#general

1 messages · Page 57 of 1

rapid merlin
#

is there is anyway to know if there is back door on my computer or not ? i downloaded unsafe programmes and i deleted them and i did scan with my anti virus but i want to make sure there is no back doors any ideas ?

loud marlin
#

without knowing, i guess windows OS, it will be hard to spot

rapid merlin
loud marlin
#

there is. just might not be simple and easy. if you do not know what you look for its hard

#

and if you did use pirated software, then most like you have or had some virus or so

crude stump
#

they always talk about Malwarebytes. i personally never had to use it but its worth a shot in you're case

rapid merlin
crude stump
#

plus, backdoors are pretty hard to find, because whoever is the attacker made sure to obfuscate it as best as possible so it goes undetected

rapid merlin
#

i think i cant use tow anti viruses at the same time right ?

crude stump
#

i dont think scan at the same time but you can use 2

rapid merlin
#

should i download new windows ?

crude stump
#

if nothing suspicious has happened, i woudnt

loud marlin
#

if you wish, then windows reinstall might be best thing to do

crude stump
#

true, do what ever you think is best

rapid merlin
#

ok

#

Thanks

crude stump
#

you're welcome

sonic blade
#

no one said review logs?

loud marlin
#

logs as in ?

crude stump
#

i mean. you dont normally think somone already knows how to do that

sonic blade
#

identify indicators that your machine is compromised through log review. logins when no one was at your machine, strange network activity such as large amounts of traffic leaving your network

crude stump
#

but wouldnt a program be better at reviewing logs

clear jackal
#

Windows events are kind of a pain for a beginner to wade through, same with network logs

chilly veldt
#

still need to finish writing my tool for that...

clear jackal
#

The best option is likely just to run something like Malwarebytes and if you still don't feel safe, reinstall

clear jackal
#

It's why you keep offline backups

sonic blade
#

So its more likely that someone has regular offline backups but isn't capable of reviewing basic logs?

crude stump
#

not your average joe of course

sonic blade
#

Okay I'm not gunna argue the point. But short of reinstalling your entire OS, just look at your logs. Get elkstack or some forwarding service with aggregation

#

Consider it a learning opportunity.

crude stump
#

what if they dont know what to look at

sonic blade
#

Googl

crude stump
#

hm

#

thats why you need a super hero to blast your viruses away

sonic blade
#

Malwarebytes isn't going to find anything before Windows Defender does. A successful backdoor isn't going to be caught by either.

chilly veldt
#

that's actually not true 😄

#

I have had stuff that easily bypassed defender, but was caught by malwarebytes

mossy river
#

Malware bytes for active scanning, Windows Defender for just base security

crude stump
sonic blade
#

Not gunna doubt you there. I take issue with "reinstall your os" as the advice.

#

That's just bad practice.

chilly veldt
#

yeah, it's often a missused advise

crude stump
#

aye never said you should do it

chilly veldt
#

I do agree on that

#

not really

#

it's the "easiest"

tired peak
#

no guarantee malwarebytes will find everything

#

I blast things away if in doubt

crude stump
#

i nuke my pc

#

best way

blazing granite
# rapid merlin should i download new windows ?

If you haven't had detected any abnormal behaviour an used defender and Malwarebytes we can say that you're relativity in the clear, but the only way to be 100% sure is to reinstall the OS

sonic blade
#

Many backdoors persist beyond the OS, so no, it isn't 100% at all.

loud marlin
#

paint PC in blue and throw it into sea

crude stump
#

cranking 90s and swimming with the fishys

tired peak
#

ultimate water cooling

chilly veldt
#

ultimate water spicing

blazing granite
chilly veldt
#

all that electricity sure do well

blazing granite
clear jackal
# sonic blade That's just bad practice.

For a normie that takes risky clicks it isn't. Thats who the advice was directed to. It's super easy for someone to grasp offline backups, thumbdrives/external hdd/etc, and just reinstall their OS versus read network traffic, device logs, or setup an enterprise log aggregation/viewing solution

crude stump
#

did you google is cooking somthing up

#

new it

sonic blade
#

firmware, bios, take your pick

blazing granite
sonic blade
#

Im trying to explain things from "I actually want to work in the industry one day", and why "just nuke your PC" is bad practice.

tired peak
#

I mean you do a lot of thing on your computers like log into bank accounts...

#

just nuke your PC is industry practice

#

(well not just nuke your PC, its one of the steps)

crude stump
#

personlly i take the smash my pc aproach

#

works everytime

chilly veldt
#

I should sleep, it's 3:30 AM

blazing granite
loud marlin
tired peak
#

You can only detect what there are signatures for, I'm gonna say I'm not personally risking it. I don't think re-imaging your PC is beyond reason

#

if someone is interested in IT and they don't know how to re-image, then maybe they should learn

#

also, check web browser extensions

#

I'm not worried about forensically analyzing your computer personally

sonic blade
#

what does a proper security check consist of?

tired peak
#

wait what? you think someone who can't reimage their computer is supposed to check their system to validate the security?

crude stump
#

though i do agree with eight somewhat. yes you should analyze your pc and try to find anything and even fix it if you do, but that takes alot of skill and knowledge. idk if someone with zero experience would know to do that. What if they delete something very important

sonic blade
#

save the files that matter.... which may be the files that are infected.

#

nice.

crude stump
#

See what you done C901 😂

#

jk

tired peak
#

I'm personally saying, I don't trust tools or even myself, someone who has done DFIR work to ensure my system is free and clear. I'm gonna reimage

chilly veldt
#

there is kek

rapid merlin
chilly veldt
tired peak
#

what do companies do when they think a system is compromised? they reimage

sonic blade
#

Here is a great example

crude stump
#

spooky thumbnail

loud marlin
sonic blade
#

right? Almost as good as a shadowy hooded hacker figure

blazing granite
tired peak
#

new laptops can come infected

crude stump
tired peak
#

🤣

sonic blade
#

or just, I dont know... review your logs and look for indicators of compromise. and then conduct standard incident response if something doesn't look right.

tired peak
#

I mean there is reasonable paranoia

crude stump
#

listen. ik the solution. don't download sketchy programs

blazing granite
crude stump
#

stay in a bubble

crude stump
#

rex knows the right thing to do

loud marlin
crude stump
#

what if they melt it down

sonic blade
#

thats definitely never been a thing.

blazing granite
crude stump
#

usually wires have like printed on letters right

#

on the casing

sonic blade
#

lol not because of a classified space mandate, maybe someone just didnt like you?

#

You wouldn't even have to do that in a scif

blazing granite
#

I remember that, the malware come from China I believed, because they have factories in China

crude stump
#

im using a lenovo right now. am i cooked

whole yew
crude stump
#

wires can hold data?

#

never knew

sonic blade
#

yeah man lots of 1s and 0s resident on unplugged copper.

crude stump
#

thank you for your service

loud marlin
whole yew
#

IIRC the first magnetic storage was a steel wire storing bits and strung between bicycle wheels for read/write

crude stump
#

thats crazy

whole yew
#

ENIAC era although idon't remember which project

crude stump
#

what if you demagnetize it

whole yew
#

what happens if you demagnetize a platter drive

crude stump
#

uh

#

wiped

#

like they say

#

dont put magnets near ocmputers

#

we putting this theory to the test. somone get me a big neodymium magnet

royal dock
#

yes my sigmas

crude stump
sonic blade
#

I would wager the tempest was understood pretty well even that far back, I'm pretty sure someone was messing with the private

crude stump
#

what co pilit thinks a hacker is

#

there hacking with actual viruses lmao

sonic blade
#

thats the covid-24 virus

crude stump
#

it is lol

sonic blade
#

solid pick hackerman

crude stump
#

its you eight

sonic blade
#

its not uncommon to shred a harddrive, cutting rj45 is pretty much unheard of. thats all im saying.

#

anyways, more interesting topics... have yall seen CAPECs?

#

cool stuff in here

sonic blade
crude stump
#

yes

sonic blade
#

I am disappointed by the lack of gloves tbg

crude stump
#

ikr

loud marlin
#

and have 5 fingers on them also

chilly veldt
#

I really should sleep, this night shift stuff be messing with me sometimes

crude stump
sonic blade
#

thats actually the bigger atrocity. what octopus has need of five fingered gloves? Honestly they should be boxing gloves to be accurate to my head cannon

flat hamlet
#

I just spent 3 hours stuck in a jr pentest room because the payload in Exploitdb is outdated and is written in Python 2 :)))))))))))) and the python 3 version wasnt in exploit db :)))))))))) i want to die

chilly veldt
#

buuut I am watching a serieees

loud marlin
#

what ya watching ?

chilly veldt
#

the blacklist

loud marlin
#

loool

#

same

chilly veldt
#

season 10

sonic blade
#

blacklist is great junk food. Its a terrible show but fun to watch

chilly veldt
#

yeah, I laughed at some of the code it showed

loud marlin
#

s10e08

chilly veldt
#

smh, downloaded the episodes

#

s10e10 😄

loud marlin
#

i didnt like e09

chilly veldt
#

it was meh yeah

loud marlin
#

8 was ok, 10 is nice rly

#

the mindhunter will prob get one more season

mossy river
#

I hope thats not piracy

valid mauve
#

Finally got my hands on the Discworld audiobooks. All of them.

"In an astral plane that was never meant to fly...", god that man was a good writer.

molten sky
#

blacklist was fine

#

that's about it tho

valid mauve
molten sky
#

let me rephrase that

#

early blacklist was fine

#

late blacklist not so much

valid mauve
# molten sky blacklist was *fine*

It had some nice twists. I liked the early stuff with Tom Keen in Berlin (That Ambulance scene had so many issues, though. kekw )

The series ending was... Well, the only way to end this, really, but for fucks sake it pissed me off.

molten sky
#

idr how many seasons we watched but we didn't watch the whole thing

#

it got to be a lil much

#

don't remember the ambulance scene tho. watched it too many years ago, lol

valid mauve
#

Tom in an ambulance racing through Berlin. They got the right jackets, the right ambulance, etc, and then they go and fuck up the license plates of aaaaaallll the cars.

molten sky
#

reminds me of how suits was actually filmed in toronto

#

quite noticably in some scenes imo

buoyant tree
#

Question: Do the US government internal hacking/tracing tools have good UI's like the ones in movies

valid mauve
#

Though even through all it's faults in the later seasons, ya can't deny Spader played the role with style. kekw

pine stratus
buoyant tree
#

I need 1 hour

pine stratus
pine stratus
valid mauve
pine stratus
#

nothing abt politics

buoyant tree
valid mauve
#

Haw, Abby... Swoon

gusty bone
#

how did i get in here

#

how do i hack im slow

#

can yall teach me pls

graceful thistle
pine stratus
valid mauve
molten sky
#

🐬

graceful thistle
#

Heya, not bad, hbu?

molten sky
#

he's dead, jim

karmic furnace
#

Soon @graceful thistle I'll be doxing myself to you

#

so I can get my Pentest+ little thingy

molten sky
#

i know where unreal lives already

#

not gonna prove it tho cause that'd be doxing

karmic furnace
#

you can also dm me and dox me that way ❤️

molten sky
#

nope, that's circumvention of the rules

#

i'd never do such a thing

karmic furnace
#

then you're lying

molten sky
#

just gonna have to believe me 😶

karmic furnace
#

i'm not gonna believe a stranger.

karmic furnace
#

pretty much

graceful thistle
karmic furnace
#

That was stressful as hell.

graceful thistle
#

I bet

karmic furnace
#

Why do I have know US laws and regulations.

molten sky
#

offensive security brings a shitstorm of legal issues

karmic furnace
#

yeah but I'm not in that country 😛

molten sky
#

nevermind then

karmic furnace
#

so it's annoying as hell

molten sky
#

i guess they can't really curate to every country at once

#

might cause compliance issues too i suppose

karmic furnace
#

something but i have it now.

molten sky
#

have they added practical components

karmic furnace
#

I knew the tools, and how to use them so that's what saved me

#

not really, it's more 'here's simulated things, fix them'

molten sky
#

more than what my old sec+ had, lol

karmic furnace
#

I can't remember what was in sec+

#

in terms of my test, i remember the things from it tho

molten sky
#

yeah i don't remember anything other than the room i was in

#

was several years ago though so 🤷‍♂️

gusty bone
#

whats poppin in here?

molten sky
#

shit, i should go make some popcorn

gusty bone
#

lol

grim sparrowBOT
#

There are no URLs in that message.

molten sky
#

.checkurls

#

/checkurls

sharp citrusBOT
#
TryHackMe
Ollie
molten sky
#

oh that works now

#

where tf is checkurl

karmic furnace
#

Well that's very depressive.

#

I had no idea Ollie passed.

gusty bone
#

hehe

grim sparrowBOT
#

There are no URLs in that message.

gusty bone
#

yall will never know what im doing

sharp citrusBOT
#
TryHackMe's Website

You should know our website by now!

karmic furnace
#

yeah no idea.

molten sky
#

i wonder if it's a permissions issue

karmic furnace
#

/socials .

molten sky
#

verified no access

karmic furnace
#

oh maybe

gusty bone
#

oh mb

#

im just doing something in yalls accounts

#

im trying to figur out how to ban but not u two some other kids

#

yall two are chill

graceful thistle
#

How to ban who from what

gusty bone
#

from dis

#

i learned it but i need to find it

graceful thistle
#

?

gusty bone
#

oh wait

#

are u a...

molten sky
#

ghost?

gusty bone
#

no

#

thats a person who protects dis from hackers

#

or some wat

graceful thistle
#

What

gusty bone
#

are u?

graceful thistle
#

What are you saying

gusty bone
#

if not than good

#

oh ur using mod nvm

#

im srry dolphin but ima have to take that

graceful thistle
#

Look I dont really understand what you're saying but it sounds kinda sketch

gusty bone
#

oml u spent money for mods 😭

graceful thistle
#

If you wanna hang around here, I suggest you read the rules and what this server is about

gusty bone
#

ight mb

#

im in a general random chat

#

yo dolphin wats the rules im slow

graceful thistle
molten sky
#

i'm with smith on that one

#

the new discord layout sucks

gusty bone
#

btw im a new person in dis so yah..

#

and reading the rules is boring

#

but ight ill try

molten sky
#

the #rules channel used to be fairly obvious, but now it's all into a weird combined server info tab thing

#

don't remember when that happened tho

gusty bone
#

can anyone gift me nitro

#

im broke

graceful thistle
gusty bone
#

pls donate to charei need some nitro

clear jackal
gusty bone
#

im new =>

#

am i the only one without a nitro

fathom dagger
#

Hi all, just want to know how you wrote the reporting like VAPT if you do it manually or with some tools? Is there any format or something like standard for the report?

graceful thistle
#

Finally after 20 mins I got the combo famn

molten sky
#

i'm of the opinion that you can automate some parts, but if you automate all like some tools claim to do then you're losing valuable info

#

(and those automated parts would need some curation)

#

no one answer tho. just about workflows.

#

what are you talking about? @graceful thistle

graceful thistle
#

I was trying to learn some dmc combos and just couldnt get the timing right no matter what. I finally got them ✅

#

highlight of my day

molten sky
#

i'm beyond confused but it sounds like you've broken past a roadblock lol

graceful thistle
#

Thats right

buoyant tree
#

now time to unlock more skills

#

because it feels kinda bland and easy in the starting

graceful thistle
#

Learn 100% of the combos

#

Get to DMD

#

Play bloody palace

buoyant tree
#

yea once I unlock more moves

graceful thistle
#

If the combat is bland, youre doing it wrong 😄

buoyant tree
#

need more time in the game

#

to unlock more stuff

graceful thistle
#

Yeah it will take forever

#

I dont wanna spoil anything

gray sonnet
#

Morning everyone

buoyant tree
#

yea I understand

midnight hazel
storm garden
#

ok

sage wolf
buoyant tree
#

I hate u

midnight hazel
languid radish
#

good morning 🙂

rapid merlin
amber quarry
#

Hello, can someone tell me where rockyou.txt is located on the default attackbox please ? I'm writing a quick procedure and don't have access to it right now
Thanks ! 🙂

wintry sluice
#

/usr/share/wordlists/rockyou.txt

amber quarry
#

pretty sure it's somewhere in /root/Tools/wordlist or something

#

and not the default path that we find on Kali

#

i'll try to find it, I have bad internet rn cause I'm on a train but we stopped at a station

wintry sluice
amber quarry
#

oh it's in both yeah

#

Thanks I'll remember that now 🙂

wintry sluice
#

there's a symlink in root/Desktop/Tools to the wordlists folder

amber quarry
#

yeah it was a symlink all along
<insert Always has been meme>

#

@wintry sluice thank you

twin ridgeBOT
#

Gave +1 Rep to @wintry sluice (current: #507 - 8)

willow furnace
#

How do i hackwifi with out kali

chilly veldt
#

You don't

broken nymph
willow furnace
#

cissp

broken nymph
#

Haha

willow furnace
#

ofc hack mine

broken nymph
#

We got a pentester

willow furnace
chilly veldt
#

@graceful thistle

broken nymph
#

Pentesting - A penetration test, colloquially known as a pentest or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment.

#

🙂

#

You don't need to get rid of your fellow Windows to use Kali

#

Use a Virtual Machine

#

and then run Kali

#

or Usb

willow furnace
#

is this guy real Ryan Montgomery @ 0day

wintry sluice
broken nymph
#

Nice bro

chilly veldt
#

Yes, that's the real Ryan

sick lance
willow furnace
#

oh cool

#

I want to learn Cyber security

broken nymph
#

Read ! 🙂

wintry sluice
willow furnace
#

but i have a potato laptop

#

😅

wintry sluice
#

that's fine. THM has an in browser attackbox

broken nymph
#

A hacker hacked sony with a roku device and a keyboard

#

lol

willow furnace
broken nymph
#

If there is a will there is a way.

wintry sluice
#

TryHackMe

broken nymph
#

Being a smart alec won't get you far my friend 🙂 . I like your enthusiasm that will get you far

#

Having a potato laptop won't matter all that much, there are a few linux distros that breath life back into older systems.

willow furnace
molten sky
#

just watched this guy on yt

#

his outro is a remix of him doing the spicy rm

broken nymph
sonic blade
broken nymph
#

Start there, and then download a tool called nmap

willow furnace
#

@broken nymph i made a rubber ducky using my USB

broken nymph
#

Start by learning how to use nmap

willow furnace
broken nymph
#

with your own IP as the target

#

of course

willow furnace
sonic blade
broken nymph
#

You won't be able to use a wifi hacking tool without it.

sonic blade
#

I prefer to have at least 9 antenna things before I hack a wifi

broken nymph
#

this guy ^^

willow furnace
sonic blade
#

its the only way to reach the mainframe and extract the RAM

broken nymph
#

(I am agreeing with you)

sonic blade
#

and they said you couldn't teach a bot anything

willow furnace
#

who

sonic blade
#

who indeed!

#

osint spider web crawler

#

rate limited

#

They were joking...

#

actually they may not have been; using nmap on your own network isn't bad advice

#

sorry i just clicked on the original post

#

Learning to use nmap is great and your own network is a safe environment to do so

wintry sluice
uncut cove
#

Hey!!

Has anyone passed Insekube lab? I'm in desperate need of advice

Nobody answered in room help, so I reckon there aren't many people who did this room bashzoom

uncut cove
#

also this

sonic blade
willow furnace
sonic blade
#

my router has a ton of antenna because it supports Wifi. not scary.

wintry sluice
sonic blade
willow furnace
sonic blade
#

nmap is literally a tool to map a network, thats all it does. it identifies things that are already there.

#

if there are issues with your network configuration, they exist regardless of anything nmap could do.

willow furnace
atomic aurora
#

Sigh

sonic blade
#

what

#

no

wintry sluice
#

no, you need to ask your friend before nmap will let you scan it

willow furnace
#

wait i am confused

sonic blade
#

I want to be charitable with this line of questioning but cmon.

#

This person wants to invade their buddies wifi dont they

willow furnace
#

i have 2 separate WIFI's 🫤

#

nmap works only on our wifi or others?

sonic blade
#

it works on all the wifi

atomic aurora
#

You should only use it on a wifi network if you have permission to do so/if its yours

willow furnace
#

👍🏻

broken nymph
mental hound
#

Ohh. Is that a new room desig? I like it! 🙂

willow furnace
#

flipper zero

wintry sluice
sonic blade
#

your welcome

broken nymph
willow furnace
sharp citrusBOT
broken nymph
#

People were doing relay attacks and stealing cars with the flipper zero so they banned it here.

wintry sluice
#

gotta verify to post screenshots

willow furnace
wintry sluice
broken nymph
broken nymph
sonic blade
#

no one here is going to teach you how to use that tool.

willow furnace
sonic blade
#

It would be irresponsible.

sonic blade
#

Then go look at youtube.

willow furnace
sonic blade
#

off you pop.

atomic aurora
#

I have a feeling that a lot of people come here with the wrong intentions

sonic blade
#

welcome to the joke

broken nymph
#

What do you mean ?

willow furnace
#

nah

broken nymph
#

Yup, that is what sells the flipper zero. World we live in lol

sonic blade
#

My college thesis was based on doing bad things, there just isn't any restraint today.

willow furnace
#

159 usd

broken nymph
#

Have you guy's seen the Rabbit OS device ?

wintry sluice
#

it also has a lot of completely legal potential.
a single tool that can do lots of stuff is useful to a decent pentester

willow furnace
#

i wonder how they created it

wintry sluice
#

by that logic, kali should be banned too

#

and all the software packages on it

broken nymph
#

That is why Canada banned it (I live there) lol

#

(if were talking about the flipper zero)

#

I think it's dumb tho, and rswallen is right. Extremely useful to a pentester

sonic blade
#

it isnt anything more dangerous than a wifi pineapple or greatfet one

broken nymph
devout palm
#

You can do it yourself with a raspberry pi or an ardunio

sonic blade
#

most people that would want to do something bad wont have the skill to utilize it effectively.

devout palm
brisk briar
#

i've read some articles and they say that flipper zero can be harmful for cars and car manufacturers which are using older security versions

willow furnace
#

rlly

devout palm
#

It's not magic...

broken nymph
#

I respect ya trust me

naive violet
devout palm
naive violet
#

A single country, no?

willow furnace
brisk briar
#

bro there are coming masterkeys so why they aren't banned

sonic blade
sonic blade
#

Good job! Mission Complete!

naive violet
#

It's not the flipper that's the problem. It's crappy automative software

willow furnace
sonic blade
naive violet
#

That's such a poorly thought out argument.
That's sweeping the actual problem under the rug

naive violet
wintry sluice
#

flipper zero: exposes problem with software in cars
solution: ban the thing exposing the problem
result: problem still exists, can't use useful tool that exposed this problem to see if such a problem exists elsewhere

devout palm
#

Banning it won't solve the problem

willow furnace
#

bruh why did i start

naive violet
#

You could use the same arguments to ban pretty much the entire industry we're in

#

So... I would recommend not supporting that approach

sonic blade
naive violet
#

Defcon has a car hacking village for a reason

sonic blade
#

So your argument is... entice more people with less sophistication to... steal more cars?

#

That doesnt really jive with disclosure provisions for any bug bounty program I have ever been a part of.

naive violet
#

It's all widely documented

wintry sluice
#

isn't it more: entice people who don't want to steal to poke around, and then report when they find problems, meaning manufacturers fix the problems, resulting in fewer cars being stolen

sonic blade
#

There is still a pprocess.

naive violet
#

It's also VERY easy

naive violet
#

Car theifs aren't going for the sophisticated attacks anyway. They just jam central locking and wait for people to walk away.

#

Banning the flipper zero is performative. It does no work to fix the problem but it's big on tiktok and scares boomers so it's quick political point scoring.

sonic blade
#

Im not advocating for the banning of any tool. I am advocating for not giving information to random people on discord.

naive violet
#

I mean, we're not?

floral wing
#

Any website builder suggestions ?

sonic blade
#

I think we definitely have.

naive violet
#

I don't think you understand the topic

#

That description makes the news

#

I'm not explaining how to do it

#

And it's a widely known attack

sonic blade
#

Ive written novel attacks on CANs, I certainly understand the topic.

naive violet
#

This isn't the CAN bus. This is RF.

sonic blade
#

Im saying we shouldnt be discussing it here.

naive violet
#

Is that your call?

sonic blade
#

Am I wrong?

naive violet
#

The extent that we're discussing it is fine

#

@brisk briar Please don't sent unsolicited friend requests

brisk briar
#

Okay

#

Bruh

atomic aurora
sonic blade
#

damn that was dirty

#

you dont play games?

atomic aurora
#

me?

sonic blade
#

Yeah

atomic aurora
#

Sure I do

sonic blade
#

whats wrong with grabbin that dub in fortnite?

atomic aurora
#

nothing

#

I saw he was playing fortnite

#

so i said go get that W

brisk briar
#

yesi'm

#

so

atomic aurora
#

genuine comment

sonic blade
#

for sure

atomic aurora
#

It’s okay man

brisk briar
#

bro are u joining

atomic aurora
sonic blade
#

yeah bruh, go play with your fellow man

atomic aurora
#

new season/map sucks

sonic blade
#

oh so your better than it now

uncut cove
#

fortnite is good, but ctfs are better

atomic aurora
#

dude can you hop off?

sonic blade
#

naw im just teasing do listen to me

#

dont*

amber quarry
#

Huh

rapid merlin
#

Noob Question: I want to port forward and I have an SSH shell, I want to use Konami SSH Port forwarding technic. But when I hit [ Enter + ~c ] I got the Command Line to disable the message, Does anyone know what is wrong I am doing?

grizzled crystal
#

are you doing this when SSHed in?

sonic blade
#

Konami SSH port forwarding isnt a thing. Sounds cool though

#

~C will give you additional ssh options i guess

grizzled crystal
#

I'm guessing konami is an article

sonic blade
#

kali@kali, fun.

rapid merlin
grizzled crystal
grizzled crystal
rapid merlin
#

did the same

rapid merlin
sonic blade
#

on no

grizzled crystal
#

Check your terminal settings. There may be a shortcut or something you're triggering

grizzled crystal
#

I love SANS articles hehe

raw smelt
#

How do you earn points in workspace?

zinc folio
wintry sluice
raw smelt
#

@wintry sluice

sick lance
sharp citrusBOT
chilly veldt
#

PJPT > eJPT

#

speaking from someone who has eJPT

#

it's not worth it at all

#

I cannot say

#

😄

#

but wayyy too basic

rapid merlin
#

what about PNPT and eCPPT

chilly veldt
#

I would skip everything from eLearnSecurity

#

tbh

devout palm
#

Don't touch CEH too

chilly veldt
#

eLearnSecurity has changed how they do certifications, and a lot of their certs have tanked because of it

#

the quality is bad, the pay is too big

devout palm
#

Yeah, you can make your company pay for them

chilly veldt
#

Offsec is quite good

devout palm
#

IMHO if you can afford, go for Sec+. It's not mandatory but helpful

amber quarry
devout palm
#

And make sure you have checked certifications that local jobs require/want.

chilly veldt
wintry sluice
#

is it worth doing sec+ if you have no other techy certifications?

amber quarry
#

def not

devout palm
#

You can also ignore certs and actually do something

amber quarry
#

when you wonder if a cert is worth it, always check the job postings in your desired work location

devout palm
#

Make projects, demonstrate your interest in cyber security

#

Then get an internship

#

You can do both

amber quarry
#

just write the name of cert on indeed and look what the jobs are and what is the amount of postings

#

indeed or any good job website for your country

devout palm
#

Home lab, writing your own tools, writing blogs etc.

#

And social networking is an important factor to get a job

#

Nah, companies don't care about certs tbh

amber quarry
#

I landed my first pentest job with no certs

rapid merlin
#

by doing projects?

amber quarry
#

Actually I had eJPT but it didn't play a role really

devout palm
#

Experience > Certs

amber quarry
#

the job isn't hacking stuff for fun and that's it

#

you need to be good at soft skills above all

#

writing, and communicating

devout palm
#

So true

twin ridgeBOT
#

Gave +1 Rep to @amber quarry (current: #56 - 117)

amber quarry
#

it's crucial to be good at those. doing ctfs is great but soft skills are too often overlooked

#

make a blog, and do some reports on the boxes you made
not a simple writeup with your nmap command and output. no one cares about that
explain the vulnerabilities, and present remediations

do 2 good blog posts rather than 10 bad ones

rapid merlin
#

but some podcasts say their AI removes our CV if we don't have specific education or specific cert

devout palm
#

Not all jobs

glass nest
#

First of all, Thats not AI. It's just a filter 😄

amber quarry
#

ATS I think ?

rapid merlin
#

yeah sorry, ats

wintry sluice
amber quarry
#

big corps need to make a first filter and they do that by looking for keywords in your CV yes

glass nest
#

since stuff like Work from home, you end up getting thousands of applications for like 2 job roles. the company NEEDS some method of filtering out people who know what they are doing and those who dont. Certs are an indication of that.

devout palm
#

I know a little trick

amber quarry
#

the writing it in white thing is dumb

devout palm
amber quarry
#

because at the end someone is going to look at it and if you don't have said cert they're going to discard it

#

if that cert is really required

devout palm
#

It's not the cert

rapid merlin
#

Which room would you recommend to learn routing?

devout palm
#

If they are looking for technical keywords

amber quarry
#

just put them in your resume then ? if you have that skill

rapid merlin
#

Its a skill I’m not the best at and would be awesome to learn more of

amber quarry
#

and if you don't it will be spotted in the interview

devout palm
glass nest
#

Exactly. You can trick your way into getting in the door if you like but you'll be shot down instantly.

amber quarry
glass nest
#

The whol HR filter is simply to get rid of folk who just did a 1-click apply and can't actually do the job.

glass nest
#

Mikey - the Wreath Network

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #18 - 402)

amber quarry
#

not routing

glass nest
#

It covers routing

#

IIRC

amber quarry
#

routing to me is RIPv2, OSPF, ....

glass nest
#

and port forwarding

amber quarry
#

eigrp

wintry sluice
#

routing?

amber quarry
rapid merlin
#

I’ll try both, gns3 is a network emulator if I’m not wrong

amber quarry
#

If you want to train networking yep

rapid merlin
#

The wreath network, is that a compromise one host, add routing rules to then compromise further hosts?

chilly veldt
#

glbp!

glass nest
#

Mikey - Thats called 'Pivoting'

chilly veldt
#

did someone say networking? 👀

glass nest
#

Too many acronyms.

chilly veldt
#

two many 😛

rapid merlin
#

But I’ll check it out, thanks guys

amber quarry
#

o7

chilly veldt
#

I have done wayy too much ospf

amber quarry
#

I did networking for some time but got tired of it

#

🛌

chilly veldt
#

I am currently studying CCNP 😄

#

for school

amber quarry
#

ah okay

#

we had to do the CCNA exam but didn't actually get the cert in the end

chilly veldt
#

finished CCNA last year

amber quarry
#

it was really dumb

chilly veldt
#

same here

#

CCNA and CCNP

amber quarry
#

but did you get the actual cert ?

chilly veldt
#

nope

amber quarry
#

why they do dis

glass nest
#

Correction - Bella is currently whinging about studying CCNP

chilly veldt
#

no!

#

I am reading netacad while we speak

amber quarry
#

pain

glass nest
#

I'm jus playin, Bella 😄

amber quarry
#

good luck

chilly veldt
#

thank you

#

luckily this class is just a 50/50 one

glass nest
#

You'll get through it, James.

chilly veldt
languid radish
#

and activate the appropriate option

#

hey there, I was wondering why there are no room for learning how to use Aircrack-ng tools suite and rooms about Bluetooth hacking on THM

naive violet
#

But it's difficult to make it interactive without running physical hardware

silver sky
lavish shell
#

Got bored waiting for some tools to finish so i decided to entertain myself with a falling matrix

naive violet
silver sky
#

Mine is currently in my local depot.

earnest iron
#

Good morning 🙂

silver sky
#

My local DPD driver only does a half run on a Saturday and always forgets my end

earnest iron
#

I know this is going to sound generic, possibly, is there a list of beginner rooms “IN oRdEr” on thm?

karmic furnace
#

@naive violet Can I dm you for my Pentest+ Role please?

naive violet
#

Yep

karmic furnace
#

Thank you. ❤️

shut hawk
#

Are you on a mission to get all the + certs?

karmic furnace
#

I have the ones I want now.

#

A+, Net+, Sec+ and Pentest+

#

now I'm on a mission to write myself up a nice little documentation structure/note taking process.

shut hawk
#

Ah nice, congrats!

devout palm
#

Congratz

hot cairn
#

@shut hawk new colour? 👀

shut hawk
#

Yeupp!!! 😄

hot cairn
#

Nice

hot cairn
#

Riding a CRJ9 today 👀

shut hawk
#

Ooo, where to?

hot cairn
#

Newark

shut hawk
#

The CRJs are very majestic

#

Wanted to learn them after the A320

hot cairn
#

they’re ok

#

The 100/200 are nothing but pain

#

Cause of how tiny the overhead is

shut hawk
#

ooooh yeah that must be annoying

#

are you quite tall too?

hot cairn
#

My bags I mean

#

My roller doesn’t hit overhead

#

They’re cramped but I can live with it

shut hawk
#

Oh rip

#

They are only short haul so could be worse ig

#

Haven't been on a long haul for agesss

hot cairn
#

Yeah fair

#

its only ~1h30

#

Ive seen them on routes up to 3-4 hours though

shut hawk
#

Ah not too bad then, is the weather looking good?

#

Newark airport looks huuuge

hot cairn
hot cairn
#

imo LHR is worse

shut hawk
#

I had some pretty bad turbulence on the way back from holidays

#

yeah it's a pain to get around LHR

hot cairn
#

Esp transferring

#

cause security takes soooo long

#

I hate how in EU airports you gonna go through security to transfer

#

I can fly anywhere in canada or the US, and only have security(or customs) at the first airport - which for me is montreal

#

Which is sooo nice, bc tighter connections

shut hawk
#

That must be nice

#

To be fair, the self-serve customs makes it go by a lot quicker

hot cairn
#

We aint got those here

#

And ive never used em

shut hawk
#

Really? They've been out for ages

hot cairn
#

Only airports ive been to that had them, i was still a minor travelling alone at the time

#

which is one of the cases you cant use them in

#

We're starting to roll them out in canada, but its just in Toronto AFAIK

shut hawk
#

huh that's interesting, wonder why it's taken so long

hot cairn
#

Atleast for Canada & the US now, you can make your customs declarations on your phone

#

and skip most of the questions

shut hawk
#

They've updated the security too at Luton and now the luggage checking is completely autonomous and everybody has to go through the full body scanner

hot cairn
#

i hate the full body scanners

shut hawk
#

These aren't that bad, compared to the circular one

glass nest
#

'Do you own a Flipper Zero, eh?

hot cairn
#

i always end up getting searched

#

without fail

shut hawk
shut hawk
hot cairn
#

ill dm

sick lance
glass nest
#

It's like... 'You know know what, I didn't think about it while I was packing my bags, but yes - I keep some Cell Cultures on-hand just in case I need to do some science on the plane.'

sick lance
#

They need to be declared for proper transport and handling.

hot cairn
#

like, why would i ever cross the border with that

#

The stuff about farms sure

karmic furnace
#

Can someone assist me with why the hell my wife's PC says its been on for 15 days.

#

despite it definitely being shut off.

#

stupid Intel machines.

glass nest
#

Yeah, Like Labs and stuff would secure courier stuff, and that would have it's own paperwork. You wouldnt just bring it with your carry-on

sick lance
#

User error kekw

ruby steppe
#

hey can someone help me if they're free?

karmic furnace
sick lance
ruby steppe
sick lance
ruby steppe
hot cairn
#

not a standard question

sick lance
#

If we can answer it, we will, if not, we'll tell you, with also why and maybe point you in a better direction.

sick lance
glass nest
#

Exactly. Doesnt the US one straight up ask 'Do you hate America, and are you planning to do bad stuff?'

hot cairn
#

no

sick lance
karmic furnace
#

I didn't even need to click that to see it.

hot cairn
#

all the US customs questions

glass nest
#

Ahh, I was thinking Immigration/Visa stuff

ruby steppe
hot cairn
#

nor for an ESTA

shut hawk
# hot cairn

I like how they keep switching between "Do/Am/Have"

ruby steppe
#

sure

near hawk
#

@shut hawk Who ended up winning that 1v1?

ruby steppe
# sick lance <:blobno:658062672520019983>

hey hello
so basically
im just a normal guy
but i want to learn ethical hacking
well i got this idea after my instagram account was hacked
since then im looking for reliable people
to teach me how to ethically hack things
and help others out
so am i in the right place at TryHackMe

#

?

hot cairn
#

Only if you havecommited crimes in the past

hot cairn
#

but that was just i-130 paperwork ive looked at

sick lance
#

We won't however help you get your account back.

You'll need to contact IG support that.

ruby steppe
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 2025)

proven spoke
#

Is the vpn fucked for anyone else?

sick lance
#

It' sok for me.

proven spoke
#

interesting

shut hawk
glass nest
#

that was an intense line of questioning

near hawk
#

Damn

hot cairn
#

hi firehawk

proven spoke
#

hello

hot cairn
#

How goes it

sick lance
proven spoke
#

am trying to get friend on THm but vpn is fubar

shut hawk
shut hawk
near hawk
#

You using MK or controller?

glass nest
#

First question about the VPN - Is your friend in somewhere like Egypt or Russia - somewhere that VPNs might be banned?

proven spoke
#

ye tru dat

chilly veldt
#

👀

#

firehawk, on thm, never seen that coming

sick lance
#

just notived I'm a server missing, then I remembered I left Off Sec.

shut hawk
ruby steppe
#

@sick lance hey bro i have no clue of anything related to coding and things, the only things i have done in coding are python and qbasic codes taught in my school.. so i went to the website and its saying out things that i have no clue of, so what should i do?

sick lance
ruby steppe
#

uhm i dont understand actually

#

like

#

i opened something of introduction

#

but it said someting a Terminal

shell nova
#

wait they still teach qbasic?

ruby steppe
#

i have no clue

ruby steppe
#

and its only for like 3 months to get a overview of coding

shell nova
ruby steppe
#

like

#

they teach for 3months or so

#

just for a overview of what coding is

#

and some python i did

#

were just basic calculation codes or strings

karmic furnace
#

Scrubz, I'm gonna be annoyed if that was the reason

#

it likely was too.

ruby steppe
karmic furnace
#

If Fast Startup is just a keyword for hibernate, I'm gonna hate windows.

#

it genuinely is..

proven spoke
karmic furnace
sick lance
#

I do the same and didn't even click.

#

I prefer mine to have it.

near hawk
#

Yea, happens to me, every time turn PC back on it runs slow check and its because has like 5 days uptime

karmic furnace
#

my wife's PC would just 'randomly' come out of hibernation.

shell nova
ruby steppe
shell nova
#

then try to understand what you're doing. the syntax isn't too complicated

shut hawk
naive violet
#

@ruby steppe was banned for asking for illegal hacking

proven spoke
#

bruh

proven spoke
shell nova
#

too late they're gone

proven spoke
#

bruh wat

shell nova
#

not the sharpest tool in the shed it seems

#

they tried to hire someone to "hack their instagram account back" or something

proven spoke
#

fair nough

plush mesa
#

its always either instagram or fortnite accounts

shut hawk
#

hi hydra

arctic iron
#

Hello, I was wondering when I'll get good in cyber (I started my journey 3-4 months ago). Or it's like the Invincible meme: "That's the neat part, you don't"

shut hawk
#

Well getting good is subjective, all depends on who you ask

proven spoke
mossy river
shut hawk
#

Compare yourself to yesterdays self

wheat crater
#

I am working for 12 years in IT now, sometimes I think I still know nothing 😄 (depends on the topic of course=

mossy river
#

My best advice is don't be so hard on yourself. If you start comparing yourself against others, you're going to make it 100% harder

glass nest
#

Wirago - As soon as you think you've seen it all, Some user somewhere does something so stupid, it makes you re-evaluate everything 😄

arctic iron
glass nest
#

They do get easier. Every day. You just gotta do it every day - Thats the hard part.

sick lance
#

Don't compare yourself to others, compare yourself to yourself.

12 months before, See how much you've grown.

proven spoke
arctic iron
devout palm
#

Hi, how can i practice writing pentest reports?

wheat crater
mossy river
arctic iron
#

@sick lance @glass nest @mossy river ty by the way, I'll practice everyday

twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 2027)

devout palm
sick lance
#

Free rep! kekw

glass nest
#

1/3rd of a rep.

sick lance
twin ridgeBOT
#

Gave 1 Rep to esqy_1up (current: #18 - 403)

mossy river
devout palm
mossy river
#

It has a section on report writing

devout palm
#

Ohh okay lemme check it out, ty

crude stump
#

Hm

cosmic pendant
#

Hello!

arctic iron
#

Question: Do people take notes abt commands and protocols or you just remember by practicing and search if necesary?

devout palm
#

You get used to commands

mossy river
# arctic iron Question: Do people take notes abt commands and protocols or you just remember b...

All of the above.

When you learn a new concept, you should always take notes.
If you are using a new tool, research the tool, look at all the options it might be helpful to you in the future.

When you need the command, you can reflect on your notes to find exactly what you need for it.
The more you reflect on your notes, the more it will convert to long term memory and you will need to reflect on your notes less.

Use a good organisation system.
For example, is the command for Windows? Put it into the Windows folder.
Does it apply to a particular service? Create a subfolder fo rthat service.

This way whenever you are attacking Windows and it has a specific protocol, you can go to it directly blobfingerguns

spice adder
#

Yeah I have to agree that having a methodology of your own is really beneficial. You may remember a lot of methods mentally, but some stuff is really obscure and uncommon in CTF’s. Being able to come back to that stuff that you’ve had little practice on since taking notes can really help save time.

I carry around an RTFM V2 everywhere I go which is a nice little handbook to serve as a methodology if I’m desperate. But something online like notion, google docs or obsidian is great to have for yourself

arctic iron
#

Very well, I'll keep taking notes in my obsidian and use a better organisation system lmao

shut hawk
#

Use whatever works best for you

#

for me it's being able to visualise my notes like this (I'm sure some people probably find this disgusting but hey, it my notes!)

arctic iron
#

hell yeah that looks amathing

#

(i'm being annoying sorry), last question, does studies like university is CRUCIAL to get a good job? :))))

rapid merlin
crude stump
#

7 hours studied this week

#

I think that’s average

lusty elm
#

Hi everyone, if anyone wants to discuss chrome DM me please

crude stump
spice adder
shut hawk
arctic iron
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #267 - 18)

crude stump
#

Oh ok

bitter quiver
#

THat makes my ADHD brain excited

#

I love my OneNote but that is beautiful

crude stump
crude stump
#

Plus even with people who do have a degree, it might still be hard to land a job

bitter quiver
#

I didn't have one

#

But I got to work my way up in an ITAD company and the title on my resume + experience I could speak to has carried me since

crude stump
#

W

#

Respect the grind

bitter quiver
#

That said I've realized, I'm usually teaching people who got out of college.

#

SOmeone gets hired with an MBA and I'm teaching them lol

shut hawk
bitter quiver
#

Nothing prepares you better than real experiences and having to look things up yourself, figure out problems.

#

RTFM life

bitter quiver
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 484)

mossy river
#

Actually pretty interesting

#

New attack vector though

shut hawk
#

I don't like it

#

imo would be better if they just made the sign-up application able to be done on any server

#

which I guess is kinda possible already

mossy river
#

I think it's nice that it's limited because scammers will obviously abuse the hell out of this

shut hawk
#

oh definitely

#

☹️

mossy river
#

Problem is that this update will be applicable to a TINY amount of users

shut hawk
#

Could you imagine if they limited it to nitro users only for ownership

mossy river
#

People with big followings obviously won't use this because of the user limit and most people will have 10-20 friends.
I can see the target audience being 13-16 year olds who put their clan name in their steam username

mossy river