#general
1 messages · Page 250 of 1
nope
centipades i wish i didn't watch that movie =/
Errhh... I'd say yes (?) I have both, I usually only use the 5G for devices near the router. Idk if your device supports MU-MIMO, if so, enable, but do your research before doing so. I did it on my part, since I had some issues with my WiFi, since then, it's been quite okay. Despite the fact my ISP sucks and I hate it, but that's off topic.
I knew this was coming and still flinched
I think 5g is faster than 2.4g
But I think that the range covered by 5G WiFi is less than 2.4G
correct me plz
lol just learnt go only has one loop construct, for - so a while true loop would be for {}.....how odd 🥴
go is weird like that but it somehow works
Correct, from what I know 5G is faster, in theory. I know there's a difference of 850 mbps in the theory, I don't remember how much is one or the other. But 2.4 tends to be more reliable than 5G sometimes.
I mean it works sure, but just...why lmao
Google doing Google stuff ig
honestly, i dont have any idea about "MU-MIMO"
I'll do a little research
Dunno, dev didn't want to implement while
get it
Also, correction to myself... 2.4GHz, and 5GHz *
Indeed. Put MU-MIMO+network when googling, perhaps you'll get some other unrelated stuff. lol
It is Multi-User, Multiple-input, multiple output. It's a tech used in WiFi routers to improve efficiency, and data transfer speeds when communicating with multiple devices simultaneously.
ah, okay
But I didnt understand what does it have to do with my problem?
Just going back to the 2.4 GHz and 5GHz. Creating a separate network might not resolve your issue. While it might solve it, if the congestion ain't that high.
If you can optimize the 5GHz channel, do it. I personally did mine. My equipment is not rented, I could do it without problems, but if rented, you'd have to use your ISP app (if they have any) or maybe even have to call support.
@high mulch I think MU-MIMO only works on 5ghz, and my router even dont support 5ghz
Aaaah, I thought you had 5GHz, my bad. I must've misread your initial comment. My mistake.
This needs to ruuuush
No problem, but yeah, I think Its the time to replace the router, it's really old
Yeah, that was going to be my next suggestion. LOL
I don't know if you have IOTs, that'd be another recommendation, to get them off.
Move the router, to a better location, more central location. No loads of furniture blocking the router, put it on a elevated position (which I should take this recommendation for myself lol).
But yeah, less headache? If you can, buy another router...
Why didn't you download kali VM, Less time
Some people say using Parrot or Kali as a beginner < Setting up everything from scratch
Opinions?
Because I install all the tools.
I used parrot and didn't like it.
I stick with Kali because it has what I need.
I see
I have an extender that I might use this time
Parrot gives more error and there whole lot of mess... Saying this from my exprience yours can be different
extender? like powerline adapters? But if that works, hopefully it works, then good! :D
hi
This is it:
https://www.dlink.com/fr/fr/products/dwl-2100ap-xtremeg-108m-wireless-access-point
my friend used it as an extender, He gave it to me a while ago, It's been sitting in a closet for years, Maybe I can benefit from it now
um
hello
already saw
i hate
skids will be skidding
the internet
and that is why we exist!
good thing i turn off all telemetry
on
whatever i use
and always worry about my security
those guys in the video were preying on the gullible mostly
basically just use common sense online
and you should be fine
there wasn't really much at all to do with telemetry
since they used RATs
yea but still
Leave them be

Bro...What........

you need and exorcist, not an AV
I tried to install metasploit on windows once while kaspersky was enabled
That was not fun
it turns out
defender
ez.. don't allow Windows to see your Linux partition. lol
no way lol 🙂
Could encrypt it..
NO WAY
IKR
@dull portal how does windows even detect the Linux partition??
im shocked
Why were you using ntfs on ur Linux partition 😭
disk is disk. file is file
yuppp, I used to run my own silly scripts, like keyloggers, or php stuff. It turned my vscode into an annoyance... recommendation, don't run it on a windows machine lol
Who in their right mind would do that 😭
God forbid an antivirus doesn't like hacktools that could be installed by a threat actor
lol
short answer, seperate your shit
Windows can’t detect anything other than like ntfs, exFAT, and vFAT
it can
It can’t detect ext4
well it did it anyway
Run a VM don't install on hardware...
im not sure of that...
Hey EZ 👋
I’ve tried in the past
afaik Windows can't see ext4 drives.
You have to install some wacky third party tooling for windows to be able to read ext4
Or you have to plug it in as a separate drive and go through wsl
so if i have ext4 and have some hack tools will not catch it ?
I'ma make a ext4 usb with hack tools on it to see if Windows detects it..
as soon as my windows computer is done creating a backup image... lol
then how in d heck ransomware and so encrypted even linux partitions and so
IT WAS THE ISO IMAGE THAT I WAS SEEDING
They encrypt the entire disk
omg lol
That has happened to me in the past
My AV catching the kali iso
yo.. yall making me want to set up a VM to test this ransomware theory..
But it detects the tool inside
So it can’t actually delete the file
Since it doesn’t exist on the fs technically
So it goes bezerk
I didn't think Windows Defender would mount an ISO to scan it..
It doesn’t I think
AFAIK
Aren’t ISOs basically glorified zip files
Nvm it’s more like tar
an ISO is basically a transparent archive format. It's possible to pull files from the ISO without mounting it, if you have sufficient free time and a deep knowledge of the format
Guess I just pinged you for nothing then.. sorry. lol
bot dead I think.. 😦
bot is on vacation
different bot
oh
rep is managed by robocop, i think
😦
i guess it could be yag?
til... by default ADUC as installed by RSAT does not show bitlocker recovery keys....
If it's a bot, I'll always blame Ben, even if it's not his fault lmao
had to look up how to get that feature installed... lol
t minus 1 day...........
until doctor apointment
ah.. hope it goes good for ya.
CheeseCTF isn't wayyy after august haha
Ouch, hope everything is okay shadow 
well it is a gender clinic doctor....
Oh
So, just saw a job posting for an incident and response analyst that the compensation included an incentive plan. That sounds like you have a quota and get commission or similar, right? lol
check if said workplace recently had an incident
sometimes they try and hire incident and response people after an incident
Google search doesn’t show anything recent
What would the incentive plan be if not some type of commission? I know you’re not selling while doing IR but still
hi
¯_(ツ)_/¯
👋
Wdym?
there is a lot of not very good tutorial content on udemy mixed in with the rarer really really good stuff
I still haven't made it through all the TCM videos yet.. got my AD lab all set up.. but.. haven't gotten further.. 😦
I see I see
shadow is debating trying to watch through all of the CS50 videos
any programming languages worth knowing for web bug bounty
or just python, html, sql, javascript and css
well a few of those you listed there are not programming languages
yes ik
js, python, php, sql, html at minimum I think.
Don't need to know ALL of the language.. just have a basic understanding of how it works.
ive been procrastinating on that for quite a while
gotcha
know how cookies work too. Very good to know stuff.
yeah ofc
@sand trench @normal fable thanks
Not necessarily, without seeing the wording I can't really give you an answer. However, performance reviews can lead to incentives where you're earning bonuses. Incentives could also be stock options on top of base pay. Etc etc
hi
Hello
good day
I see what you mean. It says “Additional compensation: total compensation for this role also will include an incentive plan”
This sounds like it’s additional but then the words “total compensation” makes me wonder
ello can you say anything else then hello or hi???
Total compensation is everything, base salary, stocks, etc @honest forge. Sorry it didn't attach to your message
my life is a failure
So when something says $350k total compensation, the base salary is probably $100-180k and then the rest is made up through stock and other potentially performance based incentives.
I’m leaving cyber
The amount of pain this computer is putting me through
It’s not worth it
I’m taking you with me Jayy
I’m so hungry but I’m out here trying to fix the bloody wifi because the company that I bought the computer from thinks it’s better to send me on a run around instead of actually looking at the specifications of my machine
No
Ah okay. Sounds like a job I’m not interested in since the salary range is $50k difference between lower end and higher end and the low end is the bottom of my range
Loading reputation exploit.exe
Believe it or not, I had to ask an IT person today if they did that.
Their response “wow! A reboot fixed it!”
Scary when you reboot your box and keyboard doesn't connect...
box?
so in that logic, ware also should mean a computer 👀 /s
Never heard that before
Thought it was about putting the computer inside a virtual box
head's starting hurting
👀
Box can mean several things.. but one thing it does mean is "computer" 😛
Like "Oh man I just popped that box" can mean "I just got a shell on that computer system"
Shoutout to Hack The Box
Is it me or the VMs are really not working well today?
thm VM ?
attackbox?
Anybody have VirtualBox installed on there Mac M1/M2 Pro, or am i still beneficial with UTM?
THM network is same speed as always for me
Doing Sourcing.Games, get this pic. @gray sonnet says: "That looks like a person I know"
all or just those you regret?
the ones i regret
Nope. Especially those not
Why


I don't even know what we're talking abt
Ping 10.10.10.10 what’s the delay? @harsh gorge
Its just a syntax error i think.
It’s slow loading rooms or just copying files or what?
Pictures?
Minimum 0, maximum 1, average zero
Can u share a screenshot?
4 received 4 lost
Interesting, maybe switch VPN server? You shouldn’t be losing packets
Day 2 of exposing Vain.
Idk it's taking forever even to locate files
Like it's there is no output for like 30 seconds
More like day 5000
Would confirm thats not from you
sudo ip link set dev tun0 mtu 1200
Try running that then test the ping to 10.10.10.10 again @harsh gorge
Yo.. Take out everything after ; and just put in whoami to see if it tells you like www-data or something.
Switch the /) behind "process" and try again.
not sure if that'll work but it's a thought.
Hai Hai
Either that or you need to switch VPN servers to one that’s closer or one that drops less packets @harsh gorge
wut system r we hecking today
Ping RCE OP
try other chars that are not ;
I was just experimenting on my system. lol
nice nice
i mostly play vulnhub cause I've played every freaking system and i swear everything is easy now
spoilers for upcomming room: last weeks room testing was of a room that got marked as hard by room testers
@loud marlin I just created a very simple hacking ducky script
you most likely want one of the simpler ones... the bash -i or nc mkfifo or python3 ones are the go tos for many
ENTER
DELAY 100
STRING cmd
ENTER
DELAY 200
STRING color a
ENTER
DELAY 50
STRING tree
ENTER```
Bask in the glory of my hacking ducky script!
@loud marlin
mkfifi
mother of god... lol
shadow remembers the old days where you can put the entire windows system upside down
BASK In the glory of the holy ducky script!
you monster 🙂
WIN + R + Enter + "cmd" + Enter + "color a" + Enter + "tree"
That's pro haxor level scripting
green terminal
If you're not using hacker green, you're not really hacking
open 3 different terminals and keep spamming tree
so is that why shadow is not a true hacker as they use the catppuccin colorscheme instead???
- How's it working as a SOC Analyst?
- How's the work-life balance?
- If I'm on leave/vacation and the company I work in has a cyber attack, will my vacation get pulled/will I have to cancel my leave?
Also... Should I become a Cybersecurity architect or a SOC Analyst?
Please tell me briefly the pros and cons of both.
I made a scambait VM that had the tree command print out ASCII art of an oak tree. Lol
Based
I may still have that file. It's like tree.cmd on one of my old windows vms..
I work in a SOC team. amjorly for firewalls and sec posture. cybersec architect is one of the elite jobs imo and is very well respected at least in my firm and its not an easy job to crack. i have seen architects as old as 50+ years with almost 10+ years of work experience. SOC has multiple levels and yes sometimes the SOC analysts more or less have to face a situation where the work life balance might get disturbed but personally i have never experienced anything as such
#cyber-and-careers would be better for ur questions.
100%. You need to be using hacker green!
architect or network security architect jobs are the best and what many should aim for. They will be the pillar for designing multiple enterprise infra so, if you are asking if that is the difference in those roles then im afraid you have to read about those profiles once again.
Wooo burpe suite mentioned
the thug muffler is so good. only if he puts the mouth as the stalker bandit that would have been perfect
@loud marlin I made it an infinate loop!
i'm in this room
there is an spip 4.2 based website
and i found an exploit for it (RSE)
i did everything
but when i do a nc command to get a shell
#room-help might be better place to ask
sorry
DELAY 400
GUI r
ENTER
DELAY 500
STRING cmd
ENTER
DELAY 500
STRING color a
ENTER
DELAY 50
STRING tree
ENTER
END_WHILE```
?
Ducky script
lots of trees. lol
Infinite trees!
what is wrong with you ???
Yes
should do WHILE TRUE right before tree 
pls... do not feed him with ideas 🙂
I'm seeing AND ONLY FOR TESTING PURPOSES, writing a python script to increase thread, and having the ducky script call it.... dunno if it'll work
python? why no powershell?
🤣
I make python into an executable
Have the script call the exe
anyways shadow is gonna have to call it an early nights... so meep moop to the beep boop for the sleep sloops
Wa?!
script call exe that calls script?
Stay up 4 more hours!
Infinite script calls!
Early! Nite shadow. 🙂
Alt, you monster
shadow needs to be up by 06:00 tomorrow to get everything done before taking the train
Ahhh Night night!
Dream of cheese shadow. 🙂
thnks mate
yayy it worked
uh oh
Taken.. a little late but better late than never.
You don't have to. About 70% of the content is free.
ig fair enough, but it has some benefits
Yeah.. you get to run ab for more than an hour per day.. but if you use a VM then you don't have to worry about that. And VIP VPNs..
Some cool rooms are sub only as well but most of the content is free.
I stopped using HTB honestly. I like THM more. I'd say try both and go your own way. 🙂
i honestly been in cybersecurity and hacking for like the past 1 or 2 ish years and only just forced myself to use tryhackme or similar😂
alr thnks man
HTB has academy now.. or whatever they call their learning progream. I believe it's all paid content though. I've always just booted boxes and hacked them on HTB. THM offers more learning content and I like the style a little better. My opinion..
@boreal scarab im 80% ish done with this one on K1C
https://www.printables.com/model/49387-x-303-prometheus
alright, i have seen that tryhackme is more of a theory based learning platform compared to hackthebox which is more practical, and less free xD
thats nice
hi everyone im new and im interested on cybersecurity do u now where should i start?
i recommend starting at networking
Try some of the intro rooms on the website too.
learn how IP addresses work, the layers of a network, etc etc
god im too tired to recall stuff rn
People Don't Need Those Silly Packets Anyway 
frfr xD
ok tyall
no way the man the legend himself @hasty sand is here
no worries
Guys I was just watching a video abt IPS, if I understand correctly the traffic first goes to the IPS. Is there any attack where its possible to change IPS rules so you basically peeled one onion layer to root right?
@hasty sand is it u from the pic?
I watched the podcast
uuuh lemme get myself a coffee and ill answer🙏
Yeah, I love TryHackMe ❤️🙏
Thanks for the kind words!
Ryan! Will you be at DEF CON 32?
How do you get to your skill level? @hasty sand
Yep!
Nice!
WWW, you're a legend mate! I've been looking at what you've done and well done to you bud
Let me guess, Red Team Village?
Idk what my skill level is, but this is a fantastic place to start and communicate with the community.
🧐 maybe!
Your like top of the top
Like your skill level
Your like the best hacker in the world
Haha def not that but I appreciate it.
Of course lmao. HTB has a booth this year too. Don't forget to say hi!
I will absolutely pop by
Looking forward to meeting
@hasty sand whats ur favorite thing to do at defcon?
Hell yah, I'll probably be between BTV, HTB, Crypto Privacy, and Recon village this year.
just wondering, what made you enter the world of technology and hacking?
Meet my friends, that’s the most important part nowadays. When I was younger I liked the CTFs and of course the talks.
Ya better bring stickers. Can't come to a hacking conference without the hackers drugs, stickers!
Do you think you can be a pentester from just ctf's?
I started at a very young age, and that’s a long story but was always fascinated with computers as well as digital marketing. Somehow I ended up here 😂
I think it takes a lot of things, but CTFs can for sure help.
Hands on practice, imo the best way to learn
imo
Oooooohh thats nice. It can be very interesting learning about how computers worked, every time you look over it, you seem to learn something new. Myself, I went down the pathway thinking, 'I know how computers work, now what are their limits? How easy is it 'break' them? etc'
Yah, best hands on practise, is creating a vulnerable windows and windows server machines while also attacking it with the kali machine
All internal
Sure that works
Now, back to coding my ducky script
WW
Once you get a 7 day streak you can do the AD machines. Pretty hard.. but worth it.
Oh I hate those. Are they still relevant xD
Oh yah. I have a script, plug it into your machine, get all the info, delete power shell history, and I'm gone
(THIS IS ALL FOR EDUCATIONAL) Don't do illegal shit kids
Well sounds like the base concept of 🐤
i have failed you master
@hasty sand are u team CG
👋
👋
What up
Hiya Tim. 🙂
Need a site to host it? lol
I has site. But 1 site I has no want work
Jesus @normal fable That script, there is no delay, just back to back to back to back running
insert rickroll here to your script. 😉
I can do that!, uno momento
Oh no.. I'm feeding ideas to Matt... and I'm probably gonna become a test victim at dc. lol
that's kinda dumb
Noooooooooooooooooooooooooooooooooo
Yes
I just took an image of my Windows machine.. so we can blow it up a little. lol
GUI r
DELAY 500
STRING notepad
ENTER
DELAY 500
STRING ROFL:ROFL:ROFL:ROFL
ENTER
STRING ___ ^_____
ENTER
STRING L ___/ [ ]
ENTER
STRING LOL===_
ENTER
STRING L \_____________]
ENTER
STRING ___I______I__
ENTER```
lol
Hehehehehehehehehe
I shall bring all my scripts!
MUAHAHAHA
I'll bring a drive with my Windows image on it so we can destroy the OS over and over and over. 🤣
Hell, I even wrote a ducky script to go through the installer prompts for work.. hehehhe
It actually worked, surprisngly
The weekend.™️
Do I have the script written down? hahahahahaha
No.. my dumbass didn't start putting the script code into .txt till way later on
if i need an advice wheres the best chanell to send on
Hell yah. Nice beer in hand
Depends on the advice
do i send it here and you can guide me to what chanell?
so I have just finished my third year
and I took networking/security/network security/ethical hacking/Penetration testing/ISMS/forensics courses in my collage
and i have loved the forensics alot and the penetration but the path for the penetration is so long
so i was thinking maybe getting good in forensics and at the same time learning small things for penetration for the future ?
so i still have a forth year and 8 months training
and I want to have good skills before I finish
I have started with tryhackme and the path for DGIR but most of it require paying like any sub links for tools or windows Forensics 2 and so on
so i wanna know am i on the right path? and what i need to do
and its worth paying right? i just wanna know to focus on what and how to study
If you're a student, you can get a student discount for the subscription
For sure do that.
Getting 20% off your TryHackMe subscription
im! thx
but for the paths ? do i keep like that?
i just dont wanna end up in two yesrs doing nothing
i wanna start focusing from now
Yeah. For learning THM is great.
Forensics isn't my thing, so I can't speak on those paths, maybe @sick lance can speak on that since it is more of his forte.
whats your path?
OSINT
I haven't seen too many data forensics type challenges on THM but I don't actively search for them.
But for general security, I recommend THM. Lots of good info.
oh got you
Nomming on info
where can I ask for tech support if y'all dont mind
Depends on the type of tech support. Having THM Site issues?
i cant manage to connect to the ovpn
Welcome!
Gave +1 Rep to @boreal scarab (current: #30 - 273)
Yep!
yay!
WOOOO
how do i link my thm account w discord
-rep Scrubz, not coming when I ping, tsk tsk tsk
ty

omg.. it blocked by Clyde.. what an a-hole.
but but but... I don wanna nitro... 😛
L Bozo!
I can't even post animated emotes in my own dang server... lol
so where can i send to get more advice on my path? this is general random chat 😂
i think #cyber-and-careers might help
yep. was gonna say. 🙂
i hate openvpn
ok thank you guys!
Welcome!
Wow.. Matt is feeling helpful today. 
Such unheard of!
Who am I?!
hoo? hoo. hoo..
hoooooooooo
moo hoo?
Hoo moo
I've clearly lost it... today.. lol
Today?
can yall help me a bit lol if i dont annoy u too much
i've sent on #site-support
Someone should help you there then.
With? If it's assistance with a THM room, #room-help is the best place.
not with a room, i'm having issues while trying to connect to the ovpn file
Ya gotta be patient.
Did You Look At Chat?
I don't live on Discord?
That's kinda like "man.. I started this stupid nmap scan four seconds ago and I still don't see any open ports" 
12 am house music with your colleagues hit different
Their message I responded to was the first one I saw
Matt.. you know better than to harass a moose...
I thought we all lived on discord?
There's enough text channels in here for all of us to sleep in lol
I call dibs on koth voice chat
I'm all for AFK VC!
They should put some kots for us in rules... lol
I'll snap rule 3 in half and hang Fluff Clan banner to hold it up
i've fixed my problem it wasn't from me it was from thm ig
docker is a container, it is basically a package with the software's operating sys files, used to seperate the software from the base system and to prevent incompatibility issues
@rapid merlin check out gtfobins.
My computer is dead
Noooooo! Jabba!! Whyyyy?
Currently working with a company to see if they can fix it
I think the motherboard has gone
123 find-me st nesw??
Daaang.. bad rap Jabba.. Sorry for your loss.
Time for an upgrade then?
Reminds me.. I have to do my clutch in my subie.. best way is to pull engine.. and I have a EJ257 in my bro in law's garage... so maybe do a swap...
im trying to mkdir and its failing wtf
what you trying to do @latent spade?
i'm trying to install vuls
and as i'm going thru a walkthrough
mkdir: cannot create directory ‘/src/github.com/vulsio’: No such file or directory
i'm getting this
and it worked before
I only recently put an i7 12700 in it boss
the command is cd $GOPATH/src/github.com/vulsio, which worked 5 minutes ago but now it simply wont
omg... oooooohhhh... mmmmyyyyyy.... ggggaaaawwwwddd.... yeah.. you got an upgrade already..
then gopath variable is not set
it was though
and waht it was set to
=/
I've been thinking about upgrading to a better processor...
nd im here with a i5-9400f
I just saw the STUPIDEST app ad in a long time:
App is AI
Ad tells people to put in their name, the month you were born, and the state.......
I'm losing fucking braincells
I'm the king
Go get something to drink, relax a bit. Maybe get some fresh air. Come back and hack more.
🤷
Are we comparing specs here?
+3070 TI
how what ?
Mine is way better, hold on let me get a pic
10/10
too soon Jabba.. too soon.
That is literally my pc
or close enough
neofetch with theme and so on
should this scare me
I'm actually so lucky I own a Macbook or I'd be out of work rn
Are you scared of equals signs or linux terminals?

Gave +1 Rep to @loud marlin (current: #27 - 311)
You can put EndeavourOS on a MacBook.. 🙂
no I'm talking about the "It will take a while for the first time"
but it didnt take a while
Putting anything other than MacOS on a Macbook is silly
it's also tilix, zsh with ohmyszsh and powerlvl10k theme
A while is variable.
I've once acquired a 2008 macbook pro which only had Windows 7 on it, no MacOS
*Unless it's a 2011 and there are no OS updates for it...
holy shit that's wiked, I need that
You are the most unlucky person ever
want
yes i know
it can't be on all linux and so but it can
it was the hardest week of my life trying to install macos on it
🧱
i did it tbh
I sowwy
I know this exact feeling
I'm sad about your PC Jabba. 😦 really am
why is your computer dying
Shit happens
yes indeed
Technology is built to fail.. This ain't NASA...
We came to the conclusion that the wireless wifi adapter was broken
Let the record state, I, Matt, Did not touch Jabba's computer. You all have no proof!
and now the motherboard is fried and it's probably because I did something dumb
how does one fry a motherboard
Oil, flour, egg
yeah basically
mmmmmmmmmmmm crunch motherboard
add a little bit of salt n pepper to it
I was looking for a gif of someone flipping a motherboard in a frying pan.. but I guess I'll just have to video it and make my own gif..
I'ma need.. a hot plate.. junk frying pan.. old motherboard.. and some bacon.
Is Jabba real or AI image gen that was way too fast
All hail Jabba the great!
boo jabba
o rly?
I don't see a crown on your head
😂
Scripted.. totally scripted... lol
Zojja has me beat
Yall can both have crowns.. just... stop arguing. lol 😛
do u drink alcohol ?
smaht
how much is not really much
Well, if I do it's on a Friday and it will be at most once every 2 months
Alcohol doesn't really affect me
Neither 😉
Had too much or just naturally? 😂
Neither, I'm on medication so booze hits like a truck 🤣
Cheap nights out for me, I can have a few drinks before I leave the house and get away with a couple of drinks at a club, mind you I could enjoy the club I tend to go to sober haha
Mind you my limit also went down after first year, I can't get away with ten doubles+mixer and 3/4 jagerbombs 😆
probably, just check the report profile section
Probably under impersonation/scammer
facebook reports don't work
you're wasting ur time if ur reporting someone
cuz they aint doing anything
they will if enough people report it
Reports work on FB...
and if everyone has the bystander effect of "I can't do anything if it's just me so I won't bother" then nothing gets done
so damn slow using wsl on mounted partitions ;-;
Gave +1 Rep to @mossy river (current: #6 - 1267)
are you making a selfbot?
what does "Serverless bot" mean
It's not hosted on a server as such, it's broken down into a series of functions that are called as needed
The functions are stored and executed on a server but they can be put on a shared server so I don't have to pay for a server for it specifically
Nah, it doesn't look to complex, it's just that I'm planning on using pulumi so it's infrastructure defined as code and can deployed by anyone to an aws account
it's also significantly cheaper as you're not paying for a server dedicated to hosting the bot, like it costs 2p per million lambda requests + some for each response but it's nothing in comparison to the cost of a server and anything within aws's thresholds will be completely free
For what platform is the bot?
I'm aware I could probably just read up a bit lmao
Discord
discord, since they added interactions and slash commands it's possible to have serverless bots
Well that's interesting. How on earth is that working I wonder.
You set the interaction endpoint for discord and then it uses that endpoint to make requests to a rest api 🙂
Last I checked the bot had to sign up to an events hub to receive guild events
Ooooooh
Yeah it's to do with the interactions side more than anything
Well now that changes things
That's a huge improvement. Shows how out of the loop I am with bot dev lmao
Currently my biggest issue is:
a. WSL actions on the host partition are so slow that I may wither away
b. Pulumi is struggling to validate my aws session
c. My laptop keyboard's m button is fubar so I have to press it to make it work
Aside from that I'm confident I can make it work, I want to do some automatic student verification for our society and had a proof of concept that used email aliases
Why pulumi over terraform / opentofu? I think we've had this conversation actually
I've used it before with work and it works really nicely with javascript and typescript so I don't need to use yaml
Fair enough 🤷♂️
as it's a typescript project anyway it made sense
I mean, the new callback design makes that all very easy. No reason at all for this to not work.
also out of curiosity if you don't mind me asking, how did your soc verify student ids? I was thinking I could use email aliases for ours because we can do id@domain to send an email
Guys, what exactly is a name server ? And is it the same as a DNS server ?
Email aliases in what sense?
exactly, and the student union were interested in a way of verifiying students for the discord so if I give them IaC and instructions for setting up an AWS account they can manage it when I hand it to them haha plus it's dirt cheap so it's easy to justify
Like we can use name@domain for email recipient address or we can use the alias of student_id@domain
I suspect you've got a similar idea. I set up a site which asks them to enter their student ID. The bot then verifies that against the uni exchange servers and sends them a TOTP. If they enter that correctly, it dynamically generates an invite and redirects them into it.
Yeah, exactly that
Ah mint
The most complicated aspect is the mail service there. Email is a pain in the arse to work with these days
So the way we did it (because we have a soc, discord url on the su page), the bot actually had two commands when I first developed it, email and verify, one sent the code to email using student id and the other took the code and gave your role
AWS SES 😉
if I can get pulumi to play ball ofc
The technology is still simple obviously, but getting past spam filters is a bitch and a half if you don't want to pay for SES / Sendgrid / whatever
Yeah but the student union said they'd be interested in hearing me out as I said other socs could also use it haha
and if I can make it dirt cheap to run it's even easier to push for it
Remember you've got to manually apply to get SES put into production
yeah, had that with work but that should be okay with a couple hurdles
Fair
what is the port 85 ? i cant find much on google about "mit-ml-dev"
Then yeah, that should do it.
Also need to check that your uni mail servers aren't going to throw a fit or reject your lookup requests
You don't really want to let people just spam your email send function
.
yeah so originally I just had a settimeout for the user and a collection to ratelimit people etc. but now I can set the apigateway ratelimit instead which is nice
Don't bet on this btw 
You will end up deploying it for them. Your typical non techy will not manage to deploy it
Wait, will that not rate limit the whole bot?
thanks i still don't understand what mit-ml-dev is
that's fine, as long as I'm not paying haha
Valid
Depends how I set the ratelimits, I could also use dynamo db for specific functions ig
not sure exactly how I want to do it yet but I'll figure it out once I've got a dev version working
I'd be careful about setting an overall rate limit on Discord. That turns it into a DoS scenario rather than a resource consumption scenario
At least it's cheaper though 
Absolutely yeah, it's something that'll require some thought, I can also probably set some stuff on SES to control it
and potentially need to look into how to handle bounced emails so it doesn't happen again and ruin the email rating because AWS get a bit hissy if you ruin it too much because it's their IPs
@pallid lotus is in the house 🥳 How are you? 👋
I'd suggest just tracking individual usage of the command honestly. Key value DB store (e.g., Dynamo) with Discord ID as the PK. Set an expiry on the key:value pairs and do it that way
There's probably a more efficient way of doing it than that, but meh
Absolutely shattered mate, and you?
looks alike machine learning
Go to sleep you silly goose
Yeah that'd be the best way I reckon
apparently it's a port i can access a web page on
You can't make me! 😝
I'm really in the wrong place to be doing dev work atm 😭
It's named that but Apache uses those ports, iirc
Correct, I just wanted to call you a silly goose
God I really am tired
I used blobfingerguns rather than blobno
That conveys entirely the wrong message.
I'm currently back at my parents so I don't have my monitor and am stuck on the laptop with a dodgy key, I could fix that or use the keyboard that's about a metre away; however, then I wouldn't be able to complain about it and I'd have less space on the small desk that I'm currently using
Me too, and organising a moving
What is your reason for staying up Mister
Port 85 tcp/udp information, assignments, application use and known security risks.
That reminds me, I need to replace a switch on my laptop keyboard. Cheers 😆
Force of habit
That and I need to shower and walk the dog
Thought you walked the dog at 10 tbf
I did
I wanted to go home tomorrow but my brother's prom's tomorrow so it's on the sunday which is annoying because it's my final day off before I go to work, I've been getting filthy helping my dad with a land rover he got recently and cleaning the garage
Shower dog and walk. k. lol
She's getting another walk because she's not feeling well
He got an old ex-MOD landrover which I've been helping him strip down, and right now my hands are filthy because I've got 2 days of oil and muck on them that will not wash off no matter how hard I try 🤣
Fun project though
for sure but my once black jeans are now brown 🤣
Not rest? Lol
the shower is for you or the dog? 😂
for ppl around him and dog
Tell you what though, that car is strangely mechano like, it literally is some bolts to remove the wings and the bonnet lifts up and slides straight off haha
That's a project
doesn't drive or have breaks right now but we took the bulkhead out yesterday so we can get the rust cleared away and weld some replacement panels in
I have a 78 chevy I need to put a new wiring harness in.. and do a lot of body work to..
rest of the cars in good nick though tbh and all the parts are there, what's cool as well though is it's 24v as it was designed for fitting radios easily
I mean in fairness this is about 50 years old this car so it's like building and disassembling lego haha
Yep. It's a cool older car. Love it.
honestly, in a day we'd got the entire front body off it
we removed both wings, the front grate, the windscreen and the bulkhead in <6 hours
I'm gonna have to do a lot of work to my truck. It needs a lot of tlc.
It was a bastard to get in the back garden though 🤣 barely fits down the side of the house and trying to roll 1.7 tons up hills with three of us was fun
But.. I bought it for $2700 and have been offered $30k for it in the condition it's in. lol
Fair play man, that's really cool 😄
yeah it's definitely fun but I'm finding that every time I visit my parents I get filthy haha
was saying though as well, whatever undercoat the MOD put on it's insane, it was everywhere and when I was removing some of them from the bolts and the surrounding metal, the paint still looked brand new
Me lmao
Not my best formed sentence, I concede
That was my hand after only pushing the land rover in 😂
It's got a hole rusted in one of the doors bigger than my fist, the bed is all rusty, the lift job wasn't done right, transfer case is grenaded, leaks oil almost faster than you can pour it in.. lol
2020
Lots of work.. lots. lol
floor pan is rusted almost completely out too..
you still access to pet tax, the discord demands tribute
pet tax! pet tax!
those square bodies though.... I've been looking for one for awhile, but out here they all want 10k for a drivable one
Yeah. They're spendy af these days.
You can't touch one for under about 20k that runs anymore.
out here anyway... huge vintage car scene.
yeah similar here with the bulkhead
Well.. I think I'll just order a whole new floor pan and get out the wire feed welder.. need to re-up my body skills anyway. Should be nice.
it should be easy to fix because we've got it off so we'll clean it up, strip it and weld it but I was saying it the MOD put some undercoat on it it'd have been in perfect condition still 🤣
absolutely, it's part of the fun as well
Thin gauge steel like that tho.. def use copper backing. lol
I would, but she's not looking her best right now. Autoimmune condition means a few bald patches, which she's none too happy about 😦
yeah, how easy's it to work on? does everything tend to come apart as it should?
I'll have to do some practice welding.. it's been a while.
what is extended passive mode in ftp? it just stucks my commands
i blame the pandemic. Seems like everyone bought a project car and ruined up the market
Everything comes apart pretty nicely. It's pretty easy to work on.. if you don't mind being in the engine bay. 🤣
I've never welded before, would love to try it at some point, there's an arc welder and tig over in the garage at the minute
sounds like the poor pupper needs all the adulation then
Cmon, I posted a damn rock lol
I couldn't get round my dad while we were working on the land rover yesterday and just crawled under the car (it wasn't on jacks) 
Take a class or two. They might have some at a local uni.
We can send virtual good juju through the picture
Yeah I'll have to take a look
remember to backstop on that thin sheet or you'll burn through. You going to stick or mig or tig?
it is mode. you can turn it on/off by tipe passive
Unlikely for a uni, there are a ton of good vocational schools over there that are state sponsored though
Gonna do mig and yeah. Gonna probably get a copper block for heat.
Hell I might just get some scraps of steel lying around and give it a go as well tbh
remember to flat weld everything. vertical is goingto make your life a nightmare
Most of it is gonna be flat. I've done a lot of welding in my time.. used to do it professionally. lol
and i'd worry less about heat and more about blowing through the sheet
Just gotta set the rig right and make sure I don't burn through that thin gauges steel.
yeah
smae thoughts. lol
i can do tig and oxy welding pretty good on thin stuff, but stick and wire feed is tough
I've actually never done tig.. but I do want to try it. Done a lot of oxy welding..
Fine art.. love it.
yep
This is the current state 😅
one of the welding tests, i had to do 3/8" plate butt weld with oxy
omg..
that was one of hte hardest
That makes sense. Seems like evryone has an arc welder these days.. but not many people know how to use one. lol
i have a really small 110v arc and a 110v flux core setup
i've thought about getting a tig want and bottle for the arc, just can't justify the cost
Unless you do it all the time for extra income, it is quite expensive.
Is there any advantage to the bottle though?
you can do it all gassless can't you with the right wire or sticks
Trying to get into RE so should I learn assembly to get started?
for sure will be of great help
Great just gotta figure out which assembly language to get started on
I "learned" welding in HS
I got pulumi to work 🥳
It wasnt official instruction, the shop teacher just had us learn from a kid who said he knew how to weld
better than our uni teacher teaching how surface mount chips can be desoldered for forensic analysis
he was a pretty useless teacher and wasn't using proper technique, left the hot air station pointing at the chip and went on a tangant and then had a go at the class for not telling him the chip was smoking as if they knew what it should look like 🤣
Nah, it's still illegal
it's not really gray hat if it's actively causing harm
tryhackme states that taking out a scammers site is gray hat
Rule of thumb if you have to ask if something is legal probably isn't
morally, i would say that it is grey. Ethically it is not
It's vigilanti stuff which is illegal in most countries
wait
morally and ethically is not the same thing?
They are not
lemme see if its illigal in my country
sry english is not my strong
Regardless of the legality in your country, the moderation policy is based in the UK where it is illegal
he's definitely going to listen to your advice
Two wrongs don't make a right, there's proper channels to go through to make sure it's correctly handled
i cant do it anyways
like, skill-wise
My opinion is that it doesn't exist.
You either hack ethically or you don't.
It's really silly to create all these different hats for different stances.
i mean... theres 3
but ok
No there's not lol
My silly coworker calls me her work husband.. lol
on tryhackme btw
Grey hat hacking can quite easily just be classed as blackhat with some moral greyness, the thing is vigilantism is effectively taking out any of the proper legal channels involved like judge and jury and means that it is not only illegal but unfair as you're deciding your own punishment instead of going through appropriate channels
its grayhat though
i think
Simplest explanation is, grey is a shade of black
tryhackme says its gray hat
not a shade of white
(i wont do it i swear) but would i be looked at wrongfully if i did
As someone who work in security, if an employee were doing that we would have to turn them in to LEO along with any evidence we saw that they were doing that from the work computer
yeah but if he told you he did it on his personal time and personal pc?
is it ok for my netcat to listen on 0.0.0.0 ? i cant get any reverse shell running
like, not on work
Additionally, if you are actually trying to combat scamming, your best bet is to leave it to law enforcement. Because it's really easy for amatuer investigators to contaminate the investigation and evidence, making it completely unusable and 'poisoning the well' of any ongoign investigations
What about us brown hat hackers?????
Depends on who I guess, anyone with an understanding of the importance of our legal systems would frown upon it, joe bloggs anti-everything may well agree with you. It depends on the individuals stance on vigilantism but at the end of the day I think most people within cyber-security will agree, while the legal system's slow, it's important and you shouldn't take it into your own hands
"mericaaa
lol
yeee hawww
howdy partner
i would have to report it to my manager and theirs, it's not my place to decide if they pose unacceptable risk to the company
if you found out your friend did it
Not only contaminate, but also potentially be wrapped up by LEO as well
would it affect your general view of them
There's also a lot of terms in most contracts that state about doing anything both inside and outside work that may well bring the company into disrepute
Well, they aren't acting ethically. So yes.
is it normal for nc to listen on 0.0.0.0 ? or am i just too fried
That's the default interface if you don't specify one
so you think people like scammer payback, which gather info and give it to the fbi contaminate the well?
damn okay man
I'll ask one question and it'll help you understand everything, why is the legal system important?
brother
look at people like nano baiter
they get into the scammers pc and send all the files to the fbi
I have a phpbash and i'm trying to run a python script to reverse shell so i can get access but after running the script nothing happens wtf do i do lol
It's not about that it's about understanding why it's wrong
that is not legal, but the fbi accepts it and uses it
Those are almost always fake/faked
because it's already done as well
LMFAOOOOO
NO SHOT
scammer payback is fake? damn says who
I would say that most of the scambaiter types are re-enacting at best. If they are actually broadcasting them doing harm to a system they don't own deliberately and maliciously, it's prosecutable.
ik why its wrong
yeah but they actually do take down systems
and they partner with anydesk and paypal
and even banks
doing illigal stuff can be justified
nop
Scammer payback and Jim Browning are kind of a different category as well - because they actually do work with law enforcement in multiple companies to shut down the scam centers. It's not apples to apples.
oh
so thats not brown hacking anymore
okay so i would need authorization
what is this nc argument 😭
The legal system is designed to enforce standards for evidence collection, integrity and thoroughness as well as to ensure fair trial and punishment.
By going about it yourself you're risking destruction of the evidence, preventing fair trial and punishment and you likely aren't going to be as thorough as someone with standard operating procedures.
People doing those sorts of things on the regular are likely being permitted and likely have to follow certain procedures for evidence collection etc. before they mess with the scammers
yeah but the thing is
india dosent do anything
They do actually have a page for reporting those things
by at least changing the website to warn posssible victims that could stop victims
... corruption
Well, that's its own problem that wants fixing, wrongs don't fix wrongs
False
https://www.businessinsider.com/scam-call-centers-crackdown-raids-india-microsoft-amazon-2023-10
They have done something
okay so you take everything litteral
It's whackamole though
I'd also argue that if you take down a website they'll just spin up another
76 locations isn't much considering how many scam call centers are in India
same thing if the fbi does it though
The fbi do more than just seize the website


