#general
1 messages Β· Page 304 of 1
wannacry only impacted about a quarter million machines. I'd like to see how many crowdstrike impacted.
A lot
10k I think
More than 5
that's it? that would be like 3 computers per customer average, if all Windows
I love seeing IT guys suffering doing that manually xD
Yeah maybe I've read that I think 2-3 hours ago stats aren't that clear
also that probably doesn't account for "customers" who are MSPs/MSSPs who have many of their own
why trust something with kernel access in first place lmao?
I trust linux kernel cz it is open source
cause the benefits outweight the risks normally
I dont use closed source stuff
And how often really has something like this happened
"don't use" and "this is untrustworthy" are two different things tho
i don't use windows for my own eps either
It's usually just eftpos going down world wide
but it's trustworthy in the context of business
the main issue here is all these companies implementing it without any proper fallback (admittedly difficult with a level 1 item)
I mean I'm not giving some company kernel access to my PC no matter what reputation it have
ring 0 π
so you're, as a business, not going to use Windows? or Mac? you're going to use Linux across your entire enterprise?
that's just dumb
Surely companies had a backup in case of an event. Emergency management lol
ring 0, that's it, thank you lol
Gave +1 Rep to @clever shard (current: #351 - 14)
Kinda maybe Ubuntu have AD now lmao?
"backup"? I don't know this word
but actually, it's less of an issue with backups and more of an issue of "how tf do we even restore??", because many of these users don't even have proper console access unless at the workstation
I don't hate on any of that software but in fact I just don't like using since I don't know what does it
maybe my data is getting sold to 3rd parties?
Too true limited access
yeah but as a business it's about risk
it's less risk to do it this way than otherwise
Biba and lapadula
would i want it personally? probably not, no
would i use it on business devices that dumb employees use? absolutely.
Forgot the actual terms
also that's why you have proper contracts in place, because if they are selling your data, and that data is protected, now you have a massive lawsuit against the company and their reputation is pretty irepperably damaged and would be hard to use in trusted envs going forward
Did they say what driver or was it just to do with the software that uses the kernel driver
By accepting the Terms of services you give them access to sell your data to 3rd compagnies lmao?
no, a contract
you sign a contract with your vendor outlining all the terms of contention you have, including your billing, volumes, what you receive from the provider, what they can do with things, etc
businesses don't just accept ToC at that volume
you have SLAs, reliability, data sensitivity, ....
They just said a kernel driver
Yeah 100% but they only give a fuck about billing and features not something else.
C-00000291*.sys
the vendor or the customer? the customer doesn't have to sign if the terms are disagreeable, and the customer, especially with counsel, does review a whole lot more than billing in sensitive environments
just because the mom and pop shop with 7 employees doesn't, doesn't mean that skipping that step is the rule π€·ββοΈ
again, at that volume --- it's a large contract, so counsel will almost certainly at least glance at it
Hey you guys know a good site that explain what the hell happen today ?
crowdstrike go boom
I know but like I donβt wanna read dumb media that donβt know anything about it talking about it
Thanks
inadvertently just described linkedin today
well, most days
What types of user privilege permissions are Windows? Guest, standard, admin, system?
User account
Been a bit
yall i own a website and i was doing port checks using nmap and it came up that there was so many ports open and then i did it to my friends website with permission and the same amount of ports came up
idk if it has something to do with nmap
Itβs so funny bro
With this crash everybody is gonna use Linux now
doubt it
It was crowdstrike, not windows
welcome to most of the internet π
crowdstrike could've screwed up Linux too
Can we all collectively blame Microsoft for no apparent reason
Just joking
#microsoftdidcrowdstrike
after wannacry, people didn't stop using Windows
Could make it a meme
No hate on MS.. I have friends there.. jeez guys.. All the MS hate needs to go.
or updated them
Make windows the nickleback of the OS
wait does anyone know anything about what is happening with nmap
People do like Nickleback
we can hate Microsoft but due to this, it isn't a reason to
Yeah I know I don't know why people don't like them
hashtag crowdstrike again π π
I don't want to say people that touch grass like knickleback, that might be a little to direct
I'd truly do that to Mac/iOS
that'd be funny "oh Monday's update is for Linux"
@mossy river I am pink haired again
quite literally looking like that right now 
oh I thought you already were
i dont hate ms but i hate that i had to download something to let me put my taskbar on right side of screen in win 11. why would they get rid of that feature...
I asked ChatGPT to generate a logo for me of "Ansible" featuring "scalability" and "automation". I was very elaborate in my prompt. This is what I got...
your lucky they didn't have a subscription fee to change the taskbar
lmao
It automated the scalability
chatgpt can only regurtitate/modify things its seen before
yeah..
Microsoft EA
I was hoping they had adopted DALLe or something
Don't hate on something you can't recreate/build lmao many people would hate on microsoft xD
thats a silly criteria
Let be honest microsoft have good shit and made life alot easier with creating some stuff why hate on it lmao?
regarding crowdstrike:
Guy from Blackpoint (MSSP) indicating that it was due to a null ptr deref
people can hate on Microsoft if they want, go for it, knock yourself out π€£
Alot of people hate on Microsoft it self and it products if you dont like it there is plenty other stuff that well suit you lmao.
some1 explain the Microsoft thing to me pls
there are certainly valid criticism of Microsoft for a variety of reason
Kernel goes brrrrrrrr
did you google? what don't you understand?
I just know it just stuff down
Busy
I have 225k on YouTube
My other channel
#general message null ptr deref in an update pushed by crowdstrike (not microsoft/windows) caused the world to implode
Itβs YouTube, there all kids to since Iβm a gaming channel
ay shootout to ma homie π
what kinda reasoning is that π
someone made an error in code I see?
so it takes 1 second to google
what you think we gonna do? provide brain osmosis?
Thomas Matthew Crooks
not 100% on if it was a bug or corruption but it seems to possibly be a corrupted file (missing the tail end?)
dam seems bad
Let put it this way some devs pushed bad code for update and since it have kernel access pc goes brrr, and also as @tired peak said google stuff for yourself not everyone would be willing to spoon feed you informations @weary sleet
what no that means we lose some
wait if you have 225k why would you link the channel with 9k to your discord instead
my separate discord account I donβt like promoting it bc then I get DMβs so I have a different discord account with this channel as a fake more
like I have an account with over 525 DMs
ah i see
but I still use this one, but itβs dead so idc
makes me wanna find nfs hp
have you tried "sudo apt update" first
you need to install openvpn? isn't it just included with the kernel now?
i thought it was at least π€·ββοΈ
sounds about right
Yeeeeh
can u do sudo dpkg -l | grep openvpn
also, what OS are you on? kali?
ohhhh snap
then its installed, you have to give it the file
fedora
how did you get pkg not find but you're on fedora
like yeah it's installed
but now i'm confused about that
fedora doesn't have apt
yum?? isnt it
if you run a command on linux without the arguments, it'll give you the help (generally)
dnf
ahh dnf
do a sudo update before that, like sudo update && sudo apt install openvpn
(yum would work as well but that's just for legacy support --- yum is actually just an alias of dnf nowadays)
they are on fedora
why they are using apt if they are on fedora π
how is nobody else questioning this error message? apt shouldn't even be present on fedora πΆ
so type "openvpn <name of your vpn file>" or "sudo openvpn <name of your vpn file>" if you aren't like me and don't run as root
I'm a say the gamer Word
this is the only nmap scan i do in a production environment
nmap -A --min-rate=100000 -sV -sC -p- `--script=vuln*
my point exactly
is it just alias'd on their system?
might be
I guess we will never know lol
maybe they went and found it, compiled it and installed it π€£
@molten sky i hate you
which is totally a move I'd do
why this time π
dnf install apt anyone?
all my homies use wireguard 
Unrelated but I'm losing in a game by 0.98 seconds so it's your fault
ehm
0.98?
idk how you mathed or in what direction but that doesn't add up in any way
0.88*
wow that's weird π I would never thought of doing dnf install apt
skill issue
same, just tried with pacman. Most cursed shit someone could ever do to a system
finnaly beat it
often breaks shit too tbh
Oi btw anyone got a way I can recreate the crowdstrike BSOD on a personal machine
your system becomes a battleground for fighting package managers
get someone to send you the corrupted driver and just drop it in place is probably the easiest
By any chance do you have a copy of the corrupted driver
@molten sky I google it. APT-RPM, basically mapped normal apt commands so that they worked with Fedora's RPM package management system.
lol if you asked me a few hours ago i would
How
apt rpm or apt-rpm rpm
Aren't you unemployed
I have no further comments
That makes me even more curious
spit it out! @blazing granite
from a quick google reading is APT-RPM, but I have to dig deeper, because I find this weird, disturbing and interesting all at the same time π
damn, how could you not see he was offering you a job!!?!?!?!
He's the reason behind CrowdStrike's BSOD
him and his partner, Matt
I didn't know Matt was working for crowdstrike π
He was undercover
bruh, I broke mint π€£
So that's basically a null value pointing to a "proper value"?
As far as I could understand from Internet
you're trying to dereferance a pointer whose value itself is null
rather than a memory addr
Oh yeah
Thinking of giving up THM. :<
why
you didn't brake anything kernel panic or GTFO π
I think it's more important for me to get a job now than to do fun tasks online.
then sure take a break
but "give up" is a bit drastic for that
Those "fun tasks" will help tho?
just come back when able
Uh, not really. I mean, at least not where I am from/at.
How
Yeah, that's probably going to be the case and then I'll try to grind to 1% again.
My country values certifications over certificates and university degrees above both.
so rude lol
thats not much different than other countries
Surely having both helps better
I can only speak for mine.
you can learn skills through various learning sites, but getting a job is a mix of degrees + work experience + certifications
It's a bit counterintuitive to try to work on one thing that's more valuable alongside something that's less valuable when you can be completely focusing on the most valuable one.
Yeah, I learned enough on THM. The rest is basically just for fun.
DevSecOps room doesn't really work so I won't engage on that.
so whats your problem?
usually certs and degrees will get you an interview, hands on experience and showing what you know will get you the job π
Hey I have a question how would I be able to get experience? take notes that all jobs wants work experience even if it is entry lvl how would I be able to get a job in the first place?*
None? I never mentioned having one.
you go for even a more junior role
This is true but my country is backwards enough to... not even test your "hands on experience" prior to seeing the certs and degrees.
apply to jobs asking for 1-2 years experience, utilize experience in related fields
lots of people get jobs as IT help desk to start in IT, also if you have opportunities to get internships, thats another way
Yes.
depends on the employer
That's not very helpful since absolutely every decision in that regard would depend on the employer regardless of everything else.
The answer is yes, that would suffice for an entry level job.
I tried booting into it, got a black screen of sadness, had to resort to windows π’
I had less than that as experience when I landed as an IT Analyst, could work for you too.
that's the job market and suks π
but it does. If you are trying to get a job as a pentester for instance, an employer may not consider doing PC repair as a valid IT experience, also you are competing against other people
but still as Azure said depends on the employee. yeah I know it is kinda similiar but concepts doesn't match
They mentioned entry level jobs.
Pentesting is not entry level.
I'm assuming they are looking for entry level cyber jobs, but maybe not
Jr is not entry level π
It's not because it's "junior" that it is entry level.
Junior just mean you just recently started in that role.
"entry level pentester" is also not "entry level" -- it's entry level for that category
but the truth is, for the job market you are working on finding a job which qualifications you meet 50% or more of and you can compete against the rest of the competition
this market sucks too lmao
yes definitely
entry level is gonna have it worse probably
So let put it this way Jr != entry lvl?
Yeah, and assuming that, working as an IT repairsperson would suffice if you prove practical knowledge in the role your are seeking.
correct
although junior is just a word
Jr. just means you are new to to the role.
damn the job market is fu34ked
but isn't junior is a title for someone that just started?
entry level pentester, that sounds something like an hr person with 0 tech knowledge would write π
Btw Verum, how did it go with reGex
Entry level means that you don't need too much experience, too much education, too much of anything to attempt it, however you have to have at least something that is related to it.
"entry level python developer" and you'll read the JD to see "must have 7 years of experience in C#, wildland firefighting, and sorcery"
Yes, my friend.
But entry level is a level, not a timeframe.
For someone who just started X role.
there are certainly people who have 0 IT experience and go into pentesting as a first IT job but its rarer
once I read a job search for more 15 year experience of "X tech" ( I don't remember exactly which) but funny thing is that "X tech" was created 10 years ago π
Can you cite a recognizable example?
sure, our friend TheMayor is one (he has created a few THM rooms)
"15 years? I invented X tech only 7 years ago" -- "we've decided to go with a candidate who better fit our goals"
I honestly believe some real negative things about HR's cognitive abilities.
I have never had a single decent experience with them, ever, in any company, at all.
makes sense considering HR isn't your friend and isn't meant to be
I can't find the article but there is also a guy who was a pool guy, whose switched careers to pentesting. I know him from a different discord
HR exists to protect the company from you
coming to thinking my reporting skills sucks if I get it right tryhackme doesn't have yet reporting rooms?
Interesting, it's a very weird case, I'm pretty sure they live in a developed country, right?
its a bit of practice, practice, practice... try doing writeups
With the kind of tech culture of "show us you can do it, not that a piece of paper says you can do it"
both are in the US
It depends on what you mean by reporting?
also I think our very own NinjaJames first job was as a pentester, maybe Muiri too
both of them live in the UK
Those are things that you learn during your experience on the job for the most part.
Learn Microsoft 365 and try to refine your vocabulary and mimick the professional language of your peers, that's pretty much all of "soft skills" necessary for jobs.
Once HR told me your resume is very impressive, but we went with another candidate. I told them, it was impressive, but not impressive enough to get me an interview π and they hung up on me π
if it wasn't probably 2am in UK, I'd probably tag them to validate
I mean writeups for ctfs are very different no? I saw some real world pentesting reports and they are very different from writeups
That's an interesting perspective.
yes but its practice, you can show your methodology, its not an executive briefing by any means
After conducting a pentest you need to write a report to the company. after all they buy your report
I think it is more of learning yourself kinda thing by looking other people reports and getting someone to review them.
and still as you said it would be a good practice for methodology
ty
+rep @tired peak
Gave +1 Rep to @tired peak (current: #15 - 498)
I have a worse story which is absolutely insane. I got INVITED to be a Network Analyst by the Director of the Board of Networking in a company, he basically told HR to give me the job. I got into the interview and there was another guy with me (?) and the HR asked "so, tell me more about yourself" without specifying who, then the guy started talking nonstop and HR gave me literally 10% of his time to talk about me, I was only able to say that I was invited by the director to be on the spot. THEY. STILL. DENIED. ME.
Oh, that's pretty easy, really, but what do you mean exactly? You don't know how to write reports in general or those kinds of reports?
I see many people fail some certs due to their lack of skills in reporting so thought before taking a certs or something why not practice reporting xD
You have GPT 4.5 at your disposal, prompt it to give you an example of a report that you'd see yourself doing in the future as a pentester.
v good suggestion, having a layout to follow
Why ask GPT when you can look up other people's reports?
- correct me if I'm wrong but GPT isn't trained on pentesting reports?
You just answered yourself twice.
Can anyone send me a picture of there pc setup in my DMs
I wanna get a pc and see what ur setups look like, and if I copy it Iβll give you nitro
And send you a photo of mine
Hello guys, I have a quick question about the ejptv2. I am willing to join this course and take the certificate. Well I saw that the certificate has 3 year date expiration. I am now 17 If I take it now would the expiration effect me when I apply for cyber jobs?
I'm never gonna dance again
Guilty feet have got no rhythm π
Please don't 
would the expiration effect me when I apply for cyber jobs?
expiration is 3 years from the date of issuance
if you wait 7 years to start working, it'll be expired (provided you don't do or they don't accept CPEs)
I've yet to see a cert with reporting requirements which accurately reflect a pentest report. I hear PNPT might, and possibly the HTB one, but no personal experience there π€·ββοΈ
Although yes, it's perfectly possible to fail something like an Offsec exam based on your report
People see chat gpt like their saviour, I see it like a plague π
chatgpt can barely figure out how to write a functional hello world
Will the companies care about it? I mean its expired but I still got the knowledge right?
my security+ lapsed idk how many years ago, it's still on my linkedin just as expired
only time it matters for me is 8570.01
If you want it to summarise or reword something it's okay, but when I see people asking it for a definitive answer to an unfamiliar topic...
ChatGPT or similar GenAi models are good to use IF you know what you are doing and know how to recognize good and bad of what you are trying to generate
I mean idc about the report in the certs but the client buys your report not for you to get flags lmao?
Thanks alot
if you have no idea what a good pentest report looks like, then its a bad idea to use ChatGPT to generate a pentest report and rely on that
Flags? In a pentest..?
U missed the joke
But yes, you're right to say that the product of a pentest is the report, not the work.
They tend to follow very strict style guides for that reason. You need to be good at technical writing.
Have a look at the RFC style guide, as a good example.
Generally speaking a pentest report is formed largely of issues taken from a KB (ideally), following a standardised format. The custom parts need to fit in with the overall style of the report, as well as the style of the team.
i.e., if you're on a team of 10, it shouldn't be possible to tell which person wrote the report based purely on the content.
Noted
Oh good, you're taking notes now? 
Let put it this way I only take stuff that I well need and wont find out
that's my point you can use it to save time, to do something that you know to do, and you can check afterwards, but people use it as an "assistant" that make the job for them and/or that do something they have no idea, that's the issue, gpt has a lot I mean a lot of issues, some field more than other but is not something that you can trust without checking
+thanks for remembering me β€οΈ
Absolutely this
Some ex-moderation habits never die π€£
Muiri was the community manager 
muiri ! your color !
( re: )
What's happened to it now...
The most ironic thing ever...... https://www.marshall.edu/library/bannedbooks/fahrenheit-451/
literally 1984
Exactly!
you clearly aren't a fan of the Il vaticano
I don't know chess!
holy hell

now is community Legend π
Everytime I hear the song: Your Love by The Outfield.... I can't unsee this vid: https://www.youtube.com/watch?v=tu_2xfhsrz8#ddg-play
Compiled from the original Tik Toks and a couple YouTube clips. Props to LJ for taking the time to synch the lips for the first few parts.
LJ Edit: https://youtu.be/9go5jzWvJsI
Original Tik Toks: https://vm.tiktok.com/ZMeexGGmN/
Filler: https://youtu.be/i5dDylLu9qs
time to go to sleep I'm falling sleep on my keyboard π Bye people have a good one!!!
π₯³
Tim! I dids a thing!
oh no
Not another CrowdStrike disaster
Installed AIX on your coffee robot?
Other than the horseshit from today??
Soonβ’
Got some coffee gear for my new baby!
Coffee bot modding? π
already done 
that's why I am awake right now and have to be at work in 3 hours

I THINK I can program it to brew me a cup in the morning... dunno lol
@boreal scarab β β β β β
otherwise send me make model and firmware and I'll find a way π
love IoT hacking
Bella, sleep?
no
I have morning shift
Gl
and on a 72 hour fast π
yeah π
Shall I expose it fully to the internet too?
,..
not needed maybe
again, depends on make and model
What? There's no harm in exposing IOT devices to the internet........ right?

hard to tell
send me your ip address and i'll check for ya
Alright!
||127.0.0.1|| Remember, it's secret! Don't give thise out to anyone else!
oh hey we have the same username
@sand trench https://youtube.com/shorts/zflp86hvByM?si=431zWLcaKCsKGWrG
Found you
what is a wildcard certificate?
you guys should check out the crowdstrike job postings
"Sr. Software Engineer - Windows Kernel, Core Platform (Remote, CAN)"
guys anyone know why he didnt work ?
no its some thing about
024-07-19 23:38:43 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-07-19 23:38:43 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-07-19 23:38:43 Cannot load inline certificate file
2024-07-19 23:38:43 Exiting due to fatal error
well i am not having fun with git and obsidan lately
I changed the name of the repo which caused it to be unable to push to it
I tried to fix it and failed each time to which i finally decided to just delete the entire repo and make a new one
that shouldn't happen
when you change the repo name on github, the old name redirects to it (as long as you don't reuse the old name for something else)
try it in your browser and it should still work.
delete the entire repo
in that case maybe don't try it
But then... on trying to clone a new repo it is saying i cannot do it due not being able to connect to port 443....
that um
well first of all, https and not ssh?
second, if it can't even hit that port, that sounds like an unrelated issue of some kind
genuinely don't remember the last time i've used https with git --- trying to remember
but yeah i'm using an old remote right now for instance --- push pull clone works fine
orgname/originalname redirects to orgname/newname on any request
in any case im kinda just troubleshooting while fixing up my notes from a ctf
Well i was gonna just copy it all to google drive and transfer it to my windows computer then use github desktop there.
Maybe it will be different
aside --- can't even remember how git over https authenticates....does it ask for your account password or something? what about 2fa?
Well it did ask for my password which didnt work. Then i figued out i needed to use the access token
ahhh PATs...
at that point why even use PATs just use ssh
more steps for a less convenient method, no?
I guess ill have to setup ssh
I also have my ssh config set up so that i can just do git clone gh:org/repo rather than git clone git@github.com/org/repo or whatever long nonsense you need
so much shorter and easier
Heard good conspiracy theories about the crowdstrike BSOD's today, It's because of microsoft taking over the world and needed a excuse for something
I also think this is just a great example of how widespread the concept of a single point of failure is. If companies built their systems with resiliency in mind, redundant measures would've been in place and this wouldn't have happened on the scale that it did
I've been reading some absolute nonsense on social media also. People who had no idea who Crowdstrike was until today haha. It must be exhausting living every day like everyone is out to get you.
While it seems simple, there are a lot of moving parts and factors that make it extremely difficult.
tbh, I'm going to hold judgment on this whole thing until the whitepaper comes out. Obviously colossal screw up, but where was the breakdown, what was the fix, what are the lessons learned, and what's in place to stop it from happening again.
I don't know that you can manage that change though
On the downstream, I should clarify. CrowdStrike needs to look at their change management procedures.
Yeah, that's a great idea. More information would definitely be nice.
It's also important to note that system resilience isn't the only factor at play here. For one, like you just mentioned, it seems like they rolled out the update to everyone all at once without prior testing in a safe environment, and without rolling basis
The Falcon Sensor is a kernel level item, afaik, and this was a driver/instruction update that went sideways
idk if you saw the john hammond video yet but two of the fixes were to rename the driver file to a .bandaid extension and the other one is to delete all driver files with a certain name
Yeah, it was a single .sys file
Bitlocker is what turned this in to a nightmare for most, but you can't throw that out.
yeah, cuz you can't enter safe mode with bitlocker on, is that right ?
tbh, they could have tested this update and had not adverse effects in their environment. That's entirely plausible. We just don't know yet and we'll have to wait for their debrief.
Yes and no
I see people calling for more redundancies, but how far is enough? Should each supermarket run a different OS, software, and internet connection on each device in the store?
You're correct in saying that you can't run in Safe Mode with Bitlocker, but the remedy is to enter your recovery key, which allows you to enter Safe Mode.
So it's not entirely unavailable
Oh yeah, I remember that was mentioned in the video now
My experience was a little different today, ended up requiring about two hours of troubleshooting, before we got my machine back to operational.
My idea of it wasn't every device running a different OS, but that there could be a backup system ready to be used in the case of the primary one going down.
Kinda like how RAID storage works is what I'm thinking
Not sure how practical that is in reality though
Hot/Warm/Cold spares are a thing, but the issue is cost
Most places don't even have the budget for their primary computing infrastructure needs
That brings up a good point about the nature of a cybersecurity department. It's a cost center. Unlike the sales team or the marketing team, a cybersec department doesn't bring in profits but still costs the company money to operate it
overall though, sad what happened today. Especially when thinking about ppl who missed their flights and hotel reservations
hell yee
especially since it's weekend
even better π
cause that means 30% extra pay 
hi
You got crowd struck did you?
Hey is there any resource on finding challenge rooms in TryHackMe other than using the search option?
looking for some guidance - at start i just wrote "malware analysis" and tried searching for challenge rooms that way, But it feels not good enough.
Goodmorning
This is literally a day off for IT workers whoβs cloud computers got bricked from crowdstrike
you mean an additional work day 
For people who work in person yes
youβd be surprised π
hey babies
So obsidian with git plugin is proving to be a bit of a pain
When pushing to github any images with spaces in the names are broken because it doesnt add the %20 to them
So im having to go through and fix each one.
Is it free though?
You're essentially being paid to be ready to take a call...
I get paid to watch netflix and have a response time of <20 minutes if there's an alarm on the system
Apparently if nano has the SUID bit set and you go to edit a file in a directory you wouldn't otherwise have permission to write to it still says something like '/ is not writable' even if it actually is writable
I opened the file in nano, saw it, then moved on to other attempts lmao. It was within reach for the past two hours RIP
damn
Unix supremacy
dont say thatπ
why...those are the rules 
isnt ngrok a beginner thing
yall how do i start learning how to "ethically hack" because youtube is just not doing it for me
it's rarely used for non-phishing things, so again, only for advanced channels so we know you're actually interested in cyber
Is it?
Is it?
according to @sick lance
my friend asked me to check if his website is vulnerable to sql injections and dont ask me why hes asking me lol
or Jabba
it's one of them, they said the exact same thing to the same person yesterday
Would have been Jabba.
yeah, it was jabba, sorry for waking you up scrubz
I was awake, lol.
A curious choice. It's a useful development tool
hello !
i'm looking for a vocal channel to chill but found nothing
someone saw one of them ?
Yeah, but we both know how the majority of new users choose to try and use it
You need to be verified to access our VC.
again, not my words
To expose parts of their home network to the internet. Yeah, that sounds very unsafe for the rest of the world...
but yes, I agree
cannot found either the channel to start the verification process, can you ping it please ?

Now you two should kiss
my account is verified but not linked to discord π’
You're not verified with THM - Discord.
Perhaps that's why it's for advanced also
The majority of users who request help do so with phishing in mind.
we should just ask the person why they want help π€·ββοΈ 
Make them write an essay on why

Then you'd get x people trying to help.
Then that's the conversation to have with them. Automatically restricting a tunnelling tool designed for development projects is just daft.
Hell, there's at least one THM room where it's actually a really good option.
makes sense
I'd point out y'all also have (officially developed) content on phishing. Can't put a blanket ban on the topic π€·ββοΈ
I wasn't around for the conversation yesterday, so not sure why they want it
Not been in my laptop for a week π
they didn't say, jabba just said the things I said and they just didn't say anything after that...
i did a nikto scan on my friends website and something came back saying /site/'%20UNION%20ALL%20SELECT%20FileToClob('/etc/passwd','server')::html,0%20FROM%20sysusers%20WHERE%20username%20=%20USER%20--/.html: Web DataBlade 4.12/Informix is vulnerable to SQL injection. what does this mean?
Where does your friend host the website?
openresty im pretty sure
@sick lance can h help me plz
Gotdamn
When I try link my thm token to my discord it says itβs been used
Probably not a good idea to do anything to it then without permission from them.
Do you have a second discord account?
Openresty is an app server kinda like NGINX
Its not a hosting platform
Lost it
How can you lose an account?
Miss place it?
Happens to the best of us
im not gonna do anything with im just trying to understand what it means so i can tell him about it
No I stopped sec 2 yrs ago and itβs in my broken laptop and Iβm just starting again
You'll need to dm me the token + account.
its also used as a reverse proxy like cloudflare to protect yourself if you are self-hosting with your home ip or smth
If you had the technical know-how of that you wouldn't come to a "hacking" discord and ask for help, WITHOUT elaborating on what you're trying to do
you as in not YOU, but that person
is ngrok rlly that popular for phishing? Never seen it used
I would say nice beginner tool.
most phishing frameworks use it
like blackeye, set...etc.
I mean, considering the same functionality is built into VS Code...
π
Ironic
I just canβt grasp how all of that could happen after massive QA trials on the update
maybe everyone was using a mac
/s
Maybe they saw the tests passing consistently in linux and macos environments but on windows "an unrelated system error caused a bluescreen during testing" and then decided to just write it off as a passing test in the release process
lmfao
it happens
if you're confident that the update works because you see it pass in other environments, and your "experts" tell you that it's "most likely an unrelated issue" and that "this update can't possibly cause these issues" then... chances are it can be written off as a test that was performed manually or whatever
I hope it's not the case because that would be outright stupid on an astronomical scale
xD
@thorn jungle don't DM without consent, thank you π
Gave +1 Rep to @thorn jungle (current: #2142 - 1)
lmfao
Took away 1 Rep from medal88 (current: #5030 - 0)
rip rep
Problem solved
I donβt think so, pretty sure itβs just one at a time
aww
+rep @shadow loom
Gave +1 Rep to @shadow loom (current: #216 - 26)

+rep @shadow loom
Gave +1 Rep to @shadow loom (current: #213 - 27)
Floor boards must be vibrating right about now. Bass goes hard
If you abuse the rep system you will be blacklisted
oof

So my speaker is dead and it takes a USB-c
Problem is that itβs provided cable is USB-c to USB-a and I have no adapters π
I only have usb-c adapters
Nope
I have every single type of usb-c cable except usbc-usbc
borrow it from someone?
Singularity XDR > Falcon confirmed?
no

Iβm in the house alone for about a month or two
Which is why Iβm blasting music π
ohh, I thought you were at uni...
Iβll need to order one but Iβm not here over the weekend
Yup I am at uni
I live in shared housing
Ah, I see
They all went home for summer
makes sense
why not you? π
beatmetoit
Iβd rather stay out here :)
Sometimes not going home is yay
Iβm paying for the house, might as well live here
But⦠I like visiting my folks
Iβm going to a party in my hometown tonight so I am visiting needed a sofa to crash on
I spent the night out with drunk friends
noice 
were you also drunk or was it just friends
I got drunk ONCE in my entire life and that's it
never touched alcohol after that
@mossy river here's some summer vibes for your speakers, btw: https://open.spotify.com/track/5qHYXcVvc9xsFB2uH7GpMN?si=b031d681cf6e4afe
I bit the bullet
massive banger
Just rubbing it in that i canβt use it right now huh ππ
gonna get it replaced?
Nah Apple says it doesnβt need to be
N- no 
Tbh I donβt know of a time that being drunk is necessary
it's never
Certified old man
isn't birb like? a million years old?
bro
this stuff is what Deadpool could be blasting on a killing spree
and you know it
@mossy river π
Birb is old?
yeah, he's like a million years old
right @shadow loom ?
Deadpool isnβt exactly young π
but he's cool 
A keyboard which adapts to you. Any software, any language, any style.
More info at https://fluxkeyboard.com/
Prototype Shown.
Fourth wall breaker
This concept looks interesting, but I just went on the website and the base keyboard is $500 π
He can be both
Eww
Whereβs the razer logo smh
Bad keyboard
So did everyone fix the crowdstrike? Is the circus over?
We all back to normal?
yeah but it's not a mechanical keyboard...
looks like it
It's a tactile feeling
their stock is till down 11% but yeah, that's about it haha
yeah, I've used it and I DO NOT like it, it's weird and very mushy tbh
it's not a bad keyboard, but it's very very expensive haha
not THIS keyboard, tactile feeling keyboards 
oh
npnp
fully decked out, this thing costs 580
expensive asf lol
and with shipping 610...nope, not for me
Is there anyone here who's done mobile app development using Flutter + Firebase?
yuh its expensive
I think I just lost braincells.... "When you buy a vacuum cleaner, you get a vacuum cleaner"
system is rigged bro

Hey guys I need to set up a new work station, can any one recommend set up machine and gadget that are cost friendly and Linux compactible for hacking and coding ....
Would recommend getting second hand if you're after cost friendly stuff
Lots of decently big vendors on ebay etc that refurb ex business stuff
I'd only buy new if it was costing somebodh else 
Linux friendliness, most things are A-OK now. Laptops can be a bit quirky
Somebody *
Thanks guys still thinking about it
sry i was in a hurry
I flexed my massive brain and solved my speaker problem π
Yoooo
Summer vibes song time
Iβm not listening to beach boys π
how π
I remembered I have a linux thinkpad.
Charger -> think pad -> speaker

CrowdStruck. 
Well, what's funny about the CS outage... you know what companies use it. And what companies don't 
Or how quickly they push CS updates
Watching the news talking about BSoD's everywhere.... I'm so proud π₯Ή
not so bad =/
And now they're talking about having the federal government watch over "critical infrastructure" .... and that was a question about "How to avoid this in the future"......
its Hyprland that is pre configured
i can DM the video of how to. and just you need change script to fit latest kali
cos there is some errors that bonk installation
if left default
sure
one min
Aaaa so tired
this is script that is for rainbow
#!/bin/bash
function random_hex() {
random_hex=("0xff$(openssl rand -hex 3)")
echo $random_hex
}
hyprctl keyword general:col.active_border $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) 270deg
hyprctl keyword general:col.inactive_border $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) $(random_hex) 270deg
May I intrest you in some coffee?
I'll brew up a mean cappuccino

for a second I thought you were using dwm or i3 lol
it looks alike
very alike haha, then I saw the - and x
i spend night of fixing bugs that didnt fit to install on kali. and finaly works
wow, thankfully it looks like it worked haha
now ill reinstall again to make it all fit as i wish
i newer work in gui like that so all is weird
hey guys why cant i cd into a directory on linux?
#room-help please
The directory needs execute permissions for you to CD into it
Eh that's more of a general linux q
that's what i thought
its not room specific
yo
try ls -alh
oh okay, yeah it seems it doesn't have those
just did, it has no execute permissions so ig that's it
yea. ninja was step in front of me π
was just surprised because ive only encountered permission denied so far, not just "cant cd"
thanks guys
It might be that sh is less verbose about it than bash
oh I see
try run bash might be there on system so bas can spawn
but you can to ubuntu
wym?
i think you can cd into ubuntu folder
Yes yes, that works, I am just trying to understand why things work the way they work
well root:root says that only root can into backup. and permissions are quite tight
and others prem are just set to r-- for rest and groud
you might try ls -alh backup
Isn't that how you get caffeine withdrawals
Yes
I got ntro yay
But my friend said I get pizza at 30 days so itβs worth it
No caffeine withdrawals for me. I could never quit coffee π
try it
Iβm sleeping much better now that I am off caffeine
every 4-6 months i do the same. for 30-45 days
funny how addictions work.. change coffee to something else in that sentence and then it's not okay anymore π€
why aren't you gradually reducing it, seems like that would be easier
funny thing is that only organ in our body that we can control is brain, and we even fail in that
Addiction to caffeine still isnβt okay. Addiction of any forms is bad
to much of anything is addiction
It stil is more "socially accepted" than something like alcohol which is more accepted than something like weed
It doesnβt work with me.
interesting
Says the person who change coffee for pizza πππ
Yo
when you quit all together is much harder, but brain gets much stronger in makind decisions
Whoa whoa whoa, I quit caffeine before I was promised pizza. But now I have a goal π
And itβs not the pizza I want, itβs the thought that counts
The official video for βNever Gonna Give You Upβ by Rick Astley. The new album 'Are We There Yet?' is out now: Download here: https://RickAstley.lnk.to/AreWe...
Addiction isnβt accepted, itβs just more easily identified with Alcohol and other substances because they have adverse effects
Saving money by not drinking anything else than water
@mossy river iirc you say to like rammstein...
https://izismile.com/2024/06/28/rammstein_concert_in_dublin_from_an_airplane_window_video.html check vid
I donβt like rammstein
hmm... who dheck then told me that
just look that it have 8-16 gb ram and ssd
if new one
if you wish some old laptop is also ok to start with
IT is fine
idk for mac but ppl do it
Cybersecurity, itβs a bit difficult
windows can do job, kinda. but ppl go with kali linux or some like that
Just a question, anyone else have a hard time with any other distribution other than debian based ones within Virtualbox? I strongly believe that it is not the hypervisor's fault within windows11 since i have disabled it and gone through that rabbit hole, I however do run this system with a i7-1400K, for a long time i was thinking that maybe the E / P cores would be messing with the virtual machines, however prior to installing the guest additions, the VM runs perfectly fine, it is only after i install the VirtualBox Guest additions that i get major visual glitches and hanging terminal windows (On every distribution apart from Debian) which is extremely weird.
it must be enabled
Hypervisor?
Yeah i have the VM on Default which does mean it will use hypervisor by itself, i meant i disabled it in the windows features, i read that the WSL functionality could cause issues with Virtualbox aswell
So i disabled WSL entirely aswell
enable hyperv
In bios or windows features?
bios
Alright i'll try that π
for in windows idk tbh
Yeah its weird, all Debian vm's are running perfectly
It might be the Virtualbox Guest Additions, not being able to work with the i7 1400k
Or maybe any of the cpu's with the E and P core technology
guest dont have nothing with cpu... iirc
Did you install the parallels tool to the guest os
so your text is blurry for your Linux VM? did you check the resolution?
did you check the display settings/resolution?
Is there a discount i get get for the monthly subscription
parallels app
any desktop virtualization software will allow you to modify the display/resolution of the VM
what happens if you select scaled? is there no option for something where it shows 800x600 (which sounds like what you may be at)
btw is it VMw or VBox?
its parallels
ah
did you google something like "virtual machine text is blurry in parallels"?
usually the reason is actually due to the high resolution of the macs, so you have to configure it somehow. On VMware, I have something that says "use full resolution for retina display". It's been a few years since I've used Parallels
something higher than that.
try double that
or as high as you can go
so now thats a different issue... again there should be a setting for that
@umbral bay π
yes normal, should be a directory named .john or similar. try ls -a to see what directories are there
Zojja, what did you think of "The beekeeper"? I thought the plot was absolutely atrocious lol
oh it was atrocious, thats why I said it is a B movie...
but its hard not to watch Statham
I can't take the deep voice seriously
Disappointed tbh, I'm normally fine with most movies but that one was awful
Didn't even make sense
hi
the movie had potentional but for me is kinda crap =/ the story can be made better
I mean it almost seems like they made it a crappy movie on purpose
I'd love a MST3K of it
Loved how the other beekeeper was an absolute maniac who lasted 5 minutes and then they were like "ok byeee" π
and then the FBI agent "did you know..."
no, no one cares
that book she had is a real book
i tried to see if the scam domain was actually registered
what does google say?
Find information on any domain name or website. Large database of whois information, DNS, domain names, name servers, IPs, and tools for searching and monitoring domain names.
It's available 
go for it
does it now? thats interesting
and I'm dubious you googled
shame that brave gave you reddit. But if you find a page that talks about it, png is usually considered higher quality but for a high quality jpeg and png, difference won't matter. Now you can make lower quality jpegs as well
Boooo
Do not try hack me
hi world. i need apy keys to theHarvester. someone have it? or someone to know where find it. message private please
what enb u use that looks nice af
Bjorn Dark Ages
Look at the night sky!

i swear go pilot likes to troll people
the who ?
you mean copilot?
I should go make some electrolytes
Guys... there's 2, just hanging around 
hehe
hey
red sun
ACTIVATE YOUR DAMN WINDOWS
what game is it π
nah
In a call with @gray sonnet
I started playing https://open.spotify.com/track/02kqNEFXbcFg22pyvUyjmI?si=01442da838d245ef
He said: "What the hell?"

again with the cursed emoji!

:smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat: :smilecat:
lol

the army of cats

i meant copilot. microsifts ai
My house smells like roast potatoes and sesame oil, it's beautiful
oooh...
yeah
Hey, you can check you are connected by pinging the ip: 10.10.10.10 if the pings are going through then you should be connected!
well... microsoft is known to have some bad troll tbh... at last they are good at it π
perhaps ... curl ifconfig,me then see IP
@sand trench Mind if I DM?
copilot never does what it says and cant spell either
yep... that sounds like microsoft
That won't work as the VPN does not touch your internet traffic
cats are the best
I just made the best fries ever
Still in a call with @gray sonnet :
Talks about a story
Says: No, OK, Yah And I didn't say ANYTHING....

Pls don't π
The email contained a link to an attacker-controlled domain (attacker.mybank.thm) with a password update form similar to a bank one. The form also has a CSRF token already set as a hidden parameter.
What I don't get is this, how can the attacker create a sub domain for a domain he doesn't control?
Vain's daily roast delivered by Matt
How can attacker create attacker.mybank.thm and mybank.thm belongs to the bank.
Can someone explain this please?
Also what's your involvement in the Crowdstrike situation
Room link?
@mossy riverDid it arrive?
Did who
Learn how a CSRF vulnerability works and methods to exploit and defend against CSRF vulnerabilities.
task 5
The Holy Grail (your PC)
No, they said the repairs they apples failed


