#general
1 messages ยท Page 94 of 1
no worries
Someone said to go for the S version, so I'm going to do it ๐ค
It's ยฃ5 cheaper so
it works on our macs at work?
well "doesnt work" = the camera stutters sometimes
u mustn't stare at ur own camfeed obessively like i do
Time to cancel my streaming arc
Solution is "use the propritary logitech software" but cant always install ๐ฆ
my friend uses a 4k go pro
windows and linux its fine for me tho
maybe I should've asked my mother for her gopro
oh well, time to go to work
I thought about using my GoPro
@chilly veldt are you a cybersecurity Engineer?
I am a security analyst and engineer yes
Damn ๐
Which certification do you have?
It's at least the new role I just got, but I am also a data technician working internal IT
I got eJPT (which I don't recommend) and BTL1
Wow just want to follow your footsteps ๐. Well am starting with the Tryhackme
To get the skills ๐
That's a good start!
I too started out with CTFs before starting my education and my first job
Why don't you recommend the eJPT?
It's too easy to pass for it to give any value, especially with the price tag that it has, the new edition has had a whole revamp so the infra is a little better, but the study material isn't the best and the fact you have to pay $750 to get access to training boxes is absurd
Yes it's entry level, but you can pass it with little to no computer knowledge
Okay
So which cert will you expect me to get in future once I am confident in the skills of getting in Tryhackme?
What does BTL1 cover?
I would recommend pjpt
Blue teaming
Basic SOC/IR/threat hunting knowledge
Mmm, maybe I misphrased my question
I want to know what it covers that any other blue team cert does not cover
Hands on usage of Siems and other tools, it's a practical exam
I see, interesting
Basically OSCP but blue teaming
is BTL1 required for BTL2?
It's recommended
I might want to jump straight to it, if it teaches a lot
It teaches you quite a good bit, would recommend taking the SOC paths on tryhackme with it
I use a Logitech wireless mouse
Itโs actually really good lol
I dropped it like 2 times
Still works
I've used logitech
I much prefer Razor
only 2k as well, much cheaper than SANS ๐ค
Oo it looks cool
Don't take BTL2 without having a company sponsor it
I had razer headphones but they broke
Of course, I would have my company pay for it
Goodie, just didn't know your situation
I'm looking to get wireless ones, I currently have razer kraken v2 iirc
I propose, explain, defend, they say yes or no
Yeah the wireless are better then the wires
Yeah, it was more if you were looking for job or already had one
Oh I have been in blue team / soc environment quite a while now
The reason my old headset broke is because just above the plug, I guess I did somthing idk but now only one headphone plays
So entry level certs I would rather skip and jump to the advanced ones where I can increase my competence
grr
This is going to be a question way off topic, but I am pretty sure there are avid star wars fans in this thread. Has anyone been following the new season of the bad batch?
Ima be totally honest, I never seen a starwars fan here
Ah, fair fair
Talk about yourself
Ah... well then. I guess I misinterpreted Jared | Jabba... lol I thought that was a subtle nod to ezra
eh hem.... 2 (:
Can we get a 3rd
But no, I haven't followed along, felt they gotten bad since the last couple of movies
They have :/ ...
Since Disney
Disney kills me... like they start some things off well, except the movies, then just derail themselves but rewriting canon events
Na someone hacked my account
How you speaking then
is @mossy river not a star wars fan? Is that not the Ezra nod I thought it was????
Hmm
because it was my other personality
Hello, welcome to Jabba the Rabbit(ใธใฃใใปใถใปใฉใใใ)! Jabba is a Flemish Giant rabbit who lives in Japan.
The main language of our channel is English because we want to share our videos with as many people in the world as possible.
However, because Jabba is a Japanese giant rabbit, Jabba's human talks to her in Japanese.
Subscribe to our channel so th...
you know... I truly learn something new every day
Donโt think that was there question jabba
Star Wars is okay
Wait you from Japan ?
I like spending time with my father, we usually watch the movies
Star wars was ruined by the new trilogy
I don't count the new trilogy... @near hawk
Valid response
Is it worth of time watching it ?
hey @rough gorge can I DM?
I havenโt watch any Star Wars
I give it try
honestly, the old republic is my favorite era
the fact that keanu reaves hasnt starred in a revan movie makes me sad every day
He literally looks like revan
@chilly veldt which path will someone take in the Tryhackme that alligns with the pjpt?
Once you've done the fundamentals (Pre-security and Web), you can do Jr pentester
Does anyone have a discord token joiner?
๐คฎ
What
discord token Joiner
I need members IN My new server
you mean the thing that joins servers
Yeah thought so
Wouldnโt that be a bot
:hammer: zendoefe#0 has been banned.
Yeah, as gonzo says, jr pentester aligns pretty well
Keep it appropriate please ๐
Mhm.
Gotta love when stuff is free.99
Iโm sure heโs joking
yea he is my frnd
hey, of course @hollow pivot
๐ฆ
sounds like a problem
re-install
Yeshhh, especially since I ain't home before 1:30 AM ๐ฅฒ
why do I need to verify my phone to speak on this server ?
is this only for me or everyone ?
some specific thing the mods added particularly for me ?
Everyone
And it's to stop the spambots
sed
jr
New room Friday!
๐ฎ
Wooooow
The straight face makes me laugh
Oh
Hi click my profile and tell me how you like my background effect
Itโs cool
any advices for job interviews?
Maybe more color in your banner
Need nitro
Only anime I've seen in a long time that made me feel like a kid again

I would ask in #cyber-and-careers thereโs some professionals that talk in there and would love to help
great thanks
Gave +1 Rep to @crude stump (current: #172 - 36)
THere is a reason I'm rocking Star Saber images on my profile atm. Watching that and Bravestar atm lol
Ello
So I have an assignment to emmulate a hack that happend in the last couple of years. (Nothing complex but not too easy either). Anyone know any sites where I am might be able to find these hacks
Google, we don't assist with coursework.
when new room?
pattern seems to be (if a room is getting released)
- walkthrough rooms at 1600 UTC
- challenge room at 1900 UTC
hmm, then imma be out
Yea every friday for challnge and then i think usually tends to be monday and Wednesday for walkthroughs?
@gray sonnet WAKE UP
ello ello
Ello
Aaahhhh
New room, just in time #1223346371550117898 ๐
Grab a brush and put on a little make up?
System of a Down ๐ซก
Ha, ha, ha
That joke came clocking in
The xz package, starting from version 5.6.0 to 5.6.1, was found to contain a backdoor. The impact of this vulnerability affected Kali between March 26th to March 29th. If you updated your Kali installation on or after March 26th, it is crucial to apply the latest updates today.
There's an open CVE, current instructions from CISA are to downgrade from the affected versions
Open Source says hello
They can track the commit of when it done. Whoever did it, it was malcious, we'll see what user it was done under.
Then, likely he was compermised, wouldn't be the first time
Oh dear
Yeah, devs get whacked don't know it
people push commits, no one checks from the main guy...
It's happened before, it will happen again, and it will happen more
just got lucky
that's why it's better to run Kali in a VM
yeah where are the branch protection rules?
I love when mother Russia tries an XXE on my server and failed 
Vue need to activate their windows
lol
Is it unreasonable for someone to be strongly opposed to the concept of IoT devices because they seem pointless and a massive security risk?
Like who asked to connect their coffee pot to the internet anyway? Does it need an internet connection?
There are some with good security and privacy backing them
And personally, I prefer "home automation" to "iot"
@naive violet can i dm you?
Go ahead bee!
Hrm. Personally I'm against the idea of adding internet connectivity to random appliances like fridges, etc.
as someone who works with creating literal IoT devices, what you find at homes are as James saying more like "home automation" and not IoT
Lamps, lights, heating etc
Hrm.
What's the difference between the two? Is home automation on a more systematic level, while IoT is only specific devices?
How do people even find your server. Itโs not like itโs a companyโs server
we create devices that help companies and people around the world with a critical infrastructure point, via a device that has been turned "technological" and connected Internet to, helping processes and compliance get done in a proper way, while not just telling you that your coffee has been standing on the burner for 2 hours now
home automation is more of a QoL inpromevment where as IoT actually solves issues, you can still live your life with no issues without having any home automating tools, whereas IoT devices might solve specific issues if not multiple issues at once
Dunno, but it doesn't have access to my internal network anyways, and ooooh, you're getting access to a VM with randomly long ass generated passwords that's only hosting minecraft
Good job, you wasted your time 
Home automation is a more descriptive term, rather than internet-of-shit
For a sec I thought James was going to be the voice of reason behind my thought process 
James, do you know anything about LoRa?
Anything internet facing is constantly scanned and attacked.
A non zero amount
fair fair, it's a cool topic
shadow is afraid of IoTTPYfP
You must be proud of your ips
I've got a LoRA satellite reception setup going at the moment
Interesting
cool
I'd show you but it'd doxx me
I love talking about my VM.
8 cores, 16 threads, 64 GB Ram,
Fail2Ban, Full disk encryption, clamscan every day with logs, UFW.
Snapshots taken every other day, clone of the VM incase of failure. Dataset on TrueNAS encrypted for that VM.
have you ever considered making a flowchart for everything
something like this
Uh... I have not lol
Wow nice set up
Oh, forgot to also state, that VM is also on a separate VLAN with no intranet access
....
DO IT
All that for minecraft? ๐
Yes
I got 2 VMs running on my home desktop right now that has access to my whole network
matt is protecting against log4shell
Hey, it also has taught me things too. Was like a fun project
Why do you need 64 gigs of ram for minecraft
why not
Like unless you're planning on creating mob farms with potentially tens of thousands of entities you shouldn't need that much
I got 256 GB of ram I can use. Might as well load that VM with 64
I got 2 MC servers on that VM for my friends
No lag whatsoever, love it
let me introduce you to mods
why not? Are you the minecraft police? ๐
Satan!
one of them is vulnerable
my 2gb minecraft server doesn't lag
You're beyond Satan.... you're Satan's Satan.
The lines aren't meant to wobble so much
what?! I am testing a room I made
My friend was paying like $20 a month for 4gb ram minecraft server. I told him to hold my beer and I made him that VM for free
nice!
paying for the server
Wait can you use a vm like a whole other operating system.
ngl thats good maths
pay 400$ for a 20$ problem
I have done that type of maths too manytmes
And after 20 months, ROI.
Nah but I was getting the server for myself anyways, and since I had the hardware, I built him a VM. I didn't know till after I bought the server that he was paying that much
@teal nexus
Once you finished learning how to use a tool is that considered a skill or do they provide more practice for it down the line?
although a 20$ for a 4gb server is criminal
Can I Use TryHackMe Without Knowledge of Networking? I know a little of cyber security and I fully know IT but I don't really know networking can I still use TryToHackMe And Understand everything they teach?
thats 5$ at most
? lol
Yes you can follow the pathways for it
.
that great to know
they teach you almost everything you need to know in order, and if you are ever confused feel free to google or ask here
The name of you and I are very similar
AHHHHH lol, you just posted that right at the moment, I posted my question lol made me super confused
What do you expect though? It's flying through space
Thought it was a bot for a second
Oooooh lmao
It's geostationary, the wobble is from my kit
Also reason why I thought it was a bot, is that this is the first time posting in this chat from my recollection lol
See now.. you could have done the robot when we went to the club. ๐
Yah.... but exposed to your entire network... even if I'm testing my own vulnerable machine, I'm putting that in my lab that cant see my network
You mean the club that gave me a double of Jameson for like $37?
Mfer, I can't dance anyways, even the robot

Yeah.. that one.. lol
yikes you can get a whole bottle for that.
god, does clubs charge that much for a double?
Welcome to Vegas! At THE MOST EXPENSIVE HOTEL ON THE STRIP...... I blame @vocal gale didn't he find that club @normal fable ?
Ye
Now collect 10k bug bounty 
๐
In vegas it does lol
He really wanted to go to a club.. but I also was okay with it.
I wanna go Vegas
He stayed there till like 4 AM, the dumbass tried to bring lockpicks through the bouncers

I went to a restaurant/bar but don't recall shots going that high, guess I was at a low end restaurant
You just weren't at a club.. club prices are high
log4shell existed in minecraft for a while
Yah... we went to the club at the Wynn
that type of club? that try to get you to throw more money? lol
Wasn't that around the time of Log4J?
They had a dress code.. for some reason they let us in. ๐คฃ
My favorite things were meat swords and white castle..
Wasn't this packed at all, but this was the club
Ahhh
Random DJ there or someone in specific? Never been to a club at Vegas so I have no idea
Ccg, the meat gobbler of meat swords.
yo guys did you learned a lot from tryhackme?
We had good food. ๐ The meat was tasty. lol
yh i have
Loved the club
its good for beginners
alr alr good to know
Dunno, we just went there just to go there since we went to the Blue Team Village party, but it wasn't popping yet, so we dipped, walked around, had white castle then went to the club
AC in the Tesla sucked in the back seat.. ๐
I'm in the process and its been pretty good. Although I just don't know when it becomes a skill after I learn it or after practicing it for several months.
Front seat was perfect 
yeah tho + 2007/3/2 just delete that thing in ur about me to be safe
I wasn't about to give up that seat

its for 18+ only?
nope just to be safe
Then you see CCG,
alrrrrr i guess
I think I might have talked about this before but if I download snort on my vm, does it automatically start logging stuff if I use the logging command when using the internet. Or would I have to enable something for that
Whats this blue team village I see?
done G thx
Gave +1 Rep to @empty atlas (current: #2040 - 1)
uhhhhhhhh man lol
@edgy ferry can answer that one, he helped with the Blue Team Village for 2023 Defcon
Good morning
@normal fable Ya know Wynn has their own PGA gold course in the middle of Vegas?
Yea, I looked it up but I assume its a group, just curious.
Blue Team Village is a Village hosted at Defcon, I believe either HTB @hot cairn or THM @mossy river (pinged ya just so I'm not mistaken) supported them, then you had Red Team Village as well
Is there a specific definitition for "Village"?
There was also crypto village (cryptography, not money) physical security Village, lockpivking Village, hardware hacking Village, and much much more
Conference room
Thanks for that clarification
Gave +1 Rep to @boreal scarab (current: #31 - 234)
Dang, I'm giving rep to the bot berries
I think of a village, tight nick community of fellow hackers
Interesting, are there tryout or something to join? lol

Tbh I have no idea lmao, never been to defcon

I am having a hard time with my pi and pdo_sqlite.
This is Hacker Tracker, we had to use it to find where the villages were, what was happening when. This is just an example of BSides Puerto Rico
PHP Warning: PHP Startup: Unable to load dynamic library 'pdo_sqlite' (tried: /usr/lib/php/20220829/pdo_sqlite (/usr/lib/php/20220829/pdo_sqlite: cannot open shared object file: No such file or directory), /usr/lib/php/20220829/pdo_sqlite.so (/usr/lib/php/20220829/pdo_sqlite.so: undefined symbol: php_pdo_unregister_driver)) in Unknown on line 0
Bro I need to go to defcon atleast once in my life
this is my downfall at 9:18 on a Saturday morning.
Do I have an Aussie defcon btw?
Basically Bsides
Comes this year!
Maybe a BSides?
Now, assumptions can be made by your Yeah/nah that you are Aussie.
Yeah nah yeah
I think we are the only people here that understand that sentence.

I'm an American, do your worst 
Are you calling out Summer schools?
I donโt have to. You and I both know your country is a fucking mess right now. I donโt have to do anything.
We seem to be following suit tho, so don't worry
(This is all friendly healthy banter)
My dad used to go to Vegas to play tournaments all the time.. ๐
๐๐
Criky
Yes... I do golf.. no.. I'm not good. lol
Despite the tone it seems like we're being rude, we're actually being friendly.
I can lose 12 balls on a par 3 course... i mean.. lol
RUDE
You have no idea what rude is.
Joke
๐
Rude emoji
Time to get outside and do some outside work while it's nice out. ๐
Smh
Americans think weโre fighting when you talk to another Australian.
Do you guys ride kangaroos speedy
Could you imagine if this wasn't such a PG-13 channel, the language we would use.
We ride Greyhounds.
Both.
Bet! We're going golfing this year!
Bless that poor dog
Who knows?
I know
How much is this thing and when is it?
Kinda expensive lol buuut
You get access to a lot of stuff
$500 just for a ticket, that's not including hotel, flight, or food
Do you recommend someone who is new to the field or would things go over my head there?
Probably spend a bit of time learning first.
Fundamentals
They have a lot of learning uh what would you call them
Expos maybe?
conference usually
Yea Expos can be a word used. I have a "cert" so I know some fundamentals but not like actually utilizing that information as it has been using THM
Iโve been using THM to do hands on learning.
I have a jr pen test from INE. it seems to have done the trick with getting around THM, but im still thinking im going to sub. always have more learning to do ๐
I just got a SEC+ and know networking. So it hasn't been too bad. Just some stuff here and there is confusing but just look up the answer if I can't find and reverse engineer the answer to understand why.
how was sec+? I am going to write it this summer, and then do pentest+ just to get actual certs
actually you prob wrote 601? Im going to be doing 701
I actually did the 701 and took me a month and a half to study and take practice tests.
@shut hawk geko
what was your experiance before taking sec+? I have 20 years in IT, but now pivoting to cyber
Had about 4 years in networking previously and decide to pivot as I was let go from my job lol
@teal nexus have a look at the defcon talks published on YouTube. They're free to watch etc online
I found some great mentorship from the Simply Cyber community on youtube. really great folks if your looking to do some more networking
Done!
Free cash money!! ๐ fr fr I boutta be rich
Fr no cap?
LOL
I just have problems with networking. Move to a new state and then got let go the following year lol
What does the ban spam do
Really never learned to network. but going to that defcon might be good
Or is it secret
Canโt tell if youโre talking about getting to know people or network computers.
Bans spammers
I think its going both ways @visual pecan
Deletes all the messages and has a prefilled ban reason/message
they want to get better at people networking, but got let go from a networking job
From the context of his message, I am meaning networking as in getting to know people lol
Exactly.....shouldn't have move states even though it was WFH
Are you really speedy
When it comes to leaving work at 5.
My old manager was mad, because I kept leaving dead on 5. Was getting paid minimum wage. I am not working for free.
You already pay me peanuts.
it was a pain to spend 14$ but i shouldn't be a Cheapskate its still worth it ๐
at least they have referral for a friend
LOL im having that issue...its not that its $14....its do i really need another subscription to something
its same with me I have like 4 or 6 subscriptions
What other subscriptions do you have that helps you with gettting more skills? lol
I just claim THM as a tax deduction.
letsdefend.io
ine.com
hackthebox.
and now im tempted to get thm lol
for me, htb, tcm, thm
good idea sp33dy. i guess its education, right?
That's not how that works
shhhh we dont talk about that
Check with an accountant based on your country/state. I am a software developer, so I have to develop and test secure software.
OH man lol. I was between hackthebox and tryhackme but jsut went with tryhackme. I just randomly picked lol
meep moop time for sleep sloop to get up early for easter while listening to beep boops
I like the boxes at hackthebox, but find the community here alot better. im only 3 days in to here tho
and the boxes here are equally as good
guys what type of career in cyber security you tryna be soc? pen tester security engineer or etc
In my country, THM can be deductible if it is leading to getting job. (Professional development)
You need a 1098-E or 1098-T to claim education on your taxes (US), iirc. You can't just claim subscriptions you pay for as education.
Well kung fu panda 4 was a really short film
i currently work in Incident response. I want to get into DFIR
wow
you're cool
Dang you are ahead of most if you already have experience. I'd assume it will be at least easier to get into DFIR
DFIR can be hard to get into
I'm just trying to get experience for now my pathway is to SOC I know its common but I have no comment
I have worked in a SOC for half a year
It's pretty chill
The job I did was 24/7 eyes on screen
So I worked in the evenings and nights
Depends on how outfited it is.
depends on the SOC, and the perpson. I worked at one company the SOC guys were leaving all the time...where I am now the SOC guys love it
be honest did you watch movies and stuff like that while working at soc ?
That's my goal to start off as a SOC guy. Just so damn competitive now...super daunting
I am allowed to watch movies, play video games, do tryhackme and other things while working
I tend to do THM rooms during free time.
The only reason why I am leaving this job is cause I got headhunted for a different job
Which is also a SOC position, but I get to help build it and create processes and engineer
And also do IR work
well folks. I have some trees calling my name and maybe a movie. I hope you all have a great night
You too, I am on my way home from work
i don't really wanna go to meetings and talk I know that you gonna do sometimes that in soc job but not as much as solutions engineers
I would have moved to rapid7, but I'd have to work in the office vs from home.
I've never been in a meeting as a security analyst in a SOC
Hi I need help . ๐Till now I have only done tryhackme linux based machine and i have completed 107 room all linux based .. now the thing is now I don't know how to approach windows based machine and when I see windows based machine i don't approach it is there any path or module or CTF which will help
so they never did meeting where you speak on how you improved and what you did this year and blah blah?
Nope, that's the higher levels job
I just sit and analyse
Do a few windows rooms on thm.
You guys know a place other than the commons places to look for a job for SOC specifically?
Which any suggestions
Almost all big companies that work with tech
it depends on what country you are on
Windows privesc
Ok
I know one I'm gonna apply to then ill have certificates and much better knowledge
Just look at careers for those big companies?
US
but def Ill never will want to work for microsoft or google it sounds good but isn't
I live currently in ireland never been in US so for you IDK
Yeah, just have a look around
also almost my whole family works at tech and similar ๐
Only my uncle and grandpa is/has working in tech, I am the only one in cybersec
my father works only in cybersec and my uncle used to my brother is trying to work for cybersec my sister works at cheese factory my mother is an graphical artist and my grandpa is chief of police retired
Kyooty how many does do you gotta actually go into work
My dad's a wood worker, my mom's a psychologist
My new or old job?
What ever your soc one is
Both are SOC
I just feel with bigger companies itโs daunting to get picked up
Hm then the one you said yo sit and analyze
Require a lot lol
I was interested in psychology once
Well my old job is onsite only, meaning we have to be at the office at all times, my new job is fully remote with possibilities to go to the office if I want to
yeah I def don't wanna go to cold a#$ office ill try to be remote
Thatโs cool
What happens if you find something tho. You said you donโt go to meetings so do you just contact your boss and report to them
We have notes, escalation people and cases that we build, plus reports we write
It's kinda hot office, free drinks in soda, coffee, tea and water, and free food for lunch
Lunch is no matter what shift you're on, paid and warm
Wow
Depends on your tooling. You could have EDR and/or SOAR that will take care of somethings, but in difficult cases, you'll have to send out to a field services/sysadmins to reimage the system.
My new job we have full access to everything and can isolate systems ourself if needed
we try to limit what analysts do on certain machines due to their complexity and can't always isolate machines.
Any of yโall know any good videos on how to isolate a machine?
Thereโs a dude named hackersploit
On YouTube idk if heโs trusted tho
when you mean isolate, do you mean take if off the network for a time or setup a sandbox on system?
Hackersploit is good
depends on your tools and if the network allows for that.
Yes
We are also only some analysts that can do it
Sandbox
I need to figure out what we have and if I have to make my own actually
Thanks
Gave +1 Rep to @wild rose (current: #310 - 15)
Yk what I very like, itโs not a sandbox but app any run is very helpful at analyzing
Any run is a sandbox itself
It's a cloud sandbox.
Yup
oh really
you use their machines to "explore" files
well it's all goes to helping out the community, so any new intel on malware is helpful.
We use private cloud sandboxes
Let's see how long it takes for me to lose access to it when I stop, would be fun
lol
im interested in what zerosilver has to say
this community is nice instead calling someone dumb they teach
he's getting there don't rush the guy
I mean, it's a 3rd party system, let's see if they forget or not
yes
this community is very nice
afterall it is for a learning platform
yeah
we host ours sandboxes internally. If I remember right, when I first joined they had some on bare metal for malware that don't work in VMs.
I have that at home
Should I play a game tonight? ๐ค
what do you use? I really don't have much use cases for a home lab anymore now that I have access to all I need at work.
I have a full network set of tools, with the really unsafe machine being a bare metal device and rest being VMs
I'm slowly working on finishing ff7 rebirth. hopefully will get on HD2 soon.
I just use isolated ESXi hosted VMs, previously Proxmox (lol may be going back to that). But yeah we did finally get a spare ESXi system at work for testing.
that's cool.
Nice, I beat FF VII Remake in anticipation for the launch of Rebirth on PC after the exclusivity period
Yeah, following a tutorial with added spice to it
I haven't played a FF game since X.
Canโt wait until they add the apcs
I'm working my way through the malware analysis module on THM. Pretty neat stuff.
I need to get an Xbox so I can play games I own... Lol
I think I've put in like close to 80hrs on rebirth. I'm on the last stretch of the game.
Yup, pretty good, I got my forensics room going soon
You haven't missed tons beyond some notable exceptions. FF XII is quite nice if you can get adjusted to how MMOish the combat is like. FF XIII is low key underrated, fun battle system.
FF XIV is a good time as an MMO and no real complains beyond having to sub. FF XV I wasn't huge on but want to revisit. FF XVI I'd love to play when it ever comes to PC
Now I wonder if I can emulate a 360...
A THM room, going public? That's super cool.
I think I might punch php.
Yuo
Yeah Xenia emulator does quite well, but RPCS3 is more robust if the game is multiplatform
Going home to finish it right now actually
yoo tryhackme is not only educational but fun I love this little fake virtual machines lmao
Yeah I've played almost ever FF game, besides 14 cuz I just don't have time to dedicate for it. But I so would.
What do you mean fake?
Yeah I only put in about 40 hours or so, but 14 is good fun indeed
You can force sync your level by reauthenticating against the bot
those virtual machines in website are not real right? like VMware or VirtualBox Its just an interface with buttons and blah blah right?
or am I wrong
Bot only updates level once a day otherwise
I need to logoff for tonight and make some dinner.
They are actual machines
They're real virtual machines and people work pretty hard setting them up.
whoever made thm needs an award
It's 1am here and I am going home from an evening shift and have to get ready for a night shift tomorrow
Every time you click "Start Machine" a real system get's spun up on AWS.
lol Kyooty. But yes they're all VMs but yes they all needed to be setup in a painstaking fashion
And tested
You can tell because they're mainly using Spice for the connection to the VMs
I've been there done that with changing shifts.
Can't forget our lovely testers. ๐
If you use Proxmox or similar, you can see the exact same sorta web UI
I thought they were fake I thought its just acting like virtual machine for educational purposes didn't knew they were real
so these are almost certantly kvm based
Yeahh, not fun, especially with Ramadan
๐๐
sup
Sup sup
You're a real trooper. Everyone that I know fakes on Ramadan, until their mother reminds them.
also I heard tryhackme has few ctf games might try few later
I keep calling tryhackme learnhackme ๐คฆโโ๏ธ
(nod) word
ุงุง
later everyone, I best be offline on a Friday night.
@sinful moon Hi!! ๐ How are you??
Pretty well, it's been a minute. You can probably guess which security event made me check in lol
0xD God means you're working for thm?
It's meaning the highest rank
No that's just the highest rank one can achieve on TryHackMe
the thm workers are named THM STAFF
oh ok
It's no worries!
I'm new here like a newborn baby ๐
i didnt mean that in a mean way
It's just a rank. Mods and staff will have different roles. ๐
oh no I understand it no worries
As we all were at some point, nobody was born knowing all ๐
This is a really friendly community for newcommers, that's kind of what this community and platform is about, just teaching security to all folks
Nobody??๐ฟ๐คฃ
Who is this Nobody person and how does he know it all?
you guys are 0xD Gods you all probably were born knowing all/j
the 0xD god is just a rank on the platform from doing the rooms
Nononono.. we're all still learning.
lol indeed a joke, takes effort to learn and advance. You'll be there before you know it
I'm not, I haven't put a loot of effort in THM since a long time, life keep getting in the way ๐ but I like the people here
Yeah this, even at this rank infosec basically requires continual learning and education, and staying up to date with news
(whoops didn't mean to ping)
Yes, highly recommended
Absolutely
alr
Obsidian and Logseq are some nice note taking software to consider
theres so much stuff its nearly imposible to remember all the commands unless you use it so offten
lol just watch for Windows Defender attempting to eat your notes on reverse shells
eh, commands you can look up, I recommend taking notes on the concepts and nuances
i use the good ole composition notbook lol
Use a good note taking app. We all have opinions on what is best.. but my opinion is whatever you will use is the best.
I normally write notes on WordPad but obsidian sounds interesting might look into it
I'd argue a bit of both, but depends on your note taking style. Just remember not to go all out, your notes are not Wikipedia, just only what you need to remember
I like trillium
Yeah Obsidian is lovely, just Markdown based. And yeah Trillium comes highly recommended by many as well
I haven't used obsidian.. so I can't say anything about it. ๐
Obsidian can be nice if you start actually connecting the dots
I CAN say that there are much smarter people in here than me..
Or you can be like me, vscode and just lots of files in 1 directory
lol fair enough, I'm sure VS Code has a markdown parser
I like making visual examples and obsidian looks like it can do that (by connecting dots and uploading pictures)
it does put then you need to view it differently from what you use for writing
I do like vscode... But I don't use for notes. Lol
I do plaintext notes that I never look again ๐
though paper notes are the best imo
i guess im the only one that physically rights down my notes
mhmm, that's kind of why I like Markdown editors that have live WYSIWYG interfaces
yeah that could work, on paper I like actually drawing the scheme out
current line is markdown until you move out of it and it's rendered
if I draw it then I can sort of go through that path high level
my hand writing is ๐ฉ
as long as you can read it, you are not making them for others
I like adding screenshots.. too many sometimes.
Yeah Obsidian added visual drawings and graphs via something like iPad Pencil input which can also be linked back to more typical Markdown notes
Also.. hey.. @sinful moon ... 
Congrats c:
thanks
Gave +1 Rep to @sinful moon (current: #38 - 189)
lol I've been here a minute but indeed heya c:
i should be lvl 13 now but ye some sort of bug
I mean are you level 13 on the site? If so it's just lag with the Discord bot, it only updates once a day unless you reauthenticate
I know. I just got busy talking about note taking and stuff..
im lvl 12 on the site but i should actually be lvl 13
lol totally fair
hello everyone
remember that they count from 0, also this is hex so...
I think it took a couple days for me to go green.
oi
oh
could be the case i guess
Oh that is odd
i think the staff know about the not leveling up issue unless thats what happens when you hit god
If you haven't yet, you could try to verify again
It's a site bug, staff knows about it
They are currently working on fixing it
Nah the bot just pulls from site info, so that wouldn't change anything.
Ah. Okay.
ye i tried this before as well
but they are working on it
not much to do :(
#mesad
They'll get it fixed.
We'll see you in advanced chat soon.๐
im mostly reviewing stuff again
lol does exist or are u kidding me? haha xd
Does. #advanced-general
oh nice
Not as active as general
im thinking about what i want to practise next mby some AD/ windows env or docker escape stuff
Most of us just chat here and room help.
AD rooms are good.
ye i should do those
hh
Alongside rooms, always good experince to spin up your own enviroments. Windows Server Evaluation has 180 day trial period in which you can setup AD and much more. Heck even Remote Desktop Services has an evaluation period on top of that
Docker is great fun to play around with, especially since I've needed to deploy custom Docker Compose configs at work before
along side with the ad rooms ill be reading a book inpt and stuff
there is a couple of techniques that i can test out on those rooms as well
have not been to much into docker env before but i should also really do those rooms as well
Mhmm, just when you start to get more mature in your learning it can be quite helpful to spin up your own labs for testing and learning
i have done this before
and honestly part of this is not just about exploiting, but learning how these are configured as a sysadmin and what they have to deal with to protect these resources
i used to setup enviroments for testing like exploit dev or re
but then i stopped learning for a while
fair enough, it's just a never ending learning exercise
ye thats true
mhmm
and we need to practise like everyday
if not u start to forget about techniques and stuff
I am a professional sysadmin and blue team infosec, but yeah offensive has been a minute for me. I do need to drive in again and refresh
thats nice
im just an enthusiast for now
my plan is to work with cyber security
especially pentest/red team
heh ironically I'll say enjoy it while it lasts, working in IT can suck the fun out of some of these hobbies but it for sure depends on the job and your work environment
just MSP things ๐
lol
lol
i think working as a pentester or red teamer should be fun
but ofc depending on the work enviroment etc as well
Yeah it would be, just difficult to land. Also good to keep in mind a lot of redteam/pentesting is just dealing with reporting and coordination with clients vs all pentesting all the time
Hi
yeee u reminded me of something REPORTING
waaaa
reporting is boring
but ye its part of the job
hey yo
i wanna work in the blue team sector and stop bad guys. preferably soc
lol that is a big part of the job indeed. In infosec it helps to be a good communicator or else your work can land on deaf ears
Even just to my senior tech boss, if I get overly verbose it'll go in one ear and out another due to his workload
what the name of the blue team job that actively hunts down the hackers
a threat hunter?
hello, is that lol means laugh happliy?
More or less yes, although threat hunting is often attempting to hunt for threats which were missed by security solutions in your own fleet. But yeah gotta keep up with current threat actor tactics and look for them in your environment.
means laugh out loud
thanks bro
Gave +1 Rep to @crude stump (current: #168 - 37)
ah im guessing if they found all the evidence they need they would be the ones who would report it to the authoritys
It's admittedly somewhat vague to me in that I'm really the only infosec person in my org. As a matter of my job yes I do attempt to identify whoever is doing these malacious actions
Depends on how serious it is, there's many security incidents at organizations that don't result in a actual breach. Just something to block in firewall/email security solution and such
@coarse heath
interesting
i got my mind set on becoming a soc 1 analyst
i love the tryhackme soc 1 rooms
so fun
not only that but actively stopping threats and investigating them are fun too
99% of the time, you and or security solutions will catch the threat before it does real world harm. Even some minor compromises can be resolved easily before more harm is done.
Although it depends on what you're dealing with. As an MSP, we have many clients including individuals, and those individuals don't really have SEC regulations regarding announcing data breaches when they let a threat actor in using remote support tools.
Businesses are another story and depending on serverity, this could mean reporting to the government and customers
yeah like cisa
etc
or should i say your local cyber agency
forget not everyone is from america lol
I am from America with my mention of the SEC, but yeah. It would depend on the orginization who they need to report to
anyone handling tax data who are compromised would immediately need to contact the FBI and IRS
oh yeah the echange commission
theres so many agencys its crazy
and they each handle different stuff
That's what your orginization's Incident Response plan is for
it delegates who does what in the event of a breach, who to contact, and etc
elizabethNoir i have a question for you, i'm new to this field and don't have much knowledge, I am a software engineer final year student. and I really want to work in this field, priority would be internship, (I think it will be easier to find), What field do you think I should focus on to work in, such as pentest or the defense... you mentioned and is there a certificate that I can easily get to start?
In summary, I need to know the most basic things I need to learn and what the requirements are in order to work somewhere right now.
Because I think that if I start working somewhere, even at the entry level, I can improve myself step by step.
CompTIA Security+ is a pretty easy to recommend beginner cert. This covers a lot of the fundamentals.
As for what position to shoot for, heck honestly getting into anything in IT will be getting your foot in the door. With your software engineering background I'd potentially recommend looking into DevOps roles and security for such, but that may be a long term goal.
I got my start literally doing IT help desk, so it's not impossible to move throught the ranks after proving your knowlege. In fact a more diverse IT job helps inform a lot about how business IT works and general issues and use cases that arise from such.
Thank you for your advices
yep np
i had the same issue some days ago
the support helped me with it
u can try to leave the room and join the room again
THM said I would fit Incident Responder ๐
regenerate a new certificate wait a couple of minutes and try to download again
lol xd
where did u take this test
THM in uhh this course called JOBS
Careers in cyber
thm
is that wat i need to do
HAHAHA
maybe it works
because when u join a network room automatically it generates a certificate for u to work on that network and if u leave the room the thing on the access page disappears and ye u got it ...
Incident Response is front line of major beaches, my friend makes good money being an Incident Response Manager. Itโs not a bad gig, but high pressure
i can imagine
Iโll be back, gotta freshen up
๐๐๐
Did someone say IR
i dont get it
whats the deal with blue team waaa
i guess i really like red team stuff lol
explain explain
The reason is because there are more blue team jobs then red team. As in variety
thats a good explanation miss bella
Not me for
Whatโs you for
ah makes sense
I love blue teaming because I like looking directly into what is done, finding those smallest details that determine if we can find out who did it and how to get it back or not
sounds fun
so it would be more into packet analysis and stuff right
I haven't even started uni
i think i could finish sec+ and offsec next month
me neither
Yeah, looking at packets, logs and the systems themselves
so i guess i have done a bit myself xd
Cool!
Wouldnโt setting up firewalls,ips/ids, antivirus etc also be apart of it
As a engineering role yes
cloud based firewall is a nightmare
for a red teamer
no joke haha
guys how do i find a flag from a txt document
Search
cant find it
search again
already searched
no u have to search again
Double search
just to make sure xd
where should i search then
I thought firewalls in general were difficult
found root
In the txt file
lol
would the find command work?
Wait is this a ctf
i mean firewalls in general are kinda of difficult to work with but cloud based firewalls are next gen firewalls
wym
Capture the flag
u get blocked by one host then its done
nah it was some shi about compromising a system
Oh
some of those next gen firewalls are using AI and machine learning
so u do something that triggers and its done xd
It still does the same no? Look for suspicious activity
Well some log and you gotta manually look through it
it also depends on how the firewall is configured as well
like u could have a badass firewall in the network but if u forget to configure right than makes no sense
i think one of the most efficient next gen firewalls in the market now days is azure firewall
but the cost its really expensive, a good idea for enterprises
stupid question, can you run python script for web scraping on android phone?
Don't confuse traditional next gen firewalls for web application firewalls and broader concepts. These are separate devices/software for specific purposes. They're not generally one size fits all
Sure, termux will give you more than enough Python in which to do so
Azure Firewall is specifically just protecting Azure resources. It doesn't really cover on-prem unless your org is heavily invested in Azure as your only cloud solution. To say nothing about insane Microsoft licensing requirements
Often for security it's a bit better to go something a bit more vendor netural
Really there is no one silver bullet, you often have to combine security frameworks to get the best coverage. So yes sometimes that means physical or virtual next gen firewalls, WAFs to cover cloud resources and more
Something like Azure Firewall is more about vendor lock in. Great if you're a pretty much exclusively Microsoft org but doesn't cover all use cases or scenerios
those companies or orgs that take security seriouly they would implement all this
but most part of the networks they protect specific servers or resourcers
Heck we're a small managed service provider and even then there's no one easy answer, we've had to build out our security stack as threats evolve
But also good to mention that you can't just purchase your way into security. Gotta configure your foundations and make sure everything works together
true
Could have the most well configured firewall in the world, but it could let something through to your completely unsecured Active Directory setup. So even just that, secure your stuff via Group Policy is a fundimental which can be easily missed
i was just about to mention that
its not usual to meet really good and consistent security solutions on internal networks
they always forget about something
could be an unupdated patch, poor password, backups etc
that could lead to something bigger
how do i see what files are running on the box
Mhmm, or even a single zero day in something you thought was safe can be exploited in hours after PoC is released
ye but most of the cases the attackers dont even need a 0day could be a poc xd
Totally not thinking of a very specific instance lol
i gotcha
I warned them five times with in three days of the danger ๐
lol
the attackers can take over the network in one day
sometimes even hours it really depends
At least thanks to my reporting, they instantly knew something was wrong and the impacted machine was shut down before it lead to a catastrophic breach
Mhmm, even just reporting on things can be a major live saver
those incidents can be found out fast or usually not?
Not always, sometimes threat actors can lurk in the network for quite some time, exfiltrading data and getting ready before they strike
Learn the fundamentals, then learn more.
have u analysed some APT stuff?
Realistically, vulnerability scanners like OpenVAS and doing nmap scans. But it does sound like you need more fundimentals
brb
Realistically not that I know of, but it's hard to attribute given I'm one person with limited time. I have analyzed Lockbit and QBot ransomware samples however and cleaned up after their loaders after our EDR tooling prevented the second stage.
Most attempts don't even get that far, but yeah those are industry known names for a reason
Morning THM ๐
Mornin
G'morning!
how's everyone doing?
Pretty alright, long day of work today, punctuated with Linux xz backdoor fun
How is Updog a thing
haha
Hah, yeah just better alternative to built in Python http server. Specifically named to make people ask that c:

