#general

1 messages Β· Page 102 of 1

surreal charm
#

What does it mean when you gmail notify you about your X account(Twitter)... saying " an Android user login your account..Location: Unknown"
How the heck will someone's location be unknown
I tried opening my X app but it keeps crashing

boreal scarab
#

You always carried a burner to Defcon lol

slender scaffold
#

oh that's true

dawn plover
#

I'm looking for a professional who can help me gather more accurate information about a fake account so that I can complement this information in my police report.

clear jackal
#

Did you know the moon is made of cheese and it's going to melt next Monday? My uncle told me that so it must be true

blazing granite
#

X didn't receive any updates for ios 17, 7 years was a nice ride πŸ™‚

crude stump
#

The police should have a digital investigator

normal fable
slender scaffold
#

I had a nice cheap phone and paid for 1 month data, you still have to sign up with a plan, but I found a person who was willing to put in false data for me πŸ˜„

mossy river
surreal charm
lavish shell
#

What's up fellow hackers

sand trench
#

funnily enough it works just fine for shadow to call and send and recieve sms and also using data

chilly veldt
#

Not me being forced to make a welcome video at my new job, so I am now generating an AI video

plush mesa
#

In this video I explain the spook technology behind apples find my device that allows missing iphones, ipads, and apple watches to be found through a crowdsourced tracking network.

β‚ΏπŸ’°πŸ’΅πŸ’²Help Support the Channel by Donating CryptoπŸ’²πŸ’΅πŸ’°β‚Ώ

Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436

Bitcoin...

β–Ά Play video
sand trench
#

sooo somewhere along the line the imei is referenced or shadows carrier does not care about weird imei number

plush mesa
#

Source? As i said a general comparisons are weird as theres no like rating. Its about the specific features

dawn plover
naive violet
lavish shell
#

Anyone else heard that Discord is going to start annoying us all with ads starting either this week or next??

worn thorn
#

that was expected

mossy river
slender scaffold
#

honestly I want to just track all the random cats in my neighborhood with these things

naive violet
#

Again people sensationalizing a headline

blazing granite
naive violet
#

When will people learn to actually read?

plush mesa
lavish shell
clear jackal
plush mesa
mossy river
#

Is your Desktop an Apple device?

naive violet
clear jackal
#

I've seen more clickbait than truth off that channel

mossy river
plush mesa
#

no. I have a imac 2011 (back when they were good)

sand trench
naive violet
# plush mesa ? My desktop isnt doing this :)

Go read about how heavily privacy preserving airtags are.
They're actually superbly well implemented.
I was skeptical until I looked into BLE, teardowns, tracking, and the safety measures. They're really cool.

crude stump
lavish shell
#

@mossy river Can I DM you about an issue I was having related to THM?

tawny magnet
#

hows the weird level bug coming along prayge

plush mesa
#

Its not just about the airtags though it in general findme. If you bought an airtag you bought it exactly for that reason. Its a proprietary protocol and all trust is placed in them. The Iphone was also well researched yet the unknown cpu register thingie was still found.

crude stump
#

I think they will announce it

#

Hopefully

wispy estuary
#

yo guys im in the basic dynamic analysis room and i cant find the apilogger.exe software in the attackbox. The utilities folder does not seem to exist. This is the path thats been provided in task 4 of the room ~Desktop\Tools\Utilities\ApiLogger.exe

#

i tried to cd into the directory nd it didnt work

rapid merlin
shut hawk
#

Located in the desktop -> Tools

oak river
#

Ah nvm

sick lance
oak river
#

πŸ’€

chilly veldt
oak river
#

Don't think so

bold dawn
#

you need to enable it

#

in the For Developers section

mossy river
tawny magnet
#

hi derek SCGwave

mossy river
#

and Windows Defender being a subscription service

bold dawn
#

how goes it?

sick lance
#

Not in that one kekw

shut hawk
tawny magnet
#

better, stomach has been hurting a lot less lately, almost normal, feel like i can focus on ccna stuff again after those few months of problems after problems

bold dawn
#

oh idk for that one, was just meaning it is a thing now

tawny magnet
#

no, app next month

near hawk
#

I have played R6 ever since the beta and still have got no Black Ice 😦

bold dawn
shut hawk
#

I'd gift you mine if I could

bold dawn
#

I forget if you're in the US. Is insurance covering everything?

near hawk
#

9 years of suffering

tawny magnet
#

doubt it now, they will prob just pass it off since CT didnt show anything

sick lance
#

What's R6?

near hawk
#

Rainbow 6 Siege

buoyant tree
#

rainbow siege six

shut hawk
#

video game

tawny magnet
sick lance
bold dawn
#

that's good at least

sick lance
mossy river
#

Your pain is my power

bold dawn
#

I have a black ice tree hanging from my mirror

rapid merlin
#

Ghost Recon isn't too bad btw

#

Sucks that it doesn't play nice on Steam Deck

#

and ubiconnect headdesk

near hawk
#

I just don't know how I don't have one yet, just need to keep grinding

#

As started to get back into it

mossy river
#

the ruined the game tbh

shut hawk
mossy river
#

I played for HOURS, almost failed my GCSEs for it

#

That's a lie, but I did play a lot

#

I know a guy who didn't show up to his GCSE exams because he was.. playing Garry's Mod.
I'm not kidding.

near hawk
#

Damn must have been comitted to deathrun or prophunt

shut hawk
#

I was late to mine because my pasta was taking to long

mossy river
#

On a server that averaged around 5 people

near hawk
#

That's like possibly the worst gamemode

mossy river
#

I mean.. it was fun back when I played it but I was more of a die hard DarkRP fan

near hawk
#

Actually no Cinema is, because you literally just watch a bunch of stuff

#

Yeaa I was always on DarkRP or Star Wars RP

buoyant tree
#

Anybody got a idea where I could get samples of people talking for a lil AI project I am doing

mossy river
#

||CancerRP|| was the worst. For those of you who don't know what it is, it was a game mode where 14 year olds were giving administrator privileges and they would doxx you if you stepped out of line or did something they didn't agree with.

Yes, that is the name of the game mode.

shut hawk
#

yeah...P2P not the best

rapid merlin
#

macOS >>>>>>>>> linux and windows

#

/joke

mossy river
bold dawn
#

hmmm

mossy river
#

There are dedicated servers, those servers were just.. owned by the 14 year olds

shut hawk
#

Oh sorry I'm getting mixed up with GTA

mossy river
#

Yes GTA is incredibly problematic

crude stump
#

Power hungry kids

mossy river
#

Interesting fact: GTA V Online Mod Menus don't actually use your computer.
It sends communicates with an external server, for Rockstar to "Block" or "Detect" a cheat, all they need to do is find the server πŸ˜‰

mossy river
rapid merlin
grim sparrowBOT
#

:hammer: newdev0000#0 has been banned.

rapid merlin
#

that was random

#

lmao why he even said that

crude stump
#

Did he say bad word

oak river
#

Bruh my rank is still not updating

#

Im 0x5

rapid merlin
#

idk

#

wat

#

I don't remember

crude stump
#

Classic

wispy estuary
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 497)

wispy estuary
tawny magnet
bold dawn
#

ping

blazing granite
bold dawn
#

thank you

tawny magnet
#

5 minute latency is crazy

rapid merlin
#

A stupid question... Do you take notes while thming? And if you do which app are you using? Obsidian? Cherrytree?

tawny magnet
#

Yea, I use obsidian, used to use one note

#

A good addition is to use physical flash cards or virtual ones with Anki

south shore
#

Hello !

rapid merlin
#

Hmm, anki didn't make me happy before but I will try this time around. Ta!

lavish shell
#

I just notepad.exe because of it's flexibility to both keep notes and it's ability to also be used to write scripts if need be

rapid merlin
#

Or vim πŸ˜„

south shore
#

What is vim?

#

Never heard of it

tawny magnet
#

Cli text Editor

#

Useful and powerful

south shore
#

Sorry im a beginner

tawny magnet
#

Command line interface

#

Like a terminal

south shore
#

Like kali linux termianl

rapid merlin
#

Very very ancient text editor on linuxes.

south shore
#

Kali linux is the goat

tawny magnet
#

There's also the more recent neovim that has plugin support and fancy features

rapid merlin
#

I remember even freebsd had one, back in the floppy disk times

south shore
#

Im on windows but installed the kali linux application from Microsoft store

#

Its working good

shut hawk
mossy river
#

Notionnnn

rapid merlin
#

Nope.

tawny magnet
#

Hecc notion

mossy river
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #13 - 498)

buoyant tree
shut hawk
rapid merlin
#

@devout palm what you using? for notes?

rapid merlin
#

It happily looks other malware wreak havoc tho

#

BLACKOUT.

#

wasp.

near hawk
#

πŸ‘‹

tawny magnet
#

That defender of yours has a hairpin trigger

rapid merlin
#

what you upto blackout?

#

any rooms you doing?

near hawk
#

Staring at the screen wonder what to do with life

rapid merlin
#

πŸ˜„ same.

rapid merlin
mossy river
rapid merlin
#

well do the Osiris.

tawny magnet
#

My defender

near hawk
#

I ain't ready for Osiris

rapid merlin
#

πŸ˜„

#

skiddy

sick lance
#

WindCorps is a good series

rapid merlin
#

wish we can get robot in here.

eternal ether
#

Hello guys!

near hawk
#

It's Windows, no one likes Windows

rapid merlin
near hawk
#

I do enjoy the Windcorp, Osiris is the only one now for me to get

sick lance
#

Shame the series moved to HTB.

near hawk
#

Wait, really?

sick lance
#

Yeah, there is 3 on thm. 2 or 3 on htb

shut hawk
rapid merlin
near hawk
#

My view is just a fence

eternal ether
#

I started reviewing my saved passwords and i saw that some were found in a data breach, others are re-used for multiple services and i was thinking of letting google passoword manager to suggest strong random passwords. Is that a safe approach or should i keep some of mine?

rapid merlin
#

like machines are shared with thm and htb?

near hawk
#

I would not reccomend google password manager

eternal ether
#

Why not?

sick lance
rapid merlin
rapid merlin
near hawk
# eternal ether Why not?

Google Password Manager is not the best service for keeping your passwords safe. From unclear security standards to poor usability to privacy concerns, Google Password Manager does not meet the most basic requirements for a trustworthy service.

normal fable
#

Bitwarden is nice.😁

eternal ether
#

Since i am logged in in both computer and smartphone because of the email, i have all of them available. Since it's Google, i find it hard to believe there would be a problem. Any 3rd party pass manager won't raise any concerns?

normal fable
#

Or keepass if you're old-school.

rapid merlin
#

I'll give it a try.

eternal ether
#

I assume you are referring to the free edition?

normal fable
#

Yes

eternal ether
#

But isn't a bit risky to trust your passwords to a 3rd party program?

rapid merlin
#

ofc, but keepassX ( idk the actual name) would be good to

normal fable
#

I used keepass for years. Was nice.

eternal ether
rapid merlin
#

google = user data collections center ultra pro max. πŸ˜„

shut hawk
rapid merlin
#

or you can write your own one.

eternal ether
tawny magnet
#

"What do you mean you rolled your own encryption!?"

rapid merlin
#

ofc.

tawny magnet
rapid merlin
#

Bitwarden +1. They were successfully audited - and the passes are encrypted by your vault password so even if someone gets your encrypted passes, they will be worthless in theory. But nothing is 100% secure

near hawk
lone thistle
#

aren't chrome passwords also stored locally on the device with the profile? I think i've even made a room/ctf on cracking the vault

near hawk
#

Yep

mossy river
#

Did you know that Google provide the functionality to download all your saved passwords in a handy zip file xoxo

rapid merlin
#

so where can people save their password we can't keep using the same password for every acc since this counts as risk and we can't now even trust google password manager so what now should we save our password in external hard drive or smth?

near hawk
shut hawk
#

There are plenty of good password managers out there

rapid merlin
lone thistle
#

1pass is chefskiss the app is fantastic, autofill gets everything, can even manage ssh keys and OAUTH stuff in there

shut hawk
near hawk
#

There are password managers out there, that you can have on a yearly subscription for Β£20-40

rapid merlin
shut hawk
near hawk
#

For the full functionality, the one I use has a family feature that comes with it for free

shut hawk
rapid merlin
sand trench
#

shadow is a bit of a whacky person when it comes to password storage

#

shadow uses keepassxc on computer and don't store any passwords on phone

rapid merlin
#

who shadow

#

what's shadow

#

?

sand trench
#

shadow is shadow... a cheese loving person from sweden that refers to themselves in third person @rapid merlin

rapid merlin
sand trench
#

no problem

#

happens a lot that people miss these things

rapid merlin
#

I guess ur user hides in the shadow

rapid merlin
#

not ready for it.

eternal ether
#

Despite the "bad" reputation about google password manager, since google stores all your passwords in chrome (or in your account, i don't know), then the only risk that i can probably think of is if someone has access to your computer?

near hawk
#

That's one of the main issues

waxen grotto
#

any good ctfs that came out in the last few months? have been mia for a bit and getting back into it πŸ˜„

near hawk
#

Which difficulty you looking for?

waxen grotto
#

intermediate-hard

near hawk
#

Clocky came out Friday, was a nice room should give that one a go, medium room

sand trench
rapid merlin
#

Clocky, Doge, kitty.

waxen grotto
#

huge, ill give it a look

waxen grotto
sand trench
#

would recommend shaker too

#

and if you feel like bashing your head against the table for multiple days:
you're in a cave

rapid merlin
waxen grotto
#

thanks shadow, i will be bashing my head against the wall shortly

rapid merlin
#

do the Reset

sand trench
#

forgotten implant is also fun

waxen grotto
#

lots of content dropped i see

rapid merlin
#

here is the room.

#

tryhackme.com/r/tryhackme

#

πŸ˜„

eternal ether
#

Is there any article on thm about some safe browsing and any necessary extensions to have?

oak river
#

If I have completed Intro to Cyber, Pre security and complete beginner can I do my first boxes?

#

Or I should also do web fundamentals, security engineer, soc level 1 and pentest+?

noble knoll
#

you can try

normal fable
#

You can always try. πŸ™‚

noble knoll
#

you always have writeups if needed, that's how you learn

spice adder
#

3rd bounty found in the weekend! latest is request smuggling 😬

#

thanks to thm for teaching me hehe

south shore
#

And you found. 3??!!!

#

Thats amazing dude

#

I have been trying to get in bug bounty

#

But i just cant i think

molten sky
#

how can you if you don't

south shore
#

Wdym lol

#

I just cant start

#

Idk why

#

When and where to start

#

I just dont know

tawny magnet
#

remove all distractions and force yourself to start

molten sky
#

now and bugcrowd/hackerone/yeswehack/huntr/intigriti/etc

south shore
#

I made a account on hacker1

molten sky
#

or don't and let me find them instead

south shore
#

All i know is echo and and cd and pwd

#

And kali linux and

#

Brute forcing

#

By hydra

molten sky
#

ah you mean technically how, you're at that stage

mossy river
#

Then for your safety I would recommend starting with TryHackMe

molten sky
#

THM ^

#

HTB

south shore
#

Htb?

molten sky
#

Burp classes whatever they're called

normal fable
#

100% do Linux Fundamentals on THM first.

mossy river
#

And check the pins in #bug-bounty for some resources when you think you’re ready

molten sky
normal fable
#

At least..

south shore
#

Burb suite!

south shore
#

Thanks yall

molten sky
#

(for burp and web specific stuff)

south shore
#

So first linux fundamentals

#

And then burbsuite

molten sky
#

si, linux fundamentals first

south shore
#

Yup

#

Is it actually possible to find bugs in websites

molten sky
#

tbf though, you don't really need to use linux to find certain bounties. a lot of web app stuff can be found with burp on windows (although i don't like it)

south shore
#

I feel like its pretty hard

molten sky
south shore
molten sky
#

community is all you need tbh. pro has some perks but they aren't required

south shore
#

Good!

molten sky
#

the only perk i use from pro is saved workspaces

#

otherwise i just use plugins

#

oh and collaborator (but you don't need that rn)

south shore
#

Im a beginner

#

Ik html css and some python

#

Nothing more

molten sky
#

yeah just start tinkering and doing thm stuffs

south shore
#

Sure

#

I will try

molten sky
#

also hi @mossy river

south shore
#

Thanks for help again

molten sky
#

i know you missed me

#

❀️

#

wtf why did discord auto emoji that

#

<3

south shore
#

Hahaha

#

I have a question

molten sky
#

we don't do those here

south shore
#

Ok

molten sky
#

( ask )

south shore
#

Does any website can get brute forced

#

Any login page

#

?

mossy river
molten sky
#

i mean, if things are done properly, it'd be difficult to

south shore
#

By hydra i mean

buoyant tree
#

the big websites usually have protections such as captcha or WAF's

molten sky
#

supposed to be mitigated

buoyant tree
south shore
#

Thanks

#

I wont ask again i promise lol

molten sky
#

you're fine asking things

#

that's what this place exists for, in the end

#

saw that

devout palm
molten sky
#

obsidian is solid

boreal scarab
rapid merlin
molten sky
devout palm
rapid merlin
spice adder
# south shore And you found. 3??!!!

hehe thanks. I must say, i've spent rougly 30 hours doing it in the past week - it's not a fast process so dont be put off that you've not found one yet, it will come :D

rapid merlin
spice adder
#

I've got to a point where i have a nice methodology to automate a loooot of the recon, finding my finds are coming much quicker because of it

boreal scarab
#

Wait, I got a better one.

sand trench
#

where is whitespace???

molten sky
#

yeah it's whitespace

#

of those four, it's C. but it's missing the actual correct answer

scenic bobcat
scenic bobcat
spice adder
graceful thistle
molten sky
spice adder
#

a true language barrier

boreal scarab
#

Y'all missing the actual best language. Assembly.

spice adder
#

never wrote in asm but reverse engineered it quite a bit

#

learn through pain rejoice

boreal scarab
spice adder
molten sky
#

"It's on github! That means it's open source!"

scenic bobcat
outer rivet
#

How y’all get that clown thing

#

?

molten sky
#

🀑

scenic bobcat
sand trench
outer rivet
sand trench
#

meep moop shadow is now gonna try for the sleep sloop to the beepity boopity beep boops while sleepity sloopity meep moop

outer rivet
scenic bobcat
#

good night shaodow

outer rivet
scenic bobcat
#

2am here AG_Stare

outer rivet
#

Which country ?

molten sky
#

be responsible

outer rivet
sand trench
outer rivet
#

Y’all from Asia ?

molten sky
sand trench
#

nopes sweden

outer rivet
#

Ohh

outer rivet
molten sky
outer rivet
#

Bio and background

noble knoll
#

Any monki lovers

outer rivet
#

Monki

molten sky
outer rivet
#

What about bio

#

You think is true

molten sky
#

i don't have the mental capacity to process what it says rn

boreal scarab
molten sky
#

off to get another drink and then get to bed before another day of interviews

boreal scarab
molten sky
#

scotch or beer for this one

molten sky
boreal scarab
molten sky
outer rivet
#

This is crazy

boreal scarab
#

Nah, @molten sky more like

molten sky
scenic bobcat
#

am on pwn104 now tho SilvCool so getting there

boreal scarab
# scenic bobcat Yeaa πŸ˜… x86_64 tho πŸ’€ and then aligning it properly and everything its sufferi...

An esoteric programming language (sometimes shortened to esolang) is a programming language designed to test the boundaries of computer programming language design, as a proof of concept, as software art, as a hacking interface to another language (particularly functional programming or procedural programming languages), or as a joke. The use of...

boreal scarab
#

I'll 1 up that

scenic bobcat
scenic bobcat
#

nah i dont hate myself that much

waxen grotto
#

any admins on?

boreal scarab
boreal scarab
mossy river
#

Literally about to sleep

waxen grotto
#

/semi serious, not interested in dropping in #site-support but it's a site bug that has potential risk to users haha

#

happy to dm to whoever and/or make a ticket

mossy river
#

Can you make a ticket on the website? Support will be able to handle it :)

normal fable
#

Man drone rules have changed a lot in the past few years...

waxen grotto
normal fable
#

If you click the chat bubble you can select 'contact support'.

waxen grotto
#

thank u

normal fable
#

Should get you there. Nobody there right now I think but should be tomorrow. πŸ™‚

real compass
#

Any rooms for the xz back door yet?

blazing granite
real compass
blazing granite
boreal scarab
#

@sand trench I need your help

scenic bobcat
#

she went to sleep already i think hehe

boreal scarab
scenic bobcat
#

am so confusled at how shellcode stuff works for pwn πŸ˜…

blazing granite
#

@scenic bobcat new pic and more colorful, nice πŸ™‚

scenic bobcat
#

Thanks, it fits me happy

gaunt basalt
#

whats rank 10?

#

is that 0xD god

waxen grotto
#

ur a wizard harry

scenic bobcat
#

I'm still waiting for the rank fix so i can get my cool 0x8

blazing granite
gaunt basalt
#

what rank fix

scenic bobcat
#

or did they fix it? the bot isnt updating ranks

gaunt basalt
#

oh word?

#

I dont know Im not close to ranking atm

scenic bobcat
#

Yeaa, im at rank 8 on the site but still on 6 here πŸ˜…

waxen grotto
#

i dont think its fixed yet

scenic bobcat
#

and nope just tested

gaunt basalt
#

rip

waxen grotto
#

im also on the road to being a wizard

gaunt basalt
#

yellow rank looks cooler than green tbh

waxen grotto
#

0x8 best color

gaunt basalt
#

In games green usually means common

#

yellow is mythic

waxen grotto
#

dont give yellow so much credit...

gaunt basalt
#

gold yellow potato tomato

#

I want a rank where my name is just pitch black

#

0xD John Wick

hot cairn
boreal scarab
hot cairn
#

Pink > Purple

boreal scarab
frank vessel
#

i don't even know what to do in this server bruh

#

should i leave but i wanna learn something new

scenic bobcat
#

anyone used pwntools? am trying to find out the best way to do the recvline() but i gotta save one of the inputs cause it has something i need 4626_glare
-- nvm

frank vessel
scenic bobcat
frank vessel
scenic bobcat
#

than maybe try that if you're brand new MochaShrug

frank vessel
#

idk nothing abt coding what so ever

#

πŸ’€

scenic bobcat
#

i mean you dont need to but like.. idk what else to say πŸ˜…

#

beginner path doesnt even go over coding

crude stump
frank vessel
#

oh

frank vessel
#

?>

crude stump
#

Interesting

buoyant tree
#

Somebody suggest me a movie for today

scenic bobcat
feral radish
#

hey guys

#

I have a question about SMB protocol, i want to try open a meterpreter session with a wordlist of default user and pass, I dont have any idea about this protocol, is this protocol can be exploited with trying a default pass and username, I dont found a much about this on internet, and i still new in this, any help

woven sonnet
#

Hello people, a question, is there someone here who can help me with my project about an app. You have to know how to develop and have knowledge of bank accounts at a good level, since you will be in charge of the area

scenic bobcat
#

@pearl lagoon why the friendreq πŸ‘€

pearl lagoon
#

Cuse you are also a red teamer
And I will also want to be a red teamer

#

We could exchange knoledg

pearl lagoon
scenic bobcat
#

why is this segfaulting why

scenic bobcat
#

Stack usually goes like

buffer / local variables
RBP
RIP
...

right? I am overwriting RBP, but i cant figure out why it just crashes before i can get RIP popped πŸ˜…

scenic bobcat
#

huh? ofc lol

pearl lagoon
#

Ubuntu , kali, parrot?

scenic bobcat
#

kali

tawny magnet
#

here i am thinking you are talking about the routing protocol and not the instruction pointer

scenic bobcat
#

hehe nah it assembly stuffs

#

every time i think i figured it out i just get hit with the fact i dont have a clue πŸ˜…

pearl lagoon
#

Btw where did you get the code ? Git?

scenic bobcat
#

my own lol

pearl lagoon
#

Oh

#

Python?

scenic bobcat
#

the exploit code, yea with pwntools

lavish shell
#

Sara, you still doing reverse engineering?

scenic bobcat
lavish shell
# scenic bobcat pwn but close enough πŸ˜…

There's a CTF event that should be coming up again at the start of October. I'm looking for team members, you interested? The event is DeadfaceCTF, it SHOULD start in October and it SHOULD last all month long

scenic bobcat
#

sounds interesting AG_Stare but October is a loooong time πŸ˜…

#

also i might be doing school at that point again think

lavish shell
#

I know, gives you time to perfect your craft lol. I had so much fun doing it last year, although it was a pain in the ass doing reverse engineering on a cell phone trying to use radare2 on a tiny screen

scenic bobcat
#

also school would be taking up all my time cause it quite a heavy class πŸ‘€

lavish shell
#

If you need help understanding the functions, I know a lot of them. Anyway, something to think about.

spice adder
scenic bobcat
#

the heck is exit code 81 even ArtsyLUL

lavish shell
#

Definitely look it up Sara, if you get any error code you don't understand, research it. Understanding the error code is key to understanding how to prevent it. I got a BSOD on a windows back in the day, some long ass error code like x0abdfxg63xblah blah. Had no idea what it meant, but once I researched it, I realized what I needed to do to prevent it in yhe future

scenic bobcat
#

I did.. but got no actual related results

rapid merlin
#

Hey guys, for the buffer overflow room in thm, if i don't have good basics in BOF, what do you recommend for me before tackling that room? Thank you

lavish shell
#

You need an understanding of Low Level Languages like Assembly, and at least an understanding of how to perform reverse engineering in order to understand what a Buffer Overflow is

rapid merlin
#

Any materials you recommend?

#

I'm going to watch Buffer overflows made easy by tcm, i hope it's enough

lavish shell
#

You can look up Micro corruptions. It's a reverse engineering game and has a few buffer overflow challenges. If you get stuck, there are walkthroughs for it. You may also look at THM in the search bar and see ehat they have available as well

rapid merlin
#

Thank you so much

scenic bobcat
placid arrow
#

Free vpn?

lavish shell
#

I believe Proton may offer a free one. OpenVPN is free (as far as I know).

hidden hazel
#

You have romania poland netherlands japan and united states in the free version

buoyant tree
#

and limited speed/bandwidth I presume

hidden hazel
#

Yep

sick lance
#

Student discount for proton

azure hinge
#

can anyone help me for a room

#

in room help section

coarse moth
midnight hazel
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @scenic bobcat (current: #413 - 11)

midnight hazel
rapid merlin
#

Why?

crystal kayak
#

hello eve

spice adder
#

Question?: Vulnerabilities that are browser specific, more specifically very old browsers…still worth reporting in a bug bounty? I’ve got 7 pages vulnerable to reflected XSS but they’re only available in long deprecated browsers

lavish shell
#

You'd be surprised the things people still use today. I know companies that still use Windows XP.

crystal kayak
#

god I just experienced a very painful learning experience

lavish shell
#

But a lot of sites won't let you view sites if your browser is outdated, so I don't know

shell garnet
#

Hey you all, i have a question on dashboard it is showing my streak is 7 (i.e i can join rooms with streak restriction) but when i join room it shows i have streak: 6

spice adder
shell garnet
#

what is the problem here is thm new interface glitchy or what?

crystal kayak
#

this stuff is too hard for me πŸ₯²

#

good night all

hazy flume
hearty plover
#

Regarding Proton, whats your opinion about it guys?
I use it because Switzerland is a privacy first country and its OS
But im curious what other ppl think

strong flicker
charred forum
wintry sluice
glossy portal
worn thorn
narrow pewter
spice adder
#

but sometimes find yourself on blacklists for emails lol

timid prism
shut hawk
crystal kayak
worn thorn
#

I might even go paid after I pick what linux distro I want to use in the future.

mossy river
#

Morning all

sick lance
#

πŸ‘‹

crystal kayak
shut hawk
#

Morning

chilly veldt
#

Morning

wintry sluice
#

morning already?

hollow pivot
#

mornin

worn thorn
#

noon

hidden hazel
#

Morning

hazy flume
#

good morning

#

i like how to oasp juice room sent me to the buro suite room and the burpsuite room sends you to the mysql injection room

narrow pewter
#

Good Morning

subtle drift
#

morning guys. I just did the same thing @hazy flume last week. they dont take long to go through and are super useful

hazy flume
#

thanks ill probably finish them today

subtle drift
#

its worth it for the other challenges in juiceshop and in the next section of the complete beginners

hazy flume
#

i like after every room just to sit back and watch many videos about it

subtle drift
#

me too. or i'll watch a walkthrough after i've completed the room to see what i could do better

hazy flume
#

nice

#

what path are you doing

#

im in the complete begginer path, moving slow

subtle drift
#

i did intro to cyber sec, pre security and now im moving through complete beginners. i started with what took my fancy and went from there. a lot of the modules cross over into other learning paths too. when i come across a room i've already done, i reset the progress and do it all again

#

i'm at 59% of the complete beginners

hazy flume
#

yea me too and after complete begginer i want web fundamentals, and then jr penetration tester

#

im at 55%

subtle drift
#

in all honesty, i'm gonna do everything on the site haha, it's all useful and it'll give me an idea of where i want to specialise. looking at doing my CCNA, too

hazy flume
#

yea i also plan to do everything on the site im addiceted

subtle drift
#

just found a 15 year old laptop that i'm gona turn into an SQL server to beat up pikapika

#

i love how hands on the site is and i'm looking forward to doing hack the box and pico ctf once i've worked my way through THM. from what i can tell, this is one of the best jump off points into security and i'm loving it

hazy flume
#

i stoped hackthe box

#

i find tryhackme better for begginer

worn thorn
#

you can test out your knowledge on htb. I still can't do some of the easy ones kekw

#

massiv skill issue on my part

subtle drift
#

i did rootme CTF not long ago and that was pretty fun . i've got Pickle Rick up next in the complete beginners path and i'm looking forward to that after doin the reverse shell stuff

#

the more you go through the rooms, the more you pick up. i know redoing some of the rooms has helped me loads when i've been a bit stuck.

hazy flume
#

i did the machines on easy there

#

before i got to tryhackme

#

but i didnt finish the modules there

subtle drift
#

i can only do one subscription at a time or i'd be on there too lol. i looked around and watched some youtubers and decided to leave HTB until i had a bit more of a foundation

oak river
#

So, I ususally do OneNotes for everything I learn and all the chapters

#

But do I really need the windows one if I use it on a daily basis?

#

I mean in this case I could just learn it, I don't feel like notes are necessary

#

Since I use it on a daily basis

#

What do you think?

subtle drift
#

you'd be surprised at some tricks you can pick up. especially powershell, active directory and some of the SQL stuff

hazy flume
#

i do notes like that :

oak river
hazy flume
#

with obsidian

oak river
#

I do with OneNote, but I might have to migrate to Obsidian at some moment

#

Or maybe Joplin

subtle drift
#

it's worth it as a refresher. i've been a windows user for 30 years and i still found it useful. the linux fundamentals is gold dust too

#

i wirte manual notes cos im old haha

rapid merlin
#

my dog almost manipulated me to fall a sleep with him

crystal kayak
#

it's cute

lyric otter
#

Hmm, the new room Windows Application Forensics was advertised as a free room and it was, now it's not a free room apparently?

sick lance
lyric otter
#

Alright, thanks for clarifying

brisk tree
#

Hey

hidden hazel
#

Yo

sick lance
#

'Ello

rapid merlin
outer rivet
outer rivet
#

Dark is way better

abstract shore
#

Thanks to TryHackMe team/community for making amazing labs!

#

I passed OSCP, only by practicing on THM

rapid merlin
#

I like light bc it fits my office

hidden hazel
#

light on top fr

simple valve
abstract shore
sick lance
#

You ask a mod nicely. πŸ˜„

rapid merlin
abstract shore
abstract shore
#

i just did all the rooms i could

#

like, i used to search for windows or AD, and do those boxes

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @abstract shore (current: #2045 - 1)

rapid merlin
#

what are some certificates that are worth chasing (ik abt CompTIA and cisco only)

abstract shore
hidden hazel
sick lance
hidden hazel
rapid merlin
abstract shore
abstract shore
#

for AD, PNPT is also good

hidden hazel
#

i recommend hack the box CPTS its pretty good

abstract shore
#

Since I work in a red team, i will look forward to CRTP etc, but i also need to do oswe

shut hawk
#

almost a week into holidays and its been raining every single day sadgecry

rapid merlin
rapid merlin
abstract shore
#

Offsec certs are expensive AF

rapid merlin
#

True

abstract shore
#

Otherwise I would have done all of them

rapid merlin
#

But the oscp is the only cert you need that really open doors for recruitment

abstract shore
#

But I will pick and choose, which ones are valueable

abstract shore
hidden hazel
#

they typically look for crest

shut hawk
#

Depends a lot on where you are

#

For example in the UK, CHECK via Cyber Scheme is one

rapid merlin
abstract shore
#

Oh wait

#

i mean OSCE

#

Do employers prefer OSCP or OSCE?

rapid merlin
rapid merlin
twin ridgeBOT
#

βž• Gave the role OSCP to trenton_.

rapid merlin
sick lance
#

There you @abstract shore congrats! and enjoy the new channels.

abstract shore
#

True, OSCE focuses more on evasion techniques etc similar like CRTP

abstract shore
rapid merlin
simple valve
shut hawk
#

Be careful about going for the advanced certs without getting any professional experience

rapid merlin
#

A friend told me to shoot for the CRTE and CRTO since they are cheaper and get you more roles

abstract shore
simple valve
abstract shore
abstract shore
simple valve
#

its called OSCE3 now

rapid merlin
abstract shore
simple valve
#

it do be like that sometimes fr fr

rapid merlin
simple valve
#

CRTO is fun

#

cobalt strike is nice

rapid merlin
#

Do you think the red team path on thm would be enough to take CRTO and CRTE?

grizzled crystal
#

probably not

#

it would help tho

simple valve
#

CRTO is heavily cobalt strike

#

helo @grizzled crystal , have there been any labs you werent able to reproduce?

#

the ntlm relay not working for me 😦

bold dawn
#

THM is mostly for supplemental learning. I wouldn't use it to replace the content that comes with a certification

grizzled crystal
#

nope! what are you struggling with?

bold dawn
grizzled crystal
simple valve
#

okay okay, i might buy some ingredients for japanese curry then can i dm you in an hour or 2?

#

i will try to redo it after resetting

grizzled crystal
#

works for me

bold dawn
#

hey Aquilo

grizzled crystal
#

enjoy your curry, im also grabbing lunch

#

hi hi

bold dawn
#

how goes it?

grizzled crystal
#

doing good! how are you?

simple valve
sick lance
#

Impacket or responder?

bold dawn
#

good. just prepping for the kiddo at this point

grizzled crystal
#

kicking it will make the dying worse

simple valve
shut hawk
#

kekw (for context, the regex matches against http URLs)

simple valve
#

hopefully resetting the lab will work

bold dawn
#

oh are you using attackbox?

simple valve
#

its the CRTO lab, everything is already provided there so i cant use other tools

bold dawn
#

ah, okay

#

interesting

grizzled crystal
simple valve
grizzled crystal
#

actually i gtg but ill follow up in an hour

simple valve
grizzled crystal
#

we can walk through it

#

yes there is a video

#

very helpful

simple valve
chilly veldt
#

πŸ‘€

sick lance
astral grove
#

I am a little afraid, I am purchasing an offsec subscription πŸ˜¨πŸ˜„

bold dawn
#

are you going for a certification?

#

the benefit? they pretty much own the cert game for the industry as of now

#

some people think the HTB ones will become a standard in the future, but we just don't really know

rapid merlin
bold dawn
#

I am starting the CBBH coursework today. I haven't used the academy yet, but it seems well structured from the outside

rapid merlin
#

Keep us updated want to know more

bold dawn
#

sure thing. I work in web sec, so not sure how much of it I won't know, but, there are some modules that spark interest, that I didn't think they'd cover

#

such as hacking wordpress

hidden hazel
bold dawn
#

nice. I can vouch that TCM exams rock, they just done have an intermediate certification yet

#

for web sec

#

so CBBH it is, and maybe I'll do their expert one down the line

hidden hazel
#

just make sure to take alot notes and you will be fine

#

my only problem with Hack the box modules is how reading heavy they are but its also good because you get alot of knowledge, just takes so much time

bold dawn
#

yeah, it also allows me to study in down time easier than having to pop up a video

hidden hazel
#

i dont particularly mind reading it just means taking notes includes more writing

rapid merlin
#

How does the cubes thing work in htb i'm kinda confused, which membership is enough to study the pentester path to pass the cpts?

hidden hazel
bold dawn
#

If you do yearly, they should unlock the path as long as you sub. Monthly, they give you a certain amount per month

hidden hazel
#

its just the exam ticket that costs the most

sick lance
bold dawn
#

so Plat gives 1000 a month

#

gold is 500 a month

#

or something like that

hidden hazel
#

i just bought the cubes outright over a few months but its defo cheaper to subscribe

bold dawn
#

yeah

#

cost under $100 to sub for it

#

and unlock the whole course if you do one month plat and one month gold

hidden hazel
#

ive done both the course for cbbh and cpts and i dont think ive spent more than Β£200

bold dawn
#

i est $150 buying outright

hidden hazel
#

because you earn cubes back

bold dawn
#

oh yeah

hidden hazel
#

if you look at the path it tells you how many you get back

bold dawn
#

forgot about earning em

#

it's such a weird model

#

but it works

rapid merlin
#

So i guess the minimum plan is the wisest

hidden hazel
#

i personally love it

hidden hazel
#

especially when you get to active directory and stuff with 30 sections

rapid merlin
#

I see i see

hidden hazel
#

it took me about a year to do CPTS but i was also lazy with it sometimes so i say 6months is a fair estimate if you really try

#

all depends on your learning speed its pretty easy at the start the progressively gets harder i did the first like 6-7 modules very fast

rapid merlin
#

Rn i'm focused on the ecppt since i already bought the voucher

#

Once i pass it i'll focus on htb

hidden hazel
#

yeah lol thats why im not doing the exams rn because you get 10 days i wanna work on some other stuff

bold dawn
#

I was debating between eWPT and the CBBH

#

figured this would be better practice

rapid merlin
#

eWPTX

#

Is the extreme version of eWPT

hidden hazel
#

i hate web so im never doing that

simple valve
simple valve
#

never go the INE route angrycooctus

bold dawn
#

INE is more recognised, was my reasoning. This cert I am getting is more for client marketing

simple valve
#

i mean as long as youre not paying for it

outer rivet
rapid merlin
rapid merlin
#

do OSE3 if you think you are Jason Todd.

#

nvm.

fluid ember
near hawk
#

Really curious to know what a XXL 1000 layer potato looks like

shell nova
umbral kiln
#

@rapid merlin cool desktop okaymelon

hearty plover
#

I got a scam phishing sms with a site which i whois'd. It is registered at aws, does anyone know where i can report that :o?

glossy portal
rapid merlin
rapid merlin
glossy portal
#

DC comics

rapid merlin
#

πŸ˜„

sick lance
glossy portal
rapid merlin
#

that's Jason.

glossy portal
#

Superior batman you think?

rapid merlin
rapid merlin
glossy portal
# rapid merlin he is.

Well his punishments are logical, but in the DC universe, the law is basically broken πŸ˜‚

glossy portal
#

Like, how the hell does Joker keep getting out???

#

Batman should look into being a prison warden πŸ˜†

wintry sluice
rapid merlin
glossy portal
#

That would make sense yeah, I bet you could progress Gotham a lot more if Batman invested more into reforming it from within, but he's only interested in beating the crap out of criminals with his own hands I think

rapid merlin
#

Bro isn't into delegating work, i guess he had bad experience with contractors who used to protect his parents

wintry sluice
glossy portal
#

Probably yeah, being batman probably sucks, his response - that is to beat the crap out of criminals is some form of rightful indignation in his eyes to the trauma caused by his parent's deaths

rapid merlin
rapid merlin
glossy portal
hidden hazel
glossy portal
hidden hazel
#

Its for 13 year olds

#

Not meant to be realistic

#

Just meant to be entertaining

wintry sluice
rapid merlin
wintry sluice
rapid merlin
#

well.

hidden hazel
rapid merlin
#

😁

smoky atlas
#

Clown everywhere

glossy portal
wintry sluice
glossy portal
rapid merlin
#

how long it takes to complete 200 rooms?

hidden hazel
wintry sluice
#

depends on the rooms

#

depends on your abilities

hidden hazel
#

πŸ€“πŸ€“

#

Nah it does

smoky atlas
hidden hazel
#

Bro asked a silly question

umbral kiln
hidden hazel
#

Depends if ur good or not

umbral kiln
rapid merlin
#

?

hidden hazel
#

?

umbral kiln
#

?

shut hawk
#

?

hushed fern
#

there are so many infosec certs and it feels impossible to know which are good, which are trash. everyone has an opinion lol

sick lance
umbral kiln
#

and everyones opinion is trash according to everyone else

shut hawk
hushed fern
#

right now i'm just brushing off cobwebs, gonna grab the comptia trinity while doing webdev stuff and THM, feels like a good initial spread

#

just in time to get replaced by AI 🫑

hearty plover
#

I went through a thought process, ProtonVPN is "no log", but what if the VPN connects to a server in the USA? Don't the policies of the USA then apply and they can thus record what happens on the USA server?

devout palm
rapid merlin
#

?

sick lance
#

Stop with "?", all you're doing is spamming.

rapid merlin
pearl lagoon
#

?

rapid merlin
#

it is for all ages there no specific age req to read those comics books but the ones who wrote it were targeting 13-16 years old

sick lance
#

I don't appreciate being ignored.

If you're going to ignore me, you'll lose the ability to speak. πŸ™‚

hushed fern
pearl lagoon
#

Things got heated

hushed fern
#

i think anyone saying anything will or won't be 'replaced' by AI is talking out of their ass. no one knows.

rapid merlin
#

i cant spin a vm
where can i host a php payload?

#

idk how to do port forwarding

pallid lotus
#

Gonna need more context than that bud πŸ˜†
What are you trying to do?

pallid lotus
#

LFI you need the payload on the target

pallid lotus
#

😝

umbral kiln
#

did you at least go somewhere?

#

or rotting inside your home

rapid merlin
shut hawk
pallid lotus
umbral kiln
#

i am

#

just eating lunch rn

shut hawk
pallid lotus
rapid merlin
#

I firmly believe AI will displace many jobs in the future, but not anytime soon. We're talking decades, not years just a personal believe its not from any source

pallid lotus
#

And why do you need it to be public?

rapid merlin
#

to escalate lfi to rce

sick lance
rapid merlin
#

idk why

pallid lotus
#

Checklist?

rapid merlin
pearl lagoon
rapid merlin
#

hell one day maybe chimpanzees will steal our job πŸ˜‚