#general
1 messages ยท Page 900 of 1
Hi everyone, could anyone suggest a name for a cybersecurity company?
Ask ChatGPT
No way, it assigned the company name which are already existed.
What's happening with Meta's social media platforms ? I see only some violent videos in my feed today , many users in the comments report the same . 
oh yea kamma was saying just the same about instagram
Tell it not to use any existing name....
I feel like it's been that way for a while + insta and twitter
Free speech maybe dunno tbh
Yeah like every other video is blured , if you click unblur it is some deep web content , like what the hell ?
I do not get any violent in my feed... I never look violent things so i don get it.
You don't have to look violent things up for it to appear in your feed
Me too , my feed is travel + cars stuff but today only some violence
But never get it...
Strange..
Well that's good. I'm just saying it can happen without you needing to search for it.
And when i see violence i mean some really dark stuff , like really dark .... I looked at the comments many people say the same . What happened to Meta ๐ ?
i see..
Meaby it is the cult 763 or what the name is...?!
Idk, could be an influx of that content or something messing with their algorithm. Could be a hacktivist thing or just something messed up. They'll probably be an answer in a couple of hours.
What's the cult 763? A new one or an old cult?
I like to take 763 down.. in sweden they force children to cut themselves and take their lives and broadcast it live. Kids stab old people in the back... Damn fools!
Well that's definitely dark, reminds me of that one group something whale. But I won't mention anything cuz of TOS
this is swedeish news but looklat it and translate the site.. : https://www.svt.se/nyheter/inrikes/satanistiska-internetsekten-764-bakom-flera-knivdad-och-sexuella-overgrepp-mot-barn
dose not work ๐ฆ
What's your favorite thing about CyberSecurity and what's something you like?
@cloud quiver here is a dark 740HP video, well the car is ๐ https://www.youtube.com/watch?v=X6p3afvTLCg
To see over 100 pictures of this car visit https://www.vanguardmotorsales.com/inventory/3636/1968-ford-mustang-fastback-restomod
1968 Ford Mustang Fastback Restomod
VIN: 8T02C145173
Check out this absolutely stunning 1968 Ford Mustang Fastback Restomod! This Mustang has a laser straight body with a glossy Black Paint finish, Painted White S...
their slogan is "NML" No lives methers.. They are doing child porn and gross acts of violence with and children...
I think there was some kid in the US who started it..
yo guys
whatโs the best place to buy a domain given that i will need to give my developer dns editing permissions
cracking into there website and play , manupulating with there request and response and exploring new topics like web3 testiing , AD hacking , exploitng EIP ๐
Thanks for that ๐คฃ . That's my usual feed today something went really wrong on social media algo side .
Gave +1 Rep to @lime ledge (current: #193 - 40)
Give got these prompts and tell it to make a name based off of this. If this doesn't work than someone with a good imagination will hit you up with a name.
Hello
interesting i try this and let see\
@fringe nacelle dmรฉd you
DM that to sid lol
ok let me see
check out https://los.rubiya.kr/
sql injection challenge almost no one knows about
had a lot of fun solving them, there are ab 55 challenges
thats karma for rep farming ๐
on instagram its nothing new tbh
I uninstalled ig like 2 days ago but my friend saw 4 police shootings today on instagram
May be ๐ฆ
I have fb since 08 and instagram since 13 . For all that period i saw 3 blured videos which were in fact harmless . Today every 2nd video is some deep web type of heavy violence but i see many users are reporting the same , hope it will be fixed soon ๐คฃ
looking at the instagram reddit there are a lot of people reporting the same today
no one knows the reason
Idk my Instagram is full of baby fever videos and lovey dovey stuff ๐
My linkedin is full of cats, and entrepreneur stuff ,
Currents politics influence heavily the algo we see in the web
lemme check mine
just the same AI brainrot as always
thats why i dont use instagram
Many research for a specific subject , in a location , will lead for you to see some bots influenced stuff
Like politics , brain rot stuff , war , cinema serie netflix .
i discovered my instagram feed is weird because my account was logged on my grandmas phone for who knows how long
so she destroyed my algorithm
You can be closer to your grandma , you know what she look on her phone
There is now reset option
no its good
makes me not want to use it
ive since removed my account from her phone
was wondering if shed like if i created her a tiktok account
Just a stupid question but there isnโt an installment option for SAL1 right?
Not that i know of
@crystal moss Please don't post harmful commands here.
Morning James 
it was just a joke, but i get it, i will not do anything like it again
Yeah, best avoided
do yall take notes while doing the room or finish it and then take notes
Usually as I'm going, scan output, then reflections on it, then forwards
usually as im reading the room
Does anyone know any low cost vpns? which are safe
mullvad
mullvad is nice
its so unreal to me how the US still uses irl cash
here in brazil almost all transactions are digital and easy to do
only old people use cash now
mullvad is swedish
i guess they are behind the curve too
Hi everyone, please I need some help. I'm working on a lab and need a firewall with web filtering to control and monitor internet traffic. Chatgpt initially suggested pfsense but that is incompatible with my Mac M1 chip. It then suggested OPNsense, which I realise will be incompatible as well as they do not also have an ARM64 version on their website, which is what I need. ChatGPT has again suggested OpenWrt and pfELK, however I am weary of following anymore CHatGPT suggestions. I have tried to check the internet by myself to see what tool would be great for me but I haven't figured one out yet. Thought of asking here to see if anyone has any helpful suggestions. Btw, I am using UTM for virtualization. Thanks a lot.
it's more privacy reasons to use cash than anything else
do not use chatgpt and do your own research/googling
I have tried googling. This is my first lab ever (that I am doing on my own) and I am not fully sure what I am doing, which is why I was using chatGPT. I do not mind doing my research but not sure what sources to trust, I don't want to download something harmful or something๐
I just put lorem ipsum text into the CyberChef Entropy/Shannon scale and it scored 4.237908394111447 ๐ฎ ๐คฏ
having fun in the Signature Evasion room ๐
what does it mean to have entropy
a challenging password to brute force? ๐ค
and a room full of lava lamps https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/
woohoo top 10% rank
Ok bro lemme check that out now
amount of randomness
for example generating a number between 1-15 is bad entropy
you can post them cash if you dont want them to know who you are etc
its for privacy
and i think the most random is natural events in nature
isnt it easier to use crypto then
i dont see how buying crypto would be easier then just putting a $5 bill in an envelope
and putting it in the mail bin
yea but you gotta get out of your house to do that
that could be interesting with floating point values ๐ค
so?
that's too much work xD
predicting the weather is some fun chaos theory
i mean, not a single number at least
3.14...
You can't predict the weather silly, the government give us rain via chemtrails. /S
i gotta study statistics at some point
They'll do it with a smile whilst logging our phone and inet data
They can have my phone data.
they probably already do lol
I doubt it, but okay.
Can I ask a question about a problem Iโve in a cryptography room
There are no URLs in that message.
Ok thank you
Gave +1 Rep to @dark mason (current: #381 - 16)
grats
Good job:)
Do it:)
You will have to verify ๐
https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account
All about TryHackMe Discord Server.
You need to verify!
Use the link KGB provided for how
Does anyone have experience using evilginx
Hi
you can learn about it in this room
task 4
This caught me off guard,
It's so random lmao
When I see on videos ai will replace cyber security jobs I get afraid and stop learning for few days then again gain energy and start learning and again I get afraid.
I want to learn cyber security but this fear distract and demotivated me . do you have any advice guys ๐ฅฒ
thank you
Gave +1 Rep to @slow cloud (current: #237 - 32)
I can even send pic on the group
Even so who will provide cybersecurity for the AI
its gonna take a while before ai can do this job
Another Ai? What about that Ai
You need to verify
click the link, verify using the instructions and then you'll be able to post images @serene reef
How can I pls I do all but facing issues
What issues are you facing?
I can send a pic in the group
can anyone make me a discord guild?
More over pls assist me withy task in soc1
if you follow the guide I linked above, you will then be able to send photos
First task
what is the task?
What will be your role as a Jr security analyst
I made it y'all ๐
Please go to #room-help ๐
Where did the exclusive invitation come from?
no i'm a new member here just want to ask how to create a discord guild
This feature is currently an experiment and only available to a select number of servers.
So if you have been chosen, you'll have the option
Plus
I have gone there no one is helping
The Guilds experiment will be ending in the coming weeks and will no longer be available. However, certain features from the Guilds experience may continue as standalone experiments.
And I can't send pic
You need to be patient, as everyone here is not obligated to help
I have explained you need to verify and linked how.
You need to do that to send pictures
neat
thanks you broo
Gave +1 Rep to @silver sky (current: #37 - 241)
Discord Gangsters everywhere are gonna be disapointed
Yea, there already is a massive black market for those silly guild tags and it seems like Discord did not want to put up with that. 
Great job Jake ,congrats ๐ 
Finally cleaned up the office
Why did you put a bag in your printer, lel?
It's a pouch
it's got my work phone in it
That's where it lives when it's not in use
That's good, my dad also does that xd
Deserved. See you there soon
How can i erase my IP adress after hacked a wifi password
@naive violet will be able to help
A great pic with your dad too, was he holding you while you took the pic of your office? ๐
Soldering at work todayyyyyyyyyy >:3
I need to start bringing my hakko in
My dad? Who's that?

The one with the beard in the picture, didn't know kids have office too ๐
I gotta learn more hardware
Fuck so much to learn so little time in the day
That's me.... 
Stuff i wanna learn besides hacking
Maths
Quantum physics
Statistics
Hardware
Hope everyone is having a great day
Bot takes a while
updates once a day
Verify again so it updates
Thanks I verify my account
I was kidding, i knew that was you lol ๐
Just do fun stuff @upper minnow
Bet you can't work out who the young one is 
Is he your dad by any chance? ๐คฃ
Hi all!!!
Goodness gracious Detective, good morning
No she is not my dad 
I know i know, she's your Greek Teacher!! ๐
Close!
Ancient Greek Teacher! Right?
bang on
Hewwooooo uwu
Finally!!
commands "cookierain" and "silverlinedluck" activated
How are you detective?
Erase it from what?
turn my uwu up on god
The mainframe obviously
Wallpaper of the day:
Help me out here
The 3 body problem is a 4 book series as amazon says
1st season of the series is based on book 1
Should I order the rest of the books?
PSU?
Read the first book and then decide.
This is a crime. It is illegal and against our rules here.
ive seen a lot of people prefer the books
I mean the netflix series is based on the first book but a fair point, though I read about it because I was reading about the Dark Forest theory which mentioned that these books have that theory so I'm curious
anyone got some obsidian plugins to make code blocks look better?
W
if yall are still not aware, im challenging myself to 180 days straight of THM and WSA
most good ones that theme the look of obsidian
I don't know what is THM and WSA are
THM = TryHackMe
The discord you are in now
๐ญ
TryHackMe and Web Security Academy
WSA is made by Portswigger
Portswigger ??
creator of burpsuite
the burpsuite module on tryhackme is a good starting point
at its basic its an http proxy
it allows you to intercept and modify network packets (= data that comes out of your computer to a server)
Iam very new in having
tryhackme has a roadmap completely for beginners
go to pre-security then cybersecurity 101 path
So it basically helps to steal the data which is on its way
Thanks for that๐๐ป
Gave +1 Rep to @oblique furnace (current: #1072 - 4)
Less about confidentiality
More about tampering the data that is sent to the server IMO
this
Like there shouldn't be any info sent from your browser that wouldn't otherwise be accessible to you
IMO ?
In my opinion.
in my opinion
๐ญ
where are you from?
Me ?
yeah
India
๐
im from brazil
in 2018 i had absolutely terrible english
7 years of being chronically online in foreign tech communities helped mold me into the tech nerd i am today
I think my English is not that bad.
better then mine in 2019
Nice
- chatting (both voice & text) with foreigners on discord/telegram
- watching global youtube
- using my devices and apps in english
7 years of doing these 3 things absolutely perfected my english
Ooo
ive only just recently done an english course and i barely did anything
i just skipped all the classes and answered the quizzes correctly
?
dunno
tryhackme website
its 14 usd a month
or 126 a year
ik we both are in the third world and its not cheap
Is there any free course
theres plenty
premium is the best way to go tho
Will I be offered a certificate too?
only with premium
tbh the best thing youll get is your THM profile
any blue teamers here at the moment?
even if ur on free
it has your entire history
what do you do if you see automation on a web page for example fuzzing
beside block it or is that it?
I think you have much experience @oblique furnace
What languages did you learned till now
Put it behind authentication if you don't want randos poking it
i only just started this month
and have done precisely 0 cybersecurity work as of rn
ik alot about computing and coding tho
If you don't want people probing your pages, you make it more difficult for them to do that.
You can do this by enforcing authentication.
This is a normal and common security control
c# and kotlin (been a while since ive done anything with them tho)
dart/flutter (replaced c# and kotlin for me)
web (basic/mid css and sql, html, php and js)
currently learning python
and c
cookies, robots, etc?
hey yall
No. Actual logins.
hi
hi
do you guys know about parrot os?
You're creating a barrier of effort for scraping etc
oh ok
yes
how is it. i liked it.
yes, and its not that good
just wondering are you bro team or just know about it
@naive violet didn't say good morning to me. I cri
i use kali, its way better imo
if u like parrot use it
its basically just more corporate/boring kali
Why?
so does kali with the everything metapackage
that is true
I would claim Parrot is pretty much equal to Kali.
yup
honestly i just prefer rolling release distros
got boring to me to
what about arch linux?
they dont tend to break
i use it too, alongside kali and windows 11 and macos sequoia
i dont have experiene with that
try it out
its hard to get it setup but once you do you never break it
I would but I'm to lazy
Hey @oblique furnace you have studied much about computing so can you tell me what should I learn in computing that helps me in ethical hacking.
And how Linux is used in this field?
if you know what you're doing atleast
i swap operating system like every weekend
Now that is something completely different, whahaha.
You can use it to hack as well, but I would recommend Kali or Parrot over Arch any day.
If you want an Arch based hacking OS, check out Black Arch or Athena OS.
ha
If you want an OS to daily drive, Arch works perfectly fine, but there might be some alternatives that will require less maintenance from you as a user.
I dont ant kali as a base because it breaks easily
basic coding (python and basic web languages should be enough) and general computing knowledge (thm's pre-security and cybersecurity 101 should get you there)
"basic web languages" being CSS, JS, HTML, SQL and PHP
Everybody always claims that, yet I have never had Kali break on me before.
Does anyone wants to rate my work for school I made?
im not that good at SQL and CSS tbh
sure
i am.
tails pfp is goated
That's the work
i have a expertise of over 5 years.
Thanks, I don't feel like doing extra work without pay. ;D
Gave +1 Rep to @ivory shore (current: #2702 - 1)
Real
uhhh
Why web languages are needed ??
so you can attack web applications
sql injection
I use Arch btw..
Cool.
this, csrf, path traversal, xss, and some others
yeah
my friend got a 300$ from his state government (in brazil) for finding XSS on one of their websites
1500 reais
that alone can pay for 2 yearly THM subs
That's pretty neat.
and if you have basic computing knowledge, you can start on WSA, which is totally free
Does anyone know a free guide to set up my own home lab ? Does anyone have any recomendations?
What in the ChatGPT generated response? 
depends on what you want in your home lab
I am considering Just mimicking SOC operations on beginner Stuff with Splunk
Aside from rate limiting (which doesn't fix the problem, only reduces impact) this is just detection.
Anything exposed to the internet is going to get fuzzed.
question to admins or staff or anyone else,
How many active users are on tryhackme?
if you wanna have fun grab a small vps and setup access loging for the ssh port on standard port 22
Why does my waybar keep crashing, the heck?
update update update
try updating it
upgrading*
But like...
Thank you
Gave +1 Rep to @silver sky (current: #37 - 242)
You have no seperated upgrade functionality on Arch.
At least not without going out of your way. ;D
It's not a solution though. It's a partial mitigation. It works to reduce impact.
I'm not sure you read the words beyond "rate limiting"
If you're going with cloudflare, at least use their bot prevention too.
why downvote
?
For the reasons I've stated
i was looking at the message when typing the question
whoever determined that this room: https://tryhackme.com/room/uploadvulns is 45 mins, is a jedi master.
i was to far up in chat to see it
If that security advice was given to me by a consultant, or delivered in a report to me by a peer, I'd raise concerns.
so if someone is attacking you watch and study basically ?
Absolutely not?
If you want to prevent scraping, bots, etc, you need to prevent it with actual controls. Not monitoring.
Monitoring helps you determine the effectiveness of the security controls you implement.
I would recommend you stop them from attacking you immediately, but that might just be me.
In the best case you have proactive measures in place that prevent an attack in the first place.
I need to take some defensive courses
If you're going to put something internet facing, bots and low skill attacks (like pointing sqlmap at it) should be in your threat model
"Attack" meaning fuzzers, scrapers, etc. causing lots of traffic in this specific case.
so a real adversary would manually test
No?
instead of using automated tools that cause a lot of traffic
I mean kinda
"The quieter you are, the more you hear"
High skill attacks are less common and harder to defend against by definition, we weren't talking about security controls for that
Automated tools are real adversaries. :D
But it is not guranteed that a more sophisicated attacker will not also use automated tools.
ah what do you do in that case
That really depends on what services you have going.
And what sort of threat model you have.
If you just host a tiny blog somewhere, you will need completely different security then a banking website, for example.
i heard that bank are easily exploited
Threat modeling is important
...no?
well some of their employees
People are different
Generally you should make sure that all credentials you use are complex enough, that your services are all up to date, and that you only allow access by others to as few things as they need to use whatever you offer.
must of read a old artical then
If this was the case, they would be robbed every other day.
You can mitigate a lot of the user attack surface with technical controls and defense in depth
so it mostly control and technique
maybe smaller banks
brb going somewhere
Huh?
shadow still feels like the discussion on changing the ssh port of your machines is whacky and heavily opinionated
meh 22 is good enough
Certified security through obscurity moment.
Even tho deception can help.
Is the soc1 path enough for the sal1 cert?
I think time is better spent on controls that will actually make a difference
though there are plenty of ancedotes proving it is not only security through obscurity
If you add it on top of all your normal security measures that is, you can't replace any protective steps with obscurity.
changes SSH port
2222
shadow is oh so funny by putting ssh on 42069
It doesn't provide security, just cuts down on automated attacks.
Those attacks weren't going to succeed anyway unless you've done something horrifically wrong.
blue teaming
No, blue teaming isn't about naming security controls
Like with "red team", being a part of the red team and being a red teamer are different.
There's loads of different roles on the " blue" side
Switch to port 19 ๐
brb putting a minecraft server on port 19
port 71337 for those binary overflow fans
impossible
literally
r/woosh
max port is 65 535
then use it
I think that was the joke
why
adding to create an integer overflow, port is 16-bit yes
think car odometer
In computer programming, an integer overflow occurs when an arithmetic operation on integers attempts to create a numeric value that is outside of the range that can be represented with a given number of digits โ either higher than the maximum or lower than the minimum representable value.
The most common result of an overflow is that the least ...
You forget that half of the Rust code is just glorified C code stored in a
unsafe{/*...*/}

I remember as a kid hacking my saved game files, and filling the bytes with 0xFF in hex, then wondering why my gold was -1
๐ signed values
I just binary overflowed the amount of hours I have worked this month
just got paychecks, ended up working 281 hours ๐ญ
"hey so uhhh we need that money back"
i know it impossible but what would you do if you saw port 90000 in a nmap scan
look at the code behind nmap
narhhhh, I already paid way too many taxes on them
and it was correct tho
for SoC install Security Onion 2 and use Nessus (free version) or OpenVAS (GreenBone)
i am back
Thanks for the reply.
Gave +1 Rep to @plain nest (current: #1767 - 2)
guys, just use hidemyass.com and tor network
weclome and to all chatGPT users! Switch to Grok!!!!
my recommendation, anonsurf
@odd tinsel
Did someone bought the SAL1 exam?
how much?
@idle mica already has it done. xD
sorry for tag KGB
It depends
np ๐
on?
297 โฌ if you're subscribed
ah..thx
and 350โฌ if ur not
with learning or just cert?
Very expensive
exam and cert
I will subscirbe soon
350โฌ with 3 months of premium and exam
Real certification
For a certification, definitely not.
I mean...is there also learning included?
yea
OSCP is 4 digits.
yep 3 months of premium
For a blue team cert
Naa
yeah....2890.-
Go look at HTB
No clue about those, to be quite fair.
yeah HTB the most expensive 1500
Was OSCP always 4 digit?
idk
As far as I remember yes, but I also don't remember very far. 
but in my eyes it is too expensive....very sad...
Anyway, it is expensive for me xd
Does the mods know how many ppl bought the exam and passed it ?
not just for oyu
I mean, it has just released
Jabba is not here
is there also learning and labs included in the price?
It would be better if they have made some discount
Yea but you get a limited package
if you are in the 100 first person
cheap certs: SecOps Group!
SAL1 is incredibly cost effective tbh. They sunk a LOT of money into development and running the infrastructure for the exam isn't free
SO 350โฌ contains 2 tries for the exam and 3 months of premium
W33t
Like shoot, my SANS classes and GIAC certs were all like... $10,000 a piece
I want to know something
dafuq
It really depends on how it is recognized in the industry. We will see
Excuse me?!
Mods won't know this information.
Not yet anyway
I'd have bought, like, a house, instead.
Industry recognition is aside from the cost and time spent developing it imo
@sick lance Do you know something abt it ?
It's just an inherently difficult thing to accomplish
About what?
How many had passed?
Bear in mind mods aren't tryhackme employees
I have no idea tbh
No, if i need to pay for the certificate on paper cuz it's optional
I was almost. ๐ฆ
But I'll make a note to let you know if I have the option to get a paper version of the cert
You passed it?
yep
Not sure,.as @idle mica
Ask*
Information wise, everything is free on the internet.
If it does cover industrial tools that requires business deal, that's what would make it really worthful.
But yeah, i get what you mean.
He doesn't know
I am taking 2 certs this week
Sure, but the idea is that you've established a baseline of knowledge
hopefully
That's the whole point and it's not just you saying it
TryHackMeโs SAL1 certification is changing how cybersecurity professionals get hired. See for yourself: https://tryhackme.com/certification/security-analyst-level-1?utm_source=youtube&utm_medium=social&utm_campaign=dakota_sal1
Cybersecurity hiring is changing, and TryHackMeโs Security Analyst Level 1 (SAL1) certification is built to prove real...
@plush bone
Hi, is the physical cert a paid extra?
Oh well there we go
tell more โค๏ธ
So i need to pay ?
Thanks for asking
Gave +1 Rep to @sick lance (current: #2 - 3427)
Didn't want to ping anyone
planning on taking SAL1 and the test exam for FOR508
@idle mica How was the exam? Is it worth the money? (Practical challenges and stuff)
I have no idea because I didn't even get an email about passing and I don't see the option to get a physical cert. But they also just launched it, so it might be something they're still working on
Unfortunately I had to reject the THM position. ๐ฆ
nice you pass it ๐
What?
They say that you get instant results
I think for that L1 SOC analyst role, it captures it fairly well. There are some things that I wish were different with more variety, but that may have just been the scenarios I got. I don't know if they're varied at all
who has OSCP+?
I was offered a position with the company, but I had to turn it down.
You do, on the page lol
Why?
Bad timing, I couldn't do the position and finish uni.
My point is that I don't know anything about the physical copy
can you send a screenshot of the webpage when you buy the exam
what a pitty
You could've asked that they give you some more time
congrats
There was comprises.
THM actually tried their best to accommodate me.
smh slack is down
Damn
I hope they won't rise the price^^
Yeah, it gives you an evaluation. Part of it is LLM-based
So you get a feedback
but now your results
tf
?

297
^
I'm in the process of doing it
After you complete the exam, you're given a score breakdown, your digital certificate, it gets sent to Credly, etc. My point about the email thing is that I didn't receive anything related to "if you want a physical copy, you can request one here" or anything like that
I didn't even know I could get a physical copy until you mentioned it ๐คฃ
Reading is difficult, why would I have read the whole page before buying the cert attempt?
How much you got (if you dont want to give me an answer np)
yep
He already received the cert. Infact I saw THM linkedin posting him on their account for passing the cert. First few guys privileges ๐
why does it feel like im not learning nothing
ik
Thats odd - you should do - let me pass it onto the team. The first 100 people get a special gift - you'll get a physical copy of the cert too.
@jagged yarrow how many so far has passed?
@jagged yarrow What's the gift ?
you might be burned out, or mentally exhausted.
Try to do something else, take a nap if you can, and just have at least one day off studying anything and get back at it.
804, but I've got some feedback about the scoring. I think it needs to be adjusted because it says "you didn't do X" when I did, etc
804 / 1000 Congrats
its mostly ctf i kinda get stuck on them because idk what to do
It's not
It's 80 questions and 2 SoC Simulators
The questions counts for 20 % and the simulator is 40% each
2 Soc sims.
But there is also likely my experience versus what is expected at play
check a walkthrough of something similar to that matter. Maybe you may learn 1 or 2 "new" methods.
Yeah
Hey! We're still working with the supplier - hoping to get this organised in a week or so
300 pounds is too much for me. I would get if it was like 150 or 200
Sweet! I'll hang it up in my office lol. Let me know if you need anything from me. I double-checked my email. I received the purchase receipt and then the marketing announcement.
๐ Sure, but would it be a paid option, or is it free?
They can't give for free i think
They need to pay the supplier
If I could get a SAL1 challenge coin, I'd be a happy little walnut ๐คฃ The collection must grow
I think the reason im getting burned out because i only do ctf no outside project/real world because II'm really don't havfe ieas
They had have throwback coins, SAL1 would have been cool.
It's hard to beat the SEC565 coin, though. Still one of my favorites
Its a surprise - pass and you'll recieve one in the post
How's the exam? I'm thinking about taking it in the future.
Just ask the team to email you soon - maybe over the next few days
Can you tell us how many ppl have bought the exam ?
Please?
You can do a note/walkthrough of your own as you do the ctf, word it properly so you can be technical, nevertheless show your thought-process as well, then post it as PoC in github, your own domain, or both.
You gonna buy only if the number is below triple digits? ๐
Fun, honestly. The SOC simulator is fairly accurate to day to day L1 SOC life
We'll reveal more stats about the exam soon - not sure about purchases, but pass rates, clients (that are happy to share) etc..
I might do some soc sim to prep.
Good deal, I appreciate it! I'll keep an eye out
I'm gonna buy even if it's over 3 digits
But i can't buy it now
I need to wait
@idle mica still no answer, cause they have to research stuff, so might just buy it myself and do it when I get paid on Friday ๐
thanks for releasing the cert, was really about time that THM created its own ๐ already working on SOC path ๐
Gave +1 Rep to @jagged yarrow (current: #139 - 58)
Is there a age limit to pass the exam
I'll check back in later - need to jump to something!
๐
Bruhhh lol. Yeah, just do that and have them reimburse you
dnd i don't think he get pings
That's great to hear, guess who'll be needing it soon? haha
indeed, cause it would be fun getting it right now, but I don't have the money for it before I get paid xD
?
if do not distrust is on you don't get pings
Yep he's in do not disturb mode
I tried
Wait
Perpetual DnD is the way
guys, any ideea where i can find a list of all usefull bookmarks? because i lost them all after i reinstalled the OS
@sick lance Do you know if there is an age limit ?
what operating system do you use
backbox linux
I don't think there is one listed.
brave
I don't think there is. I know they have a KYC identity verification thing, but you need to be able to produce a valid form of ID
What is a KYC identity verif?
that is effectually an age limit
can't you login so you could save bookmark, history ,etc
Never heard abt that
What's the age
the age of having a valid ID
More or less. You can get an ID card at any age here in the US, anyway
can't.. i need a list with all bookmarks, i lost them all again..
would depend on country in that case
My parents got me one as a kid "just in case"
country dependent
err...passport?
If you have a mobile device, you can do a sync between that device and your desktop/laptop, hence you save your bookmarks. I have done it 3 or 4 times with Brave.
Maybe just give them a thumbs up and it'll work ๐คฃ
In Belgium you can have an ID before the kid is born
on brave?
yes :)
duh
why do people use brave
Fun fact, different countries handle different forms of ID.
just asking lol
Built-in ad blocker
Only useful when watching youtube ๐คฃ
Let's not.
thats my point..?
Amen, then it has a built in Ad-Blocker, privacy, fast and reliable
Some "ID" may not be accepted. ๐
Right
guys any ideea where i can find a list of usefull websites for pentesting?
thanks a lot bro!
Gave +1 Rep to @high mulch (current: #226 - 34)
Bugbounties.
im guessing people normally say ba things about it?
exactly. valid ID
@idle mica What is the KYC identity verification
Thx
Gave +1 Rep to @shut hawk (current: #14 - 613)
What could be valid for country X, could be invalid for company Y.
It just validates that you are who you say you are
Nah, lots of people try it
I haven't found someone saying bad things about it just for the hecc of it
yet
Know your customer
Know Your Customer
Me first
who said valid according to who?
You're joking ?
as a general rule of thumb, when you want a list of resources, search github: "awesome X" where X is what you want
validity would be according to the checking party
good ad-blocker. Somewhat decent privacy.
Unless you just want the integrity of the exam to be 0 ๐คฃ
You're joking or what
KYC = Know Your Customer
'Somewhat decent privacy' is accurate
Yes, have you used crypto platforms? They essentially use KYC, you have to put some kind of ID in those to make an account
oh ok i always just stuck with firefox
Are you from my land as well 
k
It is the full form, KYC
Thx @orchid dome
its typically for anti money launding but can be used synomously for just...validating the persons identity
You're still on cooldown
do it very easy ๐
What's that academy what?
Screenshot is better.
TF? What is on cooldown and where is my rep? ๐
Much better
I gave u one
PDFs are always totally safe, whatchy mean? ๐คฃ
I didnโt receive it๐ญ
It's not the end of the world if you don't get a rep lul
Even the rep bot doesn't want you to get a rep ๐
You're still on cooldown
/j /s
AHHHHHHH
I looked at it
It's just a certification
Wolf in sheep's disguise
ooooh now you've got a cobalt strike loader on your system and china is stealing all your credit card details /j
lol
Do keep a MITRE
Yep
last time that happen i accident cooked the wolf
Extra protein I don't see nothin wrong here
The day i bought an antivirus and they told me that if i got scammed while buying with the bank protection thing they will give me my money back
i dont verify pdfs
and i reset my pc every month so
the day i got antivirus i got a few malwares :D
How
There is paranoia, and plain overkill...
Your threat model though.
What?
Bruh
Before i buy this one
I had 3 antivirus
huh?
4 if you count ms defender
You don't need an antivirus if you can't access the internet 
3!?
Wow.
Not true
When you're 16 and watch Mr. Robot for the first time ๐คฃ
...fine
doesn't the more antivirus make you more vulnerable in a way
like 6 years ago
Did you know
So basically you hired 3 sleeping guards
It slows down ur computer
There was an antivirus that used to generate a file in your computer, 'detect' it, remove it and then say 'look we removed the virus from your device you're welcome.'
MalwareBytes, Avast,
MalwareBytes is nice
Avast...
and the third one had a logo like windows 10
For a quick or deep scan
forgot its name
Anything else you prolly don't need
is bad?
BRO i was 8 years old
Now I understand why you reset every month.
i have one now
i just like a fresh install of w11
I've heard people say that you don't really need an antivirus. thoughts?
What if, chat
What if an antivirus is actually useful
What use would it have other than what Windows Defender does?
Never used one ๐คท๐ปโโ๏ธ

and white list their malware with it
Defender is a pretty good solution nowadays
Weird to hear โhackerโ ๐คฃ
Common sense + Defender is really all you need
But any sufficiently capable threat actor can bypass any AV/EDR
You can really enhance Defender's capabilities with Defender UI, too https://www.defenderui.com/
In today's episode of Propergander or actual facts
Lots of that EDR-style stuff
We test this link
The best is Crowdstrike
Ah yes
sometime the best
No option compares
sometimes you get everything down
That deserves the skull emoji
How are illegal sites able to exist on the known web? Piracy sites I mean. Torrents require VPN which means actions have been taken against them but why are other piracy sites for books and games given like a green pass?
Kaspersky is good
Red vs Blue team
Please don't discuss illegal activities here
Ohh I mean to ask why are actions not being taken against them
They are.
But still, illegal activities
What's this about an ill eagle?
Asking "how do these guys get away with this crime"
Ahh ๐
Phrased it wrong I guess
Don't worry, he's asking for a friend.
School project
Not really. No matter how you word it, it's the same question.
Again let's not.
A discussion of how people get away with crimes is not appropriate for here either way
Ok
That was aimed at @jolly aspen
wild take, very relevant because it get brought up often. this server follows "UK and california laws" and sometimes people wonder why they cant do or say things that arent banned in their own country
Yeah this isn't the place for it though
why is the idea of laws are different in places a deletable and punishable statement?
We're not playing greyscale, illegal is yes or no
Discussing how people get away with crimes is absolutely not OK
End of.
I'm not arguing this with anyone and I'll mute people who continue it.
mute it then

๐
:mute: ronin_1_3#0 has been muted.
[MUTE] I cannot DM that user.
Like that?
All in all, our national cybersecurity is lazy
If they wanted they could have blocked access to all sites but they only target the big ones
Well this will improve with time
:mute: al.saffah#0 has been muted.
Rly
So, who is ready for the MetaCTF flash CTF tomorrow? ๐คฃ
Click the mute.
ohhhhh
All of the communications, including the mute reasons, are out in the open.
Let's not drag back up what happened. Learn from it and move on
How much time did they get muted
didn't know i could do that
Are we past those topics yet
ok
Good Night everyone!
Have a cookie ๐ช
This is how you see ^
goodnighttt
Disallowed from receiving points
Anyone learned anything neat today?
I learned that I suck at wireshark still lol
Me too
not allowed?
@echo wasp We cannot help with work assignments
I'm learning nosql, and people are getting a bit stupider at my school.
sad was hoping to just know which other method besides fuff i could use
No idea
You can't allow him again?
I wonder if it's the mute...
@bitter rivet Where did this ckme from?
He got muted ?
I can't make that not a reply, ouch
Mobile?
Completely outside of our control
Crack the hash
np
a easy challenge
You can just click on the "X"
the fourth
The point is that you can crack these yourself.
If it's for a tryhackme room, please use #room-help and #room-hints
also i do have a funny story
ye okay ty
If only discord had feature parity
@orchid dome
?
Idk what you're asking
Whenever I use the bot too many times, my mobile discord has a fit and point blank refuses to anything properly when I ask if to.
I have to close it
use the website

