#general
1 messages Β· Page 902 of 1
Yea
you can yes. also using kali as any other linux based os is ok. just is not recomended to use it baremetal since is not so much stable.
git git is insalled by default
it's not really recommended to use it as any other linux, kali is a tool, not a daily driver distro. For kali to be a daily driver you have to install a whole bunch of thing on top, and doing that you'll miss the whole point of kali, and also probably open up to some security issues
the only reason i use kali as daly driver is spare laptop. that i hate... dumb ass lenovo π
I have a vm with kali and a usb with kali live, but I don't use it as daily driver, my daily driver is fedora
I do hehe
well... not so day by day... yes and no
Hey again
ello
sky
Hello please am new here I need new friends please add up
Yea add me
please do sent friend request without authorisation and interaction with the user
Carolina looks sus π€
wrong server for that π
Yup π
That account was made today btw
Like if i would add her just because of her pfp and her wanting to make friends, jokes on her i an afraid of women π

maybe some horny youngster will fell for for it π
I think I learned a valuable lesson. Don't find out you have no idea where first aid kit stuff is during an actual emergency
Also that adrenaline is very useful
I guess we live different realities, the first thing I learn is where is the emergency exit, first aid kit, and the bomb shelter
Nah I know where it is, I just found out I have no idea where the gauze is
(It was inside the roll)
I dont know if this is the right channel to ask, but i tried downloading kali on external ssd, the installation went well, i booted into kali, then exited to bios boot preferences, the ssd with kali was still there even after removing usb from which i installed it on external ssd, hovever when i booted into windows and then back into bios boot preferences, the ssd with kali was not there anymore, i checked diskmgmt and it said there is efi partition of 965 mb, but i cant find it in boot preferences, secure boot is off and usb boot is enabled. Any help would be appreciated π π
That had happened to me, but because the place was awful, and we were practically undertrained.
Also once a week I used to check if the first aid kid was properly stocked so we always knew what we had and their place
how do you see other machines that you have up? i tried opening an attackbox but said I had 3 vms alr running
Good thing to keep in the mind
kali has a discord, you can ask there kali specific questions
Manual, history
can someone help me out figure something out in john the ripper room under cryptography
no one is responding there
(When someone knows, they answer)
i need to move past that qestion
so wait, patience is a virtue, asking the same thing in different channels won't get you help any faster, you'll just annoy people
If you need a fast but potentially less reliable answer, chatgpt is there for you

doesn't know shit
User skill issue
or hacktricks.ai is sometimes useful
no
Have you checked a write-up?
yes!
Yummy unknown link

you should check book.hacktricks.xyz it's well repped
"Well repped" uhuh
Yeah..
Very trustworthy
? what's with all the negativity
Skepticism is not negative by default
mhm, yeah I'm a bit "dissociated" currently
βΉοΈ
Probably the way I phrased it
Hacktricks is very wellknown in infosec, a quick Google search would show that π
Okay maybe it is now that I read it again
:)
π¦
so no one here uses the room-help
do you code in c without classes? (c-- joke haha)
i never coded a line in my life
ah; C++ is pretty much C with classes
what is c++
I can see that now yeah, to be fair though that's the most suspicious domain I can think of
Depends on time of day if you can catch the light kgb he will basically solve anything
I am not google, however I can tell you its a programming language that's used universally for pretty much everything, from phones, vending machines, registers, etc. It's used in a variety of mobile, desktop, and IoT devices.
Low level programming lanauage
ahh thank you i didnt know it
Gave +1 Rep to @dawn oyster (current: #1073 - 4)
it is indeed a low level programming language
thank you i didnt know it im very new into computer stuff
Allg lad
Clearly
says 0xGuru 
im on temple os my friend in nsa recommended is it better OS then windows?
okay thankyou, i thought its rather OS related question so i tried it here, i will join kali dc thats a good advice
everyone that doesn't code in holy C will fear the day terry rises from his grave and punishes all of the unholy swine that plague our world.
only if you don't have wifi
Who's terry
I would know a Larry
LAN w DMZ isolating your infrastructure. ^
That's doesn't say much, I can't think something worse than windows π
Larry Davis?
they're rage baiting if you haven't caught on
Depends on what you want from your os
Completely serious question no funny business
I know Larry great game, π
Be kind before anything else even if they are we can be pleasant to them
Hey pal, what did we say about that funny business
classic haha
I know, and I've been kind and curdious the entire time.. I was just pointing it out if they hadn't caught on to that yet.
I would help knowing who terry is
also, anybody knows whats up with instagram? why is there such a high spike in violence? gory videos, people getting shot. And dont tell me its based on the videos i watch, because i have my feed based on cats, women and cars. There is no way all of a sudden it would recommend such videos, altough i uninstalled ig 2 days ago, i logged in out of curiosity today and the first thing i saw was a video of a man getting shot, many of my friends also experience the same and there are even articles about it on the internet
look up terry davis
true thats me
Do you mean Terry A. Davis
yeppers
That is not a word
In my dictionary it is.
anything can be a word if you try hard enough
holy yap to the 100th power
creepers? π
terry davis. the founder of holy C
There's a lot of inventing in this server
Windows is the best OS

Yeppers is a diminutive or emphatic form of yep formed with the colloquial suffix -ers. (See preggers.) It isn't usually included in dictionaries, and in corpus searches from the early 20th century the overwhelming result is a misscan or misprint of peppers.
Okay, now im english
Yuppers
Ishmaeli, how are you?
doing good avi
that makes sense, but I thought you'd catch on to that though.
how about yourself?
I don't do a lot of catching unfortunately
I don't like writing in C# but some times it's more consistent than py is π
I'm chilling π
C# is the prettier version of java
java is the devil in a cup π
When I think of Csharp I see a nice quiet bench overlooking a pond with ducks swimming under the trees
the only language that's suitable for OOP. I understood OOP when I learned java.
what's wrong with java
The best question is always, what's the difference between java and javascript
that's sharp π π
script
A demonstration would be ideal
was fluent at it once upon a time. stopped for a few months and lost my touch.
never went back to it again
Better for your sanity Iβm sure
wdym
meep moops it is the time for sleepy sloopy sleep sloops to the beep boops
based
Rest well shadow
plot twist, i dont use either
Assembly is the only true way
First step in baking an apple pie is creating the universe
what is C# commonly used for
new box printed
woow!
What else can you print, maybe try computer components. That would be awesome..
you can for sure. alsmost anything can be done. but all is plastic ofc
goes to maker space to stay for a couple of hours
Also me: Stays for 8 hours
Finally coming back to TryHackMe after a month of not learning cybersecurity due to moving to a new place.
I also got a new PC and monitor.
welcome back π

I don't π
btw @boreal scarab i got new hotend. the microswiss one
What about @cosmic pendant with mini @wicked sage 
WOOOOOOH
eoooy
you still typing so I guess you're OK π
Weeeeeeee
toasterrrrrrrr
I hope you didn't burn anything down today Toaster
just bread probably π
Hehe
2 toasters, are we getting invaded. The attack of the killer toasters π
Yo guys, what's with the insta feed full violent and gore reels?
Do you think it's algorithm or smth else?
Mix of algorithm and it being Instagram
Ugh, I can't digest the content
thank god I didn't open instagram today xD
I remember a couple months ago ppl were getting weird content like this one livestream of a lady giving birth
Can they fix their algorithm lol
so don't watch it. Is somebody holding a gun to your head and make you watch it?
well it only takes one scroll to accidentally land on violent content
Lol I don't watch it, it's just whenever I'm scrolling it's showing all that content
Not from my following list
Exactly
close the app and walk away
And people who are too sensitive can't deal with it ig.
Okay Mr
Oh btw, I just joined yesterday. I wanted to ask something....
Do you think hacking groups like anonymous are dead? Yk those hacktivist groups to change the world.
Cuz I mostly hear it's all about financial gains now
People using ransomwares etc
Hacktivists are always out there, but they may change over time. Some individuals get caught and some simply grow up lol
For example, there are plenty of hacktivists who operate in Ukraine's benefit against Russia and vice versa
Some are working at Walmart π€£
π€£
or McDonald , do you want fries with that hacktivisim? π
I have a theory, foil theory, that meta intern have had last day of his unpaid intership so he wanted to give meta little surprise
C# is great for rapid development with windows Forms applications. Can quickly make tools and other apps with tons of built in windows buttons and textboxes and drop downs and all kinds of other premade forms. It is also commonly used as a scripting language like in Unreal Engine.
I am a mad man
Hi guys, how do I know if my Kali Linux VM is connected to the THM Vpn? It shows the IP on the top right corner but when i try to enter the given ip of the target machine it brings me to lookup.thm, however it sais "Hmm. We're having trouble finding that site."
does anyone know how to hack a discord account someone took my one and i want it back
it is illegal do to so
its my account tho
then contact support
@mossy river
Gang
@whole yew
sup
Please contact discord support. It's illegal to hack a service to recover an account.
I said fries π
Gang. I need your aide
police notepad opens ....
Swear fealty to me!
pass
Understandable, I have to start somewhere though. π
IT is cool and all but being a feudal lord is preem.
Especially since we are bringing corporate serfdom to 2025
aside from all the feuds
Ez I'll just use you guys and win.
gg no re
survey says ...
what is wss://[ip]sslip.io:4999/
NOPE
btw hi
well the wss part
Sudo why won't you support my dreams? π
winner server shop :// <ip> .io : 4999
?
the dream of being a lord reminds me of the scam of people paying for a plot of scottish land to get a "legal" document stating lordship
Aight, time to read. Night gang night @grizzled wing
closed police notepad
That's a thing?
Wait
yes, was a thing years ago on youtube
Wow I wonder if they made money
Veggies hii
One step closer to D
π
A lot better than potato yellow
haha
Id prefer to be purple like shadow but no way im getting nitro
Nitro is a nice extra to have but not essential
this lovely song has another level in regards to Chester πͺ¦
just started shells intro room and I am curious, how do you all know what reverse shell payloads to use? They seem quite complicated so far
For real. Rest in peace
It depends on what is executing the payload. That's ultimately what'll inform the type of payload that is used
So a PHP web shell versus a stageless payload on Linux, for instance
I see
@upper minnow grats on the green. :3
I gotta study for this cert but imma catch you after >:3
You infested me
You know that song "infested" by choking victim? @fervent meteor
@seadrih is this true ?
That's me, with the bee.
Also I POSTED it to you. You should know it.
Now I know you don't really love me ....
Me rn frfr
Dexter is goatee
Are we leaking?
Wat
This seems chaotic
You're watching a breakup happen in real time, @fervent meteor has abused me and is now darvo'ing the fuck out of me.
I'll be looking for a rebound π
You don't want me as an opp, I got shooters all over. πππ
You 2 were so good for eachother
I know.....
@real lichen Ok, I made it in here if you care to chat further. π€£
What area of Cybersecurity you wanting to go into?
I'm building it now so it's still in development. It's interfacing with a whole cloud multination corporation network for my students to practice in. So it'll be a bit.
Nothing wrong with a side hustle. I have a few myself.
After 28 years in Cybersecurity it is my side hustle now. I retired in 2018.
My main work now is developing my AVN
and my security site
Just in case that wasn't obvious π€£
I'm 62
oh god, I was surprised I didn't see you reply to that :v
until I scrolled down a bit more
wow
Don't tell me I'm the oldest one on THM? π€£
It's rizzmas gang!
What was the great depression like? ππ
Thanks for that. I do like it though
Well at least you didn't ask about any dinosaurs. π€£
Real talk it's cool that the server has older people in it
Nice to see people transferring skills that would otherwise disappear
This is discord, Iβm sure half of the server users here are below 18 xD
yep, I thought it was me, but I'm a youngester compare to 62 π
Like cobal or those bad jello dishes from the 60s
What were the aspic dishes of the 60s like? @arctic token
Jello salad or whatever the fuck
cobal, fortrain, C/CPM, IRIX all that good stuff
That's legitimately impressive
I'm learning cobal rn and I can't imagine learning it from like a fucking book
I was Neo before Neo π€£ π€£
Instead of a 10 hour cobal learning and meme compilation with subway surfers in the corner
been following the white rabbit for a long time now
That's the SUPERIOR way to learn
I have my neovim with subway surfer on the side, for optimisation purposes.
Preem, nova even.
their were other "Ones" before Neo maybe one of them was you
Ok, but seriously did you have to eat those weird jello salad dishes in like the 60s-70s?
Were they even real or were they just a psyop?
Mandela Effect
do you mean the jello with fruit in it?
My grandparents died and I don't know anyone above 40 so I have to ask these questions when I can. π
I was really young but I remember those from family events
Yeah! Those things.
Yea, back in my time there community was VERY CLOSE and we pretty much knew EVERYONE because it was difficult as Fu-k to learn for anyone. There literally was no help. Either you learned and figured things out or you didn't get into hacking as it was called back then
No fucking way
I've never seen them irl
I'm not, it was a popular dessert back then π
Oww
I'm 3rd gen Ukrainian though so my grandparents made like pampushky and shit
Ahhhh, got it.
And stuff with very bland grains that tasted good.
Varenyky too
I need to make some
A DESERT?!
I saw ones with hot dogs and mayo in it?!
That's not a desert
I only ate the jello with fruit, like a fruit salad trap on jello, no hot dogs or mayo π
Oh no, that's some evil type of witchcraft...
That makes me feel like I can trust you more.
I would never trust a person who hurts themselves like that
Just like that pizza with chocolate, banana, and sweets.
maybe there were a savoury version I wasn't aware of it. Like I told you I was very young
Well hey this is all good 1st party sourcing
Besides Pizza with chocolate, banana, and sweets on it as toppings.
There's also chocolated fried chicken, which I was disgusted and surprised it even was a thing.
The idea of anything savory with a jello texture scares me
The brainrot epidemie has spread infinitly
long time ago
This is the end
Beautiful friend
This is the end
My only friend, the end
the end is a new beginning
Hi I need an advice
I got an email that I am selected for Information Security Specialist position phone interview last Friday at 2.30pm. I professionally responded at 9.30 pm. So today is Wednesday and I did not hear back from them. How to handle please?
Try to ask guys in #cyber-and-careers channel π
thx
Good evening guys, can anyone tell me what to create websites and applications, and back end or front end
Can I take what I learn here and conduct bug bounties?
Yes of course π
That is going to be a long process which can take months/years to learn π
HTML5 web3 php javascript
SQL database
Start with HTML, CSS and Javascript those are pretty much the base coding language for a website.
for the front-end at least
MY CTF starts in 2 and a half hour and im gonna freak out im so pumped! are yall PUMPED. Get PUMPED
That's the spirit
Good luck
thank you mr.pooping lion. im sure this isnt another one of my schizo episodes.
sup
helloπ«‘
hru
im awesome! and yourslef?
me too just completing fundamentals
you never truely "finish" fundamentals
gonna take easy on pentest, will go for soc for now
yeah cauz its overwheliming as beginner and can't remember commands for tools after completing modules
yep. i recommend re-doing every module at least once to cement the learnt info. and take NOTES. if you dont TAKE NOTES... i will personally come to your house and hand you a pencil... then stand over you while you take notes like you dad did when you were learning multiplication tables... im watching you...
thas cute
Haiiiiii >.<
okay dude...
Okay what?
yeah @rapid merlin also said same that notes are imp and ik why after completing some modules
THM community is very friendly fs
THATS MY @broken horizon ! π
Much friendlier than most IT/hacking forums fs
if you message in HTB, you just hope someone replies
yeah everyone here is super awesome. ive met so many nice people here
The helpful ones are super helpful but you definitely got some assholes in there.
I have a few friends that spend a lot of time doing htb stuff but they are swamped
and the guys here explain really well like best buddies
Avatar
The blue people one not the good one uwu
yeah you only get reply if ur ranked or certified and only their discord CTF team groups are cool
the HTB server is lame
i also don't use it because if you want to verify it forces you to use your account name which is also just my name which is lame
I'm not gonna shit talk em yanno, but yeah I prefer this one for chatting. :3
same
like lemme say shit without my name right there
its just chill here
They don't want anonymous opps @molten sky
Hewwo uwu
i don't even care for anonymous on here but like cmon
i'm far from anon on here
but lemme not make it front and center pls thx
I know, I mostly wanted an excuse to say "opps"
oops
Fuck my stupid life man. π¬
HELLO. i am normal! 
no you're not
@molten sky π long time no see π
hi - is your curse self inflicted?
and I thought thm friend request name doxxing was goofy
yep, it's a running issue nowadays π
Fixed some monitors by resoldering components, unfucked someones email, incident response stuff.
πππ
I would die if you could link my immature jokes to my real life identity xD
nah i make worse jokes irl
Whereas me, a man of principle have selfies on main and say weird shit.
idk why i even said that. on my actual instagram account I already post like 50% weird memes
I have embraced cringe.
I will never return to the dark days of shame.
I have achieved self actualization.
I am the same online, as in real life.
I know I hate it too. π
MY SON
What shocks?
where did you obtain this picture of my son
LMAO
That's me replacing cat6 e at work
can a cat6 even shock you?
How I feel when telling ppl irl im into hacking
It can carry power yes
enough to shock you?
thats dope
cat6 tazer incoming
Dunno I just ate it
I used proper power handling tho
every once in a while i have someone clarify my job like 'oh so like hacking' but it always sounds cliche af
Yo is that you?
That's peak
im hungry for somthing only cat6 can satisfy
what happened to the first 5 cats
I ate em
I must go bye
*deletes reply before getting banned*
cheers m8
I did eat a micro b usb when I was 10 cuz I thought it'd taste good
Later @blazing granite sleep well :3
I knew this kid in third grade who ate a quarter
Never knew what happened after that
Fecal impaction
did you expect it to taste like twislers? im so confused
I dunno guy I was 10
It was small
anyway third grade mentioned
Provided to YouTube by DistroKid
I Have A Dream (Gay) Β· dj pressed
I Have A Dream (Gay)
β 5182345 Records DK
Released on: 2023-04-10
Auto-generated by YouTube.
i did chew on some plastic teddy bears when i was in second grade cuz they looked like gummys
Hey any of y'all read the "three body problem"?
Was it good
no π
I like the 3 body problem a lot but i read it a year ago so I dont remember a lot
Me too, like 4 times. I'm using audible for my 5th read through, the VA is excellent
Hi everyone. I'm new to Discord so I'm not sure if this is the right section, but can someone help with an issue I'm having. I can't access the Subscription page under Manage Account. It's not loading andjust showing a blank screen. Has anybody had this issue and if so, how did you resolve it?
May I recommend "Blindsight" by Peter Watts?
The banana always gets me π€£
I have it on my goodreads tbr
i didnt even see it til you mentioned IT
It's good. Read it and we can talk about it
im finishing up a book rn so I'll probably get to it in a bit
Sneaky banana π
i read this book call "iboy" recently. its about a kid who gets hit in the head with an iPhone and gains the ability to hack things with his mind. (i wish i was making this up) actually a good read tho.
this is gonna be me after i finish jr pentester
π
yur gonna hit yourself in the head with an iphone? 

girl ive already done that like 5 times when scrolling on instagram with my phone over my face
why am i not a master haxor yet????1
It's worth a try
its getting exfoliated :3
its gonna have buttery smooth skin
This is weirdly satisfying to watch. I can't tear myself away. It's like watching a drunk puke in front of a sunrise.
New topics are so difficult to grasp
hello everyone! new here π
WELCOME π«‘
Hello , welcome π π
Water-cooled i7 nice
that's nice
Congrats , great job π π
Nice
I miss JS now
nice to meet you all, i started this year to learn and am pretty excited
console.write("js, misses you too")
Glad to hear that π 
It is
too much python as of late i think
that's js right ?
yuh
print_r xD
You might have gotten it mixed up with document.write
guys... i know to many languages they all just morph into one now
Thank you, but I'll need more practice on this
Gave +1 Rep to @cloud quiver (current: #1 - 3542)
Skill issue
I'll also have to take notes potentially since there's a lot more to learn
it rly is
Very
i just had a redbull and i havent had an energy drink in so long. my heart is about to explode rn.
mistakes were made
Today's msfconsole art
Looks like a cow?
MOOOO
Yeah it is a huge topic , this room is just scratching the surface
I gotta get to the metasploit rooms man Iβve been lacking
metasploit goes hard. script kiddys dream. its my dream. i am script kiddy
Is a good C2
A part of my soul dies when I have to learn a new tool just bc I donβt really like using them, I prefer learning the logic behind attacks
I'd say they are two separate things
Learning the tool is helpful and important, but learning the attack behind them can be important as well
That said, msfconsole taking so much time today
I just updated the metasploit-framework, maybe that's why
use Armitage
does anyone unironically use armitage? be honest
what in the
Use light mode
i know but im sure the staff would like to know
I donβt know why ppl are so allergic to light mode xD
#1333993673381253162 π
Just for that one room
Or clear browser cache and relogin
light mode is bad for your eyes is why
My theory is that we arenβt used enough to getting actual sunlight outside so anything bright is too much to handle xD
Exactly which is why i recommend taking walks around 9am and 5pm
Those are not active anymore
i see that now lol
Report in #1333993673381253162
I think Iβll code up an app that generates and stores passwords for sites you enter
i see ty
make your own password manager?
Yes. It shouldn't take too long
its pretty easy to google how to encrypt your files as well make sure you generate your own random keys
and look up how to generate your private key using a password that you set in the program
I have done exactly that
and dont store the password either you should only store a password hash and compare that
i wouldnt
its easy and if you do everything im saying it will be extremly secure
You canβt
Just don't try to roll your own crypto.
You must store the password to be able to reuse it
worng you come up with a hash algorithm that you use to generate a password hash
No.
But anything you want to use that password with will not simply let you pass the hash... And if it did, then the hash becomes the password.
then when i type my password in i run it through the same hash and compare it to the stored hash and if they are the same then boom
and then i encrypt the file that the passwords are stored in using my own public and private key that i generate
Also no
i have already written this code
Local pubkey doesnβt make sense
Keith, slow down and listen for a moment.
You have a password manager. To manage your login to sites and programs, let's say for instance, LinkedIn, right?
you guys missed the begining of the convo
what did I start
this guy said he wanted to write his own so i was saying how he could
I am just making one for fun
"I think Iβll code up an app that generates and stores passwords for sites you enter" - quote
Which, yes, that's a password manager, but, as chicken said, in order to use that password to login to a site, you need, the password, not a hash of it.
totally doable
the hash is only for the password to login to the app
Donβt do it this way
all your other passwords are saved in an encrypted file follow along jeez
It opens up vulnerabilities you donβt need to have
No need to store the hash of the master password at all
Hi all
Storing it only weakens the outer encryption layer
how else are you going to check if its correct?
The output being correct, tells you it's correct.
logging in tells you it's correct lol
but storing your password hash is how every website does it
Well, not every website
you wont be able to verify your login without checking it somehow either my way or the way @polar spoke
Locally decrypted containers like some online bitcoin wallets and proton mail and such donβt
Correct, so they donβt
They locally decrypt into your browser and fail on bad password
i like that
Websites that donβt use local decryption will store a hash, usually, but itβs ALSO not necessary that they do that either
Better crypto systems exist, they just arenβt widely deployed
still though you cant deny that storing the hash is how 70% of websites do it
I don't think it matter if the website itself tells me
Oh of course
But local password managers donβt π
Oh chicken... Speaking of crypto wallets. I'm a complete coin novice, but I have a few, and I need to transfer them, preferably to an offline wallet, have any good reference materials?
yeah but we are talking about how do you save all your passwords and keep somone from opening your custom made password manager
yeah i never thought of just doing it that way
Yeah, this is what I do so if you want advice on how to do it right, feel free to ask
encrypt the save file and keep your computer secure

not much else you can do
you implement a master password like we were talking about
Remember if you have it decrypted, it's plaintext somewhere on your machine.
Sorta ish
Yeah and in memory and potentially in all sorts of other places
Biometrics are neat... But also, technically, more public than your thoughts.
then you save that password in another password manager
im writing custom software for family business that saves encrypted information and i was going to do a master password. now i know how to do it the best way
Will I get sued if I use the THM logo as my GUI background
I would honestly not want to do that
Sounds like a huge amount of liability
I assume they have a trademark, and due to the way trademark laws work, they MUST enforce their mark, or risk losing it.
Nah, all of the biometrics take place in enclaves or other secure hardware elements
i love it. i went to school for computer programming / game development
So, if you have a good reason to use, and associate that use, with your software, send them an email, and get permission.
Oh Iβm sure itβs fun, it just sounds like a ton of liability
Applied crypto is hard and hard to get right
not commercial use tho
meh
i feel like its overkill cuz small business but you can never be too safe lol
i mean, i wouldnt say its overkill
Yep, but it's not copyright, it's trademark. No safe harbours.
depending on what the business does, it's probably required in some ways
yeah
figured
i'm just saying I would NOT want to custom develop anything that does that for any kind of business use
especially if they are required to do that by a compliance framework or certification process
as they will almost certainly not be happy with a custom implementation that hasn't passed audit
In the 80s Nintendo actually used their trademark as their DRM.
Morning
im doing it in C# Windows Forms which makes it super easy to do. the libraries are already there for the encryption and everything
its all already working
That doesnβt really mean itβs been done right or will hold up to any level of scrutiny
Just using existing libraries helps but doesnβt fix a lot of the nuanced faults you can introduce into stuff like this
So then the regulators will need to audit the libraries you referenced, plus your code base, plus how you implement and interact...
Sure, but given the talk of storing the hash of the master password, itβs clear that this remains difficult territory to get right despite that amount of experience
Regulatory agencies don't work on trust me bro.
They make you pay to have the code audited by their approved vendor list.
im the sole IT ADMIN / Developer / Tech
Like, this is my area of expertise and I wouldnβt even feel comfortable doing it
Yeah this too lol
Does the company process credit card payments?
Handle PII? Etc.
i setup and manage the server
dope
Oh god PCI compliance makes this a nightmare
im not storing that kind of information
I canβt imagine trying to push a custom solution to meet PCI or NYDFS or similar
thank god im not
Even PII for employees can be sticky
I worked for a credit agency once upon a time, had to do the compliance audits.
Management kept trying to take shortcuts.
Yeah, I worked both insurance AND for a bank
yeah i have been researching
I did the whole lot of it, top to bottom, and it was rough
and im not storing sensitive employee or client data either
Fact is, it's just cheaper to use an accredited solution most of the time. π
we have quick books for all that
question, does credit cards cvv work the same/similar way as passwords do?
its fun for me and free for the company
No, not really
im storing mostly bid information and job info and timesheets and work completed information
Some of that can be regulated iirc
my goal is to make invoicing a ton faster
making a custom app to do things the way we want them done
so like do cc companies store them in plaintexts in their db cause that seems unsafe
I agree that sort of thing can be fun, and educational, I just wouldn't let it anywhere near production, until, and unless, it passed any kind of regulatory commissions requirements that it may cross territory with.
Hi frnds, can someone guide me get past the task 8 in Upload Vulnerabilities room.
can't figure out how to select and upload the file via command on annex.uploadvulns.thm
Why would that be unsafe
if their db ever get leaked
we wont rely on it until it has been tried and tested for many months
all cc would just be accesible
Yeah, but thatβs a given
It's only three numbers long. Shrug
Wouldn't make a very good password right?
π
any specific regulations you think i should look at?
Hi frnds, can someone guide me get past the task 8 in Upload Vulnerabilities room.
can't figure out how to select and upload the file via command on annex.uploadvulns.thm
so why not use a password instead of random 3 numbers, is it for convenience?
Itβs just not used that way
Itβs kinda more similar to a checksum than a password honestly
It's only one part of the whole verification process.
so the verification process for cc basicly just checks if you have the card or not cause all the info needed is there, so why not add a password so if a card was stolen the thief cant just use the cc, kinda how like debit cards work
they also dont want to make using the card too complicated
use virtual cards for best security those can be regenerated on the fly
I just did JS for beginner, if we have deobfuscation online to easly deobs.. then what's the purpose of it ? Makes harder is just copy paste it on a good website. I'm newbie in JS don't yell to me π
@polar spoke any recommendations for breach monitoring software preferably open source. Im redoing our server with proxmox instead of windows
that was taken care of a while ago thanks though
Gave +1 Rep to @grizzled void (current: #149 - 54)
yeah just noticed
and actually its #1333993673381253162 because the other ones are not being used anymore
good to know I was not aware of the changes, I will keep this mind, thanks
Gave +1 Rep to @real lichen (current: #2703 - 1)
no problem
Breach monitoring?
network monitoring
open source preferably?
both are
Yeah, thatβs a whole likeβ¦ field of stuff
sweet
IDS/IPS, network monitoring, endpoint monitoring, etc.
basic small business setup what would you do?
max 10 computers + 1 server and 1 offsite computer that uses openvpn to connect to the office network
offsite is used for data backup
Span critical ports + Snort
and snort can run on like a linux server vm that i spin up?
yep, give it a try. You can create alert file and even rst traffic
Good luck to anyone participating
And may the exploits be with you
tap is inline where span is mirrored traffic
Span is working perfectly, for high traffic it may missed some packet but ...
I prefer to run my Security Onion as a network TAP but SPAN works just fine
right and the SPAN can cause dropped packets because of the mirroring its duplicating packets and adding extra traffic
just what im reading
so if you have heavy traffic TAPS might be a better option im guessing?
special hardware needed for this?
if you run it as a VM in proxmox you would just direct all traffic through it for a TAP
If you want a really good product reliable and hardware based for high traffic, Probe Vectra are good, you installed Probe on critical and strategy port and you have a brain server collecting traffic from the probe. The product is great to detect abnomral behaviour based on signature and some ai to check pattern behavior.. But it's expensive π¦
It's not for a size of 10 computer but just fyi
yeah im trying to keep it simple no need for crazy enterprise stuff
sounds cool though
Great Scott Gadgets has a decent network tap for under $50 if you needed a physical tap (keep in mind that it does lower the speed from 1000BASET to 100BASETX but for learning purposes it is good) but if you are doing it all in VM you don't need the additional hardware
snort is great for you i believe if you are concern about heavy load, check you might have some distribute design with cuthrough ..i'm not sure but i won't be surprised
im trying to apply everything im learning to the family business
i still gotta convince them to buy a nice managed switch lol
i got a router that can handle 10GBe so thats a start
and i ordered a NIC for the server that will handle 10GBe
gonna run the 10GB to the server and all the other computers are on 1000Base
we arent even in an area that will give us more than 1GB of internet down yet but internal network is getting ready lol
enjoy
ty
Did someone say snort
idk, i've not been alerted π
So tired
Snort what
Same
Not appropriate to say in this server
Made the app
So.... Don't?
Who knows ..knows
Evil Corp!!
Tirbeca AT&T building 33 Thomas I lived in that neighbourhood for a bit
What's with the no windows
it's a building only for electronics, no-one is in there, therefore no need for windows, as the phone lines/services doesn't need sun
there is me thinking servers use photosynthesis for power
Architecturally it looks horrible lol
rumour has it that is an NSA building
The ventilation must be horrible
Yep
@restive plaza this individual sent me an unprompted friend request
maybe they wanna be fren
Mr robot?
33 thomas st, NY if you want to see it in person π
I lived near by for a bit
always a chance it could blow up.

I am so tired (hi so tiredπ) I've been completing incomplete rooms since morning that I had joined but not done yet
Vro talking to himself
Helloo
I would be scared to death stepping my foot inside
does tryhackme have a challenge room thats just pure pcap analysis, i still struggle with those
what do u suggest to me to learn c or to stay on the tryhackme path ?
tf? those are to diffrent things
i dont think there is much content on learning the C lanauages however if u search for them there might be if you just want a good learning path follow this #start-here
@restive plaza there is a rule not to add or dm users without asking first please dont do that!
yoo u got friend request too???
yer i did i guessed they might not have checked the rules so better to clarify as the mods dont mind us reminding people of that one
Please am new on this app and I need friends to talk to
Ok
Okay
Can I add you
the mighty kgb wassup!
Can I add you
depends on u bro
what you find more intresting etc
Accept my request
How polite
@mossy river @sick lance
ima give u an advice on connections if u beg for it no one will need u u have to make him need u too so u can advice each other
:hammer: carolina583837#0 has been banned.
What
woah
sorry if u were resting jabba
was he realy want friends or it was a hack ?
Itβs a scam bot
aha
guessed with that pfp pick but thought id be nice as we try to spread kindness here!
me too any pfp with 18+ its likely for scams
but hacks idk if its possible by just adding u
like what
c is cool to learn how computers work
any coding lanuage will help you but mostly unless you are doing more specific things knowing coding wont be required
im not a good coder but im not a awful hacker
so tryhackme it is then
follow the #start-here path it will guide ya
thnx so muchu
this is a lovely server people always help
for example im always a big supporter of the lovely kgb he is our room helper god
imo
whats the add friends butten down the path about is it more fun this way or it takes ur time
any1 here whos done all the xss labs on portswigger?
There should be button on the left side of your dashboard below skill matrix π
I did π
whats xss mr foxy
Wasup today whit you guys?
can u gimme a hint for one of the labs
dis one
What Chanel can i find a team to join?
This one is a bit tricky . It's about one specific behavior of an animate tag which can allow us to add attributes to other tags
but isnt animate blocked
Team for what π ?
only <a> tag is allowed
ctfs
Shouldn't be it can be nested inside <a>
okok tyyyy
Sup
Dont know how it is in THM but in HTB you can do boxes in teams
You can ask in #room-help if you have some problem . There's also team option on THM . Go to your account settings > Teams
Yes, ut how to find teams to join...?!
Well , you can try to ask somebody here he is also looking for a team . Maybe you can also check #koth channel π
Please use their own discord server.
Aait, thanx
its dead
Doesn't mean you can break our community rules. π
Why you asking for hints when they literally give you the solution and hints? xD
they dont give hints for every challenge
Did ask in the site help Chanel but no answer. I did register with a Google account, now i cant change my mail or set a pass for my account, can i change this some how?
You can't change email with a Google sign in.
Then open the solution, and only see 1 line at the time
oh its against the rules
ok mb
If you wanna solve it by yourself, read the materials, try payloads and more payloads until you give up eventually and just look at the solution xd
I know, so i wonder if i can change my registration..?
For THM?
You'd need to contact support.
But I don't think so, with how Google sets up accounts.
Scrubz, I have a question regarding my "Full Name" in the Tryhackme profile, I wanted to change it to something else, it is currently 0xVoidBytes, but it says I can't have numbers on it when I try to change it to 0xSomethingElse
I already have a number on it 
You could have had the 0 before the change.
So anything set before the change, will be allowed to stay.
Ok, i see... One more q: in my profile it is a flag for UK, im from Sweden, did not find whare to change it...
Ah yes rare π·
Did everyone get a free nitro?
@crystal moss ^
Tanx
No?
I don't know then, I was gifted a free week of it
From who? THM?
Nah, they don't do nitros iirc
A free week maybe by discord themselves
how are you today guys?
I was getting free Nitro and it would have started charging me after a month
thats usually how it goes
So its the same as Music giving a month free at start or YT premium giving a month free for the first timers
π€·π»ββοΈ
A hook, so unexpected
Lemme send a screenshot
Hey Guys been a while, I have a question for the masses but background history first. we know of automated chains to mitigate HID vulnerabilities on internal infrastructure for example, white, black and quarantine lists for plug and play devices. My question is, when performing a reconnaissance during pentesting, what tools or techniques would a recon phase use to enumerate the chains and external granular PnP devices to isolate potential for HID threat vectors in anticipation of recommendations post pentest?
We know NMap and ZenMap can fingerprint internal infrastructure but that is for networked nodes, the issue here obviously is the granular nodes of PnP, perhaps someone knows of relevant scripts?
So you want to enumerate if there's any vulnerable external devices?
I shall be 0xB soonβ’οΈ
really nice πͺ
Maltego?
Maybe did misunderstand what you want to do...


