#general
1 messages Β· Page 629 of 1
Could use it as pepper spray
No lmfao
Rub there eyes with it
She meant to bring the knife.
could have used it to summon an lead a Welsh army?
not anymore, anyhow π
Hmmmm.... Makes sense @glass nest they might take their leeks but they will never take their freedom
Well can you blame us? It was their fault for being in Scotland smh
Okay lads, lasses and hacker kind. I'm off.
Good morning U S OF THE A
Google?
Chatgpt is your best friend

What does the 777 mean, sternn?
Order 777
Its a combination for 3 Groups: User/Group/others.
4: -r (Read)
2: -w (Write)
1: -x (Execute)
4+2+1 = 7 so its (read, write, execute) permissions.
777 is the same like 4+3+1 4+3+1 4+3+1 and gives every of these 3 groups permission

that's illegal, and agasint our community rules.
I mean, you just did,,,
i dont know what ur talking about
Ok. π
Sooo... Can you answer your own question with that information?
What did you say
Has anyone used clicked to get some real world experience before getting hired?
yep already did thank you
Gave +1 Rep to @glass nest (current: #17 - 509)
@dull delta get a grip you knob lmao
Polo g profile picture
Bro is not a gangster
Heβs stupid
I'd honestly never heard of that. Have you used it?
@modest mica Please don't repost deleted messages to try and cause drama.
ahaaaa
I saw it on a YouTube video where this girl used them and basically got real world experience without being employed
I'd be interested in how it emulates 'real world experience'
Me too.
Scrubz - Have you heard of it before?
Nope, I'm interested on how a non real world experirience gives you it.
Yeah. Maybe in the same way THM gives 'real hacking' experience. Controlled enviroments and such
Looks like its an interactive 'Day in the life of' thing
just was watching Black Hills Security livestream and John Strand mentioned this board game, sharing for more awareness, looks so cool! 2+ players
https://boardgamegeek.com/boardgame/182418/advanced-persistent-threat-challenge
User summary:
Advanced Persistent Threat Challenge, or APT Challenge, is a card game for two players with a theme of Advanced Persistent Threat, a method of cyber attack.
Players assume the role of cyber attackers who are planning to steal confidential documents from each other. To achieve their goals, they have to read each other's hand, plan ...
of course black hills has backdoor and breaches board game
I've played this, it's fun.
awesome
Christmas coupon for the win
Yessss


Anyone going to CCC this year?
no, no one is
ouch π¦
It's just gonna be you alone
@pallid lotus Who needs a blade with a wit as sharp as yours
just lurkin
as always
Ben !
howdy veggies
what have you been busy doing?
allllllllllllll sorts π
lotta attackbox stuff recently
okay, that rounds it down
i figured you are behind the scenes keeping the gears working
busy doing data science stuff
started reading malware data science book from the humble bundle
oooh yes
I got maybe half way through, it's what gave me the idea for my dissertation back then
awesome
if you ever wanna get side tracked, network data science is quite fun π
capturing packets via wireshark and see where the traffic is from/going?
more or less yeah. Visualising pcaps etc
I just used a lot of sample ones but you can tie it in with malware, building a network map etc
π
I mean, I don't need an excuse to make a graph π
ohh what about logs, use them for NLP sentiment analysis? would that be viable
i plot stuff for fun too
π
Actually, 46 of my teammates are joining as well
Ah good
We probably have one of the bigger assemblies outside of the general CTF assembly
Mhhm sentiment analysis wouldn't be my first go-to. Maybe something like logistic regression, but sure. Could do quite a few techniques to it. Depends what info you want to get out of them. Maybe k-means clustering - clutering would be good for grouping
yea, clustering those neighbours is a good call.
Would you guys say I should try to join the Air Force for something in cybersecurity or should I try to just do online college on my own and try to get a normal cybersecurity job in the civilian world. I am just worried because I am not sure if I will be able to get a job with not much job experience.
I am 17 years old and I graduate in 2025 so I might have to wait a bit after high school because my mom may not approve me going and I wont be 18 until basically November. I have the Google Cybersecurity Certificate and my Security+.
I like the benefits
military gives you opportunities
Alright gnight(:
The security clearance , Job exp and Job etc
they give you everything you need, plenty of cyber sec people were in military and now run or work in the industry
a networking aspect as well as that matters
if you choose not to go military route, then make a timeline for goals with certs: 6 months to learn X, 6 months to learn Y , etc
build and make a blog or youtube to prove you learned stuff
the online college program gives me loads of certs
Beeeeeen, you didn't answer my DMs π¦
at age 17 is really cool to be into cyber for white hat career intentions
CCSP , ITIL , A+ , Net+ , Pentest+ , Project+ , Cysa+ , Security+
do you know if you like Red or Blue team more?
Like red but blue pays more
dont chase the money,
the money wont last, you need the passion desire
its also a interview question of why are you into this
yea
My mom doesnt like the idea im cutting off my dreads after having them for so long
yea
Hitman is taking so long to install π«
Just remember that you need to score high enough to 1) join the Air Force, 2) high enough for the MOS, and 3) they have to accept you
but I don't have any other games or anything installed π
Well multiple factors effect download time
Including your internet speed! Not just how fast it can write to your drive
it's especially painful cause my mind is in hyper drive rn and it's probably got a couple hrs left at-least π
Just go to sleep, it's a weekday, don't stay up late
My sleep schedule is horrid rn, I'm waking up at like mid-day π
so I've just been up 12h
Smh smh
yeah, it's also killing my motivation to do anything
sleep sloops to the beep boops for the meep moops timey whimey
someone told me you look like an owl
hello 
hoody and the blowfish
ayoo guys
You just completed a path and got the cert, now if you change your name, can the changes be reflected on the cert?
Is thm down?
What is that?
Fud
Seems to be working for me.
CHicken and fries
Oh okay, sorry never heard of fud , looks good!
Fud, a stupid way to say food

Like sammich and sandwich
Haha, thanks for that. I had no idea, I get it now, lol

Yeah does look really good, hard to see any fries in that pic.
It's under the chimken!
Hi frens, please redirect if this is not the right place for this question. I'm trying to install linux on my gaming laptop. I've tried both Kali and Parrot and just keep running into issues with wifi and installing packages for some reason. I decided to install Ubuntu but I'm curious if anyone else is not using Kali/Parrot and what you do to go about installing all of the tools for THM.
you use Kali as a virtual machine
Ya, I'm doign that now and I hate it. It's so choppy and laggy it drives me crazy.
do you guys think this is a good computer so far
I've tried with Virtualbox and UTM (on my mac). I also have a kali instance in proxmox that I SSH into sometimes. I've even installed KASM on a VM in proxmox and tried that. Nothing feels natural so I just don't like using it.
well how many resources do you give the vm
Usually 2-4 cores, 4GB of memory.
what are you doing when it is choppy and laggy
Just even scrolling websites. It's not smooth like as if I'm directly on the OS.
well most of the tools that kali uses are just in the apt repository
and you can always add the kali repository to your apt sources
Like should I be expecting the VM to run as smooth as a normal OS?
i hate sql so much bros but it is necessary to learn this
When just scrolling websites Iβd say yes. If you can maybe up your resources if possible and see if that helps.
Hmm
Hie @thorn tusk
Can l have hints for Heal Machine on HTB
Thanks π
Gave +1 Rep to @thorn tusk (current: #111 - 68)
Are you using Kali for ARM in UTM?
Ya, I'm trying VMWare fusion now
As this is the TryHackMe discord, I would recommend asking for assistance on HackTheBox's discord
Sure
Or Tylerβs own Discord.
Given that you can have most of the tools directly on macOS via brew or macports, consider going native.
well that also depends as someone typing on a Mac right now. Most tools are great native but there's still plenty of reasons to have a Linux install around...
but fair I didn't scroll up to read more lol
Homebrew will give you at least 80% of what you need though yeah
Sup all
Not much, how about yourself?
Hello!
Jeez. Gnome-boxes sucks
Not really. It should be reasonable, but you do have to keep in mind however you're connecting is a remote connection, even if it's local
You shouldn't really be using your Linux VM for the browsing side anyways though, that's what your local computer is for. Just use it for the tools you need, ideally via ssh so you have minimal latency
virt-manager is significantly better, thank me later
Gave +1 Rep to @languid pecan (current: #2502 - 1)
god damn it lol
ye i am configuring it rn
one sec
cool cool, yeah it's good stuff
i was actually editing the actual config for the VM instead
Although just a heads up, it will be depreciated in favor of web UIs but nah it's a great app
Virtuabox has some issues I am not ready to deal with
Orcale is toxic indeed
qemu frontend wise though, yeah virt-manager on Linux and UTM on macOS/iOS are just lovely. I've tried more than that and these are the ones who stand out
i tried installing qemu
but ig not ready to deal w its shit too
Just want something that works straight up
you need to launch it via scripts basically if you used it bare
I am very tired
but yeah virt-manager will do exactly what you want so you're all set
also get some sleep lol
looking forward
Ah, I didn't really think of that. I guess that makes sense.
Burpsuite can't really be used via SSH, right?
yes it can!
if you tunnel your HTTP traffic from your VM to your actual computer, you can use it with burp suite and additionally use Foxy Proxy to view websites as if you had that same connection
that's what I do with my pentesting server with DigitalOcean, a Virtual Private Server. I just tunnel any traffic I really need locally back
Quick example: https://serverfault.com/questions/78351/can-i-create-ssh-to-tunnel-http-through-server-like-it-was-proxy
you just need to bind the origin and destination ports
same thing can be done for RDP which is useful for THM
enjoying some time off
nice, I'm jealous!
lol sounds about right

anyways just @pulsar jacinth to make sure they see the above
takes a tiny bit of setup but once it's in place it's no problem
I personally have my ssh tunnels set up as alises in my shell to make it easy
Oh thank you so much!! This is super helpful
Gave +1 Rep to @sinful moon (current: #35 - 248)
Yep no problem!
It's especially magic when this is all working from a VPS in a datacenter rather than a local VM. Blows my mind every time I do so
especially for the RDP stuff
also I don't know if you all have had the pleasure but holy crap is updating Linux from a datacenter massively satisfying. Typically see 3Gbps speeds and higher since either there's a local datacenter repo or it's just that fast
Yep! What about them. Are you potentially looking to verify?
yea the channel aint pop up for me also just checking around to see if i can get what i need
Sure not sure what you mean by that but by verifying your account you should be all set in terms of Discord features like embedding images
does anyone have any recommendations for some linux distros to install? looking to learn a lot more about linux
You can use Kali for beginning
kali, arch, centOS, ubuntu
I do have kali, just want to add some more to either transition to completely or just learn more
Also depends on the use case, if you're looking for a general purpose Linux distro, please don't use Kali. I'd recommend Ubuntu, Xubunut, Kubuntu and etc
possibly to eventually attack later
Kali is fantastic for offensive security but not something you just use all the time
yeah, I definitely want to try out general purpose, machines to attack, and probably create a server for backups
Yeah just get started on more standard Ubuntu based installs, Fedora is a great choice as well.
I use Arch but I wouldn't say that's something to jump into while you're still learning
(that CentOS recommendation above is also outdated, classic CentOS has been retired and there's no reason to use it over Fedora)
I'd just say pick whatever Ubuntu spin looks nicest, they're mainly differentiated by what Desktop Enviroment they come with. Note that most distros are not defined by what DE they can run, they can run anything, as can Ubuntu, but they just have some premade configs which work nicely
cool, thank you
Gave +1 Rep to @sinful moon (current: #35 - 249)
Yep no problem! Let us know if you run into any issues c:
I'll run it all in a vm to figure out what I want
although generally fixing a Linux issue is one google away compared to Windows where it's a hellish experience lol
I know theres a lot of options which is why I was trying to narrow down some specific stuff
Yeah it's not too bad when you start with some of the largest supported stuff like the *buntus. As mentioned above Linux support online (wealth of answered questions) is huge so you'll be fine
A good place even for other distros is the arch wiki as well
Agreed
the end goal is definitely to make an actual server for backups but I know I should learn more about security before I make that jump
eventually Ubuntu Server would be a good thing to run on it, you shouldn't need a GUI once you know what's up, but yep
good plan
I have resources to spare lol
I'm more comfortable with gui even if I'm running only commands anyways lmao
I daily drove Garuda for like 2 years before I took the dive into setting up my own Arch install. Every once in a while I still come across things I've missed, and I'm sure I'll continue to.
I love it.
I know I am kinda jumping in here but I am currently using proxmox if you want something that is web based.
That's fair, but I'd say work to make that transition to just terminal. Learning tmux will help tons
Proxmox is lovely but to clarify to claptrap, this is virtualization software as an OS
yeah, it's always been, I just like having google at my fingertips
I mean kinda the point of something like this is you ssh into your remote machine but still have a full GUI since you're on your local
and then tmux just gives you nice things on your server like "multiple windows"
as a quick example, here's my remote server in a datacenter, but down at the bottom, I have those other terminals I can switch to and a nice little taskbar on the right
just a simple custom tmux config
is there a good place to browse for distros?
ehh, just know that distrowatch "popularity" is gagued by view count and not actual use or voting
I wouldn't really say there is a good spot for that particularly though
Just try Ubuntu or Fedora based distros to get started tbh
I personally used Mint when I first started ,but I think as long as you stay within the somewhat Popular distros you are pretty safe.
DistroWatch can let you know what's out there but shouldn't be gagued as anything definitive by any means
I still don't know why Mint exists, but it did have a reason for a time when Ubuntu had more limitations. But yeah things change
I think its a good first step outside of windows lol.
No reason to use it recompared to a normal *buntu tho
its closer to debian and its not as bloated as ubuntu
So use a different spin
i personally wonder why freebsd seems to vanish more
only reason Mint used to exist was to provide media codecs lol
I love FreeBSD so much, yes it is lovely
the only time i actively used linux, i sticked to gentoo, but back then i had plenty of time and didnt mind to spend houres on configs lol
My first real experience was using mint so I had a Desktop to install Gentoo. That was my first time installing to hardware π .
for now, i rather prefer an enduser linux, in this case mint
I will admit after nearly 20 years on Arch, I don't do much distro hopping. Most other Linux distros are kind of boring to me. but I do professionally administrate Ubuntu Server at work.
I tend of find more interesting *nix OSes a bit of a draw when I wanna try something out
Ah yeah I started with Ubuntu in the mid 00s when it was still GNOME 2 and not that bad, then Xubuntu, Ubuntu Minimal Installs and then Arch lol
i dont like arch, no real reason, just not "my brand" xD
Ah that's fair but I'm big into like knowing everythign that makes my OS tick
arch was my end as well now I have a setup and a script that makes it easy to create and get to working order.
my first linux was SuSE, back then it was in the stores on 3,5" disks .. downloading an OS wasnt an option back then with a 33,6 modem lol
mhmm and archinstall is quite neat. Ironically back to where I stared, back the the day Arch used to have a text mode installer
This guy might be a pro skidder
kali makes me cringe
I mean it's just a tool, but yeah people blow it up to the point that normies think they should install it as their main lol
I'm gald the devs even have a page on telling people not to do that
I can't tell you how many "how do I install Steam on Kali" questions I got back when I was a Linux discord mod lol
00's the barrier was that kids needed to get their linux working, figuring how to compile their tools and actually learn to use them.. otherwise they were stuck to the "windows haxor tools" .. nowadays every kid loads kali in a vm, watches some yt clips and goes wild
god no, why would I ever run kali as main
Yeah you'd be suprised at how often that came up lol
forever to exist in a vm
i did install kali as main on my playbook, it didnt survive the first update lol
Seems a bit more robust these days but I get you. Yeah it's just much more of a one time use kinda tool.
I'm much more partial to getting those same tools installed on my actual Linux distro and understaing both how they work and why I need them
it always feels like a cheat when "oh I already have this but I didn't know why"
i run my mint on my playbook now, everything well configured, installing the stuff i need and im good with. solid solution.
alright even after a quick search, what the heck is a Playbook?
a notebook with no further use than playing around
ugh lol
unnecessary piece of hardware ^^
had me thinking it was a product
I mean even my spares I have use for occasionally, but yeah probably not that
sparebook? xD
nah lol
sidebook as in sidechick?
what do you call my retro computers?
retro computers
they're not on the side but... lol fair enough
nice nice
I have a A500, PIII and P4 machines, along with iMac G3
shiver me timbers
my youth besides the imac g3
get off tiktok
lol
Why
tiktok will be banned anyways .. luckily lol
Isnt it only in usa
its just as bad as every social media
You may enjoy my emulated A1200 setup
more than enough to let it collapse
I dont live in the usβ π€π₯΅π
me neither and still lots of content comes from there
you'll understand when you start looking back at all the time you spent on it
all social media can have their uses but not with all the tracking and alogrithims they have
without usa, a wide gap will be caused
so i rather expect it to go poof
usa is basically the interdimensional cable
loved the way you described it xD
no one watches content from indonesia or the other countries for the simple reason of language .. american content is watched throughout europe
With the new administration coming in, I doubt anything will happen to TikTok sadly
you mean Trump ?
I'd fire it into the sun but that's just me lol
yes, I was just trying not to invoke overtly political names which may inflame people lol
I remember when it was called musical.ly and I had an account when I was like 10
haha its the same with tik tok. i tottaly agree with you
true. but many administrative collectives are now alive
lol what
fyw for normies, tiktok was previously under the name musical.ly and they changed the name to tiktok in 2018 when they were changing the whole look of the app
normies are the people who know this
i think it was its own app but nobody was on it so they merged the slop together
facts
weren't they sold and merged?
typically geeks are above the social media slop
im not too much a fan of social media anyways, but thats based on bipolarity of people ... you sign up on them to share, therefore you need act responsible what/with/who .. and not sharing and being like "how would i know someone sees it? are you stalking me? dont watch my content!" blah blah etc pp .. but thats my personal feeling about it.
mhmm, I kinda noped out of Social Media years ago in the Facebook days. Only really maintain a few for infosec news and etc like Twitter, but what a mess that platform has become
only platforms I use are reddit and youtube, I need to purge all of my older accounts
I'm not sure I'd classify them as the same thing
I personally think minors should be excluded from public access on social media, not only for online safety but also because all the marketing and "tricks" are used on the fresh minds so they get addicted and people get paid for that
i have my linkedin for business reasons, i have insta to follow some friends and share holiday pics with them, facebook.. yea.. a leftover .. x .. also leftover ..
but yes cleaning up your old online presence is great
that's an ongoing process of mine
been moving everything over to my new email and deleting old accounts
and then my blog for some writeups and github .. so publishing reason
it'll be real annoying once I do that stuff for facebook
and beyond, im out of it lol
some accounts I may keep but leave completely "private"
based on lazyness .. rather share pics there for them to see and dont need to show one by one lol
I just wouldn't touch meta with a ten foot pole
fair enough but lol never happening for me
0......
besides linkedin, i dont actively use socials
I do hate it but yeah I'll have to make a LinkedIn before long while job searching
that was my cat sorry
my mobile statistic makes everyone uncomfy when it says 30 minutes per day xD
I do have an active job to be clear, but I want to keep my options on the table
the amount of times I share something and then regret some time later is absurd, so I only stick to discord and youtube
my current favo is discord, but i dont consider that as social.. rather chat or board.. a bit bbs feeling lol
true
alright I'm going to play some Rollercoaster Tycoon and head to bed. Have a good one you all!
thats the right house
hey guys , suggest any movies
What type
horror
Tarrot is a good horror movie
Hey guys, is it possible to find malware source codes for testing because I only see executables on github
Probably
You want popular malware code or just random malware code?
A Serbian Film (PH)
The human centipede trilogy (PH)
Dabbe
Talk to me
Just any random malware I just wanna read the source code. But should be something realistic
Maybe search for malware source code
Maybe do some google dorking
To get github results
Does anyone know a safe spot to post a donation link as I am raising money for my local basketball team?
Malware should only be discussed in our advanced channels.
Please don't distribute Malware in #general
Morning
Really scary movei
the story, characters, and scares are just not good, very cliche and predictable. I liked the environment and monster designs tho
next you're gonna say the slender man movie was a masterpiece
I never seen it
Their tweets are so funny
absolutely, i like these guys
(and their merch is also cooler than thm) cough
THM attackbox works 1 hour in 24 hours for free users right?
Yes
1 hour, or 1 boot up.
Ohk
@sick lance seriously .. vx isnt an advanced topic, the argument should be rather "we dont want you to play with something that might screw your computer"
Malware is an advanced topic.
Oi
for?
Morning
Everything...
Malware is not an entry/beginner level skill.
All malware analysis should be discussed in our advanced channels, this isn't a new rule,. it's one I'm more than sure you're familiar with.
ok then, not gonna argue on this.
Wdym advanced channels π€¨
@wicked gazelle
I know, but people that can will π
πππ
So, kind of defeats the purpose of the person who's asking... π
This is the purpose of separating it tho
alright then, I'll leave it to you to cover it
There isn't anything to argue over.
For clarification, it's to ensure new people don't think this is exciting, want to jump in and either break their system .or release malware, which is illegal and the police won't take too kindly to "I don't know what I was doing".
apologies for joining mid convo
Nah, my point was it was easier to link the doc on it
The doc covers what it is, and how to access it.
Data destruction software walks into a bar...
Like and follow for part 2
I hope so
hayssssssssssssssssssssss
of course you can, why dont you check their own job offers? https://tryhackme.notion.site/Work-at-TryHackMe-6bd665d7bd3448348d04fa06f4b4ef66
TryHackMe is the fastest-growing online cyber security training platform. Our mission is to make learning and teaching cyber security easier by providing gamified security exercises and challenges. Having only been around for handful of years, we've grown to more than 3 million community members and our growth isn't slowing down! π₯·
im only beginner
π€·ββοΈ
Neither is hacking generally, tbf
π¨ Just in - users are reporting ChatGPT "testing" them with simple questions, most commonly the first word of the topic or a simple math equation. Supposedly it proceeds with any response even if it's wrong. Attached is an example image;
Learning to hack is not as dangerous as trying to learn malware.
Isn't it?
I seem to remember one of the states trying to prosecute someone for pressing F12 on a website a couple of years ago.
You can go to jail just as easily for going out of scope on a bug bounty (or attacking a website without a bounty) as you can for writing a self injector and trying to send it to someone.
Arguably lower barrier to entry that way anyway.
I'm not gonna argue with a rule I implemented 
But that rule was implemented to protect the wider community, not to restrict the people who could ask.
Besides, the THM website teaches maldev basics. You can't really argue that it's out of scope for learning...
You may have implemented the rule, but that doesn't change that Malware should be asked in the advanced channel, especially by somebody who's completely new to this.
I agree, but the reason for that is to protect other users who might come along and run stuff without thinking.
Yeah, and that's the user I'm worried about, the one asked.
I don't have faith they will know how to run it in a sandbox, and just run it blindly on their host.
There was an element of "it's one of those topics that skiddies love to ask about", for sure, and the rule does help to filter that a bit, but it wasn't the reason for it being added. Worth not conflating the two reasons π
Well in that case you haven't done them any favours π€·ββοΈ
If you're right then they're just gonna go off and learn from somewhere else
That can be said of any subject though.
Hello Everyone!
I can't conrol what people do out of here, but when in here, I'd rather malware was kept out of general.
Again, I don't disagree π
I disagree with the argument you gave them for why, and I think they're owed a better explanation
This one
No, that was more of a point of the user constantly skirting round moderation decisisons.
Not of the user asking about malware.
(they being a general "they" applying to everyone)
Then say that! lmao
I'm sure they got the hint π
"malware is an advanced topic" gives the wrong impression
Anyway, I need to get back to work before stand-up 
Can continue this later
It can do, but if I let this conversation happen in general, I need to let them all.
You know where I am 
How does one find those advanced channels?
They might see #no-access
That says no access, is there some pre-requisite?
Ah yeah , I forgot π . Thanks for correcting π
Gave +1 Rep to @sick lance (current: #1 - 3115)
Is GDAT good enough to get access to it?
I think that you need to be higher level π
How do I access these channels?
Itβs easy..ish! Either, you reach the current top level on the website, level 13 (0xD), or you are OCSP/eCCPT certified (or higher).
Isn't it like basically impossible to reach max level now
...How?
Does this higher certificate mean higher offensive security or can others qualify as well?
idk it's just what I saw reading chat, that it's significantly harder
Yeah, depends on the cert though.
It's not, you can get to 0xD on free rooms alone.
i need a cool privesc idea for my ctf
hmmmmmm
whys this rooms show "3 days of access left? Not come across this before

return the slab
You'll get rmeoved after x days to save resources.
You're free to rejoin.
Would this qualify?
https://www.giac.org/certifications/defending-advanced-threats-gdat/
ok thanks
Gave +1 Rep to @sick lance (current: #1 - 3116)
If you don't get access with that cert, then no.
I see, not advanced enough compared to OSCP π
I need your advise here as i am confused in selecting the certification between these CCD, BTL, HTB CDSA or some other. my goal here is to prepare for SOC analyst or Cybersecurity Engineer
Do you have any other qualifications? Need to know some background before can advise anything
Yes i have CEH, ECIH and ECSA
Any non-certificate background? IT job experience? studies? portfolio? projects?
granted ECSA requires 2 years of experience if I am not wrong
0xD is the easiest way imo
when you do the legacy rooms, you are quickly at 20k points.. figured that a bit late
I have 10 plus years as IT Helpdesk engineer and for past one n half year i am involved in SOC project which is managed by vendor and i am collaborating with them for any alerts or incidents
No it doesnβt require any experience
Perhaps, just the metrics seemed interesting as if its very platform orientated to even sideline those conversations
I must remember wrong then
Then you basically have a foot between the door, one thing you could do is actually consulting them directly what are they training in or what certificates do they value
Most of them has done GIAC certifications but they are out of my budget
Do you know any of the GIAC ones they have?
Right. I did a lot of rooms but they didn't have a lot of points.
Its GCFA GCFR GNFA ETC
So the 500 series
ngl I underestimated the difficulty level of Boogeyman challenges
especially the last part of the first one
killed me
XD
Certainly the cheapest.
Honestly those are hard to compete with, since they are all practical if I remember correctly, but are they asking it from their L1-s or is it more their L2/L3?
A couple people in here have 3D printers donβt they
It depends on the experience they have
certs
oh
I am currently doing GCFA, its certainly an interesting one
I am currently looking for a job cus I cant afford any of the certs
relax, esqy and matt.
but I think I am doing enough to prove that I can actually work in cybersec
the main part is applying for jobs, you gotta apply for a lot
I want to get one, I wonder what brand they would recommend
Ralex*
I see, maybe best route wouldn't be a new certificate as you already have some certificates, for Cybersecurity Engineer role, I'd spend that budget on AWS / Azure training instead, but I am sure there are smarter folk here to give advice on that note
Thanks for your advice Rennet
Gave +1 Rep to @past sparrow (current: #251 - 25)
No problem
π have u tried hackthebox job board?
arent you a mod for hackthebox
Nope not mod
okay a staff
same thing
XD
I have looked at hackthebox job board
there is nothing for me, too advanced
Guys I have a question, after IP Spoofing, will it get the previous IP address automatically by reconnecting or I have to manually change it?
It may revert back to your original.
"may"?
I can't say for certain.
I have to move my motorcycle, got a new place for it, it's like 800m from my apartment, but it's raining
when you use a tool which modifies packets, it doesnt impact your own adress.
No I mean if i change my ip address with ifconfig tool, like ifconfig eth0 1.1.1.1, will it set back to the original one automatically by reconnecting or I have to change it manually?
when you change your configuration, you gotta set it back manually
Either that or then you get one from your DHCP server
Won't it revert back on system reboot?
Bambu Labs x1 carbon. Although bambu labs is releasing another printer soon. IMHO by far the best brand. Only complaint is bad warranty systemsn
Did you change your default gateway?
nah, I did nothing else but just change the ip address of the eth0 interface with ifconfig tool.
it won't, as you change the ip to be a manual ip before closing
nope.
yeah, reboot won't give you a new one, but if you have it be assigned automatically and there is connection via DHCP server, then you get it back automatically
I assume its your home network, so read DHCP server as router
if your lease period is not up and that you change back to using DHCP and not static assigned ip
but ig its not same as mac address, changes would go away after system reboot..?

best way is to copy/take a picture of your original settings
before making changes
But if you don't take a picture, you will learn a valuable lesson
thats contingent on how you change the mac address and which system.. there are temp and permanent ways
Thanks
Gave +1 Rep to @real patrol (current: #2502 - 1)
consider it "introduction to networking"
with macchanger it can be set permanent, with ifconfig its temp
nah I am not spoofing mac and IP before I understand the whole picture, still gotta learn networking and other linux stuff, lets memorize the commands for now π π
time to wait for it to stop raining
and thats not spoofing btw, thats just changing settings ^^
yeah, is there a specific problem you need help with or is it rather a general question? Little context would help
probably wifi hacking ... i mean, pentesting π all legal of course
Oeh, I should get back to CTF-ing
i wonder why no one asked yet whether he bought the router or rented it from provider π€ anyways, other things to do
If I just change my ip/mac, would they revert auto in a normal system reboot?
They aren't showing signs they're trying to hack it?
Rather how to spoof an IP.
things getting darker, I just wanted to know if these changes revert auto or no but someone saying I am trying to hack wifi i mean pentest it π π
It depends. If you configure it statically then no
If you have a concern about the behaviour of a community member, you can raise with a mod, or admin.
Instead of making a back handed comment. π
MAC should change back automatically unless you are configuring the firmware settings
Nah, Lemmi tell the WHOLE scenario here.
I typed ifconfig. I seee I have 3 interfaces, eth0, lo, wlan0.
Then I typed ifconfig eth0 1.1.1.1
It didn't return any error, and running ifconfig shows it has changed.
Now will it automatically revert back to the original one after system reboot? If it does then excellent, but if it doesn't then thats the problem.
Try it and see π
ah, that is not static configuration
so reboot should fix it
finally... a worthy answer. Thanks.
Nah, Lemmi tell the WHOLE scenario here.
I typed ifconfig. I seee I have 3 interfaces, eth0, lo, wlan0.
Then I typed ifconfig eth0 1.1.1.1
It didn't return any error, and running ifconfig shows it has changed.
Now will it automatically revert back to the original one after system reboot? If it does then excellent, but if it doesn't then thats the problem.
You could have done all these steps yourself and seen what it done. π
Hi everyone,
I have some questions regarding the advent of cyber event. Will the winners be chosen at random or the ones with the most points?
Also, for the prizes, will it be chosen randomly for us or we can choose? And can we choose more than 1 item, if so what's the maximum?
random for both
you get put in a roller with the amount of points that you have as weight, and from there you'll get picked for a random gift
Oh ok, I see, thank you
essentially like this proof of concept
Winner will be chosen at random based on the raffle ticket you got
Gaining a t-shirt would be so cool., i.would wear it at my ctf challenge in my city π
I have too much merch to choose from when I go CTF'ing lmao
Making pins from badge from the profile
I have 0 merch yet to choose haha
events merch is amazing, but eventually you get tired of wearing them
Only a pair on neutral black tshirt +.jeans
I have merch from my 2 CTF teams, and then multiple CTF's I think 5-6 different CTFs and then THM
@sick lance
love how fast that happened
@late summit Please don't advertise in this server. π
I have stuff from BSides and Locked Shields, don't think I have any platform specific merch yet
Hello
Does anyone know if it's possible to resize toolbar in a virtual machine in virtualbox? I swear I did it on my other laptop but struggling to find it on this one
Probably view settings or scale factor.
???? I dont advertise
You're new to this server.
I'm a mod, and I can see the message you deleted.
And scale factor didn't seem to do much
ahh I send wrong message from orther group
You can't hide from mods 
Scrubz is Elliot from Mr Robot btw
What realy ?
wasn't he a schizo?
I dont understand that one
like actually?
multiple personality disorder
No, not actually
where you dissociate away from reality and your other personality takes over, making you forget that period where you're not there, and/or see it from a 3rd person view
basically like fight club
I really wanted to play along with that but that wouldnt be mature
should have
Oh yeah that's different. Sounds horrible.
what room should i start with
Skizophrenia is a large theme of personality disorder / halucinations disorder
Many things can be a kind of skizo
Tutorial
It definitely has differences to MPD
already done it and i also have a degree in cyber security so dont want to start too ez
Find a path you're interested in then?
make your own room
many systems (people with DiD) have 4 different personalities, usually the system gets made due to abuse and/or other bad experiences in their younger life, due to the body/mind trying to protect you
It depend on the brain part damaged , some schizophrene diagnosis get many probleme in memory parts , some in emotions .
will probably find a path like shadow said then try to make my own room
poeple with schizophrenia* please, they are still people
Yeah the things that like to play tricks on you are the very things that try fight it off lol
I don't talk about people but about the type of illness
eh, if you already have a degree then most of those things should already be familiar to you
yea so ill look at rooms i didn't really touch or need to brush up on.
The are learning path already made
then please make sure you say that, such as "the schizophrenic diagnosis can be about many different things, such as.." to be more neutral in your wording and not to offend people with diagnosis, cause it takes a lot to even get diagnosed π
With modules/ rooms
If you're saying "some skyzo" that's referring to people
I am on phones can't type that much π΅βπ«
He didnt say offensive stuff?
it can be seen that way over text, just making sure that it doesn't turn into something bad π
It's hard to say over message and people can take it a lot of different ways
Particularly in a public channel
True and there is many differents main languages spoken , so traduction may lead to mis understanding
Only English in this channel
I spoke once on telegrame with people from Jordania , which speak Arabe ,
These is the auto-traduction
And they are many time weird stuff happening ...
Idek if I could say slang words from my country lol no one would understand them if they aren't from here
It was a conversation on a mobile war strategi game
The Jordanian Said ^Don't kill the children ^
And we were WTF
And we understood they mean the noob/ newplayers
π₯Ί
If dolphin_keys(sorry if I butchered the name) was here, could maybe translate
@sinful moon trying to figure out how to operate network settings on virt-manager
Wait is dolphin still here? From NZ?
Yeah. but she hasn't been around lately.
About the only kiwi I know here, aside from myself
aquinas_nz wonder where they are from
Nz 
a kiwi room tester, nice
probably the last sprints of Q4 that needs to be programmed
hey i want to become a pentester and im starting from sractch so basically everybody tells me to buy course hope anybody could guide?

not course
You can start here π
Cyber security is often thought to be a magical process that can only be done by the elite, and TryHackMe is here to show you that's not the case. Anyone, with any experience level, can learn cyber security and this Pre-Security learning path is the place to start.
is it free
Majority is π
Good luck on your journey π
Hey guys, just need some recommendations.
Does anyone know where we can get coupons for different certifications?
I've already got 2+ years of experience as a SOC analyst and Engineer but the prices of certifications has sky rocketed tbh π
does the highscores points take a little while to update or are they different to the points you get from solving rooms :S ?
Idk about coupons but some cheaper/worth it ones are BSCP ($99) and the htb certs ($200) ish
same as your "the user constantly skirting...". now that we exchanged our points, we can get back to the usual business π everything else rather belongs in dm, in case you feel for that there is something that needs further discussing. my dms are always open 
I booted kali linux in a separate hard disk and when I booted a problem arrived that the resolution and the refresh has to be changed but when I checked it is correct only
Dualboot?
Moderation action won't be dealt with in DM's for the clarity of other users. π
Bscp requires premium burp
Unless he already has it which I doubt it isn't really a deal
Guys I'm completing rooms but my leaderboard score isn't increasing :S ? does it take time or
Some rooms don't give points.
like don't give points to the leaderboard?
at the end of each room I've solving it says points recieved xyz
For ranking up yeah.
Oh I see damn
Hmm I'm specifically trying to climb the leaderboard atm, is there a way to know what rooms I should be solving?
Newer CTF rooms.
Does difficulty matter
Not really. π
π
I think I actually feel physically bad when I'm lazy and haven't done anything important all day
gotta take a day off once in a while but I still feel bad about it
actually these days are also necessary, i took yesterday and today off, just doing some small things here and there
Not as dual boot but like linux in 1 hard disk and windows in another hard disk totally 2 disks
Is tryhackme a good resource to learn about computer networking and linux?
Yes it is to some extent π
Would a resource specific to computer networking and linux be better?
Bcz Tryhackme seems to be the #1
You can start with this pathway π . It will teach you fundamentals of linux and networking π
Are you new to cyber security and not sure where to start? This pathway will help you acquire the core skills required to start your cyber security journey.
Cool, thx π
Hello, i have a problem in the Caldera module, when i execute this command, i have this error and i don't know why. Someone can help me please ?
command: ython3 server.py ../caldera_venv/bin/activate
error: ModuleNotFoundError: No module named 'aiohttp_apispec'
Is there a way to like ctrl+a and paste everything new in nano lol
Try with Ctrl+V
Or Ctrl+Shift+V
I booted kali linux in a separate hard disk and when I booted a problem arrived that the resolution and the refresh has to be changed but when I checked it is correct only.
Not as dual boot but like linux in 1 hard disk and windows in another hard disk totally 2 disks
Give me a solution
<\Hello World>
sudo apt update
sudo apt upgrade
sudo apt install --reinstall xserver-xorg-video-intel
xrandr --output <output_name> --mode <resolution> --rate <refresh_rate>```
OR kali-hidpi-mode
alt+f<number> to command line
What number
1
there are only 12, didnt remember anymore which ^^
Hi
in john the ripper - the basics room it tells us to use raw for some hashes and some we dont. when it tells us we can check what ones we use -raw for how does that work. because i typed in the syntax and it just shows all the formats so im kinda confused as to how that tells us. of course we can just try it with and without but i just want to know how the syntax 'john --list=formats' tells us what to use -raw for and not to. thank u and sorry if its a dumb question lol
What will it do after giving the mumber
Why are you installing Kali to your machine?
you are in cmd line and can fix the stuff
For practicing
No worries, it's a great question! When you use the john --list=formats command, it lists all the supported hash formats that John the Ripper can recognize. Each format is listed with a specific identifier (like md5, sha1, etc.).
To determine which formats require the -raw option, you need to refer to the documentation or cheat sheets available for John the fkin Ripper. These resources typically indicate which formats need to be specified with -raw and which do not...
Kali is designed to be portable or used in a VM. It should not be installed to physical hardware.
Nice ChatGPT response
Do you know what model copilot is based on?
thank u im gonna add that to my noted
Gave +1 Rep to @heavy gorge (current: #2503 - 1)
Gpt4o
Has this been publicly released?
Nah
Welcome
Rooms must go through QA process before being released publicly. Hence you should not share it here.
I have made it today and if there're any mistakes or issues kindly inform me
Oh sorry
Pakistani
Good .


hi
Hi , welcome π
I cant get to the ctf's website for some reason
it just buffers
I can scan with nmap and it says its open
π
We love spam
@mossy river @sick lance
Hey religious discussions are not allowed here as per the rules
Who is the father? Why is God sitting on the father's hand?
Has anyone else not gotten the badge after completing the AOC?
The AOC isnβt over
Well that explains it. I just did not see a challenge this AM so I guessed. TY @opaque flax !
Gave +1 Rep to @opaque flax (current: #291 - 20)
Itβs not time for a new challenge yet
2 hours.
π
Yup
Ok
yea... no funny things for a cats
Guys.. whats ur attackBox specs?? For free user vs premium user..
attack box is same for all. aside premium users get some more vpn speed and unlimited time on kali/attack box
morning
When they said,, premium user can access faster machine.. what does it mean?
Sad π’
well.. from business perspective. is fair if you pay for smth. thm does need to pay servers, employ and so
Yes, faster machines.
my back hurts
I have been trying to push my motorcycle out of my basement for hours today
I AM IN THIS PIC AND I DON'T LIKE IT
quite literally sitting like that right now
well... i did take that pic of you π
but no, trying to push a 200kg motorcycle up a ramp is back killing
yea. you do use full lenght of spine and all body. so it can be hurtfull on some parts
yeahhh, it's not out yet, but maybe my friend can help tomorrow
1000cc?? π
oh dear... still on same place ?
no, it's out of the cramped space now, and standing together with all the bicycles
650cc
Ninja or aprila?
Suzuki
I like this cat
I steal
PING
narhhh, I am in the middle of rebuilding my suzuki sv650s from 1999

Morning? Are you π¦ π« American πΊπΈπ₯ or something
wtf is a kilometer!
Wooow love that
Atleast I'm not a brit https://www.thepoke.com/2021/09/21/how-to-measure-like-a-brit-went-viral-and-it-absolutely-nails-it/
Youβll no doubt have seen the news that Boris Johnson is making imperial measures official again, giving everyone two ways to measure exactly how much stuff we donβt have anymore post-Brexit. We only mention this again because this rather marvellous βHow to measure like a Britβ went viral on Reddit and it totally nails it. [β¦]
it happens
Wrong. They measure in Maple Syrup Per Hour.
β Hit that like button and post a comment down bellow if you're Canadian π―
π¦
anyone know smth about this error kernel: nvidia-modeset: WARNING: GPU:0: Correcting number of heads for current head configuration (0x00)
You have more than 1 head? woah
i call to 5th on that
https://bbs.archlinux.org/viewtopic.php?id=294113
https://forums.developer.nvidia.com/t/ryzen-5500u-and-runtime-d3-issue/287383
Second link has a comment: "Youβre running the nvidia-open driver, another user found out thereβs an issue with the nvidia firmware and runtime-pm. Please switch to the closed driver and make sure the gsp firmware is disabled."
Please don't share Xenophobic jokes in this server.
It could make some members feel uncomfortable.
https://forums.developer.nvidia.com/t/ryzen-5500u-and-runtime-d3-issue/287383/18 .. how about that? should be independent from card what i read there
Well, you hit again. I have a widget for KDE Plasma named Thermal Monitor. I removed sensor watching for GPU and finally achieved this: cat /sys/bus/pci/devices/0000:01:00.0/power/runtime_suspended_time 38510 ~ ξ° cat /sys/bus/pci/devices/0000:01:00.0/power/runtime_suspended_time 40361 ~ ξ° cat /sys/bus/pci/devices/0000:01:00.0/power/runtim...
LMFAO
Woohoo 0x8 get

gunna finish jr pen today
is not that in this case
What about the nvidia-open driver?
stfu lol
fight me 
RAHHH FREEDOM RUN
π¦
WTF IS A KILOMETER
I approveπ¦ π¦ π¦ πΊπ²πΊπ²πΊπ²
uh
so hows it going
hi guys
hi hi
Heyo.
π π₯³
Advent of Cyber 2024 DAY 17 Let's Go!
π₯³ π
Anyone who was about when I was talking about giving my neighbour gifts for Christmas, I did and Iβve since been ignored lmao so
Guess whoβs not getting anymore gifts off of me ?
π€£
neighbors will not get it? just wild guess
I even heard her daughter say to her mum βThatβs what you wantedβ when I walked in with them so
Iβve just been bamboozled
I need to find a new penguin
i need to get some for mine neighor. they are great ppl to make you laugh
Yeah well I thought she was nice
I donβt have a great judgement of character apparently π
Wait you have a 3D printer right ?
my ones are older couple from germany. they have some special cat named Adolf what is not so popular name in netherland. and when mr.adolf escape and lady calling her with name. i laugh π
2x
I want to get one but I was unsure which to buy, I did a little research earlier and read about two different brands egeloo
And formlabs. Which one do you think is best ?
ugh target machine and attackbox keeps terminating itself, 3rd time its happened in the last 40 mins.
so. i have K1C. that is bit new serries. it is enclosed system that is needed for some special filaments printing. same printer just with no enclosed system is great
https://store.creality.com/eu/products/k1-se-3d-printer
K serries are fast ones. up to 500-600 mms.
Creality 4lyfe
Small nerdy stuff like I wanted jinxβs necklace and I wanted a couple of her hand nades
π
You Nerdy? Whaaat? Naaah :p
thats great. cos build plate is 20x20 cm. and this is mine print on top speed. it starts around 1 min to go fast. check whole vid
https://youtu.be/m6hSDt8hALQ
600mms creality Hyper-PLA 600mms speed test
I'm still having to tweak it for the wood filament. Its still going bobbly at sections
that is vase mode. so just one wall all the way. hence the speed
And what kind of filaments can it take? I read something earlier about resin
it is a bit. but not so much when is closed. for open ones they are bit yea
resin si smth else
Resin is a different thing
You can also buy special machines for carbon fiber
we use spool of filaments. best and most used is PLA
But yeah.. The standard is.. Dammit ralex
this one can yea
comes down to the nozzle and the temperatures. the k1s can go pretty hot, and have a range of nozzles
β€οΈ
Are the filaments you use more so for plastic ?
Pretty much, yeah
You into Warhammer by any chance?
The wood one I mentioned is plastic but with wood in it.
Also those are massive, how many pieces did you print for them? xD
resin is smth else. this ones are FDM type. PLA and PETG are most common
nah. not on it
hot sure tbh. but i jsut print atlantuis. and is maaaasive. over 60 cm
But yeah, the different filimnents have different properties. some are better for outdoor things, some are are more flexible.. etc
Fair. I'm not either, but I was wondering because I heard that printing and painting your own models is like 60% of the fun for the community.
Yea, I saw the pictures.
bought an ethical hacking bootcamp course on sale
orginally $100+, only $30 right now
I think Ralex or Beerise made some glow in the dark stuff π
Good deal, I suppose.
Resin would be higher quality right
Nice, Faulty. where was that from?
Udemy
Yeah, but resin is smelly, and the actual liquid is more expensive
I used to make a lot of resin cabochons eg
I used to make jewellery
the mid part is glow in dark
Thatβs cool
The resin I used to get was like glass




