#general
1 messages · Page 525 of 1
Don't forget product placement
I'm skid, so I'm more like - You see what I can do with burpsuite when capturing packets 
That's your opinion, don't know who would watch grown ass man pushing 50 who is oversimplifying network concepts to those people who aren't prepared for real world applications
I'm talking about Bombal
I mean, I don't really understand so deeply to be confident to say that I'm good at anything.
But I'm not so terrible that I wouldn't understand the whole fundamentals
Sure a guy that's focusing on promoting his own products that he overshadows on his "educational" content he provides is much more better, you know what's his priority then
Let's be real
good morning
You're funny
Alright go watch a grown man in his 50's now, that can't focus on anything else besides his Cisco certifications, you think people won't look for more diverse or vendor neutral knowledge besides that, maybe when he starts reflecting to on job challenges maybe I even peek at his channel sometime
my gf is really into K-drams too. Some are pretty good.
not bad, just having a mental off day. How are you?
I watched one that gave me whiplash.
It was a horror, police detective, and romance show all in one
trying to work with 1.5 hands sucks. work is 10 times slower.
exclude the horror then its good
oh same here
She's really into comedies and romance dramas.
oh owie thats not fun, glad you're starting to feel better, at least a little.
Can’t stop won’t stop
yeah I bet
lol my gf says the same thing that she's going to leave me for some k-pop artist or actor. lol ;_;
Everything seems to be so pretty from the humans to the landscape.
And I loveeee the food
Is the result announced?
I did 1 room today.
last night I was helping a friend remotely with a home server so I was up quite late. I'm currently on cryptography
No, they haven't told me I've won yet.
Ergh that’s how I feel about London !!
How can anyone can like it
I don’t even know
Did you get defcon33
No, only 2/3.
I have lived here my entire life
think you mean foggy and rainy
Trying to have a outlook that everything has it's own beauty is challenging sometimes.
I like the rain, it’s the bricks I don’t like
maybe you've gotten fed up of the same environment then 😂
It’s the grey and no plants
Not enough green
More green in my flat then there is on my entire road
come and see all the green of the northern parts of sweden
first time playing tech support as well lol
yeah im doing the new path rooms, I did the basics this morning but was feeling too bleh to do the next but I'll probably get to it some point this evening.
I know 🥺I wanna go there
yooo sup
I would be zero depressy if I lived in Iceland
it's funny how iceland is more green than greenland.
it is called seasonal depression or vitamine D defiency
Ofc you could
yeah was kinda blindsided with the maths of cryptography basics, I couldnt find my scientific calculator so I had to do the questions on my phones calculator lol
I take vitamin d because I have a big vitamin d deficiency
working nightshift can do that to you.
Shadow, do you have periods without sun? Or just really short days?
depends on when you ask
and also if shadow wanna answer how north or south shadow is in sweden
I'm not probing, no need to answer 🙂
Sometimes I though about running away to the top of Norway where’s it’s cold and no humans
IKEA is the land of mazes and make-believe words.
Anyone have any updates about defcon33 tickets?
I've sent mail and there isn't any response from them yet
correct as we account for less then 1% of the world population so we are inside the margin of error
Never considered that aspect.
I don't think we get it
So many people won that chance I don't know what they will do about it
too many people matched 3 deathcon33 tickets?
Yes
We have no data on that, only speculation.
More then 10 people got it
what is this based on?
Unless I've missed an announcement.
On reddit I've seen almost 10 have matched
dunno if I would trust random postings on reddit
I don't believe reddit, or anything else on the internet.
All rise for President @silver sky !
But I do not work for tryhackme, nor do I have any evidence to suggest you are wrong.
We've all done the same
I thought it was automatic. ie once you redeemed the tickets on your profile, THM was notified
They will be investigating all winners to make sure they haven't cheated
What cheating can we do on tickets bro
Hey guys
I could understand if it was emailing to arrange delivery, get more info. but the basics of informing them that someone (and who that was) redeemed 3 should be auto.
Copy and pasting answers
hello folks
for reference, this is why I wouldn't trust anything posted on reddit. this took a couple of minutes messing around with "inspect"
could probably figure out the redeemed banner given another 5
I am on linux
Just copy paste from a different place
I speedrun through most of the 101 content, since it was easy cuz I thought the event ended Friday night.
evening thm
Pure html
yh, just delete/duplicate elements
I don't trust anything on reddit regardless
It's my number one source of news! /s
Reddit was a rabbit hole for me to waste days searching.
So the reddit page I've seen is fake then
Hey I just wanted to add something. I am a little nervous about the stuff I read on reddit too. I have also won the defcon ticket, you can see it on my tryhackme profile for proof. Not sure how valid the other people are but I've found another that looks legit (on their tryhackme) profile.
¯_(ツ)_/¯
I could be. I could be real. the problem is we have no way to tell
Same I've also won that bro
not only that you also put "reddit" when you know the results you're getting are not what you're looking for lol
Stackoverflow is my google for scripting.
Me after reading 5 stack overflow pages
Lowkey reddit is usefull in some situations
probably
I should actually update stack overflow questions, I have found some solutions to things that aren't documented
Oh well, you live long enough to become the villain
I have found solutions to deprecated stuff in android
Which is so niche that only some people use it or hasn't documented it
there are no villains in a world full of monsters
That's why I drink monster
there we go. one FAKE redemption screenshot.
All of them
Another problem I've seen is that I can't be able to redeem the swags in the swags store the codes they've given are invalid
As long as there's caffeine
i completed rooms with full dedication even 2 days before event got over but i got only 7 days streak
I managed to perfectly balance my pillow on it's thin edge on top of my toes just now
or "edit: I solved it" and thats it lol
Cool!
some of the prizes were limited in number. just the luck of the draw (I only got cyber crusader, 1 day and 7 day freezes)
still, was fun and learned some new stuff, reinforced existing knowledge
people reseted rooms for multiple times and copy paste answers from medium and they got prizes
Should I post my achievement (defcon33 and path completion) on LinkedIn?
i got a baseball cap and 1 premium month 🙌
bad luck 🥲
I got a mcdonald combo
path completion mayb.
defcon not so much (just luck of the draw)
It’s a sad day to see the “Go Premium”
there are a lot of mcdonald's
Then I'll just wait for the official confirmation
Just came across this
Not quite
LOL
In Japan koi can live in the drainage canals
Apparently
you can be more confident, it is true
I mean I just wouldn't consider linkedin to be the place for the defcon prize. completing the path shows skills, and thats the whole point of linkedin, showcasing skills.
winning the grand prize in a raffle isn't the same kind of achievement.
👍
In England we don’t have a lot of rat but we have Mickey Mouse’s
Mickey Mouse’s everywhere
Mickey Mice
In every block of flat
there's loads of rats around in England.
Whenever I see one I shout Mickey Mouse
I remember my cat caught a mouse and my niece picked it up and said look mama Mickey Mouse.
I shout "oh boy, dinner"
Wut 😂
real life mice look nothing like the friendly well known cartoon drawing by the name of Mickey Mouse by Disney
I’ve seen two mice having a fight in front of me. It went on for so long I started throwing down bets
They didn’t even care I was there
My cousin screamed so loud that the cops where called to my apt.
stuart little vs ratatouille
love ratatouille. such a wholesome film
i worry about this whenever i watch a movie on the surround speakers
I really like Stuart little when I was a kid
we're gotten into trouble a few times cuz Ashton brought live birds and mice into the building.
I love birds
He goes nuts over birds for some reason than mice. He'll chase birds all day, but will kill mice like they were nothing.
It's hard to type and not fat finger with a cast on, plus not double check your work.
Why is brisket so fucking expensive?
@silver sky over here... 2 lbs for 10 pounds. 1 lb here, for $60 from a bbq place...
fancy cut of mea
Hmmm, should I
A. Just write more shitty code on top of the current codebase, make everything work and get tested to publish
B. Refactor the entire codebase and then get it tested after I write the last things
C. Do A and then refactor the code after release
Are you over here ?
A lot of meats are expensive here
@iron grove its gonna take me awhile to get through cryptography it seems T_T lol
Still in USA
Should I go vote early today or go out and get a haircut?
@sick lance Found my new fort!
I'm allotted a 2hr break from work to vote.
argh, so much blue light
but notice they don't say. Matt broke it again

Is the site working for you now? I see blank pages no matters what I try to open
In try hack does room expires like I have seen few times by now that my number of rooms decreases automatically why ?
working for me, what rooms are you trying to visit?
;M; steam workshop page no worky for shadow
shadow is making mods?
no.... trying to install mods and look at shadows collections and subbed items
the dropdowns don't work by clicking on them and it is a known bug and has been unfixed/problematic for a long time
Rooms you're currently in stay in your "My rooms"
well last time shadow checked there for rooms made private they were no in the list
oh..... seems like that got changed or reverted
good old the find command room
shadows beloved lost room of the ages
@pallid lotus If you haven't had fried avocados before, man.... 10/10, it was SOOOOO good!
Now for my burrito with steak and chicken.... after I pinged Muiri lmao
beerrise the heretic

With rice, lettuce, steak, and chicken
perhaps not the lettuce
who won? 😂
the rat
there were mice 😛 😂
one was a rat pretending to be a mouse
You can’t tell when rodents fight they just turn into a ball of fury
Who’s who I dunno
That wasn’t a rat that was two mice in a trench coat
Y'all need to listen to this man's voice https://youtu.be/IN2XA26-ay4?si=b4bnQ9MgTrdSaaW9
Provided to YouTube by DistroKid
I Wanna Be Like You (The Monkey Song) · Sid Bader
I Wanna Be Like You (The Monkey Song)
℗ Sid Bader
Released on: 2024-03-01
Auto-generated by YouTube.
two mice in a trench coat, sound like the title of a children's book 😂
im now getting frustrated with my self over this, gonna take a break then ask for help lol
Take a break, have a coffee, or a drink and come back refresh 🙂
Totally a real life story
tonight two mice in a trench coat, you can't miss it, fun for the whole family 😂 😛
One’s on the bottom, strong is he
Two’s in the middle, carrying Three
Three’s pretending not to be
THREE KOBOLDS IN A TRENCH COAT
One’s on the bottom, fiddling free
Two’s in the middle keeping the beat
I’m pretending not to be
THREE KOBOLDS IN A TRENCH COAT
😭
go to play satisfactory
oh, a patch
oh no, a patch
yh, mods broken
now not playing satisfactory
This is probably my magnum opus. But it wouldn't be nearly as great without the incredibly talented animator Rebecca Snowden (@rebexquest), they brought these adorable kobolds to life in a way I could have only dreamed of. Find their links below!
Listen on Spotify: https://open.spotify.com/album/1s6FKfbNTlX5ACaDBcwUPG?si=RAM56yXIRwySEUjiybgYOQ
...
omg the situation I just had 

hiya
how is everyone doing?
well just figured out the part I was stuck on, so pretty good xD
@iron grove figured out the part I was stuck on lol

noice! noice!
uhh guys do u have any 1 to change 20 swag code with a basebal cap code
Can anyone help me, I'm having trouble finding the answer to this question. What is the range of a section (octet) of a subnet mask?
Is this THM content? If so, #room-help is the best place to receive assistance
pretty sure tickets are non-transferable/tradable.
I didnt, decided to do the calculations on paper lmao
Again?
its happening where I am as well
why today? tomorrow is the big gunpowder day
here its because of particular groups of chavs
my sympathies
my friend claims to have just gotten an xss attack through steam dms 😬
Hi , new here, probably this is not the right channel to post this but as newbie i don't have a clue so i misuse this channel, excuse me : following the cyber security 101 , you could win prizes by gaining tickets which i did; received mail for a 20 pound discount on any order. So i immediately tried to order a nice T shirt ! on checkout however i receive illegal discount code !!!!!! ???????? did i do something wrong ? who can help me ? thx !
did you copy the discount code from the email without spaces?
@urban pelican
ok thx, i'll send a email
i know the answers is Ctrl+Alt+Delete Task manager but how do they want the answer
||that is not the answer||
Thats not the answer and #room-help not general for room help
the format is right though (key+key+key)
Well I linked it for you
hi thms official w i d e boi
i have another friend who also claims it happened to him
I'm also calling doubt until I see a working POC
or evidence
doesn't really seem like you can do anything about it anyway, other than report to steam.
as I recall from the screenshots, you just get a DM and at that point, you are boned; they are already in and have your account.
Nah
It's a standard phishing attack
Anybody know reverse engineering, im trying to learn that along with I.T/Cybersecurity?
https://dontasktoask.com/
Thanks
😄
You can actually get your account back by providing receipts to steam support.
If you activated CD keys, you can also provide the keys as proof
It might be one of the fake steam link that looks like a window on your PC
Potentially, just clearing any zero-click or XSS account takeover concerns.
the poc in that hackerone report requires a click
i don’t think it’s the same attack it is just reminiscent to me
i have two friends claiming to have been hit by steam dms that close their game and make account changes but it’s hard to prove because they’re not tech savvy
might be lying about being phished to save face
or not realising they have been phished until bad things start happening
i think that is the most likely, but what's with the DM?
it might've been a "you've been hacked give us 200" dm lol
hacker adding their own friend and sending dm back and forth for confirmation ¯_(ツ)_/¯
good point
Good afternoon my fellow script kiddies 
hello hello
Is this a good server to help a friend get their instagram account back with?
ok
anything else is illegal
CompTIA is being acquired by private equity/investment firms 
https://www.prnewswire.com/news-releases/hig-capital-and-thoma-bravo-to-acquire-comptia-brand-and-products-302294943.html
Oh no
Prices are gonna go brrr
my certs 
I didn't do much today but I did get myself through the cryptographic maths and I feel proud about that xD
@rapid merlin is that you?
Y'all send a box
Uhhh and I was thinking of getting my CASP+ just to renew my certs, but never mind then.
hey who would like to practice nc?
I'll just send messages don't worry
I just have nothing to practice with
I’m out of the house, my neighbour took me 😂
Took you as in kidnapped?
I agreed to tea but I never know how to leave. It’s been four hours
You can use your own machine!
just have two terminals up, one as the listener and the other as the client
Oh no
I just wanna talk with real person. :(
You say "oh look at the time." or whatever you say in British.
Like the South say "Bless your heart", but what they really mean is something else.
Top of the morning to you my fellow lads and lasses
Would you like a cup tea dear Benjamin
🇬🇧🇬🇧🇬🇧🇬🇧🇬🇧
btw r u from San Francisco?
naw im briish
You've got plenty here (...mostly)
but here government can read our messages.
how did u know
bird said.
this one ?
Make an excuse like say welp this was fun but I need to deal with my child’s _insert excuse
welp time to hit the head on the pillow and go honk mi mi mi
just saw a video about how youtube bots will post random names and words in comments to try and mine data. so crazy. scammers, spammers, and lowlifes will really think of every way under the sun to ruin the internet
link but i’d be very surprised this didn’t show up on everyone’s algo https://youtu.be/IDAWbzQFqqk?si=M1ZBqB2p2qUKguCa
YouTubers may inadvertently dox themselves if they put their real full name in YT's "Blocked Words". This is why we can't have nice things.
Anyone handy with converting a reverse shell into a fully interactive shell? I can't work out how it's supposed to work
I've got a dumb shell on a box I'm attacking by uploading and running a .php file for a shell. But I want to ideally run Linpeas on the server so I need a full shell
that sounds wild.
I'm not sure but probably yes and it bits hurt.
Is it TryHackMe content? If so, #room-help is the best place to receive assistance
I watched the video and its an....inventive way of using bots
I would assume the bots are doing that to gather information to either scam or to get credentials to get into the account. Theres probably other uses but those are from the top of my tired head lol
Hi...
hiya
in the video they said that there was 2 bots they found in their comments where they commented with 2 sets of names to match them up.
Ah yeah I saw that being mentioned. Another one to my list to do research on
an oracle attack sounds mythical 😂
Yeah makes me think of a wizard with an orb
Quite sophisticated with employing strange phrases to seem genuine, it's a bit more extensive than people really think
Too bad youtube isn't doing any combat
I see it from time to time but never thought much of it because you know YouTube comments but learning about it made me think "oh wait that's actually a good cover"
The trust exploit technique isn't that hard to learn, i'm actually more worried about Tiktok and Instagram
how do you even begin to count something like this?
I know for sure that Tiktok's algorithm amplifies fradulent content, especially considering the age, it's rare to discern trustworthy accounts
Disappointing but couple of flashy visuals and catchy phrases can mislead people very easily, and their thirst and potential for quick wealth won't help
Yeah for sure
Hey all, I'm slar how's it going?
howdy slar
It's going alright, you?
it's going, just hanging out trying to figure out what to eat tonight haha
i dont think only tiktok does this , youtube ig they all on the same set
Fair, I had leftovers for dinner
So what is up with this tiktok thing? I watched the video. Is it bad actors trying to find the name of the person of the channel or something more?
err youtube* sorry
It's incredibly easy on Tiktok, trust me, Youtube combines those automated systems with human moderators so they can work swiftly
That's really interesting/pretty concerning
Just that robust moderation allows quicker identification, and with some extensive privacy settings and with less e commerce integrated into someone's experience is proof that Youtube is a lot more defensive
Unlike Tiktok's scrutiny over practices
i dont see what u tryna say , but i guess u are claiming tiktok authentification is less secure ?
Yes
how do u know , any Poc ?
I just told you above
Yall I just got told about a project at 7am, got the details at 1pm, worked on a proposal until 11pm, the guy i was supposed to sent it to is asleep and two other people are telling me it’s great but also it’s mid but also great and now Im going insane
I feel like tiktok was built for the sole purpose of knowing who is behind the account
Send*
authetification vulnerabilities are critical
what auth vulns does tiktok have over youtube?
if u are sure about what u claiming then u can contact their company , that is if they offer any bounty programs
Javascript interfaces
man, if only a ton of major companies running bug bounty programs agreed with that
lol
they do, and they pay welll also
facebook , instagram especially
lol
Are we talking about auth or exposing accounts?
Because I bet both companies have strong auth but one may be lax on the exposure
as far as i can tell, no one has mentioned any exploits at all, especially not auth related
the original topic was about bots datamining by posting comments to see which words get blocked
They're handling authentication tokens insecurely and potential exploitations through JS interfaces let's just say, the app's design emphasizes the engagement where they can overshare their information, of course they are more vulnerable then
JS is client side and auth tokens are server side so what's the exploit?
i dont see how the handling of tokens and the app's design around engagement emphasis have anything to do with eachother
I'm curious what you mean by them handling auth tokens insecurely
all media apps are designed to drive engagement, that's kinda the whole point....
They can bypass deeplink verification XDD, only by loading untrusted content in this webview they can exploit interfaces to execute Java methods within app, essentially gaining their access
😐
did u actually try this or u are telling a tale
I can go try it if you want, I actually need to waste my time better
oh hell na homie i dont want , YOU want 💀
I don't really want to get into politics, but when you vilify another nation, state, or race. It's easier for the people to keep you in power when you make shit choices.
That's all I'm willing to discuss on that topic as I'm sure it would be heavily moderated.
I was about to go rest actually, but whatever suits you
true dat
there are a lot of political things people to need to be aware of , but u cant cover all , we would literally fill a bible
speaking of politics and nations , pray for spain they are drowning ...
Very true, and there are too many opinions, many of which people hold tightly. So it's best to not discuss it on a platform like this.
I saw some footage from the main cities it looked awful
ye better keep it cyber , every thing has its own place
@fair lava very interesting I guess if you pushed code through push or deep links you could execute it. Never thought of that before
push notifications*
Yo yo yo it’s ya BOI pigeon
Any raspberry pi owner, how much gb should a sd card be being a raspberry pi zero
I mean stealth ehem
I have no idea
The only raspberry pie I get is in my belleh
pretty much anything should work fine. If you're planning on storing large files then get the appropriate sized one.
Yeah I’m not. I’m thinking of doing projects like pi hole, a ids/ips etc
just get that has class 10 rated card . The cheaper ones might hurt IOPS a lot more
Thanks Volta
Gave +1 Rep to @south sonnet (current: #339 - 16)
I haven't looked at SD cards in a long time. The Last I remember getting it was for my camera and it still works great.
apparently there is a new standard which is faster (SDXC UHS-I) So I would get those now. 32 and 64GB cards from sandisk seem to be very close in price too.
In your opinion is a card preloaded with noobs better then just installing noobs on a blank sd card
blank + rpi imager
gonna do my best to finish this week cyber 101 
was so busy, that I couldn't really do it
might boost me to top 5-6%
Nice, let's hope so!
if not, gonna do soc :3
kinda what I did
and 101 is at like 58%
You did all that and you are still not in the 5%? Weird
top 7%
I lost track of where I'm at, been 1% for a while now.
I think probably because of influx of new people and more activity overall, it's much different than from years back what I think.
Yeah
Getting to higher top gonna be harder after like 1-2 years
Honestly I stop caring about rank
Yeah, it's all about skill. I feel, like I would need to redo tons of stuff
Well not even that
Some people just try to get to the top without actually learning in depth
I kinda try to do that, but I realize I spend like 3 hours on a room that was supposed to be 60mins 😄
There’s nothing bad about that
Taking your time and actually getting good at something is way more valuable then someone who speed runs stuff
This.
Give a quiz to a speed runner and a slow learner see who does better
It's important, you can't remember everything.
Something will only make sense when you look back over your notes.
i guess comptia just got bought out
Plus idk about you but when I make notes it helps me because I’m actually typing out the stuff. Sort of like how when you write in your notes you remember better
~ and nothing of value was lost ~ /s
I think for me kinda habit probably wanting to know everything by memory
which is quite insane
but also my downfall
I kinda need to learn properly, even when I have understanding kinda
any advice on best rooms to prepare for security+ certificate?
Recommend you use the Security+ syllabus and Professor Messer's YouTube videos
Thanks!
Gave +1 Rep to @clear jackal (current: #17 - 470)
hey im new here
Just finieshed vyber 101 really good room is it worth it to post the certificate on my lnked in
i asked that, i was told no
whats the reason if u dont mind
also can someone tell me if the security engineer path is a good path to go on
any insight
You can if you want as a post. It's not a certification, so it wouldn't go in that section. It's also not experience.
okay noted i ask bcuz ive seen ppl do it b4
im just tryna figure stuff out for a solid career path b4 i graduate
it's always like this
😔 🤌
like I can make tasty food, but it never looks good in photos
because my presentation skills are zero
🤌
Also.... TIL there's a town in the UK called "Wetwang"
Lighting is a huge factor in the presentation of meat...
I'm leaving that one open ended as it's PG13...
All I know it tastes good
@boreal scarab go to bed already
Gotta eat lettuce
You are not slick 🤣
I like my meat red

zumiii zumiiiiii
any fix in AD Enumeration room cant finish redteaming path because of that broken network lol
killua pfp based
i sent in red-teaming-path room
screenshots looks like im not the one who have same probs
zumi how many accounts do you have
no its not a part of the challenge i already watched yt videos of some guys that's what they did before going to the whole walkthrough
How to remove cyber crusader
u need to decrease me there
you have to advance to cyber pope
stuff and things
So rank up
For some reason, my Python script isn't correctly reading the data file. Any ideas?
and post the code too
sorry
all good mate
Code is over 800 lines, i doubt anyone wants to read over that much
USB-C ?
He's looking for a female to female type, or a nale to male type USB
Post the relevant code or a link to its Github repository
The issue you’re encountering should narrow it down for you.
ok
Try to search for "reversible USB-A"
Gave +1 Rep to @cloud quiver (current: #45 - 191)
Remember, Remember, the 5th of November
Election day 🙂 ?
? An England holiday
Idk, they dislike that guy fox
In merca, we see him as a hero
Sort of,
This is beyond 2024 USA elections
Can be related to Guy Fawkes or V for Vendetta
Thanks for the info guys, didn't know that 🙂
Gave +1 Rep to @simple valve (current: #19 - 431)
Need I say no more.
Thank you too bro 😄
Gave +1 Rep to @viral crest (current: #1550 - 2)
@rapid merlin Hello why DM ?
Called out
do you guys take notes while going through thm walkthroughs?
or do you just visit the room itself and give it another read if you ever need to revise something
Take notes
By all means
I have a bunch of notes from when I was doing TryHackMe stuff. They're not useful to me anymore but it really helped the learning process
how do you take notes
what do you write in them?
Alek!
I use Trilium
I write them generally with ASCII characters using different keys on my keyboard
What's up bruv
Hoy bruv
Hiii, to sync our account with discord, we can do a /verify true ?
!docs verify
The TryHackMe Discord Server
Too old.
Yeah i've being dm the bot but nothing happen 🥲
Did you see the website design?
But really @queen flare just start taking notes. My first notes were terrible. You'll learn along the way
And they are finally adding dark mode xd
Type || /verify || and then enter your token
lets say i am doing a walkthrough room (not a challange room)
how do i take notes that helps me with revision any more than just revisiting the room again?
well the point of taking notes is having a centralized place with all the stuff you need to know
Oh it's worked rn thx a lot
you may be in a situation where you can't go on a certain website to check the info
looks this is from a THM room on XXE. Walkthrough room.
These notes are not that good but it worked for me at the beginning
it's a mix of copy/paste the most important stuff from the room and adding other stuff like command results etc
yeah this makes sense
not sure, maybe I'll check during advent of cyber 😂
I'm prepping for the BSCP currently
i haven't really taken notes so far because i have been thinking i could just revisit the room
but seems like taking notes like this is a better idea
The Gunpowder treason and plot;
Yeah just take notes , when you will be doing a video course you won't be able to so easily check an info
For BSCP this is how I'm taking notes btw, it takes a long time to do it but it's worth IMO:
this is the easiest mindmap I did so far. The one on authentication is big
i do take notes for video courses and almost everything else other than thm rooms
i haven't taken notes on thm walkthroughts yet
i mostly used to just revisit the rooms when i wanted to revise
look at this
took me like 2 days to do the labs and render it properly in a mindmap
even if it's basic stuff
Thanks @amber quarry
the pictures are giving me a decent idea on how i might arrange notes
Gave +1 Rep to @amber quarry (current: #65 - 122)
this is more of a process on how to tackle a vuln on portswigger
but definitely your notes should be a mix of text, diagrams, screenshots etc
with backlinking
hii everyone, i am unable to use my discount voucher on swag code. it say enter a vaild code. I got voucher code on mail. its me or anyone else facing this issue
this is like 4 years of notetaking
Nice
Post in #site-support maybe
Nice! Looks like a snowflake
Is that obsidian?
Trilium Notes
Ah
TriliumNext version
Obsidian has nice graphs for notes
I don't really like Obsidian but it works too yeah
Not really useful, but nice when you want to show off how many notes you have
Yup lol
that does take a lot of time as well though
I take a combination of hand written and digital notes
That’s very organised
You might like the reMarkable 2
PineNote is also shaping up to be a good alternative (that doesn't cost an arm and a leg)
I have a little notebook on my desk, the hand written notes I usually take are for commands and general flow of what I should be doing so when I do a longer task I can quickly refer back to it.
this one took a while but it's needed if I want to have a chance at the BSCP exam
That's an interesting structure. How have you managed to keep the branches so distinct?
For comparison
What I don't show is that I have one of those folder named "to sort" 🤣
YOOOOOOOOOOOOOO
LMAO
So I’m guessing it’s a hard exam to pass then
I should also take BSCP soon 😄 . Doesn't seem that hard 🙂
looks like this at the folder level
Gimme a room and I'll ace that exam fr
I've heard mixed reviews to I'm preparing for the worst 🙂
I'm guessing you're not using clones?
Ah, that explains it
My structure is similar
But I have notes which need to be in two places at once.
Clones let you take a tree and basically put it into a second location
ahhh I see
Which is why there are nodes in my graph which have more than one parent
And why it looks like a freakin' neural network rather than a snowflake lmao
I dont use what you two use, but my notes are currently organised by path and section within that path for now.
Yeah I try to avoid this and organize them by theme and keep it in one place
Yeah that works for the beginning but then you'll end up like me with web stuff next to AD stuff
that's why I'm reorganizing everything by theme
and that's why I have a big folder "to sort"
yeah thats what I'll end up doing at somepoint.
Oh, they're organised by theme.
For example, networking theory. I could need that in two contexts:
- I'm attacking something and want to understand the background
- I'm building something and need to know how to implement it.
It makes sense to have the underlying knowledge in both locations (Infosec, and Development)
that would be more like an organization by tasks no ?
So those sections will have their own dedicated notes on network attacks and systems administration respectively, but also both have access to the foundational stuff
Eh, depends on your definition. I keep my "attack" stuff separated out from my "build" stuff
did you switch to TriliumNext already ?
Mhm
You tried the new mindmaps yet?
yeah it's bugged af 
Doesn't surprise me 😆
I upgraded a while back but haven't really had time to mess with the new stuff yet.
New installer is nice though
when I deleted the value
I'm kind of waiting on a UI improvement or I need to find a decent theme
i turned on wireshark on my home network and saw this.
the 3c: :78 mac is of my laptop and the 80: 60 is of my router.
this seems kinda weird to me as why the router is sending ARP repeatedly. any suggestion or am i paranoid
that's how ARP works
I suggest reading on the protocol
you can see the ff:ff... is broadcast on the layer 2
just asking for IP address so it can map them to MAC addresses in the local ARP table
but the repeatedly asking for ip-mac relation?
idk, who has 192.168.1.5 in your network ? does it respond ?
one of the androids. they dont respond to ping by default.
i checked, its a oneplus. but im confused why only my device (a macbook) is responding to the router while all the other ones (which are mobile phones) arent responding
have anyone want to build a team to play CTF every week ?
I'm not sure but it's probably something in the config
Try googling it i guess
Hi, I need your guys’ help. I'm looking to find a project idea for my final year, and I want to focus on cybersecurity. I think of choosing web security. Given my limited knowledge in cybersecurity (I know some Linux, Python, basic Linux commands) and the deadline in 4 months, would you recommend web security? If so, with which specific part should I delve? And what other projects can I work on besides web security?
Why not ? Which field of cysec you are most interested in ?
Me after a coffee
I working toward pentest. but nothing specific yet. I am taking a program about cybersecurity and they offer three routes for final course: SOC analyst, Windows Forensic, and Pentest.
About the web project, do you have any guidance or recommendation?
If you're interested in pentest check out this resource 🙂
Learn the practical skills required to start your career as a professional penetration tester.
Don't know , maybe I could help 🙂
Should be if it's from a trusted source
I have taken this before and i'm 24% complete. I want to get back to THM and this time i'm think of fpursuing web fundamental fisrt.
You can check out new cyber101 path then
Are you new to cyber security and not sure where to start? This pathway will help you acquire the core skills required to start your cyber security journey.
thank you. haven't look into that yet
Gave +1 Rep to @cloud quiver (current: #44 - 196)
CS101 is great
If you can find refurbished one in the official store it shouldn't be a problem . Refurbished electronics are a normal business practice for years now 🙂 .
FInished it last night, big ups team
Today I am doing some of the penetrating rooms. I figured to be able to defend I really need to see how these attacks work for myself
It's a good idea
Is the most common attack on networks MITM
I made the jump to the challenges yesterday. Did Cheese and Mushroom Kingdom. Learnt a lot about how an attack actually works
Wouldn't say so, got nothing to back that up but I've never seen one
In regards to this lol
It's a common attack in pentesting if you only have an access in the network but don't have an initial foothold on the AD
If you really want to learn about techniques real attacker use I suggest looking into MITRE ATT&CK
mitm includes a wide range of attacks. you have llmnr/nbt-ns/mdns poisoning, SMB/LDAP (NTLM) relaying, DHCP spoofing, ARP poisoning etc etc
most of the work in an internal network needs to be done on the Active Directory so I would recommend learning a lot about this
while not forgetting that some orgs now use Cloud or hybrid infrastructures so you need to look into Entra ID and cloud platforms in general
Thank you but I’m more learning about defending myself. I don’t think people use AD for just one person
Gave +1 Rep to @amber quarry (current: #65 - 123)
Ha ok well that's a whole other topic then
Setting up a domain for my house
Me and myself gonna be the best domain users around
Yeah sorry
Just me, myself and I
im addicted to watching videos of people messing with scammers again
Good Morning All
Good morning sir 🙂
asked GPT. phones dont reply as frequently to save power. and learnt something new that routers send out arp so much frequently.
Morning
I’m looking for something like Google that’s more honest
That will give me the answer to anything
How are yall doing?
Good, how are you 🙂 ?
use gemini
Great, Thanks for asking
Gave +1 Rep to @cloud quiver (current: #44 - 197)
That sounds nice except the tea part. Coffee always
😩I can’t
My wee heart can’t deal with it anymore
you're brit?
I might be 👀
Yeah can understand, used to hate coffee a long time ago
Just drank tea
then switched
i used to love coffee. it doesnt hit now like before tho.
so i stopped
I just can’t drink it because my heart rate is always fluctuating anyways
I like the taste though
hot or cold
Both
nice
Why are we all green
maybe cuz we're all crusaders
i have a green leaf tho :3
Ohhh, yeah then it can be a problem
a sea of green
sometimes it is like that
im listening to like that rn 😭
i thought how could u tell

I’m getting closer and closer to OMNI
im at hacker level
Nice good job
Congrats 🥳
I can’t believe I’ve almost done two rooms already
The event make me go up an entire level which is how I ended up green
Good luck to it
Don't laugh -- it's legitimately a decent way to run a home network
Overkill? Yes. Powerful? Also yes 
I know a few people that have something like that set up
Thank you
Gave +1 Rep to @errant fossil (current: #468 - 11)
good luck !
Thank you
Might pop to the shop and get a drink since I’m gonna be in here all day
enjoy ur drink
I do not want to bother anyone, but dose someone know if there will be another Advent of Cyber this year?
I really liked the last one. ☺️
And I cant find any Information about another one.
there should be one imo
I hope so 🙂
I don't know where to post this, but it just gives me the answer X)
Hope they do another one, The feedback on this one was great
Yep. I've got full SSO running lmao
Which ctf is the best to start with on thm
Year of the Jellyfish
Try with Rick and Morthy and Basic Pentesting CTF
Vulnversity also
Ty
Gotta love the smell of spam in the morning.

remember, dont just learn, get hired
OhSINT was nice
good ol OhSINT
Nah, I quite like my job
My most favourite one tbh
im doing some more learning before I start with the beginner ctfs
OhShit, the prequel to Osint
Im processing what I’ve learned so far b4 I continue thm
It's discontinued sadly 😢
But I want to apply what I’ve learned
Back in my day:TM: we didn't have the learning. The only option was to dive into challenges.
setting up ur own vuln os
The learning material is good, but it's not nearly as helpful practically as you might think
I figure
Just dive into some challenges and see where you end up. You'll learn a lot more that way, and it will feel a lot more natural if you develop the skills yourself.
why does this link communicate with snapchat lol
I'm more than 50% sure that it was written by AI too
I always do some extra research when im learning something on thm
its how I deal with tasks that im stuck on as well. Like when I was doing the metasploit rooms I was also reading through the documentation of metasploit
Any beginners here that wanna add each other? Im literally a NOOB NOOB lmao
i also sent u request :3
Q - why does THM seem to prefer Burp over ZAProxy? Basics (ticket evnet) and pentesting both have only Burp. I am doing all of the modules with ZAP instead.
😁
i guess that burp is more popular? dunno can't tell
Burp is WAY more advanced than ZAP
Same
I think Burp it’s more used and recognized in the industry
Community edition maybe not , BURP PRO is a whole another level compared to ZAP
from what I have seen burp seems to be an industry standard software as well, so it makes sense there are rooms on burp.
Daaamn i thought you were a beginner but 128 rooms is good work ^^
i'm speedruning this thing 128 rooms in 19 days
lmao you dont write down any notes?
i do!
oooh nice i also have a really nice notion but its in german
love notion for notes
128 rooms in 19 days? is your brain ok? does your brain need extra cooling xD
hahahahah
i just got crazy amounts of spare time to learn
thats so nice
But those advanced features are in paid version, are they not?
I have too, but ive only done 48 rooms lol
notion is fine, but has too mcuh features imo, i like my notes in plain ol txt and vim
More industry recognized, it is paid (Enterprise Edition or whatever its called) and organisations doesnt want their things done via opensource tools. Simpler interface.
i learn when i dont have a support case to take care of
You have more advanced featueres than ZAP even in community version especially if you use Extensions from BApp store
I use ZAP because i am too lazy to write hydra command for web bruteforce
i see an oldschool guy but
that's nice tho, everyone learns at thier own pace
you can do almost all the same things in ZAP. It's just that Burp is more user-friendly in their way of presenting the features
Would love to see glimpse of your vim notes
yeah I take notes, and redo rooms or sometimes sit in a task in a room and play around with it.
I see. At what level will I be able to spot thedifference? Some advanced webapps, or the whole system/applications? In other words, should I invest in learning Burp now, when I only plan to do websites if anything at the moment?
i just use it like notepad but in vim
i found out that doing rooms over and over helped me actually understand topic way better
it's soo cool to do
and organisations doesnt want their things done via opensource tools
Huh ?
I have vim but havent used it, for notes I use joplin
damn u even redid rooms?
hell yeah brotha
you are a full time THM addict lol
you should of seen me last night, when I was doing the cryptography rooms it gets you to do maths right? I was doing them by hand on paper lol
i just hope im gonna make it out of it support by learning with THM and taking the pentest+ exam.... The people in my office cant even turn on their monitor and its driving me crazy lol
i guess u can call it addiction 💀
YOOO
thsts crazy
fr
LMAO
you will make it bro!!
i believe in u
❤️ 🥹
Im unemployed and it annoys me that I cant get into IT, because I do have computer skills and when I did work in an office and most people had no computer skills so I ended up being the office tech support unofficially meanwhile the actual tech support guys rocks up in a sports car at midday.
From your reaction, guess that exp is just from my work place lmfao.
it was the questions "if q = 29, g = 5, a = 12" etc I did all 3 of those by hand on paper
Don't get me wrong I don't want to discredit ZAP by any means 😄 . It's a great tool and it's free at the end of the day , in some aspect even better than BURP ( easy brute-forcing for free, Burp requires a license for that,etc. ) . I think that Burp has better community behind it, far more extensibility options ( BApp store ),it's easier to use,faster( also requires a license ). The true power of Burp is in its extensions imo , many of which require a license .
much respect
Oh its so hard to get into IT i applied to 300+ job just to get a entry level it support position. i recommend the microsoft support certficate on coursera. it has helped to land a job
When talking about pentesting because I guess this is the main topic the client does not care if you use open source or paid tools as long as you did the job
I cant even land a job with my degree, which is why im learning cybersecurity/hacking lol
I see. They certainly have a knack for naming things - intruder, repeater... But I'll stick to ZAP for now 🙂
This is a good answer
ZAP also has those featueres
Only the name is not the same
dont get me wrong, it almost made me cry because I was trying to do it on my scientific calculator. Took a break then broke it down into really simple maths on paper.
For most of my web pentests I use Burp Pro because it's just more convenient.
I find that ZAP does it better when it comes to raw API testing
Maybe I'm just more used to importing OpenAPI docs in ZAP, it works better in my experience
I know. But the names are less poetic.
u know that learing goes hard when u get crazy emotional about problem u encounter
Function is what matters 🤣
by the end I did understand the section though
yeah emotions make everything stick way deeper in ur head
But seriously, if I say I am fuzzing the website, no one outside of cybsec will even connect the activity to hacking. When I say "intruding", its much clearer what I am doing.
for my next js app which uses SSR CSR and stuff is it best to use a VPS to host or smth like vercel? Vercel does seem quite expensive compared to vps tbf
Anyone made THM theme for obsidian?
no one actually serious in this field says "intruding". "fuzzing" is the term
Hey everyone. I am looking for a great course which help to understands the things in Web 3.0 as well as gives a hands-on in the how cyber security is integrated into it and what needs to be tested, how to be tested and how to resolve those issues. Any help is appreciated.
If you know course, please tag me.
Web3 and smart contracts on coursera, bombay's hands on web security
Its expensive because you have less overhead to worry about.
If you want to be able to control more aspects of your app (e.g., server it runs on etc.), a VPS would be fair,
If you want to spin up something really quick and don’t wanna worry about other stuff like SSH access to your VPS, OS updates, packaging, versioning, etc., then Vercel would be a better fit
How many days left on the tickets thing?
Hasn’t it ended?
the ticketing event finished yesterday
Ah shoot lol oh well learned lots
if you have won Defcon, laptop or amazon voucher you still have time to submit it via email until 7th of november
I wish
the path it’s still open to continue learning
Yeah will keep learning lo
Got another course at the moment so haven't done much THM
I really do not like Word
Wpsoffice is what I use. I wanna try libre though.
For notes? Try Obsidian or Joplin
Can we make THM theme for obsidian
I should try those tho.
Can create folders in them I'm guessing?
Sometimes my notes gets lost in the wild ahaha
yep
I really like obsidian
I've only just started using Obsidian as people have been recommending that and Joplin. I haven't played with the functionality beyond folders and some basic markdown
My writeups read like the scribblings of a deranged person at the moment too
it also has a plug-in which you can configure to sync with git and that way you can sync notes and have them backed up
Really? I thought you had to pay for the syncing. That's perfect! I'm downloading that immediately 😅
You can google the obsidian git sync solution
there is also a paid version of obsidian I think which provides that option
but with the git plug-in you can obtain similar for free
.
maybe a little bit harder to configure, but by following a youtube tutorial or google it should be fine
That'll be helpful as
Just got a scam email 😠
Ye, well for now I am in it just for fun and I will coin the term "intruding"!
$1000 cash app gift card is ready
When I feel like I’m stupid because I’m not doing my work, I just go into the comments of YouTube videos and I feel much better 😂
Someone just asked how an actress changed where her hair was growing from because she changed the parting
The comments are so funny
If it's too aggressive it won't go unnoticed
Done!
I've seen those comments before I just sigh at them lol
They make me giggle
I’m gonna get some plant cuttings
Morning THM
Good morning to you sir also 😄
Morning
How is ya'll doing today?
Good , how are you 🙂 ?
doing well, thanks for asking :3
Gave +1 Rep to @gray sonnet (current: #88 - 82)
ok thats 1 of my tasks done
Excited to crush another day
yessir that's what's up
Hey there y'all 🙂
hiya tim
I got a question: how does changing my computer's DNS server affects my anonymity online?
Isn't DNS server just something to make website URLs look better?
(clearly a noob ik)
Hey! How are you doing?
Hii! Wassup
Welcome tim 😉
🙋♂️
yeah more or less, it takes queries and translates it to what servers and systems understand. This might help you learn more https://www.cloudflare.com/learning/dns/what-is-dns/
i'm not sure how much it can affect your anonymity online except it will reduce tracking by your isp (?) (not so sure tbh)
If you're interested in DNS check out this room
If you're interested in anonymity check out this one
🙂
this room is soo good
It is . Great way to get familiar with DNS 🙂
for real
there is any rooms or resources for mobile exploit/analysis ?
Check this one out
thanks
