#general
1 messages ยท Page 26 of 1
and my hollow skull makes my voice sound deeper
Whenever i sing on my own, it feels great at first but then i ruin a note and feel embarrassed
Aye OK Barry.
My recorded voice is deeper than what I hear
i'd prefer Morgan, but Barry is cool ๐
Morgan White doesn't have the same ring to it.
Barry Freeman?
'Andy Dufresne'
White, Barry White.
I know, I was taking the joke too far, again
Coffee coffee coffee
Tea?
That'd work too
Hot Bovril?
beef tea?
Pretty much ๐
Sure
On my way to work nr2
where would i go to learn about yersinia network protocols
Anyone here have their own CVE registered
Pretty sure quite a few people here do
Yeah, Ryan does I think
Many do
How much time does it take for a confirmed bug to be registered as the CVE? (If the company itself is in CNA)?
Average
I believe muiri has one as well not sure
Depends I guess
Does it take more than 1 month?
Could easily yes
Have friends who have waited 3 months on theirs before they got it
Yea depens on severity and patching i guess
Just installed QubesOS.
Itโs completely broken.
I hate it here.
ngl these active directory stuff got me on ropes
the entire thing is just intertwined
Its open flr everyone btw
probably depends on when the fix is released
It's strange and rickety the first time you install it compared to your average OS, yeah. Its built with the infrastructure you'll use the VMs more than the host OS
I mean, if they applied for a CVE (after fix) how much time will it take approx? Does it depend on the CNA
who cuts vertically?
@sinful moon wanna feel old? https://youtube.com/shorts/2vU-ozLcbYs?si=aTPmXVk0sfjUsiM6
clearly people who can't handle more sandwich
Psychopaths
The blockbuster one ๐
I remember going to those and renting PS2 games ๐
lfie bug?
Hi everyone, I was just curious do we have roles we can assign ourselves if your going/becoming a red teamer or Blue teamer..etc
IIRC Red teamer role was for an event and it got deleted
There are no specific roles for that
Ah I see thank you!
That's funny, I am the costume lol -- Party like it's '99 fo' eva
Doesn't really help that my installation seems to be busted. Got no templates, no network, only Dom0 runs and no of the buttons in the qube manager do anything.
dnf is not present either.
L Bozo
Going over old clips with my friends is so funny
Managed to do a 720 today skiing! (definitely didn't fall over at the end)
check dms
Happened to me last time I tried installing Qubes as well. Thought it was the fact I didn't allocate enough space for the machine types
Honestly that's kind of the use case of Qubes. If you don't have a really good understanding of linux, networking, VMs, and containers, you are going to struggle a LOT
You ever think about how intensive Qubes probably is on disks? It has to commit a read of a few GBs worth of template data each time a new machine is started to copy to mem
Got it from this site: https://www.flaticon.com/
You can pick and choose what icon you want and download it.
Yep, as I'd said while ago, takes a steep learning curve
If i have to make a ret2libc atack how do i leak the libc base address on the remote system? I can do a intf vulnerabilty btw, and also i have PIE enbled on the binarry
SAMEE
is this for a THM room
yes
I am down for that. And struggeling.
Lmao.
Currently preparing a new installation media, maybe that will work.
Hmm, I gave the entire thing 1.4 TB or storage.
For the VMs it showed a little over 1.2 TB being available.
So that should be ok, I suppose.
Wonder whether it has something to do with the fact that I have two separate SSDs, maybe I should install it on only one disk or something.
To 3d print an m.2 screw hmmmmm
thats a challenge
Yah, so tiny
Even with 0.4 or 0.6mm nozzle at 0.1/0.2 layer height it's still going to be a PITA
Yeah. filament is 1.75.
Just the width of that.
might be easirt to make a 2mm 'pin' then tap it
It's so tiny. I can't find someone on Thingiverse who has posted it 
I don't think it'd be possible..
just based on the filament/nozzle with.
It'd have to be smaller/equal to the threads
To spend pennies at a hardware store for one, or hope that the 3d printed 2mm pin doesn't break in my server... HMMMMM
Print it. Don't risk leaving the house. Bears live in the outside.
Like it's already got a standoff in it, so can't put my own standoff
Because this thing is a PITA to get out
So do hooman
Got the standoff out, thanks IFixIt. Never have used the top row. Legit only use the J1 bit, cause that's the standard size for everything electronic apparently lol
So you were just whinging for no real reason?
hihi
Sorry, that was a cough - Might have looked like laughter
Nah, it's boring.
Dunno, i'm just being argumentitive for no reason
And I've not printed anything in days ๐
Phone case, phone holder, roof
Welp, hardware store I go, because this standoff from my dad's new rig is not the right height, and the screw is too short to screw into this server standoff

good luck. I hope the bears don't get you
At this point, I hope they do 
@stoic surge please do not send me unsolicited DMs
It would be helpful if someone could answer my queries . I did not get any response previously .
@clear jackal
cmon man. We are all just people here, volounteering our own time.
I would refrain from doing so , it's just that I needed some guidance as a beginner on how to approach certain things . Hope all's cool
I am not at your beck and call. If you have career questions, #cyber-and-careers is the appropriate place to ask.
Can you be at my beck an call? In case I have a moose-based emergency?
They are rare, but they happen
Sure . You could have put it in a better way tho
Sorry for disturbing
@stoic surge Have you read the server rules?
Yes, I will swim at 30mph across the ocean
them spindly legs have a lot of power, it seems
Do you need some moose for your hair? ๐
Just saw your post in #cyber-and-careers , your question might need to be a bit more specific than "How should I go about things"
Here are some roadmaps that could help https://www.sans.org/cyber-security-skills-roadmap/ and https://pauljerimy.com/security-certification-roadmap/
As for TryHackMe, you can start with the fundamentals (Complete beginner or/and Pre Security paths) then go onto JR pentester and Red teaming paths
Explore this interactive cyber security career roadmap to find the right courses for your immediate cyber security skill development and for your long-term career goals.
@mossy river I happened to make a mistake and I do apologise. It's a rookie error .
Just asking if you have read the rules as you did press the โI agreeโ button when you joined the server ๐
If you havenโt, I would recommend reading them :)
I posted my queries but somehow they didn't get through for a couple of days . In the heat of the moment , I went ahead for personal feedback .
I have but I might have overlooked some details . Will make sure to do so
hello ๐
Do , I go ahead and post my queries on the #cyber-and-careers ?
Gonzo has given you some solid advice above
Thanks a lot . I appreciate your response ๐ .
Gave +1 Rep to @hollow pivot (current: #51 - 129)
No problemo, feel free to DM if you have questions, I am not a pentester or anything close, but I can try help ๐
Waits for new tryhackme room exitedly
Guys, It is possible To do Evil Twin Attack with ESP32? Or it is possible with ESP8266 only?
I have an ISP32 with a 2.4GHz wifi chip, I'd suppose that could work.
Never tried it tho.
Thabks for this
Keep this to the advanced channels please
Ever played with an NRF52840? they're neat, they can do bluetooth and wifi 2.4ghz
I've got one programmed for BLE sniffing, it's quite cool, works with wireshark as an external capture interface using a python script
Okay
What's up James
Big fan, and they're cheap
@lament tendon @finite basalt You seen the esp32 based satellite ground station project?
Receive data from spaaaaaaaaaaace
Nope, only the flipper and itโs dev board. ๐
Damn, thatโs actually insane.
Hello
Bots a opp
Before I got rudly muted by the bot. I was going to send the offical discord for NZXT. They have there own discord if you want to ask them technical questions
Is the bot really an object oriented program?
yay comments!
Not cool comments
Is this a room youโre making?
What ya making
Unless there's a reflected XSS
shouldn't be
I see.
Just noticed you've tried it
Iโm doing this HTB room right now, and it literally crashes itself after a while for reasons I understand but donโt want to type out on mobile.
that would have been stored
Doubtful this is intended, it is really annoying.
Donโt make something like this.
Please make sure to ask before sending discord links to external servers ๐
Oh yea
Will do
even then, automod doesn't like it
Go to the hardware store to pick up an m2 5mm screw for my m.2.
Go there guy was like "m2 is 2mm, not 5mm." Thank you, I know. 5mm is the damn length
hey guys
watt the
are you paying for the subscriptions or using own Virtual Machines?
A lot more flexibility
did you just.. reply to yourself?
did you paid for tryhackme? Iยดm just starting and want to make sure
the subcription opens up a bunch more rooms aswell
lol
Agreed
do I need rooms?
as a beginner
Rooms are what we call each of the challenges and tutorials on the site. about 80% of them are free, so you don't NEED a subscription, but it does add more than a faster attackbox ๐
Always a good feeling when you're the first person to drop something in VirusTotal.
hello, i want to start openvpn with wsl ubuntu but the vpn dont want to work...
Wsl is pants for networking.
You might run in to issues with that constantly.
okayy thanks and what is the solutions ?
Personally, I'd just suggest using a VM.
@hot cairn this server is LOUD AS FUCK
So loud I can't hear myself think nor hear my other server 
Because you're shouting
Finnaly. Fucker slowed down in RPM. I can hear myself
Fml... that 32GB of ram I put in, yah no good
Back down to 16
Let me Ferox it. 
yesss but in the long term the vm become slow
you must be doing something wrong then.
New room, 25 min(s)
Eh WSL2 is fine
Yeh! Not the one in turb features on or off, but the one from the store
So you say.
But every other day I see people having issues with it ๐คท
Link?
Literally this server...
Yeah, link to the messages lol
Stop being lazy.
You search ๐ค
Quick question.
Got a ThinkServer RS160, just has 1 256GB M.2 gen 3X4.
This server is just going to be a firewall. Which is better, UFS or ZFS?
You're the one making the claim lol
How about you both provide proof
One for and one against, weโre all intellectuals we can have a spirited debate
We are?
we are, jury is still out on you.. 
I meant me, Jayy, Scrubz 
I hate you all

That's not "every other day", also if you look at the full context Ben said "may be weird", that doesn't mean it's "pants for networking"
WSL 2 was notorious for networking problems when it was first released.
As for now, I donโt know, but we generally do not recommend it for TryHackMe.
AHHHHHHH
Booting up. It sounded like my Dell PowerEdge 2950. Then slowed down to actually desktop air-cooled quiet noise. Quite lower than my Quanta 1U server.
It legit sounded like an airport
I mean, I get it works for you ok.
I wouldn't suggest it to anyone.
Well that's better, I can agree with that
But here's the question. Was that WSL through Windows Feautures, or Microsoft Store?
But giving it a blanket statement of "pants for networking" is doing it injustice imo
Thatโs a server for ya
Server go BRRRRRRRRRR.
I could hear it throughout my house F
hullo
hiiii
my server is still in hibernation
im moving soon to a 1 bedroom im curious if ill have space anywhere to set it up
Hang it from the ceiling.
What server?
So the bed's for the server?
yeah ill sleep in the bathtub
scrubz ur a genius
honestly i cant remember
i havent used it since i moved in april last year
It's been in hibernation for that long? Dang
keep server in the bathtub instead, water cooling
say how much do you think i could sell a 48 port 2960 with PoE?
How loud is your server?
not terrible tbh
My Quanta I don't know the model, their naming is very weird, but this ThinkSever RS160 is quite nice
If you don't mind being in the same room, see if you can get a half-height rack to store it in, or make an ikea rack.
i have a coffee table from ikea that fits it perfectly
@hot cairn I did a big whoopsy. I installed PFSense rather than OPNSense 
might be a centre piece in the living room
Itโll work lol
Did it have up-to-date enough drivers for your NICs?
I got a 42u rack in my 1bdr
Itโs fun
Well, if I don't like PFSense, I'll just burn it to the ground and install OPNSense
I would be amazed if you can't find an export/import utility for rules between the two.
ya it might be a bedroom special
Which software?
in unrelated news, thank god for wget
lets go wget
you get it wget
so far the only way ive been able to get anything downloaded of this 26gb file
curl requires extra flags to make it resumable.
yeah i tried witth curl with those flags and it still broke
Wget is simple
Bee, try aria2
Might be useful here
wus that
Thanks, I'll have a look ๐
Gave +1 Rep to @sonic dust (current: #1999 - 1)
aria2 is a lightweight multi-protocol & multi-source command-line
download utility. It supports HTTP/HTTPS, FTP, SFTP,
BitTorrent and Metalink. โฆ
Download utility
pretty nifty
if this breaks, ill give it a try
good thing its open src
hmm its got burp support
yes it does
whats really nice is the nmap upload. everything you scan is auto uploaded via xml
services hostnames ports etc
nice
I have a pentest report to write soon ๐
lol you are welcome @sick lance
I already had this. lol
I got it from an old mod.
0-0
I am an intern. I need help with this.
I have a csv file with 4000 ip addr and need to do whois enum and add the info in other column respectively. How can I do that?
jfc 4k?
Is this for your work/school?
Company I am intern
don't you study digital forensics?
We don't help with that sort of stuff. ๐
I do both.
I'd advise talking to your senior @real void
ohhh
Better than asking a random discord server full of strangers
spittin fax
Yeah, I always see a commercial solution recommended, but haven't looked for any community solutions.
Red team room this week.
Hmm, although a question I forgot to ask but I heard about.
Are forensics reports required to be super simple but still include all the complex stuff. (Exact example I was given, Somebodys grandmother should be able to understand it)
Ask your supervisor, that will probably be the easiest solution. ^_^
Whoever is reading the report, should be able to repeat the process so they can get the same result and conclusion.
As it the resuts need to be identical, it has to be factually correct so it won't get dismissed as evidence in court.
Dunno, I probably need to create rules. Gotta read up on OPNSense
i wish they would bring back the AD network:'(
test
I just wanted to know if there is some website or method to do this quick. So I wouldn't look stupid to ask my supervisor.
but what about the simplicity element?
Dunno, 2017 server, so probably
the test tested
Depends on the writer and template.
I've seen that were simple, I've seen some that was like alphabet soup
I just know that was an issue that LTT ran into when they moved buildings with one of their 25Gbps NICs, they had to dop PFSense and switch to OPNSense because PFSense prioritizes stability to a detrimental level.
ello
hmm.
Tons of ways to accomplish this.
Not really a hacker topic specifically, more of a data analyst topic.
But you could use a combination of simple tools like awk and sed.
You could use Python with the csv library imported
You could use PowerShell with the "Import-Csv" cmdlet.
The beauty of computers is there's never one way, and rarely one "right" way to skin a frame buffer.
python
But whois required connecting to server won't it reject request of that huge amount so I have to take that into account as well?
you can set python to only do a whois every couple seconds or somethin
That will depend on the whois solution you use, if you want to use a public one like domaintools I believe you can purchase api access to allow for large number of searches.
Yeah I understand, there are few website I know thanks I'll talk with something in my hand now.
Gave +1 Rep to @split compass (current: #54 - 123)
what u downloading tho
No worries.
Take a small subset of your data, maybe 10 lines, to make a sample set
w/ linux head -10 file.csv > sample_set.csv
Play around with your idea of how you want to make your requests, as Jayy said, invite your seniors to see and direct what you're working on.
Once you have your sample set working, if you're relying on something with a commercial API, advise your manager that you need them to purchase you API access.
Best of luck.
john coltrane, kind of blue by miles davis, tigran hamasyan
Ahhhhh
will give it a listen in 1.5 hours
Never had issues with WSL rev shells, just things mucking with iptables
also question why would someone want to view hex in Burp SUite
have fun
there are valid reasons, i just cant articulate them right now..
Yah, I run 1g, not 25 lol
hex can show some detailed things or so
such as
My 10g ports on my Quanta is connected straight to the machines
Characters not rendered in ascii
like some weird looking chars, like not human readable things
oh k, but how might that be useful? any examples
well any char have his own hex value
so if you do not know how to get something in clear text or so you can check hex value and get to be more clear
its own hex value :)
language barried... mea culpa ๐
i know, thats why i corrected! no harm
My brain not braining
yea ik... but thanks ๐
Gave +1 Rep to @wind lake (current: #58 - 115)
brain harder or osmething
did you try turn it off and on
echo -e \033[95m some characters are just weird and do nothing. \033[0m
Some characters are invisible, but will change whether an value/field matches the expected input format.
if select UserName0x01 from user_table == UserName0x01.value
Not to mention any kind of simple control characters that might be used.
Trying to take a picture at the gym after doing a heavy workout ๐ญ theyโre all blurry
My brain be thinking about this one thing
shaky jabba
strong jabba
What camera?
brains do that sometimes
That's cause your muscles tired after workout
Yeeeeeee, it's cool thoughts though
iPhone 14 Pro Max
Yeah, hard to find much better digital stabilization.
Try just propping it up somewhere and shouting "Hey Siri take a photo"
@buoyant tree
might help
Cyber chef is great. ๐
id does his job greatly
I should try running one on local hardware and see if it is more performant than the GCHQ shared instance.
it very well might be
why the festival tickets gotta be so expensive...
you've sent this to me a lot lately
i save it for very special occasions ๐
openai sora looks insane
Anxiety inducing
Does anyone know if there's any issues with doing LSB image steganography on formats besides PNGs? I can't find anything online that says so, but in class we were told only to work with PNGs for some reason
edit: nvm there's a research paper on it by bharat sinha
Oo, what are you using ur pi for?
i still have mine just sitting in a drawer somewhere, it's a model 1 tho so not very powerful xd
or 1b, i dont remember
I'm planning to code a network management tool
Just playing around right now
Ah I see, that sounds fun, good luck!
Thanks
besides the non-readable characters, imo there might also be some cases where there's a proprietary communication protocol where you might have to manually interpret the bytes
things like when they have the first 2 bytes represent an ID, the next few bytes represent something else, etc.
though I've only seen it in games and through socket communication (to lower latency, idk if ppl do it with http requests too but i'd assume there's things like c2s which do smth similar but for obfuscation, though I may be wrong)
When all you have is 6 inch ethernet cables to configure your FW on your laptop with
Splice them all together
Data rate will plummet but who cares?
Not me! As long as I can get to the WebUI, I don't care if the cable is even 5 mbps
Doesnt help that I'm getting old, bending down to configure this with no seat
I really do hate myself 
If not existing C2s, then certainly the one you write? ^_~
๐
actually wanted to make a really basic one for fun last year but didn't end up doing it
wanted to try a new language when working on it tho, was thinking of going with rust
would be a nice github project
hmm
might be a advanced implementation
Islam be upon you, my brothers
I have an important question, what do you mean by port?
Is the port the protocol or the computer port??
so not a brother but it may help for you to google. Port and protocol are not the same. The port is a number. The protocol is how you communicate on a port
like protocol http often runs on port 80
it it could run on any other port, sometimes you see it on port 8080, 8081 but if a port is available, it can be used
Do they have a device?
what do you mean?
Not...exactly
A port is more of an identifier used by a service so it can tell what network comms are aimed at it
The port has special devices
There may have once been a hardware analogue, long ago
ahh no, like hydra said, its part of a client/server architecture
so a server will allocate a port for a service, then a client connects to that part but its not a special device
You can also use port to describe a device interface, for example serial port, or usb port
But that's a hardware concept
oh true
Which is why the question is incomplete
Wait do Yk how in movies they always show the hackers pcs terminal as green? How do they do that
green font?
Legacy monitors used green phosphors
It stuck
I know the computer ports, such as RJ45
yeah you are talking physical ports then'
Ooh
Very cool tech tbh
https://hackertyper.net/ you too can be a hacker
The original HackerTyper. Turning all your hacker dreams into pseudo reality since 2011.
not sure if is correct representation. but hex is alike hash. if i explain it good
Cute
yea understood it a lil
type color 0a if ur on windows
and if char is unreadable like on first pic. you can find his hash value on table
ye
isn't that tree
Hello guys quick silly question, i haven't done any thm in a long time but for RCE with a file upload bypass, i need to bypass the filter then navigate to where my code was uploaded to get it to execute on the server right?
https://www.commfront.com/pages/ascii-chart for example
ASCII Table - Standard and Extended ASCII Chart, ASCII Codes ASCII stands for American Standard Code for Information Interchange. It ranges from 0 to 255 in Decimal or 00 to FF in Hexadecimal. ASCII codes can be divided into two sets - Standard ASCII codes and Extended ASCII codes. Standard ASCII codes range from 0 to
I was being a silly man and just thought uploading the file would get it to execute >_<
time to learn another language, Hex
hi do i need to create a new account with my student email to get the student discount? it doesnt let me change my email...
is not quite language... is just table representation or so
Simply setting my student email without verifying gave me the discount last time iirc - though, I'm not sure if you can reach this step with whatever issue you're facing - also don't know if they made it so you have to verify it now or not
Sounds about right
hex is a just a different numbering system, shouldn't take long to pick it up
https://learn.sparkfun.com/tutorials/hexadecimal/all
We do love base 16
It's a representation of numbers that happens to match binary with less space
and hex help into uderstand how cpu understand/translate. if i explain it ok
cos is 2 char
There is base32, usually used for OTP keys these days
But 2 hex digits represents one byte
@buoyant tree so when you find weird chat is like this
And that's handy
i find base 1 to be the easiest to remember
Base 2 is better
i just created another account with my student email and it worked thanks mate
Gave +1 Rep to @night prairie (current: #99 - 63)
so when you wish to program something that have that kind of weird char you can use from hex to ascii or smth like that if you cant tipe that kind of ascii on keyboard
And useing the alt-codes ๐
and that shit also hehe ๐
Yeah but use utf-8 instead
i had a few useful ones i'd use but can't remember them anymore :c
On mobile, no alt
yea... but what if you need input some Asina chars or something that looks alike the buttons on calculator that you never use ๐
Trash
It's not AI imo
Number 1 ai hater here yโall
LLMs sure
Its the current 'Big thing' so worth learning some security aspect of it
say orange
OpenAI's Sora looks insane, I'd like to get into AI at some point, seems like AI's going to be used in every sector in the near future imo
Pineapple
Apple
Pen
Mango
The fruit is a lie
Wonder what happened to bro
Just got back from dinner with an old Uni friend. Not see her in ages, and it was lovely. Went to 'blues bar and Grill'
yea trying to **kinda **remember that
Nice i try later
according to the interwebs, apparently he's still around, but i've never actually seen him again
Sure sheโs a friend ๐
Haha we did have a thing after Uni, but she lives too far away for anything to happen.
I see
AI is smart
Seems he's mainly a TV entertainer and comedian in Japan, would explain why we don't see him in the west
"make me an AI model that codes whatever I promt it in C"
well.. technically already a thing, needs improvement though
When I first met her during Uni, I went to hers so we would walk to the Union bar together (As we lived near each other then). When I got there she was playing FFVIII fight a tricky enemy, and had a page of notes - what movees she used, and what the enemy did. It was sooo geeky! We were best mates after that ๐
she's a fed
path recommended after finishing complete beginner?
hi i probably do have kind of stupid question but when using pentest tools like gobuster or nmap or some of these bruteforce/scanning tools do they like use your IP to check? so for example say if you used gobuster on google and it scanned 9k hidden pages google would see that your ip is the one sending the requests?
๐
eh AI atm is insanely expensive
if you ask me, try the Jr Pen Tester path or whatever it's called
D1 hater
nice ty
Gave +1 Rep to @molten sky (current: #93 - 67)
Like SUPER EXPENSIVE
They won't be, don't worry
yes
heck Sam Altman asked 7 trillion dollars from the world for GPU's
@shell nova
At least AI won't replace humans in any creative fields
i see
Yes, and don't scan machines you do not have permission to scan
im aware now
Yeah but they can't create. Not truly
Of course but what is that really gonna take over. Definitely the graphics industry
Tho itโs not perfect
You hear about game studios wanting to use AI art. That's because they're cheap greedy bastards, but AI art is wildly inconsistant
Those ai image creations have a hard time creating hands for some reason
so when using scanners like that its basically like im ddosing cause im sending too many requests or ddos is way more potent?
Ai wonโt take over the cyber industry anytime soon. If thatโs whatโs your worried about
More like a DOS
But yeah, you can unintentionally break things
Too many errors ai makes
i think you can't ddos/dos with simple scanning. scan might be detected but not as ddos/dos...
Might make compilers better though
I recall reading somewhere that things like nmap scans would sometimes end up taking industrial systems offline lmao
i see well i did dumb thing and i scanned website with 2K requests before i stopped it (it was supposed to check for 10k so thankfully not) do you think like the server providers are gonna notice?
i did happened
Some industrial systems are running off an old pentium that somehow runs windows XP under a machine
Probably, but that stuff happens all the time on the net
i cant remember the name for industrial hardware, the one i had in mind at least
its not neccessarily illegal no
Ugh, whatever scraps they can spare at the time
It technically is
smh
I mean I'm testing copilot, it's...alright, but definitely need to reread what it spits out
using nmap might not be illegal, but might not be ok to do so. and it can get you in trouble for sure
Why wouldn't it be illegal?
yeah i used gobuster
Your ISP can also have a problem with it
i see
wish i used copilot more in beta
In short, don't do that again
im aware now
i did it on my school website
that was hella dumb

oh... not sure where exactlyu to put that in scale of not legal/illegal but it can be problem if some big industry caught it
State website ๐
Yup
smh i thought like scraping around isnt illegal
Big industry will definitely catch it. Might deem it mostly harmless though
like its publicly available information
you would be surprised some of the hardware and software that very important systems run
Technically itโs not if you have to use software to find it
I really do hate firewall rules.. I'm able to ping from my laptop which is after my firewall, to my internals. but I can't ping from my internals to my laptop
it is. not smart to do
No I wouldn't ๐
well not you...
i mean it doesnt change anything
i could still do that manually
That's not scraping, that's a brute force attack
like it'll something like "our billion dollar program relies on this PC from 1980s..." and you are like "What?"
damn
I still have to deal with obsoleting windows XP vms
@fast wave as i say:not sure how stupid that is, but aint smart
yeah
I've dealt with older than XP and yeah we have XP too
And there's that mainframe somewhere
Reminds me of the time we went on site and they had a win 95 running a label maker or something.... obv not connected to the network
I had a program buying scrap parts from ebay because they didn't want to update the software and all current hardware isn't compatible...
so they basically have someone who has alerts for ebay set up
Every Cyber Security course should have a section that gives you insight on how to collaborate with administration/c-levels because my lord.
Itโs the infinity certs
Yup
If we could use AI to predict the stock market, it would already have been done
Would an LLM alone be able to do smth like this or would you need to specifically train a model on trying to guess the market?
Probably both, but the market as a whole is more or less unpredictable
Udacity has a course on AI and financial analysis... its been out there for almost 10 years
Stock market is more an indication of human behaviour rather than any logical or rational behaviour
there is good reason why SCADA system is used to control systems. if AI can predict things will be used as in stock market. on my work, our SCADA cost small 1mil (and more) euro to control things. and it's doing great job
what you'd really need to predict is how companies are fairing vs the stock market itself
do something dumb like turning the firewall off
or whitelist what u wanna do
and tbh, SCADA saved us on few occasion from complete environmental catastrophe...
might nob be legal... humans can't do that speed
Well FW isn't even fully configured yet. I'm able to ping from my laptop (behind the firewall) to my internal network. So laptop is on 1.0 network, internals, for this example, are on 2.0 network.
But my 2.0 network can't ping to the 1.0 network
I am not a network person, so learning this as I go
there are some companies that are using AI trading today
i work in chemical industry. things we develop can be done only if gov allow us. and some things in clear form are scary dangerous if goes out. imagine 99% ammonia got out. around 2000 liters leak will be catastrophe
but basically they are using best practices vs trying to catch the dips/rises
HFT is already dodgy
WealthFront, Schwab, Vanguard, etc all have AI advisors who will auto invest money for you
it will be illegal or so even for one moment. i think.
again... not sure how stupid that is, but aint smart
same reason why game cheating is illegal and can be punished
AI trading isn't illegal
fully develop AI that can predict stock market ?
its doing the best it can, most stock platforms out there have AI trading already
I'm not talking about crypto
same... i didn't think in of crypto
Stocks
I'm talking about stocks
I was close to working for a trading company๐
Building their infrastructure
Eh, not exactly what I wanted to do
If I look at it now
ahhhh this is the word i was looking for earilier, scada
Even though it's green stock, it's a no thanks for me
Nice
not all my money mind you but some
Yeah, of course, I have done some trading myself
Not much
they can't learn from them self. they have knowledge of what ppl provide them
They cause each other major problems and usually just end up riffing garbage at each other
Garbage in, garbage out
Would you recommend others try it too?
when AI reach point of creating better wersion of him self... we are sfucked
this is my robo (aka AI) advisor. I no longer contribute money to the account but it does pretty good
Good thing we aren't there
yea
Evening ๐
I too can shitpost poorly
yea... and they sux on it hehe
Aye, and I can too, so we're safe
Nah, cause at the end of the day, you still have people
if AI use our shitposting as learning data... we are safe for long ๐
There are other major issues with how our current AIs are producing various results and outcomes
Aside from the plagiarism?
Wasn't there some Twitter AI account that went unhinged, because well, it was learning from Twitter
think it was made by microsoft
Tay
Ah that's the one
on the topic of shit-posting and stocks:
https://youtu.be/USKD3vPD6ZA?si=O45LT2IKGcD0tP7g
Go to http://Public.com/reeves and youโll receive a free stock worth up to $300 once you open an account.
*This is not investment advice. Offer valid for U.S. residents 18+ and subject to account approval. See Public.com/disclosures/
I am not a qualified licensed investment advisor. Nothing in this video constitutes professional and/or financi...
Is it commercial software or your own?
Well that's a major issue that needs to be tackled with the companies appropriating everyone's creative outputs but there are problems with models and their behaviour, reliability, trustworthiness; we don't know what they're doing and they do very strange and unexpected things sometimes
Probably turned out better than half of other traders
It did
Actually
I saw the video when he released it
Saw an entertaining story this morning about someone winning a lawsuit against Air Canada because their chatbot hallucinated a procedure
I'm going insane with OPNSense 
That makes no sense
Need only look at the Warren Buffet vs. Day Trader story to know how that turns out and why,
"In an argument that appeared to flabbergast a small claims adjudicator in British Columbia, the airline attempted to distance itself from its own chatbot's bad advice by claiming the online tool was "a separate legal entity that is responsible for its own actions."
๐คจ
Stock markets are mostly random
That's a really fun defence
Yep that's the tip of the iceberg. They have no concept of reality or verification for their outputs so there's nothing in them that makes sense. They're just really bad at giving accurate or precise info
Yep, and any knowledge of variables that can be used to improve outcomes cannot legally be used.
They're really just trying to predict the next word that makes sense in english
Unless it's already public data
Is the file inclusion room hard or am I just a noob?
At which point everyone has acted on it, and no edge was given.
Probably just a noob
Knew it
Or the info is non obvious
Hello guys who did the new challenge Broken RSA
Anybody used burp's sequencer in a real life application here?
Keep at it, you'll get it
Breaking RSA
Can't wait till Tuesday ngl
Not the free version
Yeah pretty much, or at least we think that's what we programmed them to do. People are going to keep being fooled by these things until they're regulated properly
People in #1208126025612009492 might have, but no hints for now
Hmm, a question like sequencer needs to make a lotta requests so do they like whitelist your IP or you have to make ways to bypass the rate limits
Fair, like the story from that social media movie; trading oil futures based on weather patterning.
You'll need to Math your way in that one
don't worry... we are all noobs most of time ๐
The paid version has no limits
But it's really just a fancy version of hydra
Are you referring to this? https://medium.com/@cereantuandrei/views-of-warren-buffett-on-day-trading-views-of-warren-buffett-on-day-trading-c72aa35fbd00
One of the richest men in the world and a well-known investor, Warren Buffett is highly regarded for his investment advice.
I thought you were the fancy version of Hydra?
Idk honestly. I spent 2 hours in that room and didn't finish the last challenge...
It's an investment company's offering
It's a tricky one
check writeups... is not against the rules
Esqy can I DM you about something cool happening on Tuesday?
Not going to read right now, but if the TLDR is he and a day trader bet the S&P500's rate of growth vs. the Day Trader's ability to manufacture growth, and the S&P500 won, then yes.
I wanna do it on my own tho. That way I feel like I'm learning something
Of Course, Bella - you don't need to ask ๐
Figure out what server is running, then adapt your payload
I don't believe that hydra does analysis on token strenght
fair...
Don't want to break rules ๐
Thank you
Gave +1 Rep to @shell nova (current: #12 - 545)
Although I think Burp Suite has the sequencer in the free version
It's heavy limited
Thats cool, Bella, My DMs are open you and the other regulars anytime ๐
I have a question
yea its slow but eh its good enough for learning
share it with group...
Or am I confusing with Intruder
that might be the issue here
Ask away
wait no wtf
what is router
actually yes
Broken access control
the box that gives you internet
Did you try googling?
IDOR's for me usually
Falls under broken access control
I know what I mean, so what is its purpose in the network?
yea, although idk why but IDOR's are fun fo rme
It's not number 1 on the OWASP top 10 for nothing
to route trafic... kinda
Did you try googling?
also this
Haven't seen a SQLi on a BB or VDP yet
To bring the network together??
I tried, but I couldn't
SQLi should be getting rarer as frameworks are getting better at handling it
yea
but now I see more reports of RCE's than SQLi's in the wild
rce is usually chained with something else, usually an injection
Not necessarily SQL, command injection is still poorly handled
RCE is the holy grail for a hacker though
An RCE will be almost guaranteed critical
Good evening hackers
yea
Thank you very much, I will search
Gave +1 Rep to @night prairie (current: #99 - 64)
unless they were smart and made a service account for it with limited privileges
Still can be used as a jump server
yea but would limit exposure
Not necesaarily
Would complicate the exploit chain sure
if it's a web server, then the IP would probably be whitelisted on their database server so you could poke around there too ig
Or internal networks, possibly bypass a firewall
i rememebr few years ago, i was using my friends database server for one of my projects, we had no IP whitelist and at some point he was testing smth and disabled authentication too
few days later i see my shit aint working, i started investigating and check the database only to find a single record with a ransom note ๐
Oops
in my defence i was like 14-15 and knew nothing about security
Eh, at that age I didn't know what a database was so...
All your database were belong to someone else?
Then again the internet was just beginning, JavaScript wasn't really a thing either
at that age i didn't know how fly don't fall from sealing =/
I got into programming early, probably when i was like 8, but stopped programming like 2 years ago (besides a few small things, or uni stuff)
some wizard shit
Yup
weird indeed
Ah
cartoon teach me that gravity don't work until you look down... then you start falling down ๐
now am curious
Of course. And if you program in python, you just need to import antigravity. Solves that challenge
time to google
oh its a glue
tru tru
Was being hosted by my friend yes, was some small hobby project
couldnt afford a server ๐
It was an aged internet reference ๐
or rather, i wasnt old enough for a bank account so couldnt pay for it
eh remember time when I made a minecraft server
and made it have TERRIBLE SECURITY
for complete convivence
Oh ๐
All of the warning's I got, ok, ok.
this sounds funny, i'd like to hear more
Depends on your region, position and experience
Password was 123
A decent wage is one where you can afford a nice house in a nice neighbourhood, have a wonderful spouse, enjoyable pastimes and holidays, send your kids to college and treat yourself regularly, without the worry of debt or medical issues cramping your lifestyle
and enabled a few other settings that I don't remember
It's my usual lobby password in games, so far no one has accidently joined it
looks at my pay and the 57 hours a week I work just to survive living by myself
hmm
Whatever your boss is on
depend's on your country
I know, it sucks
If you take your current salary and subtract financial obligations, are you in plus/minus/zero?
Yeah that was about 40 years ago
Yup, student pay is not fun
Mmm pizza rolls
Things'll get better
hello, i'm new and i want to make basic ctf with my friend, the problem is that idk how to invite him in my room
Use the jr link
Yeah, just need to land this thing I talked about and then December 2025 I graduate
Then depending on degree of financial obligations, you might be earning a decent wage or not so decent
That's gonna be one hell of a celebration ๐
Why don't yall like pizza rolls, just looked them up they look delicious
Yuuuup, gonna be sooo cool, can't wait till the meeting on Tuesday
can someone help me pls
Hydra just did..
Speaking of pizza rolls makes me hungry and I don't have any more calories left 
๐ You'll have to let me know how it goes
Will do!
Since people are getting their certificates on my profile, how should I approach to get mine as well ๐ค
In the room link, replace room with jr
๐ญ
oh ok i will try thx
So December = Land thing, Graduate, Xmas and AoC. Damn bella!
No one would guess the password for my Kali laptop
Oh? What is it?
kalikali
hunter2
Default passwords are bad so I changed it
toor
In my VM's I just keep it default
i did it but it's doesn't work
root
Yeah I got it default on my VM too, but I take that laptop into uni so I changed it just incase, but don't care enough to put a proper password
Easier to not get logged out of VM's when I keep breaking them
Well land thing = probably this or next month
Change it to this
NeverGonnaGiveYouUp
honestly probably 5 other people on the entire campus even know what the default is, so i wouldn't even care
Well, I doubt anyone would guess it
(in this case)
I'm doing a hacking course ๐ญ
okay that's fair
If there is nothing of value there, why not ๐คทโโ๏ธ
'If ever you think something is obfusacted enough, some finnish kid in his bedroom will find it' - Thats an internation rule of computers
hi good night guys
does someone know how can i do basic pentesting with a friends ๐ญ
actually one of my passwords
guess for what
Minecraft? ๐
For my macos VM, I set the password to whatever the title of the VMware window was, idk why
Was annoying to enter every time lmao
kekw
You can join THM. There's plenty of rooms to try. #start-here
we wanted to do rootme, in easy mod but we don't know how to join us
Any success so far?
more than enough
at my 4th windows VM to break
others couldn't recover
now I know what not do change or delete
or just edit
@glass nest here is one more to make you fix you laser
https://www.youtube.com/watch?v=-FnCWjKV8ps
LP4 engraving slate.
TimeLapse from 24 min to 1 min.
- Dieter effect
- 2k res
- 100% power
- 12% depth
- 1x pass
Oh you want to do it together?
Uhh not sure if you can connect to the same target machine - not easily at least
You will each get your own copy of the machine to attack
and stay on a call
Dann you, Ralex
but can we do it in the same room
more soon ๐
You should be able to share the ip
we wanted to connect two VM on the same room. Is that possible?
Can you connect to the same VPN profile concurrently?
Don't need to
Oh
just target same ip
If you had the mindset of a hacker, you wouldn't be asking.. you'd just be trying it ๐
If you start a machine and I know the IP I can connect to it
I thought the machines were tied to your account's VPN profile
Now I know to censor the IP in screenshots ๐
Hehe
Too lazy :x
I had already done it to help someone troubleshoot
Aye, I've done it a few times... that comment was towards the person who was asking ๐
esqy... last one for today...
https://www.youtube.com/watch?v=FDVmWtpZUnE
LP4 engraving card with IR (1064) 2w laser.
TimeLapse from 12 min to 1 min.
- Dieter effect
- 2k res
- 100% power
- 8% depth
- 1x pass
Is that a cat with a bat?
yep
ask
in cyber area or ?
We can't really help with homework, unfortunately
Depending on some profs, it may be considered cheating
We don't want to take the risk
No worries, go see your prof if you have issues
nothing stopping you from emailing your tutor if you need clarity
i dont have a tutor and my engineering classes take a considerable amount of time and and run over his very limited office hours
What are these green things you speak of?
Hydra, I think its the food that your food eats
Best not eat them then
A Dragon Fruit does look kinda alien
Yeah that one was 7 iirc
nice weekend
I liked Thundercats ๐
I hate myself for getting into the world of Firewall Rules and OPNSense. Yaaaaay going insane time 
and save button is important
t minus 2 days
oh god oh god what is going to happen? can i sleep till 1200 on monday?
pay day for shadow and shadow finally being able to finalize their dragonbox pyra order
so unlees you shadow you should be able to sleep comfy
unless you also want a dragonbox pyra but the preorder queue is long to say the least
oh pay day nice but i guess i have to get up early again sighs
i am getting used to feel stupid had to google that XD
anyways back to watching avatar the last airbender shadow goes
can i ask someone a quick question
Hey, new here. Was wondering if TryHackMe offers regional prices ๐ค
1

:ke
thx
Gave +1 Rep to @pine stratus (current: #1999 - 1)

the tryhackme suby is not expensive
idk where u live, here 10 dollars is a good amount of money ๐คทโโ๏ธ
Any time
hm might be right there...
buy year sub

no no its true there are places where 10 is a lot sadly
I'm doing the pre security course
yes try it a bit first
from 0 to hero , perseverance is the key
Do that
Do some free stuff and see how you like it
