#general
1 messages Β· Page 284 of 1
ππππππππππππ
I have 0 idea 
all g
x is the parameter and if the developer allowed extra parameters then you can take advantage of that sometimes
a
Wake up samurai
That looks like a URL parameter.
to my understanding u use it to ignore the rest of the url u arent trying to request
IDK about your specific case.
Usually, these are used to pass extra values to the HTTP server.
http://url.example?a=1&x=2
when would u do that
/myprofile&photo=1
For example when you have a dynamic search function on your site.
Here's what the URL looks like when I do a search with the Brave browser for the word "test":
https://search.brave.com/search?q=test&source=desktop
^^^
This new machine is so really cool, i love this box hahaha
-# This user is currently under investigation by the Federal Bureau of Investigation Β· Learn More
How did you do that 
hello, im trying to switch to kali linux (not a dual boot) but i have some issues.
I installed the ISO files, and i tried different ways, with rufus and ventoy.
When i boot on the key, then select graphic install, nothing happen. I tried reinstalling the ISO file but i dont work.
Do you have any ideas what the issue might be ?
Basically:
https://search.brave.com/resolves to the IP address of the server you are talking to/searchis a file or function on this web serverq=testis a parameter given to this file or function so it can do its job.
thanks bro
please π₯²
I honestly would recommend a virtual machine over a dual boot.
Usually it's not recommended to run Kali on hardware. I'd suggest running it in a VM. kali.org also has lots of info on installing and setting up Kali.
Apart from that, we have not nearly enough information about your setup and ISO and so on to know what could be wrong.

Heh, he pulled out the new trick.
what is this bois
ah isee
scared me lol
I thought FBI upto people in public
π
Help is this a new kind of scam? https://cdn.discordapp.com/attachments/279715063902896128/1260665260541743125/4fb1df19-f72c-48b8-a8db-e4a8cb4c6d91.png?ex=66902584&is=668ed404&hm=aeb19ad5aa1e7d8cc4ca97243e5464eac83d8b60f2ce68be3a3469f23f8ff2be&
https://cdn.discordapp.com/attachments/279715063902896128/1260665260243681511/image.png?ex=66902584&is=668ed404&hm=50af0630d1f3771875b7640f5f7f4709404bd0815e72ff10e19dadc1ab34d08f&
that learn more link made it look more legit ngl
Not new, yes itβs a scam
Hi everyone, It says in Splunk 2 room that is the part of blue primer series. Do you know what that means or what is the blue primer series?
That's now a new kind of scam, but it nevertheless is a scam.
Yeah
Ohh I see thanks bros
The whole "I accidentally reported you, help me explain that everything is alright" is a very old scam.
Be wary of it.
Usually saw it on Steam.
https://youtube.com/shorts/JlO9H9KbeKI?si=796wkC0crzHRfFdV
Damn Ryan keeps finding a way to sneak into my reccomended
Do you use βautofillβ? If so, Iβd look into this. Stay safe!
Thanks for your wisdom oh great sage council bows
You're too late, seen it already.
Biiiit.
Why do you have russian in your bio?
Because I am, in fact, learning Russian. ^_^
And I have to flex the few words I know.
How are you?
I was trying to read it. lol
I see Ryan has found a way to sneak into your reccomeneded too
Haven't used my Russian language knowledge in a long time.. so rusty. π€£
My whole profile reads: "Hello (formal). I did not ask. Cry about it."
Without power, hungry, slept loke shit and my back hurts despite a 400mg ibuprofen.
So the ususal. Yous?
Maybe it's because of the ibuprofen. ;)
Just kidding, that sucks.
If that were the case, I'd request a new spine.
autofill 
I'm kinda ok, still got a bunch of stuff to do and I really don't want to.
Heh, at least you can read it.
Hello bit 
It's going haha, how're you doing?
Well.
This.
Fine, apart from that.
ah, I see
I also still need to proof read and upload the writeup for my room so I can submit it.
I've been sitting on the damn thing for like half a year by now.
Anyone here know the game OpenTTD?
Kind of a banger.
Also straight up part of the Endevaour OS repos. xD
nah not today
booooo
what's the game today?
England v Netherlands
I wanna watch that game...
Watch it then π
Itβs on itv rn
Foul already rofl??
Lmfao
Wasn't looking ahah
Just another gentle tap that supposedly vaporises the other player into dust
they're just so strong
They got too cocky
Mate youβre infront I thought you meant England got too cocky then π€£π€£
Yeah we're cooked
good morning
BREH
well, eavning its 1pm here
screw this crap
Euros 2024
thank you! I just skipped this question and wanted to finish this room.
Damn what a goal
the ISO im using is this one https://cdimage.kali.org/kali-2024.2/kali-linux-2024.2-installer-amd64.iso
setup (laptop)
Processor: Intel(R) Celeron(R) N4100 CPU @ 1.10GHz 1.10 GHz
Installed RAM: 4.00 GB (3.83 GB usable)
System Type: 64-bit operating system, x64-based processor
We're all talking in the thread if you wanna join
jabba
can you make a "note taking" thread?
lol macos waits 21 versions to implement an official window manager
15, but yes
If you can get 10 upvotes on this message without spamming or begging, yes
i was just really happy so everyone should move on and ignore that
What would you want to post in this thread?
how to notetake and how you all do it
Sure, I'll upvote that.
lets goo
halfway three
there*
Where do i link my discord token ?
@remote jewel
ty
@sick lance π
idk.... looks like +4
or +3 when you exclude self-votes
+3 is about a third
2 more votes
i had so nice day... then i get this...
cmon ppl
funny picture they chose tho
wanna know something funny
Hm?
ye?
~~ mods can remove reactions from messages ~~
And if they do, they'll get in a lot of trouble
rules π
Technically I only said 10 upvotes so sure
dev are you against that?
@mossy river it's at 10!
nah it's at 11
Note Taking
lets gooo
sin agains humanity
i wish i can comment something sarcastic... but better not... jabba will ban me asap π
i forget how many until it yells at you to make a thread
I would think maybe 10?
oh god that might take a while then
I got no more work, I'm just chilling!
apparently one thread can only have a maximum of 1000 members
Blasphemous!
..it did used to prompt us to make threads on this server, right? don't wanna mix it up with another one
I think so? Unless Scrubz broke it
Normal members can't do it
It's only admin, mods and Mentors.
damnit, scrubz broke it
Scrubz broke it again!
He would!
wonder how many we're at..... time to count
Yss
i will never look at you the same
looks like 12 total 6 each
the perm must've been changed at some point
you... you downvoter
I blame @sick lance !
i upvoted too tho so π€·ββοΈ
oh
welcome to the club then
you did help me setup obsidian... hmm
nah, only mentors and mods have this perm
ngl am disappointed
nah it definitely used to be like hey you've had a ton of replies going back and forth you should click this button to make a thread so you stop flooding chat with your nonsense on this server
Pretty sure it's been restricted since the permission came out in this server
That would be possible
I is too
maybe if we do it enough it'll turn back on

You should totally make me a mentor, and I'll just totally not create threads..... nope
Not my decision
you can't ask for yourself to become a mentor you'd have to ask for someone else

Someone find the on button!
@boreal scarab dm-ed me and asked me to forward his request that I be made mentor
I did? You're right!
have we actually had any new people given that role recently?
thought that was scrubz again
scrubz likes that blob
particularly when replying to me apparently
Hi verum π

Matt! 
Last role for mentor was Hydra
hola vain
oh wow omega is still a mod
when was his last message............
You didn't read that message did you? π
actually not too long ago. 4/8.
Sorry LEAD mentor
Whatever happened to lorestil?
Yes, is different
Yah, one has the word "lead" the other doesn't 
does lead actually do anything --- like you mentioned apparently not choosing who gets the role, sooo
idk what else
@sick lance became a mentor in August of 2023? Jesus..... Why? 
just because you don't see anything doesn't mean nothing is happening
Happy almost one year anniversary @sick lance
I was voted in.
Not voted off? Rats
well yeah, but also not always the case
that's why i was curious πΆ
and shadow will probably never be voted in :P
I already know for a fact I would never be voted in lol
ya know what i don't get
why do people star forks on your github profile rather than the actual project
people are weird
i dont star things
You can star things?
wait those are different???
my god
where was the "github needs to put a link to the .exe" thread?
someone posted that
it was funny
that was me
a) people failed to see it is a fork
b) The fork has implemented some changes that the main project does not have
the one that mentioned the sherlock project??? which is a terminal based app???
idk
ima be real my attention span is bad
adhd + negative iq = not being good at remembering stuff
first one makes sense in these cases
to answer for him - yes
if your iq truely is negative science would need to study you
it went over the int limit
wrapped back to -
reverse ghandi-ed
Suffering from success.
good job chat is dead now
you mean it was 255 and then it added one and now it is -256
thats what google said π€·ββοΈ
I'll take my paycheck and leave then lol
we will pay in exposure
we have 10k followers on insta
ure welcome
yeah those are int 32 numbers... shadow went a bit backwards and tried to do one with 512 values instead
which would make more sense for iq numbers
anyone know where muiri is
@pallid lotus
scotland, probably
should just use bool
today on nerd stuffs: https://www.youtube.com/watch?v=wMm11lzsXM0
Discover the scandalous history behind these marbled LEGO bricks!
π SUBSCRIBE for more LEGO videos
π Leave a LIKE if you enjoy
These special LEGO bricks may be beautiful but their history is quite the opposite. Behind these LEGO bricks is a rich history and countless stories of scandal, curiosity, and rebellion. LEGO absolutely despises these b...
@chilly veldt β¬οΈ look it is danish thingy
also look look it talks about scotland
i agree
anyone have experience with the AWS Cloud Institute? Is it worth it. IT's a year long assuming full time schedule
I have experience with burping while using burp
cm oin NL... let's win england π
Scotland
omw there
π¦
Awesome. Head into Glasgow and find a group of guys in green shirts. Tell them "Rangers Rules". They'll make you feel very welcome β₯οΈ
literally evil
you all want me dead
fracking england =/ heeh
Anyone watching the euros tonight?
I think there's a thread for the game right now.
oooh
How to you put a thread?
It's not a #.
it is
you can copy hte link to it. It's like a channel:)
I see. Just thought there was a special symbol like # or @ for it.
Goddamn engerland
i agree
I am quite annoyed. I missed the last step on Friday with a cooler and fell. My knee still hurts
Coworker: "Wow. You're an Adobe guru!"
Me: "No.. I just know how to use google."

just don't let them know that you do same thing for excel and so π
I don't know excel at all.. that's not my area. π€£
hence the google part
Shhhhh!!!
to be fair the kids these days are on GPT
GPT gets it wrong more times than stack overflow... π€£
if chatgpt feeds of stack overflow, all hell will break loose
chatGPT π
It does
istg ure gonna ask it anything and it will just say "duplicate question"
oh no, it started
r/programming 
Reddit too. So potential for degeneracy is real
the reddit part is always fun
you have all used geminy?
probably hit 4chan as well
one guy asked him what to do if he has depression, gemini suggested a rather doubtfull cure
Yeah don't
nonono
And it wasn't gemini. It was new google feature under search
oh
shoot mb
i thought that was gemini
Google search AI is absolutely rotten.
Gemini has been alright the few times I've used it.
does anyone rather use gemini than chatgpt though?
i use claude mostly
Hmm, I mostly use jippity.
I should install the copilot extensions for nvim since work offers me licensing.
Congrats π
have you seen the letter that ex-openai employes wrote?
ty
Gave +1 Rep to @pallid lotus (current: #9 - 778)

the disapearing hedge of mystery
Hmm, bigger token limit I guess?
its not even that much of a difference though
ollama is free and open source and self hostable
oh
damn
this new apple AI feature is fun though
not out yet, but we do have some previews
I have a tab with ollama open somewhere. I stumble across it every few days.
Not in my experience.
Probably skill issues π
Β―_(γ)_/Β―
Nah I"m just using 3.5 free through the web interface because I'm too lazy to configure copilot π
I just assume my success comes from the fact that I don't ask it to do anything I don't know how to do myself.
So it has very specific instruction, and just fixes my broken syntax.
I do want to play around with self-host though.
I have access to significant enough hardware.
You are broken syntax
Exactly, the name is intentional and descriptive.
In my experience it sucks balls any time it misses the whole project context. If code is modular and distributed enough
also known as shadow can't just randomly watch 10 min videos to figure out if they work similar to how shadow did it
But I have a 15KW power budget in my rack at work, and a stack of unused MI250 cards.
Yeah, I just ask it to complete individual functions for me; and even then, I'm sanitizing the heck out of them, so I have to then re-write them into my actual code.
Yeah, i often rewrite after it a function or a class. Which negates most of time saved
But helps with saving brand bandwidth
It's true.
*brain
using this one: https://ollama.com/library/dolphin-mistral
What it excellent at for my usecase....
Is explaining shitcode of others in concise way
artifical idiot explains shit code
just watched it... yeah basically the same though shadows model is smaller in params
Travis scoot
@crude stump best thing from corey taylor
https://www.youtube.com/watch?v=Q5OLtoY70AI
that song live rent free in my head
Lmao imagine going to a club to listen to some rave music or something, and the music artist makes you sing SpongeBob SquarePants
and when you realise this is singer from slipknot hehehe
Can we build a model to detect the intent of a prompt without fine-tuning a model and using a dataset?
Lmao
Thatβs even better
yea
Are you talking about LLMs? Also, is this homework? Question is kind of structured that way.
might @mossy river or @shell nova can help
I think @sick lance
Hello guys
how can I revert from tryhackme bot chat from reporting a bug to one option back?
I want to create a ticket but not for site bug
you can #site-bugs ot #site-support place
just be sure that you do not reveal some sensitive info if so
no no I don't wana report a bug
just a misclick
I want to report my streak didn't update today and I lost it
yes I can, but every time I should clear cache?
send email to support. with amount you have/lost with username you have from thm mail ofc
and have some patiente π
ty
talking from personal exp heh
cache clearing didn't work π
nah. then just email. best thing...
they have tons of email so 3-4 days. you just continue to work on strikes and so and they will add to it
@jagged moon Started my resilver 24 hours ago..... it's at 76%
matt... want to see something ugly =/?
Hi.
hi hi
Any professionally experienced folks here to answer to my question in #cyber-and-careers ?
Give them some time
Good morning all (:
where dheck you live when is morning π
Oceania haha
heh
do you come from a LAN down under???
That is a good one haha, that I do.
Haven't I seen your face before? π€
Joking, joking lmao
Iβm just ioking
ioking
Funny interaction
ugly no retraction
can't be mad on @boreal scarab he help me to print handcuff's key π
what is this
yep
bucket seat?
car/race alike phone stand
its a deep seat that racers sit into. its deep so it holds you in the seat well and supports your helmet
Itβs a cel phone tower o_o
question, can you attach wheels to it with a motor?
Yeah I know about that
how much $ in filament do you think it cost em
watched a yt vid on that
full car... a looot
I still question this lol
Still can you print a phone one?
me same... in my defence... i was drunk
yep π
You wanna use your phone, too late. It's driving away
ppl make hexabot with printer also heh
i guess its better then buying a whole lambo
exclude a the whole
the
did you 3d print handcuffs or somthing
i needed a key... handcuffs i had... kinda
not gonna ask
yea... better not...
if that was public on thm... was def something for #764491023127674910 heh
permanent?
yep
big hero six?
When you purchased or transferred a domain, you paid for one year of registration based on your domain ending, like .com or .org. You'll be charged a fee to renew your domain registration each year un
How?
check link
there is a renewal fee
or you can get server for like 15-20 month
ima buy a nasa super computer
anyone know why does the KOTH section not working?
whats not working
it doesn't allw to send messeges
you gotta verify
@spice topaz
my wifi sucks
You can't rep yourself. π€£
let a man dream
+rep @crude stump
Gave +1 Rep to @crude stump (current: #92 - 74)
coming in clutch
-rep @crude stump
wow
i see how it is shadow
+rep @crude stump
Gave +1 Rep to @crude stump (current: #90 - 75)
damnnn
oh...
double rep
thought that would work to show your current rep
skill issue
+rep @crude stump
Gave +1 Rep to @crude stump (current: #87 - 76)
hmm.. interesting.
lets anger the moderation team by spamming rep points
btw... @buoyant tree @crude stump glow-in-dark
It works with +, not - or /...
thx guys for helping me out
for reasons shadow has not discloused yet that is obviously a joke
yoo thats awsome
glowy mushy is not swallow mushy
mmmhmm...
the mushrooms with the green bottom is cool
back mushroom looks a lil sus but ill let it slide
they look marshmallowy..
guys anyone would like to play?
i run out of one and put 2nd one
thought you did it on purpose to simulate grass
nah
give a man a rep and he well praise you
this shit happens only in tryhackme server
lmfao
I might delete my Google and Youtube accounts. I can't stand americans popping up on my YT feed exploring our favelas like zoos.
imagine pulling this move out at the club
i mean go ahead?
I see that George Hotz is never logged in in his YT account and Google account.
i can slice in half and stic outside window π
I wish I could see the back-end of Youtube's recommendation algorithm.
have you ever thought about it as, they are bringing light to the favelas
What exactly would be that "light"?
the negative stigma
The stereotypes about favelas are true for the most part.
smurf? or just random
It's too visible to not become a complete truth.
The rest of its culture is basically local-focused, not anything anyone outside it needs to know (i.e rules, convenience, etc.)
you could always block the youtube channels
dont they also have a not interested button or somthing
Youtube's algorithm is smarter than that. I block something that makes me >react< and they will feed me more things that will make me... react.
i guess the only option is to not react and scroll past it
forest gnom
the tooth fairy is fae propaganda to teach kids it is is okay to trade body parts for money from fae
wait.. is that how we get kidney money?? 
@loud marlin HEY, need to run an idea pass ya
sure thing
So, got 300 laptops I need to enroll. already got 1 ducky, what about buying a second ducky to up the pace?
i think you can use lan hub to connect all laptops
if that help
like install windows over network thing
pxe boot type?
Why not use PXE and IaaC?
or mdt...
You should be able to make an ansible playbook to do it all
English
Network boot, and use code to automation the rest
its funny because nmap level 5 is called insane
and it is now past the 02:00 time on the clock so shadow is gonna go poof into the hay for the sleep sloop to the beep boop while they meep moop
Me after deleting production servers
@spice topaz hey can u plz not send friend request before asking?
Ik
+no creep
Im just messing around
π
Kk chill bro
I was just serching for someone who can do KOTH with me
@clever shard ok ok bro chill mb
Btw ur the one who used bad words i didnt
Sorry if i annoyed you
@rapid merlin i am fun HAHAHAHAH
@clever shard shoot i forgot to ask you, sent it a while ago though
nah but we good
brother was salivating at the pfp
yes for quit begginer path and no for complete it
:8ball: Without a doubt
yes or no
:8ball: Very doubtful
I feel like im stupid
I dont really use discord that much
And im learning new stuff
I think there is a point in thisπ
Btw how long have u been learning this stuff
I'm Curious
mmm
like 2 months if im being generous?
Wsp
whats down
average disposable income
yo product is hydra supposed to take a million years to find a password for the exploiting ftp room
idk about that room but what's your wordlist
rockyou
its literlly on its 2100 password
am i supposed to stop it or does it stop on its own when it find something
finds
many of the rooms seem to use pretty early words in the list to make it not take a millennia -- hm
ikr its weird
hydra -t 4 -l dale -P /usr/share/wordlists/rockyou.txt -vV 10.10.10.6 ftp
except i replaced the ip with the given machine one
They need to add a room on how to make a mod menu for gta v
that would never happen lol
thats cheating lol
it's actually showing attempts as they come right -- do they look normal
so weird
ill let it hit 4k attempts and then im stopping it
Does Hydra stop when a password is found? By default, it doesn't unless you specify the -f or -F option
i thought it might stop automatically but apparently not
omg THATS WHy
been a while since i've used it
BRO
already found huh
no
the command is wrong i think
its saying the user is dale
no the dudes name is mike
not dale
why would they give a random ass name for the command
keep ya on your toes
watch it be like #3 now
Can raise your t flag higher for faster search
π
how long did you wait before
2100 is a bit deeper than 4 lol
30 minutes
something like that
all i know is i wasted my damn time trying to find a password for a unknown "dale"
mike aint a very smart dude to make his password password(Mike is a imaginary dude)
The joys of tryhackme am I right

yeah but it does print
the correct passw
why is it called insane
I guess because itβs super aggressive
ayo morning
hmm
What ? Y u mentioned me ? Here
How do I hack
what do you want to hack?
morning
Good Morning.
Good morning
bep
IΒ΄m with very problems.
That doesnt sound great, are you alright?
No.
Whats up
I think someone entered my discord account, simulated as if I had asked the ex of the person I liked who had asked for nudes to publish them to hurt her and that and the community staff didn't even listen to me and I think they entered for the token because I didn't receive an email and it went through V2E.
And the guy didn't even leave a trace.
I tried to find out in every possible way.
You understand?
i thought it shows up in big the password?? i mean idk if it updated anytime since last 2 years
You should be able to check devices that are logged in. If you think your token is compromised, reset the password and use the 'log out of all devices' option to invalidate the potentially-stolen token.
I try.
But donΒ΄t show.
Whoever did this is a professional.
The discord send to me this.
F i donΒ΄t can send images.
:I
In short, discord said it detected movements on my account.
Revoke the token, work with discord support to secure the acocunt, such as with MFA and/or SMS verification.
There really isn't anything we can do more than that to help you.
I understand.
I go try to discover who enter in my account.
You can give me opinion?
How can I do this?
Without committing a crime and doing everything legally?
Ok.
If anyone can advise
#room-help message
Having problems with the Exploiting Active Directory and would like to reset the instance
Oh, yeah. I'm everywhere.
everywhere, nowhere
that's the one π
Haven't done this Room.
All good, the room has 12/5 resets but is stuck resetting π
wait i know you
buzzy bee
Please don't do this, it's impatient, somebody will assist.
hihi anyone knows what's the root password to THM attack machine?
Youll need to press the i at the bottom of the split screen, its random each time.
thanks @sick lance
Gave +1 Rep to @sick lance (current: #1 - 2501)
Hello guys
I was actually wondering....
How much can I learn without the premium subscription?
recursion
Can I learn cybersecurity properly without the thm premium subscription?
Yeah, despite premium will help to get a bigger coverage
But yes, with free it is possible
Do freebies get attackbox?
But how much?I have been trying to complete one of the beginnner paths things like OSI Models etc are premium only
1h a day if IIRC
I can't buy the subscription because I don't have the money
When I was doing LAN it was not included for free... so I think you need to use other free course like coursera to cover comes topic.
I really need some help
Almost everytime I find a good platform to learning cybersecurity,pentesting,there is always the problem of subscriptions and money
Is coursera good?
Depends on the provider of the course. I usually compare the review then join the course.
And what about using your own VM?
I'm on subscribtion and still use my VM
Congrats on new rank btw
I do use xubuntu on virtual box. It's much faster compared to browser based .
Yeah, you can use that for THM
Thanks π .
Gave +1 Rep to @icy epoch (current: #127 - 54)
But why do you want the browser based then?
Well I don't want it. Was curious about that.
Yeah fair
There should be a + in the split screen if you have premium like lionel said
ok saw it ..thanks
π
Less issues in VM's
Dual booting can give some issues with mounting etc
it's also not recommended to run Kali on hardware.
Yeah I'm still trying to fix that too
Nah I use parrot
And same problem
In Virtualbox its even smoother than in VMware
Nah, my pc is fast enough
I'm more like a NSA person /j
Recursion, see Recursion
If you have everything configured right, yes, it is safe. But I still won't recommend it.
And I even think we are not allowed to talk about that in this channel
It wouldnβt be 0 risk as there are VM escape exploits out there
VM escape exploits arenβt that common AFAIK
Plus there's networking etc
If you don't know how to safely do it, I would highly recommend not doing it
If you have multiple external drives and you dont have them connected at the same time then if somehow one got infected you can just unplug it
Yes bee π
Morning
GM
Hi, I work in car repair, I open cars radio password, I diagnose cars, I use a lot of programs downloaded by random people on the Internet, they may be harmful, and the problem is that I have my files on the same computer I work on, will a VM do the job, I will use the programs on the VM, and put my files in the main OS, good idea?
Morning
Itβs not suggested to touch potentially harmful software at all
Typically you would need to isolate your vm so it doesnβt infect your network
isolate the VM in such a way that I cannot exchange files between it and the main OS,
I do not need Internet Access for work, so I will isolate my network in such a way that the VM cannot access any device on my network
Fine?
Iβm honestly not really comfortable with confirming anything.
Thereβs no way for me to know your setup is safe across the internet π
But in any case, the VM will not be able to access the Internet, as I have canceled the feature, right?
It will not have access to any device on the network, not just the router
Whether my internet setup is secure or not, the VM will not be able to connect to the Internet
If canceled the VM's Internet connection sharing feature From the VM settings
In addition, I will make the VM isolated from file exchange between it and the main OS
Is with This setup, everything should be okay
Correct me please if I'm wrong
Hey everyone,
I've been studying blue teaming for about a year now, but I'm finding the hands-on Splunk work quite frustrating and time-consuming. I understand that Splunk is a key tool for SOC analyst roles, but I'm struggling with the practical aspects.
Can anyone share their thoughts or advice? Should I focus on improving my Splunk skills, or is it worth considering a different path? Is this experience common, or might it be a sign that SOC analyst roles might not be the right fit for me?
"Our greatest weakness lies in giving up. The most certain way to succeed is always to try just one more time."
No one can make that choice for you, do what you feel right to be in your heart is my best advice
Thank you for you advice
Gave +1 Rep to @dim stag (current: #2128 - 1)
Gave +1 Rep to @lavish trench (current: #1413 - 2)
Uh, found a nice band today from the uk. Anyone listen "desolated" ?
yeah that's fine
Is there a possibility that .txt file, a malicious file?
I mean, it could cause harm
yes, depending on the software you're using to open it
I've gotten RCE with just a .txt file, it depends on how it's being interpreted
If it was opened with the default program that is responsible for opening txt files on Linux or Windows, I think everything sould be fine.
Or there is still the possibility of danger occurring
It's not about who opens what
Extensions are just suggestions
As far as OS is concerned
if you are talking about notepad.exe though, I'm not aware of any vulns with it and they would be patched fairly quickly if one was found, so technically yes it could be possible but very unlikely
Hi!
I do know a third-party-configured Windows-sandbox VM. https://cloud.google.com/blog/topics/threat-intelligence/flare-vm-the-windows-malware/
@jagged moon
Your words brought up new things I never wondered about before
I really want to explore how this work in more detail
These questions will keep running through my mind and I won't be able to stop them because I don't know the answers πββοΈ
I thought it had more to do with the program than the OS
But your words changed my way of seeing
It's both
Feel free to join our cult for more enlightment
Cult manager is @boreal scarab
CLAN!
sounds like a furry fandom community
π
You are not wrong
Ok I thought I just had made a misunderstanding with my bad English
This is unforgivable.
/s

Can u believe that, the commies gonna holding a bigbig cult party in 16 July, and my UDP 1394 connection to the THM vpn is gonna kept blocking till the day's over.
Semi-unrelated (to cybersecurity): I just trained a convolutional neural network and set it's epochs to 155 instead of a recommended 32, used a newer optimizer and got an accuracy of 0.95, is this even postable?
If you are new then just use the Attackbox. I'm assuming you're referring to openvpn.

I think... He was joking
It's the 'tism.
I am also working on this atm.
Dw
Damn I got 0 knowledge in Windows
One message removed from a suspended account.
I shouldve done Windows CTFs way before
I did the PickleRick CTF as my first THM CTF last night and had a lot of fun, great room. cant wait to get into more and eventually Windows
can some1 help me with a simple python automation script im genuinely confused as to why it doesnt wrok
hello anyone can help me the vpn is not work
Ls is a command in powershell
One message removed from a suspended account.
One message removed from a suspended account.
Oh, dont add tryhackme certificates
That are certificates of completion
Not "real" certificates
One message removed from a suspended account.
One message removed from a suspended account.
I gotta admit.... thin clients are great for physical security.
Hear me out... if someone steals the thin client, and it cant phone home, you have 0 access to anyone's account.
You could do that yes
Who is the owner of the server?
Why?
@whole yew would I be correct in this statement, or am I wrong?
No reply.
look top right
FYI: they don't reply to DM's


enumeration failed
I'm a designer and designed a brand new logo.
What's the e-mail and who is the Owner.
Keep conversation easy.
Thank you Mr. Bot
Gave +1 Rep to @sharp citrus (current: #133 - 52)
One message removed from a suspended account.

May fav, emoji so far.
There is two of them.


oh
Ben, go back to bed
We have a graphics design team that create all the room icons, illustrations, animations, social media posts, etc, and they are awesome
Multiple people?
Wow
it's 13:39! I'm working π
yup!
Bro hates bbr.
FUCK BBR!
It used to be soo good in beta, then it was released, and tryhards..... tryhards everywhere
As a sniper, no. M200
*Snipers
One message removed from a suspended account.
if you do the complete beginner pathway it leads to the picklerick CTF fairly early
One message removed from a suspended account.
One message removed from a suspended account.
One message removed from a suspended account.
I use an extension called Dark reader in my browser
One message removed from a suspended account.
Dark theme π β’οΈ
One message removed from a suspended account.
Oh Lord, can you imagine how the internet would look if we didn't have front-end designers...?
I love em
The graphic designs
"You're 1 pixel off this picture of a cake, good job, now our entire banking system is vulnerable!"
you are chinese, aren't you?
Would a html injection be a front end vulnerability
π΅βπ«
I think not x)
XD
idk im always confused here
omg i too was thinking of the 90s websites with the texts and g l i t t e r
is there something called html injection 
i know those websites too well (i was born in the late 90s) π
Itβs where a threat actor inject malicious code into the html code of the website
in case you didn't compromise the webserver before doing that , that won't lead to anything
Well fuck you too
lol dang, now thats a tangle
that's exactly what helpdesk be like
Too right they are! Some badges make excellent stickers.
MySpace phoned, on my old Nokia 3310.
@simple valve Yo bro you here?
π€
My brother had the 3310, I got the 3315. sadly the 3315 couldnt make your own ringtones but the 3310 could. I was quite jealous
I used a website where you could create your own banners and songs etc, then send then to you in a text.
thats great hahaha
@stray oracle where is the daily creature? :p
A bit useless now thoughπ
im sorry ive been forgetting/busy x.x
i ought to
In the outdoor channel huh
apparently π€
I used to love changing ringtones, and having new songs every week.
Now if the damn thing makes a noise I bounce it off the wall.
I'll be waiting for it :)
My phone never leaves Do not Disturb
i wish changing ringtones as an aspect of personalization was still popular. something nostalgic and quaint about it... it seems kinda tacky now
ooh yay hehe
What files for fuzzing do you guys use for Path Traversal? I only found Seclists/LFI/
@sick lance What did you think of the Netherlands getting beaten by England at the euros? :)
You were the one watching euros right?
Or am I confused xd
Ben and Jabba
Ahhh
actually Scrubz was watching too i think
I was quite angry about that ref
was a crazy game nobody expected that goal at the end
Ya what? 
That's rubbish lmfao
Wait, why shouldnt we add THM certificate of completion on LinkedIn?
HTML injection is when you can insert HTMl into a web page -- either in a response from the server (reflected, stored, etc), or by abusing client side scripts (DOM based).
Think of it as being the same as XSS, but without the code execution. XSS is basically a subcategory of HTML injection
cc @crude stump
I usually do directory traversals by hand
Honored
I tried a Windows box and file guessing is not fun
To add to it, if you find a reflected content and can't leverage it to XSS due to very mean waf or whatever, you can always report it as htmli for less impact
Soft penalty, Kanes momentum took him through, and the player was booked, VAR is slowly making a contact support non contact.
However Watkins showed Southgate what's happens when you sub, Foden should have been taken off earlier, he was being rendered useless in the second half,
Depay getting injured would not have been ideal to the Dutch.
England got the reward of now playing the best attacking team of the tournament, and I think Spain will win, not because they're playing England, but they've been the best team by miles.
The real question is: who do you want to win?
I usually don't guess much either
True. I hope Lamine will score
Beautiful player
Abe
Spain.
Spain deserves much more
You see the tech stack for web app or whatever. Look for config files for those in default locations. Etc.
Who?
The only good team this tournament
You don't know what ABE is !?
Yea wish I knew this earlier
Man, I barely know you're talking about football
Abe Lincoln of course
Muir, murder pls
Anyone
But
ENGLAND
COME ON JABBA, BEN etc
Bring it!
Too hot
Goddamn engerland
Atta boy. That was the response I was after 

