#resources
1 messages · Page 6 of 1
thought i would share :https://www.hotukdeals.com/deals/certified-network-security-specialist-certified-by-network-security-cyber-defence-cnss-worth-500-expires-3152020-3463076
^ is that any good?
It's a nice course @crimson thunder .I've personally done it
Haven't taken the exam though
VIM Regular Expressions
https://unc0ver.dev/ -- iPhone 13.5 jailbreak & below is released
Also, in reference to what @honest dock said. I always send people to https://regexone.com/ to learn basic Regex. It's a great interactive & simple website.
RegexOne provides a set of interactive lessons and exercises to help you learn regular expressions
^^
https://aem1k.com/aurebesh.js/#_ -- Bypass Sanitation
im keeping that
^
wth is this?
?
on my stream
[Head to https://www.squarespace.com/nostalgianerd to save 10% off your first purchase of a website or domain using code NOSTALGIANERD]... The History of USB; So many USB plugs, so little time. Take USB Mini-B, what happened to that? What happened to USB Mini-A, Why did we mo...
@shut ferry Kinda sketch to me
@shut ferry Kinda sketch to me
@odd quest definitely “full access to every course and practice exam”
I don't know, i've just reposted it
It claims the possibility to win a lifetime access of stuff
But then again, what do i know, i'm watching the gladiator
Yeah man, not a great idea. Some are legit but for the most part it's just a scam to get their products more known
Mmh, good to know then
Pentester Academy
@narrow hinge Thanks for that! I'm curious if anyone else has taken the ICSI "Certified Network Security Specialist" course and could give feedback on it?
I have started today and completed the first module it is mostly text based and a few short videos, there are hands on activities too, so far the course is alright @shell hound
Awesome. I just enrolled, so I'll start it in the next few days. We'll see how it goes and if I want to take the exam or not
@narrow hinge Thanks for that! I'm curious if anyone else has taken the ICSI "Certified Network Security Specialist" course and could give feedback on it?
@The.Moodle#2136 just waste of time to me. Only boring theory. They don’t even included enough screen shot as well as video. They are just selling certificates and marketing their product (not education)
https://github.com/D4mianWayne/roppy
Beta version but ready to use, documentation will be fully updated by tomorrow :)
"the way of the console cowboy" https://www.youtube.com/watch?v=Lqehvpe_djs
00:17 - Why I like Tmux
01:20 - Creating Tmux Session
01:45 - Bash: Ctrl + R - Recursive Search
02:02 - Tmux: Prefix Key (default Ctrl+B)
02:05 - Tmux: New Window - Prefix c
02:07 - Tmux: Switch Window - Prefix #
02:36 - My Tmux Config
02:50 - Demo of "nested tmux"
04:00 - Tmu...
Documentation is completed.
SQL tutorials needed
@feral hawk sololearn
@odd quest haha Need fr 🥴
@feral hawk huh?
Seriously. Sololearn has SQL tutorials
I recommend them.
They are free.
There's an app too.
@odd quest Thank you fr! Looking into it now
@feral hawk https://igs.sqlzoo.net/wiki/SQL_Tutorial has some nice exercises too
@crimson thunder Thank you!!
Hey. Guys do you know any sites similar to TryHackMe (like with a lot exercises) but more towards sysops, devops, admin etc.
?
just updated this, now it supports 32 bits, 64 bits, both Intel and AT&T syntax
also it supports Intel syntax with c libraries
https://github.com/newtonsart/vscode-assembly
Hopefully these are going to be beneficial for some of you
Thanks 😊
Hello! I'm a highschool student and ive been dabbling with hacking for the past couple weeks and i really enjoy it; only thing is ive hit a wall and dont know how to grow my skills. Are there any resources that help teach people the art of hacking? Thanks!
The entirety of THM lol
I’m a noob and just doing the challenges and reading the info and when stuck looking at walkthroughs to c where I’m going wrong or what to look for
Yeah im a noob too, all i know how to do is DOS, capture WPA handshakes, and boot people off wifi with deauth commands but thats it
Ive been looking for a group of people also intrested in hacking but where i live its not too popular
I suggest just looking at the challenges and seeing what ur interested in and having a go
If stuck ppl answer in here if ur not able to find out from the materials provided or online which for the most part u can
Alright ima experiment with the challenges then. Thanks dude!
Gd luck
@stone kraken Do some walkthroughs first
Hey @odd quest
👋
How goes it?
Oops
Well i havent really gotten the chance to do anything in THM yet
My OpenVPN isnt working
Ight can do! Sorry.
ty
does anyone know if there are windows docker images that you can network together?
Docker containers are Linux only wait what
@open roost you searching for this? https://hub.docker.com/_/microsoft-windows
The official Windows base image for containers
Ok so the host OS needs to match the container OS
IIRC docker on windows requires virtualization enabled which we can't do on AWS for a reasonable price
Maybe that's for running linux containers on windows though.
I have just start as a COMPLETE BEGINNER.Whats the suggestion for me?
Thanks @worn kelp
but If you don't know anything of networks, bash.... you should start in that point, http://cybersec-lounge.com/ check this out
Yeah ,Im a very beginner . But have knowledge in C, C++ programming knowlwdge.
What to write here?
This is the wrong place for this
If you need help with a room you can ask in #room-help, and for problem with the tryhackme vpn, ask in #site-support
Where is that screenshot from?
TryHackMe Open and run the OpenVPN GUI application as Administrator
ported my gtfo tool to golang
https://github.com/mzfr/go-gtfo
any good sources to learn assembly for reverse engineer!!!!!!!!!!!!!!!
Ooo ty 😃
@tribal walrus That compiled list of resources is awesome. Thanks for that! Do you have any favorites in there? Things that you think are better than others?
Nightmare: an intro to binary exploitation / reverse engineering course based around CTF challenges.
That wasn't in compiled resources?
Probably one of the best archive of write-ups and challenges.
@odd quest Send the message you were typing
I didn't tab back to my game
holy hell
thats a lot
Hold up
Did somebody from UCF write this?
cuz HackUCF is the hacking club from that school, which is where I went lol
CODE BLOCKS OH NOOOO
@timber harbor /usr/share/wordlists/dirbuster/
That's most commonly used one.. Depending what your are trying to do.
you can download some from google?
am i dumb or i cant find any
Not familiar with arch but there must be something on the internet that would help.
Does anyone have any examples of using the PIL(python imaging library) in CTFs
Stego?
@shut ferry are you asking for resources?
So does anybody know of any software that will aggregate all of your IOT devices and tell you if any of them need firmware/software updates? It's not quite a SIEM but Idk what its called. Is tehre something like this out there?
Hey guys what's up. I created a sub domain search automator utilizing crtsh and python. You can check out the tool on my github repo. Hope it might help you with your information gathering process
https://github.com/shafdo/subdomainFinder
hugging hugging hugging
So as this is starting to "take shape" I'd like to just leave this here, maybe someone uses it in a future project :)
More routes coming soon, I plan to update it with most publicly available routes and maybe some authenticated ones if admins don't have anything against it ;) (pssst @forest pecan)
https://pypi.org/project/thmapi/
https://github.com/szymex73/py-thmapi
So as this is starting to "take shape" I'd like to just leave this here, maybe someone uses it in a future project :)
More routes coming soon, I plan to update it with most publicly available routes and maybe some authenticated ones if admins don't have anything against it 😉 (pssst @forest pecan)https://pypi.org/project/thmapi/
https://github.com/szymex73/py-thmapi
@tribal gull I like this a lot - I dont see any reason why I can't add that in. "Build your own lab off THM API's"
Daymn
A lot of functions too
I have a lot more to add, i have 91 routes saved in insomnia
favourite Golang resources?
@tribal gull nice! An API wrapper. I made one for WoW once
@crimson thunder gorillamux, gliderlabs ssh,
Has anyone used this? I couldn't get mine to boot for some reason
https://raspwn.org/
The World's Second Most Insecure Operating System!
For box creators
Sym linking bash history to dev null on multiple users
for i in $(ls /home); do cd /home/$i; ln -sf /dev/null .bash_history; done
ooh nice
also find /var/log -type f -delete for nuking logs before exporting
also
find /var/log -type f -deletefor nuking logs before exporting
@obsidian iris Watch that one.. some services really don't like their logs being destroyed. Learnt that one the hard waywithout a recent snapshot
I've yet to meet one that doesn't mind having the log wiped though 🤷♂️
i did it on dogcat and also my new room and they're both fine 🤷
nuking logs isn't a big deal because running services just create a new file/append to the same one if it's still there :p
Hm, I managed to spectacularly kill a webserver doing that with my first box...
Granted, there's a good chance I messed it up back then and just haven't bothered to read more into it 🤷♂️
the find thing i posted just deletes the files and not the folder structure
if you deleted the folders that might have been what messed it up
Uh... There is a pretty good chance that is exactly what I did 🤣
Funny, I haven't thought about that in quite some time -- I usually just delete certain ones and go from there
Thanks 🙂
I was wondering too about the use of find instead of rm -rfing the thing. TIL, thanks guys
A simple guide to sudo configuration (with no EBNF!), Author: Abhijit Menon-Sen
Keep coming back to this guide
didnt fully understand these attack when making attacking kerberos but thanks to these I kind of get it now hopefully these help someone
bloodhound handbook literally everything you could ever want to do with bloodhound https://www.ernw.de/download/ERNW_DogWhisperer3.pdf
For those that have done my Shodan room, this looks great https://github.com/ninoseki/shodan-dojo
which are the rules for this channel? can i share some copyrighted material?
If you're sharing the actual material and don't have a license to do so, then no
If you're sharing a link to material which other people may obtain a license for, then yes
ok perfect, thanks
Hey everyone! I just started a new blog and wrote my first box write-up for vulnversity. Would love some feedback on it. Thanks! :)
https://fnginfosec.github.io/tryhackme/vulnversity.html
Dunno if someone could be interested. There are a lot of study notes about pentesting. Some of them are a bit dated, but usefull https://github.com/AnasAboureada/Penetration-Testing-Study-Notes/tree/master/enumeration
Found this somewhere on another discord: https://github.com/Ziani52/Enum_For_All
@tender yoke I like the design of your blog, but you have alt tags for images with no alt text. Please consider either removing them, or preferably adding alt text? 🙂 (PS. Alt text will increase your SEO) 😉
he likes pointing that out ^ lol
I @ the wrong person lmao my bad
https://lwn.net/Kernel/LDD3/ Other mods, the book is licensed under Creative Commons share alike, as well as being sold by Orielly
Kernel module stuff
https://wiki.zenk-security.com/doku.php => french website but very useful
@tepid patio Awesome, thanks for pointing that out! I had them as placeholders to add text in later, then totally forgot about it haha XD
Appreciate the feedback 🙂
@wraith holly don't ask for people to steal content for you. This goes against the server rules.
@wraith holly don't ask for people to steal content for you. This goes against the server rules.
@odd quest ok sorry
@tepid patio Awesome, thanks for pointing that out! I had them as placeholders to add text in later, then totally forgot about it haha XD
Appreciate the feedback 🙂
@tender yoke No worries! If you ever need help with A11Y stuff, LMK. Not an expert, but I care deeply about it 😄
@tepid patio Haha will do! Thanks~
Be prepared to be pinged all the time lol. 
eh don't worry, I always have time to fix A11Y issues 😉
📢 Announcing the 2020 Cybersecurity Bootcamp hosted by the #OCRI. Learn from esteemed faculty and industry professionals and earn benefits for program completion!
Spots are filling up fast so sign up TODAY! https://t.co/XXAhJR5iAJ
#CyberSecurityAwareness #Innovate #workforc...
@topaz gulch mind pinning this?
gotcha
that's a really valuable thing ^^^
@gritty barn can I register from wherever? is it all online?
is that registration link broken for anyone else?
@honest dock ty, went there myself but it was loading forever until you sent me the link lol
lol
As I've been progressing on my journey in offensive security, my .bash_aliases has been growing. Mainly to save keystrokes and prevent errors. Here it is for your consumption.
(This is the first thing I've shared, please be nice.)
https://github.com/algernope/.bash_aliases/
(Pull requests accepted)
nice one @upper bolt
@upper bolt hey! Love using .rc files. If you're into saving keystrokes, maybe consider making some of them 1 letter long? This is in my .zshrc file 🙂 ```
alias m='sudo msfdb run'
alias n='grc nmap -p- -A -sC -vvv'
alias g='gobuster dir -w /usr/share/wordlists/dirb/big.txt -t 100 -u '
I will add a section with shorthand aliases, thank you for the suggestion!
Give that shot...
It probably should be a script file
👀
I keep it in my bash aliases
cpro () { usage () ( echo "Usage:"; echo "cpro +anon|-anon|+time|-time"; ); if [ $# -eq 0 ]; then usage; return; fi; time=0; anon=0; timelock=false; anonlock=false; for input in "$@"; do case "$input" in "+time") time=$(($time + 1)); if [ $timelock == true ]; then usage; return; else timelock=true; fi ;; "-time") time=$(($time - 1)); if [ $timelock == true ]; then usage; return; else timelock=true; fi ;; "+anon") anon=$(($anon + 1)); if [ $anonlock == true ]; then usage; return; else anonlock=true; fi ;; "-anon") anon=$(($anon - 1)); if [ $anonlock == true ]; then usage; return; else anonlock=true; fi;; *) usage; return; esac; done; if [ $anon == 1 ]; then export PS1="$(echo $PS1 | sed -e 's/\\\u/anon/g' -e 's/\\\h/anonymised-terminal/g') "; elif [ $anon == -1 ]; then export PS1="$(echo $PS1 | sed -e 's/\<anon\>/\\u/g' -e 's/anonymised-terminal/\\h/g') "; fi; if [ $time == 1 ]; then export PS1="$(echo $PS1 | sed -e 's/\\\[\\033/\[\\D{%F %T}] \\\[\\033/') "; elif [ $time == -1 ]; then export PS1="$(echo $PS1 | sed -e 's/\[\\D{%F %T}] //g') "; fi; }```
Mind if I add that with a reference to https://github.com/MuirlandOracle/linux-config/tree/master/Bash/Prompt-Alterations ?
Sure -- if you add the reference. Free publicity 🤷♂️
You may find that one useful too if you're going for that kinda thing
That for the actual functions
My linux mint install likes the alias but my kali 2020 install doesn't ... 🧐 looking into it now. the error is something about unexpected end of file while looking for ')'
There is every chance I copied it wrong. Lemme know if I did. Those have all been tested on Kali/Ubuntu and should be up to date
Which one isn't it liking @upper bolt?
Yeah it works great in mint 19
but in my kali it says source .bash_aliases -bash: .bash_aliases: line 2: unexpected EOF while looking for matching `)' -bash: .bash_aliases: line 90: syntax error: unexpected end of file
yeah
idk why it's parsing it differently ... yet 🙂
Ah, it does work.
cpro () { usage () ( echo "Usage:"; echo "cpro +anon|-anon|+time|-time"; ); if [ $# -eq 0 ]; then usage; return; fi; time=0; anon=0; timelock=false; anonlock=false; for input in "$@"; do case "$input" in "+time") time=$(($time + 1)); if [ $timelock == true ]; then usage; return; else timelock=true; fi ;; "-time") time=$(($time - 1)); if [ $timelock == true ]; then usage; return; else timelock=true; fi ;; "+anon") anon=$(($anon + 1)); if [ $anonlock == true ]; then usage; return; else anonlock=true; fi ;; "-anon") anon=$(($anon - 1)); if [ $anonlock == true ]; then usage; return; else anonlock=true; fi;; *) usage; return; esac; done; if [ $anon == 1 ]; then export PS1="$(echo $PS1 | sed -e 's/\\\u/anon/g' -e 's/\\\h/anonymised-terminal/g') "; elif [ $anon == -1 ]; then export PS1="$(echo $PS1 | sed -e 's/\<anon\>/\\u/g' -e 's/anonymised-terminal/\\h/g') "; fi; if [ $time == 1 ]; then export PS1="$(echo $PS1 | sed -e 's/\\\[\\033/\[\\D{%F %T}] \\\[\\033/') "; elif [ $time == -1 ]; then export PS1="$(echo $PS1 | sed -e 's/\[\\D{%F %T}] //g') "; fi; }```
@topaz gulch What does this do? From what I gather it's terminal PS1 stuff 🤔
Seems to only be it whining for some reason
@spiral zodiac look at the readme in that dir
anonymizes the terminal, adds timestamps
@spiral zodiac That ^^
Lets you pick a combination thereof
Took a couple of hours to get working with variable scopes, but worth it in the end
the logging functions also look nice :)
Figured there was something missing there 🤷♂️
They don't do tmux, which is a pain. Or rather, they do, but you need to log each pane differently
Very little you can do about that though, unfortunately
There is, I believe, a tmux logger plugin, which I may look into
This one I think: https://github.com/tmux-plugins/tmux-logging
That one ^^
Oh, yeah
That does it by pane as well...
Forgot that
Does essentially the same thing
There's also a terminator logging plugin, but I've never used it 🤷
Also, ew, terminator
https://github.com/algernope/.bash_aliases/commit/f1b292c210ea76104d4d3e8d317283d459996e8e
https://github.com/algernope/.bash_aliases/commit/8effc7acc6997841ac4f0f8106fb7b1afb55441c
Thank you again!
i wanted to master pwn challenges in CTFs. Any route or like direction u guys can point me to? I always skip those
@icy marsh pwntools and even boot2roots help
InfoSec skills are in such high demand right now. As the world continues to turn Read more
500 million+ members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities.
Script for fast nmap scan
Want to crack some hashes but your VM is too slow? Here's a cool tip: you can (ab)use Google's Colaboratory to spin up two beefy graphics cards to do the cracking for you. It's free, and works really well! Get started here: https://t.co/T4dESE10jy
108
Seems sketch and the picture doesn’t even show a cracked hash it’s exhausted 😆

same performance as my 1070
Hashmode: 0 - MD5
Speed.#1.........: 20221.8 MH/s (65.80ms) @ Accel:64 Loops:512 Thr:1024 Vec:1
Hashmode: 1000 - NTLM
Speed.#1.........: 35724.9 MH/s (74.59ms) @ Accel:64 Loops:1024 Thr:1024 Vec:1
Hashmode: 3000 - LM
Speed.#1.........: 19972.5 MH/s (66.39ms) @ Accel:512 Loops:1024 Thr:64 Vec:1
vs
Hashmode: 0 - MD5
Speed.#1.........: 19846.3 MH/s (50.39ms) @ Accel:64 Loops:1024 Thr:1024 Vec:8
Hashmode: 1000 - NTLM
Speed.#1.........: 35199.9 MH/s (28.31ms) @ Accel:64 Loops:1024 Thr:1024 Vec:8
Hashmode: 3000 - LM
Speed.#1.........: 15974.6 MH/s (62.65ms) @ Accel:1024 Loops:1024 Thr:64 Vec:1
still better than my igpu
tru
https://github.com/jpillora/chisel/releases
Really good port forwarder/ socks proxy, if you need help for usage Ippsec has a tutorial on his youtube
Any good resources on learning bypassing web security? Stuff a bug hunter would typically do? Not trying to learn for bug hunting specifically, just the techniques they use to do so
If that makes sense...it's early
depends who you're up against tbh, if they're cloudflare, you're whipping out zerodays
@dusk nova Check out: The Bug Hunters Methodology by Jason Haddix https://github.com/jhaddix/tbhm
Thanks!
Just got this email, eLearnSecurity is having a discount in red team courses until the end of June
Only if i could apply that to the eJPT exam voucher 😢
Yeah you can't, but I'll think about buying PTP + an exam voucher with this
well now i am thinking to get the Full version for eJPT as i will be saving around 100$ excluding tax.. exam voucher gonna cost around 250$ anyways so its better to just get full version at 350$ instead
that way i would have a free retake and time for labs.. seems worth it
Yeah but a lot of people here have said that the barebones tier is enough for the ejpt specifically, that's why I'm thinking PTP
Well i am planning to keep backup plans as well anyways 😄 but instead of PTP my plan is to start studying for OSCP on my own for almost one and a half year then go for it
has anyone tried this? looks like a cool project. I might start using this in tandem with linpeas
https://github.com/diego-treitos/linux-smart-enumeration
Hmm, yeah I've used it a couple of times.
Always a good plan to have choices when it comes to PrivEsc. Compare the outputs between linPEAS and LSE and see if there's anything that one or the other does not catch.
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology and Resources/Linux - Privilege Escalation.md I'll keep linking this
the checklist is a great place to go when you hit a hall
@spark hedge I've used it a lot. I prefer it to LinEnum
LinEnum is too verbose for me. This let's you specify how verbose you want it
PEASS is great. The accompanying site from the author is invaluable as well: https://book.hacktricks.xyz
https://twitter.com/UC_SOIT/status/1268968321455718400?s=19
Has anyone got any confirmation from them?
📢 Announcing the 2020 Cybersecurity Bootcamp hosted by the #OCRI. Learn from esteemed faculty and industry professionals and earn benefits for program completion!
Spots are filling up fast so sign up TODAY! https://t.co/XXAhJR5iAJ
#CyberSecurityAwareness #Innovate #workforc...
104
I haven't received any mail yet
Has anyone got any confirmation from them?
@shut ferry Nope nothing yet even though it's been more than 48 hours
yeah
same ^
I am pretty sure they only choose people from the same timezone
so they can have at least 90% online all the time
Yeah that's what I was going to say. Living in the states sure have its benefits
@craggy onyx oh what a good book
Also check out https://ired.team as it has very good Active Directory and Kerberos coverage
Omg
just received an email for the Cybersecurity bootcamp, it's only for Ohio residents
i'm sorry guys :c
it's fine
Don't worry! We were simply too good for them and they didn't want us to embarrass their students 
^^
Learn penetration testing in this course. You will learn the common tools and methods used by ethical hackers.
💻 Download All Lab Files: https://licensetopentest.com/
✏️ Must Read LPT vs OSCP Comparison: https://sagarbansal.com/lpt-vs-oscp/
Course created by Sagar Bansal.
⭐...
Enjoy some free content
https://www.postgresqltutorial.com/postgresql-cheat-sheet/
a nice postgresql cheat sheet I found
Ciphey - Automated Decryption Tool using Deep Neural Networks & Advance Natural Language Processing. Something I've been working on for a while! Input encrypted text, Ciphey will decrypt it and give you the plaintext. Some cool features:
- 20+ encryptions supported (hashes, encodings, basic encryptions)
- Deep neural network for finding what the text was encrypted with
- Custom built natural language processing module for identifying plaintext
- C++ core, blazingly fast.
- 20,000 tests so it's mostly bug free
Coming up very soon:
- Better plaintext identifier. 99.3% accuracy on English, 99.87% accuracy on CTF flags - especially THM flags ;)
- Faster cipher detection module with much higher accuracy (a 40% increase in accuracy, 30% in speed).
- Multi decryption levels. Your input is base64 -> binary -> caesar? No worries! Ciphey will find it.
- Custom input into the NLP. Is your flag format noob{flag}? or something else? Ciphey will learn and handle it.
- And many, many more encryption methods.
https://github.com/Ciphey/Ciphey
good work, can't wait to play with it
^^ if the pip version is significantly slow (my pip version is, >10 seconds to solve some things) try git cloning, that's much faster for some reason but I'm not quite sure why
Thank you very much @odd quest !
Hope it fits, but its free for the next 9 hours......
Yo thanks man
Looks tasty nice find
@chilly parcel got it, thanks! about the second link, have you found a way to add it to your courses? because I clicked "enroll" but it doesn't show up in there with the rest of them nvm, got it
Just a tool I created that I thought would help people!
Use it to monitor your connection with the CTF and connect with OpenVPN in one command!
Prevents you from having to constantly ping the box and is easy to use with tmux or terminator (very small pane)!
Please let me know what you think?
https://github.com/cybertheory/ctfmonitor
Moved from general at the request of @night holly !
recommended tutorials for bash scripting?
no he asked for it on #room-help
Hi, y'all.
I have written a script that will do a nmap scan and a gobuster scan on an IP and will output in a folder of your choosing
This is just the beginning of my lazy-hacker pack!
https://github.com/zeMenno/lazy-hacker
If you guys have suggestions regarding scripts just create an issue and i will look in to it!
@old pagoda Maybe make it recursive?
can you specify that?
Not for gobuster, you have to automate it yourself
no i mean can you specify your question 😄
oh! i see what you want!
yeah if you can create an issue i'll look in to it it is bed time for me so i don't want to forget this haha
but if i eventually add more lazy scripts, may this be something that you'll use for example?
Here is a fun way to practice css selectors https://flukeout.github.io/
JSshell - A JavaScript reverse shell for exploiting XSS remotely or finding blind XSS, working with both Unix and Windows OS - shelld3v/JSshell
All free devnet cisco courses https://developer.cisco.com/startnow/?utm_campaign=startnow20&utm_source=email&utm_medium=welcome-devnet-startnow
Maybe this will help...
NahamCon Exclusive Offer: 25% Off EVERYTHING from eLearnSecurity w/ Code 'NHM-CON' https://www.elearnsecurity.com/
IT Security training courses
Windows privesc ps1 inspired by powerup
does anyone have a good resource (article or anything) about actively monitoring and protecting your home network?
@crimson thunder go for nessus home on a VM and PRTG has a free version
it also depends what do you mean by 'actively monitoring'
you could also create an elk stack to monitor net flow
@gritty barn maybe I didn't phrase it correctly, I meant I want a way to check inbound connections and see if someone is trying something sketchy. thanks for the suggestion, I have little to no experience with almost anything blue-team-ish 😄
Sounds like something Wireshark can do
pfSense, Suricata and Snort come to mind for that sort of thing @crimson thunder (:
@sturdy shell thanks, I'll give them all a look
This one is about an interesting behavior 🤭 I identified in cmd.exe in result of many weeks of intermittent (private time, every now and then) research in pursuit of some new OS Command Injection attack vectors. So I was mostly trying to: find an encoding missmatch between s...
new POC vulnerability with ping that not a lot of people know about yet
Just added a new script and a recursive function for GoBuster!
https://github.com/zeMenno/lazy-hacker
Any good password lists?
Larger list than rockyou? 👀
Bruh
I gotchu
that should be around the size you were looking for, right? @shut ferry
lmao better
but I need BIGGER!
WHY
I was joking that time haha
Haha
I'm trying to hack aliens, dude
they're a lot of aliens out there
Man at that point you'd just have to combine the largest ones out there
I'll do it. Don't tempt me. haha. thanks though 😄
your best bet might be moving straight ahead into 64 characters rainbow tables 
get ready for x petabytes database
hashcat 6.0 https://hashcat.net/forum/thread-9303.html
Are there any resources on creating a room? I've got an idea in my head and I'd quite like to build a room at some point if possible.
Getting Started
thanks guys haha @spiral zodiac @odd quest
Get Our Premium Ethical Hacking Bundle (96% Off): https://nulb.app/cwlshop
How to Automate the Generation of Common One-Liners
Full Tutorial: https://nulb.app/x4oke
Subscribe to Null Byte: https://goo.gl/J6wEnH
Nick's Twitter: https://twitter.com/nickgodshall
Cyber Weapons ...
@shut ferry The room isn't accepting writeups yet, but you should probably submit it there first.
Okay thanks for information
But my friend have found someone made a writeup on youtube too
Okay thanks in advance
@shut ferry Submit it as an official writeup and I'll review it now, as I'm approving them today
https://blog.tryhackme.com/going-from-zero-to-hero/ Might as well link your source, rather than just stealing the image @queen wyvern
I don't have the source sorry, my buddy on telegram sent me this. I can delete this tho
Well, now you have the source
And you can share it with them
But also it's not in order, other than the waves
It was written by a user, not an admin
Hey ninja 😄 I Updated my lazy hacker pack, and it got recursive gobuster. Itagged you in it, would you like to try it out? (since you suggested it :D)
@old pagoda I'll be honest, I don't automate gobuster etc. You asked for suggestions so I gave one
I can take a look once I get up
your call
Stuxnet Analysis: https://youtu.be/TJhfnItRVOA
Hey guys! HackerSploit here back again with another video, in this video, Amr will be reviewing the new Ghidra reverse engineering and analysis tool while analysing Stuxnet to demonstrate it's featureset.
Learn malware analysis:
Webinar: https://maltrak.com/malware_analysis_w...
Deep Analysis of Ryuk Ransomware
https://n1ght-w0lf.github.io/malware analysis/ryuk-ransomware/
Learn Golang
https://www.youtube.com/watch?v=75lJDVT1h0s
An introduction to the go programming language for beginners. In this golang tutorial you will learn the basics of go, setup a go lang coding environment and write your first ever "Hello World!" program in golang. Go is a modern and extremely useful programming language. It wa...
How to Reverse Engineer Software (Windows) the Right Way
https://www.apriorit.com/dev-blog/364-how-to-reverse-engineer-software-windows-in-a-right-way
Just a stupid Question , does it exist a list of all CTF available online ? Because i am searching some CTF games to get some training but it hard to find .
But most CTF are team play no solo ?
yeah but you just be a solo team
or most ctfs have a discord where you can find other members to play with
Just a stupid Question , does it exist a list of all CTF available online ? Because i am searching some CTF games to get some training but it hard to find .
@sterile barn Indeed my friend, check this https://www.reddit.com/r/hacking/wiki/index#wiki_ctfs
r/hacking: A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white …
Thank you very much because it was hard to find something suitable for beginners and most of them are ctf for teams and i don't have a team and enough experience to take those challenge 👍
Hey, recently I thought about completing something from elearnsecurity, I found out that PTS barebone edition is free, although you need an invite, does anybody know how can I get the invite?
thanks @wheat canopy
Thank you very much because it was hard to find something suitable for beginners and most of them are ctf for teams and i don't have a team and enough experience to take those challenge 👍
@sterile barn no problem
really good short and concise AD videos: https://www.youtube.com/playlist?list=PLPDUz8KkxR5z2z84CJ1JyLXC9JgxkjPBk
Looks handy, thanks for the share ❤️
Windows DFIR cheatsheet this is super neat: https://www.jaiminton.com/cheatsheet/DFIR/#
That's my go-to page for DFIR @sturdy shell 👍
I only heard of it today from twitter @craggy onyx but this would of been so good throughout my degree hehe - it's wicked!
v nice lil snippets for sysadmins too

oh damn that's cool
Chev you'd love these
Jai did a great job. Two other GitHub pages I frequent often for Forensics and Incident Response are: https://github.com/meirwah/awesome-incident-response and https://github.com/cugu/awesome-forensics
https://www.ethicalhacker.net/register/
@wheat canopy Invalid CSRF Token 🤔
Hi guys, some people asked me for ressources about assembly. I find this interesting on Github : https://github.com/wtsxDev/reverse-engineering
I know everyone probably knows what gtfobins is already but I find running these commands as followed is a great way to find binarys to exploit easily for user privi escalation "find / -type f -perm -u=s 2>/dev/null; getcap -r / 2>/dev/null" https://gtfobins.github.io/
@lean warren ❤️ https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology and Resources/Linux - Privilege Escalation.md
Hello there Can someone here would recommend me a CTF only OSINT? i search few of them but i want to know if you know a CTF that is only OSINT
You missed it, but there was a missing persons CTF
Yeah but if there one that focues on OSINT like THM but for OSINT
yes something like that thanks again and yes i miss that missing persons CTF but will be another one
Found this some hours ago, think it has a good explanation of the subjects.
Table of Contents
Module 1: Security Essentials
Lesson 1: Course Overview
1.1: Areas of Focus and Exam Info | 1.2: Course Is and Isn't |
1.3: Author Introductions
Lesson 2: Introduction to Ethical Hacking
2.1: InfoSec Overview | 2.2: Threats and Attack Vectors |
2.3: Attack C...
Nice. I saw this link but I haven't seen the video yet.
https://www.reddit.com/user/goretsky/m/security/new - The thread i usually follow on reddit
This multireddit is meant to provide a collection of all IT security-related subreddits. Please contact me if you have any …
@gritty barn thanks for that, I didn't know about most of those
no problemo
https://github.com/madbomb122
GitHub
madbomb122 - Overview
madbomb122 has 4 repositories available. Follow their code on GitHub.
https://github.com/nccgroup/ScoutSuite
GitHub
nccgroup/ScoutSuite
Multi-Cloud Security Auditing Tool. Contribute to nccgroup/ScoutSuite development by creating an account on GitHub.
https://github.com/nccgroup/GTFOBLookup
GitHub
nccgroup/GTFOBLookup
Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io) and LOLBAS (https://github.com/LOLBAS-Project/LOLBAS) - nccgroup/GTFOBLookup
https://www.specterops.io/resources/affiliated-toolsets
Research and Development | SpecterOps
Developed by our team, free and open-source.
https://www.varonis.com/blog/powershell-tool-roundup/
Inside Out Security
The Complete PowerShell Tool Roundup
A hand-curated list of 70 tools to power up your workflow.
https://github.com/six2dez/wahh_extras
GitHub
six2dez/wahh_extras
The Web Application Hacker's Handbook - Extra Content - six2dez/wahh_extras
https://github.com/wtsxDev/Penetration-Testing/blob/master/README.md#books
GitHub
wtsxDev/Penetration-Testing
List of awesome penetration testing resources, tools and other shiny things - wtsxDev/Penetration-Testing
https://github.com/thebleucheese/awesome-threat-intelligence
GitHub
thebleucheese/awesome-threat-intelligence
A curated list of Awesome Threat Intelligence resources - thebleucheese/awesome-threat-intelligence
https://github.com/Elemental-attack/Elemental
GitHub
Elemental-attack/Elemental
Elemental - An ATT&CK Threat Library. Contribute to Elemental-attack/Elemental development by creating an account on GitHub.
Multi-Cloud Security Auditing Tool. Contribute to nccgroup/ScoutSuite development by creating an account on GitHub.
Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io) and LOLBAS (https://github.com/LOLBAS-Project/LOLBAS) - nccgroup/GTFOBLookup
That's a few of my my more useful bookmarks
Found this some hours ago, think it has a good explanation of the subjects.
@royal jasper I tried to watch some of this last night, but the one dude doesn't really speak properly, and a lot of the time it's difficult to understand him. I'll definitely try and watch the full 10 hours of the next couple of weeks though. I'll use YouTube captions
Table of Contents
Module 1: Security Essentials
Lesson 1: Course Overview
1.1: Areas of Focus and Exam Info | 1.2: Course Is and Isn't |
1.3: Author Introductions
Lesson 2: Introduction to Ethical Hacking
2.1: InfoSec Overview | 2.2: Threats and Attack Vectors |
2.3: Attack C...
😮
Can someone suggest some good links to learn LFI and RFI
Do you hate when you Ctrl+c in a reverse shell and lose it? I did until I found Pwncat!
The description sounds like an infomercial and I love it
And now for the small price of a git clone, you too can have your very own Pwncat!
https://www.jetbrains.com/academy/
Register before July 1st and you get all the learning material FOR FREE until January 1st 2021. I highly recommend it too, it's great.
That looks really good! Nice find @crimson thunder (:
@sturdy shell bro I can't take the credit. r/learnprogramming is saving my ass once again. just in time for my exams too 😛
just on the back of that @sturdy shell Jetbrains offer free yearly license for students
so if you still have your student email you can use it 😛
@gritty barn how did I miss that, thanks
idk
google free software for students
and swap the countries on your google search, you'll find different applications
Thanks for posting about JetBrains. I always can use more resources to help me with Python. 
Definitely going to apply for edu
Are there any resources to practice advanced buffer overflow??
Are there any resources to practice advanced buffer overflow??
@heady sierra this maybe https://exploit-exercises.lains.space/protostar/
yeah thanks
Cheat sheet for your Wireshark needs
https://i.redd.it/xna1fs2q1e751.jpg

Hey, can anyone give me feedback on my tool?
I really appreciate it!
uhmm @tepid patio wanna give it a try?
as you also have ciphey sooo.
Thanks guys
Yesterday I added some more hashtypes
To be specific 5, MD4 and SHA3-224,256,384 and 512
i might submit some issues
with open(wordlist, "r", encoding="ISO-8859-1") as FileObj:
``` <- this is a big problem with stegcracker too. i could submit a pull request
the tool defo looks fancy, but I'm not sure about it's performance against something like john/hashcat
you could also minimize the amount of code by a big factor by reusing the same code for each type and just passing the hashing function as they all seem to have the same functions
add multi threading too
and for the word list, dont do a for loop since stegcracker does that and stegcracker sucks
Add cuda support
@solemn harness let me write an issue for u with some stuff i think you can improve 😄
i submitted an issue 🙂
Quite extensive resource on CTF and a methodology on vulnerable machines: https://bitvijays.github.io/LFC-VulnerableMachines.html
Hi everyone, is there any good resources for app pen testing?
Android and iOS (books or some links to paths) anything would be helpful
iOS Penetration Testing by Kunal Relan, The Mobile Application Hacker's Handbook, by Dominic Chell @stoic stone
Thanks 🙂
You're welcome.
Is there someone who can share a good Surricata list for my pfSense?👀
Digital Forensics and Incident Response. Great resource by Jai Minton. https://www.jaiminton.com/cheatsheet/DFIR/
Nice find
Ty
hello! can anyone sugest me a good cracker for steg passwords? Im not able to install stegcracker and john doesnt seems to work properly
Why can't you install Stegcracker? Would you like some help installing it? 🙂
stegcracker is pretty much the only one and john you will have to use x2john where as x is what youre converting from
@naive lance if you can't apt install Stegcracker for whatever reason, and pip3 install stegcracker doesn't work, you can clone the repo and call python3 stegcracker on the repo 🙂 https://github.com/Paradoxis/StegCracker
im gonne take some prints to show you
sure!
what are som good resources for BO from basics to advanced.
@wispy torrent might be worth checking this out https://www.youtube.com/playlist?list=PLLKT__MCUeix3O0DPbmuaRuR_4Hxo4m3G
https://www.youtube.com/watch?v=1S0aBV-Waeo - This is what gave me the basics of BoF and made it all "click" for me. At least the theory side.
Making yourself the all-powerful "Root" super-user on a computer using a buffer overflow attack. Assistant Professor Dr Mike Pound details how it's done.
The Stack: https://youtu.be/7ha78yWRDlE
Botnets: https://youtu.be/UVFmC178_Vs
The Golden Key: iPhone Encryption: https://...
does anyone have resources/techniques on bypassing conventional IDS/APS?
https://twitter.com/three_cube/status/1278078318923755520?s=19 someone wanted scada stuff
SCADA Hacking: Modbus PLC Master/Slave Simulation #scada #scadahacking #plc #ics #cybersecurity
https://t.co/CcueuboV3o https://t.co/zdx59KQ4mU
#scadahacking
https://github.com/holmes-py/KoTH-counter
Dumb and dirty but works...
found in another infosec discord haven’t tried it yet but it might help someone
https://github.com/s0md3v/Hash-Buster
@queen wyvern fun fact: that's the same hash code we have in Ciphey, except I edited most of it 🙂 For a similar project, BaseCrack looks promising although tbh I think CyberChef Magic does most of the stuff https://github.com/mufeedvh/basecrack
@queen wyvern fun fact: that's the same hash code we have in Ciphey, except I edited most of it 🙂 For a similar project, BaseCrack looks promising although tbh I think CyberChef Magic does most of the stuff https://github.com/mufeedvh/basecrack
@tepid patio Ah. What's Ciphey tho ?
Ciphey is my worst nightmare as a challenge creator
@tepid patio the issue i was facing is fixed?
@tepid patio the issue i was facing is fixed?
@fringe spire is that the download speed? it's fixed in version 5.... but not released on Master yet 😂😂
Ciphey is my worst nightmare as a challenge creator
@odd quest Soon CTFs will only feature RSA challenges
I got a tool for that too
rsactftool
https://github.com/adeptex/rsatool
https://github.com/Ganapati/RsaCtfTool
These are the two I use
resources pdf books: bash notes for pros, linux notes for pros, linux all in one, explainshell.com is for explaining what a command does example: cd .. or ps aux | grep firefox
does any one have stuff on hacking with python
tools? or wut
if anyone needs help with subnetting, i put this together to hopefully help you subnet within 10 seconds in your head
let me know if it helps / feedback 🥺
does any one have stuff on hacking with python
@zenith flint Black Hat Python? Grey Hat Python? White hat Python? It's a book, I'm not sure on which hat it is, but it's one of those :p
Black Hat Python https://nostarch.com/blackhatpython
@night ether I've always done it by counting bits -- strikes me as being less convoluted 😆
@topaz gulch counting bits is extremely tedious and difficult to do without writing down imo 👀
not if you split them in chunks then it's pretty easy and fast
if you do it in binary you still only need to write down one octet but i’d rather count in decimal than binary 😅
idk i guess i find it hard to skip a power of 2 when counting binary in my head
hey i was wondering if anyone can share some resources on active directories, its a new topic for me and i wanted to know more about it :)
any specific area of active directory youre interested in? @lilac maple
any specific area of active directory youre interested in? @lilac maple
@azure widget i wanted to know about it in general since its totally new for me, so something like concepts and stuff
I got you
Here's a list of free resources for getting/staying up to speed on Microsoft Windows Server and Active Directory: AD Reading: Windows Server 2019 Active Directory Features AD Reading: Windows Server 2016 Active Directory Features AD Reading: Windows Server 2012 Active Director...
Red Siege is an information security company focusing on real world threats. Red Siege is an information security consulting company that concentrates on the latest threats to organizations today. We perform in-depth analysis, determine organization/business risk, and find the...
@lilac maple haha that should be enough to get you started if you need more I have more where that came from
omggg thank you soo muchh!!!!! i'll definitely let you know if i need any further help regarding this
Hey guys. Anyone here has a link to the vulnerable VMs from the book of Georgia Weidann's Pentesting Book?
Here is the SS of the part of the book. The red underlined link is dead, unfortunately
Also I think the torrent from the link "nostarch" is also dead. Anyone here know any alternatives?
the 7zip link is live
the torrent is also live
it's just their tracker that is dead
if you add a list of other trackers to the torrent it'll download just fine
if you add a list of other trackers to the torrent it'll download just fine
@tribal gull Thanks for the tip. I already did this and it worked
hello anyone know about the vulnerability in router during its boot up period?like how it can be exploited during that phase
What vuln? Do you have a CVE?
i don't have CVE right now but i heard somewhere that they can be exploited at that phase do you know sth about that @tepid patio
@tepid patio
You were the guy you wrote an issue for my tool right?
Well I have a question
I could reduce the time by multiprocessing 2 functions. But I ended up with almost 900 lines of code 😅🤣
How can I reduce that? I tried a class but I will end up with the same amount of lines lol
@solemn harness I would create an abstract class for all the crackers, and then build smaller objects using normal classes for each hacker. and then store the cracker objects in a list, and just multi process that list?
Well I multiprocessed the 2 functions. 1 starts reading the file from the beginning and the other starts from the end
And it works now, takes about 2s to crack a password which is at the end
So pretty fast I think. You know what, I will release it and send you the link
So you know what is going on lol.
@signal ether I'll be real, just make a VM.
@tepid patio https://github.com/be1807v/test
@shut ferry on some routers they have a UART header exposed on the motherboard and you can usually read the startup log and sometimes even execute commands after bootup
That is what I got so far
@tepid patio https://github.com/be1807v/test
@solemn harness Why don't you create a Git branch for testing and use that?
You repeat this code a lot: python def readBackwards(): if hash_type == 0: if verbose == True: for line in reversed(list(open(wordlist, "r", encoding="ISO-8859-1"))): passwd1 = line.rstrip() passwd_h = hashlib.md5(passwd1.encode()) passwd_hash = passwd_h.hexdigest() print("Trying \"{}\"" .format(str(passwd1))) if user_hash == passwd_hash: hash_cracked = True print("[+] Hash cracked! Results: " + str(line)) endTime = time.time() deltaTime = endTime - startTime print("[+] Cracking finished in {}s" .format(str(format(deltaTime, ".2f")))) sys.exit() print("[-] Hash not found! Maybe
Try to put it into a single function, or use a class
if you do that, you'll save a lot of lines 🙂
@tepid patio
I updated the tool
And removed around 600 lines of unnecessary code 🤯🤣
Tag me and let me now if you like it or not. Hash detection is the next thing I will work on 😀
Now cracking speed is twice as fast. If the hash is in the front of the file, it will find it in 0.01 seconds
Ofcoars do this when you have time!
Not working
Leaving sub rooms without the sub
from thmapi import THM
from thmapi.util import http_get, http_post, fetch_pattern
import json
# creds = json.load(open('./alt_creds.json', 'r'))
creds = {
'username': 'asdf',
'password': 'asdf'
}
t = THM(credentials=creds)
tmp_room = 'ctf100' # normal room
target_room = 'linuxctf' # sub-only room
def join_room(room_code):
http_get(t.session, f'/jr/{room_code}', res_format='raw')
def leave_room(room_code, tmp_room):
csrf = fetch_pattern(t.session, f'/room/{tmp_room}', 'csrf-script')
http_post(t.session, f'/room/leave', {
'code': room_code,
'_csrf': csrf
}, res_format='')
join_room(tmp_room)
leave_room(target_room, tmp_room)
leave_room(tmp_room, tmp_room)
To run this you need to:
- use python3
- download thmapi (
pip3 install thmapi) - fill in the credentials and change room codes (room code can be found after
/room/in the link
how to set up kali on dockers --> https://www.beyondlines.net/linux-on-docker/
For reference, I don't recommend this as the VPN doesn't work very well with it
Burp Suite is the premier offensive hacking solution, and now when new hackers reach at least a 500 reputation on HackerOne and have a positive signal, they are eligible for 3-months free of Burp Suite Professional.
🔥
https://www.offensity.com/de/blog/just-another-recon-guide-pentesters-and-bug-bounty-hunters/
https://www.bugcrowd.com/resources/webinars/doing-recon-like-a-boss/
https://medium.com/bugbountywriteup/guide-to-basic-recon-bug-bounties-recon-728c5242a115
https://www.hackerone.com/blog/how-to-recon-and-content-discovery @shut ferry
Doing hacking recon takes time and patience. Hackers typically follow similar steps to gather information on their targets however some details may be a bit different...
Today I am writing about the love story between bug bounties & reconnaissance, but before I do I should say that i’m not much of an expert…
Recon plays a major role while hacking on a program. Recon doesn’t always mean to find subdomains belonging to a company, it also could relate to finding out how a company is setting up its properties and what resources they are using.
Thanks @lilac maple !
np!
Hi guys! I want some feedback on my tool! Thanks! https://github.com/be1807v/Hash-Cracker
cool project. definitely worth adding to your portfolio/resume
And what can I add to the tool? To make it easier for you? 😀
Looks pretty!
Thanks guys! I really appreciate it!
Lol 🤣
hah
Should be fixed now
LM and NTLM are the biggest hashes you'll find aside from md5, so I'd prioritize adding them
I will add it
Hi guys! I want some feedback on my tool! Thanks! https://github.com/be1807v/Hash-Cracker
@solemn harness Learn Poetry and upload it to PyPi too 🙂
I was using hashlib and they provided just a limited amount of hashes
i am digging the colours
Now I found Crypto which provides a lot more.
Okay to summarise: 1. Add NTLM and LM 2. Add colors 3. Add hash detection
The screenshots? That's a website called carbon.now.sh
ohhh ok
those are all REAL malware samples please be careful and properly sandbox them
This video goes over how to setup your CAN sniffer with SocketCAN and start sniffing CAN bus packets.
Open Garages is a collective of mechanics, performance tuners, security researchers and artists. This channel will focus on hacks, mods and provide a video tutorial series fr...
Can anyone point me to any guide/tutorial/video where I can use my GPU to crack hashes with John in Kali?
I've read and seen few articles and videos where the cracking with GPU is much faster but can't find a guide to use it
Generally we would install the hash cracker on the host machine, which automatically makes use of the GPU 🙂
Although I don't think John uses the GPU as much as Hashcat does 😛
@river fractal you need cuda/opencl drivers, and then you just kinda use hashcat normally
If you need --force then you're doing it wrong
hey guys (mods) i have a question reguarding hacking with mac OS
@odd quest Should I install cuda/opencl drivers on my Windows(host) machine and then running hashcat in kali(VMware) would work?
No
Download hashcat for windows
There are builds
DO NOT run hashcat in a VM
Unless you pass through a whole GPU, it won't work
Okay got it. Thank you soo much :)
I'll try this tomorrow and see how much difference I'm getting versus my VMware (Probably CPU)
--force in hashcat can break things
It can skip over the correct password
Or spit out incorrect passwords
I was just about to ask why my malware samples got taken down and then I realized there was a rule about that sorry y’all
sorry i mentioned boolean statements
its boolean variables
i confused on seeing variable 'state'
the reason y i got different values for float b is due to encoding
Can anybody provide me with any education video from subscription plan? Want to check if I need it
Those videos are usually a fully detailed walkthrough on the room
- sharing them with non-subs is prohibited
maybe at least a part of it? Just want to see how it goes
not allowed, sorry
this is my video on how scammers scam newcomers especially into infosec field
i bet you will have lot of fun
https://youtu.be/bgigs-79suU
i know in every field some people take advantages of new comers and lure them into courses and takes money and then disappear
this guy gopikrishna never said about any certs he had
he just says we work for government , MNC's and we had some contacts with google etc full bluf...
BHIS is top in my book. 👍
Wait you mean the book or the page?
Black Hills Info Sec make a lot of good material
https://www.blackhillsinfosec.com/a-pentesters-voyage-the-first-few-hours/
@azure widget Read this one and its pretty cool
@jaunty pulsar That’s what I posted lmao
Oh I thought you meant read that one geez these networks have my brain not comprehending anything
Very nice hope you learned something from it
can somebody help me? please
@round field ask in #room-help
already did thanks
how come you create a gobuster directory within /opt but then install it with apt?
dunno if anyone has posted this already. here is a giant list with pretty much all free webinars, courses, books, etc that you can find for free about cybersecurity in general. The guy has been keeping the list updated so we don't have to worry about accessing old stuff !!! https://github.com/gerryguy311/CyberProfDevelopmentCovidResources/blob/master/README.md
anyone got any good resources on bypassing aslr? or just any advanced binex explanations?
@night ether https://www.corelan.be/index.php/2010/06/16/exploit-writing-tutorial-part-10-chaining-dep-with-rop-the-rubikstm-cube/
@craggy onyx awesome !! thank you tim :)
👍
@topaz gulch Do you have any good resources for learning bash scripting? 🙂
Would like to automate most of my box dev other then vagrant & docker compose
There were some floating around, I believe Ashu might have a good one?
I tend to just do it from notes and memory now, having Googled everything individually to begin with
Ah no worries
I'll have a look around (:
Thought it was worth an ask to see if there's anything you could recall being helpful
Hopefully can share some generic bash scripts for box dev in the near future
Nice 😁
Just me or enum4linux is really hard to get started?
Pay what you want 4 day Getting Started in Security with BHIS and Mitre Att&ck taught by John Strand
https://wildwesthackinfest.com/online-training/getting-started-in-security-with-bhis-and-mitre-attk/
Free event being held by Sans for high school and junior high students to get an introduction to cyber security
https://www.sans.org/cyber-camp?utm_medium=Social&utm_source=Twitter&utm_campaign=Cyber+Academy
A great resource for Methods https://book.hacktricks.xyz
I'll have a look around (:
@sturdy shell Once you do, it would be awesome if you can link me up too 🙂
I gotcha 
Hacknet is an immersive, terminal-based hacking simulator for PC. Dive down a rabbit hoIe as you follow the instructions of a recently deceased hacker, whose death may not have been the accident the media reports. Using old school command prompts and real hacking processes, yo...
$9.99
10218
82
Big Brother has arrived - and it’s you. Investigate the lives of citizens to find those responsible for a series of terror attacks. Information from the internet, personal communications and private files are all accessible to you. But, be warned, the information you supply wi...
$9.99
6029
77
^^ These games seem v/ cool
Anyways, if anyone wants to try out last year Defcon challenges,have a look at https://archive.ooo, they made some of the challenges online.
I own Hacknet. It's pretty neat if you want Hacker Lite experience, but it's basically like the same gameplay loop over and over again. The soundtrack is cool.
It's using like 5-6 problems basically to do all the hacks.
hey guys here is a list for those who havent read yet about the most "important web hacking tools" by hackerone
hey guys here is a list for those who havent read yet about the most "important web hacking tools" by hackerone
@haughty dirge thanks mate
Litterally just a better enum4linux
Send more 
There is also the metasploit unleashed
^
RustScan - Faster Nmap Scanning with Rust. Are you sick of waiting 20 minutes for Nmap to finish? RustScan decreases it to 39 seconds for you. (A little something I built ✨)
+ Can scan all 64k ports in 26 seconds
+ Automatically pipes into Nmap (no more copy / paste)
+ Nothing else. **Only** job is to improve Nmap, not replace it!
🤔
It's in Rust 👀 I hate doing RE on Rust binaries, but let's see, should be pretty fast since it's Rust 🤔
Rust is beautiful
@tepid patio You already uploaded to the AUR? 😄
@spiral zodiac yes ofc, AUR is best 😜 it should work (so long as I didn't mess up the checksums)
It's in Rust 👀 I hate doing RE on Rust binaries, but let's see, should be pretty fast since it's Rust 🤔
@spiral zodiac it is v/ fast but I'm using threading which is slow, and it also depends on what your machine can do
I get 26 - 40 seconds on my machine, but if you have to use fewer threads you get way less (I can run it with 1k threads tho tbf)
@tepid patio In the readme it says 64k ports, yet there are a total of 65,536 🤔

@tepid patio In the readme it says 64k ports, yet there are a total of 65,536 🤔
@spiral zodiac ah you're right, it's supposed to be 65k 😅 it does do all ports, I just rounded down for some reason writing the readme 🤷♂️
If I use this, will you use my pc to upload anime in the background @tepid patio 🧐
If I use this, will you use my pc to upload anime in the background @tepid patio
@queen wyvern of course, you're going to be mining AnimeCoin for me
@tepid patio Just installed rust_scan using cargo and shouldn't this be <ip> instead of <i>:
RustScan 0.01
Bee https://github.com/brandonskerritt
Fast Port Scanner built in Rust
USAGE:
rust_scan [OPTIONS] <i>
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-T, --timeout <T> The timeout before a port is assumed to be close. Default 1000 [default: 1000]
-t, --threads <t> How many threads do you want to use? Default 1000 [default: 1000]
ARGS:
<i> The IP address to scan
@tepid patio Just installed rust_scan using cargo and shouldn't this be <ip> instead of <i>:
RustScan 0.01 Bee https://github.com/brandonskerritt Fast Port Scanner built in Rust USAGE: rust_scan [OPTIONS] <i> FLAGS: -h, --help Prints help information -V, --version Prints version information OPTIONS: -T, --timeout <T> The timeout before a port is assumed to be close. Default 1000 [default: 1000] -t, --threads <t> How many threads do you want to use? Default 1000 [default: 1000] ARGS: <i> The IP address to scan
@spiral zodiac it's an argument so it doesn't have any flag, but I chose I because it's physically shorter. but for UX I should change to IP I guess 😁
🙂
Does somebody knows some good website/youtube channels worth checking for electronics hacking?
Like maker stuff, or hacking hacking hacking?
Since i'm pretty unexperienced in electronics i'd start with maker stuff
ty
https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w there's some more hackery electronics stuff from LiveOverflow
🙂
@spiral zodiac did u have any bugs? just so i can fix them for version 2 😄
I'll take a more in-depth look tomorrow 
Nice gonna check that out
Quicker way of leaving sub rooms. Works in browser
Steps:
- Open a page of a random room (must be a room as it grabs the csrf token from that)
- Replace the roomcode in the code below with the target room and paste it into the devtools console
const targetRoom = 'linuxctf' // Change this to the sub-only roomcode
fetch('/room/leave', {
method: 'POST',
body: JSON.stringify({
code: targetRoom,
_csrf: csrfToken
}),
headers: {
'Content-Type': 'application/json'
}
})```
const targetRoom = 'linuxctf' // Change this to the sub-only roomcode
fetch('/room/leave', {
method: 'POST',
body: JSON.stringify({
code: targetRoom,
_csrf: csrfToken
}),
headers: {
'Content-Type': 'application/json'
}
})```
Improved it for you
Can you write one that lists as well?
Because kill = bad
Tracing back VM to room if you can
i mean you could just go to the site?
The site doesn't list your currently running VMs
How to check what VMs are deployed where
Paste this in your devtools console
fetch('/api/running-instances')
.then(r=>r.json())
.then(vms =>
vms.forEach(vm =>
console.log(`https://tryhackme.com/room/${vm.roomId} - ${vm.internalIP}`)
)
)```
This will list the rooms with instances and their IPs
any other ones i could quickly whip up?
Kill all running VMs
Go to a random room and paste this in your devtools console
fetch('/api/running-instances')
.then(r => r.json())
.then(vms =>
vms.forEach(vm =>
fetch('/api/vm/terminate', {
method: 'POST',
body: JSON.stringify({ code: vm.roomId }),
headers: {
'csrf-token': csrfToken,
'Content-Type': 'application/json'
}
})
)
)```
Skidy pls steal these and give us the features thanks
If anyone has ideas for other utility scripts like these just ping me and we'll see if it's doable
maybe we'll get actual features quicker this way
That has happened before, I've thrown code out there related to copy/paste
ES6 >>>> jquery
DEFCON Ham Radio Village is holding 5$ Ham Radio Exams and they’re waiving the fee for applicants under 18 if you want to get involved with SDR this is the time to do it
Elevator Hacking - From the Pit to the Penthouse
Deviant Ollam The CORE Group
Howard Payne The CORE Group
Throughout the history of hacker culture, elevators have played a key role. From the mystique of students at MIT taking late-night rides upon car tops (don't do that, p...
Always a fun video
thinking to attempt for eJPT soon , do you guys mind sharing some resources?
The barebones was free like 1 month ago and tbh if you can do htb easy/thm medium machines you almost know everything you need
@lilac maple Check the Syllabus on the site for eJPT, as it will provide an overview of the contents covered in the course.
Alright, thanks guys :)
https://www.udemy.com/user/cliftonlkrahenbill/
Free courses for two days from Prof. K, a Udemy instructor - simply apply the checkout code for the course.
Ethical Hacking - A Hands-On Approach (E4BF17164C5AF207AC7F)
Ethical Hacking - Capture the Flag Walkthroughs - v1 (3BB90D7566D114F8C5CF)
Ethical Hacking - Capture the Flag Walkthroughs - v2 (587C1468AEE603E1909D)
Windows 10 – Hands-on Training (7D875B0510F89805D921)
Microsoft Word 2016 for Everyone (795A04E730166A8186B2)
Microsoft Server 2012 R2 - Hands-on Training I (68B222C5F4665895BC01)
Microsoft Server 2016 - Hands-on Training I (79F556DC95BFE58A6DCD)
Microsoft Server 2016 - Hands-on Training II (E95DCA443C1E81D161A5)
Microsoft Server 2019 - Hands-on Training I (678FEE9F155299C7528A)
Microsoft Server 2019 – Hands-on Training II (E579D864E18672EBDAF8)
Guys you can check out the writeup that I prepared for DEFCON27 Advanced WiFi Exploitation Workshop for Red & Blue Team Workshop's CTF: https://medium.com/@anilcelik/en-defcon-27-advanced-wireless-exploitation-workshop-ctf-write-up-f787b0899256
@proper atlas my man, thank you very much 🙂
To sus
ty 💞✨
hi people,could you recommend me some decent portalls/sites to catch up the latest info sec news,i don't use twitter 🙂 thanks
The Ultimate OSINT Guide ! https://www.youtube.com/watch?v=OZnpULVHz4w&t=3s
Hey Guys I Am Back With Another Video , in Today's Video I Will
be Showing you guys the Ultimate Website Collection For OSINT , as you Know
beginners always think maltego or any other tools are the only way
to collect decent information , but that is not the truth , watch
th...
Threader3000 now has Nmap integration. Get a full port scan and targetted Nmap scan on a target in less than 3 minutes. https://github.com/dievus/threader3000
Or install from the Pip repository
pip3 install threader3000
or
pip install threader3000
RustScan has 2 major updates (just pushed! ✨)
+ 8 seconds for full port scan, theoretical 1 second full port scan (but you gotta have a BEAST of a PC)
+ Custom Nmap arguments. So you can choose what Nmap does when you run RustScan
cargo install rustscan
This is more usable now @tepid patio
It looks good so far but it skips some ports sometimes with 1000 threads
It looks good so far but it skips some ports sometimes with 1000 threads
@queen wyvern The newer version doesn't use threads btw
I will update it and let you know
😄 ❤️
This is very cool
It's in Rust too
🤔
Why the disdain for a Rust shell?
Performing RE on Rust binaries isn't fun 😦
Yeahhh
I also don't know how I feel about a non-C based shell experience
But the examples look sick
very promising
Someone made checksec in rust.
Now, someone make pwntools in rust.
@tepid patio Rust pwntools, might be a good idea for next project.
Actually I was going to re-write some bruteforce programs in Rust, since that's where most of the speed will come from 😛
Mastering Malware Analysis — Here's another popular #cybersecurity eBook (510-page PDF) currently available for FREE download, only for the next 6 days by its publishers.
Download your copy now: https://t.co/AaGSNe7Nl4
@sturdy shell ^
😮 @gritty barn you always find the juicy stuff
I think I had a couple of pages (a chapter or so) access to that during Uni
so really good find!
😮
Thanks
guys I know all the basic commands of terminal I have basic networking knowledge and I am a complete beginner in cybersecurity and probably want to pursue a career in this domain can u guys suggest some good resources that would help me?
A really good website called "TryHackMe" where you can learn ethical hacking for free :)
@shut ferry that sounds awesome, could you link it?!?!
@little shadow
@shut ferry @cloud brook Thank you guys
But seriously tho- as long as you go through the rooms with the intent of learning and practicing the penetration process, and always try your hardest to figure it out for yourself, you'll learn plenty about Cybersecurity in no time
@shut ferry sure I'll give it a try
There's a lot of rooms geared towards complete beginners/students that run you through most of the tools and common vulnerabilities
Definitely get familiar with your tools, and the enumeration process, then you can use that as a foundation to more advanced topics, such as common vulnerabilities and exploit development, or server/webapp hardening and security configuration
TryHackMe is very well suited for beginners, just make sure to look at the big picture while you're doing the rooms, and asking yourself "how does this translate into cybersecurity" along the way
you guys seem to have a lot of knowledge in this domain so I thought I'll ask
yeah, it's just slightly weird haha, coming on the discord for a specific website without actually using it, not trying to be rude or anything
Most of the time, if you know how to exploit a vulnerability, then that means you know how to patch it
yeah, you can start with trying some of the rooms first 😛 there is a lot of content available on the website and it's suitable for beginners
@gritty barn lol Ik
this channel is designed for additional resources created by some of our members or stuff that they found online and it is possibly useful for someone
I have 0 programming knowledge I hope it won't be a problem?
you develop those skills throughout the time, everyone starts somewhere. but bare in mind you won't become a 1337 h4x0r in a week
Nor was Rome built in a day
some of them are, not all
what about you?
i work in this field
cool man
^^
guys, quick one
6!
i keep getting machine the message , undergoing maintenance of my machine
does that always happen?
If you want help with rooms, please use the correct channels
This is not the correct channel for that.
so I'll get back to you guys if I face any issue or have any doubts please help me okay?
Long as you use the correct channels for it
Read the channel titles. Read the channel topics. Read the rules. Then you'll be fine.
Alright thanks!
https://www.youtube.com/watch?v=VL2bgatmIkc @wooden mesa thank you for that 🙂
Get a guided walkthrough of various top resources to learn more in your pentesting journey and where to practice your skills. Material also reviews some top tier Infosec certifications that are available today and which ones to focus on and why.
https://github.com/ryanrohypnol/Reverse-Shell-Bash-Alias -- updated
@barren vault one line, REEE 😂
69 lines minimum
To be fair, do you really want a multiline alias in your bash aliases?
@topaz gulch I just wanted to read it, really hard on mobile
Also, I'm a sadistic bastard if you hadn't noticed 🤷♂️
REEE
I make no apologies
Bellingcat season 2 poggers https://www.bellingcat.com/resources/podcasts/2020/07/21/the-bellingcat-podcast-season-2-the-executions/
This is one of my fave startup related things (not really infosec, but theres no channel topic strictly for infosec). Dropbox 1.0 release, some guy comments "you can do this easily on Linux with all these steps". When you build abstraction, those who do not need the abstraction will be more vocal about why it should exist, meanwhile the rest of the world uses the abstraction https://news.ycombinator.com/item?id=8863
After testing Rustscan i dont recommend it
After testing it, I do. Because what I scanned would have killed nmap
The tool is in active development, what's the deal breaker for you @jaunty pulsar ?
https://ip-api.com/ good fun to mess with, personally been using it to geolocate login attempts to my honeypot
Free IP Geolocation API - lookup any IP address
@jaunty pulsar what don't you like about it? I can improve any aspects you want :)
After testing Rustscan i dont recommend it @jaunty pulsar
I'd support that too, IDK if it's just me, but I tested it 5 times on the same IP, it missed some important ports. (Maybe it needs to be configured specifically for every scan(?))
@prime mantle Might be a matter of playing with timeouts, the default timeout is 1.5 seconds, so if the network is slow or the machine is overwhelmed you might have false negatives 🤷♂️
Yeah, figured, will try that too.
Try to play with the batch size too, I think anything above 128 or 256 might be too much depending on the machine.
@jaunty pulsar what don't you like about it? I can improve any aspects you want :)
@tepid patio It's the same than nmap (with flags)
Not really
I'd support that too, IDK if it's just me, but I tested it 5 times on the same IP, it missed some important ports. (Maybe it needs to be configured specifically for every scan(?))
@prime mantle Yeah thts my point I replicate with flags, same speed mor ports
nmap --min-rate 4500 --max-rtt-timeout 1500ms -p- IP it takes double
but its pretty sure whats rutscan does
without losing ports
Copy pasting from that reddit post you saw in /r/netsec isn't helping your case. 😐
Fact, I'm no follower of that subreddit, so you think i would be saying with out arguments, i actually probed it
Maybe other sources, yes
I never said you followed that subreddit, the command you posted is copy-pasted exactly from there and this is a fact, maybe read RustScan's readme before posting.
I'd support that too, IDK if it's just me, but I tested it 5 times on the same IP, it missed some important ports. (Maybe it needs to be configured specifically for every scan(?))
@prime mantle Hey! Theres new code (released a couple of hours ago) which would help with this. In short, the "fastest" scan isn't a one-size-fits-all, but rather something you have to base on your computer specs and ping 🙂 The new code should fix a lot of those issues (but not all, still working on that part)
@prime mantle Hey! Theres new code (released a couple of hours ago) which would help with this. In short, the "fastest" scan isn't a one-size-fits-all, but rather something you have to base on your computer specs and ping 🙂 The new code should fix a lot of those issues (but not all, still working on that part)
@tepid patio Awesome! will reinstall and try again
nmap --min-rate 4500 --max-rtt-timeout 1500ms -p- IP it takes double
@jaunty pulsar This requires a lot of technical knowledge though, see Dropbox. Back in 2007 it was easy to replace Dropbox with some Linux knowledge, read the top comment. It is always possible to replace the abstraction with the underlying project, hence why it is an abstraction. The question is, whether or not people would want to? RustScan's newest feature is to help you create the fastest scan for your machine. It would be a lot harder to automatically choose those numbers for your machine with Nmap on its own 🙂 https://news.ycombinator.com/item?id=8863
Why does the Python sockets module exist, when Berkley sockets have existed since the 1980s? Abstraction isn't always a bad thing 😛
Also note, this project is only like a week old? Nmap is 23 years old. It's hard to compare something brand new, still growing, to something that old ;p
what is/where do I find devtools console ?
ctrl+shift+i
Can someone suggest some resources for learning PowerShell in depth.
p.s. don't mention the tryhackme room
Try https://underthewire.tech/ (it's like overthewire.org in that regard that it's wargaming)
@queen wyvern the first thing to think about with powershell is not really to think about it as a language but to think about it just like you would bash as they are very similar https://docs.microsoft.com/en-us/powershell/scripting/learn/more-powershell-learning?view=powershell-7
Ippsec has good stuff on Oracle padding attacks too!
Hello there, i m not sure if this is the channel for my question, if not i delete it.
A friend of mine is selling products from small producers and i want to help him by doing an ecommerce page like a shop with a cart.
Which technology would you recommend ? something like shopify, wix works well ?
the idea is to make something really simple but secure and precise
someone suggested me wordpress + woocommerce plugin
Shopify is good, it's what tryhackme uses for our swag shopppz
just finished my new hacking blog, tell me what you guys think https://elbee.xyz/
just finished my new hacking blog, tell me what you guys think
https://elbee.xyz/
@elfin geyser looks really well made
i think maybe your team logo is a bit too large though
@elfin geyser also, are you hosting that yourself or on some vps?
because i see your little challenge thing, and i'm not sure what a hosting company would think about people dirbusting
good call ill scrap that
maybe some manual enumeration if you still want a challenge
Hi friends, I'm looking for some structured material aimed at application security (books, blogs, udemy courses, etc.)
anyone got the goods? which rooms are best for diving deep into web apps and app sec?
https://github.com/0xRadi/OWASP-Web-Checklist I find this pretty useful
ohhh this looks really nice thank you
You can also look into OWASP's Juice Shop webapp if you want your own personal vulnerable webapp with a large variety and scale of vulnerabilities
It's a great playground/sandbox for webapp penetration testing
it has a list of challenges yea? or is it just a wild west do your best?
A list of challenges and even a tracker
It's like a miniature CTF all condensed into a webapp
awesome, ive heard the name but havent looked into it. Thanks!
You can host one for free really quickly with Heroku
Otherwise, TryHackMe has a sleuth of webapp based penetration rooms
yea i was going through the owasp top 10 one but it's pretty light
i think they have bigger rooms for each individual one though
Yeah, this one actually has the OWASP Top 10 all ingrained into it
I think somebody has a older version of Juice Shop on THM, but it's still basically the same
yea, this should be plenty to work with, much appreciated!
hey guys I am interested in start studying about android hacking and exploitations does someone recommend any youtuber or website for me to have a look, I already started watching the hackerone videos related to it, thank you 🙂


