#general

1 messages · Page 470 of 1

agile flicker
#

how do I fix it then

naive violet
#

Fix what?

#

It's 95% idle, that ain't a problem

agile flicker
#

.

#

oh aight

#

thanks

tepid furnace
#

I just wanna make sure im reading it right

loud marlin
#

idle state is what is ok. there is no fix for it. if fix is it to put it on load state then that is fix... i guess

tepid furnace
#

"cpu
95"
what does the 95 stand for, 95%? or like 95% overtime?

#

like is it in that instant

#

or just an average

#

I just wanna make sure im reading it correctly as 95% of his cpu is just chilling

loud marlin
#

it means it is doing nothing in 95% of time... kinda

tepid furnace
#

well "nothing"

#

but

#

works for it

#

I just wanted to make sure I was reading it right lol

tepid furnace
#

yur

tepid furnace
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #2 - 2199)

tepid furnace
#

now you get the rep :)

agile flicker
#

one question then

#

why does it tell me it uses so much in processes then

tepid furnace
#

windows lies

agile flicker
#

aight

#

thanks

#

so im chilling?

tepid furnace
#

most likely

#

do you notice performance decreases?

#

I can give you an example of windows lying too

#

windows says im using 17%cpu for something

loud marlin
#

if app or so is running smth then will be show of how much of resources it use in single unit of time. when app is done will be iddle

agile flicker
#

like I have a pretty good GPU and i put my settings on cod at lowest and I cant get higher than 100 fps

tepid furnace
#

it also says im using 10% at the same time essentially

agile flicker
#

(Rtx 3060)

tepid furnace
#

it could be vram

#

but that's a gpu thing

#

which nvidia has criminally kept vram from people

#

no reason to sell a card with 8gb of vram in 2024

loud marlin
#

at lasat nvidia works on windows...

tepid furnace
#

true

#

but nvida is kinda stupid sometimes

#

8gb of vram leaves no headroom

#

I get it's so that people will buy the gpu next year

#

but it's so scummy when you already pay 600-700 for the card

#

could buy a year for thm and htb instead of buying a new gpu

loud marlin
#

if you play games you go for that kind of gpu usage. you buy what you need gpu is not just main for gaming

tepid furnace
#

yeah

#

but still

#

3d rendering etc

loud marlin
#

there is gpu named nVidia Tesla, and have different usage

wooden totem
#

Edge is actually so buggy holy shit

#

I got 0 problems in the years of having firefox but with Edge I'm having at least 1 problem daily

naive violet
#

And which cod

wooden totem
#

MW3 seems to have super bad optimization

#

other ones should have higher fps

chilly veldt
#

Waiting on my artist to take a break so we can look at my design

sick lance
#

I haven't played CoD in so long.

#

Too busy with Diablo IV.

#

And now my project will take up time

crude stump
#

What’s your project

wooden totem
#

Its buggin me

crude stump
#

It’s really hard to make it centered

viral crest
#

GM everyone

#

6:am here

#

Drinking much I have

#

Cheers

#

Not slept a wink

#

Sucks being a programmer

sick lance
viral crest
#

Defanging malware I find myself

sick lance
#

Infact, scratch that

viral crest
#

That's what she said.
I know

sick lance
#

It looks so much cooler transparent.

crude stump
#

Your right

loud marlin
#

idk how stupid it is to play with grub, but aint smart =/

sick lance
#

Still slightly off centre.

#

But that can be fixed

crude stump
#

How’s this look

#

Yoo that looks sick

sick lance
#

Looks slightly better.

wooden totem
agile flicker
sick lance
#

Simple paint fix though.

wooden totem
#

now it wont fit to discord

#

😭

crude stump
#

It does when you save it

sick lance
#

All pics looks better transparent.

#

If they're logo or something.

wooden totem
#

not mine

sick lance
#

Especially yours.

wooden totem
#

looks bland, it needs that roundness around it to make it eye pleasing

craggy egret
#

in Dashboard it shows me as top 5% but in profile view it shows top 6%.
which one am I lol?
I see the one on the dashboard all the time so I know it's updating but it seems the one in profile is not

#

just felt like I should report that.

sick lance
#

Staff are aware.

neon merlin
#

Noob linux question but after I've built the a binary of john from the github how do I actually use it?

#

typing "john" in the terminal says it's not installed

#
sudo apt install john
sick lance
#

Did you add it to your path?

neon merlin
#

I don't know what that is

#

./john --test works and launches the benchmark

#

This is the first time I've compiled binary cause I wanted jumbo john

#

Not the one in the package installer

sick lance
#

./john works as intended, however if you wish to use john anywhere, you'll need to add it to the path, I'm not sure if you use zshrc or bashrc so you'll need to look up what you use and the command.

neon merlin
#

bashrc on linux mint

rapid merlin
sick lance
#

Google or ChatPT will assist you

simple valve
simple valve
neon merlin
#

just a path to the whole run directory or am I going to have to specify files?

simple valve
#

Pixelated art has a strong hold on me

neon merlin
#

alri cool

zealous briar
#

@sick lance hoooyyy Mr Scrubz remember me

neon merlin
#

I did all that, confirmed the directory was added echo $PATH but now it says Error: Cannot find John home. Invoke the program via full or relative pathname. For example, /full/path/john or path/john, or set and use a shell alias. when trying to type just "john" into terminal

zealous briar
#

@sick lance How are u hope u are doing great

sick lance
zealous briar
#

@sick lance Its going great but I'm feeling bored la from doing too much...

sick lance
neon merlin
#

I can't post screenshots

sick lance
sharp citrusBOT
zealous briar
#

@sick lance Mr do u know hacking

neon merlin
#

I added exactly this to bashrc export PATH="$PATH:/home/sam/Pentest/john

#

this is a direct copy paste

zealous briar
#

@sick lance I want a mentor

#

And u are a good guy

sick lance
neon merlin
zealous briar
#

@sick lance Man I learn everything deeply to not be a script kiddie but that makes me too bored to even carry on

sick lance
neon merlin
#

I ran source ~/.bashrc instead

zealous briar
#

I started networking and made a good grasp on OSI and tcp/ip

neon merlin
#

I'll try just restarting

zealous briar
#

Btw Mr @sick lance How much time did it take u to be good at hacking...

neon merlin
#

After restarting it's back to ```Command 'john' not found, but can be installed with:
sudo apt install john

#

confirmed the stuff is still added to path

shut hawk
#

echo $PATH

inner trench
#

are the thm tickets back?

#

where you could win a laptop and things like that

loud marlin
#

that was old thing

sick lance
#

Next prize event might be AoC2024.

boreal scarab
sick lance
#

It's not confirmed

neon merlin
#

They use echo 'alias john="~/src/john/run/john"' >> ~/.bashrc

loud marlin
inner trench
#

yeah i know but when you look at your profile it says "Complete rooms from the Security Engineering path to earn tickets. Collect 3 of the same ticket to win a prize. For more information on the ticket promotion, click here" but a few days ago it sayed something like "This event ended Complete rooms from the Security Engineering path to earn tickets. Collect 3 of the same ticket to win a prize. For more information on the ticket promotion, click here" or something like that

sick lance
inner trench
#

and when i click on the link it just says This room is private

Only users with the room link can access this room

sick lance
#

Yeah, you won't have access now.

inner trench
#

i hope they are coming back

shut hawk
#

Not sure why they are using an alias instead

sick lance
inner trench
#

hopefully

neon merlin
#
Session completed. 

Is !!1GOOD..*7¡VA the password?

neon merlin
#

Thats what john spat out after it cracked a hash

#

Which part of that line is the password?

shut hawk
#

Run john show

#

Or it might be john --show

neon merlin
#

neither apparently

shut hawk
neon merlin
#

stat: hash1.txt: No such file or directory

#

Why is it not default behaviour to show the result after it's done

#

Like isn't that what the user wants?

sand trench
#

Because sometimes you crack a few million hashes

#

And then showning all in output would be bad

neon merlin
#

How about a nice easy text file then?

shut hawk
shut hawk
neon merlin
shut hawk
#

john --show hash1.txt

#

And the original John command you ran as well?

neon merlin
#

That one doesn't work either

#

john --wordlist=/home/sam/Pentest/Wordlists/SecLists-master/Passwords/Leaked-Databases/rockyou.txt /home/sam/Downloads/first_task_hashes/hash1.txt

naive violet
neon merlin
#

mfw DONE and GOOD apparently means it failed NotLikeThis

shut hawk
#

Done as in exhausted the wordlist

naive violet
#

"good" is part of one of the passwords it tried

#

Done, it was done. There's no more work for it to do. Done.

neon merlin
#

They don't make this very user friendly do they

#

And the tryhackme room talks about non of this

naive violet
#

The tryhackme room, assuming this is crack the hash or something, expects you to already know

#

It's not unreasonable to have prerequisites

neon merlin
#

It's the room where it teaches you how to use john the ripper

naive violet
#

Please use #room-help for help with tryhackme rooms

neon merlin
#

By not teaching you apparently

naive violet
#

A laaaaaarge chunk of learning hacking is learning to troubleshoot and read documentation

loud marlin
#

how mice... arch is not suport ntfs by default... spent 1h try to find out what is wrong with my partition =/

neon merlin
#

For some reason when I typed --format=raw-MD5 into the original command it worked

naive violet
#

For some hash types, like sha512crypt and yescrypt which are used frequently on linux, the hash has a prefix ($6$ and $y$ respectively) to tell it what hash format it is

#

For MD5, MD4, NTLM (windows), LM (Old windows) they're all the same length and all typically hex

#

So it can't know which one it is

neon merlin
#

nice

loud marlin
naive violet
#

Best way to identify the hash type is to use context

#

Got it from a windows box? Probably NTLM

loud marlin
inner pine
#

Can anyone recommend resources for learning Python scripting for security purposes

naive violet
inner pine
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #2 - 2200)

naive violet
#

THM isn't a programming platform ¯_(ツ)_/¯

#

You shouldn't be limiting yourself to just THM, there's a lot of ways to learn

inner pine
naive violet
#

Sadly you need to learn the non security related stuff first

torpid iron
#

Hi guys, have any of you heard of Kreativstorm?
I was trying to apply for their cybersecurity position, they didn't choose me and then I received an email about their cybersecurity hands-on training program which is 149 EUR and thought it would be a great way to start my journey with at least something real-world and practical, plus, in European company. To get into it, there are 2 major steps, one is just CV and 2 questions on their website and then an interview which I had yesterday, that's why I thought it probably is not scam, as why would you do an interview when you can just charge this 149 EUR and that's it but now I did a research and found some info which doesn't seem great, there are some reviews saying that it's scam and there are some great ones but it may be their bots. At this point I'm really not sure what to do, so has any of you heard of their training programs?

inner pine
naive violet
#

There's fundamentals you need to get down before you can hit security content

whole yew
#

Without understanding how roles and permissions, you'll never understand how to audit a user

neon merlin
#

When I hear about hacking tools being bought on the dark web but I get mine free on GitHub SureBruh

gleaming gull
#

aha

shut hawk
rapid merlin
#

How much pineapple is one person allowed to intake

hidden glen
#

hey evening

inner pine
loud marlin
rapid merlin
#

RIP

loud marlin
#

top ?

rapid merlin
#

The green leaf

#

😂

loud marlin
#

oh lol

rapid merlin
#

It’s getting real cold

inner pine
#

The pineapple or the weather?

rapid merlin
#

The pineapple is gone, I demolished it

inner pine
#

Great work, I am craving pineapple now

rapid merlin
#

There was a point where I was eating pineapple four times a week

#

I wish I had a study partner 😩

#

Studying is so boring alone

crude stump
#

Hold on

rapid merlin
#

Why’s it bending like that

#

😂

inner pine
#

Song was just getting good at end

rapid merlin
#

The beat just dropped and then it finished

inner pine
#

What is everyone studying today?

crude stump
viscid chasm
#

hi

sudden bridge
#

sup H

wooden totem
crude stump
jagged thorn
#

Hey, anyone knows why i'm not able to join BreachingAD room.

rapid merlin
#

hello im currently persuing cybersecurity with cyber corps and i was wondering if there are any scholarships

#

i can apply for to get free rooms on tryhackme

sick lance
sick lance
jagged thorn
#

It is specified that streak required is 0 but still i'll try that

sick lance
jagged thorn
#

nope

sick lance
#

Then you need to have a streak of 7 or more, like I just said.

rapid merlin
#

does athena os still connect?

jagged thorn
#

Thanks

#

If you'll search just active directory then it is mentioned streak required 0

rapid merlin
#

which will look better on my scholarship resume for college

sick lance
#

Neither, as they're not really professionally recognised like certs from OSCP are.

#

They're more just a hobby.

blazing granite
rapid merlin
#

am i expected to have my cert before or after i graduate?

sage grove
#

Can someone help me with the newest #1294359222233862276 room? I gained initial access by exploiting Aria2 and im stuck on privesc by ansible-playbook. Please ❤️

rapid merlin
#

so roadmap would be tryhackme/hackthebox > cert > apply for scholarship > graduate > internship > work a job?

#

or would it be tryhackme/hackthebox > apply for scholarship > graduate > cert + internship > work a job

blazing granite
sick lance
#

Not all.

sand trench
rapid merlin
#

so basically focus on tryhackme and develop the hobby + basic skills, get a scholarship(s), graduate from college, get certs + internship for experience

#

then aim for a job

#

pretty easy road map

outer rivet
#

hui

rapid merlin
#

is it hard

#

be honest

outer rivet
#

@fervent meteor help bro

rapid merlin
#

i'm not a big math person but i've done things like sentry mba and openbullet when i was younger

#

so i have a basic understanding

outer rivet
#

bro how you stduy

rapid merlin
#

is it hard

outer rivet
#

Teach me your how you been focusing because I am done bro

outer rivet
rapid merlin
#

i heard 50% of cybersecurity is knowing which tools/programs to use and the other 50% is knowing what to look for

#

is that right

rapid merlin
#

learning difficulty i should say

sand trench
naive violet
rapid merlin
outer rivet
rapid merlin
#

some guy named intelbroker i met from ironic discord told me that

#

bros like big in the community or sum

outer rivet
#

intelbroker lol sound funny

sand trench
outer rivet
rapid merlin
#

is blue team easier then red team

#

and which pays more

outer rivet
rapid merlin
#

excited asf to try it out

outer rivet
sand trench
outer rivet
#

Woow

rapid merlin
#

what are these numbers and terms bro

#

do i have to learn these terms

outer rivet
#

College work and side study

outer rivet
rapid merlin
#

T OSWA prep im guessing is certification test preperation?

#

ik cves are vulnerabilities but wtf is a S CVE "S CVE Research"

naive violet
#

Hunting for vulns, or reading current/new CVEs?

rapid merlin
#

ahh

sand trench
#

not sure if ninja james would appricate shadow posting an example markdown files of shadows notes

outer rivet
#

@fervent meteor be like

outer rivet
rapid merlin
#

so do companies ever patch CVEs

#

or are some just unpatchable

#

and you get to abuse them forever

sand trench
naive violet
rapid merlin
#

so you could work for a company and spend ur first year making godly CVEs

naive violet
#

If there's an unpatchable vuln, you make it unexploitable or replace the thing, depending on the severity

sand trench
#

meltdown and spectre for cpus is basically unpatchable but there are workarounds

rapid merlin
#

then just continuously expand on them as work

#

like for red teaming

outer rivet
#

@fervent meteor no off day

#

?

#

nvm

rapid merlin
#

do red teamers get jobs or do they work entrepenurially or sum

naive violet
rapid merlin
#

oh

outer rivet
#

No movie day

#

?

rapid merlin
#

W

outer rivet
#

what about go out with friends

rapid merlin
#

is a bachelors degree enough to get a 6 figure job

sand trench
#

none public exploits tend to be 0days........

outer rivet
#

I do 2

sick lance
#

I'm hunting for vulns and CVE's 😎

rapid merlin
#

thats cool bro

rapid merlin
#

if you ever move to a third world country you can just crash out

sick lance
#

On Fortinet devices mostly.

sand trench
#

think the amount of hackers in shadows uni course is high

rapid merlin
#

and sell databases for money

#

being a hacker is so cool man

#

so much freedom

sick lance
naive violet
rapid merlin
#

Oh sorry

#

I didnt mean like fr

#

jokingly

outer rivet
#

you do boxes or na

naive violet
sand trench
#

well shadows course is marked as having a decent bit of cybersecurity in it so of course there will be hackers

#
  • And no crackers
outer rivet
#

yeah delete discord you will gain 1 or 2 hour everyday for real

sick lance
rapid merlin
#

I would never do crime

#

I'm a law abiding citizen

#

🇺🇸 🦅

sand trench
#

i.e it is not easy to go from basically doing nothing every day to a 9-17 study/work day

sick lance
#

Are you doing anything related to cyber?

sand trench
#

we just started the python programming section

sand trench
#

^ we will get more in depth on this soonish

sick lance
#

That sounds good, is it a 2 or 4 year course?

BsC type?

sand trench
sick lance
sand trench
sudden bridge
#

hows this possible

naive violet
#

Answer 68 questions

#

Then answer one more

sudden bridge
#

wow

#

streak of 1 day even after being consistent

sick lance
#

Then stop.

pine stratus
#

hello i bought a virtual server yesterday ,when i checked for login failed attempts i found like so manyyyyy , is that normal ?

sick lance
#

Welcome to scrapers.

pine stratus
sudden bridge
sick lance
sudden bridge
lament tendon
# lament tendon Yea.

There are a lot of bots that will just try to log into and exploit anything publicly available.

#

Normal stuff.

sick lance
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #1 - 2863)

sick lance
naive violet
#

Yeah it's just botnets

sick lance
#

Leave a python server on the attackbox long enough and something will eventually hit it.

sand trench
naive violet
sudden bridge
wraith summit
sick lance
#

admin:admin
root:root
admin:guest
root:toor

pine stratus
#

sshd[258299]: Failed password for invalid user hadoop from 187.210.77.100 port 45060 ssh2

#

im hadoop now

wraith summit
#

Yup, it's something along those line, nothing too special, but it's always interesting to analyze

wraith summit
pine stratus
#

kekw 77

naive violet
#

You should be using SSH key auth anyway, especially internet facing

wraith summit
#

I had some friends with servers up as well, and we could see the IP addresses of the attackers. One of them was even hosting a file server 💀

naive violet
#

It's important to say now that scanning or attacking them back would still be illegal.

pine stratus
#

isnt botnet just compromised systems ?

naive violet
#

I can't really explain it without breaking the rules here

wraith summit
naive violet
wraith summit
wraith summit
brittle lynx
#

Hey guys any ideas for 3d printing ? Hacking related stuff maybe ?

loud marlin
crude stump
#

Doesn’t it have to be connected to the cloud

#

I’m guessing a cloud hosting service provider or somthing?

sick lance
#

No?

crude stump
#

Oh

sick lance
#

This sense it could be actually.

#

Since it's virtual.

#

Physical servers aren't like your cloud based server.

crude stump
#

How does scrapers find it then.

sick lance
#

You connect to the server with it's IP.

crude stump
#

Oh

brittle lynx
crude stump
#

That makes sense

naive violet
sick lance
loud marlin
#

rasp 5 case

visual relic
#

Hello I am a student of btech cs
Any one can help me to provide roadmap of cyber security and provide tools details whose are really needed

#

Plz help me

crude stump
#

Wait but scrubz im not really understanding how a scraper just randomly finds a server. Like what would be considered a server.

sick lance
#

The host machine is irrelevant.

wooden totem
loud marlin
#

i have 2x. each was around 500e

wooden totem
#

damn

#

damn

sick lance
loud marlin
#

you have ok ones around 200-300 ones

crude stump
sick lance
#

Do you know what an auto-dialler is?

crude stump
#

Don’t scammers use those

#

Like a robo call

sick lance
#

Precisely.

#

It's essentially the same setup and plan.

wooden totem
#

bruteforcing luck

crude stump
#

Wow interesting

soft bramble
#

are all paths in thm paid?

sick lance
#

The paths contain subscription content.

soft bramble
finite rock
#

Do anybody else have problem with downloading the Network-VPN-Server "wreath"? Im keep getting error 500

sick lance
sharp citrusBOT
crude stump
#

Ngl. I want to set up a virtual server and add firewalls and stuff to see the amount of stuff it blocks. Idk how I would go about that so imma have to do more research.

soft bramble
twin ridgeBOT
#

Gave +1 Rep to @sharp citrus (current: #94 - 76)

boreal scarab
#

Hey @sick lance Do you have burp pro?

sick lance
boreal scarab
pearl raven
#

At this point I think we all owe at least one payment to winrar tbh.

sand trench
sick lance
#

I don't use it.

pine stratus
#

Is it safe to run a vulnerable web app on a virtual server that I don’t care about? Can hackers access my personal computer throught hat and is it safe for me to practice penetration testing this way?

sick lance
boreal scarab
pine stratus
boreal scarab
#

Speaking of secure devices.... I gotta go from WPA2/WPA3 to WPA3

sick lance
#

You're not there now?

#

Tut tut,

boreal scarab
#

My father's old phone couldn't handle WPA3, so had to be on WPA2/WPA3, now that he has a new phone, to WPA3 I go!

sick lance
#

I'd have cut him from the network. kekw

boreal scarab
sick lance
#

Kthxbai.

pine stratus
rapid merlin
#

my router admin info is admin;password

boreal scarab
#

WPA3 has landed!

sand trench
#

the default password for shadows router is EntTmGb7

#

^ which is not used because duh

boreal scarab
#

Still love that my router has the option to turn on Telnet...

sick lance
#

Telnet is still used.

boreal scarab
#

.....WHY?

#

I know for old systems they still use Telnet, but beyond that... why

sand trench
#

speed and low overhead

boreal scarab
#

And lack of security...

sand trench
#

yuups

boreal scarab
#

If I ever hear a tech today say, for a new system, "Lets use Telnet over SSH" My god, I'm kicking their ass out

rapid merlin
#

Lets use Telnet over SSH

boreal scarab
#

Now to update my router...... 10 seconds later

I bricked my router

sinful moon
#

I do miss the days when dd-wrt, OpenWRT and Tomato were popular custom firmware choices

boreal scarab
#

Looks like I'm back online

sinful moon
#

Got enterprise grade networking options on my WRT54G back in the 00s lol

#

Unfortunately the FCC kind of killed it, they weren't happy that custom firmware would unlock 2.4Ghz channels 13 and 14 in the US, and router manufactures dramatically locked down their devices for custom firmware as to not be liable

boreal scarab
#

Ayyyyy lets go, didn't brick!

sinful moon
#

just about the only decision a more liberal FCC has made that I was not happy with

#

nice nice

boreal scarab
sinful moon
#

You can but it's signifantly more of a pain than it used to be

rapid merlin
#

I didn’t know you could put custom firmware onto a router

#

Can you do that with the mainstream companies too ?

boreal scarab
sinful moon
#

and for sure depends on the make and model. I know for a while Linksys sold some at a premium that were fully opened up to custom firmware lol

sick lance
boreal scarab
sinful moon
#

but yeah the good old days were when these were trivial to do with

sick lance
#

That would breach either your contract and/or warranty.

sinful moon
#

Yeah to be very clear, I mean your self owned routers

boreal scarab
#

But if you're talking ISP, as Scrubz said, nope

sinful moon
#

heck used to be I had self owned cable modem as well

#

but they finally pressured us to rent that instead, held a "free" speed upgrade back behind using a company provided cable modem

rapid merlin
sick lance
boreal scarab
#

My ISP's router fucking SUCKED... I couldn't do much on it, and every single place I went in the router "This is advanced, and only for technicians"

*The place I was going to:*Make a device Static...

sick lance
#

ISP a offered me 945 mbps for £60

ISP b offered me 1024 mbps for £27 as part of a deal.

#

I did not take ISP a.

sinful moon
#

Yeah if possible just get an ISP device that you can disable the router and wifi functionality on and just use it purely as a cable modem or whatever

wooden totem
#

Bro what is on my bathroom tiles, theres like a dark circle on one of the tiles but every time I try to show anyone it's invisible, no trace of it. I'm the only one that notices it, been noticing for years actually

boreal scarab
#

Just give me internet, not your crappy ISP router.

sick lance
#

I have the EERO from Amazon, they're quite nice

rapid merlin
boreal scarab
#

I have the Asus RT-AX86U Pro, love it

rapid merlin
#

My internet used to be good, I got 8ms on valorant

sick lance
sinful moon
#

I mean you're the one who is providing the security practically

sick lance
#

Malware-Bytes, HP Wolf and Windows Defender is what I use.

loud marlin
sick lance
#

Malware-Bytes for the VPN also.

sinful moon
#

But even just a consumer grade firewall at the router level is going to be quite helpful

sand trench
boreal scarab
#

WPA3, VLAN, VPN Profiles, Wifi 6. mmmmm, only thing I wish it had was Wifi 6e, But I still love it

sick lance
#

Although, I recently just got a Fortinet firwall, so that will be fun.

sinful moon
#

Good luck, they have had plenty of issues but fair, also partially because they're a big target. Not sure I'd call that consumer grade however

boreal scarab
#

I still gotta mess with my OpnSense server, get that up and learning it

sinful moon
#

Yeah OPNSense is lovely

sick lance
#

This one certainly isn't, it only cost 15k

sinful moon
#

lol ouch

boreal scarab
#

Can't remember the specs, but got a server, think it has 32 GB DDR4 in it.

Use that as my firewall!

sick lance
#

Oh, I didn't pay for it.

sinful moon
#

yeah we just adopted some enterprise grade firewalls into our home network, but fair we work at home

loud marlin
#

for 15k he need to make me coffee every mornning

boreal scarab
#

(Server was free)

sinful moon
#

yeah same kinda deal lol

#

lol actually need to make some changes to it on Monday

boreal scarab
#

looks at Firewalla

sinful moon
#

Also please make sur you're only using public key encryption for ssh

wooden totem
sinful moon
#

you can also limit to just your home IP or use a VPN

boreal scarab
#

ufw, fail2ban, clamav, apparmor, usually my go to when I build a new server

sick lance
#

I have a FortuAnalyzer too.

pine stratus
#

tried it

sinful moon
#

And you're still getting invalid login requests? Because between these two/three concerns, you should be covered

#

but yes without any you will see them constantly

boreal scarab
#

Oh, and can't forget the best part about building a new server....

Cronjob to update, upgrade, and auto-remove every single night, without any of my input smilecat

sinful moon
#

also to be clear I mean a VPN tunnel rather than a VPN Internet anomizere service lol

rapid merlin
sinful moon
#

Yeah that's cursed lol

boreal scarab
sinful moon
#

All I can say is my VPS is still going strong, and between all these protections we have mentioned, I don't get any invalid ssh login attempts

#

even if it was nearly impossible anyways due to public key

#

You can just straight up disable password login after that

#

Yeah that was part of it, although I have been too lazy to get a proper VPN tunnel going. Was thinking Wireguard but lol, this works well enough for now

#

lol I have to set up enough VPN tunnels at work... hah yep exactrly

#

good luck!

boreal scarab
#

The best is when you have a public server, which is a virtual machine, and that virtual machine is VLANed off from your entire network with no Intranet access, randomly generated passwords, fail2ban, clamscan, ufw, apparmor, the works. Can't SSH into it, only way you can access it is through the host.

sinful moon
#

most likely however it's a VPS rather than a local VM that's actually exposed and has converns for VLANing

boreal scarab
#

Yah...... a VPS......

#

Yup, totally not local... nope

sinful moon
#

yeah that just strikes down VLANs and no internet access unless you have significant infra on the same account

boreal scarab
#

I can give the server 64 GB.... hell, I could give it 128 GB for all I care,

#

No extra cost

sand trench
crude stump
#

Is this a Mysql server

boreal scarab
#

It has internet access, just no inTRAnet access

sinful moon
#

Fair enough, but yeah even then not really a concern unless you have trusted resources in the same account

#

even at work, I just have a vulnerability scanning server and a webserver which are completely disconnected from both each other and work datacenter entirely which is pretty lovely.

crude stump
#

Wrong person

sinful moon
#

that is kinda the nice thing about VPS at low scale, just put your untrusted stuff over there away from anything concerning

#

heck that's why I got into VPSes in the first place

boreal scarab
sinful moon
#

I wanted to seperate my personal pentesting machine from THM and HTB as much as possible

#

so yeah it's just a server at a VPS provider instead, that I ssh into and use ssh tunneling to get THM resources like RDP back to my local

crude stump
#

Wait zumi may I dm

sinful moon
#

It's very against the THM TOS, but there are ways to pivot to other users in rare cases

#

Just not even a chance I was willing to take lol

#

plus also just good foundatinoal opsec, don't crap where you live

boreal scarab
#

Cool, I could go WPA3 Enterprise 192-Bit on this router

crude stump
#

Yeah just realized that

wooden totem
#

157 images of the same meme

ashen bloom
#

yo

rapid merlin
#

Hi

tribal helm
#

guys, isnt it possible to create more records in NTLM database via creating a lot of users on local machine and exporting the value. So, kinda brute forcing it?

crude stump
#

Any soc people here ever had to stay overtime If there has been a big breach or is your day the exact same even with a breach

sinful moon
#

I don't work in SOC but I have literally came in after the end of my work day to address breaches. If it's after 6PM I get payed after hours time and a half

#

lol one of them I warned the individuals concerned with patching literally three times, two the day of in ever increasing concern

crude stump
#

Aye but atleast you get payed overtime

sinful moon
#

mhmm I'm just the infosec "everything" at my comany and manage our external SOC and such

wild rose
sinful moon
#

Yeah there's aboslutely times I"ve had to stay late without ending my shift as well, but yep despite a two hour gap, 6 PM is always after-hours so time and a half

boreal scarab
#

I'm liking this router more and more

wild rose
#

This was prior to WFH policies were put in place.

sinful moon
crude stump
#

How did you do it

#

Micro naps?

sinful moon
#

it's more than doable, just not desierable lol

#

thankfully our only all hands on deck firewall diaster was in the morning, and I saved the day with the fix since I did my homework reading tech news prior to work lol

wild rose
#

Yeah we just got on to the contract and we were still learning that the SOC before us did not update the IPSes for over 2.5 years, so you can imaging the time it took to get those up-to-date and inline properly.

sinful moon
#

which ironically I could not help with since they were bootlooping and required on-site support, while I"m WFH

#

ouch yep

#

In our case we saw year 2022 issues cripple all of our newest firewalls at all clients everywhere lol

#

was "fun" 🙃

wild rose
#

We were hit with ransomware that took down manufacturing for 2 weeks cuz every machine needed to be reimaged.

sinful moon
#

damn that sucks

#

yeah our largest internal breach was the one I warned my boss about multiple times but we thankfully prevented any damange because I was like on top of this

#

I instantly logged in and told him how to remediate the tiny bit of damage done and they didn't penetrate beyond this single endpoint

wild rose
#

I was only added to that contract later on cuz they needed engineers and not analysts as per the contract, so I had to retrain everyone to handle engineering tasks.

cunning berry
#

is there any pro ctf players here?

sinful moon
#

If I didn't jump back in or hadn't given management x3 warnings, yeah we would have been ransomwared, along with all of our clients

wild rose
#

yikes, the stuff the keeps you up at night.

sinful moon
#

I gave them enough info to instantly know they were hacked when that system started acting weird

#

yeah for sure

#

thankfully my boss immediately shut down internet access to it and I jumped on to assist

wild rose
#

I did a ton and learned a lot from that contract, that the company wanted to poach me from my old company, but I didn't want to move cross country to be on-site.

#

But made many linkedin connections that elevated me to higher career paths.

sinful moon
#

Nice nice, yeah I can imagine

sinful moon
# wild rose yikes, the stuff the keeps you up at night.

the real scary part is that this was literally exploited by just adding some extra text onto the URL of the first time setup wizard, which bypassed auth 🙃

One of the most trivial yet critical vulns we've been impacted by

drifting mural
sinful moon
#

legit CVSS 10

boreal scarab
#

Fuuuuuuuu

#

Server decided to hop off the VLAN and onto my main network..... great

loud marlin
#

so much hardware that you flex, and it's crap

boreal scarab
#

Listen

drifting mural
boreal scarab
#

I just updated the firmware on it and it borked the VLAN

drifting mural
sinful moon
sinful moon
boreal scarab
#

And now my server doesn't have any internet access

#

Where's my whiskey?

sinful moon
#

This was just absolutely catastrophic, and if we didn't catch it due to me staying on top of things, this company may not still exist lol

#

RCE into every single endpoint with ScreenConnect installed could have been the endgame

#

we just stopped them at initial access

boreal scarab
sinful moon
boreal scarab
#

Fuuuuuuuuuck

sinful moon
#

lol not sure if you're saying for me or for your home network woes, guessing the latter

boreal scarab
#

Home network woes

sinful moon
#

Indeed but lol, you can still boot past that eventually. It will time out despite no limit

boreal scarab
#

And all I wanted was to go to WPA3, and update the firmware....

#

I swear.... I break things without even trying

loud marlin
#

skill

sinful moon
#

What router did you update?

shy fjord
#

wassup wassup

boreal scarab
boreal scarab
sinful moon
#

true but that's better than being stuck at boot

#

ah I have 0 experience with Asus routers, I am typing on one of their gaming laptops rn though and no complaints there 🙃

#

Anyways good luck to the network, I think it's back to Cyberpunk for me

boreal scarab
#

Love my router, but the VLAN in the past, on setup, was flaky, but once it got going, never gave me any issues'

#

Even replacing that NIC on trueNAS level didn't like it.... hrm

sinful moon
#

btw friendly word of advice, even if you share this server or others with me, but have never talked to me before, then no I will ignore your random friend requests

drifting mural
sinful moon
#

at least chat at me once lol in general

loud marlin
#

happy with mine...

sinful moon
drifting mural
#

After loging in to google with 2FA it kept loging me out after browser restart

drifting mural
sinful moon
#

Yeah that's because all the user accounts were deleted due to a "fresh" admin setup

#

mhmm, fair enough

#

ScreenConnect is a bit major for personal use so that's interesting

drifting mural
#

idk if thats ScreenConnect

sinful moon
#

but yep that IOC was literally what I warned about so my co-workers instantly knew what was up

drifting mural
#

but probably

sinful moon
#

only "data loss" we suffered was trivial to get back, was only the user's database and security databse basically. Trivial after we remediated the issue offline

#

Needless to say, we moved on to another solution lol despite updating

drifting mural
#

ye

sinful moon
#

CVSS 10 auth bypass just by appending any text at all to a URL is completely unacceptable 🙃

drifting mural
#

for sure

#

it's like letting everyone in to my home

sinful moon
#

Yeah it would have been potentially company ruining for us if this went its full coruse

drifting mural
#

yeah

drifting mural
sick lance
sinful moon
#

I sure do since that's literally what got me back into infosec and got me noticed for it professionally right after I was hired

#

I stayed on top of that stuff and dutifully updated the few concerns we had

#

lol log4j was my second month with this company

#

Ubiquity controllers were vulnerable to it, but I don't know if they actually had any externally accessible API endpoints in which to interact with log4j, but was a major concern either way. That was still early days for me anyways, I signed up for TryHackMe soon after

#

learned infosec on my own in the 00s, thought I could never have a career in it and gave up. Signed ontop helpdesk in 2021 an was instantly thrust into infosec and sysadmin after proving myself. Thus why I am still here, I had to play some catchup

warm grotto
#

Security research and manipulation's over-all entertaining. It's like solving a rubik's cube.

sinful moon
#

Good stuff!

#

Also lol your name is like unreadable against the yello reply BG

#

Anyways not sure why I spilled my guts about my past like that but it was both relevant to log4j and how I'm feeling in #cyber-and-careers lol

#

May be a rocky road ahead so we shall see

loud marlin
#

did you off/on it ?

boreal scarab
#

yes

#

But now one of my pi's no likey WPA3

rapid merlin
#

guys do u hate me

drifting mural
rapid merlin
#

i’m kidding idk why i felt like i wanted to copy paste that

#

it’s wild

naive violet
#

Yeah let's not.

warm grotto
rapid merlin
naive violet
rapid merlin
rapid merlin
warm grotto
sinful moon
#

sounds good hole

kindred sable
#

Ola

rapid merlin
warm grotto
knotty crown
#

anyone familiar with the vouchers? wanting to ask my work to get me one

sick lance
knotty crown
#

I believe I hve an understanding, they should just need to create an account (which is free) and then go the this page https://tryhackme.com/subscriptions and select the correct parameters and pay, but how do they assign it to me?

loud marlin
#

you get email

sharp citrusBOT
knotty crown
#

i assumed it would be fairly simple, just they get to see the code somehow and they provide to me in some way

sick lance
knotty crown
#

thank you all so much <#

#

❤️ I need to be confident in how it should work before i bring it up to them, and this makes me feel just that way. thank you so very much

sinful moon
#

on Discord? you'd just do

rapid merlin
#

The windows computer won’t update 😩

sinful moon
#

Oh I was scrolled up

sinful moon
#

I've been tracking what sysadmins have been saying about these patch tuesday updates and there's not been many major issues

#

We've already applied it to at least 20+ servers without issues

boreal scarab
#

Now I have to find a way to change my user password... cause, I don't remember wtf it was, nor the username lol

loud marlin
#

saved in browser might ?

boreal scarab
#

Nope

#

checked my password manager, not there

loud marlin
#

welll.. you are fracked lol

boreal scarab
rapid merlin
sinful moon
sinful moon
#

For example, you can see some (but not all) of the 2024-10 updates applied here because I haven't rebooted. This is also where they'd show you errors if they're not already front in center

#

lol I'm not always great at making the quotes/ideas seperate but you get the point

rapid merlin
sand trench
#

meep moop time for sleep sloop as shadow is bored and tired so the beep boops will be blasting

sinful moon
#

lol goodnight Shadow!

pliant cairn
#

off to sleep

#

was a productive day fr

rapid merlin
#

evening everyone

#

Night to everyone going to bed

loud marlin
#

nn

rapid merlin
#

just wrapped up my eCPPTv2, so my head's a bit mashed

mellow copper
#

Test

rapid merlin
#

😂

warm grotto
#

Everyone Europe?

sick lance
#

Not everyone.

sinful moon
#

I promise I will not open a comprimised MSC file or whatever for mmc profiles lol

rapid merlin
#

anyone been working on anything fun?

rapid merlin
sinful moon
#

playing video games, I've been working on beating them. It's quite enjoyable

#

Unfortuantely I don't really have tons of energy for projects outside of work anymore lol

sinful moon
# rapid merlin Windows updates 🥴

It's not actually that tricky, you still haven't given us like a single solid lead or error code to go from. No reason why October 2024 updates won't install for you from what I've been reading

boreal scarab
#

@sinful moon kill me... been trying to get PiAware to be able to connect to WPA3 network for about an hour now, no matter what I do, after I reboot, it reverts the changes, even if I set the wpasupplicant to key_mgmt to SAE

sinful moon
#

lolol

#

just please make sure your PiAware is up to date at least, I keep warning my boss has like major vulnerabilities detected

#

he may or may not be in the top 100 users for data entry lol

#

kinda helps if you put your antenna on a freaking roof of a 5+ story building on the coast lol

#

only real obstruction is a cellphone pole behind it

#

I don't have direct experience with PiAware, but I feel something in the software is overriding your settings, it does have that fancy web UI and such

#

but I can say holy crap do I love software defined radio and just general radio concerns

#

I'll say it, I think that shortwave radio is fascinating and inherently spooky, especially with its worldwide wavelengths. And is funny, radio is so much better at night with how the propagation works out, just lends to the general spookiness of radio

#

But fair, media like Silent Hill 2 (PS2) may have been the trigger, or the obscure point and click game Amber: Journeys Beyond (PC 1996). Both use radio in really supernatural and creepy ways

#

I love how the enemies who approach you in Silent Hill 2 also cause massive radio interference. That's always been a big thing for me in horror. Like if they're messing with our modern technology too, no that's even more messed up

Can see The Ring/Ringu for similar vibes

#

lol I had a hard time sleeping next to a CRT for a while after first seeing Ringu

static perch
#

I am getting error while updating my kali linux saying I should run this command sudo dpkg --configure -a.
When I ran it, it is asking restart service blah blah blah.
What should I do, coz last time when I updated my kali, I got fucked and had to install new one.

sinful moon
#

There's no reason to run that

#

just sudo apt upgrade then sudo apt update unless you want a new version, but no you don't need to reconfigure them all, that's going too far

boreal scarab
sinful moon
#

I think that's a mistake but fair enough. But I'm obsessive about updating my Linux boxes lol

#

can't complain about Linux automatic updates too much, but I'd be more of the mind that Id like to catch issues

#

also how do you handle kernel updates?

static perch
#

But it's giving me same error everytime
Error: dpkg was interrupted, you must manually run 'sudo dpkg --configure -a' to correct the problem.

sinful moon
boreal scarab
#

@sinful moon If I can't naturally get WPA3 working. What's your thoughts on this alternative:

I setup a quest network, hidden SSID, have my PiAware join that, and have it WPA2/WPA3, and have inTRAnet access, while my main network is WPA3.

static perch
sinful moon
boreal scarab
# loud marlin wpa-psk

I don't want to see that ever again....... change key_mgmt to SAE, reboot, back to WPA-PSK

static perch
sinful moon
#

But also I mean this is just a kali system right?

#

like just reinstall, that's the point, this is not a permanant install or a pentesting server

#

you can just trivially reinstall and have everything all good, nothing should be stored here locally which is critical

static perch
#

But I don't want to reinstall everytime I am doing some box. I might run into the same problem again

sinful moon
#

just yeah stick to the typical apt update apt upgrade flow or whatever

sick lance
#

If you use VMware, snapshots are king

sinful moon
#

that too

sick lance
#

Ideally though, Kali wasn't designed to go through mass amounts of updates

sinful moon
#

always nice to have rollback provisions

#

mhmm, it's purely a tool for infosec professionals

#

significantly more painful for my own choices with my pentesting server but cries in my own decisions lol

#

Still not actually that bad lol, I just never signed up to be a PostgreSQL DBA, thx Metasploit

rapid merlin
static perch
#

I took snapshots. Can I just look them by running previous snaps ?

sinful moon
#

yep no complaints there, nice showing off c:

#

I would like to get into ansible automation more

sinful moon
rapid merlin
#

I've played with chef and puppet, but prefer ansible. It being agentless is a bonus, and just needing ssh

#

A hosting company I was at a few years back used salt, that was pretty good

sinful moon
#

Totally fair, I am somewhat familiar with all three but I do not have direct experenice, just know the most about Ansible

rapid merlin
sinful moon
#

lol the limit of my devops was "make me a web host which can host three sites"

#

you bet and I just did docker compse for that, nothing crazy load balancing which needed to happen so that was all well and good

rapid merlin
#

I'm networking now, but devops has even creeped into here

sinful moon
#

lol yeah I'm just at a small org so it fell on me as the Linux peep

rapid merlin
#

you can run ansbile on modern cisco equipment

#

@sick lance just registered

#

wish me luck 🫡

#

should i setup my own VM or just use the onsite one

#

onsite one is alittle laggy for me i'm using brave

sinful moon
#

You can but it's far from nessessary, and it will be laggy either way

rapid merlin
sinful moon
#

better question

rapid merlin
#

i have used athena OS, kali, and ubuntu

#

using your own environment is much better if you know what to do

#

yes perfect

#

so i was thinking of using athena OS

#

it connects to tryhackme and has team rolls preinstalled

#

but is installing tools myself something i should learn

sinful moon
#

yeah it's literally just using sudo openvpn yourtoken.opv in your Linux guest and it'll do the thing

rapid merlin
#

okay bet

sinful moon
#

I personally would highly recommend VMware, despite their recient troubles lol

rapid merlin
#

okay bet

sinful moon
#

plus VMware Workstation Pro is now free, although you may need an account

rapid merlin
#

we use to get keys off github

#

still a thing?

sinful moon
#

lol we shall not discuss this here, but it's not a concern since free lol

rapid merlin
#

oh thats illegal i never even knew

#

i thought it was something they just allowed 💀

sinful moon
#

I think they at worst just give you a free code. I've not tried this out. I'm in VMware Users Group so I get subs for all

rapid merlin
#

W sounds good

#

im competing for a full tution scholarship for 2025 fall so you guys will see me here often

sinful moon
#

I'll just say VMware has played fast and lose with keys before but I will not elaborate from there, it doesn't mater anyways lol

rapid merlin
#

🫡

rapid merlin
static perch
#

Should I click Yes or No ?

sinful moon
#

I presume they're on Windows

rapid merlin
#

yup

rapid merlin
#

whats KVM?

sinful moon
#

but yes if you are on Linux @rapid merlin when virt-manager would be nice to consider

rapid merlin
#

ah

#

hypervisor is like the emulator for vms

#

?

#

tf is a hypervisor

#

VMware and Virtualbox are hypervisors, this is the software that manages your VMs

sinful moon
willow garnet
#

Anyone over here doing challenges on competitor BTLO platform? 🙂

sinful moon
#

VMware Workstation and Virtualbox are level 2 hypervisors which run on top of an operating system vs working with it. KVM is a linux feature that works natively with the OS to provide a level one hypervisor (aka as near to bare metal as you can get).

VMware ESXi and Proxmox also offer this feature due to them being VM server OSes

sinful moon
#

yes we know

static perch
sinful moon
#

that's why I said that it is level 1

rapid merlin
#

whats the difference between a college and university when you sign up

#

arent they the same thing

#

I didn't want to bog him down with too much info, as he didn't know what one was in the first place

#

it doesnt matter right

rapid merlin
#

bet

#

gotta install first

sinful moon
#

VMs are killer and must have info for this industry imho

rapid merlin
#

obviously, but seems he's just getting started

#

yup yup

#

just started

#

just graduated highschool looking to persue cybersecurity

#

thought maybe signing up for a program and ranking high would help with getting my accepted for a scholarship

sinful moon
#

Mhmm, was a sign of encourgement. I learned so much from them

rapid merlin
#

dw it deff is

#

i cant find a download that doesnt require a initial broadcom account does anybody have the download link to vmware

sinful moon
#

Not sure or path has to follow mine, but I love wierd/old/odd OSes and making them work in VMs and emulators. I'm not sure if retro tech is also a passion of yours but that was for sure a motivation for me

rapid merlin
#

like that one schizo OS

sinful moon
#

just potential ideas with what to use this power with, yes there are critical things you can do with these, but even fooling around is teaching you the ropes...

rapid merlin
#

Temple OS

sinful moon
#

Temples OS

#

I'd recommend waiting but yes it's trivial to install

rapid merlin
#

i was just watching a video on that

#

its crazy

sinful moon
#

much better alt OSes to try out like Haiku and such

rapid merlin
#

for sure

#

i really like athena os because you can integrate it directly into tryhackme

#

idk if they have a partnership or sum

#

but it also has hackthebox

#

and literally has ever blackarch linux tool you'd need

rapid merlin
#

also 0day knows the owners haha

#

Haven't had time to catch up with it

#

learned about them from owlsec's discord

sinful moon
#

or like here’s Win 3.11 emulated on my iPad Pro via UTM (aka qemu), with a bonus pic of Haiku

rapid merlin
#

?

#

qemu can run nearly everything lol

sinful moon
#

yes this is via AltStore plus SideJITServer. There is an openly avaliable version called UTM SE for iOS but that has no JIT support and is extremely slow

rapid merlin
#

W

sinful moon
#

but UTM SE was the proof of concept I needed to do this for the first time

rapid merlin
#

i got dynamic island + apple ai on my iphone 12

#

🧌

sinful moon
#

lol I question the usefulness of that but totally fair

rapid merlin
sinful moon
#

mhmm UTM is a Trusted Source in AltStore so no problem

rapid merlin
#

but the apple intelligence ui looks so much better

#

did dip my toe into the apple pond with a M1 mac mini when they first came out. It's my dad's plex server now

loud marlin
sinful moon
#

Yeah my M1 Mac Mini was my side machine at work for a couple years, also had an M1 iPad Pro and more.

rapid merlin
sinful moon
#

I ummmmmmm, have an M4 iPad Pro, iPhone 14 Pro, 2x Apple TV 4Ks and AirPods Pro 2 lol now

rapid merlin
#

I just couldn't get into the apple environment. It's unix, but not unix

rapid merlin
sinful moon
#

IT job very ironically is what did it for me

rapid merlin
#

i only just recently got stremio

sinful moon
#

also yes we run a Plex server with thousands of movies we own

rapid merlin
#

Yp

#

Yup

#

I own, cough, lots of movies lol