#general
1 messages Β· Page 625 of 1
been having hell with shells the past couple days and just now was the first time i finished a shell task without using any part of a walkthrough or even the hints. man the feeling when u see ur self improve in hacking is so nice.
It's okay. It's just that our humour is not compatible it seems! Take care
Good for you, good for you...
it think the shell hell the port is 666 π π
looool
i just had to put the achievment here bcoz none of my friends are into hacking so they wouldnt understand
Good work Ym!
be proud of your achievements otherwise nobody else would π
congrats!
thank u
Gave +1 Rep to @grizzled void (current: #366 - 15)
none of my friends are into tech, for that is the internet π I share wine/food/travelling and language knowledge with friends but not tech. Actually I'm the one that friends and family call when something tech doesn't work
Hmm
mmm cookiee π
Kinda cooking, this is gonna load up whenever you start the game
Afternoon THM, hope y'all doing well
sup const
step back a bit and breath
How am i supposed to memorize aal this
it's called study π
I just doing the rooms on the learning path
take note, review them, etc
Take notes, review them, even have others test your knowledge-base
do rooms, watch channels like LiveOverflow, ippsec, JH
I still dont understand how does pur browser know how to frame the http request automatically
Like how does the browser know what to draft in the http request
space repetition helps, you can google Feynman Technique too
Damn one concept just clicked for me
Thanks guys
How does the browser know what to request for just from the url to search for
Like assets and stuff
it looks up the ip on a dns server
then based on the things you search for on the website
it sends https get request
to that specific resource
Assets are based on the response
It will get the HTML, the HTML will tell it what further assets to get
and James save the day π Good morning James
^
At my job the saas is running on aws
Right now im just monitoring the security hub which just tracks the checks for configuration(cis, pci etc)
What security assessment can i do as a practice project here
That way i can submit sometthing to my boss
And not come across as dumb
And also upskill myself
AWS is big on business. When I worked as tech support in a platform for adult webcaming we used a lot AWS, because it was easier to upscale as the users went up
Can dev sec ops be remote?
I believe AWS path is available to premium users now, you maybe want to check that if your interested in AWS
go get them π
Need to read about Feynman Technique later
I love the Feynman Technique, also I'm a big fan of Mr Feynman, he had an amazing life
His name is familiar, but I've never actually looked into any of his works or anything
Hey everybody π
o/
He wrote an autobiography that it's called "Surely You're Joking, Mr. Feynman" he also was part of the Manhattan Project
Ahhhh, I've watched Oppenheimer so there's a chance he was in mentioned it
sup ryumen
it explains why his name is familiar
Him, Oppenheimer and Fermi where all in the Manhattan project. If you want to read a good biography about Fermi, it's called "The Pope of Physics"
lmao, someone made die hard v2
new action christmas movie dropped this year
called Carry-On
I am not able to connect the openvpn of "Enumerating Active Directory", getting this error can someone help me please
i know that fatal error comes if we are running without sudo commmand but over here i am still getting after using sudo
i tried downloading other AD vpn files from thm but getting this error only in "Enumerating Active Directory" room
I'm doing day 13 with websocket traffic interception, and I wonder if this is called MITM attack.. I'm pretty new to this stuff, so go easy on me. At first I was sure this is like MITM, but then I started thinking, that we aren't actually intercepting traffic between server and another user, but rather modifying data that's sent to and from our machine. Is this how it works?
btw hey @blazing granite π
@rapid merlin all done!
Morning 
its 7:35pm π
This isn't MITM attack π
idk for me present 
I gonna try and dig in on hackerone and see if I can get comfortable with it.
But tbh still don't really feel like I can tackle a bug bounty to the same professional degree as a professional hacker.
I can give it a try lol
thanks for the explanation. After what I wrote I really hoped somebody would pick up the conversation, but your response is so self-explanatory there is nothing more to talk about
Gave +1 Rep to @cloud quiver (current: #7 - 1260)
Actually, I remember (although was years ago) someone in here mentioned bug bounties in the US was useless cause the payout is way too low for the work or something
MITM often refers when somebody is intercepting communication between the two parties and tampering with it π . For example , threat actor intercepting communication from a victim using rogue Wi-Fi AP and modifying/dropping traffic . In the case of Day 13 example , we're just intercepting our own request , we're not a middleman between two parties π .
Absolutely! MITM usually involves an attacker intercepting and altering communication between two parties. In the Day 13 example, we're merely monitoring our own request, not acting as an intermediary between two different parties. π
Yup , exactly π
π how are you?
Fine, thanks for asking. There's a video rendering in the background, while I'm doing THM :D
Gave +1 Rep to @blazing granite (current: #65 - 128)
Aight, forgor about this one
Nice, looks good
Over ran the walls tho
Have an easy day peeps
We getting there πͺ
Hi
I need more coffee
for frack sake... 3min and 45 sec commercial on YT before song... fracking internet
There was no "Skip Ad" option?
What do you mean
for soem reason nop
Oh this is why I bought masking tape for my mirror
I missed that area when masking π
Clean up is effort
I still have to paint a cabinet and then I need to paint my daughter chest of drawers white
Will hope that mirror is dry when I get back so I can put it up
Slowly getting everything done
Stealth - need gift ideas. Nieces - 11, 4 and 3. Nephews 7 and 8.
honeslty, most of them would be stoked with that
they are getting vouchers for their games as one of their gifts. vbucks, roblox etc.
Oh cool, i got my niece a toy computer. Already introducing her to the tech worldπͺ
She likes to mess with her parent's laptop
Hehe Nice. Next year will be a THM subscription :p
Lmao, imagine hacking at the age of 3 that would be insane
oh, cos you ranked up on THM π
Oh dam, nice
I know, Right!
Im fixing to pay for thm premium too so i can do the other penetration testing rooms and other stuff
Ok.. 1 gift done π
Those are cool
Faulty - can I DM you real quick?
Yeah sure
done π
Iβm back
Do any of them like Minecraft
Probably
Thereβs these new things you can get
Theyβre like Minecraft blocks but magnetic
And you can build Minecraft irl
Theyβre pretty cool
Also thereβs these cars you can get that you can drive around walls.
4 year old can get a baby doll
Does that mean I'll be getting requests for 3d printing copyrighted material?
Yeah π€£
It'll get you out of the house
yeah, and hang out with friends
reckon it'll do you good?
was at frineds house for 5 min and i end up with lenovo thinkpad t450. looks new cos stil have stickers =/
guessing it will, though not part of plans cause fuel limit
Shame your bike is still in bits π¦
I do still have a couple of liters in my bikes tank I can put in my car
helps with not watering my fuel lines on my bike over the next couple of months due to vapor
it's also too cold and dark to ride a bike now
I dunno, Bella. I find that once I layer up, a dry winter dark afternoon is a really nice relaxing ride.
Ahh. ok
ends up with like 3C 8m/s
hi
but if you pop a wheelie, that will block some of the direct wind π
pop a wheelie on a summer tire with 200kg bike? 
I'm just putting off my xmas shopping. I'm about halfway done π
Well, I figured anything I order online should really get done this weekend, so if it doesnt arrive for any reason, I'll have wiggle room
I just have to go to 2 stores, but haven't felt like it yet
Not a full fledged one at least, what you're describing falls under a subset of traffic manipulation/local interception or proxying
True MITM should alter traffic between parties without their knowledge
ubuntu .iso almost 6gb... =/
Lies
it's too dark to ride safely now*
with the people here it is
Yeah, People are the worst.
mostly due to my appearance as well, as I don't have winter attire for bike riding
take lanter toi have more light π
I have to go to the store to get wide elastics π
to get the last screw off my carb
Or a drill bit
π΅ ***Dashing through the snow,
In my rusty Chevrolet,
Down the road I go,
Sliding all the way!
I need new piston rings,
I need some new snow tires,
My car is held together by a piece of chicken wire!
Oh, Rust n' Smoke,
The heater's broke,
The door just flew away,
I light a match to see the dash,
And then I start to pray-ay,
The frame is bent,
The muffler went,
The radio it's ok,
Oh what fun it is to drive,
This rusty Chevrolet!***π΅

Nice
how hight you are ?
Hi, how are you?
so you push door when says pull ?
new laptop thinkpad t450. i5 5300U, 8gb ram, intel hd graph, 256ssd...
tims typing... but theres 5 mins to go....
i think ill put kali on it...
website running slow for anyone else?
Ahhhhh I just figured out the alien thing guys
So they are going to use this clear deception to introduce tech that scans wave patterns
π π₯³
Advent of Cyber 2024 DAY 14 Let's Go!
π₯³ π
There we go π
alien movie?
@boreal scarab dheck you do ?
There's currently not enough law on the transmission of information through airspace
hi i need help to learn bufferoverflow attack can any one send my website that i can learn form it plz
might try you faworite search engine ?
Nooooooooooooooooooooooooothing π
Ngl... I was thinking about wardroning

Check out this article π
no one believe you
I swear, you have a script to post that, and it just changes the day in your post 

my hands smell like fuel now 
Drone talk
AOC talk
Bella: "My hands smell like fuel now"

hi

typical general talk
only missing someone asking sus questions for learning purposes
Wait for it
Moosic
How to get bank credentials for ethical reasons
just kidding

actually listening to nightcore rn 
hey hey, I said I was going to work on my carburetor
Oh, I didn't see that lol
it was right next to the "idk if I am going to a car meet tonight"
I joined to sing my little song lol
SKYRIM!
oh well, imma ciphen some fuel from my bike to my car so I got a bit more to run on
hackers am i right
4th year in a row tradition. π
Also still using the π as an upvote (you can not unsee that)
THM Magic happening daily. πͺ
Is it me or are some "Easy" CTFs hard
It's not just you
depend how you define easy. if how easy is to execute and get root fast and easy. then it might be that easy. if you need 100 or so steps that you need to know what you do, then might not be easy
Time to do some hillbilly stuff
is this a moment when most vm are in use?
Guys do you think ai will replace cyber security jobs?
hell no
no
no
ai is dumb π
I think AI will be added to tools
For example ghidra with AI would be interesting
You can actually see AI analysis of Malware on sites like Virus total
gonna be an arms race between competing entities
burpsuite might be also nice
i might learn it eventually
I mean the easy rooms some of them are hard to do
I get afraid when I see news about ai and Stop learning then watch motivation videos to start again
like i say. how you define easy. number 10 does not sound big. 10e is not much, 10 parking tickets are a lot
We already have a bunch of tools to help us, even though they may not be AI per say, they help automate some processes, AI may expand on this.
AI will only take over if you let it
which might be on its way based on all the implementations
People of the Cord... I'm on a bus... Wheee... Feel like a kid again. Wheels o nthe bus goes bump bump bump all day long... π€£π€£
ye are losing it
It can depend on what you learn as "easy" but some rooms you may find are harder than you would expect as easy rooms
An example I'll give is that there was an easy CTF room (can't remember which) that needed privilege escalation, it was not part of the learning path but it was an easy type of privilege escalation.
Maybe
"It's all arguably top-level trolling on Artisan's part, and it's certainly helped the startup get plenty of attention. It could backfire, of course, especially if potential customers fear reputational damage from being associated with a company that's riled so many people."
welp gonna adapt to the crazy people
@hushed heath π’π’π’
But still they need cyber guys
Maybe means like they can do some job not completely
If anti people measures exist to stop humans from figuring out how cyber attacks happened, there will also be anti AI measures. Humans will always be needed in one way or another
@hushed heath means it can reduce the demand
We can say that but still people are needed to train models
Website slow for y'all also?
There will always be a need for humans to review and correct the hallucinations in AI outputs.
^
I will always be fine, as I'm an actual domain expert, but entry level will be affected because business people will deliberately not understand that people like me aren't replaceable by AI, and they will not want to hire junior roles so they can be trained to replace me.
when doing a room about a tool on thm are we supposed to know how to use the tool afterwards or is it more like: i get what the tool is used for?

Most of the tool introduction rooms I've seen on THM aren't intended to make you an expert in the tool; it's an introduction so the next time you encounter a problem that tool can be used for, you will remember "oh yeah, i remember something like this.... [tool] is what I should use for this kind of problem"
@whole yew can we hack the ai system
ok thank god I thought i was dumb 
Gave +1 Rep to @whole yew (current: #11 - 792)
@whole yew ai
ML-based systems are notoriously "easy" to poison with malicious data, for a given value of "easy"
hi in today's challenge in AoC , do I need to run an AttackBox to see the content of route-elf-traffic.sh ? I want to keep working on my local machine
#1305926862114914325 please π
ok thanks
@glass nest the elastics trick doesn't work π
Aye. Works better on things like hex bolts. Was worth a try though
yeee, guess I'll give it a wait for when meeting with my grandpa
Grandpas always know all the tricks
evening bella, how ya feeling?
he has the tools at least, he was my go to for when working on my car living at my parents
evening esqy aswell
cause my grandparents lived 5 minutes away from them
feeling chill, might be a little high from random fumes in my apartment, but that happens 
Yeeeaaahh, but you can't beat Grandpa knowledge. Legends say it's better than Uncle knowledge
Uncle Esqy... Guess what mode of transport I'm currently using?
That's good, hope you continue to feel better
No a bus... I thought these things are myths
my apartment might be a lil illegal π
It's like a long haul bus. Has got 4 wheels and a trailer to boot. Also on my way to Cape Town for holiday
Ooh Cape Town. thats one of the two places in SA I could name off the top of my head :p
The other one?
Johannesburg :p
Voetsek...
You have home-turf advantage π
Mean that's a place and all, but I hate Johannesburg. I'm in pretoria. They're our rivals.
I mean yeah, I do. I don't know all the places in England. The only ones I know are Brighton and London. Then I mess up.
capital of s africa
No... LMAO it's where the Union Buildings are. Basically the white house of South Africa
And yeah it's a capital of South Africa. Can't remember if it's judicial or administrative. But one of the two.
Ahh. Like the ACT in Oz
Yeah... And I just checked it up, it's the administrative.
But yeah. countries man. You might not like it all of the time, but when you leave it, your heart yearns to return to see those blue mountains and brown skies... Oh wait it's the other way around.
LMAO
Anyways, need to go. Laptop battery not as good as I once thought. Barely on and it's already at 25% mind you I used it to do the AoC today too.
guys is tryhackme server is down?
Peace out Arjay
anyone here know about arm64ec integration on windows
HAMD - Might just be overloaded.
nvm its fine thankyou:)
bro i got timed out from the owlsec server for singing the sigma sigma boy song π
YAY it is dragonfable warring time
hi
hi hi
I have a question about installing kali linux on virtual box?
What partition option should I use for Kali Linux for VMware? entire disk or entire disk with LVM.
Entire Disk(in my case)
I hate ISP routers with a burning passion
Hi its a pleasure stay here i need help somebody help me please i need Know where its the password of the fisrt machine in the operation tiny frostsite and know if the machine can be dangerous? im sorru im a begginer but i wanna try
Was working, then boom.. nothing
in vm you can go just default all data on one partition
Yo,chill a little,what you want?
Explain more detailed
mmm?
Nah,its just that i didnt understood what you asking
i wanna use the first machine of the SOC advent 2024
Or maybe just bcs im high..
Hey I am new at thm , can someone help me through this
YOOO,ON THM,sorry,i thought im on other server lol,idk how to help you
false
Aint no way you actually checked a tenor URL
Thanks, I was reading up and some say entire disk is best for beginners but I found another one saying LVM is better for not losing data.
Gave +1 Rep to @loud marlin (current: #26 - 371)
ok but thanks
Gave +1 Rep to @modest burrow (current: #1645 - 2)
lvm is other thing. just do you backup/snapshot of vm when you think is smart and will be ok
Yeah im really sorry,im just a lil tired
I don't mind if the vm enviroment gets wrecked as long as my system is not affected.
Whats your setup btw?
Thank you
My physical hardware? Asus and I have an AMD ryzen 5 5500
No tower
Aaaahhh
Tower
Cool,i thought its a laptop since you didnt say anything about GPU or ram
Btw
I need more disk space . I have 16 gb of ram and 500 gb storage currently. I have a 1tb drive I need to install.
If you getting started with Kali Linux i would recommend dual booting instead of using a VM
1.It can use the entire resource your PC has
2.On VM you have limited device compatibility and failures can occurs more often(in my experience)
3.Its more performant, less laggy,works 60+hz instead of 30hz that its capped by VM
Woow,indeed,500gb can fill pretty quick,especially if you're a gamer
Or,in your case,if you have multiple VMs
just completed walking an application on the jr. penetration tester learning path, it was a lot to digest but once i figured it out it wasn't that hard

Yo,i mean,its my opinion
No one said you wasn't entitled to one?
?
You can correct me if you think VM is better
VM has its benefits,like dynamic storage
Portability
Given Kali is designed not to be an everyday OS as well as it's a pain to update (easier to just install a new image on a VM) it's better to run it on a VM
Indeed..
Ah lol
Did not even took that in consideration
Im personally running it in dual boot mode...it works better than in a VM,but mybe its my fault,probably misconfigured the VM
π
everyone behave
well.. i bonked kali
Anyway,do you think im doing wrong by dual booting?

not smart idea. if you know what you do exactly. them is ok i guess
You do you, but I personally wouldn't recommend it to newbies
Kail Linux is a pentesting OS.
You're more than welcome to run it on bare metal but here is something to keep in mind:
- If you are a security professional, you should not be performing any of your actions on your host. It's bad practice.
- Security-wise, you should expect that you are interacting with malicious actors and software, it would be incredibly insecure to do so on your host
- Furthermore, if someone does infect your OS, using a VM you can immediately stop them
- It is a pentesting OS, it's meant to be setup on the go. I can understand not wanting to setup Ubuntu every time with all your tools but Kali is intended to avoid all of the setup and just immediately get into work
- If you mess with something on your host machine, there's no snapshotting, you lose your entire host. A beginner should experiment on a VM because Linux isn't as protected as Windows or Chrome OS, you will mess up something sooner or later
Well,i cant say im an expert,but im pretty sure i did not fucked up my windows
This should be pinned tbh
the burp suite related tasks are so much fun
can just reference it every time someone asks whether they should run kali on a host
Now that's made me understand π
When installing,i saw multiple opstions: bare metal,vm,air-gapped,etc
Not sure if anyone has experience with metasploit but Iβm new to the program and Iβm in the process of installation and when I try to run the console .bat file I get an error βcannot load such file - - rex/powershell/psh_methods (LoadError)β if anyone has some insight Iβd appreciate it, Iβve allowed the files through windows defender and Iβve already uninstalled and reinstalled metasploit
I chose bare metal,but maybe ill change to a vm aswell after this advice
Fuck ISP routers, fuck ISP routers, fuck ISP router!
π
Looks like murder has happened

new laptop is weird. dumb intel gpu integrated shit...
I agree. My cable modem is in bridge mode, Everything goes through pfSense....
Back to studying
garbage π
π
more ram
DownloadMoreRAM.com - CloudRAM 2.0
"Shit with sugar on" - my mums favourite saying
lmao
What are all the certifications I can get through THM?
Stupid question perhaps, but how come sometimes you need to add an domain to /etc/hosts but sometimes not? How can you know when you need to do it or not?
You will eat what i made today... if you do not like it, then starve -- my mom
Anybody know whether it's possible to force certain file extensions (.PNG, .JPG) to go to a specific folder in obsidian?
π !!!
you can define that all pic goes in same folder in where is you document located. so all what you put in that text as pic will be saved in that folder
I should get a new SSD for my laptop, put Qubes on it, running whonix. Why? Because......... Yes
check here
πππ i fuxking feel you on this shit be so organized then boom 2024-screenshot.png just right under everything
Mainly for practical purpose i believe so that you can preform domain enumeration usually is what i have seen but ive seen its outside thoses cases as well
does anyone here have a degree in cybersec/ or a job in cyber? can i talk to them
Hi, nice Advent of Cyber 2024 π€
Ask your question, people will get around to it eventually
@shrewd escarp swap and keep for IoT research is what i do everytime lol
Yes
You just watched the newst mental outlaw video... didn't you π dont lie now
mental outlaw the goat
I like qubes
Yup
Is good what are you running on tho? And do you daily drive?
daily driving Qubes is overkill for most people
you're more than welcome too if you want
Yah, but also knew of qubes waaaaaaaay before his vid. He just sparked it up again for me to try
Well i mean its best to install on hardware over vm
Lol i figured so π€£
Qubes is way too complex for any VM lmao
I daily drive Kubuntu
Hence i was asking about daily driving
Isnt that the like chinese flavor of ubuntu?
O kde
Lol
Itβs the KDE one
Why would you do that?
I wss thinking of Ubuntu Kylin
I dont like kali linux. Just import the repos on any literally any other debian based distro. I think kali is best for exposure or if you just dont ahve time for some reason
Thatβs what I use in my dell. Iβm planning to built a desktop pc and Iβm going to use Fedora in it
You run Kylin lol? Are you in states of you dont mind i ask?
I thought kylin discontinued
Daily Driving Red Star OS π
Glad to hear I'm not the only one
π great minds think alike right?
π€£
Im not a big discord person but i actually enjoy coming here
Just thought discord was some gamer stuff for a while so i just left it alone
Need connect my thm tho
You can verify to connect your THM account and Discord profile π
The TryHackMe Discord Server

Thanks tho fr
@glass nest @boreal scarab middle part print =/
what you printing
atlantis ship/town
there is lots thing to do
true that
i did tbh print few movie props like guns. for some friends
not sure how good. i just press print lol
nice
bonked kali 2nd time in row...
Do we get private vpn configuration file, after subscription??
You get access to premium servers
The configuration file the is used is downloaded form /access page, in case of subscription also.
and iirc you get unlimited attach machine/kali. and slightli better vpn speed
- all the content
But the vpn configuration file is same as everyone use.
What makes more sense: encrypting a zip file or encrypting all the files in a zip file? π€
No intro, dumps spam, thinks it will help, 
@mossy river idk if you got the first ping, mb if you did
I edited the msg to include him so I don't think he did
@whole yew might ?
Is EU-VIP vpn servers are different from regular one? I am asking VIP is mentioned in the name.
probably got phished
What
Can you DM me with more details, please
Yes, they have better speeds & better reliability, as with most things that are paid
@sand matrix 
Can I use any vpn server configuration file to connect?
unlimited attackbox aswell I think
what do you mean
I mean when we download configuration file, we have multiple option, so how to choose which one to download and use
...
...
Is there any detailed documentaiton for what I have to do to upload rooms to thm?
aaa
Like what you're allowed and what not?
Well, yes. Also more just how I need to actually create the room, docker, VM?
It will be a VM in an ova format
The Room Review Process
Yep, those articles is exactly what I was looking for - I knew there must be some somewhere haha
thanks
Oh wow, interesting:
Brute force actions performed using the AttackBox should be completed within five minutes or less, considering that each user may have a unique VM configuration. Ensure that any hashes intended to be cracked do so within the specified timeframe using either Hashcat or John with the rockyou.txt wordlist; if an alternative method is used, provide hints accordingly.
Knowing this might save me some time when completing rooms in the future π
Actually @sick lance is it ok if I DM you quick?
Server-based ISOs are better over desktop ones for ubuntu because of conversion process
5 minutes or less? Damn I once bruteforced a room and it took me like 30 minutes lol
β Gave the role Creators-Lounge to squeezed.lemon
#creators-lounge will be a better channel for your questions @wanton ingot
No access =/
π Thanks. Don't want to too give too much away about it though lol, incase it ends up on ther
Did anyone manage to do todays AoC task on their own device (not on the attackbox)?
No, as the script won't work, and THM don't advise you to take materials off the attackbox to use.
I see
That makes sense I was a bit mad that there was no download button as usual
A warning about this would be cool
There may be something in the THM's ToS.
I meant as in the day instructions
Im reading them again and it doesn't look like it says u must use the Attackbox anywhere
I might be wrong but that doesn't mean Attackbox is a must
Is that normal
fresh kali install...
@rapid merlin Think we raided your house
is it possible to find someones finished rice for kali, and download it as an "finished product"? and if it is possible, are there any "well known ones"
ricing kali is pointless, it's inevitably gonna go boom eventually
no point wasting your time finding or creating one
I was hiding in the ceiling plants with the spooders :3
Still not worth it
plus then there's learning the keybinds
and everything else accompanied with ricing
aight
If you wanna just change terminals or wtv, fair enough
honestly, I don't know. Just seen some pictures and it looks nice, so got interested. But won't bother with it myself, I'm too new to unix
yeah, ricing is more advanced things and honestly, usually just causes complete headaches
And taking about plants I saved some at B&Qs death sale
The plants that barely made it
death sale, sounds like something out of a mission impossible movie icl
love how wacky and stupid those films are icl
They put all the dying plants in the sale in the depressy rack
And I come along and buy them all
ah LO
Β£2
π
idk, I need to stop being lazy and get a job so I can start getting certs done LOL
I would love a job
just get one 
Not necessarily in cyber, just any job that I can get too and start getting certs done lmao
A lot of the certs are expensive

I'm extremely antisocial and barely spend any money anyway
But I suppose in the long run the pay makes up for it
I donβt drink, smoke or do anything but I am wasting money on plants
Yeah fair enough
I mean is it a waste though
π
valid ig if you enjoy it
Itβs an addiction
can think of worse addictions to have
Everyday
π
i own a total of 0 plants
best so, they would live for like three weeks until they would be dead
I know a lot of people wont keep them because they just kill them
I love scar he was so sassy
βBe preparedβ was a banger
yeah he was so funny
hades was sassy asf too iirc
the thm services today has been fucked
almost done completing content discoveryπ
big amount of users
No, just will be a lot of users
plus THM machines are hosted on AWS not THM
downsides of running free ATKBox
I'd recommend just doing it on your VM(s) anyway
probably better
hmm... weirdly i got logged out of thm for some reason =/
session timeout?
no. off the site. but ok
ah
i was trying to answer this question after following the steps in the Subdomain Enumeration room and i even looked up videos to help without trying to cheat to make sure i wasn't tripping but the answer would not pop up no matter what i did
i got it now but damn
happened kinda often for shadow a few weeks back where every week shadow had to relog
why mi kali screen is weirdly bright =/
so thinkpad have external and internal battery... how that works? are they active in same time or ?
ello
Gawd I am tired
βI have nothing to hideβ.
Itβs become a default response from many to overreaching surveillance.
When did privacy start being about having something to hide? It used to simply be about having the right to decide for ourselves who gets access to our data. But over the past decade weβve lost that choice, and so much of our personal and sensitive i...
you wished to start at that time or mistake ?
that was a mistake
welpies time for meeplies mlooplies to the beep boops for the sleep sloops
the entire video is good... just if you can't watch it all so be it
each point is kinda self contained
will watch it
is DFIR, Threat Hunting or Malware analysis part of L1 / Tier 1 SOC analyst job?
or is it just log analysis and event triage?
More than likely not, it really depends on the org. I wouldn't bet on it though
I think malware analysis and threat hunting tier 3
But titles to begin with make no sense because each company has you do different stuff
it wouldn't make sense since tier 1 are the ones who escalate the events though
like how will they have time to do DFIR and Threat Hunting
whats the best free vm for windows?
probably virtual box
Which is right
me i use wsl
bcs for linux i just do basic terminal usage
but if u want full vm virtual box is the best free one
Thatβs why tier 3 and tier two are the ones that usually dive deeper
and then vmware best paid one
Thereβs two virtual box and VMware
VMware came out with a free version
i tried it
virtual box was better imo
Really depends. I agree with virtual box tho
vmware workstation pro is now free for personal use
vmware is better if u pay
So pretty much anything that has a paywall
huh
i don't think i tried pro
yeah might be better than virtual box then
VMware Desktop Hypervisor products Fusion and Workstation are used by millions of people every day to run virtual machines on their Windows, Linux and Mac computers. They give users the ability to quickly and easily build βlocal virtualβ environments to install other operating systems, learn about technology, build and test software, complex sys...
i think i tried it before they made pro free
I'd recommend trying both :b
It was a bit of a hassle to set up the account for VMWare Workstation Pro though
anybody got a link to DL kali on UTM? only finding virtual box links
Home of Kali Linux, an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments.
Cant you download the iso and just install it?
Ipak je vb tata

From "Castle" Season 8 Episode 8
Copyright ABC
Thank you, this is my first time installing Kali, I have installed other versions of linux like unbuntu. I'm definitely a beginner at this.
Gave +1 Rep to @mossy river (current: #5 - 1384)
Hey π college student cybersecurity major here!
is there a way to have the website into a dark mode?
is there a preference section just wondering
thank you so its coming dec 23rd
Gave +1 Rep to @glass nest (current: #17 - 506)
Looks that way. I just use the Dark Reader extension on Chrome, so.. It's always been dark mode for me
thank you
I use Virtual box
Are you majoring in IT/cyber or are they two different things at your college?
It's Cybersecurity and Information Assurance that's what they call it at my college
i use hyper v manager
Never heard of that, Is IT a separate thing?
How are you liking it so far?
Hi
hi
Hi , welcome π
Hey
I need a platform to master linux
Suggest me some
Check out this π
Linux is one of the major operating systems and is heavily used in organisations all around the world. Learning how to use Linux is a core competency and will help you in your hacking journey not to just use Linux-based security tools, but how to use and exploit the operating system. This module will focus on getting you comfortable using Linux.
How do i make linux my default os
I want ubuntu
I tried usb and it doesnβt work
you should install it on a partition and modify the booting options order
How can i do that
it does work, i suggest you provide more info on what is failing
so we can actually help you
If you're on Windows π
cause usb installing is a pretty much well stablished op
you are probably making one mistake along the process but we dont know if you dont show us
I try to go into bios and boot off a usb but i looked everywhere for a usb and couldnβt find one except the boot order
It has a linux option?
If you have Linux installed on hard-drive/SSD , yes π
Ok i will try that
I already have unetbootin but when i try that it says itβs missing a file
And i put ubuntu on it
@boreal scarab @glass nest it start to look alike ship... and thi is 30cm ruler to compare size =/
I want to start in cybersecurity, and I would like to know if there is any roadmap you can recommend.
Start with IT fundamentals
You have a learning roadmap in the link above π
thanks π«°π»
@cloud quiver is there any other way to install linux?
Try to install it on VM
there is multipla way to install any linux
Like i want it as my main os
Before windows 10 is unsupported
then you need find one you wish. download, get it on usb and install. depend what linux you go with there is one or two thing different from others
Check out this article from fcc π
dual boot is not so smart to go with. it can brake stuffs
What should i do
if you need windows the go with dual boot. but first read of possible issues. brake grub, bootloader things and so
I dont need windows
then you put linux of choice on usb with rufus or some windows tools and then boot that linux from usb and go from there
Ok
When i use rufus it says access to the device is denied
format that usb before
and then Windows one day says "wait a minute, this space is supposed to be mine"
Corrupted
Im actually going to change to kali
@loud marlin should i use the kali installer or a different one
Like live boot
kali is not smart to use for main os. it is unstable
Oh
kali is best for VM
Welp
try ubuntu linux
Can i still use a vm in ubuntu
π€
Said who?
Never once had any problems with kali
You use kali as your main os?
you can have it with no issue. but it is not stable for main os
it is also hacking os. you never know what can cause issue. and have way big amount things that updated all the time. that can cause issues...
What?
after updates can cause issues. long story short... not so smart idea to have it as main is or dual boot
Just run it in vm whatβs the need to run it through bios boot
blackarch as main os π΄
You have black arch?
bios run tends to be generally faster
pen distros should still be on vm tho
I could never install arch
My usb is now called Ubuntuπ€
parrot is the best kali alt
Yes
my mother called my linux vm , a video game π
Gave +1 Rep to @loud marlin (current: #26 - 372)
I have full metal USB sticks and if I accidentally leave one plugged in for too long it gets too hot to touch
i have same issue with usbC hub thngy
Thatβs on your computer
I have the same. Iβve noticed it doesnβt sleep my laptop either. Probably just need to change the settings tho
What are you running it on?
I just realized I forgot to turn on the heating 7 hours ago and now my room is at 7Β°C
idk how I didnt realize its cold af
Bootable usb with persistence
Hi guys, I'm having a problem in my lap, the internet has been slow for the last week while browsing, but the other devices connected to the same wifi has better speeds, what could be a fix
Yes but whatβs your system you run it on
Just an old dell laptop from when I went to college
I run Kali on a random Dell laptop
Itβs running hot because your processor
Ok
Same issue for me sometimes π
What model is it? Tbh, never heard of random dell.
send a pic
I love those old dell keyboards
I think i just booted into it wrong
is it just me or google search results kinda look rigged
guys what's the most practical ctf categories?
Networks
ones which can help you find real world vulns
Practical for what?
feel like pwn isnt really that useful anymore as there are more and more memory safe langs
and the skill needed to find real world binary exploits is probably super high
within everything in ctf101.org
web
pwn
rev
crypto
forens
yup ik web already
thinking which to do next
dont want to be a one trick pony
There are tons of things written in C and CPP (starting from Linux and Windows kernels). Those to stay for a very long time.
The barrier to binary exploitation is higher now, itβs not nineties anymore when one could just AAAAAAA everywhere and get a core dump. But itβs the same with Web, you cannot hope to find a SQLi when modern framework is in use.
However, both have values because not every app is written in Rust or uses a framework.
yeah i agree, and the real life scenarios of binary exploit that i know of, are all kernel exploits. but like you said, barrier for entry is super high for pwn, and the number of systems(?) with binary vulnerabilities feels super low, thus i dont think it will really be practical for me to learn pwn next heh
practical in the aspect of getting a job in cyber ig
hence why i'm asking which category is the next best to learn after web, for real world application ig
If you want to get a job in Cybersecurity, I humbly suggest to learn defence. Offensive security is a niche thing needed mostly at a very few companies providing those services. Defensive security is needed at a much wider range of organisations.
mods are asleep, post sinks
You are increasing your employment chances by knowing KQL and how firewalls work, not by learning ASLR bypasses.
i get what you mean, is this under the umbrella of sysadmin/devops?
i kinda wanna do pentesting too, so offensive is still needed for that
Not necessarily. It also could be SOC, networks, security architecture, identity management.
ππ
NEEDED HELP
WHAT
These are two different issues though - βwhat I want to doβ and βhow can I get a jobβ. You be you and good luck.
needed help getting a rev shell on a unifi network using log4j vuln
I have no idea what that means
you know about log4j vuln?
that's a myth
Stop asking to assist you with illegal stuff
just read your msg history --- if you're looking for irl stuff you should ask @shell nova he makes those rooms
?its a ctf lol
what ctf is it
and log4j vuln is 3-4 yrs old and patched in most of the networks
You then solve it yourself. CTF rules usually prohibit external assistance.
not to mention this servers rules...
That too.
whats this server for then ? just hangin out
general infosec discussion and tryhackme...
its a htb machine is that illegal here?
its an old box , i went thru the walkthru , yet im unable to somehow get the rev shell
cyber sec should b about learnin from one another , stop yappin ab the rule book bruh
you're funny
whatevr
why don't you ask the HTB discord for help. it's their box
Where can I find the rules for this group?
Thx
rule 5 says active machine so , this one aint active , its a retired machine
Just asking a question so I donβt get kicked. If I wanted to recommend a new cyber security community not in competition with THM but to help and learn extra about Cyber Security could I do this? Or is that considered self promotion? Itβs not my community Iβm just trying to help out another CyberSec Professional whoβs looking to build a community for Learning and Connecting with other professionals?
@mossy river or some can answe that
anyone knows how to update the role on Discord?
forget about other platform , i just wanna know about log4j , im not talking about the machine
bro wants to be a discord mod ig
It should get automatically updated
?
which language will be best so that i will not be caught easily
π You sound shady ahhh
But I'd go with C if I were you, pretty low-level, programs systems pretty well
yeah i am expecting this answer
Pretty steep learning curve though
performing a international level ransomware operation sounds like too risky but i wanna do that in upcoming years
π
do you think it needs a very high processor pc...?
Brother no
It's just programming
Besides it's time to pull out this copypasta
In case of an investigation by any federal entities or similar, I do not have any involvement with this group or with the people in it, I do not know how I am here, probably added by a third party, I do not support any actions by the member of this group
Cause you're SUS
good question
π lol
me too is a indian
π
i think its a good server to talk about this thing
ok where are u from?
That, my friend, is a very good question
@mossy river
π lol
Are you sure you know what discord you're in..?
hey guys do you think we can really learn hacking from 0 with tryhackme ?
tbf yeah
i am in a server which supports cyber security rather than black hat hacking
just complement it with some extra resources for networking and whatnot
ok ty
Gave +1 Rep to @dim mason (current: #2497 - 1)
Don't get stuck with tutorial hell tho
I'd recommand putting everything you can try and learn in practice, take notes and read them every once in a while
no i am not a tuto addict, I know how is the tuto hell ( i leaned programming with tuto at first and i didnt learn anything)
Yeah just trying to prevent you from falling in that trap
setting up your own linuk environment will be a good start learn the basic commands as well
It's good if you have basics in programming
thats illegal
I already have kali linux etc
i'll try ddosing my self x)
Please don't π
If you wanna practice look up vulnerable machines made for learning purposes
have you heard of the tool named stenghide tool in it
no
Fire them up and try to complete them in a safe virtual environment
ok
why would you practice ddosing
yk i want to become a white hat hacker, my dad's business got infected by a ransom ware and next time, i want to help him
oh idk
doesn't matter
lowkey does
you sure?
why is ur name anonymous
Yeah π
highkey in this server
are u a big fan of them ?
Tryna be ironic at this point
there is a big hacker group in my country named B13, they are hacking israeli network etc
yeah
i think sometimes you should watch the documenatry of specific channels like fern covering the cyber updates will give a motivation
guys i have a supposition
i think every hacker in this planete played minecraft at least once
(sorry for my english I am not a native)
where are u from
Tunisia hbu
s u p
hi
fucking india
hi howdy
i am looking for a good team which support black hat hacking and malware development

