#resources
1 messages · Page 5 of 1
Meanwhile just downloaded the book you shared!
Yeah!
Got it will look into it in a while!
Meanwhile taking notes is easy!
I always have a bunch of A4 papers on my table along with some pens and pencils@!
yeah, need to start doing that 😄
yeah, how to git gud at note taking
@gritty barn join GENERAL - Voice Channel!
Well i guess i have plenty of Repos on my github too 😛 (PRIVATE) all notes LOL
I depends on my brain lol
@gritty barn just read the Web Application Section of the book. Seems good to me!
Wait a sec. I'm supposed to work from home @spare oar
@gritty barn you have to fill out so much!
Firefox send
doing it now
You know, you shouldn't technically share it but it'd be a shame if you dropped it into my DMs with a firefox send link.
Yeah it's around 75mb!
@gritty barn share the link with me as well!
damn it i just made it download once
AHAHAH
My internet speed is 512kb/s ATM lol
OP
I can't even think about uploading anything neither downloading anything xD
my upload failed successfully
Damnnn!
yeah, I should pause my torrents
Is there a wordlist from the linkedin breach?
@odd quest i had it - let me see if i can find it - if so i will share!
@odd quest the LinkedIn leak was entirely hashed data
I can get it for you if you want but it’s pretty useless
Un salted
for those interested in security ... free training http://opensecuritytraining.info/Training.html
car hacking
This paper is important!
An excellent (if a bit dated) article/tutorial on exploiting buffer overflow vulnerabilities. It was written by Aleph One for Phrack 49.
^^
Yesterday I was teaching a guy how to do ret2libc attack should have made a YouTube video and posted it
frolic on htb does that
You did it? @storm ether
I'm not a complete degen when it comes to bin exp. I just don't remember much so every time I have to relearn it
SANS Incident Response Training Course: http://www.sans.org/course/advanced-computer-forensic-analysis-incident-response
Memory Forensics for Incident Response
Featuring: Hal Pomeranz
Modern malware has become extremely adept at avoiding detection by traditional endpoint an...
Loved this SANS DFIR Webcast
From Discover on Google https://udemycoupons.me/comptia-cysa-udemy-coupon-free/
Just got it myself. There's a button at the end saying enroll now
wrong chat
Found some EBOOKS and VIDEOS for InfoSec! Hoping it would help someone!
https://drive.google.com/drive/folders/1cjjrILQd0eFkfgX0EU__1uqkd0Q9KaEW
Does anyone have any recourse for investigating windows system
Cool Stuff!
New discount code til the end of the month: FACEBOOKHACKSPLZSIR
@gritty barn no hell no pleaseee! for god sake! That course is going to ruin ppl lives!
^ agreed. it's a good source of fun @spare oar
HAHAHAHA let's see what others have to say about this course 😄
+1
I...
Literally signed up for the course, and I hear sirens in the distance.
OH NOES BOIZ they comin for me
@ivory nebula 🤣
@ivory nebula TTL the home.
Introduction It was a cold Sunday evening, and I was doing nothing but afk’ing cannonballs on OSRS (shout out to @TimGMichaud) when I had an urge to make something. I was thinking about a conversation I had on Friday with Sion (fellow colleague/hacker friend) about methods ...
There using Twitter as c2
From image metadata
That was interesting, I'll take a look at the discord one too
For those who aren't aware of this! It's a must have in /usr/share/wordlists. https://github.com/danielmiessler/SecLists
How about we pin some resources?
I feel like we should have a wiki, or a link-only channel
A wiki, that's a nice idea to be honest.
@shut ferry Shoot it in #544951750801752079
goahead and repost it 4 me @white pivot :V
Documentation, Hacking, Phreaking, Cryptologie, Challenges, Outils, Analyseur, Backdoor, Firewall, Anti-Virus, en, Réseaux, Web - Client, Programmation, Cryptanalyse, Communauté, Chat Box, Scanneur, Box / Boites, DNS, Challenges, Compilation, IDE, IDS, Désassembleur, H-IDS...
So guy if you look in github for oscp there is many there like go-for-oscp or oscprepo
Etc
Is there any one repo well arranged ?
Cherrytree files : https://github.com/egonzalez90/cherrytree-files
Password protected
In March 2005, Hitachi Global Storage Technologies demonstrated an areal density of 230 gigabits per square inch (Gb/in2) on perpendicular recording technology, the highest areal density achieved to date based on vertical recording. This accomplishment represents a doubling o...
🔥 🔥 🔥 🔥 🔥
Anyone hv this ebook
Hands-On Application Penetration Testing with Burp Suite
Packt Hands-On Application Penetration Testing with Burp Suite
please make a room for bug bounty practice skills
#room-ideas @past cape

Oh man where to even begin with this one. This was a crazy ride and I learned a ton along the way.
good read on the new teamviewer CVE
SoonTm
Poggers
I wonder if I could emulate a Hue bridge on THM
Do it @tribal walrus
I've put far too much time into Hue security 
does someone have good resources for tunneling (i.e. hacking from an owned machine)?
thanks man!
Pwn challenges from previous CTFs https://pastebin.com/EckPRWsg
From Wild West Hackin' Fest 2018 in Deadwood, SD.
Presenters: Joff Thyer and Derek Banks
Joff has over 20 years of experience in the IT industry as an enterprise network architect, network security defender, information security consultant, software developer and penetratio...
Spector Ops released their entire PowerShell course for free ^
:o
Notice
dude awesome
https://nopresearcher.github.io/2020/01/23/OSCP-Like-Boxes.html This has binaries too
Everyone is always looking for ways to prepare before attempting OSCP or as a way to practice if they run out of lab time. Below is a collection boxes and s...
https://t.co/MSn1TF8ii2, the SSH server that knows who you are, got some newly refreshed intel! Try it out!
$ ssh https://t.co/MSn1TF8ii2
1386
3944
can anyone suggest me a good resource for learning python?
no. i think i could write some simple script in javascript or bash
Sololearn should be pretty good then
i've completed the old course from google and the w3 course, but there are only the basics (variables, strings, lists, etc...). Thanks for the advice @odd quest . i'll try that
I quite liked sololearn for SQL, Python, JS, jQuery, CSS, Java, HTML
I did a bunch
It's free, don't bother signing up for the pro
Also available mobile
I'm not a shill, but my college was
now i look at that, i remember that i've used that to learn html and javascript
If you do more JS, learn ES6
@little sapphire Any of the No Starch Python books; Automate the Boring Stuff or Python Crash course are very gentle intros and Black Hat Python and Gray Hat Python for pen testing. Violent Python is another excellent book, I've had it recommended to me by several OSCPs and pen testers in work. edx or coursera have good courses too
Perfect. Thanks a lot @wet yoke .i'll check those
Keep an eye out for a humble bundle from them soon :)
Automate the boring stuff is 100% free available online (not piracy, the author made it free) https://automatetheboringstuff.com/
Yep and the Linux Command Line book is free from its website
Introducing Updog, a replacement for Python's SimpleHTTPServer. It allows both uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use basic auth. https://t.co/UCBOHupH21
124
344
oooh that's pretty cool!
whats updog?
this entire website
If you are a fan of markdown - you will love Typora as i am personally using it as well and loving it so far!
Woah that looks rad, thanks @spare oar!
@sturdy shell ;)
https://evasions.checkpoint.com/
If you are interested in how malware detects virtual environments
It's been a long time coming, but finally it is time to launch our Call for Papers, Workshops and Training.
Talks/Workshops: https://t.co/HC9xVU2Cve
Training: https://t.co/mQZtAM2bkZ
You've got till the 10th April, so get going!
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Lil' handy tool for people who are new to Linux file perms - or just helpful in general tbh
This looks like a great resource
https://class.malware.re/
I made a repo of my favorite programs.
It contains mainly hacking tools.
hope u like it and share it :D
https://github.com/matesz44/favtools
+++ :--> updated it
- little more tools that I realised I actually use

- more description, github table format for better appearance
- programming language for each tool
bat, ripgrep, lsd, fd all good rust tools. check em out.
if anyone needs to break down regex expressions this is the site
Regex101 allows you to create, debug, test and have your expressions explained for PHP, PCRE, Python, Golang and JavaScript. The website also features a community where you can share useful expressions.
Here is a sample of an regex Explanation on above mentioned site!!!
Sublime is a super nice text editor w/ Regex integration btw
anyone having good resources/eBooks for DFIR do share the link (if PDF) share in private!
@arctic mist true!
Recommend me a network simulator that isn't Opnet
Have you tried packet tracer?
I should have said free...
oh I get it for free with my uni
Cisco Packet tracer is free afaik
I have to sign up in order to download it
Not sure if Autorecon is recommended for OSCP, anyone here actually use it?
[Spanish] how use burpsuite | https://www.sniferl4bs.com/p/guia-de-uso-de-burpsuite.html?m=1
@odd quest here you go, follow link below or i could send the pdf, let me know. Its the first link in SANS resources page
My write-up for OverTheWire - Bandit
https://alexbilsland.com/overthewire-bandit/
mmh, no mention of why 32->33 works o; Without an explaination, isn't it just a cheat sheet?
Maybe got a bit impatient. Will add more detail on the later levels
right :3 The bandit series was pretty fun, though
I'm just starting out with Linux tbh. Just writing it up so it sticks in my head better. Full Windows shop at work so I'm trying to expand my skillset
Ever since you could deploy dotnet to linux I've been getting into it. It's a lot simpler than managing (micro)services on windows
I've been going wild with PowerShell for a while. Really interested in learning about Bash scripting
You're gonna hate not piping objects :p
Oh PowerShell yeah ... the mind wanders ...
As long as it comes back to you.. :)
You'd hope eventually right
Eventually could be a long time. You won't know for sure if it's ever coming back! O:
This is for y'all that are in US: https://cyber-fasttrack.org/
CTF with a chance of winning a grant
These new NetWars challenges will be delivered to you, for free.
oh?
Hello
Is there any e-book you guys would recommend
It will be better if I can get it for free
How to Win Friends and Influence People
The Subtle Art of Not Giving a F###: A Counterintuitive Approach to Living a Good Life
Are these books about hacking?
I was asking books that I can use to improve in cyber security
Mine is about social skills which is a precursor to social engineering
same
if you need hacking
1 sec let me check my library
"Web Penetration Testing with Kali Linux" by Joseph Muniz
"CEH v10 Certified Ethical Hacker Study Guide" by Ric Messier
"Hacker's Handbook V2" by Dafydd Stuttard
Thanks
Idk if you can get them for free, but all of them are available on amazon and other services
yes
that's right
first one is really really good
started off with it and gained a lot of useful knowledge
it's pretty useful still. good luck!
Anyone got a compiled mimikatz available? cba to build it and the releases don't seem to like me
Hello everybody- I am new and just joined two days ago. I started with the beginner path and am stuck on finding flag 5 using the Linux find command. Can someone give another hint? By the way i am loving the site and the challenge. Well done! Thank you...
@jolly mauve head over to #room-hints and someone will try and assist you
ok thanks
can i have lil assistance on CTF min challenge
not here. See the response in #thm-community-media to your previous question
Burp Suite Free Training. Might help someone!
rumor has it someone is working on a burp room 👀
Port Swigger also has their training academy as well which is worth checking out
https://xmas.htsp.ro/home - Fun CTF
Difficulity level?
can you send the discord url of the CTF? I'm trying to enter but I only can open It in the browser
Cool. I'll probably try to participate :)
feel free to :P, upskilling yourself is always a good idea
especially in this dark times :c
@worn kelp huh?
@gritty barn shows a CTF and they have a discord, but I can't enter
it only opens web-discord for me too.
same
I'm trying to sign in so I can get the room link
oh, wait, i might've misunderstood something. It's not an actual link to the room. Lets look in the website's source instead :p
this is the sauce
and this is a good reddit list - https://www.reddit.com/user/goretsky/m/security/new
This multireddit is meant to provide a collection of all IT security-related subreddits. Please contact me if you have any …
nice
^^
a similar one to the above, but I find it easier to work with https://regex101.com/
I've always used regexr
Me 2
i never used any of time
i prefer manually scrolling through the stuff because i'm that guy
Why am I not surprised?
i'm sorry but my little brain can't comprehend much
You know, that's usually what smart people say
I just finished the zthlinux course. What to do know???
ps i already know python
that was my first room
Anybody has resources (possibly guided ones) for linux privesc?
@shut ferry oh Really, thanks a lot
Unrelated to information security but this is an incredible course: https://www.cnn.com/2020/03/23/health/yale-happiness-course-wellness/index.html
The Cyber Mentor is giving free lifetime access tomorrow to his Udemy course, if any of you are into that. (April 1st) Coupon code STAYINSIDEANDLEARN
https://www.udemy.com/course/practical-ethical-hacking/?referralCode=4A7D5EE973AFBCAD11C6
This is a great read for those doing day 10 of cyber advent room. It details a good aproach to server side attacks aka metasploit
https://security.stackexchange.com/questions/185644/which-exploit-and-which-payload-use
In short, after doing an nmap scan these are the most likely vulnerable services (as of 2017):
SMB/445 -88%
SMTP/25 - 78%
HTTP/80 - 58%
HTTPS/443 - 49%
SSH/22 - 6%
@wet yoke , thnx f0r sharing, yet it shows 75% off discount for me instead.
that's weird, it worked for me
can anyone suggest something to deeply understand “Exploitation” and “exploit development” for beginner?
@lost pelican anything to suggest?
Why me? I'm by no means an expert.
@shut ferry the protostar challenges are a good introduction to memory exploits e.g. stack /heap overflow
This course is great too for learning the basics of overflows
Panel
August 1st--4th, 2013
Rio Hotel & Casino • Las Vegas, Nevada
@stray orbit By default it will show that 75% off price but you have to click the 'Apply Coupon' button at the bottom just above the 'Share' button and put in the code STAYINSIDEANDLEARN, click Buy Now/Enroll (if you're already logged in) instead of add to cart
Ok this sounds really dumb. But I need a source on how to hack. We all know it's basically enumerate/recon, exploit, repeat for escalation but I can't find anything supporting the processes that I'd use
Like, portscans for recon
I guess this is why THM exists
It's really just finding the tools that work with you. So for my recon phase, I would use Nmap, Gobuster, Nikto, SMBClient, RPCClient, LDAPSearch etc. They're all bundled with Kali. Worth looking at the tools included with Kali and familiarising yourself with them.
@rose bobcat I know exactly how to do it
I just can't find anything to back that up. I've learnt how
What do you mean, back it up? As in training documentation?
I just need some material that I can cite
I'll probably end up citing tryhackme otherwise
Ah is this for an academic paper or blog or something?
Yep
Just can't find anything at all that says you can break down stuff into recon/exploit, here's what people normally use for recon
There's quite a few blog posts out there for things like "pentesting reconnaissance", but I don't know how much provenance you need for the sources - Medium blogposts don't always cut it
I mean the information has to come from somewhere, that's what I'm trying to find now
Ahh okay. I don't think its necessarily something you can pin down to a specific study or paper or training doctrine, it's just the go-to default. But best of luck - if I come across anything I'll be sure to let you know 🙂
yeah I mean that's the issue I'm finding
It's just the defacto standard
You have to look for what you can attack before you can attack it
have you tried google scholar and search for key terms?
there has to be some paper, or any publication about this
Cyber Mentor is giving his ethical hacking course away for a day on Udemy. His only stipulation is that you pay it forward at a certain point! https://www.udemy.com/course/practical-ethical-hacking/?couponCode=STAYINSIDEANDLEARN
@wet yoke Oh man, I was not looking into the text above, just believed discount code is in URL. My bad. I should RTFM first! :)
But yeah, I got it.
THANK YOU SO MUCH!!
Udemy Coupon 100% OFF For Python for Penetration Testers Course
^ got my one over email
https://www.ethicalhacker.net/register/
@stray orbit I created Caendra account and log in to ethicalhacker.net with it. Should I do something else? I didn't get redeem email?
Now, got the email with a delay of 15 minutes approx : )
For those who want to easily learn Vim:
http://www.vimgenius.com/
Anybody got any good Wireshark resources?
@shut ferry The book "Practical Packet Analysis"
Google XSS training
https://xss-game.appspot.com/
Just finished updating enum4linux to remove some of the errors and add color coding. Open to suggestions.
https://github.com/logicsec/enum4linux
@solemn heron Ideally, keep your project as a fork
I was going to originally, but wanted to talk to him first about the PR process. Not sure if he is keeping it active
so I kept it seperate until I can have that conversation
That's not what a fork is
A fork is your own version
You can PR back to main, or maintain your own
@delicate epoch I had to go a roundabout way to register. There was a CSRF error on the EH site so I registered on Caendra.com and verified. After that I was able to click the Sign-In link at the bottom of your register link and verify there and then about 10-15 minutes after I got the link to sign up to the course 😛
IoT is the worst
The S in IoT stands for security
agreed.
https://www.utc.edu/center-academic-excellence-cyber-defense/pdfs/4660-lab6.pdf
@odd quest can you send all labs/exercises?
nvrmnd, just change the lab number and can access all of those
Where would I go for good word lists?
it depends on the type of words you're looking for.
Some knowledge can be obsolete
Wisdom is the application of knowledge, useless knowledge is harder to apply
^
Wisdom is the application of knowledge, useless knowledge is harder to apply
@odd quest I'm quoting that one, thanks 😁
@spiral zodiac are you the malware from the score board? Ranked 80 something?
Yeah, why?
@fringe spire By the way the leader board only shows the top 50 users 😏
i know, i just saw you somewhere and as a pakistani you caught my eye xD
you were in KOTH with 0ptional on his steram
stream*
I was?
yeah.. last night
Sorry, I am a little distracted right now, doing KOTH
ok np
Deleted because writeup with flags
@fiery knoll I'm going to have to ask you to not post Offensive Security's paid courseware
^
That also goes for anyone and any paid course material as well
lol that's quite obvious
unfortunately it needs to be said
write a message and pin it maybe?
you know, that works if people check pinned, but half the time people don't even read the rules 
It's also already in the rules
@arctic mist sorry 
I'd be glad of any (constructive) feedback on it 🙂
@dull latch No answers in writeups
@dull latch You literally have answers to the questions in there
Every answer, more or less
Kerberos is an authentication method - Dr Mike Pound explains how it works so neatly.
EXTRA BITS: Kerberos Q&A https://youtu.be/QN4WmZXi4tg
https://www.facebook.com/computerphile
https://twitter.com/computer_phile
This video was filmed and edited by Sean Riley.
Compu...
I can not understand post exploitation. THM has a room with writeup. But it’s seem to quide hard for me. Youtube videos are using metasploit just....... can anyone share some resources to learn very basic of post exploitation? please 🙄
Before starting, I would like to point out - I'm no expert. As far as I know, there isn't a
thank you @eager imp
Cloud pentesting seminar^
Hi, i'm looking for beginner Python resources ? I finished the Python room and manage to find the flag by doing "puzzle" with info I was finding from here and there but it is still difficult for me to understand exactly what i'm writting. any suggestions?
@tacit tangle Automate The Boring Stuff is a pretty good free resource
Yeah No Starch has tonnes of great Python books. Tonnes of other great cybersec/Linux/BSD/etc books too...
No Starch Press have a good amount of books.
yeah and they have regular Humble Bundles as well 🙂 I have most of their cybersec/python/Linux/BSD books thanks to those 🙂
+1
guess there really isn't any starch in ebooks
I dunno, my tablet's a bit stiff...
get a better one
That would help...
:p
@wet yoke thanks
I don't suppose anyone has a compiled version of Akagi32.exe or Akagi64.exe
@storm ether https://www.hybrid-analysis.com/sample/d2ee12ccbadb833f9ec5dbe6b82fd6406c0216b6d2e479071650317cd4b366f5?environmentId=100 ?
Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.
The reason it's deemed malicious
is because it's a key tool that uses av evasion techniques used in malware
that blur
I'm just too lazy to compile it myself 😂
what about this one : https://libraries.io/github/rkmylo/UACME
i'm sorry i can't be of more help :c
https://www.autopsy.com/support/training/covid-19-free-autopsy-training/
Free autopsy training, certificate included.
Thank you!
any resources about bof for beginners ?
Maybe this ones are so specific, what r u looking for?
@worn kelp they said bof, so buffer overflows
ups
what even are words?
mf
I customized my tmux.conf to be able to store, and show a box IP, and be able to use it as a variable, it also shows your tun0 ip, basically saves me from tabbing around looking for an IP - if you are interested here's the way I did it https://pastebin.com/3nZFGdW7 (it won't look quite as good as mine as I used powerline styling for my version)
Learn ROP
Yeah, damn good course. I wish I'd be in that university.
Imma drop this here for that last one https://guyinatuxedo.github.io/
Nightmare: an intro to binary exploitation / reverse engineering course based around CTF challenges.
Enough for one day? @tribal walrus
Probably enough for a year 
Good luck :), if you'd like when you're not playing with your team, you can play with me.
Many thanks
xD
Your welcome.
Enjoy, as a fellow pwn, if you get stucked somewhere do ping me, I love to help people if it's about binexp.
Ah, right.
@odd quest ^
P;OG CHAMP
:)
Afterall, I'm that weird guy who loves pwning xD
Oh wait, I forgot something too. The gdb stuff, important as hell.
https://github.com/D4mianWayne/PwnLand/blob/master/Debugging/chapter-1.md
For absolute beginners, will update more sooner.
You know basics, so...try hitcon lab.
And, just wait a minute, since you're starting seriously this time, I got a repo that will help you brush up some skills.
That's for asm.
@tribal walrus https://github.com/xairy/easy-linux-pwn
There you go, easy ones + will help you in upcoming CTFs. (not PlaidCTF :p)
Alright, time to take off.
# Resources
These are the resources I have found while learning about the binary exploitation.
### Blogs:-
* <https://syedfarazabrar.com/>
* <https://kileak.github.io>
* <https://d4mianwayne.github.io/>
* <https://ctf101.org/binary-exploitation/buffer-overflow/>
* <https://blog.skullsecurity.org/category/ctfs>
### Youtube:-
* <https://www.youtube.com/channel/UCi-IXmtQLrJjg5Ji78DqvAg/videos>
* <https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN>
### Wargames:-
* <http://pwnable.kr/>
* <http://pwnable.tw/>
* <http://pwn.eonew.cn>
* <https://www.root-me.org/?lang=en>
* <http://smashthestack.org/>
* <https://exploit.education/>
### Pwn Related Stuffs:-
* PwnTips - <https://github.com/Naetw/CTF-pwn-tips>
* Quick guide -<https://trailofbits.github.io/ctf/exploits/binary1.html>
* Pwn Challenge List - <https://pastebin.com/uyifxgPu>
### Stuff Robin gave me:-
* Course materials for Modern Binary Exploitation by RPISEC - <https://github.com/RPISEC/MBE>
* Learn ROP - <https://ropemporium.com/>
* For Linux binary Exploitation - <https://github.com/scwuaptx/HITCON-Training>
* Intro to binary exploitation / reverse engineering course - <https://guyinatuxedo.github.io/>
* A collection of pwn/CTF related utilities for Ghidra - <https://github.com/0xb0bb/pwndra>
* Some pwn challenges selected for training and education. - <https://github.com/BrieflyX/ctf-pwns>
* A set of Linux binary exploitation tasks for beginners on various architectures - <https://github.com/xairy/easy-linux-pwn>
* ASM Basics - <https://asmtutor.com/#lesson1>
Just compiling them for easier use 
Good job, though that's not even 40% of total resources :(
I say bored, yet have so much stuff to do.
https://www.autopsy.com/support/training/covid-19-free-autopsy-training/
Promo code: covid19-984730-free
Hurry up, guys and girls, this works only till 15th
~500$ worth now for free
@stray orbit looks great, thanks! Does anyone here have any experience with Autopsy?
I got some...maybe I can be at any help @crimson thunder ?
Just wanted to ask if you recommend using it
I've heard good things in the past, and it's supposedly gotten better since
Very popular with lawenforcement
Love all those binary exploit resources above! Here's another one to add to the list: https://exploit-exercises.lains.space + https://old.liveoverflow.com/binary_hacking/protostar/index.html when you get stuck
Protostar is a good for those starting out, paired well with the book "Art of Exploitation" - https://nostarch.com/hacking2.htm
View excerpts from the book Download the code from the book About the LiveCD
For those more advanced, this was a good talk, would love to see a room based on it at some point - https://www.youtube.com/watch?v=6-Et7M7qJJg
@crimson thunder ... Generally a great helper and easy to use. Is it worth trying it? It depends what you are trying to achieve!
it's worth learning autopsy if you plan on doing any forensics
Well, honestly I just had a class about digital forensics and I have no reason to learn other than curiosity right now
I appreciate your feedback all
Where did all of these binary ninjas appeared from @white pivot ? You got competition now
@gritty barn Yes captain :)
And no one is going to let Robin down.
i'll follow the binaries stuff after i get a little bit better at privesc s
it seems that even if i get the way in i can't seem to escalate that quickly :c
Oh, practice it.
happend to me on both tomghost and tony
There's a Vulnhub machine with Linux Privilege Escalation which covers a lot of different techniques.
Have a look at it.
on tomghost i had localuser 1 hour before anyone else
still i messed up getting root
Ah, at least knowing your weakness us quite good, you know what to work on.
Try that machine, you'll see changes pretty quickly.
yeah ^^, thanks for your help Robin
for the ones that where wondering about my vim cheatsheet (its my personal one made overtime with help from some other vim users/websites, so I don't think it's complete)
@light hamlet that's really useful!
you using Joplin @light hamlet ?
yah
i knew it
it's the easiest way to hop between machines and still have my papers nearby 🙂
i know
(and not selling my soul to evernote, or something)
i love it ❤️ especially running as local user
i have it on all my devices
i know muri
don't start
I mean, I love cherrytree and all, but I gotta admit that Joplin is so much better for the syncing
Does it do the same kind of node based as cherrytree?
I know it does notebooks
But can notes have subnotes
yes
And subnotes to those subnotes?
Yes!
yes
I, uh, might be willing to take another look
everything that cherrynote does plus encryption
Cherrytree does encryption
@topaz gulch it even has a terminal application
joplin as well
they just updated it as well 😮
Did you not do Cherryblossom? @gritty barn 😆
not yet
it's on my list
need to polish my skills but let's move #thm-community-media
Trust me, you are going to get intimately familiar with cherrytree encrypting stuff...
Learning vim feels like learning a new programming language
It kinda is
But like a programming language
You'll be infinitely better off knowing it
Why did I have to scroll up in here, now I am going to spent the day moving all my cherry tree notes over the Joplin.
to**
bwahahaha, welcome to the cool gang
you might be able to export as html and import again
For those struggling with VIM and it's commands, try this: https://vim-adventures.com/
@shut ferry oh dude.. I didn't even know that was a thing?!
Yeah, I found it when doing the VIM topic and did a google search and it was the first thing to show.
Handy eh.
I'm gonna play that later tonight 😄
Hahah
Perhaps @somber plaza could implement it into their topic. 🙂
It's certainly helping me.
@shut ferry Could very well do! Maybe even a part 2 for more advanced commands if there's demand?
🙂
a nice list of commands to excalate: https://github.com/mubix/post-exploitation/wiki/Linux-Post-Exploitation-Command-List
A cheat sheet list for a lot of different programs all on one website: https://highon.coffee/blog/penetration-testing-tools-cheat-sheet/
Penetration testing tools cheat sheet, a high level overview / quick reference cheat sheet for penetration testing.
i don't know if it is good channel, i suppose so. i'd like to as about reversing.kr, are challs from there are for real malicious? especially i mean 'easy unpack'?
https://github.com/newtonsart/game-of-life
In memory of John H. Conway
I guess this goes here...
@thorn thorn Unless they explicitly told you to run binary in VM, otherwise it's just a bunch of crackmes.
https://www.pluralsight.com/ is offering free training
Was it good?
I bashed this video together to show you the loose concept of a buffer overflow and how abusing inputs can enable an attacker to execute code or change the behaviour of a program in a noteworthy way. This example is very simple compared to more modern examples which are covere...
found this to be really helpful if you're just getting into reverse engineering and know some C 🙂
What a great tool !!!
https://gchq.github.io/CyberChef/
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
@unborn crest Bookmarked instantly ! thx
Handy as this covers a bit of every tool somebody might use: https://www.h21lab.com/tools/penetration-testing-cheat-sheet
In the link provided by @worn kelp there's a free course on programing with Python (Certified Associate in Python Programming)
just looked through the conversations on the discord and noticed that you are a fan of pivoting @odd quest , would you mind sharing some of your resources with me if you don't mind?
oh, makes sense. sorry for pinging you then!
There's a machine name Wintermute and Tempus Fugit series on Vulnhub that have stack pivoting. @gritty barn
Remember, if you can't find the resources then make one.
very good advice Robin
:D
It's probably a well one known one but this has been a fantastic find for me: https://gchq.github.io/CyberChef/
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
It really is a swiss army knife for everything.
Maybe some of you know about it, but i Found it very cool shell. Maybe you'll like it as i did
https://fishshell.com/
A smart and user-friendly command line shell
Wrong channel @coarse helm 🙂
@topaz gulch wich chanel?
That will also help
@topaz gulch Thank you for the information. I had a question about that box as well. Cheers!
Hey has anyone done the new lfi box
wrong channel
any new tech course or security course offering for free (bcz of covit) ?
security related course is my first choice
Right here you have some resources bcz covit
@shut ferry
https://slaeryan.github.io
Creating egg-hunter shellcode, Reverse TCP shellcode, shellcode encoder, crypter etc
slaeryan’s blog - some rants about Information Security and random stuff
pretty good doc about BOFs http://www-inst.eecs.berkeley.edu/~cs161/fa08/papers/stack_smashing.pdf
pretty good doc about BOFs http://www-inst.eecs.berkeley.edu/~cs161/fa08/papers/stack_smashing.pdf
@solid wadi They have a few more when you go to the index
(i.e. http://www-inst.eecs.berkeley.edu/~cs161/fa08/papers/ or even at http://www-inst.eecs.berkeley.edu/~cs161/fa08/ you can get a lot more)
sidenote.. the Aleph One paper on stack smashing (released almost 15-20 years ago) is still used today as lecture material on UC Berkeley 🙂
just a way of saying baby
def useful
https://github.com/D4mianWayne/PwnLand/blob/master/Format String/overwrite-got-system.md
@white pivot the link isn’t working ;(
404
Fair enough, I'm just creating the study material for upcoming room.
Really? @honest dock
yeah
It's working for me?
works for me too
strange...
it resolves in discord too
Go there and see if you can see files.
works now
must be a pro 😛
@shy thunder Dedicating this week to full Pwning.
Let me know your thoughts 🙂
the format string one is exactly what i need right now
none
oh lmfao
doing it for a job interview
o
BufferOverflows are pain
what's the job

pentester
im fine with bufferoverflows and asm
it's just
when I sit down
and look at those memory addresses for the more complex pwns
oh \
the amount of bleeps I do not give rises to extrodinary levels
😂
but one day
one day indeed
go sleep
will you stop making sense
this could be that day
this is not gonna be that day @shy thunder
is that a challenge, I will force myself to learn nothing all day! 😁
😅
i dont see how those 2 have anythiong to do with eachother


the format string one is exactly what i need right now
@shy thunder I'm your angel then.
In the armssss of the Robinnnn
lmao
just dont have a crowbar in your arm and things should go fine @shy thunder
Robin doesn't do well with crowbars
Head over to #thm-community-media ?
would be wise
I'd say yes, it gives you an insight on how python is implemented in information security.
any good resource to master XSS??
any idea about black hat python ?
@ruby flint yes. i would snag it if you could.
as for cross site scripting. should be a ton of resources online everywhere
@wise fern thnx for responding i already started it today but it seems i'm just typing what he is showing not deep explanation i want something to make me code things by myself
roger.
Have you tried udemy.com
i found alot of very helpful instructor courses on there
you can dig through all the balogna
i will take a look
and find teachers you like
youll love it. and SUPER cheap. also sales all the time
once i got hundreds off dollars worth of training for less than 50
just depends when you go on there.
however, watch out for deprecated videos,
some are old...
i will try but i'm also digging by myself for every line he type to understand how it works
i'm starting to understand sockets already
Sololearn is quite good for free basic programming stuff
ooo, new to me. ill check it out
@ruby flint I recommend SQL particularly
thnx i will take a look
@ruby flint https://github.com/s0md3v/AwesomeXSS
GHIDRA is A software reverse engineering (SRE) suite of tools developed by NSA's Research Directorate in support of the Cybersecurity mission
Info: https://www.nsa.gov/resources/everyone/ghidra/
Source/DL: https://github.com/NationalSecurityAgency/ghidra
Enjoy!
@ruby flint have you checked freecodecamp ?
Hey @gritty barn is there a red team cheat sheet?, cheers
No problem, ill have a hunt around , nice find 👍
@fringe spire my recommendation https://www.sololearn.com/Course/SQL/
Thanks.. i was planning to learn from somewhere since this morning this will help alot
any idea about black hat python ?
@ruby flint Black Hat Python, Gray Hat Python and Violent Python are all worth a look.
Black Hat Go is also worth a look
thnx i already started blackhat python i'm in chapter3 it's nice but sometimes it lack explication but i try to understand with googling
If you're new to Python, check out https://automatetheboringstuff.com/
Analyzing Modern Malware Techniques (Part 4) : https://t.co/iNxm1euAKH
3 : A case of Powershell, Excel 4 Macros and VB6 : https://t.co/MQPTdz9vSv
1 : Fileless Malware - A self loading technique : https://t.co/ad0ghZ13DD cc @danusminimus
110
269
Is there a Linux Base room similar to the Windows Base? Something I can deploy a simple web server for teaching some concepts.
@devout rose probably the kali 2020 VM
Ah yes! Thanks. That'll work.
A hypervisor-level malware analysis sandbox https://github.com/CERT-Polska/drakvuf-sandbox just got released in beta. I haven't tried it yet myself but sounds good!
An upcoming room apart of my malware pathway discusses sandboxing, so I'm gonna look into it to potentially incorporate into that room perhaps
some make poki-themed rooms
@ebon valve I try to avoid Udemy courses usually. Did you get value from this one?
I haven't checked it out quite yet but John was pretty excited about it
I wanted to check out TCM one after hearing good stuff but think discount ended and can't justify near $100 for it. Problem is there are so many out there and never know what's worth considering all the free resources. Would love to do the PWK but budget doesn't allow it at the moment. Have tons of books to read through though
@north saffron TCM has last year's version of his course free on his YouTube
@wet yoke is that the 15 hour video? I've been watching his web application video series halfway through episode 2 and finding it to be pretty good
Yep that's the one. The udemy course goes into more detail on a few other things but you can pick those skills up elsewhere
I wanted to check out TCM one after hearing good stuff but think discount ended and can't justify near $100 for it. Problem is there are so many out there and never know what's worth considering all the free resources. Would love to do the PWK but budget doesn't allow it at the moment. Have tons of books to read through though
@north saffron You can find the discount code for his course on his discord or twitter.
purchased the new iphone se (moving from android). Any education infosec apps I should download that are on iOS?
checkra1n
quite comprehensive. i'll take it
@delicate pelican Would I be correct in thinking that book is not free?
It is not, I happen to have it on my other desk
Oh, that's my fault. I just googled for a pdf and grabbed the first thing I saw. Not exactly responsible, I'll admit.
Sorry about that.
I mean I've got ISBN numbers for both red and blue
Yeah the copyright disclaimer in the PDF implies it shouldn't be a PDF
A better resource: https://github.com/droberson/rtfm
The PDFs are legit a scan of the book ,you can see the scanning shadows 

this is a pretty cool command:
--exclude 192.168.0.250,10.10.0.3.254 \
| grep "Nmap scan report for" \
| awk {'print $5'}
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology and Resources/Linux - Privilege Escalation.md Some really cool stuff on here
Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)
Hello everyone
In burpsuite grep match option , anyone hv sheetcheat for that
Example, but i cant find this sheetcheat somewhere
By TCM ^^^
Learn network penetration testing / ethical hacking in this full tutorial course for beginners. This course teaches everything you need to know to get started with ethical hacking and penetration testing. You will learn the practical skills necessary to work in the field. Thro...
@raven owl That's last year's version of the course @fringe spire just mentioned before you 🙂
@wet yoke ouch sorry didnt notice.
It's ok, there's lots of versions of that course around the place, it's easy to overlook things 🙂 It's also on the TCM youtube channel and elsewhere too I believe
@raven owl YouTube one covers alot of stuff that is not covered in udemy. So both are good. Depends on person's choice.
2,908 votes and 322 comments so far on Reddit
this is a pretty cool command:
--exclude 192.168.0.250,10.10.0.3.254 \ | grep "Nmap scan report for" \ | awk {'print $5'}
@gritty barn I don't get it, whom do these IP belong to? I mean aren't they variable everytime? Please elaborate if possible!!!
Umm I see like two diff THM ip's, then a personal IP...so still can't make out whats goin on in this command?
if you read the manual you'll see what it does
hmm
it's not my own command as i copied it from https://github.com/droberson/rtfm
Got the answer, Thanks!
in case if it helps someone Free Autopsy Training Course :
https://www.autopsy.com/support/training/covid-19-free-autopsy-training/
Free before 15th May 2020
Can anyone make any recommendation for learning how to make linux kernel modules/rootkits?
And before someone says "this is blackhat", it isn't but hey merry Christmas, bite me
I'm looking into kernel modules on my own right now but not enough knowledge to make rootkits lmao.
I started reading "Designing BSD Rootkits" recently but it's more of a technical guide around the kernel and only applies to BSD sadly
Some people say that there are three things you have to do before you die: Write a book, have a child and plant a tree. Actually, the three things you have to do before you die are: write your own IRC bot, create a massive framework that only you will ever use and code an awes...
has anyone purchased the certmaster for sec+ ?
I'd like to sit for the exam this summer and wanted to know if the extra help is worth it
@tight mulch I found the certmaster to be helpful. I enjoyed the extra multiple choice questions that came along with it.
SIEM Fundamentals - Promo Code: SIEM
https://www.elastic.co/training/specializations/security-analytics/elastic-siem-fundamentals
https://register.gotowebinar.com/register/250073331082302477 - Linux Forensics Magical Mystery Tour with Hal Pomeranz (1-Hour)
You can share your stream in #thm-community-media @wanton olive 🙂
also @wanton olive
Thanks.
No problemo
is there a proper and free alternative to burp suite?
ZAP
thanks, i will try that
check out a room on THM about it
oh nice, i didnt realize there was already a room for this
Masterpiece ^
Amazon.com: Red Team Development and Operations: A practical guide eBook: Vest, Joe, Tubberville, James: Kindle Store
^Recommendation that was given to me, super cool book
This publisher made books for download for free, there is some network security and programming books in here. Take a look and download if you want!
@mystic trail No discord invites unless approved
@odd quest ok thank you
is there a reason why is this considered a resource @grim wolf? It's a write up of a low hanging fruit in my opinion without presenting any technical aspects to it other than using awscli
This sounds real neat - could be a little thing for a room at some point O.o
@paper cape Only material that you're allowed to distribute please
Am I not? I own the license to distribute and own the material
But I'm not going to do something if it's going to get me banned, my apologies
This YouTube channel for only knowledge sharing. https://www.youtube.com/channel/UCIGc6EmiuX1pHsx2TvHUedA?view_as=subscriber?sub_confirmation=1 Our goal is t...
if you want to post that license that allows you to distribute it to the masses for no cost, we can talk lol
A-Z Pen Test course with a huge discount
https://www.eduonix.com/ethical-hacking-masterclass?coupon_code=INSTA25
This one looks pretty dope ^^^
But i used all of my money from my bank account so imma go cri 😢
@unreal ibex #thm-community-media
@odd questok
@barren vault that's pretty sweet I always think about how useful certain aliases could be to speed things up but always forget to set something up. 👍
Thank you @north saffron saves a good 30 seconds 
haha it can all add up, right now I only have things like pbcopy, a gobuster and nmap one and optional's "up" alias to get tun0,pwd,and start up a http.server connection but now will be on the lookout for more or just think of what may improve my workflow and incorporate it. More tools in the toolkit 👍
Have to fix it, messed something up
I made one for the up alias too if you want me to send it to you?
It's the same one Optional uses now.
it's probably the same one then, got it from his discord a week or so ago and works fine. only change I made was to drop port 80 on it so I can just run it on port 8000 by default or specify my own port when running it incase 80 doesn't work
80 won't work if you're not root or you don't have cap bind set
don't know what cap bind is i'll have to google that but I believe that applies to the first 1024 ports, they won't work without root.
@dense musk Capabilities are a more granular method of controlling permissions. Suid's grown up brother
Cap bind allows you to bind to low ports without running code as root
https://github.com/sinfulz/JustTryHarder
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam.
(Inspired by PayloadAllTheThings)
Disclaimer: none of the below includes spoilers for the PWK labs / OSCP Exam.
Some handy-dandy juicy windows priv esc stuff on there
oh hey @winter depot! Nice repo :3
Thanks 🙂 @sturdy shell
You mind find this of interest @shut ferry
https://github.com/jivoi/awesome-osint
amazing resources
Thank you @sturdy shell

@arctic mist What can it give you? Interested in it but not sure what it is exactly
if you go on the link it will tell you ^^ @shut ferry
Ty
^
Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate issues of dependency resolution involving deprecated modules. - repo description
i just wanted to thank the person sending this 😿
it's a good repo
Wasn't sure if it was okay to post so I was looking further first
it is fine, you can re-post it
All Binaries:
https://busybox.net/downloads/binaries/
https://github.com/ryanrohypnol/Reverse-Shell-Bash-Alias/ -- Fixed the Python shell (needed to escape the double quotes) thanks to @topaz gulch ❤️
Any framwork for phishing??
google is your friend for that @devout abyss there are like 2 that i know are very popular
Okk
@devout abyss Also, if that's for anything illegal, please a) don't and b) keep it out of the server.
Phishing frameworks being one of those things with limited uses...
it's a debatable subject
Highly
we are in the point of implementing phishing campaigns for our end users
I mean there’s soon to be a room based on a phishing framework so
Potentially anyway
There's already a room on phishing
found this on a reddit thread:
https://digital-forensics.sans.org/media/DFPS_FOR508_v4.6_4-19.pdf
thought it was quite cool because i'm not familiar enough with Windows process to know when one looks malicious 😄
https://www.youtube.com/watch?v=vBJj7YMVn6I taking notes with vimiwki. Anyone tried it yet?
==========Amazon Links==========
► Buy Anything: https://amzn.to/3eT3gsR
► Blue Yeti USB Microphone: https://amzn.to/34oj8P8
► Logitech C920 Pro Webcam: https://amzn.to/2JUYiNL
► Neewer 176 LED Video Light: https://amzn.to/2xbK0Wu
💖 Subscribe and ding the bell for more vid...
Hello, I would like to share with the community my Write-Ups resources of the path of "OSCP Preparation" in Spanish. I hope it works for you, thanks: https://github.com/KAIT07/OSCP-PREPARATION-THM
what resource do you guys recommend for practising / mastering egrep's regex specifically?
should I just read up on perl's regex? I have an exam coming up and our material doesn't quite cut it I'm afraid
Almost every regex pattern is same, I'd say head over to codewars or leetcode and practice with some of the regex challenge. @crimson thunder
@white pivot thanks, that helps a lot
:)
Not sure where else to ask this: what sites are good for publishing witeups?
Alright. Thanks
does anyone have the up script that optional uses
@peak birch Create your own, it's not that difficult
I know but I don't know how to get the ip address from the script
I used the SimpleHTTPServer but I don't know how to get the ip address
@peak birch ip a s or ipconfig and some grep wizardry. Use the python3 http.server, not the SimpleHTTPServer
ok thanks
@peak birch Python2 is deprecated, try to avoid it
I know but I like it
There's a reason
they only have python3
Because it's deprecated
@peak birch Python2 has reached it's EOL for quite some time, it's time to move on to Python3.
yeah I guess I have to turn every one of my python tools to python3
that's gonna take some time
https://github.com/officialdarksheao/insta-kali Sharing a dockerfile I'm extended from kali's rolling docker image, been adding to it as I complete labs. Free for the taking - I get a lot of use of a command to spawn new hackboxes in seconds
https://github.com/newtonsart/visual-studio-assembly
I thought that this would be useful for some of you
i saw something online about that
Brand new tool similar to bloodhound for azure ad https://github.com/Azure/Stormspotter
@azure widget great share. I'm getting summoned to do some Azure work soon. Will definitely keep that tool in mind
have a look at this one too, it's for 0365 infrastructure @arctic mist https://github.com/nccgroup/ScoutSuite
Since I’m dropping all the resources today here’s a great pen testing template for Joplin https://github.com/tjnull/TJ-JPT
Not completely pentesting related per-se, but a great tool for browsing github repo's quickly:
Github on steroids
match command-line arguments to their help text
crazy framework for Osint if you need to do anything with Osint this framework probably has a tool for it https://osintframework.com/
Places are limited for our next webinar! We'll be walking through some of the Binary Exploitation challenges from the Spring Capture the Flag competition. See you there? 🤓https://t.co/SHNVVb0Svg
Hi there, I recently purchased "automate the boring stuff with python" preparing myself for the pwk material. Reading through so far has been good but I have the feeling sometimes it goes a little bit too fast on the basic ( I come from 0 programming background ). I was wondering should I stick to it or should have bought the python crash course instead ? What are your thoughts guys ?
@tacit tangle I really like https://www.sololearn.com/Course/Python for learning languages
Thanks @odd quest
I'll have a look
Looks great, this alongside with my book and some YouTube corey Schafer
Should be good for now
👍