← Intel
Oct 5, 2026 · HackerOnStreet

Back After Months

Back After Months — My Journey Into Hacking and Cybersecurity Back After Months — My Journey Into Hacking and Cybersecurity Back After Months — My Journey Into Hacking and Cybersecurity Hello, my name is Imran Niyaz , and I’m a junior

monthsemailpasswordcybersecurityjourneyoldaccesslookaccountemailsexploitform
Back After Months

Quick overview

FieldDetail
Topicemail
GuideBack After Months
Tagsemail, password, cybersecurity, journey, months, old
LengthAbout 941 words
Practice ruleAuthorized labs only — stay ethical

Back After Months — My Journey Into Hacking and Cybersecurity


Back After Months — My Journey Into Hacking and Cybersecurity

Back After Months — My Journey Into Hacking and Cybersecurity

Hello, my name is Imran Niyaz, and I’m a junior security researcher and exploit writer. After a few months of silence, I’m finally back — and I’m excited to share where I’ve been, what I’ve learned, and how I’ve been diving deeper into the world of ethical hacking and cybersecurity.

Photo by Dima Solomin on Unsplash

Where Have I Been?

It’s been four months since I last posted, and during that time, I’ve been focused on learning new technologies, reading extensively, and practicing real-world exploit techniques. I’ve explored several programming languages and frameworks, including PHP, Java, JavaScript, TypeScript, and many more. These tools have helped shape my understanding of how software works under the hood — and how it can be exploited if not properly secured.


My Career Path: From Learning to Investigations

As a junior security researcher, my journey has been incredible. I’ve even had the opportunity to work closely with an IT manager on various cyber investigations — a major turning point in my learning experience.

This article may not be too long, but I’ll be sharing insights into:

  • The tools and technologies I’ve studied
  • My journey in exploit development
  • My hands-on experience with Active Directory, network monitoring, and fraud detection

What I’ve Learned

One of the most valuable lessons I’ve learned is the importance of monitoring network traffic on a daily basis. Understanding what’s happening on the network, identifying suspicious activity, and keeping track of anomalies in real time are key parts of protecting any system.

A Real Incident at Work

One day while sitting in the office, I received an alarming message:

“We have hacked your email. This is your password. We have full access to your account.”

I was shocked — how could this happen? That’s when I realized they were using an old password I hadn’t changed in years. My new passwords were far stronger and more complex.

This incident reminded me of one simple truth:
 Cybersecurity is not a one-time task. It’s a daily commitment.


What’s Next?

I’m still growing, still learning, and still exploring the world of cybersecurity, penetration testing, and exploit writing. I plan to continue documenting my journey, sharing tips, and hopefully helping others get started in this fascinating industry.


Photo by Tim Mossholder on Unsplash

If you’re also a junior researcher or someone curious about cybersecurity, stay tuned. I’ll be posting more content, walkthroughs, and real-world investigations soon!


Don’t Panic: What to Do If You Receive a Threatening Email

Darshan beer (assuming this is a placeholder or reference — please clarify if needed), here’s an important note for every new security researcher or IT manager:

Imagine you suddenly receive an email claiming something like:

“We have full access to your information, including passwords and personal data…”

At first, you might feel shocked or panicked. I’ve been there — I panicked too when I saw my old password mentioned in one of those emails. But the first rule is: don’t panic.

Here’s what you should do instead:

  1. Stay calm and analyze the situation.
     These kinds of emails are often scare tactics designed to trigger fear-based reactions.
  2. Check the facts.
     Compare the password shown in the email with your current passwords. If it’s an old password, immediately update your credentials if you haven’t already.
  3. Look for patterns.
     If you’ve seen this type of message before or know someone who has, gather that info. Phishing and extortion emails often follow similar patterns and wording.
  4. Inspect the email source.
     Look at the email headers, sender domain, and any suspicious links. Most of the time, these are mass-spam attempts sent to thousands of people.
  5. Report and block the sender.
     Do not engage. Report the email as phishing or scam, and make sure to block the sender through your mail provider.
  6. Backtrack and log activity.
     If you suspect any breach, check your login activity, review access logs, and consider a password reset across all critical platforms.

Remember:

Just because someone claims they “have access” doesn’t mean they actually do. It’s your job as a security professional to verify, analyze, and respond intelligently — not emotionally.
Photo by Clint Patterson on Unsplash

Why Do These Emails Look So Real? Understanding the Threat Behind Contact Forms

All these problems often begin when we add a web form to a website — whether it’s a contact form, support form, or subscription form — and connect it directly to an email address.

What happens next?

You might receive an email that appears to come from your own address, which is alarming. But here’s the truth: it’s spoofed. It’s not really coming from your email account — it’s made to look like it is.

It’s very important to understand how this works.

Here’s how attackers typically operate:

  1. They scan your social media accounts.
     Attackers look for usernames, email addresses, or any publicly available information.
  2. They try to guess your password.
     They use previously leaked data from old breaches or attempt brute-force techniques on weak passwords.
  3. They send you your old password.
     Once they find a previously used password — even if it’s outdated — they’ll send it to you with a threatening message like:
  • “We have hacked your account. Here’s your password.”
  1. You panic, thinking your current account is compromised.
     But in most cases, the attacker has no actual access. They’re using your old password to scare you into reacting.

thanks for love