#general
1 messages ยท Page 236 of 1
by the head of cybersecurity
I just sent a message to support, thanks!
frame rates yes XD
Gave +1 Rep to @boreal scarab (current: #30 - 267)
That's the reason if they are attacking windows then that's even bigger issue and if av or defender is on then you are lucky if it only takes a week
Then that's who you should be asking for assistance
who is indeed... my super visor
You're welcome!
Bollocks lmfao
tell me that is private range pls?
had a meeting today, and it is normal he says
it does take some time
Then there you go ๐คทโโ๏ธ
it's not on your own personal machine is it?
interesting
Oh boy.
It's not interesting, it's outright incorrect lmao
General is on one today.
When is it not?
all on a virtualbox, kali machine, connected to the company ovpn file
before doing anything
Sounds about right
it's not crunching up too many resources is it?
sorry what is incorrect here? maybe I misunderstood
You need to be more specific about the ips and ports you define try just discovery scans first then go for flags and version info
ummm..... umm......
It freezes from sometimes
is it running off your main desktop / device?
yes of course, pasted the scope in a txt file and then ran a discovery scan to check which hosts are active. spot on.
or a device for cybersec in general
It's honestly like the blind, leading the blind...
aint that the truth
Windows may be bloatware, but specific vulnerabilities aside it's not inherently a security issue... very fortunately given that it powers both the user and server estates for a significant majority of large orgs on the planet.
Targeted malware will also breeze past consumer grade AV like Defender, a scattergun approach will usually get picked up by AV, and "will be hacked in 5 days if you're lucky" is just laughable
In other words, there was literally nothing correct in that message 
Windows may be bloatware, but specific vulnerabilities aside it's not inherently a security issue
Not, admittedly, for lack of trying with recent "features" released...
I donโt even want to like, jump in on any of thisโฆ.
I wonder which av they refered to in
av or defender
wdym?
Probably sensible...
do you have a computer that you use for personal use and leisure and running vm's, or do you have 2 devices, one for leisure/personal use and one for vm's/work
In other words.
What do you mean i have literally encountered hundred scenerios where switching off AV and defender incresed the speed of my scans and scanning windows network takes way more time them debian whats wrong with that sir
Do you BYOD.
better way of phrasing it lol, thanks
Gave +1 Rep to @sick lance (current: #1 - 2435)
just couldnt remember the right phrase
Good morning/afternoon/evening everyone (:
I'd assume any decent org will give you a device that you should use for work related stuff.
I'd hope so
I would be upset if I was expected to run intensive things off my personal device without warning lol
especially overnight things
I'd refuse.
exactly
I mean unless they wanna buy me a new gpu and cpu :)
and while they're at it throw in a mobo and case
Here I am just hoping my jobs want me to run intensive stuff
Yo! I get to do password audits!
Scanning a network entirely filled with Windows devices may take longer if they're configured to treat it as a public network (thus blocking ICMP echo and forcing you to use -Pn). AV is unlikely to make a significant difference there. The host-based firewall might.
I forgot you were looking for a new job.
I got one ๐
nice, ๐
Wait long?
Sweet! Let me know if you want to automate it ๐
Took a while for the company formation to go through but otherwise not really
Don't forget most corporate networks will have a IPS/IDS on it.
AV won't detect a scan but they will
so far I found only 1 IP that has a ton of open tcp ports, 445 and 3389 being two of the ports. If I can just obtain creds from smb, then surely i can use that to login via rdp. BA BOOM! job done. But, that one IP also has the possibility of being a honeypot set by the client (according to my supervisor). in the last 4 months they got 3 pentests done, so they are well aware.
"Most" is a strong word 
Ya that's basic knowledge that's why i said to be precise about the hosts you target and the ports you scan and the AV part was from my personal experience in an assesment
okay time for sunset prayers...
And your suggestion was to turn AV off..?
My employer still uses plaintext passwords on a system... We probably don't have a IPS/IDS.
But yes, trying to scan a full subnet will always take a while compared to a targeted scan, obviously
Cheers autocorrect...
Configuration also plays a big part. No point in deploying network monitoring if it's not being parsed or alerted on properly
You work for the US Gov? 
if you have any docs or papers on better wordlist selection that you can share.... that's my first step, i think
Yeah IT are useless.
They've just adopted our systems. We are gonna go back to unadoption because they've already broken our software
guys
Also, thanks for the edits here. That makes a lot more sense as a point. I read it originally as "Windows is a problem and you'll be lucky if you don't get hacked within 5 days assuming you have AV active" ๐
Gave +1 Rep to @sharp zealot (current: #2103 - 1)
oof, that's kind of a hard topic actually
i was actually joking about automation because i now sell a product for that lol
im using 100mbps (download speed) plan for my home internet.. it seems really slow and takes too much time to download a game
do you think it'd help to connect LAN to my computer, instead of using wifi 6 that's on my motherboard?
that would be because it's slow and games are large
at least, by today's standards
A wired connection is always better than wireless
actually, not so much on modern wireless solutions
Way to drop your product in chat 
you're 5ghz 802.11ac will pull like 1.7Gbps 2x2
which is higher than most people's internal wired networks will do
is this an option?
do you think it'd help by a lot?
yeah i actually wont be doing that lol
Depends what you've got on your LAN tbf
man ppl say 100Mbps would be enough for gaming and watching stuff but noope
true
Still worth it if you're doing a lot of huge file transfers to a local NAS or something
unfortunately pipewrench is not allowed in scope for internal processes ๐ maybe if i do an onsite with our european 24hr contractor though......
If I was in a place that I would require that, coming straight to you first before anyone else 
Not massively. It depends on so many things. Game files are massive and you are also limited by the network you are downloading from. (i e steam servers etc)
Hey, as far as I'm concerned it's thinking outside the box and taking initiative!
yeah, but shilling my companies products comes second to giving out decent info and helping people haha
max speed of modern wifi is 400mbps. If your ISP provides 100mbps, there is no way for you to get around that limitation, other than get a new ISP.
"You never said I couldn't kidnap your project manager and hit them with a wrench until they gave up the password!"
I can't say this enough. I can't wait to I move
Going from 38-40 Mbps to 9550 is going to be insane.
you'll be eating it on every host upstream from you over 1Gbps, trust me
be careful about the caps in the abbreviation. Huge difference between Mbps and MBps
I gamed and streamed on 20mbps internete.. for years.. so if 100mbps isn't enough then it's likely not the speed.
A 10G WAN connection? (Or near abouts)
very true!
How tf did you pull that off?
How about 250Mbps download speed?
Love waiting on Security Onion 2.4 to load. I just wanna have fun and see what 2 offers over 1. Even though it's been like 3 years since 1 went EOL
Huh???
what did I walk into
step 1: identify the bottleneck
Me?
i have 5Gbps and soon 20Gbps options available around me
so its not unheard of
A spot of light torture. Nothing to worry about
damn i hope me too
Christ alive. I thought I was doing well at 1Gbps WAN
Gib! Best I got is 2 GBps
i'm only running 1Gbps right now
I'm not even running on that ๐
haven't upgraded internal to 10Gbps
in what world is scope not both white and black listing?
eating it?
so i see no need for larger WAN
I'm running 90Mbps on LAN...
Sssssshhhhhhhhhhhh
1Gbps here
I have so many devices on this network it's terrible.
See this is why contracts and proper scopes are important!
10g only from server to desktops on LAN
figures why I take so long to join a game of phasmo @boreal scarab
man i'd be happy to just have 1Gbps lol
losing speed
It will be much better than what I'm getting just now.
oh for sure
anything is better than what you have now lol
Starlink would be better, save for some latency
The joys of having nothing but farms around me.
find nearby dark fiber, get it drug over to you, buy service contract through a big ISP
lol is Starlink worth getting?
starlink will cause nighttime photography of the sky be bad
Hey, that would be a dream for @naive violet and all his radio/ ADS-B equipment!
and recently there was people looking into if starlink could hurt the ozone layer
for as much as i agree, i think the issue is being overstated a bit much
how will it hurt the ozone
I fail to see the logic
how does that work?
it will certainly be a thing, but it's not a new issue and dealing with it won't be impossible, just more intensive for some
Idk how a network connection can hurt Ozone
uhhhhhhh
that seems... odd
" injecting harmful pollutants such as aluminum oxides into the upper atmosphere as they burn up during reentry."
weren't we just considering doing this
for weather engineering
isnt futurism not credible on lots of things iirc
Isn't it related to the reactions with chlorine?
I just cleaned off my desk.. and it's already a wreck again... lol
honestly, i'm less worried about latency than i am saturation. so far, starlink has been fairly reliable in terms of throughput, but as user base increases, i could see it becoming much less reliable
hence they're 4x more sats plan
So it's byproducts from satelites that cause ozone damage?
but i agree
newly, according to the above
previously it was our usage of certain hydrocarbons
the burning up of the no longer in service satelites to hold the starlink network up could cause problems
but we've curbed that so well that the ozone layer has been healing
myabe
for worldwide market, i don't think that will be enough - at some point, it has to make money, and more investment means longer to be profitable
nah not the same chemicals and metals
if you wanna cool the earth you can shoot sulfur into the atmosphere but then you get other bad effects
starlink is cash positive as of this year iirc
most recent venture wants to use calcium carbonate apparently
The air was really refreshing when we had an actual 2 week lockdown for covid.
which makes sense
God One UI 6.1 is annoying me already.
wait what??? what are you doing on that ancient version of android scrubz???
that's so deep another rabbit hole lol
until they launch 4x satellites ๐ i would be interested to see the financials, do you know if it's publicly traded?
it's a subsidiary of spacex, which is not publicly traded
well when you are sending multiple thousands of satelites into the atmosphere just from starlink it is a valid concern and needs research
they are betting on starship to like, 1/10th their cost to launch sats
I just wish i bought nvidia a year ago
1-1 first half with Denmark and England
Fixed it.
hello guys
do any of yall know how to connect my VM on virtualbox to WIFI? (kali is my VM)
i'm not convinced that elon isn't playing money games to make starlink look profitable when it really isn't - it will be interesting to see what the next 5 years holds
Set it to nat.
you might need to choose your adapter.
its possible
in the advanced section?
tbh, for as much as i dont like the stuff he gets into a lot, spacex has been wildly successful
No idea, I don't use it.
shadow actually hopes it is not profitable and that starlink gets shut down for actual fiber optic instead
and starship is looking like it'll be launching sats much sooner than i would have expected
You might need to google, or hope somebody in here can help.
Yooooo can we land on the moon in 5 years
falconx started out extremely optimistic as well, and didn't it take 2-3x longer than expected to successfully launch and land?
This partnership with Snyk is exceptional
One of my most favorite devsecops tools to use
especially with all the nonsense spacex is going through with contracts for its use
No, we've been there before and haven't went back since, something is there that doesn't want us there. /s
Partnering with Synk is a good move.. ๐
obviously it's aliens
according to micheal bay, i think its alien Robots
why building kitchen take so much time
the moon is a giant egg
and you can't prove otherwise
most recently, wasnt it an alien space ship
or like, proto human space ship
or something dumb
j/k.. but we all know it's a big cheese. ๐
i think moonfall was the most recent "the moon is not what it seems" movie ive seen
if ez can prove otherwise shadow would be impressed
and its..... bad
just read this, I myself had a laughter as someone who is also not a huge fan of AI, how do you guys find the article yourself?
lots of apocalyptic movies are badf
I cannot prove.. I can only state what I've been told. Nobody knows for sure. ๐
Pog
hahahahaha complimentary chiropractic adjustment
im on the author's side here, but in a more pedantic way
calling it AI in general is part of the problem imo
that's the thing, it's not AI at all, it's just a program that scraps data and spits it out to you, sometimes, even being false
Nerds
we're not creating intelligence because we have a very hard time defining intelligence, but we are creating some interestingly powerful and somewhat useful statistical models capable of some very cool stuff
that sounds about right, well said
i think attributing much more than that to it is... poor understanding
lots of "it can reason!!!!" going around that makes literally no sense when you know how transformers work
I think AI is simply a wikipedia
Like in your home?
like, lets step back a bit and define what it means to reason thoroughly before we say it can or cant
tbh, I'm going function over form when I get to build my kitchen
yes,....
You've got to plan, schedule contractors if you're not going it yourself, then materials have to be ordered, then work begins, then as you're working you have to crosscheck to make sure the written/draft plans are actually going to work, etc etc
it can give you information to its best knowledge that's available out there on internet and with users' input but it cannot create its own things
yh, not just intelligence. consciousness, the concept of the self. do these things actually exist? are they just emergent properties of complex systems? do you exist, or are you just a lie that you believe so completely as to think it is true without question?
actually, this is sorta backwards
exactly, we can't easily quantify these things so how can we attribute them
Is there any way to know how many users have finished a room?
Only via the API
Security Onion 2 is giving me a headache, it was Ubuntu, then they moved it to Oracle Linux which is Fedora.......
jfc
AFAIK these are open questions for researching evolutionary biologists and neurobiologists. We do know what conciousness is not though, and AI is not conciousness.
It's not. Oracle linux is a fork of centos, not fedora
Oh my bad, when I opened the browser, went straight to FedoraProject
rather, it was a fork of centos. Since RH started centos stream, i don't know where oracle pulls their builds from.
Seriously? I'm surprised the browser didn't default to security onion or oracle to be honest.
Yah, that's why I thought it was Fedora
Who else thinks that THM should have a dark theme as well its not really comfortable to learn for hours on THM website...
yh, but its works fine with darkreader
Soonโข๏ธ
Been around 4~ years now, so anytime soon hopefully...
I've used dark reader, but it often breaks the machines or simple pages from split views. So I have been using it light mode.
Just installed after facing seveir head ache
hi
bro that is literaly the only negative aspect of thm
I used to use another extension, a json something, don't remember the name, it was from the authors github I got it. was good in the beginning, but the same issue as dark reader.
Hopefully they implement it natively in the website (:
hi
hi
Exactly after paying so much for the subscription... Its feels so bad to install another extension just for THM
still doesn't change the fact you have to do it โน๏ธ
@boreal scarab welp... this is disaster...
ewwwwwwwwwwwwwwwwwww
Hey, as someone new to cybersecurity looking to improve on the skills I'm learning from tryhackme, I've been wondering something about lab boxes;
Are containers a viable alternative to having a physical lab box for practicing on? (I ask even though I realize that this entire site is very likely comprised of containers for the modules)
depends on what you're trying to practice. Web stuff? absolutely. Database? Yes. AD/Kerberos? probably, but certain products are 'heavy' enough that they would probably work better as a vm than a container.
Another thing to consider with containers vs vms, how much segmentation do you need or want in your practice lab? Escaping from a container can give very different access than you expect, and escaping from a vm is extremely difficult
Much appreciated juun, thank you. That makes a lot of sense. Being only 3 weeks in, I'm still working on the basics. I can see for the time being that a container probably makes sense but a vm is just as easy to get going. I'll give the vm route a try. Thank you
you wanted a thunderdome????
storm chaser?
nah I just like the noise
no need to chase storms when they usually pass within 1-2 miles
so I can see them from my window / porch
contact twitter support
??? why
Anybody here ever switched everything from wireless (battery operated) to wired
Tired of my batteries dying in a year or two
Keyboard - wired, Mouse - wired, Headphones - wired 

brain - wired
I like the smell and feel and all, but we have powercuts when ther's a thunderstorm haha
ahh
cause all the electrical wiring is above ground and they can't risk anyone dying
you gotta get your city to fix their grid :p
I got a wireless mouse (battery life degraded 70% in a year and a half), wireless earbuds (battery life degraded 80% in less than a year), gopro battery (degraded to 0%)
where I live we never have outagaes
The entire country is like this 
so mad right now
the only outage we had was some goof not calling before he dug
and he cut the main fiber trunk
for 4 states
4 states???? 
yep
was he punished???
well lmfao
not always, there was a scenario over here where a old guy or women cut off some fiber lines near a train track a couple years ago
"Linux
If you use Linux and donโt already know how to use GPG, stop using Linux immediately - you simply arenโt worthy!"
nothing happened because they couldn't find them
incredible
@chilly veldt gg, England was a shambles
3rd party gopro or official?
sheesh
not doing any battery management?
that's like, 100 -> 0 -> 100 rate of degradation
US/north america based?
if so, that'd be because of this
not necessairly
well, strongly correlated at least
yeah, it's not a perfect predictor, it's only one piece of the puzzle
patterns from up north cause major storms too, like polar vortex years
yes but the real indicator would the jetstream
where the 2 fronts would theoretically mix
right
gulf + canadas polar air
what helps is when the gulf air and polar air mix in the northwest of the united states
then get stuck in the midwest
all of our recent wetness (texas) has been pretty lined up with El Nino/La Nina
yep
Drink all the booze!
All this storm talk and Shadow is in Sweden 
Yeah.
@mossy river
The cat cafe I went to had kittens!
Two of the British shorthaired cats had kitters.
offical's blew up literally
well sweden is close to the golf stream
3rd party right now
that seems high, but then again I do use my tech daily
Do you chew through the battery from full charge to nothing and back?
gopro not exactly daily but atleast twice a week for timelapses or doing some stupid stuff
Yes
that will rapidly degrade them
lithium batters want to be between 50-70%
really 20-90% is the usable range
but 90-100 and 0-20 are doing damage to the battery
I usually keep my phone's in the 60% range and laptop in 80% but I can't really keep track of the small tech item's batteries
some batteries over provision to avoid this to some degree
but many don't
on cameras especially, they are likely to run kinda hot too
I always leave my laptop plugged in.
if you do that, enable some of the "Smart" battery stuff
to keep it at 70%
helps keep the battery safe
hero 8
Any precautions I should take for something without a active battery indicator
well, you can guesstimate battery percentages based on runtimes and starting from full
brb 5 min
but really, on small devices like a gopro, its likely that those are just consumables if you are running them flat
buy more, buy better
I have 3 batteries for my GP.
Getting around the same time on each battery, just depends on how I shoot.
Hellooooooooi
Hello.
I canโt believe Iโm at 2 months working in IT now
@pallid lotus how long did OSWE take you?
10/10 Will stretch again
Omg what!!!!
I want to see kittens ;(
Yeah, they brought them out just before we left, and one kitten came to say hi.
What, the exam or the course?
Exam.
It took a time
-.-
is there a dark mode
DarkReader.
Not yet
mmmmmmmmmmmm almost used up 32 GB with just 2 VM's running. Yummy
But Soonโข๏ธ
im finna go blind
DarkReader
Turn on the light in your bedroom
Or lights, if you have them. Yeah
To get passing points? About 24 hours total (including sleep, etc) iirc.
I kept going after that though.
Damn.
I wonder how fluff is doing. 
Knowing Fluff? Spectacularly I'm sure
Ya
do they really need that much?
Probably trying to mimic a computer on a VM.
Main OS is probably using 8 GB
Someone asking me where the train is going like Iโm not also thinking the same ๐ญ
Forward, trains go forward.
So each is probably allocated ~10 GB. It also depends if "expand" was set or not
I forget the actual term
Trains have seats that go both ways though so it depends on where youโre sitting bestie
No, the train is still moving in a forward direction as that's where the driver is ๐
Remember, north is always the direction you're facing! vibes
Sounds like runscape lol
https://www.volunteeramnestyday.net/
Make sure to look after yourself folks
I always have to play top down with north facing the top of the screen
Otherwise I get lost
Lmao
that could actually be the premise of a cool story.
constantly on the run from governments of the world who want to assassinate them, because they make global navigation a nightmare.
Is it worth learning the new DevSecOps module, I don't have a interest in DevSecOps but wouldn't mind learning if there's a general usage of the knowledge.
Yes, yes they do
Just did the blinkers today
I have new blinkers for my bike.. and I have to fix my headlight. Only things that really got damaged in my accident.. besides me.. lol
Lmao
My right rear blinker was broken when I bought it
Buuuuut, when the paperwork is over then it's fun stuff time
Burrrrriiitttooooo! โค๏ธ

@mossy river I know it's not in #873642346762350592, but look! Burrito!
enie minie, mynie idk
Iโve eaten too much food, I canโt look at food rn
Is there somebody else who has issues connecting to the VMs?
Are you the same way as me? If you feel full you can't even talk about food?
Mhm

Went to a buffet
These are legal?
well "legal"
they are legal until you do something illegal and then you can get fined for them
This video was so much fun and took alot of time to edit. I hope everyone enjoys it! #54 at krogers made my day!๐ shout out to everyone that was in my video! Ya'll are amazing people!
Subscribe to see more ๐
Follow me on social media!
https://www.facebook.com/glennyrides
Lots and lots of chicken

I mean they donโt obstruct the rider so theyโre fine, I havenโt heard of anyone getting into trouble for them
I am back. Now with Gigabit Internet ๐
yeah, by itself it's not illegal, they can obstruct the view, but if the cops have a bad day or you do something dumb, they can add it to the fine
Idk how that would hold in court tbf
They're slip covers, at speed they can slide up and jam the helmet or cover the visor. In the US it's state dependent, but EU/your side of the pond is a bit stricter on this sort of stuff so I was curious.
Bor it toe done 
they are also adviced not to use in high speed
Yeah if you're going to do it, add some double sided tape to secure it
yup, it'll only be used in city driving
@muted rock no unsolicited friend request please
nice, more upstream on those lines, I rarely get more than 10Mbps up. So even 100 is a big upgrade for me
long time, how're you doing?
I'm sick at the moment, first day without fever since 2 or 3 days I didn't recognise you with the new colour. Do we need to call you master now? ๐ ๐
how are you?
Doing good ๐
Amateurs
looks good
around 35 pounds for 250mbps
is it bad
i mean i came from 20mbps to 250 and the change has been awsome
I have ADSL in my apartment
39โฌ == 41$ for 1000mbps
what isp is that?
for me its virgin
which is just bad
Somebody in the woods in france
It must be because of the density
probable the provider use 1 cable with 400 different providers and thats why its that low lol
Zergling bestling
๐
change isp
my parents refuse to lol
noobs
dammm
I'm actually limited by my NIC
thats fast
and the switch
tell your parents isp is scammer
i think about 30 pound
damm they robbing you
they will change it immediately
uk?
my estimate might be wrong
oh alr
I usually get 310, but I'm streaming
pretty good for this part of the world ๐
i would tell your parents that they are getting scammed by thier isp
my ISP claims 5 Gbps
yo i get 16 download 0.7 upload that's good for ya
wow
just means I can max out the ethernet without affecting anyone
I live actually inside the earth's crust
pretty sure we all do ๐
lol
gravity is still a thing
i live in the centre actually
must be hot in there ๐
people say that nasa wifi is blazing fast, is it actually true? cause i heard it when i was small
a company with a trillion budget it should be like that i think
yeah
yeah 91 gigs dammm
11375
Wifi where? NASA has a ton of offices.
holy
megabytes
NASA is neither a company nor do they have a trillion dollar budget lol
idk probably their main office they use for launch grounds
They have many launch grounds lol
writing randomly
who is using that lol
Who wouldn't?
tell them to donate some mbps to me
Better to me
But their speeds are likely similar to other government facilities, meaning limited wifi due to being in old buildings and average wired speeds

helpdesker
Actually, it's my parents internet
first time hearing that one, i will use it next time lol
where could i get help for a bug bounty?
Didn't you ask that yesterday and got a few resources?
Anyone else's desktop discord crashed?
i mean pple
geez
what to do thou
should I study for a test
or
do some tryhacckme
this is so confusing
Probably study for the test
If you have questions, ask in #bug-bounty
Test is more important.
I don't know anybody who didn't study for a test and pass, so if you want to pass you know what you need to do ๐
2 options
- Yes, study
- Hire a witch to do some black magic or just pray
- skip option two and go strait to number 1 ๐
what is confusing is what do you find confusing ๐
I have upcoming physics and chem tests man.
physics it's OK, but I love chemistry
Chem, Really? your brain must be made of steel to manage that lol
Sorry my internet was a bit slow didn't see the NASA speed until now
I did a science orientation in my high school, I had subjects like microbiology, neuroscience, bio chemistry, etc
I like both
see now what you said there"microbiology, neurosicence" i could not understand at all .
Oh intellectual people are here๐ญ
i hate math with a passion, but started learning yesterday again of hexadeciemls and other things
i only got an A in english lol
Atleast we don't need calculus
cant we use a stopwatch on phones for that?
What on earth is hexadecimal,
thats what i said yesterday
its used for encryption ig
you can try it in the capture the flag room
๐ญ
I mean time needed to bruteforce all combinations, just an example
we actually need
Ohh Alr
https://tryhackme.com/r/room/c4ptur3th3fl4g yeah this room uses it
and a bunch more
micro comes from the Greek small, study of microorganisms or small organism ๐ neuroscience study the nervous system, its functions and disorders
encoding
Thank you ๐ซถ
Gave +1 Rep to @errant fossil (current: #857 - 4)
we need a "why the fuck" science and scientists that can tell us why OT owners most of the time dont give a fuck about cybersecurity
That's just not true
Ohhhhhhh yeah lol now i get it now yeah ig the words neurscience and microorganisms sounds to advance for me lol, Thanks for the information
Gave +1 Rep to @blazing granite (current: #75 - 84)
you don't need to know math or use math but if you do, you can understand things better, for example hash functions comes to mind
In a lot of cases, they cannot just replace components as new security features come out. If they did introduce a replacement, it could require the entire process to be reworked. Which can be upwards of millions, if not billions, of dollars.
i think i will need to look into hash functions tmrw
Thanks for the suggestion
https://brilliant.org/ maybe can help you with math
There's also potential governmental policy in place restricting changes as well
this is what i just started doing since yesterday lol, yeah it has made it easier to learn compared to my old school teacher
But if they eventually get hacked - the consequences would be worse, and might take lives. No?
Have you looked at the purdue model?
great site, I understand math is not complicated or something to be fearful of, it's depends who teaches. There are a lot of rubbish math teacher out there that scared people for life ๐
a bit yeah
exactly what has happened to me lol, in lockdown i had an amazing teacher but when we came back to school she left lol and some random teacher took over and they did not care at all
Brilliant is brilliant
there is not better name for the site ๐
Got an annual subscription 50% of because of black Friday, and it's been 100% worth it
OK so on that model, your level 0-2 items are typically all of your "unsecure" devices like PLCs and other operational devices. They should never, and really aren't if the org is competent, connected to an outside network.
that's good math ๐
Yes, those devices on paper don't have modern security and they realistically don't* if you're segmented correctly. However, a change there typically means needing to recertify the process, if not the whole environment.
They do it every Black Friday?
Not sure
keep your eyes peel for next year ๐
i 100% will do
might just get it fully now
by recertify you mean to start the whole testing process again?
It's a lot more complex than, "throw xyz security measure on it" because a) that can actually kill people, b) it can disrupt processes, and c) have unintended consequences
Look up factory certification or look on Robert Lee's website. I think he might have some stuff on there
hello
TF is this?
(Stole from someone from HTB)
The factory get certified to run in a specific configuration and changes require change management
Okay, thank you! I'll do some googling
Gave +1 Rep to @clear jackal (current: #19 - 410)
The council postponed the vote
Hi
so som guy got remote access to my computer an was playing scary music and shii i hard reses my computer and re installed win is there any way i can get him back?
lol
Someone will be by to assist you with your goals in a moment
Report and move on
@sick lanceyes daddy
it multiple orders of magnitude faster then you doing manual enumration
Please no
@sick lancelol
studied
this is crazy
model checking is so interesting yet so not usful which is crazy
you are not with the right people
if in the university u didn't go to sleep praying a subject wouldn't come up in a test becuase you didn't cover it
U didn't really live
If I was stuck on a room and needed help, what channel should I go to?
first of all look it up on google, there might be a writeup if you didn't find refrences to solve it
but you can ask here
Would that be #room-help
also you could go to room help in support, there might help you
I just completed the python playground room. And i have to admit. This was very fun.
It felt rather easy except last flag which totaly is a very unique priv esc thanks for the room
you mean the wrong people if you left thing out and didn't study, also you should be surprise how much I lived and my life experiences. You're making a wrong assumption and you know what people say about assuming ๐
neah, the wrong people are the ones who aren't creative enough, this is what cyber is about creativity, if you follow the box, you might know tools and usage, butg creativity, comes from the place we are not sure about
this is why challanging urself is important
and I see it as a challange
but
it is different for each one
Eh?
That's just poor preparation on your part.
If you went to bed praying a subject wouldn't come up in a test because you didn't cover it then that's a failure on you, not on others for being better prepared.
so I won't be jugding you
And that had nothing to do with creativity
You can be creative and perfectly organised
I'm not saying it isn't on me, im saying that the best solution comes from the places we are not sure about
for me, the part where I'm not complete is where i'm most thriving
this is just my two cent
in order to be creative, you need foundation and knowledge, it's hard to get that if you don't study. In order to be creative in cyber you need to know where to stand and what you can and can't do.
and first and second year I was organised, but now i'm why more creative
Yeah, you don't work in offensive cyber do you? 
I am
Exactly this.
Being able to research, experiment, and learn, are crucial for security testing. Having no foundation in a topic is just downright dangerous
I respect it, for me it doesn't work like that, think about it like this, we are learning reverse shell, so we read th basic, and that is all you need, the rules, when you know the rules, you can develop your own rules, which are way cooler.
What rules have you developed for reverse shells, dare I ask..?
let's say you write a program, I would spend more time knowing what do you do, how do you code etc, then learning toolsthat would help me beat your app
Better not to leave them to luck. I have math exam next week and i haven't studied yet kek
Do what I say, not what I do lol
good luck man, you got it, think about it as 7 days of hell for 60 days of heaven
Meanwhile physics:
think you can make your own rules it's pretty dangerous in this field you can end up on the wrong side in a sec
for me, I connect asm and python to have better control over a TCP connection I opened with remote shell, in a nutshell, I would love to expand, but I don't think I can that much
It's crucial to know where the limits are
I'm not disagreeing with you, just saying what works for me, to each is own
Right, okay, so that's not creating new rules for the topic, that's experimenting with new shellcode. Apples and oranges there
you are right, I think if you know how to build a right env for it you could try and experimenting
Yeah, my way is unlikely to land me in prison though 
I'm not doing it in an illigeal manner, I'm learning in a local env so I could gresp a better understanding
that's just how I learn things, see the basic then move forward
I think there's been a crossed wire here. Are you purely talking about learning a basic concept then experimenting in a lab, or (per the original analogy), are you talking about not bothering to learn the expected behaviours for security testing?
yep, we didn;t understand eachother
lol
but it's alright
you know what they say
Because yes, learning in a lab is ideal 
To anyone with a voucher and will love to give it away , I am kindly asking for it, so I could continue my learning .
@pallid lotus ๐ how are you?
๐
Nae bad, and you?
Question: is it normal that some rooms are "locked"?
bit sick ATM but I'll live ๐
Locked how?
if you don't want people to get into those that's a way to go ๐
There are some links in tasks where it leads to a locked room
I remember it was one about AD
Then what's the use of publishing a room and say it's locked... lol
Yeah hold on
๐
You're mine! throws a pokeball
It's not Friday yet... ๐
It is for me
pffft.. then you live in the future! Let me know how the weather is tomorrow.
loto numbers? ๐
Weather is nice tomorrow 
I'm gonna ask about the super bowl this year.. @devout palm, you better have the score for me! lol
Scores will be represented in numbers
if I'm not mistaken there some are free and some are premium rooms
I have a premium account though
That one shows locked for me too.
You see that?
Locked by creator it looks like.
Damn I needed to review some AD basics
The room owner has locked this room, which means you cannot view any task content.
Lemme talk to the manager to get the creator open the room 
Try this room instead. It follows the AD module. https://tryhackme.com/r/room/winadbasics
Hello, this is a retired room and replaced by winadbasics. ๐
Perfect, thanks!
great everybody deserve retirement ๐
Oh no.. what updated on Breaching AD?? It shows 100% but looks like my progress was reset.. 
Guess I'll have to do it again...
That or the Eternal Glory. ๐
Let me check for you.
Join the room.
Interesting! Thanks @umbral bay
Gave +1 Rep to @umbral bay (current: #16 - 454)
"Eternal isn't broken"
Speaking of "Eternal".. I've never had an issue with Blue.. ever.. always works the first time for me. lol
It appears as if you didn't finish the room before joining. ๐
How did I finish it if I didn't join? ๐คฃ
hello all i have a question about my next step in the jorney to becoming a cyber security beast. lol\
It is a network room, so it rotates out (unjoins) users after a certain amount of days, to keep the network seat allocation to "active users" who are still working on the network.
oh lol. Didn't know that. Well.. I guess I'm taking a seat on the room now. ๐ฆ
No worries. ๐
i just finished my introduction to the fundameltals where shoould i go next. im trying to do the investigating windows and its hard.
I just like seeing that green check when I search say "Active Directory". lol
Have you tried the new Navbar search?
I have and I like it! Excellent add.
Wait until you see the new Dashboard. ๐
what's the dev site so I can get a sneak peek?? ๐ค
is dark mode finally here?
soon โข๏ธ
soon โข๏ธ
@graceful thistleDid you stop being a mod to focus on DMC 24/7?
First time using Ghidra. Send help @sick lance
prayers... but u can do it!

what do you need help on?
Well, it's for a HTB Challenge, have to look through the source code to find the flag
i c
Run DMC?
My head hurts looking at this
DMC = Devil may cry
Yeah it can be a lot to look at as a whole. Understand what you need to find and use what search tool is necessary.
I think I bypassed a challenge like that using strings
Hello everyone, I just join this server and I need help in solving one of my task on nmap. Specifically task 11 second question which requires me to read within the script and state what it depends on.
cries in no ctrl f
so DMZ = is Devil May Zoink?
A'ight... I'll see myself out
Not in prod. ๐
HOW SOON
haha
Soon.โข๏ธ

Haven't used Ghidra in awhile. Maybe this will help. https://tryhackme.com/r/room/advancedstaticanalysis
Subscriber room ๐
Thanks, I did posted my question on there, hopefully I get help.
Gave +1 Rep to @buoyant tree (current: #115 - 57)
ngl the subscriber rooms is where I learned the most or at least put it in practice.
I said fuck Ghidra.... I just went into IDA64 and found it
that'll work too. lol
ewww
Ghidra is soo much better than Ida
Yah but IDA gave me the answer in a hex dump than Ghidra's mess of a UI
Ghidra has mulitplayer ๐
Decompiler is annoying sometimes
just set your symbols/fucntion pointer and your're gold
that's pay right?
No i use free
If those Discord Updates DMs are legit, idk if I like that
they actually are
i got 1 awhile ago.
hello
Bruh
One of my moderators got his discord account hacked ๐
Revoked his mod before he can do anything bad
Luckily
what a skid shitter
well a skid is a person who uses software with no knowledge of how it works, how do you use it properly, and just uses it for harm. atleast from my understanding
itโs just a joke
?
?
how is "what is" a joke
have a nice day
ight
The what?
sony probably wanted everyone to link a psn acc
Yall receive discord dms?
yuh
bro i dont get it. how in the world am i supposed to get root privlages in the nmap room.
thought root is only for when you ssh
like every scan i do it says "The scan you requested needs root privileges" WHAT
actually i think i need to install root login for kali
Sudo?
sudo nmap blabla

that would make more sense cus i was trying to su
Ah
now that i think is for ssh right
sudo su - should work
SSH just let's you log in remotely
(And more, but like... ๐)
thanks that worked
Gave +1 Rep to @shadow loom (current: #496 - 9)
Slowly climbing the ladder
It ends in 8 hours, it looks like I'll fail
Look forward to when you get to port forwarding and proxying with ssh, that's some fun trickery
dont give up
8 hours is 8 hours
My mistake at OSCP was that I knew what I had to do but I followed my process blindly
Like if I knew that "in all labs, gobuster gives me the path after at most 60% completion", so I would stop it early
Well guess what... This time it wasn't until the last few pct I found the right gold nugget
I wrote a blog post about "trusting my methodology but not following it blindly" - you most likely know what to do, it's just not budging for one or the other tiny reason
Is CyberLens room intended to be completed without using any stego or EXIF Data ?
it sounds like thats where they want you to look, but i was able to complete it before that came up ๐
Ever since translating morse code embedded in a photo with stego I stay clear of that stuff personally...

what makes wordpress bad
i ran wpscan and it has old pluggins
OMG theres a file traversal and a xss
thats at least a medium bounty right?
theres php object injection 2
sounds like they don't pay for bounties ๐
What does it mean when they say a "machine has been retired"?
they do though?
hi
its on a website that does the whole exchange
verify the findings manually, see if the httpd account can access anything sensitive
the timer ran out
What does that mean?
Meaning you opened/tried to access a room and it's not there? If so, it's no longer available.
Im more asking, why do machines get categorized as being retired?
I don't know what room you're referencing, but it could have been superceded by a newer room.
YouTube recommended the Gawr Gura stream to me, honestly kind of impressive on the numbers. 70k viewers right now and was only 50k 15 minutes ago
Stego is amazing
That's got to be the most efficient stream. According to YouTube they went live for 45 minutes, got 72k concurrent viewers, a ton of donos, and then dipped
Do you guys recommend going for bachelor cybersecurity
If not then what degree should I pick in university?
The Snyk news is good. More vendors should put their tools on THM.
What do you want to do when you grow up?
Specific job or career?
I find cyber security interesting
But I'm still a newbie so I'm not sure what job to pick
Go computer science if you're unsure
Also what has the world come to, Banna at top 1#
It depends on where you are in life. If you are in HS, Computer Science is a goo way to go. You can choose your path in college. That path could be cyber, AI, cyber public policy, programming, or something else. But it will give you a good foundation.
@buoyant tree is right
So go computer science if your unsure and cyber security if you are sure?
Alr
I guess I'll go for CS to see everything
yea
you can still go into cybersec if you got a CS degree
You want flexiibility. So CS with a specialty or courses in cyber
You can choose specialty in master degree righ
4 years bachelor CS then 2 years cyber
And if AI or something else grabs your attention, then do that. (Hardware programming, OS development, firmware programming, basic IT, etc.)
Usually, a masters is specific. Though CS in a masters can also take you many directions.
Someone I know has a kid that had to make the same choice. She picked the bachelors in CS with a speciality in cyber at Rutgers in the US
If you have no professional experience, don't get a masters right away. It prices you out of entry level roles typically.
Computer Security degrees are hit or miss on quality. Computer Science is fairly standardized and offers flexibility.
Counterpoint: A masters gives you an advantage in job searches where you will be competing with other masters students for entry level work.
There really is no counterpoint. The company isn't going to choose you because you're too expensive/they know you'll leave shortly after getting that initial experience.
Oh wait so while studying CS you can choose specialize?
This conversation is for #cyber-and-careers anyway
Not necessarily. Companies are willing to bring on the best talent available and grow them. That includes salary. Obviously, these are generalizatoins and YMMV. I've hired great bachelor students over master students.
In some schools, yes.
Another option, I believe Brown University lets you start general and pick your courses. You can take a little more time to feel it out.
@leaden socket what do you want to do in cybersecurity? https://www.cyberseek.org/
Hack the Gap: Close the cybersecurity talent gap with interactive tools and data
I'll try it later cause I'm busy rn
Thanks
And sorry
Be ready to sell your soul before to get into Brown
Can you be more specific?
Elaborate on prices you out of entry level roles
Like does getting a master's over qualify you?
My opinion, no
like how malicious code load into their system
suppose u clicked a link it just download in that system not able to run
Go to any cyber job on LinkedIn and look at the percentages of applicants by degree. Masters is usually the plurality.
isnโt it a lot of undergrad degrees tho?
Yes, that is what I meant by "prices you out." Salary requirements are higher and the company doesn't want to invest in you when you're going to leave for greener pastures as soon as you get some experience.
Again, this stuff is best discussed in #cyber-and-careers
Yes. And they can break through. Many masters cyber students don't have a CS background and struggle in interviews. Degrees and certs are marketing tools.

