#general
1 messages · Page 621 of 1
A degree is largely to prove you're dedicated to pursuing a task for a lengthy period of time.
Now certs, on the other hand—
dang, im working on tryhackme and have 4 courses on udemy that i bought on sale its a lot of hours but im trying to learn what i can
you're telling me you'd rather higher someone with a college degree in cyber or someone with OSCP / OSCE3 and OSEE?
Apologies for asking about report work here. I was just trying to understand the root cause of such vulnerabilities. Appreciate all of your expert input!
Yeah, all my classes are more theory and a bit outdated in terms of content and barely any of it is practical. Hence, why I started using Tryhackme.
I wasn't being tricky, I'd prioritize the certs way more. They're direct proof, from reputable groups, of identifiable skill in a certain field.
thats funny because a couple people told me certs dont mean nothing lmao
guys when tryhackme and htb teach u 5 times better the material the avg college / uni teaches u something is not right I'm just saying.. it's almost like they're better learning sources 
You know how college degrees more or less come down to a final thesis that shows the peak of your studies and research?
man i love tryhackme especially the hands on aspect of it
Certs accomplish more or less the same thing but add on a sprinkle of field-proven effectiveness to the mix.
i totally agree, certs are usually more cheaper too
depending on the one you get
comptia+ bundles are expensive asl
uni materials and college stuff tend to go through vetting process so by the time it reaches the individual the materials might not be 100% matching reality
cheaper if you go via academic platform to get student discount (if applicable)
Eh you're usually looking at 400-600$ USD for your standard sec/soc certs (with some exceptions.) Still way cheaper than the full tuition at 7,000$ USD/semester
yeah youre right
Do you really need to go ComptiaA+ --> CCNA --> Security ? Or are any other options a little bit more direct
but even with certs they don't mean a thing if you haven't done your own due dilligence and experience
Depends on what you're doing/pursuing?
u can just do Network+ -> Sec+ or just CDSA (little bit harder than BTL1)
yeah, get some experience in IT and study for security to see if that's what you want to do
It depends on how you spend your time in college too
that makes sense, one of the reasons im doing tryhackme, so i can actually learn the process on how to do things
im thinking about installing a virtual machine soon to practice
I've done A+ / It was amazing for the basics, cannot complain. But I just feel like I memorised a lot of information that I don't know when or how to apply . Are the other 2 a bit more practical?
Guys I'm so excited. I'm finally sub 100k. 2.5k positions to go to sub 90k. Current goal is to reach the 75k mark end of the year.
looking into it. Thank you!!!
Gave +1 Rep to @supple forum (current: #841 - 5)
I find it interesting when people invest a lot of time in trying to find the most optimized path to a career ticket. Being persistent in doing something you love to do can sometimes be more rewarding.
I'm studying A+ cuz I bought a voucher maybe 8 months ago and I keep rescheduling it cuz I can't bother
. You don't need A+ in cyber trust it's very easy but u don't need to know cable types, screen technologies and how to troubleshoot printers 
hahahaha
Thinking about going for the CDSA, how difficult do you think it might be? Or what's it like?
i hate troubleshooting printers
so tryhackme SOC L1 path + HTB SOC path and u will be ready
A+ is a really good starting line. CCNA is really useful for generalized network understanding and teaches you the fundamentals of how network webs work, so if you're not confident in mapping I'd highly suggest it. Sec is always good to have, but can be substituted for other stuff imo
I have yet to meet a person that lights up and gets really passionate about fixing printer issues. Unless it is like Office Space printer repair.
I always try to optimize lolz. Its not necesarrly towards getting a fast path into a career. I just feel like there is a ton of information from different fields and I always don't know what I don't know. So feeling like always lagging behind makes you do that :)))
Alright, thanks.
Gave +1 Rep to @supple forum (current: #743 - 6)
I have no trouble shooting a printer... Doubt the company would allow me near one afterward though... 🤣
Roger, thanks!!
lmao
the classic scene
Ugggh brain be tired. Been going at THM rooms for a good 3 hours already. All so I can get to my Goal of 75kth
stomp town
I'm giving its 21 December but I've given CBBH already that one was tough, I don't expect CDSA to be tough just sneaky malwares in pcap files or in SIEM tools, will probably need to read query documentations but it's not rocket science, also I think THM SOC path is amazing it teaches so many tools so u get the idea from different perspectives
that is a good team building exercise
As far as the job market goes, your most useful weapon is knowledge. Knowing a lot about the common things will get you a better chance at a foot in the door, from there you start thinking about what you want long term. Blue teaming, red teaming, distro analysis, etc...
you mean disco analysis
eek
If I just need penetration tester for a security audit or penetration test I'd hire an oscp. If I need someone who can do various cybersecurity skills and roles probably someone with a degree and a few low tier infosec certs
I'm not really fighting to get in the field yet. I have a pretty chill job that allows me time to learn. I just wanna learn as much as I can now, Its genuinely enjoyable lolz. I was asking about the Certs mainly bcs I wanted to find a learning path that makes sense difficulty wise.
like what? entry roles are either soc analysts or penetration testers and there are certs for both
@finite granite we in the same boat. Currently my job is paying me to be a full time student. So taking the time to go hardcore mode into studying as much and as varied as possible.
Cybersecurity isn't entry level . Typically you would want some IT certs or experience prior to doing cybersecurity work
Certs are like a tree. Pick a good base and slowly build up, maybe strangle a lesser tree to death and absorb their vital nutrients, you know
I'm not saying cert > degree I'm saying it's proven experience on a subject while degree is general cybersec knowledge that u might've forgotten, hell I passed linear algebra in cs uni in first year I can't even explain u what it is 
So I gotta go fully Necromancer Druid multiclass, roger
Degree shows you can do academics and have a small amount if knowledge in various areas in technology. A cert shows you have alot of knowledge in one specific area.
that is a wild perspective!
that's so cursed
like sinking into a black hole
Singularity
I'm just saying if ure going for a soc analyst role and u have a degree and another guy has no degree but has done lessons on THM/HTB and has CDSA or BTL1 he's taking the job not u, so pay attention to certs too don't give all the focus to the degree, degree is just to pass to the interview stage, after that u need experience in the position to answer the questions they ask u
Ultimately the hiring manager is gonna pick whoever they pick. Certs might be really great, but you might have a terrible personality or poor socialization. Some stuff helps, some more than others, but there's no one way ticket to success.
usually if the resume looks okay they pass u for an interview with the soc manager and then u get asked questions about the role and the tools used, protocols, and theory
no degree will help u there but THM will 
Usually, maybe. Not disagreeing with you, just saying the amount of categories that go into choosing the perfect candidate is an eldritch machination known onto the people performing the hiring.
I've personally seen extremely well qualified candidates get walked over for poor behavior over people that didn't know much but were approachable and teachable.
Talking from experience in hiring, firing, promoting and demoting. There's a ton that contributes to if you will get the job or not. Most out of your own control, but the things that are, is mainly how well do you know things and can your knowledge translate over into practice. Companies would rather hire somebody that can do the job, than hire people who know the theory behind something but will need to be trained up, unless it's an entry-level position or if it's a teaching position.
I watched a hiring manager take 50% of the stack of resume/CVs, throw them in the garbage, and say "I don't want to work with unlucky people" 😮
insider threat avoidance 
I hear ya
Luck or lack thereof isn't a protected class, nor is a typo on paragraph three line four (everything else was perfect)
yet not all environments are a good fit, or healthy
you had me at luck, after that i lost you, you started talking witchcraft 
Yeah, it's not. You get shitty environments and those 'Unlucky' ones are actually the lucky ones for missing that toxicity
To add onto this for anyone seeking work -in any subject, really- the interview process is just as much you interviewing your potential peers/superiors as much as it is them interviewing you.
100%
Man probably thinks "gah damn I'm lucky" and just threw away 50% of his best candidates
hell yeah I want my soc to be a battlefield with the manager screaming on top of his lungs every time a major attack happens
burnout in a person who really should not have been in that role
preferably at 4 am in the morning
that's the fun

What are the consequences of faking a CV
Sometimes locking in consists of taking out all of your repressed rage onto people desperately trying to prevent a database leak
If you don't get caught? None.
Impostor syndrome
I need them to rally the troops and say: They may take our systems but they will never take our Freedom
Speaking of if anyone needs me to be a reference, we were best buds at your old job
Do I want to go out and grab coffee... or make an espresso at home....
Make an espresso
Nice will take you up on that one day
espresso for depresso
Espresso yourself
Can you help me fight HR?
Sure, clean or do I need to bring a bat?
2 bats at least
What type of fight are you having? Because I shot our HR once... Her photo is still on the wall of shame in the pub...
can you invite someone to join you for coffee?
o/ people
Full scale war, they might use sarcasm and office chairs to stop us
studying time, only 2h late 
I'm ready, just hold my tequila
Seems like, HRs are not doing annual increment globally.
logging off, gotta start my shift 💀
Enjoy
Ciao, have a good one
Thanks, Ill be back to do some rooms in around 8h lolz
who help me with a little problem with openvpn on kali linux... please i can't use him for do a box 😭
Any cybersecurity Christmas gifts for someone who likes cybersecurity
Hystoricaly there was 1 dude that faked his CV to be a military surgeon , he ended up learning well on the job and saved many lives
Also that one lawyer dude who had a flawless defense record for like a decade.
what is the problem ?
A brand new mini tower preset with oled, traffic monitor and kali linux pre installed (you didn't specify a price)
share complete details so one can help you. @royal glacier
Damn
If only
buying your friend a bunch of mystery hard drives from the thrift shop
Wow I’m sure his conputer would love that
Computer
digital forensics
when I run the command with sudo openvpn with the download path, I can't access tryhackme's IP (10.10.10.10) the vpn
i can't send picture
Sorry to ask for help with something that must be so basic.
And if you run Kali or Tails from USB on you won't be putting actual hardware at risk either (at least not hardware you care about)
was connection initiated successfully in your terminal message? If you're running sudo openvpn ..., try rerunning it 2-3 times. If it still doesn't work, change the server or refresh the OpenVPN configuration file by downloading a new file from the server.
No problem we are here to help 🤝 @royal glacier
https://tryhackme.com/r/room/openvpn have a look on this room it will guide you properly.
thanks i go try this
Gave +1 Rep to @brittle drum (current: #985 - 4)
A keylogger running from a rootkit residing in memory on your main computer might be able to see that since the live boot from the USB is stored in RAM
.
Yeah that's a risk, but you're not putting an actual device in danger aside from whatever you're sacrificing to run and boot the hard drives.
As opposed to network ssh or somesuch from a dedicated device that could be ruined.
A USB that can fit all of kali is like ten bucks, a server+tower+potential escape is... more
Yeah there's a lot less of an attack scope that way for sure
If you don't configure your network right by segmenting or using proxies, vpns, updating OS's etc then that could pose an issue as well
I might be missing a few things
There's a ton that can go wrong. If it's something that's scripted to detect a network on boot then it can reach an outside CSS or host server that can do any number of atrocities
Isolation with an unfamiliar harddrive is always the best for analysis
Couldn't this be countered by altering the boot process or maybe even something as simple as secure boot?
when i start this command ? "sudo openvpn /path-to-file/file-name.ovpn" . Must it end or run in a vacuum and can I work during this time?
If we're talking about containing malware, we could de-attach it from the internet, although that's not great for dynamic analysis
Of course, that's one way. Typically during analysis you wouldn't be using an external computer that has access to the wider internet anyways, so that shouldn't be a concern. The vast majority of malware needs to be activated in some way, usually from an outside source, but ransomware could still be problematic if its activated by fileview or an unintentional run command.
if you analyse malware with an internet connection, you shouldn't.
“Just don’t”
it's generally a bad idea
yes , keep it open and running . open another terminal or split terminal for work.
I’d say it’s always a bad idea…unless it’s like completely isolated for anything else on its own connection and you want to activate it
You could change the outbound rules of your firewall, router, etc to drop all outgoing packets though through known C2 ports to effectively trap them
So yeah generally a bad idea lol
Closing the terminal will end your connection to the box/challenge, so it's a good idea to ping the challenge box IP while the command is running in the terminal. I recommend learning Tmux.
@royal glacier
And if they dynamically try to change their ports to try and bypass that, you can shut down your Internet and analyse it
If you're determined to test malware in its natural, intended state since most won't run when they don't detect a network output, you'd probably be much better off using other devices on a closed map to spoof webtraffic to see what it does.
@royal glacier let me know if you are still unable to ping challange machine.
Use something like wireshark to catch its output search
Then you might get the chance to do something neat
i think im lost ... when i try to connect to the box the web page loads ...
YAY SHADOWS PLOOPY STUFFS IS HERE
That's a good idea, there's stuff such as fakenet with is pretty neat. Just mimics a network
open source hardware maker of headphones and mice and trackballs located in canada
Gorgeous
the cmd where I launched the command is still open and working (always displays info)
Interesting never heard of it
Weird name tho
Ploopy 😂
found them when searching for mice with qmk support
and because shadow is lazy shadow ordered the fully assembled kits
Yup. Luckily if you have the malware package you can inspect it in any number of ways, but from there you can ping/nmap the ip that it was trying to reach, check its return signal, do any number of things...
No problem will try my best to help you, go to #room-help and share screenshot where you are unable to ping.
and when shadow says open source hardware they mean it: https://github.com/ploopyco/mouse
they have full schematics and everything to 3d print and order the electronics
Do all the things fr.. Now imagine a ML program that takes attack chains and makes more attack chains, then combines them into an exploit to analyse
i cant share screen shot its normal ??
Analysing attack chains is the next level unless you can reverse engineer the malware well enough to understand what's its targetting
The chaining
you are allowed to send me friend rq and DM.
yes
thanks
Gave +1 Rep to @brittle drum (current: #842 - 5)
@royal glacier
^ this one @royal glacier
can anybody recommend any good powershell resources
thanks
after that you can post images here
You should be able to file inspect and check its root commands under most circumstances unless it's been encrypted and only deencrypts when it receives a return signal - but once you capture it from the host ip on another device you can just fake it to trick the malware into activating on an inert drive.
A lot of malware is designed for Windows, so you'll usually see powershells that download distributions from the host ip's server or maybe scp gets depending on what they're attacking
hmmm
Anybody got an invite to JH's discord?
Gotta think about that one NGL. So it's like a hard coded IP that you trick into believing is communicating with its hard coded C2 server but it's actually communicating with your spoofed version?
Exactly. You use the false network to capture the malware's initial ping to our villain's host IP, which you copy and actually send, then capture the response, feed it into the malware to activate it safely, and bob's your uncle.
That's actually cool as
hey I have some questions for student discounts. My student email is not recognized so I have to apply for it manually. What are some things that could my application to fail?
You'll need to contact support to manually verify it.
Id assume different C2 architecture would require different strategies for actually adapting your detection mechanisms to what the malware is trying to do. But you could probably analyse the system calls and trace back from that too
Not sure how much deeper it gets though, I don't have experience like that
Malware is also reserved for our advanced channels, if we can keep discussion to there please. @graceful mauve @mellow gull
Whoops, will do.
Er, that was for scrubz
Yeye
Have you tried Google 😄
I don't see no advanced channel
We still newbies out here
You need either lvl 13 on the website or an official OCSP/eCCPT cert
Check the doc I pinned 😄
I only had a little more to say anyways so if it isn't a problem would a DM be fine?
Yeah sure
if I submitted the necessary documents, will I be eligible for the discount or is there any other criteria I need to fulfill
If you have proof you're a full time student, you'll meet the criteria
and what should I do if my enrollemnt documents are not in english
It's ok, I'm sure they will use a translation tool.
Am I being dumb. In this advertisement for moss it says 5kg has a volume of about 25-40 litres
Like wahhht
alright thanks
Gave +1 Rep to @sick lance (current: #1 - 3096)
Never mind I just found out you can upload images to ChatGPT
And ChatGPT explained it perfectly
Hi!
Hlw
Hey, anyone got any advice on writing a write-up for a THM room?
Hi 🙂
the point of moss is to stack up on water 😄
🎄 🥳
Advent of Cyber 2024 DAY 12 Let's Go!
🥳 🎄

how long does the process usually take
adivce rSupport are really busy due to AoC.
nice to block me when you offered to help me in mp
yoo beerise
Ugh, I want to work on my server, but at the same time, I don't want to setup the whole, monitor, keyboard, mouse crap
Hi
It’s also airy so the roots can grip
Don't most SSD's lose some storage when connected?
do I have bad memory or is there a new "certificates" tab in thm profiles? 👀
So do HDD's... but they're listed as 1 TB, not 960GB'
well it doesn't appear on public profiles I'm guessing it's new 
True, idfk then 💀
Storage devices differ in some storage when connected because of formatting and windows displaying the wrong unit for storage
Not lose, no.
It's just different people measuring differently.
960 means its a 1024 drive with space allocated for wear leveling etc
Some companies like measuring before format and after format etc and then there's Microsoft, showing the wrong unit lol
Nah it's the storage companies using an advantageous unit
Whatsup everyone?
It's usually printed on the media too, they define 1mb or 1gbit as some power of 10
How it going
Windows USES GiB as a unit but displays "GB" on the label in file explorer (and everywhere else)
GIB is GB
gib is this
Its is just less of gb
a GiB is 1.07374182 GB
Windows would say a drive is 1.07374182 GB when the drive is 1GB (Not accounting for formating and other stuff)
hello guys, where can i find room for advent questions? 🙂 Have a problem again with portswigger
#1305926862114914325 is the preferred channel for AoC
thank You guys ❤️
This one goes out to YOU: ❤️
YOU as in: you all
Have a great day fellow phreaks and geeks
Good night ❤️
i won the race condition 🎉
Congrats 🙂
спасибо товарищ | thank you comrade
Gave +1 Rep to @cloud quiver (current: #7 - 1206)
English only please.
gg on 1.2k rep kgb
Well , she provided translation 🙂
yea, i thought having both would work, but ok
No, because mods might not speak that language, and then they have to translate it to ensure it matches.
So it's easier if mods don't need to translate any text that is not English/encrypted/encoded
heyyo
o/ Bella
no hints!
Why no roles?

Left the server and came back
oh
Ok, sorry for asking
yee, slowly coming back again
welcome back, hope your feeling better
I have limited myself to only a couple of hours on discord a day
hi
still not working, but slowly going back to that again
the black void is significant?
the void isn't always a bad thing
indeed
@strong flicker LEMON
Welp, good news... network cabaling laid out, bad news, still haven't decided on what drives to put in the server. I want speed, and reliability, cause logs go brrrt. But at the same time, don't really wanna "break the bank"
@chilly veldt Bella is back!
for a couple of hours a day
Awwww
Herbal tea helps, and if ya need someone to talk to, always here.
that's valid, I hope you feel better again soon
but yeah, my body went into shock tuesday due to the amount of stress I have, which has left me to now destress, think everything through and slowly get back to work
This life thing seems pretty stressful, might leave a negative review
Screaming helps... atleast for me.
I just don't take it seriously, super cope 😎
not helpful lmao
If using Google is googling does that mean using edge is called edging ? 🤔
dude🤣
Well I do "do" stuff seriously, but I don't take it seriously
I get some points there
Hope you can destress and feel better soon, hopefully your workplace realises how badly they were overworking you and eases up
Hi
asking the real questions here 
Anyone want to add me as a friend???
Im rank 32k, trying to get some people to compare with
Add me if you want 🙂
Don't be comparing yourself to others
User?
Its for fun
KGBTHM 🙂
Makes it more engaging
fair, if it works for you, I'm not one to go against that
Sent ("Olbap")
Hi all.Going try my luck here.. Where can i get training videos for Mikrotik? Videos that i can save on my pc
What rank are u unc?
10k looks like
Cool
But 1 in our heart
u old dwarf 🙂
Youtube? idk
Yay , we're friends now 😄
15? 
why my attackbox is always lagging
May be congestion on THM side 😦
Hope not. Because it's bad today. Like even my internet felt it.
If u have any other laptop laying around it's the best time to try and install kali
Or on a usb
It isnt ideal
why
damn. Guy just has laptops lying around
Kali is meant to be used as a tool, mainly on vms
ah
But if u don't have enough ram then install it
Doesnt need to be Kali.
Just Kali comes with the tools. they can all be installed though
Thats true
@glass nest had to repaint laptop lid and did it again
shadow might have found the craziest bug they have ever spotted
The owl looks ay more detailed
where did you get your stickers from? they are awesome
yea. fit perfect colors. same as tentacles. will take zoom pics
not stickers. laser engraving
I had no idea you could do that! thats awesome. I wish my laptop made in plastic
and in app they add laser delay so it give more detailed results
this is not plastic. is metal surface. and it can be done on plastic also. kinda
for some reason ghostty ignores shadows aliases
@lament tendon u approve owl ?
Bit's gonna be all like 'Dude, Stop doxxing me!' 😄
can you make file with aliases and include it in config?
yes
it is weird as meeps
if running which alias name it outputs the alias
but when running alias it outputs none aliased version
I'm learning passive recon but the requeriments to I learned networking but it just remain me linux fundementals
I learn little but I feel boring I need it like playing
Why do chicken coops only have 2 doors?
||Because if they had four, they'd be called a Chicken Sedan||
I finished before I will repeat it again
Fundemental can get boring. But once you got them sorted, the rest of the journey is more fun, because you'll acheive more
What u mean sorted
Once you understand them.
U mean the commands yes I tried it I write my own note
Hrm, buy drives now, or buy drives later..... do want to get this server up and running
I liked it
🥺💕.
Because I finish the basics
no no, I mean the fundamentals. also known as the basics. Its the same as with any task in the world. Once you have the basics learned, Then everything that you learn from then on becomes easier to understand
i have great dark joke but nsfw lol
DM
knowing commands, is part of that. but so is understanding how networks work. What the computer is doing when you load a webpage.. all that stuff
"why did non-beehive child cross the road? cos didt put seat belt"
@loud marlin sending me cryptic as fuck messages lol
What do you call a lazy kangaroo
Betta.system?
I'll have you know that I'm not as lazy anymore
I now how to works networking in osi model
Great
But The requeriments for recon passive I finished networking but need linux to finish it
So I will learn command and I want to be transpent
The ternimal and wallpaper
To make more soft🥺💕
So use Linux
Ubuntu 💕
Good. Have fun completing it 🙂
Not AS lazy.
So still lazy.
speaking of ubuntu ive been thinking about replacing windows 11 with it
Why not, faulty. sounds good. once it does what you need it to.
you could go the 'safe' route, and dual boot with ubuntu. Means you can head back to windows if you need to 😄
youre right, im gonna weigh my options
ubuntu is a good option aswell. Theres a big community around it, so answers to different challenges are found easily
every day smth new 🙂
Hello, I am a human scientist and I can confirm that being to a reasonable extent lazy is biologically natural for majority of mammals. Through evolution only the most energy efficient ones survived
heloooo!!
first time i found out about ubuntu was when my boss made me install it instead of windows with a bootable usb and he wanted me to experiment with it, pretty cool OS
They get even cooler 🙂 Ubuntu is the 'easy' version of Linux.on the other end of the scale you have Arch, which is a pain in the next, but waaay more customisable. @loud marlin loves showing off his desktops 😄
thoughts on australia's social media ban?
tried asking for the usb to install it on my laptop but he said he erased the usb😭
Eh, USBs are cheap and easy to get :p
Here is a tool for privilege escalation od Debian based distros. I hope you will find it useful in you learning paths and more. Tested on attackbox. Enjoy! https://github.com/ValentaA/Automated-suid-privilege-escalation-tool
yeah i have one it just has my certifications on it, probably gonna use it eventually
either way, super easy to get a new one 😄
Hi everyone!
sup Jin
hey jin
i might be able to get the penTest+ cert depending how things go, really hoping i can get it
As in...Get your boss to pay for it? I've no doubt you have the skills for it
sup guys how are you all doing?
Eatin' gingerbread. so yeah... Pretty good 😄
Nice
I am new in the field of Ethical hacking so looking for some guidance
Cos it's near christmas, Lidl has all the christmassy german snacks.. like Lebkuchen
eatin dinner, also good
Good good
wbu
Thats good Jin. have a look at #start-here . Tryhackme can take you from 0 to tacking tricky CTFs 🙂
All good, it's 1 AM here just laying down
well im still learning so im not gonna take the exam until i know for sure what im doing, also not my boss, stuff happened a while back and i basically got money for education but we havent been using it so my mom is seeing if we can still use it
has anyone used Redox OS ? looking at it, seems like it would be cool to try
@glass nest i think im done... still have space...
that looks sick
Thanks let me look into it
Gave +1 Rep to @glass nest (current: #17 - 504)
ralex, you can fit an 8-bit 1-up mushroom in there. Easily.
ploopy headphones sound nice
Faulty - Sounds good. Regardless of how that pans out, may aswell keep learning 😄
find one pls 🙂
Yeah man im trying to get into pen test cause it seems fun (and pays decent from what i read)
cant do that. normal img for engraving
Yes, my old Discord account got banned and I wanna link this account to my try hack me account.
Everyone wants to be a pentester
Start by installing ubuntu already
If I had roles I’ll show you my tat
im fixing to, i left my usb stick at home so I'll have to grab that
this ok ?
Hello
whats up toxy
Looks good. Thats the one I have on my other arm 😄
Whats the best AI image generator rn?
Depends. Are you AI?
I need to weave some pots
doing test run...
Free you say
I was joking, but hey. I'm happy to be indelibly engraved onto your hacktop 😄
im about to get the 0x8 hacker title!!
But limited to some uses each day (create throaway accs)
What abt you
I'm excited for your acheivement, Toxy!
Pure commitment
nice! im doing good, just waiting until payday to get tryhackme's premium because im broke as a joke
Nice!
this better then 🙂
Ah. This is from that cartoon you told me about?
Ohh okay
Is it a website ? Or one of those discord ones ?
CARTOOOON????
YOU CALL DEATH NOTE A CARTOOOOOOON?
yea... google it lol
Bella - Yup. Just to get that reaction 😄
ill engrave tommorow... going in night shift soon
Site
Ohh okay thanks
Ill dm u some pics I made
Write my name
I'm looking forward to your circuit board project, Stealth
nah... for "special" ones only hehe
d'aww
Thank you bro
Gave +1 Rep to @glass nest (current: #17 - 505)
How much further you got to go, Toxy?
All the projects, look at these pots
Nice maybe Ill get it too
You made them, Stealth?
Currently I’m using my money to just sort my flat out because I moved in three months ago or something
They’re AI generated, I’m gonna make some :3
anybody here a math nerd
About 40 points
However the beads will be more dainty and fairy like
oh nice, Stealth. I can't wait to see them
I’m getting a new toilet seat tomorrow 😄
Esqy, do you know any good apps for drawing & writing things down interactively
Actually excited lmao
excali something is one I can't quite remember it
no idea - I'm not really an artist or anything
Stealth.. Yeah, I don't need to see that. BUT I do wanna see anything you make and build 🙂
Const - Mathlab popped up in my brain. Dunno what it does, but I've seen it mentioned
You got banned?
has anyone else gotten phishing texts like these in the past year or two? i’m wondering which threat group or tooling is responsible for them
Nothing like that.
Analysis would be for our advanced channels
But it’s black and made of wood 😂
:hammer: iamcaesium#0 has been banned.
Oh dear
Ok. And keep the toilet stuff in the bathroom 🙂
I’m so excited that a room is going to be finished here
Seriously, been waiting long enough
I've got everything I need to paint now!
Paint-filled water balloons?
@boreal scarab what is the best beginner lock picking set if you don’t mind me asking
Oh nice, send a pic when you’ve done it
yeah, it's pretty cartoonish :D
AceS - 😦
?
I want a lock picking set too
I do loads of lockpicking for fun
But I’ve not got around to that yet
I will get one eventually
Honestly, any. Once it has a tension wrench, a rake or two and a couple of hooks.
Worst case, one snaps then you buy a good version of that one.
Sparrows is one of the more well known brands
Amazon got one
You also have Lokko, Southord and a few others.
Got it, thanks esqy
something like this is perfect for beginners
The practise locks are good for learning, but will get old quickly 😄
I will do. Got quite a bit to do to be fair
I bet
Mostly prep because the wall is kind of fucked
I feel like it’s kinda cheating since it’s see through
I actually do wanna pick up a mortise lock pick, so this was a good excuse to be on that site. Thanks Aces 😄
Yeah. But its a good way to learn. Can cover it in tape to try it without looking.
Then buy cheap padlocks from.. well anywhere. jumble sales, dollar stores..
Nice, I’ll show you my bathroom when I’m done
You gotta learn where the pins are
So I guess it’s easier to learn like this
True but it’s mainly feeling no?
Yep. The see through one lets you see whats happening and why it feels that way, y'know?
Ah yes
What AI is this
Leonardo
idk why but i feel like ai is too old thing but it revealed to the public just the last years x//
guys how i can know if i pay on AWS on THM
You should have access to the AWS rooms
Hi hungry
VARG
It's ya boy hexxxy but shhh don't reveal that I'm Santa 👀

I'm not taking down the gun btw
You understand
But gimme a hug you cheeky bastard ♥️
Oh yea, that looks sick af!
I got two racks, I'll be okay 
How's things down under dude?
What will you like to eat
Tomorrow we install.... PROXMOX!
beautiful
I eat a lot of Korean food
dual ssd nice
32GB with 2 sticks, more than enough for my need
niceee
Going to be in a RaidZ1, so just 1 TB usage. Could go for 4 SSD's, but meh, for my use case, not needed.
beerrise when are you getting 0xD
??????????????????????????????
vain has already done it so why not you too
The m.2 is the boot drive for ProxMox, SSD's, or the M.2 will be hosting the VM's, haven't decided yet. But logs 100% going on SSD's
When I get off my lazy ass and log into THM lol
i will the OxD at the end of december 👀
Recently had the opportunity to test a 1TB ram server. It was awesome, the performance was beautiful
BRRRRRRRRRRRRRRRRRRRRRRRT time?
Wonder what it's at now...
Less today, nice
I only have pizza for you at the moment
Perhaps when I cook another
Server almost gave me a heart attack.... thought one of my main drives was about to error the fuck out.... nope, was one of my SSD's doing metadata VDEV crap
What time?
Also btw in Serbia hacktivists hacked a government website made for targeting students and buying their votes.
The corruption here is next level
They transferred a domain and changed the site 
All for hacktivism.... if it doesn't effect me 
Nah people here are so fed up with this corruption
always has been
The ones who are voting for SNS (a political party) are old people and they just don't know or aren't educated enough to see things for what they are
ai generated
sooo you are saying you are wasting the opertunity for prices by not doing advent of cyber???
What type of pizza ?
have you tasted Nutella Pizza ?
GUMMY PIZZA
we had once at army , they made pizza one day , and the rest of bread came for breakfast ^^ best bread for nutella ever
US? Or ally to US?
come on beerrise stop slacking of and go do advent of cyber
just so you can win the defcon ticket with acomidations and give it to shadow :P
But but but but but... that means I have to turn on VMWare, and then login, then connect, then not be lazy and read shit
no shit is written here 😠

But reaaaaaaaading!
you can also just watch the videos to get the answers :P
so python package become crypto miner...
https://blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection

I'm slacking too for AoC. Been busy with an IAM project.
shadow is trying to figure out why they smelt burnt plastic about 30 mins ago that then stopped after unplugging a thingy
that kinda sounds related ...
I'm going to take a wild guess that it isn't a 3D printer or anything that shouldn't smell like burnt plastic
If you used a low temp filament and it got stuck on the hotend and you heat it to higher temperatures it could smell weird
Too long, I need it in 3 minute long videos in a vertical aspect ratio with Minecraft parkour and subway surfers on the bottom and top
in that case yes. by default not have smell. aside of ones that are dangerous for health like ABS
Yeah, I only print in PLA, so I don't have toxic smells in my bedroom (also because I use an ender 3 that basically can't handle anything else)
and glow in dark can have hard smell due to have fluorescence DNA... long story shirt... that DNA thing smells like hell or two
Yeah it was banging
I've heard glow in the dark filament can have other issues when 3d printing too so I stay out of it
I’m actually not keen on sweets like that tbh
oh you have blue hair haven't seen it before
Oh yeah blue and pink
I also put effort into makeup today too
I took that picture today
they are quite hard for brass or "softer" material nozzle's. so harden steal is needed for long time use if so
you pretty 🙂 
Makeup magic haha thanks
Gave +1 Rep to @dark frost (current: #449 - 12)
Hey 👋 Just want to pop in and say I really appreciate AoC and the tryhackme platform. Really awesome work! Well done! Have helped me a lot in leveling my knowledge in certain areas 🙌
How are my fellow hackers doinggggg
Yeah, ender 3 nozzle is brass so I'll keep staying out of it for that reason too
(I don't dare do any modification to it, it works and I don't want to burn another 3d printer motherboard 🙃 )
tbh... you look like bisexual squirrel =)... ||no, this is not insult||
So close, I’m a bisexual racoon
i have k1c and CR10-smart-pro. you can easy mod your one. @boreal scarab have also ender or some like that
i was close then
slowly a depression grain germing ...
jokes on you, computers the only shit that make me forget mine
I felt a little anxious so I got in bed
same that why i am here , but when i return to reality , it hits hard
now shadow wonders if a tungsten 3d printer tip would work
Me and this cat sharing a brain cell rn
how to turn dark mode on thm website
Haha...I try to incorporate cyber in a way that it is my reality. So no matter whatever bad shit happens I'll think of a new CTF I managed or something to give me joy instead lmao. But currently I'm very busy so back to depression lmfao
currently there is no official darkmode so most people just use the browser extension called dark reader
It cost some money but it does exist
That's the million dollar question
Ender 3 V2, may it RIP.... now I have an Ender 3 V3 Plus
neat as tungsten has some interesting thermal properties
there is ruby tip ones
which shadow just answered :P
I wish I had one with a BLTouch (or CRTouch or whatever)
I know! Also, greetings shadowwww how is beautiful and talented shadow doing, I wonder??
My V2 had a BLTouch, Olson Ruby Nozzle, All metal hot end, PEI sheet, Stronger springs
Also had OctoPi
Now my V3 plus autolevels, already has a PEI sheet, can already print abbrasive material OOB, and has web cam I can plug in and access it's web interface
tysm for the extension. Works like a charm, i'll cry
Yay Fish!
I bought a BLTouch but the instructions were wrong, the Ender 3 models have slight changes (even the ones named the same name) so I shorted the motherboard and BLTouch :(
damn SORA does really decent anime images lol
That I got running though, flawless installation unlike the BLTouch
You mean videos?
well banging head against concrete wall to get past side quest 3
Getting all my tools sorted on my new VM.... and this face is just stairing into my soul....
Sora doesn't do images? DALL-E is the image generator
could be a different one, says sora on the box lol:
stuck at the keycard have no clue where to start ... is the race stuff the solution ... ?
well for the side quest there is a strict no hints policy
but can help with regular advent of cyber
By app.xiaoniuniao.top
i know 
yeah, chinese can take my info for all i care about
Looks like typical NY style pizza.™️
LOOK AT THE ANIME CHIBBY SPOODER
Hey hackers
I have a problem with my connection 😕
I can connect with my vpn ,but when I do ping on my machine it's not working
Sora is the AI video one
https://openai.com/index/sora/
Dall-e is the image one
https://openai.com/index/dall-e-3/
-# pointless "argument" we are having lol
Testing my judgment skills. Is he dumb or an over-smart idiot.
screenshot
I tried to use Outline but not working
Are you in Mexico? What's with the unnecessary orange overlay? lol
I think he has night filter on monitor
i love how you started calling the AI 'bro' once you started getting frustrated
I love seeing how people don't know how to use chatgpt lol
Correct
night filter = Mexian VPN?
Every single day.
I was watching jumping spider videos today
a jumping spooder?
yeah it's cute, but i wanted it to be more nightmare fuel with a cute spooder
sooo tireeed
you should try a danger noodle or a nope rope
my neck is hurting
bad sleep ?
idk
you got a tumor the size of your heart in your neck
NO DON'TTTT. u got this ma'am
that was a metaphor but fair
Oh! Sorry I have a dark past with such events :). I BELIEVE IN U
Well that was a great AOC day
well... you getting old 🙂
yeah there are things shadow might do but hurting themselves much is not one of them
Working on advent of cyber too rn! Finally found some time
I'm very proud of Shadow
I’ve really been enjoying AOC
I went to uni with a staff member love the dude he knows who he is. And he insisted I did it cause it would be good for me and lots of fun
We are all always proud of shadow!
I’ve had snakes before in the past
Just found this "Dystopian ads in San Francisco about AI employees"
chat is this real
Seems like it
They forget hacktivists?
I think it's just to promote fear of AI, no actual product
Fear of the plagarism machine?
JFC...
Get an ad on youtube for a bullshit VPN, was going to see their privacy policy (if they had one) couldn't access the site through Browserling, Urlscan.io, or my browser...
So, did a whois on the site..... these idiots have all their info on it. Is it real? dunno, but omfg
VPN market is oversaturated already
Hosted through AWS too, and NameCheap Registrar
Throw their address in, first result... "Malware Analysis Report" ... beautiful
your OSINT skillz are a blessing and a curse

Now looking up property records... if this country has them
I'm honestly surprised about the whois thing, NameCheap should have whois protections, did they disable them on accident?
Fweah
@glass nest You don't happen to speak a certain Nordic language.... do you?
Afraid not. You got Bella and i think Heapoverflow is learning one of them
I know swedish
Don't think Bella speaks this particular one
Finish?
Icelandic
Iceland challenges you to sing The Hardest Karaoke Song in the World! Try to keep up with Steindi and discover the A-Ö of Iceland.
Give it a go and share your attempt #singIceland.
Discover more about the the A-Ö and you could win a trip to Iceland. http://www.inspiredbyiceland.com/a-o
Song lyrics:
This is the a-ö [a-z] of Iceland, so tr...
Yah... Property records site is, of course, all in icelandic
ihy lol
Haha
hey guys when the advent ends will we still be able to try them?
Before 0:40 I was just thinking, Icelandic is that easy? And then the real Icelandic hit
Advent of Cyber 2024
Yes, you can still do last years
It's a very catchy song 🙂
And kinda makes me wanna visit there. so I guess it works :p
great, thanks :D
Gave +1 Rep to @finite tulip (current: #241 - 27)
So far, they have 3 sites. No data on whois for 2 of them, but all point back to Iceland
Are the side tasks impossible for beginners?
Dunno, currently doing my own OSINT shtuff
Ohh okay. Good job
YAY shadow ported their ploopy mouse from regular qmk to vial
Omori pfp?
evening
Good midnight to you
Governance & Regulation has to be the most boring room on thm
GRC is somewhat boring
I've never honestly done GRC, no plans for it
im studying for my pentest cert thats why
what does pentesting have to do with GRC
lol
maybe you should read
I literally can't explain it
without writing a paragraph
Governance is for like HIPPA or some stuff Regulation is what HIPPA protects ig and the c word is
compliance
how the company complies with the stuff
yeah i learned that
Ran the APK of the app through virus total.... Now, I'm no expert on reverse engeneering, that goes to Scrubz....... but when I see execution parents of files in the APK going to malware..... That kind of raises a red flag to me
idk I'm tired and have been demotivated asf lately icl
Call me top dog
but I've always been demotivated and never wanting to do anything but sit in darkness soo
idk
Don't think I should be seeing THIS much red... jfc
💀
Didn't know VirusTotal could sandbox APKs, that's neat
(red means Christmas presents)
You found the holiday cheer
It's pretty cool, you just need an account on VirusTotal to see it
Sily question but why does the ai assistant button obscure letters 🗣️
merry xmas
And that's just 1 zip I opened too, there's MANY more
Do you? I mean I know you do for that kind of image but can't you see network calls (atleast on exe files) when logged out
Anyhow doesn't really matter I probably have an account, if I don't it's easy to create accounts
Edit: I thought you said url bit you said execution parents so nvm
That's the best part... no. I downloaded an APK of this sketchy looking VPN I got an ad for on youtube, did some digging, they registered the site out of Iceland. Nabbed the APK, see what it's doing, and boom, Christmas lights lol
You downloaded what now
APK, of a shady as hell VPN app
yeah, it's secure
At least you saved the link to the ad to report it later. Right?
trust, make sure you put in your bank details, name of the street you lived on, mother's maiden name
Oh 100%. They also are hosting it on AWS, so going to them too.
the 3 digits on the back of your card, expiration date, your favourite childhood memory
YouTube/Google should really step up their ad moderation with all the scams and even viruses
chat can malware execute without opening the downloaded files
the name of 3 heretics, the call ok kthulhu, blood of a vampire and a starbucks cup
Does it make you feel better, that even Apple let it through?
"it's complicated"
(I see into the future)
whichever order you prefer
No, not really lol
Just saying that YouTube has a lot of scam ads (MrBeast giveaways for example)
When they try to scam me but I have no money
Are the security questions a real thing, I never ever had to type anything like that
(and I'm an adult-ish)
I had a friend that fell for a Elon Musk-like scam and added it to his PayPal or something of the sort but he didn't have anything connected to his PayPal (no card, no bank, no money), he just had a Paypal for some reason lol
Go on the play store to check out perms.....
ProtonVPN, 1 tracker, 11 perms
This VPN: 7 Trackers, 37 Perms.....
Now check the other free VPNs
"reputable" or random?
Random: 6 trackers, 17 permissions
"Reputable" (And that's HARD on the "") NordVPN: 3 Trackers, 23 permissions
My vpn is in Norwegian
Express, 2 trackers, 20 permissions
Hey, I have a question: for a person that's getting into cyber security at such time, with AI, automation etc. is it useful for example to know tr"A-M""a-m"""N-Z""n-z" (even if the command is wrong) since we have cyber chef anyway? Basically, should I benefit by studying such stuff or just use online based tools? (No, I do not have any problem nor am I lazy, regarding studying the underlying principles. Just asking if it's efficient)
Thanks for your time!
Going through all these VPN's, that VPN I'm looking into is the highest with the permissions/ trackers
what are you looking for new vpns for??? you already know of mullvad
Ask yourself this - should I learn math if I have the calculator
scroll up
Oh no, this was a an ad for a sketchy VPN I got on youtube, looked into it, They're registered out of Iceland, their APK is shady AF, their permissions are HIGH as hell
That's nothing like that! Your logic would apply: I am studying maths but should I do the hard divisions by a calculator or by hand? And I'd say by a calculator since the problem is knowing how to actually solve an equation not a simple time consuming division. So
There is your answer
Hmm. Any scenario I for some reason won't have access to browser based tool and I'll really need to know commands? Or nah?
nah
Aight. Tysm for replying
More than likely yes
no, i'm just messing around
Ohh
You won't always have a computer next to you, standing at a server and such, and you may be in an environment that doesn't have internet or allow outside devices
That's so specific tho
Okay, seems reasonable
It's really not
Learn the material, don't be dependent/tethered to the internet. Build your offline troubleshooting skills and you'll find things get easier
NO INTERNET? 
I mean I don't even understand why I asked that tbh lmao. But idk sometimes I see so many animations and I'm like "am I wasting time?"
Automations*
It's quite simple, print out the docs and troubleshooting steps for all of the commands duh 🙄
or buy RTFM
it's like £~10 on amazon
Do you want to hack a website or what?
I'm just a boy trying to be Elliot Alderson 😔 (jk don't come at me pls)
I love the thm subscription. I won't compare it with similar sites but I love that for 10€ a month I can both learn and practice. Have access to everything /nb_asked
Ain't gonna lie, if I don't use something very regularly I will 100% forget it, what I don't forget tho is how to get the answer
welp shadow is spent after having fun with their new tech.... time to go call it a nighty nights to the meep moops while the beep boops
I have no idea how to take notes
GOODNIGHT SHADDOWWW. Have a lovely sleep❤️❤️
you will now get sponsorship type messages of notion and obsidian
quick lesson on note taking.... write down a few words here and there about what you are learning about.... then reformat later
notepad.exe, I mean, it's better than nothing at least
AND write settings access.... nice
and if that does not work out to well go with the teach your rubber ducky friend how to do the thingy
Ty. That's actually useful because my problem with notes is that if I take notes for a subject and stumble across more knowledge abt it, I can't physically yk, know how much paper pages to allocate so I can add later
I mean
Maybe I'll start taking notes on the computer rather than irl because even tho I'm more likely to lose them there, I can yk, allocate space way easier
#sponsored by USB case
I use notepad personally, it just works. If it ain't broke don't fix it energy yk.
this guy is a masochist
Who
you did not just ask who after the "I use notepad for notes"
hold on let me change it
Ohh
Does it come with the usbs
Well I'm more of a productivity guy so notepad won't really cut it 🙂
Hell, I even rice my desktop
why would it come with usbs, just order usbs in bulk
You would get a case
yeah but like you don't buy a case for glasses and are like "there's no glasses in here, hello?"
Hi
One document, slowly getting longer as I learn more about cyber security, mostly small code snippets and links (currently about 70 lines I think)
I have used worse ways of taking notes before
I think writing in json would be even better
Oh, it ghets better. Virustotal is giving me more info. There's an IP in here, doesn't go to any particular country... ASN is cloudflare, but... uh. There's Mal analysis AND C2 Ransomware crap tied to it.
50/50 if it sells credit card info on black market
how did you even get to that site
And seclookup
Or or or... magical thing called GIMP!
you should call that person an idiot







