#general
1 messages · Page 79 of 1
dont undertand it well
Unfortunately, there isn't a built-in feature to pause or temporarily suspend an active voucher. can contact to TryHackMe support to see if they can provide any assistance.
i told u i dont really understand what it means
sounds like it tries to start a root privileged shell
no there isnt
Oh!
can anyone help me with a reverse shell issue? i have opened a python http server then an nc listener with teh exact port in the reverse shell php file but yet i recieve no connection
#room-help i guess
@blazing granite I'm losing braincells.... Youtuber shoots cybertruck with 9mm "Let's try some bigger ammunition"
Proceeds to shoot .22
Um.... that's smaller
Yup, him
Its a fun vid to watch btw
looks like he rigged it
He was in the military, which is odd that he would mix that up... /shrug
"It probably won't go through?"
No, it won't go through, period. It'll leave a tiny dent
Matt, check your other DM 👀
I'M TRYING TO PLAY MY GAME
nu
What game? Gonna get HD2 later this week.
Is there any website or platform specifically for digital forensics labs?
Blueteamlabs online possibly.
beat me to the punch I was about to say Blue teams labs 😂
Is this free?
No, they will have paid content.
the old ones might be free
Type faster smh.
I learned to type faster with James around 🤣😂
haven't heard of these places but I'll check them out thx
letsdefend.io is really good especially if ur aiming for a soc role…..lots of hands on practice in there
blue labs I did a few rooms, letsdefend I discover it like 2 years ago, I created an account and I never used it 😂
Thanks for the motivation Rex
Gave +1 Rep to @blazing granite (current: #134 - 49)
happy to help 😂
@wild rose the site it's great and I've heard good things about letsdefend, just life got in the way 😂
Why do we have to pay bills and taxes anyways. Why can't we go back to being in school with all of these awesome resources. I miss spring break.
Young people want to be old, old people want to be young
😏
Daytona Beach :🥳
Miami was my jam
I told the support on it but they didnt. However i wish it was reolve. But they are saying it wont. Not sure. 🤔 Who is fix? Are they?
I'm lost 😂
just have a whisky 😂
Gonna add that to my coffee
irish coffee 😂
#rules we don't allow discussion of illegal subjects here even if it is legal in some countries
@ashen wadi Let's keep the gifs to a PG13, thanks!
Gave +1 Rep to @ashen wadi (current: #817 - 4)
Apparently my Spotify thinks it's 80s and 90s music time
I only snort white monster zero 
sounds good
Not a bad time thn
Nope, good mood to be in on my way home from work

it's always 80s music, 80s musics rules!!!! 😂
Kyooty probably asked for oldies 🤣
We don't allow the sale of subs, vouhcers etc in here.
but goodies 😂
I was listening to suddenly I see, and then Spotify be putting "you make my dreams come true" afterwards
OoohOooohohohoh, were where you 🎵
I wouldn't mind if somebody make my dreams come true 😂
I really hope Spotify hasn't decided that 80's and 90's qualify as oldies yet........
it's not oldies but darn good music
I grew up listen to that music 😂
cries that oldies are now my jam... 🥲
All I know is that Bowling for Soup needs to give us the remake we all deserve
No they don't.
where is esqy when I need it 😂 I feel outnumbered 😛
Not seen esqy around for a week or two.
damn his last message is 11 days ago
so it wasn't me, I haven't seen him either, but I thought it was my change of time zone 🙂
Probably on holiday or something.
How does KoTH work? I see no other players
ohh thanks
(You'll need to verify to speak in it though)
I think it's /docs verify now.
It's been gone for a while. 😦
it was better 😦
Nah, / commands are easier to see.
Scrubz i have a question for you
If you mention with the bot
You cant mention everyone right?
Im not gonna try lol
You can't use everyone or here or you're muted.
@sick lance
Like this
Yeah, you can't mention everyone.
Alright nice
You'll be linked with the closest matching account.
Oh yeah
you can post roles, but they won't tag them.
From the rooms being released I imagine theres gonna be a DFIR learning path soon
Awesome! Looking forward to it
@sick lance
@sick lance
Too slow
Please interact with the community before self promotion, thanks!
Gave +1 Rep to @exotic grail (current: #817 - 4)

It's fine
Real life emoji
I was wondering where they were. They must be on a break.
invisible mod man
Yeah, but time is also working. 🙂
I suppose, right now I am too. (the mod position isn't the job)
You forgot xd
Gave 1 Rep to kyootybella (current: #8 - 820)
I did not. 🙂
Should i do blackout?
If you like, i can later.
Gave 1 Rep to blackout8210 (current: #71 - 83)
:))
rep aboose!!!
Sup
Sky
Got me there
What kind?
A game where you play games other create.
It’s kind of like lego except it runs on a LUA engine so developers can make their own creations
kinda like garrysmod and plasma?
Umm
Not really
You’d have to Google it to see what I mean, I don’t really know how to explain it.
It’s like a game engine and then there’s a ton of games created by community members you play
hola amigos
i'm currently doing
Attacktive Directory room but stuck at the enumeration process because kerbrute is not working. whenever i try to enumerate for accounts, my system freezes and have to force shutdown. I tried the second repo of kerb but the problem is still there. Where should i head now?
Sorry, was in a meeting
😦 I was joking, lol
more like a giant engine to extract money from parents on a consistent and regular basis... like live-service subscriptions, except it's a marketplace where community content can be purchased with gift card money
Not to mention a phishing/hacking paradise.
Yeah, that's the "above board" side of the business
A massive platform on which you can play games created by users, trade items, customise your character, socialise with other users etc
Unfortunately a lot of shady things happen on the platform and its especially dangerous towards the player base considering how young they are
There is a cool Darknet Diaries episode that discusses Roblox https://darknetdiaries.com/episode/112/
With Roblox Corporation now being valued at more than $45 billion, we ask whether the kids making the vast majority of its content are being taken advantage of?
Support us on Patreon: https://www.patreon.com/PeopleMakeGames
Written and presented by Quintin Smith:
https://twitter.com/Quinns108
Design and art direction by Anni Sayers:
https://t...
hello, which path I should start with, if I am mainly interested in pentesting ?
ooh, will take a look thanks
You appear to have answered your own question there
i mean there are plenty and some topics in each overlap, so unsure
Always good to have a wide spectrum of knowledge
Ye
Gave +1 Rep to @shut hawk (current: #13 - 490)
Spin the wheel!
Oh brother Ramadan
https://oops.cmdchallenge.com/
wow this one was fun
One-line shell challenges, to help improve your skill on the commandline.
Hotdog with cheese, Chili and Oniona
Hey Shadow
Very delicious, brother
how're you feeling today?
ah yes, genuine cheese product
a lot better
Please feed me
aye
"oh no, my one weakness: cheese singles!!"
Ey peeps
Can you hack a Facebook account?
Are you aware this is illegal?
I'm good, yourself?
Contemplating my life decisions as I struggle to finish this book on compilers so I can friggin build one for myself
Usually those questions move from "Can you" to "Will you?"
Only a Facebook account, not a bank account !!
"only a mailbox, not a safe deposit box"
It doesn't matter if it's facebook, E-mail.
Attacking a system/device/account you don't own is illegal.
it still belongs to someone else
Fucking man haha
Alotta questions
Yup, and we don't do blackhat stuff here anyway
I'm asking legal questions here and no one has answered me
What was your legal question?
lots of people have answered you:
Q: can you hack facebook?
A: no, its illegal
Thanks, but I've got it... 🙂
Gave +1 Rep to @wintry sluice (current: #240 - 21)
today on useful commands
echo "$(<file.txt)"
Yo dem dogs are fucking FIRE
for when there is no cat binary on the system
why do people like putting cheese singles on cats?
Car
hi
Guys, let's talk about the dark web
how are you
By the way, have you read the discord rules?
oki, i'm sory
You again?
Have you read the rules though?
And you're sorry for what?
Madness of a day at Alton
YOU'RE AT ALTON TOWERS!?
Went on everything
okay i will read
We were, it closes early today 4pm. Stopped for some food and now we’re on the way home
Oh man, I was this close to going!
Damnnn! Only if 😄
opted for the May week (hopefully)
How is the Nemesis Reborn!?
My brother has a pass so we skipped all the queues
What time is it now in your country?
Pretty much the same ahah
6pm
Dungeon was wicked! Last time I went Alton was 4-6 years
Me too
I can't wait to go back, we go at Scarefest where it's amazing.
In future, you should really read things before you agree to them.
You ticked a box to say you had read and accepted the discord rules.
It's dangerous to go around agreeing to everything
Really, brother
My brother does that! I can’t always guarantee I will be able to get down.
I went to scarefest something around 6-8 years ago!
Yes, agreeing to contracts without reading them is foolish and will cause trouble for you
Gloomy Wood in Alton Towers is my all time happy place, the atmosphere and the music.
Thirteen is always the best ride. Also tried the new Nemesis ride with the live actors
You’re definitely Scottish
The amount of rides that closed and opened today was exhausting
Surprisingly SFW south park clip wow
yh, I was impressed
You know how to talk, champ
especially given the rest of that episode
Yes, it's usual for people to learn how to talk.
I just actually use punctuation in messages.
teach me how hhh
Jabba, do you have plain food tastes?
Yeah, I've seen people post on IG.
Umm, what do you mean by that?
Yeah my brother was one of them ahah
Like, not very adventurous? I need to decide what 2 pizza toppings I want
adds to osint profile
Hey guys, I have now finished the Network+ course, what next??
cheese product and more cheese product
I’d say I’m quite adventurous but I do like to stick to what I know.
Peppers are always a nice add to pizza. Usually I just go meat feast
Chicken and red pepper.
Assuming you're having cheese too.
Wait they took chicken off the pizza hut toppings menu, noooo
Good luck, my brother and I have different household names, different skin and hair colour and we live hours away from each other… we also don’t follow each other on IG 🤣
oh wait scrolling
so long as it isn't pineapple
https://github.com/rust-lang/rust/pull/70645
As a kid I thought cheese wasn't a default on pizza, so I always order extra cheese. XP
First thought was Ham and Pineapple ahah
mmmmm hawiian pizza
Extra cheese should always be default on pizza.. extra extra cheese should cost more. lol
Print all files with a .bin extension in the current directory that are different than the file named base.bin.
welp shadow is stuck again
Makes me wonder if I could make a pizza on a disk of fried cheese..
spicy beef is tasty on pizza
I need to go shopping for breakfast
I got hawaiian
beef pizza no, but once in Italy I had pizza with chips and sausages, it's a pizza they make for kids but it good 🙂
wonders if shadow should grab the picture to elaborate
italian pizza is really tasty
I lived 2 years in Italy food and wine there are amazing
yuups that is it
it's not what you know but who you know etc etc 😄
I was picturing something completly different
so many question about that pizza...
it was due to a campaign where you could design your own pizza with toppings and the user asked what would be the most evil pizza to order and the poll came up with this
where the employees of said pizza place are probably distraught now
The only question that I have about pizza is how long is going to take to get here😂
Pizzas are round...
square pizzas are great
not always, in rome you have pizza rossa that it rectangular 🙂
Exactly, I don’t think we waited in a single queue!
pizza transcends all including shapes
hmmm, imma go work out and then shop
wonders in hyper-pizza
Since they originally used French bread, they are clearly eclairs
savory eclairs 😂
I suddenly have a craving for marmite doughnuts....
Savory Salmon 🍣
chicken wings
had this randomly pop in my head today https://www.youtube.com/watch?v=xhlUVyDBusg
I DID NOT MAKE THIS VIDEO - ONLY UPLOADED IT!
This vid is soo nice XD - LYRICS :
I need a double cheeseburger and hold the lettuce
Don't be frontin' son no seeds on the bun
We be up in this dri...
the NOSTALGIA
first video I ever saw on youtube
so hot
Ben 10
ben 10 was basically all I ever knew when I was younger. So sad when I turned 11 😦
Heya ben
Send me a message
Why?
does anyone here have expeirence with hosting servers using colocation hosting?
No. I know some good bulletproof hosting providers though if that would work instead. Not colocation though
Are you needing bulletproof hosting so you can be a criminal with less chance of getting shutdown?
ah kk, no all good, im trying to host my own servers in a DC but i am very new to the whole thing
uhhhh no?..
sorry, you just caught me off guard xD
so ben not 10 😂
Ben 13
:mute: mtwosixtysix#0 has been muted.
What's the site where you can report a scam url
Are you asking?
yes
Do you know this is illegal?
Oh then scrubs is here
Phishing E-mail?
Was just bouta ping you scrubs
eh a website
time to report the site and its redirects
Yeah I would use a government agency instead of google. Google is sketchy kinda
They prolly won’t even take it down
hmm, Its a information harvesting fake giveaway kinda thin
sounds like most social media sites
time to report instagram.com
Man I'm in one of those periods where you don't want to study or do anything anymore. Been like that for a few days and it's driving me nuts

i feel that
It sucks lol. Need to do a seratonin detox/meditation cycle to get that sense of reward back
The confetti at the end of a module doesn
n't hit like it did
Woahh, rainbolt did a video on tryhackme https://youtu.be/oD10LyQvhq0?si=51VR3tjentxkbBMa
for educational use. if you'd like to take a try at the room before: https://tryhackme.com/room/sakura & thank you to osint dojo for putting together this room. their youtube here: @OSINTDojo
edited by: vidmok
WOOOHOOOO
nice i only did a 1/3
Cia test?
hey anybody can suggest me how i can hack any body whatsapp
What's this?
And why do you want to do something that is illegal?
Isn't CMD challenges?
Instead of a game
Yes
https://cmdchallenge.com/
Found it
One-line shell challenges, to help improve your skill on the commandline.
Cool!
I needed currently , If you suggest me any tool which i can use it to do this.
yuup it is cool and fun
@sick lance
Are you really sure you wish to do this, despite knowing it's illegal?
I just want to get its access
ya
😨
:hammer: rajsingh_#0 has been banned.
How hard does it get shadow
very hard... but at least the have a list of answers to all the questions you can check
it can be frustrating. I got up to grep last night.
here is the beginner one from same site: https://12days.cmdchallenge.com
One-line shell challenges, to help improve your skill on the commandline.
christmas themed
with learn and answer sections
lots of different answers, which is pretty cool to look at a problem from a different POV.
the oops one is insane
new room is cool
Hello, does anyone know how I can use a Windows ecosystem in attackbox? I need to use cmd and powershell
is this for a specific room?
powershells already on the attackbox if i am not mistaken
windows privilege escalation
the windows machine should be the "Start Machine", you might need to use remina to RDP into the windows machine.
You use those on the target, no?
yay
😄
how can i do that?
join there with RDP
The AttackBox is the Ubuntu machine you deploy to perform attacks from. It is separate from the target.
The attackbox has the tooling on it for RDP
i know that
Ok, so yes use remmina or something to RDP in
I like Remmina, it's my favourite RDP client.
thanks
Fujitsu found malware in their systems 👀
who???
same goes for CISA, they had to take a few down too.
No, you were right, patients details were allegedly stolen.
Anybody watchin pirate software on the apex case live ryt now ? Just found out he had direct access to hals system
did they say wheither it was EAC or EA?
yuups
It was EAC
Rob Joyce, Chief, Tailored Access Operations, National Security Agency
From his role as the Chief of NSA's Tailored Access Operation, home of the hackers at NSA, Mr. Joyce will talk about the security practices and capabilities that most effectively frustrate people seeking to exploit networks.
A transcript of this talk is available:
https://w...
For anyone who read this is how they told me the world ends
That's a big yikes cuz it works of the kernel.
be careful in stating things like this without proof please
with thunderous applause?
how good is the talk, cuz it's 35mins long... TLDR or TLDW
PirateSoftware and ThePrimeagen sit down and talk about the recent Apex Legends vulnerabilities as professionals in the industry. We're joined by Mande one of the top pro-players for the game. Lots of investigation, evolving information, and looking behind the curtain on game security.
PirateSoftware:
https://piratesoftware.live
https://discord...
Thing is lol I’m like 10 minutes in
thank you moose
Gave +1 Rep to @clear jackal (current: #20 - 379)
But it’s very interesting
as far as shadow has seen nope it is not proven that EAC is the reason
Hasn't? Must have misread somewhere then
Was a great presentation, no one in the audience took up the QR code "challenge". 😄
If tim recommends it then I'll have a listen.
had this tab open since its released but am yet to watch it
current discussion on the same topic
Yup pretty lit
If it is EAC then it's in over 30 other games. If it's EA, they need to need to do a full review.
if it is EAC it would already be worse then it currently is
much more likely that it is just apex legends
is it confirmed that there is a hack? only just started the video and they are talking about accidental cheat activation
Right? But maybe the hacker wanted the public coverage, because Apex is their largest IP that was being publicized in a live tournament.
moddified client or some way to tell the server to do stuff it is not supposed to... with requirement of server id
inbound connection on port 135 on one of the hacked peoples pcs from known malcious ip
keep watching, Thor doesn't have all the info at the start
and not nescarilly accidental bans due to "cheat"... could just be taking down the accounts that have evidence related
is thor the guy off camera?
so I did the intro to offensive security fakebank thing and it's saying -u: command not found
thor is the name of the person also known as piratesoftware
i.e the person whos stream shadow linked
now I wonder if there was a backdoor in a cheat program that multiple people downloaded
could potentially be trojan malwares yes...
I can't access twitch from work, but have they confirmed that there was cheats on his machine?
there is a confirmation of rpc connection over port 135
NO they have not confirmed that there was cheats on Hal machine
What’s that short for
easy anti cheat
Oh
and we already debunked blackouts claim there
aka anti-cheat software
The one apex runs off of right
yup
yuups and tons of other games too
Did they even comment on this matter?
yes
What they say
epic games the creator of easy anti cheat commented on it
Oh
if you want an article
Thanks
yeah but EAC was really really quick to stake their claim that it's not them.
though take things with grains of salt in not panicking and not claiming we know everything yet
yeah but as far as we can see their statement is true
I mean they were at the heart of the accusations
please no jump to conclusions
True
also for hal and the others to be hacked the hacker needed the SERVER ID which is a good piece of information
an just as easily be said that the individual players are at the heart of the accusations, or the game is at the heart of the accusations.
But it's all up in the air until forensics team can get their hands on the system and server images.
yeah... would bet that the FBI is already contacted
absolutely.
yes FBI handles stuffs like this
???
Searchsploit
the offline exploit DB, right?
Yeah.
so close 😢
expect a new video from piratesoftware on the apex legend story soonish after the stream ends
also known as SOON TM
valve time?
nah
then you're looking at never...
Had a rev shell and accidently pressed ctrl c instead of ctrl shift c
thats real pain
that is why you stabilise shells
ouch that's like a money shift in a car.
was adding a msfvenom payload
Control insert, shift insert to copy/paste respectively
Catch your revshell with the exploit/multi/handler module in metasploit and runsessions -u <session id> instead, much easier. In my opinion, at least.
this assuming they have a keyboard with the insert button
Thank you lmao
what's the insert button tho
I like to use pwncat.
I use macros for FN+C and FN+V
the button labeled ins in the home cluster
mines next to delete
nah my keyboard's smaller than that
The most attacked website/company is not nvidia cisco etc. it's acme IT support 😂
When i just want to cancel the command that i am writing, i do CTRL + C and lose the shell
Use rlwrap for better line editing too
To exit the pwncat shell you need to type exit
nano > vim
vim > nano
Again 
nvim > nano > vim
Again. 
Y'all think I leave editors installed?
vim FTW!!
Well yes, but actually no.
nvim > vim > vi > nano.
you only use echo???
emacs is a whole operating system
I troll people by not installing editors
Insta-create macros bound to @<some letter>. :)
I used vi a long time ago, on my Unix era 😂
so no sed or awk or cat then???
no cap its powerfull
Only those
no editors, less risk of sudo/suid exploits
If i want to quickly edit something, i use nano. If i want to code or something, i use vim (rare)
echo "$(<file.txt)"
I pretty much use VSCode for all stuff
yes it is a fun echo command
So “destroyer 2009” is a movie bruhh XD
does the < do the inverse of >?
(ie >: take thing on left, stick it in thing on right)
more or less yeah rswallen
Yes.
Idk about the example you made tho.
Oh, you mean bash.
the fun thing with using echo to print out the contents of a file is that echo is built into the shell in most instances
sounds like the euler identity of bash.
meaning you can't easily remove it
# Input file contents into command
cat < file.txt
# Output command contents into file
echo "Hello World" > outfile.txt
# Put contents from file a into file b
cat < a > b
Dk but it must have something to do with this whole situation…the guy knows what he is doin & havin fun with it
# output contents of file to standard out
echo "$(<file.txt)"
ello ello inf
echo "The date today is $(date)"
output file contents to variable, then echo the variable
How have u been shadow
poetry
Yoooo
Now I wonder whether I even had the tag I currently use at the time you left.
Discord was still using the #<number> usernames at the time, lmao.
Nope ,but the owl is definitely what reminded me
Whaha
echo -e "\e[1;31mThis is red text\e[0m"
How's life going
nah, its clearly cyan
Wow, last message in 9/2023.
echo -e "\e[1mHow bold of you\e[0m"
curl parrot.live
its possible to make reverse shell here? im trying to do it but it's doesnt working (its not part of the task but i want to test it)
By the way, use \e[A and \e[K to manipulate your cursor position in the terminal.
Yeah, I can get a reverse shell on that room.
nice
I fyou would like help on it, #room-help
I did it! thank you!! Next time i need to use reverse shell generator not copying code from github lmao.
any hidden flags are here?
have a look. explore
Please make sure you use #room-help for help with tryhackme rooms
Ok sorry
What type of command do I usually have to append in a file to get root if the files a crontab
if you can edit the crontab or the scripts it runs rev shell commands or making a suid binary is the more common ways
thanks, used the rev shell
because shadow finds stabilising shells annoying they generally just set the command to run chmod +s /bin/bash as then shadow can have a root shell using bash and from there do basically whatever
good idea
I just have 4 msf sessions open right now
for the same device cuz am trying a couple dozen different exploits
I like that idea, although would probably change /bin/bash to /bin/sh in case its something like busybox where bash isn't installed
oh yeah but at that point shadow most likely knows what shells are available
in most linux instances now sh is a symlink to bash that bash treats specially
assuming your cron runs as root
yeah but not on Alpine 😉
Guys, ridiculously, I don't know where the file I downloaded is. Is there any command for this? Otherwise I'll have to search everywhere one by one lol
I downloaded it via github command line
do you still have the command line open?
sorry no
could try doing the same steps again.
I sometimes forget which folder my internet browser is downloading files to (I sometimes change it when doing multiple downloads), so just start another download to see where it defaults to saving new downloads
thank you, I will try
I am slowly learning to program python. Do you guys think its smart to tackle fine tuning llms immediatly as a beginner?
nop
any suggestions what i should go for?
depend's what are you learning python for
creating software/?
that probably depends a fair bit on your understanding of fine tuning llms on top of a decent understanding of python.
i'd say in a room of 100 people i'd be number 98 on the list to give it a shot.
ha ha , ofcourse
bro the copy in the attackbox is so bad
when you try to copy somthing sometimes the blue line stays and sometimes it just disapears
and sometimes it wont even highlight it
how are you doing icon
Like in anything you learn, get the basics hammer down, and then practice, practice, practice and then practice some more 🙂
can somone explain to me why scanning traffic with snort or any other ids/ips would help a analyst?
like what makes somthing bad traffic
im having a hard time understanding it
IDS has virus and malicious signatures to send an alert to an analyst.
so the malware has its own ip?
While IPS would automatically block this malicious traffic.
A domain/ip can be malicious. yes
np any other questions?
if its scanning domains and ips how is a domain trying to access what ever system the ids is. or is it like if somone is using a software, that software has its own ip address and when they try to use it on the system that has the ids on, it flags it?
am i thinking right?
IDS can be both on the host/system or a network appliance like a firewall, so a company's network traffic flows through it.
It won't be the software, but the system itself that has it's own IP address.
so the system would have to have been infected or is malicous for it to flag
so if you go to a site and it redirects you to a known malicious IP in it's signatures an IDS would flag it.
An IPS would automatically drop the malicious traffic from entering the network.
wait i think i understand it now. its mostly for the people whos on the network that the ids/ips is on. if they click on a bad domain it flags it and the ips would block/drop i thus basically saving the network
keyword here is that the IP or domain would need to be in the signatures for it to work.
yup
that makes so much sense now
is that why they have to be constantly updated with new rules and stuff
yup
better understanding then the room lmao. thank you
or maybe its just me
could be just me
depends on the business and the IPS company to update and install the new signatures.
Naw it's just a new concept for you to learn. It took me a long time to understand firewalls.
its fascinating
and what the difference between firewalls and IDS do.
dont firewalls block and ids just alerts?
like New Generation Firewalls can do both if you set it up that way.
but yeah to keep it simple that's right.
wait so because snort is only in a simulated machine when your doing the snort room. How would somone go about having it activated 24/7 alerting
like for the simulation your given the traffic script
you can set it up as a host based IDS and it'll give you alerts to when you're visiting a malicious site.
traffic script is just simulated network traffic.
i thought so yeah
because it only works for a little bit of a time
once you exit it stops completly and you gotta run it again
right, just like AV it needs to be running in the background for it to pick malicious stuff up.
well thank you dex
np
Keep learning
enjoying the site 🙏🏻

Interesting read! If anyone checks it out let me know what your thoughts are I'm curious.
And yes it's a public doc, Google it and it's like the first few links.
old news, it's from 2004.
That says 2024
looks like feb 5 2004 to me.
Goes to sleep sloops meep moop time for beep boop
Goodnight Moon
Night night o/
looks like 04 to me
Ah!
Very interesting. That’s about what I would have guessed just based on following trends in the news. But just FYI, the mods might say this discussion is too political.
In any case, it doesn’t bother me, and I’m not a mod.
Interesting document though. I wasn’t aware that info was public. Very cool
That’s pretty cool. I’m not a policymaker so I don’t have too much use for it. I don’t have much power beyond my votes or any sort of community involvement, so if I read it it would be purely for interest
But it’s interesting seeing the big picture
Especially since people in our field get lost in the weeds
Like, why are we chasing all these TTPs, etc. what meaning does it have in reality
who from venezuela, that wants to team up 😄 ?
I’m from U.S. and not currently seeking a training partner. Best of luck. Maybe someone else will reply
i just want to have some friends to just do boxes together. Sometimes, I get really boring...
thanks!
Gave +1 Rep to @winged summit (current: #106 - 60)
Hang around here long enough and I’m sure you’ll meet some people
No problem
I will def do that, thanks !
Quick question: Is it normal that I can't add my username to the king.txt as a root in KOTH?
That's weird...
Pretty reactive and helpful server...as always 
@blazing granite u here?
I’m here
I wanna take pnpt but I’m scared I’ll learn what I alr know
I did junior pentester red teaming and offensive pentesting paths
Their course curriculum is still nice
Gets you an intro to python programming and linux
question, is eating a chocolate mousse cake with lemon juice a crime according to you

I'm almost done on ComptTIA Pentest+ path, is it enough to be prepared to pass the exam ? It was a great path but i feel it maybe not selfsufficent for the cert. Do you have any opinion ?
crime against humanity 🙂
Morning
morn
Hello hello 👋
0611 here 🙂
0511
22:12
alien 🙂
you are in the futur 🙂
ofc. and warnning from future... madam webb is dumb ass movie lol
So far the future is wet.
london ?
Nah, Scotland.
is anyone using snort in kali linux after 2024 kali linux update ?
Nah I seen they brought it back with the update.
any staff around that can help add me to the creators lounge and perhaps help with a cert role? cheers
does anyone know where the red kali linux wallpaper is like i think it might be fan made but it looked like a gundam kinda
Bro in install snort maually successfully
Yes i use snort
Hi everyone is there any hacker?
There’s a lot here
You'd like the creators lounge?
I could try, not sure if I can do it.
➕ Gave the role Creators-Lounge to ocdc
Oh I can.
@craggy wadi you have the creator-lounge role, I'll wait until a mod is on and they can either assign you the cert, or walk me through it. 😄
I see you figured it out. Awesome!
Yeah I have an idea in mind and I hoped the channel could provide some useful insight.
Appreciate the help.
ethical ones yea
If anyone is there let me know fast
just ask mate
What do you need help with?
Hi, is UDP 40 bytes faster than TCP in a single packet?
I wouldn't say that.
just buy access and don't pirate
This isn't the sort of service we offer here.
Okey thanks
I’m kinda curious what’s the most common languages among hackers second to English? I want to learn a language and connect with other hackers so I’m curious if it would be like Chinese or maybe Russian?
I just randomly thought of the SETI program. Is that still running?
I‘m currently learning Russian because it is a surprisingly common language in general. Plus, a lot of online content is written with it as well.
That’s kinda what I was thinking it seems pretty common in the cyber sec circles
Hi, can anybody give me any suggestions for doing advanced pointer scanning
like going deep into it, more than just CE
basically wanted to do more than that in game hacking
also looking for dll injecting (process hacker)
and ||wireshark||
hey guys i have a question i am working on this school project and i have gained the shell but its in the url like
view-source:http://192.168.0.103/capstone/assets/48.php?cmd=whoami
but what if i want to have it in my terminal like the shell you get after running the pentest monkey script?
We can't help with school projects, that would be cheating.
You should ask your lecturer or peers.
tbh the project ends here i have got the rce exploit
but i am curious like like how do i get this in my terminal
It's still school work.
please
Have a read of the rules, number 5.
These are the kind of things you agree you've read.
a hint would be great
:mute: cyclotecx#0 has been muted.
Insurances be weird
Been called up by insurance companies the last 3 days because I bought a new car
can you help me though ?
With what?
what are you trying to do?
here
basically game hacking

well there's various, most are in same language and engine though
I know, in these games the mods are literally offered by the devs
not asking for online games
I just started, he asked me to start the machine and scan with the gobuster. I ran the scan, then accessed the admin money transfer panel. He asked me to transfer $2000 from another account to his account. So that's what I did, my account went from -1,232.32 to $767.68. I wrote the answer, I wrote it in different formats, I know it is not a site error, it is probably my fault, but I said there is a site error. You can come and help me quicker.
the wireshark thing was for co-op (wireless LAN party), not online
#room-help for this please.
(It's not the balance it's looking for)
I miss google CTF finals
That was pure game hacking
We had a couple of months with the source code and had to develop our own hacks, and then play football tournament mode against each other
I want to do my eJPT, and I know its on this site: https://ine.com/ But they have a lot of subscriptions and courses so I'm confused about which one I need. Off course in the most expensive one I can get it, but I'm looking for cheaper alternatives 😅 Anyone here with experience?
INE is the trusted global leader in online IT training for networking, cyber security, cloud management, and data science.
Any hacker here ?
it's not worth it
@shell nova
About what?
No?
Sure
How come,at the end he helps people?
well my employer sais its the best starter certificate for when you're new to cybersecurity and pentesting
Great
it teaches you nothing tbh, and is wayy too expensive for what you get out of it
So, about what is your project? @humble monolith
If your boss is paying,go for it. Then for real entry level pentest cert,go for OSCP then OSEP.
He's a wizard, not a hacker.
Greedy Gandalf sent the party away so he could steal all the XP from the Balrog.

even when you know very little to nothing? my boss is indeed paying for it (if it's not the 750 dollar subscription version i think)
it is the 750 dollar subscription if you want to get access to the training machines
and yes, even when you know very little to nothing, I did mine before I even knew what TryHackMe is, and I did it in 7 hours
ouch
Damn wasnt training for ejpt free and exam voucher 200$ 😮
I'm almost finished with the Jr Pentesting path here on THM and want to get a certificate
Then tell your boss to pay for your HTB:Academy cubes and voucher,for CPTS.
Its like 120$ for all modules and labs,plus 220$ for 2xvoucher
And is on pair with OSCP which is like 1600$.
I would recommend PJPT instead
so my the experienced guys with my employer advised me to start with eJPT to also not get overwhelmed
What do you mean by not having experience for pentesting? Are we speaking only about pentesting or also your unexperience for basics of network,security,scripting..etc?
PJPT would be better for you in this case, yes your employer might pay for it, but the value you get is nothing from the eJPT, where as PJPT gives you more value in knowledge
im a test automation engineer working with python, so i know some stuff, but im not familiar with networking and the real pentesting
bring up what I have said to your employer then and ask about PJPT instead
I would say go with HTB:Academy,really up to date stuff and quite cheap
cybermentor is kinda basic
thanks for all the advice 🙂
might be able to ask for a THM sub 😉
Why are dell serialnumbers soo long
same reason IP addresses are long
they are like 28 chars long
Ip aren't that long.
zap > burp
Paid burp > zap.
Which cert did you want assigned?
the serial numbers are* 😅
IPv4 addresses aren't that long.
IPv6 addresses, however...
aren't that long either
What does Zap have that Burp doesnt? Alsothere is caido,with pretty neat ui.
Only 32 bits 😅
There is a few things Zap does that are in the paid burp.
Nooo, not Greggs
just pay cash ?
won't someone think of the snackers of savoury snacks
anyways someone sent me some really important dm using this https://www.base64decode.org/, what does it mean and why's it used ?
card tends to be faster, as there is no faffing about to make change
Who knows?
It was probably encoded to obfuscate what it was.
but cash is more anonymous
If I want to be anonymous paying for a drink, sausage roll and a yum yum in Greggs, I need to re-think my life priorities.
ok but he literally sent me some random text, asked me to put it in and a link showed up, he could've sent me the link in open text too
long story
but my main question was why's it used in general
being free helps 😉
Did you click the link?
It's a good way to distribute links containing malware.
like for what exactly
nope, never
ot yet
Obfuscation...
probably to get around some discord denylists
it also tends to make the data shorter in length i think
@ashen wadi you ok, mate?
yes, that's the purpose it serves, thanks for telling but I meant like what activity
like... illegal ? or legal cybersecurity practice etc
Gave +1 Rep to @sick lance (current: #2 - 2074)
I'd look at the cybersecurity thing, could you help me in understanding it easily though please ?
You can set a link to be on the deny list, so it's sent, it will be blocked,
If you encode it with base64, then tell someone to decode it, it can send.
oh ok, but I couldn't really understand why not share the normal link
cause it might be blocked by discord
normal link may be blocked
oh ok, so he wanted to share something which discord wouldn't see
bruh, so it was indeed something not quite right cuz we aint doin do cyber practice
If anybody wanted to know what it was, they'd need to decode it.
it might not be him sending it. his account may have been compromised
we use base64 in normal cybersec practices too
it'll be a bit of a mystery
yeah but what exactly?
yup
ok, thanks for helping out guys
I'll let everyone know wut it contains when I do open it in my laptop tomorrow
until then it's a bit of a mystery
👍
I'd advise against that
well in tor
if you can, check with your friend through something other than discord to check that he actually sent it
browser
even with TOR, that won't stop you getting hit by whatever malware is behind that link
Sandboxed or not.
you're right, what about using sandboxie
oh, ok
It will stay in the sandbox if it detonates
you can probably copy-paste it in virustotal or something
well how do you suggest me I be as safe as possible then ?
Don't click links.
don't click anything
Especially if you have to decode something for it.
don't click dodgy links
well but it's tempting, I want to see it
for ultimate safety, disconnect the internet
how can I be the most safe while seeing it
hello, I've searched the chat history but can't find some concrete numbers... anyone knows a reputable source of info regarding salary range in security ?
how can they access the link then 
depends on location, experience, job, etc
by not touching the link
magic?
I need to make a room exploiting magic
ok
and I still need to finish my other room
can we create a VPS and do it together lol ?
and test that room
^_^
I know
sure but it depends within a range... like programming, goes from 60k -120k
I need to finish my slides 😦
sec+ pls.
and new job that starts this or next week
and cybersec talk to create
again, depends on location as well
remote ?
I have to make a learning session for the company I work for
ok, would be super fun though
Distributing dodgy links may not be a great way to start in here,
yes I know, I never did that lol
I'd prolly be banned
or everyone would be hacked
getting infected, on the other hand, would not be.
.
well viruses cant attack hardware rightz they're limited to software

well firmware specifically
I mean they can be stored there, as code, but they can't damage it
unless it's indirect
they can though
but that's #advanced-general
Bella's right
I've asked Hydra to show me the ropes
they can change how the hardware runs (ignoring temperature limits), causing actual damage
Sir double Windsor knot is the best looking way to tie a tie
When you're free, can you DM?
Stuxnet hmmm
Centrifuges go brrrtt

