#general
1 messages ยท Page 47 of 1
It worked
Sweet :D
Awesome dude, yeah I always enjoy getting to know more people in the space
Always great to find like-minded folk 
Yeah and idk if this is the case for you but, locally, so hard to find anyone
that's likeminded
at least, the tech peeps like to hide
Yeaaaa, thatโs where uni has helped a shit ton. Iโve networked a whole lot through it. Especially since working there, I make friends from people in all years and even staff ๐
Oh yeah I can imagine
best part about being back to school is being allowed to sit in the nice cold datacenter and just relax while setting up infrastructure
There's a local uni nearby me that I don't attend, but I casually joined their cyber club discord lol, they were friendly.
Ooo that sounds nice
it really is
Hell yeah. They got a cyber clinic you could attend or nah?
just hardstyle in your headphones, aircon above you and commands in your terminal
Also day, just realised how sick your username is. The payloads one :o
Air cooled students 
Not even water cooled smh
See, Idk since I don't necessarily have anything affiliated to them. If I work there, I get education free. My brother in law works there and his brother. They're also friends with the sysadmin so, I definitely have connections. But their hiring has been messy it sounds like, internally
I called about an application and they said they got it, I applied 3 months ago lol
no update. just in the void I guess
Free education is one hell of a bonus. For the certifications more than anything - pretty sure most university content sucks ass and is as dated as ec council ๐
Damn man, thereโs places to be filled tho?
Yeah that's the only thing that's keeping me away from the WGU idea but, I figure WGU would probably cost $4k or so max
Yeah the sysadmin told me they're always hiring apparently
and we're friends now so he's in my interest for getting something, they bring it up a lot
There is an opening in the VAPT domain, if anyone is interested they can go through this post.
Interesting
@silver rampart Please don't self promote here
I wonder why linkedin GET requests urls include device type when sharing from master device
If itโs accessible to any device
I sort of have a moral code to not pursue jobs from recruiters based in India
I am not promoting myself there is an opening in my organisation, so I am just informing everyone, if anyone is interested then it will be helpful for them
If you would like to post job openings, you will need the recruiter role. Please email jan@tryhackme.com from your company email to receive this role.
What you posted was directly to a LinkedIn post you made, not an official job posting 
Isn't that the definition of a promotion ๐
Do you guys prefer attack box or normal kali?
hi is 0xB master high ranks guys ?
my friend got it so uh
i don't frequenly use tryhackme soidk
Do all wifi adapters look like spiders? Is that normal?
I need more motivation.
Is there any reason why not?
I prefer my own Kali, as it'd set up for my convenience.
Howe I do use the attackbox now and then.
Not sure if the original user is referring to a VM or the site Kali Linux
I have my kali set up with vagrant with a share on the host for persistent files and ansible to provision
But I'm probably not entirely sane
I had a look at Vagrant, might need to set that up to give it a bash
Lagging can be a ton of reasons
It usually not the machine itself, might be your connection
Probably their network tbh
But it's still a UX issue, even if it's not directly thm's fault
Hm?
It has its uses, notably for corporate networks where a VPN won't be allowed
Or certain countries where VPNs are difficult
Or for those who want a decent experience out of the box without having to set up their machine
Users who donโt have a good enough machine to do CTFs, users who canโt use a VM (using host is not recommended), itโs great for users who are on the go and donโt have a dedicated machine, it also comes prepared with all the tools and room requirements
Or want to try before they commit
I mean the persistence is the only real downside tbh
VPN connection only. Tried attackbox a couple of times and has been more of an inconvenience than anything personally haha
Tend to run a lot of CTFโs through my exegol docker anyways now so vpn is a must
You should be able to ssh into the attackbox as well if the web UI is an issue
Over the VPN though
So yeah ok strike that
Good to know, thanks for that
Gave +1 Rep to @shell nova (current: #12 - 548)
Still useful info
Any reason?
This is purely me trying to understand why, thereโs no wrong answers ๐
Reason against attackbox or for using exegol?
AttackBox
WebUI just seems slow. Possibly my own connection during the times Iโd tried it. But just find it as another vector to rely on working right - when i could just vpn in and work in a standalone environment. Plus, any tools or docs I pick up from a box are persistent. Building my methodology and toolkit :)
I know how we can fix the webui being slow part
All in all, seems to be added steps to my usual testing
Iโll pass on the feedback, danke
Great to hear! Danke shoen
Bitte
Am I having a stroke?
Yes
Precisely
Oh good, I thought I was gonna live.
Whatโs going on
Stress mainly.
A significant amount of work stress.
Not sure if Iโm allowed to discuss it externally but youโll likely see it on the website
probation finishes in 2 days.
Last stretch ๐ช
or 3.
Glhfdd
GL.
dd ๐ญ
significantly, especially considering my work load as I have taken tech coordinator, as well as support for my job
Ugh I don't like coordination jobs
There's only me, and one other person who do it
For the whole of Australia for the company I work for..
it ain't the best.
Wow. Praises for keeping your head attached so far
Off topic, did your username used to be Bob?
Some of the days can be 10-11 hours long.. then depending on the technician we have..
No Jabba, it was always unreal.
Unreal Bob?
Blob.
Aaaah okay

Thatโs makes sense
Thought I was going to be crazy
No, no its me, not you.
Blobby helped me a lot when i was starting out
@near hawk hi mind if I DM
The CM?
Hey I don't know if I need to ask or not this question
I lost my WhatsApp data completely i have an iPhone can I take backup is there any guidance
They moved somewhere and just disappeared.
if you have an icloud, you might be able to back it up from there?
You can only backup before you lose access to the data
guess it depends.
How to find the ip address of a website?
Thereโs a native function within WhatsApp to backup to iCloud if you can still see the data
Why
I'm curious about it
I don't have much idea about it could you please guide me
don't even need a DNS.
Yes, this is what I mean
there's many ways to find out the IP of a website.
What for though
For example, I can access amazon through this link: https://amazon.com, but what would be the ip address of amazon?
that's the whole point of DNS's..
But I've learnt that behind every url, there is actually an ip address
not necessarily.
Correct, but most services don't expose the real IP address for security reasons
So there is no way to get it?
Of course, but you're a level 1, I'm not telling you how
@lethal fog
I got to where I am by studying, you need to research.
@lethal fog Sprechen sie Detusch?
Please donโt help them right after I told them theyโre not getting help sigh
Yes, I do. Where would you know that from?
Ah man, Offspring puts me in the best mood.
I wish I could be in this mood all the time.
but nooooo.
What did I even do, so that you claim these?
You were trying to attack machines on a network
You can influence your mood through listening to specific music when you are feeling a certain way ๐
When you're happy, listen to one playlist.
When you are sad, listen to a different one.
When you are sad, listen to the happy playlist
No, I wanted to figure out how to sniff my own home network. In addition to that, I do not even belong a wifi adapter, which lets me get all the devices ...
well, I need to do this at work.
you know the router that you're connected to, did that come from your internet service provider?
I don't really have any public playlists on spotify atm, music is in shambles
Yes, obviously
Are you aware that you are actually renting that piece of hardware and you don't actually own it
Gave +1 Rep to @mossy river (current: #6 - 1174)
Which means anything you do on that router may be in violation of your ISP's terms of service
Yes, for sure
Blacklisted from receiving points
And even worse, it could violate some laws.
But there are all these ethical hacking videos on YouTube about sniffing the own network...
If your friend told you to jump off a cliff, would you?
Don't trust everything you see on the internet, they are not responsible for your actions, you are.
In court you can't turn around and say well he did it
What specific network can I sniff then?
Buy your own router, set it up, connect devices you own to it
What do you mean with own router? Do you have any examples?
Would I have to pay monthly fees for it?
No
And why wouldn't have anyone this kind of router?
What are advantages and disadvantages of choosing this kind of router?
"Just because you can, doesn't mean you should."
Not committing crimes?
You don't need to connect it to a WAN
Just have your own local area network you hack on
Do you have such a router?
Yes
Might need to verify.
Still talking about this, Puv? Wow. You know, if you'd spent the last couple of days learning the fundamentals instead of laser focusing on 'hacking your own network' you'd likely know all this by now.
I mean, I have my own WLAN equipment because the ISP's router is terrible and can't reach beyond the wall
My isp router isn't terrible, my connection to the house on the other hand....
Oh I have fibre
You also have a slower typing speed than me ๐
We have virgin media business and itโs amazing
Me too.
Still can't get past 50 mbps
Shoved a cable to a switch in the office and get 1 gbps
Where I live we have the choice of 2 isps ๐ฆ
Well I have the choice of...2 if I want fibre, and dsl sucks
I get around 90 odd at home. Had maybe... 4 outages in the last 5 years. All but one were sorted in an hour though.
Iโve the router running into a switch and then into two APs at either end of the house
Yeah I have 3 repeaters
So all that data flows through you personally?
Unify APs here
I'm not that rich
You're still on cooldown
i ate kids
Just gotta wait a bit
Umm, ok?
That was odd
How can I escape here without terminating the entire process?
Google it.
It's weird how so many aspects of our identity are reduces to a mere string of numbers. Phone number, Bank account, national ID, membership numbers
massage your keyboard
@drowsy spade If you're going to troll, please leave
I did, it told me Ctrl + C, which is wrong
what's trolling ๐ฆ
i just say weird stuff sometimes
that's all
I copied and pasted your question and found the answer 
i have posted a question in room-help
@coral dagger
Please keep discussion relevant to the channel topic.
/rule
excuse me
I couldn't find it
Trying to get people to go to the channel you just posted in is impatient. Most helpers are volunteers ๐
id it weird? all those things need to be unique but easily accessible
hiya
You guys are not being helpful. Whenever, I ask something, people respond withgoogle it!
hru
gm
We're only saying it to you because you aren't Googling easy questions.
everyone
gmmm
I googled, but nothing worked for me so far, which is why I come for help
even though it's officially afternoon my time lol
thanks lol
Gave +1 Rep to @coral dagger (current: #2009 - 1)
This is obviously not what I'm looking for:
good just working on a project but my remote desktop isnt turning on for some reason LOL
give a man a fish and he will eat for a day. teach him to fish and he will leave you alone
the answer is literally in the title of that post
ctrl+z
kerr blackhole
what does this do @_@
Puvude - Honestly thats what we do. Most of us always have some sort of google search on the go. Plus, the questions you are asking are kinda basic. Not saying they're not important but if you followed the advice already given multiple times and start learning at the basics, you wouldnt have these questions
windows โ ๏ธ
url
so am i gucci or what
ive been meaning to swap to linux but yeah ๐ตโ๐ซ
belanciaga
I typed Ctrl + Z and it didn't work for me
Sunflower - Try it out inside a VM. There is a learning curve, but with the likes of Ubuntu, it's not steep at all
you have to press not type
sweet
Step 1 Google
Step 2 read google results
Step 3 rethink your google query
Step 4 ask here ๐
so are we answering questions in here if we got
i wiped my code and it didn't come back with ctrl+z
now im thrown
uh
Ctrl+shift+Z
Windows is good because many everyday programs/games are written for it. Love it or hate it, for everyday use, it just works. Some techy folk look down on it because... well, they like to delve into underlying code and stuff which windows doesnt like
G'morning Bella ๐
Please don't help them after I tell them off for not researching
esqy plz save me
oh, sorry, I didn't see that
just arrived in chat ๐
Sending the Domino's Helicopter now for immediate Evac.
I am literally doing this the next 3 weeks 
DomiCopter
Can anyone tell me what I have to do in order to escape the line without interrupting the process?
Ahhh
booty
Well... Update your Packet tracer for a start ๐
we have to do the things on real life devices and not packet tracer ๐
england FelL
Sounds like more fun that way, Bella
To be honest, you should breeze through CCNA
But it does not work
I have already finished CCNA
I could take the exam if I wanted to
Is this just a random lab, or an assignment?
this is the learning material for my next 3 weeks of classes
and that's CCNP not CCNA ๐
Ok, I'm confusing myself now.
It's more like this:
no worries, how can I straighten it up? (won't be of any help, since I ain't straight) 
No, this will terminate everything completely!
Just keep being your fabulous self, I'll work out my confusion
immoral
@mossy river
scary
can we get this money guy outta here? 0 useful contribution to the chat
Application > Social Engineering Tools > social engineering toolkit
i like megumi
Puvude - What are you trying to do now?
scratch that guys heโs cool
:hammer: puvude#0 has been banned.
haha.. Thanks
Gave +1 Rep to @atomic aurora (current: #1002 - 3)
Almost banned you Esqy, luckily I double checked lmfao
do it for the laugh ๐
All part of Bellas evil plan
I do love the SET application though
Haluka - Go to bed, man!
Oh, I though it was 12hrs difference. Damn daylight savings.
jared
Nah, Spring forward, Fall back.
I do have to work tomorrowwwww.. BUTTT I'm really loving the tunes i got going
no, you're wrong Esqy
Hello
Theres a first time for everything ๐
+1 hour in DST.
any good guides to get introduced to linux in general (command line, file structure.. etc)
-1 hour in EST
@graceful thistle i promise it's last one ๐
there's no way dolphin is awake
creative
true...
and if they are, they should definitely be asleep.
its like 3AM there
wait, 2AM?
Thats nice ๐
I'm now getting confused.
Thm has a very good module in their pre security course
yea... she prob sleep for sure
i'm probably gonna go to sleep soon..
but i wanna root a box before i go to sleep.
soooo stop mentioning me so i can focus
@karmic furnace Ok
m
Be careful. Worst case itโs 8 am in the morning you still not root and didnโt sleep. Not that this ever happened to me.
if it's 8AM, I'd be calling work.
Anyone here got advice on intellectual property? Got a tool Iโve developed that has opportunities for funding support through my university - however the IP itself will mean that they maintain rights over the product and a take of inward revenue. Iโm new to this side of stuff so looking for any guidance from anyone that may be a little more experienced. Ty :)
Just wanna make sure I donโt get screwed
Ooh, thats a good one. I'd think maybe Bee, but they've not been around much lately
Do you want to keep the rights of the product?
I think that is out of the option if I use the university, at least partly. However funding support would be a huge help so trying to weigh up the option to make sure my own monetary interests are covered and Iโve at least got an escape clause if its needed
Hey new
cmon >.<
have you seen bilo?
netcat
If you're accepting the funding and giving up your rights to the product, anything you do with the product will be fully owned by them. Nothing you can do about it.
Nope what is it ๐
Which is why I'm asking, do you want to keep the rights of the product?
You also need a contract @spice adder
Get it written, review it with a lawyer
web hacking seems interesting
Uni Is so warm!
Yeah but its full of.... students ๐คข
And it is! THM has a lot of Webhacking content. Look at OWASP top 10 task, and the Juice Shop room.
have you tried it alr?
as a beginner with no prior experience/knowledge would i be able to complete it without banging my head on the wall?
There will be a wall/head interaction regardless.
Only downside.
You'll always bang your head in the wall
Goes with the territory, But THM is designed around going from total beginner to experienced
ouch
Just had a meeting with a supervisor to discuss it further but the details around the IP still seem too vague for my liking - wish for this to go forward but idk how confident i am with the current offering
Hopefully i can get something in writing, danke
Would someone who knows web development be able to learn web hacking quicker?
Understanding the architecture of a web server and its development definitely help
Of course. If you already know a lot of the core conepts and how websites work and deal with info.
i only know http and https

Usually someone who is proficient in web development mostly understands the vulns associated with it
HTML5 and CSS?
I had no prior knowledge of web hacking prior to using THM. Only been doing it 2 weeks, but found the stuff relatively straight forward. When I had problems, I just used the discord search, but you can also ask for help in the learning path channels
These are both protocols, its a start to understanding - but look into actual development frameworks and web server architecture
frameworks such as react/angular/php?
that stuff?
wait, those might be libraries
Yeah, exactly. PHP, NodeJS, etc. In learning, you'll encounter PHP a lot. Focus on doing some THM rooms, you'll build from the ground up
oh ive never touched php
php should burn
33 applicants in 26 mins what is this.
SIte makes it easy
fix the ppl at the help desk
lmao
Customer Service Reps desperate to make the jump to IT as it's touted as the solution to lives problems
I'm better off applying for mid roles
literally. I'm better off applying to mid roles
that normies dont know about
If you already have experience yeah.
Or TIer 2/3
yeah
There's a way start to everything - i have limited php development experience however you build your knowledgebase of identifying vulnerabilities through time. Through practice you get a decent understanding of how they work, even without developing them first hand
I mean my experience isn't traditional helpdesk but I've been the lead audio engineer at a place I volunteer for 4 years and I've slowly got into IT networking stuff
i thought web hacking would be easy, just run a software/npm package and just let the software/package do its thing
Honestly anyone can do IT is my view. So I actually encourage CS reps to transition if they have solid soft skills. The only growth in Customer Service is either management or account management.
but, I can volunteer for 4 years but that doesn't provide for my future :(
start with the Pre security and intro to cybersec paths. both are excellent and provide a good foundation for the other stuff
https://tryhackme.com/path-action/introtocyber/
https://tryhackme.com/path-action/presecurity/
If you have soft skills and transition into IT, you will go far compared to technical folks with n o soft skills
yeah
Blind applicants.
yeah probably, since it's easy apply
go figure
but also advertising $60-65k
Then find out at the interview, its not a position you want.
The job I have now I wasn't qualified for lol. I applied anyways.
Yeah I need to just do that
100%
I get scared but
I don't have a job
If I could volunteer at the organization I'm at forever, I would, but I don't make money

I was hired by THM at 17 ๐ช
The difficulty of pentesting a testing a web server is subjective to the application itself. Sometimes it's as plug and play as you mention but without proper reconnaissance you wont find what exploit you need. Refer to the cyber kill chain; reconnaissance, weaponisation and exploitation etc.
If you interview well you can trump people who look better on paper. And after having done probably over a thousand interviews for hiring folks, I often don't care about degrees or other listed skills as much as I do how they react/respond to specific questions.
Gain the methodology to pentest against web and it becomes easier - much like a lot of things in life :)
I volunteer mostly.
Looking for a summer position.
youve got a great portfolio even though i didnt understand any of the projects
It's not hard to start, thm have great starting content
And fun.
Hehe thank you :) you been on my website?
Gave +1 Rep to @vapid grove (current: #2009 - 1)
yh
Apart from blind sql room 
dont tell me u got my isp, etc.
Haven't done that one yet.
Though I am learning SQL in tandem with Python
Just in case I swing full data science
Since my job has become basically that at work...without the pay
Nah, just all those funny numbers on the back of your card (jk)
I mean it's good to know the manual workings of blind sql but goddammmm it can be awkward
i usually indentify a sql vuln then spin up sqlmap
ayy aight 2 secs
You guys see the new remote drone combat vehicle the U.S. just tested out?
Hackers are going to be legit on the field operatives soon lol
Need to drink coffee so I can spell
ReconnAI is a tool im working on at the minute to integrate AI into the reconnaissance phase of penetration testing. Allows you to perform an automated scan using any tool you'd like then receive an analysis of the findings from AI. All in the terminal - and unix based currently
@vapid grove
It's in a production state, just waiting to finish my dissertation to start any form of release
it's my dissertation project
WOAHHHHH
Imagine as part of pentesting if you perfect that and load it onto a specialized OS on a drone you can just fly on top of your contracted building to test out if they(as they often do) have wifi bleed
And just let it run while you sip a latte
stuub playing 4d chess
some words here still arent on my dictionary
thats a scope of the product i had never thought of ๐คฃ flying reconnai - i like it
recon with ai sounds brutal already
flying recon ai 

I've been playing mostly with drone concepts myself. Specifically long term information gathering/slow processes using solar recharge and low drain components. Also playing with the same tech for snake cams to see if you could push a cable through a vent.
Got a lil demo of it i used for investors if you guys are interested in hearing my voice 
Thats pretty dope man - you got any prototypes in the working? Using existing tools or building your own? Just strap a rasp pi w ontop of it and let it go hehe
Tweaking existing drones. Rasp pi was going to be the board but I'm switching to bananapi for cost effeciency
I mean same thing but still
Here's a lil demo for those interested in seeing the tool :) https://www.youtube.com/watch?v=A8V_7_vyFjA&t=2s
Hell yeah man - lemme know if you wanna integrate my tool as a prototype
I'd be honoured
to have my software fly
I am okay with you mentioning your tool but can we make sure it's not becoming too excessive and boarderline just self promotion please :)
That's a long ways off but yeah lol.
Yeah of course man, its not in a release state so no distribution of it, if thats any consolation :)
Right now I'm just happy I haven't fried a thousand bucks worth of gear. Yet.
This is just a friendly message, you haven't done anything wrong ๐
Cipher - It's only 1pm. You still have a few hours to go ๐
timezones don't exist
its 1 oclock and its time for lunch
it's uk only, everywhere else is a myth
timezones are gubment lie
Time doesn't exist.
Oh. You have the whole day ahead of you. Couple of g's should be easy
gubment planted the thought of timezones using the fillings in our teeth as transceivers
British Museum also claiming time i see
LOL
My wife, being Indian, has thoughts about the BRits
how was that interview though
we should all just use UTC. life would be so much simpler
Heya hackers ๐
Easy. 3 interviews in a row across 3 days. Hiring Manager, HR Manager, Director.
Just sold myself on the transferrable skills that matched what they needed.
so, even though you weren't necessarily "qualified", you were able to perform well in the interview?
Yes
Amazing
He lived.
My rasp pi stuff comes this week, woop woop
Cipher, did you use anything to interview prep?
Jabba Museum
Barely, fueled by spite of not wanting to sleep
Whahahaha
As long as itโs nothing worse. ^_^
Might actually go to the Netherlands end of March, by the way.
Most job postings are filled out by HR/ Recruiter to include the perfect candidates items.
The perfect candidate really doesn't exist, and especially not for the ....salary 90% of companies are offering.
You WILL meet 70%+ of what is being asked probably in some transferrable way. Focus on selling the skills you have as the solution to their need, and that you areactively interested and studying some of the missing components.
Downlaoded and practiced some software I never used before and watched some training videos on LinkedIn Premium so I could speak to it
awesome
Nope, all good otherwise
And did the whole get tense panic attack thing for ~5 minutes before I slap myself a few times and say "showtime".
What role did you land my friend?
Went to a concert of nothing but thieves to this Saturday, was freaking amazing
Higher management role in a different field than I had experience in moving my from a more labor intensive field to corporate office in logistics lol
Damn, neat stuff.
Mhm mhm
Never heard of them
Better than bad ๐
Now I have to listen
Great stuff
What song would you recommend as intro
Hah. It was not good, but itโs a bit personal. Ainโt gonna cry about it.
can someone hack my friend
Early 90s vibes
Hope you are alright

please
@mossy river can
really
Why what did they do
guys, can anyone help with my school project?
no
cheqting? Is that like texting and chex mix combined
Do you have a monogamous friendship
no hes my boyfriend
No, that would be cheating.
@cosmic swallow
Cheating of any form is not allowed. This is not limited to asking for help with assessed schoolwork or exams.
exactly
Google the word monogamous
๐ฅฒ
Youโre aware this is illegal and can get you in a lot of trouble right? @native flax
you sure? it might be cheqting
Just have to make sure you do first
why
Logistics, interesting
Uh, are you ok?
how can i get in trouble
Itโs against computer misuse.
oh really
If Iโm going down, Iโm bringing you with me
logging into someones account??
oh
Look it up
If the service has software that does ye
I love this stuff
Even if HE doesn't, the service will
Drop me a DM with their account name
the internet police will come in your sleep
Easiet field to do well in, in my opinon. Massive, becoming more complex, they lack technically competent people. Logistics includes a great deal of IT expertise that goes unfilled. If you get into some reverse logistics fields like ITAD, they need enginners and programmers more than anything else lol.
Sandman 2.0
Still need to read that comic
when it comes to sleep, i prefer the hatman >:)
reminds of that scene in hackers
I was refering to the sleep man myth
i still havent watched that movie man, i need to
Is that like the failed Batman
No, just Batman with a hat
pretty much, batman for drug addicts
I did a job for an ITAD company, shittiest place ever
They can be. All the smaller ones are just...shady
Hatbatman
Slightly overweight batman with a fedora "Me lady"
I tell you they are, our one took away all our chairs from the work benches to "not damage the floor" (it was a painted concrete floor)
BRO HAHAHA
And paid everyone a different wage in the same room
O frabjous day! Callooh! Callay!
this means i cant talk now, right? D:
how will i survive without yapping
Typing isn't talking
has anyone tried web defacing?
But you are good to talk
Wait
And overall was just a boring job to be honest, didn't want to progress you in any skills or nothing
Can I DM you a question?
Yes
Why exactly do you ask
just concerned
this was the moment they found they worked for the same company at the same time
what about all capitals, this surely is reaching a higher sound level despite being funny 1's and 0's
web defacing is a thing - if you have write access to a web server
used to be a big thing back in the "anon" days
the days of thousands of anonymous skype and IRC groups
Those days were fun as a kid
XD
like, online graffitti?
darkcomet listening
i did some stupid shit for a 13-15 year old lmao
suppose they're the years to do it
Hey anyone here that will give me a recommendation about computers?
thinkpad. end of story
Buying a new one and im stuck between which offer to choose lol
you wanting a desktop or laptop?
Preferably one from 1990 or older
I already have 2 options, desktop
i cheated, i got a gen 11 :')
its fucking great tho
I just want recommendations on which one to get
Watch out with cheating, mqybe theyll ask a discord server to hack you
i'd usually say to avoid prebuilds like the plague but for pen testing specifically, you dont necesarilly need an amazing machine
Whats ur options catsuo
Tbf not for pentesting i just want it for gaming lmao
avoid prebuilds
do research and build your own. it's a lot easier people think
It has ease of use though
can even pay people to build it for you
First one is i5-12400F rx5600xt 6gb with 16gb ram 512gb ssd and 600W +80 psu which comes with a 27inch monitor
Costs 2200 in total
Oh and 1TB HDD
Like sure people overpay like hell but its easy
is that $ or euro or what?
Second one is same shit just with rtx 2070 super 8gb and without monitor
yen ๐ค
Its in โพ
what is that currency
Gel
The problem with prebuilds is that you usually get some good "selling-point" components like CPU, GPU and sometimes MBD. But everything else around it is a cheap excuse that i wouldn't trust my build with
No way you are gonna 2200 euros for that
Ooh, I never met anyone from Georgia before
Yeah so which one sounds better?
Not a big country lol
Yeah second one has rtx 2070 super but no monitor
Aye, I always like talking to folk from countries I don't know about ๐
How hard is it to get tech in Georgia?
yeah monitors are useful 
Me with my 1550 mini
And its for 2250
so i dont think you're getting your money's worth
the size dont matter ๐คฅ
Im still in school 
This one for the gpu's https://gpu.userbenchmark.com/Compare/Nvidia-RTX-2070S-Super-vs-AMD-RX-5600-XT/4048vs4062
For ~900-1000 bucks(compared to you r800 Euro) I'd expect modern components
Yeah i did that research
I got it for a pack of cigs tho
Best deal i ever got
that gpu's wont bottleneck a 12400f, so no worries
wtf
do you have any contact info for the seller lmao
i got a pocket full of old receipts if they take them as payment too
I think then i should go with the 2070 no?
Was an old mate of mine
Already have a monitor
hell yeah thats super cool. i just buy all my shit then hand the old stuff down to my little brother
But yeah my desktop is outdated as hell, but if i wanna upgrade i need to upgrade cpu gpu and motherboard all in one go
look at the other circumstances, is the seller relable? What are you going to do with the pc?
Mostly gaming
And im buying from a store
And what games?
Lol
yeaahh, a lot of the time its just worth upgrading mbd so you've got flexibility to support other components
Surviving on a ~7 year old desktop myself. 1080 ftw though. This thing trucks.
Rocket league fell off
Kinda
not RAM?
But still awesome
Rocket league was the Overwatch of sports fans
Oh yeah, might as well get a new pc without a case lol
the ranking system is silly sometimes
But can always download ram
Is not, I'm number one
Just buy a case too then, just for the feeling xD
Exactly, shes handled alot and i mostly just play offline anyway
What game?
But this full tower one is my baby
Every game.
mordhau still remains my most addictive time-sink of a video game. its so perfect
top 5% in the world (2500 players
)
I knew you got it in you
I play fighting games a lot, and some chill shit. Too old for the hyper competitive shooters
Same, simracing for me
And shit like civ and hoi4
assetto?
Only exception being Hunt Showdown. Something about the dark atmosphere
Yup
Games like that and Bloodborne bring my soul peace
I dont play games
my man. i spent a lot of time on there until my wheel broke :'(
Nightmareish realities are peaceful
i had the Shutoku revival project track mapped in my head lmao
I've never loved a racing game like I did Gran Turismo 4
Grand turismo is a fanastic series
my childhood sweetheart is the 2005 NFS most wanted
Ah
That, NFS UG2 and smack down vs raw were the pinnacle of my game experience as a child
NFS Carbon had the best OST for an NFS game.
Learned the words for window and wall in Hindi yesterday and first thing I asked my wife, because it's all that came to my mind, was how to sing the lyrics in Hindi now

Most wanted for me. The nu metal soundtracks in tht game was the catalyst of my music taste today
Please do not conduct moderation activities or enforce rules. If you think someone is breaking the rules, ping a moderator.
:mute: lifeemerald#0 has been muted.

I remember playing the older NFS games on PC in the 90s. Like NFS Hot Pursuit, but being poor I had to use keyboard controls
Driving games on keyboard. Painful
Hot pursuit was also absolutely slept on



Yeaaa just like me trying to drive my car with welded diff. Itโs either skidding or not moving lmao
Check the context of my previous message. ๐
Canโt be worse than those that use keyboard to drive in multiplayer driving sims 
Let's use a guitar hero controller instead
I think someone beat Dark Souls using that
Streamed it
They did.
Just use it as an actual steering wheel for a car at this point
Nooooo. Someone is going to wire this up to a Tesla now
Someoneโs already made a collection of videos having random items as a steering wheel lmao. Iโm sure one of them was a clothes iron
Im probably gonna set up an ai race on pc2 on lemans, multiclass lmp2, lmp1, gte, and just vibe
See, the reason he crashed causing 13 fatalities is because he didn't hold the whammy bar for the full grind thus the traction control system didn't keep working for the full turn
Whammy bar as a handbrake is the best idea Iโve ever heard
I think I need to join the Offsec server just to chat to Spooky 
They're also in David Bombal discord as they're a mod there
they're a mod in nc too, right?
David Bombal, I enjot his stuff. Network Chuck is who got me Deep into tech vs surface
Yep, last time I checked anyway
Bombal has some great stuff
Helped me learn quite a bit around physical pen testing - building rasp pi stuff, hackrf etc
Sn0ren has some great RF content too
I'm in his and Hammonds
Hammond is fantastic, really like his work
It's a glorious time to be a learner in not only the tech industry, but the security side of it.
0day ever show up in chat here?
Totally! Information Age
The most fascinating things to learn though is the old tech
Instructors who have old war stories are great
Analogue cyber sec days
Learning about older cyb sec methodologies makes me envious about how insecure applications were on a mass scale
Everything on a easy box difficulty 
You are, thats dope
Did things change that much?
Pretty sure (never tried / looked for obvious reasons) that if you look at privat ppls stuff or smaller companies everything is still very insecure.
End-point security? totally. Users, not so much
IMO Everything moves to a single point of failure -> clouds.
The more i learn about RF the more i realise how insecure that it remained over the years
Ello
Yeah, but on an application level large cloud services are security aware at least
Tons from a technical perspective

Same old issues
Humans
Yeah totally way more secure compared to everybody needs to take care of it themselves. But if they mess up. It could be very bad for a lot of companies.
maybe peoples ai takeover conspiracy doesnt seem to bad after all 
Supply chain attacks are no joke
Tonks are love, tonks are life
your banner tank has one quick loading crew
It's on repeat, Abrams can't fire that fast XD
Hopever
THe Japanese Type 10 does boast a 4 second reload
With autoloader
nah i like to believe they're just hacking, leave me to my delusions
Abrams undetected infinite ammo rapidfire cheat
That's just called functional logistics
i wonder what ghidra would think of an abrams
Abrams, where we protect crew from the ammo. The most dangerous thing inside the tank. As opposed to someone else who seats the ammo right below the crew so that when it cooks off they become cosmonauts
Yeah ive played enough war thunder to see this for myself
However, it's usually me that does the cosmos travelling
Fellow Warthunder player!
GOt my Germany to ~6.7 atm
Japan 5.7
One grind away from the first leopard
hell yeah! Im an aviation main, up to 10.0 US and around 6 on USSR
want that goddam mig29
I havev some premium jets, but my German Aviation tree isonly about ~5.7
That's honestly the sweet spot of aviation
however, XP-50 is a problem around there iirc
I own that lol
I enjoy air arcade for 1.0-5.7
At 8+ I do realistic
Using the Tornado IDS premium for grinding
IF I can even reach a base to bomb
its always fun to go into 1.0 biplanes and ruin new players 
Brother is a Marine(out now) so he ground American air up to top
And his American ground is about 6.7
I'm a Naval enjoy
One of like 10

No love for us who enjoy those behemoths of the sea
And I don't mean curvy mermaids
Taylor Swift
You aren't wrong. How else do you snag breakfast from Starbucks if not by a jet?
Hi everyone, i work at a small IT company interested in implementing an SIEM in order to monitor our clients.
Does anyone recomend a siem that fits for a small company, also what would the price be if you know
ELK. Open source, you can run for free on a fairly reasonable box (2cpu and say 4gb ram but i'd recommend 8gb ram if you're ingesting & indexing a reasonable amount).
ELK is well documented and extendatable, also, free from a licensing PoV if you're willing to run it yourself
Thanks, you know how much storage they allow?
unlimited. It's down to whatever you can provision as the box. If you're running a lower amount of HDD, make sure your log rotation is good. But there's a lot of variables i.e. how many logs you're taking and how long you need to contain them for
you can have a 1cpu and 4gb ram ELK stack with 30gb or a 32cpu with 128gb ram (plus) with 2TB on the community. There're no limits
Splunk too. My personal preference is ELK but y'know. Different strokes 'n all
I told my company we should try splunk
But they said "too expensive for portuguese clients"
XD
probably. I think Splunk push more for their commercial editions and courses/certs. ELK is completely open source, extensible, and just my personal fave especially in a "smaller" environment
Hey @lone thistle hope you are doing well, finally caught u online at the same time as i am lol, any idea if we could get the generated Password for the attackbox/ Kali ? i sometimes lock myself out of Root, Thank you !
Gave +1 Rep to @lone thistle (current: #7 - 813)
helo Ben, have you worked with k8s, specifically on security side
@hot cairn someone needs a K8s master
the passwords are auto-gennerated on deploy of the machine. You can retrieve this by pressing i on the split-screen view. For root specifically, I think this is auto-generrated to be the same as kali, if not, you can just sudo passwd root to reset the pass.
I would be a bit hesitant to give out default passwords as I use these for internal dev, but, let me know how you get on with the above and I will see what I can do. Just remember that the machine boots from a template when you deploy it, so any changes you make since then, will be lost on a new deploy
Its the elastic security right @lone thistle ?
https://www.elastic.co/ the open source version is somewhere on there or github, but yeah, elastic
thank you
@lone thistle #general message also this
gimmie a chance ๐
Never!
That perfectly answers my question, Thanks a lot
I've used k8s yes, security......ehhh. I can maybe give some tips though depending on the question
Sorry, didn't know if you saw it since you weren't tagged 
did yo course videos contain only women too?
i am working on a security baseline and have been reading CISA's hardening guide but i guess my question is, what are quick wins for K8s in terms of security
CISA hardening is good. For k8s, make sure you implement role based access (RBAC), secret management (general good practice), and pod security policies for reducing your attack surface for your pods
@lone thistle Last question while you are here, for the room "Command Injection", in the Practical, i was trying to pop a shell on it and thanks to the awesome help of @sick lance he was able to teach me how to use a PHP reverse shell script, when i tried again to teach a friend whos doing THM with me, it didnt work, was it patched or is it just an issue on my end ?
Gave +1 Rep to @lone thistle (current: #7 - 814)
and the general standard things like auditing images, implementing vulnerability scanning frameworks like Trivy and make sure you're patched
wouldn't be patched. I would just make sure that the friend's connection to THM is okay (can they access 10.10.10.10) and they are modifying the php reverse shell to match the details with their device on the THM VPN (curl http://10.10.10.10/whoami) and that the reverse shell is connecting on the same port as the listener (I.e. 4444)
Okay that confirms that the issue is on our end, will be trying again later, Thanks a lot man have a good one
No worries ๐
amazing, thanks. i think ill list those as high priority
Gave +1 Rep to @lone thistle (current: #7 - 815)
been wanting this but been thinking about how i can integrate trivy to the existing infra. in your case, was it seamless or was there a lot of debugging involved?
Pretty trivial. But then it depends on org policy etc...can you just install some tooling/framework on the k8s host. Trivy is simple to use, the "politics"/"policy" for getting it on might be a bit more ... involved
yeah definitely. esp. with senior management hating the word open source
John Oliver has episode about Pig Butchering scam
i'll try to make a PoC with trivy to try to pitch it
also no reason as to why you can't install things like trivy on a dev box and copy/build the images that the k8s uses on your dev box if you have issues installing it on the k8s host. Ideally, you want things like that in your dev / CI/CD pipeline
today has become a sad day ๐ฆ
I have decided that I have to sell my car
Ironically, I just took delivery of a new company car. Audi Q5 quattro S
https://youtube.com/shorts/jyTH0Gmy8nE?si=FoBarrWC9qn4I4Ma
Yo, this bird brings back REALLY fond memories
rust
Oh on the frame?
Nice one btw
Or the car programming is only in Rust?
Thanks Acme. It's not mine, its for my brother (director)
I'm happy with my 2005 van ๐
I haven't heard that bird in eons
And it's mine. The other folk in the office all get Mercs and Audis on leases. They're nice, but nah.
Seriously, It's rare u hear it now
Probably one of the things we killed off.
Remember the last time you seen a red lady bug?
THose orange ones ate them all
Yeah, as long as you are happy with it, all good ๐
Happy... for now. Until it breaks down again :p Luckily most of the things are stuff I can fix myself
I would comment that it's crazy that the exact same bug with a slightly different colored shell would wipe out another one, then I remembered humans
Next semi-big job is replacing the hadbrake cable. Looked a bit frayed when I was under the van a couple of weeks back
So someone commented there, that we've been hearing them less because they have been hunted
https://youtu.be/7oNljd7R1f8?si=ZGM1djK2Iz3QqOCa
But here's the bird and some noises lol
Quick video of a Mourning Dove Coo. High quality video and sound.
Sarcastic answers to frequently asked questions:
- The name of the species is Mourning Dove. I didn't spell it wrong. Look it up if you don't believe me.
- The title simply states what the dove is doing. It's not mourning anything, it's just "cooing". Furthermore, I'm n...
Slightly terrifying
Why hunt them?
Eh. Leave in 1st gear and a couple of choc blocks.. it'll be fiiiiine
Yah, when I was a kid laying down in the TV room and one flew in on me
Are they good eating or thje sort?
Dunno
In our country we have a website that has a camera on a birds nest every year
That's cool!
I remember seeing an Owl cam like that
A number of countries do that.
I can send an URL?
We have cameras on some Bald Eagle nests
Was really cute seeing the Owlets (Learned that term on here :D)
Sure
Owls are amazing creatures
You might have to translate the website xd
I'll just learn whatever language it's in.
If you click on BINNEN2 you can see the inside
Dutch
So Germany with an accent
Damn...

Yeah i remember watching the cams on sunday afternoons
I keed. I'm not that much of an expert, I just know they are heavily involved
Are Netherlands in the Euros?
Yess
All I know is even saying nice things in German sounds angry
Whats their group like?
German can compliment me and I'm scared
For the Euros?
In the Euros
Haha, did you think I meant in the EU ๐

Why they do the German like that
yeah xd
I'm intrigued to learn the differences now
You got... Austria, France and a wildcard
But yes, in euro 2024 yes
they can become second
@mossy river
damn that one was 0xD
Dutch is far softer sounding on the ears
People are suckers for free software it seems.
FOSS! Don't pirate shit, find an alternative!
Esqy is your country in Euro 2024?
Ireland, Nope. But England are
Speaking of Ireland... https://youtube.com/shorts/Y0gMiYDoP1E?si=VSZtuNhXALE4Jehj
Might have been a compromised account
1 more day ๐
Ah, they have a decent chance, but as always, France will win
Yeah, it was.

