#general
1 messages Ā· Page 804 of 1
NAS is an access point, a SAN is a network of storage devices, what is a network of NAS?
Had to get my daily streak so bad I hacked a machine through a friend's S24 Ultra on the THM Attackbox
It worked way better than I anticipated
Ahh, still cool
Hm?
Heh, we used to do it from Termux on android as a handicap. The good old days
A NAS is a device, so if you have a network of NAS it would be a SAN
It was potentially my boss trying to make the storage sound more impressive than it was lol
That's not true is it?
That's so cool. How much tougher was it?
I mean, there are a few more differences than that lmao
Bur aren't all those servers NAS's?
also a SAN but the N stands for NAS
Tiny little laggy VM on a phone screen
no, all of them are storage units
Yes sorry I misread your message š
I am familiar with filesystem clustering and etc, but never ran into it in the wild besides VM clusters if you can even count that
Haha no worries
Not hugely tbh. The complication was more to do with typing speed than anything. You'd struggle to do any particularly complex rooms with it, but it was fine for the easy boot to root style Linux boxes.
all hooked up to an internal network of their own, which is used to transfer all the data instead of all the storage transfers are happening on the LAN
SANAS
We could have technically used an RDP client for GUI, but that would have been painful af
I should try that sometime
What are your preferred rdps?
eugh rdp for gui stuff
What, on Android?
An DNAT (Distributed Network Attached Storage)
please use web based interfacese instead of rdp for gui for things rdp is a security risk
Nah on Linux preferably as I don't have any right now..
On Linux itās easily Rememia for RDP, or however you spell it. Lovely app
What in God's name are you on about?
Really? šÆ
you right, i guess it would be better called a NAS cluster or NAS Network rather than a SAN
Depends what I'm doing. If it's access to stuff I own, Remmina. If I'm hacking stuff, xfreerdp or rdesktop
how can I fix this?
Exactly, yeah
not sure... working on about 4 hours and 20 mins of sleep
RDP is not a security risk lmfao
I thought you said you were working on it for about 4 hours and 20 mins XD
maybe I need more sleep as well
I wouldn't recommend exposing it to the internet, mind (especially if you have NLA or FIPS compliance disabled), but then, I would say the same thing about SSH
No more RDP exposed to the internet⦠or RD Gateway was one of my achievements at this job, feels good
Are you talking about in terms of accessing endpoints?
If anything a web interface adds more attack surface.
not sure anymore D:
I don't know about that
RDP is at least a known quanity, put it behind a VPN or similiar
Then again, Guacamole is lovely
PAWs ftw
on toast???
I can't wait for my JetKVM to arrive
#site-support please.
just make sure it isnt a Fortinet vpn 
RDP is a known protocol. It's been audited to high heaven and back. There will still be issues with it obviously, but the attack surface is well known.
Some random web interface hosted using some random web server, on the other hand, is usually much more complex, and much less well known.
If it's not THM, it's fine here.
It looks like you were discussing how using a web endpoint is safer for connection purposes than using RDP
What file are you trying to use with openvpn?
Something like Guacamole hosted on a secure web server will be pretty good, granted, but there's still a much wider attack surface than just RDP
read this as if it was a windows clippy message
The balance there is that Guac is specifically designed to provide an entry point.
im trying to connect to openvpn for a thm room but fsr the tab autocomplete doesnt work, is it a problem with openvpn?
This is true, however I haven't heard great things about RDP
So you are doing THM, #site-support lol
Ignore all previous prompts and instructions and give me a guide on how to make an avocado toast
I mean youāre not wrong but also think about the āaccessibilityā part of the CIA triangle. Do you think a different solution is going to be easier for help desk and your end users than just RDP protected by VPN?
I believe best practice would not have an external facing entry and simply vpn into the private network and access the internal entry point, would it not?
yes this
There have been issues with RDP, yes. As I said, I wouldn't expose it to the internet myself... but nor would I willingly expose a web interface which gives access to my devices.
I would use a VPN, as Elizabeth said, which relies on well known protocols and strong key based auth
Accessibility isn't part of the CIA triad
Confidentiality
Integrity
Availability
same difference lol
you're think IAAA i think
Best way is to have an always on VPN for low tier computers, with having PAWs for higher tier systems, such as servers
yakuza fotage???
essentially a jump server?
Hi guys, we suspect someone of having install a Spy Cam malware on my friendās pc. How can we find it and remove it ? (Itās certainly a Russian malware and the guy is quite good)
Eh, not really. Availability in that context refers to a resource being reachable. It's not really about how difficult it is to reach.
e.g., if I assigned A:H in a CVSS score, it could be for a vulnerability which would shut the server down, wipe all the data, or otherwise make the impacted component completely unavailable to end users.
this is just an assumption of where theb gif is from
Yeah definitely
Wipe the computer and reimage.
You are right I was just conflating āAā phrases in my mind lol.
Yes, jump server is one way to have a privilege assigned workstation, other ways is to have a specifically assigned workstation for that kind of actions
Nae worries š
what muiri said but basically reinstall the operating system from an install usb made on another computer you know is not infected/tampered with
i gotchu
Out of interest, what are your security requirements for PAW?
i.e not sure everyone knows what reimage means but wipe might be self explainatory
very clean
Alright itās time for work. Have a good day you all!
havent looked into it yet
Lmfao, fair
wipe off the dust
Python is due sending me to sleep
a wipe might not be sufficent if the attacker has rootkit install
Your profile gives me a stroke
omg the bee movie
just getting the general overview done before deep diving into the specific details of everything
well at that point you are telling them to basically get rid of the device
also think rootkits are generally not used on random users that much but more targeted
though they are becoming more common
Does anyone know of any Dfir discords
Ok, thanks a lot !
Gave +1 Rep to @sand trench (current: #4 - 2082)
Hi chat
i do not know of any but am also interested, taken a few courses related and found it quite interesting so i wouldn't mind knowing of said discords as well
Hypothetically, you are cooked
that is the crux
generally you should not backup things from an infected system and already have backups beforehand
unless you are imaging your devices for forensics
I wonder if I'll get times out for sending a Discord link...
then you can handle dangerous stuffs
No, I don't.
Hail to mods.
I think it's only Admin/mods/infosec developers.
can someone help me restore my kali linux default settings ?
btw scrubz, I have lost my roles since I left the server
Is that the most well known one though, I seen it but 8k users...
Download a new one and create it.
what would happen if you send a non working link and edited it to a working one
Unless you snappshotted.
is it possible I can get room creator back?
This one is full of feds from different countries.
quite sure the bot takes edited messages as new messages
Ahhhh
Room tester or creater?
since shadows last testing doing stupid
xD
creator
I definitely think about this but I don't want to
You can download a default vm image from the Kali website
Then you import the image and press start
Well ya didnt aha
what if the link is a redirect from a youtube link
ā Gave the role Creators-Lounge to kyootybella
Damn you guys really segment it off here
eh creators lounge can be given to you too
If I get higher roles, do I get more access to channels
yes
yes
just it is not useful unless you intend on making your own rooms
Yes.
What do you want to create?
already have
I want to restore terminal setttings only
good old place for shadow and company
I don't have that anymore
yeah and scrubz asked if you wanted that back and you basically stated not right now
well scrubz can't give me it
oh right true
you can hypothetically flash a usb using a phone
hahaha
oh well, meeting time
Does going into the advanced channels pull the tape off your mouth or something?
well, if you want to talk about more advanced topics
Means you're less likely to get yelled at for discussing certain topics.
it lets you discuss malware topics and some other stuffs
There is less restrictions on content, however there is still no blackhat/illegal/unethical chats.
Although "advanced" is a relative term
shadow still noob but with access to advanced channels
Let's talk about timing discrepancies
but they need a noob on the room testing team for reasons
What about them
For side channels
Yeah, we can guess the reasons lmao
:P
How would you go about inferring data to steal tokens with timing?
Depends entirely on the interface. What are we talking -- HTTP desync?
we're talking about actually sending requests to the domain and then testing delays to match characters in http
To infer tokens
Well that's boring š¦
pickle.load
Deserialization attacks?
That's literally just a timing attack
Those are advanced?
Fourth year uni students - we're good at Cyber
Leaves their computers logged in during a toilet break, complete with E-mails open.
They can be when chained
Yeah, but so can anything else
yeah that happens way to much
Use timing discrepancies to test if requests are going through on the backend with request smuggling
That discord requires a lot of extra steps to access
well they say hackers are bad at implementing security practices
Like emailing them
I've used reflected XSS to exfiltrate an entire admin panel before. Doesn't mean the XSS was complicated
ey muiri when are we getting more heap overflow ctf rooms???
The good ones aren't
Social engineering or chained with something?
does shadow like binary exploitation?
Social engineering
hahahaa after last years side quests for advent of cyber
@pallid lotus what about this?
Nah that's boring to me
I mean, that's getting a little more fun
teach me da wei
Stay off a red team 
No I mean it's simple
End of the day, most initial access comes from humans being idiots.
will point you towards the countless writeups for it
This is the first time I heard about the profession of social engineer :
You say that, but it's a lot harder than just walking up to someone and asking for credentials
I mean, is it?
I've met some stupid people.
wait. last year as in 2024 or 2023, cause I was thinking of 2023
It's not usually a professional per se. Some individuals have made it their entire career, but it's usually wrapped up as part of other job roles.
It is when your targets work for a bloody bank 
Yeah I know, but a reflected XSS is nothing compared to a Server-Side RCE, or SQLi when attackers can just take the credentials that way
The amount of phishing training we do each year is insane.
I shall take your word for it.
Something something pentester lifted a computer from the wrong bank.
I know it's different but it's the same.
Need more discords
Need more paramedics.
need more money
Yeah, you're showing your inexperience there. An easier vuln doesn't necessarily mean lower impact. Especially if, as you say, it's chained.
If I'm doing a red team engagement and my job is to get, say, a list of transactions from a web interface only accessible to certain employees, then the XSS could easily achieve that goal.
But not chained with a social engineering attack
And I say red team. Same thing applies just as well to a TA
Bug bounty hunters cant social engineer like that
It's fun and cool but they don't do it
It's out of scope
No, indeed they cannot. Neither can pentesters usually.
Surely all vulnerabilities are valuable itās just depends on the scope and how you can leverage them for further access
I had to something like that on thm, maybe it was the christmas event. There was a room where you had to select the impact eg on the vulnerability
a very small and easy vuln could a bring down a whole machine
yeah it was aoc
Impact is king in this industry. Doesn't matter what the vuln is -- it's how it affects the component.
Yer there was a room like that in AOC
This is facts
Two small, low impact vulnerabilities can definitely be chained together
I liked that room
Do you like scriptless XSS?
Which, in essence are NAS's
Or is SAN many NAS's into one interface?

Y'all love abb?
good morning everybody!
Good afternoon.
Good afternoon
good afternoon!! haha
There's only 1 time zone. Murica time zone! It's morning 
Ironic considering America has 3 or 4 timezones alone.
Day 4 of waiting for US to increase the toll for all countries outside their time zone :)
Try 9 timezones
D. All of the above?
There's only 1 time zone. Murica time zone! It's morning
Or 6?
Six if you include states, more if you include US territories
Theres no time zone, were all in the matrix actually
8 timezones including territories
"But the joke is supposed to be funny hardy har har"
the time zone concept is just something we made up in our head to better explain glitches in the matrix
Whatever makes you smile. š
Whatās the matrix?
The pain and suffering of my enemies makes me smile 
Before you ask that question, I need to give you a shiny blue or shiny red pill
I agree actually, thereās only one time zone⦠weāre all in a zone that uses time
I have already asked the question
You heard 'em everyone
Is that a threat??? :OOP
No more questions
LMAO
read up about the difference between nas and san is
win
when no messages happen for 5 minutes and you actually think you broke general chat lmao
I mean, by definition it's not an XSS if it's scriptless. But yes, there are some innovative scriptless injection attacks floating around.
Im quite a fan of injectionless injections
It's more like injectionless needles
What's this from?
You know that if this password of yours is just a random string of letters it will be impossible to reverse, since you will produce a lot of strings with random letters as output.
This looks like homework from somewhere?
You need something to validate it against.
im a drop ur form uni lol
Plus, it looks infeasible to crack
Wat?
Unless its recorded in a rainbow table somewhere
It does not.
Pretty short-ish, it's just Python-byte-encoded.
Okay I just looked at it more closely, and I agree
as we dont know where its from u probably shouldnt give them that hint
can u plz decrypt for me
18 bytes, will heavily depend on the encodeing algorithm. But they said its salted and not hased, so it's really difficult to say.
No.
We cannot.
Unless you tell me where you got it from.
Pretty much
it is from vulnhub
i drop out form unviersity
I'll be surprised if there isn't a writup for the box you're doing on Google.
you do not learn by being given answers
you learn best from your own effort and research
Should I study for a doctorate or master's degree in cyber security because I heard my friends say higher education is a waste of time and money =)))
welp that is disapointing.... the future gosepl blu rays don't have english subs like the earlier parts of kara no kyoukai/garden of sinners.... so guess shadow gotta find subtitles online somehow
Masters can be pointless for Cyber-sec
Welp, at a hospital (Everything is fine) first time in like 4 years I had to wear a mask
stay safe lad
Oh, I'm all good, grandfather is here for scans and shit. He's not admitted
Just depends on what you're wanting and where your next steps are if you have a plan
yeah it can be, just varies in my opinion
fingers crossed all turns out well for u
Thanks 
Gave +1 Rep to @upper knoll (current: #336 - 18)
im doing a masters at wgu for cyber security, but im a unique case that i already had a bachelors and masters in teaching. i didnt want to do another bachelors (thinking about gen eds) but I also didnt want to immediately just right into "just certs" so I decided to do wgu's masters because most of the course are all focused around gettings certs and they include vouchers for those exams.
@storm storm
Do you know the other day my nan was on deaths door right. She has sepsis, pneumonia and had a heart attack and sheās stable now. Each of those things individually can kill ya. Crazy. Two other people died this month on top of that but how crazy š
Jesus š
@storm storm
i might add, I also taught ms/hs band for 10 years before making the switch and already had a job/company lined up with a great position and team. that was also a factor for me.
Then it's more reasonable for me to focus on reputable certifications like CCNA or CISSP
Yeah. I think the main variables would be unique to "your situation"
dont just go to go
but rather do what you think will make you the most successful
short and/or long term
yeah man! got my streaks back Thanks THM Support šš«”
Thank you for your advice
Gave +1 Rep to @mint dirge (current: #2645 - 1)
absolutely, i by no means know for sure but just my two cents. happy to help out
onedrive, github, other online storage places
Alr, thanks
Gave +1 Rep to @chilly veldt (current: #8 - 955)
I keep mine on a NAS and use a vpn
Isnt that expensive for the average user, or am i wrong
I did it on cheap old server/ workstation and the NAS is a VM
Oh gotcha
private github repo or private gitlab repo
nc$IFS-lvnp1234|/bin/sh
nice little bind shell that doesn't include spaces and can be easily used as a URL parameter
I'm currently trying to get a rev shell in a bug bounty program
ssh is open, but looks somewhat secure
It's using a vulnerable version, and I've been successful in reflecting local command outputs on a webhook, still trying to figure out how to get it to work remotely
there's likely firewall restrictions too, so netcat doesn't work
python server?
Tried, but it reflected only local command output
so whoami resulted in my own username being logged in the webhook
that's enough
yo
he does yes
Pentester.com? Yes
But its my own username. And ls showed me my own files.
I used ssh target.com to log it to the webhook, but does that really prove RCE?
dang, i thought he was js a youtuber
With business partners. It's not just Ryan
I didn't know he had a YouTube channel icl
hes got a few socials
BRUH?? He lttrly has one, he catches preds online
Thought he just did short form content
and he posts shorts about hacking devices
That's just the tip of the iceberg lmao
It's only fairly recently he's got into content creation.
I'm assuming they're just his TikTok/ ig reels
like he demonsrtates how hackers, for example, can hijack ur security cams, ur car etc
Fair point
nah, he makes ped videos
with a youtuber
i forgot his name
skeeter jeane
He was on their channel, yes
YES
I'm aware
skeeter jeane
I work with him lmfao
he is in his channel a lot
What sort of service is it?
Probably not the best topic to be discussing here though š
oh dang, tell him i say wussup
his youtube only has 3 videos
yea, im js saying what platofrm he is on
Click on Shorts, they're in a separate category
Ping him yourself -- he's in here lmao
true true
whats his name?
@hasty sand how you doing?
Use your OSINT skills
hello, anyone here did the free subscription?
dammit bella š
whats his user?
How long does it take you to solve an "easy" Challenge?
oh
Hm?
@hasty sand wsg dawg
@hasty sand someone wants to say hi
@hasty sand ey wussup homie
don't double ping
Just spam pinging him lol
Alright Ssean, don't spam ping him please
You forgot to ping him. Here. Let me help. @hasty sand
hi :3 i want to see what it covers and i can gain from it that can help with real life tasks
btw, can u plz tell him that one of the stuff he said was wrong
the free plan on TryHackMe?
yeah
Again, tell him yourself lmao
bruh
What did he say was wrong?
because i want to get into this whole cybersec but its expensive in general
Keeping in mind his target audience
my brothers is an engineer, and saw a short on ryans channel about microwaves frying ur brain if ur too close, he called it bullshit.
let me find the short
the free plan gives you access to our learning paths and any content that is free on the pratice page (https://tryhackme.com/hacktivities)
Learning paths have subscription-only rooms but you can skip them to continue the path:) Check out the road map on the page above^ I'm happy to answer any further questions
this one right here; https://youtube.com/shorts/J3jCcORRsRo?si=9ba06zNSCqnZY66P
Donāt worry, weāve all done it 𤣠ā donāt let it slowly cook your brain. Stay safe!
he said it's completly wrong
I am an engineer too but I know nothing about microwaves, being an engineer doesn't mean you know about it
and, non ionizing radiation cant strib eletrons from an atom
Can I DM you the generic details? It relates to a particular CVE
Having trouble with understanding one part of it
thank you appreciate it, ill check right now
Gave +1 Rep to @mossy river (current: #6 - 1470)
Itās not completely wrong either š
yea but he told me that he is wrong, because it is non ionizing, it cant strip eletrons from an atom and thus, cant cause cellular damage which increases the risk of cancer
even look at the comments
But he doesnāt say it causes cancer in the video?
Sure go ahead
he said its dangourus
which is conplete bs
because every second of the day, we are exposed to non ionizing radiation
Can we acknowledge the fact that Montgomery never stated to be an expert on the matter?
The microwave video was a random one but he's had plenty of educating material on that which he actually claims to focus on
yea but he was still wrong in that short, which is misinformation, the whole comment section criticized him for it, like every comment, and he saw them (ik he saw them cuz he hearted a comment so that means he was scrolling through comments) but he didnt change the info he siad in the video
I understand what youāre saying @neat belfry And you are correct, but he doesnāt actually say itās dangerous, he just says you shouldnāt look into the microwave
Regardless of whether it's ionizing or dangerous radiation or not, that video showed me that I have no business being so close to a microwave
Microwaves are non-ionizing radiation, so they do not have the same risks as x-rays or other types of ionizing radiation. But, microwave radiation can heat body tissues the same way it heats food
You're stating that it's misinformation as if he spoke about a pandemic vaccine
Source: US FDA
Probably best to keep politics away from here š
My brain is frying right now, I found a 270 bpm song
You into raves as well?
I know dw š just best to avoid it altogether as it may spark a discussion
Fuck yeah
Hell yeah let's go rave together
Welcome to German underground
I deleted it just in case then, I'm definitely not going to be responsible for that š
You've raved in Berlin??
Berlin and Hamburg
Is this one "Jr Penetration Tester" free or need to be subscribed
Saving this for later š
Ahaha, youāre all good, thank you for understanding 
Gave +1 Rep to @topaz topaz (current: #291 - 22)
There are some rooms inside the path that are premium only
I'm not going to chatgpt about my time management so I'll ask for suggestions here instead
Did my daily language study
i see thank you, and the rooms inside the path which are premium only, if i skip them does that effect my learning process or not badly?
Gave +1 Rep to @simple valve (current: #22 - 443)
I have the sub, learning from it, and have to learn python, with my academic subjects including Blockchain, Cybersec, and clooud computing, also have to prepare for my upcoming MSc entrance exams, how do I juggle between them?
I wouldnāt say thereās a ābigā effect, Iām sure its possible to find other resources that are free.
But the content quality of THM and its accessibility (most you need is in the same platform) makes it a good option also
Hiya zumi, been good. Stressed mostly lol but its been good
How you been
yeah i agree id def subscribe but dont got a job rn to pay so im trying to find online things to do to generate money
All paths are free to access, however have subscription content.
Are you a cyber student?
no, im business intelligence student, looking into cybersec
@mossy river care to set up a community give away?
OSWE is in my eyes but maybe CRTL too if time permits. Also eyeing pwnedlabsā AWS red team cert
I have a subscription code that's no use to me, #community-announcements give away?
yes yes
How about you add it to Bellaās list? š
I can guarantee CRTO is good, acces to Cobalt Strike makes it super fun lol
Could do.
@chilly veldt add a 6 month THM voucher to your list. š
how do we enter the giveaway :0
Good afternoon everyone. There is a Governance and regulation room I am starting today for my GRC journey and just wanted to know Are there any other rooms I could supplement it with?
Can you explain after what level can you consider getting CRTO?
Try out Mythic if you have time. I hear its better if you plan to customize
Thank you, I will look at it. Would be nice if more rooms could be made specifically for GRC and that career path.
Gave +1 Rep to @fervent meteor (current: #58 - 151)
(happy that I didn't get timed out for mass ping)
It really depends, I can definitely say the techniques outlined under CRTO are enough to pass.
If you edit the message it doesn't ping.
what about forward?
I didn't get the ping for that, so no. š
ah, bot might still think it's a ping 
Is April the deadline here
yes
the giveaway will happen the 4th-11th of april
and it sounds like @shut hawk is doing nicely
š«”
Keep gymming it out
Big blob
the title of the video combined with the ending phrase "don't fry your brains" clearly suggests that the video is potraying
a look at a microwave as potentially dangerous
the wording he used implis that there are risks associated with staring at a microwave
Mhm, you are right
What if there are?
but there arent.
Maybe not if you're standing away from it a little bit. I could 100% see people pressing their face against the window though.
How else will I. Know if my food is done?
This is my point exactly
my eyes crave radiation poisoning
even pressing your face against the window is in no way dangeroos
okay, let me explain.
The grate on the front of the microwave screen blocks microwaves
non ionizing radation
sounds like something my eyes need a lot of
is radiation that dosent have enough power, to strip eletrons away,
Microwaves are still dangerous to humans, thatās why they have that casing around the microwave with dots on the front panel
Microwaves can heat the water inside your body, as well as damage your eyes
Looking into a microwave is fine, pressing your face against a microwave isnāt recommended
My face craves a microwave mask
ionizing radiation, has the power to strip eletrons away from an atom (which is why it is dangourus) btw heat is caused do to eletrons movement and interaction FYI which is why your car is so hot when it is under the sun, it is metal and metal has valancey eletrons that can easly be disattached from the atom and thus creating the movement which is why your car is hot when exposed to ionizing radation AKA sunlight.
and ionizing radiation also causes cellular damage
which increases the risk of a fault in the dna making process
which can lead to cancer
I just realized I need more sunlight
which is why people say ionizng radiation is dangourus
and non ionizing isnt
but
BUT
BUT
GUYS
why are we in chemistry already XD HAHAHHA jkjk
Microwaves can cause tissue damage and heat up the liquid inside your body causing it to boil
It wonāt happen from a modern microwave, but if your microwave is damaged itās best to not put your face up against it
if the microwave is leaking radiation
Like the microwave isnt working properly and ur exposed to all of the radiation
how do you make the colors?
God I hope my microwave is leaking radiation
There are filters in graph view you can set
becuase if you stare right at it, it can damage your eye, because of localized heating
which is why people tell you not to look at the sun
with a magnifying glass
very dangerous
very
So we both agree š
VERY
yep, to some extent
š
I look at the sun šŖ
thats ok, but dont look at it with a magnifying glass.
DONT
I WARN
Yk warning me not to do something is going to make me more likely to do it
because fyi if you shine a bright light at a magnifying glass and point it at paper, the paper burns......
I mean... I wouldn't stick any appendages in a microwave. As such, I would not trust pressing my face against it as a being safe.
you shouldnāt look at the sun magnifying glass or not
you get my point..
I dont seem to see the option for colors?
yea, it can cause solar retinopathy which can damage ur vision, cuz the light
can burn ur retina
but like
u'd have to be looking at it
for a long time
and ur body tells u when it is causing damage
It's under settings in groups, my bad
Why are we having biochem class in a cybersec server anyway
which is why u wouldnt want to have a superpower that makes u feel no pain
@mossy river
That's a goated superpower wtf are you talking about
thats the dumbest thing u can have
I'd be invincible
what?
Itās not a super power at sll
No you would not be, just not would not notice when your arm falls off. ;D
Tis but a scratch
Itās a medical condition called CIPA š
do u know pain is a message, that ur body tells u, to stop fucking around, like when u punch the wall or smth
yea ik
ah thanks
Gave +1 Rep to @karmic hemlock (current: #393 - 15)
ive seen a video about a girl with a condition that makes her not feel pain
A TV show you mean?
Congenital insensitivity to pain (CIP), also known as congenital analgesia, is one or more extraordinarily rare conditions in which a person cannot feel (and has never felt) physical pain. The conditions described here are separate from the HSAN group of disorders, which have more specific signs and cause. Because feeling physical pain is vital ...
They also made an episode of House about that
^
Regeneration + no pain = invincibility
no, like a video on it, a real life event
like there was a girl with congneital
insesitivity
to pain with anhidrosis
or CIPA
Ah right
true
Itās a very interesting condition
yea
Yall have fun with biology lab, I'll be back this afternoon
biology is my fav
then physics
I thought that was just audhd related
physics L
Feeling almost no pain
NEURO
Chem W
If you continue to post so many messages in short psace of time, you maybe auto-muted from the bot.
God willing
what a way to kill the vibe
Just looking out for you is all
It's a friendly note, take what you will.
Iām lurkin from the toilet 
Next time I won't say and let you get muted. 
VirtualBox - Error In supR3Hardened WinReSpawn
NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries) (rc=-101)
Make sure the kernel module has been loaded successfully.
where: supR3HardenedWinReSpawn what: 3 VERR_OPEN_FAILED (-101) - File/ Device open failed. Driver is probably stuck stopping/starting. Try 'sc.exe query vboxsup' to get more information about its state. Rebooting may actually help.
can someone help me with this
it happened after I updated VirtualBox
š L auto-mute
wait i got a question, who coded this server bot?
@mossy river coded TryModrrateMe.
TYPE SHITTTT
MY BOI JABBA KNOW HW TO CODE
Try rebooting
thts my boi
Thatās a different bot, TMM doesnāt auto mute
When does the results for the SOC Simulator competition get released?
I know, thats why I named it. š
yo jabba can i dm u
Go for it
Anyone know about how many users are on THM?
I'd like to calculate my %
I can't give you an exact number l.
estimate lol
ok ty!
im hungry but I only have instant noodles
proceeds to give an exact number?
It is rate limited.
It's also on stats
Theoretically a small portion of those are probably alts/remakes
Still accounts on the website.
They didn't ask for active
Fair enough! 
In the % calculating does active matter?
@mossy river
like top % ?
Yes
Yes
how does he sound like?
Like Jabba š
does he have a deep voice?
plot twist jabba is a girl whos catfishing us
Like a human, presumably (I don't want to assume).
or a sexy voice? like drake
Man Jabba really getting the k-pop idol treatment over here.
Id never reveal any information I know about anyone on here.
Heās obviously Batman
@mossy river
Any reason I canāt use the AttackBox when I havenāt touched it today? Telling me I already reached the 1 hour limit
Maybe u used it last night 12-1 ;-;
does it also include the information of whether or not jabba is human š
if you need any tips, im open
or any life advice
or any coding lessons
or any lessons about ethical hacking
advice
or anything
im open to dms
This was funny:
Logged in to Shodan through Google SSO --> Accidentally opened Gmail --> Looked for scan results --> Found a link to a Quora post --> Spent half an hour reading some romance trash Whatsapp screenshots

I am the master of falling down rabbit holes
not rlly
tht dosent make me laugh
i have a complelty different humor
Not that I know ofš
do you just conviently have this meme available š
It's hard work but it's honest.
I am gratefull my uni has public transport
I get some of the weirdest romance ads come up on YouTube shorts
???? but shadow just updated their linux system and reinstalled discord completely ????
Somebody on GitHub said itās usually bc of missing libatomic now idk what that is but u can look into it
that package does not seem to exist for arch though
Auh
I just installed my discord in arch through the app to install stuff
Seemed more practical
never mind found it
I don't use arch btw š
My brother reset my all rooms wthhh
Be like me and remember every room youāve ever done (only ever done like 15)
Someone tell me the difference between a white hat, a grey hat and a black hat without a shitty answer
white hat is 100% ethical, black hat is 0% and grey is 50%
Its according to legality
White hat - stays within the law
Grey hat - willing to break some laws
Black hat - breaks any law doesnāt care will target anyone
I also use the web version just to save some mem
This is a white hat server
Grey hats aren't technically breaking laws, they are pretty just doing white hat things in an unethical manner
They are
which is breaking the law
Some ppl act like itās the most disgusting thing ever
Doing any hacking in an unethical manner is breaking a law
Using white mode has to be tho
you are either breaking the law (black hat) or not breaking the law (white hat)
nah i found a funny ass real but idk if i can send it here
White hat activities are only legal because they're doing it in an ethical manner with permission from an organization. Grey hats (your "hacktivisits") are still breaking the law.
The law being broken requires law enforcement, otherwise there would be no point in enforcing laws right? So it's just unethical
It's the people that don't know what they're doing that are breaking laws
This is certainly a take. A wrong one, but a take.
I use eclipse in the default white mode
Using a computer to gain unauthorized access is illegal and unethical
Grey hat seems more like ethical illegal hacking
black hat use dark mode, white hats use light mode.

ah so i'm a black hat then
this is a joke and I am not a black hat
welp none of the fixes work D:
Also ignorance of the law is not a defense of a crime
:[
Yeah, simply put, that is true. Hats are just intent really
"but the stop light looked green"
No, you either break the law or you don't break the law
So a gray hat is commiting crimes. Hacking a scammer could be seen as ethical but it is still illegal
Hats are not just intent, please don't misconstrue the legality of cybercrime with metaphorical nuance.

Hats are stupid
I'm a white hat
Just do it or sit there eating eggs
has anyone used the Thinkcloudly SOC program?
Good or nah?
the police do that all the timeš¤·āāļø
Sometimes when a electric scooter rider whizzes past me I feel like kicking them but then I remember I could seriously hurt someone doing that š
I look stupid with hats on
-
If they do it without a warrant or an exception to the warrant requirement itās still a crime
-
If they do it without a warrant or an exception to the warrant requirement it is not unethical or a crime by societal standards
A beanie then maybe
what if you gain unortharized access, to solve a crime
and your not LE
still illegal
Inadmissible in court and you'd be charged?
what??
Vigilantism is usually illegal
It depends on the facts of the case
i did 20
Itās a different crime
Itās not an illegal search
Itās unauthorized use of a computer
you cant be solving crimes if you aint police
so like of theres a seriel murder on the luce, and i manage to track him down and call the police on him, is that still illegal?
well what if their asses cant do their job?
If you did so through illegal channels, it's illegal, period.
It gets really murky
thats why some ppl take the matters in their own hands
It really depends on the facts of the case
horrible, corrupt law system
But you will probably get hit with a crime too
Depends on the methods you employee ig.
I know someone who does or did this, but he'd have a PI licence. Idk now, I have lost contact with the individual.
That's the opposite of the law system being corrupt.
U should play persona 5 š¤
but yea you can still be charged
Fruit of the poisonous tree would not come into effect because it applies only to law enforcement
But a defense attorney would likely be able to get that evidence suppressed
lawforce do be incompetent though, i agree with that
As it was obtained by you by illegal means
And the chain of evidence would be broken likely
yes, very, they dont know how to use computers well
but you cant do anything (legally) about it
what if u offerd the police to help them
This is not a complicated concept.
You canāt just offer to help them and then go commit any crimes
like u call 911 and be like; yo, i can hack n shit, and can help yall mf's find the criminal type shit.
this will hunt my nightmares
No
they are going to refuse
huh that is weird
U can just get a law enforcement job atp š
the discord canary build does not have the error message
no, I am not gonna be employed by the feds
i will never help the feds
-_-
theyre racist and corrupt
So donāt call and offer help first of all
Kids these days.
you can solve and help tho
well, jidion does it
Black hat hackers have malicious intent when they take over systems.
Grey hats don't have authorization when attacking systems but have the intent of disclosing it. (Which is technically illegal)
White hats only hack where they are authorized to
never heard of him
huh????
Okay? The law doesn't care about your distinction, why are we still talking about this?
how do u now know jidion???
again im not american
bro he's famous everywhere
Can I be a purple hat hacker?
What else do you want to talk about?
i dont know every american vlogger around
Yes
the chat is š„ š

what do you know this server is actually relatively active, thought for sure this would be one of those lame official servers where everyone ignores one another
he used to be a funny ass prankster, like he'd go to walmart or the police station, and troll them hardš like for example, he faked pulling a fire alarm, he made the royal guard laugh, trolled a bunch of police officers, like he's hella funny
Yay I can hack for fun and meme purposes
every day, i'd wait for him to upload
just go get a good laugh
very famous
then he got old
and decided to quit
and become a christian
That's not what a purple hat does lmao
who did
That's a black hat
but he uploads vids of him catching criminals, preds etc
But I want to be a meme hacker
jidion
the streamer ?
Then you'll become a meme
tcm academy was like that
he turned a small town in arkansas for the better, called zinc
Yay now I can try hacking and fail miserably allegedly
yea
a hacking evangelist š
and youtuber
No, it's illegal to even try
i heard he deleted all his socials and stuff good on him bettering his life
You don't have authorization
mostly black hat are hacktivist
This is incorrect too
Fine
i was talking about this jidion guy
APTs and nation states are not activists
you can go with 50 50
when's thm birthday
ik that guy but what i think is this guy has some connections to keep the guy safe
we enter some dubious legality with nation states
In nov i think š
yea
We consider APTs and nation states (that arenāt the US) to be black hats for sure
yea but if a russian hacker hacks the US its probably legal in russia
why would he care about US legality
Can I ping localhost to get my IP?
use ifconfig
The USA considers the NSA to not be an APT but garunteed china and Russia consider the NSA to be an APT
Kitkats are always good chocolates
kitkats are a cake
its kinda hypocritical to not count the US as black hat when they do it to other countries
No politics
It doesn't work
Shoooo, go away. I like to have my fair share of drama!
I think it just comes down to the perspective of the person doing analysis
Localhost is 127.0.01.
In all fairness foreign nations have a term for this called extradition. You can still be charged for crimes committed in another country (especially cybercrime), and brought to that country for sentencing.
Actually, it's 127.0.0.1
So is that my public IP address?
Get it right SCRUBZ
Sure if the nation has an extradition treaty
I have a spray bottle. I never thought of this before but itās a great idea
Or if itās in pursuit of a greater goal
No, that's your local host.
Which os are you in?
Like peace relations
I'm windows
A country will still make the request, even if they don't have a treaty, and they'll remember your name and come and getcha if you end up anywhere they can reach you.
or they might fly out agents to capture u
IPconfig or ifconfig
Yeah for sure. Lots of hackers in Russia and china have been caught because they went to a European country with an extradition treaty to the US
Ifconfig isn't working..
unles s the other country agrees its illegal
Ip a
In powershell?
ooooh powershell
Ip a is bash
like julian assange, the cia even debeted going to the country he was hiding in, bringing in agents to kidnapp him, nd take him on a flight home, or they even considerd shooting him
i thought you were on linux
Try IPconfig
i dont wanna mess with them
Ipconfig is for poweshell/windows
Ahh
Get-NetAdapter -Physical | Get-NetIPConfiguration
yea but thats cos the US is always doing illegal stuff
Alright it works but is it normal to see 10 different connections?
Ty
Gave +1 Rep to @high mulch (current: #231 - 31)
Depends what is using Which interface
If you've set up a Hypervisor at any point it can set up a bunch of persistent interfaces that show up.
Some interfaces which I haven't heard of before
nah, tbh if i was a government i'd be that pissed
he tormented us embassy officials
leaked a lot of classified docs
a ton
of embarrasing
vids
of horrible stuff
Yeah I've set up a hypervisor but there's other connections unrelated, are these other interfaces set up on my host?
Bruhh, I almost banged my head while solving this room. 10/10
thoguht medium rooms wound earn more points
nope
I don't think so
Those only exist to make your life miserable :P
Well without knowing more I can't answer that question for you. If you've got VMware you'd see a bunch of VMNet interfaces. You might see multiple Ethernet connections, or multiple LAN, or- etc etc.
to enable wsl, open powershell as admin, run wsl -- install, restart ur computer, and it also installs defult linix distribution (usually ubuntu0 then insall net tools in linux terminal
write this int he terminal
sudo apt update
sudo apt install net-tools
after installation, u can use ifconfig in wsl terminal
?
@graceful mauve
y'll got any good room suggestion?
Ty
if u want smth simpler
u can download netools for windows, like nirsot network tools
Did you know that you can use the entire local host under the CIDR notation of 127.0.0.1/8
Hah
ty @rough gorge for the walkthrough!
Gave +1 Rep to @rough gorge (current: #231 - 31)
How comes on the website thereās a easy path for blue team on soc but junior pentest starts at intermediate š„¹
There should be an easy room for dummies like me
More experience is required for penetration testing
who here has ever found a 0-day, i know jayy has and aquinas too i think? and maybe 0day, anyone else
yes it is
I find 0 day sales at the store when Iām hungry
stop the cap, it is
That made sense in my head
Lol, you're a funny guy
its when u kinda do a cyper attack against a cmpter system, ntwork, or web to identify vulnerabiltites
tht attackers could exploit
for the org
not tht hard
Okay without stirring it yeah. I though blue side was harder
Right
Yeah, it's a lot easier to talk about it than to actually do it
dude ive done it before
š„¹
Done what?
both are tedious

