#general

1 messages ยท Page 636 of 1

grizzled wing
#

๐Ÿ“ก

wooden totem
#

Get out

grizzled wing
#

that is a movie

unreal garnet
#

good afternoon

grizzled wing
#

๐Ÿฟ๏ธ

mellow gull
#

Greetings

keen quail
#

is there any hope for winning anything on advent of cyber this time

grizzled wing
#

there is hope of 1%

mellow gull
#

I did the statistical analysis on this a while ago.

#

Even the worst possible odds are like 1.5%

grizzled wing
#

the real prize is the learning along the way

mellow gull
#

The learning has actually unironically been really great, they've definitely hit more than they missed with the rooms

grizzled wing
#

last year's game AoC was buffer overflow, i enjoyed that

#

it was cool to understand what that means

crude stump
#

I told my self I will do AoC. Havenโ€™t even done one ๐Ÿ˜‚

cloud quiver
grizzled wing
#

some days are super simpl while others take time

mellow gull
#

The only overflow I knew about before this was integer overflow, which is also amusing

crude stump
#

Nah I tried. Itโ€™s not my style, I donโ€™t like how the information is spoon fed to you. Itโ€™s not a challenge which I like

grizzled wing
#

side quest

mellow gull
#

You don't have to read the guide

#

I don't disagree that some of the rooms are legit, like, railroaded for you

#

But some of them are pretty open pasture too

grizzled wing
#

what is albert_c137 typing?

mellow gull
#

I'm really curious too

grizzled wing
#

like a book?

mellow gull
grizzled wing
#

maybe a letter left in the text space

mellow gull
#

I'm a fae creature Albert I'm not allowed to look away until you're done

grizzled wing
#

just hit enter already albert

mellow gull
#

Show us the WIP

grizzled wing
#

edit after

jolly hill
#

Hi guys. So a friend of mine from China told me that he can use proxy to access THM but always fail to use openvpn to connect the VM in THM. Iโ€™m guessing maybe itโ€™s because the great firewall (operated by the Chinese government) block the ip or something. Iโ€™m just learning hacking so Iโ€™m not sure. What can he do?

grizzled wing
#

finally!

quasi hedge
#

Is there any way to generate a pdf transcript for tryhackme?

mellow gull
#

Oh, that's not what I was expecting

grizzled wing
#

that took so long to type a paragraph

jolly hill
#

Yea sorry.

#

Iโ€™m not good at English

mellow gull
#

Uh, anyways, yeah, there's nothing we can do when a country prohibits the usage of non-sanctioned VPNs

grizzled wing
#

were you using google translate?

mellow gull
#

Or at least nothing we can recommend for you here.

grizzled wing
#

maybe @silver sky is around to help

jolly hill
grizzled wing
#

ok , just curious , no issue either way

jolly hill
twin ridgeBOT
#

Gave +1 Rep to @grizzled wing (current: #81 - 94)

silver sky
jolly hill
#

Well ok then. Thanks anyway โ˜บ๏ธ

alpine lintel
#

yall be using burp suit, caido or owasp zap?

grizzled wing
#

burp suite i like

cloud quiver
mellow gull
#

Burp is fine.

rapid merlin
#

Burping is burpin n slurpin

mellow gull
#

I'm still internally a child so the name makes me laugh but it's genuinely preferable amongst the options

grizzled wing
#

one day i will use caido

alpine lintel
#

im trying to find new tools to break out of the ordinary and shi, any particular yall recommend? Been using rustscan for a while instead of pure nmap now

grizzled wing
rapid merlin
alpine lintel
rapid merlin
#

Finding new tools is always good, but using them just because they're not ordinary is rather silly

mellow gull
grizzled wing
#

try caido, if you like rustscan then caido is written in rust

grizzled wing
mellow gull
#

Even the more innocuous stuff

#

Yeah so I wrote a script in ducky and used it for parsing with my pineapple

grizzled wing
#

"that sploit is so meta " haha

#

i dont have any hacking tools, kinda glad i dont

mellow gull
#

I only have a few bits and bobs that I've been experimenting with

#

Been luckily avoiding the more expensive/questionable articles

silver sky
grizzled wing
#

haha

#

what were the arguments?

#

routerfuck -this shit

silver sky
#

There were no arguments it just displayed a screen saying searching for routers to fuck.

mellow gull
#

Hahahaha

quasi hedge
rapid merlin
#

blame yt

mellow gull
winged summit
#

lmfao

#

wtf haha

#

sorry, hi ๐Ÿ™‚

grizzled wing
#

Daniel

winged summit
#

heyo! ๐Ÿ™‚

#

how's it going?

grizzled wing
#

know of any immature named hacking tools?

winged summit
#

immature?... hmm... what do you mean? lol

#

oh

#

haha

#

hmm

#

let me think

#

fuzz faster you fool?

#

(ffuf)?

#

i mean, i like the name, but yeah

grizzled wing
#

ha

mellow gull
#

Aha, it appears

grizzled wing
#

fartercap

winged summit
#

oh, ffuf? ha

winged summit
grizzled wing
#

no idea

jolly peak
#

Hello EVERYONE

winged summit
#

hello

grizzled wing
#

posh spice is here

jolly peak
#

whats posh spice..

wooden totem
winged summit
#

haha

jolly peak
#

guys im FRESHLY new to this

silver sky
#

Ok

grizzled wing
#

so fresh?

jolly peak
#

really really fresh

grizzled wing
#

welcome

winged summit
jolly peak
#

just started aboutttt an hour ago

grizzled wing
#

nice

winged summit
#

respect

mellow gull
#

Hello Fresh

wooden totem
#

I'm surprised I didn't throw up after yesterday's huge burger, that thing was taller than my phone

grizzled wing
#

next step is to learn l33tc0d3

silver sky
jolly peak
#

not what i meant but hello.

mellow gull
#

I'm so happy at least one person got the joke

grizzled wing
jolly peak
#

im just barely on "what is networking?" someone end it

grizzled wing
silver sky
winged summit
#

ngl. i just now linked the spice girls joke lol

#

i failed lol

grizzled wing
winged summit
#

my brain must be slow tonight

mellow gull
#

Alright fellas you know what to do

#

SYN

winged summit
#

SYN-ACK

grizzled wing
mellow gull
#

ACK

winged summit
#

noice

#

lol

grizzled wing
#

FIN

jolly peak
wooden totem
winged summit
#

haha

silver sky
#

PACKETS LOST = 4

grizzled wing
winged summit
#

+_+

pulsar jacinth
#

Hi all, I'm trying to proxy traffic through my VM to my main computer. I got some help on how to use ssh -D 8089 user@ip . I have the VM connected to THM vpn. I set up burpsuite in foxyproxy but for some reason when I enable the SOCKS proxy in burpsuite I can't get to any websites anymore, I just get connection refused. Is anyone else doing this by chance?

jolly peak
#

all of a sudden i gained interest

winged summit
mellow gull
winged summit
#

turn off burp proxy or use another window to browse the web

grizzled wing
#

foxy proxy is capturing your traffic?

#

๐ŸฆŠ

wooden totem
#

Swiper no swiping

jolly peak
wooden totem
#

Looks like?

pulsar jacinth
#

So how can I access the sites that only the VM has access to from my normal web browser? Or is that not possible. I thought that's what I was enabling.

jolly peak
wooden totem
# jolly peak iykwim

What are these hieroglyphics or modern are, supposed to decipher each word out of this

mellow gull
#

THM seemed boring until I was staring at a terminal screaming about how my listener isn't listening

grizzled wing
#

when you get your first rev shell, โค๏ธ

sick lance
winged summit
wooden totem
#

Scrubz jumpscare

pulsar jacinth
grizzled wing
#

ah. i agree with scrubz

pulsar jacinth
#

Hmm, maybe I misunderstood what someone told me the other day then

sick lance
grizzled wing
#

you want to stay inside your VM and stay safe using it

winged summit
#

@pulsar jacinth so if you have host_computer > foxyproxy > ssh socks tunnel > vm_host... hmmm... how to get from vm_host to websites... it depends on the websites. if you're just targeting the thm boxes over the VPN, then you could setup a local forward from the vm_host to the thm_target. then, access the local forward through the socks tunnel maybe.

sick lance
#

Help us, to help you.

pulsar jacinth
#

I thought I could forward traffic from the VM to my actual computer

mellow gull
#

Why would you want to do that?..

pulsar jacinth
#

Let me find the post, hang on

wooden totem
sick lance
#

It's too much effort just to use a browser.

winged summit
#

@pulsar jacinth also, check your dns. depending on what you're trying to do, if your host os processes the dns before it gets to the vm, the connection might just try to go straight to the internet and bypass the socks tunnel

#

@pulsar jacinth try setting the thm target ip in your vm /etc/hosts file, then try to access the thm target by the dns name in your host os browser assuming 80 or 443 is open. curious what happens.

#

anyway, yeah. that's a pretty complex setup. have fun lol

mellow gull
#

This is not in my knowledge box

winged summit
#

one more thing. foxyproxy allows you toggle whether you want to proxy dns through as well. so if you ensure that's ticked, then you know your dns is hitting the vm host.

winged summit
#

even for me, and i'm pretty advanced

#

what's your ultimate goal?

#

and why?

#

oh shit

mellow gull
#

I am not smoochii

winged summit
#

wait

#

my brain

#

omg

#

you're right

#

+_+

#

sorry. brain derailed

#

lol

grizzled wing
#

Gaww has knowledge

mellow gull
#

It is fine, it happens to everyone

grizzled wing
#

in a busy chat

jolly peak
#

gaww lets trade brains for a day ๐Ÿ‘

#

you can be "posh spice" i can be gaww

grizzled wing
#

@jolly peak have you set up a place to write your notes?

wooden totem
jolly peak
#

havent set anything up as of now

grizzled wing
jolly peak
pulsar jacinth
#

I basically just want to be able to access the machines on THM VPN from my normal web browser but through my VM which is connected via VPN

jolly peak
pulsar jacinth
#

I can SSH into my box just fine and reach the machines

mellow gull
#

I've always been a little curious to trade minds with someone

But I'm confident I'd go crazy. Or drive the person who traded with me crazy. My mind is a labyrinth to madness and a temple to lunacy.

winged summit
normal fable
#

veggies out here still giving green bell peppers to people. ๐Ÿ˜‰ moo therea216H

grizzled wing
jolly peak
pulsar jacinth
winged summit
mellow gull
grizzled wing
#

serentity now! madness later

winged summit
grizzled wing
winged summit
#

ok, i'm convinved my roommate has taken out all the pots and pans, is clapping them together and just shuffling them around to drive me insane lol

#

haha

#

omg

#

i'm simultaneously developing an ulcer and a headache haha

#

lol, this is literally madness.... lol

mellow gull
#

Madness?

grizzled wing
#

roomates is a ๐Ÿงต

mellow gull
#

No...

#

This

#

Is

#

Sparta

winged summit
#

LOL

#

haha

#

if sparta was more passive aggressive and tyrannical, then yes. you are correct LOL

winged summit
#

indeed. dude is jacked in that movie ha

mellow gull
#

Sparta was hilariously passive aggressive historically

#

The "if" callout response is proof of that

grizzled wing
#

everyone had six pack abs

winged summit
#

but yeah. i wish my roommate would just tell me to my face, "i hate you and want you to suffer. please be miserable" rather than actually just make me feel miserable by constantly demanding attention lol

mellow gull
#

TLDR a city state said that "if they were to wage war" on Sparta it'd be ruinous

mellow gull
#

Sparta responded by sending a letter that was only inscribed with "if"

pulsar jacinth
#

@winged summit I got it to work ๐Ÿ™‚

winged summit
pulsar jacinth
#

I don't know if it's safe but it works rofl

#

So I did ssh -D 8089 user@myattackbox This opens a SOCKS proxy on 8089. I then set up foxyproxy to proxy on 127.0.0.1 for burpsuite. Then in burpsuite I set up the SOCKS proxy under network connections to be my attackbox with port 8089. Now I can access both regular websites and 10.10.10.10 and I get traffic from both in burpsuite.

winged summit
#

ohhh, maybe the socks in burp wasn't setup?

#

i mean, you said it was, but in any case

#

it's working, that's awesome ha

pulsar jacinth
#

Well that was the goal but it wasn't working. Now it is

winged summit
#

gotcha gotcha

mellow gull
winged summit
#

nice! ๐Ÿ™‚ good job

#

ohhhh. let me guess. previously, the burp socks proxy ip was 127.0.0.1? haha

#

err wait

#

that has to be because ssd -D

#

ssh -D

#

arg

#

nvm

pulsar jacinth
#

Ah it was because I had the SOCKS proxy set to my attack box IP but it has to be 127.0.0.1:8089

#

Ya, that

winged summit
#

so the exact opposite! haha nice. that actually makes total sense

#

haha

#

we shared the same erroneous thought lol

#

(at some point)

pulsar jacinth
winged summit
#

that's the tldr. but yeah. there's a lot happening there lol

mellow gull
#

Lots of condensed Neat

pulsar jacinth
#

So the real question, is this safe? Can people on the VPN access my actual computer?

winged summit
mellow gull
#

There seems to be a couple layers of access that'd need to be enumerated there.

#

To the point of being extremely inconvenient.

winged summit
#

exactly

sick lance
#

I mean, if you're paranoid about your host, why open. Socks tunnel?

winged summit
#

i presume they'd have to pop the vm to get access to the ssh socks tunnel

#

but if they compromise the web target then that's piped directly into your host os

#

@pulsar jacinth if you're doing thm on your regular host os btw, make sure you backup all your data. the likelihood of something bad happening is low, but the impact is potentially high. always good to backup data if you're homelabbing on your host... malware analysis, etc.

mellow gull
#

That's a risk that'll always be there with trying to pipe directly to your host though, no? You're ultimately still giving a straight path with a few extra roadblocks in the way.

winged summit
#

like browser in vm versus browser in host os

pulsar jacinth
#

My wife is yelling at me to sleep but I'll read all of this in the morning. Thanks all!

mellow gull
#

Of course, the VM just gives you the benefit of waay more warning if you're paying attention

#

Have a good night

winged summit
#

yeah, and if you accidentally run some malware as part of a room, it should just wipe the vm etc. versus contaminating or deleting data on your host os.... unless you have shared folders setup to access your host os through the vm, etc.

#

fortunately there's no ransomware worm analysis as far as i know, haha. talk about total nightmare scenario lol

sick lance
#

If you're doing malware analysis on THM, it's best to leave the malware on the dedicated VM.

#

Not transfer it to your own environment.

pulsar jacinth
#

Oh one more question if my vm is on proxmox with the rest of my home lab, is any of that at risk? I donโ€™t think this has to do anything with the socks stuff, just generally curious.

winged summit
mellow gull
#

This is why I've heard flash/disk boot and ram processing is a safe bet if you're doing frequent analysis, since there's no permanent data that can get dusted.

winged summit
split plover
winged summit
mellow gull
winged summit
#

i remember tails too! haha. i used that back in the day as an experiment. back when they had a CD ๐Ÿ’€

mellow gull
#

Well in their environment it's usually part of malware analysis so they have a bit of a sacrificial lamb drive most of the time

#

Maybe if it could be triggered directly from BIOS?..

winged summit
#

hmm... yeah. not sure. i mean. i was thinking more just by software in the host os. but even then, windows has protections against accessing memory out of bounds, so probably not a scenario worth much consideration

mellow gull
#

It'd be niche for sure, but fun (and spooky) to think about. Sky's the limit

winged summit
#

exactly haha

sick lance
sharp citrusBOT
mellow gull
winged summit
# mellow gull It'd be niche for sure, but fun (and spooky) to think about. Sky's the limit

but now that you mentioned BIOS, that's my tin-foil hat jam right there, haha. persistent firmware rootkits lol.... that's the cool stuff.... but so niche that i know nothing about it. i remember at one point when i learned about the IntelME, i also learned about how previous versions contained a cellular modem, and i was like, "oh, interesting, it could just communicate via LTE and bypass the OS" lol

winged summit
#

bought a rtl-sdr kit to measure stuff, but didn't think it all the way through. a cell modem needs a SIM card. in addition, a beacon probably wouldn't be sent out for something that advanced unless i was actually a target lol

mellow gull
#

Well there used to be old worms that could do stuff like that. Some older drives used to keep separate memory for boot that could be taken advantage of, but I don't think that's been a problem for a long time

winged summit
#

ha

#

anyway, i gotta get back to portswigger. 20 more challenges to go before i sleep... we'll see lol

#

it was nice chatting @mellow gull ๐Ÿ™‚

#

i'll let you get back to your MILFfinder tool

#

lol

mellow gull
#

Have a good one, see you when I see you

jolly peak
#

i wonder what alex is typing for so long

split plover
#

Guys, I can't do multiple things at a time such as learning. As being in cyber you need to have vast knowledge about web, programming, malwares, forensics and other security measures to combat against attacks. The problem is that suppose I have 8 hours for studying I'd divide them among the topics I wanna learn for exp: web and programming. However, I'd like to study only one topic deeply first then move to another one but then I think I'd lack in other things. So, any idea what to do?

mellow gull
split plover
#

The one we can't talk here ๐Ÿฅฒ

#

Malware

#

Forensics as well

#

I mean they relate ig

mellow gull
#

Well, what I can suggest is that if you can only focus on a single subject at a time, then it might be best for you to focus on a single tool at a time, and then expand your repertoire once you've mastered it.

Like people in SOC will learn the ins and outs of SIEM tools like Azure or ELK.

#

Maybe something like EnCase or TSK or Ghidra

normal fable
#

I'm about to go sideways so I should probably just say goodnight THM. Moo.. moo moo moo..

mellow gull
#

Rest well

lucid hound
#

hello everyone

weary veldt
languid crag
#

Is there any specific path for the Bug Bounty?
I've done cyber security 101 path.

azure hill
silk walrus
#

Hello

lament tendon
#

Hello. ^_^

surreal void
#

Hello

severe coyote
#

Hi, Is Veracrypt still good for external hard drive encryption? Which software do you guys prefer.

lament tendon
#

Verycrypt's still good as far as I know.

severe coyote
lament tendon
#

If you're on Windows, you could also use TrueCrypt.

severe coyote
#

i use both windows and mac

lament tendon
severe coyote
#

yeah

lament tendon
severe coyote
#

which one for vera? or true?

lament tendon
#

For Veracrypt.

severe coyote
#

ok cool/ so that means someone is still updating it. thanks man. \

#

did you had a look on github?

lament tendon
#

Last commit was 3 weeks ago.

severe coyote
#

thanks

#

i am thinking of using this tool. heard its better than truecrypt.

lament tendon
#

They both do their job.

severe coyote
#

bitlocker is also good but it works with only windows will have issues with using the drive on mac

severe coyote
lament tendon
#

But I'd prefer VeraCrypt, because open source.

severe coyote
lament tendon
#

Not 100% sure about TrueCrypt in this case.

#

Well, it is officially a "source-available freeware", which means people can at least read the source code publicly.

jolly parcel
#

any channels here to correct an instruction?

late stag
cloud quiver
jolly parcel
lament tendon
#

Or do you mean the "sufficiently long" part because the keys are fixed sizes?

lament tendon
#

I did mean the passphrase you use to generate the key, that was poorly formulated by me. ^_^

#

But yea, in that case you are correct.

late stag
#

Itโ€™s not a good idea to use a key derived from the passphrase directly for encryption. Itโ€™s better to use it to wrap/unwrap a randomly generated key that will be used for the actual data encryption.

There are multiple reasons for that, but for starters, key wrapping approach allows to change the passphrase without re-encrypting all the data.

shell nova
#

usually not at 2 am, sorry

sick lance
#

I don't have unban perms.

That's Jabba/admin only.

shell nova
shell nova
sick lance
shell nova
#

there should be an OWASP Cheat Sheet on the subject

shell nova
#

or CCM

#

these are authenticated modes which help guarantee the integrity of the data

shell nova
chilly veldt
warped grail
#

hallo

wooden totem
#

Idk what to eat for lunch, there's so many options and like none of them stand out

wooden totem
steady tinsel
#

Anyone able to hack coinstat account

tidal urchin
#

How do I utilise the $10 voucher of swag shop ?

finite tulip
tidal urchin
#

where is the code thats what i wanted to ask

twin ridgeBOT
#

Gave +1 Rep to @azure hill (current: #854 - 5)

tidal urchin
tidal urchin
cloud quiver
tidal urchin
cloud quiver
sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

tidal urchin
#

ok

sick lance
steady tinsel
#

Ok my bad

plain flint
#

#854-5

#

Hi

azure hill
plain flint
azure hill
#

Welcome!

#

How are you liking the platform so far?

plain flint
#

So i need YOUR halp

chilly veldt
#

Wassup

plain flint
plain flint
#

@chilly veldt

chilly veldt
plain flint
#

Yeah sure

frosty perch
#

also looking for some help

azure hill
#

How can we help

frosty perch
#

nvm i was just confused

#

all good for now lmao ill be back though

rapid merlin
#

Red Team capstone challenge

#

IS HARD

frosty perch
#

bet

#

got plenty of time to learn

rapid merlin
#

I spent almost 4 hours just enumerating the thing, and found all the usernames I need and something else

#

to get me into

frosty perch
#

if i need any assistance ill come right over, when i get that far, just in the first steps of offensive learning

weak nest
#

do I need to connect to the thm vpn to interact with challenge machines and AoC domains?

tidal urchin
#

Current day AOC VM is frustratingly slow when I open vscode

naive violet
#

Some may be in-browser access, or a thmlabs url that lets you access it over the internet

weak nest
#

the rizzler

weak nest
#

is there a way to connect over tcp?

naive violet
#

No

weak nest
#

aha

#

well

#

is there a way to bypass my country's restriction on udp vpns

naive violet
#

If the VPN is blocked or illegal in your country, we cannot help you circumvent that block. That'd be illegal, and we have a zero tolerance policy on illegal activity here.

#

You can use the attackbox but that's likely the only way around.

weak nest
#

I see

#

any idea how they even enforce that in the first place?

#

I'm curious

naive violet
weak nest
#

hmmm

#

like I can send/recv udp just fine but when It's a vpn it doesn't work

naive violet
#

Iirc BlueCoat, a network firewall/appliance vendor, got caught selling to embargo'd governments

weak nest
#

do they perhaps have some db or cache with known vpn ips and check against it

tidal urchin
#

the game window is not letting me resize, so unabale to see the converstaion

naive violet
weak nest
naive violet
#

With a conventional firewall it's very easy to say "no UDP traffic to this port to any IP" without doing DPI etc.
DPI needs a lot of CPU power

weak nest
#

ofc

#

well I can imagine

#

but I would've thought it'd significantly slow down internet speeds

naive violet
#

Yeah if you can't keep up

weak nest
naive violet
#

@fair lava Do not discuss illegal activities here.
Do not promote circumventing legal blocks.

fair lava
#

No need to cry about it

grim sparrowBOT
#

:mute: 3usk#0 has been muted.

grim sparrowBOT
naive violet
#

I was in an exam yesterday ๐Ÿ˜‰

rapid merlin
#

This kitten trying to fight my shoes 24/7 ๐Ÿคฃ

naive violet
#

Your poor laces...

rapid merlin
#

๐Ÿ˜†

#

Heโ€™s so energetic

weak nest
#

mine has voices in its head skully

rapid merlin
#

I love how heโ€™s constantly fighting his own tail too when it spooks him

#

Heโ€™s still staying by me, hoping heโ€™ll want to explore soon

devout palm
#

Hey folks, just a question. How would you spend your time if it was your last week?

shell nova
naive violet
#

Oh gods, padding oracles?

chilly veldt
pliant cairn
devout palm
#

I would do it as well

shell nova
chilly veldt
#

big time

devout palm
rapid merlin
#

Awwh

#

My back is killing me

pliant cairn
#

Have never done elliptic curve exp. Nore anything with aes. Any suggestions where to start?

devout palm
shell nova
#

I can lead you to Certain Doom to find out why ๐Ÿ˜‰

devout palm
#

The walking dead?

shell nova
#

Also there are suspicions that that curve is backdoored by the NSA

shell nova
shell nova
devout palm
fair lava
rapid merlin
#

I need one of those grabby things

#

The extended pincher

#

Arm claw thing

#

So I donโ€™t have to bend my back to pick things up

naive violet
rapid merlin
#

wtf

#

I didnโ€™t click that

#

Lmao what

#

I canโ€™t anymore with this bloody phone

rapid merlin
#

I put grabber in GIF and IP grabbers come up

crimson scaffold
#

hey there guys, im new learner in cybersecurity and i geniungly dont know where to start, what to start
can anyone guide me through?
would mean a lot and will also help immensly through
Thanks

cloud quiver
devout palm
cloud quiver
#
TryHackMe

Cyber security is often thought to be a magical process that can only be done by the elite, and TryHackMe is here to show you that's not the case. Anyone, with any experience level, can learn cyber security and this Pre-Security learning path is the place to start.

crimson scaffold
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #5 - 1425)

worn turret
#

Thanks man

twin ridgeBOT
#

Gave +1 Rep to @severe coyote (current: #1238 - 3)

crimson scaffold
high kindle
#

I dowoad kali from the Microsoft store how do I connect to htb or tryhackme vpn

shut hawk
#

sudo openvpn xyz.conf

pallid lotus
#

Please use a VM rather than WSL...

gray pine
#

The other guys said that ovpn doesnt work well in wsl

#

So @pallid lotus is right

shut hawk
#

they say Shrug

pallid lotus
#

Doesn't mean it's a good idea kekw

gray pine
#

Indeed

high kindle
shut hawk
#

real? what's real?

pallid lotus
#

No, it's all in your imagination

#

Nothing exists

shut hawk
#

it'll work on both

pallid lotus
#

We're all just a fantasy

shut hawk
#

fantasy is a stretch kek

high kindle
gray pine
#

@high kindle just google โ€œhow to connect to tryhackme vpnโ€

#

Youll get all the things you need

pallid lotus
gray pine
#

๐Ÿ˜ญ

#

The guide is accessible even by mistake

shut hawk
#
  1. Install openvpn <- installed by default anyway
  2. sudo openvpn xyz.conf

there's the guide

gray pine
#

Jay you forgot that he needs to download his package

pallid lotus
#

I remember when there was no attack box, and definitely no setup guide. You had to find the access page and figure out how to connect to one of the 30 odd rooms on the site.

#

A different era

shut hawk
#

Which package?

#

iirc openvpn is installed by default

pallid lotus
gray pine
#

The ovpn package with his username in tryhackme so he can connect

shut hawk
#

Ah right

gray pine
pallid lotus
#

HackBack2. Good times

naive violet
#

I remember the Kali room even if you don't

pallid lotus
#

Wasn't quite the same though

gray pine
#

The kali room was my first room ever

pallid lotus
#

It was literally just a regular room with a Kali image in it kekw

#

Subs only too iirc

shut hawk
#

@high kindle So, to summarise, instead of downloading Kali from the Microsoft store, we'd highly recommend you use a VM instead. Check out either "VMware" or "Virtual Box" and use the one you find easiest; there are plenty of tutorials on both.

pallid lotus
#

virtualbox ๐Ÿคฎ

rapid merlin
pallid lotus
#

Yes yes yes, that can be taken two ways, I know kekw

mossy river
#

W virtualbox

shut hawk
#

The only reason I have vbox installed is for genymotion

naive violet
#

UI/UX is nicer

pallid lotus
#

Not for a couple of months

rapid merlin
#

vbox is for opening the werid sites

pallid lotus
#

It's the networking and peripherals which used to annoy the hell out of me though

#

I switched to workstation years ago

mossy river
#

VMware has been causing me too many issues recently

pallid lotus
rapid merlin
pallid lotus
#

I'm trying to get permission to deploy Proxmox at work

shut hawk
#

hey jabba are all your assessments open book or is it just a first year thing

pallid lotus
#

USB passthrough being one of the big ones which just didn't work half the time.

pallid lotus
#

This was years ago now though, mind.

pallid lotus
#

Hi @naive violet

rapid merlin
#

oooooo

#

k

naive violet
#

IDK if they actually fixed stuff under-the-hood

pallid lotus
#

Really? I've had a few guest additions problems on workstation, but nothing like the crap VBox was pulling

rapid merlin
naive violet
#

Only networking "problem" I've seen is the "NAT" and "NAT Network"

naive violet
pallid lotus
#

The limitations in their network editor was annoying af too

naive violet
#

What is your use case? Tails won't be right for 99% of cases

pallid lotus
#

Although granted, the workstation networking is still fairly limited

rapid merlin
pallid lotus
#

Again, what is your use case for Tor? kekw

naive violet
#

You use different operating systems and software for different uses

rapid merlin
#

yep boss

rose tusk
#

help. I don't know how to exit vim

shut hawk
#

rip you're stuck there for eternity now

naive violet
wooden totem
#

:q! ๐Ÿ—ฃ๏ธ

rose tusk
chilly veldt
#

I feel like a hoodie dealer

#

I have a suitcase filled with hoodies

wooden totem
late stag
hushed knoll
#

Yo, I've just noticed that I have a "Legend" tag right after my nickname. Is that tag permanent? Why I even got it?

naive violet
#

0xD God was renamed to 0xD Legend

hushed knoll
#

Oh, okay, thank you :>

#

Looks ๐Ÿ”ฅ

devout palm
#

Nice pfp Muiri

tawny imp
#

hi everyone

#

are you able to make an educated guess on weather my acc is hacked? fb and insta. im worried for my safety no joke

#

i have screenshots of recent logins

naive violet
#

Change the password and activate two factor authentication

#

Do not reuse passwords between different accounts

tawny imp
#

i did that two factor was always on

#

there was a pc login a week ago, i dont own a oc

#

and 7 more, iphones, iphone 16s and ipads

#

all in where i am from

naive violet
#

If you have two factor on and they're all from where you are, they're probably all you

tawny imp
#

so two factor would mean i would have to accept the login from my own device? always?

naive violet
#

Two factor means you would have to provide a second factor of authentication. Usually more than just a password

#

This can take many forms.

tawny imp
#

but i doesnโ€™t necessarily mean it would show up on my phone right

naive violet
#

It depends what second factor you configured.

tawny imp
#

authentication app

naive violet
#

So you'd have to enter the code if that's what you configured.

tawny imp
#

so if someone would log into my account else where they would need my phone to get in?

naive violet
#

That's the idea of two factor authentication yes

high kindle
#

I use the sudo apt install openvpn
And it's say he is unable to locate the package

naive violet
#

They would need to get that code

tawny imp
#

17 logins in the span of a week is concerning

tawny imp
#

i dont download apps or anything

naive violet
#

All from your location.

high kindle
#

I use kali linux from the Microsoft store

naive violet
high kindle
#

K

tawny imp
#

i dont get it

#

is there an app i can download to see if my device is being tracked or tapped into? ive been going para for a week straight

naive violet
#

By whom?

tawny imp
#

an old enemy who has connects is the whole country and everywhere else

naive violet
#

Unlikely.

tawny imp
#

its very likely trust me

naive violet
#

Go to the police then.

tawny imp
#

the phone seems fine no lag battery loss

#

no weird apps

#

i assume you guys dont provide any services here

naive violet
#

No. Go to the police if you suspect you're the victim of a crime.

#

Don't get conned by someone selling charlatan services.

wooden totem
naive violet
#

Not with one, no.

#

You'd need 2 and the times they're from, accurate to 30s for default TOTP.
There's more than just default totp out there

#

Extended physical access to the phone is kinda... not the threat model it's for

half badge
#

I love her curves but what's more preferred is the way she articulates words

wooden totem
tawny imp
#

its very weird like i say all in my city, pc, ipads iphones i know he uses ipads. 18 different logins on both instagram and facebook, instagram password changed all in one week

twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #2 - 2225)

half badge
#

Winter break here. CYBER SECURITY AND MATHS TIME. yay

naive violet
tawny imp
#

ok. thanks for the help anyway

wooden totem
#

In most cases

naive violet
#

Which is the original English.

half badge
twin ridgeBOT
#

Gave +1 Rep to @wooden totem (current: #219 - 31)

naive violet
#

It's maths, don't let those who speak American English get to you

half badge
#

I mean what I said makes perfect sense I believe

#

Idk

#

It's an abbreviation for mathematics in my eyes. Idk abt grammar

wooden totem
#

Damn I was 1 sentence away from that, didn't read all the way through (I looked it up and first thing that came up was math is plural in all cases)

lament tendon
#

Yo No one.
How's life?

half badge
lament tendon
#

Decent, decent, thanks for asking.
A bit tired but also really motivated to build some stuff.

#

No idea what to make yet, but something.

half badge
naive violet
wooden totem
#

The British way does indeed make more sense

half badge
lament tendon
#

Software-ish.
Got a certain cool domain that I currently have an empty website on and I want to do something with it.
Just got no amazing idea yet.

crude stump
#

Itโ€™s math

#

Not maths

gleaming bear
fluid lake
#

Is day 19 the last day of the advent of cyber?

cloud quiver
#

Event lasts until Dec 24th ๐Ÿ˜„

fluid lake
#

Got it thanks!

little siren
#

is anyone elses vpn acting weird?

dark frost
little siren
#

there are 1000s of different writeups on medium

gray pine
#

Well no writeup is ever the same

#

If you build online audience using social media you can funnel it to your blog

#

Smoothie done lets get the day started๐Ÿ—ฃ๏ธ๐Ÿ—ฃ๏ธ๐Ÿ—ฃ๏ธ๐Ÿ—ฃ๏ธ๐Ÿ—ฃ๏ธ

stable comet
#

i want one too

#

can anyone provide me a free tryhackme voucher

#

i am really poor and want to make a career in cyber security

little siren
#

U can complete the AoC for a chance to win a voucher

stable comet
#

where is it

gray pine
#

Bro google

fathom aspen
gray pine
#

Dont wanna be rude but just google things

stable comet
#

ok

#

thx

fathom aspen
#

You can learn quite a lot just from free access, premium just gives better speeds and connections and opens a few more premium rooms

stable comet
boreal scarab
#

Pog, new HBA for my server has been ordered rooSlide

stable comet
#

ig it gonna take me months to win that

fathom aspen
twin ridgeBOT
#

Gave +1 Rep to @fathom aspen (current: #1658 - 2)

fathom aspen
queen forum
boreal scarab
wild zealot
#

Im gonna use thm to teach to a class

#

Just curious how do i make my own lab for students to join

#

Cloud or vpn?

boreal scarab
wild zealot
#

I should learn aws

#

I was just going to ceh modules

#

Zamn

boreal scarab
wild zealot
#

Yup

boreal scarab
#

Ok, carry on then lol. Was going to say, CEH isn't really used outside of India

boreal scarab
cosmic pendant
#

Teach CEH?

wild zealot
#

Yup

#

Using the modules and stuff

#

But its very lengthy

drifting mural
cosmic pendant
#

HI

drifting mural
#

how is your day going?

cosmic pendant
#

Good, how is yours? Why did I get a FR?

drifting mural
#

I'm good

drifting mural
cosmic pendant
#

Ask away

#

What's your background?

sick lance
boreal scarab
#

I guess @glass nest too lol

loud marlin
#

idk what i look at. don't have instagram shit for a start ๐Ÿ™‚

boreal scarab
loud marlin
#

poor kid

fathom aspen
boreal scarab
quiet pulsar
#

Beans

high kindle
#

I can't download packages in wsl kali linux pls help

naive violet
#

Did you apt update?

naive violet
worn thorn
#

got my hand on a prusa mini and it fits too well in it's designated place.

loud marlin
#

@boreal scarab ill dm you smth ๐Ÿ™‚

fair lava
sick lance
naive violet
#

Ah yes, speculation before seeing the problem

#

Good stuff

sick lance
#

The list may be broken, and needs updated.

Pinging Google won't solve broken installs.

fair lava
high kindle
sick lance
naive violet
sick lance
#

You can have an internet conn and still not be able to update and/or install.

high kindle
#

I also can't install or upgrade or update or apt full update and more

#

I'm using wsl

naive violet
sick lance
#

If you add screenshots we can help better, pictures are easier to help.

naive violet
#

Without that, it's difficult to help

high kindle
#

I can't but I can send what it says

naive violet
#

Copy/paste? The full text is the most useful thing for diagnosing the issue

high kindle
#

Wait a min

#

'http.kali.org'
Warning: Some index files failed to download. They have been ignored, or old ones used instead.

#

I can't send the whole it's too long for non discord nitro

boreal scarab
#

Sorry, had games in my messages beforehand lol

naive violet
#

Also you should be able to screenshot it?

boreal scarab
#

SysOps Saga is a thrilling simulation game that puts you in the shoes of a Site Reliability Engineer (SRE), managing the intricate web of software, security, and hardware to keep digital systems running smoothly. Developed by a seasoned FAANG veteran, this game offers an immersive and educational experience for IT enthusiasts.Key FeaturesMaster ...

Price

$14.44

โ–ถ Play video
worn thorn
#

what was the other one about?

high kindle
#

It's in wsl

fair lava
naive violet
#

This guy...

naive violet
high kindle
#

No I'm using a old pc I want to use it as a ai server or homework and maybe just do tryhackme missions

boreal scarab
worn thorn
#

yea

naive violet
shut hawk
naive violet
#

I believe by default it's plain HTTP but yep good step

high kindle
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #14 - 587)

polar wraith
#

completed my ctf pepega

worn thorn
boreal scarab
sick lance
fair lava
worn thorn
knotty pendant
fair lava
#

@high kindle Do sudo apt update if you didn't know already how to do it

knotty pendant
boreal scarab
#

One review.....

"- Tedious tasks - roll out security updates to all nodes while maintaining uptime. Great setup, but given how this needs to be done, there is a lot of clicking involved for a simple task."

#

Anyone wanna tell them?

shut hawk
naive violet
#

It's also the first thing I suggested lmao

naive violet
#

Also any IP changes etc of repos, often they go stale

fair lava
#

Can you teach me more about it

dark frost
#

๐Ÿฅณ

sick lance
#

Hopefully 17.6.2 corrects my CLI issue.

dark frost
#

New linux update?

sick lance
#

No, Vmware Workstation Pro.

#

@lyric forum ๐Ÿ‘‹

lyric forum
sick lance
lyric forum
#

I had questions, but in the end, I was answered, sorry.

small badge
#

how does one even accomplish getting vmware workstation pro everytime i try to download it i get stuck at broadcom login

sick lance
#

It's ok, next time can I ask you ping and ask furst

sick lance
small badge
#

no

sick lance
#

You'll need to create one.

small badge
#

i tried to register for one and something always covers the submit button even using tab doesnt woerk

sick lance
#

Tried a different browser?

small badge
#

ahh

primal kestrel
#

last day of work for two weeks

#

Yippeee

#

they're calling it the least productive day of the year

celest dirge
split plover
#

Hey guys, what's with the legend?

#

Why replaced God

sick lance
#

An announcement will be made shortly.

split plover
#

Ohk

#

GOD was cool tho

grim sparrowBOT
#

:hammer: 3usk#0 has been banned.

umbral bay
#

๐ŸŽ„ ๐Ÿฅณ thm Advent of Cyber 2024 DAY 20 Let's Go! thm ๐Ÿฅณ ๐ŸŽ„

shell nova
ebon herald
#

why NaN showing?

worn thorn
#

it's still starting

boreal scarab
#

Played the sysops game..... my head hurts now

boreal scarab
ebon herald
#

ya...but recently showing like this...I think they update something...thats a little bug

rapid merlin
#

hey

sick lance
#

It's not started yet, so it's Not A Number.

sick lance
chilly veldt
#

Non applicable number

boreal scarab
#

It's VERY thought intensive. Just got introduced to testing environment with 2 new software to get networking to. But the layout.... it's jank. Still have to figure that out. So far, it's good

#

@celest dirge

primal kestrel
#

just wrote a natty python list comprehension

    labeler_data = [
        (
            model,
            os.path.splitext(image)[0],
            os.path.join(labels_path, labeler, model, subdir, image),
            raw_image_dict[os.path.splitext(image)[0]],
        )
        for labeler in os.listdir(labels_path)
        for model in os.listdir(os.path.join(labels_path, labeler))
        for subdir in os.listdir(os.path.join(labels_path, labeler, model))
        for image in os.listdir(os.path.join(labels_path, labeler, model, subdir))
        if image.endswith(".png") and os.path.splitext(image)[0] in raw_image_dict
    ]
#

it's crazy these are like 1,000,000,000x faster than for loops

celest dirge
twin ridgeBOT
#

Gave +1 Rep to @boreal scarab (current: #30 - 321)

boreal scarab
sick lance
#

https://www.bleepingcomputer.com/news/security/kali-linux-20244-released-with-14-new-tools-deprecates-some-features/amp/

For those who need to support older keys for legacy systems, the new build includes the SSH1 client, which the Kali team says is an SSH client frozen at version 7.5.

That's good, SSH1 will stop the need for using oHostKeyAlgorithms and oKexAlgorithms on the some of the older THM rooms.

Kali Linux has released version 2024.4, the fourth and final version of 2024, and it is now available with fourteen new tools,ย numerous improvements, and deprecatesย some features.

boreal scarab
#

@celest dirge This is only Stage 3, oh, and you have a dev to determine if there's a bug in a software, then you have server resources, logs, etc

celest dirge
#

ooo interesting

grizzled wing
#

no email today

sick lance
#

No news is good news.

grizzled wing
#

AoC email scrubs,

#

oh well

knotty pendant
#

Christmas break is today๐Ÿค‘

grizzled wing
knotty pendant
#

Should i make a networking game

grizzled wing
#

default of Python 3.12

#

pipx | pip

sick lance
#

Yeah, there is some near changes in the past Kali of 2024.

grizzled wing
#

" Kali Linux, deprecates DSA keys for good" DSA ๐Ÿ”‘ -> ๐Ÿ—‘๏ธ

#

GNOME 47 and accent color customization !

#

new tools look cool

#

linkedin2username

somber minnow
#

could anyone help me find an iot camera/similar device that I could use to conduct a pentest for a university project? ive had a look and im struggling to find one where the firmware versions are correct.

sick lance
rapid merlin
# grizzled wing new tools look cool

this is a bit unrelated but you showed me the books from Humble a few days ago- bought all 18 today; gonna start on Foundations of Information Security now. Thanks for your recomendation again

twin ridgeBOT
#

Gave +1 Rep to @grizzled wing (current: #79 - 95)

polar holly
#

Guys... Imagine doing THM in a restaurant, due to the awesome wifi, and somebody asks you to teach them the fundamentals... Like dude I don't even know that much, but okay I'll try my best...

rapid merlin
polar holly
#

I gave them a crash course in IP, DNS and http. Just so they can start looking at websites in a different light.

grizzled wing
grizzled wing
polar holly
twin ridgeBOT
#

Gave +1 Rep to @floral charm (current: #421 - 13)

rapid merlin
umbral bay
#

๐ŸŽ„

grizzled wing
#

๐ŸŽ„

sick lance
#

I want to hack, but Kali be like

grizzled wing
small badge
rapid merlin
sick lance
umbral bay
grizzled wing
#

2 more days of AoC right?

sick lance
grizzled wing
#

oh

#

last year was 22 days

rapid merlin
#

21, 22, 23, 24 (i think)

sick lance
#

It was 24?

grizzled wing
#

hmm, oh well

sick lance
#

It's always been 24 + 1 questionnaire.

rapid merlin
#

only 22? i coulnt have known anyways cus i only joined halfway this year

mellow gull
#

I saw a mod say that the 24th was the last day. Do they post new tasks on the weekend?

grizzled wing
#

Gaww is typing awwww

sick lance
mellow gull
sick lance
#

And sometimes random days in between.

mellow gull
#

Interesting!

grizzled wing
#

October is fun event too @rapid merlin

#

halloween

mellow gull
#

I only have two more tasks to be fully caught up. I'm sick at home so I'll probably finish them today.

sick lance
# mellow gull Interesting!

Tuesday is an in-house dev room.

Friday splits between either an in house challenge room, or a community created challenge room,

calm briar
#

Hellooo lovely earthlings - worked abroad for 8 months and left computers behind to save up enough to be able to now study in sincerity . Spent the last two months studying / passing the network +. Getting back on THM - Iโ€™m getting ready for the pentest+ but I have previously complete the jr pentesting path. Any suggestions on rooms , paths , boxes ?

rapid merlin
calm briar
#

I wanna get nasty at report writing . Thinking of just cruising vulnhub for a bit

grizzled wing
shut hawk
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #14 - 588)

grizzled wing
#

would be funny if their AI wrote their technical writing

calm briar
grizzled wing
#

Fomori with the wins

rapid merlin
rapid merlin
rapid merlin
grizzled wing
mellow gull
#

I have a coworker that's absolutely obsessed with using AI assistance for just about all of their filing and reports.

rapid merlin
abstract adder
grizzled wing
#

i use AI , i like it, overall neutral

calm briar
#

Yeah Iโ€™m sure the tests / prep would but fun and difficult . But does HR know about heath and his punisher tattoo ?

mellow gull
grizzled wing
#

๐ŸŽ‰ got THM email ๐Ÿ“ง

rapid merlin
rapid merlin
#

and teh exams are actually affordable

#

not unless some companies

calm briar
#

The pentest+ also adds life to my sec+. The comptia are only good for 3 years and if you get the next in line it adds time to the previous

rapid merlin
#

i like the main TCM guys video, haven't watched one in ages

grizzled wing
#

TCM HTB THM certs all help breakdown the paywall garden the OFFSEC have, that is what John Strand is saying

#

Mayor Malware is typing malware

calm briar
#

I mean the brass ring is still the OSCP no ?

mellow gull
#

A New Challenger Has Appeared

abstract adder
grizzled wing
#

Die Hard watching is soon upon us

mellow gull
#

Best christmas movie ever

abstract adder
grizzled wing
rapid merlin
#

very sadly.

abstract adder
grizzled wing
#

const gr33ting$ = "hello"