#general
1 messages Β· Page 903 of 1
Morning!
Thanks
Gave +1 Rep to @cloud quiver (current: #1 - 3546)
perhaps i dont understand so let me try and clarify, you're assuming that a target is white/black listing HID devices? based on what, the device ID/descriptor?
if your intent is to spoof an HID device, simply look at what's plugged in and use the same ID?
honestly, i'd be pretty surprised if there was anyone putting any real effort into that sort of control
beyond blocking external storage devices or simply disabling external USB sockets, it'd be fairly difficult to implement that at scale and expect it to go over smoothly
many laptops, for example, have their keyboard simply "attached" via USB, though on an internal header
Hello everyone!
I forgot if i greeted tbh
OH MY WE HAVE NEW ROLES ?
Its been a very very long time since i joined....2 maybe 3 years now.
(I forgot my original acc password tbh)
use a password manager 
I have a notebook where i used to write my passwords.
fair enough, that's good too
When was the last time you were here? Before COVID? π
Dark mode is relatively new feature on THM
I thought he was talking about Discord
Came right after AOC2024 π€
Yeah , near the end on AOC2024 ,on Dec 23rd π
@sick lance
that actually just tried to open on my pc
without me clicking on it
jesus
It looked genuine π
My phone is fucked
nah the link had something sus at the end
like hijacker
iPhone?
One time use phone now
Just let it dry
Android
Put it in rice bro
Ahh, canβt say for sure thenπ
Best bet
Horrible idea
Risotto
green army unite!
Are we talking about za?
Hopefully I will do smth
NO
Damn

What's crackin', hackers?
The hash
my brain
i think around 2020
I feel like I will regret this, need to ask our senior if I could get read access to our codebase so I can make some code for it, meaning I would have to develop php π
Php good
Php is useful I donβt like it
php is no thanks
I have written enough php to hate it
sometimes when you turn something fun into a job you tend to hate it
I've never written php for work
'PHP' and 'fun' should never be in the same sentence
embed failure
You'll need to be verified to post embedded content
I see
You can follow what kyootyBella said
I don't think that's their name...
I'm verified
Tam knew what he meant tho
π
My bad
I always pronounced it that cause I thought it rhymed
Irrelevant. π
Itβs important to make sure that messages arenβt making community members uncomfortable, which it did in this case hence why a moderator intervened π
Agreed
makes sense ig
So that what we having for lunch today?
I slow roasted a gamon joint in honey and Iβm having some cheesy chips with it
I'm making chocolate cake
Ooo I love brownies
I can't disclose the occasion however it's important!
your most hated coworker got fired?
How did you know?
common issue I suppose 
successfully implementing security policies into a system or network to defend it from cyber attacks!
It's just reinforcement learning ifykyk
research natural language processing! it's a very interesting subject, you can find a lot of insights into how we gather, and analyze information. Especially Store it for long term recall.
has anyone used "Island" Browser? Any opinion if so?
Ah, oops!
Good Day Everyone
hey hey π
Hi
Based on standard practice for threat vector reduction and both internal and external threats and social engineering (referring you to film 'BlackHat') I was curious because in that reception scene if not sufficiently deployed as an autonomous chain, the exploit is successful.
What
Can you rephrase that?
But also from a pentest perspective how would an redteamer enumerate the current granular ecosystem remotely to construct threat modelling attack boxes
OSINt, job listings
That's what was done for the SolarWinds hack
π pertaining to the non networked hotpluggable nodes (flash drives, external SSD, mice, etc)
i meanj...... depending on the enviorment you can just walk in and look around.
go the local coffeeshop and see what people have in their laptops
No I get that, but you don't wanna get caught doing that
Yeah, but depending on the enviorment it isn't a big deal
Also that is a significant amount of extra work for the red teamer involved in social engineering and passive recon
It is a big deal in a secure environment such as DoD
For example
if it's red team, instead of a pentest it doen't matter so much eh?
That's sort of the difference
if it's in scope....
I won't talk about those types of enviorments π
Yeah but the recon phase is part of penetration testing, as is social engineering and physical tactical access / assault
I think we should halt the conversation there
π¬
If you're ever in that situation, you'll be with someone that knows what to do π
π
cuties
I will say that my company does do planning like that π
NDA man, NDA!
You're pretty silly
I know walks away hanging head in shame
shame, what's that? π π
No idea!
I saw it in a film once
Anyways GTG C|CT is static on my browser and calling me back! Peace out 01 x x
what's what?
Random abbreviations
Anyways gotta-go C|CT is static...
my dtq and fugulated Q-spec is all out of whack this morning
Yes but the anatomisation of the disassembler in the static sphere of Croasia is definitely discussable
Whoa whoa whoa... on a Thursday???
Affects the market cap drastically, I'm afraid
Yeah my BLT drive went AWOL
hey anybody got an physical image of SAL1 cert?
like, a printout?
i mean yes
like they've metioned "A physical cert sent to you" so just wanted to know if anybody got that or not
yer
Not yet
ohh
They're still working things out with a supplier.
and that comes under the same pricing mentioned or we had to pay more, any idea about that one
I'm not sure.
I asked,. It did not get an answer.
Yeah, means I am in china for a week doing fun stuff, then in Italy for half a week doing competition
Yeah, I'll be so dead though lmao
good way to leak your name
nah idrc
going to china 9th-14th and then italy 19th-23rd then school the 24th
π
im gonna go outside rn
il tell yas either when i come back (6-7pm my time, utc-3, 11am rn) or tomorrow
I'm so not jealous at all
/j /s
very happy for you
thanku thanku
and defi a little jealous
What are your competitions in China?
If I understood that correctly
work in china
Any easy filter to find the type of CMS in the logs on Splunk(SOC Level 1)
You may find the answer here
@pliant onyx Thank you!!!
Np
Have you traveled there before? If not, expect your laptop to be imaged, so take a loaner if necessary
Damn
I haven't, but I am indeed bringing a brand new laptop with nixos on it
Sup alpha
or tails
Why tails just very privacy focused ?
cause then I have only certain things laying on it, and the rest I can add afterwards when I have landed in china
yea, i guess i didn't consider their network conditions over there lol
Hey question do yall know any blender servers?
hi
Gigabrain move. It's awkward when they barge into your hotel room and start capturing forensic images of your shit right in front of you or when you leave the room
"Hmmm I distinctly remember placing these books on top of the laptop in a different order" π€£
They do that?
crazy
Anyone here reported security issues to ct.gov before and if so how long did they generally take to respond
Are they on Bugcrowd or something?
Nope, only method I found has been a direct email to them
No idea then
hello guys, im new here and i need to learn something, someone who knos the tor and deppweb can help ?
with what?
i cant found some content on internet teach how to enjoy communits and foruns on darkweeb, can you recommend me ?
I don't think we can help you with anything related to the darkweb nor the onion network
We can as long as itβs not illegal or unethical
There isnβt anything inherently bad about using the Dark Web, itβs just what you do on it
i just want to learn guys kkkk
i am not asking you to teach me
just recommend some content
content as in?
you can access anything from the dark web that you can from the normal internet, if privacy is your concern
I never knew this existed, thanks I'm gonna complete this rn
Gave +1 Rep to @mossy river (current: #6 - 1500)
I agree, but it is usually very uncomfortable talking about stuff like this, while it's isn't anything inherently wrong it's very uncomfortable
Take for example the Sakura room
I didn't want to do that darkweb shit
Osint room on thm
oh, it involves the dark web?
A bit
Might check it out later
Yup of course and that is your preference, I was just clarifying the community rules:)
I like dark web stuff
Only because its interesting, not because of any other illegal reasons
The darkweb gets a bad rep
There are a lot of uses for it which arenβt illegal, itβs just most people associate it negatively because thatβs where a lot of crime happens
It's useful if you are countries like iran
Itβs a similar perception with βHackingβ, it has a bad rep
I agree
From now on I have say to pentester and hope they don't ask further questions
Hacking has a sort of 'cool' vibe here
I don't share it of course
but its something ive noticed
like omg im superhuman kind of vibes about it
Cybersecurity is a better word because itβs used more in the industry and henceforth has a better rep
Yeah
My school had a Cybersecurity course!
It included: don't click link
don't trust strangers online
I do a cybersecurity degree π
Yes my school had the same
Thatβs commonly included in most IT courses in the UK
"What's a cookie" smh
Ours says cybersecurity too, and its just "be safe online, be respectful, dont click on links"
if you're looking to gain real cybersecurity knowledge, its useless
Just wanted to say I'm the latest Balatro addict
I curse the day I joined this server and heard of that damn drug
@mossy river You've got a new friend! π€£
This place ain't taking care of its youth!!!
Literally the match I just had
If you could bet real money on this game, would you π€
Because I know there's a lot of online card games which do primarily that
I hate gambling with every single part of my soul
I mean, fake money, sure
It's fun
+rep
Gave +1 Rep to @mossy river (current: #6 - 1501)
I once knew somebody who gambled away $200 in a casino, and then won back $50
and then went down more
house always wins, lads
Not unless you hack the house! ./s
Real, we're gonna hit it with an integer overflow to bankrupt it
Make your lottery numbers 10383892' OR '1'='1
Good morning everyone. Letβs hack π
Not today
Tmrw
At least for me
balatro my beloved
Hey
I've done HTML/CSS back in college, haven't done it since, so nope
Which kind ?
If you need any help free to ask .
anyone having any issues with loading on the site?
any issues with THM at the moment?
what happend with tryhackme?
yup, cannot load the website
I don't want to go outside make it go back up 
not really, it still struggles with loading some stuff
yes
doesnt load at all now
staring into an endless white void
yeah, for me its taking liike a minute loading the website
connecting to js.verisoul.ai some kind of fake account detection?
Yeah it is slow
same
im getting cloudflare captchas, A DDoS attack?
Same just got https://tryhackme.com/500
probably
me too
Me too
tryhacked? π€¨
again ... π
ah ffs
its probably just getting ddosed, nothing serious
this happened yesterday too
Why DDOS a learning Cyber platform xd
what time?
its gonna come back soon since cloudflare engaged
broo
it did before too
evening around 7pm i think?
its already back
utc?
not this again
Hello everyone, we're aware of a site issue and are looking into it. π
just got premium yesterday
BST
was all hyped up today
i see
for u guys?
yea
Hi everyone π . I'm not sure if this is the right channel to ask this question, but I didn't see any other channels where this question could be asked. So, I'm currently working my way through the Security 101 path on THM and I recently saw that they have the SAL 1 certification and I'm definitely interested in taking it, eventually of course, as I still have a quite a bit too learn, but my question is, I'm based in South Africa and I'm worried that the certification might not have as much weight as it would in say the UK or USA. Any thoughts or advice regarding this would be greatly appreciated
alr
working now for me
yup same
It became normal after around 9 min of load.


it doesn't have any weight at all right now, it's only been out for 2 days
give it some time and we'll see
I think it would have as much weight everywhere
Rn it's not worth much because it's new
But it has high chances (imo) it will be worth a lot
Because it's very practical
Someone took the name too seriously and said "bet"
π
Network maintenance at home*
I was talking with a red teamer today, and I asked why he chose red teaming over pentesting and he said "to give the blue team palpitations"
YES
THIS IS MY ANSWER (kinda) AS WELL
Bro chose violence
My answer would have been
"Have you seen mr robot? It's like that, but legal."
fair answer
today is Thor's day π©οΈ , may you strike down bad actors
Hi veggies
Physical security sounds awesome
But there isn't any real way to actually practice it by yourself
And tomorrow Ramadan is possibly starting
You can practice picking locks at least
And then the plug in a raspberry pi and leave phase begins
Wallpaper of the day:
xkcd comics as wallpaper?
yuups
Hi
ooh a prince
What's up veggies
hello hacker prince
Then hack it
you make it Purple Rain
Maybe
.
#ffffff user would have been more clever
It's so cold
Chocolate rain is better
I might order some pizza
π« π§οΈ
using your terminal like a hacker?
π taking a break from hacking rn
Why
Hacking is good
Hacking is life
(And possibly pain)
we need breaks but the terminal is always there
Just did a AD environment. Recorded myself doing it. I like taking lots of breaks in between
To keep my mind fresh
Like very fresh
π
I hate AD so much
hack fresh β’οΈ
I love it
And windows exploitation as a whole tbf
I mean everything is easy tbh
True true
Long hours of reading, but it's easy so you remember
true = true or 1 = 1
I plan to specialize in AD and Web personally
You forgot the '

Me too, I wanna be a red teamer, a long way till there
But very much possible
Wya rn? Like what's the process or progreaa
Web pentesting rn
I can't even get a job (legally)
Linux: linpeas and pray
And check logs (optional)
I hate having to be creative
But it's necessary
That why I hate priv esc
I had a job interview
As a IT analyst π
Did terrible
It's weird how one interview is amazing and the next is complete shit
I hate the oscp
Expensive as fuck
Oh
Then it's ok
The htb CWEE is amazing tho
Especially for students
pretty sure you wait til i'm asleep or away to ping me now
From what I have heard
If u take rhe cwee
You can easily pass the oscp
I am not
I am just saying what a friend said
That took both
Hello, thought to ask this i painted a picture of i think how it is but when it comes to quant computing how does the alphabet get affected cause now the numbers just go to 64 bytes then the alphabet starts and other special symbols like (!, #, ")... etc. (What i've heard from my teacher) but how will this be grounded since there are so much more space and so much more things going on in quant computing and will we even use this for writing or will we just do maths & cryptography, encryptions on quantum computers. I have never discussed this topic before so please if you've an answear explain a little more simpler (if possible)
I may have understood the whole concept wrong this is my first time asking a question like this so may not have formulated my self the best neither.
sup
sup
anyone know how to make my pfp like the background same as the chat backgrounds
transparent png
Are you asking how quantum computers can break cryptography more easily than regular ones?
use color picker and add same color from chat to ur pfp
That wonβt work on lightmode^
No that i do understand as it could iterate between more numbers more effectively as i have understood it but i mean how will the alphabet be layed out and how will it work since there are so many more numbers it could iterate through?
Try this -> https://www.canva.com/features/transparent-background/
It's really easy if you have photoshop
Who even uses that
i used png bfr and it worked but i lost the old picture
i answered your query
yes thanx so mush
tried just now on nitro theme and fcked my eyes
Quite a lot of people, lightmode was just an example however.
It also won't work when the colour is different, i.e. when you open their profile, the background color changes so it looks funny
Same as vscode light mode just hurts your eyes and gives you a headache
Turn the lights on in your room, it won't hurt your eyes as much, if it does, turn the brightness down on your screen π
screen is oled so i prefer darker than black hole
It sort of iterates through two states more than once. I don't claim to know much about quantum crypto, but in traditional stuff it goes through binary, like 0 1 0 1
If you know the Schrodinger's Cat paradox, you'll know that things can exist in more than two states at a given point of time, the same can be said for qubits while they iterate through a given range
speaking of VS Code the theme i had used was pulled for malicious activity, so the 2nd time something from VS Code was bad
this image helps to understand that
people worry that ai will take over jobs, I worry that quantum computers will take over cybersecurity. we are not the same 
quantum computing is 4D chess
@mellow narwhal u subbed to HTB?
doesnt work
I don't have a subscription
I play actively, but no sub
THM ?
@mossy river can you check out Kaisel's bio ?
Used to be, but no. It's worth it though
Yes it takes up a bigger part of a specific assigned integrer right? but when we are typing the alphabet the computer takes it as for example "A" (65) will they put the alphabet in 0.34 for example and then 0.341 for a lowercase "a" or how will they do that? cause they want to use up as much power or logic as possible.
Not sure unfortunately, like I said quantum computing is beyond me
yeah thats what i thought
Wdym by put it in 0.34?
now what for learning
are you new?
as far i know its just calculating same possibilities at the same time
Since regular computer used today is jumping between 0 and 1 quantom computing can jump between 0 (to) 1 (what my professor has told me)
yeah something like that
lemme see
it is both 0 and 1 at the same time
Meaning they could parse or the transistors use decimals also
ahhh so its not 0 to 1 its just 0 1 same time?
check new Google quantom processor it explains really well
yes, its both at the same time
thats how it can break modern cryptography easily
ah fuck i've completely missunderstood the concept then
nws mate, if you read the schrodingers cat paradox you might understand more
thnx bravo
its directly related to quantum theory
also microsoft also got new chip and it was created in lowest temp on earth
thought it could jump between 0 to 1 so it could parse infinite numbers till its so near 1 its 1
Its in their documentation?
SchΓΆdingers? or schrodinger
on YT there's video of their processor launch
Yooo anyone 13-17 wanting to do PicoCFT with me and a buddy we need a team. dm
yeah the first one, with those dots on top of the o
How long do they have ctf challange for?
i'll check it out thanks
Gave +1 Rep to @broken horizon (current: #2704 - 1)
looks good
itβs a ten day challenge
The Google Quantum AI team is proud to announce Willow, our latest quantum chip. Willow has state-of-the-art performance across a number of metrics, enabling two major achievements.
First, Willow can reduce errors exponentially as quantum processors scale up using more qubits. This cracks a key challenge in quantum error correction that the fi...
starts march 7th
Oh hmm okey thought it would be over the weekend
jabba
ah sheet i can't then got into swedens finals in hacking (ctf)
whats the app that u used
Can't watch it right now but I'm saving it to watch later.
What temperature does the chip operate at?
congrats
thanks but do they have once a year or is it like every 3 months or so?
Gave +1 Rep to @rugged harbor (current: #2704 - 1)
itβs once a year
negative for sure
Kelvin?
LOL those qubits are gonna die
dont know and shitGPT cant find it either
ah found it around 15-20 millikelvin so about 1 kelvin
-459.67*F
or -273.15*C
π
hello everyone
@sick lance can you check Kaisel's bio for a specific term?
looking for a friend to know about hacking
@broken horizon can you please change your pronoun area, we don't use the n word in here.
has anyone interested for making a team with me for PWNme ctf?? please dm
isn't that an on-site CTF?
the finals at least
yeahh
Can someone give me some advice for the new THM certificate?
Do I just need to pass the SOC1 path?
For the cert or what?
Tyler Ramsbey has video on it on youtube
also check out #announcements
Thanks, I'll check it out
Gave +1 Rep to @grizzled wing (current: #43 - 216)
Ignore advice learn prompt injection
Since the new cert is gonna be graded with AI anyway
There is a roadmap for preparing for the cert.
Where may I find that, Lord Scrubz?
In the certification tabs.
is THM gonna release red team certificates in the future?
Thank you.
Gave +1 Rep to @sick lance (current: #2 - 3428)
No, that's the handle of a THM employee.
Lord would be a title not a first name so Lord still applies π
Hi, does anyone know how to check a script I need to know if it works and is secure
You can use a DAST tool like Snyk
Are you here to chat, or just talk shit?
A little bit of both
Free ?
I believe so
I'm not using any prohibited things in server and server rules apply in server right?
Your response will let me know if I should take your seriously or not.
oh thats a lot of engergy just to cool it
Your bio has a word we don't use in the server, I'm requesting you change it.
also if we take all the other things into consideration then it might need its mini powerplant and to dispense that heat
Are they though?
im not using it though, anyway i'll change it for my...
Well its worth it π
yeah if it can train AI then we're cooked

there will be no privacy basically
Well i think thats the point almost and to get Satoshi bitcoin wallet with 100 million in it π
Shouldnt you be preparing for the new box?
think about how many and how fast it'll find exploits and how efficient malicous code it can plant
I don't prepare lol
there isnt privacy nowadays to begin with, something or someone is always listening
I just dive in
you can't access it anyway
And I'm doing Maldev atm
Well imagine using that as an btc miner,
yeah but you can choose how much and who to give data like you can use chinese tech in west and western in asia
Companies try to screw with technicalities to push AI where it doesn't belong to fetch more telemetry, but it's thankfully only half working and most of them are trying to make local models a thing so that we don't gotta worry about that
Battlepass rewards would be fun.
I've seen that twice this week and I called htme out both times
@broken horizon can you change your bio section?
We should be more concerned with what the UK/US governments are cooking with investigatory laws
Bye bye apple encryption π
its half working for consumers and its full working for them. with ai we basically have very efficient smart spy in almost every device
wait blud
waddup people
its not amusement
its what
dayumn...the color changed itself
ok, i will just block you then. bye
I got muscles like Superman trainer
Insert joke about sudo block
tf so you'll ban me for literally not breaking any rules
From a pentester standpoint, I'm lovin it π
The world needed us when cloud became a thing and enterprise thought it was more secure to delegate security responsibilities to single companies
They need us again now to identify the spies
You're breaking rule 1 and 9.
i didn't ask anyone to visit my bio
Screw Embracer Group for cancelling the new Deus Ex game....
Recently finished Deus Ex: Mankind divided
Such a good game...
yeah it'll interesting and only those who adapt will servive
it'll be nice to see how and where it goes
you think that me blocking people is a joke? then you clearly do not understand
Okay damn chill
Don't have to be so aggressive
veggies!
please mind your own business
I feel borreeeed
hello
go for some bug bounties
wazzup mate
finishing the phishing room
Helppp meeeeee
wut really
aye noice...that's a ctf or walkthrough?
I dont know the minimum requirements for it
Did you catch anything?
So i don't know
ur hacker without that
Do some portswigger labs. Youβll be fine
a walkthrough. π congrats on being green!
In this field, you always feel like you don't know anything
Have you heard of GNS3
There's your rabbit hole for the evening. I'm using it to make me some nice homelabs + muck about with networking and firewalls
ur in the other server aswell right
Ah yes, something new from the "menial but useful" tasks, thanks!
Gave +1 Rep to @eager marsh (current: #610 - 9)
Alrightt, thanks mate!
Gave +1 Rep to @grizzled wing (current: #43 - 217)
what are you
on?
I'm saving this, thanks!
Wait, have i seen you there?
Shit youβre absolutely right. I got absolutely no idea what Iβm doing half the time. But if I donβt know what Iβm doing. Wanna know what I do? I sit down and learn it
I just started Advanced SQL Injection, it's part of the web applic. pentesting
I donβt bitch and moan that I donβt have the resources to learn it
yes, that was a fun room!
just try all three and choose what u like and then choose somthing in them that u like and specialize that
Imma also make good notes for this room, gotta level up in the notes thing
and dont look at other stuff

And for the love of god stop idolizing cyber influencers
yup yup...just installed it. Need to set it up
I'm learning most of the times, even though I know, I don't know, it's confusing but doable
I kinda agree, but why?
Totally agreed
community plugins for color tags and color text are the ones i use
I'm adding you
okieies...will try them
added
They people like you and me and they ainβt perfect. Some of em make mistakes. And donβt wait around for them to teach you something. Learn it yourself
will create new server sometime soon after a CTF event
I remember a time where I sucked ass at AD and Web
Yeah their primary goal is to make money, not teach
But I didnβt let that shit influence me, I sat down and learned it.
Thereβs evidence to the contrary butβ¦.thanks?
For context, GNS3 is a networking "Emulator" similar to CISCO's packet tracer, except every machine running on it is in a virtual machine and it has integrations with VmWare, Virtualbox and QEMU.
All the machines show up on a nice network map where you can connect them using Ethernet to hubs and routers, bridge them to your network or isolate them from it, etc
It's a popular option for simulating network setups, with a lot of pre-existing accessible images for routers/firewalls such as CISCO, Juniper, FortiNet, PfSense and more
It also has images for Windows servers and Kali Linux PCs, I'm leveraging it to make an Active Directory lab currently kind of like the Red Team Capstone challenge on THM for fun
Adding this to the list
That's a really cool home lab idea! I'm saving it
It surprisingly is light-weight enough to run on my laptop which is impressive and to note as well, however the bigger you go the more you'll need
Having an AD With 4 windows machines running won't do well on my 16gb of RAM and 8 cores
Try 16GB with 4 cores, my laptop is old, thanks again for this!
Gave +1 Rep to @glacial cove (current: #1074 - 4)
π
hi
hello
yeah they spam cert promo videos after one hit video
its just embarrassing
they can make good money from teaching but choose easy way
Could I setup GOAD on it
i thought you were the user with same name that is on another cyber sec Discord
The only thing I don't like about GNS3 is that it pushes Solar winds software on you.
My exact question
I think so, but you may need around 16gb of RAM and lots of cores.
Hey Scrub<
from my view you are the doppleganger haha
scrubz*
Hello
Did you get an answer for my question abt the certificate
fr
Will i need to pay or it will be free?
I did not.
Since there's vagrant setup scripts for it on VirtualBox/VMWare, you very much can, granted it won't show all the machines it creates on the neat network layout fully and you'll have to patch that in yourself if you want
I'll ask again in different channel
Ok Thank you
Gave +1 Rep to @sick lance (current: #2 - 3429)
If you get an answer can you mention me ?
I have arround 128 gb oof ram
Eh?
Which one?
SAL1
I think you need to pay to take the exam?
The last time I installed it asked for my email to send me "essential solarwinds software"
Around ~$300 or something
That's not want they're asking.
So Scrubz can you mention me when you will get an answer ?
Yeah π
Ok Thank you
You can ask, people may know the answer
You're still on cooldown
Wacky. I installed it through my package manager and haven't really heard a peep from it since
TBF.
It's Solarwinds who created it
Indeed. Well, as long as it's open source and somewhat community driven, I can't complain much
And after 12 hours straight of CTF, it's time for me to stop here
So AV evasion is a huge subject, and there are multiple different generalized techniques
AV meaning Anti-Virus, such as windows defender
But I'm not sure how much I'm allowed to say without going into #advanced-general (advanced categories) territory
Yeah, it's a tough one, too. Especially sharing knowledge and growing that skill for legitimate and ethical usage without informing unethical individuals
That just says No Access for me. What is it?
Advanced general
Ahh
Dunno why that did it twice
It's a bit hard to give a brief overview, because there's a lot of aspects to it as stated
You got OSCP?
Nawh, I've got GRTP though, if that counts
I might go for it one day, but I just haven't been able to justify it yet
That's a question for Jabba tbh
One of my job roles is breach attack simulation, so loaders and AV evasion is something we've been working on recently
Would it be alright to give him a ping about it?
Yeah, Jabba won't mind
Sweet, thank you!
@mossy river Hey Jabba! For those Advanced Channels, I don't have the OSCP but I do have the GRTP. Does that qualify me? I can send you a DM with my Credly, if you'd like
With a red team operation, I'd say no. With a pentest it's a bit different, as you want to cover everything (defense in depth), but the point of a pentest isn't to get boot2root
I definitely get that. Different configurations and different experiences can be a great way to learn. Especially with the different components of AD. Lots to mess up π€£
OSCP covers AV evasion
Yeah, I was going to say, you have to evade Defender, right?
OSEP most definitely does
on the exam?
Not on the exam I don't believe (I haven't taken it), but the theory course covers it
Can't speak for OSEP
Aww man. ChatGPT AMSI bypasses would have been funny
Not entirely sure, but it wouldn't surprise me. I know you have to for CRTO. That has been my biggest pain point before taking the exam
@pallid lotus does OSEP have AV evasion on the actual exam? or just covered in theory on the course material
CRTO II definitely focuses more on research and evasion as well
Currently these are the only roles that give access to the Advanced Channels
Love my fucking job (check out my hakko iron π)
For infrastructure pentest you are usually whitelisted, but if you manage to get RCE you will definitely stop there and consult with the client about how they want to proceed
Reminds me I've just finished my first soldering training class at Uni today π
Damn, guess I better get off my lazy ass and take the CRTO exam I bought π€£ Rasta gave me grief for buying it right after SEC565/GRTP, so I should be able to get it knocked out fairly quickly
Humble beginnings
Would I be able to recommend the GRTP cert be added to that or is it just not worth it with Discord's role limit?
Thanks
Gave +1 Rep to @shut hawk (current: #14 - 614)
Theoretically
is that advanced channel sponsored by INE?
I forgot about that too lol
yeah I always forget how strict they are lol
Hey guys any recommendations on how to get my CEH certification me and my son want to get it but he is 14 can he still take it?
We aren't accepting new cert roles right now because we have a ton with only one user in - in the past I have said if we have an overwhelming amount of users suggesting one, I will consider it.
SAL1 will give you access to the channel so if you can wait a week, you will get access
Should include oswa
nepotism-ish
Become a certified ethical hacker for an in-demand career with a step-by-step guide to achieving certification in 2023.
Very understandable lol. I think my analyst number on GRTP is 201 π€£ 200 beat me by about 10 minutes. I have no problem waiting around. Thank you!
Regardless of opinions about CEH, that's pretty awesome that you're doing it with him!
Bro is winning in life. π₯Ή
Roles should be generalized; example: any Offsec cert = or greater than OSCP
Very big "ish" there - you can thank Discord for my reluctance to add new roles if you could see how many we have π
For example, here is how many roles we have on certifications alone https://tryhackme.notion.site/Certification-Roles-17eabddf65c7803882f7dff0aa9a4fbd
Gave +1 Rep to @rough dome (current: #1770 - 2)
These roles were chosen by my predecessors, I haven't completely reviewed all Discord permissions yet π
I wish it was easy for y'all to hook into Credly to automatically map and validate roles for certs. I feel bad about bugging people to have mine updated lol
It'd be nice if Discord increased their role limit a bit, too
You pinged me when I was sleeping yesterday lol
Reaching Level 13 (0xD) on the TryHackMe website
And today, just been fixing up my resume a lot..... fun stuff
can also get you advanced access
ISC2 instantly sends the CISSP to Credly but when you do CCSP based on the passed CISSP, they take 55 billion years 
It's not just about Discord's limit but also the difficulty of managing a server with too many roles π
For real, especially without some sort of automation. Becomes a full time job!
Don't worry about it ahah, it only takes a few seconds to update.
I'd love to integrate it and make it automatic however
We're looking into it with Cyber Courses. Once we have our call with Credly, I can let you know what they say if you want. inb4 $8,000/mo
That would be amazing the idea, not the cost π€£
I'd hate for my next meeting to be "Can I have $8000 a month"
"Believe me, it's for a GREAT reason and so worth the money" lol
Installing virtualbox inside of vmware feels dirty
its probably important to do some blue teaming rooms even if you are aiming for red teaming right
Yup!
It's Pearson though, so I can't imagine they'd do any sort of cool stuff like that out of the goodness of their heart
think i will start sec engineer path
But it's kind of funny
We call it purple teaming, it's always good to understand what could be blocking you when on a pentest
That's why some of the best offensive security guys spent a lot of time working as a systems administrator or something in that arena
Yeah you could be getting fucked by the edr, it's helpful to understand what's tripping you up
Know thy enemy type shit
that is the advice Philip Wylie says
good eve
ben!
veggies ello ello!
henlo Ben
yea my plan is to get a blue job and then transition to red cos its hard to start as red
w33t! howdy
congrats on first blooding SAL1 π
No fucking way really?
aye
w33t was 1st π©Έ for SAL ? cool
@idle mica Good job on that
playing vscode for 7 hours
work 
Ben is in the studio cooking
Nice game
10/10 idea. If you have trouble getting that first role, don't be afraid to look at cyber-adjacent roles either! Nothing stops you from doing cool stuff and being a security advocate in any role
Thank you! I woke up at just the right time lol
Gave +1 Rep to @lone thistle (current: #9 - 916)
oh look its the guy from rev diaries
(and I have no life)
ive been a software engineer for 3 years but its not really cyber adjacent
Since when it became this famous 
Simon wont shut up about it
debugging in the studio lmfao
I'd argue that it is as a technical role. There is plenty of good experience to lean on there. Going into a security-specific role with that will be much easier, imo. Something like application security might be a doable jump
if i dont get laid off first β οΈ
At least compared to jumping into a role from zero
all my work friends got the axe
ohhhhhh shit, I'm sorry to hear that π
Software engineers should care about security. It's because of their shitty code that i'm able to get in the first place
we have a vscode extension that points out our security flaws
when teams doesnt notify you so you call IT and everyone stands around like this
snyk i think
You shouldnt rely on that!
its company policy
Snyk can only go so far, though. It can't identify complex logic flaws or other things that can be identified by a human tester
its still good to point out some off the rip
I'm about to do an assessment and was told "yeahh Snyk is lighting up like a Christmas tree", so now I'm wondering what else I'll find π
snyk is a thing and people still get hacked
A lot of places seem to take those tools and rely too much on them. They are helpful and have their place, but what kills them is the overreliance and being comfortable that the XYZ tool says "all good"
this π€
I actually just read a really interesting article about it from Forbes, surprisingly
Obviously there is some nuance and context around shipping code with known vulnerabilities, but it is still eyebrow raising
its just... im a software engineer mostly in name, cos most of my experience has been making dashboards
10k points finally π₯³
so didnt have that much contact with coding except for scripts for automation
Great job , congrats π π
i wish thm would let me have more than one path active
i have to change my path every time i wanna do smth from a different path
tails os is now installed 
it says im in the top 8% lol i only did some rooms for like 3 months, zero CTFs or competition
but i really like the gamification stuff, I dont want to lose my streak
cursive writing shouldn't exist, why is it thought
Gang
Virtualbox inside VMware is cursed as fuck
ππ
i heard vmware is way better than virtualbox but so far it was not free, maybe time to switch
It should be free now
Not as much as a difference as there used to be.
Would you say CPTS will have the HR craze in the future? I wanna skip the OSCP and instead go for CPTS, both because of cost and resources it comes with.
@prisma mica no referral links please.
keep it a secret)
dumb question but isnt tails supposed to be used from live usb
ive seen worse
Don't post it
It is free and I've been using it from last month VMware workstation pro
not yet
Amogus
I crashed LibreOffice 
It is, I installed it on a usb
i thought you installed it on laptop
Well technically I did
Me when I'm trynna impress with the butt
please don't try this at home
Only God can stop me
Yeah, it burns.

the guy is simply cleaning his eyes to get a sharper eyesight
he goes 8k
Hey everyone
@chilly veldt i just did the MrPhisher room and enjoyed your writeup
Hello guys ,i thought thm's Cyber security 101 course was free?
Majority is
All paths are free to access, contain subscription content however.
many rooms on THM are free
But it is asking premium for linux fundamentals part 2
How to connect my profile in tryhackme
You're welcome
How
dowxprd
π€ me broken ? throw panic error
is skipping those premium contents helds you that back?
Ahaha, my immediate thought was the API had changed and I'd be spending my night rewriting the code lool
Great
purple
Adept
I got flipper

flippers are so fun to play with tbh
π¬
sick!
illness!
do you know any mobile app, which allows copying nfc tags and using the phone instead of it ?
Hi everyone!
I would get a flipper if I knew what it actually did. They sound cool but I'm to inexperienced at the moment with cyber and want to be safe.
flipper is for shenanigans
What type?
What's everyone's thought on the SAL1 cert?
do unsafe things and enjoy the life
Opening tesla charging ports @boreal scarab
turn off tvs etc
or the doors)
Not for me, for others. I saw Piratesoftwares video on them.
Is that like radio waves and ect.
bluetooth , but yea
Got it, so you can do that stuff and not risk others. That's dope. I might get one then.
have ethical safe fun 
Of course 
Is that new cerification free to do?

is on going

