#general
1 messages ยท Page 70 of 1
C will force you to do everything yourself, it's just fancy assembly
While you aren't at the register level, it's still a pain
Including memory management, people struggle with that, Python does it for you.
I think you should just write to raw memory, to REALLY understand
C# too, for the most part
And most modern languages
Why get into security if SOAR does everything for you ๐
Rust doesn't have a GC, but it does a lot of checks to make sure you use memory correctly
I think what they are trying to say is that understanding C is more like a niche thing in infosec than it is a neccessity
My point was more "People struggle with memory management" to begin with.
just start manually sending TCP packets via RJ cable
Pointers are hard
I actually only send raw electrical pulses at 1/100000th of a second
To manipulate it at the lowest level
Sounds pretty slow
I do all my UDP Scans with only a cable and a battery
I forgot what the number is
Well that number is 100 kHz
then you struggle and learn it, its a field where you need to continously learn new things, you can't give up just because something is too hard
What is the frequency of most electrical pulses on a wire in regards to computers? Or is it always different, I can't remember what my CCNA said
You can calculate it
oh ๐
Depends on the clock?
Generally in the GHz range these days
It's 7 minutes past 9.
7 past 10
my god, hydra is in the future
That's different
8 past 10
I'm unsure what to google now
Transport other ethernet and internal CPU clocks are different
Yeah but I was talking about
Sending data
Ah
:3
That is one of the things why i started learning this field. I do understand that this field is huge, 8 months ago i had no clue what programming is it was almost like a sci fy to me.
Python -> C# -> JavaScript-> some other stuff and projects (about 6-7 months) -> and last month or so iv been looking into cyber security, and this field is what i like the most. will it be easy to get into hell no, but so what, everyone needs to start somewhere,
I send my scans with pure brain power over ethernet
gotta verify yout thm account to post/embed images
there are many of them already haha
Does anyone know how the point system works? Do some tasks/rooms/questions give more than others?
Thanks @wintry sluice
Gave +1 Rep to @wintry sluice (current: #319 - 14)
"Verify"
where is the Verify ๐ฅน
Just to make one thing clear, I am not dissing your choices, you are free to make and use whatever roadmap you wish to use, I am just giving pointers as someone who is already deeper in the field. And I understand the market in this country and our neighboring countries, you want to be exceptional if you want to get employed in this field, there are people who have gone through university with mandatory internship and still fail to find a job in the field, not because they couldn't do it, but because there are no offerings, you want to shine to get noticed
Slash command
@pure kernel
Oh okay that's why I'm earning next to 0, I'm doing a pathway with lots of walkthrough rooms
im stupid(CL)
Not stupid just didn't know
This is by no means to discourage you
๐ all good, as i say in intro, any and all info is welcome, constructive criticism included, and tips what to learn are always good, i just need to prioritize basics more then rest of the stuff, after i go over basics on tryhackme ill see what i can do or learn more.
My T480 is coming today ^_^
i am currently working on construction and i love the company i work in so im in no hurry to leave, but once i learn enough i can switch the field i work.
i guess it will take me 1-2 years to have some beginner level experience
Depends on how much time you can allocate into it in a day
Morning
That's good
up to sunday i think its about 8h per day
OR how much children allow
xD
current goal is SOC lvl 1 and complere beginner path
Good luck, what do you plan after that?
What job you want to do in 5 years?
grind basic level stuff so that i understand it, comptia has certificates that might help me,
they'll only help to get past screening, which is the first stage
In this country? Not really no, they are ignored
i live in finland
Still unlikely
true but its a start
I recommend studying the materials
job market for entry-level security is harsh, everyone seems to search for 5-in-1 astronauts
But I wouldnt waste a penny on the exams
understanding it
yee you can get the certs at work, if it requires them
but some certs increase visibility of your resume, if it's completely non-technical
Yes, and you don't want your CV bloated with certificates that are same content, many seem to mistaken that the more certificates you have the more qualified you are
not all 8 of them I guess
Don't forget all your google and coursera certs
And linkedin quiz completions
or how many of them are there
I've seen the EC council "navigating the dark web" thing ๐ฉ
E๐ ฑ๏ธic
but I think it's ok to put 1-2 thm certs that provide a fuller picture on your practice and tech stack, and "upgrade" them as you progress
just mention you're active on THM that's it
really we don't care for certs of completion. anyone can go through a course and copy paste answers
nop, although you can subtly mention it in your interview
also mewing
haxmaxxing
Just say you are top 5% in thm
I'm still at top 8% but going there
well, some rooms change the flags and even the whole flow (or maybe it just breaks) after the answer leaks
I don't have any official cert yet so I'll keep the THM ones until I get it...
you can go for ISC2 CC, it's free now
I'm working towards my GCFA, told my boss I'd be done by Summer ๐
and the cert it's much, yet it means a membership
got email today from ICS2 that my ICS2 status has been suspended ๐
what cert did you have?
I had nothing there, I don't even remember I had registered there
You need to mew to your boss every start of the week
it was a joke about mewing streak
and t-pose
On odd dates T pose, on even days P pose
If I have a dynamic IP, what can someone do if they obtain mine?
If they looked the IP up, it will just give them a general raidus of the location it's coming from
Eh, you could do more interesting things, but I don't want to give people ideas
Let's not yeah
They could try and use it for OSINT as that IP could be associated with your personal identity but it's unlikely
If you donโt have ports exposed - the impact is near none beyond a rough super in accurate location (maybe state is correct)
Itโs when you open up ports the threat surfaces increases
You did the CCNA? @rapid merlin
I was going to so I had the material but I decided that it's not worth getting for me atm
Why?
I want my Pen+ and Sec+ and Net+
First
Might not even need CCNA at all
Because i heard that the CCNA is a great certification when I was trying to get study for it
But alongside i wanted to go for cybersecurity
I realized maybe I don't still need the CCNA
But some people are telling me that I still need it because it will help me in My first career in IT and even in cybersecurity
Have a look at positions of where you want to go, and look at what their wishlist of certs to have.
I want to go in to cybersecurity.. the Blue team is what I love
Either incident response or venerability management
Then have a look around LinkedIn for IR positions near you, they'll have certs listed.
I was reading that ๐ฆ
That would be better in here, it's ok, I finshed reading it.
That's for TryHackMe related support.
ah ๐
I closed the window tho
Ah, I see.
History 
I thought Firefox had like a file system where you could go back on
I saw json.l4 something files but couldn't open them
Jsonlz4 was it
please, did someone else lose connection with attackbox?
Did you leave it running for a long time while your afk
Is it possible to upload a file to a website using burpsuite using post method by selecting the file ?
nope, i was working on the owasp room, lost connection right after sent the last answer, but i wanted to complete bonus questions too
Yeah that happens
allright, thanks
If it wonโt let you reconnect, shutting down is the only option
Can't you just upload the file, turn on your intercept, capture the request then edit it before forwarding?
yep, reconnecting didnt work, so i terminated old connection and created new, waiting for initializing
Alright great
to test websites that dont support file upload directly
If they aren't giving you an avenue for file upload or you can't tell the server to get a file somehow then it's not possible? Afaik
do i need to connect to vpn if im using the attack box and im subscribed to premium?
No
ok, but lets say i wanted to connect to the website vpn, how would i do that?
and thanks
I dont know if this is correct like
If a website accepts post method and maybe it saves the file direct
You can find the steps to use the VPN on the access page
Select โOpenVPN configurationโ from the cards
No lmao
i mean there is a functionality to save it in the backend
not just automatically
on hackthebox i used to connect with the centos9 (parrot) VM
using open vpn name.ovpn
is it the same here?
Could you be a bit more clear? Go into #room-help and i'll see if i can assist.
Yes
do i need to download kali linux or working with centos9 on vmware is ok?
for thos module :
yup i need to download kali or yup centos is good?
oh ok
thanks
question,
my interspeed is 60 mbps,
infrastructure + installtion of fiber internet is possible in my house,
and they say the speed reaches to 1500 mbps, will it improve my scans speed?
because it takes 4-6 hours for all ports scan with -sV unless i use T4 or T5
do i need it or not?
it costs like 1500 euros to install it
more simple question can i expect significatly faster scans with significant faster internet ?
Have I been Pwned usually shows you.
need verify
ayy i did it 
Please I have a question, can someone that's new to cybersecurity start studying for the Tryhackme to gain experience before he/she starts going for certification?
Gave +1 Rep to @cedar scaffold (current: #2022 - 1)
yeah, THM is a good place to learn and gain practical experience
least from my perspective as a newbie to the field
i think so
It's not impossible to land a job with just stuff you've learned from TryHackMe and what not. it won't be easy, but certainly not impossible.
also the THM community has a lot of helpful and knowledgeable individuals 
@sick lance certification will do if you are looking for jobs?
They can help massively.
tryhackme is great but I would look into other stuff to broaden your knowledge
like portswigger academy for instance
Congrats on trial mod @sick lance
There's your answer.
Thank you ๐
Gave +1 Rep to @simple valve (current: #23 - 351)
ey one question can you teach a guy named @errant lily to hack like in the way that he can help friends to get like acc back or forgoten passwords ????
and do you remember me?
ok
Hacking an account would be illegal.
you ask for a reset
if you forgot your password, ask for a password reset
Then you'd use the support of the account
IE
You'd ask TryHackMe for support to get their account back
ok nvm. i was asking bc he ask me to send him a server link wher he can learn how to hack or as you call it
did you read ?
what web?
you can use a translater like deepl
then you can make more research about this leak using google
ok see you guys in 3-4months
uh ok bye xd
ok bye hopefully you grow up a little โค๏ธ
๐
hahah

Now now, let's just drop it, it's dealt with.
I am tired of taking CCNP tests 
You sound like a real mod ๐
congratz on the promotion, scrubz
Gave +1 Rep to @amber quarry (current: #56 - 118)
He is a Blue Teamer now
I did nothing but np o7
xD
Thank you!
Gave +1 Rep to @wintry sluice (current: #306 - 15)
shiny blue shield 
The blank PFP is freaky tho
Matrix is glitching
What if it's not really Scrubz, and an agent took over his body

Only downside for PortSwigger in my opinion is too much relying on BurpSuite. Its nice to learn how to navigate through linux with web app pen testing.
@sick lance I can join you in the weird questions club
Burpsuite is OP though
4th right
and this is for CCNP....
I'm glad it's not just not me.
Online game site
I mean you can download games
And fixes for games where devs are lazy
I mean... they do make it so it makes sense that their courses would be based around it
๐
for some labs it's easier to use burp suite indeed. but all of them can be done without
SySTem.Out.pRinTln
like CSRF poc generator is handy but not needed if you know how to build a CSRF poc
what test is this part of?
it's part of the overall CCNP Enterprise: Core networking cert, have to take all these tests today and the final exam
GLHF, don't die.
What the flip
How is that even relevant
Forgot an =? Or is that the sane languages talking?
virtualization, atuomation and programming of networking
forgot an =
I mean, I guess?
BGP looks like fun
it was
In college or you are trying to take the CCNP exam?
She has a job
So I'm assuming, this is on the side
Wow that's pure CCNP curriculum
IIRC it's for her job.
Please what is IIRC?
if I remember correctly
or iirc. abbreviation. if I remember correctly; if I recall correctly.
If I can Remember/Recall Correctly
Haven't heard that before.. wow
Cyber sec is not the only thing you learn here ๐
What else we learn?
Ah, yes, English
The IIRC what does it have to do with the CCNP Enterprise?
Nothing, I think I remember Bella saying she had to sit the exam for her job.
A customer wants me to do security+ because its their side compliance ๐๏ธ๐๐๏ธ
Yes ...
lol
oh yea that definitely happens with consultation / outsource companies
Networking is usefull
if you dont have some X certs, they wont get your services
Wow so no one can escape networking ๐คฆ๐ผโโ๏ธ
big reason why OSCP is relevant
Exactly
Yeah that's true
I still won't get it though, I just wont deal with this customer
I think in the Netherlands certs are less important than in the US/UK
job wont pay for it?
Only thing companies care much about is uni etc
Please have user m.bhat user id=1141247531116941392 removed from server. He is going on hacking servers posting junk about "leaked onlyfans + teen content".
You should dm a mod
No need, already dealt with. ๐
Oh xd
Oh they pay it, I just don't want it, those who want it just can consult me directly internally if they have an issue with this customer
Thanks for the warning.
Gave +1 Rep to @lavish shell (current: #554 - 7)
No problem
IIRC is an acronym, kind of like idk or ikr
It's not a certification
Don't know what the first i is for, but the rest is Internet Relay Chat
Uh no, not in this context
hello
hi
hru
@sick lance
O no phishing
@fierce tulip sorry yoshi, we don't help with research, especially if it's class work/
Thanks!
Gave +1 Rep to @icy epoch (current: #378 - 12)
And we don't click suspicious links, especially when they begin with google.docs lol
I do never click links, only when it is related to the conversation
Cheese
Cheese is a dairy product produced in a range of flavors, textures, and forms by coagulation of the milk protein casein. It comprises proteins and fat...
Is that so
yes
Gouda cheese is very good
Gouda cheese (/หษกaสdษ/ , US also /หษกuหdษ/ , Dutch: [หษฃสudaห] ; Dutch: Goudse kaas, "cheese from Gouda") is a creamy, yellow cow's milk cheese originating...
Goudse kaas ๐
okay, totally fine, thanks!
Gouda is 20 minutes away from me
hihi
Look up Gouda or gouda in Wiktionary, the free dictionary. Gouda may refer to: Gouda, South Holland, a city in the Netherlands Gouda (pottery)
Yup
Gouda, south holland
Rotterdam and Utrecht, in the province of South Holland. Gouda has a population of 75,000 and is famous for its Gouda cheese, stroopwafels, many grachten
Utrecht isnt in south holland
South Holland (Dutch: Zuid-Holland [หzลyt หษฆษlษnt] ) is a province of the Netherlands with a population of over 3.8 million as of January 2023
@rapid merlin what region are you?
South Holland
ah
zeeland here ๐
Any idea how can I activate lolcat by default everytime I open terminal
I tried aliasing in .bashrc by ```alias bash='bash | lolcat'
and restarting terminal
didn't work
wouldn't that, if it worked, result in an infinite loop?
I'm expecting to see
called bash
oh, there is an alias called bash
now its bash | lolcat
oh, there is an alias called bash
nwo its bash | bash | lolcat
Whenever I open terminal
Hmm
Wow how did you make your terminal rainbow
Oh
and i was thinlking that my terminal is over colored
You also used lolcat?
no
(only if i am root)
anyone with esxi experience.. can you enable soap api by cli? cant find anything on internet
Isnt there a VMware discord?
tilix as emulator, zsh with ohmyzsh, powrlvl10k theme and neofetch with custo theme
and i work on zelij tilling window
ello ralex
ello ello
d what
Msft
i think my brain don't brain =/
Oh flip, maybe I forgot to tell ya
I landed an internship
Security Researcher Intern
ahaaa
I was literally on edge not knowing what to do
Pentesting? Forensics? Rev?
And finally I'm at peace
Rev it is
so it's going good today ๐
Yup you can say that, although a lil tired of trying my best to teach maths to kids
How you been?
Everyone good?
you know for https://brilliant.org ?
Nope
Ohh
yea. just get from work. need some wast in peac from office ppl
What kind of maths?
Algebra...
I couldn't process that
ah...
What's wast
Np dude, I really dunno how you can even think of work while staying awake for 24h+
this...
take sleep more serious than forcing you self for anything
it's my school
Ah close enough lol 
my education is based on the CCNP, so I take these in school
ye, I use it for work too, but it's because my lectures are based on CCNP we are taking the exams
Wow that's nice
That's well grounded
Someone just bought the CCNA hardcover book for me.... but am going for cybersecurity. Don't have anything to do with the CCNA book ๐๐๐
Really?
If you are looking into security for networking, 100%
yeah, networking does indeed help you with building security
Like you said, you cant escape networking
I mean fundamentally networking is the most important aspect of any of this
None of it matters without it
im looking for someone who has taken and passed both oscp and the sans equivalent of it. Their input and experience on taking both could shed some insight for me.
++
But it's to the south of Holland, and it has its own province
Holland is a province
It isnt
Netherlands is a country, and we have 2 provinces named after it. North-Holland and South-Holland
how fix red square wile run machine?
What does the red square say?
Failed to read a named property 'origin' from 'Location': Blocked a frame with origin "https://vnc.tryhackme.tech" from accessing a cross-origin frame.
i'm going to link and write wrong connection
i can show this on dm
Isnt needed
I think you need someone from staff
What browser do you use? Do you have an adblocker on?
yandex
Can you try Chrome, Edge or Firefox?
let's try
And we need to move to #site-support btw
Never heard of that until just now
But that looks cool as heck
I figured, but I want to search for something similar at my location๐
and CyberSec bootcamp doesn't return any good results in my area
it sure feels cool as hell too
You are IRL cyberpunk now
I mean, I say if you think something works for you, go for it. CyberSecurity bootcamps in general aren't great
Had one try to get me into it for a stu-pid high cost
Nah
You can self study, enjoy life, take some certs, build a proper admiration for the field and projects over the course of a year. Make friends, and slide in smoothly vs some rush job
in the US, cybersecurity bootcamps are generally run by 2-3 of the same companies. They partner with universities, throw money at the university in exchange for the university lending their name to it.
Yep, exactly what they tried
And no one views them highly.
It's like those trucking companies that spit out "truckers" in 3 weeks
The same truckers that jackknife their loads, obliterate cars, and can't back into a dock door to save their life.
One time I had to watch one of these yahoos a couple years ago try desperately for an hour to back into a dock door before I decided I'm not waiting anymore and left the job site
Takes 5 minutes
After 60, you've lost your slot
Not a hard one either. Wide open lot, only truck, painted lines.
Nothing rushed is good
Hello THM ๐
Greetings and salutations fellow humanoid
Hello!
anyone here work with wafs often? wondering why some vendors give you URLs and other URis in their logs.
wait they updated how the certs look???
Yeah, new certs obtained have a new look.
Ties in with the UI/AB etc
welp guess shadows old certs wont change then
Nope.
Only certs that haven't been generated.
nice. pleased to meet you || ||
try emitting llvm with cargo and then compiling the llvm stack frames with clang
you can also use qemu to emulate the target architecture and native compile in the vm
it'll be slow, but it should work
well the confuss is trying to figure out the instruction set for the cortex-A15 cpu and how compiling for it will work
that's just another aarch64 chipset right? unless there are special instructions that ONLY exist in that arch, you should be able to emulate any aarch64 and compile something reasonable in the emulator
looks more like aarch32
ah, it's an older chipset
yuups
ยฏ_(ใ)_/ยฏ
if you are wondering what shadow is trying to do it is to compile the game veloren for the dragonbox pyra which uses an arm cortex-A15
from what i'm seeing, gcc and clang both support crosscompile for aarch32. if you can get cargo to emit something either of those can consume, you should be able to do it
it'll be hacky, but it would likely work
veloren itself says it wants a 64b cpu, it likely won't work at all because the 64b libs may not be have 32b equivalents
especially for the graphics layer
Crazy how the first release of Rust isn't even a decade old yet and seeing how far its used
Morning THM
mornings vain
Vain!
vain when you free to work on ctf???
it's soon iftar time 
I can do for a few hours now
then I gotta get back to studying chemistry
Hey hey! Does anyone have some cool cyber sec interviews/podcasts on YT to recommend?
chemistry sux ๐
watched 0day that one 1h long ?
Yup
well yes
Organic chemistry sucks the most
but I like the rest
once I finish my chemistry final, I can get to studying for my sec+
listened to this one recently, enjoyed the first half https://www.youtube.com/watch?v=A4ylyhqZAaI&pp=ygUTaW50ZXJ2aWV3IHdpdGggTlNPIA%3D%3D
Trust talks about his experience working at NSO Group as an iOS exploit developer, discovering 0-click, 1-click zero-day vulnerabilities.
An interview with Trust, ex-NSO Group hacker turned web3 bounty hunter and independent security researcher. In this conversation, we delve into Trust's background as a security researcher and exploit develop...
gummo on soft white?
https://www.youtube.com/watch?v=g6igTJXcqvo you have two parts
Soft White Underbelly interview and portrait of Gummo, a computer hacker from Jacksonville, Florida.
Hereโs a link to a follow up interview with Gummo: https://youtu.be/3ZtkMmVDNEo
For ad-free, uncensored videos and plenty of exclusive content please subscribe to the Soft White Underbelly subscription channel. It's $10 a month and watchable on...
Darknet Diaries 
Ah, I don't think I ever finished it, thanks
Gave +1 Rep to @loud marlin (current: #26 - 292)
thanks for email ๐
Gave +1 Rep to @hollow pivot (current: #51 - 140)
Lol, i've listened to all of them ๐
Anytime
ahahaha
https://darknetdiaries.com/episode/139/ This one was niceee
on roomate laptop
What does it feel like
? i think i don't follow
The flower
Does it feel shaved like somebody carved it?
Or is it smooth
Iโm guessing smooth because itโs basically burned into it by the laser
I have to give it a listen then
@gray sonnet : "What type of food do you want?"
Me: "Indian"
@gray sonnet : "Do you want spicy"
Me: "I'm the king of being white, I can't handle spice at all"
you laser etched a laptop screen??
slightly carved but smooth
yes. not screen. back of it ofc
I don't like indian food, no meat and too spicy
clearly likes a korma with extra yoghurt
yes ๐
nah, some of the mild ones aren't really spicy at all
@gray sonnet "1 onion Kulcha is enough to fill me up"
Me: "I'm American, that's a light snack"
You ever touched the laser before
Be me: install Phasmaphobia (22 GB game) in 3 minutes
What sorcery is this
mine is amazing
Gigabit internet sorcery
I got guidance from @gray sonnet since I didn't know what I was ordering

Forgot about the gifs
Butter chicken with a paneer and a garlic naan
Canโt go wrong
Unless the place is dodgy af
I got Lamb Pasanda
Onion Kulcha
yes. Ir (1064) one dont hurt. the blue (450) hurt like hell even on minimum power
Not dodgy at all
I had a butter chicken before that was half butter
Like it literally floated at the top
To be fair it was ok
does anyone know wht is this file is"0819f05c4eef4c71ace90d822a990e87 "
inside looks like this
looks like a sql query
is it supposed to be there??
never saw that. but my linux knowledge is limited tbh
what does it say when you use the file command
Brave
Looks like a schema definition file. You're getting the weird character strings because there is binary encoding used by the db engine.
0819f05c4eef4c71ace90d822a990e87: SQLite 3.x database, last written using SQLite version 3034000, file counter 8, database pages 85, cookie 0x55, schema 4, UTF-8, version-valid-for 8
is get this
nop... stupidity 101
I guess, the question is rather, why is it even there? ๐
yeahh
try sqlite3 {file} then type in .tables and see what pops

Did you gain superpowers
No, just cancer
just saw your other comment, I agree with Wirago... you saying there is a file in your home directory that you don't even know where it came from
i get this
00
yes... i flap with my hand so fast i fly
got any ideas
My mind skipped the L
Lookup sqlite3 syntax
ooo
Hack tricks is usually decent enough
that users table does look interesting. Id look into that and see what is in there
ooo
try select * from USERS;
sqlite3 0819f05c4eef4c71ace90d822a990e87 select * from USERS;
Error: in prepare, incomplete input
Hello, hackers! I'm in my final semester and currently undertaking a bachelor's project that involves incorporating security measures, such as encryption, decryption, and key management. We're in search for some good Samaritan who would be willing to offer a short consultation on cryptography. Our knowledge in this area is quite limited, so any assistance would be highly appreciated.
sqlite3 0819f05c4eef4c71ace90d822a990e87 select * from USERS;
Error: in prepare, incomplete input
Hello there!
We don't actually help with course work, sorry.
Well, it's not wrong ๐
It's a boat!
Oh yeah
@boreal scarab : Are you here? Are you french?
Ghost starts playing with the closet
@boreal scarab: can you stop playing with the fucking door!
booo, are you a ghost, yes!!! boooo what's the password of the wifi ๐
123456789
thepasswordtothewifiis3141592654
The Wifi Password ๐คฃ
#zhangjiashuo #shaoyuqi #jimeihan_love #jimeihan #myannoyingroommate #nashengyan #xubin #lichengxi #cdrama #cdramaedit #cdramalovers #cdramascenes #chinesedrama #trending #sbsdrama #viral #kdrama #doctorslump #netflix #jtbc #trend #kdramas #kdramalover #mydemon #instagram #BTS #songkang #kimyoojung #flexxcop #woop
740502
Is this legit? Trying to install the kali linux image.
I have, but I've heard that it takes a long time to download.
Mines has been downloading for the past 7 hours.
Hi
Use the torrent if your ISP doesn't filter torrent traffic
And I've downloaded it very fast before on a gigabit line, even without torrent
Alright. Thanks.
Next please? 
watched 1st and 2nd part ?
hmm... i need to check if i have some other. will link bit later... got some things to do atm
Interviews? Nah
"NSO tries to keep everyone very happy" ๐ฌ
So we got our coursework for Applied Pentesting for Uni.
1 hour. and I'm root.
This is terrible.
try vm escape
On my own host? 
then probably no
Talking to @gray sonnet bout my old college Intro to IT class.... and omg, how memories came flooding back on what a joke that class was to me...
We had to setup a jumper on a HDD to make it a slave, work on win 95 machines by taking it apart, saying what each component is, and putting it back together
That'll be a lovely report then
We have until April to submit it.
I have all the time in the world.
Like OMG.... no one uses jumpers on drives to slave them 
A good thing to get off your plate then
Use the root access to create a sudoer, do an authenticated nessus, all that jazz
It's like you read my mind. ๐
Bear in mind my pentest coursework was Throwback
Which I'd already ran through
And the uni broke it
I mean the year before year they got in trouble for recycling vulnhub boxes
Still dodgy you could pay the fee and get a full walkthrough...
That's not so good.
You'd better believe that report was good though
๐
Ours is a group topic.
When you guys started with all these cyber security things. Did you learn only from Tryhackme? I have problems remembering everything I learned and its hard to understand everything. Do you have a tip for that or should I just keep doing those paths and I will be fine soon?
I started TryHackMe whenI joined college to do Cybersec + Ethical hacking.
I blitzed the website and kept up the learning.
I was a good 6months to 1 year ahead of my peers.
@sick lance Congrats on the shield ๐ ๐ฅณ
Thank you ๐
Gave +1 Rep to @blazing granite (current: #143 - 46)
btw Scrubz anything you can do about getting your color to be red now
I could always ask if they can change the trial mod colour to red.
Otherwise, nothing.
and you had 0 knowledge before you started? because I have problems with many things that tryhackme assumes me to know for example in many rooms like cross site scripting and file inclusion they talk about a web server from the hacker and that the hacker can leak all contents of the website but they dont explain how to set up such a server etc. they just assume you know how its done for the tasks(no hate to the room makers)
try it out, light blue just seems out of place for you
@buoyant tree how was the film the other day? did you watch Mr Bean or other one?
You can follow the pathways to do it
I did
I had some knowledge.
Bean
then poor things
Nah, the blue is ok.
It could turn green in two weeks.
hmm
I like the light blue, it match the shield ๐
sad
Although GNU-Rex I have a lil watchlist of uncompleted movies to finish
I should probably stop hopping around and end up finishing them
I don't do watch list, I used to do book list until it got huge and I stopped ๐
my booklist is around 200 atm
although these are the ones I partially watched then stopped then started another one because I forgot I was watching that
@hollow pivot idk if you watched tv serries/show Undeclared War. hacker themed. rly nice
I have a question... I was poking around the source code of a web page getting practice doing passive enumeration and found that the version on multiple imports/include was: 1f54e36208878360084e5d4207791922 I've tried comparing it to the hash of known version numbers, I've tried to compare it to the hashes of the downloads... I'm wondering if anyone has any insight in to this
<script src="hxxps://www.xxxxx.org/wp-includes/js/wp-emoji-release.min.js?ver=1f54e36208878360084e5d4207791922" defer=""></script> <- this is the html from the page
Cachebusting
not familiar but now I know how to go look it up.. thanks!
Gave +1 Rep to @naive violet (current: #1 - 2104)
That looks delicious
Hay, we would like you to interact with the community for self promotion. ๐
Hey! anyone like to code with me? I am a newbie, so it would be interesting for both of us to do some coding together.
Iโd procrastinate it to the day before and still end up doing an all nighter

best tie for study is from 22:00 -> 02:00, everyone sleeps and noone bothers me
Oh it was.... till it made me super full lol
Best time to study is when there are exterior renovations going on
those rare moments between the intervals of drilling where you can read a sentence and then wait another cycle
xD i had last summer 100 m from my apartment demolition works (when my vacation was)
from 7 am to 17 pm sirens 5 times a day
and explosions so nice that windows where shaking
the best time to study is whenever you feel more confortable to do it ๐
I was studying for my first SANS exam like this, there were some exterior renovations going on, on the appartment I live in and they were just drilling from 6 to 18 ๐ฅฒ
seeing those shadows from windows of them walking by constantly and just drilling and drilling, making me wonder what they do with those holes they drill
I used to work night shifts then, so coming to home to sleep was always fun
@hasty palm You served in the army?
2010-2011
met my best friend tnx to amry
if i didint have knee injury propobly would have stayd there
Army was nice enough to give me basically 2 weeks off from work for 3 day event ๐ @hasty palm
I remember once it was a public holiday, a particularly cheer one and in my neighbourhood decided to make some activities for the neighbourhood kids with music and everything. I was working in a hotel at that time, I saw the structure when, cables, etc when I got out of the bus, the whole thing was around 10 meter from my building, coming from the night shift I went to sleep, an hour later, music and screaming kid, I was so happy. I put some ear plugs close all the windows and I said f them ๐ and I continued sleeping
my sister is in Kaitseliit, not sure what its in english
Defence League
she was even woman of the year or something like that once
That's nice, honestly, the sound was not bad, just the whole room vibrated on my case when they were drilling, and that wakes me up, I can sleep through any sound, but I wake up even to a slightest touch
I considered joining defence league to change my army position, but then army was nice enough to just change it for me, used to serve in combat engineers but now thanks to the treath on eastern border, I decided I want to do something related to my speciality ๐
Gave +1 Rep to @hasty palm (current: #2022 - 1)
what is this +1 thing
if anyone replys to anyone
and it contains "thank" or "thanks" or "ty" then they get reputation point
ty
Gave +1 Rep to @past sparrow (current: #814 - 4)
lol
Gave 1 Rep to rennet (current: #693 - 5)
That's the automated way. Additionally, could do it manually as well
yeah for sure, but many people are not aware of it and don't really care about giving +rep to anyone
Gave +1 Rep to @lavish shell (current: #509 - 8)
looks like 1 more keyword is in the list
ty
But it doesn't do it
there's a timeout also
5 min(s) timeout.
I mean this is past 5 minutes unless something was deleted somewhere
<t:1710276512:R>
does it work on yourself?
lame
It works on me tho
yt!
Hey everyone! Quick question, does THM have any rooms relevant to NIST Cybersecurity Threat Model?
There is also a search function on the site, I'm just saying ๐
thanks!
Gave +1 Rep to @icy epoch (current: #307 - 15)
np
I used it to no avail lmao
panics but I'm still running Windows 10
calm ah, its just Windows 10 machines that haven't been updated to latest version of Windows 10
well probably for the best
anyways full windows 10 support drops in 2025
migrate to linux or upgrade to windows 11 by then
or spend obscene amount of money and go on apple devices
why does my streak say 14 on the dashboard and 15 on the account page
try hitting ctrl + F5 on the dashboard page and see if it updates
When you talk to old co-worker friends about your old job together and hoe many issues there were.
aww that's cute
that's certainly one way to bond to discuss all the stuff that is messed up at other places
there's so much efforts put into the rooms
Oh yah, and get on the topic of a job opening at their current job, so... always a win win
I am shocked in a good way
Jsut wait to you get to the network rooms.
Amd some of the quality rooms created by community members, nevermind staff.
you mean Network Security? doing them rn
I wish my job had openings, could hire new people ๐
the fresh ones are created by the community, from what I see
Community ideas are usually one of the best, they know what they yearn and can provide it
THM release staff created rooms on Tuesday.
Friday releases can be community created or staff.
I'm on mac, and it doesnt work on windows
do mine count in there?
wait nah they're just broken ๐
Absolutely!
oh thanks!
didn't have a chance to get to the new stuff yet, on my 18th day and rounding up the basics
Gave +1 Rep to @sick lance (current: #2 - 2049)
They're just java
not Git Happens
say thank you to me
Gave +1 Rep to @uncut cove (current: #1337 - 2)
you ok, mate?
aight
it's okay
thank you
Even if they said thank you to you, it woudln't count. as they're on a 5 min timeout.
NOO
bot's a bit strange in the head sometimes
i didint get
grrrr
bad luck bro
my body be hurting
from sports?
from working out
nice!
Hy
Random thought: I very much dislike the whole "Look at a picture we took of this person in our company doing X that you never heard of, achieving X" and it's an obvious "better image" post.... ugh
Scrubz, gz!
Thank you!
Gave +1 Rep to @valid mauve (current: #63 - 108)
Also, I just noticed that code that's being used production-wide at my customer is the in-development edition of said code instead of, say, something tested!
test in prod, test in prod
yeah please don't
yes, anything is achievable through training, most talented people you see just put countless hours into training
One could say, its a talent to keep the discipline ๐
exactly, i think when ppl see successful ppl they dont usually see those countless hours or risks ppl have taken.
there is luck that can help u , but sheer amount of hours can beat that luck.
"I am not like you, you are smart", "I can't do it like you could","yada yada yada" - everyone talks about their successes, no one talks about failures, and then those who listen create illusions that they are lesser because others achieve things
blood, sweat and tears, - ppl same age as me drink, travel party etc, i study allmost all of my free time ...
I'd say opportunity is more deterministic on that than luck
I mean, people think that I know so much, but they don't see the ~60 hours of work I do every week
37 <- my age
and how could they, we don't share things that are trivial, we like talking about extraordinary things
I can be percieved quite active on discord as well, though most of the time I am also pre-occupied with something else
Speaking of I am going to sleep, cause I gotta get up at 03:30
Goodnight
Cya
I luckily have emergency evening shift tomorrow so I can afford to be awake a while
Prime time to make changes in life
I just don't want to miss my breakfast and fast all day long without any food
Work from home as taken me to the point that I eat when I want and take breaks when I want
people think I know so much, but they don't see I'm an imposter...
They don't know that I am doing an educated guess
and if I am called out for it, I just apologize and take it into account next time ๐ค
Just fake it till you make it
worked for me
it works more than you would expect
I'm finding it hard to fake my current position
needs interaction with people...
and some managerial skills...
Did I mention who I work for?
Three letters, all capitals, software development, billions of dollars and offices on every continent.
does it start with an I?
No, an S.
ah that one
Yyyyyup.
I mean it could have been IBM
That'd have been cool as well. But nah, S<redacted>P is nice too.
TIL SAP is a company, I thought it was a name of a software
I thought they were saying SCP
I work with quite a few ex-IBM employees, they don't speak highly of working for IBM
IBM had an office building outside of my hometown. we used to play NERO there until the security guards would chase us out
anyone have any experience running honeypots (conpot + templates) ?
I have had the privilege of seeing IBM SOC work, I would not want to be in this environment
why?
Too much manual stuff, I'd burn out very fast
you mean hardware or just lack of automation?
prolly lack of automation
lack of automation and maybe disagreement in processes
which honestly makes sense
I cannot really condemn automation part, because well, you can screw up a lot of things so you risk not automating, or you are just so comfortable doing things from muscle memory that you don't want to spend your time on higher priority things that could send you up
If you're not automating, you're doing it wrong tbh
Of course, get a grasp on things first, but work towards automating different parts of your role
i spent a week automating something that takes about 15 minutes infrequently
eh, half week
An example that I can give, is using (if you have access) MS PowerBI/Flow to automate "business" tasks
I set it up to automatically backup certain documents to different locations weekly
Saves me probably 15-30 minutes, but I no longer have to remember and I can use that time on something else.
Ruby on Rails isn't a language, it's a framework like Django. Ruby has plenty of security related libraries and tools, but maybe not as much as Python.
Wonders why standard c is not on the list
perhaps, though a lot of people don't really have the initiative to start those things and just follow what they are told, that's what happens when policies are made by people who don't work with it and those who do say nothing
Sometimes, the management don't want to listen because they are set in their old ways, once in a job I suggested to do things in a different way even my way was faster and less prone to errors (I proved to them) management told me we've been doing this way for a long time, there is no need to change now, bottom line this work for us, there is no point in learning something new. That was the moment I started looking for another job, I'm allergic to mediocracy
Yep, it is what it is, you either accept it and get paid for this nonsense or you move on, and that's why I am really happy and lucky with my environment
.
just use raid 0 so you have two drives
it's called redundancy
guys i need help on something, i need to pick a topic in cybersec for my graduation project, my supervisor told me to research Nextgen Firewalls, ips's and ids's. i dont know if i can code a ngfw from scratch. any suggestions?
if you're asking then you can't
ngfw is a pretty big thing
are you supposed to make one or use one?
thought about a red team releated project as well but theres nothing else to advance on
i basically need to make my own project
the main thing that makes an ngfw ng is that it operates through to layer 7 and not just layer 3/4
if you could figure out a good way to do that then it may be possible
thinking about it, i'm sure there's some videos out there about people turning simpe stateful firewalls into basic ngfw
kinda curious now
wdym by if i can figure it out? didnt you say its hard to code a ngfw?
"hard" is subjective
When I hear NGFW my mind goes straight to the likes of Palo, Forti, etc
Making something like that would be pretty difficult as a single person/small team on short notice
but ngfw is technically just a fw that can also filter at laters 5 6 and 7
so it doesn't need to be as full fledged as what initially came to mind
so i get what ur saying now but
bacon
lets say i try to make it happen and make something. what would my fw lack that can justify feasibility compared to other products
also the alternative has a typo
maintenance
Fortinet is a [comparitively] massive company and the FortiGate is one of their flagship products
They are always patching 0days. Those are bad. Especially on a firewall
Those also have actual definitions (for antimal and such) that are updated exceptionally frequently
entering that market, you need to build lots of trust
no one wants to be the live test for a unknown product
You need lots, lots of data to make layer 7 sniffing even remotely useful
so its actually not that hard, just advancing on patches are the hard part??
If the project is only a PoC then it could be feasible, if its a product with purpose to enter the market, then its way too ambitious
^
oh ok
Some people don't even trust Forti, lol
and they're massive
I deal with them cause fuck Palo
but as you said, easy is kinda subjective and im not that technically advanced rn so gotta work super hard for it i guess
I take forti over Palo but I can say I have yelled F forti several times at work as well
Checkpoint it's really good
I prefer palo as a firewall. But fuck evverrryyyyyything about dealing with them as a company. I've blacklisted them.
subjective as in 1. who you are asking that advice from, 2. what is your time frame, 3. what is your current skill set, 4. what are the actual expectations
most people here are not developers in trade
that name sounds so familiar but i can't remember who it is
oh shit i just applied there lmao
Lol
Check Point Software Technologies Ltd. is a leading provider of cyber security solutions to corporate enterprises and governments globally.
Yeah, I have also a chicken to pick with checkpoint
they do their job, but they also make me question what the hell are they doing
only unmanagable thing is the time frame, and thats approximtely 3 months.
Then you better start working
๐
don't stop there, integrate it with LLM and make it learn about traffic and blacklist malicious ones on the go
no ben come back
yeah ill see you next year for that one
oh he's back
think big, think cisco
no
depending on the level of your course, you're lileky not expected to create something new / entirely from scratch that's going to be groundbreaking.
Again, depending on your level (and I would recommend checking with your supervisor first), review existing solutions (if you want to go the firewall route) and see what they lack. Maybe you can propose a solution for that.
for example, my Bsc was reviewing how different types of ML models are used to classify malware. I didn't have to make anything - it was a research and review and identifying the good and bad of current solutions
Only then my Msc was creating a ML model that could be used to classify malware - but that was an entirely year long project
I applied there too, though company to get into, I applied for tech support/help desk position, after a 20 minutes phone call, I got an email invite for a whole day of zoom, we were like 15, after round of tests, people start to dropped, we ended up only two and in the end I didn't get it
It was a position for their office in TLV
I know a guy who work there, it looks a really cool place to work
At least you tried
i've had a full day where i've come within inches of an offer and botched it in the last 45 mins lol
dif Co
defense contractor
yes yes but AFS also needs to be super realistic about timelines here
ab so lute lee
I imagine you also have some sort of report/essay as a deliverable?
the company was founded in 1993 in Ramat Gan on the outskirts of TLV
Morning
aprreciate the answer, but as far as i understand my supervisor, i basically need to make a project in order to solve an existing problem. the way out for me here is finding a super niche problem to solve so i dont have to work may f*ing ass off for it.
Hey Ben, Vernum ๐
m
