#general
1 messages · Page 131 of 1
Lol
WDYM, it's there?
hi me new
Hey!
Hi new, I'm Scrubz.
Hi scrubz im new
How are you?
Hi New!
im great wbu
Yeah, can't complain 🙂
these are super important to the safety of the server. I think everyone should read them
look at you trying to give me more work than I already have. If only somebody could break it down for me in song and dance
So these are the rooms that will be part of the new web application path

I noticed some new channels coming up. Any chance of an LFI/RFI type channel to be coming?
The new channels are related to new room releases.
So maybe if there is a new one released.
oh my bad. I didn
t notice they were for rooms
I imagine as a new webapp path is coming out as stated in the 3m blog post then i would most likely guess there will be
I didn't see that post. guess I should follow some THM socials. Thanks!
The order of fear
Hear their call through space and time
A dark sun will shine
Welcome to the end of all
The order of fear
Hear their call through space and time
A dark sun will shine
Welcome to the end of all your
Some forensics, incident response, cloud and advanced devsecops
thats dope af. I look forward to that
I know most people will be excited for dark mode after so many years of asking
Hi guys, Do u know how I can remove all media from my discord given from a specific person. I think they installed spyware or something on my phone 😡
Also, how will I know if spyware is installed on my phone?
If in doubt, factory reset phone.
But discord warns you before you download anything from Discord.
but nobody pays attention until something happens 😂
Is there a way I can delete my chat with someone and delete the things they sent me on discord?
Deleting their chat won't have any effect on what is stored on your phone.
Well, in my defence I thought discord had mechanisms in place to stop the spread of malware
hahahahhaa yeah they try but it is definitely not fool proof
They do, but if you click "ok" then... 🤷
lost count of how many cdn links shadow reported for malware
Im planning to factory reset my phone but I wanna delete the chat
Ahh
It's not stored on your phone.
maybe the most obvious one, but not 100% effective, hence the message 🙂
Im just scared. If i factory reset my phone and install discord again. If the person has set up the malware to automatically download on my phone or something?
😒
You'd need to click the link again.
If in doubt, delete.
Imma rick roll myself for relaxation
For relaxation
I just had a listen myself
Okay. Just that I heard the pegasus spyware or something like that could be installed without clicking a link...if im not mistaken
Some random won't have pegusus spyware... 😅
Yeah ik 😂
But if they have something similar? Idk
0-click exploits are extremely rare and not often used for random people....
Likely not the case
Pegasus it way above the pay-grade of 99.99% people in Discord
1-click are a bit more common but still rarely used for random people
Eep!
I haven't ordered mine yet.
make sure there aren't snakes too 😂
Got a new hoodie and stickers coming as well
STICKERS ARE ADDED!?
Yea when 3 mil was hit lmao
It’s ashame they will take a while as they get dispatched from north carolina
Next will probably be socks and mousepads
So down for socks..
It goes like a 🐐... lmao
So how many stickers you getting scrubz?
I feel like with how excited scrubz was they’ll be sold out
an undisclosed amount I believe 😂
I got one of each in my cart... lol
Same, although it will probably take 2 weeks or longer as they’re coming from north carolina
Ordered.. and a 3M users shirt. 🤣
How to add 2 adapters( new network) to a MAC2 for a UTM VM.🙏
nice for once the sticker and shadows bank account money lines up so shadow can buy the stickers
I have a swag code I'm about to drop on it.
Can somebody link me the swag store?
I'm on mobile
Curious.. Is there a THM warehouse or is everything drop-shipped? 🤔
huh that embed looks whacky
think they have a warehouse but not sure ¯_(ツ)_/¯
yuups
finally shadows laptop can have a tryhackme sticker
together with the i void warranties for a living and queercon computer club
Thank you
Gave +1 Rep to @sand trench (current: #4 - 1711)
I need a laptop for my stickers... lol
also would thinks that the slash command might work on mobile too
Get some awesome swag to show off to your friends.
oh new icon for slash commands on discord... interesting
Same
shadows laptop is from 2017 so it is kinda old
aiming to buy a new desktop pc this year
to replace the laptop at home
Got any recommendations
for desktop pc??? or for laptops???
Laptop
18, I think
Unfortunately I’m applying for loans for school so plan to use whatever’s left for a of
Pc
Framework Laptop is great.
well shadow is kinda biased but here you go
system76 if you are in the usa
tuxedo if you are in europe
framework for easy of repair if you can get them to ship to you
most clevo based laptops if you can find those
I was looking at Framework laptops..
warning on the first 2 being expensive
Best for which os?
but they are linux by default laptops hence why they are in shadows recommended
both work
they are designed for windows mainly but linux is heavily supported by the framework community
I prefer Linux
same alt ez
I see
Okay
in this last 1 and a half year shadow has moved very deep into the linux echo system
If I ever need a laptop it will be a framework with linux. Windows will never touch it.
now running a window manager and an arch linux fork
Can still hang with Windows.. But get confused between shortcut keys and stuff...
I use arch btw and kali
sadly framework not ship to sweden yet
that's unfortunate.
Sorry, I can't talk about THM infrastructure
cc @sick lance
And India is hell
Breh... some of these companies sending emails to me like "looking for food quality manager"
DO I LOOK LIKE I'M QUALIFIED TO LOOK OVER FOOD QUALITY... breh
How about budget friendly
Understandable 😄
Yeah I said
Ils not about the infrastructure, its the name of the tool actually
Well you order enough?
battery moment
Does this mean I am protected (I didn't reset my phone) but someone said I shud install antivirus
It's part of how THM works behind the scenes and therefore I'm not allowed to talk about it. Sorry
Depends on the AV.
Is it late to join in buy bounty as compared to past years?
Which ones do u recommend?
Not really.
I got to know about hacking stuff in 2019 but due some reasons I didn't take step up
Bug bounty isn't age specific, more skills.
No idea, I don't use any.
Yeah but I lost 5 years of skills
But then, I also don't install dodgy stuff, or visit dodgy links.
Hmm okay, thanks tho
Gave +1 Rep to @sick lance (current: #1 - 2177)
Lol if u say thank u to someone it gives them rep. Thats cool
🤣🤣doesnt work for me lool
you can only give 1 rep point every 5 mins
Best AV ever is: Safe browsing practices, don't run stupid shit, don't click on random links in emails...
and obviously not give yourself rep points
Ahh okay, thanks for letting me know 😂
no problem
Sometimes they're clever.
can confirm. Defender did jack all to warn me.
In the past I got access to some emails while scraping the internet archive
Ahh okay thank u, I do know that but its usually trusted ppl i know who may have hacked me
Oh I know...
And I got a Twitter account and discord which accounts created on 2017
What should I do
?
*wonders who that random private number that called shadow was... shadow answered and said ello this is shadow and then it hanged up...
turn yourself in? Why would you take other people accounts.
Best response
Nope I didn't
Ewww, zip-up hoodies should be illegal
Check my accounts created date
Read this
with that context it sounds bad.
I remember giving a scammer a fake name told them to repeat it and i laughed at them and hung up and they weren’t very happy as they called back to argue
shadows main email has been in so many breaches shadow consider it known public info and not worth protecting
They should have their own custom linux command mouse pad
i.e not worth protecting from people randomly sending emails to them
still have good password and 2fa on it
I gave a scammer my spam email address and three months later I get called by a different scammer from a different number and he provided that email addresss to me
I literally burst out laughing
the weirdest probable scam call shadow got was from meeping hong kong
shadow answered like they usually do... person on other end say they are calling about some banking or money sending thingy... shadow hangs up as it is near midnight when they called
they never called back so it can not have been important
DrGonz0 stating that about hoodies to know who to ban from tryhackme
Seems like you have time to mess with scammers but not do CTFs 
so if anyone here wants shadows main email address shadow can give it freely... or you could just look at the email linked to shadows github account
What’s GitHub
15 breaches and one paste...
I don't think you know how little brain power it takes to just leave my phone on while I do work in the background 
website for hosting code and programs using git
git is a versioning system to keep track of changes to code
All I see is EXCUSES
Ohh
service that allows you to store code/software in the form of git repos
You could write solve scripts and have them solve challenges in the background
hah
Random question. Favorite cheese?
How much do you guys pay for yearly try hack me premium access? Anyone
Thank you
depends on for what usage...
currently looking forward to more smoked gouda grilled cheese sandwiches
That’s what I be doing. Using Gouda on sourdough bread with rubbing a clove of garlic in the bread before buttering and towering
currently not much due to onboarding thingy
Toasting
also love salami brie sandwiches
Parmigiano and Comte
Never had Comte
Tome de chevre also
They are so good when aged for long enough
@mossy river have you seen notions new calendar 👀
no
Was originally https://cron.com/
haha sometimes shadow should read their email before ordering stuffs
Sorry if that was personal
nah that is fine
ordered 2 tshirts and 4 stickers from tryhackme
then found out shadow apparently won a free tshirt from tryhackme
hence the funny
Nice. When I’m better with hacking I’ll start buying merch
A hacker embodies a boundless passion and insatiable thirst for understanding the complexities of a system, computers and networks in particular. They revel in the pursuit of knowledge and mastery, constantly seeking new solutions and opportunities for growth. Their drive and innovative spirit inspire and are inspired by the hacker community, where ideas and knowledge are freely shared and valued regardless of their origin.
Still supporting tryhackme either way

if you fall under that definition shadow already considers you a hacker
oh wow shadow actually successfully got 2 sequential tryhackme swag store order numbers
Heya @mossy river saw u pinged me yesterday for a DM
Thank you @sand trench but I’m still to new to be a hacker but that’s what I drive to be
Gave +1 Rep to @sand trench (current: #4 - 1712)
So if I like to break things I am a hacker?
if you break the things to learn how they work internally yes.. if you just break things for the sake of breaking them no
I'd be master hacker by now with all the times windows broke
Hmm
1 hoody and 9 white and 9 black stickers.
already got hoodies from tryhackme
tshirt? 👀
Oh yeah, that too.
Gonna put number 1 on the rep table on it. 
You used the stickers or are they framed
doing mr robot ctf , i fouund the wp passwd without using automation tools is that okay ? bc after finishing this ctf challenge i watched many yt videos , and they used tools in order to get the passwd 😭
Hey guys! I am having issues with connecting to openvpn becuase of outdated ciphers
#site-support please.
Where can I give suggestions to tryhackme?
if you have watched the mr robot show it would not be surprising to guess the password
i watched it ; but i didnt guess
it was located in a specific place x)
Why are there new rooms for XSS and CSRF, weren't there old ones also.
Newer content is always a bonus.
Yes, but shouldn't this be considered as a update instead of a whole new room?
by the way while doing ctfs i noticed that im using tools , that makes me skiddie?

Sometimes it's easier to retire the old room and insert newer updated content.
if you understand how the tools work no you're not a skiddie
or know how they work behind the scenes
i watched mr robots but i still cant hack a website with 3 keys
i do know , some tools ofc , but is there a point in this jouney where i should create /script something in order to take advantage of a given vuln ? sorry for my english x)
@sick lance is the top 1
so far shadow has barely ever created a script that can be reused for multiple rooms.... so yeah
Possibly swag/subsc vouchers.
Maybe @mossy river can answer.
Oh, I see it takes everything to reach that lvl
if you fall from stairs he'll take you to hospital too
Where did the feedback text reach?
Thm's email.
Who reads I mean , and how can we know they read
I think i'm more into writing exploits and finding new vuln , i need at least 10 years to be able to do that
😂
writing exploit and finding new vuln requires 10 years too
Don't tell thatto me I am 4 days old in this hacking stuff
They're read, don't worry.
There are no URLs in that message.
i still cant write a simple py script to find hidden dir , dont worry
we are learning here

tbh , if you just check a "python for hacker" course , it's already enought
you don't need to be a developer
i already did that
😏
so you already have what you need
i always have to check , but ya i know at least what is behind the scene in such enum tools
creating tools with python (basic one) to help you during hack its not so difficult
studing a programming language is more usefull to understand the different types of code
I know !!
Do u like cats ?
but i think top ones here know differents one at high level . Like 0day
i hate them , im a dog person . But i like cat meme
well shadow apparently knows enough to be part of the room tester team
if you look at my profile picture very well is a famous cat meme image modified with gimp
Well guess who isn't getting help when the fall down stairs now... 
pls scrubz, forgive me
yes , it requires patience and perseverance to be good at something
may i ask a question?
oh i have had quite a tumble
Bad 😡
that is not good man . That is god level
sure but as always shadow reserves the right to not answer
why you talk about yourself in 3rd person?
old habit shadow never stopped doing since kindergarden
special
well , unique
exactly why shadow started doing it back then is not known to shadow
yeah and makes some types of opsec impossible
mew?
palkia
You take that back right meow!
dog loves you. My dog doesn't need to hack . He can eat computer
wrong
Cats are like : "someone need help in room-help. I know the answer but i don't want to help people"
Doing cybersec training for work.. I better get 100% 🤣
you will man . Not so difficult . I trust you
break the exam, get 101%
meow !!!!
Is there any problem to you guys to ask bot level questions
Bot level?
I mean some questions looks like noob
which ones?
nope. ask. 🙂
man sometimes i get stuck in a question who is noob level and after i feel dumb
everyone can ask everything
a part Scrubz , he need to know everything
Thx for the heads up guys
yeah but idk if this happen to you too. Sometimes you get stuck in something you know but you are doing something wrong. When you find the solution you feel dumb
oh that happens plenty for shadow
though it has been getting rarer
probably because shadow force themselves to help others to learn by helping and teaching
It's good isn't it

well there is this quote from some famous person that states you don't know or understand something until you have had to explain it in such a way someone else understands how it works
After explaining you better understand it so it makes sence
hi guys, does anyone have any idea about this?
@sick lance
The comments do a pretty good job explaining...
What are you unsure about?
I am confused about one thing, how does he the ssh client knows where to get public key from, does it extract it from private key?
When you ssh you can declare the key with the -i switch.
Because you're that good.
ssh -i path/to/key *username*@$TARGETIP
*doubt
yes but still my ssh is offering a public key to the remote host to connect to it, the one that is in the authorized_keys file on remote
@sick lance
for most key types you can derive the public key from the private one
then there is also the ssh agent cache
^
Well.. Shadow is better than me..
I tried to clear cache and also still connecting, 1 note that some other parameters should be saved so we can extract rsa public key from private key
looks like it saves it for such situations
but the weird thing is when I tried to extract the pub from private it worked using this command
ssh-keygen -y -f ~/.ssh/id_rsa > ~/.ssh/id_rsa.pub , but the hash of the offered public key is not the same as the one I have extracted .... and still connecting
@sand trench
how did you get the hash???
I kinda want a hot pocket rn.. what is wrong with me???
go get a full real calzone instead
That does sound way better...
Why do we fall, so we can learn to pick ourselves up
Is tryhackme have a bug report
Batman
yes
Responsibly discovering & disclosing security flaws!
I wanted to ask me that all the thm users done bug bounty? Where can I see past reports
what mate
yup
Could you read again
oh nah
they dont share it afaik
when you run ssh -v you can see that ssh is offering RSA pub key like this
Roger that
that could be the private key hash
some of them are unsolvable now tho ,-,
like cct2019
wait really???
well you may be able to find some remnants via things like archive[.]org but the stuff is no longer live
ah
(they were using stuff not on entirely thm)
not private key hash either ... @sand trench
there is a difference in text file hash and string hash
you mean, I should cat the file then use shasum256 right?
https://www.youtube.com/watch?v=r22tyT77vOw
Whose traveling to Romania?
Thanks again to Ridge for sponsoring this video! Check them out at https://lmg.gg/Ridge-Apr24-LTT and use the code LINUS to get 10% off and free shipping!
We are sick and tired of people asking Linus for a Free PC! That's why today we decided to create THE ULTIMATE PC SCAVENGER HUNT!!! Can you figure out the clues and find the PC?
Discuss on t...
just scrolled past that one, actually
there's a BTS as well youtu.be/MllrK4XSJxc
Guy already found it apparently
real quick
Well it was sent 24 hours before that video went up to him
AMD 🤢
lmk when nvidia makes a product that works on linux
Mine works fine 🤓
Honestly it's been fine for me over like 8 years
I've only twice broken my graphics. First time I was new to Linux, second time it was a conflict with Steam packages
AMD has better CPUs for gaming, I'll give them that
i have like a 15% success rate with nvidia on linux.
Can't say I've had a great experience either
* cue torvalds nvidia fuck you *
Lots of driver issues, especially when updating
But that was my old PC, I haven't had a chance to use it on my current
There's have been a lot of problems with AMD on Windows too, it's not a one-sided argument tbh
💯
eh windows doesn't get my sympathy tho
Then we can't have a light hearted discussion then can we 😅
Exactly, which is why I no longer want to participate
As the kids say, "skill issue"
but actually tho, i've never heard of amd issues on windows. are you referring to cpu or gpu or both?
Yo
CPU.
first i've heard. kinda curious. might have to take a look later today and see what that's about
If I buy a sticker what should I put it on
I don’t really want to put it on my computer because there’s no case
I had piles of stickers collected over the years. never put them anywhere cause i either didn't want to put them on certain things or didn't want to toss them
ended up sticker bombing tf out of a few ammo cans
Yk what I do I’ll prop it up at my desk to look at
Anything you want or just keep it and don't stick it to anything. 😉
$ env x=’() { :;}; echo cloudy’ bash -c "echo sunny"
Also if I previously got that percent off streak milestone but I lost the streak do I still have that?
only 7 more hours to complete my backup 🥳
hi can someone pls tell me wht this command does exactly? I have ran it in my terminal in linux and chatgpt but theyre giving two different answers and Idk which one to believe
this command
it's less a problem of nvidia, and more a problem of the distro to include support from their end. Fedora has been really good with nvidia drivers for the past 4 years. My System76 laptop from 2015? Considerably less so.
^ I haven't yet tried fedora, so might have a much nicer time with that
Linux
Chatgpt just gets stuff off the internet
Wouldn’t rely on chatgpt to much personally
let me show u what its outputting, its kinda weird
Don't run commands you don't understand.
Also what are you doing anyways
yeah Ik its part of my uni past paper exam :/ so I have to understand it one way or another 😂
revision
I can’t help with uni stuff
😅
Sorry
can someone change this policy here lol, im not cheating i just want help with any other cyber/it related thing. FYI im studying cyber security specifically at uni, so it makes sense why I would ask cyber related things here 😅
and the thing I asked was pretty generic
Problem is that we can't verify that 😓
was just about to ping jabba
I get that..but I promise u I am doing it from uni, I can dm u the past paper too
we will point you towards the internet at large like search engines
I’m sure your professor or classmates will help
hmm thats true i guess
Sorry, If I make an exception for you, I have to make an exception for the next person
professor tends to reply slowly tho
Your professor is always there for you
okay I understand
Well not always but Yk what I mean lol
yeah ik 😂
apparently shadows brother was supposed to try denial of service a windows server in uni today
Hm why would they be teaching that? To see how bad guys do it and learn maybe 🤔
probably to learn how todefend and setup rules to avoid it shadow would imagine
did not exactly ask for why
just asked what todays lab was about
That would make sense
hello, new here...whats everyones opinions on the new website "spy(dot)pet"? If you aren't aware yet look up news on it.
Discussions of that website are going to be restricted to the advanced channels for the moment.
what software is that
where are they? I'm really curious to know people takes on it
jayy another question... do you test restore your backups to know that they work too????
@prisma trout
thank! much appreciation
Ooo I never knew about that interesting
nvidia is notoriously difficult to support tho and they actively make it even more so.. I run fedora as my daily and we encountered constant issues with all of our nvidia cards here as well
you will get there evenutally aces
I've had zero issues with the fedora rpmfusion .rpm packages for my 1660
nvidia for wayland is apparently still kinda messy
Oh thanks but I forgot to reply to cth lmao
Gave +1 Rep to @sand trench (current: #4 - 1714)
FreeFileSync
still shadow has barely had any issues with their current gtx 1070 under xorg
;-; shadow lost their 2 tb ssd backup drive
it is somewhere in shadows house but shadow can't seem to find it
old 1060s through to 30 or 40 series rtx and ampere have all been problematic here even with the rpm fusion drivers 🤷♂️
luck of the draw really
yep!
gotta have luck to get nvidia to work without any hiccups
2060 and up will get better and better open source driver support for nvidia
( well functioning cards do happen occasionally, it's just occasionally )
there is apparently near 100% support for that opengl replacement graphics library
Hi, I just finished Year of the Fox box now (special box to celebrate 100k people on THM few years ago), but I'm quite disturbed about something if someone know by any chance : are the encoded strings just a big rabbit hole ? No way to decode them ? How do you proceed to create such a thing ? I'm curious about this
@pallid lotus can probably answer this
shadow is an hero . I have 1050
but Dansu 'd like to assembly a new pc
well lots of good info on how to build pc:s nowadays
it is not super hard
generally the hardest part is cable routing
ah yeah true
https://se.pcpartpicker.com/list/VcLCn6
this is what shadow is looking at right now for a new desktop pc
Part List - AMD Ryzen 7 7800X3D, Radeon RX 7900 XTX, Lian Li LANCOOL 216 ATX Mid Tower
They might have been prizes that were up for grabs when the box first released
Im going a Little bit higher , but tbh its ok . I prefer going for a more expensive One and use It for more
it is an all amd system due better linux support
*exception being no hdmi 2.1 on amd on linux because of hdmi doing bat shit insane stuff with their licensing
I prefer amd over Intel too ngl
Im going for 7950x
yeah the cpu might change
We were so close to having a foss implementation
So close
Even if your case seems cooler than mine
yeah it meeping sucks
at least displayport is an open standard so that will work flawlessly
Are you gonna work with that too ?
???
yeah gonna use displayport for the monitor shadow has
it will work no problem
No i mean , Will you use that for working ?
well yeah
shadow daily drives linux
might install a windows vm on it if absolutely needed for school stuffs or something
university
if shadow gets in
still consider uni school
Id like to start university too tbh
Just idk if going for Cybersecurity or computer science
dont go to devry online just an fyi was a waste of time and money
But i have to think really well about It .
I already have a degree and im working rn
well shadow currently has no job
You usually go in online university to get title for career , not Knowledge
and is in a mental spiral of despair
Dansu studied law but work as SOC so
Welcome to party my brother
@hardy mica this is true
shadow can always get a job doing https://y.yarn.co/1c06b889-b20a-40e0-a35a-6d647831b728_text.gif
I work as SOC and im going for OSCP , i don't know what computer science can actually teach me
So
But title Is important
programming
"programming"
they can teach you to turn it off and back on lol
computer science in nearly ALL instances will help you learn programming
You can learn the same stuff in like 3-4 months ngl
well yeah probably
You waste your First year with math
math is important too
Hmm idk
hey
ask any architect or engineer and they will tell you how math is important
or a physcist
Im going to hack another planet
But we are neither of that
ask any cashier and they will tell you the same lol
*fails
The best math you see Is hex decoding , and there Is a site Who do It
the closest you can get to hacking other planets stuffs currently is hacking a satelite
which is not that common
And IT as a whole. CompSci is literally the foundational academic subject that all the practical aspects are constructed from.
true
Anyway programming in C Will fall me in a deeper depression
Math is the most important subject you can learn in IT, hands down. If you don't understand how a theorem is constructed, you will be unable to make good arguments for why things should or should not be done in a specific way
get chatgpt to do your homework
please don't
Hmmm idk , i never loved math tbh
back in my day we used google & wiki
Not to mention probably wrong.
Math can help for logical process but you can learn It in other ways
Hmm , idk , i hated math from start . Still strong in chess , in logic and working in IT
somehow shadow learned some harder math stuff from doing programming... like how the sigma symbol works and things
"harder"
Does crying in Descrete Mathematics count?
Naturally
Graph theory ☹️
lmao then i learnt that way.
So you know mathematics
shadow enjoyed math for their first few years of school
then it got to easy
shadow got bored
then suddenly when shadow would start again they were missing a lot of the more basic stuffs
i enjoy most of maths
meaning it got annoying having to learn a lot of concepts that should have been learned earlier
shadow still struggles with big O notation
Don't know match and not being able to learn It , its very different
The fact that i havent done any programming in an year scares me
yeah shadow can learn it and pick up decently quickly
just lacking some of the basics hurt
I can program sheet for 6hrs but get bored After 15 Min of maths
another thingy shadow no understand is how the multiplication table works
i.e shadow has not learnt the mutliplication table yet
can calculate the answer sure
but can't just recite it on the top of their head
Sure but you can still hack
yeah
Shadow what is 3 x 6
Just another proof that math Is important but not fundamental
He Will create a python script for it
6 + 6 == 12
- 6 == 18
uhhh yeah and then faster
https://www.effortlessmath.com/blog/what-kind-of-math-is-used-in-computer-programming/ <-- literally says if math isnt your thing pay someone to do it what kind of website is this
shadow what is 8 x 9 then?
72
For programming it is. ( I am rusty so please correct me)
- Time Complexities
- Graph theories
- Search Algorithms
Maths is being used in all of these (innit?)
yay
93?
Close!
the nines table is maybe one of the easier ones
Its basic math tbh . University math Is way more difficult
Don't Belive him . He Is trying to confuse you
0 + 9 == 9
1 + 8 == 9
2 + 7 == 9
3 + 6 == 9
4 + 5 == 9
5 + 4 == 9
6 + 3 == 9
7 + 2 == 9
8 +1 == 9
9 + 0 == 9
use the finger method for 9's hold up your hands and start on the left hand 9 x 5 put down your left thumb whats left 4 on left hand 5 on right lol
see
if you split the tens and ones in the nines table and add them together the answer is always nine
You are a math adept. The dark side
mhhh interesting
To conclude , i stopped study math at my 2 year in High school , still able to program
shadows latest math course was mathimatics 2c on gymnasium level
Almost the same . But im able to do graphs and algorithm
Anyway i Just see that Shadow pronous are She/her
Her talking in 3rd person confuse me
Now this is a proper beverage
Still in the US, but I absolutely LOVE Paulaner

I just had someone message me on linkedin who i never remember connecting be like we have connected for a while how are you
When I'm in Germany, I'll take you up on that offer. Hit a bar. But that bar better have Paulaner lol
I guess that’s what happens when you accept every connection
Start over with a fresh account!
It will not. Gon be my bar
Whatcha serving? 
593 to be exact
Well can get a keg of paulaner, i guess
I believe the clue is in the name, efforless 😂
you make a great point @blazing granite lol
LOVE Paulaner ❤️ 🍺 🥳
I always have that on Oktober fest 😂
I saw this glass sitting in my cabinet, went to go get some Paulaner, was all out. Quickly got my keys and picked up a 6 pack of Weissbier and 6 pack Salvator Double Bock
this means stupid in romanian D:
I haven't had their 0%, or Dunkel
Paulaner Festzelt FTW!!
Have you had their Dunkel?
Yup. Not a fan
Correct. From memory they're auto genned hashes of /dev/urandom. Probably involving a few other encoding stages for good measure.
@boreal scarab If Paulaner weren't a beer, it would have been a poem 😉
@pallid lotus Hi!! How are you?
Would random keyboard smashing also suffice?
fc24re897ujt4290ug3wer80+nfg234w8ugf389rjwgh48rug789uwerq80uf23er8yufn23
there you got jayy
some freshly smashed keyboard
G'd evenin ladies and gentlemen.
This fine sire tips his fedora as he returns to this respectable establishment to greet thy.

talking about fedora, Fedora 40 is about to be release
banana bread/sweetcake with chopped chocolate bits
What other ingredients do you have?
If you just have chocolate, you're going to get melted chocolate lol
banana doesn't taste good
eh flour and the other things
thinkin brownies
swedish mudcake???
also known as
kladdkaka
I don't want to barf.
partially
Anyone used a fax machine in the last 30 days?
actually yes
weirdly
received one
to think even the original gameboy had a printer
I have yet to see a dot matrix printer though
ooh those shadow has used as recently as fall 2017
They're fun
Old tech was so cool because of the different use cases
Though inefficient, still cool
It's interesting to think that the actual name of the Fax machine originated in the 16th century
Facsimile
Meshing of two Latin words
Never knew that
Yeah, the definition of the word is " an exact copy"
It does do that most of the time
Words are fun
fun is words
There is nothing new under the sun 😂
well we do not know how the layers of the inner earth works
but kinda whacky to consider that under the sun or not
nikto????
Yeah nikto
does nikto really allow you to scan ports???
Yes?
nmap is the standard tool for that
Yes, but in this case a room is teaching me to use nikto
/me grumbles and salt falls off
You can just literally use nikto -h <IP> -p <port/port range>
Anyone know how to report someone who clearly cheated for a CCNA? 😅
yeah but that assumes you are scanning for website ports
How did it happen?
Aren't CCNA exams proctored
?
hey quick question i was just using the website and now i got 504 Gateway Time-out is this an error on my side?
would bet they have a contact email or page somewhere
I cant see the website right now too
no that is generally a server side error
500 codes are on the server side
400 codes are you
oh calm thaanks imma note that down
Notify the testing agency if you witnessed it.
That a translation the phrase comes from Kohelet (Ecclesiastes) that was written by Shlomo Hamelech (King Solomon) other famous phrases are "eat, drink and be merry", "a time to be born and a time to die", and "vanity of vanities; all is vanity"
I ate.. now tired...
nikto vs nmap?
Nmap seems better for port scans
What's nikto better at?
Checking for vulnerabilities better or?
nikto is just that tool you run in the background
manual better
Lead dev of nikto moved over to nuclei
be manual.
what is manual
manual testing, not relying on automated tools
Low hanging fruit.
Work smarter, not harder.
better to just post a letter to internal IT and ask what ports they have open
work lazier not harder
Agreed
Work harder just to become smarter, then use automated tools
Plural of nucleus I believe 😂
Usually you would run an automated tool in the background and go deeper if needed manualy, remember no matter template you got some things require a human eye
👋
I just learned gobuster, wpscan and nikto
I mean, not when it's built into an autogen lmao
Nice, now forget all you learned about gobuster and use ffuf/wfuzz
Is it better?
faster
Aha, fair enough 
A bit different with filters I think
NOW TO GO TO THE ENUMERATION ROOMS AND GET SOME SUCCULENT JUICY POINTS
ffuf installs wfuzz failes to instal

hence shadow uses ffuf
LOUD NOISES

301 meant that the directory exists right?
Or 302
In previous exercises 301 meant that it existed
The Hypertext Transfer Protocol (HTTP) is a stateless %application- level protocol for distributed, collaborative, hypertext information systems. This document defines the semantics of HTTP/1.1 messages, as expressed by request methods, request header fields, response status codes, and response header fields, along with the payload of messages ...
Thanks.
Gave +1 Rep to @shut hawk (current: #14 - 504)
Oh hold on, I think this is the most up to date one
https://httpwg.org/specs/rfc9110.html
But the definitions seem to be extremely similar
Which part of hacking should I focus more on in ethical hacking
all of them
Indeed!! Actually at the begining of the file it says "This document updates RFC 3864 and obsoletes RFCs 2818, 7231, 7232, 7233, 7235, 7538, 7615, 7694, and portions of 7230."
if you're new to this, you probably should get the basics hammer down and then go deep into the part you liked the most.
Which basics
Is there a platform for mathematics like tryhackme
that's because if they even add 1 character they make a new version 😂
sometimes they make new files when there is a new version of the protocol there you see more of a change because they explain the new version and sometimes they compare the old and the new one
Here's a nice chill mix I just found
Mach One: #chillwave #synthwave #retrowave
0:00 Cerulean - Flight
3:36 Vokon - Lyra
7:15 Emil Rottmayer - Momentum
11:35 Alpha Room - Back Home
15:09 Vokon - Atlas
19:18 Cerulean - Realign
23:24 Albatrauss - A Changed World
28:01 Hello Meteor - Heated Seats
31:51 Cerulean - Skyway
35:34 Echosoft - Blue Eye Horizon
39:40 Decisive Koala - Astr...
"oops, spelling mistake"
time for a new RFC 
Sometime you see that one protocol has like 8 files 😂
Coworker who loves to mention they have their CCNA, but has demonstrated repeatedly having less networking knowledge than I did at age twelve.
And lots of fake CCNA certs floating out there.
There was a huge scandal revealed regarding testing in some countries recently.
shouldn't it be obvious in an interview if someone got fake certs or cheated to get those certs
It depends
that weird because CCNA gives you a solid foundation on networking, he either doesn't have it or he obtain it in dubious ways 😂
i struggle to understand how those people get a job to begin with
Because they know just enough and are also socially adept
i guess the spam interviews until they find the one that doesn't knowledge check much or at all
mmm fair enough
Yeah that's kind of what I'm worried about, the dubious ways, this guy got it moved from contract to full-time over other people who I felt were much more deserving based on the merits of their demonstrated abilities.
Tbh, I do poorly in interviews but it seems to work out
because sometimes people who interview know less than the candidate 😂
I'm actually studying for a CCNA, but life keep getting in the way 😂
Yo just keep at it Rex. It's not easy. You have packet tracer and stuff?
Relatable ...
yes, I build a few thing with packet tracer, also I did basic switch config
how do i use my 5% off swag or is that only for the shirts and stuff
Was literally talking to my coworker about studying for CCNA. lol
Swag = merch
i see
Packet tracer is all you should need for CCNA, but you may want to build a pod for fun and future. 🙂
Edit: I mean you don't need hardwaree
i guess that would make sense lmao because a sticker would be 0.06 cents
if that 5% worked on them
I'd love to, but I need time and money 😂
Merch includes stickers
5% off for me is only half of sales tax. lol
https://brilliant.org/ is pretty good too
and it's in english 😂
Thanks @hazy pivot and @blazing granite
Gave +1 Rep to @hazy pivot (current: #2062 - 1)
my level of french it's not enough to study math 😂
I think I figured something out
Every time I enter the terminal and have to ponder what commands to use from a specific tool
I should make myself a cheatsheet
For each tool
A cheatsheet can be useful, but once you start using the terminal more a more you'll remember the commands. It's a matter of habit, the more you use it the more you remember
some commands are similar to DOS so that's also a plus if you know some DOS 🙂
in a technical interview thats wild
anyways i was wondering if anyone here works in a SOC or has experience hiring people for a SOC junior position
it happens 😂 specially in small companies when on person does a lot of things,
Brilliant.com is great
Khan academy too
I forgot about Khan. Khan is good too
Yeah, I was thinking that typing the commands is kind of better
But a cheatsheet is useful too
Just use the arrows and edit whatever is necessary
there is no wrong way, what ever works for you it's great. At the end of the day is your box and you're the one using it 😉 🙂
could you recommend me one. Most of the courses that come up on google are really basic and too simple.
Are you guys disappointed with META?
I have big Hobbies with META in almost all Social Media Platforms they have
And a Album-Legacy for my future spouse and grandchildren
*an Album
They permanently removed my accounts.
Not being a brat, but, I hate it.
Guten morgen
how long does it take subscription to take. effect? I purchased a month, closed my browser and signed back in but still cannot access room I'm working on
awesome
What if let's party
back to support ticket purgatory I go...
Kiddin'
Yeah, or at least the wordlist paths
do you mean /usr/share/wordlists 😂
😂
Wait up, don't think pressured if we can't reply ha.
But, it feels like home here. This Discord Group.
Jonathan Roy - Lost 🟣 ✅ 🎸
😂
trying to test something and my test targets are being annoying
anyone got a good site that is known for reliably presenting cloudflare proxies
nvm we good i just used google itself
hey folks. curious about a line in a job posting I saw...
Extra Points For:
Guaranteed job interview if you can exploit our hiring page.
Has anyone ever followed through on something like this^^? seems like a huge risk to undertake without a terms and conditions or post referenced on the page/website.
It's a mainstream company partnered with crowdstrike but still...
immediately snapshots with archive[.]org
what do they mean by "exploit our hiring page" lol
do they give any other information like scope, guidelines etc?
right that could mean anything. like if i get root am I the new owner?
nukes all other applicants, forges job offer
seems very odd to me
Are you sure it a genuine job offer, from the actual company? It sounds fishy
hires himself as a Consultant that nobody consults with and gives himself a highest salary
RH: Are you good at hacking? Candidate: How do you think that I got this interview? 😂
GTFO of my office
gtfobins???
indeed
I studied ICND-1 and 2 back in 2008/09, scored 98 on the TestOut, but never went to write the exam. I was poor back then.
it happens, I accumulate knowledge along the years, but not certs, sometimes I got nervous with the clock 😂 I opt out for taking a few cert because it stress me out.
The training material is solid. I've only once come across a configuration that had me confused, and I think I found the answer recently, but forget it again.
Some extension to VLAN protocols that I was familiar with.
the information checks out. the person who messaged me for a phone assessment has the appropriate job title and is on linked in posting about the same position...
I will have to wait for their reply
hi, i have a problem with the MISP Room 😦
thanks
#room-help or #site-support if it's a tech issue
Yeah, my biggest concern would be the lack of a terms of engagement. Unless you find a bug program for them on one of the usual suspect sites.
what's also scary about that is with no scope they could take legal action against you if they wanted to
idk how much time passed since i used steghide
years
guys, after pre-sec what to do next?
If you want shadows recommendations it is in this order
#pre-security-legacy-path
#974406074444685322
#junior-pentester-path
#878393611929129000 (optional)
#pentest-plus-path (optional)
#web-fundamentals-path
#soc-level-1-path
#soc-level-2-path
#security-engineer-path
#devsecops-path
#offensive-pentesting-path
#red-teaming-path
#791764435991658556
@crude kettle ⬆️
and shadow is now gonna go meep moop to the beep boop while sleep sloops for the bests
@sand trench thanks... can i add friend you?
Gave +1 Rep to @sand trench (current: #4 - 1716)
Need to pin this
it actually is lol
Thanks lol
if i complete all this
will i be the masterhacker?
If you learn from it, and not just regurgitate the use of provided tooling. You will be well on your way.
Always strive to understand the why.
dont forget to dive into the practice section as well
im just joking , im doing practice for OSCP
i work as SOC analyst
I always write down what i learn, ive got a huge notebook almost full of knowledge
i still use my cheat sheet
i started off writing down my notes but there were so much i switched to obsidian
Yeah... But what you do doesn't define how well you do it, plenty of folks do jobs they don't understand.
Case and point my frustration earlier today.
why were you frustrated
getting oscp means you actually "can do it " .
Tbh im doing room to have fun , but i should start proove myself with good ones
People (co-workers) who don't live up to their station or certification.

luckily im trying to start off strong, not even in college yet and Im trying to learn what I can to understand the material rather than push it off as a "Things happen so things work" scenario
same nabeesco
I agree oscp is meaningful, being a soc analyst on its own isn't.
but i just love cybersecurity
completely agree
cybersec my beloved
its definitly easier to learn if you have a passion in it

