#general

1 messages · Page 21 of 1

crude stump
#

Might be because I’m on the phone

sand trench
#

█ is fun

crude stump
#

Light mode ahh

molten sky
#

ew shadow uses light mode

sand trench
#

it is the full block char

#

it keeps same colour as text

molten sky
#

‎is better

sinful moon
#

Ugh today I had to yeild and start calling Azure AD "Entra ID". Was specially asked by the boss loosely "help what do for Azure permissions".

lol now we're plowing forward with Entra ID PIM to manage Azure roles/resources and Entra ID roles in one spot with a sort of privilege escalation for roles when needed

#

Was not about to juggle Azure vs Azure AD for a couple hours so fair I give up Microsoft, I didn't like this change but you win

crude stump
molten sky
sand trench
#

anyways shadow should try to sleep sloop to the beep boop while they meep moops again

sinful moon
#

This is unfortunately more clear despite the awful name

molten sky
#

i also rarely if ever said azure ad, lol

#

always aad

mossy river
molten sky
sinful moon
#

Indeed lol, even the Entra ID urls still call it AAD internally

crude stump
#

Oh it’s a Active Directory

sinful moon
#

Azure Active Directory which is a seperate concept

#

and nowhere near as easy to manage as AD/GPOs lol

#

Azure AD is now called Entra ID formally

molten sky
#

it's one of those things where if they called it Entra ID from the start it would be perfectly fine, but it's because they set the standard

#

stop changing shit

sinful moon
#

Yeah for real

crude stump
#

Yk what I love about this server. Everyday I learn something new from it

sinful moon
#

I'm only just now adjusting to saying Microsoft 365 unless I have to use accronym like O365 lol

molten sky
#

O365 is still my go to

#

just automatic

sinful moon
#

fo sure

molten sky
#

even though it's actually different here

#

365 is 365 is 365

sinful moon
#

But I will admit my Skype to my boss explaining that Entra ID PIM was the best way forward would have been nearly unintelligible attempting to differentiate Azure AD from Azure roles and etc

molten sky
#

in a few years they're gonna change the name to Microsoft One

sinful moon
#

Yes, unalive me now 🙃

molten sky
#

y'all are on 365, presumably bus prem, you have teams

#

makes no sense

sinful moon
#

Yep! We even administrate Teams for clients lol

molten sky
#

dumb af but okay

sinful moon
#

Don't ask me lol

#

Boss old reason was it was easy to dump chat transcripts out of Skype, but that hasn't been easy in years

#

There were attempts before my time to convince him of Slack or Teams but didn't work

molten sky
#

btw if y'all have 40 minutes to kill, just saw this good talk from one of the github cofounders https://youtu.be/aolI_Rz0ZqY
learned a couple things i'm actually gonna add to my own workflow

Scott Chacon's FOSDEM 2024 talk on Git Tips and Tricks.

Scott talks about:

  • 06:25 Helpful git config stuff
  • 09:42 Oldies but goodies
  • 16:22 Newer git options and commands
  • 23:48 Large repo and monorepo commands
  • 33:28 Some new GitHub options and settings

Read the blog series based on this talk here: https://blog.gitbutler.com/

▶ Play video
sinful moon
#

Nice, may have to check that out!

molten sky
#

the new desktop app sucks tho

sinful moon
#

lol, common theme with Microsoft but yeah

molten sky
#

huh. bugcrowd recruiter just reached out -- interesting

sinful moon
#

Here's the new Outlook, aka OWA and missing tons of features! What? Oh we'll bring PST loading eventually lol

molten sky
#

oh my god, new outlook is the worst thing i've ever seen come out of microsoft

#

i actually didn't mind the previous one

#

hate to say it, but it was fine imo

#

the new one is terrible

#

i really really don't like praising microsoft but i actually found the previous version useful

sinful moon
#

Yeah I've seen old Outlook break in catastorphic ways but it was very rare and usually only limited functionality to a degree

But lol new one is just missing critical features indeed

#

I do daily have issues with Outlook, but that's probably our crappy internal infra more than anything else

molten sky
#

y'all manage any exchange servers?

sinful moon
#

lol don't you dare click on 67k unread messages "Logs to be Reviewed" folder in support inbox or expect to have Outlook hang so badly that it's significantly faster to kill it

molten sky
#

67k unread messages

#

ngl my personal email (practically a spam email at this point) is probably at like 18k rn

sinful moon
#

Yes, ugh, unfortunately. We're down to four, two at one client, one at one client and one internal

#

Everyone else is on O365. We're making pushes to migrate client with two Exchange servers

molten sky
#

Zoom Zoom Zoom

sinful moon
#

lol

#

Sounds like an old Mazda ad lol

molten sky
#

hm. one of my huntress people on linkedin shared something about an exchange IOC but i can't find it now

sinful moon
#

I want a creepy child to whisper "Zoom Zoom" when I connect to my Zoom room plz

molten sky
#

just trying to figure out which version of my resume i even applied with

sinful moon
#

Interesting, also I plan not to make a LinkedIn until I really need to lol

molten sky
#

the person was quick to reach out tho, just sent it earlier today

#

gonna assume it's the several month old version and not the new one

#

okay thank you linkedin

#

no header no menu

#

awesome

umbral bay
#

👋

molten sky
#

found it

molten sky
#

🌊

umbral bay
#

Proper wave in blue.

simple valve
molten sky
simple valve
sinful moon
#

It’s like currently happening with all the devops rooms released recently, I need to catch up with them admittedly

#

I’m sure they’ll consolidate them all

simple valve
#

helo elizabeth

#

i have a problem

sinful moon
#

Heya!

molten sky
simple valve
#

have you integrated mail servers with a third party bulk email provider

umbral bay
sinful moon
#

lol having issues with new DKIM/SPF stuff for Google/Yahoo? I have not directly but help push some of those efforts.

We have an Email Security Gateway which is our main ingest/output. But typically we did have to log into the third party bulk email provers to properly test the successful DKIM/SPF and etc

molten sky
#

are y'all having dkim issues?

#

i haven't had anything pop up. just new requirements that it exists

#

( i think i misread )

sinful moon
#

Possibly but you're close on the mark, Mkunkn has some question about third party bulk email provdiers which my boss handled a bit more than I.

crude stump
#

Wait is the devops room the tickets?

sinful moon
#

wut

crude stump
#

Nvm

sinful moon
#

lol above they're clamoring for devops path, and we're seeing quite a few new rooms that align with such a vision

molten sky
#

unrelated but speaking of third party providers ffuuuuuuck sendgrid

crude stump
#

Im thinking about those tickets. The one where you wins stuff.

sinful moon
#

agreed lol

molten sky
#

such a pain in the ass to do anything with

#

bouta call them tomorrow and cause problems

sinful moon
#

see them among phishing senders plenty as well

lusty lantern
crude stump
#

Interesting name

sinful moon
#

although ironically *.onmicrosoft.com is getting to be among most prolific of the not great phishing we get

lusty lantern
#

why cant i use my own emotes wtf

crude stump
#

Verify prolly

lusty lantern
#

sadge

sharp citrusBOT
sinful moon
#

Just want people to block the first address they see, but also, lol these people aren't always using advanced phishing toolkits very well

crude stump
#

Popular opinion. Cranberry juice sucks

lusty lantern
#

fake

sinful moon
#

But I am more than glad to domain block Haskell28471.onmicrosoft.com or cooldentist.onmicrosoft.com in our systems lol (as theroretical examples)

crude stump
#

I have a scam blocker. It actually works hella good against bot calls

molten sky
sinful moon
#

X-Effective-From: more or less leaving out our filtering solution's name. This header identifies the true sender and can often expose legit uses of *.onmicrisoft.com

hot cairn
sinful moon
#

So we'd get false positives if just blocked them all

molten sky
sinful moon
#

Same deal if I blocked all the awful AmazonSES phishing we got lol

hot cairn
#

/ students

molten sky
#

eh who cares about the students

sinful moon
#

that would actually kill our EDR's alerting emails to us

hot cairn
#

Depends on the company I guess lol

molten sky
#

that's poor design

sinful moon
#

Nah I mean I can block individual AmazonSES fine, but you know how effective that is

#

but if you block AmazonSES globally, yeah you'll have tons and tons of false positives

molten sky
#

honestly you should be whitelisting trusted senders instead

#

so much safer

sinful moon
#

You possibly misunderstand just how much email we ingest lol

molten sky
#

nah they can wait

sinful moon
#

lol

molten sky
#

my fucking i key is sticky and takes me like 4 tries

#

every word with an i

sinful moon
#

tried and true messge of banging on the key a couple times to unstick, and hope there's no gross residue that's the actual cause lol

molten sky
#

the opposite, actually -- it catches on the way down and won't press all the way

#

like a ridge

sinful moon
#

Is this a mech keyboard?

molten sky
#

shitty old membrane dell from the basement cause my old keyboard broke

sinful moon
#

oh lol

molten sky
#

waiting til i has monies to buy a new one

sinful moon
#

probably plastic failing and or debris in membrane

molten sky
#

literally never used before 🤷‍♂️

#

just shitty dell

sinful moon
#

Meh I do have Dell tech that's holding up for 25 years now lol, but fair enough

molten sky
#

durable and refined are two different types of quality lol

sinful moon
#

Don't make me link my beautiful Pentium III machine again to proove a point lol

sinful moon
#

Too bad I’m doing it anyways, original PSU, original a lot besides GPU, RAM and Storage. Dat legendary Intel 440BX chipset that everyone emulates for compat

#

Plus bonus pic of my cat

molten sky
#

surprised how not yellowed it is tbh

sinful moon
#

Yeah it lived in basements, although I had the SO get some black out curtians for the room it's now in

#

I can likely retrobrite if needed, but prefer not to

molten sky
#

was gonna say that's an unfortunate desk

#

but it kinda brings it all together

sinful moon
#

indeed lol

#

Well now it's crammed into home office, since we needed that as a spare bedroom after all lol

#

and now server lives under this desk, excuse excessively messy picture

#

speaking of, I gotta check iDRAC. lol that little blue display turned orange with a warning

buoyant tree
#

heya Ellie

buoyant tree
sinful moon
#

10/10 series, do watch

sinful moon
molten sky
#

hey timtaylor you still lurking

buoyant tree
#

like top 220 on THM

patent obsidian
#

Hello, can someone help me with a phishing simulation?
I am studying Cybersecurity at university and they asked us to simulate a phishing attack using Microsoft's "Ethical Hacking Resources" application and I don't know what is wrong in my php code 😦

#

I'm from Mexico

sinful moon
#

Unfortunately we are not allowed to assist with school assignments, can always ask a classmate or official school channels for assistance! But no worries

buoyant tree
sinful moon
#

I’m getting a bit too sleepy tonight, maybe another time!

sinful moon
#

But here’s one more video game cover as a freebie, cover of an amazing into song on PS1: https://youtu.be/CiE8p5VjZgo

Sam and Steve do Time's Scar from Chrono Cross. Sam does some weird stuff with his face. What's up with that?

► GUITAR TABS and more at our Patreon Page!
http://bit.ly/SGBPatreon

► Listen to us on Spotify!
http://bit.ly/SGBSpotify

► iTunes/Apple Music!
http://bit.ly/SGBiTunes

► Google Play!
https://bit.ly/SGBGooglePlay

► SUBSCRIBE (so yo...

▶ Play video
#

Just wait for the drop lol

devout palm
#

Morning fellows

sick lance
buoyant tree
#

but good song

graceful thistle
#

what kind of music are you looking for

buoyant tree
#

or any scores

graceful thistle
#

ah okay

buoyant tree
#

preferred if violin's in there

graceful thistle
#

https://www.youtube.com/watch?v=EQ7fsaj-8jc&ab_channel=TaylorDavis

not sure if this is kinda what you're thinking. it's from an anime tho but still pretty sweet violin

buoyant tree
#

actually one of my favorite artists

#

playing her on shuffle atm

graceful thistle
#

nice

buoyant tree
#

if u got any artist like her lmk

chilly veldt
#

👀

#

Morning

buoyant tree
graceful thistle
#

Hmm I don't really have too much violin going on in my library

#

Arcade Fire - Song On The Beach is a beautiful piano piece tho

buoyant tree
#

listened to it also

#

and I think the ads are getting too targetted

graceful thistle
#

basically any Debussy is nice but I'm sure you're already familiar then haha

#

Oh violin 💯

#

hella good show too btw

chilly veldt
#

Happy Valentine's

naive violet
#

@glass nest

glass nest
#

Very neat-looking 🙂

naive violet
sick lance
#

You get a chatbot!

You get a chatbot!

#

Chat bots for everyone!

naive violet
#

35gb download
smh

#

Spooky popped XSS on it already

sick lance
sick lance
covert nacelle
#

oh, except maybe the flute, harp and viola sonata

shell nova
grizzled crystal
#

Uh oh

rapid merlin
naive violet
glass nest
#

Just gotta mkae a box for it now

rapid merlin
mental hound
#

May I ask some questions from a Pentester here? 🙂

sick lance
mental hound
#

How long does it usually take to finish a pentest process?

#

I mean... when all the documentations are done and you're there to start to enumerate.

sick lance
#

Engagements can vary, probably written in the contract when you can start and finish.

mental hound
#

Right. But does it take a few hours or days?

#

You know I'm just doing these rooms and I can finish it in a few hours.

glass nest
#

From one of TCMs videos on external pentesting:

#

but it will depend on the scope

sick lance
glass nest
#

40hrs is.. well, 8hrs a day for 5 days.

chilly veldt
#

Yup

mental hound
#

I'm just curious how does it work in real life 🙂

sick lance
#

There is no standard.

You could spend x amount of hours doing this, that and the next thing.

chilly veldt
#

You do it in a 9-5 fashion if not stated otherwise for as long as the contract is stated

grizzled crystal
glass nest
grizzled crystal
#

but normally clients want the bare minimum

naive violet
grizzled crystal
#

90% of my projects are a week at most

mental hound
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 386)

glass nest
#

james - obviously it'll work better when you attach those BNC plugs 😄

mental hound
#

And what if me as a "newbie" start a pentest and I'm unable to exploit the system, because you know... there aren't any writeups but someone else could easily?

rapid merlin
mental hound
#

I mean if I'm not good enough...

#

If I miss something

grizzled crystal
#

if you can't do a pentest technically you can't be a pentester

rapid merlin
grizzled crystal
#

Ah you'll normally be mentored by a senior colleague

rapid merlin
#

Just study more

glass nest
#

Well, You'd not be working in the industry if you couldnt, but pentests are done by teams. You'll have co-workers and stuff

grizzled crystal
#

They wont just push you into the deep end

sick lance
grizzled crystal
#

As for missing stuff - you're only human. You should just do your best

sick lance
#

Sometimes I'm sure companies will have their stuff together.

Not looking at you SolarWinds123

grizzled crystal
#

And follow a methodology

#

If you have a checklist you're less likely to miss stuff

glass nest
#

Yes. No about 'Missing something' - Like Scrubz says, it might be a secure enough system. In your meeting with the client, you'd go through what you'll be looking for and your (or the companies) methodology would (or should) be set up in a way that will check for those.

#

Scrubz and Aquilo making my point while typing it.. I swear you are watching my computer...mutter mutter hackers

mental hound
#

😄

sick lance
#

As for write ups.

I don't think you'll get access to a previous scope and contract, I could be wrong, I'm sure the NDA would kick in though?

grizzled crystal
#

You can get access to the previous pentest report

glass nest
#

When I was in forensics, we basically had templates.

grizzled crystal
#

Doesn't exactly work as a writeup tho

#

What do you mean by writeup? @mental hound

sick lance
glass nest
#

I'm sure pretty much every company does

sick lance
#

Unless they're treating a pentest as a CTF

mental hound
grizzled crystal
#

Yep, at my place we generate our reports using a report tool and then fill in the blanks

sick lance
glass nest
#

Thats terrifying. Why you listening to me type?

grizzled crystal
glass nest
#

Thats as mad as someone hacking a bios based on the sound of the fans on startup

sick lance
grizzled crystal
#

I mean you could but that'd be a fast zero day

mental hound
#

Thanks everyone helping me with your thoughts. You're legendary 😉

glass nest
#

bella - ---> found one

grizzled crystal
#

Sure thing

grizzled crystal
glass nest
#

Scrubs, so one of these drones hovering outside my window is yours? Dammit

mental hound
#

Have a great day guys. I'm going back to learn 😉

chilly veldt
#

Didn't take longer than 3 days

grizzled crystal
#

That's fair it defo happens

chilly veldt
#

Yeee, it's also OT

sick lance
grizzled crystal
#

IOT stuff is fun

glass nest
#

oooh, that was ALMOST a classic interenet reference

chilly veldt
grizzled crystal
#

What is OT?

glass nest
#

another IT acronym

#

Of things?

grizzled crystal
#

Ah operational technology

grizzled crystal
glass nest
#

Oblong Table?

grizzled crystal
#

Osome Time?

glass nest
#

Ordinary Thing?

#

Osmosis Trend?

#

could be anything

grizzled crystal
#

Truly a mystery

chilly veldt
sick lance
#

Man, when members get muted, why do they always DM me to them un-muted.

chilly veldt
glass nest
sick lance
#

Hex puts monster truck tyres on for fun.

chilly veldt
#

I wanna do that, but my car is too low

glass nest
#

Hex wears a tractor tyre on his pinky finger as a ring.

#

( @silver sky I just 'Chuck Norris'd you )

silver sky
#

Oi oi

#

I am classed as heavy machinery

brisk tree
#

Hey

primal surge
#

Hi everyone, I have a question about John: Im giving it a hash to crack, and it sends me "No password hash loaded" and I dont understand why... (I use a Ubuntu VM), the command i used is john key.txt, here is the beggining of the hash :

key.txt:$sshng$1$16$6ABA7DE35CDB65070B92C1F760E2FE75$2352$22835bfc9d2ad8f779e84676de801a2712ef86e499d5cad1af838d19402729c471837fbdbe7eb172e8e9cd40ee52d959a3d772204241e305194ee7813ec99be3ced17455644ce550ad51edcb52b668bcb62e46b60a77e3cfc2e5bfe14c69db0d5d1be3c3f1d18867173d8f01ee7b00d5e88f62b3d91c81f740e14862548f318bfbf510bae62e9fae40d2bf15f36dd7d702400dfb74f9154e3d00454a049b599cb4c4070df59b18efd252d702a21a5f941f79731a70840e51608701396955798d946e01686edc557b350263e279f971eee37846e07d3594b8669d25a656c26f85046b05f44edf9529dea4ce1f8193469485640909d9dbfd4f9d45ab2ede8c6aca494a53674fb1e53bae5bcf02a6bacbea202bfc284db9d3ae446780aa8b431325948599c9ee32acb1137dcdbbe61cd555887a1642e0b4e7da972d1b32a188accf9e595a173ab64f065bfc8b23530dd0c4de3463a9b38694fb34d6101628847150f684af5f25719f8e958d34570da834bdb129482d4295768f01f4e3219d5db7c92d85a55f19c926954c84a0ba6bbe697b8655c5f98cb7441c2b8a0a3b569118ca8b14dc1a3f125857a1dab94a1513137b6d4a68f9e2d856ce66a39b5ba560e18b43517e718fd6de9b9fb4ef6fbec009ac86cc774ba4802a666bffd21c114e7adb455858d4251fef118d99b9b3607ccd130329a44da2f261526951422440b7703827e53bd05177e1e82249455ae177157256a563b28b7e0b317b99b5a6e6716c4cf3e53a79dd0ba266ad41148de21b2f305c5ba6d7e6cf

pallid lotus
heady nova
#

Ello

heady nova
grizzled crystal
gritty zephyr
grizzled crystal
#

A room is very different vs a pentest

gritty zephyr
#

True that, but i still miss alot

grizzled crystal
#

You're trying to "solve" a room, not note down every vulnerability that exists

grizzled crystal
#

I still feel like my recon is terrible but it's way way better than it used to be

gritty zephyr
#

Yesterday i was going down a rabbit hole that led nowhere because i forgot -p-

#

Always fun to repeat those mistakes

chilly veldt
grizzled crystal
#

I think muiri means that there are some silly-easy zero days to exploit out there

chilly veldt
#

yeah, that too

grizzled crystal
#

you're more likely to get that 'wait wtf did i not check this?' moment

chilly veldt
#

Speaking about OT and 0days, this one was what I was talking about Aquilo CVE-2023-20235 😄

grizzled crystal
#

and it hopefully won't be 12 hours in 💀

#

Ohhh docker shenanigans!!

chilly veldt
#

yup

#

they got asked to test the switch for a customer and found that vuln

grizzled crystal
#

I want to try to get a CVE this year, need to start poking at different products

heady nova
#

Ello bella, poki long time.

grizzled crystal
#

Hi hi i remember you!

#

You're the JLPT guy?

gritty zephyr
heady nova
#

Haha yes

jagged moon
grizzled crystal
#

Ahh how's the JLPT journey going?

#

Hello fluff!!

heady nova
#

I hit alotta people thinking they were you XD

grizzled crystal
gritty zephyr
heady nova
grizzled crystal
#

Report writing is a great skill to have

grizzled crystal
#

I may pick N2 back up later this year..i want to start taking classes again, i've been really busy so no time

#

although i've forgotten a LOT

#

it's bad

heady nova
grizzled crystal
#

That's not me i dont think

heady nova
#

Retro computing?

#

What was the term

grizzled crystal
#

You're thinking of ElizabethNoir

heady nova
#

Ah F

grizzled crystal
#

Hehehe

jagged moon
#

Oof

gritty zephyr
heady nova
#

We've had this convo before Haven't we

grizzled crystal
#

It's very funny

heady nova
#

No wonder I keep failing robot checks. My memory got corrupted

#

But yeah I seem to have mixed info on a bunch of people

sick lance
grizzled crystal
#

It's kind of hard when there's lots of people chatting

heady nova
#

Anyway. I atleast remember that you know Japanese

grizzled crystal
#

Know is a strong word

heady nova
#

And you went to a sushi shop that dolph visited

grizzled crystal
#

I am learning! (but it's been awhile LMAO)

grizzled crystal
#

Not sure who that was

jagged moon
sick lance
jagged moon
grizzled crystal
#

LMAO

#

all you need to know

heady nova
#

Hi humans, I don't know who's who

grizzled crystal
#

It's okay buddy

#

You'll get it eventually

gritty zephyr
#

Am btw reading ghost in the wires, great book, really compelling read

grizzled crystal
#

Oooh cool

gritty zephyr
sick lance
#

Fluff is either not in Germany, or not Russian.

heady nova
# grizzled crystal It's okay buddy

I'll formally introduce myself then. I'm usually called Tank/Rinz. Been here for about 2 years but only been active for around 6 months. I think I met alotta people here or not so I don't remember who's who, my bad. I'm still a student who'll graduate in mid 2025 and now I know German and Italian too

#

Yup that's all

grizzled crystal
#

Cool! I'm Aquilo, I'm a pentester

#

I pop in and out so i'm not super active

loud marlin
#

u ar poki 🙂

grizzled crystal
#

yes i am poki

heady nova
#

Ello ralex

loud marlin
#

ello ello

heady nova
grizzled crystal
#

I may change my thing too eventually

heady nova
#

Forensics, defense, offense, engineering, devsecops, cloud, hardware

grizzled crystal
#

It's good to experiment

#

Yes blue team seems fun

mossy river
#

🤢

grizzled crystal
#

but i'm leaning towards red team hard

heady nova
grizzled crystal
grizzled crystal
sick lance
#

Oh I wondered where poki went.

Just a name change.

heady nova
mossy river
#

I am a professional blue team hater

grizzled crystal
grizzled crystal
grizzled crystal
mossy river
#

So boring

grizzled crystal
#

What

heady nova
#

Now comes space problem

grizzled crystal
#

What do you mean boring 😨

mossy river
#

It’s dead

grizzled crystal
#

What do you want to do jabba?

loud marlin
mossy river
#

#redteam5lyfe

grizzled crystal
#

Ah you want to get into red teaming?

heady nova
grizzled crystal
#

evading edr and stuff i presume? actual red teaming or do you want to get into pentesting?

#

or are you just into the offensive stuff?

heady nova
#

Offensive jabba

mossy river
#

Pentesting but I’m not fully locked into anything yet

grizzled crystal
#

Ah okay

loud marlin
grizzled crystal
#

Pentesting is fun. I think you'd enjoy it

sick lance
#

Jabba is a closet blue teamer.

grizzled crystal
#

People tend to hate on the report-writing but it's a good time i swear

mossy river
grizzled crystal
#

I like writing reports

heady nova
loud marlin
#

ah. fair

sick lance
heady nova
heady nova
grizzled crystal
#

Generate reports based on a premade template, save 20 hours in formatting

heady nova
#

But I think you already got that don't you scrubz

sick lance
#

Not yet, I'm waiting.

heady nova
grizzled crystal
#

a lot and as professional as you can make it sound?

#

This is a very vague question

heady nova
heady nova
grizzled crystal
#

Like a table of contents?

heady nova
scarlet mantle
#

i hope everyone become good person in future and hapy

heady nova
grizzled crystal
#

I mean you can kind of judge it for yourself when you finish the report. How quickly can an executive get the gist of what the report is?

main kraken
#

He

#

He

heady nova
sick lance
grizzled crystal
#

You definitely want a ToC and an executive summary, but no matter what job you're doing i doubt you'll be making the report template

heady nova
#

Tanks poki

#

+rep @grizzled crystal

twin ridgeBOT
#

Gave +1 Rep to @grizzled crystal (current: #123 - 50)

grizzled crystal
#

or in the beginning of the report

#

but at the end of the pentest

main kraken
#

Scrubz. remember the problem i had yesterday? to ssh james the password for james was november16 right? when u tried to ssh in and it worked did u use password november16?

heady nova
grizzled crystal
mossy river
#

So tired 🥱

heady nova
heady nova
mossy river
#

Gym time

heady nova
mossy river
#

Need more redbull

sick lance
#

Les is redbull, more water

grizzled crystal
mossy river
#

I have a lucozade alert but it doesn’t hit the spot

glass nest
#

But Lara Croft drank that, and shes a Tomb Raider...

solar thunder
#

Hi!

sick lance
#

Hello!

grizzled crystal
mossy river
#

Redbull sponsor me

chilly veldt
solar thunder
chilly veldt
#

my pronouns

gritty zephyr
sick lance
#

Doesn't have a pfp with red bull.

#

And a rabbit

gritty zephyr
#

No only the rabbit

#

Bunny?

#

Huh

#

My English brain left me

#

Theyre the same(right????)

bold dawn
#

so tired though

mossy river
gritty zephyr
#

Rabbit bunny?

sick lance
#

I need to buy new running shoes.

rapid merlin
jagged moon
#

At least you have an English brain

rapid merlin
#

Yeah

jagged moon
chilly veldt
gritty zephyr
rapid merlin
#

I had a 10 for English lissening test

gritty zephyr
#

I do almost anything in English

rapid merlin
#

dominating

#

is that a word

jagged moon
rapid merlin
#

10 = 5 =A(+?)

gritty zephyr
solar thunder
rapid merlin
#

Jester can i DM you?

gritty zephyr
#

Ayo wtf dont trigger my bad side like that

gritty zephyr
#

Im so confused?? Thanks?

jagged moon
gritty zephyr
#

XD

#

Thats awesome

chilly veldt
gritty zephyr
#

I find multiple pronouns have an ease of use so to speak, you have two to choose from

#

Bella do you have a preference?

chilly veldt
#

Sometimes I don't other times prefer she/her

gritty zephyr
#

Gotcha

jagged moon
#

Off for lunch

#

Behave!

sick lance
#

No promises!

gritty zephyr
glass nest
#

(For a given value of 'line')

rapid merlin
bold dawn
#

we got A+ through F

#

usually based on a 100 point system

#

some local school did 1-5 though. My wife’s school did that

bold dawn
#

breaking in some new jeans at the gym today

broken thorn
bold dawn
#

it that not normal?

night prairie
#

sheesh

#

wasnt my name a diff colour

broken thorn
# bold dawn it that not normal?

Normality is often described as what’s consistent and expected from a societal perspective - saying that, society is crazy nowadays so do whatever floats your boat, I guess, lmao

bold dawn
#

lol technically my gym has a sign saying not to wear jeans while working out

#

says it’s “intimidating”

#

well for me, it’s just convenient lol

sick lance
#

2 rooms until 800.

mossy river
#

Are we seeing different numbers

sick lance
sick lance
mossy river
#

Weird, unless three rooms were released within the last 24 hours

mossy river
#

The stats should be using the same API to get that information

bold dawn
#

How often does the bot update the number?

#

cause discord shows 795 still

mossy river
#

Every 24 hours

bold dawn
#

ah

#

why the facepalm? are you not also questioning it above?

shell nova
chilly veldt
#

AAAAAAAAAAAAAAHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH

shell nova
chilly veldt
shell nova
sick lance
#

Why?

If anybody scans/tries to attack me.

THM will see it. 😎

shell nova
#

Also default Kali environments are pretty secure

sick lance
#

I know.

chilly veldt
# shell nova Oh that's another issue, sup?

hapyy thoughts flowing through my brain, cause I just had a phone call with some people about some project and they both are okay with me being autistic, and using they/them and she/her pronouns

sick lance
#

I'm not concerned with with my Kali being attacked, I don't use default creds either.

shell nova
sick lance
sharp citrusBOT
#
Pong!
API Latency

114ms

Client Ping

473ms

mossy river
devout palm
chilly veldt
sick lance
shell nova
grizzled crystal
chilly veldt
#

I got called a SME 😎

mossy river
shell nova
chilly veldt
#

can't say much about it, but it looks promising

shell nova
devout palm
#

why

#

i do that

sick lance
worn thorn
devout palm
#

Because i like control

shell nova
#

You shouldn't be running anything as root unless it absolutely needs it, and even then

mossy river
#

I thought they didn’t use toor for the password in forever

worn thorn
devout palm
sick lance
#

Although when I count on the website, I get 766.

76 pages of 10

one page of 6.

76 * 10 = 760 + 6 = 766.

#

Unless my Maths isn't mathing.

mossy river
#

There’s rooms that aren’t on that page that are included in the calculation

worn thorn
#

use it on demand not constantly. It's bad.

sick lance
#

Which could very well may be the case 🤓

chilly veldt
#

or just the unknown factors

devout palm
#

Why shouldn't i use root in a VM?

#

I don't care if anything happens to it

mossy river
#

Not only is it bad practice but it also breaks tools

#

Your goal should be to create good habits not bad ones

devout palm
#

Bad practice ok, how does it break tools

chilly veldt
#

permissions

devout palm
#

Elaborate?

chilly veldt
#

some tools set permissions based on the user that runs it, if root user runs the tool, it can break the permissions for other tools making them not work

bold latch
chilly veldt
#

that too^

finite tangle
#

Hello mates,

I am a Intern student from INDIA and want to get monthly subscription of TryhackMe. When I try to subscribe its only allow credit card and paypal account that I don't have. Can anyone suggest, is there any other payment mode to get the subscription.

sick lance
#

sudo & su is best practice.

daring gull
#

Any book recommendations for digital forensics?

devout palm
#

Makes sense

#

Now

sick lance
sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

sick lance
bold latch
#

If you ever remotely use the user account rather than root, even for starting up your OS and logging into LightDM to enter your session, anything you do as root will likely not be accessible

#

Ie you open up dolphin to browse your folders. Whatever you made as root, you won't be able to see. The app manager launches dolphin with the privileges of the user which logged in to that DE session

bold dawn
bold latch
#

Or if you can see it, you likely don't have read/write permissions so nothing goes in or out that folder

bold dawn
#

oh boom

#

book

#

I read “tool”

#

my bad lol

bold latch
#

Unless you painstakingly open up a terminal, and run "sudo dolphin"

finite tangle
twin ridgeBOT
#

Gave +1 Rep to @sharp citrus (current: #264 - 18)

bold latch
#

Speaking of "best practises" I should probably change my baremetal system's password from "root" sometime soon. Just freshly installed it and that's the placeholder until I've done all the initial installs I need

bold latch
#

I'm not installing anything outside of the trusted repos though, so unless someone's tampered with those I'm alright for the moment

simple valve
scarlet mantle
#

what would it take to be able to escalate from hacked vm to hacked host

#

a cia elite expert?

#

until then im safe if only my vm gets compromised right

sick lance
#

A 0day.

scarlet mantle
#

ah.

sick lance
#

And nobody is gonna burn one of them on a random.

scarlet mantle
#

thats hard to find right?

rapid merlin
bold latch
#

Easier than you might think

scarlet mantle
#

LOOOOOOOOOL

bold latch
#

That's why I'm changing it soon

scarlet mantle
#

@rapid merlin i dont know this person and is harassin me

#

and scrubz cal me a random

#

help

#

MODS

sick lance
scarlet mantle
#

@swift patios

bold latch
#

Soon, because I am not physically there yet

sick lance
scarlet mantle
#

it says he is moderator

#

i only ping the nice mods

#

because when ill be in the the professional setting i want be prepared social setup and public relationship and not ask favours yet

sick lance
#

It's just a name. kekw

scarlet mantle
#

i hav so many things to say

#

this is it for today

#

sight

sick lance
#

Uh, Ok.

scarlet mantle
#

is fine

chilly veldt
#

I have to start drafting a draft of a draft so I can send that to my manager to get that draft drafted properly, which I then can start drafting the final version

sick lance
#

You might be cold with all them drafts,

chilly veldt
#

yeah, I am wearing a hoodie to not drift away in the drafts

sick lance
#

Having more monitors is always a benefit.

#

Trust me, I have 5. kekw

crude stump
#

5 all on your desk?

sick lance
#

3 on my desk, two on the wall.

crude stump
#

Damn

sick lance
#

Full SoC centre here.

chilly veldt
#

I got 3 monitors

#

planning on a 4th when I get a good paycheck and gotten all the other stuff I need

#

but first, a proper power supply for my pc 😄

bold dawn
#

need a dock before I can add more

rapid merlin
main kraken
#

How do i turn openvpn off to thm i did ctrl+c and closed terminal but im still connected

sick lance
main kraken
#

What are you using 5 for?

main kraken
#

okay

rapid merlin
#

Spotify? Discord? 😛

sick lance
rapid merlin
#

five VM's? Interesting

#

For testing purposes or smth?

sick lance
#

Kali, AD and other things.

rapid merlin
#

Ah

#

Alright alright

main kraken
#

I think i have a problem

sick lance
main kraken
#

But i need to disconnect bc i think smth wrong i cant even ssh anymore

#

to thm challenges

sick lance
#

That page could be bugged

ip a | grep "tun"

main kraken
#

That worked

#

Ty!

chilly veldt
#

oh well, time to go home

night prairie
#

How you been anyway? @sick lance

sick lance
sick lance
rapid merlin
#

@lethal spruce

#

Go to learn

#

Then again learn

#

And choose one of the paths

#

I would recommend Pre Security

lethal spruce
#

ok thanks

#

this is not completely free I did few tutorials now its accessible for premium users only

#

Is it completely free

#

Alright

chilly veldt
#

92% of tryhackme is free, the paths just show some planned rooms together which is why some of them are paid rooms

#

If you go to the "search" feature you can see all rooms and will be able to sort out any paid rooms

#

If it's just something that doesn't work then it's just putting it in #room-bugs or #site-bugs if it's an actual security vulnerability, then you'll want to contact support

twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #7 - 807)

forest mortar
upper chasm
#

anyone has an issue connecting via openvpn?

worn thorn
#

if you really need an attack box then just setup your own vm

split compass
#

Finally, car theft is over. The flipper zero, and any similar wireless spectrum computer board, I guess, need to find the language of the act, is banned. 😅

shell nova
#

rofl

split compass
#

I have some letters to write today to my MP.

shell nova
#

like that'll do anything

chilly veldt
#

You sure that it's correct, what if you press ctrl+f5

split compass
#

Gonna tell them to be screwdrivers because they can be used to turn the ignition of a car.

Maybe wire cutters too that can be used to disconnect alarms. 😓

shell nova
split compass
chilly veldt
#

Throw a mail to support then

scarlet mantle
#

i hate being rich i hate easy life and i hate fame and yesmen

#

biggest bait in the book

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

shell nova
zinc prism
#

I heard that it's necessary to finagle in some other software and tools to get better functionality on the Flipper

shell nova
#

there is a bug bounty program

#

please report the issue to support

sharp citrusBOT
sick lance
#

Good luck

shell nova
#

be sure to be precise and detailed in your report

twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #12 - 542)

shell nova
zinc prism
shell nova
#

don't be stupid 😉

#

don't attack things without permission

zinc prism
#

if you don't have permission to do a thing, then it's illegal and you could face prosecution and all that entails

shell nova
#

generally explicit written permission from the true owner of the device/network

zinc prism
#

yeah

shell nova
#

attacking "your gmail address" for example, is illegal

#

IMO, there is none

#

grey hat is mostly vigilanteism, which is also illegal

#

we do not condone that sort of behaviour here, and doing so may result in you being removed from this server

#

bingo

rapid merlin
#

And because of them

#

ur not in jail

#

:))

#

That’s why labs exist like tryhackme and hackthebox

shell nova
#

just remember to stay in scope

rapid merlin
#

But thats also a fun part right?

#

And you can use a cloud PWNBOX or not?

#

Im not on HTB so idk

shell nova
#

I got started a few years back with an offline CTF

#

naw

#

internal corporate

rapid merlin
#

Attackbox ftw

#

Make a bug report then 😄

shell nova
#

attackbox is unlimited for subscribers

#

that's assuming they qualify the bug

chilly veldt
shell nova
chilly veldt
#

Yup

#

That's why I said at a time

rapid merlin
#

But lets be honest, your own VM is always better

#

Even as a subscriber

#

With one screen yeah

#

But still, when im on my laptop without external screen

#

And im using attackbox

#

Full screen mode

#

😄

bold dawn
#

HackThisSite

shell nova
#

I mean I use my VM over ssh so

atomic aurora
#

Hey guys, how are we all doing today? 😄

shell nova
#

I started learning stuff on RootMe

rapid merlin
#

I started on THM :p

shell nova
#

it's ancient

bold dawn
#

Real old

#

Outdated

twin ridgeBOT
#

Gave +1 Rep to @atomic aurora (current: #1995 - 1)

chilly veldt
#

Today has been an amazing day for me

atomic aurora
#

I'm good thanks! I was just reading your guys's conversation. Very interesting. It all sounds a bit like chinese for me still but I hope that within some months i'll be able to join you guys xp

twin ridgeBOT
#

Gave +1 Rep to @hasty star (current: #1995 - 1)

rapid merlin
#

Wait-

#

It is valentines day

#

Didnt know

chilly veldt
#

Yeah

rapid merlin
#

Single life ftw

bold dawn
#

I forgot and I'm married

rapid merlin
#

Watching Champions League and doing some THM this evening

rapid merlin
bold dawn
#

never once have I celebrated V day

#

My wife doesn't like it

#

when I remembered this morning I texted her

#

plus our anniversary is 3 days after V day lmao

atomic aurora
chilly veldt
#

My Valentine's Day is celebrated by going shopping for a new pair of running shoes and then going for a workout

bold dawn
chilly veldt
grizzled crystal
#

I have ordered pancakes for myself hehehe

bold dawn
#

I got my wife a gift for it, I just gave it to her 2 days early

chilly veldt
#

Just missing that out

rapid merlin
#

I started my day with an exam about economy

grizzled crystal
bold dawn
#

Got her one of the Cirkle flavored water bottles

grizzled crystal
#

Maybe you can bring home some chocolate

chilly veldt
#

I should also go grab myself a weight, so I can weigh myself

#

I'll add it to the shopping list

bold dawn
#

then had a nice date planned for sat (anniversary), but now we have a family funeral this weekend

grizzled crystal
#

Oh I'm sorry

bold latch
bold dawn
#

it started telling me my weight in the color orange bc I'm overweight by BMI standards

rapid merlin
#

uhm is this a black hat or white hat server

chilly veldt
#

I am also grabbing one that can calculate BMI lol

rapid merlin
#

White

chilly veldt
#

Only

rapid merlin
#

ok

#

im white hat

#

Any black hat stuff will get you removed according to the rules 😄

chilly veldt
rapid merlin
#

guys what is the main difference to white hat and black hat hacking]

#

im new to this

atomic aurora
#

white is ethical

rapid merlin
#

White hat is legal, black isnt

chilly veldt
#

Legal vs illegal
Permission vs no permission

bold latch
#

Well, one's illegal and the other isn't

rapid merlin
#

but is writing the code different

bold latch
#

4 person explanation combo

rapid merlin
#

yeaa

chilly veldt
bold latch
#

What?

atomic aurora
#

Oh i also didnt know this

rapid merlin
atomic aurora
#

so based on if you have permission or not and what you do with your access dictates which one you are?

#

or are there other factors

rapid merlin
#

i only know the white hat hacker called malwaretech

rapid merlin
atomic aurora
twin ridgeBOT
#

Gave +1 Rep to @icy epoch (current: #687 - 5)

rapid merlin
#

No problem 😄

atomic aurora
#

Have any of you guys pentested a local company before?

rapid merlin
#

no

#

im new to this

atomic aurora
#

me too 🙂

rapid merlin
#

want to be friend

atomic aurora
#

hell yea

#

zen do you have any background in it?

#

studies or so?

bold latch
rapid merlin
#

Black

#

ohhh

atomic aurora
#

Have you ever pentested a company before if I may ask @bold latch

rapid merlin
#

i thought sony hired them

#

But they didnt pentest sony themselves right?

#

Lizard Squad was a black hat hacking group, mainly known for their claims of distributed denial-of-service (DDoS) attacks[1] primarily to disrupt gaming-related services.

#

DDoS is ALWAYS black hat

#

Lizard Squad was a black hat hacking group, mainly known for their claims of distributed denial-of-service (DDoS) attacks primarily to disrupt gaming-related services.
On September 3, 2014, Lizard Squad seemingly announced that it had disbanded only to return later on, claiming responsibility for a variety of attacks on prominent websites. The o...

#

alr thx

atomic aurora
#

I swear im learning so much rn just by reading people's conversations lol

rapid merlin
#

same xd

#

which groups are known for good hacking

rapid merlin
bold latch
mint palm
rapid merlin
#

If you touch things you shouldnt you can get in real trouble

bold latch
#

We have also verbally agreed on scopes as well, but once again I am not contracted because I am not legally able to be yet

rapid merlin
#

guys is 4chan full of black hat hackers or some white hat too because i want to chat with the good guys

atomic aurora
#

I'd always make sure to have something on paper if I were you tho

rapid merlin
#

whats a grey hat

atomic aurora
#

verbal agreements mean nothing in court

#

Just saying

rapid merlin
mint palm
#

Yeah you should have everything on paper for your protection. There’s a lot of legal stuff behind a penetration test

#

Especially if you have no experience and are more likely to break things

bold latch
atomic aurora
rapid merlin
#

oh so they arent the best talking to then

rapid merlin
# rapid merlin whats a grey hat

Grey hat hackers are people who are hacking for good purposes but dont have permission. It is still illegal like @rapid merlin said

bold latch
#

And I'm aware of techniques which can strain servers or damage systems, so I'm not doing anything of the sorts

rapid merlin
#

Alright alright, but watch yourself

mint palm
rapid merlin
#

Yes they can

bold latch
#

A ping and service probe is basically unable to do anything. A vulnerability scan, on the other hand, sure as hell can

rapid merlin
#

No, also a port / service scan can break things

mint palm
bold latch
#

Good place to say though, cautious when nmapping sites you haven't been authorised to, for the new guys here

rapid merlin
#

Go ahead

bold latch
night prairie
rapid merlin
#

problem with cybersecurity is its hard to get noticed since so many people are applying for jobs requiring it

#

In my country, in fact, it isnt that hard

atomic aurora
#

I am new to cybersecurity with no IT background (studies) whatsoever. I recently decided to make a career change. I am now doing the Pre Security module on THM. Is everything you see/learn enough to start working in cyber sec? Or would you guys recommend other fundamentals? If so, do you guys know a course/website where I can learn these things? I'm just very interested in Cyber Sec. Thanks a lot in advance, you're helping me out a bunch

mint palm
sour otter
#

aye, where is esqy , he there ?

bold latch
#

Nmap even has a safe-checks option to minimise said potential damage from a nmap scan

atomic aurora
rapid merlin
#

Alright alright

bold latch
atomic aurora
#

I like to self study and have learned a lot already

mint palm
bold latch
#

If it does, the teams here aren't going to sue me over it

mint palm
rapid merlin
#

whats a cryptographic failure

bold dawn
#

this is becoming an argument over ethics. let's stop

bold latch
wild rose
#

already a spicy morning? or just simmering.

sour otter
#

guys did naughty leave the server

bold dawn
#

being sued or not doesn't make it okay. There are reasons that scopes exist, to protect items that may be damages or affected negatively.

#

If you want to practice, find a bug bounty program and scan that. MAKE SURE scanning is in scope

bold latch
#

Its less around the ethics more around the impacts of scans at this point. So, pretty interesting stuff, I'm still learning from this

sick lance
bold dawn
#

I've seen a network pentest factory reset a network connected soundboard

#

just due to too many requests crashing it

hollow pivot
#

Hey, did you email support? Could you DM with your email? THanks 🙂

twin ridgeBOT
#

Gave +1 Rep to @hasty star (current: #1321 - 2)

mint palm
#

Yes, it’s still illegal

hollow pivot
#

I got that, but can you DM the email address you contacted support with?

atomic aurora
#

gulp

rapid merlin
#

Dark grey

night prairie
# sick lance Well that's not good! How long left?

I'm in my final semester for this year, so just one more year + placement if i find one
final year should have some more interesting modules at least, we got reverse engineering and exploit dev modules next year

night prairie
bold dawn
#

by legal standards, that is illegal

proven quartz
# night prairie 2 years into my cyber degree and I've lost motivation, not going well xd

Burnout happens but you can find ways to manage it. Make sure you have other avenues to enjoy your time. Read non-college books, go walking, get exercise, join a club, go travelling, cook healthy food, have a holiday, speak to a counselor, hang out with your friends more... Find other ways to redirect your focus and know that you're making progress towards your goals

night prairie
twin ridgeBOT
#

Gave +1 Rep to @proven quartz (current: #23 - 347)

night prairie
#

oh it shows position and total now

#

+rep @night prairie

bold latch
#

Right, I'll diffuse the convo here. Thanks for all the concern though, I still appreciated the conversation

night prairie
#

well that makes sense, i'll check what it is in the future ig

rapid merlin
#

+rep @night prairie

twin ridgeBOT
#

Gave +1 Rep to @night prairie (current: #100 - 62)

rapid merlin
#

here u go

night prairie
#

thanks

#

oo 100

rapid merlin
#

hi fbi agents

rapid merlin
night prairie
#

we had an industry talk today about exploit dev, probably should have stayed for the full thing

sick lance
rapid merlin
#

they taught us to not click links and dont use ur cred card

mossy river
mossy river
atomic aurora
#

KEKW

rapid merlin
#

xD

mossy river
#

@rapid merlin What you did was a crime and is not tolerated in this server.

rapid merlin
#

what who committed a crime

mossy river
#

Further discussion will result in a mute or removal 🙂

night prairie
mossy river