#resources
1 messages · Page 10 of 1
Currently taking the TCM OSINT course, really fantastic stuff. Actually has a very nice UI and video player. It's TCM material so it's very methodology-heavy training and easily worth 4-5x what he's charging
https://academy.tcm-sec.com/courses
it's top notch 😄
have you finished it?
not this specific course, I'm halfway through the peh course (taking a pause due to other responsibilities)
I was talking about his material in general
ah okay gotcha, yeah I finished his udemy course when it first came out - didn't do the AD stuff yet though
and I currently have his Windows Escalation course I haven't gotten around to yet
I know he has a certification in the works too I'm excited for
Thanks for that link James. Something I can do while at work and with nothing to do
If yall have any comprehensive resources on threat intelligence please lets me know
Needs to read all this before summer
I'm 40% through the PEH got a fair bit to do.
Does elearn have a monthly subscription to the cyber pass pr is that a myth?
I saw themayor11 ask them and i think they said yes but if anyone who knows can confirm this
they do, its $200/month
Ive heard you have to contact them to get the monthly plan
Oh really, okay thats good to hear! Thnks for the heads up @faint sluice @magic idol
That's awesome! I didn’t know that 😍
beginner Certified Information Systems Security Professional- CISSP 2020 beginner
recyclePrice: $150 Free
Coupon Code: JHJFJDFHLSKJDF
i hope i can put this
Is it a real one or the training?
idk i got this in another server
It's not real. It's training for the real CISSP
What is the best resource to get started with Reversing and actually with Vulnerability Research?
I wouldn't focus on 'the best resource' and just start, don't fall for that toolbox fallacy.
that being said, I hear good things about no starch press, and they have a book (or two) on reversing. You can find it here: https://nostarch.com/catalog/security
(You'll end up a better researching by starting today than you will waiting for that elusive 'best' resource 😉 )
@cobalt trout ```md
Resources
These are the resources I have found while learning about the binary exploitation.
Blogs:-
- https://syedfarazabrar.com/
- https://kileak.github.io
- https://d4mianwayne.github.io/
- https://ctf101.org/binary-exploitation/buffer-overflow/
- https://blog.skullsecurity.org/category/ctfs
Youtube:-
- https://www.youtube.com/channel/UCi-IXmtQLrJjg5Ji78DqvAg/videos
- https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN
Wargames:-
- http://pwnable.kr/
- http://pwnable.tw/
- http://pwn.eonew.cn
- https://www.root-me.org/?lang=en
- http://smashthestack.org/
- https://exploit.education/
Pwn Related Stuffs:-
- PwnTips - https://github.com/Naetw/CTF-pwn-tips
- Quick guide -https://trailofbits.github.io/ctf/exploits/binary1.html
- Pwn Challenge List - https://pastebin.com/uyifxgPu
Stuff Robin gave me:-
-
Course materials for Modern Binary Exploitation by RPISEC - https://github.com/RPISEC/MBE
-
Learn ROP - https://ropemporium.com/
-
For Linux binary Exploitation - https://github.com/scwuaptx/HITCON-Training
-
Intro to binary exploitation / reverse engineering course - https://guyinatuxedo.github.io/
-
A collection of pwn/CTF related utilities for Ghidra - https://github.com/0xb0bb/pwndra
-
Some pwn challenges selected for training and education. - https://github.com/BrieflyX/ctf-pwns
-
A set of Linux binary exploitation tasks for beginners on various architectures - https://github.com/xairy/easy-linux-pwn
-
ASM Basics - https://asmtutor.com/#lesson1
The following is a list of OSCP approved tools that were posted in the PWK/OSCP Prep Discord Server ( https://discord.gg/eG6Nt4x )
Recently made an interactive cheat sheet website for Windows/AD hacking, think it could be really useful for people: https://wadcoms.github.io/
@topaz gulch Just read your OSCP blog post and wow that was amazing! Congratulations on passing! I am trying to also get the OSCP but currently feel like I do not know as much information to sign up. I have been doing a lot of tryhackme to prepare and get some more experience, but your post gave amazing advice also.
Glad it was useful 🙂
Almost metallica
Oof udemy
I updated this! https://blog.tryhackme.com/free_path/
A free guided path for beginners on TryHackMe.com
Possibly one of the worst udemy ethical hacking courses I've seen (In my opinion, the instructor doesn't explain things clearly, the video quality isn't good, he just skips over the most important things and much more)
LOL Why?
Anyone have a good article explaining port forwarding pls?
Do you understand NAT?
Once you understand NAT and how it works, port forwarding becomes a lot easier to understand
Yes I do, learned that through elearns course
So, port forwarding is just mapping a port on the public side to an IP+port on the private side. Any traffic to that port on the public IP gets sent to whatever IP+port you set it to be sent to.
Wow thats legit explaining NAT devices, thnks for the simple explanation!
ok idk i wont send anything now
everyone scolds me 😦
@spark hedge When you get the chance, could you DM me real quick? I'd love to get your opinion and thoughts on some write up stuff :)
Nah it's not your fault, you got a free course which is good but honestly it's not really a good one
Can someone recommend the Practical Ethical Hacking Course of TCM-Sec?
yes, it is really good
note you will want a HTB paid account to fully take advantage of the course
nice thank you
I've just accepted an offer for a junior incident response role, but I'm still pretty green to this side of cybersecurity. Can anyone recommend any good resources / certs to start working through?
Ideally something cheaper or my wife will murder me
Exactly what I was looking for, thanks! 
TCM teaches htb boxes in that course?
He uses HTB retired boxes to show techniques. You could just watch and follow but what I do is try the box first by myself then watch the video
For the free resources / training)
Think he'd be open to having us dev some free ones for him?
too slow
Heath? thats who the HTB reference was 🙂 he's already your boy
Yeah, fair enough 😄
True one doesn't learn by just watching
Some people do and I don't think you should ignore that
oh no, I posted it on purpose because she has paid and free resources 
Xbox Game Pass ultimate is £1 for 3 months right now, includes 3 months of Discord Nitro (if you've never had nitro before)
https://www.xbox.com/en-GB/xbox-game-pass
it's working
"Never had nitro before" also includes the snowsgiving nitro a loooong time ago fyi
What's a good resource to learn docker and kubernetes?
setup and use
Google has some good docs on Kubernetes
Humble Bundle has a huge collection of No Starch Press infosec books right now for very cheap 😄 https://www.humblebundle.com/books/hacking-101-no-starch-press-books
I had like half of these in my wishlist already, so I figured I'd share it here as well
Compose your own @cloud brook opera, rather cool exploration into composition of music and the harmony of pitches https://artsandculture.google.com/experiment/blob-opera/AAHWrq360NcGbw?cp=eyJyIjoiS3pYczhiN055UV9HIn0
Infosec resources Bee smh
Infosec resources!
I’m honored that they made AI in my name @tepid patio
I though blob was doing opera now
I am
Not specified
I am specifying now
Boooo
Any thoughts on rangeforce?
I did a few hands-on blue team type exercise in a complete virtual environment right in the browser.
$5 books and videos on Packt. any recommended books here?
packt.live/2q0AbGZ
Packt is greatly hit or miss, more miss than hit. timtaylor did mention this book (I believe) as being good when I asked about something other than Portswigger academy https://www.packtpub.com/product/burp-suite-cookbook/9781789531732
how did you find it? can't tell you how many emails i've had from them
Saw someone mentioned them on linkedin. Looked them up, signed up and thats it
Very cool practical training. Right from the browser
They are definitely not spamming my inbox. Maybe you are special :)
Wait TIL you can replace backend with server-less functions, effectively you can have a webapp without having a server which is a big plus for security (provided you trust the provider though)
I don't know if anyone has sent a list but what are the best books for OS Hacking?
I mean like that book "Android Security Internals".
Do you recommend another like this?
This list looks amazing, thanks
No worries, it's a pretty knew company which is cool
Yay thanks for sharing @sonic abyss ! Someone just told me they saw a mention of it so wanted to drop by and offer my support / say hi
Browse The Most Popular 482 Hacking Open Source Projects
Bee you already knew this -- AWS lightsail (:
AWS lightsail is managed EC2 like DO
it has a backend 😛
unless you meant lightsail container services?
lightsail is amazing, it keeps everything nice and cheap
Hey y'all! Does anyone have cool resources or a blog post on a good Kali setup for THM? I have tried: WSL Kali on my main machine, Kali 2020.4 on an older laptop, and then the THM attackbox Kali. WSL Kali has issues with persmissions and I'm not loving win-kex or xrdp, "vanilla" Kali is cool and has all the 2020.4 features that WSL doesn't but it's on a slower machine, and the attackbox has significant delay for me. I'm fairly new to Linux and networking but have a programming background, so I'd like to stick to my main Win10 machine +WSL if possible.
Just make a Kali VM. WSL is not a good solution due to how it works.
Mostly the networking setup
Cool, thank you. I have very little understanding of why networking would be better on one over another so I appreciate that.
does anyone know of a good room to experiment with ROP?
#infosec-general but VMWARE VM imo
Wsl2 is basically a VM, but it's still hyperv which precludes using userspace hypervisors
Though it might get more interesting once Microsoft natively supports Wayland
That’s not why James suggests against WSL2
as he said here it’s because of the jank networking
Seems to work ok enough for me but it's a bit janky on some machines I guess
It uses a hyperv virtual switch
I have also had really terrible experiences with the TCP/IP stack in WSL.
anyone have some good resources for network forensics? 👀
This site has some great challenges - https://cyberdefenders.org/
thanks! 
CyberDefenders is pretty good
Install a mail-server on your Pi! I use this to forward various logs like my DD-WRT and PiHole logs to a local e-mail specifically meant for my home network administration. (it also has chat rooms!) https://www.citadel.org/easyinstall.html
SANS Penetration Testing blog pertaining to Getting the Most Out of Shodan Searches
are they paid ??
does this site requires subscriptions
seems like something you could find out easily for yourself
yes/no would have been fine.
Hacking is 90% research
Noted. 
Finally got my password management off the cloud and now using KeePassXC, Lastpass makes it really easy if you export to CSV. https://keepassxc.org/
Droogy, if you are into self managed options check out bitwarden. You can do cloud, private cloud, and local only
Nvm, they changed the app version - used to have an option for a local db.
big fan of lastpass
I do like lastpass too, and for 99% of people it's totally acceptable but in the long term I want my data stored locally
I like lastpass because I can use it on my phone and computer
my android phone is so old autofill works maybe 5% of the time so it doesn't even matter to me lol
ideally I would like to just have a yubi-key/physical (non-biometric) solution for everything on my phone
What do people think of 1password in comparison to lastpass?
I use it 🤷♂️
I use Last Pass for personal and at work we use Keeper, they both are kinda similar, I just like the layout of Last Pass better
I've had problems setting up the most recent Kali as a virtual machine in vmware. Anyone have any luck with this?
Wrong channel. Ask in #infosec-general with some more details about error and possibly a screenshot.
dashlane is also a good option imo
I haven't done this workshop yet, but it looks kinda cool
Thanks, that does look interesting
ooh
Sm9l - I wouldn't have thought so. There very few (if any) ethical reasons for that sort of attack which is why we don't really talk about them here.
i mean, stress testing is a type of testing as well @calm ermine @prisma bison , as long as it is agreed in the scope of engagement.
My point still stands haha
it is still a vulnerability. Certain CiscoOS versions are susceptible to a DoS vulnerability that can crash it or make it exclude the ACLs for following packets
i can provide you with loads of them if you are interested, i am just saying that DDoS is bad, but DoS seems like a quite unimportant topic, nonetheless you want to avoid them in client engagements
Mhm of course
Free release of the training materials from a course on Source Code Auditing at Hack In The Box in 2018 - https://blog.recurity-labs.com/2020-12-23/code-audit-training-archive.html
Udemy 
Nathan House has good resources on his StationX site as well
I've seen those classes saw the logo and clicked off ... just its a bit much
Expired :(
Free Linux course: http://bit.ly/34G73WP
Free Ansible course: http://bit.ly/37KyoJu
ONLY 2 HRS LEFT
@sonic abyss
pinged u be4 its expired
Gelocating tool for Santa :P 🎅
Amazing resource
Thanks for the Udemy links. Was able to nab a bunch of courses for free. Just need to find the time in between work and uni
https://www.udemy.com/course/cisco-ccent-icnd1-100-105-complete-course-sims-and-gns3/?couponCode=NCCHRISTMAS Literally free prep course for CCNA!
The course of Nathan from Udemy. What do you mean "its a bit much"? Just out of curiosity
the logo
gotcha
All of Udemy is meh for cybersec except for TCM and Tibs
yeah TCM is solid, there is a lot of good AWS stuff there,
Udemy does have a money back guarantee, I've totally bought a course and realized it wasn't for me
I dislike the discount by 90% all the time system of Udemy and I dislike that because courses are community made some of them are just horrible
Those who put udemy courses with 100% off are amazing people
@shut ferry
Overpass
This is a cool blog post https://www.reddit.com/r/tryhackme/comments/kl8h13/upgrade_your_common_hacking_tools/
Is there an accessible mode for feroxbuster?
no but i think I can convince Tib to make autorecon accessible
i did bug John the other day too with one of his CTFs lol
The first thing I noticed was the banners
is there a way to host mp3 files
somewhere
ok nice
Lex Fridman is an AI researcher, but he also has a podcast where he interviews some really big names. Unlike other podcasters, Lex actually studies the topics of the people he interviews so you end up with some really interesting discussions. Some of the big names hes interviewed:
- Elon Musk
- Dan Carlin
- Joe Rogan
- Jack Dorsey (I loved this one, Jack calls himself a hacker instead of a CEO which is cool)
- Vitalik Buterin
- George Hotz (GeoHotz)
I highly recommend this podcast. Also, all of Lex's MIT lectures on DeepLearning are fantastic.
https://www.youtube.com/c/lexfridman/videos?view=0&sort=p&flow=grid
nice
https://fieldraccoon.github.io/posts/How-to-make-Boot2Root-machines/ for people who want to make their own machine but arent sure where to start
Setup The idea of me making this machine was to learn how it works, the setup process. Making something vulnerable and eventually how to submit and export my image to the platforms. This box consists of: Nmap the box to find that port 21 is open connecting via FTP using get to grab a file that contains credentials Using those credentials to logi...
anyone got more resources for pwn stuff?
oh thank you I haven't check the pins sorry
I will suggest one myself no clue if anyone has linked this before: https://pwn.college/
you chad
docker cleanup guide: containers, images, volumes, networks - docker-cleanup-resources.md
Anyone with a good RSS feed willing to share their OPML? Or any good blogs (with RSS) in general
its a lot of sources tho
feedly doesnt actually tell me because its too many
it just says "1k+"
thank you so much! I debated using feedly but I have a lot of privacy concerns with them, it was actually super annoying finding a good, open-source RSS reader for Windows
I would recommend launch scprits by category, example if you use "--script=auth" will try to auth with default credentials,
AutoRecon is nice, but that output woould be really helpfull, i have to write the sentence for nmap
Came across this cyberchef like site yesterday - Universal Encoding Tool - UnEnc
https://www.unenc.com/
The Universal Encoding Tool provides a huge collection of methods for en-/decoding, en-/decryption, conversions and hashing
Just released Stegseek v0.5 (The Official StegCracker Killer ™️ )
https://github.com/RickdeJager/stegseek
Changes:
* No longer eats all of your ram
* Scales better with cores. (Can try all of rockyou in under 1 second if you give it ~16 threads)
* Can take stupidly large wordlists as input. (15GB worked fine)
* Some bugfixes and whatnot
* 12 000 -ish times faster than StegCracker
Last coupon of 2020 - HALFOFFNEWYEARS
Takes 50% off anything. PEH, OSINT, PrivEsc, Hacker Bundles, and All-Access.
By request, this works on both @TCMSecurity Academy and Udemy.
https://t.co/c9y1tFtyuk
https://t.co/CADCSe1ITx
Expires Jan 1st. kthxbye ❤️
also this if you haven't seen it https://twitter.com/TibSec/status/1342514769916551175
If you didn't win, you can grab my courses for $9.99 each for the next 5 days using coupon code XMAS2020:
Merry Christmas! #InfoSec #OSCP
That’s seems like a lot of work since macros are still a thing
^ same, but I posted it anyway 🤷♂️ 😄
but it might help in evading av I guess? but the Shell in the macro should get flagged by av anyway
Finding an open-source RSS reader for Windows that doesn't look like total crap, has the features I need, and supports dark mode was actually more annoying than it should've been. Found this one which is rather good.
https://github.com/yang991178/fluent-reader/releases
😦
👀
i got a smartscreen warning on install that I just clicked thru lol
looks like that triggered in Edge?
It’s looks like it forces you to write them onto disk on an SMB share which is odd
somewhat decent article about the state of security architecture and best practices written way back in 2005.
Also has this really fun line
My prediction is that the "Hacking is Cool" dumb idea will be a dead idea in the next 10 years.
HAH
But we’re all still here buddy! Go do your blue team stuff and stop trying to discourage the red!
Does anyone know of any good resources for learning how to use Autopsy?
The free autopsy course if that is still free
Damn, it looks like I really missed out on that one
Yo guys, me and @digital swan created a small tool to help out on simple stack based overflows: https://github.com/ChevalierOnGithub/Overflowy , feedback is welcomed
DST Ports
Dest Port,Count 1,Count 2,Level,False Positive Condition,Positive Condition,Comment / Source,Sandbox Analyses Link,Speedguide Link
3369,-,1,high,Netwire,http://www.speedguide.net/port.php?port=3369
8765,-,1,high,Jsocket Sample,...
Hi everyone I just made a python tool used to automate the execution of the following tools : Nmap , Nikto and Dirsearch but also to automate the report generation during a Web Penetration Testing
https://github.com/Anteste/WebMap
This project is free and Open Source so use it as you want
@shadow blade bearing in mind that nmap doesn't work properly for more advanced scan types if not run as root, are you running that script with the SUID bit?
@topaz gulch No am just using os.sytem("nmap -T4 -A " . ip)
Oh, I can see that
Hence asking -- because if that script is given any kind of extra privileges then it turns into the easiest privesc I've seen in a long time
he means nmap uses root priv for some comands
so u goota add sudo
and tell user to run it as root
Which is a shame, because it needs SUID/sudo if you want nmap to use a SYN scan rather than a TCP scan
i will keep in mind while making my own peoject
Problem with that is said walking talking vulnerability
thanks for telling
this will help
But we don't sudo if we just want to use an agressive scan.
It's all in my nmap room 🤷♂️
@topaz gulch you're room is awesome
wait i didnt do that room till now why
ok lets continue this in #general
or muirs gonna warn us
Aggressive is just shorthand for -O -sV -s C + traceroute @shadow blade
It's still built on one of the other scan types
all in 1
muir for rustscan how do we say which port specify?
For example I have to run the script as root then run the nmap scan also as root.
But the script will be vulnerable to a SUID privesc
No clue -- I've only used it a few times I'm afraid. It'll be in the docs for it
oh np
I can just run the nmap scan as root and when the user will start it will ask for his passwd and it will not be vulnerable
Yes. It needs root privileges, but if you give it SUID then it's vulnerable to an SUID privesc (assuming you take advantage of the SUID). You would be better adding it to sudoers but keeping a password.
Mhm. That's a better option
thats a better option
But how can I add it to the sudoers ?
Thx guys I will add it
Honestly your idea of adding sudo into the os.system is probably the way forward, but ideally you want to use something like subprocess rather than system
If you’re using a VM just suid it , my vm has at least 4 ways to root 
give me your ip
Okay, won’t do much don’t have any ports forwarded or open 🤷♂️
And actually having a unintended privesc In your vm can save you a lot of time when manjaro removes your user from sudoers after a few failed login attempts 
You can login as root like I do
I didn’t have a root pw set at the time
someone was asking about setting up AD labs in general the other day, there's some interesting stuff in the replies to this tweet: https://twitter.com/netsecfocus/status/1344197765165887493
Question on our Mattermost: anyone have any nice guides to setting up an build up/tear down AD environment to practice pentesting on your own lab?
@UK_Daniel_Card this sounds right up your straat.
New OSINT OS from TMHC https://twitter.com/v3nari
Depends on the machine. This is not the correct channel. Try #site-support or #room-help @ivory flint
https://www.udemy.com/course/wireshark-packet-analysis-and-ethical-hacking-core-skills/?couponCode=GOODBYE
^ this is free for year end sale I guess.
XSS Payloads
You can also fuzz it
Can I post Udemy courses here?
is it self promotion
and is it free (mostly)
then yes
generally
i mean
the rules are in the uh
that box
next to the channelk name
Please avoid self-promotion of paid content here.
Learn ethical hacking, Python, web development and more with these 9 FREE courses! Happy New Years!
https://www.udemy.com/course/ethical-hacking-kali-linux/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/ethical-hacking-python/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/python-complete/?couponCode=EE03C893BA5B7A8127D1
https://www.udemy.com/course/front-end-web-development/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/full-stack-javascript/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/linux-system-admin/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/python3-for-beginners/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/google-chrome-extension/?couponCode=HAPPYNEWYEAR
https://www.udemy.com/course/ethical-hacking-professional/?couponCode=HAPPYNEWYEAR
#udemy #couponcode
credit: ロックン | ばかユジン
Learn ethical hacking, penetration testing and network security skills with our comprehensive course!
Learn ethical hacking, penetration testing and network security while working on Python coding projects!
Learn Python with projects covering game & web development, web scraping, MongoDB, Django, PyQt, and data visualization!
No
I know the rules...
?
U guys don't trust others
man thank you very much for the free courses
Welcome
but is there a way to search for more free udemy courses? because i'm also interested in other things
Hotukdeals
there is a reddit of udemy deals, forget whats its called but you can google
@paper bolt These were posted above by another user 🙂
I can’t see lol ive f my discord up
oof
I'm deleting it because they are right there and it's a wall of embeds
You can try the same coupon code..they r valid till 5th Jan..may be the same coupon code would work for other courses u like
i've tryed but it seems that the coupon is working only with that courses because they have been all published by the same person
Ohh...
@white pivot mind helping my pal out @remote wind with some resources? he is trying to follow your steps 😄
Lol i already contacted him @gritty barn
😂
He once teached me about stack pivioting
Hey! I am planning to take the Modern Binary Exploitation course by RPISEC soon but need some computer organization knowledge first. Are there any courses or resources you could recommend? The topics mentioned on their github are:
MIPS assembly, x86 assembly, Datapaths, CPU Pipelining, CPU Caching, Memory Mapping
# Resources
These are the resources I have found while learning about the binary exploitation.
### Blogs:-
* <https://syedfarazabrar.com/>
* <https://kileak.github.io>
* <https://d4mianwayne.github.io/>
* <https://ctf101.org/binary-exploitation/buffer-overflow/>
* <https://blog.skullsecurity.org/category/ctfs>
### Youtube:-
* <https://www.youtube.com/channel/UCi-IXmtQLrJjg5Ji78DqvAg/videos>
* <https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN>
### Wargames:-
* <http://pwnable.kr/>
* <http://pwnable.tw/>
* <http://pwn.eonew.cn>
* <https://www.root-me.org/?lang=en>
* <http://smashthestack.org/>
* <https://exploit.education/>
### Pwn Related Stuffs:-
* PwnTips - <https://github.com/Naetw/CTF-pwn-tips>
* Quick guide -<https://trailofbits.github.io/ctf/exploits/binary1.html>
* Pwn Challenge List - <https://pastebin.com/uyifxgPu>
### Stuff Robin gave me:-
* Course materials for Modern Binary Exploitation by RPISEC - <https://github.com/RPISEC/MBE>
* Learn ROP - <https://ropemporium.com/>
* For Linux binary Exploitation - <https://github.com/scwuaptx/HITCON-Training>
* Intro to binary exploitation / reverse engineering course - <https://guyinatuxedo.github.io/>
* A collection of pwn/CTF related utilities for Ghidra - <https://github.com/0xb0bb/pwndra>
* Some pwn challenges selected for training and education. - <https://github.com/BrieflyX/ctf-pwns>
* A set of Linux binary exploitation tasks for beginners on various architectures - <https://github.com/xairy/easy-linux-pwn>
* ASM Basics - <https://asmtutor.com/#lesson1>
@remote wind
Can i dm u?
Sure
A ctf on binary exploitation and assembly http://io.netgarage.org/
That looks pretty good! Come at the right time for me, wanna get back I to that! Thank you for the link L-Drago
SANS Digital Forensics and Incident Response Blog blog pertaining to Device Profiling With Windows Prefetch
@topaz gulch can I share super nerdy maths videos here that I think people will like? I.E: https://www.youtube.com/watch?v=k7q0Y2W0Rn4
This is an excerpt from Just For Graphs. Get it on DVD and download here:
https://shop.festivalofthespokennerd.com/
I analysed the data from my wife's contractions prior to the birth of our daughter and tried to guess when she would be born.
The android app I used is called Contractions Timer:
Home lab suggestions for newb? Ive got a few lightweights machines..And Im sure there are several "best" routes..Got a quad core 16gb windows desktop, a quad core 16gb windows laptop, and older windows laptop ,1 core x 2-4 gb ram. ( install linux?) Would appreciate some professional opinions if someone has the time. TIA Looking to do network analysis, nmap, pentesting, wireshark, metasploit, CTF Tools.... I really don't know yet.
Ctfs
https://overthewire.org/wargames/bandit/ (basic linux)
https://overthewire.org/wargames/natas/ (web based)
https://w3challs.com/ (category wise web,crypto etc)
Hacking Challenges: binary pwnables, web hacking, reverse engineering, crypto & forensics. No simulation. No Guessing.
Windows version of OverTheWire
https://www.underthewire.tech/index.htm
Hi @cobalt oriole,
We only accept content that is English in this server (Please refer to rule 8), and try avoiding self-promoting.
Excessive advertisement is also against our rules (rule 3) :)
@prisma bison Ok
Thanks!
Translations: ελληνικά / عربى / 中文 (Weixin video, Youtube video) / 粵文 / bahasa Indonesia / Català / Deutsch / Español / 2فارسی / فارسی / Français / עִברִית / עִברִית2 / Hrvatski / Italiano / Nederlands / 日本語 / 日本語 2 / नेपाली / Polskie / русский / Português / Română / Slovensky / Türk / український / Markdown for translating
Welcome! In this post...
Not infosec, but VERY cool
also
In 2016, we introduced AlphaGo, the first artificial intelligence (AI) program to defeat humans at the ancient game of Go. Two years later, its successor - AlphaZero - learned from scratch to master Go, chess and shogi. Now, in a paper in the journal Nature, we describe MuZero, a significant step forward in the pursuit of general-purpose algorit...
DeepMind's AI has mastered Go, Chess, Shogi & Atari games without any rules or human input or domain knowledge
Really impressive !
We don’t mess with mimikatz anymore all my homies use SharpHandler
Is this an accepted writeup?
Please only share accepted writeups
okay
Thanks C:
Great SANS video on Threat Hunting/Detection, apparently SANS youtube is infosec's best kept secret as theres only a few thousand views on each video and they are all super high-quality https://www.youtube.com/watch?v=LVSwYyDN2Sk&list=PLtgaAEEmVe6DYtY3XggF8Z4AYJAIY97Rp
SIEM Summit 2019 Agenda: http://www.sans.org/u/UIC
Presenter:
Eric Conrad, Fellow, SANS Institute
Defensible networks are designed to prevent and detect computer attacks, and are hardened at every layer. Per Richard Bejtlich, defensible networks “can be watched” and “limit an intruder’s freedom to maneuver.” For example: modern malware often a...
The purpose of this text is to provide a reference for University level assembly language and systems programming courses. Specifically, this text addresses the x86-64 instruction set for the popular x86-64 class of processors using the Ubuntu 64-bit Operating System (OS). While the provided code and various examples should work under any Linux-...
Eric Conrad is top top.
oh for sure, you can tell the guy is a Windows guru. love the fact that he almost exclusively recommends mitigations and techniques that are software-agnostic, lots of easy wins you can take away from that talk for blue-teamers. definitely starting to see why SANS is worth it!
i think SANS is the best
@fast wraith sans yt algorithm ceases to exist on a platform like yt. Aint gonna see sans as a recommended video pop up. Sucks doe
But than u got Harvard lectures that just pop up randomly on my recommended like
Harvard 🤢
thanks for this great resource I finish it all and it gives me a different vision on this topics.
hello
hi
Cool open-source packet analysis tool. chain this with an SSL/TLS decrypt key for ez traffic analysis
https://github.com/nesfit/NetfoxDetective
At 7k a course the should be the best! out of my price range though 😦
Sans does a lot more for the community than just their courses
you can get a lot out of SANS for free
Kringlecon!
Burp Customizer -- Because just a dark theme wasn't enough!
-Burp Suite 2020.12 replaced the old look and feel classes with FlatLaf, an open-source look and feel class that also supports 3rd party themes developed for the IntelliJ Platform.
-This extension allows you to use these themes in Burp Suite and includes a number of #bundled themes to try.
Does it has black background with green texts on it ? Or blue/neon texts ?! 👀
I don't really know, I haven't tried it yet but at least black background is better than the white only.
Haven't you tried Burp Suite's Dark theme yet ?! I'm afraid
Burp new UI is more than amazing
from a ZAP fan 😄
PIA have a pretty good VPN sale, $80 for 3 years and they are no-log
https://www.privateinternetaccess.com/pages/buy-vpn/
Get award-winning no-logs VPN service from Private Internet Access risk-free for 30 days. VPN for Windows, Mac, Linux, Android, iOS, & more.
Hello everyone can have an idea about RedTeam Manual Book new version?
Please use the #bookclub to ask about books.
I'm sure blogging veterans knew about this already, but just found out about Twitter Cards and how to set them up for your blog - which basically are just link previews but way more enticing to click
https://developer.twitter.com/en/docs/twitter-for-websites/cards/overview/abouts-cards
speaking of twitter tags, most sites also support opengraph which is more widespread and is an open standard 😄
https://ogp.me/
https://www.udemy.com/course/android-penetration-testing-using-diva/?couponCode=FREE3DAYS
^ this is also free. 1 day remains i think. Don't know about the course quality though.
Thanks!
np ❤️
hey guys if someone here knows how to do it
Im trying to use grep that starts in letters and ends with digits can someone help?
look at grep -e
life could be dream
anyone know where i can get new updated password dictionary thats hashed already? Newer than the one john uses? or does john hashed them automatically?
a password list
I'm not sure this will help you or not but here : https://wordlists.assetnote.io/
@glad hazel that was very helpful. thx bud
I picked the link, thanks :)
https://www.udemy.com/course/complete-webapplication-penetration-testing-practical-cwapt/?couponCode=SESSION9
https://www.udemy.com/course/linux-unix-shell-scripting-certification-training/?couponCode=LINUX_SHELL_UPLATZ
Free ones ^
Any reviews on the WAPT one??
i actually got this before. it's looked kinda beginner friendly to me. but didn't go through enough to give u concrete review. it's free so enroll first then check the reivews. lol
Lol i enrolled and then asked 
Adding those, now i have 27 courses on udemy that i have claimed but never tried going through one 😅
I also stack many videos on Udemy.... I should study.😤
where did u find the codes leg?
all free?
Same xD
with those i have 50 courSES
and i did go through any
59*
Bought one, got a couple from giveaway and all remaining were free.
David Brumley, CEO, ForAllSecure
Do you want to know how to build a top-ranked competitive hacking team? It's all about the system. In sports, we understand systems that coaches can use to build a system for identifying talent, recruiting them, training them up, and competing in big games. Learn our proven system for building an elite team of h...
very good talk
I only have 288 course by this way ....never completed any

I'm proud of you
I have 1500+ courses 👀
1644 to be precise xD
anyone explain how vulnhub works exactly?
they host ovas and you download them then run them
ovas?
Open Virtualization Format (OVF) is an open standard for packaging and distributing virtual appliances or, more generally, software to be run in virtual machines.
The standard describes an "open, secure, portable, efficient and extensible format for the packaging and distribution of software to be run in virtual machines". The OVF standard is no...
SELKS is a pretty cool Debian 10 based alternative to SO
https://www.stamus-networks.com/scirius-open-source
Stamus Networks believes in the innovative power and flexibility of Open Source software. Our primary contributions to Open Source is SELKS, a live and installable ISO implementing a ready to use Suricata IDS/IPS managed by Scirius Community Edition, a web interface dedicated to Suricata ruleset management and basic network threat hunting.
https://yofreesamples.com/courses/free-discounted-udemy-courses-list/
this gets updated every hour or so giving u all the free udemy courses. The site is awesome!
you... sniff you're a good person
Thank you so much.
Can't use mobile data 👀
lol isp blocking?
Does anyone recall a resource passing by here that interactively suggested ways to attack AD, depending on what you had (Eg: unauthenticated, authed but not privileged, ..) ?
some free resources in hacking please
Scroll up, this room is filled with them
ok
Best resource:
https://tryhackme.com
I didn't know this. pretty interesting, [interactive cheat sheet]. Thanks
Courses Sort By: Release date (newest first) Release date (oldest first) Price high Price low Overall Rating Popular (most viewed) Development Convert your WordPress Website into a react native app Free Boostrand Training Convert your WordPress Website into a react native app React Native is an excellent tool for building both android and ios ap...
How do you guys track site analytics for a personal blog? I'm thinking about just parsing apache access logs but don't want to exactly re-invent the wheel here. I would setup Google Analytics but I don't want my visitors to be tracked or make people change their privacy extensions.
are you self hosting somewhere? egress logs to ELK and Prometheus
ah I do have SO, seems like I could do something with grafana there
not just for threats!
I use Cloudflare server-side analytics
Simple Analytics, Fathom, Plausible, Matomo are all privacy friendly analytics
netlify analytics is good too
remember the days when websites had little counters...
oh geocities - at least we still have the wayback machine
Code GIMMEFREELABS
Let's you sign up with ya personal email 🙂
noted - thanks bee!
What is that used for Bee?
What is what used for?
Cloudflare Analytics?
For my blog, I run it behind Cloudflare CDN as it's static content (90% is cached so it's super fast) so I use CF Analytics for it too 😄
is it free with CF
Yes, with the tracking script
but I pay for CF and I get server-side analytics 😄
Also they're releasing a netlify competitor
I paid £29 / month for hosting and £15 / month for analytics before, now I only pay £14 / month for CF. The idea that I can do analytics + CDN + hosting all on CF is simply amazing! 😄
yeah luckily i probably have less than a couple visitors a week so i dont have to scale up my $5 droplet yet
A lot of views
My analytics are also free. Albeit not particularly verbose
That fiver gives me unlimited traffic
For a wordpress blog
ah, on a VPS?
Nah, managed hosting for my blog, given I can't be bothered setting up bruteforce/DOS protection and it's inbuilt that way (plus I set it up before I got into server management)
Ah, the managed hosting for Ghost is 29 / month ahhaha
Oof
was deffo worth it, but they weren't static
I just rent server space from Ionos. Comes with a tonne of perks
which meant CDN didn't work out so well
Had to install the stuff myself obviously, but it works 🤷♂️
Although most of my other stuff is on VPSs now
Ghost is going down a really weird route rn too
Like a Substack competitor
for some reason
Brute force time?
It's managed through the provider, so good luck
I did a droplet with a manually installed lamp stack to host wordpress which was a pain, 2nd time I migrated my site to the one-touch droplet configured for Wordpress which was super easy
I also added in a fail2ban, just to catch anyone being sneaky
also I used Simple Analytics (cause I cared about privacy, and the creator is a mutual friend) which was £14 / month (it was rather nice, but far more expensive than literally any other competitor lol)
i recently got a vpn and forgot I set the wp-admin to only accept my certain IP address and had fun troubleshooting that one
wait i can show u my expensive month of my blog
that was because i got a lot of email subs and my email provider decided to automatically scale me
and i brought Ahrefs (£99)
lmfao thats mad
yeah i literally had a heart attack
i exported my email list and i havent even touched it since LMAO
more stats for ya
I stopped caring much in 2020, my advertising platform started advertising crypto-scams which meant I couldn't justify the high pricetag (I removed them from my site) so I just stopped everything for the whole year, 2021 I'm tryna stay under £40 / month hopefully 😄
Bee is just super popular
😅 I'm actually not, I just love writing a lot and I guess people want to read what I write haha 😄
That hasn't translated to social media fame, thankfully though
or unfortunately depending on how you see things
Actually, if you're interested in writing I have an article on it -- although I primarily ran my blog out of pocket so if you wanna make tons of cash don't look at me hahaha (but do look at IndieHackers, those peeps are experts) PS: this article is a giant mess as I just copied / pasted from Notion, it's primarily for my own use so sorry it's horrifically bad to read! https://skerritt.blog/blogging/
I meant this - #resources message
uhhh
tryhackme competitor
but for
universities
i think they're making it open to anyone though?
idk tbh
i applied for a job and they gave me that code
and its in their blog post too
Oh good luck man
I'm happy with THM 😄
I love THM a lot too!!!
Very great
Easily my fave place on the internet
Your level on TryHackMe can be copied across as a role on the discord server. To do so, you will need to perform the following steps:

@ebon valve ❤️
anyone have a tool that helps to identify and crack hashes? I tried hashcat and it dosent work for me for some reason ;-;
JohnTheRipper
I'll try that, thanks
I just want something to mass process meta data and images for me
this does images 🤷
Similar to No More Google
https://nomorefacebook.xyz/?ref=producthunt
For identification use hashID : https://github.com/psypanda/hashID
(or outdated version hash-identifier : https://tools.kali.org/password-attacks/hash-identifier)
Based on the output find the # for your hash type in the hashcat manual and then use it with -m flag. (https://hashcat.net/wiki/doku.php?id=hashcat)
Or use JohnTheRipper and find the hash format here : http://pentestmonkey.net/cheat-sheet/john-the-ripper-hash-formats
Although bear in mind that they can only guess
my implementation of Hash-Identifier is actually better
maybe I should release it
it still guesses
but at least it doesn't guess it's a Wattpad Hash before it guesses SHA-1 LMAOO
always a bubble bee never a bumble bee
Fantastic, thanks!!
Thanks
cool service you can use to turn some old domains you have laying around into an e-mail forwarder
if someone ever asks for an e-mail its always fun to tell them its their name @yourdomain.com
https://forwardemail.net
I have my own tool which identifies it and then tries to crack it if your interested
im intrested, some tools cant identify NTLM
Its a WIP but here is the github
thanks
Oh nice, I'm working on the exact same thing https://github.com/bee-san/HashSearch
The Ciphey of HashCracking™️
on whatt?
HashSearch
oh
quite a lot
it actually runs
i just need to fix ur JTR func
and it'll be ready to ship 😄
i know it isn't
Stupid potfiles
ii might code my own hashcracker in rust or something that's accessible via an API
would be fun to explore GPU acceleration
they are fun
only way to do that is to code!
you should try some competitive programming
gets the mind flowing
I was thinking about looking at outdated tools
Then picking the best programming language and bringing them back
oh
the username search thing
they suck
im 99% sure ii know how to fix their biggest bug
just need to fix this function huh
btw
@CNN For those who are unaware, if you have Gboard installed, Google and so the US gov with a warrant can read your outgoing messages. The Incognito flag is a request only- the app cannot impose it on a non-compliant keyboard. Such a keyboard can be pushed to your device by Google.
interesting attack vector
would be solvable by implementing your own keyboard
We could Collab if you wanted?
Ah, sure ❤️ I was doing it for Ciphey and because HashBuster was broken and uh, abused the ToS of companies 😅
DM me! 😄
Yeah, I actually did it to because was fed up of hashbuster not working 
I finished a splunk room on the blue primer series and would love more. Are there any other resources on the net for hands on splunk?
Splunk has free version that you can run at home and do all sorts of things with it. There are also docker images, and trial downloads that you can play with. They also have github repos with past Boss of the SOC (BOTS) competitions and data sets which is a jeopardy CTF. What kind of hands on are you looking for?
similar to the rooms i guess, a guided approach as im still learning about the splunk language etc. The answers you confirm are very helpful in guiding and making sure im on the right path etc
Splunk Fundamentals 1 is a free training that is guided
They have a pretty robust community as well, keep an eye on Splunk Answers, there are lots of questions that get answered with sample data that is generated on the fly, and showcase various things that can be done with SPL
ok, many thanks for the help
Done
How you created logo.gif for this? Man, whenever I visit your repo I always amazed with something
Canvas
How do I create my own? if you have link for tool or fro canvas?
Canva 🙂
you might like this
I make all my logos in Canva, but eventually I pay @quasi scarab to design me one 😄
Thanks Bee
Just got a new phone and wanted to get away from LastPass/cloud storage-based pw managers. Imported my .kdbx KeepassXC file and has been auto-filling/working really well on Android 10
https://github.com/PhilippC/keepass2android
You bein' sweet to/about me again? 🥺 ❤️
just your awesome skills

❤️ ❤️ ❤️
I might have some more work to commission u for 👀
and i can afford it this time
with my fancy THM salary
And I might have a bunch of time to gladly and willingly dedicate to you ❤️
Hey awesome notes, just be careful you’re actually allowed to share everything in there... for example I aw an OSCP BoF which I know offsec doesn’t like and a few HTB machines which I think are all retired so that should be fine
Hey, thanks for the comment and yes all of the stuff here are from retired machines the OSCP BoF is notes from the OSCP BoF Prep Room
Thanks a lott
yess
if offsec saw the bof prep room here i'm sure they'd ask for it to be taken down lol
naah its a general Buffer Overflow room tbh but a very great herlp
i mean this one https://tryhackme.com/room/bufferoverflowprep
yup thats what i meant as well
its just basic bufferoverflows Offsec cant say that BoFs are to be taken down
well no but the program and the prompt are the same as the exam one
i am not too sure i dont think so
Oh congrats, You been trying hard i see 
Oh, they already tried
That's why it's no longer called "oscpbofprep"
Thaanks a lot mahn and yess hahah trying to include more AD content
Why site is not opening for me??
Sadly it's not working, i tried from other device on different network too lol
It just don't load
Thanks a tonn 😄
👍 Awesome stuff
Thaanks mahn
@tranquil shuttle its amazing u spend a lot of time in it
@light crystal is that opening for u?
It's not opening for me 😭
Maybe your country blocks sites with the keyword "Hacking"
We are from same country XD
Light10 and me
And i think @tranquil shuttle too
I visited his GitHub and go to the link from there
It's not same but anyway, notes are there lol
👍
This is an AMAZING RESOURCE!! thank you so much for sharing this! 😆
huh
Thanks a lot mahna dn yes hahaha its been a while
i am not too sure why yous is not working
No problems at all
SANS DFIR (Digital Forensics and Incident Response) Hunt Evil Poster
https://www.sans.org/security-resources/posters/hunt-evil/165/download
that's actually very very very useful ^ i currently work in a soc and see lots of alerts with those processes
so if you're looking for a soc role, familiarity with the processes in that document would help loads
We'll have an upcoming room covering some of these processes
🥳
I found this
Quite cute to see a THM specific cheat sheet
the timeless question
in pinned
uh
not off the top of my head
but I would try to install linux vm
so you get very fast at navigating the command line
one sec
there's a video on the file system
which is worth learning
ah nice, that's good
uh
I doubt you'll have to read the source
start looking into how programs are actually executed
There are good books on Linux kernel programming
then you could potentially progress to rootkits
and kernel level stuff
if you want to keep it hacking related
Yeah, you might need to build up to it
But try and get a deeper understanding of assembly etc.
it will provide a good grounding for linux and windows
About Bee-san:
- Twitter: https://twitter.com/bee_sec_san
- THM Staff (first 5k member, first community mentor).
- My blog has 2.3 million views, I've written 5 books on programming and I'm a Dev.to distinguished author https://skerritt.blog/ , 6000 email subs and I was an admin of r/blogging's Slack group
- RustScan is my baby https://github.co...
👀
👀
Someone who worked in hiring open-sourced a vulnerable web-app they used as part of a technical assessment in interviews
https://github.com/RamadhanAmizudin/lazyweb
Nice find 👆
Wouldn't this be more suited for #programming or...
Nah, it's a resource
jayy u always have some thing against me 
I'm sorry 
Can I post it in there anyway?
sure
Ty
Cyber Security Body of Knowledge
Cool and an Informative talk ^_^ @tepid patio
can anybody recommend a guide for getting started with API testing, for somebody who already tests web? basically just want to get up to speed on any API-specific tools, bugs to look for, etc. that I should know
postman has a lot on that
you mean the postman documentation has information on using it for security testing? I can't see that. or did you just mean I should look into postman as it's a commonly used tool for it?
edit - sorry, I maybe should have been clear in my question that I meant security/pentesting
Python is still one of the most 'spoken' cyber languages out there.
Use PYTHONISTA2021 to learn for FREE with my Python Basics course.
Tell others.
Course link: https://t.co/8aysj9IMtJ
#python #pentesting #cybersecurity #bugbounty
In this video, I will teach you a simple method that can save your time getting into ssh server via a private RSA key that is encrypted with a passphrase.
Many times solving a CTF you get to know that there an exposed Private RSA Key but when you try to use it to login via SSH it asks you for a passphrase.
the passphrase is located in the priv...
Postman can be used to test api's, what part of an api are you trying to test
I'm interested in learning how to pentest APIs in general
If you know the structure of the api, you will want to research fuzzzing techniques then
thanks. I assume there's more to it than just fuzzing though. that's why I'm asking if anybody knows any good guides which give a good, thorough overview of the tools/methodology, so that I have a plan for everything (or all the priorities anyway) of what I should research. rather than hearing about one thing here, another thing there.
like I say, I'm already comfortable with web testing. I assume there must be lots of people who've been in a similar situation and have shared info on what a web tester needs to get up to speed with to look at APIs
API testing - like most web testing - involves a fundamental understanding of the underlying technologies. I would begin with reading up on API frameworks like RESTful or SOAP and going from there.
Heck, look at what happened with Parler, all of that app data was exfiltrated via their API by simple fuzzing/IDOR techniques, nothing fancy at all.
https://swagger.io/docs/specification/2-0/what-is-swagger/
https://www.soapui.org/docs/soap-and-wsdl/
SoapUI, is the world leading Open Source Functional Testing tool for API Testing. It supports multiple protocols such as SOAP, REST, HTTP, JMS, AMF and JDBC. It supports functional tests, security tests, and virtualization.
Thanks, yeah I'm not after anything fancy - just want to cover any blindspots that I have since I'm coming from a more web app focussed background. I do know a bit about REST, SOAP, etc. already from that, but will cover those links to make sure it's all clear!
just reposting this but
working on an install script for programs and services for ctfs/general hacking
and tools suggestions people have?
I've definitely missed tonnes
Kali comes with basically everything you need. I'll typically use some version of this script for fresh installs https://github.com/JohnHammond/ignition_key/blob/master/ignition_key.sh
ah thank you, I haven't seen that from John before
what are the key differences between apt and apt-get, John switches between them at about halfway through the script
from what I can see online, it just looks like apt is the updated version and you only need to use apt-get for some features that haven't been implemented yet
eh no huge difference, some packages require backwards compatibility with apt-get while others use the preferred apt which will automatically grab newest packages
what no
apt and apt-get are the same
They do the same things
apt-get is the stable scripting interface
Apt is not
They work the same
But your statement was not correct
They install packages the same way
There's no such thing as a package that installs with one and doesn't with the other, or installs differently
They both automatically grab the newest packages
Hey y'all! The free path was updated (thanks @balmy merlin @topaz gulch @hallow meadow @glossy blaze for help in choosing the rooms)
+ Shodan
+ RustScan Room
+ Hacker Methodology
https://blog.tryhackme.com/free_path/
PS: The Shodan room is updated 👀
https://tryhackme.com/room/shodan
A free guided path for beginners on TryHackMe.com
Learn about Shodan.io and how to use it for devices enumeration - is your coffee machine publicly accessible?
https://hackmyvm.eu/
HackMyVM
new platform similar to vulnhub but very good came out a month ago
Yeah it's a good platform
Hey! I'm running a lil giveaway for THM vouchers.
https://twitter.com/bee_sec_san/status/1351594084633370637
It is self-promo, but not of paid content so idk if this channel is right?
Thanks bee I hope I win one lol
https://pwnable.tw/challenge/#1
https://overthewire.org/wargames/bandit/bandit0.html
https://go.joincyberdiscovery.com/tutorial
Some websites with challenges to do in cybersecurity
Pwnable.tw is a wargame site for hackers to test and expand their exploiting skills.
you forgot picoctf
List of wargames and some practice ctfs
The biggest CTF of 2021 so far, with over $5k in prizes, and random swag giveaways to teams (because let's be honest, who doesn't want free swag).
Running from 23rd-30th of January at: https://ctf.offshift.io/```
0/1771717177171
https://cyberlite.substack.com/ Created by: Oliver Kitchin (Not Me)
@gaunt hollow That's your substack ?
Oh, no. Should have credited the author, one second. Found this on Reddit last night
Possibly post this in #thm-community-media instead? Not sure if it counts as a resource
sorry, it was my first published writeup so I didn't really know where to put it
Don't sweat it, no problem :)
how long do the admins normally take verifying the writeups?
It's not admins
It's room creators
And it's completely up to them whether they accept, deny or ignore it
Ahh right
Well Umair said it was great if I did one
so uh
my chances aren't too bad
Which room @glacial gazelle?
Chocolate Factory
Has it been accepted or?
Not yet, Umair is going off on an adventure so his replies are pretty slow
Soooo, the writeup you posted earlier as being approved is not approved?...
No, it isn't
Please don't release/promote writeups publicly until they have been accepted on the room @glacial gazelle
free training from the CISA
101 Coding for the Public
101 Critical Infrastructure Protection for the Public
Cryptocurrency for Law Enforcement for the Public
Cyber Supply Chain Risk Management for the Public
101 Reverse Engineering for the Public
Fundamentals of Cyber Risk Management
Don't Wake Up to a Ransomware Attack - 1 Hour
Introduction to Cyber Intelligence - 2 Hours
Don't Get Caught in the Storm - Protecting Your Cloud Assets - 1 Hour
Cyberessentials - 1 Hour
Cloud Computing Security - 2.5 Hours
Foundations of Cybersecurity for Managers - 2 Hours
For anyone interested in bored uni student coursework:
https://abertaycoursework.xyz
I may or may not have been bored enough to set up a site with mine 🤷♂️
Got some fun tools in there
You are most welcome @tepid patio ♥️
Don't know why the bot deleted your kind thank you message
You got me :(
don't tell him it only emboldens his behaviour
What is this?
does anyone of you know about a list or repo containing applications and the place and format they store credentials? I know that there are some metasploit post modules in post/<platform>/gather/credentials but I assume there are way more applications that store (user) credentials in an unsafe (reversible) way.
@gaunt rain i haven't looked at that module, but i assume that just gets all system passwords
however different applications such as apache will have for example .htaccess
but i'm not aware of any tool that has this functionality of searching all applications, i've been looking before
but if you run some enum script and gather all applications on the system you can manually go through each and google the location of creds
yeah that's how i do it now, thought that maybe someone compiled kind of a directory like PayloadsAllTheThings for known apps. thx for the reply!
is there any detailed resource available for metasploit's meterpreter commands
cuz i really can't understand what some of 'em means
write Writes data to a channel (what channel?)
The Raspberry Pi Pico is an entirely new type of microcontroller from Raspberry Pi. Small, cheap and flexible - it’s great for learning to code with MicroPython! Whether you’re looking to learn about the MicroPython programming language, take your first steps in physical computing or want to build a hardware project, t
probably referring to channels you open up when you run shell from within meterpreter, i guess it would just write to stdin on whatever specified channel
also their docs are pretty good https://docs.rapid7.com/metasploit/manage-meterpreter-and-shell-sessions
looks interesting. what temperatures it can withstand?
85C according to the datasheet, i probably wouldn't rely on these things for production purposes but are perfect for prototyping stuff
also good for playing with as a digital toy.
honestly that's not a toy 😄
It's just a microcontroller?
Just get an ESP, they're super cheap and do micropython
And you can graduate to Arduino running on them if you want something better
Plus wifi and bluetooth
Interesting! Thanks, today I learn new knowledge.✨
I really need to do more with my ESP. Haven't used it since first year of uni 😆
I can't find the docs for the Bluetooth protocol I want
Well, docs yes but 0 examples
SANS has a massive list of Cheat Sheets available for quick reference to aid you in your cybersecurity training.
Sans cheatsheet cheatsheet ftw
Anyone got a wordlist of common linux commands that can be used for fuzzing a web cmd?
https://github.com/danielmiessler/SecLists might find what you're looking for here
Rangeforce has a special promotion going on right now for their Blue Team Battle Paths, $50 per path up to 3, usual price is $200/path. https://www.rangeforce.com If you are interested let me know I can put you in contact with the right person
@magic idol I think ill take you up on that offer, lmk
Here are some common ways to spawn a shell via installed Programming Languages:
Python:
import os; os.system("/bin/sh")
also
python -c 'import pty; pty.spawn("/bin/bash")'
&
python3 -c 'import pty; pty.spawn("/bin/bash")'
PHP:
exec("sh -i");
Perl:
exec "/bin/sh";
Ruby:
exec "/bin/sh"
Lua:
os.execute("/bin/sh")
If the awk command can be run, a shell can be spawned with the following:
awk 'BEGIN {system("/bin/sh")}'
The find command can attempt to spawn a shell with the following command:
find / -name foobar -exec /bin/sh \;
Here is also a good one:
script -qc /bin/bash /dev/null
i've also forgot how text editors can run commands and scripts inside of them,
add 'em here too
-_-
We all know how important it is to do enumeration on target machines so that we can choose our exploits wisely. So here is a small blog covering intro to enumeration with an example of SMB Enumeration. I'm learning and writing at the same time 🙂
Critiques are most welcome or even if you wanna collaborate
Hi!
Does anybody know of some good resources to dive deeper into windows core processes?
Did you complete the THM room on that topic? @grim plume
The definitive book on that is: Windows Internals Part 1: System architecture, processes, threads, memory management, and more, Seventh Edition by Yosifovich, Ionescu, Russinovich, Solomon.
Created a OSINT tool for Twitter! Needs API keys to work. Kronos is a simple bash script that will return a list of links containing people that your target is following, starting with the oldest first (history goes up to 1000).
@craggy onyx I’m working through it right now. Found it very interesting so that’s why I wanted to know if there are any resources to continue learning about it. Gonna have a look at the windows internals-book. Thanks!
Machine Learning (60+ hours) - https://www.udemy.com/course/machine-learning-concepts-and-application-of-ml-using-python/?couponCode=ML_FULL_UPLATZ
The free path has been updated to have.... a networking section!
Some things have been moved around, AOC1, AOC2, and Owasp top 10 make a feature!
A free guided path for beginners on TryHackMe.com
@tepid patio Thankyou so much for keeping it updated 🙂
ping?
pong
@grim crown
A) Writeups go in #thm-community-media
B) please don't post writeups that haven't been approved by the creator. It's very disrespectful, and against our rules in here.
good guide to harden your Discord account https://www.kaspersky.com/blog/discord-privacy-security/38546/
Join @shut ferry and I this Friday at 6 PM BST where we will be talking about how to harness your LinkedIn network to break into cyber!
Twitch link : https://lnkd.in/eCqNr7i
It will be recorded for YouTube as well if people can't make it.
Infosec Recruiters working predominetly in the UK, EU, USA, Singapore and Australia
Can anyone recommend a script similar to APTSimulator on GitHub? I'm trying to work on IR and forensic skills
I just need a somewhat realistic attack simulator to run against a VM
Atomic Red Team https://github.com/redcanaryco/atomic-red-team
Thanks! I'll check it out tomorrow 
made a script utilizing the VirusTotal API to run some basic analysis on malicious links/files
https://github.com/Droogy/VirusTattle
Nice script
thank you very much! (pls PR and make it better 😭 )
very true, been slacking in python - plan on re-writing my homebrew stuff with concurrency
You sound like a zsh guy... 😂
But yeah... Zsh made a huge difference for me
I was just using virus total a whole bunch doing the range force stuff. This could have been put to testing @fast wraith
Might actually redo it with your script, if you dont mind.
please go right ahead! just keep the api call limit in mind (4 per/min)
I saw a good idea out there for a possible script. Potentially like a Yara rule generator :)
we're referring to the bash shell scripting language not the actual shell itself
Oooh. I stand corrected in the case.
Yara rules are simple in itself..but a script would be nice to plug and go
definitely, seeing lots of opportunity for scripting in blue team stuff
I finished soc 1 capstone and things like iptables, fail2ban etc def could use some scripting
My brain is not big enough for that tho haha
nah all my homies use xonsh
Im the manual type of guy 
honestly just having a script that runs decent configs for all the usual suspects is more than enough, its easy to forget things when you're running through like 6 .conf files in a row lol
I lack in that department, mainly due to not actually doing it
I feel like its faster to do stuff manually, especially when you are jammed for time
true, if you know what you're looking for a good one-liner is all you need which is why i've been leaning on bash so much lately
I'll be sure to check it out...
There's also an upcoming THM room on Atomic Red Team in April 2021. 🥳
looks good :D i also recently made something utilising the VT api, however for files i use this site: https://analyze.intezer.com/, it's very OP
time to end the OS wars https://github.com/SerenityOS/serenity
Does anyone know of a CTF or virtual labs for ICS (OT) environments?
x86 (32-bit) kernel? whyyyyyy
great video on tshark usage and monitoring - shame these SANS videos don't get more love
Living in a world in which you have to assume breach, makes the thought of detecting threats more antagonizing. Compounding this agony, is a world in which we have a global pandemic and the threat actors are looking to take advantage of one of humans' most recent calamities. Since threat actors do not take time off matters the season or pandemic...
hiya
has anyone found any active exploits or been able to exploit CVE-2021-3156 (the sudo cve for privesc)
No PoCs yet.
ok thank you for update
i was unable to find any also so just confirming
CVE-2021-3156 Sudo vulnerability has allowed any local user to gain root privileges on Unix-like operating systems without authentication. Sudo is one of the most important, powerful, and commonly used utilities that comes as a core command pre-installed on macOS and almost every UNIX or Linux-based operating system. sudo is a program for Unix-l...
There is a video of a poc.
Yo

good twitter thread for port-forwarding/tunneling tricks
https://twitter.com/infosec_scarlet/status/1354528499105636353
TLDR for those without Twitter
Local Port2Port
Open new Port in SSH Server --> Other port
#Remote port 1521 accessible in port 10521 from everywhere
ssh -R 0.0.0.0:10521:10.0.0.1:1521 user@10.0.0.1
#Local port 1521 accessible in port 10521 from everywhere
ssh -R 0.0.0.0:10521:127.0.0.1:1521 user@10.0.0.1
Port2hostnet (proxychains)
Local Port --> Compromised host(SSH) --> Wherever
ssh -f -N -D <attacker_port> \
<username>@<ip_compromised>
SSHUTTLE
You can tunnel via ssh all the traffic to a subnetwork through a host.
Example, forwarding all the traffic going to 10.0.0.1/24
pip install sshuttle
sshuttle -r user@host 10.0.0.1/24
METERPRETER
portfwd add -l 80 -r 172.16.0.0 -p 80
NCAT PORT FORWARD
mknod pivot p
nc -l -p < port to listen on> 0<pivot | nc 1>pivot
REMOTE PORT FORWARDING
ssh -N -R 10.10.1.1:4455:127.0.0.1:445
attacker@10.10.1.1
Socks5 with SSH
ssh -N -D 127.0.0.1:8888 admin@10.1.1.1
DYNAMIC PORT FORWARD
ssh -N -D 127.0.0.1:1337 user@remotehost -p 8888
NCAT HTTP PROXY
ncat -vv --listen 3128 --proxy-type http
SSH GRAPHICAL CONNECTION (X)
ssh -Y -C <user>@<ip>
#Y is less secure but faster than -X
I have seen a lot of #pentesters struggle with tunneling and port-forwarding concepts. All #hackers should definitely understand these concepts for successful tests.
This thread is dedicated to Tunneling/PortForwarding tricks.
#infosec #pentest #tunneling #security #bugbounty
584
2017
sshuttle > all
Is that a THM community newsletter? would be nice to contribute to something like that @tepid patio
Hey someone know good resources to learn socket with python?
uhhhh, its caramel_members weekly news recap she does does r/nordvpn, you can DM her to help 😄
Exploitable heap overflow in libgcrypt 1.9.0 (┛ಠ_ಠ)┛彡┻━┻
It's the crypto library that gpg uses. Homebrew has 1.9.0 right now. 🚨
222
474
gotcha, well if theres any interest in a THM newsletter count me in - ill reach out to her as well
So the cats out of the bag! I've released a new tool with help from @sonic abyss @night plinth !
🔥 Introducing Name That Hash - Modern Hash Identification system with popularity ratings, Hashcat, John, and descriptions.
GitHub: https://github.com/HashPals/Name-That-Hash
Web App: https://nth.skerritt.blog/
Twitter Announcement: https://twitter.com/bee_sec_san/status/1355500939881406464
Don't know what type of hash it is? Name That Hash will name that hash type! - HashPals/Name-That-Hash
Name That Hash
🔥 Introducing Name That Hash - Modern Hash Identification system with popularity ratings, Hashcat, John, and descriptions.
The little secret project I've been working on for weeks with @q8fawazo @Jayy_2004 @OrielOrielOriel and more!
👀
Special thanks to @sharp aspen @sand schooner @night ether @hushed estuary @fast onyx @hallow meadow @thin dagger for testing and feedback 😄 ❤️
Gj
:<
you're getting thanks in the next tool release which is probably a couple of days
Waiting for more ☺️
Oh is it in python?
I thought bee will make something using rust LOL
Looking good though. Thanks bee and all the contributors
It's in Python because the original HashID was and we use some of their code
(with full-credit ofc!) ❤️
Hey everyone, I made a tool that generates reverse shells with supplied args. Never leave the browser again!
nice tool. just a small grammar thing i spot under #Usage Examples
I remember there was a free path blog for tryhackme which recommended free room. Anybody have the link for it?
nvm I found it
!docs free-path
Aww 🙂 it's great, I used it earlier to figure out which tool to use 🙂 Thank you
Nice! Thanks for the catch. I put that README together at 3 am yesterday morning
Just fixed it. Thanks again 🙂
np np
Awesome resource for blue teamers out there https://github.com/fabacab/awesome-cybersecurity-blueteam
DEDMAP Alpha Version 1.1 is out!!🔥🔥 Go check it out 👇🏻https://7Ragnarok7.github.io/DEDMAP
What's New in this Update :-
-Lots of Bug fixes
-Major Code and Performance optimization
-Great Improvement in port scanning speed.
-Drastically reduce Space and Time Complexity
-New slick seamless installer❤️
-Patched to Natively support all android devices🔥🔥
❤️
And guess what? With this new update it defeated Nmap in port scanning speed! (POC in the video below)
It beats Nmap even in its Infamous Stealth Scan mode with superuser privileges!!! All of these without even introducing multithreading in the tool yet🔥
Do use the tool and share me your feedback after using it. :) I will continue developing it. Also, it would be great if you can star the tool on GitHub and share it if you liked it 😊 ..as it has very low reach to people as of now. I will add awesome new features to this tool in near future 🙃
A Simple but Powerful cross-platform port & network scanning and automation tool made in python.
Can I recommend for recording your terminal
Might be easier then recording with your phone 🙂
Other then that, looks great!
Thanks for the suggestion!
Is it approved write up?
@next marlin Is that approved?
(If you do not respond within 5 minutes, I am going to delete it)
Submit it to the room in the writeups section
Click on the Writeups tab in the room and then click Add Writeup
it will be reviewed by the room authors
Rizin is a Radare2 fork by the creators of Cutter 🙂 https://rizin.re/
ooo
@frigid jacinth Please only post actual resources
Any recommendations to learn basic stuff of os and windows os and linux(rgt now iam learning it from linuxjourney.com,any further recommends are welcome) in the perspective of cybersecurity.
have you done the tryhackme linux fundamentals room?
Yup.. completed
well that should be most of the basics, as you go on to do more cybersec rooms on THM it should further develop your understanding if you run into problems
for windows, not sure if there are similar rooms, maybe one on powershell
UnderTheWire for powershell
OverTheWire for linux
K..what is wt iam doing now...but still confused on learning windows os
Like how to learn it from core.
Iam doing it rgt now...but before going to start powershell...i want to learn abt event logging,user management,sec. auditing and file system hierarchy in windows os...
I listed two
But before learning powershell..it's better to learn the basic stuff of windows os...rgt??..
Learning about the OS, you will have to interact with it in some way. On windows, one of the most common ways to interact with Windows is PowerShell. Skipping PowerShell, in my mind, is very similar to wanting to understand Linux without learning bash (or another shell). It's possible but increases the lift substantially.
They're asking the opposite
Can anybody tell me the efficient way for learning the SQL injection?