#general

1 messages · Page 465 of 1

rough barn
#

But like how did he get an interview for a pentester without knowing anything

sick lance
#

You'd be surprised how many people blindly apply to jobs on LinkedIn.

frigid geyser
#

Good morning guys

rough barn
#

Surely he should have been filtered out at the application stage

tawny ruin
#

It could also be a generic security related software engineering position

#

Or they might have thought it’s one

arctic cradle
#

was the new profile update reverted for some reason?

#

the dashboard page of the user on THM website is what I refer to

rapid merlin
#

Morning 🙂

rough barn
#

My dashboard has always been the same

#

Oh I saw they changed the icons for the learning paths tho

arctic cradle
#

today it's back to the old one

rough barn
#

nah I mean I never got a new one, I've seen the same one all this time

arctic cradle
#

oh

rough barn
#

One thing I've been wondering about since I signed up for the paid tier is my "premium roadmap" is missing

arctic cradle
#

premium roadmap?

#

the only roadmap I followed was @sand trench her roadmap is one of the best and well constructed imo

#

you can check it in the pinned posts

rough barn
#

So before I signed up there were two roadmaps under "learning roadmap" "free" and "premium" now I only have free

#

So I've been doing the "learning paths" instead

arctic cradle
#

hmm, I may be wrong but I think you're referring to free/premium rooms

#

paths include both free and premium rooms so now that you're a subscriber, the premium one don't show but are included in your account

#

but take my information with a grain of salt

rough barn
#

I've done pre-security, and introduction to cyber security, I'm now doing complete beginner

#

Yeah if you don't sub you can't fully finish pre-security

#

I don't think anyway, cause some rooms aint free

arctic cradle
#

I think you can but it's just the free rooms that you complete

#

don't know how the cerficiate thing works as a free member

#

but the premium is so worth it and it's not that expensive as well

rough barn
#

Other places that were teaching this were selling their courses for several hundred dollars. 14 dollars a month is a good price

arctic cradle
#

definitely, yup

#

guys, Scrubz is offline

#

nah I'm kidding, don't do that

#

I just like the gif

rough barn
#

Yeah like I first thought this might be something fun to learn when I saw stuff from Occupytheweb. And bought his book. But damn several hundred dollars to sub to his site. SureBruh

#

I don't think tryhackme teaches scada hacking though. But is that a skill you really need?

slender scaffold
#

🤔

arctic cradle
# sick lance Yeah.

that's sad, it was looking really neat, is the reason public why it's been reverted? if not, are we going to see it ever again? I really enjoyed the new layout

sick lance
#

It's going to be refined slightly, I think.

arctic cradle
#

sweet

rigid cypress
#

Someone to chat with

#

😆

median swift
#

hello guys, i have a question that id like to ask?!

devout palm
#

Just ask (:

slender scaffold
sturdy oar
#

ayo, dose anyone have any interesting 'hacktivities' like meetups, cyber spaces, open CTF's at amsterdam this week?

slender scaffold
#

This is such a quiet time

loud marlin
#

oh no wrong one

steel aspen
#

Are there any good CTF videos to watch

blissful mirage
#

hi guys, new to tryhackme and discord. I have a question regarding the Cyber Kill Chain room - task 5. The question says - Can you provide the name for a cyberattack targeting a software vulnerability that is unknown to the antivirus or software vendors? - The answer is "Zero-day Exploit" right? it keeps saying it is incorrect?

pliant cairn
#

my shift ended like 15 min ago but still have people scheduling calls till an hr later

chilly veldt
#

oof

pliant cairn
#

i know a few who schedule post my shift hours after asking my shift end time

atomic kernel
#

Anybody up

slender scaffold
#

I am trying to finish a report

pliant cairn
#

annoying fr

atomic kernel
#

Need a lil help

slender scaffold
#

So I can sleep

#

Ask and maybe ye shall receive

atomic kernel
#

I wanna play koth but every time I try to join it says koth are for intermediate level

#

What rooms should I complete to play koth

slender scaffold
blissful mirage
#

you're a star feath3rz - thanks

slender scaffold
#

Tbf I never played with the option. But that might be a way to start finding answers

pliant cairn
#

i thought it was level cap

slender scaffold
#

It might. I’m just saying what the faq says 🙂 so time to find out when can you update your experience level.

#

Or if anyone can update it no matter their exp

pliant cairn
#

im getting exhausted :/ not feeling like doing anything

#

and bored.

slender scaffold
#

I’m avoiding my report

#

I shouldn’t do this

pliant cairn
#

yea even im avoiding my work.

#

i want to go for a vacation tbh

tired moth
#

getting a job in cybersecurity would be easy if blackhats didnt suck at phishing

pliant cairn
#

blackhats dont phish. scammers phish.

tired moth
pliant cairn
#

we only have good ppl in thm

tired moth
#

he asked me if i wanted nitro for free

slender scaffold
#

Advise a mod.

outer rivet
glacial oasis
#

yo guyz

tired moth
glacial oasis
#

this website tryhackme has many courses
and i wanna learn the basic networking for managing a ubuntu server and make it secure
Which one should i opt for??

slender scaffold
#

;_; I suck at networking… I dunno the answer

glacial oasis
#

i just want to know the best course for me

outer rivet
#

?

glacial oasis
#

thnx bro

#

can i do these all in a vm of kali linux?

tired moth
tired moth
glacial oasis
#

ok thnx bro

tired moth
#

goodluck with your journey bro

slender scaffold
#

love this bro atmosphere

outer rivet
#

God level

tired moth
#

gg simon

slender scaffold
#

yay god level

chilly veldt
#

👀

tired moth
#

im top 1% on htb academy

karmic geyser
#

GGs

slender scaffold
#

Nice job

tired moth
#

thats offensive!

karmic geyser
#

I love you bing.

slender scaffold
#

=_=

karmic geyser
tired moth
#

is thischat always full of bullies

karmic geyser
twin ridgeBOT
#

Gave +1 Rep to @outer rivet (current: #492 - 10)

karmic geyser
slender scaffold
#

!8ball should I finish this report?

chilly veldt
#

yes

slender scaffold
#

Magical Bella

chilly veldt
twin ridgeBOT
#

Should I finish this report?
:8ball: Without a doubt

slender scaffold
#

Gawd Robocop

steel aspen
#

I really don't like SQL

chilly veldt
#

have you tried noSQL instead?

slender scaffold
#

Yesssss nosql

steel aspen
#

information schema, group concat .schemata and table column enumeration is annoying to learn lol

chilly veldt
#

@jagged yarrow wish I could join, but I am flying to spain the 15th 😄

#

and also from Denmark sip

glacial oasis
#

yo guyz

#

i have a issue in vm

#

where can i ask?

pliant cairn
#

google

chilly veldt
#

what kind of issue

lone thistle
steel aspen
#

Wheres an easy way to learn SQL? Both SQL rooms and I'm still not there with it

chilly veldt
steel aspen
#

Even watched a John Hammond video

tired moth
slender scaffold
#

Sql is good with practice

ashen parrot
#

Hi guys

restive harness
#

yo

slender scaffold
#

o/

south egret
#

\o

restive harness
#

|o|

slender scaffold
#

orz

steel aspen
#

Just a few of the command syntax I don't get

boreal scarab
#

@slender scaffold BOOPS!

slender scaffold
#

Why are you awake!!!

steel aspen
#

Ones above I mentioned being the main ones

boreal scarab
sick lance
#

I might go to London

boreal scarab
#

Why are YOU awake?

boreal scarab
slender scaffold
steel aspen
slender scaffold
#

Though I might put in my two weeks this week

boreal scarab
slender scaffold
#

I got a job offer as a Threat Analyst ❤️

steel aspen
boreal scarab
#

Get up and everything is cracking

sick lance
boreal scarab
slender scaffold
#

No more software engineering!!! \o/

steel aspen
#

I mean free pizza is free pizzza c'mon

boreal scarab
steel aspen
#

I'd go to it but I'm literally halfway around the world

tender lynx
#

free pizza

steel aspen
#

It's from a song by The Clash

slender scaffold
#

What ;_;

#

Is it cause of Milton?

#

Nuuu

slender scaffold
#

Yeah it looks terrible

steel aspen
#

I'm stalking Ben CMNatic, not a bad song bro listening to

sick lance
#

Although, my project has shifted...

#

It's now more red teamed

slender scaffold
#

Yikes

vagrant terrace
#

I want to ask about the basic policy of Wirewall

slender scaffold
#

The brick needs new

pliant cairn
#

firewall?

tired moth
#

did your hous get hacked

vagrant terrace
#

May I?

#

no no

#

I'm working as a Vulnerability Assessment Consultant

tired moth
#

brutforce vuln

steel aspen
#

Has someone seen heck's profile on this server? Is his bio thing his or legit??

#

Hopefully not a physical firewall

floral turtle
#

Hi guys! Do you know where or how to get started on decoding a message in base 16 string?

steel aspen
#

I feel like one of the mods should be seeing this

vagrant terrace
#

The inbound policy is set to 'deny all,' and shouldn't the outbound policy allow traffic from a specified IP to any destination IP?

floral turtle
pliant cairn
steel aspen
#

Then yeah Google lol plenty of resources

tired moth
boreal scarab
vagrant terrace
#

Can I get the anwer?

floral turtle
#

I did google and it didn't help

tired moth
steel aspen
boreal scarab
steel aspen
#

Oh true yeah

pliant cairn
tired moth
pliant cairn
vagrant terrace
#

For the general Firewall

#

policy.

tired moth
#

beerise is a meme stealer

vagrant terrace
#

At home

tired moth
vagrant terrace
#

or at comapy

#

company

boreal scarab
slender scaffold
#

Sending syn and not getting acks lol

steel aspen
#

hecks profile says something weird like suspected to be a part of something bad

boreal scarab
steel aspen
slender scaffold
#

No snacks!!

vagrant terrace
#

If the inbound is set to 'deny all' and the outbound policy allows internal IPs to reach any destination IP, won't that enable communication with the outside?

tired moth
#

If the inbound is set to 'deny all' and the outbound policy allows internal IPs to reach any destination IP, won't that enable communication with the outside?

drifting mural
pliant cairn
# vagrant terrace For the general Firewall

generally if the firewall has multiple interfaces that has for datapath, Natting etc., then the inbound datapath interface(or pool) has deny all by default. And for outbound it should have application default. Im talking wrt pfsense or palo alto as an example.

steel aspen
#

Can a mod reply? I'm confused on a user

eager marsh
tired moth
eager marsh
#

I’m not a mod

#

And neither is he

drifting mural
eager marsh
#

Good day to you

drifting mural
tired moth
#

generally if the firewall has multiple interfaces that has for datapath, Natting etc., then the inbound datapath interface(or pool) has deny all by default. And for outbound it should have application default. Im talking wrt pfsense or palo alto as an example.

steel aspen
#

Scrubs are u around to contact a mod?

south egret
steel aspen
#

Oh

#

Looked legit cos it

eager marsh
steel aspen
#

Has a thing to hover over

slender scaffold
#

Chat sure is weird at this time…

south egret
vagrant terrace
#

I don't know exactly what the customer Company's external firewall is, but my colleagues say that since the inbound is set to 'ALL DENY,' no matter how the outbound is configured, there is no internet connection.

steel aspen
eager marsh
slender scaffold
steel aspen
#

Oh nvm it is a aprt of the normal bio it's just changed I think

boreal scarab
eager marsh
#

Is Ra hard at all for anyone?

pliant cairn
tired moth
#

I don't know exactly what the customer Company's external firewall is, but my colleagues say that since the inbound is set to 'ALL DENY,' no matter how the outbound is configured, there is no internet connection.

slender scaffold
pliant cairn
#

@tired moth

slender scaffold
#

I’m gonna guess age is a factor in the answer

vagrant terrace
#

I understand that in the firewalls I know, inbound and outbound policies are bidirectional, but even if the inbound policy is set to 'ALL DENY,' the outbound policy can still allow internal IPs to communicate with the internet.

#

I said it to my colleauges, but they said I'm wrong.

pliant cairn
slender scaffold
#

Wire shark :3 get them receipts

pliant cairn
#

in a client meeting i was furious and said. "i aint got time to teach how networks work. please learn your fundamentals and come back with your queries."

sick lance
pliant cairn
vagrant terrace
twin ridgeBOT
#

Gave +1 Rep to @pliant cairn (current: #532 - 9)

karmic geyser
#

@tired moth Salam bingbong9

sick lance
karmic geyser
floral turtle
vagrant terrace
sick lance
#

Let's not take random advice from random members.

vagrant terrace
fair dawn
vagrant terrace
neon merlin
#

Is there a shortcut to open a ticket without having to talk to the bot? NotLikeThis

sick lance
slender scaffold
#

@rapid merlin hopefully nothing bad happens with Milton :/

#

Been watching it cause a friend I know is also in the path

neon merlin
#

Alright I'll email. I thought it would be easier through the site though to prove my identity

vagrant terrace
eager marsh
#

The ability to speak does not often make you intelligent

sick lance
sick lance
rose spruce
vagrant terrace
eager marsh
#

I hope you will be pleased with my very first room I am developing

sick lance
slender scaffold
#

it’s a morning o_o in THM 😂

#

Or afternoon :3 I mean whichever

#

_< yikes

tardy finch
#

@whole yew are there roles for certifications you passed ? I see you have some certificate related roles

slender scaffold
#

I’ve seen them roles

tardy finch
#

How do I get them ?

slender scaffold
#

I think it’s interesting it’s traveling East o_o

tardy finch
slender scaffold
#

Might need a mod to answer that one lol. I don’t wanna give incorrect info

#

I’ve seen a lot come from the Atlantic side mostly and then rip up the coast

#

Just like where I’m at.. hurricanes come from the east and move toward us west.

tardy finch
#

Its hitting central/northern Florida by the gulf coast from what I read

sick lance
#

They need to show a mod some sort of proof.

sick lance
steel aspen
#

Confused has been settled though

#

Confusion

sick lance
#

Nah,.can't see it

steel aspen
#

Nah I think it was just the bio but it looked different from the last time I saw it

#

Don't remember it having a hover thing.

sick lance
steel aspen
#

Okay thank you

dawn crater
#

Anyone have a thm discount voucher for me🙂

crude stump
#

No

#

Begging doesn’t get you one

south egret
#

what does

crude stump
#

Waiting for a community giveaway and trying your luck for one

silver sky
hollow mortar
#

gm

steel aspen
#

Night all

boreal scarab
steel aspen
#

1:49am is morning yes 😎

#

Gotta wake up at 7 😬

boreal scarab
steel aspen
boreal scarab
crude stump
#

Land of the free 🦅

slender scaffold
#

uhh….. o_o

sonic oriole
#

What is the flag that you obtained by following along
whats the answer to this?

south egret
twin ridgeBOT
#

I finished my report. Are you proud of me? ❤️
:8ball: You may rely on it

slender scaffold
#

Awwww ❤️ love you too Robocop

sick lance
#

No, your friend is doing something illegal, we won't be helping you.

Obviously don't click their links

reef roost
#

One message removed from a suspended account.

boreal scarab
#

Nap time

reef roost
#

One message removed from a suspended account.

split plover
boreal scarab
novel ingot
clear jackal
#

If the message got removed, I'm assuming it contained some form of legally ambiguous language in either GB or the US

#

CFAA is overly broad

boreal scarab
#

Nvm

#

I big dumb.... barely had coffee

primal kestrel
#

another tuesday another 3-5 thm rooms

empty moss
#

Hi all, quick question. What's the rules/guidelines around producing write-ups for CTFs on THM? Thanks in advance 🙂

south egret
sharp citrusBOT
south egret
#

bruh i dont know how to use this bot

crimson ledge
#

Better to let it learn how to use you

glad marsh
#

hey guys anyone has problems with starting attackbox now? Getting VM_Parsing_Error

severe condor
sick lance
sick lance
primal kestrel
#

ai elon pfp cherry on top

#

so funny

#

and without reading the original message it seems like, "hey my 'friend' is making this malware and is looking for some help 😉 "

sick lance
inland vault
#

hi

reef roost
obsidian lava
#

how to hack wifi password tell me

cosmic pendant
#

lol

crude stump
#

Double whammy

cosmic pendant
#

"oh Mighty GOogle"

sick lance
inland vault
#

wow

#

bro

half island
#

Hey, quick question, can we sponsor someone who wants to purchase premium ?

sick lance
sharp citrusBOT
sick lance
#

Nope, that's redemption

half island
#

In my memory, we had 5% reduction over the swag shop. This does not exist anymore ?

rapid merlin
#

Good afternoon

primal kestrel
#

i trust

rapid merlin
#

I trust no one 😂

crude stump
sick lance
#

They will give you a code.

sick lance
crude stump
hardy totem
#

I’m trying to connect to my tryhack it showing white blank screen

hardy totem
rapid merlin
hardy totem
crude stump
sick lance
tired moth
sick lance
tired moth
#

your a mod

sick lance
#

Correct, you're not a mod. 🙂

hardy totem
crude stump
#

Take a good guess

crude stump
#

Failed embezzlement

torpid furnace
#

Hey

hardy totem
#

Hello

sick lance
tired moth
tired moth
sick lance
crude stump
#

I think they are

#

There just jealous

sick lance
#

Nah, I'm not.

sinful moon
#

lol I would love to attend the in person THM event… if it wasn’t an ocean away. Oh well

umbral bay
#

New THM profile page is back. 😎

sick lance
rapid merlin
#

I dance

#

I dance around the flat

silent forge
#

Maybe My Soulmate Died 🎶

primal kestrel
#

is using a tool like ZAP's spider (& ajax spider) against bug bounty rules?

crude stump
sick lance
#

Check the bounty

sinful moon
#

Thanks but I don’t need to fly to the UK just for Pizza and a QA lol

arctic cradle
crude stump
arctic cradle
#

but fits the meme perfectly well

tropic sigil
#

@jagged yarrow

mossy river
tropic sigil
#

How does he have animated profile picture with nitro basic 🤧??

#

wondering

mossy river
#

I’m assuming it’s because he hasn’t cancelled the plan from since the change

arctic cradle
#

but nitro basic allows you to set an animated profile picture I believe?

errant hawk
arctic cradle
tropic sigil
#

lol

arctic cradle
#

his avatar is very cute, though

#

I can watch it all the time

sick lance
silver sky
#

Today's chest pump is unreal 💪

tropic sigil
tawny ruin
#

I thought that's an elevator, not a chest pump 🤔

misty kiln
#

I am playing CTF name all in one.. I saw LFI vulnerability. I tried /etc/passwd it worked fine.. But when I tried ../../../../wp-config.php it not showing anything.. But after php://filter/convert.base64 encode it show..why I can't directly print it out?

arctic cradle
#

elevator? isn't that a mirror?

tawny ruin
#

True.

south egret
#

i thought that was a refrigerator handle

arctic cradle
#

it definitely is

pearl raven
#

Walk in freezer with a mirror.

south egret
#

where tf is my guy pumping irons then

arctic cradle
#

guy? what guy

misty kiln
#

All in one @sick lance

sick lance
misty kiln
#

I wonder what is the difference btw them. I asked to chatgpt he saying.. It is sensitive file so that's why I can't directly access.. But /etc/passed is also sensitive file right then how I can't access wp-config.php file directly

misty kiln
arctic cradle
pliant cairn
steel aspen
sick lance
#

Then we can't help, sorry

misty kiln
#

What you mean by active...?

arctic cradle
rocky mulch
#

is it allowed in the rules to watch for guides when stuck in CTFs ? (or it's just you can't share infos)

rapid merlin
# pliant cairn eww javascript

👔 Merch drop 2023: https://posix.store

Javascript programming language

Interview with a Javascript developer with Jack Borrough - aired on © The Javascript.
Find more Javascript opinions under:
https://hackernoon.com/how-it-feels-to-learn-javascript-in-2016-d3a717dd577f

Programmer humor
Javascript humor
Programming jokes
Programming memes
Jav...

▶ Play video
#

😄

arctic cradle
arctic cradle
steel aspen
misty kiln
#

No

arctic cradle
#

it amazes me that some people still use their phone instead of smashing the print screen integrated function in Windows

misty kiln
#

There is writeup available.. But they don't mention how it works..

misty kiln
sick lance
south egret
pliant cairn
rapid merlin
pliant cairn
#

this shows how confused they were

#

and they still are

patent fern
#

What is the name of the service that lists Systems Internals as the manufacturer?

pliant cairn
#

and everyone who uses js are

karmic geyser
#

@tired moth 👀

finite rock
#

portswigger pikapika

sick lance
#

Now it's apparent...

void zodiac
#

Discord got banned in Russia 😶

unreal cave
#

hey guys. Anyone got darkmode on THM? there's this one extension for it on the chrome web store buy doesn't work. Any reccs?

rapid merlin
steep wren
#

Guys i have a problem while i'm installing Parrot OS in virtualbox. Whenever i "Install Parrot" and it says "Done" and it restart my system it gets me back to "Try / install" and it's like an infinite loop. I tried everything i've seen online and nothing seems to work. Is there anything else u can suggest guys?

unreal cave
void zodiac
#

They offer this option on the website

steep wren
twin ridgeBOT
#

Gave +1 Rep to @void zodiac (current: #2261 - 1)

steep wren
open shale
#

Who provided the auxiliary/scanner/ssh/ssh_login module? what is the info command? please.

rapid merlin
#

I always think maybe mines blocked lmao because my block on my other account was so long

silent forge
#

or just send me playlist

rapid merlin
silent forge
rapid merlin
# silent forge 😕 okey

You know each playlist literally consists of four songs. I am the sort of person where if I find a song I like I never stop listening to it

silent forge
#

for me my playlist is likes songs

rapid merlin
#

I have different ones, different ones for different moods

silent forge
rapid merlin
#

Yeah

silent forge
lone thistle
sour lance
#

Hello

rapid merlin
restive harness
sick lance
#

Oh, dlc for Diablo 4 is out today

novel sky
#

guys does thm subscription renews automatically?

sick lance
#

Yes

novel sky
# sick lance Yes

the "subscription" tab is showing as if i dont have a subscription active... weird

novel sky
#

i just today wanted to cancel it and i saw it like this

hushed adder
#

I'm feeling really weird, like I want to get into TryHackMe and start working but at the same time I do not want to as soon as I start working I end up getting distracted by another site every couple of minutes. Is there anyone else like this? how can I get past this issue?

shadow tiger
hushed adder
#

I totally feel you on that. Lately I've noticed that whenever I sit crooked I end up putting my feet on the table and before I know it I find myself just watching a movie😂

shadow tiger
#

Yeah, it really is counterproductive

#

But procrastination is definitely part of it, so you don't have to avoid it altogether

hushed adder
#

I'll try to fix my posture and get to work after a nice shower andthanks for your input

shadow tiger
#

No biggie

timber galleon
#

Hello

#

do any of you know allot about port 1801?

high mulch
clear jackal
celest valve
#

If i start using free try hack me what learning path should i start going or where should i start to learn pentesting or offensive security or some red team things

rapid merlin
#

It was warm outside right, so I dropped my coat at home. Sits down in the library and it POURS outside 🙃

pliant cairn
#

youtube did something with the ads.

#

generally ad block works. but now i guess they made it unskippable

worn thorn
#

they bake it into the video stream

pliant cairn
#

yeah pretty much

#

but im glad i found an amazing ad

normal fable
#

hey yall.. I'm still alive.. just been very very busy with life. 🙂 Hope yall are doing well.

timber galleon
timber galleon
#

queuejumper

#

its for pen testing i cant find one for rce so i tried making a payload which downloads it from my http server and it worked but i need to target the port socket itself and not the web page

clear jackal
#

No, what's it for as what is the work being done for? School, work, etc?

timber galleon
#

penetration testing

#

for work, trying to understand more about the message queueing service itself and how it communicates so i can eventually design a poc

clear jackal
#

Ah, ask your seniors

timber galleon
#

eish

#

thats the issue

#

no seniors

#

there is no poc for this? how can i ask them, i dont think you understand...im designing a poc and need the code revised by someone who knows exactly how the service communicates...

clear jackal
#

This may be getting into advanced topics

timber galleon
clear jackal
timber galleon
#

ahhh no access

clear jackal
#

I asked for mod determination on where this belongs

sick lance
#

Ah, here is James, I was about to start, but James will be better than I.

sharp citrusBOT
sick lance
#

Or was... kekw

I hope you didn't stop typing because I started @naive violet kekw

celest valve
sick lance
# timber galleon ahhh no access

The article shadow linked will show you requirements, however this sort of chat goes in that channel;, and ideally it's not a good idea to get support from random people on the internet regarding work, there must be someone you can get support from?

grave bobcat
#

Hi bros

sick lance
#

hi sisters

grave bobcat
#

I am a man

#

not your sister 😅

bleak bluff
#

are ranking percantages removed from site?

sick lance
#

Funnily enough, I'm not your brother... 😅

grave bobcat
hushed adder
grave bobcat
#

🌹

bleak bluff
#

cuz i can not clearly see my percantage that im in

hushed adder
bleak bluff
#

yea

grave bobcat
#

Is it hiden ?

timber galleon
#

proving vulnerabilitys are more of a goal th

naive violet
bleak bluff
celest valve
#

Lol

sick lance
timber galleon
grave bobcat
timber galleon
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #1 - 2848)

celest valve
#

Whats poc

timber galleon
#

proof of concept

celest valve
#

Wat

sick lance
sick lance
timber galleon
timber galleon
# celest valve Wat

A PoC (Proof of Concept) is a demonstration that proves a vulnerability can be exploited.

boreal scarab
#

I broke TrueNAS Scale shell!

grave bobcat
#

bros

remote breach
#

hey people halfway through the redteaming path but feeling a bit lost as what to do after i dont have a formal cyber education and was considering doing the ceh exam but its way outta my price range any and all advice will be appreciated

grave bobcat
#

i think we need a dark mode on the site

sand fractal
#

guys i need help some guy doxing my family in school and he gives information and make fun could anyone help me get revenge please?

sand fractal
#

bro

#

i need real revenge

#

i aint no shit snich

sick lance
#

"Real revenge" would be illegal, and not advised.

sand fractal
#

i just need to doxx him back tha's all

#

not hack

sick lance
#

Doxxing is illegal...

sand fractal
#

he did dox

sand fractal
#

what?

muted nebula
sick lance
muted nebula
boreal scarab
#

We're not helping. Doxxing is illegal. Please go talk to your principal, or the local authorities.

sand fractal
#

bro

sick lance
#

If you keep asking, I may mute you/remove you from the community, as you're not here for ethical, legal reasons.

twin cipher
#

how do i be haxxor

boreal scarab
sand fractal
#

the group says tryhackme

twin cipher
boreal scarab
sick lance
#

The group promotes ethical hacking, and cyber security.

#

what you're wanting help with, is neither of those.

drifting mural
sand fractal
#

what about public info?

sick lance
#

Releasing info in a threatening manner is illegal.

celest valve
sick lance
#

Please drop the subject, now.

sand fractal
#

no just public , like oculd anyone go to jail for doxxing publc info

#

could

placid sand
#

I have a question that I'm hoping y'all may be able to answer for me, if I'm receiving threats from someone via snapchat is there a way to reverse look up what number they're attached to? Or any other information? Also I apologize if this isn't the right group, I don't really know who else to ask

placid sand
#

If I only have a username then what other information can I provide them?

boreal scarab
#

There's a term for it. And we, for the ethical side of gathering info, do not call it "doxxing". "Doxxing" we consider the unethical side of info gathering.

naive violet
celest valve
celest valve
rapid merlin
#

what is more fun event wise, blackhat or defcon?

naive violet
#

Defcon for sure

celest valve
#

So popular

warped summit
naive violet
#

Blackhat is more corporate aimed, defcon is more hacker-culture aimed

night quail
#

Hi

naive violet
celest valve
#

Np

finite rock
tired moth
#

hi

celest valve
#

Hi

finite rock
rapid merlin
#

👋

celest valve
tired moth
#

why is there so much mod abuse in thm

finite rock
rapid merlin
#

😎

finite rock
#

HTB goes crazy lol aniguns

rapid merlin
#

I’ve not been in htb in ages

mossy river
rough gorge
#

No new room today?! 👀
New schedule gets me confused 😅

crude stump
rapid merlin
naive violet
#

You get bsides and 44con in the UK

#

Some regional defcon or owasp chapters, a couple of 2600 clubs

muted nebula
eager marsh
#

Bsides is also in Austin

#

Never been tho

rough gorge
muted nebula
sick lance
#

Tuesday - Friday is the days, unless they've changed.

rough gorge
woven prairie
#

hello can anyone help me with virtualbox?

sick lance
#

What do you need help with?

static sierra
#

i need staff to help me

#

i didnt recieve my monthly hacker badge and i was #1 all countries yet i received nth

crude stump
#

What is a monthly hacker badge

static sierra
#

hacking into machines more than anyone for this month

#

i spent countless hours trying to achieve this badge yet i didnt receive yet this is not smth i can tolerate as a user who have been promised to with rewards

sick lance
static sierra
#

and i did reach out to them

sick lance
#

Then wait for them to reply.

static sierra
#

scrubz u dont understand how painful it is when u spend countless nights and hours dedicating urself to that specific platform which is in this case thm just to acheive a reward that would make me feel better about my dedication its like u study 4y in BCs then the college shut down for war or wtv

crude stump
#

🥳

celest valve
sick lance
crude stump
rapid merlin
#

How to get badge help others and support them easy pizy 😉

static sierra
#

im talking about monthly hacker badge my man

rapid merlin
#

I'm talking about staff role 🙆

static sierra
#

gl with it seven

#

may u get what u deserve

#

<33

sick lance
rapid merlin
gloomy hamlet
#

pog

chilly veldt
#

apply for a position

rapid merlin
#

How ?

#

I'm not done anything great so far to apply, may be i could try

chilly veldt
sick lance
#

All people in this server with Staff role are actually staff.

rapid merlin
#

Is there anyway i could become staff like helping others and supporting them

chilly veldt
#

nope

#

staff is staff employees of the website

rapid merlin
#

Cho Chad

chilly veldt
#

there's community mentors, which are people who have helped a lot around in the community, they are NOT employeed by thm

rapid merlin
#

But in htb it's different xd ! i thought same would be apply here

chilly veldt
#

htb staff is also employeed by the company

crude stump
rapid merlin
pine belfry
#

ahh i wouldve loved to travel to london and help but too much going on lol

chilly veldt
rapid merlin
chilly veldt
#

I should go back to writing my project

#

almost done AU_pepevibe

crude stump
#

I would die

chilly veldt
#

this has taken us a week to write

rapid merlin
#

I could write a lot I reckon

sand fractal
#

back

rapid merlin
#

I think it’s because people type how they talk and I talk so fast. People ask me if I can sing rap god

chilly veldt
#

this is a report on redesigning a whole network for a municipality

rapid merlin
#

Sounds interesting

chilly veldt
#

yeah, it is, but when you have 2.5 weeks total for the project it gets spicy

oak tangle
#

I took a break from tryhackme for a little while, and now I can't remember what command I used in windows to transfer a payload from the attackbox?

eager marsh
oak tangle
#

the windows host is a virtual machine provided by the room

eager marsh
#

Oh well in that case you might wanna use IEX to transfer it

#

Setup a Python http server and grab the file from your attack box

oak tangle
#

I know I used the python server. I just can't remember the Powershell command I used.

#

What is IEX anyway?

eager marsh
#

Invoke Expression

#

Gimme a sec I’ll send you the command you have to use

pearl raven
sick lance
#

Depending on the file, you perhaps shouldn't take it.

crude stump
eager marsh
#

Invoke-Depression

pearl raven
#

lol

oak tangle
#

I just found it; it was invoke-webrequest. Thank you anyway!

eager marsh
#

Glad to see you ended up getting though

twin ridgeBOT
#

Gave 1 Rep to omegawarton (current: #2261 - 1)

void zodiac
#

Access to networks for 7 days of streak.

What is this access? What does it give?

sinful moon
#

aka instead of just one machine, it’s a whole network you’re looking at and moving laterally though

sinful moon
#

mhmm it is for sure

#

It’s normally just for subscribers, but yeah with a 7 day streak, you can access some of those for free

sick lance
#

Throwback was a seperate purchase.

sinful moon
#

Ah ouch, shows how long it’s been since I’ve checked up on this, but fair I’ve been a sub for years

void zodiac
#

So no benefits for me since I have premium

sick lance
#

Nah, subs get auto access.

sand trench
#

shadow was one of the last few people to ever complete throwback network

sick lance
#

Oh god.

#

£4.6K

sand trench
#

HOLY MEEPs

pearl raven
#

lulz

sand trench
#

anyone wanna burn holes in their wallets???

sick lance
#

And I get to try and break it. 😂

sand trench
sick lance
olive portal
#

Hello guy

pearl raven
#

On sale over here:

sick lance
#

I have my hons project to do involving Fortinet products.

#

It's going to be fun.

pearl raven
#

Ah cool

sick lance
#

Anyone using a .io domain?

eager marsh
#

Oh

#

I guess it isn’t

sick lance
#

Throwback is not included in the list, nor is it still available

sinful moon
#

Yeah that was already clarified for me by… yep

#

it just was the last time I was working on the Networks so shows you how long that’s been lol

sick lance
#

Red team best network

sinful moon
sand trench
#

meep moops time for sleep sloops to the beep boops

pearl raven
#

Night Shadow

shut hawk
#

way too many important domains

boreal gull
#

i actually did not, i’ve been here since 2019. i just checked message history and i got here before you did! i took a lil hiatus back then

#

Unless you count Slack

#

The original community Slack not the employee one

shut hawk
boreal gull
boreal gull
#

when ur as old as me you’ve gotta dig through the history to see how people ended up 👵

shut hawk
#

Cloudstrike is coming to my uni to do some recruiting 🗿

boreal gull
boreal gull
#

when they come to unis it’s mostly sales in my experience :/

pallid lotus
boreal gull
#

it’s always sales for big corps

boreal gull
boreal gull
#

mod shop

#

mod shop

#

stupid auto correct

pallid lotus
#

Si

shut hawk
#

No potential job opportunity?

pallid lotus
#

Do you... want one?

boreal gull
shut hawk
#

Honestly I'd take anything kekw

boreal gull
#

i’m sorry to say

boreal gull
#

maybe you will be their scapegoat

shut hawk
#

I would single handley raise their stocks

boreal gull
shut hawk
#

By removing all regex

boreal gull
#

i can make 10

#

on tiktok

#

idk 10 of what

#

but i can get 10

shut hawk
#
/[^a-zA-Z ]/g
boreal scarab
crude stump
#

What’s with the weed symbol

crude stump
#

Yeah I’m confused

chilly veldt
#

my fingers, they hurt

shut hawk
chilly veldt
umbral bay
chilly veldt
umbral bay
chilly veldt
#

some of the topics at least on how to redesign a network to make it more secure and redundant

chilly veldt
umbral bay
chilly veldt
#

it's written with a municipality network in focus, we had to take their current enterprise network and redesign everything to make it better and make a report on how to implement different design features, and security features

wooden totem
crude stump
#

So that’s why

#

It’s a joke on 420 in the name

chilly veldt
#

286 servers segmented into respectful networks with different levels of security, with Vlans/subnets and portgroups for said network, all hooked up to firewalls, making sure all the network traffic is monitored and restricted

#

welcome to school projects

sick lance
chilly veldt
#

I actually do know how to write cursive

wooden totem
#

I tried reading my notes from school when I was writing everything in cursive, half of the words are unrecognizable

chilly veldt
#

luckily we are 4 people in this group, so I haven't written everything

wooden totem
#

average group project

eternal timber
#

Imagine trying to read Russian in cursive

chilly veldt
wooden totem
crude stump
#

It clearly says “drink vodka…”

eternal timber
barren spade
#

Hi everyone

undone citrus
undone citrus
pine belfry
#

chat give me a roast rn

pine belfry
#

on another note, does anyone have any resources i can use to learn more about $PATH since its interesting and common in privesc

#

(that looks heavenly)

undone citrus
undone citrus
pine belfry
#

Absolutely

#

Less fiddling with VMs, more rooms, and you get to support them

undone citrus
twin ridgeBOT
#

Gave +1 Rep to @pine belfry (current: #2261 - 1)

undone citrus
#

Idk even know why I have code academy tbh I want to learn cybersecurity not much about coding

pine belfry
#

Yeah defo, im not too sure what codeacademy is but if youre learning about cyber this is one of (if not the best) resource for learning about it

pine belfry
#

im on a cybersecurity course and i go to a lot of networking events and this is one of the top things that is mentioned there without a doubt

#

anytime!

undone citrus
#

Any local news or news papers

#

Cause I want to get involved I have work experience coming up and I need to find a company to take me

pine belfry
#

I usually use something called "eventbrite" and search for cyber events there, im from bristol in the UK and there is loads of stuff around here. tomorrow theres a cybersecurity convention, and i just go to those and talk to as many people as possible

#

would 100000000% reccomend getting linkedin too if you havent already

barren spade
undone citrus
undone citrus
pine belfry
#

ah great, definitely check it out, theres loads of events and everyones in the same boat so i wouldnt worry too much or be nervous about it

#

(also they usually offer free pizza and drinks which is very enticing)

undone citrus
pine belfry
#

youre good! happy jobhunting :)

karmic geyser
boreal scarab
#

@chilly veldt send help

chilly veldt
boreal scarab
chilly veldt
boreal scarab
barren spade
#

check helm status first tho

jovial wave
#

do info rooms award points?

eager marsh
jovial wave
#

sadge

jovial wave
sinful moon
boreal scarab
twin ridgeBOT
#

Gave +1 Rep to @barren spade (current: #2261 - 1)

boreal scarab
#

Fuck you bot

pearl raven
#

lmao

hot cairn
#

so kubectl edit deploy fixes it good enough lol

boreal scarab
#

So long as VPN is good, and able to access the webUI + other apps can talk to it, all that matters 😄

eternal timber
#

Hell o

boreal scarab
boreal scarab
eternal timber
boreal scarab
eternal timber
#

Nice

crude stump
rapid merlin
#

program it to make chocolate bars with a QR code on them

winter swallow
#

Hi

rapid merlin
winter swallow
#

How's everyone doing

rapid merlin
#

doing good here, music and ☕

winter swallow
#

Nice!

#

Good to hear

boreal scarab
winter swallow
#

Sooo I'm actually a newbie when it comes to cyber security but I'd like to join the industry later so can anyone suggest some resources if possible and also um a roadmap to entry level jobs in cybersecurity 👀

rapid merlin
#

OWASP Top 10 - 2021 Task 11: I successfully discovered cute cat pictures blobheart

regal forge
#

Hello folks,
I am stuck at a certain problem which is regarding XSS, if someone could give me an explanation that would be highly appreciated 🙂

Given the following JavaScript snippet of a page running on HTTPS, explain how a Network adversary could execute an arbitrary payload in the origin of the HTTPS site. You can assume that the site is not sending an HSTS header and the attacker cannot get a valid certificate for the site. Also, explain how this could be addressed (the script_host should still be stored on the client and your solution must not rely on HSTS).

function writeAd() { // getCookie extracts the value belonging to that key var script_host = getCookie('script_host'); var script = document.createElement("script"); script.src = script_host + "/ad.js"; document.body.appendChild(script); } writeAd();

sinful moon
#

The real question is, is this some of your course work? I’d just be curious what this is for

regal forge
smoky granite
#

hey

#

how are you doing

sinful moon
#

Then there’s some potential ethical concerns with us helping you with this unfortunatetly

#

That being said, it’s not all that hard

sinful moon
#

yes heya

regal forge
#

can you just say if I am going in the right direction?
What I think is an attacker can host a malicious JS file with the name as ad.js and host it on his own domain and then set the cookie with the url to his domain.

smoky granite
sinful moon
#

lol you are not wrong. But I would advise you to consult with your classmates or study group rather than here.

sinful moon
#

we’re glad to help with these sorta questions but it gets tricky when it’s homework/study material

smoky granite
outer rivet
#

Love the icon in website

coral phoenix
#

Hello chat, mods, and staff

outer rivet
coral phoenix
#

I know everybody

sinful moon
#

lol not quite the same local group as I had in mind, but… potentially

neon merlin
#

Planet Earth? Don't post my dox NotLikeThis

sinful moon
#

lol

#

also happens to be one of my fave documentaries so I can’t complain there

coral phoenix
#

When is THM going to release certificates?

karmic geyser
karmic geyser