#general
1 messages · Page 822 of 1
I assume the box is a reference towards HTB
i did, its a HTB logo made into a garden = pun

gimp?
oops sorry
Is there a dark-mode version? 
why lol
did i tag the wrong person?
noo
it is mostly catppuccin mocha palette but yeah agree... it is good palette
I can make turn it into a dark version for you if you wish
no, i used Figma
graphic designers who use gimp as their raster program too based
lol nice lots of figma hype even in corp
i use one of shadows wallpaper from her git, i think cloudy galaxy or so
just let me know if I can DM you for it
why does my machine not work, im not on a vpn or anything
Sure thing!
Figma was way better in 2019 than it is now, its crappier now
i used to use gimp cos i didnt know how to pirate photoshop
i was calling you a _ lol
it is better to be a veggie in a garden than a fruit in a farmer's market
#site-support maybe?
Where to find the token
On your THM account
i dont know if this is a good thing or bad thing
🤦♂️🤷♂️Then Why does the guide say discord profie
https://tryhackme.com/manage-account/account-details scroll all the way down till you see this
I hope that aint your token
thats all the info i needed to hack uyr account
It's not.
good luck
it says dont share
let me know when you hack it
underscore needs more love
shadow has one persons token :D
Void about to be the next 50$ steam commnity marketeer 😭
shadow's?
especially for variable names !
yuups
i hope its an "easy" one so i could have a hope of solving it
which one
where i mean
we will have to wait and see
7PM GMT.
Thank you
Gave +1 Rep to @arctic cradle (current: #273 - 24)
tryhackme releases new ctf:s on fridays
i also know all your tokens
nice
Does anyone have what SHADOWBROKERS shared on GitHub in 2016???????
(just not who they belong to)
oh i forgot about that one
i guess you could impersonate another account
@upper minnow how is your back doing? feeling better?
ctf's??
not really, but thanks for asking
Gave +1 Rep to @grizzled wing (current: #50 - 172)
capture the flags
also known as challenges
doing a massage next week
A.K.A nerd puzzles
A.K.A throwing random shit and see what sticks
A.K.A cyber war games
My uni hosts ctfs but I feel like I’m too slow to do them 
🤓
Baba is Adorable
Sounds fun, or is it?
the second best puzzle game ive ever played
what is baba?
first is outer wilds ofc
Baba is Rock
my fav nerd puzzle yt is ted ed lol
I am Beginner and learning java ryt now,do I have to invest time more in mastering java or should I spend it on rooms in tryhackme which practice will make me a better cybersecurity expert or penetration tester
??
Baba Is You is an award-winning puzzle game where you can change the rules by which you play. In every level, the rules themselves are present as blocks you can interact with; by manipulating them, you can change how the level works and cause surprising, unexpected interactions! With some simple block-pushing you can turn yourself into a rock, t...
$12.49
18100
87
its from a really complicated puzzle game
i searched youtube and then your comments showed
@high mulch it's done, I will just post it here, lmk if you want any other modifications
depends a bit about how you tackle the problems and what topics you find fun
.
when theres a random void in your yt home page
???
java will teach you how programming works and maybe how to detect bugs
tryhackme rooms will teach you a wide area of different attacks on software but the programming parts will be missed out on for the most part
I also tuned the colors a bit (give me a second for the full res to load at IBB site)
pwetty
java isnt really a big programming language
for hacking the best ones are python,C, SQL and javascript
been working professionally with Photoshop for like 15 years now, I still prefer to do stuff with it on my own rather than using an AI lol
is this meant to be the kali dragon
thx mate
Gave +1 Rep to @arctic cradle (current: #268 - 25)
no idea, shadow posted the picture
Java or coding is not essential, knowing how HTTP works and other fundamentals is. Coding skills is an asset that will help

I'm sorry,software attacks don't need much programming??
again depends
knowing how to read the malware
yeah as a lot of tools are already made
another game for baba fans
Yea but I want master atleast one lang
Master C if you want low level, that is very beneficial in cyber security
yea python 🐍
do you want the PSD file as well if you want to tune it later on?
i dont think having c as your first language would go smoothly
Pietone
Yea but I want to master atleast one lang and am learning it in my college but they are very slow,do u suggest any source which helps me progress fast
Nah, I'll probably procrastinate that. But thank you again! :)
eh its a good way to not get addicted to OOP
What's the difference btw java and JavaScript
i agree, but this person started with Java, so i went with another language that could be appealing. Python is the better for most cases
idt i'll ever be addicted to oop lol
JS/JavaScript is a lang for web
I love objects
language for cyber security coding , hmm, that is usually from books No Starch Press has great selection. geeksforgeeks is a great resource for languages.
also w3school
if you want/ have $ you can learn from the youtuber Low Level Learning, he teaches C for cyber security (no idea on quality)
thats my go to !
low level learning kinda likes to overcomplicate stuff
theres also a few websites where learning coding is gamified
he is also full of ego
that’s like 80% of the computer science community if I’m honest 😅
freecodecamp on youtube is always available
we all have our own egos
i know assembly btw
i think
depends on what field of computer science community you follow, i watch and follow Data Science, no egos there
do you know Assembly?
you can opt to go to freecodecamp.org and find a better structured road there, instead of the Yt videos.
I kinda used to jump the videos timestamp because I found some steps slow or redundant.
no i mean hes always harping about assembly
oh ok
So is 80% percent of the cs community complacent
bet the first thing he tells a date is that he knows assembly
he is married
I know assembly, I know it exists thats prettty much it
i know that Assembly exists
i know sooooome assembly? not confident enough to accurately translate it to code
Yeah, you forgot the pickup line that involves mentioning their use of arch
latest app shadow has used that was entirely made in assembly that shadow knows of is the grc.com dns benchmark....
i watched 5 minutes of freecodecamp video on it and was like nooooo, back to Python for me
they say deepseek was made in assembly which is insane
yea, i heard that too
for those that wanna learn assembly: https://store.steampowered.com/app/370360/TIS100/
TIS-100 is an open-ended programming game by Zachtronics, the creators of SpaceChem and Infinifactory, in which you rewrite corrupted code segments to repair the TIS-100 and unlock its secrets. It’s the assembly language programming game you never asked for!The Tessellated Intelligence Systems TIS-100 is a massively parallel computer architectur...
$6.99
3136
video of what? because they do have python courses too
tis ||nuts||
tessellated intelligence systems
tis ||tits||
oh its part of a hacking bundle
not surprised there but did not check the bundle
are all shadows links store.steam ?
also please if you plan to play tis-100... print out the manual on actual paper and use staples to stick them together
it makes the experience so much more fun
Well, learning assembly isn’t a choice for me, I’m a student and it’s a requirement down the line 🙃
nooope
🤢 some Assembly required
are you the same hello kitty or a new one
same i HAVE to learn mips 😦 why cant i just learn x86
I just joined yesterday, I didn’t know there was another hello kitty
Hello Kitty 0xHacker
never knew hello kitty could hack
@polar shale is the fellow hello kitty
blakey is kitty too
Oh, that’s funny
that doesn't seem okay
you two are the same rank so i thought it was the same person
we have 2 🦉 s
bit and?
how many shadows you got???
who knew turning my head to the side monitor will lead to neck pain, I now can't turn left lol
more than 1 🐰
we have 1 
should i invent a hacker name instead of using my real name
ooh fun usernames
my name in online places was usually chagarumagala
why not
Make it the dragon warrior
shadows username is from ages upon ages ago
dragon warrior is poop class in dragonfable :P
printer_hacks
god i grinded so much for it
Chargoggagoggmanchauggauggagoggchaubunagungamaugg
did you know that printers can play the doom soundtrack
no one could pronounce it so everyone just called me chag
any sound producing item can be an instrument, any instrument can play doom ost
is mayonaise an instrument???
yes.
Song made from only mayonnaise.
I hope that the quality of this channel is evened out now from all the yeah boy videos.
Animated footage belongs to Nickelodeon/Viacom but is used within fair use. Everything else was produced by me.
Tags-
is mayonnaise an instrument
is mayonnaise an instrument remix
is mayonnaise an instrument song
is mayonnai...
im doing principles of security room and i cant for the life of me understand this bell la padula model vs biba model
📧 I just got mail from THM
what is it 👀
@rapid merlin thanks for
You don't have to be great to start,
but you have to start to be great
Gave +1 Rep to @dim path (current: #418 - 14)
did you know that diagrams date back to cave drawings
I threw in a fun fact
electronic postage letter, sent to your inbox every friday that informs you what happened in the week of THM, who are the cool people on the leaderboard, new rooms, etc
but if someone down can write up cant they alter stuff they arent authorized to see?
I want to purchase HTB vip pass, but I don't have credit card. Can someone help me with gift code. I CAN pay
gosh i need to revisit this room someday
I mean I wouldn't know, you're studying it
It’s been a bit, but I think I understood it as being able to pass new documents you wrote upwards rather than altering existing ones
oooh makes sense
I saw geeksforgeeks until now,but why did u suggest me that and have u taken a course there?
I was looking up to take java class there but they've got videos recorded and that is how they'll be teaching
i use geeksforgeeks as a reference often. i have not taken any of their courses
Will recorded classes be worth a shot
no idea
B O R 
udemy already has a deepseek course 
of course 😭
I came across its Ad, and LOL'd
that^^^
gn mate
how deepseek's search function never works
Oh god, not the AI programming
Its gonna be banned on the us soon so why bother
XD
You can run it locally from what I've read, and tweak it.
True
But most arent gonna be bothered
Good thing my country has good relations with china
ok im back
any other arch users having issues launching purp post jre 23 update?
hi twinn :3
hi 👋
seems to be working fine on mine
you dont even know the mistake I just made it was stupid lol..... the project tried starting on my internal display (which is closed) cauing me to think that it was crashing only to find successfully launched in logs .. checked my internal display and there she stood ... LOL
i think i might need more tea
or maybe less
idk
why do yall drink tea again
green tea because it is good asf
As a tea drinker, it tastes good
health benifits too i guess but mainly becasue it taste good for me
i normally hear coffee
Drinking herbal tea also causes me less stress than coffee
coffee is okay. I coudln't imagine drinking all that daily espeically the coffee we have here in america
big ole' 500ml mug, filled with at least 10-20 grams of sugar, creamer and other nasty shit idk im good
sounds like a desert rather than a daily beverage
i only drank it in the morning sometimes
Real, I always get weird reactions when I tell people I drink unsweetened tea
another one is coming
I will add a slight bit of honey at times for naturally added sugars
🤮
but mainly just plain
dont like honey?
Where are the energy drink enjoyers at?
switched to tea
I must be weird because I’ve never had a single energy drink in my life
Tea over here
I don’t know why 💀
i struggle to look for the emoji so i kinda send it late
guys someone wants my ip and wallet address? this is 100% scam right -_-
i love honey
Yes that is a scam
to be honest tea with low caff brings me more energy than a 300 mg can of monster for example
We do it for the kingdom
ohhh lol
lol yea
prolly skiddy scammer lol
"what is your IP"
Yes it a scam never send your ip they only need the receive wallet address
you aren't missing out on much
you can't really do much with and ip can you (public)
Not much
unless you really know what your doing
They might be wanting to send you free RAM for your computer.
yes, back in the day you could call up ISP and SE them into giving personal details but long gone are those days lol
they aren't stupid anymore
But some people can find your private ip from your public
Mediacom was the easiest to target
social engineering 🔥
Let's be honest, if someone wants something hard enough, they can get it
but they can't do nothing
you have a private IP to communicate with devices locally within your network thats it there is no need to conceal your client IP address
Gd luck I got proxychains
D:
Please don't take my moneys
doesn't the nsa spy on end points or something
to late
oh wait
im thinking or tor
of*
proxychains relies of tor in a default config
brb going to lunch
Yea but if you mix the proxies to countries the nsa have a hard time accessing like Russia or the Netherlands you should be good
And you need to make sure the servers you use don’t keep logs don’t use the free servers pay for it in monero
And you can make the proxies dynamic which means the end point won’t be the same it will keep bouncing around
i think you were using defualt
@arctic patio siri the ai ?
when i was a skid i use to go logging people ip and thinking i had theiir location
lol it was what it was lmfao
isnt it the server location
x-forward-to face ass lol
i gotta learn my headers 😭
ISP location most of the time and is pretty accurate to at the very minimum the state/city the ISP / host resides
pretty useful if you want to report suspicious traffic as well just run a whois on the IP and you can get an abuse email to write to
yeah
Made up the name years ago, just kinda sticked
ah
if you are into that kind of thing
what dones that do
does*
isn't it like logging ips
on your site
Found my parents address and phone number by looking up their name on google 
same
When I looked up mine I saw a pretty lady that definitely wasn’t me tho
lol
if you dont mind me asking how old are you
19
when did you search yours
because im pretty sure you can't find nothing public on anyone under 18
Just now
Fun
depends
if someone under 18 registered for a service that got breached, their PII would also show up
i meant with osint
Mine looks about the same! That's what happens when you're just starting out! lol How long have you been at it now? I'm like... maybe 3 months in.
year
Great job , keep going 🙂 🚀
I've been practicing and playing around not on tryhackme
I was mostly doing malware development
and networking , and coding
well not malware but making windows applications
anyone else here ever feel lik you're NEVER going to get this stuff??? LOL I just keep plugging along but.... Uggg....
I have NO IT experience before starting this so...
trust me the more you do it the more confident you feel
i thought i was never going to get it
How can you mostly do Maldev, but not actyally make Malware?
what level rooms are you on now? Med? or hard?
i didn't do madev
im looking into i wanna start doing malware development
easy for me
you want to develope malware??
med
yeah
why?
it seems fun
I don’t think that’s appropriate chat
that was my thought.
didn't know that
maybe for like.... sending to scammers networks to delete all their files... THAT would be cool!
that would be illegal
Illegal.
who's gonna report it? The scammers??
Is that gray hat
wait its not
Black
Kinda thought so
That doesn't change the fact it's illegal?
well, it's illegal for them to take money from me under a false pretense/lies. That's also illegal but no one will do anything about that. SO....I wouldn't feel bad doing that to them cuz they're STEALING PEOPLE'S MONEY.
U can try reporting it to the cops
Though whether or not they do something is iffy
Sueing is prolly better
Gl with this one scrubz im out
I all ready did.Reported to the FBI. I got NO RESPONSE>
you can't sue anyone if you don't know where they really are and you can't find them now.
Like bruh
if you do send malware to the scammer you and the scammer will go to jail
100% justice
Some of this stuff takes time too, unfortunately.
And there're a bit more variables to that too.
I could use malware in red teaming if i ever get the job
naa..... scambaiters do it on youtube videos and they're still around
I reported it in June of 2024. Still nothing.
do you know how the scam centers work?
yes. this wasn't a scam center I don't think but.... was contacted through FB IM
for a crypto investment scam
ah
hmm
idk honestly
someone can
There’s not a ton they can really do besides track it. But getting the cooperation of certain other countries is extremely difficult if not impossible
On top of the other challenges that go into it
also the scam center just don't run in plain sight
I'm schooling myself on this to learn and to do good with it. Like to help OTHERS get their money back or whatever if I can get a job doing that. I'm going into digital forensics
yep. I know.
Money recovery should be left to LEO.
I don't think their a job for that
The money is also usually gone
Hacking a scam centre is illegal, there isn't any justification for it.
well, digital forensics CAN
um no
not for some things. but others there are.
yes.
yes it would and it would be AWESOME!!! Maybe someday.
And you're banking on
A) The money transactions present
B) Gift cards not to be used.

but the government would be extremely mad
I heard a podcast one time of a guy who was saying that everythign thinks that you can't trace crypto, but you CAN... but it's a long process.
How is everyone doing...happy weekend to all 🙂
Can't banks do that
I mean that’s the whole point of the block chain
In other news.
Ghidra 11.3 is out.
good not weekend yet till i get out of school 😭
ya. they say you can trace it but it doesn't tell you who it is.
And you can’t just always reverse a financial transaction
A thought entered my mind, does moving crypto between many wallets cost commission fees?
Learning about abstract data types rn
IDK..... I'm just working towards digital forensics and wherever that takes me.... and then to learn some scambaiting skills to maybe help stop others from being scammed would make me feel better about losing so much money.
If you use debit that money is gone
yep all the time
depends on how you do it
I remember that ai grandma
theirs very thin line between illegal and legal
The new python lib for it is so good
I've not had a chance to play around with it yet.
Interesting
There really isn’t. You either are following the statutes or not
I'd love a way to interact with it through Python
The morality or how they are applied is gray
Legal and illegal is a pretty solid line just go ask a lawyer I think ur confusing illegality with immorality
The only thing you can really do is waste their time.
well sometimes it can be thin
one accidentally typo
No not really
Intent is usually always part of the law
No because grey hats are deemed illegal so...
In fraud you have to prove intent at least in the us
It's black and white
It’s called carpus delecti
Grey hats aren't a thing anymore tbh
You have to have intent and to do the act
Its either black or white
or green
So it's black or white
yea unfortunately vigilantism is illegal
Yeah
unless youre batman
I wish
It again comes down to how the law is applied that makes it gray
There was a guy in this server talking about hacking smth without permission and reporting the bugs
Doing illegal things without malicious intent is still illegal
fontaene
Yes there’s multiple states of intent
Ok so a question are there any good free/low cost Threat Intel sites that have live daily update on companies getting hacked along with data such as (T. Actors/Groups their attack vector practies) and especially listing hashes of malwares they use !? Possibly linking that to mitre aswell ?
Yeah, illegal
tbh the only reason id not be grey hat is cos im extremely afraid of getting caught
If you don't have permission, don't touch it, simple
Depends on the crime
Or you could end up in trouble
Agreed
and batman will knock on your door
Sorry it’s not corpus delecti it’s mens rea
idk why grey hat is taken in a viable context. its still illegal
it was suppose to be like a middle thing but i think the more you learn the less of a factor it becomes
yea but some laws are stupid
AAAAAA...wait just clicked on discord shot Civ 7 is comming 🙂 love this game...i must stay strong 😄
Grey hat hacking is like ordering a gun from the dark web and then saying "Well I wasn't going to shoot anyone with it"
its still not allowed
I don't think this conversation is going down a productive route.
Yeah it would come down to knowledge that what you’re doing is illegal which makes it prosecutable
does anyone know about the court case where they said inspect element is only used by professional hackers
That's not grey hat.
Isn't it like, pentesting without permission, but without malicious intent?
It’s rare but there’s a certain example of a crime that is punishable even without intent but I don’t want to mention it in this server
This is also true
Like, engaging with a target with no scope, ROE, etc
that black
black hat is with malicious intent
It also depends on the jurisdtion
grey hat suppose to be someone who follow the laws sometimes
They deal with both sides of the scale yes
from definitions
No.
Look up Khalil Shreateh, that's the perfect example.
if their osint but they want more info so they might get some info from the dark web(i'm not sure if this is right but someone fat check me)f
That's a very vague description.
fact*
Grey hat isn't down to having malicious intent.
I asked one professional once...and this makes 0 sense...who would violate laws for entertainment and not the money you can call those dumb hats
A lot of people have nothing to do with their lives.
thats my hat
People who want a safer internet in general
Omg that's crazy lol
I mean, they have a clearly outlined ROE, but how did that dude get away with modifying existing user assets that weren't his lol
It's pretty simple, like spreading malware to some scammer.
You want to do something "good" but you simply commit an illegal act in the process.
They morally view it differently
And on the other side...
https://www.thesslstore.com/blog/mysterious-russian-grey-hat-vigilante-patched-over-100000-routers/ - Grey hat with "good intentions".
so basically they follow their own laws
Breaking into systems to patch them?
well what the people want
But... it's still illegal, isn't it
Yes
hi
hi
Hello
sup!
sup!
can someone explain what exactly a gateway is ?
i m novice
Nothing much hbu?
That's my point though.
So is legal action not initiated because its negated by the fact that they patched it?
Or is it entirely dependent upon the jurisdiction of the customer/victim in this case?
@sick lance So it like if someone takes down a scammer website for the community?
Doing Active Directory room
That's illegal.
good intent but not ethically legal
Nicee
ik I'm trying get a better understanding of what they mean by the good description
Hello 👋
You seem new here, just started?
Ethical and illegal aren't dependant on the other.
Heya
I mean it comes down to law enforcement and the attorneys
They can choose whether or not to prosecute
hi
Makes sense
openvpn won't connect in kali Linux I tried OpenVPN: General troubleshooting
can someone help me
They could or could not for a multitude of reasons
Mhmm
No matter the intention or how much it benefits everyone, any action done illegaly and without proper procedure is well illegal.
Take OSINT
Doing Osint is perfectly legal.
However, what you do with the information would determine if it was ethical or unethical.
Hii
Which room are you at?
Time to study
Again it’s not the law that’s gray. It’s the application of the law and how it is enforced that’s gray
If you go thru the proper channels, yes.
Sometimes it can be a gray area. Like that BH who went thru the proper channels to unwrap a vulnerability on FB with his old laptop, he got ignored by Facebook staff, he proceeded to hack Mark's account iirc, as for PoC or something, and he wasn't eligible for the reward, until people started complaining and he got some money with a fundraise or something.
🙇 thank you sire
Gave +1 Rep to @sick lance (current: #1 - 3362)
Is it lazy. or a way to double check you're reading?
we can do that
Doing networking, trying to cover my bases
😂
✋ 🕵️ 🤚
There's a check for that?!
i thought posting answer were breaking a rule
Wow

✋ 🕵️ 🤚
Is that my little pony?
Yep 😊
Yup, please don't post flags in the channel.
oh ok
That's nice, well, I wish you luck
Search how many times I sent it and see who's combo it is
Which one, not apple jack.
People who text with punctuation are scary
Thank you, all the best to you too ❤️
Gave +1 Rep to @sturdy pike (current: #360 - 17)
Pinkie pie
oh btw i always wonder what if someone makes a bot to just answer all the question on all the rooms
Pinkie Pie whooohoo
well, our new combo then
I've gotten seventeen thank yous? DAMN
:p
LOL because you can't tell if they're pissed or not
People do, yes.
Hmmm.
what happens whne the do
One person did and got banned
Thank you!
Gave +1 Rep to @wheat flare (current: #1061 - 4)
study or gaming
ah
Smarttt
Fortnite time.
are you trying to get me insane 😛
I will finish this battlepass
Who still plays that...
Crazy way to say HTB
COD?
Am I the only one who never played it?
I play OW did also finish the battlepass
wish they had taught us smth useful like love2d in college instead of fucking opengl
I'm with you
Replace words fortnite with life and battlepass with calendar year
Subway surfers on another monitor for ultimate brainrot
(. ❛ ᴗ ❛.)
like what am I gonna do with opengl in my social life? Increase the graphic processing?
subway surfers was a fun game
Nah, I didn't buy this one, the skins look shit.
yeah it was fun
Temple run 😭
Did you ever play Civilization I can see numero 7 comes out :)...i am not even going to look at it...instant adictions
The nostalgia
i used to play it
Are you a gamer? What else have you played?
play this https://neal.fun/stimulation-clicker/
you like my little pony or you just using it as a pfp pic
its brainrot speedrun
just wondering
Nah, games like that bored me.
I don't play it, but a reel or two comes my way because of a friend who likes them all, I can agree.
Bro 💀 clicking simulator
game hacking
I prefer online with few exceptions this is one of them 🙂
I drive cars ||IN games||
League, genshin and honkai ( I don't have a proper set up yet but when I do, I want valorant, halo, COD, apex )
League nice I stopped Genshin and Honkai
I like finding glitches and stuff that breaks games. Might be fun to mix both hacking and gaming
I only hacked Mr. Malwares game so far 🙂
I was going to play Fortnite, but my partner stole the PS to play Hogworts.
I'm starting to do that but im on a really low level (cheat engine)
bug hunter
Liked that game just no time
Didn't like it?
Indeed 😎
I've played most of them and currently play Genshin and Star rail, which server are you in?
i use to like find glitching but it was normally something small
to much farming for artifacts and talents scrolls
By honkai I mean 3rd impact not star rail but I just play genshin now and EU server
never god good artifacts
Anyone going to play monster hunter wilds?
Same hereee
well i like web game hacking
It's frustrating
ye
I started with black ops zombies. I loved going out of bounds and exploring the map
nice
How so?
javascript
Ah
And wuwa?
Yeah I got you in honkai impact, star rail is in the same franchise so thought I should mention that, is honkai impact good? I've been told to download it.
Ah, you're in a different server
javascript is pretty fun to play around with
Personally loved impact but it got slightly complicated for me ( bummer ....)
I used to play Genshin, I quit bc of the gacha system 🙃
You weren't f2p?
I have Zongli, Raiden, Jean, Furina, Venti
I was f2p the grind got tiring
It is very demotivating
the cool thing about js is i can do crazy things without breaking rules
Well that and the bad writing turned me off
Oh you stopped very early, I got too many characters to mention..
Ion play for writing tbh
At some point u just start logging in doing commissions and logging off that’s when u know u should quit
oowwh an playstation aloy
💀
my friends all migrated to AFKarena
des tryhackme have something like hackthebox battle ground
Much better topic!
Oh I’m the opposite I’m a storyline player
Fair enough
ohh i thought that was something else
ima check it out rq
I think I had Raiden, Lyney, Hu Tao, and Wrio
Koth is fun but you need to understand how it works on THM. Theres differnt ways to get points
Speaking of HTB, anyone here got exempt from the age restriction system because they were i.e 2 months away from being 18?
So you're just on genshin now?
Or you still have to go through it
Yep
HTB don't allow under 18's now?
crazy
for HTB you must be 18?
...I lose Most of my 50/50 so..
id just lie my age
That's bullshit
Yes.
Thank God that THM allows all ages
hackthebox wants less users at the point
Istg try to make an account under 18
hmmm fake id 🙂
hmm jail time
hacking too mainstream now 😤
Oh same and I’d always get Diluc 😵
Nice room and free meals 🙂
I'd c1 some of my characters...🥲
The age restriction seems like a bad feature, my biggest regret is probably not getting into hacking at a younger age
%50 chance you'll have a good room mate
I don't want to lie but I also don't wanna go through the consent thing..
Like why does it HAVE to be printed then scanned for review
Bruh.
no actually %30
Thats motivating
lol
I wanna become a sock analyst
I might just email their customer service or whatever and see if I can get an exception
Pardon?
you're in the..wrong industry?
socks?
LOL
Yes to protect from threats
SOC*
Okay um....what do you exactly
OHH
I work in IT
But former weapon engineer
Kabooey
Oh woww
oh wow
Oh yeah SOC not socks lmao
😭😭
No socks
Yep funny misunderstanding
you want some socks?
I do assume that it’s still a role though
is their something wrong with that i analyst sock form 9 to 5
Otherwise, who analyses the socks?
Uh.... another brainrot convo?
If you love feets
Someone must ensure that the cotton thread count of my socks is to standard right?
A machine..
A SoC isn't something is analysed.
nooo not feet socks 🤣
Nope, and I don't want to be. 😄
Why not?
seems boring in my option
It's not as exciting as breaking stuff.
What’s boring is GRC
thats why i skipped that room
Yeah if you’re technical for that
Not everyone’s brain’s work the same haha
yea they didnt really vibwe w me
Don't you need to know regulations?
yeah i was joking
i had another acount
I mean to a degree it’s probably something you would want to be aware of, I’d take the room
Oh lol
but i switched because of something
i forgor
but I did do that room before i switched
So you wanna do defense rather than offense
ew regulations
What do you guys do to learn from boring training material? Asking for myself lol. I have to take a course, but it’s spoken by a robot and no transcript
Yes correct.
someone has to do it
I'm a student so wouldn't know
To each their own 🤷🏾♀️
I m studying my socks
Hey awesome people
what brand
What are you on about ...
Offense would be pointless without defense, and vice versa
with holes
nasty socks
You have a point
started coding my CTFbuddy 🐍 program
ohh whats that
just skipping to the end and then searching for the material somewhere else
(early stages of CTFbuddy)
also you gotta do the boring stuff before you get to the fun part
soo depending on the situation it gave you a solution
why -sS it thought the common was -sV
nmap --help for other scans
i know
do you understand the material?
just a placeholder
i just don't normally see -sS
scan works
ah
Evening folks.
isn't it stealth
How's life?
everyone has their preferred scans
Syn Scan, default if you're root
good wbu
It’s more about learning a new product. It’s hard to focus 100% when the course is so shit
It is considered a stealth scan, yes. But it means SYN scan. ^_^
Good to hear, same here.
-Pn dont ping 🏓
thats why i was wondering because in ctf you don't have to be stealthy
"Ping not" ;D
(Prolly not, but it's funnier that way)
this project gives me something + to work on
"ping not, therefore i am not pinged" haha
i struggle to come up with idea in coding
Generally you don't get too big of a speed difference between -sT and -sS, so you can use either or.
Make a regex parser.
No external libraries.
much like Rustscan, it works but if you are using real IPs you wont be using it
so rustscan is basically for ctf's
only time i use -T is for gobuster threads
wow...
Naa, you can use Rustscan in a real Pentest too.
what do you guys have against GRC man i wanna go into GRC :(
The only time you need to stay proper stealthy is during red team engagements.
its loud , so maybe
it doesn't really matter if your loud in a pen test does it
- depends * i suppose
Pentests are authorized and designed to test the applications, not the blue team.
Would actually be better if you get the scanning out of the way faster.
That depends on the duration of the recon engagement.
Red team engagements are (hopefully) also authorized, but they are designed to test your blue team and not as much the underlying technology.
that is just my opinion, i stick with nmap.
So you want to make a lot less noise during those.
yeah
I mean, it would not be ideal if your scanning brought something down.
if it did i would close my laptop and cry
That is also correct, don't masscan DoS your clients internal network. 
I have some stories.
as Tib3rius & John Strand said in their podcasts, not all companies have staff who want pentests, find them adversarial
DDoS bits and bytes
yea sometimes companies remove themselves from bug hunting programs cos the pentesters make too much of a mess
plus all of the 🖊️ ink gets everywhere
Source
idk heard the cyber mentortalking about that
That figures.
what what are we talking
"<Insert metal gear revengeance armstrong quote here>"
it is a joke, a pun. 🖊️ = pen ==> pen test, ink in pen gets messy
Pen testing, obviously.
Pen testing is what happends when you give a pentester to much space.
hjnbfcvdg ghvblopkö.,¨ä'`Å
Ö_jknmuih,tfgcvb
?
thats funny english
That's your worst password yet.
lool
face smash
Kudos for having spaces though.
your face smashed that password
One day I will make a CTF where the SSH password is literally just ***************.
yess
i see that in source code so often in the js section
even more so is how many complain about certain symbols in the password
hiding the password in plain sight
lol
hacknet does that on one of the "quests"
PSYOP
look: my password is *****
wait really
@shut hawk Hey maybe not.
12345678
actually you know what better safe than sorry
My password is h3ll0w0rldh4ck3rp4$$wörd
Lmfao yeah, kinda realised when I sent it 

psyOps 🫦
not have to change my password 😡
shadows password is shadows password is shadows password is shadows password is shadows password is shadows password.....
She's stuck in a loop, kick her.
👢
Yo is here someone very experienced in python ?
Now that you have one of my passwords, you just need to figure out which of my 100 email aliases on what service you can use it for.
Should be simple enough.
ctrl + c
Just ask 🙂
Ask away
Heyo, I do that as a job. Sometimes.
oh you meant literally lol
I have a fair amount of experience with it
was to bored to do ctrl c and ctrl v so actually typed that out
60+ years
That's plenty.
I meant to cut the program running :P
Linux is 🥇
oh right... yeah
I really don't get to use it that much
Which Linux is 🏅 ?
it my second time using it out of my hold career
all of the distros
We'd rather it wasn't used in here.
can you brute force ?
AmongOs
:D
okkk
yes
can you brute force ?
yes
is it considered rude
yes
What are you targeting?
Yeah, it can be.
Sure can. Will I tho? Nope.
how many people here are panicing about the y2k38 bug????
Scrubz can handle that, he's already here anyways.
i actually have a brute force python script
I wasn't worried about Y2K, so no. 😄
i forgot about it
well..its still a bit far away 
just for your info people started patching against y2k back in the 1960:s if shadow recalls correctly
Really worried I'm building a bunker
whats y2k39
Not very well if I remember all the buzz.
And stickers.
The year 2038 problem (also known as Y2038, Y2K38, Y2K38 superbug or the Epochalypse) is a time computing problem that leaves some computer systems unable to represent times after 03:14:07 UTC on 19 January 2038.
The problem exists in systems which measure Unix time—the number of seconds elapsed since the Unix epoch (00:00:00 UTC on 1 January 19...
Oh, I was speaking to James about this a while ago.
ohhhh
it will most likely kill a ton of embeded devices unless patching picks up considerable speed inside this year or so
its still...13 years away 
so no more time
That is when we unlock Time Travel
lloool
Portswigger is annoying me.
the best solution is to upgrade to 64 bit intergers but there are other ways around it too
Port annoying
doesn't some cryptography function use time

