#general
1 messages · Page 480 of 1
@rapid merlin that's like basic 😂 but a good start for a young man like
I like Trilium, some like Obsidian, you also got Joplin
I use Onenote, pen and paper and my white board.
User interface on mobile
Obsidian FTW
It was meant as a joke😂
Just a heads up - there's a lot of business pressures that can affect careers, just saying that "skills" prevent someone from getting laid off is not how the businesses judge keeping someone on the payroll.
The method for taking notes, is not as important as "how" to take notes.
Write notes using smoke signals 
Taking notes. I use obsidian and notion
Notion? I though that only for like organizing stuff
Nice
I might tru
God I am just very literal person
Well I guess that depends in many factors but u r kinda right
Yeah I mean u gotta do some to do list to track ur progress at some point right. And use obsidian to link interrelated topics and also good for writing ctf write-ups
Oh well, time for my stop, have a good one everyone. 👋
this
Till we meet again 😄
❤️
Ok but, I already completed 3 paths and the notes I only took were photos for the tasks in the room it will be highly appreciated sending me your notes
Very nice look
ty
Did u customized it yourself
arch btw
Maybe u should add ur pics in the note taking apps
arch yes. a lot. obsidian, not so much. i spend fair amount of time to custom it. look and keybinds thing to be faster
Fair enough 😂 you can't say u use arch without doing that right.
Which de is tho
hyprland
Damn I know that is something I should try
I usually use debian based distros but recently I am kinda trying black arch
Changed the colours @loud marlin? Its cool tho
colors are based on wallpaper. script create 15 colors based on current wallpaper. and appy that colors on system
Lovely and cool
Dude I can never do such customization. Did u followed some walkthroughs or u just made that from scratch
used ml4w as base theme. check github
as new wallpaper the new colrscheme
why 15
idk. it is script like that by default
arching
yea
Will do. If I have time and the Energy 😂
i hve kali also hyprland
Can I take a peak
gib few min. got some thoing to do
any mods around?
ill send in 2-3 min
you also got DM from rinz ?
please mute @heady nova
yup
I got his phone number from when he was working at microsoft in my city, I am calling him to inform him
i just got DM from Rinzler with malicious steam gift card link, VirusTotal flags it
bad rinz, bad 🙂
yea
I didn't like the file manager but the rest seems cool. Especially the transparent part
@sick lance our rinz got hack... can help ?
Not really.
frack =/
i got compromised
good thing i immediately went to VirusTotal
Secured your account?
check friends and apps
my linkedin got compromised yesterday
shows you are likely a spammer
also login sessions
time to fresh os install
any other way?
I have labs setup
hmm
let me see
change all the things... use vpn
I dont think files get effected
change all passwds and so on
dont use betterdiscord if so crap thing
One of my mods in another server also got hacked the same way. He went to bed and next minute he’s spamming scam links
best of 🍀 luck to Rinzler
checked em
no better discord
windows ?
yes
ohh
can be as most like
might be best to do
aight
you can reset and keep apps and onedrive
gonna fall back to kali
as daily driver?
nahm, I'd choose *nix
yes
the Rinzler is no longer labelled a spammer
long time folks
the linux disease
haa
might as well tear down you walls, the viruses hide there too and transmit harmful emf
put foil on head also
got it
DE REZ ! DE REZ!
hey sudo , how you been?
could be better, could be worse. been learning more about databases for potential jobs, still unemployed
how about you?
hey, not always gonna be night
been hustling here and there
the 🌞 will rise eventually
how was the MSFT internship awhile ago - last time iwas here
It was good
a bit hectic
9-12 was in office
9am-12am*
wowza
they liked your work in the grid
now I'm gonna try build a business alongside a 9-5
alot of money down the drain prolly
but hustle is hustle
and bustle
mhm, you in eu?
nope
us?
i am wherever you want me to be
@gray sonnet nope, still can't dm
wym you still can't DM?
in the hustle grid, that pfp still is as green as ever
wtf, when did discord implement that?
and I see people falling for this
try re enable
suspicious activity would naturally block you from DMs
and try emailing discord
aye
let's see if i can get a sample
smort
am part of the botnet prolly
anywho, I got a chemistry mid term to prepare for, I'll cya'll later
keep calm and reinstall
chemistry!
get those benzoates good
p
drink dihydrogen monoxide
new energy drink?
lol 🙂
its water
H2O = dihydrogen oxide
⛵
❤️
it's punishment from heavens for playing too much dark souls i guess
when they told me it's not for beginners they really meant it huh
skill issue 🙂
How can I use the attack machine if I don’t have anymore hours
Can I use my own Linux?
Yeah, connect to the VPN.
yes. use vpn from thm
https://tryhackme.com/r/room/openvpn can help
Okay
D: shadows poor pocketflare
hi shadow
dheck is pocket flare ?
I have Been having trouble connecting using OpenVPN. Hope this works
ello ello veggies
mini flashlight that is from keyport
@loud marlin
yes my dear ?
kali good right?
ubuntu
a bit.... had to go sleep before sitting in front of pc all night long
go ubuntu or arch might
got it
https://hyprland.org/ and check wiki ofc. if you didn't
arch come with almost no "standard" app on it. clean os 90%
and which arch should I go with
https://archlinux.org/ and watch vid of how to install via archinstall scripts. manual install is pain in ass
got it
or if you want more like archlinux but with graphical installer and working out of the box more or less you could try endeavour os
whaaat... no rep 😦
+rep @loud marlin
Gave +1 Rep to @loud marlin (current: #24 - 352)
thanks
Gave +1 Rep to @sand trench (current: #3 - 1925)
@sand trench show it 🙂
Thank you for reporting this. We are investigating. 🙂
Gave +1 Rep to @vague coral (current: #2275 - 1)
ello tim
You need to change your account password, it bypasses 2FA
Let's see the first person who can switch around the letters in premium user 😄
not free user
@heady nova managed to get a sample?
So it's not an image that is attached: 🤔
Something to do later I guess
I apologize; I am just curious about new things and want to learn cybersecurity, but no one has helped or guided me.
so corny honestly
what is bro doing 😭
Nothing now 
oh well guess this didnt last long for him now
THM rank as job title 
I'm sure you can fingure it out. 🤔
God damn Hydra is annoying.
I can use it to get a username, and a password to a ScadaBr login, can i do it together.
Trying to demonstrate the many ways it can be done.
Python script, burp and Hydra done.
Zap and ffuf next
fuff my beloved
Anyone who good in .net programming
Is anyone else driven nuts by Captchas asking you to identify a motorcycle, while showing you a picture of a scooter?
What is that
five hundred instances of python
only the person asking for .net advice
What’s the command to download open vpn on kali Linux
if i had to guess sudo apt-get install openvpn
a role? at thm? as a CTF player?????
what
sudo elevates your privileges for the command. i just assume it's needed because messing with networking usually requires root privilege
That is not a real role for the record
I'm aware, that's why it confused me
Oh okay now once I have open vpn how do I open it
People on LinkedIn put their job title as CTF player at TryHackMe 🤷♂️
is room tester a real role???
sudo openvpn ./yourvpnfile

we got pro play in tryhackme before gta6
How do I find the file location of the vpn
huh
https://tryhackme.com/r/room/openvpn you should read this room
I can’t find it
read the room is a funny phrase to use there
It should say your username and then .ovpn
Ok
should be in ur downloads folder like any other file
or sometimes on the desktop
Nothing in my downloads
Oh well
check in ur browser the download directory or even better click open file location
redownload it again i guess?
Are you using the file explorer or terminal to check?
Nah nothing there
If you’re downloading it, on your browser press “show in files” on the downloads page
does anyone have a fun room suggestions for me? 😺
Guys I download the vpn for Linux but the file is 0 when I write in terminal sudo openvpn the file name can’t connect. I use parrotOS ?
You'll probably get the same output if the file isn't working
Maybe ask in #site-support too 🤷
^ easy to medium for me
Linux Fundamentals 1 + 2 + 3
Thank you
Yeah Linux fundamentals for sure
Also check out OverTheWire if you want just raw Linux ctfs
Okay
bandit labs
Lowkey the best way I learned any sort of Linux stuff was to just use Linux
Ong
I went all out and ripped out windows and jumped in without knowing what to do. It was the best way to learn imo
But if you don't want to do that just dual boot and try use it for normal web-surfing for a while
How do you dual boot again
Don’t you need an extra hard drive (ssd) with Linux or anything on it then wanting to use Linux you go to your bios menu?
Or am I completely wrong
I think you can do it on the same partition
Or no
A different partition, same hard drive
I've never dual booted lol
If you have the option, I'd also suggest WSL. Just the terminal (I think) but if you use it often you'll get used to it
Like with a lot of learning you just gotta dive in and get used to it to learn anything
At least that's how I see it
Is there a way to stop the stupid spam,scam messages on LinkedIn
dont open the messages 
I can close them 👀
the inmail stuff from recruiters are always funny
pull an uno reverse card and spam/scam them back
They’re gonna turn me into a computer
That Message Sounds Very Legit Especially Because Of Capitalized Characters!!!!
I feel like this is when I hear new rumours about me and I’m like wow 🍿 tell me more
Sounds interesting
😂
you're not gonna miss on the opportunity, right??
🥳The emotes 🎉
let us know how it goes being "FORMAL Task Manager Position"
send them a picture of a task manager 
that is the only best move
Tell them I’ve already hired one for myself
There’s only space for one task manager around here
How come on the site it says I’m level 3 but
On here it says 0x1
you can grab your discord token again and re-verify
verify again
it will update asap or it will after 24 hours
no worries
Yurrr
I'm level 999999 but here it says something else wth
mmh did someone had to generate their vpn after the new dashboard release, or is that just coincidence?
somehow my all time working does not anymore 😦
Maybe, someone was having issues here before
Yurr
It'd be weird if the frontend changes affected backend imo
ye :/
Sick new color
Yepper
stranger things have happened!
What does level 4 looks like
True lol
ayy, looking good, congrats 😄
Yea
grind up and find out
I ain't paying for glorified IRC
i am 
The standard one or for a network?
the standard one, vip, my beloved 10.8.211.1 😅
Yeah just keep doing rooms, you'll learn the process
Gave +1 Rep to @sand trench (current: #3 - 1926)
12 rooms a day ? i think u are speedrunning more than learning
My dad is vaping in the car and it’s making me feel sick 🤢
dad ? vaping ?
how old is he 30 ?
@umbral bay does that count?
Yeah he used to smoke a lot but he got copd and now he vapes
But it smells awful
even tho vaping is VERY unhealthy , recommond for him using mint/cherry vapes xd
He’s using something that’s like gold blue tobacco flavour
It doesn’t smell like tobacco
Vaping is the worst way to imitate a steam train, ever.
I like the smoke tricks you can do with vapes
But I don’t vape
😂
i can smell it from here 😵💫
You must be easily amused.
Likely the VPN server got updated which invalidated your ovpn file. Did you have to regenerate it, and does the new one work?
You already said something similar to this before and I agree
new one does work, did not have to generate. Only missing my ip :p
I have to carry a mattress down a main road
It does not. 😄
Pretty strange way to spend your Friday night, but you do you I guess.. 😄
This is awkward.
Where do you live?
reveal urself chinese spy
China, spyland
everyone missed friday 13th like a month ago or something
I missed tattoo deals
Annoyed me a lot
Life is good 😏
That's good!
what happened to your face lel
beep beep VROOOOOOOOOOOOOOOOOM
Wait wym 😂
Cars b like
13k?
https://tryhackme.com/r/room/defensivesecurityintro Whats the last answer of this room
why are you asking??? just follow along with the view site button
Hello
#room-help please.
This is illegal and against our community rules
If I was going to remove you, you would be gone:) this is your chance to try and follow our community rules
Damn some tea
the person had lot of free time in their hands
Probs a kid
@chrome vale ayy how was the ejpt ?
@wraith fjord I passed! 85% haha. No points for metasploit despite using it quite a bit. No idea how the grading works. Appreciate the ask!
ayy congratulations !
Thanks 😊 !
office rules 😂😂😛
Especially on Friday
Yep.
This is actually my workplace's evacuation plan as well.
Windows defender
They really missed an opportunity here with: 3. git out
I'm back y'all
well you gotta git push the door to git out
I remember you omg you refer to yourself in 3rd person

got into uni as a computer engineer and started doing research and project in robotics. Now that I work a lot with Ros I'm seeing a ton of vulns so I'm back to the fun
resetted progress on all of my rooms
ello ello
damnnn, do u like it tho ?
@placid bridge How many rooms?
on try hack me?
i think 39?
ion know
dont use the internet
Keep your computer offline forever
do more.
why would you have to?
inshallah later i just been doing oscp for now
had a challanging ctf machine they gave
2nd time? 💀
im not done obviously, im doing the course work
ill be done in a monthish
simple answer == you can't
more in depth answer ==
you close down as many of the low hanging fruit holes as you can
using strong passwords form a password manager
multi factor authentication on everything you can get multifactor on
keep your email secure
read up on how to detect common scams to avoid falling for them
make sure you have windows defender enabled as malware protection
let windows firewall be active and installed
do the htb Pentester Path too man.
would also prep you better.
finished that
just never gave the cpts exam
right when i finished i just bought oscp
and started that
and yeah it prepared me better

think @mossy river might be interested
One Hammer ticket please.
No, private sale is not allowed in here
YAY a scrubz
ye oscp has some labs that id rate hard or very hard machine
I didn't get a plane ticket.
LoL
cool
enjoy your course man
I don't plan to ever take OSCP
ye fam hope ur journey goes well
my plan is OSCP -> CPTS -> OSWP -> CWEE and so on
IT IS MAN, having good notes is such a good skill
wallahi try bookstack
I struggle with it every day.
amazing resource for note taking
u use obsidian right?
Cool
with newly released theme by golam71.
yeah id say obsidian is good but i realized long term it wont be helpful for me
so i moved to bookstack
just for long term oganization
basically a self hosted website
Ive been learning for around to months and i havent taken any notes, yall are making me feel bad lol
well an alternative to note taking is trying to teach others how to do what you are trying to learn
def take notes
long term helpful
memorizing is good too
so if u take notes repeat them by typing them
dont copy paste
Did a whole ass room and its 2 am and i cannot write notes :/
I will do it tommrow ! 😦
*Did got root as well.
right yeah i deff need to start and even though i havent i also havent talked to anyone about what ive learned etc i know thats bad and i need to start talking to people more on here aswell.

ill check out bookstack
Hell yeah what room?
i prefer u start with obsidian tbh
heres an idea
of my old web enumeration notes
alr np wow yeah that looks way better on readability
ye ye
make notes
and then put them in a canvas
for readability
bookstack doesnt have much readability
just has a better way to organize massive content
@placid bridge Sorry for interrupting do you speak Arabic?
la
thats all ik
lol
Akh. Al-3afu
im guessing it would be better for larger learning like going for a cert or something
bookstack^^^
i mean its good cause i had to combine notes of multiple cert to make one path
Use Krita
ah
How far are you guys in cyber security? I just started my degree in computer science 😄
what plugin you using for gprhs?
Simon does both.
takes extensive notes and teaches other from there
What what you using fo rthat?
like this
bookstack brother
notes arnt complete tho
have to slowly move them here
Nice arts
im personally not that far im about 60% of the way through in complete beginner path, starting from pre Security, and trying to learn bug bounty stuff on the side
finished 🙂
Nice! Congrats!
yess is that ur notes?
Oh shoot, that’s neat! It’s a fun degree 😄😄
You can never reach the top of or the bottom of the spectrum of cybesec.
def was
0xBEN
no idea who that is but yeah

Oah will try.
ah ok still doesnt look bad but smaller tasks i can see how obsidian would be better
chk htbcord. 😉
Huh
Yes haha I was so confused
My bad
rockyou is taking its sweet time with Basic Auth...
did the labs actually require u to brute force

doubt it
OSIRIS room last step is killing me
maybe CQURE tools updated a lot since then
at 50 requests per second you'll be a while
Oi uei! 'omelander done killed my wife and took me bloody son
Lmao😭
I cant wait to finish one of my courses the software I use requires me to disable memory integrity
x2
soydevs
I am trying to understand some code right now and it hurts my brain
If it acts as malware...
brainfuck will be even crazier
...it will be treated a such.
pyinstaller also is seen as malware
pyinstaller pes are unsigned
ik
why smartscreen is alerting to a seemingly signed app here, i'm at a loss
but even when I just compile
a legit program no malware in it
it just says malware found
yeah because unsigned (most likely why)
when I was on windows lol
windows be hindering your workflow like crazy
glad I switched
yeah idk it was just the installer not that actual app
i mean yeah windows does that quite a bit but requiring signatures is actually reasonable security wise
yeah well I dont need that spyware av anymore lol
all the telemetry it is packing too
as much as i dislike microsoft, not sure if i'd go that far in regards to defender anymore
it is well known that defender also spies even when it blocks malware
it's become quite solid over the years and it's not as ridden as people expect from M$
wat m8
...define spy?
telemetry is spyware to me
i mean yeah but what
meep moop time for sleep sloop
just open wireshark and you will see for your self
windows is a telemetry shitshow but defender isn't the telemetry behemoth here
is there a way to switch my thm account to a different discord account
Sort of phone do you have? 🤔
lineageos with no google apps
Yes, you ask a mod nicely.
it does send data for operational needs but so does every other modern AV
Makes sense now.
alright thank you
Gave +1 Rep to @sick lance (current: #1 - 2881)
clamav is probably the only modern av that comes to mind that doesn't send real-time data and that's a very different type of AV, one that doesn't spot the same issues
I mean google play services USES FRICKING 400MB in the background dude
google play =/= defender
never said that
oh yeah -- defender just isn't the enemy in this case
and I hate everything coming from MS
I liked windows defender threat intelligence dashboard for enumerating subdomains from websites with 1 click to a csv
it could give me 5k subdomains in 1 second
it's time @sick lance
it is paid now btw
Hoping it's isolated.
What were you doing that was hindered?
it is slow buggy and insecure
- it has that av that bugs my mind
So you can't point to anything more specific is what you're saying. It's fine to not like a product/company, but brushing things in broad strokes is meh
I dont need windows to eat so much ram I rather give it to a vm on linux that I want to run smoothly
Windows never gave me issues
good luck with the new recall feature btw in 24h2 lol
it will come to be cross platform
windows 10 will see its end soon
Recall will be stored locally.
And there isn't anything you can't disable via Powershell.
Good.
only the hackers or people with normal sense will
All I'm getting out of this conversation is overly broad statements and unsubstantiated claims. I love the internet
if you say so
I mean, I speak to people who claim Windows and their phone are spying on them, yet use Alexa.
that is ridiculous
oh man there was this vuln in those google home devices where you could deauth the wifi and the home would disconnect
which in return resetted itself
well, the windows part is true lol
then you can register it and spy on people
Did you see they lost a month's worth of logs?
but it should probably be patched by now
i'm all for hating windows but it seems he's just doing it to do it 🤷♂️
Yeah, that's why I jumped in. I'm all for not liking things, but hating just to hate doesn't help anyone is a common symptom of being terminally online
what in the hell lmao
it doesn't even seem like they lost data, it just never got added in the first place? that means it won't even be in companies' (non-Sentinel) SIMs or logs or anything
i wonder what the estimated % of lost records is
defender used to be pretty shit but it's honestly pretty good nowadays -- for all microsoft's faults, it's actually a viable AV and even a somewhat viable EDR
may deploy a managed edr overtop of literally just free-tier defender to a good 1300-1400 eps soon, to replace crowdstrike
Yeah, it will be interesting as that data is used to establish standard vs anomalous activity
Hi everyone im new in cybersecurity and tryhackme
Before Yesterday i took a lab class and we used the L2 MAC Flooding &ARP Spoofing
My instructor has asked me a question in the lab class the question is "why is the data here is 666 bytes"
In step 4
Could someone explain to me please
Page doesn't exist, I'm going to assume it's a private room.
Wait leme see i guess im sharing something wrong
No its good https://tryhackme.com/r/room/layer2
If the page doesn't exist to you search for the tool "L2 MAC flooding & ARP spoofing"
What do you mean by real?
It’s a real super cat
Oh, I thought you might've meant, real photo that you made.
make his nemesis a racoon
Alright

writing game cheats
I did like a 1h30min cyber security meeting today with a client and there’s only so much I can talk in one sitting lol
That is cool
At that point you start spewing random protocols
lol and this point you start burning up the earth generating AI with wasted GPU cycles
But nah yeah it was hard to keep going after that long presenting
skril issue
well not when the whole challenge is to make those cheats 
haven't you heard of hackceler8?
o_o
that is an interesting dichotomy however, game reversers are often extremely darn experienced and I always love to see it
Aye art ai is fine
Just not yours thus far
hackceler8 is a ctf that works around a game that the internal devs at google has made, our goal is to make cheats for this game to win it as fast as possible
Wow
mmmm celery
heh I only kid :P
every round we are playing something changes in the game, making a certain cheat not work for example, or you'll have to rewrite something or build something new
these rounds have 3+ different challenges you then have to solve using these cheats and knowledge of the game
every round is 1h 30min, where 45 minutes of them is preparing for the round
lol I got into malware reversing courses and etc with the eventual goal of “maybe I could reverse some retro x86 games to help restore them”
What course
God that’s even worse
What year are you doing? @chilly veldt
year?
2024
it's on right now
this weekend
we played the prelim rounds today
Ahh, the other Google CTF was in June
ye
You got your whole team on it?
approx 20 players
Wowsers
18 players sitting in malaga in a villa playing together
Awesome!! Glhf
(actually 14, with 4 players being onsite the google finals)
might have a watch
Some pics I've taken from the villa
it'll be streamed on sunday
Win ❤️
Beautiful scenery+pool+CTF?! Absolute heaven
very lucky!
big time
make the most of it 😆
we have
Why did tryhackme remove the total hours of study/week that would appear on the top right
Are you both there
i mean i'm not but i'll split it if i still win somehow
Hrrrmm
You have been booped!
you’re a boooop
what community plugins would you recommend/settings also is that graph view or how did you get it like that its sick
It's a canvas, I use the GitHub plugin on dark mode. It's personal preference
Have fun with it
But don't waste too much time on it
Readability and ur personal likeness matters
No, you're a boop!
sure, splitting 0 still gets 0 
there is no winnings
hi
Ah, there is no place like 127.0.0.1.
hey y'all, I scraped a Raspberry 3 from an old project, looking to use it as a homelab to practice networking attacks
Anyone done it before?
What’s the move? Docker?
!verify
- Cisco Talos has observed a new wave of attacks active since at least late 2023, from a Russian speaking group we track as “UAT-5647”, against Ukrainian government entities and unknown Polish entities.
- UAT-5647 is also known as RomCom and is widely attributed to Russian speaking threat actors in open-source reporting.
Absolutely wild the amount of time and complexity a nation state backed groups malware is
So what's the deal with Microsoft recall? Are windows users going to be forced to install an update with it?
I prefer ::1 🙂
There are projects on Google and Github that utilize Raspberry 3
IMO, the sky’s the limit
Botnet
you're right. Decided on using Alpine as a base and docker on top
Why you asking if anyone has a botnet? 👀
Just they seem cool
And I want to make my own
Seems like he has some very legitimate business
Shhhhhhh
This is not the server for that and that's illegal
Bro
Having a botnet is not illegal
Just using it for illegal purposes is
And I would never do that...
fed?
This isn't the server to be asking about botnets
Why not
The illegal part is when it’s non concessional botnets which is 99% of them not much different from malware chains really
I was wondering if anyone had one
please stop. This is not the place for it
We're an ethical hacking and you have just joined out of nowhere asking if anyone has a botnet with no context lmao
And ethical and learning is focus in these servers no one’s gonna help with anything potentially unethical regardless of what your intentions are
Mods, expose him to Lovecraftian horrors beyond Human comprehension
Botnet is Not illegal
wat m8
I'm curious
you're not helping your case
Lets stop this convo and not continue to ask about botnets 🙂
Doesn’t change the fact no one knows your intentions
^
Let’s listen to blackout
I would spam him till he answers, be stupid not to really
yeah pretty helpful, just hard to get ahold of sometimes
what is on oct 21
How can you get a legal botnet? Isn't a botnet having thousands of compromised machines all over the world doing your bidding?
How would you get thousands of machines legally?
Unless you are a massive company
that's french for 127.0.0.1
Let's not, he's in a European timezone
I notified the moderation team in the appropriate channel, just ignore the person asking about the botnets
It’s sarcasm but then again people are asking about botnets In here
I don't know, it's kind of hard to tell sarcasm in text..
yo
You did not /s
Yes let’s all ping a mod and break several other rules 🤦♂️
Very nice I’m stuck in procrastinating if I go straight for cissp or not
👋
👋
How likely is someone going to have vim as able to be run as root with no password? This is in the "common Linux privesc" room
Why would someone set this up?
OCT 21??
I honestly don't know, but considering some people's laziness, it could happen.
The point there is how you can abuse certain binaries for privilege escalation, not because of vim.
You can replace vim with any other binary.
eh, it's more of like a SUID file risk, like reading /etc/shadow than anything else, too.
SUID is different from sudo
oh, sudo, I thought you guys were talking about SUID.
FYI: this years defcon's conference is uploaded to youtube
cool
Shame that it only gets run in America tho
Hey guys I need some ideas for a machine i am making for a class i am teaching. It is being hosted on tryhackme so other people can access it to and work on it. My class is full of very beginner people so i dont want anything that is super hard. I already configuired ssh to be vulnerable but want some ideas that arent to hard to impliment for it and would be fun to learn
Linux or Windows
linux
The vim memes are true, how to l do I permanently exit?
turn it off and back on again
Right now I'm typing :!p and it's going back to terminal but then when I type anything it opens vim again
:wq
It goes back to terminal and says shell returned 127 press enter it type command to continue. Any input just opens vim again
even with :wq ?
That says e32: no file name and doesn't exit
press esc a few times to ensure you are in normal mode and then try :wq
and if that doesnt work try :qa!
[No write since last change]
/bin/bash: p: command not found
shell returned 127
Press ENTER or type command to continue
[No write since last change]
/bin/bash: p: command not found
shell returned 127
Press ENTER or type command to continue
[No write since last change]
/bin/bash: q: command not found
shell returned 127
Press ENTER or type command to continue
[No write since last change]
/bin/bash: q: command not found
shell returned 127
Press ENTER or type command to continue
[No write since last change]
/bin/bash: q: command not found
shell returned 127
Press ENTER or type command to continue
that will force quit all vim sessions
Every one of these is an attempt lmao
ayyyyyy still know a bit of vim XD
what about hash cracking or something like this (i am also a beginner so dont laugh at me)
youre all good lol. I actually like that because you have good views on stuff you want to learn
I'm not sure why the normal quit commands didn't work. Maybe because I had just used vim to spawn a root shell
That is a good idea because I am preparing them for the Lockheed Martin hacking competition and they have some of that stuff
In a room i had to get the key using vigenere cypher and still my head went spinning
Vim is crazy lol
lol XD
yeah cyphers are fun but a bit confusing to get used to
but the problem is that i already knew about vigenere bcz of 9th grade
yeah lol
DxRK what about cloning a room you like?
want to hear how a single letter typo costed my win in KOTH?
happened with me
I think koth can be improved by allowing for:
uppercase and lower case letters in a username
but wouldn't that make matching usernames conflict?
yes this is frustrating
write your name in lowercase and then get Fu**ed
bcz mine is Sm1l3
Dont really want to clone
I think it would be good to have some kind of averaging system that finds the most similar username in the round, so that it will pick a username like:
GuineaPigLord
instead of:
GuineaPigLOrd
no i am talking about a feature or like getting an idea to create a similar vuln
why not? Is it against the rules?
just wondering
theres a setting on some of them where they dont want you to clone anything from the room
so i just dont really want to risk it yk lol
DxRK can you share the room with me when it is complete
yeah
its super easy lol
I mean theoretically, if you were able to somehow compile it into a .img file, and upload it back to your computer, run it on virtualbox; would that be against the rules?
Dont know and dont really want to find out XD
true.
I already lost my main thm account and dont want to loose this one
I was about to ask the same thing
I seriously dont know. I log in with my email and it just says there is no account on this email or somthing like that
it was just gone
strange
interesting..
you can contact THM
I did
so they don't know what happened either?
they just said that there is no account under that email address
so i just made the one i am currently on like a year ago and am trying to get it back to the rank i was
That's sad.
was gonna say the same
I dont really care to much because i just use it as a teaching tool or to learn something new but i was sad lol
losing all your progress is really sad
yeah, same, at most I can only keep a month streak lol.
then you have to probably redo all the rooms you did..that would suck.
yeah lol so im just working on getting back my 0xC rank back
i got an idea.
I used to be wizard, why was I moved back a rank?
what about creating a different acc for room development
so this way you will not lose your main acc
the only one I really hated redoing was the Eternal blue room lol
For copying rooms?
yeah...
I don't like any of the metasploit stuff, I mean using it is a breeze when you're not being quized on LITERALLY everything, but it's good to know.
for any reason bcz u r afraid of losing your acc
I also dont want to copy rooms because I like seeing what I can come up with. I also like adding stuff I have seen irl on pentests and stuff like that so I have stuff I can add I just dont really have anything super beginner I see alot lol
really only like basic printer exploits but I dont want to have to clone drivers and setup a virtual printer XD
I am working on my own rooms, but they are just so hard that I don't think it would be..beneficial to have these rooms on there. It's like the kaizos of tryhackme.
I just continually work on them until it becomes unsolvable.
ive been messing around with some AI ive been working on trying to see if I can impliment it into a thm room. I have a few different ones but the one i really want to add simulates social engineering and want to try and setup a room with that where you have to interact with the AI over chat or somthing to try and get creds or somthing
I actually DID that!
