#general
1 messages Β· Page 102 of 1
You always carried a burner to Defcon lol
Hm thatβs weird
oh that's true
I'm looking for a professional who can help me gather more accurate information about a fake account so that I can complement this information in my police report.
Did you know the moon is made of cheese and it's going to melt next Monday? My uncle told me that so it must be true
X didn't receive any updates for ios 17, 7 years was a nice ride π
The police should have a digital investigator
I've been trying to get moon cheese for so long now... dang it.
I had a nice cheap phone and paid for 1 month data, you still have to sign up with a plan, but I found a person who was willing to put in false data for me π
As an avid Wallace and Gromit lover, yes it is.
I know right
What's up fellow hackers
funnily enough it works just fine for shadow to call and send and recieve sms and also using data
Not me being forced to make a welcome video at my new job, so I am now generating an AI video
In this video I explain the spook technology behind apples find my device that allows missing iphones, ipads, and apple watches to be found through a crowdsourced tracking network.
βΏπ°π΅π²Help Support the Channel by Donating Cryptoπ²π΅π°βΏ
Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
Bitcoin...
sooo somewhere along the line the imei is referenced or shadows carrier does not care about weird imei number
Source? As i said a general comparisons are weird as theres no like rating. Its about the specific features
Here in Brazil it's complicated, because it makes it seem like crime pays, because these people always end up with impunity.
Lmao someone hasn't actually looked into it properly
Anyone else heard that Discord is going to start annoying us all with ads starting either this week or next??
that was expected
Before I watch it, can I guess that it uses other people's Apple devices to transmit your device's location?
honestly I want to just track all the random cats in my neighborhood with these things
"Quests" where you're tasked with videogame challenges for rewards. Not adverts in the advertising sense.
Again people sensationalizing a headline
I was born and grew up in Argentina so I know the feeling
When will people learn to actually read?
right. I looked at the privacy center and i knew that with the asked permissions etc but not the domains it connected to
Exactly!
π
Ah ok, I just glanced at the article, didn't actually read it. What's up with these loot boxes? What's the point?
Of course they haven't, it's Mental Outlaw
? My desktop isnt doing this :)
Is your Desktop an Apple device?
The point is on-brand monetization without being intrusive
I've seen more clickbait than truth off that channel
Really? I'm shocked lol
no. I have a imac 2011 (back when they were good)
the lootboxes were an april fools joke by discord apparently
Go read about how heavily privacy preserving airtags are.
They're actually superbly well implemented.
I was skeptical until I looked into BLE, teardowns, tracking, and the safety measures. They're really cool.
Itβs all digital currency no cash app etc. thatβs weird
@mossy river Can I DM you about an issue I was having related to THM?
Go for it
hows the weird level bug coming along 
Its not just about the airtags though it in general findme. If you bought an airtag you bought it exactly for that reason. Its a proprietary protocol and all trust is placed in them. The Iphone was also well researched yet the unknown cpu register thingie was still found.
yo guys im in the basic dynamic analysis room and i cant find the apilogger.exe software in the attackbox. The utilities folder does not seem to exist. This is the path thats been provided in task 4 of the room ~Desktop\Tools\Utilities\ApiLogger.exe
i tried to cd into the directory nd it didnt work
Its not in the attack box, its in the deployed VM
Located in the desktop -> Tools
Did you use sudo?
Ah nvm
it's a windows machine
π
Hey! There's Sudo in windows now
Gosh I forgot about this
hi derek 
and Windows Defender being a subscription service
Not in that one 
better, stomach has been hurting a lot less lately, almost normal, feel like i can focus on ccna stuff again after those few months of problems after problems
oh idk for that one, was just meaning it is a thing now
any results?
no, app next month
I have played R6 ever since the beta and still have got no Black Ice π¦
That's sad
ah, hope they finally find whatever the cause has been
I'd gift you mine if I could
I forget if you're in the US. Is insurance covering everything?
9 years of suffering
doubt it now, they will prob just pass it off since CT didnt show anything
What's R6?
Rainbow 6 Siege
rainbow siege six
video game
yea, insurance is paying
Ah, thought.it was seige
that's good at least

R6 was great games in the Las Vegas times
HA! I have ton of black ice π
Your pain is my power
I have a black ice tree hanging from my mirror
Ghost Recon isn't too bad btw
Sucks that it doesn't play nice on Steam Deck
and ubiconnect headdesk
I just don't know how I don't have one yet, just need to keep grinding
As started to get back into it
the ruined the game tbh
alright old timer π§
I played for HOURS, almost failed my GCSEs for it
That's a lie, but I did play a lot
I know a guy who didn't show up to his GCSE exams because he was.. playing Garry's Mod.
I'm not kidding.
Damn must have been comitted to deathrun or prophunt
I was late to mine because my pasta was taking to long
PoliceRP
On a server that averaged around 5 people
That's like possibly the worst gamemode
I mean.. it was fun back when I played it but I was more of a die hard DarkRP fan
Actually no Cinema is, because you literally just watch a bunch of stuff
Yeaa I was always on DarkRP or Star Wars RP
Anybody got a idea where I could get samples of people talking for a lil AI project I am doing
||CancerRP|| was the worst. For those of you who don't know what it is, it was a game mode where 14 year olds were giving administrator privileges and they would doxx you if you stepped out of line or did something they didn't agree with.
Yes, that is the name of the game mode.
yeah...P2P not the best
Wym p2p?
hmmm
There are dedicated servers, those servers were just.. owned by the 14 year olds
Yes GTA is incredibly problematic
jeez
who raised those kids
Power hungry kids
Interesting fact: GTA V Online Mod Menus don't actually use your computer.
It sends communicates with an external server, for Rockstar to "Block" or "Detect" a cheat, all they need to do is find the server π
β¨ the internet β¨
LMAO
:hammer: newdev0000#0 has been banned.
Did he say bad word
Classic
thank u very much. Itβs my first time using tryhackme so rlly appreciate the help
Gave +1 Rep to @shut hawk (current: #13 - 497)
i got the fix

ping
pleasure
pong π
thank you
5 minute latency is crazy
A stupid question... Do you take notes while thming? And if you do which app are you using? Obsidian? Cherrytree?
Yea, I use obsidian, used to use one note
A good addition is to use physical flash cards or virtual ones with Anki
Hello !
Hmm, anki didn't make me happy before but I will try this time around. Ta!
Obsidian.
I just notepad.exe because of it's flexibility to both keep notes and it's ability to also be used to write scripts if need be
Vs code is better
Or vim π
Like kali linux termianl
Very very ancient text editor on linuxes.
Kali linux is the goat
There's also the more recent neovim that has plugin support and fancy features
I remember even freebsd had one, back in the floppy disk times
Im on windows but installed the kali linux application from Microsoft store
Its working good
Not a stupid question, of course - you should be taking notes. A lot of people use Trillium, Obsidian, Joplin to name a few
Notionnnn
Hecc notion
Go on, put malicious code in there, I dare you
Ty
Gave +1 Rep to @shut hawk (current: #13 - 498)
whitelisting the notes directory
Me when I have no internet and can't access them: π
@devout palm what you using? for notes?
Defender immediately thinks md file is a trojan and must be nuked hahaha
It happily looks other malware wreak havoc tho
BLACKOUT.
wasp.
π
That defender of yours has a hairpin trigger
Staring at the screen wonder what to do with life
π same.
Very angry, evil little cat is my defender
Yes! You are correct, this is what happened to a ton of peopleβs notes a while back
well do the Osiris.
My defender
I ain't ready for Osiris
WindCorps is a good series
wish we can get robot in here.
Hello guys!
It's Windows, no one likes Windows
Ooh cute
I do enjoy the Windcorp, Osiris is the only one now for me to get
Shame the series moved to HTB.
Wait, really?
Yeah, there is 3 on thm. 2 or 3 on htb
I quite like having them, nice view outside
How? what's the machine name there?
My view is just a fence
I started reviewing my saved passwords and i saw that some were found in a data breach, others are re-used for multiple services and i was thinking of letting google passoword manager to suggest strong random passwords. Is that a safe approach or should i keep some of mine?
like machines are shared with thm and htb?
I would not reccomend google password manager
Why not?
Not sure, just heard it was on there.
like creator submitted there or something else?
true.
Google Password Manager is not the best service for keeping your passwords safe. From unclear security standards to poor usability to privacy concerns, Google Password Manager does not meet the most basic requirements for a trustworthy service.
Bitwarden is nice.π
Since i am logged in in both computer and smartphone because of the email, i have all of them available. Since it's Google, i find it hard to believe there would be a problem. Any 3rd party pass manager won't raise any concerns?
Or keepass if you're old-school.
I assume you are referring to the free edition?
Yes
But isn't a bit risky to trust your passwords to a 3rd party program?
ofc, but keepassX ( idk the actual name) would be good to
I used keepass for years. Was nice.
third party: GOOGLE
You're correct. I was saying it based on the company reputation
google = user data collections center ultra pro max. π
If you're paranoid about saving it with another company, you can get self-hosted ones - of course they come with their own issues as well
Can you elaborate a bit more on your answer?
"What do you mean you rolled your own encryption!?"
ofc.

Bitwarden +1. They were successfully audited - and the passes are encrypted by your vault password so even if someone gets your encrypted passes, they will be worthless in theory. But nothing is 100% secure
aren't chrome passwords also stored locally on the device with the profile? I think i've even made a room/ctf on cracking the vault
Yep
Did you know that Google provide the functionality to download all your saved passwords in a handy zip file xoxo
so where can people save their password we can't keep using the same password for every acc since this counts as risk and we can't now even trust google password manager so what now should we save our password in external hard drive or smth?
Belive this room is about the leakage of Google passwords https://tryhackme.com/r/room/chrome
There are plenty of good password managers out there
that cost money
1pass is
the app is fantastic, autofill gets everything, can even manage ssh keys and OAUTH stuff in there
There are password managers out there, that you can have on a yearly subscription for Β£20-40
π― I use 1p and it's free for student on developer pack
For the full functionality, the one I use has a family feature that comes with it for free
They have a phone app
but I do have Bit Finder Password Manager so I guess ill try to use that
shadow is a bit of a whacky person when it comes to password storage
shadow uses keepassxc on computer and don't store any passwords on phone
shadow? what do you mean by shadow
who shadow
what's shadow
?
yep that's the point
shadow is shadow... a cheese loving person from sweden that refers to themselves in third person @rapid merlin
wait I didn't read ur user π
I guess ur user hides in the shadow
it explains fully? right
not ready for it.
Despite the "bad" reputation about google password manager, since google stores all your passwords in chrome (or in your account, i don't know), then the only risk that i can probably think of is if someone has access to your computer?
That's one of the main issues
any good ctfs that came out in the last few months? have been mia for a bit and getting back into it π
Which difficulty you looking for?
intermediate-hard
Clocky came out Friday, was a nice room should give that one a go, medium room
were you here in december??? if not check out the 2023 advent of cyber side quest rooms
Clocky, Doge, kitty.
huge, ill give it a look
i was, about the time i stepped away hahah those were solid
would recommend shaker too
and if you feel like bashing your head against the table for multiple days:
you're in a cave
try Bogyman
thanks shadow, i will be bashing my head against the wall shortly
do the Reset
forgotten implant is also fun
lots of content dropped i see
Is there any article on thm about some safe browsing and any necessary extensions to have?
If I have completed Intro to Cyber, Pre security and complete beginner can I do my first boxes?
Or I should also do web fundamentals, security engineer, soc level 1 and pentest+?
you can try
You can always try. π
you always have writeups if needed, that's how you learn
3rd bounty found in the weekend! latest is request smuggling π¬
thanks to thm for teaching me hehe
You started bug bounty?
And you found. 3??!!!
Thats amazing dude
I have been trying to get in bug bounty
But i just cant i think
how can you if you don't
remove all distractions and force yourself to start
Hmm
now and bugcrowd/hackerone/yeswehack/huntr/intigriti/etc
I made a account on hacker1
or don't and let me find them instead
ah you mean technically how, you're at that stage
Htb?
Burp classes whatever they're called
100% do Linux Fundamentals on THM first.
And check the pins in #bug-bounty for some resources when you think youβre ready
HackTheBox (after using THM for a bit)
At least..
Burb suite!
https://portswigger.net/web-security portswigger academy it was called
(for burp and web specific stuff)
si, linux fundamentals first
tbf though, you don't really need to use linux to find certain bounties. a lot of web app stuff can be found with burp on windows (although i don't like it)
I feel like its pretty hard
Si. Devs are dumb
I downloaded community edition
community is all you need tbh. pro has some perks but they aren't required
Good!
the only perk i use from pro is saved workspaces
otherwise i just use plugins
oh and collaborator (but you don't need that rn)
yeah just start tinkering and doing thm stuffs
also hi @mossy river
Thanks for help again
we don't do those here
Ok
( ask )
Hello π
i mean, if things are done properly, it'd be difficult to
By hydra i mean
the big websites usually have protections such as captcha or WAF's
supposed to be mitigated
Cap solver?
might work in some cases
Obsidian
obsidian is solid
how you got that Clown thing now?
C
By saying AI will replace programmers
none.
hehe thanks. I must say, i've spent rougly 30 hours doing it in the past week - it's not a fast process so dont be put off that you've not found one yet, it will come :D
No, I don't have on my client.
I've got to a point where i have a nice methodology to automate a loooot of the recon, finding my finds are coming much quicker because of it
where is whitespace???
yeah it's whitespace
of those four, it's C. but it's missing the actual correct answer
js obviously

missing brainfuck
indeed
i'm gonna rewrite my tools in brainfuck just to mess with the next person
release all ur tools open source, but its just brainfuck
a true language barrier
Y'all missing the actual best language. Assembly.
all my homies love asm
never wrote in asm but reverse engineered it quite a bit
learn through pain 
Here. Try APL
this whole thing looks like an encoding issue + some strings
"It's on github! That means it's open source!"
I wanna get better at that for pwn and re but it hurts my brain 
π€‘
Discord clowned us for 1st of april
it was from doing the discord event on april fools day

meep moop shadow is now gonna try for the sleep sloop to the beepity boopity beep boops while sleepity sloopity meep moop
I might have to banned you hold up
good night shaodow
Is 7 pm for me
2am here 
Which country ?
Bro want be parent
haha same
Yβall from Asia ?
nah kids suck
nopes sweden
Ohh
Rate my profile ?
i like your guys' fish
Bio and background
Any monki lovers
Monki
pretty sure your glitchy profile screen just gave me a mid-stroke seizure

What about bio
You think is true
i don't have the mental capacity to process what it says rn
It also hasn't been updated since 2001

Hi bread
off to get another drink and then get to bed before another day of interviews
Hello bread
scotch or beer for this one
π

nah that was earlier
Nah, @molten sky more like
on a serious note i haven't been that fucked up since uni
fun days, lol
Yeaa π x86_64 tho π and then aligning it properly and everything its suffering but also the 1 thing i think is really cool and wanna be good at
am on pwn104 now tho
so getting there
Here's some more fun ones for ya https://en.m.wikipedia.org/wiki/Esoteric_programming_language
An esoteric programming language (sometimes shortened to esolang) is a programming language designed to test the boundaries of computer programming language design, as a proof of concept, as software art, as a hacking interface to another language (particularly functional programming or procedural programming languages), or as a joke. The use of...
"esolang" is such a dumb word
I know these
brainfuck is actually quite interesting tho
Have you tried coding it?
any admins on?

@mossy river or @naive violet , requestforcomment is looking for any moderator. Either of you awake?
/semi serious, not interested in dropping in #site-support but it's a site bug that has potential risk to users haha
happy to dm to whoever and/or make a ticket
Can you make a ticket on the website? Support will be able to handle it :)
Yes sir!
Man drone rules have changed a lot in the past few years...
didnt see a place to submit an actual ticket but dropped it in feedback
If you click the chat bubble you can select 'contact support'.
thank u
Should get you there. Nobody there right now I think but should be tomorrow. π
Any rooms for the xz back door yet?
too soon
Yeah I figured, just thought Iβd ask
I don't even know if there is a project about that, but even if there is, people need to create a room, and then test it, before release it, that's why I said too soon
Ik
she went to sleep already i think 

am so confusled at how shellcode stuff works for pwn π
@scenic bobcat new pic and more colorful, nice π
Thanks, it fits me 
ur a wizard harry
I'm still waiting for the rank fix so i can get my cool 0x8
she would probably say wholsome goodness π
what rank fix
or did they fix it? the bot isnt updating ranks
Yeaa, im at rank 8 on the site but still on 6 here π
i dont think its fixed yet
and nope just tested
rip
im also on the road to being a wizard
yellow rank looks cooler than green tbh
0x8 best color
gold yellow potato tomato
I want a rank where my name is just pitch black
0xD John Wick
no
Yes!
Pink > Purple
Purple>everything else
i don't even know what to do in this server bruh
should i leave but i wanna learn something new
anyone used pwntools? am trying to find out the best way to do the recvline() but i gotta save one of the inputs cause it has something i need 
-- nvm
idk I'm new and i'm completely lost
did you tr #878393611929129000 ?
nope
than maybe try that if you're brand new 
I manage a discord league lol
idk nothing abt coding what so ever
π
i mean you dont need to but like.. idk what else to say π
beginner path doesnt even go over coding
Whatβs a discord league
oh
Shellshockers league that I made using discord
?>
Interesting
gots it^
Somebody suggest me a movie for today
I was gonna try "Meet Joe Black" again cause youtube shorts is pushing it a lot for some reason 
hey guys
I have a question about SMB protocol, i want to try open a meterpreter session with a wordlist of default user and pass, I dont have any idea about this protocol, is this protocol can be exploited with trying a default pass and username, I dont found a much about this on internet, and i still new in this, any help
Hello people, a question, is there someone here who can help me with my project about an app. You have to know how to develop and have knowledge of bank accounts at a good level, since you will be in charge of the area
@pearl lagoon why the friendreq π
not the place 
Cuse you are also a red teamer
And I will also want to be a red teamer
We could exchange knoledg
*Knowledge
ehh thats what the discord works for rn
mby later if you stick around :
why is this segfaulting 
Ok
Stack usually goes like
buffer / local variables
RBP
RIP
...
right? I am overwriting RBP, but i cant figure out why it just crashes before i can get RIP popped π
Idk
Are u using a vm?
huh? ofc lol
Idk maybe u had a linux machine lol
Ubuntu , kali, parrot?
kali
Actualy no idea sorry
here i am thinking you are talking about the routing protocol and not the instruction pointer

nah it assembly stuffs
every time i think i figured it out i just get hit with the fact i dont have a clue π
Lol
Btw where did you get the code ? Git?
my own lol
the exploit code, yea with pwntools
Sara, you still doing reverse engineering?
pwn but close enough π
There's a CTF event that should be coming up again at the start of October. I'm looking for team members, you interested? The event is DeadfaceCTF, it SHOULD start in October and it SHOULD last all month long
sounds interesting
but October is a loooong time π
also i might be doing school at that point again 
I know, gives you time to perfect your craft lol. I had so much fun doing it last year, although it was a pain in the ass doing reverse engineering on a cell phone trying to use radare2 on a tiny screen
I dont usually last all that long tho π burn out quite fast
also school would be taking up all my time cause it quite a heavy class π
If you need help understanding the functions, I know a lot of them. Anyway, something to think about.
possibly be interested, sent u a dm
I am getting the hang of that just struggling alligning the payload itself rn π
the heck is exit code 81 even 
Definitely look it up Sara, if you get any error code you don't understand, research it. Understanding the error code is key to understanding how to prevent it. I got a BSOD on a windows back in the day, some long ass error code like x0abdfxg63xblah blah. Had no idea what it meant, but once I researched it, I realized what I needed to do to prevent it in yhe future
I did.. but got no actual related results
Hey guys, for the buffer overflow room in thm, if i don't have good basics in BOF, what do you recommend for me before tackling that room? Thank you
You need an understanding of Low Level Languages like Assembly, and at least an understanding of how to perform reverse engineering in order to understand what a Buffer Overflow is
Any materials you recommend?
I'm going to watch Buffer overflows made easy by tcm, i hope it's enough
You can look up Micro corruptions. It's a reverse engineering game and has a few buffer overflow challenges. If you get stuck, there are walkthroughs for it. You may also look at THM in the search bar and see ehat they have available as well
Thank you so much
LiveOverflow has a good tutorial series on it too
Free vpn?
I believe Proton may offer a free one. OpenVPN is free (as far as I know).
Proton vpn has a free server but also a payed plan
You have romania poland netherlands japan and united states in the free version
and limited speed/bandwidth I presume
Yep
Student discount for proton
please could share link of micro corruptions
just use 1.1.1.1
Thank you
Gave +1 Rep to @scenic bobcat (current: #413 - 11)
th ank me too
Why?
hello eve
Question?: Vulnerabilities that are browser specific, more specifically very old browsersβ¦still worth reporting in a bug bounty? Iβve got 7 pages vulnerable to reflected XSS but theyβre only available in long deprecated browsers
You'd be surprised the things people still use today. I know companies that still use Windows XP.
god I just experienced a very painful learning experience
But a lot of sites won't let you view sites if your browser is outdated, so I don't know
Hey you all, i have a question on dashboard it is showing my streak is 7 (i.e i can join rooms with streak restriction) but when i join room it shows i have streak: 6
Yea thatβs tru, doesnβt seem like thatβs the case for this site tho. Iβll add it into the report :)
what is the problem here is thm new interface glitchy or what?
everytime i thought some room was bugged i ended up finding the answer and it wasnt
Regarding Proton, whats your opinion about it guys?
I use it because Switzerland is a privacy first country and its OS
But im curious what other ppl think
#site-support please.
expected behaviour
Hey, kinda smart ngl
makes sense in my head
Python be python...
i enjoy it
but sometimes find yourself on blacklists for emails lol
it's cute
Their service is decent. Though the move to remove the option to manually pick what vpn location you connect to was a weird one. Email aliasing is great.
I might even go paid after I pick what linux distro I want to use in the future.
Morning all
π
morning
Morning
morning already?
mornin
noon
Morning
good morning
i like how to oasp juice room sent me to the buro suite room and the burpsuite room sends you to the mysql injection room
Good Morning
morning guys. I just did the same thing @hazy flume last week. they dont take long to go through and are super useful
thanks ill probably finish them today
its worth it for the other challenges in juiceshop and in the next section of the complete beginners
i like after every room just to sit back and watch many videos about it
me too. or i'll watch a walkthrough after i've completed the room to see what i could do better
i did intro to cyber sec, pre security and now im moving through complete beginners. i started with what took my fancy and went from there. a lot of the modules cross over into other learning paths too. when i come across a room i've already done, i reset the progress and do it all again
i'm at 59% of the complete beginners
yea me too and after complete begginer i want web fundamentals, and then jr penetration tester
im at 55%
in all honesty, i'm gonna do everything on the site haha, it's all useful and it'll give me an idea of where i want to specialise. looking at doing my CCNA, too
yea i also plan to do everything on the site im addiceted
just found a 15 year old laptop that i'm gona turn into an SQL server to beat up 
i love how hands on the site is and i'm looking forward to doing hack the box and pico ctf once i've worked my way through THM. from what i can tell, this is one of the best jump off points into security and i'm loving it
you can test out your knowledge on htb. I still can't do some of the easy ones 
massiv skill issue on my part
i did rootme CTF not long ago and that was pretty fun . i've got Pickle Rick up next in the complete beginners path and i'm looking forward to that after doin the reverse shell stuff
the more you go through the rooms, the more you pick up. i know redoing some of the rooms has helped me loads when i've been a bit stuck.
i did the machines on easy there
before i got to tryhackme
but i didnt finish the modules there
i can only do one subscription at a time or i'd be on there too lol. i looked around and watched some youtubers and decided to leave HTB until i had a bit more of a foundation
So, I ususally do OneNotes for everything I learn and all the chapters
But do I really need the windows one if I use it on a daily basis?
I mean in this case I could just learn it, I don't feel like notes are necessary
Since I use it on a daily basis
What do you think?
you'd be surprised at some tricks you can pick up. especially powershell, active directory and some of the SQL stuff
i do notes like that :
Im at the introduction part for windows
with obsidian
Seems pretty good
I do with OneNote, but I might have to migrate to Obsidian at some moment
Or maybe Joplin
it's worth it as a refresher. i've been a windows user for 30 years and i still found it useful. the linux fundamentals is gold dust too
i wirte manual notes cos im old haha
my dog almost manipulated me to fall a sleep with him
Hmm, the new room Windows Application Forensics was advertised as a free room and it was, now it's not a free room apparently?
Yeah, it's a subscription room, the announcement was wrong.
Alright, thanks for clarifying
Hey
Yo
'Ello
my are like that
Good management with the notes
Thanks to TryHackMe team/community for making amazing labs!
I passed OSCP, only by practicing on THM
light on top fr
time to get ur role π
how
You ask a mod nicely. π
I'm preparing to pass ECPPT, do you think thm would be enough? And what rooms do you recommend?
Hello Mr.Mod man, can i get the role?
yeah for sure, go for it
i just did all the rooms i could
like, i used to search for windows or AD, and do those boxes
I see, thank you
Gave +1 Rep to @abstract shore (current: #2045 - 1)
what are some certificates that are worth chasing (ik abt CompTIA and cisco only)
best way to get into a girls DM
It depends how many boxes you do and how wide your knowledge is its best to just follow a course that comes with a course
That's very creepy, and I'm male.
depends on what sort of career your after
Depends on if you want to be on the offensive or defensive,
On the offensive i'd recommend to start with EJPT and then ECPPT and then OSCP AND THEN OSEP
It is creepy, and I'm not
EJPT is nice
for AD, PNPT is also good
i recommend hack the box CPTS its pretty good
Since I work in a red team, i will look forward to CRTP etc, but i also need to do oswe
almost a week into holidays and its been raining every single day 
My goal after finishing the ecppt to go for the red team path
Same going down that path eventually
Offsec certs are expensive AF
True
Otherwise I would have done all of them
But the oscp is the only cert you need that really open doors for recruitment
But I will pick and choose, which ones are valueable
but its a beginner cert, right? what about OSWE
surprisingly in the uk its not on many job applications
they typically look for crest
Not really
Depends a lot on where you are
For example in the UK, CHECK via Cyber Scheme is one
I think oswe + the INE cert for extreme web application are a good combo
I like to be prepared I would say both (also collecting certificates is sort of my hobby)
I think it's the next step for you for sure, i mean there is a difference between professional and expert
β Gave the role OSCP to trenton_.
Here know the mena region oscp is op if you get it you're getting calls
There you @abstract shore congrats! and enjoy the new channels.
True, OSCE focuses more on evasion techniques etc similar like CRTP
I know right! I work in UAE
Yess it's next level more like a red team path
there is no more OSCE
Be careful about going for the advanced certs without getting any professional experience
Ohh nice, i have many friends there, was planning to come there but still need the oscp and don't have the funds to afford it yet haha
A friend told me to shoot for the CRTE and CRTO since they are cheaper and get you more roles
this is overkill
Why
they split it into 3, OSWE, OSEP, and OSED
Get some certs and ur employer will sponsor you
what? lol
its called OSCE3 now
Yeah that's what i'm working on rn
They are milking it fr
it do be like that sometimes fr fr
In your shoes i'd shoot for CRTE and CRTO fr
Do you think the red team path on thm would be enough to take CRTO and CRTE?
CRTO is heavily cobalt strike
helo @grizzled crystal , have there been any labs you werent able to reproduce?
the ntlm relay not working for me π¦
THM is mostly for supplemental learning. I wouldn't use it to replace the content that comes with a certification
nope! what are you struggling with?
what's going on?
hmm i may be able to help troubleshoot in a bit if you'd like
okay okay, i might buy some ingredients for japanese curry then can i dm you in an hour or 2?
i will try to redo it after resetting
works for me
hey Aquilo
how goes it?
doing good! how are you?
my head dying bc i cant reproduce an attack and its been 3 hrs
Kick it.
Impacket or responder?
good. just prepping for the kiddo at this point
kicking it will make the dying worse
impacket ntlmrelayx but i cant seem to get a hit on it
(for context, the regex matches against http URLs)
hopefully resetting the lab will work
are you using the pimp my kali package? Or did you install it yourself?
oh are you using attackbox?
its the CRTO lab, everything is already provided there so i cant use other tools
did you follow the demo video? firewall setup and all that
User1?
oh, i did not know there was a video
actually i gtg but ill follow up in an hour

idk what user1 is but its hosted over snaplabs
π
Is this done over SMB?
I am a little afraid, I am purchasing an offsec subscription π¨π
are you going for a certification?
https://medium.com/@zenmonke/trying-smarter-oscp-vs-pnpt-f824b543bb05
I'd recommend reading this. I haven't personally done OffSec's learning, but it sounds like it is not the best. They charge a lot, and then people are having to dump more into other learning resources to pass
the benefit? they pretty much own the cert game for the industry as of now
some people think the HTB ones will become a standard in the future, but we just don't really know
So might jump on them before the prices skyrockets
I am starting the CBBH coursework today. I haven't used the academy yet, but it seems well structured from the outside
Keep us updated want to know more
sure thing. I work in web sec, so not sure how much of it I won't know, but, there are some modules that spark interest, that I didn't think they'd cover
such as hacking wordpress
I have done the course not the exam its pretty good
nice. I can vouch that TCM exams rock, they just done have an intermediate certification yet
for web sec
so CBBH it is, and maybe I'll do their expert one down the line
just make sure to take alot notes and you will be fine
my only problem with Hack the box modules is how reading heavy they are but its also good because you get alot of knowledge, just takes so much time
yeah, it also allows me to study in down time easier than having to pop up a video
i dont particularly mind reading it just means taking notes includes more writing
How does the cubes thing work in htb i'm kinda confused, which membership is enough to study the pentester path to pass the cpts?
i cant even remember how much it costs but wasnt alot
If you do yearly, they should unlock the path as long as you sub. Monthly, they give you a certain amount per month
its just the exam ticket that costs the most
Probably best asking their Discord.
i just bought the cubes outright over a few months but its defo cheaper to subscribe
yeah
cost under $100 to sub for it
and unlock the whole course if you do one month plat and one month gold
ive done both the course for cbbh and cpts and i dont think ive spent more than Β£200
i est $150 buying outright
because you earn cubes back
oh yeah
if you look at the path it tells you how many you get back
So i guess the minimum plan is the wisest
i personally love it
dont have to buy alot at a time because the modules take a while
especially when you get to active directory and stuff with 30 sections
I see i see
it took me about a year to do CPTS but i was also lazy with it sometimes so i say 6months is a fair estimate if you really try
all depends on your learning speed its pretty easy at the start the progressively gets harder i did the first like 6-7 modules very fast
Rn i'm focused on the ecppt since i already bought the voucher
Once i pass it i'll focus on htb
yeah lol thats why im not doing the exams rn because you get 10 days i wanna work on some other stuff
i hate web so im never doing that
uhh yea
CBBH >>>>>>>>>>>>>>>>>>>>>>>>>>
never go the INE route 
INE is more recognised, was my reasoning. This cert I am getting is more for client marketing
oh yea, definitely then
i mean as long as youre not paying for it
Congratulations π
Happy for you.
CBBH for sure.
do OSE3 if you think you are Jason Todd.
nvm.
Wow congratulations ππ
that's just a millefeuille
@rapid merlin cool desktop 
I got a scam phishing sms with a site which i whois'd. It is registered at aws, does anyone know where i can report that :o?
The DC character?
Ofc.
DC daniel cormier ? Ufc champ ?
DC comics
π
leave it on feds.
Wat?
Badass.
that's Jason.
Superior batman you think?
he is.
Well his punishments are logical, but in the DC universe, the law is basically broken π
Agreed.
Like, how the hell does Joker keep getting out???
Batman should look into being a prison warden π
corrupt officials most likely
We should report them too
That would make sense yeah, I bet you could progress Gotham a lot more if Batman invested more into reforming it from within, but he's only interested in beating the crap out of criminals with his own hands I think
Bro isn't into delegating work, i guess he had bad experience with contractors who used to protect his parents
batman does the vigilante stuff.
but bruce wayne does the public facing stuff
Probably yeah, being batman probably sucks, his response - that is to beat the crap out of criminals is some form of rightful indignation in his eyes to the trauma caused by his parent's deaths
π
So at the end he just needed therapy? Not kill ras al ghul?
Both would be a good asset in reforming Gotham, he could leverage the Bruce Wayne personality to look into the corruption and the vigilante personality to do the "dirty work" but it looks like he's mostly interested in being the vigilante
Because its a comic book/movie
Therapy would probably lead to a less agonizing existence for him yeah
he does leverage Bruce Wayne to look into corruption, but there is only so much he can do as a regular citizen.
Wait batman isn't real?
nah, its for all ages
well.
ππ€
π
Clown everywhere
Yeah you're right, a realistic batman would probably be impossible, I saw a comic strip where the guy survived being thrown out of a space shuttle
Bro what's ur wpmπ
age of the geek, my dude.
150 on a good way
how long it takes to complete 200 rooms?
Well how many rooms do u think u can do on average daily, then do 200/you daily average

Damm
Bro asked a silly question
depends if you have the answer for them or not 
Depends if ur good or not
not necessarily
?
?
?
?
there are so many infosec certs and it feels impossible to know which are good, which are trash. everyone has an opinion lol
Depends on where you want to go, and what employers look for
and everyones opinion is trash according to everyone else
have a look at the job market in your local area to get a rough idea of what they are looking for
right now i'm just brushing off cobwebs, gonna grab the comptia trinity while doing webdev stuff and THM, feels like a good initial spread
just in time to get replaced by AI π«‘
I went through a thought process, ProtonVPN is "no log", but what if the VPN connects to a server in the USA? Don't the policies of the USA then apply and they can thus record what happens on the USA server?
?
?
Can you show any source that we will?
Stop with "?", all you're doing is spamming.
?
?
it is for all ages there no specific age req to read those comics books but the ones who wrote it were targeting 13-16 years old
I don't appreciate being ignored.
If you're going to ignore me, you'll lose the ability to speak. π

this was just said tongue-in-cheek, jesting about the current AI-everything bubble.
Things got heated
i think anyone saying anything will or won't be 'replaced' by AI is talking out of their ass. no one knows.
Gonna need more context than that bud π
What are you trying to do?
lfi to rce
get back to work
LFI you need the payload on the target
i am trying a payload from a checklist
i need evil.com/mypayloadhosted.php
Any VPN company could log your traffic, you basically have to trust that they don't
Also, why are you not working?
But if they don't collect any data in the first place, then the US authorities can't exactly get anything? (Unless they were to magically make up some data to collect)
I did on my holiday a few weeks ago.
This one is because I wanted to get a bunch of shit done around the house
I firmly believe AI will displace many jobs in the future, but not anytime soon. We're talking decades, not years just a personal believe its not from any source
Okay, so what are you wanting to host a payload for?
And why do you need it to be public?
i am trying a payload from checklist
to escalate lfi to rce
Is this homework? π
idk why
Checklist?
yeah ofc
Idk man it seems prety close like 3-5 years
yeah
a famous one
hell one day maybe chimpanzees will steal our job π



