#general

1 messages Β· Page 50 of 1

thin raft
#

I think it might be a good idea

shell nova
#

glhf

frozen mural
#

I didn’t know this, really?

thin raft
#

I will go with the easy ones, by any chance would I be able to do maybe the medium ones also?

shell nova
#

@mossy river want to chime in on this?

shut hawk
shell nova
bold latch
#

Sharing the same VPN/IP is messy either way

boreal scarab
#

Anyone used Cloudflared DoH before?

thin raft
twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #12 - 550)

tired peak
#

why wouldn't you use your own VPN file?

shell nova
#

doesn't guarantee the same network

tired peak
#

ahh

frozen mural
tired peak
twin ridgeBOT
#

Blacklisted from receiving points

#

You can't modify your own Rep... Silly

shell nova
#

yeah let's not abuse that please

shut hawk
#

wait you can blacklist uses from gaining rep?

shell nova
#

apparently

bold latch
#

I do tend to wonder if THM will have that sort of feature someday. It seems intuitive for people seeking more hands-on mentoring, or a solo game of who-can-hack-it-first rather than a public KOTH

#

Sharing deployed machines, that is

thin raft
#

I tried to give 1 rep to Robocop, just needed to see what it does

shut hawk
thin raft
#

is there a way to see your rep?

shell nova
#

you can technically access the same room (outside networks) with different VPN profiles

shut hawk
shell nova
#

it's the same IP

#

but I wouldn't abuse that too much

bold latch
#

So if you share the machine's IP to another user, you can both join the machine?

tired peak
#

basically anyone on the network could access your deployed systems

shell nova
#

just for troubleshooting

shell nova
#

VPN gives access to the 10.10 range

bold latch
#

In the linked message Jayy posted, Jabba did say "no sharing deployed machines" specifically so it is still currently unallowed

thin raft
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 482)

shell nova
#

that's why I said I wouldn't risk it beyond troubleshooting

tired peak
shut hawk
#

You did it here, in general

thin raft
bold latch
#

Well, if boss says, it goes

mossy river
tired peak
mossy river
#

Huh?

tired peak
#

they were talking about sharing a vpn file to do the same room / system

left lantern
#

Hi boys i loking for a team

tired peak
#

"boys"

mossy river
#

Yup, still against ToS, see "Account sharing"

left lantern
#

To CTF competition

frozen mural
left lantern
#

Who can join to me

bold latch
#

It would admittedly be a neat feature

tired peak
mossy river
#

It's not designed to be co-op

shut hawk
#

A co-op feature would be awesome tho)

bold latch
frozen mural
#

As long it’s not authorized by THM policy then forget about guys, I didn’t know that

left lantern
#

Who can come friends

vagrant surge
#

Hey guys i have wrote a script for a blind sqli in shell script where to post this code to allow others to check it and to improve my code?

shell nova
#

to exploit?

mossy river
left lantern
#

@evreyono

shell nova
#

the bot gets angry

left lantern
#

Ok

mossy river
#

And I don't think it's really about speed, I think that sends the wrong idea.

boreal scarab
#

Yah, I use Q9

left lantern
bold latch
mossy river
left lantern
#

Do you want join

shell nova
thin raft
left lantern
twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #12 - 551)

shell nova
shell nova
bold latch
vagrant surge
twin ridgeBOT
#

Gave +1 Rep to @thin raft (current: #2011 - 1)

bold latch
#

Also, bit of a farfetched concept, but imagine simulating a red-blue team engagement with a shared network of sorts over the THM servers

thin raft
left lantern
#

I want be professional in CTF challenges web and network can I improve my self

shut hawk
left lantern
#

Please boys help me i want learn

thin raft
vagrant surge
left lantern
#

I am in the top 1% in THM

bold latch
shell nova
bold latch
#

The help comes after that

left lantern
#

But I still think i am very weak

shut hawk
shell nova
#

then keep practicing

bold latch
#

And do some reading outside of CTF platforms, for that matter

#

Pick a topic and your favourite search engine

vagrant surge
#

blind sql takes for me allot of time... and i have only 24h to pass the test

left lantern
bold latch
#

Or dockerized SearXNG if you fancy multiple

shut hawk
shell nova
#

or is that the report phase

left lantern
loud marlin
#

hmm... if Voldemort wish to find harry he just need to write letter, give it to owl and then follow owl on that fly stick...

vagrant surge
#

from my knowledge it 48 hour, but only 24 hours to get all flags and the next 24 hours to write the dokumentation

shell nova
left lantern
shell nova
#

keep at it

#

you'll get there

thin raft
left lantern
twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #12 - 552)

shell nova
loud marlin
left lantern
#

I want friends to play together

bold latch
# left lantern What is the best website to practice

Plenty of people here will say the obvious choice, TryHackMe.

HackTheBox is an alternative people tend to go for after TryHackMe, because it's got somewhat tougher machines and a more competitive aspect

And then you have websites for research, like Maldev Academy, Sektor 7 and other similar places

If you got cash, check out Offsec and their various courses as well

thin raft
#

I ve heard that Offsec is quite good despite the prices, is it an industry standard?

bold latch
#

Look at some malware samples (safely and in a sandbox/VM) from VX-Underground maybe

left lantern
vagrant surge
shut hawk
loud marlin
bold latch
# thin raft I ve heard that Offsec is quite good despite the prices, is it an industry stand...

I have no personal experience with it, but I've seen it endorsed very highly while looking around; its certifications are definitely looked at by plenty of figures in the industry and it's a cornerstone in the world of pentesting by the looks.

To give you an idea of their involvement, they're the people behind https://www.exploit-db.com/ if you've ever used it.

https://www.vulnhub.com/ is also ran by g0tmi1k, who is a Live Instructor at Offsec

Several members of the main team behind Kali Linux itself (see https://www.kali.org/about-us/) also teach and run courses in Offsec

left lantern
#

I want see any one how to play pls

#

I want take experience

crude stump
#

Congrats @loud marlin

gritty zephyr
#

Heya

left lantern
#

I want study privilege sclation more any one knows how to be get more informations

loud marlin
#

google ?

left lantern
loud marlin
#

well... start with THM, then expand around google, YT and so

#

there is one book i know that might help

thin raft
left lantern
twin ridgeBOT
#

Gave +1 Rep to @loud marlin (current: #26 - 287)

crude stump
#

When your phones thinking too hard

loud marlin
#

or smoke some funny flower πŸ™‚

crude stump
#

😨

sand trench
crude stump
#

Cleanses the the nose

boreal scarab
#

Welp Quad9 DoH using DNSCrypt on pihole has so far been a bust...

sand trench
#

???

#

quite sure shadow got that working without much problems

boreal scarab
sand trench
#

Β―_(ツ)_/Β―

boreal scarab
#

I've spent like 2 hours trying to get it to work just on my old PiHole before I put it on my TrueNAS PiHole

sand trench
#

shadow did do that a long while ago ( about 9-12 months or so ) before switching to nextdns

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 1647)

sand trench
#

no problem

buoyant tree
#

was using pihole with quad9 b4

#

privacy

#

nobody can trace u by ur DNS requests

#

your orgin Ip is still exposed

sand trench
#

nope dns by default is not encrypted

buoyant tree
#

DNSSEC is then used for encryption I think

#

and for non-repudation

sand trench
#

it is starting to become more common with dns over https/dns over tls
and the old dnscrypt protocol

boreal scarab
#

Gets REALLY complicated really fast when it comes to DNS

buoyant tree
sand trench
#

those are not by defaults for dns.... but yes those are getting more common

whole yew
#

Your threat model for exposure has misunderstandings everywhere.

sand trench
#

using DoH generally does not harm your privacy and helps your security a bit but it is not a huge game changer

boreal scarab
#

That's why I'm not concerned if it works or not, just a nice little project on my now "Decomissioned" pihole

sand trench
#

well there are some benefits with this but if you don't trust cloudflare it gets very icky and complex

loud marlin
#

protonvpn ftw πŸ™‚

buoyant tree
#

didn't IVPN have a exposure vuln a few months ago

crude stump
#

how does nope and not sure fit in the same sentance lol

loud marlin
#

so far im happy with proton service. protondrive is nice to have

buoyant tree
#

recommend me a custom keyboard shortcut for a pause/play button

#

thinkin alt + shift + p

loud marlin
#

gdrive complains if i upload something that is false-positive. proton-drive ofc not heh

buoyant tree
#

hmm been a while since I have uploaded my files to the cloud

sand trench
#

which is patched for a long while as it is from 2017

buoyant tree
#

hmm must have been another vpn

#

oh it was PureVPN

#

not ivpn

sand trench
loud marlin
#

true. just for pass manager i use bitwarden

sand trench
buoyant tree
#

Shadow could probably hack Ivpn

sand trench
#

which is from 2023-09-07

#

all of those are patched by now qube

#

so nothing major to worry about unless you do not update your stuffs

loud marlin
#

@whole yew you here might ?

buoyant tree
#

yea mullvad is great

sand trench
#

but this also seems like a vuln that affected a lot of different vpn providers

crude stump
#

yara is so dang confusing

buoyant tree
#

Been on its lockdown mode for a few weeks now with quantum encryption enabled

sand trench
#

so this is just ivpns report on the issue but it seems to have been a problem for others too including mullvad

buoyant tree
#

@sand trench help me select a movie/tv series for today

#

Looney tunes, Mr bean, E.T

crude stump
#

none spongbob

buoyant tree
sand trench
buoyant tree
sand trench
#

which is rowan aktinson playing another person fighting a bee

#

oh....

buoyant tree
#

flamethrower for bee

#

simple yet perfect

crude stump
#

who in there right mind would use socks as a proxy smh

sand trench
loud marlin
#

where is juun when you need him =/

crude stump
ocean hare
#

say something crazy

#

and he'll pop

sand trench
#

yeah

loud marlin
#

nah... but smart hehe

crude stump
#

maybe a ban but atleasty you would get his attention

loud marlin
#

earth is flat ||will it work||

crude stump
#

earth is a donut

#

confirmed

sand trench
#

the universe is torus shaped

loud marlin
crude stump
#

exaclty

sand trench
#

and the earth is a klein bottle

crude stump
#

theoretically imagine with can create our own black hole. then we can throw all our trash away

#

one that wont rip apart earth

loud marlin
#

true story... 20kg fell heavier to lift on north and south pole πŸ™‚

sand trench
#

of course it does..... you are in all that keep warm gear

crude stump
#

how do you free up hard disk space

loud marlin
loud marlin
sand trench
loud marlin
#

btw shadow... is it true that defcon is cancelled this year ?

crude stump
loud marlin
#

don't listem/follow my advice... i learn a lot from mistakes of ppl who did listen me

crude stump
#

heck nah

#

5

#

soon to be 6

loud marlin
#

and im chemist... so for sure don't listen my advice's

sand trench
#

much to the dismay of all the alcohol brewers

loud marlin
#

any solid reason why ?

#

oh

sand trench
#

ceasars palace which hosted defcon for years canceled their contract earlier

#

so there was some scrambling to make sure defcon could still happen

loud marlin
#

oh well...

cosmic pendant
loud marlin
crude stump
#

yeah let me just delete all my windows files what could go wrong

loud marlin
cosmic pendant
#

WRP helps, but it isn't perfect, so still shouldn't say it πŸ˜‰

#

atleast it wasn't linux lol

loud marlin
#

yea hehe

crude stump
#

whats crazy is the amount of files windows needs to be able to run

loud marlin
#

well... it's windows yea

cosmic pendant
#

any 'modern' OS is like that

#

Atleast with a gui...

loud marlin
#

btw... can i set external drive in linux as trash/deleted files to go there?

cosmic pendant
#

...... ummm

#

idk, that's like mount /dev/null eh?

#

probably should be careful that people don't try anything remoetly like that on a system that's important

loud marlin
#

hmm... didn't think as dev/null... more alike if i delete something goes there as alike i copy it and can use it if i need restore something

cosmic pendant
#

read up on inodes

#

when you delete a file you're not moving it, you're just removing the link unless you overwrite it

#

liunux inodes are insane

loud marlin
#

can you run out of inodes?

cosmic pendant
#

yeah, you can

#

it's like the number of open file handles

loud marlin
#

i read they are incrementing or smth

cosmic pendant
#

it's happened to me a few times

loud marlin
#

one more q... if i use LUKS to encrypt external drives, as i encrypt OS drive. And i reinstall OS with different LUKS password, does external drives use old password or new one

rapid merlin
#

hello guys

#

how to hack

steel aspen
#

Did virtual box have an update? When I go fullscreen on VM. My windows taskbar still shows up when it never use to if I put my cursor on it. I've got it on hidden but the VM use to be completely separate. I'd have to minimise VM to see my host machine but now it's just there whenever I move cursor down.
Edit: seems to have fixed itself? That was weird.

loud marlin
#

fair

loud marlin
cosmic pendant
#

to fix the inode limit?

loud marlin
#

y

cosmic pendant
#

there is a command on file limt

#

you just change it

#

ezpz

loud marlin
#

oh

crude stump
#

bruh im literally so confused, in the questions it asks me to scan the file with yara and when i do it comes back positive even tho its not . im in Soc 1 btw

#

hopefully this is not a spoiler

sand trench
#

bleepity bloopity to the beep boops while the meep moops are flying for the sleep sloops

loud marlin
#

night night

woeful rock
#

πŸ˜„

loud marlin
#

opa... frost... long time...

woeful rock
#

o/

#

How's it going

loud marlin
#

\o

#

so far so good... you ?

#

how's a that dog ?

buoyant tree
#

hullo

stuck tangle
#

Just completed the Moniker Link room. Kudos to CMNatic for the great content.

loud marlin
#

yea... ben did make few of nice rooms

midnight hazel
#

how is this hectic

loud marlin
#

?

stuck tangle
#

Also... top 3% now 😎

idle peak
#

Hey ✌️

loud marlin
#

ello

graceful thistle
#

Hello

loud marlin
#

ello dolph

graceful thistle
#

How are you

loud marlin
#

good good... doing some engraving on wood. house smells like bbq πŸ™‚

graceful thistle
#

Hehe nice

loud marlin
#

yea... you? not working?

graceful thistle
#

Yeah am working rn

loud marlin
#

oh...

graceful thistle
#

Quick break

loud marlin
#

fair

woeful rock
#

she is a qt 3.14

loud marlin
#

is what ?

woeful rock
#

cutie pie

loud marlin
#

ahaaa

woeful rock
#

She's sleeping atm

loud marlin
#

looks like teddy bear heh ❀️

woeful rock
#

She is a happy girl

boreal scarab
#

So glad I moved the PiHole to my server, looks like it's blocking and querying more things than my Rasp Pi Pihole

loud marlin
#

still didn't broke something ?

graceful thistle
boreal scarab
#

Was not about to push to prod without testing lol

golden timber
golden timber
#

Applies December 23 2023, not even able to get to my application until March 4th 2024

#

Is that not insane to anyone else?

boreal scarab
#

Yah I saw that on the github, but it doesn't have the toml config

#

Yah, that's where I'm stuck on. Everything else is fine, and I can just do sudo apt install dnscrypt-proxy, no need for wget.

#

Well if you get DoH Working with Quad9, DNSSEC, Filtered, and no logging, lemme know lol

#

Right now, my PiHole is just setup on it's default DNS, Quad9, Filtered, DNSSEC

molten sky
boreal scarab
#

Jesus fucking ping

mossy river
#

@boreal scarab what

boreal scarab
molten sky
#

did you try q9 and get slow

#

not surprised if so

boreal scarab
#

Nah, I always use Quad9 on my network. Hell primary DNS on my router is my PiHole, and that's going to Quad9, and Secondary DNS on my router is Quad9

#

I quite like Quad9

#

How many more times can I say quad9?

#

Quad9

molten sky
#

Quad9

boreal scarab
#

mmmm Quad9

blazing granite
#

Quad9 πŸ₯³ πŸ₯³ πŸ₯³ πŸ˜‚

molten sky
#

i use quad 255

buoyant tree
molten sky
#

that was only triple

boreal scarab
#

But Quad9

loud marlin
#

matt pls don't broke the internet =/

buoyant tree
#

matt u ever broke quad9

boreal scarab
#

PiHole uses the main Quad9 IP and it's seocndary

buoyant tree
loud marlin
#

you also don't have raspberry pi anymore also

molten sky
#

@shell nova

loud marlin
#

@mossy river

molten sky
#

or @mossy river

molten sky
grim sparrowBOT
#

Done!

loud marlin
#

that's jabba taking job for him self πŸ™‚

molten sky
#

mod abuse

boreal scarab
#

Official visualizer for Kyle Gordon’s β€œThe Irish Drinking Song (feat. The Gammy Fluthers)”.

Listen to β€œThe Irish Drinking Song": https://kylegordon.lnk.to/TheIrishDrinkingSongID
Listen to Kyle's debut album 'Kyle Gordon Is Great': https://kylegordon.lnk.to/KyleGordonIsGreatID

Produced by: Jamie Siegel
Mixed by: Jamie Siegel
Engineered by: Jami...

β–Ά Play video
boreal scarab
molten sky
#

y'all saw the ubiquiti rgb switches i assume

#

looks like someone played snake on them

boreal scarab
molten sky
#

i think i was one of the first people to link to it here 😢

buoyant tree
#

...

molten sky
#

...

boreal scarab
#

...

molten sky
#

...

hexed sandal
#

What is the URL that the infected host connected to?

molten sky
#

also, what are you referring to..?

graceful thistle
#

aaaand another workday done

#

time to switch to the fun computer

molten sky
#

you have a fun computer?

#

didn't know that existed

graceful thistle
#

well its any device that is not my work laptop :p

molten sky
#

if i'm not working, i don't even wanna be on a computer 😢

buoyant tree
molten sky
#

i poor

#

always working

buoyant tree
buoyant tree
molten sky
#

negative

graceful thistle
molten sky
#

a student of life

#

still haven't learned much tho

buoyant tree
graceful thistle
#

Im currently on a Bloody Palace run. Learned a few new combos that came in really handy

#

no spoilers

buoyant tree
#

hmm

#

u play on pc or console?

graceful thistle
#

pc

buoyant tree
#

nice

#

RTX 4000 series or 3000?

molten sky
#

lol nvidia

graceful thistle
#

I have no idea, it's my partners PC

buoyant tree
#

hmm

#

u should fire up task manager and see what PC ur even using

#

its a first todo step

molten sky
#

in the words of our lord and savior linux tech tips, "nvidia, fuck you"

graceful thistle
#

hmmmm I mean, it runs the game, thats all I kinda care about hehe

#

I never use it other than for this

buoyant tree
#

hmm

molten sky
#

new reddit just got newer and uglier

unreal schooner
#

guys anybody knows a workflow tool (open source) for security tools automation?

molten sky
#

that's very vague

#

gonna have to be more specific

unreal schooner
#

i mean any workflow engine that we can make custom config to run specific tools and interact with each other using outputs as inputs from other

#

its paid :"/

molten sky
#

ah yeah i see
read that as if you were looking for a plug and play SOAR-type thing

#

lol they don't even have a homepage?

#

what are they?

unreal schooner
#

they offer workflows

molten sky
#

reads like a nessus type deal

#

argh

#

need an account to view anything whatsoever

#

ayy i got to a homepage

#

looks like .com is the normal .io is the portal only

#

curious how in depth the custom workflow part goes but the rest of their product just sounds like nessus & maybe we can auto validate

unreal schooner
#

hmmm

molten sky
#

probably gonna read up myself tbh. I've been writing my own workflows for quite and we haven't had a reason to look

#

i tend to avoid places that advertise "automated red team!" πŸ˜‚

unreal schooner
#

πŸ˜‚

#

what do you use to make your own workflows

#

also what methodology u would consider

molten sky
#

honestly it just depends

#

don't really have one specific methodology

#

sometimes it's easy sometimes it's completely custom

#

building out a new monitoring/enum/validation/etc server for myself rn and 90% of it is just service based and dockerized

#

they all play together nicely and exchange information as needed

cloud summit
#

Awww it won't show it, it has Try Hack Me on top

sharp citrusBOT
molten sky
#

(for image embeds)

graceful thistle
#

I just had a great idea for a project. I want to be able to play DMC5 and DMC3 at the same time with 1 controller 8)

stuck lichen
#

anyone know how to figure out who behind a tiktok account

#

how i get them

graceful thistle
#

why do you need that information

stuck lichen
#

because its a ship account and its one of my friends nad im tryna figure out wjo

naive violet
#

No?

glossy portal
stuck lichen
#

no one gonna say its them

#

becuase i wanna know who it is

naive violet
#

Yes, and you're not a moderator.

whole yew
#

Unethical, it's not allowed anywhere.

twin ridgeBOT
#

Gave +1 Rep to @whole yew (current: #10 - 733)

rapid merlin
#

What's a ticketing in soc?

naive violet
#

Did you google this?

amber wing
#

hey guys if you would have a mac i7 what free vm ware would you install to do kali linux without problems, Thank you!

lament tendon
#

VirtualBox, I suppose.

fresh cobalt
#

Anyone understand the purpose of Task 10 PATH on the Linux Privilege escalation room. We’re supposed to compile a C source code that trigger thm wish is a simple shell. It works only if the C script is compiled with root privilege so what’s the point if we are not yet root . I was able to solve it by using the one already compilez on the targzt machine that is already root . any idea ?

simple valve
fresh cobalt
twin ridgeBOT
#

Gave +1 Rep to @simple valve (current: #24 - 345)

brisk tree
#

Nothing better than pulling a muscle in the gym πŸ™ƒπŸ˜‚

naive violet
#

And practice πŸ‘€

golden timber
#

Any legitimate advice on revisiting tryhackme after a long break, half completed rooms make things hard to get back in the swing

#

My guess is just get good?

mint palm
glass nest
#

You can always re-do rooms

golden timber
glass nest
#

Or jump in the deep end do a challenge room - It will all come back to you

golden timber
#

Yea well, the tutorial walk thru rooms are good for learning but I dont find them as fun as the real boxes

glass nest
#

Yah. Depending what bit you wanna focus on. OWASP/Juice Shop for web, What the Shell for shells..

golden timber
#

It is really hard for me to pick up on them

#

I guess I am focused on completing learning paths when I think trying a challenge first would prompt direction where to learn

glass nest
#

This is about getting back after a long break though. Honestly, even just reading through tutorials you've already done, much of it will come back to you

golden timber
#

Essentially the challenge box will be a pre assessment and guide me better than a learning path first

#

BC I'll be like oh, I dont remember that, now I know where to hone in

glass nest
#

Good option. But it's more like you'll be 'Dang, I used to know this!'

golden timber
#

I just have a hard time digesting content without finding an issue where that knowledge would have benefitted me

#

Like, I need to hit the wall first

#

Good insight, this helped me

#

I'll try that

glass nest
#

It's cool, I awas away for about 2 years πŸ˜„

golden timber
#

Welcome back lol probably around the same here

glass nest
#

now I have more tools (granted they are for woodworking) and slightly fuller beard, as that makes me wiser.

golden timber
#

Its like, learning threat modeling after you've done juice shop might give you a different perspective vs before it

glass nest
#

The OWASP rooms are honestly a goldmine. they cover so many things

golden timber
#

Is bug bounty a good boost in income eventually

#

BC I think owasp to that pt would b nice

#

While applying for jobs I'd love to try a few bounty programs

glass nest
#

Eh. We get like 5 young folk per week who've done 0 learning and wanna JUST learn bug bounties because of some of the high rewards.

golden timber
#

Yea

shell nova
glass nest
#

But certainly worth having a pop at some of the low-hanging fruit

shell nova
#

it's a huge effort for relatively low payout

golden timber
#

I want what I can get but knowledge over all

glass nest
#

Don't we all πŸ˜„

golden timber
glass nest
#

Of course.

golden timber
#

like, would that motivator make it worth while? other than the knowledge acquisition

golden timber
#

That's a fair position

#

See, I genuinely don't know - I could see either side here

glass nest
#

Also depends on the job you are aiming for

shell nova
#

depends on what the personrobot on the other side values

golden timber
#

yep hydra, completely right, in this market..

#

well, I appreciate you guys being real w me and helping - I know a lot of people have high expectations by the glamor of cyber. I understand a lof of it is hyped up and being monetized/marketed by all the influencers

lament bobcat
#

Thanks for new learning path πŸ™

shell nova
#

most people won't get much out of bug bounties

golden timber
#

but the people who do are outliers for sure or very skilled, stumbled upon a bug with a large time cost, etc.,

glass nest
#

Dupes, and t-shirts πŸ˜„

cursive flame
#

Hello, my name is fola and I am very new to cyber security. However I got stuck at the second task on the beginners page. Though I am using my phone for this exercise, does this have any effect on my exercise or I am doing something wrong? Please I need help!!!

golden timber
#

I guess I'd just try bug bounty for fun and worst case I get knowledge out of it, but I wouldn't be doing it for the money, only the valuable experience and marketable nature of being able to talk about it

shell nova
cursive flame
#

Now I see why I get stuck

#

Thank you, I will try with desktop later.

fresh cobalt
split ore
#

Also, I think phones aren't exactly the best way to learn beginner stuff. Virtual keyboard isn't doing any wonders, even if it is possible to run attackbox on a phone, using it may be difficult

golden timber
chilly veldt
#

Morning

brisk tree
#

morning

golden timber
#

Mow some lawns

spice adder
#

CVE-2023-32367 for those curious

golden timber
#

Oh very nice

sick lance
#

@mossy river this u?

rapid merlin
rapid merlin
zinc folio
rapid merlin
spice adder
mossy river
#

What’s wrong with burp suite

glass nest
#

Maybe its too useful?

hearty gull
#

wassup esqy

glass nest
#

Eyup Linkan

hearty gull
#

you got some tips for sqlmap? like finding parameters and some useful commands or smething

glass nest
#

Oof, Not used that in ages.

hearty gull
#

well ima test that

glass nest
#

Task 2 covers the commands

hearty gull
#

yeah

chilly veldt
#

my whole schools internet has turned off

spice adder
spice adder
#

If it’s a box and know it has sqli I just run sqlmap <url> <params> β€”dump till I get something cool most times

worn thorn
#

why not manually hunt for interesting tables and entries first. I'd dump as a last resort.

spice adder
#

If it’s a box then it’s just quicker with no risk of shutout due to noise unless there’s IDS or WAF

#

Why spend time manual testing all the way to creds once you’ve already found an sqli in a request

worn thorn
#

using only automated ways can be boring after a while and you don't actually know why it happened

spice adder
#

This is true. But you get ample verbosity if user cares to look at the path sqlmap took. I’d rather know for sure that sqli is the intended path for a box by automating it in a few minutes rather than manual testing for 10+ minutes. I still recommend manual testing as a first call for your reason alone though

brisk tree
rapid merlin
#

Anyone have the problem after learning some stuff you cannot sleep peacefully because your mind keeps racing back it?

loud marlin
gritty zephyr
#

Happy day @loud marlin

loud marlin
#

ello ello

gritty zephyr
#

Heyaaa

wintry sluice
#

"oh god, I've got mud on my hooves. eww. jump yuck. jump disgusting .jump I sure hope no one is filming this"

gritty zephyr
#

Ypu have a vivid imagination, i like that

loud marlin
#
#

result is like you have black hole of a car πŸ™‚

rapid merlin
#

πŸ‘‹

rapid merlin
#

thats me when i was 13 lol

loud marlin
#

when i was 13 i eat mud =/... burp didn't exist at all lol

mossy river
#

Hey @rapid merlin can you change your pronoun, it is not appropriate for this community

chilly veldt
#

sooo muuuuch CCNP PepeHands

mossy river
#

Thanks πŸ™‚

loud marlin
chilly veldt
loud marlin
#

πŸ™‚

rapid merlin
chilly veldt
#

well technically ENCOR v8

#

but still CCNP Enterprise: Core Networking

ancient cipher
#

What's everyone hacking today?

warped crane
#

Yo ppl how's everything going

wintry sluice
loud marlin
#

they did have some pack of network and so

spice adder
rapid merlin
#

what are you now? :p

warped crane
#

Wanted to ask something, to hack another machine first i have to get it's ip address and then open terminal and use ssh (target ip address)?

spice adder
#

An older script kiddie πŸ˜‚

rapid merlin
#

lmao

spice adder
#

That gets paid at least

loud marlin
warped crane
#

Then what's the use of secure shell?

rapid merlin
warped crane
#

Isnt it a command to access another machine through ip?

wintry sluice
warped crane
#

But as mohta said there must be an open port

spice adder
wintry sluice
#

pretty much. its just a way of connecting to another machine. what you do once you are connected is another matter

wintry sluice
warped crane
loud marlin
#

skype was new thing... back in my time

rapid merlin
#

damn you old 😭

ancient cipher
pastel vigil
chilly veldt
near hawk
#

Alex what book did you win?

warped crane
loud marlin
wintry sluice
pastel vigil
warped crane
#

I am not going to do so

#

I am just trying to understand and learn what is ssh for

#

Coz i remember a room where it required me to use ssh to connect to another virtual machine and get the flag

#

So i thought that's how hackets connect to other machines

#

Using ssh

#

I don't know how else can anyone access other machines coz that's as far as i got kekw

pastel vigil
#

IIRC, that flag was just a text file somewhere on the computer. that room teaches you how to navigate a computer with SSH and find a specific text file

wintry sluice
warped crane
wintry sluice
#

that's how everyone starts out.

rapid merlin
#

Hi everyone. I'm new here/

wintry sluice
#

hello, new here

warped crane
#

Hi new here

rapid merlin
rapid merlin
warped crane
shell nova
rapid merlin
surreal plover
tired peak
#

that pic isn't what it looks like but from far away it looks very questionable

golden timber
#

Is this a weird job application question

#

or is that just me?

spice adder
#

Yeah I had some awfully specific questions on an application form for startup businesses this morning. I don’t mind, but trying to find the relevance to the application leaves me confused

near hawk
# golden timber

I don't understand the whole purpose on why jobs do this, just makes it annoying to go through and submit the application

gritty zephyr
#

Having a teacher trying to explain python to people who dont know python when hes vague as balls is fun

gritty zephyr
wintry sluice
wintry sluice
gritty zephyr
#

Yeah that would suck indeed

simple valve
gritty zephyr
#

No but i meant the specific hiring on ethnicity or sexual preference for diversity

simple valve
wintry sluice
#

to quote a relatively famous district attorney: "The world is cruel, and the only morality in a cruel world is chance. [flips coin] Unbiased. Unprejudiced. Fair."

golden timber
#

seems really just like data harvesting

simple valve
#

I do know some programs try to hire for diversity or at least try to allocate a certain percentage of their hiring for diversity hires

golden timber
#

that seems a little controversial imo if you're hiring a certain race

#

for the purpose

#

like, if that makes sense

#

like why cant' we just hire based on skillset

simple valve
#

Bc of privilege

#

Anyway, I don't think this type of conversation is going to go anywhere good and I think its a good time to drop it now and talk about something else

golden timber
#

i just think if you can do the job, you can do the job

#

yeah that's fair

wintry sluice
golden timber
#

I guess all the power for them to do so

#

but, I'd like to opt-out

wintry sluice
#

anywho, how about that weather?

spice adder
#

Yeah, it does make you wonder if these questions will sway your chances in the final selection though. I had one's about social-economic upbringing as well as sexual orientation today

golden timber
wintry sluice
#

that's quite the commute πŸ˜†

golden timber
#

yeah for a $16 an hr job, no thanks

glass nest
#

Age is a thing though. In UK anyway. You can work when you are 16 BUT there are loads of rules the employer has to follow, especially if the person is still in full-time education.

#

Although the employer may not be able to say 'No' as a result of your age, technically it can't be directly about that, but more likely is things like - The role will require more hours than they allowed to work per week, There are certain tasks that need to be done and needs to be someone over 18 and a company simply might not have the resources to support that

#

If someone is 16, they can only do 2 hrs on a school night and have to be finished by 9 or 10pm. Although there are some jobs that have that, there are many others where thats just not needed

gritty zephyr
glass nest
#

See, That would depend on the industry aswell

gritty zephyr
#

grocery store stockboy lmao

glass nest
#

There is some wiggle room, but again - Theres a lot of Risk assessment and all sorts around it

#

School holidays up the amount of hours a young person can do aswell

gritty zephyr
#

"no madam, we DEFINETLY dont have the product in the back, but sure ill check anyway" simulator

wintry sluice
#

some products are age restricted too. if you can't buy them because of age, you probably can't sell them either.

glass nest
#

No idea why so many of the young folk on here are eager to get into the workplace. Work is so much more of a pain in the butt. Ok, you get paycheck (after the government takes their cut), but if you mess up? You're gone. No after-work detention. Plus most of the paycheck goes on other stuff - commuting to and from work, smart-casual clothes etc. Plus, you're spending most of your waking week in that place, so even spending that money becomes a pain

#

DJ - Every store has a 'Back' where all the good stuff is kept. a Magical store-room with all the items in the world

#

Aye, So although working in a newsagent is cool, They wouldnt be able to sell booze - and have to get an over18 to do that for them

#

That being said, Nothing against young folk getting a part-time job - Once it doesnt interefere with their education. Just.. at my age, I yearn for the simplicity of going to school, listening to a few lectures, and head home at half past 3

#

At which point, Mom/Dad will have dinner already cooking and the house will be clean

nova pollen
#

But what do you do with all this free time without money πŸ€·β€β™‚οΈ

glass nest
#

Theres a lot of beauty and fun in this world thats free.

nova pollen
#

Which you don’t appreciate at that age (mostly)

glass nest
#

Zactly. Even just hanging out with friends. Doesn't really happen at my age - Everyone is usually busy with their own work or with their family.

glass nest
#

Emerald, Still not 0xD? I'm not angry. Disappointed πŸ˜„

ocean hare
#

LOL!

#

ok i confess

nova pollen
#

Yeah I know the feeling. Also a lot of my old pals moved away. Me included πŸ˜… so you just can’t meet up that often

ocean hare
#

i actually don't ever bother answering to the modules i complete

#

but i do progress

mossy river
#

πŸ€”

#

So how do you know you’re correct?

ocean hare
#

Addicted to demos and walkthroughs on youtube

#

guilty

#

if challenge boxes gave more points, i'd be golden

shut hawk
#

They do give more points, then walkthroughs

ocean hare
#

?

#

rly

shut hawk
#

yes

ocean hare
#

how much does a medium one for example give? say 0day

sharp citrusBOT
shut hawk
#

That I cannot remember

#

ah I've summoned the docs

mossy river
#

It’s all on the knowledge base

glass nest
#

The whole website is a knowledge base πŸ˜„

mossy river
#

Some don on the bus was handing out Ferrero Roche to everyone

glass nest
#

Jabba - I'm gonna need a hint, I don't know the song in your profile thingy

#

I can usually get it, but not this one

mossy river
#

I can’t tell if you’re being serious or not

glass nest
#

I am.

mossy river
#

It’s by Khalid

#

Not DJ Khalid

glass nest
#

You had Zombie by the cranberries a couple weeks back

mossy river
#

It’s whatever the vibe is when I think about changing my status

#

Zombie was the vibe of the week

brittle flume
#

has anyone ever used lacework for container security and is the product any good? or a similar container security tool they would recommend

glass nest
#

It's a fun side-quest πŸ™‚

simple valve
#

trivy is good @brittle flume

mossy river
#

It’s my secret way of finding someone with my crazy music taste

shell nova
#

harden your containers properly πŸ˜‰

glass nest
#

Yep, not heard that before

brittle flume
brittle flume
twin ridgeBOT
#

Gave +1 Rep to @simple valve (current: #24 - 346)

mossy river
glass nest
#

The guy whos first in the office is big into hiphop and R&B from the 90's and naughties, so thats usually whats on in my background

wintry sluice
#

I use headphones

glass nest
#

I don't think it's possible for me to ever forget about Dre at this point πŸ˜„

#

Oh yeah, I headphone it up if I need to stay focused, but many things in the job need me to be calling people and talking to folk

brisk tree
#

trying out microsoft copilot and the images it can design is mad

floral wing
#

Is being in the top 5% considered good or is it normal ?

toxic glen
#

I got to the top 1% and then gave up on tryhackme

#

Nothing left to do.

#

So the % thing is what you make of it.

floral wing
floral wing
toxic glen
twin ridgeBOT
#

Gave +1 Rep to @floral wing (current: #2011 - 1)

floral wing
#

Can I see how many rooms I have completed on the site ?

spice adder
floral wing
spice adder
boreal scarab
#

Morning!

wintry sluice
#

but its 1500....

#

silly murican

boreal scarab
#

10 AM!

boreal scarab
wintry sluice
#

I made no such offer.

#

imagine not keeping track of the time with UTC

boreal scarab
#

Yes you did you said 1500

wintry sluice
#

I never used a currency symbol

warped coyote
#

Hello everyone, I performed a scan with nmap on my personal server using a basic command that included -vv and it gave me the ssh private key. Does the -vv command itself execute a particular script?

wintry sluice
#

just means verbose level 2

warped coyote
#

I litteraly got SSL certificates of all the services running + ssh key

#

how is it possible

simple valve
#

not the private key

warped coyote
#

ooh

#

how can i break it down ?

simple valve
#

break it... down?

#

not sure i understand what you mean

warped coyote
#

I mean

#

unhash it

#

and use it

simple valve
#

you cant

warped coyote
#

its md5 encrypted

simple valve
#

its a hash

brisk tree
#

i started an nmap scan at 11:53 and its still going ahahaha

warped coyote
#

but can i use it ?

warped coyote
#

and what can I do with my SSL certificates

simple valve
warped coyote
#

they all are outdated

#

what does that mean?

simple valve
#

i have a strong feeling that its not your own server

warped coyote
#

it is

#

why would I lie

simple valve
#

if it was, you would know what those mean

#

nwy, i will refer you to jabba, he knows more

#

@mossy river

chilly veldt
#

I was just about to say that, let's have the expert handle it

warped coyote
#

its an ancient PC from my grandma lmao

simple valve
#

will you be doing cyber apocalypse?

warped coyote
twin ridgeBOT
#

Gave +1 Rep to @simple valve (current: #24 - 347)

chilly veldt
#

Been hitting top teams last couple of years, so of course we going for it again

proven cave
#

Hi, I am looking for like-minded people to learn with me on tryhackme. throwback German language is important as I can't speak English well but understand it legibly. cri
I would be very happy to hear from you if you are interested. happyCat

mossy river
gritty zephyr
warped coyote
lament tendon
#

Who are have ping me?!

gritty zephyr
#

Me

#

Hi

lament tendon
#

Oh, hi, whahaha.

wintry sluice
lament tendon
#

Generally would not be against it.

warped coyote
lament tendon
#

Howβ€˜d you like to go about learning together?

gritty zephyr
#

XD

proven cave
lament tendon
gritty zephyr
warped coyote
#

a web server yes

lament tendon
#

I did accept your friend request.

proven cave
gritty zephyr
lament tendon
proven cave
twin ridgeBOT
#

Gave +1 Rep to @lament tendon (current: #36 - 207)

sick lance
warped coyote
#

yes

gritty zephyr
#

Isnt it your grandma's?

sick lance
warped coyote
#

buddy

#

she gave it to me

#

I was clear

gritty zephyr
#

Csnt hurt to make sure

warped coyote
#

I think you're just a waste of my time

crude stump
#

πŸ˜‚

#

Be nice

gritty zephyr
#

Oh no a person on the internet doesnt like me, whatever shall i do

lament tendon
#

🍿

wintry sluice
gritty zephyr
simple valve
chilly veldt
fathom ruin
warped coyote
#

yeah my debian laptop with 4 giga of ram is very expensive

#

apache is very expensive too bro

rapid merlin
#

I just made a vm

#

What syntax do you use to redirect bash history to null?

glass nest
#

@molten sky Might know πŸ˜„

proven cave
mossy river
warped coyote
#

LMAO

shut hawk
warped coyote
#

bro dont get it

shut hawk
#

I haven't had food since this morning, forgive me

glass nest
#

Dude! It's like 4-pm. Go get your grub on!

shut hawk
#

I knowww just haven't been feeling well ☹️

near hawk
#

The only thing i've had is a Caramilk easter egg

glass nest
#

A Balanced diet is good for recovery. Good job Blackout πŸ˜„

shut hawk
#

I had an apple, keeping the doctors away

steady pond
#

Guys do u have group or discord for crtp/crte?

mighty herald
#

hi i am new guys

wild rose
#

I think matt touched my PC cuz it BSOD while trying to update vmware.

rapid merlin
#

Nvm, got it

#

How’s everyone doing today?

carmine sedge
wintry sluice
#

you are forgiven

near hawk
#

In slang for brits it basically means crazy

#

can be used in good or bad way

carmine sedge
#

Why are Brits and just Euros in general better hackers than Americans

#

I make the joke with my friends that the only way you can afford to live anywhere near London is to work in technology

near hawk
#

I wish that was true

#

It's like 2k/month just to live in london

brisk tree
blazing granite
carmine sedge
near hawk
#

Yea true, I want my own place but everything is expensive. I wanna buy a house but cheapest one is like 200k-250k

blazing granite
#

I lived in London, but it was a different time and situation. I lived in quite a posh place πŸ˜‚

brisk tree
sand trench
#

meep meep

tired peak
#

in the US, people would wish a house was $200k-$250k

desert shuttle
#

tomato tomato

carmine sedge
carmine sedge
sand trench
#

houses around shadows area is starting at around 1 mil sek and some go up wards of 15 mil sek

#

sek being the swedish krona currency

blazing granite
shell nova
chilly veldt
#

My 62m2 apartment in Denmark costs me 751 USD a month

sand trench
#

96568 usd

shell nova
#

I was looking in EUR, but yeah still very reasonable for the first figure

carmine sedge
near hawk
tired peak
#

apartments in my area are minimum $2500/month

shell nova
#

London is insane. So is Paris

tired peak
sand trench
shell nova
#

yeah but reno work isn't that bad either, at worse you'd be doubling the price

brisk tree
shell nova
#

unless it's a demo job

blazing granite
chilly veldt
#

In Copenhagen if I want the same size apartment it's 2200 USD a month

shell nova
#

kinda glad I was able to buy my place when I did

sand trench
#

also that number shadow gave is what it was in around 2013....

carmine sedge
sand trench
#

so dunno about now

carmine sedge
brisk tree
#

yeah

blazing granite
#

I may buy a place in Argentina, as investment and also to have it when I come to visit my family

tired peak
carmine sedge
brisk tree
#

hes on 45k now so its all good ahaha

shell nova
#

wheee, fluff added

blazing granite
#

but the real estate in Israel it's expensive

fathom ruin
carmine sedge
blazing granite
# fathom ruin because israel in a war

I'm not going to enter in politics, specially with people who don't know the day to day of the situation, but I've lived in Israel since 2001 and it always had been expensive, the current situation has nothing to do with the prices.

carmine sedge
brisk tree
#

his ex had to share a house with 10 people in london just to survive

tired peak
shell nova
#

median salary is a bit higher in California, yeah

tired peak
#

I'll say California is affordable to me but for many, it is a stretch

carmine sedge
tired peak
#

fun fact, my salary range was higher in the DC area and it went down when I moved to California

brisk tree
carmine sedge
blazing granite
brisk tree
#

its so cheap and great weather

carmine sedge
tired peak
#

where I live, its not 2 mil for a 700 sq ft home

carmine sedge
ocean hare
#

delete that

tired peak
tired peak
ocean hare
carmine sedge
# ocean hare πŸ’€

thats the only reason I think the housing market hasnt completely tanked is because of poeple who bought in like 2017

shell nova
carmine sedge
blazing granite
shell nova
ocean hare
brisk tree
#

it is amazing and super safe

blazing granite
brisk tree
#

ahahahahaha

tired peak
ocean hare
#

read that again

carmine sedge
brisk tree
#

you should go on holiday. the food here is phenominal

shell nova
grim sparrowBOT
#

:mute: lifeemerald#0 has been muted.

tired peak
blazing granite
shell nova
#

would've gotten around to that I suppose, @tired peak

carmine sedge
shell nova
#

Feds seem to mostly stay in DC and Las Vegas IMO

#

πŸ˜‰

#

(that was a joke)

brisk tree
carmine sedge
sand trench
#

the feds currently have a hard time staying in sweden where they are outside their normal jurisdiction

#

^ also a joke

shell nova
#

To be fair, there probably are feds in here

carmine sedge
sand trench
#

oh shadow is betting on there being

blazing granite
sand trench
carmine sedge
shell nova
#

aight, I need to go home now

carmine sedge
clear jackal
blazing granite
shell nova
#

I mean Americans do tend to advertise the fact that they're American a bit too much