#general
1 messages · Page 48 of 1
on the whole back right side
France, Spain, or England?
I dunno. I like looking for the underdogs, y'know?
ah yeah
Well football... Kansas City Chiefs won the superbowl... for soccer, idk, idc about soccer 
its called football
*Handegg <-- Fixed that Matt
Soccer
Football.
You guys are pansies who wear armour when you're playing rugby.
You remember the Joe Biden where he says its called soccer?
A seasoned Highland Games veteran like you, would say that Scrubz 😄
Oh, PLEASE tell that to the lineman of any NFL team. Good luck with them.
I hate that guy
xD
Huh. There was a Georgian user on here earlier - Looks like they are playing Luxomberg in a few weeks
Trump next elections?
imagine a game, where most of the time players have the ball, its in their hands. imagine calling that game football
For real
49ers fan so I'm still salty
I think TimT was rooting for them aswell
2020 all over again minus the plague
All that armour. 
Seen more contact in an ice hockey gane, the Canadians got you beat.
Armor* but do you see those hits? How quickly their head snaps back?
Armour is spelt correctly.
Mi amor
Follow HF on Instagram! - http://bit.ly/1U8sAgV
Follow HF on Twitter! - http://bit.ly/1IVYecq
Like HF on Facebook! - http://on.fb.me/1VZq23s
Song: Here Comes The Boom - Nelly
https://www.youtube.com/watch?v=nqWZqQXk_Ao
Copyrights to the NFL, NCAA, FOX, NBC, CBS, and ESPN
Only gumshields.
Or teeth
Compared to our hits, that's nothing
Plus we have done a ton of research on CTE and want to prevent it. Safety is a huge thing.
Alright, in America, call it soccer. But dont go to other countrys buh buh its soccer because we already have a sport that is named football (but we have the ball in our hands there)
Alright there Scrubz. Why don't you come to the US, get hit by college or NFL level lineman, then come back to me on how that feels.
Cause I used to be a lineman, we got power
Football vs American Football
checkered ball game to make it international
Sorry 😂
You're so easy.
To defend football? Oh yah.
It does look good
After one of them Tosses a Caber in the Highland games
Literally flipping a telegraph pole
*Hand Egg
Freedom units
are you willing to come here and get tackled by a professional rugby player?
And y'all tell me "Nah, this what it's supposed to be called"
Telegraph..... not telephone, telegraph........
I had to carry one 1K, dump it in a river, then duck under it.
100%. I will defend football and how hard we hit
1K of feathers or 1K of bricks?
Was that your rite of passage into adulthood, scrubz?
Although sounds like a Tough Mudder thing
When was the last time y'all used this?
Man I wanted to do tough mudder but didn't before I got hurt and now I never will
It's depressing
I think I saw one where they had to army crawl under and eletrified net 😄
Never because I'm not old
Matt - Thats how I use Discord..
Does it matter?
They used to have hanging electric wires you had to run through. But they stopped that after someone was running through and it wrapped around their neck and they got stuck getting electrostrangled
Physics is a cruel mistress sometimes
As is new words I've never seen before.
several few years ago
To be fair, every kid should learn morse code
cos amateur radio doesn't interest me
It's useful in weird fun ways, and has survival uses
@shut hawk did you get your invite?
It's fun if you and a friend know it and no one else does
I went through a cipher phase
Something as simple as pigpen really throws most people off
meanwhile, everyone else just uses e2e encrypted chat and laughs at you with emojis
Depending on the exploit, Sure.
Incoming new OS from X, formally known as Twitter, as Elon throws his toys out the pram again.
Langning - Have you done the LFI room on THM?
I did that one an hour or so ago. was fun
I've not done a THM room in a bit, waitiing until 7PM so I can submit my flags for #1210662756659765330
It's interesting, and feels like it's a core skill/technique
Thats ok. Look at 'What the Shell' room. That coveres how to get something going in python.
Combine the LFI with the Python stuff
Guys please help
I have the answer for question: What is the URL that the infected host connected to? https://controlc.com/548ab556
but it says wrong why?
room Benign
Also for MISP room What event ID has been assigned to the PupyRAT event?
1146 say it wrong
Hmm?
#room-help would be a better place, could get lost in here, someone will help you soon enough.
thanks
Langning - Arguably, If you can get a python script on there, it might be easier than the PHP stuff in the LFI room
im curious what he is gonna do
Over-react as usual.
release X-ubunt- oh
Y'all stretch so hard your eyes go blurry?
Probably not in the LFI room. That will just show the technique. 'What The shell' has a couple of python scripts in there (IIRC)
How long ago 😄
Ah there we go. Probably slipped your mind how to do some stuff. Get a refresh sesh on
What the shell is a really well put together room
And this time - Take notes 😄
Big life hack
The notes I took before I left for a while have been a lifesaver
Hi everyone,
iam doing linux modules room , and iam having a error on awk command, i think iam doing it right but it always giving me a worng answer, alreay peaked the hint and put in FS= but still giving me error
Trying this answer: awk ‘BEGIN{FS=” “; OFS=”:”} {print $1,$4}’ awk.txt
What the shell opened my eyes up to using SSL over reverse shells. Pretty neat
I did Jameses 'Wonderland' room, and the old notes were invaluable
Yet to try that one. Tryna finish my jr pen tester rn and i feel burnt out after doing 3 other courses this week 😂
Peix - Break the command down and make sure each bit is what the machine would expect
80% in, so close
I liked it. Don't feel like I could take on Looking glass JUST yet though
Anyone ever use vc for doing boxes together? I rarely do team stuff unless it’s a ctf comp but it’s usually pretty fun as a group
Did a koth with a friend in vc once, that was fun
Used to be a study group.
Back in Ye olden days
Yeah, It happened a fair bit.
No I don’t have friends 😅
Was also the odd walkthrough event
Maybe should bring back the Geoguessr
Haha, those were funny
There was a time with the Chess tournaments as well
You got us
parasocial hacker friends
That would be really fun to do
I mean I’d be absolutely terrible at it, but fun
Bit of a loose osint challenge
It's crazy what folks can do with that knowledge
There are crimes that are solved/committed based on figuring someone's location out purely by reflections in glasses/windows and piecing together a location.
Kudos to the law folk who are experts at it
Yeah shit is absolutely nuts man. I read an article a few weeks back about a member of a ransomware group that got caught through investigators extracting and identifying his fingerprints from a photo posted online, there was a defcon talk on the methods used a while ago too I believe
It's only going to get crazier as well
But now we will see risks such as people using that same thing to frame people
Mouse and mousetrap, never ending story
Can’t be superhero’s without the supervillains ;)
Fair
Cyber has always been a game of cat n mouse. Suppose there’s some job security in that at least haha
I still don't like some poor man/woman losing time of their life because a criminal was "smart" though.
I mean the whole bank fraud thing before digital era
Humans gonna huume
Hey guys. How do I change requests permanently when using burp as a proxy? I want to change the value of a cookie while I am browsing a site and that cookie value is reverted back to its original whenever I change a page
Probably using Macros, there's something about how to use them in Burp Room
The talk was several years ago from the ccc actually.
Ahh I see, thanks for clarifying that one up
Gave +1 Rep to @nova pollen (current: #277 - 17)
The POC was taking a fingerprint from a German politician. Highly recommended 🙂
No ☹️
Reeeee, just found out I maybe have a 3 month quitting warning
Damn, I got two. 
anyone know of anyone here working for a uk company but working while abroad (for months at a time)?
Yeah, for some reason they sent me another e-mail today
This domain playminesweeper.ai is available to sale for now
Gave 1 Rep to esqy_1up (current: #19 - 397)
@noble nacelle Let's avoid abusing the rep system please
Sorry autocorrect being overzealous
Go to the Proxy tab -> Click Proxy Settings beside Websockets history -> Edit your Match and replace rules
I think that rep was for this earlier
#general message
Fair, didn't look back, internet on mobile a bit flakey here
Something like this probably @brittle lynx
good idea to use for bug bounties
reply to someone and say thanks, or @ them with the same
Just say thanks in a reply
Gave +1 Rep to @noble nacelle (current: #2009 - 1)
rep abuse!!
Like that
Gave +1 Rep to @shell nova (current: #12 - 549)
Gramma
Because English is a good enough language that you can swap every word in a sentence, almost every letter in a word, leave out words entirely, and still get your meaning across.
If you're skilled at linguistics, that room may make your eyes bleed.
i talking about an...
It's the lower case i more than anything ;p
I nuffin c wrong
What is the name of the "Operations security" i talking about an...
That question is a fascinating use case in grammatical structure
*blush*
wholesome google translate
(A room on the platform that has past proof-reading :p)
Discord mobile app is just terrible.
is it normal for job applications to have IQ like tests?
depends on what the job is but could see it happen for a few
talking about the ones like these
only if your name is jayy
I say IQ, I really mean specific pattern recognition in grid patterns
I've applied to a few that had them.
Mostly banks.
I'd say C
hey no helping jayy with the interview
Seemingly I got > 95%
😅
reasoning (jayy, don't peek): ||one square going bottom left to top right, one square going top left to bottom right, one squre going from right to left, one square staying in the same spot||
shadows last IQ test made shadow scored a 100-105 iq range
well this was probably one of the better ones as it was held by some psychatrists
IQ is supposed to measure intelligence, but does it? Head to https://brilliant.org/veritasium to start your free 30-day trial, and the first 200 people get 20% off an annual premium subscription.
If you’re looking for a molecular modeling kit, try Snatoms – a kit I invented where the atoms snap together magnetically – https://ve42.co/SnatomsV
...
due to having to question if shadow can understand the treatments they are under
I need help with my network setup
Easy, Start by 3D printing something.
Well yes, but no
So: Have a Cat6 plugged into my router on it's 2.5g port, mode is Access on a specific VLAN Profile on .52. I plugged it into the second 1g port on my server, and have my VM using that NIC as it's.... NIC. On TrueNAS Scale Network section, I have on NIC 2 182.168.52.2/24, tested and saved.
On my router's VLAN section, 2.5 is green, on my guest network VLAN section, where I can add VLAN's and all, got that on wired and not wireless network, but it shows 0 clients.
lol
Don't ask why, just, if you got knowledge, lay it on me
Sounds like it might be to do with the second port on the server
Or the first - The untested one
First is on my LAN already, getting network.
Does it work if you unplug t'other?
Anyone here know and can explain to me how can I block specific site on my laptop or router... pm please
Cyberdeath - Depends on the router, but there will usually be a setting for blocking specific sites. Some even allow keywords
show it some football (warning: if you attempt to show it a hand egg, it will explode)
Is attackbox safe to use at work?
You should really be working at work 😄
Im in it with lots of downtime
Ok, so 1g port on my router is running down to me, to a switch, from the switch runs into 1g on the server and IPMI, those work just fine. got 2 10g NIC's in desktops to the server, those work. Just port 2 1g NIC, either not configured properly, or what/ But TrueNAS does see it's live, but no data, cause no IP
Boss is cool with learning
define safe. it won't attack you, but you might get in trouble for not working
Ok, So I'd say - Unplug the working one as you KNOW you can get that up and running, and see if the second one fires up. If it does, then theres a conflict somewhere
Basically work backwards to troubleshoot
Then I have to configure the network in TrueNAS itself
WAIT
.....
I think I know why. the fucking IO VLAN selection has been a PITA to me, never gives DHCP
Like will my boss see normal https traffic?
That was my next thing 😄 Check the IP and just assign it one
Cos DHCP can sometimes be squiffy
If the vm is running through the browser then it should all be https?
(This was all right on the very edge of my knowledge BTW) For real though, I think your Candian business partner might be the best placed for stuff like this
Don't worry, I already raised my SOS flag to her. I even went to the Homelab discord, but they were just ignoring me lol
Either, they didn't know, or they didn't care to help
What are you using the TrueNAS for?
Emma is probably rolling her eyes and saying "Oh god, not again" /s
'eh'
I'm just assuming it's Emma that you're refering to. 😂
I jumped in to the back end of the conversation.
NAS, MC Server VM, and other shtuff
It is
That MC Server is using that VLANed NIC
Well, when servers are mentioned, Emma is usually involved 😄
Public server, or just you and your buddies?
My friend's buddies
Actually nice of you to host a server for them. You feeling alright? 😄
Right now he's paying like $20 a month for 4gb of ram. I was going to hook him up for free with a 8 core, 16 thread 32 GB MC server VM
checks pulse Nope
bit overkill lmao
8 core, 16 Thread you say?
Indeed
Got 28 cores, 56 threads all together in this bad boy.... I COULD make it 44 cores, 88 threads if I SO desire, but that's shelling out like $420
Hehe 420.
I kid you not, that's the price of the paired CPU lol
Would that max out the capacity of the server?
It'd certainly keep your house warm and toasty
the CPU, yah. That's the max one I can get, an Xeon E5 2699 V4. 22 cores, 44 threads each
I rock a E5 2680 V4, 14 cores, 28 threads each.
What RAM can you get up to potentially?
they should give you a Rioja at least 😂
1.5 TB. I have 256GB ram in it right now
DAMN FUCKING RIGHT!
Luckily with RAM you can kinda ramp it up if memory prices dip
The CPUs aren't priced by performance btw. You can get really nice parts super cheap where large server farms have been killed off
It's server ram so that's a chunk cheaper anyway
Huh. I thought it'd be more-or-less the same.
you can always just download ram too
TIL
I need more storage 💀
Oh yah, my 2680's (paired) were $46
James - I nearly got banned earlier 😦 Jabba misread a message, then double checked and banned the right person :p
😂 That almost happened to me, except it was a warning, and Zojja rescinded it.
Have you asked nicely?
Ah yes, lemme ask my server to PLEASE work
Remember to give it a pat and remind that it's a good boy.
Does the DHCP have access to both of the NICs?
ditch the bullet there 😂
Aye. I'm hoping it was Jabba like 'Wait a sec, Esqy wouldn't say that!'
Or does each NIC have it's own? Could be a conflict
(Thats Why I suggested unplugging the working one to test the non-working one)
They each have their own mac so should be chill
Should be, but this is Matt configuring them
So on my router side:
Have 2 VLAN's I configured to test, 1 is n IOT one, another is just generic guest. Both are not using wifi band, JUST RJ45. on the LAN VLAN side, 2.5g port on my router is in Access mode using the generic guest VLAN Profile.
On my server side:
VM is using NIC2 (One connected to 2.5g on my router) as it's NIC. On the network side of TrueNAS Scale, IP Address is the same VLAN ID as the Guest network on nic2.
that's the confidence we need 😉 😂
Honestly feels like something you need to be sat in front of to figure out
Sorry I can't be any more help
Hello guys, I am on "Inite" box I am connecting as www-data but I don't found the Privesc vector despite a LinEnum and manually enumeration. Can you give me some tips or hint ? Thank you !
hi everyone, I plan on getting a bachelor in cybersecurity. I would fail a CS Bachelor as I am pretty average in maths. However, I read on reddit that you can't succeed a cybersec career without having a CS Degree. I'm pretty concerned right now and I don't know what to do. Any advice. Pardon my broken english.
Why not study maths more?
#room-hints or #room-help maybe will help
tried several times, always failed.
Thank you
Gave +1 Rep to @blazing granite (current: #148 - 44)
If you think you'll fail you've already lost. Universities have a lot of resources for things like that.
They may even help with extra classes.
But yes, You can plan a career using various certs and stuff. Arguably, a CS degree would open a lot more doors than having cybersec-specific certs.
you didn't fail, you've just found out several ways that don't work for you 😉 keep trying 🙂
And yah, As Scrubz says - They'll have additional classes. During my degree, a few of us were having trouble with Differentiation and Integration. So we found a Maths-degree friend who (For payment of beers - After the fact, of course) would sit with us in a library study room and go through it with is.
Thanks for the positivity guys
So even if the Uni DOESNT offer it, You're surrounded by folk who know and are usually willing to help. Especially if you can help them recover their dissertation that they accidently delete and panic (Happens more often than you'd think)
Weeeeee. University is good fun. Enjoy.
You learn even not on a school day. Remember that.
G'd evening Hex 🙂
disclaimer I work for a university
G'day
Yes, I'll look into that even tho I don't think my relationship with mathematics can be repaired
Kalvi - You'll be surprised. Stuff can make a lot more sense when they are in a familiar context.
Oh I'm terrible with maths, but I'm learning!
Afternoon Esqy, new time zone, it's 15:22, and I'm still jet lagged 😂
Yes it's fun because it's not like any other subject but that's a whole concept to assimilate
For Pure maths, yes. But when you are using it for a specific application, it's waaaay easier to grasp
I find that anyway. Other people might not
Today I used maths on my degree course
Pun intented? 😂
Yeah I agree but CS is not really specific
Was is breaking force of various joints? Cos thats more Physics 😄
what's your degree ?
Kalvi - It kindof is.
Security and Risk Management
With regards to maths, anyhow
nah, the cos function
For now I'm staying in my mum's house, she has a spear room so I'm OK. We (Mum, two siblings and me) went to a kind of steakhouse for her birthday so great 🙂
Oh, you're still there? I though by shifting timezones you meant you'd left already
But no, You're still jetlagged from a few days ago?
/oooh that's whyy
It was actually spending of a budget and justification
Thats an important one. Unless the places has already had a security breach, then it's simple 😄
I still here, I arrived on Friday, you don't flight 28 hours to stay for 4 days 😂
Yup! All trig boils down to is just the unit circle
(circle with radius 1)
Well, I don't know your life - Tht could be the high-flying jet-set life of the Rex
Even then, clients always have a budget and it's usually pretty low
My sleeping schedule was a mess even before flew so, I'm getting used to it 😂
Well.. Just don't touch it anymore 😄
Security is seen as a thing they have to have but won't properly fund it
Usually for insurance or other regulations
Yeah, just to tick boxes
Usually you have to appeal to their sense of not potentially losing money in lawsuits
But it's all going well, Hex?
For example, universities will have security.
Some see it as a service, as in they fund it, train their staff, engage with the local and wider community, keep people safe etc.
Some see it as, we have to have them, but let's treat them like shit and fund them like shit and wonder why their response to issues is awful.
Also don't forget that they don't have proper policies in place
VLANed, seprated from my whole network, can't access my main network, but can still ping out. LETS GOOOOOOO
My degree is going well.
I will probably leave employment at the university after.
the discounted degree is a major incentive
So far so good, I'm on a hunt for a remote position now, so I'll be able to spend more time here
Oh the business folded mate.
Oh no, sorry to hear that
Yeah financial issues
Spent too much on Security?
I'm only messing. Have the old crew got anything else brewing you can jump onto?
Hex, what's ya degree?
Security and Risk Management
Oooh
Funnily enough at Portsmouth Uni
Sure
Hehe, I went there for a year. And I had an unconditional offer to do a Masters in forensics from there
I have a tech side too, I worked help desk, tech support, and I even did some IT consulting in TLV the idea it's get a job that pays in dollars so here in Argentina with the exchange I'll be king and I also could help my mum a bit
@glass nest I got a lighter for paracord and heatshrink, pain in the butt
In the same couple of weeks, I also go a job offer for grad entry for the forensic job. Was a really tough choice at the time
I love Forensics
Have a flat peice of metal (Spoon, small knife) so when you melt the end of the cord, you can flatten it without 3rd degree burns 😄
Rex, It is one of those.. Fun to learn, and when you are actually doing real live cases is REALLY interesting
Or just have asbestos fingers like me
Wow, 1840. I should probably drive home
1840? Positively Victorian
In your delorean?
I wish 😄
thoughts on va panels?
Not as good as plasterboard.
One issue running into so far, is I can't copy and paste commands into the Spice Javascript client, and since the VM is seperated on my network, I can't SSH to it to easily copy and paste commands.
That... and I can't fucking type -
Fast IPS is similarly cheap and doesn't have such sucky colours
u using vmware?
I love the field as a whole, but I only delve into when I was in uni and Computer forensics on my own.
Jumpbox time
Bastion hosts, go full enterprise
TrueNAS Scale, hosting a VM
I also read a few Forensic anthropology papers, fascinating subject
Rex - The HUGE negative is that as soon as you are involved in the process in anyway, You can be summoned to court as a 'Professional Witness'. And usually they would call everyone possible using what they call 'Defense of bodies'. If John can't make it, Well - our whole case hinges on Johns work, so we need to postpone y'r honour.
so glad i know about cyber security and using VirusTotal ! Been busy with archive.org and keep scanning whatever i download and stay cautious (all of the downloads are for VMs)
So I'd get the summons on a monday for the following monday, Then at about 1630 on Friday, I get a call saying I wasn't needed.
Only had to physically go to court twice
🥦 🥦 🥦 long time no see
🦖
@grizzled wing I'm in Argentina 🙂 I made it to my mum's birthday 🥳
Our witness statments were templates - 'Got exhibit ABC-1 at <time, date>. Opened it, extracted info, resealed at <time, Date>. Put info on a CD exhibit Esqy-1 and sent to the officer-in-charge'.
If anything, i can have the VM use the main network for now so I can get it configured, and once done, move it off main and onto it's VLAN..... but if I have to do stuff on it, then I still need SSH access, or copy and paste functionality
that is good news!
Heh OIC
Hehe, Thats the term!
Most of the OICs were cool though. HMRC/Border police were a bit more... 'Don't care, extract everything' So they'd get ringtones, default wallpapers, everything.
or.... I can just enable it access to intranet on my router side, so when I need to do work on it, flick that switch, SSH to it, do my job, flick it off, boom
Sounds like that server needs a Pentest...I might know some people...
what would you guys recommend to be the best modules for someone learning web exploitation for CTFs?
OWASP top 10 is a good'un for that
thanks I will take a look at that!
Juice Shop aswell, But I think thats more-or-less the same content
Be my guest, I would actually love to see it
By people, I meant Muiri and James 😄
UFW, ClamAV, Fail2Ban, VLANed. Soon OPNSense FW. Because... why. the. fuck. not.
i should do some THM , need some motivation
haha thanks
Jump on the new room, Veggies
Well, Juice Shop is a sponsored OWASP project....
exfilbur one?
I never looked into the link between them. I figured they were just different flavours of the same thing.
Like Apple and Orange Juice 😄
Yah. Scrubz suggest I give it a go. Depending when I finish in the workshop, I might do later tonight
That being said, Scrubz might just be shilling whatever is new...
reee, they aren't giving much for my car 
Wsg thm gang
😄
Hey I have a problem with a pc I’ve just built. So I click the button to turn the pc on, ram, case fans and gpu starts flashing its rgb lights. CPU cooler and case fans are working but nothing is happening. I mean for the 20-30 seconds monitors don’t show anything and it looks like pc is waiting for gpu fans to start working. Until gpu fans don’t start working then pc will not turn on fully. Anyone knows why is that?
Plethora of possible issues. From something like ram not being seated, to GPU not being seated or not having power plugged in.
You ever tried smashing it
I have fixed an old PC before with repeated knee blows to it's face plate
Everything works tho
I mean besides this one thing
Obviously something isn't
Ikr it’s crazy
I miss when technology was built like a tank and you threaten it into working with violence lol
You might want to take it to a actual computer store and have them diagnose it
Well my gpu is connected to the power if it is working
A computer not booting that was just built is really far easier to diagnose hands on
Motherboard have status lights and did you cross reference the manual?
no beeps whatsoever?
It has no mouth, but must scream.
My ps5 gets angry when I turn it on
Does new Mobos not beep when theres an issue ? am i too old ?
If u mean a white little light in the corner of the motherboard then it’s on the moment monitors starting to show smth
Not all systems beep anymore lol
Depending on the mobo, many have a little series of lights that can indicate basic info
your best bet would be Unplug everything and replug everything, if it still doesnt go on, then u need to go to a pc shop so they can troubleshoot each part alone
In your situation my first step is removing and reinstalling everything.
Second step is replacing parts 1 by 1 with known good parts.
Hardware troubleshooting can suck and be time consuming
also check the little pins on ur mobo, sometimes missmatching some can cause issues (its in the mobo manual)
Ah the goold old days when a server won't boot but has dozens of sticks of memory
Good luck finding the bad one
smtimes the mf would beep because they are not on the right channel, like u forget and mismatch the channels
Yeah but it's generally difficult to cross channels thanks to color coding
Then again
I had a tech on my team drill into a laptop battery
So
I don't judge
I believe people can and will do anything
Natural selection
Natural "do you know how much paperwork I have to do now because of you" career limiting selection.
IT department now run on tickets, i needed my bios battery changed once because when my work laptop died it reset the clock and everything, Lord behold he left me on read for 2 months and counting now
"Open a ticket and wait, do not message me"
Screw driver time
oh i aint opening company property laptop
they are leasing them so i dont wanna mess with that
I popped open my work laptop at that same place and upgraded the ram, had one of our engineers use his HDD cloner to clone my HDD to an SSD.
IT lady was cool with it
Ah
Ours were owned, and less than "new"
Im on a constant war with the sysadmin because he keeps blocking all the "High seas" website i watch stuff on
i discover a new site -> he blocks it -> i find a new one
I don't use my work laptop for anything but work, and spotify
i wouldnt be surprised if he sometimes come to the open space to slap me one day
Well had to sell my personnal pc for some reasons and now i dont have a pc beside the work one
Ouch
and i wouldnt want to run kali on my steamdeck either
so the cloud machines by THM were godsent
"Shhhh its only a live usb ;)"
lol. Just be safe man
they have this hardware control software that doesnt let u plug any external devices
I still wouldn't
so i had to go through FTP for file transfers, which worked for a while until it got too tedious
Save up and snag a cheap used laptop or such
Do that and keep your job safe.
Jokes aside, you would get in trouble for doing what i'm doing ?
even if its just THM so Cloud based machines
Generally from my experience reading over contracts, any physical manipulation of the loaded OS would definitely.
As for the cloud machine use might not be an issue at all. Unless they audit you and ding you for non-work use.
Even if they don't care right now, it can be a nice record for them if they suddenly need to reduce staff.
I always follow a work mantra that puts me above the easily disposable staff
Were all disposable. But make them actually have to work for the justificaiton lol.
I've read the contract, they allow non-work use to a limit
whats the limit? i dont know
It's what they define in their time of need
Which is ?
Ahh the beauty of a vague 'fair use' policy 😄
A sliding scale that benefits the company in the end
Kinda like infinite PTO policies eh?
Zactly
well i was indisposable until they added 3 people to my team which i taught and brought them up to the same level of skill i have, now i'm disposable
Which plays into your thing aswell. Any 'taking advantage' will be noted and used against you in a court of law
I sometimes make myself disposable, but as my entire skill set of developing teams. Result is instead I get moved around to implement Six Sigma concepts and standardize processes.
Being disposable is a valid skill set when you do it right lol
Yep. That's why I avoid it.
If I'm going to talk on Discord, it's phone or personal system for example
Alr I checked the led debug lights and it looks like for the 15 seconds after the clicking a button motherboard shows that dram is not connected and cpu is not connected, then it disappears, it shows that gpu is not connected and second after it boots whole pc
I'm working right now
i do have a small laptop with mx linux on it, shit has an old 1ghz amd processor, in an effort to make it usable i added 8gb of ram and an SSD, but oh boi 1ghz of CPU power IS NOT enough in 2024
Back in my day with my 8 mb Tridant 3D blade card
I had to wait, and I had to like it too
Wait isnt Discord encrypted ? they can log my conversations if i use discord on navigator?
beside a keylogger i dont see how ?
I just read them and remember them. Logged.
It's HTTPS but nothing more
They can see you are using it. And a great deal of company security software can take occasional screen shots.
Most companies don't go as far as keylogging, but they technically can
i'm starting to not like this as i'm leaning toward my credit card to order that cheap 200$ refurbished lenovo
Best to always seperate work and personal
Organizations often man-in-the-middle TLS
Meaning ?
Ugh. so unmotivated right now.
Meaning they can see the plaintext traffic
Everything you do on your system goes through their network and is entirely visible to them.
We usually go through Netskope as a VPN and Crowdstrike Falcon for device sec
Oh, @shut hawk Were you looking at those IQ-test logic puzzle things earlier?
Same visibility as ur ISP ?
More usually because they have access to your laptop at a software/hardware level and can call on info depending what software they have installed and running.
Do you have productivity software as well?
Like ?
Many companies who offer remote/hybrid jobs, and some micromanaging ones who are purely on site run software that tracks what employees are doing on their systems.
It can by as minor as occasional logs to almosy full on mirroring of everyone on a dash

oh, yeah? was wondering if it was normal for job applications to do them
Did i read that right ? anal Jobs ?
sorry couldnt focus on the rest
Fixed
@shut hawk Ahh. ok. I got a game on the Humble bundle called 'Mind Bending Masterpeices' called 'Taiju'... Puzzles in that remind me a lot of those challenges
perhaps the formal name is Remote Inspection and Monitoring Job
oh, send away - I love doing them
But from what i've seen its pretty chill here
It's on the Bundle 😄
they just route all traffic through a VPN with a site blocker, didnt see any more logging, how could i check if its being logged
thanks!
Hard to do. I always just assume I'm watched.
Easier/simpler that way
Don't like anxiety
Imma stick to the attackbox for now until i get a personnal pc, if all arises i'm just doing a cybersec course on THM
i take SSRIs for that stuff
I just started an SSNI

First week I was wired like a crackhead, for 2 weeks after that I slept all day, then since then I've been focused and capable.
I also take it for fibromyalgia though
It's nice to mitigate pain
is that some new update ?
is taking notes necessary when reading through Areas of defensive security
No lol
how do you guys remember all of that information
"SSRIs work by increasing levels of just one type of neurotransmitter (serotonin) whereas SNRIs increase levels of two types of brain chemicals, noradrenaline and serotonin"
Repetition
i do, i use Notion for note taking
I use One Note
notion vs hand written notes
as an academic written notes make u remember stuff WAY MORE, but notion is convenient for copy paste
You apply it. THM is really good because it has active learning where it will test how well you understood the information.
There’s flashcards too.
I also found you can do practice questions online for a certificate that has the topics you just learned
I'm just so happy that the network VLAN is finished. Now to debate if I need to add a dedicated FW server or not
Vlans are cool
Quick question, does premium also offer faster VPNs or are they the same as the free tier?
Very, my VLAN's can't see into my main network, and I can't see into it (The way I like it)
One of the reasons I subscribed because on free vpn nmap scanning never ends 🤷
Kinda. your nmap scan show you what doors exist. You then use your skillz and knowledge to knock on those doors and try to gain access. Depending on what you see will depend on what your next step is. See an http port (like 80) open? pop onto a web browser and see if theres a site.
And yes, you see FTP? there are a few basic things to try first.
This, over time, will become your 'methodology'
and is why notes are so important
nmap can also tell sometimes tell you what exactly is running on open ports
Yup. Thats where you play with nmap settings and built-in scripts
Nope. nmap is 'informaton gathering'. what you do with that information depends on what it is.
And thats what all the other THM rooms are for 😄
nmap can tell/show you open ports. and if ports is set as default for services you can tell waht service it is. and you can change port for each service
change port for service
FTP by defaulkt is port 21
You can host a website but it doesnt have to be on port 80.
you canb set custom, or non default port, to some other
In fact, CCTV systems regularly use 81 and 8080 for their web UI
there are industry standards for what protocols run on certain ports.
but there is no requirement that a server adheres to them.
Lets say you have 5 different web services - one for the public, one for CCTV, one for suppliers, Staff portal and a Members area. you COULD build all that into one site, OR have them on different ports and serpeate. so you'd have http://10.10.10.x:8080
There are standards - Like a web browser will look at port 80 by default
Like that list Ralex linked.
or 443 for https
Means that tools can be used (Not just hacking tools, legitimate things for productivity) and can point to the most likely ports
Am absolutely speed running slow cooked pulled pork
I also love waiting faster.
been in for 4 1/2 hours so far and it's nearly ready, threw it in and it's on 220c rn because I want to eat it tonight
also remembered apple cider vinegar this time so I've mixed some of that with some chicken broth, threw in some smashed garlic and half an onion and rubbed the pork in paprika, salt, rosemary and thyme. Shits gorgeous
You know you are a hipster when you 'smash' ingredients 😄
gotta get that flavour 😎
sounds like you've really gone for it though Burrish
It's cooked, so I've flipped it, removed the foil and am getting some colour on the other side and getting the other side nice and juicy
also 4.5 hrs is a sunk cost.. you sure you wanna rush it on the final stretch?
I literally got in from work at like 16:40, got it all ready and in by 5pm
(I can't cook, so I'm winging this)
Yeah I've work tomorrow and am going to have some tonight some tomorrow night
Get it ready the night before, and leave it while you're at work 😄
I'd love to leave it longer but I need scran and it tastes good now anyway
Yeah, I was going to and then ended up in a rush
but that apple cider vinegar's carrying, I forgot to buy some last time (when I first tried making it) left it for about 10 hours low and slow and it was great but it was missing something flavour wise (as much as it was tasty)
I borrowed my moms slow cooker ages ago. Feel like I should use it for something. apprently its mostly as easy as throwing a bunch of stuff in, pressing go and leaving it for hours
I'm doing mine in the oven 🤣
I debated getting a slow cooker but I wouldn't use it enough
pretty much. some veg, some stock, and some mince. perhaps a couple of mushrooms.
I think based on current flavour I'd either leave it longer next time or add a little more of the apple cider but it's amazing, reminds me somewhat of the butchers I'd go to and their pulled puck sandwiches which is what I was going for
I legit googled 'Can I put anything in a stew?' the other day. i wanna empty out my freezer, got a bunch of veg in there
Got some par-bakes to throw in as well later and so I'll put it on some crusty bread with some paxo cranberry and chestnut stuffing and apple sauce
Don't tell my family. As we are all Irish, I may be disowned for not ever making a stew 😄
My mum's irish and I love her stew but I don't really like potatos in stew as much as it's heracy to not 🤣
Not a fan of potato in soup either unless it's blended
baked potato is best potato. with a crispy skin 🤤
Love a good soup but I love a smooth soup
A half remembered fact - Doesnt potato serve a function? reduces salty flavour in a stew?
Baked potato is quite good but I can make banging roasties
Reduces the saltiness and adds starch which can help thicken it iirc
roasties are rather tasty too
I learnt from my mum that a little sesame oil on roast potatos is amazing
Like just a drizzle over the top
Roasted parsnips though... mmmmmmmmm
Especially burned a little around the edges
Fo drizzle 😄
My Mom cooked a ham in coca cola a while back. Then scored the skin, rubbed in brown sugar and then grilled it. That was soooo gods damned nice.
ooh very nice
Literally, my brother asks her to cook one for his family every year on xmas
Yeah i've heard of cooking in cola before, and heard it can have amazing results
coca cola? 😬
the acidity tenderises it and the sugar helps create a sweet glaze iirc
or the sorcery used to create coca cola is imbued into the meat.
So you get a sort of sweet and tangy result which is very tender, never tried it but heard good things
Either one is a legit theory
Have you heard about pineapple being used to tenderise steaks?
It's amazing how things can interact with each other when cooking
Never. although to me a steak is... a steak. peppercorn or Blue Cheese sauce, if I'm feeling fancy
yeah it's got enzymes in it which help break down the steak and tenderise it
Hello Universe!
Hi!
Like how pinapple dissolves your tounge if you eat too much?
Exactly like that
If you overnight marinade something in a marinade that includes pineapple, be prepared for a gross slurry instead
can only have a bit of it
bananas without b is pineapple
Bromelain enzime
screw it, Imma go to bed. Tired and unmotivated, May aswell call this one 😄
hehe... night night
good night 🙂
Y’all what should I say if someone asks about tryhackme. Someone did ask me and I said it was a hacking training site and they gave me a weird look. What should I say instead of hacking, like how do I explain it?
You'll Good?
Gamified
Oh yeah that would make it more friendly
Pineapple pizza!
Ew
Idc what anyone says pineapple on pizza is underrated
Gamified site to learn cyber security
It is a crime to eat pizza with pineapple on it
Hawaiian pizza
Oh yes
Pineapple does not be on pizza
Belong
I seen that delete Emerald 😂
It's OK. Mods can view them
That is probably the best way to describe it
Do you work in PR?

Can confirm, we can see deleted messages.
mmmmmm
banana
chicken
curry
peanuts
pineapple
pizza
Ngl I assembled the pulled pork sandwiches and me and my housemates had them, four rolls total, didn't even use plates, just ate straight from the cutting board, that shit was amazing
Got told it was the best pulled pork they'd ever had 😆
If you have any left over, mix a bit of the pulled pork into mac'n'cheese, top with a mixture of bbq sauce, panko and parm cheese, and broil in the oven until the mix crusts up a bit
That sounds amazing 😮 I've plenty left over, it's my scran for the next two days before I go to securitay 😄
Why you gotta do this to a hungry man
altogether? 😂
Crab cake sandwich 
with a NZ Sauvignon Blanc 🙂
Why you keep deleting your messages
well yes alll of that on a pizza is amazing
why want to do that to the pizza 😂 pizza it's amazing the way it is
if you want atroscities of pizza look at swedish kebab pizza which has iceberg lettuce on it

Holy eff, I just worked super hard for like 3 hours straight. I’m exhausted
Like, I went hard af
time for some grilled lettuce
Exactly my thoughts
Lol
I’ve been craving lettuce all day. It’s just what I need
Deep fried lettuce
Don't think I have that 
Chardonnay also good
Anybody here wanna help me shorten a list of 6 laptop's down to 1
But red 
i'll buy 2 for 10 bucks
A Soft, light body PN can work
I really need to create a wine collection document and share it with you @blazing granite 
Cava, Champagne, Prosecco, Riesling can work too
All the wine we have, vintage, just so I know what's what, where's where
but still white 🙂
eh
he
I gotta finish the wine I have now before buying more wine lol. Our shelves are full, wine we bought recently is still in boxes

meep moops it is shadows time for the sleepity sloopity sleep sloops to the beepity boops
Hi all, the Holo & Wreath room have lots of questions and I wonder if it is feasible to do a few every day or it is better to run it all the way?
I mean without having to redo all questions already answered?
you're asking if you can do some now some later?
yes
your progress on the target machine itself will be lost, if any, but the questions themselves will remain answered
Thanks, so it means i will have to redo all or some of them (completed) to continue?
you can do some of one task and some of others but you need to finish every question of every task to be able to get the badge
understood, i wanted only to understand if would have to redo questions to continue where i left. i seems its not like a permanent progress (questions will be answered, but to continue task 10 as an exemple I would need to redo task 1-9 )
it is permanent progress. You can do any question you like. lets say there are 10 tasks and i want to to the very last task. i can do that one and leave the others unanswered.
and to answer your question no you dont have to redo questions. they save once you complete them
o.o
how much did you remember
Thank you for your answers!!
your welcome
Thanks
Gave +1 Rep to @crude stump (current: #290 - 16)
what website is that AIO
Thanks, trying to go for 160 this year now with 100% accuracy
Gave +1 Rep to @noble nacelle (current: #1327 - 2)
Can do 160 but I keep getting 90%~ accuracy
I'd say, online playground for technical people to practice security best-practices in a safe environment
just reply with hackertyper.com
Ah localization woes, GG Microsoft. Yes I would like to unpostcode one file please
||zip being replaced with postcode due to British english find and replace in localization||
lol indeed
I'm not a UK Windows user but this is far from the first time I've seen this online, cracks me up
tangent, but i made my powershell accept yaml 😶
can't believe it's not native
only json is dumb
.7postcode files are now the new standard
kinda wanna start using that tbh
lol default open with 7zip will still do. Indeed
Think 7zip has a clear magic header
eh u can do it technically with any file
yeah but why would i 7postcode a txt file
yea probably although was thinking about manually unzipping it by specifying archive type
mhmm, the file utility on Linux usually tells you
Because what even is an extention on Linux c:
yea
also have u played deadspace?
the modern remake
I got about half way through the original game back in the day before getting bored
dovetail?
yup and the 4k is literally stunning
barely any grain
even
one thing following or being linked to another
morning
The 4K release actually does have a decent bit of grain but totally sane 35mm style
m
mornin'
hows everyone getting on today
yea
good right now, terrible before (had to be tech support for a few hours for relatives)
lol just mean that to say, old movies inherently have grain due to being filmed on... film, and scanned in.
It's typically how much processing and digitial noise reduction was done which decided how much (or which film stock). Most good remastere preserve the grain but it's not obtrustive in that it's "clustered"
Yea but like a few its quite clear grain
But in the thing its just not as visible
oh no thats not good. i always have my relatives come to me with tech problems
and the thing is the best name I could do
Somehow they all got the same malware on thier PC's and now its my task somehow to remove it
Seeing the grain is usually the sign of a good rip or restoration. I'd be a bit questioning if you don't see grain in many of your UHD remasters, but fair also laptop screen I'd venture
Like I can't describe the movie better than the thing although the name of the movie is about the thing which is a movie about the thing which is the thing
my previous landlord asked me for advice after someone supposidly hacked his tinder
😂
nice
when you tell people youre in cyber do they do the wee hand thing
Like its a grain level thing
2001 and robocop had more
but the thing had less
I'm petting my kitty but it's both inherent to the print and what processing was done
Also going to be watching the dollars triology next month
You got a kitty?
Good prints have more since they're preserving detail
it seemed like a good mix
got 52 things to find in metasploitable 2 for my internship this week
should be easy for you
eh switch to rustscan for a lil more speed if u doing so many things
yeah i will do
just need to work out what they keys are to press to get my curser back to desktop because its not the normal one for kali
hmm
its usually Ctrl+Alt but that isnt working ahaha
oh i dont need to click in i can just type thats good
I quickly looked at the rustscan github docs but didn't find: does it support like nmaps --script vulns?
Rustscans good, I forget to use it a lot of the time tho
The plague of habit. Using the same tools for the rest of my life to perform reconnaissance
Like making a subway order. Ima look at the menu and get the same shit I ordered for the past 8 years
what would you guys recommend to be the best modules for someone learning web exploitation for CTFs?
okay thanks a lot!
idk who saw the Sherlock drama last week
but the devs published a release v69 with an exe in response
yes
a guy called everyone on github stinky nerds
so he wanted .exe's
instead of .py
oh noes 🙂
eh thats different
not a active ctf
a retired one
did anyone send a ".exe"? 🙂
didn't even notice that one, lol
love his sign off too
So, herby, I request, in order to be more culturated, to add [..] sites to Sherlock.
Best regards,
a fucking degenerated
lmfao -
i applied for a role at this company the other day, and very quickly got a "we're not moving forward" email
a recruiter from said company messaged me on linkedin earlier saying i should apply for said role
Smelly nerds 🤣
Copypasta material
Your name 😂
😂😂😂
I can guarantee that they do not check the source code for anything they wouldn‘t like anyways. 
Scrolling further up makes me feel like I missed the joke. 😅
Anyone here tried the Seattle V0.3 ctf?
No, is it hard?
Well as a V0.3 it's probably not finished 😄
Not that hard just simple sqlmap and burpsuite work
But getting to the root is my problem right now.
Ah, you should be like a chameleon and blend in with your peers for help.
Not sure about that it was published at 2016.
I was able to get the admin credentials, but escalating to root not yet.
Still trying
So the admin doesnt have root?
Bet that was a rollercoaster of emotion!
It is 
If you got admin, there might be some SUID things you can exploit
I actually have the supposed root credentials but it isn't working when I enter it in the machine.
Huh.
Exactly.
Can the admin access the shadow file?
yes
And not able to get root from there?
Reeeeee
Karma - the description on vulnhub lists what it's vulnerable to.
Whatchu reeing about Bella?
Still annoyed that I mixed CCNA up with CCNP?
no, school being boring
I've now learned to read more than 3 characters in a course description 😄
Karma - Keep chipping away at it, looks like there may be a few different vectors of explotiation on this one
I actually found a walkthrough showing all the results of the vulnerabilities. But they do not show the exact way on how to get to the root. Just literally showing the root credentials and that is it.
Yeah I am trying to find solution
and the datacenter is full of people
Eew. Not people!
Thats just rude of them
Wish my lectures did this
😂
Im at the dentist, again
Pro tip, keep both of your front teeth whole and you avoid alot of mess
How are you peeps
Hello everyone! I am starting to learn SOC, but I have a challenge with the first question on the pre-security pathway. (What will be your role as a Junior Security Analyst?) Can somebody help, please?
It should all be in the text 🙂
@spring siren if you carefully read the documentation you can easily answer the question
#pre-security-legacy-path for further path questions
like @gritty zephyr told it is often given in the text
Which room do you suggest after finishing Jr Pentester?
I have read through the documentation and I have been entering the answer but still giving incorrect answer as response, I'm done with other questions and I got them correctly
Pentest plus, redteaming etc
If you just want to move on with the rest search up a walkthrough of that specific room
Finally able to reach the root, I fell into a rabbithole after all 🥳
Good Work, Karma
hi everyone
i just wanted to ask if it's better to invest in a premium vpn plan or stick with the free plan, some friends told me that my data will be threatened if i use free vpn
Yeah i think he meant data
yeah
Ask your friend why
Really depends on vpn provider if im not mistaken, some use your data, some dont i believe
But dont quote me on that, im a newb
There’s data protection laws and most VPN providers have a “piracy” guarantee
I’m curious on what your friend means by your data will be threatened
Thats true
Sold in the ways that are possible maybe?
Unless you consent, they can’t sell your data
his true location was exposed somehow
I don’t think your friend is a trustworthy source of information
well yea maybe lol he's an i don't deny that
Nah we’re not discussing that here
We can't?
Correct
Ohh alr
@rapid merlin yes
You will be muted if you discuss this
I wouldn't go with a free version, as there is often a reason why it's free. For example: https://www.youtube.com/watch?v=ql2vPGxe5Wg&pp=ygURc2V5dG9uaWMgZnJlZSB2cG4%3D
Your roundup of cyber security tech news :)
0:00 Intro
0:14 Free VPN Is Really a DDoS Botnet in Disguise
4:51 Smart Watches target US Military
8:38 Full Extent of Encrochat Operation Revealed
Sources:
Free VPN:
https://lecromee.github.io/posts/swing_vpn_ddosing_sites/
https://www.androidpolice.com/malware-android-vpn-ddos-botnet/?newslett...
sry
:mute: xdragon_dev#0 has been muted.
You were warned
thanks mate
Gave +1 Rep to @hollow pivot (current: #51 - 136)
did anyone succeed in getting metasploit container running? (phocean/msf) I cant get database connection.
docker run --rm -it -p8400-8500:8400-8500 -v $HOME/.msf4:/root/.msf4 -v $HOME/.msf4:/opt/msf/config -v /tmp/msf:/tmp/data phocean/msf
What are your reasons for using a VPN? That can also help answer your question
Cool, I thought it worked here
political reasons and identity disclosure, as im an activist in a 3d w country
Where do I submit a room that needs updated?
Basically an answer changed because the MITRE framework added 1 of the techniques. The correct answer is technically outdated by 1
I need some drill that goes hard
Well my labs are getting... interesting
I finish Uni in two weeks
lmfao
@lone thistle send drill xoxo
Scrubz, I ordered flavoured creatine because I dry scoop. It tastes so good, I want to sit here eating it
isn't armitage just a bad gui on metasploit?
it is
Drill? Search up heart warming drill
Good drill song
are you fr? 😭
Yes
This is like if Ed Sheeran watched top boy
I didn't notice but yea it does sound like him 
Looking for hard tracks, obsessed with this rn https://open.spotify.com/track/4V5er0Fzkjh4AZEFXoSTIr?si=fa182be41f954271
Literally my whole playlist
hehe u said ur playlists were private, we got a sneak peak
i feel like its the eldorado at this point
Private meaning they are literally set to private