#general
1 messages ยท Page 476 of 1
any tips for me im also a beginner
Do you have basic operating system knowlegde?
yup a little
since thats always where i advice people to start when they wanna try cybersecurity
like a normal person operate that much
can give me like index
operating system -> ?
Linux, Windows
How did you land your first job
the complete beginner path is pretty good
or pre security
good starting points
operating system -> linux,windows -> ?
i applied ๐
๐
Windows: Powershell, procmon, event viewer, AD, user, groups, authentication, authorization ...
Linux: Bash, using Terminal, kali linux, familiar with different tools..
there are a lot of stuff, I can't list them all here
any resource
I second this
in learning paths i choosed the beginner one
i will see you after i complete this path first
and thanks
I need y'alls opinion. I wanna get a Wazuh server up to monitor my server. Do y'all recommend I just boot up a new Virtual Machine on the server itself, same VLAN and all...... or I have an AIO sitting around collecting dust I could use for this.
no idea what you're talking about
any indian here by chance
Wazuh, SIEM monitoring
Keep the EDR separate imo
Yeah
think its for professional person
So, put it on the AIO?
Not gonna be a huge issue if it's just for your own home use
Depends, what's the specs and requirements?
Yah, just my own home use
I don't know exactly the specs, I just remember, got it from work for free.... Has a quadro, a xeon, and 32 GB DDR3 ram, believe a WD Black HDD? It's an HP Z1 Workstation
i saw someone i know used dell latitude old laptop as server for his website
What in my arsenal isn't overkill? 64 GB DDR4 in my desktop, 256 GB DDR4 in my server, 32 GB DDR5 in my laptop, 48 DDR4 in my other laptop..... 32 GB DDR3 in AIO. and another 32 GB DDR4 in a lenovo server collecting dust
Anything can be a homelab ๐คทโโ๏ธ
I mean, I've got 64GiB DDR5 in my PC lmao
You could even use your phone, there's a cool blog that talks about it
Oh, and 32 GB DDR2 in a crappy Poweredge III server that is my shelf lol
brb... gonna build a homelab out of popsicle sticks
ok flex smh
Only time I think I've ever actually come close to using that is CAD modelling
LMAO now that is a flex
Just casually use a server as a shelf
I need to upgrade my laptop's ram to 64, running 4 VM's at 4 GB each is killing me and their performance... also need to throw more cores at em
my coworker is ignoring me and it's getting in the way of my department goal ๐บ
It was a easy $20 shelf right there lol
Speak to your line manager
i have to create my own startup over this
I will! 
this is my modest homelab lol, nowhere near but serves me well
i really should. i'm always at odds with IT
I still need to start on my homelab
what's the best ddr 5 6000mhz
But i need build a new server
you will be lucky to find a processor to properly support those speeds
already have one
Fantastic
That server is soooooo freaking loud. start it up, and you go deaf. Thing sounds like a freaking airport. 15k HDD's in all 6 bays. Said fuck it, and put it ontop of another server that's crappy, that I got for free, from early 2000, and using both as a shelf
using ryzen 9 7900x
Wha? All their good for, crappy hardware for today's standard
msrp on that is crazy
L
L
i expelled that evil from my life
Not anymore
i have 32 gig ram thinking bout getting new ram 64 gig or 128
is proxmox still good or are there better options?
Do you think it would be safe to buy a second hand pfsense router ๐
Would time that demon got worked on
which memory segment are global variables stored?
oh it's stored on google servers
so true
thanks!
Gave +1 Rep to @sharp sail (current: #208 - 31)
you're welcome!
how much $ you think to spend on router as in general? and what you wish to do as in network or what ever you do?
ok i'm just curious which brand of ram is one of the best, like crucial
I actually want to buy one for my mums computer for extra security
So my neighbour can do one โ๐ป
For her computer?
๐
Anyone know why text message scammers use accounts with rumbler[.] ru, Iโm guessing itโs hacked accounts that hackers are using to send scam messages through.
I had 8 phone numbers, all were gone within the day of me buying them
It would say no SIM card. I tried them in multiple phones
Honestly, for a home network you'd be as well picking up some low-powered second-hand ex-enterprise hardware and installing OPNsense / pfSense yourself ๐คทโโ๏ธ
My perimeter firewall is OPNsense running on an old Dell PowerEdge R220. Ancient tech now, but still works absolutely perfectly. Handles everything I need it to.
That's overkill for a home network. A 50 quid usff thin client would be just fine, provided it's got at least two NICs
Whatโs interesting is that rumbler is a Russian Gmail service. I put the fake usps link into urlscan and it pings a server in China. Makes me laugh because what legit usps website uses a Chinese cloud server
I found a Protectli Vault Pfsense Router Firewall for around that amount
Reminds me...... I gotta mess with my OPNSense server, get that up and working
you have an OPNSense server?
Hi vain
Hello there ๐
are you working on any other room?
Not suspicious ๐
Not as of now, but we are brainstorming ideas for the cheeseCTF sequel ๐
First glance, these look pretty cool
Sounds cool
Meh, not setup... Lenovo server 32 GB DDR4 ram
ah, so OPNSense on that server
ZUMII! Hai :D
there's a sequel?
Not sure how you've found one for 50 quid though
not yet 
Yeh.. or proxmark, don't know, still debating
hyd today?
Least I'm seeing is about 380 right now
you mean proxmox
aye, nice!
Man... my AV wants to decide to use every freaking core to run its scan
Tomato, tomahto
Better than yesterday haha ๐
proxmark is an actual piece of hardware
greedy ahh
I don't know what it's used for but ik it exists lol
Radio attacks mainly
seriously
ah, TIL
Oh you're running crowdstrike falcon? ๐
what was the device used for cloning RFID badges?
Think of it as an older, more advanced version of a flipper zero
But much more powerful
Hi Arhu ๐
Hey there Vain
hyd today?
proxmark3?
oh yeah this one
Good thanks. Had a productive day at work, heading for a running exercise in a bit.
Gave +1 Rep to @gray sonnet (current: #87 - 81)
Lmao, nah, ESET
I've had some fun times with crowdstrike, large codebases, rebasing and recompiling them.
dheck you doing?
abusing his cpu
AV scan
what is disturbing, knowing what is most usual result of mat doing stupid things ||BSOD||
it's CULT
CLAN
@gray sonnet get on it
stop lie to ppl
how to join cult clan? or can i find the information on the website ?
you gotta sacrifice a cow
then follow the instructions here: https://fluffclan.com/join/index.html
Vain?
What are these clans for?
what is the benefit of joining fluff
nothing you'll just be worshiping fluff
for what?
There was a mod here named fluffme or somthing like that, canโt really remember. He left and they crated a clan on him
Oh no, there's a memebers tab, you can see whose in it
and why he left?
or she ?
Think they just didnโt have time to moderate
hmm
definitely not a cult 
We got 14 members in the clan!.. 15 including FluffMe
should i join?
it fake name for matt's CULT
CLAN!
Sounds like a cult ngl
Do yall wear red robes and make sacrifices
@gray sonnet @strong flicker @real token Assemble!
hashashins
what index
Oh I have no idea lol
i think they are talking about home page
I'll work on it in a couple hours
Oh yah, that's blank, Vain, get on it
whaaat
WHAT'S BLANK
your cult clan leader is telling you to get to work
home page
so go
Home tab! There's barely anything on it!
huh
Your cult is slacking.
do u have cookies?
how many clans are there?
I think
?
??
??
what do you mean by killed?
Think real hard
idk lol
you can chat without being verified ๐
Yes you can
skill issue
but i am
i did it
how do u know that he didnt do that ๐
Stay anonymous
I am a huge fan of Assassin's creed
why
what about rdr my cousin is a huge fan of it
ok
me too
Iโm playing Evony
i was gonna play it but then changed my mind
LEAGUE OF LEGEEENDS
can you guess who I mained
I didnโt remove it, at some point discord was distracting me so I left the server
Morning everyone! Our friend, @gray sonnet , just recently went through a bunch of emergency medical surgeries. He's in need of funds for his college. Any amount at all that you could give, would mean the world to us!
Disclaimer: I have been granted permission to post.
https://www.gofundme.com/f/support-anirudh-dillis-education-after-medical-crisis
No
Yes....
I would love to oneday, i have never done it
why
What?
So what
Atleast a watchdogs lover
Love watchdogs ๐ฅ
They finished filming a watch dogs movie
Yes
I played watchdogs 1
Hold on
Miss fortune
Have u watched assassins creed?
Havenโt announced it yet
No but I used to play her back in the day
The movie?
yes
No. I think I tried but I didnโt like it
yuumi ?
me too it was boring
Nah
Fhis
No action for a game thatโs about action lol
Who I played was such a stereotype I canโt believe you didnโt get it
yasuo ?
Bro I beg them to make a assassins creed black flag remake bruh
they are working on it
Sorry guys, i just wanted to know how it feels to be #1
really
Hell yeah
I am a midlane main, I wish I was good at yasuo
Ahri
Warwick ftw
xd bruh even yasuo mains are garbage , very few know how to play it correctly
Any resident evil fan here
they cant
Used to watch the guy โyasuoโ on YouTube, he was cool
10/10
I know one but he isnt here
Fabulous games
if u talkin about "yassuo" ye , but now he is a gambling addict
unfortunate downfall
Oh damn, big sad
Gave +1 Rep to @crude stump (current: #72 - 110)
Gracias
capcom make remakes with luv
thats why they remakes are the best
Factual statement
why there are so many people interested in blue teaming?
And they always pulled it off cus the fans are loyal
I love investigating attacks and defending them
alot of people are in it
๐ป
now i understand
Unlike red teaming almost everyday something is being attacked and there needs to be people to defend it
Iโll forever be a bluey
True
Theyre like the gigachads black hoody wearer of blue team
do you know about the internet archive ?
I want to spend my time hunting criminals
In a Batmobile
โฆ
My gaming name was Batman for the longest time
Some weirdo that used to hang out with us tried to steal it
๐
๐คบon guard
aye
she's scared
time to introduce spidermobile
but it can stop the fight
then fight to the death
She said she is taking tea
maybe
@rapid merlin Levi do you play KOTH
what exams
which grade
ok
u r 17 ?
me too
Pakistan .
and u
nice
yes
but our people are not too kind to each other
yes
๐
I love you people you are way too ahead
@rapid merlin ?
Ok sorry
Sorry
bye
Yes you are the winner bcz refree said
Good luck for your exam
bye
I'm going to kill my printer......
Need to scan something... tells me it's busy.. DOING FUCKING WHAT?!
Thinking about it ๐
Sorry it was me.
Despicable
Must be personal problems
poor printer
There was a whole work around just to get the damn thing to give me the files and for me to upload them
Like... jfc...
I figured this question would be appropriate to ask in this server. Is the anti-virus tool "f-secure" safe and reliable? My father is insisting I run their online scanner on my device, but their website feels very scammy to me
sounds really unknown to me
go for something more trusted
Eh, it's fine. I wouldn't recommend paying money for personal use on a windows device, Defender is good enough* for almost all consumer use cases.
If you are going to spend money on an AV, i would suggest BitDefender as I've had really good experiences with it.
ESET is slovakian and has very friendly ties to russia, for whatever that's worth. It also means that since they do business in russia, they had to turn over all their source code to the russian authorities for "security review"
it's why many companies pulled out of russia a few years ago
Aaaand goodbye ESET
I use Eset
long time
many times that
does it matter? I'm pretty competent in the field
and yes, it's been longer than 5 years.
how much longer, i'm not willing to say.
Oh, I've been learning IT related stuff for 30 years. I didn't start working in cybersec until 2018 though.
hes old as bible it self. juun was doing pentest for Egyptians
2018 is when I moved careers fully into cybersec. I did do other stuff before that. How long before that.....
i was there, i know all ๐
indus river valley, actually
creator of Piramid of Pain ๐
pretty sure that was the south american cultures
GUNDALF
Hey guys, new here. I'm doing MBA and I can choose my major between Data Science or Cyber. I'm inclined to Cyber, what you guys think/
?
how does attack defence ctf work?
any recommended tools and stuff?
I've been facing this error with openvpn. Can someone help?
Yeah MissStealth called it, Iโm a millennial and lol is there to soften the intended impact of whatever I have to say, especially if Iโm not being entirely serious. Nice stat tho lolโฆ crap there it is
are you talking about king of the hill ?
something like that
That is pretty much how it works.
well you dont need any special tools but the ones thm teach you to use to root the machines
but dont expect to win, depends on the time of the day, some people use homemade scripts that root machine very fast. with rootkit and shit
New printer picked out. Even supports WPA3-SAE 
just try to have fun finding vulns and get some flags
3d?
Normal
pif...
My printer is quite old, defaults to 2015 for the date.... leave that thing offline all the time unless I need it.
@sick lance i mistakenly ban myself from my room , please help me ๐ฅฒ
Email support for this
@tough ravine
okk thanks
Gave +1 Rep to @naive violet (current: #2 - 2205)
...was it just to see if you can?
i cannot unban myself
yahh ๐ฅฒ
How did you ban yourself
Support can help out, hopefully they clone your room and add you to it.
i thought as a creator i can unban myself ,
Bonsoir est-ce que il yโa des franรงais ?

I am looking for a mentor, someone who can teach me the basics
Start with Pre-Security pathway on THM , you have everything that you need to know for starting there
Hi, for moderation purposes, we use English to speak. ๐
Thanks for the advice
Good luck on your journey ๐
However we do have some French people in the server, one of the staff who regularly converses is French, or lives in France.
Thanks
Look in the mirror ๐ and welcome
@hollow pivot if you are might amoung alive ppl, let me know... i got question about flint-2 ๐
Hey, how's everyone doing today?
Good , how are you ๐ ?
That's good to hear. I have been better. Feeling a bit sick today, but otherwise good
Guys who knows, how to change the name in certificate ?
Sorry to hear that, I hope that you'll get well soon ๐ 
I changed already in my profile but anyway all the time getting the same name
again and again
Thank you ๐
Gave +1 Rep to @cloud quiver (current: #239 - 25)
Jesus
Is Lord, what about Him? ๐
You can't change the name when you generate a certificate.
Theyโre OOO until next week so probably wonโt respond til then
frack damn it lol
did you might try to google it ?
yes but it says to do 2>/dev/null
check what streams its using, and what the number corresponds to (stdout & stderr)
what command you try to run in first place
find / flag.txt 2>/dev/null
That's not quite correct syntax either
|| find / -type f -name flag.txt 2>/dev/null ||
Oh ok. Thanks
Gave +1 Rep to @cloud quiver (current: #233 - 26)
Can someone explain to me why every time I change my router password it resets and goes back to the default Pw
Somebody reseting it?
Ok, is it somebody else ?
Completely factory reset the router, unplug the cable that gives you internet, then connect with the Admin:password, change the password, connect to the internet.
Iโve tried
what router ?
If you think somebody is changing your password etc
Contact your ISP.
I need an actual hacker to have a look
@rapid merlin Likely its a R/O filesystem when you are comitting the new pw
And if you are logging into the router to update .. .are you doing things like wr running-config or whatnot
I tried, I called and asked them to update my firmware. Got through to an extremely fuzzy call, she acted like she knew nothing and then the firmware wasnโt updated
or try change password in offline mode. like no internet to router. just local login
Not sure how to do that
Every time I go into router Iโm kicked
I just told you...
And then itโs reset
unplug cable that give internet to router from isp
web browser ui it can be accessed via 192.168.x.x ip and login and change
It wonโt load when I get kicked
I get blocked
If someone can get this guy out Iโll give you my left toe
is that case now on this router you are on ?
Yes
Mind you Iโve been getting harassed and attacked for a year after reporting someone for a case
Getting called a whistle blower and it has been a constant fight
Imagine if the police actually did something in the Uk I would still be working on my art business
is there cance that you connect to internet via phone and turn off router ?
if you can be online via hotspot and turn off router and uplog internet cable then you can login on router and do the stuff
what router is ?
that does not help ๐
No matter what internet I got or where I was they find me
I just want my life back
I cant believe Iโm having to learn an entire subject just to be left alone
let me try be nice. tell me what modem is and so... i might help if i know more detail
default isp routers are quite easy. when you get to own routers the shit hit the storm
you dont' need a hacker to audit it. Do you own the router, or is it ISP owned?
Log into the admin console with a physical cable, disable wireless, reboot. If the router has been that deeply compromised, better off getting a new one with a different mfg
sup
if the router is continually compromised with wireless access disabled, there's a bigger problem and you should consider changing the ISP to one that does NAT and does not assign public addresses to customers
Who is your ISP?
@rapid merlin here is quite nice list of ppl who can help and share some words of wisdom. if you ask ppl can help
Wifi pirates
Ah the cantenna approach to internet service
I think you forgot to attach the list
I agree, to double check you're not on it. /s
i can't dox all the list ppl ๐
any romanian here?
Vodafone but it doesnโt matter who Iโm with
Theyโre always able to get in
Why not just get a new one
Not saying this is the case but is it possible you are just super paranoid?
what is full name
of router
No
โVodafoneโ
This is why Iโve not been getting help
also you using VPN in general
if u know admin creds try making the wifi insivible and give it an impossible to guess pass
Because people assume Iโm paranoid or crazy
@rapid merlin check in back of router full name ...
Can I dm you it ?
sure
and see if the "hacker" (if there is one) can access ur network anymore
Bruh got muted lmao
cant get any darker than that
Look the only reason why I assumed that, is because many people stated ways to fix it and even scrubz said to factory reset the router, you said you tried. I donโt know anything that can bypass a factory reset.
Do routers have firmware?
Itโs a hub
Do hubs have firmware?
If they do I'm pretty sure there's malware that can sit in firmware no?
Is it a half pinter now?
@crude stump Isn't the whole bypass factory reset why mobile devices are soft-bricked if you wipe before unlocking?
It's no web interface printer now 
I fixed it, had to reset it. I quite like this printer over my old.... just entering wifi password is a no go, missing characters I need
everything that runs some sort of code has firmware
Yes that is true
They are rare
Honestly I donโt really know. Donโt androids soft brick
Yay don't you love forced updates
in short... every litthe shit have firmware ๐
Love em
can anyone help me with that junior security analyst intro answer?
What will be your role as a Junior Security Analyst?
To analyse the security as a junior.๐
Also the answer should be in the text
Imagine reading the text ๐
Man, y'all are savages lol
And fuck my IT department
Jks
Love them when they don't take 6 months to do a ticket
why do I see so many people be annoyed by updates (not specific to this server), just click "update and shut down" after a session one time
i think people just don't like the unexpected/forced updates. if they have a choice, i don't think they care
We are a 24 hour department. These are CCTV monitoring stations.
When IT force their updates, they don't allow us to delay or stagger the restarts which leads to us being blind
I dont think you get forced updates if you update first many times you get the notification
welp. i don't know what to tell you ha
In this aspect I like apple. They ask or inform that the update will happen in the night or you can update now.
oh right the 24h thing, yeah. Still odd about the regular users I see tho
yeah. i respect Apple for that too.
I also like Linux. Debian in particular doesn't force updates at all ๐
actually. wait. i have had some weird moments. but it's mostly cool lol
Regular users don't see the restarts as it's always in the evening or overnight.
like, i recall one time i shut down and my computer literally turned back on and installed updates lol
but most of the time that doesn't happen
๐
Working on talking to satellites, on and off
O_O talking? or listening?
Im working on AWS cloudtrail investigations
I have a license, so talking
You can get a license too!
haha, i'm too afraid. no thanks lol
Ham radio license lets you talk to ham radio satellites, amongst other things
what was the typical response be when you try to contact?
There's people on the other end
You beam up, it beams back down
cool
Most comms sats work that way
"So.... how's the weather"
would you be able to transmit to ISS if ofcourse if all things line up
ah, whew - you freaked me out man. i thought you were like, pentesting a satellite at first or something, haha. then you mentioned HAM and a wave of relief came over me lol. (not saying you're not qualified to pentest sats, but man, wouldn't that be scary?! haha)
Yeah I got the kit for it, just... Need to go outdoors and set it all up on a good pass
so cool
Doesn't take a lot to talk to the ISS, I listened in on a contact the other week
Signal was weak but it worked
We let students have the excitement of talking with crew members on the ISS, inspiring them to interests in STEM fields. Event info at https://t.co/lK6Sqbx1CN.
i want to get my hands on that eventually
Get a ham license! Not sure where you are, but UK and US are pretty easy
What would you even say though
and what gear/ docs if i want to get started?
What's the difference of vulnerability research and reverse engineering
whatever but it would be so cool irrespective.
Getting your license should involve a bit of study, so you'll learn about the gear and docs you need.
Long story short, transciever (radio) and an antenna
gotcha
build it in a cave with a box of scraps for the authentic feeling
i was tinkering around with atlas and ATTK maps. I set up my own maps with Navic Indian nav system
In a time where we have starlink they still communicate with radio?
Little toooo high frequency for that
Starlink uses radio.
i'm not an expert. but i'm pretty sure they go hand in hand. reverse engineering is used for vulnerability research. reverse engineering allows you to figure out how software works (even binaries or closed source projects, etc.). Then, you use that understanding to find out how the code works and find vulnerabilities with it.
Wifi uses radio (microwaves)
Ethernet signalling is baseband, basically radio but slower
Yes I mean in master degree u do vulnerability research
And reverse engineering is for example ghidra
What's the difference
Not sure. It depends on the degree probably.
hi everyone
What you do in other degrees
I would contact the school. They'll have all the details.
i'm confused. what do you mean?
how long have you guys been doing cyber security for?
They told me it's more low level, protocols and maths
started 20 years ago. Took a 12 year break (on and off). Getting back into it 5 years ago.
You told it depends on degree
So 5 lol
Learned another thing today ๐ sounds fun doing a little research on that
thats nice to know. im new to learning cyber security
8 haha. i edited my comment
what did you learn?
Iโm the best
rigght
how long did it take u to get where u at right now?
Honestly im not that far
i really wanna learn alot about cyber security
I do it every weekend
Is koth active still?
and how are you finding it ?
I love it
Going to be honest, it took me way too long to figure out that transceiver is transmission and receiver mashed together
does anyone know how to hack wifi passwords?
can anyone try and find the source code to this (dont run it as it bricks your masterbootrecord)
@naive violet or @mossy river do, it's their favorite activity
Just a moment
@naive violet can you teach me?
I'm building a transverter at the moment.
Transmit receive conveter
Yes but this is a restricted topic -> https://tryhackme.notion.site/Advanced-Discussions-8d3d6f19846943fe9f0e3febaa6ae607
can we message privately
i have a question can u use cmd ?
i seen this one yt video
Sorry, we do not bypass the server rules here ๐
no worries
It sounds like you're new to cybersecurity. Why not sign up to the platform and learn how cyber works? https://tryhackme.com/
yeah ive already signed up just thought u guys can help me
Noone is going to help you hack anything. Especially some stranger on the internet whose intentions are unknown.
New printer is setup, way faster than my old one
@left hornet Please don't distribute malware here
how did u learn then?
i wanna be the good hacker
hello
my question is can i stream and upload youtube videos for tryhackme machines?
Using platforms like tryhackme. Part of learning is learning how to learn and being an autodidact
The golden rule of hacking is you don't hack anything that doesn't belong to you.
Once you have learnt about the laws and ethics, you can learn how you can get the proper legal permission to attack stuff that belongs to other people with their permission.
For their writeups, or stream/ youtube vids OF the rooms?
stream/ youtube vids OF the rooms
@mossy river any restrictions from THM POV for this? Not sure if y'all have any rules round it.
i seen people online doing it but wanted to confirm here
Yeah, you can't use THM art as thumbnails, or reveal flags, hashes or passwords
@placid bridge ^
everything else is okay? as in the proccess, and commands
just blur out the flags hashes and be custom thumnails
This only applies to ones posted in the Discord server and ones published on the website
Ah, I thought it was a general rule for all.
@sick lance how to join creators-launge?
time for early sloop sleep to the beop boep while meep moop so that shadow can deal with lab stuff tomorrow
โ Gave the role Creators-Lounge to 0x_indranil
gn shadow
Night
so i can post videos of me completing free room challanges just blur out password, hashes and flags? is that correct?
Whatโs up fam, missed you lol
holsa
lovely avatar
Yup:)
You can email support for a more detailed breakdown of the do's and don'ts :)
much love brother for sure do u have an email?
well, that's pretty obvious but ofc you should if you want to
linux host OS?
and a flash drive or some shit like that
as a host OS?
I just use a VirtualBox VM
just use vmware
But I also checked out WSL (Windows Subsystem for Linux)
You can install Debian or Kali within Windows like an App
ahh ngl i just want linux as my main op system
yeah its good but doesnt have much
never do that tbh
least imo
whys that?
using vms is everyone method and mistakes on ur host and having a not a goo dunderstanding of it can just lead to issues
i wanted that once but it isnt worth it imo
imagine runing rm -rf /
rip all ur files
I've dual booted Linux and Windows, but I don't think I've ever run it as a main
yeah
hacking is kali linux or parrot
I use Kali for most pentesting things
well im a newgen
i tried parrot but moved to kali
but if i was doing daily usage, I'd use Debian
wanting to learn so learners one
anything I want in Kali, i can install in Debian ๐
facts, it's lil bit harder to maintain linux
Debian is what Kali is based on
ahhh
Kali just has everything and then some pre-installed
what are the basics i should learrn about ccoding an shi first
yeah they made vms specfic to situation based on linux
python is good to know
kali is for pent testers
bash scripting is also helpful
like ik bat files almost jack shi about python c# and shi
I'm not an expert ofc but I'd not recommend daily driving kali tho
bash scripting is the linux version of batch files
ahhh oaky
learning coding will help multiply ur hacking strength its not nessasry but will make u much better
code review is important though
you will encounter and will use a lot of b64 encoding
./verify
./verify
ight we good now
verified myself
rip
ngl been forever since i been on tryhackme
ill slowly start using it again
๐ what i do man, i used to use tryhackme 3 years ago but stopped
still a noob tbh
do the incave box.
yeah, hopefully i keep like a daily thing of things to do if i get time i will ๐ฅฒ
sniffs I smell bullshit in this sentence towards me
๐
today was refining my sql injection methodolgy and ill be doing 3 boxes of it next
give me the raten raten raten raten raten rat!
lol how so?
just finished watching some show
.
cd .. && ls -la
although sharing uname -a and or neofetch would be fun
turns out I have way less in my iOS gallery than I had hoped lol. Wereโs my NeXTSTEP oneeee
lol like 90% of the posts in #general regarding NeXTSTEP were from me
close enough, thereโs uname -a on Apple Rhapsody DR2 (x86)
bah where are my *nix nerds!
Oh I have no idea lol
Welp.. was going to setup Wazuh today.... did not do that, oh well.
Why not? Didnโt look too super complicated despite the server infra required
at the same time I get you, I donโt always have the energy after a day of IT/infosec for these kind of projects lol
guys help there is a bug like always on the machines
i use this command :
Set-PSSessionConfiguration -Name Microsoft.PowerShell -showSecurityDescriptorUI
but it wouldnt open the window UI as it says :
This will open a window where you can add thmuser2 and assign it full privileges to connect to WinRM:
OUTPUT :
PS C:\flags> set-PSSessionConfiguration -Name Microsoft.PowerShell -ShowSecurityDescriptorUI
WARNING: Set-PSSessionConfiguration may need to restart the WinRM service if a configuration using this
name has recently been unregistered, certain system data structures may still be cached. In that case, a
restart of WinRM may be required.
All WinRM sessions connected to Windows PowerShell session configurations, such as Microsoft.PowerShell
and session configurations that are created with the Register-PSSessionConfiguration cmdlet, are
disconnected.
WSManConfig:
Microsoft.WSMan.Management\WSMan::localhost\Plugin\microsoft.powershell\InitializationParameters
ParamName ParamValue
assemblyname -
pssessionconfigurationtypename showSecurityDescr...
PS C:\flags>
i tried :
Restart-Service WinRM
Oh, printer issues... ended up buying a brand new printer, not 3d, just normal. But that turned into me hopping on my desktop after a month of it being offline....... so, a lot of updates
A lot of app updates, not even just windows, I'm still working here updating my desktop after 5 hours after I got my printer
Omg... the defaults security wise were abysmal
No password encryption, 112 Bit SSL encryption, every... fucking... protocol enabled...
it's always the printer or the DNS ๐
damn guys UsDoD arrested
I had to go through, disable IPV6, a bunch of protocols, SMB 3 enabled with encryption and hashing...... think I spent at least 30 minutes testing, making sure everything looked good
Ainโt that old news
he was doxxed before
Or actually I think only his identity was exposed
Yeah
this is an arrest
Good
good? :( he was my G
He can be your g in jail too
๐คฃ๐คฃ๐คฃ๐คฃ๐คฃ
spending time in jail with your Gs
what else you want in life
iโm just joking guys black hat is bad
why did you disable ipv6?
If itโs not something you are using practically in small business then itโs just an additional liability
near 0 reason to support it on your internal networks anyways atm
worst case it could be a massive blind spot for your org or orgs. As IPv6 logs are often stored separately
No IPv6 in my home network, so no IPv6 shall be needed on le printer
What type of printer are we talking about
My bad, I assume that he had ipv6 support, I had everything on ipv6 in Israel
No worries, yeah most small to medium business just turn it off since itโs often a massive blindspot
Guys we are coming in a bigger way
2k sales in the new store
Moving to 5k soon inshallah
What
Hello everyone ! I'm new in cybersecurity community ! I'm very glad to be here โบ๏ธ
Anybody know any decent Alpine compilers on GIT? Trying to run some more protocols on my barebones ISH
hello everyone
can someone whos pro help me pls ?
i got a quesstion.
can someone help pls ?
this is the quesstion.
Whatโs the question? I ainโt a pro but you can probably ask in room or site help
Violation ๐ญ
what kind of information does aircrack-ng need or use from a capture.cap (for example name.)
that will aircrack-ng use and a word from wordlist to crack the the password.
or how does even the wpa2 password cracking work ?
in need.
or how does a aircrack in deep crack the wpa2 password
(what info does aircack-ng need from the (4 way handshakes) use to crack the password ?)
i come in peace ๐ญ
i needed a technical ethical help bro ๐ญ
im not black hat yo
its related to "hecking"
friend but i guess i need information which you don't understand i guess ?
or do u understand it ?
as if u see my profile i say im 3+ years in ethical hacking.
if you need ask quesstions if u need proof
lol mind games, love it.
... if you don't care then why are you answering me stuff ?
its not Try Hack Me related but its related to hacking bruh...
Your G? time to snitch to the FBI
idk why you agresive af bruh
I aint reading all that.
Good for you, or sorry that happened to you
Whats the difference between paid and free? Just academy stuff?
nope buddy its asking in general chat a general question this chat aint #room-help
More rooms, 24/7 access to the attackbox and more resources on the machines
It looks that that the only one that doesnt understand its you
Me when I don't understand what teacher is saying
it is related to hacking BRO ๐
i want to understand how it works.
i aint idk what you think i am. or whoever u think am i.
i said and will say again
i come in peace and need help related to ethical hacking speseficly on
how does aircrack-ng work / what info from 4 way handshake does it need to crack the pass or the hash.
how it really works in deep.
Thank you. I have HTB as a sub, was going to try this out too.
Gave +1 Rep to @chilly veldt (current: #7 - 889)
...
then why tha hell people keep telling me what am i able to do or what should i do ? ๐ญ
im in general chat to ask simple quesstion..
No worries
Hey wifi hacking is restricted to the advanced channels #rules @fading dagger
What rule may i ask you
Rule 10- Follow our community guidelines -> https://tryhackme.notion.site/Advanced-Discussions-8d3d6f19846943fe9f0e3febaa6ae607
yes
as i knew it does that.
but i want to know more deep how or what information does it need to
take values
hash them
do stuff
and compare hashes...
i don't want to be a script kiddi bruh
General chat in most discords like this are for memes. Actual channels are for help
ty tho for answering not like others ๐
np buddy
huh
i just joined to ask for help...
for example which channels are for asking quesstions ?
Exactly, our advanced channels are for discussions where we need you to have specific requirements so that we know you are here for Cybersecurity.
Oh cool! So in not no access channels he can ask questions
I also cant see those channels
Yes, please read the document:)
: ( same
do you use arch linux ? ๐
respectfuly.
Not to be mean but.... So I need to read a documents do x and y to get access to a channel to ask a question?
No, it tells you our requirements to get access to the channels:)
I use Ubuntu
@quick dock
okk
Thank you
๐ญ BRRRUH
But ty Jabba
Make an account/ link it to discord for the help channels
this aint open source kinda stuff bruh : (
I'm always happy to improve our community. Would you be able to elaborate on what isn't "Friendly" here? :)
Its bit over complicated for example to ask for help on those topics
Mos peopel joing because they like THM or they need help with anything regarding to hacking
Or they dont use thm a lot
Wait im not allowed to talk about wifi cracking and asvanced topics until i get OSCP? Why
i asked simple quesstion how is it friendly comunity if i needed simple answer and nobody doesnt answer me or i need to wait for idk like a week to level up to ask 1 simple quesstion ๐ญ
who said?
Maybe reaching to lvl 13 is not that hard
Someone pinged that above
strange
Yeah but why?
Thats kinda dumb
This Discord community is for the TryHackMe service, while we are happy to help, we still have to protect TryHackMe's interests. "Hacking" discussions are often for illegal purposes which is against Discord's TOS and will result in our Discord server being terminated.
Mmmm but you think that thats the best way to deal with that?
But we talk about ethical one
It's a restricted topic. If the question was about a TryHackMe room, we are more than happy tro help #room-help
agree.
Not to metion other.... server..... ๐ข but they dont have those restrictions and you can actually ask anything
in the correct channels ofc
so can i ask my quesstions about wifi stuff in #room-help ?
name ? pls
No
okay.
After a lot of research, yes:)
@quick dock Please do not circumvent our server rules!
i couldn't veryify my acc in that server ๐ญ
try all of em until u find the right one
I see
Thats not a circumvent thats a noob asking for help in a legit pentest scenario
If it's against our community rules, you suggesting somewhere where they can ask the question is the definition of circumvention ๐
As a side note: you shouldn't be asking random people online for help with a "legit pentest scenario" anyway. Ask the seniors at work.
i got ban'd for making jokes the popular server ๐ญ
i can't even try to get back on the server
they don't care
nothing personal but mod's are bad people. (like gov. kinda people.(if you got problem send it to email me.(and waits for years ๐ญ )))
yesterday i found the fluff clan
nothing personal about the mod's in this server !
fluff the only mod they love
Isnt that what this server is for? To learn
No. This server is to provide support for the TryHackMe platform.
Ok fair, my mistake
All good. Easy mistake to make ๐

"OSCP | PEN-200: Penetration Testing with Kali Linux(About 3 months):
This certification serves as a gold standard in cybersecurity and often bypasses many HR screening processes."
what do they mean by "bypasses"?
Fancy way of saying that it's often a keyword to get through HR checks
So have this and you're getting an interview basically?
As in: OSCP is on the list of certs they look for. If you have it, you may get to the next stage. If not, nada
Not a guarantee
But it potentially removes an obstacle if that's something they are looking for (and it often is)
You do also still need to have relevant experience/ be a good fit for the role / etc
Can confirm OSCP is good for getting job interviews
It basically means that you'll have a higher chance of getting noticed
That ^^^
And it just so happens to be the one that costs $1600 
Well, that and it can outright exclude you if you don't have it lmao
All the CompTIA stuff seems way cheaper
For now... Offsec were just acquired by a private equity group
Expect price increases
We shall see if their reputation holds
$1600 is the minimum, thats if you can do it in 90 days.
If you want 1 year to complete it's $2500
@pallid lotus @simple valve Guys what is the best advice for a semi-new person on pentesting? What are the key values to be able to go further and move freely in each environment?
Im asking this because I stop doing pentesting to do other things and right now... I feel lost, and some times I get stuck in easy things or not being able to find the answer or the "way"
i posted my quesstion in #room-help pls help
Approach a sales rep if youโre from a company. They usually give some discounts.
Unfortuantly I am not from a company.
"pentesting" is a job role. If you're a pentester, speak to the seniors on your team if you need help.
If you mean hacking generally, you'll find that it's often quite different from pentesting.
Both
Attend a local conference where OffSec is a partner. They might give out discounts.
At its foundation pentesting is just a really specific QA check conducted by a professional with "hacking" skills.
i.e., you follow a methodology (preferably a custom one built on top of a standard), and use that to framework the testing you conduct
I'm like not in this industry at all. I work in a completely different non computer industry. I'm just looking into possibility of a lateral career move. As in I dont want to start from the bottom because it wont support my family
i hate the mod's on this server.
i needed help but i see i need to wait for weeks in this server to get access to special channels to be able to get a answer a simple quesstion.
i do not recommend this server ๐
cries in PA Dutch.
Very very few local events for me ๐
people don't change.
if they are paid well and comfortable
they don't give a f about others.
i hate and will forever hate people who are like mod's in this server : (
Same here 
A) conferences are a good bet then,
B) remember that cybersec generally is considered an advanced IT topic. It's rare that you'd be able to move laterally into a cyber role from a completely different industry.
That said, the flip side there is that starting at the bottom is generally still pretty well paid.
I'd be looking to make at least ยฃ35k for the first IT role if that's even possible.
Anything less and I'm losing too much switching careers
The lowest salary I've seen for a cyber role in the UK (SOC tier 1) is about ยฃ28k straight out of uni

