#general
1 messages ยท Page 756 of 1
Hey @opaque flax
Cant miss great games tho
Donโt give up .
Can't miss life either ๐
Donโt forget to mention stressful aswell . Hahaha ๐ or probably thatโs just me .
Gaming is also good. Burning yourself out on one thing that you really like isnโt a good idea
on the topic of video games being a waste of time: i read something that intuitively made sense (no SOURCE??) basically there an argument that humans should spend their time doing something for work, health, and hobby. spiritual too but i would tack that in with health. i say this because theres something positive about having a hobby to deload the stress from your brain.
Balance
@strong cape use ./verify
Last night I got the jr pen tester certificate and it feels so good knowing what they talk and how I understand what they talk about . Nmap,msfconsole are my best friends now hahaha.
congrats!

without the dot and with your token
sigh gonna have to buy more of this artist music later:
Did shadow receive her rare anime video collection yet?
Stopped for fries and mayonnaise I bet
stuck as it has not moved since 05:40ish local swedish time
or well it might have moved
just no new updates from fedex
i need ideas for graduation project related to cybersecurity
pihole to look at what dns requests computers that use it send and how many of those go to weird places
dossent something like this exist ?
i think this already exists
yeah so??? you can still do research on that and propose interesting information
Muiri is stuck in my head forver.... ordered Vegan food
should i even say it lol
And I'm not even Vegan
shadow is so far gone into the none vegan side of things that muiri dislikes shadow stance on food
im anti vegan
i only eat the bad animals making vegans starve ^^
dog meat >
Weird how unnecessarily contrarian people get about food preferences
People just being people.
this is still pretty much civilized .. ask about editors or distributions, then you see the server burn ^^
Gave +1 Rep to @jolly aspen (current: #216 - 34)
im wondering what word triggered the +1 rep
I think YAGPDB is a bit broken
pretty much
civilized
ask about editors or distributions, then you see the server burn ^^
cough vim ๐
ask about
Gave +1 Rep to @jolly aspen (current: #210 - 35)
this is still pretty much civilized ..
wait what was it
Damn, Steam updated their download page
then you see
The server burn
nano 
what words trigger the +1 rep ?
this is still pretty much civilized .. ask about editors or distributions
Thatโs what rev and I were trying to find out I think
yes
Gave +1 Rep to @knotty cargo (current: #646 - 8)
braaaa
probably just scrubz messing with the bot
@knotty cargo thanks
+rep @half girder
scratches neck got anymore of that rep?
The server burn
+rep @cloud quiver
sooooo @twin ridge no rep for me ?
waits patiently forโฆ
Ask
About
lemme tryyh
admin
^^
meanwhile some admin is messing with us and shadow +rep'ing people
much
Well I know that lol. Meant, I never seen em before
much
by that logic you have disociative idenity disorder and work for tryhackme
much!
Gave +1 Rep to @boreal scarab (current: #29 - 338)
much!
when the announcment appeared on my screen it caused a lot of flag
oh ey the soc simulator is out
its called simuletaaaaaa
test 12
Uh, teams?
been testing the soc simulator a bit as a room tester
enjoy people
it is confusing and hard to start but good learning experience
i want to become a hacker on soc simulator
we are a teem of 4 haha I can't convince them to do it ๐
Anyone wants a hacking service
oohhh...
What like?
@nocturne spire
DM me
hahha
hi
Whats with someone about to be banned and me just opening discord
Prizes for the top three teams include
1st Place: Free TryHackMe for Business subscription (up to 10 licenses) and PlayStationยฎ5 Digital Edition Console ($4,500 value)
2nd Place: Free TryHackMe for Business subscription (up to 10 licenses) and Nintendo Switch or Oura Ring ($2,500 value)
3rd Place: Free TryHackMe for Business subscription (up to 10 licenses) and Raspberry Pi or Hak5 gift card ($1,000 value)
Wow, them prizes.
Give use a head ups next time
Looks nice
I need a team
Gonna get some clarifications, because I don't think its 100% clear
for my team i choose Linus Torvalds, Steve Wozniak, Ghidra, the NSA, and APT1
general question will this knowledge be transferable, even if you don't use the same products ?
Well I ainโt a blue team guy personally, but I can try
Team frenchfry
Hello guys i just started any tips for starters?
aint winning, so im not excited
Yes?
Donโt give up .
Did people actually win stuff from advent of cyber?? I participated finished all the challenges and havenโt heard anything. They had all those prizes and now thm is doing another giveaway
You can start with this pathway ๐
https://tryhackme.com/r/path/outline/presecurity
Cyber security is often thought to be a magical process that can only be done by the elite, and TryHackMe is here to show you that's not the case. Anyone, with any experience level, can learn cyber security and this Pre-Security learning path is the place to start.
Gave +1 Rep to @steel iron (current: #2612 - 1)
All winners were E-mailed.
Be consistent. Persistent and have fun
how's everyone? I been away for awhile
Thanks
Uh ok..yag is sick
should have called this unsecure ๐
it's 1854 hours and I wanna go home from work
Hi, what rooms would you recommend for linux priv esc?
Why ๐ ?
idk what is presecurity ๐
Gave +1 Rep to @cloud quiver (current: #2 - 2326)
You should. Whats keeping you from going
Oh wow
Introduction to security ๐
that rep machine going brrr
incident response
lemme get some ")
Enough replies..
And I think it works!
No that room already exist we need another name ๐
this room is awsome
Incidents come and go...leave it to yoir manager ๐
Iโm trying here
I want to know what it is
well, I am the senior responder, manager just needs to approve what I am doing
@twin ridge thanks that was helpful
You need all the bugs to beat me. ๐
What is presecurity ๐
Gave +1 Rep to @modest thicket (current: #348 - 17)
๐
i think even spaces give rep 
what is presecurity ๐
Ehh...ikik been there done that. I recently moved from soc to prodsec. Life has not been this much better
Gave +1 Rep to @jolly aspen (current: #206 - 36)
Security ๐
This room made me realise i need to understand basic linux programing interface (C programing)
Security ๐
I have a question is there any way to changes the site language i've been using tryhackme for 6months now but i think there is some words that I didn't understood in the begining .
I just need to push the PR and then it's sleep time
Not officially.
hmm it didnt for me
ะััั ััััะบะพัะทััะฝัะต?
You can use browser extentions, but all answers are in English.
i like some guys' way of vision
Yest
English only please.
ah sorry this is not the same room
Did they plan to add language option in the next update of the site?
aaaand bitbucket has issues, so PR is tomorrow
yeah theres 2 with the same name
I don't think so, and also not really clear.
Are you new to security and not sure how to start? This pathway will give you the core skills required to start your cyber security journey.
Oh yea i might try that thanks
it's this one
Gave +1 Rep to @sick lance (current: #1 - 3278)
Im taking a wild guess on what this means. With my 300 ish streak on duolingo - it means "russian anyone?" Correct me if im wrong
I dont google. I learn by conversations and duolingo
Yes
I wish pentesting simulator
Never felt this happy 
Russian is so hard
I wish pentesting simulator
I bet you wish "pentesting simulator" cybervenom
Who will participate soc simulator. Can I join your team?
So every challenge room on the platform? ;D
What u mean
Every CTF is some sort of pentesting simulator, no?
Ur right
Indeed.
But I need it like real life someone tell me hack like that and then we have team and do some hacking
In this case I recommend you look into bug bounties through sites like HackerOne. There, companies but bounties, often money, on vulnerabilites on their website.
Try bugbounty. Legal and stay inscope
Gave +1 Rep to @granite narwhal (current: #705 - 7)
plus, attackbox is always there
So you can attack real services and maybe even get paid for it.
bugbounty
Gave +1 Rep to @pliant cairn (current: #367 - 16)
Bot is botting
Wow, at this stage it's just anything with a y?
Let me finish the path and then go to. The bug boumty
Gave +1 Rep to @pliant cairn (current: #348 - 17)
Is it giving rep for saying "bug"?
did that really need a ping
bug
Y
Ok, anything with a y at the end.
smokey
can someone respond to me with what is it called when hackers find a bug for an organization and get paid for it?
nope
This is buggy
bug bounty
Neither.
Gave +1 Rep to @modest thicket (current: #329 - 18)
YEAH LOL
Y at the end. So funny bunny runny
its probably that
bug bounty
boy
Nope didn't work
bug bounty
Gave +1 Rep to @sick lance (current: #1 - 3279)
I'm on cool down
๐ญ
huge skill issue on my part but ethical hacking is too hard ๐ซ
Bug
Not if you learn.
Us moment.
yeah like how do you even find bugs
Let me finish pentesting and be professional on it
Bug Bounty Hunter
I've tried for years, read so many books, tried different sites, etc etc, I don't know what to do honestly. I couldn't hack a potato windows xp that hasn't had updates in 9 years
Use a magnafying glass, best place to look is under rocks.
Gave +1 Rep to @modest thicket (current: #320 - 19)
Lift the rock. Under the bed of a typical dorm. In the cracks of the ceiling. They are everywhere
Wow, you really didn't learn EternalBlue?
I'm glad to see we're still memeing
what's that
You would've come across that at some point, having read books realted to the subject
Big big bug.
Ms017
boy...
uy
bounty is good.
Gave +1 Rep to @mellow gull (current: #83 - 91)
i dont think we are talking about those type of bugs

so are you guys taking a look at the soc lab??
Bazinga||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||||โ||_ _ _ _ _ _ _ ty
Gave +1 Rep to @sick lance (current: #1 - 3280)
Eternalblue is basically an old exploit which allowed an attacker to get access to all the devices connected on the network by exploiting a misconfigured implementation of the SMB protocol on Windows.
Sifu music goes very hard. I feel like doing kung fu. I don't know any kungfu.
Presecurity ๐
Gave +1 Rep to @modest thicket (current: #307 - 20)
Presecurity ๐
Gave +1 Rep to @jolly aspen (current: #201 - 37)
LOL
but that's not around anymore, right?
Presecurity
Gave +1 Rep to @jolly aspen (current: #194 - 38)
@sand trench Were you the person with the list of good security related blog sites?

Gave +1 Rep to @sand trench (current: #4 - 2061)
It is.
where tf was that rep trigger
think that was scrubz or shadow
Security
oh, securi"ty"
Itโs presecurity with the emoji
I've read these plus a book called conf!dent cyber security
i could not hack a machine to save my life
Gave +1 Rep to @sick lance (current: #1 - 3281)
systems which haven't been upgraded for 9 years?
I'm loving this rep bug it's so funny
hello guys! aside from the competition, is there a way to participate in the new SOC labs solo?
Presecurity ๐
@shut hawk here is shadows exported rss feeds list if that is what you are after:
Have you seen how many airports who use XP as their OT/IT?
perfect TY
Did you read or just turned pages?
no problem jayy
Damn, I haven't actually. How interesting.
I didn't know anyone in the world still does
I read them, but it seems like either nothing worked, was outdated, or that it simply wouldn't work on an actual target
scrubz might have some additional sources that could be added too jayy
Like if you gave me a machine I could not hack it
Blame the firewall
Cool new feature that a premium membership doesn't cover, paywalled for businesses. Gotta love it.
9 years is nothing
I personally have seen and work with a bunch of legacy systems that use super outdated and vulnerable versions of windows
whats wrong with this, there's no information showing right?
truly, what a shame
When Crowd strike fucked up, some went back to Windows 3.1
That desperate ๐คฃ
I mean, it was a choice between something and nothing I guess
but what do you do when the systems are all up to date, etc, and your job is to hack it? Do you just see the latest windows and go yeah job done
You can identify that it's an older windows type by the file symbology on the webpage
Fair amount of Osint on this board
Gave +1 Rep to @mellow narwhal (current: #307 - 20)
but how would you even hack this place? without knowing ip etc
I can say, it was also broadcasting an ssid
Just because everything is using the latest version doesn't inherently mean that its not being used in a way that isn't vulnerable
There's an entire process called the CKC Framework that explains this entire process. First step is recon, always.
or without doing something super obvious like sticking a usb in their computer
is the soc simulator free or do i have to pay for some of the labs or modules
Many, if not all, ICS systems run on legacy software, and since they "shouldn't" connect to the internet, only communication is done internally (sensors and actuators) they're normally not updated
fly a drone in there thts got a malicious usb-drive mounted on it. fly the drone into the server closet. this is theoretical simulation for ethical pen testing. with permission
Quite often misconfigurations cause vulnerabilities, even on up to date system
I'm surprised that hackers didn't attack it right then and there
Stuxnet is a wonderful example of this.
I tried to study this for years all through school/college, now I've got no future because I focused soley on this only to realise that I can't do it ๐ซ
If you studied this for years and don't know about BSSID discovery I don't know what to tell you, if I gotta be fully honest.
Relax. And try again. You can do it.
How do you hack an ICS system if it doesn't connect to the Internet?
Think stuxnet.
You go to it.
where are you tripped up at
what qualifications do you have. consider networking/help desk first?
Social engineering
Or use a method that you can control, or set up something that will look for something, then if it has it, attack, if not disarm.
Supply chain attacks also
I have a comptia+ networking certification
But initiating any form of communication with the machine?
you arguably have the most difficult of the trifecta. you can be a network/security tech
Gave +1 Rep to @gleaming grail (current: #2612 - 1)
Oh, that required physical access right? Unless I'm mistaken
Stuxnet kind of spread is possible with a 0day or 0days. Considering the current security posture of many companies its not that simple. Social engineering is best bet.
Yeah
Some industrial plants use modbus traffic which is built with zero security.
So you can pretty much MiTM it.
Gave +1 Rep to @mellow narwhal (current: #294 - 21)
Yep. easiest way into any machine
I would not know how to do any of this lmao
do you want to know how to? if so, think of the right questions to ask.
Ohhhh modbus, I did a pcap challenge involving that once
And yes everything is plaintext
Would not have been possible without someone inserting a usb where they're not supposed to.
well I kinda wanna do ethical hacking, but something always goes wrong, and it just seems impossible to actually hack any up to date machine
I've been trying to hack my laptop for ages
Yes, because that sort of communication is more focused on being available than confidential.
Thatโs the fun
Try your hand at #1312113121040535656 4, it's an up to date machine.
Stuxnet is complexed and advanced, the story behind it is so rad it deserved an episode on darknet Diaries
Thats what happened in most cyber incidents
I'm already on the network, I know all the critical info of the laptop. despite these huge advantages, I can't get anywhere
It gives ARPANET vibes
Yeah, but the method of delivery was more important than the execution
Do you attend on tryhackme paths?
Is it a Linux?
ethical hacking is an advanced role. If you want career advancement start with another Cyber discipline.
I saw those, and I have looked at pretty much all the fundamental topics
Gave +1 Rep to @mortal acorn (current: #1291 - 3)
maybe to hack up to date stuff you need to buy some zero day exploit from shadow brokers for five million
Seriously, do an AOC event. Then start the presecurity path. Youโll catchup fast
Gave +1 Rep to @gleaming grail (current: #1712 - 2)
Well, this isnโt what most pentesters do. Many of them wouldnt be able to โbreak intoโ a well configured and updated laptop.
windows 10
YAG is making it RAIN today
Honestly, its possible that the system is secure lol
Is it serving anything? Any services?
However, check the version, and if it hasn't been updated, try searching for CVEs on NIST or exploitdb
which date after that version
I don't think my laptop should be secure, there's no antivirus, no crazy firewall stuff, defender is disabled, it's probably not completely up to date
This would be useful
Because generally, Windows updates are for a reason, so there'd be some form of a vulnerability in your current version
Do you feel like its not sticking onto your memory or is it the modus operandi that u dont figure out?
There is so much help you can get man
Or woman
How would you find out exactly what os version the laptop is running if you couldn't access it directly? I've tried on nmap -o or whetever the comand is, but it returns very basic information at best
-A
Man...
First step. Enumeration, learn what they do and it will make alot more sense
I think you should start from the beginning, this is some knowledge you should already have with Network+. No need to hack your laptop first.
i used the nmap gui so I wasn't entirely aware of the command
โOr whatever the command isโ speaks volumes. Learn what they are and do and it helps tremendously
I start to doubt if you read anything at all in the first place. If i have to be very honest with you
Ping
Not free, and you can't purchase access without being a business and buying multiple seats.
I tried my best with nmap, the gui has options for OS discovery etc
which I used
Bro uses zenmap?..
Isnt zenmap deprecated? I last saw it when i was a kid lol
Yeah it is
watch these vids. https://youtu.be/4t4kBkMsDbQ?si=PtJe9wwrdr_b3Lxb ~~~ https://youtu.be/JHAMj2vN2oU?si=U9f8oFyFGn0xqPGr
Learn Nmap to find Network Vulnerabilities...take it to the next level with ITProTV (30% OFF): https://bit.ly/itprotvnetchuck or use code "networkchuck" (affiliate link)
**This video and my entire CEHv10 journey is sponsored by ITProTV
watch the entire series: https://bit.ly/cehseries
โก๏ธSupport NetworkChuck: https://bit.ly/join_networkchuck
โ...
NMAP Full Guide #hackers #nmap #hacking #hackers
Full guide on Kali Linux https://www.youtube.com/watch?v=dJjQoxwyNCc&t=101s
All links I used in the video:-
https://nmap.org/p51-11.html
https://nmap.org/ncrack/
https://nmap.org/ncat/
...
don't think I've used zenmap
The normal version has that too. ^_^
Zenmap just uses nmap under the hood.
-sV ๐
ah yes this one is familiar, I used this
Zenmap is the official cross-platform GUI for the Nmap Security Scanner. It is free and runs on Linux, Windows, Mac OS X, etc.
Zenmap is a GUI, but
its basically just nmap command structuring
That's version detection, OS detection is -O. ;)
I must be wrong in that case, I'll load up the one I used
ah, right.
-O for os and -sV for versions
Yeee
-A does both
Is there anyone among you who knows how to crack game cheats?
That I didn't know
-A is aggressive.
I'll have to remember
A for "Aggressive"
Ah yes you're right, I didn't see zenmap under the nmap part, its been a while since I used it
so yeah I use zenmap
I generally just go sudo nmap -sV -Pn -p- <ip> for most cases
โฌ๏ธ โก๏ธ โฌ ๏ธ ๐ ๐ข โฌ๏ธ
50% there
-p- checks every port
i thought it was something to do with the thing blocking the request
so it bypasses it somehow? probably wrong
Disable ping probes, scan all 65535 ports
where can i sent pics
We don't do game cheats here or software piracy
pff okey
@fossil anchor please do not solicit business here. We are not hackers for hire.
If you continue to discuss it here, you will probably be removed due to our rules on unethical and/or illegal activities
What are ping probes?
When you ping an IP you send little packets to it
Man, 10 degree weather, in short sleeve shirt, not bad at all.
Right
Try Googling that, actually nmap has maaaany interesting flags that not everyone knows about
So itโs an interesting thing to research
It skips host discovery. Usually it pings to confirm that its up, but some firewalls have detection rules for that, so it assumes that the host is up without sending ICMP ping packets.
-Pn skips the ping scan, basically nmap won't confirm that the target can actually be reached before starting a scan.
-p - tells nmap to scan a certain port range, and the second - means all 65535 ports.
is that C
To anyone that has read books on cyber security stuff, how much of the content actually worked? Everything was older versions, different commands, I could barely get anything working even in practice
Most of it under the right circumstances.
By default nmap will only scan the most common 1000 ports, correct me if I am wrong.
My favorite is -sC --script vuln
Correct.
think so, yes
Definitely, NSE is useful
I tried to buy the most popular books, did you happen to read any that I sent?
Did you send a picture or something earlier?
here
Might be a dumb question, but is the soc simulator competition free to enter?
Apparently needs to be a company thing?
๐
Have to be part of a team dashboard, not sure if that's fully company exclusive
The Soc simulator has one for subs, one for business and another for no idea.
Nowhere until you verify with the bot
What tool do you prefer for finding web pages and subdomains? I've heard gobuster, ffuf , dirbuster, sublister
where is the bot? ๐
I see, Iโve got some work colleagues, we would like to participate but not sure if we will get the support from our company
Be careful with the difference between vhosts and subdomains
My personal subjective preference is ffuf. I don't think it matters too much tho.
google time ๐
It can search for vhosts, but it's a bit more tricky then with, let's say, gobuster.
@sharp citrus
Vhosts are a http thing, subdomains are dns. They're often used together, but they don't have to be
Or just do do /verify
I've read two of these and only one of them would I consider "popular." If you want effective resources I would suggest content published by Packt, there's a very useful book on using Kali written by Glen Singh that's very informative.
Ohh, out of curiosity, which is the good one of the two?
Gave +1 Rep to @mellow gull (current: #82 - 92)
Topmost book on using Python.
Ohhh interesting
The good books I've read are conceptual.
Exploits go out of date, so do commands, etc.
The concepts don't. They evolve a little and we get new ones, but almost always building on existing knowledge
Learning the methodology and process of discovery - the innate curiosity that comes with this work - is extremely valuable and helps to build an essential mindset.
The Blackhat Python book is good now it's updated to Py3
If you get a Py2 copy, run
why would you ever buy a py 2 lmao
run in what sense
For people who want to get into security as a career, I really recommend reading about theory
Run away
It must be a big skill issue but I had huge amounts of trouble with this book, it would often just make you copy out tons of code, I wouldn't know what the code did, but also, all of the environments were outdated, I could never get the code to run etc etc
Python 2?
It's an older edition of the book
People buy books second hand all the time, I'd recommend it for a lot of things
I got a lovely second hand book today
The price for some books is awful.
40$ a title for half the stuff in cyber security is rough
i only buy 2nd hand cars ๐
what im i missing here did grep "HTM" access.log but don t see a flag prob blind lol
To build on this, learn the context security happens under. What are the business drivers? How do you fit into the business?
How does security actually work? Why don't businesses put the "proper" amount of work in to make sure they're never hacked?
#room-help please
C'mon scrubz, at least say please
I mean, stop fixating on past failures and start on a THM pathwayโฆ
- this. If you spend more time lamenting over past failures than trying to course correct and improve, then of course you won't make any progress.
I haven't liked a lot of coding books
A very good portion of hacking is failing, then failing, then failing again a dozen times before finding something that works and running into another wall to bash your skull against until something else works and so on
F
Itโs fun!
i liked clean code ๐
physical books are so 2015 ๐
should give it to my friends to cuz they write spaghetti
tryhackme is set up in a pretty fun way does remind me of duolingo ๐ค
Jokes on you most of mine are 1995 or older
Linux Programing Interface is the goat you should buy it ๐
that explaines why you are a SENIOR mod
jk
I wasn't even born then!
how did you get those books then?
Second hand
1995 was 30 years ago
Various stores, events, etc
Correct
thats very old
oh i just had to buy then for my first cs year but was just a waste of moeny most of the books were useless now i just do online payed cources on the side and buy a book when it intrests me

big fan of rss, I'm going to have a look
some might call it half of a life time
apparently 2 of the feeds in that file does not work nicely with freshrss ;-;
i tought the witcher 3 was released a while back was 9 years 
yeah enjoy.... just be careful to not nuke your already imported feeds if you import that file
where can you see those roles bind to your progress btw?
Is it possible to form a team of five for this challenge on THM https://tryhackme.com/r/resources/blog/soc-simulator-competition-2025
that's for the advice, but it's not my first rodeo ๐
hover
the house is empty and the tunes a blasting
you wouldn't know if it was empty
Gave +1 Rep to @finite basalt (current: #101 - 76)
I want this bot INCINERATED
...what did that trigger on?
it seems to be having issues today
yummers
Gave +1 Rep to @naive violet (current: #3 - 2240)
ok nvm thats new info
Empty
Gave +1 Rep to @wooden totem (current: #180 - 42)
Yep lmao
Wild because I used a single ty the other day and it didnโt work
maybe it was made for variations of ty so it accepts tysm and stuff, but they didn't think of actual words that have ty
Prefix is unusual
the bot got updated today or something
It doesnโt work for justโฆ
Security
Gave +1 Rep to @wooden totem (current: #179 - 43)
Holy shit, that didnโt work earlier
Are you trying to ty it together
Gave +1 Rep to @wooden totem (current: #175 - 44)
if thats the case maybe "thx" also works?
Thx
Gave +1 Rep to @wooden totem (current: #173 - 45)
More ammo
Maybe thxs works too?
try by adding letters on the left side of thx
Rtyr
You try
you gotta reply btw
๐
cooldown
Styl
Ahhh ok, thatโs why some werenโt working earlier
๐ญ
You have to reply to a person
We already know it doesn't work if there's text at the end of the detected string
So rhahdjalthx would work but shdhahthxshsha wouldn't
life stuck at pink color
I dont remember if only at the end was tested
As long as there's an empty space after it it works
tytest
It can be anywhere in the post otherwise
idk if im onnn cooldown
I was supervising the experiment, I don't have any remarks on a test that is specific to only at the end characters
https://youtube.com/shorts/Mbh8n3sFvo0
@blazing granite
This table loved the 08 so much they wanted to try the 05! 05 was SINGING!
#fypใทใ #fyp #pov #wine #sommelier #restaurant #food #foodie #lasvegas #trending #drink #asmr #luxury #wow
Ha I knew of the soc simulator before they even announced it
So if I was to try thrifty
Gave +1 Rep to @mellow gull (current: #82 - 93)
Yup
Yeah that's scuffed
Hmmm, to drop out and get a better job or to stay and suffer for the rest of the year 
what about thisthx
Gave +1 Rep to @mellow gull (current: #82 - 94)
none of the triggers do
fifty fifty
Then of course it also doesn't matter if it's at the end specifically
It can bethx anywhere in the post
Gave +1 Rep to @wooden totem (current: #170 - 46)
Well if I drop out I have to fight for future salaries
it just needs "no visible character" after it
Yup
As long as a space is appended at the end of the string
It can be anywhere as long as it ends in thanks ty and thx
there's your answer, that'll be 150 dollars
โ ๐ต๏ธ ๐ค
say the line @mellow gull
But I am currently underpaid and overworked
hey wsp
it seems there is a search for 3rd option
what are you talking about
I'm on cooldown ๐ข
Possibly, but I am graduating in December
I tried Chateau Latour twice. It's a great wine, but I've never had that vintage.
I see we're not on the same page here, my line after โ ๐ต๏ธ ๐ค is always "absolute convolution"
I will add this to my knowledge repository
Let's give it another go
there's your answer, that'll be an additional $25 charge
Guys I need immediate help please if someone can find a lost phone with no wifi help me
Not really
it's a very rare moment, special occasions
Contact the local law enforcement
I'll be prepared next time. I won't be defeated again
It will take too much time i for real need quick help
Contact your phone service provider
if you have the option find my phone enabled, the phone will transmit location data to other phones in proximity without wifi, you gotta log in on another device
Gave +1 Rep to @whole topaz (current: #2614 - 1)
I'm gonna do something to you
We can't know if it's your phone or not therefore we can't help
Itโs my sisters phone I swear
those are literally all the options you have
Again, go to local law enforcement
Ok thanks yโall
are you allowed to munch those
Looks like you're forking over $1900 lol
Wait, is this a MANGO MANGO๐ reference ๐ฑ๐ฑ Chat! This is a MANGO MANGO๐ reference ๐คฃ๐คฃ๐คฃ. Boi, you won the Internet meme of the day ๐๐ซฑ. Only the Balkans with noradrenaline will understan
is that ryan gosling
Yup
it's not a cheap wine, but the price depends a lot of the vintage
what's the bounty
Gave +1 Rep to @knotty pendant (current: #1713 - 2)
Idk
give me 2 cheeseburgers and i'll do it
cool
There
hello
Donโt tell mom
Hey guys, im new
I'll tell Dad instead
NOO
JASON web tokens room finished
๐ฅฆ
๐ฆ
how are you?
No time for feelings
More points
It's a cat Sakamoto in red scarf, from the hit manga Nichijou (the scarf allows him to speak)
Hello everyone. Glad to join and just have to take a look around now and get familiar with the lay-of-the-land here ๐คฃ
please don't break anything
IT will be difficult, but I'll try....
bro is into something ๐
Gave +1 Rep to @knotty cargo (current: #596 - 9)
Great advice wiseone
bot liked the cyber security part
Gave +1 Rep to @wooden totem (current: #169 - 47)
I think itโs a cape!
@blazing granite https://youtube.com/shorts/tpwFZIaDMBs
Why'd he light the candle?
When I try to run a command like 'whoami' on powershell-client, a task is executed but I can't see any output in the screen. Any idea will be appreciated.
you're into wine now
@blazing granite forced me to be! He held his sommelier gun up to me!
black hat hacking in style

What's "powershell-client"?
There's starkiller and powershell-client. The second one is a shell command.
Right, so within Empire? Within Starkiller?
Empire strikes back?
is that calling a macro ?
Wdym
i mean its skipping calling a macro
I think a way to get destination addresses is dynamically getting them in the runtime
he try to learn assembly
Which is hard. This is a common problem in obfuscators.
Screw polymorphism. I can't make my binary work.
No, it is an instruction in a legit binary
Instead of hardcoding the destination offset, it's using registers to make jumps
i thought its jumping to an address which has a macro
so it says skipping indirect calls
oooh wait indirect calls
Quick dumb question I probably know the answer to but would I be completely lost if I went into the soc simulator only having done some of the soc analyst path ?
Nah it's my obfuscator
assigning addresses to a register right
Yes, and jumping depending on that register
That's why we can't guess where it is jumping to without running the binary
Causing problems
Frustration is real
isnt r supposed to be a refrence for a 64 bit register ?
there is call or so in programing thing. and heap does not know to use it ๐
so the 8 must be a register right
r8 is a register
what ive taken in uni about registers go like rax, rbx rcx
oooookayyyy
learning assembly is fun
i want more of it now
Oh let me make you less interested real quick:
https://docs.oracle.com/cd/E19641-01/802-1948/802-1948.pdf
You don't have to read all of them tbh
Just mess with assembly and it will automatically be placed into your brain
a short one ๐
ive taken many of it in uni
to the Protection Model Instruction part
which is, less than half of the book 
I get really bored when reading books
what happened to the advent of cyber prizes? have it been announced yet?
not more than i do
But when it is about preparing something you can use, you read it with ease
Matter of interest basically
like a project
I think they sent a mail to winners
Of course, emails have been sent 3 weeks ago
Nice seeing you all around here again
Ok back to work, need to fix this stooopid indirect calls
where do u practice assembly ?
thx
Reverse engineering
Gave +1 Rep to @topaz topaz (current: #330 - 18)
nice
Does reverse engineering also teach you about writing assembly?
I'm very far behind this knowledge so I'm wondering what to expect
It does help but writing assembly is another thing
There are many options you can use when writing assembly code
So you need to choose an efficient solution to a problem, and create a proper structure
@timber galleon Nice to see you in here ๐คฃ
๐ welcome
๐ Unmuted himira_2
Yes, you pinged everyone.
wild
I WAS LITERALLY ASKING SMTH ๐ญ
ikr
yeah
pinging a server with 250k members...
i see so
oh. yeah ofc i did so.๐
and the amount of carbon footprint u make (jk jk jkkkkkkk)
not mentioning the 0.0001% of them who thought their phone is on silent but it ringed in a senstive area
Or it's like, common bot behaviour.
Why don't you ask like the rest of us human beings? ๐
Lol
At work I have my brightness set to the Lowest level possible with blue light filter on 24/7, my coworkers clown on me constantly
https://tryhackme.com/r/room/osimodelzi
Task-4
Hello, normally pictures like these look neat to you, but they look like this to me. What do you think could be the reason?
I feel that
Right? I like making my displays look like the kindle kind, almost as if it's on paper
yo ?
Lighting in the office doesn't get in the way so why not
always lowest possible not healthy too
What do you mean
is math useful in this area of expertee, in your guys opinion
if u find it hard to read something on the screen, its unhealthy for eyes
This shouldn't taste so good
I don't reach the point of straining no
I can't see the image
If you're on dark mode some material may not be 100% optimized
just above that is ideal
Awooooga
Gigachads never strain their eyes even on turned off monitors
but it did anyway
Cappuccino?
Hot chocolate
@hasty sand im ur biggest fan! conragts on getting #1 on tryhackme
Fr
I'm ass at math and I'm still here. So not really, but there is probably a specific field in CS that requires it
Still awesome
It was also 40 cents
It doesn't have to be, no
hmm wasnt he the #1 already ?
So cheap as hell
Wtf?.... You made it yourself or something ๐ญ
Nah
Bought it from the cafรฉ shop
49 cents
For a few years at least
40*
Like 49 cents in the Philippines?
Asian country?
Europe
We steal wallets
Wait I think I know
Take a guess
Albania?
No
Romania
Ayyyy
Hahaha I lived with Romanians, we have lots of common words you and I
Like?
I'll translate so it doesn't break the rules but kouti(box) kalorifer(radiator), tsigar(cigarette), fasoli(bean) and many others
Yeah kinda similar
wait fasoli is an arabic word
That's crazy
The tiktok 12 hours ban was crazyyy tho
squid game!! ๐ฅ ๐ฃ๏ธ
Hahahahahahaha what? ๐ญ
ur pfp
๐
Oh nooo pal ๐ญ
My grand father was from Romania
yeah the goat
I want to see his stolen wallet collection
wheres he from
I know you guys sell tons of cheap leather wallets and they're genuine
Everything here is cheap for Americans
Trust me not just Americans
Or even Europeans that aren't in the balkans
Prices in similar European countries for leather goods are nearly double yours
He was an honourable Rumanian Jew
Ahhh
Have you been following your streaks pal?? You've been the same level for a while. Better not be slacking.
South Florida, FL
||i didnt just look that up ๐ญ ||
There's lots of people saying he's not for real though I hope it's not true
I don't bother giving into such allegations though it's pointless
Does anyone have any info on his revshell site? I was gonna dm him for more info, but I chickened out 
@topaz topaz You talking about Ryan?
Yeah
Yea, I'm not a big fan
What kind?
I don't know who he is, but I love the malicious live podcast.
Click his profile, it's the site in his description
Tbh I get that as I've seen what some might claim about him but I see nothing malicious about him, if anything he claims to be of benefit to society without asking for anything in return afaik?
I can't consider myself not being a fan of a person who claims to help
Yea, there is that, so maybe not all bad.
I know what you mentioned but I'm asking what kind of info
I don't think he'd respond even if you didn't chicken out
I love the offering to help as long as you are truely helping and not confusing or giving bad advice. I understand advice is just someone's opinion though but still.
Ohhh, idk more about what the site does and its purpose.
I'm not too well informed on Rev shells yet.
Bad advice as in?
advice damn
I think the THM modules would help you many many times more than dming
Just some things he's said over time. Don't want to talk about him without him being able to defend himself.
Fair, I get that. Differing opinions are always respected
Ohhh is it similar to how in the Cyber advent where you took over an AI, after figuring out that it can send pings back? Appreciate the response yah 
Yes
You didnโt get a chance to win a trip to defcon D:
Kind of but it actually ends up being a reverse shell cause you make the AI use netcat
It is a command injection tho. Ai prompt injection
not a waste if u learn from it!
I was gonna go regardless so
I think you have to gain a lot from it
Hello everynyan
AoC2024 was beautifully made and had material from many different topics
Hey pal nice seeing you
I wish I were a breeze
Formless just traveling everywhere
Come drink with me and my group! On Thursday night we get a limo or party bus, go to hofbrauhaus and get drunk, eat good German food and have a good time. Then Go back to the hotel and drink more
This reads like a copypasta
Ok
That's fair
So, I'm going through a CTF and I don't understand where's the tool located in attack box, also dunno where to ask that :D
I can install it but I think that it's a bug
We always try and find someone new to add to our group every year
Is that defcon?
Yeah
Sounds cool mane
what are you talking about? I hope to join you but don't think that I'm gonna be able to :D
Oh bet. Last year I found a guy who was like โIโm locked out of my room for a few hoursโ cause he didnโt have a key. I invited him and it turns out heโs a senior software dev at msft ๐คฃ first time at defcon too
Are defcon tickets still $2k and up? I tried finding tickets for the events, but I failed lol.
Defcon tickets are 400
hmmmm shadows answered questions spiked today....
just as shadow is startin to ramp up their ctf beating :D
Anyways itโs a good time. Itโs a weekend long party with hacking in the mix
That's what I assumed, is there any big difference with black hat and defcon?
2k maybe with accommodation included
Black hat is for the professionals defcon is for the hackers/enthusiats. also defcon is more partying than black hat and black hat is professional and for companies
Danke
He did specify tickets
hello
Fair. Thereโs lots to do at the convention center too
Appreciate the explanation! I was curious on going, tryna build up connections and learn more. I've heard that doing the villages is the best way at defcon
Defcon is hacker pilgrimage
You wanna go see talks? Go do that. You want to solve a complex cryptography puzzle that takes the whole weekend ? They got that too
If you want to get hands on training and learning? Villages
Hey!
The easiest village to get started with is physical security and lock picking
I like doing challenges. I find a ctf and get free swag
Getting connection on such event is soo cool!
Swag is also awesome but you can do both sometimes
noted.
Lockpicking is ๐
I was chilling with the good fellows at the malware village in one of the other cyber sec conferences I attended, that stuffs good too
LOADS to do though, and loads of walking
100%
Have entire lockpicking kit wit a lot of locks at home :D
bro your name is taller than my life + hrru?
Oh shoot i found the issue
Lockpickers unite ๐
I didn't know virtual function offset table is stored in .text section which is meant to be for code section
Thereโs also lots of training to be had. For example I learned how to hack one of those door buzzers you see in apartments
Yes! (What does hrru means?)
For sure. But like I said. You get what you want out of it which is what makes it so good
how are u
You will miss things, but that's ok
The workshops are hella cool if you can get into them
I always make sure to atleast hit the up the vendor area
Peak of the conference for me
Ohh, I'm fine! Pretty good actually!
I used to be afraid of chatting with people back in the day but now look at me :D
I think I understood something in this life xD
Ahhh that's the one I'd just been to, plenty of good faces and workshops there
I think 5pider was chilling at the last one as well, Havoc C2's creator
Gimme a sec
These bad boys were circulating in the malware village
How bad they are?
When I was in line con to get my badge I saw some putting down fake 100s all over the place lol
Theyโre prob just USBs with malware on them
To like test in a sandbox
Yep, USBs with a defanged multi-stage infostealer


