#general
1 messages · Page 76 of 1
one more try... @hasty sand might among alive ppl. to DM if you free to continue last convo ?
Say I found a exploite on ubers app where would i report this?
to them ?
Check of they have a bug bounty or a security text.
Like its quite serious
if bb then might get some $. if not then direct toi them
Alright
man, i'm a big believer in the hacker codex and that you should only do good with your skills, but damn, i would have to lie if i would say some people wouldn't absolutely deserve to get all their stuff pwnd
That's not a very pleasant attitude.
bit hars attitude yea. but as hack codex if you follow it you report things and so
not saying it's the right thing to do or that anyone should act on this feeling, but damn, some people just would deserve it. like, i would love to quote the doctor into these peoples faces sometimes. "good men don't need rules, and today is not the day to find out why i have so many"
Guys i have a Question.
Tryhackme is built to simulate real world usecases regarding the machines and their way in and how to work with it. But sometimes there is steganography involved. Now the Question: Who uses Steganography in the real World? :o?
Not who, but which Company and better, why?
steg is not used direct in company. if you wish make data safe you encrypt it.
No one, some rooms are more realistic than others that's all
Stego is also a pretty broad term
plenty of stego is in use, but its not for the things you might expect
as soon some mention cracking or similar, chicken is summoned 🙂
various forms of image watermarking and document marking could be considered steganography
Yeah I'm sure it's actually used for something but not for hiding a RSA private Key for example
Remember that not all CTF seek to have high realism
Some are just made to show you some kind of technology or concept which could be useful in very specific cases
cant say enough how i love the community. i was curious had a question and 5min later 10 replys
let's excange our priv keys 🙂
Thank you guys very much man
thor from piratesoftware showed his password for twitch once I think on stream that used steganography 
I'll show you mine if you show me yours
🙄
@echo steeple u ok ?
🙂
Sheeeeesh
also there's certainly some stego in places where you might also find crypto
e.g. anti-censorship layers for networks like tor
or for some C2 comms
'cause you know me
My TCP is TLC
You know my port, baby
Just Slip me your private key
😂
Data exfil maybe, doesn't seem to be super efficient though
Ohh that's smart I can totally see a use now
the anti-censorship and watermarking use cases are more common but yeah, C2 comms could certainly make use of various stego tricks
does metadata effect hash result of files ?
depends on where it's stored
While clever, let's keep it PG-13 k?
if its stored external to the file, no
if its metadata like on a photo, its in the file, so yes
it's from a song "SSH to your Heart"
if magic number is changed does that effect also ?
the "i show you my private key if you show me yours" reminded me of the chorus 😅 Shannon Morse really killed that chorus
aha... nice to know. so hashing of files takes all the things about file stored into file and make result. so any changes in backed it effect result
hashing consumes any blob of bytes you give it, whether its a file or just some data youve supplied
if you change any of those bytes, the hash should change
so for files, if you change any byte in the file, expect the hash to change
but some metadata may be stored outside of the file itself
by the OS or other applications
understand now yea
how to install windows 10 in linux ?
Use a hypervisor.
No
What?
i want to install windows machine in my linux/vmware
linux and windows are different
Oh, windows offers dev vms
You need like 50gb free tho
Windows is bloated af
Windows N exists.
i have 50 gb
im pretty sure windows has there own virtual machine
if thats what you're talking about
can anyone help me out ?
we are trying
absoulutly not /
You would like a Windows VM in your Linux host OS?
Or is linux inside a vm, and you want a vm inside the vm?
its like 22gb /
thats what im confused about
you took so complicate
My poor laptop knows the struggle
welp somethings in the world is conplicated
in vmware there you can install metasploit burp etc vice versa i want to install windows 10 machine in my vmware
Yeah, but is your host linux or Windows?
You’re running Linux and want to install windows inside VMware?
Fair, you’re just wording it awkwardly
Hence the confusion
I imagine
Unless I’m very wrong lol

Linux is like a car
Windows is a car
You can’t put a car inside a car without something in the middle
Like a hyper visor
A hyper visor is like a shrink ray
(I need coffee)
you send that link is ok i guess\
☕
thats crazy
Made me laugh, I like this guy
@spiral dagger absolutely not.
hahahaha
what /
I deleted your message, we won't be helping if that is the reason you'd like to create a windows 10 vm.
That isn't a topic to joke about in this server.
what happen @sick lance 
i apologise
my file downloaded can you do setup @sick lance
@rapid merlin hey buddy hows you
Good, you?
ifykyk
wow
Use Google, should be a standard setup
At this point I'm too afraid to ask
dirty joke in his name
How long? Like chewbaca?
October, I have curly hair so it’s just been looking ok
But now it gets in my eyes, especially when I sweat
Then stop sweating?
googlr told me why you need vmware use my windows machine
Wish this was an option
Google this “how to install a vm in VMware”
google "Google how do i google google "

You’re gonna break the internet
Morning. God I love scammers trying to phish for info, they never do. Always glorious wasting their time
doesnt it make you feel loved berrrise
its like you're there main money income. like im rich or somthing
wow
googles alive
cmon lofter finish what you started
Nah, scared the curly hair will hit the floor and cause me to over flip
How to hack google in 10 mint

This search should be global search
Google "the answer to life the universe and everything"
42, what does this mean
When i lvld up in THM, when does it show in the discord :o? im still hacker and thm website shows me im omni 😮
Google "Tommy Devitto and his take on JWT"

say i run a kali vm in vmware fusion with a bridge network adapter. i randomize the kalis mac address. i then use aircrack ng on kali to gain access to a wifi router. would the wifi router show a connection from the host machine, or just the randomized/anonymized kali machine? would there be anything else that would enable the defender to trace the attack back to the host machine?
reverifying can force update i think
you have to /verify again
@cedar scaffold thanks a lot brother
Gave +1 Rep to @cedar scaffold (current: #1339 - 2)

@crude stump thank you too ❤️
anytime
Usually takes up to a day for the update to work through the queue
or google "askew" lol
Hello, I want to send a screenshot for a problem I am experiencing, how can I do it? (I don't know how to use Discord)
Then you can send a screenshot
Can't bridge wifi for aircrack, need usb passthrough
use what ACME sent
which means the mac of the network card of the host machine/the attached dongle would show up in the routers logs, right? or is it possible to randomize the mac of the usb passthroughed wifi dongle, too, within kali, so the attack would be anonymized and couldn't be traced back?
I think you meant to react to James?
oh yeah, sorry.
np
Type this into your terminal:
macchanger -h
thank you
Gave +1 Rep to @crude stump (current: #232 - 22)
thank you too bro
But how it works on wifi, idk. But on cable , my router shows my parrot VM as a different device with a different MAC.
it's just a hypothetical i was thinking of. i do not currently have targets for such an attack. i'm just interested in whether it would be possible to anonymize such an attack to a point where it's not traceable to the host machine
i mean...that would be the base assumption here, no? 😂 everything here is based purely on educational or ethical use. everything else would not be okay.
Eggking❌️ hugeegg✅️
😂 if that would be the case, i wouldn't ask here and risk a ban. i actually like this community. but i'm gonna be honnest, one of those cases actually made me think of this question. but as i said, no intention to actually act on that and make myself a criminal. was just curious and this question was tickling my brain for a few days now and only way to scratch it is by having the questioned answered. maybe eventually i'll try it out on one of the routers i have flying around somewhere in my tech-garbage pile, but for now, it's really just curiosity
Risking a ban for this after 3 years in the community would be dumb
But how yall doing?
I have a question.
Yeah go ahead
The things available in tryhackme website, are they enough to land me a entry level job?
i have a cat in my lap, a good sitcom running in the background, and a CTF to do. so not much to complain about.
probably not land you one but it will definitely prepare you for a entry level job
Yes and no
Just what AceS said
ok thanks.
Gave +1 Rep to @crude stump (current: #223 - 23)
Okay I understood.
not only that but if you tell the employer that you actively do tryhackme. it shows them you're really interested and want to learn
is there a way to run virtual linux on the web? I want to learn linux
Oh yah
you can learn linux using the attack box in tryhackme or if you want you're own virtual machine you can run VirtualBox or VMware. Then of course you 'ed have to pick a os
Mac spoofing won’t work unless he has the psk anyways
i personlly use Virtualbox and then i run kali on it
Unless it’s configured in an awkward way ig
I don't think my pc can handle VirtualBox or VMware. I'll try the ones available in tryhackme then. Thank you.
Gave +1 Rep to @crude stump (current: #218 - 24)
forgot to mention virtual box and VMware are the most known.
you can always adjust the settings. like how much ram you want it to use etc
glad to help
will it run on 8gb ram?
sorry having trouble to understand what exactly you mean. so, randomizing the mac will basically do nothing when attacking the device and it will always show the original device mac?
i think so. i remember someone said that it ran on there crappy computer perfectly
No, just some Wi-Fi auth is based on Mac whitelisting
Thank you once again. I'm installing virtualbox. Any suggestions on the linux distro?
you don't mean the manual whitelisting where the admin would give the router a list of macs the wifi router is allowed to accept, correct?
you should be fine with 4gb RAM for your vm just dont have too many programs on your host and the vm open
Depends
I just want to learn pentesting and get familiarised with the linux os.
The "standard" pentest distro would be kali but its pretty bloated you can test if it works with your RAM limitation and otherwise go for a more minimal distro. But as Ace said you can also just use tryhackme's attackbox
so ubuntu is your classic linux distro, but you'd have to download all the tool packages. Kali is you're pentesting distro which has many of the tools you would need for basic pen testing in it. Parrot Os is another one but im not to fimiliar with it, but i heard its a good distro too. Its all up to your preference tho
Will it be ok if I use kali distro for beginning and also testing?
Okay, thanks. I'll download the kali image then.
Gave +1 Rep to @crude stump (current: #209 - 25)
i like kali because its super ez to acess your terminal and tools
post cat
have fun. ik not all computers are the same but when i first downloaded kali for some reason it left out some pretty crucial packages and i couldn't do anything on it
so you might have to redownload it need be
Hi
Cat tax
hello
So, I will be able to download those right?
yes
Are you a pc expert?
you shouldnt have a problem
no
Should I turn on virtualisation in bios?
yes you will need to do that
Any pc expert
Or any gaming laptop owner
Thanks.
Gave +1 Rep to @crude stump (current: #201 - 26)
Just say want you want to know, I'll try to help
@sick lance
I believe dedicated GPU is running in background in task manager it shows 50c
Hi!
We don't allow sale of vouchers etc in this server.
is there a H at the end of your CPU model?
Ok my bad
Why you have a American name indian
Well, for starters you need to understand that high performance cpus which are mostly available in gaming laptops drain battery power faster. Reason is the clock frequency and the clock speed of the cpu. There's nothing you can do about it, only remedy is you can keep your laptop plugged in while using it.
??
He said rs Indian rupees?
why can't he have a american name?
Yeah but even dedicated GPU will consume power right?
Yes.
He is giving me that Microsoft executive scam vibes
Why dont you plug the laptop?
How can I stop it when I am not gaming or editing
thats not nice
what do you mean "even" of course it does do you think its just powered by your wishes and dreams
any suggestions on laptops that has high battery durability and usage. I can use it for longer period of times without needing to charge?
I mean not while playing games or editing
those gaming laptops normally also come with massive rgb lighting do you got that on
Im using lenovo yoga slim from 2021 and it still works very well. Battery can last about 8-12 hours,screen is 1080p ,16gb of ram and 8core amd cpu.
Only downside for me is shallow keyboard but you get used to it. When its plugged to external monitor i use Logitech MX Keys MINI
Getting h or u series cpu
You dont H
Thank you for the suggestion.
Gave +1 Rep to @ashen wadi (current: #1339 - 2)
Even quad core is perfectly enough for majority of tasks for infosecurity stuff.
Nah only white backlight keyboard that too I don't use it
i love that cat lol
Yeah they consume less power
ok
U series consumes least power 9-15 watt
Thanks.
Hi
...
you good
How can I stop my dedicate GPU from running while not playing or editing
I am fine how are you?
I believe it's consuming my battery
Even while not using it
@plush mesa help
does your cpu have an integrated gpu
@rapid merlin Try this link: https://forums.tomshardware.com/threads/how-do-i-setup-igpu-for-windows-and-default-apps-and-dgpu-for-specific-apps-mostly-games-on-a-desktop-pc.3708730/
I have an older System:
MB : GA-H77M-D3H (rev. 1.1) (Bios ver.F12)
CPU: i7-3770 (w/intel HD 4000 gfx)
GPU: Nvidia GTX 650Ti 1gb
Ram: 12gb, Drive:480gb SSD
Windows 10 21H1
I have been trying to set up my Computer (main pc) and Windows, to use the integrated Graphics; and specify in windows to...
Yes
you could do it through bios
Thanks let me check
Gave +1 Rep to @ashen wadi (current: #1008 - 3)
Bios piss me off I get instant pstd
I hope it helps ,if not just google some more and you will find answer.
Then you wouldnt survive DOS gaming if you dislike bios 😦
I did Google it says about mix switch which my laptop doesn't has
What's dos gaming?
Yes integrated GPU with dedicated GPU
MS DOS (OS).. We used that in 90s to launch games.
How can I get into bios?
No offense mate but google it
Option name?
Write brand and model of laptop plus bios key or something
I mean the full gui UEFI we get mow are just tooooo fancy
idk
😈
Im gonna update my bio in discrod for all those who cant google
give me second
Its my original copypasta btw
:hammer: ondent#0 has been banned.
Rip 🕊️
To many words 😢
"You mean you want all answers on silver plate? Let me understand this cause, ya know maybe it's me, I'm a little fuked up maybe, but who who do you think i am,am I a clown to you,do I amuse you? Do I make you laugh, am I here to fukin amuse you? What do you mean simple google search wont give you ansers? Tell me?"
Or do it right and spam every possible key you think it could plausibly be
Morning
I am googling i haven't found any solution
It says dgpu even consumes 10-15 watts in idle state
personlly i think taking a bat to it solves it
he faaast
😭 my laptop GPU sucks all battery
My laptop can't even last 2hrs without plugging it
😭
If you name me your top3 manga,ill help you
- Berserk
- Monster
- Death Note
A silent voice
Summer ghost
Attack on titan
I don't know i am new to mangas even the mangas I read they are animated
Summer ghost is 2021 anime short film only 30min run time
I highly recommend you watching it once
You are tearing me apart chosoo
Tell me
You saw summer ghost?
Please i have a resisting urge to discuss about it but it's so underrated
Nah mate,im fan of older anime/manga..2005+ stuff is bloody awful.
For example Riding Ben is awesome
Oh
@ashen wadi watch this
Ninja Scroll
Akira
etc
All beautifully hand animated
With true passion and love
Did you saw houls moving castle?
I wanna watch it if you saw give me your thoughts
Its great
Yes
That wild girl?
Also even if its shonen and quite overrated,i really loved beginning of naruto (ninja arc),before they all become supermans.
I haven't watched it because of too many eps I will start that
Its cool anime if you like struggling mc's
Yeah I literally saw so many edits in last two years
Did you see garden of words?
Ooof
IMF as well had their emails compromised.
Apparently Sainsburys said it’s due to an overnight software update
the same goes for McD's they said it's from a misconfiguration change.
i require help from someone who works at tryhackme
So, my streak was reset
and i used to have 1077 days last i checked
i'd like to request that someone working tryhackme resets this
please
i intend to hit the 1500 day streak at the very least.
best to message them using the chat feature at the bottom right on the website.
Try support #site-support
used to be
not anymore
I've been in India for the past 8 years
Hey, the education system is fucked 😄, can't keep blaming yourself for it
your Tokyo Ghoul chall is messed up nvm
All after At&T went down
hey @acoustic sand mind if I DM you?
I'd say I fixed a electric guitar, but I just put on new strings.
I've left that bit to my dad
Volume potentiometer stem was snapped, my dad tried to fix it and didn't get the wiring quite right so no sound
So quick read of the wiring diagrams, check over the thing, and moved two wires and all sorted
Sounds like it was an adventure to fix a "fix". Always harder to fix someone's previous work.
Inside of a strat is pretty simple at least
good fix then
What doesn't help is the manufacturer using black wires for things that aren't ground/negative
ooof yeah that would make it more tricky
is it just me or does ||cracking the password with hydra|| in the mrrobot room take a while? Been waiting for over 5 minutes now.
@echo steeple #room-hints but yes, it's an ancient room off vulnhub
anything with the word "hub" raises an eyebrow. Many places renamed themselves to centers or place.
Anyone know good video explaining this section in details
Daves?
Tiberius have some neat shit:
Win
https://www.udemy.com/course/windows-privilege-escalation/
Lin
https://www.udemy.com/course/linux-privilege-escalation/
Gonna have to use YouTube. I usually search on google “ tryhackme PrivEsc walkthrough”
It wasn't THAT spicy 👀
Is it just me or is the chicken purple
how to stalk
?
wat
I tried but all are talking about the previous model
I am just afraid that this dude will be like just reading the model from what the 1s rating are saying
@ashen wadi Please keep it in English only here
I just copied some stalker memes my friend 😄
Yes, but please keep it in English only.
To be clear, yes that includes memes in non English languages.
Who lives here in America ؟؟
🇺🇸
My dream, my man
Is ___
Oh, hangman, I love this game.
E.
- focus on one web app bug ( read about it, notes etc .. )
- AD pentesting / Basic malware dev
i am studying those 2 at the same time, is that okay or over ?
i am already good at web app pentesting, bug bounty, discoverd some bugs in Apple, cambridge, harvard, UK gov, AU gov, IBM ..
but still yk never end learning
and AD pentest also i am not that completly new ( i know the attack pth, ptt, kerbroasting, ACL abuse etc
maldevacademy course
ok... what exactly is your question then? why wouldnt it be ok to learn multiple things at once?
but my q, is it okay to learn those 2 together, web app pentesting/ AD pentest, malware dev
again, i am not completly new to this, web app already at a vgood level, ad pentest also good, but still as i said always there is something new
so its ok to learn multiple things at once
of course
People learn how they learn,
because i feel like if you focus on 1 thing, you would never be able to learn the other things, you will be stuck in one field, so learn multiple things same time
hey i'm new here but earlier to day my system acted funny like my game alt tab and played around discord just hovering around and nothing would respond for a couple seconds so i don't know if helldivers 2 anti cheat was causing that issue or some was able to remote control my windows system with i after setup my pc using my microsolf account than switch it to a local windows account so i don't the game cause that or i've been hacked and my surfshark antivirus is not detecting it and finally i do consent someone to personally dm me so i we can figure it out if is something or just the game anticheat causing that
ls soImportant software development in cybersecurity ؟؟
also guys
check up on my last article ( not an ad, feel free to dislike it )
cant we send it here ?
Please interact with the community more before you start self promoting.
Hey THM, how's your weekend going?
Could be lag
Like game lag
@uncut valley oh man i forgot to put commas and pointers when i was writing that
Download malwarebytes, use the free premium trial to perform a full system scan.
What you described just sounds like your system was lagging, which is common for full screen applications that are GPU/ CPU intensive
Especially if you alt+tab.
Yeah sounds like lag to me
Full screen applications often don't like when pop-ups appear which will take you out of the application. Two monitors and faulty mouse locking can also make you click out of the game
well@mossy river i was hell playing helldivers 2 on impossible and a the amount of enemys spawned in did makle my system lag like crazy
Honestly its to much in my opinion,focus on one aspect then move on.
and cause my razer mouse software, to glitch
That might be it
Disable Razer Cortex if you see your system lagging often
is malware bytes better than shufshark antivirus software
No clue but one is known for a VPN and the other for anti-virus
malwarebytes has a vpn now?
77% off is general.
Yeah
really
YAWN
Hmm
I have one more day for this assignment 
What's it on?
I have to write a psychology paper on a topic of my choosing
I got my pentest assignement released on Tuesday, got until April 19th to hand it, got root in 25 min(s).
I keep forgetting you have psychology in your course.
i've had a hard time look up hows good malwarebyts, before mainly how many devices can have it on before, i'm at limit.
Premuim has a limit of 10 at base.
thanks for info
If I am allowed to, I will publish my paper if I ever get it done.
You wouldn't be allowed to?
There's rules with distributing your work at the University
Just have to make sure I am not breaking any of them
What are the options?
Whatever I want -- I cannot go into details while the coursework is active
Mk
as i said bro, i am already good at web app pentest, really good and bug bounty hunting and have a good record
also AD not new, know the most attacks, just going deeper, but mal dev completly new
so i am learning more about AD/ and maldev and aside learning abit more about web app to not completly abondon it, what do you think
because i want to move from web app , i cant just focus on one thing, but also when i move to other areas, i cant forget the web app thats why i keep learning aside the ad, maldev
Wonder if they're true to it....
hey, can anyone teach me how to manually teach me how find virus/malware in my system. and i do consent for someone to, DM me
Step 1: Don't ask strangers in a cybersecurity Discord
Step 2: Don't pirate material, download dodgy apps.
"hey can anyone do a free forensic analysis of my computer without me having to do the simplest google search"
If malwarebytes says there's no malware, chances are there's no malware
If you haven't downloaded anything dodgy recently, why are you worried you have a virus? @uncut valley
Well of course they are 😃 just like every other VPN provider!
just to know how k, my antivirus says no threats but still i to know how in the future okay
i have a question, no not about malware on my desktop. What does "limited access time" mean in Active Directory rooms?
and yes i am careful about what i download.
It's a network, it can be launched for a limited time period
You get removed after x number of days to save resources, you can re-add yourself.
Prevention methods are the first, and biggest, step to stopping malware.
This goes for most things in cyber, such as phishing.
If you can stop the initial attack, you will be alright.
so its like normal room but instead of manual start/stop machine it just starts and i have access for limited period of time, and when the time ends, its just reseting but i lose everything i did on machine?
And when you system has been infected, there is not guarantee that the malware is gone even after manual removal.
the only things i do download is from mainly reputable for having good software. but incase it's a fake link like the obs download a year ago were users would download was infact malware you know
You won't lose progress, no.
Some machines may revert back to a state where you need to set things up again though.
Small price to pay, but it's great.
i mean losing progress on machine, like changes or something
Not very often, usually you're done with the room before you're chucked out,
This might sound a bit extreme but why would anyone here waste their time on teaching you something about a topic you dont seem to be interested in enough to learn about yourself? The entirety of TryHackMe is dedicated to cyber security and there's also rooms about Malware Analysis on it. there's a bunch of free youtube videos about this topic. The entire internet is full with free knowledge yet you dont want to spend your time on that but instead ask someone else to spend their time on you to explain you a massive topic
Most people who downloaded that version of OBS automatically clicked on the advertised link.
Always scroll down past the advertised section on Google, this is where you receive the actual websites.
This isn't meant as an offense, just think about it. There's loads of free knowledge available to you
yes thank you for helping
I remember that!
also was just asking because someone will always forget to mention how to do something, forget some others things that're really important and forgot to mention it than i get screwed over and stuck not knowing what to do. thanks for reminding me about a video i do have save to watchagain.
If malware bytes didn't find anything it's very unlikely you will make out anything suspicious
Unless you know you've downloaded something potentially sus.
What I usually do is to take a note. I use obsidian. So lets say if I need to update or change something that I only do every couple of months. I got notes to check and so I will not spend hours to check how to do it
thanks, i just rushed through first room cus i was afraid i will lose access or something 😁
Gave +1 Rep to @sick lance (current: #2 - 2060)
Malware has loads of places to hide, maybe it only runs at certain times etc. Without the actual program which is malicious you can analyze it's pretty hard finding suspicious stuff because it can have already spread to a bunch of places and you dont know where and even if you found some stuff you never know if its maybe still on the system
is malwarebytes that good ?
i have also one more, maybe a little stupid question. When, in your opinion, is a good moment for starting to play with ctfs?
It is good enough. Defender and malwarebytes
i personally dont use an anti virus but ive heard its pretty godo and also used it before, ive heard from someone recently that apparently its not that good anymoer and apparently hitmanpro is good but idk that one
Start now. Even if you didnt get any flag. It is the knowledge that you gain matters
You could find a dedicated course for it
ok, thanks
Gave +1 Rep to @whole moss (current: #408 - 11)
hello
Wsp
Which is crazy how google or what ever search engine even advertises potentially unsafe websites
that's why i have always my adblock turned on
Good
Very good actually
The weather
Where I’m at it’s beautiful out. Perfect temperature
Read this wrong, I thought you said smell wood. I got confused lol
I have a dumb question !
I was solving the Relevant room and got stuck in the part in which i have to upload the exploit to the smb sever, So i took help of the writeup provided and I got to know that I was using wrong exploit generated from msfvenom. So the main question is how do one identify which exploit to generate and use
The exploit i was using : msfvenom -p windows/meterpreter/reverse_tcp
Exploit needed : msfvenom -p windows/x64/shell_reverse_tcp
Those are payloads, not exploits
One is staged, one is stageless, and one is a meterpreter and one is a plain shell
Plain shells can be better against bad antivirus
is windows defender good antivirus?? shadow is of the opinion it is nowadays
Pretty good yeah
Despite the false positives, it is pretty good yeah
You get false positives?
Brain is fried, 10 hours of straight maths 
Anything I have had flagged has been hacking tooling or otherwise dodgy
Yeah, Windows Defender has only flagged my own stuff that I've placed in the wrong place.
Nothing serious.
I made the mistake of running a full scan, with my Kali VM files present, was a huge pain to go through 
This is the case for me as well, though it also flags nc
That's hacking tooling to me
I've had a couple false positives with python exes, but that's to be expected considering the nature of how they are used and made
Well, sometimes my C++ applications (server) gets flagged
It has legitimate uses >.<
You reckon you could convince your corpo overlords of that?
Yeah it'll be able to scan WSL soon if it doesn't already
Hello, the room Lateral Movement and Pivoting is in resetting mode ( network state ) since yesterday. Does someone know what is happenning ?
Probably not
They aren't the sharpest tools in the shed
I think obfuscated binaries get flagged with a logical reason
I am stuck with this question in Maldoc room: What is the full URL which contains the keyword slideshow?
I've answered http://aristonbentre.com/slideshow/O1uPzXd2YscA/ but it still says it is wrong, what is the actual answer?
Please don't post across multiple channels, this is spam, someone will answer you in room help 🙂
https://cloud.google.com/run
Til this exists, gonna see what sort of computational power you can get for free
Im interested in how are rooms points calculated. For example majority of them have 60-120 points but then some of the rooms can have 500-1000 points if you solve them.
If they did, I've never seen it
That article should explain it, not sure how up to date or detailed it is
Not really
Don't worry, 7 hour scan and it was still going on my 1 TB M.2, 11k malicious files..... all Kali and Parrot
Point system changed at one point.
Points don't matter (:
Thank god mine was only Seclist kek
Why milk stouts so dang good?!
Ha
My AV detected payloads in the SecLists
That's possible
There are xss and other injection payloads
new thm ui is smooth and fast asf
Each question is worth x amount of points.
Questions are worth more on challenge rooms.
Back in the day, questions were worth a lot more.
There was a point recalculation, but older rooms were not affected by this. Which is why you see users on older rooms with a massive point difference.
Hello all, does anyone have any links to a POC or information on CVE-2022-37958 and how it actually works?
Nope, only student discounts
What's this for?
a ctf
Cheating of any form is not allowed. This is not limited to asking for help with assessed schoolwork or exams.
Asking for help with active CTFs can get you disqualified
I'm officially a haxor man I helped non computer people with a phishing link and explained it 😎
Waiting for my call to the matrix now
https://matrix.org/try-matrix/ here's your invite to the matrix
Probably means you didn't do it right
Please go to #room-help and show us what you're doing
Hi
hi
Hi
whats the discord token for?
Verification
ah how do i verify then
./verify
np!
#bot-commands then /verify
./verify
#bot-commands /verify
doesn't need to be in bot commands
Should I do the Harvard CS50 thingy for the certificate
I don't think you should do anything for the certificate.
bruh
this anime is utterly trash sorry
why did the animation go from rlly good season 1 to rlly ass
It's okay. They are just new.
yeah ik but like, new to discord or ?
They might not know how the bot works 🙂
.verify
Why are some rooms marked hard but are easy asf and others marked easy and hard asf
What rooms?
Difficulty is subjective
depends on what you know
Does anybody know why the OpenVPN connect over the network interface with import from file fails and through terminal works?
not in this case
take a look at retro room (hard) vs razorblack (medium)
you guys know that feeling when you have a question while doing a machine and then forget it and cant ask it? xD
thats how i dumbass feel rn
Retro is hard because of a few complicating factors. Blaster is the same but without those.
cant remember what it was damn
Or terminal if I be more specific
Difficulty also shifts over time
It’s so ez to accidentally close out your terminal and have to do the cds and commands all over again
... Just did that
Rip
yea, although redoing easy rooms again
just to clear up my concepts
https://github.com/ajeetdsouza/zoxide might be interesting
Oh shoot
z is nice, yeah
I’m new to GitHub, do they have like a tutorial on how to download that stuff?
or releases
should probably use cargo for zoxide
do mods even sleep?
yeah, spread out a lot in different timezones
what if mods are AI or aliens
Yah, if say Ninja or Jabba are asleep, Juun's awake
beep boop

How you doing Hydra?
guess Matt missed the reference again
Wym 
Weekend? What's that
This is true,and not only for THM,same shit for HTB/PG.
Just got off work, and I got work again in 8 hours
And before that I had work from 2300-0800
what is the reason to have so many scans that discover ports by connection reset? like xmas, fin, null, ack or window scans all seem to discover open ports by connection reset
That sucks! New job start now! 💪
Actually having a bit of problems with starting the new job, due to being this busy
ouch
Sucks. Here's hoping 🤞
And I be working like 6-7 days a week this and next week
Been there, it takes a lot out but you'll be moving on soon 🙂
go nap
Cause I have to make some breakfast
I ammm
I am on my way back in a bus right now
lmao yeah im not completely crazy
ppl be saying its subdjective
smh
when both are on wordpress
lmfao0
I need a tinfoil hat
But it is subjective 🙂
I would find Web super easy but Reverse Engineering super difficult. Doesn’t necessarily mean that all reverse shell rooms should be set to hard
Which is why we look at the texhnique and set the difficulty based on that
If you think a room’s difficulty is massively incorrect, drop a message in #room-bugs
Mimikatz sounds innocent name and cute for evil purpose !
I'm hooman
Liar
ey is it eligal to get somones ip ?
For what purpose
Yes it is
and...
And what
is it legal to have someones face on your pc even if they dont want that
wtf
and can i call the police bc of that
@mossy river knows more then me
ok
You mean as a desktop background?
Or like as a picture
as a web pic
I don’t know what a web pic is
website
Still not sure what you’re referring to
Apparently he wants someone’s ip to troll but idk how that has anything to correlate with putting someone’s face as there webpic
Unplug your router for 30 minutes
Routers use dynamic IP addresses
wtf is dynamic
It means it changes. It is not static.
oh ok, but still can i report that to the police ?
That could be considered harassment
Depends on your country’s laws, unfortunately I am not a legal representative
idk i live in germany and they live in poland
Best thing is to block them
Is this discord?
yes???
Block, report, change your username
You would be surprised
idk i can try
They can’t add you if you change your discord user
Especially if you block them
Plus if they create Alts and somehow find you again, block em. They can go through all that trouble but all you have to do is hit one button
Then you can file a report for harassment^
Tell your friends who you trust “ yo I’m . So you know. I changed my user
Wdym
What is the name of this ?

Ok nvm im gonna send you the add of that person
no
yess
Ok?
Isn’t that what you plug your computer cord into. It converts your homes volts to the proper voltages of your computer?
Like the charging block thing what ever it’s called
hi yall
Aw
you guys 🤔
Look what I said
Or is that a Ethernet port?
I can’t tell what plug is in the front from the picture
I don't know
Can you take a picture of the hole in the front of it
hello, i was wondering if any staff member can answer why THM has a path dedicated to pentest+ and not for OSCP or TCM?
it is well known that OSCP and TCM are better certs to have than pentest+
In front of him is a port
oscp😎
I’m guessing because pentest+ is a good beginners cert
yess beginners
Without port and end picture, I will assume this is rj11/12 or telephone connector
I do not think so RJ45
I want to know. How it works
One way to know is to pop the surface box open and check the wire arrangement, it can be a straight through or crossover
What is its purpose?
An alternative if there is no existing wall port. The surface box can be mounted to the wall and same with the ethernet cable
Again this is just my assumption if that is a surface box
RIP THM interface aesthetic 
meep moops it is now time for the sleep sloop to the beep boops times agains for shadow
Research skills, man
You clearly fail at validating basic CAPTCHAs since you're not a real human being 
The new interface update of THM doesn't show if a module or a specific CTF is complete by a green square or not
What option best represents the process in which the actions of a hacker are simulated to find vulnerabilities in a system?
Offensive security
Defensive security" "But in the response format, it says this: Response format *********** ********, and I don't know how to respond because it always says the answer is incorrect."
Read the section carefully
gm
Do you recommend any room or machine to practice with DNS records?
Morning
why are you waking up so late? you have to crack JEE, wake up earlier
Indian parents be like ^^
jk kid
Mornin'
how're you doing today AIO?
still night around here 😂
I think Offsec is tough on training unless youre a verified partner
iirc
I know they have in person classes through other companies afaik
The path was made in collaboration with CompTIA a couple of years ago for I believe what was the release of the new exam at the time? In order for there to be official training for the certs you're mentioning, business relationships would need to be established and the parties just may not be interested.
As far as being "better certs," not always true. It's generally recognized that OSCP is the entry level pentesting certification, but there are situations where it may not be appropriate and something like Pentest+ is. Also, Offensive Security has really kind of priced OSCP out of the "out-of-pocket" certification range which, in my opinion, will probably change the certification landscape once HR catches up.
Pentest+ is usually for certficiation stack, I think its just entry and not completely junior level skills unless you skill up. Is that true?
I just finsihed building up my desk from having to dismantle everything on acc't of flooding
like 5 HOURS to route all my cables again
and its still looking a little rats-nest ish
Now wifes asking me to dress her desk ..
just use a those little twister things
I have zounds of zip ties, anchors , some velcro, and a few bread ties
I use a hub for my desktop
the speed of USB is inhuman i tell you so extendeding it doesnt matter
I have little usb-3 hubs i can stick on anything for a temporary breakout, but only one computer gets a dedicated hub
Has anyone here played with the bacula windows agent
agreed re: usb speeds
but only the people who had to deal with RS232 or earlier will ever appreciate that statement i think
There is no lag at 2400
Is it better to work with SoC anaylst first before going into Pentesting?
I am finishing up the pentest+ courses for PBQ on the cerficiation and its alot searching for a specific url when I can just spider through the website
using BurpSuite or DirBuster
in the OWASP top and fuzzing for the security questions with BurpSuite. I havent finished the phisining or windows lateral movements but I read books about it
no practical skills lmao even though its simple
Is there a way to modify rdata to chinese in ida?
do you recommend python the hard way?
wdym?
bruh offensive pentesting and some of red team is litterlly the same in oscp
I’d like to know if I’m lazy ! How many task a day are you doing in each room ? How much time a day you spend on learning/trying stuff ?
thanks, this is what i wanted to know.
Gave +1 Rep to @clear jackal (current: #20 - 378)
how do u fake localhost
i tried changing x forawrded for and host to localhost
its a ctf
I know I'm late but Doom Eternal is such a fun video game
damn, ineed more context
How to resolve Burp project: Could not lock User pref. Lock file access denied
convert code to a downloadable file
fortnite cheats
dm me ill show the folder files
no i just need help converting it to a .exe file
.
@sick lance
:hammer: peakd.exe#0 has been banned.
Ah James to thr rescue.
why cant i edit in the burp suite repeater?
What are you trying to edit?
i completed 2 hrs of morning study. also i wake up earliest. its between 530 ish
then got bored
sorry i had to blur so much
u can edit the lhs
Hey, can someone please tell me how to add a machine in virtual box with a different location for it?
Did you know a group of rabbits is called a fluffle?
Relatively new term, mainly used in Canada.
jee doesnt ask this nope
wdym
like region of file path?
good morning
How do I get started
Have a read over #start-here 🙂
I have done that
@fervent dock also, you may need to give us a little more information, then we can advise accordingly
Like i'm a complete newbie so
have a look at the some of the started stuff on the website.
You should know our website by now!
Wrong command first time. 😅
Good place to start, Introduciton to Cyber Security @fervent dock
It's a vast field after all. 🙂
Every journey starts with a single step, and all that 🙂 good luck @fervent dock
@fervent dock all good, just persevere and don't giveup, it's hard for everyone but it will all come together, I promise 👍
not sure if this is a real pentest but this is not pixelated enough. if you are using greenshot put the pixel ratio to the max otherwise it's readable:
https://bishopfox.com/blog/unredacter-tool-never-pixelation
okay
thanks
take a look at the article and the tool, it's interesting stuff
I gave you a reply in TCM server
Anyone have any thoughts on the Cybersecurity Certification Bundle on Humble Bundle right now?
@rapid merlin tl;dr block it out with block color, typically black
hello.
Hi
hi
Watch the stream here:
https://piratesoftware.live
#Shorts #Twitch #AshesOfCreation
I enjoy that mindset
Their first short that I saw was cringe so I immediately took a dislike but I've been slowly warming up to their content
Gosh, what was it about?
I don't remember
They talk a bit about their work for blizzard, it's quite interesting
Apparently his dad was the WoW guy from family guy lol (correction: south park)
I enjoy watching his content too
Not a fan of Humbles Bundles for certs.
Generally the companies that bundle with them are "indie" companies, which is fine for games and table top stuff
But you can expect the same thing with the cert prep companies.
Aye
There's a whole other world outside of JEE kid
Agreed
thanks for suggestion
Gave +1 Rep to @hasty palm (current: #1340 - 2)
as name says Tryhackme general chat, if u need help or guidance ask what is your trouble?
This is a discord community for the TryHackMe platform https://tryhackme.com
just posting here since i get 0 reaction on a question i asked in the Cyberdefense learning path
Room help needs to stay in the relevant channels
:/
If you aren’t getting a response in the path channels, ask in #room-help
ok thanks
But please remember that community members are volunteers
I wonder if anyone knows any platforms for cryptography attacks 🤔


