#resources

1 messages · Page 8 of 1

shut ferry
#

htb getting bored really fast its not a challenge anymore for me

prisma bison
#

Seems like a flex but why would you come to a learning platform if you’re bored of a Competitive platform

odd quest
#

To beat szy

prisma bison
#

Pfft impossible

#

Leave him b

rain carbon
queen wyvern
#

I have taken this one, it's decent for complete beginners . It's avaiable on youtube as well if you don't want to give your credit card to coursera, but you don't get a certificate (ofc) that way

daring hull
#

It's just a class. The classes should be from iCollege. Which it isn't awful. The course I was doing was entertaining at the least and kinda felt like a typical college lecture that I know of, but I think they fluff the entertainment a bit too much. I haven't delved too far into it. I think it's worth it if you're supplementing your info because it's relatively cheap.

#

Like for college, being able to do S+ videos on that site and supplement with whatever my professor is saying is cool. Multiple perspectives on the same thing.

gritty barn
#

We've also been given a 30% discount code on
@nostarch
books! Head over to their website and use the code "BSHTX30" during checkout!
(until 17th of September)

tepid patio
#

Ciphey - Automatically crack, decode, and decrypt ciphertext without knowing the key or method of encryption used.

Supports 34 methods including XOR-crypt, caesar cipher, most base decodings and more.

Since the last time I have posted, we have added:

+ XOR
+ Repeating-key XOR
+ Base62
+ Base91
+ Base69 (nice)
+ Base58
+ Base58 (ripple)
+ AtBash
+ Standard Galatic (Minecraft enchanting table)
+ Binary Substiutuion cipher
``` and we're adding even more 😄 (full list here <https://github.com/Ciphey/Ciphey/wiki/Supported-Ciphers>)

PS: We're **very** easy to contribute to. Just DM me if you want to contribute something ✨  

https://github.com/Ciphey/Ciphey
GitHub

Automatically decode encryptions without a key, decode encodings, and crack hashes - Ciphey/Ciphey

shut ferry
odd quest
zenith flint
#

old but it's good

tepid patio
#

^^ Resource is free before anyone tells me to check it oue 👀

cloud brook
#

Hello I am Blob! I published my blog post about how to go about making a Vulnerable (linux) machine, for those of you who are interested in that type of thing. Feel free to check it out here:
https://bobloblaw321.wixsite.com/website/post/the-making-of-a-vulnerable-machine-blob-blog

(I'd love feedback for if there are more services you'd like to see how to set up if you guys enjoy that post!)

daring hull
#

I watched the first half before I fell asleep last night. I think it's very informational, at least the portion about why certain programming languages have become as popular as they have.

https://www.youtube.com/watch?v=QyJZzq0v7Z4

Richard is a member of the Elm core team, the author of Elm in Action from Manning Publications, and the instructor for the Intro to Elm and Advanced Elm courses on Frontend Masters. He's been writing Elm since 2014, and is the maintainer of several open-source Elm packages in...

▶ Play video
gentle comet
spiral zodiac
tepid patio
shut ferry
white pivot
#

Nice one @shut ferry

shut ferry
#

thanki

novel lava
past oyster
#

I didn't think that it was possible to hack neural networks

#

Thanks for this, something nice to read during lunch for the week 🙂

gusty pollen
#

is it possible to use a neural net for the defense?

sturdy shell
#

Indeed (:

#

It's a cough thing that's being cough tried for a box

daring hull
#

Resource Request: One of my classes is basically part of CompTIA's Security+. We are given access to the book CompTIA Security+ SY0-501 Cert Guide, Academic Ed (2e). The book seems okay, so far, but it seems like we're not getting too many lectures and are being expected to just kinda read the material and figure it out. The book is from 2017 and given the nature of InfoSec, I suspect some things might end up not being correct for 2020 standards, possibly 2021 when I take my exam. THM, as a general resource, has helped me prep a lot for the first few chapters, but considering this monster of a book has 18 chapters, I do have some concerns. Eventually, I'd like to turn this class into getting my own Sys+ certif and eventually OSCP.

For anyone who has done Sec+, do you all have any recommended resources that can help me succeed? Are there any pitfalls that caught you? I'd love to hear some input.

unborn gust
#

@daring hull I just took my security plus three weeks ago. It was not bad at all the first 4 questions are all practical and I recommend you skip them and move on to the 75 multiple choice. Some of the questions are multiple answers and they do give partial credit. The only study tool that I used was a book that I bought online which is : Security+ Get Certified Get Ahead. That book I read it and studied the definitions really well and did well on the exam. If you have some prior experience in Cyber Security then some of the concepts is just repetitive other things will be new

daring hull
#

That makes me feel better, especially having a jumpstart in InfoSec with a good community. I just started on my path officially this year, so while I still have a lot to learn, I definitely know that I know more than I did. I usually see a lot of people parrot that Sec+ was really difficult and a lot of people flunk the first time. I'll check out the guide you mentioned.

spiral zodiac
daring hull
#

The other day I talked about Dark Reader. I think some folks are unaware you can blacklist certain websites from Dark Reader so that you can use the dark mode that the website provides.

Dark Reader can be found here and is available on pretty much all of the major browsers: https://darkreader.org/

If you want to blacklist websites, head over to the tab labeled site list and click on not invert listed, then add the domains you don't want Dark Reader to... darkinize. If you're a uni student and are having to use e-books, Dark Reader is really awesome because it gives you a dark black background with light grey text and it makes reading a lot easier.

sturdy shell
#

+10 this it's saved my life since

gritty barn
#

-5 the above sentence needs some inglish inprovements @sturdy shell

#

(that is done on purpose btw)

azure widget
keen field
spiral zodiac
prisma bison
balmy merlin
#

That's not even accepted on the writeups on rootme

odd quest
#

And please only post it of it's approved

#

@lone crane please don't post writeups unless they're approved by the room creator. Writeups that are approved go in #thm-community-media.

lone crane
#

ok

queen wyvern
#

It's free for today if you wanna enroll

daring hull
#

Great catch, Quantum

sturdy shell
#

Please don't share referall links @digital crag

digital crag
#

sorry

sturdy shell
#

You can share that the course/offer exists, but yeah, no refereals pls :3

digital crag
#

thanks for the warning

shut ferry
sturdy shell
#

Windows resources looks good, defo gonna give some of them a read (: thanks!

shut ferry
#

Sure thing 😄

#

Out of curiosity how deep into windows exploitation are you trying to get @sturdy shell?
I could DM you some notes ive been taking in school depending on what you're studying

sturdy shell
#

Ah, not so much windows exp specifically. I specialised in malware analysis in my degree so anything Windows RE I eat up (:

#

Not trying to get any 0days or write dll injections hehe 😅

shut ferry
#

Have you used flarevm at all? Ive heard some pretty good things about it

sturdy shell
#

that's a pretty cool repo aye, I'm on VirusShare + a few other closed circles for that sorta stufff

#

FlareVM is great!

shut ferry
#

I really want to get more into the RE side of things, ive really only been focusing on pure binary exploitation stuff (RE is a part of it I know) but would you have any recommendations on things I could use to work on?

#

I will need to write a thesis paper at some point in time

#

and id like to do it on malware RE

sturdy shell
#

Really good if you want a quick lab environment, making your own is a lot more riskier and tedious but is a lot better in the long run

#

For Windows Malware RE? I can dig some out for sure

shut ferry
#

yeah I just picked up an old thinkpad x220 from a craiglist guy that im planning on using for an isolated lab

sturdy shell
#

I have a couple of beginner friendly Malware RE rooms on THM already

#

Granted you're analysing software that I had to make that pretends to be malware

#

but the next one is doing all the forensics of Ceber and Wannacry but it's chunky

#

I'll dig out some good stuff bare with me 👍

shut ferry
#

oh word? ill have to check that out. Right now im just trying to develop more skills, so it dosent have to be real malware. As long as im able to develop that process then all good

#

thanks!

sturdy shell
#

Accepted your FR (:

shut ferry
#

❤️

sturdy shell
#

Yeah it goes through all the practical techniques (: my dissertation was on malware detection via ML so I'm keen to hear about yours ^^

shut ferry
#

Well its going to be a paper im going to be submitting for this scholarship/program. Its not "graded" but its supposed to be a technical paper displaying knowledge as to why id be suitable for the program. I can do anything I want for it, no set topic

sturdy shell
#

Ah I gotcha, pretty neat to have that freedom

#

I'll shoot over some stuff when I get the chance later today (:

shut ferry
#

thankie :))

white pivot
#

RE/PWN for life.

ebon valve
tepid patio
#

premiers in 2 hours

#

😦

ebon valve
#

Super super soon

spiral zodiac
faint sluice
#

awesome

azure drift
#

Hey , have a quick question

I’m pretty new to reverse engineering, I have a very basic knowledge of x86 and wonder if there is any methodology / course to improve skills ? ( other than x86 courses )

fringe spire
#

@azure drift #general . Also read channel description

cloud brook
#

lol james just told him to ask here

odd quest
#

I really liked Shellcoder's handbook

#

@fringe spire A request for resources kinda fits here, don't you think?

fringe spire
#

lol james just told him to ask here
@cloud brook uhmm..... Hides

odd quest
#

The Shellcoder’s Handbook it's not really an x86 book but I've found it super interesting with bof etc

runic sorrel
tepid patio
#

His friend's name is Caleb, very talented coder 🙂

runic sorrel
#

Yea had to go back in the video to find his name haha, Thanks

white pivot
#

@azure drift Check the pinned messages, there are some resources.

spiral zodiac
night holly
#

👀

tepid patio
daring hull
#

That's really cool of Microsoft to do

gritty barn
#

Dropping this in resources too:
https://pauljerimy.com/security-certification-roadmap/ for people that want to build their own certification path. It's an interactive map that also takes you to the payment screen and provides some short details about the cert itself (pricing too)

IT Security Certification Roadmap charting security implementation, architecture, management, analysis, offensive, and defensive operation certifications.

#

@honest dock mind pinning this for other people to see it too?

gritty barn
#

ty

honest dock
#

np

faint sluice
#

Dark also references that chart in his new video

magic idol
#

Not sure if this is the section. But, can anyone recommend an app for droid to get infosec news etc. I tried setting up alerts via google but 1) nothing comes thru 2) i dont want my email to be filled with notifications. Looking for like an alert feed type of an app, if it even exists.

tepid patio
#

Sounds like an RSS reader to me

#

I use Feedly

magic idol
#

Thank you for the suggestion. I also set google to notify via rss but nothing ever comes thru.

spiral zodiac
queen wyvern
#

#request Resuources on sql injection pls 😕 (not cheatsheets or rooms), not anything too beginner friendly 🙂 I can't find anything that isn't too beginner friendly or too easy, I have done that kind of injection, some advance onces are just too small to learn anything

night holly
#

Did you look at port swigger?

honest dock
#

Check the “resources” Task in my sql injection room

#

it has plenty of challenges/blogs/guides/lists

azure widget
queen wyvern
#

Check the “resources” Task in my sql injection room
@honest dock Isn't that sub only ? I don't have a sub currently

odd quest
#

Easy fix for that

#

PortSwigger is really good tho

queen wyvern
#

Not so easy for me. I literally have to beg a friend of mine to get me a voucher since my bank declines any transaction with THM automatically

#

I almost forgot about web academy

odd quest
#

I'd also personally recommend learning some webdev so you can add some context to your sqli and sql knowledge

queen wyvern
#

I am learning php and js

craggy onyx
#

What do you want to learn? Database security?

odd quest
#

Getting a holistic picture with all your context has been super helpful for me

queen wyvern
#

I just want to get good at owasp top 10

#

I thought I will start with injetions, sql in particular

craggy onyx
#

I would start with learning how a database works, how queries work using SQL, how a database interacts with web services, etc..

#

Foundational level of understanding what is being attacked.

queen wyvern
#

Yes I watched a vid on mysql

craggy onyx
#

Set up a mysql database and populate it with tables, etc..

queen wyvern
#

That's what I thought, to better understand sqli, I need to learn sql first. so that step is clear 😁

craggy onyx
#

You are probably running into the issue that most videos / tutorials online are introductory in nature. They only scratch the surface of topics discussed.

#

Which gets frustrating. 😄

tepid patio
#

Hey! My friend made an interactive editor for binary exploitation 🙂 🥳 Friend: @analog shoal. @white pivot you might like this 😛 https://smashing.c3murk.dev

white pivot
#

Nice one @analog shoal

queen wyvern
#

You are probably running into the issue that most videos / tutorials online are introductory in nature. They only scratch the surface of topics discussed.
@craggy onyx Exactly kekw

pliant swift
#

Does anyone have a version of incognito2 already compiled in exe

queen wyvern
#

They already have an exe on github

spiral zodiac
queen wyvern
astral dawn
pliant swift
daring hull
#

Practical Ethical Hacking, Windows and Linux PrivEsc on sale, again

ebon valve
glad hazel
sturdy shell
#

Nope

#

But they're very very frequently on sale (:

#

And they're real good sales too

daring hull
#

@daring hull Are this cources goes for free any time?
@glad hazel You would have to watch his Twitter. He sometimes drops free codes (as seen in the original tweet) but the courses go on sale often and I'd say it's worth giving the guy money for making good courses

modern abyss
#

I have updated my ezpzBOF v2.0 🙂 Can try use this on any bufferoverflow room in TryHackMe hehe

queen wyvern
odd quest
#

What

#

The only rules are against self promotion and piracy really

queen wyvern
odd quest
#

Self promotion.

#

Please remember rule 15.

queen wyvern
#

self promotion of paid content, so unless you get someone else to promote the paid content, it's fine ?

odd quest
#

It's a well regarded, widely accepted high quality course. Sundae does not profit from it. Sundae is sharing a discount code.
Sundae is fine.
Please leave the enforcement of rules to the moderators.

queen wyvern
#

I'm not encfocring any rules, nor picking on sundae. Just trying the understand the rules better

odd quest
#

Your message seemed very much like a complaint.
Do not self promote here. If it's something you made (and will make money from) or something you make money from (eg referals or made by a friend who is sharing profits), don't use this channel to advertise or promote it.

arctic mist
#

Hey guys, buy throwback kekw

queen wyvern
#

It was a question, sorry if it felt like something else. I have never and won't promote anything mine, or someone else's of course. Have a nice day 🙂

ebon valve
spiral zodiac
white pivot
#

Dark is on write-ups spree.

craggy onyx
grim crown
arctic mist
queen wyvern
#

There is

#

I have been learning from awesome repos for months now

tranquil shuttle
#

Hey everyone i made this resource for hacking kind of to act like a cheat sheet and stuff and now i transferred it over to a subdomain any kind of suggestions or comments would be very much appreciated as i am trying to improve it and then later on make it public and open source notes in a way

tepid patio
spiral zodiac
tepid patio
#

oh hi forum staff Ma1ware

spiral zodiac
#

😉

fringe spire
#

Fix Forum blobknife

spiral zodiac
#

🤫 It's not broken! blobknife

fringe spire
#

Everytime you change Sorting it shows different results

spiral zodiac
#

🤫 Let me advertise lure people into the forums!

prime mantle
#

LMAOOO

shrewd ginkgo
#

Stumbled upon this website/blog about a week ago after completing James' Crypto 101 room. The blog has very nice essays on HTTPS and Public Key Infrastructure as well as refreshing & fun to read posts on games, encryption, web security etc.
https://robertheaton.com/

tepid patio
fervent stream
#

its been like that for a couple weeks im p sure

#

weird they are just tweeting about it

faint sluice
#

when they going to add wide pages as a default option?

faint sluice
gritty barn
#

nice, i plan on taking N+ next month

white pivot
#

You're on cert spree or something? @gritty barn

gritty barn
#

I'm on vouchers are about to expire spree @white pivot

white pivot
#

Wish I could be that lucky

shrewd ginkgo
ebon valve
vast isle
#

great passive OSINT search engine

#
#

good tools

spiral zodiac
#

Navi's nice, I've used it before

shut ferry
#

Thanks! I use this as well

runic sorrel
fossil gorge
#

Does anyone know any book / website to practice network diagrams?

shrewd ginkgo
#

Draw.io is a nice diagram making website
You can make network diagrams with it too

fossil gorge
#

@shrewd ginkgo where can i get scenario questions based on which i have to draw a diagram?

shrewd ginkgo
#

Now that I don't know

azure widget
#

@fossil gorge I mean it depends on what you’re talking about if you just want a static picture then pretty much any flow chart creator will do. If you want something with more functionality then something like packet tracer which is a network diagram simulator or GNS3 which is a network diagram emulator, can help you

#

I personally really like GNS3 because it has so many options for packages however it can also be harder to setup

fossil gorge
#

@azure widget I was hoping to find something that will describe a network and then require me to draw its diagram

#
  1. Two networks A1) B1)
  2. Each network requires a border router
  3. Each network needs a firewall blocking inbound traffic
  4. A1 has four network subnets A) R&D B)Customer Support C) IT D) Data Center
  5. B1 has three subnets A) HR & Legal B) Users C) Business Apps
  6. Both sites are connected via a VPN
    .....

Something like this that I could put up using drawio

ebon valve
quasi crescent
#

Hi, I am looking for a good OS course

#

If anyone has some online courses on the bookmarks, I would appreciate if you shared them

#

❤️

ebon valve
fringe spire
#

Are you allowed by admins to post that here?

spiral zodiac
shut ferry
queen wyvern
#

Umm, that actually is not allowed

tepid patio
#

Looks to me like it is?

queen wyvern
#

This is a writeup of some sort that makes answer to RedTiger's Hackit Public, when the owner of the challenge has mentioned that they shoudn't be made public

nova pond
#

Hey guys, what would be a good resource to learn reverse engineering?

I already know a good amount of c++/assembly and have already done some easy crack mes, so I am not a complete beginner.

shrewd ginkgo
nova pond
#

Thanks. Will take a look at it when I am home.
If anyone else has other suggestions just tag me 🙂

elder vault
#

Hi guys. I'm new here.. Can I get any resources for learning bash scripting please?

civic halo
#

Have you tried Google?

elder vault
#

yeah.. but there are many and i'm confused

queen wyvern
#

@elder vault

elder vault
#

okay bro. I'll try that.. Thank you

solemn bough
jaunty raven
#

Can you guys recommend me a book or any resource on how to make your own CTF ?

pale dew
topaz gulch
#

@jaunty raven I have slides from a presentation I did on it on my blog (https://muir.land/content). Dark also has a blog post on it on the TryHackMe Blog: Making the Mountain

sturdy shell
#

Also lowkey going to plug this from TryHackCIT

#

granted 99% of the content to go with it is missing, the URL's at the end are useful if you're looking to create some stuff for THM specifically (but the stipulations are pretty sensible for any CTF)

shut ferry
topaz gulch
shut ferry
#

ok

glad hazel
#

I just published How to install Ubuntu with GUI on Digital Ocean for free ? https://link.medium.com/KGsjA5KkZ9
@solemn bough Is there any way I can get the same t results with AWS?

queen wyvern
#

Yes

#

Use an AWS Account

solemn bough
#

Yes mate @glad hazel you could Just follow the same process I used digital ocean as they provide credits instead of free tier you could use free tier too but the speed is comparitively slow

glad hazel
#

You mean the response will be too slow to work with

#

?

#

I mean kali is not going to hold on free tier specs. I guess

civic halo
#

@glad hazel if you want a proper hosted solution for Kali. Check out the TryHackMe subscription. It's $10 a month and you get a AWS hosted Kali or THM AttackBox. The only thing you won't have with it, is Persistence. Once it terminates its reset back to factory. But it's a good solution if you haven't got good hardware to run a VM.

lavish burrow
#

can i get some resources for creating rooms based on owsap top 10

keen field
quartz torrent
#

want to know how to do automation script writing

craggy onyx
steady crater
#

Hey guys im trying to learn Python code so does anyone know a course or a place that teaches me
I only know Print("")
lol

odd quest
#

Sololearn

steady crater
#

is that the website or something?

odd quest
#

Have you googled it?

#

Because you should

prisma bison
#

The best place to learn is solo learn in my opinion but just typing in “Python Basics” or “How to code python” into google has many YouTube tutorials and websites dedicated to teaching you Python :)

tepid patio
#

My face resource is "automate the boring stuff"

tribal gull
#

oh man i haven't seen that channel for months

#

he has some really nice vids

night holly
#

Shame he doesn’t do it anymore

sturdy shell
#

thenewboston

#

holy moly

jaunty raven
#

Yeah he has some great tutorials on his channel

tepid patio
civic halo
#

Yay

#

Need a new shirt tbf

spiral zodiac
prisma bison
#

Very cool

shut ferry
odd quest
#

VM escapes pay big money

#

Huge bounties

shut ferry
#

I'm really glad I found out about it

odd quest
#

Because it's typically significant if you can escape the VM

shut ferry
#

I'm going to google it a bit more, hopefully find a poc

#

I'm going to start separating my network...

sturdy shell
#

If you can escape from a sandboxed VM be it Hyper-V/VMware you're showering in money and job prospects

keen field
inner pewter
#

Hypervisors can be exploited, but unsure if you can break out of the VM via the guest OS

#

Thats better, now I have a name ha

keen field
#

what's the difference between a cloud base vm and vps?

inner pewter
#

P->Private - host resources not shared with other vms

#

A VPS can be a cloud (IaaS) service...its justs dedicated

grim crown
odd quest
#

Hypervisors can be exploited, but unsure if you can break out of the VM via the guest OS
@inner pewter Yes. You can. It's a severe vuln

ebon valve
azure widget
#

This is what nightmares are made of

tribal gull
#

oh god 1.5h of darkstar

#

also not sure if it's just me but the timestamps aren't showing D:

azure widget
#

Instead of ocean waves to go to bed now you can listen to dark star

tribal gull
#

😄

ebon valve
#

Timestamps are down below

#

I'm not sure why YouTube isn't showing them on the video, they were working yesterday when I tested it

pale dew
#

1.5 hour to understand shiba1

cloud brook
#

dark, i still cant SSH into shiba1

#

halp

ebon valve
#

oof

queen wyvern
#

forget that, how to deploy machine

azure widget
#

some of the best guys in the industry if you don’t already follow their work I highly suggest you do

white pivot
night holly
#

@spiral zodiac 👀 ^

spiral zodiac
#

Ooh, very nice! Good job on that writeup @white pivot

thorn rock
#

dark, i still cant SSH into shiba1
@cloud brook are you using correct password?

spiral zodiac
#

🤦

white pivot
#

Ooh, very nice! Good job on that writeup @white pivot
@spiral zodiac Assuming JB's tag, you guys were looking for something like that :p

edgy plank
#

are you using correct password?
not psswd problem man

cloud brook
#

@cloud brook are you using correct password?
@thorn rock I think so... it doesn’t work 😦

prisma bison
#

lmao

topaz gulch
#

inb4 Bob is trying ssh shiba1@localhost with his own password 😁

#

(Yes. That has happened, and yes, the person posted their own password in community-help)

spiral zodiac
cloud brook
#

Wait so the password isn’t iamblob6969?

prisma bison
#

(Yes. That has happened, and yes, the person posted their own password in community-help)
Damn

#

Blame Pars, bad instructions

topaz gulch
#

Oh, I frequently do 😁

shut ferry
#

hahaha

arctic mist
sturdy shell
#

Oooh that looks good

cobalt trout
#

Good courses on: Networking (Especially for cybersecurity), Server Administration (Windows AD DC, ...), LPI?
I aim to study the basics before moving on to specific fields like PT and Red Teaming...

craggy onyx
magic idol
#

Can someone recommend a book of some sort on pentesting/kali. Something that possibly teaches tools and shows methods

#

Its confusing, as there is a lot to choose from. Looking for something that mirrors OSCP study material

keen field
#

@magic idol beginner level?

magic idol
#

@keen field yes, preferrably.

keen field
#

@magic idol ETHICAL HACKING
AND PENETRATION
TESTING GUIDE
RAFAY BALOCH

magic idol
#

Thank you. I will look that up on amazon :)

keen field
#

very beginner friendly

magic idol
#

Classic matrix wallpaper haha

keen field
magic idol
#

Before I decide to purchase Ill wait for a few more suggestions/opinions

#

Thank you tho. It is now added to my list of possibilities@keen field

faint sluice
#

although her new book is coming out 'soon', this is a classic https://nostarch.com/pentesting (Penetration testing by Georgia Weidman)

magic idol
#

Cool. Thank you.

ebon valve
dire linden
#

how can i hack on a Macbook Pro

odd quest
#

You can use a VM, or you can install tools on macos

faint sluice
#

(I'd really only do that if you have a spare macbook or such... but that is just me)

queen wyvern
#

I'm also not sure about the legality blobgrimacing

odd quest
#

Yeah that sounds pretty sketchy to me seeing as it violates the license terms @rough trellis

#

I'm deleting it

dawn trench
dire linden
#

thanks mate

#

that was helpful

dawn trench
#

kali comes with hydra and nmap

dire linden
#

cool

willow crag
#

Guys i can't deploy the room. Is there a page to view all the deployed rooms at once?

cloud brook
#

Check tech support. Termy tagged you @willow crag

willow crag
cloud brook
#

That’s what you get when running szys snippet?

willow crag
#

Yeah Giving errors but one of my VM i think got expired. So it's good for now.
Maybe THM should create a separate page for checking and monitoring VM's..

cloud brook
#

or just turn off the VMs as you leave the room

willow crag
#

😄 Yeah

pale dew
#

the script worked, this is the output it sends, i just tested here

haughty aspen
cloud brook
#

Beautiful

#

Perhaps add asp to the aspx list?

unreal hollow
#

I am working on writeups for different rooms I have been working on, but I want to know the best way to post them - i.e. blog, github, etc. Any ideas would be helpful

tepid patio
#

blog preferabl

#

you can host a free blog on github pages using jekyll

#

or you can use 11ty or hugo or gatsby + netflify

unreal hollow
#

LGBee thanks, I will take a look at them

shrewd ginkgo
spiral zodiac
severe moth
#

hi, does any one have a good resource about buffer overlfow?

arctic mist
#

Tib has a bof room on thm

#

other than that, dostackbufferoverflowgood is p-good

severe moth
#

thanks, i give it a look. yes the THM rooms i have found. i need only some thing to read about this first. 🙂

ebon valve
#

This is fairly technical but it's a great resource

night holly
ebon valve
spare vapor
#

A proper guide to crack the exam 💯 sadcooctus

spiral zodiac
night holly
tepid patio
#

Hey everyone! 👋
It's hacktoberfest time! If you submit 4 pull requests this month (after signing up to Hacktoberfest via https://hacktoberfest.digitalocean.com/) you'll receive free merch (a shirt, stickers and maybe some other things).

Ciphey is now open for Hacktoberfest with a whole range of GitHub issues (and we add more everyday) ✨

https://github.com/Ciphey/Ciphey/issues?q=is%3Aissue+is%3Aopen+label%3Ahacktoberfest

GitHub

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡ - Ciphey/Ciphey

odd quest
#

@small night ?

tepid patio
#

@odd quest It's a referral linnk

#

an MLM

#

One link is okay because it's an event, but any more and it's deletion blobban

#

tell u what

#

that's better blobheart

rapid vortex
#

Any good ios exploitation book

craggy onyx
#

There is the iOS Hacker's Handbook, but it is quite old from 2012. A more recent publication is iOS Penetration Testing: A Definitive Guide to iOS Security, by Kunal Relan. @rapid vortex

odd quest
#

@grizzled notch please don't post referal links

#

That resource has already been posted

rapid vortex
#

@craggy onyx thanks

ebon valve
crimson thunder
#

hit me with your fav wireshark learning resource

azure widget
#

@crimson thunder Well, I think wireshark is fairly intuitive, the documentation for it is amazing. You can find samples to practice with https://wiki.wireshark.org/SampleCaptures I would just practice, it really depends on what you want to do with wireshark and why. I’ll be coming out with a room soon on it so all resources will be in one place.

crimson thunder
#

@azure widget good to know that about the documentation. I'll give it a look. Nothing particular, just need to dive in while preparing for the ejpt

azure widget
#

I have no clue what wireshark has relevance in eJPT but 🤷‍♂️

gritty barn
#

it has no relevance for eJPT @crimson thunder don't worry about it

crimson thunder
#

it's covered in the course

gritty barn
#

yeah, not on the exam

crimson thunder
#

oh I don't expect a wireshark exam or anything like that, but just reading the material feels wrong 😛

#

anyways, I never really properly learnt to use it and generally I try to have more than one resource for everything

#

thanks for the answers

craggy onyx
#

Learning Wireshark in general is an asset to have, as to having visibility how normal/suspicious traffic looks like on a network. How network packets in general look like.

azure widget
spiral zodiac
#

👀

azure widget
#

I’ve looked at the content it’s nothing crazy but free is free

tepid patio
edgy plank
queen wyvern
queen wyvern
#

**8 Hours Web Application Penetretation Testing **

tribal gull
#

@queen wyvern 1. the shortened link does not work
2. why did you shorten it? are you hiding a reflink?? kekw

queen wyvern
#
  1. It works 👀
  2. It's udemy, there's no referral
  3. I shortened it, cause the link was ugly @tribal gull
tribal gull
#

uhh i think you can remove most of the query params

queen wyvern
#

Edited

tribal gull
#

noice

versed shoal
tepid patio
queen wyvern
#

Yes

#

Yess !! Thanks

#

For people wondering how to embed, copy the link and select embed , or create a new embed and paste the link

azure widget
spiral zodiac
tepid patio
ebon valve
shut ferry
#

Note - I was banging my head trying to fix this, thought I'd pass this along to help others.

Issue - The newest version of VirtualBox-6.1.14-140239 for MacOS Catalina has a bug that aborts Linux VMs when it attempts to check audio permissions with CoreAudio, ICH AC97 enabled. I haven't fully tested with SoundBlaster 16 or Intel HD Audio, enabling them doesn't crash the Linux VMs. Windows VMs don't seem to be effected.

Resolution - Disable the audio in the Linux VMs settings. Try using the SoundBlaster 16 or Intel HD Audio if you need audio.

queen wyvern
#

@shut ferry Spamming same question in multiple wrong chats flush

spiral zodiac
queen wyvern
#

Yes my bad

tepid patio
#

u ok? blobheart

civic halo
#

I suggested that they put it here. @queen wyvern u OK hun?

shut ferry
#

@queen wyvern 1 - My bad, apologies - it wasn't intentional. 2 - Other mods keep telling me to post in other chats. Simply trying to help out.

spiral zodiac
#

@shut ferry None of them were mods, and this is the correct chat. 🙂

shut ferry
#

@spiral zodiac 🤘

civic halo
#

I'm not a mod but I knew it would get lost in General and this is a nice safe place for your fix

queen wyvern
#

I already apologized, but in my defense I just saw this whole bunch of a text in 3 chats in under a minute

shut ferry
#

I'm still learning the lay of the land. I appreciate the help.

scenic summit
#

need a few sources for concepts regarding embedding something to a file (commonly used within images particularly)

#

i dont know the name of its process

azure widget
#

Steganography

queen wyvern
#

Do you mean Steganography ...

crimson thunder
tepid patio
prisma bison
#

👀

odd quest
scenic summit
#

@azure widget @queen wyvern tnx much both of you

odd quest
#

https://github.com/NinjaJc01/thm-compete-bot
So I decided to make a discord bot to encourage my housemates to compete for a leaderboard position.
As it's Hacktoberfest, I opensourced it and converted it over to embeds.
It's designed for smaller communities, and gives a daily leaderboard of the users from the config file.

Update: It now adds profile pictures to individual user statistics.
PRs are open for adding features, long as you can justify it

tepid patio
dapper hound
#

Anyone know some good sources to learn powershell more in depth. Just completed the thm room and enjoyed it so wanna go into powershell in depth now thnks

azure widget
#

over the wire

dapper hound
#

Do u know the specific section its under, if u dont mind me asking?

azure widget
#

Ah shit I meant under the wire not over

knotty sequoia
dapper hound
#

Ahh perfect, thnks both for the help 🤟🏻

queen wyvern
#

@dapper hound

cerulean viper
#

xD

queen wyvern
#

Please avoid self-promotion of paid content here.

#

@cerulean viper

cerulean viper
#

aight man I was helping 🥺
no issues

queen wyvern
#

A 4 days old website selling a 225$ course sure isn't sus at all

honest dock
sullen turtle
tepid patio
sand portal
#

can anyone recommend a good reference for sed?

night ether
nocturne heart
#

Hi are there any resources one would recommend for digital forensics? I completed the iOS forensics lab which was amazing, i would like some more to do. Pls guide

low goblet
#

Hello all! I am looking for some documentation for Cobalt Strike artifact kit (official or Unofficial)

craggy onyx
#

Hi are there any resources one would recommend for digital forensics? I completed the iOS forensics lab which was amazing, i would like some more to do. Pls guide
@nocturne heart Click on Forensics to see all rooms https://tryhackme.com/hacktivities

cold drift
#

GHunt is an OSINT tool to extract information from any Google Account using an email. https://github.com/mxrch/GHunt

GitHub

🕵️‍♂️ Investigate Google Accounts with emails. . Contribute to mxrch/GHunt development by creating an account on GitHub.

queen wyvern
#

Can I have your email pls @cold drift

#

Wait, you are not @cloud brook KannaWhat

cold drift
#

Wait, you are not @cloud brook :KannaWhat:
@queen wyvern nop

odd quest
#

oh no

cold drift
#

Can I have your email pls @cold drift
@queen wyvern send me your email first pls @queen wyvern

pale dew
#

blob 2

spiral zodiac
#

@cloud brook you have an imposter now

gritty barn
#

sus

queen wyvern
#

Yeah, I saw him vent

cloud brook
#

OI

#

WHAT IS THIS NONSENSE

#

!ban @cold drift

#

its ok guys hes banned now

spiral zodiac
#

🔨

cloud brook
#

@odd quest can you ban plz

odd quest
#

👀

cold drift
#

OI
@cloud brook why?

cloud brook
#

Cuz you’re imposter blobknife

#

There’s only 1 baam allowed in this discord

cold drift
#

Cuz you’re imposter blobknife
@cloud brook imposter??? oh okay, it's my favorite manga character (TOG)

#

so, i'm sorry

cloud brook
#

No sorry. Just ban

#

Also it’s not a manga

pale dew
#

no sorry just baam blobfingerguns

tepid patio
#

@cloud brook this is why you slightly edit your photo

#

so if someone does have it, you know they stole it from you

fringe spire
#

then copyright claim

cold drift
#

Also it’s not a manga
@cloud brook webtoon ah ah

cloud brook
#

@cloud brook this is why you slightly edit your photo
@tepid patio it’s just a google image tho haha

cold drift
#

so if someone does have it, you know they stole it from you
@tepid patio I do not even know its id, in addition I have this photo for a long time (from google image) in all the platforms where I am registered (hackthebox, discord, ...)

cloud brook
#

Not good enough

#

I have it there too

#

I vote we do a hack off

#

Gib public ip

faint sluice
#

Hey I took a class from Lenny many years ago

tepid patio
#

Lenny maintains the docker image for Ciphey

#

v/ nice person

#

also like super very helpful over DM

#

Like TryHackMe mod level helpful, literally sends me like 20+ messages to explain a problem / help me fix it

#

Very very nice person

#

love that folk

faint sluice
#

Yup, very nice, was a good and patient instructor

sullen turtle
#

It might seem quite basic to some people, but for CTFs (and koth ;) ), this is all you need to know for file upload bypasses

#

It's only 9 pages, so not a bad read

#

and it shows you the PHP going on in the background to give you a deeper understanding

shut ferry
#

I collaborated with Superhero1 and have put out this video on Binary Exploitation, its the first part of a much larger series. New videos will be coming out as time develops.
https://www.youtube.com/watch?v=fuV0p8mop5w

In this video we will look at two simple demos on Linux by reverse engineering and learn about buffer overflows.

Please subscribe, like & comment!

Cheers, superhero1

[ #! cat superhero1-links.txt _ ]
Tools

▶ Play video
low goblet
#

Hello all! I am looking for some documentation for Cobalt Strike artifact kit (official or Unofficial)
@low goblet Anyone?

gritty barn
#

for people that want free certifications

night holly
#

Did somebody say free certs 👀

random elk
#

I bought the book and I wanted to share it with the community. Enjoy tipsfedora

night holly
#

uhh

tepid patio
#

1 second 👒

night holly
#

wait bee

#

let me grab it for mal analy

tepid patio
#

17mb

#

im on 200kbps

#

can you open it for me and tell me if its legal

night holly
#

I got it

#

One sec

#

let me open in linux

tepid patio
#

ok cool im on 20% download rn

night holly
#

I mean he said bought

#

soo

tepid patio
#

All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means,

night holly
#

rip

#

kek

civic halo
#

The Ebook is Free if you buy the book

tepid patio
#

ok 2 the secret chat i go 🦇

civic halo
#

Not for distribution

random elk
#

It can not be free if it's bought 😫

tepid patio
random elk
#

Don't have access to talk-with-us

tepid patio
#

check again

civic halo
#

They don't have the role Bee

tepid patio
#

they do now

civic halo
#

Not on my end kekw

tepid patio
#

smh

#

discord cache

civic halo
#

They had it earlier

tepid patio
#

feck it i'll just leave em in there hopefully they'll get the message kekw

civic halo
#

kek

tepid patio
#

ok its solved

#

that chat is just 99.9% discord caching issues

tepid patio
random elk
#

Still not have access but it's not a big deal, I won't send anything "illegal" anymore 😂👍🏻

civic halo
#

The fact that you've put it in quotes makes me thing you don't understand the fact piracy is illegal

random elk
#

Not at all I put it in quotes because it's illegal for you but not for me because I bought it 😉

#

Sorry for this mistake

odd quest
#

The distribution is illegal. So it's illegal for you. @random elk

random elk
#

OK ok Einstein

#

I aplologized

#

Aplogized

ebon valve
#

Alright, I banned him for that commentary

civic halo
#

I was waiting for someone to ban him kekw

faint prism
sturdy apex
#

thanks ! @faint prism

faint prism
#

The price is right..

odd quest
#

I want to say TCM also made part of one of the courses free

faint prism
#

link?

#

looking on their website..

odd quest
#

@faint prism blobfingerguns

faint prism
#

Ahah. the devils in the details (comments below) ty

#

Other than CERT/the osint github, can you guys think of any other halfway decent free threat intelligence lists to pull from

tepid patio
#

oh god

#

i told you

#

dont use that link

#

here

#

i'll repost it for you 🙂 Please in the future use links that do not have some encoded 4000 character parameter 😛

#
thick zodiac
#

hey guys, for a course in my cs degree, I have to attend an it related webinar and write a report on it. Since ive been so interested in cybersecurity I would love to follow a cybersec related webinar. Unfortunately im not exactly finding anything interesting... Anybody that has good sources for security related webinars? (it has to be in the future and live, im not allowed to watch a video of a seminar/webinar from the past)

craggy onyx
#

Search for a local BSides online event in your area @thick zodiac

thick zodiac
#

oh thanks! will do!

lime sleet
#

Search for a local BSides online event in your area @thick zodiac
@craggy onyx
what if area doesn't have local events 🤔 ... it's soo rare here

craggy onyx
#

When they're online, it is possible to attend them by signing up beforehand. Find the nearest one you deem useful. 👍

magic idol
#

In case someone didnt know, mostly beginners like me, PayloadsAllTheThings by swissky is fantastic

balmy merlin
#

There is the ZTH obscure vulns room which has that included

tepid patio
night ether
gentle shuttle
sturdy apex
#

good resources to learn RE?

queen wyvern
#

Hey @sturdy apex

#

Check the pins 🙂

sturdy apex
#

@queen wyvern Thx ^^

keen field
#

guys
any reverse engineering resources (very basic)
cuz i'm really noob @ rev eng
tnx

tepid patio
#

I started it

#

it's not proof read so it was physically hard for me to read

keen field
terse temple
#

A list of good resources to make a level up? Interesting writeups, some books, links

proper mica
#

Introducing HAT - The Hashcat Automation Tool has received 100 stars on Github! Wh00t!!!
If you're a pentester who wants to automate the laborious task configuring hashcat for every wordlist and add a bit of flaw check out HAT. Links to large working wordlists too! https://t.co/10xQH2caeT

white pivot
#

guys
any reverse engineering resources (very basic)
cuz i'm really noob @ rev eng
tnx
@keen field

# Resources

These are the resources I have found while learning about the binary exploitation.

### Blogs:-

* <https://syedfarazabrar.com/>
* <https://kileak.github.io>
* <https://d4mianwayne.github.io/>
* <https://ctf101.org/binary-exploitation/buffer-overflow/>
* <https://blog.skullsecurity.org/category/ctfs>

### Youtube:-

* <https://www.youtube.com/channel/UCi-IXmtQLrJjg5Ji78DqvAg/videos>
* <https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN>

### Wargames:-

* <http://pwnable.kr/>
* <http://pwnable.tw/>
* <http://pwn.eonew.cn>
* <https://www.root-me.org/?lang=en>
* <http://smashthestack.org/>
* <https://exploit.education/>


### Pwn Related Stuffs:-

* PwnTips - <https://github.com/Naetw/CTF-pwn-tips>
* Quick guide -<https://trailofbits.github.io/ctf/exploits/binary1.html>
* Pwn Challenge List - <https://pastebin.com/uyifxgPu>

### Stuff Robin gave me:-

* Course materials for Modern Binary Exploitation by RPISEC - <https://github.com/RPISEC/MBE>

* Learn ROP - <https://ropemporium.com/>

* For Linux binary Exploitation - <https://github.com/scwuaptx/HITCON-Training>

* Intro to binary exploitation / reverse engineering course - <https://guyinatuxedo.github.io/>

* A collection of pwn/CTF related utilities for Ghidra - <https://github.com/0xb0bb/pwndra>

* Some pwn challenges selected for training and education. - <https://github.com/BrieflyX/ctf-pwns>

* A set of Linux binary exploitation tasks for beginners on various architectures - <https://github.com/xairy/easy-linux-pwn>

* ASM Basics - <https://asmtutor.com/#lesson1>```
#

That's more pwn based than re based, but one is a subset of other.

fresh crater
#

beautiful

versed shoal
loud pier
sturdy apex
#

where can i find Ryan's CTF style ctf

lean widget
#

could someone help me in linuxprivesc machine ... i am unable to send the shell.elf file from my attackers machine to target machine ......task no 10 (wildcards)

cloud brook
keen field
#

i also recommend 7th ed. of the book above
it's a 0 to hero guide

civic halo
#

third time's a charm

crimson thunder
#

found this by chance, has anyone used it?

spiral zodiac
#

I have, there's also an "nmap vulners"

keen field
#

@spiral zodiac is that sudo nmap -sV -A -Pn -v --script=vulscan/vulscan.nse or else?

spiral zodiac
#

That command is very much redundant, you're using -sV with -A -A does both -sC and -sV as well as -O and traceroute.

keen field
#

yeah i know - but sometimes this works better in this way
that's a complete monster command
i like it

frosty cave
gritty barn
#

that's a nice cheat sheet ❤️

faint prism
#
keen field
#

will be hard then, when we wanna find all these sources here

craggy onyx
night holly
#

https://pwn.college
https://ctf.pwn.college

This site seems to have a decent amount of information and challenges on pwn stuffs

spiral zodiac
#

I've seen the first one before

night holly
#

I think the ctf part was released recently, but there seems to be a lot of challenges on it.

white pivot
#

It's from ASU, the creators of this platform are current DefconCTF organizers, and of course from Shellphish team.

tepid patio
mental coral
sturdy shell
split hamlet
#

Are there any good resources for setting up a android pen-test environment? I have an extra android phone so I don't need an emulator unless working with an emulator is easier. Would like to start testing mobile apps and platforms but not sure where to start.

crimson thunder
#

Use john (and anything else in /usr/sbin) without sudo as root: while logged in as root, append this line in ~/.bashrc
export PATH=/usr/sbin:$PATH

pallid sonnet
civic halo
azure widget
#

Steal my spreadsheet like that angrycooctus

civic halo
oblique quiver
willow crag
#

Guys, I'm having hard time with BOF.
Please share some good resource for learning BOF for OSCP.

fringe spire
willow crag
#

Share link to it Link

cerulean viper
#

meow..

#

Resgister please ^^
love u all

topaz gulch
#

@cerulean viper if that's a referral link, please replace it with a generic link to the resource 🙂

cerulean viper
#

cri okaie

cerulean viper
#

hey guys! greetings

#

so I just received an email from cybrary.com , they're offering me like 70% off to their annual subscription, $630 off discount after applying the coupon

#

Its $900 annualy but with coupon its only $270 🥺 I wish I had money atm..

#

anyways, If anyone of you is interested in that then lemme know, since it can be used only once and

#

its ending in 14 hours from now ,

#

time lmao

fringe spire
cerulean viper
#

yes I got that same mail! not sure if coupon works individually 😅

#

but it is

spiral zodiac
azure widget
queen wyvern
#

How much fun it is to click through random links

azure widget
#

if you’re uncomfortable with links use virustotal. NEVER click on a link if you’re uncomfortable or not sure about it until you confirm it is fine

cloud brook
#

Put the link in virustotal and it tells you if it’s valid?

azure widget
#

it will tell you if it is identified by anti virus and malicious checkers, it can identify malware, spam, and phishing campaigns

barren vault
glad hazel
pliant moat
#

its for binexp

#

so if you leak a libc address

#

and you want to know which version of libc it is

#

you plug the addr into the site

#

and it tells you

arctic mist
radiant gate
#

lots of awesome tools are made by them

cedar orchid
ebon valve
cerulean viper
#

hey guys just in case you missed, refer to this message segment -

#

extended time line - till 18th oct 2020... 2 more days I guess

#

so so , here's the coupon for 70% off

#

ZLU4Zo14

glad hazel
ebon valve
#

Oh make sure you have the custom tmux bit

#

Lemme grab my screenshot for my tmux

#

Also, make sure it's for the profile you're actually using

#

If you launch tmux as root, it has to be in the config spot for root

low ingot
ebon valve
#

Facts!^

low ingot
#

Basically goto as it's easy and just works

glad hazel
#

But not working

pliant moat
#

did you restart the tmux server?

glad hazel
#

I still get the normal tmux

pliant moat
#

and/or source-file?

glad hazel
#

did you restart the tmux server?
@pliant moat How can I do that?

pliant moat
#

oh ok you havent yet

#

C-b, colon

#

source-file ~/.tmux.conf

glad hazel
#

after starting tmux?

pliant moat
#

wait

#

did you exit out of the tmux session?

#

w/e

glad hazel
#

Yes that just default one not the github one

pliant moat
#

tmux kill-server

#

then spawn tmux again

glad hazel
#

let's do this in ib

#

Thanks for the help

keen field
versed shoal
rustic sundial
#

.

night holly
rugged stump
#

I m a beginner how to learn cyber security

queen wyvern
rugged stump
#

Yea

queen wyvern
#

That's one such website

rugged stump
#

But I don’t understand how to start

cloud brook
#

Beginner path

#

Some rooms are suggested on your dashboard as well

rugged stump
#

Which i read book about cyber security

tepid patio
oak pecan
azure widget
queen wyvern
#

Nice Find blobfingerguns

tepid patio
odd quest
#

oh no

inner oriole
#

Started writing posts on DFIR. It is still in its infancy but the aim is to break down some of the topics and concepts I feel Iare sometimes over complicated in other posts I read when I was starting out. Feel free to check it out and I will be regularly posting.

https://rorywag.gitbook.io/sleuthifer/

shut ferry
#

Jesus that discord RCE looks nasty 😦

sturdy shell
#

Defo a follow from me @inner oriole will be keen to see what you come out with!!

inner oriole
#

@sturdy shell cheers mate, will endeavour to be quick posting content :)

azure widget
#

This is an amazing opportunity to get SOC experience for free and find out what it’s like in a real live environment

modern abyss
edgy plank
#

POGU

#

lemme try that later

modern abyss
#

sure 🙂

frosty trellis
#

Hii 🙂 i am new here

#

Call me Enigma

tepid patio
queen wyvern
#

My First Ever Actually 😄

queen wyvern
#

**More Places to Practice/Learn Hacking **

#
https://www.hackthebox.eu

Vulnhub
https://www.vulnhub.com

Practical Pentest Labs
https://practicalpentestlabs.com

Labs Wizard Security
https://labs.wizard-security.net

Pentestlab
https://pentesterlab.com/

Hackthis
https://www.hackthis.co.uk

Shellter
https://shellterlabs.com/pt/

Root-Me
https://www.root-me.org/

Zenk-Security
https://www.zenk-security.com/epreuves.php

W3Challs
https://w3challs.com/

NewbieContest
https://www.newbiecontest.org/

The Cryptopals Crypto Challenges
https://cryptopals.com/

Penetration Testing Practice Labs
http://www.amanhardikar.com/mindmaps/Practice.html

alert(1) to win
https://alf.nu/alert1

Hacksplaining
https://www.hacksplaining.com/exercises

Hacker101
https://ctf.hacker101.com

Academy Hackaflag
https://academy.hackaflag.com.br/

PentestIT LAB
https://lab.pentestit.ru

Hacker Security
https://capturetheflag.com.br/

PicoCTF
https://picoctf.com

Explotation Education
https://exploit.education/

Root in Jail
http://ctf.rootinjail.com

CMD Challenge
https://cmdchallenge.com

Try Hack Me
https://tryhackme.com/

Hacking-Lab
https://www.hacking-lab.com/index.html

PWNABLE
https://pwnable.kr/play.php

WHO4REYOU
https://34.73.111.210

Google CTF
https://capturetheflag.withgoogle.com/

ImmersiveLabs
https://immersivelabs.com/

Attack-Defense
https://attackdefense.com/

OverTheWire
http://overthewire.org

SANS Challenger
https://www.holidayhackchallenge.com/

SmashTheStack
http://smashthestack.org/wargames.html```
crimson thunder
magic idol
#

Taking a google automation with python course and it is super confusing. I am not sure if I am not comprehending the material or their choice of using math to showcase python was not a very good choice

#

My brain is literally on fire

#

Pure frustration here😫

safe wave
#

hey there , i would like to know what sites to refer from before i start actual hacking , since the courses here are paid right? and i have zero knowledge of hacking.

#

thank you

prisma bison
#

Tryhackme is free

#

Subscribing is optional

#

I’d suggest trying the platform before making any decisions

magic idol
#

Subscribing is the best decision I made recently :)

#

Just imo

safe wave
#

is there a step by step process on what to do first

magic idol
#

Yes there is.

shut ferry
queen wyvern
#

is there a step by step process on what to do first
@safe wave Do the Welcome Room and OpenVPN Room first to know how to connect properly to the THM Network and do other rooms. Start doing rooms on your dashboard. Go to hacktivities, Sort by Free and Walkthroughs and start doing them

waxen lodge
#

anyone knows where i can get basic wordlists from? like rockyou.txt and dirbuster lists'

azure widget
#

seclists

waxen lodge
#

nice, thanks!

#

damn rockyou.txt is actually from a leak

#

i thought it was some basic made password list

tepid patio
#

this looks v/ cool

sturdy shell
#

Oowo

#

Wait Bee interview me

#

is that how it works

tepid patio
#

yess

#

you can interview peers

#

and sure

#

@sturdy shell we can do it rn?

sturdy shell
#

oh nice - great find

#

I'm eating ahah, just wanted to say hey to you 👉 👈

#

that'sa cool site

tepid patio
#

okkiii~~~

odd peak
#

@sturdy shell sorry for the ping but would you mind sharing you essay on emotet when it's done?

sturdy shell
#

No worries about the ping (: and sure, although I'm making study notes and then writing up to a blog post rather then an essay. But I can share it when it's written up for definite 👍

#

@odd peak (:

#

Appreciate the interest

odd peak
#

awesome

cerulean viper
visual wharf
#

Anyone here can check and give feedback about a recon tool i find in github?

azure widget
#

thats not typically what this channel is used for but Im free right now so whatever send it

visual wharf
azure widget
#

so pretty much just a rip off of tibs tool https://github.com/Tib3rius/AutoRecon I mean it can be good for ctfs and practice boxes but thats about it

visual wharf
#

Yes the autorecon is best too but i have sent a tool that can do more thing , similar like Autorecon but with more feature

#

But Autorecon is my tool to go.

azure widget
#

what features does it offer that tibs tool doesnt?

tepid patio
#

Just a headsup, it is 100% possible to fake a commit at any time. You can literally make a commit for the date marked january 1st 2019 if you wanted, so this statement doesn't actually hold much value 😄

visual wharf
#

Just check it out , its really cool tool , it has sowmthing like auto evil-winrm etc and also impact tool is run in auto mode ones the port is there , seclist and many thing is done one by one based on the port and nmap result

arctic mist
#

auto evil-winrm..?

tepid patio
#

to be fair, in about a months time rustscan will also have an autoreceon clone kekw (or, depending on the licenseing, autoreceon itself would be pretty awesome)

craggy onyx
#

Import-Module MakeMeEnterpriseAdmin.ps1 /autobots

crimson thunder
#

It would be awesome if someone could curate a list about these less known but just as good (or better) tools

#

I'd do it but I don't know enough

shut ferry
#

Hi All

#

Im looking for any resources (im greedy that way lol)

crimson thunder
#

@shut ferry you've come to the right place, just scroll up

shut ferry
#

so let's say for instance i wanted to simulate setting up a network similar to what is used in a call center or hospital. are there any good tutorials for this? i've found one on youtube that goes through setting up a windows server 2019 active directory domain controller. is that what i am looking for? and if so, is there an equivalent for linux?

azure widget
#

Hospitals are so vulnerable it can’t even be simulated it’s mad

shut ferry
#

lol, i'm really just trying to learn how a system administrator would go about setting up a network and then securing it

gritty barn
#

call centres are quite easy @shut ferry

#

it's mostly a windows DC with a lot of devices, nowadays a lot of organisations use Twilio as a service provider for call routing, sometimes you may see implemented some QoS too

shut ferry
#

windows DC?

gritty barn
#

yeah

shut ferry
#

oh domain controller, like what i mentioned originally?

gritty barn
#

what i've set up at my previous place is that + a very stripped down version of widnows

#

yes

#

so it's not a lot going on, can't speak about hospitals as i haven't worked for one yet

shut ferry
#

okay, that's what i'll work on doing then. i'm going to set it up in virtual box, and see how it goes. eventually i would like to attack it to see how secure it is

gritty barn
#

but call centre i can tell you ^^ as i worked through upgrading from SIP phones to VoIP and stuff

shut ferry
#

i'm not necessarily interested in the applications on the computers, more so just setting up the environment, roles, and such

gritty barn
#

you already have a few DC labs on THM so you don't really need to set it up yourself to be fiar

shut ferry
#

oh okay, i did not know that, thank you

gritty barn
#

search for Windows in the searchbar, most of them are DCs 🙂 then you also have throwback to mimic real life examples

shut ferry
#

i've done some of those machines, and sort of know what i'm doing from an attacking standpoint, but i'm wanting to learn from a blue team side of things

gritty barn
#

i have a room, hopefully coming up soon which focus on blue ^^, should be in the next few releases

#

it covers smb 1,2,3 ; msrpc and a few other bits and pieces

shut ferry
#

sounds great, i'll keep a look out for it. i've found the active directory basics room, and that was one of the things i was looking for as well. thank you.

gritty barn
#

no worries, good luck though

shut ferry
#

will do thanks

west lark
#

👆🏾 this is a really informative presentation on how to leverage local privileges to SYSTEM privileges with whoami /priv

glad hazel
#

Which one is good nmap or rustscan?

azure widget
#

rustscan uses nmap lmao

glad hazel
#

okay so I better be using nmap then?

wary lily
#

rustscan is kind of like an add-on for nmap

#

makes scanning significantly faster

glad hazel
#

okay

#

thank you guys

#

I never used it so will stick to nmap for now

azure widget
#

I mean the good thing about using rustscan is the creator is one of the mods here and you just bug them to fix things or add features

#

I also like supporting smaller developers so that too

neon dagger
#

Guys, any tool recommendation for bluetooth sniffing?

tepid patio
#

rustscan has a scripting engine as of 4 days ago which supports any language, including Python -- so if you want to write scripts in python there's that 😜✨

gritty barn
#

Microsoft, in collaboration with MITRE, IBM, NVIDIA, and Bosch, has released — Adversarial ML Threat Matrix Framework — to help security analysts detect, respond to, and remediate adversarial attacks against machine learning (ML) systems.

Details: https://thehackernews.com/2020/10/adversarial-ml-threat-matrix.html

The Hacker News

Microsoft and MITRE Release 'Adversarial ML Threat Matrix' Framework to Protect Machine Learning Systems from Adversarial Attacks.

tepid patio
#

yes

#

if anyone wants to 1v1 me on codewars or do a mock interview DM me

crimson thunder
#

@tepid patio can you elaborate pls? in a pm if this is getting out of scope for this channel

tepid patio
crimson thunder
#

ohh nice one

modest hedge
#

@tepid patio do infosec jobs emphasis on coding rounds?

tepid patio
#

i don't work in infosec, I work in AI so I wouldn't know 😛

modest hedge
#

Ahh I thought since you posted that guide, you might be an infosec professional

#

How do you combine AI and infosec?

sturdy shell
#

There's a whole heap of uses for AI in Infosec

#

A big one is anomaly detection for stuff like IDS & IPS'

modest hedge
#

Considering an algorithm is used to detect, wouldn't it be plausible to evade it?

#

Also just realized this might the wrong channel for this discussion 😅

tepid patio
#

Considering an algorithm is used to detect, wouldn't it be plausible to evade it?
@modest hedge To bypass it, you'd have to understand the algorithm 😛

#

No one on this planet ever understands exactly how a neural network with 5 billion neurons functions

craggy onyx
#

The power of machine learning models, is to adapt to changing vector landscapes and update detection rules in real-time. Some examples of usage of Machine Learning in security are: Phishing domain detection, Malware detection, Botnet detection, Anomaly detection, IDS evasion detection, Threat Hunting APT detection, etc.. @modest hedge

modest hedge
#

No one on this planet ever understands exactly how a neural network with 5 billion neurons functions
@tepid patio Didn't think of it like that 😅.

balmy merlin
glad hazel
#

rustscan has a scripting engine as of 4 days ago which supports any language, including Python -- so if you want to write scripts in python there's that 😜✨
@tepid patio okay will try rust then

azure widget
#

this is a really good talk / hangout with Dave Kennedy talks about C2, AV evasion, PE and other advanced topics

thick bridge
#

Hi mates,
how do you do daily/weekly information monitoring on hacking subject ?
do you use RSS ? do you have any tips or software to share in order to begin a correct ethical hacking information monitoring ?

tepid patio
#

i have an rss feed but tbh i just pay attention to twitter / this channel

crimson thunder
#

there are tons of sites

#

also definitely check r/netsec if you're on reddit

thick bridge
#

thanks ! Seems i really need to check for a RSS reader and set something to begin with.

crimson thunder
#

the daily swig has a rss btw

tepid patio
#

I use this 😄

thick bridge
#

feedly looks awesome ! gonna give it a try thank you

crimson thunder
#

oh that seems better 😄

craggy onyx
#

Feedly has a cyber security section as well, from which to select favorite feeds. It's great. 👍

crimson thunder
#

Dark mode in OWASP ZAP:
get the weekly release here: https://www.zaproxy.org/download/#weekly
Tools > Options > Display > Look & Feel: Choose either Flat dark or Flat darcula

crimson thunder
prisma bison
#

Ooooo that’s super cool

tepid patio
night ether
#

@worthy blaze offensive path on tryhackme is a good start, if you subscribed which is only like 10/m i think

#

did i dream that message i swear it was just there

shut ferry
#

It was posted in general @night ether, maybe you got confused

worthy blaze
#

@night ether Thank dude

magic perch
azure widget
maiden smelt
#

hi guys! Can you send me some good resources for learning reverse engineering?

shrewd ginkgo
shut ferry
#

Anyone recommend a linux box or writeup similiar to eCPPT DMZ machine. Bufferoverflow done, down to the last box, rooted all except for this machine.

crimson thunder
crimson blaze
#

Awesome blind SQLi scanning/testing tool:

#

Bunch more random cool SQLi scanning tools listed here too:

edgy plank
reef epoch
crimson thunder
#

what are your go-to resources and/or tools for iot pentesting?

craggy onyx
#

The IoT Hacker's Handbook: A Practical Guide to Hacking the Internet of Things, by Aditya Gupta.

crimson thunder
#

@craggy onyx thanks! could I ping you for an additional question?

craggy onyx
#

Go ahead.

solar socket
#

improving all the time

shut ferry
#

Is there anyone here studying for COMPTIA Sec+?

tepid patio
#

when people reply

#

When I reply

crimson thunder
#

I thought you were going for a meme format there

#

got confused for a second

azure widget
#

I’ll reply when I get a second

glad hazel
#

Is there anyone here studying for COMPTIA Sec+?
@shut ferry I'm

fast wraith
azure widget
#

That sounds very scary

#

Ah 50 lab containers, that’s different

fast wraith
#

Im going through it right now and they are all super high quality, I'm really impressed tbh. Each lab comes with a pdf that explains what to do. The docker framework also has an api that starts each lab by module name from the command line, and then automatically launches everything necessary for the lab. I would compare them to Hera Labs.

crimson thunder
#

Thanks for the feedback. The file is big but I'll have to download it now 😄

azure widget
civic halo
#

@azure widget Just approved that, for some reason it was flagged

azure widget
#

reee

civic halo
#

Reee because I approved it or that it was flagged?

azure widget
#

flagged

civic halo
#

Yeee

rapid vortex
#

Sites For CheatSheets

queen wyvern
#

Cheatsheet on what

shrewd ginkgo
rapid vortex
#

Cheatsheet on what
@queen wyvern like nmap ,priv esc.... etc

topaz gulch
rapid vortex
topaz gulch
#

Don't need a cheatsheet if you've already been taught what to do

#

And you should be taking your own notes

#

Which will become your "cheatsheets" if you need a reminder

rapid vortex
topaz gulch
#

There's no point in being handed everything on a platter -- you don't learn that way

rapid vortex
#

Thanks @topaz gulch

solar socket
tepid patio
#

We now support 50+ methods of decoding / cracking / decryption / decompressing / de-esolaning(?) partyHard https://github.com/Ciphey/Ciphey

GitHub

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡ - Ciphey/Ciphey

prisma bison
maiden smelt
#

oh opps

clever dove
#

Watching it rn

#

Waiting

maiden smelt
#

in 71 mins hah

#

ye

woven sinew
#

hey!

glad hazel
#

We now support 50+ methods of decoding / cracking / decryption / decompressing / de-esolaning(?) :partyHard: https://github.com/Ciphey/Ciphey
@tepid patio Really Awsome. Love using it

waxen lodge
#

https://www.youtube.com/channel/UCsKK7UIiYqvK35aWrCCgUUA i just found this channel that explains basic web exploits, and he is pretty good at it. But weirdly enough he doesnt have many views even though the quality of the video and the explanation is very high.

spare flicker
#
bluescreenofjeff.com - a blog about penetration testing and red teaming

It’s not fun to get caught on an assessment because your target has your toolset signatured. It’s even less fun if that signature is easily bypassed. Cobalt Strike’s Malleable C2 is a method of avoiding that problem when it comes to command and control (C2) traffic. Malleable ...

azure widget
#

https://www.bc-security.org/post/empire-malleable-c2-profiles/ - this is relevant as Empire is more accessible to users and has a lot of the same feature outlined in that blog post as well as in general

Empire 3.4.0 is our next major release and is packed with one of the most advanced features to-date, Malleable C2. The Malleable C2 Listener gives control to operators to customize their beacons to match specific threats. It does this through profiles, which are simple scripts...

plucky galleon
#

Are there any rooms that teaches exploit development

shrewd ginkgo
tepid patio
low goblet
#

Hello all! I am looking for some resource to learn python and c# for cybersecurity any suggestions (videos, books,...)

azure widget
tepid patio
#

thank you cry ❤️ I should really turn that into something useful :P