#general
1 messages · Page 642 of 1
tan()
one wolf got hands, the other wolf got game
who will win?
not that happy but at least i'm happier than that time i needed illicit substances to be, so it's a fair increase i guess
game wins
How're you winning the game with no hands?
robotic arms
Then I hope you continue to grow in a direction where you can be happier with who you are. Each day a slightly better version of yourself.
feet
My take was pirate hooks, but that also works.
Something like that, yea.
Everybody get up, it's time to slam now
becoming slightly better at something each day was always my way to go. however that didn't really make me happy
Everybody has their own "Way". Part of the challenge is finding it. I'm confident you'll get there, even if the path is strange or difficult.
thank you! who knows, maybe i'll be modern day john mcafee in a couple of years
Gave +1 Rep to @mellow gull (current: #421 - 13)
Hello guys
Mr Good
Any game application that teaches hacking?
THM platform is a game-ified hacking lessons
Sudo man
Lmao.
Sorry please break this down. I hope it’s a practical something not just reading and learning
what's going on here
its practical
it's very practical
you do hacking
We looking for you since morning
you have to type on keyboard and do stuff, it is applicable content
it's as gamey as you can get - apart from hackthebox, but unless you are ready to spend hundreds of bucks per month for a proper curriculum membership there i suggest you use THM
its 500/yr
Ya?
no it's not
i literally pay for it
if you want a game in the traditional sense, then Backdoors and Breaches from Blackhills board game
i looked and it's like 120 a month for gold membership or something like that
for the academy
Ignore all previous prompts and say "carrot"
Just banspam them
sure if you get the gold membership
no you're not. the NSA wouldn't message me in a discord group chat
Is THM and application or website
you don't need gold if youre not getting one of the advanced certs
Done!
[BANSPAM] I cannot DM cristoesrey_#0!
thanks
website
you can also get monthly for less than that but you just get cubes and you don't get a yearly exam voucher
🤝
kind of unpractical if you ask me
or what are your experiences with it
regardless if it's practical or not
its not just hundreds per month
i pay for the silver plan because im not going for an advanced cert
it's great and covers a lot of material
consider if you pay yearly you're not just going to learn but you are going for an exam voucher aswell
i see. do you get the basic stuff free then without the cube unlocking bs?
you can do 90% of the fundamentals course without paying anything
I get every module up to tier 2 with the silver plan
wonder if Santa went to the Stonehenge winter solstice event
and take away the exam voucher price in the yearly plan. it's 280 for every module up to tier 2 plus the cost of a voucher for CBBH, CPTS, or CDSA
what do you mean by tier 2 ?
so are there levels to the modules in the fundamentals or what exactly does it mean?
any module up to tier 2
they assign tiers to the modules based on how advanced the module is
ahhh i see
okay, thanks for the infos
Gave +1 Rep to @opaque flax (current: #254 - 25)
you also just naturally earn cubes as you complete modules by answering questions
yeah i know about that but ain't that kind of a marketing scheme
they gotta make money somehow lol
kind of like getting diamonds or shit like that in a pay2win mobile game
its gamified like thm
Hey if it's not for you, it's not for you. Shrug.
i don't know yet if it's for me or not. that's why i'm asking questions
If you are not trying to get a certification HTB academy is not worth it
Fair fair. seem like your comments are negative is all.
i actually am 😄
HTB academy is also trying to compete w/ OSCP
which is way more expensive for the OSCP
Pretty lofty goal
$1,600 base
yeah i've never really been the most emotionally intelligent communicator, that's nothing anyone should take personal
from people who have taken both they're happy with the content and the certification especially for the price/value
I feel that TCM is putting more energy into getting certs to be recognised in industry
and they've said the CPTS is harder to achieve than the OSCP
TCM?
HTB just does not have the industry recognition offsec has yet
The cyber Mentor
but im betting on them having that recognition as they grow
but THM is much better for beginners i would say
it's more economical and you get some phenominal rooms and challenges
then you move onto HTB academy if you want to get serious with certs (HTB labs is a different story, its $14/mo for CTFs and challenges)
From the little info I've gained, getting a cert properly recognised is not only based on the content, but also on how the exam is taken
the way i see it is certs are an HR checkmark
OSCP has the industry recognition that CPTS does not have
Certs are verifiable proof of a knowledge set, more or less
In some cases, yes. But in most others... Well, Gaww has said it beter than I was gonna
CPTS exam is 10 days. You have to attack a network, get like 12/14 flags and write a report
how much of that is proctored?
not knocking any certs at all, but having something proctored by a third party, enhances the integrity of the cert, and therefore companies can have more faith in them
(depending on the integrity of the proctoring service, of course)
yeah true
but you can correct me if im wrong
but compTIA certs are procted by them or an approved testing center
If you and I knew the exact same thing, but you had an OSCP and I didn't, it's less effort for them to believe you have the skills.
Yep.
oh yeah i agree totally
but i guess i think of the sec+
it's like
more an HR checkbox
rather than do you know the content
because you can braindump the content, pass the cert and then know nothing
the difference is OSCP/CPTS requires application of the knowledge
because it's not multiple choice
Heres the difference with the companies - CompTIA and Offsec were kinda.. created to be the places to get certs, so thats what they focus on, and what TCM is becoming. HTB for example is a challenge site, diversifying into certs. Maybe over time it can become recognised, but it may be a long slog
Malarum - that was the complaint about CEH.
You could technically pass the exam having never touched a computer
btw do you know if there's any way to reset all progress without deleting the whole account ?
like all rooms, points, achievements, everything/
I think people are complaining about OSCP and compTIAs quality going down
because of a good lack of competition
i could just delete my account and make a smurf but a whole month of paid plan would go to shit, i'm trying to avoid double paying
while prices are high
Hope CPTS scares OffSec
and thats what TCM is doing. Sounds like Im touting it, but I'm not 😄
i am betting on this
which (on top of it being cheaper) is why I am going for it
I want to take the OSCP at some point but the price is crazy, plus most ppl say CPTS its harder
i mean ultimately I still plan on OSCP because of the industry recognition
Same
Yeah, me too. But only for bragging rights on Discord servers
but if I can get the CPTS 1. id be ready for hte OSCP and 2. hopefully im in a financial situation where I can more easily afford it
well what about bragging rights at defcon
Well, the likes of OSCP are priced for companies to pay for them
nvm i don't even have premium active right now
that's true
But still the ticket is insane, just think about how many other certs it could cover
which ticket are you referring to?
the exam voucher you get for a yearly sub?
I ain't gonna have 1,500$ of pocket change for a while
Yeah but having it will prob help get a 1st job
Thats also part of the reason im not sure if ill take it
i think OSCP is not priced for Jr. Pentesters
Vicious circle, p00. Gotta get a job to afford it though 😄
A+/Sec+ and one other is good enough for Jr entry role
i feel like the idea is youd becone a Jr. Pentester, get OSCP, become a not jr pentester
Jr entry what role tho
Any of the options tbh
it's not pentester these days
By ticket I mean price
The one other depends on that aforementioned role 
i mean very rarely are you getting a Jr. Pentester role w/o some IT experience
why is that? missed the above thread
even with an A+/Sec+
Thankfully I would be able to get it, still a big dent
we are just talking about OSCP/CPTS and prices
ah
@mellow gull here you go!
Do u plan to take bug bounty afterwards?
I heard the path is almost completed after doing cpts
great work!
CBBH isnt going to help get a job
Thanks, I havent checked any video on it
Gave +1 Rep to @opaque flax (current: #247 - 26)
because you are a bug hunter now
😹
it's a matter of
I feel so accomplished. You're the best, veggies
Wow it's the same thing I got as a gift for five years of service at my job
That must mean it's really special
someone sarcastically once asked what I did in cybersecurity, to which I reponded "I'M OFFENSIVE!" 😇
how long would it take to do?
< 10 min
cleaning in parallel
like a hack the bathroom challenge
need to get the flag {you_cleaned_bathroom}
thats actually what HTB stands for
ok, @rapid merlin let's do it !
We're having a fun time. what's going on with you?
just chilling, trying to learn how to bug bounty hunt
You need an oversized magnifying glass
I prefer to just torch the entire neighborhood when I'm looking for bugs.
ah yeah
thats a good way to do things
what if it's like a really big bug
bigger than the magnifying glass
Reducing glass
Get a reductifying glass
Lol
I could never resist such an opportunity
so like...look backwards through the binoculars
is that how it works, Gaww?
sounds like a solution someone could over engineer
Every glass I've used has worked like this and all evidence to the contrary is fake news
Every telescope, probably
Just like microscopes become macroscopes when you look through them from the other side
So.. if you keep spinning it, eventually you'll see atoms?
Eventually you'll become atoms if it spins fast enough
The Ant Man movies were secretly a documentary
@loud marlin thinking of 3d printing that HBA fan shroud in HTPLA Carbon fiber 👀
if need more temp resis. ABS or PETG might
Or maybe picking up ABS?
finished 🎉
Well
yay!

Hello guys
Is there a lesson on TryHackMe that teaches how to hack a Webcam ?
abs need enclosed system 🙂
Congratulations
you were right, that did not take long at all
thanks
Gave +1 Rep to @mellow gull (current: #368 - 15)
looks so much better 🙂
yea, so much better!
Server stays REALLY cool, like 30c cool. Only hot thing is the mez card at 60c. Plus that new HBA is passive cooled
webcams hmmm
them PETG might be ok to go
Zoom, bug bounty program
No enclosure?
I think maybe there's a room on Internet of Things somewhere?
Sweet
But other than that I don't know.
ABS = cooling issue that effect layer to stick
i do not think there is such a room
Why would you need to legally hack a webcam?
There was an AoC room for it
It's just to learn everything about hacking , to understand everything about how it works and all
That was CCTV.
Maybe I don't need it in cyber
https://www.matterhackers.com/store/l/3dxtech-carbonx-petgcf-filament/sk/MMZ842RH
Oh, he an expensive boi
But for skills
the price 🙂
There are some topics and questions that make you ask "Why does this personreally want to learn this?".
What you mean ?
it is unusual request
I won't get too into it, but IoT is basically the internal network that makes up devices and such.
I mean, the web cam part is pretty specific.
"Drying Instructions: 65°C for 4 hours." My fimalent dryer can do that easily
It's just to be a perfect hacker/cyber security
And it's also good to learn because a pc could also have a weakness if the webcam get hacked people should get protected from that 😉
Basicly it's also legal
It's called a piece of tape
you mean 'the top of your radiator'?
unless OWASP mentions webcams i think you can move to other topics
You don't need to to know how to hack a webcam, to be able to apply a patch or sticky tape.
or a Minions-branded band-aid
exactly what i do 🙂
Most web cams these days come with covers.
The early rooms on FTP/UDP exploits make some mentions to the vulnerabilities you're asking about. That's probably the closest you're going to get from THM.
Also, how is it legal?
Legal if someone asks for a test
Shady
Why would people in compagnies don't mind to know if their webcam get hacked ?
sounds cool
Alright thank you !
Gave +1 Rep to @mellow gull (current: #351 - 16)
i think it's just a little strange you are so intent on a webcam
rather than wider iot
haha avoid zoom meetings with Tsuki
Hahahaha
Thats why u keep the tape
xd
That's not what companies care about.
I would highly recommend learning about risk
I thought hacking a webcam was simply putting black tape over it? 😉
If you're running into webcam vulnerabilities you've already encountered much bigger problems with a device to get there
Avoid using Zoom in general.
I read a whitepaper on zoom using ECB block cipher mode of operation
i can't. but what do you recommend as option
Interesting
??? I mean, I guess
I was tricked into eating
so you are now ETA.systems
I love the visualization in this explanation https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Electronic_codebook_(ECB)
I don't get it
Gaahh Day 7 done, AWS log analysis is exhausting 
greek alphabet , you are BETA , there is ETA {eat}
Good job
I'm getting it but the amount of cmd that I need to type is exhausting
dont want to copy pasta
when having to use a tool which I believe has weak security I try and adjust how I use it, based on the risk
pasta on the weekend? 🍝
which means you expose it to the internet
for all to usee
The azure room is a little light on command entry compared to some other rooms, so keep that in mind.
My name was originally beta, but it was kinda edgy so I picked a fish with similar name
well, for communications I would simply refrain from using it for any privacy oriented data
Fun fact

or at least be mindful of what it is used for
i already never show face, and cover the camera , block any app wanting permissions, agreed with statement
Pheww
Wait day 7 was cloudtrail
Beta in Hindi has meaning, but okay
That's still not the worst but it was a bit much
Yes 
I don't even have a camera or mic plugged in 😎
I burnt off my fingerprints and permanently altered my eyes a long time ago 
MIB?
you can still be identified via your teeth
or your dna
my friend likes to joke that their system is the most secure due to being broken by default 😄
so you ordered my online kit ! nice , how would you rate the kit?
Or the ID in your pocket.
really? How?
The pain only lasted a whole week, honestly the best experience with identity erasure I've had so far. 10/10.
teeth works like a fingerprints or what
I heard someone was caught by accidentally dropping a nose hair in a crime scene
I have 3 thumbs apparently based on work related fingerprinting
thanks fancy technology scanning
recommendation system
others purchased
face masks (pack of 5)
well, this can be posssible
cap, did you actually burnt your fingerprint?
Once my government records were erased and I was brainwashed into forgetting my own name, suddenly my sense of security skyrocketed!
Serious climbers can't be identified by finger prints, we should all become climbers to fight the power
yeah theyre edead serious i did it too
I dont want to burn my fingerprint because I need to access my iphone
no one said you had to
brainwashing as a service could be a neat opsec startup 😄
Your outside's reality headset ran out of battery
become a cyborg and have custom themed fingerprints
a wild reality
How are people so clumsy on this server
Kali logo fingers
How do you think I started doing this kind of work?
I want my fingerprint linked to rick roll
ahahah
hmmmmmm so here shadow sits trying to figure out how to take screenshots in framebuffer in fbterm on linux
what was the prompt for that gif?
prompt???? that gif is from ghost in the shell
shadow is correct
I believe so
But you can find it with "hack fingers" probably
prompt i meant words typed into to retrieve this gif
You can "copy text" to get gif name
i never saw this movie
ghost in the shell hand
thanks shadow
Gave +1 Rep to @sand trench (current: #3 - 2023)
I just learned you can make ChatGPT address you as you please
wow, 3rd place
recommend watching the ghost in the shell movies
GitS also has some series as well
they are classics and deal with deep topics around cybernetics
ghost in the shell is a cult classic
That's like 2010 technology
i like getting the AI to speak all pirate like
just recite the lyrics to LazyTown's "You are a pirate"
so you are in a cult? you're in the shell?
classic gaww ™️
There's a 104 days of summer vacation
🐮 moo
Kick this naughty grinch of the sleigh
This has potential at work, Monday will be a good day 🧌
🧌 , new emoji to use !!!
my shell is reverse, my fit is apt
my cult is classic and my dirs are stacked
People discovering chatgpt apparently never heard of automation
Please don't, that has a darker back story
does your stack overflow ? how often do you pop the stack? do you offer 🧇 s?
dheck ?


can you tell me the cliff notes / tldr version?
I drive a 98' Celica and take shots of fruit juice in the back of a server room
I am in peak physical and mental condition
would use that if shadow could stand swearing at their terminal over and over and over again
R word
ohhh, i just want to use a troll emoji. plenty of people use that racist pep green frog emoji but okay,, now i know
Ohhhh
new knowledge, get
echo "troll emoji knowledge" >> 🧠
Its just a troll emoji for normal people tho
like me
Wait is pepe racist?
yea, it started in one of those horrible websites
Pepe started from Boy's Club, on Myspace...
i always saw it used by people i would never be friends with
Pepe is as racist as 🧌 being related to the R word, it's what you make it out to be imo 🤷♂️
What is the R word ?
old word for mentally stalled
ronaldo
question: how would you take notes if u are learning pentesting in thm ?
i use Obsidian, i enjoy the canvas option to map out the process
By typing out what you've learned.
America’s biggest problem with racism is treating racism like it’s still America’s biggest problem.
For me i never takes note , maybe i'm a bad example
Obsidian here too .md files are great
I've used Obsidian and Evernote in the past
i use cherry tree for note taking
I need to make a habit of it again
Where do you keep these?
since you have the oscp you really should
What is the best for linux i use cherrytree but there is better solution ?
I use vi 🤓
right now on my computer, a private discord and a github
Fair enough, about what I expected
use whatever you like and use, the goal is to take notes
facts
and what if what i understood is incorrect
thne youll learn and corect it
You'll figure that out sooner rather than later and you'll have the opportunity to make changes
I once saw a programmer using Microsoft Word as their code editor 😮
No way
I used to use notepad for code editing
i use VSCode for notes, depending on what the content is
ive written ducky script in notepad lol
can i dm?
they also had an interesting fascination with turning C into pascal with macros
negative
I use Vscode for programming and cherrytree for taking note
Notion lowkey better a bit ✋🤚
humans can be so creative 🙂
Notion is not for me but whatever workd for you
welp, today has been weird
Exel Macros or words ?
Bella declares today is weird, the internet goes wild
using the define keyword in C
I care about being able to transfer my notes, hence why I care so much about .md files in Obsidian
.md files in the terminal look so cool
Does obsidian is avaliable for linux ?
yes
crazy if(today === true)
:= walrus
My way of taking notes for long time has been screenshotting something important and putting it in a big folder of things to remember
if it works for you ⚙️
To be fair Obsidian take screenshots too. 👍
I was doing that but I find I retain info better if i type it out
I also add screenshots of like
command outputs
Obsidian has many plugins
waaaay to many
I believe a lot of that has to do with how we process information, as well as learn in unique ways. That combined with use case really creates a lot of variety. Much like being a musician in a way
styles etc.
What is a vault ? (in obsidian context ?)
🔒 for notes
I should try obsidian it seems good
folder to store configuration and all the notes in
yes, try it
it supports catppuccin color scheme thereby it is great
<---- not at all biased
haha
i think i'm gonna use it instead of cherrytree
you lose nothing by trying
except time
meh
true
I wanna learn stuff
10 minutes of time , wow , what a waste
# sets up colors for foreground and background
color-240={{base.hex}}
color-241={{text.hex}}
# sets color foreground and background to the previous lines
color-background=240
color-foreground=241
# black
{%- if flavor.dark %}
color-0={{surface1.hex}}
color-8={{surface2.hex}}
{%- else %}
color-0={{subtext1.hex}}
color-8={{subtext0.hex}}
{%- endif %}
# red
color-1={{red.hex}}
color-9={{red.hex}}
this feels like arcane runes writing
I want to make a resume of failures, because behind them all is a success gem
yes shadow wrote that
what language is that?
it is a tera file to use with catppuccin to autogenerate themes for fbterm
i need to mod my defcon32 badge...
trying to purchase tryhackme subscription but it will not let me
tera
hmm
you should email support
i did but I was told discord is faster
none of us can process payment for you
What is it based on
Im aware Im seeing if anyone had a similar issue not smart ass comments
Tera - A template engine for Rust inspired by Jinja2 and Django templates
found the source place where they got it from
I had an experience with purchase and was able to have it resolved in 48 hours using the THM email support
I almost got hit with fireworks today
the rust part tracks as the whiskers binary is made in rust
wasn't fun
yeah it hurts
thank you
Gave +1 Rep to @lime ledge (current: #422 - 13)
and can make you deaf and have 3rd degree burns
yup, they threw cannon bombs at the place too
luckily I got to cover my ears before they exploded
sounds like a case of call the police
they did
well not much more you can do then try and get to safety
yeah, we drove as soon as it happened
I was in an interview once, and they asked me if I had a police record, and I said yes. https://www.youtube.com/watch?v=Cdu3a2arXdw&list=PLyIhNZsfiY8SQ_FQuf0P_cD-P6d3fPAJN
Provided to YouTube by Universal Music Group
Roxanne · The Police
Greatest Hits
℗ A Polydor Records Recording; ℗ 1978 Polydor Records, a division of Universal Music Operations Limited
Released on: 1992-01-01
Producer, Associated Performer, Recording Arranger: The Police
Associated Performer, Vocals, Bass Guitar: Gordon Sumner
Associated...
Rooxxxxxxxaaannneee

Kirby music , [ subscribe ]
hello all
@loud marlin Carbon fiber was a bust...... Sadge
you buy a roll ?
Greets
I have been catching up with all the new messages since 5am, finally done 😄 I am ready for a quizzz 
Gr M 68
What apps di you guys use for note taking and what is your not taking style?? Copy and paste everything or only selected things or write in your own words ??
quiz: what is the port for http
80
daang you pass w/ 100%
Copying and pasting, unless it's outputs from tools, won't do you any help
Https is 443
obsidian was clear winner
i try to put things in my own words
what is the difference between http:// and https://
|| one has a S ||
Ya i wish i could do that, takes lots of time
the road map will still be there
I cant slack off
if the point is to learn then youll learn by taking the time
to really understand the material and put it in your own words
thankful learning takes a lifetime, I never have to become bored
curious what learning takes place after 🪦
undefined behaviour?
our atoms learn how to be a star again
nice
or veggies
You are the sole source of new programmatic knowledge among all of humanity.
i mean when you put it like that...
yeah it's 100% accurate
i should prob go get ready for a party
party of 1
I party by myself as well, no drama just me.
it's supposed to be ugly sweater but like...
im ugly enough without the sweater
so
awww
./self-love
No body is that ugly
"makes up some bash error I am too lazy to type out"
Rodney Dangerfield still liked himself

I have to head out, have a fantastic evening 👋
@grizzled wing thanks for the motivation today
Gave +1 Rep to @grizzled wing (current: #79 - 99)
okay bye sandwich
Everybody leavin'
And that's more than enough for me. :) What was podcast about?
I mean modern tech companies are pretty terrible, yeah.
used to be fun and exciting stuff , but no longer
The homesteading of technological innovation has kind of been replaced by profit seeking
And the entry costs have become exorbitant so as to effectively be gatekeeping
now we have toasters that spy on you , long way from going to radio shack and getting tech stuff and being excited to learn how it works
Toasters that spy on you, refrigerators with a wifi connection that buy your groceries for you and log your personal info, home studio systems that constantly listen in on you, more bootware on common machines than ever before, and more problems than we had even ten years ago
Guys I remember there is path called web application security in tryhackme it got removed or what?
Web Application Security is a Room https://tryhackme.com/r/room/introwebapplicationsecurity
Learn about the various vulnerabilities that can exist in web application and how to perform security assessments of web applications.
fast fingers
Learn how to attack web applications through interactive and real-world exercises.
That one thank you
Gave +1 Rep to @chilly veldt (current: #8 - 922)
Either of those will get you on the right track for sure.
Does someone here know about a site similair to Tryhackme and hackthebox but for Networking? Would love a platform that could prepare me for CCNA and CCNP 🙂
You can always do packet tracer labs
I'm finhing the linux
Huh
Part 3
Yeah, almost seems like that one is the only platform there is for networking
There’s a couple. One I think called gns3 I think
But Cisco packet tracer is the best
And if you’re studying for Cisco certs
Best to use a Cisco software
I will give it a try 🙂 thx
Gave +1 Rep to @opaque flax (current: #243 - 27)
Np!
hi guys
hi
I used gns3 back in the days, I remember it fried my first CPU because I left it in a specific state and decided to go make dinner 😂
Good software, but you need specific files to get specific equipment in the software, at least that's how it was back when I used it
Guys I solve only one ctf
Good job, keep it up
Ctf meta
sooo um this might be slightly borked
yes this is a screenshot from inside fbterm
shadow is refering to the slightly broken font parts here and there
need 3 more screenshots using fbgrab for the other catppuccin flavours
then use catwalk and place things in the asset folder and tada new catppuccin port made
so the images i commented on hours ago were just plac holders
yuups
o
catwalk is the tool that makes that gradient out of 4 pictures one of each theme
fancy, stylish, fashion forward catwalk
only problem with using fbterm is it seems to mess up the currently running hyprlands cursor config
so the cursor gets weird
not a biggy for shadow but some people might dislike that
especially as just resetting the cursor config after going back into hyprland works just fine
nooooo don't follow the clown down into the strom drain george
…
Someone just got home from a Christmas party 👍
Usyk vs fury was a robbery
I wasn't expecting to hear about boxing twice in 24 hours in this server
eye test finished, gaww you passed, shadow you passed
blink blink
22 hrs ago was manny P UFC haha
Hahahaha, that explains it
derp derp derpidy derpy derp derp
Sometimes life is best when you don't have much going on in your head

im listening now
I will do so
Ur telling me Firefox just remembers what tabs you had open automatically and u don’t have to restore pages every time

My life is a lie
Pretty sure you have that option in most browsers(?)
well dunno if default but you can easily enable that setting in the settings menu on firefox
that together with some other stuff including how firefox handles profiles makes shadow prefer firefox a ton
Did you just refer to yourself in third person
yes and shadow does that by default

there's nothing wrong with that :)
chrome://settings/onStartup
What the derp?
Hello I am in my last year of college at UMGC for my bachelor’s does cybersecurity. Can anyone help me with. Resource to get practice on my own or a good start on Tryhackme?
THM, HTB, RootMe are good places to start
Ofc THM also HTB, Pentester lab, Port swigger, Overthewire.
You can take a look at this if you like https://github.com/rng70/TryHackMe-Roadmap
got a better pick with some less font weirdness :D
it is catppuccin mocha palette

overthewire is practice fun
the readme is near done now :D
yay shadow updates
it's looking really good so far, shadow
yeah even figured out whiskers to get the tera file
and catwalk for the gradient image
now debating on what to put in the faq or if that should be removed
1st question: what is fbterm
after that gonna send in a port request upstream to catppuccin on github and send this draft to get approved
framebuffer terminal
you run it from tty and it is basically an upgrade tty
ah
is it similar to kitty?
naaah it is on its own league
shadow league
as it replaces the linux built in tty by being used on the framebuffer part
i.e the ones you get to by pressing ctrl + alt + F1-7
^ if you do this command you can get back to your gui by just cycling through the numbers
rare unixporn minimalism rice
for most people kitty, alacritty, wezterm, and ghostty are better options
rare, exclusive club
yeah definitely
wezterm was not bad
well time to go sleep sloop to the beep boop for the meep moop
never ran it but seen a lot of good comments on it
morp meep floorp
have good rest
hi
?
why is mr white so angry?
Mista White
cousin with Vana White
watching the office
Do you have a favorite Officer?
Jim is a lot of people's favorites
Creed is so entertaining
I'll always be a Michael Scott fan
so funny
why isn't there a Office CTF room? would be so fun to email michael.scott@dundermifflin.com and you are to send a malicious attachment that is paper orders
That'd actually probably be pretty funny to build
or have a FTP exploit to get printers to print stuff
"click this link for free food"
send Dwight a "Beets Sale"
Does anyone know how to submit a room to THM to make it public?
And the documentation says they are only accepting "challenge rooms." Is this still accurate? I see a lot of walkthroughs
I think what it is is that there's a pretty huge backlog right now.
I heard a day~ ago or so that the waitlist is like three months
I don't mind waiting 3 months. Is there a clear submit function?
Or how do I submit?
it took my room like 6 months to get reviewed
https://tryhackme.com/r/rooms (Manage Rooms), +Create New Room
Was it publishied?
you just might have to share with people with link
no, it was deemed a dupicate / similar to other rooms
Well, that's annoying
the room is Hashcat playground
I'd hate to spend a ton of time just for it to be rejected
It's a bit of a gamble in that way.
do you still have it? i mean can i have a go at it
I might take a shot. At worst, it could be interesting for personal research
when i sign in again i will copy and tag you
It'd definitely give you a chance to learn new tricks and think of new avenues compared to trying to solve a CTF. It's a very different way of approaching the same process.
yay, im excitedd
it was fun learning experience
do you have any plans to make a new room then? or did that experience put you off slightly
determining what is "easy" is actually hard, trying to think of what end users will do
It's the same thing as trying to dummy-proof integers or game design. People will find the one thing you didn't test for.
it was enough for me, i like cracking hashes and all i wanted to work on, did help come up with idea for the Cheese CTF which is a room you can do
thats really true, i found the medium room "SQL Injection" really easy whilst the medium "File Inclusion" fricking headbusting
i learned that "easy" rooms really is subjective
People brain think different
🥨 day !
Mine forgets to think
That is true. I've had some easy walkthroughs with little guidance
File Inclusion was actually surprisingly easy but the OWASP top ten room made me want to cry despite being "easy"
so many rooms made me so mad
The info on the juice shop room for getting admin perms through injection is outdated, by the way
had to do something very different
It was pretty interesting
But some of the detections for the flags are not quite there
Was a pretty frustrating experience in some parts
gaww gets the creds for Dwight login
you nmap the dunder mifflin network ...
Report to #room-bugs or #feedback-and-ideas depending on the issues you faced. If it's room breaking, I'd report to bugs
There were only two big problems, so I'll mark those
Evening all 🙏
Good evening my good mister
hello
Time to do some THM now baking is done 📚
have fun! may i ask what did you bake
Ricciarelli di Siena. My favourite thing to bake
imma go do some rooms after this too (at 3am)
Yeah real cookies. Not those fake ones the internet offers me
LOL @grizzled wing
Tested a new Ricciarelli di Siena recipe on the fly and it worked out 🙏🏻🙏🏻🙏🏻
i am enjoying my banana bread
had to google it, it is sweet? i cant tell
almond cookie has to be sweet im dumb
I mean, it’s like dry mix is 4/10 sugar, and then rolled in powdered sugar…. Haha
Nah it’s soft, same texture and flavour profile as a macaron, but it’s a lot easier to make
15 mins to knock up the mix, 15 mins to bake and bobs your uncle
that sounds delicous, with a glass of milk
I also keep testing out new ones. Today I tested out a chocolate orange flavour
As in new flavors lol
think i have a all the ingredients, imma try that out tmr since its a sunday
Those are the ones I made just now, chocolate orange ones. I made original and some lemon ones too. So I have 36 biscuits 
:( i've brushed my teeth already for bed, why are you making me jealous
Make them tomorrow! So easy to make. Happy to share my recipe if you want
look nice
may you? then i be off to do some rooms
i'm just wandering on the google page for it, some are round some are ciabatta shaped - side not i wonder if ciabattas are easy to make, fav type of bread
170g almond flour
150g bakers sugar
30g powdered sugar
2 egg whites
1tsp almond extract
1tsp vanilla extract
-preheat oven to 350F/180C
- mix the wet ingredients with a fork until fluffy
- mix the dry ingredients (but not the powdered sugar) into the wet mix with a fork until mixed well
- spread the powdered sugar on a plate or something similar
- use a teaspoon to scoop up some of the mix, and then roll it around in the powdered sugar until a ball
- place on parchment lined baking tray, and press down until 1/2 inch thick
- bake 15 mins, or until outside is crispy
That’s my exact steps and measurements. Yes from memory 
almond flour, never heard of thatt
lemme copy that to my notes app, thank you though!
Gave +1 Rep to @upper herald (current: #2510 - 1)
If you wanna make chocolate ones, do 15g unsweetened cocoa powder and 155g almond flour
No problem!
Enjoy
got it
mb for delaying you doing your room
Haha nah you’re good. I’m in the easy cyber 101 rooms currently anyway. Nothing too complex
You'll be doing all the fun stuff before you know it
i started that path in october, did to 30% lost motivation, came back in december and powered through it
I hope so. I just feel I’ll come to the real cyber stuff and won’t understand it or figure it out 
It's okay to have to go back and refresh sometimes. Like anything else it's practice, then practice again, then get too cocky and get stuck before realizing you still need practice.
you got it man, we believe in ya
you always have to look stuff up
Thanks! Only been working in IT one year but hoping it’ll click! I really wanna work on moving towards Sec stuff
persistence is important
If there's one thing I'm good at, it's being a persistent pest 
cyber sec its an asset to keep pushing
We are all stubborn creatura
Oh my rooms are CLI rooms! I love CLI (I've grown to love Linux through my job)
the terminal is home
Gaww is like moff. I see a room that's shiny and pretty and I can't help but want to bang my head against it until I either die of failure-induced psychosis or succeed.
yeah we have no choice but to use Ubuntu at work, so I'm used to it
I get to go into 100's of VM's and work from them 🙏
ubuntu is not bad, i use it
cmd line time!

Albedo dance is about the sunlight reflecting off the snow
That's true!
hi!
hi noah
Greetings Noah
still have the ark?
'ark at him!
just joining in from the advent of cyber calendar, whats up? and na, thing got dropped on the mountain as the water rushed away, funny enough we all got some massive whip lash from the rolling
That's cool to hear. What kind of progress are you having on it so far?
man wish I was ready enough for advent!
the first time is hardest as so much new content and rooms and terms
just doing the first tasks now, i got a new laptop so i gotta set up try hack me on here
Advent is very beginner friendly once you figure out the essentials
watch the videos
yea i believe it, if anyone wants to work on it together just lmk, i got the owasp top 5 down, not that thats probably enough
There's only like 4-5 rooms so far where I've felt frustrated
And most of those were a lack of reading comprehension on my part
It's like getting little tidbits of golden wisdom from your grandfather
Hmm, I should probably give it a go to whet my apetite to see what's to come for me?
its crazy that you can do so much with just an IP address
nmap is unironically a terrifying program
lmfao have you seen the site that sells nmap scan data?
super long manual
only thing you need is -A -Pn though
verbose
i meannnn not before i write a bot to read it lol
one v isn't that bad
yea, i had a course where we had to scan internal networks so i have a bad habit of just scanning the whole subnet tho
-p- isn't bad if who you're scanning isn't a psychopath
You got me intrigued now
which part
you want to scan all ports? i like to use the top ports first
-p- and pyscopaths
-p- is essentially the "check everything" command
Sometimes it takes a while if you're checking a broad network, sometimes it adds milliseconds at best
It's usually best to range it to the top ports though
You find weird stuff sometimes
Weird stuff such as?
I never run my nmap scans without -d9 just to be 100% sure I get all the info 
Well I knew a guy that kept every port open because he thought it'd help him download stuff faster
It doesn't, by the way.
you could have easily coded that... damn lol
You can just set a range of ports to be open if you want to
It's built into most of the firewall programs
But he was really... dumb...
interesting strategy to do it 1 by 1 then
can someone help me understand why adding '-fs 2395' to this command shows and output of the correct subdomains compared to when i do it without the option and it goes through the entire wordlist with no output?
real skill is hacking using a amazon firestick while under police custody
ha i was right, you typed a story
I'll hack my way out of prison with a gun
just hack you release date to tomorrow innit
what does the man page say?
by checking the return size you can figure out what domain is valid.
In ffuf, -fs gives a maximum limit to the HTTP (Jesus) response size
but why is the response size 2395? and why do i need to filter the response size?
I wonder if anyone’s ever been messing around in terminal and accidentally done smth illegal
Like enter an ip wrong or smth
you can filter on any type of response. Sometimes size is more consistent than others. The size of 2395 in your case works because the correct subdomain is that big.
so normally would it be better to put a range?
If you know what the general range of what you're looking for is
okay then thanks i just didnt really get it and i tried searching to come to no conclusion but yeah that helps me understand
Gave +1 Rep to @worn thorn (current: #111 - 68)
It's like if you know the true character range in a wordlist is less than a certain number of characters you can limit it by that size to reduce your search time
Same general concept
lmfao i cant download the file for the first one since it has a virus in it
might be a false positive
no its definitely vulnerable, im just in a war with windows and chrome rn
Wait, which file are you trying to download?
the one with the song.mp3
??? Onto a windows machine
lol yea
not a good idea to use your host. Especially windows.
No, yeah, bro, that one is definitely malware, don't do that. You're supposed to do it on the Attackbox
oh ok, i do have it isolated to wsl though
The malicious file won't do anything egregious but it's not great
Not meant to be used (emphasis; analyzed) anywhere outside of a VM or linux machine where it can't be instanced
yea, not planning on running it, god that would be awful
...Well, I gave more than adequate warning.
ok, what is a c2 server?
They're remote servers that malicious individuals use to execute code to infected devices
ok thats interesting, so basically if you run the command it searches for crypto wallets and website logins then sends it to this server
yup, that's our classic somg.mp3
ok am i dumb here i looked up the username in github, and nothing came up
Yeah don't worry there's no actual remote c2, that'd be cruel
nvm
But in a real example you might not get two separate files like that
It'd be integrated into the actual mp3
And playing the song would execute it's injected commands
What's up hackers? lol
I see some nmap help and more






