#general

1 messages · Page 520 of 1

rapid merlin
#

proton isn't privacy focused

#

never was

obsidian helm
#

Surf, Proton I think

gritty fern
#

How can a VPN even be security focused?

rapid merlin
#

surf, probably not

gritty fern
#

Not very fluent in VPNs

obsidian helm
#

Hello guys

#

I'm new here what's up

rapid merlin
#

if so, mullvad.

obsidian helm
#

@rapid merlin really?

obtuse mortar
#

Yeah Mullvad seems to be consistent

wooden totem
rapid merlin
#

Proton has been exposed, and laughed at by every single person for being a horrid service

finite basalt
#

I still have doubts about data collection but in terms of tying it to an identity mullvad seems better

gritty fern
wanton schooner
#

oh ok thnks

tranquil lark
#

Is the site working for everyone rn or is it just me thats broken?

gritty fern
#

broken rn

obtuse mortar
#

Although Mullvad does fall under 14 Eyes

rapid merlin
#

doesn't matter

obsidian helm
#

@gritty fern yea, I'm new here and I just started chatting

rapid merlin
#

they've been raided before, no logs or anything was found

gritty fern
wooden totem
obsidian helm
#

@rapid merlin yea that's clear

ebon quartz
#

is the site acting up for anyone else?

rapid merlin
#

For anybody coming, yes the site is down, staff are aware and are working on a resolution, thanks.

obtuse mortar
#

Ever tried IVPN? Looks semi trustworthy

rapid merlin
#

no

#

I was put onto mullvad by a friend in 2021

#

never looked back

obsidian helm
#

Nope

finite basalt
#

for the sake of ease I just use protonvpn personally

#

not proton sorry

wooden totem
#

this guy is getting paid to recommend mullvad

finite basalt
#

nordvpn*

trim scarab
obtuse mortar
#

I have been running tails + mullvad + tor and have not found any leaks

obsidian helm
#

Nord?

finite basalt
#

I've heard good things about mullvad but personally don't care too much about security of it as much as speed

chilly veldt
#

It has good speed

rapid merlin
#

yeah, you might have to swap servers a few times though

gritty fern
#

@obsidian helm i dont accept random friend requests

obtuse mortar
#

On mullvad you can't do more than a double bound?

obsidian helm
#

@gritty fern I understand... Kinda seem strange, but gte to know each other at least I have no friends here

wooden totem
#

I saw surfshark being rated better than nord

ebon quartz
south dock
ebon quartz
#

I would need to open a new tab then it would be complete. I lost 2 tickets completing the room

stark wolf
#

something going on with the site?

obtuse mortar
rapid merlin
#

yes

trim scarab
rapid merlin
#

Surfshark, express & nord advertise through grifting yters

hasty sand
#

It's back

rapid merlin
#

o/ ryan

chilly veldt
#

I personally love mullvad

wooden totem
rapid merlin
#

good work on the peoples call centre with pierogi lmaoo

twin ridgeBOT
#

Gave +1 Rep to @wanton ridge (current: #2338 - 1)

rapid merlin
rapid merlin
wooden totem
ebon quartz
#

anyway to see if I got the tickets from the room I completed? I wasnt able to see if I received them

chilly veldt
#

I mean, if you want privacy and secure connections mullvad is top 1 cause it's ram only infrastructure

void zodiac
#

Oday

#

Hi

wooden totem
obtuse mortar
#

Outside of reading actual auditing reports its actually hard to find a non grifting list of good vpns for privacy and user security

hasty sand
chilly veldt
#

How you doing Ryan?

void zodiac
rapid merlin
#

ryans discord getting lit up rn

ashen bloom
#

yo friends

wooden totem
#

I think this 0day fella is a celebrity here

rapid merlin
#

its normal, he is top 1 right now lol

hasty sand
#

About to get some Chick Filet, hope you all have a great day and thanks for the kind words ❤️

gritty fern
#

0day!!

obtuse mortar
#

what VPN does this 0day guy recommend?

gritty fern
#

Chick filet is fire

hasty sand
boreal scarab
#

Can you get me dinner? 👉👈AMpuppyeyes

ebon quartz
#

woah is that really who I think it is?

obtuse mortar
twin ridgeBOT
#

Gave +1 Rep to @hasty sand (current: #49 - 167)

rapid merlin
#

mullvad its a real god vpn for not beeind rastred

#

they dont know who paid his service 💀

rapid merlin
sick lance
boreal scarab
rapid merlin
#

Oh man that’s my favourite too

rapid merlin
hasty sand
rapid merlin
hasty sand
#

The real "computer man" @quartz osprey

gritty fern
wooden totem
gritty fern
#

No it prints all of discord

#

You might run out of paper

hasty sand
#

Rick is my business partner, make sure to DM him and ask if he is the "Computer Man" (he's in the office next to me)

boreal scarab
loud marlin
rapid merlin
void zodiac
ashen bloom
#

I NEED ATTENTION

boreal scarab
pearl kindle
#

finished two rooms with 500 status code 😦 dont know if i got tickets or not rip

ashen bloom
boreal scarab
#

@hasty sand when will we get a 0day joindeleteme discount? kekw

void zodiac
weak orchid
#

beep

hasty sand
rapid merlin
ashen bloom
pliant cairn
#

Hey all

void zodiac
ashen bloom
boreal scarab
gritty fern
hasty sand
#

I’ll make a THM discount if you guys want one.

boreal scarab
void zodiac
#

Done 🙂

hasty sand
#

I was waiting for our international removals to be complete before I announced it here and on socials.

hasty sand
twin ridgeBOT
#

Gave +1 Rep to @void zodiac (current: #377 - 14)

ashen bloom
void zodiac
void zodiac
#

Amazing movie

candid river
ashen bloom
#

WHO NEEDS A INBOX MESSAGE, I CAN PROVIDE INBOX MESSAGES

void zodiac
candid river
hasty sand
ashen bloom
rapid merlin
candid river
twin ridgeBOT
#

Gave +1 Rep to @hasty sand (current: #49 - 168)

ashen bloom
loud marlin
#

you need turn off caps

hasty sand
twin ridgeBOT
#

Gave +1 Rep to @hasty sand (current: #49 - 169)

rapid merlin
wooden totem
#

I also got army recruitment in the mail

rapid merlin
#

Oh no

rapid merlin
ashen bloom
#

OH MY GOSH, KHALIFA IS TYPING

#

HARD

hard badger
#

hi guys, i have a problem that i cant get in touch with machines through VPN.

gritty fern
#

Why

ashen bloom
#

🤣

wooden totem
void zodiac
rapid merlin
void zodiac
#

More cringe content kekw

gritty fern
#

r/masterhacker

void zodiac
#

:(

void zodiac
cloud quiver
ashen bloom
wraith fjord
#

hmmm i read DDOS

ashen bloom
ashen bloom
#

IF ANYONE KNOW TROUBLESHOOTING, TELL ME "why my both laptop and pc disconnecting usb connected devices like mouse and keyboard".... It's annoying now..... At least laptop has a touchpad,,, so i can use it.....

#

Is it a malware problem or a hardware related problem?

#

I also get an error message like "mscp.cfg not found" when starting windows in both devices since i got my usb disconnecting problem......

boreal scarab
wanton schooner
#

──(kali㉿kali)-[~]
└─$ subfinder -d example.com | httpx -title -ports 443,8443

           __    _____           __         

_______ / / / () / / _____
/ / / / / __ / // / __ / __ / _ / /
(
) /
/ / /
/ / __/ / / / / /
/ / __/ /
/
/_,/.
// /// //_,/___//

            projectdiscovery.io

Usage: httpx [OPTIONS] URL

Error: No such option: -t
[INF] Current subfinder version v2.6.0 (outdated)
[INF] Loading provider config from /home/kali/.config/subfinder/provider-config.yaml
[INF] Enumerating subdomains for example.com
guys i have tried everything but this is not owrking

#

what can i do ? to fix this error

wraith fjord
#

http://example.com ??

wraith fjord
#

also

wanton schooner
wanton schooner
past obsidian
#

Hello

wooden totem
boreal scarab
clear jackal
ashen bloom
wanton schooner
clear jackal
wanton schooner
fiery kite
#

im just finding out the actual 0day is a mod here gtso_wow

wanton schooner
#

so i was just doin it in virtual machine

sick lance
clear jackal
#

What were you doing reconnaissance on? You said you changed it to example.com

clear jackal
#

Oh, hi scrubz

sick lance
#

:wave;👋

wanton schooner
clear jackal
boreal scarab
#

Senior mod

#

Get it right

boreal scarab
wanton schooner
ashen bloom
boreal scarab
#

Can my damn 20 ft power cables arrive any slower?

wanton schooner
wanton schooner
ashen bloom
wanton schooner
#

it sspotify program i was doin on @sick lance

ashen bloom
#

replace version in the last like it

sick lance
wanton schooner
crude stump
wanton schooner
wanton schooner
rapid merlin
#

Choccy milk making everything better

wanton schooner
#

what do i do now ?

sick lance
wanton schooner
#

nd i was just following the tutorial

void zodiac
#

Pizzburgers

wanton schooner
sick lance
wanton schooner
sick lance
#

Does the video do it on Spotify?

wanton schooner
#

yes

#

so how cna i make this command work i tried to save it in txt file but still not working ? 🥲

ashen bloom
wanton schooner
ashen bloom
boreal scarab
#

@sick lance What's the difference between mod and senior mod?

#

Was going to ping James, but since you're here, you might know.

ashen bloom
wanton schooner
ashen bloom
jolly ember
#

Yes, now they are not displayed as they were before, which is very sad.
Either it was removed altogether, or there is a clever way to do this, which I do not know about.

#

This kind of view looks much cooler than just displaying icons.

wanton schooner
sick lance
#

Senior mod can right click ban.

boreal scarab
#

Ooh, fancier punishments!

neat tusk
#

milk noises

rapid merlin
#

how can i verify my acc, thanks ❤️

#

?

sharp citrusBOT
sand trench
#

coffee coffee COFFEE

boreal scarab
sand trench
#

beerrise name is patrick????

sand trench
#

shadow pleads the third

pearl raven
#

pleads the third in third person, Shadow pleads the Ninth?

sand trench
#

hmmmmm

delicate kite
sand trench
#

like right to privacy

#

or right to love whoever

#

or right of indigenous people

pearl raven
#

I think all those things certainly should be protected, yes.

sand trench
#

The enumeration in the Constitution, of certain rights, shall not be construed to deny or disparage others retained by the people.

#

for those wondering what the 9th entails

pearl raven
#

From what I have read Shadow appears to have those ideals, I apologize if I am mistaken?

#

I was certainly not trying to upset Shadow.

sand trench
#

oh sure but the american amendments have a hard time applying to shadow as a swedish citizen

pearl raven
#

Understood lol

sand trench
#

right to privacy is very deeply ingrained in shadow

sand trench
#

you just did

delicate kite
#

There was no question mark

pearl raven
#

Don't ask to ask, just ask.

pearl raven
#

Damn!

delicate kite
pearl raven
#

That doesn't even make sense Scrubz, 200, 200 and 100? 250, 250, and 1 free?

pearl raven
#

lol

sick lance
#

Gottem.

#

HA!

pearl raven
#

Confirmed, Scrubz is an evil Genie.

glass nest
#

Nah. It's been established that Scrubz is a guy who won't get no love from me, when he's in the passenger side of his best friends ride, trying to holler at me.

pearl raven
#

lol, not many gifs that are 'pg13' for that...

glass nest
#

Finally friday! This week has both flown by and dragged on. such a weird dissonance

rapid merlin
#

o/ people

pearl raven
#

Hey constant, how are you?

delicate kite
#

Right I can't even form my question

glass nest
#

It's cos it's friday, Mohamed.

pearl raven
#

^ Scrubz

exotic vector
#

It is hell outside

glass nest
#

You subconciously want to chill, so your brain is rebelling

jolly ember
delicate kite
#

I made it from pre security path up to red teaming path, and I feel like I stopped learning. If the room has no info or hints I don't think I can complete it, although from how much I have done I should be able to complete an easy rated room like "whiterose" or "ignite"? Any suggestions on what I should do, maybe I just need a break or something. I know the question is discombobulated, my mind can't form a proper question right now.

delicate kite
jolly ember
#

@delicate kiteOooh, friend, this is what I need!
Damn, I was sure that this button does completely different things, which I didn't even click on. (thank you)

pearl raven
sand trench
#

try the practice tab

#

with the based on your experience

jolly ember
exotic vector
#

I need to practice, but im not sure at what point I can practice with my skill level

dull river
#

Yo

pearl raven
#

The link Shadow posted above will give suggestions based on that.

exotic vector
twin ridgeBOT
#

Gave +1 Rep to @pearl raven (current: #78 - 88)

dull river
#

I am trying host Kali on my USB but I can't find it in bios I am using and hp computer

dull river
#

Anyone here can help ?

exotic vector
rapid merlin
#

Now I’ve seen it, I can hear it

#

💃

olive owl
#

Do i get anything if i boost the server?

delicate kite
sick lance
olive owl
boreal scarab
#

My dumbass was looking for my phone... panicking where it was...

It was in my hands... watching YouTube

brave pilot
#

guys how do you get the roles thing?

exotic vector
sharp citrusBOT
brave pilot
#

like yk, subscriber and THM level

#

ohhhh do i verify in the discord or on my thm account?

#

okay tyty🙏 🙏

#

ah very cool, my roles are set to me automatically

crude stump
#

If someone has a domain, can they sell or disable it fast. The reason why I’m asking is because I’m analyzing a usps smishing scam I got. I put the link into url scan and it has a picture of the fake page. I wanted a more in depth picture so I tried to put the url into hybrid analysis but it says the domain doesn’t exist. The actual text said you have 12 hours to confirm your address(it’s fake) but I’m thinking, is it possible whoever is behind it sold or disabled the domain once that 12 hours was up?

brave pilot
#

whats the cyber crusader role about?

boreal scarab
#

I called her with my phone....

swift ice
#

regardless, I like Any.run as a free sandbox to visit URLs and detonate malware

#

you will have to use a business email though (a school email also works)

crude stump
swift ice
# crude stump That actually could be the case

also, there was a cool talk at DEF CON about these USPS smishing scams
https://youtu.be/gLOv67LlIQs?si=zJCBYevULzKxGs3n

This past holiday season saw a dramatic rise in SMS phishing (smishing) messages, specifically targeting people pretending to be the USPS. Almost everyone in the United States received one of these messages using a kit sold by the ‘Smishing Triad’. While many of us knew these were scams many more did not, including someone close to me.

I knew I...

▶ Play video
crude stump
#

If it is that’s good but a bummer cus I wanted to see it in a sandbox environment

swift ice
#

yeah, the speaker basically did your work for you lol

#

but as always, there’s more work to be done stopping these guys

#

it has become whack a mole at this point

silver sky
jovial reef
# crude stump Aye

Today, I got a smishing scam that when embedded, has a redirect to the real gov uk site but when you set the User-Agent to a mobile device, it will go to a malicious site

#

lol

#

It's weird

silver sky
crude stump
#

Yoo that actually might be the thing

silver sky
#

No it isn't might. It is. Harder to analyse anything on mobile

#

Given your target is SMS too

naive violet
#

Most web browsing is on mobile devices now

crude stump
#

Hm is there a sms sandbox environment?

#

If that’s even a thing

silver sky
#

But you can't "sandbox" SMS as you are thinking

jovial reef
#

Yeah, when I send the request in burp, I can intercept it on my mobile and somehow I still get redirected even when I use the same user agent and sec-ch-ua headers

crude stump
#

Looking at it through url scan, it shows the redirect and it’s to the official usps site

#

Damn criminals have to be smart

jovial reef
jovial reef
#

Because it gets a 302 to the real site

silver sky
astral relic
#

how to unlock Linux Fundamentals Part 2

jovial reef
crude stump
#

Ima think over this

jovial reef
#

Do I have to make an emulator or something?

astral relic
silver sky
astral relic
#

anyone help me plzzzzz

jovial reef
silver sky
silver sky
jovial reef
#

Proxy and repeater is free without a subscription

silver sky
#

They wasn't asking about burp 😅

jovial reef
#

Oh

#

They replied to my msg 🤣

silver sky
#

I know

astral relic
#

i am new on tryhackme right now i dont want to pay for that now what should i do for learn about it

astral relic
jovial reef
jovial reef
silver sky
astral relic
#

what should i do for learn more about this

crude stump
silver sky
glossy mantle
jovial reef
#

You have to have a subscription to do Linux Fundamentals 2

crude stump
#

Also there are some YouTube channels and websites that talk about Linux

glossy mantle
#

one step at a time 🤝

astral relic
#

can you suggest some room

crude stump
#

The Linux fundamentals are basically the bare basics of Linux

jovial reef
twin ridgeBOT
#

Gave +1 Rep to @silver sky (current: #43 - 199)

crude stump
#

A lot of it is online

glossy mantle
wooden totem
#

I'm surprised I haven't received any sms scams/phish in years, cus I think I remember I used my same phone number and "used" it on some Spawn free gtaV money site

glossy mantle
crude stump
#

Once you get a new phone number that’s how I got tons of scams

astral relic
#

thank you all for your suggetion

wooden totem
jovial reef
sand trench
#

mmmmm modded noita is fun

wooden totem
#

I guess I never responded, I only got 3 contacts and ignore everything else

jovial reef
#

Why am I so happy about that...? idk

crude stump
#

Hold on I gotta learn burp suite now

sick lance
#

Burp is op

swift ice
#

it just sucks that the Pro version costs around 45 plates at Panda Express

polar spoke
naive violet
polar spoke
#

2.4ghz or mostly subghz?

naive violet
#

Got some 2.4ghz non wifi stuff in the works atm

polar spoke
#

looking at some 2.4ghz stuff for a project, bluetooth/wifi ranges but protocols are handled

#

currently, need to do some direction finding work and having a real hard time finding anyone doing anything similar

#

without BT5.1 CTE and phased arrays

naive violet
#

I had a similar thought recently

#

I want to see some 2.4G DF stuff

polar spoke
#

i'm about 10 seconds from just gluing some directionals together into an array and using RSSI

#

because i cant find anything useful in this space

naive violet
#

Hi gain, so highly directive, antennas are available

polar spoke
#

right, i've used them before for... stuff

#

just cant believe there's not even a directional sweep DF setup

naive violet
#

I'm mostly looking at satcom at the moment so I need stupid high gain as 2.4ghz power is expensive

polar spoke
#

i'm also looking at satcom equipment

#

but for terrestrial use

#

because satcom is the only time you find mobile-ish antennas apparently

#

winegard dishes and such

naive violet
#

Yep and usually hi gain

polar spoke
#

exactly

naive violet
#

The mobile TV sat dishes are all gonna be 10gig, I think S band TV is pretty much dead

#

Gain for a given dish is a lot less at 2.4 compared to 10

#

I'd probably look at a patch, there's a ham with some good 2.4g patch arrays

polar spoke
#

oh yeah, but a retro fit with some directional 2.4 feed means i can spin and sweep and hopefully get power/rssi related vectors

rapid merlin
#

Holy shit

polar spoke
#

i dont need trilateration or anything

rapid merlin
#

Chickenman

polar spoke
#

just vectors

rapid merlin
#

Ur cool af

polar spoke
#

🫡

#

haha

naive violet
polar spoke
#

i mean, it cant be that bad can it?

#

use an omni for channel select

#

then spin a channel specific feed until i get frames and measure angle and power

#

and repeat until decent confidence in direction

#

could probably coerce frames from the omni

#

to get repeated vectors faster

#

i dont need AoA or anything precise, just rough directions

#

2D

#

honestly i'm surprised at the lack of commercial availability for this

naive violet
polar spoke
#

it doesnt seem that hard

#

but even the drone defense work is mostly around parsing packets for GPS info and not just straight direction finding

naive violet
#

ToA would be difficult, comparatively, but RSSI seems easy

polar spoke
#

right

primal kestrel
naive violet
#

I'd get a patch or panel etc with a sharp null in the middle and tune to that I suppose

primal kestrel
#

FROM the victim

polar spoke
#

SiLabs has some AoA/AoD stuff using a phase array for BT5.1, but it relies on the 5.1 CTE spec for phase analysis

#

this thing

#

it seems to work relatively well, but without the client device doing CTE it doesnt really work at all apparently

#

which seems kinda surprising to me

#

i'd think at some point someone could slap together some coherent receivers and do ToA or at least a handful of directionals in an array to use RSSI

#

but i cant seem to find any good examples of it for this

#

most people seem to be under the impression that the "noise" on those channels defeats this

#

but i'm looking specifically for a usecase where noise is not an issue, very few if any clients powered on in range

naive violet
#

Direction finding (DF), or radio direction finding (RDF), is the use of radio waves to determine the direction to a radio source. The source may be a cooperating radio transmitter or may be an inadvertant source, a naturally-occurring radio source, or an illicit or enemy system. Radio direction finding differs from radar in that only the directi...

#

That's what I'd go with, two channel

polar spoke
#

yeah, that's going to be tougher

autumn breach
polar spoke
#

i'm trying to keep this within the span of man portable or perhaps vehicle based

#

so my distance between antennas will be quite small

#

looks like there's very few commercial options

#

if any

#

even the defense oriented ones appear to be sub 2GHz most of the time

#

this one claims <2GHz with one model being "expandable" to 3.5

#

i'm wondering if it's just because of the hardware or if there's an RF reason why this gets so hard above 2

naive violet
#

So I've been reading about defense comms recently

#

For... reasons

polar spoke
#

of course

naive violet
#

(they released a nice pdf)

primal kestrel
naive violet
#

Battlefield comms tend to be much much lower, not a lot above L band most of the time

polar spoke
#

yeah, of course

naive violet
#

So not a lot of point DFing a beam that goes practically upwards

polar spoke
#

which is crazy to me because modern battlefield comms Do use channels up there

naive violet
#

The ew sections in that doc I tagged you with are worth a read

polar spoke
#

they just dont seem to be talked about a lot

#

hmm cant reply in thread

naive violet
#

Might ahve to join?

polar spoke
#

not sure tbh

#

but as far as modern battlefield comms go

#

there's quite a bit above L band now

boreal scarab
#

Hey James and chicken waveyboi

polar spoke
#

👋

naive violet
boreal scarab
#

How ya doing?

naive violet
#

So hard to DF something that you can't see

polar spoke
#

this P2P meshnet stuff

naive violet
polar spoke
#

man portable

#

for the crowd favorite, the MPU5

#

this is how you would run the network backing your ATAK

#

adhoc mesh, somewhat often in C band apparently

#

even the "poor man" designs for doing this without spending 30k$ for a radio are all 5ghz based

#

common way to achieve that seems to be a custom firmware for UBNT Rocket M5 nodes

#

give it a paint job and some antennas and you get away with a cheap alternative to an MPU5

boreal scarab
naive violet
#

Chipping away at the same old

mossy river
#

*Plugs in my computer*
Me: Haha imagine if it doesn’t start

My PC: dead

boreal scarab
mossy river
#

(Didn’t plug the power cable in)

boreal scarab
mossy river
#

It’s not my fault, all the cables behind the PC were plugged in 😭

#

The power cable wasn’t behind the PC 😂

devout palm
#

lul

polar spoke
#

they are quite popular these days

#

apparently

#

sweet

#

lol

sick lance
# polar spoke lol

Whilst you're here.

I've tried searching everywhre, do you know a hypervisor where I can use VT-x passthrough, Hyper-V and Virtualbox claim my CPU doesn't have VT-X, however I know I do, I can run android studio on my host and emulate a phone, I can't do it in Virtualbox/Hyper-V

polar spoke
#

is it enabled in bios?

sick lance
#

For some reason it VT-X won't work via a hypervisor, and I also checked if I can WSL the stuff I need, but seemingly it won't see the ADB.

sick lance
polar spoke
#

hmm

sick lance
#

And Android Studio uses it on my host for the emulation.

polar spoke
#

maybe it's not VT-x but something else?

#

like SR-IOV

#

and the error is being unhelpful?

sick lance
#

There is another error, I'll pull it up

#

Just need to boot it

polar spoke
#

ok

boreal scarab
#

You mean the HTC crypto phone? Lol

sick lance
boreal scarab
#

Introducing the Cryptophone, the next-generation device that combines the usability of the smartphone and the security of a crypto hardware wallet. The secure all-in-one device revolutionizes how we access Bitcoin and Web 3 - empowering you to buy, sell, send, receive, borrow and lend.

shut hawk
sick lance
#

But in the VM it's telling me I can't.

polar spoke
#

oh two layers of virtualization?

shut hawk
#

On vbox, in the settings -> system -> processor is the nested vt-x... enabled?

sick lance
naive violet
#

Greyed out is a bad sign IMO

sick lance
#

It's because it's booted on.

shut hawk
#

What's your CPU?

sick lance
#

Unlocks when it's turned off

#

11th Gen Intel(R) Core(TM) i7-1165G7

shut hawk
#

oh wait

#

do you have hyper-v and virtualbox both enabled?

lapis monolith
#

hello can anyone tell me for pcap challenegs can i access the machine to my ovpn kali vm ?

#

cause i m asked to use tryhackme machine only

#

which is is very laggy on browser

sick lance
#

No, Hyoer-V is disbaled.

north badger
#

Anyone here good with Assembly programming cause Im currently losing my sanity

wooden totem
north badger
wooden totem
lunar bone
#

Pwncat hasn’t been updated in years. Obviously still functional just wondered if there’s any alternative that’s maintained

north badger
sick lance
north badger
exotic vector
#

look look im light green !!!

devout palm
#

Nice!

lunar bone
lunar bone
sand trench
#

welp it is time for the sleepy sloopy to the beepity boopity for the meepoity moopeity

brave pilot
#

just hit lvl 3💪

#

😔

#

i'll do it now😔 🙏

#

there we gotipsfedora coolguy

#

thank you! I'm gonna be learning about packets and frames now💪 💪 coolguy

dusky bone
#

I thought this was an interesting site. I found it in the book I am studying. "Networking basics" an older book but still has some useful stuff in. All labs for networking.

tranquil lark
#

Finished the Cyver Security 101 path. Got 2/3 for all the big prizes maybe next time

forest forge
#

cool

eternal timber
#

Elo

sudden pond
#

WhiteRose done😄🙂

drowsy hollow
drowsy hollow
glass nest
#

Not with that attitude you won't. gotta be in it to win it, and theres no point in admitting failure befre you've tried your very best

brittle lynx
#

Hey guys
Does anyone know a bug bounty hunter or a web assessment specialist ?
I am trying to decide if I should focus on web hacking and master it instead of being average at all stuff

glass nest
#

We see a lot of young folk come in here thinking that Bug Bounty is their key to getting rich quick - This is rarely the case. The most logical plan would be to 'git gud' (as the kids say) before expecting any returns on bounties. That being said, Nothing stopping you from signing up and seeing how they are structured and what is expected etc.

brittle lynx
#

Or do employers not look for specifically web hackers ?

molten sky
#

you can find a job doing that, sure ---- it's not normally people's first job though

glass nest
#

Depends on the employer. However, remember, you want to make yourself a desirable person to work for them

#

Hey, Productivity 🙂

molten sky
#

many people internal transfer into it or move laterally into it from software or whatever non-dast 'else'

molten sky
eternal timber
#

Russian roulette?

drowsy hollow
glass nest
#

Have you learned anything from the rooms you did?

crude stump
glass nest
#

86% of stats are made up

drowsy hollow
eternal timber
glass nest
#

Well, if you learned anything, Then, in a way, you have won 😄

brave pilot
#

guys can you help me out please

chilly veldt
#

currently steaming all my clothes

brave pilot
#

am i allowed to ask for help?

eternal timber
#

I need to steam mine

crude stump
#

Of course

chilly veldt
#

of course

eternal timber
#

They’re all wrinkly

brave pilot
#

i'm stuck on a question but its not for school work or anything

#

just the course thing

drowsy hollow
glass nest
#

Nah, At the very least you'll be back for the Advent of Cyber event 😄

brave pilot
#

thank you🙏

drowsy hollow
brave pilot
#

sure

molten sky
#

immediate jail time

#

not even a trial

dusky bone
#

plus we cut ya noogies off!!

keen light
#

Does try hack me use guacamole to set up the clientless connection to the attack box

fair lava
#

Yes

#

So it allows them to access directly through browser

brave pilot
keen light
#

I’ve had that before at a friends very nice.

brave pilot
#

Nah i was just asking because my dumb self accidentally joined the mf hackthebox server instead of tryhackme discord at first so I accidentally made a hackthebox account

#

And in hackthebox rules oyu cant ask for help or smth idk i think i js read it wrong

clear jackal
brave pilot
clear jackal
brave pilot
#

Yupyup i got help hella fast

jovial reef
#

By the way, can I ask for help for retired CTFs on tryhackme that aren't public?

clear jackal
#

I'm going to assume no, but I'll ask a mod for determination

jovial reef
#

Ah ok, thanks :)

#

Because I have done the CyberFirst CTF and there's this one IoT module that confuses me lol

versed hinge
#

man im exhausted.. been doing rooms for the last 9 hours

jovial reef
#

At least you can access the rooms 😃

#

I haven't had access to any of the tryhackme rooms for like a week

#

It keeps saying "User not in room"

versed hinge
#

did you click the Join Room button

jovial reef
#

I can't do any rooms on the platform whatsoever

#

The rooms that I have tried don't require joining

versed hinge
#

clear your cachce/cookies/dns?

jovial reef
#

It was, yes

sick lance
#

Ah, probably not, as I don't know if THM wish to make it public.

jovial reef
#

ah ok

sudden pond
jovial reef
#

It was one for schools I believe

#

So it's probably a different one

#

It was hosted on THM just over a week ago

rapid merlin
#

Anyone ever got this error?

azure hill
#

Try run the program as administrator

#

I convinced a scammer to click a grabbify link and it pointed to Nigeria, I can't resolve the IP though does anyone have any advice what I can do with the information provided by grabify

mossy river
gentle rose
#

😮

azure hill
#

Ah I see, my apologies

#

So how do people like scambaiter etc make videos about these kinds of things if its illegal (I guess it would depend on what country you're in also(Note I'm refering to law not community rules, which I respect)

rapid merlin
#

I love being woken up by phone calls when I’ve already told someone not call but knock because I’ll be ✨asleep✨

clear jackal
#

Or, in some cases, done in conjunction with Law Enforcement

azure hill
#

Makes sense, damn

#

Still so many people irl getting scammed it's so sad to see

molten sky
azure hill
#

ikr..

clear jackal
azure hill
#

Then tell the users they're untrained

swift ice
#

or just don’t do it lol

#

unless your name is the FBI or CIA, then “hack back” is illegal

azure hill
#

depends on your countries laws I guess

swift ice
#

tell the NSA that coolguy

clear jackal
keen light
clear jackal
#

Offensive cyber operations are technically acts of war

keen light
#

But I wouldn’t recommend it

swift ice
#

sure sure, I truly believe the FBI is doing what they say they’re doing /s

chilly veldt
#

it's also illegal for them 😄

clear jackal
#

If you have evidence that they are stepping out of bounds, you can report it to the multitude of watchdog agencies or the Office of the Inspector General as a whistleblower

azure hill
#

I'm reporting to the only relevant authority in my jurisdiction

#

I imagine lots will get done >.>

keen light
#

Yeah Governments do lie, but mostly when trying to protect citizens and operatives apart from some clear (historical cases) that are evidently wrong.

#

History is messy

azure hill
#

So how about all that nonesense from 'CIA' officials about how hackers have the green light against ISIS.. Is that BS also?

#

'proposed' US military operation

#

nothing official yet

#

wait I read further

#

I just realised all we can do as hackers 'legally' is educate other people to educate other people until we're employed anyway

#

hacking = pyramid scheme perhaps lol

#

depression is real

keen light
#

True could develop tools though maybe a RustMap or RustJohn

#

Farm those GitHub stars

dusk tangle
#

The DoJ in the US said that they won't charge you anymore for attacking stuff if they can't prove you weren't doing it in good faith security research

#

but I mean that's risky so

#

prolly don't

keen light
#

Although most stuff is like that, you can become a mathematician and then do math in your room but you won’t make any money unless your employed, but teaching will earn you internet “respect” and maybe some money if you have a donation scheme or are employed to teach (content creator). And as long as you know something that someone else doesn’t no matter how simple you can teach(as long as it’s correct :))

rapid merlin
#

Do u guys use docker or vm?

keen light
#

But for what specifically

molten sky
rapid merlin
#

Im having problems with kali bc it's always breaking, stuffy24 told me to use docker to spin it up and down real quick. Idk what it means

molten sky
keen light
#

“hello I’m from the government and I’m here to help”

dusk tangle
#

who here plays D&D

rapid merlin
#

Like my main problem is that I spend so much fucking time downloading new Kali images bc it's always fucking breaking

molten sky
keen light
#

I just use it on my system live

dusk tangle
#

we should have a THM D&D campaign

keen light
#

Burn the USB 🔥

molten sky
rapid merlin
molten sky
#

would need more details. hypervisor, host, resource usage + allocation, error messages.....

wild rose
rapid merlin
#

And then the problem is usually solved

#

But it takes so much fucking time

#

Idk why he recommended docker for this

molten sky
#

that um -- that both answers little and raises more

#

you shouldn't have to redownload any new isos, the disk image remains unchanged

#

also can't say why things are breaking without knowing what's breaking or what's being done leading up to 🤷‍♂️
but when it does break, you should be able to rebuild with the same iso. but when it does break x2, you should be using snapshots to avoid needing a rebuild in the first place

#

well, assuming your hypervisor supports snapshots

rapid merlin
molten sky
rapid merlin
molten sky
#

pretty much

#

a snapshot in time

rapid merlin
#

Mh nice

#

I can use that just after downloading Kali image

#

So it's always fresh

#

I'll try now thx

molten sky
#

I typically take three snapshots on a new build --- one immediately after install ('genesis'), one immediately after updating ('updated to...'), and one with the base required tweaks for my normal use ('with tweaks' + a desc)

#

(overboard for most, useful for myself)

crude stump
# clear jackal Offensive cyber operations are technically acts of war

But that depends on the severity of the operation no? Like if a nation states starts causing power plant meltdowns that’s when it’s a act of war, but large scale spying via cybersecurity attacks happens all the time and nothing is really said about tensions rising because of spying. Or is the reason for that because it’s hard to pinpoint exactly where that attack is coming from. What’s your opinion on that

molten sky
#

i'm free ! finally cleared my github notifications
pages and pages of hacktoberfest spam PRs and issues

rapid merlin
#

I don't think my laptop supports snapshots @molten sky

#

I'm not seeing anything that I see in the tutorials

#

Like I have much fewer options

molten sky
#

your hardware shouldn't make a difference, it depends on the hypervisor

#

i.e. vmware vbox hyperv qemu etc

keen light
#

Do you do bugBounty/Ctfs while listening to music

tepid furnace
#

of course

keen light
#

What genre.?

#

Or just whatever?

pearl kindle
#

Hihi

boreal scarab
#

$130 for the setup I want for monitoring both my main and my VLANed network.....

#

Reee

pearl kindle
#

damn

molten sky
#

woah

#

OSCP is removing bonus points

#

interesting

#

and we're getting an expiring oscp+ alongside now as well --- 8570.01 compliance incoming?

molten sky
pearl kindle
#

maybe oscp+ but oscp stays indefinite right

wild rose
#

right

molten sky
#

yeah you earn both

pearl kindle
#

perf

molten sky
#

my guess is they want to become compliant with 8570 for the sake of getting that clearance moneys but also let people keep earning lifetime certs

pearl kindle
#

prob

molten sky
#

i wonder how long til they do the same thing for their other certs

#

can't imagine them stopping with the one

pearl kindle
#

let's see

molten sky
#

looks like 140 CPE credits over three years to maintain, with $135 AMF

pearl kindle
#

wah

molten sky
#

so 140 edu credits and $405 every 3 years to maintain

pearl kindle
#

that's why i love thm

swift ice
#

wait until you find out OffSec got bought by a private equity firm a few weeks ago

molten sky
swift ice
molten sky
#

oh my

#

PE is the death of all things

pearl kindle
#

offsec is the new take-two

#

rip

molten sky
#

i wonder if the two changes are related to one or the other

swift ice
#

it’s most definitely a push to be on the 8570 list as many have already predicted

molten sky
#

lmfao wait why are oscp certs "Blockchain Secured"

rapid merlin
#

no idea

molten sky
#

looking at someone's profile and noticed that their oscp cert has a Blockchain ID number alongside

pearl kindle
rapid merlin
#

been here for days, but ty

molten sky
#

the "Blockchain Record" was created 3 years after the cert was issued as well. huh.

pearl kindle
#

i don't believe it's related

rapid merlin
#

^

#

probably some way of verifying who they are, 0 clue

molten sky
#

wish i could compare but i don't care enough to see another person's profile

#

Accredible for those who are familiar

pearl kindle
#

ya

#

oh yeah i forgot to say, i said days earlier that i had a potential job for devsecops, i refused the offer 😦

molten sky
#

should've sent em my way lol

versed hinge
#

awe yeeeah, hacker in 4 days

pearl kindle
#

i will keep being a devops engineer for now i guess

#

but i really want to be a devsecops

boreal scarab
#

Canceled that order... back to squire 1 cause AIO I was going to use isn't powerful enough... fuck

wind mantle
#

I created a video on YouTube about the new Cyber Security 101 learning path. And I sent an email 7 days ago to get the 5 Extra Tickets! But no answer yet . What should I do?

clear jackal
#

It's 8140 now, I haven't seen OffSec mentioned yet

molten sky
#

eh i keep hearing that but it's still all i see
is it finally official?

clear jackal
#

8570 has been deprecated officially for a few? Maybe 1 year(s)

molten sky
#

is the cert matrix the same? i'm getting a very similar result for that part of it

#

seeing a weird new qual matrix tho

clear jackal
#

Cert matrix doesn't really exist anymore, afaik

molten sky
#

hm

#

All of the DoD 8570 certifications did carry over to the DoD 8140 Cyber Workforce Qualification Program, and they were aligned to the appropriate DCWF Work Role and DoD 8140 proficiency level.
well that's worth something I suppose

clear jackal
#

I'm not really dealing with that stuff anymore day in and day out, so my info on the new stuff is going to be a little skewed

#

It's been a mess though

molten sky
#

i just remember "it's gonna be deprecated for real this time" about 73 times

#

delays and delays

#

never read much into it beyond that

#

might read up now that it's a real (and in effect) thing

clear jackal
#

It was deprecated for real within the last 4 years

#

I can't remember specifically, time is mushing together for me

molten sky
#

i wouldn't doubt it --- I haven't followed too closely. haven't had a need 🤷‍♂️

clear jackal
#

I know it was deprecated because it had a direct impact on my life lol

vestal phoenix
#

I'm re-watching Mr. Robot. time really does fly.

crude terrace
#

hi everyone, i am unable to to solve this question "When was the twitter.com record created? Provide the answer in YYYY-MM-DD format." even though i write the correct answer "2000–01–21". i am getting incorrect answer popup

#

can anyone help me

vestal phoenix
crude terrace
#

here

#

shot*

#

but this question is part of "Networking Core Protocols" part 3

molten sky
#

well that was tasty

#

don't really have food but i found some still-good cream cheese i forgot we had and tortillas, so i made a couple cinnamon roll up things

rapid merlin
#

Is it easier getting a job in networking than in cybersecurity?

molten sky
#

probably, but lacks details

#

lvl 1 soc guy and new networking guy are probably similar

#

not equal but close

lunar bone
#
 The tool is made by someone that does not read the nmap man page. The tool just try to connect to the 65K ports in big batches. This approach will give you tons of false negatives and firewalls will block you instantly (or just fake the exposed ports).

But the worse thing is... that you can do exactly the same thing with nmap. The params by default in RustScan are 4500 connections at same time and 15000 ms. If you set the same in nmap...:

nmap --min-rate 4500 --max-rtt-timeout 1500ms scanme.nmap.org -p- 
#

I just read this about rustscan :\

#

not only is this correct from my benchmarking nmap with those flags is faster

keen light
#

Buts it’s Rust

#

That makes it automatically better

lunar bone
#

and it has lolcat

#

by default

keen light
#

Tmux 4 way split with cmatrix vim and gtop arch desktop rustcan and coding socks

#

I hate rainbows and lolcat

#

I also hate RGB

#

I haven’t looked into rustscan , is it just nmap but rust.

lunar bone
#

yeah tryhackme recommened it for koth

#

to scan faster

#

was a troll

#

any of the crazy fast stuff like masscan (that's actually fast) give hit or miss results just because of the speed

keen light
#

So basically just nmap ported to rust

lunar bone
#

yep

#

and THM boxes can't respond fast enough for it to make any meaningful difference from what i'm seeing

keen light
#

Soon rust will assimilate the Linux kernal.

lunar bone
#

rust is bad

#

overly complex

keen light
#

I like it, but that’s just me C is very nice tho

lunar bone
#

worst of c and higher level languages combined

#

c is good because it's old

keen light
#

What language do you like.

lunar bone
#

go

keen light
#

I like c because it is so basic to understand but then gives you infinite freedom after that

lunar bone
#

@daring arrow

keen light
#

Go is good I’m probably gonna learn it next

lunar bone
#

but for the most part its super fun

keen light
#

nil

lunar bone
#

nah thats not that weird

keen light
#

What’s the worst bit

lunar bone
#

tabs is

#

it wants tabs

keen light
#

In rust it’s anything Async

lunar bone
#

is anyone else seeing starts in expired for koth

#

what happened

#

nvm

#

blud how does drew already have a flag and I can't connect to the box

lunar bone
#

someone really disabled ssh during koth

#

how fun

#

and no ones resetting it except me 💀

wraith fjord
#

howdy

lunar bone
#

hi

rapid merlin
#

did Russia actually fine Google for $20,000,000,000,000,000,000,000,000,000,000,000 ?

lunar bone
#

yes

#

it has the same meaning as me saying im fining u 2 gajillion $

rapid merlin
#

crazy

lunar bone
#

kernel modules are hard 😦

#

apparently the version i'm running of kali kernel headers just aren't easy to find

#

and wsl uses weird kernel

stray tapir
#

Hello

versed hinge
lunar bone
#

Custom weird kernel

static coyote
#

hi friends

arctic cradle
#

puny money

crude terrace
#

anyone interested to train together

terse edge
#

quick question, what if i run out of rooms to complete and still haven't gotten a complete ticket? (free user) for trywinme

sick lance
olive owl
#

Amazing

terse edge
#

alright, thanks

exotic vector
#

hiya everyone

sick lance
#

👋

#

It's a wet day for some OCR training, which means the fields will be bogging!

exotic vector
compact quest
#

Hello

exotic vector
wraith fjord
#

Me after having unhealthy amount of sweets

compact quest
#

I'm new here

#

Happy Halloween

exotic vector
compact quest
#

thx

sick lance
glass nest
#

I see OCR and I think optical character recognition, but realise.. that can be right if you are talking about boggy fields.

polar wraith
#

is it possible to get the cyber crusader rank removed from my profile

#

not that i want to

#

just curious

neon merlin
#

It goes when the event ends

polar wraith
#

its permanent lol

neon merlin
#

I'm sure it was said in here that it would go away when the event ended before

#

Also:
"How long do I keep the Cyber Crusader level?

When the ticket promotion is over (4th November), your 'Cyber Crusader' title will disappear and your level will be recalculated."

exotic vector
#

@stark gust I changed my notetaking regime a little. And its working out better for now.

exotic needle
#

Does anybody know how to stop rsyslog daemon process in linux

exotic needle
#

It didn't work 🙂

sick lance
polar wraith
#

that sucks

exotic needle
#

Stopping rsyslog.service but its triggering units are still avtive
Syslog.socket

exotic vector
#

im using joplin, so I have nestled folders for learning paths so each learning path folder has another folder for the main topics where notes for those topics are and a lab task folder.

I started to do my note write ups once I have done with doing rooms for the day, or done the next morning.

I still have to transfer my notes to joplin though but gonna do that when I have a little more time, so probably sunday night lol

sick lance
exotic needle
#

Just don't want to make my system activity logs

sick lance
#

Make it what, sorry?

exotic needle
sick lance
exotic vector
#

yeah no not gonna do that xD
I done it this way with joplin because it syncs to my phone and uses markdown.

#

it is, its so quick to just put a code snippet or create headers or make a page wide line to seperate sections up.

sick lance
#

Is there a reason you want to stop the logs?