#general
1 messages · Page 780 of 1
what happened if you dont mind me askgin
33B fits in 32GB?
it's a distilled model, whatever that means
yeah, they've done some cute optimizations
NDA
producted by rtx 5090
special thanks gta 6
pretty sure than not every parameter is used at the same time?
someone broke it?
ouch? that's called a discount
Buy the dip
or it's lowered quant or such
Depends if it's gonna come back
get that 10 years in
probably some packing too yeah
Like if this has proven a lot of the value is based on hype, the value is a way out
You use Jetbrainz, aye?
aye
Is there a way to get the information like this, like Spyder does?
based on hype? but but but 500B$ Stargate project that doesn't have secured funding yet!!
might be some debugger plugins
My lecturer is trying to get me to use Spyder for this reason, but I don't like Spyder.
By telling you if you do something intentional to get muted because it was done on purpose it will be long intentionally thus meeting you with equal force you think that’s a mod flexing their power? Lol wut.
Little intentionally instigating and provoking then being mad when you get smacked for it if you get smacked for it like calm down. Dude didn’t even mute you after you said that whole edgy statement
are we talking about deepseek r1? I've self-hosted it and it's pretty incredible seeing the reasoning process
This is like one of the most chill places for mods trust
Ya.
yeah, scrubz posted the stock dip from it's release
a bit slow, but i was using the 32b one so kinda expected
what hardware?
is it time to buy stock?
4090 rtx, 64 DDR5
I mean it'll likely recover
ehh, depends on what you believe
ahh nice
cant hurt to try the smallest model
Nah man, go big or go home 😄
your laptop will love you 
can you run doom?
barley
bruh
every time someone says bruh, god kills a kitten.
wait idk why I said 4090, it's a 4070 rtx
wth
lol, wut?
# Actual DeepSeek-R1 (requires 336GB+ VRAM for 4-bit quantization)
ollama run deepseek-r1:671b
funny cuz i got hurt ystrd while bike riding
I have Ollama running, I just need to download and/or setup whichever I want to use.
welp, gotta go scrape up a bit more VRAM
🤨
Was it because you shoved a stick into the spokes?
don't worry, manufacturer model numbers confuse me as well
huh?
AWS might be able to help I guess?
@polar spoke have you benchmarked the 50 series on hashcat?
I mean, I can't even link a meta quest 2 to my GPU.
idk wht tht means
not properly but we have some iffy numbers from someone who ran a broken bench
ion get the joke
oh wait it's VRAM that it wants? well, strike running that locally I guess
I dont have a 50 series card yet
ey scrubz, wsp homie
lol yeah the intel CPUs really mess me up
Going to play Fortnite then BO6...
You?
yah no not gonna use that
it's not bad
I have 4GB too.
bored as hell, im sick tdy sso didnt go to school
shadow is sticking with dolphin-mistral
Nvidia T500.
a lot of people are mistaking "not a huge jump in perf like last time" for "it's bad"
no real improvement on the raster side for a given power
bit better on memory though
it's basically an architecture and node refresh
and for that, it's actually quite good
didn't they boost power by 100% last time as well?
3090 -> 4090 was ~ 2.5X in some tests
do u play chess
4090 -> 5090 is ~ 1.5x on the high end
I feel like you can copy and paste this to almost anything
true lol
yeah but with a 500W! power envelope
I've seen frame generation is a huge problem
people still think the 4090 was a bad deal because it was "too expensive"
Not since school.
4090 was 600W unlocked
even a 4090 boosted that high will give the same perf
in case everyone forgot lol
do u wanna play a chess game
thought it was 300W
no
which is still ridiculous
it also liked to catch on fire
well
the 12VHPWR connector had issues
but that's been replaced entirely
so it shouldn't be an issue going forward
yeah, I saw the GN video
No thank you,.as I said, I'm off to play Fortnite and bo6
Gave +1 Rep to @neat belfry (current: #1718 - 2)
shadow uses ollama and open-webui
isn't 1200 recommended
but yeah, the 5090 doesn't have some "insane power draw" like everyone seems to think it does, at least imo
My machine is bugged, I have already restarted it but it still remains that way, how can I solve it?
anyways, nvidia still stuck on moar power mode
what do u do for a living?
also too damned expensive
didn't they say it was "double the performance"?
nah probably only 900-1000
https://youtu.be/EtX6xyb_4fo be like
RTX 5090 early benchmarks have finally come out and it looks like the RTX 5090 is about 30% faster than the previous 2+ year old RTX 4090 at a much higher TDP, this is very underwhelming considering that both of these architectures use the same manufacturing node. Jensen Huang claimed that The RTX 5090 is twice as fast as the RTX 4090 but nowher...
fake performance
it's all up to how you test it
much like the Apple M1 was NOT 3090 equivelant but they said it outperformed it
they're still hitting huge diminishing returns
we're doing that again
why is 5090 already out
apples to oranges comparisons are all marketing does anymore
right
not for long
when new amd gpu????
oh man, AMD fumbled that one so hard
sadly
sits here with their 7900xtx
i have no idea how they mess this stuff up every time
that sounds powerful
maybe they like being the underdog
they are fumbling their driver improvements, dev confidence, and their hardware launch
it's a mess
my laptop is showing graphical glitches from time to time and it's scaring me
cause it's an APU
what are graphical glitches
shadows laptop has not been booted up since shadow jumped out of uni due to huge mental health decline
buy a new one
well, green lines across the screen from time to time are bad™️
thats cable interference in my experience
if you are seeing artifacting that is limited to individual lines i'd assume screen or screen cable long before processor issues
I can't afford to upgrade my 11-year-old tower, how do you think I can afford a new laptop
save up
s'called life, mate
GPU artifacts typically impact entire frames or entire types of rendering
has a tendency to drain your bank account
fr
hello, is there anyone who knows how to work well with cisco packet tracer app and create lans, networks, setting ips, default gateays, subnet masks and configuring routers? id love to ask some questions
c'est la vie
can someone help me in roomhelp
last time I had a GPU die it showed similar symptoms
Just a reminder that everyone here is a volunteer and will help you when they are able.
even if you start showing that kind of issue
maybe
hoping it's just a driver issue
here or in private?
on a laptop?
the core is very likely not the issue even if it's dying
If you have questions, just ask. #infosec-general might be better because it's slower
RAM is probably soldered in
depends on the laptop i guess
nah i said maybe sum1 here knows
wants framework laptop
Is this for homework?
recent-ish lenovo
i know. i was just asking for help.
framework didn't want my money last time I tried
when setting two lans on cisco packet tracer, and then adding a router, after the ip address assigning and default gateway, while configuring the router, what ip address to assign it if the two networks using different subnet?
they kept rejecting my card
Patience is a virtue. Asking across multiple channels doesn't get you assistance any quicker.
???
well kinda same here but they have since started selling to sweden
oh huh so not same
#infosec-general is better because it's not moving fast. Answer @sick lance first though
nah, they just didn't support the whole 3dsecure thing
oh like the thingy that asks for swedish bankid when you pay with a swedish debit card???
yeah
welp that sucks
FREE DOWNLOAD: https://venjent.bandcamp.com/track/boiling-up
LOVE IS THE ANSWER Vx
Connect with Venjent
Site: https://www.venjent.com/
Instagram: https://www.instagram.com/venjent/
TikTok: https://www.tiktok.com/@venjent
Twitter: https://twitter.com/venjent
Facebook: https://www.facebook.com/Venjent/
YouTube: https://www.youtube.com/@Venjent
...
here we go again
Hiii alll
I have uploaded a machine since yesterday and it is still converting with NaN% percentage, is there any issue on tryhackme? I need to upload it asap
Hey, a lot of people are reporting this lately
I've asked some staff but not heard back
Ohhhhh noooooo since when
guys i gotta question, discord is 13+ right?
cuz if it is, why is it so easy to acces servers with adult content in it
why can i go on the internet, ignore the rules and warnings, and look at stuff!!!
like bruh, on discovery u'd see many many servers with crazy stuff
I mean there's a reasonable expectation of don't be stupid as well
yea they aint answering for shyt
I can't imagine why...
last time, i contacted discord support and got no response
im not joking, dem mf's dont care
no regulation and 13 yo can access that type of content even outside of discord easily
lies! you get a wet rock
I feel like this is really a potato
not rlly, in america, in states like texas, u cant anymore
Hi, I'm in Texas, that's not even close to true lmao
would need a banana for scale to make sure
Hold on lemme go get one
it is, when i was there, i tried accesing it and it sent a message saying to verify
n stuff
you get wet rock which is better for hole made hot food
yes, if you pick one of the like 4 major MindGeek sites, you get a warning
that doesn't mean it's not easy to access
or that somehow the regulation changed how the internet behaves
Not sure this is an appropriate topic for this environment
yeah, trying to stay in the guard rails here a bit
i mean most adult sites have that screen
Let's move to a different topic please
^
i was lttry js in texas not long ago, i got tht screen, i did an expiriment
well, i've been in Texas essentially my entire life, save for some travel
so
I've got quite a good idea of how that regulation has impacted services across the internet and it mostly... hasn't
but again
new topic
bruh, so u tellin me im tweaking?
this is not the place to discuss
yea true
coffee is like the best thing humanity ever discovered
there's better, it's just... not socially acceptable anymore
lol
I need a stimulant, not a depressant
I disagree
unless im trying to reach the ballmer peak
bro coffee aint good for ur health
Since when a beer is considered depressant?
beer is a depressant, it slows down the central nervous system
the Ballmer Peak is real
which is what a deoressant is
ask me how i know
most research suggests its perfectly healthy in healthy doses
Nah that's a lie
:p
It's antidepressant xd
Both wrong
i really wonder, i highly doubt you can reach the point with bud light xD
i wouldn't want to regardless lol
everything has a side effect
it surpesses instead of stimulates hence why it is worse for technological development unless you got ballmer peak
i agree
so you're wrong on this one
there's a reason why all ctf players are alcoholics (joke)
everything has a ld50
It does both
do show me a good paper that says coffee is always bad for your health lol
It’s the one substance that actually ingresses cells uniquely to any other. Because alcohol is bipolar so there is a unique effect on lipid bilayers
beer dosent suppress, it depresses. it has a chemical called ethenal which increases the effect of gaba in ur neurotransmitter
well, once you reach the point you drink coffee before sleep, you only drink it for the taste anyways
Every year for CMIYC @ DefCon, I do my best to fit the stereotype 🙂
i didnt say its bad, im saying it has side effects
everything that has to do with medicine has a side effect
let me tell you that
side effects doesnt mean its unhealthy. Also it only has side effects for some individuals
shadow once again raises you that everything has a ld50
Can someone help me with cyber security?
yup
depends on what specific niche part of cyber security you need help with
understandable, I mean, it's crypto, you have to be drunk to know math
pentest
well, to some extent it does and no it dosent only have side effects for some individuals, if it happens to person a, itll happen to person b
god tell me about it
So that's the reason i want to sleep after having a beer
like viagra was intended to lower high blood pressure .. we all know it sold for the side effects xD
I don't want to code or do computer stuff
you are doing a pentest or you want us to pentest you????
I can't, cause I don't know math xD
But i realised coffee really works for me
lmao
I can speak fluently, which means i can do critical thinking
Normally i can't do it
sounds like something an LLM would claim
not rlly, it can make u feel relaxed and it negatively affects ur sleep
When I drink coffee im getting so tired wow
Not true. Some ppl have higher tolerances to caffeine than others. Also some are allergic to coffee while others arent.
well I know basic math, but I dropped out of high school
I said i wanted to sleep, didn't say i go to sleep
Yeah it makes me relaxed
I am a beginner and I don't know much about pentest, I couldn't find a good source on the internet either
Also you can very well go to sleep with a couple of beers
Basically hungover
shadow heavily dislikes the taste of alcohol
on average, the side effects ot caffeine are the same. high intake can lead to anxiety attack, coffee can cause stomach upset or indigestion and u can expirience withdrawl symptoms like headaches or irritabillity, it increases adrenaline too
you heard it here first folks
showering in cold water which gives you an andrenaline kick is both good and bad for you
there are more positive affects than negative which is why its not unhealthy but again, the side effects are very much there
i made a mistake
you testing out the new deepseek model?
Tell me the good news first
so you agree with my original point?
lol
yes
I happily had 1 monster sometimes 2 6 days a week when I was on nights
tf is deepseek
so u just wanted to be a contrarian?
thanks but, my pc need upgrade for open virtual box in tryhackme. another website or wiki/book?
Gave +1 Rep to @sand trench (current: #4 - 2071)
bro i on use ai
U see this cat in my profile pic? I bet you wish you had one just like it
I'm not your bro, dude
my cat better 😎
try using the attackbox on tryhackme then.... not much you can do without a good laptop/pc
Pic?
its ai generated xd
yeah its my cat
matter fact ai is act good, i use tht sht for my homework, when sht gets hard, use tht mf
Haha jealous
bro the relience on ai in todays world is alarming
Wouldn't it be great if we can access attackbox from like navbar?
its like A****
ai is a big threat to human integrity
Ah now it all makes sense xd
okey. i try buying ssd
lets outsource actual skill to an AI model lol
ai has goods and downs
AI sure has its uses
LLM:S on the other hand is mostly plagarism machines
the good part is tht u can let it do ur work for u, bad news is tht it can take ur job from u too
or make u less. valuable
its supposed to be at best an assistant. Ur not supposed to make it do your work for you sigh
?
si
??
did they stutter?
who?
what dont you understand?
no lol
I know. this chat is gibberish right now. im outy
well with your current attitude, an AI can easily automate you away in 4 lines of code
well nah the IQ of this server is in the negative because shadow is giga stupid
shadows statement stays the same.... the generic IQ of this place is below the normal level because shadow is stupid
who say shadow is stupid?
because crows and octopi and squids are smarter then shadow :D
What'd you break this time? ;D
local git repo
Ah, fair.
I do think everyone has to go through that at least 4 to 6 times in their lives. xD
more!
You have no idea how many bugs get spotted by users on Linux testing branches, rolling releases and especially the testing branches of a rolling release, so be sure to appreciate the people who save you from all those issues.
==========Support The Channel==========
► Patreon: https://brodierobertson.xyz/patreon
► Paypal: https://brodierobertson...
this is bad bug
How does it make you less valuable? Just use it like everyone else, and make yourself more valuable thereby. It's just another tool
Heh. Have not updated my laptop in days.
i use kali i am hacker🤓
well this is just in arch-testing versions buit yeah
Hey everyone, hope you’re doing great! I wanted to ask for some advice.
I’m an IT student specializing in Cybersecurity next year, and I’m currently looking for a summer internship focused on security roles.
I’ve been using TryHackMe—finished the Pre-Security path and making progress in 101—but I’m not sure what to focus on next. Should I go for Security Analyst or Security Engineer? Which one would give me a better shot at landing an internship in the next 6 months?
I’ve enjoyed CTFs, but I feel like the pentester path doesn’t match real-world roles right now, so I’m leaning more toward the defensive side.
My university also covers certifications for the next two years. Any suggestions? I’m currently working on AWS CCP and RHCSA to build a good foundation. Let me know your thoughts!
Holy wall of text
Those I'd honestly say that neither path will give you an advantage over the other.
What people look for most for is being generally comfy with computers in general and, importantly, the interest and motivation to learn new stuff about something.
At least in my experience.
If you want to works towards an security engineering related internship, do that path, if you want security analyst stuff, do that.
If you are not sure what the difference is, I recommend you read up on it. ^_^
soc level 1 and soc level 2 paths give you chances for soc jobs which are quite common for early cyber security people...... helpdesk is the way for simple early IT job
yes is it
For getting a proper job, not just an internship, there will likely be higher knowledge and skill-borders.
Plus can’t you do internships each year
So you could try both
Well, if you are still in school or college, unlikely.
We had a dedicated time frame where we were supposed to find an internship for a few weeks, was pretty fun.
But then it was time to go back to regular classes.
in shadows gymnasium years there was a period of time where shadow needed 15 weeks of internship
15 is wild.
hey everybody!
It was 3 for us. Hardly any company wanted to hire anyone for that short, was relly difficult to find something for some people.
Hello. 
lol
eyy
shiny
Coolio. ^_^
potato color
thats a great color
Thanks for the advice! The thing is, internships here are super limited, and you have to compete for them. Most of the time, they expect you to already have skills in the path, not just general knowledge or motivation to learn. So yeah, I need to choose a path and focus on it!!
Gave +1 Rep to @lament tendon (current: #37 - 238)
Thank you!
+rep @sand trench
Gave +1 Rep to @sand trench (current: #4 - 2072)
i dont translate 😭
+rep @sand trench
You are on cooldown. ;D
You cannot spam the rep commands, so I did it for you. ^_^
ohh thanks
+rep @sand trench
Gave +1 Rep to @sand trench (current: #4 - 2073)
nice
MAGIC SPELL~~~||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||_ _ _ _ _ _ _ ty
Gave +1 Rep to @sand trench (current: #4 - 2074)
report
Shadow's not going to be surprised about 20 million pings at all.
yes
Yo yo yo
yoo gigachad
I havent been here since days
yeah me too, i was lock-in
@sick lance
@sick lance
Don't click on this, guys. ^_^
lock n load
but. but the 50 bucks
yeah that is common enough that shadow just noticed them when they got time
why no linux install instructions ;M;
We missed a great deal 😭
Ive a friend that dosent knoe anything but a pro at reverse engineering
shadows forte in hacking is probably sadly game hacking
He can barely do subnetting but he can find buffer overflows and debug binaries etc
this looks awesome whatever this is lol
which is not very popular
Roblox hacking scripts 
expense tracker... i.e to keep track of what amount of money you have spent each day and figuring out your stuffs
naaah mostly single player games
with things like cheat engine or pince
I've always wanted a terminal based everything app :>
In this case it's just finances but thats awesome too
That dosent count for me
well not touching multiplayer game hacking for a lot of reasons
mostly it is unethical
If i accepted selling roblox scripts i'd be a millionare now but
Gigachads dont live off cheats
though have had some fun with creating mods for games using lua and json and java
which could be considered hacking in some instances
Lua is my faviorate
I coded a roblox game with lua over 5000 lines
It was some great days
here is shadows current fun time with game hacking: https://www.twitch.tv/papa_jefe
xd
he is using random number generator manipulation and hacking in pokemon emerald
@naive violet if you are still here
Bro thats wild 💀💀💀
that is going further then most people would but fair
Whom here believe in transgender nonsense
Meh, what do you expect from morons
I thought u deleted it for rule 9 
I deleted it because it would look like a reply to your message. I meant to imply the malware author by "moron".
im doing jabba's room 
Can clicking on a link actually hurt you though? Unless it’s a zero day of some kind?
And transgender is not a belief
Yikes.
Quick reaction ✅
well dunno but not gonna go and check...
Thats a reaction for a guy well not younger than 18
Wdym
VirusTotal
Rule #2
I need a virus total account
Don't have a virus total account
The action and time u took for it is an average for 24 yrs old
VT is great, just be careful what you upload 🙂
guess shadow is special for having a virus total account then
still trolling?
Imagine being 18+ and trolling on discord for days at time
Not talking to u
Nd im not trolling
U made it look like on now
I didn't get what it has to do with age
some people don't have jobs or better things to do
Rule #1 and Rule #2
That TUI finance tracking app is so cool I wanna make something similar now :>
No constroversial topics and no being rude
Brah
Right
"brah"... what are you 12?
Nevermindd
Oxymoron af'.
you got a cellphone in your cell?
Shhhh..
Bro ur the one acting like 12 lol
Don't tell anyone, they will raid my cell
lol
Crazy how many people sent me friend requests and shit thinking I'm real
And choosing the number 12 specifially is for a bad purpose
just tell them you're on hold with United still for your claim
That's a good one
fr? JAJAJAJAJA
Yes. There are multiple different types of vulnerabilites like XSS, XSS injection (kind of a rare one) and other stuff you really don't want to risk.
Yeah but this clearly doesn’t have XSS in it or SSRF or others
how can you know that without risking it and looking at the source???
Is there a mod up rn
I can be embeded in a JS tag on the site you are visiting.
scrubz seems to be here soonish
Guide them to #1332425025399292044 when they come
Yes, for real. Even on this mobile FF-type game I play. I got like 30+ friend requests the first 3 days I started playing.
In this case it would be CSRF. ;D
In case you want to deepdive into what is possible by just having Javascript run within our browser, I recommend you look up the BeEF exploitation framework.
Pretty cool tool.
Also browsers are in sandboxes
As they should be. xD
honestly, I don't think there's much or any risk from clicking a link like that these days barring a browser specific exploit or you entering creds or downloading and running something
but wouldn't suggest anyone click links they dont trust regardless
wait is firefox in a sandbox??? thought that is what people used firejail for
And i guess they wouldn't waste a sandbox evasion with fake steam xd
Done!
It would be funny if someone made a kernel-level browser
Why thoo
+rep @sick lance to the rescue
Gave +1 Rep to @sick lance (current: #1 - 3318)
Because they feel like it
It has site isolation as far as I know.
Something, at least.
firejail is cool tho, you can start all sorts of stuff in there. Wonder how effective that is tho. 
Ok, I have a serious issue with this.
shadows main gripe with it is if there is a vuln in firejail they get suid bit perms if exploited
now there is no telling if such vulns exist or not
just shadow is spooked by that possibility
Multi account containers has been a savior for work
This is no way to speak about a lifestyle of a community member, I'v already removed three users this week with transphobic/xenophobic/racists views.
You can consider this your last warning.
terry would
I manage over 100 clients and tenants
Lucky me, I'm just skipping the firejail part altogether, hehehe.
But I also got NoScript on block-by-default, I guess.
Won't protect me against anything, but it'll do.
yess xd
shadow just uses ublock origin in hard blocking mode
Naa terry wouldn't do glowy behavior
it is a huge reason why a lot of people can't use google chrome or chromium based browsers
as multi account containers have such huge usage potenital
I have that as well. But it blocks ad domains, while NoScript just blocks all javascript everywhere and I can reenable it for only the domains I need and for only as long as the session is open.
noscript is maybe not fully dead but eh
Pretty neat plugin.
I use Brave, simple and fast. It has built-in ad blocker.
ublock in advanced hard blocking mode blocks javascript if you tell it to
so you can have it block all javascript by default there too
why block all JS by default?
ye if u want that old web experience of exclusively seeing static html/css :>
It still ships with current Tor installations, even.
Its just less of an adblocker and more of a quality of live upgrade for people that don't like javascript. xD
that's going to do more to break usability than to protect you from much imo
other than maybe some basic tracking stuff
Because me no trust.
fair enough
Well, the stuff I need is enabled on a per-domain basis.
yeah and shadow is fully aware of this... hence why shadow go through the trouble of figuring out what needs unblocking to work for each site they use often
Same.
it is a once setup cost and after a bit better privacy and security
yeah
well thats dedication
dedication and persistence is part of the things shadow has good skills in
I use Malware-bytes extentions and VT4.
Anything I download gets automatically sent to Virustotal.
Where can I post a question regarding Cybersecurity / Awareness in RL I have a question and need a second opinion
and cheese knowledge 🧀
Here.
naturally
I got no download checker, to be fair.
Waaaah
Ah, the convo is back. xD
@cunning igloo Is this homework?
No its not I need a second opion about an issue I'm facing
Ah, could you please upload as a file, that was a massive wall of text. 😄
how do you know so many?? im impressed
How are you dealing with downloading personal stuff, idk, medical documents and such?
Does it prompt you for an upload?
In that case I might be interested in that extension. :3
Trust me on this, DON'T do this
reading through the database shadow has multiple times over and always rereading the one that is posted for the day
automatic VT upload is.... not recommended imo
also read through the wikipedia page on cheese quite a few times too
If not, you should maybe attempt to remove your stuff from VT now tho. xD
wow thats a lot of work
Which one?
the VT upload
i mean, even then, i would suggest against it
VT is a great resource
but it's also a DLP nightmare
everything that goes into it, comes out the other end for some of us
Oh, I know, I had a sub a few months ago and got pinged when a few quesitonable files came.
This
yeah, if you spend some time on setup, you can catch some very juicy stuff
i see it multiple times a day, every single day
I no longer have a sub. 😦
What's DLP an acronym for?
I've had to alert companies to complete infra compromises via VT
Ah, thanks. ^_^
Gave +1 Rep to @sick lance (current: #1 - 3319)
like, keys to the kingdom in easily searchable files
Prevention/Protection I think either is fine
just flowing into VT with no regard
Yep
I've only been doing it for a few days, I've only really fed a few binaries and python scripts.
yeah, I see a ton of it from the browser extension but there's also plenty of other things that feed it
some i still haven't identified
it's a mess
stuff just flows into it all day long and i have no idea how some of it ends up there
iirc what I saw/was informed was that every hash and contents of a new executable being run were submitted to VT
I'm really interested to set something up now so I can have a nosey.
This could have been a good dissertation.
How come you get so much insight into this?
Job related?
Which is more than bad, you're self breaching at that point because it's all searchable on VT with their paid stuff
I hope this is fine:
This is so much better, you're asking for help, being descriptive, and not taking up half the screen (and my screen is on potrait mode) 
Nope, just have access
And an interest.
Fair, fair, makes sense.
nosey isn't even the half of it haha
It's not really something I can assist with, somebody might be able to though.
you should see what shows up
Do you need a subscription for that stuff?
Students and certain research categories can access for free if approved
Oh RLLY.
but you are restricted a bit
Ah unfortunate. Got a Shodan membership tho, that place is yet another treasure grove. :D
Ouh, that is fancy.
Which place is this
VirusTotal
Oh reallyy
xD
there's a lot of quirks to it
that make it difficult if you aren't used to working with their specific stuff
not sure where shadow heard this but heard things about google dns being used to track users by what domains they quried so would not be surprised if a chinese dns server did the same
Isn't the google DNS free? 8.8.8.8?
Feel like that's not just Google
not a lot of meta data in dns requests more then source ip being your natted ip at home plus the domain name and a cache value last shadow checked
DNS is it's own rabbit hole and I will refrain HARD from getting into that one
there's just so much going on there
unless you count time to live as a meta data point
ISPs have used it forever to track people/stuff
What use do ISPs have with it? Unless they build shadow profiles
true... shadow just don't have any ready available source hence why the not sure where shadow heard this
ISPs are your first line of DNS lol
isps have been caught injecting their own ads on connections in the past but yeah building advertising profiles basically
they have a vested interest in keeping your DNS queries with them first and foremost because it allows them to serve local cache and such
Sell your data
how do you feel about using unbound and https://quad9.net/
good enough for most people
Classic -_-
if you want better then most people you could set up a pihole using unbound and quad 9 as the upstream dns provider
When you say most...
and there clarified
Mhm
if you want super mainstream dns server though shadow would point people at 1.1.1.1 from cloudflare
not googles 8.8.8.8
if you want even better then just regular pihole you would setup dns over https or dns over tls or dnscrypt
if you are using custom DNS, know that you may be losing performance and gaining latency to all sorts of services
yeah hopefully
So that means they can get some information and still can use it to track and analyses an companie and still using for phising / spam ?
e.g. Netflix local cache system at your ISP vs wherever google or cloudflare decide to route you
could significantly lower perf if you aren't aware eof it
potentially yes if they do reverse ip lookups
Im my own first line dns
I don't use DNS, I have a physical notebook with a lot of funny numbers in it.
lol
So My concerns are correct specially when it goes over china.
ipv6 or ipv4???
or are you the rare ipv5 user????
don't think an ipv7 version has even started being developed but could be wrong
although i guess that's still technically "longer"
it was proposed years ago
there's an RFC and maybe some other documentation
but it was never adopted for anything
fair enoughs
The Internet Stream Protocol (ST) is a family of experimental protocols first defined in Internet Experiment Note IEN-119 in 1979, and later substantially revised in RFC 1190 (ST-II) and RFC 1819 (ST2+).
The protocol uses the version number 5 in the version field of the Internet Protocol header, but was never known as IPv5. The successor to IPv4...
I don't know what that is. I don't know what DNS is either. I just have a notebook with really hilarious numbers such as 228855 and 12345678. :D
How to exploit the ftp port of a web server
What
feel like that wikipedia article is a good history lesson for a lot of network technicians
Yeah it depends
How to
Mm
Need tea
Makes me laugh “how to”
👍
How to get up
Next time you can also just put this exact sentence into your search engine tho, it'll show you a bunch of helpful stuff. ^_^
shadow has probably messed with dns more then most people
just because they thought dnssec and encrypted dns is fun
not to mention dns blocking lists
some of those DNS exfiltrators can be pretty fancy code wise
Got to help set it up in an internal network recently, and by help set it up I mean watch a guy click one button and then have the ansible pipeline do everything else. xD
Thanks pihole
Gave +1 Rep to @sand trench (current: #4 - 2075)
yeah shadow now uses nextdns
Yeah I use my domain controller as dns then it forwards all requests to my pihole instance
mostly because it has some nice features standard pihole does not provide
and because shadow did not feel like running a pi all day every day for pihole
Pihole is then set to I think cloudflare and Google
I remember running/maintaining BIND 4 😄
Oh my pihole isn’t on a pi
Mines in an lxc
main problem with self hosting the pihole is how often shadow relies on their nextdns instance on their phone when out and about in the wilderness next to the telephone towers
Is there any vulnerability on php version 7.4.10
try googling
I googled but
There is no major
No major what?
What's this for?
good question
To hack a web server
who owns the web server
Where is the server located? Who owns it? Is this homework?
No
What made u want to hack it tho
Is it a tryhackme challenge?
Bro 🤣🤣🤣🤣
I don't know that I recommend you lick a webserver
Ok bro
ping 192.168.1.1
The amount of times I've entered pint <ip> instead of ping <ip> ...🤦
Cheers bro 🍻
Does it work 🍺
The amount of times I've entered gut push instead of git push 🤪
Bro i want the variables of php 7.4.10
well if you are doing that on linux you can set an alias to avoid the problem
or setup a function that tells you it is ping you meep moop not pint
Are you doing a TryHackMe room?
No bro
Overcast ☁️ +2°C (-1°C): ↑3.1m/s: 100% humidity: 0.0mm: 0 uv: 991hPa
well this feels like nice weather for january
I think php has a lot of variables
I am trying to hack a website server
Yes
PowerShell has aliases too!
Do. You have permission to hack it?
yessir!
Bug huntting bro
yah but not sure if you can set those to permanently stay each time you open a new powershell window like you would do with bashrc or zshrc
what scope Lil bro
You can. ^_^
It's a bit scuffed tho.
Linux is just better.
Deets
(And now we wait for the arguments to start.)
agree whole heartly with linux is just better
What does powershell call aliases? The same?
Yea.
Yeah the same
Is it a cmdlet or...
Powershell has tons of aliases
still use cat anyway
Get-Childitem is like that part that is not the alias tho.
Forget I said anything, I can't read.
HI can someone help me please?
I’m so tired
Im in OWASP Top 10 - 2021 room
You should post it in room-help
section 4 ask me to go http://MACHINE_IP and its not work
There should be a green button that says "Start machine" somewhere.
After that you will get an IP address that you can connect to to using the attack box or the VPN.
Thoughts on deepseek
Yes this what I did
I'm glad we have innovation. And its open source. Stocks can take the hit in the short run
people having issues today
try http instead of https
This isn't an etc/hosts issue right
You are going to https://... while you need to visit http://... instead. ^_^
They’re calling deep seek agi?
deepseek is top of charts
Hi everyone! I’m Demmy from NYC. I’m new here and excited to be part of this community. I’m a student and a budding entrepreneur, working hard to support myself through school on my own. Looking forward to engaging conversations and hoping to feel right at home!
doubt we actually got artificial general intelegence in the vains of how it is depicted in sci fi
hi demmy
Happy to help. 
Welcome.
AGI is vague and not near to happening
Thanks
Gave +1 Rep to @lament tendon (current: #37 - 239)
No GlaDOS yet
sadge
until i have halo cortana im not happy with ai
which has more real world style boxes - HTB or THM?
In my opinion, HTB.
but if your newer thm is far more friendly
But getting into it is a lot more difficult then THM.
htb is more advanced
For learning content, I prefer THM at the moment.
HTB usually
HTB does have academy now, but its pricing scheme is a bit stupid
But as others said htb is harder
htb academy is rather like reading man pages
THM is defo better value for money, but I remember when i was doing boxes few years ago some felt very CTFY
their hands on approach is ... improvable 🙂
I’d expect ctf boxes to feel ctfey
But HTB not work only for infrastructure PT ?
how u doing good sir!
and less APP ?
To be quite fair, HTB boxes don't really feel like real pentest engagements either.
what about pro labs?
ive seen them advertiised
watched Pantheon as if I were cramming for finals or watching a lecture video.
Thm has similar
Not sure, didn't pay for those.
To pro labs as well
oh u mean like wraith?
never tried pro labs, only did a few boxes
Yeah
I’m saving my prolabs until I finish the academy path
Then use it to for practice CPTS
Good place to lean APLICATION PT ?
Anyhow. Leaving. See you guys around.
PortSwigger is good?
are there any websites that provide like real world simulated retired networks with machiones u can pentest not just something made by a random user
Good night 🙂 @lament tendon
PortSwigger is good for Webapp/API pentesting.
Not sure whether they got any application stuff as well.
Sort of rare, I got no names for you.
Closest you'll get to the real deal is bug bounties, but that'll require some experience.
No clue how well versed you are.
still starting out, just curious for future reference
do tiny companies also host bug bounties
or is it just like paypal amazon etc
You can also look for a VDP
yeah best bet is checking sites like hackerone for bug bounty programs
Which is basically bug bounty without the prize
welp shadow gotta dissasemble their ploopy headphones headband as the clamping force is too light
test test
test run ok
well then one of those external cmus programs works :-:
a
Would love to pick at somebodys brain regarding installing kali. I've got oracle virtualbox and have setup kali via iso in the past. Issue I've ran into the last few installs is it seemed unstable (from my very limited knowledge) and would freeze and crash at times or wouldn't boot via oracle virtualbox. My curiosity is how others have setup Kali. What have you used to setup a VM? Is Oracle VirtualBox the way to go? Could it be the amount memory, threads, etc. I give it? I've now got a USB I keep the latest kali install iso on. Looking for thoughts, advice, etc. as I move forward.
VMware workstation pro and the prebuilt vm image
any suggested links or places to read up on this? Do you have any reasoning why you prefer or suggest it? Or is this more of the standard?
It just works better for me and you can find the prebuilt vm image on the Kali website
I use qemu/kvm and use iso
that's an easy solution 🙂
That’s why I suggest it
Imo vmware works better and all you have to do is import the image
Then Kali
if I want a quick vm I download the ova, but 90% of the times I use iso because I like the options to set up things my way
What’s everyone up to ?
You mean like the virtual machines settings or the install?
is doing it that way the same as running the iso and installing? whats the same or different
sorry for 20Q, just curious and want to know.
both
No you just import the virtual machine and hit start
For me default settings are fine
I have no friends
sometimes is fine, but even if I don't change anything I want to have that option just in case. I'm kind of neurotic that way 🙂
So bored I’m gonna open Duolingo
And study some language
Study arabic
Watching BHIS - Talkin' Bout infosec News.
nice language
No thanks, I’m doing Norwegian
Gave +1 Rep to @untold zephyr (current: #2631 - 1)
Nice I need to watch some
i did Bolt CTF mostly on my own ! 🎉
Ohhh good job
just needed some ideas on some stuff
i also was watching
Tib3rius is live 🔴
Well the more I look into my case the more I just want to leave this country.
Nice. I was busy earlier so I missed the live stream, so watching it now.
But also practicing some Norwegian
Norway is the way
Same.
Norwegian Black Metal 🤘
I love the languages up that way. Norwegian and Swedish ❤️
hey i want to set up my home lab for cyber? does try the hack help me to set up a lab?
i enjoy Finnish Metal
I enjoy some good ole, Old Man's Child, out of Oslo
finland is the most metal country based on metal bands per 100k people
Scandinavia own the Metal music in my book
Oh wow
Do you think I would survive if I left England and just lived abroad
for some reason i have to type "-p1-65535" if i want to scan all ports, using "-p-" not working
Got a job out there somewhere
depends on how good your english is
yes exactly this is why it might be a problem
My Norwegian is basic
you can also leave it out
I’m confused
nmap -Sc -sV $ip
plenty of native english people who have poor english
I call it the funner grammer language 🤓
I can articulate my sentences correctly. I think 😂
If I want to be professional I can
I’m just lazy on discord.
😌
laid back 🙂
englishhhhh
On discord I’m a bit of a plebasaurous
the plebs
But you should hear me speak to the people on the other end of a pay check.
i thought if i do that way it only scans like 1000 ports
the fast top ports is -F
My Norwegian though is pretty bad
ok, thank you
Gave +1 Rep to @grizzled wing (current: #57 - 150)
yeah that is just top 100 ports though
i speak Python
@grizzled wing what is a good metal album to listen to?
-p- is all ports
this not working for me
though -p- depends on where in the command it is placed
oh ok
Yeah we will call it that 😆
sudo nmap -A -T4 -vv -p- -Pn 10.10.253.16
generally the command shadow uses
also that ip should probably not have been included
but doubt it is online anyways
i enjoy this Ukrainian band
https://youtu.be/ZIGxetR8XrE?feature=shared
Country: Ukraine | Year: 2024 | Genre: Cosmic Black Metal
Order CD, Merch & Digital Album:
https://labyrinthusstellarum.bandcamp.com/album/vortex-of-the-worlds
https://m-hall.store/band/labyrinthus-stellarum
Alex Andronati - all music and lyrics, vocals, drum programming, arrangements, mixing
Misha Andronati - guitars, mixing, mastering
Dm...
how to i get the subscriber role?
subscribe to tryhackme then rerun the verify command
subscribe where
PsyBeast is a 0xVisionary
can't get the link as already subscribed and it does not show up in the options then D: