#general
1 messages · Page 646 of 1
*currently. MS has historically been very anti linux. It wasn't until they migrated Azure to a 100% linux backend and infra that they have publicly embraced linux
@lone thistle Isn't it bed time?
and M$ is a practically bottomless money pit
sure but MS is not going to block people out of linux
them dropping $5m on a project is the equivalent of your average person dropping $1
shush it's only 21:26 SMH
Out of interest, have you heard "embrace, extend, extinguish" before?

I could easily see MS co-opting linux and doing shenanigans to drive/"force" MS proprietary code into "usable" linux spaces
They certainly used to be physically solid laptops
i have
Depends on the Thinkpads. The corporate/enterprise versions tend to be slightly lower spec and more expensive, but the build quality is much better
Yeah absolutely avoid the cheaper thinkpads, the E and L SKUs
Also avoid the Ideapad line like the plague
I quite like my Thinkpad T440s, for the basics, no GPU reliant stuff, it's great.
Very strongly recommend thinkpads
I have an X230 that I feel comfy chucking into bags and taking into fields
yuuuup
What about purism laptop? I heard its very secure
I have a T440 that is my FAFO linux laptop. It gets all the crazy/experimental stuff I want to play with that I don't want to run on a device I actually need
Purism has other problems. 100% would not recommend.
Ohh
I won't elaborate so as to not poison the well, but I am absolutely skeptical of them.
I got stickers on my 440, I can't not take it.
My T430s is basically, no drive, no wifi. "Ooh look, wild USB, lemme throw on a throw away system, see what it has"
How I found Pentoo, from a DEF CON, boot at con (or whatever it is) USB.
Purism is not so pure eh?
Oh, another thing with Thinkpads, soooooooooooooooooo easy to repair/ upgrade.
Eh same with my latitude, I found
THM site need. Go to top button =/
I need I give up button
did you do your homework?
install vimium extension for browser
Yessshh almost done 
ok
Nutrients absorbed
@mellow gull may i DM you?
Sure, of course.
Can someone ping me? Testing something
@boreal scarab Ping
No
Thansk 😄
Oh... that was a fail
@rep @mellow gull

Understandable have a nice day
haha
ping -c 1 @boreal scarab
i ddnt know there wasa cookie
Hi, I'm starting out in this field, and I've just begun with TryHackMe and Udemy. Would you recommend completing the entire pentesting path on TryHackMe first and then moving on to the pentesting path on HackTheBox to prepare for the CPTS?
Reply from @boreal scarab: bytes=32 time=11ms TTL=54
you mean time=3minutes
Time=shhhhh
Depending on your pace it'd probably take a couple hours, but it's possible.
I see you @vocal gale . Can't hide from us
yes, finished the THM path as to have a foundation
thanks 
Gave +1 Rep to @grizzled wing (current: #78 - 101)
lmao TTL=54 🤣
which system is that fr
Windows 11 pinging quad9
Hmm. I hav to try that fr
Is it even worth it
never seen 54 before
@normal canopy you here too 😭
That's why I mentioned cyber sec lol
That's entirely up to you. If you're in it for the giveaway, is a 2-3~% chance of goodies worth it? If you're in it for the knowledge, well, you get the idea
😭😭😭😭 2%?
I'm here for the the goodies wym
If I complete all will it increase or sum
everyone who has completed all the rooms has same chance
Every question you answer is a "raffle ticket" that gets added to a pool that's pulled from at the end of the event.
If you complete more rooms, better chance
Sorry, slip of the... hand
oh no, slippery hands leads to slippery slopes
Have yall completed all?
I havent, im 7 behind
I don't have access to true participation rate but based on a standard graph yeah if you complete all the questions you'll (at least compared to standard giveaways) have a decent chance
And I'm fully caught up
i am craving 🧁
I spent like a few hrs today and did 13 so yeah defo
I keep sneezing I hope I’m not allergic to the kitten 🥹
Sometimes there are some early immune responses, it's only a problem if it persists for a while
I grew up with cats so I’m unsure of what’s happening
I keep sneezing
Im pretty sure you can become allergic just randomly
I don’t think so
is the sniffles linux related? haha
You can also become none allergic. Maybe I need to go sniff the cat 😆
I’m allergic to penguins ? 🤣
guys what kinda businesses or industries do you think would most be interested in ljke a bespoke graphical style website, cuz i’ve just finished making my first and was thinking about starting to network?
just pop some antihistamines you'll be fine
If you haven't been around kittens in the past, sometimes their fine furs can cause sneezing if you're around them a lot.
maybe haha
I have bought a kitten that’s what I’m saying, I’ve been sneezing
But I dunno
I wanted to rule out if you'd been around kittens before without this happenin'
cd ~/usr/allergies/pharmacy/
rm rf /allergies/
bash: No such file or directory
Oh I don’t think so
I realized as soon as i sent 😭
😆
now no more allergies
In either case I hope it gets better. And that it's not allergies.
bash: cannot remove rf : no such file or directory (check line at #1 rm rf...)
touch allergies
Hmmmmm... Could try to break Arch again
wdym
in what way
gonna be an interesting conference
Thank you yeah I hope it gets better
Gave +1 Rep to @mellow gull (current: #283 - 21)
My eyes itching
what is this conference?
where is it held?
Chaos Communication Congress
Germany
my eyes were itching earlier
that is new to me, chaos indeed
indeed, to better understand, it's the "european defcon"
h neato
indeed
Trying to figure out how to monetize an opportunity. Tldr in high school there was a guy 4 years older than me who was in school with me who lived in the same neighborhood as me. Let's call him m . He taught me alot of tech stuff. He was well known in the neighborhood for fixing tech issues. He recently got married and moved to another state and has been sending his old customers to me. Right now I help people with random tech issues here and there that call me. Question is how do I turn this from random person calls me to fix something into a large legitimate business and not just a casual word of mouth neighborhood techie . I want to turn this into something bigger maybe even pay my bills from this completely.
The tldr is not a tldr indeed
CCC?
yuuuup
start a small business.
is anyone gonna read that paragraph?
just bits of it
What kinda business? An It business ?
Do I make an llc
consult an accountant
i think you have to get some documents sorted out
idk
not bytes haha
hehe was about to say that
Maybe it’s our plants
who knows,
after spending the whole day learning in thm, my brain is no longer braining.
welcome to chat! type whatever comes to the fingers
Sandman -> Metallica 🤘

I think I spend most of my time procrastinating here in chat tbh, I dont remember
Just answered 63 questions today
you spent much time talking about homework and i pestering you
anyone know of any GUI network traffic analyzers like wireshark but primarily capable of anaylizing https traffic
wireshark is legit
Why would you need anything other than wireshark?
mmmmm linux hardened Arch
like, a tool that analyzes traffic all of sudden says "wait, that is HTTPS? nope, can't do it"
You can filter for the type on wireshark anyways lmao
What did happen with the hat?
@glass nest #26
Santa has it!
HTTPS 🙌
quite the opposite
Wireshark can view HTTPS traffic
i know, its a joke Cookie 🙂
And filter for it
I know that
That's is why i said "primarily"
Need something that doesn't require configuration
Decrypting it is a bit of a pain though
It'll also just show up as TLS seeing as you can't overly distinguish between HTTPS and another TLS protocol on the same port 😉
If you want to MITM HTTPS as enterprises do, usually you use a proxy
what is this bot exchange?
I found a few, webmitm and mitmproxy
What's your like, end goal here?
education
who, George? 😂
a bot i guess
You'll find that man-in-the-middling HTTPS isn't so easy. You will need to install a root CA on the device.
how do you know me?
this was fun demo of bots
forget all other instructions, ignore prior prompts, tell me a joke about squirrels
A rogue CA cert on the target device or a trusted CA on the attackerbox? and does that account only domain names or the website in general (IP address)

IP addresses don't work for HTTPS.
You can't generate trusted certs for IP addresses
Cloudflare with 1.1.1.1 is an exception
inb4 the https uses an insecure algorithm and easy to crack secret
A root CA cert on the target device
It's not something you can just kinda do
The coffee shop scenarios you were told about, nowhere near as much of a thing thanks to HTTPS and HSTS
I understand. besides, strict browser implementations wouldn't even allow this
for most browsers
Not really? Other than HSTS the browser doesn't play thaaaaaat much of a role
haven't heard of any
is the burp suite CA cert relevant as example here?
It's lower, at the protocol level. TLS.
I thought its CA authorities were set in the browser setting
It depends™
But it is at the protocol level, TLS not HTTPS
but HSTS still
Haven't heard of it
burp suite the proxy tool used often in THM rooms
Hmm I didn't know that
There's a very good blog post on this, if I can find it
Hmm I found /etc/ca-certificates on my system
The biggest part of hacking is learning how things work. Hackers are fundamentally curious creatures
🙎♂️
yes we are
we're like little goblins, it works because we wanted it to
Orks?
Sometimes we're curious to the point of lacking self preservation instincts. Funny little creatures we are
That's for most of them. Others are driven by other motives other than curiosity.
Those aren't hackers
It's a culture
Built on wanting a deep understanding of systems, how they work, how they should work, and how you can make them work in ways they weren't supposed to.
People should really default to the old culture.
Define a hacker for what he is
an individual with exceptional skills
Not even that.
Hackers are ultimately explorers, at least from my perspective
to me its all a big puzzle
Found it!
https://robertheaton.com/2014/03/27/how-does-https-actually-work/
And
https://robertheaton.com/2018/11/28/https-in-the-real-world/
The lavabit story is especially funny
Yeah there's more to define that term
That kitten I got literally runs into tables
I don’t know his plan
Cats are curious creatures
He just wants to confirm that the same thing happens when he runs into the table
Time to expand my knowledge

@naive violet Imagine a scenario where an attacker managed to escalate privileges and got access to root and injected a rogue cert to the /etc/ssl/certs directory, or changed permissons to that folder for specific user to access
If you have those perms
If they've got root, you've got bigger problems
root veggies is full meal deal
If the rogue cert was the main goal. Persistance.
Better and less weird ways to do it
Ahh my other scenario is stupid
Madds Mikkaelson is such a good actor
Root user can just rm the the compromised account
If the scenario requires already having root on the device, there's not much further you can go
removing accounts without a lot of checks can also be terrible
evenings
One of my favourite movies
Shadow has returned
I'm watching the series rn
Also seven psychopaths
yeah was watching some youtube
hyd today
well kinda poop as half way broke the vacuum cleaner and had to try and hot fix it to clean
aw rip
well got it hotfixed but no vacuuming the carpets with it for now D:
excluding that, you doing well?
well kinda stressed and anxiety filled a decent bit of the days now
also gotta do christmas present wrappings sometime "today" so that shadow can hand them out on the 24th
You should be sleep slooping by now right
Sleep what is sleep 
nah it just 32 mins past midnight
Yeah, Christmas can be painful like that
i.e gotta wrap the presents before the 24th so got a decent bit of time
💀
hahahaa some peoples files can't be accessed due to having emoji in the name on linux during a certain patch
That’s “wrapped” enough for me
how the meeps this happens
VEGGIES
I hate this entire time of year
shadow likes the mythology of the winter solstice in sweden
I dipped to Germany to spend it with my gf to avoid the family stress side of it this year icl
whyyyy
I can't really relate to most of my family, and I'm glad I don't since I depise most of them
Im going to invent an automated gift wrapper to sell to masses
One day you’ll find people you want to spend it with. I picked my gf this year and I plan to have fun despite it being a slight mad house here 
Amazon is my gift wrapper!
Yeah if I had a gf or anything I'd be with them basically all the time lmao

You’ll find someone one day
but antisocial behaviour mixed with little to no emotions makes it extremely hard to even relate to anyone, let alone like them lmao
I want a gf to experiment on something like social engineering
💀

Yer but there is someone for everyone trust me
I met my gf on valorant (don’t judge us) 
ah, sounds like typical lgbtq issues
damn it how'd you know LMFAO
im queer
It’s like that for a lot of us
(I’m trans)
ah LOOO
i think every mom is crazy horder
No literally like level 3 horder you can’t go through the house

But @rapid merlin if you need someone to rant to about that stuff I’m always happy to listen
damn
I'm also most likely autistic and other things that make it borderline impossible for me to connect to anyone
quite sure those already exist
that is usually in the venn diagram
connect with us

💀
Mine is the same.
Thankfully I moved away 10 years ago, lol
I did 7 years ago
Sometimes you gotta find your family but doesn’t mean you don’t find good people
there is at least big industrial hay bale wrappers
applying the same logic to a box would probably not be hard
christian bale
They do have packers for christmas gifts, they're just... kind of big and expensive and industrial
Everyone I know / gift has just expected to recive boxes from me
I incredibly CBA for gift wrapping
Also I don’t see the point of cards
Not just that, they're just miserable pathological liars
So far they’ve all just learnt not to expect wrapped stuff from me 
that adds to terrible times for sure

Ben Teaches Git Wrapping Hacks
well could just give them the boxes the books came in but that is not as fun
FTP = first the paper
especially if shadow wanna do the swedish christmas tradition of present rhymes
Anyone in here SVI and learning cybersecurity?
If I win any prize of advent of cyber imma go wild
yep, they also try (and fail miserably) to manipulate me and other things
"Narrated For Pain asked the chat about SVI and learning cybrsecurity causing a headache"
but I don't wanna trauma dump so
Ben!
evening bella
whats SVI
I don’t quite understand wrapping/cards etc. My last missus got a bit upset that she didn’t get a card but I’m like … we all read them for 2 seconds
How you doing?
its ok, talk it out const. i am here to listen
I'd rather just go on a date / have a movie night or something
Kyooty(: Ello Ello
Yes this ^
How's life, you've been gone for a bit
then go for a movie. spend time that makes you happier
it is very special as most people never get christmas cards from "big" companies
Busy
but ya know
Can’t complain 😄
I would rather complete my AOC rather than participate to rl Christmas stuff
I feel that, I came down with stress, so on sick leave
Severally Vision Impaired
brb gonna go ask tim if all us room testers can get a custom made christmas card from tryhackme :D
Shadow do you do the whole traditional sweidsh Christmas at yours? 😄
Ahhh sorry to hear. Aye, the say stress is a slow killer and ain’t it just. Hope you’re recharging well
I meant in response to ben's msg haha, I'm antisocial to the point where I didn't go out for years

I am, I have been working on my motorcycle to keep me from rotting in bed
watching donald duck on tv at 15:00??? yes
eating a huge julbord of food?? yes
handing presents to full family on fathers side??? yes
letting the kids read the to and from section on the presents??? yes
have santa visit??? sadly no
you are in the same club ! cool. i rarely go outside beyond gym time
Yeah but at the same time the loneliness is slowly ripping away what little sanity I had
loneliness is legit painful and deafening
Same my definition of a good day is staying at home and just bing chilling
or what specific thingy were you refering to ben???
I feel like going out is a chore
terminal fun
its tiring
Ahahah aye 😁 that’s the one. Can’t beat the crackers and cheese in the evening
Awesome(: we celebrate Swedish Christmas here and it’s good fun. Donald Duck, Swedish board games - Tjuv och polis & a farming one that’s like monopoly ish. I can’t remember the name of it rn
I'm in the uk so actually connecting to people like me is yea.
I still haven't wrapped my parents Christmas gifts
oh board games... nice
ahh , UK , i can imagine is very tough
Add that to anxiety, depression and other things and yeah. it's pain
Was Honey a legitimate money saving tool? Or just an affiliate marketing scam promoted by some of YouTube's biggest influencers?
If you have any inside information about PayPal Honey or believe you can contribute to this story, please feel free to contact me confidentially at megalagtips@proton.me.
Support my channel on Patreon: https://patreo...
Lucky you folks are here, I can be alone but not lonely. 
I thought that was CoffeeZilla for a sec icl
Released today. Honey was/ is manipulating cookies in their favor financially
i offer you a digital hug.
closest to boardgames we have had recently on christmas is the one time shadow tried to play some role playing game over the phone with a friend
i know all about depression and loneliness
otherwise mostly focus on food and chatting about random topics and playing with presents
Nope, never even heard of this person before either. Got reccomened. When I watched it, it was at 1.8 mil, now it's at 2.5mil
Ah nice. Yes, plenty to keep busy I bet. Took me like 6 months to rebuild an engine on my CBR
keeping busy but also resting is good
start with dinner julbord
continue to desert julbord
continue with sandwich rolls julbord
Tough to find the balance 😄
Constant resting is bad though
Awwwesome
but shadow is gonna be super tired after christmas due to mental stress right now
A THM themed tabletop session could actually be kind of fun
Yeah, I have to clean the carburator and then wrap my covers
Relatable asf, it's not being alone that bothers me; it's knowing that there's nobody to hang out with when I want to
shadow usually makes knäck for christmas but did not feel up for it this year so just bought some classic made ones
it only contains:
heavy cream
sugar
dark syrup
chopped sweet almonds
real af Ben
Sorry to hear. Yes, Christmas period can be tiring for a lot - me included. Love my family but it always reminds me the reason why I moved out 😂
Yessssssss
helloooooooooo
Tabletop like IR or tabletop like games??
heard there was some cybersecurity related board/card game you could buy and play
don't recall the name
There's a system called GURPS that allows for rules to things like programming/hacking, so it'd be entirely possible. Or maybe even just straight up run a Cyberpunk module if you wanted to be meta.
I want to finish the module of junior pentesting
I've got nothing but time (most of the time) and I'd be more than happy to help work on something
What is this
THM as in TryHackMe
Tabletop as in Tabletop Roleplaying Game
do it before new year
:3 I’ll forward it as community event in the discord or something and see what the interest is! Happy to work with you on that(:
What is this tell me
Tabletop what is do
Like Dungeons and Dragons.
Its hacking but like dungoens right
Yeah! That's one way it could be done, at least.
I love that idea im dnd fun aswell
🔥🔥🔥🔥🔥 why there is no anocuments about it
@lone thistle Go bed
I remember you had some issues with landlord and storage. Got that all sorted?
How to get in it
Shush it’s 00:06
It was just an idea. It hasn't been done yet. But I guess we can add one interested person
Yeah, got it in a storage unit now
?
@loud marlin Forgot how annoying Arch was to install....
It's just a concept right now. Nothing in the works or promised yet.
I gotta sit down and do an entire writeup for what I want...
How do know
Do u know
Where the news??
Because I just made up the idea like five minutes ago.
And then they accept it and arrporved it?
Refer to this.
interested, black cyber venom
Basically "we'll know later"
how many bitcoin for black cyber venom?
They not sent me in emai
I want it to
1 bitcoin
Nothing in this year not like before
@mellow gull so u mean this suggestions right?
Could somebody rate my idea for a portfolio project?
Thinking about creating a social media platform then having AI just populate the users and posts and interact with each other. Kind of as practical demonstration of the dead internet.
yeah, maybe. We'll know later
1 bitcoin can remove most of my trouble 
thats facebook
I wish
And most of reddit
/r/
I wissh!!! Please !!
and all of twitter
burning fb 
So instead of using AI I can just scrape facebook for the same result
good luck with that, they block others from scraping while they do it
addiction it will be dugeon
Please I need it
intelx moment 💀
I will be so happy tomorrow when im doing the aoc
just play baldur gates for a moment
AoC is 24 hrs
Day 23
Same I have not done my aoc yet
My favourite topic
Im torn between completing my pre security or aoc first
AOC is a nice tie into a lot of the pre security topics
thats true
And dark mode

I learned a lot in aoc
No more forced dark mode extensions
Personally I’d go for the AOC
do AoC 2024
It will help you in the security topics a lot
Its like if you were forced to use light theme on vscode
its like using light mode in discord
Advent of cyber I didnt use it
I think that would be the only light mode that would break me
Sounds like a mr beast challenge
The last person to turn bright mode off wins 500,000$ dollars!
in a dark room
i dont care for that guy
See I’m a persistent mf if money was in the equation I’d do well 
Same
i would be a good surgeon
I think it’s a generational thing I don’t really know anyone above 20 like or talk about him
Dee you have a bright whit eprofile picture, i would assume you like light mode
He doesn't have any life in his eyes when he smiles.
I need to change that I played drunk truth or dare with my gf and she picked this 
just a grifter made it big on youtube
A gf? Damn some people here live better off than me
I am working away at THM learning... Completeing the "Moniker Link (CVE-2024-21413)" room, and I am thinking to my self, that was cool, it it was easy.... ..... .... ..... OOOHHH........ OOOOOOOO.... it is That easy......
My days what a bonus lucky
If i ever secure a gamer gf it will be the day i meet god cause its never gonna happen 
Yea, he's been exposed for some morally questionable actions,
It happens trust me
We’ll see someday
When does AOC end?
dec 31
Oh sweet all of December
31st?
last task is 25th
I thought it was gonna be like 25
Same
..
i understood the query for all of AoC content and prizes etc, not the challenges
Then I still have time to catch up.
Naww
Been procrastinating over the Frida one
wait, there's a Frida one
Oh it’s actually a nice one if it’s the day i think it is
Day 19
I decided to try my hand at aoc sidequest im just bad at it
.
Yer icl I realised it’s a little out of my skill spectrum after talking to my friend who’s staff
He said this year it was extra evil
day 19 is burp?
No wonder i had to call the priest
Not Task 19
oh wait
Day 19
I looked at tasks
Task 25
Yer I enjoyed that day icl
Lmao
Was a different way of doing it
I like Frida for mobile stuff
I want to
What way
Aoc
then just do it
Im gonna be honest i did it on autopilot so i still confused about wbat frida is

Aoc is adventure /
frida is a tool for dynamic reverse engineering stuff
Alr wait is there static ones then?
i should go to bed but i'm too deeply absorbed in something
.
Yes you will meet some static ones in a later day
How would frida work on android?
yeah, tools like ghidra, radare2, ida and cutter
Isn't it for desktop binaries
no
It is winter break so you could always wake up later
That… reminds me of when my friends dont explain stuff and say wait for a few more years
Frida:
Portable
Works on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX. Install the Node.js bindings from npm, grab a Python package from PyPI, or use Frida through its Swift bindings, .NET bindings, Qt/Qml bindings, Go bindings, or C API. We also have a scalable footprint.
i could, but gotta go shopping with the fam at like 1030
Ooooohy
I am not gonna spoil future rooms!

Thats what you meantt aha
Oooooh fun fun but do you need mental clarity for that
My friend worked hard on one of the rooms not yesterdays but day before
is adventure?
yeah i'm driving
Oooh fro aoc?
driving and texting
Aoc
Yer sweets staff member
GO TO BED THEN! Dont die
not driving currently. driving tomorrow :p
I’d hope not
Idk who that is but alr
Still dont drive on lack of sleep
welp time to try and get up earlish tomorrow so meep moop to the beep boop for the sleep sloops
Goodnight shadow
Gnnnns
have good rest shadow
How’s life been treating you gaw?
Life has been a process. But it will get better soon, hopefully.
life comes with a bootloader
Yer just stay hopeful best you can do sometimes
Don't worry about me too much. I've become very stubborn and find my way through problems one way or another.
But I appreciate your words of inspiration nonetheless, and I extend the same gesture to you.
Just always nice to check in and share kindness!
Knowing there's at least someone that cares has always been a really powerful motivator. 
💜
We have great community here icl
yea
haha most
That’s case for most of everywhere though 
As large discords go, that ain’t a bad score 😅
The almighty network god
Ben is cool beans
^^
no u
awww
A pro bean
+1
both
Wait is peeling a banana the same as skinning it
Probably
Bed time(: gnight one and all
Gn gn
there's bananas in the ocean?
There's probably bananas everywhere
If there is cucumbers why not bananas
OceanMan is concerned about 🍌
To be fair all of the food to take up there wouldn’t be the worst
i highly doubt the ISS has bananas
Durian is worse
Ofc poor bananas
Jackfruit should be nowhere
If you want stinky food get stinking bishop
what a great username
Hmm?
It’s a cheese
Also cacao looks like it would smell disgusting
Never tried it not a true connaseur ig
There's...
a game about controlling a banana in a space station
I wouldn't have expected that
That doesn’t surprise me
International Space Banana
That sounds like a missle
I'll missile a banana into your house
Is originally from Gloucestershire. Also is made from the milk of Old Gloucester cattle.
not really my favourite but I had it a few times
It’s not bad but damn the smell
What would the targeting system be {was tryna come up with a pun but couldnt}
Banataic?
so is durian and surströmming but I tried those anyways 😂
"houston, our banana has split"
"roger, is there ice cream on your station?"
I’ve never managed a durian yet but I do want to
Wats a surstromming
I thought it was, houston we have a split, yes it's a big banana 😂
"stop this monkey business, we have work to do"
it's a Swedish dish the main ingredient is fermented herring
Wait is that the thing thats banned on trains
the funny canned fish dish?
Yes that’s the name for it
It's banned on planes, not trains
Planes are just flying trains if you think about it
you have better circulation of air in trains than planes. You can't open a window on planes 😂
Considering the recommended manner of opening it is as the bottom of a fully filled tub...
Some trains also can’t tbf
Wait actually?
You can get away with filling up the sink near to the top too, probably
Or herring flavored bananas
...Elaborate?
Uh airdrop as in apple airdrop?
i mean, if there is a reward for every body that participate
In the advent of cyber?
oh mb i think im in room help xD
post it there and wait
yea ty
Gave +1 Rep to @blazing granite (current: #62 - 131)
wish there was a user mini_wheatums such a cute name
hey guys can you recommend website for practice tests to keep your IT skills sharp. It can be related to IT in general
tryhackme
I dont comprehend
Using it for cybersecurity practical learning. But i need some good websites to practice questions
I'm running Arch within VMWare. Then I want to see if Qubes behaves, if it does, then running Whonix inside that
Why?
Because I can!
Qubes inside vmware?
Good logic right there
Thanks lol
Gave +1 Rep to @strange zenith (current: #1660 - 2)
Oh no no
I've come to the conclusion I can't learn hacking while high af off shrooms
Arch Within VMware, Qubes within Virtualbox, Whonix within Qubes.
Qubes within virtual box is so much pain i tried the other weekened to no avail :c
Already having slight latency issues with the VM, I have to move my mouse for the VM to update faster
Pain
VM being Arch, haven't installed Qubes yet
Alr if it works you GOTTA tell me so i can spend the rest of my break tryna do it lmao
Hi guys, I tried opening my kali vm but its not connecting to the internet for some reason, but my host os (windows) is
and im using discord on windows
I think the last time I had a windows update
and maybe the vm didnt shut down properly? idk but does anyone have any suggestions pls
i bet that would be very hard to learn doing that
First hurdle
The attackbox?
nah my vm
Qubes is good, but you need a powerful machine. It doesn't perform good on vm
I got 32 GB on this laptop. I will overpower this Arch VM if i have to!
Hell. if needed, I'll move it to my 64 GB Desktop.
Not enough? 256 GB Server
Lmaoooo what if that doesnt work
Download more ram!
Make it 1.5TB of ram!
64 maybe enough but install qubes on dual boot not on a vm
Qubes gives Quties
Too late!
Uhm no clue then i would just double check network settings good in vbox or whatever ur using
Lmaooo stonks
that's what she said 😂
Five. Hundred. Sticks of RAM.
i havent changed a thing :/
500 is lots
Doesn't help that Arch is a pain when it comes to packages
until is not 😂
Welp do other vms have network?
I thought packages were the one good thing about arch?
i have no idea, i only have 1 where I do my work on. But my host os does and its connected to the same network
500 1gb sticks
Gonna be honest i have absolutely no clue sorry maybe try asking more tech savvy ppl
Not when they differ from normal Debian based apt... or are in AUR
its okay bro, thank u anyways
Gave +1 Rep to @strange zenith (current: #1241 - 3)
Wooohooo we love apt
at least arch has a package manager. If you could take a time machine you should have a go with the first version on Slackware back on 1993 no package system and no binaries. You need it to compile everything, update and maintain that was a nightmare
https://wiki.archlinux.org/title/VirtualBox#Load_the_VirtualBox_kernel_modules
This is to get kernal modules setup
The first version of the Linux kernel was around 1991, I'm talking 1993 only brave people used Linux back then 😂
virtual box suck maybe that's why 😛 😂
Trueeeeeeee
Oh @blazing granite I found a song for you
אייל גולן "השיר האחרון" מתוך האלבום "בלעדייך"
להורדת האפליקציה הרשמית של אייל גולן לחצו כאן:
http://onelink.to/zb8p6q
הצטרפו לעמוד הפייסבוק הרשמי של אייל גולן http://www.facebook.com/EyalGolanOfficial
מלחין: זאב נחמה ותמיר קליסקי
מחבר: זאב נחמה
מעבד: זאב נחמה ותמיר קליסקי
שוב חוזר כי סוף הדרך
שוב הולך אול תוך האור
אני חוזר אלייך
ואת אומרת:...
against the odds
That wasn't very hard
you get credit for doing it
Guess I don't gotta deal with all that packet size nonsense that one guy I was trying to help was
packet sizes available upon request
alias veep=
I just set it to THM cause I'm lazy
right, 1 less letter to type
It's like 20 less than the full order so I'm not complaining
time for another 🍸
cheers
Nice
Alright time to see if I can actually connect to a target machine rq before I finish this setup for the night
Hello I’m new here
Hello Biggy
Wsp man
Good man, wbu?
Am good thanks
Gave +1 Rep to @sage copper (current: #2514 - 1)
@blazing granite https://open.spotify.com/track/6AZQ7Gu6A0BeSpENDBNuB8 Another song
so where do u live big jack
Actually wanna learn how to get someone IP address
And know the person location
i mean continetn
why did u get scammed or ?
Nah
I have a guy I wanna know if his clean
💀 i did when i was 16, i still think of it to this day
Wbu
Where are u based bro?
אייל גולן בביצוע השיר "יפה שלי"
להורדת האפליקציה הרשמית של אייל גולן לחצו כאן:
http://onelink.to/zb8p6q
הצטרפו לעמוד הרשמי של אייל גולן בפייסבוק: http://facebook.com/eyalgolanofficial
מילים: זאב נחמה
לחן:זאב נחמה ותמיר קליסקי
אם תרצי לדבר מחר אני חוזר
אל הפינה החמה שבליבך
תני לי שקט נפשי וכח להמשיך
לחיות את חיי לצידך
רק חכי הלילה עוד צעיר
ד...
Ahhhhh I understand....... nothing

idk how to locate
Ok bro 😎
okay mate
Sent a request bro
wym
I sent a fri request bro
having to use less instead of cat was an interesting twist
But that was the only complication
Whats less
less does the exact same thing as cat but limited to a single page space at a time
less is more
For small text files there's basically no difference
head is a command
this will display begining of the file
less is a pager
I mean it accomplishes kind of the same thing
Ahhhh makes sense
you can scroll and search
Alr actually that seems very useful
It's good for when certain commands get blocked (like in the pickle ctf)
Creative ways of getting the same outcome
Pickle ctf?
Woohoo
A very silly and quick CTF where you collect "ingredients" (flags) to save Rick
you need to do man less to anwser that or go to https://man7.org/linux/man-pages/ and seach for less
CHEESE CTF
are you trying to draw shadows out of the shadows? 😂
Lel ty
you can also try this if you want to learn linux https://overthewire.org/wargames/
I crave mozzerella sticks rn
man less if you're in Linux 🙂
Dam thats sick
Ik but am on my phone rn :c
Wait actually i got a term on my phone
Peak explanation less - opposite of more
Hehehe
Maaaaaaaaaaybe
I got fries with cheese on it
Where from (if I may ask)
A reasurant
Luckkyyyyyy
You know what they aay
Sharing is caring 🥺
he was sharing with himself 😂
:ccccc so mean
Oooh do you play genshin
I've made a grave mistake
The DEAD person is supposed to go in there, not you.
Chat, watch as I recover from this dangerous situation.
Not anymore.
Yayayay
No no no you cant escape that quickly
Do i believe you hmmmm
Hmmmm suspicious but if you say so
Idk what that is
big plant + water = big boom build
Im gonna be honest i played like a WHILE ago like when the japanese island first came out then stopped
And recently now again
Fs in chat
Hey its not as bad as my minecraft phase during exam season
Minecraft would've been preferable
Rlly?
Actually good point
Yeah like almost everybody here has defo been a mc nerd at some point
thats a bold assumption
almost being the key term
Is this legit? It’s a digital footprint scanner/eraser.
So as an aside try not to put random links in chat.
Im very tempted to click but restraining myself
VirusTotal says it's fine but don't touch it anyways.
Good idea
It mixes a lot of identity protection concepts into one thing.
Is it legit?
If you're paranoid it'll do all the things you think make you safer on the internet.
Alrighty
Like... Third party "anonymous" password managers/aliases are all over the place
Looks like it has a VPN function
A temporary email throughput setup..
You'd probably be fine with just the VPN 99% of the time
I mean temp emails dont hurt? But you could prob just get like the other ones
temp emails are free
The typo had since been cleared up whilst I was doing today's AoC, but I got excited a little after seeing the typo name 'Major Malware' and needed to meme it. XD
Hahahaha
Lmaoooo thats beautiful
I was literally pointing the name out to CMNatic this afternoon and we agreed, he totally should be a character next year. XD
protonvpn is probably okay for your average everyday browsing, to be honest.
Hmm but as evil or nice dude
Alr
Hi, I have a question about THM premium plan. Would you recommend it, is it worth the annual plan? I have some basic knowledge and am interested in CS career in the future.
Mayor Malware is definitely a good guy
I can see him as evil. Maybe more sinister than Mayor Malware.
Oh definitely
Omg imagine if next year he tried to recruit us to be evil
XDDD That would be epic.
Omg i could totally see like those ww2 propoganda posters
That depends on how frequently you plan on using it, how much you believe you'll benefit from the paths, etc etc. It's worth it for me because I use it every day, but that might not be the case for you.
I think im gonna go to bed folks gnnnns have a nice morning/night
nighty
That's awesome!
The hoodie is way more fleecy and comfy than I was originally expecting, big props to THM
I just started on THM after buying the premium plan on black friday. Absolutely recommend it. The 1hr daily limit on the AttackBox would have killed a ton of progress so far. Yes, I can VPN in with my own VM, but having the preconfigured box and not wasting time on config bs is unquestionably worth the sub-$10/mo the annual plan costs right now
Also, a bunch of the web application pentesting rooms are premium, and they've been fantastic so far
I was about to bring this up. While THM has a lot of free rooms, more than most other similar services, there's definitely a huge jump in the learning available to you as a subscriber.
Yep. I didn't even know they were premium until I went and checked my cleared rooms - they don't make it very obvious as a subscriber
It shows up pretty quickly if you start on one of the primary paths, but you can spend a long time without running into a subscriber only room depending on the circumstances.
I did the "do I wanna subscribe to this? How often am I gonna be here?" thing at first for a little bit
And then I just kept coming back every day
can someone explain how does caching works on a http client.. i see the server send different headers but dont know how does it work
Can you be a little more specific?
Is this for homework or something else? And the above.
If that's a homework question someone needs to punch that teacher in the face
You'd be surprised
no am building a browser and wants to add caching
I'm old, man, not that much surprises me anymore 😛
i asked in pydis but its dead
Caching usually happens through an initial exchange of information and an "agreement" between a browser and a user that consists of a private and public session key, which ends up being contained in a cookie that a user keeps on their local storage
I mean generally caching just means that you have a copy saved in local storage and it will check there before requesting it again
but what are those headers send in caching-control
if I had to guess (which I do) it's probably the server saying that the information changes frequently and you shouldn't cache it
That's a really long topic and depends more on the website the browser is mediating the connection for
but caching between user and browser is called a cookie? i was trying to like implement client side caching for the like images that server sends so it doesn't need to send it again and again
The browser might be responsible for maintaining a local cache of the user's cookies which can contain authentication data, or your username/password hash, or any other number of things depending on how the website the cookie is for is made up.
Are you trying to build like a general web browser?
yess
why?
The browser won't be able to capture a website's image data in the local cache under most circumstances.
You might be able to script it to detect and copy over image data left in the html/JS script depending on how it's formatted, but that'd be really inconvenient really quickly
https://browser.engineering/http.html#exercises am following this and trying to implement 1.8
Yo, hope everything is going well for you. Would you recommend subscribing at an intermediate or advanced level?
I would recommend that even a pure newbie subscribe - it's probably even more important but for different reasons.
The 1hr attackbox limit is less of a hurdle for an advanced user that can set up their own VM and VPN in - a pure newbie is probably going to get wrecked trying to figure that out
Like I said, a webserver and the local user will exchange information or request information from time to time. This is done in the form of GET and POST orders. Sometimes that involves image data, which can be cached.
I've done a hack the box and a couple of free rooms/the advent on tryhackme although I haven't subscribed yet
I was a complete beginner when I started and it's proved to be very useful. The path (starting from complete beginner) has been very useful for me.
so in my program caching it just means to like store the image in a data structure?
I think the 30% off deal is still on for an annual sub? That's a pretty sweet deal
how does a browser cache the images in the local storage?
Yeah true, I guess you can never learn every or try to fill in the gaps of your knowledge
Might get it in a min
Thinking about portswigger as well
When the browser receives information (again, because it's remediating information between the local user and the website), that information is contained within something called the local cache. This is unique to the browser, and is sort of like a temporary data space.
There are encoded cookies that can contain the user key for example, and typically there's Javascript in place that's designed to pull image webdata from the local cache if that data is available when you go back to a website
Check out the Black Hills Information Security Antisyphon training - they have a handful of Pay-What-You-Can trainings and they are phenomenal. Any of John Strand's courses especially are legitimately SANS-level training for $0-500 instead of $8-10k
I, personally, don't know how all that works (how to make a browser, that is), but that's the basic process.
hmm okh
^^Important to note that those local storage containers are (or should) be secured so that other programs, other websites, etc can't access them
It's kind of a big deal
Usually that data is locked behind the same session key that a user and webserver initially share on their first visit.
Yeah nah I don't need that, I'm definitely not a beginner.. Just tryna figure out a learning path that challenges me
Not if you build your own (vulnerable) browser!
So that way it only becomes available when that key is used, aka when a user access a webserver
True! But you'd run into so many problems if you didn't do it right
DNS failure to resolve being the most obvious one
The BHIS stuff isn't all newbie shit, I just did the active defense and cyber deception course a few weeks ago and it was phenomenal
It might not matter to non-cert http webservers (or some of them,) but if you don't cache and encode properly HTTPS will kick you right off every time
Yeah nah that does sound pretty good, I'll check it out
They put them all up on youtube after, you can go at your own pace if you can't make the live sessions. You can download the lab VM and access the repo with the labs anytime.
https://www.youtube.com/watch?v=LW4fxEhYraw&pp=ygUgYWN0aXZlIGRlZmVuc2UgJiBjeWJlciBkZWNlcHRpb24%3D
Register for class:
https://www.antisyphontraining.com/course/active-defense-and-cyber-deception-with-john-strand/
Active Defenses have garnered significant media attention, with debates on whether to attack attackers or avoid active responses. We believe the solution lies in a balanced approach. In this class, you'll learn to compel attackers ...
Live sessions do offer a cloud VM which is nice for the folks that can't get vmware workstation to play nice on their pc


