#general
1 messages · Page 206 of 1
yes
it does seem like we have things in common
did you hold an exam to get certified?
i believe that i do as things i do on kali with the usb save, like logging into my gmail, and i have set up a persistent tails storage before
is this a feature of usb's or the os you put on them?
yes, written, tasting, oral and practice exam.
idk really
but ig on some operating systems you can't so I will put it on the OS
bro had more tests than you need to own a handgun
you earned your place in the high court of sommeliers
I have one 🙂 semi-automatic pistol
it's evening here 🙂
morning
nah you are certified in everything sir
a friend who live in a rough place has permission to carry an uzi
im if you can become a sommelier then the pistol should be lightwork
Hello People
where are you from?
some things 🙂
Active warzone in Kenia?
I live in Israel
Man I am enjoying TryHackMe, making more progress than ever
why would God s chosen people be so aggressive
prefer not to answer that one, the conversation can go political really fast
naw, lets not have this conversation please
I have enough IRL
"What's Matt listening to today?"
Watch I kveld med Ylvis on discovery+: http://bit.ly/IKveldMedYlvis
New Ylvis video! https://youtu.be/Smeqw0qoYBw
iTunes: http://smarturl.it/YlvisFox
Ylvis - [Official music video playlist HD]: http://www.youtube.com/watch?v=jofNR_WkoCE&list=PLfNe3nGQENtP3VCn1t1pybju9ffSPBohU
Buy or stream the song here:
iTunes: http://smarturl.it/thefox-itun...
is that you in the costume? 😂
true
I just had that picture where they are chill as hell
doing that dance you know at the weddings
mb
@sand trench
Have been trying local file inclusion on a web site but ../../../etc/passwd shows 403 forbidden error
Also have tried multiple payloads but all of them leads to 403 forbidden access..
Does it mean that the site is vulnerable and if yes then how can i proceed further from this?
Anyone ?
@graceful thistle nobody here is gonna give you advice hacking random websites. I assume if this was related to a THM room you'd have mentioned it.
Umm learned this from tryhackme but want to test it on real targets so whats the deal? Why cant you?
@mossy river
There’s laws surrounding computer misuse and not hacking what you don’t own
So it's really to your benefit that you dont' try this on random websites - in many places, it's illegal to even attempt it, and as a future cybersecurity professional, it's unethical to hack things you don't have proper permission to hack
I need energy drink
Many hackers have found themselves in very serious trouble for hacking without permission. having proper legal protections and a good contract is what separates working professionals from arrested amateurs. For instance, google the Coalfire physical pentesters who were arrested in 2019 for doing their jobs.
Due to an improper scope, they were pentesting a site they did not have proper permissions to pentest.
You need sleep. Energy drinks are poison
so is water
I thought Coalfire did have proper permission, but the local courts rule against them and threw out their appeal.
Hey jun I have a question about this same topic let say during a red teaming exercice I did the same thing and Pentested something that was out of the scope would I get legal conciseness from it?
It's 50/50, honestly. The building they were pentesting was owned by the county, but was housing state judiciary records - they had state permission, but not county.
Legal conciseness is not a term I understand.
typo my bad
damn dont know how spell the word
If you go out of the defined scope on a contracted engagement, you (and your employer) may be subject to civil and criminal liability.
If you mean consequences: you absolutely can get in trouble if you go beyond scope
i needd it, i have work
starting my new work
So the absolute rule when on a contract is: don't go outside the scope, and don't access things that you aren't protected by the contract to access.
I do have a question to this.
Say I own a domain, files are mine, but hosted on someone else's machine. Would permission be from me, or the other person if I wanted to conduct a test?
Good luck!
Thanks for the clarification. I remember their CEO going to any and all security conferences and even b-sides to promote their case.
Gave +1 Rep to @whole yew (current: #10 - 755)
Thankk you
Ohh I see thanks for you making it ever clear.
Gave +1 Rep to @whole yew (current: #10 - 756)
All of those
Think about what's being touched, and what may be housed on the host. Lets say your pentester escapes the vm/container your infra is hosted on, and they get domain aadmin to the underlying technology stack. Are you legally able to grant permission to access that stack outside of your tenancy?
Ah I see, so the answer would be no. And permission would be needed from that other person, gotcha. Thanks 
Gave +1 Rep to @whole yew (current: #10 - 757)
Public cloud providers like aws and azure provide blanket permissions for certain types of testing on certain scopes BTW. Without them you could not have your own cloud-hosted application tested.
guys
You do look more like a cat, yeah
i am the cat of wisdom
it is 599
usd
u get 3 mo. access to their library too
What does the library contain
everything they have iirc
yeah i would like to know what kind of books do they have
for real
does library mean all their courses or what
Good observation, now go back to work :p
Guys
i feed heart broken
i discovered after 3 days that Try hack me courses are not all free
Around, but not more than, 70% of the content is free
@pallid lotus i did it for you
So i can rely on HTB?
LMFAO
cuz i really like the content
I remember the conversation it was more like 67% I believed
68 or 63, depending on which API endpoint you believe
Not sure what you mean?
I was close, my memory still works I guess 😂
This community is for TryHackMe, we don't really discuss HTB content. They do have their own discord where you can learn more.
@slender scaffold you here?
what does this community discuss then?
o/
This is the discord community for TryHackMe
??
I just ran 3.5 miles, I am now slumped in my chair feeling great after my Gatorade
yes i understand you , but i mean what the things i am allowed to talk about? u said we don't discuss the content
#1 This is a federal crime without permission and discord is fedded as in they will give over info to feds if they are asked to
#2 You're probably nowhere near experienced to even do this and after that even get away with it and clean your traces
#3 CTF's are superior also for learning anyways because they have the specific vulnerability you're trying to learn already in them, and you can learn through the struggle of trying to find it and exploit it
overall its a pretty dumb idea
I haven't have supper yet, I'm debating, I'm tired
Nvm, false alarm. I remembered the song, Chromance - Lollipop
Lol
Oh, I was just telling you that they have a discord if you want to learn about their content. We discuss TryHackMe content, computer stuff, etc etc
How's Featherz doing?
There seems to be a misunderstanding: tryhackme(THM) and hack the box (HTB) are separate, independent sites.
Pretty good. My arms sore
Awww! ❤️
That's a sh*t ton of bird food
Oh that's just 1... we got like 4 
Must be the lifestyle creep I keep hearing about
What is lifestyle creep
You start with one bird feeder out of college by the time you are as successful as @boreal scarab you have 4+
3 regular ones, and 1 suet
Sparrows look happy
Suet sounds french, must be fancy
Fat ass chipmunk kept eating some of the food 
Hmmm, I should put 1 more suet up, right near one if the feeds, spicy suet, so the squirrels and chipmunks try that and run away
okay thank you bro . Have a good day
Gave +1 Rep to @clear jackal (current: #19 - 405)
I need to restart my router.... ugh
is the stack save address of function?
meep moops time for sleep sloops to the beep boops
What do you mean?
Anyone knowledgable in VPNs?
Just ask your question
@whole yew You going to Defcon again this year?
What’s your question
Please correct me if I’m wrong, does a vpn mask both the public ip address that an isp gives the router and your device’s ip address when you connect to the router?
is stack in memory store a address of the function?
my english is not good
so maybe you cant understand me
No, thats the register
Pretty sure your isp knows if you are using a vpn
Wait
For sure but what exactly does a vpn mask
Well it gives you a new ip
You need to verify to post images
Why the image dosent work?
how can i verify?
Which ip?
A vpn servers ip
so what is stack do?
Yea you’re right
Are you asking about how things get stored in the stack?
But like what does it mask it on
It basically connects to what ever you are looking for via the servers ip
yes
I might not be following?
When you mean mask?
Like with eax, ebx, and ecx?
Yes
Those are called registers
So if you have a phone
Yes
The stack is the order of operations
And you connect it to some airplane wifi, the router assigns you an ip address
Let’s say you want to look up how to bake a cookie. If you turn on a vpn, which ip address will it mask, the ip address of your phone or the routers ip address?
he store a function
and globa varaiable?
Your phone I’m pretty sure.
Well actually. Hmm
Because you can get a vpn on your router
For example I have nord vpn
If the router owner wants to check my ip, he’ll just scan it
But if I have a vpn, does that mean that the Nord ip address I was assigned shows up on the ip address device list
Or does Nord only mask my ip address when I’m browsing on the internet
Who is he? Is there something you're looking at? Is it homework?
If you are connected to a router or wifi access point the person who controls those always sees your local IP. Using a VPN doesn't change that.
Gotcha
There we go
They can see the traffic, they can't see the content
So I connect to a compromised star bucks wifi while I’m connected to a vpn and look up Bruno mars songs, will they see what I’m looking up
Not the content
The VPN is a pipe that goes from your device to the VPN server
Like google said
No
And whatever data you send out to the internet, you still send it to the local IP of the default gateway, even when using NordVPN.
Right
On a home network that'll be the router, typically on something like 192.168.x.x
Does nord affect the router’s ip at all?
No
Like a vpn
👍🏻
If you're talking about going through the router
Don’t routers come with there own specific ip address
I got so confused because chat gpt was giving me a bunch of bs
That's a different question from the one you asked before. If the connection with NordVPN is secure, encrypted and there's no man in the middle, the wifi operator doesn't see what you're doing. That has nothing to do with the fact that you still have to send your traffic to the local router's IP address first.
Hello whats the difference between proxies and vpn ?
Virtual private network
And you're sure you can judge that, given you ask here?
Have you conducted a query utilizing your favorite search engine?
You can easily get a result to that question.
If I’m confusing something please tell me because I may be throwing loose terms around that might have different meanings
Home routers might have a pre configured IP in one of the RFC1918 ranges. Generally there's nothing to stop you from configuring any IP you want on your router.
if i search for something in google , and there is someone in the middle , he can see what i'm searching for?
That’s not answering your question lol
He’s alluding to did you google?
So
i understand
If I’m looking up cat videos
Ok
A proxy server and a VPN will both mask a business's IP address. However, a VPN will encrypt all data that is sent and received. This is a capability that a proxy server does not have. So for those that are currently using a VPN, there is no need to connect to an application or website via a proxy server.
what traffic is encrypted
First my phones ip address sends packets to my router’s ip or to my vpn server?
To your router
Ok so my router picks up the packets
Ok actually the answer is more complicated
Your router is what routes you to the internet.
The data goes to your router. Has to.
lol
So then some process makes my router send the packets from the cat video request to my vpn server?
What makes this more complicated is that you not only have IP addresses but also MAC addresses
Correct if I’m wrong, the MAC address is just the name tag of your device while the ip address is the location of your device on a network
MAC = L2
IP = l3
Client -> VPN server
VPN Server -> internet is not
(unless by the protocol, i.e. https)
What is L2 and L3
OSI model
Everything within the same subnet talks over L2
layer 2 and layer 3 in osi model
Everything on dif subnets uses l3
I mean it’s not the best model but visualizes
You switch to a host, you route to networks
Could you explain the packets moving from your phone to YouTube and back?
I recommend doing the intro to networking for tryhackme
It explains the osi model for you
what is hexadecimal used for?
L2 -> Router IP, Router does NAT, goes to your ISP gateway, BGP Magic, youtube servers
There are resources you should use, like THM rooms and Youtube
its used for developer but i still cant understand why developer need to learn it
Squeeze vpn in there lol
if that so using proxies and vpn is the same no ? i don't think someone nowdays will use ftp or http or anthing that don't use SSL
...........
also i cant understand
different levels
It’s a search engine
Router-> VPN, VPN -> server
All the VPN does is make a tunnel from your device, to the VPN server
after the VPN server - the traffic is the same
its useful when your own public wifi and dont trust the network your on
but it just shifts the point of trust
I said more complicated because even though you configure your phone with the router's IP as gateway (or this is done automatically), your phone never sends a packet with this IP as destination.
DHCP hands out a default route via it
Instead it uses the MAC address to send data to the router on the local network. Which in turn it gets using the IP address using ARP
Oh ok
The point I was trying to make is that a device on a LAN never sends out a packet with the default gateway IP as destination IP, when accessing a website or some other service.
#BringBack802.5
Hullo Emma
As short as I can make it: Your phone connects to wifi router, gets told via DHCP that 192.168.0.1 is the default gateway to the internet. Phone does ARP lookup to figure out device that has IP 192.168.0.1 has MAC address ABC. Phone now wants to send data to Google with address 8.8.8.8. Phone puts this 8.8.8.8 in the destination address of the IP packet and sends it to the default gateway (=wifi router) using MAC address ABC. Default gateway forwards the packet to your internet service provider.
The source and destinstion MAC address change with every hop in the network, the destination IP address usually stays the same.
There's two different addressing schemes at play which makes understanding everything harder.
.......................................................................................................................
Let me publish that rq
Does your mac address leave your local lan?
No. It doesn't exist beyond the next router.
A router forwards the packet with its own MAC as source MAC.
Good, you're paragraph wasn't clear 😄
"With its own mac": more precise: with the mac address of the interface the traffic is being sent out on. Might be many on an ISP router in a datacenter. Each interface with a unique MAC address
I got everything besides the part with ARP
ARP is the protocol used to find out the MAC address of a device when you only have its IP address
Oh ok
Hey all. May someone answer my question:How can i learn hacking
I could not find an article, please try again.
So your phone might send a message to all devices on the local network asking "who has IP 192.168.123.123" and then that device responds "it's me and I have MAC addres XYZ"
Hi
i need help
i can connect to openvpn i can ping 10.10.10.10 but still its showing not access in thm
What are the best free courses for programming
CS50 on YouTube is great for absolute beginners.
@hot cairn im going to leave my flights alone be there's no other options, but now I can't select my seats
It's an x class ticket, which should allow selection, but I can't on AC or Turkish
yo anyone wanna do somthing?
somthing as in eating pizza, for sure
What are you wanting to do or have someone do?
Any tips for understanding network
No
i just did the file inclusion room and at the last part i decided not to just do a print to execute the hostname command with a remote file inclusion and i have just spent the last like hour finding out how to set up a python3 server and a php reverse shell with netcat then i typed in hostname on the reverse shell and that just felt so rewarding when it finally worked
It amuses me how every time I come across this reflex/sentiment on this server I try it out myself and without fail I get an answer that's not only objectively correct but beats anything provided by users (including myself) in terms of conciseness and being well-structured. By a wide margin. Can't wait for the future 🚀
There's fantastic resources on YouTube, including the CCNA course by Jeremy's IT lab. If you want it less technical: Professor Messer's Network+ course.
currently ai is just a llm rn tho, just wait until we have legit AI.
imagine AI philosophy
morality
like if its moral to kill an AI that can think like a human
or the value of the life of an AI vs a human life
Tbh, all this AI talk since last fall has really just made me want to disown society and live in the wild before I become victim to AI turnkey tyranny.
General AI is a long way away look up the human brains computing power
I wanted that long before already 😅
i had hope. i was naive
just bored wanna do some rooms idk
its the boiled frog anaology
where's everything on fire?
assuming that you're not in a IT healthcare lol
MAN THAT scene from the IT Crowd made me laugh so much
Let's write a email to the fire dept
whats everybody getting into tonight ya'll
maybe some fallout nv, prey or another celeste run 
life is better not following the norm.
#koth we have a channel for that
ohh okk
Munchies
Bur me no have snacks

I have a very funny case of "Exploit works locally but not on remote". §(/$&§/&%
Thats a fact tho.
Specially since in this case there's no silly addresses and pointers involved that could be different and the target server is just straight up returning nothing.
👀
I meant when searching for a solution to a problem you have and the only answer is "works now"
But yours is true too
I honestly think is just broken. I get output when I input something executable but wrong and and different output with stuff that contains errors, but when I put the exploit that works on my machine ;) it just closes the connection.
Disappointing, I like getting flags.
sometimes you need to modify it a bit before it works.
But I got zero clue what to modify.
It's just some very basic Python bytecode.
I can send it to you through DMs, together with a link to the challenge if you really care, but I honestly think it's just broken.
Morning
Morning.
Go bed
waki waki!
Morning simon
Not easy
let's leave that upto some RedTeamOps in here!
how they did in their pentest? kinda tl;dr ig!
Vain, Rank up 😭!
I'm almost at 0xB lmao
Morning
The users are i guess
Mz bank issues phishing / smishing PSAs every other week
My*
morning
So some time when i use openvpn i got this "packet HMAC authentication failed" can anyone help me to fix this error ??
#site-support please.
hi can some one help me. i want to learn kali linux or anything basics related to hacking
from where i can learn basics
i do know basic linux commands
Go and solve TryHackMe workthrough
and little bit abtprogramming langs too
@rapid plover
You should know our website by now!
ok
Yup
depends on the country, really
I heard US banks still rocking 20th century tech (like KOBOL and whatnot), but I doubt they're "easy"
gm
Does anyone have any experience trying to set up GoPhish on a Kali VM on Apple Silicon Hardware
Hay, phishing is illegal, did you know that?
Scrubz, have you heard the new viral banger made by some irish kids?
Not yet.
Is it difficult to find a vulnerability in Chrome?
i wana try to found a vulnerabilty in chrome
Good luck!
Cruinniú na nÓg, Europe’s only national free day of creativity for young people is back, with over 1,000 free activities, taking place on Saturday, June 15.
Young rappers from The Kabin Studio in Cork & Lisdoonvarna have teamed up to make a belter from Cruinniú na nÓg, the national day of celebrating youth creativity 🔥
🎵 @gmcbeats
📹 @swanigue...
It’s for school, but they didn’t teach me how to set it up or I’m having problems
Idk if it’s my Mac or I’m just stupid
But it’s not working
Then please speak to your teachers, it's their job to teach you.
We won't help you set up a phishing toolkit as it's illegal/unethical if not performed during an engagement.
My only question is that does installing it on MacOS system on a KaliVM make a difference? Or am I not allowed to ask this ?
Does the Silicon architecture make a difference in the installment of a program?
I can't/won't say, sorry.
Please speak to somebody who teaches you.
Dam :/
hows everyone today
Fine
Input car details, and pay...
Credit card doesn't work
INDIA
You might need to purchase a voucher instead, AFAIK India doesn't support subscriptions
How do u do that.?
Remember and set it to what you want.
Buddy it's the same thing all over again 😭 even tho I set my international transaction to 10k rupees , it's showing me that ur bank has rejected the payment
Need to speak to your bank then, sorry.
Debit card?
Both of them are giving the same problem
You need to speak to your bank... 🙂
100 bugs!?
Is that all? 
Ah, a month is better than 24 hours.
@dark swallow please don't dm without permission.
It's in the rules.
my day today is shit
Day 7 of trying to find a preowned mw3 on FB marketplace
why
gl
me it's day 40
the first 2 weeks is difficult but after it's easier
gl men
I have decided that I will not be using nicotine unless someone asks if I want a cigarette or something
😭
cause I don't feel like self medicate myself any longer 🙃
if i'ts difficult no nicotine you have electronic cig
it's a good alternative
I have done no nic for years before
you smoke since when?
I have smoked since I have 12, but it's been on and off, last few months I have done nicotine pouches instead
now how old are u?
20
yo
11:35
bro i haven't hacked in like 6 months and i know nothing
😭
narh, nordic europe
i could hack almost every easy room if i tryed and gave myself like 5 hours
Denmark
ohhh slay
You'd need more than 5 hours for every easy room.
fr?
thats fucking it
i want to learn pure hacking
i want to steal someones bank info for BETRAYING ME
i want to make that fuckers life a living hell
wtf
i will do anything in my power to get this fucking persons life
ive had it
im fr tweaking
Contact your bank and local LEO
There is 382 rooms, even if you spent 10 mins at the most on each room, that would take 3820 mins, which is 63 and half hours.
Yeah
i dont care
i want to learn how to destroy a persons computer just by knowing their roblox username
Now take in to consideration a room could take you 10 mins, or even 30 mins.
That is illegal, if you continue you'll lose the ability to speak 🙂
you're look like stupid i think
uhmmm 5 hours per room
wth
i will go out of my way to do this
not 5 hours for every easy room
its not illegal if you dont get caught
if i didn't use a tutorial or smth like that
It doesn't matter.
Its Still illegal and unethical, so we don't teach/discuss in this server.
o ok
well i heard of this hacker team that gets rid of those dark web websites if ykwim
This is your last chance 🙂
Please drop the subject
haha i have a felling your just a kid who got scammed on roblox and wants to destroy his pc
Then it would take you 1910 hours.
100%
i gotta get my anger management up
Please don't antagonise users, especially after a moderator has asked them to stop.
my bad. its just funny
Can I dm you?
sure
Thanks, it's just harder to moderate these type of situations when people jump in and cause further chaos.
Gave +1 Rep to @hazy sundial (current: #2085 - 1)
@sick lance i have a question how did you get motivated to stay into hacking?
i stayed for about 3 months and then gave up
It's something I really enjoy.
I enjoy breaking things, making things, discovering things, I enjoy Blue team as much as Red Team, Sure I'd love to do pentests etc, but I'd also love to investigate attacks, digital and physical evidence.
It's so much easier when you love/enjoy doing what you're doing, and not motivated by money, you know?
i mean yeah i enjoy hacking but i had a guy with who i did it and i just haven't spoke to him in 6 months
They could have just been bored and stopped, or stopped speaking to you.
he was in like top 1000 on tryhackme
Perhaps they moved on to HTB,.tcm etc.
maybe? he said tryhackme was too easy
and tbh i haven't spoke to him because I like to have competition and he already knew everything
and its really hard to find people with my interests at my age
yo
This is impossible
???
dude the mods told me to shut down the topic im talking about
i aint speaking no mo today
seems like a fair request
Use any critical thinking please, if this was possible then millions upon millions of peoples computers would be destroyed rn
Okau
everything is possible but not many people have the knowledge to do something like this
Youre trying to rush hacking too much ramen enjoyer, build your skills over years before trying to do cool hacker stuff in movies
lets end this topic plz
Hello, moderators have already dealt with this, please drop it. 🙂
Ok im not on the topic anymore
You did reply to me about the topic btw..
But yes im over it now
yo
finnalyy fix ho gaya
@sick lance you're in cyber since when ? And what study do you do? ( sorry for my english )
congo

I've been in cyber since the 90'.
Currently studying Digital Forensics and Cyber sec (which is really DF with Red Team topics like Pentest and Malware Exploit and Analysis)
fr fazool sv
you're in DFIR?
Yup.
baahar ho chal
ahhhh i was thinking that you're young but no
😭
English only please. @odd vine @blissful vessel
cool! DFIR is an interesting domain though
sure man
kkk is it forbiden
?
tf nahhh have u read the rule 😭 ?
do you think so?
lel we were speaking eng but with some clasical touch uk

you are ukrainian?
Please keep all communication in English. This also means no encrypted posting.
btw what u doiung here what do you do for living?
who?
you
touch of uk
it's ukrainian?
no we're from Pakistan 🙂
okkkk
yk well
how to get roles in this server?
role of thm rank?
thnx
welp now im calmed down
nice
jeez i was fucking fuming
i felt like i was gonna kill someone ngl
what mean jeez? @mint gorge
😭 bro what
oops wrong reply
THIS is what got me sayin jeez read allat
You mean illegal hacking, black hat
shhhhhhhhhhhhh
nahhh it isnt
i aint gonna talk abt that no more
ahhhh sorry x/
i said that to the mods
fine got roles
its finee
You need to verify your THM account
Yeah, that topic isnt supported here cus the website this server is for is specifically for ethical hacking, like a job you know
ik ik
hacking as in hacking someones account back because they lost it
right?
yeah yeah
Hey guys
I’m running a security assessment on a wps web
I’m using wpscan —url https:example.com —passwords /path/to/pass —usernames userX —max-threads 1 —throttle 500 | trying to avoid the WPS sanity check, but still encountering to error “unknown response received code: 401” and error “:server error, try reducing the number of threads” WHICH I did! | any ideas??
These errors caused by the sanity check, I know other methods to bypass the sanity check like: CAPTCHA Solver tools, Proxy Networks or VPN and DPN.
The WPS version is the latest which is 6.5 that has been release this April and the plugins are patched except WP-crone which can be lead to DDOS (not useful in my case) and there’s no known vulnerabilities, the Themes cannot be detected at all.
Sounds like I did avoid the sanity check with the above command but still encountering issue with this “error: unknown response received code: 202”
Which the 202 status code means: The request has been accepted and is pending processing, but it hasn't been completed yet. It might be acted upon or rejected during processing.
i can't remember the flag off the top of my head, but I wonder if it's blocking the user agent?
maybe --randomise-user-agent
i'd have to look at my notes
For where/what?
Already tried, no luck!
I would like to provide more info but contract is private 🙂
Probably best you don't disclose any details in a public server.
Yeah I know very well, thanks!
Gave +1 Rep to @sick lance (current: #1 - 2349)
Please stop asking for help in this server, if it's work related, speak to your supervisors, if it's school related, please speak to teachers.
No worries, I’ll make sure, but can I ask why? When I’m not revealing any private and sensitive info about it? revealing
can someone explain the difference between an ethical hacker and a red teamer
Not revealing any information doesn't give anyone an idea if what you're doing is either ethical or legal.
What's the difference between a stack and heap
And we don't help with schoolwork/uni work/work in general.
Alrighty, thank you!
Google will probably give you the best answer
What is the Internet?
it's this cool little box in the north pole that contains the entire universe and more in a 6"x6"x6" cube
it's for wordpress sites
that wasn't his question
he was asking if it was a ctf, school, work, etc
i misunderstood
my bad
thanks mate
Gave +1 Rep to @bold dawn (current: #76 - 82)
I started learning on tryhackme.com yesterday, and now ive read the IDOS thing with a room where u revert products on a shopping page that have been switched up by a hacker. But, when i clicked open next (for the next lesson) it was a premium one and i cant access it without premium. What free lesson should i learn now? i dont know where to continue
What’s the name of the path
let me check
cyber security path
i learned about web application security
offensive security is premium
i meant operating system security
Search up in the search bar operating system security
There should be other options you can choose
That are free
i see linux file system analysis, security principles, security engineer intro, security awareness etc but not operating system security
Hm
Hey guys i would like to start into bug bounty how should i start learning
Hi all,
I have an url: target.com/00T/e?retURL=%2Fhome%2Fhome.jsp
Can someone please guide how I can bypass the url redirection restrictions
hackerone website
It's the same as tryhackme but it's fully focused on bug bounty
Hi 
It's included in security engineer path check modules in Network and System security in Security engineer
I dont see operating system security in it
Linux and windows hardening
yes
after isod or whatever it is called, where do i continue (i dont have premium)
when i click next lesson its operating system security which is premium
You need premium for Structured learning path
you can go to search and apply filters to get all free rooms
You can do the paths in order and just skip the sub content
damn didnt realise pepto bismol was so strong
whats happening
work wants me to make an intergration with a website, their api looks so bad that I think that if I do what we need it'll dos the whole website
because of their bad implementation
💀
Hello this is Tom speaking from Macrohard, we noticed in our systems your anti-virus has expired. Could you please share your username and password with me so I can make sure you continue yo receive full protection? /s
I just saw something on tv ( XD ) it was talking of data breach in my country and so it made me think of something. Where does hacker acceses data breach or even website like ';--have i been pwned? ?
I already bought a new one, lol
I don't take the chance.
trust this men for sure ( ps : u may try Scrubz passwd : 123456789 )
they seem to disagree
A full year even, somebody's rolling in cash.
My old bank paid for it, they bought it for me for the past 7 years. but I changed banks 😦
This is opsec 101, now I know your old bank
1 step closer to the money
awesome, thank you!!!
Gave +1 Rep to @warm kettle (current: #1388 - 2)
😬😬😬
can you share the link, i can't find it
please and thanks!
Good to know the VPN won't interfere with OpenVPN.
There's sites out there but they're trading in criminally obtained material. It's funding crime.
We don't discuss them here, as it's illegal activity
RTFM have a coin 👀
(0nly for US)
how did u get the coin?
It's not mine.
@hot cairn
They didn't say canadian french
Search in Google
in Indian accent
also when you are in Belgium they do not like ppl with english. So they speak French all the time. Last time when i was on airport i make small incident with guard who didn't wish to talk with me. =/
Let's not make jokes like this. 🙂
most of the scammers are from India
I'm an Indian bruh
k
I bet it is in morocco since local folks hate french speakers.
we are being suppressed by the media now
we can together as a union and unionize try hack me. Hack for the people by the people
vote for me as ur union president 2024
I'm not the media, however we wish community members respect other members by not making jokes that could upset, or alienate them from the rest of the community.
In this case, you could argue it was minor racsism, which isn't tolerated, at all.
they will come with worse surprising us making us we don't exist anymore
as A union member and future president I will tolerate this
You'd tolerate racist jokes being said in chat?
(Baring in mind, this is a professional work place for some of our community members)
chill out scrubz i am missing around xd
it says random chat, pg13
then rename as professional behavior only allow
in addition, he said a fact most of the scammer are from india
so i don't see anything wrong with that
That wasn't the part I had an issue with, that's a general opinion.
The part I had an issue with referencing another joke "in Indian accent".
hey guys, how do I link my discord account with tryhackme?
@crisp fractal
Ty !
@boreal scarab 4x 250g of glow in dark
Oooooh 👀
if u were here youd realise the amount of jokes which are made are worse but its all in a friendly way lol, someone from outside will prob take so much offense that no one in the world would 😂
nice. i looked at the book so much in it
👀
But this isn't a chat built around those standards. There's people of all cultures that deserve respect. We have a zero tolerance policy on racism here, including racist jokes
something doesn't like what you're trying to do.
What os are you trying to install?
Not install, reboot, kali, I broke kernel trying to install gnome, so did a clean reinstallation
this is a new, clean machine
you're trying to reboot kali in VB?
Yeap
I have been forsaken 😭
hello
got a question fellows
should i skip the complete beginner path for now on THM and go straight to SOC1 ?
no problem.... actually enjoy getting pings when someone points at this.... as it show that people still use and love shadows list
hello
ello ello
i am new here
Hello 👋

Where can I get a Win7 VM to test Immunity Debugger and Buffer Overflow?
Might it also work on Win10 or the protection mechanisms will stop the BoF?
hello new, im ralex
get one from microsoft might ?
u guys will discuss about ethical hacking here right
Yep
i want to learn about ethical hacking
#start-here is a good place to start
yes. it is offical discord server of tryhackme.com site
I recommend you start with the introduction to cyber security path on THM
sup
Did that. I can't even install Chrome. It says "Not a valid Win32 application" while I actually installed a 64 bit OS
fml
how do i update my level?
try a chrome 109 build? unless you need the latest

try using the /verify command
woop woop
Hay, let's not promote piracy please. 🙂

Link?
You should know our website by now!
After learning this what will I be able to do
depends on you!
Hi, how many rooms should I complete before becoming eligible for the King of the Hill game?
none to all
I hope it is good as internet says. ordered it =/
it is dependant on the skill level marked on your profile
it is dependant on which square you have put here
I'm complete beginner :))
yeah those don't really matter but you need to place it at intermediate to do koth
no problme
but i think i need to practice more
well doing
#pre-security-legacy-path
#junior-pentester-path
should put you good enough to handle most of koth
yeah but they are not free :((
Ok
Hey anybody know where I can get an rdp?
can you prvide more details
use xfreerdp or remmina... would recommend remmina
assuming you are looking for rdp clients
The Remote Desktop Protocol (RDP) is a protocol, or technical standard, for using a desktop computer remotely. Remote desktop software can use several different protocols, including RDP, Independent Computing Architecture (ICA), and virtual network computing (VNC), but RDP is the most commonly used protocol.
yeah.... that explains a bit about it
Do you know where I can get it online ?
as shadow stated you probably want remmina
unless you wanna run a remote desktop protocol server on your computer
which is a big security risk
these are free room list?
Need security ip
yuups should be... some might have changed to none free sadly enough
wow thanks a lot
Gave +1 Rep to @sand trench (current: #4 - 1761)
no problem
where r u from?
do u work as a security specialist
currently??? nope unemployed and planning to start univeristy
What do you mean?
No complaints so far, and have barely gone into all of the customisation
fair fair. for sure i must replace mine.
Rdp I need a secured ip
A secured IP? What does that mean?
Are you trying to get a machine that you can RDP into?
What happens if you rdp into localhost? Is it like back in the day when you connected a camcorder to the TV and pointed it at the TV? 
Rdp I want to put my Kalix there
Kali Linux is supported on many different devices and systems. On some of those systems, you may only get a bare-bones install and occasionally may not have direct access to a GUI such as with WSL or Docker. One simple way to get access to a GUI for Kali is by installing Xfce and setting up RDP.
All my pentestings tool there
I want to my Kalix there . I don’t wanna to install directly
You need a machine to run kali on.
That can be a virtual machine, or it can be a physical computer.
What are you going to study?
someone knows how to passby the error of chrome " connect-src 'self' " using extension of chrome? i'm trying to use an http request but dispatch this error
Does anyone know where to get started im new
Any book recommendations for starters?
book or you can also check some YT videos
Depends on what you already know.
Nothing
Will do but some books will help too
you know you way around in linux in general ?
Idk what that is
Im really new
is also OS, just total other side of windows
K
might check in general what is linux OS and how it works and so on
K thanks
linux is open source OS that can be tweaked in details. since all files are text files and can be tricky. but that is magic of it
You will be using the Linux operating system a lot in this field. So I would suggest going through one of the many Linux courses on YouTube. There's also books but I don't know them.
great magic of linux is terminal. alike power shell in windows, but with more magic
Is it similar to coding?
I will
No. It's an operating system like Windows. Just different.
not so much. terminal is way how you give task to linux application.
Kk alr
as i say. first check what is linux, how it works and so on in general of linux info
Alex, you printed a chessboard yet?
K thx
Gave +1 Rep to @loud marlin (current: #27 - 305)
not yet. atm printing some storage bins
a practical usage for a 3d printer
This one is good: https://youtube.com/playlist?list=PLT98CRl2KxKHKd_tH3ssq0HPrThx2hESW
yea.
idea for next print tho
uff... looks nice
Hello
How can I make a virtual phone number that I can use in WhatsApp
Why don't you just use an actual sim?
Not sure if they are accepted by WA, but Skype sells virtual numbers.
It's a business number I want to make ...mostly helps one to avoid inconvenience of disturbance on personal phone
They aren't
Are you sure?
One can make them for free hence its that Knowledge I'm searching for
Dunno if that's meant to be sarcastic but yea tried out a crap ton of providers, textnow, google, wa, and a few more
It's not,
I have one.
Weird, I tried a couple months ao
Did you succeed
Nop, just ended up calling someone I know in the US to buy a sim for me
Oops I also needed one of +1 probably the US
What's your country
Pakistan
IT with security focus
2 years
assuming full speed which sounds rediculous for shadow to handle currently so probably gonna bargin for 50% study rate
Just remember you'll get out what you put in 😄
yeah
just have a decent bit of burnout in the past and shadows mental state is a mess
so gotta be on guard
gotta love working in a team full of nerds
all my jokes land nicely in the team chat 
hoping to get some good life long and living close by friends though
also thinking about maybe attending the pride parade this month in town
idea 🙂
Try hack me attack box networking server is which location if i use vpn to that location can i use attack box smoother?
22
you need to use thm vpn to access thm machines in general. attack box is ok but far from being good compared to local VM
I can’t use openvpn the government banned it
But i trying a way to use tunnel in tunnel method in which use vpn from host
But still trying not success yet
forgot that we are upgrading the kitchen this month so there might be some delay before shadow can build their computer and therefor delaying buying the parts.... should definitely get time before the end of july
welp meep moop
we can not help you bypass government rules
attackbox should still work and might be your only choice
So i asked that i want to use vpn to use attack smoother
not possible
I've already spoken to you about this before.
I don't appreciate being ignored.
I don’t ignore you
???
@rapid merlin
oops
I only want to learn peacefully
Always ask permission before sending a DM or friend request to another user.
probably miss click ma3rouf
you can do so with the attackbox.
No one found the new Search magic on the site yet? 👀
care to share what you need to dm shadow about?? as a topic?? before shadow accepts
we could use a KQL search room though 👀
could be cool to learn more about azure on thm
I'm calm.
Please no bugs, thank you
Gave +1 Rep to @sharp citrus (current: #168 - 39)
is it possible to hack an instagram account? just curious
Legally? No, so we don't discuss it here
This is illegal, an dnot spoken about in here. 🙂
Click the magnifying glass on any page. 😄
im just curious, its possible right
Anything is possible in the world of cyber
Okay okay clam down i dont ignore you bro i am just finding a way to learn i will use attack box only
shadow has a lot of stalkers and creeps trying to contact them... so therefor kinda reserved on accepting friend requests or stuffs
Just requires someone ambitious enough to find out how
cooool, might have been too small for me to see
You can switch between rooms, modules networks etc?
okay, but what if the account is a fake account impersonating u and sharing private data? is it legal?
singular them/they/their... i.e speaking in third person
All included.
they/them is a nongendered singular pronoun that can be used to talk about a person with unknown gender
What's legal or not depends on the jurisdiction. In most places it's illegal.
sooo gonna purpose a challenge... if you verify on here and can get into the advanced channels shadow will seriously consider it
Now you're coming off as quite rude
You need to take it up with the service. Two wrongs doesn't make a right 😁
Depending on the data, you could hold the account holder legally liable, but you would need to contact a lawyer and your local authorities
thanks
Gave +1 Rep to @chilly veldt (current: #8 - 840)
I'd appreciate it if you'd stop, if you're annoyed about this, then maybe you can take a 5 min(s) break?
oh okay, thats what happened to me. Someone made a fake account and exposed photos of me and other private information. I tried reporting it several times and contacting instagram support but it didnt help. I dont even know who made it
Then it's really the only think you can do,
Yeah. Im 13 and he litteraly exposed my adress and other private stuff
Contact police and/or a lawyer.
I would probably inform your parents of the situation 🙂
nah its not that serious
Better safe than sorry.
not the exact house number, just my street.
Which path do i need to learn for bug bounty in try hack me
Then you're out of options.
and the photos are public photos i posted before (some are now deleted)
Which ever rooms cover web topics.
New Web Path coming soon too.
thats why i asked if its possible to hack an instagram account
Possible, yes.
Mhm, you're young, probably best not to take one-way decisions that will screw up your life just because someone posted some pictures on Instagram
As Jabba already mentioned.
