#general

1 messages · Page 30 of 1

opaque zodiac
#

All ports with -p- tho

half girder
#

jep, and sT does just a connect scan which will be quicker

opaque zodiac
#

Mm, good point

#

I think I'll need to redo the nmap room tbh

#

Well, that got me the answer (It was between 1-9 to be fair) but I think I'll be redoing the nmap room before I go forwards

toxic glen
#

I need to take that attitude 🤣

winged summit
#

Good evening (or morning, etc). How is everyone?

opaque zodiac
#

Doing well

#

Getting back into THM stuff, yourself?

winged summit
#

Eh, just lamenting the background check for a job lol. Wondering if I’m gonna be one in a million or just fail as expected haha

opaque zodiac
#

Fingers crossed!

winged summit
#

Thanks

#

What THM stuff you getting back into?

opaque zodiac
#

Eh, just starting things. Networkservices room at the moment

#

Onto red-team stuff later, but going back to basics until it's more concrete in my head

winged summit
#

Yeah always gotta make sure your basics are solid

opaque zodiac
#

100%

rapid merlin
#

Hey

winged summit
#

Hi

rapid merlin
#

How can I make money? So I could save it for my cybersecurity certifications.

winged summit
rapid merlin
#

bug bounty

winged summit
rapid merlin
#

Yeah, but i couldn't find anything reliable. Tell me if you know any online jobs i can do

winged summit
rapid merlin
#

I don't think I have any professional skills to represent on LinkedIn

winged summit
#

Thanks

twin ridgeBOT
#

Gave +1 Rep to @round jay (current: #1999 - 1)

winged summit
#

Thank you

#

Haha rich is relative lol

graceful thistle
#

🤨

#

thats terrible advice

winged summit
#

Doing things I wasn’t supposed to do a long time ago before cybersecurity was gamified. Granted, I shouldn’t have done those things. However, I learned most of my current skills recently

naive violet
#

Please don't say these sorts of things. We don't take kindly to trolls here

graceful thistle
#

please dont say such things

#

oh

naive violet
#

Morning dolphin

graceful thistle
#

good morning

winged summit
#

I make $28/hour. So not sure if that makes me rich. However, I’ve worked minimum wage jobs most my life

graceful thistle
#

hey you two are new here, I'd ask you to please take a minute and read our #rules

#

this server is PG13

#

strictly

#

I think both of you may need to chill a litle

molten sky
#

🍿

naive violet
#

Why do you think?

#

This isn't tiktok

#

Please leave this to the mods.

molten sky
#

anyways sup james/dolphin/other james

winged summit
molten sky
winged summit
molten sky
#

not even writing any go, i just want it to work 😶

naive violet
#

@hollow matrix everything alright?

winged summit
molten sky
#

my god i just noticed the meows

naive violet
#

@hollow matrix Please don't spam here. If you continue, you will be muted

molten sky
# winged summit What are you working on?

owasp split amass into pieces in their new version...... now instead of running amass in a docker container i have to run amass enum in a container and install each of the oam_tools on the host separetely, which requires go 1.21+, and only 1.20 is available on the repository, and when installing manually the gopath gets screwy, and nothing is consistent

#

bouta just use a deprecated version of dockerized amass and be done with it

naive violet
#

I never got amass to work

winged summit
molten sky
#

i've never had any issues with amass until they decided to break it into 17 different tools

molten sky
winged summit
#

Wait, doesn’t go require a manual install anyway?

molten sky
#

dnf/apt/yum/whatever install golang

winged summit
#

Hmm. Try going to the go website. I think it’s pretty easy to install without package management

#

It’s actually the preferred way last I checked

molten sky
#

yup it installs fine, but when installed manually none of the pathing is set up properly by default for some reason and even after setting it up things just aren't where they should be

#

repo is preferred here cause it can actually get security updates as needed (w/out intervention), but i don't mind binaries or source when necessary

winged summit
#

Ah, I see. Sounds like some configuration is required then

#

For the paths etc

naive violet
#

Installing go from the repos is almost guaranteed to get you an outdated version

molten sky
#

which is NORMALLY fine

#

it's normally fine being one behind or so

#

but nope it uses something brand new

naive violet
#

Ubuntu etc always seems to ship ancient versions and I've had tooling not work because of it

#

ahem Nuclei

molten sky
#

yeah ubuntu is horrid in that area

#

but hey, it's stable

#

wonder how easy it would be to intertwine rolling and stable repos to pick and choose for each package

naive violet
#

Run a stable core set and rolling addons?

molten sky
#

si

naive violet
#

I guess libc etc is the hard bit

molten sky
#

w/out ppas or equiv

winged summit
#

@molten sky does it install to /usr/local/go?

naive violet
#

But you could also just go for something like flatpacks with a fully immutable OS

molten sky
molten sky
naive violet
#

It's what the steam deck does

molten sky
#

been curious about silverblue/spins

#

ostree and all

winged summit
#

Silverblue? What’s that?

molten sky
#

tldr; immutable fedora

winged summit
#

Hmm interesting

#

I’m currently running Debian as my host and love it

#

Simple af and just works with tons of supported packages

molten sky
#

I had weird issues with it as a desktop

#

not sure why

winged summit
#

Hmm, interesting

molten sky
#

using fedora now tho so 🤷‍♂️

winged summit
#

Haha nice

#

Fedora is solid

#

I got exposure to Fedora with QubesOS

#

My vault VM ran it

molten sky
#

fedora kde has been the most pleasant OOTB experience i've had for a workstation in years

#

(with dedi gfx)

#

it just worked

#

no artifacting, stuttering, no weirdness whatsoever

winged summit
#

Yeah, I didn’t have any issues when I ran it either

#

Like I said, it’s a solid distro

molten sky
#

the only issues i've encountered since rebuilding have been discord being a POS (normal though) and HexChat crashing because it doesn't support wayland

junior wraith
#

hola

molten sky
#

aloh

winged summit
#

Probably due to the fact it’s upstream from red hat. Although the corporate changes may affect things. I haven’t been following it

molten sky
#

coming from manjaro it's night and day

winged summit
molten sky
#

from a distro that can't even update their damn certs on time to here

molten sky
#

oddly enough, HexChat is preinstalled on the cinammon spin of fedora. not on the kde one though

winged summit
#

I see. I’m trying to remember the name of the server that replaced freenode. That was the last I visited ha

#

##security lol

#

Yeah buddy

#

And ##privacy

#

Libera

#

That was it

molten sky
#

Libera still exists i think

#

not on it tho

winged summit
#

Oh and OFTC

#

No worries I don’t expect you to drop your hangouts in chat haha

molten sky
#

all of the ones i'm on rn i probably can't name drop in #general lol

#

if i was in the super secret special hackerman channel then probably

#

but i lazy

#

been 0xwhatever for like a year

winged summit
#

Haha no worries man I understand

molten sky
#

nothin too notable tho. the more interesting stuff is on forums elsewhere, where I probably wouldn't want to use naked irc

winged summit
#

Haha yep. IRC - the original reason to use a VPN to hide your IP address from creeps hahaha

#

Totally get it

#

Anyway, I’m off to bed man. I gotta get some sleep. Have a good one dude

molten sky
#

huh. i've got a gluetun container running. i wonder if i can redirect hexchat to use that.

#

probably a waste of time tho

naive violet
#

@forest root Why?

#

What?

#

What?

#

Why did you post an email address here?

grim sparrowBOT
#

:hammer: hileci31.#0 has been banned.

molten sky
#

well then

rapid merlin
#

Any certs for digital forensics?

grim sparrowBOT
#

:hammer: glock19ext#0 has been banned.

glossy portal
#

You can bot discord accounts

grim sparrowBOT
#

:hammer: postagent#0 has been banned.

glossy portal
#

Interesting

naive violet
#

Discord actively detect it and ban accounts

glossy portal
#

I'm aware, but it should be harder on discord compared to other platforms

molten sky
spare ridge
#

Three bans in a row, damn

naive violet
#

Low effort trolls

spare ridge
#

Deserved then

molten sky
#

@spare ridge what's up with the recluse thing in the bio

spare ridge
#

Basically time until vacation

#

Been a busy month NotLikeThis

molten sky
#

ooooooohhhh my goddd

#

i figured out a way to make it work

#

i forgot you can install other versions of go with go itself

molten sky
abstract oriole
#

hey guyz

#

does anyone knows how to use burp collabrator feature in zap

lilac kestrel
#

Good morning

past sparrow
night prairie
#

i need to learn how to use git properly at some point 😭

#

can someone help me rq, i accidentally fucked up my commit history

#

i changed a file name via windows then pushed it (didnt using git mv), but then i see in the remote repo that it created a new file with no commit history and the old file still remains

#

i tried git revert but there was a change made after that to the new file and now there's a conflict

molten sky
#

reset and rebase then force push

night prairie
#

uhh i kinda fixed it ish

#

so i reset, there was conflict cause of the latest commit, i discarded the changes by deleting the file and pushed

molten sky
#

that works

night prairie
#

now the old file still exists in the remote repo, but i dont have it locally

#

tried git pull but says it's up to date

molten sky
#

the commit tree is fine locally tho?

#

git log what you expect?

night prairie
#

just cloned it again lmao, least amount of work

molten sky
#

was gonna say

#

in the future, interactive rebasing is your friend ----

#

git rebase -i <bad hash that ended up in the middle>

#

then git push --force-with-lease (similar to --force but safer)

night prairie
twin ridgeBOT
#

Gave +1 Rep to @molten sky (current: #88 - 69)

night prairie
#

ffs

#

used git mv this time

#

and no commit history

#

im confused

#

shows that it was renamed

#

but in the commit history of the file it doesn't show anything from before the rename

#

normally it says it was renamed and theres a button to view older commits

#

fuck it, im recreating the repo and redoing each commit 💀 it's gonna show i started the coursework one day before the deadline though

solemn beacon
viscid hill
#

top 0.1% after about 7 months, never give up!

hardy spade
viscid hill
twin ridgeBOT
#

Gave +1 Rep to @hardy spade (current: #1999 - 1)

sick lance
worn summit
#

I'm new to the site, is there like a page with the correct answers for some tryhackme rooms, for when im stuck?

viscid hill
#

dont try look for answesrs, hints or a little bit of a push, persistence is a useful skill when hunting for bugs etc

viscid hill
glass nest
#

On challenge rooms, theres a tab at the top labelled 'Writeups', that should help. For tutorial rooms, if you can't answer the questions, it's worth re-reading the content.

viscid hill
glass nest
#

Aye. gotta use your own personal ethical compass too. Only read enough to get the hint

tame nymph
#

I’m dirty coin expert

glass nest
#

Cool. I have a genuine 'Piece of Eight' on my shelf 🙂

viscid hill
glass nest
#

Thats the key to learning. Just getting the answers to gain THM rank is just.. cheating yourself

naive violet
sick lance
#

Can't be an expert of my coins, they're all clean.

#

I put them in Coca-Cola every day.

glass nest
#

I'm either tired or naieve. I genuinly didn't think it might have been something 'untoward'

#

Maybe try Cillit bang. make a penny look good as new

tame nymph
naive violet
#

Again, wat?

glass nest
#

Ahh. Lazy sundays 🙂

tame nymph
viscid hill
#

how'd you get that?

glass nest
#

For folk who just churn through to get answers.. Yep 😄

shut hawk
glass nest
#

Tom - My Dad got it for me for good luck 🙂

viscid hill
#

damn looks nice, is that the original case or a re-used one

#

sorry not case, box**

sick lance
#

His dad was Long John Silver.

#

Long lost relative of Peg Leg Pete.

glass nest
#

Well, it was the box that it was sold in. I guess the seller put it in there to look nice. The holder and chain are cool aswell, It's engraved with the name of the ship it was recovered from

#

HMS Hollandia (IIRC - I'm too lazy to walk 1 step to the shelf)

chilly veldt
#

hmmm, I could go for some honey sesame chicken

#

for the rest of the month

viscid hill
#

damnnn it was recovered from a ship, better hold on to that

#

would be cool to myseriously give to your grandchildren

#

for no reason

glass nest
#

Ooh bella, that sounds nice.

viscid hill
glass nest
#

You haven't lived.

#

😄

chilly veldt
# glass nest Ooh bella, that sounds nice.

yeeeees, I have like 1.3kg of chicken breast in my freezer, accidentally froze it all in one bag, so I have to make something out of it, and after making the chicken I can freeze it again

glass nest
#

Eesh. hammer n chisel time 😄

chilly veldt
#

or just make delicious food out of it

tame nymph
#

Meow

grim sparrowBOT
#

Done!

glass nest
#

@naive violet

#

You are too damn quick!

#

you must go through a keyboard every month as a result of the keys melting

sick lance
glass nest
#

Ignore it 🙂

sick lance
#

And remove the URL from the pic.

Rather not somebody click it in here.

mossy river
#

@hollow stream please censor phishing URLs

ornate root
#

Hellloooooo

paper bough
#

Hiiii

sick lance
#

Hello!

ornate root
#

I wanna ask who got linux basics for hackers pdf🥹

indigo magnet
#

There is a new book coming in May 🙂

ornate root
#

Can you kindly help me with it🙏🏻?

sick lance
#

What do you need help with?

ornate root
indigo magnet
ornate root
naive violet
indigo magnet
ornate root
sick lance
#

This actually just reminded me to sort ouf my PDF folders.

tame nymph
#

/banspam

half girder
#

rather prefer a real book, tried tech books on kindle, doesnt really work out for me

ornate root
#

Add it google drive and add me I don’t care about piracy its for my personal use

tame nymph
sick lance
#

We care about piracy.

near hawk
#

I bought bunch of books on humble bundle only read one

tame nymph
#

For real.

sick lance
#

If you really want the book, pay for it.

tame nymph
sick lance
#

PDF is easier to search.

grim sparrowBOT
#

@ornate root has been warned.

grim sparrowBOT
tame nymph
#

Why pay when u can get it for free

#

😯

half girder
#

because someone spent a lot of time to serve the knowledge nicely arranged on a plate

grim sparrowBOT
#

:hammer: ssiimmppeell#0 has been banned.

ornate root
#

Lol

strong flower
#

hi m new

half girder
#

speaking of books, need one about vba, work forces me to dig into 🙄

ornate root
#

Thanks for your help

glass nest
#

Kanga - For VB surely you could just throw a stone

half girder
glass nest
#

Ahh, so the question was more to whittle it down 😄

half girder
#

err or vending whatever

crude stump
past sparrow
#

Wondering if anyone has any interaction for powershell and what could be good sources for more hands-on interactive learning for it (Something in terms of challenge / solution )

shut hawk
#

Underthewire

past sparrow
#

Thank you

woven urchin
#

i just cracked now and its say rubber-hose. Did u carcked correctly ??

woven urchin
#

yes

sick lance
#

Active?

woven urchin
#

its hiring challenge

shut hawk
#

We can't help then sorry

#

Errr the whole point of a hiring challenge is to test your skills

woven urchin
#

i already sloved

#

just want a confirmation from him

shut hawk
#

oh no! anyway

woven urchin
#

what is this

shut hawk
#

ISC fees

#

I don't have any certs though from it, so not much point in paying

woven urchin
#

is this phishing email ?

shut hawk
#

nah lol

#
woven urchin
#

oh ..

glass nest
#

so... you are expecting a knock on your door asking if you are John Conner?

vast zinc
#

aws showing no card detail and I can use the instance

#

so I can use without payment?

desert shuttle
#

Mor Ning

sick lance
#

Afternoon

silent sail
#

good night

chilly veldt
#

so uhm, my speakers in my monitor just broke, so now I can't hear anything from my desktop, yaaaay

proven quartz
#

That sucks! Can you replace them? Driver issue? Just the entropy of the universe?

chilly veldt
#

physical speaker issue

#

I ordered some external speakers instead

#

found some cheap one

proven quartz
#

Hopefully they'll hold you over a while at least

desert shuttle
#

It’s too cold

chilly veldt
#

yeah, the speaker in my monitor held for over 2 years of constant usage

proven quartz
#

The ones in my laptop stop working occasionally. Only solution I've found is to reboot into Windows so am assuming the manufacturer's software does some kind of verification or something...

chilly veldt
#

This one is for my desktop, my headset broke in 2022 and I haven't bought any yet, I just used my speakers in my monitor instead, which now broke

#

Lol

proven quartz
#

Yeah it sucks when stuff just dies. Like, you were working fine just a minute ago... what's changed?

chilly veldt
#

Scratchy scratch sounds, due to a Spotify song which was too loud

proven quartz
#

Well yeah I guess that helps but at least you can get a replacement

#

Some of the keys above the spacebar on my laptop stopped working one time so I've been using a usb kb from an old server the last few years

rapid merlin
#

Hey 👋

wraith fjord
#

Guys quick question...it might be a little bit meh and basic, but how do you know what directory listing to use when enumerating.. like i use "directory-list-2.3-big.txt" and in some of the room write ups, i've found people using different list like "common.txt" or "dirsearch.txt" and get the expected result.

Or at what point you are like "Hey, this is not working, let me try anathor directory listing" ?

split compass
boreal scarab
#

@jagged moon FLUFFFFF. Did you have fun on http of our site? 👀

chilly veldt
proven quartz
proven quartz
#

I'm impressed

chilly veldt
#

yuuuuup, quite nice

wraith fjord
twin ridgeBOT
#

Gave +1 Rep to @split compass (current: #53 - 124)

wraith fjord
sage flame
timid prism
#

@gray sonnet

#

:(

gray sonnet
#

True

boreal scarab
#

Whoever did this.... i hate you.

#

And you spelt "You're" wrong

#

No more sus for you! DNS no likey

valid mauve
boreal scarab
#

Or @jagged moon 👀

glass nest
#

It's the candian spelling

valid mauve
#

Took the time today to migrate my family away from locally saved passwords to my Vaultwarden instance.

No more "Aaaah, I forgot my 6char password which is based on my name!"

Makes a very happy Mac.

boreal scarab
#

Lemme guess, they still use the short passwords and not generate long ones? 👀

#

@gray sonnet "How do I disconnect? Fucking discord"

valid mauve
#

My little brother actually generates them! I'm impressed.

brittle lynx
#

Hello anyone know a good LFI automation tool

gray sonnet
boreal scarab
#

I love seeing the TOR networks accessing the site too. kekw

valid mauve
loud marlin
#

discodogo

sand trench
#

dogisco

hardy copper
#

Guys, what vps do you recommend that takes paypal/crypto? I dont need anything fancy, I just wanna test my api, learn how to setup https, try to hack it, bla bla bla, so that then I make sure my main server is secure

glass nest
#

not able to just use a card? even a prepaid one?

mossy river
#

Can’t you just host it locally?

#

You’ll still have to ask the VPS if it’s against their ToS

glass nest
#

Oh yeah, That too.

loud marlin
#

esqy. ever run to gridfiniti project 3d prints for tool storage and tings ?

glass nest
#

I considered it, but found it's cheaper and easier to just make the storage out of wood.

loud marlin
#

yea. i just making one to test. rly nice project for sure

whole yew
#

finger joints are way easer to cut with a jig on the table saw than waitiing 3 days orthe laser.....

boreal scarab
#

Or. Hear me out. Buy a server and everything you do on it. You're allowed to do, because it's your server.

glass nest
#

It's a great idea, The whole gridfinity thing is a good idea.

#

Also, I generally just butt-joint stuff - actual wood is kinda pricey, and finger joints on plywood are a PAIN

whole yew
#

yeah, that's fair

glass nest
#

that being said, I might give it a go for my next thing - Pirate treasure chests from reclaimed Palletwood

whole yew
#

tear out is a lot worse on ply

#

do you have a jointer?

worthy dirge
#

Hello guys

whole yew
#

because you'll want a jointer to build the sides and top of your pirate chest

glass nest
#

No, But I do have a router table and a dovetailer jig

whole yew
#

hmm

buoyant tree
#

Any ideas what it could mean

glass nest
#

Wait.. Jointer - Yes I do.

#

For some reason I was thinking of a Mortiser

whole yew
#

router to make the edges perfectly parallel is going to be a LOT of work to get right

glass nest
#

Hehe, I got confused cos you jumped from joints to edges 😄

whole yew
#

kek

#

yeah, you answered the joinery question, so it was time for a new topic

glass nest
#

I got a cool planer/jointer thing. Good for a lot of stuff, but I bust out the actual planer for the harder woods

#

Picked up some Cherry, Sapele and Purpleheart planks last week. Dunno what to make from them yet though

whole yew
#

so you have one of those electric hand planars? i'm looking at one of those, but i'll probably split the cost of a thickness planar with my dad before i do

naive violet
whole yew
#

get ready to change the blades in everything the purpleheart touches

glass nest
#

Yeah, but rarely use it. The planer is one of those Triton ones borrowed from my buddy who's in Canada for 2 years

#

already replaced the blades on it, cos he last used it on SUPER dense seasoned oak he salvaged from work

whole yew
#

purple heart is going to tear those blades up waymore than that oak did

#

it's way more dense

#

it's almost as dense as ironwood

#

or ebony

glass nest
#

He works at a dockyard that service submarines and ships, so they use these giant oak blocks for support. Basically seasoned to the gills and spend a tonne of time in a nautical setting. Planking them up with a chainsaw and jig was FUN

#

Yah, but purple looks SO NICE

buoyant tree
#

Just thinking to monitor logs for anything suspicious

naive violet
#

This is normal for anything exposed to the internet.

glass nest
#

I made an Ebony pen t'other day. First 2 I tried chipped right at the end. Dense and brittle.

naive violet
#

You should always be monitoring for anything suspicious. Get centralised logging

whole yew
#

if you are doing any crossrips of the purpleheart, expect to change blades at least 3x as often

glass nest
#

Yah. Measure THRICE and cut once on this stuff

buoyant tree
naive violet
#

That's not what I said though is it?

glass nest
#

the trick with it is to douse it in Isopropyl Alcohol before finishing, and leave it in the sun. That gets the purple a-poppin

cosmic pendant
#

Hello

glass nest
#

but UK being UK... right now the last purple pen is a boring brown 😄

whole yew
#

Can confirm: notifications turned on is not the same as a centralized logging system

buoyant tree
naive violet
#

Syslog

#

Syslog is the industry standard

buoyant tree
#

oh you mean logging the server's actions

cosmic pendant
#

May I recommend, OCSF

whole yew
buoyant tree
naive violet
#

That's website logs, server logs, all of it.

buoyant tree
#

may have to do the room on logging again

glass nest
#

Nah, the alcohol works well. Evaoprates super quick. I use it between sanding grades

#

Probably works better on tiny pens rather than anything bigger

chilly veldt
#

Logs! HYPERS

buoyant tree
devout palm
glass nest
#

Although I think UV light is the key. I have a few scraps of Purple, I'll try the oils and see what happens

chilly veldt
#

I love logs

naive violet
chilly veldt
#

I should go grab dinner

glass nest
#

Yes bella! honey sesame chicken!

buoyant tree
devout palm
#

Sorry for hopping in grossly... So what are you all up to today?

chilly veldt
#

that's not today, I have 1 portion of chicken alfredo left

glass nest
#

So what're you thinking? Chargrilled with mushroom?

buoyant tree
#

tho will try and implement syslog for the wordpress and self-hosted ones

agile flicker
#

I need some free rooms

#

where can I find em?

glass nest
#

Excellent.

#

on THM!

agile flicker
#

I'm there LOL

#

I'm just confused

glass nest
#

Shadow has made a suggested free path - I think it's pinned..

agile flicker
#

where do I check...

glass nest
#

Yup - second post on the pins of this chatroom

naive violet
#

If you go on to search, you can sort by free/subscriber

agile flicker
#

ohhh

#

found em

glass nest
#

Whats the percentage at, James? was 80% free last I checked

agile flicker
#

thanks 😃

#

thanks, Uncle and Ninja

naive violet
#

Not a clue

glass nest
#

but James, you know everything!

agile flicker
#

how do I use the attack box?

glass nest
#

Click 'Attackbox' at the top of the room

agile flicker
#

then?

glass nest
#

Click on one. It will open up in the side of your browser

agile flicker
#

ok

#

btw when I use it it is VERY laggy

#

why is that?

#

do I need to use the vpn with it?

glass nest
sage flame
#

you don't need vpn if you're using either of those boxes - they're already inside the network

agile flicker
#

what now?

glass nest
#

Well, it's web-based, so reliant on your internet connection

#

Work through the Tutorial room.

sage flame
#

i believe the resources those boxes are given are also based on you being subscribed or not

#

might be wrong doe

agile flicker
#

where do I find the tutorial area?

glass nest
#

For real, stepping through the whole process is long - the Tutorial room explains it a lot better than we can

boreal scarab
glass nest
#

There

boreal scarab
#

You get better attack boxes when you're subbed

sage flame
devout palm
sick lance
#

Free users get 512mb and half a core.
subs get 1GB? and a full core.

agile flicker
#

ok the attack box is loading

#

im in tutorial room now

#

same

sick lance
#

Hello and welcome.

agile flicker
rapid merlin
#

hello

sick lance
#

So many new people today 😄

glass nest
#

Chill 🙂

agile flicker
#

okay I pasted the IP

#

now what?

rapid merlin
#

yes

glass nest
#

Follow the tutorial.

#

@naive violet

agile flicker
#

.

#

im so confused

#

with everything

grim sparrowBOT
#

:mute: cihadulah#0 has been muted.

glass nest
#

Just read through the tutorial room. It tells you the exact steps to take

agile flicker
#

what do I do now

rapid merlin
#

Hello

devout palm
agile flicker
#

bruh

loud marlin
#

vpn is only if using local VM/kali

agile flicker
#

im done with the tutorial and I only pasted smth in a web...

naive violet
#

That's the intro to the site

agile flicker
#

this is the whole tutorial?

naive violet
#

There's a lot more teaching content after that

glass nest
#

Aye. That was a 'how to use the site' room

agile flicker
#

ohhhh

#

now I found some rooms

night prairie
#

😬

#

i got curious after they didnt reply

#

so i checked it out

#

downloads a fake d.js package from npm which installs malware

#

the package had almost 100 downloads in the past week alone

#

they dm random ppl in the discord.js server and ask for help with their bot, saying it wont run

boreal scarab
night prairie
#

oh

#

they're not in the server

#

i should have specified that, my bad xd

#

was just sharing it cause i found it interesting xd

boreal scarab
#

If Scrubz wants to RE that malware, and share with the class his findings 👀

steady rapids
#

hey is someone also having issues with the vpn?

steady rapids
#

all of them

#

eu 1, 2, 3

sick lance
#

Sophie looks like the Terminator.

sick lance
boreal scarab
#

Haven't been on in awhile. But 3 is known to cause issues, in the past at least, that I'm aware of

sick lance
steady rapids
#

switzerland

sick lance
agile flicker
#

Im finally GETTING “going”

shut hawk
#

Yay, back home! In the airport there was an Windows XP display that had crashed kekw

shut hawk
boreal scarab
#

👀

buoyant tree
boreal scarab
# shut hawk

I know it's just running a display, but jfc... XP at an airport

shut hawk
#

Lol if it ain't broke don't fix it I guess (till now)

sick lance
shut hawk
#

Let's hope it's not networked then 😆

glass nest
#

Pff. Why would it be?

boreal scarab
#

Hehehehe

boreal scarab
glass nest
#

Nah, a departure screen is fine how it is.

shut hawk
#

It's a static display, so ideally shouldn't have to get updated information

sly saffron
#

I need help

glass nest
#

You're a static display, Jayy

sick lance
sly saffron
#

It’s with the web app security

#

Section

sand trench
#

t minus 4 hours and 35 mins

naive violet
glass nest
#

I think I need help. I need Marie Kondo to come over to my house to get rid of a bunch of junk

sick lance
glass nest
#

That would be on-brand for me. both the game and the typo

sick lance
#

In Football news.

You can take Kane out Spurs, but you can't take Spurs out Kane kekw

shut hawk
buoyant tree
#

Should I do TCM today or Portswigger

glass nest
#

Yes.

buoyant tree
#

not both

loud marlin
#

yes

night prairie
#

rip, was hoping i could check it out with any.run

#

i do the same haha

#

well, i have everything forwarded to a proton inbox

chilly veldt
#

USE THE DEFAULT SHAPE FOR SCREENSHOTS psyDuck

devout palm
#

Nice drawing

night prairie
#

Anyone got a paid any.run account where they don't mine running a sample for me?
File is too big for the free version

night prairie
#

Oh right

#

I'll ask again when I reach 0xD 😂

devout palm
#

):

#

I need to grind

sick lance
#

Get the hash of the file and chuck it in Virustotal

shut hawk
#
#

@night prairie

echo igloo
#

hello roomies

loud marlin
#

ello

echo igloo
#

hows it going?

loud marlin
#

so far so good

night prairie
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 476)

shut hawk
#

I much prefer it over any.run

night prairie
# sick lance IIRC they offer a free 14 day trial.

Oh, I wasn't aware of that. I think I'll try out triage for now and save the trial incase I need it in the future.
I did try putting the url into virustotal but I don't think it downloads the file from the URL, and I don't want to download it to hash

sick lance
night prairie
sick lance
night prairie
#

:c

#

I haven't completed a room in so long 😭

sick lance
#

Slacker.

#

IIRC yeah

#

DO and Github are two I see around here suggested.

shut hawk
#

Used DO for over 2 years, highly recommend

proven quartz
#

AWS gives you a free Windows and Linux instance for your first year

shut hawk
#

Very easy to setup

shut hawk
proven quartz
shut hawk
#

AWS is a whole skill

#

Like navigating a maze that an evil puzzle master setup

proven quartz
#

Set up another one

proven quartz
sick lance
#

Link your IG account.

#

They want to?

#

It shows on their profile.

buoyant tree
#

not twitter

sick lance
#

twitter re-directs to X

glass nest
#

It's gonna be a use case. So much of cybersec and infosec is based around careers and working. IG is more of an artistically creative thing

#

And peoples dinners.

buoyant tree
#

Eh I don't like meta

glass nest
#

It's the 'social' part of 'social media'

buoyant tree
shut hawk
#

why lol

buoyant tree
#

too much tracking

proven quartz
buoyant tree
#
  • I don't use those platforms a lot
sick lance
#

Not even their marketplace?

shut hawk
#

Fair enough

buoyant tree
shut hawk
#

Yeah FB marketplace is goated

buoyant tree
#

"Olx"

sick lance
#

That reminds me, I need to buy new running shoes.

buoyant tree
#

I gotta use whatsapp

sick lance
#

Don't need an FB account to use Messenger.

shut hawk
buoyant tree
#

tried to convert everyone to Signal, horrible fail

#

meta = facebook

#

X = twitter

#

same thing

sick lance
#

I don't think you do?

proven quartz
shut hawk
#

Meta is the company

#

Facebook is the product/service

buoyant tree
night prairie
sand trench
#

???

#

shadow has zero of those accounts

night prairie
#

is your threads account

buoyant tree
sand trench
night prairie
#

legit opened it once and never again

buoyant tree
sand trench
#

eeew apple products

glass nest
#

Eh. I can never get into those social medias. I used facebook a fair bit in the early days as I was travelling at the time, and facebooks was great to keep in touch with folk. but the other ones... eh. Like... posting on Twitter/X - Why would anyone wanna know what my thoughts are in 160 chars? IG - I don't take that many photos, unless they are wires that I need to remember how they are set up. I still have Facebook for messenger on my phone, cos my friends use it. Linkedin - I'm not actively looking for a job

naive violet
buoyant tree
#

like with SMS/MMS

sand trench
#

using sms yeah

buoyant tree
#

okay

buoyant tree
night prairie
glass nest
#

Whatsapp is giant in europe. met so many people who use it as their go-to

sick lance
#

My family use Facebook, however I'm talking to them less and less, I could delete it it and they won't notice.

I use IG for my Hyrox and ORC racing.

sick lance
buoyant tree
#

What's that

sick lance
night prairie
crude stump
#

I got a game y’all should play. Hell diver 2, it’s so fun I really recommend it

crude stump
#

Yk what I mean

buoyant tree
#

Break it accidently probably

glass nest
#

I know East Asia - for various reasons - use Wechat. For pretty much everything - Calling, texting, paying

buoyant tree
#

I think normal operating system's dont work on it

#

So no windows/linux

night prairie
#

I may be wrong, but can't you already rent them in the cloud?

sick lance
#

I don't use Cyber-sec at all on IG.

night prairie
night prairie
glass nest
#

I look at it sometimes for Woodworking, for inspiration. But Youtube works for that. Usually If i have time to do that, I'm sat at a computer.

night prairie
#

Hmm, I'd probably try to use it for some sort of AI model (no clue how AI works, so perhaps it's not applicable in this case)

#

You?

#

Jarvis 👀

#

i wonder how long it will be before someone tries to make jarvis

#

well, before someone makes a good jarvis*

#

gotta watch age of ultron again, that shit scared me when i was younger 😂

#

wish we had more iron man movies

#

ig we still get the techy stuff in spiderman now at least

buoyant tree
#

with the hologram also

#

yup

naive violet
#

Bad protections get bypassed.
Defence in depth is valuable, and some vulnerabilities can be properly mitigated

#

For example XSS, you can use safe sinks and CSP etc

#

For SQL injection, you use prepared statements

spice adder
#

when do site ranks get synced with discord? ive gained quite a few today and see im still level 3 here 😂

sick lance
#

But it's once a day usually, although I think it's rate limited.

spice adder
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 1974)

naive violet
#

In the end, security issues usually boil down to bad code or bad design

#

It should be

#

But it very much isn't

#

It's a solved problem

shell nova
#

PHP feels like the only thing I know that still allows it easily

spice adder
#

quite a large supply chain attack due to SE and SQLi here in the UK last year

naive violet
#

But developers suck

naive violet
spice adder
#

Was a big one, but primarily due to the social engineering aspect of the attack. Companies infrastructure tend to be a lot more lenient the further you get in

proven quartz
shell nova
naive violet
#

PHP is PHP, Python makes it easy-ish, Java made it pretty easy but I guess that depends what libraries

shell nova
#

Hibernate makes it bloody annoying to allow injection

tough relic
#

Hi all

honest crown
#

hey bois

sick lance
#

Hey GIrls.

naive violet
sick lance
#

Superstar DJ's...

Here we go!

honest crown
#

i need ur help, I am not able to connect thm via openvpn in windows (I tried all servers)

sick lance
#

I can help there.

grizzled crystal
#

For anyone using a vertical monitor, do you have any preferences? I'm thinking I get a 24" one, but I'm unsure what's most comfy

shell nova
grizzled crystal
#

never had one before, i'm splurging haha

sick lance
grizzled crystal
#

yeah, is 22" not too narrow?

sick lance
#

It's great for Discord and Word.

#

Not at all.

grizzled crystal
#

oh great

naive violet
grizzled crystal
#

yeah it'll be nice for referencing docs and whatnot

naive violet
#

Boo that's no fun

night prairie
shell nova
naive violet
#

It's nice

grizzled crystal
#

that's what i'm thinking, one 24" IPS

naive violet
#

Need to rotate one at home but I don't want to buy a stand

grizzled crystal
#

there's no name for it?

naive violet
#

The same as it would be outside an API? I don't get what you're asking

grizzled crystal
#

I normally just say "I've found a vulnerability in this API"

twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #1 - 2100)

night prairie
#

If someone wanted to go down the path of VR and expdev, which resources would you guys recommend?

I know of pwn.college but is it enough to get started on real bounties?

sick lance
naive violet
#

What's the word you're trying to find an equivalent to?

naive violet
sick lance
#

Oh wait, I seem to remember something about your set up...

naive violet
#

I mean my new ones are just tilt stands

grizzled crystal
#

you essentially get a couple of college courses completely free

naive violet
#

No there's not a different word for it

grizzled crystal
#

Nope, I mean it depends on what the vulnerability is

naive violet
#

Tfw "bola"

grizzled crystal
#

I once spoke to a guy who tried to convince me BOLA was when API and IDOR was when not-API

naive violet
#

I like the idea behind calling it bola, it sounds more accurate, but.... IDOR was already accepted

grizzled crystal
#

I had to actually pull out google in front of him he refused to believe that they're the same thing

#

yeah it's confusing for sure

#

IDOR is what i'm used to, but i feel like BOLA is also pretty easy to get used to

#

and it feels more accurate

#

As easy-to-use terms though BOPLA BFLA and BOLA is just evil. Too many acronyms!!

glass nest
#

Tryhackme? That sounds like an interesting site..

night prairie
#

I did get invited to this VR server for UK nationals a while ago, it has both students and professionals, but unfortunately it's not very active

#

I think it was created by one of the exp dev companies here

rapid merlin
#

do thm

#

htb is hard for beginners

night prairie
#

Imo, THM is better for beginners, though I heard the HTB Academy isn't bad either

rapid merlin
#

have fun hacking

twin ridgeBOT
#

Gave +1 Rep to @noble veldt (current: #998 - 3)

spice adder
#

productive pain NotLikeThis

grizzled crystal
#

Pwn.college is great for binary exploitation fundamentals specifically. For general fundamentals definitely look at THM & HackTheBox

#

No worries

sand trench
#

t minus 2 hours

proven quartz
#

Keep it up!

sly saffron
#

TryHackMe isn’t fully free is it

twin ridgeBOT
#

Gave +1 Rep to @proven quartz (current: #21 - 351)

sly saffron
#

glass nest
#

Nope. It's mostly free though. the number I go with is 80%

sand trench
#

main ones would be networks and paths

sly saffron
#

I can’t continue the intro to cybersecurity

glass nest
#

you can skip the premium parts.

spice adder
#

mine was to graduate, im a semester away and think im looking good for it :) ended up with my dissertation going in for becoming intellectual property for commercial use. which is unexpected, and nice xD

sly saffron
proven quartz
#

Do it when you can. Set a time and try to commit to it. Eventually it will be 'the thing' you need to do

glass nest
#

just click on learn, and open the learning path again.

sly saffron
#

Will try again

dense cedar
#

I have a question . Is there access to systems and knowledge of programming languages ​​explored? ; A question that confused me

sand trench
#

??? does not parse question.... error error ????

rapid merlin
#

Guys

#

Anyone tried the hacker arise course? Its 3 years long and its from the guy on David bombal podcast thats fighting in the cyberwar in ukraine

#

Im thinking of taking that after cpts, that guy sounds like he means serious business

dense cedar
#

Why, brother, does he not have an answer?

rapid merlin
#

Its 1500 dollars for 3 years

dense cedar
rapid merlin
#

This Is why i was asking if anyone tried it, If hes like on David bombal yt channel he def knows his stuff

#

I mean hes fighting a war with that

#

He probably can teach you the skills that a senior pentester need lol

dense cedar
#

He has a YouTube channel

rapid merlin
#

I mean

#

Its not linked from David bombal videos

dense cedar
shut hawk
#

The website gives me very script kiddie vibes

#

And it's $1000 which is a pretty hefty price tbh

near hawk
#

They’re revamping the website

desert shuttle
#

I wish it was warm all the time

dense cedar
#

Brother, are you kidding? He has his own channel for fun

near hawk
rapid merlin
dense cedar
outer hound
#

That occupytheweb guy types so slow.. I think he's a course and books seller at first place

rapid merlin
near hawk
#

Yea he create a linux basics for hackers

shut hawk
rapid merlin
#

I know

dense cedar
#

There are a lot of free podcasts

rapid merlin
#

This Is not hacker arise

dense cedar
#

why

rapid merlin
#

Because hacker arise Is a guest

#

David Is david

#

Hacker arise Is guest hes not david

#

There are two people here

#

One Is david

#

The other Is occupytheweb aka hackerarise

dense cedar
#

You mean by me, the channel, not me, David

rapid merlin
dense cedar
#

hhh am sory

reef dust
#

Does the "START MACHINE" feature and OpenVPN feature have unlimited uses? Or does it have a limit like the AttackBox?

dense cedar
#

im*

#

I speak Arabic

sand trench
#

the limit that you might hit with the start machine buttons is the max 5 running target machines

#

the others is unlikely

reef dust
#

Alright. Thank you.

sand trench
#

could be

#

never hit the limit so dunno

sick lance
#

It's 3.

#

Maximum of 6 hours too.

#

But they can be re-deployed infinite times

buoyant tree
#

anybody did the math how much it costs thm for a hour of running the attackbox

molten sky
#

$73

dense cedar
near hawk
sick lance
#

Not sure how much THM are paying for the services tbh

dense cedar
dense cedar
rapid merlin
#

Seems like his course Is pretty sus

dense cedar
twin ridgeBOT
#

Gave +1 Rep to @near hawk (current: #88 - 70)

boreal scarab
#

@blazing granite what's the name of the wine maker?

#

Cause it's hard to find any bottles with that whitaker name

molten sky
#

@boreal scarab get fid

boreal scarab
sick lance
boreal scarab
molten sky
sick lance
boreal scarab
molten sky
sick lance
#

Claims to enjoy OSINT, but can't use it to solve a basic wine maker question 😹

boreal scarab
urban acorn
#

Amazing

molten sky
molten sky
#

0118 999 881 999 119 725 … 3

boreal scarab
#

Mine actually spells out something lol

sick lance
blazing granite
sick lance
#

You mean it was written on the label looool

molten sky
#

oh t9

#

just saw numbers on my other screen

#

well you're welcome

sick lance
boreal scarab
sick lance
molten sky
#

@mossy river

boreal scarab
#

@whole yew

blazing granite
#

@boreal scarab the grape it's called Grillo, but you can find it as Riddu and Rossese bianco too, the grape is used in the Marsala wine

molten sky
blazing granite
#

@boreal scarab where did you find it? it's not a typical wine that you find everywhere

boreal scarab
grim sparrowBOT
#

Done!

sick lance
molten sky
boreal scarab
boreal scarab
sick lance
#

And point still stands, English speaking server.

sick lance
boreal scarab
blazing granite
boreal scarab
boreal scarab
sharp citrusBOT
sand trench
dense cedar
mossy river
#

-undelete -a

grim sparrowBOT
#

Done!

grim sparrowBOT
next totem
#

how many rooms are there on tryhackme guys ?

near hawk
#

A lot, around 800+?

next totem
#

damn

#

that's a lot to do haha

glass nest
#

You best get started!

blazing granite
#

Esqy how are you

next totem
blazing granite
next totem
glass nest
#

Hiya Rex 🙂

sick lance
rapid merlin
#

Anyone here try passbolt pw mgr?

next totem
rapid merlin
#

Definitely, restrictions on free accounts boss

sick lance
next totem
#

oh okay

urban acorn
dense cedar
next totem
#

is it possible to create my own rooms ? I mean how does the validation process work ?

glass nest
#

Yep. you create the room, and submit it. Then one of the good-looking, hard-working Room testers will go through it and wither approve it, or offer feedback on whats needed for you to re-submit.

solar thunder
#

hi!

#

wow green mushroom

glass nest
#

I think you said that last time, ATP 😄

solar thunder
#

can be

sand trench
#

WOOOOHOOO dragonbox pyra ordered

solar thunder
#

?

sand trench
#

super amazing mini computer running debian arm linux

buoyant tree
sand trench
#

it sure sounds cool and amazing....

buoyant tree
sand trench
#

to think it has been 8 years already

buoyant tree
#

HUGE 32GB

sand trench
proven quartz
sand trench
#

sdxc cards goes up into terabytes if shadow recalls correctly

sand trench
#

though the pyra runs more general generic linux meaning better app support too

#

according to some other pyra users shadows favourite music player cmus works