#research

1 messages · Page 1 of 1 (latest)

earnest frost
#

🙌

wary thunder
normal marsh
#

so would that veratasium video about ss7 and hacking the phone network count???

hazy crypt
normal marsh
#

well it is discussion and documentary format

deep barn
hazy crypt
#

Starting a discussion

If you are looking to start a discussion, please ask a moderator or community mentor to create a thread for you.

upper orchid
# normal marsh well it is discussion and documentary format

http://media.ccc.de/browse/congress/2014/31c3_-_6249_-_en_-_saal_1_-_201412271715_-_ss7_locate_track_manipulate_-_tobias_engel.html

Companies are now selling the ability to track your phone number whereever you go. With a precision of up to 50 meters, detailed movement profiles can be compiled by somebody from the other side of the world withou...

▶ Play video

Local GT is IP/international number of your local operator node..
Server/peer is your service provider
Client is you..
Msisdn is phone number of target..

The attacked server is simulated as you may have been able to tell from the 441234568890 number..

▶ Play video
#

The discussion ends when you realize its just like finding a node on the network, so you need to get access to the network first

#

before you can track someone

normal marsh
#

yeah fair

#

think the veritasium video is more none tech person understandable but more in depth is good

rigid kelp
#

After all my research i've uncovered a universal truth installing Linux won’t make you a hacker

dark sedge
deep barn
rigid kelp
#

Does any-one get any voucher after compelting Cybersecurity 101 path?

stoic glacier
jade heart
#

Created a note on subnetting based on what I learnt from the pre security. I don't know how much I pulled off the important information. Expecting honest comments and advices to improve my note more. Thank You.

scenic crane
#

Hi

ripe wedge
#

hi guys i have problem while buying thm premium it keep decliening my payment

#

im from india

#

i have tried with five different debit cards

ripe wedge
oak shoalBOT
#

Gave +1 Rep to @atomic turret (current: #44 - 194)

proper magnet
#

whats the tools working on Cloud Shell

glass zinc
#

anyone have any research or guidance on file level encryption vs drive level encryption?

looking for things like why you’d choose drive level over file level for backups in particular

is general guidance “it doesn’t matter, as long as it’s encrypted”?

gray mural
deep barn
hazy crypt
cunning kelp
crimson lotus
# cunning kelp Yeah, disk-level encryption these days can take advantage of the TPM in your mac...

Just adding a couple things I thought of as well related to this

An attack may be possible in some situations where the attacker has extended unrestricted access to your hardware. The attack could enable them to retrieve your key from the TPM. Because of this, some people prefer to use disk level encryption in the other configurations mentioned, where the key had to be either inserted, manually entered, or even delivered by a Tang server or bitlocker network unlock. These configurations can open a different attack surface, but they also prevent decryption by the more commonly known methods for retrieving keys from the TPM.

cunning kelp
#

You can also require encrypted usb keys and control/manage the keys centrally for file transport. So if you had to physically transport a sensitive file to a restricted/air-gapped location, for instance, key management for the usb key and file can be maintained securely and access can be very tightly controlled

hazy crypt
#

Hey, would you be able to make a post rather than linking to your Twitter? This channel is strict on advertisements, it is very clear in the guidelines -> #research message

verbal coral
#

@strange quartz Sorry, for the protection of our members, I'll have to ask you to ask our server to do this

unkempt jolt
#

Hopefully this is the right channel for this but recently the FBI and tons of other partners dismantled the RedLine and META info stealer. https://www.justice.gov/usao-wdtx/pr/us-joins-international-action-against-redline-and-meta-infostealers. I found the report very cool. At the end of the report they show the redacted warrant they sent to the domain hosting provider. It’s very cool the amount of work our federal employees from around the world worked to shut down these 2 prolific info stealers.

strange quartz
open sedge
strange quartz
open sedge
verbal coral
#

It is

stone mica
unkempt jolt
#

reverse engineering the patch itself was very smart.

unkempt jolt
#

Also your website looks fabulous

tawdry zephyr
cunning kelp
oak shoalBOT
#

Gave +1 Rep to @cunning kelp (current: #21 - 436)

hazy crypt
#

Over the past few months, has anyone seen any particularly interesting vulnerabilities or threats?

Further reading would be great 😊

normal marsh
#

interesting and scary for shadow

#

not that shadow runs ubuntu

twin plover
#

I've just come across these "telegram trading bots" for solana coin or something. I know they're not safe and I want to prove it. Has anyone got any more information on these bots? I can just tell there's a team waiting to wipe everyone's crypto wallets on the other side, I was wondering if there was a way to prove it.

#

The one someone has said was called "trojan solana bot" or something similar.

verbal coral
bitter karmaBOT
twin plover
terse crater
#

Anyone analyzed ACS_stream Programm? I tried but couldn’t find anything. It collects routing table and network infos on startup. Tried to find if it forwards those information

azure field
# hazy crypt Over the past few months, has anyone seen any particularly interesting vulnerabi...

Tracking an NK campaign right now, someone in here reached out with a file malwarebytes detected as a stealer, turned out to be invisibleferret - worked with victim to find the initial IOC and started tracking a multitude of LI profiles spreading beavertail + invisibleferret combo through contagious interviews, almost all of them are crypto related and ask the interviewee/victim to run a node project, usually some boilerplate web app with an exec snuck in that executes obfuscated node (beavertail) within a PNG

will likely soon have a research article and TTP/IOC report on our blog but Unit42 also covered this very well: https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/

#

seeing a big uptick as we've identified a few new C2 rotations and new campaign IDs as recent as a few days ago

marsh niche
#

Anyone familiar with sensity-ai/dot or any new improved versions ?

unkempt jolt
azure field
round laurel
#

I'm working on a honeypot project. This mainly focus on finding if there any flaws present in the present honeypots.
Can anyone suggest how should I start n find out some resources as I'm not so familiar with it

hazy crypt
cunning kelp
rotund latch
hazy crypt
# rotund latch https://revdiaries.com/post/solara-malware-analysis

Awesome analysis! I'd definitely like to come back to this post as a later point and see if this Malware creator is behind any other of the popular malware scripts.

It's actually incredibly common for Roblox DLL injectors and scripts to actually be malicious.
Something about Solara is that it actually was a real 'legitimate' cheat but, if I remember correctly, someone created their own fake Discord and started distributing a fake version.

rotund latch
rotund latch
#

They have updated their github account, you can find them at the very bottom of the page @hazy crypt

And i have found 2 different samples associated with the same developer.

bright oasis
bright oasis
#

kind of frightening

rotund latch
cunning kelp
rigid kelp
unkempt jolt
twin plover
#

Anyone heard about these telegram channels cropping up in the Uk?

#

What's happening is people are clicking links to join them, and then the link redirects them somewhere, asks for camera permission, takes a photo with front and back camera and then sends that to someones private telegram channel

#

I'd give it a good look through but it seems like a lot of trouble

cold axle
cold axle
#

Nice read, thanks for sharing

oak shoalBOT
#

Gave +1 Rep to @wet crystal (current: #59 - 147)

stone mica
#

Very interesting, thanks for sharing!

oak shoalBOT
#

Gave +1 Rep to @wet crystal (current: #59 - 150)

cunning kelp
#

An old story from back in 2017 popped up while scrolling. Though you might find it of interest

Here's the article:
https://www.wired.com/story/malware-dna-hack/

And here's one from the IEEE:
https://spectrum.ieee.org/researchers-embed-malicious-code-into-dna-to-hack-dna-sequencing-software

WIRED

Researchers planted a working hacker exploit in a physical strand of DNA.

IEEE Spectrum

The DNA-as-malware hack, although difficult, points to weaknesses in bioinformatics software

modest dune
#

can a attacker get shell of Victim through bind shell ?
is it possible ?

hazy crypt
chrome bay
rotund latch
amber maple
oak shoalBOT
#

Gave +1 Rep to @rotund latch (current: #27 - 362)

chrome bay
oak shoalBOT
#

Gave +1 Rep to @rotund latch (current: #27 - 363)

full solstice
unkempt jolt
unkempt jolt
stone mica
#

Feel free to share more if you do work on more. I'm personally very interested in forensics, but don't really want to go into the technicalities of it.

#

So I enjoy reading articles like yours.

#

It feels like a sherlock investigation lol.

unkempt jolt
oak shoalBOT
#

Gave +1 Rep to @stone mica (current: #153 - 54)

obsidian kettle
oak shoalBOT
#

Gave +1 Rep to @unkempt jolt (current: #61 - 143)

oak shoalBOT
#

Gave +1 Rep to @obsidian kettle (current: #1858 - 2)

unkempt jolt
#

Glad you like it

hazy crypt
#

this is a place for research, not advertising, please read the guidelines in the channel description

glass zinc
#

i like this ty!!!

oak shoalBOT
#

Gave +1 Rep to @wet crystal (current: #53 - 172)

unkempt jolt
cyan kindle
rigid kelp
#

hey guys ik this is super random but ive just started my journey into cybersecurity and ive missed a class where they where using the amazon aws

ive created a http server ( public) and database(private) i ssh'd into http server already using my key which i transfered using scp -i EC2_ubuntu.pem EC2_ubuntu.pem and now when i im in the ubuntu machine and i try to ssh into the databases private ip it doesnt show anything no words and 2 minutes later it says ssh: connect to host 10.0.0.223 port 22: Connection timed out

if someone could help me i would greatly apreciate it and i will be in ur dept 🙏

twilit leaf
# rigid kelp hey guys ik this is super random but ive just started my journey into cybersecu...

first of all: wrong channel. next, you do NOT provide enough information here, with that it’s impossible to help you. besides what you ask is a rather noob question, are you sure u wanna start your journey into cyber now? instead i suggest you learn more basics in network + operating systems. to fix your problem make sure you know at least enough about ssh (PW + PKI) and how to add ip address, change routes, learn what subnetting is .. the list seems long so i stop now but should be a start that keeps you busy. good luck 🙂

jade vigil
#

Hi

scenic pike
#

How to capture login traffic without Wireshark ?

earnest frost
mellow plank
#

guys i found something interesting, is there a way for a phone on your network to declare itself as a router and appear as one in ipv6 neighbor discovery?, i ran the network through wire shark and it seems there is a device spoofing requests trying to look like my router with smaller differences to the mac address

also i blocked upnp request on my router a few days ago because it seemed like i am getting DDoSed from all of my IoT devices, so now i get a ton of port 5353 request instead by the same volume

also there was a suspicious address trying to access SMB today which i have never seen before

all of these got blocked of course, but the only devices that were acting weird is that phone that appears as a router, and another computer that can traceroute other devices, but you can't ping that computer or traceroute it, sounds like a man in the middle attack with a rouge router, i might be looking too much into things but i did get an arp poisoning alert from that same phone when the issues started, plus there a hefty amount of arp requests in the wireshark sniffing i did before

what do you think?

mellow plank
rigid kelp
#

Okay

#

do you have IPv6 RA Guard enabled?

mellow plank
#

im less worried about their foothold, more about how they are doing it

rigid kelp
#

easy, MitM

mellow plank
#

yeah

#

arp poisoning, mitm, lateral movement, IoT device acting like botnets, rough routers using ipv6

#

was wondering who else acts in that fashion

rigid kelp
#

Who doesn't ?

#

It's really common

mellow plank
#

mirai spiked on days where i had the most intense attacks

#

so i had my suspicion

#

but i dont see any malware drops

rigid kelp
#

Yet

#

If I'd be you, I would disable IPv6

mellow plank
#

yeah i thought about that

#

but my curiosity has the better of me haha

rigid kelp
#

Fair Enough

#

disabling DHCP is also one thing I'd do

mellow plank
#

i actually wanted to check my DHCP tables but cant because of the hardware im using

#

i think they know this hardware because of the way they are attacking

#

its very simillar to the recent ASUS routers attack

rigid kelp
#

Then you are going to have a long night

cunning shuttle
#

Unplug internet. Problem solved

stone mica
#

Also I'm not sure why would someone chain such a complex attack unless you are a very high profile such as a government or a high value target.

mellow plank
#

Didn't find it's command and control though so can't attest to that

obtuse dirge
trail torrent
#

Does anyone have any favorite research papers about China's AI ecosystem or cyber policy? I want to further my knowledge here.

cunning kelp
#

Just a fun jaunt into a little bit of recent history

https://www.youtube.com/watch?v=fxqcwK5OMag&pp=0gcJCcEJAYcqIYzv

The Shadow Brokers leaks are one of the pivotal moments in history: not only did they create a massive wave of cybercrime and caused nothing short of a political scandal, they also gave birth to one of the Internet's most enduring mysteries. Who were the Shadow Brokers? How did they pull off one of the craziest hacks of our time? The answer is s...

▶ Play video
dreamy nimbus
#

Hi everyone,
Does anyone know how to get SoP for SOC operations and if any real world datasets for research purposes?

Is there a legal way to get some good datasets?

cunning kelp
vast wave
cunning kelp
golden hare
cunning kelp
golden hare
cunning kelp
#

A very important topic we've touched on at various points...

https://en.wikipedia.org/wiki/IP_over_Avian_Carriers

In computer networking, IP over Avian Carriers (IPoAC) is a humorous but ostensibly functional proposal to carry Internet Protocol (IP) traffic by birds such as homing pigeons. IP over Avian Carriers was initially described in RFC 1149 issued by the Internet Engineering Task Force, written by David Waitzman, and released on April 1, 1990. It i...

cunning kelp
#

How the NSA Hacked Huawei: Operation Shotgiant

https://www.youtube.com/watch?v=aQNgelm7JeE

How do you hack the largest tech corporation in China? Well, if you are the National Security Agency of the United States, you just… send a phishing email. At least that’s how Operation Shotgiant, one of the most ambitious operations of the NSA, happened. In the span of a few years, Huawei was hacked - and possibly, all of its users.

🎯 S...

▶ Play video
crystal topaz
cunning kelp
hazy crypt
#

this channel is for research, please use #resources 🙂

uneven osprey
cunning kelp
hazy crypt
#

The image gives off Watch Dogs (the game) vibes

hot raft
#

/so_much_for_subtlety hay whare ara find a tools

thorny thicket
#

Anyone here prepping for Python basics / Security+ / THM modules / AZ-900 and wants to form a beginner study group?

stone mica
thorny thicket
dire spindle
#

Yes google is.

thorny thicket
glossy thorn
pastel lichen
#

Ethical basic book links can somebody provide to learn

timber urchin
hearty oak
undone shard
halcyon wadi
#

.

slender void
#

anyone ever wrote and submitted CVEs?

#

i've got a couple i found but not sure about the process

earnest frost
slender void
rigid kelp
#

Tested on:

  • Windows 10 Enterprise x64

    • Specs: Intel i5-8500, 8 GB RAM, 256 GB SSD, SentinelOne EDR installed
  • Ubuntu Server 22.04 LTS

    • Specs: AMD Ryzen 5 3400G, 8 GB RAM, 128 GB SATA SSD, default ufw firewall
  • Debian 11 (minimal install)

    • Specs: Intel Pentium G4560, 4 GB RAM, 40 GB HDD
  • MacOS Ventura (Intel)

    • Specs: Intel i7-8850H, 16 GB RAM, 512 GB NVMe SSD
  • AWS EC2 t3.medium (cloud target)

    • Specs: 2 vCPU, 4 GB RAM, EBS storage, Linux AMI
  • VirtualBox/VMWare VM

    • Specs: 2 vCPU, 2 GB RAM, 25 GB virtual disk

— — — —

Worked on minimal:

  • Debian 11 VPS / VM

    • Specs: 1 vCPU, 2 GB RAM, 20 GB disk
  • Raspberry Pi 4 Model B

    • Specs: Quad-core ARM Cortex-A72, 2 GB RAM, 32 GB microSD
#

i am currently writing a full blog on how i came up with the idea for project synthesis and more — stay tuned, may take a minute, trying to garner some outside help with it😄

#

please take this seriously

rigid kelp
undone shard
full elbow
#

Hey guys idk

#

If I'm on the right channel

#

But could anyone recommend mu WordPress and drupal ctfs that I can use to get practice in?

full elbow
#

Ping me if you're willing to help, thanks

sweet cedar
#

@full elbow have u tried Drupalgeddom?

earnest frost
latent dust
#

hi guys
anyone know about how to do penetration testing for web application

hazy crypt
full elbow
full elbow
earnest frost
full elbow
oak shoalBOT
#

Gave +1 Rep to @earnest frost (current: #1 - 5968)

slate tusk
#

@earnest frost I will enter university, but I love cyber security. Should I enter computer science as a university major instead of the cyber security college? Because my teacher said that cyber security is a major, not a field. I also believe that cyber security depends on side certificates, a creative major.

earnest frost
sweet cedar
hazy crypt
#

Can you make sure that all articles published here are freely accessible to read (i.e. not limited to members only or are paid).

undone shard
hazy crypt
#

Post the free link please not the members one.

undone shard
#

Hey I posted free link

hazy crypt
#

I opened it, it was still not the free one 😅

undone shard
#

Kindly open this

#

@hazy crypt hope this link is working.

hazy crypt
#

Seems to be okay, thank you

fallen geode
rigid kelp
young egret
#

@stone mica
Hey, sorry about reaching out to you, I just had a quick question for you.
Do you by any chance keep track of server statistics, specifically monthly message counts? I'm looking into a decline in social media usage, I was curious to see if this server affected in the same way

stone mica
young egret
stone mica
#

Would you like the cert roles?

oak shoalBOT
#

Gave +1 Rep to @stone mica (current: #26 - 406)

oak shoalBOT
#

➕ Gave the role OSCP to zumiyumi

primal citrus
#

Great write up, Zumi. I especially liked the detail you gave in your advice about having a disciplined methodology and its rigorous application.

Discovering your own flow is so important and I’d often overlooked.

I also liked you comment about knowing how far to go and knowing when to stop.

hazy crypt
#

Just so people are aware:
This channel is not for promotion. It is intended for research-based discussion - links will be removed if they do not fit the guidelines of the channel (this can be found in the channel description).

shadow sluiceBOT
#

:hammer: buieevdkw5iw#0 has been banned.

shadow sluiceBOT
#

Done!

digital mauve
#

DeTraced Security has finished our second engagement! This time we followed a TA across the internet. This time we've published both a blog post and also IOCs/YARA rules. Feel free to check them out!

BLOG:
https://detraced.org/posts/infostealer-turned-ransomware/

IOCs:
https://github.com/DeTraced-Security/detection-rules/tree/main/groups/betray

DeTraced Security

Just when you thought a TA wouldn’t shift TTPs…

GitHub

A collection of detection rules from our various engagements - DeTraced-Security/detection-rules

stone mica
#

That's reserved for advanced channels.

tardy narwhal
#

yo i got a problem is there anyone?
i accidentally bought PT1 and now i want to cancel
is it Possible?
because i dont see any Cancel anytime button

tardy narwhal
#

😶

sand pumice
#

Heya guys how's it going?

I just joined a team doing research on post quantum cryptography (PQC) in classical networks and so I lightly dipped my toes in lattice cryptography, NIST's current standard algorithms, Rolfe Schmidt's Triple-Ratchet yada yada

For more context, we want to discuss, since PQC implementation is a classical problem (no quantum hardware needed), what's getting in the way? Why do we not have PQC everywhere already? Is it the problem of key sizes, is it some other bottleneck, etc...

I just wanted to ask over here if you guys have any impressions, heard of anything interesting, etc?

hallow zinc
#

I assume it's mostly just the inertia and difficulty of switching over existing systems? It takes time to upgrade things

#

Like the US Govt has addressed PQC as something to use but their timescale is to get all their systems changed over by 2035

#

Balancing the added cost of rushing to upgrade everything sooner with the added risk of upgrading later

#

Plus since most PQC algorithms are pretty new there's a higher risk of new vulnerabilities being found. Patched now but KyberSlash springs to mind

#

Replacing cryptographic hardware modules is trickier than replacing software as well . and hard to justify to consumers., so a lot will not be updated until replaced

#

But to answer why we don't have PQC everywhere already, they only standardised it a year or two ago and it takes longer than that to implement a change of that level for a lot of large systems and organisations

#

And a lot of smaller less critical systems will feel less pressure to switch

#

Document from NIST outlining the steps involved in migrating^

#

@sand pumice

sand pumice
oak shoalBOT
#

Gave +1 Rep to @hallow zinc (current: #3240 - 1)

sand pumice
#

Stay blessed

hidden geyser
#

Hello everyone, I have a question: would anyone be willing to take a look at a vulnerability report I created earlier this year?

It’s based around an audio exploit I caught in the wild and reversed engineered. I sent the report & exploit to Google’s research team on April 11th and on April 16th, Apple pushed out emergency patches that match the description of the report provided and accredited Google.

I found what I believe is a hardware flaw on the iPhone and would like an opinion of whether I am missing the mark or not..?

slender grotto
#

Helo any help me

glossy thorn
#

Hi! Happy to share it with you

Microsoft blocks VBS macros on retrieved word document templates, even in a local intranet networks, to prevent phishing

I found a way to bypass it on local networks, using LLMNR poisoning. Can be useful for local phishing assessments!

Microsoft didn’t recognise it and there is no patch

https://github.com/rubenformation/Office-Intranet-MOTW-Bypass

GitHub

New Unpatched Intranet Mark-of-the-Web Bypass. Contribute to rubenformation/Office-Intranet-MOTW-Bypass development by creating an account on GitHub.

stone mica
#

If it's not related to THM we cannot help.

civic oriole
#

Hello guys, can anyone explain to me why can't i crack my own kali linux password using John the ripper. I just finished doin task 6 of "John the Ripper: The Basics" room and i wanted to try it out on my own system.

I'm using a usb bootable OS of kali linux.

#

mmmmm am i askin in the wrong room? lol

stone mica
civic oriole
stone mica
#

Likely it did not recognise the format

civic oriole
#

hmmmmmm

#

quick qs, how should i write a yescrypt in the "--format" of john?

civic oriole
#

oh, thanks @digital mauve

oak shoalBOT
#

Gave +1 Rep to @digital mauve (current: #31 - 351)

civic oriole
#

🥲 still couldn't crack it. Thanks anyway guys 👍 👍

#

ah wait bruh, i mispelled "crypt"

#

hahahahaahah! finally cracked it

digital mauve
#

there you go lol

still sandal
#

How to crack it

still sandal
#

What format

rare seal
#

Hi

gilded acorn
#

hey guys

#

umm....heloo?

glossy thorn
#

I found that fileName parameters in the ms-photos URI handler supports UNC paths.

Combined with a server redirection, it allows to leak NTLM hashes, with a one click condition (open photos popup) from any browser.

This combination could allow wide supply chain attacks, since it moves from a browser redirection to NTLM hashes leak.

Find more details and a POC about it

https://github.com/rubenformation/ms-photos_NTLM_Leak

GitHub

New unpatched 0 day vulnerability allowing to leak NTLM hashes from browsers with one click - rubenformation/ms-photos_NTLM_Leak

brisk willow
#

I hope I'm asking the right room here, but does anyone have any suggestions on THM rooms to help in mastering Wireshark? I've done Network Traffic Basics, Wireshark: The Basics, and Wireshark: Packet Operations. When I got to Wireshark: Traffic Analysis, it immediately felt overwhelming and like I needed more practice with the Wireshark foundations. Any recommendations would be appreciated!

dire spindle
#

downlaod the .exe

still sandal
#

very studious

earnest frost
still sandal
#

can do

willow pine
glossy thorn
austere verge
glossy thorn
austere verge
# glossy thorn This one

I'm still quite new and networking is not strong suit, what is Mark of the web bypass exactly? And did you use burp suite or custom tooling for LLMNR poisoning?

glossy thorn
austere verge
oak shoalBOT
#

Gave +1 Rep to @glossy thorn (current: #3292 - 1)

glossy thorn
high tree
#

ngl sorry i didnt read the rules i just saw research and posted something never before seen before the uhh the impossible happening is what im referring to btw

icy spruce
#

Hi is there anyway to download G-Drive video, which I have view only access..
Any browser extension or downloader?

still sandal
#

try

viscid jacinth
#

Hi all , I would like to know your opinion on the most important points regarding maritime traffic and its traceability. If you have any ideas, I'm all ears. My husband is working on a research project on this subject. Thank you. My DMs are open if you have any information.

still sandal
#

with rules

restive hedge
#

Hello guys...

#

Can anyone help a 15 years old kid by making an basic research in deep way about - all common thing, activities and function of malware and virus and more.....
But here is the catcher, it all should need to be common.
Advance thanking you.
For helping.

static basalt
restive hedge
#

Yea...
It because i am planning to build an unbreakable antivirus.....
It can be impossible but until i see what make it impossible....
To learn why it is impossible i need data about the common things of malware... M

lusty bone
#

Hi everyone,

I’m an ISC2 CC-certified cybersecurity undergrad( final year) with solid theoretical knowledge and intermediate Python skills.

Looking for Final Year Project (FYP) ideas that are feasible, doable, and novel in cybersecurity.
Please share your thoughts 🍀

restive hedge
#

Built an antivirus

karmic hearth
#

With python experience, security focus, and considering what's modern and popular, you could look into AI guardrails. What seems to be generally under-emphasized is response-based checking (and this is often very complicated to build because responses in chatbots are often streamed to the user)

keen warren
#

Is wsl good for hacking ?(I have a old laptop which only has one port so I can't boot into kali Linux)

sly flume
keen warren
compact acorn
#

Hello everyone,
I am a cybersecurity student and I am currently working on a CTF. However, I am encountering several difficulties, particularly regarding the management of rights and the exploitation of files.

In the scenario, I play as Alice and I have to send a message to Bob using a mechanism related to the cron.log file located in /tmp. I managed to create a script via nano to retrieve a message belonging to Bob, in which there was a flag.

However, my teacher explained to me that even though I had 'passed through the door of Alice’s burrow,' I hadn’t gone 'to the end of the burrow.' In other words, I started the exploitation, but I did not push the logic to the end.

I think that a complete Cyber Kill Chain should be set up, notably by using a reverse shell to obtain access under Bob’s identity (or at least perform actions on his behalf). The problem is that I can’t use Metasploit, because Alice doesn’t have the necessary rights to run it. It’s at this point that I block.

I am also supposed to find root access, but I did not see any exploitable trace in the files provided.
Would you have any advice or leads to move forward?

This lab is inspired by both Matrix and Alice in Wonderland. I have already followed the white rabbit... and now I have to find out how to explore his entire burrow, until the end

#

I have screenshots if someone wants more details

storm matrix
#

Does anyone have an utility tool for managing tiktok

compact acorn
#

Yes... On THM on private room I need to to an Vertical Privilege ... I haver did horizontal

verbal coral
compact acorn
keen warren
#

My budget is 500 what laptop should I get for software development and ethical hacking I'm also planning to get a wifi adapter

hollow tundra
twin wadi
#

Buy second hand

keen warren
ember furnace
#

hlo

keen warren
#

Hi

rigid kelp
#

Hello is this the room for malware development and analysis?

rigid kelp
rigid kelp
#

How to get in?

rigid kelp
rigid kelp
oak shoalBOT
#

Gave +1 Rep to @spare monolith (current: #93 - 113)

rigid kelp
#

I'll grind more

#

no worries, enjoy

clever silo
cunning kelp
clever silo
cunning kelp
keen warren
#

Should I use reverse tcp or rce?

gilded trellis
clever silo
sly flume
keen warren
wary crest
keen warren
#

Reverse tcp*

wary crest
#

Like I said, it makes no sense. One is a specific technique while the other is a broad category of vulnerabilities.

keen warren
sly flume
keen warren
#

I already know

steady vortex
#

Heyy guys today i got the Advent of Cyber rewards and i have got 75$ voucher but i am not able to utilize it cause i already have the premium so if anyone wants it .
Dm me .

thorn totem
#

Hii guys I want to learn free el ethical hacking h from basic , anyone have idea Abt free alternative. ?? Plz DM and reply me..

vapid crystal
#

Bro i also want it
If you get any information pls share with me

drowsy flint
thorn totem
weak glacier
drowsy flint
# thorn totem Actually i have gone in this website in past but I don't know how to use this we...

you just click on a room, then follow the steps to complete it. each room will have text you have to read, and questions to answer based on the text, and sometimes interactive machines. since you said you wanted a free alternative, you can go through the links in the article i gave and comeplete them in order. It should give you a lot of knowledge. If the site is too complicated or hard, there are many walkthroughs on rooms on youtube :)

thorn totem
#

Tell more about on youtube?

tranquil ember
#

Hi everyone!
I’m looking for Discord or Telegram channels/bots that focus on cybersecurity news. Specifically ones that share updates on major data breaches, threat reports, and security incidents. I tried searching for them via reddit forums and google dorks but couldn't find any links. Any help is appreciated

drowsy flint
# thorn totem You said on youtube?

if you just look up “tryhackme room walkthroughs” you can get help on some rooms for the site. Alternativly, you can search for things like “ethical hacking” or “eithical hacking courses” to get informational videos

thorn totem
drowsy flint
drowsy flint
thorn totem
drowsy flint
thorn totem
drowsy flint
#

usually i have to take notes and the questions help. i read the text once, then read the questions, and answer any i can,then read again to answer the rest of the questions

drowsy flint
thorn totem
south citrus
#

So what are some good trends to be researching as of today?

stone mica
#

Not the place for recruitments.

#

Oh you spammed it everywhere. kek

sly flume
keen warren
#

Should I install debian or kali?

verbal coral
elfin sparrow
steep oxide
# keen warren Should I install debian or kali?

Well I was in the same spot and now I run kali as a container in fedora. I use distrobox to run kali in a container and it's very impressive. You can even run GUI apps from the container and also export them to your host machine and they will still run under your container. Not to mention I can access all of my host files from the container. You can give it a try and check out for yourself -> https://github.com/89luca89/distrobox

steep oxide
oak shoalBOT
#

Gave +1 Rep to @copper anchor (current: #790 - 9)

blissful harbor
#

Anyone ever heard of silent Mafia or slient Mafia or mafioso. Just asking

oak shoalBOT
#

Gave +1 Rep to @steep oxide (current: #3614 - 1)

timber urchin
#

A structured, cross-referenced knowledge base for Android security research.

How malware works. How attacks exploit the platform. How protections are broken.

https://zahidaz.github.io/awake/

lone river
#

Anyone ever here of a collect agency called Harris & Harris?

keen warren
#

No why?

cold spear
#

Hello everyone,
I’m currently learning IBM QRadar SOAR and working with playbooks and Python scripting. If anyone has experience in this area, I would greatly appreciate your guidance.
Could you please share any recommended learning materials, documentation, courses, videos, or practical tips that helped you?
Thank you in advance for your support!

keen warren
#

Does tryhackme have certifications?

keen warren
#

Thx I guess?

oak shoalBOT
#

Gave +1 Rep to @earnest frost (current: #1 - 6119)

bronze igloo
#

can someone help me??

vernal temple
#

Hi are you interested in possible collaborations with my company in vulnerability research on mobile and desktop?

heady fable
#

Anyone have a suggestions for github projects on cybersecurity? would love the reccommendations!

keen warren
#

Can you run hydra on a Linux emulator

#

And one more thing which language is the best? Python or C++?

gloomy breach
#

It’s better to know both

earnest frost
earnest frost
keen warren
#

Thx

keen warren
oak shoalBOT
#

Gave +1 Rep to @gloomy breach (current: #3680 - 1)

bitter karmaBOT
sharp ember
#

is this really how this server works?

#

i dont think you know what ethical hacking is

keen warren
#

Does anyone know how can I apply for mod

winged portal
#

Hey THM Fam! Sharing my own research: Human Detection of AI-Generated Phishing (participants welcome)

The study is live and open for participation if you want to contribute to the dataset or see how you perform. It's free and takes about 5 minutes - and as a bonus, it's a video game:

https://research.scottaltiparmak.com/

I'm running a study looking at which phishing techniques produce the lowest human detection rates when all stimuli are AI-generated. The core question is: when writing quality is no longer a distinguishing cue (because everything is LLM-generated), what structural and contextual properties of a phishing attempt are hardest for people to catch?
The study uses a 1,000-card dataset across six phishing technique categories and three legitimate email categories, all generated by LLMs to partially standardize linguistic quality across conditions. Participants classify each email as phishing or legitimate and rate their confidence.

Early data from 95 participants (1,520 classified cards so far):

Overall detection accuracy ranges from ~80% (general users) to ~88% (infosec professionals)

The gap between security professionals and general users is not uniform across techniques.

Authority impersonation shows a clear training effect, but hyper-personalization narrows the gap significantly

17% overall bypass rate (phishing classified as legitimate)

The full study protocol and dataset design are published on Zenodo:
Altiparmak, S. (2026). Human Detection of AI-Generated Phishing: Study Protocol and Dataset Design for the Threat Terminal Experiment. DOI: 10.5281/zenodo.19059296
Happy to discuss the methodology, limitations, or anything about the design. Still in data collection so no firm conclusions yet, but the directional patterns are interesting.

Threat Terminal

Can you spot a malicious email? Test your phishing detection skills in this retro terminal game and live research study.

long saffron
# winged portal Hey THM Fam! Sharing my own research: Human Detection of AI-Generated Phishing (...

Hey, looked decently good, maybe include a little more variation, such as shorter variants of phishing emails or some more sophisticated ones, where BEC (Business Email Compromise) would also come into play, as an example, sending an email with passing headers from the correct domain, but at an unusual time, which should raise suspicion. UX wise, I'd tell you to please resize the actual email window to more like a square, cause it's quite annoying to read long lines of text going almost straight down vertically.

winged portal
#

Hey, thanks so much for checking it out! Appreciate all the feedback, all very valuable, some already in planning and some I will need to add, as I aboslutely agree. Thanks again!

keen warren
#

What is flipper zero best for?

sly flume
keen warren
solar horizon
#

record and replays

rose dirge
#

Hello! I'm a graduating Computer Science student, currently taking Thesis. Me and my groupmates would like to gather information in creation of our thesis application. We're looking for any Cybersecurity professionals as our participants.

Please click the link below to participate. This would only take 5-10 minutes. Thank you!
https://forms.gle/7pmWb3tNoaPKDfPQ9

keen warren
#

What is the cheapest certificate?

cunning kelp
# keen warren What is the cheapest certificate?

The Google Cybersecurity Certificate can be completed in the first week (it's a free trial), in about 15-20 hours if you cover it 100%. I did during one Christmas week, between parties and hangovers just for fun. And it's taken seriously by practically nobody. Its only advantage is you get a voucher for $50 off the Sec+, which is only really useful if you complete it in the first, free week and cancel the subscription. Otherwise you'll be paying $50 a month for a completely substandard intro to cybersecurity. This is just a certificate of completion too, not a certification.

The ISC2 CC is frequently offered as a free course/certification package, but the expectation is that, after a year you will start paying for the ISC2 subscription and continue to acquire (and pay for) their further certs, like SSCP, CCSP, all the way up to CISSP

oak shoalBOT
#

Gave +1 Rep to @cunning kelp (current: #17 - 619)

arctic wyvern
#

I am a new teen entering the coding world and this channel makes me wonder about what one can research in this topic .Someone please explain with simple small example

arctic wyvern
#

.

severe steeple
#

Guyss need assistance here what online jobs are you doing to survive in this economy?

potent leaf
#

I'm trying to figure out how to DNS attack my own internet

slow bobcat
iron bone
wispy bridge
cunning kelp
oak shoalBOT
#

Gave +1 Rep to @cunning kelp (current: #17 - 625)

subtle wraith
#

Has anyone had experiences with the Splunk certifications, especially in regards to SOC management and architecture? Worth it?

dusty rune
#

i need a real life example log in json to test a tool. anyone got any sources for that?

twin sand
#

chatgpt?

dusty rune
rotund wing
#

😫

dusty zealot
#

fl0ck have recently popped a number of cameras in my area, and i am looking for ways to capture (ethically) and present vulnerablities to my city council. what are ways I can wardrive and just ingest data outside of wifi pineapple (not that that will work, i think)

#

**for research purposes

verbal coral
dusty zealot
livid osprey
#

Hello guys

#

Please I’m new here

solar horizon
#

hi

twin sand
#

hi

last scarab
#

Hi

peak flower
#

Hello

narrow frost
#

Hi

viral nacelle
#

Hi

opaque obsidian
#

wsp

pallid oar
#

So I was invited to a bsides convention by someone who works in cyber security .. any advice how to prepare

keen warren
#

how to find vulnerability

sly lake
oak shoalBOT
#

Gave +1 Rep to @sly lake (current: #1833 - 3)

rapid sigil
#

Please interact with the community before posting your external posts. @distant steeple

hollow sky
#

does someone where i can find promotion codes for tryhackme payment?

keen warren
#

Can I use promo codes for make premium cheaper

left thorn
#

Yes, you absolutely can! Try ChatGPT. I got somewhere from 30%-40% off. Totaling around ~$45 knocked off. I use it every time for all kinds of related things.

twin sand
#

U had gpt make promo codes?

keen warren
#

No 😂

#

Just wondering

ivory cloak
#

Hey I'm new here

granite lily
#

Hi I am new I want to learn but I don’t know where to start from

granite lily
oak shoalBOT
#

Gave +1 Rep to @sly flume (current: #45 - 263)

neon basin
#

Hey everyone, I've been building an open-source PQC readiness scanner for SOC environments. It scans live endpoints, detects TLS cipher suites that are vulnerable to harvest-now-decrypt-later attacks, and scores them against NIST's new PQC standards (ML-KEM, ML-DSA, SLH-DSA).
Output is SIEM-ready JSON, designed to integrate straight into existing SOC workflows.
Still actively developing it (PCAP analysis coming next). Would love feedback or contributions.
GitHub: https://github.com/surendrababu-sec/pqc-soc-readiness

vital dagger
#

where can i learn manuel scaning vulnarality

#

ik how to use Nessus OpenVas but need to be sure false-postive

stone mica
#

What exactly do you mean?

vital dagger
stone mica
#

Just to make sure we have the same thing in mind

vital dagger
#

How can I manually identify vulnerabilities that I might find when scanning all ports using Nessus?

stone mica
stone mica
vital dagger
stone mica
#

False positives are not rare. For example, let's say you have Tomcat V1. Nessus checks all CVEs for Tomcat V1 and tells you your product is vulnerable to all of them. This is theoretically correct but not necessarily technically correct: some vulnerabilities only apply if your V1 is configured in a certain way. Your version is vulnerable, but exploitation might be impossible if it's not configured in a way that the vulnerability requires. (False positive)

stone mica
vital dagger
#

and where can i learn how to do manually

stone mica
#

It depends, you're talking from a vulnerabilities management perspective (You already have internal access to the company) or from a pentester POV?

vital dagger
#

I am just still learning Vulnerability managment role

stone mica
#

You can use netcat for banner grabbing, owasp zap, burpsuite...and manually try to check all of these

You can use NMAP but without the -sC or --script=vuln parameters or else it becomes pretty automated

#

Curl also works

stone mica
vital dagger
#

voc?

stone mica
#

Vulnerability Operation Center

vital dagger
#

oh ok yeah

#

do you have any video for this

#

or tryhackme room

#

by the way thank you for your time

last scarab
#

Hiii

last scarab
stone mica
oak shoalBOT
#

Gave +1 Rep to @stone mica (current: #20 - 539)

stone mica
keen warren
#

Does tryhackme have internships?

keen warren
oak shoalBOT
#

Gave +1 Rep to @long saffron (current: #248 - 46)

final jewel
#

CIPHER-0x AI Agent detected a potential Zero-Day during advanced Malware Analysis.
In this video, I explain how my AI Agent “CIPHER-0x” autonomously analyzed and inspected malware samples, including a suspicious malware linked to a potential zero-day behavior.
The project combines AI reasoning with malware analysis techniques to automate detection, behavioral inspection, and advanced threat analysis. https://drive.google.com/drive/folders/1GrVo9Y2rMj9MLkTw3kUcgwnWSySb3DIe?usp=drive_link (this is my research )

keen warren
#

How good is ghidra

sly flume
keen warren
oak shoalBOT
#

Gave +1 Rep to @sly flume (current: #42 - 275)

twin sand
placid loom
keen warren
#

Ok thx for information

turbid radish
#

guys

merry venture
keen warren