#general
1 messages Β· Page 915 of 1
Yup that type of advertisment is working really good π been following him for a long time
Thanks
Gave +1 Rep to @sharp citrus (current: #75 - 114)
Thanks
W
Every time he pops up heβs got me cracking up. He never gets old
Tysm
If you're going to send multiple links, please remove the embeds.. 
Are there any steganography rooms as well?
Have you used the search?
Good point
If not, may I introduce you to it?
@boreal scarab you use turnkey in prox?
My brain power is a little bit under room temperature
Pls forgive me good sir
does anyone regularly use the terminal on mac?
o/ shadow
@dark mason Not really an appropriate envriorment for that joke.
huh
konst == art in swedish
go eep eep then
need some rooms for steganography if possible-
streak of 59 days ended, was fun
Go search
Hi Sudo
hello kamma
i'm reading the article on
Close to 12,000 valid secrets that include API keys and passwords have been found in the Common Crawl dataset used for training multiple artificial intelligence models. - bleepingcomputer
Well thatβs not the worst thing they could be doing with the data
i ended mine after 102 days
Were you always green
it's all good,
you can ask for strike restore
i dont want to keeping streak alive is kinda pain in the ass
Day 3 of Ramadan hits differently, especially when its first day working as well
its gets boring after a while
i have been green for some time
I meant Slob
i have 45 rooms left on my list of to do
Youβve always been a green veggie
It becomes a responsibility after a while
i have the streak images for all of the streaks so to me it doesn't truly matter
(not earned all of them of course)
i was level 8-9 when i joined i think
or maybe higher
i dont remember
i think i was potato
Higher level than I am now
hard to imagine KGB as anything but green
kgb was born green
yep
before thm was a thing he's already 0xD
tell me about it π
damn
im at 33690
this is me 
who has the highest streak in history
shadow absorber i think
I was sitting at like a smooth 70 something before I lost mine
My longest streak was like 60 smth days
friend so far
I tried to use my voucher, but uhhhhhhhh that thing was messed up
ups
i went 90 days or so for real streak
im aiming for 90 days and then i will drop it
lesson to learn, dont use voucher on feb you lose 2-3 days 
yeahhhhhh
im sitting comfortably at 47 streak
once I get my 90 day badge, I'll be straight.
.
.
.
There's no more streak badges after that... right???
there are
that's a w e s o m e man
i earned the 90 days one, so that is the highest i got
30, 90, 180, 365, 500, 750, 1000, 1250 and 1500 i think
oh.........
streak 365 is the best one

has anyone used the SOC Simulator yet? If so how is it?
I don't wanna mess with it until I finish the Security Analyst path obvi
I was learning things on Let's Defend for a little bit before I hopped back on learning stuff on THM
John Hammond put out a video on it
any dnb/edm enjoyers present?
(I live for hard styles, I live for hardstyle, baby)
can i dm you a song i made (youtube link) and get your feedback on it
oh noice, I'll have to take a look at it
sure
watching through it being a SOC seems so stressful
you gotta be always paying attention to the notifs
techno: boots and pants and boots and pants and boots and pants and boots and pants and
trance: boots boots boots boots boots boots boots boots boots pants boots pants boots pants boots pants boots and boots and pants and pants and boots and boots and pants and pants and
dnb: boots and pants and boots boots and pants, boots and pants and boots boots and pants, boots and pants and boots boots and pants, boots and pants and boots boots and pants and pants and
Guys i accidentally snapped my streak yesterday cuz I've been sick
My streak is at 0
Fr
πfr fr
shadow flexing? 
you couldve had higher but broke it
is anyone else having issues with the VPN?
u wont see this on HTB, because their leaderboard system is actually fixed and do not grant you points for copying and pasting flags that exist in walkthroughs.
This is why THM always gets memed
are the flags randomized?
huh thats a good idea
but its still easy to cheat
nah they are not
Try to change the server π
We get people completing like 600-800 rooms in like 2 weeks. I mean they only fooling themselves just to be placed higher on the leaderboard.
eyyy @cloud quiver new color!
okay
you potato now like me π
yes they are at least on seasonal machines
new flag gets generated after restart
it is me or I'm stupid.... the room named 'Windows Fundamentals 1' is weird
Which selection will hide/disable the Search box? the anwser is taskbar no?
Maybe recent rooms? but not older? if they are that is great. But again I think rooms that have walktrhoughs should not be awarded points after completion.
First in that sub-menu π
i think you guys are talking abt diff platform
what in d heck is goig with ram =/
well thm is not competitive platform
whoever watch is rly dumb lol
why would they create a leaderboard then
just wondering are there any rules for making write up on priemium rooms
@chilly veldt if you are looking for more certs the new #announcements post seems right up your ally as you have btl1
to track progress perhaps
generally not as long as you respect the 72 hour embargo and/or the room creators wishes if it states to not make or post writeups
oh ok
nah, then why do they have first blood points
okay its not as competitive as hackthebox
and as for first bloods i feel like you should be given extra credit always if you solve something first
It wouldn't make sense for walkthrough rooms to give you credit because it incentivises rushing over the content as opposed to actually learning
I agree
also zed if you look at the content provided by both platforms, hackthebox is exclusively just machines and challenges
for learning you have academy
thm has both
yep, I like the way HTB have sort of put it together.
number going up makes me wanna learn though
i like number going up
this exactly
points on thm are more of a progress tracker
Points still go up when you do walkthrough rooms π
it rewards people who started THM earlier with more points though π
If you started TryHackMe early, you would have more points anyway as when points were recalculated, we didn't remove points from accounts π
yep π
However I agree, and I wouldn't mind suggesting a competitive aspect to the team - I'm all for competitive gamification. It's part of my dissertation π
I'm somewhat of a windows expert but going through the windows training anyway as part of my path. There's a question I absolutely am having trouble answering...
What is the command for Windows Troubleshooting?
I think it starts with c:\windows\system32___.exe / __
Can someone help me get unstuck? Is this the right forum?
the aoc sq are a good competitive aspect
Yearly leaderboard or only points for machines that do not have walkthroughs.
number go up is hella addictive ngl
jax has 100% completion of htb machines
dude completed everything
the guy is blooding every challenge with 3m users compared to the top3 in the leaderboard right now who only blooded a lot of rooms with fewer people on the platform
Well, taking away points from walkthrough rooms wouldn't make it fair on users who only want to use the platform for casual learning - not everyone wants to do challenges, but they still want to earn levels as a personal achievement and progress tracker.
If it helps, I believe challenge boxes have reduced points for the monthly leader board after a certain time frame π
Could I create a vulnerable virtual machine for testing?
Yup
By downloading another virtual machine?
Just setup a virtual machine to whatever .iso file you have and then make it vulnerable :)
The way I read it was challenges that don't have write-ups? But that's hard to enforce
I believe it's on one of the help docs
sounds more like insane to enforce but agree james
Wait slow down. π how do I do that?
Set up a machine like you normally would, then modify it to be vulnerable to whatever you want to test :)
I have virtual box so I need a different virtual machine?
i.e. if you want to practice brute forcing FTP, setup FTP and give it a random password from rockyou.txt, make sure it's accessible on your local network, then boot another VM and voila
actually do have a question how do you make pcap files for rooms, do you just make two vms that are communicating with each other then capture the network?
Pretty much
Yep, that's how I did it for Overpass 2
challenges that do not have write-ups for about a week or 2 and then once walkthroughs are released it grants 0 points. Once walktrhoughs are released its not that hard to just follow it step by step and collect the points. But just my opinion.
I will download and set up a virtual machine and come back to you
might not be appropriate to ask here but how about for wireshark challenges thats essenstially malware analysis like aoc sq 1, does the victim vm actually get infected for real
Was difficult, lots of broadcast from random stuff on networks so fully isolated is needed
wouldnt that be a good thing, like add another layer of obscurity
Don't do security through obscurity
Will points be removed from accounts in the future for any accounts that benefited from large point rooms that are now capped at lower points?
that was meant to be recalculated a while ago
Vulnhub is the best for this
Well, yes, but as James said it's an isolated VM.
Start VM, download malware, isolate it, enable wireshark and any other monitoring service (i.e. memory dump), detonate malware
Be mindful that if you do execute malware and it connects to a C2 server or other service, this would be considered unauthorised access. Yes. Silly, I know.
You can mock the c2 servers often
Very cool to learn how but I'll reserve anything further for #exploit-and-mal-studies
Me losing marks on my assignment because I thought they mocked the C2 server but in-fact they 'compromised another computer on the network'
sup
I mocked their C2 for my malware forensics coursework, instructor particularly liked it and used it as an exemplar next year
Damn
I would sudgest using vmware
it is free now
I put a ton of effort in 1st and 2nd year and got low marks so I pretty much gave up this year lol
Missed Christmas and new years implementing a fully working, secure hotel service only for him to not look at it
fsr i feel like the definition of low marks for jabba would be diff than most
I want to do pen testing and the course said to use 2 virtual machines. 1 with Kali and the 2nd one should be vulnerable so I can execute attacks
virtual box is fine but VMware create virtual machine to but the app is better and now it is free
60% is pretty low, even if it is a 2-1, we have been told my lecturers that they won't give above 70% on most assignments π€·ββοΈ
the installation file is hard and weird to get but I have it on me if you want to install it
VMware is like a better version of virtualbox
evil lecturer?
whats the minimum grade to pass
40% is to pass
ah
but lecturers have a habit of setting unreal expectations in their mind and not communicating them in the assignment brief.
well that sucks
speaking of which, just remembered something how did your ml assignment go
the irony in them expecting us to use perfect English and grammar only for the assignment brief to use American English and be riddled with mistakes (yes, there is a review and approval process).
Surprisingly really well, even after I had to strip it down to bare bones because I hadn't executed it and it would take more than the time I had left to finish running lol.
I got 72% I think - which is the highest grade. His comments were fair and actually quite helpful, not just the assignment but for my understanding on ML
Apparently not many other people were happy with how it was marked bahaha
jabba beat the system by being too good
Guys I messed up...
So I was doing an online coding exam for work purposes.
One of the obvious instructions were to not switch tabs (obvious because checking to see who's cheating) I set my autocomplete to ctrl + tab. Used chrome and...
It's bad.
Wrote to the instructors to see if they can forgive me, but highly doubt it. π’
Sounds rough, I hope for the best outcome pal
Thanks @topaz topaz hopefully they do understand and either accept it as is or let me retest because I know my course work. Python is a second language by now.
Gave +1 Rep to @topaz topaz (current: #264 - 27)
I'm assuming that they can see whether or not it was an accident, but your approach of addressing what happened rather than hiding definitely should tell them it was truly an accident
Hopefully. I'm not sure how it works because they use Coderbytes to test our knowledge. So it's not propriety in any way, but hope that they can see what happened and that I was only out of the webpage for max 1 second... Besides this has got me spooked due to the big Plagiarism document they make you accept before testing.
also, for future just have that one tab open in the window
then it'd be impossible to switch, because no others exist
That's my battle plan, but because the link is via email I made thr mistake of not closing the Gmail tab.
why did everyone stop typing π π€£
anywhere where i can find free rooms?
@G4G in the infinity hotel... (Quantum Maths)
u crazy or sum?
No... However if you know, you know.
So cool
I have a twin turbo so what
@grizzled wing https://arxiv.org/pdf/2401.12242 this looks interesting
oho
i was talkingabout
wsl
2
in cmd
so i could use linux sub system
but thats cool
what car you got?
Im kidding g
u got car?
Yeah golf 2 tdi
my dad had one but it just got oblyrated by BMW
crashed into him over 120miles per hour
good thing my dads car was big
Where r u from gng
Georgia
Makes sense
wbu
Serbia
cool
XD
Georgian and a Serbian man meet
Its similar here
yep
Wait like Georgia in the US or actual Georgia
anyone christian?
Serbian orthodox
Oh now that is interesting
yep
in Georgia
bro what i know
i can get a job
and i do NOT know that much
thats how weak our cyber security is
Well gotta work on that!
i mean
what can i do
im learning much as i can
and i will leave this country
π
if i get a job
im boxer too
but boxin aint it for me
You mean Sakartvelo π π¬πͺ
@cloud quiver oh you became room tester, congrats π₯³
Thanks π
Gave +1 Rep to @half girder (current: #145 - 56)
yall like our fighters?
what fighters?
neither, i dont have a religion
i cancled my membership plan like 20 years ago
if its not personal how old r u
40
fr?
yea pretty much
We do not allow discussions on religion or politics here for the record π
got that
oh not going to discuss religion, everyone is free to believe in whatever, also the flying spaghetti monster π
as some who is no religion. i do consider my self member of TST
yep im sorry
your right
hm why should that worry you? @olive jay
It's okay! π
thanks
Gave +1 Rep to @mossy river (current: #6 - 1509)
well, in georgia money is tight
and i mean tight, so i need a GOOD job for my family
well yk thats why im saying if i get a fair pay doing this
georgia, usa?
nope georgia,batumi
Sakartvelo π π¬πͺ
you from there?
shadow want shadow want repebble
woohoo. serv installed
local proxmox
oh so its using your resoruces right?
on pc where is installed yes
well, my pc can BEARLY handle windows 10 XD
@olive jay well, unfortunately i dont have no idea about your country, so it would be negligent to adivse something. best idea might be to ask in #cyber-and-careers specifically for your country
it is on another pc. the server pc
thank you
Gave +1 Rep to @half girder (current: #141 - 57)
thats cool
you mind telling me the specs?
i get an idea why the headset i got for 20 bucks was 20 bucks ... damn it
is lenovo t450. 16gb ram. idk details. but it have proxmox installed and 2x 1tb ssd and 2x 500gb ssd for storage. and one 4tb hdd
Sponsor: Thermaltake Tower 600 Case on Amazon https://geni.us/wjtN
We've seen a number of user reports pop-up about ASRock motherboard and 9800X3D CPU instability or failures, including CPUs dying (or sometimes, seeming "dead" due to instability -- but then working again with a new BIOS). We put together this report as we research and monitor th...

That storage
W computer hardware, clearly industries are pumping them out too fast
does not affect shadow as they are on an older rysen cpu and not an asrock motherboard
still don't like when this kinda stuff happens enough to actually spur up reports in the "news"
Take a wild guess how much this 500ml of hot coco costed me
10 cents
Damn
That's a steal π€£
Romanian market is crazy
not gonna specify a currency
I heard something happened near there today
just 500 some currency
What?
I ain't aware of nothing
Wait a sec
You seem a little bit different
NEW COLOR
π
KGB - Congratz on the room tester! π₯³
Again?
Anyways be safe
yeah kgb is now "forced" like the rest of us room testers to test rooms and no longer get blood points :D
Thanks π
Gave +1 Rep to @devout palm (current: #27 - 371)
kgb is top 10 on thm .. might be a reason?
Maybe
Hello people!
Yeah by recommendation from staff i suppose
Hello Master!
yeah I need to level up to get the Red colour
the only staff recommendation ill ever get will be a mute for lifetime xD
Looks the same for me
Yoo..KGB, congrats!
Hello, mostly by being active on the platform with challenges, be active in the community, and get noticed by contributing to making our content even better. π
Awesome! So basically everyone has a chance
doesnt @cloud quiver qualify for the act of kindness badge? π
KGB is very helpful
Thereβs so many rude boys outside, I constantly think thereβs a fight. Itβs so dodgy out π₯²
I gotta hear that all day
Give me mountains and rivers
KGB is my fav member from here
Bird cat
Yeah. Veggies is pretty cool
this is oat
Which one should I choose?
BBQ pollo
I was thinking the spicy one
Calabrese or salame

Only 11 euro for a pizza π

"Only"
Verdure looks fine too
Heads or tails?
In romania it's... 4. 4 dollars for a big pizza
Heads
That was a photo I took in Tenerife
One sec
Bro a fucking 500ml solda was 5 dollars
The fuck
From a good pizza place
Tenerife

Maspalomas is already cheaper
40??????
Yeah go Pizza Hut
Miami is cheaper
You start adding your pizza bits and then youβre like βyou know what, what about macciesβ lmao
But Miami is not near Tenerife lmao
I know
Because maccies is like 10 and Pizza Hut is over 30 everytime
This is a romanian dessert
Even papas is so over priced
Domino's dead in italy
No more Domino's here
PapanaΕi... you can choose the toping
Chocolate, jelly, whatever
If you're eating Dominos in Italy when there's much better local fresh Pizza, I have nothing to say π
Oh... there was people that chose Dominos over normal pizzerias, I saw it with my own eyes

Tourists I'd hope
Fake Italians
Italy has the best fucking pizza
Me fr
Well it was born here
Iβm gonna make choccy milk
If u get from a knoen pizza brand like doninos, Take a money management class and a sanity pill
Never heard of it
I will be happy if pineapples on pizza get banned on menus. I do not know who started this cult
That's a one good looking pizza π
That's a normal margherita
They usually cost 4/5 euro
But it will be the best pizza ever
Do they have pineapple pizza?
the virgin olive oil will be called olive oil after Chuck Norris visits it
Oh shit
You are an Italian
hey everyone!
I think a hitman has already been sent after me
Just a weird feeling
Hi hi
hey'
Wait... how do you know.. you know Markov ?

and with complete reason π
I am about to be famous!
chat
So he has failed, eight?

Right...
should i buy a thinkpad t470
Well, kali won't have issues to run there
The only doubt I have is the 2 core CPU
why kali
Welp that's what I use for cybersec
ill lowk get arch
You can choose any linux distro
whats wrong with it
Bro likes the challenges
It's... arch
yes
What @sinful bobcat said
or wants to say I use arch btw because it's cool now π
u pmo so bad
"My condolences btw"
Well yes it's a pc lol
I don't use arch π
Honestly I wouldn't miiiind I would do it one more time. I would let you cut the liiine just so I could be right where you areee..
Idk if it's your first or not, usually thinkpad are the first choice for beginners since the low prices and decent specs
what if im from romania?
Go on a trip to romania
Just for the laptop
You will be better off
I have no idea man
If you are then even better
Lower prices than most of europe
i wonder why
is funny because he was willing to spend 3K and he goes for a thinkpad t470 π
so funny
knee slapper
Oh he was not serious
This was for 800$ btw
he was in the chat for a few day asking the same question π
Be nice
Why does everyone say stay away from computer science
I'm scared from 13th and 14th intel man
It's programming
It's ironic, I'm not being mean
It's starting to get annoying
Why?
I went full AMD honestly
Elaborate
That's what I'm saying. It's different "no developer jobs" or no future for devs than "don't go to wtv has to do w computers ever again"
hey anyone interested to participate in HACKTHEBOX CTF can dm me
That's bullshit
AI can't do shit without developers
I fuckin love computer science. All these ppl say I shouldn't pursue because there's no job market tho and all these homeless jokes like gimme a break
is there any benefit in using OpenLDAP instead of responder
The amound of errors and vulnerabilities they give is insane
I mean the job science for computer science is shocking at the moment, but I haven't heard anyone say not to pursue it
i got this for $15
Raspberry pi?
A gem
amd is doing good, I have a lenovo legion Ryzen 7 32 gb 1 tb ssd, and it goes well
Wdym shocking? Shocking in what sectors? And for what country? That's what I mean. They terrorise people for no reason
Computer science is a good degree because it opens you up to a lot of IT jobs, I'd be inclined to tell people not to do degrees like Cybersecurity because computer science opens similar doors that Cyber does
its a laptop with a core 2 U7600
For 15$
Any laptop for that cheap is a good deal
i found it on ebay by sorting lowest price
who is going to train a create the models? π
I'm the only one of my group of friends with full amd (7800x3d+7800xt) and I have NEVER encountered an issue, from the setup, to stability, to performances and temperatures
All my other friends with intel+nvidia they all had problems, and for higher prices, lower performance and much more stability issues (primarly with expo and xmp enabled also)
In the UK and US (AFAIK), there are a lot of jokes about computer scientists getting a degree only to be homeless because there aren't jobs. However, in the UK, the job market is shambles right now anyway
I'm just young and confused. I do clearly know I love everything in my bio for example. To actually know it and learn it because I love it. But when it comes to what I'll get a certificate for to actually have as a job everybody make it seem so bad
How do I link my discord token? Iβm discord illiterate
There are steps
wrong link
Lmfao
I had an i7 before, and I telling you the amd gets a lot cooler under pressure, the i7 I had you could fried an egg on top of the laptop, π
Perfect
i remember they changed it but i forgot to which one
not just the UK, the states have job issues too. a bunch of jobs either with a skill cap too high for new people to get into or fake jobs
Thanks!
Gave +1 Rep to @sharp citrus (current: #74 - 115)
Oops
the bot shouldn't be able to recieve rep lol
the bot deserves love too
True as long as it's not the x3d, I had to change from an air cooler to an AIO this summer becasue the 7800x3d was TOO hot (91Β° undervolted at -20)
the job issues might be rather focused on the known companies like ms / google / salesforce / etc
guys should i do https://tryhackme.com/room/owasptop10 or https://tryhackme.com/room/owasptop102021 ? i am prepping for an interview
im watching this 4 hour long video on bug bounty and the shits kinda fire
Both are really fun
Go for both of them if you have time
which one is more up to date?
i will eventually for sure. but right now what do you think?
2021
bot out here stealing my rep
Aye it worked thanks again
I'm not saying it freezing, but the difference is it's warm and BBQ π
is there no 2024 or 25?
Hmm I suspect no
But
This one has everything you may need
Lmao
I helped a friend find a road exactly yesterday
From an instagram video
thanks! i will start with this then!
Gave +1 Rep to @sinful bobcat (current: #527 - 11)
I need to learn the following in 2 weeks
- steganography
- cryptography
- more osint
You welcome, when you finish the normal room challenges, there are some other, with various difficulty, in a particular section of the website
steganography is so lame. unless i don't know lol
False
Good for exiftrating data as a red teamer
is it relevant? outside of tryhackme challenges
.
Theory of Stego is interesting, relevance in the field and implementation into CTFs is what makes Stego suck
you mean in tryhackme website or owasp?
The owasp room I sent, the juice shop, it's basically the last one task: Exploration!
The only reason Inam learning it id that I have the Cybersecurity olympiad in 2 weeks
alright let me run your profile picture through the tools lol
I did my own "vault" app lmao
(Android only)
id not be dumb enough to hide them in my pfp
xd
It won't take you two weeks, don't worry, you could knock it out in about 60 minutes
just other random songs and photos on my pc xd
Hard to balance it out with school
I am more worried about crypto
Mhm
My biggest enemy
My lecturer hid all his files in images, but he also took a saw and cut off the top part of his phone because he thought the government were watching him so
ok i will start with juice shop right? or first top 10?
The "try not to commit self quit" problems
Crypto challenges are π β οΈ
Try directly the juice shop
thanks!
You welcome
I love him already
If I had two weeks to learn Crypto, I'd spent that two weeks finding someone who knows crypto and add them to my CTF team
tape could do the same though
It's individual

The sad thing, at least for me in italy, is that without a university, cryptography in CTFs is almost impossible for me
It's called Stegonography, but it's very obvious because no image of Shrek is 20GB in size, and it means you have to extract it and rehide it everytime you want to view it. Use bitlocker.
Last flare-on we had Elliptic curve combined with .NET native
And the attack was very specific
God i hate crypto
Ohhh okay, interesting. Thanks
Gave +1 Rep to @mossy river (current: #6 - 1510)
Na, that is fun
0
What if they use tape see-through technology!
What
I'm more web osint binary then privesc or windows things
If you give me logs I'll be the happiest person you could see that day lol
Does your lecturer have paranoia combined with schizophrenia?
you can always comfort yourself with coffee, wine and great food π π
my kali is running really good today π
Oh well, you listed the three top things in italy
Too easy

I know I've been there many times and I lived in Italy for 2 years π
I lived in Roma and Firenze, but being around a lot. I love Bologna
Daaaaaamn
Firenze is the best place to live with your girlfriend / boyfriend
Rome is the historical one
And bologna is just a place where living is fine and calm, not always in a rush like big cities but not a ghost town like smaller cities
And tortellini..
Damn
and ragu π
Oh daaamn, ragΓΉ alla bolognese

(I finished minutes ago my dinner and now I'm still thinking at food)
Also Bologna has one of the oldest universties in the world
bro i made 6 hotpockets today and every single one had bad
Most of italian universities are OLD
the bread was stail asf and it was a brand new box
The whole Emiglia Romagna is great in gastronomy π

University of Bologna is the oldest in Europe and one of the oldest in the world π Oldest than Oxford, Salamanca, Sorbonne
Also since the time that opened, never closed its doors until today
he sounds like an interesting conversation icl
What's up James
i just found 3 things in the owasp juice shop 
hi people, pardon me if it is no longer right to ask such questions on this channel, i've been away for a while. is there any point on ddos attacks other than causing harm? does the attacker benefit in any way, or is it just the receiver losing customers and money? or are there cases where ddos is a part/preparation of another hacking attack?
A distraction, but usually it's used with extortion
Looks like a spaceship π
had to talk to a lawyer today π
@real heath there is a cave with your name in Jerusalem π
In the old city to be precise π
haha nice, my name exist on both arabian and persian languages, so wouldn't be a surprise
I used to live near there, that's why I know the place π
In another cave ? π
i had once seen a method about causing a race condition on the server, and then leveraging it to perform an exploit. that made me wonder are there such methods where ddos is used to enable or facilitate another hacking act
I don't live in caves, the rent free is tempting but there are really chilly in winter
Let's be careful not to discuss illegal activity
I was gonna ask if you are batman π
nop, just GNU-Rex
sorry i did not mean that, what i mentioned was an ethical hacker's work published as a bug bounty
That was puerly education content/question...my 2 cents
It's moreso the end part
"For educational purposes" isn't a get out of jail free card
Haha fair enough but he was not asking how to do it lol..
Mhm which is why it wasn't a warning, just a friendly reminder
thanks, i will keep the conversation in the legal borders
Can't fight both ninja and jabba π i surrender π
Not looking to argue don't worry, just clarify why and what happened π
ay up james, how're you?
Uhh
Is Zeek room bugged? Task 2, last question
Random Question has anyone been to the RedRocks concert π
can't say I have but my room feels like a concert at the moment, uncomfortably hot and with music blasting
I believe I have heard about DDoSing a website and then using DNS hijacking, however I couldn't find anything in my Google search @red surge
the goal would be to take the website offline, and then spawn a fake one for users to use
kinda surprised it's not used in other ways these days
but probably best not to get into how it could be used
I believe I am down with the sickness in a less musical sense so I'm sweating it out and blasting music to make myself feel better haha
Feel better Burr
Hey jabba asaf was actually asking the question π
so can we say, ddos is mostly extortion like a cyber-violence, without any gains to the attacker, so out of ethical hackers' domain. but there are also (maybe uncommon) cases, where it is used to combine strategically with another methods
Ah oops, scatter brain
sometimes it's done out of political motive, or personal motive rather than financial
No worries its interesting π
i think i might have experienced such attacks on some governmental website which kids here use to check their school notes. it happened quite a lot when i was on middle school
That's an interesting attack for sure, but useless if you are targeting phising campaigns like Instagram or bank accounts
DDoSing those would be a pain
Yeah things are going around at the moment
went up to scotland for securi-tay, was looking forward to both the conference and three days of heavy drinking. Was tired for the conference but made it and only managed about 4/5 pints over 3 days, I literally struggled through a pint at an open bar π
Absolutely devastating
and my housemates came home each night steaming so I also ended up helping them where possible bless em
Hello
I have a question about the AD rooms of the Red Team path
Are they all connected into one AD environment or no
@sick lance @jagged yarrow are any of you available right now
What's up?
Would you ban this individual for trying to dox other server members
user: nvrrlove
I'm assuming that's your name?
Yes it's an online name i go by
on my public spam email
And he's attempting to dox me
@prisma schooner
:hammer: nvrrlove#0 has been banned.
[BAN] User left the discord server.
What if this user made a fake user with the same PFP ?
What do you mean?
U got no confirmation because it could have been fake
U want to convince hackers that you cant make a fake image and profile to do this?
Given that the user left right after I pinged them, I find it highly likely lol.. furthermore, Discord usernames are all unique and there is a ban appeal process for the user to appeal their case in the event of wrong bans.
If jabba requests me to make a video of me copying user id he can do it
Oh ok
why would they do that tho
He achieved nothing with this
i know
that's one of his alt accounts which i realized later on
I'm guessing he's not a private investigator
his mother kicked him out the house and destroyed his phone
hello everyone
he now lives with his nanny
that raises more questions than answers
yea he makes a fake online persona to seem cool, he has absolutely no knowledge regarding pentesting either which i ctf'd him in
he also pretended to be a 764 member
just came to speak to you actually, do you know of any hash:cracked_hash lists for any hash_type at all? I am having problems finding them. I would presume someone has done sha1 for rockyou or something but I am out of luck π€ I can make it myself but I am lazy hahaha
i found a better version of rockyou but its 200 gb
why would it be worse
because it's 200gb of complete garbage assembled by someone who doesn't know that RockYou was a real website that got breached and not a name of some random wordlist
i am not sure how to answer this, someone presents me with a hash and I should answer with the cracked result (ignoring everything related to collisions π )
then you don't want hash:plain pairs
you just need to crack it like any other hash
well, the whole point of rockyou is for bruteforcing, more inputs is a bigger chance for receiving a result, no?
no
the only downside is it takes more time
more words != more better
i essentially want the db for https://crackstation.net/
Crackstation is the most effective hash cracking service. We crack: MD5, SHA1, SHA2, WPA, and much more...
why
why not just get a decent wordlist and use hashcat?
because you actually need the words to be useful
and related to what you are attacking
and not just random strings
Hashcat is something I'm glad I learned,.and I'm still learning with it.
okay, i will just make the database myself thanks π
Gave +1 Rep to @polar spoke (current: #139 - 58)
there's an infinite amount of learning to be done on that front, I'm still learning from it too
I would advise against it
it's just a waste of space to do that
even a simple attack can span petabytes without breaking a sweat
it's both more space efficient and faster to do the attack at time than to try to precompute and store
which is why 1. no one should be making hash:plain databases, and 2. no one should really even be making rainbowtables
thats interesting thanks, i will still do what i said but i will think about this π
it'd be far better to simply get a decent wordlist and toss it into hashcat or similar
you'll run out of storage for a database like that long before you run out of compute
and you'll have spent the same amount on compute as well
@rapid merlin You really need to review your conduct here.
You just reported someone for doxxing, and then decided to give out information about another person's life... of which you were investigating with no authority. Do you see the irony in that?
Not only is it inappropriate to discuss here, it's evident that you are being unethical.
W music
absolutely
I got a song suggestion if I may
I was listening to it at like a medium-loud volume and my housemate messaged in the gc to compliment the song choices so I cranked it up for him haha
absolutely mate π
Bricks to the butterfly
I'll add it to the queue, cheers π
It's a hidden gem I am telling you
It's just started playing now, will lyk what I think
"investigating"? he told me his mothers name before, we were friends
gonna have to add it to the playlist, maybe not this playlist but it's definitely a good song
Sad yet happy at the same time
absolutely, and love the tune too
Have you heard of HOME?
:hammer: sinboundsoul#0 has been banned.
I recognise the name I think
That turned south so quickly
Upon viewing their moderation history, I found that this isn't the first occurrence for them.
well it was pretty obvious why that happened
I get why you banned him, it was kinda funny to "HE DOXXED ME" to him basically doing the same
Did you also randomly receive a nitro trial from discord?
oh I thought u meant recently
I did ages ago
I only used the trial because its free for x amount of days.
got bring me the horizon blasting and I'm here playing clash of clans
I honestly do not know how the mods manage to monitor all the chats with the amount of users in this discord. Surely they get a guy posting a dodgy link every now and again in a random chat

Try chess
gotta participate in the clan war
Everytime you lose a piece just turn up the song a little bit
It will be absolute cinema
bad idea for me haha
I was never into gaming. The only games I have ever really played are the old school Counter strike 1.6 and runescape π
I play flight sims mostly
And tactical shooters
I have a 50W RMS amplfiier in a small-ish room
Anyways
it's maybe at 65/70% now and it's about 90 db as far as my phone can tell, mind you I don't know the accuracy of that
No worries mate, sleep well π«‘
I am on GMT time so I am heading out as well π
I'm off with the house to get desert at midnight and then when I get home I'm gonna hit the bed
What is happened with the oscp and what is oscp+?
@finite basalt I got a new RF toy, tested today - want to see in DMs? (It has my callsign, more info than I want in public)
Oscp+ = oscp that expires
absolutely mate, drop me a message π
Apparently some certs need to expire for gov work
Where is the lifetime oscp?
The regular oscp still
for now haha
maybe im blind but are there any rooms about hard link attacks?
Man I was saying that my desk was vibrating but the housemate who complimented my music taste just let me know he can feel his floor (my ceiling vibrating) haha
Hi
Hello, so the free pathway only allows 1 hour a day now? Am I forced to now pay to effectively study?
From Skidy? Yes.
The attackbox is one hour a day.
Yeah, why did you change it
good shiii costs π
Up until today, I could extend the time
The attackboxes are different from the target machines
Use the VPN and it'll be all good
Bear in mind mods aren't employees
I know it doesn't work for everyone due to geographical restrictions etc. but if you can I'd recommend setting up your own kali vm, they will usually run better and allow unlimited use
Well, with free lessons that require me to start a VM, it tells me I cannot anymore because my hour has already been used
You'll be hitting the wrong button in that case
the attackbox is limited, the target machines can be extended
That's to deploy an attack box rather than the targets


