#general

1 messages · Page 76 of 1

loud marlin
#

yea. only home craft using

#

one more try... @hasty sand might among alive ppl. to DM if you free to continue last convo ?

versed coral
#

Say I found a exploite on ubers app where would i report this?

loud marlin
#

to them ?

versed coral
#

I'm assuming on hacker0ne

#

Directly or?

sick lance
#

Check of they have a bug bounty or a security text.

versed coral
#

Like its quite serious

loud marlin
#

if bb then might get some $. if not then direct toi them

versed coral
#

Alright

echo steeple
#

man, i'm a big believer in the hacker codex and that you should only do good with your skills, but damn, i would have to lie if i would say some people wouldn't absolutely deserve to get all their stuff pwnd

sick lance
#

That's not a very pleasant attitude.

ashen wadi
#

I would love to hack pedo cabal

loud marlin
echo steeple
#

not saying it's the right thing to do or that anyone should act on this feeling, but damn, some people just would deserve it. like, i would love to quote the doctor into these peoples faces sometimes. "good men don't need rules, and today is not the day to find out why i have so many"

hearty plover
#

Guys i have a Question.
Tryhackme is built to simulate real world usecases regarding the machines and their way in and how to work with it. But sometimes there is steganography involved. Now the Question: Who uses Steganography in the real World? :o?

#

Not who, but which Company and better, why?

loud marlin
#

steg is not used direct in company. if you wish make data safe you encrypt it.

amber quarry
polar spoke
#

Stego is also a pretty broad term

#

plenty of stego is in use, but its not for the things you might expect

loud marlin
polar spoke
#

various forms of image watermarking and document marking could be considered steganography

amber quarry
#

Yeah I'm sure it's actually used for something but not for hiding a RSA private Key for example

#

Remember that not all CTF seek to have high realism
Some are just made to show you some kind of technology or concept which could be useful in very specific cases

hearty plover
#

cant say enough how i love the community. i was curious had a question and 5min later 10 replys

loud marlin
hearty plover
#

Thank you guys very much man

cedar scaffold
#

thor from piratesoftware showed his password for twitch once I think on stream that used steganography brandon

amber quarry
shell nova
#

🙄

amber quarry
#

@echo steeple u ok ?

loud marlin
amber quarry
#

Sheeeeesh

polar spoke
#

also there's certainly some stego in places where you might also find crypto

#

e.g. anti-censorship layers for networks like tor

#

or for some C2 comms

echo steeple
shell nova
#

Data exfil maybe, doesn't seem to be super efficient though

amber quarry
polar spoke
#

the anti-censorship and watermarking use cases are more common but yeah, C2 comms could certainly make use of various stego tricks

loud marlin
#

does metadata effect hash result of files ?

polar spoke
#

depends on where it's stored

shell nova
polar spoke
#

if its stored external to the file, no

#

if its metadata like on a photo, its in the file, so yes

echo steeple
loud marlin
polar spoke
#

magic numbers or magic bytes are strings of bytes in the file

#

so yes

echo steeple
#

the "i show you my private key if you show me yours" reminded me of the chorus 😅 Shannon Morse really killed that chorus

loud marlin
#

aha... nice to know. so hashing of files takes all the things about file stored into file and make result. so any changes in backed it effect result

polar spoke
#

hashing consumes any blob of bytes you give it, whether its a file or just some data youve supplied

#

if you change any of those bytes, the hash should change

#

so for files, if you change any byte in the file, expect the hash to change

#

but some metadata may be stored outside of the file itself

#

by the OS or other applications

loud marlin
#

understand now yea

spiral dagger
#

how to install windows 10 in linux ?

sick lance
#

Use a hypervisor.

polar spoke
rapid merlin
spiral dagger
#

i want to install windows machine in my linux/vmware

crude stump
rapid merlin
#

You need like 50gb free tho

#

Windows is bloated af

sick lance
#

Windows N exists.

spiral dagger
#

i have 50 gb

crude stump
#

if thats what you're talking about

spiral dagger
#

can anyone help me out ?

crude stump
#

we are trying

rapid merlin
#

Download from here

spiral dagger
crude stump
#

ok

#

then give a little more detail

sick lance
#

You would like a Windows VM in your Linux host OS?

Or is linux inside a vm, and you want a vm inside the vm?

rapid merlin
#

Inflates to 50

crude stump
rapid merlin
#

My poor laptop knows the struggle

crude stump
spiral dagger
sick lance
spiral dagger
#

getting my point

#

linux

rapid merlin
#

You’re running Linux and want to install windows inside VMware?

rapid merlin
#

Fair, you’re just wording it awkwardly

#

Hence the confusion

#

I imagine

#

Unless I’m very wrong lol

spiral dagger
rapid merlin
#

Linux is like a car

#

Windows is a car

#

You can’t put a car inside a car without something in the middle

#

Like a hyper visor

#

A hyper visor is like a shrink ray

#

(I need coffee)

spiral dagger
#

you send that link is ok i guess\

spiral dagger
rapid merlin
#

What’s the goal anyways

crude stump
#

thats crazy

rapid merlin
#

Made me laugh, I like this guy

sick lance
#

@spiral dagger absolutely not.

spiral dagger
#

hahahaha

spiral dagger
sick lance
# spiral dagger what /

I deleted your message, we won't be helping if that is the reason you'd like to create a windows 10 vm.

spiral dagger
#

no no its joke buddy take it EZ

#

reply now ?

sick lance
#

That isn't a topic to joke about in this server.

spiral dagger
#

what happen @sick lance SureBruh

#

i apologise

#

my file downloaded can you do setup @sick lance

#

@rapid merlin hey buddy hows you

rapid merlin
#

Good, you?

spiral dagger
#

where are you from

#

?????????

ashen wadi
#

What did he mean by "virtual..69" !

spiral dagger
crude stump
#

wow

rapid merlin
shell nova
#

At this point I'm too afraid to ask

rapid merlin
#

I’ve been avoiding a haircut for months but now I have to face the machine

crude stump
#

dirty joke in his name

rapid merlin
#

October, I have curly hair so it’s just been looking ok

#

But now it gets in my eyes, especially when I sweat

ashen wadi
#

Then stop sweating?

spiral dagger
#

googlr told me why you need vmware use my windows machine

rapid merlin
rapid merlin
ashen wadi
#

Google this "How do i learn to google"

#

Its like googleception

crude stump
#

google "Google how do i google google "

rapid merlin
#

You’re gonna break the internet

boreal scarab
#

Morning. God I love scammers trying to phish for info, they never do. Always glorious wasting their time

crude stump
#

doesnt it make you feel loved berrrise

crude stump
#

its like you're there main money income. like im rich or somthing

#

wow

#

googles alive

#

cmon lofter finish what you started

rapid merlin
#

Google staff came to my house demanding a back flip

#

What now?

#

I can’t jump

ashen wadi
#

Are you afraid you gonna slip because of all that sweat?

crude stump
#

lofters back

#

cmon man im dying to see what you have to say

rapid merlin
spiral dagger
cedar scaffold
spiral dagger
#

This search should be global search

rapid merlin
#

Google "the answer to life the universe and everything"

rapid merlin
hearty plover
#

When i lvld up in THM, when does it show in the discord :o? im still hacker and thm website shows me im omni 😮

ashen wadi
#

Google "Tommy Devitto and his take on JWT"

rapid merlin
echo steeple
#

say i run a kali vm in vmware fusion with a bridge network adapter. i randomize the kalis mac address. i then use aircrack ng on kali to gain access to a wifi router. would the wifi router show a connection from the host machine, or just the randomized/anonymized kali machine? would there be anything else that would enable the defender to trace the attack back to the host machine?

cedar scaffold
hearty plover
#

@cedar scaffold thanks a lot brother

twin ridgeBOT
#

Gave +1 Rep to @cedar scaffold (current: #1339 - 2)

cedar scaffold
hearty plover
#

@crude stump thank you too ❤️

crude stump
#

anytime

shell nova
#

Usually takes up to a day for the update to work through the queue

rapid merlin
#

or google "askew" lol

mellow flicker
#

Hello, I want to send a screenshot for a problem I am experiencing, how can I do it? (I don't know how to use Discord)

sharp citrusBOT
rapid merlin
#

Then you can send a screenshot

naive violet
echo steeple
# rapid merlin Then you can send a screenshot

which means the mac of the network card of the host machine/the attached dongle would show up in the routers logs, right? or is it possible to randomize the mac of the usb passthroughed wifi dongle, too, within kali, so the attack would be anonymized and couldn't be traced back?

rapid merlin
#

I think you meant to react to James?

echo steeple
#

oh yeah, sorry.

rapid merlin
#

np

rapid merlin
mellow flicker
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #232 - 22)

mellow flicker
rapid merlin
echo steeple
rapid merlin
#

I wasn’t giving tips on being criminal

#

But ok

echo steeple
#

i mean...that would be the base assumption here, no? 😂 everything here is based purely on educational or ethical use. everything else would not be okay.

ashen wadi
#

You obviously decided to hack someone,based on your comments one hour ago .. SUS!

spiral dagger
#

Eggking❌️ hugeegg✅️

echo steeple
#

😂 if that would be the case, i wouldn't ask here and risk a ban. i actually like this community. but i'm gonna be honnest, one of those cases actually made me think of this question. but as i said, no intention to actually act on that and make myself a criminal. was just curious and this question was tickling my brain for a few days now and only way to scratch it is by having the questioned answered. maybe eventually i'll try it out on one of the routers i have flying around somewhere in my tech-garbage pile, but for now, it's really just curiosity

rapid merlin
#

Risking a ban for this after 3 years in the community would be dumb

#

But how yall doing?

finite edge
crude stump
#

fabulous

#

yes

#

speak your mind boy

#

😂

rapid merlin
finite edge
#

The things available in tryhackme website, are they enough to land me a entry level job?

echo steeple
#

i have a cat in my lap, a good sitcom running in the background, and a CTF to do. so not much to complain about.

crude stump
rapid merlin
#

Just what AceS said

twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #223 - 23)

finite edge
crude stump
#

not only that but if you tell the employer that you actively do tryhackme. it shows them you're really interested and want to learn

finite edge
boreal scarab
crude stump
rapid merlin
crude stump
#

i personlly use Virtualbox and then i run kali on it

rapid merlin
#

Unless it’s configured in an awkward way ig

finite edge
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #218 - 24)

crude stump
crude stump
echo steeple
crude stump
#

i think so. i remember someone said that it ran on there crappy computer perfectly

rapid merlin
finite edge
echo steeple
#

you don't mean the manual whitelisting where the admin would give the router a list of macs the wifi router is allowed to accept, correct?

plush mesa
finite edge
plush mesa
#

The "standard" pentest distro would be kali but its pretty bloated you can test if it works with your RAM limitation and otherwise go for a more minimal distro. But as Ace said you can also just use tryhackme's attackbox

crude stump
finite edge
crude stump
#

yes

#

kali is pretty beginner friendly if i say so myself

finite edge
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #209 - 25)

crude stump
#

i like kali because its super ez to acess your terminal and tools

crude stump
#

so you might have to redownload it need be

rapid merlin
#

Hi

echo steeple
crude stump
finite edge
crude stump
#

yes

rapid merlin
crude stump
#

you shouldnt have a problem

crude stump
finite edge
crude stump
#

yes you will need to do that

rapid merlin
#

Any pc expert
Or any gaming laptop owner

finite edge
twin ridgeBOT
#

Gave +1 Rep to @crude stump (current: #201 - 26)

finite edge
rapid merlin
#

I have a gaming laptop

#

Battery of it drain so fast

crude stump
#

@sick lance

rapid merlin
#

I believe dedicated GPU is running in background in task manager it shows 50c

sick lance
#

Hi!

We don't allow sale of vouchers etc in this server.

finite edge
safe barn
#

Ok my bad

rapid merlin
#

GTX 1650 laptop

rapid merlin
finite edge
# rapid merlin Yes

Well, for starters you need to understand that high performance cpus which are mostly available in gaming laptops drain battery power faster. Reason is the clock frequency and the clock speed of the cpu. There's nothing you can do about it, only remedy is you can keep your laptop plugged in while using it.

crude stump
rapid merlin
crude stump
#

why can't he have a american name?

rapid merlin
rapid merlin
ashen wadi
#

Why dont you plug the laptop?

rapid merlin
crude stump
plush mesa
finite edge
rapid merlin
plush mesa
#

those gaming laptops normally also come with massive rgb lighting do you got that on

ashen wadi
#

Im using lenovo yoga slim from 2021 and it still works very well. Battery can last about 8-12 hours,screen is 1080p ,16gb of ram and 8core amd cpu.

#

Only downside for me is shallow keyboard but you get used to it. When its plugged to external monitor i use Logitech MX Keys MINI

ashen wadi
#

You dont H

finite edge
twin ridgeBOT
#

Gave +1 Rep to @ashen wadi (current: #1339 - 2)

ashen wadi
#

Even quad core is perfectly enough for majority of tasks for infosecurity stuff.

rapid merlin
crude stump
#

i love that cat lol

rapid merlin
finite edge
rapid merlin
finite edge
silent sparrow
#

Hi

rapid merlin
#

...

silent sparrow
#

you good

rapid merlin
#

How can I stop my dedicate GPU from running while not playing or editing

rapid merlin
rapid merlin
#

Even while not using it

#

@plush mesa help

plush mesa
#

does your cpu have an integrated gpu

ashen wadi
#
rapid merlin
silent sparrow
#

you could do it through bios

twin ridgeBOT
#

Gave +1 Rep to @ashen wadi (current: #1008 - 3)

rapid merlin
ashen wadi
#

I hope it helps ,if not just google some more and you will find answer.

#

Then you wouldnt survive DOS gaming if you dislike bios 😦

rapid merlin
rapid merlin
rapid merlin
ashen wadi
#

MS DOS (OS).. We used that in 90s to launch games.

rapid merlin
ashen wadi
#

No offense mate but google it

rapid merlin
ashen wadi
#

Write brand and model of laptop plus bios key or something

naive violet
silent sparrow
rapid merlin
#

Seriously infront of mod

#

Lmfao

silent sparrow
#

😈

ashen wadi
#

Im gonna update my bio in discrod for all those who cant google

#

give me second

#

Its my original copypasta btw

grim sparrowBOT
#

:hammer: ondent#0 has been banned.

rapid merlin
#

Rip 🕊️

ashen wadi
#

To many words 😢

#

"You mean you want all answers on silver plate? Let me understand this cause, ya know maybe it's me, I'm a little fuked up maybe, but who who do you think i am,am I a clown to you,do I amuse you? Do I make you laugh, am I here to fukin amuse you? What do you mean simple google search wont give you ansers? Tell me?"

spice adder
chilly veldt
#

Morning

rapid merlin
#

It says dgpu even consumes 10-15 watts in idle state

crude stump
#

personlly i think taking a bat to it solves it

ashen wadi
#

He is coming to rescue

crude stump
#

hm

#

wrong bat

ashen wadi
#

he faaast

crude stump
#

he is fast

#

the drip is immaculate

rapid merlin
#

😭 my laptop GPU sucks all battery

#

My laptop can't even last 2hrs without plugging it

#

😭

ashen wadi
#

If you name me your top3 manga,ill help you

finite edge
rapid merlin
ashen wadi
#

Where is vagabond? Blade Of Immortal?!!

#

naniiiiiiiiiiii

rapid merlin
rapid merlin
ashen wadi
#

You are tearing me apart chosoo

rapid merlin
#

What

#

You already know it?

rapid merlin
#

You saw summer ghost?

#

Please i have a resisting urge to discuss about it but it's so underrated

ashen wadi
#

Nah mate,im fan of older anime/manga..2005+ stuff is bloody awful.

#

For example Riding Ben is awesome

rapid merlin
#

Oh

ashen wadi
#

Vampire D:Bloodlust

ashen wadi
#

Ninja Scroll

#

Akira

#

etc

#

All beautifully hand animated

#

With true passion and love

rapid merlin
#

I wanna watch it if you saw give me your thoughts

white nexus
ashen wadi
#

Its from ghibli studios right?

#

Watch Princess Mononoke

rapid merlin
rapid merlin
ashen wadi
#

Also even if its shonen and quite overrated,i really loved beginning of naruto (ninja arc),before they all become supermans.

rapid merlin
ashen wadi
#

Its cool anime if you like struggling mc's

rapid merlin
rapid merlin
near hawk
#

Sainsburys and tesco IT has gone down

#

Yesterday wqs mcdonalds

chilly veldt
#

Ooof

wild rose
#

IMF as well had their emails compromised.

near hawk
#

Apparently Sainsburys said it’s due to an overnight software update

wild rose
#

the same goes for McD's they said it's from a misconfiguration change.

dusky oriole
#

i require help from someone who works at tryhackme

#

So, my streak was reset

#

and i used to have 1077 days last i checked

#

i'd like to request that someone working tryhackme resets this

#

please

#

i intend to hit the 1500 day streak at the very least.

wild rose
#

best to message them using the chat feature at the bottom right on the website.

dusky oriole
#

Thank you, both of you

#

:D

timid prism
#

@gray sonnet are u nri

#

even they have it easier to get admission 😭

gray sonnet
#

not anymore

#

I've been in India for the past 8 years

gray sonnet
forest forge
#

your Tokyo Ghoul chall is messed up nvm

near hawk
rapid merlin
#

Rip

#

Nationwide issue due to bad software update

gray sonnet
#

hey @acoustic sand mind if I DM you?

naive violet
#

@glass nest Fixed an electric guitar this afternoon

#

Good adventure

wild rose
#

I'd say I fixed a electric guitar, but I just put on new strings.

naive violet
#

I've left that bit to my dad

wild rose
#

what was wrong with it?

#

the pickups?

naive violet
#

Volume potentiometer stem was snapped, my dad tried to fix it and didn't get the wiring quite right so no sound

#

So quick read of the wiring diagrams, check over the thing, and moved two wires and all sorted

wild rose
#

Sounds like it was an adventure to fix a "fix". Always harder to fix someone's previous work.

naive violet
#

Inside of a strat is pretty simple at least

wild rose
#

good fix then

naive violet
#

What doesn't help is the manufacturer using black wires for things that aren't ground/negative

wild rose
#

ooof yeah that would make it more tricky

echo steeple
#

is it just me or does ||cracking the password with hydra|| in the mrrobot room take a while? Been waiting for over 5 minutes now.

naive violet
#

@echo steeple #room-hints but yes, it's an ancient room off vulnhub

wild rose
#

anything with the word "hub" raises an eyebrow. Many places renamed themselves to centers or place.

toxic inlet
#

Anyone know good video explaining this section in details

boreal scarab
naive violet
crude stump
boreal scarab
crude stump
#

Not in a bad way

boreal scarab
#

It was mild, thankfully... if I got their hottest one.....

crude stump
#

Is it just me or is the chicken purple

rapid merlin
#

how to stalk

mossy river
past sparrow
#

wat

toxic inlet
toxic inlet
naive violet
#

@ashen wadi Please keep it in English only here

ashen wadi
#

I just copied some stalker memes my friend 😄

naive violet
#

Yes, but please keep it in English only.

naive violet
dense cedar
#

Who lives here in America ؟؟

crude stump
#

🇺🇸

dense cedar
ionic pagoda
#

guys

#

my learning methodology is

crude stump
#

Is ___

sick lance
#

Oh, hangman, I love this game.

sick lance
ionic pagoda
#
  • focus on one web app bug ( read about it, notes etc .. )
  • AD pentesting / Basic malware dev

i am studying those 2 at the same time, is that okay or over ?

crude stump
#

Wdym malware dev

#

Malware analyst?

ionic pagoda
#

i am already good at web app pentesting, bug bounty, discoverd some bugs in Apple, cambridge, harvard, UK gov, AU gov, IBM ..
but still yk never end learning

#

and AD pentest also i am not that completly new ( i know the attack pth, ptt, kerbroasting, ACL abuse etc

ionic pagoda
plush mesa
#

ok... what exactly is your question then? why wouldnt it be ok to learn multiple things at once?

ionic pagoda
#

but my q, is it okay to learn those 2 together, web app pentesting/ AD pentest, malware dev

again, i am not completly new to this, web app already at a vgood level, ad pentest also good, but still as i said always there is something new

ionic pagoda
plush mesa
#

of course

sick lance
#

People learn how they learn,

ionic pagoda
#

because i feel like if you focus on 1 thing, you would never be able to learn the other things, you will be stuck in one field, so learn multiple things same time

uncut valley
#

hey i'm new here but earlier to day my system acted funny like my game alt tab and played around discord just hovering around and nothing would respond for a couple seconds so i don't know if helldivers 2 anti cheat was causing that issue or some was able to remote control my windows system with i after setup my pc using my microsolf account than switch it to a local windows account so i don't the game cause that or i've been hacked and my surfshark antivirus is not detecting it and finally i do consent someone to personally dm me so i we can figure it out if is something or just the game anticheat causing that

plush mesa
#

i had a stroke reading that

#

use point and comma for gods sake

dense cedar
#

ls soImportant software development in cybersecurity ؟؟

ionic pagoda
#

also guys

#

check up on my last article ( not an ad, feel free to dislike it )

#

cant we send it here ?

sick lance
#

Please interact with the community more before you start self promoting.

ionic pagoda
#

its not an ad, i dont win anything with it

#

okay thank you.

devout palm
#

Hey THM, how's your weekend going?

uncut valley
#

@uncut valley oh man i forgot to put commas and pointers when i was writing that

mossy river
sick lance
#

Especially if you alt+tab.

crude stump
#

Yeah sounds like lag to me

mossy river
# sick lance Especially if you alt+tab.

Full screen applications often don't like when pop-ups appear which will take you out of the application. Two monitors and faulty mouse locking can also make you click out of the game

uncut valley
#

well@mossy river i was hell playing helldivers 2 on impossible and a the amount of enemys spawned in did makle my system lag like crazy

ashen wadi
uncut valley
#

and cause my razer mouse software, to glitch

mossy river
#

Disable Razer Cortex if you see your system lagging often

devout palm
#

Although, you can scan your system

#

Just to make sure

uncut valley
#

is malware bytes better than shufshark antivirus software

mossy river
#

No clue but one is known for a VPN and the other for anti-virus

buoyant tree
#

malwarebytes has a vpn now?

sick lance
#

77% off is general.

sick lance
uncut valley
#

really

sand trench
#

YAWN

sick lance
buoyant tree
#

Hmm

mossy river
#

I have one more day for this assignment dingdong

mossy river
sick lance
sick lance
uncut valley
#

i've had a hard time look up hows good malwarebyts, before mainly how many devices can have it on before, i'm at limit.

sick lance
#

Premuim has a limit of 10 at base.

uncut valley
#

thanks for info

mossy river
#

If I am allowed to, I will publish my paper if I ever get it done.

sick lance
#

You wouldn't be allowed to?

mossy river
#

There's rules with distributing your work at the University

#

Just have to make sure I am not breaking any of them

devout palm
mossy river
#

Whatever I want -- I cannot go into details while the coursework is active

devout palm
#

Mk

ionic pagoda
# ashen wadi Honestly its to much in my opinion,focus on one aspect then move on.

as i said bro, i am already good at web app pentest, really good and bug bounty hunting and have a good record
also AD not new, know the most attacks, just going deeper, but mal dev completly new

so i am learning more about AD/ and maldev and aside learning abit more about web app to not completly abondon it, what do you think

#

because i want to move from web app , i cant just focus on one thing, but also when i move to other areas, i cant forget the web app thats why i keep learning aside the ad, maldev

sick lance
#

Wonder if they're true to it....

uncut valley
#

hey, can anyone teach me how to manually teach me how find virus/malware in my system. and i do consent for someone to, DM me

mossy river
#

Step 1: Don't ask strangers in a cybersecurity Discord

sick lance
plush mesa
#

"hey can anyone do a free forensic analysis of my computer without me having to do the simplest google search"

naive violet
mossy river
#

If you haven't downloaded anything dodgy recently, why are you worried you have a virus? @uncut valley

plush mesa
uncut valley
#

just to know how k, my antivirus says no threats but still i to know how in the future okay

lapis vigil
#

i have a question, no not about malware on my desktop. What does "limited access time" mean in Active Directory rooms?

uncut valley
#

and yes i am careful about what i download.

buoyant tree
sick lance
mossy river
#

Prevention methods are the first, and biggest, step to stopping malware.
This goes for most things in cyber, such as phishing.

If you can stop the initial attack, you will be alright.

lapis vigil
mossy river
#

And when you system has been infected, there is not guarantee that the malware is gone even after manual removal.

uncut valley
#

the only things i do download is from mainly reputable for having good software. but incase it's a fake link like the obs download a year ago were users would download was infact malware you know

sick lance
lapis vigil
sick lance
plush mesa
# uncut valley hey, can anyone teach me how to manually teach me how find virus/malware in my s...

This might sound a bit extreme but why would anyone here waste their time on teaching you something about a topic you dont seem to be interested in enough to learn about yourself? The entirety of TryHackMe is dedicated to cyber security and there's also rooms about Malware Analysis on it. there's a bunch of free youtube videos about this topic. The entire internet is full with free knowledge yet you dont want to spend your time on that but instead ask someone else to spend their time on you to explain you a massive topic

mossy river
plush mesa
uncut valley
#

yes thank you for helping

uncut valley
#

also was just asking because someone will always forget to mention how to do something, forget some others things that're really important and forgot to mention it than i get screwed over and stuck not knowing what to do. thanks for reminding me about a video i do have save to watchagain.

plush mesa
#

If malware bytes didn't find anything it's very unlikely you will make out anything suspicious

sick lance
#

Unless you know you've downloaded something potentially sus.

whole moss
#

What I usually do is to take a note. I use obsidian. So lets say if I need to update or change something that I only do every couple of months. I got notes to check and so I will not spend hours to check how to do it

lapis vigil
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 2060)

plush mesa
#

Malware has loads of places to hide, maybe it only runs at certain times etc. Without the actual program which is malicious you can analyze it's pretty hard finding suspicious stuff because it can have already spread to a bunch of places and you dont know where and even if you found some stuff you never know if its maybe still on the system

lapis vigil
#

i have also one more, maybe a little stupid question. When, in your opinion, is a good moment for starting to play with ctfs?

whole moss
#

It is good enough. Defender and malwarebytes

plush mesa
#

i personally dont use an anti virus but ive heard its pretty godo and also used it before, ive heard from someone recently that apparently its not that good anymoer and apparently hitmanpro is good but idk that one

whole moss
past sparrow
twin ridgeBOT
#

Gave +1 Rep to @whole moss (current: #408 - 11)

jovial tapir
#

hello

crude stump
#

Wsp

crude stump
lapis vigil
crude stump
#

Good

#

Very good actually

#

The weather

#

Where I’m at it’s beautiful out. Perfect temperature

whole moss
#

Read this wrong, I thought you said smell wood. I got confused lol

granite tundra
#

I have a dumb question !

I was solving the Relevant room and got stuck in the part in which i have to upload the exploit to the smb sever, So i took help of the writeup provided and I got to know that I was using wrong exploit generated from msfvenom. So the main question is how do one identify which exploit to generate and use

The exploit i was using : msfvenom -p windows/meterpreter/reverse_tcp

Exploit needed : msfvenom -p windows/x64/shell_reverse_tcp

naive violet
#

Those are payloads, not exploits

#

One is staged, one is stageless, and one is a meterpreter and one is a plain shell

#

Plain shells can be better against bad antivirus

sand trench
#

is windows defender good antivirus?? shadow is of the opinion it is nowadays

naive violet
#

Pretty good yeah

devout palm
#

Despite the false positives, it is pretty good yeah

naive violet
#

You get false positives?

shut hawk
#

Brain is fried, 10 hours of straight maths NotLikeThis

naive violet
#

Anything I have had flagged has been hacking tooling or otherwise dodgy

sick lance
#

Yeah, Windows Defender has only flagged my own stuff that I've placed in the wrong place.

#

Nothing serious.

hollow pivot
#

I made the mistake of running a full scan, with my Kali VM files present, was a huge pain to go through NotLikeThis

shell nova
naive violet
#

That's hacking tooling to me

shut hawk
#

I've had a couple false positives with python exes, but that's to be expected considering the nature of how they are used and made

devout palm
shell nova
naive violet
shell nova
#

Yeah it'll be able to scan WSL soon if it doesn't already

fresh cobalt
#

Hello, the room Lateral Movement and Pivoting is in resetting mode ( network state ) since yesterday. Does someone know what is happenning ?

shell nova
#

They aren't the sharpest tools in the shed

devout palm
#

I think obfuscated binaries get flagged with a logical reason

simple cloud
sick lance
shut hawk
#

https://cloud.google.com/run
Til this exists, gonna see what sort of computational power you can get for free

Google Cloud

Build and deploy scalable containerized apps written in any language (like Go, Python, Java, Node.js, .NET, and Ruby) on a fully managed platform.

sick lance
#

Didn't Bee or Chick3n list that before?

#

I could be wrong.

ashen wadi
#

Im interested in how are rooms points calculated. For example majority of them have 60-120 points but then some of the rooms can have 500-1000 points if you solve them.

shut hawk
#

If they did, I've never seen it

sharp citrusBOT
shut hawk
#

That article should explain it, not sure how up to date or detailed it is

ashen wadi
#

Not really

boreal scarab
sick lance
#

Point system changed at one point.

boreal scarab
#

It didn't even reach my 4TB m.2 yet

#

I just killed it after 7 hours

devout palm
#

Points don't matter (:

devout palm
boreal scarab
#

Why milk stouts so dang good?!

shell nova
devout palm
shell nova
shell nova
#

There are xss and other injection payloads

devout palm
#

Aye

#

I'm glad it's not the whole Kali Linux getting detected

vast zinc
#

new thm ui is smooth and fast asf

boreal scarab
mossy river
wraith nova
#

Hello all, does anyone have any links to a POC or information on CVE-2022-37958 and how it actually works?

hollow pivot
#

Nope, only student discounts

mossy river
#

What's this for?

hollow yew
mossy river
#

Link?

#

Not only is it against the rules but it's against the rules of active CTFs

sharp citrusBOT
#
<#651923438524432404>
Rule 5 - No Cheating

Cheating of any form is not allowed. This is not limited to asking for help with assessed schoolwork or exams.

mossy river
#

Asking for help with active CTFs can get you disqualified

hollow yew
#

i'm sorry i figured it out myself tho

#

i'll delete the messages

steel aspen
#

I'm officially a haxor man I helped non computer people with a phishing link and explained it 😎

#

Waiting for my call to the matrix now

hollow yew
steel aspen
#

Its a clever phishing link to non computer people

#

The php with the %2F ones.

naive violet
#

Probably means you didn't do it right

naive violet
#

Please go to #room-help and show us what you're doing

boreal scarab
rapid merlin
#

Hi

past sparrow
#

hi

rapid merlin
#

Hi

runic garnet
#

whats the discord token for?

atomic aurora
runic garnet
#

ah how do i verify then

atomic aurora
#

./verify

runic garnet
#

nvm thanks

#

thank you

atomic aurora
#

np!

rapid merlin
civic jacinth
#

./verify

past sparrow
#

no dot

#

so ...

#

/verify

civic jacinth
shell nova
#

doesn't need to be in bot commands

sharp citrusBOT
buoyant tree
#

Should I do the Harvard CS50 thingy for the certificate

devout palm
#

I don't think you should do anything for the certificate.

rapid merlin
#

this anime is utterly trash sorry

#

why did the animation go from rlly good season 1 to rlly ass

devout palm
rapid merlin
devout palm
#

They might not know how the bot works 🙂

crude stump
#

.verify

rapid merlin
#

Why are some rooms marked hard but are easy asf and others marked easy and hard asf

devout palm
#

What rooms?

shell nova
#

depends on what you know

versed prairie
#

Does anybody know why the OpenVPN connect over the network interface with import from file fails and through terminal works?

rapid merlin
#

take a look at retro room (hard) vs razorblack (medium)

hearty plover
#

you guys know that feeling when you have a question while doing a machine and then forget it and cant ask it? xD

#

thats how i dumbass feel rn

crude stump
#

Yep

#

Especially when your gonna do the question and you accidentally exit your vm

naive violet
hearty plover
#

cant remember what it was damn

crude stump
#

Or terminal if I be more specific

naive violet
#

Difficulty also shifts over time

crude stump
#

It’s so ez to accidentally close out your terminal and have to do the cds and commands all over again

crude stump
#

Rip

buoyant tree
#

just to clear up my concepts

shut hawk
crude stump
#

Oh shoot

buoyant tree
#

hmm

#

may install it on my vm

shell nova
crude stump
#

I’m new to GitHub, do they have like a tutorial on how to download that stuff?

crude stump
#

Oh wow

#

Should’ve guessed readme was the tutorial

shell nova
uncut cove
#

do mods even sleep?

shut hawk
#

yeah, spread out a lot in different timezones

uncut cove
#

what if mods are AI or aliens

boreal scarab
boreal scarab
shell nova
chilly veldt
shell nova
#

I have been unmasked!

#

I mean

#

HELLO FELLOW HUMANS

chilly veldt
#

How you doing Hydra?

shell nova
#

hey Bella

#

weekends are nice 🙂

shell nova
#

guess Matt missed the reference again

boreal scarab
#

Wym paradox

chilly veldt
ashen wadi
chilly veldt
#

Just got off work, and I got work again in 8 hours

#

And before that I had work from 2300-0800

uncut cove
#

what is the reason to have so many scans that discover ports by connection reset? like xmas, fin, null, ack or window scans all seem to discover open ports by connection reset

proven quartz
chilly veldt
shell nova
#

ouch

chilly veldt
#

Yeee

#

Cause I need 2 days of physical onboarding

chilly veldt
#

And I be working like 6-7 days a week this and next week

proven quartz
#

Been there, it takes a lot out but you'll be moving on soon 🙂

chilly veldt
#

Yeee

#

Need to wake up in 3 hours though

shell nova
#

go nap

chilly veldt
#

Cause I have to make some breakfast

#

I ammm

#

I am on my way back in a bus right now

rapid merlin
#

ppl be saying its subdjective

#

smh

#

when both are on wordpress

#

lmfao0

ashen wadi
#

I got u fam

crude stump
#

I need a tinfoil hat

mossy river
# rapid merlin ppl be saying its subdjective

But it is subjective 🙂

I would find Web super easy but Reverse Engineering super difficult. Doesn’t necessarily mean that all reverse shell rooms should be set to hard

Which is why we look at the texhnique and set the difficulty based on that

#

If you think a room’s difficulty is massively incorrect, drop a message in #room-bugs

fresh cobalt
#

Mimikatz sounds innocent name and cute for evil purpose !

sick lance
crude stump
#

Liar

light halo
#

ey is it eligal to get somones ip ?

crude stump
#

For what purpose

light halo
#

trolling

#

sending.using

crude stump
#

Yes it is

light halo
#

and...

crude stump
#

And what

light halo
#

is it legal to have someones face on your pc even if they dont want that

uncut cove
#

wtf

light halo
#

and can i call the police bc of that

crude stump
#

@mossy river knows more then me

light halo
#

ok

mossy river
#

Or like as a picture

light halo
#

as a web pic

mossy river
#

I don’t know what a web pic is

light halo
#

website

mossy river
#

Still not sure what you’re referring to

crude stump
#

Apparently he wants someone’s ip to troll but idk how that has anything to correlate with putting someone’s face as there webpic

light halo
#

no no

#

a rondom guy has my ip

mossy river
#

Unplug your router for 30 minutes

light halo
#

he has it saved

#

i think

#

i can show you it on a call if you want?

mossy river
#

Routers use dynamic IP addresses

light halo
#

wtf is dynamic

mossy river
#

It means it changes. It is not static.

light halo
#

oh ok, but still can i report that to the police ?

mossy river
#

Not really

#

Unless they are harassing you

light halo
#

nah only by spaming my fac on evry chat

#

sry my grammer is bad.

mossy river
#

That could be considered harassment

#

Depends on your country’s laws, unfortunately I am not a legal representative

light halo
#

idk i live in germany and they live in poland

crude stump
#

Best thing is to block them

light halo
#

nah they will not stop

#

alt acc´s

crude stump
#

Is this discord?

light halo
#

yes???

crude stump
#

Block them and change your username

#

And pfp of course

light halo
#

dude

#

they are not stupid

mossy river
#

Block, report, change your username

crude stump
#

You would be surprised

light halo
#

idk i can try

mossy river
#

They can’t add you if you change your discord user

crude stump
#

Especially if you block them

light halo
#

yea

#

i know

#

but then im gonna be Lonely

crude stump
#

Plus if they create Alts and somehow find you again, block em. They can go through all that trouble but all you have to do is hit one button

mossy river
#

Then you can file a report for harassment^

crude stump
light halo
#

Wdym

dense cedar
#

What is the name of this ?

ashen wadi
light halo
#

Ok nvm im gonna send you the add of that person

blazing granite
#

no

dense cedar
#

yess

crude stump
#

Isn’t that what you plug your computer cord into. It converts your homes volts to the proper voltages of your computer?

#

Like the charging block thing what ever it’s called

rapid merlin
#

hi yall

crude stump
#

Aw

dense cedar
crude stump
crude stump
#

I can’t tell what plug is in the front from the picture

dense cedar
crude stump
#

Can you take a picture of the hole in the front of it

rapid merlin
#

hello, i was wondering if any staff member can answer why THM has a path dedicated to pentest+ and not for OSCP or TCM?
it is well known that OSCP and TCM are better certs to have than pentest+

dense cedar
crude stump
dense cedar
whole moss
dense cedar
crude stump
#

We can’t help you without a port picture

#

Sorry

whole moss
whole moss
#

An alternative if there is no existing wall port. The surface box can be mounted to the wall and same with the ethernet cable

#

Again this is just my assumption if that is a surface box

dense cedar
#

It's a good thing

#

thank you🤝

upper bison
#

RIP THM interface aesthetic kekw

sand trench
#

meep moops it is now time for the sleep sloop to the beep boops times agains for shadow

dense cedar
#

Research skills, manblobfingerguns

upper bison
#

The new interface update of THM doesn't show if a module or a specific CTF is complete by a green square or not

split lintel
#

What option best represents the process in which the actions of a hacker are simulated to find vulnerabilities in a system?
Offensive security
Defensive security" "But in the response format, it says this: Response format *********** ********, and I don't know how to respond because it always says the answer is incorrect."

timid prism
#

gm

coarse moth
#

Do you recommend any room or machine to practice with DNS records?

gray sonnet
#

Morning

gray sonnet
# timid prism gm

why are you waking up so late? you have to crack JEE, wake up earlier

#

Indian parents be like ^^

#

jk kid

buoyant tree
gray sonnet
#

how're you doing today AIO?

buoyant tree
gray sonnet
#

who isn't

blazing granite
#

still night around here 😂

thorny walrus
#

iirc

#

I know they have in person classes through other companies afaik

clear jackal
# rapid merlin hello, i was wondering if any staff member can answer why THM has a path dedicat...

The path was made in collaboration with CompTIA a couple of years ago for I believe what was the release of the new exam at the time? In order for there to be official training for the certs you're mentioning, business relationships would need to be established and the parties just may not be interested.

As far as being "better certs," not always true. It's generally recognized that OSCP is the entry level pentesting certification, but there are situations where it may not be appropriate and something like Pentest+ is. Also, Offensive Security has really kind of priced OSCP out of the "out-of-pocket" certification range which, in my opinion, will probably change the certification landscape once HR catches up.

serene wren
molten solar
#

I just finsihed building up my desk from having to dismantle everything on acc't of flooding

#

like 5 HOURS to route all my cables again

#

and its still looking a little rats-nest ish

#

Now wifes asking me to dress her desk ..

serene wren
molten solar
#

I have zounds of zip ties, anchors , some velcro, and a few bread ties

serene wren
#

I use a hub for my desktop

#

the speed of USB is inhuman i tell you so extendeding it doesnt matter

molten solar
#

I have little usb-3 hubs i can stick on anything for a temporary breakout, but only one computer gets a dedicated hub

#

Has anyone here played with the bacula windows agent

#

agreed re: usb speeds

#

but only the people who had to deal with RS232 or earlier will ever appreciate that statement i think

#

There is no lag at 2400

serene wren
#

Is it better to work with SoC anaylst first before going into Pentesting?

#

I am finishing up the pentest+ courses for PBQ on the cerficiation and its alot searching for a specific url when I can just spider through the website

#

using BurpSuite or DirBuster

#

in the OWASP top and fuzzing for the security questions with BurpSuite. I havent finished the phisining or windows lateral movements but I read books about it

#

no practical skills lmao even though its simple

brittle merlin
#

Is there a way to modify rdata to chinese in ida?

serene wren
brittle merlin
#

wdym?

rapid merlin
fresh cobalt
#

I’d like to know if I’m lazy ! How many task a day are you doing in each room ? How much time a day you spend on learning/trying stuff ?

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @clear jackal (current: #20 - 378)

rapid merlin
#

how do u fake localhost
i tried changing x forawrded for and host to localhost
its a ctf

keen osprey
smoky osprey
#

I know I'm late but Doom Eternal is such a fun video game

simple valve
#

damn, ineed more context

hasty sun
#

anyone know how to convert src to a .exe file?

#

its multiple

spiral jay
#

How to resolve Burp project: Could not lock User pref. Lock file access denied

thorny walrus
hasty sun
#

convert code to a downloadable file

#

fortnite cheats

#

dm me ill show the folder files

#

no i just need help converting it to a .exe file

chilly veldt
#

@sick lance

grim sparrowBOT
#

:hammer: peakd.exe#0 has been banned.

sick lance
#

Ah James to thr rescue.

rapid merlin
#

why cant i edit in the burp suite repeater?

naive violet
timid prism
#

then got bored

rapid merlin
#

sorry i had to blur so much

timid prism
#

u can edit the lhs

rapid merlin
#

nope

#

wait

#

i may know why

#

ok nvm sorry

rustic totem
#

Hey, can someone please tell me how to add a machine in virtual box with a different location for it?

gray sonnet
sick lance
timid prism
rapid merlin
#

like region of file path?

hasty palm
#

good morning

fervent dock
#

How do I get started

sick lance
fervent dock
#

I have done that

candid raft
#

@fervent dock also, you may need to give us a little more information, then we can advise accordingly

fervent dock
sick lance
fervent dock
#

Oh

sharp citrusBOT
#
TryHackMe's Website

You should know our website by now!

sick lance
#

Wrong command first time. 😅

candid raft
#

Good place to start, Introduciton to Cyber Security @fervent dock

fervent dock
#

Oh man there's so much thing to begin

#

I will try

sick lance
#

It's a vast field after all. 🙂

candid raft
#

Every journey starts with a single step, and all that 🙂 good luck @fervent dock

fervent dock
#

I see

#

Thanks for your support

candid raft
#

@fervent dock all good, just persevere and don't giveup, it's hard for everyone but it will all come together, I promise 👍

amber quarry
amber quarry
#

take a look at the article and the tool, it's interesting stuff

amber quarry
minor delta
#

Anyone have any thoughts on the Cybersecurity Certification Bundle on Humble Bundle right now?

naive violet
#

@rapid merlin tl;dr block it out with block color, typically black

terse sage
#

hello.

near hawk
#

Hi

rapid merlin
#

hi

naive violet
#

I enjoy that mindset

mossy river
#

I love PS' whole standing

#

Very respectable dude

naive violet
naive violet
#

I don't remember

mossy river
#

They talk a bit about their work for blizzard, it's quite interesting

shut hawk
#

Apparently his dad was the WoW guy from family guy lol (correction: south park)

mossy river
#

Correct

#

But it was south park not FG

shut hawk
#

I enjoy watching his content too

bitter quiver
#

Generally the companies that bundle with them are "indie" companies, which is fine for games and table top stuff

#

But you can expect the same thing with the cert prep companies.

gray sonnet
gray sonnet
rapid merlin
#

Agreed

plush thicket
#

thanks for suggestion

twin ridgeBOT
#

Gave +1 Rep to @hasty palm (current: #1340 - 2)

mint storm
#

Can i ask what kind of server this is?

#

Bcs i spawned here

hasty palm
#

as name says Tryhackme general chat, if u need help or guidance ask what is your trouble?

mossy river
willow garnet
#

just posting here since i get 0 reaction on a question i asked in the Cyberdefense learning path

mossy river
willow garnet
#

:/

mossy river
#

If you aren’t getting a response in the path channels, ask in #room-help

willow garnet
#

ok thanks

mossy river
#

But please remember that community members are volunteers

past sparrow
#

I wonder if anyone knows any platforms for cryptography attacks 🤔