#general

1 messages · Page 116 of 1

molten sky
#

not great

gritty fern
#

Actually you could compress the trash into a black hole at which point hawking radiation will shoot the matter back out as a single element

restive thorn
#

respect @gritty fern

molten sky
#

we actually do have like a hot-tub sized metal pit out by the cabin that gets some roarin burns going during deer week

gritty fern
molten sky
#

pallets on pallets on pallets make the garbage no more

#

i try not to breathe it too much tho

restive thorn
#

thanks @gritty fern

twin ridgeBOT
#

Gave +1 Rep to @gritty fern (current: #826 - 4)

gritty fern
#

Guys we should hash password hashes

crude stump
#

Hm

gritty fern
#

They would be like 100s of times more secure right?

molten sky
gritty fern
#

Tell me what

molten sky
#

nobody tell em that some algos already do that

gritty fern
#

So do it three times

restive thorn
#

i just exploited XXE in less than a minute for a job interview box n im so happy i have 20 mins left XD

molten sky
#

nobody tell em that some algos do it more than three times

gritty fern
#

For things like checking a password you dont need speed

restive thorn
#

20 mins ...final question JWT shit...can it be done XD

#

feels possible

molten sky
gritty fern
molten sky
#

sha-2 apparently does either 64 or 80 rounds

gritty fern
#

i*

#

What about 256

molten sky
gritty fern
#

Alright im making SHA-2048 it runs it through 10 trillion times then runs it through 256 then 128 and so on until 1

molten sky
#

you kid but that's actually effectiveish unless the algo itself is broken

#

all about making things slower

gritty fern
#

Ill be dead by the time it finishes prolly lmao

#

Joking itd probably take atleast a year though

molten sky
#

adding different algos can add weakpoints in some ways tho

gritty fern
molten sky
#

depends on the situation but say one algo is more prone to collisions than another

gritty fern
#

But thats the whole point of using all of them

#

Just makes it like 5 billion times harder to crack

molten sky
#

man i need sleep

gritty fern
#

Sleep then

#

Its like 11:30 for you?

gritty fern
#

Go to sleep my guy

#

I should sleep actually

#

I have ACT practice testing tmrw

molten sky
#

lol tests

gritty fern
#

I hate tests

molten sky
#

lol x2 ACT

gritty fern
#

question

molten sky
#

answer

gritty fern
#

my user is an actual memory adress right?

#

Cuz i dont fully understand memory addresses like idk if theres range limits or such

molten sky
#

man i haven't done anything with memory since uni, outside of the odd 15 minute BOF session

gritty fern
#

Ok lol

molten sky
#

couldn't tell ya

gritty fern
#

Well nighty night

#

sleep well everyone

molten sky
#

good timing cause discord just crashed on my desktop

#

as usual

#

fuckin discord

gritty fern
#

One last thing before sleep

#

(relevant cuz 0day)

tawny widget
#

God morning

brisk pier
#

Morning

buoyant tree
chilly veldt
#

You know you're good when you win a CTF with only 1 point

buoyant tree
chilly veldt
chilly veldt
#

Thanks, it was a meme challenge that did it for us

buoyant tree
#

meme challenge?

chilly veldt
#

Yeah, they had a meme challenge called guessctf, aka guess the solutions, aka figure out 31 different challenges in 1 challenge, aka figure out the password to 31 zip files

shadow sundial
#

beginner bug bounty hunter here, what are some places where I can find the latest news and vulnerabilities?

charred forum
#

eid mubarek

chilly veldt
#

eid mubarak!

worn thorn
near hawk
#

Exploit-db you can find CVEs with the PoC

hearty gull
#

is there a room for learning reverse engineering with ghidra or some other tools?

sick lance
#

Search Ghidra.

chilly veldt
#

I just fixed my script!

#

this looks easy to finish now

brisk tree
#

hey

shadow sundial
twin ridgeBOT
#

Gave +1 Rep to @near hawk (current: #67 - 97)

twin ridgeBOT
#

Gave 1 Rep to .scrubz. (current: #1 - 2149)

rapid merlin
#

What's the best way to transfer information from short term memory to long term memory?

lean cove
#

somebody had a problem with the pyramid of pain practical not working?

sick lance
lean cove
#

ok thanks

fickle token
#

Hi all. I'm trying to find info on Google Cloud security vs Azure security in terms of cloud tooling, learning material, and general attitude toward security.

Why I'm interested in this: I've noticed Microsoft catching some heat lately, and I'm weighing whether I should pursue more certifications for GCP or Azure. I'm particularly interested in specializing in a platform that is suitable for small businesses and new startups. Google seems to be very proactive and engaged with security, and I have been impressed with their learning material, so I am leaning that way.

hearty gull
neon river
#

hello everyone

#

is it just me or are there a lot more bots in the VirusTotal comments/community section than there were say 3-4 years ago

chilly veldt
#

it's not really bots

#

it's more like automation due to detection via honeypots or something alike

neon river
#

wish there was a way to filter them lol

rapid merlin
#

How is everyone

sick lance
#

Ah, set up my new kali box and forgot to get the wallpaper from the attackbox.

brisk tree
fallen lion
#

yo hi

shell nova
#

Zzz

gilded stump
#

Hi

sick lance
left kindle
#

Hi

fallen lion
#

i want to dm TryHackMe admins

left kindle
#

Where can I use Discord token?

sick lance
gilded stump
shell nova
#

How the hell does it take 2 hours for a mechanic to change 4 wheels?

sharp citrusBOT
fallen lion
#

i built a machine and i want to know how to upload a room and i want to know if they pay for room creators or not

sick lance
shell nova
fallen lion
sharp citrusBOT
sick lance
shell nova
#

Enjoy

fallen lion
#

i wanna DM the admin to see the attack path is it good or not

shell nova
#

Don't need an admin for that

sick lance
#

QA will decide that when they review your room 🙂

shell nova
#

The room will go through several rounds of internal and UAT testing

shell nova
fallen lion
twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #11 - 564)

shell nova
#

Oh gods WSL just updated and it brutally nuked all my sessions >.<

sick lance
#

RIP.

shell nova
#

Yeah considering that ansible was provisioning a vm

#

Hooray for idempotency?

chilly veldt
#

gotta love fixing an issue and then finding a whole new one psyDuck

brisk tree
#

Damn ahaha

chilly veldt
#

oop

near hawk
#

That’s pretty good pay

brisk tree
#

Ot is

#

It

shut hawk
#

Ooo

sick lance
#

Incase you didn't see it.

brisk tree
#

I saw

#

That could mean anything. Some have you meet up like 1 a month or could be once or twice a week

#

Wish they would specify

sick lance
#

"How was your commute"

"It was ok, no traffic in the sky"

brisk tree
#

Ahahahahaha

#

Talking about flying. Dubai will soon have air taxis. So excited

plush sierra
#

Hello

brisk tree
#

Imaging flying to work in a flying taxi 🤣

shut hawk
#

you mean a plane?

brisk tree
#

No a flying car

sick lance
rapid merlin
brisk tree
plush sierra
#

...
Hello sudoeurs teams

sick lance
#

Dropped off at work by drone.

brisk tree
#

Ahaha would be so fun

rapid merlin
brisk tree
rapid merlin
brisk tree
brisk tree
rapid merlin
brisk tree
#

No this is my first lot of experience in it

sick lance
#

I just finished my group report for Pentest, we're going to over it once or twice until we hand it in.]

brisk tree
rapid merlin
brisk tree
#

A few companies in India are doing remote pen testing internships

sick lance
#

@steel aspen did you get your a new kali box set up?

#

This is Gnome, you'll want that.

boreal gull
#

vmware vs virtualbox for windows

boreal gull
near hawk
#

Hyper V

boreal gull
#

but ty

#

i'll check out hyper v

near hawk
#

I’ve always found it the most stable imo

sick lance
rapid merlin
brisk tree
boreal gull
brisk tree
brisk tree
sick lance
#

all my malware stuff is in vmware with windows.

rapid merlin
brisk tree
#

thats giid

#

good

rapid merlin
#

Just wish I had a teacher bc online and videos get me lost if I’m not dead focus on it, like eyes wide and glued to the screen XD it also helps if I have questions in that instance

boreal gull
chilly veldt
#

all my vms are also in vmware

#

I hated virtualbox when I worked with it and never went back

#

qemu or vmware

hollow pivot
chilly veldt
#

and how messy it was in total

#

(mind you, this was several years ago)

near hawk
#

I started off with virtualbox then got annoyed at, went to vmware but for some reason my CPU in my kali kept spiking and now moved to hyper-v everything smooth

rapid merlin
#

Did anyone get interested in hacking bc of anime? Just curious

hollow pivot
chilly veldt
boreal gull
chilly veldt
#

me too

#

ngl

rapid merlin
#

Which one was it

mossy river
near hawk
#

Good movie, had to watch that like 4 times in film studies

rapid merlin
#

Never seen it yet

#

Might watch it later tonight

bold dawn
#

i like star wars

#

irrelevant, but still good

brisk tree
#

Jeez this is going to cause an uproar

mossy river
vagrant sonnet
#

Yooo which kali linux should i download theres like 8 of them

gritty fern
#

VM or booting

vagrant sonnet
#

Hackin

vagrant sonnet
#

Sorry I'm completely new...

gritty fern
#

Lol ok you need to watch a YT video on USB booting and virtual machines first

vagrant sonnet
#

oh

#

whats the difference

gritty fern
#

And from there you can decide which kali to download

gritty fern
#

Both have ups and downs

chilly veldt
#

VM doesn't reset everytime?

#

then you have a broken vm at least

jaunty prairie
vagrant sonnet
#

whats vm

chilly veldt
#

virtual machine

gritty fern
#

I dont think i run live boot but maybe ig

vagrant sonnet
#

Sorry, I could be asking really dumb questions

#

But we all were new to this stuff once

jaunty prairie
gritty fern
chilly veldt
vagrant sonnet
#

I think that will have many cons, leme search it up rq

chilly veldt
#

not that many cons

jaunty prairie
#

depends on your hardware.

chilly veldt
#

most servers today is virtualised

vagrant sonnet
#

I don't mind whichever one, as long as my pc is safe and I should be able to play video games on good graphics like the way I do rn 😭

jaunty prairie
#

then you definitely want a VM.

vagrant sonnet
#

Oh okay

#

Whats the othero ne

gritty fern
#

Dual booting

vagrant sonnet
#

What's the other one? Going to research bout it.

gritty fern
#

way harder to set up

vagrant sonnet
#

Thanks.

gritty fern
#

But i prefer it personally

vagrant sonnet
#

data loss and glitches are the cons of dual booting

#

yeah ill stick to the first one, VM.

gritty fern
#

data loss?

vagrant sonnet
#

Why cant i attach dam images

jaunty prairie
#

I have a dedicated laptop that runs kali, but I only pull it out when I am pen-testing wifi or using some other kind of peripheral USB device

gritty fern
#

with / verify no space

vagrant sonnet
#

I've...

sharp citrusBOT
vagrant sonnet
#

yay done

#

thaks!

#

thanks!

jaunty prairie
#

so your best bet IMO is to download oracle virtual box, and the Kali virtual box appliance

gritty fern
#

yep

gritty fern
vagrant sonnet
#

Okay, now which one...

gritty fern
#

Yeah there should be a VM one specifically

vagrant sonnet
#

thats what that guy suggests as well

jaunty prairie
#

^^ yes david bombal has great content

gritty fern
#

David is a great source

vagrant sonnet
#

okay

vagrant sonnet
#

i cant seem to find it

jaunty prairie
#

david bombal
network chuck
rona kahlil
john hammond

will all teach great stuff...many others even, but those are my personal fav

vagrant sonnet
#

btw which one here is virtual box

shut hawk
#

None of them

vagrant sonnet
#

Oh

#

So where do I download it?

shut hawk
vagrant sonnet
#

ohhhh

shut hawk
vagrant sonnet
#

Now which one

vagrant sonnet
#

but didnt the other 2 ppl said "VM"

shut hawk
#

VM is an acronym for "Virtual Machine"

vagrant sonnet
#

dam how large is this file gonna take a while....

vagrant sonnet
sick lance
shut hawk
#

It's a whole operating system, it's fairly large

shut hawk
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #1 - 2150)

vagrant sonnet
#

Ay so you guys must be some professionals of hacking

#

Prob mastered hacking by now

shut hawk
vagrant sonnet
shut hawk
#

Virtual Box is within the Virtual Machine category

vagrant sonnet
#

oh alright

jaunty prairie
vagrant sonnet
#

oh

#

lol

halcyon mantle
#

do u guys have this error too ?

"Wed Apr 10 13:52:05 2024 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=425397202556807641543660048237946304772097879576
Wed Apr 10 13:52:05 2024 Sent fatal SSL alert: unknown CA
Wed Apr 10 13:52:05 2024 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
Wed Apr 10 13:52:05 2024 TLS_ERROR: BIO read tls_read_plaintext error
Wed Apr 10 13:52:05 2024 TLS Error: TLS object -> incoming plaintext read error
Wed Apr 10 13:52:05 2024 TLS Error: TLS handshake failed"

vagrant sonnet
#

Joined all these servers around 30 minutes ago, found this one the most helpful tbh.

#

Ay that flipper zero and usb killer gadgets are expensive

jaunty prairie
#

those are just toys for fun IMO. toys to screw around with, in the bar with friends. "hey chuck, if i can change the TV channel you gotta buy me a beer"

sick lance
jaunty prairie
rapid merlin
#

https://null-byte.wonderhowto.com/how-to/hack-wi-fi-cracking-wpa2-psk-passwords-with-cowpatty-0148423/

In step 6, what is the reason of mentioned the SSID!!
In bruteforce, We only need the hash, is not it!!
Even when searching, I did not understand what the purpose was
Isn't the hash is the hash of the password? So what does the SSID have to do with the hash of the password?

Why we mentioned SSID, why we just dump the handshake file! And start the bruteforce.
Like most tutorials on Internet. this is my first time I see someone mentioned the SSID on bruteforce, So what mentioned SSID change?

Using for example airgeddon or aircrack-ng, we don't need the SSID to found the plaintext password , We just need the handshake file, isn't?

Isn't the process of the WPA bruteforce is trying to find the plaintext of the WPA hash password, by Converting a word to a hash and comparing it to the WPA hash until we find that match it, So why we need the SSID!! 🤷‍♂️

WonderHowTo

Welcome, my hacker novitiates! As part of my series on hacking Wi-Fi, I want to demonstrate another excellent piece of hacking software for cracking WPA2-PSK passwords. In my last post, we cracked WPA2 using aircrack-ng. In this tutorial, we'll use a piece of software developed by wireless security researcher Joshua Wright called cowpatty (often...

sick lance
rapid merlin
#

So what SSID mentioned change on the process!

worn thorn
#

think about it. What is a SSID? That will answer your question.

vagrant sonnet
#

YO

#

It DOwnloadeED

#

do i click on the folder

worn thorn
vagrant sonnet
worn thorn
sick lance
chilly veldt
#

what*

vagrant sonnet
worn thorn
#

I had three seperate people ask me to playtest for them and 3 out of 3 were malware.

worn thorn
rapid merlin
sick lance
worn thorn
#

so you need to have the ssid of it.

#

which it happily screams if not suppressed.

chilly veldt
#

when you want to program but you can't cause you have to talk to a person about what they want this to do, but the person is unavailable for a talk

chilly veldt
#

I have 3 different ways to solve this issue, but I need to hear what my colleague wants it to do, and that is different for each 3 solutions

#

so I am waiting for them to be able to have a small call so I can talk with them about the solutions and ask what their intent is with this program

vagrant sonnet
worn thorn
#

the good old chain of command... Talking to 6 people to answer a simple question

rapid merlin
worn thorn
rapid merlin
worn thorn
#

maybe they didn't mentioned it before and just slid it in 🤷‍♀️

#

Some tutorials aren't really that great.

rapid merlin
chilly veldt
#

cause it's a seed

#

read the text

rapid merlin
worn thorn
#

with context it makes more sense

rapid merlin
worn thorn
#

also typo in the article kekw

rapid merlin
worn thorn
#

haven't really lookes at nullbytes for a long time but they were a reason for me to start the journey.

chilly veldt
worn thorn
#

It's time to dust kali off and not hibernate again. Hope I still remenber how to linux ...

rapid merlin
# chilly veldt google 😛

I say "Even when searching i did not understand what the purpose was", Why did i come here if i found the answer of my question on google! 🙂

sick lance
rapid merlin
rapid merlin
hollow pivot
# rapid merlin Previously I was, Not Now on most case lets say

If you google something and don't understand it, that is fine, it happens to everyone. But then you need to be more specific with your question:

" I read about X in this article, and when the author talks about Y, I don't understand what he means by Z. I did some more research, and I am having trouble connecting the dots between Y and Z. My understanding is that Y and Z... Is that correct?"

worn thorn
chilly veldt
#

SSID is the name of a wifi which stands for Service Set Identifier

fleet finch
#

guys can anybody tell me if it is necessary to add spaces to SQL injections? I see that many times I need the trailing space, therefore it is not enough to make something like

admin' or 1=1--

but I need

admin' or 1=1-- -

but I see in wordlists like wfuzz that I use with burp that there is no trailing space... is this bad?

shell nova
#

Depends on the backend usually

#

You'll probably want the semicolon as well. Also the -- - formulation includes the space after the comment token

fleet finch
shell nova
#

Could be

#

The space is technically not necessary

simple valve
#

Depends also on how wfuzz sends it. Could be url encoded. So you see -- but its actually sending --%20

fleet finch
# shell nova The space is technically not necessary

i think the space is technically necessary because i had many cases where inject is not working because mysql really wants a space. for example
select * from users; --comment without space
select * from users; -- comment with space

the comment without space will give sql error because "--" NEED a space afterwards so the injection will also fail

simple valve
#

Off the top of my head, I don't know other RDBMS that requires a whitespace.

fleet finch
#

so basically I dont break anything if I replace all "--" with "-- -" in the wordlists, because mysql needs it and others just ignore the additional "-"

simple valve
#

Yeah. You can also use --+ , --%20 , -- x, etc.

jagged moon
#

-- - is also important

#

With trailing space, as hydra mentioned

rapid merlin
rapid merlin
fleet finch
# jagged moon `-- - ` is also important

why? if I have "-- - " with trailing space the single "-" after the double "--" is a comment and ignored anyways... so whats the difference in having a comment that is ignored by the interpreter having additional space?

jagged moon
#

When how web app processes user input is no less important

#

It's all added to protect the trailing space, basically

chilly veldt
jagged moon
#

Bet it's used in some obscure dbms too

cosmic pendant
#

😄

devout palm
#

Eid mubarak

rapid merlin
delicate reef
#

hey yall anye1 here knows any good mic for like under 50 bucks?

#

40$ 50?

#

i know theres solocast hyperx

rapid merlin
delicate reef
#

eid mubakar is for muslims bro

rapid merlin
delicate reef
#

eid mubakar bro

worn thorn
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @delicate reef (current: #1024 - 3)

chilly veldt
rapid merlin
worn thorn
#

There are two sides of this. Knowing how a program works and just using it without thinking about what it does.

#

You can always check the docs of it to learn more.

chilly veldt
brisk tree
#

To relatable 🤣

worn thorn
#

damn

tropic stratus
#

Since it seems on a SSH connection it sends every letter you type even before you hit enter to execute the command, does that mean blueteam gets to see my awful typing skills? 🤣

#

Like, having to backspace because I typed a flag wrong, or used the wrong capitalization, etc

astral nova
#

guys i installed linux on an external flash drive can you suggest any good course for ethical hacking because i am thinking of learning ethical hacking then go for cyber security to have a good base

#

free

mossy river
astral nova
#

i m litterly 16 so please

patent hinge
#

The first F in SSH is Friends :)

jagged moon
#

Comms are encrypted

astral nova
mossy river
#

There are tons of free rooms

#

Like 80% of the platform is free

patent hinge
#

Bro did all the free ones

mossy river
#

And don’t forget to check out the networks

rapid merlin
#

now

patent hinge
#

1337

astral nova
#

i started from the introduction then midway it said this room is for premium users

tropic stratus
#

here's a bunch more free rooms

mossy river
#

Just move onto the next free room on that path

patent hinge
astral nova
#

i didn't know you can skip them

mossy river
#

Just click on the next room

patent hinge
#

true hacker mindset 😉

rapid merlin
#

bypassing the system!

#

1337

astral nova
#

thanks

worn thorn
#

Talked to the monkeys (my IT department) again. They still refuse to enable the use of hardware keys for the work microsoft account and force me to use the closed-source authenticator kekw The only place where I can use the key is the windows login...

worn thorn
#

really like the consistency.

astral nova
#

everyone thank you i got dumb for a couple minutes turns out you can thanks

rapid merlin
devout palm
brisk tree
worn thorn
#

That will be me after I'm gone from my current job.

brisk tree
#

I'm nearly out of money and still can't find a job 🤣

fleet finch
#

can anybody tell me how to find out the target in responder? I am in a network and responder grabs some SMB NTLM hashes with infos like
Client: xxxxxx
[SMB] NTLM-v2-HASH: xxxxxx

but I cannot see WHICH smb server should be reached. I want to pass the hash now but need to know on which server

umbral kiln
devout palm
umbral kiln
jagged moon
steel aspen
#

Any good resources to learn about AI?

carmine sedge
mossy river
#

Please do not recruit here

pallid void
carmine sedge
mossy river
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1217)

steel aspen
undone sorrel
#

can someone assist me on a crackme using asm?

carmine sedge
#

I may get some hate for this lol, but if you are wanting structured learning, Udemy has always been a decent resource for me. Outside of like Youtube videos and Google. But I am sure someone in this discord is going to have a better answer @steel aspen

worn thorn
undone sorrel
worn thorn
#

I recommend doing some guided rooms to learn the basics.

warm bear
#

^^

worn thorn
#

crackmes difficulties are wild sometimes

undone sorrel
worn thorn
#

yea

undone sorrel
#

bro it makes no sense

undone sorrel
twin ridgeBOT
#

Gave +1 Rep to @worn thorn (current: #142 - 48)

worn thorn
#

you're welcome.

undone sorrel
#

i can send you the crackme if you want guy even put 'easiest one i could make'

#

kinda bugged me i can't do it

worn thorn
#

naw I'm good.

undone sorrel
#

no worries mate 😄

worn thorn
undone sorrel
#

if you don't mind me asking where are the guided rooms?

worn thorn
#

you can search by type "walkthroughs" and keyword like reverse engineering

undone sorrel
#

mate this is amazing this website

#

would you say it's a benefit to go premium?

worn thorn
#

There are some benefits but I'd start free to get a hang of it first.

astral nova
twin ridgeBOT
#

Gave +1 Rep to @carmine sedge (current: #2054 - 1)

worn thorn
#

You have 500+ free rooms to pick from so you have a lot to choose from.

carmine sedge
#

I agree with Vedrfolnia, free is good to get the hang of it, but the premium is worth it in my opinion should you decide this platform is for you

undone sorrel
worn thorn
#

It indeed is

undone sorrel
#

and the write ups are the explanation to that specific room?

scenic bobcat
undone sorrel
scenic bobcat
#

"Reverse Engineering"

worn thorn
undone sorrel
#

erm, i did re to like do silly things like instead of take away health it adds health

scenic bobcat
#

I've done a few crackmes so i can help if you're stuck but you do need some assembly and architecture knowledge 😅

carmine sedge
#

the writeup rooms are good, but luckily the community around THM is so large, you can always find very detailed writeup on medium

#

I have had to reference those more than I would like to admit when I get stuck lmao

undone sorrel
undone sorrel
crude stump
#

Yur

scenic bobcat
# undone sorrel may i ask, what did you do to learn it ?

LiveOverflow's video on Binary Exploitation helped a lot for me, along with i already had some knowledge of C so assembly wasnt the biggest leap its just very annoying to read hehe
outside of that its just having good tools, i like iaito for static and gdb-gef for dynamic testing

undone sorrel
fleet finch
#

guys when I grap NTLM hash with responder and it looks like this:

user::SOMETHING:1111111111111111:22222222222222222222222222222222:<VERY LONG STRING>

what is the NTLM hash? the 32-char long 22222 or the 16-char long 1111111? When I look at tutorials it sais that when I pass hases to impacket they want hashes like
hash1:hash2
and hash1 and hash2 look like the same length. but they arent in my case. I also see something like 0000000000000000000:222222222222222222

what exactly do I pass as hash now?

carmine sedge
undone sorrel
#

also, would linux or windows be the best system to use? or does it just depend on the ctf i'm attempting to do etc

undone sorrel
mossy river
undone sorrel
#

i want to learn like cpp but it seems like for what i want to do , i need to learn asm but after 5 minutes of looking at it, just gives me a headache

scenic bobcat
carmine sedge
#

As soon as I get to reverse engineering at any ctf, I go ahead and head over to medium because I know I am gonna need it

fleet finch
undone sorrel
worn thorn
scenic bobcat
undone sorrel
fleet finch
#

so I do not pass something like 111111:22222222222 or 00000000000000:22222222222222222 but only the 22222222222222

#

like impacket-smbexec --hash 2222222222222222222222

undone sorrel
scenic bobcat
carmine sedge
#

other way around. Dynamic is like anyrun, static is dbg @undone sorrel

undone sorrel
#

ahhh i understand, thank you ❤️

#

and, is there a limit to how many rooms i can join?

sick lance
#

Nope.

scenic bobcat
undone sorrel
#

mate, this website

#

seems perfect

carmine sedge
#

For what its worth, the people in this room are so much more knowledgeable than me, I start second guessing my own name lmao

sick lance
#

Right now I'm currently in

scenic bobcat
#
Static analysis is a test of the internal structure of the application, rather than functional testing. Dynamic analysis adopts the opposite approach and is executed while a program is in operation.```
worn thorn
undone sorrel
scenic bobcat
undone sorrel
#

mate, this discord is so welcoming also if i go anywhere else to explain my issues, i just get shutdown

carmine sedge
undone sorrel
twin ridgeBOT
#

Gave +1 Rep to @scenic bobcat (current: #311 - 15)

sick lance
#

This was one of the best Ghidra rooms, but it's private now for new members.

#

I'm loving the blue windows boxes we're getting these days.

#

And it's one from Arabel so it's going to be good.

shut hawk
#

appreciate that the sub/free release rate is balanced, (3 sub then 3 free then 3 sub etc)

buoyant tree
#

somebody tell me the first movie to watch today

carmine sedge
#

batman begins

worn thorn
#

matrix

sick lance
#

I wanted to see the new Bill & Ted, but it feels like Keanu forgot how to act as his character.

worn thorn
#

always a good one.

mossy river
buoyant tree
#

Today about 3-4 movies

#

It's EID

near hawk
#

Defo can smell a DFIR path coming after all rooms are released

buoyant tree
#

Going to watch matrixx first prolly

worn thorn
#

honk have fun.

sick lance
carmine sedge
#

has anyone watched the new fallout show on prime video

mossy river
sick lance
worn thorn
#

damn millennials

crystal wren
#

jesus

noble knoll
#

Back in my days there was no such thing as secure protocol

worn thorn
#

Pre 2k be like upvote

crystal wren
#

Ouch ): that comment made my knees hurt

shut hawk
#

Ayee new Alex Rider season out

chilly veldt
near hawk
#

👀

chilly veldt
near hawk
#

8k more users til 3 mil

sick lance
#

Or atleast a capstone project eh @eternal roost 👀

near hawk
#

3 mil will be this weekend

sand trench
#

grrrr it is still there and annoying shadow

sick lance
narrow pewter
#

Guys, I need help! I have no idea why, but my kali machine, baremetal, updated and upgraded 2 days ago, now gives me an error like this:

Reading package lists...
E: Could not get lock /var/lib/apt/lists/lock. It is held by process 4362 (apt)

What should I do?

#

Is it safe to just kill process 4362?

sick lance
#

ps aux | grep apt

#

Check what's running.

#

If they won't work, you can remove the lock manually.

#

sudo rm /var/lib/apt/lists/lock

narrow pewter
#

I just wanted to be sure it's safe...

sick lance
#

I don't know what's running on the process.

#

This is a quick example on why it's bad to run Kali baremetal, you'll be doing this, alot

narrow pewter
#

I will try killing and see what happens

#

It did not work...

#

I will shutitdown and try reboting...

shell nova
whole yew
shell nova
#

Reboot should work

narrow pewter
#

Thank for the help anyway

oak river
#

Yes, but this is in terms of pentesting I guess?

#

A Null, Fin or UDP scan are stealthy enough?

simple valve
#

Modern systems have detections for them

#

But its all up to the SOC if its actionable or not

oak river
#

Yeah, but in this case I am just learning

#

Moreover the complete beginner path

#

And I am training for SOC entry position so

#

It shouldn't matter in this case?

simple valve
shell nova
oak river
#

irl?

shell nova
#

Go slowly enough that they forget you 😉

#

Though a proper Siem would still be able to alert

oak river
simple valve
devout palm
#

Or be a needle in a haystack

shell nova
#

There are so many scans on the internet that you'll probably get lost in the noise

gritty fern
#

You could use decoys and silent maybe

oak river
#

I guess physical human resource pentesting is the best option then

shell nova
#

Least until you actually do something

oak river
#

Can't resist my demands, when I hold his browser history as a hostage

shell nova
#

If you want to be stealthy you'll want to make your traffic look as normal as possible, but that's my opinion

devout palm
#

Yeah ^

glacial bone
#

Hello, I am a beginner in cybersecurity and I am planning to subscribe to TryHackMe, but I am afraid of getting lost. Is it correct to start with the 'beginner path' first and then move on to the 'jr penetration tester,' considering that I am interested in pentesting?

devout palm
#

Try to make it as identical as possible with regular packets

clever shard
shell nova
simple valve
oak river
devout palm
oak river
#

I just know how to use nmap for enumeration and gobuster

#

For now

shell nova
#

Heh

#

Limit the scan to the ports you want to actually attack

simple valve
#

i started as a wee lad who blasted nmap -A on every machine tryhackme had

clever shard
devout palm
#

Then run a scan on labs and check Wireshark

#

That might give you some ideas

clever shard
shell nova
#

That's not how proxies work?

oak river
glacial bone
# gritty fern probably

But it says 'intermediate,' is it for people who have a good foundation, or did they write that to indicate that it might be complicated?

oak river
#

Wireshark became fun once I did the wireshark room though

#

Maybe I still don't undersatnd some things, but I guess I'll get the hang of it

#

Good that I do OneNote

simple valve
devout palm
gritty fern
glacial bone
oak river
glacial bone
devout palm
#

But definitely, subscription is worth it

oak river
#

Do the easy rooms and gradually progress

clever shard
devout palm
gritty fern
devout palm
glacial bone
twin ridgeBOT
#

Gave +1 Rep to @devout palm (current: #27 - 291)

dusky sorrel
#

guys..I hope there will be at least one person focusing on soc areas.
I have been focusing on offensive side for a few months and still I am not good in that but I want to try learn some from a defensive perspective and trying to SOC, i Found it interesting but at the same time it find it hard to learn so that it is more theory when compared to offensive(accrdng to me). so how could i get on with this guys and i really like bash scripting, i mean i just need a proper path to follow.

devout palm
#

So there's no "hiding traffic"

glacial bone
devout palm
glacial bone
clever shard
clever shard
#

hiding your traffic

devout palm
clever shard
glacial bone
simple valve
sick lance
#

Or is that VPN.

devout palm
sick lance
#

Probably VPN.

devout palm
#

Yeah

clever shard
twin ridgeBOT
#

Gave +1 Rep to @simple valve (current: #22 - 362)

devout palm
#

VPN -> Encrypted packets

devout palm
#

Proxy -> Not encrypted

sick lance
devout palm
clever shard
#

proxies packets aren't encrypted right?

sick lance
#

Depends what sort of VPN you're using.

sick lance
dusky sorrel
# simple valve The SOC paths are good

i have just started it, but was in a little bit of confusion there, do I need to go through all theory(obviously I am a lazy man), wish more practical lessons are there when compared to offensive. I guess I have to continue on the path.. just learning step by step.

shut hawk
#

Pretty much all Morden VPN protocols use some sort of encryption. Unless you are super old and using something like L2TP which doesn't provide encryption

naive violet
#

@clever shard not an appropriate joke to make here

simple valve
dusky sorrel
#

@simple valve sometimes, I just need a push, thanks mate✌️

twin ridgeBOT
#

Gave +1 Rep to @simple valve (current: #22 - 363)

devout palm
devout palm
#

It's actually fun, when you learn offensive security to defend

#

Defensive security to attack

#

Theory serves as a guide for practical application. Keep up with the study (:

#

There's theory in general cyber security, not only defensive side

dusky sorrel
#

thanks for all the say guys, got me motivated✌️ time to go, have a great one everyone, peace..

sleek viper
clever shard
sleek viper
#

As a defender you should know how an attacker works, and as an attacker you should know how you can be detected or investigated.

naive violet
sleek viper
clever shard
#

but still you right

mossy river
#

What’s up party people

naive violet
summer carbon
#

how to see how many points I have earned

clever shard
#

and their conest?

devout palm
naive violet
devout palm
summer carbon
twin ridgeBOT
#

Gave +1 Rep to @devout palm (current: #27 - 292)

summer carbon
#

my level isn't updating on my profile anyone knows why

devout palm
clever shard
#

👍

summer carbon
sleek viper
#

@clever shard check out proxychains tool

clever shard
#

@sleek viperNo money to get proxies

summer carbon
clever shard
sleek viper
#

you can find lists of free open proxies

clever shard
#

💀 if something is free then you're the product

sleek viper
#

Smart man 😉

#

but you can still chain between multiple proxies

summer carbon
sleek viper
#

They might dump your traffic though

#

hehehe

clever shard
#

they keep logs and they're willing to give it to anyone with power

summer carbon
normal fable
#

🍿 hi

sleek viper
#

keep in mind that mini Tor exit nodes are dumping traffic

#

*many

devout palm
clever shard
sleek viper
#

there are ways to enumerate people over TOR

normal fable
#

How's the Heap? 🙂

summer carbon
devout palm
normal fable
#

Just working. Stopped and looked at chat. lol

sleek viper
#

My point is nothing is foolproof. it comes down to a series of practices and just like defending security is a layered approach even when you're attacking or trying to remain private 😉

clever shard
#

@sleek viperwake up lil bud tor isn't that secure

devout palm
sleek viper
#

lol

#

but it gives you another layer of obfuscation

normal fable
#

About to go out and look at the ducks in the lake. 🙂 🦆

clever shard
summer carbon
devout palm
sleek viper
sleek viper
clever shard
devout palm
sleek viper
#

lol

clever shard
summer carbon
# clever shard I guess anonymity is a illusion

I agree with you , anyone knows what's protocols actual structure or core of networking , all we know are what they have tought us . IETF and other organizations know actually what's going on

sleek viper
#

And yes, anonymity is an illusion depending on where your location is, how you're hiding your traffic and what country you reside in

clever shard
sleek viper
#

depending on what you do with that anonymity just remember it's going to come down to how many resources someone is willing to spend to locate you or investigate your activity

clever shard
#

it just scratched that part of my mind could anonymity be a thing?

summer carbon
#

when giant agencies needed , anonymity is nothing

sleek viper
#

Tor was developed by the US Navy to protect a dissidence in many countries, freedom of speech does not exist

#

dissdents

mossy river
#

Alright

#

I think it’s too political now

sleek viper
#

hacking is political

#

It's only too political when it hurts your brain

mossy river
#

This discord server is not political 🙂 please keep it out of here

clever shard
#

@sleek viper I dissagre with you

#

hacking isn't political

sleek viper
#

thinking outside the box is always political

#

but you're entitled to your own opinion

#

And literally saying that people who seek privacy are criminals is a political statement and it's based on an opinion

summer carbon
# sleek viper dissdents

All I know is we all are puppets who work with some CLI and GUI tools with knowledge of RFC documentation , DOD know what's the truth is .

sleek viper
mossy river
#

This conversation needs to stop or everyone involved will be temporarily muted. This is your final warning.

sleek viper
#

okay, I will abide by your terms and agreements. moderator

summer carbon
sleek viper
#

not trying to cause problems, just trying to get people to think about their activity

#

lol

devout palm
#

So, what did you folks learn today?

clever shard
summer carbon
devout palm
#

Jeez, i meant about cyber security

hollow pivot
#

really?

patent hinge
whole yew
#

Yeah, lets not say actually wrong things.

clever shard
#

and u?

whole yew
#

Keep in mind this discord is intended to be a good place for security and IT learners to start out

summer carbon
#

VPN , even GForce Now servers blocked me when I connected using nord VPN 😂😂

devout palm
#

Code is invalid

whole yew
#

Also removed the code, because that's technically self-promotion.

patent hinge
#

damn

whole yew
clever shard
summer carbon
devout palm
patent hinge
whole yew
patent hinge
boreal scarab
summer carbon
whole yew
devout palm
#

I personally use Mullvad

clever shard
sleek viper
boreal scarab
whole yew
#

I've never seen a mullvad sale; that doesn't mean they haven't existed or won't exist, but the price has been basically the same since the service started

patent hinge
summer carbon
#

Forget about VPN what about DPN

boreal scarab
patent hinge
#

B)

worn thorn
#

fellow proton users tipsfedora

sleek viper
#

Just rent a vps and setup open vpn, I run a ton of vpns all over the world, Don't use third-party services that are managing your endpoint. that's bad advice

sleek viper
#

I started replacing all my vpns with wire guard recently and I like it better

patent hinge
#

Dude spends more money on VPS than on his bill

boreal scarab
#

"My Lord"
"Proton User"

sleek viper
#

vps is like a couple bucks

#

lol

worn thorn
#

heh

jaunty prairie
#

I feel if a 3 letter agency is going to ask questions my VPN provider is a lot safer then my VPS provider.

sleek viper
#

Way cheaper than paying for VPN service

patent hinge
#

so is a vpn sub with more servers

#

Easier to blend in

sleek viper
#

That's why you don't log on your own VPS where you control the end point

whole yew
sleek viper
#

It's not a provider. it's a product

boreal scarab
#

Just build your own ISP... done.

sleek viper
#

You can host it yourself

#

Yeah, building your own VPN on a $3 VPS is way easier than hosting your own provider

#

but go ahead. just keep paying third parties to host your VPN endpoint. have fun

patent hinge
#

I will and I do

sleek viper
#

well, if you don't care about your own privacy, that's your prerogative. what can I say? I'm just offering advice to people who care about that kind of thing

worn thorn
sleek viper
#

That's one way of building your own ISP LOL

patent hinge
#

For me just masking my IP and DNS is good enough

shell nova
#

Eh, wireguard is nice, but I have no illusions about data privacy with that

summer carbon
#

Decentralized VPN(DPN)

sleek viper
#

most of those vpn services are probably using wire guard or openvpn

patent hinge
#

VPS provider logging connections

sleek viper
#

You're just paying them for the endpoint

sleek viper
patent hinge
#

And the hosting for the server

boreal scarab
#

Wait, it's starting to get on this level

sleek viper
#

your basic lol

boreal scarab
#

You're*

sleek viper
#

your are

#

noob shit

worn thorn
#

oi

boreal scarab
#

You know discord isn't E2EE, right?

sleek viper
#

I'm not saying anything that requires anonymity

#

just trying to give the masses better advice

#

And if you want to work in security, you should probably learn to run your own VPN rather than use a third-party service

#

It's not that hard

shell nova
shut hawk
sleek viper
#

I guess it's just me then huh?

summer carbon
#

where would this annonymous conversation leads NotLikeThiskekw

shell nova
sleek viper
#

low end box is good

#

I like vultr too

#

or linode

shut hawk
sleek viper
#

Yeah that is pretty suspect

#

lol

brisk tree
shell nova
#

I have a wireguard going to my home network, works well enough for hotel wifi

summer carbon
#

how about IPV6 only decentralized , and heavily secured network device , that's why I love deeper.network

sleek viper
#

It's especially great when I travel outside the country and I want to watch my regular media

shell nova
boreal scarab
#

When at Defcon, I just rocked Proton with a kill switch, even on data.

sleek viper
#

My ISP is cool with it

crisp patio
#

anyone had any experience with vmware running like complete garbage unless ran as an admin? got a new laptop and done the normal disabling of hyper-v and device gaurd but it still runs like shit unless run under admin

grim sparrowBOT
sleek viper
#

vmware has some very complicated licensing and some very serious hardware requirements

#

try using proxmox at home or just virtualbox

lavish sparrow
shut hawk
#

Vmware has worked great for me

sleek viper
#

I thought they ended VMware player

crisp patio
sleek viper
#

I use VMware in the Enterprise

crisp patio
#

I also have a valid license for pro

shut hawk
#

How much resources have you allocated the VM?

sleek viper
#

okay, well if you have a license that's different and you're meeting all the regular minimum requirements?

crisp patio
#

yes

sleek viper
#

maybe try using a tool like "latencymon" if your on Windows

#

is it the hypervisor itself that's running slow or is it your VMS??

boreal scarab
#

I love my recruiter. Read my email wrong, and he writes back to me: takes another sip of coffee

When recruiters can joke, I'm all for it.

sleek viper
#

I think your hard drive, bus and memory speeds are going to come into play here as well.

summer carbon
# sleek viper My ISP is cool with it

The advent of quantum computing is poised to revolutionize our information infrastructure due to its potential for vastly superior security capabilities. Even now, the NSA has acknowledged the future risks associated with quantum technology. It’s conceivable that a quantum network could mitigate some of these challenges. However, looking back from that advanced standpoint, our current conversations might seem quite quaint! 😄 LOL

sleek viper
#

Yeah, quantum computing is going to turn this industry on its head

sleek viper
#

It's going to make things much more secure and it's going to introduce a whole new level of threats, especially when it comes to cracking encryption

sick lance
summer carbon
boreal scarab
#

Lemme put my help desk glasses on

sleek viper
brisk tree
#

This is wild ahaha

sleek viper
summer carbon
#

Workstation Pro is amaizing

crisp patio
#

apparently they may be some issues with 17.5

sleek viper
#

could also be the drives you're using

boreal scarab
sleek viper
#

I've had horrible latency from using cheap nvme drives

crisp patio
#

first thing I did

#

and virtualization security is off

summer carbon
boreal scarab
sleek viper
#

try that program latencymon

boreal scarab
#

Can't remember the exact name

crisp patio
summer carbon
sleek viper
#

What is the brand and type of SSD? what is the bus speed??

crisp patio
crisp patio
sleek viper
#

sufficient for an end user maybe not for a hypervisor, depending on the load you're putting on it

crisp patio
#

it's definitely sufficient for a vm lol

boreal scarab
#

I say crap, for this instance...

sand trench
sleek viper
sand trench
#

depends on what the hypervisor is

summer carbon
#

maybe your m.2 had been corupted , once it happened to me , when I work on something large it is struck in

sleek viper
crisp patio
#

possibly. It's brand new so I would hope not but I could alwys wipe it and see

summer carbon
sand trench
#

together with knowing that email as a protocol is insecure in EVERY way

sleek viper
#

I had an Alienware r3 13, I was getting all kinds of system side latency and it turned out to be my Toshiba M2 drive such garbage. I replaced it with a Samsung Evo+ It was a game changer

crisp patio
boreal scarab
#

Wtf is that app yuou can test disk speed with

sleek viper
boreal scarab
#

CrystalDiskMark

#

Run that, see what speeds you're getting

#

Should be up in 7k with gen 4x4

sleek viper
boreal scarab
#

Gen 3x4 would be 3k

sleek viper
#

Can you give us any indication what type of load you're running?

sand trench
#

laughs in no crystaldiskmark for linux

sleek viper
#

is it one of your VMS is being slow or the whole platform??

summer carbon
#

did you cheked your PC for malware or intrution

boreal scarab
sleek viper
#

This is where latencymon might come into play

sand trench
#

shadow can find benchmarking tools for linux if they need them but so far it is not a necessity

sleek viper
#

It's not always easy with the out of the box tools to see what's taking up resources on Windows. might need a couple extra utilities to drill a little bit deeper

boreal scarab
#

Time for food. Left overs, or should I buy something?