#resources
1 messages · Page 14 of 1
Gave +1 Rep to @fast wraith
Offensive Software Exploitation Course
Reverse malware first, develop second
hiya all. just starting the thm. running non-kali linux locally. recommendations on installing tooling locally or creating a dedicated kali instance to do all the things from?
Now why would you want to do a thing like that? 👀
learnin? am not gonna do anythin bad..
sus
:(
There are precisely no legitimate uses for malware if you're not a professional redteamer developing tooling, and even then that's a very specific class of malicious software developed by professionals for use in authorised situations.
It's something that can be discussed in #exploit-and-mal-studies, but nowhere else in here.
oh, i understand ur worry..sorry..just a interest for learnin. am never gonna do anything bad with it.. and for the channel, sure sorry again
So no one can write some malware to gain experience on actually implementing injection/hooking/evasion techniques, so if that person does land a red team job in the future, they can have experience in offensive tooling and be of more value? Plus, u can build more knowledge on actually using the msdn docs for various api functions used in different classes of malware. Their is more to just reading what the api functions does. If u can actually re implement a specific technique using the api docs, and some googling, then thats more valuable knowledge for yourself and a job in red team or security research down the line.
You can do whatever you like -- you just can't talk about it in here 🤷♂️
Be aware though: it's illegal to develop malicious software in many jurisdictions -- even without intent to distribute or deploy.
Sooooooo, you had better have a bloody good reason for it if anyone comes calling
Your best bet is to look into building offensive tooling rather than traditional malware -- then you have a plausible reason if you are a student, in industry, or looking to enter industry. Regardless though, if you're discussing it in this server, it goes into the specific channel that we have set up for it. There are way too many malicious skiddies around for us to have the liability of y'all discussing it publicly.
Correct. Nothing wrong with what you stated on the legal side of things. Just feel like when diving into a particular subject in cyber besides grc, if u aren’t actually doing any hands on and re implementing techniques for learning purposes, then how does one actually understand the subject matter come a real engagement
Their is a channel for this topic here?
#exploit-and-mal-studies -- it's restricted under a few different roles (0xD, Throwback, OSCP, eCPPT, and a few other of the entry level certs).
requesting if anyone has a sane and practical implementation of zettelkasten in Obsidian - I've read the top articles that come up in Google and watched Obsidian's video on the subject but it's still a bit confusing
Confused regarding? Zettelkasten or obsidian?
zettelkasten, obsidian is easy enough to understand
Zettelkasten is ez too, if you prefer book, i would suggest How to Take Smart Notes: One Simple Technique to Boost Writing, Learning and Thinking – for Students, Academics and Nonfiction Book Writers
Or just watch/read summary of it. It isn't specifically for obsidian, but it's core is zattelkasten method
I would recommend it
Bypass defender with Powershell? Run the same payload twice, yeah, you did read that correctly. Watch. 🙃 https://t.co/CaxnJYeJHy https://t.co/i8S6ByJ4vn
246
754
thanks!
omg the lols of that type of a failure
I wouldn't worry about it- organizing your notes in a tree structure is basically the same thing. Only more sane to manage.
true, its starting to get a little annoying having huge tree structures to scroll through, esp since some structures are like 5 folders deep
and now I'm in the process of centralizing all of my notes from various cherrytree DBs and multiple Obsidian vaults, figured I could try something different
I've had good luck using Trilium - as much as I loathe JS and Electron apps, it does have most of the features I want when taking notes
Could I get the OSCP role? I got mine about a week ago but I didn’t realize it would also give access to another channel, so I didn’t bother asking for the role. I’d be happy to DM proof 😊
I'll trust ya. Congrats 🙂
Thank you! 😄
Does anyone have good list of burpsuite (pro included) extensions used in CTF and bugbounty context?
#room-hints or #room-help are more likely to help you then here and also specifying what room and task you are on will help too
i don't think they're asking for help with a room, just in general to help them when doing any room/bb
maybe ask in #bug-bounty ? I think most people use burpsuite free or owasp zap
Alright!
Yup
@hushed estuary ⬆️ scam link
¯_(ツ)_/¯
@prisma bison could you delete the message in here??? and the other places it is in???
To track state-sponsored malware and combat the stalkerware of abusive partners, you need tools. Safe, reliable, and fast tools. That’s why EFF’s Threat Lab is proud to announce our very own tool to download Android APK files, apkeep. This enables users to download an Android APK or number of APKs...
https://www.trustedsec.com/blog/obsidian-taming-a-collective-consciousness/?hss_channel=tw-403811306
Anyone knows about an academic paper about web hacking/security??
With a credible author
Is this for an assignment?
Yes
Are you sure it wouldn't be cheating if we gave you some?
Try searching with Google Scholar or asking for help at your school/college/university library
Wait is that cheating?
What about names of the authors
Would that be considered as cheating?
Also every time google scholar I get like pdf where I have to buy them
Some academic journals do require buy-in; if you connect to google scholar through your university wifi or vpn, you should have access to those.
Oh alright thank you
Hey guys. I threw together a small nmap tutorial/cheatsheet. It might be useful if you're going through the Furthernmap room. It covers basic switches, scripting and scanning types. Hope this helps
Thats very nice, thanks!
Gave +1 Rep to @boreal ermine
Thank you sm
Gave +1 Rep to @boreal ermine
https://owasp.org/Top10/ for a bit more context (Still in draft for now)
OWASP Top 10:2021 (DRAFT)
I like these changes
I didn't see that link earlier thank y0u
Gave +1 Rep to @hushed estuary
Bot too strong 
haha
it tkes the word thank
Any blog/article for note taking tips? I am kinda new to reports and notes so it would be helpful.
Tried finding but haven't caught something useful yet
@odd quest ^
it takes trial and error to find a method that works for you, I recently integrated Zettelkasten into my note-taking which has been pretty handy
the biggest take-away for me is that you just need to write things down, have a daily note that you just always have open, end of the day pull out important bits you like and see how you can file and categorize those important bits
Yeah
Thats one hard part of it
Regularly updating them and categorizing them frequently and efficiently
@spiral zodiac Muir deleted it because "it's an n-day vuln -- we probably shouldn't be directly advertising code for it".
If something is deleted, probably best not to repost it?
Oh it was muir he could have told me smh, but okay I understand why it was deleted 
Yeah, sorry, did it on mobile in a hurry ♥️
Last week's Metasploit wrap-up includes an exploit for Confluence Server CVE-2021-26084 and loads of fixes and quality of life improvements. Get it: https://t.co/RQIzUB2Ac9
I try this tool it require python 3.8 or later
Upgrade your shell automatically. It sounds interesting.
AD Pentest Mindmap - by Mayfly
AD Pentest mindmap upgrade :
Full version: https://t.co/hE0VKO5b2I
xmind version (slow, the map is big) :
https://t.co/D3Dck14tiq
Fell free to tell me what is missing !
150
314
solid explanation of AXFR
https://cr.yp.to/djbdns/axfr-notes.html
Upgrade shell??
Found something interesting from a IT news website.
It's a leak of a Ransomware group affiliate who was let's say not very happy and fed up by them, so he leaked there total playbook.
It's kinda interesting to see how a group access and pivots through the network, exfiltrates data, and many more.
It's also interesting for understanding Attacks against AD, Kerberoasting, and many more.
The catch is, its purely on Russian, so a tool like Deepl can come in handy if needed.
//It's purely for educational purposes only//.
Link to the documents:
https://github.com/ForbiddenProgrammer/conti-pentester-guide-leak
I hope it's not against the Server rules, to link this resource.
-R1ot
I assume he means make it interactive and stable.
oh like an automatic python -c bin bash thing??
Time 2 update 
I think so? Haven't tested it.
This is great read https://kerkour.com/blog/shellcode-in-rust/
A few months ago, we saw how to execute a shellcode from memory in Rust. What if we could write the actual shellcode in Rust?
Writing shellcodes is usually done directly in assembly. It gives you absolute control over what you are crafting, however, it comes with many, many drawbacks:
It requires a lot of deep knowledge that is not transferable...
AWSome Day Online Conference is a free, one-day cloud training delivered by AWS
https://aws.amazon.com/events/awsome-day/awsome-day-online/?trkCampaign=awsome-day-online&trk=
Register (before 30 Sep) to participate if you like 🙂
AWSome Day Online Conference is a free, online training event that provides a step-by-step introduction to the core AWS services for compute, storage, database, and networking. AWS technical experts will explain key features and use cases, share best practices, walk through technical demos, and be available to answer your questions one-on-one.
[Replying to the now deleted message] I believe this is a scam going around the cybersec discords recently
It's everywhere
I hope it's not another academic project gone wrong like that one uni injecting crafted fake vulnerabilities to the linux kernel github repo to test the effectiveness of open source code audit practices.
maybe you should be clear that AWS is not the scam 🙂
Oops 😂
no its ok, just wanted to make sure others knew the AWS is a valid link and not a scam
oh definitely
-.-
^
If you want to get into the growing field of cyber security and ethical hacking, you are going to need to understand how to use Linux. We just released a free course on the freeCodeCamp.org YouTube channel that will teach you all the common Linux skills used in cyber-security
👍
https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html
https://docs.microsoft.com/en-us/windows/win32/bits/background-intelligent-transfer-service-portal
How attackers use the Background Intelligent Transfer Service (BITS), techniques for detecting attacker activity, and the public release of our BitParser tool.
Download Eric Zimmerman's EZTools DFIR Tools
Can I get any Networking related stuff here
Hey any resources about Threat Intelligence infrastructure ?
great bash shell reference guide
https://github.com/jlevy/the-art-of-command-line
Nim for offensive security For a while now I have been playing with the programming language Nim in the context of Offensive Security. Nim is a relatively young and fairly unknown programming language that has a syntax quite similar to Python’s, so is very easy to pick up. It however offers the flexibility and low-level capabilities of languages...
^ good article, the author is one of my friends
https://www.makeuseof.com/how-to-learn-python-for-free/ has some useful links to free courses.
Also i found this pretty useful too https://danielmiessler.com/blog/build-successful-infosec-career/
a sane way to grep through code!
https://github.com/returntocorp/semgrep
What are your favorite SQL injection tools/scripts/etc. ?
Last update: July 10th, 2021
Updated June 5th, 2021: I have made some more changes to this post based on (among others) techniques discussed in ZeroPointSecurity’s ‘Red Team Ops’ course (for the CRTO certification). I’ve re-written and improved many sections. New sections have been added on DPAPI and GPO abuse. Notable changes have been made to ...
Should introduce me, I'm a fan 🙂
Hello
You are from Pakistan?
University of Helsinki DevOps with Docker course.
Thanks a bunch for sharing, Freddie! I missed it last time.
Gave +1 Rep to @glacial gazelle
Made an awesome thread to explain all the essentials tools in a simple way.
#cybersecurity #infosec #oscp
Inspirations/ Mentors: @theXSSrat @_JohnHammond @davidbombal @offsectraining @InsiderPhD @0xTib3rius @RealTryHackMe @hackthebox_eu @BlackHatEvents @BHinfoSecurity
@odd quest ^
I don't want to be rude but there isn't much of a guide in that blog post.
An Extensive Repository for Free Resource on Cybersecurity, Hacking, BugBounty, Certifications, and much more!
To all my fellow Infosec old farts, what’s one piece of advice you would give yourself during your first week of your first Infosec job?
thnks
Ive written some random thing, If some kind soul reviews it Ill be grateful
https://hamzawinix.com/zathura_in_wsl/
yoh, I use it on linux, pog :v. Its the best pdf viewer imo
so what do u think I got right and what did I get wrong in the article ?
is there something you would change ?
its pretty straight forward, altho the assumption of VcXsrv being installed is bold its understandable, some people might be wondering about why you export DISPLAY on the zathurarc but I think people who want zathura on their linux are aware of why cuz they worked with zathura previously. another note is the set sandbox none, I would explain a bit better, for the rest it seems a cool walkthrough for a problem I didnt know there was an answer
Thx for the feedback @jagged haven
thank you for the article 
Gave +1 Rep to @last wolf
Dirk-jan Mollema - Breaking Azure AD joined endpoints in zero-trust environments
How much trust is zero trust anyway? As more security controls are added to protect cloud accounts, much of that trust ends up on a users endpoint, where long-term credentials are stored which comply with strict security policies, such as Multi Factor Authenticatio...
@hushed estuary
hmm
Likely not around at 3 am
Hey guys, I've been enjoying writing while I study this PEH course, and thought my notes may be useful to others. I've written my own version of the teaching, not verbatim, in case that worries anyone!
Critiques and comments always welcome too 🙂
https://heavenly-nape-4b6.notion.site/Practical-Ethical-Hacking-The-Cyber-Mentor-Udemy-Course-02b07014b6eb4695bbcd3b423f7e5325
that is nice!
https://github.com/taielab/awesome-hacking-lists
Big archive of applications.. Uhh... nothing else to say, it takes like 1 minute to scroll all the way down
@cobalt lily
https://github.com/hasherezade/malware_training_vol1
👍
"The course is accessible for FREE right now on UDEMY with the code "LLS10K" as a part of the fundraiser I'm doing with them. If you have ever wanted to donate to me, buy me coffee/food, or just support me, please take the time to donate it to LLS instead! https://pages.lls.org/ltn/sac/sacr21/BSadeghipour"
Freddie coming in clutch.
At this point, I've never bought a course on Udemy but my library is packed.
https://jc01.ninja/pwdump/
Hate messing with meterpreter hashdumps or impacket secretsdump pwdump format? Try this
Spits out a hashdump that's ready for John to use immediately, or hashcat to use with the --user option
Homepage for NinjaJc01, CTFs, projects and cool things.
Bad.
It's all clientside but it's not very robust
A (hopefully) actively maintained activity-based-autosorted list of InfoSec Streamers
Hello Toaster
Can you also add the mode for JTR/Hashcat? Or the command itself so user can just copy paste?
No, I cannot
Because I don't want to add fields to enter wordlists and hashfile locations and stuff like that
Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices (implemented as containers), supported by code for providing application services called service mesh. Both of these components are hosted on a container orchestration and resource management platform, wh...
hey :) give #start-here a read through to help you get started
ESET's T2 Threat Report
https://www.welivesecurity.com/2021/09/30/eset-threat-report-t22021/
Hey, have any of you guys taken the Cisco course about networking? If so, is it worth it?
An Extensive Repository for Free Resource on Cybersecurity, Hacking, BugBounty, Certifications, and much more!
@raw ice i have went through all of the old CCNA/CCNP/CCIE RS track and I can say that professionally it will open a ton of doors, however, for cyber security IMHO you will not get much value past the CCNP level certs. The OSCP and CISSP is going to get you past the HR gatekeepers at that point.
XXE Valid use case This is a nonmalicious example of how external entities are used: <?xml version="1.0" standalone="no" ?> <!DOCTYPE copyright [ <!ELEMENT copyright (#PCDATA)> <!ENTITY c SYSTEM "http://www.xmlwriter.net/copyright.xml"> ]> <
Security Idiots is a place where some insane idiots try thier hands on with Security.
can i dm @tepid patio ?
ok 🙂
How to configure burp suite with tor for better anonymity
https://youtu.be/uGyKfeJBDbw
In this video i have shown how to configure BurpSuite with Firefox Browser, and how to configure BurpSuite with Tor service.
Link to download Burp Suite:
https://portswigger.net/burp/releases/professional-community-2021-8-4?requestededition=community
I do not claim the ownership of the track used in this video.
All rights belongs to the ow...
@next marlin Hey Man 🙂 Not seen you here before 🙂
are you a ccie or did you just go through the training?
@night ether held CCIE RS until it changed to EI in 2020 working on getting my collaboration to re-up.
daaaamn huge brain gg
Nah huge brain would of reupped before covid hit and testing became a PITA
CCIE when?
my dumbass can't even do ccnp yet
CCNP big brain
I keep trying to do CCNA with Mike Andersons course but get bored after a video or 2 
@night ether CCNP isn’t that bad, the TS exam is so so good at learning the material you need. If you can identify what’s broken and how to fix it you are we well on your way to passing the rest.
gotta use jeremy and keith
ah i'm gonna be doing security, not enterprise
don't do networking anymore so don't see the need of going any further than ccna r&s
Makes sense.
@night ether from what my colleagues have told me you will get a ton more mileage out of OSCP or CISSP unless you are trying to pigeon hole into Cisco security
yeah i'm doing oscp too (already failed once but will try again soon 🤪 ) - i just really like the cisco side of things
as well as the guys the write the official study guides for ccna/ccnp, the content and the way they phrase it is sooooo good
Nice! Good luck my friend!
I just started down the OSCP path been working on proving grounds and THM. PG was a bit too hard for me starting out, THM fit that middle e ground nicely.
who dey?
awesome :) are you planning on shifting into security? or do you just like it as a hobby? (also let's continue in #infosec-general to stop flooding the #resources channel)
from cbt nuggets; jeremy cioara and keith barker
hmm okay I look, thanks 😄
I have the CCNA R&S, yes this one adds a lot of value as it will give you a solid networking foundation
CCNP and CCIE are overkill unless you want to focus on network security
On a side note, the CCIE is currently free if you have the brains for that.
Hold up. I'll link it.
Heard it first from David Bombal.
https://learningnetwork.cisco.com/s/article/byod-mobile-labs-overview
oo
that's cool
you still need the core exam though for it
ie. the core ccnp for that track
Mhm. Pretty sad otherwise I would've signed up. Never look a gift horse in the mouth.
Non-monetary self promo 👀 But PyWhat 4.1.0 Bug Bounty Edition™️ just released 🥳
Now with:
- 69 new regex for bug bounties 😏
- Supports UNIX pipes (curl abc.xyz | pywhat) 🍕
- New bug bounty mode designed to work with your flows 🔥
Hello, does anyone have good recommendations for C? Crash course, practical, I'll take it 😄
freeCodeCamp got me through my Operating Systems course, but it definitely is intended for people just learning to program
https://youtu.be/KJgsSFOSQv0
This course will give you a full introduction into all of the core concepts in the C programming language.
Want more from Mike? He's starting a coding RPG/Bootcamp - https://simulator.dev/
⭐️ Course Contents ⭐️
⌨️ (0:00:00) Introduction
⌨️ (0:01:22) Windows Setup
⌨️ (0:05:02) Mac Setup
⌨️ (0:09:04) Hello World
⌨️ (0:12:51) Drawing a Shape
⌨️ (0...
Isn't this simmilar to CipHey?
Anyone that has given Security+ 601 can recommend which book to go with?
Thanks so much! That works for me 😄
Gave +1 Rep to @orchid basin
I'm doing very similar -- OS & embedded systems so 😳
I made the mistake of taking my OS class right after I had my Programming Fundamentals/Java course without knowing anything about architecture, memory, etc so a lot of it went over my head 
What breaking into a well defended network feels like...
pretty great opportunity to earn some free certifications and education (A+, Security+, Cisco CyberOps, plus others) if you qualify - program is supported by the NSA
Certs as in vouchers? Awesome.
Does anyone know good ansible courses?
@zealous void I don’t know about courses, but this book is amazing and helped me learn Ansible.
The best book for 'intro to ansible' that I've found is the pearson IT cert guide for the RHCEv8
Thank you
Gave +1 Rep to @jagged tiger
Thank you
@calm ermine
heh
also uhh @hushed estuary
check another channel
hmm?
nitro scam spam
ah
Is it ever gonna end?
probably
it was a good typo squatting attempt should have tried a homograph attack 
how widely used is Ansible? Looks really useful Wondering if I should get across it.
It’s pretty popular. We use it it at work to set up firewalls, Selinux, nginx, and other stuff and it keeps things nice and consistent.
Ansible is very widespread. Especially since the only real prerequisite is that a managed server has python3 installed
Consistent is good. I'll add that book to my tbr.
This is the third video in my Path towards my GXPN. The GXPN is the SANS 660: Advance pentesting and exploit writing class. In the video, I cover my progress so far. Also in this video, I discuss 4 ways to determine your buffer size for exploitatiation. Give me your feedback below and make sure you like the video and subscribe.
1:04 : 4 ways to...
Does anyone have recommendations for OSCP/real-world machines to practice on? I think I've done all the ones Tryhackme has to offer, and all I have left are the straight up CTF machines.
If I have to choose, then OSCP.
I just figured real-world would be closer to OSCP than CTF
Real world infra pentesting is mainly AD
There is no AD in the OSCP exam
Or SCADA/ICS/IOT for that matter
Which THM machines have you done?
A lot of them. I can go look and make a list. I even did a good amount of CTF machines before I got the feeling that it wasn't really helping me.
Good point on this
I did the Pentest and CompTia+ paths, so all the machines associated with those
That's about as close to an OSCP exam machine as you get in terms of style -- although not in terms of content (for obvious reasons)
If you can do that in under 4 hours, you should be good to go
Right on, thank you very much.
I'm actually getting an error going to that link
I'll try manually searching
Weird, can't find it
Is it this https://tryhackme.com/room/yearofthejellyfish
@topaz gulch ?
I don't know if the course is worth it but it's free so here it is :
https://www.udemy.com/course/learn-digital-forensics-beginner-to-advanced-2021/ with the code DIGITALFORENSICSFREE
Hey, I just published a list of resources I found/used in my cybersecurity journey, might be useful to some of you:
Eol. Php
Thanks @shut ferry
Gave +1 Rep to @spare finch
PNG -> 89 50 4E 47 0D 0A 1A 0A
ZIP FILE -> 50 4B 03 04 or 50 4B 05 06
MAGIC BYTE
This is a list of file signatures, data used to identify or verify the content of a file. Such signatures are also known as magic numbers or Magic Bytes.
Many file formats are not intended to be read as text. If such a file is accidentally viewed as a text file, its contents will be unintelligible. However, sometimes the file signature can be re...
@light crystal 🤔
anytime
ah ty
Gave +1 Rep to @glacial gazelle
thanks @crystal slate
Gave +1 Rep to @crystal slate
oi, anyone have some UK based cyber sec online store they suggest for some cheap kit to dick around with?
@mod
Nice resource @glacial gazelle btw, congrattzz
swan u already have things 🤣
https://developer.microsoft.com/en-us/windows/downloads/virtual-machines/
Grab a pre-built Windows VM for dev stuff. Comes with Visual Studio, WSL, etc.
Free, licensed for up to 30 days. Get an new VM after it expires.
Can someone link me up with some resources to create VMs
You can find some more from the internet but these two are also good if you want to create a box on THM.
https://www.youtube.com/watch?v=2qUWfrqAwdI
https://www.youtube.com/watch?v=XyEmZUpNVcI
Thanks a lot
Can anyone suggest how can i improve my scripting? Like any practice platform or something?
A blog focusing on hardware and software reverse engineering
There are a good amount of websites pinned in the #programming channel for coding challenges. But, you could also always try and make autopwn scripts for boxes you've already completed. Or try and recreate challenges you've seen in the language you want to practice.
One of the things I do a lot is redo anything I'm doing in burpsuite repeater using Python. If I do it right, it's probably faster
Will sure do. Thanks for the info
Gave +1 Rep to @orchid basin
try solving challenges
Seems pretty interesting
Thanks
Gave +1 Rep to @light crystal
https://i.blackhat.com/us-18/Wed-August-8/us-18-Guri-AirGap.pdf
Attacks on airgapped infra
Quick trick to safely use netcat on low ports without sudo.
Capabilities are like SUID but more granular, you can assign specific permissions like binding to low ports.
iirc kali did something so non root users can bind to ports less than 1024
Huh, that must be the version up from me
I believe it's a parameter when compiling the kernel
Initially I thought Kali used authbind for this purpose, but after a bit of research I found that they modified a file /usr/src/your-kernel/include/net/sock.h
They changed this line which pretty much takes care of everything from there:
#define PROT_SOCK 0
The default value of PROT_SOCK is 1024 which is the normal port bind limit.
You can also change that parameter at runtime using sysctl, sysctl -w net.ipv4.ip_unprivileged_port_start=0
Capabilities are also great though
Oh yeah for sure it's better to use caps over system-wide so you can have finer control
Also so you don't introduce security issues same thing goes for disabling aslr you should never disable it system wide and instead use setarch
SANS has a massive list of Cheat Sheets available for quick reference to aid you in your cybersecurity training.
What is caps?
He means capabilities
For scan open ports
!rule 11
Rule 11: No distribution of illegally obtained materials within the discord. Do not pirate books in #bookclub. This also applies to classified (or potentially classified) materials, which should also not be posted in the server.
@shut ferryWhich part of that was difficult to understand?
Thanks a bunch.🙏
Gave +1 Rep to @night ether
@everyone Happy Cybersecurity Awareness Month!
To help generate more interest in the security field and hopefully help close the security job gap, we are giving away our best-selling Practical Ethical Hacking course. Expires at 3:00pm EST on 10/20/2021. See image for code.
https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course
^free PEH course
from TCMs server
Fortunately everyone ping is disabled 
Yep haha. I copied the msg from their Disocrd server
https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course
Coupon code- SECURITYAWARENESS
Will work till 3PM EST on 20th October 2021
Image
Is anyone have this materials
Which one
all of them


Hi, I want to learn how to create/analyze Malware. I'm doing this course on tryhackme https://tryhackme.com/room/malmalintroductory. I'd be happy to know what other resources are
On the search page, https://tryhackme.com/hacktivities?tab=search, search for malware 🙂 
newest phrack issue from a couple weeks ago
http://phrack.org/issues/70/1.html#article
Phrack staff website.

How to Take Notes Like a 1337 Hecker
- It is important to note, haha note get it, that even with all of the solutions and new and flashy tools available for note taking, your own note taking should be very indiviualized and meet your needs.
- These resources should also be prefaced by saying that I am a heavily biased towards obsidian, therefore most of my resources are centered around Obsidian, but can be applied anywhere. I will attempt to keep this updated as I encounter and collect other useful links
- The first step to effective note taking is to identify what you need and why you need it,
- From the LYT PKM Kit,
You don't need any of this. Just make notes and start writing. Worry about structure later.
- Moving on from why and how to begin effectively taking notes lets talk about resources to get there.
- Note-Taking Platforms by Category
- Mind-Style Platforms
- Trillium
- Obsidian
- Evernote
- Roam
- Automated/Synced Platforms
- Jupyter
- Joplin
- Straight to the Point/Node-based Platforms
- Notion
- One Note
- Cherry Tree
- Unique platforms
- Compendium Cards
- Mind-Style Platforms
- Syntaxes and Languages to take notes
- LaTeX
- Markdown
- HTML
- MathJax
- Mermaid
- Just straight up notes dawg
Pandoc doesnt fit under this category but can be really helpful for converison
- Personal Knowledge Management Resources
- Zettelkasten
- LYT - Link Your Thinking
- Evernote
- PARA
- IMF
- Research and Academia Resources
- Zotero
- Research Rabbit
- Random Helpful Links I Utilize
- https://www.icl.utk.edu/~mgates3/docs/latex.pdf
- http://thedocly.io/
- https://math.meta.stackexchange.com/questions/5020/mathjax-basic-tutorial-and-quick-reference
- https://mathpix.com/
- https://www.youtube.com/channel/UCfhSB16X9MXhzSFe_H7XbHg
- https://forum.obsidian.md/t/para-starter-kit/223/2
- https://forum.obsidian.md/t/lyt-kit-now-downloadable/390
- https://github.com/argenos/zotero-mdnotes
- https://www.youtube.com/watch?v=XbGJH08ZfCs
- https://docs.google.com/document/d/1Ti90jJG2b9cnKbOoGZyT6ve5P_iyhva6lLRrlL9sCek/edit#heading=h.jcidduny8pla
- https://www.youtube.com/watch?v=ziE6UExsOrs
- https://publish.obsidian.md/hub/00+-+Start+here
- https://oasislab.pubpub.org/pub/54t0y9mk/release/2
- https://www.youtube.com/watch?v=JoCjpTXCklw
- https://chris-grieser.de/Comprehensive-Academic-Workflow-from-Reading-to-Writing-in-Markdown
Posting this here as well because why not
https://hackingpassion.com/ Jolanda de Koff is really awesome!
HackingPassion.com Learn Ethical Hacking and Cyber-Security. We help people become ethical hackers so they can test security systems. We ♥ open-source and Linux
@night plinth ^^
https://www.linkedin.com/posts/jose-praveen_freelearning-packtpub-freecourses-activity-6857323331826401282-is-9 came across this linkedin post about free packtpub library
https://subscription.packtpub.com/register without the sketchy linkedin post
new blog post going over how I implement Zettelkasten and take notes
https://droogy.tech/post/lazyzettelkasten/
Found this really interesting talk by SANS about making digital alert-traps, y'all should check it out if you have time https://www.youtube.com/watch?v=KgQoGIkozL8
Relevant Course: https://www.sans.org/sec550
Presented by: Kevin Fiscus
Follow Kevin here: https://twitter.com/kevinbfiscus
The overwhelming majority of our defensive security solutions focus on the tools and technologies used by attackers. Unfortunately, as we have seen countless times in the past, when you pit static technology against a crea...
oh. I hadn't noticed it was posting in every channel. MB!
Suggestion for improvements would be appreciated:
https://youtu.be/4of_6Q_wHzw
Is it desensitisation or deserialisation?
Learn real world pentesting plus which tools are the best to use with Ex-NSA Hacker Neal Bridges. Neal tells us what he carries in his backpack when doing real world pentests.
My apologies for the issues with this video. I had to remove the previously uploaded video because I had movie clips like Mr Robot and The Spy Game in the video and YouTu...
a pin of this would be nice
Already pinged Muiri Sleepy
??
Ok
@shut ferry Response.
Yes. You can checkout this course from edx. It is from Harvard University.
https://www.edx.org/course/introduction-computer-science-harvardx-cs50x
It covers some computer programming foundations (don't get overwhelmed). From this you can actually learn how computer understands us.
Do checkout their other courses.
@calm ermine lemme do a talk about note taking
Esqy, don't let him do a talk about note taking smh
We require our speakers to be competent
C’mon Muirrrr
That’s not what you were saying in me dms ay bruv
You wish smh
He is, he's just very confused
Not an unusual state for him, I may add

Thanks
Gave +1 Rep to @dull barn
Mb 
Not sure where else to ask for help, but I’m experiencing major burnout, can’t even sit down for 30 minutes now to complete a few rooms or tasks without feeling tired or my mind getting occupied
Was able to sit down for ages and manage to get a lot more done but no idea how to get out of this rut I’m in
It's easy to end up overworked and overtired, what with the state of the world and pressures of work and study. Are you getting enough rest, eating right and getting exercise? Those basics are important. Fresh air and sunshine - resting the brain and eyes.
Social media isn't helpful - make sure when you're having downtime, you're actually having downtime. Read a paper book, grow a potplant or something. I think it's important that our tech time is good quality - when you're working and playing in a screen-heavy environment, you need mental downtime, and save your screen+keyboard time for the important stuff.
... the other thing is, what's your motivation? Do you have a clear goal?
The team Killer Queen is hosting their first CTF: Killer Queen CTF!
Killer Queen CTF will be primarily targeted at high school and college students featuring tons of challenges ranging from a beginner level of difficulty to ones that will test even the most seasoned competitors. It will feature all of our favorite categories including web, crypto, pwn, rev, and forensics with a variety of exciting topics such as quantum-safe cryptography that are not always covered by many other CTFs.
Killer Queen CTF will also be featuring a list of extensive prizes for both open and highschool division from top sponsors as well as a special prize for the top female competitors. Partnering with the WiCyS organization, we hope to increase the amount of participants and the diversity of our competitors so make sure to tell everyone you know to come participate!
Killer Queen will be providing a competition that is both great for new CTFers to learn and fun for more experienced players so regardless of your skill level, we'd love to see you come join :)
Max team size is 7 people.
Prizes:
High School Division:
1st Place - $500, Wolfram Award, and HTB VIP 1 year
2nd Place - $250, Wolfram Award, and HTB VIP 6 months
3rd Place - $130, Wolfram Award, and HTB VIP 1 month
4th Place - $20 and Wolfram Award
5th Place - $20 and Wolfram Award
6th Place - $20
7th Place - $20
8th Place - $20
9th Place - $20
10th Place - $20
Open Division:
1st Place - $500
2nd Place - $250
3rd Place - $130
4th Place - $20
5th Place - $20
6th Place - $20
7th Place - $20
8th Place - $20
9th Place - $20
10th Place - $20
Middle School Division:
1st Place - $50
CTF link: https://2021.killerqueenctf.org/
CTFtime link: https://ctftime.org/event/1482
We hope to see you all on October 29th for this exciting 3 day CTF!
For those of you more Junior Pentesters out there ^
Getting about 5-8 hours of rest per night
Out for quite a bit of the day, so defiantly getting fresh air
And my motivation is to just kinda learn the most I can I guess?
Thanks for taking your time to respond aswell
Gave +1 Rep to @worldly palm
The problem seems to be that you're overextending yourself in place of learning and honing one particular sub skill in cybersec
I've been there before.
I agree, likely overextended. Focus on just one pathway. And maybe take a break - perhaps do some related lighter reading - something like Mitnick's Art of Inivisibility - for inspiration. Get more sleep.
Rust is crazy fast 😮 https://twitter.com/bee_sec_san/status/1453317350258790405
You may wish to advertise that in the HTB server instead :)
https://github.com/swanandx/rustywitness Tool for taking screenshot of websites, like gowitness (more similar to webscreenshot.py) written in Rust!
currently, just slightly faster than gowitness, like around 5 seconds
for ~15 urls
I know what I'm learning after solidity.
Haha, if you like solidity check out Solana. It’s a cryptocurrency but with Rust 😊
or maybe THM can sponsor too :)
actually, do THM sponsor many ctfs?
I've seen it about and was gonna try it later. Learning sol for now to attempt some smart contract ctfs.
They do, yes, but that isn't a request for sponsorship -- it's an advertisement for an already-running CTF 😆
yeah I know
I was more just asking generally
I rarely see their name of prize sheets, when HTB seem to appear everywhere
Perhaps because HTB is seen as more of a practice ground and THM is more for learning. I think it's assumed that CTFers have the basic knowledge? Idk
THM tends to do things like Diana initiative, plus another few similar ones.
Remember HTB also got given what, 11 million, to distribute as sponsorships to CTFs?
make a flash loan attack 😉 they're rather fun and require economic undertanding to exploit, as well as code exploits 🙂
I will! It's on my list along with re-entrancy and a few others. The goal is to get all the common ones down. Thanks though!
Gave +1 Rep to @tepid patio
shit really?
was that government funded or something
I didn't hear about that
They got 11 mil in series a funding. It wasn't for sponsorships, just a general investment in the company.
Cool 403 bypasser with a big effort on UX
If anyone has any suggestions or opinions feel free to DM me or just tell me here
You're using a LOT of global variables. You should be passing those as parameters, especially URLs/ports etc.
Big ASCII banners have a lot of accessibility impact, damages UX horribly for screenreaders.
Variable names could be improved, and they're not PEP8 compliant.
You don't have a final else in your if elif block in banner() or main(). Also weird to use os.system() there when you could be using input(), makes it non-portable.
You could also swap to requests rather than urllib, it has a much more friendly interface for programmers
For this one I simply couldn’t in order to keep the script shorter since I’m brute forcing http methods and I can’t do it using requests without import the api which seemed like a headache
Thanks alot tho
Gave +1 Rep to @odd quest
You're brute forcing methods? requests has get and put and patch and stuff so where's the issue?
I’m using way more and I want it not to be like 15 lines of just the requests
Oh Jesus, yeah, if you're using globals like that, just go OOP...
Think about "designing to do one thing". Each function is meant to do 1 thing, each class is meant to do 1 thing, each file is meant to do 1 thing (even if those things grow "bigger" the higher up you go) 🙂
I'd sep it into files so it's easier to navigate
I would also pin your versions in https://github.com/sootier/403bypass/blob/master/requirements.txt. One day one of those may upgrade and break your program 🙂 By pinning them like requests=0.6.0 you ensure it will always work and won't break due to unexpected upgrades 😄
I changed it a bit if anyone wants to take a look again, I did leave two functions with quite some globals but I removed quite a bit aswell and I think it would look worse to have tons of parameters on a function that is being ran quite a bit of times {banner func)
Thanks so much for the feedback!
Gave +1 Rep to @tepid patio
@hushed estuary
The Indie Python Extravaganza! A collection of books that will help you to improve your knowledge of the Python programming language one page at a time. Join four indie authors in a journey from the basics of Python to the structure of production-ready systems, going through the core features of the language, some intermediate projects and a dee...
These guys are providing free Python ebooks until the 31st
Nice. Thank you. I’m just starting to learn Python, so this is timely.
Gave +1 Rep to @primal onyx
@odd quest
another one kek
@topaz gulch totally new link
https://www.youtube.com/watch?v=4d-qmWLt90E Would recommend this video if you are new 🙂
In coordination with the National Initiative for Cybersecurity Education (NIST NICE), I will be livestreaming a presentation and QA on how to get into cyber without experience.
Cybersecurity is an amazing field with significant opportunity, but individuals are often faced with the catch-22 challenge of needing experience to get a job, but unab...
Sure thing!
https://www.learndmarc.com/ @fast wraith this site looks quite nice
Learn and Test DMARC
You might also enjoy https://dmarcian.com/dmarc-tools/ 🥳
ooh that’s quite cool too thanks :D
Gave +1 Rep to @craggy onyx
ooh nice that is pretty spot on
The best thing you can do is forget about there being any sort of "pathway" or secret knowledge you're missing out on.
Learn everything you can about IT.
- metastable state
I'm looking for some good learning resources (books/courses/videos) related to IOT security. Does anyone have any recommendations?
Check out IoT Security: Advances in Authentication 🙂
Thanks @craggy onyx
Gave +1 Rep to @craggy onyx
looking for good resource about msfconsole, anyone have?
Metasploit Unleashed?
Good list of certs https://pauljerimy.com/security-certification-roadmap/
(interactive)
That's already in the pins I believe but it is pretty good
Good afternoon !! Newbie, here::🍴
think I know what my next hardware project will be, always wanted to look into LoRa
https://makezine.com/projects/armachat-lora-communicator/
Anyone have a resource for scripting filling out job applications?
I know there's some for scraping sites like Indeed with BeautifulSoup but was wondering if theres something similar with maybe filling out applications with Selenium?
Why?
https://mikehudack.substack.com/p/a-product-management-reading-list also this is great for product managers
I think they want to spray and pray.
😦
Eh not really, it’s more like when you apply in like Indeed/LinkedIn, and you put in your resume and then it still asks you to put your entire work history into the job application
It’s mad annoying and mad time consuming
probably not worth the hassle of adapting the script to all the various job boards that could pop-up, it takes like 5 extra minutes max to fill out that information manually provided your resume is formatted properly
also, if every application you send in is via the company website - you are doing something wrong, you should ideally be passing off your resume directly to hiring managers first
sometimes they'll come back and tell you that you have to fill out the company application first, thats fine but at least you're on the radar at that point
Thank you very much for these tips
Gave +1 Rep to @fast wraith
^^^ That's why social networking is so key. It's really easy for a hiring mgr or recruiter to ignore things from people they don't know anything about
Would you connect with them via LinkedIn?
IMO LinkedIn is hot garbage. Local meetups, SIGs, conferences, school, and work are where I met my most valuable contacts. From CISO down to admins, devs and soc analysts.
Special Interest Group
gotcha, thanks for the insight @jagged tiger
Gave +1 Rep to @jagged tiger
We've commissioned top experts in information security to bring you 100% free courses. Learn at your own pace, get certified, and earn CPE credits.
If any of you got some servers and want to selfhost something
Hey
Hey
Anyone here knows a katoolin working repository
Most of the repos ...they use that key server that is gone down and other ones dont work with it
Please I'm currently on my ubuntu and want kali repos ...is there any other way than katoolin?
is there somebody who can tell me if its possible with amass to display the running service on a subdomain? struggling with it since yesterday...cant believe that there is no option for it :/
Subdomains resolve to an IP like a domain does
So scan the IP?
yes yes...i was just wondering about if amass is able to do that in one step right away...scan the domain for subdomains and give the subdomains back, INCLUDED the versions...i wrote a script to do it with python and nmap afterwards (nmap -v and so on). but if there is the possibility to do that within amass with a parameters seems more logic so i am searching if there is such a way to do it...
Scanning for subdomains is a pain
It's either brute force, zone transfer, or dorking
Zone transfer?
Zone transfer.
This is a talk I created to share with folk who have higher risk of being targeted by stalkers, violent exes, or others with prying eyes and a sense of entitlement. It was presented on January 9th, 2021 as part of the Sex Worker Safety Conference sponsored by PornHub. (Huge thanks to DommeKat, Lola Jean, and everyone else behind-the-scenes who...
is it useful for cyber security?
Anyone have something about fully tearing out Defender on 21H1?
https://www.alphr.com/delete-windows-10-defender/ gonna give this a go
oh shhhhhisssh that's super damn awesome!
I am surprised at every minute of information in this video, it's just so so info-packed
@shut ferry thanks! didn't know I needed this, but it's pretty damn good
Gave +1 Rep to @rapid eagle
If you're just starting in programming/infosec, here's a list of obvious and less obvious things you can put on your CV - a 🧵
Some of these things can be done in a week and might improve your CV.
Did I miss something? Please add to the thread.
And RT so it helps more people :)
151
425
If any1 of you want to practice their AD skills

Wait you guys threw it into this tab, after saying it was 'too much' information when I posted it
😆
Lau is not us and this list has been known by many prior to you posting it.
Bold claim. Gotcha
https://youtu.be/MGt-DpYf30g Tips for countering impostor syndrome (in French from Devoxx FR 2021)
Qui n’a pas un jour prononcer les phrases :
j’ai l’impression d’être un imposteur ?
Je ne me sens pas légitime de faire ceci ou de faire cela ?
Certaines personnes sont persuadées qu’elles ne méritent pas leur succès, malgré les efforts qu’elles fournissent pour réussir. Elles s’auto-persuadent souvent que leur réussite n’est pas liée à leur ...
Good website to make resumes for little effort
For those who are applying or have interviews coming up, I found these articles useful!
Ian Neil published his Security+ SY0-601 study materials for free.
https://securityplus.training/
Credits Certification Station
Free threat hunting training at 1100 EST (10 hours from now). Can partake live and get a certificate of completion, or register and watch the recorded session later and do the same training, just with no certificate.
https://www.activecountermeasures.com/cyber-threat-hunting-training-course/
This was yesterday, I took the class
Oh. Looks like I posted very late. How was the class?
Sorry I mistyped the question
sir
Looks like I missed your class :(
Very good, I've taken it twice before, this one in particular is the updated course which is why I wanted to check it out - used to be 4 hours
That was Great. I am very curious to learn from your course.
I am very glad that I was speaking to the instructor of that course 🙂
I'm not the instructor lol, sorry for the confusion
Np 🙂
Awesome! Thanks
Gave +1 Rep to @spare finch
Doesn't that break Apple TOS for the OS?
Anytime 
Given its popularity I think Apple / GitHub would have take it down way before but I may be wrong, I don't exactly know their ToS
Better fork it just in case.
I starred it but yeah we never know :p
Hackerone
Calling all hackers! HACKtheMACHINE hosted by US Navy and powered by FATHOM5 and Booz Allen Hamilton, launches TOMORROW! With 3 tracks and up to $90k in prizes, the event offers bug bounty rewards and competitions to test your cyber skills. Register before it's too late! http://ow.ly/hO5C50GO0fi
HACKtheMACHINE: Unmanned is the first in a series of public-facing technology challenges designed to accelerate the U.S. Navy’s Unmanned Task Force. This challenge will forge a community of partnership between the Navy, industry and academia for the creation of new high-end unmanned vehicle capabilities.
Those categories are really exotic.👀
Except data science
for my k8s friendos https://www.cncf.io/announcements/2021/10/13/entry-level-kubernetes-certification-to-help-advance-cloud-careers/
wow, really useful post from this random guy I found
definitely recommend following said person
DAMN i wonder who that mad lad is 🤔
You'll often be better encoding it before transfer, just fyi
It's usually fine, but if it happens to corrupt (and you don't bother taking a hashsum / don't have the tools to take a hashsum), you're gonna have a hell of a time figuring out why
This is literally the reason why base64 encoding exists
Also helps evade network monitoring, although you may need something stronger than base64 for that 
I need to meet this genius and give him a thank you.
Gave +1 Rep to @glacial gazelle
@topaz gulch base32 
@fringe spire dunno but you should definitely like and retweet this mad lads tweets 😏

Compress it 
Type each letter manually 😄
I'm not us? 
hello, any resources on how to approach benchmarking and implementing a security/pen testing strategy for a platforms + infrastructures ?
If you rename procdump.exe to dump64.exe and place it in the "C:\Program Files (x86)\Microsoft Visual Studio*" folder, you can bypass Defender and dump LSASS. https://t.co/Vk8vPYFTPC
Neat trick, although both writing to a Program Files (x86) subdirectory and dumping LSASS require SYSTEM/Admin rights anyway (i.e. making it easy to bypass defender in a dozen legitimate -- albeit potentially louder -- ways)
👍🏿
Immediate subdirectory, perhaps.
Steam installs games there, they don't need admin often
BlackBerry released a book on cyber threat intel today. Completely for free. Deals mainly with Cobalt beacons from my scroll through.
https://blogs.blackberry.com/en/2021/11/all-your-beacon-are-belong-to-us-new-blackberry-book-cracks-code-of-cobalt-strike-threat-actors
"Finding Beacons in the Dark: A Guide to Cyber Threat Intelligence" is the most comprehensive collection of cyber threat intelligence (CTI) focused on Cobalt Strike team servers ever produced. Learn what you can do to proactively protect your organization from the growing threat of Cobalt Strike Beacons and team servers from BlackBerry cybersecu...
Now you know why they stopped making phones. 😉
Yea, I already got a copy
Whenever you end up on Okta login, click on "Need help signing in" just to see if there is any link to their internal wiki or helpdesk. I ended up on an IT helpdesk which had "Sign Up" enabled and got access to internal docs, passwords & what not. #bugbountytips https://t.co/W6yMm1pJLc
more self-promo
but for boot2root machines, so might be helpful here
You make me want to steal those tweets.😂
(this isn't anything new, capabilities have probably been around for longer than I've been alive)
just haven't seen many people here use them before
Guys what is Cloud storage bucket used for
You answered it yourself. Also sounds like a google question
Yeah
https://portswigger.net/web-security/certification burp suite certification is 9 USD currently
Note: requires full license of burp pro
You can use the free trial.
nah, unfortunately you can't
I'll get the email real quick
It doesn't specifically state that anywhere. Hmmm...email? 👀
Because from what I've seen, you could even attempt it without the license. You'd fail of course though. One of them even mentioned that they don't monitor it. You just need access to a valid license
Oh right, well by all means give it a go
the support email suggested otherwise
but it's only like 9 bucks, so is there any harm in trying?
worse that can happen is you pay the money, then you get to the exam and they decline you
which from what you said sounds unlikely
Mhm. It is 9 dollars so @sand parcel our guinea pig will do it and tell us how it goes lol
apparently it's rather hard...
I've heard that from two sources now, the 3 hours just isn't enough time
That email is vague and this whole thing is confusing because I've checked all the faqs, website info etc and it doesn't specifically state that you can't use the free trial
RIP. People have passed it though. Maybe the difficulty and the rep of Portswigger will make it valuable in time.
yeah, and it's very cheap now so I don't see the harm in attempting it
have you spoken to anyone who's passed?
Not yet but I could. Just need to go hunting lol
Easiest place to find them is LinkedIn
ah right, looks good cheers
Oh, that's easy if they don't monitor it then.
I have my own version of collaborator on a VPS, and Adam made one for THM too which is on his github and easy to deploy :kekw:
PyIntruder - Extremely Fast Intruder Replacement
Repo: https://t.co/yRSaq4SLvu
Creators: @yash114bansal & @SagnikHaldar1
#infosec #bugbounty #bugbountytips #CyberSecurity #burpsuite #intruder
A Nmap Cheatsheet
Hey!
Does anyone here know how many days(maximum) would one have to give the Burp cert after purchasing it?
12 months
Thanks!
Gave +1 Rep to @broken burrow
I was told by email I could use the free trial version, but it's not recommended since "some users faced difficulties during the exam".
What's the harm in doing it for 9 bucks?
I see someone's active again.👀
yeah little bit, mental state slowly improving x)
Awesome seeing you back around regardless. OSCP done?
Yeah some time ago already. Got CRTP in the meantime as well, prepping for CRTE now
Hows it going for you?
Nice nice. I'm trying to save up for oscp. Taking any odd jobs I can to make it work. I've got an interview for a contract tomorrow so hopefully I land that one. I'll have more than enough to buy the course if I do land it.
Oh nice 😄 You'll get it for sure!
I sure hope so.😄
https://grow.google/intl/en_in/certificates/?utm_source=HPP seems interesting
None. I honestly can't see what kind of difficulty could arise from doing the exam with the free trial version. By the way, they increased the time from 3 to 4 hours.
networking icons 😄
and other icons
If anyone's still editing /etc/hosts with vim/nano – you deserve better!
hostsed
this seems like a very unnecessary tool
So it’s echo? But it only has one use?
It’s probably more annoying to use for CTFs too if you end up discovering a new vhost midway through since it doesn’t seem like there’s an option to edit an existing entry
Also, why are there 4 different aliases for the same function? I don’t mean to dunk on this too hard, because it was probably created with good intent, but this is excessive.
alternatives for https://letsdefend.io/
awesome course, $10 is a steal - great for people looking to step up their networking and pivoting a bit
https://opsdisk.gumroad.com/l/cphlab/blackfriday2021
UpdateThis lab is best paired with The Cyber Plumber's Handbook which, as of September 6, 2021, can be found for FREE here: https://github.com/opsdisk/the_cyber_plumbers_handbook/Your purchase includes a PDF lab guide with 45+ exercises and 28 days of interactive access to a real live lab to practice SSH tunneling and port redirection techniques...
75% discount for students 👀
Hi
NOTE: Jump to 24:17 if you are only interested in the Wireshark capture and SSL decryption technical explanation. You can also follow along by downloading the Wireshark pcap using the link below.
Learn how to decrypt TLS / HTTPS traffic using Wireshark.
// MENU //
Is it important to learn Wireshark: 0:00
Will you get a better job? 2:19
Welcom...
Is there a way to get a version of openvas that is 100% compatible with a known kali version?
not really sure where to ask this room seemed like the right place
@shut ferry check in #start-here or in the pinned messages I guess
cool
Any time I've used OpenVAS, I've always run it in a docker container. I would not straight up install OpenVAS on Kali without a container imo
Keeps things cleaner, you don't want 100 different installs of tools you've only used once to bloat your machine.
OpenVAS should be treated as an appliance, whether installed in a VM or on bare metal. Regardless, when I've installed OpenVAS, I always use a stable supportable OS as the base. Usually that's the version bundled with Greenbone OS as it is less messing about to get it working.
their website has fairly recently had a change to make it much less usable, though
I should have specified that my problem is more along the lines of getting postgresql to start on the designated web port 9392 or something along 9000s they may have more than just one don't quote me on that. Everything else works fine or rather was tweaked to work I am just curious because this seems very how would you say it...disorganized as each small tweak or detail can throw off the whole software solution, with that in mind does anyone actually use openvas like today or these days I get the feeling most people would just use exploitdb or something easier to maintain?
anyone know's how to create virtual machine like attackbox
Guys I need help devoloping a kernel exploit for windows any resources you would recommend
- Install Linux, AttackBox uses ubuntu but Kali will be easier for step 2
- Install cybersec tools
Anyone,??
Not to be a discouragement but if you're asking us that question then you're probably nowhere near capable of doing so. I've never done anything like that before but a good place to start would be learning assembly and getting low level with a computer, reverse engineering, writing shellcode and looking at existing kernel exploits.
I have kali installed, what I want is attackbox like GUI.
Hey guys is there any resources regarding hardware hacking in THM. Looking for the basics then building my way up. Looked at some LiveOverflow videos (GOLD). Mostly there are lectures on this which doesn't make me feel awake. Anywhere I could try them online?
This is all I know that relates to it tbh.
https://microcorruption.com/login
There are also a couple of No Starch press books on the subject that could be worth looking ay
Might be worth taking a look at Azeria Labs too
https://azeria-labs.com
Thanks for the info! I already had a look into the micro corruption. Will take a look on the books
Gave +1 Rep to @broken burrow
@serene fossil and how exactly is that a useful resource? 
ok nvm I thought it was a nice article. but apparently it is not appreciated. I couldn't care less.
I mean, what reason could you possibly have for needing to know how to hire a black-hat hacker?
More to the point, what reason could everyone else in here have to do so?
Jesus I get that you want to be important. But I don't care. I thought it was a nice article that's all. Well I'm going to get on with my life. Success with it!
Charming 🙂
He’s rekt you there lad
nice resource
good read http://phrack.org/issues/66/10.html
Phrack staff website.
Math explained in easy language, plus puzzles, games, quizzes, worksheets and a forum. For K-12 kids, teachers and parents.
Did you paste the wrong thing?
Did you mean for that to be two links?
thanks for the heads up, copied a second one that I didn't mean to post
Humble Bundle - Hacking eBook Bundle
https://www.humblebundle.com/books/hacking-by-no-starch-press-books
pretty interesting write-up on COM tradecraft
https://medium.com/maltrak/com-objects-p-1-the-hidden-backdoor-in-your-system-947ac4285e85
Does anyone have a Windows XP VM for practicing Pentesting/metasploit on?
Stock up and save in our Booksgiving Sale, now through December 1.
I think I got mine from Windows a long time ago, but I'm not sure what a Google search would yield today
if you happen to use unraid there's an xp vm option to install
talk on breaking into Threat Hunting from Active Countermeasures coming later today
https://attendee.gotowebinar.com/register/4497991437362184208?source=thc
If you somehow can get hold of a visual studio code license, you can get access to the XP .iso and license keys. Otherwise...I can't really think of any other way :/
Oh man this is great! Thanks
Gave +1 Rep to @ripe wasp
@ripe wasp @shut ferry Licensing on that is technically not legit. Deleting it.
Was that the MacOS docker thing?👀
nono the windows xp vm that came with internet explorer to test dev on it
microsoft pulled it out and now you can only get those starting from windows 7
Ah rip
Still haven't tried it though, I will some day 
Same
Does anyone have any recommendations for a good way to obtain Security+?
Study hard and pass the exam.
Professor Messer. He has free videos and is enough for most people.
Thank you!
Can somebody suggest me a good resourse to start web app pentesting ?
Is HTS still a thing, its what i used way back when.
Web Application Path at https://tryhackme.com
Portswigger academy
Thank you so much for this. It really helped me.
Gave +1 Rep to @atomic yoke
those trying to write a good resume:
https://ocs.fas.harvard.edu/files/ocs/files/undergrad_resumes_and_cover_letters.pdf?m=1598037165
It's a handout to Harvard grads from what I know, I could be totally wrong, but hey, the doc is really nice.
I can swear there's a famous super upvoted post in Reddit by a ex recruiter guy who shared exactly the same format. (Yeap! https://www.reddit.com/r/jobs/comments/7y8k6p/im_an_exrecruiter_for_some_of_the_top_companies/)
damn, plagiarism or what lol
very similar content
either way, I just went through it, and felt that the Harvard doc is clearer to understand, whereas the Reddit one is kinda more like a human telling the approach, so depends on personal preference in the end.
I'm gonna ask for these 18 books for christmas, have any of you read at least one of these on the list? They seem useful/interesting.
https://www.humblebundle.com/books/hacking-by-no-starch-press-books?utm_campaign=07_0562&utm_medium=paid&utm_source=facebook&utm_content=2021_hackingbynostarchpress_msrp&utm_term=2021_hackingbynostarchpress_book_bundle_mobile&fbclid=IwAR2KXfZTp6ZlZW00qY18E6lWHlvTg10hFS1xxn8IXKfMityQGyp5cAiwqWE
I have that bundle
If you're pretty new to everything they will have some helpful stuff
Thanks! I still have a lot to learn so I hope this will be useful
Gave +1 Rep to @atomic token
Got 'em!
anyone who can help me bypassing file upload?
is that for HTB challenge?
Can anyone recommend good discord servers where writeups are posted related to bug hunting and Pentesting? Searching on medium is sometimes just exhausting
ya had some issus, but ive done it already
thank ya tho ^^
would recommend asking in the relevant discord though.
my question wasnt related to any platform, it was about the method but yea, thank you anyway.
Gave +1 Rep to @fringe spire
hackerone
If you have an account you can read the latest published bounties
Most of the time including pocs and stuff like that
Could be overwhelming at first tho
A lot of the hunters link there blog post related to the bounty in there to get a bit more explaination
In this Black Hills Information Security (BHIS) webcast, you will learn tools and techniques for performing penetration tests against Microsoft Azure environments. Increasingly, more organizations are migrating resources to being hosted in the cloud. With this comes a greater potential for misconfiguration if there isn’t a solid understanding of...
check out
hi, what is a nice tool for keeping notes? (for attacking machines)
I would suggest Cherrytree for notes on specific machines, and Trilium for general notes 🙂
looks nice, thank you very much 🙂
Gave +1 Rep to @topaz gulch
obsidian
Notion you're at the mercy of the company not going down, but it's very pretty. Obsidian your notes are stored in plaintext markdown on your hard drive, so good luck when you start writing notes that trigger AV
(Spoiler: AV deletes them for you)
can't you just mark that folder for exclusion for the AV though??? even though that might be a security risk
Yes, but then where do you think I'm storing my payloads if I compromise you?
/dev/shm probably
but yeah if you can figure out what folder is excluded form the antivirus when hacking a machine that is a great spot to store payloads
Get-MPPreference
Problem solved
Have the stager find the excluded directory, save all later stages there.
And you use AV on Linux..?
clamav
for files shadow shares with family and friends
so in a way both yes and no to that question... it is part of daily scan as long as shadow don't have that disabled... which they currently have
Just dropping this here as the conversation is relevant, I saw this few weeks back in random GFeed, the app looks nice and is opensource. https://github.com/AppFlowy-IO/appflowy
Very much like notion
rip-off but yeah
Here just use one of mine.
you just mad Obsidian is better
https://cryptohack.org/challenges/ (Dropping this here so it's not lost in the general chat)
Made by the same guys that made embedded security ctf. Fun
idk that doesn't sound right, got any source? 👀
I remember finding mentions on their that they made it after cryptopals? I can't remember.
cryptopals != cryptohack tho
MysteryTwisterC3 also cool
this is 8super* cool!!!! https://www.reddit.com/r/tryhackme/comments/r9xjep/quizlet_for_the_full_presecurity_path/
32 votes and 3 comments so far on Reddit
No-to-low-cost guide to infosec
damn why windows gotta be so hard to learn how it works
Really isn’t
Here a article from me about broken link hijacking 🙂 https://proviesec.medium.com/broken-link-hijacking-what-it-is-and-how-to-get-bounties-with-it-ca64db6a3f74
new drive-by attack via Windows URI handler, great write-up on bug hunting methodology too
https://positive.security/blog/ms-officecmd-rce
Chaining a misconfiguration in IE11/Edge Legacy with an argument injection in a Windows 10/11 default URI handler and a bypass for a previous Electron patch, we developed a drive-by RCE exploit for Windows 10. The main vulnerability in the ms-officecmd URI handler has not been patched yet and can also be triggered through other browsers (require...
Hey guys just wanting to know if there are any good guides on Red Teaming that assist in stealth when perform enumeration
more so IT/network enumeration not physical
Can you guys please fill out this google form, its for a school project
A lot of people would be happy to if they knew what it involved
@uneven flume Please ask for permission before sending survey links
who do I ask permission to?
A mod here. Not by DMing them though.
basically the survey just asks a bunch of questions about what you look for when buying a laptop
can I just ping them?
I'm one.
What class is it for?
Have you had an ethics review done?
its for a JOT case competition
A what?
its for a friend, she's writing a report about laptop companies
Basically its an extracurricular that focuses on business
she's writing a report
and she wants data
also wdym by an ethics review?
Hi guys! Now that Active Directory has become part of the OSCP I've written a guide on how to setup a lab for pentesting. This is just the setup, nothing about the vulnerabilities, but I'm expecting to cover some typical attacks in the following days.
If any if you finds it useful, then I'm happy!
https://shroudri.github.io/guides/setting-up-active-directory/
Now that Active Directory has become part of the OSCP exam, it has gained even more interest in the pentesters world. Setting the whole thing up is not too complicated, but it can be intimidating if you don’t have much experience with Windows Server. Hopefully, this post will guide you through the installation so that you can have your own lab. ...
I have been collecting resources and wrote down some AD resources including THM rooms and other things that can be used to practice AD https://github.com/zjja/Cyber-Notes/blob/main/Learning/Active_Directory.md
thm-banner-gif needs translators
https://github.com/OSCAR-WOS/thm-banner-gif
Two word-class experts of security – Paula Januszkiewicz and Mateusz Chrobok -will share their experience on event for tech leaders ‘A stormproof security strategy for your digital product’ on 14th December.
You are welcome to join them!
Take your free ticket here: https://hubs.la/Q010Cpsr0
Roadmap for bugbounty
An unbiased look at Web3.
https://youtu.be/wHTcrmhskto
A complete introduction into the wild world of Web3 - the decentralized web. Is Web 3.0 the future or is it all hype? Learn about the technologies and patterns used when building a dapp on the blockchain. https://fireship.io
#web3 #blockchain #webdev
🔗 Resources
Hardhat docs https://hardhat.org/
Web3 is BS https://www.stephendiehl.com/blog/we...
NGL "Unbiased" and using 4chan templates strikes me the wrong way
It's unbiased in that it doesn't push it onto you. Just explains the premise and how it differs.
Then leaves you to form your own opinion. Much better than our mutual friend from a few days back 🙂
Subtitling 'by answering stupid questions' also doesn't indicate lack of bias
The creator doesn't mean it in a demeaning way. It's in the same context as when people make self deprecating comments like "This may be a stupid question but..."
Russel & Norvig once defined artificial intelligence as "any modern technology". They talked about how all exciting & new tech was classed as AI, even if it didn't fit into the original definition of AI.
I feel the same way about Web3. All new & exciting web technology falls under this banner, even if it doesn't pertain the original meaning 🙂
Exact same thing happened with "Blockchain" in 2017. A lot of tech was named under that phrase even if it didn't need to be or it didn't fit. ICO mania spewed hundreds of scams. If you was a tech company you put "Blockchain" in the name to 10x your valuation.
Then all the silly uses eventually died out, and we mostly reserve blockchain for the real uses (all ledger related, of course. Mostly in cryptocurrencies, logistics, or any application where you need a really strong ledger. AWS has some great real world use cases here https://aws.amazon.com/qldb/customers/?pg=ln&sec=c#Driver_and_Vehicle_Licensing_Agency)
Going even further back, the dot com mania (https://en.wikipedia.org/wiki/Dot-com_bubble) had the exact same thing
People just seem to find a new tech, try to implement it in every single way possible and eventually it finds its use cases 😄 (after all the bad ideas die)
That's true. It doesn't discount how interesting learning it is though. 😄
Oh btw Bee, have you played around with WebAssembly and Rust?
i have not 😦
i am doing a builspace course rright now haha
What? Me too! 😂
Oh that one. I suck at front end so I'm leaving it on the backburner for now but I could sign up for it too
I'm also shitty at Rust haha. Need to sit down and look at the syntax
i am also bad at frontend but i plan to learn it
I'm also trying to put aside learning React and see if I can do the same project in Svelte instead
Seems easier and better than React
But harder to learn in the beginning perhaps. Web3 in this context just applies to decentralised web apps so maybe we haven't seen much that doesn't fall under it but is classified as web3.
I'd class Mastodon as web3
decentralised, giving the power back to users
@broken burrow are u in any DAOs?
Not at all. 😆 I'd like to see how they function though.
I'm in developer dao, do rec checking us out when we open signups back up (bankless dao is also cool)! 🙂
would you consider microservices to be web3 then?
I will! Gonna look it up and watch. What protocol does it run on and do you need to exchange membership tokens with cryptocurrency?
depends, can any user run a microservice on your platform? if so then yes 🙂
well
not your platform
a decentralised mesh of microservices anyone can contribute to, then yes
dev_dao signup is not open right now, the entry originally was an ERC-721 but we're creating an ERC-720 for people 😄
bankless DAO airdrops you a POAP after 1 month of membership to their newsletter
Is openness a requirement of web3? Instead of say, load balancing across multiple k8s clusters?
its not a requirement, but you can't build things without it being in the open. An example is building a video game and having swords in it. Those swords would be non-fungible tokens which would allow any other game to easily import them, and anyone can fork your game and change the code if they would like. It's a public blockchain so openness is baked in 😄
one of the problems a lot of startups face is that people can fork them and just do it better, or you build something and in a weekend there are 500 shitty forks of your startup 😅
ERC-720...🤔 I've never heard of that token standard. How does it differ from 721?
Or a much better one in a month
Look at what happened to Dapp tools
721 == non-fungible token
720 == fungible token
if you've ever used a token (BAT, DAI, USDC, Shiba Inu) you've used 720 😄
Paradigm made a faster rust based framework named Forge
No wonder I was confused
some startups are designed to be forked and worked on, like Loot project or Sandbox
You should take a look at this since Rust seems to be your jam. Uses ethers.rs as opposed to ethers.js
ahhh I have great respect for Georgios
I have more respect for his colleague, samczun. 😄
Georgios is a beast too though
The premise of web3 is a decentralised internet owned by the people not just huge tech giants that control all the information so less censorship, little to no collection of PII and user data and ads unless the user opts in. That doesn't mean everything including sensitive information has to be public as there are off chain solutions for that and nothing sensitive or private should be stored on the blockchain. The video I linked explains it to some degree
Let me throw one in: IPFS
Mhm.
i think single sign on is the biggest improvement I've seen
super simple to integrate
privacy orientated if u want it
just super simple
Ethereum and it's children(all the ones that came after it) also hit home the fact that cryptocurrency isn't meant to replace or really be a competitor to fiat currency. It's meant to fuel the decentralised ecosystem and implement faster transactions without a middle man to restrict the transfer to certain countries/slow them down
Oh btw @tepid patio did I mention that the Foundry actually lets you write tests in solidity not JS or python?
oh thats cool!!
i need to do some more non-buildspace stuff
from a banking perspective defi can help a lot
fintechs succeed because they are tech based (compare to old banks which are not). it means we have a lot of automation in place that can cut down costs, time and other things to make it better for the user.
defi is the same but for finance, just more automation 😄
https://www.gro.xyz/ is one of my personal faves for this
Gro protocol is a stablecoin yield aggregator that tranches risk and yield. The first two products built on it are the PWRD stablecoin with deposit protection and yield, and Vault with leveraged stablecoin yields.
their tranche system is p/ cool
That one seems pretty cool and their security seems great. They even have a bounty up on Immunefi. I'd look at their smart contracts and see if I could get away with a bounty but they've been audited multiple times so I doubt i'd find anything
I can barely finish Damn Vulnerable DeFi as it is haha
Hft?
High frequency trading
DeFi/Blockchain security is actually why I've learned blockchain dev
My friends have told me multiple times that I can't audit a smart contract if I don't know how it works. I didn't listen so I found out myself when I everything looked like gibberish in a CTF. 😆
I've started to love dev though
Auditing is big big money haha
Hm...isn't that just day trading but with a higher chance to lose money?
Salary wise, you could start out entry level with about 100 to 150k but I've heard skilled auditors and some freelancers earn over 300k.
Well, for a hedge fund preferably
It is basically day trading
You actually get all the money if you’re the fastest lmao
The problem is figuring out how to be fast
Risk free too if you can figure out that
Arbitrage it’s called
I just love the idea of writing code and optimising it and the hardware to be as fast as physically possible
And to play with the real world financial markets
“Flash boys “ is a good book about this
And “flashboys 2.0” is the blockchain white paper exploring this too
Flash boys looks suspiciously similar to flash bots
So you basically want to create a bot/program that's fast enough to automate this process for you?
It’s the same thing haha
Yes but the “fast”part is the hardest
It’s really hard to get into it as everyone else has billions
To work with*
Ideally I’d work for a hedge fund or a quant firm
Billions of funds?
Yeah you can’t be the fastest unless you have enough to invest in. Being fast
An example is laying a fiber optic cable@from one side of the US to the other just to experience 18ms faster latency
Of course. I'm assuming there'd be some application of front running when it comes to implementing this in the blockchain world so you'd better have enough gas on hand. 😆
Front running is actually a HFT attic haha
Attic
Tatic
You can protect against it in the stock world by using the IEX exchange
Or by trading exclusively in darkpools
Which you can do neither of as you’re not a hedge fund lol
👀In a gc a few days back someone mentioned a protocol that offered 5 or so % yields in staked funds every 8 hours so they were thinking about taking out a flash loan a few minutes before the stake ended.
I've not seen it tested but it seems relevant to the discussion.
And then staking to significantly increase returns before paying it back.
I'm not sure how flash loans work but it seems like it could work in practice
Flash loans exist for 1 transaction block
You’d have to be in the same transaction block as the payout
It’s possible but unlikely to time it perfectly
If you used an oracle to time it too you’d be paying for that also 😦
Interesting
(Log4j Vulnerability in Java) https://www.lunasec.io/docs/blog/log4j-zero-day/