#general
1 messages ยท Page 63 of 1
Hi guys I have a code base in SQL/JS and PHP. I need help in finding vulnerabilities in codebase and exploiting them. Would anyone be willing to do it with me?
For what purpose ?
Go for it!
Learning to codereview a PHP based server. I have never worked on backend vulnerabilities . Hoping to start and work with someone together starting on Monday.
Why are you doing the code review (which codereviews are pretty garbage btw - as far as security is concerned)
I understand but my job requires me to learn so no option.
Oh, this is for work professionally?
consulting
learning for professional work yes but the codebase is a dummy one for practice.
Neat.
Our company has a collection of practice codebases
Do you know PHP?
Not at all. Learning JS for next 2-3 days and then will move to PHP
Hard to review something in a language you don't know
thank you! just dm'd
Gave +1 Rep to @grizzled crystal (current: #119 - 52)
Code reviews are hard when you know the language, they are nearly impossible to do well when you don't know them
Best of luck to you
It depends on the reviewer tbh
Haha yeah true.
I mean, a good reviwerer helps, but also the context. Do you have any reason to believe there is something malicious going on? Insider Threat?
I'm doing some research in this area, it's cool
I have a coding bg a little so I am guessing some Googling might help with stack overflow ๐
You tend to catch the obvious stuff, user input not sanitized, poor architecture
Some automated tools are getting better at it, notably sonarqube
Hi
it's the unobvious stuff that is still the security problem.. I hate automated tools, but they are getting better
I've seen a big leap
Which can do taint analysis
Yeah, but the easy stuff crops up super often
Can anyone help me with CEH prep?
try harder oops wrong one ๐
what's your issue?
Similar idea though ๐
Take notes
I have my exam scheduled on Saturday need some tips๐
Are you ready?
Good luck, rest up
Yes
Alright then, good luck.
You got this then
Just wanted to ask how to deal with confusing questions
Do they still have that stupid question about gratituous arp?
Get a good night's sleep
That was the stupidest question on a test I ever seen
Got my CEH exam this year, very excited for my first cyb sec cert
this is low i'd say
yea but the article claims "actively exploited" - whatever that means (they don't elaborate
#microcenter #nas #westerndigital
How come, no matter how much storage you have there is never enough!? Jordan has more hard drives from Micro Center than he can hold. But is it enough??????
Shop the Synology SYN-DS923 Plus: ๐ https://micro.center/ol9a ๐
Shop ALL Storage Solutions:๐ https://micro.center/vul7 ๐
#iwantamicrocenternearme #pcsto...
And you guys were dissing me for having 12TB planned
Having lots of storage is only good if you are going to use it
Otherwise, donโt waste your money. Storage will get cheaper
That is a real link
A referrer link
Probably not the best idea to post a referral link here though
Nice try: in getting us to give you a small reward
Itโs not against the rules
I mean sure but I still don't like it

I thought it was a polyglot
+1
Probably ethical issues imo
Kernel Level Rootkit?
Thanks Toaster!
Gave +1 Rep to @cosmic pendant (current: #37 - 192)
if done correctly, yep
One thing I've observed it is always easier said than done in hacking, but when we ourselves delve deep into hacking we face other issues as well. The tiniest ones isn't it?
Always true. I do believe I have need for that 12TB on a for-life scale, seeing how I've used just over half as much in the numerous PCs I've owned and passed down
You get a lot more use out of your PC than I
I struggle to think what 160TB's worth would be useful for though
Most of my storage is used by games and VMs
Databases
Well, safe to say most of it is the chunky downloads my game libraries throw onto me. Most of these things take up ~100gb a pop
i think you have a whole database of games
I have 2 TB on vm's alone.

Yeah my current desktop sits on 3.5/4TBs worth of games and VMs rn
12 TB is like 12 brand new pc's
What could you possibly use all of them for?
But how do you manage to store these much of data
Can you rephrase that?
Malware analysis, Malware exploit/written.
DFIR, kali and a full AD network.
2TB SATA HDD 2TB NVME SSD, that's about it.
Ah okay now it makes sense
Very cool projects
I'm too scrub to be doing all that
I mean if I were to implement that rootkit myselves having good conceptual knowledge, it wouldn't come easy there's always those 1/2 minor issues I'd get stuck into
As for how I manage to amass that, well. VM practise installs and games I haven't used in years
In a lab environment*
........... If you know how to do it, it's just a matterof doing it ๐
Maybe you know better because you are experienced๐
There are books you can read up on
A full AD network? I should probably get a lab up and running with that at some point, but surely that can't be over 100-200gb of storage at most
Please suggest
Doesn't that exploit require a chain of different exploits to work though? Or am I thinking of the wrong iOS CVE
Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats
Rootkits: Subverting the Windows Kernel: Subverting the Windows Kernel (this one is older but still the basics are good)
I have an Server set up, I also have a cli only and gui servers for backups. And have 6 different "client" pc's.
Bring your own device you mean!?
Ahh right, I forget there's mailservers and simulated backup servers with whatever samba shares
nope
Then
Why 6 whole clients though?
google it
Oh yes gotcha!
Because I use them to "simulate an org"
Lmao
Allow I'm a beginner ๐
No no I'm just thinking about the phrase
Bring your own device attack
Hehe
Yes you got me Cam!
Keep up that enthusiasm ๐
You'd be surprised how many people don't update their devices etc and that a method used to infiltrate a network.
I just ignored the V there I suppose ๐
Yes, definitely.
At my current job which thankfully I am leaving, all my staff leave their windows without updates for months...
That is the breeding ground of vulnerabilities
When we got a new IT director he locked everyone's devices that were x weeks out of date
Maybe they don't care about insider attacks๐
I mean they all have very sensitive PII so they should be
What is PII๐
Personally identifiable information
Oh๐
Best tip: learn how to research, it will massively benefit you in this field ๐
Learning is a skill
the amount of times someone has said something and I've had to open a google tab to keep engaging in the conversation 0.0
That shows a good mindset ๐
Point noted!
That's a flex
That's how I should view it but I used to see it as incompetence when I was younger.
I soon realised the fact you're even willing to go out of your way to learn is the important part, not what you do and don't know
Exactly, and not a lot of people see that.
Most people try to compare themselves against others.
Rather than comparing, use them to further your learning.
If you are smartest person in the room, you are in the wrong room.
Facts my friend
Having this realisation shows intelligence 
Mhm I try not to overestimate
EDIT: thank you however
Nothing but truth. Especially that last sentence.
Donโt sit in habituation, learn to enjoy the uncomfortable growth
People that refuse to accept that others are smarter usually struggle to ask for help. This causes frustration and slows their learning journey down.
The more you know, the less you know
I wonder how Fortinet are for certs.
haha yes
i got another one
idiots admire complexity, geniuses admire simplicity
salt water when boil pasta
aany one know abt webhook and how it works
What would you like it for?
not sure i have heard abt it
Basically, you call a url to perform an action
There are many many many implementations
example number 1 million of me failing to run a command because I've got a space where it shouldn't be 
That hurts
yeah i was trying the nfs mount command and had a space between the hyphen and nolock
and for the life of me could not see why it wouldnt run ๐คฃ
That'll break yeah
we got there eventually
I kept flailing at a command because I forgot a - once
does THM have webhook course
spaces and case errors are my nemesis
answer I may have
@shell nova
what did you mean by this account ?
No
Inspirational success stories: https://tryhackme.com/r/resources/success-story
The funny thing about motivation is that, it happens after you've started working, and usually after the work is done
I wasted like this half of my premium month, lol
music works for me.
blocks out the world of the simulation real.
Schedule a few hours. Do some work. See results. You're now motivated. Schedule more work tomorrow
wsp everyone
Guys are there any default creds for telnet/ssh?
And I just start studying on thm, and I get bored and sleepy
Naive question but please answer
idk tbh
I tried brute forcing ssh through hydra did not work same for telnet
telnet has no such thing
Used nmap script for telnet
How do I find out the username passwd
Brute force should always be your last option

I mean as 9999 port is open and listening found a hint there but it doesn't work at all
Abyss
Are you doing a tryhackme room? @spring token
Yes
go there and itll help u
Jared I got questions if you donโt mind
Ok
hmmm @sick lance ๐
https://www.vmware.com/security/advisories/VMSA-2024-0006.html
didnt know ryan is here'
he jump from time to time yea
damn
'Sup?
Didn't get any response
Hi
I would like to buy tryhackme premium I need a body for discount. is anybody interested in ?
I'm tired off myself that I'm even unable to crack ssh and telnet
keep trying
I will atleast I gave my best
you'll learn how, cuz failure always stop when they fail in something, and mistakes are great sometimes.
Yes hopefully I can learn
itll take time but keep going
always having issues with english cuz im iraqi :/
I find finally getting the hang of something after some difficulties is more rewarding than getting it first try. You usually have to navigate some problems and so understand what you are learning better.
thats the point'
u learn smth useful from ur mistakes
So It been on my mind for long time I google and everything but it just making confusion so I am trying to update my resume and trying to add some good stuff for example homelabs so what is homelabs is the one I do ctf like Kali ?
https://noted.lol/homelabs-and-learning/
So for example my homelab consists of a small server and raspberry pi
Oh wow I appreciate it big help
Wish you a good day y'all
VmWare don't often have bugs, but they do, they're critical.
yup, vm escape time
as in, breaking out of the simulation type escape?
accessing the machine hosting the VM
yup
eeeeek
Guys can anybody remember if there is a cloud azure or aws pentest course on thm or htb? I think i got E-Mail about this 1-2 months ago
there is an AWS here on thm
Thanks
you're welcome
hullo
I might do a room on this
Reee
Nice
How do cops track criminals phone numbers or mobiles?
May be difficult to demonstrate in a practical sense
Espeically if the user does not have VmWare.
Yup, was thinking more of a theory based room instead of practical
sup everyone!
I have a comment about "Complete beginner" learning path. IMO Kenobi should precede "Basic Pentesting" room, because Kenobi kinda introduces back the smb enums
Secret law enforcement tactics
They aren't accepting community walkthroughs anymore
Hi
Have a look at the "Anom" phones.
Afaik
I'm still looking to buy one.
Ah rats, you're right - forgot about that
here is Bubbels
And what r those tactics
I thought I bought an Anom phone, but it was inactive.
werent that honeypots
Not honeypots,
honeypots have useless data on them.
Trojans, woud be more accurate.
well if you bought the phone from your local fed i would consider it an honeypot
They didn't know if was feds behind it until the last minute.
Maybe I'm mixing things up here I'm starting to loser overview with all those privacy marketed phones ;) but weren't that the anom phones who were sold by the FBI?
I'm also not looking to purchase it for privacy, I'd love to chuck in all my DF tools.
That's why I want to do it ๐
They can check which towers the numbers bounces from, so it's not as accurate as GPS.
Triangulation works, so determining which cell phone towers are nearby.
if they know enough about the phone, they might be able to use local wifi too
Phones can also be tracked with a similiar method to apples find my. Basically phones check which other devices are nearby. This isn't as exact as GPS/
like the covid bluetooth sorcery?
yeah right
hey
Anybody here tried commando vm ?
Not for a while, is it still supported?
Well it look like it last update was 5 months ago so
But is something weird about it I did it yesterday after installation process it didnโt download any tool at all even my antivirus is off
Do you have enough space?
Way more exact actually, uses wifi networks etc as they're fixed typically
yeah most wifi networks don't move around
yup, a lot of tech youtubers who show around the wifi options don't sometimes blur it
so since u can lookup thier SSID on wigle and u got thier location of filming if u can cross reference a few more wifi networks if the same one exists in multiple areas
or just go to the site of the network and home in on it by measureing signal strength
Unpopular insanity: change your wifi name every 5 minutes.
I do update mine on occasion
or just set it to not broadcast
Usually cartoony names
or make it hidden
I swear every apartment complex has one chucklebutt who laughs that theirs is "FBI Surveillance van"
I see that too!
Be creative.
"Hannibals Meat Locker"
"Total bodies: 5"
"DefinitelyNotAHoneypot"
"DefinitelyAHoneyPot"
Do you keep your thm 0x1 on purpose?
ye
also Cipher of Sin, Helldivers 2 getting a lotta updates
integer overflow; return to start
Yes it is
Me and 2 buddies doinging all evening tonight after work
hmm
Mostly doing hard missions now but we may up it
Right
ah ok. I didn't know the specifics anymore i remember a samy kamkar research he did ages ago where both android and apple phones do this based on MAC address
although now me focusing on movies more
What movies
finishing up my denis villeneuve binge
Oo
Helldiver difficulty is slight. Only with a good team tho
Arrival done, Blade runner 1 done (pre-req), bladerunner 2049 almost done, dune part 1 done
I play with randoms
WE want to go higher difficulty but we are unlocking a few more gear items and wewant a 4th player we know
Yeah MAC addresses of wifi access points, BSSID
Same but some reason I always end up with some good players
I got Mexican coke!
eh 1 I get 1 good player
After a few ranks, most players are good
the rest are bozos
FOR DEMOCRACY
Oooh that really does taste different
wanna know smth, mexican coke or what yall call it was the standard here in Pakistan about 2 years ago
I heard Mexican coke actually tastes real. Assuming we are discussing soda
now they switched it up to the weird one
TACOS
I think itโs because they use cane sugar
oh... right... soda. the soda coca cola. that soda.
Wrong person
No Comment
use the 3 lemons wisely
That's LIME!
same thing
Facts
the more bitter/sour the better
Omfg, I had doubts bout this place..... this thing is AMAZING
Mexican coke is less loaded eith sugar, feels less carbonated. I love it
My favorite Mexican dish is birria tacos
adds to OSINT, Matt is at a mexican place eating 3 taco's which is in a platter/combo, contains spice, rice, lime, beans
although idk why we call it coke
Yoooo. I use Pakistani Camo on my ZTZ 96a in Warthunder
coca-cola is the proper name
cos it used to contain the non-soda stuff
ur words don't make sense
Back they they use to put coke in Coca Cola
Talking about his fighter plane in warthunder
Or tank
Or ship
Matt no at mexican
eh I don't play warthunder
I rock the Pakistani Army camo on my ZTZ 96a tonk in Warthunder
@heady nova
A fellow armor lover?
No biggie, just like saying hey - connection here
ye
Looks slick
btw u play any single-player games
"Worst" (I don't see it at all that say) I've done is weed. (It's legal recreational here, deal with it)
Gunner, HEAT, PC! Total War Warhammer III, Total War Rome/Napoleon/Three Kingdoms. Stellaris,Hearts of Iron, Warno, Sonic Mania, Panzer Paladin, Cassette Beasts, Ozygen Not Included, Don't starve, Elden Ring, Cult of the Lamp, Fallout 4.
To name a few
Mfer doesn't know how to actually smoke it

waiting for the mechs on helldivers 2
I'm level 25 so should hopefully have it unlocked
wait, wait, wait mechs are coming to helldivers 2
Ditto. Kinda wondering what they are going to toss to the enemies to balance it out
Mechs, APCs, etc
...
Helldivers 1 had them
I love mechs
we need a buff like this, titans on helldivers difficulty is tortue
This game is just starting my man
oooo yeah. I haven't faced a titan on that diff yet
I can imagine
hmm so mainly shooters
uhm isn't total war a shooter
Why is it always you?
gunner seems like one
Noooo. Strategy
hmmm
๐
80% of what I currently play is strategy games
oh k
WHen I do play FPS I use the mapping on th eside of my mouse to move things like jump to my mouse
nice which mouse u got
Nice. I want to play most of those but my PC can't run most of those, I have most on my PS5 but can't enjoy it ther eyet
Razer Naga Trinity
more horizon soon ๐ฅน
oh k
yup
although gonna play ghost of tsuhima first
its also getting a port
I saw the minimum reqs for that and I'm so far under it's no longer funny
After my India trip I plan to save up for a ~$1500 ish gaming PC
Then all will fear me
which monitor?
get a better monitor then pc
Good enough
get a 1440p one
I'm still using an i5 2500K ๐
Meh 4k just means you need a huge gpu
Mine's a 4670K at least
My brother does it and is like look how pretty this is
I see no difference
Eyeball upgrades wen
No upgrades, only downgrades
eh get a higher refresh rate and color accuracy atleast
I have an IPS monitor, accuracy is pgood
I mean, your eyes can't keep up with all the FPS etc.
some places offer laser eyes
Outside of strategy games I play a ton of retro games.
I'm stuck in 1986
Refresh rate is shite, but so is my gpu
get a CRT
Yeah CRTs are heavy
get a ancient desk
i have every uncharted game and havent finished one yet really need to
yup quite heavy
When I'm healed I'll hand make my own oak desk
THen I can do it
u should do it
i will
I can make a far better desk than 95% of these companies
ive hp probook 640 laptop with i7U which im using rn :)...
i need to finish resi 4 first
resident evil 4?
yeah
hmm
on hardcore mode just now
Also this standing desk is nice
i gotta play it sometime
its soooooooooo good
Been wanting to play through RE 2 Remake
got it in library
it was so well done
hardcore and resi 4 is perfect'
you should do it ive played it once its amazing
got both games and haven't had time to play them
Man that was a lot of positive instant feedback on the game lol
Yeah it's on my soon to do
But probably not till May
How many games have yall bought and haven't played
Several thousand
But that's from 10+ years collecting
ANd Steam used to do really nutty sales
Plus I have humble bundle subscription so each month I get like 10 new games
i have witcher 3, baulders gate 3, alan wake 2, all the uncharted, cyber punk, elden ring, control
Witcher 3 > all of the list.
i got all of those except balduers gate 3
control is awesome
i dont wanna talk about it 
I cannot wait for Silent Hill.
it is i need to finish it
RE2 remake was good.
Re3 Remake was disappointment.
well in the trillions?
RE: Village was good.
im not that rich 
i keep seeing vidoes of the baby from Re8 and it terrifies me
heard its the best

Bahha!
Get on twitch and stream it.
So I can laugh at you ๐
ill stream it drunk one day that will be interesting ahahaha
although why you waiting for Silent Hill only
its remake*
The majority of the games released these days are poor.
I'm a major SH fan, and I really hope it's worth the wait.
Sh2
both great
Silent Hill isn't getting a remake
well think shadow fixed a "bug" they are having
i need to try silent hill
Silent Hill set the bar for Atmopsheric horror.
u played the first alan wake yet
no
watched a video on it like how it inspired RE and stuff
Play it before Alan wake 2
before last year the only games i commpleted were the first two uncharted remakes
ok i will do
Nah.
They drew insperiation from each other, RE dated SH by 2 years.
one game that got me emotional was beyond two souls
@loud marlin https://mitxela.com/projects/etching_pcbs
Btw
Got it, not played it.
nice. just he have 40w laser, and mine is 2w. just he dont say what power he used to do the task. but yea. it can be done. and results are quite precise
its amazing i nearly cried at the end
You're just etching paint so I reckon it's fine
Chemicals for actually etching the copper away
FR4 copper boards are cheap and might be pretty
Can I post a mock question in here to show you how stupid my SoC exam is going to be?
yea. i can do the metal. but will need lots of passes to do so. but will try for sure. just when i get some time.
Seeing as you're not asking for helo with it, yeah
if i ever get my hands on around 10k$ will get fiber laser around 60-80w to make 3d stuff
Oh no, when you see this question, you'll see why I'm not asking for help...
Ferric chloride is a bit nasty but he talks about ways of making it less nasty
๐คฃ
must be a type of malware
true. + i can get my hands on more pure/potent ones that you can't get in free sale and so. that might give better results
...
what exam did you say this was an example for?
A network protocol seems correct
where is option E all of the above???
SoC.
level 0?
If you don't get 90% then I'll be disappointed
If I get less than 90% I'll be dissapointed 
905!
good one hymnosi
bbbut isnt linux the kernel not the operating system ๐ฅธ
@naive violet also... i have some machines and ways to "enrich" copper with more electrons, ions and stuff that might result in better conductivity, without loosing any other properties
Clearly B
Trace resistance isn't much of an issue
You just make em wider
its all but C is most used
Its still wild to me that most computing is almost done at atom levels of conduction
yea. i kinda did get that from what i read. with more powerful laser i can even "drill" a holes for soldering and so. so yea... laser, as in this case, can be useful for making pcb's
Like what the hell i cant even multiply correct and these dudes use atoms for some calculations
I just get JLCPCB to make them lol
Quantum effects are real
hehe. fair. one downside of galvo laser is that the laser that comes from middle point and if you do on wide area, it kinda all small angle of cutting. if i explain it right
My mind is just boggled when i think about it, and im just learning a pea size bit of knowledge of it all
I need to work out how to cut sheet steel
We're at the stage where electrons can tunnel through a FET gate
laser. let me find you some video ๐
I don't have a laser
Water jet also works
I like your pretty words magic man
GWEIKE G2 20W FIBER LASER (Available Now) - https://bit.ly/G2-20W-Metal-Laser-Engraver
Laser Cutting Tool & Materials:
Sheet Metal Holder for Engraving & Laser Cutting - https://ebay.us/sNERYw
Metal Business Cards Blank 0.2mm - https://amzn.to/44mN5gi
Metal Business Cards Blank 0.8mm - https://amzn.to/3pr3K3i
Bulk Slate Coasters - https://amzn....
Also don't have one of those
Also plasma torch
I'm a big fan of not spending money
True, prefer watching stuffmadehere for the tooling porn
spend money in useful thing is perfect
Using something once isn't cost effective
true
You get the cheap tools, if they break then you use them enough to get the better tools
This life is also one use only, have some fun with it ๐
fun with useful things is more better tha parties
I'll scribe some lines and see how I get on with snips
imagine urself hacking ur friend just for fun
That's no fun
@naive violet i can cut card for sure. will make you vid. but it need some time.
hello
Incredibly illegal, which leads to a huge lack of fun
card as metal sheet
if u friend know abt it ofc
I wanted to look up the penalties to add as a disclaimer to my pres, they're...high
In France it's up to 300kโฌ fine and up to 7 years in prison
hi how do i get started?
ofc and thx for advice
Gave +1 Rep to @gritty zephyr (current: #153 - 41)
For us its max 4 years plus fines
@gritty zephyr let's make sure your comments are appropriate for an educational environment
Sorry, shall keep it more sfw
Probably a bit on the line yeah
@naive violet this one is great
https://www.youtube.com/watch?v=yKHvCprJGQg
Wobble laser cutting brass 1mm
Laser marking system review:
https://www.triumphlaser.com/laser-marking-system/
Contact us for a quote and details:
https://www.triumphlaser.com/contact/
For more information, please visit our website:
https://www.triumphlaser.com
you also can contact us directly. Thank you for your watching, remember to subscr...
I prefer styropyro's laser.
how do i get started with ethical hacking?
that guy is a freak... i watch him what he doing
I hear that www.tryhackme.com is a good source
I'm impressed he hasn't killed himself yet tbh
or cut some parts of boby and going blind and crazy =/
wasent there a channel for suggesting rooms?
Nah he's already mad
Both valid interpretations tbh
I got kebabmix for dinner!
for sure. tbh... prob lot's of things might be illegal to do so lol
Ooh interesting
can finally probably switch to shadows fairphone 5 with calyx os now
I like my FP5
from the short test run shadow did they also like their fairphone 5
time for a stroll I guess
That's why you don't use rockyou for network brute forces
just been waiting on this calyx os release
what would you recommend, instead?
Generally not brute force
and if you must brute force at least use a web dir discovery list for finding directories on the target host
oh but the stem implies using brute force
Yeah but real world...
Hi, how to check the overall quality of randomness estimated to be?
Task 8 Burp Suite?
Burp's sequencer may help with that, as well as reading whats in the room
heya ben
@quartz mulch @primal ivy #room-help please
I see Ben Lurking ๐
Go to direct?
Ben hating?
Nah, no idea who that is.
don't forget the foil hat

eh X-files doesn't have a lot of tin foil hats
No choice E. All of the above. ๐ฅณ
darkweb2017-top10000.txt takes only 40 mins btw
depends on your target, tool threads, timeout, internet speed
i remember seeing the "cool ass paranormal entity" episode as a kid... freaked the shit out of me xD
and size of the wordlist, primarily, I'd say
yea
me watched x-files first time when I was about 7-8
Hey yo
me too, was about 8 or 9. and the episode with this guy who was able to squeeze through holes and gaps. we had this ventilation shaft in the bathroom... was afraid he was comming through that xD
@hasty sand you might here? mind i DM?
Tooms!
i sweated a lot of info rooms and now i have a bunch more badges and completed rooms
Hey everyone, im creating a CTF team, starting with the picoCTF 2024 and then moved on to others CTFs... if someone here want to join, feel free to DM me ๐
@shut hawk
Belkasoft sent you another course yet?
that one was scary
surprising that you can do the exam review before the actual exam and then you get instantly passed
How does that work lol
Probably just a IDOR
it doesn't alloow u access to the cert url before the exam
but since the review redirects u to the exam cert
Ohh
emailed the site about this stuff
Wanna refresh
yup
eh simple English test
just a requirement for a lotta programs here
Oh
Yeah
"Beyond the Basics: Mastering Advanced Digital Forensics Techniques."
Do certs ever expire?
nop
Thatโs good
yea ik, was talking in other context
.
ah, I think it was just a general question
๐
Thatโs fire
Ah your right
Should be offical merch
heh
yea... depend of from where u get them and time to make it
Hi, really sorry, busy day.
Did you get an answer to your question?
guys ive a question, when u try to turn on ur laptop with battery without charger it wont work, but when u plug the charger it turns on, while the drivers are all on latest updates, what could be the issues?
also have some small metal boxes or so
Sounds like an issue with your battery. When you use your laptop with a charger plugged in, it doesnโt use your battery.
Or in most cases it doesnโt. If your battery is flat, it will be taking the charge and immediately powering the laptop
Yes I did thank tho
Gave +1 Rep to @mossy river (current: #6 - 1188)
+10
The stickers are the only thing that we canโt always guarantee that they are in stock.
I canโt discuss the process externally but everything else on the store should be stocked ๐
Bet. Once they do a eventually come out Iโm buying it asap
my laptop is hp probook 640 g2, and then if i unplug the charger and trying to power it, it wont turn on, so what could be the Solutions?
the fans do
and also another question abt trojan viruses and how to remove it
Answer (1 of 13): You need a new battery, it's as simple as that. If it's an external battery, no problem, just buy a new one. If it is internal, then look ata few videos of how to do it with your model and go for it. It's really not difficult if you can handle a screwdriver. It's up to you. If y...
Sorry, I canโt provide device support over the internet.
If these donโt work, take it to a tech shop
Sounds like a bad battery. Depending on the quality of your laptop it may be better to just buy a new one. If you bought a $100 laptop, why spend $80 just for a battery? Chances are, if it powers on whilst plugged in but not when unplugged then it's the battery.
heh in iraq its only 5-19 dollars
Run malware bytes or any other antivirus you have.
Also Microsoft defender
You can DM me for instructions on manual virus removal, or you can otherwise try things like bit defender or other anti virus programs. Not all anti virus programs are equal. Nord may catch a virus that McAfee doesn't, and bit defender may catch one that neither of the other two did.
and if there's a file that microsoft defender cant access, what i could do ?
Manual virus removal through command prompt
thx
Gave +1 Rep to @lavish shell (current: #607 - 6)
Although, sounds to me like you may be experiencing registry issues which can be fixed by using Ccleaner to fix broken registries.
Iโm kinda confuse why defender wouldnโt have access to a file
it skips it
Oh
I see
We give help, not answers. You don't learn anything by being spoon fed answere
You can have hints tho here #room-hints
did he/she left that fast?
@quartz mulch
Only for hints tho
thx
anyone have vodafone internet in UK, is it any good?
@naive violet https://www.twitch.tv/oh_bother
This guy is doing antenna stuff and boards. Incase you're interested
I've discovered one issue with standing desk. It's been 4 hours since I sat down and I didn't realize till my knees informed me
what somewhat annoys about this cyber security and it in general, i like it and im like a kid in a toy store, amount of stuff i see per day that is new and what i must know in order to get a job in this field is insane.
"Jack of all trades, master of none"
that's why you need a purpose in your learning. then you pick tools that suit for this purpose and refine your trade
๐ have u seen a kid in a toy store and tell him pick 1
One tomato at a time
as much as I understand you, being a kid in a toy store will probably not get you far in this field
part of it is just learning how to gather OSINT efficiently
true
and generally how to ask questions
cause the correct question already contains a half of the answer ๐
it took me about 5-6 months to figure out what i want ot of this it, this is how i ended up in tryhackme and cyber security
so do you want to atacc or protecc
You know the full saying for that right?
or both for those of the purple persuasion
"A jack of all trades is a master of none, but oftentimes better than a master of one."
purple rain...
The amount of people I meet with PhDs that are entirely incapable at some common things is testament enough to the full saying
stumbled upon it recently
I think CyberSecurity requires a wide scope of understanding.
it might sound wrong but im so beginner that i dont care but iv been thinking of soc analytics or pen-testing as a start. i dont care what i do as long company where i work understand that im beginner. i guess whatim trying to say is "Where can i be most useful?"
and a portfolio
I tell folk make a github early actually lol
FOr IT, Programming, Cybersec folk
my last 10-13 years is construction work ๐
Even IT. You can do cool network automation work with PowerSHell and display it
That's a great thing though. That's solid life experience, understanding people, regulations, time constraints, logistics
ALl of that realistically transfers
Especially if you got into leadership
Feel good about that
yeah but not only this
on cybersec interviews, they often ask about your practice e.g. what you managed to implement or how you managed to improve anyone's security posture.
If you do the paperwork right, you can often get in some freelance practice helping local churches and non-profits set up and test.
and it is a plus if you can tell the amount of money that was saved by mitigating the vulnerability you found or something like that
The payment is them letting you list it as experience on your Resume
But cosntantly using things like THM is a great thing to include and show
yes, I do volunteer for ISC2 as SME, this is great practice
But real world physical stuff is big
Not if I buy them all 
oh my
Donโt you dare
omw to scalp thm stickers
just do it every day, and eventually you'll become good at it 
true
Good evening everyone! How can I read the forum from this thread? https://tryhackme.com/forum/thread/62bc5fb1fcafa700618f25f0
It's always redirecting me to this discord server
I think that means you can't read that forum thread
at a guess, I would assume it no longer exists, and that this discord is it replacement
Discord has over taken the forum, yeah.
ahh, nice! Could you maybe tell me how to fix the openvpn peer certificate verification failure?
Are you using Eu_reg_3?
Yes
Actually, #site-support please, I can help.you there.
@glass nest @boreal scarab
That's quackers
what does the blue one do?
I'm guessing the silver is concussion, and the red is remote explosive
blue is just holding his breath for last 3 days...
I'd be miffed if an assassintook me out with an explosive rubber ducky
xd
no you wouldn't because (1) you'd be dead and (2) it would be hilarious
I'd be so angry my spirit would linger
Follow him/her home and write mean messages on the bathroom mirror for when they shower

if i notice explosive duck ill prob pick it my my self lol
how would you know it was explosive?
It would have a fowl plastic smell
the whole idea is it just looks like a normal rubber duck
๐ชฟ
timer: <t:1709848330:R>
how dare you
||lol||
Speaking of explosive rubber duckies, there's a new usb drive that destroys itself with the click of a button.
ill ask before ๐

ppl have to much of free time to make dumb things like that
Sir and or Madam in the black tux, would you kindly inform me IF this particular rubber water fowl is capable of explosively damaging the objects and people around it? It would greatly aid in my decision making process
if you don't ask you will never know for sure ๐
someone should make a usb stick (with usb C) that wipes itself if you insert it the wrong way up
It's actually useful and designed for security. Can't perform forensics on an object that's been totally destroyed
you can always perform forensics
Small onboard battery that when triggered starts writing overtop of the data constantly
But it doesn't always yield results
good encryption with compliated password is much more ok. and you can faster unplug than find the button lol
Source - I've wiped probably 100,000 hdds/ssd
Not exagerating
Was my job to lead a team doing purely data sanitation on loose HDDs/SSDs for a couple years
Do admit SSDs there for a moment could not be reliably wiped, but they can now
so you had a job involving playing around with magnets and emps
3x pass with 0/1 will make it greatly to not retrive data
neat
Nah, various passes . 1,3,7, and a few more versions
There is a symbol on the keyboard i see alot in the videos I can't find
Standard DoD 3 pass is really succesful for HDDs
Its like a stick ( l )
| pipe?
Hard drives to deal with are actually those "hybrid" drives that have the small SSD board and a traditional platter
How to type it on mob and on laptop keyboard?
yea... full disk ecntryption with super-great password also is greatly safe
depends on the keyboard layout
So on laptop i have to install some custom keyboard to find it
for me (UK) is on the same key as backslash (\)
Wait wait i think i found it
Depends who is looking at it. Encryption that stops most hackers is fine, "National" level actors are a bit more capable.
Lol i have been searching for 2 days
Omg it's the same

Ty rswallen โค๏ธโค๏ธโค๏ธ
This one has a button that when pressed burns the circuit board by sending sending mass amounts of electricity through it. So if USB ran on 5 volts, it would send 30 volts through the board
fair...
quacky quack
Ay
I hate to bring up a mood killer but has anyone lost their passion for hacking before, this has happened to me multiple times and i come back to it the work just gets tedeous sometimes and i loose enthuziasm i dont know if i should pack it up but i dont want to because i cant imagine what else id want to do its just not like how it was when i started
if you spend any time programming or on the command line, that symbol will quickly become your favourite symbol
take a break
burnout is a thing that exists
It sometimes comes and goes, but I always stuck with it. Even when I don't have access to a pc, I've spent hours inside of nano on my phone coding away.
Idk i think tbh this all started when i tried to start focus on getting a job before i did it just cuz i wanted to learn now i want to get a job but i think thats wrong mindset. Before i was hungry for knowledge and i just want that feeling back tbh
honestly just sounds like burnout
go outside
touch some grass
come back to thm in a couple weeks
So hi
I have ADHD
And before I got diagnosed, yeah this happened to me big time. I was doing international CTFs, I was working in pentesting, and the combined experiences, plus my inability to make myself actually practice for CTFs and resulting negative feedback loop, made me burn out HARD on hacking. I honestly thought I wasn't cut out for it.
Took a break for a few years. Actually got diagnosed. Got on meds. And then I realized that, hey, I can actually do this thing. Do I go out of my way to hack on THM, admittedly no but every once in a while I pop on and do a CTF, and I tend to stay up to date with news and whatnot. I also have a bunch of other things going on with university, so that is a contributing factor lol.
While I'm not 100% sure I could do pentesting as a job, I still try to keep my skills sharp, and I've got a security analyst internship lined up for the summer.
(Also, this wasn't just hacking I was burnt out on. School, compliance, development, a lot of shit.)
Is today an essay kinda day? 
No matter how much you learn, there's always something new to learn. Perhaps red team penetration may suit you, instead of lofing around waiting for an attack, be a pentester. Cleverly find new ways to to exploit instead of waiting for a system that's already exploited to try to create a patch for it
i didn't want to say it lmao
No, I just tend to write them in response to things ๐
I regularly hit the character limit when posting on LinkedIn
this is called burnout and is totally normal
(Also I'm not saying you have ADHD, I have no idea what your day to day is like, this was just my experience)
I can provide you links for bug bounty programs that pay pretty good cash, if interested
as a warning, BBPs are a good way to get burnt out as well, lmao
hundreds of other people fighting to find things first and pickings may be slim on popular programs
VDPs are often more fruitful if you want producitivty over cashflow
(bounties are great tho)
Whats VDP?
No i think thats my problem focusing on it for money and jobs ive turned it into a chore instead of a hobby
I think this is influenced by the imposter syndrome, while it is really an annoying feeling you have to remember the road that is yet undiscovered for you. Try a new field within cybersecurity or IT in general. I think we have all felt this, but we are in this together. Stay curious! :)
Vuln disclosure program
technically a BBP is a type of VDP. Just means vulnerability disclosure program. But the disctinction I meant to imply was programs that pay bounties vs those that don't.
Man I have had ADHD since I was a kid and it always caused issues. Recently started a medication for my fibromyalgia and my anxiety and BAM. Suddenly I study every single day across 5 applications + what I do for work to build tools + gaming + watching shows finally
programs that don't pay bounties will have more pickings and less competition normally
First time in my life it's felt beneficial vs horrible
LEGIT YEAH
So vdp is more about just generating the report and not focusing on the money?
A job is what you're required to do to survive, but bounties are on your own time, pick and choose which you want and still keep it as a hobby, just onr that pays
I started when i was 15 and im now 19 i think its also demotivating because cybersec is so vast u cant learn everything u always feel behind
pretty much. The DoD for example has a pretty prolific VDP where sometimes they'll pay out for bigger issues but like 90% of reports are unpaid
You have the greatest advantage of any field friend. Youth. Don't feel demotivated. Many folk trying to break into CyberSec are twice your age
other than the DoD one, most VDPs have less competition because people want monies
And anything tech related often includes a lot of unspoken "agism"
Like heck before I got diagnosed I was UNABLE to force myself to do ANYTHING
Dishes? Lmao nah
Housework? Only if my roommates reminded me endlessly
School? Thought I was gonna have to drop out
Work? Ha, between the ADHD and having ZERO interesting things to work on I was like the least productive person ever
You cant be an expert in everything, it is so vast, just learn what suits you and try to stick to it
Also, if you're participating in VDPs on sites like Bugcrowd or H1, they can lead to more/better invites to private bounty programs down the line which have less competition as well
Thanks for the info!
Gave +1 Rep to @molten sky (current: #77 - 78)
Yeah, its the imposter syndrome. Its when you feel like you have learned a lot, but there is still infinitely much to learn. As much as we all hate this demotivation, we have to hit it with all our might and move past it. You have been learning this for years now, you are the prodigy. I believe in your strenghts, you can do it!
movin up in the ranks
I'm also usually more quiet about it because employers are uh . . . not the kindest folks to those with ADHD, to put it nicely.
Eh, you learn to cope. It's nothing worth talking about.
Tbh i probably have adhd but over time ive just sort of had to force myself to live with it im not diagnosed but i do find it hard to cocentrate or get things done i just have to force myself and i went from a very lazy person to a pretty productive one
at most maybe ask about flexible hours but i wouldn't ask for like accomodations or otherwise mention it (personal opinion)
I have stress jobs when I technically have anxiety/depression/adhd/few injuries/headache condition.
None of it is allowed to impact me, so I don't mention it.
some companies don't mind flexi
Exactly, other ways to set yourself up
I wouldnt say it isnt worth talking about, but it is something that you just have to deal with
I feel like there's a level of nuance in the sense of "What do I need to do my job?"
Many folk make it their "identity" though
isn't worth talking about as in it's not worth trying to get special treatment for it
At work. Had a dude call off because his finger was hurting, the other manager looked over at me who was working 1 handed in a cast and laughed lol
also wouldn't mention it during interviews/hiring
We work on laptops
Remember that you dont have to overdo stuff. Take a break just for yourself - a week, a month perhaps. Come back to it when you feel like it. When you return, you will feel more free and maybe regain the motivation. :)
Dude called off for a sore finger
Yeah good point, if its bothering you this much maybe seek a therapist ๐
And honestly some accommodations can be beneficial for everybody, not just ND folks
it's my typing finger!
I agree and I tell some employees to get accomodations.
But there is a real reason for it, and then there are...well people who don't fit well in a team that desires success
I can tell you most IT peeps are ND and still make it work regardless, not trying to invalidate anything here
tf is nd
Neurodivergent
the only nd i know is negligeent discharge
"Neural DIvergent" it's a new trend word
ugh
It doesn't exist
Wait what
why do we keep making up words
ADHD isn't ND. We just had to get hit a few times more as a kid to listen.
How we roll
neurotically spicy โญ
. . . Dude, our brains are literally wired differently are you shitposting lmao
No I'm not. I learned to use it to my advantage and grow within companies.
How are you coping with the trauma my dude XD
Everything in this world is made up.
Technically, I'd say very successfully.
Great ๐
not denying the existence of things, just that the constant changing of language because words hurt people every 3 months gets old pretty damn fast
Everybody is unique in their own amazing way
the underlying cond is obviously a real thing
But yeah just try to make your own brain work with you instead of against you in whatever way possible
That hurts, could you rephrase that? ๐
I use specific music with isochronic tones, avoid certain stimulants, use other stimulants, meditate, and manage serotonin addiction.
Most people who have ADHD want to do nothing to moderate it is all
weird. I just use music that sounds awesome
Gosh darn kids with their neural networks and neural divergents grrr
honestly most people i know opt for caffeine before anything else
Cancel culture is a pest imo and im pretty damn left if i dare say so myself
trying to avoid medicating
Ai is stupid XD
I do like the caffiene...
not 100% sure what you're saying but i think we agree
I think that's a huge generalisation. What do you mean by moderate exactly? ๐ค
That everything you say can hurt people and people think thats not politically correct because of that, ypu cant please everyone lol
oh yeah we 100% agree then

