#general
1 messages Β· Page 96 of 1
it's a nice show, but it won't be beneficial for the wine. That's OK for people who like show more than wine, I like more wine than show, I'll keep my wine in a bottle where it should be π π
I don't remember any music recs from you, that might be it
I feel like any other time I would be so down to this but I genuinely can't get into it, same with Jinjer
lemme dig out some playlists for you later jabba
like? may u please assist me if its not a lot to ask
Let me check my archive, are you looking for something faster or slower?
may all your corks develop holes
So, you exploit a vulnerability to deliver a payload.
A fully updated Windows box isn't going to have known vulnerabilities for the most part
So you'll be looking at weak passwords etc
@icy cosmos I really like the rhythm and melody, but there's something about that vocalist that doesn't quite click with me
In a default configuration, there's not going to be much you can do
then what shall i do? my virtual box has kali and windows 10
Hey guys, I hope you are doing great! I am trying to do "Crack the hash" the room but last 2 task of Level seems impossible to crack it even though I followed the some guys and did the exact same thing but I cannot get the result, did someone do this room? If so, I appreciate anyone who will ping me about that..
This is still my recommendation @steep hare
Having Kali is nice and all but its not super helpfull if you dont know what you're doing with it π
I genuinely don't know.
I have been through tons of genres and I just can't find a style to stick with.
As someone who does everything with music, it hurts my soul
so try learning more fundamentals and figure out the tools (which all are explained on THM) and then try again? once you understand how and why these things work?
i agree!! i want to learn tho!!
????
β€οΈ I have your DNB playlist everywhere lol, I even moved it to Apple Music before my subscription expired ahah
that sounds very helpful i will def try that out
and if i run into issues i will ask! is that ok
got a new PC, have to re-import my library into foobar
it'll be a few minutes before i have everything indexed again
Yah. But it's airating (however the hell you spell that) itself!
this way, you will be forced to drink it, or watch it spoil
I have about 30 hours of dnb & techno on my usb for my dj decks. Need to transfer it onto spotify at some point
ask away. people here are great.
friendly and super helpful
again too much show for my taste, that's not for a profesional or even a serious wine lover
that's probably my lifetime of dnb and techno listening π€£
i can tell! u all seem great!
Thats fine, but do try to explain your issue and what you've tried when you do 
thank u for being patient
hullo
if you want somebody to be force to drink wine, obviously you don't know anything about the subject.
yes! i will thank u once again!
Gave +1 Rep to @scenic bobcat (current: #559 - 7)
will be back
Listening to playlists I made years ago can either be a absolute goldmine of nostalgia or the most upsetting memories ever π€£
Hehe. I mean that USB is 64gb and itβs full. 64Gb is a LOT a lot of songs of various genres
what's up?
Garage, house, techno, dnb, etc
But for now: trains
Iβm playing TS3 over the cloud
No cringe!?
Working beautifully
I was really into jungle as a kid
Jungle is massive π
I'd argue that's in the "most upsetting memories" category
that's why the lion got lost in the forest, because jungle is massive π
nothing at the moment
trying to decide what to do tonight
nothing? not even atmosphere!?
party π₯³ π
too much energy required
Oh, so what you're really saying is, I need yo travel to you, get a fountain and pour wine into it for your house decoration, got it
not wine fountain for me thanks π
Gave +1 Rep to @boreal scarab (current: #31 - 235)
Ez rep 
My next goal
Gmod, Police Simulator Patrol Officers, Cyberpunk 2077!
spread managed democracy
Yah? Come back to Vegas! Cause ya don't got any Texas De Brazil up in Canada, eh
We got a place called pampas
All you can eat
The Pampas are fertile part of Argentine provinces of Buenos Aires π
Uncharted 4
waters?
Yeah, its a good room.
I got stuck on this machine lol, I'll redo it to see where I went wrong.
oh right, i havent seen any yet or mby just missed it but is there anything that goes over Reverse engineering etc. in thm?
There's a malware analysis module.
ohh, i'll look into that sometime 
I've done a few simple things from 'crackmes' but always get stuck at anything past the very easy things π
theres a few if you type in "reverse" into the search
Em
Heya
Howdy
Howdy
Look who's back π
heyyy scrubz
π
i wanted to ask you
i did the wifi hacking room
i could hack my home wifi and iphone wifi now
but
Yeah, ask the creator π
oh wow
good to have you
i am finding some wifi in my house
that is greater than my own wifi
how is it possible
Aye heβs back
Higher transmit power, better antennas, better propogation
no, i suspect its my own wifi, and its a limitation by my internet company
because i didnt get the highest package
What do you mean by "greater"?
can i send here a screen shot from wifite?
what is the info i need to delete from the screen shot?
my wifi is 66db and the greater one is 99db
what does it mean?
-66 is more signal than -99
oh
33dB more signal, which is a HUGE amount
but it doesnt show it as negative does it
is the 26db one faster than my home wifi then?
Because it's bad software
No, it doesn't mean faster.
honestly i didnt finish your room
Honestly I'd use better software
wifite is overly automated and you don't learn anything
true, i tried with airodomp-ng and it didnt work tho, i need get back and see why
i constantly got an error about the channe
no matter what i did
i was actually searcing for you if you exist here on discord few days ago
probably missed you
Stronger signal doesn't mean faster
can i send you pm?
What for?
to ask you questions
Regarding?
Damn, It's 6 years old (wifite )
.
All the cool kids are using hcxtools now
regarding solutions of why some networks do not work
Are you attacking networks that aren't yours?
and about solution of the desirable password cracking i want is like 23434349734 pherabyte
no, all networks here are mine
2434349734 pherabyte
?!
i inserted it to generate all passwords from 8 to 63 characters, using abcdefghijklmnopqrstABCDEFGHIJKLMNOPQRST0123456789
the size of the file is scrazy
That's way too much
and i obviosuly stoped crunch
lol
dont know where it even saved that file will have to look it
you aren't gonna bruteforce a 63 character password anytime soon lol
what else can you crack hard passwords?
So...
what else can you do for cracking hard passwords*
You know what makes the passwords "hard"?
Yeah that's right - they're not possible to crack
ofc it is.there are something like 63^62 possible permutations
I believe that what comes after terabyte is petabyte
Well its possible but not plausible
also the probability of a ! or ? Nulling your entire wordlist is pretty high
i inseted my password into the 10mpasswords file, it didnt contain it
yeai didnt remember the name well i guess
remembered the p tho
true i was thinking about that
so how can a password that is lets say @#GH^%$DFDFGDSFGS%392987fsdfsV be cracked?
cough cough
realistically, it can't.
No
not a single computer
By that point it's much easier to just walk into your house and hit you with a big hammer until you give me the password though
but what i say isnt possible? to try ALL passwords?
perhaps if we tasked every computer on earth to work on the problem for a million years, we might get the answer
That would take so long that the sun would engulf the earth
but in a theoretical situation lets say that putin wants to build a computer that is strong enough to calculate any pass, can he?
no
can you realistically count every star or every sand grain?
i understood, but my pc is normal i thought there should be some 1000000000000000000000000000000x stronger machines who can do this
So you knock 30 zeroes off. The number is still too big to process before the sun explodes.
the number of permutations is several orders of magnitude larger than that
its like being limited to physics law, digitally
its a limitation of resources, both physical and temporal (time)
It's just how big numbers work
They're such big numbers that you can't really think about them or contextualise them
Look at the rock you wordlist or any other big one and check how many passwords in contains ans then check its file size. Then think about how many words a text file needs to be in the peta byte size
i asked becuse my 10m passwords file finishes in about a minute, and i inserted my password there to be the last one
10 million is 10 000 000
That's not a lot.
14 characters is beyond our reach for wifi at the moment.
Can I have that wordlist? π
so i guess smart password files is a better solution
my wifi password is THANKYOUSCRUBZ
feel free to login if you are around
i mean, the password file i have seen are poor. they dont even contain all possibilites of date of birth password
how big does a file containing all dates of birth of all people in the last 100 years?
This is quite easy to calculate
lets say i was borin in 3 of march 1990, so the password is 03031990
all dates can be inserted
Even ignoring date format, assume it's YYMMDD, YYYYMMDD
so 6 or 8 digits, 10 digits possible in each.
10^6 or 10^8
and can be 331990 as well and stuff like that
10 mil or 100 mil
you are good in math are you
So sub 200 million
using the beef technique, can we control all the files of the computer on which we attack, apart from multiple web attacks?
I studied maths but this isn't difficult maths
if 10m (10^6) passwords take 10 mins,
10bn (10^9) passwords take 10000 mins (~7days)
10tn (10^12) passwords take 10million minutes (~19 years)
10quadrillion (10^15) passwords take 10billion minutes (19,000 years)
etc etc etc
for a password that can be 63 chars long and contain a-z,A-Z,0-9, we are talking something like 6^63 passwords.
Do you understand what XSS is?
BeEF π
make sense
I am trying to understand
ok ninja bro i will continue with your room and ill continue to ask more questions later
i like challenging rooms
you can also reduce that removing invalid dates (like 00 as the day/month) and only up to 31 for days, 12 for months etc
Hi anyone completed clocky room
also include february dates
for comparison, the universe is only about 4.36x10^17 seconds old atm.
that would be included in the up to 31 days part
yeah just realised, my bad
no way youve been counting
It makes so little difference, and then you lose out on forward vs reverse formats
good point
i think you can just include all dates of february like it has 31 days instead of descluding 28 29 30 31
ninja, on my desktop everything works fine , but on my macbook with fusion player and kali, and the same network adapter, kali finds the USB, it shows when i list usbs, but doesnt show with iwconfig
maybe do you know why
I don't use a mac, too expensive for the poor design and specs
I'm sure it's broken USB passthrough, but Workstation and VirtualBox just work for me
this is tsw3
I can't walk, this is fun
nicee
Dang Jay, congrats on the role
it seems like theres a new release every year π
I was playing tsw4 on xbox game pass but it's sooo basic and I was prepared to spend like Β£50 on more routes
Ty! Nice to see you back :)
that means Ben got a demotion from lead bot dev
Just did a new squat PR 
Sup Derek
so just forked for tsw3 as I plan to play this when I get back home, rented a VPS that has a GPU and it's exactly like playing locally performance wise. it's mad
nah nah we're a team
managed democracy - hd2
thanks! I needed a break from some higher activity discords, this being the most active lol
welcome back Derek:)
that may be a little too much for tsw3
nice to see you
Yeee welcome back Derek, been missed
probably, but the only thing I can play on is a macbook air m2 chip. Parallels or crossover wouldn't work
respect, I only lasted a week w/ out 
I got some servers spun up on a new network running a secure web host. Got a SIEM running with regular vuln scanning. I plan to rent out web hosting from it eventually
also with daily backups
why are you on a macbook?
oo cloud gaming
so I had to get something that was x64. Currently paying for a server that is 16gb RAM, x8 cores xeon @ 3.00ghz and a NVIDIA T5 at about 0.85$ dollar per hour that I run it
ran on a separate server
visiting family for easter/holidays. no desktop for me π¦
Servers are savior
so, that's what's new with me
geez, do you have a contract?
But sometimes costy
well, no x64_86x device anyways
ooo, any random internet bots say hello?
naaah just top up your account with credit π
also:
stop/start whenever you're charged per hour for run time
perhaps try out geforce now
that may be cheaper
pay as you go?
only about 2500 a day
congrats
lol
I did aye but it doesn't support the games im looking for. At least with this provider they just give you a whole server that you can install whatever on
whens the big day? π
They actually gave us a range since my wife is high risk
huh thats preaty neat, how much control do you have over it? root ssh access or just click game and play?
Beginning of July to August 1st
pure admin baby
it runs on AWS kekw
i could probably run it myself on AWS for cheaper, but they integrate things nicely, and they've automated clients such as moonlight and parsec which is 10000000% better than RDP
ah, hoping it all goes well β€οΈ
I'm gonna be running parsec > RDP where I can. This ting is mad. It's like I'm running it exactly on my laptop. Uses like 6mpbs a sec though lMFAO
yeah i don't think my internet could cope with cloud gaming lmao
Honestly RDP is really nice for things that aren't games, as long as it's the MS client and MS server
what's the latency like?
I have a timer on my phone to track
plus as it's all credit that you add to your account, ultimately, if you forget to turn it off, it'll only use up the credit you applied which sucks but at least it's not like 100Β£+
You better have it or you will become po
oh yeah big advocate for RDP. I mean, I usually have like 4 different RDPs a day concurrently at minimum a day
Put parsec has been the only thing that can parse through controller input, render at 4k on my macbook, and render the game at 2k @ 60fps without that much latency
yeah seems pretty cool. free tier is basically connecting to one device
for me that's perfect
cool
Aren't the servers with graphics card expensive
full desktop
yes
this tier is designed to train AI models lmfao which is all that was available at the time
it's like a nvidia t5 which compares to a nvidia 1080ti in terms of gaming
guys how i donwload a certificate in pdf extension?
the need to play ts3 >>>
I put on Β£30 for ts3 & helldivers 2, gives me about 24 hours run time (though obvs you bring the games i.e. steam and BYOL for windows)
you can get this provider to license it but it's like 3x the cost per hour
but yeah defo need a good internet connection. My parsec is using about 6/7mbps constant over wiif
eh, only cause I want to. I own the games, my desktop at home is perfectly cabaple, but I just want to play them while i'm visiting family in my spare time loooooooool which I'm stuck to a macbook M2
which is arm:(
my ping 
that is peak what are you testing it on
Oh yeah? 
how can you have those speeds but that ping dafuq
pi connected wired to the router
Idk my internet is so weird
My download speed is like ~500Mbps consistent
but my upload + ping is so bad
like when I'm on call I have a 5 second delay for when I speak
the pi thinks in entish, but responds in binary
pis for throughput or duplex speeds suuuuck at least from pi3
combination of interface speed & cpu
oh its the same on any device
peeeeeeeak
@boreal gull can confirm how bad it is on call 
Lmao that's weird
I mean ISPs esp. in UK for residential prio download > upload. At my house I was on 500mbps with 450mbps down & 30mbps upload
The NIC was usb, pain
since we got 1gb it's 950mbps down, 50mbps up lmfao
yeah I find it odd
unless we upgrade to business where we can tell them hey I want more upload
makes backing up large files really annoying
eh yeah sucks...but I guess your average joe doesn't need mad uploads
true
I'm at my mum house so I can't complain, but it could be a lot worse π
Have you seen mine?
my cloud sync can never catch up
I'm writing from the future
are you with dial up? π
this is nuts, and I thought mine was bad
I can't even screenshare on discord
eh, even for a city bandwidth it's not that bad, believe me, in our country if somebody's living outside of town his internet speeds are lower than 50mbps ususally
Damn
the main problem is that the servers won't keep up with the speed hah
Yes, my connection it much higher, but I'm not there now π
π³
what do you need to download at your mum's house if 200mbps is not enough xD
bro is downloading nsa database
yep, the connection is always set at the lowest one, so you have to pick your server carefully π
It's OK, but I'm not used to so sometime I complain because look slow to me π
the best speed I've seen during downloads is on google drive, most sites don't like people with unnliimitedd powaaa
sites have limited bandwidth too
oh yeah it hits bad when sites load 500ms slower, and I'm not even joking rn
when I'm outside of my home it feels like my cpu isn't doing its job, feels so slow
steam games go pretty fast
oh yeah, they've upgraded their servers a while ago
but my hdd isn't that fast π
covid kinda forced them to.
At home I have fiber the whole way, I believe here they have fiber until the big box outside and from there to the apartment they use coaxil.
mm fiber
in this case is fiber to the apartment π
indeed so when you're used to that everything else is slow π
I'll be here for a bit so I have to get used to π but like I said it could be much worse, actually I was worried about internet speed, and I was surprise π
I thought it was going to much, much worse π
Your machine is initializing...
Use the AttackBox to attack machines you start on tasks
Loading ( -15009% )
hi guys! Do you have any ideas what is this?
My internet is fast, idk, it just doesn't loading
As long as it loads with a few minutes you're good.
just says some crazy stuff when it first starts.
try in #site-support
yeah rooms can take like 2-5 minutes starting up, depending on the room.
Patience is a virtue π π
absolutelyπ€
I snapped my neck and now it feels like my neck is supporting a bowling ball.
getting to that age...
do any of u play world of haiku, is it worth buying, it seems interesting way to practice hacking
From scanning their website, it looks like they're just starting out. Don't know if $100/yr is worth the limited content, when you have THM with hundreds of rooms of content.
but Carnegie Mellon Uni is a great school.
on steam, the reviews say that the game is discontinued.
Indeed, I believe it's a bit ambitious to charge that amount of money for not that much content, when there are more season site that provided much more content for same or similar amount of money. They should know their places in the market
Lol, just found out I can use my iPhone as a powerbank for my android
Finally a proper use case for an iPhone
I mean facetime is pretty nice. If I ever am forced to pay for youtube premium, I'll probably switch.
YT premium is actually a great sub
I don't use YouTube on my phone
I don't use yt that much on any device
congrats
I haven't been able to progress in cyber security for days because of the error I encountered.
The funny part is that I still can't find what the error is
π€¨
Irl how common are SMB misconfigurations that would allow an attacker in? I would imagine it would take realistically two things 1. SMB misconfiguration and 2. Having default passwords
SMB shares open to any user or even anonymous happens all the time, and then people write scripts with passwords in etc etc etc
Really really bad
It's how Uber got hacked
I work for a very large βcompanyβ I couldnβt imagine having that on any of our systemsβ¦ canβt really believe that would be a large issue
I mean, ubers large and it happened to them
Mmm, way bigger
With the large company you just dont know youve got it
the problem is often that the company doesnt know what systems its got running
xz backdoors can happen to everyone too
Anyway, just seems so simple. So I guess itβs common then? Would you then say itβs in my best interest to memorize the SMB commands?
though the dev that commited that did a poor job of not looking involved
memorize the SMB commands?
that's what cheat sheets and google is there*? for
its better to understand what they are doing
instead of memorising the syntax
Fair
smbclient -L is 50% of what you need
And if you're on Windows then net view and stuff
Iβm on Kali
A question for you, when I use service apache and open my localhost via Kali, I can see my files. But when I open the same from virtual box windows (example: 10.0.5.8/index.html), the site gives an error. (ip addresses are the same)
You won't always be.
What error?
and for sudo ..... sudo -l is most of what you need
Hey there π I've got another question if anyone here knows
Go ahead
Has anyone used proxyscrape and can give me an honest feedback?
Watcha scraping?
Thatβs a good point, tbh I feel dumb cause I never really thought of that
Meh, not too bad
(this site cannot be reached)
I'm trying to create a tweeter bot and I keep getting blocked
Sign up for their API plan
I think you need to use their API
it's just so it could send me a SMS whenever there is somthing I will find "DANK"
I cant really work their api so i tried just using proxy and scraping instead for now
I cant really work their api
Wdym?
sounds like something against their tos
Who has an idea for a hacktwon website ??
if it is I wont do it
That's a breach of their ToS and therefore against the rules here
If you're being blocked, it's for a reason
I'm just building a bot for finding dank memes
alright
wont do it
I didnt know and don't want to get blocked due to it
can someone help pls when im try to connect to openvpn i have this error message :
2024-03-30 17:42:41 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-03-30 17:42:41 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-03-30 17:42:41 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-03-30 17:42:41 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-03-30 17:42:41 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-03-30 17:42:41 DCO version: N/A
2024-03-30 17:42:41 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-03-30 17:42:41 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-03-30 17:42:41 Cannot load inline certificate file
2024-03-30 17:42:41 Exiting due to fatal error
@naive violet Can I DM you for a sec since you are a senior mod?
About what?
saying I'm sorry and new for not getting the rules and I should have been more carefull
It's fine, just bear them in mind in the future
which server are you trying to connect to?
im try to connect to try hack me machines
@trail merlin please ask in #site-support
ok
Hacker level 9000.β’οΈ
moar THM stickers?
like hal9000? π
you got worse one
THM{Hello World!} would be a cool hommage as a sticker
Some trivia I learned is apparently the "Burp" in Burp Suite stands for/means nothing, just the creator would name his tools random things when creating them, and "burp" was the name he chose for that particular tool, and the name stuck
"John The Ripper" was also originally called "Cracker John" (parody of CrackerJack) but the creators brother I think convinced him John The Ripper sounded cooler
Just thought that was interesting. Also IIRC the Code Red worm got it's name because the people who discovered it were drinking mtn dew at the time

Yeah I was wondering why it had that name, I mean Nmap is pretty explanatory (it "maps" networks) and so is some of the other tools but I had no clue what Burp Suite was
then when I found out what it is I was even more confused by the name
How about Hashcat?
Isn't hashcat something that breaks password hashes like John The Ripper?
I could ask chicken the origins of it if you guys want
Sure
Personally I prefer John over hashcat
I'm old school like that, John's been around since the late 90's IIRC
yup
Yes, just wondering if you'd found anything on the history of the name
You got a gaming GPU? Hashcat tears through hashes then
fr tho i was initially trying it on my VM for one of the rooms here and it was like "1 hour" left - i ended up installing it on my host with GPU support
down to like 5min~ cause GPU

1080ti but my Kali VM is on virtualbox which doesn't use the GPU very well. Also I just think John The Ripper has a cooler name lol
Hashcat runs great on WIndows
Yeaa 
It's just a zip file, run it from powershell/cmd
just install only the cracking thing on host and copy the hash over if you need to- keeping the rest on the VM
speeds up a loot
Hash speed on VM vs Host machine; it was quite funny seeing just how big that difference was 
def doing this
Does windows AV pickup hashcat?
I think so, I'm not sure
ehm, i dont recall it giving me issues 
No
virtual machine you can't use your gpu try my recommendation install john/hashcat on your main system
welp shadow just spent about 3 minutes on something crazy nonsencical thingy
rick astleys never gonna give you up but the lyrics is sorted alphabetically
a friend of mine is also quite busy with Rick Astley's song 
big ups pars
i still talk to him here and there maybe once a week
what a character
π
the paralympics????
maybe swafox? he's an og
is paradox part of the paralympics???
nah just a character of THM
similar to elf

gone but not forgotten. very good times with them
well have most likely done some rooms they contributed
pars probably yes
though can't just pull it out of shadows mind which
Got a good few created rooms
I guess the paradox is when the Paralympics gets an standing ovation π π
some company or business has also started what they call the enhanced olympics or something similar
where all types of doping will be okay but you have doctors testing you to make sure you no fall over
hey guys, anyone knows if in the new kali linux version auth.log is in another folder or with another name, because i downloaded the lastest version and i cant find this archive
did you check Kali's website or visit its discord? That probably the best place to ask
Google it's a great resource too
anyone ever deal with ethernet over power? does it work well? is it very reliable?
specifically looking at TP Link
I haven't have the pleasure π
nothing on google but i'll try visit its discord, tks
Is that like WoL?
No, Power over Ethernet (PoE). Basically one cable to provide both power and connectivity
Can be quite finicky by all accounts. If you get components which work together, and make sure that the switch / injector / whatever is definitely rated to provide the amount of power you need, it should be okay
EoP would be slightly different, and I do have a former co-worker who used the power circuits in the house for networking transmission. It did not work well, co-worker went back to the previous wireless network within a week.
I've found that extension cables can cause issues. where possible, plug it directly into a wall socket. further, if possible have both adapters on the same ring circuit; can work if they are on separate rings, but its temperamental
powerline adapters
older houses where running ethernet is not viable
or rentals where the one is not allowed to make those changes
βΉοΈ
Fair
or where wireless just doesn't work because too many walls
That's the first I've heard of that. Fun.
Is this still working?
Also question about John. John's been around since like 1996 right? MD5 hashes came in 1991. So if cracking a hash via brute force takes ages on modern hardware....how did people do it in 1996? Was the dictionary attack the main "point" of John and the incremental brute force more of a proof of concept?
Amazon.com: powerline adapter
Yo yo yo yo
Wait that's actually kinda useful
Itβs a party in the house tonight
Wonder how viable it is
Powerline (ethernet over power) is ass
oh
Hmm, it seems like a interesting concept although the few reviews I saw either made it a great placement for long distances or with concrete walls while you are going to get limited speeds usually 20mbps and high latency it
I mean also the fact it turns your house into a giant antenna
Elaborate
Interferes massively with a lot of radio stuff
Hmm, how does it do that though, isn't it using the cables for transmitting the connection (sorry if that may sound stupid)
Changing electrical currents in a wire makes an antenna
But wouldn't the effect be minimal since its not pointed or uniform
Inverse square law so it's distance
And no, it's not minimal. Radio reception is based on incredibly small signals. A nearby weak signal can often overpower a distant strong
Reminds me of my physics class
Hmm, any book you recommend on the topic
About radios in general
Not really, outside of studying for a ham license
Is it possible to get a ham licence outside of the UK
it will be called different things in different places. just means amateur radio
Pakistan
PARS, pakistan, amateur, eadio, society, ham, satellite, shehzad, pinkpanther, jeep, ap2aum, hams, antenna, 2meter, 70cm, vhf, uhf, hf, broadband, CB Radios,CB Slang,Linear Amplifiers,CB Microphones,Schematics,CB Antennas,CB and Ham Radio Knowledge,pakistan amateur radio,pakistan,CJ,islamabad,ap2aum,ap2mks,ap2nk,ap2pnp
PARS, pakistan, amateur, eadio, society, ham, satellite, shehzad, pinkpanther, jeep, ap2aum, hams, antenna, 2meter, 70cm, vhf, uhf, hf, broadband, CB Radios,CB Slang,Linear Amplifiers,CB Microphones,Schematics,CB Antennas,CB and Ham Radio Knowledge,pakistan amateur radio,pakistan,CJ,islamabad,ap2aum,ap2mks,ap2nk,ap2pnp
Hmmm
I think I met the guy who wrote the article
bookmarked it for later
hey ninja when i enable the monitor mode, the new interface name is wlan0 but that isnt the formwar answer, can i get a hit?
This is a google question, like most of the rest of the room
#room-hints for room hints
You've got MOCA too
Not sure if you've heard of that
Ethernet over COAX
yeah ethernet over coax is whacky
also if you want crazy wifi networks shadow could point you in the direction of a few hospitals in sweden
the networking that goes on to let the wifi cover all the areas it needs and also all the ethernet/cat cables to connnect devices
it is a huge undertaking
still it was neatly done in the hospital that shadow had their internship at
wifi gets tricky with all the walls and long coridors of hospitals
not to mention the cafeteria microwaves
ah, I meant PoE
Good to know. Any other options outside of hardwired
end of procedure???
oh ethernet over power... so powerline......
but you correct yourself to power over ethernet
well power over ethernet is generally just plug and play if your source for the network connection can handle the power draw
Guys I need help
my vmware workshop eth0 wont assign an ip address from the dhc and I looked in the internet for solutions but couldnt find any that work
nd everytime I try to ping 8.8.8.8 it gives me " ping: connect: Network is unreachable"
can someone help me plz
It's neat, but sadly not common outside the US
I have coax ran to every room of my apartment from a cupboard, but sadly not ethernet.
I bought a pair of MOCA adapters to use that, it worked
which moca???
Science and technology
Moca (genus), a genus of moths MOCA (protein), a protein involved in cell signaling Moca, a nickname for Andira inermis MOCA, an application runtime environment and programming language by Blue Yonder Minimum obstacle clearance altitude Multimedia over Coax Alliance (MoCA), an industry group which develops specifications for home networking over residential coaxial cable 4,4'-Methylenebis(2-chloroaniline), a compound used as a curing agent in polyurethane production Molybdenum cofactor cytidylyltransferase, an enzyme
I wonder which one specifies running networking over coax, shadow
obviously the moths plus the protein 
π
hey ninja
bitte um Hilfe eine kleine WhatsApp Attacke auszufΓΌhren
i honestly dont understand why the answer is W, when i use --help it shows w another thing
Please keep it in English only.
Attacking whatsapp would be illegal and therefore against the rules here
good evening bella
think the answer is mostly pig butts but who knows....
This attack would be legal because it was agreed upon and is only valid as evidence
check the network settings that you set in vmware
try and make the device connect to dhcp of the router if you are running in bridged mode....
Attacking whatsapp is not legal because you do not have a signed contract from whatsapp
black hats on the other hand......
What about them?
I have a bet with a friend that only one message should appear
also would assume people who have a signed contract with whatsapp would not ask for help here....
Sir, I was just hinting that black hats would do the opposite, hack whatsapp regardless.
:hammer: cygro_#0 has been banned.
Yes, I'm aware. We don't tolerate blackhats here.
I think you have to be very brave here as a mod. haha
Blackhat hacking is illegal/unethical hacking. By definition, performing illegal actions makes you a blackhat.
Yes, I'm aware.
So why did you feel the need to point it out?
could sail out to international sea and declare a small nation on their boat and then make it illegal to stub their toe???
Rated worst actor on rotten tomatoes
It worked thanks a lot 
Gave +1 Rep to @sand trench (current: #4 - 1683)
You won't get it.
Becoming a micronation is very difficult
I had an amazing workout today, and now my legs don't work like they used to before
yeah it can't be as easy as they make it out to be in tv series and movies for jokes
So why even ping me with it?
Stating the obvious? Not a valuable use of your time
perhaps adding a GIF to my reply would have been more appropriate.
damn
Chill out.
I think I like this Ninja Dude, he seems efficient to me
I paid 130 dollars for top resume to write me a resume and after running it through an ATS i feel scammed π
Got a solid score of 38
scoring systems for resumes seems weird but have a feeling a lot of companies use some internal system for it to filter out a huge bunch of requests
yeah, looking to see if there is a more reliable alternative to running a hardwire
You can just use overleaf
@thorny walrus you might have to learn bibtex commands but just use chatgippity for that.
curious what you guys use as apose to dirb or dirbuster for directory/file enumeration. I have always liked them, but seem slow during KoTH
ffuf or wfuzz
ahhh! ffuf i used it before, completely forgot about it. Its going in the toolbox now. I dont think I have used wfuzz tho - will look into it
thanks alot
It was your choice to interact with me anyways. you couldve just ignored.simple as.
no worries mate, anyway I can help.
would it just be as simple as filtering out the 200 OKs or should I be thinking deeper into it?
It's summer time!
If you can get away with it, running a cable is the best. You can get some neat ones that are easy to run along the floor etc without becoming a trip hazard
with ffuf..... I think I had a way to filter out the 200 OKs, but I forgot the options for it. haha
its cool. Ill read the man page. looks like its a simple -mc 200 but ill read a bit more
thanks again!
no probs.
Spring?
Well, the clocks
Its snowing where I am at lol
yeah, just trying to avoid stuff like that while in a rental. I'll probably go for that and just run it across the corner of the ceiling
Yeah, but we just turned over to CEST
I ran ethernet everywhere in my last rental
Darek you start your google job yet?
Just... over the ceiling
You could say, it ran over your head
Sorry, I'll see myself out
hehe
So bored at work that I am just driving around on a segway
Not yet. I am in charge of websec at my current company
tho
Oh nice
they haven't decided on a title though lol
and the pay bump is practically nonexistent
but resume boost for the future lol
other words, probably being taken advantage of
nono not google
that position hasn't opened yet
?
yeah
Dang
I don't mind too much right now
I love how my phone was like "your alarm at 3 am is ringing soon" and I look at the clock being like "it's 10 minutes till 2 am, that's not soon" and then realising that we are skipping 2 am tonight
do yall have a different day that the time switches?
Looking at your security archive website, what do you mean itβs to perform penetration tests. Also itβs a very neat idea
Today the CET turns into CEST
Wow, every minute is important at this time of the year, I hope the change of clock doesn't/didn't interfere with Suhur
Suhoor is pushed an hour back, so it's at 4 am and not 3 am
Cause the sun rises an hour later
meaning that iftar is also an hour later
Having THM go directly to /paths is annoying
Adhaan just gave now for me
Nice, Ramadan Mubarak
To you same sis
Thank you
not full pentests, just web security assessments. That way it can only be used for consulting, and not compliance. Saves me some extra work. And the project isn't meant to do that. It's more to showcase my abilities in web sec, and to have a project I can improve my skills on
Oh thatβs cool
and also made some side income to support the little one on the way
I am hungry though, so I will go make food even though suhoor is in 2 hours
Priorityβs
Can't even sleep afterwards, cause I got work till 8 amπ
meep moops shadows is finally timey whimey beepy boopy beep boop to the sleep sloop for meep moops time
gn shadow
Do I have the permission to DM you?
And you as well?
dm away π
Sure
I'm going to sleep, you can DM me and I'll answer you tomorrow when I wake up, good night
Bye people!! π€
it should?
idk it did last time i tried it
It usually does but there's a bug and the team is working on it.
Ohh alright
Can't help ya man. You'll have to ask tiktok to recover your account.
Please ping a moderator^ π
Was going to if he pushed the issue, but will do.
Itβs not my account !!
π
You know that's illegal right?
Not even brute force ?
Correct, not even brute force.
Ah ok thank you anyways !
I should go test my room
I should get some sleep
I had not, although at the very least that's two data transfer cables which instinctively makes more sense... Although whether the same applies in practice is another matter 
whoa you're here
Excuse my ignorance please, i made a transaction on the Optimism network through my OKX wallet and it has 18700 block confirmations, should i be worried? I didn't get my money yet
idk about blockchains sorry dude all I know it's I have 20mins left until it's the end of my birthday
Happy birthday buddy
thanks man
aww Happy Birthday 
niceu. I'm learning LFI ~ on the very final one now for RCE
I cant get past the last challenge of Pwn101 πππππ
I'm too stewPID
Ohh i didnt even know they had Pwn on here 
but I also wanna get all the basics down first π
Hey, can someone recommend a cheap 20-50 wifi adapter that has packet injection, monitor mode and ap mode. I did find the TP Link AC600, but I'm not entirely sure if it whats I need
I've been researching for hours and can't find anything
Alpha makes some good ones iirc. 30-50 I think..
Think I found a wifi adapter, just unsure if it supports ap mode. I got no idea how do find out if it does, any ideas? (ALFA Network AWUS036ACS)
ping
well I don't own it, I can only google it
TIP: for devices that emit radio frequencies, and if you are in the US, you can use https://fccid.io/ to get detailed information about the device. even if you are not in the us, sometimes it still shows.
Just do research. That's like 70-90% of cybersec...
Expensive is a state of mind. π€£
Alfa AWUS036NHA, everyone says good things about it and its recommended everywhere
yeah, you're like screw this, I'll just get it
Hello Everyone,
I am facing issues in connecting with tryhackme and getting error. it will be great help if anyone will help me to resolve it
Try one of the other servers available on the website if you're having issues with the VPN - also #site-support
hi everyone
Hi
I use an alfa model
which one?
alfa awus036nha
Ahh
does it have ap, packet infection and monitor?
roles aint fixed yet
Weird feeling knowing I just responded to my last alarm, analysed the last logs, did my last manual threat hunting and logged off the SIEM for the last time at my now old job
Yes
They are working on it
ahh kk thxx
hi
Moo
catgirl
sorry for the awfully late reply, had pings off, but yeah @teal nexus essentially at BTV we focus on defensive security (as the name suggests), got a bunch of really cool talks, workshops (tracks), and events that we run throughout defcon. if you end up making it this year, feel free to come by and say hi :)
Y'all.. drop the #gang tag. Clan describes it enough. Lol
Sounds good. I might need to make a trip even if its alone haha
ahhh
What do I need to know before connecting to Pwn101 machines? Somehow pwntools always fails to connect
Maybe I'm doing something wrong
morning
morning
morning
Good morning π
hows everyone
Good evening
Hi
Guys which one do you recommend for computer engineering, Mac or Windows? and Why?
Research
Whatever you choose.. learn.
Best path.
Tempted to get the pnpt and just add it to my PayPal credit
Before it goes up in price
?
How much is it?
The question makes little sense. Can you define computer engineering? It's a huge field that is only partially related to the os.
Recently released ctf's
what is it
Morning
Happy Easter for all.
UK clocks went forward last night, that means the Friday night rooms will release at 8PM GMT.
yo

i just started with my first task and its hacking ur first machine and it says ''Click the "Start Machine" button. Once loaded in Split View in your browser'' how do i split view my browser?
There's a blue butto at the top that says Show split screen
THANKS
Gave +1 Rep to @sick lance (current: #1 - 2113)
Does THM reward room creators like HTB does?
Also, is there a difficulty limit?
I've got some insane box ideas but not sure if they'd be better fit for THM or HTB
Not outside of comissioned content
Aww
No :)
Looks like it's custom made.
Contact the author of that video, they might tell you how created it.
hey, when I finish a CTF/ general room, you get a popup with an option to share the achievement, but the link to share on linkedin is broken, is there a fix or a planned fix for that? been checking for a few days so far
is level not updating thing fixed yet?
congrats on mod
Thank you!
Gave +1 Rep to @bold dawn (current: #75 - 79)
no problem! must not have noticed yesterday
OH GOD ITS MONDAY SOON
Bank Holiday Monday, so it's cool.
heh
the last 24 hours
most the authentications are communications with the backup server
somebody had fun spraying
This your website?
HELLO
Helllo
I drop in sometimes π
That's between my whole web server, and backup server, and SIEM server
Somebody was going wild wth
Built a new standing/sitting electric desk yesterday
need to move the painting over to line up
I bet
where is your mousepad
heh
don't have one
not by choice
just by the fact I haven't had time or money, as it's not a priority
I donβt use a mousepad
My mouse is also a nice little $5 I found
I'd like to get one of the logitech mouses with all the macros

hello spore
ah fair
yeah logitech are great
join the G502 club 
I don't have a mouse pad either, table works well.
My table developed a smooth spot where I use my mouse.
yep
basically, it's been 8 years I haven't use ms-dos and I forgot my password on a dental software that is now discontinued, and I wondered if it's possible to retrieve my password of this software?
Depends. but if it's dental software, you have an IT Team?
I worked on a dental company 10 years ago, and I lost contact with the software's developer
Probably need to reach out to someone to help that's a professional. I think there are too many gray zone things.
alr, because in this case the password isn't stocked in ms dos, but on the software
You could always call up the dental company and ask for the developers name
Eh they might push you away tho
i either have a 502 or 503
yoyoyo sporeo
have you blessed THM with salem's presence yet?
Yep. They've updated a lot of their policies, being in place for 15th April iirc
good
What sort of Behaviour?
Eh, I haven't looked in to how they do it.
Not sure if these might help but theres one called gephi or you got cytoscape
oo thank you
Gave +1 Rep to @near hawk (current: #70 - 87)
gephi looks good
like a call graph?
like in Ghidra?
yeah
Ghidra, always π
@chilly veldt hi, as you've done BTL1. I wanted to ask if I'll need to study from external resources or the course is enough itself?
Happy easter everyone may jesus bless yall β€οΈ
You too
Thanks!
Gave +1 Rep to @crude stump (current: #162 - 38)
Hi, I only used the study material that was in it, plus my knowledge I have outside of it all
Wreath or Breaching AD
When your clam scan results are in a very weird directory path... thanks TrueNAS
Do you know how routing works?
Nope
Every security professional needs to understand the network fundamentals. This module will introduce the core concepts of computer networking, covering everything from the Internet Protocol (IP), network topologies, TCP and UDP protocols of the OSI Transport Layer. Donβt worry if that sounds complicated, as this modules labs uses fun beginner fr...
Follow the paths
Check out TCP/IP Network Administration book for better understanding. It's partly outdated, but contains extensive fundamental knowledge + you can find it on github
+1 for that book. great content
yes
Isn't that piracy?
I don't know
it's licensed by github if it's there and they don't remove it. but if it is, I can remove my advice
Whoever uploaded it is infringing copyright.
I doubt it's licensed by Github.
not necessarily. they might be unaware of its presence.
Just because a repository has a license doesn't mean the contents are actually under that license
True. Only the copyright holder can assign a license to something.
ok, got it
Hey everyone, Question. Do you find it easier to have a list of tasks to complete when pentesting a site or program that usually follows a structure ofc,
Reconnaissance
Enumeration/Scanning
Gaining Access
Privilege Escalation
Covering Tracks
Reporting
but more in line with programs to run ect
I have a checklist, but hacking is a lot about trying stuff that nobody would try normally, so don't rely on that stuff too much.
Having a structural approach to it will help tho!
Yes you work to a methodology


