#general
1 messages Β· Page 65 of 1
I like having the cores for vs code etc
My Windoes vms have 12Gb eacb
Alright cya guys later I gtg now
Each*
what do you use as a hypervisor?
I do that, but sometimes I need a full editor for scripts etc
why I am stuck at level 5
ye
Vmware workstation pro
Re verify
thx need to try it. do you use flare vm by any chance??
Gave +1 Rep to @sick lance (current: #2 - 2031)
nah I kinda used to it now
I do. π
probably not a bad idea to shove a codium on it
oh wow can I ask you a question about the installation process?
did you have any difficulties with the ps permissions for Set-ItemProperty? Cause I have these, even after I set them according to the guide
No, I turned off the av and it was straight forward.
I used Terminal emulator though
Multiple accounts...
Better discord π or? it does look like they have access to it though...
probably
ok thanks, gonna try this one
given their roles they shouldn't
yeah
that's why my train of thought went straight to better discord
you do realize that third party clients are not allowed by Discord ToS, and that it's a bannable offence here, yes?
I hate when that happens lol
what's third party clients
π€¨
a client made by not the owner of the original client
third party*
BetterDiscord, for example
I didn't even knew about that
some owners allow third party clients like reddit...but not discord
oh
Yeah
can I send a track here?
what?
eh?
chill guys I am trolling btw , my friend is god not me
train tracks can be dangerous. please do not redirect them
mmhmm
oh the trolley problem
but I'm talking about music, haha
jots things down in the mod notebook
Mod OSINT. a terrifying thought
but I want to ask what are there in these channel
advanced sorcery
oh we have notes on everyone
naani
It's impossible to view messages in hidden channels even with a third party discord client, so because the new message icon is showing it can't be an external client
so all other channel are for beginners
but not when u get god level right?
when you get god level you get access to the advanced channels, yes

a fair point
I think there should be more 2-3 level coz god is easy now
advance is not worthy of god
takes commitment to get to god
I have seen many get god in 3-5 months
You probably could,
nah I am being practical ofc not in weeks
There is enough free rooms and rooms with extra points.
You'd probably be flagged though for auto-cheating.
I mean if you answer dump then yeah
It's 20K points right?
that's why I thought it would be great idea to have each flag unique
Yeah
no copy from others
Dynamic flags are tricky.
or getting changed every 1-3 months
wanna know why
I wonder if they keep notes of our techniques and exploitations used for challenges.....
THM?
Muiri had tried on a room once, but it required an external service
yes
Yeah, I remember that one, needed to E-mail them.
nah, but you can
requires infra to know how the flags are generated, and where they belong
respect for muiri π
note to self: should not use attackbox. never know who else may be watching
logging of a dynamic cluster is a pain in the butt, so I doubt they do it
I thought they did that in redteamcapstone
I mean they monitor usage of the attackbox
Good note, and it has been noted π
Red Team is different, you need to place your Username and unique ID in a file.
but does it mean collecting, storing and analyzing all event logs?
oh
mostly CPU, memory and network
or it's more like passive (or active) detection of something that's outside the term of agreement for the AttackBox
The file is read, and then the flag is E-mailed to you, it's not dynamic, they can just check if the account has obtained the flag was legit and not copy/pasting
if the attackbox starts attacking outside the THM network, that probably gets flagged
and the user may get site-banned
it's a Ben, hide!
Site banned? Not account banned? I mean, surely not just a simple IP ban?
account banned, same thing
none of them are mine π
More or less just making sure it wasn't just IP ban. That's all I'm saying on that topic
atttack boxx ugghh
I don't think THM disclose their banning poilicy, but you look hella sus right now.

aint mine either, but I can spin something up if you want π
the flag static, indeed, but they create and terminate machines, and in the case when they are able to read the terminal logs of every AttackBox they created, then there must be a separate storage and a way to extract them in real time
because when a container dies, its logs normally dissappear
it's not containers
hoi4? what a nerd
Whay if the user doesn't use an attackbox, but their VM?
hoi4 is based
too smart for me
anyway see you all later
Nah. must be an age thing.
Hi Ben π
to much management for me
we played Diplomacy at lunch at work a long time ago
~600hrs but only 36 achievements? for shame
Then they have to connect to a VPN
So these are VMs? But what do they run on?
AWS I imagine
π¦
AWS host the VM's.
40+?
with a bunch of VPCs to manage the access
eh, not yet
Oh so EC2 instances with buckets, probably... thanks
what you'll consider peak age
meh I used to play mp and mods
dyam I got the motivation to be a god level for that advance channel
iT dEpEnDs
but I think it's the time when someone's in their best capacity, which still can't be completely measured by anything
How thoroughly do you take notes of your rooms and what tools do you use?
Depends how well I know the material.
notes, screenshots and a I use a terminal recorder.
you mean you dump your console commands?
Yeah.
cool
what tool do you use?
and here I am copy-pasting like an idiot
googling led me to https://github.com/asciinema/asciinema
That tool.
Asciinema can record the terminal, and allow you to copy and paste from it.
that one had issues with wayland, no?
I want to create a knowledge base of my rooms in Obsidian, but it looks so scary
you should use joplin is easier
obsidian is just too much
I don't like that it uploads to a third party
looks like Notion to me
I want to use Obsidian to create a node, its visualisation levels are through the roof
You can save it locally.
it would be great to have notion and obsidian linked so that we can use both of them
without import/export
Mine is just a circle 
ur a maniac
but I think it's possible
nah I am kinda used to notion butt I like obs ui
what do you do in notion? knowledge base?
nani
notes like methodoly, process , enum etc
I just want to understand how it is possible to get used to notion
and can't use both in windows host , defender detect and delete it
using it for 2 years now and still can't, but it's very flexible
Notion is good, until your notes are deleted, or you turn it in to a C2
deleted how?
for a ticket board it has very little room for SLAs, analytics, metrics etc.
maybe they can be integrated through some third-party services, but I haven't seen any successful cases yet
@pallid lotus --> https://www.youtube.com/watch?v=1M2UzQYwbxE&ab_channel=JohnMalecki
I Tested Viral Drink Pouring Table
I build a table that can pour me a drink.... but it doesnt come without some hiccups.
Check out THUNDER LASER - https://bit.ly/JM_ThunderLaser23
Grab some Shop Shades - https://bit.ly/ShopShades_YT
Check out the Servita Bartender Kickstarter - https://bit.ly/JM_ServitaBartender
Want to see more crazy buil...
Wait, notion deletes your notes?
They can do.
Ask Meggy. 
same with obsidian, getting your notes deleted while you're in the middle of your cert exam 
Wasn't that Spooky? 
yup
oh thats rough
Muiri has that too, no?
moved from obsidian to trilium
but you can host your node locally
yeah... that's how it got deleted
It's plain md so AV can see it and wipe it
spooky got their notes deleted by windows defender
backup to github or similar.
problem solved
For their OSEP exam.
or... trilium which encrypts your notes
If I fail this exam, I'm going to be so mad...]
what happened?
... I hate these questions π
They're really bad...
windows defender thought it was malware and said "YEEEEEEEEEEEEEEEET"
big time
I asked my friend about advanced channel he said it just a normal channel like general but with god levell nothing special
losing motivation
I thought you were already 0xD?
you get access to a lot of fun talks though
0xG
oh thx
Gave +1 Rep to @sick lance (current: #2 - 2032)
ofc my friend is one of the first god in this site
Bold claim.
how many time I told you thing which turn out I don't lie
did someone say trilium
If you say so.
Yes!
i love trillium
so so good
although i am a bit jealous of the obsidian canvas feature..
Itβs less restricted so you can talk about topics not allowed in here
I am also testing obs
slay
ROFL
This is third year π¦
happened to me I was god in maths, physics but very poor in theory exams like history etc
I could graduate with a BsC this year π¦
here's mine, all of those unconnected dots are really funny
how unconnected
Doesn't Physics have alot of theory?
i have a lot of unconnected notes
but with logic
And history doesn't have.. Logic?
history is memory 
i guess physics is a bit more intuitive
not modern historical science though
I think we find interesting topics or lessons easier
what
Humans haven't made the most....logical decisions 
ever
but generally, on average, in history a cause comes before an effect
History is too human for logic
if we could prove logic In history there would be no wars
history*
no they are just trollers
not real
yes and there will always be those who believe the mainstream consensus is a pack of lies
deep down they know they are wrong but they won't accept it
no, some if not most are true believers
I think it comes exactly from this. First people get dissappointed in mainstream consensus, and then they're in the pipeline towards Ancient Aliens or flat Earth
I told you they will never accept it to person , not even accept it themselves but they know they are wrong
There are a lot of flat Eathers who have proved itβs round and accepted it.
these theories base themselves upon blurring the concepts of "right" or "wrong"
and for example even if someone proved to the flat-earther that the earth is round, well it may not be enough
yeh π€£ its always funny to me when flat earther try to prove that earth Is flat but turn out its not
there's actually flat earthers that used 20000 USD to prove that it's flat and found out it was round
I think I have seen video about that or something

btw I am flat earther
I'm donut earther
am I weird? I am currently eating chips with chopsticks
I like the idea of the universe being a hyper-torus
chips as in pringles?
crisps*
yeah, food like pringles
these are with the taste of chili mayo
yeah, but who cares? also better for not getting fingers all icky
eating those with chopsticks is kinda hardcore
yeah, I am in the middle of LoL games
don't want my warwick jump to get messed up by sticky fingers
ha
Hii
Anybody know about hacking and networking
I want to learn about networking any budy help me π
thm is a good place to learn 
Ya but how I learn fast with expert experience
Our content was written by experts, itβs the same as having one of then with you
yeah the rooms are a mix of theory and practical
so you get experience doing the things
Hmm π€
and if you don't understand something in one of the rooms, there are plenty of experts here who can help
spend more and more time , that's the only way to get exp
Γk I research
I feel iv learnt a lot In the short time iv been actively using THM
same
Hack the box is good for beginning?
also find it enjoyable, doesn't seem like a chore, feels good when you finally get your code to run or whatever it is your aiming for
it would take 2 year to be able to start there
New wifi is insane
Yeah for sure! THM is fantastic as a place to learn
iv not tried htb but from what I've read thm is more beginner friendly
Much higher skill floor than THM and more expensive for their academy content in comparison to THM. Youβd be throwing yourself in the deep end with HTB, not the most advisable option :)
THM is way more beginner friendly, HTB can leave you scratching your head for a while as a nub. Writeups and retired boxes are your friend if starting with HTB
thm pathways are also great for those who don't know where to start, get a feel for all the fundamentals then take the later paths that interest you
even then u can't start
Thanks for your great opinions π
also new content seems fairly regular which is nice even if I have more than enough to be getting on with as it is π€£
Really enjoyed the new content so far. That http desync & smuggling room was a fun one
56 hr no sleep
WHAT

dude
more like 450k
GO SLEEP π
literally not braining
"what if "
but with real real user its 20k
I think more like 120k
ur rank must be 120k that why
what's yours
12k
i see
it must be still low in soc eng
I think thereβs a lot of inactive users, itβs not necessarily hard to get to top %βs if you put the hours in and I think itβs pretty easy to stay top %βs too even if inactive
but even top 1% is not best enough
Iβm at 5% after a couple weeks of hammering it out
yes
Top % doesn't mean anything.
yeah
People putting their THM rank in their LinkedIn says otherwise π
If anything you can have how active you are, to the people around you.
iv only just made it into top 100k 
but to beginner its their motivation
That's also why THM have around 2k employees.
real game is after top 1% trust me
my motivation is knowing stuff I don't know now 
I tried to make custom theme
looks relaxing
and made new shortcuts to stop using mouse , finally I love not using mouse that much
i have a flu and i feel like ****, my only comfort is that i have windows fundamentals 2 and 3 left , then im done with 1 thing. and onto the next
hey man I found your article it seems
https://medium.com/geekculture/optimized-note-taking-9d663eec898c
looks very similar this pic over there. so you're not only top 1% THM, but also a content creator?
Lucas Soares, huh
here is the conf file If anyone want to try it https://github.com/vadaysakiv/terminator-terminal-theme
noooooooooooo waaaaaaaaay

don't forget to follow me
not giving up that easily, are we....
gold
flu gang π
everyone join it, noone likes it
yeahhh, it's been day 3
get well!
feeling better
since its international womens day, this is for u
outside of former USSR it is rarely celebrated, even in Warsaw Pact
day 1 was full of sleep cause I was on like 40C fever π
Thz
it's celebrated in Denmark, we are doing a demo today actually
even google is advertising it
that's true, but there aren't many countries with official holiday on this day
even in Eastern Europe
demonstrations are held, unlike the majority of countries that have official holidays at this date 
we have an official holiday here
that's wonderful
we have nothing like this in Poland
its not official, but since im sic and wont leave the house today my wife even in the morning was "Where are my flowers?" π
π
we actually call it international womens fight day, as it's because of how we faught for our rights
I have a question about a problem I had on a test and got it wrong, I would like to hear your opinions on this. Anyone willing to answer?
ask ahead
Which statement describes the most precise difference between a public and a private encryption key?
A. Private key is widely used in symmetric encryption, while public key is used in asymmetric encryption
B. The private key is known only to a specific user, the public key to others
Keep in mind the question mentions "most precise" and not "the simplest" difference. Which of these would more suit it? Because I know Private key encryption is also known as symmetric and vice versa with public key encryption. Though the B answer is also correct, but I find the A choice more precise.
I guess the logic here would be that you can use private key in asymmetric encryption as well, and there is no clear data on how wide this is used in both methods
so I'd say it's a distractor, a very clever one
Yeah, that too. I found these types of questions inaccurate because the answers can also include some nuances that also could work apart from other answers.
But in this case which one would you have picked?
tbh I'd pick A and lose
I answered A, but I am ready to explain that my answer is also correct in its own way.
hahaha, it's googling that helped me wrap me head around it
but! these questions for tests normally have to quote academic literature, and fresh one, too
I think that A is more precise because it goes more in depth in the definition rather than the B answer. But thank you for your opinion either way! :)
there's a trap, because in Symmetric encryption, the private key is known to multiple users
no, A describes these keys in broad terms
and for B you have to know the process
it's a wierd question and I think the examinaer was trying to be too clever
it is strange why this question ended up in an exam
Do you think its worth to submit an appeal that A was right aswell or do I just leave it be? This point doesnt really change the mark, but I would also like to know their opinion on this one.
Homework?
might be worth the appeal
Test
post exam
It wasnt really an exam, it was just a test
You got stupid questions too then. :kekw
Yeah, I figured
saying that B is wrong because of the symmetric loophole
I assume you use asymmetric encryption to get the private key to then use it symmetrically?
Thank you guys for the opinions, it really matters to me! :)
uhm what
hydra, I have to write an whoami 
I worded it weirdly. I meant would you first use asymmetric encryption to securely exchange private keys and afterwards switch to symmetric?
How far'd you end up getting? I've nearly got to second stage I think
anyone wanna collab on some room or just chat about? DMs welcome.
Not too far.
Is it still active?
I think i got frustrated and left doing it
Can anyone tell me which directory contains the source code of linux commands
Note: I am not asking for binaries xD
My Malware-bytes expire soon π¦
Thankfully they do student discounts, so I can grab the premuim and the VPN for Β£24.99
Year or Month?
Year
Works out just Β£2.08 (around) a month.
I know, I know, I missed out in the lifetime pass because my bank gave me a 5 year code.
My bank do not have lifetime because it auto-renews every year
I'm no longer with the bank that offered it π¦
I don't think I'll ever switch banks tbh
I had to, because at the time RBS were closing accounts in my area for no reason, and they wouldn't restore or disclose the reason why.
Introduction to Cyber Security and
Pre Security
weeeee - gogo next π this stuff is pretty interesting
So I switched before mine could have been closed.
One of the people I spoke to who got their account closed had to wait 8 weeks for the recovery of the money in the account.
these 2 are done
Glad you've been enjoying the series, and hopefully more great things to come
Good spots to start
π i agree, tryhackme site is a Treasure trove.
Wsg people
im trying to learn as much i can so hopefully by the start of next jear i could change the field i work
Hii
Solid timeline. See if you can work in some certs along the way
I want Learn about networking guys and budy please help me
Well, part of what THM does is indeed networking
Give me any source π
THM/Google/YouTube
Ha but I want to learn fast with expert expertise
Ya
Any budy is free I want mentor
CyberSecurity, even networking, is so massive you don't really have mentors outside of paid classes/good friends/ senior associates at work
The time involved in directly teaching all of it is kinda nuts
im looking at some basic comptia security, maybe basicas like a+ and ccna, or cycs+, but these buggers are expencive
I literally got started on YouTube vids and branched from there.
Pricey, but skip A+ IMO. Net+ and Sec+ have more value and A+ means you know how to turn a PC on and off and clear a printer spool error.
CCNA and CySa+ are excellent
i would love to get knowledge first and let my future employer pay for these but i guess i need the investment into cert first to be able to get a job
Really depends
But generally if you have no degree, being able to show projects/portfolio that represents your skill and knowledge and a few certs is key
That or knowing someone in a company already
Or working in IT getting into being a Network Admin or something then sliding into it
Lateral moves
iv worked on construction last 10 years and looking onto cybersecurity
xD there are no connection sadly
but using sites like meetup and constant learning updating cv (even professional help on it would be good), 1 or 2 certs and at the end of the day its a 1000 mile journey not a sprint.
If you want to get into security operations/engineering, then Comptia A+ and Support role is a great way to begin to work on your portfolio
mhmh
cause certs normally get you through screening, but after the screening you need to go through a panel interview, where you need to recollect practical experience
this is why i like tryhackme
Hi!
Hii
oh but it's not really practical experience. after you follow whatever path you choose and learn it, you need to go out in the field, and make a name
freelance, bug bounty, research, volunteering etc.
You started SOC1 course yet?
i started 3 days ago, i finished Introduction to Cyber Security and Pre Security, goin over Complete Beginner atm, next i thought soc lvl1 or cyberdefense
SOC lv1 has a lot of great info in terms of understanding the mindset.
Ultimately my goal is to leave no room unturned
I'm rounding up web fundamentals, complete beginner finished, and going to follow-up with Defensive Security because it includes malware analysis
14th day here
Nice! Keep driving forward
time started flying after I joined thm hahaha
Do you play with tech in general?
Agreed. I juggle THM/CodeAcadamy/DataCamp/DuoLingo/Mondly
So a solid ~2-3 hours a day vanishes
Now that I have room I'll probably dig out the Arduino as well
long story, easier would be to explain in voice
your skill and knowledge will be more important than volunteering etc during an interview
yes, but volunteering for the right organizations in right activities can improve the necessary practical skills
I am human
Not always
For the job itself maybe yes
Without practical experiences to talk to, even being able to recite everything verbatim isn't super impressive
It's why experience trumps degrees
But lots of companies do matter about other things too
volunteering is generally good for the CV
I've been teaching people with MBAs how to do things, I have nothing.
Even if you have a lot of certs, a degree, some experience as a volunteer, but lack basic knowledge I doubt that this person would be@hired
They "know" more, but they have no understanding of applying what they know.
ANd the knowledge they tend to have is the core muscles. Extremly strong main groups of muscles, zero strength in the stabilizer muscles.
Which if youve ever done sports you know yields poor results.
THM and a cert or two covers most basic knowledge needed
Especially for entry level or pseudo cyber security jobs
Especially if you branch out into the other sides you bump into
And if you follow Sec based youtubers
Doing a room here and a cert does not mean too much if that person cannot describe their skills during a technical interview
That's just word smithing
Proper wordsmithing can make a hamburger flipper sound like the most priced member of leadership
I know, I've taught former employees what to say when helping with their resumes lol\
Homelabs are the best to test your skills
You can have every cert in the word, but without any skill that comes with it these mean nothing
And displays you know how to troubleshoot hardware usually.
Hence...the practical experience he mentioned
Bug bounties, volunteering
The things that will give them experiences to talk about and connect to knowledge
That's the whole point I mentioned the MBA folk
Most come out with all this education
But completely incapable of executing on it
??
Why do people do this
Spooky
Delete there questions
Glitch in the matrix man
I always set my powershell colors to black/green lol
Matrix ruined me 20 years ago
@worn summit check out the Linux fundamentals
nah idk how to ask my question properly lmao
Itβs straightforward
Just ask
for a task in class we need to do a Tryhackmeroom, where we learn cybersecurity in linux
Not poorly
and i was wondering if someone knew a good room
linux fundementals isnt really cybersecurity related is it?
i already checked that room but idk if its good enough
It shows you how to use Linux.
In theory, you can do many of the THM rooms in Windows.
He mentioned βmaking a nameβ in the industry by doing that, but thereβs a ton of people that simply pretend theyβre doing stuff, but nothing comes with it
I already know how to use linux, but it has to be about Cybersecurity related things in the tryhackmeroom
and i cant find a good one
A ctf might be good for you
I get that. But they are also optimistic and looking in at a new industry. They don't mean famous, they simply mean to have value.
However, if this is an educational task, you should aks your teacher if they want you to use THM.
YOur teacher from an external org is having you do a THM room, and gave no direction on a specific?
I'll copy paste it, sec
Find a nice Linux room on tryhackme that has to do with Security (the fact that the VM is a Kali Linux is not enough, it really has to be about the security of a Linux machine or attacking a Linux machine). So you can choose whether you opt for an offensive or a defensive room.
its translated from dutch so might be a weird translation
Linux priv esc
huh
Many tools that you have access too use linux
this one looks nice i guess
As in, learning privilege escalation techniques for Linux machines
Lots of rooms on THM about it
No not that lol
I mean the teacher just handing off to THM
Feels like when a teacher partied too hard last night and just has the class repeat yesterdays lesson while they nap
They could be part of the educational plan.
Didn't know THM was integrated like that
THM have personal, business and educational accounts.
for our exams there's a listof tryhackme rooms we need to " study " π
Do you get a college degree from the school?
Yy
Really, we shouldn't help users who are on plans that aren't personal.
Fair
I didn't realize though
But I think recommending a nice room isn't helping
In a bad way
If you are still stuck, ask your teacher for clarification
If we help it falls under cheating
But if you're tasked to find a room and do it, then report...
Rule 5 - No Cheating
Cheating of any form is not allowed. This is not limited to asking for help with assessed schoolwork or exams.
If it's an actual course, ping your peers as well who are doing it.
if u guys see this as cheating then idk
See what rooms they each dipped into
It's not really up to any of us as individuals. We have to follow rules.
I've been in enough trouble as is

You could always use google
I wouldnt ask it here if i didnt use google first π

There is using google, and effectively using google
okay
Please do not post IP addresses here
Hello can sombody maybe recommend me a room that uses linux and learns me more about security
Please do not mini mod. Enforcing rules is for moderators, if there is someone breaking a rule, ping a moderator
I wasn't...I was explaining why we can't help.
Is this for a class? π
Swear itβs the same dude lmao
No just for myself i want to selfstudy to learn more about security
thats not me
Moderators need to be made aware of users breaking rules.
This is so that we can note and identify users to inform other moderators π
Got it. Was just trying to be friendly
friendly..
but okay, i'll look for a room myself. thanks anyways guys! didnt know there were strict rules like that
does sombody have any recomendations for me
Hi, I see that the 'thefindcommand' room has already been removed from tryhackme and it's not possible to join it anymore. Is there perhaps an alternative to this room?
Pre-security, introduction to cyber security rooms
I mean paths
Sadly, there isn't π¦
THM having issues right now?
Not for me
My VPN times out every 2 minutes, and goes slower and slower up to the point where it disconnects
ah im not on vpn so
My other tunnels work fine
It died again. I'll continue later, or try cycling the box
oh wow
Hello! I'm wondering why the Attack box is recommended over the web based Kali Linux machine? It seems like they both work okay.
Attack box is updated more regularly, at least to my knowledge.
Does not really matter which one you use tho.
I personally reccomend using your own Kali VM
The attackbox has been designed by the tryhackme team and the tools are hand selected
Yeah i prefer my own machine too
I use the attackbox at work π
Our PCs are ancient and I don't have admin powers π
Usually a safer option, since most orgs don't want someone using a local machine full of hacking tools or using a VPN out of the network to somewhere else
Attackbox has materils also (pcap, images etc)
Our office style computers are from 2005....
Our CCTV units are brand new and customised. I have admin powers on them.
Not sufe if kali box has it
Own machine > Attackbox
IT would have a fit.
Ohhh for doing thm
I thought for your work
xd
hi
Using you main work PC for hosting hacking tools and connecting to a network of hackers would be a horrible idea.
no doubt someone would be marched to hr
Hello. π
It would be. Especially as my organisation had a major cyber attack in 2021
how to learn pwn and re in tryhackme ?
Hi Scrubz π π
If I used my own VM at my old work.... let's see how many teams will be on my ass:
Info Sec Analysts and management, Licensing, Desktop Support management.... list prob goes on
I've already been marched to HR once.
I was scared you werenβt joking. π
Well you'd better be on your best behaviour so!
Hey, where can I ask questions regarding ip gathering ?
Unfortunately they had a cyber attack.
Not sure what, they didn't release any information!
Not even a damn disclosure? Jesus....
The complaint got thrown out.
Found out it was all lies
Happens all the time everywhere, so welp. Your companyβs not broke and still operational.
I do have the resources to use my own hardware, but I have just been using the Web based stuff and was curious about the difference. I appreciate all of the conversation! Looks like there are some different views about it. If you are using your own hardware, it would be best to segment your network and isolate that environment correct?
That's good news then
@gentle adder If you're still floating around here, please message me at your earliest convenience in regards to the debugging.
Just said no sensitive information was taken.
Speculation was ransomware
I remember when we (desktop support) had to isolate a laptop and.... y'all gonna hate this... info sec team called in a certified CEH to do analysis on the laptop 
Why
Can we talk on private ?
Okay
Parent complained I put their daughter at risk by not allowing them entry to the car park. (Didn't have a permit, gave them options with public car parks on our safe route where you can request a chaperone)
Not exactly putting your daughter at risk
Not anyone in digital forensics... nah.... CEH... in the US
Well you did all you could to facilitate then
That's exactly what HR said. I followed policy
Tbf parents have been on edge this year.
Don't blame them, a student was murdered here last year
Yeah it's fair they have concerns but you can't be responsible for everything. It doesn't seem like an emergency situation or anything like that
No we can't. The review has concluded our department went above and beyond to assist the police in scene guarding, evidence gathering etc.
Nothing we can do.
The only thing the review said was we ideally need more staff. But that won't happen
Sounds like you did all the right things then π
Yeah that's the main thing
We've learned some lessons from it for sure tho
can you explain to me what ACME IT SUPPORT is?
AS long as it improves how things are done and makes it a better environment, then it's a great outcome
why ACME of all names
hey guys what do you think what role tryhackme play in the life of a newbie of this field π
tryhackme helps you upskill π
lots and lots of paths and new learnings
tryhackme is for you to gain technical experience without being in a cybersecurity job role
My name?
not only
Acme IT Support is an example website on tryhackme
yes, there are lots of rooms with ACME Support
Yup
why Acme
yeah idk
it's the favourite of Willy the coyote π
is it real world experience?
Nope, but sometimes, close
as close as it gets really
Like most things, imo, thm teaches theory and practical applications but in the real world you need to figure out how it applies
ello
some of the rooms can represent 1:1 how you would hack into a machine in a real environment
@mossy river
Like it gives you a damn good start if you're learning but you need to be able to continue learning and learn how to apply knowledge, also depending what you focus on impacts it.
I've focused mainly on Linux and am pretty good but pivoting and windows machines are a work in progress.
In a practical environment you may encounter Linux but there's lots of windows environments so the only limit of thm is your choice of rooms and ability to adapt and apply what you've learnt
Whatβs this
its a vpn to stop ppl getting hacked
Youβre such a liar lol
Go on then, whatβs the VPSβ IP address?
wym
Thought so.
Did you write this executable yourself?
Virustotal flags it as detected by 35/72 π€
And it talks to discord, never seen a VPN do that
Yeah I figured π
Nice one from discord, they noticed me its a scammer
I know what it is, just thought it would be interesting to talk to someone distributing it
before you ban them, ye?
100% guarantee itβs a 13-15 year old who joined a token scammer Discord
tbh they probably left already
https://www.virustotal.com/gui/file/f863748884bdbe63185147b20fdca62458b99af81d522f210f8c2aac1071a97b/behavior if you want to see its report, is the behaviour thing new?
VirusTotal
@hushed flame You still here?
I'd never seen that built into vt before albeit a while since I used it
I think they got the wrong target audience
Trying to βhackβ people in a cyber discord is hilarious.
Reported him to Discord β
I am such a professional Jabba taggerπ
Didnt saw that message π¦
Honestly I accidentally downloaded it to my phone but I might go analyse it and see if I can find anything of interest, I've enough free time π
Thatβs too funny
:hammer: dripzy4#0 has been banned.
had some crypto libs in there it seems
Find their server and report it
That's the intention
And if I find a webhook, I'll report it to discord in case it's on another account
What a pleasant interaction
No problem
What a guy
Whilst also having all of his socials in his discord bio. Not the smartest, unfortunately
Bring back the Skype days, l33t names and bios and not to forget, dark comet rats being thrown around like itβs going out of fashion
They were the days π
I'm that old I remember AIM!
(skype isn't even that old...)
AIM is
You got somwthing older?
ICQ!
Oh yeah!
well there was a time before chat programs... people had IRC and before IRC, they had usenet
and before usenet, they probably had to call someone
Collect call
what was even more funny, is I first thought I had blocked the person
Pager
Good, so Discord is working
I had to look it up, they had email before usenet and then before email, you had to call (or maybe you had to use your HAM radio)
Doesn't appear like that on mobile
Just shows the messages
Correct
Interesting stuff
Soon
when I went to college, I would use "talk" on unix to talk to college friends
College is before uni right?
When I was at secondary school we used to use the windows shutdown with a message to communicate in class
Oh. Mb
nah its all good
y'all say uni, we say college (although we do have official definitions for college / university)
Plus it was funny to us back then because the PC would shut down and they'd lose their work
Looking back at it, not funny
Gtg watch f1 highlights. Bye for now
Someone did that to me in secondary school and it didnβt save my homework that I got to school two hours early to do
anyway, in college (I was 18), there was a friend who I used to use "talk" to. I think the guy had a crush on me, he was a nice guy, then he was like "have you heard of irc?", he introduced me to irc and then we kind of didn't use talk anymore and I didn't see him on irc after that. I would see him once in a while on campus but we had different classes and what not. I hope he did well
i keep mixing up some of the osi layers :S
Awww
That's some dank stuff right there
Please Do Not Throw Sausage Pizza Away
nah, there are a lot of people who will come into your life and leave and its ok
I am not people
ok besties will come into your life and leave and its ok
All People Seem to Need Data Processing
sure brits would do it the other way
im using All Ppl Seem To Need Data Prossesing
Funnily enough I was taught the sausage pizza one at college
in the US, we do from bottom upwards because the only way to go is UP
Please Do Not Teach Stupid People Acronyms if you want to go the other way
Jabba beat me to it
Application Presentation Session transport Network data link physical
Is the only way
I mean if just bruteforcing the knowledge works for you, go for it
I make drill songs from the knowledge I learn
Never Eat Shredded Wheat
Nerddrill
Brute force always
Not always the best method
π΅ I ainβt gonna brute force, donβt call me hydra, draw a web from my nmap, man like spider π΅
I have a feeling it's a py2exe bundle based on strings @chilly veldt π€£
it's certainly bundled python code of some variety
The .exe that user sent?
yep
Yeah most token grabbers are written in python
No Access 
Is there any bug bounty programme hubs (like hackerone, bug crowd) that are very unpopular since like any programme on hacker1 had been reported like 150 times.
You need to work hard to get invited to programs with less people on them
oh okay
Synack Red Team, but itβs hard to break into without specific certs
New account, or deleted and re-joined? o.O
what
I wna join just to be mentored π
Good evening kind sirs
Anyone has good resources/references on working with large numbers of files in python ?
Processing, Extracting text, etc ...
ChatGPT
Well well well
where is catgpt when you need it????
A cat trained on object oriented programming would be better at large and complex file operations than GPT
No doubt
isnt python already the first misstep when you want to handle large and complex file operations
π
Suggestions ??
try nim
so if i find a csrf vulnerability would this count on the bbp, one of the exlucsions mentioned: "Missing security best practices that do not directly lead to a vulnerability"
it has a similiar synthax to python and is way faster
about "complex file operations"... well im not sure what you're trying to do are you just trying to read/write stuff from/to a file? There's libraries for that
The problem isn't the language itself, but the large quantity of files i have to work with :/
The thing is i have to work with a LOT of file paths and extracted text, and i'm having some trouble creating iterators/generators to process those values.
What I meant is that python is a pretty slow language. If you really have to work with a lot of files and speed matters python is probably the wrong choice. If the speed of the program doesnt matter then theres nothing wrong with python.
its here
what
There's predefined libraries for reading and writing to files almost any language. About creating iterators/generators not sure how i can help more as thats application specific and not quite sure to help with that without knowing more about the topic. Assuming from a bunch of files the same stuff has to be done with the file i would write a function for it and add the paths to an array (or depending on the size an own list file) through which i would iterate
@plush mesa bro can you help me
So when you all started out doing boxes how long do you work on a box before you get a hint from some where? Obviously the longer you struggle the more you are going to learn, but I feel like I am so close. I think I have to laterally move into another user on the box to continue. I can see a possible way to get to root, but the current user I have does not have the correct permissions to access directories and files that would be needed to do it. The user I think I need to get is the owner of them. Cron job runs every minute as root.
Driving me crazy.. lol
you can help yourself by deleting your message else you will get banned noone in here will help you with illegal stuff its against the rules (and my ethics π )
Just need help
what's slowing the program execution is having all those values stored in memory.
I was able to increase the speed with generators, and it's working a lot faster than you'd expect.
Now being more specific:
Say if i extracted text from 40000+ files, what would be a better way to process that text than storing it in a dictionary ?
@mossy river
That's what i've done, but with huge ammounts of files the array becomes huge as well, and decreases the program execution speed
Why
i need
Why
Can you do it?
If you tell me why you need it
Someone hacked my email, I want to know this email for recovery
Sure you do
help me
If that was your email, you would know it
Thatβs illegal bud
I'm assuming you're only storing the data you need from the files in memory right, not the entire files (if you only need specific parts)? In that size category I would write the data to a file on disk to not blow up the memory
yes That's my email.
ik
You know there are feds in this server right?
The mods should get spray bottles
Please donβt involve yourself
Just spray anyone who deviates the rules
Makes the situation 10x harder to deal with
what feds
Just got sprayed 

:hammer: ragabhai_#0 has been banned.
Jabba what is the message you get when you get banned
I thought about that yesterday, would that be a 'pythonic' way to perform that file operation?
Say i have 40000+ file paths, perhaps the program can work by storing those paths in a .txt file and then iterating trough the same, instead of holding the 40000+ strings in memory?
By the way, thanks in advance for you help...
Gave +1 Rep to @plush mesa (current: #473 - 9)
might be worth using something like an sqlite database
The reason and an explanation of the appeals process
A database might be overkill, if it's just a fixed list it would be easier pasting them all in a simple .txt like you said and then you can use the classic python with open(...) and then do readline
or read in multiple at once
Oh
Nothing special
I honestly don't know if reading one line at a time or reading multiple at once and then splitting that data up would be faster
anyone have suggestions for pentest report templates?
if those files are on the same path/a few similiar paths you could also just read in all on that path/blacklist a few files on that path or something like that
I assume you already have a list of paths to read in anyways right?
Should add a gif of a cat getting sprayed
You can find examples on GitHub
There's a repo with public reports on github, I worked from that for mine
I know that processing speed depends on hardware specs etc.. But by creating a generator in one of my functions, the program was able to process those huge number of files in less than 20 seconds (Tested on different hardware), when storing values in memory, the process time was huge ...
What do you mean by generator? But nice, good to hear
Not specifically pentest, but Expert Witness reports are also a good format
Basically i accept user input for a path e.g --path /path/to/dir
Then the program walks that path and yields the paths. That part is OK.
After that i have to group those files by MIME types for further processing, hence the problem we're talking about.
The temporary solution i made was storing those values in a dictionary:
text: [List of txt files]
pdf: [List of Pdf files]
The problem is, the more files that directory contains, the larger the dictionary becomes, storing those objects in memory, slowing the program execution.
The previous suggention you made seems to be a workaround for this. Group the types/paths on a separate file e.g. pdf_paths.txt , and then iterating trough that with with open (...)
Btw let's go to #programming
I think John Hammond also demonstrated a more automated tool that pushed stuff to private repos for you to generate a report. Was in his OSCP video iirc
I can show you if youβd like π /s
Hi all, I need to intercept HTTP (over TLS) requests as mitm. My plan is to setup e.g. a raspi which acts as access point and routes traffic through the ethernet port to the internet. The victim would connect to the wifi. The idea is to use mitmproxy as software. Are there any better ideas or alternative recommendations? My knowledge might be a bit outdated
What's this for? THM?
No, actually test/demo setup for my job
Ah, ask your senior then
thx, "did you google" would also be a good answer
What should I do for lunch? @naive violet
Food.
I could have said a liquid lunch.
Iβm having four double quarter pounders π
wow, some time I can't finish one and the chips π
did you google it, is always a good answer π
I actually did ... seems mitmproxy on something like a raspi is still the way to go
I passed my test
yay
Mfer aren't you already a professor? Taking your own tests?
LOLOL Nicely done Berrys π
My radio
Congrats!!!!!!

Toaster: "I scored a 100 on my test"
Us: "What test?"
Toaster: "My own test I created for my class, I passed it"
Us: 
hahah lol
passed
passed. not "got a perfect score". just passed
you still need help? if you need help in scripting tasks i can assist you, iterate through files/lists and parse / match pattern all thus stuff.
made me laugh, thank you
Gj
Your what now?
mini computer that runs debian arm linux... will have fun playing open source games and maybe hacking from it
Glhf
Might be fun to throw a Kali on that, though dunno if all the tooling exists for arm
not seen kali for arm
and then there is the problems of the custom kernel things needed for support of the weird keyboard and buttons
There was a nethunter build but never got that working
looks like a bulkier steam deck
and just installing hacking tools from source or from debian repos should work
weird question, why not just put debian on a steam deck
it is actually smaller
genuinely wndering
because when shadow preordered the dragonbox pyra the steam deck was not even a dream yet
preordered it in 2016-05-05
That's a short pre-order, grats! /s
@normal fable @vocal gale ordered white castle for lunch! Woooooo!
They seem to be in need of a web designer...
None out here.. Except frozen..
Someone remember my order number- 58, ty
67, gotcha
-58?
58
22
oh k, thought the indexing system was bad and u were given a - number and now you have to wait for the system to glitch out for your order
reeee, I am beginning to hate eating rice and chicken 
can i have a 3389 with that please, and a large dr pepper
then stop...
Switch it up, do chicken and rice
eh add some yogurt to the mix
bella has had to much rice and kicken
try harder
well bella is trying to have low calorie counts
I got 3 more meals of honey sesame chicken with rice
Order is 58.
Ty
No prob
your order is Cerium
Someone tried taking my order
did you beat them up
yeee, going falaffel though
I stood there menacingly
no
is it possible to be a good human being
yes
:hammer: nightmare14226#0 has been banned.
Jabba is civilized, he would not take action directly, wait for a few years then pounce when they aren't expecting it
i have experience with jabba
I gave them a chance to remediate the problem, this is Β£25 worth of food
Who takes food?
Fast food or a shopping?
free to them



