#general
1 messages · Page 116 of 1
Actually you could compress the trash into a black hole at which point hawking radiation will shoot the matter back out as a single element
respect @gritty fern
we actually do have like a hot-tub sized metal pit out by the cabin that gets some roarin burns going during deer week
u too man
pallets on pallets on pallets make the garbage no more
i try not to breathe it too much tho
thanks @gritty fern
Gave +1 Rep to @gritty fern (current: #826 - 4)
Guys we should hash password hashes
Hm
They would be like 100s of times more secure right?
guys don't tell em
Tell me what
nobody tell em that some algos already do that
So do it three times
i just exploited XXE in less than a minute for a job interview box n im so happy i have 20 mins left XD
nobody tell em that some algos do it more than three times
For things like checking a password you dont need speed
FIFTEEN
double des does 16 by default and it's like stone age
Jesus christ is cant be beat
sha-2 apparently does either 64 or 80 rounds
sha256 set between 1000 and 1B-1
Alright im making SHA-2048 it runs it through 10 trillion times then runs it through 256 then 128 and so on until 1
you kid but that's actually effectiveish unless the algo itself is broken
all about making things slower
Ill be dead by the time it finishes prolly lmao
Joking itd probably take atleast a year though
adding different algos can add weakpoints in some ways tho
Even if i add all of them?
depends on the situation but say one algo is more prone to collisions than another
But thats the whole point of using all of them
Just makes it like 5 billion times harder to crack
man i need sleep
lol tests
I hate tests
lol x2 ACT
question
answer
my user is an actual memory adress right?
Cuz i dont fully understand memory addresses like idk if theres range limits or such
man i haven't done anything with memory since uni, outside of the odd 15 minute BOF session
Ok lol
couldn't tell ya
God morning
Morning
eh Nile or 0day are probably the most dangerous, even more in a combination
You know you're good when you win a CTF with only 1 point
..., the guy hacked the CTF?
No, we got so many points the CTF backend shows our points wrong
Daymn
Congrats
Thanks, it was a meme challenge that did it for us
meme challenge?
Yeah, they had a meme challenge called guessctf, aka guess the solutions, aka figure out 31 different challenges in 1 challenge, aka figure out the password to 31 zip files
beginner bug bounty hunter here, what are some places where I can find the latest news and vulnerabilities?
eid mubarek
eid mubarak!
nile do be a secret villain making food.
You have sites such as hackernews, hackread, bleeping computer for news
Exploit-db you can find CVEs with the PoC
is there a room for learning reverse engineering with ghidra or some other tools?
Search Ghidra.
hey
thanks, I'll check them out
Gave +1 Rep to @near hawk (current: #67 - 97)
Gave 1 Rep to .scrubz. (current: #1 - 2149)
What's the best way to transfer information from short term memory to long term memory?
Notes
somebody had a problem with the pyramid of pain practical not working?
Yeah, it's broken, that's what you don't need the flag to progress.
ok thanks
Hi all. I'm trying to find info on Google Cloud security vs Azure security in terms of cloud tooling, learning material, and general attitude toward security.
Why I'm interested in this: I've noticed Microsoft catching some heat lately, and I'm weighing whether I should pursue more certifications for GCP or Azure. I'm particularly interested in specializing in a platform that is suitable for small businesses and new startups. Google seems to be very proactive and engaged with security, and I have been impressed with their learning material, so I am leaning that way.
yeah saw that right now doing some x64dbg
hello everyone
is it just me or are there a lot more bots in the VirusTotal comments/community section than there were say 3-4 years ago
it's not really bots
it's more like automation due to detection via honeypots or something alike
wish there was a way to filter them lol
How is everyone
Ah, set up my new kali box and forgot to get the wallpaper from the attackbox.
not bad how about you
yo hi
Zzz
Hi
Are we boring you!? 
Hi
i want to dm TryHackMe admins
Where can I use Discord token?
Admin required or can a mod do?
Why
How the hell does it take 2 hours for a mechanic to change 4 wheels?
@left kindle
i built a machine and i want to know how to upload a room and i want to know if they pay for room creators or not
I need to replace my 4 tyres too 😦
We do not
Okay
They don't for the latter question.
any one who have knowledge about room creation will be more than enough
Jabba just answered you, abd Hydra linked the docs 🙂
Enjoy
i wanna DM the admin to see the attack path is it good or not
Don't need an admin for that
QA will decide that when they review your room 🙂
The room will go through several rounds of internal and UAT testing
ah okay
If something's up, you'll be asked to make changes and resubmit
okay all good thanks
Gave +1 Rep to @shell nova (current: #11 - 564)
Cheers
Oh gods WSL just updated and it brutally nuked all my sessions >.<
RIP.
gotta love fixing an issue and then finding a whole new one 
oop
That’s pretty good pay
Ooo
I saw
That could mean anything. Some have you meet up like 1 a month or could be once or twice a week
Wish they would specify
"How was your commute"
"It was ok, no traffic in the sky"
Hello
Imaging flying to work in a flying taxi 🤣
No a flying car
Or a helicopter.
Im doing alright currently studying hbu
Just relaxing before I get my project for my internship
...
Hello sudoeurs teams
By 2026 apparently
Dropped off at work by drone.
Ahaha would be so fun
What kind of internship
Pen testing
How is that going?
Ahahaha that's what I want to work towards 🤣
Really good. We'll be doing a live pen test on a client I think
Whats your background in pen testing? Any background knowledge?
No this is my first lot of experience in it
I just finished my group report for Pentest, we're going to over it once or twice until we hand it in.]
Aww nice. I did enjoy doing it. The dream is to tell people there security is crap 🤣
I want to get into pen testing but have almost no experience in anything tech related jobs so learning from scratch
A few companies in India are doing remote pen testing internships
@steel aspen did you get your a new kali box set up?
This is Gnome, you'll want that.
vmware vs virtualbox for windows
oh i like qa
Hyper V
I’ve always found it the most stable imo
Vmware 1000000%
Sadly I’m not a student so I can’t do internships
are they good
courses are good their sales is horrible
ah do you think youll ever study it
oh
all my malware stuff is in vmware with windows.
Im trying to go back to school for it but for now using thm to learn
Just wish I had a teacher bc online and videos get me lost if I’m not dead focus on it, like eyes wide and glued to the screen XD it also helps if I have questions in that instance
i need to take a pcap of something, what do u do to make windows shut up 💀
all my vms are also in vmware
I hated virtualbox when I worked with it and never went back
qemu or vmware
Any specific reason why you hated it?
the UI
and how messy it was in total
(mind you, this was several years ago)
I started off with virtualbox then got annoyed at, went to vmware but for some reason my CPU in my kali kept spiking and now moved to hyper-v everything smooth
Did anyone get interested in hacking bc of anime? Just curious
Maybe I don't use them enough to notice a big difference between both
yeah, this was like 4 years for me
no i did it bc i was gay
Which one was it
Movies, specifically Ferris Bueller’s day off
Good movie, had to watch that like 4 times in film studies
Hopefully not in here though
Yooo which kali linux should i download theres like 8 of them
Whatre you using it for?
VM or booting
Hackin
Lol ok you need to watch a YT video on USB booting and virtual machines first
And from there you can decide which kali to download
VM resets everytime and Dual Booting doesnt
Both have ups and downs
Thats not true, unless your running a live boot in VM
whats vm
virtual machine
I dont think i run live boot but maybe ig
and uh whats that
Sorry, I could be asking really dumb questions
But we all were new to this stuff once
virtual machine is like running a computer inside your computer.
No such thing
it's a "computer" that runs inside your own computer, it's virtualized to make it look like a real computer
Oh what
oh
I think that will have many cons, leme search it up rq
Not really
not that many cons
depends on your hardware.
most servers today is virtualised
I don't mind whichever one, as long as my pc is safe and I should be able to play video games on good graphics like the way I do rn 😭
Just use a VM
then you definitely want a VM.
Dual booting
What's the other one? Going to research bout it.
way harder to set up
Thanks.
But i prefer it personally
data loss and glitches are the cons of dual booting
yeah ill stick to the first one, VM.
data loss?
Why cant i attach dam images
I have a dedicated laptop that runs kali, but I only pull it out when I am pen-testing wifi or using some other kind of peripheral USB device
you have to verify
with / verify no space
I've...
@vagrant sonnet
so your best bet IMO is to download oracle virtual box, and the Kali virtual box appliance
yep
Anytime
Okay, now which one...
oh
Yeah there should be a VM one specifically
Install Kali Linux on Windows 11 using VirtualBox for free - it's not a difficult install and it's a great way to get started.
Need help? Join my Discord: https://discord.com/invite/usKSyzb
// Other Install Options //
Kali Linux USB Live Boot: https://youtu.be/FYYU9qZ0Pps
Kali Linux Dual Boot: https://youtu.be/2vTVA-Nq0bw
Kali Linux NetHunter P...
thats what that guy suggests as well
^^ yes david bombal has great content
David is a great source
okay
So which one here is virtual box
i cant seem to find it
david bombal
network chuck
rona kahlil
john hammond
will all teach great stuff...many others even, but those are my personal fav
btw which one here is virtual box
None of them
ohhhh
Now which one
VM is an acronym for "Virtual Machine"
dam how large is this file gonna take a while....
Yeah, shouldn't we be downloadin the first one?
Don't you mean abbreviation?
It's a whole operating system, it's fairly large
Yes, thanks
Gave +1 Rep to @sick lance (current: #1 - 2150)
Ay so you guys must be some professionals of hacking
Prob mastered hacking by now
Not sure what you mean?
Because the ppl i met earlier said get Virtual Machine which was the first option in the list but we got the second one, virtual box.
Virtual Box is within the Virtual Machine category
oh alright
jack of all trades, master of none lol
do u guys have this error too ?
"Wed Apr 10 13:52:05 2024 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=425397202556807641543660048237946304772097879576
Wed Apr 10 13:52:05 2024 Sent fatal SSL alert: unknown CA
Wed Apr 10 13:52:05 2024 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
Wed Apr 10 13:52:05 2024 TLS_ERROR: BIO read tls_read_plaintext error
Wed Apr 10 13:52:05 2024 TLS Error: TLS object -> incoming plaintext read error
Wed Apr 10 13:52:05 2024 TLS Error: TLS handshake failed"
Joined all these servers around 30 minutes ago, found this one the most helpful tbh.
Ay that flipper zero and usb killer gadgets are expensive
those are just toys for fun IMO. toys to screw around with, in the bar with friends. "hey chuck, if i can change the TV channel you gotta buy me a beer"
I used to have a watch that done that.
haha yeah, I had that watch too.
In step 6, what is the reason of mentioned the SSID!!
In bruteforce, We only need the hash, is not it!!
Even when searching, I did not understand what the purpose was
Isn't the hash is the hash of the password? So what does the SSID have to do with the hash of the password?
Why we mentioned SSID, why we just dump the handshake file! And start the bruteforce.
Like most tutorials on Internet. this is my first time I see someone mentioned the SSID on bruteforce, So what mentioned SSID change?
Using for example airgeddon or aircrack-ng, we don't need the SSID to found the plaintext password , We just need the handshake file, isn't?
Isn't the process of the WPA bruteforce is trying to find the plaintext of the WPA hash password, by Converting a word to a hash and comparing it to the WPA hash until we find that match it, So why we need the SSID!! 🤷♂️
Welcome, my hacker novitiates! As part of my series on hacking Wi-Fi, I want to demonstrate another excellent piece of hacking software for cracking WPA2-PSK passwords. In my last post, we cracked WPA2 using aircrack-ng. In this tutorial, we'll use a piece of software developed by wireless security researcher Joshua Wright called cowpatty (often...
Why do you think you need the SSID?
I talk about the guy on the tutorial, the "traditional" way to do WPA bruteforce, There is no need to mentioned SSID
So what SSID mentioned change on the process!
think about it. What is a SSID? That will answer your question.
It's like having all the keys in the world but you don't know which lock it fits.
Ay im never trusting github again i downloaded this hacking tool called builder bat and it gave me some virus thing idk what it was so deleted it
Always check the content you download beforehand 
Why hypervisor are you using?
what*
what is that
i thought github is safe
I had three seperate people ask me to playtest for them and 3 out of 3 were malware.
not always.
But why can we find the password without the SSID then, for example using aircrack-ng
You need a hypervisor to run a vm
Virtualbox is good.for starters
you need to target a router first to capture the handshake
so you need to have the ssid of it.
which it happily screams if not suppressed.
when you want to program but you can't cause you have to talk to a person about what they want this to do, but the person is unavailable for a talk
pain
I have 3 different ways to solve this issue, but I need to hear what my colleague wants it to do, and that is different for each 3 solutions
so I am waiting for them to be able to have a small call so I can talk with them about the solutions and ask what their intent is with this program
oh
the good old chain of command... Talking to 6 people to answer a simple question
yuuuuup
We're talking about what's next captured the handshake, We of course need to specify the AP to capture the desired handshake, But when doing Bruteforce, do we need the SSID, if yes why?
during bruteforce, no. You already have everything you need.
But In the tutorial, i see he have the handshake, and he mentioned the SSID! 🙆♂️
maybe they didn't mentioned it before and just slid it in 🤷♀️
Some tutorials aren't really that great.
Look, he select the handshake and select the wordlist and select he handshake
with context it makes more sense
We talk about null byte
also typo in the article 
This is the whole of topic, what this mean!
haven't really lookes at nullbytes for a long time but they were a reason for me to start the journey.
google 😛
It's time to dust kali off and not hibernate again. Hope I still remenber how to linux ...
I say "Even when searching i did not understand what the purpose was", Why did i come here if i found the answer of my question on google! 🙂
Because you come here for alot of things when you could easily google.
Previously I was, Not Now on most case lets say
In all cases, the AP is not logically identified via the SSID, because it is possible that there are two APs with the same name
If you google something and don't understand it, that is fine, it happens to everyone. But then you need to be more specific with your question:
" I read about X in this article, and when the author talks about Y, I don't understand what he means by Z. I did some more research, and I am having trouble connecting the dots between Y and Z. My understanding is that Y and Z... Is that correct?"
I'm not really that versed in WiFi Security and how to differentiate between two devices having the same ssid.
uhm, the SSID is the network name, not the AP
SSID is the name of a wifi which stands for Service Set Identifier
guys can anybody tell me if it is necessary to add spaces to SQL injections? I see that many times I need the trailing space, therefore it is not enough to make something like
admin' or 1=1--
but I need
admin' or 1=1-- -
but I see in wordlists like wfuzz that I use with burp that there is no trailing space... is this bad?
Depends on the backend usually
You'll probably want the semicolon as well. Also the -- - formulation includes the space after the comment token
yes but when I look into SQL wordlists like here
https://github.com/xmendez/wfuzz/blob/master/wordlist/Injections/SQL.txt
there is no -- - but only --
isnt this failing a lot of cases because -- - works everytime (because the single - is commented out anyways) but the normal "--" could miss
Depends also on how wfuzz sends it. Could be url encoded. So you see -- but its actually sending --%20
i think the space is technically necessary because i had many cases where inject is not working because mysql really wants a space. for example
select * from users; --comment without space
select * from users; -- comment with space
the comment without space will give sql error because "--" NEED a space afterwards so the injection will also fail
Only necessary if its MySQL
Off the top of my head, I don't know other RDBMS that requires a whitespace.
so basically I dont break anything if I replace all "--" with "-- -" in the wordlists, because mysql needs it and others just ignore the additional "-"
Yeah. You can also use --+ , --%20 , -- x, etc.
I know of course, Maybe I will replace the Word "identified" to "specified", I am weak in English Language 🫠
Anyway, Can you help me about my question if You understand my issue
why? if I have "-- - " with trailing space the single "-" after the double "--" is a comment and ignored anyways... so whats the difference in having a comment that is ignored by the interpreter having additional space?
You thinking about it in terms of sql syntax
When how web app processes user input is no less important
It's all added to protect the trailing space, basically
I do not help with wifi bruteforcing as a principal sorry
Bet it's used in some obscure dbms too
Eid mubarak
Just by doing a Scan, and choosing the AP number
hey yall anye1 here knows any good mic for like under 50 bucks?
40$ 50?
i know theres solocast hyperx
Eid Mubarak to all
Is Eid today in all religions?
eid mubakar is for muslims bro
Ah, Fortunately, I am Muslim 😀
eid mubakar bro
that is quite obvious but how does the program achieve it. This is what I meant by my statement.
Thank you, Eid Mubarak Too
Gave +1 Rep to @delicate reef (current: #1024 - 3)
Alaynaa wa alaykum!
Oh, I understand you.
But in the problem I faced, we don't deserve to see the program from the programmer's point of view. All I want to know is why we specify the SSID.
Anyway as you said, we just need to handshake after captured it.
There are two sides of this. Knowing how a program works and just using it without thinking about what it does.
You can always check the docs of it to learn more.
Read about the PBKDF2 algorithm
damn
Since it seems on a SSH connection it sends every letter you type even before you hit enter to execute the command, does that mean blueteam gets to see my awful typing skills? 🤣
Like, having to backspace because I typed a flag wrong, or used the wrong capitalization, etc
guys i installed linux on an external flash drive can you suggest any good course for ethical hacking because i am thinking of learning ethical hacking then go for cyber security to have a good base
free
i m litterly 16 so please
The first S in SSH is Secure
The first F in SSH is Friends :)
Comms are encrypted
i completed the free ones but i don't have money digitally to buy the annual subdscription
Bro did all the free ones
And don’t forget to check out the networks
1337
i started from the introduction then midway it said this room is for premium users
Yes, you can skip it
here's a bunch more free rooms
Just move onto the next free room on that path
i didn't know you can skip them
Just click on the next room
true hacker mindset 😉
thanks
Talked to the monkeys (my IT department) again. They still refuse to enable the use of hardware keys for the work microsoft account and force me to use the closed-source authenticator
The only place where I can use the key is the windows login...
really like the consistency.
everyone thank you i got dumb for a couple minutes turns out you can thanks
lmao
It's how I feel trying to get in 🤣🤣🤣🤣
That will be me after I'm gone from my current job.
I'm nearly out of money and still can't find a job 🤣
can anybody tell me how to find out the target in responder? I am in a network and responder grabs some SMB NTLM hashes with infos like
Client: xxxxxx
[SMB] NTLM-v2-HASH: xxxxxx
but I cannot see WHICH smb server should be reached. I want to pass the hash now but need to know on which server
responder won't tell you that, it can only tell you what authenticated to you
you need to figure out a target yourself by for example spraying the credential over the machines in the network or enumerating gpo's on the domain
literally me in 6 years
Boop yer nose


Any good resources to learn about AI?
if you are brand new, then TryHackMe is the right place. It is truthfully the best learning resource I have found for beginners
Please do not recruit here
where can i post
what are wanting to learn regarding AI
If it were an official job offer for a company, #jobs-board
Otherwise, not here unfortunately 🙂
okay thanks
Gave +1 Rep to @mossy river (current: #6 - 1217)
Just general knowledge
can someone assist me on a crackme using asm?
I may get some hate for this lol, but if you are wanting structured learning, Udemy has always been a decent resource for me. Outside of like Youtube videos and Google. But I am sure someone in this discord is going to have a better answer @steel aspen
is it for a ongoing ctf?
no mate, it's a website called crackmes i picked the easiest one and just don't get it at all
I recommend doing some guided rooms to learn the basics.
^^
crackmes difficulties are wild sometimes
is this for tryhackme?
yea
mate, i watched a few videos been learning asm and i thought "surely i can do a level 1 difficult"
bro it makes no sense
thank you, i'll have a look now
Gave +1 Rep to @worn thorn (current: #142 - 48)
you're welcome.
i can send you the crackme if you want guy even put 'easiest one i could make'
kinda bugged me i can't do it
naw I'm good.
no worries mate 😄

if you don't mind me asking where are the guided rooms?
you can search by type "walkthroughs" and keyword like reverse engineering
There are some benefits but I'd start free to get a hang of it first.
thanks i arleady found what i want
Gave +1 Rep to @carmine sedge (current: #2054 - 1)
You have 500+ free rooms to pick from so you have a lot to choose from.
I agree with Vedrfolnia, free is good to get the hang of it, but the premium is worth it in my opinion should you decide this platform is for you
bro this website is amazing
It indeed is
and the write ups are the explanation to that specific room?
Have you ever done RE or similar? there's some x86 architecture and assembly basics rooms on THM that will help tho
what is re? 😆 i'm that much of a noob mate
"Reverse Engineering"
you could say so yea.
erm, i did re to like do silly things like instead of take away health it adds health
I've done a few crackmes so i can help if you're stuck but you do need some assembly and architecture knowledge 😅
the writeup rooms are good, but luckily the community around THM is so large, you can always find very detailed writeup on medium
I have had to reference those more than I would like to admit when I get stuck lmao
may i ask, what did you do to learn it ?
everyone probably does tbf aha 😆
Yur
LiveOverflow's video on Binary Exploitation helped a lot for me, along with i already had some knowledge of C so assembly wasnt the biggest leap its just very annoying to read 
outside of that its just having good tools, i like iaito for static and gdb-gef for dynamic testing
could you explain the difference between static and dynamic testing please ? i know i could look it up but i learn a bit better if someone explains
guys when I grap NTLM hash with responder and it looks like this:
user::SOMETHING:1111111111111111:22222222222222222222222222222222:<VERY LONG STRING>
what is the NTLM hash? the 32-char long 22222 or the 16-char long 1111111? When I look at tutorials it sais that when I pass hases to impacket they want hashes like
hash1:hash2
and hash1 and hash2 look like the same length. but they arent in my case. I also see something like 0000000000000000000:222222222222222222
what exactly do I pass as hash now?
Annoying doesn't even begin to describe it.. in my opinion its mind numbing and I am absolutely awful at it
also, would linux or windows be the best system to use? or does it just depend on the ctf i'm attempting to do etc
i absolutely agree with you mate
iirc the 2's.
Windows host with both a Linux and Windows VM
i want to learn like cpp but it seems like for what i want to do , i need to learn asm but after 5 minutes of looking at it, just gives me a headache
Depends, sometimes its a linux binary, other times its a windows one having VMs of both is handy
As soon as I get to reverse engineering at any ctf, I go ahead and head over to medium because I know I am gonna need it
iirc?
mate these questions make so much sense idk why i don't think of them 🤣
If I recall correctly
static is just looking at the disassembled code as is, dynamic is looking at it while the program is "running" and going through it setting breakpoints to see what everything does etc.
should you always run in a vm to ensure you don't get anything or does tryhackme make sure there's nothing malicious?
so I do not pass something like 111111:22222222222 or 00000000000000:22222222222222222 but only the 22222222222222
like impacket-smbexec --hash 2222222222222222222222
ahhhh okay, so static is like ida and dynamic is like x64dbg/32 ?
Best practice is VM either way, THM should be safe untill you get the malware stuff etc. but yea just try to keep it to VMs 😅
other way around. Dynamic is like anyrun, static is dbg @undone sorrel
ahhh i understand, thank you ❤️
and, is there a limit to how many rooms i can join?
Nope.
Oh
guess i learned that wrong?
For what its worth, the people in this room are so much more knowledgeable than me, I start second guessing my own name lmao
Right now I'm currently in
Static analysis is a test of the internal structure of the application, rather than functional testing. Dynamic analysis adopts the opposite approach and is executed while a program is in operation.```
yea. Look at the definition of a ntlm hash. The 1's part is empty. I haven't seen one where it differed before.
bloody hell 🤣
ahhhh right okay
This one should be a good start:
https://tryhackme.com/r/room/x8664arch
mate, this discord is so welcoming also if i go anywhere else to explain my issues, i just get shutdown
yeah, anyrun, joesandbox are a couple of good ones for dynamic
will get reading, thank you a lot everyone
Gave +1 Rep to @scenic bobcat (current: #311 - 15)
This was one of the best Ghidra rooms, but it's private now for new members.
I'm loving the blue windows boxes we're getting these days.
And it's one from Arabel so it's going to be good.
appreciate that the sub/free release rate is balanced, (3 sub then 3 free then 3 sub etc)
batman begins
matrix
I wanted to see the new Bill & Ted, but it feels like Keanu forgot how to act as his character.
always a good one.
My mother wanted to take me to see it but we never got round to doing it
Defo can smell a DFIR path coming after all rooms are released
Going to watch matrixx first prolly
have fun.
Sure it will be streaming soon.
has anyone watched the new fallout show on prime video
It’s about the memory and the experience smh
You millennials and your tiktok netflix prime
Millennials 
I still have my Blockbuster card.
damn millennials
jesus
Pre 2k be like 
Ouch ): that comment made my knees hurt
Ayee new Alex Rider season out
me who has a dfir room laying in QA queue
👀

8k more users til 3 mil
Or atleast a capstone project eh @eternal roost 👀
3 mil will be this weekend
grrrr it is still there and annoying shadow
Guys, I need help! I have no idea why, but my kali machine, baremetal, updated and upgraded 2 days ago, now gives me an error like this:
Reading package lists...
E: Could not get lock /var/lib/apt/lists/lock. It is held by process 4362 (apt)
What should I do?
Is it safe to just kill process 4362?
sudo kill 4362
ps aux | grep apt
Check what's running.
If they won't work, you can remove the lock manually.
sudo rm /var/lib/apt/lists/lock
I just wanted to be sure it's safe...
I don't know what's running on the process.
This is a quick example on why it's bad to run Kali baremetal, you'll be doing this, alot
Yap, now I know to not do this again...
I will try killing and see what happens
It did not work...
I will shutitdown and try reboting...
Already?
Restart it. Typically the lock will clear when the software updater completes checking for updates in the background
Reboot should work
I just shuted it down for now, that's all I can do remotly for now. Once I get home again I'll try starting and see.
Thank for the help anyway
Yes, but this is in terms of pentesting I guess?
A Null, Fin or UDP scan are stealthy enough?
No, just as loud
Modern systems have detections for them
But its all up to the SOC if its actionable or not
Yeah, but in this case I am just learning
Moreover the complete beginner path
And I am training for SOC entry position so
It shouldn't matter in this case?
Yes, if you're just doing machines in TryHackMe
I'd assume a weird scan is more interesting than a slower TCP scan
So how do you do stealthy scanning then?
irl?
Go slowly enough that they forget you 😉
Though a proper Siem would still be able to alert

definitely but with a lot of firewall logs i might check for better IoCs like ssh logins, etc.
Or be a needle in a haystack
True
There are so many scans on the internet that you'll probably get lost in the noise
You could use decoys and silent maybe
Least until you actually do something
If you want to be stealthy you'll want to make your traffic look as normal as possible, but that's my opinion
Yeah ^
Hello, I am a beginner in cybersecurity and I am planning to subscribe to TryHackMe, but I am afraid of getting lost. Is it correct to start with the 'beginner path' first and then move on to the 'jr penetration tester,' considering that I am interested in pentesting?
Try to make it as identical as possible with regular packets
shouldn't a proxy/vpn should be enough to hide your traffic?
probably
It'll hide the origin in the immediate
depends on the network setup tbh
Well as a scrub I still don't know how to do that
Hide your traffic from what?
i started as a wee lad who blasted nmap -A on every machine tryhackme had
yeah that my point the proxy server's ip would be disblaed in the logs
from the server
That's not how proxies work?
Yeah, maybe only the ports that I would want and no others
But it says 'intermediate,' is it for people who have a good foundation, or did they write that to indicate that it might be complicated?
Wireshark became fun once I did the wireshark room though
Maybe I still don't undersatnd some things, but I guess I'll get the hang of it
Good that I do OneNote
you need some foundational knowledge before jumping into those paths.
Hey, in my honest opinion. I would take a look at free ones first. To get an idea on how i should proceed
You should be fine since it guides you as long as you know plenty about computers
starting beginner is better ?
You can jump to any path that you like, however don't get shocked that you don't understand anything or forget everything within a week.
starting beginner path is ok ?
But definitely, subscription is worth it
Do the easy rooms and gradually progress
well correct me if I'm wrong but proxies hide the ip origin shouldn't be enough to hide your traffic? with some severeal proxies?
#general message
Here's a recommended order of paths by shadow.
You can skip the ones that require subscription
I use 3 when trying to not get blocked
It would mask your IP, yes. But can be tracked by contacting the ISP.
Ok thanks you, but i didnt started jr penetration tester, i just started beginner path
Gave +1 Rep to @devout palm (current: #27 - 291)
guys..I hope there will be at least one person focusing on soc areas.
I have been focusing on offensive side for a few months and still I am not good in that but I want to try learn some from a defensive perspective and trying to SOC, i Found it interesting but at the same time it find it hard to learn so that it is more theory when compared to offensive(accrdng to me). so how could i get on with this guys and i really like bash scripting, i mean i just need a proper path to follow.
So there's no "hiding traffic"
But in reality, I don't know where to start. I just started the beginner path, but then I'm not sure what to do next. Do you have any paths to recommend to me to assimilate well?
The SOC paths are good
SOC is fun, unless you take care of the logs! ™️
What do you think I should start with?
that the point of proxy
hiding your traffic
Pre-Security Pathway
how in the world your isp can track it?
Ok before pre security pathway should i make beginner path ?
You -> ISP -> Proxy -> Server
You can see where it's going, you might not get to see what is sent.
Or is that VPN.
You can follow the list 🙂
Probably VPN.
Yeah
yeah I see now thanks!
Gave +1 Rep to @simple valve (current: #22 - 362)
VPN -> Encrypted packets
proxies
Proxy -> Not encrypted
Not always.
Generally speaking
proxies packets aren't encrypted right?
Depends what sort of VPN you're using.
Some of them add on https.
i have just started it, but was in a little bit of confusion there, do I need to go through all theory(obviously I am a lazy man), wish more practical lessons are there when compared to offensive. I guess I have to continue on the path.. just learning step by step.
Pretty much all Morden VPN protocols use some sort of encryption. Unless you are super old and using something like L2TP which doesn't provide encryption
@clever shard not an appropriate joke to make here
Yes, theory is good. It helps you understand why we do stuff.
@simple valve sometimes, I just need a push, thanks mate✌️
Gave +1 Rep to @simple valve (current: #22 - 363)
I mean, you can practice by
- Intercepting packets with Wireshark
- Building a home lab and setting up an EDR
- Messing with SIEMs
gotcha..!!!
It's actually fun, when you learn offensive security to defend
Defensive security to attack
Theory serves as a guide for practical application. Keep up with the study (:
There's theory in general cyber security, not only defensive side
thanks for all the say guys, got me motivated✌️ time to go, have a great one everyone, peace..
After a 27 year career in IT Operations and Cyber security I can validate this.
sorry but how is it inappropriate? it doesn't seem to go against the #rules but idk
As a defender you should know how an attacker works, and as an attacker you should know how you can be detected or investigated.
It's illegal, so it is against the rules
Do pre-security then complete beginner, even if you have experience.
how I said to stay anonymous. I didn't say to do illegal stuff and for me anonymity isn't always related to bad/harmfull actions.
but still you right
What’s up party people
Using your neighbor's wifi? Yeah that's unauthorized access. Textbook illegal.
with peremission?
how to see how many points I have earned
and their conest?
Dashboard
Nah mate. Nice try.
Don't make those sorts of jokes here.
Thank you soo much
Gave +1 Rep to @devout palm (current: #27 - 292)
my level isn't updating on my profile anyone knows why
It's a known issue. Staff is going to handle it
Thank you bro , I thought it's a issue of mine
Sox4-5 proxies are encrypted as are https proxies. Http proxies are clear text.
@clever shard check out proxychains tool
who need to buy it while you can get it for free
wdym free proxies?
you can find lists of free open proxies
💀 if something is free then you're the product
if explain your need I could provide some
they keep logs and they're willing to give it to anyone with power
yeah but tor proxy solutions could solve much of that
🍿 hi
Hai
wake up lil bud
there are ways to enumerate people over TOR
How's the Heap? 🙂
that's true , but you can configure with strict security
Great. What about yourself?
Just working. Stopped and looked at chat. lol
My point is nothing is foolproof. it comes down to a series of practices and just like defending security is a layered approach even when you're attacking or trying to remain private 😉
@sleek viperwake up lil bud tor isn't that secure
Breaks are nice
pretty sure I just said you could be enumerated over Tor
lol
but it gives you another layer of obfuscation
About to go out and look at the ducks in the lake. 🙂 🦆
I guess anonymity is a illusion
Actually for learning , it's not a big deal , anonymity need when you need to play the evil 
What are you aiming to accomplish? You don't require paranoid anonymity unless you're a criminal.
telling people you're committing a federal crime in multiple countries and making jokes about hacking your neighbor's Wi-Fi is less secure 😉
I think that this is a fallacy that privacy should be considered evil or somehow shady
Fun fun
i would like you to tag me in the text I said anything related to that

lol
I'm not trying to accomplish anything illegal
I agree with you , anyone knows what's protocols actual structure or core of networking , all we know are what they have tought us . IETF and other organizations know actually what's going on
And yes, anonymity is an illusion depending on where your location is, how you're hiding your traffic and what country you reside in
- I'm not trying to accomplish a such thing
depending on what you do with that anonymity just remember it's going to come down to how many resources someone is willing to spend to locate you or investigate your activity
it just scratched that part of my mind could anonymity be a thing?
when giant agencies needed , anonymity is nothing
another fallacy that people who seek privacy are criminals. many times they are dissidents or they are trying to avoid the reach of over-aggressive or dangerous government entities
Tor was developed by the US Navy to protect a dissidence in many countries, freedom of speech does not exist
dissdents
This discord server is not political 🙂 please keep it out of here
thinking outside the box is always political
but you're entitled to your own opinion
And literally saying that people who seek privacy are criminals is a political statement and it's based on an opinion
All I know is we all are puppets who work with some CLI and GUI tools with knowledge of RFC documentation , DOD know what's the truth is .
absolutely! and this comes down to what exactly you're doing and how many resources someone is willing to spend to investigate your activity or location
This conversation needs to stop or everyone involved will be temporarily muted. This is your final warning.
okay, I will abide by your terms and agreements. moderator
I'm done , take it easy we all wonder what is behind this thing call network , no one knows
finnaly someone took action
not trying to cause problems, just trying to get people to think about their activity
lol
So, what did you folks learn today?
how to drink water the proper way
no free speeches in this room , and stay away from reality
Jeez, i meant about cyber security
really?
the code is real lmao the statement less
Yeah, lets not say actually wrong things.
Keep in mind this discord is intended to be a good place for security and IT learners to start out
VPN , even GForce Now servers blocked me when I connected using nord VPN 😂😂
Code is invalid
Also removed the code, because that's technically self-promotion.
damn
what have been violated
Don't worry about it, keep doing your thing
for kernel exploits?
my level isn't updating can you take a look please
Nice! I've been doing some challenges on TryHackMe lately
use code genericYoutube69420 at checkout
I don't have anything to do with that. Not a dev for the bot, and not a THM employee.
Also literally 1984
This is my opinion, and some here have the same view. Stay away from Nord, move to like ProtonVPN, IVPN, or Mullvad VPN.
Ohh I thought as a moderator you can help me with that
Sorry, not a thing most of the mods have control over. You can try to re-verify with the bot, but it should auto update daily.
I personally use Mullvad
OK
heard Mullvad having disaccounts
is that true?
All VPN services can dump your traffic. you should host your own VPN at a friendly VPS provider of your choice. wire garden open VPN are extremely easy to set up.
Moderators just moderate discord, or some do reddit.
If you see "THM Staff" tag, they work for THM, in different departments. But most will tell you to email support.
I've never seen a mullvad sale; that doesn't mean they haven't existed or won't exist, but the price has been basically the same since the service started
I don't like Nord myself, I use ProtonVPN, used Mull in the past
Forget about VPN what about DPN
I use Proton here as well
B)
fellow proton users 
Just rent a vps and setup open vpn, I run a ton of vpns all over the world, Don't use third-party services that are managing your endpoint. that's bad advice
I started replacing all my vpns with wire guard recently and I like it better
Dude spends more money on VPS than on his bill
"My Lord"
"Proton User"
heh
I feel if a 3 letter agency is going to ask questions my VPN provider is a lot safer then my VPS provider.
Way cheaper than paying for VPN service
That's why you don't log on your own VPS where you control the end point
.... Wireguard is a VPN product. That's the literal definition of what Wireguard does.
It's not a provider. it's a product
Just build your own ISP... done.
You can host it yourself
Yeah, building your own VPN on a $3 VPS is way easier than hosting your own provider
but go ahead. just keep paying third parties to host your VPN endpoint. have fun
I will and I do
well, if you don't care about your own privacy, that's your prerogative. what can I say? I'm just offering advice to people who care about that kind of thing
use your neighbors /s
That's one way of building your own ISP LOL
For me just masking my IP and DNS is good enough
Eh, wireguard is nice, but I have no illusions about data privacy with that
Decentralized VPN(DPN)
most of those vpn services are probably using wire guard or openvpn
VPS provider logging connections
You're just paying them for the endpoint
100%
And the hosting for the server
your basic lol
oi
You know discord isn't E2EE, right?
I'm not saying anything that requires anonymity
just trying to give the masses better advice
And if you want to work in security, you should probably learn to run your own VPN rather than use a third-party service
It's not that hard
Weren't you just asked to be nice?
I'd love to know where they got the pricing of $150 per year for a VPN 
I guess it's just me then huh?
where would this annonymous conversation leads 

nord 
Anything with web 3.0 is a big nope from me
Lifetime fee as well is a bit sus to me
Yeah that is sus
I have a wireguard going to my home network, works well enough for hotel wifi
how about IPV6 only decentralized , and heavily secured network device , that's why I love deeper.network
I'm doing the same thing and I have my network split into three segments and my employ ees also use my wire guard that's hosted at my home for business purposes. we have a whole test Network.
It's especially great when I travel outside the country and I want to watch my regular media
That last part might be against local regulations, fyi
When at Defcon, I just rocked Proton with a kill switch, even on data.
My ISP is cool with it
anyone had any experience with vmware running like complete garbage unless ran as an admin? got a new laptop and done the normal disabling of hyper-v and device gaurd but it still runs like shit unless run under admin
false
vmware has some very complicated licensing and some very serious hardware requirements
try using proxmox at home or just virtualbox
ups missclicked
Vmware has worked great for me
I thought they ended VMware player
I have ran Vmware for years and the laptop is brand new with 32gb ram, ultra 9 and a 4080 that's not the problem
I use VMware in the Enterprise
I also have a valid license for pro
How much resources have you allocated the VM?
okay, well if you have a license that's different and you're meeting all the regular minimum requirements?
yes
maybe try using a tool like "latencymon" if your on Windows
is it the hypervisor itself that's running slow or is it your VMS??
I love my recruiter. Read my email wrong, and he writes back to me: takes another sip of coffee
When recruiters can joke, I'm all for it.
I think your hard drive, bus and memory speeds are going to come into play here as well.
The advent of quantum computing is poised to revolutionize our information infrastructure due to its potential for vastly superior security capabilities. Even now, the NSA has acknowledged the future risks associated with quantum technology. It’s conceivable that a quantum network could mitigate some of these challenges. However, looking back from that advanced standpoint, our current conversations might seem quite quaint! 😄 LOL
Yeah, quantum computing is going to turn this industry on its head
VM stuff is on in bios?
It's going to make things much more secure and it's going to introduce a whole new level of threats, especially when it comes to cracking encryption
Vmware workstation Pro has been fantastic for me.
I use latest one with factory default settings , no issues , what is the OS
Lemme put my help desk glasses on
You have to enable a setting in BIOS if you want to be able to run a hypervisor on most modern machines
I'll have to try it. I do like VMware
Workstation Pro is amaizing
windows on a brand new Asus Zephruys. Hardware should blow away my old laptop that runs it fine. Vmware is bogging down the whole system as soon as I start it
apparently they may be some issues with 17.5
could also be the drives you're using
Hyper-V off? Virtual Machine Platform on?
I've had horrible latency from using cheap nvme drives
yes
first thing I did
and virtualization security is off
Processor isn't sufficient for both OS or RAM isn't sufficient , nothing to worry about a bug .
How much resource did you give the VM? Enough cores and ram? Is it running off an HDD?
try that program latencymon
You turned the memory something protection off?
Can't remember the exact name
running off SSD with 4 cores and 8gb of ram for windows host
it would be great if we get visual screenshot of specs of your pc
What is the brand and type of SSD? what is the bus speed??
2.5 or m.2?
it's an intel Ultra 9 it's definitely sufficient
m.2
sufficient for an end user maybe not for a hypervisor, depending on the load you're putting on it
it's definitely sufficient for a vm lol
But the memory protection crap from windows is off?
I say crap, for this instance...
yeah
well there is plenty of problems here too as the cheap vps:s generally mean the vps provider has full access to reading everything going on in the vm
I mean that's kind of a blanket statement. it depends on how many resources you have are located to the VM in what you're trying to do with it. what types of calculations or software you're running.
depends on what the hypervisor is
maybe your m.2 had been corupted , once it happened to me , when I work on something large it is struck in
And that is a very important point to consider when renting any kind of service from anywhere.
possibly. It's brand new so I would hope not but I could alwys wipe it and see
yuup yuup
specs of pc and windows version please
together with knowing that email as a protocol is insecure in EVERY way
I had an Alienware r3 13, I was getting all kinds of system side latency and it turned out to be my Toshiba M2 drive such garbage. I replaced it with a Samsung Evo+ It was a game changer
It's a windows 11 pro with 32gb rams, a 1tb m.2, and intel Ultra 9 with a 4080. Hardware is more then adequate
Wtf is that app yuou can test disk speed with
I keep telling that to people in the Enterprise.....
CrystalDiskMark
Run that, see what speeds you're getting
Should be up in 7k with gen 4x4
That's a good call
Gen 3x4 would be 3k
Can you give us any indication what type of load you're running?
laughs in no crystaldiskmark for linux
is it one of your VMS is being slow or the whole platform??
did you cheked your PC for malware or intrution
laughs at Shadow's misfortune
This is where latencymon might come into play
shadow can find benchmarking tools for linux if they need them but so far it is not a necessity
It's not always easy with the out of the box tools to see what's taking up resources on Windows. might need a couple extra utilities to drill a little bit deeper
Time for food. Left overs, or should I buy something?


