#general
1 messages · Page 54 of 1
I know you I know you, add me and chk our mutuals
Hahah
Funny
Nice moots
Funny 🤣 right
Yeah bigmanskid is a cool guy
I forgot who j is
Nvm i know
Thats my fav person on discord
Good developer
Yeah him and wizard are pretty cool guys
Haha thats funny
Never thought i'd see someone that knows them here
Now we are good frnds right 😭
Yes besto friendo
I know everyone one, I'm from good security background you kmoe
Not much com kid
❤️❤️❤️❤️
Do you know of the chon's
❤️
Harmless got termed again lamo
Not sure
It's back, he made new accountz
Im not in new server
I guess this is a sign of I play too much
anyone who can help me with a ctf? dm pls
Is it an active CTF?
hello can anyone help me understand hashing?
noob question: Whats the point of hashing when there are tools online that can reverse the hash? Or am I misunderstanding something?
Is this why "salting" is used? So the hash is non-reversible?
Hello i need help something that is personal it was not id hacking or related to that
They're not reversible, that's a lookup table.
Salting prevents precondition where you build a table to look up the hash to password.
Okay so everytime I use a online reverse hash tool, it can find the password because its already stored in a table?
Yes
and salting is a addon to a hash in case its already on a table??
It prevents all of these precomputation attacks
but are salts like the same or are salts also hashes?
Ask the question?
If we can help, we can.
ohhh this explains it well
salt is added to password then hashed and stored
No need for the DM, just ask in here.
so salts are random values?
I am on app it has a prediction game of fruits how can i make it for mine
not random. you need to know/store salt or so to be able restore pass, so to say, in case you need it
How can it predict which fruit you want?
Or do you want to claim the app?
🤔
ahh okay, but do we know for example the function for MD5 that makes the hash?
it can be some random thing, but it needed to be known
if we know the function for a hash, cant we reverse it?
What do you mean?
if pre hash is not known then reverse is extremly hard
like i am on talk talk application a virtual application there is a game that we need to put coins for play so i wanna make it for me
point of hashing is to be fast in one way, but extra slow and pain in reverse it
So you want to rig the game to get money?
i wanna to make that game
for my application
Ah
You want to copy it, or create your own.
yes\
Is this for homework?
not homework just my greedyness to learn
Are you wanting users to use virtual, or real currency?
now... if you know all about the blender, salt and whatsoever before what it goes inside blender/function... tyou cant just get all it back in original state
When a password is on a "lookup table" that I can get by reversing a hash on a online tool. How did they find out the hash for a password?
as i am using that audio application we pay coins to play if we win we can send it and at the end of month we can get money
its stored in table
but is it because they compared two hashes and already had the password and then they get the same output hash?
29f2c1eae0b60c967c90f8513c871258 > delete all
This might help you understand a bit better https://www.tiktok.com/@davidbombal/video/7341037322483420448?is_from_webapp=1&sender_device=pc
yes
and even slight change is another hash result
aahh
that tables we call rainbow table
okay now I fully understand stand
yeah I was looking at crackstation.net
and I guess they have a big rainbow table for passes
shouldnt this be in .txt
linux dont care for extension
i downloaded over windows
]
tht idk
all resutls have fixed lenght. so if you do not know of password or so pre hashed getting it back is extra hard
now try to get this back
how??😆
that's the point
impossible
without bruteforce otr so yea
so can I use hashcat or john ripper for a simple hash reverse?
if you have years of you life yea... or good rainbowtable
then its fast
if prehash is in table
is rainbowtable same as wordlist??
now even if is in table and salt is added later then is even hard
hashcat and john don't reverse, they just generate tons of hashes really fast and sees if they match
kionda
im trying to do this
Crack this hash: $2a$06$7yoU3Ng8dHTXphAg913cyO6Bjs3K5lBnwq5FJyA6d01pMSrddr1ZG
You cannot dehash, reverse, or decrypt password hashes. These words confuse a key concept of how password attacks work. Use 'cracking' instead. This is why.
wild Hydra appears from nowhere
a rainbow table is a mapping between the hash and it's plaintext
that's bcrypt, no?
is this your card
and program compare hash and if it finds it it spit out password
compare provided hash
nope 😉
huh okay
and that's hydra 🙂
so If I find a matching hash, how can I recieve the password for it?
rainbow will show as result only
can I use hydra for cracking this hash?
kinda
not easily, and very slowly I guess?
without good rainbow table is hard
if not hydra how would I crack this hash?
it'll spit out the plaintext that generated the matching hash
go look up hash collisions
so where is this hash from anyways?
tryhackme Task 5 in Hashing - Crypto 101
tbh you want your salt to be unique for each entry in the table
you'll probably want hashcat then
or john I guess
for bcrypt they're both equally slow
sigh
im completely new to hashcat, how would my command look if I wanted to crack that hash?
knowing its bcrypt
I'd look up the help page 🙂
give me your fried chicken recipe hydra
take chicken, flour, egg, breadcrumbs, then dump in fryer
I cant find bcrypt in Hash Modes
cornflakes also work
gotta let them research, mate
but yeah that's a good reference
I only know of that because THM told me about it
if you give a man a fish, he will eat for a day. if you teach a man how to fish, he will eat for a lifetime.
25600 then
maybe, try it
found where THM told me of that link
Task 4 of Hashing - Crypto 101 😛
Is this right? I put the hash in a txt file but it doesnt seem to work?
thanks
you need more RAM
(its not my screenshot btw)
So @heady quartz
I suggest you to crack on your host
Hello any help??
Maybe there are no designers? ;p
how do I crack on my host? or add ram
Can you suggest me some colours
if its a VM, change the settings
I am not a designer
Im sure there are discord servers for that
Still a review
Sorry im at work mate
Morning
Mornin'
No hash-mode matches the structure of the input hash.
I keep getting this error on hashcat for this hash: $2a$06$7yoU3Ng8dHTXphAg913cyO6Bjs3K5lBnwq5FJyA6d01pMSrddr1ZG
sounds like a job for google
Ain’t a designer but my favorite color is blue
nothing tells me what hash type this is
Use this tool to identify, detect, and analyze hashes online
Cooking up some hashbrowns
thats gonna be a good weekend
yeah worked the second time
Awsome 
I have paste the link to my website
Can anyone tell me what IS Management means in cybersec?
Are you referring to information systems?
I believe so yes!
This is a module in my study
and I was wondering what it will be
IS Management, mapping, authentication methods
1st of March and the first snow of winter just started falling
Yeah at least it won't stick since it's been raining and temperature is about 4C
Haha best I've got is a nice toasty room with my laptop and a little hacking to be done
Sorry for asking such a vague question but its all the information I have haha
what is the context? Like where did you see that?
Hi Zojja!
I have not seen you in a while
@glass nest Pretty much almost fully recovered now, last week they measured the wound 1.5cm now they measured again today and now it's only about 3mm deep
1.5cm deep??
Yea had a back surgery which they leave it open, was originally 4cm
what
Wow
they leave your back open?
under the left side, it already says "Information Systems", they are being vague but I would take that to be various computing devices
hey hey
That was on 23rd Jan when I had it
Yea an open wound surgery
alr t hanks!
ah alright, glad to hear you're almost fully recovered
what was the cause?
It was an abcess that infected my tissue from 4cm deep 10cm long and 3cm wide
Hey guys thank you for having me here am New here and want to start my career in cybersecurity so am starting with the Tryhackme
Pre security course
is that from the US? cuz I think Information Systems is an old term... like 40 years old, maybe something you saw in the 1980s/1990s
welcome
Tryhackme is good to learn for someone starting out in cybersecurity right?
yup
#room-hints and #room-help are great places for when you are working through TryHackMe to ask for specific help
there is also #pre-security-legacy-path
Have to verify
Thank you 🙏
Anywhere or DM's.
when you type /verify, no one can see it here but you could DM the bot as well
Okay 👍
Yet another beta invite for Arc...
Why did you sign up with so many emails lol
I didn't, these are all the same E-mail...
But the invite is associated with the email?
🤔 huh
Speaking of email....I saw down and cleaned out my emal after 4 years
Took hours
Luckily you can bulk delete a lot of that crap
I auto sort my folders.
I have a few rules, but only for things I just need a record of but no tsee
I have rules set up so the E-mail from x will go to folder x
Now I just sit down once a day and clean it up
Granted this is my professional email
My old personal one I just need to napalm
@shell nova I can see you 👀 
I should do that too xd
But i dont want to
I segmented it. LIke an hour here, hour there. Eventually it got done.
Feels nice though
Yeah fair
Wayyyy too tired
Congratz!
awesome!!! Congrats!!!
Congrats on that. The big success!
i like arc tho
They offered me a base salary and a bonus based on performance. If I wanted to negotiate the salary for a little more how should I go about it? When the recruiter asked me for a minimum figure they offered me more than that already but I'm thinking 2-3k more.
did you already accept the job? what is the job? whats the offer?
I didnt say anything to the recruiter yet
I said I need to check a few things
the job is junior information security analyst
so what you could do, is say that you would want to counter. Did the job have a listed salary range?
no
I mean, it wouldn't hurt to ask for more, worst that can happen is they say no
You can generally search job title and by state
how should I ask nicely =]]
I would just say that you would counter offer at (XX amount).
If you find people in your region make more on average for said position, and the company isn't extremely small, you counter with the offer you want and also reinforce the transferrable skills and benefits you bring the company that really make it worth it.
and I would also emphasize that you appreciate the offer, you are excited about the job but would like the amount you have determined. 2-3k won't make or break an offer
Yeah if they like you, they like you. They generally pick you for a reason.
yeah Im thinking £3k more
Least likely to murder me in my sleep
I asked chatgpt to create a message 
NO
lol
I mean it can give good ideas
But don't copy any of it. Write it in your own way
Give it that special spark of "you"ness. You are what sold them on hiring.
I'll also say ChatGPT messages are notably ChatGPT messages and don't seem human
If they do take it on the chin.
I'm sure there is people who'd love to be in your position and possibly ask for less.
Been a hiring manager for almost a decade and if a resume or response bores me it's not likely to overpower others.
I didn't want to say that the true worst they could do is say no and move to another candidate.
I've taken a position for a title before, got that onto the resume, then moved on. But I'm old now.
No job is your last job.
I'm a senior technical type, I do tons of resume reviews, luckily we haven't seen applicants using ChatGPT but for resume reviews online I've done, I see it a lot and its very noticeable
Most people use GPT entirely wrong lol
It's a tool to enhance human creativity, not replace it
yup
I use Co-pilot for really stupid things.
github copilot or the bing one?
Bing one.
the bing one is fun to play around with
I got a call from the recruiter to say why the sudden change in salary expectation
I use Chat GPT-4 as a mini-dungeon master aid for enhancing my ability to adapt on the fly when my players do something really silly so I don't have to spend 5+ minutes getting stats together
Got a lil custom GPT for it
and what'd you tell them?
I'm thinking of going to Trader Joe's to pick up some things for my husband and I's zoo trip today
I said I did a little bit more research about the average salaries and this offer that i gave them is still lower than average, she said that during the interviews etc I said minimum is x they offered me 3k more than x and now I asked for 3k more. I said it would be a fairer starting point for me
thats a good answer
can they retract the offer because I asked for more money?
Is this your first ever cyber security style position?
I would've also probably thrown in "inflation"
im scared I fucked it now
Yes
yes
oh yeah true
they can retract the offer but most companies won't retract for 3k
like if you had said 20k, maybe
I've retracted offers for that exact thing actually
Isn't this the UK though.
I'm not sure.
That's a good sign
They can if the offer wasn't already accepted
If it was accepted, no
im scared now tho I dont want them to retract it
well they can but do they is the question
she went to relay the info to the manager
I think you are right they shouldn't retract it
like we wouldn't retract an offer for a few thousand
But neither of us can speak for other companies
I'm sure you'll be fine, just don't be dissapointed if the offer isn't matched.
^
huge jumps tho, we may be like "sorry we cannot meet this and we may not be the right company for you" OR I think HR has a little dance where they talk about bonuses and the "total value" of the position
You have plenty of time for raises etc.
Chin up
I won't have an issue if they offer isnt matched tbh
would of been nice for a little more but dont want them to retract it
lol
I think it will be fine, don't stress
But then, what do I know?
I just signed a contract today for some contract work...
So, techinally, this will be my first, unsure if I can list it as "experience" though.
they may even do something like offer a small bump up like 500
Yeah, that's true. they might match 3k, but somewhere inside that.
chin up
I've had to advocate for myself with job offers before and yes its always stressful
Zojja, do you do recruitment?
Good opportunity to learn to cope with stress/risk. Zen out and remember that no matter what, it isn't the end of anything
i am stuck x2
no, I'm on the technical side so I'm more involved in doing resume reviews / interviews
Ah, well I was wondering if it was normal for pattern recognition tests to be included in the application?
when cyber managers are hiring for people
Like the square ones normally found in IQ tests
Yes.
oh no clue at all
really?
ahh I'm in the US
i sohuld of just taken the first offer hah
nah you good
All good.
I wish I countered my first job offer but I didn't even know it was an option
^
Real
I do however note that I'm far more likely to accept lower if it gets me specific experience/title.
A title on your resume can be more powerful than a degree
@shut hawk
When I applied for Cyber and Security Analyst with Barclays, I was given 3 tests.
1 IQ, 1 personality and a mixture.
Dafuq
lol
I wonder why.
Aced all 3, then rejected me for being over qualified.
Personality test as in you get given questions and it's a "Strong agree, agree, disagree, strong disagree"?
should I just reply to her original email with the document she wanted me to fill in
LOL
Oh god
Tale as old as time
Yeah.
And
Scenario A is playing out, you're doing action B
Which is best
X / Y / Z
Fair enough
Yeah I've done similar stuff, but never 3 things. Mostly just personality stuff.
But I'm in management. My actions can benefit a company, or royally fuck em
So I get it
I've done things with problematic employees where I position a lead across from us with a large window when I have difficult conversations just as a CYA
How would an IQ test or a personality test help for a cybersecurity position?
Are my certificates not proof enough?
This, plus if you have tendencies to leave things alone
Unwillingness to confront an issue
Do they prove you can problem solve, or retain information and act accordingly?
I think so, I studied for the exam, that means I must have at-least taken the time to understand what I was doing
But that's my point though, you studied for an exam, IE you took data, remembered then answered questions.
IQ tests are usually "Which shape is next"
Makes sense, but don't you think a cybersecurity related test would suit best? Because I often see people correlate being good at chess with having high intelligence, but that is far from the truth
I'm seeing the same here
Yeah it's less of an IQ test and more of a pattern recognition test
IQ tests are meaningless anyway, you can train for an IQ test which basically defeats the purpose
Cognitive!
I had one of those too
Dissapeared too fast, my brain slow
What type?
(Lookup Grandmaster Krammik for proof and lols 🤣 )
Oh mathematics
Yeah, I was looking for example,s then found cognitive
8 / 0.4 = 20?
i had to do the same lol
yes
I had to do a combo of math tests in 2020 for a program.
Applied/Conceptual vs actual math. My actual math was trash, but my applied/concceptual was supurb.
I can't math on paper, but I can guesstimate exceptionally well.
@rapid merlin Keep it PG13
Kerberosting.
The next position I apply hopefully won't.
But I'll have a Uni degree with it, so 🤞
Fingers crossed and lets go!
Non-professional rant
WHy is every PC game today 100GB+

I don't have this kinda space on my 2 SSDs
should checkout vampire survivors
I'd say bad optimization and people just getting creative?
Great game
I lean more to that first.
COnsidering the massive detailed worlds people have made using less space. Lazy devs
In the 80s/90s devs were developing tricks to get more out of hardware limitations
Today so many just seem lazy.
I feel like if I knew my PC had a keylogger in a realsituation
I'd just write the weirdest Muppets/TMNT cross over fanfic stuff on it so that the perpetrator needs therapy.
So you can get stunning images like this
And of course discord screws it
I make that joke because at one of my jobs around ~2013 we found an old word file on a network drive from a former employee that left scars on all of us lol
What am I looking at?
Microsoft flight sim
Haven't played it since 1998 so I don't know what may be off
The whole world data is actually 2 Petabytes that it streams from, but the game engine and models only take 150gb
Yeah it looks a lot more impressive now haha
LIke no hiccups?
Only flying I do is in Warthunder and sometimes that goofy engine decides "Your Tornado has decided to marry the ground"
Runs at around 50fps on my machine
Gorgeous
Which is really really good considering the level of detail and realism
Feels like a great way to meditate/relax
Pop on some nice headphones, turn down the lights, lay back and enjoy the view
Jayy whats that qr in your bio xd
There's something called "VATSIM" which is basically simulated air traffic control, that's not so relaxing 😆
Look at the QR emoji names
I've heard how calm those folks stay during emergencies. THose are special humans
I'd be stressed
Ah
Yep they definitely are
A lot of things you need to manage while in that situation
There's a saying "Aviate, navigate, communicate" - this is the general order of actions when flying the plane
I've always been an ERT member at every company, and helped out in some medical emergencies. But you get to wind down after. Those folk don't.
My saying would be "Avoid the ground"
Professional the floor is lava
h
I wouldn't worry lol.
Your job is the same job
And remember this is just one job on your step to greatness.
@shell nova New Dosh video is up, and i was a fool for thinking it couldnt get worse
But congrats dude.
Thank you!!!
Gave +1 Rep to @bitter quiver (current: #605 - 6)
Apparently it went up to the head of it sec
Shows they wanted you
Now get in there and show off
And remember the main part of any job
Is to learn
IMO
after parents evening my school finally gave me a laptop
You needed one?
its a lenovo chromebook but im gratful because i can do some stuff without paying
yeah for a couple years
i had to do my homework and stuff
at the school library
or an external one
and in general i was struggling without one
cause a lot of stuff i wanted to do i couldnt do
Your own, or a borrowed one from school?
Nice! Use it well!
yes i will download a lot of ram first
yep, also necessary
That escalated fast.
ill send it to to you idk how to do it
dms dw
yk when im old enough to access it i want a whole home lab and so many videogames and stuff its gonna be so fun
Home server 😄
yeah
maybe i could fit it in a honda jazz/fit and go on an adventure wouldnt that be cool
@boreal scarab this is what I meant by my monitor boot sequence
lol even better, starlink for remote places without coverage
probably like the vpro but better :p
Smaller 😮
actually knowing apple, maybe worse
yeah im scared too
its ok cause theres other options anyways
rn, vision pro is easy the best on the market
nothing really compares that well exept the like other high end industy optipns
but too big and too heavy
makes your neck stronger dw
Max Verstappen 2.0
haha
it would be good to intergrate with a helmet for racing sims
like actual gforce
You watching f1 qualifying rn?
wait is that rn
Yup
im not too into f1 but i think motorsports is something i will get into once i have time
im allways studying 😓
Me too
Have to make a book assignment this evening
About Projekt 1065 from Alan Gratz
Sports is one of my non-IT hobbies.
good idea but I would choose star trek and a x-files crossover, sadly this just me testing
idk how to do image search on discord
Must have been age ago
🍿
haha
I looked at all the images I sent never sent this before 😂
Not yet. He has an investor interested who wants to invest 100k so I’m wanting then suing cause then I’ll get the full amount before tax. If I sue right now all rhay will happen is he’ll lose his business and I won’t get my money back
everyone who i study with uses discord, but after trying again and again i still cant install it
i found a way
If you have restrictions on the laptop...
i installed it anyways
the school can see but if they dont care enough to properly restrict they care enough to stop me
you can also use discord dorking (has: image, from: <user>)
idk why they made a maps profile of me... they must be tracking me !!1!!1
nerd nerd nerd /j
It's their property, they will want to track where it is.
i clealry indicated i was joking and they legally cant through maps anyways but maybe through other non google services
They can if you have there property on you
How did I know you were joking?
You can track devices via Google...
1!1!!1!
I just assumed you couldn't hold shift properly 🤷♂️
you two dont understand
lol
Understand what
Obviously but if you have a Chromebook that is run by the school they can still track google maps. Google maps has nothing to do with private data
still track google maps ?
Yes
what
english isnt my first language but even i know this is somehow wrong
Uh huh
Well all I know is it’s not against the law to track your own property aka the schools stuff
Plus most schools make the students sign a contract that gives them permission to do alat
Mfer loading line by line

YAWN
where are your manners
somewhere
shadow is lucky to not be homeless if that is what you are afer
you are not worthy
Check yourself before you fail to rep yourself.
-rep bad trader.
What should I have for lunch?
Mediterranean
Rice bowl with hot gyro meat, some hummus, babba, pickles
Rye bread with liver paste
Now I'm hungry
Jokes on you, I love liver.
if you lover, why don't you liver wither
Same, it's a Danish lunch food
that's new?
yeah
old
they're the same picture
Just bought 9 oz of liver spread for $9.... I hate this economy
1 usd a made up unit
Sorry Swedish KronA... I can't hear you over Norwegian KroneE!
a made up unit was refering to oz but okay

yo
hmm
I don't know how a investor will invest in his business
kg are made up too. entirely arbitrary amount
nah a kilogram is 1 litre of water
very logical
its also kinda arbitrary though
The new definition relates the kilogram to the mass equivalent of the energy of a photon at a specific frequency.
Forsake tradition, measure things with random objects. "It's 3 bananas long by 2 iphones wide"
at least that is defined with scientific things which are none changing unless the universal laws gets changed
Which is technically possible with the right unimaginable cataclysmic universal event
It's so GOOOOOOOOOOOOOOOOD
Ayo Bullet Storm, Mad Max are solid as well
Bullet Storm is great 1990s style chaos fun
That's a solid set. I've never been able to enjoy the DMC style combat that Bayonetta hailed from. I know it's good, just not my genre.
yup just got my payment for a website
so now time for shopping
Very nice. Time for rewarding the hard work
yea, currently helping the client set the website up on his own server
but hes not techy
so my head hurts being tech support
Yeah. Change how you phrase everything and giving each task/item a "relatable" term.
yup
Energy consuming
its a daily task for me, tech guy in the family
I'm the tech guy of mine, but I just pretend I don't know anything
good idea
actually super smart one
hmm
Usually it's easy stuff though
btw the cool way Helldivers do their battle pass things is
They never expire
They just plan to gradually add content, but you can always slowly just get whatever
None of that anxiety inducing Play only me for 3 weeks or miss out low grade stuff
And as a married adult working full time and studying a few hours a day
I appreciate it
Blue team room.
Ooooo what a unique room
does it come with a heavy metal badge?
wanna see some crazy tech some people made???
yeah it is meeping smellivision
Huh
Reminds me of the gun that could smell enemies we invented for Vietnam

Weird tech
so who here is gonna go out and spend 150 usd to buy a gamescent????
google did this years ago (Google nose)
yes but that was not based on the sound from the games meaning it needed special development to work
true ||and it was also a prank||
Sup sup
Nice, I ditched the work party to go work out
Healthy living > socially drinking
aaand how much of energy driink you take today ?
None!
I've drank 2 redbulls, but I didn't take them
But we never skip leg day here
ofc not... every day you can run from problems
It is leg day here, we definitely skip leg day
so you skip arm day
or do you skip neck day
????
I just completed room/rustscan, and "Task 3 Accessible" stood out to me:
"Click 'completed' if you agree A11Y in infosec is important."
I very much dislike these mandatory political positions, and having to agree with the author to "complete the assignment", so to speak, to get the grade.
What's next? Diversity, equity, inclusion? Can't we just keep the politics sort of on the side, sort of opt-in?
Smh
I do skip arm day
It is not necessarily political though?
It is inclusivity.
@Jared It is.
No it is not, do you know what A11Y is?
I like being included in things
A11Y means accessibility.
Of course.
So no it is not political.
making it so blind and deaf people can enjoy internet content
@Jared I disagree with your position.
And you are taking a really bad stance right now.
You are welcome to disagree but at the end of the day it is a fact.
It's politics, because we disagree.
That is not politics.
You can't redefine politics as morality, as a means to fixate some social change.
This conversation needs to end. If you do not want learning to be accessible to people who suffer disabilities, please submit it to the #feedback-and-ideas form.
One thing I hate about leg workouts is glute kickbacks
My position is a lot more nuanced than "not wanting education to be accessible" to people who suffer disabilities. But I will refrain from pursuing the subject in this forum. You are the mod, and I have no authority here.
I hate that leg day lacks chest
what is this leg day?
Like especially when you can't change the height of the box you lay on, cause it hits my stomach in the wrong height so it feels like I am getting punched
im boutta hit a clip
leg day is my favourite
btw i use cheetos deoderant
At this point, I think you're just being a poor troll
General is going to go on one, I'm leaving 
why did you ask this
human trebuche
i think he has potential
Implemented!
Question to the people not using the AttackBox. What is your setup? Bare metal install on an omd laptop or is VM the way to go?
Kali VM is what I'd recommend
kali vms all the way down
are you a sigma
I am not a greek letter, no
del 2010 laptop
ye

only in ohio! my fellow sigma
@royal dock Hey, let's not.
Okay great, been struggling for a week trying to get either Kali or ParrotOS to dualboot on my 2017 macbook pro. Seems like i will have to give kali VM a go then hahah
what the hell did i do
stop flirting
sorry kevin
kali is good
youre turning general on keep it for dms
yes my sigma king
Dual booting is fun, but I'd just do a VM for now.
dualboot is nice but it can lead to full lost of data
Also the only time I tried to dual boot with a Mac it was just issues.
Could be I was allergic to Apple
Me either lol
It works more or less, but things like palm rejection while typing and weird scaling are really frustrating me
I know college frat stuff, but I don't know anything outside of Phi Theta Kappa honor society
Because I got into it like 17 years ago for a year
Before I became dumber
But don’t know if those things are actually better in VM or more of the same issue
eh going to start in 6 hours ~
Me busy atm
Been planning to play it
Welp here goes 2 hours of my life on WIkipedia again
got time reserved
in japanese a kappa is a type of yokia
nobody's gonna distract me
ah I see
I still cant believe I got the job
Too many formulas
congrats 😄
Brain pain
thank you!
Gave +1 Rep to @graceful thistle (current: #22 - 351)
Very nice! That was my setup as well until I finally just this week secured 5 day wfh
Who's going to tell you it's being removed 
Get a refund on your thankfulness
glares over at windows
treason
kali is not stable OS so to say. it can do crap things if dual boot
Some folks are also surprised to realize that Kali linux is not secure really
Wat?
This is wrong
eh
This has been disproven SOOO many times
like, not secure as in ?
Kali is secure from the get go.
Providing you don't use kali:kali or root:toor
ubuntu server is worsely secured by default then kali
admin:admin
(comparing it to, say, debian proper)
Maybe I've been lied to and believed dem lies
I'll dive more into it
Let me get an article for you, hol' up
*mostly because ssh is enabled and there is not a lot of security features implemented at the start
Hit me with the word page
That doesn't mean Kali is vulnerable
That's like me opening all my ports and going "omggg this OS is so vulnerable"
I've only heard people call it unstable before.
and then ytou have this guy...
https://www.youtube.com/watch?v=TcMf5SJOV-Y&t
You NEED to know these TOP 10 CYBER SECURITY INTERVIEW QUESTIONS
https://elevatecybersecurity.net/interview
Important personal security tips if you use CTF sites such as TryHackMe, HacktheBox, or even the PWK, etc.
WEBSITE
https://elevatecybersecurity.net
GITHUB
https://github.com/self-m4de/
JOIN THE ELEVATE CYBER DISCORD CHANNEL
https://dis...
Don't talk about me like that
Oh yeah, Ramadhan starts in a little over a week

Because it is.
this is it. people hear "kali is insecure" and think we mean "you're gonna get hacked right away and lose everything!"
that's not what we mean for the most part
@bitter quiver https://blog.spookysec.net/kali-ootb/
the OS isn't designed to be daily driven so security isn't as critical
it's designed to be disposable
Spooky is ignoring me. 
I'll read through it. I appreciate it
kali is secure as it can be... stable to be used as main os... not so much
They're literally the only reason I'm in the off sec server
when we say kali is insecure we mean in comparison to the alternative, not that kali is dangerous
not really. quarterly "stable" releases under deb sid
stable with quotes
deb sid being unstable/rolling itself
Anything is secure if you harden it
if
i never had issue of using it as bare metal on spare laptop. but regular backup is must due to full disk encryption
And 90% of things are insecure if you do not
Makes sense, but the final line of it was ominous loll "and don’t store any sensitive data (long term) on your Kali machine and you will be perfectly fine."
My view point was from a daily driver perspective
sure. but we're comparing out of the box here
It's a pentesting OS, you're not meant to daily drive it
I know this
That "if" is entirely pivotal, nothing in the history of things has been properly secure out of the box
don't store any sensitive data on pc at all. get external disk and do backups
Still doesn't make it an insecure Operating System, just means you're making it insecure
I keep a flock of cycling carrier pigeons that each hold part of a system of M.2 SSDs that I have in a striped raid partition.
There is such notoriety in how insecure defaults are, its a surprise anyone can expect a system to be secure "out of the box"
You can do the same on any OS, this is why you should learn proper practices from the ground up.
it comes with a ton of software that's not as frequently patched --- out of the box, it's arguably much less secure than debian out of the box
Ahoy
That's why you keep it on a VM.
My entire concept was if John Doe booted it up, it's less secure than almost anything else he can use.
Everyone here knows a bit more
Literally everything you're saying just tells me that you don't follow proper security practices. It's the same as people who run as root and say "I know what I'm doing, I just don't care"
yes. we're talking about the average user.
I've only ever ran kali on a VM, same with Parrot. Except for testing Kali on a pi.
as an os, kali doesn't have as many protections while also having more holes.
Netcat is installed on most UNIX systems, that is what you use to open the insecure connection.
we know about that, but the average user may not
stuff
I see
Go on, elaborate, what holes
your pfp is a helmet so you race
@glass nest LP laser got big update... from 2k mm/s to 4k mm/s.... it's freaking nice
tons of rarely or slowly patched software would be an example
Like?
man idk i don't keep a mental roster of every program that comes with kali, lol
but it's loaded with tools with single maintainers who have lives and can't patch things on the drop of a hat
which is fine, because it's meant for people who have an understanding of security -- but if one of those tools has a hole, the average person isn't as equipped
ITS FRIDAY
purely comparing attack surface
If this is such a problem, you would immediately have a list.
You're arguing with literally no backing
you disagree that a larger attack surface poses more risk?
No, I disagree with the fact that you're arguing without any backing.
not really. i'm literally just saying bigger attack surface = more risk.
No you refused to provide any list because you don't know
i've even agreed that it's not neccessarily unsafe, just that it's not as safe as deb proper
You're arguing for the sake of arguing.
because said software is a nonconcern [to my use]
not sure how one could disagree with a larger attack surface = more risk, even if the risk doesn't mean immediate death
dude you're making no sense my guy
I understand him
Jabbaaaa, I hit a new leg press PR
5 metric tons????
I mean if you make a statement like that I wold think you would have proof to back it up,
Oh
just saying
No no, I have to take care of my bad knee, so only 160kg with 10 reps
you need proof that having two servers is more risk than having one server? or that driving 100 miles is more risk than driving 50?
1.6tns???
it's exposure
actually having one server is more of a risk
Bigger the city, the harder for police to police it
frr
I guess, times 2 sets
If you are a smart IT you have redundancy. Never single threaded
oh oh ozempic
I’m what way?
So don't join the discussion if you literally have no idea.
You said that software caused security holes and then said that you aren't concerned by it? Like fr? Are you srious?
Love that jingle
stability is a different convo. we're talking about attack surface
if that server Fails you are l Fooked
yo @crude stump u think if i ask thm support nicely they will give me the username i want
Well even attack surface you want to have a fail back
Definitely
I got my username changed by em
really?
idk how y'all don't get the concept of attack surface
Yes
damn k i ask
how tho?
i am happy to know that i know that
I get the concept of attack surface I don't know how yo udon't udnerstand fall back
When your on the website you see the little thm cloud thingy at the bottom left
Click that
No, we do not change usernames of existing accounts.
If you username is not already taken, then yes we will.
Sure you might have more of a risk, becasue multiple attack vectors and such. but you ar ein idiot if you have just one server
more things on a system that the average user will never use = more unnecessary risk
Huh?
