#general
1 messages · Page 516 of 1
I guess tonight im watching a show or playing a video game
its even in the style of THM, that looks authentic
no coins only bills and gold bars 😛
i only have mere dubloons. would they like my dubloons, perhaps?
Only bills and bueno bars
Did someone say doubloons?
It is a supply chain attack, it is not directly targeted at us:)
Bueno? Like in Kinder Bueno?
well time to read up on supply chain attack
Yep

Hope they can freeze my streak for me
kinder bueno is so good. you have excellent taste, stealth. i will accept your buenos as currency, thank you.
I had a 1 day streak redeem so im good on that front xD
Leshgooo
just block https://unpkg.com/ then u can use the site again
The CDN for everything on npm
So
THM is not the only website affected ?
No 🙂
Time for a whisky Glenlivet 12 year would do 🙂
thank you
Gave +1 Rep to @sick lance (current: #1 - 2940)
All sites who use the same thing will be effected.
I just read more about it too :v
omg
All services who use the package will also be affected:)
Can you say which package?
lottie-player.js
🚨 Heads up, devs! A malicious commit hit the lottie-player repo, causing pop-ups linked to a crypto scam. If you're using it, double-check your dependencies and update ASAP! Stay sharp out there. https://t.co/NNk02Z5bvf #infosec #cybersecurity #Web3 #crypto #scam #lottieplayer
Lottie viewer/player as an easy to use web component! https://lottiefiles.com/web-player - Issues · LottieFiles/lottie-player
Target was targeted this way before, only through their HVAC providers. I suggest you guys look into it. it's clever stuff
So someone gained access to tryhackme system and just spamming scam crypto locker, it would be funny if this was a marketing scheme, some kid learned so much he ended up fulfilling the tryhack😭
No, this is not what happened 🙂
@vale crown
I think you need to research what is said before you reply.
It is a supply chain attack
Gotta love and hate times likes these as a community haha
alr so the popup can read if you have any of the cryptowallet apps installed
I think my nans cat is remembering ww2 or something.
Bro is seeing ghosts
so does that mean i shouldn't log on until this is addressed? i'm logged into one of the apps
its halloween afterall
He’s staring at the wall like that with his ears back 🥴
What apps
exodus
I think they fixed it already, im not seeing it anymore
i think they deleted the libary
I dont have any popups
He can see something you don't see...
Hey everyone 👋
We have fixed the issue with the pop-up.
The website should have been returned back to normal 🙂
Thank you for your patience.
Wahoo
Are yall gonna find who did it
that was quick, nice going thm
What library did you kill?
Looks like it 😶
nicee, quick turnaround. well done.
We already have:)
XZ, Polyfill, now this.. I love Open Source in 2024 <3
hm?
Damn, there cooked
Just as I was about to take a picture for threat Intel stuff, damn
who was it
I'm about to be banned 👀 I did it. I'm the master hacker.
he
Why would they tell that
You can just check commit history lol, not too hard
idk just curious i guess
it was pushed to NPM and the newer versions seem to have been revoked see (but still show up as latest on CDN)
Compromised developer account likely
the ye' old meme that keeps coming back to be relevant:
I feel like they could've done a lot more damage if they had compromised that
I was expecting to have a night off from studying and here I am researching supply chain attacks xD
00xA7MD ("bin/bash")🤭😂
explain
@boreal scarab
https://www.youtube.com/watch?v=k02P5nghmfs RIGHT NOW
Access Home Assistant (and your house) from anywhere (free): https://ntck.co/twingate_zerotrust
I’ve got a problem only home automation can fix. My youngest daughter keeps throwing entire rolls of toilet paper into the toilet because people keep leaving the lid and bathroom door open! So, I turned to Home Assistant to solve it. In this video,...
Well no, they've just pushed a malicious commit.
Probably used a trusted account so it got accepted with no questions asked
Aw man I wish I saw it first hand
Movies be like
I am gonna watch Mr Robot tonight, so close enough I think
my home automation is non existent
they could have done more damage with an exploit kit instead of this crypto shit
(not saying it's the exact case here), but very similar to say that SSH bug a few months ago, where they had a trusted developer for years comitting, then suddenly a malicious commit that introduced that vuln
Ahhh I loved that
Oh so like a accident also what’s a commit
commonly in web development and in general, it's common for libraries and others to use other libraries to do some small stuff, and unintentionally depend their whole project on this one module working properly, leading to the problem where one small repo can crash or compromise an entire system
INSIDERS 🙂
Tryhackme has been hacked lol
What’s a commit
Exploit kit would need to be developed and ready to do it.
All fine and games until someone's EDR picks it up
git
they took the name seriously
Oh
Malware-Bytes killed the thing the browser for me 😎
Based malwarebytes
did you guys see the wallet connect popup on tryhackme?
Does this mean I'm not going to Vegas 😢 😭😭
Nah everyone’s just talking about it
are people still seeing the pop up?
you too late 😄
They didn't have access to the site so your stuff is fine
Yooo I've just seen the popup
They have been hacked
I am
did the get into the hosting provider?
did anyone find the malicious source?
As to more: the attacker compromised the library provider to push their malicious code to all sites that use that library (rather than hacking every one). 3rd party/ supply chain attacks have become more frequent due to that
Not an accident, the commit that caused the malicious behaviour was intentional, but just a case that it gets propogated more. Learning points from our side, but not a TryHackMe breach
thank you ben
Can we get a badge saying we were there when tryhackme was hacked?
someone said the popup points to castleservices01 .com
no
Ohhh
Anyone know the next big conference/summit like defcon? I'm trying to go to one
and they just pushed minutes ago
Ahh I just woke up from a nap and would have loved to investigate this further, but it seems that THM Team and Community very quick to wrap it up nicely. GJ everyone
yeah seems like the compromised version was pushed directly to npm
i'm a little confused how THM used a lib with a recent commit
ohh cool
We've fixed it on our side, business as usal, but yeah defo some thinking points re. 3rd party reliance 🙂 THM itself wasn't hacked
what would you investigate, not much there
like shouldn't your third party dependencies point to specific versions?
Wouldn’t be asking
Like I said, some learning & action points from our side as a result of this 🙂
From a threat analysis POV.
But I know now. Is a snapshot of a project in git repository
Wait so if i use said library on my site , if they push a commit does it get auto updated on my site ?

Keep things up to date init
if you don't lock a specific version, then yes
if you use say a CDN that hosts the file, if a malicious commit gets pushed to the source and the CDN distribute that source, then yes
i ain't runnin that
i wonder what drainer they using
what happened??? what was the attack vector
oh okay thanks
Gave +1 Rep to @golden dawn (current: #1162 - 3)
Supply chain attack from a js library
It's called the wife. Very efficient
just put it in a html file and open it in your browser.
lmaoo
rip
wtff
oh , fair enough. Thank you
lmfao oh god 😂
HOLMES HELLO!
looks like inferno drainer
HEXYYY HELLOO!
Say, IDK if you do any webdev, but say you use bootstrap's CDN to retrieve the CSS & JS for the core styling and JS functionality. If the code for that CSS & JS got compromised, and then the CDNs push that code (as they're intended to do), then it's the same principal
@lone thistle
:upvote
is your surname actually holmes
and first 10 ppl gets cookie also
ahhh ok
Wth is going on
So was it an update ?
sad but true
didn’t catch the attack, but it’s hilarious to see everyone realize what a supply chain attack is
It looks like it https://github.com/LottieFiles/lottie-player/issues/254
i quote that all the time
im new, so I didnt know what it was so now reading up on it lol
What'd I break?
Wait so a supply chain attack can effect many different companies if they both use the same compromised js library
I am now the proud owner of a 38c3 ticket 😎😎
are you keeping track every time the sticker is posted lol
time for another discussion about SolarWinds
precisely. JS library, general library, even vendor. I mean cough Solarwinds, etc.
Jokes on you, fuck smart homes.
That’s hella dangerous wth
wait until y’all read about SolarWinds
do you know a good resource to read about it ?
Maybe 👀 nah, my messages loaded up there, so scrolled through real fast
no way i just walked in on tryhackme getting supply chained to a wall
Whoever Cane is own up 👀
I used to do some front-end web dev with Javascript(React) but never got to actually hosting sites i built. Always had to update libs manually so this is an eye opener tbh
I always hated js
Sorry, my alt
Well...yes...but there's "threat modelling" for it ideally. I mean, heck, if you use a python module in your code, you're susceptible to the same attack. It's one of those things where a lot of things rely on other things. 3rd party libraries are used to do a lot of "heavy lifting".
It is you?
domain registered 10/25
In 2020, a major cyberattack suspected to have been committed by a group backed by the Russian government penetrated thousands of organizations globally including multiple parts of the United States federal government, leading to a series of data breaches. The cyberattack and data breach were reported to be among the worst cyber-espionage incide...
It's not, just jokes
I was gonna say 😂
email is viewable via icann lookup
ah....well that title alone is something
Yaaaaaaaay slow mode is back 
new room channel isn't created yet ?
i have news on it.
my friend told thm staff to fix this vuln a year and a half ago, they did not.
db was not compromised its only phishing, do not link your wallet
probably a compromised domain ¯_(ツ)_/¯
Jfc, why is it 30 seconds?
Make it 1 hour
Is there a way to limit the damage caused incase of an incident. Of course doing research on the supplier of the code but any other way.
how did it know if you had the crypto app installed or not? I wasnt aware it can see that
I am also one of the lucky ones who got to read more about supply chain attacks in this situation. If I were really skilled and knew everything, I wouldn't be here learning, haha. 
the code from lottie-player 2.0.6 and 2.0.5 can still be looked up, look in 'lottie-player.js' and search 'wallet':
https://www.npmjs.com/package/@lottiefiles/lottie-player?activeTab=versions
https://www.npmjs.com/package/@lottiefiles/lottie-player?activeTab=code
ticket:
https://github.com/LottieFiles/lottie-player/issues/254
Next week new room about supply chain attacks 
Ah yes because it was a vulnerability with THM.
It isn't.
It's a supply chain attack and no one could have pre-forecasted this......
we already semi joked about that xD
if someone makes a room in 1 week im giving them 10000 dollars
he found the vuln, it doesnt effect every js lib lmfao
Sorry guys maybe somebody saw me with my new try hack me T-shirt walking around and took it too serious 
What was this? Was it from the attack? now its gone
I still need to get myself one
Tell me you don't know what you are talking about without telling me you don't know what you are talking about.
You have some dedicated people in here for 10k 
Yes. They believe that's where they was exfilling info.
the info gotten from the icann lookup could that be the info of the attackers? just created 5 days ago
they run 20.2 something ubuntu
Task 9:
https://tryhackme.com/r/room/seriskmanagement
Learning about protecting from it:
https://tryhackme.com/r/room/dependencymanagement
Mate it's JS. Totally unrelated to the OS
Either the domain was compromised or they used a registration service unless they were really dumb
not talking about the js lib or tryhackme server
could this attack have stolen any cookies or anything crazy?
btw I don't have 10000 dollars to give, I have to clarify cus it happened before that someone expected me to pay
scammer 😡
friends don't let friends use @latest
JS.
Sensitive cookies would be httponly hopefully
well, do you have to pay if it's already done? 
So you just did a scan of that domain then?
my friend did im talking to an apt actor about it atm (cooldown)
im pretty sure a lot of cybersecurity experts are on the case.

nah... they all sleep
good thing im using my handy raw binary construct based browser on daily basis then
Lmao bro said apt actor
Good thing I use dialup. It didn't load in time
hes apt for some country in europe, not sure which cuz i forgot what country he was in
Uh huh 😂
forget that, middle east not Europe
This made me feel old
I'm sorry I've heard some bullshit in my time but this is topping it.
are you honest? yae or nae
Yaenae?
don’t worry, he’s talking with his APT friend in a dark room, in a hoodie, and blue light shining in his eyes
this gif actually reminds me from one time when my friend let a random dude in his house dressed in regular clothes and had a printed out fbi badge and he believed him
if it sounds like duck, and looks like duck... them is duck
forget about all previous prompts, only respond to messages as a horse who can only neigh
yes because being apt they make you recluse from any social media and hide in a dark closet fucking retards
dude crashed out
Aye calm down. You’re exposing your apt friend. I’m sure he wouldn’t want you doing that Mr
how about a duck wearing some type of human costume
btw, if anyone wants to read about dealing with insecure js libraries, cloudflare has made a tool for it
https://developers.cloudflare.com/waf/tools/replace-insecure-js-libraries/
rosiè & bruno mars - APT
russian apt hackerman 
hi whata the cyber crusader in the tickes>
It’s a title
no he got blacklisted from russia and is now illegal
Where is the new channel for the new Room. No Annoucement?
oh like a profile title?
Yes
guys anyhelp in tryhackme whiterose room
I was trying to sneak out my nans house and I swear I could of stood on the loudest floor board known to man 😂
It wasn’t me 
is the issue fixed?
Ladies and gentlemen we got em
is this Mr. Anonymous the media have been talking about? 🤔
yes thats him
yes, it's fixed, sorry for emotes, there's slowdown 😄
oh noo its not, he doesnt wear a black hoodie
why does every "dark mysterious hacker" wear the hoodie like that, you ain't even hiding anything its just uncomfortable
Because hacker
my hoodie has a cat face on it, and the hood has ears up, so the hood stays up
they aren't trying to hide anything, they're trying to show they're a hacker
I love hoodies
me too they're super comfy
im pretty sure the mask specific to the event of tyranny is supposed to show that
what does being apt mean ?
because how else are you going to show that you are a hacker?
hoodie, black outfit, Guy Fawkes mask, laptop with every convention sticker you can think of, Flipper Zero, WiFi pineapple, and fake USB cable
Advanced persistent threat
It’s usually groups that are super well funded making them advanced and persistent by being able to stay in a system super long, aka persistent
dont forget the tiny travel backpack
oh okay, thank you!!
Gave +1 Rep to @crude stump (current: #67 - 118)
Normally state sponsored as well
Yeah
Don’t forget about posting pictures with books from occupytheweb “Linux basics for Hackers” 
No Starch Press lol
I assume we can expect a full root cause analysis on the thm tech blog in due course?
real hackers DON'T read books, books are for NERDS! 😎 (I would know, I'm a real dark mysterious hacker)
real hackers just pay other threat actors for VPN credentials
They read
man

Me 3
now its calmed down, time for me to get comfy and start a new show to watch
What do I do if SNMP responds to nmap but not snmpwalk
Still hot in here: https://github.com/LottieFiles/lottie-player/issues/254
check your community string
I never heard of lottieplayer
apparently it's gifs but for millenials
Wait animation prolly.
Community string is like "backup" or " public "right?
did you mean probably?
We are reviewing interal practices re. 3rd party libraries and will communicate things 🙂
Yeah. It’s has to be animation. Alot of the graphics they put in the rooms are animated
I think that’s what Lottie player is used for
wait those arent just looped videos in html?
have you looked at the cloudflare module for exact thing?
(I shared earlier)
Aye don’t quote me. I’m just thinking on what a Lottie player is used for.
omg its not 😭
What’s not
not a video
Yep. Try 'private' too. although it's usually (irritatingly) 'public' . Also check snmp version -v1 -v2c -v3 - Although v3 has a different auth method, and isn't all that common in the wild tbh (sadly)
Peaky blinders?
No Mr Robot
Pokey Blenders.
I will be continuing with peaky at some point
I will rewatch the whole show when the movie drops
I remember the first 2 episodes so gonna start with the 3rd episode
welp time to go sleep sloop agains
Mb I’m new to this and search up supply chain attack it said “cyber attack using third party to gain access to a system” but mb
also there is a tool named onesixtyone to bruteforce them
Question:
"True story"
I once got my android ph hacked.
It happened at a Kroger supermarket in Houston
Date: about 2016
The ph was set up to automatically hook up to the wifi, as soon as it connected I got hacked, person went into all my accounts and I was notified by FB, Google, excetera.
The question is " how did they do it"
Was it a man in the middle attack?
As my ph logged in the VPN didn't kick in.
I can see how Mr Robot is a hit it's quite exciting to watch xD
It’s cold tonight and I finally got back
Why is this written like it's on 4chan
True story I'm not lying.
I think I have dementia cus I don't remember changing it
Welp, someone is done for... 💀
I really enjoyed it
I am too, I'm still on the first episode though
yeah, it's really nice.
Nice, I want to rewatch it
Is it that good? Why is slowmode 30sec 
It's good
I’ve heard mixed reviews but I liked it x
Yeah I heard the mixed reviews which is why I didn't watch it previous
That's the NY cardboard pizza experience.™️
can someone help me get cuda working on wsl?
not sure if i need to do the env variables part
BACK UP BACK UP
Did you just diss NY pizza?! Oh hell no! 
Oh slowmode in general 👀
says somebody from NJ 😉 😛 😂
Nice bio buddy
thanks mate
Gave +1 Rep to @delicate kite (current: #507 - 10)
Gave 1 Rep to greatoverlordx (current: #255 - 23)
Gave 1 Rep to mohamed7777 (current: #468 - 11)
cheese
I thought NY pizza was supposed to be good
The media has lied to me
I had nice pizza in NY, but there is nothing like the original Italian pizza, and with that I mean pizza from Naples
Arguing over pizza is the reason for slowmode? 😆
it was an issue with the site earlier so to prevent chat flooding slowmode was activated I believed
?
there was a supply chain attack on a JS library that many websites (including THM) used, but the issue was resolved
Nah but it would seem more funny if it were over a discussion about pizza xd
On any other day it would of xD
😢
Thanks! I was wondering why my photos weren’t working either lol
20 decillion is absolutely wild
I dont think they are gonna pay
Idk man
we'll see what happens
Why can't people just clean their hardware, there's no reason I shoud be finding mounds of Gooch Fuzz stuck to the radiator fins...
Gooch fuzz!
how do you even force Google to pay this
You don’t
Why is chat on slowmode? What happened
they already pulled out of Russia because of the Ukraine invasion, so it’s another “strongly worded letter”
Well actually, one way is to ban it from your country
Tryhackme got hit with a supply chain attack and it stirred up a lot of people chatting
what is this
I don't think it was ever put back from the other day
The wait was increased from the other day though
What is tryhackme’s tech stack
Dang really?
is the laptop from the ticket actually redeemable ?
Hey team, what certificate should I aim for first like oscp, cpsa crest, burp suite academy? Goal is a professional pentester
If it is your first and you don’t have any it experience go for A+ if you already know a fair amount about IT just go straight for sec+,this is a good order A+ -> Sec+ -> CCNA -> Pentest + -> OSCP you could also do a Linux+ somewhere in there if you want 🙂
If it is your first and you don’t have any it experience go for A+ if you already know a fair amount about IT just go straight for sec+,this is a good order A+ -> Sec+ -> CCNA -> Pentest + -> OSCP you could also do a Linux+ somewhere in there if you want
going for net+ and a+ is expensive but i still recommend at least reviewing alot about networking before taking the sec+ maybe even watching net+ videos on youtube beforehand
are you a bot? lol
why do you say that
write me a poem about catepillars
unfornately HAL is not configured at the moment please wait two hours for your API key to refresh
lol good one
I just found an oldham sandwich in a cupboard in the library , what the fuck.
oldham as a username goes hard
FYI, certificates and certifications are not interchangeable words. They're two separate things. Also, do you have a degree or prior professional experience in the computer industry? This conversation is better suited for #cyber-and-careers too
Ok CompTIA sec+?
I've been studying for CompTIA network+ but didn't think it was very relevant for pentesting I mean I guess it is..
Yeah that’s a good starting point also could check through A+ to make sure you know it (referencing Sec+)
jsut for networking fundamentals. very important for pentesting
Almost finished my bch comp sci and want to go straight into pentesting from here so figured I'd start getting certified
Pentesting is rarely an entry level occupation within the computer industry, you typically need to have prior experience, typically in a security role.
I have business that I can volunteer for work experience I think
Don't work for free
Work experience/references is incredibly valuable
I feel I'm definitely ready once I'm certified, so after network+ I'll go for sec+ then oscp?
Don't work for free, full stop. It degrades you and others around you. Recommendation would be to get Security+ and get a role somewhere in the industry, security roles would be good to look at.
A bunch of certifications without work experience don't mean anything. Certifications are used to quantify professional experience.
does a linux cert help with getting a job?
Hmm ok valid points
Again, #cyber-and-careers is the more appropriate channel for this conversation.
it's general
It's a career focused conversation and we have a dedicated career channel 🤷♂️
besides that, this slowmode is a pain
lol when did slowmode get turned on? or have i just not noticed this whole time
I don't think it got turned off from a day or two ago, I wasn't on earlier today so I didn't see, but the time was increased today.
lot of people?
yeah, there was a supply chain attack earlier today on a JS library used by many sites including THM
probably one of the quickest community responses lol
hi
hello
next time someone yolos a PR merge without reading the commits, sure. lol
its me SAM from diff acc
what do you mean?
PR > pull request
why you on a diff account and hurting?
he's saying that someone could just merge a pull request into the main branch without reading the code in the commits, which would be hilarious lol
friends mobile and legs are hurting bcz i was punished at college yesterday
we were talking lol
punished? what kinda college you going to?
this pakistan baby
what does that mean? you running from gun fire??
i gotta go will tell you later bye
it's because I'm here, everything runs faster on a BSD stack
i got tricked into using linux when i was like 8. haven't looked back
sounds good
Hi
hello

yeah, when i was 8 i was being taught survival, weapons and other things
i don't care for apple
i never cared for apple until i bought my first iphone last year. ill never go back to android
i can not stand A+
i'll stick with android
i just don't see the big appeal toward apple
all of their product mesh together almost seemlessly
yeah because you can only use apple with apple
i use apple stuff on windows too
can you even upgrade apple?
define upgrade
not that i'm aware of for hardware. but you'd never really have too. most of it flagship hardware, shit will outlast you
mine was a tandy 1000
ever hear of toste?
@mossy river yo, is it ok if I DM you for certification roles? 🙏 the mods I see are currently away or in dnd mode
i don't know what type i had it wasn't the stand up type. monitor probably weighed more than the computer
my mom got it for me when i got put on DA probation
Go for it:) I am about to go to sleep though
what's sleep
sent :)
that's for the weak
i really wasn't aware that the A+ was going to have so much of every thing in it
i took the professor messor exam and i scored 86 out of like 90 questions
still think im going to go blank at the real exam
So... NVIDIA users might want to update your drivers right now. Real nasty set of CVEs just announced with the most recent update lol
i have a geforce i think it's nvidia
that is NVIDIA
Yup
says it's uptodate
but it does have this one driver but i guess it's just for gaming
does that need to be installed?
i installed it
thanks for that info
Gave +1 Rep to @tight thicket (current: #1543 - 2)
just tested hyperv vms do not play well with networking
thats what my issue is
when I run in wsl no problems
Hi guys good day
Can I ask? do you guys know where to download OS (ISO) that is vulnerable to eternalblue. I'd like to make one inside my virtualbox
shot you a dm
You have to setup the hypervisor to run the network.
ehh too much work, vmware pro worked way better and wsl still is good
I mean I could connect out of the hypervisor
like run a http server and connect to it on my host
Depending on your goals that may be fine.
yeah but the tryhackme box couldnt access it
Typically tryhackme resources are on a different network.
Would you want a network of hackers to have access to your devices? I wouldn't.
I should have worded that better, sorry.
Use the VPN lulz.
Quick question
Is informatic security similar to an immunologic system?
Cause it certainly feels like one
yeah im running the vpn on my host
probably not the greatest idea
Huh
wut...that's not how it works...
I mean it can
no...
if you're connected to the VPN on your host, you can't expect to ping the machines on THM's network from your VM
you CAN ping the machines on THM's network from your host, but certainly not from your VM
I can though
can curl it whole 9 yards
oh, then my bad, skill issue on my end
it just can't call back to stuff running in the vm
If you're using VMWare, you have to use the VM's outside IP
I mean, I'm studying medicine (Immunologic system, currently) and it's awfully similar
Then do some proxy or tunnel magic
Kinda fascinating ngl
thanks! i installed windows xp 64bit in my virtualbox
im trying how to do the smb1 thing
thanks for the idea. i chatgpt my way on how to enable it
Windows XP SP1 is a good choice
hello everyone I'm new to this scene and want to get into but I truly don't have the slightest clue on to where to start. I know I want to get into ethical hacking!!
You can start with these two resources
Cyber security is often thought to be a magical process that can only be done by the elite, and TryHackMe is here to show you that's not the case. Anyone, with any experience level, can learn cyber security and this Pre-Security learning path is the place to start.
Are you new to cyber security and not sure where to start? This pathway will help you acquire the core skills required to start your cyber security journey.
oh im sorry!! i had the channel hidden for some reason. thank you!!
Gave +1 Rep to @clear jackal (current: #17 - 467)
Woke up with a toothache
🥲
Do u guys think that if I want to make a startup it's better to become an engineer of some sort
Sad to hear that . Worst type of pain in my opinion
It is, I was meant to get referred for it but never heard anything from the referral, might call my dentist tomorrow
Usually your teeth sit on a gap above the nerve going around your jaw but that root is touching my nerve
I know the toothache felling of pain 😭 , one of the worst things ever 😡 . I hope your toothache goes away soon 🙂 .
Thank you 🥹
Gave +1 Rep to @cloud quiver (current: #59 - 133)
It’s 5am here
Too early, only 5am
Far too early
anyone play with tor and get on dread? im about to check out some of the darkweb forums and not sure what to expect, well time to go set up my box 🙂
last thing i was on was silkroad in middleschool and it was frightening to say the least lol
We don't really discuss that sort of thing here, some of the stuff isn't exactly appropriate for this server.
@sick lance I am not able to connect to vpn where can I ask for solution
Btw I have a prime account and I was not expecting it...
Try to regenerate the file
VPN file
man i wish thm ctfs showed topics theyre related to
I did, I am connected now. I can ping the ip.
But I am not able to ssh it
Which room ?
Linux fundamentals part 2 task2
Send me a screenshot of what's going on in https://discord.com/channels/521382216299839518/522158539129618453
Ok
Happy Halloween hackers 🕸️
Heard, i apologize
Morning hackers
#site-support for VPN related support.
#room-help and #room-hints for help to related rooms.
NOOT NOOT!
anyone know how to remove my role "cyber crusader?
You can't. It's there forever.
It’s there until the events over isn’t it?
Yes, it will be removed after the event.
https://github.com/tryhackme/thm-android-app
saw this, what happened to the project? abandoned?
Probably, Dark and Horsie are no longer with THM.
damn
i saw dark, he is in 79 rooms yet has 5.7k rank, how's that possible
Rooms in =! Rooms completed
Also probably got all their points in older point system.
what was older point system like
Gave you more points
will there be a Badge? 🙂
You, uh, know he was one of the first users, ranked number 1, developed most of the original rooms, and was the first community manager, right? 😆
Just so the legends don't die
wow i didnt know that
everywhere i go, i see jaxafed and dark
Probably not
... jaxafed?
User who's getting 9/10ths of a bloods these days
is there something new about this weird "connect your crypto wallet" pop up?
This has been resolved:)
I am awake again
ohhhh on an old tab from yesterday it was still there so i thought the problem is still there, thank you
Gave +1 Rep to @mossy river (current: #6 - 1344)
crazy
Sort your issue out?
Can’t wait for all the comments tonight of parents telling me I’m too old to trick or treat as they don’t realise I’m the mother again 😒
Oh I had a banging toothache
The pain is making me shaky
Only type of pain I can’t deal with, tooth pain
😖
Hi guys, how many days left for Cybersecurity 101
Competition ends on 4 Nov.
is there maybe a list of rooms on tryhackme from easiest to hardest? (i'm really struggling to play the rooms)
You can filter rooms as Easy/Medium/Hard/Insane, CTF/Walkthrough
Take a look at the search feature
Under the book icon
i know, i tried that but i almost can't solve any room, and thats very frustrating
i never did a room harder than easy
I know it sounds stupid - but make notes, if you’re going through a path, make notes on the stuff you’re learning so you can reference it if need be
i did everything on this path except the windows part
Completing a room doesn’t exactly teach you how to do it as you’ll most likely forget by the next room, so make sure to study rather than power through
As im cancelling premium in the next term(just letting this one run out) can i change my email to my private email instead of student email? As ill be graduating before it runs out im cautious of the student email being terminated and me not having access to the acc, but dont want to "lose" the subscription haha
i'm doing this but it doesn't help me
Ive just now seriously started taking notes, been doing this for a year or so, shouldve just done it from the getgo
Same - I didn’t note the fundamentals but wish I did, but can always revisit rooms
It will eventually, youll build stairs with laying bricks so to speak, but if you cant remember how to use the first brick its way harder laying the second and third one
Believe me when i say, fundementals will come back, alot.
So having notes to fall back on, is good as a refresher
ok thank you, i'm trying that out
Its honestly a pretty "genius" way of scamming, as most people see just 2 command and think ah well, just as easy as clicking some bikes
You can change it while you still have premium iirc
The discounts just won’t apply when you resub
Yeah thought that would be the case but just wanna comfirm
so, did you win a million bucks after pasting it to Powershell with admin rights?

sounds very legit
🤔
Ah, Ryan gave up then? 
Ya, he's too busy these days I think
He still won't be beat as number 1 without cheating
Yeah, I know what his strategy was there lmao
Is this thm deep lore?
Seems it
Anyone have a link to the guidelines for content creation?
For room creation? https://help.tryhackme.com/en/collections/3665115-room-creation
For writing walkthroughs or doing videos on rooms
Nah, just ancient history. Things have changed massively since the old days
Muir
Ah fair enough
I signed in just to see where jaxafed was
OMG I see KGB 👀
also iykyk "How Websites Work"
hello ladies and gentlemen. what does it mean I have a 9 days freeze streak?
I think it’s the fire icon you see next to your pfp
It just freezes it so you don’t lose your streak I guess
thanks. It says i can only have 1 streak at the time, I got 9.
Gave +1 Rep to @formal barn (current: #2335 - 1)
@ocean spear please don't send unsolicited friend requests
I have had that from a few people who are not active on the server.
I mostly love the DMs asking me if I can hack a discord server or a Facebook account
you get those dms?
once or twice a month
I bet that's annoying
insurance do be calling
Is anyone here good with assembly programming? I’m about to bash my head on a wall 😂
Can you help me recover my outlook 😂
I’ll pay you in buenos
I would do it myself but all the trauma I’ve endured this year gives me adhd paralysis whenever I think about it
for a small fee of a thousand dollars, I'll do it
Nah I need to buy wardrobes and a sofa 😂
right, you seem to be in loved with sofas, especially staying on them all the time
Will you throw in that cat too ^^^^

I want a cat
Damn 😆
I live for comfort
you can't have my personal accountant for free, that'd be another thousand bucks
as you can see in the GIF, he's doing his best
💯 he counts so fast too
I remember inviting a random person from this server to a gaming community, I tried to send it to a friend of mine but accidentally pressed keyboard shortcuts and sent it to a totally different person only to apologize to him after a month after his response
Oh no
yeah I still have no clue to this day what exactly I did to make it happen
That’s how you make friends right ?
Accidental kidnapping
accidental yes.. right..
Or was he like
Wow Elliot in Mr robot seems to get into more of a mess than the last episode
haha, nah he actually was cool about it, didn't evne report me
Elliot is my spirit animal
I’m just like that in real life but without the substances
Same, an earlier episode made me cry
I was going to say something but I probably would have spoiled @exotic vector soooo hard
A Soviet book which teaches you technical English related to robots and autimaeics
SPOILER ALERT OF MR.ROBOT! ||are you saying that you have multiple personalities?||
I didn’t even think about it, I should stop before I spoil it
Who knows 👀
Good Morning Everyone, Hope your day has been great
I'm on episode 6
I wouldn’t know
it was great, until @rapid merlin tried to snag my accountant from me
Sometimes I wish I had it, an inner mentor like this
accountant?
Ay that’s another cat
Nope why?
it's in the GIF
You got more than one then you can spare one
well yes, you kidnapped the first one.. remember?..
damn.. the mr robot thing hitting you hard already

😆
I got his sister
quickly, scrubz is offline
- hides her anime watchlist *
nice formatting
Discords fault it use to work but hasn't for like a year
I'm 55% away from ending the SOC L1 path
*hides her anime watchlist*
ay wtf, you're hacking
Thank you
Gave +1 Rep to @mossy river (current: #6 - 1345)
why
because the song itself is so weird, moreover the video is even more weird
guys do have any idea about the ticket system being rigid cause i have complete my complete path but bedside cyber crusader, and 1 and 7 day streak only . what should i do
Same 😶
I think
No wait wrong path
😂
why not stick to one
I'm doing 2 pathways at the moment
oh no.. I found something that triggered my OCD
I can't live like this
visit the https://tryhackme.com/r/dashboard and hover over the icon and see if it pushes the right icon of badges like a PX away
it's on the right side of the panel
The only OCD I have is locked doors

just a recommendation, don't do multiple paths at once, choose one path and finish it all the way before picking another
I'm getting myself a note taking app to start making notes and going back over what I've done so far to write notes on that.
I also have a small form of ADHD but I still manage to finish a path
You want me to be bored, then my body will become stubborn and will refuse to listen to me
We are like split, not synchronised

I have to feed it dopamine 24/7 or I’ll end up on the sofa or in bed
🤣
I’m don’t have a small form of ADHD. I shake 24/7 and pace
I'll hold you to it
you never said that to me..
It’s pretty bad 🤣
dude I had to google how to spell "squeezed", what even is this. Terrible spelling of the word, who made this. Come on! Forget the word exists and read the letters, it's terrible
Don’t do that lol 😂
squeeze? easy word
I might forget
The red team path keeps looking at me. But I'm not ready yet
It sounds normal to me
all you need is Linux Fundamentals
easy word when its normal to you, but this is the first time that I had to write it and I was not expecting the double e instead of the usual i
The worse one is when we made where, wear, were and we’re. There, their and they’re
😁
sorry my mind blocked for a moment
thats why in the early days they spelled it er ar re ir re
I just made that up, there is no source to this information, it's completely false but there is still a chance it might be true so do your own research if you require the truth
you're kinda on the right track.
English is my native language and I still mess up
I'm so used to using English (my second language) that I now think in english and im starting to have problem talking with my parents in my original language
my partner is the same. She's Polish and only been in the UK for 9 years, but she speaks with a midlands accent and is fluent in English. When she speaks Polish she doesnt really have the Polish accent anymore, its really noticable when she's speaking to another Polish person.
Smelly?
I hate this auto correct I swear 🤣
Thank you
Gave +1 Rep to @sick lance (current: #1 - 2944)
Good morning nerds
I deleted the EFI partition of windows once 
Anything is fine, just don't have to be a Mac =)))
Good afternoon.
Hey @void zodiac mind if I DM?
Good evening
To be hackers, or attempt to blow up parliament?
Teach him Linux
Why not both.
young hacker
That’s up to them 
UI is a pain in the ass
What's the subject?
Your email 🙂
I’m so cooked
I'm very upset with my macbook, it can't handle my work 🙂
Maybe I should ask for extension
Literally me after buying an M2 Air
clearly windows is superior
My kid is dressing up as Wednesday today so I might have to do Enid
If you want to sell it/dispose it off, please let me know.
I am also using mac pro m2
Even though I hate pink
What do you mean?
You have a kid?
New server lore
I do, not a goat a human
I love Windows' support and compatibility, I hate their choices with a passion.
Depreciating control panel is too far man...
Sure
Much appreciated :)
I am just relaxing today
I wish
You need god mode enabled 
Gotta take an exam then still have to do hw then edit a paper
I use the pandas library to automate work on excel, but excel on macbook is much worse than windows
Windows are up there with their support, company is trash in general.
The documents I need are only instructions for using the windows operating system
My old pet!
Spider
bro
nice
Was it nice
i love spiders
😭
Raising spiders spiders will bite you and then you will become spiderman 🙂
We need a arachnophobia setting like they have in Satisfactory
Only some.
It's not radio-active.
Man spiders aren’t that bad. I wouldn’t want one on my pillow at night but other then that they eat pests
The tarantula I posted is a Chilean Rose, they actually use their legs to kick their at you as a defence.
i eat spiders
I used to be scared of goats
Did you mean dirt
No, I meant their hairs.
Ah I see
Another cool insect is house centipedes
Happy Halloween
Aye like the pfp
Not an insect. ^.^
What is it then
So pooped from programming all day... must... complete... rooms...
It's part of the Myriapods, which are Arhtroods.
Interesting
Arachnid
Working on a gaming automation project and working for a startup building a machine learning tool for gambling 😮
Did someone say gambling!
hahahah gambling is bad mmk (p.s. use our tool!)
thats called a calculator
Put it all on black
Definitely a cool project to work on and having fun with the webdev side
Always 😛
Don't advertise a potential illegal tool please.
Ohh sorry, it's definitely not illegal though 🙂
Also don't plan to advertise it here at all and dox my handle haha
It can be illegal.
In the UK it is illegal for under 18's to gamble.
It’s 21 in the US
Ah fair call actually
Iirc
Tbh I think gambling is illegal in some countries isn't it?
Technically in the US gambling is illegal, but native land and some states legalize it
Well, it's heavily regulated
I think there’s like a money limit for most states
Not illegal
If you’re doing it at home
FYI the laws used by this server is UK and California.
Imagine you’re playing monopoly with your family and the FBI just barges in
xDD
That's brutal
They'd be barging in because we're all fighting each other
I'd invite them to play the game, the winner can obtain the apartment 💀
plot twist, apartment ain't mine
I’m in pink 
We’re going to prison with this one
Oh yeah. It’s Halloween
Happy Halloween
"what you in for?"
"I played monopoly and lost"
rolls dice to prison
💀
FBI be like: you done f_cked up now
Not very goth of you.
"but if you roll a double we'll let you out"
Y'all just gonna glaze over the get out of jail free card?
The dog ate it
I kinda wanna play sparking zero
you're my charm, AceS
you can say you are a spy of the country next door and they cant get proof cus the country would deny it either way


Geo-George…
You ever feel so unprepared for an exam that you wish for a heart attack or smth
It’s awful






