#general
1 messages Β· Page 430 of 1
Morning beauties
moorning
I just realized that I have the power to switch phone number anytime I like. I only have 2 phone contacts
I want to play DnD
That's great. Then I don't have to do that ^^ . Jokin.
I really enjoy to find out how things work and its important but i never calculated multiple choice βοΈπ
I'd probably either not reply or ask that they contact via email
You're the one doing the leet cert my G , You tell me
Who adviced you do to do CEH btw
i need some help over here with nmap
i used the following command -
nmap -sP 127.0.0.0/24
this is my home network
i'm using kali linux in oracle VM
for some reason it says that all 256 hosts are up when i only have 2 devices connected to the internet currently.
can anyone explain why this is happening?
no one
#room-help bruv
its just me
oh sorry
i search it on internet and i got this recomend
and ur saying it like i have a terrible mistake doing it
loopback
I think it was an attempt to appear particularly modern ^^ . And i knew already the number of the recruiter for any question on my side so i knew it was valid ππ
though im still on it (learning phase)
I envy you, shini. starting out was a lot of fun
fair, but yeah, I'm against turning third-party services as corporate devices. there's a reason WhatsApp and co aren't used, and it's Meta.
CEH is usefull when applying for Government jobs and stuff but only for that . You don't learn much in my opinion . The exam is useless . There are better certs such as ejpt
But if you're already doing CEH now , Keeping on it but do practice and learn on your own as well
You can learn and practice on platforms such as Tryhackme and Hackthebox
Why?
clammed up dog
It's not THM material.
fair
you're pinging localhost each time
of course it works
oh wait i'm supposed to scan eth0
cn i dm u??
wdym by that
that may help, local nets would usually be the 10.0.0.0/8, 192.168.0.0/16 and another wierd one on the 172 range
No , But you can ask anything ov here
I'm sure there are smarter people then me who will like to add there opinions
The metadata or the company name? Can you please explain?
Company
ah!
infamous for slurping data from all over
I was right in my thoughts. Thx. Yeah i know and it was the bare minimum like time for the interview and just 2-3 'low level informations' .
Never would send some internals, resumes, contracts etc. .
3 devices
much more realistic
@shell nova how did you know it was pinging the localhost?
okay thanks
Gave +1 Rep to @remote swallow (current: #284 - 19)
127.0.0.1
The ip
so for basic it's good?
because it didn't start with 10 or 192 or 172?
or is 127 specifically assigned to localhost or something like that?
Everyone has there own path . Personally i would never do CEH because i won't be learning anything . I would rather go with THM/HTB and then a cert of choice
But that's just my opinion
- is yourself
ah
when is it not?
You can change things
π«’
When it's changed.
like spoofing?

okay will see
No you can just change it
i can?
spoofing is pretending to be something youβre not
stop with this gif it singes my eyeballs
are you talking about only the private IP or public IP as well?
got you
is it safe to say that if i ever change MAC address somehow, then that is spoofing?
since MAC addresses are meant to be permenant i guess
you "cant" change mac address
There are tools to spoof your mac-address . and yes mac-adresses are permanent
If youβre sending data that includes your MAC address and youβre changing it before it reaches whoever youβre sending it toβ¦ yeah thatβs spoofing
But you really arenβt changing your MAC address
I like to use random mac addresses.
who you sending addresses to
got it
so if i actually change stuff that's just changing stuff
if i keep the stuff original, but change the source headers before sending it to my destination somehow, that's spoofing
Every network I connect to,
nowadays most devices use randomized mac address
Not at all.
I ordered once from Uber Eats and got a cold dinner, to top it off, McDonalds packed the wrong stuff and then blamed UberEats.
'ello.
really? that doesnt sound right
just change the NIC man π
average US fast food delivery
Where can I learn about Mac spoofing ?
Things that should be eaten right away is very much sadness when ordering delivery :/
Like tacos >_<
Simply use macchanger and you're good ( if in linux )
Are there any GUI ones ?
Not that i know of
Okay thank you
gooey
why is that?
it's really easy , you can use a tool called mac-changer it's in kali repo i guess
π probably bettercap not quite sure , but i love cli
Looks inside
python console
You might like reading this : https://www.securew2.com/blog/how-do-mac-spoofing-attacks-work
They explain how,what etc ..
Aunkon - the MAC address has info in it - like a code indicating the manufacturer. I think what you are referring to is mobile devices which... I guess 'autospoof' the mac address
Thank you
Gave +1 Rep to @remote swallow (current: #269 - 20)
that's correct .
The right hoody for the right season ππ
Nah...
Nah! Wasn't a good one ^^
The whole 127.0.0.0/8 range is localhost
hey if i am scanning for TCP 80 and 443 ports on my local network from my laptop (using VM), would the results include if my laptop's ports are open or closed as well?
result depend on what command you run
nmap -sP -p 80,443 <local network address range>
it returned quite a few
the computers and router with firewalls returned filtered, as expected
my phone returned closed
but there's one device i can't identify
nevermind its just my vpn lol
googled it up
Piracy is illegal
Buy it legally
but I want the key for free
"getting it for free" is pirating
because its 200$
Then get a job if the price of a license is an issue bro
I just wantedto know if isthere any way tot get it for fe
unfortunately, you simply can't buy WindowsXP license keys anymore
at least, as far as I know
To be perfectly fair, you can use it unactivated for 6 months or so
imo, the "right" thing to do is to simply use the one everyone else is using
hiya chickenman. Long time no see
π
In the interests of not getting the server banned from discord, I'm gonna have to delete that
what is this
this isn't exactly a "piracy" link
I know
in fact, it's often reference from microsoft related forums if you look around
That's why I didn't say I was deleting it immediately
it's a clean XP .iso with a license key included
He's complaining about the price lol. Is it a bunch, yes. But piracy is illegal and you're not supposed to talk about illegal stuff here
i severely messed up
Aight gonna have to google for it now
yeah, if Microsoft wanted to remove it they've had 6 years to do so and haven't
i'm very new to cybersecurity
and I was doing nmap port scans over my home network to practice and learn nmap
i accidentally used the wrong IP (basically used 198 instead of 192), and accidentally scanned an organizations network which belongs in a different country.
am i going to potentially get into trouble?
what should i do now?
it's like one step removed from them posting it themselves at this point
Abandonware is always a legal grey zone
agreed
would be shocked that they forgot to do so =/
got it
Freeware, shareware, bloatware and now abandonware. what other 'wares' are there?
I'm very much a proponent of keeping old stuff alive, this is just the way it goes most of the time
Malware
Meoware
if the company can't or won't support it officially, but is willing to look the other way, that's enough support for me
underware?
I think I heard donationware before
software?
Random phrase:
Its kinda crazy sometimes how ppl wanna look like misterious beings/hackees and have everywhere accounts (ig, fb and so on...) π . I've noticed that a lot lately.
software and hardware are just sitting there aswell
Generally agree, though discord may not
yeah, true
Hope they took the chance π
You are probably black listed.
you wont get in trouble, its whatever
Probably not tbh
thanks
that's good to know
The internet gets scanned nearly constantly
port scan does literally nothing unless they're running on a 0.25 core machine
π
Depends on the scripts you run
but it does look sus to the organization since i was scanning for http/https specifically
this
that is if they check their logs
It's also lost in the flood
they wont even have a chance to see you
nice
unless you flooded the hell out of them for days
At worst they have a soc and your IP is on a watch list
wouldn't they their IPS/IDS at least react to the scan somehow?
doubt it tbh
i see a lot of ports as "filtered"
Probably by shutting it down
They usually just block everything
ah!
i would be surprised if anything is even looking for scans
Soc would
these days, it probably just auto rejects traffic for a period of time and doesnt alert
But maYbe there is a strange admin who snatched your ip and swattin you now. π . Nah, jokin
But they'd be looking more for internal scans
yeah
Can't really swat with an ip
Yeah i know
lmao
i do have a vpn on
slap a box directly online, run tcpdump, watch the flood π
Public ip isn't static π
Eh, mine is
Oh I have a small http server running in docker and the logs are sometimes hilarious
i bet
I mean whoever connects to it just gets rickrolled anyway
Yeah would say. There has to be a server and or you made it static or its ipv6 as main ip already
In which way?
Nah my ISP is cool
There were a few ads in there
Mh? Kind of vip service?
Whats the reason for a static ip? Just an example.
Probably because it's fibre and they couldn't be arsed to make it dynamic
Thank you Free π
the number is hugely different, the actual speed is more realistic but I havent tried it with ethernet yet cus my pc is in a weird spot away from the router
it was around 70mps down and 8mbps up before
got it for free from isp too
Australia π¦ and windy weather
sucks , so called "fibre" network when it's fibre to the node still
stodgy government couldnt shill out a bit more to do fibre to the premises
penetration tester and red teamer are different things?
Technically the scope of a red team is a bit larger
and a bit more fun
Someone always comes in the chat to mention purple team
Blue team rules π
Purple team ftw?
I have more affinity for red.
Chaotic good is fun
Isn't red team sometimes monotonous?
Me tho. I don't think my knowledge would be sufficient for either of them. But if I did, I would tend towards the red team. As far as I know, however, there is no such classification here.
Buuut the blueis have also the task of digital forensic. Thats quiet interesting as well.
Blue teamer and being a part of the blue team are kinda different
Red teamer and being a part of the red team
The classifications also break down, as all rigid classification systems tend to
Fair. It's also hard to imagine that reds/blues only do red things or blues only do blue things, but I haven't had any experience of that yet.
On the other hand, there will already be a reason for the classification in both.
How is everyone ? π
But does it have a right to exist as a team or is it a scam like fullstack? To be able to pay one person the average of both and save money.
At least blue teams (in some ocassions) get to see interesting things
Purple team is an illusion, its just used kind of like "i use arch btw"
Wasn't there a (kali) linux distribution? Kali purple or somesing?
kali purple had blue team stuff added
I would probably use the good old "it depends".
Cursed Technique Amplification: Blue. Cursed Technique Reversal: Red. Hollow... Purple!" I alone am the secure one
Yeah
Yes heard of. But it was related to your statement that's an 'illusion' . It doesn't mean just offensivesec make the rules but it seems they try to establish it as a valid path.
Fine, thank you. Hope you are too...? ππ
Gave +1 Rep to @drowsy swift (current: #676 - 6)
Is there a quiz I can do to decide which road to follow on cybersecurity, based on my character?
I'm INTP-A character
I mean read, blue or purple
I mean red teamer, incident responder, security engineer. security analyst and pentester
Yes
Yes on thm website. What you could do as well is to read about the paths. Which task they have and so on.
The THM website also has a career quiz Iβm pretty sure
Yes I did it, but wasn't quite sure inside me about the answers
It was a little abstract
And fictionary
Its more about your tendencies as carved in stone yk.
Also you have the choice to read about them. Or at least to google or use whatever you want to | grep information
It showed me security analyst
Then it took me to a room
Web application security
Hm?
I mean after the quiz
And I don't understand difference between modules, rooms and paths
Thatβs not right
Once you click it
It has 3 categories
Click and category and scroll down. It should tell you all about the job
Yes I mean it showed me security analyst as something that suits me
So this is more blue?
Yes thatβs more blue
Check SOC Level 1 and 2 for Security Analyst
Iβm okay thank you, I might pop to the shop and get a snack before the party. Iβm ready to go, a bit sleepy
Gave +1 Rep to @sullen hearth (current: #234 - 25)
Ohu yeah, the family partey ^^ . Have a great time and try to enjoy it ππ. I bet it will be great. Snack before? Very polite. If i went to a fam party i try to get hungry af π
Btw it was a great reminder to hunt some food and mayyybe take a nap
π
Me after I become skibidi ohio
Thats the code foooor???
Sry im old.
Ok. 2 more advanced right
There is going to be loads of food there but Iβm after that toffifee.
Itβs brain rot slang
Iβm stress eating lol because I have to go out
Yes, I can understand that. I also had to struggle with a kind of addiction ^^
Edit: i mean toffifee βοΈ
Okay. I had a thought in my mind about getting hi*h but irdk. And im not sure its allowed to post it here.
But that is not a good habit. Why its so stressful?
Iβve never liked parties to be honest and I also donβt want to be stuck around family.
You know what? It's good that you're going. Only weaklings avoid situations in which they feel uncomfortable.
Ig it ainβt that good
So. Time is come... i have to eat and nap and wake up but then is thm time π₯³
because people think it is to hard for a medium
which honestly it is in shadows opinion
for those that were here before I got sent into timeout yesterday and witnessed the transphobic comments, I don't want to rehash, but the behavior of that user was exactly as this quote. - "Never believe that anti-Semites are completely unaware of the absurdity of their replies. They know that their remarks are frivolous, open to challenge.
But they are amusing themselves, for it is their adversary who is obliged to use words responsibly, since he believes in words. The anti-Semites have the right to play. They even like to play with discourse for, by giving ridiculous reasons, they discredit the seriousness of their interlocutors. They delight in acting in bad faith, since they seek not to persuade by sound argument but to intimidate and disconcert. If you press them too closely, they will abruptly fall silent, loftily indicating by some phrase that the time for argument is past."
β Jean-Paul Sartre
cause people think it's hard and they don't get flags easily
this is a hacking server..
So itβs a skill issue
yes
@viscid hill I know. IDK why that dude was spewing transphobic crap. I just got my timeout removed and I felt it important to include some context and analysis of the situation. Said user was banned for his behavior. I got a timeout because I posted his personal info..
π
doxxed
@mossy river
yep
Mate, move on please
FYI, we try not to rehash drama... try... if you had an issue, you should DM a mod. If you see comments not in line with the community, you ping a mod (or 2).
and Hydra had 4 simpler words than I
Like I have a choice π Iβm going to be taking my laptop and soju so I can study and relax in one of the empty rooms.
I try
are reactions a privileged thing in here?
no
y I no can make react?
it doesn't hurt to verify though
already have
then why your name white?
I think I need 2fa activated
That was one of my strangest thm discord moments ever... until now.
which? and which?
eminem looks so different
Yea. On stage with limpbizkit
is it him? I wasn't sure, I was trying to be funny
Don't tell me
I did 2FA. My name is still white.
It's Linkin Park
no now he looks different, like his most recent videos, wild... that animated gif tho
Oh. Thought it was funny so i tried so hard to continue π€£
W
Well, we don't discriminate 
You are
Orange? what does that even mean?
It means you are a noobie. jk
I mean. I am
That you aren't ready young padawan
lol
0x6 rank
what level must I be to not be orange anymore?
0x7 or back to 0x5 π€·
word
Is there a little guide that shows the levels and colours ?
Wrong article
figure out my bio. you get a prize
Don't feel like decoding random base64
At least better than your redirect rickroll smhsmh
Idk if there is an overview. Just figure it out about the bio or ranks on thm website βοΈ
Which one?
my rickroll is better than yours
Last room
Oh that one, I control them all from https://admin.hydrashead.net
Super Secret Admin Panel, Keep out!
Some say you can get ultra admin privileges at admin.tryhackme.com
lol
Thank you π
Gave +1 Rep to @devout palm (current: #27 - 320)
There's an SQL injection in your admin panel
You might be able to change your own color
Nah free vouchers
π«’
go do a few rooms, you'll get there although orange is a nice color
Thatβs so skibidi ohio
I wonder if THM has an issue being scanned 24/7
wait wait, I just got used to skibidi rizz... whats skibidi ohio?
Everyone is scanned 24/7
your mom?
I dunno, I gave up a while ago
maybe I should try that
am I scanned 24/7?
What the sigma
Kitten collected.
E kitten collected
Fortnite beta
Pic pls!
Skibidi ohio
Gn chat
Nice car
Very demure very ohio
don't make fun of us old people
We will stop mogging once you realize it's skibidi time.
Ik they so evil making fun of us oldies like that I am almost at end of life stage
what'd I just say
Tbh I have no idea if you're older or younger than me
older I'm sure
Heap zojja is just looksmaxing right now
Not by much if so
Im currently rot maxing
Discover all 52 runs and the best moments of the 11th TRAM-EM European Tramdriver Championship on September 14, 2024 in Frankfurt a.M., Germany. Twenty-six t...
You'd probably get further if you stopped jumping down rabbit holes to be honest
Technically correct
Practically? I don't think so
As i don't know which one is the rabbit hole 
If the prize is not getting Hydra to say skibidi ohio rizz uwu and mewing us while saying this we donβt want it
Probably the bit with only client side javascript
Wow...
yeah, nothing more. And its live.
...wow
And why are you guys not throwing every url through a proxy, smh
I don't see no client-side javascript
Because we trust the authors
Then you're probably not too bad
Wait, you trusted me? Awww that's so cute
Is Java in this room
PROBS
is Jabba in this room
π
That's worse than Shepherd betrayal
I trust you hydra
hi
See that's your first mistake
I mean yeah but it's not central, could have done the same with python
aaaaaand first time in a long while shadow asks a question in #room-help
Soonβ’οΈ

alguien que hable espaΓ±ol necesito ayuda
English only 
anybody ever tried the SIFT dfir workstation on VM provided by SANs? I'm just get tired of configuring Volatility 2/3 on Kali again and again
ΒΏCon quΓ© necesitas ayuda?
(What do you need help with?)
I'm trying to fix the error but there's no way
@mossy river Can help with that
Thanks , I need help
we don't do this here. This is an ethical hacking server. "Hacking back" is not considered ethical
I am trying to track down the phone number that he is pretending to be the seller because he has scammed me out of $500 and I want to try to recover all the information possible before going to report him to the police station in my town. This person is asking for deposits to reserve the vehicle and has scammed many more people. That is not ethical.
like I said, we don't do that here. I'm sorry you were scammed but that is out of the scope of this discord
I'm not going to ban you for now but if you persist, you will be. For now, have a nice break from THM
Can you hack more energy into me please?
beep beep beep beep coffee done
I don't drink coffee anymore. (pleas don't ban me)
drowns esqy in energy drinks
looks at the 4 faxe kondis I have downed instead
To be fair, I did build a box this morning
I am waiting for my ctf team to full solve something π
@glass nest
20 more million points to go! WOOOH!
Ranked 1400 π
Folding@home Statistics
Gfuel? I had Sneak for a while - got some for my sisters husband for xmas - apprently that was the wrong thing, as he likes it so much he gets some every month
thats pretty cool

i use the mac one on pc too but with wallpaper engine so it changes with the day
i got good wallpapers for my host machine. Im searching for kali tho.
for kali i use the stock one(too lazy to change it)
yeah i use the stock blue one with small logo
thats the nice one
anyone know where i can get this? I have serched in the stock repo of kali and also in the debian wallpaper archives
i used to have this long ago but couldn't find this bad boi
I got you
I found a frog in my sisters garden πΈ
this is the most random comment i've seen today
So farπ
had to manually tweak cus og res was stuck https://file.io/KstOyjtOiqjI
idk any other uncompressed file sharings
shared with file.io - super simple file sharing
perfecto
thank you both
I think I'm gonna have borrow Ivy, I will give her back eventually
She's a small cutie.
those whiskers, she is just perfect
Cat
So cute π
Makes sense
Ragdoll cross Selkirk Rex
Oh wow
That's the new kitty! β€οΈ
Fluffy thing
hi hackers
hope all is well
I canβt wait to go home π
Iβm so gone, I wanna go home
That soju was very strong
Why has your mind succumb to the 1 braincell sharing chat here
Donβt question my ways
Clam infection
Just heard someone come up to the door and say β uh sheβs still alive β
Talking about me
π
in what context
why you drinking rice juice
I mean if your texting fine it canβt be that bad
Survivor bias
You dont see what is being deleted
I am so gone, the room is spinning
Time to sleep
Sure
Hello, What job makes use of osint and recon mostly those things. I find them facinating and would like to do that for a job if possible. I do not know all the jobs that are in cyber.
Well forensics
Hello Ludde, thanks! I would like to work in law enforcement getting criminals.
I did
noice one!! Thanks Ludde!
I do forensics βπ»
I reached level 2 in Tryhackme, how am I doing?
Cheers budd!!!
I am not sure op$, what does it mean
last nick
short form of opsluwe
@shell nova 12 lvl badge give me
Osint is fun
yep
My favourite thing
osint gotta be the most enjoyable part of cybersec
Fr I love it
statistics
So am I over 18k among thm users?
basically top 2% means you're better/higher than 98% of others from everyone (100%)
haaa
okay
I am 46th in my own country
I think Iβm the 100th π
Hi folks π
I hate these things!!! It takes whole 10 seconds out of me, not that it means much in grand scheme of my time but the unexpected "fuck you do this" is annoying, like a forced ad
im closing in
And I forgot my fucking password and have to do it again!!!!!!!!
I dont even want to log in anymore
Which rooms/paths you are in?
Language βοΈ
Me everyday
I must extend my most profound and unreserved apologies for the regrettable utterance of expletive language that has, alas, escaped the confines of my otherwise carefully measured discourse. It is with the deepest sense of decorum and contrition that I acknowledge this lapse in verbal propriety, and I humbly beseech your forgiveness for this most unfortunate transgression.
I am quite willing to accept this formal apology. Please continue sir.
is this a copypasta or you wrote this by yourself
if its the former i am adopting it, in case of the latter, i am stealing it
my beloved
depends on engagement scope. not every pentest requires OSINT, and some orgs will specifically disallow OSINT techniques as part of the SOW or MSA
that said, when i'm doing internal pentest, i absolutely OSINT my coworkers to ensure that they aren't leaking data that is sensitive to them
i found a couple of coworker home addresses that were tied to corp assets, they didn't realize that those items were being registered under personal ownership
Hello, I am trying to log in
problem is, it is saying password is wrong. I tried resetting, but i am not geting any email
I know password is correct as it is saved on edge and i used to directly log in using that
email is also correct as i can see the spam from tryhackme
sent in #site-support but no one seems up
Please don't cross post.
You'll need to contact support who's currently closed until Monday.
I understand your disappointment in this matter, however I cannot help, and support does not work on Weekends.
hah.......... guess this weekend is for parties.....
Have you tried to manually login via different browser/incognito browser?
yeah, tested 2 browser. I even tested multiple passwords (which i have used throughout lifetime)
I have always used edge to log in so pass and email was saved. It was my subscription accout so i seriously dont want to start a new account
sadly i never set up SSO
Also could be that your email provider has some issues. Ping them to check if their server(s) are reachable.
ah. lemme check
didnt thought of that
... something seems off with outlook
their response time is 200+ ms
Its long ^^ . So might the problem is on their side.
well, thanks guys. I will go and sleep for now
will check back again. If nothing happens, i will email support
anyways, i got a question. As you might know, i shouldn't use my windows machine to run VM to learn RMA
and an external SSD is expensive
do u think i can makedo with USB 3.0?
You should use your windows to use VM's if you have the resources.
but VM which i will use for testing would also be Windows. Malware could jump out couldn't it?
This sort of chat is reserved for our advanced channels.
I recommend not playing with malware until you know how to avoid that sort of thing fully
Gave +1 Rep to @stark gust (current: #676 - 6)
oooooooh boi, it do has a pre-configured Volatility2
Iβm so bored over here, literally laying upstairs antisocial Af
I had a little discord thing pop up with what looked like a message and a user pic. It went before I was able to click on it. How can I find it again please. I did not recognise the pic or get to see a name and I am not that good at discodr
possible but unlikely. VM escapes are known, but if all you are doing is THM, the likelikhood you'll pick up something that malicious is extremely low
Try the inbox on the desktop
if someone is testing malware and doesn't know how to sandbox properly, they should not be detonating malware at all
Got made to go to a family party
But Iβm upstairs like the hobbit I am
i'll reiterate because it's so important: if you do not understand how to properly sanitize, sandbox, and airgap a device do not experiment with malware in it. This is how you open yourself up to absolutely horrific civil and legal liability
If the malware escapes from your device because you had insufficient sandboxing, it's almost the same as if you personally distributed it. Intent matters, but intent matters less in a civil suit because your escapee caused damage
Why not join the party?
do you get anxiety in those situations, I do
Nah I was too drunk to function
oh, I see. are you still drunk
No but Iβm tired now. I want cake
why not test just test the malware on a system that's not connected to any networks
πΊ
OH, then get some cake! I like cake
Guys great news!!! I got in
i did the pyramid of pain recently and found it a little confusing. There is a practical element (apparently, couldnt find it), what else is there besides youtube that could give me some kind of practice with the POP?
I checked some old emails, and there was a email regarding a new badge i got. Using a new account i checked it. Copy pasted the username
and password worked
Thanks!!
Gave +1 Rep to @stark gust (current: #615 - 7)
some malware (not super common, but does exist) is capable of recognizing saved network credentials for wifi and connecting the device. It's not an area that's safe to play in without a lot of supervision and an actual expert on hand to help
WOOOOOHOOOO shadow got github copilot for free because they are a student
even experts sometimes get popped with malware escapes, the potential for harm is huge, especially given how sophicated modern trojans are
^ this is why shadow has decided to not touch malware at all if they can avoid it
that is really intersting to know
in case of such malware, what damage can they do if someone tests them in the wrong way on a pc that's not connected to any networks?
more risk then it is worth it in shadows eyes
Chihuahuas trying to steal my cake
some malware has inserted itself into ring0, and waits for the device to reconnect. Then, the malware becomes active again.
some malware has used any plugged in usb stick to migrate to new hosts
WOOO
that's also happened
oh i was talking about having a computer that's disconnected all the time and specifically used for testing malware only
It would be fun to see you can force it to reproduce copyrighted code
nice!
i would not recommend it. even if it's disconnected all the time, you still have to get data in and out somehow - a malware payload of badusb means that you absolutely cannot trust anything you ever plug into that device
well shadow checked the allow using code from other repos in the settings....
that's a great point
shadow would like to believe they know what they are doing when it comes to stuff like this... but yeah no not gonna risk it
how do you safely test malware then?
not asking because i'm going to try it but i'd love to just have a basic idea in my mind about how it works
lots of layers of protections
what layers though
true i should do some reading myself first
i would leave it to the experts to do. You need logical and physical separation, as a start. You also need specialized tooling to monitor what's happening in the sandbox, both kernel and user space memory.
is using online hash cracker a good option
What is the vm
most recent "malware" shadow had on their machine was the xz backdoor that did not work on arch based linux distros according to checks
There's a lot of specialized tools one should be an expert in, and FOSS solutions are not great in this field. They can work, but you really really need to know what you are doing. It's not a good area to FAFO.
not for any hashes you actually care about
Hello, all malware discussions should be on our advanced channels.
if you use a hash from one of your production auth systems, congrats, you have just distributed very sensitive info to the entire world
going through "complete beginner" pathway?
Scrubz, we're not at the point yet. We're keeping things on the level to explain why this isn't a good area for experimentation.
Guys
idk im following the free roadmap atm then ill get into the detailed rooms n revise things ocne again
Does meta store whatsapp chats?
Supposedly, whatsapp is E3E but it's been compromised so many times who knows
Treat it like a barely better than SMS option.
What's e3e
A typo. E2E
Idk what's either
end to end encryption
i would not trust zuckerberg with my data
Oh
meta and windows are my favourite type of software, I luv em
Bro I just want to know if in 5 years my chats and media will still be stored
eh, honestly, big data doesn't care about individuals. They care about grouping individuals into demographics to sell market research
Lockheed Martin is my favorite war company
lets ease off the potential politics topics.
shouldn't with anyone π
still def stealing tho
@whole yew
the likelyhood that if you do something "interesting" that your data is stored but hard to know for sure
how is it stealing? you agree to it when you accept their cookies and use their sites.
The only way you could know that is if you host all your data yourself
you should read the privacy and tnc of meta/whatsapp if you are concerned tbh
I'm talking abt WhatsApp and meta
depends on the system. there are regulatory requirements for specific types of messages, the company will store encrypted messages for as long as they are required to
let chatgpt do it and summerize
Iβll look , the microwave is on fire
But after how long are these deleted?
see above answer
those regulations are getting weaker and weaker in terms of consumer protections.
I wouldnβt rely on any company for storing sensitive data
I donβt mean to be political but those are the facts
tbh always go with "digital footprints are permanent". Worst case scenario 
such a terrible idea. how do you know that chatgpt hasn't hallucinated something critical in that summary if you don't know the original? chatgpt requires a domain expert (in this case, someone who has read and understood the original work)
its very easy to let it show you where the thing summerized is
In terms of consumer protections, absolutely. Government regs vary and often a company will obey the absolute stricted regs because it's easier to apply one set of policy than to apply policy for each country they do business in
most advanced llm gets confused with strawberry. o4 does better job apparently. but human conception of a topic > ai conception
so, read yourself
Bro even chats are insane. Like is it the government who rules us anymore?
Iβm not sure water and electrics is what youβre supposed to do
you can microwave water, it just boils. just don't microwave water in a metal bowl or cup
there's certainly a lot of argument around the topic of privacy
usually yes, i'd agree that people who are serious about their privacy should read the privacy policies more carefully
do... I.. Microwaves .... do you know how microwaves work
large wavelengths i guess.
does YOUR microwave use ARCH LINUX to operate? no? YOU are not a real hacker.
radiating and vibrating the atoms
i just thought of something
Gopi Bahu is Love β€οΈ
a microwave that runs on redstar OS
I use microwave arch btw
i microwave arch btw

specifically tuned to heat up water molecules
life is all about distractions from the horror of living
im saving that quote im fucking ghandi
haha gandhi*
All of the forza games are like 75% off right now but Iβm poor 
gndahi*
or its the collection of little distraction in the beauty you try to find in this chaos 
I died #blownupbymicrowave
Wow, like a dollar? Damn, I sunk a lot of time into the first one, thanks
Gave +1 Rep to @pliant cairn (current: #615 - 7)
my microawve when I installed doom in it
i got it for even less actually. i got it for 50 Rupees lol
It was Β£0.84 for me, the same as some instant noodles are now
apparently it has got a lot of content and its going to be offline mode too.
unlike the one before
their choice of going broke is to make sure the game doesn't die apprently. so, there are a lot of concurrent players now
my favourite hobby ngl
Iβm gonna wear my slippers to the shop ποΈπποΈ
I am 3p off using my steam balance π¦
Nooooo
i shall sell a csgo case
DIY roomba is on my bucket list of projects
i removed my payment method stored in steam cause i don't want to go broke.
it was a good decision
I had a long break from CSGO and came back semi-recently, to find the cases were wortth $$$. Think I made about Β£400 to put into stocks π€£
lovely
The steam decks always go out of stock as soon as they go on sale I swear
yeah..snapped up real quick
Are you planning on getting one?
thoughts on attackbox vs openvpn?
my own machine unless I'm travelling
i mean for participating in thm rooms
yeah, this
OpenVPN
so openvpn right?
because you can't access thm rooms over the regular internet
Answering on behalf of jayy, yes
Do thm certificates work?
microwaves also have a high chance of creating superheated water in the microwave unless you have something to start the boiling and conversion to steam
i.e add spoon to water after microwaving it and it boils over or explodes into steam
I got one the other day
Most common use of a certificate is help with getting employed, so if they "work"? Yes, but aren't officially recognized so not to an extent others might
Especially when Tim Taylor keeps adding rooms to paths π
kebab
noo the candy called turkish deligth
A certificate is more important that learning to you I see π π
I read the whole Lion, witch and the wardrobe thinking Turkish delight was some sort of turkey soup
Turkish delight is a soft thing
untrue :3
oh yeah? tell me everything you've learned ever
thereβs too much to list and Iβm not in the 1up competition
Ooooo looks pretty
Cant list anything cus you hate learning π π
Okay
feath3rz is somehow better then shadow at tryhackme
lies π
Well now yall have to compete
@whole yew maybe I don't have a full picture of privacy but this is from the WhatsApp privacy policy in the eu
I do like competition β€οΈ
But not when itβs a pointless measuring contest
What's that
one of the customers mistakenly requested for deletion of their official facebook group
was able to recover after 8 months
digital risk protection
So how long do you think they hold it
we basically protect trademarks, find scam website and stuff and take them down
I remember reading upto 90 days
but now that i was able to recover after 8 months, i dont know
meta group
all fall under same group so they may retain data for quite long or might never delete
I gets cold outside. Any cool clothing brand suggestions?
I need sweater and hoodies
....
Yea but this privacy policy is for Whatsapp media content not Facebook group, ofc they are correlated but I haven't read fb privacy policy abt groups
I'll check it out now
I am not fashionable :< I cannot help
my point is that they mentioned that they delete all data after 90 days yet recovered after 8 months
Too bad
do tag me on that. I need that policy to show at office and make a note regarding this with manager
Ok
You workin for meta?
Ah okay
ever heard of Uniqlo?
i heard their products are quite good
never tried it
oh i cant attach images....
search 90 on this page
u should find what i was saying
Nope. But google did i think. Let me take a look
ngl i already forgot what u doing
lol
how do i get more privileges here like reacting to people
Can't find any 90
To verify your account
verify.txt
verify.txt
I dont know how to use the docs but type '/verify' and use your token from thm @idle beacon
its weird how they kept it beyond 180 days
stuff happened......... due to this line
This privacy policy seems a lot more lenient than WhatsApp's
I didn't find any "in case we can't delete it" in WhatsApps
our company doesnt deal with whatsapp so i never read that policy
but facebook and insta have similar policies
https://foundation.mozilla.org/en/privacynotincluded/ This might interest y'all
why would a vacuum cleaner steal data
Bro tbh... As long as they don't keep it for years on end it DOES bother me because of how the power abuse but I was paranoid abt this because someone sent content of me on WhatsApp and I was worried abt that
ffs, i forgot my bookmarks are there
thats how u give away PII
great
unless it was CP, and police was reported, u are fine.... i guess
I have read it. Not new but it is interesting.
No no it wasn't porn in general
Or anything illegal
Just personal things
ah
And I mean I know it won't go around for people to see it but yk I don't want fucking whatsapp to look at my shit
If they don't keep it in like 5 years I am not incredibly worried abt it
if they are retaining data for 5 years, more than anything, i would be impressed
Depending on governments making requests, that would only apply if there is no regulatory or legal requirement
the literal quantity would be insane
Hello !
Just started to learn, and I'm trying the first EasyCTF.
It gaves me an IP, so I scanned it with nmap, but it's not working (host seems be down).
Any tips to get started ?
Thank you ^^'
Gave +1 Rep to @stark gust (current: #566 - 8)
someone got root in the new medium machine ? π
Sure you can get root pretty easily π
π¦§
it does not steal data... it vacuums it up
So glad Iβm home π
π¦§
truly fascinating
the amount of data points that make people unique online is huge
how was it yesterday?
I hope my 200 hours of talking to myself in empty voice chat were private or else im getting 10 life sentences
Wait what happened yesterday π
You did have a drink or two if I'm not mistaken π
not really a good sign if you don't remember π π π
that was like today
Oh I had one drink. Enum put up with me for like an hour and then I left call and went to sleep.
hi
Tonight I had a few drinks and slept for four hours
4 hours is a miracle
I'd probably sleep for 14
I missed the whole party
Every day is a party if you have unlimited supply of rice based alcohol
(thats terrible wisdom)
that's the general misconception with alcohol, if you drink until you're dizzy, throw-up or don't remember what happened the day before, you're doing it wrong. You suppose to enjoy the drink, the palette of flavours, its complexity, finesse, etc π
Alcohol is never lacking in my house, but I don't get drunk π
I did enjoy the flavour, thatβs why I drunk it all haha
Also I only like like once a year
dolphin!!! π how are you??
good morning! not too bad, waking up, got my coffee. hbu?
zumi having a rough day
Hiii


