#general
1 messages ยท Page 636 of 1
๐ก
Get out
that is a movie
good afternoon
๐ฟ๏ธ
Greetings
is there any hope for winning anything on advent of cyber this time
there is hope of 1%
I did the statistical analysis on this a while ago.
Even the worst possible odds are like 1.5%
the real prize is the learning along the way
The learning has actually unironically been really great, they've definitely hit more than they missed with the rooms
last year's game AoC was buffer overflow, i enjoyed that
it was cool to understand what that means
I told my self I will do AoC. Havenโt even done one ๐
Today is a great time to start ๐
some days are super simpl while others take time
The only overflow I knew about before this was integer overflow, which is also amusing
Nah I tried. Itโs not my style, I donโt like how the information is spoon fed to you. Itโs not a challenge which I like
side quest
You don't have to read the guide
I don't disagree that some of the rooms are legit, like, railroaded for you
But some of them are pretty open pasture too
what is albert_c137 typing?
I'm really curious too
like a book?

maybe a letter left in the text space
I'm a fae creature Albert I'm not allowed to look away until you're done
just hit enter already albert
Show us the WIP
edit after
Hi guys. So a friend of mine from China told me that he can use proxy to access THM but always fail to use openvpn to connect the VM in THM. Iโm guessing maybe itโs because the great firewall (operated by the Chinese government) block the ip or something. Iโm just learning hacking so Iโm not sure. What can he do?
finally!
Is there any way to generate a pdf transcript for tryhackme?
Oh, that's not what I was expecting
that took so long to type a paragraph
Uh, anyways, yeah, there's nothing we can do when a country prohibits the usage of non-sanctioned VPNs
were you using google translate?
Or at least nothing we can recommend for you here.
#site-support is my guess where you want to ask
maybe @silver sky is around to help
Nah I write myself.
ok , just curious , no issue either way
Ok thank you so much.
Gave +1 Rep to @grizzled wing (current: #81 - 94)
Nothing. We cannot provide support bypassing content or VPN restrictions as this would be unethical and illegal (as per your friends countries rules)
Well ok then. Thanks anyway โบ๏ธ
yall be using burp suit, caido or owasp zap?
burp suite i like
I prefer Burp ๐
Burp is fine.
Burping is burpin n slurpin
I'm still internally a child so the name makes me laugh but it's genuinely preferable amongst the options
one day i will use caido
im trying to find new tools to break out of the ordinary and shi, any particular yall recommend? Been using rustscan for a while instead of pure nmap now
so many hacking tools have weird funny names
Using "ordinary shi" isn't always a bad thing
ik, I will keep using the same things, just want to broad my horizons
Finding new tools is always good, but using them just because they're not ordinary is rather silly
I have a legitimately difficult time talking to my father about what I'm learning cause half the terms are borderline incomprehensible garbage or silly nonsense
try caido, if you like rustscan then caido is written in rust
yes, whenever you talk to regular people and have to define all of these terms and worse makes us sound crazy. " i was using ffuf"
Even the more innocuous stuff
Yeah so I wrote a script in ducky and used it for parsing with my pineapple
I only have a few bits and bobs that I've been experimenting with
Been luckily avoiding the more expensive/questionable articles
Listen my first tool I wrote was originally called RouterFuck.
We are all childish at heart
There were no arguments it just displayed a screen saying searching for routers to fuck.
Hahahaha
Reminds me of this clip from the blacklist: https://www.youtube.com/watch?v=MQKoBNv-pNM&pp=ygUyaSB0aGluayBpdHMgY2hpbGRpc2ggYW5kIGNvbXBsZXRlbHkgdW5wcm9mZXNzaW9uYWw%3D
Three people, three ballons.
Also I don't know how to edit videos, those stupid marks are on my video
Hey I was using Burp Suite to test this website for SQL Injection
that is one long url
blame yt
Reminds me of something called MILFMap from forever ago, basically the same silliness
Daniel
know of any immature named hacking tools?
immature?... hmm... what do you mean? lol
oh
haha
hmm
let me think
fuzz faster you fool?
(ffuf)?
i mean, i like the name, but yeah
ha
Aha, it appears
fartercap
oh, ffuf? ha
that real? lol
no idea
Hello EVERYONE
hello
posh spice is here
whats posh spice..
You can manually copy url or just remove everything after second = (? on other sites)
haha
guys im FRESHLY new to this
Ok
so fresh?
really really fresh
welcome
kindly confirm that you are fresh
just started aboutttt an hour ago
nice
respect
Hello Fresh
I'm surprised I didn't throw up after yesterday's huge burger, that thing was taller than my phone
next step is to learn l33tc0d3
Nah brainfuck
not what i meant but hello.
I'm so happy at least one person got the joke
no Santa, the new posh spice
im just barely on "what is networking?" someone end it
i got it
I didn't realise we needed a new one
your computer says SYN then server say ACK
my brain must be slow tonight
Did not know that, thansk
SYN-ACK
i wrote a python link stripper that cleans the url from youtube
ACK
FIN
im going through and answering all the questions at the moment
ACK/2A
PACKETS LOST = 4
all of the SYN / ACK will become fun soon
+_+
Hi all, I'm trying to proxy traffic through my VM to my main computer. I got some help on how to use ssh -D 8089 user@ip . I have the VM connected to THM vpn. I set up burpsuite in foxyproxy but for some reason when I enable the SOCKS proxy in burpsuite I can't get to any websites anymore, I just get connection refused. Is anyone else doing this by chance?
honestly i tried to dive into THM a while ago but it seemed boring
all of a sudden i gained interest
yeah, it's because if you're proxying through burp, and burp has socks enabled, those websites are not found in the socks tunnel you have setup
One becometh possessed by an unnatural muse from time to time.
turn off burp proxy or use another window to browse the web
Swiper no swiping
this is what speaking smart looks like
Looks like?
So how can I access the sites that only the VM has access to from my normal web browser? Or is that not possible. I thought that's what I was enabling.
iykwim
openvpn
What are these hieroglyphics or modern are, supposed to decipher each word out of this
THM seemed boring until I was staring at a terminal screaming about how my listener isn't listening
when you get your first rev shell, โค๏ธ
That more than likely won't be possible.
Ideally you'd want to keep your host away from the thm network as much as possible
sorry man i cant help it
that's a very interesting question. i've never thought about that setup... hmm...
Scrubz jumpscare
No, I get that part. I don't want to use the browser in the VM though.
ah. i agree with scrubz
Hmm, maybe I misunderstood what someone told me the other day then
What did they tell you?
you want to stay inside your VM and stay safe using it
@pulsar jacinth so if you have host_computer > foxyproxy > ssh socks tunnel > vm_host... hmmm... how to get from vm_host to websites... it depends on the websites. if you're just targeting the thm boxes over the VPN, then you could setup a local forward from the vm_host to the thm_target. then, access the local forward through the socks tunnel maybe.
Help us, to help you.
I thought I could forward traffic from the VM to my actual computer
Why would you want to do that?..
More immersive
To be honest, all the hoops you'd need to jump though, you may just want to use the vm
It's too much effort just to use a browser.
@pulsar jacinth also, check your dns. depending on what you're trying to do, if your host os processes the dns before it gets to the vm, the connection might just try to go straight to the internet and bypass the socks tunnel
@pulsar jacinth try setting the thm target ip in your vm /etc/hosts file, then try to access the thm target by the dns name in your host os browser assuming 80 or 443 is open. curious what happens.
anyway, yeah. that's a pretty complex setup. have fun lol
one more thing. foxyproxy allows you toggle whether you want to proxy dns through as well. so if you ensure that's ticked, then you know your dns is hitting the vm host.
all good. what you're trying to do is very complicated
even for me, and i'm pretty advanced
what's your ultimate goal?
and why?
oh shit
I am not smoochii
Gaww has knowledge
in a busy chat
@jolly peak have you set up a place to write your notes?
mm no
You CAN'T handle the raw power of gaww, you will go insane, you will hurt people
havent set anything up as of now
highly recommend you take notes right away
youre right i just started my brain would fry instantly
I basically just want to be able to access the machines on THM VPN from my normal web browser but through my VM which is connected via VPN
will do
I can SSH into my box just fine and reach the machines
I've always been a little curious to trade minds with someone
But I'm confident I'd go crazy. Or drive the person who traded with me crazy. My mind is a labyrinth to madness and a temple to lunacy.
gotcha.... yeah. that's gonna take some work. it it just like a UI thing? like you like the ease of your native os browser? i know that VMs kinda suck, but man... that is some hoops you're jumping through for sure
veggies out here still giving green bell peppers to people. ๐ moo 
that was fun in philosophy class to think about your identity outside of your body etc
lets get the process started !
Ya, pretty much. I just hate using the browser remotely. If I get it figured out, I'll let you know lol
"labyrinth to madness and a temple to lunacy" i'm stealing that lol
I'm a firm believer that if anyone underwent a sudden shift in perceived experience and mindset there'd be irreparable damage. It'd be like stepping into an alien world.
serentity now! madness later
hahaha, omg, i saw a funny seinfeld clip recently that cracked me up. i never saw that episode, but my friend showed me clips lol
that show lives on , always funny
ok, i'm convinved my roommate has taken out all the pots and pans, is clapping them together and just shuffling them around to drive me insane lol
haha
omg
i'm simultaneously developing an ulcer and a headache haha
lol, this is literally madness.... lol
You may take of my whims as you willโ
Madness?
roomates is a ๐งต
LOL
haha
if sparta was more passive aggressive and tyrannical, then yes. you are correct LOL
indeed. dude is jacked in that movie ha
Sparta was hilariously passive aggressive historically
The "if" callout response is proof of that
everyone had six pack abs
i think i vaguely remember what you're talking about
but yeah. i wish my roommate would just tell me to my face, "i hate you and want you to suffer. please be miserable" rather than actually just make me feel miserable by constantly demanding attention lol
TLDR a city state said that "if they were to wage war" on Sparta it'd be ruinous
ahhh haha
Sparta responded by sending a letter that was only inscribed with "if"
@winged summit I got it to work ๐
nice. how?
I don't know if it's safe but it works rofl
So I did ssh -D 8089 user@myattackbox This opens a SOCKS proxy on 8089. I then set up foxyproxy to proxy on 127.0.0.1 for burpsuite. Then in burpsuite I set up the SOCKS proxy under network connections to be my attackbox with port 8089. Now I can access both regular websites and 10.10.10.10 and I get traffic from both in burpsuite.
lol, i thought you already did that?
ohhh, maybe the socks in burp wasn't setup?
i mean, you said it was, but in any case
it's working, that's awesome ha
Well that was the goal but it wasn't working. Now it is
gotcha gotcha

nice! ๐ good job
ohhhh. let me guess. previously, the burp socks proxy ip was 127.0.0.1? haha
err wait
that has to be because ssd -D
ssh -D
arg
nvm
Ah it was because I had the SOCKS proxy set to my attack box IP but it has to be 127.0.0.1:8089
Ya, that
so the exact opposite! haha nice. that actually makes total sense
haha
we shared the same erroneous thought lol
(at some point)
You actually understand what's going on though, I still don't haha
host os browser > foxyproxy (with dns tunneled) > local socks proxy setup via ssh -D > gets tunneled to VM host, where it has access to whatever network resources can be reached by that host > dns/route specifies vpn network for thm target > accesses thm target... travels back through same path with responses.
that's the tldr. but yeah. there's a lot happening there lol
Lots of condensed Neat
So the real question, is this safe? Can people on the VPN access my actual computer?
they can probably reach you, but i imagine it'd be a pain, and thm generally protects against that sort of thing. but there are no guarantees
There seems to be a couple layers of access that'd need to be enumerated there.
To the point of being extremely inconvenient.
exactly
I mean, if you're paranoid about your host, why open. Socks tunnel?
i presume they'd have to pop the vm to get access to the ssh socks tunnel
but if they compromise the web target then that's piped directly into your host os
@pulsar jacinth if you're doing thm on your regular host os btw, make sure you backup all your data. the likelihood of something bad happening is low, but the impact is potentially high. always good to backup data if you're homelabbing on your host... malware analysis, etc.
That's a risk that'll always be there with trying to pipe directly to your host though, no? You're ultimately still giving a straight path with a few extra roadblocks in the way.
yeah. i mean, if you're in a vm just on the vpn, then they'll just pop your vm
like browser in vm versus browser in host os
My wife is yelling at me to sleep but I'll read all of this in the morning. Thanks all!
Of course, the VM just gives you the benefit of waay more warning if you're paying attention
Have a good night
yeah, and if you accidentally run some malware as part of a room, it should just wipe the vm etc. versus contaminating or deleting data on your host os.... unless you have shared folders setup to access your host os through the vm, etc.
fortunately there's no ransomware worm analysis as far as i know, haha. talk about total nightmare scenario lol
If you're doing malware analysis on THM, it's best to leave the malware on the dedicated VM.
Not transfer it to your own environment.
Oh one more question if my vm is on proxmox with the rest of my home lab, is any of that at risk? I donโt think this has to do anything with the socks stuff, just generally curious.
not too familiar with proxmox, sorry. but i hear it's really cool and i do want to try it someday, haha. from what i understand it's a baremetal hypervisor. they probably handle security pretty well. i'd be more worried about any access you grant the specific vm in proxmox
This is why I've heard flash/disk boot and ram processing is a safe bet if you're doing frequent analysis, since there's no permanent data that can get dusted.
interesting... i haven't thought of that angle. very cool.
Brother, what OS you use for malware analysis?
i don't think he's doing malware stuff, i just mentioned it in passing to talk about security scenarios. from what i recall he was just doing web challenges on thm
RAM forgets all information on shutdown, and a USB boot with a tails setup has the same hallmark. If you don't have a permanent hard-drive there's no (or very minimal) danger. I know some data forensic guys that do things that way and it's always seemed very interesting.
nice. for sure. i knew that about ram, but you got me thinking about how if something is not overwritten in memory, that it could potentially be triggered again by something before a reboot
i remember tails too! haha. i used that back in the day as an experiment. back when they had a CD ๐
Well in their environment it's usually part of malware analysis so they have a bit of a sacrificial lamb drive most of the time
Maybe if it could be triggered directly from BIOS?..
hmm... yeah. not sure. i mean. i was thinking more just by software in the host os. but even then, windows has protections against accessing memory out of bounds, so probably not a scenario worth much consideration
It'd be niche for sure, but fun (and spooky) to think about. Sky's the limit
exactly haha
Malware analysis discussions are kept for out advanced channels.

but now that you mentioned BIOS, that's my tin-foil hat jam right there, haha. persistent firmware rootkits lol.... that's the cool stuff.... but so niche that i know nothing about it. i remember at one point when i learned about the IntelME, i also learned about how previous versions contained a cellular modem, and i was like, "oh, interesting, it could just communicate via LTE and bypass the OS" lol
Oh ok
bought a rtl-sdr kit to measure stuff, but didn't think it all the way through. a cell modem needs a SIM card. in addition, a beacon probably wouldn't be sent out for something that advanced unless i was actually a target lol
Yeah my bad
Well there used to be old worms that could do stuff like that. Some older drives used to keep separate memory for boot that could be taken advantage of, but I don't think that's been a problem for a long time
nice. that's wild. i mean, not nice, but cool. very interesting
ha
anyway, i gotta get back to portswigger. 20 more challenges to go before i sleep... we'll see lol
it was nice chatting @mellow gull ๐
i'll let you get back to your MILFfinder tool
lol
Have a good one, see you when I see you
i wonder what alex is typing for so long
Guys, I can't do multiple things at a time such as learning. As being in cyber you need to have vast knowledge about web, programming, malwares, forensics and other security measures to combat against attacks. The problem is that suppose I have 8 hours for studying I'd divide them among the topics I wanna learn for exp: web and programming. However, I'd like to study only one topic deeply first then move to another one but then I think I'd lack in other things. So, any idea what to do?
Do you know what path, if any, you want to pursue in the cyber security world?
The one we can't talk here ๐ฅฒ
Malware
Forensics as well
I mean they relate ig
Well, what I can suggest is that if you can only focus on a single subject at a time, then it might be best for you to focus on a single tool at a time, and then expand your repertoire once you've mastered it.
Like people in SOC will learn the ins and outs of SIEM tools like Azure or ELK.
Maybe something like EnCase or TSK or Ghidra
I'm about to go sideways so I should probably just say goodnight THM. Moo.. moo moo moo..
Rest well
hello everyone
Is there any specific path for the Bug Bounty?
I've done cyber security 101 path.
I'd go jr pentest path next the web app penetration I think it's called
Hello
Hello. ^_^
Hello
Hi, Is Veracrypt still good for external hard drive encryption? Which software do you guys prefer.
Verycrypt's still good as far as I know.
heard they stop the support. Which is the best one among all?
If you're on Windows, you could also use TrueCrypt.
i use both windows and mac
IDK.
Worst case you just generate a sufficiently long AES key and encrypt the data manually, lel.
yeah
Their last release was September 2nd, 2024.
which one for vera? or true?
For Veracrypt.
ok cool/ so that means someone is still updating it. thanks man. \
did you had a look on github?
Nope. https[://]veracrypt.eu/en/Release Notes.html
But you can check the github here as well: https[://]github.com/veracrypt/VeraCrypt
Last commit was 3 weeks ago.
They both do their job.
bitlocker is also good but it works with only windows will have issues with using the drive on mac
yeah true
But I'd prefer VeraCrypt, because open source.
yeah.
Not 100% sure about TrueCrypt in this case.
Well, it is officially a "source-available freeware", which means people can at least read the source code publicly.
any channels here to correct an instruction?
You cannot do that. AES keys are of arbitrary length - 128, 192 or 256 bit.
Wdym by that ๐ ?
nvm i pasted the wrong instruction at #room-bugs
AES-CBC?
Or do you mean the "sufficiently long" part because the keys are fixed sizes?
Yes
I did mean the passphrase you use to generate the key, that was poorly formulated by me. ^_^
But yea, in that case you are correct.
Itโs not a good idea to use a key derived from the passphrase directly for encryption. Itโs better to use it to wrap/unwrap a randomly generated key that will be used for the actual data encryption.
There are multiple reasons for that, but for starters, key wrapping approach allows to change the passphrase without re-encrypting all the data.
usually not at 2 am, sorry
I don't have unban perms.
That's Jabba/admin only.
you have the Key Encryption Key which encrypts the Data Encryption Key. Naturally, you vault these in different places
morning @sick lance
๐
of course this all depends on the confidentiality of the data you wish to encrypt. Sometimes a proper KDF is sufficient
there should be an OWASP Cheat Sheet on the subject
https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html and https://cheatsheetseries.owasp.org/cheatsheets/Key_Management_Cheat_Sheet.html
Website with the collection of all the cheat sheets of the project.
Website with the collection of all the cheat sheets of the project.
CBC is technically vulnerable to attack, prefer GCM
or CCM
these are authenticated modes which help guarantee the integrity of the data
passphrases should follow the standard reccomendations, aka use a password manager ๐
war flashbacks to every crypto CTF challenges
hallo
Idk what to eat for lunch, there's so many options and like none of them stand out
What are the options?
half the food on the planet
Anyone able to hack coinstat account
How do I utilise the $10 voucher of swag shop ?
You add the code at checkout
where is the code thats what i wanted to ask
Okay, thanks
Gave +1 Rep to @azure hill (current: #854 - 5)
where is the code
It should arrtive on your email ๐
Sorry havent received any, i checked all mails from TryHackme, is it possible to to sedn it again,
Try to reach out to support ๐
ok
This is illegal, and against our community rules, please stop asking.
Ok my bad
Hello
I am a new members of Your try hack me
So i need YOUR halp
Wassup
Yeah fine
what specifically do you need help with?
Yeah sure
also looking for some help
How can we help
I spent almost 4 hours just enumerating the thing, and found all the usernames I need and something else
to get me into
if i need any assistance ill come right over, when i get that far, just in the first steps of offensive learning
do I need to connect to the thm vpn to interact with challenge machines and AoC domains?
Current day AOC VM is frustratingly slow when I open vscode
Often, yes
Some may be in-browser access, or a thmlabs url that lets you access it over the internet
ok so iirc the thm vpn is over udp
is there a way to connect over tcp?
No
If the VPN is blocked or illegal in your country, we cannot help you circumvent that block. That'd be illegal, and we have a zero tolerance policy on illegal activity here.
You can use the attackbox but that's likely the only way around.
Deep Packet Inspection
Iirc BlueCoat, a network firewall/appliance vendor, got caught selling to embargo'd governments
do they perhaps have some db or cache with known vpn ips and check against it
the game window is not letting me resize, so unabale to see the converstaion
Yep, that's DPI where it analyses the content/structure of the packet

With a conventional firewall it's very easy to say "no UDP traffic to this port to any IP" without doing DPI etc.
DPI needs a lot of CPU power
ofc
well I can imagine
but I would've thought it'd significantly slow down internet speeds
Yeah if you can't keep up

@fair lava Do not discuss illegal activities here.
Do not promote circumventing legal blocks.
Alright, you can maybe get outside a little, you were here all day yesterday and now....Sun won't kill you
No need to cry about it
:mute: 3usk#0 has been muted.
[MUTE] I cannot DM that user.
If you're trying to stalk me to that extent, I think you got me mixed up with someone else.
I was in an exam yesterday ๐
This kitten trying to fight my shoes 24/7 ๐คฃ
Your poor laces...
mine has voices in its head 
I love how heโs constantly fighting his own tail too when it spooks him
Heโs still staying by me, hoping heโll want to explore soon
Awwh
Hey folks, just a question. How would you spend your time if it was your last week?
Solving side questssssss
while technically vulnerable it's still a pain in the arse
Oh gods, padding oracles?
all the AES-CBC challenges I have done ๐ญ
Spend time with fam and then possibly just drive to random places. Just drive tbh.
Real answer - do thm
Yeah i like driving
I would do it as well
yeah, pain.
big time
You have not seen the real pain. ECC (elliptic curve) exploiting.
Have never done elliptic curve exp. Nore anything with aes. Any suggestions where to start?
ECC is great, but avoid ECDSA
I can lead you to Certain Doom to find out why ๐
The walking dead?
Also there are suspicions that that curve is backdoored by the NSA
Lmao really?
nah, Java was a bit broken
can't remember if it was that one or another, but one of the standard curves was thought to be
There has been a lot of news lately about nefarious-sounding backdoors being inserted into cryptographic standards and toolkits. One algorithm, a pseudo-random bit generator, Dual_EC_DRBG, was ratified by the National Institute of Standards and Technology (NIST) in 2007.
Ask him what color are meadows beyond his mud puddle rather than listening to that nonsense
I need one of those grabby things
The extended pincher
Arm claw thing
So I donโt have to bend my back to pick things up
Kindly, if you have something positive or even just informative to contribute then do so.
If you dislike or disagree with the rules here, you're more than welcome to leave.
But with the pincher
wtf
I didnโt click that
Lmao what
I canโt anymore with this bloody phone
I put grabber in GIF and IP grabbers come up
hey there guys, im new learner in cybersecurity and i geniungly dont know where to start, what to start
can anyone guide me through?
would mean a lot and will also help immensly through
Thanks
You can start with this pathway ๐
You can first #start-here and sign up on the site. There are recommended paths to follow (You don't have to) here: #general message
Cyber security is often thought to be a magical process that can only be done by the elite, and TryHackMe is here to show you that's not the case. Anyone, with any experience level, can learn cyber security and this Pre-Security learning path is the place to start.
okie let me see
Thank youuuu so muchh
Gave +1 Rep to @cloud quiver (current: #5 - 1425)
Thanks man
Gave +1 Rep to @severe coyote (current: #1238 - 3)
man this is amazing
Thank You man๐ซธ ๐ซท
I dowoad kali from the Microsoft store how do I connect to htb or tryhackme vpn
sudo openvpn xyz.conf
Please use a VM rather than WSL...
they say 
It should work fine in WSL2 iirc
Doesn't mean it's a good idea 
Indeed
Hey will it work on kali or ubanto and Is it even real
real? what's real?
it'll work on both
We're all just a fantasy
fantasy is a stretch 
The command
@high kindle just google โhow to connect to tryhackme vpnโ
Youll get all the things you need
I stg if someone wrote a bloody guide...
- Install openvpn <- installed by default anyway
sudo openvpn xyz.conf
there's the guide
Jay you forgot that he needs to download his package
I remember when there was no attack box, and definitely no setup guide. You had to find the access page and figure out how to connect to one of the 30 odd rooms on the site.
A different era
Think he meant the config
The ovpn package with his username in tryhackme so he can connect
Ah right
It was fun tho
HackBack2. Good times
Hey they had a Kali
I remember the Kali room even if you don't
I remember it
Wasn't quite the same though
The kali room was my first room ever
@high kindle So, to summarise, instead of downloading Kali from the Microsoft store, we'd highly recommend you use a VM instead. Check out either "VMware" or "Virtual Box" and use the one you find easiest; there are plenty of tutorials on both.
๐คฎ
๐ถ
Yes yes yes, that can be taken two ways, I know 
W virtualbox
The only reason I have vbox installed is for genymotion
lol its only two ways
Have you tried it recently? They did improve it substantially
UI/UX is nicer
Not for a couple of months
vbox is for opening the werid sites
It's the networking and peripherals which used to annoy the hell out of me though
I switched to workstation years ago
VMware has been causing me too many issues recently
Welcome to Broadcom
i mean what is your main reason to shift from vbox
I'm trying to get permission to deploy Proxmox at work
hey jabba are all your assessments open book or is it just a first year thing
Networking and peripherals mainly. It was significantly less polished than VMware overall. Things just worked in VMware, but took ages to get working in VBox.
If James says it's better now than it used to be, I trust him though.
USB passthrough being one of the big ones which just didn't work half the time.
who is james ???
This was years ago now though, mind.
I've had equal amounts of problems on both lmao
IDK if they actually fixed stuff under-the-hood
Really? I've had a few guest additions problems on workstation, but nothing like the crap VBox was pulling
Only networking "problem" I've seen is the "NAT" and "NAT Network"
...but why?
The limitations in their network editor was annoying af too
What is your use case? Tails won't be right for 99% of cases
Although granted, the workstation networking is still fairly limited
why ?
torproject reccomended the tails
Again, what is your use case for Tor? 
You need to understand that choosing the appropriate tool for the job is what makes something the "best" or even just "good"
You use different operating systems and software for different uses
yep boss
help. I don't know how to exit vim
rip you're stuck there for eternity now
Power cycle
:q! ๐ฃ๏ธ
didn't work, I've put it in rice too
:helpclose will bless you
<Esc> then :q! <Enter>
Yo, I've just noticed that I have a "Legend" tag right after my nickname. Is that tag permanent? Why I even got it?
0xD God was renamed to 0xD Legend
Nice pfp Muiri
hi everyone
are you able to make an educated guess on weather my acc is hacked? fb and insta. im worried for my safety no joke
i have screenshots of recent logins
Change the password and activate two factor authentication
Do not reuse passwords between different accounts
i did that two factor was always on
there was a pc login a week ago, i dont own a oc
and 7 more, iphones, iphone 16s and ipads
all in where i am from
If you have two factor on and they're all from where you are, they're probably all you
so two factor would mean i would have to accept the login from my own device? always?
Two factor means you would have to provide a second factor of authentication. Usually more than just a password
This can take many forms.
but i doesnโt necessarily mean it would show up on my phone right
It depends what second factor you configured.
authentication app
So you'd have to enter the code if that's what you configured.
so if someone would log into my account else where they would need my phone to get in?
That's the idea of two factor authentication yes
I use the sudo apt install openvpn
And it's say he is unable to locate the package
They would need to get that code
17 logins in the span of a week is concerning
Apt update first.
i dont download apps or anything
Not with two factor and a good password.
All from your location.
I use kali linux from the Microsoft store
Still applies.
K
You asked us for this.
i dont get it
is there an app i can download to see if my device is being tracked or tapped into? ive been going para for a week straight
By whom?
an old enemy who has connects is the whole country and everywhere else
Unlikely.
its very likely trust me
Go to the police then.
the phone seems fine no lag battery loss
no weird apps
i assume you guys dont provide any services here
No. Go to the police if you suspect you're the victim of a crime.
Don't get conned by someone selling charlatan services.
Couldn't the attacker steal 1 valid code to then replicate the authenticator pattern later
Not with one, no.
You'd need 2 and the times they're from, accurate to 30s for default TOTP.
There's more than just default totp out there
Extended physical access to the phone is kinda... not the threat model it's for
I love her curves but what's more preferred is the way she articulates words
Right, thanks for correction
its very weird like i say all in my city, pc, ipads iphones i know he uses ipads. 18 different logins on both instagram and facebook, instagram password changed all in one week
Gave +1 Rep to @naive violet (current: #2 - 2225)
Winter break here. CYBER SECURITY AND MATHS TIME. yay
Go to the police. Hacking accounts is a crime.
ok. thanks for the help anyway
Plural of math is math
In most cases
Not in the King's English
Which is the original English.
Ty. I'm greek. I know it is mathematics. Not mathematic. Ty for helping out
Gave +1 Rep to @wooden totem (current: #219 - 31)
It's maths, don't let those who speak American English get to you
I mean what I said makes perfect sense I believe
Idk
It's an abbreviation for mathematics in my eyes. Idk abt grammar
Damn I was 1 sentence away from that, didn't read all the way through (I looked it up and first thing that came up was math is plural in all cases)
Yo No one.
How's life?
Uh idk. Hbu?
Decent, decent, thanks for asking.
A bit tired but also really motivated to build some stuff.
No idea what to make yet, but something.
Again. I don't disregard your knowledge cause I don't claim I know English grammar all that well. It's just that w my logic I explained it makes perfect sense lmao
Wow!
In the last phases of building something here, just deciding on a box to put it all in
The British way does indeed make more sense
I mean, built software? Robotics? What!!
Software-ish.
Got a certain cool domain that I currently have an empty website on and I want to do something with it.
Just got no amazing idea yet.

Is day 19 the last day of the advent of cyber?
No ๐
Event lasts until Dec 24th ๐
Got it thanks!
is anyone elses vpn acting weird?
Do a blog with write up of challenges,
saturated
there are 1000s of different writeups on medium
Well no writeup is ever the same
If you build online audience using social media you can funnel it to your blog
Smoothie done lets get the day started๐ฃ๏ธ๐ฃ๏ธ๐ฃ๏ธ๐ฃ๏ธ๐ฃ๏ธ
i want one too
can anyone provide me a free tryhackme voucher
i am really poor and want to make a career in cyber security
U can complete the AoC for a chance to win a voucher
where is it
Bro google
Dont wanna be rude but just google things
You can learn quite a lot just from free access, premium just gives better speeds and connections and opens a few more premium rooms
oh i gotta learn a lot from the free resources
Pog, new HBA for my server has been ordered 
ig it gonna take me months to win that
There's lessons along the way and then you get to hack-along with the lesson, if you get stuck then #1305926862114914325 is there to help
okkk thanks for the help
Gave +1 Rep to @fathom aspen (current: #1658 - 2)
No problem, happy hacking

christmass?!?!?
Christmas
Im gonna use thm to teach to a class
Just curious how do i make my own lab for students to join
Cloud or vpn?
@near hawk I believe this is your domain.
Wait, before you do that. Are you in India?
Yup
Ok, carry on then lol. Was going to say, CEH isn't really used outside of India
@cosmic pendant Can maybe weight in here too? Toast, it's Info sec class related.
Teach CEH?
Hey, Toasty
HI
how is your day going?
Good, how is yours? Why did I get a FR?
I'm good
I wanna ask about pursuing PhD
You can create your own VM, upload it and then they can use the VPN to connect to it.
idk what i look at. don't have instagram shit for a start ๐
Don't mneed to be signed in
poor kid
Apparently there is a H2D coming out in the new year ๐
More printers? JESUS
Beans
I can't download packages in wsl kali linux pls help
Did you apt update?
Can you show us what happens when you try to?
print the world !!
got my hand on a prusa mini and it fits too well in it's designated place.
@boreal scarab ill dm you smth ๐
You don't need to update anything, do ping -c 4 google.com first and see if it fails
Apt update will update the list Kali pulls everything from.
The list may be broken, and needs updated.
Pinging Google won't solve broken installs.
How do you know? Did he tell you that?
It's says unable to locate package nmap
It's a common issue to not be able to install or update, whilst having an internet connection.
It could be their AV that is potentially blocking it
I'd recommend a screenshot so that we have the full context
You can have an internet conn and still not be able to update and/or install.
Please can you take a screenshot that shows us the error(s)?
If you add screenshots we can help better, pictures are easier to help.
Without that, it's difficult to help
I can't but I can send what it says
Copy/paste? The full text is the most useful thing for diagnosing the issue
Wait a min
'http.kali.org'
Warning: Some index files failed to download. They have been ignored, or old ones used instead.
I can't send the whole it's too long for non discord nitro
Wonderful!
Sorry, had games in my messages beforehand lol
Put it into a text file and attach it, should let you get around it that way
Also you should be able to screenshot it?
SysOps Saga is a thrilling simulation game that puts you in the shoes of a Site Reliability Engineer (SRE), managing the intricate web of software, security, and hardware to keep digital systems running smoothly. Developed by a seasoned FAANG veteran, this game offers an immersive and educational experience for IT enthusiasts.Key FeaturesMaster ...
$14.44
what was the other one about?
No I don't got discord in my pc can someone help it's says he can't connect to http://http.kali.org/kali
It's in wsl
If you're gonna listen to him you'll never fix anything XDD, just add me
This guy...
Are you using a school or work computer by any chance?
No I'm using a old pc I want to use it as a ai server or homework and maybe just do tryhackme missions
That I linked?
yea
Seeing as you're apparently a dev, you should have learned effective troubleshooting and how to read error messages.
Being hostile to all those around you provides precisely zero help, and additionally makes people dislike you.
If you try to navigate to http.kali.org/kali/ on your windows machine, what happens?
I believe by default it's plain HTTP but yep good step
I found yt toutrial from networkchuch but still thanks
Gave +1 Rep to @shut hawk (current: #14 - 587)
completed my ctf 
both look well made. Though the Network Engineer might be worth it.
Sadly, that one isn't released yet. But Network Engineer is in my wishlist
I'm sure you could do worse for a source.
Does your pc have any issues connecting to anything?
What do you mean hostile? I even let you talk and I didn't say anything, let's see how will you fix it
gonna enjoy the pain of an engineer for fun 
cough Sysops Saga
@high kindle Do sudo apt update if you didn't know already how to do it
whats this
One review.....
"- Tedious tasks - roll out security updates to all nodes while maintaining uptime. Great setup, but given how this needs to be done, there is a lot of clicking involved for a simple task."
Anyone wanna tell them?
@fair lava They can't, that's the issue we're trying to solve here
Really?
It's also the first thing I suggested lmao
Yes. Current state of what's available in the repos
Also any IP changes etc of repos, often they go stale
Can you teach me more about it
phew
Hopefully 17.6.2 corrects my CLI issue.
New linux update?
hello
What's the friend request for?
I had questions, but in the end, I was answered, sorry.
how does one even accomplish getting vmware workstation pro everytime i try to download it i get stuck at broadcom login
It's ok, next time can I ask you ping and ask furst
Do you have a broadcom account?
no
You'll need to create one.
i tried to register for one and something always covers the submit button even using tab doesnt woerk
Tried a different browser?
ahh
last day of work for two weeks
Yippeee
they're calling it the least productive day of the year
Was thinking about getting game, is it worth playing?
An announcement will be made shortly.
:hammer: 3usk#0 has been banned.
๐ ๐ฅณ
Advent of Cyber 2024 DAY 20 Let's Go!
๐ฅณ ๐
did we get demoted?
why NaN showing?
it's still starting
Played the sysops game..... my head hurts now
^ Read above lol
ya...but recently showing like this...I think they update something...thats a little bug
hey
First hacked:
It's not started yet, so it's Not A Number.
Hellooo ๐
Non applicable number
It's VERY thought intensive. Just got introduced to testing environment with 2 new software to get networking to. But the layout.... it's jank. Still have to figure that out. So far, it's good
@celest dirge
just wrote a natty python list comprehension
labeler_data = [
(
model,
os.path.splitext(image)[0],
os.path.join(labels_path, labeler, model, subdir, image),
raw_image_dict[os.path.splitext(image)[0]],
)
for labeler in os.listdir(labels_path)
for model in os.listdir(os.path.join(labels_path, labeler))
for subdir in os.listdir(os.path.join(labels_path, labeler, model))
for image in os.listdir(os.path.join(labels_path, labeler, model, subdir))
if image.endswith(".png") and os.path.splitext(image)[0] in raw_image_dict
]
it's crazy these are like 1,000,000,000x faster than for loops
Alright, thanks. Imma check it out.
Gave +1 Rep to @boreal scarab (current: #30 - 321)
Welcome!
For those who need to support older keys for legacy systems, the new build includes the SSH1 client, which the Kali team says is an SSH client frozen at version 7.5.
That's good, SSH1 will stop the need for using oHostKeyAlgorithms and oKexAlgorithms on the some of the older THM rooms.
@celest dirge This is only Stage 3, oh, and you have a dev to determine if there's a bug in a software, then you have server resources, logs, etc
ooo interesting
no email today
No news is good news.
Christmas break is today๐ค
i went to Kali's blog
https://www.kali.org/blog/
Home of Kali Linux, an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments.
Should i make a networking game
Yeah, there is some near changes in the past Kali of 2024.
" Kali Linux, deprecates DSA keys for good" DSA ๐ -> ๐๏ธ
GNOME 47 and accent color customization !
new tools look cool
linkedin2username
could anyone help me find an iot camera/similar device that I could use to conduct a pentest for a university project? ive had a look and im struggling to find one where the firmware versions are correct.
We can't assist you with your project, can you please seek advice from peers of lecturer.
no worries, cheers
this is a bit unrelated but you showed me the books from Humble a few days ago- bought all 18 today; gonna start on Foundations of Information Security now. Thanks for your recomendation again
Gave +1 Rep to @grizzled wing (current: #79 - 95)
Guys... Imagine doing THM in a restaurant, due to the awesome wifi, and somebody asks you to teach them the fundamentals... Like dude I don't even know that much, but okay I'll try my best...
ha! have fun teaching them - teaching what you have learnt is great for revising and it let's you know if you really understand the topics yourself
I gave them a crash course in IP, DNS and http. Just so they can start looking at websites in a different light.
yay ๐ happy learning !
you can show them the sensionalized network chuck video about wifi hacking in a coffee shop
Thank you. I will have fun tomorrow, because we set up a follow up for tomorrow when I can actually focus on more things.
Gave +1 Rep to @floral charm (current: #421 - 13)
it already so confusion, but im gonna use this as an opportunity just gain a faint memory when i actually learn the topics on a later date
๐
omd i've seen that video tooo
๐
I want to hack, but Kali be like
the reindeer ate the email
is that a vm?
bit cringe but they lucky to have found ya, someone so willing to teach
Of course ๐
Rollback email. ๐
2 more days of AoC right?
21, 22, 23, 24 (i think)
It was 24?
hmm, oh well
It's always been 24 + 1 questionnaire.
only 22? i coulnt have known anyways cus i only joined halfway this year
I saw a mod say that the 24th was the last day. Do they post new tasks on the weekend?
Gaww is typing awwww
New rooms come on a Tuesday and Friday after the event ends.

And sometimes random days in between.
Interesting!
I only have two more tasks to be fully caught up. I'm sick at home so I'll probably finish them today.
Tuesday is an in-house dev room.
Friday splits between either an in house challenge room, or a community created challenge room,
Hellooo lovely earthlings - worked abroad for 8 months and left computers behind to save up enough to be able to now study in sincerity . Spent the last two months studying / passing the network +. Getting back on THM - Iโm getting ready for the pentest+ but I have previously complete the jr pentesting path. Any suggestions on rooms , paths , boxes ?
omd i missed that, only fully locked in mid november. hyped for next year's halloween event then (2nd fav holiday)
I wanna get nasty at report writing . Thinking of just cruising vulnhub for a bit
there are report templates on github so you can practice writing reports of your pentesting -- ๐ง smart move
I'd do PJPT over Pentest+
https://developers.google.com/tech-writing/one
Is fantastic for techical writing
im bookmarking that for sure, thanks for sharing
Gave +1 Rep to @shut hawk (current: #14 - 588)
would be funny if their AI wrote their technical writing
I was mainly doing it to stack my other compitas . I got the ejpt a few years ago . Already got sec+
Fomori with the wins
do people do that in real engagement so to save time at the end
After Pentest+, I'd do PJPT & PNPT by tcm-sec
how good/ recognised are the TCM certificates?
based on my understanding that you have your template and standardization and then make changes for the target you are dealing with
I have a coworker that's absolutely obsessed with using AI assistance for just about all of their filing and reports.
ohh that makes sense, it would be hell to start from the beginning for every one
Not popular or accepting yet, but it is really good
i use AI , i like it, overall neutral
Yeah Iโm sure the tests / prep would but fun and difficult . But does HR know about heath and his punisher tattoo ?
I don't mind it, but I want to make sure I'm capable of performing a task on my own without it.
๐ got THM email ๐ง
True, however tcm-sec is ran by good people (am biased since I'm friends with a few of the support staff)
ohh, would you say HTB or TCM after i complete most of Tryhackme?
and teh exams are actually affordable
not unless some companies
The pentest+ also adds life to my sec+. The comptia are only good for 3 years and if you get the next in line it adds time to the previous
i like the main TCM guys video, haven't watched one in ages
TCM HTB THM certs all help breakdown the paywall garden the OFFSEC have, that is what John Strand is saying
Mayor Malware is typing malware
I mean the brass ring is still the OSCP no ?
A New Challenger Has Appeared
But the industry's point of view is still with those old certification standards.... the people who are hiring you might not know or be exposed to the contents and the trainigin meterials, they just follow what has been followed from years
Die Hard watching is soon upon us
Best christmas movie ever
I am not sure, I mean both are at the equal level in my eyes.....
have a few laughs
I feel it funny reading it ๐
const gr33ting$ = "hello"


