#general

1 messages · Page 917 of 1

twin ridgeBOT
#

Gave +1 Rep to @carmine tinsel (current: #666 - 8)

carmine tinsel
#

For challenge rooms, light involves simple sql injection and SQHell involves hair tearing sql injection

whole gazelle
carmine tinsel
#

No I mean like sqli that makes me wanna tear my hair out

#

I swear I didn’t invent a new type of sqli lol

#

I got like 2/5 flags before I started raging, will come back to it this week tho

static acorn
#

🍪

#

hi cooooki

whole gazelle
#

lmao

rapid merlin
#

Morning

upper knoll
#

Super useful

#

Same with nosql map

carmine tinsel
#

lol yes I should probably do the sqlmap room instead of trying to do things manual

#

I just wanna fully understand the logic of how they work yk

upper knoll
#

No that’s a tool

#

And payload all the things has a great chat sheet

carmine tinsel
#

I see, gotta look at it

upper knoll
#

It will help a lot

#

It explains things too

carmine tinsel
#

I’m a portswigger cheat sheet user already so it will be a good addition 🙂

upper knoll
#

I love payload all the things

jolly iron
#

Hello is there a room for FUFF?

cloud quiver
jolly iron
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3678)

sturdy pike
sinful bobcat
#

Yooo fr

#

I just noticed

sturdy pike
cloud quiver
whole gazelle
#

cookie eaters!

rapid merlin
#

PHPSESSID=cookieeaters

sinful bobcat
tardy finch
#

A group of us are working to pass our pnpt. If you would like to join us. Dm me

twin ridgeBOT
#

Gave +1 Rep to @sinful bobcat (current: #492 - 12)

sick lance
#

Can't be expected to remember everything.

sturdy pike
sturdy pike
sturdy pike
slate wing
#

You sure it is good enough? I also want it for my small buisesses

#

And personal storage also

#

Practicing cybersec and system administratation too

sick lance
#

@chilly veldt You getting Sal1 via BTL1?

chilly veldt
chilly veldt
slate wing
#

Also did u manage a server before?

cloud quiver
twin ridgeBOT
#

Gave +1 Rep to @sturdy pike (current: #117 - 68)

slate wing
#

So maybe one with no noise will be great

sick lance
#

Waiting on SecOnion installing is pain.

#

I need to find a ready made image. kekw

chilly veldt
chilly veldt
rapid merlin
#

Feeling so lazy but I gotta clean up, I’m out of energy

#

Need elixir

sturdy pike
#

Metasploit machine in task 6 is just for listening? Do I need to start attackbox for it?

silver sky
sturdy pike
#

Meatexploit is hard

silver sky
#

Hello!

sturdy pike
#

How are you?

gray sonnet
#

Hex! Hai :D

rapid merlin
#

I’ll start body popping

#

No fr though I can’t drink them anymore.

#

Ironically my mum would moan a lot about them and then one day I had one and thought I was having a heart attack.

silver sky
#

Have you tried the bean brewing method?

sturdy pike
#

References going over my head, I'll just eat a cookie and black coffee instead.

compact mango
#

Good morning

sturdy pike
#

Hey hey! I understand it now, metasploit is actually easy!

rapid merlin
#

You know I used to drink coffee all day and it had no effect but now I can’t even have a sip

wet marlin
#

new day new me

upper knoll
#

Matcha is my fuel!

wooden totem
#

Matcha people don't exist

#

Same with mint ice cream

stone basin
#

I feel like Matcha is more about the experience then the drink itself.

rapid merlin
#

hello everyone

stone basin
#

hey

dreamy forge
#

hi guys

broken horizon
upper knoll
shut hawk
wooden totem
silver sky
upper knoll
#

Mb I guess I’m a bot

silver sky
upper knoll
#

Boop beep?

silver sky
#

Bot confirmed

upper knoll
sturdy pike
wooden totem
upper knoll
#

I really do not

#

I go out of my way not to eat metal

#

I do love Asian cuisine

silver sky
#

That is what a bot would say

#

A LLM

sturdy pike
#

Agree

upper knoll
#

I’ve been programmed to weeb

shut hawk
wooden totem
#

I clearly hit a defense mechanism of the bot and now it redirected itself to appear more normal by mentioning asian cuisine

upper knoll
#

Second anime I ever watched

sturdy pike
#

Same lol

#

My first was Parasyte the Maxim

upper knoll
#

Mine was Naruto

shut hawk
#

ive only watched 1 anime, guess which one?

sturdy pike
shut hawk
#

nope

whole gazelle
#

pokemon!

#

or naruto

dark mason
#

Hi chat

upper knoll
#

Wassup

dark mason
#

How is everyone?

sturdy pike
whole gazelle
dark mason
sturdy pike
#

But then I was told to skip fillers

upper knoll
shut hawk
broken horizon
sturdy pike
upper knoll
#

Pokemon was great

shut hawk
whole gazelle
broken horizon
#

its easy and u can do it later whole CPTS

sturdy pike
#

And the latest I watched

whole gazelle
twin ridgeBOT
#

Gave +1 Rep to @dark mason (current: #365 - 17)

upper knoll
#

One piece was too much for me

upper knoll
#

Watched a lot of fairy tail

#

After that I was burnt out for long anime’s

wooden totem
sturdy pike
twin ridgeBOT
#

Gave +1 Rep to @broken horizon (current: #1772 - 2)

dark mason
#

When I get home I will do my math homework and start learning steganography

sturdy pike
dark mason
#

@whole gazelle may I ask you something?

dark mason
#

I don't like ice cream that much

wooden totem
whole gazelle
dark mason
sturdy pike
whole gazelle
dark mason
#

Ah, alr

#

I wanna know if it is possible to learn the basics in 2 weeks

whole gazelle
#

sounds doable imo

dark mason
#

I am think I am going to skip crypto and pwn this year

whole gazelle
#

so what u gonna do instead?

tawdry blade
#

How can i ask to change my email on THM support

#

The bot doesn't give me the option.

silver sky
#

THM support?

tawdry blade
#

@sick lance Do you know how i can do it

silver sky
#

You mean on your account?

tawdry blade
#

Yep

#

On my THM account

#

I cannot change it

sick lance
#

Are you google

tawdry blade
#

I want to change it to outlook

upper minnow
#

Cant you just change it

tawdry blade
#

No

silver sky
#

You should be able to change it via your profile

tawdry blade
#

It doesn't want to

upper minnow
#

I remember it being pretty easy to change

tawdry blade
#

I can't

#

The box is gre

#

grey

silver sky
#

Email support then

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

tawdry blade
#

Thanks

#

@silver sky

#

See?

silver sky
#

Not really, I dunno what it normally looks like

sick lance
#

Ah, because of how you created you THM account, you can't change it, I don't even know if support can do it.

tawdry blade
#

I create it with an email

sick lance
#

Google SSO is different from a normal account creation.

tawdry blade
#

I don't remember

silver sky
#

Ahhhhhh

tawdry blade
#

Naa

#

I didn't create my account with GOOGLE SSO

sick lance
#

Then what you've been told, doesn't change.

You'll need to contact support.

near sapphire
#

but feel free to try, maybe something changed since I last asked

rapid merlin
#

Hey guys im close to completing pre security now and im heading onto cyber security 101 and I was just wondering after that what's the best thing to get into I like protecting stuff and systems and want to work for the government doing that stuff but I also like messing with things and bypassing and breaking it aswell what would be best

rapid merlin
cloud quiver
rapid merlin
#

What do you recommend is best to get into

cloud quiver
desert shuttle
#

KGB the goat

main meadow
#

i wanna try a new web browser... Arc or Zen ?

polar holly
#

Was trying to attack a sandbox system and currently falling short. It's behind a red-Node and nothing I've tried worked so far. I found various pages linked to the main IP page.

queen flare
#

what's the room tester role?

sick lance
#

Community members who help test out the rooms after they reach UAT stage.

queen flare
#

uat?

sick lance
#

User Acceptance Testing.

#

This is the final phase of THM's QA department.

queen flare
#

now what is qa department

shut hawk
sick lance
#

The Quality Assurance departmed of TryHackMe, in which timtaylor is the manager of.

shut hawk
#

✨ quality assurance ✨

sick lance
shut hawk
#

qa is to ensure it meets standards, stars are usually good standards

rapid merlin
#

What do you guys do

slate wing
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #8 - 967)

rapid merlin
#

I don't even know what to learn

blissful snow
#

hi

blissful snow
rapid merlin
blissful snow
#

I mostly do web hacking

#

I also practice or things

rapid merlin
rapid merlin
blissful snow
#

idk

#

mostly web

rapid merlin
#

You got a job?

blissful snow
#

not yet to young

main tiger
lone thistle
#

👋 hello thm

#

hope we're all having a great day so far

blissful snow
#

day*

lone thistle
#

we can all but try right 😄

oblique furnace
near sapphire
#

hey ben

near sapphire
lone thistle
cold veldt
near sapphire
blissful snow
near sapphire
#

nothing fancy really just basic oop

blissful snow
#

ooh

oblique furnace
whole gazelle
#

respect respect

hollow nebula
#

anyone know where windows ISO's could be found for use as a lab? evaluation copies are fine. i got the windows server iso running but can't get a user station running

oblique furnace
#

arch+kali+win11+sequoia

#

thinkpad t480 my beloved

#

500gb for each os

dark frost
#

Anyone know about IBM ? And the Cobol programming ?

blissful snow
sick lance
dark frost
#

What takes you back ? You in the twenties , you talk like an old man

oblique furnace
pliant onyx
#

Chat can yall review my small code

blissful snow
#

I'm not sad im just suprised

pliant onyx
#
public class Rough                        {
public static void main(String[] args)    {
System.out.println("Hello, World!")       ;
                                          }
                                          }
blissful snow
whole gazelle
pliant onyx
#

That's the sweetest thing anyone has ever said to me

whole gazelle
pliant onyx
dark frost
whole gazelle
pliant onyx
pliant onyx
#

A friend was also learning

#

His logic is incorrect though

dark frost
#

Good start

whole gazelle
blissful snow
#

the school wifi is so laggy today 😭

dark frost
blissful snow
#

nah I think the band width is just horrible

polar wraith
#

hi

polar wraith
#

how do i change my email on tryhackme

rapid merlin
#

I guess through support

silver sky
polar wraith
#

havent used sso

#

cant change it tho

cedar shuttle
tribal lion
#

hello guys

#

for somereason i can't access ssh while solving a machine

#

i tried multiple vpn files but it didn't work

polar wraith
#

what does it show

tribal lion
#

ssh just doesn't reach

polar wraith
tribal lion
#

got it

oblique furnace
#

are u on the vpn?

tribal lion
#

i am

cursive crag
pseudo egret
tribal lion
#

i did

pseudo egret
tribal lion
#

its just like a udp connection thus ssh dont connect

tribal lion
pseudo egret
tribal lion
#

yea it is

#

it was working yaster day

#

im super confused why it is not working

polar wraith
#

does it show port unreachable?

tribal lion
#

it shows that something is unreachable in the vpn connection
lemme check

lime belfry
#

just to make sure I understand right When I but the SAL1 cert it doesn't come with premium or training I have to but it separately right?

lime belfry
twin ridgeBOT
#

Gave +1 Rep to @polar wraith (current: #277 - 25)

pseudo egret
hollow nebula
tribal lion
#

any way it says this
2025-03-04 09:28:42 read UDPv4 [ENETUNREACH]: Network is unreachable (fd=3,code=101)

polar wraith
#

thats an openvpn problem

tribal lion
tribal lion
polar wraith
#

use tcp

tribal lion
#

ok how 😅

#

what i do is downlaoding the vpn file and open it using openvpn

#

@polar wraith

polar wraith
#

open the ovpn file

#

in a text editor

#

what do u see next to "proto"?

tribal lion
#

tried it

#

but the vpn didn't work

polar wraith
#

i mean

#

open the vpn file

#

using a text editor

tribal lion
#

i did
i changed it to proto tcp is this what do you mean

polar wraith
#

nano <name>.ovpn

#

ah ok

#

didnt work?

tribal lion
#

no

polar wraith
#

idk then

#

whenevr ive ssh issues i switch to tcp

rugged marsh
tribal lion
#

thx blobfingerguns

polar wraith
#

starts workin ¯_(ツ)_/¯

tribal lion
#

i will try again may it works this time

cedar shuttle
tribal lion
#

HTB is better they make a file for each protocol bashzoom

cedar shuttle
#

WHAT IS TLS RAAAHHHH 🦅 🦅 🇺🇸

hollow nebula
sick lance
sick lance
hollow nebula
#

even if i could get some old windows boxes from vulnhub but havent been able to find anything that wasn't zany

sick lance
pseudo egret
sick lance
hollow nebula
#

that's worth a try. i was even trying to follow the john hammond AD videos just to gain basic keyboard skills for normal AD activity - and all the set up is now not working via windows evaluation vms

cedar shuttle
hollow nebula
#

i mainly use oracle but i'm ambidextrous

sick lance
#

Fuck off Vbox

hollow nebula
#

Like i was just getting a hanging black screen after a successful install and reboot of my system. why did the change the logo? it look's like a new jersey surf brand now

hollow nebula
sick lance
#

Vmware is better

hollow nebula
#

"If you fail to activate this evaluation after installation, or if your evaluation period expires, the desktop background will turn black" is on the evaluation page - but i never had a chance to even activate it. so who knows. i'll do the whole thing again in vmware. i just wanna get the skills to pay the bills , and the lord is put obstacles infront of his toughest soldier

sick lance
#

Oh, that's just WIndows being WIndows, you need to get a key.

hollow nebula
#

yeah but i didnt even get to a place to fill in the key

grizzled wing
#

@sick lance got a silly question, i think i already know the answer , but, doing the SOC 1 & 2 is best way to prepare for this SAL 1 ?

grizzled wing
sick lance
#

Recommended learning tab.

grizzled wing
#

good to know

pseudo egret
#

guys ever heard of athena os ??

hollow nebula
#

zues...athena..i'm sensing a theme

obtuse star
#

Hello, i just joined this great community. my name is ijego and i am a cyber security Analyst. I am excited to be part of this great community

pseudo egret
main meadow
#

yes there is apparently, but its lightweight and has not much stuff preinstalled

red idol
#

Did anyone-by any chance- take the CI/CD security? Did that lab work for you at all?

dark mason
#

Hello everyone

rapid merlin
#

Hello there

pseudo egret
rugged kayak
#

@sick lance you have many vms, how do i optimize windows vm a bit

#

do you debloat them

#

or how do you set windows vms up in general

sick lance
#

Just set them up normally,

What do you mean optimise?

lethal pike
#

Can someone help me with something that is not exactly legal?

upper knoll
mossy river
rugged kayak
#

well i am bit scarce with resources, do you idk run some debloating scripts or something like that

lethal pike
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1511)

grizzled wing
#

so anyone that goes to the SAL 1 link will get a email saying "we've noticed you've been exploring the SAL1 certification;"
very fun

polar wraith
#

is there no rule against minimoddign anymore?

sturdy pike
#

Meterpreter

#

This metasploit hell is neverending

jolly iron
#

Hello

rough wagon
#

hello ladies and gentlemen and just wonderful people! I hope you all doing well!

shut hawk
main tiger
mystic stone
#

is the platform ok? it says my credentials are invalid even though i logged in a couple minutes ago

sturdy pike
cedar shuttle
sturdy pike
#

Should I take notes for meterpreter?

#

I don't wanna

sand trench
#

YAY YAY YAY

hollow nebula
#

i'm having a hell of time doing this. ill be ready for nmapping by midnight. just had the second blackout of electricty of the day

sand trench
#

Wallpaper of the day:

hollow nebula
#

soon as i get back to the US, i'll turn my rasppi into a windows box and attack that. that'll show'em

blazing granite
proud needle
#

kinda off topic but do yall use windows or linux?

shut hawk
#

🪟

blazing granite
sturdy pike
#

so I will

blazing granite
pliant onyx
#

One great thing about meterpreter (among many others) is the post exploit module

#

There's a post exploit vulnerability scanner that I often use

unkempt breach
rugged kayak
sturdy pike
blazing granite
# unkempt breach both 😎

I did dual boot for a while then I realise that I hadn't booted in windows for 10 month so it was a waste of space 😂

wooden totem
#

Wait hold on, I gotta check something
How many hours do yall sleep without an alarm?

hollow nebula
#

nice try diddy

blazing granite
shut hawk
#

I don't sleep with an alarm, i just let myself wake up whenever

hollow nebula
#

you guys ever seen any labs or vm's based on IT/OT systems ? or specifically medical field stuff which i guess is like It/OT/and iotot?

wooden totem
shut hawk
#

~9/10 hours

wooden totem
#

interesting

cosmic pendant
#

2 big reasons, alot of it is hardware, and licensing

#

They don't want people looking at, REing or testing their stuff

hollow nebula
#

i mean i guess alot of it could be mimick'ed with conpots and a couple windows boxes..pfsense, etc

silver sky
blazing granite
#

I don't use alarms on weekends and bank holiday, but yet again it depends on the day, some weekend I wake up at the same time of the alarm, some times earlier, and some time way after, my body is kind of crazy like me 😂

shut hawk
cosmic pendant
#

That's like saying finding a flaw in a cisco router, works on junipers almost

weak flume
hollow nebula
cosmic pendant
naive violet
cosmic pendant
#

I have a raspberry pi that's a traffic signal

naive violet
#

Some of the OT stuff is architecture at least

hollow nebula
cosmic pendant
#

that setence broke my brain

hollow nebula
cosmic pendant
hollow nebula
#

i've done a few conpots to play with protocols, but would love to do some maritime themed labs - or more realistic set ups. been learning lader logic etc.

blazing granite
cosmic pendant
#

Also MILSTD-1553

#

good read

#

There is also a boat version of that....

hollow nebula
cosmic pendant
hollow nebula
#

i'm definitely not a pro but i hav interest

hollow nebula
naive violet
#

It's OT
A lot of it is hardware

hollow nebula
#

The macyste is super interesting but i havent been able to get to working yet

#

i've messaged giacomo and russo before, they answered back. cool dudes

ancient mirage
#

i find this in every fruit drink i don't understand why... https://en.wikipedia.org/wiki/Acesulfame_potassium

Acesulfame potassium (UK: , US: AY-see-SUL-faym or ), also known as acesulfame K or Ace K, is a synthetic calorie-free sugar substitute (artificial sweetener) often marketed under the trade names Sunett and Sweet One. In the European Union, it is known under the E number (additive code) E950. It was discovered accidentally in 1967 by German ch...

#

it's always too gooddamn sweet bro

sick lance
#

SCADA hacking 🤢

hollow nebula
# naive violet It's OT A lot of it is hardware

I can immitate the bridge system easily enough - it that most maritime vessels claim air gapping in OT and IT - so unless there is a USB attack- you are left doing AIS spoofing, mitm ecdis updates, SAT and COMMS mitm

naive violet
#

Sat being satellite? Vsat etc? They're awful but should be segmented
Architecture.

hollow nebula
#

i mean i have 10 years on cargo ships - but yeah i've never had the ability to crack in and look for myself lol

hollow nebula
naive violet
#

Yeah VSAT terminals are stuck in 2007

#

Rare to find them internet exposed though, dutch gov had one a few years ago that went famous

rustic plume
#

Hi All, I submitted the survey form yesterday evening as I have btl1 , I am just wondering if people have received the voucher already for SAL1

hollow nebula
#

maritime industry is even slower than normal ics because they'll just sell a ship - and the vuln gets passed on

sick lance
hollow nebula
#

Ais spoofing ( and other vectors) are also applicable to airports and other spots. that'd be a fun box

naive violet
#

Ais ain't for planes, 'tis boats.
ADS-B for planes

#

Some interesting talks out of Defcon etc on ads-b spoofing and spoofing immunity

earnest fog
#

welp, it's official, sent resume to national guards cyberdefense unit. shrugs Also, hi everyone. have a great day.

naive violet
#

Good luck

hollow nebula
#

yes ! ads-b

cloud quiver
#

@sick lance

grim sparrowBOT
#

Done!

blissful snow
#

when you run banspam does it clear all spam with regex or do you have to put a user

dark frost
#

i love this word regex

blissful snow
#

same lol

hollow nebula
#

i have a nerd fantasy about making a framework that's a mix between recon-ng and a metasploit thats strictly for ICS systems - so you could OSINT and store it in a database- then find the structures--and lock and load the exploit or coms

blissful snow
#

what is ics again

hollow nebula
#

industrial control systems

blissful snow
#

ah

sand trench
blissful snow
#

I'm bored can someone give me an idea again

dark frost
blissful snow
#

mines are blurry and pretty bad 😭

sand trench
#

but most recently from the catppuccin discords wallpaper forum channel

blissful snow
#

ohh

blissful snow
sand trench
#

sure

blissful snow
#

thankss

dark frost
#

shadow has the best servers discord list

hollow nebula
sick lance
hollow nebula
#

like i imagine alot of it could be done via api's and it would really just be a database holding the information

sand trench
sick lance
blissful snow
sick lance
#

I'm actually working on one right now.

sick lance
rugged kayak
hollow nebula
#

well where do i start to learn about how i could make one? like i don't even know the vocabulary to search besides " framework" - which i found there are libraries for making frameworks which is awesome

sand trench
sick lance
hollow nebula
#

wait huh? i'm not looking for vulns - i'm talking about creating a shareable framework similar to recon-ng and metasploit

naive violet
sick lance
#

Er, what does Metasploit do?

#

Swiss army knife of hacking tools.

wooden totem
sick lance
#

I'd certainly easier at this point.

hollow nebula
#

like an additional module

sick lance
#

Yeah.

#

SecOnion takes too long to install.

sick lance
hollow nebula
#

i mean - recon-ng is just using the api keys like shodan etc, and holding the data. if i could input the api keys in metasploit, and have an additional room on the init_db to hold the recon'ed osint info. i mean there is already a LOOT option right?

sick lance
#

How would you deal with the devices that aren't connected publicly?

hollow nebula
#

i actually learned alot about networking setting up the visual ones..also the dude thiag alves

#

his labs and plc stuff is great. my linkedin has all the ics labs i've put together . the visual ones in ignition are fun

sick lance
hollow nebula
#

ahh i'll have to take a look. armitage always struck me as a cool idea also but i could never get it working

sick lance
#

Armitage is no longer supported.

hollow nebula
#

ahh thanks

#

have you done the free CISA ics courses? grassmarlin heavy

sick lance
#

Grassmarlin was annoying, worked when it wanted to 😂

hollow nebula
cosmic pendant
#

OHh, that's cool, I dind't know that was public

#

LOLOL

hollow nebula
#

yeah grassmarlin was no the coolest - but i like the idea of it being passive

sick lance
cosmic pendant
#

grassmarlin

sick lance
#

They usually copy alot of the Emails yeah.

hollow nebula
#

check out the phishing room

sick lance
cosmic pendant
#

No, it is 😄

blissful snow
hollow nebula
sick lance
blissful snow
#

read it again

sick lance
#

However, I don't think we should discuss how criminals commit crimes. 👀

sick lance
#

From an analysis PoV, yes. They try and immitate the E-mail as much as they can.

cedar shuttle
#

Anyone here went to WGU? Considering transferring there

dark frost
#

WGU ?

blissful snow
hollow nebula
sick lance
cedar shuttle
sick lance
#

Fortiphyd was part of my BsC. 😅

dark frost
#

What is WGU?

cedar shuttle
#

I have my GISF/GFACT maybe they’ll waive some of the courses

dark frost
sick lance
#

Gosh.

#

The last push is the worst.

dark frost
#

Hard working i see 💪

sick lance
#

Right now, as part of my project, I'm installing Sec Onion, to impliment in an ICS testbed.

dark frost
#

I have no idea what that mean

#

Good luck 😊

sick lance
#

My Uni has a test bed for a level crossing (car crossing train tracks).

cedar shuttle
#

SANS is too expensive, wgu i can apply for fafsa

dark frost
#

So you installing a secured infrastucture to monitor and control Train passing tracks ?

hollow nebula
dark frost
#

Touching some Scada ICS?

dark frost
sinful bobcat
hollow nebula
lost skiff
cedar shuttle
dark frost
#

Technology
COMPARE
Cybersecurity and Information Assurance – B.S.

VIEW DEGREE
Protect your career and earning potential with this degree.

MORE DETAILS
APPLY NOW
Time: 60% of graduates finish within 29 months.
Tuition: $4,365 per 6-month term.
Courses: 34 total courses in this program.
Certifications included in this program at no extra cost include:

Certified Cloud Security Professional (CCSP) - Associate of (ISC)2 designation
Systems Security Certified Practitioner (SSCP) - Associate of (ISC)2 designation
ITIL® Foundation Certification
CompTIA A+
CompTIA Cybersecurity Analyst Certification (CySA+)
CompTIA IT Operations Specialist
CompTIA Network+
CompTIA Network Vulnerability Assessment Professional
CompTIA Network Security Professional
CompTIA PenTest+
CompTIA Project+
CompTIA Secure Infrastructure Specialist
CompTIA Security+
CompTIA Security Analytics Professional

#

Incredible , and expensif but seem worth it

hollow nebula
#

some of those are stacked certs

eager marsh
#

For the love of god I dont care who the IRS sends, I'm not taking your cert THM

eager marsh
#

Almost all of them are anyway

tardy crater
#

Heyy, i was wondering, do you have any recommendation or know about some quality universities that have a programme in computer networks, in Europe? Something close to that or simmilair?

blissful snow
#

i forgot i could get domains like this

sturdy pike
#

Good night everyone

blissful snow
#

good night

sturdy pike
#

Don't say the word of the module I'm doing and I'll have sweet dreams

sturdy pike
blissful snow
#

waitttt

#

yay nvm

sturdy pike
blissful snow
#

😮 🫢 😋 👍

blissful snow
mellow narwhal
sturdy pike
wooden totem
#

I just realized that stars you see at night are stars

cedar shuttle
wooden totem
# cedar shuttle Impossible

I never really gave it a thought, just "yeah thats that, stars in the sky", but like no, it's cooler than that, they are stars as in giant fucking plasma balls in space light years away

cedar shuttle
wooden totem
#

and there is so many, visible, so far away, you're in the middle of the universe, empty space

cedar shuttle
#

Some people said I work in the backrooms

blissful snow
cedar shuttle
blissful snow
#

i don't actually have because I think mail.com isn't really the best

#

nah you good

#

i do have one

blissful snow
#

nice

#

the only reason i know about this is because i need a temp mail and also phishing simulation

#

yeah

half girder
#

the only reason for nice domain names i can think of is for making funny vhosts for irc bouncers

hollow nebula
hollow nebula
sick lance
twin ridgeBOT
#

Gave +1 Rep to @hollow nebula (current: #2712 - 1)

blissful snow
#

i already took it and gavef it a random password and logged out

sick lance
#

Netcat is watching me.

sand trench
blissful snow
#

lol

#

$0.00

#

its all free

sick lance
#

Don't mind me...

half girder
blissful snow
#

*cat bans everyone

sick lance
naive violet
#

Magic

languid torrent
#

Hello I had a question I am doing the course on Nmap my question is nmap is only used to see which port is open / closed or filtered?

naive violet
#

It can do vulnerability checks too

sick lance
naive violet
#

And you often use it for host discovery as well

naive violet
wooden totem
spark crown
#

Team, I used THM few months ago and have completed few learning modules but I wanted to re-do them again but as those modules are completed already, I couldn't be able to practice them again. Is there a way that THM clear the modules I did so that I can practice again.

carmine tinsel
#

You can reset your progress

spark crown
#

Great. Could you please let me know how to reset the progress

dark frost
#

When you open the module , on top they are settings

carmine tinsel
#

Click room options

spark crown
#

I see it!

#

THanks much team!

dark frost
spark crown
#

It looks like I can reset the room but not the whole module like Presecurity path or introduction to cyber security

crisp creek
#

Yep, you have to visit every room

languid torrent
#

does it list all the ports that are available on the network?

spark crown
dark frost
languid torrent
west ingot
#

So, my friends are organising a talk on pentesting tools for our juniors in my college and invited me to give a talk on that topic as a whole.
Now, I may not be very good when compared to seasonal CTF players and other pentesters but I do know quite a few things which I believe could be useful for my juniors and would give them a head start.
I would like to get a few suggestions on what to actually talk about. I’m thinking of talking about categories such as website enumeration, brute forcing through passwords, logon crackers. The target audience is people who are familiar with programming and computers but not security related topics.
So anything..? (Sorry for the message dump T_T)

dark frost
#

It map the open port for an IP you gave

#

Yes it does map all the ports if you give the right argument

#

By default only mainstream used port are tested , as it take lot of time

brittle lynx
#

Hello

#

Does anyone use vmware ?

naive violet
sick lance
languid torrent
naive violet
#

You identify services

brittle lynx
# sick lance Yes.

do u know how to connect my Kali and Windows VM on here so that they share the VPN

sick lance
naive violet
#

Which you can then interact further with

brittle lynx
naive violet
#

Without doing some dodgy NAT and routing stuff that's not very possible

dark frost
sick lance
inner goblet
#

I’m doing a room and it says “what is the user flag?” How do I see what the flag is?

sick lance
inner goblet
brittle lynx
languid torrent
sick lance
brittle lynx
blissful snow
#

if i were to go for a cret which one should i get first for offensive security

inner goblet
dark frost
sick lance
#

Attackbox != Target machine

brittle lynx
languid torrent
blissful snow
#

one a day isn't that hackthebox thing

brittle lynx
#

Are u sure that vmware doesnt have a solution to doing it ?

sick lance
dark frost
languid torrent
twin ridgeBOT
#

Gave +1 Rep to @dark frost (current: #277 - 25)

dark frost
#

Dns is the service that traduct
A domain name to an IP adresse

languid torrent
sick lance
dark frost
inner goblet
# sick lance Which room are you doing?

I forgot the name of it but it had a ip address and machine but the machine didn’t load. It only displayed “Target ip lookup” so I was very confused. I refreshed and tried the basic one.

languid torrent
sick lance
sick lance
inner goblet
sick lance
inner goblet
#

@sick lance I will do it through Kali Linux. I can set it up on the Kali I normally use? It’s just 1

sinful moon
#

Yep that's just fine

languid torrent
sinful moon
#

VMware Workstation Pro is also now free, if you can stand jumping through Broadcomm's awful website

blazing granite
brittle lynx
sinful moon
#

You don't need to, just connect with your VM

boreal scarab
#

Puts cayenne on my sandwich
Doge walks under me where some cayenne flakes fell on the ground
Doge licks it up
Doge rushes to doge's waterbowl

flat steppe
#

Hey, I recently got the voucher for the SAL1, and my skills revolving around blue team and defense are incredibly lacking compared to the red teaming side of security.

Anyone have recommendations on how i can get to the skill level needed to pass this exam by the end of the month?

languid torrent
#

and if i have understand nmap for port and gobuster for files ?

crisp creek
sinful moon
flat steppe
#

Can the SOC level 1 path and SOC simulator be completed by the deadline of the end of the month do you think?

boreal scarab
#

Spicy food is spicy

sinful moon
#

I've never had a need to run the OpenVPN connection with two VMs at the same time. Can you explain why you need this?

#

If you're on a Windows host and have a Windows and Linux VM... what the heck is the Windows VM for?

blazing granite
inner goblet
sand trench
#

but technically yes

brittle lynx
whole gazelle
#

i program computers!

crisp creek
sinful moon
flat steppe
#

thats actually pretty manageable

sinful moon
#

You probably dont' want to waste RAM running both the Windows and Linux attack VMs at the same time all the time anyways

flat steppe
#

wheres the line of people that will hire me after i pass this certification?

sinful moon
sinful moon
flat steppe
sinful moon
#

Typically the OpenVPN just werks

flat steppe
#

oh the joys of the cybersecurity job market.

whole gazelle
#

yeah

#

with bunch of other ppl who got certs

inner goblet
flat steppe
#

at least i get a chance to fill a large skill gap

sinful moon
flat steppe
#

i have been preparing for the OSCP and really neglected defense.

sinful moon
#

If it's a long bit of terminal output and successful stuff, that's a good sign

#

just leave it running

blissful snow
#

are tryhackme giving out oscp any time in the future in ctf?

#

I just read something about them doing that

sick lance
#

They might do.

#

They gave away OSCP vouchers with the red team path.

inner goblet
sinful moon
#

Oh as a give-away? That would be neat

crisp creek
#

next christmas?

sick lance
#

Blue team vouchers with their Soc 1

sinful moon
#

oh lol

blissful snow
brittle lynx
#

Does anyone know where i can get a windows 10 ISO

sick lance
sinful moon
flat steppe
#

they should give me free oscp for passing their certification and making a video on it.

sinful moon
#

not the example

sick lance
#

As a prize.

crisp creek
#

for christmas?

blissful snow
#

h ok

#

didn't know that

#

so basically im paying 14 for oscp

flat steppe
#

"How I Passed the SAL1 in 25 Days- And Got HIRED?"

blissful snow
#

?

sick lance
crisp creek
sick lance
#

I wonder what is next for THM 😉

sinful moon
#

Too busy with work to even attempt doing any of the give-aways psyDuck

but I'm glad they happen

carmine tinsel
#

Is that a hint lol

crisp creek
#

their own red certification maybe?

sinful moon
#

Yes it would stand to follow

sick lance
#

That is in the works, but not anytime soon.

sinful moon
#

We shall see

#

oh nice lol

flat steppe
crisp creek
#

it was funny, tho

languid torrent
#

SYN scans return a TCP RST packet after receiving a SYN/ACK from the server (this prevents the server from repeatedly trying to complete the request) SYN scan allows multiple people to be tested and each port to be tested only once?

crisp creek
#

didn't get it at first glance

sinful moon
#

Even with basic API knowledge it's not too hard to poke at that kinda thing

sick lance
#

Come on Rex, you've been here long enough.

carmine tinsel
#

Anyway I did nmap intro today, I keep forgetting what the switches mean lol

#

It was good to recap

sinful moon
#

My best advise is to nmap every single room, even when they don’t ask you to. Not only good habit for CTFs but yeah will get you to learn flags like the back of your hand

carmine tinsel
#

Oh yes definitely I try to do that lol

loud marlin
#

nmap all the things

wooden totem
carmine tinsel
#

Really needed that today

sinful moon
#

plus lol, every major vulnerability scanner that I know of is literally just automating nmap. Great skill for sure

#

Nessus, OpenVAS, and many many other solutions are largely just a crap ton of nmap scripts

#

We did try a vulnerability solution at work and while it had its own agent, for network stuff yeah that was also just running nmap as normal

topaz skiff
#

is there any reason not to just do the "scream at everything" nmap scan on -T4, or rather, is there any reason to be quiet / stealthy with the rooms?

sick lance
#

-T4 is fine for CTF's

sinful moon
#

There is near 0 reason on THM unless there's rate limiting, which is pretty rare on THM

cedar shuttle
sick lance
#

There is one challenge on THM where you need to not trip the alert system with nmap

sinful moon
#

but I know Muriri or however their name is spelled has done at least one rate limited room

topaz skiff
#

oh neat, looking forward to getting to that quiet challenge

sick lance
#

Muriri kekw

loud marlin
sinful moon
#

irl though, I never use -T4 and have seen even standard rate being rate limited

#

so expectations may not always match reality, obviously -T4 is loud and noisy, but who cares for most CTFs

carmine tinsel
#

-T5 for max chaos

naive violet
sinful moon
#

never in my life tried it since yeah when even nmap docs says it will break things, I believe that

carmine tinsel
#

At this point it isn’t an nmap scan, it’s a nmap assault

naive violet
#

I wouldn't scan embedded systems etc at t5

sinful moon
#

that's kinda critical tho lol

sick lance
#

I wouldn't scan anything at -T5 tbh, I'm not that impatient.

naive violet
sinful moon
#

half the reason I got a used server is for dat Dell iDRAC c:

#

Wow

carmine tinsel
#

I would do it for the lolz

inner goblet
#

Do I have to download the key inside of Kali?

carmine tinsel
#

With script kiddie switch enabled

sick lance
sinful moon
#

Presumably your Kali setup should have a stable internet connection just like your host, I will say

#

plus if this is literally a text key then you can copy and paste from host to guest VM depending on your VM software

inner goblet
# sick lance Which key?

I’m trying to do this openvpn thing and it’s saying it’s not finding a file or list of my downloads file

sinful moon
#

did you actually download it to Kali then?

inner goblet
#

I downloaded the file try hack me gave me on my actually laptop and not Kali. I downloaded openvpn on Kali and I think that’s the problem

sinful moon
#

Yes you need to download that file inside of Kali

cedar shuttle
sinful moon
#

once you do, it should just be in your Downloads, so you can simply just do these two commands

cedar shuttle
#

Can you cause damage with a botnet running t5s?

sinful moon
#
cd ~/Downloads
sudo openvpn YourUsername.opvn```
sick lance
#

We won't be disciussing botnets.

inner goblet
sick lance
#

We don't discuss illegal/unethical topics.

#

As per our community rules.

sinful moon
#

You don't have to do your THM lessons there, but you need your attack machine connected to the THM network

topaz skiff
#

how often do you have to water bottle spritz people in this discord with that rule warning Scrubz, ha

sick lance
#

Depends on the day I guess.

inner goblet
cunning zenith
sick lance
#

Yes.

cedar shuttle
#

Just making an observation mb

sick lance
sinful moon
#

There's other ways to transfer the file instead of downloading, but lets just keep it simple

cunning zenith
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3454)

cedar shuttle
sick lance
#

We don't discuss taking down botnets, using botnets etc.

inner goblet
#

It’s still saying “error to open config file”

sinful moon
#

Then you likely still don't have the correct path

sick lance
sinful moon
#

indeed would be best to continue there

blissful snow
#

dos anyone know where i couuld train for oscp

carmine belfry
blissful snow
#

im new to crets 😭

dark mason
#

Do you guys know any NoSQL tools similar to sqlmap?

carmine belfry
blissful snow
#

could you send this my dm i can't watch it atm

carmine belfry
blissful snow
#

I keep forgoting about that

#

forgeting*

blissful snow
carmine belfry
#

No problem. No I mean, you can save that link into a note or something. Copy/paste it 🙂

blissful snow
#

kk

#

for some reason i awlays lose them

#

but i think i have it this time

#

are there any speific networks that help with cret

#

or their all good for practice

carmine belfry
#

Red team capstone challenge is a bit more advanced, but it can definitely be useful to go through if you have the time

blissful snow
#

I was doing wreath i forgot what happened tho

#

also what do you think I should know before i attempt to study for oscp

carmine belfry
tribal lion
blissful snow
#

ok the only thing i need to study is active directory exploitation😃

#

last time i did it, it was pretty easy

#

do i have to be like realllly really good at them

sick lance
sinful moon
#

Mhmm, it's actually kind of sad that AD/GPO is a dying breed. Azure/Entra ID/Intune is just awful in comparison

tribal lion
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3455)

blissful snow
#

whats gpo

rapid merlin
#

It’s hella cold in here

sinful moon
blissful snow
sick lance
#

Security Onion will be the death of me.

sinful moon
#

But yeah Group Policy be how you actually apply security policies and more to AD objects

silver sky
sick lance
loud marlin
#

wrong chat

sick lance
#

I seen that typo.

loud marlin
#

=/

sick lance
#

Here all day folks.

#

Security Onion will make sure of that.

blissful snow
#

welp i have to g in 3 mins

sinful moon
#

just don't forget to hijl-lmno-p as well

#

I killed chat with my awful "joke" lol

#

but nah I was just lurking in the support channels for a bit

rapid merlin
cunning zenith
#

ive seen a lot of people in this server kinda identify tryhackme as one of their "main things", giving their user profile or whatnot. This confuses me because i was thinking this was just some educational platform, didn't realise people may get really connected to it... may i ask, as we go deeper into the game of tryhackme, what exactly is the appeal here (im still a beginner tryna figure my way through presecurity)? what makes people want to share their user profiels and collab or whatnot?

carmine tinsel
#

they are thm addicts 🤣

cunning zenith
#

but WHY 😂 what makes it so addicting--

rugged kayak
#

when you get serious and more knowledgeable you will consume every resource there is

cunning zenith
#

so what, this is like some social media platform for beginner hackers or something?

sick lance
#

The rare chance, you may actually get a job oppurtunity in this server.

#

It's very rare, but it happens.

whole yew
# rugged kayak its mostly beginners imo

"mostly beginners" is the intent of the server - it's intended to be a community where people with limited or even no IT background can begin to learn the basics and fundamentals of infosec

rugged kayak
cunning zenith
#

yeah thats what i figured, im using it for that very reason

rugged kayak
#

everyone was beginner

cunning zenith
#

just didn't see why people got so attached to it lol, kinda reminded me of a cult-like following or sum 😂

cunning zenith
rugged kayak
#

about ranks and stuff

cunning zenith
#

oh dear, talk about it 😂

cunning zenith
# rugged kayak people like to brag i guess

idk looked like a way for them to build something up for themselves because they lacked the pussh to get out of the comfort zone and build the true knowledge set required for a field liek cybersec, but then again, im probs overanalysing

#

crazy fascinating stuff how we go in expecting one thing and then come out hooked on something else

carmine tinsel
#

leveling up in thm gives me that dopamine rush until I realize just how little I know 🤣

rugged kayak
cunning zenith
rugged kayak
#

learn everyday

#

learn as much as possible

#

and try to enjoy it

cunning zenith
#

but then again, respect to people finding entertainment in something educational, def a better way to spend time

rugged kayak
#

i was doing dev before i started cysec

#

"hmm this shit is interesting"

#

and 3 months later i am preparing for CPTS

cunning zenith
rugged kayak
#

just feed your curiosity

round orbit
#

What sounds better to put on my LinkedIn?

  • SOC Analyst
  • Security Analyst
  • Security Operations Center (SOC) Analyst
  • Any others?
cunning zenith
#

meanwhile my dumbass be like what the hell is cpts, prob some big level certification or sum 😂

rugged kayak
cunning zenith
rugged kayak
#

i just try to be less dumb than i was yesterday

round orbit
#

Cyber Security Analyst?