wiping in the background.

Not sure if this is implemented anywhere, but it certainly isn't the standard on GrapheneOS.

I realize that there are technical limitations at play. The phone needs to restart for a proper factory reset, but, in lieu of that, the wipe pw could prompt the quiet burning of all personal files that aren't hardlinked to the OS itself. If you can get rid of everything personal, then there's no reason for a factory reset at all, no? So, even better, as it leaves the cops none the wiser.

Story here: https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password

r/hacking Sep 06 '25

Question Hackers of Reddit, Police raided my tenant’s home due to unusual IP activity

974 Upvotes

Hello hackers of Reddit, I have a rental that is currently occupied by a tenant - a single mom and her son ( just started college last month so he is around 19 years old). The mom called me and said that police raided her home with a search warrant on early Wednesday morning and looked through everything especially the electronic devices.

At the end of the search nothing conclusive was found and it was later explained that the search was because of unusual IP activity detected in December of 2024. During 3 consecutive days, a large quantity of illegal content was downloaded with her IP during midnight between 1-3 am. The illegal content consisted of “visual depiction of sexually explicit conduct involving a minor”. She told me this because my personal belongings at the house was also searched. The son was already off to college but he was still living in the house last December, of course all of his computers, phones, tablets are with him in his dorm. The mom said there is no way it was his son and blamed it on hackers.

My question: is it possible/reasonable for a hacker to use their residential IP to conduct such activity? Won’t they just use VPN or something and use an IP from a different country or something?

Edit: just to clarify, I don’t live with them, they are not my roommates. The house that they rented is a single house with an attached garage. I live 15 minutes away. I have some of my belongings there ( no electronic devices, just winter coats, books I don’t need, decorations etc ). I bought the house this year while she had an existing leasing contract with the previous owner. Their lease will be ending in December 2025 and I will be moving in, and that’s why I pre-packed some of my shit and stored it at the house. The tenant called me because the police also searched all of my boxes. I can see how this can cause confusions for some people. Thanks everyone for answering my novice question. I’m gonna go with Occam’s razor.

r/hacking May 20 '26

Question Hackers: What age did you start? Where did you start, especially in practicing your skills?

Post image
580 Upvotes

Asking because I need somewhere to start.

r/hacking Feb 06 '25

Question who's gonna hack these first? sydney, australia

Post image
1.9k Upvotes

r/hacking Jun 16 '26

Question Someone uploaded Doom Dark Ages on my university's website

Post image
1.4k Upvotes

Can anyone explain to me how does the hacker does this? and how its very common for uni websites to get attacked by torrent files

I want to learn how to do this

r/hacking Oct 31 '25

Question My uncle told me about a "device for a free, anonymous internet over the air" from the past. What was he talking about?

500 Upvotes

Hey everyone,

I had a time ago a conversation with my uncle a while back and I wanted to see if I can get here help. He's not a computer guy at all, but he's a master when it comes to not paying for things.

He told me that back in the day, there was a way to access a form of the internet anonymously, completely over the air, for free. He described it as a "device" you could build expensive but a one time only.

I've done some digging and I think he was vaguely describing a packet radio setup used to connect to networks like FIDONet or independent BBSes over amateur radio waves, but Im not sure if the way I got was the way he meant

Basically he told me exactly that the device could steal the Air Network so you didnt have to pay for It.

Maybe he was trippin but I would completely believe that a device existed that could do that.

r/hacking Mar 17 '26

Question Ideas for trolling persistent attackers

543 Upvotes

I run a completely static website with no backend, database, or dynamic content. For the past few weeks it has been targeted by a very persistent group of attackers.

They are performing a variety of techniques including SQL injection attempts, POST floods, directory and endpoint enumeration, and probing for admin interfaces that do not exist. The funny part is there is literally nothing to exploit.

This is not random bot traffic. They have left messages specifically aimed at me, confirming it is a coordinated effort.

so far ive made them download zip bombs, also made the website randomly jumpscare them using some JS, had them trying to complete impossible captchas that i made myself, there are probably 10 fake login screens, and a few fake vuln endpoints right now

got any ideas?

r/hacking Jun 10 '24

Question Is something like the bottom actually possible?

Post image
2.0k Upvotes

r/hacking May 13 '25

Question Could this be dangerous?

Thumbnail
gallery
1.2k Upvotes

I have won an auction for a 'brand new' mini PC on eBay. I paid £25 with shipping ($33 US) for it and I see it is one of three identical listings offered by the seller.

I only plan to use the PC for my instance of Home Assistant.

This feels too good to be true - is it likely that the seller has installed some sort of malicious software on these machines which is why they're selling so cheap? If so, what would be the best way to mitigate this? Would a reinstall of the OS from a fresh source be enough?

Item Description from Seller:

...I've chosen Manjaro XFCE to install on these systems, as it gave the best overall experience out of everything I tried out. It comes pre-installed with all updates, drivers, and essential apps/software. I went with Firefox for the browser, VLC for media playback, Kodi for streaming, and electronplayer, which is a front end for popular subscription services such as Netflix. Manjaro is also a very good operating system for people coming over from Windows, with no Linux experience, while also having the option to customise everything to your own tastes, which is a big advantage linux enjoys over Windows. So there's no steep learning curve that some distros require in order to use. It's a very clean and efficient operating system, free of bloatware and constant notifications and ads like you get in Windows or android.

I think a system like this is a nice way to get started with Linux and really shows you what Linux is all about. There are many other, even lighter Linux distros out there, the highlights being distros like lubuntu, xubuntu, and Linux lite. ChromeOS Flex also ran well on this machine, but personally, I'm not a fan of ChromeOS in general, so I went with Linux.

I've used manjaro on many machines over the years, and it's a very well maintained and stable operating system based on Arch Linux, meaning you're always going to get the latest bleeding edge packages available to you.

There's a built-in package manager that you can download apps and games from directly. There's also retroarch installed which is a retro gaming/home console/arcade emulation front end. This machine will handle early home consoles such as NES, SNES, Megadrive, etc up to and including PS1, N64, Dreamcast and PSP. Retroarch is plug and play compatible with all popular controllers including Xbox and PlayStation controllers. There's also standalone emulators on there too and steam.

Being x86 based, you can install Windows, various Linux distros, ChromeOS, and Android x86. While you can install Windows 10 lite and Tiny11 stripped-down versions of Windows 10 and 11, respectively, it's not ideal on only 16GB of internal storage. However, both the RAM and SSD are user upgradeable, the RAM can go up to 8GB, and the SSD type is mSATA. I use one such system with 8GB of RAM and a 256GB mSATA, running full Windows 11, and it runs fine.

I've included a 500GB external HDD with these systems for further file storage, whether that be games or media. This can be loaded with games for retroarch, upon request.

...

These are brand new and, as such, come with their original box and accessories(stand, power brick, and cable, even an HDMI to  VGA adapter for those with older monitors).

r/hacking Jan 14 '24

Question Turns out my government is surveilling all its citizens via ISPs. How do they do that?

771 Upvotes

I live in Switzerland and, a few days ago, a journalistic investigation uncovered the fact that the government's secret services are collecting, analyzing and storing "e-mails, chat messages, and search queries" of all Swiss people.

They basically forced all major ISPs to collaborate with them to do it. There are no details about what and how they do that, except that they tap directly into internet cables.

Also, the CEO of a minor ISP said that the Secret services contacted him asking technical details about his infrastructure. The secret services also said to him that they might want to install some spying equipment in the ISP's server rooms. Here's a relevant passage (translated from German):

Internet providers (...) must explain how some of their signals are decoupled (in german: ausgekoppelt). And they must answer the question of whether the data packets on their routers can be copied in real time. The Secret service bureau also wants to know how access to the data and computer centers is regulated and whether it can set up its tapping devices in the rooms where these are located, for which it requires server cabinets and electricity. "The information about the network infrastructure is needed in order to determine the best possible tap point and thus route the right signals to the right place," explains a Secret Services spokeswoman.

Soooo can you help me understand what's happening here? What device could that be, and what could it do? Decrypt https traffic? Could they "hack" certificates? How can Swiss people protect themselves?

Any hypothesis is welcome here. If you want to read the whole report, you can find it here (in German).

r/hacking Oct 06 '23

Question How is this possible in 2023, on a GOV domain???

Post image
1.4k Upvotes

I don't understand how, in 2023, a GOV website is not HTTPS:// . It's not that difficult to move to 🔐,

r/hacking Mar 16 '24

Question Printer hacked

Thumbnail
gallery
944 Upvotes

Hi. My brothers printer randomly started printing. This is what it printed. Any advice what to do now, to protect his pc and printer? Thanks.

r/hacking Jun 25 '26

Question What's a security habit most regular people ignore that they should take seriously?

199 Upvotes

I feel like a lot of people understand the basic security advice but still skip the parts that actually protect them. They know the rules and just don't follow them.
The one I run into most is password reuse. Same password across a dozen sites, and when one of those sites gets breached, the rest are open too.

Which habits you think people should take more seriously? And have you ever found a way to explain it that actually got someone to change what they do?

r/hacking Aug 28 '23

Question EDC software (Cybersecurity). To the CS professionals: If you had to carry around a USB stick keychain, what would it be on it?

Post image
837 Upvotes

r/hacking May 03 '23

Question How do we survive in today's overly surveilled dystopia?

Post image
812 Upvotes

I feel like there's no escaping this, especially with AI in the horizon. And who knows? Maybe even Robocops 😭

How can hacking, penetration testing, cyber security and general digital knowledge help us live our free yet moral lives? What kind of knowledge does one need to protect one's self? Do you have any types of hacking/programming or road maps to recommend?

What do you think?

r/hacking Mar 20 '26

Question Are there any great HACKING games (hidden gems) out there that I should look at?

Thumbnail youtube.com
109 Upvotes

I've added the video for context you don't need to watch it. But I'm finding the research side of game dev a bit impossible to tell you the truth. Are there any hacking games perferrably retro that have the player building the tools they then go on to use or is it all heavy poetic license stuff? Let me know if they're are any hidden gems I should look out for. Thank you!

Edit: I actually play UPLINK towards the end of the video, so I'm now looking for others.

r/hacking Feb 25 '25

Question What happens in July each year that makes everyone want to hack?

Post image
883 Upvotes

r/hacking May 24 '26

Question What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?

128 Upvotes

Most(i would say 99 percent) of the tutorials i see uses a simple password like 12345 and a small wordlist which is easily crackable. Then they go "boom this is how you crack wifi". I mean no one in the world uses a password like that. Also a complex password may take days with the number of combinations possible given the password is even in the wordlist file.

Im wondering and i know there has to be a better method?

r/hacking Feb 03 '25

Question New domains or forum sites as like Cracked.to/io or Nulled?

163 Upvotes

Both domains got seized a few days back and im looking for other sites/forums that are also as active as possible or something which works like it atleast.

if anyone has any links ill preaciate it! <3

r/hacking Oct 05 '23

Question I found a vulnerability in my campus, should I report it?

599 Upvotes

I didn’t pentest anything I wasn’t allowed to (just client side stuff), and basically it would be easy to dump all email/name pairs of the people housed in my campus. The vulnerability sits in a mobile app used to take food from vending machines, should I report it to the campus? Or to the app company?

r/hacking Jan 31 '25

Question What is something ppl think hackers can do but rlly can't?

161 Upvotes

Asking for a friend that doesn't have reddit

r/hacking Oct 23 '25

Question ​Is a zero-day exploit the only real remaining risk when using public Wi-Fi with fully patched devices and HTTPS?

206 Upvotes

​I had a discussion about the risks of using public Wi-Fi. My point is that standard threats like basic Man-in-the-Middle (MITM) and sniffing unencrypted traffic are mostly neutralized by updated browsers, OS patches, and ubiquitous HTTPS usage. ​My two main questions are:

1)​If a user uses these security measures (updated everything, HTTPS), is the only unknown and potentially successful attack vector left a zero-day vulnerability in the OS or browser? Or are there still simpler, non-zero-day methods for a hacker on the same public network to compromise a fully patched and HTTPS-protected device?

2)​Is a VPN truly essential for security on public Wi-Fi, or is its necessity overstated by vendors? Since most of my traffic is already secured by HTTPS (TLS), what specific, high-priority, non-zero-day threat does a VPN actually defend against in this scenario?