#general

1 messages Β· Page 82 of 1

kindred apex
#

who is best in python here

#

?

rapid merlin
#

LMAO

wintry sluice
kindred apex
#

and java ??

sick lance
#

That is a general question, nothing wrong with it.

And I'm not the best at python. lol

kindred apex
#

who knows css

polar spoke
#

who cares?

#

haha

sick lance
#

Are you going somewhere with the questions @kindred apex

wintry sluice
#

never played css. tf2 was my jam

rapid merlin
#

@sick lance would you consider yourself more of a scripter than a programmer?

boreal scarab
boreal scarab
#

Dragonborn Helmet with Dead President's effect, favorite hat and unusual effect

kindred apex
#

gas anyone used esp8266 microcontroller

#

has

#

?

polar spoke
#

lots of people have

boreal scarab
#

I feel like we're playing 20 questions here with no clear answer in sight...

rapid merlin
kindred apex
#

who is a programmer here ??

sick lance
polar spoke
wooden totem
#

@sick lance can I DM you, I've gotten suspicious dm

rapid merlin
sick lance
boreal scarab
devout shore
#

hey man

near hawk
#

Hello

sick lance
# devout shore hey man

Can you please ask people before you DM them, it's in the rules of the server, that you've accepted.

devout shore
#

H1

sick lance
twin ridgeBOT
#

Gave +1 Rep to @stoic fjord (current: #1343 - 2)

fluid ember
#

Is it like a rank?

wintry sluice
#

its just a way for the discord mods to see who is being helpful

rapid merlin
wintry sluice
#

learned some snort earlier

vast zinc
#

0x3 , wizard , infosec dev , god all are just 50 shade of green

polar spoke
#

nothing wrong with a little green

shell nova
near hawk
vast zinc
#

orange gangπŸ’ͺ

crude stump
shell nova
#

I didn't make the colours 😦

vast zinc
#

what if

sick lance
#

I like my name colour.

vast zinc
wintry sluice
#

but, 0day is orange, hydra is green, jared is blue and scrubz is cyan

#

much confusing

sick lance
#

Jabba is staff.

shell nova
#

More of a sky blue than cyan

sick lance
#

Staff overrides mode

vast zinc
#

very very limited choices of color here

crude stump
#

I like scrubs color

shell nova
#

0day is old man mod πŸ˜‰

crude stump
#

All the other colors are bleh

vast zinc
#

jayy color is best

crude stump
wooden totem
#

missing a desaturated yellow

sick lance
#

0x9

wooden totem
#

thats more orange-y

sick lance
vast zinc
wintry sluice
#

room tester?

shell nova
wintry sluice
vast zinc
sick lance
#

Jayy's colour is lead bot dev

crude stump
#

Something that strikes fear into users

shell nova
crude stump
#

πŸ₯΄

wintry sluice
wooden totem
# sick lance

oh it is yellow lol, my monitor has more orange yellows

rapid merlin
crude stump
#

A white name with a black shield

#

Wait no

crude stump
#

Black shield wouldn’t show up

#

White shield with a white name

wintry sluice
#

white/grey is the unroled colour

crude stump
#

😨

shell nova
sick lance
shell nova
#

Or the dreaded '... Is typing'

normal fable
#

Morning Hydra. πŸ™‚

shell nova
shell nova
vast zinc
#

0x3 enjoy god status

#

amongus

wintry sluice
#

nah, 0xD is god

crude stump
#

I’m curious how do you guys even choose mods. There’s so many qualified people in here I feel like it would be tough

vast zinc
sick lance
#

Mods are chosen from the Community Mentors.

crude stump
#

Ooh

shadow hill
crude stump
#

That makes sense

sick lance
#

Community Mentors are voted in by the current CM's.

wintry sluice
#

far better than strange women lying in ponds handing out swords, to be sure

fickle inlet
#

hi

sick lance
#

HEllo.

sick lance
fickle inlet
#

fine

shell nova
crude stump
#

Hell yeah

wintry sluice
#

makes more sense with a \/

#

/verify

crude stump
#

I feel like that would confuse someone more

vast zinc
#

../../../../../verify

crude stump
#

. /verify

#

That’s better

vast zinc
#

i am surprized how i didn't get ban yet

sick lance
#

Why is that?

normal fable
#

I'm still going through that command challenge that shadow posted a few days ago. 🀣

wild rose
#

it's pretty fun but challenging

boreal scarab
#

Scrolling through YouTube Shorts and I end up getting @hasty sand in my feed. Mfer's hacking my YouTube too kekw kekw

chilly veldt
#

wait wrong song

hasty sand
#

🀣

#

Can't type today?!

chilly veldt
#

me neither

#

been awake since 3 am

#

πŸ˜„

hasty sand
#

I don't know what time it is there, but it's almost noon here.

#

Or I'd be taking a nap too

chilly veldt
#

just got home after work, stopped working at 2:30pm as I started at 6 am

wild rose
#

I don't know how you do it Bella. I work from home and I'm dead asleep by 9 or 10pm.

chilly veldt
#

it's the thoughts

#

the numbers make me awake

sick lance
#

0day is alive.

wild rose
#

It's the voices for me

sick lance
#

I think Relax was going to send out a search party kekw

loud marlin
#

oof

#

but i guess hess afk now since im late lol

sick lance
#

You missed by minutes.

loud marlin
#

ill pay Sopranos guys to bring 0day to discord πŸ™‚

#

dinosaurus extingt but no trace of 0day hehe

vast zinc
boreal scarab
#

Server ramps up speed and I lose internet connection.... fun

loud marlin
#

bsod is next

#

now we expect something smart to tell...

boreal scarab
#

I was playing a game, then it said no internet... I check the router, that's fine. Check my phone, down, laptop up.... like tf

loud marlin
#

but we will be wrong

crude stump
#

How long have y’all been hacking

uncut cove
#

got this mail here

loud marlin
wild rose
crude stump
#

Hm

#

12 years

#

?

wild rose
#

12pm

boreal scarab
crude stump
#

Ment

wild rose
#

Check the uptime of your router. It sounds like it restarted, since other devices were randomly offline too i.e. phone.

wild rose
boreal scarab
#

Nothing but PSU alerts....

wild rose
#

maybe it's time for an upgrade.

boreal scarab
timid prism
#

u

#

what to do when ur bored

sick lance
boreal scarab
#

That router was changed recently, been good to me..... minus the VLAN headache it's causing me right now

timid prism
#

🐱

boreal scarab
#

Browsing round Shodan....

#

Do you think they have enough open ports?

loud marlin
#

more than 7

boreal scarab
#

But wait, there's more!

#

Every one of those ports? NGinx

wooden totem
#

What's your favorite

boreal scarab
#

They're all Synology disk stations NotLikeThis

shut hawk
#

Security through obscurity 🧠

boreal scarab
#

That's not even the best one. Browse another category, they got CVE's going back to 2006......

#

82 CVE's on this one machine... JFC

#

One exploit doesn't work? Try 81 more!

#

I'm honestly losing braincells browsing Shodan.... I have lost faith in some people

crude stump
#

What you doing

boreal scarab
#

@crude stump

#

Browsing some categories in Shodan, (and for the mods, ONLY BROWSING) the amount of shit I've seen open that shouldn't be is astonishing

simple valve
#

IT 🀝 not having an accurate inventory of assets

scenic shuttle
#

I really wanted to do capture the ether, any place where I can practice it

#

cause ig the rinksby network is down

sick lance
boreal scarab
cloud socket
#

Hi all. I just subbed to tryhackme.com and I'm at the Linux fundamentals part 1 module. I've been trying to get openVPN to work but it will not connect to the configurations given to me by tryhackme. I cannot answer the provided questions and complete the rooms without opening the machine on the vpn. There is a different machine on tryhackme called the attackbox but it can't be used for these specific questions. Is anybody able to help me figure this out? I'm just starting my venture in the cybersecurity area.

sick lance
boreal scarab
sick lance
sick lance
cloud socket
boreal scarab
#

So..... got MalwareBytes browser guard, browing some ports on Shodan.... get an alert:

"Website blocked due to insecure login"

sick lance
boreal scarab
#

I think I laughed the loudest I have ever laughed at that message

cloud socket
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 2080)

sick lance
young egret
#

hi

cloud socket
sick lance
sick lance
sleek shard
#

Is there a way to configure local dns on ubuntu using commands/shell scripting?

#

I have found people doing it using the GUI only but surely you can do it through the terminal?

twilit phoenix
#

Holy Fucking Mother of God

cedar scaffold
twilit phoenix
#

I just spent two hours troubleshooting a script because i missed a single hyphen

#

Apologies for the profanity

cedar scaffold
#

hyphens, spaces and capitalisation... the true terrors

twilit phoenix
#

Indeed

normal fable
#

Like when you miss a semicolon...

sick lance
sleek shard
#

Trying to configure local DNS to use quad9's service (9.9.9.9) as the default DNS server using shell scripting

shut hawk
#

(if I remember correctly)

#

and then netplan apply

sleek shard
shut hawk
#

honestly, I may be completely wrong - haven't used ubuntu in a long time so

sleek shard
#

no idea but I just opened the netplan dir and it only has one file (.yaml)
and it has like 3 lines none of which are useful or related to dns

shut hawk
sick lance
#

I'd try the /etc/resolv.conf

river drift
#

what is the discord token for in the account details part of tryhackme?

shut hawk
#

To verify your account here

#

if you click someone with a coloured name it will show you their level

sick lance
#

I now have 15 E-mails with my beta invite to Arc...

shut hawk
#

they really want you to use it lol

sick lance
#

I get a new E-mail every second day...

shut hawk
#

I got some on my other email accounts (around 4 unique in total)

wintry sluice
#

is it anygood, this arc thing?

shut hawk
#

its alright

#

very morden design, but extenions don't really work well

sand trench
#

WEEWOOWEEWOOWEEWOO

sleek shard
# sick lance I'd try the /etc/resolv.conf
 cat /etc/resolv.conf 
# This is /run/systemd/resolve/stub-resolv.conf managed by man:systemd-resolved(8).
# Do not edit.
#
# This file might be symlinked as /etc/resolv.conf. If you're looking at
# /etc/resolv.conf and seeing this text, you have followed the symlink.
#
# This is a dynamic resolv.conf file for connecting local clients to the
# internal DNS stub resolver of systemd-resolved. This file lists all
# configured search domains.
#
# Run "resolvectl status" to see details about the uplink DNS servers
# currently in use.
#
# Third party programs should typically not access this file directly, but only
# through the symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a
# different way, replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 127.0.0.53
options edns0 trust-ad
search localdomain
topaz kiln
#

what should i do first comeplete begginer or web fundamentals

sleek shard
#

Am I supposed to change loopback add 127.0.0.53 to 9.9.9.9 to make it my default dns?

#

or add a line under it
"nameserver 127.0.0.53"
"nameserver 9.9.9.9"

river drift
sharp citrusBOT
sleek shard
#

Thanks. Is there a way to confirm it's working though?

sick lance
naive violet
#

Look into systemd-resolved

sick lance
#

Mine doesn't say all that, πŸ˜…

hushed adder
#

I'm back πŸ˜„

sick lance
#

You were gone?

hushed adder
#

about 3-4 month ago

wintry sluice
sick lance
hushed adder
#

I didn't want to do anything, but I'm fine now

wintry sluice
#

there be the reason then πŸ˜›

sick lance
#

Kali is better? I agree.

hushed adder
#

Kali is better

wintry sluice
#

it is, but wolverine is using ubuntu

hushed adder
naive violet
#

I'm amazed at people's willingness to look past "Do not edit."

#

Like that's clear...

wintry sluice
hushed adder
wintry sluice
#

heresy

hushed adder
#

you should have realised when you saw the panel below

wintry sluice
#

I did. hence why it needs more xfce πŸ˜„

#

cool background tho

normal fable
#

needs more cowbell

hushed adder
normal fable
#

moo therea216H

sand trench
#
❯ cat /etc/resolv.conf
# resolv.conf autogenerated by '/usr/bin/ivpn-service'

nameserver 127.0.0.1
❯ cat /etc/resolvconf.conf
# Configuration for resolvconf(8)
# See resolvconf.conf(5) for details

resolv_conf=/etc/resolv.conf
# If you run a local name server, you should uncomment the below line and
# configure your subscribers configuration files below.
#name_servers=127.0.0.1
#

TADA

sick lance
#

Magic!

sand trench
#

vpn works flawlessly so far

vocal dragon
#

Guys how to not become a script kiddie

blazing granite
blazing granite
wintry sluice
#

could even write your own versions of tools to gain a good understanding of whats going on under the hood

shut hawk
vocal dragon
blazing granite
wintry sluice
wild rose
shut hawk
vocal dragon
young egret
#

use a notetaking tool like

#

obsidian

sand trench
#

eeew relying on spotify

young egret
#

or cherrytree

vocal dragon
#

πŸ‘

#

Gonna check them out

#

Thanks guys

sand trench
#

TRILIUM NOTES

blazing granite
sand trench
#

for that store in database instead of .md files meaning no angry windows defender

young egret
#

how do you structure yours

sand trench
#

structure??? you structure your notes???

wild rose
#

you can structure them by tools, rooms, general info.

sand trench
#

and here we see apple getting sued in anti trust cases in the usa

cedar scaffold
#

iv just decided I should probably keep electronic notes and not paper ones, gonna start copying stuff into obsidian this weekend. looks decent from what iv seen of it so far

young egret
young egret
twin ridgeBOT
#

Gave +1 Rep to @wild rose (current: #380 - 12)

vocal dragon
loud marlin
#

@boreal scarab

sand trench
#

where is the ceramic 3d printer???

loud marlin
#

soonℒ️

wintry sluice
#

you can 3d print ceramics?

sand trench
loud marlin
#

not sure ceramic as 100% ceramics. but you have filaments that are infused with things. like carbon, wood and so

loud marlin
buoyant tree
#

anybody here got final fantasy knowledge

wintry sluice
#

I'm pretty sure its a game series.
but that is about the extent of my knowledge of it

wild rose
#

"final fantasy knowledge"?

loud marlin
#

ask chatGPT πŸ™‚

buoyant tree
loud marlin
#

yes. and quite big serries

buoyant tree
#

thinkin about starting playing the series but need agood order

wintry sluice
#

sequencial?

chilly veldt
buoyant tree
buoyant tree
forest forge
#

yooo i got a prblm plz

#

while trying to send files using nc

sick lance
#

FF series should be played in the order they're released in.

forest forge
#

this on ma machine
└─$ nc -l -p 1330 < linpeas.sh

this on the remote : basterd@Vulnerable:/tmp$ nc ip 1330 > linpeas.sh

mossy river
#

Honk mimimi

sick lance
#

With the exception of FF X and FFX-2, FFXII and FF VII with the spins off, they're not really related.

You'll get the odd easter egg here and there.

crude stump
indigo sapphire
#

hey guys

wild rose
#

not really, there's no real connection between them besides mortifies

crude stump
forest forge
mossy river
indigo sapphire
#

ive been having a problem with my VPN connecton

#

look

forest forge
crude stump
#

Said it first

#

Ha

mossy river
sick lance
#

Not on mine you didn't.

wintry sluice
crude stump
#

Bruh

#

I call edited

sick lance
#

It's not, refresh the client.

crude stump
#

I’m joking but I am refreshing but it’s still saying I’m first

#

Nvm

wintry sluice
sick lance
#

Or, use the channel that is intended for room help, lol

wild rose
#

out of context.

sick lance
valid mauve
wild rose
#

It's better than remake

devout palm
#

Hiya

valid mauve
devout palm
#

Sup

valid mauve
#

Not much, currently digesting wonderfully tasting food and thinking about taking a nap (I mustn't, I got stuff to do that's got a deadline that's tomorrow morning). You?

mossy river
#

Can’t wait to cook, so hungry

devout palm
blazing granite
mossy river
#

Twisted my whole perception

whole yew
wintry sluice
blazing granite
#

I'm here all way πŸ˜‰ πŸ˜‚ πŸ˜›

crude stump
loud marlin
whole yew
loud marlin
crude stump
#

Hm I’m guessing it’s sort of like a resin printer but with ceramic?

blazing granite
loud marlin
umbral bay
loud marlin
#

full size 3d print. =/

wintry sluice
loud marlin
#

y

#

there is 20kg of filament for sure to make it

crude stump
#

What’s the budget to make that

#

Gotta be over 100

#

In filament

loud marlin
#

1kg of filament is around 30e cca

wooden totem
#

are people with a cybersecurity profession more likely to get cyber attacked?

wintry sluice
#

yes, because they are more likely to be on a targeted network

crude stump
#

I mean if your a admin for a company a threat actor might focus on you then someone else

#

Basically got the keys to the city

wintry sluice
#

same reason tornado chasers are more likely to get caught in a tornado than the general population

wooden totem
#

One one hand, they are useful targets. On the other hand, they know more how to secure themselves

crude stump
#

But at the same time a cybersecurity specialist knows more about internet safety so going after someone with none might be there main priority

wild rose
#

Not entirely, if you take the basic steps to protect yourself like not reusing passwords, enabling 2FA, and keeping up on your cyber hygiene you shouldn't be a high target compared to someone in HR, C-suite, or a domain controller admin.

wooden totem
#

I wonder what's the most targeted cybersecurity position

wintry sluice
#

intern

wild rose
#

depends on your followers on twitter/X lol

#

the more followers the bigger the game.

crude stump
#

Like watchdogs

#

Ooo

#

Never thought of that

#

Crazy

wild rose
#

yeah don't do that one. lol or don't be on social media at all.

wintry sluice
#

social media is the antithesis of social

#

whoops, didn't mean to reply to that

wooden totem
#

Uploading the whole daily schedule online

cedar scaffold
#

as a not super social person it's been eye opening reading the mitnick book, just how much he did with lists of employees/roles and such MonkaThink

crude stump
#

Which book?

cedar scaffold
#

ghost in the wires

crude stump
#

Thanks

cedar scaffold
#

np it's a good read/listen

loud marlin
sand trench
#

boing boing boing boing boing boing boing boing

serene wren
#

SEC573: Automating Information Security with Python

#

Anyone know how to get a free course of this

blazing granite
serene wren
#

sec573: automating information security with python free GIAC

#

Anyone know how to get a free course of this

bitter quiver
#

Work for a company/instutution that pays for you to take it.

mossy river
#

If it costs money, someone has to pay for it

naive violet
#

It will not be free

crude stump
alpine nebula
#

who tf payn for tht

crude stump
#

People

alpine nebula
#

why is it so much lol

bitter quiver
alpine nebula
#

have u guys taken it?

bitter quiver
#

I got about 15 grand worth of training at one point that way.

alpine nebula
#

i mean if u count degrees

crude stump
alpine nebula
#

ahh that makes sense

bitter quiver
#

Yeah, generally 100% a business need or contract obligation

alpine nebula
#

if they can get a package deal

crude stump
#

Yep

#

Money talks

alpine nebula
#

anyone know of any internships to apply for?

#

i getting at over 200 applications this week

crude stump
#

Search indeed

alpine nebula
#

got every indeed post

bitter quiver
#

LinkedIn/Indeed will help you far more with that as it will need to be local.

#

Use LinkedIn

alpine nebula
#

linkedin covered too

bitter quiver
#

Hmm

alpine nebula
#

lockheed and raythion covered

bitter quiver
#

Could be your CV isn't making it through bots or you are just lost in the volume

crude stump
#

Wdym covered

alpine nebula
#

i mean i only applied to these within the past week

crude stump
#

Oh

alpine nebula
bitter quiver
#

Bruh, some of those takes a very long time to hear back on lol

crude stump
#

It will prolly take awhile

bitter quiver
#

Even months

alpine nebula
#

yeaaa

#

yall think the netowrk + cert is worth anything?

shut hawk
#

Over what time period have you sent almost 200 apps?

alpine nebula
#

or is there a better/cheapeer alternative

alpine nebula
crude stump
#

Damn lmao

shut hawk
#

Wow..thats nuts, do you just spray and pray?

alpine nebula
#

lmao

crude stump
#

What are you gonna do when they answer you

alpine nebula
#

for the most part

#

10 have cover letters

alpine nebula
crude stump
#

Your wild

#

Over 200 applications in 8 days

past sparrow
#

spray and pray is best way to get interview if you don't know what you are doing

alpine nebula
#

then what entails knowing what you are doing?

crude stump
#

Somones with connections

alpine nebula
#

i have multiple resumes to cater to position

crude stump
#

Get a job fast

alpine nebula
#

yeaaa i need to go out and network

#

cant seem to find any tech related events tho

#

in NYC too

#

only one i found was some bootcamp thing

shut hawk
past sparrow
past sparrow
shut hawk
#

I guess

alpine nebula
crude stump
#

Personally Bryce. Ask the ceo out for a drink

#

Works 100%

alpine nebula
#

lmao

#

why not a coffee

#

or a spa day

crude stump
#

Yes

alpine nebula
#

on me

#

ill cover the bill

crude stump
#

Hand him a Hundred and tell him to buy himself something good tonight

past sparrow
#

naw, you need to get along with the person who would be involved in the hiring process, go out with a "potential future boss", have few drinks and some man to man conversations

crude stump
#

Tell him you live in a mansion

wild rose
#

I slept my way to the top

buoyant tree
#

Anybody here going to get the brain chip

wild rose
#

at my desk

crude stump
alpine nebula
buoyant tree
crude stump
#

Maybe if I’m paralyzed

wild rose
#

or a monkey

crude stump
#

Wyd if someone starts controlling your thoughts

#

πŸ˜‚

shut hawk
past sparrow
crude stump
#

Exactly that. You hear a faint whisper in your ear β€œtake over the world my personal robot”

past sparrow
#

But as Warren Buffet said - if you don't make money while you sleep, you will never become rich
So I started sleeping at work

buoyant tree
wild rose
#

that's why I get paid overtime when I'm oncall

buoyant tree
#

its only able to read your thoughts and upload them atm

wild rose
#

like if you want to play Pong

shut hawk
past sparrow
#

don't want to download someone else's thoughts

wild rose
#

they'll probably serve you ads 24/7.

devout palm
#

My thoughts: ||Never gonna give you up||

wild rose
#

Then you'll need an additional chip to block ads.

crude stump
buoyant tree
#

I almost got rickrolled atm

past sparrow
#

then you need to pay for subscription to not have ads

#

but the service will change and you will only pay for less ads

crude stump
#

Wait how does the chip work. Does it not have a battery?

#

Like how does it charade

buoyant tree
crude stump
#

Charge

buoyant tree
#

its got a battery

#

and it charges like phones

wild rose
#

so you have to plug yourself in using USB-C

crude stump
#

Yk those movies where they gotta plug themselves in with a charger to sleep

#

Lmao dex is one step ahead of me

astral fiber
#

hi all i have question how i can do architecture of honeypot for protect system if you have advice

astral fiber
#

i want do like simple architectur for see threat in system by using honeypots

naive violet
#

Ok, so do it?

devout palm
#

You can build a fake SSH server

crude stump
devout palm
#

For instance.

naive violet
#

Well documented

astral fiber
astral fiber
devout palm
astral fiber
#

its just introduction for understand

#

this the probleme

#

for me

naive violet
#

Spin some up in a lab and see what they do

astral fiber
#

i want like using dionaea on docker for see in the first how its works

naive violet
#

Try it

#

@astral fiber Do not send unsolicited direct messages, it is against the rules

#

@astral fiber Please do not send DMs without getting permission first. It is against the rules.

astral fiber
#

okay i understand

serene wren
naive violet
#

You realise that SANS courses are notoriously expensive right?

serene wren
naive violet
#

There's Blackhat Python instead if you just want a book

serene wren
#

I see you can join the school for free till you get a job

naive violet
naive violet
serene wren
#

Yah most of it is showing you how to connect sockets and make tools. Plus command and control centers with python. I rather have a project based book to do some little sample works

naive violet
#

Find some projects then and do

serene wren
#

😦 I want that course though

#

Very structured

naive violet
serene wren
#

More modules than black hat hook

#

No I want a book that reflects it's course

naive violet
#

So you need to buy the course for that.

#

SANS/GIAC are like other cert providers.

serene wren
#

Pentesting CompTIA reflected intro to ethical auditing

#

And everyone like sybex makes a book

#

Why not GIAC

thorn basalt
#

hey can someone help me with an encrypted string? i think it's base64 but can't decrypt it

naive violet
wide quarry
#

Hello

naive violet
#

SANS provide good training material. That's their market offering. No one tries to write material for their courses and exams

mossy river
#

I asked where it's from, not to post it πŸ™‚

thorn basalt
#

ok, it's from reverse shell trojan malware, that connects to C2

sharp citrusBOT
alpine nebula
#

wtf comptia pentest is 400$

naive violet
thorn basalt
#

so the connection allows to execute commands and it sends them encrypted

alpine nebula
#

should i get it

serene wren
alpine nebula
#

or is getting the normal comptia what i should aim for

serene wren
#

It's like everything from the PenTest PBQ and then some

naive violet
#

Comptia are a company

alpine nebula
#

like would it be weird to have only comptia pnetest

#

and nothing else

naive violet
#

No

serene wren
naive violet
#

🀒

serene wren
#

Everyone posts materials for books online and learning

alpine nebula
#

and i can go into this test bare knuckle?

#

fuck it ima do pentesting comp tia

serene wren
#

No they want you to pass by their definitions

#

And it's just PBQ to become junior PenTest

#

Also pentesting by their definitions is just auditing not like a criminal bug bounty hacker

alpine nebula
#

is there any entry level jobs and or internships tht make sense for a pentest comptia cerrt?

serene wren
#

No penetration jobs are usually for people with higher experience and higher degree

naive violet
#

Lawd

serene wren
#

PenTest gives you that your knowledge in pentesting not being a super skilled in hacking and finding every flaw

alpine nebula
serene wren
#

Which company wants

#

Companies want people with experience in pentesting, you got to start from sysadmin or something

naive violet
#

You very much don't have to

serene wren
#

Look at job description 3-5 years experience in diagnosis and blah blah blah certifications

naive violet
#

Lmao, that's not a requirement.

serene wren
#

Yah you can have labs to prove you did in GitHub

#

That's true

naive violet
#

They're always "our ideal candidate" not requirements

#

And lawd not github

#

This ain't dev

alpine nebula
#

ok ok

#

which is the best recognizable pen testing cert

naive violet
#

OSCP has the best mindshare IMO

serene wren
naive violet
#

Lmao

normal fable
#

OSCP is recognized globally. Not all certs are iirc.

naive violet
#

OSCP doesn't tick compliance boxes for pentest roles

serene wren
#

I disagree with not having programming knowledge to show like CompTIA PenTest shows

clear jackal
#

I push sensitive outputs from pentesting engagements to public github repos. My customers enjoy being able to access the findings quickly.

alpine nebula
naive violet
alpine nebula
#

nyc

#

USA

normal fable
#

Sec+ is good for gov work in the US..

serene wren
naive violet
#

US Pentest+ ticks the box but I think DOD 8570 or whatever is getting overhauled

naive violet
alpine nebula
#

ok so DOD 8570 is the best?

serene wren
naive violet
normal fable
#

Listen to moose. πŸ™‚

clear jackal
#

8570 only matters if you're trying to do DOD work

alpine nebula
#

ok lets be straight forward here

clear jackal
#

8140 is the replacement but it's not fully implemented yet

alpine nebula
#

which is the best to get if u have none

#

that ticks boxes

shut hawk
#

awhhh man

naive violet
clear jackal
#

Security+ is the baseline for security

serene wren
#

Best to work in the field and I need help finding that impossible content

clear jackal
#

That exam is the bare minimum amount of knowledge that you need

chilly veldt
serene wren
#

There is exam questions and no study guide yet

chilly veldt
#

yup kek

whole yew
#

Strongly recommend you don't get a cert just to get a cert, or because you think it will open doors. It won't, by itself. Look at job reqs in your area, and target your learning for the things those are asking for.

serene wren
alpine nebula
naive violet
serene wren
naive violet
#

For what class?

#

The sans one?

serene wren
#

Yup

naive violet
#

I swear to whatever deity, stop trying to pirate that damn sans course or I will ban you

whole yew
#

Government jobs are a different kind of thing entirely than private sector. Comparing hiring requirements between them is like comparing arsenic based life to carbon-based.

clear jackal
#

601 will be retired*

clear jackal
#

Look up the retirement date and if you think you can study and take the exam before it sunsetting, go for it.

thorn basalt
#

can anyone help me with decrypting a string? I'm stuck

mossy river
naive violet
thorn basalt
#

but i need to be level 13 or OSCP, lol

naive violet
#

It's a potentially dangerous area of study

thorn basalt
#

ahh okay

crude stump
#

Scary stuff right there

cedar scaffold
#

one day!

blazing granite
#

two days!

crude stump
#

3 days

cedar scaffold
#

its gonna take me a while to get top rank, but I look forward to knowing more by then stonksup

naive violet
#

Yes that's what happens when you expose stuff to the internet

mossy river
#

You're on public infrastructure, it'll happen

crude stump
#

There watching

naive violet
#

They run a cloud

blazing granite
#

wait for the 40 thieves πŸ˜‚

mossy river
#

Good

#

Dropshipping is the worst thing to exist

serene wren
#

They wanna know what your cooking

crude stump
#

They knew you were making to much. Suppressed you

near hawk
#

I need to order more chocomel

mossy river
#

Flavoured creatine was probably not my best purchase

near hawk
#

Yea, never go for flavoured

mossy river
#

I 'dry scoop' so I thought it would be better to go flavoured

blazing granite
#

it doesn't sound good

loud marlin
#

non flavored creatine is hell =/

mossy river
#

the flavour is not that good.. strawberry and lime

#

I think I'm conditioned to the chemical taste of unflavoured, it doesn't phase me

near hawk
#

I don't get point in flavoured creatine when theres shakes for that

mossy river
#

I thought it would be nicer for dry scooping but it's so strong

loud marlin
#

you can take with no flavor for sure. kreatine don't have bad taste, compared to BCAA natural taste

mossy river
#

It tastes like chemicals lmao

#

it tastes terrible

clear jackal
mossy river
loud marlin
#

yep. tbh one of most terrible taste i know from chems

mossy river
#

It's not dry scooping per say, I just fill my mouth with water and scoop into my mouth

near hawk
#

Flavoured creatine is ultra processed that's why I stopped taking it

mossy river
#

You aren't meant to dry scoop anything

near hawk
#

I usually take creatine tablets

loud marlin
#

flavor is added. you can also use some dextroze if you wish to add some "taste" to almost anything

mossy river
#

You should only take dextrose if you need it

loud marlin
#

i was more in to add small amount for taste

#

or to "mask" some bad taste

mossy river
#

Mhm but not to confuse your statement with "dextrose makes everything taste better" because you will give yourself diabetes

serene wren
#

Whats the string malware analysis tool called Yet another ****

#

Always forget

#

Found it nvm

crude stump
#

Like eating a popeyes biscuit with no bev

left pebble
#

is there a way to use the static analyse room for malware analyse on a file i found? cant use my own pc as iam not at home 😦

#

or do i break the rules or smt when i transfer it via the keyboard ?

mossy river
#

I believe putting malware onto the machines is against the site's terms of service.

#

They are not intended for personal use regardless.

left pebble
#

ahhh damn 😦 ty for the answer

left pebble
#

@crude stump y or falcon sandbox, the problem is, i cant deobfuscate it and just get the sourcecode there

crude stump
#

Jared I’m saying if he thinks he has a file that’s infected scan it with malwarebytes

#

Jabba I ment

left pebble
#

its infected. i already know it

crude stump
#

Oh

left pebble
#

100%. i also know which techniques it uses. but i need to get a vm where i can decompile & deobfuscate it, so i hoped i could quickly take the room vm as there are already the tools i need and the possibility to transfer it

#

but if its not allowed i dont do it. thank you anyway guys

mossy river
#

We limit malware discussion to the advanced channels πŸ™‚

left pebble
#

@mossy river guess i have to link my discord to the thm account soon. anyway πŸ˜› ty for answer

twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1199)

left pebble
#

@crude stump ty

crude stump
#

Or I mean

#

Pin it so all you gotta say is check pins

mossy river
#

It's confusing and still relies on me saying "check pins"

#

Someone might check the pins looking for resources etc.

crude stump
#

Ah true

bitter quiver
#

Had AI make a cool claymation image of a 1980s "hacker" in an office setting and honestly, it's neat. usually very hit and miss

crude stump
#

Bros hacking a city

sand trench
#

is that the empire state building???

crude stump
#

Yes lol

#

Mr hack the world

wooden totem
# bitter quiver

im surprised it made a decently good looking chinese characters

bitter quiver
#

Yeah it usually fumbles on that

fathom hull
#

unable to download wreath vpn :(

mossy river
fathom hull
#

none

#

need to download the config file

mossy river
#

Open the wreath room and screenshot the network diagram please

fathom hull
#

alright

sinful moon
blazing granite
#

@sinful moon Hi!!! No time no see πŸ™‚

sinful moon
#

Heya! (also the above is halarious)

#

I've been around but busy with work as always, but did get to see a show last night which was nice

blazing granite
sinful moon
#

Nah only one or two timezones away from me, I'm in EST. But nice!

#

I've met a lot of retro gaming friends from Argentina on Discord

blazing granite
#

Israel is 5 hours and 6 in summer hours ahead of Argentina the first 3 days jet lag was the B.... πŸ˜‚

sinful moon
#

Oh damn, I forgot you were based out of Isreal but yeah, must have been rough

#

Thankfully I've not had to experience jet lag. I've just been up and down the US East coast for the most part

bitter quiver
#

Half my retro systems friends be from abouts there

sinful moon
#

Oh yeah there's plenty in South America, especially with the massive Sega dominance

buoyant tree
#

Heya Ellie

#

long time no see

buoyant tree
sinful moon
#

lol that's the point, indeed

#

It's spitting out a basically "I can't fufill that request" prompt, but this is a song generator so it'll still make a song out of it

buoyant tree
#

I sadly watched madame web since I got a free ticket

#

and I have to say its a ~~great ~~movie

buoyant tree
sand trench
#

anyone wanna have some fun troubleshooting with shadow???

buoyant tree
sand trench
#

somehow shadow about once every 3 months corrupt their sudo cache making it impossible to run sudo commands until they relog

#

any idea what could cause it or how to fix???

sinful moon
#

I've not run into that in 16 years of Linux use. Real weird issue

buoyant tree
sinful moon
#

Are you using any PAM stuff?

sand trench
#

it fails on the password prompt taking all passwords as invalid

sand trench
sinful moon
#

That's about my only thought, other systems that hook into this sorta thing

sand trench
#

not a huge problem as reloging fixes it

#

just it feels weird

sinful moon
#

What is that PAM solution you're plugging in if you don't mind me asking?

sand trench
#

pam is only plugged into lightdm and not sudo

#

and in there shadow also added the option to use a yubi key for login

sinful moon
#

Fair enough, yeah normal use case

#

Hmm, maybe something weird there but I doubt it

#

I just know my work MFA can hook into PAM and many other security solutions can so I was curious

fallen swan
#

You are asked to test an application but are not given access to its source code - what testing process is this?

sand trench
#

if you wanna read shadows sudoers file

#

does not really give any useful info

fallen swan
fallen swan
# wild rose black box

wow, thanks!, i was writing black box testing, and the system keeps saying incorrect answer

twin ridgeBOT
#

Gave +1 Rep to @wild rose (current: #352 - 13)

shut hawk
sinful moon
#

lol indeed, please sing your stock AI "I can't complete this request" responses to me

crude stump
#

the copy and paste on the attack box is insufferable

sinful moon
#

And that's why eventually you use a VM or VPS as an attackbox imho

buoyant tree
sinful moon
#

I mean it works on Firefox, but you have to jump through the same hoops. There's no true copy buffer shared between them

crude stump
sinful moon
#

Fair enough

crude stump
#

its just the dang highlight disapears

#

like its highlighted and when you click off of it to copy it disapears

buoyant tree
#

Also Ellie since you're here, give me a couple of the best live action adaptations you got

crude stump
#

you ever wanna punch a hole through your screen

sand trench
buoyant tree
sand trench
#

oh missed the wanna in there

rapid merlin
#

This van near my house is like on a schedule, every 7 days at 12 at night, he moves his van somewhere else on our street

#

Very weird

sand trench
#

....

crude stump
#

lmao what

buoyant tree
rapid merlin
#

Literally LOL

#

They need to change their playbook, the movies have taught me enough πŸ˜’

buoyant tree
crude stump
#

see in the window a whole server rack in it

rapid merlin
#

Honestly the dude inside wearing full black with a black cap on, I’d rather not even look in his direction lmao

buoyant tree
rapid merlin
#

My assumption is he’s living inside of it so he’s moving it around to prevent someone reporting him

rapid merlin
buoyant tree
crude stump
#

omg i cant. this whole time my snort rules werent working because instead of making the sid:100001 and 100002 i made the rev1 and rev 2

sinful moon
sand trench
sinful moon
#

And even then the movies often differ dramatically vs the sorce material

crude stump
buoyant tree
sinful moon
#

Tired of movies with original plots??? But uh my favroite adaptations I've mostly already told you

buoyant tree
#

hmm

#

What about a movie with great sound design and nice music

#

Watched baby driver, something like that

sinful moon
#

2001: A Space Oddesy, Blade Runner, Starship Troopers, The Maltese Falcon, and others could be considered adaptatinons

sinful moon
#

Same director

#

Fantastic movie

buoyant tree
#

Watched scott pilgrim

#

enjoyed it

sinful moon
#

also same director lol

buoyant tree
#

yea I know

#

shaun of the dead probably next

#

been on my watchlist for a while

sinful moon
#

yeah it's a good time for sure

buoyant tree
#

Edgar Wright has a great knack for creating fun movies

sinful moon
#

Hot Fuzz is also decent but not quite as up there, then his bar hopping one was only alright imho

buoyant tree
sinful moon
#

Going back though, his TV show, Spaced, was quite good

buoyant tree
#

I believe I watched it a few years ago but its worth a rewatch

rapid merlin
#

Shaun of the dead and hot fuzz are great

sand trench
#

should definitely rewatch hot fuzz

#

remember so very little for said movie

crude stump
#

there should be a cyber warfare room where you battle it out with other hackers

feral shale
crude stump
#

True

boreal scarab
#

@pallid lotus vegan cheese burger!

valid mauve
#

Screwed around with SSH certs and SSH-SK keys, fun stuff.

#

Nearly locked myself out of everything, but fun.

topaz kiln
#

hacking is so fun!!

buoyant tree
blazing granite
valid mauve
#

Cycled all my keys, got FIDO-backed SSH keys and login manager now.

I'm gonna be better secured than the Infra I used to manage.

Wait, I disable root login, so I already am! kekw

#

Tomorrow I'm gonna yubi LUKS. Thought it best to do that when it's not 3.30am.

upper bison
#

Quick question: what is a busybox

#

I've searched it on Google but I still don't get it

#

Is it a set of "pre-compiled" binaries or "pre-made" Linux commands to use/upload on other Linux machines?

#

Correct me if I'm wrong

clear jackal
upper bison
#

Oh wow!

#

It's actually one command with loads of Linux binaries in one compound

normal fable
#

symlinks to busybox for commands.. limited... slightly.

rapid merlin
#

Hii guys I have a question I am doing pre security from THM I want the certificate do I have to pay for it or it's free

#

πŸ˜…

normal fable
#

Certificate is free. It's not a certification. Don't get the two confused. πŸ˜‰

#

I don't know if ISC2 is still doing the 1MCC.. but if you're looking to be certified.. it may not be a bad option..

#

gawd.. I don't know why nobody is liking me on my tinder.. I DID put that I use Arch.. kekwsanta

naive dock
normal fable
#

I should put "If you've never built LFS.. you should." lol

#

or some random 1337 looking Linux command.. that'll get me friends. lmao

lucid wasp
#

Um

normal fable
#

brella

#

β˜”

#

🐬 therea216H

buoyant tree
normal fable
#

It stopped earlier. WA.. go figure.. rain.. heh

buoyant tree
#

hmm, raining for me atm

normal fable
#

I haven't been outside for a few.. so maybe.. I'll be in a bit.

normal fable
#

No rain

past sparrow
#

Differating between certification and attendance certificate can be confusing if both words are so similar

normal fable
#

A certificate is merely an acknowledgement of completion whereas a certification is an accredited document stating that you have completed an exam on a certain subject by an accredited examiner. Best way I can state off the top of my head.

#

I am also not the smartest person in the room.

past sparrow
#

Sadly it is very ambiguous for many of us who don't speak English natively since it may or may not translate into 1 word

normal fable
#

English is hard.. Even for native speakers.

past sparrow
#

And well, even for those who know, you may think they are the same because root word is the same, well, luckily people find it out rather fast

normal fable
#

I look at all 'Certificates' as 'Certificate of Completion'. Certification is different. It's a 'proof of knowledge' type thing.

past sparrow
#

Yes

#

Funny how university degree is actually certificate of completion

normal fable
#

Rennet.. you are used to make cheese.. πŸ˜› kekw

#

And it's my sleepy time. Good night all. πŸ™‚ Hope you sleep well or have a good day.

past sparrow
#

Goodnight

past sparrow
shell garnet
#

hey all i have been facing issue in connecting breaching AD lab i have connected with my VM /openvpn. VPN is assigning me the IP but in THM the connectivity status still shows not connected.

rapid merlin
#

pinned messages in site support

buoyant tree
#

Heya Scrubz

sick lance
#

Hello

pallid lotus
boreal scarab
pallid lotus
#

Wait, what?
That's some impressive melting

boreal scarab
#

I was impressed too. Thing was damn good

sick lance
#

@pallid lotus tell your pfp to stop changing

pallid lotus
#

Happy?

sick lance
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #9 - 738)

pallid lotus
#

Literally didn't do anything, but Okey dokey kekw

tall elm
#

Hello guys i have a general question concerning AD (not related to a room) can i ask it here ?

sick lance
#

I know, it's for some reason my your pfp is the butterfly when I'm on the mobile app

tall elm
#

Thanks, my question is about Kerberos. The Service ticket content is composed if i understood well in two. 1/Service portion and 2/User portion. The Key for the Service portion can it be NTLM hash ?

sick lance
#

Unless I'm completly wrong, it's been known to happen kekw

tall elm
#

Yeah same for me but i saw on a website that it was encrypted with the account NTLM hash

#

so im confused

polar spoke
#

It depends on the kerberos type

sick lance
rapid merlin
#

Hi Scrubz

sick lance
#

Hello acme.

rapid merlin
#

Hyd?

sick lance
#

Good, yourself?

polar spoke
rapid merlin
#

Nice, im fine too, thanks

polar spoke
#

eType 23 TGS tickets are encrypted challenges where the key is the NT hash of the password

tall elm
#

There is more than one kerberos type ? Ok im more confused Hahaah

twin ridgeBOT
#

Gave +1 Rep to @polar spoke (current: #155 - 40)

rapid merlin
sick lance
rapid merlin
#

If all goes well, you will then receive a green role

sick lance
#

Oh! it's only 3 days.

For some I was thinking of two backs.

rapid merlin
#

Time flies