#general
1 messages ยท Page 234 of 1
There's programs called hex editors. People who use them will see a lot of hex numbers.
Depends on what you're doing.
:0000000000
@wide marten Mind if I DM?
Shoot
Ty ๐
Is that an emoji I don't know?
I think itโs supposed to mean like a really wide open mouth ๐ฎ
me thinking that I can finish fixing my bike today
Gets hit with too small nut
I hate using LMG's in MWIII
Oh nice!!!! GL. Scratch up on your road theory, listen on the day and always look where you wanna go ๐ and you'll be fine
You riding too Ben?
Used too. Don't have a bike atm
Ah fair
soonโข๏ธ
Yeeee
need to get outta london first
Been riding mine 3 times now
how is it
Yuuuup
nice!
Only issues with it has or is being fixed
Vacuum line that was dead and a spark plug not fully plugged in
Now just the back blinkers that are changed out to some retro style ones
sounds good ๐ you'l have to send some pics when it's all up and running!
For sure!
Yall have country roads right?
0-100km/h in 3.4s
Top speed 205km/h
yeye but it just doesn't make sense for me atm to have a vehicle. It usually takes longer to drive anywhere than public transport. Plus don't have anywhere secure to store it at home, bike theft is unfortunately pretty big here
Anything two wheeled it's gone before you know it ๐คฃ i've had two bicycles nicked in a year so i've given up on that as well
Yep thatโs the issue and london drivers are the worst
plus everywhere is 20mph. I mean if I had a bike i'm not a speed demon but i'd like to get it out of first gear LOL
Is there a place here to discuss rooms without asking for help? Would that be best placed in this channel or maybe in room help?
Best bet would probably be room help if you need clarification on a room
not really clarification, just discussing it in general.
questions such as, how useful is this skill in actual pentesting, did you guys enjoy this part/find it is easy, and so on
I just wanna bike to also skip traffic
Any big city drivers, are just the worst, from what I've observed over the years.
I'm always super nervous when I'm on a bike around traffic, I have no trust for most of the drivers in the area
I'm in a small place and it's awful too, so many accidents.
People know exactly where all the cops are and all traffic laws are made up if the cops arent around
Oof 
Still probably best for #room-help ๐
thank you
Gave +1 Rep to @near hawk (current: #53 - 135)
elder brother of my friend died from a bike accident. he went out for bike racing and till to this day we couldnt find his body
Wow, I'm really sorry to hear that
drive carefully
yeah for sure, There are some places around where I have to bike on a road where cars drive 90 and the shoulder of the road is pretty small. It's scary
YAWN
tired?
yeah
thats scary
KMPH? 90 MPH, if you're in the US, is speeding in every state and on restricted roadways which don't allow cycling.
oh yeah, kmph
Change your passwords
Isnt there anything else I need to do
guy had total access to my pc
I think I gave him my network access or something
You can reimage the PC then
Am not experienced
I guess my question would be how do you know you're hacked?

We can't really do much more to assist you. Follow the guidance you've been given and if you think a crime's been committed, you can contact law enforcement
Lost all my cryptos
im not from US, so in our country in the hilly areas often there are arrangment of illigal racing competition,
But isnt there any tricks I could try to check if my network is safe now
Change your passwords and make sure devices you don't own aren't connected to your router. You can call your ISP or use their instruction manual to figure out how to do that
NJ drivers summed up in 1 short.
@molten sky
And if y'all think "Oh that's just 3 people in 1 short"
No, that's every. Single. Day. Of. Every. Second.
๐ญ
hello guys i need help
What you need help with?
i need to put 2 wireless devices on the same dongle
i tried "unifying" but it doesnt work
hii. so when i have started thm i can able to share room completion on my linkedin. but right now i just solved the new launched ios room, when i try to share it on linkedin it is showing cyber security training as an logo. why i can't able to share the original logo. or is it the default on for that room?
As in you're trying to share your main computers connection with another device? Share the host connection with a VM?
I assume you're talking about bridging?
hello thmcord
heuu i want to combine a wireless mouse and a wireless keyboard on the same dongle
That only works if the manufacturer of the mouse and keyboard supports it, afaik
are they by the same manufacturer?
Hi all!
hiya
i think that should be pretty easy if u use logitech with unifying
yes yes
If I use my university email address, and once my studies are finished, can I re-change the email address back to my personal email?
just follow the instructions
i think you can have up to six conneted to one dongle
yes i tried but the software does not detect the dongle
probably
Well, makes sense. But can anyone please confirm?
Is the model of dongle supported?
yes you can change the email whenever you like, but naturally, you will lose the student discount
yes
try buying a new dongle?
Well, after uni, I probably wouldn't be eligible for the student discount (imo)
aye:)
they're, like, 12 bucks
yeah
(on a 49% discount tho)
nah
for me?
but all in one lump sum if done annually just to clarify^
mb i meant that the unifying recievvers are $12
ah ๐
lol i misunderstood ya
lol
hey i am doing the new ios room and im stuck on the last 2 questions. can anyone point me to the right direction
please
im new here but i think u should use the room help channel
my bad i thought i was there haha thanks
no prob!
@boreal scarab
https://www.reddit.com/r/ender3v2/comments/n3clew/ender_3v2_422427_board_tmc_uart_mods/ might be cool for you
@lone thistle just on a trip right now, Damm she feels amazing after getting the motor to run 100% it's so smooth
A bit scared about the acceleration, but need to get used to that
does anyone know how someone was able to put up a seo backlink to the following url?
was just trying capture the flag on thm, and it had different things to translate into like hex and base. and i dont really know what any of those things mean as i am not there yet so does anyone have a resource where it lists all these and thier meanings and when to use them?
hexadecimal
base64
is more or less just math
hexadecimal is used because it handles conversion to binary easier
im terrible in math
well maybe
anywebsite or source that has all these listed?
well no as technically there is infinite number bases
i.e as many natural postive numbers that exist you can turn into number bases
though would think there is a lot of math resources on google or youtube if you search for number bases math
so what are these called and how do i identify if this is hex or this is base or ik morse
hexadecimal uses 16 symbols to represent numbers from 0-15
base64 uses 64 symbols to represent numbers from 0-63
binary uses 2 symbols to represent numbers 0-1
those are the most common outside of base 10
technically there is octal too but has been ages since shadow saw that used
Alr so imma just note this down
octal being 8 symbols from 0-7
go for it
math classes in year 8 in school
lol i did not pay any attention back then
fair enoughs
think that briliant.com might have good math resources on this topic but not sure
guess its time to learn the math again
yeah
alr imma give that a try
Thanks a ton
ill try
is learning number bases important in infosec ?
depends but it tends to help with things like intergers and encoding formats
and booleans
stoppp teaching..
Anything between "never touching them" and "working with them daily" is possible
why???
Although don't think b64 has 64 symbols
get good
Doesn't b64 use = and a-z
0-9 + a-z + A-Z + 2 others
you just need to recognize the difference between the encoding and which one is used where.
forgot b64 had numbers and +/
Can someone please tell me the best way to begin the hacking study part after doing the foundational studies?
Ping me pls
usually identify it by trailing = or ==
#start-here And you can follow the pathways
yup
.
if you want weird look at base32 encoded data

The amount of stupidness I see on youtube shorts
A-Z 2-7
fun stupidness???
Fun OSINT stupidness
Guy decided "Hey, let me show you my badge.... with my name on it" Then another video "Hey, let me show you where I work"
Hi, I'm hacker. proceeds to do some basic OSINT
Hey, let me show you my home.
MTV Cribs
'ey let shadow show you their hospital
No doubt there is a short.
Of course, this is all for fun, y'all aint getting the video, the name, or anything from me.
oh wait it is illegal to record in here
oof
why oof??? it is a good thingy you no record in hospital
A German youtuber managed to sneak into the opening game of the euro 2024. Among other sources he looked for badges on social media.
But I can't do OSINT on you, I cry. Nah, jk lol
Yeah, the amount of people I receive at work (I work in a customer service job) that give me their social and they don't even notice it... omg... how do they make it to this point in life... How are they alive?
Mind you, the procedure I'm charge of, doesn't require social, just ID.
Welp, got their instagram. jesus, guy is making it too easy for me
but you already knows shadows home town beeris
True
@boreal scarab OSINT again? ๐
Already got his age, address, where he works, ....... like JFC do people not care about that?

always ask HR where the nearest resturant that the workers go to is
makes it easy to clone near field communication badges
btw what is this topic called?
I'm just at a loss of words how simple it was to get it just from 2 shorts
I can't even speak.... this is just..... wtf
not complety sure but something alined to number bases
Thats the word i was looking for, Thanks again
Gave +1 Rep to @sand trench (current: #4 - 1777)
Is learning the same for you guys as well where any new concept is strange and confusing at first, then frustrating and infuriating when trying to execute it and then when you finally figure it out it's greatly satisfying
or is it just that I'm always getting it wrong and first and getting super annoyed
that is the best part about learning
yeah it's real good when it finally clicks
only for things I don't want to learn or that I am told that I need to learn but have no drive to learn
So you never find it frustrating when things aren't working as you think they should?
here in infosec and tryhackme that is
Is it too late to start for a high school grader to start their journey on this field(cyber security)
No
When did you guys started your journey
maybe a week ago
ofc not
ik a lot of ppl who were in different fields for around 20 years before switching to it or cyber
That's nice
๐
It's a dome on top and bottom on the flat earth so the air is in a sphere /sarcasm
there should be a programmer meme channel
So if the Earth was Flat, you should be able to see from one end to the other end using a really powerful telescope. why can't we?
uhhh
Yea
bc earth isn't flat?
Trees are in the way
What about the ocean
Why can't you see england from nyc using a telescope?
no trees there
because no 1 willingly looks at the british
good point.
ow
๐ ๐
I feel like I should apologize to the brits but then I'd have to talk to them and I wouldn't want that
๐ ๐ ๐
(jokes aside i've been to england a few times and had a great time, beautiful country and lovely people)
I was wondering whether that would be possible on a flat earth. It's close. Ireland in the way of most of England.
Ok pick Ireland
Isnt there an issue with trying to see too far over water? iirc at least scientific experiments using lasers or optics above water has issues due to refraction
You can't see Ireland from NYC
yes u can
Prove it. Show me a picture
facepalm
didnt they turn that off after the topless incident?
lolz
oh nvm, you answered before I even asked the question lol
It's reopened. They placed a queue rope and a security guard there.
Can't have nice things...
@mossy river ^^
apologies sir
Clearly, the earth is a large disk, sitting on the backs of 4 giant elephants, which in turn stand on the back of the Great A'tuin, the World Turtle.
Reminds me of Shaman from Year One movie
When the turtle climbed out of the sea with the Earth on its back.
Was about to ask which one, but physical, gotcha
I had the same thought. 
Well that one went whoosh...oh well
It was a fun movie.
Might I interest you in the works of our Lord and Saviour, Sir Terry Pratchett?
not at all. a very good time to get into it. it's only going to grow and grow
I started about 6 years ago when I was 34
Though I had a good start as a dรฉvelopper before then
Bedroom, especially with UK heat
Thanks for the inspiration
How do i install BEEF on Kali. And dont send me a link haha.
Heh, I was melting at the office today
Isn't it already there? Also isn't it terribly obsolete and borderline useless these days? Also also, what do you actually want to do with it?
No. I thought it allows you to access a computer thorugh a malicious link. If im wrong, please correct. I have no idea haha.
is there an actual mentor program at THM or is it just a vanity role on Discord for smart people?
Mostly recognition for those who like to help a lot
cool
I like birb's definition tho
If you intend to go through with that, then I must warn you that accessing a machine you do not own without the express legally binding consent of the owner is illegal and can be sanctioned with stiff fines and/or jail time
oh
vanity role for smart people? 
mb
I mean....
Yall ever check the stocks of cybersecurity companies during a time of war. Itโs crazy how much wars increase the market
ww2 brought us out of the great depression, so yeah
I'm the kind of smart that 50/50 shares knowledge and just has fun (memes around)... I'd never get that 
some people go "how do i nmap my toaster" and the always-serious-helpers-with-vanity-roles do their best to explain what nmap does and why a toaster cannot possibly respond to a port sweep
Depends on the toaster these days tbf
I'm sure there's a smart toaster around
100% 
Avian carrier?
Airborne crust?
correct
High data volume, high latency
No packet guarantees

Shop Revolution R180B High-Speed Touchscreen Toaster, 2-Slice Smart Toaster with Patented InstaGLO Technology & Panini Mode online at best prices at desertcart - the best international shopping platform in GB. โFREE Delivery Across GB. โEASY Returns & Exchange.
This memo describes an experimental method for the encapsulation of IP datagrams in avian carriers. This specification is primarily useful in Metropolitan Area Networks. This is an experimental, not recommended standard.
it's a thing
Just gotta remember to stay on the legal/ethical side of things, and also that newbies will tend to take you seriously even when we all know it's meant to be a joke
This is where it starts to get real
There was a successful experiment a while back
i hate chatgpt ๐คทโโ๏ธ
That one definitely has too many ports open
I'm sorry
Putting bread in the toaster so you can start via Wi-fi on the ride home to save you 30 seconds
But can it run Doom?
just wait until it starts advertising itself as the DHCP server
Imagine running doom at 90.seconds per frame via images in burnt toast
people have run doom on .. was it a pregnancy test? or a toothbrush? both?
so why not
Geoguessr?
Yep
And by the rules of the internets, someone somewhere has done this
I lost ๐ฆ
What haven't people tried to run Doom on?
I need to refresh my memory on geotips
Was going to say an ultrasound machine but that's been done
You use that tool 0day shared a while ago?
don't tempt them.. I'm sure there's Doom running on one of the buttons of a Streamdeck somewhere
Lost its appeal for me with everyone studying meta instead of real geo knowledge.
HAHAHAHA
Yea, it kinda has gone down hill especially as you need a subscription to play
god that's so dumb 
Geospy?
Ye
i wonder if lockheed martin will make an ad about an f35 pilot playing doom on the interactive panel
I use it time to time but not for Geoguessr
RFC 2324
Tryna become the next rainbolt
Extended by RFC 7168
I should expose Telnet to the internet ๐ค
the release date perfectly matches what i was expecting
That reminds me I need to get The Java Machine back on track
Please don't
Unless it's a honeypot

RFC4824
Isn't IP a binary protocol though
This memo amends RFC 1149, "A Standard for the Transmission of IP Datagrams on Avian Carriers", with Quality of Service information. This is an experimental, not recommended standard. This memo defines an Experimental Protocol for the Internet community.
Suppose you can base64 first
You're asking for trouble, try harder
That beautiful data
FTP is too easy
your internet is slow
or honestly, the peering is bad
is most likely shitty peering
Are you going to complain about my router again? XD
I got a random idea just now about a learning app that looks at your screen the whole time and you can ask it stuff with the voice and the AI whatever app would show on screen instructions or tips in real time as you do something so you learn quickly idk. Just a random thought
Isn't that plagued by the same issues recall is?
I'm not familiar with recall
Well, Recall got recalled
From the same rfc ๐
windows recall which was recalled due to how pissed people were
isnt that just a recorder with extra steps
basically what you suggested take screenshots analyze and store them. Lookup when user asks for info
guys i cant join koth it says
Uh-oh! Only intermediate and advanced experienced leveled users can play King of the Hill.
does anyone have idea
Need to edit your profile
how
add full name?
I was more thinking the app guiding you than the app just remembering the stuff that you do
No, there is a part where your level
Also is weakly stored and can be remotely viewed by unauthorized third parties
Experience level, not thm level
where can i see my experience level
Should be on your profile
I'm on mobile 
Yeah but I don't have my 2fa key on me right now
thanks so much guys
i did it now i can join
god thanks
im so happy rn
Glhf
I meant the channel on discord.
I bet something similar is coming in a few years, the concept just sounds so cool
Sounds bloody spooky to me
Sort of can do this with the metaverse 3.
DIY while looking at the manual as you build.
Ugh I hate that name for that concept
Vmware and critical, name me a more iconic duo.
https://www.helpnetsecurity.com/2024/06/18/cve-2024-37079-cve-2024-37080/
I've been dealing with this since Monday. Most servers are patched now.
hi
oh no
I just got my first google generative AI response...
I thought this was US only...guess they've branched out
hello , im new here , im new to cybersecurity , i just started , and during my first session , the one named intro to offensive security , in the task number 2 , i have to submit the amount of money i have in my fake bank account after hacking bank named fakebank , its clearly 767.68 , but when i write it like that , it tells me its wrong , i dont see where the mistake is , pls somebody help ? thank you
It's not looking for a total, but a flag.
is there any challenge room about moodle on tryhackme?
a flag ?
Adding non toxic glue to pizza?
A bit of text, probably starts with THM{
A flag is like a hidden message that you find after you successfully hacked into or just hacked
Something
Hello
kek no was asking about some DHCP stuff
oh alright ill try the flag tnx
So the LLM answer only summarizes one classical search result?
for that specific query looks like it
that does seem accurate
Duckduckgos LLM only summarizes Wikipedia pages. Pretty stupid
should be able to change terminal settings, or else save the output to a file.
Honestly would prefer this over random sites
Smart*
Bruh
Why is it stupid?
Cus itโs Wikipedia
???
HUH?
You're not serious, right?
How accurate is Wikipedia to a actual resarch page
wut.
Wikipedia is accurate
- Wikipedia literally takes information from research articles, and cites it all at the bottom
- How accurate are random sites compared to Wikipedia?
accuracy can be argued with. For example, in uni here in the UK it's frowned upon as using that as sources
I always just tee that to a file so i can look into it later.
But usually terminals also have a option to increase the scrollback buffer
Same with us schooling systems
But the source listed in the references are fine.
edit: Mostly
aye yes
well, if you read them and are reputable
but directly quoting from wikipedia & referencing is not good. but generally for info wikipedia is alright in my experience. But won't beat actually finding papers and reading them ofc
It all really comes down to researching the resources you are using
Mhm but what isn't frownd upon is finding the primary sources that Wikipedia cited hehe
It's surprising good, especially as a jump point
no that's fine
I still fail to see how summarising the wikipedia articles is stupid?
at masters it's a bit more "you need to be finding them"
Primary sources are the best of t he best
not stupid per se, but it's better academically speaking to go to the direct source and summarise yourself rather than using someone elses summarisation for example
How do you know the llm is summarizing a actual good (accurate) wiki page
You're free to conduct your own research and composite your own answers, no matter how wrong they are, without expert assistance
Everyone is going to be using gpt these days, smh
I agree with that, but the original argument was about DDG LLM using it as the source as opposed to other sites
Doesnt the internet work like when you post something thats wrong instantly 1000 people will jump on it to correct you. Thats wikipedia nowadays?
oh fair. idk sorry I just joined in the convo very late and saw about using wikipedia as sources haha
It looks like ChatGPT use tends to slow dramatically as soon as school semesters end, so that seems to be the prime use for it
npnp, btw signing up for the FREC3 course ๐
OH NICE
While you wouldn't reference wikipedia, you can explore and reference their sources
you doing a combined course or over weekends etc?
why do we have IPV6?
why dont we just stick with IPV4?
running out of combinations
uhhh the 5 day one, not too sure about specifics rn
Damn it
You beat me
Now i can change my expertise to intermediate on profile.
IPv4 was hitting its limits before someone decided that NAT could serve most peoples' needs
But there is only just over 4 billion addresses and about 3 billion useful ones
Surprised? ๐
oh wow
yeah fair fair. 5 days is the general duration of it but you have ways of say doing a week course or over say 3 weekends depending on the provider. GL and lemme know if you have any questions ๐
Aah I see now, I do - how intense did you find it?
No, the limitations have been making themselves real like some in the AI field predicted years ago
Wikipedia is a good place to start, but since it's community edited, do not trust it to be completely accurate if you care about correctness. Use wikipedia as a starting place, not as the primary reference.
How close are we to actually using all of them
Citing wikipedia for an academic paper is almost always a terrible idea
That's why you need a 10.x.x.x or a 172.16.x.x or a 192.168.x.x address range in your home or company a lot of the time
Yeah thatโs what Iโve been taught
I like to see some robust implementations of Qualitative AI that actually "learns" ๐
are those just a list of ranges for local ips'?
a lotta info dump. Experience helps ofc. Common sense and listening wiith good note taking
Air-quotes very appropriate when mentioning "AI".โข๏ธ
the tricky thing for me was more the theory than the practical elements especially for the assessment
Well it's difficult to say. All the usable ones are at least under control of companies or goverrnment organisations but they can lease small subnets
They're considered reserved network ranges that you can use in private networks not directly connected to the internet
Is that the SJA one you booked, Jayy?
mhm i see
also another question sorry
do both protocols change from time to time or are they both static (IPV4/IPV6)?
Theoretically we did use all IPv4 ips and there wasnโt a back up plan like ipv6. What would happen?
Should I be making flashcards to memorise as much as possible? Or focus more on trying to understand why?
I'm waiting for the day when one AI charges another AI for algorithmic plagiarism. ๐
AIception
We're now at the stage where someone has proposed just skipping over the next big goal for AGI and going full belt for Superintelligence... Like yes, let's use a black hole as a power source before we've figured out how to fly that far
Let's start really small .... skip .... unlimited power.
Ooh is this the uhm cracked team?
Most of what you'll see is IPv4. IPv6 is a different protocol stack and they're not directly compatible. A computer can participate in both networks simultaneously (capacity pending)
Nothing dramatic at first. ISPs and other companies couldn't be assigned new addresses anymore. It would slow down growth. AFAIK that's been the case for years already.
It's a lot of knowledge test & decision making generally for FREC3. The practical assesments are more ensuring you don't do it wrong if that makes sense?
nice nice. LMK how it goes. It's basically brand new to SJA so should be good.
Yeah, let's jump an impossible technology with no theoretical objectives and go to the thing it could turn into. We'll just need all the fuel and building resources, and lots more compute
Feel like I'll be the youngest there ๐
Thatโs nice
Yeah, it's just more bull before the bubble pops from what I can tell
Plus LAS are changing their roles quite a bit. More info in DMs if you'd like but good opportunities coming up
Probably. Though it is June so you'll have some coming in preping for the uni pathway i.e. paramedic science
i see
thank you for your time
also im just starting ethical hacking and i dont know alot about some computer facts
you also have other sources i could use from + TryHackMe website
Gave +1 Rep to @proven quartz (current: #21 - 390)
Ben, how many rewatches of the x-files are you on
IPv6 stinky
3
Debating starting my 3rd, rewatched it in December only
halfway through 4
There's lots of stuff about Linux and Windows and Networks to get you started. Search for them in the Walkthroughs section
Oh good point
a necessary evil ๐
ya,man
that's what scares me
just SO much stuff to learn but i hope i'll do it
Thanks have a good day!
Best of luck and have fun
`Reserved IPv4 address blocks in IANA (Internet Assigned Numbers Authority) ran out on February 3, 2011. And the free pool of IPv4 addresses held by APNIC which is RIR in the Asia Pacific region ran out on April 15, 2011. In addition, the free pool of IPv4 addresses ran out in RIPE NCC (September 14, 2012), LACNIC(June 10, 2014) and ARIN(September 24, 2015).
This does not mean we will not be able to use the existing IPv4 Internet after the address pool runs out, but there are no more unallocated IPv4 addresses available from the Regional Internet Registries.` https://www.nic.ad.jp/en/ip/ipv4pool/
Oi @blazing granite , mind shooting me some lingustics books in DM, like why language evolved and how it even works on the low level for beginners
hey man you mind if i add you?
Cant tell. which device is using the most data?
probably the green one
is that pihole
Maybe they should resolve the measurement bias first, instead of loading up on quantity.
without the reference color chart definetely you can't ๐ ๐
Well you can ask any questions in the appropriate channels. I'm not always available but there's lots of helpful people in the Discord. There's also a lot of discussions of various topics if you use the search feature. You should verify your account
Does this help?
How does SSH take that much bandwidth unless you were using scp
ssh? ๐
Gotta move files around
It doesn't work if you're in a web browser on mobile, Subtlety. If that's how you're using discord currently
wonder if it's feasable to move that amount of data directly over ssh in text

encode a ubuntu desktop iso in base64, copy it over the shell session and see if it breaks
Otherwise it's now a /docs search: verify
Oh they've got all the data humans can produce. They've reached a stage where there's no new data to farm, just a lot of repetition of previous stuff, so they're thinking they can have the ML algos generate the data (the same as how AlphaGo played more games than humans in thousands of years of history) and that that combined with lots more compute will solve most of the issues and lead to the machines eventually solving themselves
I just touch it and it breaks
if you have an actual job opportunity to offer, please contact one of the Discord Admins to verify your recruiter status to post to #jobs-board
attempting encoding a 20 gb file in base64 then copying it over the shell session
Ah I didn't realise they'd changed it ๐ Thanks for the info
Gave +1 Rep to @clear jackal (current: #19 - 409)
We can't all crash systems with your flare tho ๐
huh apparently fzf has shell intergrations
for things like ctrl + r history browsing

yeah i've been wanting to try it out. fuzzy finding is history is really useful
We need the Data Discernment Protocolโข๏ธ, to solve the outdated data problem. ๐
install fzf
run source <(fzf --bash) or source <(fzf --zsh)
make sure to have a history ammount and append set in rc file
i.e it is not hard
yeah it's just that I forget to do that when I'm on the VM.
ah fair enoughs
shadow is more questioning if they should use it on their daily driver
couldn't hurt I mostly daily drive windows due to various reasons so don't really have a use for it on that
to each their own
on windows barely run like 10 command so the regular that are easily accessible by regular history search
linux simply does everything shadow needs and at a faster and nicer pace then windows 10 and not touching windows 11 with recall
I have a question about the site..
scratches head why cewl is still borked
what part though? I don't see any active issues on their repo that would suggest it's broken
Why canโt I see my machine that is started when in a room? There is also no option for split screen.
every time shadow tries to run it it complains about no existing json bundle for ruby
could be because shadows ruby verison is significantly newer then the one used by cewl
some target machines don't launch split views and you are meant to attack them in other ways
@umbral bay I'm doing THM rooms again, are you proud? ๐ฅบ
You can still disable recall
if you don't wanna spin up your own kali linux vm the route forward is hitting the start attackbox button
The one problem i usually have with ruby stuff is that it doesn't install dependencies automatically I usually have to go manually install them.
Now i wonder if there is a pipx like program for ruby
gem
by default installs ruby packages as more or less standalone and only in user space instead of system space
does it isolate the environ though. I honestly have no idea how ruby deals with dependency hell. But gem pretty much always has failed to install dependdecies. Probably due to me doing somehting wrong
not sure
yeah I guess I had to use bundle instead of gem
reading the documentation helps who knew ๐คทโโ๏ธ
I don't think there's enough poorly paid people in third world countries to make that work...
feels like the amount of poorly paid people in third world countries decreases by multiple promil every few months
Does this seem stupid to me or is it really.
Sending a password in plain text via HTTPS to a api that hashes the password in MD5
then the second request sends the password hashed with the response from first request then another request for the username
well yeah that sounds like a security risk
What would the security risk be except the plain text password
plaint text means that if anyone can sniff the connect they can impersonate users or admins by login into the user
the second part is using md5 which is no longer considered good enough for password hash storage
the third is sending user data to an api that could potentially be exploited if you send it the right data as the password variable
the third one is hard to know if it exists or not so maybe scratch that depending on senario or info
||Are you a vulnerability? Because I want to exploit you. ||

This actualised slay.exe โ ๏ธ
Brotha
I think โexploitโ is the wrong word here
Thanks, sending a email to my bank right now.
Gave +1 Rep to @sand trench (current: #4 - 1779)
First felt a lot off due to the highly weird implementation
your bank use MD5?
also their bug bounties is a mess
wut
can get you into a lot of trouble
It's a third world country
What can you expect
The website UI was last updated in 2014
noice
I would move your money first, so they don't lock your account in retaliation, etc.
Sounds about right
The balance is pretty low. so no worries there
well you outsmarted them with this move
You can't steal me if im poor
spooky scary skeletons
@sand trench I has mozzarella sticks! 
nono . He wake up , he bark at another dog , he goes back to sleep.
Dumb Dog
Fried 
Baked one's are meh
I thought non-fried are regular sting cheese?
i go back studying NTDS.dit attack , see you later guyz
yes tbh
sounds/seems like a magnificent life.
lol
nah, it's magnificent life when you don't want dog food and my mom gives you steak
that is a magnificent life
or when you are a dog but you have a memory form bed
i should have taken a chiwawa , it'd have been less cringe
frfr
i wonder if the internet engineering taskforce is still a thing
@sand trench someone said me you are one of the best C# programmer in the world. Is this true?
???
How dare you prefer the literal demonic imps over literally any dog
Hate filled creatures, them
I hate chihuahuas.
And yes, I meant for the dog. Who wouldn't just get up, bark some sh-t up, and go back to sleep. lol
you mean microsoft java???? :P
Hey guys, took a small hiatus because of summer college courses (Biology major intended course + cyberSec hobby = very rough time)
shadow does emma do c#
I got the linux cybersec book though im gonna start reading it
me too , but seeing a chuhuahua sitting on a memory form bed is less cringe than see a pitbull
Are you one of the best microsoft java develpor in the world?
Let the doggo rest like a king.
not really
C#?
nah shadow has not touched c# or java in ages
could you be thinking of emma
i think you can be the best if you want
you just need to start
maybe starting answering some questions in the programming discussion
I gotta ask. Y'all ever had your teachers say "This is the worst class I have ever had?"
naturally
if they don't say that they got fired
i need help and was wondering if sm1 could help me
I swear, they use that line as psychological warfare.
let's be honest , no student care
for?
Oh no, but the good ones would feel guilty inside like they did something wrong when they didn't lol
It's fine, you'll find a point where you can say "this is the worst class I'VE ever had". For me it was malware analysis at university, assignment completed week 1 with full marks.
imo good ones have some kinda of problem. TBH bad ones have surely more , but yeah
i was wondering is it possible to track a phone number i have been getting harassed and the person is impersonating sm1 i know
I haven't been in school in a hot minute. I'm just thinking back to my high school days lol
@sick lance

so it's impossible?
how do you know it's not @boreal scarab ?
maybe he is harrassing you
wow wow, this went from 0 to 100 lol
@shell novahydra would help
We just wont help as that would be considered unethical.
You need to report it to your local authorities
Vigilantism is unethical and against our community rules
that guy started a discussion that went for over 4 hours. It's devil himself
yeah i just wanted to know if it was someone i knew before i took it any furter
All I said was study OSINT 
Yes the police will know
I mean at major reason , if it's someone you know , report him
I thought it said "I plead the FIFI"
It does lol
its not really serious serious its just a constant annoyance
it's a crime. Report it
the worst part about it is the acting of sm1 ik
second crime
yeah i said that
we are already at 2, just report it
Canโt you block phone numbers
report it. Block the number, it's probably a continuous scam scheme. The same happened to me, when a family member got their phone stolen (they forgot the phone in a supermarket, when they went back, no phone was found). They based the scam call based on the details found on the phone.
Based on the occurred, I simply cussed them out, blocked them, and continued with my life.
This conversation doesnโt need to continue
Why not block them
i have
no this person knows personal details about me and relation ships of mine
^
that's not harrassing

that's giving me more gif to use
Oh don't get me started, Jabba would yell at me lol
im a gif addict too , so yeah
Just makes me sound bad, thanks
Gave +1 Rep to @boreal scarab (current: #30 - 265)
Free rep, gracias ๐
to not get your fingers bitten off drop the cheese @boreal scarab
Oooh, cheese! I want! (:
Your true colors are showing
You're still on cooldown
Crazy
Triggered
We still love ya. I know I can spam a lot of gifs lmao. I try and take it easy, but come on, its fun!
Oh hell no you aint taking that rep!
You just have to be mindful of how comments make community members seem to people viewing.
There has been a lot of โmod hateโ recently in the discord server and itโs not appreciated - not saying that you are the one hating
A hater


Hi
Hi

Mod hate, people can hate on me, but when volunteers are spending their free time protecting and growing the community, only to be hated on, itโs sad to see ๐
so we can hate you?
Time and a place homie
Jabba is the best
I always make fun of @cosmic pendant burning crap
I knew that was coming
Bet that smells bad

Always busting Toaster's chops, with all the beep beeps too
But who hate mods in a discord server?
People who go against the rules
They hate being told no
pfffffff
Thatโs with every discord server tho
We heat cheese just for the melty texture.
It is delicious.
i have a dark humor joke , but i'll pass on this one
yeah best to pass.
and times for the whimes of the bimes where shadow goes to sleeps for the sloops to the beeps of the boops while meepity moopity meep moop
Goodnight Moon
hi
LowBatteryD2.โข๏ธ
R0D2 ๐
Hello everyone, is there a way I can change to pay for the subscription with US $ instead of GBP? I don't see an option to do that.
Or will it automatically convert with Paypal/Debit card?
It will automatically convert. Possibly not at a favorable rate, but afaik that's your only option. I misremembered then. Or I was thinking EUR
https://tryhackme.com/r/pricing you can select USD at the top. It's $14 a month if you do it month by month.
I don't remember seeing that option (and I'm pretty sure I looked), but either way I'm set up now.
if the null byte is fixed by php 5.3.4 does that make file inclution impossible?
or does it just reduce the things that it can do
It does not make it impossible. Only that particular method.
what other method can you use to make it not add a ".php" and stuff
cuz THM does not tell you the new one
also @wide marten i sent you a friend req ๐
You can find loads of other techniques here: https://book.hacktricks.xyz/pentesting-web/file-inclusion
thanks!
I know, but since you earlier mentioned you're 15 and I don't know if your parents would appreciate you being "friends" with a stranger twice your age, I declined.
oh they know, but i comprehend
i hope i can still dm you if i have questions
still working on the jacket ๐
Why? I assumed it's easier
I just dont like the multiple choice format of it
and there isnt as much info / material to prepare
@hot cairn @wide marten how'd you guys gain the hacker intuition?
like, i see THM taking conclusions from error msges that i never would have seen
Pattern matching / repetition
Ask me once I passed the OSCP ๐
ok
Opposite of not asking to ping
its asking to ping before dm'ing
Example?
Pretty much
you learn to pickup on things
and while usually it doesnt exactly apply
being able to pickup on things similar you've seen before and apply that concept
Learning to learn is important aswell
you get that "deadeye"
things always change, so being able to pickup on things and adapt is key
which room do we ask for help
But its kinda creepy
go ahead

No, im asking for me. I just joined and I'm stuck on a THM exercise
room-help
awesome thank you
Will it be illegal if i had the password for every user in a school webpage?
that's very vague
Im not planing on having them
I need help configuring my pc to wake up up from rest. Pc wakes up but monitors are still off
Im just questioning if the police will knock on my door
so you have them
go into the monitor settings and set to to sleep rather than turn off
Loved repping THM at Defcon
Dms
sure
How did you aquire them? It doesn't need to be illegal for expulsion.
everyone had the same pass
he didnt like sqli or sum
thats what he told me
Also, I would recommend you report it to your school administration
.
I would do school IT
I got out of that school a long time ago
I just had my profile still active
fyi school admin and IT are often not the brightest and can accuse you of doing dumb shit if you report, as well
yes
ik
so if you aren't able to articulate yourself, silence is sometimes easiest
So you're using passwords on systems you're no longer permitted to use?
i found a XSS wordpress in my schools website
and cant report it
cuz they'll blame me for random stuff
No
I was a student
extension is like 5 years old lmfao
Do they have a bug bounty? If not, you shouldn't have been poking around.
@blazing granite I hope they have this again this year lol
But i tried logging into my friends users and it got through


wait poking around is frowned upon?
and I know it's not actual wine, it's the app
what type of wine goes best with wannacry
In the United States, it's illegal without authorization.
The cheapest bottle to cry into when you got wannacryed
And it's unethical otherwise
Running automated scans can break things. You donโt do it on things you donโt own. You break it, you break computer misuse and suffer the consequences
sounds great
i did not know that mb
wont do it again ong
I hate kids today's lingo
Lol
sry english is not my first langauge
i just use what i see
I'm just old as hell, and hate the whole "on god, skibbidi....." whatever else cringe shit there is
nah you cant group me up with that for using "ong"
thats like grouping a hacker with a war crimminal
i hate that 2
you sounded like 100 there ๐
ong
Ong is not a misspelled omg?
(but actually tho i agree)
on god
anyways
diamond is unbreakable
beat ya to it
TIL


that's so mean
i can not
productivity cant go there
il dm you
alex I think that
๐คจ
diamonds are incredibly hard and resistant to scratching, this does not mean they are unbreakable
so true
Lol
How can I turn it on now to change those settings so I donโt lose my notes from restarting it ;-;
^
wait, no
What is koth?
nvrmind
king of the hill
Whats that?
i SO BADLy wanna watch it live
Lol
@clear jackal read his username
?
read the username
Coconut water in spanish
no

nw
I will come here with the result of my search
is not


