#general
1 messages Β· Page 171 of 1
Not that bad
That doesn't overly stop malware from bricking your system
It's happened before on a number of occasions
itch is not like Steam
It's all indie creators
I've had a look, and only seen posts where some trojans were found on itch.io, but they were all in password protected RAR folders, which sticks out as obvious to me.
Oh yeah sorry, I should've explain what itch io is.
It's basically a place where you don't have any QA overhead to upload your game/project and it's free to use.
The downside is that no one checks if what your uploading is actually a game or just malware.
From what I read, they are going to ban password protected RAR files out right.
Pirate Software was given malware as the output of a gamejam and has gone on record about it
Oh that's good.
I need to watch more of their content it seems.
Like I'm just saying you absolutely shouldn't rely on a third party there to protect you...
Oh really!?? I should see how he handled that then
VirusTotal etc
Right just have some basic static virus checking helps got ya.
thanks for the help guys I'm gonna look up that pirate software video
β€οΈ
Use GPU passthrough, if capable
You can be fed a crypto miner of course, and it would work in this case. But still
Combination of things will keep you safer
Overall it's rare to get GPU hungry application on a game jam. But they also not optimized at all. So you might need a gpu
Fun fact, many of those "can you try out my game" scams on discord would give you an itch link.
heyoo, does anyone here use ZAP proxy as a fulltime burpsuite replacement?
Depends!
I use burp pro, but for ctfs etc -- zap
got it
do you have any resources to help getting started with burp, setting it up and integrating workflow?
that's the thing, zap does not
Ah, getting started with zap, you mean
i have been looking all over for zap resources
yeah
My first intro was in THM room on zap
And i already was familiar with burp
Then you just click around and read KB for stuff like replacer and other plugins
makes sense, thank you
My main reason to use zap was:
- to learn it and not be locked on just one proxy in terms of proficiency
- no rate limits on stuff like intruder
whatβs the best resource that helped you master IDOR vulnerability?
can anyone share their best resources and learning strategy please
I wonder why this would happen:
DMAR: Intel-IOMMU force enabled due to platform opt in
uefi setting?
Hey guys...
Just a quick question. π
It may be dummy question...
hello
What reading have you already done on the topic?
I don't want to tell you what you've already seen
I just came across this term while surfing my Udemy. I have this course in my library there π The Complete PLC Programming Bootcamp
Never heard of that, I will look into it.
It depending of the GPU intensive stuff, in a community I help run there are people like me who write there own game engines. So it's hard to tell if I'm being fed something bad or good.
The community is very small still so I have a low chance of it happening but it's better to be safe than sorry.
But I have no idea what it is
Did you google it?
Stay safe!
A programmable logic controller or programmable controller is an industrial computer that has been ruggedized and adapted for the control of manufacturing processes, such as assembly lines, machines, robotic devices, or any activity that requires high reliability, ease of programming, and process fault diagnosis.
this much from wiki π now I am more confused :
will this PLC be useful in cybersecurity too?? π€
Securing PLCs is very important
stuxnet moment
hehe.. then I will start that course too and get some idea about PLC.. π
Thank you β€οΈ I will try β€οΈ
Gave +1 Rep to @jagged moon (current: #12 - 565)
Expecting malicious code goes a long way already
Rather than blindly trusting an itch file
I need coffee
Thanks π I will solve this problem one way or another
This would make a funny CTF challenge
That's easy to do in C :p
If the null-byte vulnerability has been fixed in php, what else can we do to bypass the appending of *.php?
3 attempts to launch Discord from Startup, GG Discord.
C Programming isn't all it's cracked up to be boys and girls.
IT TAKES GUTS. GRIT. DETERMINATION. SELF HATE. LUST?
π« COURSES π« Check out my C Programming courses at https://lowlevel.academy
π SUPPORT THE CHANNEL π Become a Low Level Associate and support the channel at https://youtube.com/c/LowLevelLearning/join
Why Are Switch Statements so...
guys,
how to automate hack wifi
@sick lance would you like to answer this?
Wdym?
Which Wi-Fi are you hacking?
WPA PSK
Ok, who's?
who?
Yeah, who owns the Wi-Fi?
hiya i'd like some advice so ive been using tryhackme for the past month and ive learnt a lot but im getting tired of it are there any other similar platforms which i could use to learn more? or perhaps practice
wifi around me I don't know who has it
So you know that would be illegal?
There is plenty of other resourced, hackthebox, vulnhub, portswiggerlabs etc.
Is there really a legal wifi hack?
do you perhaps have a list?
If you own the router, yeah.
I just gave you it... π
im sorry but how old are you?
you do realize cybsecurity specialists break into stuff with prior consent right
if you dont gain permission from the owner of the router it would be a crime
It is?
Leave it to the mods please
If you don't know, just say you don't know
I do know, I know it's illegal.
sure go ahead
if i were you i'd just ban them they're obviously a troll a low effort one at that
You're obviously asking on the ground on black hat material, which is what we don't teach, or promote in this server
Good job you're not me then. π
It seems like you don't know about pentests
Yeah you're not heh
Yeah, but that's contracted.
What happens when you encounter something, for talking sake.
A router that is out of scope, do you hack it?
You're taking what I say completly out of context, which is a low ball troll effect.
Hacking != illegal/unethical.
Black hat hacking is, and this server is not for that
low effort trolling tsk tsk
Anime pfp
Ah, so you're raising points that you don't know, then declaring kid.
Good bye π

pattern recognition is built from experience
scrubz certified master troller confirmed?!!?!
lmao, that was interesting
master hacker
they also definitely don't understand the legal differences between hacking the "wifi around you" and a contracted pentest with a given scope
missed opportunity honestly
they def wouldve fell for it since they have the mental capacity of a toddler
grrr you look like you look like you have a stable well-adjusted fulfilling life !!!! gottem
damn, you got me π
π -- master hacker (me)
Still is.
Ideally, we'd like members to join, know they have asked the wrong question in terms of legality and or en-ethical behaviour, and want to remain in the server and learn a more legal and ethical approach.
fair enough
As mods, we don't like banning people right, left and centre because somebody doesn't know any better.
Yeah I'd generally agree
I mean they'll get banned if they keep at it
I really want to reply to that π¦
How do I turn on my PC
"Happy hacking people"? Or "happy hacking, people". Or "happy, hacking people" which the 3rd one is pretty close grammatically to the 1st π
hello all recently I made a question on Reddit that doesn't attracted a lot of people and thus my question has not been solved so I am expecting to post it here maybe some of you know the answer. Excuse if it is against the rules to post content from another source I don't want to spam if its forbidden, I will delete it. Here y can find the question thanks in advance https://www.reddit.com/r/hacking/comments/1clh6dm/can_a_buffer_overflow_attack_be_executed_on/
@steel aspen You're up buddy ^
I'm gonna pretend I know and then say that's up to the mods π€π
ASLR isn't perfect
https://book.hacktricks.xyz/binary-exploitation/common-binary-protections-and-bypasses/aslr
Given it's a demo in a lab environment, I suspect they've turned off protections as well
I really need to add hack tricks to my bookmarks and give it a read
ASLR makes it tougher to predict where stuff is in memory, but it doesn't shut down exploitation entirely.
Where can I learn fully about aslr. Hacktricks got a good read on it?
Guessing also YouTube
Lol I just linked the hacktricks page
Good read?
Depends how much you know already
The leaked pointers etc are often how Source games like Counter Strike get exploited despite having ASLR etc
so even with ASLR and fstack protector on it is still possible to perform a buffer overflow attack but its to tougher
Yes, hence why it's still important to write good code
Exactly. Even with ASLR and stack protection in place, it's still possible to perform a buffer overflow attack, but it definitely ramps up the difficulty level. ASLR and stack protection add extra hurdles
@sturdy yoke Hey, please don't send big walls of text here like that. It's spam which is against our rules
I'm going back through past modules and taking notes
and I'm starting to understand the content a lot better
and its clicking a lot better
F-35 supremacy lol
What's your preference in appearance? The F-14A Tomcat or the F35 Lightning II?
good timing im having trouble using burp suite
i cant access any webpages using the proxy event log showed certification issues which i resolved but im still unable to access any webpages its just stuck on loading
Turn intercept off
The port that you're trying to connect to isn't open, or there's another network issue
F-22 Raptor
this room is really messy it seems to gloss over important details and ruminate over the most minute nuances like i can figure out the components on my own
the latter im assuming ugh ive been trying to fix this for 30min now
Generally get stuff working without burp
I remember this room can be annoying, but what James said works.
Open the website, then open burp.
If you continue having issues like this, please ask in #site-support
yeah one sec ive restarted the target machine gonna use another ip
10.10.239.111
can u access this?
otherwise i think its a browser issue on my side
yeah im stumped off to #site-support i go
Yup
Why does scrubz have empty png as pfp
What is the strategical advantage behind such decision
is funny
a quick question what is the best usb drive type fat 32 or exfat or ntfs
"Best" always depends on usecase
for file transfer
Doesn't matter much
Google the differences and make an informed decision, that's my advice
was there ever a non-perl exiftool?
because i swear i had one where i could just drag files onto the script
found it nvm
Halo
Share the wealth
https://exiftool.org/ the .exe download, for windows
A command-line application and Perl library for
reading and writing EXIF, GPS, IPTC, XMP, makernotes and other meta information
in image, audio and video files. For Windows, MacOS, and Unix systems.
in linux yu have exif tool in terminal
keep doing the rooms.
Bro give me good advice for first time
heap is going to give you!
Discordians is wild
matt... so ienable something in slicer that turn my prints from 2h to 13h, and i do not know what i did =/
You asked this before
IDK why you're asking me, I just use Burp Pro and do stuff manually
there is not plugins direct for we app. might not direct for it. if you have zsh shell and use ohmyzsh, you have this
https://github.com/ohmyzsh/ohmyzsh/wiki/Plugins
I think that doing it all on your own is way more rewarding
true. but there is no harm done if you use some plugins and so to help you. some results and so kinda need some complicated regex and so things that some sraderd with comunity in order to help thigs go fast
Automated tooling misses stuff too
tminus 1 day
well if you wanna slow down your shell start up time be shadows guest
Not what I mean at all
true. if you do use shit load of plugins then yea
nah you only need about 1-3 plugins from ohmyzsh to get a slow down
i have few enabled
so i did not notice some slow down
shadow no longer uses ohmyzsh
and they have noticed a huge speed boost
now i wonder if i enable all plugins, waht time will be =/
-undelete -a
most of them are useless too
yea... that was bad idea...
So bored
do 10 pushups
25 slow and controlled push-ups, close hold to focus chest
i like one when you spread hands more far. aslo slow and controlled. for me it kills
that would be more back
I said bored, not "I wanna be in pain" 
close are called military press ups I think?
in a diamond pushup your hands are next to each other
Correct
Rookie numbers 75 more
Hello, is there a policy about straming paid learning path on twitch ?
@near hawk might give you hint
Youβre fine to stream a learning path/subscriber rooms. Youβre not allowed to to stream any education/private rooms or challenges that have been released under 72 hours
If you plan to have a VOD after the stream you canβt use any if THM graphic content as a thumbnail
Discord and Website are separate entities
yes. just ppl do come ehre to fast answer
Ok thanks !
Gave +1 Rep to @near hawk (current: #60 - 116)
imo it would be better to put it on the website itself as we cannot enforce rules privately in here and expect everyone to follow them when they aren't in the Discord server π I will pass on the feedback
website will also work indeed
@boreal scarab i sand it as best i know and clean shits... only some nice paint job is needed
I'm surprised it hasn't already been thought of
Not using TryHackMe graphics is copyright law and the 72 hour rule is only specific to discussions in the Discord server.
There are no other rules when it comes to challenge rooms, hence why there are none of them website
π
Chan the title of the vid contain Truhackme in it ?
Yes
thanks
Gave +1 Rep to @mossy river (current: #6 - 1238)
Chan is crazy
@mossy river I have a simple question i have a keystore that stores some sensitive string data and also I have a keystore passphrase in a string that I pass it as CLI argument in the Java app and store in memory. If a hacker has a reverse shell on my PC is he able to retrieve keystore passphrase from memory? Is it inevitable to protect it? Assuming the java app does not communicate with any server or third party.
Don't pass passwords etc in command line arguments
@naive violet how to load the keystore passphrase then?Any suggestions?
Sorry, I don't yet offer Secure Software Development consulting
according to your experience what would you do in that case
Is this an application for your work?
its personal application not for my work. maybe i will release it as open source project on git i dont know
Common Weakness Enumeration (CWE) is a list of software weaknesses.
Hey look that's even a Java Keystore!
ooooo good job my friend that's exactly my case i read it very useful so if i understand correctly it's inevitable to protect a keystore passphrase
from game Darksiders. The death, one of 4 horsemen of apocalypse
-storepass can be an env var or a file too
Not much better than passing it on cli, but better
Chmod 400 on file, and it's already much much better
perfect just one addition when i read on memory storepass string from file and save it in memroy would be better to use this?https://docs.oracle.com/en/middleware/idm/identity-governance/12.2.1.4/omicf/org/identityconnectors/common/security/GuardedString.html
This is due to cmd line arguments being stored in /proc
Not due to memory anything
@molten sky TIL there used to be an East New Jersey, and a West New Jersey in the 1600's
Additionally, if the call to keystore with cleartext pass as arg is in java program -- it's easily decompiled back to source
I wonder if you can use standard usb stick as 2fa
I'm a senior penetration tester
For windows you could probably access the WMI to check if the USB is plugged in, and then get information about it that you could then use....but why? And that information could probably easily be spoofed (this is just from a quick thought, don't quote me on that)
SOC security engineer, monitor and response
and Internal IT responsible
Ordered Starbucks, haven't in a very long time... I'm sorry. How can you fuck up a NEW JERSEY BAGEL so badly.... thing is so thin
Or.... put crypto key on USB
that....also works
Not really. Just pay for yubikey or cheap alternative. You not getting full protection with workarounds -- due to ability to copy
Imo, tho
Gib hugs
you can make one with a pi pico iirc
Yep
How much for pico these days?
could not trust my self not to lose it
3-5$ IIRC
Niceeeee
i am thinking of something else to save in the file with Chmod 400 the keytool passphrase and then read the file and store the plaintext in GuardedString which is saved in memory as encrypted and when I am done with it garbage collected. Will this be better?
yeah, 5.5$
Yes. But i am not a java dev, consult someone with expertise and experience on top of that
a
You can use file: construct in the arg though. So no need to read to var, really
I am so sorry
it's pretty fun
BOFs?
Until it isn't, and your eyes are completely red
it's better than forensics
Want to learn hacking? (ad) https://hextree.io
π₯³
Lmao. Tru
@boreal scarab
=/
Who are they?
and i wish to print this in glow in dark
https://www.printables.com/model/75075-lovecraft-chess-set-v2
Hello,
I'm interested in computer security and I would like to know if a career in computer security and penetration testing would allow me to travel abroad (have assignments) while working for an international company.
Often, although I think less than before covid

how can i turn off winlock
An example (testimony) ?
An example - my seniors used to get flown all over the world for in-person penetration testing including oil rigs, luxury yachts, and far away countries
we get flown out for big competitions at the same places^
I've been on site but not international yet, and some of the work that'd usually be on-site in-person has gone remote as they've seen workers can remote in etc
Flying someone out and having them stay in a hotel with meals paid for is rather expensive
Okay, but is it less common currently?
In my experience, it's been a lot less common after covid.
why do people doesnt take it seriously when i tell them i want to be a hacker, they then joke and talk about hacking pubg and getting modded stuff and all
Still happens though
Because "hacker" is a charged word
There's a lot of meaning behind it, especially with the media still calling cybercriminals hackers
security professional
Too broad
SOC engineer
Also wide
I guess thereβs a higher chance of travelling when you join a big consultancy (the big 4) that has international offices
i used terms like cybersecurity and all and then they ask whats it about, and after listening to which they go back telling me to get themselves unblocked from their exs number, like Bruh be serious π
of course i joke back
but still seriousness sometimes is missing
Yeah that's why the job title is "ethical hacker" or "penetration tester" or "security tester"
Counterpoint - they already have people in those offices to do that work.
dont get me started on the term 'penetration tester'
π
It's fine if you're talking to someone in the industry or with more than a 14yr old's sense of maturity.
listens to music
music plays a high pitch winding up sound
Thinks it's my server powering up even though I haven't touched it

You haven't lived until it spins up to full at 6am and doesn't spin back down!
me dreaming to become a badass hacker after watching a movie in which a 14 year old hacks the whole school and alters his marks
2 years later...
on my way on suing bollywood
wait till you start hearing it without music, then the fun begins
What for?
@royal shuttle
Please dont advertise any job/recruitment offers before speaking to the admin team please.
Hello guys, I hope you all are doing well. I was wonder if someone can tell me how can i get mentor in Try hack me?\
those were more real than central
Guys, what you recommend for my router, set the channel auto, or set it manually, May I have some Wifi problems, It is not stable.
Any concrete in your house, metal walls, a "faraday" cage around your router?
Have a look at what channels are in use
See if auto is doing it right
Set manual if you know how to look which channels are in use. Otherwise auto
Oh. James got it
No, But I connect to it from far away, From another floor
May want to put in a repeater
See, my IT Support experience really coming in handy here 
Gpt?
Alright there ChatGPT
Seems
Would 2.4 ghz network work better in these conditions, if dualband?
Degrades less, right?
Yes, 5Ghz can't penetrate walls like 2.4ghz can
Is it good idea to install kali linux as dual boot of windows 11?
Why not?
Please don't use gpt to farm karma or provide answers. If you have sufficient expertise on the question you shouldn't need ai anyway
When setting the router to choose the channel automatically, how does it choose the best channel?
VM more convenient, unless your laptop/pc is a potato, imo
Usually, checks channels. Picks the less busy ones and more suited to band, iirc
I hate adhd
Depends on the router, though, i guess
I planned on doing dishes, put together the dishes I had laying on my desk, went to do dishes, did all the dishes, forgot about the plates I had on my desk
π
Your problem is more likely distance and obstacles that degrade signal, not channels
and now I don't have the dopamine to do the rest
The router scans for less congested channels and selects the best one based on interference.
@lone plover if your router supports it. I would split the WiFi into 2.4ghz and 5ghz. Connect to 2.4ghz, if it's still flaky, add a repeater.
Well you're in luck. I had to install 2 in a client's house. Bit hefty in price, but works. Mind you, 2 needed to be installed.... 30k sqft mansion
Give me 1 sec
Are antennas huge and ugly?
Can you not enable wifi calling?
Might need to ask building for permission
True, normally setting your Wi-Fi channel to automatic should work fine without issues.
Antenna's are dope and awesome!
Works with one of two sims, for some reason
Well, if there was a problem with the channel, what are the results, a wifi problem (I mean the wifi gets cut off), or an internet connection problem?
If the connection is to ethernet and there is a problem with the channel, this will not change anything, right?
Can be both. Cuts and drops.
Ethernet is unaffected by wifi channels in any way
Repeater means adding a router connected to my router via cable ethernet?
Then connect to the added router. Right?
This is a refurbished model. But this is what we used
Damn that's expensive
You can probably get away with a cheaper model, we just needed 5k sqft. And we had to buy 2.... sooo lol
Rich people problems
Not persay a router. Yah. You have ubiquiti gear that uses your ethernet connection, then creates a new WiFi to join. But some you got that just sends the same WiFi. And basically boosts it
Isn't the channel responsible for AP broadcasting only? Does it have anything to do with packets transmit?
Oh don't worry they got a bowling alley in their house... and mini golf
Get it
Need
Uh... Military?
how can a rich people have problem tho
That doesn't look like any civi grade stuff. Especially that car.
With the convenience of VM's, there is no need for dual boot these days.
It's not ap broadcast only. Data too
They can have tech problems.... so they call me 
HAHAHA U RIGHT
Relatively low frequency outputs on it though, sad
On SINCGARS?
Even though I'm a civi and not military, I know what I'm looking at when it comes to Military equipment 
1st one is a dish with a waveguide into an LNB, not sure what frequency but I'd guess Ka or Ku
0 designers involved
Don't ask me for specifics, bur military just has that.... feel
Green and brown
Green and ruggedised
Actually Matt, I have some lovely ex-mil kit that doesn't look it
Radar etc parts
SINCGARS operates in VHF
James, I nerded out my fridge and found out that it isn't working properly
Oooooooooh. Got a pic?
so now I am getting a new fridge from my landlord
DAMN MILITARY SHI ??
"landlords hate them. Use this simple trick to get a new fridge"
LESGOOOOOOOOOOOOOOOOO
the best military equipment is the one that doesn't look like military π
HAHAHAHAHAHA
I still hate the whole "military grade" crap
why tho, military grade must be really strong and stuff stuff must be perfect right ??
4 medical grade thermometers in my fridge
Space grade is the new cool
oh my god u right
my taste is tr-3b
Not at all, often means cheapest acceptable
damn u right tho cuz it will use for many
my fav is what DARPA make
military grade means fixable as easy as possible
damn
If I had to choose. Would always go with German tanks, love em. Especially the jagdpanzer
can it be fixed with gafa and zip ties yes? then military grade 
Even in WW2 they used HF, pretty dope stuff back then already
HAHAHA U RIGHT THO
HF also used to mean something different
The Shermans were equipped with SCR-508 or / and SCR-528 if I'm not mistaken
Like, a UHF connector isn't good at UHF, very lossy
but war make technology more fast develop
True, in a sense
leaves a tiny island
All the billionaires have places there because of that
I had one...
Nuclear subs gon meet there after
isnt putin sign the paper that the only nuclear war happen to is to the those who have nuclear too
I'll be driving one.... soon
Nuclear Physics one of my fav topics!
For real?!
Yep, end of the month 
And yes, I'll be sending pics
My lawrd! That's dope!
Tiger. Too easy.
I was just gonna ask
Too easy?????
I don't think anyone here is knowledgeable about that matter to answer your question my G
Most of us don't have a saying in it. We can think and say what we want but is Putin gonna give a damn?
@rapid merlin Please do not troll here.
damn mb if i troll
Bro said earth is flat 
ill stop saying weird stuff
i ask pliss im confuse, the america gov know everything tho
Yah. 1 sec
We're gonna find out
Earth isn't flat my friend
I mean russian nuke doctrine is not secret.
i belive u
We're not the american government
.
It's basic science, I didn't invent anything
they know what we didnt know, do we know what they know ??
Not gonna lie, but preparing yourself (technology wise) for war isn't a bad thing at all.
Preparing as in, thinking how you would support your country by trying intercept or jam enemy RF (for starters).
Think about it
@rapid merlin look verified
Is that a tongue twister? 
More like
i mean the cia or i should call college student for the governemnt to do some research, know some stuff about some stuff
noo XDXDXD theres meaning behind it
Suuure
Brev...this server isn't the right place to ask this type of question, believe me
u right tho
Glad you realized
how to deffense my computer from hacker guys
@harsh surge
(Mind you, VERY "modern" tank)
Security is a myth
We asked you to stop. You agreed. Yet here we go again.
wait wait pliss i stop this time
K
Unplug power cable
That's what they call an M-2020
What if it's a genuine question?
He might be a beginner
I see
Are you a beginner in cybersec?
didnt even learn yet but ofc human is more easy to manipulate
keep all software up to date, keep the firewall up and configured at all times, dont open suspicious links and dont download and run suspicious files
what
Alright, not gonna lie, ChatGPT sounds more of a human than you my friend 
and many more things
They used a Russian hull, took inspiration from M1 Abrams for turret. But.. many smoke/ grenades, 2 rockets that you have to manually put in, no auto reloading.
It's like. All mashed together
Also, don't install 16GB of extra RAM from internet 
copy that sir, u r such a kind person thanks π
Gave +1 Rep to @charred forum (current: #1381 - 2)
HAHAHAHA
Now that you mention.. π€―
i think their turing machine work hmmmm or maybe the chatgpt has advance really far
Happy Hacking, people! Gonna fetch my lunch + β
is this tank prepared for world war 3 ??
damn thats really scary
The questions is, are we prepared for WWIII
i got my plan but i neeed to buy flashbang and smoke granade
since im not in the usa its really hard to have it here
I'm more worried about our critical infrastructure as it is, status quo
damn fr tho
Come by Walmart, no problem
haha
@harsh surge https://youtu.be/uQfgE6nRUV4?si=6-t8xlrlSn7rgxQ4
If youβre ever injured in an accident, you can check out Morgan & Morgan. You can start your claim in just a click without having to leave your couch. To start your claim, visit: https://www.forthepeople.com/TaskandPurpose?s=86%3A2313
The M2020 was first unveiled in October of 2020, during a military parade celebrating the 75th anniversary of t...
damn this is new?? the most scary tank is the one they didnt show
let us go to DARPA site (tell em for study tour :D)
Why are there holes in the turret composite
how can i get ban on philosophy stuff man, i didnt even say some hatefull speech or type anyhting hatefull damnn
hmmm u right tho
is it air flow ??
What area are you referring too?
The giant cutout
By the smoke/grenades?
These?
Yes
its smoke launchers
"Cut a hole in the armor, we need extra smoke!"
Dunno but it's a possible weak point. I'll have to see if an6 other tank designs had these cutouts
Literally a giant hole
Correct, could be used for missle defense
damn if a tank prepared for missile deffense thats some real hard veterean u will not survive war
I asked Tank Encyclopedia if they know
I hope this is a light tank, those holes look like giant 1 hit kills
what about thermite granade guys ?? could it penterate the armor ??
its fun tho
their ballistic missiles that were used in ukraine have a 50% failrate
that should tell you everything
DAMN BRUH THATS CMONNN
feels bad
Cant be having war discussions i dont think β
WW2 is fine (I hope) but csnt get political. Current wars, stay away from. π
we keep our secret close, thats great
Guys, do you mind changing the topic please?
It's not really fitting in here π
Where in the world have you been? π
Bowling
And what about war related topics involving cybersecurity?
With Niko?
Don't you have the discord members list visible?
I'm always here π
Well yah, but ya never talk 
You gotta bowl once a while
xd
I'm not a man of many words π

thats dangerous
if my pc lag because i install kali linux with 2200G 8gb ram is it should happen ??
or maybe theres something else that causing my pc lag with kali linux
the quieter you become the more you are able to hear
damn this make me want to install linux as main
not yet happening but is it not possible ??
i do not understand you
wow, cloud is hard βΉοΈ
trying to setup a server with GCP (programmatically) but it's very overwhelming lol
Sorry Fontaene, just wanna answer 1 last thing then I'm done. @wooden totem M10 Booker has those cutouts styles
I thought clouds were soft π π
Take your time, go through the steps. You'll get it
Yeah, I think its because everything is treated as a separate entity - the engine instance, disk, image, network, zone, scope, project, machine type - and you get so many different options for what to use for each lol
Will really aid your understanding to get it done that way
This always seems more weird than threats found
hello
Please make sure to use appropriate usernames in here π
sure
sorry
is this good?
Well could be better, but at least better than the previous one π
Not really
π
I cant sleep :(
thanks a lot
Gave +1 Rep to @sharp citrus (current: #190 - 32)
π
Goodnight Jabba
@rapid merlin Do you want to ask your question here?

You seem to have something to ask and you sent me a friend request π
https://tryhackme.com sign up and try out the learning paths :)
We are at same level 
Is this a TryHackMe room or other CTF?
I am a little busy at the moment sorry π
okay dont worry π
feel this so much when it comes to having to explain iso 8601 in here and other places
head hurts
iso 8601 is great
Shadow do you know any good cyber quizzes
does the command challenge count???
free
finally starting to feel tired.. so time to go try and sleeps again for the meep moops to the beep boops for the sleepity sloopity sleep sloops
Hello guys. Please I need help figuring out something, too much information online. Has anyone configured purview ? How long does it take from data labelling, to configuring DLP rules ? What are the steps ?
Is it great with out of the box policies ?
What's The Deal With Halloween?
Hello!!! Thank You for coming to my channel, I do greatly appreciate it!!!
Welcome To The Bret Crow Show!!!
My name is Bret Crow, i'm a Composer/Bassist that loves to play and create music, write & perform my own Original music with a looper pedal, add...
Ahat is that song?! I'm trying to remember
Red Teaming
I'm an idiot, that's the Seinfeld theme
@rapid merlin
You have to verify to send images
π
π
Bought this tiny second hand book today, interesting that they had to mention "printed in occupied Japan" π
I've heard of that before but never seen it irl
kinda want something stamped with that
It is from 1949, year checks out.
A Miscellany on the Shin Teaching of Buddhism by Daisetz Teitaro Suzuki.

Is that a Panda waving after 8 beers?

100% yes
I bought if for $4, it goes for $150 on Amazon. π
i'd say that's a pretty good deal
@hot cairn not sure if this has happened to you, but have you booked an Air Canada ticket through another Star Alliance member and the tickets don't match up?
I booked a non-stop and Air Canada has me on a different flight with a layover
air canada sucks so not surprised
It won't let you book with another star alliance member?
we've just always had issues, esp around covid. like nothing was normal during covid but they seemed to go out of their way to screw us over every chance they could beyond what everyone else did
Code share ?
Did they change the airplane allocation?
unfortunately our only alternative out of ewr is United, and guess what, that United flight is actually an Air Can flight code shared
Oof
United is not bad
Better than spirit airlines
Hehe
eh, i'd rather fly ryan
Budget friendly I see
nah just very anti air can
just had a lot of issues with em
my last air can flight they lost my fishing rod both ways
and that's without even stopping at yyz (known shitshow)
If you like endless elevators, I'd recommend Madrid airport as a transfer. π€£
Worse terminal design award probably would go to Detroit airport.
haven't been to detroit. is it bad in a always was terrible way or a post-9/11-security-ruined it way like newark
the old pinwheel design at newark is pretty solid for when it was built, but security had to be shoehorned into each of the spokes and completely cut off the terminals and made everything cramped af
Booked AC through Turkish, I had to send an email and then call to book through Turkish.
Flight was listed on Air Canada's website not Turkish, if that's the info you're looking for
I don't think anything shifted allocation wise Tim
Newark would be another I would avoid when flying between the midwest and Europe.
I've had that happen before, especially when flying on a cheap class ticket.
Atlanta is far from perfect, but has been a decent transfer. ORD Chicago used to be better than it is now. Another year and we'll all have to fly with REAL-ID π
I think, well, in technical terms: your PNR is fucked
I messaged AC on messenger, we'll see if they respond
Iβd call them
I have the booking and receipts from Turkish
Oh I will
The flights not until July
Yeah, I took the lazy approach first. I'm getting ready for bed and don't want to sit on the phone right lol
Apparently BC changed Airbnb rules though
Bruh they responded in French
Oh, there's the English lol
I have a quick question. I found a Github that is obviously distributing Ransomware/PW-stealer. I reported it to Github but it is still up... What other steps can i take for that user account to be closed?
VirusTotal
Not much else just file a issue and commit for it so if anyone looks there they can find out
I mean Windows Defender catches it as you download it. EDIT: Its all detected by MS-defender thankfully.
is it actively being used maliciously or is it just there
cause you can certainly store PoCs and stuff
Hey
Nothing. You have done your due diligence. Any action you take that could be considered an attack beyond just notification of relevant stakeholders (in this case, github) would be vigilante-ism. And that can very easily poison any legitimate evidence gathered by LEO if action needs to be taken. You are best served by reporting and moving on
hi
Hey everyone π
morning
hello, im new to this. anyone interested in showing me what they can do? i would love to learn.
what would be a good online site to view image metadata like exiftool
ngl i google that every single time cause i can never remember any sites for it
i use exiftool whenever i'm home tho
I tried many Google sites
it's not giving the gps
by the way what does profile id timee means?
weird. are you sure it has geo loc? just to get the easy one out of the way
just tried with pic2map.com and that one worked for geo
profile date time is probably just when the photo was taken (or made), no?
I'm not sure
not sure what else it'd be. looks like the date taken
or is it like this image was edites by any software that's why not showing geo
editing software should leave that data intact unless instructed otherwise
*should
a lot of services strip geo loc when sent though
i.e. discord
There's not always GPS embedded
does that profile date time mean it was taken in 2018?
well it would imply it, but anyone could change it
Yeah I got it now, I tried checking another image from my phone and it is showing lots of information like phone name, gps
I Don't think in my friend circle there is many people who even knows what is meta data
Remember, googling is research, not cheating.
i actually googled it myself but completely butchered the reading half of that process apparently
yyeah anything we find on Google is publicly accessible so its all legal
That's not what I'm saying
I mean there's some exception
And also not necessarily true.
I'm just suggesting that you should use a search engine before asking here
oh ok thanks, I asked here bcz here is experienced persons who hve already done the research and can explain better
Gave +1 Rep to @naive violet (current: #2 - 2139)
(ChatGPT is not a search engine, to be clear)
That's the wrong attitude to approach this with.
This field is all about research and reading.
We all just google it too
without google, we will all perish
Amen
im new to pretty much everything "hacking' related. i know my way around windows. whats the best way to learn in your opinion? straight to ctf?
THM-style ctf
probably not true ctf or HackTheBox-style ctf yet
unless you learn through pain
then go straight for HTB Fortresses
no
you don't go straight to ctf
Ok, i usually learn hands on. making mistakes and what not.
first complete intro to cyber sec
i have
going to complete beginner is a step down
So the course? lol
i tried windows exploit basics and i feel like i know nothing lol
@charred forge how tech literate are you
otherwise, i mean
if i throw you in a shell will you know what's what
im a hardware guy. which obv means nothing. hahaha dont laugh but im not even sure what a shell is...
Howβs everyone
then yeah head on over to the ones Ibrahim suggested probably
you should get yourself virtualbox or vmware player and poke around in some linux vms
i have completed all of those aswell. i acutually have messed around in virtualbox with ubuntu
ayy
more likely just need to follow the course until i can comfortably do my first ctf
Fuck boradcom
btw are you paid or free
yes
Truth
i mean no but yes

also hello
im extremely interested in this stuff haha. and im paid
Then you should be able to do whatever
Thatβs what my schools having us use
Hru
trynna install vmware on my new PC and they've had their site under maintenance for 13 days now
Def start with the basic ones, then go from there π€·
anyone got a VMWare setup file?
i say jump on into the Jr Pentester path then and see how you feel. It's somewhat guiding but it's not throwing you ALL the way into the deep end. You can always switch up or down depending on how it goes
Waybac machine linn.
Link
ah, thanks scrubz
Jayy posted it last week.
the Jr Pentester path has a good bit of both web app stuff and systems stuff
fairly guiding in both but not necessarily handing it to you all the time
should end today anyway.
Opportune word there
if you want a solution
kvm/qemu
I don't have the time lol, I came back from the hospital just to set up my PC and I gotta go back in a few hours
I won't be back until the 18th...
ive dipped into that. My main question is how long does it usually take one to learn enough to get a job in cyber security. or do some bug bounty's comfortably
i'd be curious to see what vmware's numbers look like 5y from now
these days i look at doctors very suspisiously that i know how admissoins happen π
hope everythings good at ur end
still pretty up
comfortably? depends what that means
lmfao, yes, everything's good at my end lol, they finished a liver biopsy a few hours ago and I got some time to kill so I came back home
the longer you do this the more you'll realize how little you know, less than you think you know now
you just learn to accept it lol
Make some dalla bills lol
that is the most biology for me in 2 years
ah that comfortably
yeah not many people live off bounties
it's often just a side thing
thought so
isnt usually like
no not like
my mom went to a doctor few days ago, that guy didnt know what he was saying, i said now i know how he became a doctor 
the top 5% that gets into private programs
that usually can make a living off it
what did he say then?
my PC is very green lmfao
i mean i wasnt there but another doctor told us whatever he said was nonsense, trusted one cus shes moms friend
makes sense
Also what are most of you working on or studying currently? and how long have you been hacking?
private programs as a category doesn't have the highest barrier of entry --- just don't be reporting "you don't have dkim!" and ping the triager every 13 minutes for an update on your Informational, and you'll get some invites eventually
oh btw we got a new car
WOOT WOOT!
i spend 2 hrs cleaning it 
stop driving around in that and go study
then stop cleaning it
study, you have your JEE in 7 months
been taking a break from sec the last month myself and doing some foss stuffs. it's good to pivot sometimes and give yourself a lil reset
not enough time to finish all the syllabus and practice questions
u see i make myself much more guilty
my brain got used to it π
all that works is be hard on yourself
thats effective
Do you think certs are necesarry to obtain in these cyber careers?
yes
i know india values CEH a lot apparently but other than that not really
get one or two and call it quits
then when you have a job that pays for them, THEN you get more on their dime
India, Pakistan and a few other south east asian countries, less than 10 in total
that's it
really?
i mean out of all the people only ceh?
Indian HR values CEH a LOT
fuck iit hello ceh 
cause it has Certified and Hacker in it
outside of those countries, CEH is eh. HR knows what it is but even there, I'm seeing it asked for less and less frequently lately. CEH and the ECCouncil don't have the best rap around here
Interesting. and as someone who knows as little as i do... what kind of position should i look for? basically, if you could go back. what would you do?
Security analyst or Junior Pentester
lmfao
We hire juniors/trainees with little to no experience
the most common way imo is people get a job in a SOC somewhere doing triage all day
There are companies out there, just rare
can I apply π
that's probably the easiest but far from the only
i can understand due to the overpopulation, but even at that i think ceh is not a prority (if you are considering someone newby, around 20-30 age) even the countries #1 college couldnt place 40%
Pretty usual way in, IT support or NOC as well
giv job plz
Interesting
Sadly as with many companies in this industry, we don't hire internationally for clearance reasons
on that note, aren't you uk?
Yep
Skills definitely help tho i would assume
I know people all over though, including other companies that help people get into the industry
depends on the company. small co? yes. big co? nah you need 17 yoe with this specific email client version and a doctorate ( s ) ( sorta s )
We look for a mindset really, the hacker mindset. Wanting a deep understanding of how things work.
Someone I respect put it as "We look for the sort of people who took their toys apart as kids"
Hi on average how much time it take to complete thm for new one and complete beginner in this field π€
complete THM? That's a lot of content
Don't think you can complete something updated regularly
Or old content gets retired.
complete it today you'll be uncompleted tomorrow
Always be on that grind
Only because its new room Tuesday
Just become 0day
New room Friday.
THM release atleast 2 rooms a week.
Tuesday - Thursday then




