#general
1 messages ยท Page 558 of 1
As you are
What's wreath? Like the Christmas thingy?
one of the network rooms on tryhackme
It also barely works, although that's on the TryHackMe infrastructure side. Network itself is fine.
Speak for yourself!
Right, okay, I am 23 ffs
that's old
Try me. 19
lol
... I hate you all 

Well, it worked well enough to teach me how slow proxychains are ๐
fair enough ๐คฃ๐คฃ
We love you too! 
Muirr how it feels like to be old
my eyes and brain hurts
I dunno. Give it four years then you tell me
Also, theres not a lot of hands-on labs for practical practise on pivoting
I don't want to be 20 years old 
what's 19 like
I don't remember it
Ugggghhhh, I really want that pillar drill
Omg, Fallout 4 collections take forver
You hack stuff and call Muiri old
What's stopping you?
Black Friday isnt for a few days ๐
oh @silver sky When you asked Squad, you mean Squad 44?
Sounds fun ๐ญ๐ญ and a lot like 18
No
Squad
Oh, then still no lol
A pillar drill really ups your forstner-bit game
Squad is the embodiment of tactical military action. Compete in massive-scale 50 vs. 50 battles in the most realistic combined-arms first-person shooter. Squad emphasizes combat realism through teamwork, tactics, and authentic warfare. A wide selection of realistic faction-specific weapons and vehicles allow players to build their own loadouts t...
$49.99
141950
Get it
I also want a new mitre saw... And I want to see if I can get deals on both lmao
I have so many games 
Oh, Black Friday soon.
Oh your poor bank acount. RIP.
What's a pillar drill...
Squad my beloved
I can already take ยฃ50 off the total bill, but it'll still be ยฃ600 odd
Actually I'll search it up
So you can join me and @lone thistle in walking 5 miles, digging a hole and then dying to a person hiding in a bush
Hence waiting a few days for black Friday
OOO COOLLL
Pillar Drill in the US is a Drill Press I think.
I remember these in DT class!
Watch me find a freakin' table saw as well
Not sure what it's called elsewhere.
When we did woodwork
Synapse - It a drill thats basically mounted so its solid. You can then use a lever to push the drill down, so you know it's dead straigh
They were funnn
could be useful
I liked the belt sanders though ๐
The number of rip cuts I know I need to do is steadily mounting
The ones I have at work... like to walk a little ๐ฆ
And my track saw ain't brilliant
why does everyone need a saw just for sawing tables??? sounds like a very weirdly specific saw to need
Ahhh that makes sense unc ๐
...
can I call you unc
Sounds about Hell Let Loose ish
Course you can Synapse. It's the name I chose ๐
should have marked that with joke probably
I could use some actual tools but I know I'll never use them
๐๐
I use pen to cut wood
Probably
I use my fist to cut wood
Minecraft mentioned
Muiri - have a bit of a google, but theres a guy (I think it's Izzy Swan, Maybe?) who made a jig to make bowls on a table saw. The thing looks mad.
I use your head to cut wood ๐
How the heck does that work?
In layers?
It's an effective tool
That's...
Lemme find it
Cmon 44
What is life if you don't have danger
Folks
Have you ever dreamed of making fancy wooden bowls with your table saw? You havn't? Well what ever you're here now anyways. Let's watch how to make a bowl using nothing but your table saw. Visit my website link down below to download a free set of plans as well as plans for all my other projects.
Join this channel:
https://www.youtube.com/chann...
Eh, they make blades that sacrifice themselves when in contact with anything conductive.
Shouldn't get anything more than a slight nick ๐
Folks
that almost hurt
cower before the glizzy
Must kill all the bacteria 
I should clarify, the blades don't sacrifice themselves persay. There is a brake built in that shoots itself into the path of the saw teeth, effectively stopping the blade spinning, and shearing off several of the teeth in the process. It's very quick, and it's a fantastic safety feature.
That's some clever tech
Or the solution is, just don't stick your fingers near sharp spinning blades
Common sense isn't common?
Jowp, yeah, I saw somthing like that, SawStop?
I think that's the name, yes.
Even better though
Do both!
Have a safety mechanism in case. As you wear a seatbelt in a car.
I know they do other stuff like beasty fences and stuff. Looks like they are starting to move towards th UK
It's risk, same as cyber
Reduce the likelihood (keep your fingers away) and the impact (make the blade stop and not take your fingers off)
Right tool for the right job, Zumi ๐
Nice, James. i like what you did there Keeping it relevant ๐
Same reason I have a silicone Wedding Ring ๐
Cos you can't be trusted with metal?
You build a lot?
Work with lathes, drills and mills often.
Work work or hobby?
Both, the company I work for mainly does electronics/IT, but we do produce some wooden / acrylic products.
Nice
It's fun, I get to mess things up every now and again ๐
Hai
heyy guys
Do they let you use some of the equipment for your own projects?
I have free reign. I should clarify, on my own time, not the companies ๐
Thats bangin'
Do anyone know de OS footprinting or attempted it?
also fresh here -- hey
Hey bro
what is that?
hey!
It's when you detect the OS of the device connecting to your network via your IDS/IPS
ohhh blue team stuff i think
it's really difficult that's what I heard
but i havent done it
yeah thats blue
nothing is difficult i mean if you are curious about it its gonna be fun learning it so it might be "complex" but not difficult
couldnt agree more

Oh my bad is SOC I Red team?
Amazing!
SOC is blue team
I'm doing de SOC I cert or trying to going slow like I did in Security + I did them both slow
soc is = detecting, monitoring, investigating, and responding to security incidents to defend an organization from cyber attacks
Ok great
so yeah blue team
just got my A+ cert in september. going to start on a network cert next year and started a tryhackme account to have fun in the meantime
I like both red and blue team, since malware analysis can be considered as blue team
compared to malware development and execution ๐
Mostly SOC level 3 afaik
Red Team = Offensive
Blue Team = Defensive
It depends on the company though
Yeah i did not want to say that xd (Obviously not executing)
Holy shit this guy is a nutcase
That actually worked really nicely though
Who needs a lathe, amiright? 
My laptop speakers just creaped me the hell out. Playing heavily modded Fallout 4. Nora is talking... and I thought it was actually coming from behind me WTF
You shut your filthy mouth
Just use the damn table saw, duh!
Hehe
let's see it
Erm
Hello, here the domain and subdomain points to same IP, but how does browser/server know which website the client is requesting
DNS resolution maps all subdomains to same IP, while browser sends HTTP request with the host header specifying subdomains or domains
Just a thought: imagine you are in your room. And everyone is asleep, but you. And you hear your door bell ring after every hour....what will you do?
People say, best is to call the cops when you are 100% sure something is off....
Plot twist is here: the door bell is not located outside the gate but, outside the wooden door that leads to your garden and then comes the gate......
Someone's definitely inside or is the machine malfunctioned?
I would be too lazy to even think about it tbh...
The bell is really loud
Scary
Had to stay up till 6 am
How did others not wake up
The browser doesn't know
The browser asks for the content and the webserver provides it
Sorry, my question was not clear.. i mean, as domain/subdomain all will resolve to same ip, how does server knows which website to serve to the client
Based on host header included in the HTTP request
Then yep that's the Host: header
It's called vhosting if you'd like to look into it more
thank you everyone
Hostnames are only important to your computer.
Either it will be resolved internally (From a local cache or hosts file)
Or via DNS (In that order).
Your web browser then connects to that IP, compares any certificates found to the FQDN you provided, informs you of any matches or mismatches.
It further provides a header full of information including the requested URI/FQDN.
As part of the FQDN above, the web server can provided you the appropriate vhost, or an application router/HTTP Proxy can redirect you to the correct internal system or VM.
Fwiw, vhosting doesn't have to be FQDNs
FQDNs is more of a dns thing, vhosting and dns are related but very much separate
True, I'm just used to seeing vhosting rely on the FQDN, usually if someone wants to do something off the rest of the URL I tend to see HA Proxy or NGinx reverse proxy.
There's a lot of overlap in some of the web technologies with minor nuances.
that's if you're being sensible with it lmao
Also FQDN being fully qualified
VHOSTs don't have to be
That's true.
I've seen vhosting used to backend without an fqdn referenced from a front end public facing server via fqdn.
hostname only routing shudders
Guys, i used to take notes in Notion app because of its cloud sync function in my windows(host) machine.. i dont take notes in virtual machine(kali) as i feel it can crash someday... But Notion is very laggy and slow.. any alternate better note taking app where i can sync to cloud and access from other devices..(free app)
I love notion, so idk
i take a lot of screenshot and i think because of this, its very slow sometime
Everyone's going to tell you Obsidian.
I'm not saying they're right or wrong, I haven't used it, but that's what I hear every time its asked ๐
is it fast compared to Notion, free and can be access from any devices?
ill have a look..
I was looking for a relational notes app recently, and, decided I'm probably going to end up running a wiki and just using git to back it up XD
evernote or obsidian yes
or trillium
if you need cloud sync and need it for free that is a hard thing to come by
technically obsidian can do it over git but then you gotta use git repos and know how protect those
If you have keybase, it supports git protocol and would be automatically encrypted with your PGP key. So I guess that's an option.
I still use it even after the purchase, but I'm going to migrate away from it as I start self-hosting more.
Apparenlty Proton's free tier includes Proton Drive, which would probably be enough for simple notes storage.
well shadow was talking about in client sync methods
but yeah other online storage methods can work for not storage too
anyways shadow has a headache and wanna be up decently early tomorrow so it is now meep moop to the beep boop for the sleep sloops time
Good night
anyone got any good recoomendations for notetaking? currently using a private discord server
๐
:hammer: aron7303#0 has been banned.
[BAN] User left the discord server.
Thanks jabba
I don't know what I missed but it looks like it needed everyone on deck.
lmao
neovim

oof @ Affero GPL
i thought notepad was enough ๐ญ
neovim looks like mostly for code/i'm taking the majority of screenshots (fornow)
does it have a place for my screenshots?
yes and no
Obsidian is good for pasting screenshots and it appears on the current folder (You can change it)
There are some parts that are not free.
Thats how you know it's a quality product
hah
Ok. look up how to do a XSS attack
And now you'll know what it is and how to do it ๐
hey uncle sqy . how u doing
wdym your first CVE though
I evolved it seems
the first CVE you exploited?
oh wow fair play
Gratz, hix ๐
what is a CNA? ๐
thanks
Gave +1 Rep to @glass nest (current: #18 - 453)
1028 out of 1500 words. ALMOST THERE.
cmon, synapse. stop getting distracted - XSS, Go ๐
i wish to use a static discord token , but it is what it is
oooooooo
i guess this token is tracking me
okay okay XSS
the best arrows are explosive
Explosive Cross Site Scripting? Thats gotta be a room idea ๐
All the elements explode
There are no URLs in that message.
ummm
Explosive SQL injection'๐ฃ
true dat
XPLOSIVE SITE SCRIPTING
ssti ๐
Don't forget about XXXSS
when was the first xss attack discovered
fr ?
well whoever discovered it , for sure was a mastermind
Samy Kamkar - How I Met Your Girlfriend
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend.
This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP sessio...
people who actually think out of the box
im going to carry on after i finish my duolingo#
Don't forget the https://en.wikipedia.org/wiki/Samy_(computer_worm) Samy Worm
Samy is my hero
Samy (also known as JS.Spacehero) is a cross-site scripting worm (XSS worm) that was designed to propagate across the social networking site MySpace by Samy Kamkar. Within just 20 hours of its October 4, 2005 release, over one million users had run the payload making Samy the fastest-spreading virus of all time.
The worm itself was relatively h...
i remember this episode
See Synapse? XSS is cool ๐
And a Square. and a Circle. You... you a squid game?
The 'bermuda payload'
I FINISHED MY DUOLINGO
Good. Lets hope your daily sacrifice appeases that evil owl
duolingo knocking on your door ๐ค at 3:00 am . u openning the door ? yes or no (for the streak u abandoned)
yes (i have a baseball bat within arms reach)
https://youtube.com/watch?v=twE-zdUkB_U
for anyone that practice MMA or any MA.
I thought this video was interesting.
Something weird is happening in martial arts... The world's greatest fighters have stopped sparring. In this video I explain why, what they're doing instead, and how you can do it yourself (5 steps). This unique training method maximizes learning, while minimizing injury.
Music Credit:
Scott Buckley - released under CC-BY 4.0 - www.scottbucjk...
Ohhh i remember this!
I remember the guy who did RockYou used to go to websites and just put speech marks in entry fields
I'll watch this later :0
Totally, this is something I started doing in practice, years ago. And also to select better any sparring partner, since a lot of people tend to have a lot of ego or fragile one when sparring.
I still spar
ยฏ_(ใ)_/ยฏ
can't damage what's not there
TLDR of the video is not to stop sparring, is to do it properly.
Oh good.
Yeah, I found that when I was doing sword-fighting with some other nerds. One in particular offered to 'teach'. but his teaching simply involved showing the 'student' that he could whoop them over and over.
Hi
Annoyingly he was kinda good. Not because of his skill, He was just like 6.5ft tall, so had ridiculous reach. If he was less of a doorknob, he would be a valuable person to learn from
Been a while. How's everyone doing?
not anybody can be called "teacher" really
Don't forget Charlie Zelenoff, what a jackass.
AWFUL Humans // Charlie Zelenoff Getting DESTROYED MUST SEE
Self Proclaimed Boxing CHAMPION Destroyed By Deontay Wilder After Threatening His Kids
The delusional GOAT, think fights Floyd Mayweather, Deontay wilder and many more, despite thinking he's the best and sucker punching loads of people he can't fight to save his life and so, is frequ...
Yeah, but it was the best way I could say it on here :p
Oh this a hood's classic

Can confirm, Muay Thai and Wrestling made me dumber ๐
Yeah sparring is essential. I only spar with people I know, and I do not bring ego into it ever. I let my partner set the pace usually ๐

That's just a landmine of a statement...
That's absolutely how it should be. And for the last part of the sentence, that's good. That's why I limit myself nowadays to practice by myself, and concentrate on the Art part of Muay Thai, which I luv.
i need somw help with my facebook account who can do so
Good thing you didn't go to the boxing route.

Facebook support can help you:)
let me guess u want help hacking a fb acc ?
Lemme tell you about my teenage years ๐
Oh no
I was fortunate enough to avoid injury and too much head trauma ๐
Without getting this to the political arena, which I have no intention to do. I'd say that it's no really jew, but more Israelis. Israel invest in their people and it shows.
no facebook could not i want to get my acc that was hacked back it is part of my career im a musician and cant do my thing without facbook
@pearl raven
In one of my previous jobs, I had this supervisor, a very nice gentleman, what I know of security and helped to get to supervisory positions, was thanks to him.
He used to box, and one of the things that led me to decline his offer to be trained by him, was him himself, the migraines he'd get, oh no... The medicine he had to take, was "oof" and that's an understatement. I would have to cover for the rest of the shift for him, because he'd be dozing off.
He used to train certain police departments from here in regard to self defence.
Gave +1 Rep to @pearl raven (current: #78 - 91)
tried that who ever did it set up two factor against it so i cant get in
if i facebook would have helped i would not be here ive been trying to reach facebook all day they dont have a good way to actually contact them
It's not our service, there's nothing we can do here
Yeah I was concerned for a while, I started getting headaches and learning was getting difficult... turns out I'd never had an Eye Examination... I needed glasses...
I told him 50/50 jokingly, to train me for mma in regard to striking and go from there.
He was like "nah, boxing or nothing". I was like "nah... I'm good"
Dodged a bullet tbh.
Oof, thank goodness nothing heavy/bad...
Yeah, and also because I'd feel limited on boxing. Thing I didn't feel when kickboxing.
More range, less head impacts.
Oh... that's not really appropriate...
It was supposed to be head banging... not banging it's head
I have a coworker that was going to (I reckon) BJJ or jujitsu.
Only bad thing is I don't have money to spend on that, but I'd luv to.
@pearl raven
https://www.youtube.com/watch?v=LtJSUmlcCT4
this was my supervisor/mentor, Ed Pollard.
Freddie Pendleton Vs. Ed Pollard
December 4, 1993 | Miami, USA
Contest in the welterweight division. Pendleton was the IBF World Lightweight Champion.
yooooo ๐ this one a lil freaky
i mean he's on cocaine
(and i like that)
evening thm
Very cool, I can't watch the video right now, I'll check it out later.
no probs :D
xss practiceeee
sorry if this is annoying
i had no clue you could use html like this
I did Jiu-jitsu for a few years it was great, the life happens and I had to stop
Yeah, hopefully you can get back to it :)
lol why does this work
I just realized that an AWS network would be so much more secure than an AD network.
Because even the host discovery is completely removed by using AWS.
You're not allowed to scan any host or instance that is not a part of the target company.
That means you CANT EVEN PING SWEEP.
the notes app?
yea
Just remember, threat actors do not care
ping sweep as in testing all the ports right?
(ive only come across that in nmap)
also it wasn't create it by microsoft, that's a huge plus ๐
Are you trying to say Azure? Active Directory and AWS are not equivalent technologies
"How unnecessarily large do you want the notification window?" YES
Is trying de 1=1 on username or password fields illegal? I havenโt done it was just wondering if it was ?
It would be an unlawful pentest.
It's more unethical than illegal but depending on your country, if you do end up accessing anything you're not authorised to, it could be considered computer misuse if they decided to report you or take you to court.
General rule of thumb is not to pentest things you don't have a written signed agreement to. If you do pentest something and it crashes, you can get in a lot of trouble. Especially if they pull up the logs following the crash and they can see you're doing something you're not supposed to.
All of this is very situational depdent, but why risk it at all?
Unless you are actively persuing bounties on a programme, you're looking for trouble ๐
Oh ok this is understandable and very concerning because I think too many kids or script kiddies do these things. Glad to know itโs punishable.
Hello all
Man... not eating basically all day has left me so low on energy
No, im new ๐ฆ
i joined cuz im doing tryhackme free stuffs
i got kinda stuck on something
i found the answer but idk why is that the answer
then you are officially a hacker, welcome to the club
How does one add 45 additional words to an essay
Thank you i suppose ๐
Gave +1 Rep to @silver sky (current: #44 - 204)
According tothe quiz in the website i would like to be a Security analyst
Bullshit it!
Is it that good or bad?
I can't even think right now... was playing fallout 4, then BOOM low on energy
Might have to ya know
Btw can someone help me to explain me some stuff pretty quick?
Is about some simple stuff in the test of tryhackme
I just want to know why is THAT the answer
Well is from an easy thing "apparently"
question is:
Whats the name of the scheduled task that is malicous.
answer is = Clean file System
then ask me other 2 things which are name of the file task was running and which port with it was
nc.ps1 and 1348
So i be like yaii i foound the answers
but Idk why is that malicious
if i google nc.ps1 i just found some kind of forks for spagetti ๐ญ
Shaking im so low on energy, damn
Because it's abnormal. When you look through the scheduled tasks you'll see normal things that should be labeled correctly, the name is trying to disguise the task as "Clean file System" so when a user looks at it they just think it's something else
ok
I basically haven't eaten all day.
Sounds like your blood sugars are low
why have you not eaten?
I have no idea 
Got food in me now. I'm happy. Already feeling better 
Oh much better now ๐
That's great general but another settlement needs your help
H........ HOW THE FUCK DID YOU KNOW I WAS PLAYING FO4?!
you just said
i got word of another settlement asking for help
@boreal scarab I DID IT, IT'S SUBMITTED
i'll mark the location on your map
WOOOOOOOOOOOOOOH
Home-made fried chicken, from the real CyberChef
HAHHAHAHA
classic
The Town of Goodsprings Celebrated Fallout: New Vegas
E-T- Fresh Jerky :
https://etfreshjerky.com/
FOLLOW MANTIS:
โบOfficial Site - https://www.tksmantis.com/
โบTwitch - https://www.twitch.tv/tksmantis
โบPatreon - https://www.patreon.com/TKsMantis
โบDiscord - https://discordapp.com/invite/cfpb5AX
โบFacebook - https://www.facebook.com/TksMantis
โบTwi...
Hey Iโm not sure where to ask this. But I wanna get into network security (defending side) but idk where to start. Does anyone have any suggestions on what I should look into first?
If the best hacker knows all the ways in then canโt they tell the best defender or blue team to patch all the point of entries except the user ofc they cause 90% or breaches I think?
I've got my active directory controller all setup and my samba share on proxmox I think, I've not done it in a vm though because I didn't want any bandwidth restrictions etc. for accessing my btrfs array
๐
all set up to use proper active directory groups as well
Only took 506 different webpages to get proxmox and AD working
both subvolumes within the same drive, just need to sort out my backup script at some point, especially as it's raid 0
hi
hi ๐ how're you?
im good! i just signed up. this site seems pretty cool.
how are you?
I don't think anybody realizes how hard it is for women to work in the postal service. It's such a MAIL dominated industry!
Doing well thanks ๐ keeping myself busy
if your goal is performance rather than data redundancy go for it
So bad ๐ญ
aw i cant link gifs haha

The kind of data I'm storing isn't valuable so I'd rather have the storage capacity and the speed
The purpose of the vault is that it's a btrfs subvolume designed for documents that may want backing up and they'll be differentially backed up to my dad's server which has raid 5
great choice then ๐
And now I have an active directory server to authenticate with and use for any devices on the network
Only thing is I may want to make it externally accessible or setup a VPN because I primarily use laptops at the minute
A few years back I was playing with AD and Linux, I used LDAP with good results
I used samba primarily because it's a mix of devices and I wanted the built in file share functionality
I might even set it up with a print server as I've an old usb Samsung printer I like to use
It's a black and white and only does one side at a time but it costs 10 quid for toner haha
If you want double sided you've got to do the print all odd pages and then flip it and print all even pages haha
samba is for filesystem, with LDAP your Linux server join the AD kind of crazy but kind of fun ๐
Yeah but samba does also have stuff for full fledged domain controllers too
I did samba too, I usually go full Linux but sometimes it's fun to mixed it up ๐
That's fair, I use a mix so samba made sense due to windows devices
Proud Linux user since 1993, it's more like 90% Linux 10% windows
https://youtu.be/knkEzgT_UeE?si=LrRkRr4d1LXMlrkF
I... I love this company
Sing along to ๐ โBRING MY PARENTS BACKโ ๐ the new smash-hit from the Duolingo holiday album โOwl on the Prowlโ ๐ฆ
Hereโs how to keep your family safe and avoid ending up like Timmy:
๐ Buy a Duo Plushie and remind your family to do their lessons: https://store.duolingo.com/products/duo-plushie
๐ง Stream the full โOwl on the Prowlโ holiday album ...
They just go with the memes 
I hate using translating to "learn" a language, in order to learn/use a language properly you need to understand the language without translating, it'll be harder but better results at the end
That's my experience, I only speak 5 languages
Oh ONLY 5 languages
I have friends that speak more languages than I do, so there is nothing to brag about. One of them speak 15 languages she's a language monster ๐
I'm trying to learn Norwegian. Could only really say "Thank you for the meal." And "You're welcome"
Melk og kaffe, takk.
some people have a knack for languages, and most Americans don't ๐ ๐
I think si spelt that right
๐
Milk and coffee please.
I feel sad for Asians. Most Asians only speak one language, while the situation seems different in Europe
Hey hey hey hey hey. I gotta learn a language that's one of my nationalities!
that's look like a cultural thing.
Aaaand doing duoligno, and already forget crap.. then again, has been many months
because duolingo is crap ๐
I quite like it
Hi, need input pl0x #974406074444685322 message
Duolingo is very useful if you're learning a language from a completely different language family than your native tongue, as it treats you like a complete beginner
if you like it go for it, but just you just said you, that you did it and you don't remember shit so maybe it's not the best system ๐
post there and wait, patience is a virtue. Also posting in different channels only will annoy people
I'm pretty much done this box and have been waiting for a while... :S
It also helps, atleast for the basics, that Norwegian sounds close to it's English counterpart
I haven't been on duolingo, or talked in Norwegian to anyone in months, maybe even a year
people here are all volunteers they will answer when they have time or will, there is no time limit ๐
revshells is unsafe, I guess people like to mess with others here
yea thing is its a REALLY simple query
and I need to get this box done before midnight :S
that's your need, that have nothing to do with all the other needs of people here in this server ๐
nvm i got it, was going to hit it eventually
for advent of cyber whats the min qualification of skill you should have to be able to solve
jr pentester work?
beginning friendly I believe
Okay thanks
HI
No skill needed
you dnt need skills, its very beginner friendly
Does anyone have a sort of blueprint for obsidian as to what they did or wish they did for their journey cyber security/programming journey ?
Cool, will try
hlo
advent of cyber seems really fun and it being beginner friendly would most likely help ALOT with gainin skills
you are wrong
Need money donโt language
I have a lot of friends who speak 3-6 languages and they are still working for 1500-2000โฌ.
My cousin is 19 years old, speaks only English and earns 5000โฌ every month.
Lol
Itโs the big difference.
Quick question are most of the exploits and stuff learned in these labs still applicable in real world?
same doubt from day one
In general, yes
The exploits just take other forms.
Yes, most exploits learned in labs are still applicable in the real world because they teach foundational principles, real-world attack techniques, and skills transferable to modern systems. Many organizations also run outdated software, making older vulnerabilities surprisingly relevant.
this hit hard :x
Does anyone know if there is way to do snapshots using UTM as your virtual machine? I'm using a m3 MacOS, running Kali linux. I've looked through the settings on UTM and tried to find videos on YouTube but nothing is coming up.
i do speak 3 languages :3 and somehow what you say is true for me exept i do 0 โฌ
Methods and techniques like nmap skills, metasploit etc most definitely
but in europe it's very common to have more than 2 languages
in Switzerland everyone speak 3 language normaly if they went to school .
World Metrics
Additionally, bilingual job seekers experience a 77% increase in opportunities when applying for jobs in the current labor market.```
i know in India it's very common to know 4-6 languages , with the many locals dialects
respectfully youre so wrong idek where to begin and it just sounds like you're coping because you have difficulty learning other languages. People dont learn other languages for the money, they learn it to communicate better with others, meet new people, learn different media, etc. learning languages is not an easy feat so it's a direct opposite of laziness. Egotistical is going around asking people if they can speak english when travelling instead of making sure they feel more comfortable by talking to them in their native tongue. Egotistical is going and expecting your friends who have english as a second language to be doing all the language heavy lifting instead of you making a move to do the mental conversion strain instead.
Science confirms he is wrong, keep learning languages people ๐
Might I recommend C#, beautiful language
completely agree there on both aspects
i suggest golang
Seems everyone is learning go lately, in demand or easy language I wonder?
in demand for the most part
it's also a beautiful language
not the easiest though
Hey guys
Anyone did OSCP and can tell me if there is anything in the Red Team path that is good for preping the OSCP
I suggest checking their curriculum and aligning it with the Red Team Path
Hey I see u have the CRTO, when I checked Indeed there are no jobs that are requiring it.
So can I ask why did u get it and is it still worth looking at ?
It was a requirement for my current job
Wow, do pen test jobs and red team jobs require and know about it ?
I guess it differs between certain areas and countries. I know for sure that CRTO is looked at in Japan iirc
It depends on the employer tbh
There are other certs like GPEN, GRTP, GXPEN, OSEP, etc. which they look at as also desirable
looking for a job , is a job itself
, been pimping my CV , changing it for every jobs offerts
That is correct, job hunting in itself is a full time job
How Bro there are only 45 jobs in the world asking for CRTO, is it really worth it (im looking at indeed)
very niche indeed , but you may get better pay or can be promoted later for having it
Is the Red Team Capstone Challenge the biggest network on THM ?
Yo Iโm new too!
Looking to break into the cyber world as a junior pen tester.
I have a friend in IT who said that I wonโt be able to do that since there are no entry level roles in cyber.
If so, how should I proceed? I have no certificates or degree but Iโm open to gettting whichever certificates that can help me land a job
Don't listen to ur friend and go for ur dream
Yeah fr Iโm still completing the courses on THM
Iโm only 22 so I figured I got time
But idk what to work towards tbh
I searched and then arenโt lots of pen testing jobs in my areas
Iโm based in AUS^
And I will give u my personal moto, don't do boring one-thing modules
Do the big labs with multiple stuff in them and just research whilst you do them.
That is much more exciting and will drive you to learn whilst you are hacking
Which ones are those? Any u recommend?
Iโm low key overwhelmed by the amount of rooms there are
So Iโm just following the premium pathway ๐ญ
So far itโs been lots of reading and 0 practice
U know how there are rooms, and modules, and paths? There is also a tab called "networks" those ones are filled with multiple computers to hack
So u go to them, and u just keep researching everything whilst u do them
Use chat gpt as ur companion
Is there a certain point I should complete up to before moving to practicals?
Or do โnetworksโ teach me as I go?
Yeah there is one point and 1 prerequisite that you have to have:
YOU HAVE TO GO HARD
U just have to go hard and research hard
I am always hard ๐ฉ
Alright imma do that tonight
Thanks for the tips ๐
So youve just outed yourself as a racist against second generation immigrants from eastern europe ๐
You did not have to stoop this low
On top of that, youre also incredibly incorrect
And how can you call people arrogant for having parents that made sure theyโd be as multicultural as possible
check pm?
In general, this is what I have seen, I told it as I lived and saw it, my aim is not that way.
What did you see other than far right wing media ๐
God you people are so stereotypical itโs not even funny
Possibly my most unhinged playlist
I've managed to split 20 hours of music into roughly 16 playlists
I dare you to work with these people and then youโll realise that BECAUSE theyre second gen immigrants they work harder than most and lack arrogance
Calm down, there is no need to prolong it, you can close the subject ๐
Theyve grown up and watched their parents struggle assimilating
Well i think there is no need to be an ignorant racist yet here you were sending tons of paragraphs
Dont like it when your rubbish actually gets analysed and called out?
Why are you so angry?
You expect me not to be after you say something so provocative?
I didn't say anything about racism, I made an observation, I didn't use hate speech or anything else.
Your โobservationโ was hate speech. Learn what micro aggressions are
I didn't understand what I was saying about your own point of view and how you look at it from that angle and interpret it according to that perspective, so I wanted to close the subject.
Stereotyping second generation immigrants from eastern europe saying theyre lazy classifies as hate speech
You comment according to your own perception.
I'm not taking sides but I think the argument may be scaring others from the chat
I just hopped on to talk about how bad that one playlist I made is
Hello
Hey, how're you
im fine thank you and your?
Gave +1 Rep to @finite basalt (current: #107 - 69)
Doing well thanks ๐ just sifting through my one big playlist to make it more manageable
Nice, and have you fun with playlist music?
Yeah it's fun so far but a little stressful
I've never thought about genres before, I just threw em all together
I've not slept but it's now 6am so I think I'm gonna get up, sort a hot water bottle and a blanket and go do some work downstairs
There you go mate, once you're verified you can embed gifs
ooh ok
but you will manage it because I also added all genres
Morning
yay
Morning
So far
nico collin's ๐
I will say other than my sad playlists, kartoffel and lasaga are my favourites, some class music
Also Nico Collins is mint
i need that i'm so edgy fr playlist
It's still a work in progress but I'll send it once it's done
alright
I've also got the playlists: fuckin sexy like, overthinking and overthinking but upbeat playlist which are good so far, pre me rock also bangs
This is some of fuckin sexy like and pre me rock
omg the 1975
They were all in the one playlist, was something for everyone in that haha
I'll have to check those two out
But yeah plenty of good ones
Friday I'm in love is a banger though, one of my favourites in there
I am on the red team capstone right now and I only scanned like 4 hosts
I think the rest of the hosts are on private networks maybe
(hopefully)
Yeah there is, thanks for clarifying that those are real
But btw I just want to say that there is a skill to be learnt by dealing with 1000s of hosts at once
You have to adapt and use organizational tools
I mean real tools that people made
But this is still nice practice that might be easier
would be a bit costly with 1k hosts ๐
Nope u only need 50 dollars for a permanent lab with thousands of hosts full of vulnerabilities
For example the Sliver Module on HTB
oh?
For a AWS enterprise for 50 dollars as well u can get the PwnLabs Cyber Range
Which has 10s of AWS assets
Or the HTB Pro Labs
50 dollars
But THM is 14 dollars for EVERYTHING, so deal is still very good
I see, PwnLabs Cyber Range sounds interesting have you done it?
Yeah I was invited to do one early to see if it has problems
And let me tell u it was very exciting
Others also shared with me that they too found Pwn Labs very good quality
Well if u are me its 50 a month and bootcamp is 175 a month
That's because I started my own company and I can bargain (which is something u should do too)
But if u are just a normal person then u pay 200 for those cyber range and 350 or 400 for the bootcamp
hmhm I do have a company
Use that company to get deals and trials for everything
al right thanks
You know it's a good morning when you have already been reverse engineering for over an hour and it just turned 8
Morning hackers
Morning i want
This is just general reversing so I can take screenshots and explain what's found
That, i don't like
Well I have already reversed it to fully understand the code, I just have to write about my findings, luckily to people who understand code
Thatโs not a network, right? Its just a bunch of labs per module
If Iโm getting the context right, thousands of hosts spinned up does not cost $50
sometimes I just love how Bing is so stupid slow to update
Itโs snowing
I love snow
Where ๐ ?
@cloud quiver what is your tryhackme Username? and can I add to you as frnd 
Yes buddy , of course ๐ . KGBTHM is the nickname ๐
England
Lucky you ๐ , I love snow .
So do I
morning, its a snow day :D
I cant take a photo to show because everyone would be able to figure out exactly where I live
When I look out my window I see snowy roof tops
Ben - Thats mad. Like.. 2 weeks ago it was shorts n t-shirt weather
Ah. You live in a christmas card. Confirmed
I don't care what anyone says, you are an honorary south-westerner ๐
Yeah, it's not that I don't like writing. I just get distracted and finish it in more than it should take.
We generally don't get too much snow in the city. I heard its because it's by the sea and the air is too salty, but I dunno. We snow up on the moors (Countryside) though, which isnt far
I am cold and it seems I have a package delivery anytime between now and 1pm
y'all got your natural grit salt ๐
It's like that in my hometown, it'll need to be very cold for snow
Thats right Ben. that explains my salty and gritty personality
oh yeah the heating had to be whacked on this morning. Sorry Martin Lewis 
The heating is on but it's currently being overpowered rn lol
Fae - Even if it gets cold here, it's usually just frost and ice with adamantium-like properties. Usually the snow arrives if the wind is blowins from the north - i.e from where the moors are
hello everyone , I just want to do OSINT challenges can you give me your fav one
you must be near where I live xD
Try this one ๐
have a look at Tracelabs, Thats their thing. I don't know if the have challenges as such though
Fae - I'm in Plymouth ๐
oh....you're nowhere near me
I did it
This one maybe ๐ ?
I love windows
getting a random hardware bluescreen out of nowhere
and now everything works just fine
thanks
Gave +1 Rep to @cloud quiver (current: #22 - 410)
when in doubt take a nap and your technical problems solve themselves
I have so much doubt, that I'd sleep all day...
im on linux so all my technical problems are caused by me
ill probably be in bed later watching shows
What're you currently bingeing?
me and my partner are currently binging big bang theory.
Ooh.. fun fact: Leonards specs have no glass in them ๐
Guy's I'm having issues with finding correct return address I stack can anyone able to help me with that
In exploit development
hey
dheeraj - May be worth waiting till james is back on.. Seems like he kindof understood your whole process. I was lost when you were explaining it ๐
๐ซ omg
oh I know, and they're all in their late 30s playing mid to late 20s characters
When he will be back ?
Well, he's UK based, so likely he's in work now.. Maybe 9 hours? (5 or 6pm UK time)
There are other people who know this stuff, it's just I know you've already gone through most of it with him, y'know?
May ik how are they
I've no idea, to be honest. We have a whole range of people here
Haven't u done exploit development bro?
I thought u might know I'm new here
Oh Alright
Yah, It's a fair assumption. Also, Well... james is also a Mod, and exploit development is kindof a... gray area.. on here. If your chat is with a mod, it's less likely to cross any lines
in fact, usually it's only really talked about in the #exploit-and-mal-studies room
most of it is to protect the server from getting nuked
Yeah ok
I see let me ask there then
No Access REEEEEEE
I have some reading to do today
Guys does anyone know , how u get a job in physical red teaming or what certs r requireded
Hey, Black friday discount coming?
Ha e a look at jobs around you
Maybe
OSCP or eCPPTv2
I don't see anything in linkedin and don't see anyone talking about how to get in it , mostly its about pentesting
I was talking about physical pentest
You mean IOT hacking
Hardware hacking stuff?
If u want me to be particular, u can say similar to black team
Black team kinda do stuff illegal
North korea is hiring
Most I got was , get in a cyber security firm as a pentester and hope they give u a physical pentest along with an internal pentest
If you are looking for IOT Hacking you check this course https://academy.tcm-sec.com/p/beginner-s-guide-to-iot-and-hardware-hacking
U get a contact to break in a building and try to get as much as information u can , and later u have to report it
Ohh
Yea , that what I am being talking about, it comes in red teaming (physical part)
that sounds really fun
Lockpicking, bypassing alarms, surveillance systems, and understanding physical barriers.
Using tools like lockpicks, RFID cloners, and badge duplicators.?
I mean if u r bored of your pentest job, yea it's fun. But it's alot of work , and it can go for days or weeks
Yea that stuff , but I don't wanna learn it or anything. Its just i wanna know , how to get hired as a physical red teamer , i didn't find any job listings in linkedin
its probably something you get invited to do
Yea
Nah, its just u have to find a cyber security firm that gets those contracts
And it's not easy to find
On Linkedin I don't kind see that kind of job posting
Do you attend events such as defcon or besides?
That's what I am saying, its not listed
I didn't
For that you need to engage with community or networking kind of stuff
I mean they can guide you
I listened to people who r into that field , they just said they r into red teaming and get contracts from companies to infiltrate their buildings
That's why I am here , trying to find someone
Hi
Mostly that kindly offers services to the company
You can put out on linkedin
If you are looking for contracts or kind offer them your services
I don't think, they juts give those contracts to anyone, u can get them from your company which deals with offering pentesting services
That's why I am here trying to find someone who is into this and can guide me
Usually you go that way after being in pen testing for a while
You need to work for a company that offer it really
Liability and risk are obscene, not viable for a single person
gm thm
morning
Any names
im practicing the basics on my homelab and its wild how slow a UDP scan is compared to TCP scan
yea LO
I was surprised how long a paranoid nmap scan took ๐ https://nmap.org/book/performance-timing-templates.html
oh yeah paranoid scans take forever
I think someone here mentioned that they run a company specialising in physical pentesting. I forgot who it was but i think it was one of the guys with the light blue role
Community legend
What does light blue role indicate
Idk they probably contributed something to the community
I mean . What's the name of the role
Oh its this guy
@silver sky can I DM u , or just talk here , i really need to ask some questions about the physical pentest
Thanks alot
Gave +1 Rep to @south egret (current: #555 - 9)
how you feeling this morning
cold, its been snowing and my flat is freezing
yeah it's snowing where i am rn too LOL
I woke up and was like da fuck is that snow
it snowed last night here
idk I was asleep by half 1 ish
and my curtains were shut way before that
today I shall fix my vms!
I havent been outside yet because waiting for a delivery (if it arrives) and waiting for my partner to wake up. But the roof tops I see are all covered in snow but I suspect the ground is gonna be barren because yesterday a lot of gritting salt was poured onto the streets
ah
yea idk my rooms at the back of my house so i never rlly know
what goes on outisde
unless it's out back
and...it looks like I need to fix 1 of my vms
Black team?๐ค
gm scrubz
Hello
do you use vmware or vbox?
U can google
no virtualbox
Or you.cajntell, since you raised it.
this apparently
Thanks
Gave +1 Rep to @wanton ridge (current: #816 - 5)
oh, yeah idk why but vmware is being so annoying lately
idk abt virtualbox
Oh wow that's james bond cools stuff
Black like the suit man in black
apparently anyway, I only did like 2 searches to try find an answer while kali was autoconfiguring nw kek
That looks made up so people can do illegal shit
yea LOL
red team with extra bullshit
Most people go
Blue team > Pentesting > red team.
However there are a few exceptions.
it honestly just looks like a way of getting an APT on paper without raising red flags
He is not sure what he Wana do? ๐ฅฒ
gm jabba
Apt apt apt apr uhuh uhuh
how many times do you think kali will die today
Good morning 
3.14
Apt get install?
;-;
What apt mean ๐?
@rapid merlin I have almost solved my issue xD
Advanced Persistent Threat
lazarus n things like that
๐
black team literally just looks like a way of putting it on paper
Cool stuff
apartment
^
Got rid of Virtualbox and started using VMWARE?
scrubz vmware has been shit the last couple days
mustang guitar โค๏ธ
For you maybe.
okay
I really hope one of your vms dies
no
It's ok, they're all backed up with Snapshots.
dude i actually can't even install kali
it's just randomly getting stuck on things
LOL
Send screenshots
it was doing this yesterday, except it got stuck on unpacking hashcat-data (amd64) (I don't even have an AMD cpu or gpu)
is that virtual machine?
not to mention, extreme input lag; NAT randomly pulling a brick out of it's ass and not working
clang C compiler
well, and C++ Objective-C if that is your thing ๐
vbox would probably fix most issues, but at the same time; ew vbox.
[self rarelyUsesObjectiveC];
on virtualbox I have this issue where I can put all my vms on the internal network and all but 1 would be scanable
from my experience this is not related with the AMD CPU or anything I had this problem before just increase the storge minim storge to run kali Linux is 25G or something like that
hashcat probably wants it for the OpenCL
this lazarus ๐ ?
"The Lazarus Group, a cybercrime gang linked to the North Korean government, has been involved in several cyber attacks"
also known as APT38
Trying to upload a ISO to THM yet has been sat on 00.000 percent for 26 hours.
THM merch should have a THM lanyard lol. Unless I'm blind.
still stuck on the ss
.
no idea what causes it
got it from kali.org
fixed it
it was going so well..
oh it is
was just taking a while
almost there!
this CyberChef (room) is awesome
nice to have all the things in one place
IT FXIED
YAY
WHAT
evil windows
now it's just letting me sign in
wtf
was the image verified prior to install?
yea it was from kali.org
the hardware is ok? https://www.memtest86.com/
ye
Best korean group, before BTS
I am applying for anything related to IT
in my city
W
Need money to buy thm premium 
The salary range from post to post is ridirulous , some pay +10k a month , some 5k . For same jobs/ qualifications
o/ THM
o/
O7
Don't apply for SAP jobs
What SAP?
It's a fraud, shitties IT job ever
It's a program used by big companies
But it is so stupid and complex
But what does it really involve
As long as it pay and i don't sleep on the street 
I found a few IT jobs that I can apply for because the description is really vague like wow
This morning i applied for a vague job paying 12k โฌ / month . That said we need a guy that do HPC
High perfomance computing
Whatever that mean 
basically meaning they'll take just about anyone
does anyone ever ask for low performance computing? ๐ค
๐ค indeed
going through :Tutor in nvim rn
yay
Yeah it means I need to make up a CV for it and do a quick search on their "nice to haves"
Nvm they require 1 year experience in IT and customer support
I said i do c++ high perfomance ๐ฅบ , but the activities can be anything



