#general

1 messages Β· Page 625 of 1

blazing granite
#

Don't you worry. I always joke about my age πŸ™‚

brittle grove
#

been having hell with shells the past couple days and just now was the first time i finished a shell task without using any part of a walkthrough or even the hints. man the feeling when u see ur self improve in hacking is so nice.

half badge
drifting mural
blazing granite
brittle grove
#

i just had to put the achievment here bcoz none of my friends are into hacking so they wouldnt understand

glass nest
#

Good work Ym!

blazing granite
brittle grove
twin ridgeBOT
#

Gave +1 Rep to @grizzled void (current: #366 - 15)

blazing granite
languid pecan
#

Hmm

blazing granite
#

mmm cookiee πŸ˜‚

snow path
#

Kinda cooking, this is gonna load up whenever you start the game

rapid merlin
#

Afternoon THM, hope y'all doing well

blazing granite
#

sup const

wild zealot
#

I feel overwhelmed

#

Left behind

blazing granite
wild zealot
#

How am i supposed to memorize aal this

rapid merlin
#

notes

#

Nobody expects you to know every little thing

blazing granite
wild zealot
#

I just doing the rooms on the learning path

blazing granite
#

take note, review them, etc

rapid merlin
#

Take notes, review them, even have others test your knowledge-base

wild zealot
#

Yes

#

Never give up

rapid merlin
#

do rooms, watch channels like LiveOverflow, ippsec, JH

wild zealot
#

I still dont understand how does pur browser know how to frame the http request automatically

rapid merlin
#

wdym

#

pur browser?

#

Oh, do you mean your?

wild zealot
#

Like how does the browser know what to draft in the http request

blazing granite
#

space repetition helps, you can google Feynman Technique too

wild zealot
#

Damn one concept just clicked for me

#

Thanks guys

#

How does the browser know what to request for just from the url to search for

#

Like assets and stuff

rapid merlin
#

it looks up the ip on a dns server

#

then based on the things you search for on the website

#

it sends https get request

#

to that specific resource

naive violet
#

It will get the HTML, the HTML will tell it what further assets to get

blazing granite
#

and James save the day πŸ™‚ Good morning James

rapid merlin
#

^

wild zealot
#

At my job the saas is running on aws

#

Right now im just monitoring the security hub which just tracks the checks for configuration(cis, pci etc)

#

What security assessment can i do as a practice project here

#

That way i can submit sometthing to my boss

#

And not come across as dumb

#

And also upskill myself

blazing granite
#

AWS is big on business. When I worked as tech support in a platform for adult webcaming we used a lot AWS, because it was easier to upscale as the users went up

wild zealot
#

Can dev sec ops be remote?

blazing granite
rapid merlin
#

alr time to study

#

need to continue with brrute force attacks kek

blazing granite
rapid merlin
#

Need to read about Feynman Technique later

blazing granite
rapid merlin
wheat pecan
#

Hey everybody πŸ™‚

rapid merlin
#

o/

blazing granite
rapid merlin
blazing granite
#

sup ryumen

rapid merlin
#

it explains why his name is familiar

blazing granite
chilly veldt
#

lmao, someone made die hard v2
new action christmas movie dropped this year

#

called Carry-On

sleek bolt
#

anyone can help me with exploiting log4j

#

in unifi network

bold nova
#

I am not able to connect the openvpn of "Enumerating Active Directory", getting this error can someone help me please

#

i know that fatal error comes if we are running without sudo commmand but over here i am still getting after using sudo

#

i tried downloading other AD vpn files from thm but getting this error only in "Enumerating Active Directory" room

split ore
#

I'm doing day 13 with websocket traffic interception, and I wonder if this is called MITM attack.. I'm pretty new to this stuff, so go easy on me. At first I was sure this is like MITM, but then I started thinking, that we aren't actually intercepting traffic between server and another user, but rather modifying data that's sent to and from our machine. Is this how it works?

#

btw hey @blazing granite πŸ‘‹

silver sky
#

@rapid merlin all done!

oblique loom
#

Morning coffeecup4

wicked gazelle
cloud quiver
oblique loom
#

Its 6:05 AM :O

#

Are you in the future or past? lol

wicked gazelle
oblique loom
#

I gonna try and dig in on hackerone and see if I can get comfortable with it.

#

But tbh still don't really feel like I can tackle a bug bounty to the same professional degree as a professional hacker.

#

I can give it a try lol

split ore
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #7 - 1260)

oblique loom
#

Actually, I remember (although was years ago) someone in here mentioned bug bounties in the US was useless cause the payout is way too low for the work or something

cloud quiver
split ore
blazing granite
split ore
twin ridgeBOT
#

Gave +1 Rep to @blazing granite (current: #65 - 128)

split ore
rapid merlin
silver sky
rose tusk
#

Have an easy day peeps

oblique loom
#

We getting there πŸ’ͺ

weak birch
#

Hi

oblique loom
#

I need more coffee

daring jackal
#

I got paid, i can finally afford the premium for try hack me😭

loud marlin
#

for frack sake... 3min and 45 sec commercial on YT before song... fracking internet

daring jackal
rapid merlin
silver sky
loud marlin
daring jackal
#

BruhπŸ’€

#

That's insane

rapid merlin
#

Oh this is why I bought masking tape for my mirror

rapid merlin
#

So I didn’t get the bleed

silver sky
rapid merlin
#

Clean up is effort

#

I still have to paint a cabinet and then I need to paint my daughter chest of drawers white

#

Will hope that mirror is dry when I get back so I can put it up

#

Slowly getting everything done

glass nest
#

Stealth - need gift ideas. Nieces - 11, 4 and 3. Nephews 7 and 8.

daring jackal
#

Get them all $2k gaming pcsπŸ‘

#

Jk

glass nest
#

honeslty, most of them would be stoked with that

#

they are getting vouchers for their games as one of their gifts. vbucks, roblox etc.

daring jackal
#

Oh cool, i got my niece a toy computer. Already introducing her to the tech worldπŸ’ͺ

#

She likes to mess with her parent's laptop

glass nest
#

Hehe Nice. Next year will be a THM subscription :p

daring jackal
#

Lmao, imagine hacking at the age of 3 that would be insane

glass nest
#

Wait, Faulty.. y u not blue? πŸ˜„

#

Gratz πŸ˜„

daring jackal
#

Oh, idk

#

Why am i green

glass nest
#

oh, cos you ranked up on THM πŸ™‚

daring jackal
#

Oh dam, nice

glass nest
#

I know, Right!

daring jackal
#

Im fixing to pay for thm premium too so i can do the other penetration testing rooms and other stuff

glass nest
#

Ok.. 1 gift done πŸ˜„

daring jackal
#

Those are cool

glass nest
#

Faulty - can I DM you real quick?

daring jackal
#

Yeah sure

glass nest
#

done πŸ˜„

rapid merlin
#

I’m back

rapid merlin
glass nest
#

Probably

rapid merlin
#

There’s these new things you can get

#

They’re like Minecraft blocks but magnetic

#

And you can build Minecraft irl

#

They’re pretty cool

#

Also there’s these cars you can get that you can drive around walls.

#

4 year old can get a baby doll

glass nest
#

I did print this a while ago..

rapid merlin
#

I want it πŸ˜†

#

I’m going to be nerding out my bedroom soon

glass nest
#

Does that mean I'll be getting requests for 3d printing copyrighted material?

rapid merlin
#

Yeah 🀣

chilly veldt
#

hmmm, should, should not hmmGe

#

thinking about going to car meet today

glass nest
#

It'll get you out of the house

chilly veldt
#

yeah, and hang out with friends

glass nest
#

reckon it'll do you good?

loud marlin
#

was at frineds house for 5 min and i end up with lenovo thinkpad t450. looks new cos stil have stickers =/

chilly veldt
#

guessing it will, though not part of plans cause fuel limit

glass nest
#

Shame your bike is still in bits 😦

chilly veldt
#

I do still have a couple of liters in my bikes tank I can put in my car

#

helps with not watering my fuel lines on my bike over the next couple of months due to vapor

chilly veldt
glass nest
#

I dunno, Bella. I find that once I layer up, a dry winter dark afternoon is a really nice relaxing ride.

chilly veldt
#

it's 5C with 10m/s

#

and I only have summer clothes

glass nest
#

Ahh. ok

chilly veldt
#

ends up with like 3C 8m/s

glass nest
#

but if you pop a wheelie, that will block some of the direct wind πŸ˜„

chilly veldt
#

pop a wheelie on a summer tire with 200kg bike? kek

glass nest
#

I'm just putting off my xmas shopping. I'm about halfway done πŸ˜„

chilly veldt
#

lmao, fair

#

I haven't done any shopping yet

glass nest
#

Well, I figured anything I order online should really get done this weekend, so if it doesnt arrive for any reason, I'll have wiggle room

chilly veldt
#

I just have to go to 2 stores, but haven't felt like it yet

fair lava
#

True MITM should alter traffic between parties without their knowledge

loud marlin
#

ubuntu .iso almost 6gb... =/

chilly veldt
silver sky
#

Incorrect

#

I ride in the dark

chilly veldt
#

with the people here it is

glass nest
#

Yeah, People are the worst.

chilly veldt
#

mostly due to my appearance as well, as I don't have winter attire for bike riding

loud marlin
#

take lanter toi have more light πŸ™‚

chilly veldt
#

I have to go to the store to get wide elastics πŸ™ƒ

#

to get the last screw off my carb

glass nest
#

Or a drill bit

boreal scarab
#

🎡 ***Dashing through the snow,
In my rusty Chevrolet,
Down the road I go,
Sliding all the way!
I need new piston rings,
I need some new snow tires,
My car is held together by a piece of chicken wire!
Oh, Rust n' Smoke,
The heater's broke,
The door just flew away,
I light a match to see the dash,
And then I start to pray-ay,
The frame is bent,
The muffler went,
The radio it's ok,
Oh what fun it is to drive,
This rusty Chevrolet!***🎡

rapid merlin
#

Nice

boreal scarab
loud marlin
#

so you push door when says pull ?

glass nest
loud marlin
#

new laptop thinkpad t450. i5 5300U, 8gb ram, intel hd graph, 256ssd...

glass nest
#

tims typing... but theres 5 mins to go....

loud marlin
#

i think ill put kali on it...

pine belfry
#

website running slow for anyone else?

crystal mauve
#

Ahhhhh I just figured out the alien thing guys

glass nest
#

Any second now.....

#

Waaaiiit for iiittttt....

crystal mauve
#

So they are going to use this clear deception to introduce tech that scans wave patterns

umbral bay
#

πŸŽ„ πŸ₯³ thm Advent of Cyber 2024 DAY 14 Let's Go! thm πŸ₯³ πŸŽ„

glass nest
#

There we go πŸ˜„

loud marlin
crystal mauve
#

The drones in nj

#

They want the rights to scan wireless information

loud marlin
crystal mauve
#

There's currently not enough law on the transmission of information through airspace

manic blade
#

hi i need help to learn bufferoverflow attack can any one send my website that i can learn form it plz

loud marlin
#

might try you faworite search engine ?

boreal scarab
#

Ngl... I was thinking about wardroning

cloud quiver
loud marlin
boreal scarab
boreal scarab
chilly veldt
#

my hands smell like fuel now kek

boreal scarab
#

Drone talk
AOC talk
Bella: "My hands smell like fuel now"

wintry edge
#

hi

boreal scarab
worn thorn
#

typical general talk

wintry edge
#

right

#

lmaoo

worn thorn
#

only missing someone asking sus questions for learning purposes

boreal scarab
#

Moosic

true urchin
#

just kidding

boreal scarab
worn thorn
chilly veldt
boreal scarab
chilly veldt
#

it was right next to the "idk if I am going to a car meet tonight"

boreal scarab
#

I joined to sing my little song lol

boreal scarab
chilly veldt
#

oh well, imma ciphen some fuel from my bike to my car so I got a bit more to run on

#

hackers am i right

umbral bay
#

Also still using the πŸŽ„ as an upvote (you can not unsee that)

loud marlin
umbral bay
#

THM Magic happening daily. πŸͺ„

wispy sparrow
#

Is it me or are some "Easy" CTFs hard

true urchin
loud marlin
chilly veldt
#

Time to do some hillbilly stuff

formal ermine
#

is this a moment when most vm are in use?

random sequoia
#

Guys do you think ai will replace cyber security jobs?

wispy sparrow
#

hell no

loud marlin
#

no

finite tulip
#

no

loud marlin
#

ai is dumb πŸ™‚

worn thorn
#

it will assist not replace

#

also that

mossy river
#

I think AI will be added to tools

#

For example ghidra with AI would be interesting

#

You can actually see AI analysis of Malware on sites like Virus total

worn thorn
#

gonna be an arms race between competing entities

loud marlin
#

i might learn it eventually

wispy sparrow
random sequoia
#

I get afraid when I see news about ai and Stop learning then watch motivation videos to start again

loud marlin
finite tulip
#

We already have a bunch of tools to help us, even though they may not be AI per say, they help automate some processes, AI may expand on this.

mossy river
#

AI will only take over if you let it

worn thorn
#

blobfingerguns which might be on its way based on all the implementations

polar holly
#

People of the Cord... I'm on a bus... Wheee... Feel like a kid again. Wheels o nthe bus goes bump bump bump all day long... 🀣🀣

worn thorn
#

ye are losing it

finite tulip
viscid hill
finite tulip
boreal scarab
boreal scarab
#

"It's all arguably top-level trolling on Artisan's part, and it's certainly helped the startup get plenty of attention. It could backfire, of course, especially if potential customers fear reputational damage from being associated with a company that's riled so many people."

worn thorn
#

welp gonna adapt to the crazy people

random sequoia
#

@hushed heath 😒😒😒

hushed heath
hushed heath
mossy river
#

If anti people measures exist to stop humans from figuring out how cyber attacks happened, there will also be anti AI measures. Humans will always be needed in one way or another

random sequoia
#

@hushed heath means it can reduce the demand

hushed heath
wary root
#

Website slow for y'all also?

random sequoia
#

@@abril.livia are you not afraid?

#

@mossy river ☺️☺️

whole yew
rapid merlin
#

^

whole yew
#

I will always be fine, as I'm an actual domain expert, but entry level will be affected because business people will deliberately not understand that people like me aren't replaceable by AI, and they will not want to hire junior roles so they can be trained to replace me.

rapid merlin
#

when doing a room about a tool on thm are we supposed to know how to use the tool afterwards or is it more like: i get what the tool is used for?

whole yew
#

Most of the tool introduction rooms I've seen on THM aren't intended to make you an expert in the tool; it's an introduction so the next time you encounter a problem that tool can be used for, you will remember "oh yeah, i remember something like this.... [tool] is what I should use for this kind of problem"

random sequoia
#

@whole yew can we hack the ai system

whole yew
#

You need to be more specific

#

What system?

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @whole yew (current: #11 - 792)

random sequoia
#

@whole yew ai

whole yew
#

ML-based systems are notoriously "easy" to poison with malicious data, for a given value of "easy"

rich cosmos
#

hi in today's challenge in AoC , do I need to run an AttackBox to see the content of route-elf-traffic.sh ? I want to keep working on my local machine

rich cosmos
#

ok thanks

chilly veldt
#

@glass nest the elastics trick doesn't work πŸ™ƒ

glass nest
#

Aye. Works better on things like hex bolts. Was worth a try though

chilly veldt
#

yeee, guess I'll give it a wait for when meeting with my grandpa

glass nest
#

Grandpas always know all the tricks

rapid merlin
#

evening bella, how ya feeling?

chilly veldt
rapid merlin
#

evening esqy aswell

chilly veldt
#

cause my grandparents lived 5 minutes away from them

chilly veldt
glass nest
#

Yeeeaaahh, but you can't beat Grandpa knowledge. Legends say it's better than Uncle knowledge

chilly veldt
#

yeeee

#

so might bring the carb with me the 21st

polar holly
#

Uncle Esqy... Guess what mode of transport I'm currently using?

rapid merlin
glass nest
#

a tron motorcycle?

#

A snowmobile?

polar holly
#

No a bus... I thought these things are myths

chilly veldt
polar holly
#

It's like a long haul bus. Has got 4 wheels and a trailer to boot. Also on my way to Cape Town for holiday

glass nest
#

Ooh Cape Town. thats one of the two places in SA I could name off the top of my head :p

polar holly
#

The other one?

glass nest
#

Johannesburg :p

polar holly
#

Voetsek...

glass nest
#

You have home-turf advantage πŸ˜„

polar holly
#

Mean that's a place and all, but I hate Johannesburg. I'm in pretoria. They're our rivals.

#

I mean yeah, I do. I don't know all the places in England. The only ones I know are Brighton and London. Then I mess up.

glass nest
#

Is pretoria not a microstate?

#

Wait, I'm thinking of Lesotho

loud marlin
#

capital of s africa

polar holly
#

No... LMAO it's where the Union Buildings are. Basically the white house of South Africa

#

And yeah it's a capital of South Africa. Can't remember if it's judicial or administrative. But one of the two.

glass nest
#

Ahh. Like the ACT in Oz

polar holly
#

Yeah... And I just checked it up, it's the administrative.

#

But yeah. countries man. You might not like it all of the time, but when you leave it, your heart yearns to return to see those blue mountains and brown skies... Oh wait it's the other way around.

glass nest
#

Or that way around πŸ˜„

polar holly
#

LMAO

#

Anyways, need to go. Laptop battery not as good as I once thought. Barely on and it's already at 25% mind you I used it to do the AoC today too.

quaint sleet
#

guys is tryhackme server is down?

glass nest
#

Peace out Arjay

little linden
#

anyone here know about arm64ec integration on windows

glass nest
#

HAMD - Might just be overloaded.

quaint sleet
sweet sentinel
#

bro i got timed out from the owlsec server for singing the sigma sigma boy song 😭

sand trench
#

YAY it is dragonfable warring time

ashen marsh
#

hi

loud marlin
#

hi hi

shadow chasm
#

I have a question about installing kali linux on virtual box?

#

What partition option should I use for Kali Linux for VMware? entire disk or entire disk with LVM.

modest burrow
#

Entire Disk(in my case)

boreal scarab
#

I hate ISP routers with a burning passion

forest comet
#

Hi its a pleasure stay here i need help somebody help me please i need Know where its the password of the fisrt machine in the operation tiny frostsite and know if the machine can be dangerous? im sorru im a begginer but i wanna try

boreal scarab
#

Was working, then boom.. nothing

loud marlin
modest burrow
#

Explain more detailed

forest comet
modest burrow
#

Nah,its just that i didnt understood what you asking

forest comet
modest burrow
#

Or maybe just bcs im high..

midnight coral
#

Hey I am new at thm , can someone help me through this

modest burrow
grim sparrowBOT
modest burrow
#

Aint no way you actually checked a tenor URL

shadow chasm
twin ridgeBOT
#

Gave +1 Rep to @loud marlin (current: #26 - 371)

twin ridgeBOT
#

Gave +1 Rep to @modest burrow (current: #1645 - 2)

loud marlin
modest burrow
shadow chasm
#

I don't mind if the vm enviroment gets wrecked as long as my system is not affected.

modest burrow
#

Whats your setup btw?

shadow chasm
modest burrow
#

Uuu

#

Asus VivoBook?

shadow chasm
#

No tower

modest burrow
#

Aaaahhh

#

Tower

#

Cool,i thought its a laptop since you didnt say anything about GPU or ram

#

Btw

shadow chasm
#

I need more disk space . I have 16 gb of ram and 500 gb storage currently. I have a 1tb drive I need to install.

modest burrow
#

If you getting started with Kali Linux i would recommend dual booting instead of using a VM

1.It can use the entire resource your PC has

2.On VM you have limited device compatibility and failures can occurs more often(in my experience)

3.Its more performant, less laggy,works 60+hz instead of 30hz that its capped by VM

modest burrow
#

Or,in your case,if you have multiple VMs

daring jackal
#

just completed walking an application on the jr. penetration tester learning path, it was a lot to digest but once i figured it out it wasn't that hard

modest burrow
silver sky
#

No one said you wasn't entitled to one?

modest burrow
#

?

#

You can correct me if you think VM is better

#

VM has its benefits,like dynamic storage

#

Portability

silver sky
#

Given Kali is designed not to be an everyday OS as well as it's a pain to update (easier to just install a new image on a VM) it's better to run it on a VM

modest burrow
#

Indeed..

silver sky
#

Plus you fuck with secure boot by dual booting

#

so

#

upset windows

modest burrow
#

Ah lol

#

Did not even took that in consideration

#

Im personally running it in dual boot mode...it works better than in a VM,but mybe its my fault,probably misconfigured the VM

silver sky
#

Jabba is typing

#

shhhhh

#

πŸ‘€

modest burrow
#

πŸ˜‚

silver sky
#

everyone behave

loud marlin
#

well.. i bonked kali

modest burrow
#

Anyway,do you think im doing wrong by dual booting?

silver sky
loud marlin
silver sky
mossy river
# modest burrow If you getting started with Kali Linux i would recommend dual booting instead of...

Kail Linux is a pentesting OS.
You're more than welcome to run it on bare metal but here is something to keep in mind:

  • If you are a security professional, you should not be performing any of your actions on your host. It's bad practice.
  • Security-wise, you should expect that you are interacting with malicious actors and software, it would be incredibly insecure to do so on your host
    • Furthermore, if someone does infect your OS, using a VM you can immediately stop them
  • It is a pentesting OS, it's meant to be setup on the go. I can understand not wanting to setup Ubuntu every time with all your tools but Kali is intended to avoid all of the setup and just immediately get into work
  • If you mess with something on your host machine, there's no snapshotting, you lose your entire host. A beginner should experiment on a VM because Linux isn't as protected as Windows or Chrome OS, you will mess up something sooner or later
modest burrow
grizzled wing
#

the burp suite related tasks are so much fun

rapid merlin
#

can just reference it every time someone asks whether they should run kali on a host

modest burrow
#

When installing,i saw multiple opstions: bare metal,vm,air-gapped,etc

exotic maple
#

Not sure if anyone has experience with metasploit but I’m new to the program and I’m in the process of installation and when I try to run the console .bat file I get an error β€œcannot load such file - - rex/powershell/psh_methods (LoadError)” if anyone has some insight I’d appreciate it, I’ve allowed the files through windows defender and I’ve already uninstalled and reinstalled metasploit

modest burrow
#

I chose bare metal,but maybe ill change to a vm aswell after this advice

boreal scarab
#

Fuck ISP routers, fuck ISP routers, fuck ISP router!

AMkannamiddlefinger πŸ–•

boreal scarab
loud marlin
shrewd escarp
rapid merlin
#

Back to studying

daring jackal
#

guys

#

what should i eat

loud marlin
#

garbage πŸ™‚

daring jackal
#

😎

modest burrow
silver sky
daring jackal
hexed kestrel
#

What are all the certifications I can get through THM?

wary root
#

Stupid question perhaps, but how come sometimes you need to add an domain to /etc/hosts but sometimes not? How can you know when you need to do it or not?

loud marlin
rapid merlin
#

Anybody know whether it's possible to force certain file extensions (.PNG, .JPG) to go to a specific folder in obsidian?

whole gazelle
#

πŸ“ !!!

loud marlin
boreal scarab
#

I should get a new SSD for my laptop, put Qubes on it, running whonix. Why? Because......... Yes

polar shale
polar shale
wintry edge
#

does anyone here have a degree in cybersec/ or a job in cyber? can i talk to them

broken rampart
#

Hi, nice Advent of Cyber 2024 🀟

rapid merlin
polar shale
polar shale
rapid merlin
#

mental outlaw the goat

polar shale
polar shale
rapid merlin
#

daily driving Qubes is overkill for most people

#

you're more than welcome too if you want

boreal scarab
polar shale
rapid merlin
#

Qubes is way too complex for any VM lmao

blazing granite
polar shale
polar shale
#

O kde

#

Lol

blazing granite
steep mountain
polar shale
#

I dont like kali linux. Just import the repos on any literally any other debian based distro. I think kali is best for exposure or if you just dont ahve time for some reason

blazing granite
polar shale
#

I thought kylin discontinued

#

Daily Driving Red Star OS πŸ˜‰

cloud quiver
polar shale
cloud quiver
polar shale
#

Im not a big discord person but i actually enjoy coming here

#

Just thought discord was some gamer stuff for a while so i just left it alone

#

Need connect my thm tho

cloud quiver
loud marlin
#

@glass nest @boreal scarab middle part print =/

rapid merlin
#

what you printing

loud marlin
#

atlantis ship/town

rapid merlin
#

my friend one time printed a phone case for himself

#

it was pistol shaped

#

XDDDD

loud marlin
#

there is lots thing to do

rapid merlin
#

true that

loud marlin
#

i did tbh print few movie props like guns. for some friends

rapid merlin
#

oh cool

#

sounds fun

#

are you good at 3d printing

loud marlin
#

not sure how good. i just press print lol

rapid merlin
#

nice

loud marlin
#

bonked kali 2nd time in row...

sand matrix
#

Do we get private vpn configuration file, after subscription??

silver sky
#

You get access to premium servers

rapid merlin
#

which means better speeds

#

among other benefits

sand matrix
#

The configuration file the is used is downloaded form /access page, in case of subscription also.

loud marlin
#
  • all the content
sand matrix
rapid merlin
#

I think

#

but I don't see how that has anything to do with subscriptions

lethal fog
#

What makes more sense: encrypting a zip file or encrypting all the files in a zip file? πŸ€”

little siren
#

No intro, dumps spam, thinks it will help, snorlax

rapid merlin
#

@mossy river idk if you got the first ping, mb if you did

#

I edited the msg to include him so I don't think he did

loud marlin
#

@whole yew might ?

sand matrix
#

Is EU-VIP vpn servers are different from regular one? I am asking VIP is mentioned in the name.

mossy river
#

Can you DM me with more details, please

rapid merlin
#

Yes, they have better speeds & better reliability, as with most things that are paid

#

@sand matrix upvote

sand matrix
#

Can I use any vpn server configuration file to connect?

rapid merlin
#

unlimited attackbox aswell I think

rapid merlin
sand matrix
rapid merlin
#

...

blazing granite
#

...

wanton ingot
#

Is there any detailed documentaiton for what I have to do to upload rooms to thm?

opal perch
#

aaa

sick lance
wanton ingot
wanton ingot
#

Yep, those articles is exactly what I was looking for - I knew there must be some somewhere haha

#

thanks

#

Oh wow, interesting:

Brute force actions performed using the AttackBox should be completed within five minutes or less, considering that each user may have a unique VM configuration. Ensure that any hashes intended to be cracked do so within the specified timeframe using either Hashcat or John with the rockyou.txt wordlist; if an alternative method is used, provide hints accordingly.

Knowing this might save me some time when completing rooms in the future πŸ˜‚

#

Actually @sick lance is it ok if I DM you quick?

fair lava
opaque ember
twin ridgeBOT
#

βž• Gave the role Creators-Lounge to squeezed.lemon

sick lance
loud marlin
#

No access =/

wanton ingot
#

πŸ˜„ Thanks. Don't want to too give too much away about it though lol, incase it ends up on ther

little siren
#

Did anyone manage to do todays AoC task on their own device (not on the attackbox)?

sick lance
#

No, as the script won't work, and THM don't advise you to take materials off the attackbox to use.

little siren
#

I see

#

That makes sense I was a bit mad that there was no download button as usual

#

A warning about this would be cool

sick lance
#

There may be something in the THM's ToS.

little siren
#

I meant as in the day instructions

#

Im reading them again and it doesn't look like it says u must use the Attackbox anywhere

sick lance
little siren
#

I might be wrong but that doesn't mean Attackbox is a must

granite narwhal
#

& what will do in linux

granite narwhal
loud marlin
#

fresh kali install...

boreal scarab
#

@rapid merlin Think we raided your house

rapid merlin
#

ready or not?

#

LO

boreal scarab
#

Yeeeeeep

#

New DLC

rapid merlin
#

ah nice

#

I played it briefly a year or two ago

#

I never fully got into it though,

wary root
#

is it possible to find someones finished rice for kali, and download it as an "finished product"? and if it is possible, are there any "well known ones"

rapid merlin
#

ricing kali is pointless, it's inevitably gonna go boom eventually

#

no point wasting your time finding or creating one

rapid merlin
wary root
#

I mean if it's one command in the terminal, maybe not useless

#

πŸ˜„

rapid merlin
#

Still not worth it

#

plus then there's learning the keybinds

#

and everything else accompanied with ricing

wary root
#

aight

rapid merlin
#

If you wanna just change terminals or wtv, fair enough

wary root
#

honestly, I don't know. Just seen some pictures and it looks nice, so got interested. But won't bother with it myself, I'm too new to unix

rapid merlin
#

yeah, ricing is more advanced things and honestly, usually just causes complete headaches

#

And taking about plants I saved some at B&Qs death sale

#

The plants that barely made it

rapid merlin
#

love how wacky and stupid those films are icl

rapid merlin
#

And I come along and buy them all

rapid merlin
#

Β£2

#

😏

#

idk, I need to stop being lazy and get a job so I can start getting certs done LOL

wary root
#

just get one blobfingerguns

rapid merlin
#

Wow I with I had thought of that

rapid merlin
rapid merlin
wary root
rapid merlin
#

I'm extremely antisocial and barely spend any money anyway

#

But I suppose in the long run the pay makes up for it

rapid merlin
rapid merlin
#

I mean is it a waste though

#

😏

#

valid ig if you enjoy it

rapid merlin
#

can think of worse addictions to have

#

Everyday

#

πŸ˜‚

wary root
#

i own a total of 0 plants

#

best so, they would live for like three weeks until they would be dead

rapid merlin
#

I know a lot of people wont keep them because they just kill them

rapid merlin
#

β€œBe prepared” was a banger

#

yeah he was so funny

#

hades was sassy asf too iirc

wary root
#

the thm services today has been fucked

daring jackal
#

almost done completing content discovery😌

wary root
#

are they being perma DDOSed or smth

#

my target machines just randomly dies

loud marlin
#

big amount of users

silver sky
#

plus THM machines are hosted on AWS not THM

rapid merlin
#

downsides of running free ATKBox

#

I'd recommend just doing it on your VM(s) anyway

#

probably better

loud marlin
#

hmm... weirdly i got logged out of thm for some reason =/

rapid merlin
#

session timeout?

loud marlin
#

no. off the site. but ok

rapid merlin
#

ah

daring jackal
#

i was trying to answer this question after following the steps in the Subdomain Enumeration room and i even looked up videos to help without trying to cheat to make sure i wasn't tripping but the answer would not pop up no matter what i did

#

i got it now but damn

sand trench
loud marlin
#

why mi kali screen is weirdly bright =/

loud marlin
#

so thinkpad have external and internal battery... how that works? are they active in same time or ?

loud marlin
#

ello

rapid merlin
#

Gawd I am tired

loud marlin
#

sleep

#

or coffee

sand trench
#

β€œI have nothing to hide”.
It’s become a default response from many to overreaching surveillance.
When did privacy start being about having something to hide? It used to simply be about having the right to decide for ourselves who gets access to our data. But over the past decade we’ve lost that choice, and so much of our personal and sensitive i...

β–Ά Play video
loud marlin
#

you wished to start at that time or mistake ?

sand trench
#

welpies time for meeplies mlooplies to the beep boops for the sleep sloops

sand trench
#

each point is kinda self contained

loud marlin
#

will watch it

rapid merlin
#

is DFIR, Threat Hunting or Malware analysis part of L1 / Tier 1 SOC analyst job?

#

or is it just log analysis and event triage?

clear jackal
#

More than likely not, it really depends on the org. I wouldn't bet on it though

crude stump
#

But titles to begin with make no sense because each company has you do different stuff

rapid merlin
#

it wouldn't make sense since tier 1 are the ones who escalate the events though

#

like how will they have time to do DFIR and Threat Hunting

modest mica
#

whats the best free vm for windows?

rapid merlin
#

probably virtual box

modest mica
#

does it depend on what you're doing?

#

like which one you choose?

rapid merlin
#

me i use wsl

#

bcs for linux i just do basic terminal usage

#

but if u want full vm virtual box is the best free one

crude stump
#

That’s why tier 3 and tier two are the ones that usually dive deeper

rapid merlin
#

and then vmware best paid one

crude stump
#

VMware came out with a free version

rapid merlin
#

virtual box was better imo

modest mica
#

so should i get the free version then or try virtual box

#

aight

#

ty

crude stump
#

Really depends. I agree with virtual box tho

rugged kayak
#

vmware workstation pro is now free for personal use

rapid merlin
#

vmware is better if u pay

crude stump
#

So pretty much anything that has a paywall

rapid merlin
#

i don't think i tried pro

#

yeah might be better than virtual box then

rugged kayak
#
VMware Workstation Zealot

VMware Desktop Hypervisor products Fusion and Workstation are used by millions of people every day to run virtual machines on their Windows, Linux and Mac computers. They give users the ability to quickly and easily build β€œlocal virtual” environments to install other operating systems, learn about technology, build and test software, complex sys...

rapid merlin
#

i think i tried it before they made pro free

queen halo
#

I'd recommend trying both :b
It was a bit of a hassle to set up the account for VMWare Workstation Pro though

remote jewel
#

anybody got a link to DL kali on UTM? only finding virtual box links

rugged kayak
opaque flax
remote jewel
#

got it

#

XD

#

thanks

shell peak
crude stump
shadow chasm
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #5 - 1384)

cyan sapphire
#

Hey πŸ‘‹ college student cybersecurity major here!

wet rivet
#

is there a way to have the website into a dark mode?

glass nest
#

Check that link

wet rivet
#

is there a preference section just wondering

wet rivet
twin ridgeBOT
#

Gave +1 Rep to @glass nest (current: #17 - 506)

glass nest
#

Looks that way. I just use the Dark Reader extension on Chrome, so.. It's always been dark mode for me

rapid merlin
rapid merlin
cyan sapphire
wet rivet
rapid merlin
#

How are you liking it so far?

uncut pewter
#

Hi

rapid merlin
#

hi

brittle lynx
#

Hello

#

I'm about to launch into the red team capstone

#

ANy tips for me

cloud quiver
zealous basalt
#

Hey
I need a platform to master linux
Suggest me some

cloud quiver
#
knotty pendant
#

How do i make linux my default os

#

I want ubuntu

#

I tried usb and it doesn’t work

rapid merlin
cloud quiver
rapid merlin
#

so we can actually help you

cloud quiver
rapid merlin
#

cause usb installing is a pretty much well stablished op

#

you are probably making one mistake along the process but we dont know if you dont show us

knotty pendant
knotty pendant
cloud quiver
knotty pendant
#

Ok i will try that

#

I already have unetbootin but when i try that it says it’s missing a file

#

And i put ubuntu on it

loud marlin
#

@boreal scarab @glass nest it start to look alike ship... and thi is 30cm ruler to compare size =/

rapid merlin
#

I want to start in cybersecurity, and I would like to know if there is any roadmap you can recommend.

cloud quiver
cloud quiver
rapid merlin
#

thanks 🫰🏻

knotty pendant
#

@cloud quiver is there any other way to install linux?

cloud quiver
loud marlin
#

there is multipla way to install any linux

knotty pendant
#

Before windows 10 is unsupported

loud marlin
#

then you need find one you wish. download, get it on usb and install. depend what linux you go with there is one or two thing different from others

cloud quiver
loud marlin
#

dual boot is not so smart to go with. it can brake stuffs

knotty pendant
loud marlin
#

if you need windows the go with dual boot. but first read of possible issues. brake grub, bootloader things and so

loud marlin
#

then you put linux of choice on usb with rufus or some windows tools and then boot that linux from usb and go from there

knotty pendant
#

Ok

knotty pendant
loud marlin
#

format that usb before

wooden totem
knotty pendant
#

Im actually going to change to kali

#

@loud marlin should i use the kali installer or a different one

#

Like live boot

loud marlin
#

kali is not smart to use for main os. it is unstable

knotty pendant
#

Oh

loud marlin
#

kali is best for VM

knotty pendant
#

Welp

loud marlin
#

try ubuntu linux

knotty pendant
#

Can i still use a vm in ubuntu

loud marlin
#

is much better and is wide used

#

yes

knotty pendant
#

πŸ€‘

inland cave
#

Never once had any problems with kali

knotty pendant
loud marlin
inland cave
#

I run multiple systems on different devices

#

Not the best but not stable? Idk

loud marlin
#

it is also hacking os. you never know what can cause issue. and have way big amount things that updated all the time. that can cause issues...

inland cave
#

What?

loud marlin
#

after updates can cause issues. long story short... not so smart idea to have it as main is or dual boot

inland cave
#

Just run it in vm what’s the need to run it through bios boot

wooden totem
#

blackarch as main os 🏴

knotty pendant
wooden totem
#

pen distros should still be on vm tho

wooden totem
knotty pendant
#

My usb is now called UbuntuπŸ€‘

wooden totem
#

parrot is the best kali alt

knotty pendant
#

Yes

dark frost
#

my mother called my linux vm , a video game πŸ˜†

knotty pendant
#

My mom called my pc a cpuπŸ˜”

#

@loud marlin thank you for helping meπŸ€‘

twin ridgeBOT
#

Gave +1 Rep to @loud marlin (current: #26 - 372)

knotty pendant
wooden totem
#

I have full metal USB sticks and if I accidentally leave one plugged in for too long it gets too hot to touch

loud marlin
#

i have same issue with usbC hub thngy

opaque flax
inland cave
#

What are you running it on?

wooden totem
#

I just realized I forgot to turn on the heating 7 hours ago and now my room is at 7Β°C

#

idk how I didnt realize its cold af

opaque flax
wheat mesa
#

Hi guys, I'm having a problem in my lap, the internet has been slow for the last week while browsing, but the other devices connected to the same wifi has better speeds, what could be a fix

inland cave
opaque flax
late stag
inland cave
#

It’s running hot because your processor

opaque flax
#

Ok

cyan sapphire
split plover
crystal mauve
#

I love those old dell keyboards

knotty pendant
#

Im just installing it

rapid merlin
#

glad to hear that

#

what was the problem?

#

i guess secure boot or something aching?

knotty pendant
pliant cairn
#

is it just me or google search results kinda look rigged

acoustic obsidian
#

guys what's the most practical ctf categories?

cloud quiver
acoustic obsidian
#

ones which can help you find real world vulns

late stag
acoustic obsidian
#

and the skill needed to find real world binary exploits is probably super high

acoustic obsidian
acoustic obsidian
#

thinking which to do next

#

dont want to be a one trick pony

late stag
# acoustic obsidian feel like pwn isnt really that useful anymore as there are more and more memory ...

There are tons of things written in C and CPP (starting from Linux and Windows kernels). Those to stay for a very long time.

The barrier to binary exploitation is higher now, it’s not nineties anymore when one could just AAAAAAA everywhere and get a core dump. But it’s the same with Web, you cannot hope to find a SQLi when modern framework is in use.

However, both have values because not every app is written in Rust or uses a framework.

acoustic obsidian
#

practical in the aspect of getting a job in cyber ig

#

hence why i'm asking which category is the next best to learn after web, for real world application ig

late stag
molten sky
#

mods are asleep, post sinks

late stag
#

You are increasing your employment chances by knowing KQL and how firewalls work, not by learning ASLR bypasses.

acoustic obsidian
#

i kinda wanna do pentesting too, so offensive is still needed for that

late stag
knotty pendant
#

😝😝

sleek bolt
#

NEEDED HELP

knotty pendant
late stag
sleek bolt
knotty pendant
#

I have no idea what that means

sleek bolt
#

you know about log4j vuln?

molten sky
#

that's a myth

late stag
molten sky
#

just read your msg history --- if you're looking for irl stuff you should ask @shell nova he makes those rooms

sleek bolt
opaque flax
sleek bolt
#

and log4j vuln is 3-4 yrs old and patched in most of the networks

late stag
opaque flax
late stag
#

That too.

sleek bolt
opaque flax
#

general infosec discussion and tryhackme...

sleek bolt
#

its a htb machine is that illegal here?

opaque flax
#

ya know

#

rule 5 says what you should do

sleek bolt
sleek bolt
opaque flax
#

you're funny

sleek bolt
#

whatevr

opaque flax
#

why don't you ask the HTB discord for help. it's their box

sleek bolt
#

it does not matter

#

im aking ab log4j vuln not solving the whole box for me

dull storm
#

Where can I find the rules for this group?

dull storm
#

Thx

sleek bolt
dull storm
#

Just asking a question so I don’t get kicked. If I wanted to recommend a new cyber security community not in competition with THM but to help and learn extra about Cyber Security could I do this? Or is that considered self promotion? It’s not my community I’m just trying to help out another CyberSec Professional who’s looking to build a community for Learning and Connecting with other professionals?

loud marlin
rapid merlin
#

anyone knows how to update the role on Discord?

sleek bolt
# opaque flax

forget about other platform , i just wanna know about log4j , im not talking about the machine

#

bro wants to be a discord mod ig

rapid merlin
#

no, i want to update the level

#

I'm 0xB now

abstract birch
#

hey guys

#

3 weeks ago the lockbit ransomware operator caught by the FBI

cloud quiver
abstract birch
#

?

rapid merlin
#

Probably start learning programming

#

From there you do you

abstract birch
#

which language will be best so that i will not be caught easily

rapid merlin
#

πŸ’€ You sound shady ahhh

#

But I'd go with C if I were you, pretty low-level, programs systems pretty well

abstract birch
#

yeah i am expecting this answer

rapid merlin
#

Pretty steep learning curve though

abstract birch
#

performing a international level ransomware operation sounds like too risky but i wanna do that in upcoming years

rapid merlin
#

πŸ’€

abstract birch
#

do you think it needs a very high processor pc...?

rapid merlin
#

Brother no

#

It's just programming

#

Besides it's time to pull out this copypasta

#

In case of an investigation by any federal entities or similar, I do not have any involvement with this group or with the people in it, I do not know how I am here, probably added by a third party, I do not support any actions by the member of this group

#

Cause you're SUS

abstract birch
#

where are u from

rapid merlin
#

good question

hoary tiger
#

πŸ˜‚ lol

abstract birch
#

me too is a indian

hoary tiger
#

πŸ‘

abstract birch
#

i think its a good server to talk about this thing

rapid merlin
#

But I'm not indian

abstract birch
rapid merlin
#

That, my friend, is a very good questioncoolguy

polar wraith
#

@mossy river

hoary tiger
#

πŸ’€ lol

rapid merlin
#

Are you sure you know what discord you're in..?

eternal tartan
#

hey guys do you think we can really learn hacking from 0 with tryhackme ?

abstract birch
rapid merlin
#

just complement it with some extra resources for networking and whatnot

eternal tartan
twin ridgeBOT
#

Gave +1 Rep to @dim mason (current: #2497 - 1)

abstract birch
#

i will suggest you a yt channel which i found best for the basics

#

anon Ali

eternal tartan
#

ok ty

#

i will learn the basics of intenet ( ip , THCP...)

rapid merlin
#

Don't get stuck with tutorial hell tho

#

I'd recommand putting everything you can try and learn in practice, take notes and read them every once in a while

eternal tartan
rapid merlin
abstract birch
rapid merlin
#

It's good if you have basics in programming

polar wraith
#

thats illegal

eternal tartan
polar wraith
eternal tartan
#

i'll try ddosing my self x)

rapid merlin
#

If you wanna practice look up vulnerable machines made for learning purposes

abstract birch
eternal tartan
#

no

rapid merlin
#

Fire them up and try to complete them in a safe virtual environment

wooden totem
#

why would you practice ddosing

eternal tartan
#

yk i want to become a white hat hacker, my dad's business got infected by a ransom ware and next time, i want to help him

eternal tartan
abstract birch
rapid merlin
rapid merlin
eternal tartan
cloud quiver
wooden totem
polar wraith
#

mods help him out

rapid merlin
#

Are we telling him?

#

πŸ’€

eternal tartan
#

are u a big fan of them ?

rapid merlin
eternal tartan
#

there is a big hacker group in my country named B13, they are hacking israeli network etc

abstract birch
#

i think sometimes you should watch the documenatry of specific channels like fern covering the cyber updates will give a motivation

eternal tartan
#

guys i have a supposition

#

i think every hacker in this planete played minecraft at least once

#

(sorry for my english I am not a native)

abstract birch
eternal tartan
#

Tunisia hbu

whole gazelle
#

s u p

eternal tartan
abstract birch
whole gazelle
#

hi howdy

abstract birch
#

i am looking for a good team which support black hat hacking and malware development