#general
1 messages · Page 33 of 1
lol top gun?
eh I uninstalled miles morales and rdr2
now to decide between these 3 to play first
They have a whole modern day alt reality earth with insane geopolitics and near future weapons
its chinese?
THeirs a new DMC?
Ace Combat, its Japanese by Namco
its DMC 5
The newest entry is a good start
holly I thought they stopped at 4 when I had my ps3 !
It’s even got Top Gun DLC for you lol
yup
Just buy the base game
It's Webkinz!
eh its 18$
Nah! Webkinz! One of my childhood games!
for the complete maverick edition
Do it on sale, but that’s not bad compared to the above lol
even if I don't play it still a good collection
yea but the next game I want to buy is really undertale
I don't care about the story right now
i want those epic scores
lol undertale is kinda all about the story as well
yea but the main reason I am playing it because of the scores
May have to spam a fave of mine
They are GREAT
send it over
かめりあです。
hi, it's camellia.
以前から、「スマブラに #Undertale のキャラが、 #Sans が入ったら #MEGALOVANIA のリミックスを作る」と明言してきました。
from a while ago, I've been mentioning that I'd make a remix of megalovania when sans or some character from undertale joined the smash ultimate.
そしてご存知の通り、先日のアップデートでスマブラにSansのMiiコスチュームが入り、そして「MEGALOVANIA」のToby Fox本人によるアレンジも収録されました。
and as yo...
Epic
although for personal listening I prefer taylor davis's version
Some more nastolgia
lol yeah I think I did link it previously so makes sense
And nice, yeah I’d heard of this as well
I’m slightly too old for webkins and ToonTown but more than familiar with their tech presence
first I heard you say that
And lol watched my fair share on YT videos ok then
What do you mean?
You are too old for something
When the were new
oh k
I’m not excluding me trying out ToonTown Rewritten at some point
oh k
Just was a teen and my younger siblings were all in
and the ending changes entirely so great
Which to play first
Can’t help when I’ve played only one of those
all are great fighting games just can't decide which one to play first
Evil west I really wanna play for over a few months
but DMC5 i heard is great
I would describe them more as beat em ups and similar, fighting game has some Streeter Figher expectations in English
eh ones beat em up
ones slice them up
ones shoot them up
Heh totally fair
What is the best VPN file configuration for Asia?
Likely IN-Regular-1 or AU-Regular-1 latency wise. I’d imagine some of the EU VIP ones would be fine if you have access
VPN only help a little it's better to create your own VPN Military grade encryption if you don't want the company to give away information to the government
I do have access to them, now I am based in south east asia, i will give all three a shot,tho would be nice have a feature to check latency from the website
You can do your own solutions like WireGuard for access to your own stuff, but they just mean OpenVPN access to the site
Yeah unfortunately can’t check your own latency easily via the site, some simple ping checks looking at TTL of THM targets should help once connected via each OpenVPN
I'm using proton open sc and brought my own servers through me and my buddy are building it
They were mainly a stuffed animal toy that just happened to have this web aspect
Neopets did similiar, but they never went all in on the “the toy is the product” aspect
You guys don't know proton is open sourced?
What are you building into yours that wine-staging or proton-GE don’t already provide?
me and my buddy's just wanted something of our own.
Nice idea I guess, but yeah just keep your fork up to date with upstream
Also kinda missing out on some niceties like just using protonup-qt to manage the most popular custom proton versions
Including some neat ones like Luxtropedia which acts as a shim to actually load Linux native source ports for specific games
hello chat
Heya!
send help
lol that new one that’s supposed to be rated as badly as that um, other related movie?
morbius
yeah lol
yup
I’ll pass for now
Planning on watching it for comedy
Sony needs to stick to their animated ones, which are killer
yup spider-verse certified great
well the start of it was finding out that owasp split amass into several separate tools recently
low key have that with my vuln scanning at work
Early 2000 childhood games
so now I can't dockerize it as a whole unless i use an old version
Not hard of that being the case before, weird
and then to install the seperate new tools onto the host itself, it requires a new version of go that's not yet in the repositories, which just didn't work for some reason when installed manually
spent a few hours trying to resolve only to remember that you can install new versions of go alongside go with go
What host? Just do Kali or Arch tbh
server does a lot more that i would rather not use either of those for, lol
never been a problem 🤷♂️
I was being facetious, it’s mainly just used for THM/HTB while having no relation to my home network beyond ssh/ssh tunneling
I just pretend it’s my c2 infra since I’m a leet hacker lol. But nah I’ve tried some c2 frameworks on it for real
Yeah and then I ssh in, and then ssh tunnel my HTTPS and or RPD traffic back to local as needed
just uses the vpn like you would from your own computer
I’m just making this remote VPS do the attack box duty, and tunneling the things I need back to me
I could get more fancy than that but this is nice
i need something to send emails with from the server. just simple notifications when a new asset is discovered. think i should just use sendmail or got any fancy ones you've played with recently
Yeah my last investigation into Linux mail was more of a fullstack but sendmail should do fine
If you want cheap and easy, and don't already have a reputable SMTP server you can relay through, SMTP2Go is solid.
I've personally never been a fan of sending mail out via a built in function.
no relay needed, just going direct
Fair
relays are good normally i just don't have a need when emailing notifications to myself
I can also tell you the SMTP relays I see used most in phishing attempts 🙃
also dealing with relays is such a massive pain in the ass sometimes
SES is expensive
SendGrid is owned by Twilio now
Mailgun or whatever is sooooooooooo delayed, and sometimes fails entirely
SMTP2Go I haven't tried yet but do plan on trying
email sucks
screw email
Mailgun was one of the first on my mind lol
and yeah Sendgrid as well
Not sure if AmazonSES works the same way but whew so much phishing from them it’s silly
And can’t just block these, gotta be surgical
If we blocked AmazonSES, we’d block default EDR notifications 🙃
we should just deprecate email
top gun maverick hits hard
Almost like it’s 1960s plaintext protocol that we’ve tacked onto over the years enough that it’s gotten insane… or something lol
just reattached to tmux to see i never actually started the thing i wanted to start
Google and Yahoo, “you need SPF and DKIM”… yo, you all have it and are sending out so much phishing lol
come again?
Many challenges
wait do you mean just don't use a relay at all
They mean full email stack
you'd still need an smtp relay or 90% of your outgoing is getting dumped by google/ms/etc
managing a mail server nowadays is a massive time suck and a huge PITA
It’s hard to build good reputation on your email, especially if it’s a weird VPS host
digitalocean gave you a sus ip? oh well, no mail for you
send it to something that’s at least half respectable
lol DigitalOcean I actually hugely respect for their anti phishing. I have seen one single DigitalOcean VPS as the web mail host of phishing in my three years of work
spamhaus and barracuda
seen them as lofi c2, but only just the once for phishing
If it’s a big VPS name, it’ll always be OVH to a fault
lol, right on spamhaus's removal page
Yeah they have a 25 day waitlist at the very least
SMTP is about as much as they’d like you to do ideally
They say you can, but have a whole page on why self hosting email is not ideal lol
lol I do see them in phishing as well but fair enough
google and microsoft have ruined self hosted email
lol maybe not completely wrong, but yeah things with email reputation are much more difficult these days
boss tried to get me to build a self hosted email sever for some low key stuff (full stack). Mentioned how difficult this would be. After a while he checked up on my progress and remakred, “just using a service would be more expedient”…
Yeah lol it would have, as I possibly recommended from the start
cheaper to spend a couple bucks a month of licenses than it would be in the man hours just to maintain the thing
For real lol
at least my low key Linux Docker hosts need barely any maintenance. Even have RMM now which is nice c:
It’s for sure doable, one of the full stacks I was looking at basically Dockerized all of the standard Linux tooling for mailservers. I’m just not sure how down to the component that was
one sec
Darn it, wanted to dig into their docker-compose.yml but too much digging for me rn. This is just a nice full stack you may be able to pick apart for only what you want: https://mailu.io/2.0/
Quick search of DockerHub shows just custom/community postfix containers however, unfortunately
But it’s not too hard to build a DockerFile for something like this
Anyways, back to my classic TV shows and dozing off, nice chatting with you all!
I saw openai new addition of sora. Creating short videos from prompts. They look decently good
Morning
m
I feel dead
same
Any free resources for preparation of btl1 certificate?
I can't actually buy it yet. And I can't access course material unless I buy it. Can I?
So that's why I was asking if there are any resources?
Unfortunately I think that's correct --- course and cert are sold hand in hand
SBT (the people who run the cert) also run SBT Online or something with a similar name, and it probably has a lot of the same topics
from what I can tell, it looks like the rooms are (likely) structured pretty similar
had the name wrong -- it's Blue Team Labs Online (BTLO)
i think they have some free sections but I haven't used btlo myself
@chilly veldt are you able to confirm? not sure if you've tried their labs
They have a free option, if not then there's also letsdefend.io who also makes labs like that
"Letsdefend.io" does this one provide free labs?
Yeah, it does
Alr thanks 😉
https://twitter.com/vxunderground/status/1759732862335504773?t=HBeTYcUApLoATinloh6hFw&s=19
Hahaha ha!
Lockbit ransomware group administration claims that law enforcement agencies compromised them by exploiting CVE-2023-3824
More information: https://t.co/28v1Yz4L7t
Honestly? Lmao
Seems like it, I know the website was taken last night
There's a lot of misinfo already going around about it
VXUG are solid as ever though
is anyone here good with silver bullet? just starting out
From what I have read some places is that they only got access to servers running php, and not backend stuff
https://twitter.com/vxunderground/status/1759703708785365068
Lockbit ransomware group has issued a message to individuals on Tox.
"ФБР уебали сервера через PHP, резервные сервера без PHP не тронуты"
"The FBI fucked up servers using PHP, backup servers without PHP are not touched"
why this command not working for me
what ?
Did you get it?
Hi, is a mod available? if so, can I DM you regarding the feedback meeting?
It's 9am in UK... Probably in a couple of hours, I'd imagine?
Thought you could schedule it? Also 1:1?
feedback meeting?
15 minute thm product feedback meeting
Alright
I'd have to write stuff if it's 1:1, hopefully I can avoid talking if it's a big conference...
I'm not sure if I know what exactly you are talking about :p
I thought Dolphins knew everything...
All good, I'll figure it out
You got this, shei 😄
To be fair, all the THM folk I've spoken to have been cool, so theres nothing to be nervous about
Morning
that makes sense, but I gotta at-least try to leave an impression I'm getting free vouchers in exchange xD
😮
So I'm assuming I have to put in some effort on my side too, like a bulletin "here's what you can improve"
Integrated dark mode!
Thats been suggested so many times. It's a meme at this point
I once got the perfect bot response on that one. Should still be in #764491023127674910 somewhere.
It is 
Haha, oh Fawaz. what a legend.
What can i use instead of Ncat on Linux (Ubuntu), or i can install ncat on it?
You can install Netcat on Ubuntu
This one was the best.
Thanks
Gave +1 Rep to @hollow pivot (current: #51 - 131)
Is the attackbox dependent on your computer's speed?
No, it's specific amount of resources it gets, it might seem slow because of your internet connection
Shouldn't be, but it may be affected by your network
what ever happened to nanaisu
haven't seen them in the server for a while
unless they changed name
they gave me 3 months of thm premium when I first started out 
Left the server.
I don't want to join a server to talk to them, but I have some questions for 'em.
So I'll email them.
That works
Oh dear
Kinda desperate here, what's wrong with this filter? Syntax seems to be fine
"AND is unexpected in this context" but that's where it should be I believe
is it lowercase and?
jesus christ
😆
&& would work too
here
Gonna steal that
its only because Kali hates me..
Thanks man, the examples on the room are not precisely correct
Gave +1 Rep to @shut hawk (current: #13 - 477)
Huh, link the room
Sounds normal
Muiri said the other day that when he resigned the admins changed his rooms to THM, I think that was the reason why
reported thanks
Gave +1 Rep to @gritty marten (current: #998 - 3)
If you find any others, feel free to put them in #room-bugs
Absolutely!
all hello curious for those who have climbed the ranks of leaderboard did that ever result in receiving better job offers?
Does anyone know how to create a gmail account without verification?
You still need to verify the account with a phone number or email address
hello guys, I have some doubts to clear, when I apply for entry level opening in cybersecurity like analyst roles, most of the job description includes we have to aware with frameworks like ISO 27001 like that, so we have to achieve any kind of certifications on these in order to add these on the resume? or is it just about the knowledge, sorry if this is a blunder question.
Iso 27001 is a certification for a company. Not for an individual. You just have to understand what it is and what it means.
|| @dusky sorrel ||
Okay, thanks mate @rapid merlin I am just confused whether I can add it on my resume or not, so I think I have to learn a bit more about these standards.
Gave +1 Rep to @icy epoch (current: #551 - 7)
hmm
wonder why they did that
If you want to work for cyber in EU i suggest to learn about the new directives
You can become an ISO27001 certified auditor
And if you’re a lead auditor you might find a lot of new opportunities in some European countries
got it.
Bot
Do you want hacked?
This is how you get hacked.
You affected by the hack?
Lmao.
No.
litteraly he posted it in every channel
Yep, I pinged the mods so one of them will remove it
Needsleep asked about the picture I posted.
Not the Adobe crack.
I think it was just a comment on the adobe because it was posted in every channel.
my fault, I misunderstood
I know that someone is talking about an affiliate unhappy
Yup
It'd around lhnch time for some mods, so it will be gone soon.
Lunch*
Yeah. But that's a lot more advanced than a "normal" security analist
But it's good for further in your career
I wouldn’t say that’s more advanced, it is mostly legal, not that deep in the technical stuff
If you’re a lawyer it’s easier than if you have some technical experience tbf
Ah
https://tryhackme.com/room/whatisnetworking
i found some differ differ course on this
Any systematic course in networking for free

Also https://skillsforall.com/career-path/network-technician?courseLang=en-US it's a web run by Cisco and it's free
2 people arrested, 34 servers taken down 200 cryptocurrency accounts frozen.
reeee, I have to boot into my windows partition because of having to print
can't you print without windows?
how to get burpsuite professional for free?
You can't.
The printer breaks the print if I print from Linux
shut
Yeah, like I just get numbers on the side of the paper nothing else
Is it like a special print?
weird
Drivers man I'm telling you it's the spawn of no good
field in networking without networking
My pc juked me regarding the update and now ive been staring at the percentage counter go up 1% every half hour

Windows hates me
Do you have a HDD
cad no. have onshape
@paper delta Hey, can I dm?
Sure
Old one at that lol, prob 5-6 years old
So i know where the problem lies, but update time is so boring because of it lol
is just me or THM is having some problems? any time I try to connect or im doing a box, the machine be going extra slow
Honestly, L.
Sadly dont have the money for quick upgrade, as priorities lie elsewhere for the things i earn atm haha
Eyyyy, izz meeee. 
Honestly I saw that and immediately thought why it looked so familiar lmfao
Hahaha
How do you define a cybersecurity framework?
Context?
weak sauce
My old college IT guy used to change passwords to 'forgetful' if you needed a change 😛
It’s because of Windows’ password expiry
I have to change my password every now and then but because I don’t ever use the lab I forget it
Yeah it happens.
Lab... sits there 
yo guys
im searching a youtuber
for ccna Switching, Routing, and Wireless Essentials
ccna2
anyone recommends one?
You discovered that the login page allows an unlimited number of login attempts without trying to slow down the user or lock the account. What is the category of this security risk?
need help plz
Is this for a THM room? #room-hints or #room-help
if this isn't for a THM room, I'd look at OWASP top 10 https://owasp.org/www-project-top-ten/
I don't know if he is a youtuber but Neil Anderson has a good course on Udemy
Morning! 
you again... 🙂
ill check it out, im already taking the cisco thing in uni, i finished ccna1, we did half of ccna2 so far and then we got ccna3 left
field in hacking without networking
You're looking for a field within networking without having to do networking?
Networking is the basics of how everything talks together, if they can't talk together how can you hack it?
Tryhackme!
N ▵ N = Ø
You need to understand TCP/IP and the other protocols in the stack. You need to know what IP addresses are and why every machine needs their own ones, what ports are and what protocols typically use what ports, and what applications use those protocols. You need to know lots more about how networks connect and talk and how networks can be used to facilitate and prevent communication in various ways
Speaking of networking, just finished the interview I had an hour ago, went really well and they seem really interested
This is all about topics are use in hacking networking
You can search for networking rooms on THM but there's also courses like Network+ and CCNA
https://tryhackme.com/hacktivities?tab=search&page=1&free=all&order=most-popular&difficulty=all&type=all&searchTxt=network
Oh, they edited their message, now my joke does not work anymore…
David Bombal is a good person to watch for networking
People who do hacking/pentesting need to know lots about networks and systems engineering and administration, operating systems, software and how it all works together
ok I try Hard
By
Wait
Can you make a List for Me to do networking stuff for hacking field
Take Your Time
No one is the same, we don't know what you know and what you need to learn, so research is key
CCT can cover the basics, it's free to learn at Cisco Netacad and it's pretty expanded, you can then choose to do CCNA if you'd like
ohhhh
@proven quartz this was the thing I was talking about ^^
No, you‘re probably just shy.
But nothing keeps you from just staying inside.
¯_(ツ)_/¯
Ooh! That's awesome! You found out a bit more about what they're up to?
Do you guys think 16 GB RAM is enough to run 2 VMs at once?
Yeah, it's really cool!
Yep
Plenty, I ran 4 VMs on that at the same time before, depends on the VMs but 4gb ram is enough
(Linux is 2gb enough)
Id like to run one Windows and one Kali so i can pentest the windows using the kali
Seems like somewhere you'd like to get stuck into then?
Alright thanks
Gave +1 Rep to @chilly veldt (current: #7 - 811)
8 is not mandatory
Yeah! Plenty of learning on top of it, and moving around internally
The role is basically a direct upgrade from my current
Sounds like a great opportunity and a step up in a lot of ways
I know, but just an easy number to throw at it
just a noobie question, can i make a exploit in msfconsole or msfvenom and save it externally to execute it manually via server
and not use the default process through msf
I'm looking for the cheapest laptop that can smoothly run 1 Windows VM and 1 Kali VM
Any idea how what specs I should aim for?
Yeah, seems like they are really interested in me too, they got some more of my contact information and is taking contract and salary internally now
That's really cool! I hope you'll be heading that way really soon then 🙂
Thank you! Now to talk with my current part time job about the change😅😅
(I'll first do that when I have a contract in hand)
you can still have lockdown for yourself
Metasploit is a tool for developing and executing exploit code. It's quite normal to use exploit code without using metasploit when exploiting a vulnerability. You should check out the Metasploit content in THM
Can a Free version of Windows VMs have the latest updates so you can try to bypass the latest Windows Defender?
Or do I have to pay to have the fully patched Windows in the VM?
on tht only, but wanted to know how to export the created exploit
😄 Yeah the change will be good for you and your current job will just have to fill in when you've departed 🙂
It should have the latest updates still, but not some features
Yeah, plus I am not mandated that I have to sit in the office to work😅
But I'll probably work March out at my current job and then leave, if the contract is signed by then
Microsoft releases ISOs you can use for testing but I think they only get critical updates and there may be a time limit on usability. If you're going to use it long term, you'll need to get a licence
Bwehhhh, I have to cook when I come home
Yeah it's great if you can work from home to get things done. Would make it more comfortable and easier
There are free windows vms? I thought you need to license everything
So how do I practice bypassing the latest Windows security systems?
Do I get a license for my VM?
I just had last night's leftover pizza but I defrosted some chicken the other day I think I need to cook tonight or it will go off
Yeah, I have to cook it today
Have to make 2 weeks worth of honey sesame chicken
Yup, it's a nice role
Plus I get all the training and certs I need, meaning I'll probably go through all Microsoft cloud certs😅😅
Oh I love that stuff! Such a tasty meal!
Ooh sounds like you'll be keeping busy 😛 You'll be the local expert 🙂
Everyone else also has them, so just gotta join the ranks 🤣
hey
👋
You'll fit right in so 😛
Heya
Yeah, everyone else there is all technical and doesn't really have that practical knowledge of low level SOC stuff which is where I come in
Plus my friend works in another department
So you'll be able to teach them a thing or two 🙂
Well typically you should get a licence for any software you intend using long term. Or you could use the cloud and practice in there, as long as you comply with the provider's terms
Yeah, I'll be helping in training some of the new people later on
And then sending them off on BTL training sessions to make sure they're doing things how you like em 😄
Who knows
Hello
Setting the standards in the place 🙂
BROS
Let's see now, it's waiting time
Til then, back to the hack 😛
This is the Discord for Try Hack Me, which teaches ethical hacking and cybersecurity
Back to making food* 🤣
And probably work out
Who am I kidding, I am too tired for that
Food and then relax
Have you learned any haking from here
😛 good options, but yeah get fed and take it easy 😛
You can learn ethical hacking. Go to #start-here to get started
what food you making
Yeah, need to make all my chicken into honey sesame chicken and then make 5 portions of rice
nice
Sounds like lots of fun! I do love to cook. Got a 16 inch pizza last night though so working through it
But before I have to make food, I have to clean my whole kitchen
is that chicken in fridge?
you know, the frozen one that is dead... 🙂
Yeah, I bought me 3.2kg of chicken breast at the start of February, and been slowly working on that, and this is the rest that is left now
Yup, threw it in the fridge when I decided not to make food yesterday
Oh cool! Normally I use a 340g portion of chicken breast each time I stir-fry, usually some peppers/onions and other veg and spices if I have them
Occasionally more, like 500 or so
Nice! Yeah, been using 1.9kg the last 2 weeks, so I have 1.3kg left, which will easily go into that mixture nicely and hold for 2 weeks
I do portions of like 80-100g chicken per portion
Might want to pull out my wok for this chicken today due to the amount
Yeah I usually manage 3 biggish plates with rice or pasta when I'm cooking something. It's coming into lamb season so there'll be lots of fresh lamb in the local butchers. Will be making spicy madras curries
Sounds amazing
And yeah I always use the wok and high heat, cos you never know what you'll need to get in there 😛
Yeah, sadly it's a flat bottomed wok, so I can't use it that well on open fire stoves 😦
Yeah I have an electric stove but would love a gas one. And a round bottom wok. I love making big meals that way; check #873642346762350592 for more of my work 😛
Same, and will do!
Chicken breast is the best when you brine it beforehand. Makes it come out so juicy no matter what you do with it after
I don't generally add salt to my food
Oh yeah, my speakers arrived today
Only from chip shops, I have salt.
I add salt if the recipe says so
i had the dryest chicken breast earlier
overcooked it
infact it was slightly burnt
Yuk
I love to change and play with recipes 🙂 I learned to cook by figuring it out myself as a kid when the parents were out working
Pretty sure I'd be pretty terrible at baking a cake though 😛
Yall ever feel like you wanna do something but don't know what to do?
Instant pot is where it's at. I use mine all the time everything cooks so fast and I always make enough for a few lunches or dinners
hullo
🦗
I know exactly what I should be doing, but shortly after I somehow find myself here or in the pub 😛
What’s your go too drink
I'm sitting here, wanting to go out driving for the fun of it, but don't know where to go, or what to do
Some kinda beer or whiskey depending on the mood
a weird gif
All roads lead to Vegas
Yah.... 3 days later
8 hours to Canada was brutal
Try driving that, alone. No one but your music
I had to call some people so I would have someone to chat to XD
less distractions
Besides my music at max volume XD
Less visual distractions I should say then
Ok, gonna rewatch the defcon documentary later in the week
I do that too when I don't focus on my micronutrients
You coming to DC32?
From a classic movie.
And due to my weight-loss journey I am really focused on what I eat
It's very important to get all those in 🙂
Definitely gonna try. It's been kicked out of Caesars though
Yes man
Yah, sad, dunno why. But Sadge
You going to pre reg? Or linecon?
I'm going to getajobcon, hopefully before the local bsides 😛
Yaaaaaaah, I need to join you at getajobcon
Well I'm gonna hit my course pretty heavy the next few weeks and really try get the cert
Anti corruption bureau using the justice fund to buy spyware to use against political enemies 😭😭😭
Well I have years of experience, just also years of not working and having fun/studying
oo I think I watched that one
where hes a lawyer right
that was a long long long time ago I watched that
I have months of not working, but still "working" with IT shtuff
Have worked in cybersec before and have plenty of connections. I just want to get my cert done. So much work in it 😛
A lil sad malwarebytes isn't detecting anything atm
That reminds me: https://www.youtube.com/watch?v=lOHw_tJe7fs
Canada plans to ban hacking devices along the lines of the Flipper Zero in order to prevent… car thefts?
Watch the full WAN Show: https://www.youtube.com/watch?v=-SLaZd2f_mI&list=PL8mG-RkN2uTw7PhlnAr4pZZz2QubIbujH&index=1
► GET MERCH: https://lttstore.com
► GET EXCLUSIVE CONTENT ON FLOATPLANE: https://lmg.gg/lttfloatplane
► SPONSORS, AFFILIATE...
oh yeah i heard of that, didnt look into it tho, lemme see this vid
There's a good nickname for it also: The tiktok stupidity ban
Leading theory is that the canadian's saw tiktok's which showed flippers unlocking cars
had to replay those first few seconds to make sure i didnt forget english
still no clue what he said
I've worked in Desktop Support/ Technician before, no info sec. But got connections waaaaaay up in C level territory. Hell. I have a 2 reference letters, one from CFO, one from CEO
I'll be careful what I say about car hacking, but the attacks that the flipper can do have been mitigated for a long time on car keys
You can also use cheaper hardware to do the same thing better
All the flipper does is make a pretty UI
Flipper can't even handle it though, unless you use other equipment to block the key fob signal, and shit, that whole "Flipper zero bad" is a joke
Connections are the most important thing you can go with
Linus even brought up the Kia Brothers thing...... like that was on Kia for not having basic security implemented in their cars
It had NOTHING to do with Flipper capabilities
Ooooooh yah
The radio module, the CC1101, they're stupid cheap
Some French politician in Canada
although a lil thing that we have in third world countries, just stealing the keys
its quite common
yea
I think Linus brought up a point in the way the law was written, it basically was like "Yah, so we ban phones, and laptops now?"
This is why you should fight for technology representation in your legislative bodies
Right to Repair!
oh 😭
Yesterday, the White House convened a roundtable with federal and state officials, small business owners, and private sector leaders to discuss the importance of the right to repair. In the simplest terms, the right to repair is the right to fix something you own when it breaks—either by yourself or by taking it to an…
Cool
I am trying to finish Linux Fundamentals step 3
However on the log part where it has me trying to access apache2 logs
its encrypted in yellow
I dont think its supposed to be..
no permissions granted everytime i try to interact with log
#room-help might be better place
So your fingerprints can be recreated from the sound you make swiping a screen
https://www.independent.co.uk/tech/fingerprint-clone-hack-security-printlistener-b2499111.html
And the paper is free here
https://www.ndss-symposium.org/ndss-paper/printlistener-uncovering-the-vulnerability-of-fingerprint-authentication-via-the-finger-friction-sound/
I mean tech is gettng crazy
every day gets more dystopian
It's natural evolution
It's only dystopian if we abuse it or fail to advance as a species/culture.
Which luckily humans never have done
Welcome, I want to study the basics of operating systems course. What is the best course you recommend to me??👍🏻

On YouTube
As in how an OS works? Specific OS like Windows/Linux?
It all obeys the laws of physics. Stay off the internet, go to the pub
That used to be what I did, until I took a medication prescription to the knee that makes drinking not wise.
hhh
Sorry for your troubles
😎
FreeCodeCamps Linux Introduction course is a very solid one.
No, nobody said that. I've never seen an Arch user who looked like that either

Free ?
FreeCodeCamp is a site/youtube channel, they have an intro course for Linux. "Free" is just part of their name.
THM has a solid Linux portion as well, but it's not going to go as in depth
Primes you for the next steps
There's tonnes of free Linux tutorials on the internet. There's even free Linux tutorials on Try Hack Me https://tryhackme.com/hacktivities?tab=search&page=1&free=free&order=most-popular&difficulty=all&type=all&searchTxt=linux
I love the term hacktivities
Can I learn and become a professional in Linux without paying?
Almost tempted to explain that 'hacktivities' is a portmanteau of 'hack' and 'activities', but I wouldn't do that 😛
cs162, many free lectures online too
You can reach the level of a professional for free quite easily. To break into it it really depends on what you mean. Working in IT as helpdesk? Working in a NOC? There are simple certs as well for it.
linux basics for hackers, short book. Find it as a pdf for free online
Professional in Linux is honestly just being a professional digital librarian from the era of the Dewey Decimal System.
or just try and install gentoo,
Primes you for the next stepsCan you send it to me, brother? Thank you
Gave +1 Rep to @wintry garnet (current: #2000 - 1)
internet is big place. lot's of free resource.
send the book?
Google my man
You’re aware that’s piracy right?
No one here going to send you anything paid for free lol
🫡
Just google learn linux
😲
Honestly not. Linux is quite a modern os, it's the most widely deployed operating system on two planets in the solar system
whats linux?
videos in YT and so are nice source. since show you command and results that you might expect

100%, however it's still functional as a tiered system of logic
As opposed to M$ or Mac

@wintry garnet has been warned.
a BSD clone
😲
Oh dang. It got real here
but for the best learning hands on experience by using it in a vm or on baremetal is the best

I am just a beginner in operating systems and I want to get into cybersecurity. Should I learn Windows or should I focus more on Linux?
would recommend linux mint for that
Both.
After you've done all the Linux rooms on THM, you can do OverTheWire
To me, some people say that Windows is important
you can hear on my new speakers that it's really cheap plastic ones, but I don't mind 😄
We provide basic training to users who are new to the field, check it out

You can learn pretty much all of that on THM though. It's cheap to sub honestly.
booo poor quality speakers...... booo
You should learn both. You need a good grasp of Windows, Linux, Networks and other technologies you'll learn as you progress
shadow wanna have best audio quality possible for the price of under 300 usd
Wait till you realize how many different network hardwares you will end up learning besides Cisco.
I needed just something that I could have so I could hear what my coworkers says in meetings when I work from home or just have a random youtube video playing
Wait does THM have vender specefics. I never checked
No they dont
But that makes sense
Avoids uh...inter-company issues
Just enjoy it.
It's not a race. If you enjoy it you will be passionate about it, and that shows when you actually try to get into the field
That rule applies to any field
i really liked the uploadvulns thingy it was fun
But Arch is love, Arch is life!
I use Arch btw.
So nice to connect my flipper to my laptop, clean up some non working apps and updating the firmare
You can have whatever os you like 🙂 I do love my Linux Mint, even though I've been using Linux since the 90s
shadow loves their current install of endeavour os
but that is maybe not the best place to start your linux journey
I love my Arch, using Win11 right now, because things, but when I need to work on my servers, or just general things, Arch.
Might have to try it sometime
Mint is always solid.
It's the one I recommend to people if they have a less than tech capable family memeber that needs their systems wiped and they can't afford windows.
It's honestly perfect for normal use
Nowhere near as resource heavy as Ubuntu
Not really. Metasploit exploits are Ruby files that have to be saved into Metasploit's exploits/ directory to be then be ran via msfconsole. You don't develop exploits in msfconsole, you write them using a text editor. You can find plenty of PoC exploits that are standalone Python/Ruby/whatever scripts or C/Go/Rust/whatever program that you compile on GitHub or exploit-db.com. If you want something that is in between a standalone PoC script and a full blown exploit framework, checkout ronin-exploits. It can generate boilerplate exploit files that can be ran as executable scripts (ex ./myexploit.rb -p host=.... -p port=...); so long as ronin-exploits is installed.
It works on my hardware (mostly) and I get to play with other distros in VMs
anyone from india having cyberecurity related whatsapp groups??
can you please share the links!
Or from anywhere from the world just needs to be in english
it is an arch based distro that is nearly vanilla arch.... there is just a single added none arch repo that has some helpful scripts and programs to make the experience more smooth
also graphical installer
Man so many Indians in here, it's a great place to be considering I'm there in 6 weeks lol
Get some travel tips!
Taking my Indian wife as a guide. I am 100% bringing flannel shirts, blue jeans, and a cowboy hat to ham it up in the small towns.
Sounds interesting for sure
🤝 
I broke Linux Mint, VERY easily. So not going back to it
you'll get along with beerise famously
Everything is in God's hands, brother
https://youtube.com/playlist?list=PLBlnK6fEyqRiVhbXDGLXDk_OQAeuVcp2O&si=qNEPC4d7OMMNExkh . What do you think of this course?
You'd blue screen a tea spoon when stirring tea
I think I broke my SMB share...
Yup, I did
Priceless. You're hired.
Fixed it. Turned it off and on again 
@boreal scarabCan u recreate ur breaking skills
I touch, it breaks
Now a days when I break stuff now I figure out what causes it
he wish. even he don't know how he doing it lol
yk there's a actual job for it
sometimes happens to me
just hope he will never drive a place
always works! (except when it doesn't)
but hey it always works
I still hate Microsoft XD
2 more arrests, this is fun.
TF you do?
For a second I thought Microsoft had released their own variant of Adobe XD and i was very confused
Sadly, nothing.
I'm refering to Operation Cronos.
ooh
Screw Adobe, Use Gimp, or PDFGear
FOSS all the way! (PDFGear is not open source, just free)
Figma
That's a name....
Gimp isn't really a good replacement for Adobe XD
I'm unaware of a good FOSS variant of figma
I was about to say, thats looks paid
it used to be free..before they got bought
still free but with limited functionality :/
this link that is on "walking the application" on tryhackme, does it still work for anyone, it doesn't work for me. this is the link https://lab_web_url.p.thmlabs.com/
You need to start the machine.
it always show error
If you need further support, please use #site-support and somebody will assist you.
even when I start the machine, it doesn't work. my daily subscription is finished now but if I try tomorrow it will still show the same thing
The URL won't work in the attackbox, as that's a public facing URL.
thank you
Gave +1 Rep to @sick lance (current: #2 - 1986)
question why is the extend time thingy not worky for me and why cant i get a new ip or restart the target without loging out and in again?
I don't use it on the attack box. I use it on my browser
If you started the correct machine, it would have updated.
The correct machine is a green start machine button, not the attackbox.
The attackbox is a seperate machine 🙂
You know you start the attackbox then start the machine. I did that the timer started, I was given an IP. I waited 2 minutes and same thing. I even tried using my VMware but it's still same issue
Glass of wine, contemplating my life choices over Discord, lovely day
it works for me i just went there
I've just tried it and it deploys for me just fine and can access the URL from my Kali VM using the VPN and from the AttackBox. The URL changed to one with the IP of the target as follows within seconds of the machine getting an IP address:
https://10-10-48-148.p.thmlabs.com
After two minutes if the URL hasn't changed then try a refresh
hmem its worky
Make sure you're not going to the https version of the site
always
Anybody got a room with HTTP verb tampering
@shell nova or @mossy river
getting a itch reading this but knowing its against rules can't talk a lot about it arghh
i just look
@sick delta has been warned.
thank you james
That's an old attack
been doing a few Portswigger lab's and kinda like it
Don't have any in mind, unfortunately
yea searched across THM barely any
There was one exercise on rootme if memory serves
feel free to make one
I think rootme had a
swear to god man, if u ever need help from an admin from tryhackme just forget about it
???
dudes are so stupid that is not worth spending any time here
just go to freakin google or somethin
im removing my positive review of this platform after this fontaene ahole
treat me like crap
fuck this man
im out
What happened @royal whale
:mute: renozion#0 has been muted.
😅
that was awkward
They were even more awkward in my DM's
also scrubz... shadow still not got their drop
Oaft.
ooh YAY finally got the last common drop from the quest that was not a dupe
that took a long time for some weird whacko reason
now only the rare drop left
0x8 😎
welcome to the named levels
Thank you lol
Same one as yesterday?
same quest as yesterday and the day before yes
have done around 100 runs now and the drop rate of the rare is probably around 1%
What game?
dragonfable
Nice, looks cool
it is fun and has a very good story
Do you make notes when completing rooms?
most of the time yes
What kind of notes, the ones that explain differences and other stuff or commonly used commands?
method
order of commands
details of what the room is explaining if an info room
Is making notes digitally safe tho
How do you mean?
For example, to be sued lol or to have my account suspended. Some things like that?
Account suspended unlikely, but possible. Host your own notes.
Sued? Why would you get sued?
But since everything is for the purpose of testing and ethical training, I guess nothing will happen.
Maybe they’ll think that what I am doing is dangerous
¯_(ツ)_/¯
depends on where and how you store the notes
for example with trilium notes as the app you will have your notes basically only on your machine... unless you rent a vps and setup a backup to said vps which shadow does
I’ll use Notion. And write things that bothered me and a brief description of the program, what it does and its purpose. With some example commands
Writing on paper is gonna take a lot of time
What does it mean?
As safe as you want to make it?
Paper notes are traditionally considered one of cyber securities first line of failures lol. Someone writes down a password or important info and then leaves their notebook somewhere.
in the case of a house fire paper and offline storage is about equal
Hello, is that possible to get a TryHackMe openvpn configuration for TCP 443
In management(not CyberSec related) I always wrote in specialized shorthand because I've had my pad misplaced a few times.
currently NO
I only use truly cold storage anymore for non-important backup. Like a Kamen Rider show or something.
did not mean cold storage only meant offline storage
My country block internet and all UDP port
i.e attached to your computer but not backed up over the internet
sup guys anyone willing to study with me eCTHP i have the course and everything but watin for someone to study with me
So I need an TCP config for TryHackMe
your only option is the attackbox....
The only thing I know is that I am only logging through my own pc or I’ll do live boot. Last time I got hacked bcs of Keylogger
I mostly use the attackbox only. Used to use a pi with kali but I've been moving about too much
I don't like that, coz I have my Kali
Physical keylogger?
Or malware
School pc, friend installed keylogger and I didn’t know
Looks interesting, what kind of pre-existing knowledge is expected?
We can't help you break your country's laws
Intéressant
ejpt ecppt
- am in last bachelor dgree of cybersecurity
Just use the attackbox. It IS Kali and won't lead you into trouble
sadly sometimes, it's not about what we like but what we have available
The problem is that teacher asks us to do things in Google classroom. School didn’t want to make edu mails so we were forced to use our main ones
That's not breaking law. I just need a TCP vpn config instead of UDP
attackbox isn't kali btw
Protonmail, or just a spare gmail my man...
Fair
I have neither, however I have active GDAT, would that be sufficient?
Too heavy to lug around? 😄
I have like 4 proton mails, 3 gmails, 2 outlook(hotmails) lol
@burnt palm has been warned.
No but though the pi is tiny it's cumbersome for all the cabling + peripherals.
I run back an forth between two states lol
I like jus tlogging onto THM and going zoom
Back then I didn’t care but now I do
Do u have the basics of cybersecurity like
python + linux etc ?
Interesting interview from a former NSO employee https://www.youtube.com/watch?v=NC4uzV-syIw&list=PLwoiB_pSA_EiqY30euNBmxoJMj2IoEiUh&index=2&t=716s
An interview with Trust, ex-NSO Group hacker turned web3 bounty hunter and independent security researcher. In just under a year, Trust has rocketed to the top of the code4rena leaderboard, and has made waves on both code4rena and Immunefi.
In this conversation, we delve into Trust's background as an exploit developer at NSO Group, and learn mo...
Then you have grown! It was nothing more than a lesson.
@naive violet ?? 👀 what I did to be warned bro ?
👀
Is there any way to auto remove accounts from mail address on sites that I don’t use anymore?
@burnt palm You asked for help breaking laws. The warning says this.
This isn't up for argument, so I suggest that you stop.
Auto not really. But you can sit down and go through them and just update to a new email + password
dunno, vaske. intersting question though
Periodically doing a checkup on your digital hygeine manually isn't a horrible thing
then anything else is easy
There are, let me try find them
Digital Hygeine - never heard that term before
Sorry, I think you guys just didn't understand my bad english. So forgive me
Ehh, I'm just wondering if companies keep my data when I delete my account
Course they do.
Alright
probably not the emails themselves, but certainly some metadata from the account
So, hey everyone--just hopped over here from reddit. Curious how you all are liking TryHackMe? Seriously considering it for some upskilling for a career pivot--but is this entire group of individuals all 20 somethings? Are there any mid-life adults around? Nothing against the younger folks--truly. Just, looking for my tribe.
90% do, but some offer the option to request it deleted, And you can always manually submit a request to delete it. One of the best things to do is update all your info to incorrect stuff before deleting lol
wanna txt priv ?
To some extent.
If you're in Europe, you can invoke the right to be forgotten
All those ages and more, elizadoo
Sure, hit me up
There are people of various age ranges from young to older
37 bud
I'm old
Legend has it theres even an Irishman here, but I think thats just a scary campfire story
Do they still store mail:user:pass combinations? That is a great idea, let’s just hope they don’t store info before edit

If I sneeze too hard I fart and make my knees hurt
FWIW I didn't finish my Bachelor's in CompSci until I was into my 30s, and I didn't get my first job in Cybersecurity until I was almost 40.
You shouldn't be reusing passwords anyways
in europe you have:
the right to be forgotten
GDPR
gdpr can be used to find out exactly all the data a company has on you
and also generally helps with the right to be forgotten if you want said data removed
not old at 37! I'm 44. but THANK you for raising your hand--I'm so old school I walked uphill both way in the snow...
Gave +1 Rep to @bitter quiver (current: #2000 - 1)
Most sites don't store passwords
I made sesame chicken 
turns on Hollywood Irish OOh look at mee!! I'm a leprechaun! turns on regular Irish accent not really, I'd never wear a green suit 😛 And I have no lucky charms
but it is smarter to not get you data deleted if in europe get the data deactivated like an active directory user
My life in the physical labor markets before I got into offices added 10 years to my actual age 
It would be great if, for example, there was a site where you enter your email address and you can see which sites you have account on
Think about the potential for abuse.
fair. I've been in energy for a while now and te poor bastards out in the field are SUFFERING by 37
Yes, that makes sense too :/
I would not want that, in general. Think about all the data that would have be shared and available from all services for that to be a thing.
James - EMF kinda clashes 😦 I have an event the weekend after, So 2 weekends in a row is pushing it for me
Boo
It's every two years
Fingers crossed for 2026
reason beeing is.. they could claim to have gotten your info from somewhere else after the deleting again and can send you commercial stuff if you get it deactivated they are done.
Torn meniscus surgery in one knee, tendinitis in both achillese tendons from my 20s, torn UCL right thumb, several tears in my left thumb currently actually. Frozen shoulder at one point, spine rotated 180 degrees from a sports accident late 20s. etc, etc, etc.
Tylenol, Ice, and Ethical Hacking. My new Podcast.
Last batch of tickets goes up at 9pm today
this one is paid though https://joindeleteme.com/?utm_source=influencer&utm_campaign=DD20&coupon=DD20, there is another one with a free offer, but need to remember what it's called
I have a problem that this is a very old email and when I was younger I logged in everywhere and left information. I should start cleaning it all up because my main mail is too full of nonsense
They actually have to demonstrate in court that they did reacquire that information through purchasing or other agreements, once you've made the request
are you going as a group with people, or solo mission, James?
I've contemplated one of those erasure companies but wasn't there a situation where someone working for them blackmailed a person?
Or is that just fanfic in myhead
Who said I was going? 👀
I'd listen to that podcast
It was an assumption - Just the radio stuff alone 😄
Didn't know you were that old Juun 
Maybe this one?
Age is just how refined we are. Life is one long process of mental fermintation
kek, i wasn't the oldest person at the table for lunch, but it was close
Juun was around when THM was a BBS 😄
Ouch
kek
Low blow
I actually used the BBS system back in the day
Never heard of this one
yeah.. after you showed proof that you requested it... and then they and then.. sounds like a lot of work time and maybe money. i am sure most will delete it because if they fail to do so in the first place they get problems hmem
on a 9600baud modem
It's ok, Cipher - I'm 41. In the old-folks club 😄
Back in my day mom had to write down the command to navigate MS-DOS to launch my games by command line. And we had no mouse
Mostly if it's a CA identity or GDPR issue, yeah. But there are companies that explicitly don't do business in those regions specifically so they can avoid the law
I was that age when I dun got my cataract surgery 😛
I need to get my modem going
Cipher - Pretty much. First computer I used was a Commodre64
true
one of my younger nephews asked me what a modem was used for - which lead to a fun discussion of baud vs bps and why overhead counts against bandwidth
Does anyone here have experience in reporting a word-press plugin vulnerability?, if so
Which Partner I should report the vulnerability to.
Biggest thing I've learned... don't be in a rush to grow up. I've had any amount of DMs from folk asking how to get in the workplace at 14 and 15... It's like.. Cmon. Enjoy your youth! Work sucks!
I missed that era mostly. I love watching 8-Bit Guy and RetroRecipes for that content though
I like modems thanks to RF stuff.
Lots of modulation involved
Gave +1 Rep to @whole yew (current: #10 - 731)
Same reason I enjoy playing Comet 64



