#general
1 messages Β· Page 50 of 1
glhf
I didnβt know this, really?
I will go with the easy ones, by any chance would I be able to do maybe the medium ones also?
@mossy river want to chime in on this?
if the easy ones are too easy, try a medium
Sharing the same VPN/IP is messy either way
Anyone used Cloudflared DoH before?
great, thanks
Gave +1 Rep to @shell nova (current: #12 - 550)
why wouldn't you use your own VPN file?
doesn't guarantee the same network
ahh
Because platform does not allow two users to participate same room
I mean if you were on the same network, you could access the same systems
yeah let's not abuse that please
wait you can blacklist uses from gaining rep?
apparently
I do tend to wonder if THM will have that sort of feature someday. It seems intuitive for people seeking more hands-on mentoring, or a solo game of who-can-hack-it-first rather than a public KOTH
Sharing deployed machines, that is
I tried to give 1 rep to Robocop, just needed to see what it does
blacklist scrubz when he's 1 away from getting #1 
is there a way to see your rep?
you can technically access the same room (outside networks) with different VPN profiles
yup! do !toprep in #bot-commands
How?
So if you share the machine's IP to another user, you can both join the machine?
basically anyone on the network could access your deployed systems
just for troubleshooting
ye
VPN gives access to the 10.10 range
In the linked message Jayy posted, Jabba did say "no sharing deployed machines" specifically so it is still currently unallowed
I don't think I can, but thanks for the info, it says it was disabled by server admins
Gave +1 Rep to @shut hawk (current: #13 - 482)
that's why I said I wouldn't risk it beyond troubleshooting
You didn't do it in #bot-commands ....
but not technically unallowed
You did it here, in general
lol, you're right
Well, if boss says, it goes
Sharing deployed machines goes against our terms of service
yeah but so does sharing vpn file
Huh?
they were talking about sharing a vpn file to do the same room / system
Hi boys i loking for a team
"boys"
Yup, still against ToS, see "Account sharing"
To CTF competition
Is there any legal way to access the same server while solving a room?
Who can join to me
It would admittedly be a neat feature
why not do each of your own machines? if its the same "room", the systems should be identical
Other than getting lucky? No.
Regardless of you being on the same machine, you're not exactly going to see each other anyway
It's not designed to be co-op
A co-op feature would be awesome tho)
see here for some reasons why it might be neat
As long itβs not authorized by THM policy then forget about guys, I didnβt know that
Who can come friends
Hey guys i have wrote a script for a blind sqli in shell script where to post this code to allow others to check it and to improve my code?
to exploit?
Boot2root isn't really a cyber profession
@evreyono
Ok
And I don't think it's really about speed, I think that sends the wrong idea.
Yah, I use Q9
I am looking for a team help me please π
Of course, it's certainly not. Just for the individuals who struggle with some machines
We saw.
Do you want join
if someone is interested they'll reply
check Github, make sure you don't share any sensitive information there
Thanks man can you help me?!
Gave +1 Rep to @shell nova (current: #12 - 551)
nah
what exactly are you trying to exploit, is this for THM?
It isn't, yet KOTH hits it off quite well. A private lobby system for premium users or organisation/uni teams doesn't sound bad
thanks i will change it from private to public
Gave +1 Rep to @thin raft (current: #2011 - 1)
Also, bit of a farfetched concept, but imagine simulating a red-blue team engagement with a shared network of sorts over the THM servers
only use this as a POC and explicitly mention not to use for ilicit activities
I want be professional in CTF challenges web and network can I improve my self
Yes you can, #start-here π
Please boys help me i want learn
Jay gave room, you click room, you learn
it's not only for THM the idea is to build a "easy" quick blind sql script.
i want to make the "PEN-200: Penetration Testing with Kali Linux" and there is not sqlmap allowed..
I am in the top 1% in THM
Take it easy, watch some videos, hop on the platform's learning paths and be patient with it
that's pretty meaningless tbh
The help comes after that
But I still think i am very weak
You realise we have a wide variety of users here, that includes people who aren't boys?
then keep practicing
And do some reading outside of CTF platforms, for that matter
Pick a topic and your favourite search engine
blind sql takes for me allot of time... and i have only 24h to pass the test
I'm sorry but I didn't talk any one before forgive me
Or dockerized SearXNG if you fancy multiple
thought it was 72
No problem, I'd just recommend being more open with your requests
or is that the report phase
What is the best website to practice
hmm... if Voldemort wish to find harry he just need to write letter, give it to owl and then follow owl on that fly stick...
from my knowledge it 48 hour, but only 24 hours to get all flags and the next 24 hours to write the dokumentation
I hear tryhackme.com is good
I'm playing every day but i think i am still weak
Implant a gps tracker
never heard of it 
Thanks β€οΈ
Gave +1 Rep to @shell nova (current: #12 - 552)
I mean are phone books still a thing?
smart smart... apple tag thing...
I want friends to play together
Plenty of people here will say the obvious choice, TryHackMe.
HackTheBox is an alternative people tend to go for after TryHackMe, because it's got somewhat tougher machines and a more competitive aspect
And then you have websites for research, like Maldev Academy, Sektor 7 and other similar places
If you got cash, check out Offsec and their various courses as well
I ve heard that Offsec is quite good despite the prices, is it an industry standard?
Look at some malware samples (safely and in a sandbox/VM) from VX-Underground maybe
Thank you very much π
i know allot of it sec will accept you as pentester if you have this certificate, without your are kown in the "secene"
Imagine Voldemort looking up harry in it lmao
car insurance π
I have no personal experience with it, but I've seen it endorsed very highly while looking around; its certifications are definitely looked at by plenty of figures in the industry and it's a cornerstone in the world of pentesting by the looks.
To give you an idea of their involvement, they're the people behind https://www.exploit-db.com/ if you've ever used it.
https://www.vulnhub.com/ is also ran by g0tmi1k, who is a Live Instructor at Offsec
Several members of the main team behind Kali Linux itself (see https://www.kali.org/about-us/) also teach and run courses in Offsec
VulnHub provides materials allowing anyone to gain practical hands-on experience with digital security, computer applications and network administration tasks.
Congrats @loud marlin
Heya
Hi
I want study privilege sclation more any one knows how to be get more informations
google ?
I mean resources
well... start with THM, then expand around google, YT and so
there is one book i know that might help
yeah, that is why I mentioned the word "industry standard" so it is quite nice
Thanks πβ€οΈ
Gave +1 Rep to @loud marlin (current: #26 - 287)
or smoke some funny flower π
π¨
well that is one way to get sent to the hospital for smoke inhalation
Cleanses the the nose
Welp Quad9 DoH using DNSCrypt on pihole has so far been a bust...
Could you help?
Β―_(γ)_/Β―
I've spent like 2 hours trying to get it to work just on my old PiHole before I put it on my TrueNAS PiHole
shadow did do that a long while ago ( about 9-12 months or so ) before switching to nextdns
this on the other hand sounds like what shadow did: https://hndrk.blog/tutorial-pi-hole-and-dnscrypt/
@boreal scarab
Thank you!
Gave +1 Rep to @sand trench (current: #4 - 1647)
no problem
me also going to set it up
was using pihole with quad9 b4
privacy
nobody can trace u by ur DNS requests
your orgin Ip is still exposed
nope dns by default is not encrypted
it is starting to become more common with dns over https/dns over tls
and the old dnscrypt protocol
Gets REALLY complicated really fast when it comes to DNS
but it still doesn't make you private
those are not by defaults for dns.... but yes those are getting more common
Your threat model for exposure has misunderstandings everywhere.
using DoH generally does not harm your privacy and helps your security a bit but it is not a huge game changer
That's why I'm not concerned if it works or not, just a nice little project on my now "Decomissioned" pihole
well there are some benefits with this but if you don't trust cloudflare it gets very icky and complex
protonvpn ftw π
didn't IVPN have a exposure vuln a few months ago
how does nope and not sure fit in the same sentance lol
so far im happy with proton service. protondrive is nice to have
recommend me a custom keyboard shortcut for a pause/play button
thinkin alt + shift + p
gdrive complains if i upload something that is false-positive. proton-drive ofc not heh
hmm been a while since I have uploaded my files to the cloud
https://vulners.com/cve/CVE-2017-20112 this is the only thingy shadow finds on ivpn vulns
which is patched for a long while as it is from 2017
gonna keep looking a bit
true. just for pass manager i use bitwarden
Context TunnelCrack is the combination of two independent security vulnerabilities (LocalNet attack and ServerIP attack) that affect VPN applications. The research paper detailing these vulnerabilities was published and presented on 11 August 2023. IVPN apps were not tested by the researchers, and unlike other providers, we did not receive a vul...
eh don't look too much, we don't need a new CVE
Shadow could probably hack Ivpn
which is from 2023-09-07
all of those are patched by now qube
so nothing major to worry about unless you do not update your stuffs
@whole yew you here might ?
yea mullvad is great
but this also seems like a vuln that affected a lot of different vpn providers
yara is so dang confusing
Been on its lockdown mode for a few weeks now with quantum encryption enabled
so this is just ivpns report on the issue but it seems to have been a problem for others too including mullvad
none spongbob
arghh I don't need my watchlist becoming bigger
man vs bee
watched it
yup and its perfection
flamethrower for bee
simple yet perfect
who in there right mind would use socks as a proxy smh
SOCKS is an Internet protocol that exchanges network packets between a client and server through a proxy server. SOCKS5 optionally provides authentication so only authorized users may access a server. Practically, a SOCKS server proxies TCP connections to an arbitrary IP address, and provides a means for UDP packets to be forwarded. A SOCKS serv...
where is juun when you need him =/
funny name
yeah
nah... but smart hehe
maybe a ban but atleasty you would get his attention
earth is flat ||will it work||
the universe is torus shaped
that is what i wish to debunk... we all know it's donut... just flat is to try get him here
exaclty
and the earth is a klein bottle
theoretically imagine with can create our own black hole. then we can throw all our trash away
one that wont rip apart earth
true story... 20kg fell heavier to lift on north and south pole π
of course it does..... you are in all that keep warm gear
how do you free up hard disk space
true... just not as in case...
delete Windows and Program files folder
"and that is how i lost my other eye"
- defcon
btw shadow... is it true that defcon is cancelled this year ?
only one of em
don't listem/follow my advice... i learn a lot from mistakes of ppl who did listen me
and im chemist... so for sure don't listen my advice's
well it was close but seems it is still happening
much to the dismay of all the alcohol brewers
ceasars palace which hosted defcon for years canceled their contract earlier
so there was some scrambling to make sure defcon could still happen
oh well...
Now Now, tsk tsk
was hope to summon juun π
yeah let me just delete all my windows files what could go wrong
tbh... it is bit hard to delete it even with admin priv... at last in modern windows
WRP helps, but it isn't perfect, so still shouldn't say it π
atleast it wasn't linux lol
yea hehe
whats crazy is the amount of files windows needs to be able to run
well... it's windows yea
btw... can i set external drive in linux as trash/deleted files to go there?
...... ummm
idk, that's like mount /dev/null eh?
probably should be careful that people don't try anything remoetly like that on a system that's important
hmm... didn't think as dev/null... more alike if i delete something goes there as alike i copy it and can use it if i need restore something
read up on inodes
when you delete a file you're not moving it, you're just removing the link unless you overwrite it
liunux inodes are insane
yea... as in windows it can be restored with extra tools... but yea... you get what i think of
can you run out of inodes?
i read they are incrementing or smth
it's happened to me a few times
one more q... if i use LUKS to encrypt external drives, as i encrypt OS drive. And i reinstall OS with different LUKS password, does external drives use old password or new one
Did virtual box have an update? When I go fullscreen on VM. My windows taskbar still shows up when it never use to if I put my cursor on it. I've got it on hidden but the VM use to be completely separate. I'd have to minimise VM to see my host machine but now it's just there whenever I move cursor down.
Edit: seems to have fixed itself? That was weird.
no idea
fair
in that case. what solution can be if OS reinstall might not be option or smth ?
to fix the inode limit?
y
oh
bruh im literally so confused, in the questions it asks me to scan the file with yara and when i do it comes back positive even tho its not . im in Soc 1 btw
hopefully this is not a spoiler
bleepity bloopity to the beep boops while the meep moops are flying for the sleep sloops
night night
π
opa... frost... long time...
hullo
Just completed the Moniker Link room. Kudos to CMNatic for the great content.
yea... ben did make few of nice rooms
how is this hectic
?
Also... top 3% now π
Hey βοΈ
ello
Hello
ello dolph
How are you
good good... doing some engraving on wood. house smells like bbq π
Hehe nice
yea... you? not working?
Yeah am working rn
oh...
Quick break
fair
is what ?
cutie pie
ahaaa
She's sleeping atm
looks like teddy bear heh β€οΈ
She is a happy girl
So glad I moved the PiHole to my server, looks like it's blocking and querying more things than my Rasp Pi Pihole

still didn't broke something ?
Omg
Oh no, I still can't DNSCrypt to work, I'm giving up on it. Luckily I was testing it on my "decomissioned" pihole... so no issues on the server side
Was not about to push to prod without testing lol
don't forget πΎ button
Applies December 23 2023, not even able to get to my application until March 4th 2024
Is that not insane to anyone else?
Yah I saw that on the github, but it doesn't have the toml config
Yah, that's where I'm stuck on. Everything else is fine, and I can just do sudo apt install dnscrypt-proxy, no need for wget.
Well if you get DoH Working with Quad9, DNSSEC, Filtered, and no logging, lemme know lol
Right now, my PiHole is just setup on it's default DNS, Quad9, Filtered, DNSSEC
did i hear github
we stopped using quad9 tbh, resolution was always slow for us (compared to 1. for example)
Jesus fucking ping
@boreal scarab what

Nah, I always use Quad9 on my network. Hell primary DNS on my router is my PiHole, and that's going to Quad9, and Secondary DNS on my router is Quad9
I quite like Quad9
How many more times can I say quad9?
Quad9
Quad9
mmmm Quad9
Quad9 π₯³ π₯³ π₯³ π
i use quad 255
quad9 quad9 quad9
that was only triple
But Quad9
matt pls don't broke the internet =/
matt u ever broke quad9
not YET
PiHole uses the main Quad9 IP and it's seocndary
any ETA
you also don't have raspberry pi anymore also
@shell nova
@mossy river
or @mossy river
damnit
Done!
that's jabba taking job for him self π
mod abuse
https://youtu.be/nbHI7mSHVw8?si=OzutOnXEHjkADj9L
It's released!
Official visualizer for Kyle Gordonβs βThe Irish Drinking Song (feat. The Gammy Fluthers)β.
Listen to βThe Irish Drinking Song": https://kylegordon.lnk.to/TheIrishDrinkingSongID
Listen to Kyle's debut album 'Kyle Gordon Is Great': https://kylegordon.lnk.to/KyleGordonIsGreatID
Produced by: Jamie Siegel
Mixed by: Jamie Siegel
Engineered by: Jami...
Soonβ’
@hot cairn Oh Emma, another one talking about the RGB Switch lol
...
...
...
...
What is the URL that the infected host connected to?
well its any device that is not my work laptop :p
if i'm not working, i don't even wanna be on a computer πΆ
u ain't working right now
the one with DMC5
aren't u a student
negative
Ill switch to the super fun computer after dinner
hmm, probably tmrw or day after tmrw's the day for DMC5 to start for me
Im currently on a Bloody Palace run. Learned a few new combos that came in really handy
no spoilers
pc
lol nvidia
I have no idea, it's my partners PC
hmm
u should fire up task manager and see what PC ur even using
its a first todo step
in the words of our lord and savior linux tech tips, "nvidia, fuck you"
hmmmm I mean, it runs the game, thats all I kinda care about hehe
I never use it other than for this
hmm
new reddit just got newer and uglier
guys anybody knows a workflow tool (open source) for security tools automation?
i mean any workflow engine that we can make custom config to run specific tools and interact with each other using outputs as inputs from other
example : https://trickest.io
its paid :"/
ah yeah i see
read that as if you were looking for a plug and play SOAR-type thing
lol they don't even have a homepage?
what are they?
reads like a nessus type deal
argh
need an account to view anything whatsoever
ayy i got to a homepage
looks like .com is the normal .io is the portal only
curious how in depth the custom workflow part goes but the rest of their product just sounds like nessus & maybe we can auto validate
hmmm
probably gonna read up myself tbh. I've been writing my own workflows for quite and we haven't had a reason to look
i tend to avoid places that advertise "automated red team!" π
π
what do you use to make your own workflows
also what methodology u would consider
honestly it just depends
don't really have one specific methodology
sometimes it's easy sometimes it's completely custom
building out a new monitoring/enum/validation/etc server for myself rn and 90% of it is just service based and dockerized
they all play together nicely and exchange information as needed
(for image embeds)
I just had a great idea for a project. I want to be able to play DMC5 and DMC3 at the same time with 1 controller 8)
why do you need that information
because its a ship account and its one of my friends nad im tryna figure out wjo
No?
Go ask your friend?
Why does it matter who it is, if they're using your image, I'd simply report the account and move on
Yes, and you're not a moderator.
Unethical, it's not allowed anywhere.
Gave +1 Rep to @whole yew (current: #10 - 733)
What's a ticketing in soc?
Did you google this?
hey guys if you would have a mac i7 what free vm ware would you install to do kali linux without problems, Thank you!
VirtualBox, I suppose.
Anyone understand the purpose of Task 10 PATH on the Linux Privilege escalation room. Weβre supposed to compile a C source code that trigger thm wish is a simple shell. It works only if the C script is compiled with root privilege so whatβs the point if we are not yet root . I was able to solve it by using the one already compilez on the targzt machine that is already root . any idea ?
#room-help but the idea is path hijacking. With how Linux treats the PATH variable, the directories on the left are read first before others.
Ok i get it , thatβs right. I was just frustrated to not being able to do a more complete hack. But yeah fair enough, thanks !!
Gave +1 Rep to @simple valve (current: #24 - 345)
Nothing better than pulling a muscle in the gym ππ
Try the Deja Vu room for a different explanation
And practice π
Any legitimate advice on revisiting tryhackme after a long break, half completed rooms make things hard to get back in the swing
My guess is just get good?
Notes!
You can always re-do rooms
Reset progress?
Or jump in the deep end do a challenge room - It will all come back to you
Yea well, the tutorial walk thru rooms are good for learning but I dont find them as fun as the real boxes
Yah. Depending what bit you wanna focus on. OWASP/Juice Shop for web, What the Shell for shells..
It is really hard for me to pick up on them
I guess I am focused on completing learning paths when I think trying a challenge first would prompt direction where to learn
This is about getting back after a long break though. Honestly, even just reading through tutorials you've already done, much of it will come back to you
Essentially the challenge box will be a pre assessment and guide me better than a learning path first
BC I'll be like oh, I dont remember that, now I know where to hone in
Good option. But it's more like you'll be 'Dang, I used to know this!'
I just have a hard time digesting content without finding an issue where that knowledge would have benefitted me
Like, I need to hit the wall first
Good insight, this helped me
I'll try that
It's cool, I awas away for about 2 years π
Welcome back lol probably around the same here
now I have more tools (granted they are for woodworking) and slightly fuller beard, as that makes me wiser.
Its like, learning threat modeling after you've done juice shop might give you a different perspective vs before it
The OWASP rooms are honestly a goldmine. they cover so many things
Is bug bounty a good boost in income eventually
BC I think owasp to that pt would b nice
While applying for jobs I'd love to try a few bounty programs
Eh. We get like 5 young folk per week who've done 0 learning and wanna JUST learn bug bounties because of some of the high rewards.
Yea
not really
But certainly worth having a pop at some of the low-hanging fruit
it's a huge effort for relatively low payout
I want what I can get but knowledge over all
Don't we all π
generally speaking, right? I'd agree, but in the event I published a CVE, would that pay off in terms of resume value?
Of course.
like, would that motivator make it worth while? other than the knowledge acquisition
who knows, probably not tbh
Also depends on the job you are aiming for
depends on what the personrobot on the other side values
yep hydra, completely right, in this market..
well, I appreciate you guys being real w me and helping - I know a lot of people have high expectations by the glamor of cyber. I understand a lof of it is hyped up and being monetized/marketed by all the influencers
Thanks for new learning path π
most people won't get much out of bug bounties
but the people who do are outliers for sure or very skilled, stumbled upon a bug with a large time cost, etc.,
Dupes, and t-shirts π
Hello, my name is fola and I am very new to cyber security. However I got stuck at the second task on the beginners page. Though I am using my phone for this exercise, does this have any effect on my exercise or I am doing something wrong? Please I need help!!!
I guess I'd just try bug bounty for fun and worst case I get knowledge out of it, but I wouldn't be doing it for the money, only the valuable experience and marketable nature of being able to talk about it
you'll have issues accessing the VMs with a mobile device
Yes will do
What browser do you use? I believe the site is optimised for PC multitasking as the attack machine opens one one half of the page. It may raise errors on phone software
Also, I think phones aren't exactly the best way to learn beginner stuff. Virtual keyboard isn't doing any wonders, even if it is possible to run attackbox on a phone, using it may be difficult
Morning
morning
Mow some lawns
bumping this :)
If itβs any consolation, my friend found a CVE in Apple IOS and got it published. Heβs now working a very good job. It wasnβt the only thing he was doing but it definitely helped, heβd already been active in the field of IOS reverse engineering and code analysis for a few years prior
CVE-2023-32367 for those curious
Oh very nice
@mossy river this u?
meaning?
Bhai, your pfp is telling me more
that movie was great. I don't remmeber the name tho
have you ever delt with Kubernetes π
nah man not into cloud that much I am noob in this field
Gunda 
ahhh!
Whatβs wrong with burp suite
Maybe its too useful?
wassup esqy
Eyup Linkan
you got some tips for sqlmap? like finding parameters and some useful commands or smething
well ima test that
Task 2 covers the commands
yeah
my whole schools internet has turned off
Have they tried turning it back on?
Try do manual testing for an sqli prior to using sqlmap. In use I just use my get or post params and set it to do itβs thing. If it identifies anything then just add the specific db with -D then if you find tables do -T with relevant tables etc
If itβs a box and know it has sqli I just run sqlmap <url> <params> βdump till I get something cool most times
why not manually hunt for interesting tables and entries first. I'd dump as a last resort.
If itβs a box then itβs just quicker with no risk of shutout due to noise unless thereβs IDS or WAF
Why spend time manual testing all the way to creds once youβve already found an sqli in a request
using only automated ways can be boring after a while and you don't actually know why it happened
This is true. But you get ample verbosity if user cares to look at the path sqlmap took. Iβd rather know for sure that sqli is the intended path for a box by automating it in a few minutes rather than manual testing for 10+ minutes. I still recommend manual testing as a first call for your reason alone though
well i'm going to test that
i have so many questions ahahahahahahahaaha
Anyone have the problem after learning some stuff you cannot sleep peacefully because your mind keeps racing back it?
Happy day @loud marlin
ello ello
Heyaaa
"oh god, I've got mud on my hooves. eww. jump yuck. jump disgusting .jump I sure hope no one is filming this"
Ypu have a vivid imagination, i like that
β¬οΈ Black 4.0 (Use Code DYCBLACK for 10% OFF) - https://culturehustle.com/products/black-4-0
π Shop Our DIY Kits - https://www.dipyourcar.com/pages/main-category
β€οΈ Please Subscribe to DYC!- https://www.youtube.com/dipyourcar?sub_confirmation=1
π Join our FB Group - https://www.facebook.com/groups/DipYourCarCommunity/
So apparently there is a n...
result is like you have black hole of a car π
π
when i was 13 i eat mud =/... burp didn't exist at all lol
Hey @rapid merlin can you change your pronoun, it is not appropriate for this community
sooo muuuuch CCNP 
alr
Thanks π
humble had one book
it's the one I am doing
π
thats not a memory to be fond of xd
What's everyone hacking today?
Yo ppl how's everything going
life
they did have some pack of network and so
When I was 13 I was an absolute script kiddie
what are you now? :p
Wanted to ask something, to hack another machine first i have to get it's ip address and then open terminal and use ssh (target ip address)?
An older script kiddie π
lmao
Is it really that easy?
That gets paid at least
i had crt monitor and mouse with ball that i need to clean lol
not really
Then what's the use of secure shell?
you cant ssh if theres no port open (for ssh which is 22)
Isnt it a command to access another machine through ip?
that's how you would connect via ssh. plenty of reasons to do that beyond hacking
Aha i see , so ssh is mainly to connect to another machine
But as mohta said there must be an open port
Hell yeah. Iβm old enough to remember pinball and minesweeper but not crt monitors π
pretty much. its just a way of connecting to another machine. what you do once you are connected is another matter
seems more like an earthquake
So i can connect to any machine in the world if i have it's ip?
skype was new thing... back in my time
damn you old π
Amen
ssh uses a server-client setup. the machine needs to be hosting an SSH server for a client to connect to it
we got it in paper instead π
Alex what book did you win?
Everytime i come to ask about something i end up feeling i have no fking idea what's going on 
old school
you can try.
doesn't mean it will necessarily respond.
plus, you shouldn't try to connect to a machine you aren't authorised to access; it's rude, and possibly illegal.
if you wanted to access a computer with no monitor (or just remotely), that computer needs an SSH server running on it and then you can connect via a client to do pretty much anything, just by means of a terminal instead of a GUI
I am not going to do so
I am just trying to understand and learn what is ssh for
Coz i remember a room where it required me to use ssh to connect to another virtual machine and get the flag
So i thought that's how hackets connect to other machines
Using ssh
I don't know how else can anyone access other machines coz that's as far as i got 
IIRC, that flag was just a text file somewhere on the computer. that room teaches you how to navigate a computer with SSH and find a specific text file
there are multiple ways. ssh is just one. others are ftp, http(s), telnet, smb.
I see
See when i said everytime i ask something i feel like ( you know nothing john snow )
that's how everyone starts out.
Hi everyone. I'm new here/
hello, new here
Hi new here
π
Bruhhhπ
Is that your hacking profile pic?
oh gods there's some PTSD
Yess?

that pic isn't what it looks like but from far away it looks very questionable
Yeah I had some awfully specific questions on an application form for startup businesses this morning. I donβt mind, but trying to find the relevance to the application leaves me confused
wich one
I don't understand the whole purpose on why jobs do this, just makes it annoying to go through and submit the application
Having a teacher trying to explain python to people who dont know python when hes vague as balls is fun
for diversity
Its funny because that would be illegal in terms of hiring laws right
its weird to see on an application, but I can see why they'd want to collate that sort of data for PR/equalities reports.
depends on the country. some places allow it to be a deciding factor when its basically a coin flip between two equally qualified candidates. kinda sucks if you get turned down for a job because of that though
Yeah that would suck indeed
I would assume not, there's usually a "Prefer not to say" option in these questions
No but i meant the specific hiring on ethnicity or sexual preference for diversity
I'd guess there's an implicit rule here but its never outright said
to quote a relatively famous district attorney: "The world is cruel, and the only morality in a cruel world is chance. [flips coin] Unbiased. Unprejudiced. Fair."
i guess dei but
seems really just like data harvesting
I do know some programs try to hire for diversity or at least try to allocate a certain percentage of their hiring for diversity hires
that seems a little controversial imo if you're hiring a certain race
for the purpose
like, if that makes sense
like why cant' we just hire based on skillset
Bc of privilege
Anyway, I don't think this type of conversation is going to go anywhere good and I think its a good time to drop it now and talk about something else
they probably are. as you say, it might just be for data gathering; something to tally up for specific reports
anywho, how about that weather?
Yeah, it does make you wonder if these questions will sway your chances in the final selection though. I had one's about social-economic upbringing as well as sexual orientation today
yeah even the disability questions make me wonder if the employer will have a bias. I had an interview where I was asked how old I was, and I have reason to believe that is what convinced them to want an on-site interview even though my friend was fully remote at that company - wouldn't have been a big deal but they wanted me to drive 6 hours to their headquarters at $16 an hr
that's quite the commute π
yeah for a $16 an hr job, no thanks
Age is a thing though. In UK anyway. You can work when you are 16 BUT there are loads of rules the employer has to follow, especially if the person is still in full-time education.
Although the employer may not be able to say 'No' as a result of your age, technically it can't be directly about that, but more likely is things like - The role will require more hours than they allowed to work per week, There are certain tasks that need to be done and needs to be someone over 18 and a company simply might not have the resources to support that
If someone is 16, they can only do 2 hrs on a school night and have to be finished by 9 or 10pm. Although there are some jobs that have that, there are many others where thats just not needed
damn i was doing a part time job(5-6 hours at a time) at 16
See, That would depend on the industry aswell
grocery store stockboy lmao
There is some wiggle room, but again - Theres a lot of Risk assessment and all sorts around it
School holidays up the amount of hours a young person can do aswell
"no madam, we DEFINETLY dont have the product in the back, but sure ill check anyway" simulator
some products are age restricted too. if you can't buy them because of age, you probably can't sell them either.
No idea why so many of the young folk on here are eager to get into the workplace. Work is so much more of a pain in the butt. Ok, you get paycheck (after the government takes their cut), but if you mess up? You're gone. No after-work detention. Plus most of the paycheck goes on other stuff - commuting to and from work, smart-casual clothes etc. Plus, you're spending most of your waking week in that place, so even spending that money becomes a pain
DJ - Every store has a 'Back' where all the good stuff is kept. a Magical store-room with all the items in the world
Aye, So although working in a newsagent is cool, They wouldnt be able to sell booze - and have to get an over18 to do that for them
That being said, Nothing against young folk getting a part-time job - Once it doesnt interefere with their education. Just.. at my age, I yearn for the simplicity of going to school, listening to a few lectures, and head home at half past 3
At which point, Mom/Dad will have dinner already cooking and the house will be clean
But what do you do with all this free time without money π€·ββοΈ
Theres a lot of beauty and fun in this world thats free.
Which you donβt appreciate at that age (mostly)
Zactly. Even just hanging out with friends. Doesn't really happen at my age - Everyone is usually busy with their own work or with their family.
i agree so much
Emerald, Still not 0xD? I'm not angry. Disappointed π
Yeah I know the feeling. Also a lot of my old pals moved away. Me included π so you just canβt meet up that often
Addicted to demos and walkthroughs on youtube
guilty
if challenge boxes gave more points, i'd be golden
They do give more points, then walkthroughs
yes
how much does a medium one for example give? say 0day
Itβs all on the knowledge base
The whole website is a knowledge base π
Some don on the bus was handing out Ferrero Roche to everyone
Jabba - I'm gonna need a hint, I don't know the song in your profile thingy
I can usually get it, but not this one
I canβt tell if youβre being serious or not
I am.
You had Zombie by the cranberries a couple weeks back
Itβs whatever the vibe is when I think about changing my status
Zombie was the vibe of the week
has anyone ever used lacework for container security and is the product any good? or a similar container security tool they would recommend
It's a fun side-quest π
trivy is good @brittle flume
Itβs my secret way of finding someone with my crazy music taste
harden your containers properly π
Yep, not heard that before
i dont make them lol
thanks
Gave +1 Rep to @simple valve (current: #24 - 346)
Very unfortunate. Itβs from my Spotify 2019 wrapped
The guy whos first in the office is big into hiphop and R&B from the 90's and naughties, so thats usually whats on in my background
I use headphones
I don't think it's possible for me to ever forget about Dre at this point π
Oh yeah, I headphone it up if I need to stay focused, but many things in the job need me to be calling people and talking to folk
trying out microsoft copilot and the images it can design is mad
Is being in the top 5% considered good or is it normal ?
I got to the top 1% and then gave up on tryhackme
Nothing left to do.
So the % thing is what you make of it.
Truee
The new devsecops path tho
No thanks, I work with devops people and they don't seem to get anything done or have fun.
Gave +1 Rep to @floral wing (current: #2011 - 1)
xD
Can I see how many rooms I have completed on the site ?
Yea go to tryhackme.com/p/<your_username>
Thankss

Morning!
10 AM!
But I'll take that $1500 you're offering
Yes you did you said 1500
I never used a currency symbol
Hello everyone, I performed a scan with nmap on my personal server using a basic command that included -vv and it gave me the ssh private key. Does the -vv command itself execute a particular script?
just means verbose level 2
I litteraly got SSL certificates of all the services running + ssh key
how is it possible
you're getting the hashed version of the public key
not the private key
you cant
its md5 encrypted
its a hash
i started an nmap scan at 11:53 and its still going ahahaha
but can i use it ?
lmao
and what can I do with my SSL certificates
not much i guess
i have a strong feeling that its not your own server
if it was, you would know what those mean
nwy, i will refer you to jabba, he knows more
@mossy river
I was just about to say that, let's have the expert handle it
its an ancient PC from my grandma lmao
helo bella how are you
will you be doing cyber apocalypse?
thx
Gave +1 Rep to @simple valve (current: #24 - 347)
Most likely
Been hitting top teams last couple of years, so of course we going for it again
Hi, I am looking for like-minded people to learn with me on tryhackme.
German language is important as I can't speak English well but understand it legibly. 
I would be very happy to hear from you if you are interested. 
Whatβs happening boss
I think @lament tendon would be interested
hi
.
Who are have ping me?!
Oh, hi, whahaha.
which is it - a personal server or an ancient PC from grandma?
Something for you?
Hmm, depends.
Generally would not be against it.
PC = Server dont get me wrong
Howβd you like to go about learning together?
You get the answers, i copy
XD
I sent you a friend request 
XD. Hey, youβre already part of our group. ;)
Got some relatively big stuff planned by the way.
So your grandma has a ancient server lying around
a web server yes
I did accept your friend request.
About Discord? Is it ok?
One could say, youre planning in bytes???
Hehe. π
Thanks
Gave +1 Rep to @lament tendon (current: #36 - 207)
Do you own the webserver ?
yes
Isnt it your grandma's?
Csnt hurt to make sure
I think you're just a waste of my time
How would that comment affect me
Oh no a person on the internet doesnt like me, whatever shall i do
πΏ
do you not feel a markΓ©d sense of shame and humiliation?
My man, thats my normal state regardless of internet peeps XD
Nice to hear, i might tackle some of it but maybe only the web challenges π
That's totally fair, I play on a bigger team
Your personal server?
Bro you have to be shiting money
yeah my debian laptop with 4 giga of ram is very expensive
apache is very expensive too bro
@molten sky Might know π
We cant dm you π
You can send me a friendrequest
LMAO
oh
bro dont get it
I haven't had food since this morning, forgive me
Dude! It's like 4-pm. Go get your grub on!
I knowww just haven't been feeling well βΉοΈ
The only thing i've had is a Caramilk easter egg
A Balanced diet is good for recovery. Good job Blackout π
I had an apple, keeping the doctors away
Guys do u have group or discord for crtp/crte?
hi i am new guys
I think matt touched my PC cuz it BSOD while trying to update vmware.
forgive me, I am American. By mad you mean its pretty legit?
you are forgiven
Why are Brits and just Euros in general better hackers than Americans
I make the joke with my friends that the only way you can afford to live anywhere near London is to work in technology
I mean itβs amazing
Tech for the big ones like Amazon or Finances π
ill be honest with you Blackout, that's not living...... that's surviving
Yea true, I want my own place but everything is expensive. I wanna buy a house but cheapest one is like 200k-250k
I lived in London, but it was a different time and situation. I lived in quite a posh place π
i can barely survive on that in glasgow. that is not nearly enough for london
meep meep
in the US, people would wish a house was $200k-$250k
tomato tomato
I got bad new for you, here in America 200k can pretty much get you a trailer on a lot
took the words right out of my mouth
houses around shadows area is starting at around 1 mil sek and some go up wards of 15 mil sek
sek being the swedish krona currency
what do you buy in London with that? a meter of space π
is 1M SEK still reasonable? can't remember the exchange rates
My 62m2 apartment in Denmark costs me 751 USD a month
96568 usd
I was looking in EUR, but yeah still very reasonable for the first figure
It makes me sad to see how everyone is in the "I make enough to survive."
Just for a 3 bedroom it's 400k
apartments in my area are minimum $2500/month
London is insane. So is Paris
again, super cheap compared to here
though those houses are in need of lots of renivation so it is not a good mark to shoot for
yeah but reno work isn't that bad either, at worse you'd be doubling the price
yeah my cousin used to live off 25k in london. dont know how he did it
unless it's a demo job
so every big city, Tel Aviv the rent is out of control π
In Copenhagen if I want the same size apartment it's 2200 USD a month
kinda glad I was able to buy my place when I did
also that number shadow gave is what it was in around 2013....
That sounds like those California prices
so dunno about now
you saying 25k a year?!?!?!?!
yeah
I may buy a place in Argentina, as investment and also to have it when I come to visit my family
yes although when I lived in the DC area, it was similar. People are renting rooms for $1800/month, its wild
Your cousin needs to write a book
hes on 45k now so its all good ahaha
wheee, fluff added
but the real estate in Israel it's expensive
because israel in a war
I don't know how California stays afloat honestly. I used to think that everyone in California just made triple the national median, and realized no. The only thing that keeps California up, is the fact that somehow every billion dollar powerball ticket is sold there 
I'm not going to enter in politics, specially with people who don't know the day to day of the situation, but I've lived in Israel since 2001 and it always had been expensive, the current situation has nothing to do with the prices.
He still should write a book on surviving London with only 25k. There is nowhere in America that you could do that lol
his ex had to share a house with 10 people in london just to survive
I still haven't won the powerball... but honestly, lots of people in California bought when prices weren't so crazy and there are some people that get paid quite a bit
median salary is a bit higher in California, yeah
I'll say California is affordable to me but for many, it is a stretch
That is literally insane to me. Like something has literally got to change because soon, no one will be able to live anywhere
fun fact, my salary range was higher in the DC area and it went down when I moved to California
im in abu dhabi its not so bad here. it makes me see how messed up the economy is in the uk
yeah, but its the people buying now.... like how....
I like Abu Dhabi, I've been there a few times
its so cheap and great weather
but not enough to justify 2 million for a 700 sq ft home....
we bought 16 months ago, we had home equity from another state
where I live, its not 2 mil for a 700 sq ft home
dc to California??? you sound like a fed lmao
no, I get paid more than a fed
why you telling people to delete things?
from 1895
thats the only reason I think the housing market hasnt completely tanked is because of poeple who bought in like 2017
nah
LMAO π
When I went with my now ex-gf we stayed in Burj Al Arab π
please stop attempting to minimod, or you WILL be muted
awww nice
i have ur privacy at heart β€οΈ
it is amazing and super safe
it was a business trip that I tagged along π
ahahahahaha
nah, I can take care of myself
u gotta take a break from discord
read that again
Nah, im playing. Only reason I said that is because those are 2 major stop points for fed ops
you should go on holiday. the food here is phenominal
iunno, that looked like an order to me
:mute: lifeemerald#0 has been muted.
I dunno about California being a fed hub
I know I went a few times, food it's amazing along all the middle east π
would've gotten around to that I suppose, @tired peak
I thought most of the new Cyber Command was sent out there after they split from NSA
no clue
Yeah. Iβve gained a bit of weight cause they make it America sizes portions here π
you're good G, I don't take anything personally
the feds currently have a hard time staying in sweden where they are outside their normal jurisdiction
^ also a joke
To be fair, there probably are feds in here
oh you know there are
oh shadow is betting on there being
What happens in Vegas stays in Vegas π
you american?
hahahahahahaaaaa nope
lets print that out and make that this discord's logo
aight, I need to go home now
well, if my American flag didn't give it away... I am π
The biggest 
that's one of the Las Vegas moto π
I mean Americans do tend to advertise the fact that they're American a bit too much
