#resources
1 messages Β· Page 3 of 1
+rep
Gave +1 Rep to @jade shell (current: #3 - 2097)
+rep
Gave +1 Rep to @cyan tundra (current: #29 - 333)
Thanks for the awesome resources
You're welcome!
This is a good resource for ADCS
This site and author has blogs on the major escs and walks through how they work
Metasploit Documentation Penetration Testing Software, Pen Testing Security
View Metasploit Framework Documentation
Also this article going over using metasploit for them. I highly recommend you learn how to do them as manual as possible to actually understand them and donβt forget to do your research on bloodhound to learn how to spot these.
Epic, much appreciated π
@main ether Please don't self promote in this server.
There're courses for that on THM π
Hi!!!
For the people here who have to suffer rote memorisation exams and want to learn stuff which is not easy to put on flashcards, I wrote about methods for memorising things using Anki as a scheduler
You can apply this to many things, for example doing a THM room on a schedule
I suggest against memorising everything and also remember you can always google things.
But if you do find yourself in need of implementing a spaced repetition system for things that aren't flashcards, this works quite well π
https://skerritt.blog/memorising-leetcode-by-using-anki-as-a-scheduler/
^ Memorising keybinds in Anki is really useful to
Hello lads, I am looking to do an online streaming session where I talk about AI and prompt engineering. Any books, articles, THM rooms etc that you can recommend? Please and thank you β€οΈ
Advent of Cyber 2024 Day 18 is about prompt injection π
yes I did that but I was thinking I will go a bit more in detail and even jail break DeepSekk R1 about topics that are censored
@bright osprey Please don't post referal links in this server.
30 day free trial for certmaster: https://www.comptia.org/training/certmaster-learn/trial-sign-up
Are there any discounts or offers for exams too ?
For students yeah you can get a steep discount on their academy store
Please don't self promote. π
Forgive me if this is the wrong channel to query, but does anyone have any recommendations on a room that deals with cookie manipulation? I'm doing my Sec+ course and the subject of cookies came up, and now I have this itch to poke around and learn how you can manipulate and leverage cookies
This one π
https://tryhackme.com/room/jwtsecurity
Thank ya!
for Women in Cyber Security podcast The Cyber Queens (on Youtube, Apple podcasts, etc)
for UK cyber security Smashing Security podcast
What is this?
Chennel where you can share some interesting resources π
Hey can anyone help me get rid of the virtual box turtle
I tried bcdedit /set hypervisorlaunchtype off
Disabled core isolation
I did turned off all the hyper v feature and even check the control pannel
In the task manager virtualization is also enabled
some of the best reverse engineering resources:
https://class.malware.re/
https://0xinfection.github.io/reversing/
https://beginners.re/
https://challenges.re/
https://pwn.college/
https://crackmy.app/
https://crackmes.one/
https://pwnable.kr/
https://guyinatuxedo.github.io/
Go and check whether your bios has enabled visualisation or not
Learn to touch type and improve your typing speed with free interactive typing lessons for all ages. Start your typing practice now!
Hello team, do you have any resources, tools, or software to improve online security and anonymity (OpSec)? I'm looking for solutions to be more anonymous and secure on the internet and in the context of a CTF. Thank you in advance!
check out michael bazzells books
π₯WE'RE OPENING UP THE OFFENSIVE OPS CTF FOR ONE DAY ONLYπ₯
Join in this fun opportunity for some amazing hands-on challenges based on our SANS Offensive Operations courses!
Wednesday, Feb 28 10am - 4pm EST
Details and registration here: https://t.co/oLdFCCTxF9
DLL hijacking and more
I dont know if anyone requested this yet, but would it be possible to install mysql on the parrot os thm attackbox
Try to suggest it in #feedback-and-ideas π
Do you have any cool free resources that talk about analysing portable executables?
Can Anyone help me how to start learning hacking I need a road map to become a pentester and a mentor
You can follow this roadmap π
https://tryhackme.com/hacktivities
Thankyou KGB
Does anyone know a good resource for event filtering/searching on Windows event viewer, I think it was Xpath/XML
Timeline explorer?
Tools for inspecting .csv files
Ohhh
Thanks!
Gave +1 Rep to @jade shell (current: #1 - 4229)
What are you trying to do exactly? You can create custom views and further refine with XML.
Short intro article here https://www.papertrail.com/solution/tips/windows-event-log-filtering-techniques/
A quick search will provide quite a few resources including some vid tutorials.
I'm currently doing the Windows Event Logs & Finding Evil module on HackTheBox Academy, one of the questions requires me to make queries using XML/Xpath.
Also thanks for the article!
Gave +1 Rep to @round orchid (current: #312 - 21)
I'm not too familiar with HTBs format but do they provide any guidance? What exactly are you supposed to be searching for? Perhaps specific event IDs, date range etc via security logs. Feel free to DM if you need some help.
If you're doing HTB content, can you please ask their own server for help.
We don't know their rules of helping etc.
This is also going in accordance with our community rules.
Event IDs or processes. I just needed some articles to give me more insight on how to better perform search queries.
No worries, I don't really need help with the module. I just needed some resource to better further my understanding in search/querying for specific EventID or processes.
For sure I understand. Well the most basic filtering via XML would probably be by log type and event ID. Something like this.
Just replace Path with your desired log type (on both lines) and EventID with the ID you want to filter for. Easy peasy.
Another article that should get you all the way to your desired goal.
https://techcommunity.microsoft.com/blog/askds/advanced-xml-filtering-in-the-windows-event-viewer/399761
feel free to dm if needed
Thanks a ton!
Gave +1 Rep to @round orchid (current: #304 - 22)
Hey
Does anyone know good resources for maldev? Maybe a roadmap?
Maldev is for our advanced channels
Thanks! I'm going for PWPA, is it considered a recognised cert?
Gave +1 Rep to @stuck abyss (current: #2 - 3581)
Check your local job listings, is it required? Β―_(γ)_/Β―
I don't see eCPTx either, but it's listed as a recognized certification in the article
This is a relatively recent certification by TCM Security and with the number of options available, might take a few years to be recognised to the level of OffSec and SANS.
Missing Semester
Thats actually cool
Now its time to spend the day customizing to get ready to do it
Hehehe
Please don't advertise here π
anyone know where i can get a T568A Flag? Lawrencesystems sells one but I'm looking for the whole flag to be color
Welcome to the Damn Vulnerable RESTaurant π
You ordered a new YouTube video, right? π
I recorded myself solving the Damn Vulnerable RESTaurant challenge live π΄
https://youtu.be/CdVTG3aWTew?si=inmuQ6aFZ-Atipel
Play around with the DamnVulnerableRESTaurant yourself: https://github.com/theowni/Damn-Vulnerable-RESTaurant-API-Game
βΆοΈ YouTube: https://www.youtube.com/c/PinkDraconian
π Patreon: https://www.patreon.com/PinkDraconian
π¦ Twitter: https://twitter.com/PinkDraconian
π΅ TikTok: https://www.tiktok.com/@pinkdraconian
βΉοΈ LinkedIn: htt...
https://gralhix.com/ has some really fun and practical challenges
Hey guys, just wanted to share - unfortunately for the french speakers only - a sub free magazine about Cyber I ran into during the InCyber forum last week : https://www.cyberun.net/cyberun. Good stuff, well written and organized. (I have no affiliation to it)
For any chromium users that don't want to see the weekly rank on their dashboard: https://github.com/ASlimeInAHoodie/Anti-Competitive_TryHackMe
Need some SANS advice from y'all.. these are the 4 I'm considering getting, ordered from most desirable to least.
SEC511
SEC573
SEC598
FOR498
This will be my first SANS cert.. any advice on which one to pursue or any other really solid courses I might have missed?
Vencord is against Discord's terms of service, please do not promote it here.
i made a pdf to help me with the soc sims and though i share it. Any inprovments? https://pdflink.to/7ad42fd8/
is there a place i can find all the free SOC resources, cant afford any subscription right now
Here's the list of free THM rooms related to SOC π
https://tryhackme.com/hacktivities/search?page=1&kind=all&searchText=soc&contentSubType=free
you can filter thm rooms by subscription type
but i get lost, like theres one room about something n next one totally different thing
end of the day, i just complete rooms in their individual capacity & have no clue about my overall learning
i havent read this myself, but there might be something of interest to you there https://www.cadosecurity.com/wiki/free-soc-analyst-training-resources
The demand for skilled cybersecurity professionals, especially Security Operations Center (SOC) analysts, has never been higher. With cyber threats growing in complexity and frequency, organizations a
Hey, Anyone with Student Id need Perplexity AI Pro Free 1 Month?
For the defensive security nerds, and offensive security nerds that want to beef there systems:
This a pretty thorough guidelines set for helping with hardening computer systems:
https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/ism/cybersecurity-guidelines/guidelines-system-hardening
Does anyone have good recommendations on Youtube channels and/or podcasts that are both entertaining and useful for learning a thing or two? I have a lot of traditional learning resources but I'd love to find content like storytellers and that sort of thing. Thinking Darknet Diaries and stuff along that line. Any ideas?
2 YouTube channels:
mental outlaw
Tech with jono
Mental outlaw is great to catch up whatβs new/interesting to learn and from time to time shows hands on tutorials
Tech with jono is very good at giving a visual aid in showing what he does as a SOC analyst
Awesome, thanks for the suggestions! I already do watch Mental Outlaw from time to time but hadn't heard of Tech with Jono. I'll definitely give it a look!
hi there. Any good study materials ( video will be nice) about active directory?
There's multiple rooms on THM about it
I'll also look for some videos you can use
One minute
Learn why Kerberoasting is still such a popular attack vector, explore relevant data sources, and uncover visibility gaps by way of Atomic Red Team
"Kerberoasting" was first identified by Tim Medin, CEO of @RedSiege, nearly a decade ago, but Conti and other ransomware groups are reportedly leveraging it as part of their modern-day playbook.
We...
I'm doing a CTF (not on THM), and I need to escalate my privileges in Linux. Linpeas flagged /proc mounted. However, I don't know how to exploit that to escalate my privileges.
Any resource that could help me with that is welcome
Which CTF are you doing?
It is a school challenge, so I doubt it is publicly available. I completed the linprivesc room on THM, but it doesn't cover privilege escalation related to the Docker container.
I also found this as a suggested reading, but I'm still unsure how to approach it https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation/sensitive-mounts.html
We can't assist with this then, sorry.
What would y'all recommend when you're trying hard to study but can't seem to keep your mind focused? I've tried total silence, calm music quietly playing, drinking tea (I do that either way), really struggling to focus today though. Just curious if anyone has some tips to help in cases like that
howdy peepz. I made a little site putting my notes online here https://pwnpedia.com/
let me know if you think it's cool or if you think there's anything else I should add or take away! happy hacking friends!
Great name and really cool idea imo. At the very least as a repository for your own reference but I could see people using it for sure.
I wouldn't change the simplicity of the functionality. It's great the way it is in my opinion.
Cool thing is you can keep adding as you go.
hell yeah! thank you!
@topaz gulch i read "elf door" and suffered some flashbacks
Elf didn't bother with doors. He just walked through the wall leaving elf shaped holes in his wake
It's a project I did some time ago
And when he walked out, somehow, the machine mysteriously begins to shred itself....
inside joke 
Stg that boy was a cyber weapon of mass destruction
You can keep your ransomware. I'll just send in my Elf
Lol, weird...
Where is elf?
vmlinuz-$(uname -r)
Hello, I wanted to get into developing rooms (Web app pentesting) for TryHackMe, where should I start?
Follow simple steps to create, manage, and share your room.
Hot off the press. Fact sheet for MITRE's AADAPT framework. Pretty cool.
https://www.mitre.org/news-insights/fact-sheet/aadapt-cyber-threat-framework-digital-assets
Hey guys need some good resources for Blockchain pentesting
i came across cryptozombies and ethernaut, also i saw some machines on HTB
my issue is i dont understand whats happening in these challenges
i would like to know if there are any free course/resources
IT people, do you know about proxy tunneling? Proxy strings... threading? Where you line up like 9 proxy IPs to hide your own.
Any videos, tutorials or resources to help would be appreciated π€Ί
I know networkchuck has a good vid on proxy chaining
Not a "direct" resource, but I just found a free demo on Steam for a pretty good hacking game. It's pretty barebones but it gives an introduction to some industry standard tools while providing a ctf-esque environment to practice in
It's called HackHub
Not to be confused with a game by the same name on Itch
I have installed neo4j and bloodhound, once i start both services, i use neo4j credential to login to bloodhound, but it says login failed?
anyone know how to configure it properly?, In bloodhound interface it asks for Email Address and Password instead of username, bolt url, password
Explore vim.rtorr.com for an extensive Vim cheat sheet, offering clear, concise commands and shortcuts for Vim users. Whether you're a beginner or an experienced developer, find tips and tricks to enhance your coding efficiency in Vim.
smoking his lungs out and
every os possible
https://niccs.cisa.gov/tools/cyber-career-pathways-tool
This is a good website too
National Initiative for Cybersecurity Careers and Studies
https://www.youtube.com/watch?v=uTAaFExLgwQ
This is good too
Start your IT Path with ITProTV: https://ntck.co/itprotv (30% off FOREVER) *affiliate link
Are you wanting to get started in IT in 2023? Do you want to become a Hacker? A Network Engineer? Cloud Engineer? System Administrator? In this video, NetworkChuck will show you the path to getting started in IT and Cybersecurity that will help you rea...
It's still advertising, please don't do it here.
i wonder how they solved the problem with all the telemetry going back to MS
Ah nevermind, that was for something else from before. Nevermind
Does tryhackme have any OSINT type modules or does anyone know any other good resources for OSINT related things
Yeah, there are some OSINT rooms, this is one of them that i can remember off the top of my head: https://tryhackme.com/room/ohsint
Hello guys my name is Vibhas and I am 3rd year Cybersecurity student so i have made obfuscation tool name as ObfusEngine i would love if you guy use this tool and give some Feedback and this is my first time making a tool:
https://medium.com/@vibhasdutta11/why-i-built-obfusengine-3ede602b81f4
Whats that tool do
Can you tell me here
Did anyone else struggle with the pre-security area of the THM website? I'm struggling digesting the material. Can you guys recommend me some resources that found that helped you process the information? Preferably visual if there is one.
What's the problem exactly ? Try to reach out in #pre-security-legacy-path channel if you need any help with the path π .
This isnβt a place for self promotion and must be resources, not links to music
No clue how many of these overlap :hanashrug:
https://github.com/jivoi/awesome-osint
https://github.com/Astrosp/Awesome-OSINT-For-Everything
https://github.com/cipher387/API-s-for-OSINT
https://bskythreadreader.glitch.me/#/
https://www.tineye.com/
https://cybdetective.com/osintmap/
https://github.com/thehappydinoa/awesome-censys-queries
That's most of all I have
Thanks!
Ill try most of em out
Always appriciate a little help in OSINT
why does he change the language between English and Hindi π
Hinglish ππ btw english subs are in it
Post more, and Iβll sub.
Sure brother
wtf is hinglish
a mix of hindi and english?
why would he speak that way
the indians that dont speak english wont be able to understand 100% of it and the english speakers who dont speak hindi wont be able to understand 100% of it ;/
Totally valid point, but Hinglish is actually the most natural way a huge part of the Indian communicates, especially in tech.
@tight jungle Please keep this channel for resources and avoid self promotion
if you wanna drop all ip's that have tried to brute your box
journalctl -u ssh | grep 'Failed password' | awk '{print $(NF-3)}' | sort -u | while read ip; do iptables -C INPUT -s "$ip" -j DROP 2>/dev/null || iptables -I INPUT -s "$ip" -j DROP && echo "Dropped $ip"; done
I don't know if this counts as resource serarching but im starting my cybersec school soon and they asked me to buy a laptop that had rtx 2060 or higher. Now if it was my choice i'd just go for a thinkpad T-series but no gpu. So i have couple of laptops in my list, any recommendations are welcome : 1. Lenovo Legion 5 2. Thinkpad T14 gen 3 (lack of gpu) 3. HP Omen 16-c0600nz . I was also thinking the ones that are specifically designed for pentesting but they somehow also lack GPU other than ones that cost alot.
Definitely get a decent gpu, you'll want it for tools like hashcat and John. Lenovo has a good rep for playing nice with Linux.
Thanks for your reply. I see from most replies and searches that legion 5 is pretty good. Im also considering P-series ThinkPads with strong GPUs.
Gave +1 Rep to @worldly palm (current: #1463 - 3)
I've seen some comments disliking the keyboard on the Legion so you might like to check whether it will suit you for typing assignments. (not a deal breaker imho, you can always add an external keyboard).
Honestly couldn't care Less about it since I use stenography
ah k.
Thanks for the info tho.
0xMatheuZ
Learn how to bypass modern defenses with io_uring
hey do you guys have any recommended youtube playlist or resources to learn proper impacket usage? and methodology based things?
The best thing I found to help me with impacket is the github documentation.
hey im sorry im new to github i cannot find the documentaion? i did google around too
You have to click on the examples folder, then you'll get a lot of impacket scripts. Click on any of them, you'll see the code.
At the beginning of the code are 4 lines ish that tells you exactly what it does.
oh yes i found them thank you!!
Learn about bloodhound, its installation, about ingestors and usage. Mapping attack paths with bloodhound.
Iβm an Indian student pursuing a BTech in Computer Science and currently relying on an education loan. Iβm really interested in cybersecurity, specifically Red Teaming, and want to earn industry-recognized certifications. However, due to financial constraints, Iβm unsure which certifications to focus on. Can someone help me with any advice on affordable yet credible options.
hey is anyone a hacker
Yes, what for?
No promotions in here please. π
i use that one a lot
this gitbrew organisation seems to be compromised
just tried to visit it and it gave me the fake cloudflare verification phish
HI everyone I need lots of essential combos in brazil governments, educations and medicals. I can pay it with your comfortable demands.
what?
why?
you do not need to know it anyway i can afford to pay for them if they are accurate.
lmao automodded
what is this dude on about
An essential combo
bro use google translate please
oh they might mean combo lists
I was thinking the same
π
you need to verify to embed
@shut ferry
π too boring
do that ^
i sent a report lol
omg meee
:hammer: blackadamas__#0 has been banned.
404
Self promotion is not allowed in here and please do not promote this everywhere.
Anyone wanting to do the EJPT exam itβs on sale. EJPT exam voucher and 3 months of prep for 125 dollar.
This looks super cool
It'll definitely make my notes shorter not having to write down tool syntax 
Hello
Hey folks
Anyone got good resources (blogs/writeups/cheatsheets) on:
β’ PHP upload bypass
β’ PHP reverse shells
Working on THMβs Root Me and would love some study material.
Thanks a ton
Not blogs, but for PHP reverse shells, you can check out GTFOBins.
https://gtfobins.github.io/gtfobins/php/
Check this resource π
https://tryhackme.com/room/uploadvulns
Anyone here prepping for Python basics / Security+ / THM modules / AZ-900 and wants to form a beginner study group?
Please don't spam the same message across multiple channels , bot may automatically mute you for that
Thanks a ton !
Ok, so if you want to learn to use OpenUSD here's 2 ways to do it. https://www.youtube.com/playlist?list=PL3jK4xNnlCVcae9UrxpVWyFw63QCFA6JA is the Video's, and https://www.nvidia.com/en-us/learn/learning-path/openusd/?ncid=em-prom-338923&nvweb_e=lJODT593j9w2yguzju_bEA2Aza5yS211RIr2IB13Z0vGlCEPqmt01Ec54mPD8ga2lEIw0xTXCuxd9vN1No--4g&mkt_tok=MTU2LU9GTi03NDIAAAGb9gXmA_qkLbVGeNnZTHtotIt9g3anL0BDziQts-DNtjQk1ID-R808ILCafl378fl3pWStbOFXTqN13KZHwQkMJAPxOxGZruA8MuqM2NM76BQYEbDbKKU0iAguoDvzn08 is the course's which might have videos too, I am not sure yet.
Though it might not exactly be something to do with Cyber Security, remember that learning all different things can always come in handy sometimes, especially when it might have to do with security for code or other programs.
They also do offer an exam for Certification, so look it up if you finish the courses and want the certification. Not sure of the price though.
This would've been useful for a certain industrial instruction CTF challenge
Yes true
This is relatively useful but I find the name misleading π
Hahaha βautomatedβ π
It's not that, it makes it sound like it's some sort of useless nmap script π€£ probably something like "AutoEnum" would be better
Yes true. That name would be better.
Itβs indeed an AutoEnum tool.
https://github.com/pikpikcu/Pentest-Tools-Framework
I found this aswell have not tested it yet.
If you are into physical security, check this out!
https://www.stingrai.io/blog/build-clone-defend-long-range-rfid-attacks-explained
Tired of looking for cyber tools all the time:
https://tools.chateauforge.com
Thanks looks nice.
Gave +1 Rep to @vital snow (current: #3072 - 1)
Hello everyone
Hi Does anyone have a notion AI subscription?
Hey does anybody have any recommendations or resources for learning AWS quickly?
AWS Skill Builder
Thank you!
Gave +1 Rep to @jade shell (current: #1 - 5833)
Udemy course
Hello, sorry but advertisement is not allowed in here.
@slim kiln Let's hang well we knock out these out and learn
Does anyone have any cyber news podcast recommendations? I tried CyberWire Daily, but the guys voice sounds like a tiktok voice filter. Can't cope.
Preferably uk based
DarkNet diaries maybe
mod this is advertisement
Nah it's real lol
Is there kleopatra for windows? I want to practice pgp
Not anymore. It was free initially as a new launch offee
I've removed it
Is this what you are looking for?
https://gpg4win.org/
If i want to study for CompTia would the security+ SYO-601 be the best book option?
No! The 601 series has been retired... the current test is the 701, and there is enough difference that it definitely matters.
Ahh okay thank you!
Gave +1 Rep to @vocal fjord (current: #3092 - 1)
No worries... Just got mine a few weeks back. Good luck!!
Congratulations and thank you!
Gave +1 Rep to @vocal fjord (current: #2035 - 2)
@prisma bison can help you
:hammer: anonymous_player45_02076#0 has been banned.
Pgp
Like pgp keys
sorry
Okay, there's something called PGP tool https://pgptool.github.io/
I've not used this. Check if it meets your requirements.
PGP for Windows, MacOS and linux. Desktop application to encrypt and decrypt PGP files. It's free and easy to use. OpenPGP compatible.
thanks
Gave +1 Rep to @ripe adder (current: #1238 - 4)
Greetings all! Iβm Havoc, based in New Zealand.
Iβm here to connect with mentors, peers on similar learning paths, and people who share my values. Iβm starting with OSINT and plan to follow a cybersecurity learning pathβunless mentors suggest a better direction.
My goal is to use these skills for humanitarian causes I care deeply about, such as countering human trafficking and promoting child safety. If youβre already working in this space, Iβd be grateful for any advice on the best pathways to follow.
I work full-time and can dedicate around 16 hours a week to learning. Once Iβve built up my skills, Iβm committed to giving back by mentoring others.
If youβre on the same path and want to collaborateβor if youβre experienced, share my values and want to clone yourself in me to amplify your impactβhit me up!
Hello I am looking for a mentor and someone to help me on my journey to become a pentester, it would be great anyone can message me and I'm ready to learn like a padawan
If you wish to be a pen tester, i would suggest reading the hacking exposed books as a baseline, old but relevant. Then try the junior pen tester path, learn linux (virtualbox + kali), python, study owasp guides and VMs plus ensure you have a good under standing of basic networking, services and web technologies.
GitHub
Linux-like PowerShell Core Profile. Contribute to CrazyWolf13/unix-pwsh development by creating an account on GitHub.
Very cool website for beginners in Linux.
https://explainshell.com/
It explains what each part of a command does.
For example if you find a Linux command in tryhackme and you will understand what each switch and each part does exactly.
is there any blog or github repo for free Reverse engineering tools ? Anyone to follow for methods to solve ctf challenges related to RE ?
https://malwareunicorn.org/#/. This might be helpful
Hey everyone! π
Iβm currently diving into C and Assembly to get a deeper understanding of hardware-level attack techniques. On TryHackMe, my plan so far is:
x86 Architecture Overviewβ
x86 Assembly Crash Course (almost done)
Buffer Overflow Prep
Buffer Overflows
Sudo Buffer Overflow
NoNameCTF
Binary Heaven
Are there any other THM modules youβd recommend for learning more about low-level exploitation? I know thereβs a lot to explore and I want to make sure I donβt miss any essential content.
I have recommendations but they aren't on THM, check out open security training 2's courses on x86 and by vulnerabilities
I'm not sure if I am asking in the right place. but I need to decrypt a SHA256 Hash. I hit a dead end. this is my bash: 2025-09-05 00:14:25 [INFO] Decrypting secrets.enc
Passphrase (no echo):
2025-09-05 00:15:47 [ERROR] Decryption failed: [Errno 2] No such file or directory: 'secrets.enc'
this is the part of the code that has the passphrase info : def derive_key(passphrase: str, salt: bytes) -> bytes: log("DEBUG", f"Deriving key with PBKDF2 iterations={PBKDF2_ITERS} salt={salt.hex()}") key = PBKDF2(passphrase.encode("utf-8"), salt, dkLen=KEY_LEN, count=PBKDF2_ITERS, hmac_hash_module=SHA256) log("DEBUG", f"Derived key {key.hex()[:32]}...") return key
I hope someone reaches out. i can give more info. i reached out to some well known Hackers only to be Ghosted. hey, i aint mad at them.
Thanks, I will check out!
Gave +1 Rep to @nova loom (current: #203 - 48)
https://github.com/zahidaz/jezail
Jezail is a powerful, all-in-one Android application that runs entirely on your rooted device, transforming it into a comprehensive security testing and device management platform.
whats the sha256 hash
No promos in here.
Where is a good place to leaen python coding?
top udemy courses are fine
whats your exp level
None. Want to learn python cause im doing cybersec101 moving into pen testing.
yeah top udemy courses are fine then
never ever buy a non-discounted course there
they should be 20 bucks max, more like 10
freeCodeCamp
please dont spend anything here, you don't need to
Udemy courses aren't the most reliable either
A Page in : Automate the Boring Stuff with Python
edX
You can learn computer science with Harvard experts. Sign up for Harvard CS50 on edX today and gain foundational computer science knowledge on your schedule.
YouTube
Welcome to my Channel. This channel is focused on creating tutorials and walkthroughs for software developers, programmers, and engineers. We cover topics for all different skill levels, so whether you are a beginner or have many years of experience, this channel will have something for you.
We've already released a wide variety of videos on to...
I am quite happy with the Udemy courses I did so far
I would recommend them
I am sure there are also bad ones
I am however not convinced by things like freecodecamp
These resources are all free, include multiple different forms of learning and are wholly recommended by the python community
I'm glad, but you don't need to spend any money when better options exist for free
I would need to take a closer look at them to make that assessment
But I'm sure if you make this recommendation they are a good choice
https://github.com/Kurumizaki/kurumi Autofix Wifi Adapter TPLINK ,Atheros Driver
Does anyone know of any learning resources that teach specifically IDORs? All content I've been able to find is too superficial, I'd like something in-depth
.
That's not much of a "deep" topic. There're two walkthroughs on THM about IDOR you can check them out , also check out Access Control and Business logic vulns. section on PortSwigger's WebSecurity Academy
Here are some of my recent articles:
Do give them a read Iβd love to hear your overview and perspective on how these approaches resonate with todayβs CTEM priorities.
Hi, I just completed the web application roadmap and I was wondering if there would be a list where there would be all the rooms related to web vulnerabilities thanks
I've developed bloodyAD-mcp (Model Context Protocol), a personal project aimed at simplifying Active Directory interactions for cybersecurity tasks.
The core idea is to enable control of bloodyAD (a powerful AD tool) via natural language, using AI assistants like Gemini-CLI or Claude Desktop. bloodyAD-mcp acts as a secure Docker container wrappe...
.
hi everyone,
So I am learning about networking. I have learned all the concepts like IP, MAC, the OSI/TCP-IP layers, DNS, routing, NAT, and different protocols. But I am still confused about how everything works together. I mean, how does each part play its role, and how does it all come together in practice?
is there any resource that can help me understand that?
I found these two YouTube channels to be very helpful when I was in my "Intro to Networking" class in my CS degree:
YouTube
If youβve been in the Network Engineering career field for any small amount of time, then youβve probably been frustrated at how difficult it was to find articles and videos that were reliable, thorough, and understandable.
You found articles that were very entry level, that perhaps gave simple definitions but did not communicate enough to ...
0xH3G4Z1
Hash length-extension attacks explained: why they work, how attackers automate them
Hi everyone!
Iβm really interested in learning ethical hacking and penetration testing, but Iβm not sure where to start. I want to build a strong foundation and learn the right way.
Could anyone here share:
- A recommended roadmap or learning path for beginners?
- Essential resources (books, courses, labs, or YouTube channels)?
- Any communities or platforms where I can practice safely ?
Iβd appreciate any advice or guidance you can offer. Thanks in advance!
https://tryhackme.com/hacktivites for the roadmap.
Get the hell out of here scammer
Thank you man
Gave +1 Rep to @tough kindle (current: #25 - 404)
Hi, can any one suggest me how can I practice networking
cisco netacademy, you have free courses over there. If you want to learn first I would advise to use someone like professor messer on youtube π
Like for application
Its pretty depressing when you can only access the intro part of the rooms and then you have to learn the rest from Indian teachers on YouTube π
Welcome to pentesting. Those who are successful are those who love learning.
You will be spending quite a bit of time researching and learning new things throughout your career.

Hi, can any one suggest me how can I practice networking
Any mobile apps yall have for learning resources/tools, any that is related to cybersec or any that helps you in learning generally?
No advertisement in here please.
Yep, your own. ;D
Hey Brothers
is there anyone from Pakistan ?
also i just found out a site , Learning Treasure for begginers (Its not any promotion )
No promotions in here. Read the rules.
its my project but its also a resource tho for developers
Does anyone have a good book/resource on secure SDLC, looking for scalable ideas, tooling, best practices that they can reccomned. Most of the stuff I'm finding is pretty entry level or expensive? I'm fine with it being expensive as long as it's worth it
Like for application
Discord / THM recruitment message
Hey β Iβm Lone Wolf, learning THM (web & pentesting). Looking for 1β2 motivated people for daily 1β2 hour lab sprints & write-up exchange (remote). If youβre consistent, reply and letβs set a trial 3-day sprint.
Where are you going and how would you do this?
GitHub
A structured 90-day cybersecurity study plan for beginners (2025). Covers certifications (Network+, Security+), Linux, Python, Wireshark, Git, ELK, cloud security, and ethical hacking. Includes han...
This full-length course is an introduction to cybersecurity for technical and non-technical audiences alike. You'll learn how to secure your accounts, data, systems, and software against todayβs threats and how to recognize and evaluate tomorrowβs as well, both at home and at work. Learn how to preserve your own privacy. Learn to view cybers...
This guy is great, I watched his intro for programming which helped me immensely, thanks for sharing
Gave +1 Rep to @teal breach (current: #260 - 36)
New blog drop for quick tech learning: https://chandsk03.github.io/blog/ β clean notes, tutorials, and updates for students and self-learners. Save it, share it, and send feedback to help improve!
Here's a packer I made in rust that allows you to mix-and-match and create your own payload execution chains.
https://github.com/brightio/penelope
Imo the best shell handler, it auto stabilize the shell, you can easily upload or download files from the machine, comes with some scripts like a background linpeas etc, (allowed in Oscp without the linpeas usage)
you can use the linpeas part in OSCP
Fr? Oh yeah because it isn't an "auto exploitation" script but an "auto enumeration" one?
yes, its just enumeration
Ic ic ty!
linpeas you can use, but smart shell handlers like penelope and pwncat seem to be in a gray area (or so my research says)
penelope absolutely fine
Avoid massively promoting please.
It's nice. Is the application open source or closed source?
Hi can I hack this
Your application is good. Explains commands very well by breaking it down.
If it was open source I just wanted to see how you have implemented it.
Does this use a LLM?
Ok my feedback would be: take it down, remove the client side gemini API request (have it be done server side), reset your API token and then put it back up
Your google API token is leaked
Literally just open the devtools and make a rqeuest
Hi everyone where can I get an OTA app
Please i am in need of a study mate, please someone serious.
Learn about the history of the Internet. In this course you will learn how the Internet was created, who created it, and how it works. Along the way you will meet many of the innovators who developed the Internet and Web technologies that we use today.
π Course website: https://ihts.pr4e.com/
βοΈ Dr. Charles Severance developed this cour...
what about its auto persistence feature
A Page in : Automate the Boring Stuff with Python
same guy as the internet history video, this was how i learned to program;
its aged like fine wine imo and its 100% free;
there are lots of videos on youtube as well that help teach this stuff;
A Page in : 3rd Edition
there's also 3 editions, make sure to read the 3rd edition as it is the most up to date and also free;
Does anyone know where I can find the full question set for the boss of the soc challenge? The whole set, not just the ones on the thm lab
Does any one know how can I prepare for cnsp exam or matterial for it
Hello
I would like to practise web vulnerabilities (client and server)
Do you have any boxes to recommend that are purely practical and not based on a CVE, etc...?
OWASP Juice Shop?
https://github.com/0x90n/InfoSec-Black-Friday
https://github.com/wwwiesel/InfoSec-Black-Friday
Some deals might be overlapping
Thank you so much @simple creek !
Gave +1 Rep to @simple creek (current: #973 - 6)
This video captures the baby animals and the wild when they are young. you will find relaxation with the peaceful music and the cuteness of the comforting animals, a healing video.
Some of the baby animals I had to go to the zoo because they are very rare, you can't even meet in the wild like red bears and pandas.. I also bought some footage of...
for when you need a break from stress;
goat 
Iβm waiting until this Friday to get the subscription for THM. In the meantime, does anyone recommend or have any resources they could share to me for me to learn more about the Network/Lan or the Lenox modules that are in the pre-security section?
Are you using HTB and PicoCTF?
In this video I go over shell tricks to manage your files more effectively on Linux.
My merch is available at
https://based.win/
Subscribe to me on Odysee.com
https://odysee.com/@AlphaNerd:8
βΏπ°π΅π²Help Support the Channel by Donating Cryptoπ²π΅π°βΏ
Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjY...
Learn Git and GitHub from scratch with clear examples, real workflows, branching, merging, stashing, rebase, pull requests, and more. Perfect for beginners who want strong foundations.
πResources
π Git/GitHub Cheatsheet - https://www.facebook.com/share/p/17sW4f865u/
π logicBase Labs YouTube Channel - https://youtube.com/@logicBaseLabs
...
git is probably the most important tool you will learn in almost any area of tech and one area i think everyone should learn regardless of cyber or dev work or even just wanting to write poetry;
having version control on my documents has saved me far too many times to count;
In this episode, we are breaking down something every hunter needs but almost nobody masters: writing a bug bounty report that gets accepted fast. You can find a real vulnerability, even a critical one, and still get rejected if your report is unclear or missing key proof.
In this video, I will show you the exact structure I use to write clean a...
Iβm not too exactly sure to be honest..
AdPeek is a small Python tool for extracting useful information from Active Directory over LDAP. It focuses on fast enumeration and identifying misconfigured ACL paths without requiring a database or GUI (Poor man's bloodhound-ce).
https://github.com/0xUnd3adBeef/AdPeek
Hey guyss , im currently trying to find any good recourse for some projects/virtual home labs and such focused on blue stuff that is worth putting on my CV trying to build my portfolio, if you guys know any projects guides like these or any recommendations will help a lot and thankss
Stanford, The Modern Software Dev
- Open syllabus (can view slides, etc.)
- https://themodernsoftware.dev/
A four hour compilation of nine original hacking documentaries, exploring the world of state-sponsored hacking, cybercrime and events that shaped the cyberspace to the point of no return.
π― Subscribe to @cybernews for more hacking documentaries, tech innovation and the latest in cybersecurity: https://cnews.link/subscribe/
π¬ Stay connect...
To win the giveaway:
LinkedIn post: https://www.linkedin.com/posts/abedhamdan_heres-a-giveaway-from-one-of-my-favourite-activity-7399209845511602176-x4v0
Letsdefend:
https://app.letsdefend.io/pricing
Letsdefend SIEM Engineer Pathway:
https://app.letsdefend.io/path/siem-engineer-career-path
Letsdefend SOC Monitoring Simulation:
https://app.le...
https://m.youtube.com/watch?v=CWtLdR2SxNY
This is a good collection too;
Use βunixguyβ coupon code at http://nordpass.com/unixguy to get NordPass Business with a 20% off! The coupon applies to all new Business plans.
To follow through, download the FREE Cyber Security Resume/CV references in the video: https://unixguy.com/free
Start a non-Technical Cyber Security Career! Get lifetime access to GRC Mastery Train...
passing along from one of my co-workers. intro to advanced bash shell scripting, free course
gm
Hintfo, a free metadata viewer: https://hintfo.com/
FotoForensics, a free forensic analysis tool for photos: https://fotoforensics.com/
hintfo: Hidden hint information metadata viewer
For students: HackTheBox is doing a holiday CTF on December 19-21 if anyone is interested:
https://ctf.hackthebox.com/event/details/university-ctf-2025-tinsel-trouble-2993
HTB - Capture The Flag
Play the University CTF 2025: Tinsel Trouble event on the Hack The Box CTF Platform. <div><strong>π Grand Legend β </strong><strong><em>The Tinsel Trouble of Tinselwick<br></em></strong><br></div><div><strong>In the snow-glittered village of Tinselwick</strong>, where peppermint chimneys puff cinnamon steam and toy trains zip between roofto...
I'm breaking down the ultimate list of Bug Bounty Hunting Tools from A to Z! Based on the incredible GitHub repository by 0xKayala, this video covers everything you need to know about the essential software for finding bugs and earning bounties.
Hello Hackers, Developers!
Welcome To Hacker Joe Channel. Joe is here, I'm all about helping you t...
In this episode of Weekly Purple Team, we explore a vulnerability in Microsoft's ms-photos URI scheme that allows attackers to leak NTLMv2-SSP hashes directly from web browsers with just one click. Although reported, Microsoft did not recognize it as a vulnerability, and no CVE was issued.
π΄ RED TEAM PERSPECTIVE:
Watch as we demonstrate how ...
Hello group,
Iβm looking for someone experienced in ethical hacking or cybersecurity whoβs willing to teach or mentor me for free. Iβm a beginner, motivated, and interested in learning the right and legal way. Any help or guidance is appreciated.
Can you stop spamming ?
Okay
Tool for remote Windows system reconnaissance and data collection using the Windows Remote Management (WinRM) protocol.
https://github.com/on-em/homerdump
Can someone give me a roadmap for ethical hacking
Thanks you soo much
Improve your cybersecurity and Linux skills by solving challenges in the Bandit Wargame from OverTheWire. This video is a walk through of how to solve the challengesβbut make sure to try each on your own before watching the solution!
π Start the game here: https://overthewire.org/wargames/bandit/
βοΈ Tutorial from Sabyasachi Paul. Chec...
kinda useless, looks like AI generated code
Project to Make Windows Powershell Cool
https://github.com/uzairshahidgithub/ZSH-Integration-for-Windows-Powershell.git
good discussion on wordlists https://youtu.be/qXfSZrDtehI?si=xVH-OyRfUWgpHf6G
I'm Neha Khatri .. and a beginner in the field of Cyber security
i have seen roadmaps alot and everywhere the starting point is Cover IT fundamentals
can anyone please guide me any recourse of this ?
The resources in this would help ... do read the entire article though... helps a lot https://dfirmadness.com/getting-into-infosec/the-five-pillars/
if you ever have a path traversal/file read exploit and find yourself lost in what files to find or just find yourself within a lowkey CMS - this tool allows you to input the framework, web server running, OS and users in /etc/passwd and will generate a wordlist you can use to FUZZ for high priority files depending on your context -> https://pwnbase.org/helpers/file-read
Pwnbase
Community-driven platform for security tools, CTF writeups, penetration testing techniques, and collaboration. Free security resources for OSCP students and security researchers.
is that a cfmoto 675 sr r?? sorry for being off topic π
Yes it is haha
is it yours? can I dm for some info about it?
its mine and yeah sure
what's the really real paid website that really teach u everything and better than the others , paid recources for learn the real hack not just commands like metasploit...)
Hey everyone, I wrote a guide on web app pentesting methodology for 2026. Would love feedback from experienced pentesters here to improve it.
https://karrab7.com/articles/Pentest-Methodology-in-2026-Web-Apps
so good i like it
give the free rooms of pre-security path in tryhackme a try, they go over stuff about the field and you can see what is considered the fundamentals as well
https://youtu.be/c3Cn4xYfxJY
On @faint sluice 's recommendation (ty kindly!), going to be taking this course since not only does it teach aws cloud in detail, but more importantly it has lots of practical labs i can use as portfolio projects;
Prepare for the AWS Certified Solutions Architect - Associate certification and pass! Certify your knowledge and skills in AWS technology, across a wide range of AWS services.
βοΈ Course developed by Andrew Brown of ExamPro. @ExamProChannel
βοΈ Contents βοΈ
0:00:00 Introduction
0:34:47 Setup
0:52:38 Amazon S3
10:52:02 AWS API
12:19:...
I love Andrew Brown
Are there any good articles or blog sites where we can read different type of vulnerabilities and how we can actually replicate them step by step?
When I do a pentesting on an application, I am having difficulty to figure out when to do what so I feel that learning about attacks and how to perform them will eventually help me have a broader perspective and would help me in doing pentesting properly. Is it a right approach?
you wonβt get far with only frameworks like MITRE, CWE, and CVE; you need real hands-on experience to actually get better. what separates the skilled from the unskilled is the ability to not just see an application, but understand it; and know which vulnerabilities are likely to apply so you can save time, set focus, and find issues that others simply wonβt
I wouldnβt say there are necessarily specific blogs you can read to immediately get better, but my best advice is using PortSwigger Web Security Academy and other exploitation-focused CTFs/labs, and reading HackerOne Hacktivity posts along with things like NCC Groups reports and PortSwigger blogs and just overall gain more experience
Ohk, thank you so much for your detailed replyπ . I will try doing just as you mentionedπ
Gave +1 Rep to @tall condor (current: #70 - 150)
any one from india
Sorry can you help me VPN is not working I tried everything
paste your console in #site-support
Iβve created ShadowHorn, an open-source OSINT & threat intelligence platform.
It gathers data from social media, code repos, and breaches, then uses AI to correlate everything into graphs and reports.
If anyone wants to contribute or collaborate, youβre most welcome!
appreciate ur tool π
Thank you
Gave +1 Rep to @serene jay (current: #202 - 51)
Yes
Is there anyone who can help me to get a better start in cyber security career for red team pentenstester
Pls guide me in depth with certificatation
Bro tell me in depth and in full details
Help me buddy
Guide me
No one is going to do it for you. Use any search engine, you have plethora of tools and resources available online including LLMs. Duh, even searching this Discord server will give you a lot of information.
A Page in : Automate the Boring Stuff with Python
Buddy tell me your search engine name and other information about it
How can I start tell me in depth step by step
did you read it?
What
did you read #start-here
0:00 - Introduction
4:12 - Installing VMWare or VirtualBox
10:27 - Installing Linux
16:00 - Configuring VirtualBox
19:15 - Kali Linux Overview
22:45 - Sudo Overview
27:58 - Navigating the File System
46:10 - Users and Privileges
1:03:05 - Common Network Commands
1:11:32 - Viewing, Creating, and Editing Files
1:17:54 - Starting and Stopping Servi...
Yes I read it but I don't know about how to discord
did you sign up to tryhackme.com?
Its a link, click #start-here ;
What's next
Tell me all steps
I have joined the community of try hack me
it literally lists the steps in that link. have you signed up to the website tryhcakme.com?
If I can massage on this community then it clearifies that I have sign up
no. the website is separate from the discord. this is explained in the link #start-here
Ohh
I got it
What should I have to do after sign up in try hack me
im done. its clear you still havent read #start-here
I am going to read it
And thanks for the help buddy
Hello team!
I've created a course on learning Linux. It's a beginner's course designed to give you the skills you need to get started in Cybersecurity or DevOps/Sysadmin. So I'm looking for people to critique my course π
. FYI, each chapter is linked to a Google form. You can also DM me with your feedback.
Course link: https://github.com/N0vachr0n0/Hands-on-Linux-course
Arigatoooo ππΎββοΈ
@stuck abyss
Heyy guys today i got the Advent of Cyber rewards and i have got 75$ voucher but i am not able to utilize it cause i already have the premium so if anyone wants it .
Dm me .
Dm
Done!
is sharing your stuff alllowed here?
I think π
you gotta get me banned if i send something here π
I'm not the admin π
We are in the resources zone and I see others share public or private resources
and it does look great! the course. will def check it out in detail
I'm looking for guys to help me improve my course
Maybe It's not very good for starter and I don't know π
Thanks
I'm waiting for your feedback
Gave +1 Rep to @inland ore (current: #3550 - 1)
i have exam from tomorrow, i should not be even here! but i will let you know later.
Hii guys I want to learn free el ethical hacking h from basic , anyone have idea Abt free alternative. ?? Plz DM and reply me..
Hello, could someone help me with aireplay-ng and airodump-ng?
Here is my command with airmon-ng:
airmon-ng -b a wlan0
Then when I select a channel with airodump:
airodump-ng -c 1 --bssid XX:XX:XX:XX:XX:XX wlan0mon
Problem: as soon as I fix the channel, my card automatically switches back to 2.4 GHz (I can see it with iwconfig), while the target is in 5 GHz.
Then, when I try a deauth attack with aireplay-ng or with reaver, nothing happens.
I specify that:
the interface is correctly in monitor mode
the target is on 5 GHz
but the channel selection seems to force it back to 2.4 GHz
If anyone has an idea
Hey! I've been creating free educational content on cybersecurity topics, especially** Windows privilege escalation** these days. I make these for my own learning journey.
Saw the warning about self-promotion and don't want to violate any rules, so if anyone's interested I can DM the link. Just wanted to offer it as a learning resource!
And.... I'm using TryHackMe content and labs as well as guides from OffSec for most of my learning and videos.
hello
Hey people! I am looking to learn to work with various levels of safety, but currently I have one goal that I really want to work towards:
- Learn to create programs that allow/disallow access to various targets (think of IP/hostname addresses, applications/programs already installed on the PC) and create various conditions to allow this.
Key features:
- Ability to give or remove access to a user/device on those various levels,
- Give or remove the access based on various context (timezone, tasks completed, privileges that the user has)
- Make it very hard to remove/overcome that access. Not something that you could essentially restart the pc/turn off the program and now the access is reclaimed. Instead, it could only be overcome with a specific password/set of passwords or only after a certain timeframe.
I have this idea specifically to try and create such a tool for ppl like me who are having a hard time controlling themselves in terms of entertainment (video games, youtube, netflix and all). The key component is removal/taking away the access so that the person has to do something else and can't overcome it (I know that absolute inability to overcome this obstacle probably doesn't exist, cuz you can always reinstall OS or replace PC parts, but you get the idea)
So, if any of you would have any ideas on what these topics are specifically, what materials I could look into to start learning such things, it would be great.
Example of such tools would be app called "Freedom". I have no idea how they have created it, and how I could do it myself (something similar, but over time potentially more sophisticated and more suited for various contexts).
Hello guys, I built a small Chrome/Edge extension to help SOC analysts and threat hunters save time during IOCs lookup.
With one click on the extension, it automatically extracts IP addresses, domains, emails, and file hashes from current webpage and lets you analyze them instantly through api calls or using external TI platforms.
If you are dealing with a huge amount of IOCs, I believe this will help you from copy-pasting and multiple tabs headache :).
https://github.com/AnisseHounaoui/IOChaser
I am new to this and would love to learn Linux, so Iβll check it out and give you my honest opinion
I am interested
A good resource for all available certs on the market (Free & Paid):
https://www.dragkob.com/security-certification-roadmap/
Thatβs massive
for a second I thought those were all the certifications you hadπ€¦ββοΈ
I am trying to figure out how to engage my team on thm. Unfortunately the help page is not really helping much. To you experienced team members or team creators out there how did you do it
you still interested
Or you seen a resource ?
90-Day Cybersecurity Study Plan
This repository contains a 90-day
cybersecurity study plan with daily
tasks and learning resources...
https://github.com/farhanashrafdev/90DaysOfCyberSecurity?tab=readme-ov-file#introduction
Thank you, But
I'm looking for Ethical hacking free course, not cyber security?
But Thank you a lot for your efforts.
Gave +1 Rep to @frail ingot (current: #3585 - 1)
Hey everyone, I just published my first write-up for the pwn101 challenge! π I used Pwntools to develop a functional exploit for the buffer overflow vulnerability.
βFull write-up & Exploit code here: https://github.com/VayloBat/My_pwn_journey/tree/main/pwn101
Hello guys ! If I buy SEC1, can I take the test whenever I want?
Big thanks to Brilliant for sponsoring this video. To try everything Brilliant has to offer, visit https://brilliant.org/davidbombal to start your 30 day free trial or scan the QR code onscreen β Youβll also get 20% off an annual premium subscription
Stephen Sims joins David Bombal to discuss Operational Security (OpSec) through the lens of...
#sec1 message 1 year
Please verify your account and interact with the community more before advertising.
I just bought the sec1 certification which said it is 40%off but when I buy it, it is just $126. I really donβt know why that happened to me and I am a premium user.
Can some one tell this situation to THM team members for me please ?
@bold fractal
Hello everyone,
I have a $10 Swag Voucher left. I hope it is allowed to share. Feel free to use it:
kuwctj-79o2gr-gpyp8h-h5al4g
Hello,
I'm really new to all this and was looking at the free training course first on THM website. Why there's some links, when I open, says "This is a private room". Why it is private? Can I get access?
For example - Intro to Offensive Security.
Private rooms are generally "retired" and not accessible but by the owner/staff (or "in progress" if it's a new room soon to be deployed).
But the room you mention can be found at https://tryhackme.com/room/offensivesecurityintrokK
Maybe it's a newer version of the link you have.
@amber spruce Thanks buddy! The one you shared is helpful.
Gave +1 Rep to @amber spruce (current: #304 - 33)
do someone have a swag voucher giving away
Get up to 67% off Kali Linux VPS hosting with Hostingerβs one-click template. Use code FIRESHIP for an extra discount - https://hostinger.com/fireship
Let's learn the fundamentals of penetration testing and ethical hacking tools by running 10 free and open source tools on Kali Linux.
If some of these tools feel illegal, that's because they c...
Any good resources people recommend for getting fundamentals of web dev down?
In this video, I cover the OWASP Top 10 2025: Application Design Flaws room on TryHackMe.
This room focuses on security issues that originate from poor design, configuration, and architectural decisions, rather than simple coding mistakes. These flaws are often built into systems early and can have serious real-world impact if left unaddressed....
Hello guys do you know any websites to view written triaging alerts? thx
https://axl0t0l.github.io/posts/Pentesting-Basics/
Pentesting Basics by Me!!
Please suggest any recommended edits
Thank you bro I was searching for this
Gave +1 Rep to @fathom grove (current: #3615 - 1)
Private rooms are generally "retired" and not accessible but by the owner/staff
Not quite, if they're not fully emoved, people who've had access previously can access the content.
thus the use of the word generally, I suspected there could be another obscure or rare explanation and wanted to focus on providing help in this case. ty for the clarification.
Thank you! It looks pretty good
Gave +1 Rep to @fathom grove (current: #2342 - 2)
hello all, do yall know what room or challenge to practice AD pentesting other than Compromising Active Directory room? really need it for exam prep
Canβt find itβ¦ getting 404 code
Anyone got any good web app resources?
Not much, other than Web Security Academy by Portswigger
Anyone know some good papers on LLM and AI security ? π
.
YesWeHack Dojo, similar to Web Security Academy but covers some more and different web vulns
Me too, @fathom grove did you remove it? The link is not working
I`m currently checking out https://www.freecodecamp.org/learn
Anybody got a good template for writing up investigation reports? been struggling to know with what to put/format into a report
For inciden response or for pentest ?
incident response pls π
`Time of activity:
List of Affected Entities:
Reason for Classifying as True Positive:
Reason for Escalating the Alert:
Recommended Remediation Actions:
List of Attack Indicators: `
This is from THM SOC sim π
Ah thank you so much! I have not checked out the THM SOC sim yet but this is very helpful
https://pentestreports.org - Professional Pentest Reports for CTFs
Hey everyone, I made a video explaining how Nmap works (host discovery, port scanning, SYN scans, service detection, NSE, etc.).
Itβs meant to be a beginner-to-intermediate guide for anyone new to Nmap.
Would really appreciate your feedback.
In this video, I explain how Nmap actually works and how hackers use it to scan networks, discover hosts, detect services, identify operating systems, and automate enumeration using the Nmap Scripting Engine (NSE).
We go from basic network scanning concepts to powerful NSE scripts, helping you understand how Nmap performs scans at the packet le...
Hi, anyone got some web to check sender mail reputation?
DKIM Record Checker β https://dmarcian.com/dkim-inspector
DKIM Record Validator β https://dmarcian.com/dkim-validator
TO CHECK DMARK RECORD of a domain β https://dmarcian.com/dmarc-inspector
Domain Health Checker β https://dmarcian.com/domain-checker
Reputation check on email addresses (account required iirc) β https://emailrep.io
Also maybe https://talosintelligence.com/reputation_center
Utilize dmarcian's DKIM Inspector to see if the public part of your DKIM signature has been implemented correctly in the DNS of your domain.
Utilize dmarcian's DKIM Validator diagnostic tool to validate the content of DKIM records, and learn why that is important.
dmarcian's DMARC Record Checker allows you to view the DMARC record of any domain and test if the TXT record is valid and published correctly.
Use dmarcian's DMARC Domain Checker to find out if an email domain is protected against phishing, spoofing or fraud.
Illuminate the reputation behind an email address.
Super, thank u!
Gave +1 Rep to @amber spruce (current: #304 - 34)
Hello
So as curious for yall...is there any github relating to cyber security projects would love to check it out!
If you're into red team
I don't know where to post this, but if you're are looking for a team to participate in CTFs:
CTFtime: https://ctftime.org/team/183212/
Dm is open π
Hi guys! Not sure, if this is the right channel, but maybe it helps any of you. Happy to receive feedback:
Built a CLI tool that might be useful for anyone doing SOC Level 1 or DFIR rooms β especially anything involving VirusTotal lookups (Invite Only, MrPhisher, that kind of room).
vex-ioc β VirusTotal IOC enrichment from the terminal.
Instead of opening VirusTotal in the browser and pasting hashes manually:
vex triage 44d88612fea8a8f36de82e1278abb02f
vex investigate evil-domain.com -o rich```
Auto-detects IOC type, handles defanged formats, two modes (fast triage vs. deep investigation), MITRE ATT&CK mapping from sandbox results, STIX 2.1 export, SQLite cache. Works with a free VT API key.
Useful for rooms where you're working through a list of IOCs and don't want to context-switch to the browser every 30 seconds.
GitHub + install instructions: https://github.com/duathron/vex
PyPI: https://pypi.org/project/vex-ioc/
Good share β
Anybody got a good resource for cloud security projects/mentors?
i want to start cybersecurity but my tutor is charging 58k which i cannot afford can anyone hele me to learn it with free resourses
Youtube
Hey, I just put together a full walkthrough on exploiting OWASP Juice Shop β covers getting into the admin account and manipulating the payment system with Burp Suite. Thought it might help anyone trying to learn web exploitation. youtube.com/watch?v=TCU8e5z9ghE
most chill hacking tutorial ever, lol. nice music.
Appreciate that man π
Iβve been wanting to do more long form videos so Iβll do more in the future
Hey everyone, can anyone help me with notes of cyber security 101 rooms , I am not very good at making notes , so was just hoping if there is any resource that could help
hi, I was looking for ADWS libraries in c++ but found nothing, so I created it myself by reimplementing the protocol stack, if any of you is interested:
https://github.com/ZakiPedio/BridgeHead
Description:
BridgeHead is a C++20 static library implementing the full Active Directory Web Services (ADWS) protocol stack directly over TCP. Named after the AD bridgehead server, the gateway through which directory traffic flows, it gives your C++ code the same low-level access to port 9389 that PowerShell's Get-ADUser and Get-ADComputer use under the hood.
(this should theoretically works on Linux but I never tested it and I saw that the GitHub tests failed, if this project get a bit of interest I can adjust it)
let me know if this can be any useful for any of you or any comment on it
Just released pentest-ai, Claude Code subagents for offensive security work.
Install: copy 6 files to ~/.claude/agents/
What it does: Claude auto-routes to specialist agents for recon analysis, AD attack methodology, detection rules, STIG compliance, and report writing.
Every technique maps to ATT&CK, and the exploit guide gives you the defensive perspective too.
Free: https://github.com/0xSteph/pentest-ai
Check the example outputs to see if it's useful for your workflow.
Old-school Windows x86 stack overflow lab. Just leaving it here in case someone enjoys stepping through the basics.
https://github.com/nataliadiak/windows-x86-shellcode-poc/
Hello Everyone π
Iβve just published a new blog post on Chisel HTTP Tunneling & Pivoting as part of the NetPivot-X project.
While this topic may seem straightforward at first, it often becomes challengingβespecially for beginners. In this article, Iβve broken it down into clear, practical concepts that you can confidently apply during labs or actual engagements.
Read it here:
https://teamsimple.net/blogs/chisel-http-tunneling-pivoting
If you find it valuable, feel free to drop a β€οΈ and share your thoughts or questionsβyour feedback is always appreciated.
Chisel is a lightweight tunneling tool that wraps TCP/UDP traffic in HTTP, enabling stealthy communication over ports 80/443. It uses a simple client/server model with no SSH required. Ideal for restricted environments, it supports reverse tunnels and SOCKS5 proxies for pivoting and accessing internal networks.
are here people who write their own tools?
some tool which log and help to write a report?
I know there some for bug bounty
your tool looks impressive
Anyone knew best 5ghz supportive wifi adapter for injection
Just published a new blog
How I compromised +35M accounts with a single API request
does anyone have the published a list of the 100,000 most common passwords i need it
Not sure if you still need it but I did a quick search and found this
https://github.com/danielmiessler/SecLists/tree/master/Passwords/Common-Credentials
Thanks π
hello is there any free resources for the cybesecurity beginners i appriciate for the help
Can i clone this form my terminal?
yup use git clone
Firstly, please don't post the same thing in multiple channels, secondly, the suggested THM free path is here:
https://tryhackme.com/resources/blog/free_path
Hey I'm a newbie in Cybersecurity and I'm eager to learn from others who had experienced with this.
How can I learn or what are the things I need to learn? And the resources if it's possible?
hello i am new here give me guid pls
A good path to start is the PreSecurity path https://tryhackme.com/path/outline/presecurity
Wrote a short blog post about turning Nmap XML into an interactive HTML report for scan triage:
https://mΓΆbius.band/blog/nmapview/
It covers the workflow, why I used XSLT, and where the browser-based approach starts to hit limits.
Helpful thanks
Gave +1 Rep to @gusty mountain (current: #3709 - 1)
CIA & DAD triad, for those unfamiliar.
Can someone recommend me:
AI tools used in ethical hacking / pentesting
Any good workflows combining AI with cybersecurity tools
Penligent is an AI-powered penetration testing tool that requires no expert knowledge. With simple natural language prompts and a single click, you can scan for CVEs, uncover vulnerabilities, validate issues, and produce reliable reports.
Done!
Hello guys
I have a question...
I'm very interested in cyber security especially pen testing but I don't know where to start learning... Is the tryhackme pre security path good for a solid start or i should look somewhere else?
pre security is good to start with
Thanks
Gave +1 Rep to @lost agate (current: #1101 - 6)
Hey everyone π I got tired of trying to remember steghide, zsteg, and binwalk syntax during boxes, so I built an open-source tool to automate the whole stego process.
It's called StegoForge. I compiled it into standalone executables, so you don't even need to mess with your Python environment. You just run it.
The best feature for CTFs is the auto-extractor:
stegoforge ctf --file target.wav
It automatically runs RS analysis, Chi-square, offline HuggingFace ML models, and AES brute-forcing to blindly extract hidden payloads from images, audio, and MP4s. It also generates visual diff heatmaps of the manipulated pixels.
Fully FOSS (MIT). Would love to hear what the THM community thinks or if you end up using it on a room!
Repo: https://github.com/Nour833/StegoForge
Check out my new post. ‡οΈ
https://www.reddit.com/r/netsec/comments/1snem8w/haproxy_http3_http1_desync_crossprotocol/?a
Hello guys, I built a Chrome/Edge extension to help SOC analysts and threat hunters and IR save time during IOCs lookup and investigation.
With one click on the extension, it automatically extracts IP addresses, domains, emails, and file hashes from current webpage and lets you analyze them instantly using external TI platforms.
If you are dealing with a huge amount of IOCs, I believe this will help you avoid the repetitive workflow :).
I hope its helpful
https://github.com/AnisseHounaoui/IOChaser
GitHub
Browser extension that makes IOC lookups faster than you ever seen. - AnisseHounaoui/IOChaser
+ idor-hunter Β· Python, MIT
Automated IDOR hunting β sends every request as User A, User B, and unauthenticated, compares responses, and flags broken access controls.
Detects horizontal privilege escalation, missing auth middleware, and write-without-read gaps. YAML-configured. Outputs an HTML report, JSON findings, and CSV probe log. For authorized use only (bug bounties, CTFs, own systems).
Repo: https://github.com/11lunaric11/idor-hunter
Questions/feedback welcome via DM!
hey ! im searching for internship in india for cybersecurity . can u help me ?
does someone where i can find promotion codes for tryhackme payment?
Try ChatGPT. I got somewhere from 30%-40% off. Totaling around ~$45 knocked off. I use it every time for all kinds of related things.
hello. can i get a few suggestions about coursework to start a career in cyber security?
U need the cyber security road map
please can u help me with that
Hey, if i start learning to code through roblox studio do yall think it would help me to learn proper coding?
I know python and basics of linux
and currently enrolled in google cybersecurity cert.
is there anything else
Hello Community,
Built a CVE prioritization platform https://cve.integrate.com.mo/ or whatever you named it, this is not a "Yet another CVE database" kind of style, it do the following in a shot, just submit a CVE number or a Tenable Plugin ID and it will do the heavy work for you.
β’ Turn scanner findings into practical exploitability decisions
β’ Tell users which findings actually matter
β’ Cut through CVSS noise
β’ Explain severity downgrade/upgrade reason, attack path, friction, compensating controls, and real-world relevance
Hope you like it and let me know your comment!
thanks
Hey folks π Built a little browser game over the last few months β Cyber Defense. You defend against real ransomware groups (LockBit, BlackCat, Cl0p, etc.) using actual TTPs from open-source threat intel (shoutout to ransomware.live).
Free, no signup needed, runs in browser: https://darklayer.ai
Mostly looking for honest feedback β what's confusing, what's boring, what breaks. Made by one person (me, 20+ years in security, tired of dry training material π
). Roast it if you want.
share some top score results lol
Hey everyone. I put together a small Windows auditing tool in Python after finishing the Cyber 101 path. It's meant to help identify suspicious processes and network connections. I had to look up a lot of the process iteration logic on Google to make it work, but itβs been a great learning project. If you're looking for a simple script to see how psutil works with networking, feel free to check it out. Link is here: https://github.com/Oliver-Sec/System-Auditor
anyone had time to test it?
i made a free binary analysis framework thats running 100% in your browser. No ads, no signup, no bullshit, 100% free! just a cool tool for static analysis. check it out if you looking for something like that:
https://aethersec.de/crypteia/
feedback is very welcome
PortSwigger is doing a survey to link Burp Suite Community to an account. #1161285617519431752 message
Hey, I built a simple python script that can convert shellcode up to 11 formats, it features bad-byte detection, entropy range, and a pipe-friendly CLI. zero dependencies, works everywhere python runs
repo: https://github.com/d7da/shellcast
or download yourself: pip install shellcast
Hello, I just released a new updated version of IOChaser, it now support selecting multiple IOCs from any webpage and display verdict + meaninful details regarding each IOC. Check it out! https://chromewebstore.google.com/detail/IOChaser/gjomgdkjfhpmmmlleefbblnfeanmniem
hey guys, how did yβall learn Flask/InfluxDB/Grafana ?
Hey everyone, I built a free open-source tool that might be useful for your home lab or CTF setup.
PCYBOX Orbis : real-time network traffic visualizer with anomaly detection
It shows every connection your machine makes as a live graph, and flags:
- Beaconing behavior
- Suspicious processes (cmd.exe, certutil, powershell making outbound calls...)
- Connections to known bad ports (4444, 9050, 1337...)
- New devices appearing on your LAN
GitHub: https://github.com/Mister-iks/pcybox-orbis
Would love feedback from people in the security space.
Yo! I'm on the hunt for some solid Bug Bounty learning resourcesβboth videos and websites. What are the 'gold mines' you guys would recommend for someone starting out? Appreciate the help!
Btw, will there ever be a version for firefox?
Yes
Nice, ty
Gave +1 Rep to @tough kindle (current: #20 - 541)
can it be integrated in a google sheets request to display the creation date in a cell for example ?
Wdym?
I mean when it displays a room info, is it inside the extension or is there an url that i can use ?
Hi, buddies.
Im hear for your help.
I've seen that almost all the phone servicing shops can unlock any phone they want.
I wanna know how. Cuz im trying to learn it. And i can't rest until I've learned it.
Hey guys im not sure if its the right place to post it and if admins will aprove it ,
but i created a Write up tool with some nice features inside. currently im posting THM Writeups over there , each account can create his own writeups and share it with non user friends.
Its very friendly to Newbies , Jr's , builtin commands and shortcuts.
Send me DM with your request to get approved.
It shows it inside the extension.
Nope if they don't have the password they can't just unlock the phone magically and access your data.
Any sites to practice reverse eng
crackmes
@woeful wharf Please slow down. Further spam will result in a short timeout.
@woeful wharf Please slow down. Further spam will result in a short timeout.
Very cool tool nice interface too !
hello
Hello, Everyone, I'm creating this advanced SQLProbe injection scanner with WAF detection, auto-parameters, headers/cookies testing, and 87+ payloads for modern websites.
This GitHub Resource Link: https://github.com/Shreyaskalyani/SQLProbe.git
And This is an AI-powered XSS vulnerability scanner with a multi-agent architecture. Detects reflected, stored, and DOM-based XSS vulnerabilities.
This GitHub Link: https://github.com/Shreyaskalyani/XSS-Hunter.git
GitHub
Advanced SQL injection scanner with WAF detection, auto-parameters, headers/cookies testing, and 87+ payloads for modern websites. - Shreyaskalyani/SQLProbe
Built VoidAccess, free open source dark web OSINT platform. you put in a query, it runs a 13-step automated pipeline over Tor and returns a full threat intelligence report. extracts IOCs, maps relationships between entities, exports STIX/MISP/Sigma. good for anyone learning threat intel methodology β TCM Security's OSINT approach is basically the backbone of how the investigation flow works.
Anyone here use Microsoft Copilot?
If so, you probably share my frustration with Microsoft. They still don't have an option to bulk delete chats!! Well, I got so fed up with it, that I built my own browser extension. It works like a dream. You can select what chats you want to delete, and then bulk delete them at three different speeds, with a pause and a retry option. You can get it on Chrome here: https://chromewebstore.google.com/detail/copilot-chat-batch-delete/ndhlafbieanmkgipgihhpgoelgnhmide
It has no reviews yet because it is brand new, FYI. Hope it helps you turbocharge your workflow!
It's 100% free.
Upvote if helpful
Anyone have any information/advice about cryptography and whether cryptographers are at risk of being taken over by ai
built a free email OSINT tool, checks 800+ platforms, breach exposure,
infostealer logs, and maps an identity graph showing why each hit is
high confidence (not just a raw dump of results)
tested on my own email β 39 accounts found in ~60 seconds, no API keys needed
pip install mailaccess
github: https://github.com/KatrielMoses/MailAccess
lmk if you try it π
made a lolbas privilege aware checker in go: https://github.com/aaron-kidwell/goLoL
you need to check post quantum algorithms those ones will survive in the future
Hi, is the correct channel to ask about malware analysis and homelab setup?
Hi everyone, Iβve started publishing cybersecurity blogs and CTF write-ups on Medium focused on web security, PortSwigger labs, tryhackme labs, hackthebox, huntress labs, authentication vulnerabilities, and practical learning content.
Iβll be consistently posting new write-ups and learning resources. Feel free to follow and support the journey!
Read stories from Inconsistent on Medium: https://medium.com/@buggyboy
LFI Explained and the techniques to leverage a shell from a local file inclusion vulnerability. How to get a shell from LFI
nice
Ohh, this is cool π
BEST PRACTICE FOR BOF
Don't suppose anyone has any resources on OSINT? π
@graceful estuary http://rgho.st/private/79G7Y4d2H/e78b35a911e718133eedf117690a404a
@graceful estuary https://osintframework.com/
EVERYTHING YOU EVER NEED TO LEARN IS ALL IN HERE.
Ohhh, thats awesome
just bought some materials for OSWP, fuck installing the drivers is the hard part π
what exactly do you have to set up? :p
https://gchq.github.io/CyberChef/ This website has some useful tools can even analyze hashes however it can't identify some more complex hashes
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
ill be live streaming me attempting to root https://www.vulnhub.com/entry/hackinos-1,295/
xd good resource
https://www.secjuice.com/how-to-handle-an-intrusion-on-a-windows-system/ I wrote this last month π
Oh thanks π
Walkthrough for Kioptrix #4 in prep for the OSCP:
In preparation for the OSCP, I'm doing a couple of vulnerable machines from vulnhub. This is my walkthrough for Kioptrix #4. My course on Beginner Python Eth...
good Job ...keep it upp
Great work.
What's that for?
Oh BlueKeep
Tested it out works but just need to add your own payload in code which is in python.
Well, the actual code itself is not public just yet. Still waiting for more people to patch.
List of Red teaming, pen testing, and OSINT resources: https://pastebin.com/rMw4WbhX
^ Pretty cool
@forest pecan Really?
yh
@white pivot, good naming convention Haha
Ah, since I always want to have someone like Alfred, I named it after him.
Let me know your feedback, though.
? @cold salmon
Alfred Pennyworth
I know, I thought you're saying the toolkit doesn't worth a penny.
@white pivot batman sucks π
Are you judging him on the basis of live action appearances?
@whole grove that's fine, you can be wrong ;P
Lol I was just trying to provoke robin π
@whole grove It's not that easy. :p
Nearly forgot to mention that Packt is having a $10 sale on pretty much everything right now: https://www.packtpub.com/
Packt is the online library and learning platform for professional developers. Learn Python, JavaScript, DevOps, Linux and more with eBooks, videos and courses.
@forest pecan Do we have a high res of the THM logo?
have a bunch of stickers i'll be printing soon
Heya, what for sorry?
Oh right aha
issue is stuff are expensive when converting it to my currency
like $4 for 5 stickers (for example) is just a 'ripoff' as I can print the same stickers but for $3 for 20 for example
well when using Liras
Yeah annoying tbh
disadvantages of a stagnating economy
sadly
I dontn see a store/swagshop in the site tho
If you'd have more completed I'd have sent some for free
Something to work up to I guess?
i mean I am busy with a few finals. I'll be working on some rooms and writeups that'll be done later this week
like I am still waiting to publish my OhSINT
but again; self printing the stickers is the most beneficial thing for me as I'll set custom sizes and such when i'll print em
like the Ataturk signature will be larger than the rest and maybe Kali will be larger than the rest but smaller than Ataturk
you get the point :P
Okay awesome π
@forest pecan wanna send me that shirt and sticker(s)? ;P
And since everyone is trying their luck. Let me also ask you; wanna send me that shirt and stickers π
The THM sticker is cool! As is the tshirt
I want a sticker too π
here as well π send some swag stuff please
Lmao I'm definitely in trouble for this
haha just share the design would be ok lol
I'll harass Skidy to let me set up a Designed By Humans storefront
@ebon valve shhhh don't worry about skidy just promise everyone that he'll give shirts and stickers
Lol
Haha I'm going to be in such a heap of trouble for that
Good luck
@shut ferry how do you print stickers?
@molten kayak printing houses
My classmate is a creative director at a marketing firm/digital printing service
Heβll print em for me and do the inner cuts etc
damn
I already made em die-cut, just need printing and inner cuts
There are websites like Stickermule locally as well but they require bulk orders/quantities
Whereas I only need 1 or so
So its just easier and way cheaper for me to print what I need
@forest pecan THM stickers?? π π
I think I got a local shop next to my house that has printers and like sells books and stuff.
ill ask there if they can print me some
but how can I give them the pictures
So @shut ferry you can have Defcon Stickers for cheap?
I mean if I can get a good picture of em and import em to Illustrator, why not
Like the Github sticker is bootleg af ahahaha
Or the mozilla sticker
Man, I need some stickers for my laptop, cheap ones are like $3-5 but import charges are like $25 and that too for a little sticker.
can anyone suggest any resources/books/websites etc for learning x86 assembly?
Honestly, there is no straightforward way to learn it. You have to pick a lot of resources like course materials from universities website and in my opinion PMA would be helpful or you can try x86 room.
@glad oyster did you checkout the x86 room?
Yeah, I've done that room, a good tool but looking for even more now :D
Mess with C and objdump @glad oyster
Or gcc -S
Honestly once you know the basics of how asm works
You can just google any instructions you find and don't know
That's basically what I've been doing so far - also reading "The Art Of Exploitation" which is giving me a decent knowledge of assembly.
I'm just struggling with the radare2 room just now and want to know more about assembly
Do you need any help?
Well I'm on the final exam part and just can't seem to work it out. Doesn't help that I cant execute the binaries on osx :((
Use a linux vm then?
Good shout. but currently on holiday in the middle of no where with no linuxs boxes downloaded
Ah
@glad oyster this book is supposed to be good: Practical Reverse Engineering: x86, x64, ARM, Windows Kernel, Reversing Tools, and Obfuscation
Boi for a sec I thought you were posting the bdsm test lmao
HAHAHAHAAHAH
https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE/
Check this out
anyone got a good source for some of the more exotic encoding methods?
Yume is our resident cryptologist
nah nah
as in, non- xor, baseX, utf-16, hex, binary, morse, braille.... but more like stuff that unless you been doing CTFs for a while you probably havent seen... e.g. moo
well moo isnt really an encoding, it more an obscure programming language
yeah realised that
this ones a good list
you may encounter some of these at some point
yea i dont think the 2 two im looking at are in cyberchef, but if they were I wouldnt even know it because i cant identify what im looking at
ill dm you
1 sec
yea thats kinda what i was looking for, im familiar with most of those on that list but there are a few i havent heard of
oh good to hear that's what you're looking for π
Good @regal torrent

Esoteric Programming is different from cryptography.
can some explain command with strings -e l (is that mean encoding character to print)
yup it encodes character
hahhaha well something better is there
yeah the new post is really really amazing π
oh damn.... I thought you are referring to that post π
π
anyway there is nothing like stealing others credit .....π
@regal torrent and me waiting for ur forensics room
its still pending
once its uploaded to server its loosing half of the vulnerability , due to WAF
oh
that's bad
why don't you make a volatility room until then
I really want to get my hands dirty with some more mem dumps
once i am done with my Angr script
Angr wot
its an utility in python
what?


