#general
1 messages Β· Page 73 of 1
Are updates important?
Yes.
Updates can sort out known vulns and bugs in software.

cool pfp choso
Thx sm i grayed manga panel
Gave +1 Rep to @astral crest (current: #2025 - 1)
thts cool
i installed kali today with a great tutorial, he covers 2 options i went through option 1, do you want the link?
Nah it's cool, I already know how to install it haha
i also installed it like 4 times and had problems with network
Help
Ayo Vain !
wassup?
Yessir
finished my finals today haha
Lessgoo
figuring out what's wrong with my VMWare
hope u did fine in them
or trying to
I had food poisoning for 2 of them...
we had 6 in total...
im solving SQL challenge on THM
Eyy! nice!
Does anyone know how to extract table names from Orcale database?
I hate SQL
Select * from table? Idk lol
hmm, i used all_tables, DBS_tables, user_tables.. nothing worked out
You should check Google
those tables doesn't exist
it's a challenge specific thing
the only thing i can do is to extract the table names blindly using Substring
which idk if that's a thing or not
idk if that would workout
Select table_name from dba_tables?
Is it a blind SQL injection?
yes
the table dba_tables doesn't exist because this doesn't return anything
You're going to have to extract the name then yes. Portswigger should be a good reference
i done portswigger
Maybe from Oracle or the name of the fake DB
never seen a Database without built-in tables
hi shadow
im trying to solve this one
I'm not sure what you mean by that. Check portswigger in terms of payloads you can use
It'd have to have built in tables
yeah i know, i have tried what i learnt from it, nothing worked
Have you checked every resource? You haven't missed something?
You may have an easier time using sqlmap, although it's still a good idea to know how to exploit it manually
Double check over everything
Sqlmap basically gives the answer right?
We should probably move to #room-help
i have to learn it manually cuz in CTFs we can't use SQLmap besides it being so bad at finding SQLi actually lol
Hey Poki π
all_tables is the built in one for Orcale DB
Anything else from Google.
Fantastic!
Oh yeah, definitely, more hacking for me now hehehehehe
Each time I update my phone I end up with some form of bug for a week lol
But you still have to extract the actual table names. all_tables is a relational table, it's not going to have what you're looking for
so, have you got an idea on how to extract the table name?
Nice! I'm not too bad, I'm sick so just rotting in bed haha
get rest and drink lots of hot soup π
I don't want to give the answer away. I think you should check Portswigger again
helps me everytime haha
Yes! Lots of tea is being drunk
I cri evritym
Thank you!
I'm Samsung user and don't like iPhone or anything apple related but it's getting tempting to switch to the dark side π
I use Samsung.
I owned the very first iPhone, I didn't like it that much I actually went back to Blackberry.
Although iPhone doesn't seem much better refsrds to that
Regards
I miss the blackberry
I miss button phones lol
Samsung is definitely better
π’
Any decent resources/videos to learn basic python?
@grizzled crystal i literally tried everything, nothing is working π₯²
humble has a coding book bundle atm. that has some python stuff.
https://www.humblebundle.com/books/learn-you-some-code-no-starch-books
I missed the t9 phones. I have a big thumbs and qwerty on phone is a challenge
Got ptsd from that? 
Maybe
Sony Ericsson lol
Nokia baby
I had the Samsung D500.
That thing survived two washing machine spins.
Had to protect the floor somehow.
nokia do good basic phones (for those who want to avoid smart phones cos of the distraction)
If I cba with my phone I put it in ultra battery save mode
Only allows texts and phone calls, calender etc.
The essentials
Very true.
Drilling companies are a bit inefficient tbh
All they gotta do is drop the Nokia
lunchtime?
Arch btw
Just had my best interview yet
That's good
I really wanna breakthrough into this field but I'm dreading the social aspects π
ditto. social anxiety is a pain
Guys I found the perfect video to send to someone when they ask what is a ddos
am am am am am am am
#hacker
#hacks
#hacked
#computing
#computer
#memes
#meme
#ddos
#server
Yeah it ain't great. Holds back everything lol.
Thumbnail already gonna let y'all know it goes crazy
Attackers looking pretty sus fr
humans π
Grossss π
Why human when can computer
Fantastic!
im trying to create a listener in netcat but when I execute the command (pressing enter) it does not give me any response and lets me continue writing: sudo nc -lnp 8081
hey peeps i was writimg a report on the picklerick room and was wondering if the webserver is vulnerable to LFI, path traversal or command injection?
Can you perform any of those attacks on the machine?
Is this also homework? π
Are you allowed to attack rooms in an otherwise unintended way to how it is laid out?
yea refer this articlr for an idea
https://medium.com/@JAlblas/tryhackme-pickle-rick-walkthrough-5f79716a86dc
Hi! Itβs time for another CTF on TryHackMe. This time we are having a look at Pickle Rick, which is a nice thematic challenge. Letβs go!
what homework?π
Have you done the room?
Can you do the attacks you listed on the room? If so, there is your answer really.
Sorry to disturb ya guys but as someone who wants to get into the field of software engineering/ cyber security where should I start if you dont mind me giving me a few hints
If its blind, you have to do error based sql injection letter by letter. Either that or sqlmap
Sqlmap automates it for you
You can take a look in #start-here
If you can I donβt see an issue
If you can I donβt see an issue
It depends on the room.
You wouldn't use an attacks that disrupt the network for the network based rooms.
When QA test a room, one of the things they do is search for any unintended methods of attack.
well im not able to differentiate/identify which one of those attacks was performed by me
Fair, I assumed it would be like htb where other methods of exploitation usually become part of the walkthrough
But makes sense
if its a walkthrough room, its best to stick to the script, as the aim is to learn that method of attack.
Then I suggest you re-do the room, and think about what attack you're using.
I could tell you the picklerick room has an Idor and you could add it.
it's not blind after all
it confused me that MySQL had a table called Dual
i thought it only exists on Orcale
https://stackoverflow.com/questions/33378732/whats-the-best-mysql-alternative-to-dual it's a dummy table
it's omitable in MySQL
Hey y'all!
So I remembered I was helping a buddy of mine build up his cyber security company for five years. I made cold calls, set up appts, and even caught McAfee's attention as they wanted to negotiate a contract with us.
Unfortunately that small company went under after the pandemic.
I was wondering how I can use that experience to my advantage in this rough job market.
I didn't do anything technical; no pentesting or anything like that, just more administrative work. Although my buddy did educate me a lot on the technical side of IT security.
Any ideas on how I can use this on my resume? I don't want to embellish my experience, but at the same time I really need to start adding anything that can get me some attention.
I used to be the same but then I realised they are just people. They are probably just as nervous. I told myself Iβm an actress and Iβm playing the part of confident Michelle. Told the negative voice in my head to F off and then got on with it and did the best. Even managed to quiet the heart thumping in my ear
that kinda reminds of psychonauts
What interview you got hired?
so, how did go for confident Michelle? π
might be worth posting this in #cyber-and-careers so that it isn't lost in #general and also there are definitely people who frequent there who'll be able to give some advice:)
Awe sweet, thank you.
Gave +1 Rep to @lone thistle (current: #7 - 822)
why it shows that im still connected to the vpn if the vm is off?
I answered 99% of the questions without hesitation
At times I did ask if they could give me a sensation or reword it but I answeref
I hope you get it π
did you kill the openvpn process before turning off the vm?
yes
Whatever happen happens. Iβm happy about the small wins
oh nowit shows not connected,just took time
Confident Michelle FTW π
Yes
My pc screensaver is a pic of a lambo and a yatch and rhe words I can and I will ahaha
What job position?
Security operations analyst dlp
Nice. I start working in SOC at the end of march. Had 3 interviews and one technical homework.. But i managed to impress them,so much they wanna pay for my SANS certs (which i dont wanna do..Gimme OffSec blood)

Aww thatβs good
They asked me if I was doing any courses and I said I had started the isc2 cc cert
HEY! Don't dox me
he ?
well... you ahve 2x size bigger eyes π
google: flemish rabbit
cmon. they already asked you not to dox them.
i want problems all the time π
Which one you are going to get first?
long time no see
yup
u saw the new creta?
ial;ehgioeahglk my card is declining thm premium
That's not good.
Your bank than it's bad?
probably
and now the paypal option wont show up smh
Kick It.
you kick it im not a mod
Your bank lol.
I have a question, what is the difference between a host and a client?
did repl change its free hosting
Ψ
host is general term for both clients and servers
Hey there Jazz π
vain
nope, been under a rock for the past 2 weeks haha
in pain
well yeah
how much time left?
This means that the worker is me and you are the user
craaaaaawling iiiiiiiiiiin my skiiiiiiiiin?
i realised the big cars have the same price range π±
Im gonna start with OSWE,then OSEP and last OSED. I have to ascend 
What?
But those are not SANS ...
Yeah those are from OffensiveSecurity. I dont wanna do SANS,they are so pricy that i will concince my firm to pay for offsec instead.
This means that the agent is the user
πΈ π«‘
You're not SANS
A lot of companies actually can get price off from SANS
You might have hard time convincing them if your work is in SOC
What?
if they're willing to pay for the more expensive cert, why not take it?
If they hired you to SOC then they likely expect you to do SOC work not offensive security work, there is no point really hiring someone into SOC if you are training for them to leave this environment, it doesn't make sense from the business side
Good luck
I am not sure I follow what you are saying
its in a company called C security, they train you for 4 months before the work
and it will be devops or cyber job depends on that
My brother is dressed
okay
yeah, but what position?
Artificial intelligence will replace developers
i dont know
ok π
Do you have proof of this? π
?
AI will replace artists
how can you not know what position you're interviewing for?
she said on phone the position is based on the 4 months course and it will be subjeced to devops or cyber after that, thats what i know
Ah, I see
spray CVs everywhere
Didn't you see what GPT Chat is doing?
i send 2 days ago to 5 companies and they answered me
Being confidently wrong multiple times?
chatgpt is like one million monkeys randomly typing on typewriters
Morning. Happy Pi Day. π
ChatGPT makes so many mistakes
please can help me with linux privilege escalation task 5?
what is this?
You can ask in #room-help
happy 14/03!
This was said by the CEO of a company
Must just be a US thing because of how e do dates.. lol
ai
Damn mobile.
Oh, then he must be right ^^
Yes, for sure
But cybersecurity has a future in artificial intelligence
this is what my friend sent me 
There is a new βAIβ which is much better at developing software but I donβt think it will replace developers
Only make it easier to write code
it has a future everywhere. but the future is infinite in length
Which one? Some french company released their AI recently and apparently it's much better than GPT
Introducing Devin, the groundbreaking AI software engineer that's revolutionizing the field of coding and problem-solving. Devin is the new state-of-the-art on the SWE-Bench coding benchmark, showcasing its unparalleled ability to tackle real-world engineering challenges.
What sets Devin apart? This cutting-edge AI has successfully passed pract...
AGI? doubt
This is what we hope for π€
I take no credit for finding this video, this was shared by an employee
Co-Pilot are releasing a a security version in April 1st too.
I think that it will even replace film producers and actors 27%
Blackbox?
or
AI is certainly going to busy.
again, the question isn't if. it's when and to what extent. we're probably talking years if not decades for that level of sophistication
Itβs on the video :)
oh xd
Yes it will be busy Penny
Yes, I think in the future
I posted another one yesterday in #1096897654962786434" if you want to see more)
Deep inside, i hope AI is going to be a flop
Why?
I think Human Intelligence is decreasing from it
in what way?
How do i do gif ΨΨ
People are becoming too much dependent on ai.
I think, used and made in the right way, it can be a massive benefit and fantastic tool to utilise
Maybe yes
But i hope the big tech companies dont take it too far
id assume you need to verify
hard thing
Verifying?
It's super simple to verify... lol
Max Fosh
^ You can either do it here, or message it to the bot, just go to you THM profile and find the discord token, you type /verify [token here with no brackets]
Not to be confused with Walter Frosch
Hello guys π
How are you, man?
Am good
I have decided to make here my community and to learn from you guys. I have decided that I don't want to go into certifications, i Want to gain more skills and get experience which is the most important
So I want to continue with my Tryhackme course
No I didn't....my phone got spoilt
I had to get a new one
Ah, and you forgot your discord login details?
So everything wipe out
I couldn't remember it
Which was bad for me π€¦πΌββοΈ
So how will I become verified?
Welcome, man π«‘
Thank you β€οΈ
Gave +1 Rep to @dense cedar (current: #2025 - 1)
what do you study
Bsc computer science
That's good, keep learning
Thank you
Where are you from
I want to go into cybersecurity am a Newbie π
Nigeria
This is nice and cybersecurity is really fun
Hello, we are neighbors π
Yeah and I found Tryhackme as the best place to learn π
Where are you from?
I have a nature that many people find in me
Morocco
Hahaha do you like Morocco?
A lot π
offincef securtu
Have you ever come to Morocco?
yees
No but I heard a lot of good things about them
Welcome
I just started the pre security and you?
1 year 6 months ago
Wow you have gone far π
What paths did you do?
i love this field
He studied A+, Network+, Linux+, Security, and many more, but research skills are one of the most important things
And tryhackme paths?
On Tryhackme?
Yeah
Wow
Currently doing the Active Directory module
Btw, is this the new GUI or the old one?
new
Great observation 
what's happend with GraphQL room ?
@hasty sand ppl says 3rd charm work... if you here let me know if i can DM due to last convo we had π
because i was try to find and i didn't see
I don't see it either so it may have been retired would be my guess.
π¦
Guys anyone have Tryhackme subscription
ππ
f
A lot of people are subscribed to THM
who have a video how to setup burp with foxyproxy
I want to learn SOC L1 and L2 and junior pentesting i am not in that state to purchase new one π
So sometimes giveaways are held here, but most of the rooms are free
Burp and foxyproxy are already setup in kali.
like with extensions
Yes you are right but those are.just basics soc L1 need subscription
@shut hawk i joined THM right now with my acc on proton mail id . Is it fine to have proton acc instead of gmail? if yes i'll take subscription
Uh, I don't see any reasons why having a proton email would be not ok
You should be able to get a sub on it just fine#
I've just checked and a lot of the rooms on there don't need a sub
SOC L1 does not i have checked
ok thanks , one more doubt, the certificate issued will be on name added there or the username ? i want it on name
Gave +1 Rep to @shut hawk (current: #13 - 486)
If you've put your name, it'll use your name - otherwise it'll use your username
Okay
Where did you get it? π
looks like base64 with the trailing ==
Tried all but not able to crack
My friend has sent me this
And where did they get it from? π
Let me ask him
Ideally, in this server we don't help people with external active ctf's or applications as this would be cheating.
Which against the server rules.
perhaps its been ciphered multiple times
that's a flag.. it's a challenge.
Okk i will delete this
please help me
looks to be potentially from PicoCTF
Its from Pico
You were right. π
called it π
Must be the ongoing CTF there doing then
@fair fable please don't ask in here for help on an active CTF.
@boreal scarab dont use spray for hot bed stick prints. zt last on large prints... can't unstick it =/
Okk sorry
Thanks.
Gave +1 Rep to @fair fable (current: #2025 - 1)
What is robocop @sick lance
A discord bot, that uss a rep system
Don't worry, I used glue on a GLASS bed, and had a large print that had a lot of points touching the bed..... that day I cut up my hand so many times just trying to get it off XD
Don't worry, I'm fine, no hospital or anything, small cuts
i used spray thing... mother of god... lol
Now, what should I do for lunch?
Eat food.

What is rep system
nothing aside for fun and that admin can see how much some user is "nice" π

How to join fluff clan
it's cult
It not security group ?
It's too late.... We couldn't save him.
one of them.
one of them.
one of them.
one of them.
it's cult fot fun THM users or so
Okk π
We managed to save one.
progress progress
Fluff clan seemed to take out the cooctus clan
someone was saved?
what from?
from the ... Nooooo!
from bad influence...
time pass from saved user of fluff cult: <t:1710435506:R>
Who is enjoying the Ramadan atmosphere here?
What are your thoughts on the new look?
omg, THE skidy
Good evening Skidy 
Hi all!
Hey Skidy. The look needs a few tweaks due to the contrast, but looks good.
Hello!
Not sure if this is the correct chat room, but
I was wondering about how to do the CTF boxes that correspond to the learning path?
For example, I just finished web enumeration, is there any method to search for it(linked to the learning path/modules)?
I'm sure you'll get the bugs worked out.
sup sup
will the new look have dark mode?
not yet.... apparently
It will, you can find the changes in our improvement blog
You can search for tags in the search box.
time to break fast
thanks jabba... that is harder to find without your link then shadow would like to admit
Clan!
lie!!!
It should be in the notifications section of any of the updated pages π
still probably gonna use dark reader as it has colour themes option
Jabbbbbba. What should I have for lunch?
Salad
Can we/you link the CTF boxes to the modules/learning paths in the future?
After you finish the Introduction to Web Hacking section in the Web Fundamentals learning path, you should do these CTF boxes to practise and such?
And thanks for the heads-up 
Gave +1 Rep to @sick lance (current: #2 - 2053)
Alright not Jabba..... Shadow π
Does anybody read this as 5treak required?
pasta alfredo
Yeah.
that seems like a typo or a bad font choice or some clipping
I seen steak first though, I'm making dinner as I'm hungry.
I can do the box without the streak required
Not a typo, it's an s but I think the font could be a bit better imo

Sub overrides streak.
is that a good or a bad thingy???
Good, I just realized he looks sad XD
I can now that you mention it.
Maybe I'll do that for dinner
@whole yew You seen the new finals season?
eugh shadow feels spent... but they have more room testing to do....
but thank you for your hard work
could take a break but then this room will not be as heavily tested as it could be
hello there!
Hello!
ello ello
General kenobi!
General Kenobi?
Ohh damn ok XD
what's it ?
Star wars!
oh, i'm not that much familiar with it
you should, it's good
okay, i'll try
shadow knows a person that has not watched the following:
star wars
lord of the rings
star trek
harry potter
not watching lotr is unforgivable
Anime anyone ? Ive been watchin solo levelingβ¦super epic
yeah, i'm here
not watched any anime since cells at work season 1
Last I watched was chainsaw man
i didn't watch any of them yet : )
love anime
U should watch solo levelingβ¦we r just at 8 episodes
meh
Oo yea i watched a bit of thatβ¦the theme song was bangin
getting anime is hard and expensive
Wym ?
i've covered 2 episodes only
thank you @wintry sluice
Gave +1 Rep to @wintry sluice (current: #269 - 18)
due to academic pressure, it's quite tough to manage time for watching anime
Understandable
: (
aanime is weird. seems to have a weird obsession with power levels.
@shut hawk RM2 go to my sister... =/... i prob need get new one...
@wintry sluice yeah, its not for kid
technically just finished avatar the last airbender but would not call that anime
Yea deffo not XD
atla is awesome. try the dragon prince (made by the same people)
was thinking about asking to borrow the avatar the legend of korra blu rays from friend too Β―_(γ)_/Β―
how was that ?
i heard that its quite interesting
Monster. This anime is on another level
Kenzo Tenma
it was really really really good
it ranks very high even on imdb for any animated series
it is ranked 12th on imdb:s most popular tv shows
just the reason to get one! π
yes not only in animated ones but for all tv shows ever
tru tru
i need to watch it then
ah yes monster
somehow shadow failed to finish the last 10 or so episodes of said series
@rapid merlin is light your favorite anime mc ?
Scott Chacon's FOSDEM 2024 talk on Git Tips and Tricks.
Scott talks about:
00:00 - Introduction
01:06 - About Me (well, Scott Chacon)
02:36 - How Well Do You Know Git?
05:09 - Our Agenda
06:25 - Some Helpful Config Stuff
09:42 - Oldies But Goodies
16:22 - Some New Stuff (You May Not Have Noticed)
23:48 - Some Big Repo Stuff / Monorepo Stuff
33...
I only love these three anime's monster, death note and baki
Johan and light are just super cool. They are my idols.
Light as an idol? π¬
light is my most favorite mc in anime
yeah, i don't see anything wrong in light's ideology
guess someone has not yet watched the movies of death note series
Ugh movies ain't that well
yeah, i think so
If you like light. You gonna love Johan too
Cant tell if sarcasm, haha. Anyway, was also a big DN fan but defo on team L. Light was a great villain tho. Read the manga many many times
i don't know about Johan but i'd prefer to take light as my idol too
searching for places to watch kara no kyoukai again*
He's from monster. You will love this series bro
i think so! i'm going to watch it soon after my midterm then
thanks for your suggestion @rapid merlin
Gave +1 Rep to @warm pier (current: #2025 - 1)
Naoki Urasawa is great in general. If you like Monster, recommend to check out his other work
poooh ty
Gave +1 Rep to @shut hawk (current: #13 - 487)
u forgot chefs
ππ

hey you are more then half way there lepiz
Would it be against TOS if I stream THM content?
Just be sure to not stream the new THM THM challenge rooms before 72h
You can ping Jabba if you have more questions
Director of soc was impressed by my enthusiasm for ethical hacking and he already confirmed that i will eventually get to work with their small team of pentester experts
Let me cook brooo 
I see, that's nice, maybe they let you also get red team sans then π
And if they do always remember "sharing is caring"π
Hello Android.
π
Been along time.
I am no hacker, I am just good at being persistently annoying π
good evening all
GIF is taking ages to load.
listening lectures is boring as fk
Yeah, might be discord issue then
start taking colorful notes to make it interesting
No problem
I think you just need to verify your thm account
There's a few gifs taking time to load.
But mine loaded perfectly fine
Might be a good idea not to send gifs if they don't load, best not to spam up chat.
Boo all you want.
I'd rather not have general flooded with gifs that don't load, it looks as bad as a giant wall of text that's been spammed.
That won't look good whilst I'm on trial
Or in general
It's a Discord issue, they have registered it on their status page
Lol how did u saw boo
I copied the link and pasted it in a URL which showed me what it was.
Yeah, I thought so.
Good job I'm not a wrestler then Android.
I love when it's so nice out, grab a nice fruity adult beverage, relax.
has it affected attachments or just gif's
All media upload
Yeah, I've uploaded a few things to my Unis discord and it won't accept them.
Rip gif
Black Mirror returning 2025.
nice
People who use earpods, or wireless ear buds.
Is it just mine where one loses battery faster than the other?
Making my own CTF today, so damn fun watching it all come together
Depends on what you're listening to
yes. depends on the model/obvs product, but I know with airpods at least with how they work, one ear pod (assuming you are using both) is responsible for communicating with the phone and then sending that to the other airpod. It depletes quicker because it's doing more than the other
@naive violet my ADS-B is getting 300 messages/ sec, same spot as it's always been, haven't moved it from the ground level. Need to plan out where I wanna permanently put it.
Huh, wow, I did not know that.
No, but I only wear one earpod at a time so
I use a crappy pair from Amazon.
I do have a problem where my right earpod is a lot louder than my left one βΉοΈ
Sometimes when I have my galaxy buds in and I want to listen to music but also talk to people, I keep only 1 in. I know you can have them to where it passes outside sound in, but it sounds too weird to me
plus iirc only one at a time gets designated as the microphone, so if you're on a call or summit, that'll contribute. IDK if noise cancelling uses both or just one mic but that might have something to do with it as well
I got an LNA and I've had satellite up and running
Got a bit more software to set up for it though
Make it yourself, or bought it?
LNAs are hard to make yourself IMO
Active components, lots of factors
I got another RTL too, so that I can run satellite independently
RTL SDR v4?
Nooelec again
Oh nice, I know @normal fable Is in the market for an SDR
V4 doesn't offer much considering I have a SpyVerter for proper HF coverage
I know v4 has something built in. Doesn't the v4 have noise filtering built in?
Upconverter?
I'm kinda looking at the Radioberry..
Is that what is in v4?
Don't know if it does all I want.. but maybe..
Yeah some filtering and an upconverter, I have the spyverter as an external upconverter. More modular.
You going for TX too then?
currently debating which company I want to take my MC drivers license with 
I kind of want a Lime SDR and if I get one I'll do some more QO100
I'll probably get a Radioberry and do a full breakdown. lol
Yup, upconverter, had to look it up.
Your minecraft? π
Motorcycle π
2 wheel?
I have a 2 wheel endorsement.
BRC was good. I'd recommend anyone take the course. (Basic Rider Course)
Whats the theme of challenge?
https://v3.airspy.us/product/upu-fp1090s/
I still have have this between my radarbox ADSB SDR and my antenna
Helped A TON with message rate and some extra miles in range
The issue I have at the moment is that I want a filter with like 10% bandwidth
Which is a LOT for most filter constructions
Either that or I just need a very sharp high pass
Aimed towards more beginner level CTF players. It's Broken Authentication and RCE on the web server, then to multi level privilege escalation with different methods up towards root :)
Can check it out here if ur curious, ive just dropped it on my github.
*FYI: Only the Docker version is available to get to root *
Spins up in a single python script, was initially made for playing around making a OWASP inspired vulnerable web app but then turned into a full pwn box lol
Anyway to construct something easily for that use case? Or is it a very niche issue that's hard to find a suitable device to accomplish that?
Yes you can do it, but it needs kit I don't have
Or spending like... $60+tax
https://www.minicircuits.com/WebStore/dashboard.html?model=ZABP-450-S%2B This'd be ideal but cost
hey guys quick question
when you create a CTF and want to do a networking challenge using a foreign protocol, how do you fake it?
Not sure what you mean by foreign protocols. What protocol are you trying to incorporate? Protocols are usually defined by an org, an I am currently blanking on the name of it. IEEE?
No, that's not right
JetDirect
not really foreign but still
I'd look to see if you can find documentation on the protocol
Looks like it's also called AppSocket
yeah i has multiple names
wdym? It's being used in a lot of printers
Like technical documentation for how it works, because you want to implement it
Would you say making your own room / challenge is also a good way to learn the topic itself?
You need it to be doing stuff for people in the CTF to find, don't you?
Otherwise it looks like it runs on port 9100
yeah but couldn't I just record the data which my flag is in? The idea is to show that the procol isn't secure at all
it on tcp
its basically sending a page description language file to 9100
https://github.com/kenyapcomau/p910nd
Looks similar
Short answer? Yes. Long answer? Iβd say it depends how much effort you want to put in. I found a lot of the methods Iβd initially thought of are things Iβd already known. But thereβs nuances about almost every part of setting a box up so flattening those out to get it to follow a path that you want it to is definitely a learning experience.
I definitely got good docker experience, spent half my day in the dockerfile π
@mossy river
Yeah my question was more root of - Should I start making rooms of something I already know well, or something I can learn on the way
@misty frost please don't sell vouchers here.
looks cool, ill check it out
thanks!
Gave +1 Rep to @shut hawk (current: #13 - 488)
Honestly pick something you think sounds fun, youβll learn even the hardest stuff as long as youβre passionate and willing to take the time to learn it.
For me the project started as a simple login form that I gave a demo on to my cyber clinic yesterday to present packet sniffing over http. Then today Iβve just been adding bit by bit, but only because I enjoyed it :)
PI DAY
hmm
it only works where you have a weird format π
its steam sale today also
you calling iso 8601 weird???
Should I buy or not
Nice! Im also plannin on creating series of 2-4 challenges,all connected together with story and comic book,made by me. Its work in progress cause im i barely started doing storyboard. This is gonna be new take on CTF! 
Sekiro is my favorite game of all time,if you love hard games and blade of immortal,get it!
I would easily do that only for the price of Sekiro
Sekiro is a freaking awesome game!
hmm
Hei at least he didnt trow shit at you like monkeboi..
how many thousand times did yall die?
Weall died about fiddy times yo 
A couple of thousand times, including 2 keyboards died....
Just the average gaming experience of souls games - still easily worth it ( :
Noice!
Fucking finally
They reused some stuff but overall its really impressive. Lazy devs should wathc and learn from FromSoftware.. THere is no need games to be over 25-35 gb
Make it quick
lets make it 2tb
I dont believe you played agmes in 2007 but that was the year of Crysis and the game was new graphical benchmark for about 5-6 years. And it was only 6-7gb lol
Thanks
@twin ridge thanks
Thanks @twin ridge
it won't work

every time a crysis game releases the video game world does a flip
Thanks
Gave +1 Rep to @chilly veldt (current: #8 - 818)
Well only first one is good lol
Thatβd be so sick! I kinda wish I did a theme to mine now. Especially given Iβve called it doombox - could be some huge doomguy references in there π
... All I need is to buy more games that I'll not play. Lol
Remastered..
rermastered has better graphics
GET OUT OF HERE
You mind giving it a go sometime? Trying to get some feedback considering itβs my first official box Iβve created
Against fully modded Crysis 1? no sir.
... no comment
Im kinda newbish to give feedback,i never did any CTF rooms.
In terms of creating them.
Oh thatβs fine! I just mean trying to complete the ctf. Iβm wondering what the paths to root is like for someone that doesnβt know the box haha
Iβm kinda biased since I created it 
Is it for THM?
It was initially for my cyber clinic but Iβve turned it into a full CTF. I can always submit it to THM tho :D
If you want to submit it to thm QA ask you don't give it out.
And we don't allow advertisements of ctf external that you've created.
The intention wasnβt to advertise, I was asked about it. But I get what youβre saying.
Much appreciated.
Who do I ask about submissions?
you just submit it on the website
It looks good to me π
Only the Access Machines button looks a bit strange to me, idk why
You just make the room public and it goes in to a QA queue
dang it. just saw most of the devsecops path is behind the paywall. guess i have to buy a THM subscription again.
That isnt a bad thing btw :p
Is there a specific format required for submissions? Currently set up as a docker
Text looks lower than the red circle?
Has to be submittable to the uploads page
Danke, shall have a look when I get home
super glue and neodymium magneets make hell of combination =/ (in not good way)
That sounds like a sticky situation
btw, anyone know any good pluralsight courses? I still want to get something out of the company subscription while i'm legally allowed to access it.
Yeah but thats with the old one too
But idk
more alike shitty situation
π¨ it. π
there is no point to buy games, i dont have time to play those that i have atm
I want to find a good game to get into.. but I keep getting back to Minecraft. lol
I'm having issues connecting to my VM on thm
I'm using openvpn in regular and also tried other servers but the result same
i have few too many
#site-support please π
...
everything
how's callisto protocol
idk, i didnt play it lol
read somewhere the facial expressions in the game are next gen
My favorite game on Steam so far is Sheepy. lol
lol, where can i see that?
Happy pi day
I go to Profile > Games in the browser.
I blame it/programming and cyber-security, it has ruined me - i used to have fun any play games like 20-30h a week now its only 5ish per week. and most of the time i study.
Jesus
those are steam hours
You know what is a nice game? Shadow of the tomb raider.

That's 300 days of play
10 years or bit more
Same i think
but for how many years did you play it?
Diff for streamer
That's work to them
I have 15k hours in work
for me about 10or 11 years,
I'm not a big pc gamer anymore.
My mobile workstation has a T500, but I only use that for hashcat. (It's not great, but it's better than nothing).
Me using my 6750xt only for hashcat π
im happy that i reallised last summer that i must start studying, and investing to the future, it took me from python to (all over the place) jupiter notebook, nlp, javascript, backend, data science, etc like 6-7 months, to find that i like security part the most.
8+h a day study
tryhackme is really nice place 9th day atm
Do it other way, blame games for starting only now
I am glad I stopped Dota, who knows where I would be now ...
β€β€ Thank you for listening! Subscribe for more.π ππ
β€β€ Turn on notifications (π) to stay updated with new uploads.
β€β€ Click "SHOW MORE" for artists and photographer's info and download links .
πΏ EXYZ & SENZO - KOSHIRO
π½ Genre: Trap
β¬β¬β¬β¬β¬β¬β¬β¬β¬β¬β SUPPORT THE ARTISTS ββ¬β¬β¬β¬β¬β¬β¬β¬β¬
πΆ EXYZ :
https://www.instagram.com/exyz_muzique/
https://twitter.c...
In fact, my curiousity in cyber sec is because of Minecraft
Heh
Got my first SQL injections done there
cracked servers with plugin based authentications were the best π₯²
Warthunder isnβt bad
u always send this meme, always confused about its meaning
as background music i like Hip Hop Lofi Beats ,
I don't think its a meme π
gif*
It's just so happy and carefree
windows web server is a nightmare for me
IIS?
the thing is it should be easier because most part of the time windows web servers comes with system privileges xd
ye
but its ok i just be like "what should i do now?" when it comes to windows server xd
I love IIS.. it's so.. easy to make do what I want it to. π€£
when its linus i already know what i should do and what to look for
but when it comes to windows its like my brain fails
brain panic xD
i just have a question how u get rdp on windows? i mean do u find the credentials to login or u have to crack the hash?
I actually haven't hit IIS for a looong time.. I need to dig into it agian some time.
every time i get into a win box i dont know what to do after having a web shell or something lol
haha
Lofi hiphop and retro/synthwave
Here lately though I got into darksynth
No idea how
Feels primordial
If you get a shell, then you're pretty much golden. Especially if you get a system shell.
ye
There are tricks to do. Check out the AD rooms. π
but how do u escalate that shell to rdp?
alright ill check thanks
Gave +1 Rep to @normal fable (current: #60 - 112)
I'm not sure we're supposed to go into detail about things like that in general. May be more of an advanced topic.
i really have to work on my windows networking and admin skills
it's relaxing deer jump on lake... π
Always makes me π
Spanglish lesson done for the day. π€£
Usually you don't need to
Windows is entirely different world but linux, but I highly recommend learning them
not even when doing red team ops?
ye i really need too ... because i feel like my windows admin / networking skills are pretty bad
In windows, shell and rdp are slightly different than in linux
Especially in AD environment
since you have AD accounts and local accounts, and both function slightly different from each other
What do you need a GUI for?
yes plus UAC, register and etc
in case i needed to have more control of the environment im on
GUI is not for me.. and if you have system, you are the computer. lol
Yeah, those things and many more
More control? That's what a terminal is for
need gui to see the post it notes sticked to the monitor 
not for me either xd so in this case should be more effective to understand more about admin etc using the command line
LOL
Have done my fair share of windows, honestly if you are past automatic exploitations, you can be quite satisfied with yourself
not easy stage to get to
Under the keyboard... π
Most windows rooms be like "use this metasploit module"
usually i have to search up stuff because i usually forget some commands
need to make a cheatsheet just in case
ye thats true
have to take notes on everything, just not a cheatsheet.
I don't think its necessary to learn commands by heart, just learn to recognize them, eventually you remember them by heart if you write them enough
powershell .NET style can be quite unusual to get hang of
ye thats what i do
i dont make good use of powershell
just in case i need to run post exploitation scripts or something
Which powershell could easily do
Powershell is way better than GUI..
in CTF-s you often could find powershell to be the exact thing that gives you the privilege escalation
Though usually its just some process that has way too many permissions π
no problem, good luck
any recomended virtual box for mac?
oracle isnt supported
fusion by vmware
thanks
VirtualBox should work on Mac..
its not free?
it says unsupported hardware architecture
Which chipset you got?
M1 or M2 chip?
m1 pro
Parallels or fusion would probably be best bet then.. Not sure though. I don't run Mac hardware that new. lol
can i ask a question
Might be able to get kvm running on it??
how many monitors u guys have ?
i have kali on my desktop but my nic doesnt support monitor mode and i cant complete the wifi cracking room, so im trying to do it from the mac, will my mac support it?
2.5
Hi, Could someone explain to me why find is at the end of the command?: sudo LD_PRELOAD=/home/user/ldpreload/shell.so find
More than likely no.
Google it, you may need to have a USB Nic card though
Find is the program being ran
i have 3 but i with i had 4. do i have a problem ?
i did, i followed many solutions it isnt supported
Yeah. You're down one monitor. π€£
I have a 24" and an ultra-wide monitor.. then my work laptop..
and a very messy desk at the moment...
good eve
sscrubz could you reccomed a wireless adaptor to buy to add to my desktop to make it work?
Argument
2 π
Look at UTM if you're looking for free. Fusion is slowly getting better, but yes, that requires a license, similar with Parallels (though parallels would be your best bet in terms of performance and compatability)
thanks, ill try both
Gave +1 Rep to @lone thistle (current: #7 - 823)
but the argument can be any executable and the result will be the same? finally the find does nothing because it will return a shell with privileges
It absolutely can
Have the OS be ARM64 if you can - it runs basically native. x86_64 kinda ... sucks on UTM at least in my experience as it's "emulated". Getting better slowly...but everything like that needs time to catch-up
It returns it with privileges because its preloaded with sudo
Ah, sharing screen with friends
thank you
Gave +1 Rep to @past sparrow (current: #509 - 8)
Hello, I want to get OSCP but I'm new to cybersecurity. Should I register TryHackMe first to learn or go straight with Offsec OSCP?
learn stuff first
Would suggest THM first, so you're not wasting your money if you don't finish oscp
which you will not finish for sure
Got it. Thank you for your advice.
Learn A LOT of stuff first
It's not a thing you just jump into without any knowledge
if my wireless adapter doesnt support monitor mode, so i cant use tools like Aircrack-ng, will there be more limitations to similar tools?
Thanks mate.
Gave +1 Rep to @past sparrow (current: #474 - 9)
You can get a USB wifi adapter that supports monitor mode. Alpha makes them. Not sure on the model anymore.. I have one somewhere..
I'm sure there are smaller ones by other companies too.. but not sure how well they work.
To use Aircrack-ng u need a wifi card that supports monitor mode (Most laptops do that), however to send packets (Which is what u do when wifi hacking), u need a wifi card that also is capable of sending packets. (U can usally get one on amazon for like $15)
Idk your computer knowledge, but there's lots of things u need to know before u can get a job in cyber security.
(1) Learning computer science (How a computer works).
(2) Learning the fundamentals of windows, and Linux.
(3) On THM I recommended learning every course that says (easy) as though teach u more fundamentals of computers.
Theres more, but im to tired to think of any.
Yes, I know that cos I'm graduated in IT.
Awsome
I just considering of OSCP fee and course with THM.
@mossy river can vote
If I'm thinking of the roght thing it's around 1500 usd to take the OSPC exam.
what's ojos rojos ?
Don't pay for the OSCP yourself, get a job and get your employer to do it
@stone osprey was wondering.
Also, smart.
yeah, that's a good choice
helldivers
Sheepy. π
well time to launch helldivers until I crash it
U know what? I just moved from Cambodia to Australia. Im work at KPMG as IT Auditor but after arrive in Australia I can't get a job because of not yet become resident.

