#general
1 messages ยท Page 244 of 1
hi i got muted
if you think so
Do people always crawl from rocks at this time?
Yes.
yeah im playing doom 2016 then playing eternal.. for the 3rd time
I swear every time I come onto the Discord at this time that's when the cavemen of socialising arrive
I seen before you messaged xD
If you think something is going to offend somebody, you could always keep it to yourself, that way you won't offend anyone. ๐
Very true but this chat been weird then lol
Is there a free one? Like except AWS, Azure?
can't offend anyone if you never say anything ๐ง
Not without limitations
Are limitations bearable?
GPG an PGP is very confusing, I mean I know each one and the difference but why do that
Depends on your use case, for me it wasn't, so I do everything on my host.
i want to upload a room to tryhackme. can anyone please guide me a bit?
https://infosecwriteups.com/how-to-make-our-own-ctf-challenge-with-ease-6b15f76865b5 i used this for reference.
i used an ubuntu server v24 and set up everything for the challenge and then converted it to ova (and later saw v20 is the max allowed).
I mean it's not for detonation so power shouldn't really matter unless it's so slow that it can't run a reverser tool
I know, I was talking about static analysis.
i have a mac m1 (and i made that server from my friend's pc). now i wont see him soon and i need to make the room asap. (tldr: compatibility issue arm vs amd)
can i prolly spawn an ec2 and do the work there and then upload that ec2 or something?
Hmm yep, host it is. I already got a lab setup in my host, just can't bring it to work
pweese anyone ๐ฅน
I'm surprised work isn't supplying you with an org laptop to do your job...
Right? Apparently they never had an intern
So they couldn't set up anything
Told me to use my own resources
๐
But can't byod

I just calculated, it's going to take 32 hours to post all 224k entries into a database
gah, this heat
it's wonderful innit
no
how hot is the UK jabs?
nearly 30C!!!
oh 81F, y'all must be melting
im dying
thats as hot as it is here in SoCal
its not that bad
Nice here.
I bet Scrubz gotta be somewhere in UK
I am, however it's not as warm as where Jabba is,
Amateurs
Couldn't be bothered to pick up my phone ๐คท
If it dispalys the same information, who cares? ๐
Are you using Microsoft?
Thats more like it
Lol
When i was living in Dubai we would get 40 in the summer and that was hard
is mindblowing how in countries like Egypt people live in 40 degree celsius weather
or 110 F
its amazing that the brits were so big on colonization, everywhere they went it was much hotter... maybe its what they truly craved
that s enough heat to cook yourself a good meal
it's 32 degrees here in monsoon...in the summers it goes to like 45-50 degrees celcius
Not all.
Only things I prefer hot is my baths and food.
how about tea?
everywhere they went there were gold/slaves/spices
I don't drink tea, at all.
true
not even black tea?
I drink tea.. although I like iced tea more than hot tea
None. ๐
mmm, nice hot tea, tasty cold brewed coffee
with a bit of milk
I haven't bought yorkshire tea in a bit, I should.
I barely find any in my country and need to bother relatives to send it from UK
its one of the brands we get in the US grocery stores, that, tetley and PG tips

nah I'm calm
just cut my program time down from 32 hours to 12 hours
I see why 64GB ram is so important
Guess who broke their laptop last night on a pentest
Tetley on top
What the hell where is your community legend role
Community legend role?
@mossy river reddit folks don't get one?
There ya go
Of course 
OH LOOK SHINY COLOUR

Thank you Jared
๐
You almost look as cool as me ๐
No, u old.
No u old
Reminded to take laptops off when climbing fences
F
It's an ever evolving platform
Minimalist.
AGAIN??
Yup
They always choose the worst uis
I liked the old one
New ui looks nice
I don't know why they're bouncing around so much
But for veteran discord users itโs a step back in ease of access
I agree with Jabba
This was because of a complaint that user profiles were too big
bruh...
So now you have to click to see the full profile instead of it always showing
ease of access >>>>>>>>> looking good
and since when did companies start taking complaints from 1 user seriously???
search is still bad. Discord pls fix.
It would have been > than 1.
hehe
I know, I was making a sarcastic joke
Yay us oldies are now gonna be confused
1.2k pts from godhood ๐ช
Yet, you were saying you should always wear sunscreen 
Not learning from your own advice lol
I hear horseradish sauce is helpful when you feel like this
I definitely should have put on sunscreen
Iโm like a piece of steak on the bbq
You some clone?
One has to make the mistakes to inform others
I have 4 Kali VMs for some reason...
Hi
I had a ctf where two jpg images were provided.
One called original and the other called edited
I converted them into a text file and ran diff to find the output of
7298d7297
< zged
However that only means between those two lines theres zged as a string but that kinda means nothing to me
Maybe im going at it the wrong way
well well... internet is down
rip
Hottest day this year here. 29C
Since when does The Netherlands look like this? lol
Or isnt that here?
it's not...
Ahhh
If you came to India, you're gonna have a hard time haha
hi , can i start learning reverse engineering while im still beginner , in coding ?
you can learn anything you wish and want ... at any time you wish
But it will take much time :)
also, no vindaloo ๐ข
i mean isn't re requires deep understanding of coding?
ouch, why no vindaloo ๐
as i say... anything at any time... you go with flow and learn what you missing and so, thing i can promise you, it will not come ower night... im sure that you know that ๐
Yes, of course it requires advanced knowledge of coding. RE isnt something easy...
make notes all the way. read around, follow things...
๐ท๐ธ
start small. make plan. do not overload you self. take brakes and rest...
alr , thank you !
Gave +1 Rep to @loud marlin (current: #27 - 310)
I didn't think you could get a vindaloo in india.
if you learn on working days, try take rest on weekends or so... also it help if you find mind alike ppl in own town. share ideas and so
i have a 11 month free . ill try to gain knowledge everyday .
that's nice. take like week of all pc stuff... refresh brain
indeed
hardware?
ha ?
like pc stuff?
all that include pc. is nice to take liek whole 7 days or so off all the things
ohh alr
it help brain to calm and when you back you have that push again. butrnout is shitty thing
yeah thats true going piece by piece is best and not everyone is same some take longer than others to understand the same thing
I've been on a burnout since 2022
frack... you are old ๐
no sunscreen since 2022? ouch
people who don't wanna end up looking like a steak on the bbq
have hobby that require doing complete opossite stuff is help to keep up. for example. cooking is great. also you can learn how to draw and/or painting. that way brain need thing of how to use hands in creatiwe way.
NHS advices you to use sunscreen whenever you are outside. You should opt for a lower factor when you're indoors
I wouldn't mind tasting like one thooo
Are you a kannibal?
thats very true, for me i use drone videography and thats been great together with learning computers
Tf did discord do with profiles
try learn how to draw with pencil or so. i was quite shocked of how it effected me. you need pay atention for real to make something on paper
as for example when you do some "hacking" lots of things are autotype with hands
Guys what do whe think of HP Wolf
I use it.
i used to before and became great at it but got busy, I think i should pick it back up
You fr?
if something gets past HP Wolf, it doesn't get past Malware-Bytes.
Tbh its a hell for MSPs
for me is great. don't do it often but when i need it help to get that "distraction" an get back
Wait guys "a hell" or "an hell"?
Mhh. Interesting. My English is not peak level you know xd
But, it's hell for MSPs
Because HP installs it on every Windows installation they distribute. Many people use the default installation of windows...
thats great, its my first time hearing about the opposite idea, it makes a lot of sense
๐
yeaaaaa .... listen
My sister once ordered what she thought was just a salad in Thailand, right
spicy salad
she gets it, then panics and looks at me like "are... are those things moving? tell me they're not moving"
they were moving
she didn't eat lunch that day
They were moving. - Birb's sister
whatewer you do with hands only in order to create new thing is is something that have affect in different way of what you do on daily thing it affectr brain in great way
my dad once went to vietnam when he was in the special forces for training exercises
idk jungle warfare or something...but when he was done with training him and his mates decided to get dinner outside...they were selling worms
in paper cups
to eat...
my dad and his buddies noped the f out of there 
ooo, klingon cuisine
Klingon cuisine 
that is very true and helps set your mind off things
i also did learn sign language. SLU
The crunch of bamboo shoots are good
i tried but i ended up disliking eating
for some reason, i read 3 times "the church of bamboo shoots" in a row
school exams are really boring
i waste my 2 hours there
Same even walking to the shops I am burned
I noticed that all the defcon ctf winners are huge groups. How is that fair for solo players
That's, in fact, how it works
I don't think you understand how difficult the defcon CTFs are
gotta specialise
I am finding it hard to uninstall Burp:
sudo apt purge --auto-remove .BurpSuite
[sudo] password for kali:
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
E: Unable to locate package .BurpSuite
E: Couldn't find any package by glob '.BurpSuite'
thanks.
I see
do you know what is the scariest plant in the forest? bam boo ๐ ๐
alternatively, eat human brains to increase your intelligence
100% works. totally legit
Enjoy trying to avoid Kuru.
Kuru incoming
pacman -S BrainPremium
How do they know
can someone help me please?
welp, the email about a redudancy meeting is definitely not concerning
Aw damn so you canโt fake it
time management?
Sorry, I have no idea. Why do you want to uninstall Burp in Kali if I may ask?
It is making me crazy
I want to reinstall it after that
books of gold?? ๐ฎ
What do you mean by crazy?
oh, beige
I don't mind tests, but I hate timed tests. I always I'm afraid of run out of time, and leave questions unanswered not because IDK those just because of the effing time
real
I had a test today and just didnt fill 5/33 questions because I didnt have enough time. I hate it.
I am trying to finish the UploadVulns room and I find it not consistent with its problems, sometimes it works in a certain situation and sometimes it doesn't.
also the whole VM crushes because of it.
my worst nightmare when it comes to tests
Mhh strange. Tbh I dont know how to uninstall. What you can do is installing another installation
Download from the burp site
I did an update
you think installing over it without uninstalling is ok?
YAY ueberzugpp has just updated to fix yesterdays software to new probelm
Yeah just install it in another path
I will try
Thanks
Gave +1 Rep to @icy epoch (current: #149 - 48)
hello
hi
is it allowed to ask about sub subscriptions here?
About subscriptions? Depends what you gonna ask lol
just how the annual subscription works
so what happens if I cancel the subscription after few months
It will continue until the end of the subscription
which will be a year from you signing up to it
There's your answer :)
ah I guess monthly subscription is for me
So if you cancel it 6 months in, it will continue for 6 months before it will expire and you'll be back to the free tier.
Should you want only a few months, a monthy subscription will be better for you
that should be right
No bella, what did you do?
try to take over the world?
thanks you two :)
Your welcome
I was training with a special unit in the home guard and we had to do mout!
+rep @silver sky
Gave +1 Rep to @silver sky (current: #47 - 161)
+rep @rapid merlin
Gave +1 Rep to @icy epoch (current: #145 - 49)
xd
Ooooh fun
It's so cold
You good?
Broke or broke broke?
Need +20C then I'll be happy
Yeeee, clearing 3 buildings, 1 of them dry and the 2 others with blanks
Damnn thats hella hot
57 won't hurt no-one
The one we did dry was team based in a 2 story building, which was fun, and the 2 with blanks was solo clearing
Im sure not. Im not going to collapse no no
If its ever gonna be 57C here im moving to Antartica
Booo
I fell on it climbing a fence and it's broken the screen
think everyone will be dead if its that hot
Nooo, you gonna (let someone) fix it?
I might just use it as an excuse to use the business profits to buy a new one
A win is a win
Safe to say I will now get military experience cause I will be joining that unit
what unit
totally-scrubz
Euros in 71min!
who's playing?
im cooked ๐ญ
that will be interesting
Nah, Netherlands and France are already trough
I just like netherlands and austria.
Italy-Croatia was a fun one to watch
Yeah me too
What players do you like? Frimpong? Simons?
Alaba?
don't know the players. Not that into football.
Fair fair
though germany scotland was a slap and a half and also I'm glad switzerland won against us.
Where are you from?
germany
I though they won :O
Nah they drawed
damn
92' goal Fullkrug
Any of you ever watch the Seattle Sounders? Just curious what your opinion of them is.
But watching your team play knowing they are already through, nothing is better
Nopee
tell them to get a ssd
Was about to say lol
HDD is slow... Duhhh
But I'm scared the rules dont allow helping with work questions...
yea germany do be strong but sometimes a bit goofy.
They are really strong. Especially the midfield. Kroos dropping to defence for the buildup etc
Beautiful team. How's the atmosphere in Germany?
that is a double sided question. It's either close to heat death or a bit of pride for waving the flag.
Hi!
greetings
Fair fair, have you been to a match already?
nope. I don't like big gatherings. Gives me the bad goosebumps.
Defrag just moves stuff around (fragmented files) so that they're less fragmented. I'd NOT defrag if it is a SSD as it can really mess things up. HDD is okay. May help.. may...
You dont like the orange army? xd
nightmare that :o
Gave +1 Rep to @normal fable (current: #54 - 135)
How y'all doing?
Fine. Hbu?
Good, how're you doing?
horrible
Morning Matt.
bored to the bone.
Why horrible @crude stump ?
cant get ovpn to connect
regenerate and re-download?
in a minute im bouta do that
Did you use sudo? :p
yeah
Little tired, Let my AV ran over night... excluded the ISO's and VM's that would be problem childs..... AV still reported on em, breh
Have you attempted methodically depleting the flow of electrons then re-enabling the flow of electrons?
Oh noo
genius
hold on a minute
WAIT. Ovpn for THM, or something else?
yes thm
MC Hammer won't help because you in fact can touch this
maybe enjoying some series' or just laying down idk
Do you by any chance have a backup of your ovpn profile? New ones I downloaded hated me, but my original from my, now broken, Kali. worked.
keeps cat litter in car
no sadly. My orginal(the problematic one) is my first i downloaded
i worked on friday
Absolutely as you should. I need to do that as well.. but I've never been stuck in my car.. yet...
had vacation and now its dookie
Are you trying to get that one to work, or trying to download a new one?
trying to get that one to work
i might just regenerate one
nah but overall my days good
@boreal scarab Boxes ๐
Same here, and I usually only carry that in the winter, but jumper cables, I go everywhere with em. Not once do I leave jumper cables at home.
Have I ever needed em? Nope.
I keep one of these in my car for entry purposes
Wtf are you doing with a halligen?
I have jumper cables, tire pressure gauge, OBDII code reader, water, a blanket, full size spare and tools.
Raids
Oh that's right, forgot you're Fish and Wildlife officer
(US Equivilent, all I know)
It's actually for my other job
bondsman?
We don't have them in the UK
Oooh, what kind of raids are we talking about ๐
shadow legends
The one thing from DEF CON that really stuck with me was the Physical Bypass Village tool they showed off:
Wanted individuals, drugs etc
Oooh, I see ๐
wait are villages like showoffs of different tools and such
interesting
That tool is mainly meant for glass doors, but if you can get it through the door, you can use it. Very tricky though
Police do the arrests, we do the entry as we don't need a warrant
then we invite them in so no need for a warrant
makes sense 
Yes, normally coffee or tea tbf
Sorta????
For that village it was. But for Blue Team VIllage, I'll let @edgy ferry answer that one
"so how was your criminal life"
Oh no, not with the criminals, with the police yes
ooooh
what job is b&e irl
ah
hi !
i should really watch a video on past defcons
villages are community ran and we pretty much showcase a lot of cool shit ๐ค
When I come knocking you better open
we also run contests / ctfs in person
interactive too?
Aren't security officers supposed to keep people out instead of breaking in?
where you can follow along learning something new
thats sick
last year we had intro to detection engineering stuff
Depends, in my job it's more a blurred line between security and law enforcement
Security force for the air home guard, a reaction unit that helps the air forces
how beginner friendly is it. i asked that question here too but i would love to hear other people
The chairforce
water bottle lid...
do you help them when they run out of donuts?
inticrate
its a mix of everything, as a beginner you can do 90% of the stuff with ease :)
including the ctf
support is always there, just walk up and ask away!
thats awsome. thanks for answering
We help them when they have to emergency land or if an airbase has been lost, etc.
We clear the area for them to land safely
Fair enough
but if you keep it in your car, you can
can't use it if you lose your keys...
Thank god I don't lose my keys xD
Gave +1 Rep to @wintry sluice (current: #155 - 47)
So not chairforce, also we are all volunteers, but we get full training and need to be active and keep training to stay on the same level as the actual military
I was only messing โค๏ธ and fair enough, good luck to you
Thank you, and I know, at least we aren't seapickles or sock people
Gave +1 Rep to @silver sky (current: #46 - 162)
Wait, Danish Airforce is also called Chairforce?
I thought that was a US name 
I just stick to eating crayons
Now Marine's are brought in?!
Narh, just wide messing
I mean, we have the frog guys
How many times do I have to tell you.. CRAYONS ARE NOT FOOD! 
They are snacks
But candy
๐
frogmen are awsome
Chainmail in modern combat is so strange
except for maybe in east london
thats a net
It's not chainmail
It's water net
nook from rainbow six sige
US, We got Navy Seals and Delta Force
New invention idea.. flavored crayons. lol
Marines will be all over that!
green berrets, rangers etc
we got so many special forces units its crazy
I know but the joke wouldn't work with water nets
Oh we got TONS of special forces
That was my target... lol
Yeah, special.... Forces
I like the strawberry flavour the best
jkjkjk.. in case any Marines are here. We โค๏ธ you too.
Wide, just be happy I ain't coast guard lmao
You were in the military before voluteering?
Wide, I'm still getting used to seeing you in blue..
Nope, only military training I've had is from my parents
Aren't you also Canadian?
My dad was in Afghan back in 01
Danish
https://en.wikipedia.org/wiki/United_States_special_operations_forces
"How many Special Forces you want?"
US:
United States special operations forces (SOF) are the active and reserve component forces of the United States Army, Marine Corps, Navy and Air Force within the US military, as designated by the Secretary of Defense and specifically organized, trained, and equipped to conduct and support special operations. All active and reserve special operati...
Nice. A generation-gift ๐ค
They just call every unit that goes outside of their bases special op
We're talking about special forces ๐
I was in afghan in 2019 ๐
What area?
Yeah
Can't remember what area my dad was in, he was luckily only on base down there
Communication specialist
2 years before I was born
Probably bastion
Yeah
The danish used Bastion quite a bit
Welp, time to wait for a recruiter to call
Here 2009 ๐ค
โค๏ธ
One of the craziest part of my life.
Special Forces != Special Operations Forces, just FYI
Thats crazy when i look back 
Mid 20s is great until u reach 30... its better ๐
Did you saw the new vid of David Bombal?
Started 4 years ago
U will if u work for it. And as far as i know you do.
Then u r a crack when i am advanced ๐
Playing for Kalmarunionen, the best CTF team in the world ๐
Contracting in Iraq was crazier than Afghan I'll be honest
Thank you, got called the best forensics person under 21 last year in Denmark
Gave +1 Rep to @shut raven (current: #498 - 9)
Just by studying thm, htb and other small CTFs every weekend
And then of course certificates whenever that was needed due to job
Not really, but we just started something up locally
Thankfully i was not involved in iraq. I had the call of duty just in 2009 and joined the dudes in 2005.
My first job was IT-support too, and now I do SOC engineering
Oh fun, Iraq in 2018 was a boiling pot
I wrote a company yesterday for a support job ๐ . Maby it works but idts. It would be my 28 rejection ๐ฅณ
Shoot for 42!
๐
Oh tought you mean in 2003. Operations abroad are no fun. Honestly, i was happy as my time was over.
Omg vain isnโt green anymore
Oh I was only a child in 2003.
I was 5 back then
But i'll never forget it and the dudes i had the honor to serve with still unforgotten.
I grew up on watching the iraq and afghan war on the telly 
Can anyone help me out with error in #subs-room-help
At this time me too but a little older ^^
Which unit?
Looking for someone to go through ctfs with? Add me and DM
I forced him to do rooms, and now Vain and I are doing nothing but rooms and boxes day in and day out
I was a private contractor with Olive Group and Constellis
I thought that said:
"I was a private contractor with Olive Garden"
I would see what you like whenever you get there, a lot of things change when you finally get into it
LET'S DO ROOMS!!
COFFFFEEEEEEEEEEE
My train is like 40 minutes late
Probably faster walking than waiting
Get to stepping!
It'll take 3 hours to walk if not more
And we just started driving again
Ah okay nice. Had to googel it. More the infrastructure path?
Mostly armed guarding and convoy security
Most employees of privat companys had often a lack of ammo and support. Never envied them.
Olive Group was okay for that, Constellis was a bit of a shit show in regards to that.
@boreal scarab reset the DNS counter
Late to the party here but it'll be 4 sticks running in dual channel.
Channels != sticks or slots
@silver sky wb Hex
Hello ninja! how's things?
Pretty good, certified infrastructure team leader with the CHECK scheme now
Been fixing lots of stuff hardware wise. Keeping busy.
Ooooh very fancy, I've found out today I might be being laid off
So taking a look for other jobs right now
We're hiring pentesters from trainee to senior really, but in office
Unfortunately too far to travel for me

When I'm getting my paycheck I'm buying premium so I can continue learning my beloved penguin
Penguin? Maybe THM needs a mascot
Linux lol
that is elf mcskidy
That's AOC exclusive
Whaaat if i suggest u to set up an office here? My home? No?
^^
Just EP gainz ๐ช
Yeah it's me ๐
But penguins wear suits no neckties.
I can wear a bow
Now we are talkin' ๐
Hacking Hippo
Damn that's actually a good account name lol
sup
What do I get with premium More juicy stuff
Open one in Scotland
Should I buy flipper zero ?

I don't know, will you use it, or leave it it a drawer?
Thanks
That's realistically why I'm not buying one.
I have one, all I use it for is to turn on my TV monitor as i lost my remote, that's it now
You need no office. U guys have the real mckenzies already! 
CCG Reaper used it to troll DEF CON 31 and rick rolled the WiFi
Damn
Over price remote tivi
Well
Rick roll sound fun
Doing it on the school television will get me detention level 2
Pretty bad
Would be funnier if I do this on ceremony
Yeah let's not talk about playing with equipment we don't own or have permission to mess with
are there any games for beginners on tryhackme?
loads
for example?
u can filter ur search for beginner/easy rooms
yesterday I tried playing the rick and morty game and I also tried playing agent sudo but I almost couldnt do anything
thank you
Gave +1 Rep to @silver sky (current: #46 - 163)
Those are ctfs
Well Iโm the Rick and Morty is
this is a good one to start with
blue my beloved
โค๏ธ
I cant do even this
I dont know what to do at this point
Practice more then
Then practice using the teaching rooms
@sick lance will be interested, or perhaps @delicate coyote (sorry wrong james)
To be able to do these, they require prior hacking knowledge
and how do I gain this knowledge
By using the website? we have teaching/walkthrough rooms
@sage rune Please don't advetise your services ๐
There are many windows hacking rooms that help
theres so much and Im new to this so I cant even find anything youre talking about
Itโs cool. I was trying to find out what Iโd be interested in lol
I'm sorry dude 
I wasn't very interesting
Has anyone finished the offensive pentesting pathway?
is there any possible test environment for infected files?
in addition to creating a virtual machine
Well you can set up one but you have to really isolate it so it doesnโt infect your main os
hmm
don't
what kind of attack is it called if I create a bad program with the same name as the normal "good" program?
trojan
so it's just a basic trojan? I thought there was a special name for it
Well a Trojan is the broad term for it
It's really not?
It's a trojan, something pretending to be something else.
But like there are different Trojans that to different stuff
here's more depth; as a school assignment I created 2 programs with the same md5 hash, different sha256 hashes. Their "payload" is quite literally a text line. I'm working on some resume repository stuff so I wanna make sure I use the most technical language possible to explain everything I've done.
No
Trojans pretend to be something it's not
that is the definition of a trojan
A Trojan Horse is a type of malware that downloads onto a computer disguised as a legitimate program. The delivery method typically sees an attacker use social engineering to hide malicious code within legitimate software to try and gain users' system access with their software.
so I just wanted to make sure trojan is the best way to describe it "technically." I'm not always great at technical language :/
Best way, linux host, windows VM
but leave it to the professionals
Yeah that is true. Iโm just saying thereโs different types of Trojans like back doors etc.
A backdoor is technically not a trojan
Is a reverse shell classified as a back door?
no
well a backdoor can be a trojan if it's disguised as something else
I think I donโt understand what back doors are
Think about a castle: A backdoor is someone inside the castle letting you in
backdoor is something u install in a system after you compromise it so u can access it whenever u want . am i true ?
nop... it's a rev shell. backdor is there to make sure that you can access system if main access fail. it is more on to that but in short
it would be like Apple making it so if you input the special password "ilovefeds" you can get into all phones.
time to figure out if I have some steel wire laying around
I see what you mean. So letโs say I installed a program that sends some sort of connection back to my host every 5mins and if I catch that connection I have shell access. Would that be a back door?
yes
Ah ok I get it
wait
when you say install
do you mean "install" as a hacker or "install" as a developer
Either?
if you mean hacker then no; it's not a backdoor.
More as a hacker
Ah
Backdoor is an insider threat
No?
Wut
No it's not
back door is more complicated way of getting on system. rev shell is simple command to call back host/attacker. Backdoors are obfuscated and hard to detect. and they are, in most case, not detected in AV. rev shell can be easy spoted
An insider threat is somebody who leaks information from inside the org.
backdoors are deliberately placed in programs, no?
That's, uh, one definition? Certainly not the standard one 
not what I meant.
A program, or any other system
Backdoors typically will be installed with other malware to make sure the attacker can access the machine even if the inital payload is detected later.
Backdoors are deliberated placed in programs as an alternate way of getting around a security measure
oh Wide, you like bikes?
Ah, glad we agree it's not an insider threat then. ๐
Summer sucks
It's anything which provides access (to one degree or another), using a method unapproved or unknown by the owner of a system
okay my misunderstanding; I thought for it to be considered a backdoor it had to be installed by an insider.
I would you even go about hiding a back door from a AV?
what type of AV
yes.
I mean a insider threat could put a backdoor into a system
it is not detected in AV
he was asking how you'd go about doing that
But I donโt think thatโs what heap means
and is hard to spot in forst palce. you need to know what you look for
isn't a backdoor make sure that let you access to a system after compromising it ?
oof I'm going to type out everything I meant and why I was wrong gimmie a second

I donโt really know the different kinds so Iโm not sure
Same way you'd hide anything else from AV... Reduce the suspiciousness
nothingtoseehere.exe
best naming method
Looks innocent-antivirus
A backdoor is an alternative way of getting around a security measure: think like a rope at the back of a castle wall. You don't have to try and get in the front door, you just climb up the rope. My wrong assumption was that this implied it had to be setup by an insider, but it does NOT.
Have not learned anything about hiding programs from a AV so that must be why Iโm confused about that
I mean, it doesn't technically need to be a bypass to a deliberate security control either.
"Due to how poor this polish virus is please delete one of your own important files"
oh it doesn't? interesting. Is it just a way for infil/exfiltration?
Research research research
Make it slow like a turtle or fast as light.
You should go learn about what types of AV programs there are. Signature based is one, go find out the others.
ok... today ill rm .ssh folder
Yup thatโs what cyber is all about
Unless we expand the definition to include things like NAT and inbound firewalls -- which technically are actually security controls, but not ones we'd really think of in this kind of context.
I thought this was about bullying kids on fortnite and actually being able to hack their account?
lol I didnโt know that was a way
isn't the that a definition of a zero day vulnerability?
no
lol nah butโฆ ๐
It's a poor AV that only uses signature based checks...
A vulnerability the developer doesnโt know about
but it's where he should start IMO
You don't categorise AV by the detection techniques they use
That's not a "type" of AV. They all use signature checking and heuristic checking, amongst others.
brb I obviously need more caffiene since I'm not being careful with my words.
At that point we're talking about the features built into an AV engine, but they're still fundamentally the same category of software
It's the time from discover to time to react if im not wrong.
ngl, MRE's are really nice when you're home late
If there are zero days. Happy day for some Hackeez
Close. It's a vulnerability which has not been disclosed. e.g., if an issue has been exploited in the wild, you would say that it was a zero day exploited by x,y,z up until the point of disclosure.
Thereafter it becomes an n-day vulnerability
Listen to the song " i want my money back" ๐
Apts love em
just confused , a backdoor is like a misconfiguration or is something installed in a sys after being compromised ?

Installed after.
It's a concept to describe setting up "backdoor" access, usually into a system you don't own or control.
For example, sticking a key into a user's SSH authorised keys file would technically count as a backdoor, even without installing anything, or altering any programs
I hope you'll are taking notes.
I'll do that while working on my bike in a bit ๐
Uhhhhโฆ
going to be working with fiberglass 
remember to wear protection peeps
fiberglass is a mess
asking someone that has finished all paths in tryhackme:
how long did it take you?
Debatable. I'd just call that command and control personally, potentially mixed in with persistence techniques if you've built in ways to recover lost agents.
Backdoor would be more like adding something which allows you to connect into the compromised instance.
That said, at this point it's all just semantics. The end result is the same.
no one did that bc there is always new rooms
Eh? Of course it's been done lmao
Would it be accepted despite the encryption?
Whether it stays done is another matter...
Great, didnโt know thm had a AV evasion room
Yeah
even new rooms ????
Pardon?
you'll ๐คจ
You all
Plenty of folk done everything on the site
Ryan used to keep up. Not sure if he still does
Canโt imagine having it all done
im just making my feel better
ignore me
If i am right u said u have to put a key in the (private?) - key ...?
Phone auto correct, ๐
No, you'd stick a public key associated with a private key under your control into their authorized keys file
There are several ssh key. How do the process work? That's what im not understand.
Or preferably just run off with their private key 
Not, admittedly, that you're likely to manage that irl
Eh, then again. Best practices are frequently broken
Racoon, what's your favorite MRE?
None, they all taste like ๐ฉ
This one actually tastes pretty alright
Chicken with sweet & sour and pasta
Unfortunately Iโm going to be eating those a lot
in your job experience , you stimulate apts Campaign ?
Simulate?
yes
Think they mean use there tactics
Yes, I have been involved in adversary emulation campaigns.
Ah okay. Think i can follow. Even tho dont yet understand the whole process. But sounds interesting ๐ค
one of my friends "ransomwared" his first company on a red team assessment, not long ago, he rewrote some of the lockbit code and called it lockbyte 
must be fun , have you succeed ? 
Define "succeed"
Remember you want to be caught in those engagements. You try your hardest to avoid being caught, but "losing" is what you're hoping for
Whats this. We discovered today that im a boomer ๐
did you find any valid attack vectors that can be critical for the organization you have been hired in ?
Military Ready-to-Eat meals
field rations as they are also called
Meal Ready to Eat
oh
Not sure I can answer that one, legally speaking lmao
okay .. i just find that interesting
and fun job
you can... we will tell no one... also share your ssh keys โค๏ธ
Hiya
where is the risk if he shares when u don't know anything about him?

Hardcookies also called "tank plates" ๐
and much more of things
lmao, nice
U could break it down to "u can't poop for 4 days cookies"
It's not like you see in the movies. There's a lot more stress to it than you'd expect.
yeah, we have that too
It's not like you just get to run around a target network without restriction. The scope is wider than that of a pentest, but it does still apply.
I mean sometimes you do
Great invention ๐ . And if u buy them today u can eat them in 10 years ๐คฃ
Not common thouhh
yuuuuuup 
oh well, I need to go get some steel wire, cya later
ups... i "forget" to turn off my wifi-pineapple
Don't forget the song!
people who work within the organization can be tested if they are vulnerable to social engineering attacks ? 
ofc. no one is immune to any kind of test/attacks
Sometimws
Depends on scope. Always depends on scope.
there is something i don't get , i think the goal of red teaming is to protect the organization from external threat actors attack , why the hell they make scops for the test while they knows everything about who they hired . ? isn't the organization should be tested for all things so no chances for threat actors to compromise the organization?
Scope is about time, practicality, risk to business critical systems, budget
There's lots of factors
You cannot possibly hope to exhaustively test every facet of a large organisation even with 20 people in a month
Ah. Now im on the way. U have to gain access or already infiltrate the target system. So u could leave the key there. Thats great. But how would an attacker camouflage it? Every known user has a already a key. The soc would detect it right?
Red teaming and pentesting are different right?
Yes, but it can get confusing
"the red team" is often a short hand for offensive security
Ah ok
scope is important when critical systems are being use, a story for you:
be new at pertest
pertest eye clinic systems
one of the IPs was connected to a remote laser surgery system
someone was being treated during pentest
luckyly noone got hurt
stay within your scope and ask alot of questions, it will keep you from having to hire a lawyer.
Both hack systems without getting a jail sentece
One sounds fancy - one doesnt
the best way to defense is to attack

not always
what is a security framework for 100$ please.
you still go to jail
police pentesting lol
the would definitely benefit from it. I bet some of your local police servers are really easy to [//redacted//]
lol
Oh i have nice general question.
When and why u get in touch with cyber-security and what was the main reason?
to change your pasword cuz you forgot lel
astral, did you see that Fluff is back?
he a mod again?
lol no, he came yesterday and now he is running both noob and legend badges lol, I dont think he is modding tho
Fluff does not have a noob badge.
why not?
Fluff too advanced for noob.
idk maybe SMTP or SSH gotta ask fluff himself
just had a question, i have virgin media at my house and in their app you can create another network for Guests, This would be subnetting right?
Nah that's a wholly seperate network not a subdivision of yours
no guest network and subnet are diferent
it depends on the scope of the guest network aswell, some guest networks provided by a regularr router may or may not us vlan internally aswell
Even thought it would use the same resources and run off the same router?
Ohhhhhh now it makes sense, My brain is not working rn
dapends on the router configuration, if they are running it through vlan. if you want to check, look at the IPs, they shoudl be nearly identical exept for the routing prefix
as in subnetted IP should be the same as the main network except for the routing prefix.
Alr this makes sense, Thanks for the help
Gave +1 Rep to @sage schooner (current: #1401 - 2)
Thanks for the quick response
๐
hi
If i cant understand something, is it best to stick to it or move on further?
Look for external materials
Try working for a bank 
Bunch of possible ways, not least because Linux systems have historically been notoriously poorly monitored. But yes, it's not something you would usually do on a red team
I agree with Scrubz. Other ressources, other explanations
Muiri! You coming to DEFCON? Can't remember if I asked
Alr imma check out some other sources then, Thanks @sick lance and @barren lantern
Gave +1 Rep to @barren lantern (current: #2112 - 1)
@mossy river you following along?
depends on the org, but mostly on the application - and even with ti's shortcomings, syslog and journald have both been waaaaaaay better than the default windows events system

on the vid of intro to lan it says this
while on the website it says 4 bytes(32 bits)
which is correct?
4 bytes
is 8 bytes outdated?
oh alr
well it depends
8 bits = 1 byte
hello
if the police do not announce themselves in a raid on your home, and you shoot one out of reaction you will be found innocent
this has been set as precedent although varies from case to case
i thought police had protection during a no knock?
again it depends
if executing a no knock warrant that is
It's all contextual, and this kind of thing gets very political very quickly.
oh i see what you're saying
although that usually never happense
I would ask that the conversation move on to another topic before it gets to a point where one of us has to stop it
and is best to always comply
fbi open up!!
fair enough
thank you
Euro is a mess right now
the value of the euro?
both games in group C is just 0-0
Football
My mouses main buttons are ain't working so am using the side buttons as a replacement
Any ideas for a new mouse
have you tried turning it off and on?
yes
I like my logitech G203
i use the corsair ironclaw and i really like it
it's wired though
the corsair is too