#general

1 messages Ā· Page 9 of 1

molten sky
#

if you want cheap

buoyant tree
#

eh the 75$ one is within my budget range

#

thinking if i could score a better router for the same price in good quality used

molten sky
#

i've got a $1000 fortigate sitting under my desk and i still use the $30 archer, lol

#

well, more accurately, like four of them (the archers, not the fortis)

rapid merlin
#

Only need one.

buoyant tree
#

what's a fortigate

molten sky
#

firewall appliance

rapid merlin
boreal scarab
#

That new marvel movie...... horrible. The acting is piss poor, and the story is just so cliche

rapid merlin
#

Movies nowadays are pretty boring.

buoyant tree
rapid merlin
blazing granite
molten sky
#

haven't seen a movie in ages

#

i'd rather be fishing or something tbh

buoyant tree
#

watch a good movie now

rapid merlin
boreal scarab
# rapid merlin Like always.

End game was good, but this one was like "If you do X, you will be X" Like breh.... think we all got that, why the fuck put that line in?

molten sky
rapid merlin
buoyant tree
#

so u havent played any of the modern masterpieces

buoyant tree
rapid merlin
#

I am not interested in playing video games.

molten sky
#

modern masterpieces? not many nowadays

rapid merlin
#

It's not for me.

buoyant tree
#

I couldn't sleep today because I kept reading Harry Dresden

buoyant tree
rapid merlin
#

I tried playing games one time after 10 minutes I got bored, so I stopped and never played since then.

molten sky
#

good publisher for classics

#

cheap clothbounds

buoyant tree
#

eh I do e-books

molten sky
#

(instead of the normal plastic crap)

buoyant tree
#

cheaper and better

molten sky
molten sky
blazing granite
# buoyant tree eh I do e-books

I love e-books because I can carry around a lot of books in my kindle, I moved a lot, I lived in 4 countries, shipping books it's expensive, I have around 1000 books in my mum's home

buoyant tree
#

I got a kindle atm

#

planning on upgrading to a kobo

rapid merlin
#

I only use pdf's (ideally).

buoyant tree
#

eh epub's for me

#

I don't like pdf's

#

too much like reading images

rapid merlin
#

You can have images in pdf's.

blazing granite
#

epub FTW šŸ™‚

rapid merlin
#

Frankly I also don't care which medium it's in. As long I can actually read the book.

buoyant tree
#

yea

#

what books u been reading lately

rapid merlin
#

There is like at least 15.

#

Mainly IT related and 2 about genetics (personal interest).

buoyant tree
rapid merlin
#

I do read philosophy here and there (mainly logic stuff but that's about it).

buoyant tree
rapid merlin
buoyant tree
#

been reading a lotta books on that also lately

buoyant tree
#

great examples

rapid merlin
# buoyant tree U read how i rob banks and other such places

I haven't read specific works on social engineering, but I'm deeply interested in psychology in general. I mainly focus on understanding the fundamental aspects of the human psyche, the ego and common issues that many people face. I find that understanding these principles helps me make connections with social engineering concepts. You can also build frameworks.

blazing granite
twin ridgeBOT
#

Gave +1 Rep to @blazing granite (current: #152 - 41)

rapid merlin
rapid merlin
#

Did any of you watch Mr. Robot? People talk a lot about it.

#

I won't watch the show I just need to know the whole backstory and how it ends.

molten sky
#

i didn't but the family enjoyed it

#

i have a feeling it'd be like being knowledgeable about firearms and watching an action movie, where everything it just glaringly and unimaginatively wrong, ruining it, so i haven't actually watched it yet

buoyant tree
#

kevin mitnick style book

rapid merlin
#

Sure, I will take a look at it.

molten sky
#

everyone i know that's watched it (not in the tech space) has enjoyed it though, never heard anything bad

torpid ether
rapid merlin
tardy wraith
#

Hey can anyone recommend me a box to practice linux privilege escalation that is relatively hard

molten sky
#

if you're ready to do harder stuff i recommend adding HTB to your repertoire as well

#

generally less hand holdy than THM

rapid merlin
molten sky
#

^

rapid merlin
#

You need to have the right mindset.

molten sky
#

agreed

rapid merlin
#

But it's a very good platform.

tardy wraith
#

OKay thanks i will look into it

blazing granite
rapid merlin
sinful moon
#

It’s a FREAKING SUPERCOMPUTER on a single chip

rapid merlin
sinful moon
#

lol, 00 were a different time

buoyant tree
sinful moon
#

Got 800Mhz PIII in my Win 98SE machine

rapid merlin
#

I like that era, especially JDM wise.

sinful moon
#

Agreed for sure!

rapid merlin
#

Some of the finest engines ever developed during the 90s.

sinful moon
#

lol the Night Boys or whatever in Initial D use Dell XPS machines just before my 99 model

blazing granite
rapid merlin
#

That's where I learned about the 1jz,2jz,RB25, RB26 and so on.

#

Tuning nowadays is garbage though.

sinful moon
#

Can highly recommend Initial D, especially for the 90s/00s cheese. Dat eurobeat, and yeah they do go all out on the car tech, even if it’s sometimes fantastical

rapid merlin
#

If I ever decide to start watching entertainment, I'll keep that in mind thanks.

blazing granite
rapid merlin
sinful moon
rapid merlin
#

All my hobbies are IT related aside working out.

sinful moon
#

Exposing yourself to more hobbies will make you dramatically more well rouded and will play into your infosect interests indirectly

rapid merlin
sinful moon
#

More you learn about modding games very directly influences infosec, and can get into reversing

rapid merlin
blazing granite
# rapid merlin Is it edgy?

the problem of seeing old series, it's that people watch it with present eyes, without having in mind the context in where was created

sinful moon
#

Totally, and while I wouldn’t say gamify, yes people use them all the time to reverse and patch older games

rapid merlin
rapid merlin
#

Last time I ever did was like in 2012.

#

Lasted 10 minutes.

sinful moon
#

I just somehow doubt that infosec is literally all you do, you do need to be more well rounded in multiple feilds of tech alone to excel in IT

blazing granite
bold dawn
#

@rapid merlin What do you do for work?

rapid merlin
bold dawn
#

Ah, alright

rapid merlin
rapid merlin
crude stump
#

Anyone here follows like cyber news stuff

rapid merlin
sinful moon
#

Absoultely

bold dawn
#

I do incident response and pentests in between, merging more into Web Security

sinful moon
#

Nice nice!

rapid merlin
sinful moon
#

I ugh, do all infosec tasks at a small org, but it’s interesting

bold dawn
#

starting to do web pentests now, and responsible for implementing the fixes

sinful moon
#

or rather for many orgs lol

bold dawn
rapid merlin
bold dawn
#

and I have an amazing mentor

rapid merlin
bold dawn
#

How old are you now?

#

20-21?

rapid merlin
sinful moon
#

Yeah Managed Service Provider is great experience

bold dawn
#

Ah, I’m 19, so we ain’t too far off

crude stump
#

Y’all hear about how lockbit ransomeware attacked a children’s hospital and won’t unlock there systems even tho it’s a non profit. Talk about a new low

blazing granite
sinful moon
#

I have about 12 seperate Active Directory domains to protect

rapid merlin
bold dawn
#

that’s what’s insane to me

rapid merlin
bold dawn
#

yep

buoyant tree
#

Also Ellie I got a question

bold dawn
#

I have a possibility of being hired under him sometime this year

buoyant tree
#

Is the 1960's Ocean's Eleven worth watching

sinful moon
rapid merlin
bold dawn
#

he’s fighting for another associate position

molten sky
sinful moon
#

I just focus on the tech, but fair I get pulled into compliance and bussiness stuff more than I expected

molten sky
#

guess i'm never working for mandiant unless a recruiter reaches out to me first

bold dawn
rapid merlin
molten sky
#

got i hate their application portal

bold dawn
#

but the web team has extra budget

sinful moon
bold dawn
#

My mentor would be my big boss, so he’d refer me, but would have to step back from interviewing me

rapid merlin
sinful moon
valid mauve
#

Yesterday, we got "smart Meters" for our heaters. Today, I'm researching SDRs and the things sheets to see if I can grab data.

rapid merlin
#

Something along the lines of what IOActive is doing.

molten sky
#

an EXPLAINABLE mistake is one thing, negligence is another

sinful moon
molten sky
#

also, backups

#

all the backups

rapid merlin
molten sky
#

if you fuck up and you can't restore, that's a bigger problem

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @molten sky (current: #98 - 63)

bold dawn
#

yeah right now I do security for an MSP

sinful moon
#

Yeah I’m in year three now

buoyant tree
blazing granite
rapid merlin
sinful moon
molten sky
# rapid merlin Got it thanks for the heads up.

(as a note : the msp would be liable, not you, unless the msp goes after you directly as an employee for something dumb like you sabotaged shit -- but the msp is liable for the customer stuffs)

sinful moon
#

so being infosec person kinda advantageous at times

valid mauve
rapid merlin
valid mauve
#

Also hi Noir!

rapid merlin
sinful moon
#

868Mhz doesn’t sound too high for an RTL-SDR Blog USB stick at all

#

they just released the v4

#

probably most economical way to get into this stuff

molten sky
rapid merlin
sinful moon
#

It was found that cheap DVB-T chips could be tuned to whatever, custom firmware and then custom USB devices cropped up as a result, just for SDR

rapid merlin
valid mauve
molten sky
#

šŸ»

molten sky
rapid merlin
sinful moon
torpid ether
rapid merlin
bold dawn
molten sky
#

(hence negligence mention)

hot cairn
#

@valid mauve šŸ‘€

rapid merlin
torpid ether
# molten sky (hence negligence mention)

Yeah I missed the original message in that thread basically saying ā€œare you liable if the customer gets hackedā€. So yeah, I agree on that, not unless you’re criminally negligent.

molten sky
#

yeah as an MSP you're there to reduce the odds essentially

#

unless zero downtime is written in your contract, which would be dumb imo, downtime is inevitable

sinful moon
# rapid merlin Are you into exploit dev?

Not realistically, at work I’m primary defensive and securing infra/doing security engineering, but I also validate new products and continuing infra via some security testing.

Plenty of attacker focused and good bit of reversing in my spare time, but I wouldn’t allow myself to be called an exploit dev there yet either

molten sky
#

ugh. @mossy river

torpid ether
#

Ew

grim sparrowBOT
#

Done!

molten sky
#

so much spam in the last few days coming from aged accounts

torpid ether
#

As if anyones like, ā€œhey that sounds like spam, but the account isn’t brand new so..!ā€

rapid merlin
#

Still have a lot lot lot lot lot more to learn.

sinful moon
#

I’ve had to kick some long inactive members of other Discords who got compromised

molten sky
blazing granite
bold dawn
sinful moon
rapid merlin
#

So yes in a sense.

sinful moon
#

Business administration, compliance, and finance is not fun

#

keep that in mind if you want to start a business

#

It will distract from the actual tech

bold dawn
#

some people find it fun… not me lol

rapid merlin
molten sky
#

like i have the time

sinful moon
#

Public Telegram? lol what’s a PT other than that Silent Hill demo that was killed? But yeah I get you

rapid merlin
rapid merlin
#

@bold dawn Like you won't have a smooth sailing operation.

#

Ideally, you seek individuals akin to yourself, yet in reality, you will encounter individuals whose actions can nuke your business.

#

Or just mess things up since they don't work at your level.

#

For instance, I tend to handle everything on my own, especially in group projects (at school) . However, this approach isn't sustainable. I am good at my work, I just prefer not to deal with individuals who don't take things seriously.

#

I also admit that I can be the worst teammate sometimes (I do everything at the last minute : homeworks, projects and so on), haha.

#

If you genuinely perform better solo, it might be best to avoid team work. It could otherwise hinder your talents and drag down your performance.

#

I tend to work/do everything at the last minute because I enjoy it, it adds to the challenge.

#

Getting a good grade holds more personal value when you start and submit your work just a few hours or minutes before the deadline.

#

It serves as a statement of your intelligence and overall capability.

#

Of course, if the team is worth it though.

#

I believe I'm a great team player, but where I currently am, I'm truly at a disadvantage when working in teams.

glossy portal
#

yep, I feel you, and I'm in the same position as well, I do great when it comes to individual competitions, where other people's work don't affect me, but I need to learn to work in a sub optimal team, in my current position

#

Cybersecurity is better solo though? does that sound right to you?

molten sky
#

depends on the context

#

often a team is better tho

glossy portal
#

makes sense, I have a long way ahead of me, hoping to learn this too at some point

rapid merlin
#

I am not good at all at this yet.

#

I will probably label myself a hacker in like 7-8 years if everything goes right.

glossy portal
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @glossy portal (current: #800 - 4)

rapid merlin
#

I need to know way more.

molten sky
#

you have no idea how many people i meet that are so called experts and don't know shit

#

so many people never leave the "i copied and pasted this script off of the youtube comment section" stage, lol

#

aight night y'alls don't do anything dumb while i'm gone

#

or at least record it if you do

buoyant tree
#

ubuntuv28 atm

#

but missed renaming a few

sinful moon
# rapid merlin I need to know way more.

Agreed with productivity. I know both of us have pushed you a bit, but it’s only because yeah you show great promise. Just again I will advise to round out your at least infosec technical studies in other fields of IT. They all feed into the same pool of knowledge in ways you can’t anticipate

molten sky
#

didn't even notice that msg

#

i still don't know shit

sinful moon
#

Learning basic sysadmin tasks on Windows AD/Group Policy or Linux is a massive benefit

molten sky
#

google is a critical part of my job

sinful moon
#

just as a small example

#

lol indeed

molten sky
#

90% of what you learn will be how to become more proficient at google

#

well, let's say 80%

rapid merlin
sinful moon
#

tbh if you’re familiar with Linux troubleshooting, then already will be. But fair you sometimes have to delve into black arts to find actually helpful Windows pages that aren’t straigt up sysadmin lol

rapid merlin
sinful moon
#

It’s often a bit easier than Windows, but fair some of that is my famialirity

rapid merlin
#

So I will eat, drink, dream and breath low level linux for a while.

rapid merlin
sinful moon
#

Just trivial for me to read and understand the Linux exploits, vs crazy API calls some Windows app may be trying

rapid merlin
#

Same with learning.

rapid merlin
sinful moon
#

I just have to analyze any given payload and determine what it does lol, not always given the choice. But practically it’s most often just phishing and me analyzing the payload is going above and beyond lol. Already blocked the sender

#

speaking of, Microsoft, please get better about all the *.onmicrosoft.com phishing you’re sending out. It’s a pain in the butt to block properly, especially if they spoof another *.onmicrosoft.com recipient

#

It’s also funny to see how threat actors poorly misuse what is clearly phishing as a toolkit service powered by *.onmicrosoft.com, they spoof being a Gmail sender via onmicrosoft, and then spoof a ton of replies they got to their phishing, trying to legitimize the thread with real replies and signatures….

but every reply is like indignant ā€œthis is SPAM, unsubscribe me NOW!!!ā€ lol

#

Just poor templates and poorly ran campaigns lol

buoyant tree
#

Ellie u remember this scene

sinful moon
#

Yes

buoyant tree
#

pretty fun if u add in the context of the episode

sinful moon
#

Whole show is great

#

and yeah especially the ciphers and hidden clues everywhere

#

First instance of time travel, yep that character was in the background of all the episodes he popped into

sinful moon
#

only ramps up from there

#

yep

buoyant tree
#

didn't notice him

sinful moon
#

Mhmm, always a sign of a good show, then they planned this stuff out well ahead of time

#

Babylon 5 is my fave for that, but not recommending you jump straight into that just yet lol. Probably need more 90s TV watching

#

That series was just planned out for the entire run, with ā€œtrap doorsā€ written into storylines at any time if an actor or actress was forced to leave the series

#

happened at least twice for very major characters and handled well

rapid merlin
#

There is also the language barrier.

sinful moon
#

Indeed but most of these phishing as a toolkit things have sane extremely tricky templates out of the box

rapid merlin
#

With Russian as my mother tongue, I can discern things pretty quickly (forum wise).

sinful moon
#

I see some Intuit (Quickbooks) phishing that is quite scary at times with the same tactics exactly, but done properly

rapid merlin
sinful moon
rapid merlin
#

The weakest link is the human being, so it's good that they are well-versed in phishing.

sinful moon
#

At worst it’s spoofing their own address from an *.onmicrosoft.com domain/IP. Obviously can’t block that. So I block the *.onmicrosoft.com tenant via Regex content matching in the headers

rapid merlin
#

It's next level bad in some cases.

#

I like poor phishing attempts.

#

It's funny.

sinful moon
#

Can’t say I see any of that at work, but tons of ā€œwe watched you with your webcam on while you did X, and hacked you, here’s out bitcoin addressā€ sorta thing.

Super lazy, typically not bad english but all templates

rapid merlin
#

Things like that.

sinful moon
#

Yeah those sorta things I see are all lazy templates and low effort tech, big meh

rapid merlin
#

APT style attacks are very much more next level because they actually go ahead and build the proper infrastructure.

sinful moon
#

I’ll just say that targeted attacks also range from extremely dumb to extremely sophisticated

rapid merlin
#

Some fields or areas are more susceptible to phishing attempts than others (finance and so on).

sinful moon
#

Deal with both nearly daily. Even tho I’m mostly doing high level infosec stuff, I accidently became ā€œthe phishing personā€ as a result lol. Again just small business things

#

This is tax season and our CPAs are getting slammed with industry specific phishing

rapid merlin
#

Despite the harm caused by Carbanak, their whole APT style attack is just incredible. So I like reading about them.

rapid merlin
sinful moon
#

I’m actually kind of proud of our best users, they know something is up and tell us if they opened the attachments in the slightest.

#

Yeah no, a PDF asking you to sign into DocuSign is indeed not normal lol (lead to O365 phishing, they didn’t click on that)

#

btw if anyone is a MSP or IT for a law firm, there’s a big O365 phishing campaign going around, with infrastructure based out of Brazil. Compromises legit legal (usually paralegal) accounts and spreads

buoyant tree
#

hmm interesting scams

sinful moon
#

Yeah I kinda get to see it all, it wild range from obvious to full on ā€œthis could potentially fool me too but I’m glad our clients picked up on the issuesā€

#

Not saying I’d nessessarly fall for these, but bit more scary when they’re actually using 1:1 sorta email templates

buoyant tree
#

hmm

#

haven't seen a lotta examples of industry targetting

#

just general scams

lyric lava
#

where can i find ghidra logs?

rapid merlin
rapid merlin
coral berry
#

I am trying a lab in portswigger academy on delay attacks but this script does not work.

cookies = {'TrackingId':"x' ; SELECT CASE WHEN (1=1) THEN pg_sleep(10) ELSE pg_sleep(0) END--"}
r = requests.get(url_to_attack, cookies=cookies)
print(r.status_code,r.elapsed.total_seconds())
exit()

however manually intercepting and adding this same TrackingId works. Why is it not working in the code?

sinful moon
#

Threat modeling is the name of the game. Do consider I’m doing IT for small/medium business and we are not the concern of nation state or APT level hacking. Yes this concern is factored into our threat modeling, but it is not a practical business concern

rapid merlin
#

Which is why I like reading about these APT's.

#

It's very sophisticated and well organized.

sinful moon
#

lol if you read some of their playbooks, not always

#

for sure depends on the threat actors

lyric lava
# rapid merlin ~/. ghidra/

no such folder

dir /b /o:gn
docs
Extensions
Ghidra
GPL
licenses
server
support
bom.json
ghidraRun
ghidraRun.bat
LICENSE```
mossy river
#

x' ;

rapid merlin
coral berry
rapid merlin
mossy river
sinful moon
#

Some described ā€œAPTā€s are literally googling their tools, so must take a grain of salt with both the source of the report and the associated attackers

lyric lava
rapid merlin
lyric lava
sinful moon
mossy river
sinful moon
lyric lava
rapid merlin
sinful moon
# rapid merlin Sure thing.

Yeah I loled at that thing yesterday ā€œ3 million IoT toothbrushes used in DDOS attackā€. Nah it was translation error/misunderstanding lol….. but still profited the security company in question lol

rapid merlin
#

So all files/entries.

mossy river
#

That is correct, but it is more accurate to say hidden files šŸ™‚

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1146)

sinful moon
#

There’s no way your toothbrush would be connected to WiFi lol

rapid merlin
#

I am pretty surprised as well.

sinful moon
rapid merlin
#

Maybe the dock is connected to wifi.

blazing granite
mossy river
rapid merlin
sinful moon
#

Yeah it went from Sweedish misunderatanding to English fact

blazing granite
rapid merlin
mossy river
rapid merlin
rapid merlin
#

I assume it's possible technically speaking to hack an intelligent toilet (yes that exist).

sinful moon
#

They would only ever communicate practically via bluetooth so it’s not even sensable

rapid merlin
#

Still very stupid to implement.

mossy river
#

Malware bytes did it best

rapid merlin
#

Iot devices are a mess.

blazing granite
#

I like bleepingcomputer

rapid merlin
blazing granite
rapid merlin
sinful moon
#

Bleeping Computer has saved my butt at work and made me look impressive

#

Turn of 2022 our firewalls were randomly rebooting, instantly saw the issue there and reported to all techs

#

Mitigated pretty quick

blazing granite
sinful moon
#

But lol at Year 2022 bugs lol

clear jackal
rapid merlin
#

I will check that website.

sinful moon
mossy river
#

Didn't even need to ask to know it was time related

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sinful moon (current: #40 - 181)

sinful moon
#

Exchange also had major hickup for 2022 lol

blazing granite
rapid merlin
sinful moon
sinful moon
buoyant tree
#

Ellie how many ubuntu machines have u set up

sinful moon
buoyant tree
#

and kali also

sinful moon
#

That’s not normal, why do you ā€œhave toā€

rapid merlin
#

A lot of nice red colors.

rapid merlin
#

Just use the prebuilt vm.

sinful moon
rapid merlin
sinful moon
#

Honestly Outlook and Exchange is kinda notorious about leaking NTLM hashes, it’s not great

#

lol one two years ago was triggered by a ā€œremote alert sound effectā€

blazing granite
rapid merlin
sinful moon
#

Most likely, it’s getting too late for me to double check

#

Sounds right though

blazing granite
rapid merlin
sinful moon
#

There’s no need ever to reinstall your Linux infrastructure unless you messed something up

rapid merlin
#

Kali Linux is very cluttered.

sinful moon
#

Like dramatically

rapid merlin
sinful moon
# rapid merlin Kali Linux is very cluttered.

Yes, but is instantly deployable for people who know what they need. If you’re still learning then… again I just literally installed all the packages I needed in arch which is good bit more painful in Ubuntu unless you want franen Kali kinda setup

blazing granite
sinful moon
#

I haven’t actually seen material differences in Kali Purple beyond theme

rapid merlin
#

All I need.

sinful moon
#

still had to download promised included software from apt

rapid merlin
#

If it works, it works. I am not there yet.

sinful moon
rapid merlin
#

It works, it's fast for me.

#

I want something that works right off the bat.

sinful moon
#

pacman new hostness and downloads concurrently

#

although obvs *buntu need not apply lol

rapid merlin
#

I don't need all these novel features.

#

I am good with apt for my use case.

#

There is also dpkg which I use from time to time.

sinful moon
#

that’s totally fine but you need to expand your view a bit in my opinion. I’m not saying use Arch like an elistis, I’m saying try all the Linux distros you can and learn how things differ. Especially stuff like Fedora since that could have an impact on future careers

sinful moon
rapid merlin
sinful moon
#

Don’t pidgonhole yourself in *buntu land, there’s much more to LInux than that

rapid merlin
#

Otherwise, I would be on Windows 100%.

sinful moon
#

Okay… but it’s an ever growing segment of ā€œcloud infrastructureā€ which must be understood, and that has its own set of condrunums

#

You just seem to be trying to learn skills for IT, so I’m just trying to assist with some goals

#

cloud/devops is huge, and securing that properly is even better

rapid merlin
sinful moon
#

I’ll just say all the Linux knowledge you can get will be beneficial, and will scale with importance for how large the org is

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sinful moon (current: #40 - 182)

blazing granite
rapid merlin
#

@sinful moon I also have remnux which is nice that it's based on ubuntu installed on another vm.

sinful moon
blazing granite
#

it's a work in progress šŸ˜‚

rapid merlin
#

@sinful moon Do you run hyprland or something like that (not sure of the name)?

sinful moon
rapid merlin
#

Like a dynamic tiling Wayland compositor if I am not wrong.

sinful moon
#

No these are servers

#

No graphical interfaces

rapid merlin
#

On your personal computer do you run it?

#

I am a huge noob when it comes to linux customization.

#

Like I legitimately know nothing.

sinful moon
#

One sec

#

So Wayland is indeed the display server of the future, however Nvidia are dragging the feet and forcing people to stick with the traditional xorg if you want reasonable gaming performance.

At the moment my Linux gaming laptop is running Arch KDE + xorg, because I have Nvidia graphics and need 1.5x style fractictional UI scaling. Something my fave DE, XFCE, can’t do natively

rapid merlin
#

Not practical at all though.

sinful moon
#

It’s a pain and a half if you were doing qemu/kvm aka libvirt stuff

#

But there’s for sure easier ways to PCI passthrough

#

Either way, it’s doable but not something I’d recommend for someone with little Linux experience

blazing granite
buoyant tree
#

if network changes i can't connect to it

rapid merlin
buoyant tree
#

so factory reset it

sinful moon
#

also why not static IPs

rapid merlin
#

I always suggest that people start with challenging tasks so they can push themselves to learn quickly.

#

Too easy = too boring.

#

Only if you are perfectionist though.

sinful moon
#

Sure, learn LInux, X509 <3

buoyant tree
sinful moon
#

okay, so it’ll get DHCP and you can IP scan where it lands

rapid merlin
sinful moon
#

imho don’t get overly ambitious, just learn the basics and using it like a normal OS

#

then you can grok how to exploit even better

#

you need a baseline for what you’re even exploiting from

rapid merlin
#

That's how it began for me with Gentoo. I genuinely believed that was all there was to Linux. Looking back, I think they recommended it to challenge me or just for laughs.

buoyant tree
#

hfilebrowser/filebrowser:s6 "/init" 2 minutes ago Up 2 minutes (unhealthy) 0.0.0.0:8080->80/tcp, :::8080->80/tcp

rapid merlin
#

I don't think they expected me to get it up and running.

buoyant tree
#

hmm anybody got a idea why the docker container isn't serving

sinful moon
#

Gentoo is far from the best start with Linux but yes

rapid merlin
#

It's just tedious.

#

A monkey could get gentoo up and running.

sinful moon
#

No one sane compiles everything in 2024 lol

rapid merlin
sinful moon
#

compile only what you need to

buoyant cairn
#

Yo

rapid merlin
rapid merlin
lucid elm
#

is anyone able to assist me with tryhackme steel mountain
ive completed the entire room with CVE-2014-6287 rooted and priv escalated but the room wont accept CVE-2014-6287 as the answer

#

even writeups / walkthroughs show its CVE-2014-6287

blazing granite
sinful moon
rapid merlin
lucid elm
#

cheers

rapid merlin
foggy leaf
#

hlo

sinful moon
# rapid merlin Sure if you have to.

All I have to say is that stock Ubuntu and Gentoo are poor reference for working with Linux professionally, especially not using them all that much

blazing granite
foggy leaf
#

how do I claim roles/

sinful moon
#

Yeah can not blame you one bit lol

sharp citrusBOT
sinful moon
#

@foggy leaf

foggy leaf
#

thanks

buoyant cairn
#

What’s good yall

sinful moon
#

Yeah I don’t mean to harp on it so much but Ubuntu Server is what I deploy at work, do kinda need to know just terminal administration basics to get ahead there

#

let alone my docker setup

#

although lol Docker-Compose is trivial to administrate once it’s set up

blazing granite
rapid merlin
gray tendon
#

I def think the Debian stuff is nice in my book, it all just kinda works, and ubuntu has easy access to most packages, tons of documentation, fairly lightweight, and runs on anything.

rapid merlin
#

Ubuntu is awesome.

sinful moon
rapid merlin
rapid merlin
#

It's so flawed that even malware can't affect it.

buoyant tree
#

Ellie I finnaly crashed my RPI

sinful moon
#

It can

blazing granite
sinful moon
#

Unless patched it’s vulnerable to EternalBlue and much more

rapid merlin
rapid merlin
#

It's borderline art.

gray tendon
#

yes

#

its awesome, I've done the TM labs for it, and it is a great feeling when it works.

#

You just feel like a hacker

sinful moon
rapid merlin
foggy leaf
#

I actually lost my 19 day streak

#

will I get it back if I contact staff or create a ticket?

rapid merlin
#

No (just try again).

gray tendon
#

did you actually do anything that day?

sinful moon
foggy leaf
#

no. I wasn't feeling well yesterday.

sinful moon
#

Not sure why that guy said no lol

gray tendon
#

don't think they would just cuz u wanna keep ur streak....lol maybe worth a try

rapid merlin
rapid merlin
sinful moon
#

Being sick that day is pretty valid

foggy leaf
gray tendon
#

u can win streak freeze tokens or whatever, but u'd have to have it upfront

rapid merlin
sinful moon
#

Like THM support has a method of contesting this

blazing granite
foggy leaf
rapid merlin
#

How would you even go and prove it?

sinful moon
#

That is a joke obvs, you don’t need to prove it, just give a valid reason

gray tendon
#

Alls u gotta do is answer one question I think, or do you need to finish a module?

#

to keep streak

sinful moon
#

THM staff are not hard butts if there’s a reasonable stance on why

twin ridgeBOT
#

Gave +1 Rep to @sinful moon (current: #39 - 183)

rapid merlin
sinful moon
#

Not something to abuse, but being sick? Yeah that’s no fun for anyone and understandable

gray tendon
#

Yah, I dunno. Could go either way I guess. I've never tried to contact them for anything.

rapid merlin
foggy leaf
#

I mean, if ppl are able to hold their streak for 20+ days, then missing 1 day is kinda unusual for them without proper reason.

buoyant cairn
#

U guys are also sick today?

rapid merlin
blazing granite
#

I believe that other than a site error or downtime, there is no other valid reason to ask for a streak restore, it's your own responsibility to manage your time, also you only need to complete one task to maintain your streak

sinful moon
gray tendon
#

Right, but at the same time. ur streak isnt really all that important in the scheme of things. So you lose ur streak and start it again today.

rapid merlin
foggy leaf
rapid merlin
gray tendon
#

so are they gonna spend time answering emails, etc for something like that........obv a few here or there, but if it was large scale, I can't see them taking the time to deal with each case.

rapid merlin
foggy leaf
#

3yr old post

buoyant tree
#

just was playing 8 concurrent streams

#

while plex and jellyfin weere doing metadata lookups

gray tendon
rapid merlin
sinful moon
rapid merlin
gray tendon
#

Also, it is worth ur time & effort to try to get it back, right.....lol

mossy river
rapid merlin
gray tendon
#

Do u get extra Attack box time or something, I forget what the streak benefits r?

foggy leaf
rapid merlin
#

Using streaks as a motivator can be effective, but relying solely on them for learning information security on THM it's not good.

foggy leaf
buoyant tree
#

Also @sinful moon what game's have the best music/scores

mossy river
#

What's your query?

foggy leaf
gray tendon
#

To make maintaining a streak worth it, we throw in various rewards for different streak milestones, such as:

Badges,

Access to TryHackMe networks,

Streak freezes,

Discounts on merchandise

foggy leaf
#

can u read from there

rapid merlin
foggy leaf
gray tendon
#

Contact support at support@tryhackme.com; please provide your username and the last value you remember your streak was before it reset. While waiting for support to get back to you, you can continue your streak; those days will be added to your original streak count.

You have up to 7 days after losing your streak to contact us, or you will be unable to claim your streak reset. Furthermore, support will not combine old streaks or transfer streaks between two accounts.

blazing granite
#

I think my longest streak was 40 something days, but I never paid much attention to that.

mossy river
rapid merlin
foggy leaf
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1147)

mossy river
#

You are forever in my debt @foggy leaf

sinful moon
#

I’ll leave it at that for now as to not rack my brain too much

mossy river
#

alr, it's almost 5:30am, gn yall

sinful moon
#

G’night Jabba!

foggy leaf
#

thanks gn8

brisk tree
#

morning

sinful moon
rapid merlin
sinful moon
#

but I’ll sure as heck spam Chrono Cross if you’d like that too <3

rapid merlin
#

Anyway I have to go, things to do. Time to no life what I was doing. Goodbye everyone

sinful moon
#

G’night X509!

buoyant tree
#

sure dm a few over

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sinful moon (current: #38 - 184)

blazing granite
#

morning here, 7:24

buoyant tree
#

was just awake

#

10 am over here

brisk tree
#

9am

buoyant tree
#

did ur boss finnaly pay u

brisk tree
#

only a small amount ready to sue now.

buoyant tree
brisk tree
#

i have loads of messages of me asking him when were getting paid. also have emails from a payroll intern he hired asking how much i was owed

blazing granite
brisk tree
#

ahahaha yes internest for all the mental strain šŸ˜‚

blazing granite
#

interest for the time, on top of that he should put more for emotional distress šŸ˜‚

brisk tree
#

yes exactly ahaha. one of my collegues is so stressed about money hes drinking everyday. but yeah i need to sue now and see him crumble ahah

blazing granite
#

yay, get the bastard šŸ˜‚

brisk tree
#

yep ahaha. he keeps trying to guilt trip me too making me the bad guy for not working

blazing granite
#

Once somebody try that on me, and I told him, you got there wrong guy, I don't give a sh*t about, you can drop dead for what I care but not before you pay me, FYI I have no emotions šŸ˜‚

brisk tree
#

ahahahahhaha i am losing my patience. he owes e 7,600

#

me

blazing granite
#

that's a chunk of change šŸ˜‚

brisk tree
#

it is and hed better soon. One of the main tech guys is so fed up he started his own company ahaha

blazing granite
#

he should take all the unhappy employees with him and let the guy alone to deal with all the problems šŸ˜‚

brisk tree
#

well he asked me to help him get clients on a commision basis. if i bring anyone in i get 25%

blazing granite
#

I must go, see you people!!

#

@brisk tree I hope you get pay soon

brisk tree
blazing granite
#

sleep šŸ˜‚

brisk tree
#

ahahaha

chilly veldt
#

Morning

lyric lava
#

i have this if statement
in ghidra
how can i make it always false
i dont want to break the whole program

brisk tree
chilly veldt
#

I had a fun night

#

Let's just say that I forgot it was picture day today, and there was karaoke

brisk tree
#

oh damn. least you had a fun night

sick lance
lyric lava
#

my friends crackme

sick lance
#

Then awk your friend. šŸ™‚

#

Ask*

lyric lava
#

i figured it out

white bronze
#

Morning guys I'm a new one on this server

sick lance
#

Hello a new one.

lyric lava
sick lance
lyric lava
#

fair enough

white bronze
#

This server collects hackers?

sick lance
white bronze
#

Good so white hat hackers,

sick lance
#

Yes

white bronze
#

M I'm a cyber security student nd I wanna learn more and more in this domain

graceful thistle
#

welcome, youve come to a good place

white bronze
#

Thank you @graceful thistle

twin ridgeBOT
#

Gave +1 Rep to @graceful thistle (current: #22 - 348)

chilly veldt
#

Eyyyy dolphin

graceful thistle
#

Eyyyy

#

how are you

sick lance
sharp citrusBOT
#
TryHackMe's Website

You should know our website by now!

chilly veldt
devout palm
#

Ey

#

yo

#

Mornings

graceful thistle
#

Good morning

graceful thistle
chilly veldt
graceful thistle
#

ah, you went for peak photo day conditions

chilly veldt
#

Yes

graceful thistle
#

pff, too much keyboard switching. 1 trillion typos

chilly veldt
#

Cause I had to crash at my friend's as my car got locked in and I couldn't get out

#

Get home*

sturdy vortex
#

Site down ?

glossy portal
#

Working for me

rotund wigeon
#

Seems up to me

lyric lava
#

is c++ null == 0x0 in assembly?

sick lance
lyric lava
#

learning

devout palm
#

nullptr?

lyric lava
#

no

#

the valuetype is a class

sick lance
#

Is this home work or school work?

lyric lava
#

home work

sick lance
#

We don't help with homework, sorry. šŸ™‚

lyric lava
#

i meant like not related to school

lyric lava
#

what should i ask here

devout palm
#

so?

lyric lava
#

about politics

#

?

devout palm
#

Doesn't mean we should help your homework

lyric lava
#

its not homework

#

i am just learning

devout palm
sick lance
#

I don't believe you.

lyric lava
#

i am not in college yet

lyric lava
devout palm
#

Use google, take a look at C++ pointers and assembly comparisons

lyric lava
#

hmm

#

are online c++ to assembly actually accurate or is it asm pseudocode?

devout palm
#

Why do you need a specific answer

#

when you can learn what it does, and answer

#

Assuming it isn't a college homework

lyric lava
#

šŸ¤”

#

why would i want to learn wrong information

devout palm
#

Wrong information??

#

Wdym

#

Learn what pointers do, learn assembly instructions

#

And then you will find the answer

lyric lava
#

wtf there is no null in c++

sick lance
#

Null pointer?

eternal ether
#

Can i ask something about game cracking (for educational purposes only) (no techniques) or is it not allowed?

#

What does it mean to "crack a game"? I am assuming they are not referring to just obtain the files from setup when installing it

sick lance
#

We don't discuss piracy in here.

#

Fixed.

eternal ether
#

I don't mean to pirate a game but what are they referring to when they say that they cracked a game?

shell nova
#

ie CD keys, DRM, etc

eternal ether
#

Back in the old days you had to put the CD disc in the driver to be able to play it

#

But now i suppose you say just bypass this protection?

shell nova
#

yeah but then burners came along

sick lance
#

Back in the older days, they gave you a puzzle to solve to play the game (Escape from Monkey Island)

shell nova
#

some had codes in the manual

sick lance
#

MGS was a classis example too.

#

Having the codec address for an NPC on the box.

eternal ether
#

So they don't refer to just "obtain the files from the setup". Because that is easy to do basically

#

I am trying to analyze what was happening in the old days when we bought physical cd disks and then digitalization came

foggy leaf
#

hello

sick lance
#

Hello!

gritty zephyr
#

Heya

pearl badge
naive violet
#

@eternal ether Cracking a game is piracy

bold latch
#

Lo. Anyone familiar with WiFi devices much?

#

And more specifically Linux comparability here?

eternal ether
#

Not how to crack a game

naive violet
chilly veldt
valid mauve
bold latch
#

Yep, I know, google and forums. I've been prodding about in there but I haven't found the type of responses I was looking for and thought this might be a good place for some newer/relevant polling

#

Before I do buy a dozen USB dongles that allegedly are supported by Linux according to some forum post in 2005, what types of cards have you peeps had a hassle-free experience with personally?

#

My desktop's network card seems broken, I cant quite be bothered to fix it, wanted to finally get to that fresh desktop install and realised I can't ping the net because the adapter I'd used until then isn't supported out of the box by the liveUSB's kernel

chilly veldt
#

Depends on the usage

bold latch
#

So I need literally anything that can connect to the net and won't seem foreign to the LiveUSB installer

heady nova
#

ello

bold latch
#

Literally all I need it for is to pull the drivers for my OTHER adapter and install dkms git and some C libs to be able to build and install support for it

bold latch
gritty zephyr
#

Seeing alot of great peeps here, hows everyone doing

heady nova
#

had been slacking off for the week

#

hbu?

bold latch
gritty zephyr
bold latch
grizzled crystal
#

Yes rest is good

#

Resist the hustle culture demons inside of you

gritty zephyr
grizzled crystal
#

Hi hi, how's it going?

#

Long time no see

gritty zephyr
#

Pretty good, new semester of school, digital forensics

#

So pretty interesting

grizzled crystal
#

Sounds fun

gritty zephyr
#

It should be

#

Were working with law enforcement and everything

grizzled crystal
#

Cool! Sounds pretty hands-on

gritty zephyr
glass nest
#

I do recognise the name

gritty zephyr
# grizzled crystal Cool! Sounds pretty hands-on

We need to make a playbook for a "crime" and put the digital traces of that onto the phones, law enforcement will get a copy and we will analyse the digital traces of another team to see if we can recreate the crime

grizzled crystal
#

The name changed i believe

gritty zephyr
#

So yeah pretty handson

gritty zephyr
glass nest
#

Hehe, I used to do that as a job. Not the scenario, the other bit šŸ™‚

gritty zephyr
#

But were also gonna get data from the phones and stuff

glass nest
#

Well, a tip from someone who has extracted info from a lot of phones - Drug dealers LOVE putting photos of their stash on their phones. And... well, a lot of them don't turn off location services, if you get what I'm sayin'

sick lance
gritty zephyr
#

Yeah im thinking of getting some photos from google, changing the metadata for the scenario and make a lead that way

glass nest
#

It's like they WANT to be caught šŸ˜„

gritty zephyr
glass nest
#

probably outside of your remit, but many of them also had photos of their girlfriends on there

gritty zephyr
#

Im guessing without clothes or nah

#

Hahaha

glass nest
#

NSFW, but it was technically part of my work

gritty zephyr
#

But yeah thats part of linking evidence

sick lance
#

Emails, texts, locations phone calls.

glass nest
#

If you want, I can DM you about a case that I actually had to go to court for, and the evidence wasn't the most obvious

gritty zephyr
glass nest
#

Done šŸ˜„

#

Continuing from before, The geotags on photos - Even ones of dubiousness gives the OIC (Officer in Charge) a couple more avenues of investigation, especially if they are taken in a persons home or at a location where theres cameras etc

#

Dammit, I'm actually excited about your project. You truly are...... Devious šŸ˜Ž

heady nova
#

Ello esqy

glass nest
#

Sup Rinz.

heady nova
glass nest
#

Any amazing new developments? 2024 seems to be the Year of the Tank

heady nova
glass nest
#

out of how many?

sick lance
heady nova
glass nest
#

And how many people applied?

heady nova
#

Atleast I'm yet to meet another Security Researcher Intern

glass nest
#

There we go man. That's a 9% chance for your role, and you got it.

#

Scrubz - I like that.

heady nova
#

There is, and Idk what to say man. Everyone is like "oh the bar is too low for getting offered a full time role after intern. Like 32 out of 50 get offered a full time"

glass nest
#

Who cares about that. that shows that they expect the interns they pick to be successful.

#

not a low bar, just confidence that the interns they choose will hit the bar they set

chilly veldt
#

OH FOR DUCKS SAKE

glass nest
#

Everyone else didn't even get through the door. Go reclaim your sense of accomplishment

#

bella - Parking lot still locked?

heady nova
glass nest
#

what do you mean 'Other Friends'?!?

chilly veldt
heady nova
#

Yk reading that book "How to make friends and influence people" was worth it

glass nest
#

Shei - Is that a new Purple look I see on your name? If so, Gratz šŸ˜„

heady nova
#

My rent got down to 0

heady nova
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 382)

heady nova
#

Congo

glass nest
heady nova
#

Tank sad

glass nest
#

I want my mortgage to be 0!

#

but thats like.. 25 years away from now

heady nova
#

I'm still on the door of adulthood

glass nest
#

It's like rent, but you own it after a long time.

gray sonnet
#

Morning THM

heady nova
glass nest
#

usually cheaper than rent aswell. I'm in a 2-bed house with a garage and it's costing me £450 a month

heady nova
glass nest
#

If I had a partner or a room-mate that would be halved

heady nova
gray sonnet
# heady nova I'm still on the door of adulthood

Basically, you want some money, you have a property, you give the rights of your property to the bank in exchange for the money, you have to pay back that money with a fixed interest on that money, mortgage simplified

heady nova
glass nest
#

Haha, theres very litte tech industry in the south west corner of England šŸ˜„

#

Rinz - nope. they'd be paying me rent and I'd be paying the mortgage.

gray sonnet
gray sonnet
glass nest
#

Difference is, if they fail to pay me I still need to make the full payment

heady nova
gray sonnet
#

THM meetup

heady nova
gray sonnet
#

I think there was a #meetups channel lmao

gray sonnet
heady nova
bold latch
#

Weird thing happened with my discord, completely logged out and couldn't retrieve or send messages on servers

#

Back now

heady nova
bold latch
gray sonnet
glass nest
#

Well, theres some legal things around it. long and short is that I'm the one who owns and is responsible for the property. Thats all the bank cares about. If I have a tennant, then thats my issue.

#

That being said, Last tennant I had was a buddy, and I let him stay for free

gray sonnet
#

Lemme DM you, don't wanna dox the details of the city lol

chilly veldt
heady nova
heady nova
glass nest
#

I don't think you can Doxx a city šŸ˜„

sage wolf
#

new york city

#

oops

heady nova
glass nest
#

Thanks Kona, hacking it now..

bold latch
glass nest
#

Rinz - Yup. Can do what I want.

bold latch
#

You could probably climb to 0xD just by doing all them paths and getting down with the basics and not-so-basics

rapid merlin
chilly veldt
rapid merlin
#

On paper it is your house right?

#

In my country it works that way. I think it works the same in USA etc?

heady nova
#

We can basically turn it into a double storey house and put different rooms on rent

heady nova
sick lance
#

hit the right rooms which have bonus points for flags.

bold latch
chilly veldt
#

Some colleagues who can't even troubleshoot things properly

bold latch
#

Really appreciated the learning paths for teaching though, they're excellent at what they do

rapid merlin
chilly veldt
#

"shit no worky, oh well"
Waits multiple weeks before reporting
New ticket
"Network doesn't work and hasn't worked for weeks, plz fix"

bold dawn
#

got alerts from work for some reason even though I shouldn’t be on call

now I’m running on 2 hours of sleep

heady nova
chilly veldt
#

Otherwise they complain to my manager

sick lance
rapid merlin
#

mhh

#

Hey

glass nest
#

Yeah. Although the bank has a claim on it. HOWEVER - the banks claim is only to the value that I still owe them.
If the house costs say £200,000, and I've paid off half - If stuff goes south, the bank can only claim £100,000 if the house is sold through whatever means. The 'complicated' part - If I see a house for £200k and buy it the bank lends me that (It's usually less, as they'd want a deposit of like 10%, but lets say 200 for ease of maths).
In 5 years time, my house could be WORTH £250k.
So in that 5 years, If I paid £500 a month - I'd have given them £30k. so I still owe the bank £170k.
Now, because the house would now cost MORE for someone to buy it today (5 years on), theres a gap of £80k between what I owe the bank and what it could be sold for. Thats whats called 'Equity'.

chilly veldt
#

And I bet you, said ticket is literally just a switch that has lost power or some shit

desert shuttle
#

Hello

bold latch
#

They never mention it anywhere, but the second you sign up for any remotely related Comp Sci course, you sign an invisible contract that assigns you to being tech support for the technologically inept people around you for life

#

All the way to and beyond employment

glass nest
#

Thats a simplification, as there are interest rates and a few other bits, but thats the basic concepts

rapid merlin
#

i guess im not buying a house for a while ;p

glass nest
#

If I had this old head on me when I was younger, I would have bought waaaay sooner. Theoretically, I could have paid off my 1st house by now.

heady nova
glass nest
#

Yup. Long term investment.

#

Lots can change though - places like Detroit, there are some areas where the housing market crashed so the value of the house actually went DOWN, but you still owe the same amount to the bank. This is why houses in areas with less crime and such cost more.

heady nova
#

Yk what, maybe I can do that once I get myself to US

chilly veldt
#

REEEEEEE

#

Now my cat won't start

#

Car

glass nest
#

Acme - always worth looking into. The hardest part for a lot of people (including me) was getting the deposit together. My house was £160k, aos I needed to save up a deposit of £16k while also paying rent somewhere else etc. Plus the extra 'Buffer' - theres other bits depending on country, but Lawyer costs were about £1200, getting furniture and stuff also cost a bit, Getting stuff connected Like internet also had 'setup fees'.

#

that being said, 0 ragrets. House is now worth £210k 5 years on, and I'm not plannign on going anywhere just yet

glass nest
#

Yeah, but a calculated one.

heady nova
#

I'll keep that in mind

glass nest
#

If the house is in a crappy area, it will cost less (compared the the same house in a nicer area).

#

I got really lucky, mine was a new-build in a new estate that was still being built. since I've been here, the estate has tripled in size, opened a school, build a direct road to the main 'freeway' in and out of the city, and a leisure centre will be built in the next 4 years (i think)

#

all those are factors that make it a more attractive place to live, which makes the house cost more.

#

i 'suffered' through not having those things, and over time it's (hopefully) gonna pay off.