#resources

1 messages ยท Page 13 of 1

cerulean viper
shut ferry
#

Hey! Here is a giveaway of BTL1 certs. Course is great, and imo it is worth the shot ๐Ÿ™‚
https://securityblue.team/btl1-100-giveaway/

SECURITY BLUE TEAM

security blue teamBTL1 GIVEAWAY WELCOME TO THE BTL1 GIVEAWAY! Weโ€™re passionate about training the next generation of cyber defenders using practical teaching methods. To celebrate one year since Blue Team Level 1 launched, weโ€™re giving back to the community. BTL1 is trusted around the world to train technical defenders in governments, law enforc...

odd sinewBOT
#

Gave +1 Rep to @halcyon rose

sinful fern
#

If anyone is interested in learning about the mathematics behind asymmetric cryptography/number theory...this guy guys channel is great! Just going to leave it here ๐Ÿ™‚

fast wraith
ebon tide
#

MSI-Nvidia RTX 3090 24gb ddr6x only for 350$ (only in india)!!!

odd quest
#

That sounds like a scam, and also doesn't sound like a resource

fast wraith
#

Namecheap apparently doing takedowns via Twitter now? Might be able to automate this in my workflow if so

gentle shuttle
#

I reported a domain to name cheap yesterday. Wasnโ€™t even a good phishing attempt - came from a mobile number and claimed to be a bank. Then their page was prevent-payment.com/bank-name

cobalt turtle
#

Hey,
I have done a lot of windows priv esc, but it still feels weaker than my linux skills. I thought about filling some gaps with the tiberius course (1,5 h) on udemy, but I just found the course from tcm which is almost 7h. Don't want to buy both, anybody here who has done both or can recommend one?
Thanks in advance.
P.S.: I hope this is the right channel.
Edit: I just buy both, f**k it, good education is worth every penny ๐Ÿ˜‰

crimson thunder
cobalt turtle
odd sinewBOT
#

Gave +1 Rep to @crimson thunder

crimson thunder
lean citrus
lyric mirage
normal saddle
#

ty

barren vault
barren vault
#

It's not perfect, but it's way faster than Hydra

prisma bison
#

Oooooh

sonic abyss
#

o

spiral zodiac
shut ferry
#

for this on 0day's twitter

prisma bison
shut ferry
#

thanks

abstract plaza
#

Crypto Cafรฉ - Cryptography Seminar Series at FAU

glacial gazelle
#

In addition to John Strands Pay-What-You-Can Trainings we have a great line-up of four to 16 hour Pay-What-You Can courses to consume within the next few months! Password Cracking 101 + 1 with Will Hunt and Owen Shearing; Regular Expressions, Your New Lifestyle with Joff Thyer; SELinux โ€“ Necessary and Not Evil! with Hal Pomeranz and Getting Started with Packet Decoding with Chris Brenton. Check out our website for more information on all of our training options! https://wildwesthackinfest.com/training-schedule/

Wild West Hackin' Fest

This page contains details about upcoming information security training courses brought to you by Wild West Hackinโ€™ Fest.

fast wraith
#

holy shit hal pomeranz has a pay-what-you-can for SELinux

warped pulsar
#

It is time my dudes

#

Here's the script i was talking about last month (sorry it took so long)

remote wind
fast wraith
warped pulsar
#

I mean did you check the script itself? I added a bunch of comments there. But yeah i should Probably write a small doc how to use it

#

i have the document i submitted for the project but thats more the project management document thing of the project

#

wont be of any use to you

#

Thanks tho

glacial gazelle
warped pulsar
#

I tried it for some of the tryhackme boxes and it worked

glacial gazelle
#

ahh right, but you had to change the target url etc.?

warped pulsar
#

I used the dvwa because i needed a test environment since college demands testing

#

but yeah just grab whatever target you want and modify to your needs

#

there might be some tweaks here and there for different targets

#

but it should still work

#

Its not a be all end all solution, but i can say it works in some of the tryhackme boxes (altho i only tried the simple ones)

glacial gazelle
#

yeah, it looks good

#

the GUI module looks fun to play around with as well

#

Strategy 3 works every time.

Discord mod is the most powerful position in the world. Full power, complete control... and there is an easy trick to speedrun it.

Twitter โžค https://twitter.com/beluga1000
Join My Discord โžค https://discord.gg/CETznntGeQ

โ•”โ•โ•ฆโ•—โ•”โ•ฆโ•—โ•”โ•โ•ฆโ•โ•ฆโ•ฆโ•ฆโ•ฆโ•—โ•”โ•โ•—
โ•‘โ•šโ•ฃโ•‘โ•‘โ•‘โ•šโ•ฃโ•šโ•ฃโ•”โ•ฃโ•”โ•ฃโ•‘โ•šโ•ฃโ•โ•ฃ
โ• โ•—โ•‘โ•šโ•โ•‘โ•‘โ• โ•—โ•‘โ•šโ•ฃโ•‘โ•‘โ•‘โ•‘โ•‘โ•โ•ฃ
โ•šโ•โ•ฉโ•โ•โ•ฉโ•โ•ฉโ•โ•ฉโ•โ•ฉโ•โ•šโ•ฉโ•โ•ฉโ•โ•

#Discord

โ–ถ Play video
#

@shut ferry found this one a decent resource

shut ferry
#

finally

#

@topaz gulch can I get mod

#

I'm a girl btw

warped pulsar
#

Lmao

topaz gulch
shut ferry
#

frick

#

no

#

no

fast wraith
cobalt turtle
odd sinewBOT
#

Gave +1 Rep to @fast wraith

remote wind
light crystal
#

gg @remote wind

summer mirage
#

LoL

sonic abyss
#

Very cool swanandx!

remote wind
odd sinewBOT
#

Gave +1 Rep to @sonic abyss

sturdy shell
blazing magnet
topaz gulch
#

Niceeee!
Why not put it on TryHackMe @blazing magnet?

#

God only knows we need more RE content, and that looks awesome

blazing magnet
topaz gulch
#

Yep!
Just a suggestion obviously, but I reckon that would be really cool, both for us and in terms of you being able to provide machines containing the binaries / software / etc for easy deployment, hosted by TryHackMe, so nice and easy

#

A lot of the content on the site is exactly like this: stuff provided by the community just for the sake of learning, teaching and transferring knowledge

#

Feel free to give us a shout if it interests you -- happy to talk more about it if you want ๐Ÿ˜„
(Obviously no pressure there though ๐Ÿ˜)

blazing magnet
topaz gulch
#

Sounds good to me! ๐Ÿ™‚

flint bison
#

@blazing magnet if you verify with the bot, one of the mods can add you to the room creator's channel

#

!docs verify

fervent summitBOT
topaz gulch
#

Oh, that's a good shout actually. Don't even need to verify for that though ๐Ÿคทโ€โ™‚๏ธ

#

Added

flint bison
#

My mistake, thought you had to verify first. Thanks, Muiri ๐Ÿ™‚

fast badger
#

clear

topaz gulch
#

Np ๐Ÿ™‚

fast badger
#

whoops

sour cobalt
#

Does any one has completed Windows Fundamentals 2 I am stuck on one question can anyone help me

#

I didn't find any writeup so

light crystal
#

@sour cobalt #859514456107515904
There's a tool tab in System Config panel. Click on that. Then look for the first tool there. Try launching that?

sour cobalt
#

I have tried that. It is not working @light crystal

odd quest
azure widget
frank plover
#

Tldr; uses Vim to take notes and pushes to gitlab for study as well as ease of writing report. Reports are made through a script and exported to PDF

#

Also has a script that zips everything for OSCP exam submission into a 7zip format

spiral zodiac
#

jabba blobknife

#

don't you dare delete that

prisma bison
#

Don't click, it's a rickroll!

#

I promise you all, don't click!

spiral zodiac
#

nano lover blobknife

#

(it's not a rickroll)

prisma bison
#

Imagine not being able to exit your text editor without turning your computer off!

spiral zodiac
#

imagine using nano blobknife

noble tangle
#

For those familiar with MITRE's ATT&CK framework, and those in blue teaming, MITTRE has published a new framework for defenders called D3FEND, which could prove fruitful for all of you: https://d3fend.mitre.org/

noble tangle
crimson thunder
#

nano is great. you have to use something until you learn how to use vim

spiral zodiac
#

eww ๐Ÿคฎ

crimson thunder
#

good to see you ma1 ๐Ÿ™‚

spiral zodiac
#

Hi.

frank plover
#

imagine getting stuck in vi the first time using Linux and having to reboot the machine to get out of it

unreal hollow
#

vi man - how to exit, turn off machine or just try :q

flint bison
light crystal
glacial gazelle
#
:! kill -9 $(ps aux | grep "vim " | grep -v "grep" | awk '{print $2}')```
#

is my go-to

dark mortar
spiral zodiac
vast mountain
#

The Russian roulette one kekw kekw

upper field
#

Can someone delete this message? ^ It's a scam link

sturdy shell
#

got it (:

fast wraith
night ether
gleaming sapphire
#

where can i learn about more about the process of setting up a p2p application

flint bison
proud quest
#

Any Good Resources For Learning Privilege Escalation for beginners?

flint bison
proud quest
#

Apart from that?

flint bison
#

I've seen some udemy courses on it as well, but haven't personally used them

night ether
#

thecybermentor and tib3rius both have courses on privesc but they are paid

proud quest
#

Any good blogs?

night ether
spiral zodiac
#

He was the greatest follower of nano, with him gone, there can be no resistance.

night holly
#

wait pars is gone?

topaz gulch
#

@shut ferry

#

Yep ๐Ÿ˜ข

#

Para, get back here

unreal hollow
night holly
fast wraith
sand parcel
#

any recs on ctf/htb streamers that are live on some kind of regular basis?

light crystal
#

credit - @lapis herald

warped pulsar
#

nano!

#

is the cloud storage link safe?

shut ferry
#

hi somebody has a COVID-19 test samples

prisma bison
sonic abyss
tepid patio
fast wraith
#

had a bit of an "aha" moment recently when reading up on the difference between exporting variables and direct assignment in bash, i.e., export ip=10.10.10.10 vs ip=10.10.10.10

exporting a variable applies to sub-shells spawned from the current one, so for tmux users, just export the machine IP before you start tmux, and then you don't have to constantly retype it

glad hazel
#

What is the difference?

night ether
indigo pike
#

Makes sense.

short sleet
lavish rune
fast wraith
cerulean viper
#

Lots of giveaways happening so here's the one for MPP course

upper cloud
spiral zodiac
sonic abyss
#

oh lordy

fast wraith
spiral zodiac
#

Did someone delete my message? ๐Ÿง don't remember what I posted

#

I'd really like to know why it was deleted

#

and who deleted it

#

next time pls tell me why you deleted my message, so I can protest properly. blobknife

#

Ooh think it was the blueteams thing I posted blobknife

#

did you remove because its competition? kekw

peak leaf
#

BTLO? pepega

shut ferry
#

I had the time to save it anyway tipsfedora

proven agate
fringe spire
shut ferry
gentle shuttle
#

Python based brute force tool. Currently implements SSH, but other network services are coming soon. This works faster than hydra (through thorough testing). Highly modular so only new service classes must be added to extend. https://github.com/Cerbrutus-BruteForcer/cerbrutus

GitHub

Network brute force tool, written in Python. Faster than other existing solutions (including the main leader in the network brute force market). - Cerbrutus-BruteForcer/cerbrutus

calm ermine
#

@shut ferry

balmy sun
#

how is it faster than hydra considering python is one of the slowest langs out there

gentle shuttle
#

๐Ÿ™‚

#

Unsure. Hydra may not be written the most efficiently for SSH but on the same number of threads as hydra this runs far quicker.

balmy sun
#

oh that's pretty weird ig

celest widget
jagged haven
#

hmmm, ik it wasnt for me but :v as I use i3 I am quite interested in that awesome :v. Thx for the indirect tip

faint sluice
#
freeCodeCamp.org

Earning the Certified Information Systems Security Professional (CISSP) Certification proves you have what it takes to effectively design, implement and manage a best-in-class cybersecurity program. The CISSP is one of the most valuable Cyber Security Certificates in the market today. We just posted a 13-hour course on the freeCodeCamp.org

peak leaf
celest widget
#

As far as I know it's i3 or not awesome

#

Or not dwm

spiral zodiac
#

That's neither i3 or dvwm it's tmux.

peak leaf
#

Yeah, you can't tell what WM/DE he's using with just cropped screenshot

shut ferry
#

hi. just asking around if someone has an shodan premium account to borrow

shut ferry
#

hi does anyone have js resources?

clear hollow
fast wraith
shut ferry
#

+rep @clear hollow

odd sinewBOT
#

Gave +1 Rep to @clear hollow

tepid patio
topaz gulch
#

Oh, I read the tweets. Something tells me this ain't meant for resources ๐Ÿ˜†

#

It ain't April Bee smh

tepid patio
#

I don't think it should be

#

cause uh

#

what rule was it

shut ferry
shut ferry
sonic abyss
#
#

Such a great resource

tepid patio
lavish rune
haughty kernel
#

Does anyone have some good C resources?

light crystal
#

i can share these

#

@haughty kernel

haughty kernel
odd sinewBOT
#

Gave +1 Rep to @light crystal

languid parcel
#

anyone got any good resources that teach Bash Scripting effectively and detailed?

languid parcel
#

you sir

#

are aamazing

#

*amazing

#

thank you

#

because I'm great with utilizing Linux but when it comes to scripting in sh, i'm just baffled lol

languid parcel
#

idk what it is, coding intimidates me lol

light crystal
#

lol

sonic abyss
#

Hi everyone, I've updated my osint challenges & aded a few more - checkout pins to see the list blobfingerguns

light crystal
#

@sonic abyss thanks for tellin that, now amma edit my reosurces link ๐Ÿ˜›

odd sinewBOT
#

Gave +1 Rep to @sonic abyss

small bramble
brave elk
#

Any good tips or programs that help you document your steps when hacking?

night ether
fast wraith
brave elk
brave elk
odd sinewBOT
#

Gave +1 Rep to @night ether

light crystal
light crystal
odd sinewBOT
#

Gave +1 Rep to @fast wraith

light crystal
# languid parcel you sir

In this video, we will cover how to do simple scripting in Linux with Bash. We will learn about grep, cut, tr, for loops, if statements, and more.

Timestamps:

0:06 - Introduction & ping
3:10 - grep
3:46 - cut
5:15 - tr
5:50 - Writing a simple Bash ping script
11:20 - Improving our Bash script
14:15 - One line for loops
17:53 - Closing remarks...

โ–ถ Play video
sonic abyss
#

Really nice for google dorking

remote wind
#

Thnx for sharing, looks very nice

shadow zenith
#

Good morning people! I'm developing a new tool to automate pentesting through a visual interface, which allows to create "recipes". It is still a bit green but its development is active. I encourage you to leave a star if you like it and any comments on what to improve or what to implement in the near future.

The tool in question is this: https://github.com/cosasdepuma/Masterchef

In the cookbook directory you have some recipes already created to play with. Best regards and keep on being hack!

GitHub

๐Ÿณ The most delicious pentesting tool. Contribute to CosasDePuma/Masterchef development by creating an account on GitHub.

tepid patio
oblique forge
#

This man is brilliant and has free lectures out the wazoo

placid wadi
#

indeed, Sam Bowne is awesome

#

this is a pretty badass tool I just found

sonic abyss
shadow zenith
odd sinewBOT
#

Gave +1 Rep to @tepid patio

kind matrix
#

any room or any online resources for learning aws pentesting?

remote wind
kind matrix
#

thanks buddy : )

light crystal
#

+rep @remote wind

odd sinewBOT
#

Gave +1 Rep to @remote wind

zealous void
#

Any free courses for python with penetration testing?

night ether
#

yo wtf is that website

#

that is amazing

craggy onyx
#

Yo Jake! ๐Ÿ˜„

zealous void
odd sinewBOT
#

Gave +1 Rep to @fast wraith

gray sparrow
#

Good day everyone. Any resource of Application testing, reviews of the tested application, and solution to the tested application

bitter ember
#

what is the correct path after pre learning

light crystal
#

try the beginner pathway

#

@bitter ember

bitter ember
#

then

#

offensive ?

tired bison
#

After beginner pathway, you can aim for offensive security if that's what you're interested in. It's not really a stepping stone of 1,2,3. I prefer blue team a bit more so I'm pursuing the defense pathway after beginner (or rather at the same time now)

#

There's also "web fundamentals" if that interests you

flint bison
#

The pentest+ is also a good one to do after the beginner path. It has a lot of overlap with beginner path, so you can finish the pen+ path fairly quickly/easily (it's like 10 extra rooms).

shrewd ginkgo
shrewd ginkgo
ancient gale
#

Hi all, can anyone please donate me a subscription/one month voucher for me to learn in THM.
Thanks in advance!!

prisma bison
#

Hey!

This isn't the right chat to ask.
I would recommend waiting for a giveaway to happen because you've asked a couple of times now:)

tepid inlet
#

can anyone provide resources for powershell scripting which can be used to automate certain tasks?

balmy merlin
tepid inlet
#

thanks

uncut ether
#

Wrote a little something to hijack your webcam feeds and replace it with a pre-recorded video. Happy Meetings people xD

https://twitter.com/whokilleddb/status/1417144636787675139?s=19

Wrote a little script to hijack your webcam and set a pre-recorded video as your camera feed to save you from meetings which could have been an email๐Ÿ˜†

Tested so far on(In-Browser):

  • Google Meet
  • Zoom

This was originally a part of DSC NSEC WOC 2020-21
https://t.co/do8XvNM2vA

sonic abyss
#

Haha that's pretty cool

uncut ether
#

Things I do to get off classes creepypog

tardy kindle
#

Does anyone know good youtube channels that cover mostly red teaming?

tepid inlet
#

if you're given to write an assembly program which takes 2 command line arguement,then calculate the sum of these arguments and print the result,how would you write this code?

uncut ether
tepid inlet
uncut ether
#

It means hexadecimal

tepid inlet
#

suppose in assembly language,we are writing
mov bl,[rsi]
where rsi register contains a string,then what will be stored in bl

pine blade
#

Suppose rsi contains the value 0xdeadbeef it will treat that value as an address, dereference it and store that byte in the lower portion of ebx

tepid inlet
#

thanks

#

str_to_int:
xor rax,rax
mov rcx,10
next:
cmp [rsi],byte 0
je return_str
mov bl,[rsi]
sub bl,48
mul rcx
add rax,rbx
inc rsi
jmp next
return_str:
ret

can somebody explain me this,the main problem I'm facing is from the line 'mul rcx'

pine blade
#

In short that mul is negligible

#

Oh wait sorry I read that too fast and forgot the add rax, rbx

#

This looks okay at first glance what error are you getting?

tepid inlet
#

no no,this is from a blog post i was reading,the writer must have written it correctly so i guess it will return no error

tepid inlet
pine blade
pine blade
#

Oh that's just the way x86 works

tepid inlet
#

thanks for clearing my doubt

pine blade
#

Yeah it was originally designed with 32 bit registers in mind so that if you multiply 2 32 bit values you can get the resulting 64 bit value from eax and edx now that 64 bit is a thing and SIMD extensions exist it's something that stuck around for backwards compatibility https://www.aldeid.com/wiki/X86-assembly/Instructions/mul

Mul
tepid inlet
#

this is of great help,thanks again

narrow prairie
#

x86* has a lot of backwards compatibility built in, it's very easy to get confused on what's going on. Boot in Legacy BIOS mode and the system starts in 16 bit real mode, then has to be told to enter 32 bit or even 64 bit modes, low level stuff is a lot of fun, even if it can be a headache.

magic shale
light crystal
tepid inlet
#

this is a part of an assembly program where r12 contains the number of digits in the string(eg. "123" ,r12=3) and the string is in stack,and we have to output the string,can somebody explain it
print:
;;;; calculate number length
mov rax, 1
mul r12
mov r12, 8
mul r12
mov rdx, rax

     ;;;; print sum
     mov rax, SYS_WRITE
     mov rdi, STD_IN
     mov rsi, rsp
     ;; call sys_write
     syscall

jmp exit
narrow prairie
#

@tepid inlet #programming is probably the better room for you to be asking these assembly questions

Somewhere in the program, something along the lines of

.data
some_string: db "Hello world!", 0 ; Just some_string
some_string_len equ $-some_string ; Calculate the length of the string
.code
some_function_we_called_somewhere_in_the_program:
mov r12, [some_string_len] ; Move the strings length into r12
push some_string ; Push the memory location of some_string to the stack
jmp print ; goto our print method, it doesn't perform any sort of return itself so assumed a jmp

will be running and that is going to jump into the print function, not 100% as I am not overly familiar with the syscall instruction.
Within this print code;

print:
mov rax, 1 ; Set the rax register to 1
mul r12    ; Multiplies the value of rax by r12, this is 64bit so the result is stored in rax
mov r12, 8 ; r12 is reused for the value 8
mul r12    ; We're now doing rax * 8, this suggests to me that the values on the stack are stored as 64bit values so we have 8 times as many bytes and we reflect this
mov rdx, rax ; We're now storing the result of the multiplication in rdx which is used by the syscall as the length parameter

Hope this sort of helps, just worth noting I'm not 100% on what's actually happening, describing what I see as I can't find any examples online that work in the same way.

light crystal
light crystal
tepid inlet
shut ferry
#

For those that want to study Android

craggy onyx
tepid inlet
#

can someone provide the resources for learning assembly lang for cybersecurity

shut ferry
shut ferry
# tepid inlet can someone provide the resources for learning assembly lang for cybersecurity

IntroX86 :- https://www.opensecuritytraining.info/IntroX86.html
ARM Assembly :- https://azeria-labs.com/writing-arm-assembly-part-1/
Art of Assembly (Book) :- https://nostarch.com/assembly2.htm

idk if any of these are good enough, but I hope this will be some help at least.

light crystal
#

any good mind maps for enumeration part? like a checklist thing

glacial ferry
fast wraith
#

@night ether I remember you mentioned you had some exp with OSSIM -- currently playing around with a deployment because the ELK stack in SO is constantly dying on me, got any good resources for OSSIM besides what AT&T has out already?

light crystal
remote wind
#

Nice

night ether
glacial gazelle
#

new training platform from cisco, definitely worth checking out

open knoll
#

Guy anyone have good resources for learning phishing ?

odd quest
#

Why do you want to learn phishing?

storm ether
open knoll
odd quest
#

It's generally unethical

open knoll
odd quest
#

So we ask that you avoid discussing it here, under rule 9

young jacinth
odd sinewBOT
#

Gave +1 Rep to @glacial gazelle

fickle mulch
#

I have read that, some company asks for phishing campaign to increase awareness among employees. So learning about phishing, social engineering is a good skill for job, I think

shut ferry
#

Great examples to help with sed. I used one right now to filter a huge wordlist. 10/10

bronze flint
burnt knot
#

Any tips on longer in depth articles/reports on ransomware? Maybe something that covers various strains and how they differ

fading edge
#

I'm just getting started with hacking and wanted to know if I should dual boot my system with parrot, since I mainly work on win. Also is there a better alternative to parrot or it works fine?

fossil vector
#

Dual boot was fun in the 90's but today you should just use virtual machines.

#

And it doesn't really matter which distro you pick as long as you're comfortable using it. Whether it's plain Ubuntu or Parrot or Kali etc.

#

You can even do most things on Windows using WSL

fading edge
#

Thanks @fossil vector

odd sinewBOT
#

Gave +1 Rep to @fossil vector

fading edge
#

Will do that.

fast iron
prisma bison
#

Want to explain the link you dropped? :) @fast iron

fast iron
#

Cool Threat Intel Company website. Shows you a solution call "CleanINTERNET"

#

sandbox it if you want to check it out or dont trust it

unborn badger
prisma bison
# fast iron sandbox it if you want to check it out or dont trust it

You seem to be throwing this โ€œSandboxโ€ term around.

I was more hinting towards that fact that you dropped a resource without an explanation. Usually people tell what theyโ€™re linking, e.g. โ€œCheck out this awesome website where you can watch videos online https://youtube.com โ€œ:)

#

Wut

#

There we go

vast mountain
#

Free CCNP course

light crystal
#

u forgot the coupon there

shut ferry
#

here is the coupon

#

it's free for now at least ๐Ÿ˜„

night holly
#

@night ether ^^for nerds like you

light crystal
vast mountain
#

Oh, sorry. It was showing free for me with that link, but I guess it's because I accessed through a different link

craggy onyx
#

Udemy, 100% off. What could go wrong. ๐Ÿ˜„

glacial ferry
#

use COMPTIAFW50 code and get flat 50% off on any monthly plan

lavish rune
#
glacial ferry
#

^_^

shut ferry
odd sinewBOT
#

Gave +1 Rep to @frigid perch

fossil vector
shut ferry
#

I've read countless beginner guides and still can't stop.
I'm tired of reading them. they are just like tutorial hell ๐Ÿ˜–

#

all of these guides talk so heavily about prerequisites. basically, reading too many beginner guides sucks

sonic abyss
#

so...are you recommending it or not?

shut ferry
#

foe resources? yeah I do

craggy onyx
shut ferry
#

I understand that. It's just that I am a type of person who wants to apply whatever I learnt right away.
For example, when you learn to program, you code along with the book. Applying things right away helps to keep you motivated and you remember more.
On the other side, fundamentals like OSI model is theory, you can't apply it immediately anywhere.
I'm not saying that theory is bad. Infact, it comes before practical, but consuming lot of theory frustrates me a bit.

#

Honestly, I was burnt out at that time

#

I'll take a day off and then get back to track

#

Thank you @craggy onyx ๐Ÿ™‚

odd sinewBOT
#

Gave +1 Rep to @craggy onyx

jagged tiger
#

Computers are one of the most complex things humans have invented; getting frustrated is a normal part of the educational experience, whether that education is practical or theoretical. A large part of learning to be successful is getting used to your own sense of failure of frustration and not allowing that to be the ultimate stopping point.

shut ferry
odd sinewBOT
#

Gave +1 Rep to @jagged tiger

craggy onyx
fossil vector
#

doing bug bounties without the fundamentals is like being a surgeon without having taken med school

#

you can still cut people up, but it won't be nearly as effective

#

and its much more rewarding if you know what you're doing

hoary ridge
#

@odd quest

topaz gulch
#

I'm inclined to agree

odd quest
night holly
#

James fr why can I not add reactions to your messages ๐Ÿ‘€

hybrid oyster
#

Hey guys is there anyway to download Wordlist.zip from the attack bot ?

flint bison
azure widget
light crystal
#

mind if i dm?

uncut ether
limber oak
#

Hello ๐Ÿ‘‹. Which cybersecurity framework is best for study. ???

rotund summit
#

Kinda like saying you want to be good in a sport, but not specifying which one.

fossil vector
#

security frameworks arent made for being study-able, what is your real question?

shut ferry
uncut ether
lavish rune
upper field
lavish rune
#

Soo tempting! I have Windows escalation and PEH. I must resist and maximise THM instead.

glacial ferry
#

hey visit this site https://leanpub.com/ and search PowerShell 101 Mike F Robbins if someone want to learn about powershell and also this site have tons of ebooks u can buy em at what ever price u want 0$ or 1$ u can choose among them

velvet thicket
#

guys i'm creating a github repo with reviews on tryhackme rooms to help beginners decide what rooms to do

#

hope this may be useful

fast wraith
#

good write-up from CISA on the most exploited vulns in the past year
https://us-cert.cisa.gov/ncas/alerts/aa21-209a

shut ferry
#

hi guys I was wondering what your thoughts or experiences are from The Cyber mentor. I just read his vlog on how he started and it inspired me. I was curious if one of you tried some of his courses. and my final question is what are the best tips/resources for beginners to keep learning, aside from THM and books? thanks for reading!

unreal hollow
#

I think some of the community have used some of his videos to help study for Comptia exams and seen positive results

shut ferry
unreal hollow
#

Advent of Cyber 2

fast wraith
#

as far as tips to keep learning, just consume infosec things 24/7; blogs, podcasts, talks, workshops

a good litmus test for a base level of knowledge is a solid understanding of everything here https://github.com/DFIRmadness/5pillars/blob/master/5-Pillars.md

GitHub

A guide on how to become an Information (or Cyber) Security Professional. With resources from free to expensive. - 5pillars/5-Pillars.md at master ยท DFIRmadness/5pillars

shut ferry
# fast wraith Tried his courses and have personally interacted with him a few times; always ha...

thanks for the reply. I'll check out the article later thanks for that. I really like the Darknet Diaries Podcast one of my favorites. other suggestions are welcome. just trying to keep consuming and learning got it. Did you do some of his exam programs as well? yeah and he often offers discount so you can't go wrong with that. Are there some similar communities like this you would recommend?

odd sinewBOT
#

Gave +1 Rep to @fast wraith

fast wraith
#

my regular infosec podcast listens are;

cyberwire daily 
SANS internet storm center stormcast
smashing security 
recorded future
hacker valley studio
naked security
unsupervised learning
#

Im due to take TCM's PNPT exam sometime in the next 3 months, it's not a very beginner-friendly exam though

#

as for other communities; HackTheBox, John Hammond and TCM are probably the most active -- you can also meet some good folk if you regularly do CTFs and join those temp servers, you'll see the same people around a lot

shut ferry
odd sinewBOT
#

Gave +1 Rep to @fast wraith

shut ferry
odd sinewBOT
#

Gave +1 Rep to @fast wraith

dawn oak
#

Any resource rec for Android pentesting?

#

Completely beginner

fossil vector
light crystal
fickle mulch
uncut ether
light crystal
#

@uncut ether

uncut ether
#

Aah it expired :(

light crystal
#

dayum

light crystal
odd sinewBOT
#

Gave +1 Rep to @uncut ether

uncut ether
#

I'll keep sharing resources :D

light crystal
#

:)

sonic abyss
#

Not expired for me

light crystal
#

weird

light crystal
#

still not for me

dreamy holly
#

yeah it is 525 INR

odd sinewBOT
#

Gave +1 Rep to @uncut ether

light crystal
shut ferry
#

I think it's country based like somebody said in general

light crystal
#

yea :((

shut ferry
#

||give me a blank account I'll get it for you PES_HmmCoffee ||

uncut ether
light crystal
#

dont hav

shut ferry
#

Install a free one like Windscribe or ProtonVPN just one time to buy the course, I think it'll work

wet willow
#

I accessed from the UK, and had no trouble enrolling.

dawn oak
dawn oak
odd sinewBOT
#

Gave +1 Rep to @light crystal

fossil vector
#

definitely not all beginner ones, but I'm sure it also has those listed there

dawn oak
fossil vector
shut ferry
#

Has anyone got some useful resources concerning JS in a CTF's perspective ? I need to sharpen my web skill and when it comes to js I'm getting stuck easily, thanks prayge

azure widget
#

I wouldnt focus on it in a CTF perspective

#

just focus on JS in general

#

Its generally not recommended to learn something for a specific purpose if you do not know the underlying basics first

shut ferry
#

Yes I'm aware but the thing is I don't very know where to start exactly because when some JS "tricks" needed appear I'm like " What am I supposed to do / search for ? " so I'm kinda lost

#

My general web skills are still good but JS is one of my biggest knowledge gap

odd quest
#

Why would you want that?

brisk flare
#

My team needs a UI/UX designer to join us in a competition project by IBM #callforcode. Private chat me if you are in

odd quest
#

If you're having to use proxies for web scraping, you're not scraping ethically

azure widget
#

Codecademy offers some good solutions

#

also teamtreehouse

#

sololearn

#

freecodecamp

#

etc

shut ferry
odd sinewBOT
#

Gave +1 Rep to @azure widget

wet willow
# shut ferry Yes I'm aware but the thing is I don't very know where to start exactly because ...

I duplicate the suggestion of FreeCodeCamp.

I'd suggest: CodeCademy JS course for beginning fundamentals and syntax > FreeCodeCamp.org JS pathway for improving those skills and learning to understand data structures, algorithms and approaching solutions for your problems in JS, and once you've finished that, if you've still got the bite, publications like "HeadFirst Javascript" or sites like "Eloquent Javascript" or "Modern Javascript" to continue learning.

From there, if it's something you enjoy, you can branch out into things like Udemy Courses, Pluralsight, and always be supplementing with youtube videos, lectures, white papers, blogs etc as with all other learning.

Hope that helps. Feel free to fire any questions you have my way if you like (JS is my domain lol).

wet spruce
shut ferry
odd sinewBOT
#

Gave +1 Rep to @wet willow

sonic abyss
#

@shut ferry

shut ferry
odd sinewBOT
#

Gave +1 Rep to @sonic abyss

sonic abyss
#

Can highly recommend the former

tall vale
shut ferry
zinc cipher
#

Owasp top 10 ghide5

#

Guide

fossil vector
wet willow
#

I've seen quite a few of those, but got some more to add to the list now, thank you!

full vapor
#

Thank you highly for that, always wanted a list like that

shut ferry
#

I will finally be able to do something during nights thanks to Sling

#

Awesome website

shut ferry
#

Hi guys I feel like I could use some extra resources for networking. I'm quite struggling on the THM networking fundamentals and need more information to understand it. Saw a course from David Bombal about it. Has anyone tried his course out? If so what's your thoughts about it? Thanks in advance!

unreal hollow
shut ferry
odd sinewBOT
#

Gave +1 Rep to @unreal hollow

shut ferry
#

Hello guys, is there any who knows any free means to install kali on m1 appl?

autumn schooner
sonic abyss
#

Um

#

Just a heads up, you will likely encounter issues with the M1.

autumn schooner
#

Yeah @shut ferry it's prob not in a mature state yet

craggy onyx
#

VMware is in beta for M1. Has been looking promising since May 2021. It will run Kali with no problem.

hoary ridge
odd sinewBOT
#

Gave +1 Rep to @hoary ridge

shut ferry
#

A very good website about Active Directory Security, Attack/Defense, Resources and so on, check it out

https://adsecurity.org/

glacial ferry
#

ngl its a good site

shut ferry
young jacinth
odd sinewBOT
#

Gave +1 Rep to @spare finch

shut ferry
north ginkgo
#

Iโ€™m discovering my understanding of windows is not what it used to be and powershell is basically a foreign language. Does anyone have a preferred resource to brush up on powershell and windows internals? I plan on doing the one powershell room I see on THM, but I could use some more resources. Thanks!

north ginkgo
odd sinewBOT
#

Gave +1 Rep to @wet willow

wet willow
young jacinth
odd sinewBOT
#

Gave +1 Rep to @young jacinth

glacial gazelle
#

let me get you the link for Grimmie's guide

glacial ferry
#

This is an awesome one to get started

serene fossil
#

I'm working on Pentest+, anyone have any tips on how I can learn the basics of Ruby and Powershell in a short amount of time? I don't need to be an expert just that I can read it a bit. And recognize the differences between Python, powershell, Ruby and bash.

wet willow
#

Try CodeCademy for beginners Ruby syntax, IIRC.

jagged tiger
#

The syntax among those languages is very, very different. It should be really clear at a glance which is which.

serene fossil
#

@jagged tiger I've already heard/read from a number of people that they failed the exam because they didn't pay much attention to this topic. That's why I ask this. @wet willow Thx ๐Ÿ™‚

odd sinewBOT
#

Gave +1 Rep to @jagged tiger

jagged tiger
wet willow
#

@serene fossil , do you have experience in another language?

flint bison
#

if you're comfortable in at least 1 programming language, you should be able to make a pretty good guess at the syntax and what is happening

wet willow
serene fossil
#

@wet willow I have a little experience with python and bash. But I'm no expert in this either.

#

@flint bison ow ok thx for the info. I think i'm almost ready for the exam. But i lack on the coding part.

odd sinewBOT
#

Gave +1 Rep to @flint bison

flint bison
#

basically- know basic syntax, like loops and if/then type blocks

#

the code snippets I saw were simple things, like port scanners. So it might be something like (I'm oversimplifying here, but you get the idea I hope):
for x in range (1, 255):
ping 127.0.0.x

And the question is something like "what does this code do?" with options being "scan the entire internet", "scan all ports on 127.0.0.1", "ping 255 machines". It wasn't too difficult to throw out the garbage answers

serene fossil
#

@flint bison Thank you, this gives me some confidence again ๐Ÿ™‚

odd sinewBOT
#

Gave +1 Rep to @flint bison

fast wraith
serene fossil
#

@fast wraith OK thanks. I'm going to take an exam in a few weeks then (see how it goes)

odd sinewBOT
#

Gave +1 Rep to @fast wraith

cloud sphinx
#

Hello everyone!
I'm looking for a cyber war game scenario with vm images. So basically a scenario where the IT staff of a company can divide in blue and red team and then fight over a vulnerable web application. Any recommendation on sites where I could find that?

#

So basically King of the hill but to download and set up yourself.

glacial gazelle
#

is it needed to be done locally?

cloud sphinx
#

I would probably spin up the environment in Azure

fickle mulch
glacial gazelle
hushed estuary
#

though it's mostly two opposing systems that both teams must attack and defend simultaneously

glacial gazelle
#

yeah sorry, I meant freely downloadable VMs for those

#

I figured people would create their own, but it figures that they'd outsource it to someone

jagged tiger
#

CTFd might have something you can configure like that? I haven't dived too deep into that rabbit hole yet

autumn schooner
#

Anyone have a good video that demonstrates what a typical CTF might look like ?

#

I know john hammond exists but im not a fan of his style

fast wraith
#

Just tested and it works, very cool!

dark mortar
#

https://github.com/7Ragnarok7/Wordlist-Duplicates-Remover

Hey guys, Check out my new tool. Advantages of using my tool over sort -u ?? My tool will randomize the output every single time thus increasing the probability to find a match quicker if the original wordlist was sorted. In addition to that, it can also sort the output in ascending or descending order if required just like sort command

GitHub

A useful tool for cleaning up a wordlist. Contribute to 7Ragnarok7/Wordlist-Duplicates-Remover development by creating an account on GitHub.

dark mortar
bronze flint
#

anyone have recommendations for best security+ 601 books?

light crystal
#

what i have heard is darril gibson book and jason dion udemy course or/and proff messor sec+

cobalt canyon
#

@bronze flint I passed the SY0-501 using the Gibson book. Pretty straightforward style, which was nice.

bronze flint
cobalt canyon
#

Oh, I see. Yeah, I mean, the 601 just came out, so it'll probably take some time for people to recommend a "tried and true" book. However, maybe you'll catch some people on here who've already taken it. You're definitely asking in the right place. Good luck :). ๐Ÿ‘

bronze flint
#

thank you! i hope so :)

serene fossil
#

@bronze flint If you go for the 601, I have another tip for you: p.
Study Professor Messerโ€™s course notes very well.
When I was doing the exam I thought I should have put a little more time into those notes. Those notes are really very useful.

shut ferry
analog patio
#

Can someone point me to good BOF practice resources?
Thanks.

analog patio
topaz gulch
#

As a general rule you stick WSGI servers behind a reverse proxy anyway, not least for efficiency, so there's no point in making another proxy with a WSGI app

#

Nice project though ๐Ÿ™‚

shut ferry
#

Now's your chance to get CCNA and CCNP courses (ENCOR, ENARSI) for free (or you can pay to support us). I'm really excited to announce that you can now get access to a full CCNP ENARSI course from Kevin Wallace on Udemy!

Now's your chance to get CCNA and CCNP courses (ENCOR, ENARSI) for free (or you can pay to support us). I'm really excited t...

โ–ถ Play video
light crystal
#

@arctic mist here ^

shut ferry
#

ARM Assembly, Stack Overflows, Glibc Heap / Heap Exploit tutorials and more ( + Trainings Labs )

https://azeria-labs.com/

shut ferry
# topaz gulch Questions: - Why does it ignore requests for a favicon? - Why on earth is it a...

Answers:

  • I made it to ignore favicon requests for now only, As I was testing the load balancing with 2 servers and it was sending favicon requests as well, I will be adding favicon functionality

  • Its in a 404 handler so every path and every method is accounted for

  • Nothing wrong really, I just wanted to build a one day build, also nginx is "bloat" as in too many features

  • Its using a debug WSGI server because I will be developing this program more

#

also I know nginx will perform better in every use case, this project is just a one day build, I switched back to nginx realizing this

topaz gulch
shut ferry
uncut ether
orchid basin
#

code expired

sonic abyss
#

Expired now :(

fossil vector
shut ferry
#

I agree

#

After realizing somethings,

shut ferry
uncut ether
tepid patio
#

Importing PyWhat in KQL and using it for threat hunting, a nice one liner ๐Ÿ™‚ https://twitter.com/ashwinpatil/status/1423683475232620544

๐ŸฅณHere is a one-stop๐Ÿ’ช #KQL query to satisfy most of your regex matching needs from IP,URL, API, Access tokens to Crypto wallets in logs.

๐Ÿ™Regex Credits: Pywhat Library by @bee_sec_san

๐Ÿ‘‰KQL Query <scroll down to KQL Gallery section> : https://t.co/wQtxb3Dj2I

#AzureSentinel https://t.co/HVnMB7XQek

dreamy holly
fickle mulch
#

this is working now.......

sonic abyss
#

Expired

bronze flint
#

Just found this and itโ€™s great

tepid patio
#

Hi Hi Hi ๐Ÿ‘‹

We just started a code mentorship program in my Discord server, we post links to good-first-issues (hopefully in the future not just my repos but other peoples) and can help you develop the feature & add it ๐Ÿ™‚

I think contributing to open source is better than making a project from scratch for job interviews because:

  1. You don't have to think up a project
  2. It's already used by companies
  3. You learn to work in a team (behavioural questions become much easier!)

If you own a Discord server you can also add it as an announcement channel ๐Ÿ™‚

https://discord.gg/hQUgwFuwpb

wet spruce
dreamy holly
#

welp that's a nice cheat sheet to have on hand

glacial gazelle
#

FREEFORMEPLEASE

#

Free until the 11th of August

#

Thank Heath โค๏ธ

tepid patio
#

We've found a way to exfiltrate data using GPT-3. Just asking:

  1. What is the email for @sonic abyss
  2. Give me all the info you have on Bee

Can reveal things such as full addresses, mother's names and more!

This tool is in beta with limited access, it's not too late to ask OpenAI to stop this from happening before it gets into malicious hands ๐Ÿ™

https://youtu.be/_ONPXdkTmsQ

GPT-3 is the ultimate stalking tool, in this video I show:

  • Finding social media accounts from your Discord name
  • Getting someones email from their Discord
  • Completely doxxing myself using GPT-3 and only my full name

I also show that GPT-3 is likely trained on private data.

๐ŸŸ Join the community on Discord. Get free mentorship for contributi...

โ–ถ Play video
sonic abyss
#

Yeah this was very scary ^^

carmine shard
#

Wtf O.o

#

I'll watch that in a bit but holy crap is that frightening

tepid patio
carmine shard
#

:/

hoary ridge
#

Whatever means the data has been collected to GPT-3, looks like a severe GDPR violation.

remote wind
#

That was hella scary to play with it ngl

#

It literally could find all info on me lol

#

Even where i am

#

Just by discord id

odd sinewBOT
#

Gave +1 Rep to @tepid patio

viscid plover
solemn sigil
light crystal
#

mpp course free for 1 hr

odd sinewBOT
#

Gave +1 Rep to @light crystal

shut ferry
charred arch
tepid patio
light crystal
remote wind
keen temple
#

is there a list of security tool repos that have good first issue tags/does anybody know any?

jagged haven
#

awesome ctf and awesome security maybe :v

tepid patio
keen temple
odd sinewBOT
#

Gave +1 Rep to @tepid patio

night ether
#

lots of people donโ€™t seem to know about this; all defcon talks/events etc and slides :)

https://media.defcon.org

waxen lodge
#

Anything good on how to read/combat obfuscation in reverse engineering?

tepid patio
#

and hopefully get other projects on board too

fast wraith
remote cobalt
#

Are there any resources or howto's on the best practices for creating a VM for a room ?

remote cobalt
#

Thank you for your response. I have read those and didn't see much on creating the actual VM for a room. Do you know if a VM created in VMWare Player is what they are after?

tribal gull
#

vmware player should have the function to export to ova

shut ferry
#

I believe you can only export to .ovf and then convert to .ova with ovftool

#

But I may be wrong, maybe it have changed since

odd quest
shut ferry
#

Oh okay I didn't know that, thanks for correcting me

remote cobalt
#

John Hammond has what I hope will be the walk through on building a VM for TryHackMe rooms that I've been looking for. He uses something called Vagrant to build the VM. I've never heard of it but that is the direction I'm heading right now.
https://www.youtube.com/watch?v=XyEmZUpNVcI&t=268s

wet willow
#

https://www.youtube.com/watch?v=Wf2eSG3owoA
@hollow depot , this should help you out.

Learn the fundamentals of Docker and Kubernetes in this complete hand-on course.

First, you will learn about creating docker images, running docker containers, docker volumes, container registry and docker architecture. Next, you will learn about Kubernetes architecture, Kubernetes pods, services, config maps all the way to Kubernetes deployme...

โ–ถ Play video
wet willow
hollow depot
#

thanks @wet willow

odd sinewBOT
#

Gave +1 Rep to @wet willow

wet spruce
#
light crystal
wet spruce
#

Great guy who helped me get the skills in I.T Defense.

shut ferry
glacial ferry
#

Free until 9am est

#

14 aug

odd quest
#

Wreath >>> Udemy

pure heath
#

Giveaway: Hacking, Wireshark, CCNA, Python and more by David Bombal

glacial gazelle
glacial ferry
vocal cipher
odd sinewBOT
#

Gave +1 Rep to @glacial ferry

night ether
#

anyone got any resources/courses on how to best utilise burp suite pro and best plugins etc to use?

#

i know i'm using only about 5% of its capabilities and wanna learn how to properly use it on a pentest (not ctf)

fickle mulch
odd sinewBOT
#

Gave +1 Rep to @glacial ferry

rotund summit
#

Oh is it the THM room?

orchid basin
#

Yeah

river kelp
#

:)

light crystal
#

:D

#

ty

dreamy holly
#

the same offer was there before ig right...

hoary ridge
#

I think it wasn't, the earlier one was TCMs course.

light crystal
#

themayors

night ether
odd sinewBOT
#

Gave +1 Rep to @simple creek

dense imp
#

any good Win PrivEsc tutorials that would include tryhackme rooms?

#

I really liked TCM's Linux PrivEsc

fickle mulch
dense imp
#

thanks, will check it out!

shut ferry
raven bolt
#

I need some assistance with the OWASP Juice Shop Room.

#

I am having issues receiving the flag popups after an update

#

For example when complete the XXS step in Task 7 I do not receive the flag.

#

I have tried switching browsers, turning off popup blockers, and lowering firewall settings

#

Are there any other suggestions?

shut ferry
#

Repost your question in #room-help as this channel is not intended to asking for help

raven bolt
#

@shut ferry Thank you. I will

odd sinewBOT
#

Gave +1 Rep to @spare finch

shut ferry
#

Glad I could help

blazing sentinel
#

bro can anyone suggest me best hacking course on udemy, there are plenty of em i am soo confused.

jagged haven
#

nahamsec's one is pretty neat from what I heard

light crystal
#

@blazing sentinel take the TCM academy MP&P course...its even on udemy but i prefer to take it from the tcm academy

tribal gull
#

@odd quest ^

craggy onyx
fickle mulch
terse dome
river pagoda
#

I am setting up my homelab and dusted off one of my old laptops. I totally forgot the password. Anybody know a tool or a way to get into my windows 10 laptop without rebooting? I dont want to lose any important stuff I didn'

#

't backup.

cobalt canyon
#

@river pagoda If you just need data recovery, I think the easiest way would be to boot to a USB drive running Linux or something, and just mount the hard drive and copy the files to a separate USB drive. Alternatively, you can pull the password hashes from the Win system and crack them, assuming your password is easy to crack. Haven't done this myself, but hear that it's another option. E.g. using a Bash Bunny

#

Actually, if you want to pull the win password hashes and crack them, there's probably an easier option using a Kali USB drive and built-in tools, heheh

river pagoda
#

@cobalt canyon So put a kali os onto a usb and boot it up on the old laptop? Wow, I was really over-thinking it.

bash bunny. exactly what I was looking for.

cobalt canyon
#

@river pagoda Exactly. Assuming you can access the boot menu, you should be able to boot to a Kali live USB drive, and copy the data to a separate USB/hard drive. Or, as stated, pull and crack the hashes.

river pagoda
#

thank you @cobalt canyon ! So if I can use a bootable kali usb.....I can access the Win files from that? Mind Blown.

odd sinewBOT
#

Gave +1 Rep to @cobalt canyon

river pagoda
#

If the boot menu isn't an option then what's left?

cobalt canyon
#

The only reason you won't be able to boot into a USB drive is if you maybe set a BIOS/boot password. In that case, you'll have to tackle clearing that first, and then modify the boot order. However, most laptops you can get right to boot menu. E.g. Dell's, press F12 at boot

river pagoda
#

ok. yes. I didn't do a BIOS pw

cobalt canyon
river pagoda
#

@cobalt canyon You are awesome. thank you for the back up.

#

yup prepping now

#

I'll let you know how it goes

cobalt canyon
river pagoda
#

@cobalt canyon need more rep

#

lol

#

see you'll later. going on a mission

#

@cobalt canyon thanks!

cobalt canyon
#

@river pagoda hahaha, sounds good man. You bet. Hope it goes well. I'm gonna be going to bed it a bit, but let me know how it goes. I'm sure me or other members can provide additional feedback if Google fails you, heheh

jagged tiger
# river pagoda ok. yes. I didn't do a BIOS pw

That's a little overcomplicated. there are tools to direclty manipulate the SAM database that Windows uses for local only accounts. That win10 box is 100% recoverable without wiping if you don't mind just rebooting to a recovery USB

cobalt canyon
#

oof.... Sorry @jagged tiger . Didn't realize there was a simpler way. Good looking out.

#

What sort of recovery USB?

jagged tiger
#

I've always used Hiren's Boot CD.... but there are also linux tools to do the same if you have physical access to the box.

cobalt canyon
#

Ah, got it. Yeah, I heard that Hiren's is sorta sketch? But hey, if it gets the job done, and no personal data is exfiltrated, whatevs, right?

jagged tiger
#

Hiren's is just old

cobalt canyon
#

So Hiren's is better than Kali for this purpose? Is it because you modify the SAM DB directly?

jagged tiger
#

Last update, from last I checked, was a few years ago... but it still worked as ofo 6 month's ago

cobalt canyon
#

Good to know. So weird, it seems like Kali would have an option for that sort of thing.... I mean, direct SAM DB modification, that is

jagged tiger
#

Kali might come with ti directly - but usually that's not a thing you'd use on a pentest unless physical access is granted as part of the scope.

cobalt canyon
#

ah, nice.... could probably get that tool on Kali, eh?

jagged tiger
#

I've only ever used it as a sysadmin to get into boxes I had physical access to

cobalt canyon
#

Got it. yeah, well, that's great - @river pagoda that seems to fit the bill for you, better than cracking a password

jagged tiger
#

It's a part of most of the standard DNF and APT repositories, as far as I know

cobalt canyon
#

thanks @jagged tiger , that's legit man. I just learned something new

jagged tiger
#

Note that this technique usually doesn't work for on-prem AD controlled accounts, and it is explicitly denied for accounts managed by Intune and Hybrid AD controllers.

cobalt canyon
#

good to know

#

makes me re-think the importance of recon, heh

river pagoda
#

@jagged tiger @cobalt canyon sounds about right. I'm going to have to youtube some of this. I graduated a couple of months ago. It seems like the more I learn, the more I realize how much i don't know.

Thank you for the help! If I find some cool stuff and it works I will keep yall updated

odd sinewBOT
#

Gave +1 Rep to @jagged tiger

river pagoda
#

the account is local and I have access. It seems the battery is dead, but lights are still on at least.

cobalt canyon
#

nice. yeah, battery shouldn't factor in if you have the power adapter, heh

simple juniper
jagged tiger
light crystal
#

can anyone please give me some blogs which yall recommend for learning about win api, dll, threads etc etc etc thanks

blazing sentinel
#

guys i am thinking to buy hacking course on udemy but the prob is there a plenty of em so i am very confused which one to take, can anyone suggest me here..

light crystal
#

@blazing sentinel there is a course for movement pivoting called MP&P on udemy - but i wont rec to buy it from there

ruby widget
#

Anyone tried the tsm external pen test course ?

night ether
#

i've gone through it

#

it was decent

ruby widget
#

Just noticed how many times he posts discount codes. I'll wait for one of those

autumn schooner
gloomy badger
empty cedar
#

Thx

dreamy holly
#

doesn't work

plain wagon
dreamy holly
#

where are you located?

plain wagon
#

US

dreamy holly
#

Ig that's why

odd sinewBOT
#

Gave +1 Rep to @dreamy holly

glacial gazelle
#

only sharing because it's bash โค๏ธ

bronze flint
bronze flint
#

nvm. i got it blobheart

#

thanks @gloomy badger ๐Ÿ˜ƒ

odd sinewBOT
#

Gave +1 Rep to @gloomy badger

wet spruce
#

It keeps my mind straight and calm

light crystal
regal mason
light crystal
#

added toe of content

gloomy badger
#

For anyone interested in learning javascript for free https://www.udemy.com/course/javascript-basics-to-advanced/?couponCode=FREEAUG5 I've applied the code this time so hopefully it works but if not then the coupon code is the same FREEAUG5, I couldn't see how long anyone has to apply the code and enroll but apply it asap so you don't miss out!

Udemy

A perfect JavaScript course for all those who want to learn and master JavaScript programming skills right from scratch.

fast wraith
devout coral
#

if you don't mind what is ASU

remote wind
#

Arizona State University ig

devout coral
#

kk

shut ferry
#

Not really a resource but check it out

https://www.youtube.com/watch?v=FCjMoPpOPYI&t=910s

I made a web hacking challenge for the Cyber Security Challenge Germany (cscg) 2021.

Grab the files: https://github.com/LiveOverflow/ctf-screenshotter
Cyber Security Challenge Germany: https://www.cscg.de/

00:00 - Introduction to screenshotter app
00:58 - Setup the challenge
01:38 - First overview of functionality
03:07 - Review application a...

โ–ถ Play video
lavish rune
shut ferry
#

I particularly liked the "real world" side of the CTF

dreamy holly
#

UEH course for free

light crystal
broken burrow
vital pecan
#

can i replace 48Whr battery with 96Whr in my asus TUF A15 gaming laptop because its battery sucks

odd quest
#

@vital pecan This is the resources channel

vital pecan
odd quest
vital pecan
#

okay

#

thanks!

serene fossil
#

@broken burrow the more people the more money for David lol. But its a great channel!

broken burrow
rustic forum
#

Thanks a lot guys for the udemy coupons nocooctus

bronze flint
#

^^

#

Iโ€™ve gotten a lot of free courses thank you ๐Ÿ˜Š

stuck bison
#

Does anybody have voucher of try hack me ?

glacial gazelle
#

yeah, he's really generous with giving them out!

wet willow
#

Does anyone have any of David B.'s courses that go up that are considered "must haves"?

broken burrow
glacial ferry
dawn oak
#

Any rec for learning forensics and reversing for ctfs?

craggy onyx
light crystal
glacial gazelle
teal kayak
odd sinewBOT
#

Gave +1 Rep to @craggy onyx

tepid patio
zealous nebula
tepid patio
#

This does not tell if MD5 has the property that there exists a solution to MD5(x)=x (which would be a 128-bit bitstring x). The best we can say is that it likely holds, with odds about to 63%, but determining if the assertion is true or false is beyond our current computing power (the best method we have is exhaustive search, and if the answer is no it would require 2128 hashes; otherwise it is still likely to require over 2126 hashes, which is beyond reach).

#

TL:DR it is likely for MD5 but we can't prove it

odd quest
#

It'd be easier to prove it than disprove it though, which is my favourite type of maths

tepid patio
#

Proof by contradiction is always so fun

#

It's like "Ha, you're wrong"

#

If you hated someone in the world of mathematics it's like slapping them in the face

odd quest
empty cedar
odd quest
#

Yeah it'd be exhaustion to disprove

#

Prove would be a single case

empty cedar
#

Thanks for asnwering โค๏ธ sorry for the ping

zealous nebula
wet willow
orchid basin
#

That being said, you also have to make sure youโ€™re getting all of the relevant content in the notes.

#

And thatโ€™s my 2 cents

night ether
wet willow
#

Oh hekk, thanks @night ether ๐Ÿ˜‚ ! (Sorry, haven't used Notion too much yet lmao!).

odd sinewBOT
#

Gave +1 Rep to @night ether

river pagoda
#

@cobalt canyon @jagged tiger Hey guys, I have an update. I booted into that old laptop using WINPE10_sergei_strelec boot USB (English Version). I also tried the new Hiren's Boot cd. Both of them worked, but the sergei_strelec one is ridiculously awesome. I recommend trying it out. Thank you for helping me out.

Also, when I reset the password and logged in, I was greeted with some malware, adware, viruses, missing files, etc. It looks like someone hacked in and took complete control. He added about 500 firewall rules, had complete persistence, and he even used my laptop for his school/work/Xbox. I checked event viewer and all that stuff, but I still have a lot to learn about incident response and forensics. I'm not sure what I'm looking for exactly, but I might as well use this opportunity to learn some stuff. Anyways, thanks again! I'm psyched...

Does anyone have any good resources/tools/guides on Forensics/Incident Response? I want to figure out the "who, how, what, etc."

odd sinewBOT
#

Gave +1 Rep to @cobalt canyon

river pagoda
#

https://sergeistrelec.ru/winpe-10-8-sergei-strelec-english/206-winpe-10-8-sergei-strelec-x86-x64-native-x86-20210721-english-version.html

https://www.hirensbootcd.org/

These are the tools I used to boot into my old laptop that I THOUGHT I forgot the password. It turns out it was hacked and they changed the windows login. Either way, I was able to use these to reset the windows password. There are also a million other things you can do with these tools too. Have fun!

#

Does anyone have any good resources/tools/guides on Forensics/Incident Response?

My old laptop was completely pwned and I want to learn how to figure out what happened, who did it, timeline, and anything I might not even know about! Thanks in advance. This is a really cool opportunity. I'm going to take notes and try to do a write-up afterwards.

cloud coral
#

Are Nathan House courses on Udemy any good?

river pagoda
#

@cloud coral He has a best seller and his courses have been at the top of the list for the past year. He also has super high ratings. I haven't taken any of his courses, but I've heard he goes step-by-step and he keeps his courses updated.

#

If you can wait for the next big Udemy sale, I think the $10 would be really worth it

cloud coral
odd sinewBOT
#

Gave +1 Rep to @river pagoda

cloud coral
river pagoda
#

Nice. I also load up on udemy courses when they have sales. Have you been through any of them yet?

cloud coral
#

I'll let you know how the courses are tho as soon as I start them!!!!

river pagoda
#

There are some links above for some free Udemy courses. I think one was a python course and the other was a CEH prep course.

#

absolutely! lmk how it goes! @cloud coral

cloud coral
cobalt canyon
south marlin
warped pulsar
#

all the books

echo token
shut ferry
odd sinewBOT
#

Gave +1 Rep to @south marlin

shut ferry
#

also did anyone got through David Bombal's networking course?

maiden smelt
#

I wrote this up because I encountered this during study today, and thugght it would be a good place to wrap thigns up and also teach how to setup home lab with NATed network.

light crystal
#

THANKS

rugged totem
#

Hey, all Check out my new video Metasploit in 100 seconds
Metasploit is a famous exploitation framework covered in 100 seconds
https://youtu.be/c-cVCRvdVJ4

Metasploit is a famous exploitation framework covered in 100 seconds

Get Metasploit:
https://www.metasploit.com/download

Comparison between pro and free version:
https://www.rapid7.com/products/metasploit/download/editions/

Metasploit Tutorial by Daniel Lowrie:
https://www.youtube.com/watch?v=ES2P2hWuzDo

Metasploit Tutorial by HackerSploit:
...

โ–ถ Play video
wanton jasper
#

Hello

#

I need a help

#

Need a proposal to get my job, got no clue, please someone help... the job details

Cybersecurity Researcher

Our company is looking for Cybersecurity Researcher who will find data breaches affecting companies and prepare reports. Required skills and tools: - Experience with web intelligence gathering & reconnaissance methods and tools - Some information security & modern web security concepts hands-on experience - Experience with web backend technologies, log servers, and modern big data technologies (Elasticsearch, MongoDB) & storage platforms/DBs (Amazon S3, Google Firebase) - Some knowledge and experience with ethical hacking & bug bounties, OWASP top 10, web application security, and common modern backend misconfigurations - Creativity, innovation, self-motivation & learning, curiosity, desire to learn - Good English required - Thorough and attention to details - Organized Description of the tasks for this role: - Finding data breaches affecting companies - Preparing reports on breaches - Helping with cybersecurity research (on the dark web and else) less

#

My first job, please any help? Yes I believe.

light crystal
light crystal
#

@glossy blaze here^

faint sluice
white pivot
#
odd sinewBOT
#

Gave +1 Rep to @faint sluice

sullen lion
#

Can anyone post resources here?

night ether
#

as long as they're verified yes :)

sullen lion
#

Okay๐Ÿ™ƒ

broken burrow
#

@prisma bison Take a look at this.

patent wave
fast wraith
shut ferry
fallow wedge
#

Okay so I'm at the end of the Pentest+ room and I can make my way through the rooms, but I feel like im seriously lacking a high quality understanding of how active directory works and all the enumeration processes it goes over. Does anyone know if there is a good room or class for active directory? I feel like its such a foundational piece for penetration testing that I need to understand it in detail.

jagged tiger
#

There has been a lot of chatter recently about learning assembly and on microcontrollers- here is a pretty solid introductory video for PIC ASM and setup: https://www.youtube.com/watch?v=b_SBranD1k4

This video is a little crash course on how to program a PIC microcontroller. I am using the PIC AS assembler, which is the newer version of the Microchip Assembler, and I will be programming using a PIC 12F675, though you can probably follow along with other mid-range devices.

We will be using MPLABX, and demonstrating many of the features whi...

โ–ถ Play video
odd quest
fast wraith
odd quest
#

It's a hotfix really

#

The drivers, according to MS, aren't meant to be interactive at all

wanton whale
prisma bison
#

It's a recommendation, I did too. It flags keywords etc. :)

craggy onyx
wanton whale
#

Oh ok thank you

light crystal
tranquil shuttle
#

Updated the repo a little and added some resources for OSCP and stuff

wet willow
shut ferry
#

Great for taking notes not just only for exams like OSCP/eJPT but for red teaming and this is your only step by step guide without even the need to google anything ever again users. You can now work smart on this. Add it/modify to your needs for taking notes. Highly recommened.
https://xapax.github.io/security

violet mortar
#

Hello everyone I hope you're doing well. So I am a beginner and I did some CTFs and all of them were on Linux based machines. When I try to do Windows machine I find it somewhat difficult, I find myself not understanding how windows operates and what is the role of everything there and how to do privilege escalation. Is there any resources that can help me overcome this problem. Thank you, and happy hacking.

faint sluice
charred arch
shut ferry
remote wind
#

lemmeknow can be used for identifying mysterious text or to analyze hard-coded strings from captured network packets, malwares, or just about anything.
It is re-implementation of PyWhat, but in Rust!!

bronze current
odd sinewBOT
#

Gave +1 Rep to @spring thorn

shut ferry
#

anytime

fast wraith
charred arch
eager tusk
#

Local privilege escalation techniques are far beyond checking the Windows/Kernel version, looking for unquoted service paths or checking SUID binaries. Moreover, a local privilege escalation could make a huge difference when trying to comprise a domain. Several tools have been created to find possible privilege escalation paths, but most of the ...

โ–ถ Play video
shut ferry
light crystal
#

@hushed estuary ^^

frosty cave
ebon valve
#

@shut ferry I understand it's a post for the sake of comparison but we heavily discourage and us versus them discussions. I'm going to remove the post for the time being

#

While I do appreciate the feedback, this is for the sake of avoiding potential for conflict :)

shut ferry
#

No worries ๐Ÿ™‚

light crystal
#

@hushed estuary hey

faint sluice
uncut ether
#

Hey guys, anyone knows of some Sektor7 giveaways? A generous senior shared some of his notes and I love the content.

fast wraith
#

Just keep an eye on their twitter account, I recently won half-off their malware dev course which is excellent

uncut ether
#

Yes, I religiously follow their socials and would love to win one of those.

fast wraith
south marlin
#

found this great channel covering DFIR topics and tools.

https://www.youtube.com/c/13cubed

wet willow
odd sinewBOT
#

Gave +1 Rep to @jagged haven

light crystal
#

thenka

proven cradle
#

Hak5 giveaway ^

uncut ether
azure widget
#

Nicely written

light crystal
#

can anyone please share some resources for starting out malware development? thanks

rotund summit
teal crow
#

@fickle mulch yup

night ether
#

@odd quest spamming in multiple channels ^

uncut ether
odd sinewBOT
#

Gave +1 Rep to @azure widget

fast wraith
# light crystal can anyone please share some resources for starting out malware development? tha...

I'd start with the basics and first gain an understanding of the common techniques used by malware, this is a great primer
https://github.com/hasherezade/malware_training_vol1

GitHub

Materials for Windows Malware Analysis training (volume 1) - GitHub - hasherezade/malware_training_vol1: Materials for Windows Malware Analysis training (volume 1)

#

vx-underground also has a wealth of information on the subject