#general
1 messages ยท Page 248 of 1
Im also younger than fluff/Hydra.
30, indeed. 31 soon
Ah, he's a Leo.
im 24 am i still young ?
I'm a lot younger than that
me
Scrubz ^^^
I can't beleive that people of this age is running THM from behind...
naah
I've done all the unethical stuff, so you don't have to ๐
ooh
Right. Okay. 33
32
I know it's between 30 and 35
I'm going away for a couple of weeks in a a month or so and due to space and weight ill just be taking a chromebook with me, I should be able to keep up my THM streak with just the attack box yeah? have only ever used the VPN on my VMs
Hydra is only 35?
Don't even need that technically
you'll be alright mate
Hydra is older
dunno if a chromebook can even run chrome these days though
Old but gold. Period
So are you saying you're not younger than 35?
I'm saying I'm inside that age range.
Okay, so, 32 it is then
Come to India you will thank god that your apartment is still not that hot
Gave +1 Rep to @chilly veldt (current: #7 - 848)
I'm not that old.
I am the oldest i guess.
Old enough to have, what, 2 kids? ๐ด
Can you share your notes?
Do you take notes of your own?
I do
my sister was that "age" when she was 19 
But I still I don't have that much yet
Some people have kids early
Just started if you could share that would help me understand better how to take notes and all
Nah I'm older
Christ. Well that's sobering
Some people are reckless as well it seems
With the greatest respect: lunatics ๐
Sure
Kids are a blessing. ๐
They're very important. Without notes, everytime i would boot from zero ^^
Everyone is different with this. Personally I like a hierarchical style of layout. Do what works for you. Experiment with different styles until you find something you liked then stick with it.
You should aim to never need to solve the same problem twice.
understood, Would take note of this as well
Note down anything you think will come in handy down the line. Everything you learn. Every new topic, links to tools, concepts, things you've heard but don't understand yet.
As long as you keep organised, you'll be a lot stronger for it overall
hierarchical gang
I keep my notes in a program called "Obsidian" and just create a new file for each tool, concept or topic that I come across that im learning.
Name
Quick description of what it is, what its used for and why.
Syntax
Example of how its used
Obsidian is great... Until you start developing malware, or doing anything else that Windows classes as malicious
Hey
Then storing your notes in plaintext becomes a bit of an issue 
Best one for me.
honestly didnt even think about the malware aspect and WIndows kicking up a fuss about it haha, Thank you for that early warning. Definitely something I will keep an eye on
Gave +1 Rep to @pallid lotus (current: #9 - 772)
Yes, I also started using it from yesterday
I like Trilium personally. Does most things that Obsidian can do. Doesn't store notes in plaintext on the disk. Built in sync, etc. It's a neat bit of software
Making stuff organized and searchable is very important in the notes too. Don't know how many times i looked for stuff by faint terms. The stuff i thought I'll never forget
Obsidian works great and you'll see the connection between some things if you take the time to link it
But, again, do whatever works for you
I'll check out Trilium (:
What to use in that case?
Trilium gang!
Does @shell nova have children?
Trilium gang!
Yeah
Oh OSWE friends.
That
I like Trilium. As does Fluff 
Realistically, whatever you want though. I know people who use OneNote / Evernote. I know some who use Joplin. Trilium is awesome.
I'd suggest not using CherryTree for anything big, but it's great for projects as well.
Thing @tired peak had another one she liked too?
Obsidian is nice, but defender gets mad at exploit code
I use OneNote for my uni stuff
I saw people be ultra efficient in onenote, so i don't discard anything
Just ask both Spooky and Cry 
Half of spooky's notes disappeared the morning he sat OSEP lmfao
Notion is nice
Is OneNote free, or is it tied into the Microsoft suite sub?
I have it free through my uni but dont want to get too comfortable if I decide to not pay for it myself after study is over
Only downside is you need an initial internet connection
Oh yeah, knew I forgot one. Notion is sleek. Potential issues with not having full control over the hosting, but it's sleek
I tbink you get so much free.
Windows+. ?
I've tried notion for programming but it was a mess. But everyone has to check what works. Maybe it was my bad but if notion gets down your notes as well.
Maybe it's allocated to how much you get cloud storage free with an Outlook account (5GB Maybe?)
They also seem to randomly like deleting infosec related stuff
yeah looks like it, after a little digging found that you can only save to the cloud not locally unless you pay
I've recently switched from a hierarchy structure to a flat structure for my notes, surprisingly works quite well
Their edr may fuck you
Some my Notion notes went missing, I'm guessing they didn't like my malware notes
I think it was fixed.
Meggy was storing jndi payloads. 403
Definitely emphasis on backlinks and tags
When was this?
Way back in September.
Zettelkasten style?
Fluff! Hai
I only recently checked.
Yep!
They certainly destroyed Mega's stuff when he was taking log4shell notes lmao
Could be but im not sure. I've used it for just two weeks. No cloud sync or anything like that.
Hey @jagged moon how long does it took you to crack all those exams?
One of the big reasons I like self hosted notes
Is it called like that?? ๐๐
See, I like a mixture. Why have one when you can have both?
Do a tree, with backlinks and clones
I asked and their notes just got temporarily blocked, never destroyed
Fair
I am slow due to busy full time job. So one a year. But it's not needed
But I do understand your point of self hosting
Reminds me, I need to look into clustering
That definitely works, problem with doing it on notion is that it's only one parent so can be difficult to workout what goes under which

True
Lmfao
You can do most actions with keyboard shortcuts, become a power user!
I am a lazy mouse user ๐
wait until you hear about Ctrl + c & Ctrl + v! ๐
Would recommend it. You will be lightning fast
But i just started at vs code with shortcuts 3years ago so im not in the position to say something ^^
Generally that's to make it clear that they're copying and pasting. Keyboard shortcuts don't show up well on screen.
You do get software which displays your keypresses, but most folks don't seem to use it
Thats for demostration purpose I guess so that the person watching would know what he copied
Edit: I didn't see the muiri response...
Heh
I saw a cool overlay that did toast notifications
Like "copied: ssh root@host"
Like on the phone
Gonna be hell of a ride
Notion
I worked at one as i worked for harley. Was fun but i enjoy my to wheels.
Really, I could have sworn you have a lightweight local one at some point. Apologies!
joplin for a while
but I switched to Notion after that
Helloo how is everyone?
Nah, wasn't Joplin. Something paid for, but iirc a one off payment
OH, I almost forgot about that
Good
Typora (I did forget)
Typora is good and lightweight. I can tell you that I don't take a lot of notes these days ๐คฃ
Typora is a lovely text editor
I use leafpad lol
And notion for everything else
India vs England match is gonna start in 2 hours. Its gonna be so fun. Can't wait.
Aint no way i actually went to admin.tryhackme.com.
Good Wbu
You got rickrolled?

thought i was gonna get admin access
Thats Understandable, get a good nights sleep
Had a few early mornings
not anymore?
Niiiice
Fun fact. That actually is where the admin portal is. You just need to find it.
Just remember though, no automated scanning of out-of-scope targets. You'll need to manually try a few endpoints ๐
@rapid merlin what was the payment for you in ur country for A+
253 for 1101 and 1102?
Ah thanx. Was on the comptia hp.
I'll do some warm up questions 
hi!
did you pass it?
wow, congrats. what did you use to prepare for it?
I wonder if it aleviates the career as much as CompTIA says it does ๐
And it's one of the certs needed to complete the Security Technician path, if I'm not mistaken
I need some help
With what?
So I used little big mouse
and it turned off my second display
it said its not active
and I don't know how to connect it again
Do you have a 4K monitor and an HD one?
The HDMI is in, power, everything is correct but in settings it says my display isn't active
Where do I check?
but I believe so yes.
good luck! I hope you earn the certs in no time
You don't know the devices you purchased?
Yep, where do I check the input source?
let me check
did you try... rebooting?
I'm going for aws certified cloud practitioner atm
Neither are 4K
Most people I know who use LBM has 4k and an HD.
Can windows detect them?
Did you do what Zojja suggested an rebooted?
how'd you fix it? was it a reboot? ๐คฃ
I read an article the other day talking about people how don't really know what rebooting is because things have been called Restart for a while
Nah, I installed the newest windows since I read some stuff online, so I just installed the newest windows
what
like version
in 2 minutes you installed the latest windows?
Afaik, they mean to separate things though. Even though they have somewhat merged recently
it's called restart from ages of dinosaurs, as i remember...reboot is also new for me...
That was the fastest instalation/update to the newest Windows ever...
wait
on unix, it is still reboot
software update I mean
did the software update include... a reboot?
Ah you buy just one of them.
reboot
fair yes. restart i remember was when i had win 95 and so
I think A+ should be fine without a second retake
My first attempt was 5 points less than the passing score, so I decided to buy an app with 680+ practice questions. Actually, there are apps like this one that are even free, so it is also a good way to practice anywhere you want
I saw both with a little self study guide and retake for 630 bugs. Its a word hey... Idk.


Its not free
Wtf????? Its a youtube redirect

you've been rickrolled, baby
Yt hacking try. See you in court.
lol
Not all the commands got transferred over. ๐ฆ
I can't get my GPU to get my displays.
And it's annoying.
whats a good one with stylus?, on android tab which i can sync on phone
No idea, sorry
Yeah, Samsung, Nokia, Blackberry, iPhone
You know, you'd get an answer so much faster if you just ask the question.
Two phones I don't know.
I'm about to upgrade and unsure if I should get the pixel 8 Pro or S24
Prob the pixel.
Macroglossum stellatarum
why cant this be something like "ye/no" lol
Bless you.
hehe ๐ ๐คญ
Am enjoying the music on loop 
I mean, they're pretty much the same thing
ikik trivial af but just saying
never heard "nay"
s24 with no question
Compare both specification,
Software update frequency
Year of os update and security patch
After sale service
Most important UI exprience
There doesn't seem to be a channel for this room but it was a good one!
Reading write-ups afterwards (I just loaded a script and waited when the bruteforce-protection wanted me to ๐คทโโ๏ธ ), I noticed that my foothold was different from the other users' ๐ช (not sure if that was intended?)
p50 pro is better
apollo is stuck on android 12
EMUI 12 is android 13 i think
its identical
i prefer EMUI slightly slightly
For me I would go with Xiami
xiaomi*
Room channels get archived a bit after they're released
why
Because there is plenty of custom rom available for them
Eh, I've had a Samsung since they released S4, i might be time for a change.
Not sure about huawei
but
oh shiz 
i dont wanna custom rom
i cant on the p50 pro
cuz of warranty and stuff
im on a custom rom rn
Yeah, then go with pixel but you will surely miss the s24 touch
The archived channel for Hijack can be found [here](#release-help-archives message)
Its just another level
Even after installing custom rom you can actually claim warranty
not really
If you reupload the official rom
on xiaomi you can
if you use mi unlock
idk man
what would u pick for daily driving
the p50 pro is so sexy imo
and has better specs
(NO SIDELOADING PLEASE.)
Well as I said earlier I don't have much idea of huawei phones as they are hardly availaibe in India
i just now realised kali has a root terminal
Seriously????
yeah
Outcast is one of the best ppls I know.
Bruhhhh
well
huawei phones have GSpace
and its basically google apps all in one
i think only some are web apps
and they have appgallery where u can get more important apps via .apk
and they get it from their own sources
ok ok i get it 
Since the bike passed inspection, it's now fully in my name and owned by me, time for customizing 
Nice! Congrats!
i dont really understand on nmap is used in a pentesting way. As im doing the nmap room it asks for me to used a ftp anon script. i do it and it works but how would that help me?
Anon access to ftp can be a vulnerability. Espcecially if it contains sensitive data.
could lead to further compromise.
note that I said "can" and not "is"..
and im guessing would nmap also help setting up a reverse shell?
sense you find open ports?
THM attackbox cannot open
It's a tool I use just to find open ports. Can enumerate services and there are scripts (nse scripts) that you can run to find further iofo on the running services.
i see
Wooo, share images after customization
probably after some months, but sure
Nmap is useful
i got your word now scrubz
Would wait for it 
I can't drive bikes
After the last accident, I am no allowed to drive anymore
So I am happy for those who are enjoying 
how much are they selling the p50 pro for?
I haven't been on a bike since my accident. It's been almost a year. I think it's about time I get back on..
I am enjoying it, and I will be driving my friends on trips, and next year the plan is to do confirmation driving for peeps
are you in the us?
uk tho right
nope
Uk
then dont get both of them either get the s23 or the s24 ultra cause for us in uk they have a shitter chip
I just searched its a 2021 model?
Hi all
On the contrary i have the S22 Ultra and mu partner has the S23 Ultra and they're both good phones.
for me it says 1149 pounds, for that its too expensive
Why not go with Iphone then?
then its not worth to upgarde
thats what im thinking or samsung
@naive violet can I DM? Got a radio question
Samsung I would suggest over IPhone
Same
Damn good display and camera with same level of processing power
the iphone 16 leaks say the iphone will look worse lol
for me it does look like a s23 now
Nu uh
Samsung on top
I never had an Iphone, so I don't give a shit whatever they are doing
iphone has no creativity its honestly depressing
i have a 12 and prob gonna get a samung soon
how can I get a role
Yeah get one
You need to verify
you will need to verify
thx
minimalism that costs a thousand bucks
minimalism by changing a camera and keeping the same design
slap a 1000 price tag on it
the s24 ultra looks way more minimalist than any iphone
TOOOOOOOO mucccccchhhhhhhhhhhh
expensive and less features
half the time you wont see the inside unless you take it to a repair shop
tbh i had both samsung and apple
For people who dont care about features the iphone is fine but if you like tech you will atomically choose a android
what does that mean in english
the mirror comment says it all 
but at the end of the day everyone can choose what they like and i might like something else and you might something else its fine. Just love what you have
oh
damn right
As I said don't take it personal

Please allow the VM 5 minutes to fully boot up.
dispare
5 minutes is crazy
I agree with sal, and @rapid merlin I meant no offense..
shadow hates waiting for this kinda stuffs
For what?
a vm to boot
for a tryhackme ctf target machine to full spin up
ello ello mogamboo
Mee too
Yep go ahead
That's the longest 2 minutes spent
Try restarting
oh noes

also check the smart data on that drive
Why do shadow come online only at this hour?
What does shadow do rest of the time?
Any fullitme job or something?
from 00:00 or 02:00 try to sleep.... at 10:00 finally fall asleep... at 15:00 get up and eat breakfast... at 15:20 go shower... at 16:00 eat dinner
HDD? even sata SSD with modern windows operating systems can be painful to use if you boot it up after a long time. It usually tries to index search, update and other background jobs that basically makes the device unusable until everything is done
It takes 10 hours to sleep?
Your condition seems worse than mine
yeah lots of tossing and turning
and some micro sleep here and there during that time
Don't mind my bad english
That means you are not employed... Student?
well gonna start uni this fall if shadow gets in
def replace it with a SSD if you actually want to use the device for something. I'm guessing the device probably also has very little RAM so anything that doesn't fit will also gets written to pagefile on disk making the situation even worse
High school?
Mannn this is crazy
THM full of young guy
nah just a SSD can give it a second life.
plenty of shops sell replacement batteries
my old Pentium laptop ran as my testing NAS for years with a SSD. (it had broken screen and battery).
SSD + lightweight linux distro can do a great job - everything is basically a webapp nowadays anyhow ๐คทโโ๏ธ
I would suggest battery from authentic source
Local battery will cause more trouble latter
Incase if you can still find
If not there is no other way
lol my current "laptop's" battery which used to be plugged in 24x7 before I built a desktop bloated to the point that broke the screw joints in the laptop chassis
you can start uni older
Iโm not an expert, but thatโs probably bad
Hello
if i clear a hard drive from a company laptop, then use a fresh download of windows, is there any possibility of them monitoring my activity?
Spicy pillow??
Does the company still own the laptop?
yesss
Just freaking take it out before it explodes
Was very common with certain Dell models...
its from an old workplace and its been a few years since i worked there, they never asked for it back
can't find one atleast not one that ships to my place at a reasonable price.
Also barely use the laptop. Obviously the pillow was removed the same day and disposed of later
oh k
using it with charge only makes sense
using it with a spicy pillow makes no sense except that you should run as fast as you can
I'd search amazon and ebay for a replacement battery. I know there are aftermarket ones for certain machines.
why the heck is firefox broken today
anyone know the answer to this?
yeah no nothing ships here. Even AliExpress is banned to get a knockoff version
what country
oof
India
eh then you got local tech market's
beep boop, hello fellow humans.
Call around to shops.
Alt EZ does.
Have you tried turning it off and turning it back on?
have you attemted methodically depeting the flow of electrons and then in a few seconds re-applying the flow of said electrons?
yeah no it's a obscure laptop. That probably was only likely sold less than single digit in the entire country. The only way would be to get the service center to import it. But no way I'm paying like 250+USD to get 6+year old battery replaced
Most of the time, if we don't know the answer or it isn't documented in our documentation then yes we have to research the issue. If it's an immediate thing or not doesn't matter if we don't have the answer.
The thing to keep in mind as that we give best effort to support issues even if we don't know. We have tricks to try to get things working as quickly as possible.
All else fails.. research the issue and find alternate solutions. If one does not exist, then deep dive and come up with a solution.
recently had a friend ask me about a support ticket he got. I found the fix under an hour while their dev team also received a bug report from another team and the fix release date was expected around Q1 2025.
Then post it on stackoverflow or somwehre and be a hero other techs who run into the same issue. ๐
friend of mine asked me to test the security of his WP site for any vulnerabilities, I attempted LFI and I feel like WP has banned my IP or something, I didn't even use VPN as there was mutual agreement for the "pentesting", has anyone run into similar issue where WP flagged his IP due to LFI attempts?
I cannot load any website at all hosted on WordPress
was it a xxx.wordpress.com site?
nope, they just use WP as hosting
yeah likely could be blacklisted
anyone know if i clear a hard drive from a company laptop, then use a fresh download of windows, is there any possibility of them monitoring my activity?
Eh make a post about the question then comment "I solved it" without any details for maximum effect
should've used a testing environment for it, didn't think it through about getting flagged so easily
That's what I put in the resolution of all my tickets.

I got demoted to 1.. but pay increase. ๐คฃ
I've been a l1 tech for over 5 years now??
We do a lot more than your standard help desk though.
The fix was reported to their company so I think they fastforwarded the fix. I'm not sure. It's sorta like a helper tool for one of their main products.
No path to L2 even.. even for people who have been with the company for over a decade...
Yeah. It's a good job to have if you have a good team and good manager.
Reason I haven't left yet. I love the company, my team and manager.
aside from violating the AUP of the company that owns the equipment, there are other ethical considerations from doing that
havent been at the company for about 3 yrs and they didnt want the laptop back
that doesn't change your liability - unless you have it in writing that it's yours now, it's still technically their property, and modifying it could result in some liability
Just start applying now bro, itโs only help desk @rapid merlin
10th gen i5, not that bad
they may be paying lease on that laptop, and if their asset management isn't great, they may not even know you have it. that doesn't change the ownership though
i do know people who were billed for the company laptop they did not return when they left the company, even years after
Sony has even made a property theft claims against it's employee for a mouse. Which ruined the employees career after they got hacked
Why worry about your accent?
I mean it doesnโt really matter, almost every help desk I call in USA is staffed by Bengali or Indians or whoever else. You type like a native Iโm sure youโll be fine broski
Iโm guessing because of all those scammer videos blowing up on YouTube, Indians got a bad rap right now in IT lol
I work with people all around the world tbf. I'm backwoods white trash 'merican...
hes gonna be sleeping this weekend
Oh youโre Czech I was way off
Youโll be fine just practice man. And if you do land a help desk gig what better way to practice than 40 hours of English a week
Youโre already over qualified
Just rip it
Most of my communication with people is via email or chat. We do take and make calls but it's more frequent that we get tickets submitted through our ticketing system and respond via email out of that. 90% of the time we resolve the issue through email.
I'd say that if you speak 'good enough' english, then help desk would be okay for you.
I have always treated ever interview as a way to learn where to improve.
Yeah exactly, the worst they can do is say no.
The fact that you can even bug bounty is what I meant by youโre over qualified. I donโt think web app testing is a skill the average help desk employee has lol
It's not. Neither is configuring Cisco devices.. just good troubleshooting skills is all you need and customer service. Customer service skills are essential.
Yeah. So it still might be degrading. But at least you wonโt be digging ditches
I do dig ditches when I have to. lol
Moved and had a hard time finding a job.. so.. ditch digging it was for a while.
I'd say you need at least the knowledge required to pass A+ in helpdesk
From just that description, I'd hire ya on a trial basis to see how you did with people. The technical skills can be trained and every environment is different.
That's true
there's nothing as infuriating as being forced, by policy, to get help from helpdesk and they just not understanding the problem at hand
A+ is preferred for help desk.
A+ will help you with that
I once had a problem where some websites and services was blocked on my PC, which were not blocked on their PC. They asked if I had run Windows updates - and even had the audacity to try to run win upd themselves
and if I had rebooted the PC
and if I had tried connecting to another network

Lmao maybe they have their own dumb script of preliminary questions as dictated by company policy birb?
After long insisting and incredible willpower to not punch anybody in the face, a senior guy overheard us and figured out that my PC was accidentally enrolled in a beta program for a web proxy, which needed to have some services whitelisted
Yeah that sounds silly
Ya know.. sometimes I'll call a user and say "I know you've already tried all this.. but we have to go through this stuff again."
It's frustrating.. but process.. ๐คท
They 100% have a checklist and I bet you that in 60% or more of the cases that checklist solves the problem
"Are you sure the computer is plugged in?" 
All hail The Process!
but when a DevOps guy has to ask service desk for help debugging their stuff, it's usually not the low-hanging fruits xD
(and especially not due to missing Windows updates like WTF was that kind of suggestion)
"Have you tried closing your Word and PowerPoint files?
"
SAY "have you tried" ONE MORE TIME 

Oh yeah.. I don't train you on how to do your job.. You should talk to your manager about that. ๐คฃ
How tough was OSCP birb ?
depends
if you have a programming degree and 3-5 years of experience working as a programmer/DevOps, and can devote 4-8 hours every day for 2 months, then pretty easy
if not... eh

dunno
hi
Thatโs the end goal for me, Iโm coming from sales though. Zero experience with anything. I just learned to touch type lol
Some people spend multiple attempts before getting lucky enough to pass the exam, others ace it on first try
Software engineer?
yes
smh smh
I went from zero to OSCP in 2 months passing the exam on first try in half the time but I'm also a massive nerd
ยฏ_(ใ)_/ยฏ
well strictly speaking I'm not a software engineer
I've got a B.Sc. in softwre development
N1z0ku also just passed their OSCP
fair fair
they're from HTB
Did you spend a lot of time in the lab prior to taking OSCP?
only the OffSec lab
I rooted 53 machines or something like that (this was in 2019 btw, so before they introduced AD)
Are there any guides youโd recommend or any particular scripting languages or concepts that were helpful? I do alright with THM stuff but my fundamentals are pretty nonexistent
I'm debating re-purchasing lab access and going through the material again.. then actually taking the exam.
Now weโre all harassing birb
I hate tech support like this
Feed us ๐ฃ
For me the OSCP (PWK course*) material was what taught me all I needed to know about infosec back when I studied for the exam. That and whatever extra material I needed to learn to pwn the lab machines - things like WPScan and CrackMapExec are really useful but I don't think either was covered in my course material. I had to "discover" those tools while going through the lab.
Besides that I'd recommend familiarity with at least one programming or scripting language, ideally Python or Bash
If you can write simple scripts and you know what a "socket" I think it's safe to say you know enough programming/scripting to pass
yes
I think
wait
hmm'
If used correctly, crackmapexec is op
I believe you can use your own tools, but you need to document them and how they work in the report. I'm not 100% sure.
I never had to. Only my own scripts which were then documented with source code in the report.
Help desk and tech support is not only about technical knowledge, written and oral communication is super important.
I don't communicate the same here as I do through email, on a support call etc..
js.. lol
I got my first tech support job because I had experience with client-facing roles in the hotel industry; the little tech knowledge I had was just a +
Things like "Yall need ta chill" would be more like "Okay. I understand your frustration. Why don't we take a deeper look at what's going on so we can figure out how to better communicate together." or something like that.
If you need any tips, lemme know. I worked corporate.
did CME ever fix the part where it doesn't give any output when it fails to connect?
shadow got their first job programming cash registers through church connections
I did a lot of volunteer work prior to my first IT job.
yes matt is from the big bad red blue and white country known as the usa
American speaker* 
ahem... 'Merican... tyvm. ๐
New Joysian, thank you
You speak for America?
omg lol
That's quite clever
huh?
@amber inlet/@normal fable I wrote about my OSCP experience in my one and only blog post on my website dedicated to this exact situation 
If you want to give it a read, here's the link: https://localnest.xyz/2019/07/27/yet-another-oscp-exp.html
(It describes what "building a methodology" means, which was a problem for people studying back then - they were all told to "build a methodology" but never what that actually meant)
"He's just a normal bloke" 
Let's go las vegas
โค๏ธ
I will def give that a read. Thanks Birb!
Gave +1 Rep to @shadow loom (current: #372 - 13)
Money is on me
Huh?
If not for the curiosity then for this reason:
When going through the course and hacking my way through the lab, I often chatted with fellow students and current OSCP certificate holders about this and that. One of the questions which I frequently asked them is which topics I should focus on learning first and how I was able to tell what I needed to know. More often than not, the recommendation was to โwork on your methodologyโ. I asked how I should go about working on it, and what a โpentest methodologyโ was exactly, but I usually received mixed replies. The common denominator however was to hack more machines and learn by doing. I was left feeling confused because to me it felt like I had asked how I learned to swim, but had then been told that the way to learn how to swim, is to try to get across as many lakes as possible with less and less help.
It's a bit of a weird situation to be in, gotta admit
"How do I get better?"
"You just gotta do more."
"OK nice. What does that mean?"
"?????"

Iโll check it out, and yeah Iโve definitely learned way more by just doing rather than memorizing a bunch of random concepts. Although I usually do not like doing things without knowing the โwhyโ behind every little thing.
Answer earlier question in 1 gif.....
But yes lmao. Feel free to DM
bet matt is worse at english then the majority of nordic or netherlands people in here
Matt's english is pretty good. lol
i again got burnt by reading a file and piping the output to the same file idk why i can't remember to not do that
All aboard!
than*
Naw fam, my English ain't wack!

can we stream THM rooms?
WOOHOOO
I guess, right?
wait.. how many hotdogs long was that boat?
that time studied is so so so so so wrong
(old ones, not the < 72 hours ones)
so long as it doesn't explicitly tell you not to, or is less than 3 days old
cool
Believe it was about 73 Chili dogs long ๐ค
Standard chili dogs or Costco size?
the legit top 1% of thm 
Your the best
That would be cheating no?
There are quite a lot of questions that don't require an answer, so maintaining a streak isn't too hard, as long as you can sign in every day.
Oh wait
NOOO, why did the steam summer sale have to be now
Flew over my head
It's just that shadow is dedicated to maintain their streak.
Who here has soc analysis experience. I got a question
Just ask your question
Anyone wanna watch some Year of the Jellyfish shenanigans live? I can't speak right now, but I could stream it in one of the voice channels
I can join, but later tonight, if you're still doing it then.
chooo chooo
I'll watch.
When you are looking at logs for a huge corporation. The amount of logs is gonna be going a mile of minute. Is there a way to slow down logs? Or do each analyst team get a pcap file and they analyze that one pcap file. Ik there are tons of filters for something like wire shark etc, but even with filters you might miss a potential intrusion. I just have a hard time understanding how it runs for a big corp instead of something like a home network.
logs can be separated for each service and so
Filtering and alerting only on specific things
Standard ๐ค
nah shadow has a goal of a minimum of 1 question a day.... also shadow has a very steady flow of new rooms to answer questions in thanks to room testing
Gave +1 Rep to @shut raven (current: #429 - 11)
You need to narrow the pipe, otherwise you're going to miss things
I see like brute force artifacts etc
Event ids
Lots of filtering rules, there can be whole teams dedicated to it
Gave +1 Rep to @sand trench (current: #4 - 1788)
Thanks for all of your guys response
Year of the Jellyfish shenanigans at https://discord.com/channels/521382216299839518/521382216304033796 if anyone else wanna join. Fair warning: got dinner comming soon too so may not be 100% super very hackerlike active

I would say donot pay much attention to the difficulty rating. Just start doing whatever room you feel like. Get through some of the paths so you have the base knowledge and just attempt whatever box you feel like.
I've definitely had boxes rated easy that feel like insane due to missing a tiny clue and some insane rated boxes feel easy.
i would've never seen this coming
@hollow pivot How are you today btw?
A wild Szy has appeared 

oh there is a bug hunter role did not notice it before
I guess I'm one down out of ?? bugs to report to get that role
i've only seen like 4 other people have it
That box is slightly mean
Bug hunter role is usually meant for people who were authorized, and within scope, finding vulnerabilities within TryHackMe
https://help.tryhackme.com/en/articles/6495946-the-bug-bounty-program
Responsibly discovering & disclosing security flaws!
3 vulns required to find
Verified and confirmed
of course lol
Pretty hard nowadays
Might be some things with the redesign
Perhaps
But 1 is not enough, you need to find 3
๐ฅฒ
well I'm more than happy with my tee. thanks to blackout ๐
What kind of bugs are applicable?
Security.
Those
7 have it.
i had to find more 
Nah i thought spiders
oof
"had"
okay yeah didn't have to
have u played factorio much lately?
but like first month of me using this site and i find that the entire messages feature is one giant BAC
Syz was held at gun point to find more vulnerabilities. He HAD to 
live listening on everyone's group chats 
nah
Free pentest
No force
got a bounty too but wasn't much
i don't want to touch factorio until the expansion drops
otherwise i'll get sucked in and i don't have time as it is
fair fair, you can't escape it 
modded is super fun
we have around 70 on my 1GB RAM VPS, no idea how it's still surviving
really well optimised
I have a krastorio save lying around....
i'd rather spend 8 hours writing a binja plugin for one thing than start another factory nowadays lol
which is exactly what i did until midnight yday
How many people actually find bugs bountyโs in tryhackme
Unknown.
But 7 people have the rank in the server.
don't mock me sir
I don't think it's even 2 this year
Iโm guessing thatโs mostly when TryHackMe first came out
i didn't say anything
or I will steal your cherry coke
just said that i didn't see this coming
Possibly
That sounds dangerous
I love pigeons
Skill issue
what the fuck is the "owner" of a drive. I've heard of owner of a folder or a file, but never an entire drive
Doing good, hbu?
I found something that says the "Owner" of C:\ is TrustedInstaller
that's the only reference I've been able to find to an whole drive owner
Sorry for the confusion with the things i have said lmao. I'm a little bit high
Oh
And i do laugh to my own jokes
Pretty good, writing up documentation right now ๐
yeah it sucks that international travel is so expensive
@gray sonnet @devout palm https://www.ftc.gov/news-events/news/press-releases/2024/06/ftc-takes-action-against-adobe-executives-hiding-fees-preventing-consumers-easily-cancelling
That definitely sounds like adobe 
how can i find investors in students?
i need someone to pay for me a certification
that i can't afford
but i have to ability to take
@shadow loom Unmute? 
get a internship
Anyone here got an estimate of how much mobile data i will need as i will be travelling soon and want to get data in the country i travel. just for using thm daily.(i will use hotspot)
depends will you be using the attackbox
idk im on the pre security path so i think at the end a bit
My daily usage if using attackbox was 3-4gb
Thanks a ton, imma get 100gb then and if i need more ill get it
Gave +1 Rep to @buoyant tree (current: #112 - 60)
Yeah without attackbox it's probably going to be around 100mb
Birb hacking for masses?
not yet ๐
Lets goooo. Wrote instrcutions for an app because installation was confusing. Now it's in their official installation instructions
Unpackrr?
Yep 
Nice
See, I don't always break operating systems, I also help people with step by step instructions lol
Did they ask you to do that
I told them they were missing it, owner of the app asked me to write instructions since he doesn't use that OS, wrote it, then he added it to the instructions
Shouldโve been paid
Open source contributions are good too
Did the instructions also note how to break it?
Their old instructions did 
Old instructions didn't have a caveat of "If you setup your download client to use a different mount path, do X"
It basically said "Add this, and this, good luck"
Spent a day going in and out of docs, reddit, no youtube videos. Now that it's added, and in a simple step by step instructions if you have a different mount path
@shell nova Role request
no, pi as in pie without e
lol, it's okay.
Nah a pi hole is a dns sinkhole on a pi
any tutorials?
Yes hold on
how Am I finding someones ip adress out?
Man I have to say one word for the author of windows privilege escalate room is really goat ๐
He smoked me with that task it's been 5 nights I still not completed that room
Real bro he unlocked beast mode at that time
I never feel hard to other rooms except this
@mossy river
@barren knoll What are you trying to do that for?
wym
Why are you trying to get someone's IP?
???
look at prv chat
Oh, private chat.
Must be important
Someone has their IP
Why am getting this error in attackbox?
They're scared because they're being lied to by the "hacker"
No internet on the attackbox unless you're a subscriber
Was thus from a random email?
I am
Looks like IPv6 is broken then
That's a target machine, not an attackbox
Target machines don't have internet (with like, 2 exceptions)
Fuck me
I didn't realised I was using the ssh even after completing that room
Thanks for pointing out
Aha, no problem

Car insurance is the bane of my life.
powerlevel10k is deprecated
shadow gotta swap prompt
but it hard to setup time to configure any other one
Any scripting language should work, pick the one you like the best; JavaScript is kind of unavoidable since it is the scripting language of the browser. Focus on learning fundamentals like string manipulation, working with arrays and hash tables, how to pack/unpack binary data, how to do File I/O, run commands, open sockets, do HTTP requests, parse JSON or HTML/XML.
very true 1.5k for a learner and then 4k for a corsa lol
I'm going to assume gender and age will heavily influence that.
yeah 18 but gender matters?
For the US it does
Yes, Men always pay more than Women.
Young male, you're basically screwed
guess ill drive when im 40 in this economy
Mines only gone up
If you can, stay under your mother's insurance until you're legally required to pay it youself
Mine too.
Mine too
thats what i will be doing but i saw that they made that illegal a while ago
im not sure tho
It was supposed to go down at 25
turns of age to have it lowered
Also car insurance: Costs more than last year
Backwards country right there... tf
insurance companies are one of the worst scams
state of uk rn
What has been made illegal?
Apparently using your mother's insurance till you're legally required to pay it yourself?
idk i saw a post about 7 months ago not really sure
Been illegal here for ages, it's called fronting and it's insurance fraud
Yeah,
I feel so bad for you guys
The main driver has to be the person named as the main driver...
You can add your parents on to your insurance.
apparently the usa is closing in on 54 trilion in dept
Because lying counts as fraud there? Does for your lot too, mate
I think you're confusing health and auto insurance
I would like to know your source..... US Treasury says 33T
Both
Health insurance is 26, car insurance is based on address
oh wait they stated that is by 2034 or so..... so it is a prediction... shadows fault
You need to be living with your parents.
still that dept is crazy high..... poor current young people and future young people that gonna be forced to help pay that off
Oh we're already screwed in this market 
Honestly, it will end up being taxes by corporations more than individuals that pays it off. And tightening the spending belt, which our government has never been good with, but has gotten consdierably worse since the 90s
But that's also going to go political so we'll drop the taxes and debt stuff please
I need to see what other apps I should add to TrueNAS
OFFLINE BACKUP OF WIKIPEDIA
I NEED STORAGE!
Emma is using all of my storage!
109GB with images and media
what is emma storing???
Dunno
don't you got read access???
Yah, but her data, I'm not snooping, no right to lol
I'm a good boy
๐
James, don't you dare say I'm a bad boy lol
Hi everyone, I'm new to this world and just starting out. I'm eager to expand my knowledge and improve my skills. Could someone recommend some books to me? I'm already following the learning paths on TryHackMe and practicing; I'm nearly finished with the beginner path, so I have a basic understanding but still have much to learn.
Have a look in #bookclub
Being a secondary driver is fine, but you have to actually be the secondary driver. If you drive it 50.1% of the time, you're committing insurance fraud
Nah I'm trying to figure out earthing and grounding
Like OSINT? OSINT Techniques: Resources for Uncovering Online Information by Michael Bazzell
Here's the thing, how am I supposed to measure that? White board by the keys "Who took the car?"
Milage of the car...
how would they know who drove how many miles
Let's not try and promote fraud...
You should really be aware of who normally drives the car.
It's on them to prove dishonesty, sure. Just... Don't promote insurance fraud.
yeah but just asking as its pretty stupid
A lot of systems are designed for honest people
You should try your damndest to be an honest person.
Honest people get screwed by them the most, i agree being honest is best but insurance companies
Not promoting fraud
NO ONE TRY THIS
In the US, that's not really considered insurance fraud. (not a lawyer)
If your parents own the car, and you use it. That's not fraud.
"Your parents own the car, and you live with them: If your parents own the car youโre driving and you live at the same address, you can be on their auto insurance policy. Youโd be considered a covered driver for that vehicle."
Sounds remarkably like you're suggesting defrauding insurance companies still.
Perhaps it's better to move forward?

"Can use it" is different to "be the main person that uses it"
There's no caveat (as far as I know) that says that for the US. @whole yew Can probably correct me as he has more wisdom than I do.
parrot?
My understanding is that James is correct, even for the US. "primary driver" is still the person that drives it the most, it's sort of a situation where insurance companies don't look too hard because it doesn't cost them much in the way of profits. Pretty cynical, but that's my observation of what's on paper vs the reality I've experienced.
hmm looks good, installing it
Thanks for clarifying Juun! 
Gave +1 Rep to @whole yew (current: #10 - 762)
the worst to get is a blackbox lol
Sure, although first fixing my VM
somehow broke it in a way I don't know how to describe
@shell nova ๐ pcb day
I don't know what the purpose of a 4K linux VM would be, but good for ye
Now you can see the nmap scan in more detail.
How is it broken?
Most of the time I wouldn't bother to game in 4k even if I had a 4k monitor. It's a lot of extra compute for not a lot of extra benefit.
my computer can read and when i put the micro sd, sound
work
but i cant
use
and see
in my disc
ah oh my zsh
Can you please type all in once message please.
That's the level of skill and precision for micro SD btw
of course like this
the noob trap that slows downs tons of shells
ok
you know shadow is a noob when it comes to permanently deleting data of ssd:s
Muiri?
Shitposting?
Wow
have had the fun of using a degauser and hdd shredder before though
Just procrastinating
that does not really show the shell in your picture and more so shows your customised prompt
That's kinda cool.
Set-screws with probes that are backed by traces to power and data lines?
there is ohmybash too
I use the micro SD for my Nintendo Switch, on Tuesday I played Fortnite which I have saved on the micro SD, the fact is that I left the console in standby mode and when I turned it on yesterday it didn't want to read the micro SD, the console didn't It didn't detect it or anything, yesterday when I connected it to the computer it did detect it but yesterday taking certain steps to unlock it I think I screwed it up hard and it no longer appears on the disks, unless I see it in the disk manager, I think the console found it I locked the micro SD and I ended up screwing it up, now I literally can't do anything with it
both are posix compliant
zsh has better plugin support
which gives you things like syntax highlighting and auto complete commands
zsh has better built in tab support then bash
alacritty using the sixel fork
Gave +1 Rep to @sand trench (current: #4 - 1789)
i send the message
but i cant send image right here
i cant show you how is the memory and other things
You will need to verify
how i verify?
The TryHackMe Discord Server
Blue terminal blocks on the top one.
Mounting holes are just grounded
It's just handy little boards to turn 7-25v into a clean linear 5v for powering radio amplifiers and stuff
Oh wrong image
SHell
Bourne Again SHell
Korn Shell...
There's a lot of shell options out there ๐
Yeah basically, tiny tiny probes to hit the pins in the memory
No worries, I know you've been working on your PCBs for months, I know this because I've seen you speak of them before, and I haven't logged into chat in months ๐
They all have different pinouts apparently
Looks like you can be messy too and use enamel wire
That tracks, probably all determined by the integrated controllers.
I imagine the mess enamel wire option is what happens in Louis Rossmann's shop.
If I ever visit Austin, I am so taking advantage of their open repair nights ๐
Police forensics use the spider ones, although I don't think it's common
The short enamel runs probably have better signal integrity.
very very very fast update cycle as it is rolling release and also has bleeding edge updates for software
no need to reinstall or use dist-upgrade to keep your system updated over multiple years
very very very very great documentation in the form of the arch wiki
the arch user repository has basically all the software you could ever want that is not in the primary repos
the primary repos has a lot of software too and has a tendency to get new packages from the aur in there when enough votes on said software goes through
fancy colored options and nice multiple download at the same time for package management
What is the token of my discord profile?
go onto your tryhackme profile and go into manage account and scroll down until you find the discord token portion
ok thanks
Gave +1 Rep to @sand trench (current: #4 - 1790)
kali is the industry standard for a few reasons
like comming preinstalled with a lot of tools
but arch linux is definitely decent for hacking
as you can get nearly all hacking tools installed easily
archlinux by default is very very very barebones
you basically build your own daily driver distro with the packages you install
hello everyone! When I want to make a transaction with the inscope url given in a bug bounty target, are sub domains and directory urls included? So, is it necessary or prohibited to scan sub domains and directories via inscope url (main domain)? Are the sub domains and directories I found considered outscope?
@umbral bay @mossy river Question about bug bounty
You should ask the company that has the program
Usually it will say in the program, if it doesnโt, assume you cannot.
Sounded like it was for THM, so pinged you two just incase ๐
thank you!
Guys can someone help me?
Maybe 
I want to conect with the cloud's sv
For test the machine
But when i put the code in the vpn give it me error
Hi?
eugh starship feels slow because of powerlevel10k:s instant prompt feature
502 is usually a cloudflare thing. if you're getting 400s, that's probably more indicative of a problem with THM itself
Guys it seems to me that thm focuses much much more on post exploitation stuff rather than gaining the initial foothold is it me or that's how it is?
Like I'm in red teaming path and it's 80% post exploitation
Initial Access isn't worth much. It's what you can do with that access that a Red Team is for
I got Red Teaming cert a lil over a week ago
@mossy river @naive violet
@junior beacon ?
I swear, feels like I got Jabba on speed dial today ๐
Jabbas not that fast atm
stop it, seek some help. Broken url anyways
@whole yew
Done!
Fixing my computer rn lol
Don't tell me Matt got near it.
I plead the 5th
and shadow pleads the 3rd
Protecting your private property?
refusing to house soldiers on private property for those wondering
You have the right to remain silent. Anything you say can be used against you in court
you have the right to not house troops on your propertiy
The Third Amendment to the United States Constitution places restrictions on the quartering of soldiers in private homes without the owner's consent, forbidding the practice in peacetime. The amendment is a response to the Quartering Acts passed by the Parliament of Great Britain during the buildup to the American Revolutionary War, which had allowed the British Army to lodge soldiers in public buildings.
As long as you don't plead the 18th ๐
You plead the restrictions on the quatering of soldiers in private homes without the owners consent?
yuups
Amen ๐ป
