#general

1 messages · Page 483 of 1

blissful badge
#

Silly 😛

#

Im in the unknown apparently

dapper girder
#

Yes

ruby sand
#

ah, but you're in the known unknown.... careful not to venture into the unknown unknown. that place is scary!

dapper girder
#

What in the gpt responses

blissful badge
#

Endless

ruby sand
#

the known unknown means you know you don't know a thing... the unknown unknown means you don't know you don't know it yet. how deep does it go? how long is a piece of string??

blissful badge
#

hey! I do know things

#

🥲

ruby sand
#

lol, the more you know! 😛

blissful badge
#

Lol

ruby sand
#

perfect example of an unknown unknown for me, let me look that up 😛

#

ah max value, indeed.

blissful badge
#

Of string

#

😂

ruby sand
#

derp... i really tied myself up in that piece of string.

blissful badge
#

Don’t do it!

blissful badge
ruby sand
#

aw tanks! Half the battle is turning unknown unknowns into known unknowns. I spend half my life learning what i need to learn, and how to learn it effectively.

blissful badge
#

I spent half my life playing outside

ruby sand
#

showoff.

blissful badge
#

The other half I began learning and now I started my journey into the unknown unknown

warm grotto
sonic totem
#

greetings

ruby sand
#

merriest of mornings!! how's all, the like, such, whatnot, and etc.???

rapid merlin
#

Cute cat

arctic cradle
rapid merlin
#

I read that as now, spent a solid five minutes confused. Where’s my glasses

arctic cradle
#

I don't have vision issues (maybe slight one) but coding a year ago, the letters would be slightly blurred

#

after getting proper glasses (+0.5), I felt like I was reborn

gray sonnet
rapid merlin
azure oasis
split compass
#

Fun, I saw on John Hammond the other day an attack vector of tricking people to WinKey+R, Ctrl+V, Enter to run some dropper code that is saved to clipboard by the "prove you're human" prompt on a page.

And tonight, I see someone in Reddit who was hit with this attack vector.

stoic quarry
#

Yeah it's been around for a while now, right clicking also works so they could obfuscate it a bit better

#

Ultimately it's just getting someone to open a shell or whaever from their side

#

(LIkely just install redline or something less exciting)

split compass
#

Yeah, I'm just surprised to see someone hit with it. I feel like copy and pasting random things from the Internet is one of the first things I learned to not do 30 years ago ^^;

stoic quarry
#

Grandma going to wordleanswers.co.uk and misspelling it would probably make her follow instructions

naive violet
#

Same reason everyone accepts cookies

split compass
#

I get why it works, just the lack of computer literacy makes me sad.

#

Some vectors just seem too easy 😄

hushed knoll
#

I remember when I copied linpeas from a website cuz I was a noob and couldn't deliver it to the machine. When I ran it it was like "bro did you just copy linpeas from a random source and run it without checking the source code?"

stoic quarry
#

Eh, don't get too upset

#

Lawyers do more complicated work than I'd ever bother to learn about, if they need my help printing to the right computer then I'll gladly help

naive violet
stoic quarry
#

I think computer literacy should be increased overall, but that's from a tech guy perspective

#

I'm sure doctors think first aid should be increased overall too

rapid merlin
rapid merlin
azure oasis
twin ridgeBOT
#

Gave +1 Rep to @midnight sentinel (current: #2280 - 1)

pliant cairn
#

will give you roots

split compass
# stoic quarry I'm sure doctors think first aid should be increased overall too

They wouldn't be wrong. I've seen some really foolish first-aid choices in the field XD

Used to support ~100 lawfirms.
Two of them had wire transfer scams occur at one point 😦
A third one had an end user almost get hit with an Apple gift card scam, but the office admin caught wind, after purchase, but before transfer of the codes.
So they became Christmas party raffle items.

split compass
stoic quarry
#

Roll with the punches type deal

split compass
#

Yeah, she was a crusty sort, but easy to get along with if you understood her.

#

I can appreciate someone who's been in it long enough that the weight of the years shows in how little patience they have for puffery 😄

stoic quarry
#

Yeah 100%

#

As long as they're not stubborn about change

split compass
#

Fortunately she wasn't.
She just knew that technology had sped past her at some point, so she knew enough to know what sounded right, but not to keep up with the current tools and tradecraft. So she was a good office liaison for us at the MSP side.

stoic quarry
#

Love the MSP life

#

The helpdesk > security path is real

naive violet
stoic quarry
#

Yes

#

Yes they do

#

The recent "I'm in a meeting please message me on WhatsApp, I have an important job for you" (gift cards) emails look too similar to legit emails I've seen

rapid merlin
#

How is everyone today

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @brazen vigil (current: #2280 - 1)

rapid merlin
#

Made some chicken soup for my flu thing

stoic quarry
#

Doing well

rapid merlin
#

Took ages to cut everything up but it’s worth it

stoic quarry
#

Fingers crossed it clears up soon!

chilly veldt
#

I just woke up to 38C 😭

stoic quarry
#

To what now

arctic pebble
#

It’s about 14c here

stoic quarry
#

Oh temperature

#

Lol

#

38 is crazy

arctic cradle
#

you're all wonderful, enjoy your weekend

rapid merlin
#

Thank you

rapid merlin
arctic cradle
chilly veldt
rapid merlin
#

Too warm for me

unique vale
#

helllo, does anyone can help me with python shell please.
im trying to reconnect to the shell but i cant enter export term=xterm 😭

rapid merlin
rapid merlin
naive violet
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #2 - 2207)

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @brazen vigil (current: #1506 - 2)

unique vale
rapid merlin
#

One message removed from a suspended account.

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @brazen vigil (current: #1134 - 3)

rapid merlin
#

One message removed from a suspended account.

#

One message removed from a suspended account.

naive violet
#

There's a timer on it yeah

rapid merlin
#

One message removed from a suspended account.

naive violet
#

And if you abuse it we'll be disappointed with you

queen flare
#

is the top x% ranking system gone?

rapid merlin
feral dawn
#

where can i go to ask for help about a room

#

i dont understand what im doing wrong

naive violet
queen flare
naive violet
#

Where are you looking? It's on your profile

rapid merlin
naive violet
queen flare
naive violet
#

You need to complete more rooms in order to get ranked

queen flare
naive violet
#

Ok, but

#

Things change.

queen flare
feral dawn
#

thanks, just dropped the question in there if anyone can help

twin ridgeBOT
#

Gave +1 Rep to @plain grotto (current: #626 - 7)

queen flare
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #2 - 2208)

naive violet
#

I think you need to get into the top x percent in order to recieve a rank. Maybe 10%? Not sure

#

I'm not staff

queen flare
#

what's CONTRIBUTOR?

naive violet
#

¯_(ツ)_/¯

naive violet
#

Nope.

queen flare
#

can we do that too?

#

or is it something exclusive

naive violet
#

Not site staff, I don't work for THM, I have no sway.

naive violet
queen flare
#

ah

naive violet
#

I had a CVE allocated but they haven't published it

queen flare
#

@rapid merlin when did you last complete a room?

naive violet
#

It's fixed and then the product went EoL so ehhhh

queen flare
#

maybe completing one now will get your rank back

#

i will make my own vulnerable product

#

then publish a cve on it

naive violet
#

Responsible disclosure wise, I don't think I should publish it
It was a local privesc via an application on Windows, let you pop system from a standard user. Was nice.

#

Not a clue, if ever

#

Hence "forever pending"

#

I find cooler day to day, I just can't publish it because it's all NDA

#

Yeah I'm a senior pentester, I hack stuff all day almost eevry day

#

With permission, and I get paid for it.

#

I work for a company
Freelance pentesting isn't a thing. The huge amounts of legal liability, contracts, and insurance you need mean you absolutely shouldn't freelance

#

Have a look at job postings in your area

#

You can't speak globally for something like salary

sage thicket
#

Hi i need help finding a room. It is about the "find" command in linux terminal. I have looked but not able to see it.

shut hawk
#

It's retired, you can't access it anymore sadly

sage thicket
#

😭

#

all good

#

thx levi

naive violet
#

@gusty thicket Please don't send unsolicited friend requests or direct messages. It's against the tryhackme discord rules.

arctic cradle
#

James, can I be your.. friend..?

dusty ice
#

hi

#

What is the best tool currently available for hacking a phone?

arctic cradle
dusty ice
arctic cradle
naive violet
arctic cradle
#

hack a phone

feral dawn
#

theres literally just not anything inside of this folder and its saying to look in the folder

arctic cradle
feral dawn
#

lolllll

naive violet
dusty ice
naive violet
#

Just look at the known CVEs for the phone. They get patched.
Unless you're a government, "hacking a phone" isn't really a thing.

cold sparrow
#

Trying to get "go" to work is killing me

dusty ice
naive violet
#

Like people don't hack phones over the network like they do computers.

#

Short of literally government agencies

#

You'll discover your phone has no services listening

#

They're aggressively sandboxed too

naive violet
naive violet
#

wat

dusty ice
arctic cradle
#

the question is why you would want to pentest your phone @dusty ice

sick lance
#

Pentesting a phone is different from hacking a phone.

naive violet
#

If you're going to do a pentest against it as well, you should do some basic threat modelling first. What attacks are likely? What attacks will succeed?

dusty ice
sick lance
# dusty ice what

But James is right, phones are not like computers, you can't just hack it easily, anything that can be exploited will get patched almost immediately.

Classic example is Pegasus, that relied on 0-day exploits with zero clicks to hack phones.

naive violet
dusty ice
arctic cradle
dusty ice
naive violet
#

What do you mean?

arctic cradle
#

something tells me that you want an automation tool to help you do all of the job and realistically if you want to do phone hacking, in my honest opinion you would need hardware to play around on a hardware level or even further kernel exploitation

feral dawn
#

What section of cyber makes the most money? I love the field but want to focus on what i can make good money in lol

dusty ice
naive violet
sick lance
#

Unless you want to spy on people, there is no real advantage to hacking a phone,.unless you plan to bug bounty it

dusty ice
dusty ice
naive violet
#

How are your skills in the cyber security sub field of binary exploitation?

arctic cradle
dusty ice
# naive violet How are your skills in the cyber security sub field of binary exploitation?

I actively use Nmap and Metasploit for penetration testing and vulnerability assessment. Nmap helps me in network mapping and discovering hosts and services on a network, while Metasploit provides powerful tools for exploiting vulnerabilities and conducting security assessments. Additionally, I am involved in code development to create custom scripts and tools that enhance my penetration testing capabilities. This combination of tools and coding skills enables me to perform thorough and effective security analyses.

sick lance
#

Wow, ChatGPT much?

naive violet
#

The answer is also irrelevant

dusty ice
naive violet
#

Scrubs, I'm writing a con talk

sick lance
dusty ice
jaunty agate
#

Please help me with the issue , I am not able to connect Bluetooth in my Garuda linux,it is even not listing devices ...

Please help I am stucked here from last night ,🥺

tepid furnace
#

uh

naive violet
dusty ice
tepid furnace
sick lance
naive violet
# dusty ice What do you mean

If you want to find phone vulnerabilities, typically these involve the field of "binary exploitation".
This includes buffer overflows, heap flaws, use after free, and similar.
If you want to "hack a phone", you will need to discover the vulnerabilities. You will need to learn a significant amount of skills.

arctic cradle
crude stump
naive violet
#

👀

dusty ice
shut hawk
#

Or you could start on TryHackMe

dusty ice
kind narwhal
#

@sick lance

sick lance
#

My malware class was actually on phone malware last Friday, actually...

kind narwhal
#

There is a problem with this willow ctf

sick lance
kind narwhal
#

I log in with ssh key and enter the password sign_and_send_pubkey: no mutual signature supported
says

naive violet
kind narwhal
naive violet
rapid merlin
#

Hope everyone is having a good productive day. Stay hydrated!

boreal scarab
#

Morning!

crude stump
#

it makes me laugh how when you try to download google chrome edge is lie determine to change your mind

tired bear
#

🙂

boreal scarab
#

@naive violet

naive violet
#

@tired bear Absolutely not OK

crude stump
#

aw man i missed it

crude stump
#

I see

naive violet
crude stump
naive violet
#

No chance lol

crude stump
#

Oh

#

Lmao

#

Like a small talk

naive violet
#

At least to start

earnest swan
sick lance
earnest swan
jolly wedge
#

Can I do a practice easy room if I haven't done all the introduction to cyber security and complete beginner part or it is too hard ?

crude stump
wooden totem
crude stump
#

lunchly enjoyer

wooden totem
crude stump
#

Facts

#

Especially prime

#

Taste straight nasty

wooden totem
#

marketing the only thing holding them up

rapid merlin
#

lol nvm found a send feedback button my slow ah

crude stump
#

@sick lance There’s so many tools flarevm has to offer. Is the default tools good enough or should I just install all the available tools I can. Im prolly not gonna use most of em but 🤷‍♂️

sick lance
crude stump
#

The basic with suffice ig

kindred apex
#

Helo

#

Guys I have a issue

sudden pond
kindred apex
# sudden pond what?

I am getting a link 50 dollar Steam card from everywhere like X discord etc don’t judge me I am just 15 and learning some ethical hacking but I am in learning phase soooo what should I do

clear jackal
#

Don't click links

sudden pond
kindred apex
sudden pond
kindred apex
#

Oh

kindred apex
#

Bruhh

sudden pond
#

u?

kindred apex
#

India

sudden pond
#

neighbors

kindred apex
sudden pond
kindred apex
sudden pond
kindred apex
#

Ye sir

crude stump
#

It’s usually spread by hacked discord accounts

kindred apex
#

My friend sent me

#

@crude stump sir r u a experience white hat hacker !?

crude stump
#

This is a ethical hacking server

#

We don’t provide hacking services if that’s what your asking

kindred apex
kindred apex
crude stump
#

Best bet is for them to contact discord if your friend is still hacked

crude stump
rapid merlin
#

To complete the ''Crack the hash'' challenge what prerequisite knowledge do i need or what rooms should i complete in order to crack the codes.

kindred apex
rapid merlin
sudden pond
rapid merlin
sudden pond
#

and others manually by using the rockyou.txt wordlist

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sudden pond (current: #924 - 4)

sudden pond
rapid merlin
brazen oyster
#

Throwback room already gone?

sudden pond
sudden pond
brazen oyster
brazen oyster
sudden pond
#

i just played 5-7 koth till the end

brazen oyster
# sudden pond you guys are hell too good at KOTH

sad that a high ranked than me dmed me yesterday and said i played using autopawns. My 20 + notes and articles about ctfs write ups i read for weeks just to learn playing ctf koth became useless 😅

sudden pond
#

thanks @rapid merlin for a thing

twin ridgeBOT
#

Gave +1 Rep to @dense pagoda (current: #2281 - 1)

kindred apex
sudden pond
#

@kindred apex you are annoying

kindred apex
sudden pond
#

u just dont answer the questions in a right way

sudden pond
#

what is ur thm usr name

kindred apex
sudden pond
#

try hack me

near jay
#

which openvpn file do I use for koth games? the "machine" one ?

sudden pond
kindred apex
near jay
sudden pond
#

THIS CHANNEL IS DESERTED TODAY!!!!!!!!!!

#

ITS ALL EMPTY HERE

silver sky
naive violet
sick lance
#

Yeah, server is quiet on a Sunday

naive violet
#

You can take a break, go outside, learn a skill, all sorts

#

I, for one, have been designing things and working on a talk

sick lance
#

Working on Fortinet equipment, looking for vulns and CVE's well taking notes for my interim report.

rustic totem
#

Guys I just installed burp professional in my kali machine but it's not showing where it has installed...just the old pre-installed community version.....any suggestions what should I do?

sudden pond
#

Bye!!! Dog probelm

rustic totem
sick lance
marble tapir
#

Finally I'm here 😁

rustic totem
#

But my mentor gave it to me😭😭😭 ....others r using it too😭

sick lance
#

What a shit mentor...

marble tapir
sick lance
marble tapir
naive violet
rustic totem
#

Didn't know

sick lance
sand trench
sick lance
#

I'd ditch the cracked copy and the mentor too.

marble tapir
sick lance
#

Poor mentor if they're condoning the use of illegal software.

pine stratus
#

isnt burp suite community edition enough ?kekw

sick lance
naive violet
rustic totem
marble tapir
#

👍

pine stratus
naive violet
pine stratus
naive violet
pine stratus
crude stump
#

Anyone know any practice websites I can practice using ghidra

#

Can’t find nothing on thm

naive violet
crude stump
sudden pond
#

I discovered another solution for the famous openvpn problem

marble tapir
#

Tamil Nadu for now

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #3 - 1927)

sudden pond
sand trench
sudden pond
sick lance
crude stump
#

no

marble tapir
crude stump
#

only intermediate python. sort of intermediate

sick lance
#

Two rooms which feature crackme's

crude stump
#

oo thank you everyone

#

yk its good when a russian is writing it

sick lance
#

If you do learn to write C, then write you own code, compile it, then chuck it in Ghidra.

crude stump
#

thanks

#

its crazy how harvard has all this online

rapid merlin
sudden pond
sick lance
sudden pond
#

you cant find the wordlist for this now

sudden pond
sick lance
sudden pond
#

i am not helping him just telling

sick lance
sudden pond
#

ok @sick lance

narrow bone
#

https://www.youtube.com/watch?v=nODVcuLhe1M

Interesting video they mentioned even 0day with his revshells page at 44 min 😂
Blue Vs Red Team

Big thanks to ThreatLocker for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

NOTE: Jakoby’s video freezes from time to time because he had to use a backup Internet connection as a result of the storms experienced in Florida over the past few weeks. Apol...

▶ Play video
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sudden pond (current: #789 - 5)

sick lance
#

Ghidra looks better in darkmode.

sudden bridge
sick lance
rapid merlin
sick lance
#

Ghidra is bae.

crude stump
whole yew
# rapid merlin For free?!

Harvard, Stanford and MIT all have really great compsci youtube channels. They upload the lectures for a lot of their classes, for free.

sudden bridge
crude stump
sudden bridge
sick lance
sudden pond
#

cant wait for tomorrow

#

wondering what's the surprise

sick lance
#

I have an idea, we were talking about it on Friday and I wrote in the text bar and took a screenshot, I'll post it if I was right.

#

Urgh, I can't work right now because my kitten is not leaving my laptop alone.

rapid merlin
#

i need to crack a hash for ctf
my laptop started giving burning smell
my student azure vm is running slow
any free and fast way to crack it?
its eta is 5hours
running rules

rapid merlin
sick lance
sudden pond
rapid merlin
sick lance
rapid merlin
#

my student azure has limited resources

sudden pond
#

try some online tools

rapid merlin
rapid merlin
sick lance
rapid merlin
#

on its hash

rapid merlin
sudden pond
#

can you share the hash

rapid merlin
#

so 12 hours burned there

rapid merlin
sick lance
rapid merlin
#

its a zip2john hash

sick lance
#

We're not helping, if you continue to discuss this, I'll mute you for 2 day(s).

rapid merlin
#

the burning smell from laptop is strong 😂

sick lance
#

You could be melting your CPU.

rapid merlin
sick lance
rapid merlin
#

its not using my resources

#

smell was earlier when i was doing it locally

sick lance
#

Yeah...

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @whole yew (current: #10 - 782)

sick lance
#

So you could have done damage then.

rapid merlin
crude stump
#

You’re welcome

sick lance
#

I want to use android studio on my VM, however Vmware does not support Nested virtualization or Virtualized Intel VT-x/EPT

mossy river
#

Android studio uses virtualisation?

sick lance
#

For the phones, yeah.

mossy river
#

Is it for the android device?

#

Ahh thought so

#

I used an old Samsung, put it into dev mode and tested directly on the phone

sick lance
#

I may need to do this with my Uni work.

#

Right now I'm using a cloud based VM, but the RAM is pathetic.

mossy river
#

I moved to flutter and dart

#

we did it in college and it was quite easy

rapid merlin
sick lance
rapid merlin
#

thats the problem

sick lance
#

Then it's one you'll need to figure out.

whole yew
mossy river
#

Yeah, I think I used it

#

iirc VSCode has a plugin to do it?

whole yew
#

Huge performance cost, if you have a rooted physical device to test on, it makes android dev/RE way faster.

sick lance
#

I have a rooted android handset, old Samsung Note 9.

whole yew
#

The only down side to using a physical device with android studio is that you are limited to the version of android on the device

mossy river
#

Hmm true

sick lance
#

And some of the apps I may need to use will get flagged by my AV, and I don't want to set up exclusions based on them.

whole yew
#

Android Studio works great on Fedora and Ubuntu. Just sayin'.

sick lance
#

It's the laptop I'm using, I think, or perhaps possibly a VmWare restriction.

rapid merlin
#

😂

#

if i disconnect ssh
i can still see the result tmrw right?

#

if it stores it somehwere

sick lance
#

Does the VM run 24/7?

rapid merlin
sick lance
rapid merlin
#

😂

mossy river
whole yew
jolly forge
# rapid merlin its a zip2john hash

funny, I used zip2john today. Although cracking the hash wasn't done on my own PC, I don't think it would require too much out of your PC especially for a CTF. What wordlists were you using?

brazen oyster
#

Throwback room totally out?

naive violet
rapid merlin
#

eta is 12hrs atm

jolly forge
brazen oyster
rapid merlin
#

of rockyou

naive violet
#

@jolly forge @rapid merlin Please stop discussing it here

jolly forge
#

is it against the rules?

naive violet
jolly forge
#

how is it cheating when you just discussing a technique and not directly giving the solution?

rapid merlin
#

strict rules

naive violet
mossy river
mystic trench
sick lance
# rapid merlin strict rules

How would you feel if you cheated out of a position in a workplace because somebody asked a server for of hackers for help?

rapid merlin
sick lance
median pollen
#

Hello friends

rapid merlin
crude stump
#

Orange is festive

pulsar spoke
#

Since when can we add friends on THM?

sick lance
#

It's been there for years.

sand trench
sick lance
#

It's just more noticeable now.

pulsar spoke
sick lance
#

Oh well, I can't use Android Studio for what I want right now.

pulsar spoke
#

I didn't notice it until the new update

sick lance
#

Stupid Vmware and not allowing VT-X

sudden bridge
#

you have no friends on tryhackme
cri

sick lance
#

I have two

pulsar spoke
pearl raven
#

I have one...

sick lance
pearl raven
#

Above average 😛

sudden bridge
#

i sent one to my irl friend... he didnt accept.

sick lance
pulsar spoke
sick lance
sick lance
#

Unless it's changed 🤔

mossy river
sick lance
void zodiac
#

Did anyone have an imposter syndrome while starting studying on THM?

mossy river
sudden bridge
sick lance
mossy river
#

🤣

#

hi scrubz

sick lance
#

So it's not been changed 😎

void zodiac
pulsar spoke
pearl raven
sick lance
pulsar spoke
pulsar spoke
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #1 - 2885)

crude stump
#

I call free rep

pulsar spoke
sudden bridge
#

unthank him.

pulsar spoke
#

unthanks @sick lance

void zodiac
crude stump
#

You would die

#

I am slow af because I try to learn the tools in depth

clear jackal
sudden bridge
crude stump
#

Reee my flare vm is done

pulsar spoke
clear jackal
#

Take notes, review the materials, explore rabbit holes, and make your own journey

void zodiac
crude stump
void zodiac
crude stump
#

I really like this model

sudden bridge
#

yeah man personally i was STUCK in this networking theory thing. i'd say get hands-on with wireshark and use RFC at best (would not suggest RFC if you're unfamiliar with docs reading) and get on the track.

crude stump
#

Networking can be a rabbit hole section fr

void zodiac
sudden bridge
#

exactly.

crude stump
sudden bridge
crude stump
pulsar spoke
#

Since when did THM make Linux Fundamentals part 2/3 for subscribers only? 😠

crude stump
#

Was it not always like that?

sudden bridge
#

no it was free 😂

crude stump
#

Damn

#

Ngl that’s crazy

sudden bridge
#

thm really want 💰

#

even the windows ones are behind paywall now

void zodiac
void zodiac
sudden bridge
#

have what

crude stump
void zodiac
pulsar spoke
void zodiac
sudden bridge
sudden bridge
tepid furnace
#

thm is a buisness

crude stump
brittle lynx
#

Hello where do u recommend to learn cloud pentesting and defending (hands on) affordably?

void zodiac
#

Just other courses are much more expensive, that's why I say it

mossy river
pulsar spoke
mossy river
pulsar spoke
sick lance
pulsar spoke
crude stump
#

Yk what would be a smart idea. Periodically making things that are free paywall and things that were not free, free

crude stump
pulsar spoke
#

oh, wait. I got it now

crude stump
#

Ye

pulsar spoke
#

I got confused when you said free paywall

crude stump
#

Oh lmao

pulsar spoke
#

punctuation, man

crude stump
#

Hm your right,

sick lance
#

Depends on how often it does switch, if it does.

crude stump
#

Every year maybe

sick lance
#

Big announcement tomorrow though.

crude stump
#

But at the same time paths are super long, so maybe you make a informational room free but the challenge room stays behind the paywall

crude stump
void zodiac
#

The best idea was to give a 3 months voucher for a call with THM team and give them a review

crude stump
#

Yeahhh you getting me now

void zodiac
sick lance
#

People complain about the cost of THM, but since they launched, they have only raised the price once, and the cost pays their employees and other stuff.

#

People forget that.

#

Understandable that not everybody may in the position to purchase a subscription, they're exempt from my statement.

void zodiac
#

Offensive security courses which cost in total 140k$... kekw

rapid merlin
#

The same people complaining about the price I bet are the same ones paying £20 for a games skin

void zodiac
sick lance
#

60% of the content being free is a great balance.

rapid merlin
cerulean nest
#

guys im getting a new computer

#

laptop

#

any recommendations

sick lance
rapid merlin
void zodiac
#

My 1.4k$ Lenovo which died shortly after I bought it😶 it survived only for 2 years

Still no clue what happened to it since April

mossy river
#

what 😭

#

I bought a £150 second hand one three years ago and it's still balling

void zodiac
# mossy river what 😭

I was playing BeamNG and it just turned off and never turned on. Bios battery is ok, power battery is ok

pearl raven
#

that explains it

mossy river
#

Not really

void zodiac
mossy river
#

Gaming on a laptop doesn't mean it's going to die.

void zodiac
#

True

pearl raven
#

No, but it likely will be overheating for extended periods

cerulean nest
#

and uh

sick lance
#

I may need to upgrade my workstation if I can't get Vt-x to work.

cerulean nest
#

ig hash cracking, and stuff

void zodiac
cerulean nest
#

rtx 4090 preferrable

#

with uh

#

not an ARM cpu

void zodiac
#

I wonder if my CPU died

mossy river
mossy river
#

Get a tower with a dedicated GPU if you want to do hash cracking

pearl raven
#

Sometimes they can be salvaged with a good cleaning and a new application of thermal paste.

rapid merlin
void zodiac
#

Even no signals or leds

pearl raven
#

Ouch

naive violet
void zodiac
mossy river
# rapid merlin What’s your view on chromebooks

Chromebooks are great. Super efficient and high performance.
Chromebooks with the touch screen functionality and stylus are also awesome and useful to those who want a laptop and a tablet.

I wouldn't recommend them for Cyber because it's a custom OS that isn't supported in a lot of software.
Requires you to install other software like Anaconda which can be very temperamental.

If you are in full-time education, looking for something to do your assignments (especially a math based course or one that requires you to create diagrams etc), I couldn't suggest one more.

fair jungle
#

Get a thinkpad install debian OS, transcend to another universe

mossy river
#

I got a thinkpad and installed Ubuntu™️

fair jungle
#

Hell yeah

rapid merlin
#

I use mine for research and stuff

#

And to study

void zodiac
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1326)

mossy river
#

I got an M2 Macbook Air.
Best and worst decision.

Great for coding, writing assignments and doing work.
Terrible for VMs and Cyber (ARM CPU).

void zodiac
#

How long will it take to complete all paths on THM?

rapid merlin
#

In the end I just walked away 😅

mossy river
mossy river
mossy river
cerulean nest
mossy river
#

I wouldn't worry about rushing the content though.
Taking proper notes and performing further research of each room you are completing to commit to your notes will leave you much better off 😊

cerulean nest
#

around 2-3k budget

#

or 4k at max

mossy river
#

I could not recommend not to spend more than 1k on a laptop.

cerulean nest
#

wtf? the gpu itself is 1.6k

pine stratus
cerulean nest
#

maybe cause im not gonna use the desktop

#

i want smth portable

#

but powerful

naive violet
#

Gaming laptops are... Still not great

cerulean nest
#

yup

#

im using the gpu for hash stuff for CTFs

mossy river
#

You're going to be wasting your money 🤷‍♂️

cerulean nest
#

i cant carry my tower to places

#

laptops on top

mossy river
#

You can RDP into your Tower from a laptop

naive violet
cerulean nest
#

im using the gpu for compute

#

ye i like laptops

#

portable

naive violet
#

You can always rent GPU time. Bet it works out better.

#

Especially on battery life

cerulean nest
#

plus im gonna have my computer plugged in 24/7

#

idc abt battery life

void zodiac
mossy river
cerulean nest
#

asus rog zephyrus g16 is pretty good

naive violet
#

If you're gonna have it plugged in all the time... Just get a desktop

cerulean nest
#

i cant just pick up my desktop

#

and go places

#

laptops on top

naive violet
#

But hey, your money to waste in the end

cerulean nest
#

its not a waste is it?

#

around $2k for a 1.5k gpu

#
  • other stuff
#

its good for the price

cerulean nest
mossy river
# void zodiac How important is making notes?

I think notes are very important.
From a scientific POV, notes actually help you turn what you have learned from short term to long term memory.

But, I can't say that notes are for everyone. If find them useful, I really recommend you to take them.
If you find them to be unhelpful, try finding a way of storing the information that is suitable for you! Whether that is recording and walking through the content, saving videos of other people explaining it or other:)

cerulean nest
#

yeah notes are important

#

my entire notes combined is over 1mb

rapid merlin
#

Hope everyone is having a wonderful day!

pearl raven
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @pearl raven (current: #87 - 81)

cerulean nest
#

🌊

rapid merlin
#

Hi guys

#

Who know about swiftseek

#

It work my google chrome and i cant delete it

jagged otter
#

💩

mossy river
# cerulean nest its not a waste is it?

The problem with laptops that have a dedicated GPU is that they are less efficient.

  • Laptops have limited airflow and smaller cooling systems due to their compact design. They are prone to thermal throttling.
  • Laptops tend to wear out faster because components that are soldered are subjected to constant heat.
  • Some laptop manufacturers will lower the performance of the laptop to ensure that laptop isn't overheating.

You can spend your money on whatever device you want, I just want to ensure you have all the facts before you make a decision.
If you are still happy with buying one knowing this then all the more power to you 😄

#

Cooler hardware = faster hardware

#

I am

fickle fulcrum
#

hii guys

rapid merlin
#

I tried to google it and cyberfirst girls competition came up

fickle fulcrum
#

can someone help me with education advice pleasee

sick lance
mossy river
#

I remember doing CyberFirst about 5 years ago

#

No, this was a competition for Secondary School students

sick lance
#

It's a great idea, want more women in cyber? Aim one for them.

rapid merlin
#

On my way!

#

😊

fickle fulcrum
#

thank you. so i have a bachelors in international relations and i'm working in an SaaS company, so wildly different career to cybersec. i wanna switch to cyber and i know i can just get the certificates like comptia sec but i'm thinking to do a part time masters in computer science with cyber security. is it valuable or a waste of time? i just wanna open some options up for myself

mossy river
#

There were a few stages.
You had to be within x amount of people to complete a certain amount of the stages.
If you passed the stage, you would be invited to the next.

If you won all stages you got an internship and fully funded University scholarship iirc.

fair jungle
mossy river
#

You need to look at the job market for jobs you want to do and see what they requirements are

fickle fulcrum
twin ridgeBOT
#

Gave +1 Rep to @fair jungle (current: #1136 - 3)

fickle fulcrum
#

it's honestly mostly computer science

boreal scarab
mossy river
#

Computer science degrees are great for IT as a whole.

fickle fulcrum
#

the thing about jobs, i don't know yet

#

i know it's a bad motive but i just wanna increase my pay and do something enjoyable

mossy river
#

I just don't think Masters offers much over a Bachelors degree from the people I've spoken to.
*This advice is purely anecdotal and not official advice.

fickle fulcrum
#

yeah i can imagine

#

i'm definitely not going back for a bachelors

#

it's either masters + certs, or just certs

#

i just figured that a computer science masters opens up a whole load of doors

boreal scarab
#

@cosmic pendant I feel like toaster may be beneficial here for this conversation

fickle fulcrum
#

thank you

mossy river
#

Just to confirm Neon, are you UK or US?

fickle fulcrum
#

UK/UAE

void zodiac
#

From what I saw, companies mostly require only knowledge, some also require work experience in cyber sec. And mention certificates as a bonus for getting an interview.

Haven't seen companies asking for a degree in IT or cyber sec

(I have no experience in this field, just saying what I noticed)

naive violet
#

Masters in cyber over qualifies you really

#

You can struggle, especially at the entry level

fickle fulcrum
#

so it's really just certs and experience

rapid merlin
fickle fulcrum
#

okay my next question - how do i gain experience without taking a serious pay cut?

mossy river
#

I know of people who get Masters degrees then move into Junior roles and really struggle lol

naive violet
naive violet
grim sparrowBOT
#

:hammer: aaaaaaaaaaaaa08527#0 has been banned.

fickle fulcrum
#

because obviously i'm earning my own salary now in a non entry role in my sector. i am worried about years of being on a lower salary. do you think i could do some kind of volunteering or internship on the weekend and that still count?

cosmic pendant
sick lance
#

Somebody really is annoyed huh.

fickle fulcrum
pearl raven
#

Apparently.

boreal scarab
#

There's toaster! Hi toaster! AMcatwave

void zodiac
mossy river
naive violet
boreal scarab
#

No one lives in my mind rent free. I charge them, I'm pretty rich in that sense then kekw

void zodiac
rapid merlin
naive violet
#

The first one is difficult, then it's non stop headhunting in cyber

void zodiac
fickle fulcrum
#

so the consensus is that the degree isn't worth it? what about outside of cybersec, would it be useful to have anyway? i feel like maybe it would demonstrate experience / interest / foundation knowledge

boreal scarab
#

Every, single, year.

fickle fulcrum
#

i just don't think people take me seriously with a non-STEM degree

#

maybe it's my own insecurity

rapid merlin
mossy river
# fickle fulcrum why do they struggle btw?

The environment is much different and what you learn on the course isn't always what you need for the job.
Job experience and academic experience is much different. I can't speak from experience.

fickle fulcrum
#

yeah fair enough, makes sense

#

i've seen cybersec degrees are not technical at all

mossy river
fickle fulcrum
#

yeah it doesn't exactly prepare you

sick lance
#

My BsC will hopefully be good.

#

My Hons project will get me contacts in Fortinet and Scottish Police.

boreal scarab
#

I got an associates in IT, not specifically cyber sec, but still took courses for sec while there

fickle fulcrum
#

better than no degree though I think

boreal scarab
#

Er, well, AAS

fickle fulcrum
#

nice

sick lance
#

I've already networked with Scottish Police - Cyber department, current and former.

fickle fulcrum
#

lots of different backgrounds i see

sonic vessel
#

Is anyone here good at drawing like personified cartoons of objects? Like a can driving a boat for example

fickle fulcrum
#

nope

boreal scarab
#

I'm not in info sec though. My background is support.

fickle fulcrum
#

ah okay

#

i am so stuck and don't know what to do

sick lance
boreal scarab
#

I demand that be added to #quotes .... oh wait

void zodiac
# fickle fulcrum nice

Another thing. You would have to combine work and studying. In case of studying on THB/HTB and getting certs you will have much more free time than if you would do Master degree

fickle fulcrum
#

and get some experience on the side, if possible

sick lance
#

Hack The Box, a platform with the same idea, but different delivery method as TryHackMe.

fickle fulcrum
#

while studying certificates

#

ahh okayyy

void zodiac
devout zephyr
#

hello guys,i am new heree

fickle fulcrum
#

both but i meant the initial work experience

boreal scarab
fickle fulcrum
devout zephyr
fickle fulcrum
#

it's gonna be tough but i already work minimal hours / super flexible 'full time' jo

#

job

rapid merlin
#

One message removed from a suspended account.

fickle fulcrum
#

so i want to make the most of this and try and use my free time to develop this career somehow

void zodiac
fickle fulcrum
#

okay thank you

#

but THM won't help employability right

sick lance
#

It's not going to be easy, it's not impossible though.

fickle fulcrum
#

thanks i just wish i knew the right steps to take

flint lintel
#

Anyone here who is just learning these stuffs for fun ?

rapid merlin
flint lintel
rapid merlin
#

One message removed from a suspended account.

void zodiac
#

I learnt at THM for a couple of months more than I learnt at my uni for 3 years. And well, THM experience kinda helped me at uni. Still getting Bachelor's right now

rapid merlin
#

One message removed from a suspended account.

flint lintel
#

ahhh okay i dont expect any kind of employment from this

rapid merlin
#

One message removed from a suspended account.

flint lintel
narrow bone
#

Does anybody use a MacBook with the M chips running a VM (Kali) and what’s your experience?

slender current
#

Is connecting to the site via http considered dangerous for the site itself?

naive violet
lone thistle
#

so far, x86_64 VM in things like VMWare, (there's another one I'm forgetting - UTM?), still kinda suck because it's emulation not virtualisation

#

Linux x86_64 emulation on it is bareable, Windows x86_64 it's veeeery not

rapid merlin
#

hello i need help to decrypt a password for the website hackthissite
Level 6

Network Security Sam has encrypted his password. The encryption system is publically available and can be accessed with this form:

Please enter a string to have it encrypted.

You have recovered his encrypted password. It is:

914588h:

Decrypt the password and enter it below to advance to the next level.

Password:

how does it work ?

placid bridge
#

Hey guys wassup

sudden bridge
#

sup sup

sudden bridge
muted nebula
#

damn just hit 50000 point on THM. XD

#

I wanna add some firend what are your usernames on tryhackme?

sudden bridge
#

#1520 NotLikeThis

sudden bridge
#

bro give some tips man

muted nebula
muted nebula
sudden bridge
#

so maintaining a streak like yours can get me in the upper end of 1%?

#

15k brings us at 1% but 15k doesnt sound very impressive

void zodiac
muted nebula
# sudden bridge so maintaining a streak like yours can get me in the upper end of 1%?

no I meant you have to keep learning and solving challenges everyday. don't pay attention to the ranking. Your main goal should be to learn and practice. The rank comes automatically after a while. I've been doing this for almost a year now everyday. I also started from 0 points too but my goal never was to "get my ranking up". It just happens on its own.

sudden bridge
#

ah gotchu

#

what category do u play

muted nebula
sudden bridge
#

like oh, the most rooms on thm are boot2root but there's gotta be a category you're well versed in like web, forensics, crypto, RE or even a broader one

#

i dont care about rank too much either, just wanna put it on my resume lmao

muted nebula
sudden bridge
#

nice man

muted nebula
#

Like back then I would solve a single question and I would jump +200 ranks. Now i have to solve an entire challenge room with like 90 points to move +5 ranks

eternal timber
#

Shrek Harvey

sudden bridge
#

doing soc path right now. was at 5%, reached at 2% and will even reach 1% but this path wont end 😭

#

its fun tho. well documented and everything

muted nebula
sudden bridge
#

you'll love wireshark one 😁

muted nebula
#

tshark is what I'm currently interested in

sudden bridge
#

oh thats ones also good

#

did u like MISP and openCTI? those were pain in the arse

void zodiac
#

I want to do Pentest. Should I also complete soc?

sudden bridge
#

very daunting

sudden bridge
muted nebula
sudden bridge
#

those rooms were where i re-thought my choice of choosing this pathNotLikeThis

muted nebula
muted nebula
void zodiac
sudden bridge
muted nebula
sick lance
#

Former blue teamer will make a great red teamer

muted nebula
void zodiac
#

Red

sick lance
#

Won't want to go back to blue team kekw

void zodiac
#

Is the job market overheated for junior pentesters?

devout zephyr
#

i thought pentest needs experience

#

thats why i am currently doing soc path as i have no experience in jobs

#

any pentest stuffs are complicated to me idk why

karmic geyser
muted nebula
karmic geyser
muted nebula
karmic geyser
#

REDACTED

crude stump
sand trench
#
  • wonders if that bug scrubz found is fixed on tryhackme yet
muted nebula
rapid merlin
#

Or how even

#

This bleach is burning, hope my hair don’t fall out

karmic geyser
sick lance
#

Being a blue teamer you'll know what to look for, what to defend and what to hide.

Being a former blue teamer you'll know all these tricks

devout zephyr
jolly forge
crude stump
#

Heck nah

#

Better not

karmic geyser
#

What ever you say, both teams are goated.

fast thunder
#

Is there any place here where I can get help, not with TryHackMe but if a site is legit or not, watching on VirusTotal is seems Malicious. It for a friend who is losing money, and he will not stop, so Im trying to reach out to a professional and I know there is many of you here. Just to show him that yes this is not legit, or maybe it is.

sand trench
#

and peef poof to the sleep sloop shadow goes while the beep boops are blasting

karmic geyser
#

Went to a poetry event!

limpid fossil
#

Mac book pro or dell xps which should i get?

crude stump
rapid merlin
#

I asked for the winter all year and now Ive got a cold I’m second guessing myself 🥴 I want one of those wearable blankets

sleek flicker
#

Hey guys

void zodiac
#

"In case of cyberattack just pull cables"

Is it a good advice?kekw

void zodiac
sleek flicker
#

How are you guys doing

void zodiac
sleek flicker
#

I’m alright

#

Thanks for asking

#

I’m waiting for the big news to drop

void zodiac
#

What news

void zodiac
#

"THM mobile app" kekw

sleek flicker
#

Is any of you already in a cybsec job?

rapid merlin