#general
1 messages · Page 696 of 1
yea thats what i was wondering, payload sizes are shown when they are sending the stage etc
Basically add the payload to the overall shell size. By the time it attaches to a process unless someone’s paying attention the footprint is very small tacked on to that processes usage. They are very hard to detect if you don’t know what you’re looking for but like anything definitely can and can trigger baselines when they go anomalous
guys i had this email in my inbox for a couple days, just saw it, not sure what to make of this
i cant seem to be able to paste images
"Congratulations!
You have won:
a 6-Month TryHackMe Subscription
Please allow 7 days for us to reach out with more information on claiming your prize. In the meantime, you may wish to check out the prize terms & conditions below!
"
scam
Emails was sent today
from TryHackMe Prizes prizes@tryhackme.com
Dang
Did you participate in the AOC? Is it from THM? Just apply typically logic. Were you expecting this?
Etc etc
yea, this was the base of my thinking. that if it attatched to a process then the spike could be monitored, but it being so small makes it a bit less anomolous
i did do a couple tasks but i wouldn't give me that prize
Domain seems legit for average person
It's a raffle.
my mind went to detection ideas, cool tool.
This is correct. Typically when you are at that stage in a pen test you have essentially completed your goal anyways to be fair.
So you could answer all questions and not get anything.
Answer one and get something
Yes you are hoping they catch it, great but even if they don’t, also great.
yea thats why i'm a bit tempted lol
Review the headers etc. if you did legit win something congrats.
What if it was a process that isnt supposed to make connections ?
i believe there is a filteration before the raffle idk
Then you have chosen poorly on what you have attached to
you smell and touch the cork to check its health and subsequently the wine, if the cork is dry probably contracted and let passed more oxygen the it should that could affect the wine, maybe the cork had tca, etc
Thats a good point, attach it to a process that mimics the closest behavior
It also just depends on the scope and rules of engagement if your goal was to take it as far as possible remaining as stealth as possible is key so you can remain in and pivot and see what else you can do. If the goal was to get to the point of executing an exploit based on a vulnerability you are tracking in their system then stop. Then you don’t even attach it at that point. You stop, log the results and methods used and that’s it.
Often times that’s the case. You say look I was able to shell you here is how and why.
That’s often more than enough for a report.
Most companies when running a pen test will have you very specifically scoped in for a line of business application as an example and the rest of the infrastructure is off limits. They will give you specific ranges and a singular app or a maybe a couple to test. It typically comes down to time, money, and what their goal is. Many times the pen test is to help certify them in various compliances and is a step in that direction. A full pen test like full on wild, go crazy pen test is absurdly rare in the business world.
give it to me
Wow
farther explorations in the dm?
so strategically speaking, its a temporary shell. used for the utilities it provides like hashdumping, and placing a more stable shell somewhere for persistence or immediate offload of data/hashes etc?
This is for the most part true. Most pen tests will not have you perform a hash dump as an example. You will stop at “I could have”
Is the single or couple of application testing also under the black box term ?
So when a company asks for a black box pentester for example
I think i saw one sometime then
So black box tests are usually external, they are to test typically APIs etc for an application.
Sometimes it’s a test of networking infrastructure
A white box is almost always internal.
If in doubt, wait the 7 days, THM will give you a code.
Sometimes you get a white box for a company that’s both external and internal
Black box can be (n).
What do you mean by filtration?
As can white box.
If you maybe are wondering why then learn some of the offensive skills you are, it’s because of two areas. One is working for example in an org they deploys advanced offensive techniques. They do exist typically are government backed. The other is so you aware of the techniques which helps you defend against them.
Pen tests for orgs are often far less exciting than your experiences in CTFs
But that’s ok you get paid well and remain knowledgeable
are there still legal agreements that go with those rare go crazy attakcs . @jade wing ? ive barley begun to delve my feet into this world but im aware breaching legal agreements is a huge no no (in my country)
1 hour and 3 minutes in.... still encrypting
It’s a massive no no to go out of scope and breach an agreement. It can cause legal issues for you and your company and bring lawsuits as well.
Not to mention likely get you fired from the company you are working with.
Im too far away from doing this lol
Those agreements are no joke.
Sometimes its just fun to learn
Oh yea absolutely they are a blast to do. I learn all the time from them.
It’s all about keeping your skills fresh and having fun man.
It just gets a lot more policy based and progressional in the real world is all.
they have made this clear.
however say I as an individual i discover a bug on a site or service with no open bounties . how would I approach this as i dont think companies would react to kindly to an email i found stating i found a theoretical weakness in said system
To scratch the itch of wanting to go wild you do ctf events like Bella and get on teams for it. They are a blast to do.
I have no intention to . I just keep seeing alot of that stuff get brought up for my exams
If you are in a professional setting of a pen test you notify and let them know it was not executed on but was identified just out of scope.
You typically shouldn't be seeking out problems with random webservers that don't have a bug bounty/arbitration program anyways imo?
this is all out of my current abilities mind you but you were providing such good info so i had to ask .
really?
If you are doing a bug bounty and they don’t have a bug bounty in place or are out of scope of that bug bounty you simply don’t.
It’s an ethical dilemma at that point if you notify. If it’s discovered but not acted on by you but you notify anyways the typical ethical guidelines dictate you follow up a few times and give it a timespan of 6-12m before releasing a write up.
When you do you never give the code directly for others to exploit it. This often times motivates that entity to fix it.
If you're doing anything more complicated than using inspect on a webpage you're treading a dangerous line when interacting with a service that you do not have express permission to investigate.
Also sometimes scans can go aganist law
Some people do that for fun, I steer clear of that because there is no money in it for me.
I ain’t running a charity over here.
Why are you testing a site/service that has no bounty? That would be the first question.
i am not . like i said this is out of my ability. I asked the question to make sure i dont get in trouble
This is correct, I don’t do this at all. It invites trouble in many forms.
I'm not saying you were, it's just the response to your hypothetical.
this is the response i was looking for . thank you .
i do homelabs now but no way i get hired to pentest anytime soon
Gave +1 Rep to @jade wing (current: #297 - 20)
If you're using the site as intended, and a bug occurs, just email them.
i want real hands on expierience is all but i am avoiding trouble hence why i got a subscription and what not
This is also highly relevant as a question in the exams. They are asking you to think logically. If they ask a question like that it’s testing your ethics. Choose the answer wisely and put yourself in a professional mindset. Hypothetically indeed you wouldn’t be in that situation.
thank you guys all for the feedback
This is why we use labs and virtualization to test these sorts of things out. It gives us the ability, time, and resources needed to practice these skills in an ethical and safe manner.
There are lots of tools available for this.
Critical thinking is important
of course . im just hungry for the real thing is all . i do appreciate any and all feedback
Yup keyword is always going to be “ethical” and “ethics” you will get black listed so to speak professional really quickly for stepping out of line in these regards. You will even lose licensure and certifications.
Many of the certs you will go after have you agree to a code of ethics and if you are found in breach of them your stuff gets revoked.
From personal experience, we had someone try to nessus a /8 in a mock engagement on a public address space
It can completely kill your career. Also land you in a cell. So just have fun ethically in labs and sims and ctfs l good.
Lmao
Oof
There's countless ISOs that allow you to host virtualized webservers that let you test things like XSS and other things you might be looking for in a bug bounty. OWASP BWA is a popular one for getting started and it's very easy to set up.
We've had clients give us addresses they don't own too...
Yeah, the engagement was in RFC 1819 space...
Due diligence etc on public ranges especially
cool . ill check this out . is it very resource hungry on the computer?
i had people giving me 192.168 addresses for external scanning 😄
Takes like 2 gigs of RAM dedicated tops, and only while you're running it.
i had a proeminent pentest org scoping an external pentest for a 10.x /16 network address recently
You can run a networking lab with a quad core processor and 6 GB of RAM just to be safe
everything is possible, welcome to fill in this spreadsheet to give pricing to customer
awesome . ill check it out . also begun the portswigger labs alongside thm if you guys have any additional resources lmk . thanks
Gave +1 Rep to @mellow gull (current: #205 - 35)
"Pls keep it between us and dont share it"
nah, i've asked them, could you please confirm with your networks department as this information might be incorrect
good to know that next time they provided me with their MPLS range which is fully internal 
if someone can, please thank Bubbles on the THM support staff for me
Have Debian with a GUI and then run headless VMs through QEMU-KVM/Virt-Manager
So personal experience from a while ago with dark trace (I know I know) I humored them and let them run a demo for us and we specifically scoped them in specific infrastructure and ranges. They came back to us 2 weeks later with an eager engineer and presented the data and had scraped well past the scope of the engagement. I was not kind nor pleasant to them. They almost got sued into the ground. The meeting was recorded and we had them dead to rights. They had to formally apologize, purge data from their systems and send us an official certificate of destruction of our data. AND they obviously didn’t get my companies business and I told everybody in my sphere to avoid them like the plague. These are the consequences when you go out of bounds.
I wouldnt have that much patience 
I was livid.
they dark traced their way out
Who wants my password?
theres some interesting stuff in this amd ces conference
Only 3,840,000 characters. No big deal.
It's not that hard to confirm the owners of IP/DNS ranges, too
It takes a pretty distinct mess up
crashing every service you use
how long did it take to finish?
Oh it's still going
1 hour and 20 minutes in, Keepassxc is still encrypting
oh no xD

can a clipboard even hold that much?
Surprisngly, yes
It was most certainly an over eager engineer expecting to scare an executive into purchasing their service they didn’t realize I was also a very skilled engineer and not born into leadership and clawed my way up and was savvy. They thought they would get one over on a boomer ciso who would be impressed. The sheer scummy tactics displayed enraged me to no end.

Now Libreoffice Writer on the other hand.... it wants to commit suicide.
It can do images so yeah technicially not big deal
"oh, password character min? let me introduce you to my password"
Hmmmmm could make it 7,680,000... OR EVEN 15,360,000 CHARACTERS
I try not to use passwords at all when available
oh I see, I copied it and discord was like, nope, thats a txt file now
Fuck it, lets make it 122,880,000 characters
It's crazy because this exact problem you're mentioning is usually talked about in the first ten pages of just about any and every book you read on this subject. Whether it's on ethics or use case, you always stick exactly to the precisely defined limits of your task and you always double and triple check to make sure the ranges are owned by the organization in question.
Gotta love USB-C technology
Bnuuy
guys i need a new setup layout so bad, i nearly knocked my laptop down 3 times 😭
how? xD what is your set up?
Yea it was a rookie mistake to say the least but the thing is like I said I think it was intentional. I think they were intending to use the mass amount of information they had to scare someone who didn’t know better. These dudes went into r&d systems and dev networks that we were fully aware were not secure. They were not available externally at all with the internal access they had and tried to use those out of scope areas as example of the security holes we had.
Also panic moment. I'm obligated to mention that when you set up intentionally vulnerable VMs make certain it is not available to the open internet. Make an internalized network all the time, every time.
What’s sad is I liked their platform but the price was already an issue and the sheer fact they did what they did ruined any potential partnership
i have my laptop on a stand and my keyboard under it and i keep knocking it off
Check out this 200$> setup
saving up for a whole new setup tho
unless you like excitement and sadness
i dont have room, my desk is way too small 😂
Ik its nonsense i just wanted open tabs to send to my friend to scare him 
lol indeed
It happens. All it takes is one person being a little too zealous to ruin it for everyone. This isn't the kind of job where you intentionally go above and beyond LMAO
dear lord 🙂
My setup
ALL THE PINK
wait hol up how do i send pictures
i noticed yea 🙂
you have to verify
That one on the top right 😭
needed to find a color that is good for detecting if I haven't drawn properly
Three monitors is already pushing it for me
Hello world
I need one more tbh
I have the one monitor
Why u in the dark
old pic
One little, 100 inch monitor 😅
Hello , welcome 😄
bella pink 😂
Hey i appreciate that alot actually cause that can be super dangerous. I have an old craptop completely segregated i run malware on so im gonna use those. Ive just never heard off intentionally vulnerable. Vms being a thing.
(but I am still in the dark, cause then I get to see the colors better)
Just subscribed to premium, its a very nice learning platform
Eye strain simulator
Glad to hear that you're enjoying here 🙂
Keep up the good work 😄
Ive delt with severe eye dryness for 4 months
Kinda hard learning technic english but I’m holding on
It was the worst experience ever
indeed
no simulation my eyes hurt after 30 seconds of seen that pic 😂😛
Feel free to ask and reach out here whenever you need help 😄
Thanks !
Gave +1 Rep to @cloud quiver (current: #4 - 1850)
Yeah you see all sorts of cool setups. I run metasploitable 2 & 3, OWASP BWA, an internalized AD network, and some other stuff. Other people have their own thing going on. But it's essentially how we cultivate our abilities in a manner that doesn't endanger ourselves or anyone else.
@exotic vector 1 hour, and 30 minutes, and it's finished.
Woops
though the electricity bill is so high that I can only affort to either have lights on or my pc turned on
I’ve heard their model is to try to scare people into buying their product. I’ve heard nothing but bad reviews of dark trace
so battle of the power
@sand trench
You literally have 4 monitors on at all times
lmao
Not a big deal tho
That's paying for room heating
i think i did it
Inefficient room heating
yay
A solar panel and buck converter, and get a second charger and cut the head
Boost converter?
@cloud quiver r u a bot 👀
Yeah there's like 3 types. Buck, boost, buckboost
I am actually joking, I use typically 50% less power than a normal appartment of my size
I have 2 monitors and I have my second one off at all times that I'm not using it, plus I have power saving mode on my main one
To the previous convo, this is what I'm rocking atm
Idk i think its buck
rockyou.txt
Hey nothing wrong with that.
Although increases 1% eveey 15 minutes lol
Boost if the voltage goes up
If it works it works, brother
But keeps the laptop on
i keep hitting the laptop and nearly knocking it off
Ah yes then its boost
my awerage daily usage of power is 2.65 kWh
I should be real 😄
Superglue (This is not legitimate advise)
U r active every time ⌚, no sleep
I call buck for them all
i was thinking about ziptieing it to the stand tbh
I use like 70-85 kWh a month
I was told pc wastes a ton of electricity so I had to pick one that is the most efficient
When I was younger had a similar setup, I used an external display and my laptop off to the side though. If you can, I would recommend it.
Actually never checked, what percentage of electricity bill is just the pc
U mean the house right 😭
I could honestly live with 1 outlet
Kyooty subsists directly off of electricity, didn't you know?
i seen a pegboard with a sliding bar with 2 monitor arms, i was gonna get a laptop tray mount and another monitor and put it on the back of a new desk
no, I use it to power my tools
Don't, it is wrong and will confuse people who know electronics
I know when I fire up my server cabinet at full load if I leave them on it can easily add like 100-200 dollars on top of my bill.
Ur pc probably consumes 200-400w so running it 12 hours a day, youre looking at 3.6kwh daily, which translates to 108kwh monthly
Multiply it by the cost of 1 kwh in ur country
Under heavy load maybe
I'm pretty sure there's a lot of factors
what
At idle it's way below 100w
Reminds of one of the Darknet Diaries episodes
We speak arabic here so i use different terms, unless im on the internet like now
Is there anyone who wins any prize of the Advent of Cyber 2024???
We will love to hear from you.
Yeah i dont believe it will run at more than 400w unless doing hashing or gaming maybe
I was about to say, my pc with 4 monitors run me approx 0.26kWh per hour
Yo wtf, electricity cost literally doubled in my country since last year
In my country, kwh price increases with the consumed amount 
that's called supply and demand
Should'nt it be the opposite ?
0.11 last year, 0.22 this year
Dang thats too expensive
@worthy plaza I won a prize from advent
first time? 😂
I asked it how many years it'd take to break a 3,840,000 character password.
It's just loading...
at least its thinking
JUST finoished
Its like ahh man how do these humans live
94^3,840,000
It says: trillions upon trillions of years
I pay 96 euros for 3 months of electricity
i asked it to make me a whole rant abt why sharp cheese taste so weird as if it was coming from trevor phillips and it did 😂
granted i got timed out cuz i think i bypassed filters
It's a new feature, it's searching the internet in real time
It found out that it should stop calculating and just give a big number 
That wasn't a joke
Tell it how much time exactly
Only one monitor?
How do you cope?
That 1 followed by 7,576,810 zeros
Jesus
i dont have room for another one atm
Relatively small number
I only rock 1 monitor, my laptop... Desktop has 3
.-. it can't see it in my badges why
What is the prize...???
Bet... Libreoffice writer is still loading the file
think that badge has got deprecated but who knows
Ahh there we go
shadow never got a chance to get this badge
I won a gift card to the swag shop.
Mobile discord sucks ass question mark
i tried copying all of that and discord restarted
Wait, lemme add to something...
HOLY 8MB txt file
My Resume now:
Windows 10: 70+
Windows 11: 3
Windows 7: 3
CentOS: 2
Kali: 3
Arch: 3
Mint: 2
Jabba's Spotify: 1
Mage's Discord: 1
"-" oh sh*t
Enjoy 🎁
1MB is aprox million characters
add shadows dragonbox pyra
ascii.
I'd expect it to be less if it was utf-8 or utf-16
idk how many of yall know who this is but jt music has hats and i lowkey kinda wanna get one cuz they look comfy
I could THEORETICALLY have 1,112,064 different characters in a password
JT music is pretty good
And all i have done is draw bunnies
My Resume now:
Windows 10: 70+
Windows 11: 3
Windows 7: 3
CentOS: 2
Kali: 3
Arch: 3
Mint: 2
Jabba's Spotify: 1
Mage's Discord: 1
Shadow's Dragonbox Pyra: 1
That's just bit combination at this point
find a site you can break by setting non-printing ascii characters in your password.
unicode WOOOOOOOOOOOO
DAMNN 8 million characters
\00
shadow will continue to claim that xkcd is a gold mine of fun stuffs
If that's a normal problem, what's the odd one
Oh you're a fan of xkcd? Name every comic
could do that but shadow would get banned
hehehehehehehehe. I could use python to generate every single unicode character in a password.
this may be a stupid question, if a website use to allow < into their passwords and now they dont, but youre password was made before and contained a < will it kick it out or allow

sorry that was the wrong keyboard issues one: https://www.xkcd.com/1586/
"Before logging in, change your password"
would not work mostly as passwords are hashed
so they would have 0 chance to know there is a < in the password
You can type the password and it would tell you nuh uh
It depends on how they've configured their backend?
Are you folks using keepass?
1password here
Bitwarden, personally
So i want to sync my passwords with my phone and laptop
UwUPasswordz here
I made Keepass stupid....
1800 transforms, took it 1 hour and 30 minutes to complete encryption
honestly best way to keep passwords safe is to just remember them imo
I would probably look at official documentation to see if it's possible
Bitwarden lowkey?
This leads to password reuse
But then you need to use same password for every other website
LastPass
Is that a password manager

Or a variant of them, which is a bad practice
which also leads to a problem if places force you to change password to often
Doesn't every password manager do this
as then you will start using predicatble patterns
I have a fun story from a month or so ago:
I received an email from a magazine i subscribe to, that also has a digital component.
We have implemented our new password policy to improve account security.
This means when you try to log in, you will be prompted to reset your password if it does not already meet the new criteria.
Don’t worry, your account is still safe, and you can reset your password at any time.
There's something they implied here, that they absolutely wouldn't confirm by email. I sent them a couple of emails over the last month or two, but still haven't received an adequate response for my security brain.
Keepass is self hosted
Found out that our dog likes the snow, but only when it's taller than her. lol
Account based ones ig
You do too
Or would I guess
What’s your guys opinion on setting up WINS servers in 2025?
Can i do something like
Server gets the public key, generates and stores passwords
Both my PC and phone have the private key, only these two can decrypt.
lol it's about 8 inches of snow so far with more to come.
Ugh. Really?
Reason I ask is cause I have a sysadmin at work that always says we gotta setup a wins server yet MSFT say it deprecated so I wanted other opinions
just use this in your password and you'll confuse everyone
So like if you lose access to both phone and pc you lose access to passwords?
You can use * or space " "
xd
the greek question mark; the bane of C#
Yeah
please don't say you're thinking of making your own password manager.
I am
please don't.
write the passwords on a piece of paper, put it behind your phone case
nowadays most sane compilers handle the greek question mark in the same way as a semicolon
Why? Too many things to consider?
let me try my luck... chicken man i have some question about hash from 7z2john...
i code in notepad
you don't compile with notepad do you???
Microsoft word.
I don't think it is completely worked out-- I'm getting the PARSING_ERROR
Ctrl and F5.
no, i build everything in paint
crypto is hard. software development is hard. The combination of the two is just fraught with pain and misconfigurations.

My undergrad degree was Bioinformatics. Can confirm.
cleared cache already... not working.
Issue resolved.
I think he's linking in
Like…Linkedin ?!?
laugh track plays
Linkin park
linkedin bark. It's how good doggos find new jobbos
Experience:
- CTF Player @ TryHackMe
Feeling chilly
me when making soup
can you learn more than basic networking on thm if u purchase a subscription?
There’s a whole free roadmap
Unless you’re talking specifically networking
IG to know enough networking to be comfortable in the other rooms etc?
The question doesn’t make sense unless they mean “if don’t purchase a subscription”
But yes
Yeah but I got the gist
Mostly yeah
There’s some networking concepts you may have to Google
But that’s part of the learning process
That's fair enough, but is premium worth it?
Well yeah
Curious if anyone can recommend any trusted secrets scanning scripts for websites. I will not use unless I understand the code of course but will save some reading if I can get some common suggestions.
if not would there be a list to include in things to scan for I could unclude in my checklist while writing my own script?
The issue is takeover of legacy code with hardcoded secrets
Worth the annual price of 95 usd on discount? xd
for the better attackbox policies, totally.
If you’re serious about learning then yeah it’s worth it
@hollow rapids #general message
95 is cheap for the stuff you learn if you utilize it correctly
I am a total noob, but for example - the networking fundamental is premium, when I try to enter some of the rooms
i recommend it, just for the rooms, challenges and the attackboxes
or the avent code still should be valid i think
whew might have to install graphene on my phone, got a "fun" email from google about an update they're gonna push to my pixel 4a
But how in-depth does THM go in terms of knowledge on the topic. I know they can't cover everything, but do they entice research in the specific topics?
it's like anything educational; you're always free to do more research yourself...
yeah you're suppose to be doing extra research and reading outside of thm
It gives you a solid foundation and path
you can click on the path and itll tell you what rooms are connected to it
Thanks guys 🙂
🙏
AOC2024 should still be valid for a promo code to in order to get 30% off
@polar spoke if you find you self here. got Q about some hash thing 🙂
At this point, why not just add him as a friend and DM him 
ehhehe
fair yes... nah i do things so far so great. just stuck from time to time. and i have weeeeery long hash that idk how to
YAY MARVEL RIVALS BEING NICE TO MAC AND LINUX PLAYERS
Power move
They send a pigeon
Lol
time to bird hunt
will the bird display a holographic message from its eyes
since we all know birds are robots
Yes, cause birds aren't real.
anybody win anything?
Yes, every winner has received their emails.
we finally made the bald eagle the official bird of America, cuz they were able to fit a robot in one.
its a sign
date with your english teacher
he retired
add him on fb
To a wedding or a formal event 🙂
or a gay speed dating event
i should dm someone ik that still goes to my hs to piss my ex off and go to their senior prom
recaptcha is for tracking real life people
not for stopping bots
anyone that think it stops bots needs to do some research
That's a bit weird
i didnt even win a congratulations email
But but but but but... it says "I'm not a robot"
when was the last time you noticed google lying to you???
1 nano second ago
Every day
just for your info recaptcha is mostly made by google
At this point, what isn't 
cloudflare
Cereal (probably)
I think a visit to a psychologist would be more productive 😂
also
hate your facebook is not made by google
I hate that FB isn't owned by Elon!
google wants to buy brazil #fakenews
were e-mails sent to all participants by chance, to let them know they were involved in the raffle?
no
if you don't get an email, it simply means you won nothing
I'm also a little disappointed I won NOTHING from the cyber event. 😦
actually, you won 24 days of free training
I won knowledge so I'm chillin
Fr
so he can destroy that platform too? 😉 😂
Well, it was most likely that you would not get anything
lol if that's what you think.... sure
the attention on twitter wasn't enough for the free-speech absolutist
better luck next time 🙂
'I am not a robot' isn't what you think.
Remove your personal information from the web at https://JoinDeleteMe.com/chuppl20 and use code CHUPPL20 for 20% off
Sources:
https://docs.google.com/document/d/1NRMfJo7UrTUuQOacSx2EdxMtQ2PMvdU1GTpCEHqk5Tw/edit?usp=sharing
We launched a Patreon!
https://patreon.com/chuppl
Video by - CHUPPL
Producer - J...
imma start my captcha business
This but replace recaptcha with everything
Thanks. I found that the last contest before that one, I had JUST STARTED and I didn't get an email or anything but I had won a hat and shirt but... they wouldn't let me claim them anymore by the time I saw I had won something. 😦 so I was really hoping this time....
Gave +1 Rep to @blazing granite (current: #60 - 136)
well not everything is spyware
but yeah there is a decent bit of the big tech websites being bad
My microwave probably listening rn fr
that's some dark ninjutsu shiet
and was REALLY Crossing my fingers for DefCon!! lol
If your fridge requires a wifi connection to run properly and your toaster has bluetooth, you know what kind of consumer you are.
140k in the room, 2k prizes
while not just "divide 140 by 2" since your chances depend on how many questions you answered, it was still low chance of getting rewards
i ran into a website, which shouldn't have told me who's going to collect my data (and there was a list of over 150 companies by names 💀)
the only technology shadow trusts is the ones shadow has fiddled with a lot
I even answered EVERYTHING! lol
hence vial-qmk keyboard and mouse
and ploopy headphones
Even under the most optimal conditions it was like a 5% chance.
Imagine someone answered 1 question and got a prize lol
It's snowing again 
Same even a bit of the side quest, no prize here either
wait so am i really a robot -_-a
could have happened even though unlikely
ya. I guess with only 2000 prizes.... lol slim chance.
your pfp makes me smile internally
Smile externally, too.
@sand trench did you win anything?
felt better, thank you
Gave +1 Rep to @mellow gull (current: #201 - 36)
did any of u win ? -_-
not me :/ didn't expect to win either
winning was the friends along the way😁
guess i'll pay that month out of pocket
Good, you deserve at least a little joy.
nope but that's ok. The things we learned along the way.
question..... ??? My 2024 stats thing says that I was in the top 95% of people in the USA. What exactly does that mean?? Does that mean that of all the USA people I'm in the top 95%? Like... there aren't very many in the USA doing this??
you get a stats thing?? 0.0
The bonds we formed, the things we learned, and the people we met.
At the end of each year yeah.
Top 95% of the US would be a large number.
is it measured based on country or globally?
Yep. It was at the top of the dashboard. Might be there yet?
It's gone now surprisingly. It was up for like three days.
Wonder if there was an issue?
IDK but mine was up for weeks
a badge and the certificate of completion
sup
I guess I missed it 😛
please dont mine bitcoin on paper
"Winning was the friend we made along the way" or something
Well, good luck next year/event
Mine bitcoin in the mines like the rest of us.
you're 5% from the bottom 😂
Damm, can't believe I didn't win anything in the AOC. did every regular task
There's plenty of us right there with you.
doing tasks only increases your chances by some 0.01% maybe
haha
i thought of doing the side-quest, but gave up without a second thought
barely familiar with linux, and it expects me to hack a firewall and VM
it was already 2 days before the end of december
touche
I started but got busy, got some time and managed to complete Q1 and Q2
They probably got a hold in there too
AFAIK everybody that finish it goes to a pool and from there randomly people are chosen, so don't worry about it, it's not a reflex on your skills, and better luck next time
im the #1 user in san marino
Monthly?
its just 2 of us XD lol
impressive, how much of an experience is usually required for these kind of difficulties?
I started few months ago studying networking and operating systems
the only red/blue activities i did were the ones on AOC
Well, most of my cyber security learning is from THM and I've only been going for 139 days straight so not that much
I also didn't get that far 
not that much, been doing it for nearly half a year
I'll see if i could complete it by the end of this year
Maybe if I had more time but that's mostly an excuse
ive been trying to figure out what i can study while i'm doing my full time job, port #s is a great one, any other suggestions?
You can still try to complete SQs, just now if you get stuck you can look at a walkthrough for that part
the baby steps 👶
Yeah, a lil more than that I would recommend
I am done with Pre Security, Introduction to Cyber Security (maybe 101 is equivalent) and Web Fundamentals
Currently 50% Jr Pen Tester
That being said you don't need to have that much but it can definitely help
Where can you see stats by country?
woaahhh what is thatttttttttt
most of them require a Business account but there is at least one that doesn't need Business
@glass nest
The darned "fake png"
there must be some mistake i did not receive an email letting me know i won a prize in AoC
Can we see the winners list somewhere?
"-" so ok I need a job first
Winners lists are not public, the emails were already sent out privately to all the winners
The question is what counts as a business account
Is it a custom domain
Or do you have to talk to a salesperson
an account you do business on I suppose
Damn why didn’t I think of that
ok, thank you
Gave +1 Rep to @karmic hemlock (current: #1021 - 4)
SOC Simulator
Yes indeed. SOC simulator
yep "-" available for business accounts
if we find the minimum amount of $ for a business account then pool the right amount of people to pitch in, could we make a not for profit then give timeshares to payers-in: THM wins & we win
company buy the business plan instead of premium
We could make a thm business account called thm discord
business accounts are more expensivo?
gotta assume but youre right, maybe theyre cheaper
I can request a free trial
like 500$ and more like I remember
I’m pretty sure anything business is more expensive anywhere
multiple user access tho?
budget of company 
yeah
the company training their employee there and made special plan for them ...etc
"-" I'm broken dude 🤣 it's not
Pretty sure the business account comes with a lot more customization
yeah 
Plus you can make custom rooms and they don’t get reviewed or anything. But they’re private obvi
so if 5 us got together and created a biz account we'd get a discount on a yearly sub?
You can do that with a free account
❯ ghostty +list-keybinds
ctrl + shift + comma reload_config
ctrl + shift + v paste_from_clipboard
ctrl + shift + c copy_to_clipboard
ctrl + shift + i inspector:toggle
shift + insert paste_from_selection
YAY filtered away all the conflicting keybinds
why does chrome block some tast files

task
now the tui apps and tmux can handle all the keybinds
technically yes
¯_(ツ)_/¯
"-" tumx is good but need some practicing and more customizing the shortcut
you can customise the shortcuts/keybinds in tmux config file easily enough
but yeah practice makes perfect there
New goal yall, I wanna be in the top 100k by the end of the month
In a TryHackMe business account, the number of accessible accounts corresponds to the number of licenses your organization purchases. Each license grants access to one user, and administrators can manage these licenses through the management dashboard. This setup allows for flexible seating, enabling you to reassign licenses to different users as needed without limitations on how often you can make these changes.
Rn I'm chilling around 138k
Great goal, Best of luck to it.
"-" so the licenses from where
Shadow is the ultimate business person
Thanks dude! Wishing you success as well
Gave +1 Rep to @errant fossil (current: #229 - 30)
where is shadow "0"
i dunno if it's worth it tbh, theres peepl who work the system to get high rank
Top 100k isn't that difficult.
prob like 50% of the people who completed aoc
►Subscribe my channel : https://goo.gl/4Y7gYQ
►Composed by : Yuki Kajiura
►From : Kara no Kyoukai - The Garden of Sinners
►Follow Yuki Kajiura :
http://www.fictionjunction.com/
►Purchase / Support Yuki Kajiura :
CDJapan: http://www.cdjapan.co.jp/product/SVWC-7749?s_ssid=e367905a0e48475a7c
♫Tracklist :
KnK I : Kara no Kyoukai - Thanatos ...
It's certainly not something that's, like...
music makes shadow wanna rewatch even more
Is working the leader board a common issue?
"-" so yeah can I know who is Fluff I didn't understand what is it
Top 100k overall isn't too big of an ask either.
It is a great checkpoint towards a bigger goal, and also will be a big motivation for higher goals
you're right top 100k is in sights bebe
I'm only barely at 0x9 and I'm at 78,000
I'll be there soon 😁
.-. how you are in lvl 8
shadow is in the top 3k users on tryhackme
I think the path I'm on right now should be enough to push me up there, I'm only 38% done with it
maybe cause i dont do rooms? just the pathing
"0" 0xD is very far
I'm gonna be sitting in 0xD eventually if I keep up at the rate I'm going
when will winners be announced?
If you pursue the path consistently you'll get there. :)
FluffMe was a mod in the server, this message summarizes it better- #general message
Already announced, check emails.
They've already been announced, emails were sent out privately
ohhh k thanks
where is shadow clan???
Is there a shadow clan?
¯_(ツ)_/¯
"-" like one month and half to get this rank it's easy if u have already strong background in the programming and network
INITIATE SHADOW CLAN
Found the Shadow Clan
Hello, dont know if this question belongs here. I just started tryhackme a week ago, did some beginner learning rooms and now started the AOC. I'm currently doing Day 4 but man I feel a bit lost. I'm doing this day with the video on my second monitor but without it I would feel a bit lost.
So my question is, am I jumping in this too soon ? Should I have done a lot more other rooms before doing the AOC ?
I would say i have a fairly strong background in it. I've competed before and I'm in a club at my school so I've just been blowing through the introductory stuff making notes on it
I would like to get more technically knowledgeable though at some point
Most people feel like it at the start, For me i looked up other videos on youtube about the topic and got a better understanding. Taking a Break also helps a ton, Its a marathon not a sprint.
Yep Im not rushing at all. I'm trying to do one room per day
u can follow along through walkthroughs on youtube on anything u get stuck on
im watching owasp unrelated tryhackme stuff before i do the modules rn
"-" oh this look good
nah the videos and task text is there for you to learn in aoc.... it is the most beginner friendly content on tryhackme by far
take a look at the last few years of advent of cyber
Thats a great way to go about it at the start, it will get hard later and having a clear understanding of the basics will help a ton.
So following along the video while doing the room IS a good way to learn ?
heck yea
yeah no shame in it as long as you learn from it
every way that makes your knowledge grow that is not illegal or unethical is good
if you are new, following along is an awesome way to learn
wen your new just building the habit of studying the material is a huge step
anybody listen at stupid speeds lol
Thanks a lot guys for your feedback
Depends on the content
yeah I could not solve any CTFs and didnt want to do they since I couldnt solve then I followed now I can solve without following if I am lucky
"-" yeah good I'm web dev and computer science graduated I'm already start learning cyber like 3 months :"))) I feel like I'm in very late point
the aoc vids are cool to watch too since ull get your favorite content creators and then branch more into their stuff
its nice wen u see a module, look it up on youtube n yer like oh wow tiberius has a youtube on this
u know exactly what kinda style ull get
Never too late to learn something new! I'm in Computer Science as well and looking for my first internship
tryhackme is good for the company want entry lvl ppl
I tried it
Ugh Covid succckkkksssss. Thankfully this is much more mild than the early days, plus we had shots and boosters in previous years. I'm on about day 5 of this
And yeah TryHackMe is fantastic and was exactly what I needed to refresh my infosec knowledge when landing a role professionally
useful but I think this need reading books "-" the books always move deeper in the concepts
Sure, but also sometimes harder to keep up with the very rapid pace of infosec developments
bless you
heck even one of my fave infosec books, Black Hat Python, or whatever it's called, needs quite a few revisions made by yourself to keep the syntax relevant to modern Python 3
although I won't lie, that was part of the fun for me, updating the code for any issues
ah i just got that book
Fantastic book, but yeah expect some issues if you do it 1:1
but it'll make you better at Python either way
thats the main reason why i wanted to get it. to learn how to make my own tools
mhmm great reason and great book to do so with. There's a reason most infosec POCs are Python
Bunny
yeah this is the point by when I said late "-" the cyber security in the time need more learning it's not that easy as 90's or before 2014
Nah I'd actually argue the opposite, this is by far the easiest time to get into infosec
When I solve one I ways like to look up a walkthrough see if people took any different routes
I got into infosec as a teen in the 2000s and while there were some resources, it's nothing like the abundance of resources and sites like THM we have today
Also as a teen in the 2000s there was no clear carreer path into infosec unlike today which was a major contributing factor in why I didn't persue it much further, just kept my eye on developments until I had to do it professionally
back in the 00s I resigned myself to graphic design (didn't pan out even though I'm good at it) and IT (did pan out but took me another decade lol)
Vast majority of infosec resources we have these days are significantly newer than the 00s or 90s
very well said
thanks, lol c:
hmmmm idk I have like a lot of dark things in my mind ,but this is so interesting "-" a lot of work
what even is the "-" that you keep using lol
think its a face
-.-
dark things?
Also while infosec and similar can be used for darker purposes, I will remind you that's not why we're here. We do use this knowledge for good and the betterment of IT and our infastructure and not causing havok
🤣 just reaction I used to use it
lol is it supposed to be a smiley/text emoji? I'd probably do an underscore instead if that was the case
i just dont get what you mean by dark things
It's obvious and why i said the above
Has anyone in here participated in CCDC before? I have a couple questions if so
"-" I mean like a young man you have scary about the future and something like that sorry my English is bad I'm just talking with words that I have :"))
ah gotchu
Fair enough, you're doing fine
We like?
@sinful moon 👋 how are you? feeling better?
Yes
I think he expresses surprise but silently maybe
too pink for my taste, but I bet you love it, so that's the important thing 🙂
You get the stamp of approval
The one on fuel tank is will of course be covered by the handle, like this
shh same difference
I love bunnies
the bike is called "Pink Bunny"
It looks great
Is it yours?
it's going to be, I am currently designing the look for it, so I can wrap my bike
Totally fair, very nice
I love Japanese motorcycles in games very much but I don't think I could ever bring myself to ride one irl
JDM cars and domestic imports however I am very much all about however
@sinful moon @blazing granite @rapid merlin Music sesh again tonight?
I have on-call server reboot at 8 PM EST and then potentially Halo MCC coop with a friend at 9 PM EST, so probably not unless it's later than that
but I do have to drag myself into work tomorrow for time entry despite still being quite sick or elsse I'm not getting paid so can't stay up too late
What’re you rebooting
Three virtual servers for an estate planning org
yeah it's no big deal and I automated the updates, I just need to manually supervise the reboots and ensure everything comes back up as expected
ah nice
for Linux that's freaking easy af
Yeah the only hiccup is the update will reset the certs on the web server
ouch
They’ll point to the self signed certs instead of the let’s encrypt certs
why though
The vendor
oh self signed certs and lets encrypt nevermind
idk why I misread that the first time
I mentioned it to them and they said they’ll fix the config soon or note it down
So it doesn’t reset the certs it looks for
Yeah normally Let's Encrypt bot or whatever just does the thing
Yeah this web server config gets reset whenever you update the vendors software
Cause reasons
thankfully for my web hosting server, I use Nginix Proxy Manager handle the Let's Encrypt certs for all three I'm hosting at work
Yeah, not a picture of my bike I am using as reference, forgot to take pictures of my own before it looked like... This
again I'd recommend Traffik instead of Nginx Proxy Manager but that's still decent
that's a pain in the a 😂
I just didn't know as much at the time when setting this up
Yeah it was a pain when I did it for the first time with no documentation and had to go searching for the certs and didn’t know where they were
So now I’m teaching someone to do it “in case I move to a different team” as my boss said in the meeting
why didn't you make it Docker/containerized as I did? Then again who knows how vendor specific this actually is
I didn’t configure the system
I just maintain it
The engineer who made it got fired 🙂
I just kinda rolled my own solution but the ask given to me was "host three web servers on a single host" so many ways to attack that issue
lolol fair enough
The weekend after the engineer got fired some networks went down
Suspiciously enough
I mean I should hope that all access was revoked when he was fired
ouch, I bet that the system wasn't well documented 😂 so in the dark with somebody else system that's fun 😉 😛
But I won’t get into it
I've even helped the boss with "did you remember x, y and z" when he offborded a former employee
I had an SA write over the private key passwords in our documentation
so it's conceviable that smething was missed
So I have to roll the documentation back
And I have to go write a bunch of docs on how to maintain this server
but also that's what password managers are for
petitioned for years for us to adopt one and I'm so glad we did
So we use ITglue which has a password management section
Yep that's solid, and solid documentation management
But an SA updated the pw in itglue
mhmm good revision management helps as you mentioned
So when I had to login to the server last week to fix and issue it took me minute to figure out why I couldn’t ssh in
I tried to get mangement into IT Glue but he wasn't having it for some reason
Then I realized he overwrote the password
It’s prettt great tbh
It consolidates everything helps organize it
Oh right, because Kaseya bought them up
that is actually a decision I agree with lol
Only if you keep up of course. My team and I have spent so much time fixing shit documents
I think we moved away from anything Kaseya except for itglue
They also bought up Datto who handles our ticketing system, Autotask and my boss was furious lol
Idk if I prefer ancient or day to
Datto
Axcient
God autocorrect
We use the connect wise suite for RMM
lol Axcient the backup system? We may or may not use that
yeah
We use both
I love recovering files when people are careless with them
And delete them off the shared drive
Axcient is signficantly better than Arcserve/StorageCraft that we used to use
restoring files with Axcient is just trivial in comparison to StorageCraft where you'd have to mount a backup drive on a server and jump through a bunch of hoops
Yeah I do like just being able to sftp
with Axcient you just mount the backed up volume in the cloud and... download the file you need
so much easier
that too
Yeah I like Axcient a good bit, I'm kind of the secondary backup manager in our org
When to be announced winners?
We don’t have a backup manager
Already announced
You would have gotten an email if you won
Arcserve/StorageCraft was a mess in comparison, and only getting worse. Good reason we moved away from them
We use 3 different EDRs which is a pain in the ass
They used to be one of the name brand backup solutions in the MSP space before Arcserve bought them up and started discontinuing their products and firing people
whattttttt
Actually 4 if you count ms defender
Oh Broadcom!
We moved from a more traditional Entepirse AV to our current EDR which is one I was championing
don't get me started with Broadcom lol
I was a champion of VMware even in my personal life until Broadcom ran them into the ground
We use huntress, sentinel one, crowdstrike, and or Ms defender
And have threat locker in our stack too
They are not at the same time
We're a S1 org I will say though
lol Threat Locker keeps trying to cold call us
It’s a pain in the ass dude. I think we don’t configure it right
always gets past Dispatch who asks me "uh Threat Locker wants to talk to our cyber security person, do you wanna take it"
No
It constantly locks shit up that we’ve previously let through
lolol
And I don’t have access to it so I have to ask an SA to unlock it so I can install the software
but those threats have indeed been locked
And sit awkwardly on the phone with the client while waiting for a response
https://www.youtube.com/watch?v=_KX30__lT3c damn this looks amazing
Witch on the Holy Night,
Witch on the Holy Night movie,
Witch on the Holy Night anime,
Witch on the Holy Night movie release date,
Witch on the Holy Night release date,
Mahoyo,
Mahoyo movie,
Mahoyo movie release date,
Mahoyo anime
Typemoon,
#anime
^ not out yet
Thanks for confirming my suspicions though, yeah Threat Locker is not a solution I want
well the trailer is out but the movie is not
It could be like I said, my company doesn’t configure it
Very very happy with S1 though, we used an outsourced SOC that I manage and it works out well
They only use like 1 of the features according to my SAs who gossip
I just check behind the SOC's decisions and reverse them when needed
Ufotable going unnecessarily hard as always
lol again, I probably sound awesome but I work in a pool of like 6 techs total
yuups
so people just kinda gravitate to the roles they are apt at
My company is like 150
same team that made the kara no kyoukai movies and probably why shadow got recommended that trailer
Somehow I feel like I also wear many hats
So it can get to be a bit much at times
Probably cause I forced myself into those hats tho
Yeah just don’t take on more than you can handle as tempting as it is sounds
They also did Kimetsu no Yaiba, Toriko, all the good Fate stuff, oh and Katsugeki! Didn't expect Shadow to be a Nasuverse enjoyer
I’m just trying to show them why they should promote me or move me to infosec
None are anime I know of or were excited for
to be honest only one shadow recognise from that list is the fate stuff
But I'm not a typical shonen anime enjoyer lol
Probably what they're most well known for so not too much of a surprise :)
I prefer my anime to be a bit more thought provking and stylish
shadow mostly know them from kara no kyoukai
which deals with life and death and morality
kara no kyoukai released in 2007 :D
fair
it has been shadows favourite anime for ages
Souren my beloved
even though shadow has not watched it since 2016
Not sure it sounds like my jam after reading Wikipedia but I'll keep it in mind
kara no kyoukai is plenty thought provoking
while looking extremely polished for its release year
If you like series that deal with morality, a lesser known one that I recommend to everyone is Nurarihyon No Mago
Oh, and a good slowburn one is Kekkaishi
sad it is not in 4k but that was not a thingy back then
NGE, Ghost in the Shell, Cowboy Bebop, Madoka Magika, Lupin III, Serial Experiments Lain, are a bit more my speed
and classics like Space Battleship Yamato
the anime series or the movie series of ghost in the shell???
and if the movie series the cgi or the hand animated ones???
both, and no CGI lol
Ghost in the Shell 2.0 is a travesty and will not be discussed lol
:P
The sequels are never as good... v-v
that is not a sequel
2007 Japan be like, "let's replace amazing hand drawn animation with awful CG"
that is a remake of the first ghost in the shell movie using a lot of cgi
and it did not hold up ot the test of time
yeah the OG stands up so much better
I think I have the original on UHD physicially, or if not that then I at least have the blu-ray
we just rip the discs and they go into our media server
*VHS
shadow has all the ghost in the shell movies on steam.....
yeah steam does videos
If steam started a streaming service that would be
interesting
odd choice but okay
and no they no longer sell ghost in the shell movies on steam
I have a couple movies on Steam but they're mostly gaming documentaries
shadow bought them when they were buyable
but yeah much rather own the discs
they stream in 1080p so just fine
But yeah we're up to over 1,600 movies on UHD, Blu-ray or DVD
kinda weird shadow did not buy ghost in the shell on blu rays but oh well
starting in mid 2023
we're so done with streaming, and rather own our movies in signifcinatly higher quality than streaming services put out
The only DVD i own is of my graduation
and instead we are are own streaming service instead lol
we only go DVD when we have to lol
we recently got rid of most of our vhs and dvd collection
you'll be kicking yourself when you see which of those DVD releases have never gotten blu-ray releases
Discs.. Only a handful of games. most of which are old Final Fantasy games
not really much worth keeping in there actually
should have ripped them at least
eh there was nothing in there shadow had watched in the last 10+ years
fair enough
I've been told I can't get too much into this in this chat, but one word, MakeMKV
well guess the bamse vhs and dvd could have been worth something :P
we literally have two blu-ray drives in our server to handle the ripping and etc lol
so eli.... how do you handle region locked blu rays???
if that is even a thingy anymore
NAS handles the storage and server does the hosting and encoding work
For UHD Blu-ray region encoding is a thing of the past
for older, I can't get into that information in this channel
fair
shadow is just hoping they did not shoot themselves in the foot by getting the kara no kyoukai blu ray box set
Needless to say though, we always try to get the actual region we live in so we can play them in consumer blu-ray players though
But also Blu-ray region wise, US and Japan are both Region A
where does EU land???
the tricky bit is if they come with english subs for a Japanese release
UK is region B, I imagine EU is as well
Can you not export the subs as an srt?
yes you can
^ according to reviews and info on the listing they come with english subtitles..
just requires more work with MkvToolsNix-GUI
I was gonna say, surely it's just a timestamped text file. no need to get more complicated than that
Depends on the release
some Japanese Region A Blu-rays do have English subtitles, some don't
i hate when websites make it super difficult to find the settings because they want to be different.
I'd recommend checking blu-ray.com for info

