#general

1 messages · Page 49 of 1

mossy river
#

So even if I sent you the link, it wouldn't work

flat hamlet
#

yea sadly but i wouldnt mind some public ones u liked if you could share em

#

u got great taste

mossy river
#

I got German, Spanish, lofi rap, rock, sad music, take your pic

#

rest are on Apple Music

flat hamlet
#

German, Lofi Rap for now

#

Die türen are a vibe

near hawk
#

I just listen to song once and if it sounds good like it

narrow phoenix
#

Bought premium and it wasn't activated but I received an email saying it is activated sadcooctus sent a ticket.

flat hamlet
jaunty scaffold
#

Is the ability to change users pfp via click jacking a serious vulnerability

mossy river
#

Nah

#

Low-medium impact

mossy river
jaunty scaffold
mossy river
crimson hedge
#

Hey can I have some technical questions?

jaunty scaffold
# mossy river What's that

state-changing requests, which refers to the type of request that results in data being changed from one value to another

crimson hedge
#

I use encrypted Jwt for authentication

#

with RSA algorithm

#

The question is

crimson hedge
#

Do I have assign each Jwt a different key pair?

jaunty scaffold
#

Yes

mossy river
#

It's fine here

crimson hedge
#

Oh, sorry

jaunty scaffold
#

The website ask the user to upload an image to win a prize but there's no prize and it changed user pfp in the victim site

#

two clicks to be precise

mossy river
#

@crimson hedge No, you don't need to assign each JWT a different key pair. You use the same key pair for signing and verifying JWTs

jaunty scaffold
#

The entire user setting page is framable

#

There's no protection for click jacking

#

Every page is framable

twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1176)

mossy river
#

Click jacking and changing the user's pfp completely changes the vulnerability score

severe seal
#

where should I put my token from thm?

jaunty scaffold
#

Is p3 serious

sharp citrusBOT
jaunty scaffold
#

I consider p3 to be serious

mossy river
#

Doesn't need to be bot commands, it's an empheral response

near hawk
#

p3 is like medium

mossy river
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1177)

severe seal
#

okay. how to regenerate it because I already used my token

mossy river
#

DM me your token please

jaunty scaffold
#

Right so may be cause some annoyance at most

severe seal
jaunty scaffold
#

Click jacking is not serious tbh

sick lance
#

Is it like sherbet?

#

I think so

jaunty scaffold
#

Thanks y'all

mossy river
mossy river
severe seal
hearty gull
#

is it some good site i can see examples of code with CVE's that is published and public?

near hawk
#

Exploit-db

mossy river
#

CVE detail usually links to them if I’m not mistaken

#

Nope that’s the wrong website hold on

#

Nvd that’s it

rapid merlin
#

Which one?

ember tartan
#

Does anyone know how to switch windows when in the AttackBox window???

Like I want to run WireShark while running the Terminal.
But when I use WireShark it takes over the whole right screen.
And if I want to view the terminal, I have to either move WireShark or shrink it.

Please and Thanks!!!

rapid merlin
#

ahh

shell nova
#

truth

ember tartan
# mossy river Are you in full screen?

Yes and no.

When I use full screen, on that window, I still can't switch windows as I please.
WireShark still takes over the whole screen.

How can I view different windows and what I can't figure out on my own.

quaint beacon
#

Hi,
can someone help me with openvpn connection troubleshooting

rapid merlin
quaint beacon
#

it seems no one is there to support

rapid merlin
#

Not now maybe

#

But in a couple of time

crude stump
quaint beacon
#

okay thanks for the update

#

will wait for response

sick lance
#

Oh you don't need e-mail for that

crude stump
#

He’s talking about the site support here in discord scrubs

#

Pretty sure atleast

junior wraith
#

got a revshell working from internal VM to an azure vm running metasploit as docker container!

rapid merlin
#

@mossy river time to delete a message! /j

mossy river
#

Boss, you need to chill

rapid merlin
#

Thanks sir

drowsy spade
#

sire

mossy river
#

Not old enough to be a boss

drowsy spade
#

16?

#

boss is a little bit shy

mossy river
#

20

drowsy spade
#

oh

#

uhm

#

you can be a boss on discord atleast

mossy river
#

nah

rapid merlin
drowsy spade
rapid merlin
#

No

#

Jabba is Jared

drowsy spade
#

jared is jabba

rapid merlin
#

Im reacting on your message xd

rapid merlin
drowsy spade
#

meow

grim sparrowBOT
#

:hammer: money_hmm#0 has been banned.

zealous stag
#

/wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords
any help
/wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords/introspect
/wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords/(?P<uuid>[\w-]+)

rapid merlin
#

Interesting

rapid merlin
valid mauve
rapid merlin
#

Oh ur right

mossy river
valid mauve
mossy river
#

Huh?

valid mauve
#

Unless you're saying that we do in fact have rooms on WordPress lol.

mossy river
#

Of course we do, there's tons of rooms on WordPress. I haven't been actively competing on the platform and I know that lmfao

valid mauve
#

Forget I said anything then. Gotta find time to dive into those.

rapid merlin
#

Btw who is #1 in points on the platform?

valid mauve
#

But first, turning pacemaker shell scripts into Ansible.

valid mauve
rapid merlin
#

oh thanks you three

mossy river
#

wut.

rapid merlin
#

Dutchie in fourth

#

woo

outer sapphire
#

can any mods help me?

#

someone dming me her with server invite

mossy river
tough island
#

If I were to change IP adresses and keep on connecting to the openvpn server, would I end up getting blocked? Are there any measures against something like that?

mossy river
#

They don't, that's not true at all

tough island
mossy river
#

You can't connect on the same tunnel on two different devices if that's what you're asking

tough island
#

No I mean if I were to connect from two IP adresses every day (not at the same time), could that get me blacklisted or something?

mossy river
#

No

tough island
#

Okay, good to know

crude stump
#

I don’t think that would ever get you blocked

tough island
#

Was asking since my OpenVPN connection just completly stopped working. I've been banging my head against the Keyboard for a couple of days now but nothing seems to work.

rapid merlin
#

Maybe try to download a new config file?

tough island
mossy river
tough island
#

alright

#

Did that

#

still the same thing

umbral bay
tough island
#

I tried all the different servers. Eu3 was the only one that worked and since that has stopped

#

Well, seems like I'll need to look at my PC settings. Maybe thats the problem

#

Oh that's actually a good idea. I'll do that

rapid merlin
#

You can, for THM?

#

But you have to do with the regular servers

#

So they are slower

mossy river
#

Please do not suggest this

#

We do not suggest that you chain VPNs and suggesting to bypass country or service restrictions is (potentially) illegal.

#

A restriction is there to restrict, not to be bypassed

#

wut

#

You need to use the OpenVPN service to connect to the TryHackMe OpenVPN servers

#

Yes.

quiet flax
#

Gitlab/Jenkins servers down again on cicdandbuildsecurity. Please vote for reset.

ocean hare
#

link

mossy river
sick lance
#

Yeah, state your subnet would be best

quiet flax
#

10.200.3.0/24. Jenkins is up but Gitlab is still down.

sick lance
desert shuttle
#

Hello all

rapid merlin
#

hii

bright flicker
#

Hiyaaaa

#

I need help logging onto my Remote Desktop 💀

#

Hasn’t been allowing me for days

#

And I googled ways to fix it to no avail

mossy river
#

I’m in desperate need of a meal plan worry_pray

bright flicker
#

👀

hollow pivot
mossy river
hollow pivot
#

I'm sure you can google that

mossy river
#

Didn’t ask you to plan it for me smh

#

Just a statement

hollow pivot
#

Well I've sent you one since i'm such a good friend

glossy portal
#

@mossy riverWhat are your goals with the meal plan?

mossy river
#

Bulk

glossy portal
#

Dr. Mike Israetel on YouTube, I'm assuming you're training too?

mossy river
#

I know what I need to do

#

But a lot of my meals are planned on a whim

#

Need to properly plan a routine

thorny helm
#

how do I send images

glossy portal
#

Eh, you don't really need one if it gets the job done

sharp citrusBOT
glossy portal
#

@thorny helm

#

One of your worries would be gaining weight too quickly maybe, I dirty bulked for a while, would not recommend

thorny helm
# sharp citrus

Need to use a different email from my tryhackme account since I use my personal one for discord and my school one for tryhackme

glossy portal
#

Get the token from the account you want to verify

mossy river
#

It’ll happen eventually but I’m just riding it out atm

glossy portal
mossy river
#

Nothing I can do, my body will slow down naturally

#

Until then, I just have to ride it out and do with what I can

thorny helm
#

ok anyway where do I report a glitch

glossy portal
glossy portal
mossy river
glossy portal
#

Makes sense, but I'm inclining towards the slowed metabolism being not significant enough, also the health problems sound rough

glass nest
#

Just live your best life. Eat as well as you reasonably can and keep active.

molten sky
glass nest
#

Live your most average life

languid radish
#

which room do you advise for learning to write shellcodes and make buffer overflows?

#

what are the main skills needed?7

near hawk
languid radish
#

thanx!

#

exactly what i am looking for

hollow pivot
#

This room teaches you some of the skills you asked, Assembly, CPU Registers, BOF

glass nest
#

Hiya DrG. How're things at THM towers?

hollow pivot
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 398)

glass nest
#

(In my mind, THM offices is like a Transylvanian castle)

#

Living the dream here. Researchin some cool camp gear I can try to make from wood

wild rose
#

Doc wanted to ask if the giveaway are physical books or ebooks?

hollow pivot
wild rose
#

cool

hollow pivot
#

I've read them, so might as well share the knowledge

glass nest
#

I heard good things about Coutdown to Zero day

#

I'm a big fan of 'the history of hacking' type books. Kevin Mitnick, Cliff Stoll etc.

hollow pivot
#

I will probalby add the hacker and the state to a future giveaway, just want to see if my dad wants to read it first

glass nest
#

Have you seen 2600's big book? It's called 'A hacker Odyssey' with tons of articles from since the mag started. It's amazing seeing 'New stuff' that is basically common knowledge or totally obselete now.

wild rose
#

What's your take on Lockbit 3.0 getting shut down by the FBI and Lockbit's ability to put up new backend so quickly?

glass nest
#

2600 can be VERY hit-and-miss. Some articles are all about a specific make/model of elevator system, but others are more general

hollow pivot
glass nest
#

Was released... Maybe 7 years ago, I think?

hollow pivot
glass nest
#

It's like hacking in a time machine

#

Dex, I only heard about it yesterday. But I've been focusing more on my workshop for the last few weeks, so not surprising

wild rose
#

It's pretty new. Not much information is out there besides the site the FBI took over and the release of decryption keys.

glass nest
#

Ahh ok. No doubt it'll be a hot topic on here in short order 😄

#

Most exciting thing in my city this week: someone found an unexploded WW2 bomb in their back garden, so 3.5k people had to be evacuated while the military transported it to sea for an underwater detonation 😄

near hawk
#

Oooo, the Devsecops path has now released

rapid merlin
#

oh lol yes

#

didnt saw it yet

glass nest
#

Just got the Ping. Blackout is on fire today 😄

tired peak
#

I might have to do this path... since its kind of my job

#

can you give me money?

glass nest
#

Only if its put towards.. well, You know what I want you to get 😄

tired peak
#

no, do not ask for money here

wild rose
rapid merlin
#

interesting

#

and they are provoking the police to hack them again

pseudo scroll
#

Krax is here animewave

glass nest
#

I can see Krax!

#

Woah!

#

not see you around in about a month

near hawk
glass nest
#

you mean, you used your elite-level OSINT?

pseudo scroll
#

Glad to see u Esqy bro

#

Howdy?

glass nest
#

Good to see you too. Any fun projects on the go?

wild rose
#

Not sure if devsecops is for me, but I'll give it a go to say the least.

glass nest
#

You might find it's the thing you've been looking for all this time

tired peak
#

DevSecOps is a great skill to have

pseudo scroll
glass nest
#

Zojja - True, but you are kinda biased 😄

pseudo scroll
#

What kinda DevSecOps?

glass nest
#

Very nice, Krax. Independantly or at sk00l?

pseudo scroll
glass nest
#

Good job on staying focused.

#

So can we expect some awesome hacking tools from you? the next WoW?

tired peak
#

I might have to become a subscriber again so I can do the entire path 🤣

glass nest
#

Just to show us lot how it's done?

tired peak
#

maybe

outer hound
#

what kind of hacking is this? 😅

glass nest
#

What flavour have you gone for Krax?

tired peak
#

I've been doing lots of KodeKloud lately

glass nest
#

I've only heard that a couple of times, Do you rate it Zojj?

tired peak
#

its pretty solid, especially if you looking at DevOps stuff

#

but it isn't cheap either

pseudo scroll
glass nest
#

the million dollar question though - Is it worth it?

tired peak
pseudo scroll
#

Code training?

tired peak
#

no, IaC, infrastructure as Code

pseudo scroll
#

interesting

glass nest
#

Is there a free trial of it or anything?

tired peak
#

looks like they have a week free trial

glass nest
#

basic package is $12 a month, paid yearly

#

Although that with a 40% at the moment

tired peak
#

yeah I have the Pro version

glass nest
#

Still, wasn't as much as I was expecting

tired peak
#

my husband does as well (we don't share accounts)

glass nest
#

Are you winning?

tired peak
#

always

glass nest
#

haha

tired peak
#

oh which reminds me, apparently I'm a higher elo than him (chess), we don't play against eachother cuz we like being married 🤣

glass nest
#

Hehe. My dads advice to my brother: Never play monoply with your wife

tired peak
#

yeah I lost so many friends with monopoly

glass nest
#

apparently Monopoly is the game that causes break-ups 😄

tired peak
#

I play to win

glass nest
#

Last game I played with friends was Pandemic board game. It's cool, cos it's more of a co-op style thing

nova pollen
#

Oh nice devsecops path ❤️

wild rose
#

Once someone doesn't have enough money to pay rent and has to mortgage a property, I lose interest with the game.

tired peak
#

no, let them mortgage everything, let me collect my monies

wild rose
#

ruthless and to the point. haha

buoyant tree
#

hmm going to do the new devsecops path

tired peak
#

yes, come to the devsecops path

pseudo scroll
#

Peace out guys, have a good one, cheers

wild rose
#

I need to finish the soc2 path before I start the new path.

wintry sluice
#

what is devsecops?

glass nest
#

I don't think I meet the requirements

wintry sluice
#

same. I have many prerequisite skills 😄

wild rose
#

I would need to pump myself up before starting it, but I'll scroll through the rooms first.

glass nest
#

Are you a tyre?

wild rose
#

Looks like I'm about halfway through the path. I should just keep going.

#

I'm more tired than a tyre.

#

Speaking of tyres, Formula 1 starts back up this weekend.

buoyant tree
#

but still going to do it since its a small pathway

nova pollen
#

Seems interesting. Looking forward to it. I’ll do that next.

glass nest
#

aye, does look intresting. Like... showing what the role actually is

#

This is a big moment, AIO. usually you are trying to choose between 2 things 😄

buoyant tree
#

can't get more bored

near hawk
#

Need to decide what to cook tonight

buoyant tree
near hawk
#

Nah

#

Had some other day

buoyant tree
#

rice?

near hawk
#

Also had that the other day as well

#

Maybe a smoked salmon

urban whale
#

woops wrong chat

tired peak
#

my appetite is all wonky, I've been enjoying soup

wild rose
#

soup sounds good for lunch

wintry sluice
#

Beans baked upon the toast

tired peak
#

you bake the beans on the toast?

nova pollen
#

You have time to eat 😅

sick lance
#

Baked potato, chicken sweetcorn, peas and some green beans for me.

tired peak
#

I love green beans in soup

hollow pivot
tired peak
#

and here I thought french food was... not good

hollow pivot
#

Pistou is like a pesto, which makes it even better

tired peak
#

yeah, looking now at a recipe

#

ok gonna have to make this

hollow pivot
tired peak
hollow pivot
hollow pivot
#

I put Beans mostly, green, white and sometimes red. I also add zucchini

tired peak
#

yes, zucchini is great in soup too

hollow pivot
#

You can also add a few potatoes if that's your thing

tired peak
#

potatoes are fine, I'd prefer those over pasta

hollow pivot
hollow pivot
tired peak
twin ridgeBOT
#

Gave +1 Rep to @hollow pivot (current: #51 - 137)

lone thistle
#

DevSecOps path 👀

tired peak
#

cmn, you are so 20 minutes late

lone thistle
#

well, if anything, I've known about it and worked on it for a year 😛

umbral bay
#

Ben is like a wizard, always exactly on time.™️

shut hawk
#

woah new devsecops path!

lone thistle
#

I believe the term is #fashionablylate. Much like most blue teamers to an incident 😉 /s LOL

tired peak
#

oh damn, throwing shade

wild rose
#

ouch

sand trench
sand trench
#

gotta update the path order

lone thistle
#

shoutout all the blue teamers

sick lance
#

Next path!

How to fix a printer

Soon™️

lone thistle
#

How about new path: cooking classes with CMN

#

May have to update our T&Cs that I'm not responsible for injuries though 🤔

#

i'm sure we can get it past legal

umbral bay
lone thistle
#

whattya think, tim/QA? 😄

shut hawk
#

as a room tester I 100% approve

ripe tartan
#

Really dumb question, But was was wanting to post a PSA for people who may be in the path for the Eclipse in the US in April, what channel whould you suggest I do that in?

sick lance
graceful thistle
#

PSA to the 7 people in there

molten sky
#

8

graceful thistle
sick lance
wild rose
#

oooh how to get the taste tester role?

ripe tartan
shut hawk
ripe tartan
#

But anywho, we'll try it here:

wild rose
#

I'll have to mark that down on my calendar

whole yew
wild rose
ripe tartan
#

It'll be my second total that I've seen

lone thistle
whole yew
molten sky
#

************

#

huh

glass nest
#

hunter2 did that work?

molten sky
#

yeah you're safe

surreal zodiac
#

I have a question for the THM admins. It used to be that when you completed the learning paths, you'd get a certificate with the number of hours that the path corresponded to. For example, "Junior Penetration tester, 64 hours."
However, it looks like that's been removed. Is there a way to get that back? I used THM to renew industry certs like CompTIA but it will only work if it lists the hours.

molten sky
#

wait, comptia accepted thm as CE?

#

first i've heard of that, lol

shut hawk
#

This is what it used to look like

clear jackal
#

If you get audited not sure if that holds up, ngl

surreal zodiac
# shut hawk Where did it say the hours?

You know what, you're right. It wasn't on the certificate. It used to be on the page with the learning paths and then when you clicked into the path, it said the hours.

clear jackal
#

At the least, it likely isn't able to be used for 64 hours

molten sky
#

yeah a certificate of completion and a certification are quite different

clear jackal
#

You can't even use SANS courses for that many credits

surreal zodiac
#

I called them before I submitted it and I think I also submitted a screenshot of the page with the hours.
I'll try to find that.

clear jackal
#

Unless you got it in writing, them saying it's OK, I would be cautious

molten sky
#

if you have it in an email or something tho 👌

surreal zodiac
#

I found it.

clear jackal
#

Yeah, if they audit you and you don't have it in writing all they have to say is "our representative was mistaken, please make sure you read our TOS and the acceptable CEU pages blah blah blah"

molten sky
#

If the auditor is nice they can sometimes give a grace period to come into compliance, but it's not guaranteed

surreal zodiac
#

This discord channel won't let me upload the photo. It's greyed out.

sharp citrusBOT
shut hawk
#

Attachments are locked to verified members only

surreal zodiac
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 480)

surreal zodiac
#

When I submitted to comptia, I submitted that screenshot with the cert for web fundamentals.

sick lance
#

IIRC I don't think THM ever told you how long you spent on the path.

shut hawk
#

How would it measure the time spent on a path?

surreal zodiac
#

Well, if CompTIA audits and rejects those, I have wayyyyy more than the minimum hours required between training that I've done, obtaining higher certs, and other activities.

sick lance
#

I'd just stick to stuff that gives the credits.

#

I got my E-mail for the Android Forensics.

shut hawk
#

Same

sand trench
wild rose
#

Are you saying he doesn't spell his legal name with 2 y's ?

molten sky
#

then they can be reversed too sometimes

shut hawk
sand trench
#

...

#

welp someone messed up

#

anyways anyone wanna help shadow with were to place this new path in the path order???

shut hawk
#

not sure yet because haven't fully gone through it

sand trench
#

hmmm good enough

#

thanks jayy

sick lance
#

The new DevSecops cert will have the new theme for me. 😄

sand trench
#

+rep @shut hawk

twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 481)

crude stump
wild rose
#

Is this helldivers2?

shut hawk
#

yes

sick lance
#

Looks like Destiny combined with Battlefield.

shut hawk
crude stump
#

Goty 2024

wild rose
#

How is the game? Thinking of getting it, but I'm free-time strapped.

shut hawk
#

Best to play it with friends

wild rose
#

sad... no friends.

crude stump
#

You could play with randoms

wild rose
#

I hear the servers are usually full.

shut hawk
#

Not anymore

#

They raised the capacity so it's fine

ocean hare
crude stump
grizzled dirge
#

is it worth getting? looks fun

crude stump
#

Yea

#

Most fun I ever had in a game before

sand trench
ocean hare
#

yes but they wil do both, so they might as well start with something practical and not the boring one

wild rose
#

I'll look into it. I'm pretty excited for FF7 Rebirth.

sand trench
#

DO NOT AGREE

sick lance
#

Me too, doube I'll play it though.

#

Too busy on CoD and Fortnite.

sand trench
sick lance
#

When I have some time from hacking.

sand trench
#

but pre-security fundamentals is super important to understand to have any form of foothold for practical practice

ocean hare
#

ok i forgot about linux fundamentals

#

sure

sick lance
#

@shut hawk

Did you ever get the warp terminal to appear?

shut hawk
#

No, didn't look into it

sand trench
wild rose
#

I just started playing fortnite with my nephew. He's pretty good at it. He's terrible at CoD though. I haven't touched CoD since it's release.

ocean hare
#

no

sick lance
#

I enjoy Fortnite, it's good for some mindless fun.

#

CoD I get more competitive at.

sand trench
#

annoyed at discord for not supporting custom themes in their official app which means people break discord tos to get it to look the way they want

#

eh for shooting games shadow enjoys battlebit remastered

sick lance
#

Emerald i sjust sad because they're terrible at it.

shell nova
shell nova
#

I'll take my revenge in other ways

crude stump
#

I’m crazy at fortnite

#

Don’t let me see you on the island

sand trench
#

well not a lot of shooting games that can be played on linux

sick lance
#

I need to pick up BBR

sand trench
#

it is a lot of fun... sadly vain and berrise seem to have swapped game to play so got no one to play with right now

wild rose
#

BBR?

glass nest
#

Bance Bance Revolution

wild rose
#

sounds about right :p

sand trench
wild rose
#

ah another fps

sand trench
#

yeah

#

it works neatly on linux for now as it uses easy anti cheat with the version compatible with proton/wine

whole yew
#

IMO the finals is the best BR game irght now

crude stump
#

That’s a battleroyal?

#

Thought it was a 4v4

sand trench
wild rose
#

I tried the finals and couldn't get into a flow.

whole yew
#

depending on mode, it's 3v3 or 3v3v3v3

crude stump
desert shuttle
#

Have i been inside too long or am i easily fooled?

sand trench
#

it is a very good illusion

pseudo scroll
#

How often do u go out/exercise, Shadow?

rapid merlin
#

Is there a room that teaches how to packet sniff and reconstruct a jpeg/png file?

hearty plover
#

Sometimes i do a room and im limited by my knowledge where im facing a problem or a solution i dont even know, is it bad then to watch a walkthrough?
If yes what should i do elsewise

#

Thanks for every answer

pseudo scroll
#

What are walkthroughs for then?

sand trench
desert shuttle
pseudo scroll
hearty plover
rapid merlin
#

My first few CTFs I had to read writeups only

hearty plover
#

thanks a lot for the answers regarding my question

#

❤️

#

such a good community whenever i have a question i get relevant answers man

#

makes me feel not dumb and alone on ma way

sand trench
pseudo scroll
#

I think the most powerful advantage of THM over other platforms is it's walkthroughs mechanism

rapid merlin
hearty plover
heavy temple
#

Hi is there an easier way/tool to crack a WiFi password without the need of using tools that require trying numerous wordlists and wait for so long until i get the password like in aircrack/ wifite?

desert shuttle
#

if this is on thm boxes before you click on it shows what it needed in the box like xss and such

buoyant tree
heavy temple
pseudo scroll
#

I prefer to read the walkthroughs and not quit the room unsolved

#

I want that flag :))

buoyant tree
heavy temple
#

Aight

naive violet
#

@heavy temple You know that's illegal right?

heavy temple
#

Would the "only For educational purposes" usage be a problem?*wink wink

mossy river
#

So you do know it’s illegal

pseudo scroll
#

That wink wink though :))

heavy temple
#

I don't really need his wifi just wanna test tools and the known script kiddie method doesn't always work

mossy river
#

But you’re aware it’s illegal right?

atomic aurora
#

Hey guys, maybe a stupid question but.. how do I change the username I see when using cmd? I tried looking for tutorials but I can’t seem to find a good one.

grim sparrowBOT
#

:hammer: msl.7#0 has been banned.

mossy river
#

🤣

#

I still am not sure if they know it’s illegal tbh

naive violet
#

They said wink wink

#

Pretty blatant and they're pretty evidently a muppet

pseudo scroll
#

That wink wink was so stupid :))

mossy river
#

They might have a twitchy eye

shell nova
#

Get yer own safe

sand trench
pseudo scroll
#

That bot name is TryModerateMe :))) cool

wild rose
#

Congrats to the giveaway winners.

sand trench
#

oh ey ralex won

#

Overcast ☁️ +2°C (-1°C): ↑3.1m/s: 87% humidity: 0.0mm: 1 uv: 1017hPa

sand trench
#

considering the amounts of lakes and rivers and stuff around here yeah it is wet

thin raft
#

quick question regarding the meterpreter agent that you inject in a system

#

it says it runs on the RAM and it is not written on the disk

#

how it is that actually possible?

#

like, suppose you are downloading a file from the internet (which is the meterpreter agent), wouldn't that be written on the disk first?

sand trench
#

look up ramdisk

thorny walrus
#

yipee

thin raft
#

I do understand that using an exploit, you can inject a process

#

that is understandable, but before you execute the program

polar spoke
#

disks are just really slow, cold, presistent memory 🙂

#

(not that that helps with the current question, but maybe for general understanding)

thin raft
#

understood, thank you

#

my question was related to the fact that in the Meterpreter room, you needed to wget the file from another computer from the same network

#

and wget command will "download" the file which will be on the disk? isn't that right?

#

then of course, after execution, it might get deleted

#

but first the file will be on the disk not on RAM

#

that was my concern

#

yeah, that is correct

sand trench
#

a good example is the eternal blue exploit

#

it never lands on disks as it attacks something already running

thin raft
#

I was thinking of the posibility of downloading the agent from a web page for example

#

without exploiting an actual vulnerability

polar spoke
quick cipher
#

what would you guys recommend to be the best modules for someone learning web exploitation for CTFs? intermediate level

thin raft
polar spoke
#

right

thin raft
#

most of the files will go to the disk

polar spoke
#

well, it depends

#

specifically, it depends on what tool you used to "download" the file

sand trench
#

all shadows files go to floppy disks

quick cipher
polar spoke
#

i disagree

glossy mantle
#

hello fellow humans

polar spoke
#

downloading just implies the file is being pulled across the network

#

not that it must be going to disk

thin raft
polar spoke
#

but again, that's perhaps a bit pedantic for the current conversation

glossy mantle
#

u know ai is a thing nowadays 😹

sand trench
#

ello other eldritch horrors

thin raft
#

thanks for the answers

polar spoke
#

and, in that regard, memory is on disk in some cases

#

though to be fair, i'm not sure how SWAP plays in for fileless malware or similar

#

as usually you aren't doing anything HUGE enough for that

#

right, SWAP is a whole rabbithole

#

lol

#

200gb malware

#

haha

glossy mantle
#

and fight agents

polar spoke
#

uncompressed 8k ransomware popup

#

gotta make it look pretty

thin raft
#

opinion on games hacking? sounds very interesting for me, but at the same time it looks like a burden to learn it. Besides that, it is illegal

polar spoke
#

careful

glass nest
#

Your last comment says it all 😄

polar spoke
#

Discord TOS has a specific "no game hacking talk" clause

#

so, perhaps better not to

thin raft
#

ok, then I will type it again, reverse engineering ?

glass nest
#

not really worth it. No end-game that I could think of which would be ethical. no need to even think about it

thin raft
#

that is why I mentioned it is a burden

#

to practice it you will need to create your own software

polar spoke
#

the skills for reverse engineering and such are useful in industry, but that use case has no ethical end game for sure

glass nest
#

Zactly, password chicken. Either way, Lets stay on the right side of the Mods 🙂

thin raft
#

don't worry, not planning to switch sides, just curious about it

polar spoke
#
Do not share content that violates anyone's intellectual property or other rights. This includes sharing or selling game cheats or hacks. For more information, please view Discord’s Copyright & Intellectual Property Policy.
#

the language has changed to be "don't share game hacks"

#

so maybe discussion is borderline

#

but i would still avoid it

glass nest
#

If thats the case, it would be in the advanced channels.

polar spoke
#

agreed, the server rules apply as well, so if anything it may need to happen elsewhere even if discord themselves arent super strict

glass nest
#

Anyhow! Vegtable Gyoza - Delicious or no?

thin raft
#

I am not sure if the algorithm of discord goes through it all, tbh

whole yew
#

It's not allowed here at all, as far as I know. Because of the TOS.

polar spoke
glass nest
#

The.. gyoza ones 😄

whole yew
#

Vegatable Samosa's are a solid dumpling choice

polar spoke
#

i'm a fan of gyoza with leek in it, but usually leek is mixed in with pork or chicken or similar

#

so it sorta depends still

glass nest
#

A solid choice of dumpling, or a choice of solid dumping

#

I don't think i've ever had a bad Gyoza.

thin raft
#

aren't there red teamers for the gaming industry also ? lol

polar spoke
glass nest
#

(Or Esqy and Chicken change the subject really subtly)

polar spoke
#

lol

paper notch
#

Hello is there any ai that can help with my german homework xd?

glass nest
#

i'm craving Gyoza, so It was all I had on my mind 😄

polar spoke
glass nest
#

The one inside your mind, Daki 😉

paper notch
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 399)

glass nest
#

Honestly, I'm a Dim Sum feind. Also Sushi. And tapas. Anything thats 'Many tiny foods'

paper notch
#

so theres non of them

glass nest
#

It's like being a giant

#

Daki - Cmon man. It's your homework. to prove YOU know the subject.

#

Not to prove you can ask a computer.

#

Also, languages are fun

polar spoke
paper notch
glass nest
#

Pfff. Asian supermarket. Get it froxen, then steam to perfection 😄

#

Daki - Yes, it is. Many industries are HUGE in germany.

paper notch
graceful thistle
#

Motivated

glass nest
#

You got this. German isn't all that hard once you get into it

whole yew
#

Tamagoyaki is one of my favorites

glass nest
#

What are those awesome octopus ball things?

#

Takoyaki maybe?

#

That being said, I would climb inside and live in a Char Sui Bao if I could.

whole yew
#

takoyako are the fried octopus balls

#

tamagoyaki is the rolled omellot

graceful thistle
#

Hmmmmm you got me thinking about making some okonomiyaki now 🤔🤔

#

Havent eaten that in years, time for some experimentation

sand trench
#

food?
food!
food food...
food food food!!!!

nova pollen
#

shadow seems hungry

fair geyser
#

Is it risked to stream my CTF ?

mossy river
fair geyser
#

I saw some ppl hiding it

mossy river
#

imo it's more effort than it's worth to hide it

glossy mantle
#

food!?!?!?

sand trench
#

food food

nova pollen
#

sometimes i wonder if this is code for something which i just don't understand yet.

sand trench
# fair geyser I saw some ppl hiding it

generally that vpn ip will at worst get someone to be able to get into your vm... but in nearlly all instances nothing will happen if you share your vpn ip

halcyon wyvern
#

Hey, theres one question i seem to cant figure out

What language is best to learn? C#, C++, C, Java, Python, Ruby??

nova pollen
naive violet
#

There's no best

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 1646)

glass nest
#

Depends what for. If you're not sure, Roll a dice.

nova pollen
sand trench
nova pollen
#

Has a lot of “it depends” in the answer.

glass nest
#

Also, if you learn 1 fairly well, most of the programming concepts carry over, and there are just differences in Syntax.

halcyon wyvern
glass nest
#

The basics are largely the same

halcyon wyvern
glass nest
#

The biggest difference in lagugaes are if they are object oriented or not. I prefer it, but some others don't

halcyon wyvern
sand trench
glass nest
#

C++ for general use, python for scripting, C# if you wanna develop an app

chilly veldt
#

whitespace

glass nest
#

this is where the 'it depends' comes in 😄

glossy mantle
#

me want to learn assembly 🤩

nova pollen
#

What the software you are writing does. How fast it needs to be. System / hardware it is running on. And so much more.

glass nest
#

BUT if you are only starting out, any of the ones you mention would be ok. Honestly though, I found C++ to be fairly straighforward. Python is really easy to learn

nova pollen
glass nest
#

Fair fair. I've only done a TINY bit of C#

nova pollen
#

But smart pointer etc made it easier. But debugging is still way easier in other languages especially for beginners.

sand trench
#

has made a game using xna in c#

glossy mantle
#

is rust hard to learn?

shut hawk
#

subjective

nova pollen
#

C# just supports so much stuff out of the box which you need to write yourself on c++

glass nest
#

White tiger - honestly just pick one and go for it. C# is a nice option.

#

(based on what NeedSleep said)

nova pollen
#

But switching later from c# to c++ is fairly easy.

mossy river
#

This protein powder is so good, it's like nesquik

shut hawk
#

having prior experience will certainly make it easier, the rust book makes learning it a lot easier

glass nest
#

Just don't get FOMO. Everyone has their fave 😄

flat hamlet
#

Thing is you'll find yourself writing stuff in many languages, just pick one to learn the concept, after that you adapt to your needs (i started with Python, ended up with C++ for Arduino and Kotlin for Android)

glass nest
#

Python is almost pseudocode 😄

flat hamlet
glass nest
#

Just say what you wanna do and Python will do it 😄

desert shuttle
#

i like the strawberry nesquik

flat hamlet
#

but hey, we dont want to reinvent the wheel

mossy river
#

Teachers: Don't write Python as pseudocode, it's not the same!
Me: Writes Python and gets the highest grade

nova pollen
#

just in general, pick one and stick with it. switching languages with different syntaxes (even slightly) will mess you up 😄
switching later is much easier. most of the languages share a lot of syntax.

mossy river
glass nest
#

You don't wanna define a variable type? Don't worry, I got you!

nova pollen
lament mantle
flat hamlet
boreal scarab
#

Y'all hate it when your project is finished.... but want to do a brand new project, yet don't know what to do?

mossy river
#

Don't forget HTML

nova pollen
halcyon wyvern
twin ridgeBOT
#

Gave +1 Rep to @lament mantle (current: #304 - 15)

boreal scarab
#

Actually @glass nest . You gave me a good idea

glass nest
#

Oh no, What have I done?

boreal scarab
#

Well.......

mossy river
boreal scarab
#

Nah, I need to fix my trueNAS PiHole to allow me to access my router because it's using https now... but Asus wants to be Asus and be a TINY bit PITA

#

So I can free up that Rasp Pi currently as my PiHole to make into OctoPi for my printer

glass nest
#

Oh sweet.

nova pollen
#

i don't say it is useless, just not a typical programming language

glossy mantle
#

nice name PiHole

mossy river
glass nest
#

But the internet is Srs Bsns!

nova pollen
#

🙂

boreal scarab
#

But need to test some of my devices on teh TrueNAS PiHole, before doing the DNS swap on the router

glass nest
#

DNS... shudder

boreal scarab
#

Yah.....

#

Fuck DNS

glass nest
#

The cause and solution of so many challenges

boreal scarab
sand trench
#

is that a haiku???

boreal scarab
mossy river
nova pollen
#

Just went through the phishing module. i did not know open source framework like that exist 😄 explains a lot.

flat hamlet
sand trench
#

it is even worse if you have the auto animate off

hot cairn
sand trench
#

stupid backbone internet

boreal scarab
#

Riddle me this...... I can't access my Asus Router from my TrueNAS PiHole, but I can from my Rasp Pi PiHole........ I COPIED THE DAMN CONFIG

boreal scarab
wild rose
#

Yeah we had issues where our BGP was being rerouted "unnaturally" through China, whenever we're close to introducing a new product to the market.

flat hamlet
nova pollen
boreal scarab
#

I broke it.....

glass nest
#

Beerise, have you seen 'The Fly'? Just a warning for your teleporter

boreal scarab
glass nest
#

If only building stuff was an easy as hitting it with a wrench...

wild rose
#

Good ol' TF2. I miss those days.

boreal scarab
glass nest
#

Yah. Hat Fortress 2

blazing granite
# boreal scarab I was waiting for the *-Sun Tzu*

All warfare is based on deception. Hence, when we are able to attack, we must seem unable; when using our forces, we must appear inactive; when we are near, we must make the enemy believe we are far away; when far away, we must make him believe we are near, Sun Tzu

flat hamlet
#

Yup
-Sun Tzu

boreal scarab
#

WOOOOOOO. Got my TrueNAS PiHole working now! LETS GOOOOO

chilly breach
#

how to start in the world of hacking?

glass nest
#

buy a black hoodie

boreal scarab
blazing granite
glass nest
#

GNU-rex is also right though. #start-here Is also a fine option.

flat hamlet
#

Oh and use the Kali Linux wallpaper for your phone 😉

boreal scarab
#

Remember Remember, the 5th of November. the Gunpowder treason and plot. I know of no reason, why the Gunpowder treason should ever be forgot.

#

V for Vendetta is AMAZING

hot cairn
blazing granite
flat hamlet
boreal scarab
#

I think I can cut my DNS on my router over to my TrueNAS instance now. LETS GO

glass nest
#

Famous last words

#

'It's always DNS' - Sun Tzu

blazing granite
naive violet
#

@glass nest satellite ground station fixed and recieving satellites 😎

boreal scarab
glass nest
#

Eyy! Nice!

chilly breach
glass nest
#

Whats next?

naive violet
#

Looking to expand it and replace the antenna long term but that's a high effort project

boreal scarab
glass nest
#

This is where you need your own hose

chilly breach
blazing granite
glass nest
#

Wolf - #start-here Is a solid step. Basically, Log on to tryhackme.com and start on one of the paths. Some are locked behind a subscription, but you can skip those if you don't have the resources to get a subscription. Most of the rooms (A term we use for the differen tutorials and challenges) are free

boreal scarab
crude stump
naive violet
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #19 - 400)

glass nest
#

I meant house, but a hose is useful

naive violet
glass nest
#

Yah. Having a workshop for the thing you enjoy doing is like having a little slice of heaven

crude stump
glass nest
#

Except that it gets messy as hell, and I've no idea how those youtubers keep theirs so tidy

woven prairie
#

hello guys

naive violet
#

Listening with an SDR is way easier, cheaper, and generally more legal than any transmit

glass nest
#

Maybe cos they are massive compared my single garage

woven prairie
#

i know it is not related to THM but is it safe to use protonpass browser extention on my hacking virtual machine? if it gets hacked is it possible that they access proton pass too?

glass nest
#

G'd evening Chara

naive violet
boreal scarab
#

Ayyyyyy cut over my laptop to my TrueNAS PiHole DNS and it's looking spicy. Lets GOOO

glass nest
#

It's like the network issue was resolved and the floodgates opened 😄

naive violet
#

Esqy, you worked with copper pipe before?

boreal scarab
#

Connects laptop to TrueNAS PiHole

TrueNAS PiHole Blocks: ALL NVIDIA

woven prairie
quiet pulsar
#

helloo

naive violet
crude stump
#

Long

glass nest
#

Allo Vibes 🙂

quiet pulsar
glass nest
#

How goes the challenge?

woven prairie
#

i mean i have pin code on proton pass tho

quiet pulsar
#

been a while

quiet pulsar
desert shuttle
#

enum enum enum

naive violet
glass nest
#

😮

boreal scarab
#

Bout 2 minutes my laptop has been connected. bout 10 for my mobile devices.... NVidia really wants to get info XD

naive violet
molten sky
#

I'm trying out co-pilot rn
it just suggested a comment for one of my code blocks that was like "This is a bit of a hack, but it's the only way we can do this right now. It's not perfect, but it's the best we can do."

naive violet
#

Geforce Experience

quiet pulsar
woven prairie
quiet pulsar
#

my eyes are burning

crude stump
glass nest
#

ok ok. getting closer to that free subscription 😄

naive violet
sand trench
wintry sluice
#

free subscription?

quiet pulsar
glass nest
#

rswallen - I set Vibes a challenge

quiet pulsar
#

its weird for some sites

boreal scarab
# naive violet Geforce Experience

Oooh, well I've had it on my laptop, and my desktop for a very long time. But PiHole always blocks it. Never had any performance issues on my Rasp Pi PiHole with that many requests. As far as slowing down my rig, no issues here either.

sand trench
quiet pulsar
#

all im missing

naive violet
quiet pulsar
#

pg

molten sky
#

damnit you read it faster

sand trench
#

true

naive violet
#

@woven prairie Keep it appropriate for an educational environment.

wintry sluice
#

dunce for fudge?

quiet pulsar
#

how does openvpn work

#

like with the rooms

#

i have it connected

#

but do i just use my terminal normally now?

wintry sluice
#

yh, just use the vpn ip when rooms what the attacking ip

#

easiest to just open another terminal

quiet pulsar
#

and how do i connect to it through the terminal?

polar spoke
#

oh is this for a VM to use for malware? don't log in to sites where security matters from VMs where you plan to sandbox malware...

wintry sluice
polar spoke
naive violet
#

The ones that change wallet addresses are insane

polar spoke
#

yeah exactly

#

lots of cute tricks to be had with stuff like that

naive violet
#

Also hashcat is still awesome so thanks for your work on that

desert shuttle
#

yes thank you a lot

polar spoke
#

just wait until the next gen stuff comes out

#

gonna get even more awesome

molten sky
#

..next gen?

#

am intrigued

polar spoke
#

🙂

#

soon™️

wintry sluice
#

hashsabretooth

sand trench
#

well there are others yes but dark reader is more trusted then most as it is free and open source software

wintry sluice
#

doubt you'll find one that doesn't have that permission. it needs it to make the background dark

naive violet
#

Of course it does...

molten sky
polar spoke
#

lol

naive violet
#

Read - see what's light
Write - make the light bits dark

wild rose
#

hashlion

boreal scarab
#

I'm excited to do the cutover to my TrueNAS PiHole.... but also, kinda worried about the DNS shit for the Asus Router borking up where I can't access the router anymore... but should be fine, cause same exact configs

#

Yah, from my Rasp Pi Pihole DNS to my trueNAS Server PiHole DNS

#

It works! I can finnaly use that Rasp Pi as OctoPi again!

#

Always lovely to see when doing changes, that one system has 0 updates, and the other system has all the updates (updates being queries here)

#

AsusWRT

#

Kinda stock firmware... just beta version of the firmware for more VLAN control

#

Nvidia go nom

molten sky
boreal scarab
#

I've looked at it, but even Merlin doesn't have the control I like. For example:

I can config a Guest VLAN to not allow intranet access on ethernet connections, or wifi connections.

I have a 2nd NIC on my server, going to a specfic port on my router (Could be any, but this one is 2.5g port) I can set it to use that VLAN profile, then anything on my server,m I can config to use that NIC besides the main network NIC

#

Anti-Telementry, annoying ass ads... malware sites, etc. + Got it going through Quad9, Filtered and DNSSEC

boreal scarab
#

Don't worry, easier than it sounds.

#

If a monkey who can break countless number of operating systems can do it, anyone can (that has IT knowledge lol)

#

Fuuuuu, something is still using my Rasp Pi Pihole...... time to hunt it down

loud marlin
#

How Gonzo DOXed 3 ppl with no books 🙂

loud marlin
#

you need verify

sharp citrusBOT
boreal scarab
#

Best part about my router: I can export it's client list. I couldn't do that with my ISP router... crappy thing

loud marlin
#

is there any useful thing that you ever can do with default ISP router ?

boreal scarab
boreal scarab
#

Made 0 sense why..... Tech who installed it did that. Didn't do that on my new router, cause yours truly... surprisingly... knew what I was doing, unlike that dumb as hell tech

shell nova
#

mwahahahahahahaha!

#

IT WORKS!!!!!

loud marlin
#

dheck

naive violet
shell nova
#

what?

#

it's umm C?

#

why is making shit insecure so damned hard 😦

naive violet
#

Jboss?

shell nova
#

eh that's what the base image uses

#

as a username

bold latch
nova pollen
#

I turned blue 🥳 with 49 minutes to spare before i get my 90 day streak badge 🙂

shell nova
#

too lazy to try to force the change

naive violet
boreal scarab
bold latch
#

I ended up finding a definitive solution for my homeserver's OS in the meantime, by the way. Looksl like I'll be rolling with a ZFS cluster on ProxMox with an Ubuntu Server running on it

shell nova
bold latch
shell nova
#

though to be fair I think that might just spike the difficulty from easy to wtf

shut hawk
#

I prefer AdGuard's UI

bold latch
#

Isolated away from the main Ubuntu server, so it's secure and away from grubby hands

boreal scarab
#

The ONE thing I will miss with the Rasp Pi Pihole, is the automatic gravity list updates. Had a cronjob to do that.... So gotta see how I can do that with the TrueNAS instance

naive violet
#

Nothing good ever came from Java

bold latch
# shut hawk I prefer AdGuard's UI

Yeah, the UI and installation is apparently more hands-off than Pi's and the features out of the box look better, like DNS-over-HTTPS. But Pi seems to be endorsed as more customisable by others

#

Yes, I'm also familiar with that non-root feature as well. Pretty neat

loud marlin
#

Alcohol is more social acceptable to drink public than milk... =/

shut hawk
shell nova
#

anyways I'm not planning on submitting it to THM....yet

bold latch
#

Does it support making custom local DNS with name-ip pairs and recursive DNS? I've not dug around to see if that's the case

thin raft
#

as a quick question, I can see that both Red Teaming and Offensive Pentesting are Intermediate difficulty and they are both recommeneded after the JR Pentest room si done. Based on your experience, what would be the next room to start with (preferably based on difficulty)

bold latch
thin raft
#

understood, thanks for the opinion

whole yew
shell nova
#

truth

#

hi juun

thin raft
shell nova
#

I made a thing. It's only moderately evil

frozen mural
#

tip: when you want to participate a room with your mate on the same network (hack the same server), use the same access file (openvpn file)

bold latch
#

Offensive Pentesting just feels like a slight extension to JR Pentester to test knowledge, Red Team adds in proper evasion techniques, logging evasion, all that cooler jazz

shell nova
shell nova
#

yeah you risk a site ban

whole yew
thin raft
#

I plan to go to some CTFs before starting the Offensive Pentest room