#general
1 messages Β· Page 52 of 1
Got one in like two minuets about to start if you want to
Never mind, not enough people joined so it's over
Ooouuu POC for?
super special secret hackerman stuff
Wish there was a downloadable lab or something similar. Even a person vs bot type thing would be great
No, wasn't enough people unfortunately
https://tryhackme.com/room/kothfoodctf
https://tryhackme.com/room/kothhackers
https://tryhackme.com/room/redisl33t
Oh damn, thanks man. Super helpful lol. Guess ifI learn to use my eyes I'd actually have known lol
Gave +1 Rep to @unreal solar (current: #122 - 51)
π
So, are there tools preinstalled like recon-ng, snort, etc, or would I need to download my own?
Morning

m
It's quite good
im no longer stuck
Good morning everyone
m
yoo
How are yall doing?
fine how abt u
both tired and wide tf awake at the same time
Yeah I have the same mate
just spent the last several hours doing powershell stuff so life is fun /s
π
~~ no ~~ yes
on the one hand..
i need sleep
on the other.... i've got so much shit to do
and the other other... i don't want to do any of it
i've had this exacto knife on my desk for like 2 weeks now that i just keep playing with and i have no idea where tf i got it from
just appeared here
I planned to do keylogger as my final year project in python what kind of api shall i use i am so confused can anyone suggest me?
I think I broke my switch setup
how else would you see a website?
you have to get access to the html before the website can load?
you can get access to the html even without inspect π
but you'll need access to the html no matter what, otherwise the website wont load, html is the thing that makes the website
π
Morning all π
You can copy the html to "clone" the website, so you can browse without interaction with the main site.
We don't discuss these sorts of topics outside of #advanced-general
I doubt a key logger has the required complexity for a final year project also.
Guess what james
Done that was fun
Scams like that occurs often because it's (like you said) as easy as copying the HTML/CSS of a website. However, you cannot replicate the domain name of the website, which a end-user will most likely notice, even though these fake websites wil try to imitate the domain name as closely as possible.
This is an "evil bit" solution
Off to Dundee today in about 4 hours
And you keep asking this and you always get the same answers @rapid merlin
Do you know one definition of insanity?
π
Trying to listen to alien broadcasts?
me when reading CCNP
yes, CCNP. Not CCNA
reading and reading but getting nowhere 
Did you just skip CCNB through CCNO?
yeah, and then skipping everything from CCNQ to CCID so I can take CCIE
What bit of CCNP are you trying to understand?
currently doing a lab on GLBP
Ahh. that was the graphic you posted yesterday?
don't tell them about view source
that too, or curl
I have a quick question
I did that for my cicd pipeline status so I could feel better about it failing with no obvious reason
Changed the fail to a pass π
I have a quick answer
Does anyone here have experience with Software Defined Radio? Me an my team have been looking for people who are skilled at it
for a ctf?
Definitely people here for that anything in particular? There's actually a thread where some radio discussions take place
Yeah, we've been doing Ringzer0CTF and was never able to get that section done
We can't help with active ctfs unfortunately
I'm not asking for help, just looking to recruit for a team lol. Ringzer0CTF never shuts down, it's 24/7
Also https://nohello.net/en/ while it's a joke website, it is also good guidance for how to ask questions effectively, just helps you get a quicker answer and makes it easier
I don't want to come across as a twat but it's worth a look
if it never stops, then it's a good way to learn SDR
Also I disagree with not saying hello, it's more the question asking part of it π always welcome to say hello and chat here
Insane? I was insane once
they locked me in a room
@finite basalt hello
What the crazy I was crazy once meme?
Crazy? I Was Crazy Once. They Locked Me In A Room. A Rubber Room. A Rubber Room With Rats. And Rats Make Me Crazy is a copypasta that loops the aforementioned line. While the origins of the meme likely predate the modern internet, variations of the poem have been posted on the internet since at least 2002. Versions of the copypasta also include ...
Alright guys you all take care, I got to finish this machine before my wife gets back and sees me hacking again π
Morning! How're you? π
a rubber room
Gl mate
A rubber room with rats
rats? rats make me crazy
Crazy? I was crazy once
aaa
sounds like you've gone crazy
I had a brain once 
human or it doesn't count here
i just believe i have one but cant prove
goose
@lavish shell I'd personally start by trying out one of the public websdrs or one if the airspy server network boxes on SDR#
Look at the waterfall, poke around, use the SIGID wiki to look at what you're looking for and get your bearings
what is sleep?
it's what lazy people do
Alright, thanks for the heads up. I'll look into it
Gave +1 Rep to @naive violet (current: #1 - 2103)
Hi, can someone help me ? I'm looking for Act of Kindness Badge, which room is contained? Thx
the act of kindness badge is given out to members of the community who have done great acts of kindness and can only be obtained by an admin giving them it personally
OK, thx for answer! I'm just looking for missing badges, sometimes I have finished room before badge is add.
And Webbed badge ? Where is possible earned?
In this module, we'll take you through the building blocks of the world wide web and explain in detail exactly what happens when you enter a website address into your browser. From DNS to HTTP protocol this module will give you all the information you need to understand the world wide web.
THX
hey
Gm.
hows things
Yeah, can't complain.
Yourself?
yeah good just looking at twitch overlays ahaha
For your own channel?
yeah thinking about streaming again
Hacking or gaming?
Gonna Collab with Ego?
I know, lol.
hax
h4Xx
-T0 
im using -T5
don't use -p- first?
try rustscan, it's way faster
i just used the command i was told to use then cause it ran for 6 hours yesterday i just added -T5 to it or it would scan 16 million ips
π
What if it's not a CTF?
break all the things
Jeez, not even going to ask why the whole /8 netblock. Just checking for alive hosts or going straight to ports?
Is this part of your Internship?
Hoiw's that going?
it is. its intense in a good way they are preparing us for real life work. feel like ill get a years experience in these three months ahah
They must cram it in, if they're condensing 12 month in to 3
There's somebody else in this server who's doing the same thing.
they arent im just saying with how intense it is
ahaha
got 53 nmap scans to perform this week
Anyone here doing devsecops
official now?
Yeah.
Hey
Nice, finally able to see in more depth what I've been running for some time now 
Did a full upgrade some time ago, and found myself on 2024.1 before release
the temptation to run my own Cybersecurity competition for students in my part of the UK...
Having to join a Discord server just to DM somebody 
hi, is it normal tohat ssh has no "up arrow" for seeing the previous command ?
bruhhh
do it
It can be, yeah.
depends on what shell it spawned
I likely will, may reach out to thm (education) to see if they wanna partner or something on it LOL cause I think it'd be great (now to decide what challenges to do, wanna do a 50/50 of red and blue)
i used ssh username@ip on the attackbox version SSH-2.0-OpenSSH_6.6.1p1
should i run ssh with other commands or upgrade the shell ?
so is it possible to start ssh directly with bash ?
Screw it, I will. Okay time to start designing the CTF
Good luck on the journey 
Thanks dude! Time to see if any of the educational places in my area are interested or companies wanna work together on this π
Gave +1 Rep to @unreal wadi (current: #690 - 5)
N,E,S,W of UK?
Yes.
Hello, this IT...
Good luck British pounds?
Have you tried swithing it off and on again?
Blow inside the cartridge, that helps me often times XD
IPv4 on top
How are you beside the tech troubles bella?
South West (Will DM a screenshot of rough area covered if youd like), however if I get national interest may run 4 area comps and then a final national one
Good to hear, did any rallying in the offtime still, or have you ceased that!
?*
heh?
haven't done much with my car lately, actually going to sell it soon as I just found a massive amount of rust
miata
stock, engine swaps are illegal in denmark
Good morn thm
Oh damn whats the reasoning behind that?
Heya
Any of you know openAI Api key alternative? I'm working on a discord bot, and they want me to pay 20 bucks
If it makes you feel any better I have a fist size hole in my boot well because of rust π
You can get an api key for 3.5 for literal pennies
"rust" 
Oh wasn't aware of this, checking out
Ainβt no rust if there ainβt no metal there π
Good morning
Hahahaha
laws
Np dude, Iβve been using 3.5 turbo 16k and the most itβs cost me in a month is just over $1 lmao
making it "unsafe"
Lots of requests to api as well
ain't no way
thanks man
Np np
But do you know why they made the law, emmisions?
Ah right
Miatas are fantastic cars. A lot of the older ones have many rust issues tho but luckily the majority of their panels are replaceable, cheap to replace too
Can buy a whole sill for around Β£70-100 here in UK
the new path has so much information to absorb i feel stupid
if parrot os freezes allocate more cpu or memory?
Have you tried allocating more, instead of asking? π
What's the worst than can happen, you freeze it faster?
Have you checked which one is being filled?
@chilly veldt some lil shots of my friends mk1 mx5. I miss that car so much. If ur thinking of a new car, definitely a good choice
oh no lol i asked first
Yo that yellow car is fire looking
Danke 
I have driven NA's before, and got friends with Drifting/track versions of them π
Ah sick! The 1.6βs are fantastic engines and the whole chassis is an amazing platform to build on
The most fun Iβve ever had in something just over 100hp
1.8 π
Naaahhh you want the 1.6 if you ever want to do anything with it modification wise. A lot more reliable to work with. Or just drop a mk2/2.5 engine in it and have a reliable turboβd lump in it π
no, I drove 1.8's
but I am going to get a 1..6
Oh I see, great! good luck with the search
Theyβre pretty overpriced these days, as much of the old jap stuff. Worth experiencing tho
already got one in eyesight, though yeah, need to save up
With the THM ctf rooms can I exploit them to get more info within reason or do I have to follow the room properly? I wanna be able to practise what I learn fully but don't want to get in trouble either
You are the master of your own learning
If you find other ways to exploit something, more power to ya! In fact that's how you know you're getting skilled.
Obviously not DDoS or getting into internal servers or anything like that just strictly to the machines themselves
I just wanna see what I can do with my skills I've learned via THM
In a legal setting
Is that allowed?
As long as youβre not breaking our TOS then yes
Yeah I'm not gonna do anything stupid or anything that feels off.
It'd just be good to practise everything I've learned
You mean like taking a CTF room and exploiting in other ways than it wants you to right?
Yeah within reason
Oh yeah thats completely fine I've seen people do it before
THM has been great for learning
Real I been here since 2021 I believe
Never stopped paying for it once, its such a game changer.
Yeah roughly same here with next to no experience lol
Had never used Linux before not properly
Didn't know how to operate VMs or what the goes were with ISO files lol. Even something as simple as ports were new. I mean I knew about SSL/TLS but that's pretty much as far as my knowledge went.
Never heard of an FTP server lol
I was the same way, I tried to extract their local VM env as the ISO file, I had to figure out later that I was supposed to get the bare metal for an ISO file.
Yeah and even getting started with openvpn to connect to theirs properly was a mission ππ€£
Im not gonna lie I struggle with that still sometimes, something to do with it saying its connected but not working on THM's machines even though I can connect to their test site.
But yeah I wish it were more user-friendly at first to get the hang of Kali
Yeah i remember having to change something in the ovpn file to get it working and it took a while lol
Lots of Google and YouTube
Yeah I like to watch NetworkChuck
He's good at explaining things although I feel like he's for younger people
When do I not have coffee?
Yeah he's pretty good at explaining core concepts for newbies but idk how good he is at a professional level
Yeah he got one thing right professionally
Coffee
Yeah NetworkChuck I feel is for younger auidences, if I were 12 I'd be watching non-stop.
Ironically my passion for programming and then into hacking was because of roblox and C language I wish I knew about him back then
Never understood programming language. I'm trying to learn python and having a lot of trouble.
2010's hacker movies π
The only hacking "movie" I know is Mr. Robot
You remember that one hacker movie where they hack a whole group? Like frame them for something?
Does matrix count? π€£
Oh yeah that's really good too
Badass.
The first one yes. 2nd and 3rd movies were eh.
MR. Robot inspired me to be better it is so cool how they integrated cybersecurity into a show so accurately
I only remember the first, was too young
That's lucky lol
yeah I pretended to be him when I first started watching it, wouldn't recommend emulating his personality xD
Altho last parts of 3rd movie wasn't too bad. Ctrl C and Ctrl V of Agent Smith/Hugo Weaving
Haven't watched the 4th one.
Looks like they put Snort back in Kali.
He is def schizophrenia
Can't do it without laurence Fishburne
Fantastic show. Genuinely wish I could watch it for the first time again
yep DID, but it's just another way of coping with reality
That's another tool I've been having trouble with lol. Did the first 2 rooms. Snort and the basics. But I think it's live attacks I'm stuck on at the moment
doesn't help that he doesn't get serious help...reminds me of a certain someone in the programming community...
Which is sad but cool at the same time both psychologists and programmers / hackers can all get something out of it lmao
The art of deception, who better to share thought with other than a psychologist, or another hacker π
FB and Reddit give Kali users a bit of stick lol
Therapist, if only he got therapy early man
Also art of deception is a fantastic book
haven't read it, checking out
oh social engineering
A classic for social engineering. Really worth the read
Reddit is a dumpster fire.
I'm usually careful around that stuff, "if you lie down with dogs don't be surprised when you wake up with fleas" but yeah it's a skill I could use, if acquired ethically
Yeah it's turned pretty badly but even most FB groups to do with cyber and Linux give Kali users stick
The Secrets of Reverse Engineering is a good one too
Thick book full of interesting material
Good thought. Itβs a skill in this industry. One that I donβt have a lot of direct practice with
@lone thistle
Do you have any W7 images for VmWare? π
Iβll check that out, thanks!
Gave +1 Rep to @spare vapor (current: #472 - 9)
np
You do much RE? I fell into a black hole of it about 6 months ago, love it
Used to but I took a hiatus for my mental health and forgot pretty much everything
FB probably not much better
I plan on returning to it when I complete Cyber Defense path
I must add, I still hate how complex typecasting can get. Skill issue for me tho
Any reason in particular you think Kali users get stick aside from the stereotypical h4x0r?
Gotta look after yourself, you understand your own path. U got this 
Thats when you change one datatype and convert it to another right?
Because it's pretty much "plug n play"
Yeah, gets confusing for me when Iβm working with entities n fucking referencing a type casted relative address within an object of a module address
Ubuntu seems to be the same but Ubuntu doesn't get much stuck
That is the skill issue part for me 
Sticl
https://blackarch.org/
Honestly blackarch is worse, the website literally screams script kiddie vibes
BlackArch Linux is a lightweight expansion to Arch Linux for penetration testers.
Can't type tonight
Arch user's seem annoying af
Every FB post "I use arch BTW"
Is it ment to be a status thing in Linux? Lol
It's become a meme
ubuntu has a bug that prevents terminal from opening, if the locale isn't en_US
Tbf the reverse engineering I donβt mind, itβs the development of projects to work with reverse engineering finds
I just gotta get better at C
I can't remember what I set mine as but haven't used by Ubuntu vm for a while. That'd be fairly annoying though.
it's just a meme that they like to flex what distro they use
I'm not sure why, but BA logo always reminds me of the Delta Force emblem and original CoD MW
I'm gonna assume arch can be a pain to set up from scratch or something
It can be, but it's a lot easier now with the use of graphical installers like other linux distros
absolutely! stopped deploying my vms on ubuntu when even setting en_US didn't open the terminal 
I can see that
Sounds like Ubuntu just trolling lol
Oh makes sense. Graphical installation is a lot easier.
Somewhat ironic for me considering I find command line tools easier to use than graphical tools like Burp or Wireshark
But with command line just have to remember the switch and syntax ig
Some of the graphical tools has stuff everywhere it feels like Windows
Graphical interfaces have their use, especially for showing large amounts of information in an accessible way
Yeah snort/tcpdump involves lots of scrolling. Not that Wireshark doesn't but it's not hard to find what ur looking for at least.
Well idk about tcpdump only used it a handful of times but I remember having to scroll a bit
Honk
GUI and CLI both have their pros and cons in specific use cases
Yeah definitely depends.
But I'll always prefer command line I think
Can snort record live network traffic like Wireshark does?
e.g., tshark (cli) is great for quick IP parsing from pcap, but fails to show extended data in nice readable format when you can get it quickly out with wireshark (gui)
Yeah Ive used tshark a few times too. It's really good.
my company simulate phishing attack, and 277 users fall for it. they enter username/pass π
You ever used snort? I heard it was pretty good too
I've just been learning it
I've done the first 2 THM rooms n halfway I think through the 3rd
also nobody knows how many of them have already entered their credentials in a non-simulated phishing π
if there was any, that is
It's definitely good to learn. It does a lot of different things
I didn't even know they had a room for it, I just started using it myself a few days ago
we have 2fa for all logins. and for sure we have extra high security in general due to nature of work and so
but you are not wrong
277 people got called into office? π€£
Yup, heard it was good for network intrusion prevention
i think they might do some education for sure
There's 3 I think. Snort, snort the basics and snort live attscisb
Attacks
ugh... was in the middle of final task in exploitingad as time ran out, and network shut off. Wouldn't be an issue, but even after restarting the network, no icmp or other packets go through anymore. Anyone want to chime in with a reset (currently 3/5)?
Which subnet?
did you click the link π
10.200.83.0/24
at home, outside the company network and did OSINT. i reported it at same day, just i enter eatshit@die.com Y0u5uX87
and i was THIS close to male some flood thing to automate enter/send
nah. hight power hold me nack. it is shade area to do. and i kinda think it was simulation due to some OSINT. was to easy to pass to us in first place
@sick lance did you get a ticket for the conference in the end?
Nah, I've got uni on a Friday π¦
Anyone is a hacker ?
nope
Hacker? What's that?
a big knife that hacks instead of cutting, maybe?
I was thinking a cereal killer, but a spoon doesn't do very good at hacking lol
The epic story of one man's encounter with the most relentless murderer of all time. Real movie in the works! Details: https://www.youtube.com/watch?v=gbqKLJtOaGw
Subscribe! http://bit.ly/subscribeRG
See the entire HSM series: http://bit.ly/hsmseries
Exclusive content on Facebook!
http://www.facebook.com/RichardGaleFilms
Rate The Horribly...
death bt the spoon
Yeah!
Why does he kinda look like the owner of McAfee
lol
I think I was trying to SSH into the wrong domain, there are multiple domains in those rooms like ZA\ or THMWRK1\ etc.
if you are born deaf... on what language you inner thoughts are ?
sign language
=/
vibrations in morse style code
Pictures
And indeed sign language
might be
Prolly what ever they grew up listening too
Wait lmao
Bruh
I didnβt read
I wonder if deaf people have inner monologue, not everyone does
I find it hard to comprehend what reading must be like without inner monologue
Imagine reading in braille
Lol ive just seen weβll be exploring ctf websites in our ctf lab class & thm is one of them
THM bout to get more users lezgooo
Is it possible to run Windows on my Mac Mini M2? (without a VM)
Yeah
Mac has the option to dual boot using boot camp assistant
not anymore unfortunately, only if you have an intel cpu
I think it's only for Intel based chips
Sounds like a very Apple thing to do
M family chips have different architecture than Intel. So the only option is virtualization
I miss playing Valorant but I dont wanna buy an extra PC for it
I doubt that VMs use your GPU enough to run a game
Check if you can use cloud gaming for it such as nvidias one
You can run it in chrome
I think theres a input delay in shooting games
I never had issues
But Iβm also not a serious gamer
Did you try shooting games on it?
A few
were you able to hit some headshots?
Just need a direct rj45 ink
In pvp Iβm usually the one getting shot
But I have in story mode
lol ill try it
Just finished Jr Pen Tester. That was juicy
Congrats π
I wonder if it's the same statistics as everyone else or actually more common
@shut hawk
Got your Arc E-mail yet?
I've had 3 now... 
no, I even emailed them about my student email not working and they haven't gotten back to me βΉοΈ
Why THM emails has been landing into my spam folder?
I use Proton Mail and it says that the THM email domain has failed the domain authentication check
Your E-mail rules, perhaps.
Rules?
In my email box, I just created a specific rule to forward THM emails into a specific box
That's it
Be me:
-Wake up to hear a strange beeping sound. Panik
-Don't hear your server running. Major Panik
-Power is out Panik
-Remember your server is on an Eaton UPS Kalm
-Eaton UPS isn't supplying the server with enough power to power the PSU's Panik
-Power comes back on. Kalm
Lets go Nvidia made me Β£7
I don't think you passthrough for your GPU and VM, otherwise Hashcat would be good to go from a VM AFAIK.
I believe it's possible? But its certainly not recommended to do
Much better support on the actull host
Did something change with the GPU market? Suddenly 30xx series laptops and PCs are reasonable
Probably becasue the 50 series is coming out soon
I connected with a senior security engineer at Rockstar games and it's taking every ounce of me to not ask about gta 6 leak π
99 more members on the Reddit and will do a sub giveaway
Scrubz, just did the event for how many from our soc and alumni are going to the conference, we got about 30 π
We an army
Hell ocan anyone help me I want to search for a value within any table of a database in mysql
I never care much about leaks of AAA games anymore
I get excited for indie devs making a new 16 bit platformer
going for an enjoyment meal today π
:/
Always the leap years
That's literally an "evil bit" solution...
π€£
You know that's solutions that don't work right?
π
to simply answer your question: yes some do.... how does shadow know?? well had some deaf friends from school and asked them to explain things.... some kinda see the signing they do as abstract inner monologue and others more see text as their inner monologue
anyone see what is wrong in this image???
what the...
you spot the error vain???
with google genie?
π
Huh? No all the sweet ones on Steam
set up ssh? or the developer mode part
it is in the set up ssh part
sudp apt install openssh-server
hint: || look up what distro steamos on the steamdeck is based on||
π
it's pacman
haha yeah it is based on arch so it would not be apt install
not to mention it is immutable
yup
Man I love these things. Actually gives detailed info
So that file casually encrypted everything!
Good thing you didnt run on your own pc
I mean it's the little report thing from one of the modules
@mossy river you there??? got a question
It's cool to read through and see what it did
Hm?
see image above
and also how you are doing and if you found the information about deaf people having inner monologue interesting
Is this a static report on tryhackme or is it an active thing it runs
oooh it is from a tryhackme room
? Yes
thought you were messing with malware samples on your own computer for a bit
Hell naw.
Whats the name of the room btw?
I just did a fresh wipe as I do like once every 2 years just to keep it fresh.
Pyramid Of Pain
ahh
anyways time for shadow to head to the store and pick up some french fries
But it takes forever to load when you click it so Iw as wondering is it a software snapshot that actually runs, or some static "info"
Vs the other questions using a simplified report you sift through to identify answers and info
Oh god. No the real deal
Like Panzer Paladin
the link is a static version of the analysis task. So an analysis isn't ran everytime, it's just a shareable link to the analysis that was done originally π
Which?
She thought the static report was malware or sum
What a good day
what
@pallid lotus just arrived in your ends π
Usually the next working day automatically or you can reverify and should update it
hmm k
Next working day? π€£
Funky sentence, go sleep
I'm forced to play Palworld
By whom
Girlfriend
Recenlty addicted to the game
I hope youβre aware I already knew that entire conversation
Is Muiri still in Dundee?
I thought they left after graduating.
I know where Muiri lives π
But I'd never say
Yeah, I think I asked the after they graduated if he moved closer home, and I can't remember the answer.
Even then, I can't remember if they're from Invernees, or near it.
π
Hii all. I need some advice on certs plez. Considering doing eJPT because people are doing it. But I don't have a clear idea of what I wna be doing π \
Good morning all
Hiya alex dot exe. Long time no see π
Same to you! How are you?
Living the dream. Unwidning after work to re-energise then into the workshop π
sounds fun
I spoke with a recruiter at an agency this morning. Was pleasant
A little typical recruiter slang. I was gonna play corporate bingo
What are you making???
you need to add 'put a pin in it' and 'circle back'
You''re doing a cert because people are doing it?
I don't understand that logic...
thanks, I found this on wikipedia actually https://en.wikipedia.org/wiki/Buzzword_bingo
Buzzword bingo, also known as bullshit bingo, is a bingo-style game where participants prepare bingo cards with buzzwords and tick them off when they are uttered during an event, such as a meeting or speech. The goal of the game is to tick off a predetermined number of words in a row and then signal bingo to other players.
Gave +1 Rep to @graceful thistle (current: #22 - 350)
gotta match others idk
got a couple of jigs I need to put together, then a box, a reel for my air hose, gonna have a crack at a foldable chair - which I will template up so I can repeat it easier
and inbetween it all - organise the workshop a bit better
Everyoneβs situation is different, the cert might be close to useless in your area
Surely though, you'd do all certs, because people are doing them?
Which area of the field do you want to move in to?
Welcome to life, brodda π
I can't decide for sure. I am between VaPT and GRC rn ( I am currently doing )
Let's take this offline
ah yeah good one
Then look for certs which specialise in that area?
Sounds awesome!
Visit https://redis.info/nicholas2 and get started with a free-forever plan or use the code NICHOLAS200 to get $200 credit for any paid plans (starts at just $7/month)
Just shipped this new video and I think it's gonna be a huge win for us in Q5. Let's circle back on this to unpack our key learnings and touch base on any action items with our ...
Alex - so much woodworking is making stuff to do woodworking π
eJPT is related, but I only have 5 months experience so idk if I should buy it now or later π€
rn there is a sale for annual fundamentals on eJPT
Custom tools for custom works!
You donβt really have to buy the INE course, everything (or most) can be found for free on THM
eJPT is not that much of an HR boost, but Iβd take it as a really expensive lab and a fun experience
Yeah, I have most of the foundational knowledge and concepts grasped. It's just I have to find practice to the relevant subjects/techniques tested in eJPT.
I am doing ecppt with non IT background and with basic of cyber security knowleage Im doing a best
If you have a lot of spare money then Iβd say try it out, but otherwise there are better alternatives
Guys i am facing a issue with the xfreerdp
How long have you been preparing? and when are you planning to do it?
can any one help with it
Got it, thank you mate
Gave +1 Rep to @mint palm (current: #267 - 18)
3 month
Whatβs the issue
Wishing you success π
btw, if you buy the voucher, does it expire after some time?
now i have trying Buffer Overflow Prep
I have buyed totally 6 month valid to take test
now it is over 3 month
Ah oki
till have time to take test may month !
β$ xfreerdp /u:admin /p:password /cert:ignore /v:10.10.103.16 /workarea
[23:35:20:831] [28493:28494] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
can any one help with it
I have google ed but i am not geting solution
Pmed
Or please point me to a right channel
Vouchers don't expire
it will expire after 6 month
No they have no expiry date
you speaking about INE !
Ahh sorry, thought you was reffering to THM
#room-help is better if you need help on the rooms
thank you dude
Are there any active discounts for THM subscription?
There is 20% off if you are a student I think.
Yep
You're account would need to use a student email for the discount to be reflected in the pricing π
Doesn't need to be.
Good evening everyone, im new to these part of it. I have a little problem with my section. Can i ask here?
You can E-mail support and prove you're a student that way.
You can contact support and prove it that way
Section of what?
Not a student. I guess there aren't any active promotions?
https://tryhackme.com/room/operatingsystemsecurity -> the password provided in the instructions is wrong. i try bruteforcing the password
Not a problem if not.
there isn't, no.
#room-help for this, it could get lost in here. π
sorry, thank you
Spent 40 min trying to debug why my code wasn't starting, realized I didn't call the function
yup although I probably made the function too big that it was almost all my code
so didn't even realize I was coding inside a function until later, (was continuing a few months old project)
This only occurs every 4 years π
The leap year bugs, definitely not Citrix/Sophos vulnerabilities π
they've been having quite the run
So have EA π
Just wait for 2038
It's weird to think about 2038
Firstly if I'll even be alive, since anything can happen and our health is never promised. And secondly, how wild will tech be
I will get past this great firewall of Windows 7! 
Was talking to a guy about bugs, he said that he hated them because they crawl on you when you sleep π
They're not wrong.
Technically wasn't the first ever computer bug literally a moth that got fried inside one of those old giant room size computers?
TIL Google warns you about password breaches even if your password isn't stored with them
Where? π
I am assuming anywhere chromium touches. It happened on my phone and using chrome on my pc
Were those password breaches for gmail addresses/email addresses you registered to google services with?
Yeah, Bitwarden has the feature. I just wasn't expecting it from google because I don't use any of their account management products
No, work email and an account with an organization that is not google
hmm ok interesting
Yeah, it was a surprise. Though I suppose it shouldn't be considering how much google has their fingers in at varying levels
At least you know your password was breached
After? When I see a breach I start swapping passwords right there, and generally any other accounts associated with it either via linkage or the email used.
I don't play that game.
In 2024 someone doing crap on your account can lead to a period of pain in the butt time fixing it all
Have you considered the fact that they might not be able to change their passwords while at work...?
The only thing that was disappointing to me that got breached was my club penguin account
This
club penguin was a old game right which got shutdown?
Am I that old?
Yea, then they put it back up
do people still play it
Not sure been a long time, pretty sure Disney made their own one then that got shutdown

I wasn't able to get my account on the remake version
I couldn't either, although I just wanted to play it again to get to black belt
Anyone know when Deadface is happening this year? Maybe October 20th like last year perhaps??
The past has been in October, so yea most likely then
I think Duolingo is wrong here smh
As someone who goes through many thoughts at one time, this is sentence I would say
I mean eating a schnitzel at a waterpark is also possible
The coffee is cold. Do you swim here?
I donβt think you realise how many times Iβve pressed the coffee on that same question
Ok quick question, i need to simulate something on a phone(see it as a playbook) for my digital forensics semester, for that i want to inject stock photos with exif data to simulate it being taken at a certain place, anyone know a tool for this?
Like where i can add time/coords
its not π
except that water != Kaffee ^^
android emulator?
True. I just tell my boss I need a few though. But not all bosses are flexible or care, I've had some that aren't.
Itβs a sentence you figure out by context but there is a lack of context and it can be subjective
imagemagick or exiv2.
Alternatively I am sure that there is some way to do that with ffmpeg, if you have too much free time.
Well, you swim in water, not coffee, so that's your context
On IPhone you can also just click on the "Info" icon in your gallery and add a place there.
It doesnβt imply that you have been in the water or swim.
Itβs actually a really odd sentence, it would make modern sense to be βDer Wasser ist kalt. MΓΆchtest du schwimmenβ
*Das
But I got your idea.
Used Duo for almost 3 years. It got worse by time π¦
Fun fact: there's actully a spa in Japan where you can swim in coffee 
Duo has gotten really good, but as someone who speaks German to my friends, it doesnβt really prepare you for actual conversations.
But the concept is very well made and it does work for casual learners who want something to do on the go.
People that actually want to learn a language should use Duolingo as well as watching TV shows/ movies, reading books, conversing with other Germans and researching grammar, sentence structure, etc.
My biggest problem with Duolingo is that it tells you how to do it, just not why.
There is a language app that tells you why but I forget itβs name and itβs a premium
Yes, correct, I get confused when switching between two languages lol, I was still thinking of coffee hence the wrong gender haha
As someone who also used to speak German and has been to Germany multiple times, I agree
"My biggest problem with Duolingo is that it tells you how to do it, just not why. " dont question german grammar, i don't understand it myself as native speaker
I speak a mix of German, Turkish and English which is utterly useless in actual conversation because the words I donβt know in German, I never actually learn.
I'm speaking 4 languages, German as mother tongue. i still think Ger is the least intuitive π
Are you thinking about babble for the other service jabba?
Not everyone can just blindly follow the rules. Especially me, I have to understand why something works before I apply it.
It also makes sense when you grow up in the language but English doesnβt heavily enforce cases which means people learning German from English can struggle with the word order and the forms of the words changing.
Iβm not saying you canβt just go ahead and remember all of the sentences, just means itβs really hard to create your own sentences and imo it creates more effort.
I think it might be, yes
And! A perk of learning German at such a low level actually improved my English
One tip I can give you on your german journey
It's die Nutella in case you ever get asked
What? Never! It's DAS Nutella xD
DIE NUTELLA
are you basing that on the article Italians use for nutella?
Krapfen or Berliner @plush mesa @wheat crater
iirc they use la
Berliner
I guess you could use any article in german
Krapfen! π
A. yeah it has a feminine ending
2. das Nutella is just wrong
oh god
its late
der nutella
cant even do numberings anymore
Oh god my brain interpreted that as a 1 wtf π
der nutella is 100% wrong
das feels best, because you know, it's an inanimate object lol
but thats a bad logic
Every object would be das then
Wow, the duden says you can use any article
It's both feminine, masculine and neutrum. Even though the ending is feminine ;)
Aahahahaha, I did not ever expect non-german people to argue about this. xD
Das Nutella here, der Nutella there.
Not even Germans agree.
You would be amazed how Austrians and German can argue over language π
Iβve had my fair share of German disagreements π
same argument with Marmite/Vegemite - in nz and AU - sorry but the brtitish stuff is gross
This reminds me of "Ich bin ein Berliner"
Marmite is disgusting
At least he got a laugh
Should be burned from existence
All the good speeches are funny
You can literally leverage the answer to this questions as OSINT, because it's region dependent what people call it. 
Yup π
Itβs always fun to get to people from different areas in the call and ask the question
thanks π
Gave +1 Rep to @lament tendon (current: #35 - 208)
nutella π€€
They are different
if you're new, use Kali
if you're pro, Use Kali
If you're really really pro, use ubunutu and then turn it into Kali π
does anyone know if possible to change the cipher suites of a subdomain only?
on cloudflare
this sounds like a lengthy way to say "don't use parrot"
I don't use Parrot, I don't know anyone that does that I worked with, or have worked with. But I look at like this. OffSec, some of the best training, some of the best people, make and use.... Kali
The best tools are the one you use, you like and are comfortable with,
Try both, in VMs. See which one you like more, and use that.
You can use any OS you want, it's a matter of building or locating tooling that matches what you want to do, and then platforming it in a way that's easy for YOU to deploy and manage.
At work, it literally doesn't matter what linux distro I use, because I use IaC to manage my tooling and tooling config. Every security assessment gets a 'fresh' VM and the playbook gets run from scratch.
indeed
Since we're on the topic. Obligatory don't use Obsidan π
kek
To my experience, the actual difference between Parrot and Kali isnt that big. Just UI stuff
The Obsdian devs fight their user base enough, I'll defer to them π
Parrot has been much more unstable for than kali, and comes with a lot fewer tools installed by default.
I, personally, wouldn't recommend Kali Linux, yeah it's great because it comes with all sorts of tools pre-installed but chances are you're either not going to like the tools, not use the tools, not know what they do, or are otherwise unfamiliar or uninterested in the ones provided.
Wait
Did you just argue to remain ignorant? Don't learn new tools. techniques and only stay with what you know?
Lol no, let me explain
But some people like parrot more; my experience with parrot is that it made things more difficult (not less) and so I dumped it. Kali is a good enough platform for most of the security activities you'd expect to do, and it's oriented towards new-to-security but not necessarily new to IT.
@lavish shell you should verify first :0
Funny thing is, kali broke 2 times at my pc, and parrot didnt
It isnt down so
but I like obsidian
That is unique to you; Kali used to have a tendency to break on big version updates. Since they moved to a rolling release, it's been much more stable.
I did too, I really did.....
I'm always going to just be a OneNote weirdo
Yeah to make it better, older versions were more stable xd
I had the cannot-log-in issue
Point being, you can grab an OS crammed pack full of tools that take up a lot of space, or you can use an distro like Bodhi where you have the extra space and can install the tools you want and not have a ton of space used up by tools you don't like using
the login loop
Kali minimal is a thing...
why not?
Just like Android is an OS
But also, Kali coming with most tools by default is great when you don't have internet access likea gov't facility
Cold server room in the middle of nowhere, you know what you have
(Parrot has most tools Kali has too)
So, big advantage, and Juun is 1000% right since they started doing the rolling updates with regression testing
I understand what you're getting at; often, new linux users don't really get how to install all that tooling on their own if it's not in a compatible repo. That's fine, we shouldn't gatekeep people from exploring and learning security topics because of it. Kali is a 'good enough' solution for those kinds of introductions, and it does simplify tool management for many orgs who use it as the security distro of choice.
And when you are learning. ok you might not use a lot of the tools, but there are some tools you'll use a lot π
do you recommend something else instead?
hiya Toaster π
Joplin
Hey Esqy!
I tried every tool under the sun for notes, i think a few folks here know that π
Joplin is the best mix of ease, accessbility, sync, multi user.
Currently giving Trilian the college try
Obsidian just stopped working for me randomly
Trillian has some very strong arguments for it; I like the note-locking capability the most. Joplin is a close second on that front, and does tagging better though
The old software that combined ICQ, AIM, MSN, etc?
lol
you old
Do you remember when it was called Gaim?
I do
Pepperidge farm remembers
It really depends on what you prefer honestly, I prefer something that offers more customization. That's why I use Bodhi. To each their own, Kali is good, hell I don't think there's such a thing as a "bad linux distro". But Bodhi offers so much in terms of customization
Arch
π
see, I prefer something that actually works π

I sure do love compiling!
Whatβs poppin
I love using heptabase
Does anyone know of any OS written in a mem-safe language?
Does Tails have that?
If you find one, ping me. I'd be interested in that.
wonder about NixOS or one of those immutable core
So is DHS in America π
they mean stop using C
Did the whitehouse just realize risks of memory in 2024 or something?
Like it wasn't a thing in the 90s
I don't think so, e.g. Rust is also considered memory safe to my knowledge.
yup
C# is also considered as mem safe afaik
Ok, thanks to the background code in this image I stumbled about an absolute comedic gold mine:
https://stackoverflow.com/questions/1642028/what-is-the-operator-in-c-c
Gave +1 Rep to @cosmic pendant (current: #37 - 191)
You just have to ignore all the normal answers. ;)
Sounds like a perfect fit for AI.... /s
reading the explaination ruins the joke tbh π
wut???
Fun fact, this actually works.
yeah it works but why the meeps
meep?
YAY the sixel branch of alacritty on the aur got updated
boo tmux not handling sixels well in alacritty
guess it is time to bring out zellij
[#2]
This meme went quite popular during July-August 2021 and i decided to finally upload a full video (without that weird black and white watermark in it) version of this meme.
Music is Heartaches by Al Bowlly. And for those wondering... i am the creator of the original meme. It just flew under my head back on my EATEOT times.
I can imagine the smell
I can't π
I don't know wtf is going on with my VM, it's hating against the tryhackme site today. I used it for endless hours last night, now it's saying I have to use a desktop version.
I often forget to turn off the proxy on my VM
Nah, that isn't the issue, it's reading my bowser as a mobile version rather than a desktop version
i was told to use thm by cyber security police thingy (at school) and im only 13 lol
i only use kali for burpsuite because ubuntus graphic are weird
good luck
ty
Small update on my very important scientific work.
C++ is great.
im experienced with lua coding (can do most stuff off by heart) but not other languages and cba to learn them
Welcome! Don't worry, you're not alone - a lot of the users here are quite young
Ty
Anyone from the homeserver squad around?
Ask your question
Need some opinions on cloud backup options. What's y'alls provider, if you have any?
Got my issue fixed lol, someone thought it'd be funny to change the browser settings to where it would be initiated through a terminal session rather than starting regularly when clicked
Hell yeah, still more efficient than Python 
Comparison of Instant Messengers
Here's a comparison, I like using filen personally
I've been thinking ideally of a Nextcloud instance, which'll be hooked up to an external cloud to ensure data integrity because as much as I can trust ZFS, well. 3-step backup ideology
Looking at Idrive, Blackblaze and whatever else's around for some 10TB plan
Filen looks decent, yeah
Idrive looks just a bit cheaper with its $300/year plan compared to the translated $431 filen's charging you
Or would be, if you're using 10TB that is
Which well. Quite a bulky amount
Filen had half prices on black Friday which is what I got
What are you using 10tb for?
10tb is alot?
Barely an EmmaByte
for us, simple mortals, 10tb is nice π
@bold latch if you want cheap backups - backblaze personal
Felt like a sweet spot for a "set up and forget" type homeserver plan i'm expecting to last for a lifetime
you can also just buy a 14tb HDD for like ~$130
and put it somewhere safe
as a backup
with a physical 4x4TB NAS system
well, the whole point of an online cloud backup is if something happened to home, data's not lost
store it at a friends/family place
mb even throw it in a junker PC to do online backups
and i'd need it sync'd regularly, yeah
right, that's a good point. why not just invest the Β£300 yearly into a second server to cluster and run an additional ZFS pool on
zfs send | zfs recv best
ππ
use that budget to replace faulty drives and ZFS redundancy backups to recover data
ahh. imagine. 1 server with ZFS tier 1 redundancy and 4x4TB. another server with ZFS tier 3 and 4x8GB storage or somethin
how do you abbreviate that when labeling
are you the one who created the video
no
ckt?
CCT
reasonable, but probably not. if it's a "pay what you use" case, i've seen backblaze seem reliable on that front
oh actully
π
you were supposed to say CKT
$140 a year for 6TB
yay, I won π₯³
i just had the realization that depiste CKT being the norm around here.... why do we use a K???
everything's a lie
pronounciation
or buy it physically for 80$
that'd be a great deal, yeah. looking for consistency though, rather than any potentially temporary deals
I think it locks you to the price
https://www.tarsnap.com/deduplication-examples.html
Finally theres this, now I have no clue how it manages to reduce backup size this much, but seems pretty good for power linux users
Tarsnap deduplication examples
Last time I used a cloud based server it stayed the same price since 2018
Still dropped it though
just checked, its $240
oh wow i misread the original msg
ahhh, gotcha
Hey red teamers

