#resources

1 messages · Page 14 of 1

light crystal
#

Thank you!!

odd sinewBOT
#

Gave +1 Rep to @fast wraith

light crystal
shrewd umbra
#

Reverse malware first, develop second

shut ledge
#

hiya all. just starting the thm. running non-kali linux locally. recommendations on installing tooling locally or creating a dedicated kali instance to do all the things from?

topaz gulch
#

Now why would you want to do a thing like that? 👀

light crystal
#

learnin? am not gonna do anythin bad..

tranquil shuttle
#

sus

light crystal
#

:(

topaz gulch
light crystal
#

oh, i understand ur worry..sorry..just a interest for learnin. am never gonna do anything bad with it.. and for the channel, sure sorry again

shrewd umbra
# topaz gulch There are precisely no legitimate uses for malware if you're not a professional ...

So no one can write some malware to gain experience on actually implementing injection/hooking/evasion techniques, so if that person does land a red team job in the future, they can have experience in offensive tooling and be of more value? Plus, u can build more knowledge on actually using the msdn docs for various api functions used in different classes of malware. Their is more to just reading what the api functions does. If u can actually re implement a specific technique using the api docs, and some googling, then thats more valuable knowledge for yourself and a job in red team or security research down the line.

topaz gulch
#

Be aware though: it's illegal to develop malicious software in many jurisdictions -- even without intent to distribute or deploy.

#

Sooooooo, you had better have a bloody good reason for it if anyone comes calling

#

Your best bet is to look into building offensive tooling rather than traditional malware -- then you have a plausible reason if you are a student, in industry, or looking to enter industry. Regardless though, if you're discussing it in this server, it goes into the specific channel that we have set up for it. There are way too many malicious skiddies around for us to have the liability of y'all discussing it publicly.

shrewd umbra
#

Correct. Nothing wrong with what you stated on the legal side of things. Just feel like when diving into a particular subject in cyber besides grc, if u aren’t actually doing any hands on and re implementing techniques for learning purposes, then how does one actually understand the subject matter come a real engagement

#

Their is a channel for this topic here?

topaz gulch
#

#exploit-and-mal-studies -- it's restricted under a few different roles (0xD, Throwback, OSCP, eCPPT, and a few other of the entry level certs).

fast wraith
light crystal
fast wraith
#

requesting if anyone has a sane and practical implementation of zettelkasten in Obsidian - I've read the top articles that come up in Google and watched Obsidian's video on the subject but it's still a bit confusing

remote wind
#

Confused regarding? Zettelkasten or obsidian?

fast wraith
#

zettelkasten, obsidian is easy enough to understand

remote wind
#

Zettelkasten is ez too, if you prefer book, i would suggest How to Take Smart Notes: One Simple Technique to Boost Writing, Learning and Thinking – for Students, Academics and Nonfiction Book Writers

Or just watch/read summary of it. It isn't specifically for obsidian, but it's core is zattelkasten method

#

I would recommend it

spiral zodiac
sudden fern
jagged tiger
fast wraith
#

true, its starting to get a little annoying having huge tree structures to scroll through, esp since some structures are like 5 folders deep

and now I'm in the process of centralizing all of my notes from various cherrytree DBs and multiple Obsidian vaults, figured I could try something different

jagged tiger
#

I've had good luck using Trilium - as much as I loathe JS and Electron apps, it does have most of the features I want when taking notes

upbeat token
topaz gulch
#

I'll trust ya. Congrats 🙂

upbeat token
#

Thank you! 😄

balmy sun
#

Does anyone have good list of burpsuite (pro included) extensions used in CTF and bugbounty context?

sudden fern
#

#room-hints or #room-help are more likely to help you then here and also specifying what room and task you are on will help too

night ether
#

i don't think they're asking for help with a room, just in general to help them when doing any room/bb

faint sluice
#

maybe ask in #bug-bounty ? I think most people use burpsuite free or owasp zap

sudden fern
#

@hushed estuary ⬆️ scam link

carmine shard
#

shouldn't it also be deleted? 🤔

#

the message I mean

sudden fern
#

¯_(ツ)_/¯

#

@prisma bison could you delete the message in here??? and the other places it is in???

fast wraith
split mantle
shut ferry
#

Anyone knows about an academic paper about web hacking/security??

#

With a credible author

odd quest
shut ferry
#

Yes

odd quest
#

Are you sure it wouldn't be cheating if we gave you some?

#

Try searching with Google Scholar or asking for help at your school/college/university library

shut ferry
#

Wait is that cheating?

#

What about names of the authors

#

Would that be considered as cheating?

#

Also every time google scholar I get like pdf where I have to buy them

jagged tiger
#

Some academic journals do require buy-in; if you connect to google scholar through your university wifi or vpn, you should have access to those.

shut ferry
#

Oh alright thank you

fast wraith
shut ferry
#

Hey guys. I threw together a small nmap tutorial/cheatsheet. It might be useful if you're going through the Furthernmap room. It covers basic switches, scripting and scanning types. Hope this helps

odd sinewBOT
#

Gave +1 Rep to @boreal ermine

odd sinewBOT
#

Gave +1 Rep to @boreal ermine

shut ferry
vast mountain
azure widget
hushed estuary
odd quest
#

I like these changes

shut ferry
odd sinewBOT
#

Gave +1 Rep to @hushed estuary

shut ferry
#

Bot too strong cri

hushed estuary
#

haha

light crystal
azure widget
dawn oak
#

Any blog/article for note taking tips? I am kinda new to reports and notes so it would be helpful.
Tried finding but haven't caught something useful yet

fiery bear
night ether
#

@odd quest ^

fast wraith
#

the biggest take-away for me is that you just need to write things down, have a daily note that you just always have open, end of the day pull out important bits you like and see how you can file and categorize those important bits

dawn oak
odd quest
#

@spiral zodiac Muir deleted it because "it's an n-day vuln -- we probably shouldn't be directly advertising code for it".
If something is deleted, probably best not to repost it?

spiral zodiac
#

Oh it was muir he could have told me smh, but okay I understand why it was deleted vent

topaz gulch
#

Yeah, sorry, did it on mobile in a hurry ♥️

split mantle
rain kernel
#

I try this tool it require python 3.8 or later
Upgrade your shell automatically. It sounds interesting.

split mantle
shut ferry
fast wraith
queen mortar
#

Found something interesting from a IT news website.
It's a leak of a Ransomware group affiliate who was let's say not very happy and fed up by them, so he leaked there total playbook.
It's kinda interesting to see how a group access and pivots through the network, exfiltrates data, and many more.
It's also interesting for understanding Attacks against AD, Kerberoasting, and many more.
The catch is, its purely on Russian, so a tool like Deepl can come in handy if needed.
//It's purely for educational purposes only//.
Link to the documents:
https://github.com/ForbiddenProgrammer/conti-pentester-guide-leak

I hope it's not against the Server rules, to link this resource.
-R1ot

broken burrow
drowsy niche
#

oh like an automatic python -c bin bash thing??

shut ferry
broken burrow
remote wind
#
brittle nymph
#

AWSome Day Online Conference is a free, one-day cloud training delivered by AWS
https://aws.amazon.com/events/awsome-day/awsome-day-online/?trkCampaign=awsome-day-online&trk=
Register (before 30 Sep) to participate if you like 🙂

keen temple
#

[Replying to the now deleted message] I believe this is a scam going around the cybersec discords recently

keen temple
#

I hope it's not another academic project gone wrong like that one uni injecting crafted fake vulnerabilities to the linux kernel github repo to test the effectiveness of open source code audit practices.

faint sluice
#

maybe you should be clear that AWS is not the scam 🙂

keen temple
#

Oops 😂

faint sluice
#

no its ok, just wanted to make sure others knew the AWS is a valid link and not a scam

keen temple
#

oh definitely

keen temple
#

-.-

split mantle
crimson thunder
split mantle
light crystal
light crystal
odd quest
#
split mantle
light crystal
tranquil snow
#

Can I get any Networking related stuff here

light crystal
short junco
#

Hey any resources about Threat Intelligence infrastructure ?

fast wraith
abstract pilot
abstract pilot
split mantle
#
Cas van Cooten

Nim for offensive security For a while now I have been playing with the programming language Nim in the context of Offensive Security. Nim is a relatively young and fairly unknown programming language that has a syntax quite similar to Python’s, so is very easy to pick up. It however offers the flexibility and low-level capabilities of languages...

spiral zodiac
#

^ good article, the author is one of my friends

light crystal
#

damn

#

nice frands

gloomy badger
fast wraith
flint bison
#

What are your favorite SQL injection tools/scripts/etc. ?

split mantle
#
Cas van Cooten

Last update: July 10th, 2021
Updated June 5th, 2021: I have made some more changes to this post based on (among others) techniques discussed in ZeroPointSecurity’s ‘Red Team Ops’ course (for the CRTO certification). I’ve re-written and improved many sections. New sections have been added on DPAPI and GPO abuse. Notable changes have been made to ...

split mantle
gentle jolt
#

Hello

fringe spire
#

You are from Pakistan?

light crystal
gentle saffron
craggy onyx
#

Great read ^^^

#

Of note: Vinny is not afraid 😄

fringe spire
glacial gazelle
broken burrow
odd sinewBOT
#

Gave +1 Rep to @glacial gazelle

lean coral
split mantle
shut ferry
#

@odd quest ^

prisma bison
#

I don't want to be rude but there isn't much of a guide in that blog post.

keen field
split mantle
light crystal
#

thnks

last wolf
jagged haven
last wolf
jagged haven
# last wolf so what do u think I got right and what did I get wrong in the article ? is ther...

its pretty straight forward, altho the assumption of VcXsrv being installed is bold its understandable, some people might be wondering about why you export DISPLAY on the zathurarc but I think people who want zathura on their linux are aware of why cuz they worked with zathura previously. another note is the set sandbox none, I would explain a bit better, for the rest it seems a cool walkthrough for a problem I didnt know there was an answer

last wolf
#

Thx for the feedback @jagged haven

jagged haven
odd sinewBOT
#

Gave +1 Rep to @last wolf

azure widget
#

Dirk-jan Mollema - Breaking Azure AD joined endpoints in zero-trust environments

How much trust is zero trust anyway? As more security controls are added to protect cloud accounts, much of that trust ends up on a users endpoint, where long-term credentials are stored which comply with strict security policies, such as Multi Factor Authenticatio...

▶ Play video
fast wraith
#

@hushed estuary

languid parcel
#

hmm

hushed estuary
wet willow
light crystal
#

that is nice!

bright osprey
broken burrow
cobalt lily
#

👍

glacial gazelle
#

"The course is accessible for FREE right now on UDEMY with the code "LLS10K" as a part of the fundraiser I'm doing with them. If you have ever wanted to donate to me, buy me coffee/food, or just support me, please take the time to donate it to LLS instead! https://pages.lls.org/ltn/sac/sacr21/BSadeghipour"

broken burrow
#

Freddie coming in clutch.

#

At this point, I've never bought a course on Udemy but my library is packed.

odd quest
#

https://jc01.ninja/pwdump/
Hate messing with meterpreter hashdumps or impacket secretsdump pwdump format? Try this
Spits out a hashdump that's ready for John to use immediately, or hashcat to use with the --user option

spiral zodiac
#

that's actually quite useful, bookmarked

#

I wonder if I can break it somehow

broken burrow
odd quest
split mantle
spiral zodiac
#

wow dark is there 🤔

#

pls stream minecraft again dark kthnxbye blobknife

dreamy holly
#

Hello Toaster

remote wind
# odd quest

Can you also add the mode for JTR/Hashcat? Or the command itself so user can just copy paste?

odd quest
#

No, I cannot

#

Because I don't want to add fields to enter wordlists and hashfile locations and stuff like that

split mantle
shut ferry
#

from where can i start?
i am new
to hacking
pls
help
(:

night ether
fast wraith
raw ice
#

Hey, have any of you guys taken the Cisco course about networking? If so, is it worth it?

keen field
mighty ferry
#

@raw ice i have went through all of the old CCNA/CCNP/CCIE RS track and I can say that professionally it will open a ton of doors, however, for cyber security IMHO you will not get much value past the CCNP level certs. The OSCP and CISSP is going to get you past the HR gatekeepers at that point.

light crystal
hollow phoenix
#

can i dm @tepid patio ?

tepid patio
next marlin
#

How to configure burp suite with tor for better anonymity
https://youtu.be/uGyKfeJBDbw

In this video i have shown how to configure BurpSuite with Firefox Browser, and how to configure BurpSuite with Tor service.

Link to download Burp Suite:
https://portswigger.net/burp/releases/professional-community-2021-8-4?requestededition=community

I do not claim the ownership of the track used in this video.
All rights belongs to the ow...

▶ Play video
calm ermine
#

@next marlin Hey Man 🙂 Not seen you here before 🙂

night ether
mighty ferry
#

@night ether held CCIE RS until it changed to EI in 2020 working on getting my collaboration to re-up.

mighty ferry
#

Nah huge brain would of reupped before covid hit and testing became a PITA

night holly
night ether
night holly
#

CCNP big brain

#

I keep trying to do CCNA with Mike Andersons course but get bored after a video or 2 kek

mighty ferry
#

@night ether CCNP isn’t that bad, the TS exam is so so good at learning the material you need. If you can identify what’s broken and how to fix it you are we well on your way to passing the rest.

night ether
#

gotta use jeremy and keith

night ether
#

don't do networking anymore so don't see the need of going any further than ccna r&s

mighty ferry
#

Makes sense.

#

@night ether from what my colleagues have told me you will get a ton more mileage out of OSCP or CISSP unless you are trying to pigeon hole into Cisco security

night ether
#

as well as the guys the write the official study guides for ccna/ccnp, the content and the way they phrase it is sooooo good

mighty ferry
#

Nice! Good luck my friend!

#

I just started down the OSCP path been working on proving grounds and THM. PG was a bit too hard for me starting out, THM fit that middle e ground nicely.

night holly
night ether
#

awesome :) are you planning on shifting into security? or do you just like it as a hobby? (also let's continue in #infosec-general to stop flooding the #resources channel)

night ether
night holly
#

hmm okay I look, thanks 😄

urban badge
#

CCNP and CCIE are overkill unless you want to focus on network security

broken burrow
#

On a side note, the CCIE is currently free if you have the brains for that.

night ether
#

que

#

where did you see that?

broken burrow
night ether
#

oo

#

that's cool

#

you still need the core exam though for it

#

ie. the core ccnp for that track

broken burrow
light crystal
tepid patio
#

Non-monetary self promo 👀 But PyWhat 4.1.0 Bug Bounty Edition™️ just released 🥳

Now with:

  • 69 new regex for bug bounties 😏
  • Supports UNIX pipes (curl abc.xyz | pywhat) 🍕
  • New bug bounty mode designed to work with your flows 🔥

https://github.com/bee-san/pyWhat

GitHub

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️ - GitHub - bee-san/pyWhat: 🐸 I...

sturdy shell
#

Hello, does anyone have good recommendations for C? Crash course, practical, I'll take it 😄

orchid basin
# sturdy shell Hello, does anyone have good recommendations for C? Crash course, practical, I'...

freeCodeCamp got me through my Operating Systems course, but it definitely is intended for people just learning to program
https://youtu.be/KJgsSFOSQv0

This course will give you a full introduction into all of the core concepts in the C programming language.
Want more from Mike? He's starting a coding RPG/Bootcamp - https://simulator.dev/

⭐️ Course Contents ⭐️
⌨️ (0:00:00) Introduction
⌨️ (0:01:22) Windows Setup
⌨️ (0:05:02) Mac Setup
⌨️ (0:09:04) Hello World
⌨️ (0:12:51) Drawing a Shape
⌨️ (0...

▶ Play video
carmine furnace
#

Anyone that has given Security+ 601 can recommend which book to go with?

sturdy shell
odd sinewBOT
#

Gave +1 Rep to @orchid basin

sturdy shell
#

I'm doing very similar -- OS & embedded systems so 😳

orchid basin
#

I made the mistake of taking my OS class right after I had my Programming Fundamentals/Java course without knowing anything about architecture, memory, etc so a lot of it went over my head kekw

glacial gazelle
fast wraith
broken burrow
zealous void
#

Does anyone know good ansible courses?

gritty shuttle
#

@zealous void I don’t know about courses, but this book is amazing and helped me learn Ansible.

jagged tiger
odd sinewBOT
#

Gave +1 Rep to @jagged tiger

light crystal
#

@calm ermine

spiral zodiac
#

nice typo squatting huh

#

l vs i

#

good try

light crystal
#

heh

spiral zodiac
#

also uhh @hushed estuary

light crystal
#

check another channel

hushed estuary
#

hmm?

dreamy holly
#

nitro scam spam

hushed estuary
#

ah

keen temple
#

Is it ever gonna end?

hushed estuary
#

nope

#

did Esqy right-click ban?

dreamy holly
#

probably

spiral zodiac
#

it was a good typo squatting attempt should have tried a homograph attack kekw

light crystal
#

HEHEHEHE

#

lets talk in #general instead instead of here 😛

worldly palm
gritty shuttle
jagged tiger
#

Ansible is very widespread. Especially since the only real prerequisite is that a managed server has python3 installed

worldly palm
split mantle
tepid patio
thorny ocean
#

Does anyone have recommendations for OSCP/real-world machines to practice on? I think I've done all the ones Tryhackme has to offer, and all I have left are the straight up CTF machines.

night ether
#

hmm

#

oscp and real world are totally different so which are you after

thorny ocean
#

If I have to choose, then OSCP.

#

I just figured real-world would be closer to OSCP than CTF

topaz gulch
#

Real world infra pentesting is mainly AD

#

There is no AD in the OSCP exam

#

Or SCADA/ICS/IOT for that matter

topaz gulch
thorny ocean
#

A lot of them. I can go look and make a list. I even did a good amount of CTF machines before I got the feeling that it wasn't really helping me.

thorny ocean
#

I did the Pentest and CompTia+ paths, so all the machines associated with those

topaz gulch
#

That's about as close to an OSCP exam machine as you get in terms of style -- although not in terms of content (for obvious reasons)

#

If you can do that in under 4 hours, you should be good to go

thorny ocean
#

Right on, thank you very much.

#

I'm actually getting an error going to that link

#

I'll try manually searching

#

Weird, can't find it

topaz gulch
#

... Yes

#

Please ignore my inability to remember room codes for my own boxes...

thorny ocean
#

Lol

#

No worries, thanks for the suggestion.

little canyon
shut ferry
cold bay
gleaming wind
#

Thanks @shut ferry

odd sinewBOT
#

Gave +1 Rep to @spare finch

light crystal
#

PNG -> 89 50 4E 47 0D 0A 1A 0A

ZIP FILE -> 50 4B 03 04 or 50 4B 05 06

MAGIC BYTE

glacial gazelle
#

This is a list of file signatures, data used to identify or verify the content of a file. Such signatures are also known as magic numbers or Magic Bytes.
Many file formats are not intended to be read as text. If such a file is accidentally viewed as a text file, its contents will be unintelligible. However, sometimes the file signature can be re...

#

@light crystal 🤔

shut ferry
odd sinewBOT
#

Gave +1 Rep to @glacial gazelle

sudden fern
#

thanks @crystal slate

odd sinewBOT
#

Gave +1 Rep to @crystal slate

coral sentinel
#

oi, anyone have some UK based cyber sec online store they suggest for some cheap kit to dick around with?

light crystal
plush lily
fickle mulch
#

@mod

remote wind
#

Nice resource @glacial gazelle kekw btw, congrattzz

light crystal
#

swan u already have things 🤣

odd quest
autumn void
#

Can someone link me up with some resources to create VMs

fringe spire
autumn void
#

Thanks a lot

dawn oak
#

Can anyone suggest how can i improve my scripting? Like any practice platform or something?

split mantle
orchid basin
#

One of the things I do a lot is redo anything I'm doing in burpsuite repeater using Python. If I do it right, it's probably faster

dawn oak
odd sinewBOT
#

Gave +1 Rep to @orchid basin

dawn oak
odd sinewBOT
#

Gave +1 Rep to @light crystal

odd quest
shut ferry
odd quest
#

Quick trick to safely use netcat on low ports without sudo.
Capabilities are like SUID but more granular, you can assign specific permissions like binding to low ports.

spiral zodiac
#

iirc kali did something so non root users can bind to ports less than 1024

odd quest
#

Huh, that must be the version up from me

odd quest
spiral zodiac
#

Initially I thought Kali used authbind for this purpose, but after a bit of research I found that they modified a file /usr/src/your-kernel/include/net/sock.h

#

They changed this line which pretty much takes care of everything from there:

#
#define PROT_SOCK   0
#

The default value of PROT_SOCK is 1024 which is the normal port bind limit.

pine blade
odd quest
#

Capabilities are also great though

pine blade
#

Oh yeah for sure it's better to use caps over system-wide so you can have finer control

#

Also so you don't introduce security issues same thing goes for disabling aslr you should never disable it system wide and instead use setarch

split mantle
spiral zodiac
#

He means capabilities

plain gust
#

For scan open ports

topaz gulch
#

!rule 11

fervent summitBOT
#

Rule 11: No distribution of illegally obtained materials within the discord. Do not pirate books in #bookclub. This also applies to classified (or potentially classified) materials, which should also not be posted in the server.

topaz gulch
#

@shut ferryWhich part of that was difficult to understand?

night ether
broken burrow
odd sinewBOT
#

Gave +1 Rep to @night ether

balmy sun
#

^free PEH course

#

from TCMs server

shut ferry
#

Fortunately everyone ping is disabled nocooctus

haughty zinc
balmy sun
shut ferry
runic flint
bright lantern
#

Is anyone have this materials

shut ferry
#

Which one

glacial gazelle
#

all of them

dreamy holly
shut ferry
hardy peak
inland anvil
craggy onyx
fast wraith
azure widget
#

How to Take Notes Like a 1337 Hecker

  • It is important to note, haha note get it, that even with all of the solutions and new and flashy tools available for note taking, your own note taking should be very indiviualized and meet your needs.
  • These resources should also be prefaced by saying that I am a heavily biased towards obsidian, therefore most of my resources are centered around Obsidian, but can be applied anywhere. I will attempt to keep this updated as I encounter and collect other useful links
  • The first step to effective note taking is to identify what you need and why you need it,
  • From the LYT PKM Kit,

You don't need any of this. Just make notes and start writing. Worry about structure later.

  • Moving on from why and how to begin effectively taking notes lets talk about resources to get there.
  • Note-Taking Platforms by Category
    • Mind-Style Platforms
      • Trillium
      • Obsidian
      • Evernote
      • Roam
    • Automated/Synced Platforms
      • Jupyter
      • Joplin
    • Straight to the Point/Node-based Platforms
      • Notion
      • One Note
      • Cherry Tree
    • Unique platforms
      • Compendium Cards
  • Syntaxes and Languages to take notes
    • LaTeX
    • Markdown
    • HTML
    • MathJax
    • Mermaid
    • Just straight up notes dawg

Pandoc doesnt fit under this category but can be really helpful for converison

#

Posting this here as well because why not

light crystal
serene fossil
light crystal
#

@night plinth ^^

finite patio
robust notch
fast wraith
balmy sun
#

Found this really interesting talk by SANS about making digital alert-traps, y'all should check it out if you have time https://www.youtube.com/watch?v=KgQoGIkozL8

Relevant Course: https://www.sans.org/sec550
Presented by: Kevin Fiscus
Follow Kevin here: https://twitter.com/kevinbfiscus

The overwhelming majority of our defensive security solutions focus on the tools and technologies used by attackers. Unfortunately, as we have seen countless times in the past, when you pit static technology against a crea...

▶ Play video
balmy sun
#

@prisma bison ^might wanna remove that phishing post

#

or any other thm staff

fringe spire
#

they noticed

#

will be gone soon

balmy sun
#

oh. I hadn't noticed it was posting in every channel. MB!

late comet
odd quest
late comet
#

Oops, that's the reason I've posted here

#

Thanks for the correction

#

Fixing ...

serene fossil
prisma bison
#

Already pinged Muiri Sleepy

broken burrow
#

@hushed estuary @night plinth

#

RIP

#

Sorry, guys!

hushed estuary
#

??

prisma bison
#

Scam

#

It's gone Muiri got it

hushed estuary
#

Ok

dull barn
#

@shut ferry Response.
Yes. You can checkout this course from edx. It is from Harvard University.

https://www.edx.org/course/introduction-computer-science-harvardx-cs50x

It covers some computer programming foundations (don't get overwhelmed). From this you can actually learn how computer understands us.
Do checkout their other courses.

azure widget
topaz gulch
#

Esqy, don't let him do a talk about note taking smh

prisma bison
#

Nono

#

Let him

#

And if it’s bad, I get to ban him

topaz gulch
#

We require our speakers to be competent

prisma bison
#

C’mon Muirrrr

azure widget
topaz gulch
#

You wish smh

glacial gazelle
#

isn't cry american

#

:|

#

ay bruv

topaz gulch
#

Not an unusual state for him, I may add

glacial gazelle
#

poor guy

#

an identity crisis type of thing?

broken burrow
odd sinewBOT
#

Gave +1 Rep to @dull barn

light crystal
#

IG those are pirated books?

#

@balmy sun

balmy sun
shut ferry
#

Not sure where else to ask for help, but I’m experiencing major burnout, can’t even sit down for 30 minutes now to complete a few rooms or tasks without feeling tired or my mind getting occupied

Was able to sit down for ages and manage to get a lot more done but no idea how to get out of this rut I’m in

worldly palm
# shut ferry Not sure where else to ask for help, but I’m experiencing major burnout, can’t e...

It's easy to end up overworked and overtired, what with the state of the world and pressures of work and study. Are you getting enough rest, eating right and getting exercise? Those basics are important. Fresh air and sunshine - resting the brain and eyes.
Social media isn't helpful - make sure when you're having downtime, you're actually having downtime. Read a paper book, grow a potplant or something. I think it's important that our tech time is good quality - when you're working and playing in a screen-heavy environment, you need mental downtime, and save your screen+keyboard time for the important stuff.
... the other thing is, what's your motivation? Do you have a clear goal?

noble tangle
scarlet venture
#

The team Killer Queen is hosting their first CTF: Killer Queen CTF!

Killer Queen CTF will be primarily targeted at high school and college students featuring tons of challenges ranging from a beginner level of difficulty to ones that will test even the most seasoned competitors. It will feature all of our favorite categories including web, crypto, pwn, rev, and forensics with a variety of exciting topics such as quantum-safe cryptography that are not always covered by many other CTFs.

Killer Queen CTF will also be featuring a list of extensive prizes for both open and highschool division from top sponsors as well as a special prize for the top female competitors. Partnering with the WiCyS organization, we hope to increase the amount of participants and the diversity of our competitors so make sure to tell everyone you know to come participate!

Killer Queen will be providing a competition that is both great for new CTFers to learn and fun for more experienced players so regardless of your skill level, we'd love to see you come join :)

Max team size is 7 people.

Prizes:
High School Division:
1st Place - $500, Wolfram Award, and HTB VIP 1 year
2nd Place - $250, Wolfram Award, and HTB VIP 6 months
3rd Place - $130, Wolfram Award, and HTB VIP 1 month
4th Place - $20 and Wolfram Award
5th Place - $20 and Wolfram Award
6th Place - $20
7th Place - $20
8th Place - $20
9th Place - $20
10th Place - $20

Open Division:
1st Place - $500
2nd Place - $250
3rd Place - $130
4th Place - $20
5th Place - $20
6th Place - $20
7th Place - $20
8th Place - $20
9th Place - $20
10th Place - $20

Middle School Division:
1st Place - $50

CTF link: https://2021.killerqueenctf.org/
CTFtime link: https://ctftime.org/event/1482

We hope to see you all on October 29th for this exciting 3 day CTF!

#

For those of you more Junior Pentesters out there ^

shut ferry
odd sinewBOT
#

Gave +1 Rep to @worldly palm

broken burrow
#

I've been there before.

worldly palm
#

I agree, likely overextended. Focus on just one pathway. And maybe take a break - perhaps do some related lighter reading - something like Mitnick's Art of Inivisibility - for inspiration. Get more sleep.

tepid patio
topaz gulch
remote wind
#

currently, just slightly faster than gowitness, like around 5 seconds

#

for ~15 urls

broken burrow
tepid patio
glacial gazelle
#

actually, do THM sponsor many ctfs?

broken burrow
topaz gulch
glacial gazelle
#

yeah I know

#

I was more just asking generally

#

I rarely see their name of prize sheets, when HTB seem to appear everywhere

broken burrow
topaz gulch
tepid patio
broken burrow
odd sinewBOT
#

Gave +1 Rep to @tepid patio

glacial gazelle
#

was that government funded or something

#

I didn't hear about that

light crystal
tribal gull
icy marsh
#

Cool 403 bypasser with a big effort on UX

#

If anyone has any suggestions or opinions feel free to DM me or just tell me here

odd quest
# icy marsh If anyone has any suggestions or opinions feel free to DM me or just tell me her...

You're using a LOT of global variables. You should be passing those as parameters, especially URLs/ports etc.
Big ASCII banners have a lot of accessibility impact, damages UX horribly for screenreaders.
Variable names could be improved, and they're not PEP8 compliant.
You don't have a final else in your if elif block in banner() or main(). Also weird to use os.system() there when you could be using input(), makes it non-portable.

#

You could also swap to requests rather than urllib, it has a much more friendly interface for programmers

icy marsh
odd sinewBOT
#

Gave +1 Rep to @odd quest

odd quest
#

You're brute forcing methods? requests has get and put and patch and stuff so where's the issue?

icy marsh
#

I’m using way more and I want it not to be like 15 lines of just the requests

topaz gulch
#

Oh Jesus, yeah, if you're using globals like that, just go OOP...

tepid patio
# icy marsh https://github.com/sootier/403bypass

Think about "designing to do one thing". Each function is meant to do 1 thing, each class is meant to do 1 thing, each file is meant to do 1 thing (even if those things grow "bigger" the higher up you go) 🙂

I'd sep it into files so it's easier to navigate

I would also pin your versions in https://github.com/sootier/403bypass/blob/master/requirements.txt. One day one of those may upgrade and break your program 🙂 By pinning them like requests=0.6.0 you ensure it will always work and won't break due to unexpected upgrades 😄

icy marsh
#

I changed it a bit if anyone wants to take a look again, I did leave two functions with quite some globals but I removed quite a bit aswell and I think it would look worse to have tons of parameters on a function that is being ran quite a bit of times {banner func)

icy marsh
odd sinewBOT
#

Gave +1 Rep to @tepid patio

icy marsh
#

@hushed estuary

shut ferry
#
Leanpub

The Indie Python Extravaganza! A collection of books that will help you to improve your knowledge of the Python programming language one page at a time. Join four indie authors in a journey from the basics of Python to the structure of production-ready systems, going through the core features of the language, some intermediate projects and a dee...

#

These guys are providing free Python ebooks until the 31st

wet spruce
dreamy parrot
odd sinewBOT
#

Gave +1 Rep to @primal onyx

shut ferry
#

@odd quest upvote another one kek

odd quest
#

@topaz gulch totally new link

topaz gulch
#

Yep so I see

#

-undelete -a

balmy sun
shut ferry
#

https://www.youtube.com/watch?v=4d-qmWLt90E Would recommend this video if you are new 🙂

In coordination with the National Initiative for Cybersecurity Education (NIST NICE), I will be livestreaming a presentation and QA on how to get into cyber without experience.

Cybersecurity is an amazing field with significant opportunity, but individuals are often faced with the catch-22 challenge of needing experience to get a job, but unab...

▶ Play video
night ether
craggy onyx
night ether
odd sinewBOT
#

Gave +1 Rep to @craggy onyx

fast wraith
light crystal
#

The best thing you can do is forget about there being any sort of "pathway" or secret knowledge you're missing out on.
Learn everything you can about IT.

  • metastable state
shut ferry
#

I'm looking for some good learning resources (books/courses/videos) related to IOT security. Does anyone have any recommendations?

craggy onyx
shut ferry
#

Thanks @craggy onyx

odd sinewBOT
#

Gave +1 Rep to @craggy onyx

shadow imp
#

looking for good resource about msfconsole, anyone have?

odd quest
#

Metasploit Unleashed?

balmy sun
#

(interactive)

plain wagon
#

That's already in the pins I believe but it is pretty good

shut ferry
normal hazel
#

Good afternoon !! Newbie, here::🍴

fast wraith
shut ferry
#

Anyone have a resource for scripting filling out job applications?

#

I know there's some for scraping sites like Indeed with BeautifulSoup but was wondering if theres something similar with maybe filling out applications with Selenium?

tepid patio
broken burrow
tepid patio
shut ferry
#

It’s mad annoying and mad time consuming

fast wraith
#

probably not worth the hassle of adapting the script to all the various job boards that could pop-up, it takes like 5 extra minutes max to fill out that information manually provided your resume is formatted properly

#

also, if every application you send in is via the company website - you are doing something wrong, you should ideally be passing off your resume directly to hiring managers first

#

sometimes they'll come back and tell you that you have to fill out the company application first, thats fine but at least you're on the radar at that point

shut ferry
odd sinewBOT
#

Gave +1 Rep to @fast wraith

jagged tiger
#

^^^ That's why social networking is so key. It's really easy for a hiring mgr or recruiter to ignore things from people they don't know anything about

shut ferry
jagged tiger
#

IMO LinkedIn is hot garbage. Local meetups, SIGs, conferences, school, and work are where I met my most valuable contacts. From CISO down to admins, devs and soc analysts.

shut ferry
#

gotcha, understood

#

SIGs?

jagged tiger
#

Special Interest Group

shut ferry
#

gotcha, thanks for the insight @jagged tiger

odd sinewBOT
#

Gave +1 Rep to @jagged tiger

light crystal
shut ferry
young juniper
#

Hey

#

Hey

#

Anyone here knows a katoolin working repository

#

Most of the repos ...they use that key server that is gone down and other ones dont work with it

#

Please I'm currently on my ubuntu and want kali repos ...is there any other way than katoolin?

foggy kindle
#

You could try that.

#

Otherwise just download the tools you need on Ubuntu

neat pine
#

is there somebody who can tell me if its possible with amass to display the running service on a subdomain? struggling with it since yesterday...cant believe that there is no option for it :/

odd quest
#

So scan the IP?

neat pine
#

yes yes...i was just wondering about if amass is able to do that in one step right away...scan the domain for subdomains and give the subdomains back, INCLUDED the versions...i wrote a script to do it with python and nmap afterwards (nmap -v and so on). but if there is the possibility to do that within amass with a parameters seems more logic so i am searching if there is such a way to do it...

odd quest
#

Scanning for subdomains is a pain
It's either brute force, zone transfer, or dorking

broken burrow
odd quest
#

Zone transfer.

shut ferry
fickle mulch
tepid patio
#

ty

balmy sun
odd quest
#

Anyone have something about fully tearing out Defender on 21H1?

prime mantle
#

I am surprised at every minute of information in this video, it's just so so info-packed

#

@shut ferry thanks! didn't know I needed this, but it's pretty damn good

odd sinewBOT
#

Gave +1 Rep to @rapid eagle

shell cypress
tribal gull
#

If you're just starting in programming/infosec, here's a list of obvious and less obvious things you can put on your CV - a 🧵

Some of these things can be done in a week and might improve your CV.

Did I miss something? Please add to the thread.
And RT so it helps more people :)

Retweets

151

Likes

425

shut ferry
light crystal
#

thek society

#

but i still het u

shut ferry
icy geode
#

hi everyone

tender mauve
broken burrow
tender mauve
#

Bold claim. Gotcha

hushed estuary
#

https://youtu.be/MGt-DpYf30g Tips for countering impostor syndrome (in French from Devoxx FR 2021)

Qui n’a pas un jour prononcer les phrases :

j’ai l’impression d’être un imposteur ?

Je ne me sens pas légitime de faire ceci ou de faire cela ?

Certaines personnes sont persuadées qu’elles ne méritent pas leur succès, malgré les efforts qu’elles fournissent pour réussir. Elles s’auto-persuadent souvent que leur réussite n’est pas liée à leur ...

▶ Play video
orchid basin
south marlin
nova current
fast wraith
nova current
#

Sorry I mistyped the question

#

sir

#

Looks like I missed your class :(

fast wraith
#

Very good, I've taken it twice before, this one in particular is the updated course which is why I wanted to check it out - used to be 4 hours

nova current
#

That was Great. I am very curious to learn from your course.

#

I am very glad that I was speaking to the instructor of that course 🙂

fast wraith
#

I'm not the instructor lol, sorry for the confusion

nova current
#

Np 🙂

shut ferry
broken burrow
odd sinewBOT
#

Gave +1 Rep to @spare finch

jagged tiger
shut ferry
shut ferry
broken burrow
shut ferry
#

I starred it but yeah we never know :p

nova current
#

Hackerone
Calling all hackers! HACKtheMACHINE hosted by US Navy and powered by FATHOM5 and Booz Allen Hamilton, launches TOMORROW! With 3 tracks and up to $90k in prizes, the event offers bug bounty rewards and competitions to test your cyber skills. Register before it's too late! http://ow.ly/hO5C50GO0fi

HACKtheMACHINE

HACKtheMACHINE: Unmanned is the first in a series of public-facing technology challenges designed to accelerate the U.S. Navy’s Unmanned Task Force. This challenge will forge a community of partnership between the Navy, industry and academia for the creation of new high-end unmanned vehicle capabilities.

broken burrow
#

Except data science

nova current
#

It looks really awesome

tepid patio
glacial gazelle
#

wow, really useful post from this random guy I found

#

definitely recommend following said person

fringe spire
topaz gulch
#

It's usually fine, but if it happens to corrupt (and you don't bother taking a hashsum / don't have the tools to take a hashsum), you're gonna have a hell of a time figuring out why

#

This is literally the reason why base64 encoding exists

#

Also helps evade network monitoring, although you may need something stronger than base64 for that kekw

broken burrow
odd sinewBOT
#

Gave +1 Rep to @glacial gazelle

glacial gazelle
fringe spire
#

Type each letter manually 😄

broken sedge
#

hello, any resources on how to approach benchmarking and implementing a security/pen testing strategy for a platforms + infrastructures ?

supple adder
#

If you rename procdump.exe to dump64.exe and place it in the "C:\Program Files (x86)\Microsoft Visual Studio*" folder, you can bypass Defender and dump LSASS. https://t.co/Vk8vPYFTPC

topaz gulch
supple adder
#

👍🏿

odd quest
topaz gulch
#

Not in this directory tree certainly

#

Read/Execute

broken burrow
#

BlackBerry released a book on cyber threat intel today. Completely for free. Deals mainly with Cobalt beacons from my scroll through.
https://blogs.blackberry.com/en/2021/11/all-your-beacon-are-belong-to-us-new-blackberry-book-cracks-code-of-cobalt-strike-threat-actors

"Finding Beacons in the Dark: A Guide to Cyber Threat Intelligence" is the most comprehensive collection of cyber threat intelligence (CTI) focused on Cobalt Strike team servers ever produced. Learn what you can do to proactively protect your organization from the growing threat of Cobalt Strike Beacons and team servers from BlackBerry cybersecu...

#

Now you know why they stopped making phones. 😉

spiral zodiac
#

Yea, I already got a copy

supple adder
#

Whenever you end up on Okta login, click on "Need help signing in" just to see if there is any link to their internal wiki or helpdesk. I ended up on an IT helpdesk which had "Sign Up" enabled and got access to internal docs, passwords & what not. #bugbountytips https://t.co/W6yMm1pJLc

glacial gazelle
#

more self-promo

#

but for boot2root machines, so might be helpful here

broken burrow
glacial gazelle
#

(this isn't anything new, capabilities have probably been around for longer than I've been alive)

#

just haven't seen many people here use them before

violet tide
supple adder
#

Guys what is Cloud storage bucket used for

broken burrow
supple adder
#

Yeah

fast wraith
sand parcel
odd quest
#

Note: requires full license of burp pro

broken burrow
#

You can use the free trial.vent

glacial gazelle
#

I'll get the email real quick

broken burrow
#

It doesn't specifically state that anywhere. Hmmm...email? 👀

glacial gazelle
#

when I asked

broken burrow
#

Because from what I've seen, you could even attempt it without the license. You'd fail of course though. One of them even mentioned that they don't monitor it. You just need access to a valid license

glacial gazelle
#

Oh right, well by all means give it a go

#

the support email suggested otherwise

#

but it's only like 9 bucks, so is there any harm in trying?

#

worse that can happen is you pay the money, then you get to the exam and they decline you

#

which from what you said sounds unlikely

broken burrow
#

Mhm. It is 9 dollars so @sand parcel our guinea pig will do it and tell us how it goes lol

glacial gazelle
#

apparently it's rather hard...

#

I've heard that from two sources now, the 3 hours just isn't enough time

broken burrow
#

That email is vague and this whole thing is confusing because I've checked all the faqs, website info etc and it doesn't specifically state that you can't use the free trial

broken burrow
glacial gazelle
#

have you spoken to anyone who's passed?

broken burrow
#

Not yet but I could. Just need to go hunting lol

#

Easiest place to find them is LinkedIn

sand parcel
glacial gazelle
#

ah right, looks good cheers

topaz gulch
#

Oh, that's easy if they don't monitor it then.
I have my own version of collaborator on a VPS, and Adam made one for THM too which is on his github and easy to deploy :kekw:

barren vault
wet spruce
#
Humble Bundle

We’ve teamed up with Pluralsight for our newest bundle. Get software like Hack Yourself First: How to go on the Cyber-Offense & Security for Hackers and Developers: Overview. Plus, pay what you want & support charity!

shut ferry
#

A Nmap Cheatsheet

simple juniper
wet spruce
simple creek
#

Hey!
Does anyone here know how many days(maximum) would one have to give the Burp cert after purchasing it?

simple creek
odd sinewBOT
#

Gave +1 Rep to @broken burrow

marsh grove
stoic field
broken burrow
broken burrow
stoic field
broken burrow
stoic field
#

Hows it going for you?

broken burrow
stoic field
broken burrow
#

I sure hope so.😄

light crystal
marsh grove
fast wraith
shut ferry
#

networking icons 😄

#

and other icons

dense acorn
#

If anyone's still editing /etc/hosts with vim/nano – you deserve better! WokePepe hostsed

jagged tiger
#

this seems like a very unnecessary tool

azure widget
#

So it’s echo? But it only has one use?

orchid basin
#

It’s probably more annoying to use for CTFs too if you end up discovering a new vhost midway through since it doesn’t seem like there’s an option to edit an existing entry

#

Also, why are there 4 different aliases for the same function? I don’t mean to dunk on this too hard, because it was probably created with good intent, but this is excessive.

jaunty pulsar
fast wraith
#

awesome course, $10 is a steal - great for people looking to step up their networking and pivoting a bit
https://opsdisk.gumroad.com/l/cphlab/blackfriday2021

Gumroad

UpdateThis lab is best paired with The Cyber Plumber's Handbook which, as of September 6, 2021, can be found for FREE here: https://github.com/opsdisk/the_cyber_plumbers_handbook/Your purchase includes a PDF lab guide with 45+ exercises and 28 days of interactive access to a real live lab to practice SSH tunneling and port redirection techniques...

orchid basin
#

75% discount for students 👀

honest raft
#

Hi

azure widget
simple juniper
halcyon ridge
#

Is there a way to get a version of openvas that is 100% compatible with a known kali version?

#

not really sure where to ask this room seemed like the right place

tepid patio
shut ferry
#

resources for beginners?

#

helo?

glacial gazelle
#

@shut ferry check in #start-here or in the pinned messages I guess

shut ferry
#

cool

orchid basin
#

Keeps things cleaner, you don't want 100 different installs of tools you've only used once to bloat your machine.

jagged tiger
#

their website has fairly recently had a change to make it much less usable, though

halcyon ridge
# jagged tiger OpenVAS should be treated as an appliance, whether installed in a VM or on bare ...

I should have specified that my problem is more along the lines of getting postgresql to start on the designated web port 9392 or something along 9000s they may have more than just one don't quote me on that. Everything else works fine or rather was tweaked to work I am just curious because this seems very how would you say it...disorganized as each small tweak or detail can throw off the whole software solution, with that in mind does anyone actually use openvas like today or these days I get the feeling most people would just use exploitdb or something easier to maintain?

digital lichen
#

anyone know's how to create virtual machine like attackbox

shut ferry
#

Guys I need help devoloping a kernel exploit for windows any resources you would recommend

odd quest
broken burrow
digital lichen
odd quest
#

They're both XFCE

#

I'm sure you can find out how to do things with some googling

keen thunder
#

Hey guys is there any resources regarding hardware hacking in THM. Looking for the basics then building my way up. Looked at some LiveOverflow videos (GOLD). Mostly there are lectures on this which doesn't make me feel awake. Anywhere I could try them online?

broken burrow
broken burrow
keen thunder
odd sinewBOT
#

Gave +1 Rep to @broken burrow

topaz gulch
#

@serene fossil and how exactly is that a useful resource? chceyes

serene fossil
topaz gulch
#

More to the point, what reason could everyone else in here have to do so?

serene fossil
topaz gulch
#

Charming 🙂

night holly
gleaming wind
spiral zodiac
sterile frost
odd quest
sterile frost
#

thanks for the heads up, copied a second one that I didn't mean to post

regal pilot
fast wraith
ripe wasp
#

Does anyone have a Windows XP VM for practicing Pentesting/metasploit on?

sterile frost
solemn socket
#

if you happen to use unraid there's an xp vm option to install

fast wraith
shut ferry
#

Oh man this is great! Thanks

odd sinewBOT
#

Gave +1 Rep to @ripe wasp

odd quest
#

@ripe wasp @shut ferry Licensing on that is technically not legit. Deleting it.

broken burrow
shut ferry
#

microsoft pulled it out and now you can only get those starting from windows 7

broken burrow
#

Ah rip

shut ferry
shut ferry
#

Does anyone have any recommendations for a good way to obtain Security+?

jagged tiger
#

Study hard and pass the exam.

golden gyro
shut ferry
#

Thank you!

vestal swallow
#

Can somebody suggest me a good resourse to start web app pentesting ?

halcyon forum
#

Is HTS still a thing, its what i used way back when.

shut ferry
shut ferry
#

Webgoat

vestal swallow
odd sinewBOT
#

Gave +1 Rep to @atomic yoke

prime mantle
#

It's a handout to Harvard grads from what I know, I could be totally wrong, but hey, the doc is really nice.

shut ferry
prime mantle
#

damn, plagiarism or what lol

#

very similar content

#

either way, I just went through it, and felt that the Harvard doc is clearer to understand, whereas the Reddit one is kinda more like a human telling the approach, so depends on personal preference in the end.

frosty rune
#
Humble Bundle

Pay what you want to think like a hacker with this ebook bundle from No Starch Press.

atomic token
#

I have that bundle

#

If you're pretty new to everything they will have some helpful stuff

frosty rune
odd sinewBOT
#

Gave +1 Rep to @atomic token

frosty rune
#

Got 'em!

median meadow
#

anyone who can help me bypassing file upload?

fringe spire
shut ferry
#

Can anyone recommend good discord servers where writeups are posted related to bug hunting and Pentesting? Searching on medium is sometimes just exhausting

median meadow
#

thank ya tho ^^

fringe spire
median meadow
odd sinewBOT
#

Gave +1 Rep to @fringe spire

urban badge
#

If you have an account you can read the latest published bounties

#

Most of the time including pocs and stuff like that

#

Could be overwhelming at first tho

#

A lot of the hunters link there blog post related to the bounty in there to get a bit more explaination

shut ferry
#

In this Black Hills Information Security (BHIS) webcast, you will learn tools and techniques for performing penetration tests against Microsoft Azure environments. Increasingly, more organizations are migrating resources to being hosted in the cloud. With this comes a greater potential for misconfiguration if there isn’t a solid understanding of...

wet spruce
#

check out

hoary canopy
#

hi, what is a nice tool for keeping notes? (for attacking machines)

topaz gulch
hoary canopy
odd sinewBOT
#

Gave +1 Rep to @topaz gulch

sweet mountain
#

obsidian

topaz gulch
#

Notion you're at the mercy of the company not going down, but it's very pretty. Obsidian your notes are stored in plaintext markdown on your hard drive, so good luck when you start writing notes that trigger AV

#

(Spoiler: AV deletes them for you)

sudden fern
#

can't you just mark that folder for exclusion for the AV though??? even though that might be a security risk

topaz gulch
sudden fern
#

/dev/shm probably

#

but yeah if you can figure out what folder is excluded form the antivirus when hacking a machine that is a great spot to store payloads

topaz gulch
#

Get-MPPreference

#

Problem solved

#

Have the stager find the excluded directory, save all later stages there.

#

And you use AV on Linux..?

sudden fern
#

clamav

#

for files shadow shares with family and friends

#

so in a way both yes and no to that question... it is part of daily scan as long as shadow don't have that disabled... which they currently have

prime mantle
#

Very much like notion

#

rip-off but yeah

azure widget
#

you just mad Obsidian is better

shut ferry
broken burrow
tribal gull
broken burrow
tribal gull
#

cryptopals != cryptohack tho

shut ferry
#

MysteryTwisterC3 also cool

tepid patio
atomic token
#

Cryptohack, cool

#

Cryptopals was awesome

fast wraith
shut ferry
azure widget
#

Really isn’t

untold bramble
fast wraith
#

new drive-by attack via Windows URI handler, great write-up on bug hunting methodology too
https://positive.security/blog/ms-officecmd-rce

Chaining a misconfiguration in IE11/Edge Legacy with an argument injection in a Windows 10/11 default URI handler and a bypass for a previous Electron patch, we developed a drive-by RCE exploit for Windows 10. The main vulnerability in the ms-officecmd URI handler has not been patched yet and can also be triggered through other browsers (require...

sterile gale
#

Hey guys just wanting to know if there are any good guides on Red Teaming that assist in stealth when perform enumeration

#

more so IT/network enumeration not physical

uneven flume
#

Can you guys please fill out this google form, its for a school project

broken burrow
odd quest
#

@uneven flume Please ask for permission before sending survey links

uneven flume
odd quest
#

A mod here. Not by DMing them though.

uneven flume
uneven flume
odd quest
#

I'm one.
What class is it for?
Have you had an ethics review done?

uneven flume
#

its for a JOT case competition

odd quest
#

A what?

uneven flume
#

its for a friend, she's writing a report about laptop companies

uneven flume
#

she's writing a report

#

and she wants data

#

also wdym by an ethics review?

shut ferry
#

Hi guys! Now that Active Directory has become part of the OSCP I've written a guide on how to setup a lab for pentesting. This is just the setup, nothing about the vulnerabilities, but I'm expecting to cover some typical attacks in the following days.

If any if you finds it useful, then I'm happy!

https://shroudri.github.io/guides/setting-up-active-directory/

faint sluice
fiery bear
dark silo
gloomy helm
olive crypt
#

Two word-class experts of security – Paula Januszkiewicz and Mateusz Chrobok -will share their experience on event for tech leaders ‘A stormproof security strategy for your digital product’ on 14th December.
You are welcome to join them!
Take your free ticket here: https://hubs.la/Q010Cpsr0

fervent parrot
#

Roadmap for bugbounty

broken burrow
odd quest
#

NGL "Unbiased" and using 4chan templates strikes me the wrong way

broken burrow
#

Then leaves you to form your own opinion. Much better than our mutual friend from a few days back 🙂

jagged tiger
#

Subtitling 'by answering stupid questions' also doesn't indicate lack of bias

broken burrow
tepid patio
#

Russel & Norvig once defined artificial intelligence as "any modern technology". They talked about how all exciting & new tech was classed as AI, even if it didn't fit into the original definition of AI.

I feel the same way about Web3. All new & exciting web technology falls under this banner, even if it doesn't pertain the original meaning 🙂

#

Exact same thing happened with "Blockchain" in 2017. A lot of tech was named under that phrase even if it didn't need to be or it didn't fit. ICO mania spewed hundreds of scams. If you was a tech company you put "Blockchain" in the name to 10x your valuation.

Then all the silly uses eventually died out, and we mostly reserve blockchain for the real uses (all ledger related, of course. Mostly in cryptocurrencies, logistics, or any application where you need a really strong ledger. AWS has some great real world use cases here https://aws.amazon.com/qldb/customers/?pg=ln&sec=c#Driver_and_Vehicle_Licensing_Agency)

#

People just seem to find a new tech, try to implement it in every single way possible and eventually it finds its use cases 😄 (after all the bad ideas die)

broken burrow
#

Oh btw Bee, have you played around with WebAssembly and Rust?

tepid patio
#

i am doing a builspace course rright now haha

broken burrow
#

What? Me too! 😂

tepid patio
#

Ship your own custom NFT collection on Solana w/ Metaplex in a weekend

#

?

broken burrow
#

Oh that one. I suck at front end so I'm leaving it on the backburner for now but I could sign up for it too

#

I'm also shitty at Rust haha. Need to sit down and look at the syntax

tepid patio
#

i am also bad at frontend but i plan to learn it

broken burrow
#

I'm also trying to put aside learning React and see if I can do the same project in Svelte instead

#

Seems easier and better than React

tepid patio
#

react has so mnany blog posts / stack overflows

#

i think its easier to debug

broken burrow
#

But harder to learn in the beginning perhaps. Web3 in this context just applies to decentralised web apps so maybe we haven't seen much that doesn't fall under it but is classified as web3.

tepid patio
#

I'd class Mastodon as web3

#

decentralised, giving the power back to users

#

@broken burrow are u in any DAOs?

broken burrow
tepid patio
jagged tiger
#

would you consider microservices to be web3 then?

broken burrow
tepid patio
#

well

#

not your platform

#

a decentralised mesh of microservices anyone can contribute to, then yes

tepid patio
jagged tiger
tepid patio
#

one of the problems a lot of startups face is that people can fork them and just do it better, or you build something and in a weekend there are 500 shitty forks of your startup 😅

broken burrow
broken burrow
#

Look at what happened to Dapp tools

tepid patio
broken burrow
#

Paradigm made a faster rust based framework named Forge

tepid patio
#

sorry

#

erc-20

#

hahahaha

broken burrow
#

kekw No wonder I was confused

tepid patio
#

some startups are designed to be forked and worked on, like Loot project or Sandbox

broken burrow
tepid patio
#

ahhh I have great respect for Georgios

broken burrow
#

Georgios is a beast too though

broken burrow
# jagged tiger Is openness a requirement of web3? Instead of say, load balancing across multipl...

The premise of web3 is a decentralised internet owned by the people not just huge tech giants that control all the information so less censorship, little to no collection of PII and user data and ads unless the user opts in. That doesn't mean everything including sensitive information has to be public as there are off chain solutions for that and nothing sensitive or private should be stored on the blockchain. The video I linked explains it to some degree

craggy onyx
#

Let me throw one in: IPFS

broken burrow
#

Mhm.

tepid patio
#

i think single sign on is the biggest improvement I've seen

#

super simple to integrate

#

privacy orientated if u want it

#

just super simple

broken burrow
#

Ethereum and it's children(all the ones that came after it) also hit home the fact that cryptocurrency isn't meant to replace or really be a competitor to fiat currency. It's meant to fuel the decentralised ecosystem and implement faster transactions without a middle man to restrict the transfer to certain countries/slow them down

#

Oh btw @tepid patio did I mention that the Foundry actually lets you write tests in solidity not JS or python?

tepid patio
#

i need to do some more non-buildspace stuff

tepid patio
#

fintechs succeed because they are tech based (compare to old banks which are not). it means we have a lot of automation in place that can cut down costs, time and other things to make it better for the user.

defi is the same but for finance, just more automation 😄

#

https://www.gro.xyz/ is one of my personal faves for this

Gro protocol is a stablecoin yield aggregator that tranches risk and yield. The first two products built on it are the PWRD stablecoin with deposit protection and yield, and Vault with leveraged stablecoin yields.

#

their tranche system is p/ cool

broken burrow
#

I can barely finish Damn Vulnerable DeFi as it is haha

tepid patio
#

I’ve never done defi security

#

I wanna get into hft tbh

#

So much fun

broken burrow
tepid patio
#

High frequency trading

broken burrow
#

DeFi/Blockchain security is actually why I've learned blockchain dev

#

My friends have told me multiple times that I can't audit a smart contract if I don't know how it works. I didn't listen so I found out myself when I everything looked like gibberish in a CTF. 😆

#

I've started to love dev though

tepid patio
#

Auditing is big big money haha

broken burrow
broken burrow
tepid patio
#

Well, for a hedge fund preferably

#

It is basically day trading

#

You actually get all the money if you’re the fastest lmao

#

The problem is figuring out how to be fast

#

Risk free too if you can figure out that

#

Arbitrage it’s called

#

I just love the idea of writing code and optimising it and the hardware to be as fast as physically possible

#

And to play with the real world financial markets

#

“Flash boys “ is a good book about this

#

And “flashboys 2.0” is the blockchain white paper exploring this too

broken burrow
#

Flash boys looks suspiciously similar to flash bots

broken burrow
tepid patio
tepid patio
#

It’s really hard to get into it as everyone else has billions

#

To work with*

#

Ideally I’d work for a hedge fund or a quant firm

broken burrow
#

Seems like a good project.

#

I'll add it to my ever growing list

broken burrow
tepid patio
#

An example is laying a fiber optic cable@from one side of the US to the other just to experience 18ms faster latency

broken burrow
#

Of course. I'm assuming there'd be some application of front running when it comes to implementing this in the blockchain world so you'd better have enough gas on hand. 😆

tepid patio
#

Front running is actually a HFT attic haha

#

Attic

#

Tatic

#

You can protect against it in the stock world by using the IEX exchange

#

Or by trading exclusively in darkpools

#

Which you can do neither of as you’re not a hedge fund lol

broken burrow
#

👀In a gc a few days back someone mentioned a protocol that offered 5 or so % yields in staked funds every 8 hours so they were thinking about taking out a flash loan a few minutes before the stake ended.

#

I've not seen it tested but it seems relevant to the discussion.

broken burrow
#

I'm not sure how flash loans work but it seems like it could work in practice

tepid patio
#

Flash loans exist for 1 transaction block

#

You’d have to be in the same transaction block as the payout

#

It’s possible but unlikely to time it perfectly

#

If you used an oracle to time it too you’d be paying for that also 😦

broken burrow
#

Interesting

sterile frost
pure heath