#general
1 messages Β· Page 140 of 1
fair
I inhale it through my lungs
butt-chugg ftw
dayummnn
Do you have a redbull vape?
Bad for you
Breath air!
Jealous
Thats a Wolverhampton bus chair pattern
I think you mean west midlands bestie
That'll do too
Iβm in coventry
Wanna see how I found that?
You are also on a bus
SOme dude uploaded a photo to ebay xD
ππ
Ah their chair looks much cleaner
I guess he couldnβt wait to get home to post it to ebay?? π
Just don't pat it i guess, a moving eBay office.
even worse
ewwww
This isnβt by choice, just going to the gym
I live in a much nicer area
Brum is a different breed
hey guys
reminds me of indigo somehow
whats the best way to land a cybersec internship?
I'm in college rn (Grade 12 by US standards) and am doing my A Levels rn.
Unfortunately, our coursework barely touches upon cybersec related stuff, and I really want to get some experience..
do tryhackme courses work?
My THM experience helped me land a job. The skills I learnt from the platform have been invaluable.
does it count on your resume?
TryHackMe and networking with others
Its on my CV yeah
That's how I got my internship that led to a job, as a year 12 student
"Cyber" is what you make it, if you want a job and want to do it. Do it to the best of your ability.
which courses did u take?
The field is bloomin huge, get stuck in and do as much as possible. e.g.
- Network with people
- write blogs
- start projects
- learn how android/ios/windows/linux/w.e works
- Learn how to program
- Learn BT/RT
- Work with others
- Help a community
- Bug Bounties
- Hack stuff!
etc etc the list goes on
Does my academic performance count? I happen to be a reasonably good student, especially in computer science
I know how to code, and know reasonably well about linux
Depends on the field you want to go into and on ur degree. I'm biased with academia, so best not to ask me (i dislike it)
am typing from linux rn as a matter of fact (endeavoros btw)
FM, maths, comp science, physics
I dislike it too. My parents are adamant about me getting a degree though ;/
pretty much the same as yours, except FM. took chem for some reason
rip
Did the red pathways and just learnt rooms that interested me
You could do the paths in this order
But its a bit preference
Only red, only blue, both
thank you!
Glad i could help
Trying to workout with an injury is the worst
I have to go so light out of fear of worsening
working out is the worst
Is it really working out if you don't feel half dead by the end of it though?
Depends.
If Iβm doing chest and my legs hurt then Iβm doing something wrong
I generally come out of the gym quite energetic
Working out releases dopamine
I mean if you think about it, it makes sense. You go to the gym to better yourself
Feel accomplished after
inf energy strat
Yeah until I sit down then honk mimimi
WSL 1 had routing issues
If your system can run a hypervisor like Vbox or VMware you might as well use them
iirc, wsl have its own networking stuff, maybe seperate to the windows host, will that affect reverse shells
spot on
hmmm, i'll check, thanks
fancy buzzwords
all three I guess
hiiiiiiiiiiiii
I see cyber as cne imo either using them or defending
Mil is always messy, they just have a lot of wonga
I do like how the US have their good cyber guys as officers and not sprogs
Oh thats crap, from what I saw most of the good ones were officers and had training galore.

Yeah cause they're always the best xD
The grass is defo greener on the other side tbf π
U lot get SANs thrown at u too, those things are crazy expensive
Sounds like it'll keep u busy like
wipe your pc
what does that do
Ask him if he is a masterhacker
Wanna see the email he sent me lmao
no
it looked proffessional asf
If he was on ur PC why would he email you?
if you think your computer has been compromised, I would do a full wipe and reinstall
idk gang Idk what this shit is he said he was on my pc and came to a understanding as to who I am
just because they said they were on your PC doesn't mean they were
Nah shit's fake. 99% chance he is not on your pc. But to be sure, reinstall Windows
he sent me 3 passwords
(Assuming you use windows)
so a Thailand hacker is in your pc . First question : HOW?
that I use
Could be from breaches
Leaked passwords
so definitley a scare tactic gotcha my bad I really looked everywhere on what to do, I just got a pc
Change all your passwords, change the password of your email. Reinstall windows. And ur good to go π
Yeah I made 2 new emails on a vpn and switched everything accordingly to those new emails
I'd use the opportunity to get a password manager and change them all. Set up 2FA/MFA where ever you can.
(a password manager isn't a person)
2fa is not a password manager
he also sent me screenshots of me playing a game, in tab on youtube
Then, reinstall windows
wipe completely then reinstall
Format your drive
I ran malware bytes tho and it says it removed 22 PUPS and 1 Trojan but I read on quora there is probably something hidden still, if thats the case Ill reinstall rn
malware bytes won't catch everything
^^
Yeah just do that
Windows installation media stick, format the drive
Btw quroa is a load of crap don't take any advice from it
WikiHow?
There are definitely some scummy services which provide that.
Exception, not the rule
Like most of the internet, it's great if you don't mind fact checking stuff
Yep, just pretend it's April 1st all the time
ππ

My pc had a heart attack after it saw the kali iso.
I though I was yet again outplayed.
Windows Defender or?
yea
Mine doesnt get heart attacks from that lol
weird...
Yeah agreed
I had it mounted for whatever reason.
You mounted the ISO?
yea fat fingered it prolly.
That'll freak out defender
I have that too. And when I tried to delete the iso from my previous vm. The VM broke permanently
it indeed does.
Grub rescue!
grub is cursed
Get a bunch of warnings about 'hacking tools'?
defender tried to send bloodhound deb for analysis 
Early and still mostly one-handed. Please excuse my errors in typing.
i have an uncommon question
doesnì't reverse shell knowledge belong to BASIC knowledge?
a BASIC revshell is new to me
im readying an apply for a job and they wrote : Advanced knowledge required : Reverse shell
I'm not sure what you mean by this.
just what reverse shell knowledge is considered
is it not a basic thing?
BASIC programming lang?
no basic "tool" to use
yea 
indeed what is an "Advanced revshell"?
Possibly a revshell that's designed to evade AV, hide traffic in some way..


Jabba! Hi. π
hmmm could make sense.
But tbh im still confused , i read :
Basics : TCP/IP Exploitation, port swigging , network connections , etc.
Intermediate : WinRM exploitation , SMB scannering , msfconsole , etc.
Advanced : Reverse shell , bash scripting , antivirus evasion, etc.
Hello Alt Ez | moo
greetings jabba
Greetings to you Vedrfolnia
Greetings everyone!
Is that for a class description?
no for a job apply , under "Requirements"

Apply. π
Real
i already have a work , one of my friend just sent this to me
Hey Jabba
Wowow real world friends who are interested in cyber sec
If I saw a description like that here, my first thought would be "I own this job now"
IIRC BASIC doesn't have any kind of network library. You'd have to write that first
sadly not existant in my circles
forgor the /s
Surprisingly they are for mine 
Yeah in mine neither
some totally not from THM, noooo
not even close , he was a java developer
ahh
mine don't really care about any of that.
thm is a safe space with likeminded lifeforms 
this job is for : Security Engeneer
seems like all this skills are completely useless for the job you are applaying in
The description looks very watered down.
@hot cairn are you a lifeform? π€
some form at least
@boreal scarab you try PETG fillament ? what temp you have ?
No, only PLA, 210
We are all lifeforms of some sort... I would hope...
a ok. then esqy was =/
bit creatures currently
you just cant tell anymore these days. you might all be deepfakes
watered down is just another way to say sheet
I hadn't thought of that.
@normal fable https://youtube.com/shorts/g2DR2K5skzk?si=ds2wFf830voig-tN
IF this is in Vegas, we're going.
Ya know.. there is a shoot every year.. lol
At Defcon?
Last year it was like $30ish to register.
you would expect a bit more backlash
And you didn't say anything?!?!?!?!?! WE'RE GOING THIS YEAR
Ima dm cuz I'm not sure it's appropriate for THM chat.
@willow iron and @willow basalt shadows profile picture was a commission shadow paid for... the user that made it no longer makes commission art pieces
@rapid merlin yes shadow has had nitro for a long time on discord....
also generally don't send random dm:s on this discord
thanks for answering! was kinda hoping they would still be open for commissions, too bad. srry if dming was inappropriate
nah it is fine
also refering to shadow in second person is fine.... shadow themselves will of course refer to themselves in third person though
ty for clarifying!
gotta love wasting 2 hours writing reports just for someone to look at it for a few seconds and sign it. Almost like it's unnecessary work to begin with...
only until it has more storage
Sry for sending dm + ty for info β€οΈ
Gave +1 Rep to @sand trench (current: #4 - 1719)
chat.
Nice work π
thx
Did you build in an option to throttle?
what do you mean
Is it faster than RustScan?
Option to limit packets sent/time.
Or is it just 'you get fast. That is all'
#room-help for help with THM rooms.
You've been asked far too many times to use room help for help in rooms.
okay
no
That could be important in some cases. I've had to limit speed on some THM boxes.
@rapid merlin please interact with the community more before self promotion
Caller: May I speak to <my name>?
Me: May I ask what the call is regarding?
Caller: Absolutely. (hangs up)
π€£
definitely scammers testing that the number is valid
No wonder I keep getting telemarketing calls. I pick them up waiting until I finally get a actual call center scammer so I can waste there time but they hang up. Bummer
Prolly sold my number 
Or is using a spoofing call bot
Sometimes I just use my best bot voice and say 'hello' every few seconds. lol
Kali 2024.1 sure does take a while to install..
Should I get two 4tb NVMe drives? Hmm..
sending much love from Moldova π²π©β€οΈ
Is there anyone here who works as a SOC analyst
Im asking cause Id ask what their job is like
How does their day usually go
Ever wondered how SOC (cybersecurity) Analysts REALLY work from home? Are they living up to the expectation? Well... Let's find out!
Cybersecurity Certification Study Resources
CISSP Study Guide - https://amzn.to/3LmjOLM
CISSP Practice Tests - https://amzn.to/3oreDRO
Security+ Study Guide - https://amzn.to/3mTGPwg
A+ Study Guide - https://amz...
Yeah, just wanted to chat with someone directly
I do
So what is it like?
I work part time SOC in the weekends
You just like top/htop Linux systems and check how the machines work and check log files?
Tickets?
I should look for a part time SOC job..
in what way, for me it's been pretty chill, weekends are typically low alarms like 3-4 that I investigate when they come in
What does an investigation include?
Diving into servers/PCs event manager/log files?
Using some tools like wireshark?
figuring out if the alarm was triggered because something malicious or not, if it is, see what have happened, do we have to do something to mitigate and fix the issue or was it blocked after it was found
When I was an analyst. First thing is the shift turnover, check alerts/tickets, see what needs to be escalated, and answer emails.
I use microsoft tools only for now
we use tools that work from event logs to make it more readable and in one place, sitting in a SIEM
Next check the recent intel of new attacks, apply blocks for those, and then it's SIEM for most of the day depending on what is critical.
Lunch, check emails, more tickets and alerts, write up reports, more documentation on incidents that need to be resolved and finally shift turnover.
I personally does engineering on the side when there isn't alerts
But mostly your job is observational, consulting and communicating with Incident Response etc.?
And customers*
yes
I don't talk with IR cause I am IR
I do all from monitoring to analysing to responding
Any help to get TCP flag from borderlands room?
If you're a tier 1 or 2 SOC analyst, you operate as Security Helpdesk and do a bit of everything.
I watch my email where I get notified
go for it
Maybe I should do the SOC tier 1 beforehand
the worst they can tell you is no
Path on THM
True, but I am afraid that I might not do my job well enough
I mean I work mostly well without pressure
as a tier 1, you're expectation isn't as high as an engineer, who will often have more technical knowledge.
Like I said, you operate as a "Security Helpdesk" moving tickets around to the right teams, watch the dashboards to escalate alerts, and do investigations on your free time to better yourself to be a fit for teir 2.
how points in room works? I see people getting more points than other ? why ? ths
first blood... and so
i usually do a lot of networking security + wireshark checks. Most of the time there are low profiles attacks
ok then we have all the same points , so its not based on time?
You mean something like a customer support account attack or?
Yeah if you apply and they hire you then you obviously have some value
if some solve first gets more points. prob 2nd and 3rd person
you usually checks for strange packets , sometimes some idiots try an active recon but nothing more . Most of the time the "worst" attack are pishing mails that people working in your office open
Apply, apply, apply for jobs, like shadow said. You'll have to start somewhere and a tier 1 SOC analyst is a nice position.
I'm just kind of worried. You see, my last job involved tackling a lot of customers on a daily basis
I was a Junior network engineer
the work is very chill , the boring part is the networking part. Usually NOC should solve it , but most of the time the requires SOC intervent
They didn't fire me, I left by my own volition
I am a SOC analyst as my 1st job
No less, I was a JNE for a VERY big corporation
nothing to worry about trust me
And I kind of have something like a proffesional trauma because of that
if you are completying room in THM you are way more ovequalificated for the jov
How many tickets or customers do you usually have?
Once I had active 25-30+ tickets which was insane for me
depens on days tbh. In Friday you have the big requests. Most of customers call you for strange shit
Strange stuff", like what? π
You'll have those days where you'll get a lot of tickets/alerts
Most of the time in scale :
-Pishing
-Low Profile malware
-"My antivirus doesn't go"
How do you spot malformed packets though, you obviously must know how normal ones look? Did they teach you that or you knew/had to teach that yourself?
what you want , networking security strange or soc strange? Your choice and i'll tell
I know we have one such room about wireshark on THM
Mine was pretty quick.
I have completed it but still
Both?
tbh you know how a normal packet is too man
if you see a fragmented one you know something is happen
I mean obviously I could look at some normal traffic
it's enough
To make comparisons
if you find a TCP SYN without SYN ACK , you already know that there's something strange
I don't know why it's taking so long.. I gave it 8gb RAM, 4 cores and its on a fast NVMe drive..
Installing from ISO
having a networking background will definitely help you.
Networking :
One guy thought it was smart to create an access list with only his own ip , so he could complete his work faster . Guess how it ended
By others from his team/company not being able to access his or the company's resources?
Disk IO is super slow rn.. 11M max so far...
This access list was done on a router or he just modified file permissions?
SOC .
One guy , tbh one sysadmin decide to download a "ACTIVE DIRECTORY MENAGER" from internet . Moral of the story was a simil noescape.exe, all we had to do was backuping back the system
Yeah, the three-way handshake
Is that ransomware?
as NOC and SOC you have access to it
a very low profile one
Most difficult as SOC , was a guy who opened an email that had an image with a code injection in it. Took us almost 8hrs to understand whats going on.
exactly it is so difficult
Low-profile means low-privilege account or what do you mean?
they have autobackup daily
very bad ones
Steganography?
no one ensure it manually. Not becouse you can't but becouse you need to much time and you need your system back asap
yep, but trust me , it's an unique event you see it
I still don't understand, they tried to hack low-privilege user profiles on the network or?
what image viewer had the vuln of executing malicious code in it?
they sent an email with a banner of the company
the banner had the code in
so I found out its a Sextortion thing happening to me, he sent another email and the ransom doubled
they encrypt the file in the system
pretty sure he just tryna to scare me now
Oh, so they encrypted uninportant files that had privileges that most users could access?
right but just that by it self doesn't do anything, whatever's loading the image must have executed the code - I'm just curious as to what it was
hey guys im applying at montclair state uni
By low-privilege you mean files that most people can access and high-privilege is data that few can access?
Good luck!
some fucker from thailand he said he has full control over my pc but he is emailing me why doesnt he just leave a text document on my desktop?
they have a general CS program and a combined MS/BS program for cybersecurity
which program should I shoose?
*choose
One that suits you.
What OS are you running?
How do I check
Run a full-scan on your PC from Windows Defender and/or anti-virus suite that you have.
I did that, got 22 PUPS
and quarantined
in the email he contained 3 of my passwords and a screenshot of me looking at a mod menu website
Oh.
he sounded so proffessional in the email
What does he want, money?
I really dunno what would suit me...I'd like to pursue a career in cybersec but i dunno much about what degree employers would preer
im struggling explaing it in english. This virus encrypt some unimportant sheet on your pc , disable task menager and create a lot of files on your OS.
To solve it you licterally find the "disable" file in systems file , delete all the files , delete all the process and delete all the new users
and very nice
but backup is way faster
he was super nice, yeah he wants 1000btc or hes releasing all info he could "possibly obtain" to the public
it was an ip grabber who try to grab every ip you interact too
Contact your police/digital police department.
trust me , difficult to find , stupid to delete
Sent them his btc address and email address
low profile = sheet one
If you would like to prevent that or are worried, the best solution would be to turn-off your PC and Unplug the HDD/SSD and get a new one with a re-installation
ah right, so it was just a URL to the malicious server that logged the IP of who tried to load it
a very bad work tbh , but on the moment we were :"wtf is going on?" so you always think the worst scenario
some people say hes just trying to scare me because why would he email me but some are saying that he might just be bragging about this stuff and be some kind of egotistical "black hat"
and it was a mistacke
Potentially Unwanted ProgramS
He wants money, that is extortion.
So he def has everything he says he does?
that makes sense, better safe than sorry
I changed my emails and passwords and enabled 2fa
Extortion - When someone holds something yours that they should not hold/possess and use it against you.
Potentially unwanted programs.
If you have an upload pfp functionality and it lets you use custom URLs, that's one way of seeing who views your profile
What have you been doing? When did these pups appear or what did you download/visit?
If I was to get into CS, would I be able to combat this in the future or is there nothing you can do? And the only time I accidentally opened an email saying I won a giveaway because I mistook it for a game giveaway I entered in
surely more interesting than "i disabled my antivirus how i reactivate it?"
just any URL pointing to the the attackers server
you could also try for a CSRF/OSRF if it supports actions via a GET request
as thats how the image is loaded
nono , its an URL pointed to attackers server. Every loaded IP was sent to them
he said in his message "I tell you if you want to avoid this learn internet safety rules and steer clear of dubious sites" word for word
please help if you can :/
#resources message
this is a live demonstration of abusing it to perform actions on site
and tbh is way easier to create than you think
Bare in mind any sort of hacking back is illegal.
yeah its interesting to know for sure
really?
Not even if he has information you cant like hack back to delete your info?
Yes, it's blackhat material.
noice so Im fucked just because I accidentally clicked a fake email
Did you download/run anything or just browse to a site?
browsed to a site
then you are probably fine (provided you have an up-to-date browser), unless you inputted any sensitive information obviously
i downloaded a mod menu a week ago but when downloading it it didnt say anything was wrong with it, usually on any site i go to my antivirus flags like crazy but this time it didnt
thats only other time I did something fishy
I had pics of id and ssn in my google photots
Mod for what?
how would I know if he is using my information? like start getting called by police or randomly get swatted?
Mod menu for some game I think
I forget the game
guessing random emails/numbers is something that does happen, i'd just block them tbh
if they start/continue to harass you, then contact local police
Can I send you a small bit of what he said like the part that worries me? its not a link you click on im sending a prntscreen
maybe a zero day (99% its not ) but who knows these days
nah , no way
am I able to put prntscreens in this chat or will I be banned
Are the E-mailing you from your own e-mail?
my friend looked at it he said it looked fake af but ive never seen it before and it looks wild
no, its from some Dorthea
if scrubz approves π€·ββοΈ
wait im no getting it , a guy is sending you email where he treathen you?
yes but he also in the email sent me a picture of me on a website of my screen, and 3 passwords I regularly use
Ideally, I'd rather not members send each other such content.
Just incase.
What If I copy and pasted or typed word for word?
some APT member was bored 
a picture of you on a website of your screen. So your personal photo?
Not in this server then, @rapid merlin if you want to you can DM me it
or the screen of your pc?
the screen of my pc
looks like as if I was in a discord sharing my screen on a website
he got from the taskbar to the tabs
so , hipotetically this guy as a meterpreter session in your pc , right?
no becouse 2 are the things :
- you installed a trojan
- this guy exploited you
now3
Was about to sat something dumb but nvm
Trojan makes more sense
kinda strange someone use a reverse shell on you and open a meterpeter session . 1 ) becouse its difficult af doing it on new OS 2) becouse : "who get so much effort for a random guy?"
so you installed a trojan
you go on your task menager >>> you click Active >>> you close suspicious process.
You reinstall Windows and you change your passwords.
Et voila , you are safe.
Then you take these screenshots with email he is using and you took it to police
@rapid merlin
simple and effective
is it possible he found my email off a data breach and he only has passwords to my emails?
and hes using to scare me?
and how he get the screenshot of your pc?
Change passwords, but beforehand double-check that the recovery-email hasn't been changed, and turn on 2fa wherever you can
maybe when I opened the website something autoinstalled and tooka picture
he found your email in some shitty dictionary , and did some useless bruteforce
like scsys whatever its called
surely you have it saved in something and you forgot about it
its 99% a trojan
but for real man , do steps i wrote
AND BUY AN ANTIVIRUS
trojan in 2024 shouldn't exists
That will just make me safer in the future, if he has my info like social security i need to focus on getting that back
XSS shouldn't exist in 2024, but here we are π€·
sure but atleas XSS requires some knowledge , trojan can be blocked by every antivirus
People will always try piracy and get infected this way by trojans, it still works because it's people will still try and grab stuff for free.
An Anti-Virus is only as it's good as it's database...
how you get that back ? if he saw it he has it. Just go to police and nothing happen , simple
so this isnt that serious?
Most probably he is a 12 years old who downloaded :"BEST TROJAN.EXE"
I like how you assume it's a he π
I barely use the internet and this happens
follow steps , go to police and gg
By your logic, this shouldn't happen.
a 12 years old girl usually its more mature
by my logic not everyone has an antivirus
unfortunally
girls are all smarter than guys.
Windows Defender would like a word with you.
im not talking about you , but about him
oh oh my bad
im talking about real antivirus
I thought you saying im dumb for whatever i visited which I agree I am dumb for not being more careful
Windows Defender of today isn't the Defender of years ago.
I know hes from thailand though
thats all I know he accessed a steam account of mine from a thailand ip
There honestly isn't anything you can do to "get that back." contact LEO, and if you are underage, let your parents know.
yeah but windows defender its not norton. If windows defender allow a trojan of a guy "WHO EMAIL YOU BACK"
well
no more to say
What is LEO
Change the account passwords, go through the platform recovery, and dont' re-use passwords. That's basically all you can do if you get hacked.
surely not the best hacker in the field
I use Bitdefender and it expires soon so I'll renew that or something else
Norton is worse than Defender.
Do you have any sources to back all this up?
I'm surprised that word isnt censored on here π
norton itself is a pup 
after reinstalling windows I can log back into all my stuff? its fucking creepy he can take pictures somehow
Noroton is not worse than Defender. My source is :" this guy have a trojan on his pc sent by another guy who emailed him back". I mean
idk
My Malware-Bytes ends in 30 day(s), that's when I upgrade to include the VPN etc.
this says it all
Im staying logged out of everything on my pc
Not a valid source.
It's an isolated instance.
Isolated but real. An Antivirus in 2024 can't let this happen in any way
Unless you know, it's not in the database.
An anti virus is nothing without it.
if a trojan is not in the database means its created by someone who actually know very well what is doing. That one guy , surely doesn't email you back. For obv reasons
you'll never know.
You're certain it's a trojan.
its a meterpreter session?
Have you seen it?
what are the odds a guy who emailed him back performed a real hack?
no but i use logic to go by exclusion
So youre providing nothing but opinions then?
lmaooooo
im trying to fix the poblem , this is what im doing
what is LEO
Maybe VNC viewer ? Logged into a free wifi network with a weak password which could get brute forced .
I mean, you think you are...
and I should only worry if he sends another email>?
I swear, everytime I play Fallout 4, everyone and their grandma is pinging me on discord, on steam, pigeon carriers...... 
hehe
Right click > mute.
with the information he provided to us there are 3 possible ways :
- It's a trojan
- it's a meterpreter session
- its a 0 day.
Now , what are the odds a guy , who email you back telling you :"i have your password" , created a 0 day or a meterpreter session?
So , im going for the most obv one.
After i said him how to solve the most obv one i said him to go to police and provid them his proofs
it's enough to fix problem , i think π
then if this guy actually created a 0 day or a meterpreter session , well , unique cases exist
maybe he was a genius then he broke his head and become an idiot , who knows. Still better go for the most obv one
I dont try to be annoying when I ask this but off the info I shared is it sound like he is trying to scare me into paying or if he actually has info and knows what hes doing
Have you ever seen a thief come back to you and say :"hey look , i stoled your necklace?"
Same thing. Stay chill , do steps i said and GO TO POLICE
Police will fix your problem anyways and take this idiot
occams razor. The screenshot was probably shared with some online tool and the email in a databreach some time ago.
no need to dig deep.
oooooorrrr
4. A scare tactic
or or or
5. VNC viewer
looks like mine too?
What sort of images do they have of you?
The best one is "I caught you on camera doing X" That's great.......... I don't have any cameras connected to either my desktop, nor does my laptop have a camera 
if you have emails that have a screenshot and some old passwords and you know they are fake i wont care anymore
If he actually has a screenshot of his windows session, they should got it someway
that is a scare tactic is for sure , i mean this guy emailed him back
not the sharpest knife
I have pics of you > Is this E-mail active
Reply > yes
he said he showed him the picture
he said in his email he doesnt reply and wont monitor replies
if he just wrote :" i have picture of you" , for sure , its a scare tactic
he said the only way to resolve this is to pay him 1000$ btc
he sent a picture of my computer
not me
The sad thing is that some people fall for this trick
@sick lance
a scare tactic is :" i have picture of your computer " not actually having it
So they sent you an E-mail to try and get something out of you. but they don't monitor replies?
If they don't monitor replies, how did they reply to your initial e-mail?
yeah he said only way to remove this is to pay him 1000$ BTC wallet, gave me his bitcoin address and said after the money comes through he will delete saved information on me
they didnt reply
Usually it's 'I have a video of you ... having a personal moment... on webcam, and I'll email it to your contact list'
Timezones.
more professional 
This makes less sense as I ask more questions.
This is a classic spray and pray, hopefully somebody panics and sends me bit coin.
I will explain from the start in as few words possible so it isnt confusing
wait im starting not getting it
@glass nest what temp you have on PETG ?
they have a real picture of your pc or they said they have?
bro's yapping

Don't send money. Ever. Disconnect it from the internet, reinstall your OS.
Usually compromises like this happen from pirating software and media.
I wake up this mornign at 4 am to a email from dortheacorelizo, I open it up, 2 attatchments, one is a picture of me surfing the web, the other is a document telling me his demands, in his demands he says he doesnt monitor replies, says dont bother going to police because he "cant be found" and he is "the best in his field"
They did say they downloaded a mod tool for a game they can't seem to quite to remember.
and above the attatchments was 3 passwords I use on a daytoday basis
This is either scam baiting too far.
Or it's a troll.
That's my opnion.
250, but it was a bit stringy with that
hey guys. I was on this room Data Exfiltration and could not get ICMP data exfiltration to work on msf6 auxiliary/server/icmp_exfil. Tried sending packets to myself (both on VM and native OS) on interface tun0 from attackbox and from room's dedicated machine but no BOF packet get received. Strange enough, when I send a BOF packet to the AttackBox and listen on interface ens5 on msf5 on AttackBox, everything is working fine. Tried tcpdump to see if packets are reaching me and they do, but msf6 does not seem to catch them.
Did anyone encounter problems on Metasploit Framework 6 using auxiliary/server/icmp_exfil ?
Seriously, take it off the internet, backup your photos and actually important documents, then reinstall the OS.
#room-help please.
you have coasting and jerk set on ? and/or outer wall wipe distance ?
Scan the files before you transfer them back over to a new installed OS.
i changed passwords and emails, and removed virus
ok
reinstall windows
gg
you are free
go jogging
lol
you dont think this will only piss him off and encourage him to keep following me?
following you with what?
idk hacker mans things
you watched too much films
to bruteforce a very good password you should wait 978 years just to see : "no password match"
@glass nest btw send me your k1 profile file... cura or creality π
you downloaded some shitty file and this is the result. Follow the steps we reapeated you and go chill
An hacker who email you back : it's not an hacker , is dumb as fuck
so chill , you are not in contact with Arkdata or Mitnick for sure
RIP mitnick
He didn't email me back, he sent the first email
π¦
And he only sent one and one only email
enough for being dumb
Ignore it.
Your phone is not rooted, you cannot do that
Ok bet
oh so enum doesn't work without root permission?
basically
thanks
Gave +1 Rep to @shut hawk (current: #14 - 505)
Please don't use that word here. π
Oh I'm sorry what did I say
The r word, it's not welcome π
@sick lance
:hammer: dt.skii#0 has been banned.
Is Thailand have alot of bad hackers or people that try to look like hacker?
just happened to take a break from work at the right (wrong?) time
I happened to look at chat at the wrong time too.
Same 
I deleted the email he emailed me on so he gone he is the hacker you see on the goofy movies you know ππ
I have a Question :
how in the world there can be kids as old as 15,16,17 that are exposing security vulnerabilitys in huge tech enterprises. while some people learn for several years but still do not reach something comparable
You need a rice cooker?
I think I need someone to just keep reminding me of things
But a rice cooker also works
Iβd much rather purchase a razer tkl mechanical gaming keyboard tbh
luck and a lot of work
some people get stuck in tutorial hell thinking they can not do something or are not good enough to do something as they have only done tutorials
Priorities...
where shadows money for new computer???
(source: me)
Iβm actually torn to be honest. My headset works fine but Iβd like a new one
Whereas my keyboard has physical damage and I should probably replace it firstβ¦
I also just spent Β£300 on a new CPU so itβs like do I really need toβ¦
shadows headphones work near flawlessly
I'll send you a dollar π
but they need a cleaning
SteelSeries 
shadows patreon only takes euros.... but good luck
hopping for that luck too
Iβm 90% sure my nightmare last night involved steel series
litteraly discribing me but cant find the way out of it
Is it worth learning cs as a beginner in 2024?
Counter strike?
I abbreviation a lot I'm sorry
help desk customer service???
It's cyber security
according to shadow life is all about learning and teaching others
hey guys does anyone know the issue in #subs-room-help thank you π
so its not worth it
the only thing why it wouldnt be worth it is when you just do it for the money
cs also often refers to computer science, as in the degree program
very vague initialism lol
CS == customer service
what room is that? you're an 0x7 with no cert or special role and the room says No Access ,-,
Yummy chicken
subs-room-help @molten sky
ahhh right i'm not subbed anymore lmao
I only want to learn to learn to protect myself from this BS or future possibly worse attack I don't want money
I dont want to deal with this ever again
ok than its realy not worth it
if that's what you mean, then that'd be like "should i learn to change my own tire?"
,,,,yes?
Welcome to discord
I keep to myself I don't talk shit I don't do this to others and randomly to me it comes
no worries it is the subs room help but I think I have the solution now
nothing wrong with learning the basics of security to keep yourself secure, and anyone who says otherwise is just dumb
there's a reason hunter2 is a meme
cause people don't know the first thing about basic security and then are all surprised when they lose access to their accounts
Fr just chilling infront of my PC an laughing myself to death
I'm lvl 5 now
*oh no I subscribed to every site imaginable and use the same password on all of them. How did I possibly lose it all
*
Yo yo yo
like you can call AAA and wait 3 hours for them to come meet you in the middle of the sticks somewhere or you could just learn the basics of it and do it yourself
I used 6 passwords to 10 different site
Well 6/10
I changed them all and changed all account I own to 2 new emails
like i have passwords i reuse
you're not gonna be 100%
but those reused passwords are on dumb shit that i don't care about whatsoever and just wanna poke around on real quick
just use Google Passwort manager
Oh well the 48 hour deadline when I find out if he's trolling lmao
I did now
use something other than online solutions if you plan to never sync.
Nahh itΒ΄s good as long as you never put in, the same password as your google emal adresses password there wont be a problem at all.(Its free)
and google owned
eeehhhhhh
I hate google
it's definitely better than NOT using one for most people
But I still use there products smh you canβt escape em
but browser based password keepers are known for being..questionably secure
firefox has gotten a lot better with theirs, but google i'm still not too sure about
I don't use any google products directly.
i mean its google. right? .... RIGHT?
it's often just not held anywhere close to the same standards as standalone solutions -- it's an afterthought and a random bolt on for a separate product
To the extent that they're DPAPI
If someone has access to your DPAPI keys that's a real bjg problem
Definitely not. Look into the implementation.
That's not nice
.NET is like a completely foreign thing to me lol but yeah google no good
Oh shoot
It's not dotnet, it's a windows api
I love google π
thought dpapi was .net but you're right -- .net just has access to it
Thoughts on DuckDuckGo?
google password keeper would be barely a step above using Notepad as far as i'm concerned, lol
bruh, why only the link loaded?
eh. it used to be good, but they went a bit downhil imo
I still have them as defaults in some places cause lazy but I find myself having to look elsewhere sometimes
embeds are only a thing after verification
π’ π«
i just got a message on linkedin and i have like 20 tabs of it open doing research and it just went beepeepepeppprepepepepewaoaewt as they all notified
hahahhaha i am feeling you
Pause
Linkedin allways spamming me like shit.
Yeah and they are emailing me some recruiter sent me a message
Like idc
I dont want an email for that
you know you can turn that off..right
Yeah but they still do that
Yeah same probleam just unsuscribed recentaly
i never get emails cause mine are disabled in settings π€·ββοΈ
They make it like you need to uncheck 100's
Did you guys also put way to much information about yourself into your linkedin account ?
mine literally just says Company A Company B Company C
Nah only the place i work at
shit
Problem is, my work does some page with pictures of all employees
But im not on that :))
was gonna say, not part of my JD so nope
not getting paid to be paraded
not your marketing piece
Yeah
Yeah ok this is the difference i am still like searching for oppurtunitis
so am i
I still get recruiters and headhunters in my inbox despite it being vague
some good ones too
how much expirince do you have ?
on linkedin specifically, just 4 or 5
I was talking to my manager today, and said like I am going to look more at the pentesting field. They said like, ah maybe we can create that as a new service here
lol
spread across idk how many domains tho, very all over the place from software to kernel eng to security etc
2 years already. Since im 14 lol
time flies
dont forget your discored bro that you exchanged today some messages with
How can you legally work?
did not get it you are 16???
yee
Idk, its possible in my country
i mean, i was helping around construction sites in the middle of the prairie at like 12 and 13
Im currently SOC
I worked at 14 for a swimming job
you are a high value individum in this field
wdym?
And that's illegal lol. Construction is considered hazardous work in the US.
if you are someday a hiring manager
Yeah, I did too but there were massive restrictions.
in this industry? fuck no, lmao
my level is very over-saturated
ahhh xd
tbf that was in canada
Only expirence in years matters
nope, not at all
depends on the company
I just looked it up, still illegal in Canada.
over here in germany it is like that in most companies and govermant jobs
it's difficult to interview as a generalist a lot of times as well, since many companies want people who are specialized unless you're getting paid pennies on the dollar
when you're not specialized or siloed, companies are often going to defer to someone who is actually specialized in the thing they want
This was for an indoor pool with multiple other adult instructors so was pretty safe
it's a short sighted way of doing things, but it's the way they're done
yes your right but here we dont even have people that are generaly educated (not everytime but this is considerd the standard today)
not sure if it'd qualify as "construction" since you weren't actually doing the construction, same way that an office worker on a construction site isn't a construction worker
but either way, cash in hand in the middle of nowhere so π€·ββοΈ
got pulled off site a few times to beat out brush fires with a shovel
was a good time ngl
Yeah, I'm not saying it wasn't allowed. Just that unrestricted work for anyone under 18 is pretty uncommon in countries with established labor laws or are otherwise "first world."
osha/ccohs be damned
yeah over here it's a bit different
right up around nyc
Agreed
a lot of the jobs that AREN'T saturated want 4 or 5 days onsite in nyc rather than true hybrid or remote, which isn't the most feasible for me at my new spot
This guy is 16 working since 2 years that is CRAZY
I lied, 1 year and 10 months
same thing
pretty uncommon in countries with established labor laws or are otherwise "first world."
lmfao
you must live in the wealthier areas
white picket fences everywhere
How did you end up getting it?
What do you do, if you don't mind me asking? I guess I'm more curious how everything works in, I think you said Germany, and how that works with legal documents. Do you have to get your parents to sign off?
I knew one of the managers. (Didnt apply through him btw)
Nah, grew up in a rural farming community. It's just that the state took minors working very seriously.
Nah my parents didnt had to sign. I had to get a Declaration of good conduct and sign myself.
But the Netherlands
ngl i've also never seen a farm town where the kids weren't involved
Certs?
Nope
Just knowledge i already had
And they wanted to give me the chance (im the cheapest employee for them)
AI trolling me
but it's less about the State giving permission and more about "who cares what the State says" in these cases
if they cared what the state said, they wouldn't be handing them cash off the books π€·ββοΈ
This will likely help a lot in the long term, this is pretty good
Yeah
Cute cat
it does, that's for sure
i assume @rapid merlin is customer facing as well?
hope ' ll find something similar
π¦
Yes
specially Wile E. Coyote π π
yappadapadu
fuck having a mil draft, we need a customer service draft. everyone should work customer service for a few years, lol
different cartoon completly π
mip mip
wrong animal but right cartoon
This guy doesn't have a sound effect
Mostly dynamites
and trying to kill the mip mip

poor Willy
not a single person here has spelled his name right yet, lol
Willie?
Wile
wile e coyote
better willy
Wile E. Coyote I edited my msg π
How is the name of mip mip
the onomatopoeia was meep meep or beep beep
despends of the episode
it doesn't look like the cartoon π
when the tail is raised it has some more resemblance
is someone of you allready married ?
Single, never married, no kids. I have enough problems in my life to keep adding π
true
relationships can be a happy thing too ya know
i barely have time to think, let alone involve someone else, lol
nothing to do with happiness --- literally don't have the bandwidth for it
Guys i don't want to interrupt but is this discord also for newbies like me? I mean, is it possible to find help with some things? Or is this server more for people with experience
to be honest i just wanna have kids
have them and raise them?
~~ you aren't allowed to use discord until you have OSCE3 ~~ yea ofc you're welcome here
yes like it is so beutiful
he uses discord. that's impossible.
look at my profile
certainly they can, but you have to look really hard not everybody is lucky and get it on the first try. I really don't have the strength I only had 3 major relationships in my life, after that it was a string of dates and very casual relationships.
Okay thanks cause i would really need some help with literally everything, not now ofc , im just so bad at this stuff
Gave +1 Rep to @molten sky (current: #75 - 82)
of course π
Im not saying you MUST be. Just providing a little balance in the 'fuck no' responses
yup everyone's here to learn just the same
well most people are
But tell me, is it hard to get good at this with 0 background in programming or cyber security?
nobody (except myself) was born knowing everything
gotta start somewhere
dont you wanna raise some very good penetration testers? you can build for them the way since they wear little kids? as long as they want ofc
Knowing everything would be the worst burden imaginable
No point hacking anymore, or playing a game, watching a movie, or going on a date.
knowing things is lame, knowing people is how you get paid
depends on how much time you put into, how much passion you have and how bad want to be good π
don't burn yourself out tho
hello everyone
Tons of success stories. But they all passionately enjoy it
And the last question, is learning how to legally hack or anything involved in this is hard on TryHackMe without premium subscription?
100%
most of the site is free tbh
eh not until you have hacked into every major company in the world twice
do the free stuff first and if you still enjoy it, throw a few bucks to thm and do the premium ones
wait, you only needed to do it twice? shit, i got ripped off then
80% the site is free so start get the feel and then if you really like it, you can buy the sub, but it's not required to learn
for most certificates you need premium but if you just wanna learn than this site is perfect
okay this is probably my last question, Where should i start? is there some path that i should follow? Some courses that are really important?
normaly the site suggests a path which is the best suitable for you
yeah but i did the first 3 lessons i think and after that i needed premium to proceed with next ones
nvm i thought #start-here had more info
the site isn't the most obvious about it tbh. it's a business after all, so they kinda wanna encourage people to pay
if you go into the Search tab a lot more is visible
and you can filter free only
tommoro i will go to hard exam of cybersecirity and i dont understand anything about reverse engineering i want someone to help me to answer any qustion i send
just buy premium it realy is a good price for what you get
hit up @graceful thistle or @sick lance they're normally avail
π€£
yeah i guess but im not really able to spend $14 monthly on this, i know how it sounds but yeah im kinda broke
we can't help you with this. You need to properly study your coursework and do the exam based on what you learned and know. Good luck, study hard.
yeah so do you have any sugestions where should i start? Or just to click random free courses and learn with them
if you are a studnt its only 12.60
if he can't afford 14 he can't afford 12.60 lol
For real xD
If you can't afford it, then just enjoy the thousands of hours of free content.
Especially that i don't know if im going to like it or even understand it
