#resources

1 messages · Page 16 of 1

jagged tiger
#

Yes. Humble Bundles are legit. They work with the publisher to establish a baseline, and you get to adjust how much of your money goes to which party (publisher, humble, or the charity).

odd sinewBOT
#

Gave +1 Rep to @jagged tiger

odd quest
#

@hearty forge This is advertising at this point, it's not a cybersecurity related resource, it's a clothing store.

hearty forge
#

research about it please 🙂

#

Thanks and apologies James

odd quest
hearty forge
#

alright, sorry.

hearty forge
#

If you're interested in learning Reverse engineering. for beginners: https://youtu.be/D6mVIos-S2M

An introduction to Reverse Engineering & OllyDbg tutorial, a behind the scenes of malware analysis, and using tools like Ollydbg. As a practical example we'll be looking into the first giveaway challenge on TPSC's Discord server.

🔥 Buy the best antivirus/security products with exclusive discounts and support this channel:
https://www.thepcsecur...

▶ Play video
inland berry
#

Hello all, I kinda feel bad posting so soon but we have great event that is free for virtual attendees. If you are in data analytics or data science or in product development you know the pains of getting the right data when you need it. You either get a massive data dump of all the data including PII that you don't need or want or you get Dr. No'd because the data base has PII that they can't share so the just block the whole database.

As data governance and policy management get modernized this will be easier and give your teams the data agility they need to move fast and do it securely so you remain compliant. Anyways, I digress. The event is called AIRSIDE. We have an in person element in NYC at the TWA hotel and the virtual experience.

https://airside.live/2022/virtualexperience

We have great speakers from FINRA, Yotpo, Snowflake, Capital One, Amazon Web Services(AWS), Kyndryl, Slalom, DataOps.live, The World Bank, Collibra, DataWarrior, Bill.com, Cooley LLP, Splunk

If you have questions let me know. Happy to discuss more.

iron shadow
ionic eagle
#

I am trying to level up my personal notation skill for taking notes and document my knowledge and new stuff I learn. I was wondering if anyone has a recommendation for a service/app for organizing personal notes. Would love to hear what you guys use and don't forget to include why you recommend it. 😀

steep skiff
#

I just began using obsidian as well

ebon lodge
#

I like cherrytree ngl

#

But obsidian does have some cool features

finite patio
stuck abyss
sturdy shell
sturdy shell
#

not sure who the resource is for - curious minds maybe? But I'm quite proud of it and my masters thesis extends this into using ML and dynamic analysis

modern dagger
#

It does't have to be tryhackme specific b ut I'm not on my work machine so I was wondering if there any documentation or modules that I can just read while I'm at work

empty tusk
modern dagger
#

cool beans, ill take a look

urban void
shut ferry
#

heyo!
Microsoft cloud challenge starts soon - today, and free exam vouchers are waiting for you:

AI-102: Designing and Implementing a Microsoft Azure AI Solution
AZ-204: Developing Solutions for Microsoft Azure
AZ-220: Microsoft Azure IoT Developer
AZ-400: Designing and Implementing Microsoft DevOps Solutions
DP-420: Designing and Implementing Cloud - Native Applications Using Microsoft Azure Cosmos DB
MS-600: Building Applications and Solutions
PL-100: Microsoft Power Platform App Maker
PL-200: Microsoft Power Platform Functional Consultant
PL-300: Microsoft Power of BI Data Analyst
SC-200: Microsoft Security Operations Analyst
SC-300: Microsoft Identity and Access Administrator```
https://www.microsoft.com/en-us/cloudskillschallenge/build/registration/2022?wt.mc_ID=Build2022_corp_soc_oo_tw_MFSTLearn_5_10
stuck abyss
#

There's a few there I don't have.

I'll need to get them.

shut ferry
#

I cannot decide which to get, haha. The one which seems most fun is also least useful for me, but maybe that is the purpose of the challenge, to explore fun stuff.

stuck abyss
#

@jagged tiger

jagged tiger
#

Lets not post resources that contain illegal stuff, mmkay? @azure bolt

#

It's also hard to moderate content as part of an archive. If it's something that's available on github, just post the link to the repo please

dull gorge
#

It's all shit about carding, there is literally no legit use for this. Stop trying to peddle it.

dull gorge
#

I mean stop trying to share this around servers meant for learning ethical hacking, not fucking stealing credit cards

#

this is not a cyber crime discord

#

go away

jagged tiger
#

If it contains any content that deals with stealing CC info, that's definitely illegal.

#

No

#

No it would not

dull gorge
#

Dude stop

#

You're sharing tips on how to commit crime. Also wouldn't be surprised if it was backdoored

jagged tiger
#

That's not how 'stealing your own card info' works.

dull gorge
#

We do because again this isn't a cyber crime discord

#

Go to 4chan or something

jagged tiger
#

Zepher, please stop. Thanks for pointing out contents though

dull gorge
#

Again, learning. Training.

#

RIP. Thanks Juun 👀

odd quest
#

https://www.youtube.com/watch?v=_mZBa3sqTrI You think you know plaintext?

Software is complicated. Machine learning, microservice architectures, message queues... every few months there's another revolutionary idea to consider, another framework to learn. And underneath so many of these amazing ideas and abstractions is text. When you work in software, you spend your life working with text. Some of those text files ar...

▶ Play video
balmy sun
#

^Can confirm that's a really good talk

turbid badge
#

After 6+ months of juggling full time work and bootcamp assignments, I’m working on my final presentation to showcase my learning and skills. Could anyone recommend a tutorial on how make a nice, interactive PPT/ video presentation? Many thanks!

ionic vault
#

Hi all. Can someone help me with a sample/template OSINT report for reference? I am preparing my first one and would appreciate any help. Thanks

finite patio
#

(ISC)² is offering 100,000 free exam vouchers for the (ISC)² entry-level cybersecurity certification exam bundled with free enrollments in the (ISC)² entry-level cybersecurity certification online self-paced course.

Note: Only UK residents ages 16 and older are eligible to participate in the program.

https://cloud.connect.isc2.org/100K-inthe-UK
please, make use of this free opportunity

Admin, this is not a self-promotion post.

icy marsh
tacit burrow
#

@icy marsh blessed sir

#

Come be

#

With me

#

And vc 😉

#

#Bars

stuck abyss
icy marsh
#

Not in the UK

stuck abyss
#

Ah, so it's locked to UK.

#

I didn't check it out, an unverified user posting a link is super sus imo.

icy marsh
hearty forge
azure widget
steep skiff
#

this was my best logical choice to ask the question, but does anyone have a resource to set up a linux server through vm so i can basically set up my own lab?

kind trout
#

You can get Ubuntu server and run it as a vm

steep skiff
#

not spending all night again fighting it, so thank you i'll begin researching it agian in the morning

static veldt
dense fable
#

Hello everyone ! Does anyone have documentation on polyglot files to understand how it works ? It seems really interesting

steep skiff
odd sinewBOT
#

Gave +1 Rep to @kind trout

kind trout
#

np

left granite
odd sinewBOT
#

Gave +1 Rep to @static veldt

static veldt
odd sinewBOT
#

Gave +1 Rep to @left granite

onyx vapor
#

https://www.upskillcyber.co.uk/candidates - UK Only sponsored 10 week course
There's some conditions such as not having/pursuing a cyber security related certification or degree etc. so make sure to check if you're eligible but, from what a mate said, completing it gives you the following certifications: GIAC Foundational Cyber Security Technologies (GFACT), GIAC Security Essentials Certification (GSEC)
Don't know if it's useful to anyone but thought it might be worth sharing

ebon jasper
#

Studying for the OSCP and would like to learn of alternative methods to metasploit. Anyone able to recommend a blog/articles that detail the use of tools outside of MS to get reverse shells/drop executions?

#

Tbh I’m still learning how to get into boxes but I assumed that metasploit still handles payload and handler info? Like even if I got the script outside of MS, I’d need to use msfvwnom to generate the reverse shells?

#

Def my lack of experience but THM goes hard into the MS ecosystem so I don’t know much outside of it

#

That’s a neat site , looking at it rn

#

Interesting. If that’s the case why not allow MS at all then? If I can still use the scripts stored in its framework?

#

The more I learn the more I discover I’m still a script kiddy lol

#

Which also happens to be owned by offensive security 🤔

#

So searchsploit is still g2g then? Seems just like more work for the same payoff

#

Sure thing

odd quest
#

With plain shell payloads yes, not with meterpreter payloads

ebon jasper
#

Another question, would any have a guide on learning about reverse engineering? I think? My use case is;
Given a closed source program, it encrypts a 6 digit code with DES, and outputs it as a proprietary file format. How can I learn to view the encrypted content to then attempt to brute force the code/key?

vocal shore
shrewd mist
spring wren
stuck abyss
#

No access to materials or labs though.

lucid edge
#

Also the course to be stream is 1.0 version, now i guess we're at 2.0 after 1-2 changes in curriculum

#

Btw i had a question to experienced people here in Infosec. I just completed my university exams, and today i resume hacking studies for oscp. Should i contribute 5 hours to network Pentesting and 5 hours to Pentesterlab badges in a day? Is it a good approach?

#

Or do i need to make any changes to this? Any suggestions are welcomed

hushed estuary
#

10 hours per day is a lot

stuck abyss
lucid edge
# hushed estuary 10 hours per day is a lot

I want to just get oscp done with before the end of this year. I have started preparing two times till now but had to quit due to university shenanigans. But my exams are over today so might as well buckle up and get started with oscp prep

hushed estuary
#

Yeah but don't burn out 😉

lucid edge
lucid edge
#

Btw for people who have done some exercises/acquired some badges. What path/badge should i start with? Essential badge or HTTP badge?

stuck abyss
#

@prisma bison

prisma bison
#

-ban 729595049347907594 -ddays 1 Soamming twitch, not here for THM

odd sinewBOT
#

🔨 Banned ItsMe#9384 indefinitely

coral loom
#

@sturdy shell

shut ferry
stuck abyss
#

This could be useful for anyone.

graceful mountain
stuck abyss
graceful mountain
simple juniper
# graceful mountain why not share the tweet link so people can directly check it out <:lemonthink:81...

We're going to livestream our PNPT training on Twitch.

No masquerading. No requirements, or additional benefits, to purchase any of our materials.

Just free hacking

Even better? If you attend every session, we will give you the 5 PNPT courses free when we're done

Details soon

Likes

879

Retweets

165

odd sinewBOT
#

Gave +1 Rep to @simple juniper

lucid edge
odd sinewBOT
#

Gave +1 Rep to @mighty gazelle

lucid edge
balmy sun
#

Any practical oriented syzkaller tutorials out there?

#

Kernel fuzzing is new to me and I'm barely getting into linux subsystems to the point where I can make a few misc kernel modules

#

But kernel fuzzing seems far away

empty tusk
#

For anyone interesting in the CCNA

plush lily
#

Hi all, I'll be streaming a walkthrough of Bravery from the Digitialworld series (VulnHub) on 17 June. The machine is available for everyone to download and deploy themselves.
https://www.vulnhub.com/entry/digitalworldlocal-bravery,281/
I really encourage those who are currently enrolled or plan on taking the OSCP to tune in as I'll be using this to demonstrate how one should approach the machines in the labs and the exam.
Hope to see you everyone there!
https://discord.gg/CZC54puC?event=984942367377334322

iron vine
#

Hello all, just joined and relatively new to all this! I'm looking for the 'Find command' room for linux. Looks like it was previously here https://tryhackme.com/room/thefindcommand but no longer available. Anyone know if it has been moved somewhere. I tried searching for rooms using 'find' but cant locate anything similar. Thank you 🙂

visual aspen
iron vine
#

Ah that looks ideal, thank you 👍

simple juniper
iron shadow
#

hey,
I have a question regarding the registry
as an upcoming (hopefully 😅 ) cyber security personnel I probably will have to investigate IOC's
and one of them is Registry
is there a blacklist of malicious keys/values ? that should raise a suspicious, as each software creates its own key it can be hard to know what is legit and what could be malicious

  • while writing that question I can to the realization that maybe it is better to go by a whitelist instead of a blacklist as it is probably more practical
    so check whitelisted keys and if you see some key that is not in the list it could be analyzed for a final conclusion
night night
#

This a personal project for creating a large resource for aspiring hackers to learn any aspect of hacking from. Growing every day

burnt sinew
#

Looking for good resources about storing confidential data in corporate environment. More likely about types of storage, backups, restoring confidential data, policies about storing data and etc... can be a book also

shut ferry
#

For anyone looking for a hands-on interactive way to learn AWS

balmy sun
#

what are yalls favorite blogs for vuln research and binexp?

icy marsh
icy marsh
#

^^Awesome study! Read the PDF!^^

ebon jasper
#

Pretty dope cheatsheet for quite a few items

lucid edge
#

Hey! Can someone tell me how to get started with code reviews? What prerequisites are required?

ebon lodge
#

I have this table

shut ferry
#

Does anyone know a good resource for learning Cloud interactively? I appreciate the plethora of videos but would prefer to learn by actually using it

simple creek
sudden fern
#

4 year old script???

prisma bison
#

Are you sure that's OSCP friendly?

rough wigeon
ebon jasper
#

Anyone have a good resource for learning hydra? This shit is so cryptic for some reason. Specifically learning to brute login forms

orchid basin
#

Don't want to be that guy, but just read the documentation 🤷‍♂️

#

And if that doesn't work, you can always google something along the lines of "thc-hydra guide" or "thc-hydra ctf" and see how people use it. I'm sure there's also a hacktricks page including it.

stark wigeon
#

Hi guys,
Does anyone have a good resource / good place to start on av killing techniques or uninstalling?

shut ferry
odd quest
lunar bay
lucid edge
#

Hey! Just started learning buffer overflows. Just wanted to know if there's any prerequisites to learn before starting it?

#

I just don't want to be lost while learning it. So i am trying to learn the prerequisites first

ebon jasper
lunar bay
ebon jasper
#

Not sure, but I believe the specs are posted online

odd quest
#

@ebon jasper @lunar bay There's Turbo Intruder whoch I haven't tried, and there's ZAP. They're both much better than Hydra for anything even slightly complicated when you're dealing with http logins.

shut ferry
median ore
#

anyone know a good website for documenting resources on the website for studying?

twin grotto
faint bridge
# median ore anyone know a good website for documenting resources on the website for studying...

I use Obsidian to take notes, really cool and powerful tool (and free too!). It allows you to connect your notes and view them in a graph view, if you're the visual type it will help very much in memorizing the connections between different topics. If you are not familiar with Markdown you'll have to learn the syntax, but I think it is pretty easy to catch up with the basics, after that you won't want to use anything other than this for taking notes I think - at least this is the case for me:) https://obsidian.md

balmy sun
#

Does anyone have good resources for learning syzkaller?

median ore
odd sinewBOT
#

Gave +1 Rep to @faint bridge

median ore
#

much appreciated

#

I was looking for obsidian specifically after seeing someone use it and didn't know what the name was but this is it so thank you :D

shut ferry
#

It's pretty cool..

lucid edge
#

Hey is anyone aware of errors in Spike package in ubuntu? I want to use it on Ubuntu but my spike script always produces an error called undefined symbol s_readline() or any command i write

shut ferry
#

I just started THM and realise I need to change my note taking setup. Right now I use a free StandardNotes accounts. But I'm missing inline images and maybe syntax highlighting. What do you guys use? Anyone got experience comparing Obsidian to StandardNotes?

graceful mountain
shut ferry
#

ah thank you, I'm new to discord aswell, feeling slightly overwhelmed atm 😉

burnt parrot
jagged tiger
#

The one real advantage that digital notes have over pen and paper is cross referencing and tagging notes

odd quest
#

Searching too

#

Control F through your handwritten notes, I dare you

shut ferry
fiery bear
#

Ew medium link

shut ferry
#

learn > b*tch

fiery bear
lucid edge
#

Hey i am learning buffer overflows through vulnserver. I am not getting a shell even after running my exploit script with the shellcode. Vulnserver is getting a connection but the shell is not coming through in nc

#

Any help?

#

My python script

plain wagon
#

Is this a Tryhackme room?

tribal gull
plain wagon
#

Yeah, I was just asking because if it was a room then #room-hints or #room-help would have been where I would send them, but thanks

stoic field
odd quest
#

-ban @zealous raptor -ddays 1 Nitro phishing. Secure your account and then appeal this ban by emailing bans@tryhackme.com

odd sinewBOT
#

🔨 Banned Thek41234#3878 indefinitely

lucid edge
lucid edge
odd sinewBOT
#

Gave +1 Rep to @tribal gull

gleaming wind
stoic field
stray fossil
#

A while back I had my hands on a huge database dump. I ventured into a lot of hashcats' features and advanced options in an attempt to crack as many of these hashes as possible. Here is a run down of the stuff I found very useful.

Happy cracking!

https://www.youtube.com/watch?v=m5Ix94hbzaU

brazen sequoia
#

@gaunt needle Did you read the channel description?
Please avoid self-promotion of paid content here.

nova current
#

@hushed estuary sorry for the ping

sudden fern
odd quest
#

@undone belfry please stop self promoting

#

You have 7 messages in this discord, now 8. They've mostly been self promotion or arguing when we ask you to stop. Please stop otherwise you will be banned @undone belfry

sudden fern
tranquil grove
#

Does anybody know or have any good resources on Crowdstrike, on how to query it?

bronze sluice
#

Does anyone know what to do if you’re logging into kali Linux on your VMware virtual machine and you randomly get the error unable to contact settings server when you try to login

polar karma
#

https://www.microsoft.com/en-gb/events/training-days/
another az-900 and sc-900 free training + exam(free voucher) starting soon

stoic ingot
tranquil grove
#

Does anyone have any good splunk or crowdstrike resources, cheatsheets outside of what thm offers? Or any tips and tricks from somebody experienced with these apps?

gloomy oar
#

To help companies implement threat hunting for #log4j everywhere, I have updated my open-source log4j bypass tool to search for many more bypasses and to be much easier to use.

You can find the link below! Please feel free to use in your work and share!

https://github.com/cyberqueen-meg/log4j-bypass

GitHub

Contribute to cyberqueen-meg/log4j-bypass development by creating an account on GitHub.

icy marsh
#

NDC conferences are just amazing! They have some classics like The Art of Code and loads more! And my favourite thing is that every single talk is uploaded to their youtube, meaning they have 1000s of talks about literally everything! High recommend!
https://youtube.com/c/NDCConferences

fallen zephyr
#

Hello, I want to learn assembly for reverse engineering and malware analysis, can someone point out a good resource for that? Any dialect will work, I just need to get my hands dirty

tranquil shuttle
tranquil shuttle
brazen sequoia
tranquil shuttle
#

though seems to be working for me

brazen sequoia
odd sinewBOT
#

Gave +1 Rep to @tranquil shuttle

odd sinewBOT
#

Gave +1 Rep to @tranquil shuttle

tranquil shuttle
remote wind
#

@fallen zephyr

summer plinth
#

Learning AWS
Does anybody have experience with a good resource to learn AWS, for advanced Linux users with knowledge of basic networking and so?
I will try Udemy, Youtube and online tutorials, but if anybody have experience with some particular resource being good, and not for total (Linux/networking) beginner.

versed spire
tranquil shuttle
tranquil shuttle
odd sinewBOT
#

Gave +1 Rep to @versed spire

lethal wind
odd sinewBOT
#

Gave +1 Rep to @tranquil shuttle

tranquil shuttle
thick herald
summer plinth
tranquil shuttle
#

no problems and yes its most probably the cloud fundamentals one its a preety good primer for their more vendor specific courses like AWS, Azure

coral loom
#

Welcome to the book of tricks, hacktricks contain notes, guides and cheatsheets for a whole lot of areas in cybersecurity, what it be escaping sandboxes, creating shells, image forensics, you name it, they have a little of everything.

https://book.hacktricks.xyz/welcome/readme

Welcome to the page where you will find each hacking trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

lime phoenix
brazen sequoia
south marlin
tawdry bridge
vast pine
#

Shell Job Control / Basic File Operations / Directory Operations / File Viewing / File Creation and Editing / File Properties / File Location / File Text Manipulation / File Compression and Packaging / File Comparison / Printing / Spell Checking / Disks and Filesystems / Backups and Remote Storage / Viewing Processes / check / Controlling Proces...

tepid patio
#

this is cool from @remote wind

#

PyWhat's Rust counter-party, LemmeKnow, as a website 😄

deep abyss
sonic abyss
stone mulch
sonic abyss
#

page not found (?)

empty tusk
#
empty tusk
odd sinewBOT
#

Gave +1 Rep to @sonic abyss

sonic abyss
#

Credit to @orchid basin this is amazing ^

orchid basin
#

Credit to 7oaster who isn't in this server lol

#

I just found him post about the fact that he made it

tawdry bridge
tepid patio
mild ermine
#

INE has some great content for cloud and aws if you want to try those