#general
1 messages Β· Page 62 of 1
ok. And thats because the school don't deem them needed for your education. If you feel it's needed, then contact your teacher
i did
ok. then you've done all you can. There's no hacking this thing. Just work with the tools you have.
excellent π
it doesnt work for anki idk why
I've said why.
why cant i do more
Ask your school why you can't.
im not trying to be annoying i just want software
OR ask them for written permission to hack the computer
@bleak dagger We are not going to help you bypass these restrictions
It's clearly not actually your device, as it is administered by the school
ok
Please stop discussing it here as it'd be illegal/unethical to do that
k
+rep. used MrRobot, Pickle & RootMe. Whilst doing a demo of simpleCTF as a guide to web boxes. Was good :)
pickle riiiiccck! Great room
Yes.
Damn right! Piiiickle riiiiiiiiick
Also easily googleable. @bleak dagger If this is something you are struggling with, I'd urge you to contact someone -->https://blog.opencounseling.com/suicide-hotlines/
Comprehensive list of suicide and emergency hotlines around the world. Includes additional hotlines and links to in-person care.
im not pregnant
I liked the PickleRick room, I done it before I watched Rick and Morty.
I watch it now, but it's... Ok.
:mute: life.out.there#0 has been muted.
You mentioned the S-word. So, I responded to that.
Priase James π«Ά
@bleak dagger has been warned.
honestly, Mr. Robot has been one of the more fun rooms. It showcases a lot of techniques and that room actually got me into watching the tv series
Yea people loved it in the cyber clinic. Fan favourite. Great box for beginners too. Really helps get foundational practice with manual reconnaissance and easy code injection
Bad - did it encourage you to buy a black hoodie?
...it might have...
and to constantly talk like you've just woken up?
Urban camo hoodie >>>>> black hoodie
Mr robot is great fun too! Fantastic show. Iβd already seen the series but boy do I wish I could watch it for the first time again
Haha
I like to call that my female mate call
Yike.
Pikachu hoody >>>> ALL OF YOURS.
stuub - I could only watch it for a bit. the camera work was... of putting. Persons head in one corner with the rest of the screen empty.
Maybe that was the point
Man, the show is so wild. But It makes me appreciate all of the rooms that have been dedicated to Mr. Robot in try hack me
alright you win
Nuh huh. Werewolf graphic fantasy hoodie >>>>> 
ralex - 2 wildly different subjects there π
Oh Esqy I got that steel sheet
Sweet. will it do the job?
Did all your stuff eventually come?
It's just barely thin enough
Scrubz - Jameses secret is.. he's ALWAYS waiting for stuff π
Waiting on one last parcel before I can get my full satellite ground station running
see? π
Should be tomorrow or Friday
good things come to those who wait
Yeah, all artistic choices by the set. Think it does a good job of portraying the theme but I get where youβre coming from
Don't wish your life away
Is it portia Doubleday? did a cracking rendition of 'Everybody wants to rule the world'
@glass nest Hi how are you?? π
Damn rex! Still in the homeland?
Me: Everyone deserve 2nd chance...
My sister: ||That is why you have younger brother||
=/
Brutal, but very quick.
true... but i don't expect nothing less from my sister tbh
will be disappointment if she don't say sarcastic things...
@spice adder you could have gone the cheese route and loaded up kioptrix and told them to go at itπ
Hey everyone, in my company we basically have to on board a few vanilla windows computers that we cant manage through AD because of the image source however we have to onboard them as safely and as securely as possible, windows management is not my strong suit but I still want to do this task. If any one has any experience on the topic or has any insight I am glad to go into more details and get the community's opinion
how to start bug hunting for real websites (not only ctf's)?
sounds like you need an rmm
and how to connect discord to tryhackme?
easiest way is to look at sites with vdps/bbs programs and start on them
Whos gonna get there first...
Well done, Jayy π
thanks bro
Gave +1 Rep to @sharp citrus (current: #231 - 22)
vroooom
That will definitely be implemented but I feel like there is much more to do
we dont trust the image sources
or that the users will regularly update
or them with admin rights
can you expand on that please
It worked, Kuba π
oh I am not going to lie, it is a bit of work. But yeah, a decent rmm is where you need to start. It can handle patching, you can deploy items through scripts, ect. As for Admin rights, I would never in a million years give any standard user Admin rights. Plus that violates NIST Guidelines anyways
https://www.hackerone.com/
https://www.bugcrowd.com/
sure, checkout the links above - sign up to them and you'll see a list of websites with active programs which you can then scour for bugs
Sounds like they shouldn't be on your network
It is kinda of complicated, the business department trusts them but we in IT think they could be OR could be used as attack vectors so we want to limit everything and take our precautions
exactly right
So we want to develop policies and guidlines for how to safely onboard vanilla os while we are at it
So don't give them access to company resources.
I'm worried it'd trash your compliance
Easy solution. Take a waiver over to the business department leader and tell them that not only does this disqualify you from cyber security insurance and its a not best practice, but that it is also a violation of policy and they personally assume all responsibility for what occurs after.
One thing I am considering is creating an entire seperate VLAN for them with least prev
but its the OS part that scares me
having to constantly check of updates and stuff
What should I buy with my $75 amazon credit? I was thinking 12 months of Mullvad
Ngl that's outbound only access territory
but i guess rmm makes it easier
an RMM will take that worry away. LOL alright im done throwing out RMM
pwnagotchi
Truthfully any OS is dangerous in the hands of someone who doesn't care or isn't informed about cyber security
rasbery pi 0 wh and e-ink screen
i already have a flipper and 5 raspberry pi's
nice
They would be complaining the second their computer turned on lmao
Ill look into a good rmm and how to implement it, if you could name a user friendly one that would be amazing. even if its not free or open source its okay they will have to cover the cost
Fax
What can you do with it and what you did ?
Oh yeah definetly, but throwing the blame and turning our backs would be "half assing" the job which we dont want to do
I mean lets do it well even for future occurences
I set up a vpn gateway for remote access into my church's network, as the lead sound engineer / network admin, then I could do some remote network shenanigans
no lie, never ever use an open source RMM. As for recommendations, I'm really careful about recommending products to be honest. There are good ones out there, like Connectwise, Datto, ect. Finding your right rmm is like fiinding your favorite flavor of linux tbh
fair enough
I can respect that. It is more of a "you really need to understand what you are asking for here"
connectwise had a breach recently
No that's risk transfer
Yeah, every IT principle you follow will tell you its a bad decision but at the end the business wants what the business wants
What's wrong with an open source solution?
^
Yeah, I know. Unfortunately it was a bad one that is hard to defend
nothing is wrong with open source solutions. But for something as critical and mass deployed as an RMM, I would never use a free open source solution. No support, no accountability, everyone can see the source code and look for vulns, I mean list goes on for that one.
That last one is a benefit not a drawback.
Open source solutions can come with support contracts.
you think we should draft a doc that says if anything bad happens that will trace back to them they should take responsability? i mean its not a bad idea tbh legal wise
It needs to end up with your CISO IMO
what makes it worse is how easy it was exploitable. You know that vuln was getting worked over long before anyone found it
It's a huge amount of risk. Either that, or simply do not allow them access to your company resources.
Compliance or block it from the network
ur totally right btw idk what i was thinking.. open source
I guess its just dealers choice then. I personally would not recommend using a free OS project for an RMM.
people that think closed source is more secure then open source software makes shadow go WUT
neither is really more secure by default
Look, Shadow, I like hiding behind the beautiful bliss of ignorance and believing everything vendors tell me
yeah but not in a corporate environment
but in closed source you are betting on the few programmers that make the code to find and fix all the vulns instead of everyone that can read the open source code to do the same
does this mean people read all the open source code that is out there??? heck no
eh when those people realize that programming languages are open source 99% of the time
No that's wrong
Open source solutions can come with paid support contracts. It's Red Hat's whole business model.
It's not the language, it's the product.
I thought IBM bought the rights to red hat
Yes. It hasn't changed the model.
okay so before we steer off topic too much, im gonna make a list of critical points we need to focus on and everybody is free to add/comment
Thats why we have the undeniable king, the code and savior, chat gpt. verions 3.5
@finite folio Honestly if I was talking to a client about this, I'd spend a lot of time gathering requirements. What do these devices need? Why? Any access to company resources?
Yeah I saw John Hammond's video on PoC and it was embarrassing
verify the os image and source / implement and rmm for patch management / create a sperate VLAN isolated from company resources / revoke admin rights
yeah but in 2023, red hat stopped making the source code public
what about local policies ? isnt there something to be done there
dude I cringed so bad... for granted John Hammond is the GOAT. but still.....
ohhhh dw there will be a lot of that
just ask chat-gpt
they wont get 1 right above what they need
It's still available to customers etc. It's still a support model of open source software (Linux)
Plenty of others but that was a widely known example.
the making the source none public to none customers is heavily debated if it is legal or not
due to the source licenses
honestly you are probably right. Im betting you know more than me, so I concede lol
?
enable secure boot and disable bios. never go wrong w that
when I saw that 20 second video of 0 to hero
yeah... Although when you see a hammond video pop up, and its under like 5 min. You know its real bad, because John will give you full tech breakdown
Yeah
yeah, password restrictions, history, length, requirements, ect
some one give the the right to upvote xD
thank you bois, if anyone has and idea he can msg me it would really be appreciated ill update you whever i can
just saw this. That is step numero uno IMO
maybe it will be story of how the cmpny got breached but hopefuly not xD
thats the spirit
does it have darkmode
Asking the important questions
as far as shadow has heard and seen... no dark mode yet
we only care about integrated dark mode
yes
Smh
that is where the visually impaired get left out???
then again with the new light theme/mode some of the answer boxes are way to low contrast
they can use a white mode extension
why should they have to???
black > white
(not people :))
I see a new tab 
They had to kill it after a little bit iirc
So it's back
Well on your way to a career as a front end dev
is vh even a CSS unit? π€
by getting an AI to do it? π
.titanic {
float: none;
}
Interesting
overflow: hidden
}```
Meta goes down, now LinkedIn is down

Thatβs weird
those 2 are not related so indeed weird
BGP is a hell of a technology 
unless it is related by the user base jumping from facebook to linkedin to ask if things are broken
yeah just ask emmers
What do you guys recommend as passive cybersecurity learning? I dont have the energy or mental fortitude to do a ctf but i kinda wanna still learn some stuff
Ive been watching ippsec but i cant really think of other good things
podcasts?
you can listen to them while doing other things etc. Nice way to learn somethings without doing
apparently that is a real website
it is indeed

Anything you guys recommend?
thugcrowd
Honestly reading chat here is good. Lots of people here with much experience. Especially when the more technical questions come up
shadow is not really a podcast listerner Β―_(γ)_/Β―
hey what's better thm or hackthebox?
THM
it's free?
you are a real lurker huh, good shout though of course
hackthebox costs money
I've learned more from a couple of people here than I have from podcasts 100%
Just popped in hehe
Free to an extent, at a certain point it cost
You are asking this in the THM discord, you might get some biased results π
you're asking what's better in a thm discord, likely going to receive a biased take. (not knocking thm I love it, just saying lol)
jayy beat me
Has anyone watched the new dune 2 film? I saw it last weekend, so good

can't really afford going to the theatres so nope not seen dun 2
how do i link my thm account to discord?
*dune 2
~70% of all content on here yes
kek
GG
I think it'll be streaming in a few months! Something to look forward to
sandboy adventures part 2
Nope, need to read the book first
He's sandboy alright
Yes!!!
can't really afford streaming services either but oh well
never actually really seen or been into dune, but i know the gist
Also doubts the library will get it soonish
I'm literally just about to start rereading the second dune book
ok
Hopefully soon
i'm green now
google sometimes has, interesting stuff
such as trailers and such!
well it also helps shadow is not super interesting in dune
do you recommend?
Worms! Politics! Religion! Sand! Worms! Worms! - gist of dune
Yes it's my favourite book series
big scary worms
very scary big worms
and some humanoids who thought it would be a good idea to settle there
for some godforsaken reason
They didn't exactly have a choice
They've adapted though it's cool
They ride the big worms
im just messing about, dont know that much
i saw that in the trailer yeah
Hehe I'm trying not to spoil anything
It's very cool
maybe ill go read it soon
iv bought the first book, it's sat on my bookcase... one day!
Yes! The audiobook is also great
Darknet diaries is full of both technical and non technical podcasts with very interesting people. Worth a watch if you havent yet
me with the 40+ books on my ereader
i mostly listen to his podcast, great guy with enthousiastic approach
btw @grizzled crystal , im at MAG 112, listening to it on and off, shit is confusing still but i understand most of it
if you like Darknet Diaries, check malicious life
yes my friend loves this one. it's really entertaining
this also, I even pop in koth channel and read through, even though I have no idea about most of the things they talk about. every now and then I understand a little bit more 
nop, me want to go but parents dont allow
waiting for blu-ray release now
Omg you're so far ahead! How are you liking it?
htb academy or htb
its good π
Favourite character? π
Ooo just checked their website and I see theyβve got interviews with Mitnick. Love that guy
Subjective.
For sure, it helps to read through conversations
iv just started mitnick's ghost in the wires on audible
rip mitnick. we got him kicked off of at&t with edward amoroso's cuid
hmmmm, i really love the voice of gertrude ever since the first circus tape
im reading that atm!
I did sandworm and then the cuckoo's egg, now ghost in the wires
???
sandworm and cuckoos egg were both great
Totally! Even my lecturer/supervisor at university listens to it π I often listen in the car while driving. Find it quite motivating towards doing further research as well. Very valuable
those are books haha
Gertrude, what a gal
wtf I didnβt even know he died until now :o
Wow Iβm out of touch
ghost in the wires... rip off of ghost in the shell
Loved his book art of deception
it's a podcast created by the people of Cybereason
rereading all his books atm
1.8 more books left
hi, im looking for a friend who is interested in cyber sec. Im from europe :). Feel free to dm me
for what purpose? π
Friendship
Hi, my friends and i are on tryhackme and we have a Discord server, i added a channel thinking it would be nice if I could get the scores from my friends list in THM to post on the channel once a day what the score are. I thought i could do this via a webhook but im not getting anywhere. Anybody have any tips?
@shut hawk Might be your best bet, if it's possible
I'm going to pass this along to @mossy river because I'm not sure what the ToS is for automating the data gathering of friends score lists from the site
knock knock Esqy, knock knock Esqy, knock knock Esqy π
Hmm? sup Rex π
I'm well, a bit tired I'm looking for a place here in Argentina (I'll stay for a while until my family problems settle down)
We don't provide public documentation for the API.
Ive looked into it a bit, but is anyone else getting lag in the SSH terminal in the Common Linux Privesc room? SSH was working fine until i got to task 8, where I suddenly started geting horrid terminal lag. At first I thought it was actually freezing, but when I went back after a few minutes to try something, I saw all the commands i tried to run when it wasnt showing up. It will work smoothly for a minute or so then starts lagging. Is this just me or has anyone else experienced it as well?
On some occasions I've had the issue, but for the most it typically runs well for me
yeah thats my experience as well, maybe just a bad day. Just wanted to see if it was something to do with the room or something i needed to fix on my end
Alright, thank you!
Gave +1 Rep to @mossy river (current: #6 - 1187)
where do i put my discord token in?
In the chatbox. Type /verify
@tawdry pendant
@lavish shell ty
Gave +1 Rep to @lavish shell (current: #692 - 5)
@sick lance whooo
The case was pretty fun, and managed to pass the extra challenge quiz in the end!
grats
Good job
its a shame they added those ugly red rectangles.
they kinda ruin it.
@grizzled crystal Possibly able to get the ticket for 25$ and watch it this friday
u think its worth it
normally tickets are 8$ but I gotta bribe parents
I think so but you should probably watch the first movie
yea watching it tonight again
Yay, enjoy!
agreed
Yurr Wsp TryHackMe community
Best community on this app
We all have our own cup of tea
so you came to thm discord server and tell them in front of everybody. i don't like thm.
it's like going to the united state and tell them, i hate the united state.
so, they will say.
And in both of those instances the opinion should be respected
Aye we all have our own opinion
and everyone goes happy
yeah, we can put our opinion with much more respectful manner i guess.
there are contact form and suggestions to make anything that may not look good, better.
Besides attitudes you all gotta change that shit on your own
i have a friend that tells me about cisco netcad the same thing. that there courses are not good
THM is a lot better than some other places
there are people that can learn by reading and practice. while other by watching. so if you preffer watching i guess THM is not the best option for you.
pass my salutaions to Mr PoloMints.
he must have a special badge for himself as (Room Master)
best content creator π₯ .
false
Hm, I wonder
not malicious, just want to help people get their certifications
Wdym
Click the link and find out
let me know if you have any questions!
Grr
I mean to be fair a lot of people are doing that right now

It's okey, never mind.
I have a friend there, living in phili he tell me that the state is going crazy at the point that they will ask people fees from breathing air from different states. lol
I think it is, I noticed that too
eg: if you're in phili you need to pay to breath in NY.
Can't we all just get along?
Yep, why?
Given the context, which of those do you think is more likely? 
That would be lovely, but I'm increasingly convinced it's antithetical to human nature
Sums up the health insurance 
My tax return only gave me back $175 out of all the money they took π
It's ok, I treat everyone online as if they were AI. If they don't respond well, I just tweak the conversation a bit to alter their responses π
That's how I treat humans in general
Changing my name to AI Aiko now
Lmao, no man with dating you get a hell of a lot more input than output haha
You have been reading too much robert greeene books
Is business not a series of exhcanges of risk/reward that is impacted by how it's delivered
Worst part is you're actually not wrong... whilst simultaneously demonstrating exactly why everything's fucked lmfao
Too much Robert Greene books for you
Not sure who that is lol. But I've done my dating, completed my adult friendships phase, and am married
It's how life is
The world is fucked if you look deep enough
W
Im never getting married lol
Oh thank god my power came back on now I can study yayy
Lol
if you look deep enough
Really?
You learn chess if you plan to play is basically my view.
You can leverage kindness just as much.
And if you look deeper you'll find just an old intel i7 6600 cpu processing our surroundings
anybody here watched a quiet place
True
π
The simulation theory lol
At least it wasn't Trump, that guy still runs on DOS
eh me need horror

i thought the thing was a normal sci-fi as well as alien, they didn't seem scary tho
I deleted my message because I remembered the rule about politics lol
Sameee

I'm still a huge fan of old school cheesey horror
I don't disagree. If you take emotion entirely out of the picture and look at humans as being logic puzzles then you're exactly right -- it's just a series of stimuli which cause a desired outcome.
Only issue with that is that humans are emotional creatures, and you treating them otherwise doesn't exactly help with the shitshow of a world we've created for ourselves. "Everyone for themselves, screw the rest of the species" is a great attitude on paper, but just makes you an asshole in real life.
Sorry, I neglected to read the rules so wasn't aware about topics that were out of scope
me need something to scare me
watched the menu and laughed my way through it
Then of course you get to the point where you just want to step outside of the entire construct of societal interaction and nuke the whole freakin' lot of it 
Best I can do is offer you a mirror
There is definitely someone somewhere plotting that
Was hoping that world peace would be achieved when 2020 started guess not
eh lets do a american cheeseburger
Could you tell them to hurry up please?
hah
Most are emotional creatures. I specifically identify folks who can be trained up and do so, and offer compassion where functional. Part of what I teach them though is identifying people in a way that offers you an understanding of how to lead them. Which also means you understand their input/output and assign a value to the usefulness in your particular situation.
You know the saying "When you're in a hole, stop digging?"
What hole?
I can be emotionless when it's useful lol
points at deepest man made hole
All depends on why you're in a hole
It's a beneficial trait to me, not a hole
Wife hates it because I'm hard to argue with because I don't get upset
If you're in a hole because a heavy object has trapped you, either dig or suffer to the end
Again, I don't disagree. It's a very beneficial trait for an individual.
Less good if you give a shit about anything else on this lump of space rock we've all ended up sharing
I can agree with the sentiment. But just as an unarmed individual will struggle heavily, and it may even be impossible, to defend themselves against an armed adversary. Understanding and making use of the system is the only way you develop any type of leverage to have a positive impact.
I lean into kindness because it comes around.
Rather have a warm hand slap by back than a bitter heart stab it
You realise that's a never ending cycle, right?
Correct.
Do you have a solution?
And now I'll be leaving. Have fun
Take care
@sharp citrus

Sup
See aforementioned "nuke it all"
Genuinely, no, I don't.
I don't personally believe that there is or can be a solution. I think that this entire parasitic species is fundamentally flawed -- desperately trying to cling to life at any cost, despite that being the worst possible outcome for literally everything else. In the end that's the driver for everything we do π€·ββοΈ
I have no hope that humans will change -- that people like yourself will be less manipulative. That bigots will stop being bigoted, or that they will die out. That carnists will stop mindlessly killing for no reason. That warmongers and politicians will stop clawing for power. I could go on all day about the crap we pull to each other and the planet.
I have no hope that people will care, or that they will change. So no, on the grand scale of things I don't think that you choosing to not actively toy with people for your own gain will make a difference. I just think it's still worth raising the problem rather than quietly ignoring it.
Idealistic views. It's a nice thing to enjoy.
And an all too common occurrence these days π
Very very common
Something so common, having so little impact though.
You can do good things for people, only if you are capable of doing things to begin with.
Love takes energy
You have to build it up to give it out
When you're trapped into postmodernism, the only way out is to deconstruct yourself into nothingness. π
Classical heat death theory of the universe rendering every point moot?
It is a nice bed time story for me
lol
Philosophically speaking. π
Of course. We still have obligations as individuals.
We can ask questions, but still carry out duty
Benefit of being married actually.
She keeps me in check and productive

meep moop time for shadows sleep sloops to the beepity boopity beep boops
Speaking of obligations as individuals. I don't know about you guys. But I get pretty angry that the Nation State Actors can pretty much do as they please. I would like to contribute to the protection of my nation, but from my understanding, you need a good education to get into that.
I wish I knew of a way to, "cheat" the system or if there was a program to take people that want to do the thing; to the next level. I believe I heard the head of the FBI in the states saying that even if they had all of their agents focus on China, they are still out numbered. Where is urge to get more people to help with that?
My apologies, if this was not the intent of the past few statements made here. It just got the blood boiling.
What country do you live in?
That States.
Was that a question or a new novel you're working on? π
Atleast they care enough to round up and not down
I appreciate it for sure, i think i missed some of the other context, but that's okay
Honestly, in terms of ethics, that whole thing is questionable. Everybody says white hat, but it's only the act of a white hat as defined by the Nation state hackers. I'm sure the one's that they target would otherwise consider them to be black hats. That's why I feel the only line in ethics or morals is the line you yourself draw and whether or not you ever decide to step over it.
It's all relative (mostly).
But that is a more an academic conversation that doesn't really fit here
Sorry, the only friend I have is known as qwerty π
Has anyone learned anything neat recently?
Been learning a lil about Rpa with uipath
It's not recent, but the keyboard used to be in alphabetical order but was changed to it's current latout because people were typing too fast on the typewriters and the striker tongs kept getting stuck together
RPA = Remote Path.....?
Robotic process automation
ohhh, wasn't expecting that, very cool
basically automating stuff with a UI and clicks
once I learn it I should be able to automate stuff a lil faster than I could do in python
neato
What u been learning Toaster?
I've learned that managing a Windows workshop when you aren't allowed to set up AD is a pain in the butt.
Anything windows it too much pain
π―
ooo, what hamster u got?
hamster?
So ham isn't hamster
amateur radio
so u cooking some Ham?
Software Defined Radio??
hmm
SDR
yeah, parts of it
I think I need sleep
learning about some of the DSP and filterting and such
You have the tools to analyze radio signals?
Because Ringzer0CTF has a few challenges that deal with it if you wanna test your skills
btw Toaster do you play any games
how do i add up my writeup?
Preferably not here lol. But basically any other site that offers a blog or feed type setup, a lot of people use the site medium
@sinful moon u here?
Watching Foundation, huge fan of the books so itβs interesting to see the series
Nice
I need a recommendation for a movie seating
Uh middle is always good
hmm foundation seems interesting
The books are better as always but itβs quite a decent series so far
Guessing Dune II?
Enjoy
And yeah thatβll do
Yup
watching it this saturday
go back more if its imax, i was nearly in the back row for my showing and could see fine
hmm
tbh imax wasnt very worth it unless you're seeing the 70mm version, would be fine seeing in digital or amc prime
How can I check if its the 70mm version
just shows IMAX
it should say, theres only like 9 theaters in NA showing the 70mm version afaik
eh going to the only IMAX theater in Pakistan
oh dang yeah I dont think 70mm made it there yet, should be a good time either way though
yea
going to opt for this seat
Buffer overflow is sooo annoying
And also fun, loved doing it in Microcorruptions using a debugger for an MSP430 Microcontroller
Is it too early to start forming a team for a month long cyber security event in October? New people are ok, but I always wait until last minute and that's all I seem to get. I would like yo have people with experience.
hi I normally use HTB Academy for you know pentesting but I'm trying THM out for OSINT
and I got stuck on this one room
its the sakura room
I was able to find out the attacker's real name but don't know their email
can someone give me a hint on how to find their email?
Go to help channel and someone will assist you.
ok
need to test something relating to vbox/vmware
debating if i should install it on my host or within another vm πΆ
I would do it in a VM as it would provide an addition layer of virtualization and protection. When I do malware analysis I use a distro of linux that's a VM version rather than just an iso for that very purpose.
Ah, ok. Well that's all based on preference so...good luck with that π
i wonder if it'll complain since i'm already running kvm
morning
m
It might lol, just smack it around a bit until it cooperates
how are you
tired af
hm. i should grab a desk beer.
quarter to midnight
sry more like half
forgot my clock is fast
always set my watch and car a few minutes ahead
never be late
think a desk beer is needed
ima do the thing and vbox then ima grab one
nice
Don't forget the shower beer before bed π
i wish i could have a desk beer but tis 8:30am ahjaha
that's like the perfect time for a desk beer tho
is it a beer in the shower or beer instead of water ahaha
always
cold beer hot shower
i dont have beer. I have whisky and kraken and chocolate vodka
something tells me that drinking deset might not be very pleasant
The Saharah one? Sounds like it'd irritate your throat π
its made in glasgow
that is cheap thats like Β£8
and where i am its Β£4 for a litre
aed you half then half again and tou have pounds
Delete before my wife sees, she'll be wanting that next, after sex on the beach, which sounds like a good time but ironically isn't after a couple
i normally defer to an islay
trust me you need to try chocolate vodka its calls for alcoholism ahaha
but ironically isn't
just like the namesake
you cant even taste the alcohol it when yoiu drink it with coke all you taste is chocolate dessert
have you ever had the hersheys collab beers
i forget who they did them with
but my god
no i havent
Only thing I taste is 0's and 1's. I've been in the matrix too long
over here they sell 80% absinth for Β£12 ahaha its wild
back in the day (like a few years ago, lol) we would just by some spirytus for mixing juice and shit
ahaha
at 96% and the same price as vodka, it ends up being cheaper in the end
use half as much, doesn't dilute the flavour as well
over here its cheaper to buy spirits than it is red bull ahaha
Juice and shit mixture doesn't sound that great honestly π
i once got dared to mix vodka and rum and whiksy together i thought i was gonna die ahaha
you ever go swimming at the beach? πΆ
That's one of the most Scottish things I have heard all year.
how so
I drank vodka and jack Daniels at a river, I wound up getting dragged by arms out the road by my friends because I was too drunk to move
that's just a tuesday here
ahahahaha where i am every scottish person would love. Unlimted drinks for 4 hours for Β£40 and they dont measure you get like 70% spirits and 30 mixer ahaha
Chroist.
I won't be going anymore after that nice little visual element
Makes Australia seem dry, and it doesn't need help with that.
women get to drink free on weekdays for three hours ahaha
all the fishes!
What happens beneath the water, stays beneath the water haha
ahahahahahaha
Anyone have any idea at all exactly when DeadfaceCTF will begin? Is it the first of October, or the second week of October?
bash | tee
ope
would tee file.out <<< bash work
genuinely don't know if that op works for that or not lol
right -----
tee file.out <<< $(bash)
virtualbox users --- when setting up a windows vm, do you use the auto installer for the tools with an unattended install or do you install the tools after booting in? curious.
same q for vmware ppl if any are here
Dune part 1's insane nwo that I am watchihng it seriously
did you get your dune bucket
nop what's that
noway you do cod aio
cod?
yea
just a popcorn bucket
yk
nothing special or weird
Iβve not seen it
oh k
yea bro fr like salty popcorn
It looks so awkward to use
40$*
dam i dont have that for a empty bucket of sweet popcorn
eh if I become a billionare then sure
trillionare
now you got to get your hand out buddy
i have a new friend request apparently but i have no idea who tf it was because discord doesn't sort them by date recieved ,-,
noice
can you not see the name or do you just not know who they are
literally never heard anyone reference STAR outside of "here's how to do well in an interview!" bs blog posts
i have a whole list of people i've ignored but not declined and discord refuses to sort it
its what ive heard alot i do a star method answer
i get friend requests daily i just decline
brb gonna go apply for this cool DLP role i found
after getting annoyed i've adopted the igaf method for interviewing
a lot more casual
if the interview begins very scripted and question and answer i'm turned off of that company pretty quickly
i need to stop being nervous and just charm the interviewer
it's easy when you don't care anymore
Yeah I need believe in myself and stop the wee voice in my head telling me I canβt do something
Indulge in a generous holiday allowance with a minimum of 7.2 weeks, wierd that they give you 7.2
just list the number of days or do whole weeks
it's literally just 36 days
say 36 days
also that's pretty standard i feel like, is it not?
that's literally just unpaid time off
can't say i've heard much but they aren't big around here
tesco is a huge supermarket chain in the uk
the only bank i've written off as "absolutely tf not, never, no matter what" is wells fargo
otherwise π€·ββοΈ
ahahaha why have you written them off
it's a whole thing going back many years but if you've seen the inside you know how bad it was at one point with legitimate corruption and theft from customers and such
silently encouraged
oh damn
know quite a few people who outright toss resumes of those who list Wells depending on the role they had there
lack of trust due to how widespread it was
that sounds really bad
lmfao
From NBC:
In 2016, Wells Fargo was found to have opened millions of unauthorized accounts for existing customers to meet sales goals.
straight from the justice department:
Wells Fargo Agrees to Pay $3 Billion to Resolve Criminal and Civil Investigations into Sales Practices Involving the Opening of Millions of Accounts without Customer Authorization
the other main company i've written off to the same degree is tiktok
for different but hopefully obvious reasons
yeah i can understand why
lmao another one from Harvard Law, specific to LA:
In September 2016, Wells Fargo announced that it would pay $185 million to settle a lawsuit filed by regulators and the city and county of Los Angeles, admitting that employees had opened as many as 2 million accounts without customer authorization over a five-year period.
yeah pretty widespread and silently encouraged fraud
employees were fired for not taking part in some areas
yeah π¬
wait they were fired for not taking part in the fraud?
obviously it wasn't made out that way, but if you didn't take part, you were suddenly on the chopping block and they did everything they could to push you out --- whether through "downsizing" or finding other things they could hit you for cause with
Thatβs really bad
Sorry to interrupt, just a quick question. If it's inappropriate I apologize, but just curious. Meta Data on pictures, I know it can and does get deleted, but would it be possible to perform forensics on the image to retrieve what was deleted from it? Probably not...
also:
The bank settled allegations that it illegally repossessed military membersβ cars, and it was found to have charged car owners for insurance they didnβt need and paused borrowersβ home loan payments without their approval during Covid.
on the image? not necessarily. on the storage media itself? absolutely
well, not necessarily if it's done properly
some yes some no
Facebook removes it
certain metadata will be kept but some will be removed (if they do it right), like geoloc
But some sites, most definitely and it is scary easy to extract data
i've made a few k just via dumb ass exif issues
I'll shut up now, talk to you later
Well, I knew the answer just wanted to confirm. As a picture doesn't contain a storage device, there really isn't anything to retrieve deleted info from. He was right, 100%
obviously poor deletion methods could be an issue
like apple's issue with cropped photos being uncroppable
but normally yea
Ok, got work to do. Trying to install a linux distro on my phone.
why do i have a feeling it's nethunter
Kali?? Nah, I never did like Kali
Setting up a VM on my android, so my choice of an OS is only limited by my preference.
Yes, virtual machine on my android
..what hypervisor?
Limbo x86 Arm Emulation
It allows me to hack on the go without relying on termux
Trying to setup openvpn for THM on windows, doesn't seem to be connecting, any ideas?
what is that gui even from
I really need to switch to a linux distro, but I like playing games without having to worry about support
idk about the openvpn client itself but for some clients you might need to adjust the available ciphers
no idea how that works on windows tho
Makes sense, guess I'm using the attackbox now
drop a message in #site-support or something, someome who actually uses windows might come along
do you actually play anything that runs annoying and extremely invasive anticheat, or?
used to play valorant, not recommended, minecraft these days, but I'm too lazy to make the switch
yeah no idea about valorant, but minecraft would be more than fine
honestly proton and lutris and such have come extremely far
the steam deck being arch based has pushed things along
Honestly, you don't have to switch. You can have an OS on VM alongside your original windows. But Linux is better. Even their slogan is better "Microsoft gives you windows but linux gives you the whole house"
^^^^^ set up a kali vm for thm, use the vpn inside the vm
i mean, still should switch, but that also works
my grub entry for windows is "Waste of fucking time"
Ironically, I got errors from tryhackme on my pc saying I needed to use a desktop but managed to start a machine on my phone π
That's what I do, I'm following the windows priv esc/ exploitation series and man the attackbox is slow af
No they're using the attack box for the room windows priv esc
Kali VM is what I use to hack mostly, but the attackbox because of the windows machines
I don't have a way to remote connect, because openVPN's not working on windows
but the attackbox because of the windows machines
can you elaborate
i think i'm missing something here, lol
I have tinkered with PowerShell a bit, not enough to diagnose issues but if you ever forget your wifi password I got you
i've been dealing in powershell for a couple weeks now for the thing in my bio
i hate it
worst thing i've ever made myself do
powershell is misery
Sorry, I might be not explaining myself well, just woke up, so I'm doing the windows fundamental and priv esc rooms, they require a windows machine to connect
So I have to end up using the attackbox
You don't love all the cmdlets? I sort of liked it because sooo many commands I knew from command prompt also work in PowerShell
is that the name of the room? kinda wanna check what you mean
it's also poisoned my mind
i forgot how to add in bash
Currently on this one, you should find a whole series I think
Haha
oh shit i see what you mean
yeah i actually still use a linux vm for those
not always kali but still a vm
connect via openvpn within the vm and then i connect to the machine with remmina
that's interesting, I'll have to look into this later
So, is your whole issue with OpenVPN?
yep
kinda happy with the results still tho
wouldn't wanna do it again
but it's made deploying vms much nicer for us
Would it be against the rules to talk about maldev academy here?
@glossy portal rdp-ed into the target machine with remmina from within kali using the vpn
makes sense, I'll try to implement this
unfortunately yea --- can be talked about in the adv channel tho (after 0xD)
vmcemption
Kali VM on a windows, using rdp inside Kali for windows
sounds wrong
Sorry, running vm in split screen mode and targeted wrong screen
this guy wants us to think he knows vim
you will be banned for this
unforgivable crime
o7
I actually hate vim. Prefer nano
okay yeah go ahead @graceful thistle
something something center a div
what is this, trying to trigger all the FE devs?
Hey it's hard doing all this 0n a phone; At any rate, it was nice knowing you lol
i mean, you don't really need to wait for that
the normal clipboard can still be used
i mean you can actually make vim just used the system clipboard
i forgot how tho
been years
Does the ctr+c option work in vim for copying?
ed is the best
shut up im dumb and preoccupied π
boooo
normally you can just shift highlight
that normally puts most emulators into marking mode
have to use that quite a bit when i'm layers deep in tmux weirdness
i try not to change hotkeys too much tbh
i'd rather work with what's normal, so that i'm not completely lost when i move to someone else's desk for 3 minutes
greetings to you people
hola
so many rooms are out recently... do you even sleep?
no
:!sh is also good
This is the only sleep we know: 0101001101101100011001010110010101110000
:e! [oh you already typed it]
very useful for certain situations
but why are exclamation marks put so randomely in Vi commands
cause we're excited to be vimming
so :!sh means yea let me have that shell
Shut up computer, I know what I'm doing π
still why not :sh!
pro tip:
add fpush to your git aliases to force push with lease
cause ik nobody does with lease automatically (lazy)
makes sense now :! thank you
Gave +1 Rep to @coarse totem (current: #122 - 51)
should change someone's key to exit vim when they aren't looking and watch hell break loose
mods are asleep
no
Nah I'm awake and caffienated
caffeine sounds good rn
tempted to just pull an all nighter
wait shit i forgot to get my desk beers 4 hours ago
this is a travesty
i was gonna ask about that ahaha
@molten sky You any good debugging linux boot issues?
Tried two different distros, using an emulated core2duo processor, 800MB ram, 10GB hard drive so room and storage isn't an issue. I just don't exactly know what to do here
which virtual machine do you prefer for a beginner
Oracle VM box
is it free
for reliability and less crashes id go for the free version of vmware
yes
i get distracted easily sometimes
it's hard sometimes when you don't have a scroll buffer and errors are lost, but the kernel panic msg on line 2 sounds like the one to focus on (no working init?)
otherwise not the faintest clue. i'm used to debugging these, but used to it in a throw-everything-at-it-and-see-what-works way, lol
nah it's late now, bouta just call it instead
grab some banana bread first tho πΆ
paid? vmware workstation any day. free? vbox at least has snapshot support without $$$
||(kvm is still king tho)||
good idea
maybe get a desk beer tomorrow for the weekend
it's 3:20 in the morning here on thursday πΆ
bloody hell you need to sleep ahahaha
H, well thanks anyway
Gave +1 Rep to @molten sky (current: #81 - 77)
ohh, nice, when did it change?
End of an era... π¦
Vmware workstation Pro is the bees knees.
yeah, i noticed
as tom posted, the nessus room has definitely changed
too bad broadcom bought them
i agree tho
do you think they'll discontinue vmware?
No.
can't imagine them doing that --- it's a money maker
bug they're messing with licensing for certain vmware products, already tossed out perpetuals for the effected ones, and they're probably gonna start ignoring the minor product line (ignore, not discontinue)
iirc they're the biggest hypervisor provider?
idk about the biggest but they are big
you've also got kvm, hyper v, etc
xen/citrix (although that one is minor compared to those)
oh yeah, I totally forgot about them lmao 
you still awake? ahaha
Hello i am currently working as a junior system admin but i also do some networking jobs , i want to know the rooms realated to system admin , and networking since when i search in the site it doesnt give me everything
Vmware is the company. Which product do you mean?
oh yeah, my bad I didn't mention, workstation product line
they definitely won't discontinue the ESXi line
They're selling off chunks of the business too
oh wait what π
who is vmware?
Me
I believe I figured out the issue I was having.
I'm VmWare.
lol
For my phone, I was trying to use distros that were 64 bit when the VM only supports 32 bit which (I believe) resulted in the kernal panic message. So, aside from me not using my brain, I don't think I should have any more issues with the vm π
I feel stupid for not remembering that sooner
Last otter pic....
I promise nothing
someone sent me a pic yesterday of the fattest squirl ive ever seen ahahhaha
no ur just bad at pool
Morning
I've mostly switched to KVM as VMware workstation on Linux is pain
Gm thm
Cgroups >> 
I mean containers are good too ^_^
Every time the kernel updates I have to recompile and resign the networking modules
Manually
Especially since the kernel updates about weekly
Maybe they fixed it in 17
But the V6 kernel requires signed modules
Hmm
I was still on 16
morning
I try to use automated tooling to generate the VM in any case
Packer is nice
And vagrant isn't bad for managing them
That would be more terraform
Heh had to lookup the french cybercrime section of the penal code...don't hack things you don't own, the fines and jail time are huge
(for a presentation I'm working on)
that's because Europe is GOATED for their laws surrounding privacy imo.
Yup
Yeah, suppose that would suck.
I still use windows.
Lecturer said my assignment looks good, this is scary news
Why!?
you done good.
Whyβs it scary news?
@grizzled crystal , are you available for DM? π