#general
1 messages Β· Page 98 of 1
Wired or wireless?
Very easy to detect on a wired network, you look for macs that shouldn't be on that port
Hi everyone
Please who can help me out on Task 3
I did the exercise but didn't understand the question
" What is the flag that you obtained by following along?"
there is a file on the machine. user.txt, root.txt,flag.txt. something along those lines that needs to be pasted in
I would assume one would just look at the MAC Address Table right?
wireless
but what if its an unknown mac address, one that was never seen in the mac address table
I'd say that wouldn't be spoofing then, that's just a rogue MAC address
You can probably set up a MAC Address filter for known trusted addresses and then set up an alert when a rogue MAC address is detected
But I'm not a network admin so I'm not entirely sure its feasible
@simple valve seems like the right track
You could check the first 3 parts of the address to see which manufacteurer it belongs to. If its badly spoofed the person mightve just used a random one. Not sure how reliable this is as many smartphones spoof their mac address when connecting to APs
I dont know if for example apple devices still follow apple mac address naming after apoofing but they probablx do i guess
Many companies these days use 802.1x, commonly abbreviated to dot1x as a security mechanism to prevent spoofing
This means that all MAC addresses are managed through a list distributed to switches and managed centrally and all devices are given certificates to ensure validity
Can be creds rather than certs, and it doesn't use the mac addresses but yes
Also not used as widely as you'd hope
We managed over 80,000 computers and phones this way on a company network where I worked previously
Im currently doing the linux fundamentals part 1 but the machine is not starting?
When i tried previously it worked just today it doesnt come up like usual
Please do not self promote here
Sorry
curious to know at what time the monthy hacker leaderboard gets reset
Midnight GMT.
this is taking so long, I keep finding issues 
Hello
so basically mac address filtering?
No, ignore mac addresses there
It's authentication, uses a radius server and certificates or credentials to authenticate before providing access
Just completed the Introduction to Cyber Security
THM is really good at explaining things
Nice
I hate setting up radius π
Me too!
It's so bad on cisco equipment
@crystal cypress We don't offer help with active CTFs as it's considered cheating
Degree is better
I'm sorry, I wasn't aware that this was a closed game though
We used Cisco Identity Services Engine, it required multiple senior engineers to manage and coordinate everything to do with it
#room-hints please
Got it, I'm new here.
yeahhhh
we have to do it for school
ohh alright
yeah havent learned about radius yet, will soon
thanks!
It can be a lot of effort but it'll be worth it π
What is "spare time"?
yeah, it's nice to learn
also it's taken over 25 minutes to upload my machine to tryhackme 
Are you making a room?
You not uploaded before?
uploaded like 14 times now 
I remember the good old days where it'd upload at stupid low bitrate no matter how fast your upload
I had Skidy personally grab a VM image from my Google Drive to upload it faster
feel ya π’
I got 300/60
50/10

Whatβs that one website where you can find your internet speed
Thanks
Btw the ping is the worst part
yup, that's why I put it with me 

I received a notification that one of my passwords was leaked in a data leak!
Wow!
When I opened it, the password I used was password 
sorry, had to test it out

Do yall use strong passwords for your lab machines?
/testing machines
Strong under what grounds?
I usually try to include at least a symbol, number, capital letter and 8+ other characters.
Even though it is a lab machine, I am still interacting with public services etc.
Random generated 12-16 character passwords
james for how long have u been hacking?
Like 5 years? But general sysadmin and related things for a lot longer
I was born wearing a hoodie and fingerless gloves
Your whole name reminds me of a name from a game I use to play lol small time mmo
im trying to set up home lab and i bought HP Z440 10-Core E5-2640 v4 2.40GHz 128GB RAM 2x 2TB HDD No OS and acer monitor , please which graphic card will be good for the set up
If you're just doing a homelab, all you need is a video output really
Although it depends what you need a GPU for
Guys, I'm sorry in advance if I'm going against any community rules, but I'm desperate and I need help.
I was scammed by a person on Facebook who was the moderator of a community with 150,000 people, a community for exchanging and selling CS2 skins, after I paid this person to buy a skin, he simply blocked me from everything and removed me of the group, leaving me with nothing. can anybody help me? Thanks in advance!
2 of them
@dawn plover There's nothing we can do
Contact the police.
Ooh..sorry about that bro
Just been reading some documentation on XZ. The whole social engineering aspect of that backdoor is a vector I was wondering about just yesterday:o
It's not a gaming PC, so huge amounts of RAM like that are quite normal
I've got 3 machines in here, one with 32g, one with 48, one with 96
I never knew a pc can hold so much ram.. I'm such an amateur
That's a workstation so a bit more than a normal PC
Servers too, you can easily do 1 or 2 TB
I just have 64GB or ram right now in my mobile workstation
8Gb on my main machine and 4 in my kali machine... I can't even begin to imagine so much RAM....
sounds like he got a server
Workstation so not quite
I need to set my server up
hmmm
What's the diference between a workstation, a gaming PC and a server?
I have got some of my servers running, but I need to set up my big one
Wow wow...how can a physical ram be stored in a server
Maybe I'm just dumb or I don't understand non of this
A server is a physical device
it's a large computer with a lot of resources
in very basic terms
Workstation is less Powerfull then a Server but still powerfull enough to make a small Lab running.
A Gaming-PC is focusing mainly on GPU/CPU for 3D-Games.
A Server is like a Server with bunch of load of RAM/CPU/SOCKETs etc.
Gaming PC is just a typical PC with a GPU, workstation is working towards server specs so typically a higher build quality, more RAM and more IO. Server is that taken to the extreme. Designed to run all the time, often redundant power supplies and stuff so that even if one goes bang the server keeps running
Damn!!
Thank you π
Ooohh.. thanks
Gave +1 Rep to @naive violet (current: #2 - 2111)
Is there a way to learn binary exploitation with already old and patched CVEs?
But...how come you guys know so much about workstation, gaming PC and servers?
How do you learn about anything?
You read about it, play with them
Geeking out probably, and also Computer Science careers (?
And also this, of course
Y'll learnt from college π ..huh
So I have a mock practical exam for SoC....
Guy gave us live malware, no virtual environment π
It was just an idea π
Not overly.
Yeah... I'll blame my country for this π
I'm self learning too π
π you ain't scared
of what?
W
Never mind bro
oh alright
Ninja how many years have you been hacking
I'm sorry but I am genuinely interested on this question lol
Thatβs crazy
Could be better.
Do you have a isolated sandbox you can do it on?
@crude stump
Only 5?? Your so knowledgeable I thought it would be longer
I have been working in the IT for over 10 years. Would be sad if stuff you get taught in the first 1-2 years will be gone immediatly.
guys, check this out
ik that link RICKROLl
I can't get the link to work, was it taken down?
Which link?
Wdym
Come on, it's april fools, it's like the perfect time to post it
the admin tryhackme thing
that is just a rickroll lol
yeah thats it
no it's the admin panel
Totally
Yeah, totally
I still donβt understand how that works lol
It's just a redirect
this is actually the only day of the year where the admin page is actually the admin page
π±
||Not real, April fools||
WHAT
Does tryhackme look for translator contributions?
would be nice though
Bruh
It seam more like an alias. I have Brave prepared to block redirects and it still opened the youtube
All content is currently only in English:)
Oml Iβm just getting Apriled fools a lot today
wym an alias
Wait is this serious?
It's not?
Yes, better move your providor.
The HyperText Transfer Protocol (HTTP) 301 Moved Permanently redirect status response code indicates that the requested resource has been definitively moved to the URL given by the Location headers. A browser redirects to the new URL and search engines update their links to the resource.
Google man smh
Just asking Jabba-san β€οΈ
San is crazy
Well, looks like its a hoax
Brave did not block, so it's my hyphothesis π€·ββοΈ
What do you mean by "alias"
I mean there's no way Gmail can be sunsetting, this is insane
It blocks grabify redirects, so it should have worked
it blocks known suspicious links
Yeah because it probably looks for the grabify domain
It's just a redirect
I read that it is possible to redirect directly in the dns, so like put two domaind in the same ip, so they are the same thing
It can't block all redirects or you'd basically break the internet
This is seriously how my Uni is giving us Malware for a SoC class...
Well. Your experience of it
i feel like they do this same joke every year
Ok, then any idead of why it did not block?
Every day π
OGs remember that gmail got announced originally on 4/1 and a lot of peple didn't think it was real w/ all the free storage
well google like to kill off services on a semi regular basis
True
π
Thatβs actually crazy
Because you can't block 301 responses without destroying legitimate functionality lmao
Ok, thanks
Gave +1 Rep to @pallid lotus (current: #9 - 746)
So....where are you supposed to download it, if not on your machine, virtual environment or sandbox environment? 
i.e whatever Brave is doing must be detection based. Whatever metrics it's using don't cover the THM admin rick roll
=> No block
Uni computers π
A secure uni computer right
When you say live malware...
You mean literally off the shelf?
I have no idea what it is yet, it's titled update.pdf
Well, download it on a uni system and find out 

Why would they not name it something thatβs not so casual as update
I need to way until Thursday. π
SoC enviorment, innit?
Free WiFi maybe
i might

Me too, just to have fun analysing it π
it's a pdf, how can it be malicious!!! /s
add_ram.exe
Get this person a computer!!
I have no idea, I think it's an April Fools from my lecturer.
ASAP
I mean, it's like when someone says don't press the button. Maybe also a new Phishing tactic to say "Don't download this under any circumstances" π
That's very cool Zenux
literally my downloads folder
Did you get rich yet
Where are you even supposed to download it then? And do you first have to sign in on that malware analysis machine with your email??
Oh mate, don't be greedy, share that rich advice.
Where do you get those π?
that would be my prank malware
Don't let your anti-virus hold you back from being rich
@lean plaza <3
Man it sucks to be ill during Spring
But I guess some people have problems when Winter/Spring switches
Hey
Cold?
one or the other gets me every year
Oh sorry about that
Nothing to be sorry about, it's natural I guess
But thanks
I hate efective antiviruses... I'm trying to write one and everytime I boot it deletes the virus I'm working on!
Yeah, hopping from cold to warm weather disrupts the immune system I guess
Yeah
Three seperate times someone asked me to do some playtesting for them and all of them were rats. One even bothered to make a website to make it more "legit".
Yβall seen the dude that made a beans virus. Everything you click it opens up a picture of beans
You should seriously use a VM lol
Hope you get better soon π
I'm almost good, thank you for your good wishes π€²
I have tried many times, but can't
Gave +1 Rep to @narrow pewter (current: #2041 - 1)
Gonna start my presecurity path now
I have tried VirtualBox ans VmWare, neither worked
Whoever thought of paths is a genius
What did not work?
The applications in general or
Did you create your own antivirus?
Starting Vms
DM me if you want, Ill see if I can help
Do you think it might be because I only have 8Gb ram?
That shouldn't be a problem
Some OSes need just 1GB ram
Or even less
Like Bodhi linux
Anyone else here love cryptography?
I have win7
Maybe you didn't configure something probably
Probably
Always thought crypotgraphy was cool growing up, ciphers, encoded messages, etc.
After you install VirtualBox and start the interface
You should have an .ISO image of your desired OS ready
Also each OS should list in their documentation, what their requirements to run are
You know that's end-of-life and hasn't had security fixes for years right?
I know, that's why I'm migrating to linux
maybe you wanna be a cryptographer
Why didn't you use the free-Upgrade to 10?
Nah, I'm too dumb.
I just find it a interesting subject
never too dumb to learn somthing
Not good in maths, but would want to learn more in this direction someday
Before days I just realized something, while playing chess
I was afraid to lose
Thats a problem
like when the Germans in WW2 had the ciphers broken beccause the Allies recovered the Enigma Machine
Losing isn't failing
Can't stand it... I prefered to stick with Win7 Professional, I have much more control and is more, at least for me, intuitive
or the Zodiac Killer's messages which to this day, are still unsolved
So yeah, trying is better than sitting with crossed hands
How the Hack, did u got GOD Level in here π with win7
They are
Not all of them
At least that's what I saw in a lot of news, etc.
like that
Some have been cracked
The 2nd machine (my grandmas, with 4Gb RAM) running kali helped π
My mother's a huge fan of true crime/legal stuff, unsolved mysterys, etc.
Oh hi
haha i see
so I take after my mother a little bit on that
Long time no see
Sure thing
Booting side by side with win Vista, my grandma wanted to keep it
Too busy driving like an asshole in my asshole car π
What kind of access to networks does the 7-day streak give you?
What car ya got
So with my t450 i will soon rule the universe i guess
AFAIK, networks are like rooms/CTFs but it's a bunch of linked computers behind the same router
Id get the T800 if there was one
instead of 1 box

Mitsubishi Evo X
Who knows π€·ββοΈ
DAAAMN
omg marry me
I don't plan to touch those until way later, Im struggling just with 1 box rooms xD
Jap for the win
πππ
Is it tuned
I'm a cool asshole so it's fine
bro thats a nice ass car wdym
Nope. SST so no power mod to preserve the transmission
Ah
Plus it's highly illegal
And I don't feel like getting my car taken from me forever by the police
Want it to live as long as possible
I could add 100hp just by remapping the fuel injection
But meh
It's already powerful enough
Damn, that's more than enough
How much fuel does it gulp?
Also are you using gasoline with LPG or only gasoline?
10 l / 100km if you're cruising on highways n big roads
Only gas, 98
You get 15/16 if you do city and big roads
20 if city only
That's fairly well for such power
30+ if you push a little
A wild Horsie has appeared!
Is a 2 liter
30+ is 
Indeed
do you ever think packets are scared because of the time to live timer
Hmm, good question
Depends on what kind of data they transfer I guess
the router has a weapon to their head, they are terrified
Or maybe who is at the destination
on quiet nights i can hear them scream
exactly
they cant take a break
there worked overtime
poor packets
Why ?
It reminded me of a question a friend once asked me: "Would you be scared if you knew when you were going to die? That you would die for example in the next 2 hours?"
The packets face the same destiny
They know when they are going to die...
Was this "friend" your grandma?
Not really
pings must be really terrified
It was a friend that had sociology at school
I think I want to get more birds tattoos on my arm
they got a mind of there own. if they escape they die. like the suicide squad
Got an interview setup for a new job that's doing waaaay more than what I'm used to
(thats a movie)
Good luck! π
you got it
good luck
oh you're like new new
??
discord account and everything
Thanks all

just observing da
I have been trying to think of a profile picture, but my mind is blank
what do you like
To many things... From learning how the sun produces energy to observing tree leaves falling
Thank you so much β€οΈ π
anytime
@narrow pewter u also joined THM today?
Nope, I've been doing for (going to check...)
Question, where do you check?
W profile picture
Discord, but I think that shows when you are joined the server. Thought it was from the website.
@mossy river
Please don't promote your discord here
Thanks again β€οΈ
Gave +1 Rep to @crude stump (current: #159 - 39)
your welcome
@mossy river So sorry ill stop
Read the rules while you're at it π
Ok
Is there any way to see in THM? I'm logged in but can't find anything...
hmmm let me check
whats happening?
Trying to figure out when I joined THM
I have no idea
oh
Look in your mail for the first mail you got from them?
Good idea π
Going to check
1/04/2023, the date of the "verify your email" email
Hmmm. No, I can't find anything either.
So exactly 1 year!
Oh so today is exaclty 1 year GZ
ππππ
May I ask if you already had previous knowledge when you started with THM or if you were completely new to the field?
I had already seen come john hammond's videos, network chuck's too. And I have been programming in python for 10 years
John Hammond == β€οΈ
10 years wow
It was from his videos that I came here
Respect
His videos opened up a new world to me
I also started witch Chucks Videos, but I've read time and again that he doesn't have such a good reputation in the "community".
Did not know that... He seams a good guy
Maybe a little bit addicted to coffe...
Nice
And now i stuck with David Bombal, great mentor
Im here for like 2 weeks lol
Know him too, I installed kali in my phone (unrooted)folloing one of his videos
ive found and started tryhackme by looking up "How can i learn cybersecurity"
Reminds me of "You need to learn hacking, NOW!"
True
The same with Linux
haha true
Here in discord or THM in general?
Both
The beginner paths on THM have helped me so much. The last time I had anything to do with hacking was 15 years ago. Back then we used to print out pages and pages of tutorials from the forums. π
ACK

It's the SYN of TCP... to catch COVID!
Atempt to make a joke....
Still wondering what to do today π€ pwn101 is cool but getting hardstuck for 5 hours.. isnt
were adding a new layer i guess
Or continue zipping through fundamental stuffs
wait so what would the new layer be after physical its hm untouchable?
hello thm community, im facing a problem with internet connection on my attackbox in CONTENT DISCOVERY room, does anyone have an idea what could fix the problem? Here's also a screenshot
The amount of work... π
layer 8 is often used jokingly to refer to the end user
i think you havent turned on your vm yet
ooh
I have like 5000 words of notes around the network fundamentals 
there in the attackbox
i mean the machine ip hasnt been generated yet
The target machine lol
that could be it
i do have an IP address! Just didnt catch it on the screenshot!
Go to task 1, button there
It should show up otherwise
#room-help would maybe the better place, something like this is easily lost here
nevermind! It works well, seems like the vm didnt spawn properly
thank you all for help! kudos
im looking for a software / cybersecurity job (3+ experience), please DM if you can help me with that.
have fun pwning
Thank you!:)
Gave +1 Rep to @dire crane (current: #822 - 4)
Have fun
Another question from the newcomer...
What are reps?
Like these
what are they?
Your Reputation, if u help someone u get some rep
Reputation
Okidoki, thanks
you can never have enough fundamental knowledge, go for it
Click here to get free 100+ rep<
Anyone got the FreeRep.exe
how easy it is to create something of value
Looking through the dashboard and it came to my mind... How is it possible that THM does not have a DarkMode?
Soonβ’οΈ
I know we are all white hats
I don't know how that could happen either, fortunately brave has a darkmode
Hay can anyone help me with my server I need a administrator
i think chrome has it built in setting
Which server?
why are you in win7
haha
Never updated, I don't get along with the new ones
win10 is about to go out of service
if you use EOL OS, then you don't get annoying popups about OS update, win win
True
knew someone is gonna say it
I'm not joining your server to hack it, I'm not going to hack, nor will anyone here.
We're not hackers for hire.
I'm slowly migrating
Hey guys, the linux guy recommends to use linux
but it takes time
jokes on you i use windows
it would be a shocker if he recommends windows π
because of the 1 gig ram?
y'all use OS? I send bytes directly into a router with batteries
And 100 Mb of network speed...
pshh i indivdually bite the packets into bytes and then send them into the router
And my atempt of building a NAS beeing currently in lockdown
if you use a PC/laptop/tablet you need to use a OS in order to make it useful π
I have an exposed security lacking wifi connected rotating fan that can be accessed internationally, Security risk? nahh
How do you receive, though?
uh
Somebody else Windows 7?
(This is a VM)
havent thought that one through
are you threatening them too? because lifespan....
I use a battery π
yes
nice nice
ngl i hated win7
Why?
couldnt wait to upgrade
I read TCP response with my finger tip
7 it wasn't that bad
i say that is installed baremetal! π
You'd be wrong.
battery for power, OS for functionality π
Do you count kernel as OS? You can have a kernel and no os on top, right? Or am I just making no sense?
yeaa, it just a tad boring
but I also dont really wanna full on skip it cause what if there's something in there i didnt know yet 
was afraid that
why is every video clip of malware on any run like a very old windows version
I think you got lost in the joke, but its alright, I stop pushing it
where is your malware folder
Think of the number of malware that's been written for older systems
I know the struggle, but you'll be less stuck later on.
oh yeah back then there wasnt much protection
Man, you only say thruths
shame on me haha
you could run AV and let it use half your system resources!
On this VM
nah stop it I'm blushing
'oh my tribes 2 FPS is trash? i'm uninstalling norton'
back when 3rd party AV's where decent
Yeah
and not straight up spyware 
wow, Norton that's a blast from the past π
I actually had McAfee
Norton utilities π

So for poor honest hackers... how much better is VMware compared to VirtualBox?
And up there you guys talking abou 1T - 2T of RAM...
he should take good care, pandas are on the road to extinction π and judging for what you're saying so that PC π
I used to run Avast many years ago 
How does a NAT work exactly? Is it something like: modem-router gets a frame, frame gets de-encapsulated to MAC, modem-router checks ARP cache and looks for IP, consults IP table, encapsulates to packet, then sends the packet?
Am I even close?
which website did you download that. cant find any, theres one from mandint?
does vm ware have a free version? i can never remember
vmware player yes
both have plus and minus from what i know
I used too, nowadays I use Bitdefender for active defense and Malwarebytes for passive
i personally use virtualbox
I use Linux as a main OS, but when I used to use win more often I had Kaspersky it was pretty good
I hear a lot of arguments over if VBox or VMware is better
Ah, Windows Defender here and malwarebytes if things start acting funky π
i think vmware is supposedly faster?
I use virtualbox because the free version of vbox has snapshots are are useful if I wreck the PC by accident
What AV do you guys use (and ladies, of course)?
would you prefer this one or virtual box?
free vmware doesn't have snapshots
these days my understanding is windows defender is solid, so i lean on that
VMWare is or "should" be slightly faster, i've personally been using Hyper-V on Windows which feels quite smooth too, along with free and snapshots etc.
Me neither
sometimes a cleaner can be useful if you dont have much space or memory
on Linux use qemu/KVM there isn't anything faster than that
it's an official microsoft thing? Hrm
Mostly my brain
Hmmm maybe i give Hyper V a try.
that's great, not a lot of people do that nowadays π
Did some googling and it seems Kali might not play all that nice with hyperv
that is the reason why there is maleware
Again, I use virtualbox. I have a few small complaints but it's absolutely functional
Maybe I should get a special hard drive just for Kali bare metal, idk
or do the live USB thing
yep, tik tok and instagram take over their brain π
I also use it and have been very satisfied so far, but have never had to do anything major with it apart from running a few machines
My problem is with those you have to do lots of rebooting every time you want to switch between tryhackmeman and normal computer user
and with the VM I can be on tryackme on my local machine, fire up virtualbox, etc
On my live USB, I have to choose "live with USB persistence" to lauch the system in normal live mode with no persistance and no other mode works....
really? i had no issues yet
Just a few anecdotes
And only maneged to install kali in baremetal on the 4th try
Don't use kali baremetal
VM is fine, if you're going to go bare metal, just use an old laptop, that's what I did
Any reason in special?
why ? i was thinking of making this laptop kali bare metal if i get new one
with only 1 gig ram he has to i guess ^^
It's 4, ijn the machine I'm using with kali
I tried a dual boot on my laptop with Kali and Kali just gives me a blank grey screen lol
I can still boot into normal windows fine
oh, my bad, sorry
but yeah I agree baremetal is pretty risky
No problem
i think it depends on what you want to do with the baremetal kali, there are scenarios in which it can be useful
The reason for running Kali in VM's is you're often doing Cybersec related things on it, and in the odd case it gets infected or wrecks itself - its simply kill it and restore snapshot
I had kind of the same problem, but for me was kernel panick msgs. Had to wipe it out with win and install again. It was then at the 4th time that worked
or just load a fresh copy
Okidoki
Exactly.
what you can say with certainty is that kali is not a daily driver as an os
Yep
Yea
I remmebered reading a reddit post saying like
but legit my laptop can't handle that much load i got potato one T~T
"never, ever, evre, try installing steam and discord on Kali"
Tried and agree with you now π
he didn't elaborate what happened specifically but his choice of wording implied it wrecked the system
why in the 9 circles of hell would anyone do that haha
I don't know lol
Ahhhhh....
Is it safe to say that I just tried installing discord in the kali machine?
apt install discord?
did not work
btw assembly anyone? the EIP register, which one is equivelant to that in the 64 bit stuff? or is this the other syntax i got like RIP, RBP, RAX, etc
was thinking of searching with more time later
I use Parrot for Discord and Steam π
hahaha
thats not much better 
Now I know not to try
rip
The R prefix means 64bit
Like EAX, RAX
you're using kali for something that wasn't built for, so that's on you π
Ahhh; yea i tried googling it but didnt get a clear answer π
Mate u really making my day thanks π
Gave +1 Rep to @narrow pewter (current: #1351 - 2)
thanks
Gave +1 Rep to @naive violet (current: #2 - 2112)
No need to thank π
Gave +1 Rep to @dire crane (current: #699 - 5)
I see that the rep script is already well thought out
I can't go into detail right now because I am a little busy but here's a quick rundown:
- Kali linux is a pentesting OS, it is designed to be setup when you need it for an engagement. This is why it has almost every tool for most hacking scenarios preinstalled on it.
- You should never hack on a host machine, always on a VM. Regardless of what you are doing, it is very bad practice and in reality very insecure.
- Kali linux has had problems with being daily driven in the past.
You would be better of installing another distribution and only installing the tools you want/ need. It will be faster and you will learn how to use Linux much faster.
Not ours
I'm the one who has to thank. Talking to you guys made me much happier.
Thaks π π
Oki, I'll have that in mind. Thanks
hmm i see thanks
Gave +1 Rep to @mossy river (current: #6 - 1205)
And always remember what Condor said: "A fool with a tool, is still a fool"
it's even more dangerous π
But Kali do be giving the cool hacker vibes - although i still dont know what any of the tools do past basic nmap and dirbuster stuff 
There are plenty of threads on the internet that go into much more detail, but there are also a lot of people on the internet who say using Kali Linux as a daily driver is great.
It is down to your judgement, but I'd like to emphasise point two. Just because you can doesn't mean you should.
If you are looking to daily drive linux, don't bother with a pentesting OS because it's optimised for pentesting.
If you are looking to move into security, you can still daily drive Linux but run a VM with your security testing OS.
@dire crane there is a Spanish saying that can be translated as "Dangerous as monkey with a razor blade" π
Wonder what happened for the phrase to be made lol
Kali is also best always installed in the "everything" version π
The best think in kali, that makes everyone I show it to be like "You're a hacker!" is typing in the terminal "kali-undercover"...
ugh i dont know if i should use a windows 7 vm or windows 10 vm for malware analysis
@mossy river Would it be a good idea to at least put hashcat/John on your local PC to better take advantage of the hardware? I know virtual machines tend to have problems utilizing the hardware effectively
omg i didnt even know that was a thing lmao
Yes, at least hashcat.
I haven't been in the hacking game for a while, but back when I was actively participating in CTFs john was good enough to run on your VM.
The only ones who are more painless than people who use Kali as a daily driver are people who use Arch as a daily driver. π
I still prefer John over hashcat
btw while we're on that dont forget to swap out your hostname if you're red teaming
a friend of mine plays blue team for his company and they ran an exercise and he just sees in the logs, one of the hostnames "kali"
-> Block
Hashcat is technically better, but John The RIpper wins just because of the name, and I think John is easier to use
Lmao
just give a razor blade to a monkey, it doesn't know how to use it, he would either hurt itself, or start to weaving it and hurt others π
I changed mine to "Server"
But already used "Admin's-laptop" too
I wouldn't be able to help myself from choosing a really silly name like "Hackerman" or "Neo" etc
John has a lot of uses, such as ssh2john zip2john etc.
Most CTFs nowadays have rules on crack timing which makes it a hell of a lot more bareable.

i don't just have kali bare metal on my t450, i even have stickers from hashcat and "hacker inside" on it, so everyone knows when i turn it on it's serious
there is another version that is says shotgun instead razor blade π
Everyone turning off their devices...
"Karen@Accounting"
nobody would dare block that
wohoooo
or HR π
I do wonder, is social engineering something that's allowable in white cards?
good one
better for them
jabba do you recommend windows 7 or windows 10 vm for analyis
White cards as in ethical hacking?
@sick lance
You can turn Windows 10 into a Flare machine, so that is a plus.
Dunno whether that works for Windows 7.
I use W10 for analysis, but if we went to go in depth, you need to be 0xD
ight thanks
Gave +1 Rep to @lament tendon (current: #35 - 213)
Like let's say you wanted to do social engineering as a red team, but you're super unconvincing, are white cards (used as a "alright, let's say a wizard did it") used in that case to play out a scenario where maybe someone (I.e. a new employee) fell for it?
like white cards are used to "simulate" certain things if they can't be done for whatever reason
Have to go... π¦ Loved talking to you all π 'Till next time! Happy hacking!
You can operate from assumed compromise, but usually that's not what whitecards are for
maybe a system is too delicate, or they wanted to use a zero-day exploit but none such exists, etc
bye da
yeah
Yβall recommend network + or CCNa for jobs ?
But for real its my social engineering tactic, sound and smoke, "Hello, I found this laptop in your foyer it looks dangerous, do you want me to check your servers?" π
Once I was in a coffee shop, drinking coffee and doing some THM rooms, somebody walked by my table and saw my screen. He looked at me with "you're hacking NASA face" π seriously I thought he was going to call the cops on me π
Ok staff
I imagine that can be negotiated with the employeer for the pentest, etc.
were you wearing a black hoodie?
but yeah usually jobs have requirements for like certs and stuff

Actually I was, but I didn't have the hoodie on at that time π
Should've been wearing black sunglasses as well and according to stock photos a balaclava
Who's wearing a black hoodie right now? Where are the dedicated ones in here, haha
uh oh it fools day
I am wearing an official TryHackMe hoodie https://store.tryhackme.com/ π
ohhhhhh need one
Hey Shadow π
Same!
shadow is too.. the red team capstone one.... but this one seems to have had a bad print as the back print of the badge is almost gone after just 3 washes
I have one, but from a company I used to work. I need to get the tryhackme one π
i looking for buy XMR
Depends on the detergent you are using and dryer heat etc.
a what?
the other one shadow got has aged more gracefully using same washing routine
monero is not available on binance
You're in the wrong server lol
You not my father
This isn't a cryptocurrecny server, this is a dedicated community for https://tryhackme.com/
I have to say I really like the community here, it's a shame I didn't get in right at the beginning.
they're different prints and materials
Or should be
π
And you'll notice quicker fading on bigger prints with more vibrant colours
hows assigments going Jabba
@mossy river this user is everywhere.
well one is a xl red team capstone hoodie this one is an xxl
just talking about crypto and wasting time
π
Hi I think with your experience you can answer my question #cyber-and-careers
not really complaining as it is still comfy
I can't do much on those grounds unfortunately
I'll let you know when I've startedβ’οΈ
I'm not from the USA sorry
kek I've been sweating mine out for the past couple days, it's almost due 
A whitecard is used to continue playing out a scenario, in the event an unexpected deviation occurred, so the scenario can continue and the deviation is marked as noted.
I have already missed my personal deadline for the first one.
Going to see if I can do it all tonight to move onto the next one.
I just found out the first version of Wi-Fi came out the same year I was born ππ
@outer rivet No one will hire you just because of a certificate, they all want to see projects or something similar. It also depends on what you want to work as. As a developer, Network+ won't help you much.
it wasn't wifi, not even internet when I was born π
Ahahahahahaha
π
One of my friends did just did a bootcamo for a cert and got hired his first interview
there were things call books and library that were people used to get information π π
Can i have the omni statue please?
Doesn't exactly speak for the company. But of course there is such a thing now and then.
Nuh uh
I used to use encyclopaedias when I was at primary school
@rapid merlin
yes thanks
it might not work because of the leveling up thing
but try it anyways
not wikipedia? π
It will still verify you, just might not give you the right role.
oh yeah then verify
I remember Encarta and Encyclopeadia Britanica π
You see that i'am not verified ?
any leads on if it might be fix tho jabba?
It will be, it's easter at the moment π
In ur profile ur not
I wasnβt allowed a laptop till high school
Role Roulette!
inb4 mod role
Thats good parenting
Do a few months learn things get a cert then they help you get a on
Job
My parents would ground me and make me use computers LMAO.
I had my first laptop for 11 years before mr aunty got angry and smashed it
π
oh your talking about the level in thm
The first computer I used was in my father business and it was a TI99 π
yes
70% of all the certificates out there are overrated and overpriced. Unless it's Comptia or something like that. Certificates should also be something that the company pays for. But that's just my personal opinion.
My parents would buy me phones, laptops, iPads and I would unintentionally break them because I was so out of touch with technology.
I was obsessed with going outside, literally as soon as I got from school I would stay outside from 4pm-10pm every day.
Weekends, you would see me for tea and that was it.
Ahaha nice
this message is brought you by Comptia π π
hahahaha
I didnβt get my first phone till I was about 14 it was the wee brick Nokia one
3310?
discord famous is crazy
idk how it is for cybersec but like, i got a programming internship simply by having a few projects linked in my cv even tho i dont have any degrees or diploma's ~ (the job wasnt really something for me tho π )
I wasnβt allowed to play vilolent games cause apparently wokld make me violent too π
Nooo! That's so sad. I had my first phone around 8 I think
#room-help If it's THM.
I lived with my very strict aunty and uncle
My father bought my brother and I Grand Theft Auto China Town when it was released π
Strict creates sneaky
yeah that's exactly what i mean, if you have what it takes you don't necessarily need 1000 certificates
I was going to release a very updated and vuln free CTF and get you all to hack it as an April fools.
All I was allowed to play was Nintendo and forza
A father's friend had a mobile it was a small briefcase π
What else do you need!?
why didnt you
Same ive still never played gta to this day by the time i was allowed i was too behind
They always found things. I had to hide pain killers cause I used to get bad migraine and she found them and threw them away
Wouldn't be released in time and I don't think QA would see the funny side.
Probably get annoywed for wasting their time.
is there such a thing as vuln free?

Yes. Off.
I'll just upload a xz room
Nah there is over 1 or 200 rooms in the queue.
This is a rough guess
Be me:
Android auto refuses to work with voice activation
Remove some google permissions because it wasnt working and google doesnt really need access to some stuff
Android Auto: "Hey I'm working, but you need to give me permissions"
Me:
nothing beats cussing at ai
whaa dont be mean to the AI! i'd rather be on their good side when they take over
also ChatGPT is a π for helping me summarize notes etc
I have an ai gf
@boreal scarab afternoon, how are you?
Lmao
feel that
MYSTERY FOOD
Dunno what I'm ordering. But it's damn good
ChatGPT is great at helping me through a ctf every time i hit something i dont understand
I'm glad that turn up OK, it don't like mystery in my food π
Yeaa
its so funny asking them to simplify something a bunch of times till you eventually get it
Half the time GPT dont get it and your dumbing it down for it
Oh I asked him to surprise me, I took a look at it said BBQ, and I didn't read further
Excited as hell
"It is important to emphasize that I am strictly for ethical hacking and not for illegal or unethical activities." yeahhhh gpt we know that already the last 900 times
its sadly no use for Rust code tho π
I have to tell it its a ctf like 10 times before it gives me an answer
every time i ask it to write something in Rust it makes up crates that dont exist
the time you wouldn't need to do that, would be the time that machines would take control π
for python too and apis are a disaster in general
BBQ sounds great, still we have different definitions of BBQ and also I would never say surprise me, because 9/10 I won't be pleasantly surprise π
but it feels like gpt is getting dumber and dumber, I believe that all the restrictions that come with it do that
tech is so weird sometimes
the first few weeks you could work really well with it
it does, but I was born in Argentina so it's hard to meet my expectations or even be pleasantly surprise π
internet on Kali was working fine when i went to sleep, and now suddenly its not working even after reboot
but Host does have connection and afaik its just bridged
I mean, a jazz and rib fest with the right crowd is un-beatable regardless of ones origin
I hate kali with wifi i switched to parrot because of it
not on wifi, cable
Btw when we verify do u just put ur token in the chat or is there a bot or sum
its /verify and then token should show
Go to Argentina try Asado and then tell me about it π
sudo systemctl restart networking
Yeah but do u just put it in the chat that doesnt seem very security wise
in the slot the command gives you, it doesnt show
Ah cool
it's all performed clientside
Damn
I plan to actually
We have some Brazilian and Argentinian BBQ places around
With the actual folk
It's decent
nope π
chimichurri is high tier
Packages: 1679 (pacman), 14 (flatpak)
removing packages to decrease attack surface goes brrrrr
ifconfig shows its up and running and i can see the traffic from my host lol
If ur using vm its probably something adapter related
is it on a VM?
vmware?
VM, Hyper-V ; was working all fine till .. just now,no issues yesterday when i went off π
what's the output of the ifconfig command?
Have you tried manually disabling/enabling them?
Saw a "This is a D.A.R.E. community" sign.... for all the non Americans, that was a failed early 2000 drug prevention program for kids... I laughed out so loud when I saw that
places that said Argentinian BBQ are a lot, but almost nobody has the real thing, judging by my experience, that's why I said if you have the time go to Argentina π
All DARE did was educate me on what drugs were. Beforehand I barely knew about it lol
I plan to. I kinda want to do a van life style escapade through south America at once point
Also, question @blazing granite
WHy does BRitain shoot so many TV shows in ARgentina?
lgtm Β―_(γ)_/Β―
Thats what i thought π
Like half the older shows I see there from the 2000s were shot in Argentina
and it does pick up packets in Wireshark, but only from my host 
For example in Israel (where I live) I know a few BBQ places own by Argentine that live in Israel, there are good, but still not the same as the source, because to resist the trip the meat has to be frozen you lose some qualities there.
checked your dns resolution?
Ah, frozen meat sucks

Where should I got in ARgentina for the best
Have no idea, I haven't lived in Argentina for a long time π
Cost.

nslookup
it's not a google problem or may in your area, I have no issue, check your internet connection
I mean.. i'm literally talking to you from my Host

on which google is fine
Hyper-V for VM idk if there's all that many network options available? i just kept it on 'default switch'
It worked fine yesterday and i didnt change anything about it π
reboot also didnt help
pc's be weird
They have an address in their ifconfig tho
Heyyyy
the user on that thread does too
Its April Fools guys
hi i wanna aseq about how people add description in tryhackme profil
April foool
no they don't
I believe this was disabled temporarily
Go to "edit profile"
no inet here
^
Manage Account ?
Odd.. did it auto update and broke something?
Yws
It was working literally 20 mins ago
*yes
and just stopped
Just click on your profile



