#general

1 messages · Page 31 of 1

proven quartz
#

Nice one. It's always fun having a small computer around to do cool things with

sand trench
buoyant tree
#

u listen music from the cli/

sand trench
proven quartz
buoyant tree
sand trench
#

the pyra will definitely be able to do some fun and cool things

sand trench
#

also no

#

shadow prefers to own their music in drm free formats

#

meaning flacs or mp3:s

#

yes that means it takes up a lot of storage space

#

but also means playback wherever and when ever

#

without internet

buoyant tree
#

Although I use plexamp

sand trench
#

shadow mostly uses bandcamp when buying music

#

their selection of formats to download in is nice

buoyant tree
#

nice

rapid merlin
#

Is shoutcast dead now? lol

buoyant tree
#

what's that

sand trench
#

some media streaming software

buoyant tree
#

Also shadow it seems that spotify TUI allowed according to spotify tos

#

cuz it uses api

next totem
#

thank youuu

twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 390)

sand trench
#

ah okay then

#

still don't have the data cap to stream from spotify

#

will stick to music files

#

cheaper in the long run

buoyant tree
#

ye

rapid merlin
#

@sharp citrus

sand trench
#

why ping botto???

#

botto not answer

cosmic pendant
#

lol

steady rapids
#

Hey whos pretty confident in blue teaming and could help me out? i think my network has been actually hacked...

sand trench
#

IoC:s???

buoyant tree
#

I would recommend you redact the IP's

#

before sharing logs

steady rapids
#

this was all the "hacker"

#

nobody i know of

sand trench
#

you know what... dunno what the president is for following the rules when it comes to this kinda stuff... hopefully @shell nova can pipe in

sand trench
buoyant python
#

I need some help with a CTF for college, is anyone available for some help please?

buoyant tree
#

uhm @shell nova may want to take a look into this

mossy river
#

Why are you scanning stuff you don’t own?

sand trench
#

oooh jabba works as substitute hydra for this

steady rapids
#

nvm i was just looking for help

sand trench
#

reporting the ip to authoritis and the isp/vps service provider would work

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 1633)

buoyant tree
#

doesn't make sense

#

its localhost

sand trench
#

hope this is a joke as that is not something you do

proven quartz
#

That's not the address exposed to the internet. That would be the external address of your router 😄

#

Depends how your network is set up. The 192.168 address space is not routable on the open internet

flint sluice
#

Apple innovation is wild.

proven quartz
#

Haha just a bunch of stuff that allows you to do experimental things and work stuff in the safety of your own network

sand trench
#

ip blocking is not the best way to go about blocking threats....

mossy river
sand trench
#

ala see the pyramid of pain

proven quartz
buoyant tree
#

also has anybody here ever reported a CVE?, may have found one

proven quartz
#

That's normal practice for any routing device on the net

sand trench
proven quartz
pallid lotus
#

Ta for the reminder lmao.
Recently took my perimeter firewall out of double NAT but forgot to block internal ranges on WAN. Knew I was forgetting something kekw

steady rapids
# mossy river Are you going to answer my question?

I wasn't planing on doing something illegal. Somebody invaded my privacy so i looked further into it. This guy had a bunch of malware hosted and thats how far i got with my knowhow. I still don't know if any of my devices are infected but i dont think its wrong to ask for help if needed even if nobody can help me.

mossy river
#

But weren’t planning on doing anything illegal

steady rapids
mossy river
#

Doesn’t justify your actions

steady rapids
mossy river
#

Admitting to it in the discord server, and involving members of the community in your crime? Yes. Yes I do care

sand trench
#

welp time for shadow to just go sleep

buoyant tree
steady rapids
mossy river
#

This conversation is over, if you have any problems, please report it via the steps in the rules

sour geyser
#

oof

near hawk
#

I really should get some sleep but instead i'm eating skittles

split compass
#

Looks like I missed something spicy.
Why can I not have an Ozymandias (ala Watchmen) wall of monitors and be able to track them all?

buoyant tree
wind dust
#

skittles are tasty, but they are not as good as starbursts

split compass
#

I used to get skittles and starburst out of a refrigerated candy machine, they were awesome.

near hawk
#

Yea, but they had no tropical ones 😦

buoyant tree
#

aren't skittles just mixed ones

split compass
#

There's at least 4 different packages denoting 4 different flavour combinations I can think of.

near hawk
#

Yea, OG, sour, wild berries and tropical

split compass
#

And then you get that layer of flesh that sloughs off of your tongue.

molten sky
#

send --help

#

sounds like bs to me

#

sour good

split compass
#

Then I always end up asking myself, if I eat this, is it canibalism?

molten sky
#

@rapid merlin just reminded me to order more sriracha

split compass
#

Oooh, anyone booked to go to Defcon this year?
Heard there was a big venue change.

molten sky
#

venetian canceled on them out of the blue

#

forget where they moved to

#

sry, ceasars canceled

#

looks like they were able to beek the convention center instead

#

lol they're selling a shirt now that says UNCANCELED

split compass
#

Las Vegas Convention Center

near hawk
#

I wanna go Defcon but in America

split compass
#

Apparently the whole conference fits under one roof in one wing

molten sky
#

not a fan of having my shit dug through my some random hotel clerk without them saying anything to you

split compass
#

@near hawk I haven't been to one yet myself, been to one HOPE and that's it so far.

Been wanting to go to Cons since like 2005.
Missed out on Toorcamp.
CCC's events always look cool.

#

I probably could've managed to go this year, but I've designated a bunch of my vacation time to a visit with my parental units in March to go skiing in the rockies.

#

Are you trying to hack me! I heard about thiese "Vishing" scams on Fox!

#

It literally can't hurt to try, but just don't be surprised.

#

Honestly, I've been amazed at which accounts I have not lost access to over the years.

#

My Steam account, for instance, is from WAY back when your e-mail was your user name...
But my e-mail was from a private e-mail service that no longer exists, I ignored the accoutn for like 12 years, and was able to get it back somehow.

#

But they weren't a marketplace at all back then.
They were just a match-making server/co-lo host and Anti-Cheat system.

#

Even harder to verify.

#

No transaction histories.

#

Yeah, Steam is a lot more today than it used to be.

Marketplace
Store
Community Centre
Game library
Distribution Network
Anti-Cheat Vendor...

crude stump
#

Guys I'm doing task 8 of soc 1 cisco talos and in one of the scenarios it wants me to open up a email and put the hash of the attachment with the email in cisco talos. so i finished it but i was curious what the attachment actually was so i put the SHA256 hash in app.any.run to see if anyone posted it there and they did, but whats different is app.any.run says its non malicious but the cisco Talos scan says it is malicious. so what is it?(or is it just meant to get flagged on cisco talos}

stuck otter
#

Do you recoken it is worth sending an expression of interest for a job while i am studying. Since i dont have the cert for it yet.

#

I think it makes sense to at least be on their database.

molten sky
#

notable contributions to open source as well

sage wolf
#

and

#

LINUX

strong flicker
molten sky
#

classic

grizzled light
#

Can I pay someone to hack my grandma? She is a real B

near hawk
#

Well I am finally gonna go asleep after 2 hours of saying I will

grizzled light
#

$50 bounty on my grandma

#

shell never see this coming

wintry patio
buoyant tree
#

eh @mossy river if ur here may want to see dis

compact iris
#

Hello guys, I have a question about the streaks on Tryhackme
I recently lost both of the weekly streaks while almost getting the badge which is weird since I do them every day. May the algorithm work as like 24h from the last activity?
Also, how to the IceBreakers work...? 🙂

stuck otter
#

The day steam turns evil will be a sad day in pc gaming history.

buoyant tree
#

ikr

crude stump
#

Poor granny

crude stump
crude stump
buoyant tree
#

Heya @sinful moon guess which movie I just finished

buoyant tree
molten sky
#

idk i kinda want a snack

buoyant tree
molten sky
#

ngl that sounds like a good option

buoyant tree
#

I need ur advise to

#

tho

#

Top gun maverick or Arrival

molten sky
#

i actually haven't seen arrival

#

not much of a movie person

#

mav was okay 🤷‍♂️

distant gazelle
buoyant tree
#

@boreal scarab u ever broke vlc?

boreal scarab
buoyant tree
#

i managed to break it somehow

slim galleon
#

Hi all! I am new 🙂 I see access to King of the Hill competitions, yet nothing else? Would be super appreciative of any tips to start me off! I have some pentesting experience (though still certainly consider myself a beginner!) and am new to this site. Thank you!

~Allie

boreal scarab
buoyant tree
#

with no experience

boreal scarab
trail sequoia
#

hy , i tried to much time bruteforce but didnt get the password can sameone have solutions Bruteforce the Administrator account's password!

trail sequoia
buoyant tree
buoyant tree
sudden copper
#

Sub Chat

#

It's been a while

trail sequoia
sudden copper
#

Positions tab sorry

#

i forgot to say please

trail sequoia
sudden copper
#

Use Hydra better

buoyant tree
trail sequoia
sudden copper
# trail sequoia ok sir

hydra -l admin -P rockyou.txt MACHINE_IP http-post-form “/admin/index.php:user=^USER^&pass=^PASS^:F=Username or password invalid” -V
Try something like this
Also read hydra quick to understand how it works

sudden copper
#

it says 1 payload position but i don't see it

molten sky
#

hacking is bad

#

stop it

buoyant tree
#

thats the correct password

sudden copper
buoyant tree
#

its another symbol

sudden copper
#

§§

#

it's a very weird symbol tbh

molten sky
#

eh

#

for section

sudden copper
#

but i can't pepehands

sudden copper
#

now it's accurate

glossy portal
#

Just don't do drugs

sudden copper
#

AYO

#

i was just thinking about it

molten sky
glossy portal
#

Hey, I bet you could solve a lot of his problems with a gym membership and a drug rehab program

sudden copper
#

imagine being world's top hacker but yet so lonely

sudden copper
molten sky
#

you can download anything but a social life

sudden copper
#

you need a hug for that

glossy portal
#

What if I told you, you can.

#

You need to work for it, like everything else

#

It's not going to be handed to you

#

Put in the work in therapy etc.

sudden copper
#

not always the case tho, he was doing larger stuff in his opinion that's why

glossy portal
#

that's also the case yeah

#

But generally unless you're a big vigilante criminal, there's a solution

sudden copper
#

the one he already stolen before lol

#

let's not talk about mr robot here it sounds very illegal lol

glossy portal
#

it's just a show, but I'll respect the rules if it doesn't allow that

molten sky
#

rules are just suggestions

#

sorta like that geneva thing

boreal scarab
#

Almost broke my TrueNAS... phew

molten sky
#

what'd you do

sonic knoll
#

how do i change my password on the website

#

i forgot it

molten sky
sonic knoll
#

thanks

boreal scarab
# molten sky what'd you do

One app decided to fail midway through, and I couldn't remove it, then another app was updating and failed, restarted so restarted TrueNAS.... now my share is borked...

molten sky
#

welp

#

would it have helped if it was dockerized

boreal scarab
#

Fixed it

#

Had to turn the shares off and on again couple of times

boreal scarab
molten sky
#

you broke your nas by breaking a container on the nas

#

damn

rapid merlin
#

Hello.

#

Guys, tell me something.

molten sky
#

"something"?

rapid merlin
#

How can I learn hacking. : )

atomic aurora
#

Goodmorning everyone. Is there some website for wordlists of hidden pages/passwords I can use when pentesting or do you make them yourselves?

molten sky
rapid merlin
#

Wait a sec.

#

I have some questions first.

#

Can you answer them?

molten sky
#

kali comes with the SecLists wordlists preinstalled, along with rockyou

molten sky
atomic aurora
#

Right.. that actually makes a lot of sense. Thanks man!

molten sky
rapid merlin
atomic aurora
twin ridgeBOT
#

Gave +1 Rep to @molten sky (current: #89 - 70)

rapid merlin
#

...?

molten sky
rapid merlin
#

Man how many possibilities are you typing? : 0

rapid merlin
molten sky
#

trying to think of a way to answer that's acceptable for thm, lol

rapid merlin
#

You can answer me in DM if you want to.

#

Have sent you a friend request.

molten sky
#

a lot is possible, but it's far from mr robot hack the planet in 15 seconds

#

a lot of prodding and a lot of paperwork for some industries

rapid merlin
#

What is prodding?

molten sky
#

poking and things and seeing what might break

rapid merlin
rapid merlin
glossy portal
rapid merlin
glossy portal
#

Yep, but remember he's a very unhealthy individual to emulate, personality-wise

rapid merlin
#

I've gained interest in hacking.

rapid merlin
#

But the things he's doing are holy. blobheart

#

I want to learn.

glossy portal
#

Go here, pick an easy path

rapid merlin
atomic aurora
#

The world is your oyster.

unborn cairn
#

read the website owo

glossy portal
#

There's a perfect room for that 😉

molten sky
glossy portal
rapid merlin
#

I mean for now. Maybe that will be my first milestone. 😂

glossy portal
rapid merlin
#

To learn only?

rapid merlin
wanton furnace
#

Any Best Resources for Learning Networking

#

@wanton furnaceHi

glossy portal
glossy portal
unborn cairn
#

I'm really grateful for whoever added SSRF onto THM.

#

I had trouble self-learning.

rapid merlin
#

@glossy portal BTW Shei... I just want to know, is it actually possible through?

#

Wifi hacking?

glossy portal
#

Yes, there are many ways

wanton furnace
glossy portal
wanton furnace
#

Thanks

rapid merlin
#

Man there are no paths whatsoever.

#

It's only loading and not showing anything.

#

@glossy portal, I need some here over here.

glossy portal
rapid merlin
#

Now tell me something. I am pretty much unaware of the things mentioned there.

#

Tell me which path to follow.

#

Suppose I want to be like Elliot.

#

😂

glossy portal
rapid merlin
#

I don't know, you suggest something to me. @glossy portal

atomic aurora
#

Pentesting

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @atomic aurora (current: #1323 - 2)

rapid merlin
naive violet
#

None of those

#

Please don't post giant blocks of text like that @wanton furnace

#

Those are Networks, which teach network pentesting not networking

wanton furnace
naive violet
#

You can

#

There's lots of content on it

#

But you were not looking in the correct place

wanton furnace
#

so you please provide link for easy netoworking @naive violet

naive violet
#

I don't have the website open and I'm not signed in from here.

Go to the search page and use the search box.

wanton furnace
#

Thanks

finite basalt
#

Morning 🫡

wanton furnace
#

You Late Morning 12 Hour 30 Minute Ago

naive violet
#

This is how timezones work, yes.

wanton furnace
#

Oh Sorry

devout palm
finite basalt
desert shuttle
#

Man it sucks to overlook the small stuff

rapid merlin
#

Facts

chilly veldt
#

Morning

naive violet
#

@finite basalt how's hacking the EM space going?

rapid merlin
#

Good morning people who have similar interests to me

molten sky
#

👀

molten sky
#

gotta love when you turn to youtube to figure out how to do something and the most coherent video is by a child

#

watching a literal child to figure out how to do the thing i forgot how to do

sharp spear
#

Hi guys, I'm a complete novice in hacking, I'm not looking to go through any type of learning, I just want to know from you, who have already used the site, to learn something, what I learn with my free registration, will I be able to do exercises like from pentesterlab?

rapid merlin
#

I dont have experience with pentesterlab. Could you define more what you want to do?

sharp spear
#

like, in the module where I am, I am learning the basics about networks and many other things, however I wanted to know if in my account with free access, I will have access to more ''right'' content literally teaching how I can enter systems and servers, obviously for educational purposes

rapid merlin
#

Yeah there are lots of free rooms

nova pollen
#

You can’t complete paths but there is a ton of free content to learn a lot.

distant gazelle
#

therte is also a lot on youtube

mossy river
#

Earliest I’ve been awake in weeks 😴

sick lance
mossy river
#

Yes :(

#

Woke up at 7am

#

Class isn’t until 10am, but I had to make sure I was awake haha

sick lance
#

Have you been awake since 7? 😄

molten sky
mossy river
shell nova
#

I hear you

sick lance
#

I slept in today, I got up at 8 😦

molten sky
sick lance
#

I usually wake up at 5.

mossy river
shell nova
#

Can I go back to sleep yet?

mossy river
#

I really struggle with early mornings. I wasn’t always like this however.

From ages 7-15, I would get up at 5/6am, get dressed and sit downstairs until it was time for school

mossy river
sick lance
mossy river
chilly veldt
#

Jabba, may I DM about a topic I wanna talk about?

molten sky
#

part of me whats to know the other is too tired to care

chilly veldt
#

It's just a topic that is a little political, so I wanted to hear before talking about it to not break rules

mossy river
molten sky
#

Writing for POSIX is a waste of time and energy

grand bone
#

Hey people I don't know where this belongs maybe someone can point me to where I can get help. So in Network Services 2 Enumerating NFS Task if I do it with the attackbox everything works fine, but if I do it with my own vmware machine, I mount the directory and everything's fine but as soon as I ls in the mounted directory the terminal freezes up and I can't reach the directory from a new temrinal window too. Someone maybe able to help me or point me in the right direction? I am just using a normal Kali on vmware setup, haven't changed anything from the original distribution.
Thank you so much!

I have posted this in subs-room-help a few hours ago but no luck

mossy river
#

#subs-room-help is restricted to only subscribers so there’s less people around to help

molten sky
#

i forgot that i'm not subbed anymore and was confused :/

rapid merlin
#

Thats a pain

sick lance
grand bone
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1159)

shell nova
mossy river
chilly veldt
#

my whole stomach feels like I was punched like a punching bag by a boxer

glass nest
#

Well, thats what you get for keeping in shape.

chilly veldt
#

yeahhh, I worked abs yesterday

vast badger
#

wrong gif lol

mossy river
#

Yeah…

rancid maple
#

Hi everyone, am a Full Stack Developer, nice meeting you all.

I wanna ask question and I need you guys suggestions for the question... Am I free to ask here?

mossy river
#

Go for it

rancid maple
#

my lecturer is pursuing a master degree course, he's about to build a project, a wide one, he called me and explain the project to me that it's a master's degree project not like school project that it's gonna be wide. the project is based on agricultural sector (Nigeria for example) and AI. as he explained to me he said, it going to be an application that'll predict what famer will do for his next plant, just like forecast since it's built with AI, like forecast predicting the weather if it's going to rain today or not, if it'll be sunny tomorrow or not like that.... he said, if the famer plant maize today following the AI app that's going to be build, the AI will tell him what to do next, maybe in the next 4 days he need to add fertilizer or wet it or do something else to it.

He also said that as i know we're going to collect data from various places in agriculture to train the AI, so AI will work very well and accurate, he also said that he also want it to help the economy as things are cost in Nigeria nowadays, instead of importing things in from other country.

What he told me to do now is to make research about it and i think about the agriculture too also.

Need your assistance, you can use your country as example instead of Nigeria

vast badger
#

basically an ai farming app

rancid maple
glass nest
#

Base the info from the same time last year. 2-pronged attack - Get weather info from whatever national weather service is in the country, and contact a farmer (Or farmers) to get yeild numbers as a proportion of field size. Surprised a Masters student wouldnt have already done this though/

rancid maple
glass nest
#

the simple answer is - Step 1: work out what info you need. Step 2: workout where you can get that info from. Step 3: work out HOW to get that info.

twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 391)

brisk tree
#

hey

sick lance
#

👋

mossy river
rapid merlin
brisk tree
blazing granite
sick lance
#

We don't want her anymore.

She abandoned her country for sunshine.

nova pollen
#

That’s harsh 😧

brisk tree
night prairie
#

._.

sick lance
chilly veldt
#

your*

night prairie
#

I haven't gotten a bsod in a while

sick lance
#

No, I was right.

She's an opinion.

chilly veldt
#

fair fair

sick lance
nova pollen
#

I miss the old bsod they looked way more scary 😂

night prairie
sick lance
night prairie
#

😂

#

is there a way to check the last uptime before shutdown?

#

pretty sure my laptops been running for like a month straight 💀

#

i stopped putting it to sleep at night as well

#

probably not a good idea

sick lance
#

Just left open?

night prairie
#

just leave it locked, screen is always closed but it's connected to my monitor and still awake

mossy river
#

You should shut your PC down regularly smh

night prairie
#

It's a bad habit, it started when I used to leave my laptop running here and I would visit my family on weekends then RDP into it so I could do my uni work

brisk tree
night prairie
#

Got proxmox on there but no VMs ATM, had one for an MC server but we stopped playing

night prairie
stuck ridge
#

run hell diver servers

#

they need its

#

bad

stuck ridge
#

:p

night prairie
#

What's hell diver? I recall someone mentioned it here yesterday too

brisk tree
#

But yeah it’s not good for it to be on all the time

stuck ridge
#

its new game

#

but they are having issues handling so many players

#

its a long q to get in lol

stuck ridge
#

yep

#

lol

#

democracy

night prairie
stuck ridge
#

yeah, screw that lol

#

new world had the same issue

night prairie
#

I just wanted to collect my daily reward 😭

#

I don't hear new world mentioned anymore, did it flop?

stuck ridge
#

yeah

#

end game was weak

#

they have problems balancing the pvp so people fell off

night prairie
#

I met one of the devs once, asked him for a game key but he said no 😔

stuck ridge
#

aww what a loser

night prairie
#

I mean, understandable, it's a £50 game XD iirc

stuck ridge
#

you would think they have pull to hand out free keys

#

but they are probably underpaid devs

#

being pimped out to the system

night prairie
#

Tbf I asked him jokingly, I doubt they'd give out the game for free to some random guy 😂

#

Met him at AWS' Shoreditch office iirc

stuck ridge
#

oh

#

how everyone doing tonight

brisk tree
#

Doing ok wbu

stuck ridge
#

hanging like wet laundry

#

:p

#

trying to trouble shoot an elastic instance

brisk tree
#

Awww

stuck ridge
#

morning

brisk tree
#

I’m still trying to recover from 4 hours of free drinking on Saturday 😂

stuck ridge
#

oh shit

#

nice

#

what did you drink

brisk tree
#

Cocktails

stuck ridge
#

sounds like a good time

brisk tree
#

It wasn’t the next day 😂

sacred lichen
steel aspen
#

I'm a better chef than Gordon Ramsay, I'm a CyberChef 😎

stuck ridge
#

rip

near hawk
#

?

mossy river
#

I’m interested dm me

night prairie
#

i've been dreading writing unit tests since yesterday

#

but once i started it, turned out it wasnt that bad after all

rapid merlin
#

👋

#

Sup everyone

#

Time for some THM Rooms

finite basalt
sick lance
#

Get a new phone 😄

lucid tinsel
#

i don't understand "payload" very well, so if i send a payload bash code to target, and its contents is "ls -la" then the target got payload that i send. And target's computer will "ls -la"?

#

i don't quiet understand this

mossy river
#

<@&1174352727451652214>

#

que

sick lance
#

Deleted -role eh...

boreal scarab
#

Jabba borked something

sick lance
#

DevSecops role incoming 👀

boreal scarab
#

👀

mossy river
#

</verify:1174352727451652214>

#

👀

#

</verify:1174352727451652214>

#

:(

sick lance
#

Somebody Reboot Jabba.

mossy river
#

verrerèify

mossy river
wraith nova
#

Does anyone know why secretsdump isn't outputting anything? I have extracted a copy of the SAM and SYSTEM files and am using python3 secretsdump.py -sam ./Desktop/SAM -system ./Desktop/SYSTEM LOCAL command but not getting any output

wraith nova
#

I have a forensic image of a hard drive and some of the files are password protected so I am trying to extract the pass from the registry to see if the same password has been used for the files

mossy river
#

For what though

#

Is this a CTF?

wraith nova
#

no its for uni

mossy river
#

We don't help with schoolwork here

sharp citrusBOT
#
<#651923438524432404>
Rule 5 - No Cheating

Cheating of any form is not allowed. This is not limited to asking for help with assessed schoolwork or exams.

wraith nova
#

the work isn't assessed but ok i apologise

sick lance
#

Not now, I think it will be in your end of module coursework or exam though.

sick lance
mossy river
sick lance
#

DokiDokiDoki has been typing for a long time...

upbeat scarab
#

Hi, is there any room focused on covering tracks or logging security ? I have already done Windows and Linux core rooms or event viewer for Windows, is there anything else focused on a red team/pentest way ?

#

was looking for my english words, it's quite a long day 😄

sick lance
#

I'm not sure a room is there, or I can't think off the top of my head right now.

near hawk
#

Not sure if this is what you're looking for but maybe this module might help?

https://tryhackme.com/module/security-information-event-management

upbeat scarab
#

ok nevermind, I will look for security blogs or things like this, I think that it would be great to get this some day, something related to the cleaning phase instead of enum/exploit/post-exploit, there is already nice things about persistence 🙂

cosmic fiber
#

Hey ya'll! Would anyone happen to know if there are Meet Ups or group practice sessions? I'm still very new to security but I want to learn with ya'll.

cosmic fiber
sick lance
devout palm
#

is this new?

near hawk
#

The bonus points?

#

They've been they're for a while

devout palm
#

Oh bonus points

#

It'd be nice if there was a point indicator of each question

icy grotto
#

can i have a question, what questions or topics are mostly used in techno quizes?

near hawk
#

It would vary I guess

icy grotto
#

but waht are mostly?

near hawk
#

No idea, they're all most likely going to be different

sick lance
#

Standard points

30 for challenge

8 for walkthrough/info

Bonus points if specified.

near hawk
#

6 points if walkthrough rooms are older than a month

sleek shard
#

Can I ask about ARP-Spoofing in this server? If so, which channel?

#

its more about the behavior of ARP on wireshark

near hawk
#

You can ask here

sleek shard
#

Using Host-M, I sent an ARP REQUEST poisoned packet to Host-A (It had B's IP address and M's MAC address). This was a success and Host-A's ARP cache table was poisoned. It had M's MAC address assigned to B's IP address. However, when I sent this packet using Scapy, I looked at wireshark, and weirdly, the only packet that was captured by wireshark was from host B (Who is 10.9.0.5 (A) tell 10.9.0.6 (B)) but why is that? Why did B send an ARP request and how did it even know M and A were communicating?

rapid merlin
#

How is it possible that I have credentials of a user and I can RDP into the windows machine, but when trying to SSH into the machine I get Permission denied?

near hawk
#

Is ssh open?

rapid merlin
#

and scp is part of ssh right?

#

im not sure how to check if ssh is open

#

I solved it by using meterpreter's "download" command, but still, im not sure why i couldnt ssh

near hawk
#

What room you doing?

rapid merlin
near hawk
#

Unfortuntley I haven't done that room, take to #room-help

rapid merlin
#

No worries

blazing stone
#

lets say i get a scam sms, and i want to investigate it cuz i think i can maybe learn a lot from it, but i would like to use a vpn for it (and ofc vm but i have that). what vm do yall use for things like this, btw it has to be free im not paying 💀

#

idc about the location as long as its a good safe vpn and it hides my actual ip

crude stump
#

@simple valve I bought this is how they tell me the world ends

crude stump
blazing stone
#

whats a sandbox

#

im using virtualbox

#

but i have the vm im more asking for the vpn

#

also ye it has a link

hollow pivot
blazing stone
#

im not sure how i would create a sandbox tho tell me more

crude stump
#

It’s basically so your vm is totally isolated from your computer. It’s mainly used to test malware

blazing stone
#

how do you do that

sick lance
#

If you can't, create a sandbox effectively, I believe you shoulnd't try.

#

Learn first

rapid merlin
night prairie
blazing stone
#

i have this link

#

would love to see what it is

sick lance
#

If you don't know what you're doing, don't interact with it.

Just report and move on.

night prairie
#

</verify:1174352727451652214>

night prairie
#

👀

blazing stone
#

how much harm can a link do

#

famous last words

#

XD

sick lance
#

You learn by learning the fundementals and isolation first.

mossy river
blazing stone
#

so i cant get scammed

sick lance
#

I mean, you wouldn't like to click the link, don't have isolation and bam.

Malware central.

mossy river
#

If you analyse every single scam link that you come across, you will be here until the end of time

blazing stone
rapid merlin
#

Uh?

sick lance
blazing stone
#

apparently you cant 💀

mossy river
#

@rapid merlin Are you fr?

rapid merlin
#

You dont know threat yeti?

blazing stone
#

which is why i would click it in a kali vm

mossy river
#

Don’t own it, don’t scan it

rapid merlin
blazing stone
rapid merlin
#

It provides you a screenshot

blazing stone
#

whats wrong with that

rapid merlin
#

Of the website

mossy river
# blazing stone wdym

Don’t touch things you don’t own. It goes quickly from looking at the website to you breaking computer misuse

#

You don’t have any business messing with scam links

#

Report it and move on, you’re not Batman

#

I’m Batman.

hollow pivot
blazing stone
mossy river
#

@blazing stone I can open almost any scam link and know how the website works, what malicious techniques and how to prevent other users from getting caught in the same scam. Do you want to know how?

crude stump
#

Find a trusted source to walk you through it. But personally instead I would go to app.any.run which basically is a data base of all malware’s different researchers put. You can look up the malware and see it in videos if it

rapid merlin
#

Jared, threadyeti provides you with a screenshot of the website. It does basicly the same as urlscan.io. Nothing illegal right?

blazing stone
#

i mean idk if its mallware its a link

#

and its clearly gonna steal bank credentials

mossy river
#

I’m really glad you asked. I signed up and subscribed to TryHackMe premium.

TryHackMe is a great website and by subscribing to their premium subscription, I was able to get full access to their learning paths that guided me to understanding the fundamentals of cyber security

blazing stone
#

💀

mossy river
blazing stone
#

ive done somet things

#

but i mean a realworld thing is diff

rapid merlin
mossy river
blazing stone
mossy river
blazing stone
#

its curiousity

#

if i report it ill never know what it is

rapid merlin
sick lance
#

If you look at it, you might still no what it is, unless you know what you're looking at/for.

mossy river
#

Curiosity killed the cat, satisfaction brought it back.

If you already know it’s not legitimate, you’re not going to be satisfied when you open it and see it’s legitimate

night prairie
mossy river
#

Do you want to know a 100% foolproof way to not get scammed or hacked?

rapid merlin
blazing stone
#

well ofc dont do anything but i mean

mossy river
#

A common prevention method that most cyber security professionals will teach you is don’t click on things you aren’t 100% sure you know are safe

hollow pivot
night prairie
mossy river
rapid merlin
#

what if a 0day no click hits you or idk how it was named

#

where you dont do anything and your phone gets owned

mossy river
#

Show me one

rapid merlin
#

i mean yeah

blazing stone
rapid merlin
#

o

night prairie
#

then ur cooked

rapid merlin
#

ok

#

very low chances to be the target of one

#

but

#

never 0

rapid merlin
rapid merlin
sick lance
#

0.1% perhaps.

blazing stone
rapid merlin
rapid merlin
#

fascinating i know

near hawk
#

Possible but very rare

blazing stone
#

like the attacker just straight up sending their own entrance 💀

hollow pivot
rapid merlin
#

That malware is very expensive. Not affordable for "normal" criminals.

blazing stone
#

fr

rapid merlin
#

But I think that is something for advanced channels

rapid merlin
#

😄

blazing stone
#

its war level shit

rapid merlin
#

Thats what i heard

mossy river
#

If someone is targeting me with a zero click vulnerability, they have their priorities messed up

sick lance
rapid merlin
night prairie
# blazing stone is that even possible

yes, but they're too valuable to be used on some random person
you'll likely only see politicians, journalists, etc. get targeted by those

i may be wrong but i recall reading about security experts being targeted too

shut hawk
#

Yeah 0days can be worth potentially millions of pounds, if you are a target for one to be burned on then you have far greater problems

night prairie
#

didnt russia start offering 20mil for them?

#

actually probably best not to discuss it here

rapid merlin
#

True

sick lance
rapid merlin
#

I know what channel you linked, but no access

#

:))

blazing stone
sick lance
#

Y'all need to level up.

night prairie
#

how much to buy 0xd 😔

rapid merlin
night prairie
#

or is that still an issue

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @hollow pivot (current: #51 - 130)

mossy river
mossy river
#

I can’t give you 0xD but I’ll take the $20

near hawk
devout palm
rapid merlin
#

Ill give you a tip on how to get 0xD the fastest way possible

#

for $20

blazing stone
#

well im still curious as to what it is but i guess ill folow your advice 😦

devout palm
#

I'd purchase a subscription with that money, much worth it than 0xD

lone thistle
crude stump
#

Personally I feel popular when I get a scam message

#

They all want me 🤩

lone thistle
#

must be nice 😦

crude stump
#

Befriend your local scammer

#

😂

lone thistle
#

I already pay my landlord. Isn't that enough? KEKW

crude stump
#

Even a Nigerian prince wants to contact me

blazing stone
#

its quite a boring message

#

it supposedly from a bank, which i dont use, saying [insert bank name here], because of an update you need to verify your account, do this on this website: link here

#

XD

#

its obvioulsy just gonna grab your creds

rapid merlin
#

Hi

#

sup trump

crude stump
heady nova
#

Ello

night prairie
brittle lynx
#

If there is an empty error in response to a LFI attempt whats that mean?

mossy river
#

How do you know it's an error if it's empty?

brittle lynx
mossy river
#

Still doesn't answer my question 😁

brittle lynx
mossy river
#

How do you know it's an error if it's empty?

#

What is telling you it's an error?

crude stump
#

The error

shut hawk
#

time to say bye to my storage

crude stump
#

Bye bye storage

bitter quiver
#

Glad I got back into this

#

Started new medication that helps with anxiety and now I wake up at like 6am daily to spend an hour on here

normal flare
#

is there a place where i can get a free linux cloud vm?

bitter quiver
#

Free I'm not sure of, at least not one that lasts long. But it's generally easy to run inside a VirtualBox VM on your own machine.

buoyant tree
bitter quiver
#

Network Chuck showed a couple options but they were short trials

buoyant tree
#

what GPU u running it on

bitter quiver
#

Then it costs per hour

boreal scarab
#

Sashimi from a japense super market. and real japanese soy sauce from Japan made the traditional way

boreal scarab
#

And Boba!

boreal scarab
#

Squid

#

Oh and octopus too

buoyant tree
#

makes my stomach hurt not in the good way

boreal scarab
#

Oh I love Sashimi

grizzled crystal
#

i also love sashimi

boreal scarab
#

Didn't realize it had octopus in it lol

grizzled crystal
#

youre living the high life

shut hawk
boreal scarab
buoyant tree
boreal scarab
#

This is the soy sauce

sand trench
#

yuup it sure is

boreal scarab
buoyant tree
boreal scarab
brittle lynx
shut hawk
#

oh interesting, it's written in python

buoyant tree
mossy river
boreal scarab
#

That octopus was quite good. Chewy but good

shut hawk
# shut hawk

and of course, they haven't setup the requirements properly kekw

boreal scarab
#

Steamed rice cakes

brittle lynx
crude stump
#

If it’s empty wouldn’t it not be a error?

brittle lynx
crude stump
#

Hold on what are you doing this for?

buoyant tree
brittle lynx
crude stump
#

Oh I have no knowledge on that room kekw

shut hawk
buoyant tree
shut hawk
#

ah its using a conda envio

sand trench
#

nvidia driver stuffs is nightmare fuel in coding stuffs

buoyant tree
#

just pull a all nighter, hydra wasn't working for me a few days ago so I coded a version very very specific for my needs and built one in go

shut hawk
#

these are it's requirements

sand trench
#

how did you even break hydra aio???

#

it has been stable for shadow for ages

#

and that is still using kinda bleeding edge with arch based distro

buoyant tree
sand trench
#

huh interesting

buoyant tree
#

then its installition wasn't working anymore

shut hawk
#

ah, did you install the latest version?

sand trench
#

wonders when aio is getting 0xD

buoyant tree
#

may have done sudo apt update && upgrade

shut hawk
#

ok fixed, I just added pycryptodome==3.15.0 as a requirement and then monkey patched the entrypoint bat file

buoyant tree
#

but eh its workin now

buoyant tree
shut hawk
#

why?

buoyant tree
#

its the programmer move

shut hawk
#

😎

buoyant tree
#

Also Jayy by any chance u know react.js?

shut hawk
#

I know of it

#

I don't have any experience programming in it

buoyant tree
#

Gotta learn it

#

need course recommendatinos

grizzled crystal
#

sign me up

#

i actually recently bought a bunch of javascript courses

#

i feel like i need to get better at web dev to get better at web hacking

buoyant tree
#

eh I can read javascript like I can read go

grizzled crystal
buoyant tree
#

but I can't write in it

grizzled crystal
#

React has a lot of weird idiosyncrasies. It's worth studying in-depth if web security is something you're interested in

buoyant tree
#

Just for some work

#

gotta build websites

#

thinking about this one

grizzled crystal
#

Yeah that one's good

#

I've done that one, it'll get you going

grizzled crystal
#

i want to try conveyor belt sushi

#

genius concept

boreal scarab
#

I know there's a place in Japan for people who have a tough time with social anxiety, where they interact with people behind a wall

grizzled crystal
#

I think that'd make my anxiety worse

crude stump
#

It’s a restaurant for introverts

boreal scarab
crude stump
#

It’s a cute idea

grizzled crystal
#

ohhh thats really cute

boreal scarab
grizzled crystal
#

i thought you talked to other customers through the wall?

#

i was confused

#

this makes more sense

boreal scarab
#

Oh, and those Anti Social reasurants

grizzled crystal
#

sounds great

solemn ravine
#

For Windows machines, why SSH refuses to connect, the only way is rdp. Is it usually the case?

grizzled crystal
#

it depends on which ports are open

solemn ravine
#

22kekw

grizzled crystal
#

well, if you can connect with rdp another port is probably open

boreal scarab
grizzled crystal
#

googlefu will tell you which one

boreal scarab
sand trench
#

T minus 2 months TM

boreal scarab
sick lance
#

Urgh, is it really locked to W11?

boreal scarab
sick lance
boreal scarab
rapid merlin
#

Is there a THM Path that covers topics from the CompTIA Network+ ?

bitter quiver
#

The networking portion is rather light from what I've done recently.

#

However, ton of free resources out there for N+

#

It's just memorizing a lot

wintry garnet
left parcel
#

Hi

wintry garnet
#

I would recommend CCNA tho

left parcel
#

New member here!

rapid merlin
wintry garnet
bitter quiver
left parcel
bitter quiver
#

CCNA is much harder and specific. N+ is generic

#

However CCNA is more fun

#

I used the Boson Netsim software a lot

left parcel
#

Huh

wintry garnet
rapid merlin
#

Im going for the Net+ because im aiming for the Trifecta

left parcel
rapid merlin
#

Actually I should start with A+

wintry garnet
bitter quiver
left parcel
#

Huh is hacking difficult?

bitter quiver
left parcel
bitter quiver
#

Script kiddies are hackers and it's easy for them.

bitter quiver
left parcel
#

Who are script kiddies?

rapid merlin
left parcel
wintry garnet
bitter quiver
#

Hacking is for a lot of folk. Recreational fun/people who wanna be pen testers/ people who want to be in cyber security blue teams/ people who have ill intents

rapid merlin
left parcel
#

How to know if you should do this or not

bitter quiver
# left parcel Who are script kiddies?

Wannabe hackers who learn how to automate things and use scripts that already exist but lack any fundamental understandig ofwhat is happening at a hardware/software level

bitter quiver
#

Do you just wanna know what the movies are all about?

wintry garnet
bitter quiver
#

^

#

Even if you are passionate you are going to get irritated

#

Often

left parcel
bitter quiver
#

But that's where the joy comes in. When you break through a wall

left parcel
#

Hm

#

So like

bitter quiver
left parcel
#

Problem solving?

left parcel
#

Above 18.

bitter quiver
#

Analytical skills, problem solving, logic

left parcel
wintry garnet
bitter quiver
#

In fact if you brag you are a shitty hacker

glass nest
#

Ability to handle large amounts of coffee

#

Eh.. depends what you brag about 😄

left parcel
glass nest
#

Getting a CVE published is kinda braggable

bitter quiver
left parcel
#

So I gotta know if it interests me or not

bitter quiver
#

I mean non-white hatters who brag

#

And paint a target

wintry garnet
glass nest
#

I know what you mean Cipher 🙂

left parcel
#

Cypher

#

Valo player here

bitter quiver
bitter quiver
left parcel
bitter quiver
#

Anything Riot games to me is like a slugs skin.

left parcel
#

I play because my friends play it

wintry garnet
#

I like women

bitter quiver
#

^

#

lol

left parcel
wintry garnet
#

And, going outside

#

..sometimes

left parcel
#

I play sometime bruh

bitter quiver
#

Also Channing Tateyum and Henry Cavill are my male crushes so I like women like 99%

#

But there are exceptions

wintry garnet
bitter quiver
devout palm
#

Hi

bitter quiver
#

Like. I ain't gay, but I ain't saying no

left parcel
bitter quiver
left parcel
wintry garnet
sick lance
#

IF/When I get a CVE, you best beleive I'll tell people.

left parcel
bitter quiver
#

Don't hate me because I'm beautiful

left parcel
bitter quiver
#

But Wander

#

For THMs cost

#

It's really worth it

wraith fjord
#

I forgot, where to navigate to access throwback? That was the AD lab yeah?

jovial notch
wraith fjord
#

Dissapointed potato noises

sick lance
#

Plenty of good AD networks to do.

bitter quiver
#

lol

heady nova
#

Sup

sick lance
#

General is on one tonight it seems.

boreal scarab
heady nova
#

Ello scrubz how's school

#

Sup matt

#

How sleep?

boreal scarab
#

CHilling, drinking my Boba and updating my laptoop

heady nova
boreal scarab
#

Also want to finish working on my firewall.... but also too lazy to finish working on my firewall

boreal scarab