#general

1 messages Β· Page 939 of 1

grizzled wing
#

sudo apt install

knotty fern
#

why

grizzled wing
#

you put Discord on Kali? why

blazing granite
# knotty fern why

visual basic hasn't been used in something useful and serious for years, and even in the golden age of vb (if were one) that language never matter

grizzled wing
#

was mr robot hacking in .NET ?

knotty fern
high mulch
#

fuuuucccc, this always gets me

sand trench
#

oh you found the teleporting spider gif

ashen sorrel
#

Yo guys how can a hacker know and get a server ip ? Like if someone will hack a company should he first hack any router to get into the company network? And then how he get to the server ip (just asking for educational purposes only πŸ™ˆ)

grizzled wing
alpine aurora
#

wee my laptop is back on discord πŸ˜„

blazing granite
dawn grove
#

Yea... not the smartest way of sending a message like that

alpine aurora
#

@grizzled wing weee just need to drag the file in to my termin befor it well work why i do not know D

grizzled wing
alpine aurora
grizzled wing
#

my guess is that you were trying to update a file but did not provide the Goddess of Death and Destruction a path to update so it failed

#

drag & drop filled in the path for you

grizzled wing
#

now you know

#

give Kali a path for her destruction

alpine aurora
grizzled wing
#

solve for y

alpine aurora
#

@grizzled wing you ask why discord on kali bc kali is my main os on my laptop and win is online for my 3d print

grizzled wing
alpine aurora
grizzled wing
alpine aurora
#

ok..

#

all soo i know ther are a !"#Β€ lots of progam install 99% of thm do i not know yey i knoq that ;D but when i do THM step by step i well learn some of them soo that is how i do

#

||test||

sand trench
#

test response

alpine aurora
#

@sand trench hey ther all good πŸ˜„

sand trench
#

well kinda tired and forgot to turn on the blue light filter on their desktop so might have screwed up sleep again

#

got a full 4 hours and 30 mins of sleep last night though

#

also reading extreme privacy 5th edition again

whole gazelle
alpine aurora
#

uhh that do not sound good

alpine aurora
grizzled wing
alpine aurora
#

no damn

#

how do i get kali on my

grizzled wing
#

Netherlands and Norway NL flag

alpine aurora
#

1-0

#

denish

#

danish

grizzled wing
#

Danish/ Danes

alpine aurora
#

ya

grizzled wing
#

wood shoes

alpine aurora
#

im hafe nl / dk

#

lol'

sand trench
#

πŸ‡³πŸ‡΄

#

^ this is norways flag

grizzled wing
#

Vikings

alpine aurora
#

how do i get the kali icon

grizzled wing
#

i edited

alpine aurora
#

kali hehe

#

you made it your self

grizzled wing
carmine tinsel
#

Kali lincox

sand trench
#

yeah this is gonna be hard:

grizzled wing
alpine aurora
grizzled wing
#

that would go against the easy part

alpine aurora
#

well i did try

grizzled wing
#
try:
   request()
except:
   exit
sand trench
# grizzled wing that is easy

shadow heavily regrets to inform you that their closest irl friend has used the nothing to hide argument multiple times while shadow has talked about privacy and security

alpine aurora
grizzled wing
sand trench
grizzled wing
#

tan()

alpine aurora
sand trench
#

ignore that the link was huge

grizzled wing
#

wow that was long string

#

the python hair clip πŸ”₯

sand trench
#

it is the animfied mascoot of python

#

also known as PY-tan

grizzled wing
#

ahhhhhhh the PY tan makes sense now, not a trig joke

alpine aurora
#

hehe πŸ˜„ damn i do fell like the new kid

carmine tinsel
grizzled wing
#

http.server contains "Jokes"

whole gazelle
#

πŸ¦“

alpine aurora
#

ther is no plase like 127.0.0.1

grizzled wing
#

πŸ¦“

whole gazelle
#

ZEBRAS ARE SO COOL

sand trench
#

zebras: the to wild horses we could not tame

whole gazelle
#

like horses but better

sand trench
#

i.e we never successfully tamed zebras and therefor never got a chance to domesticate them

grizzled wing
#

where is Mage haha

grizzled wing
sand trench
#

huh shadow got the information by searching youtube late at night

carmine tinsel
#

Guns germs and steel guy?

grizzled wing
sand trench
#

well said youtube late at night happened back in 2014

#

sooo technically known if for years too

grizzled wing
#

haha ok

alpine aurora
#

if i have a pdf and i like to read see it in a better way then on a brower what well i do ??

grizzled wing
#

install Flathub on your machine, then find a PDF reader

sand trench
#

new section

grizzled wing
sand trench
#

it is what shadow is using to read extreme privacy 5th edition right now

#

it can read most common ebook formats

grizzled wing
sand trench
#

assuming you are gonna read the ebooks on linux that is

empty dust
#

I need help my pc don’t want to charge te page of truhackme.com

grizzled wing
#

requires a πŸ₯·

alpine aurora
blazing granite
empty dust
#

I need help my pc don’t want to charge te page of truhackme.com and I’m not verified

grizzled wing
alpine aurora
wooden totem
# sand trench new section

It always makes me uncomfortable when a numbered thing has the number as a word, just say section 7 it's easier to remember

desert shuttle
#

okular is good enough

grizzled wing
#

okular wins

sand trench
#

yeah for most people okular should work

blazing granite
grizzled wing
#

not everyone absorbs shadows

sand trench
#

shadow just likes the workflow of zathura more

alpine aurora
sand trench
#

GIB GIB GIB

desert shuttle
#

GO GO GO

alpine aurora
#

GIB Csi navy ??

blazing granite
alpine aurora
#

i have install 2 progs πŸ˜„ on my lap

sand trench
#

it is an alternative way to write give

alpine aurora
#

arr

#

bbl all

eager marsh
#

My honest reaction

whole gazelle
grizzled wing
#

yes i did

umbral badge
#

wierd

inner goblet
#

I just found that out this morning. He also loves Campbells soup can

#

Interesting. I love his story. He seems like someone I can actually be friends. People paint him as this very dangerous guy I think he’s misunderstood. People need to understand his message more.

#

I like the podcast first time hearing of him and watching it

alpine aurora
#

the task bar in the butten on kali how do u lock it so i dont move the apps

wary ocean
carmine tinsel
#

he has imposter syndrome?!?!

rapid merlin
#

How does one get roles here-

carmine tinsel
#

Never doubting myself ever again lol

rapid merlin
#

Also I need help with intro to linux 2, where am I going for that-

carmine tinsel
#

use /verify command

rapid merlin
#

okay thank you

carmine tinsel
#

your discord token is in your thm profile settings

mossy river
#

Where did you get it from?

fathom turtle
mossy river
#

We can't help with schoolwork here sorry, best to ask someone who runs the club

rapid merlin
#

testing

#

okay yay

split compass
#

Oh cool. Tech Ingredients just did what I was thinking about with microwave components.

#

You don't have a lot to work with there. Good luck.

sand trench
#

welp time to head for the beds to sleep sloops to the beep boops while meep mooping

split compass
# eager marsh

Lol l was once told by a person I know, they want to get me hired because they need more brains on legs... This was my mental image.

inner goblet
alpine aurora
#

if i like to use my tv a monintor nr2 i have a cromecast in it what more do i need ?

fathom turtle
chilly veldt
#

Morning

alpine aurora
#

moning

mossy river
chilly veldt
#

My body has gotten used to the new timezone already

alpine aurora
chilly veldt
alpine aurora
chilly veldt
#

And it's breakfast time

alpine aurora
#

stop hold it im sooo hungy right

#

btw @chilly veldt i might need a litte hint im trying to use my cromecast on my tv but my kali see it but i cant cast on it why

silver sky
desert shuttle
#

2 bowls, double the dishes

alpine aurora
silver sky
#

Do not use Kali as a daily driver

chilly veldt
alpine aurora
silver sky
alpine aurora
silver sky
#

Have you hardened the system?

alpine aurora
#

i have dule boot on my lap

#

win and kali

silver sky
#

If you are going to use it as a daily driver, at least follow what they say to do

#

Otherwise you're just asking for trouble

alpine aurora
#

thanx but 1. ther is no seek optinos for spefic

#

and google do not like me

silver sky
#

I've literally linked the guide

grizzled wing
#

haha

stuck idol
#

Hello all.
I have a quick question regarding the timestamp for the β€œYearly activity” functionality in the Dashboard. During the last week I’ve been trying to complete a room every day, but if I have some activity in my morning and then some other activities in the evening, those will be tracked in different days. Does somebody know what is the server’s time zone?

grizzled wing
#

THM server is in UK time

stuck idol
#

I don’t understand. Right now is 12:28am, March 12 (In UK) and I just started an attackbox, went to check the yearly activity and it is showing me the event in March 11

#

It makes no sense for me πŸ₯²

mossy river
stuck idol
#

Yes, but I am 101% sure that I finished a room yesterday in the morning but the server tracked my activity in March 9. It is evening now in Colombia, and I wasn’t able to progress any room today until just now, but it is tracking the activity for March 11 and leaving March 10 empty

#

Just to be clear, I’m not complaining, I just want to understand the timezone so I can make progress be visible every day

mossy river
#

Your timezone should match the timezone of the country flag on your account

glacial pine
#

Hiiii

sullen flame
#

Hello Ive just finished the pre-security path and will now start the 101 path. What a fascinating world this is

topaz skiff
#

hope you enjoy the paths~ there's a lot of fun things out there to learn

tawdry orchid
#

hi

alpine aurora
blazing granite
alpine aurora
carmine tinsel
#

oh yes im new to hacking too and there's so much to learn😍

drowsy dust
#

Life

#

Okay back to life

alpine aurora
#

what ever task i try i have to pay 😦

#

are ther it is

craggy tinsel
#

Currently taking an intro course on THM & the Google one as well. There’s so much to learn & it’s so fascinating. Only thing I regret is not diving in sooner!!

carmine tinsel
#

Oh me too xD

#

If only child me was on the pentesting grind instead of licking windows (yes, i did that as a kid)

crude stump
#

Tsk tsk tsk

umbral bay
#

πŸ‘‹

crude stump
cloud quiver
idle wharf
#

Hello kinda new to this and know a little bit of things but im looking for either a partner to do some of these machines or someone to teach me a thing or two if anyone is interested just DM me

wild mist
#

Hello

frosty thunder
#

guys is crontab having suid set gonna help me privesc

#

gtfobins doesn't show but sometimes it doesn't and its still possible

chilly veldt
#

Gosh dang it, can't even change the backup of the router to reflect my changes

blazing granite
chilly veldt
#

Nothing touches the laptop outside of testing stuff

blazing granite
grizzled wing
#

finally finished that room

blazing granite
#

I was for a week there a while back πŸ™‚

blazing granite
frosty thunder
blazing granite
chilly veldt
cloud quiver
carmine tinsel
#

🦈

blazing granite
carmine tinsel
#

cant find wire emoji

fading ermine
#

Should I use a ssd for protesting

#

Pentesting

devout condor
#

why not?

#

sure

devout condor
blazing granite
# fading ermine Should I use a ssd for protesting

there is not should, you use what you have, ssd are becoming more common nowadays so you probably have an ssd, but that doesn't mean have to, or should. Make do with what you have, that resourcefulness can make you good in the real world, because out there you have to think on your feet, 9 out of 10 thing won't go the way you planned

devout condor
#

TLDR: yes, or whatever

#

xD

fading ermine
#

But I'm using my dads laptop

devout condor
#

use vmware

#

and thm machines

#

ez

fading ermine
#

Won't let me download stuff on his laptop

devout condor
#

so use THM machines

#

u dont need to download anything

blazing granite
grizzled wing
#

THM has browser based VM machines, i use them

#

no reason to not hack and learn

quartz flame
grizzled wing
#

not all

#

you can filter for subscription or free rooms

blazing granite
quartz flame
twin ridgeBOT
#

Gave +1 Rep to @grizzled wing (current: #38 - 242)

inner goblet
#

How do I stop my Kali from going to sleep?

quartz flame
#

@inner goblet

You can change the preferences from the power manager settings

blazing granite
#

πŸ˜›

inner goblet
quartz flame
#

@inner goblet

On the top right click on the battery icon or search for the power manager

elder peak
grizzled wing
#

i forgot my tmux commands

quartz flame
alpine aurora
#

i try to find my pwd on my mobem (hydra) and i get timeout hmm and the user / pwd on the lable do not work hehe

oblique furnace
#

today was a shitty day so i couldnt do

#

but il grind tomorrow anyway

#

and i had a streak freeze

#

i went to campos and absolutely everything went wrong

cloud quiver
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3871)

blazing granite
alpine aurora
#

can i ask abut hydra if it on my own gear i try ??

mossy river
#

That's fine

grizzled wing
#

hydra is great

cloud quiver
steady pewter
#

It should keep the computer from turning off

grizzled wing
#

there is caffeine for your computer

inner goblet
twin ridgeBOT
#

Gave +1 Rep to @quartz flame (current: #2733 - 1)

steady pewter
grizzled wing
steady pewter
grizzled wing
#

ha

blazing granite
grizzled wing
#

/usr/share/beverages/

wintry flower
#

Hola

#

Need some advice on directory brute forcing

#

Target website seems to block automated tools like ffuf or dirb but manually checking the urls it works so the directories exist, I suspect a firewall/Waf Is blocking the tools

#

Tried everything but nothing

mossy river
#

Which CTF

wintry flower
#

Urchinsec out of thm

#

Any tips to bypass protection or alternative methods

mossy river
wintry flower
#

Yeah

#

To join it needs registration code which you need to enum the web to get it

mossy river
#

Best to ask in their Discord server πŸ™‚

wintry flower
#

The thing is why I couldn't see the directory during the enum

inner goblet
#

What does it mean when I try to nmap a ip and it said all ports are in ignored state?

mossy river
#

I would recommend typing into Google before asking here, you might just find your answer right at the top πŸ˜„

inner goblet
wary ocean
#

i summited a video to a bug bounty program and didnt listen to the audio cuz i thought it wasnt recording, turns out i sent half a podcast to these people by accident

wary ocean
#

it wasnt a bad podcast, but i didnt know it had audio

steady pewter
#

@rapid merlin Is it alright if you ask before sending me a friend request? Thanks.

twin ridgeBOT
#

Gave +1 Rep to @west kiln (current: #2733 - 1)

steady pewter
#

damn it.

#

not again.

wheat hare
#

πŸ’―πŸ”₯

steady pewter
alpine aurora
#

i love hydra when i try to use it on my modem it fuond 16 password the work ( well it say) non work

alpine aurora
torn spindle
#

did support read an email?

blazing granite
# alpine aurora ya

don't do that, because it doesn't belong to you belongs to the isp, so you have not auth to do things like that. It can get you in troubles

torn spindle
#

πŸ’€ just asked for clarification if there is compensation or not πŸ’€

alpine aurora
#

@blazing granite IOU

#

@blazing granite if i buy a TP-Link Archer AX3000 router AX58 then its ok right

young nebula
#

where can i get a account password reset link

alpine aurora
fallen remnant
young nebula
#

password reset link for login is broke and dont send email

#

yes

#

please and thank you

steady pewter
#

contact support then.

blazing granite
#

@alpine aurora rule of thumb is you don't own it, don't mess with it, services like internet, mail, etc. Even if you pay for it, you don't own the soft/hardware you just paying for the service

young nebula
#

site-support... no support admins in here?

alpine aurora
blazing granite
steady pewter
#

yeah.

young nebula
#

rgr

#

thx

alpine aurora
young nebula
#

they taking for ever for reponse

blazing granite
young nebula
#

yeah that link is bs.

steady pewter
young nebula
#

waiting all day for the reset email to come in

#

this has happened before ... i had to come here for reset

#

thanks though

blazing granite
alpine aurora
young nebula
#

thast freaking rediculous.

steady pewter
#

and they're only human beings.

young nebula
#

lmfao

blazing granite
young nebula
#

automation

#

no worries ... i get that ... i thought maybe a admin was in here cause they aint in the site-support channel either...

#

no worries thanks. s

blazing granite
young nebula
#

neither have you then. why have a password reset link and it not work

#

does every site hae human intervention for password reset or just thm

#

hello

alpine aurora
young nebula
#

stop being dumb

steady pewter
#

Sometimes things break.

young nebula
#

dude for years that link has never worked

blazing granite
young nebula
#

ssssssshhhhhhh you dont knwo

cloud quiver
young nebula
#

2025 automate password reset for front end

steady pewter
young nebula
#

gn children

alpine aurora
#

@blazing granite 10 years ago i use to work for a ISP as tech sup πŸ˜„

steady pewter
blazing granite
celest dirge
mossy river
blazing granite
#

@mossy river apparently he got a bit angry because support didn't answer his email right away πŸ™‚

alpine aurora
celest dirge
#

If it were me, I wouldn't get mad if support took long, different timezone and probably stumped with a lot of tickets/workload

steady pewter
young nebula
#

see you not even gettting the point of the isssue.. lol hilarous.... the password reset link does not work it has never worked .... no response in the site-support side .... looking for admin is all i was asking for

haughty snow
#

hello. I'm thinking of getting back into ethical hacking after 3 years(i wasnt too much of a pro, just spent a bit of time on THM). I had the cyber mentor's practical ethical hacking udemy course from 2019. I was wondering if i should learn from that or one of the more recent youtube courses? or is there any other good resource for learning? thanks

alpine aurora
steady pewter
celest dirge
blazing granite
cloud quiver
steady pewter
alpine aurora
#

i just have (internet/tv) from a danish isp soo the job ther was easy

alpine aurora
#

i use to put pc togather back in the days

young nebula
#

your injection is baseless and pointless. the fact that the link has never worked is the real issue... the fact that ya gotta get a human to reset the password is rediculouse.. if you cant see that as teh root cause then there no help

haughty snow
mossy river
blazing granite
young nebula
#

no one is being rude

steady pewter
mossy river
cloud quiver
alpine aurora
young nebula
#

if you aint gonna read the statment and jsut resend me the reset link then yeah thats being dumb

sand mason
alpine aurora
steady pewter
haughty snow
sand mason
young nebula
#

no that is speaking the truth

#

plainly

cloud quiver
steady pewter
blazing granite
mossy river
young nebula
#

would you like me to hold there hand through it even more

young nebula
#

asked for an admin to help with password reset are you that admin

steady pewter
mossy river
#

I hope you're aware that your conduct in the Discord community may result in removal from the platform @young nebula

young nebula
#

absolute power currupts absolutly

mossy river
#

You need to wait for report to respond to you for account-related problems.
We are unable to help you via Discord because of confidentiality and security concerns.

sand mason
young nebula
#

where is the bug report link to submit request to fix the password resset link again

alpine aurora
young nebula
#

so jabba aint an admin and has no power

steady pewter
# sand mason The half asleep eurkeas are real af tho

Yeah, most say it can't be maintained and run for a long time. I've had no problems (other than well...everything,) and uh, still trying to figure out a new VBIOS for it so I can finally run it much more efficiently, as I believe that it's not just the hardware, but also the code DRIVING the hardware.

steady pewter
sand mason
alpine aurora
#

@blazing granite is ther a place to try useing hydra wher its a litte bitte hader ?+

steady pewter
#

It's worth it always.

#

But for me, any small victory is enough.

blazing granite
#

use the seach function

sand mason
steady pewter
#

4096 CUDA cores is what I work for, and it may (or may not) be a small number, but it's my VRAM that matters to me. (24GBs)

blazing granite
#

@alpine aurora Also I'm pretty sure that there is a room that teach you how to use hydra too πŸ™‚

steady pewter
#

So I can run large models, and/or train very small models very fast.

#

Sometimes at the same time.

alpine aurora
#

im abut to get mad (HackPark’ is a Premium room) is poping up all the time

blazing granite
#

time to go people! bye πŸ’€

alpine aurora
#

me2

steady pewter
alpine aurora
#

gn all

sand mason
steady pewter
#

And bonus tip:
Neural networks train fastest on hardware like mine when you train in batches rather than individual tensors.

#

But that's a bit universal..

sand mason
#

I'm assuming you're refining premade models

steady pewter
#

But for premade ones, I'd have to say..GPT2, because it was much better, and open source.

steady pewter
#

But unfortunately qiskit doesn't want to work on python3.10 (i.e., the python distro my Tesla K80 works on, so.. honkpeace )

#

Good news is that if I can figure out how to either A. reimplement kepler GPUs into Torch or B. Make my own AI framework and GPU drivers
I'd be all good to go!

steady pewter
# sand mason

What is this? Oh no, you hacked my virtual cam, good thing I have OBS looping this video!

faint grove
#

anyone know how to log into any tt account w/o the psw?

mossy river
faint grove
#

oh ok

young nebula
#

..... xoxoxo hydra for the W

#

lol

#

just for future reference it is extremly rude to tell some one to use the link that they just said was broken.... I do apologize to you for calling you dumb that was also extremly rude i realize you was only trying to help. 12hrs later no response no reset link is horrible customer service ... the link has not worked since 2023 the last time i had to reset my passwd. xoxoxo please forgive my rudeness that extended from my frustration..... have a wonderful evening!

mossy river
#

Customers service is not open 24/7 πŸ™‚
It is also a message queue service, which means you are put into a queue and you will be moved back up the queue if you keep on updating the ticket.

young nebula
#

xoxoxox

#

reset link should be fixed

split plover
#

software engineers are fckd?

#

anyone up to give it a try? tell me how it is?

#

some feedback?

mossy river
#

It looks really nice and it pretty surprisingly if you only copied and pasted from AI

#

However, I just uploaded a picture of John Pork without even needing to mess with the request 🀣

mellow narwhal
#

AI has a long way to go to replace software engineers lol

mossy river
#

It claimed to have processed my email perfectly fine

split plover
split plover
mellow narwhal
#

You do need to fine tune the accuracy though

#

my email content:

#

(i wrote it myself for fun, of course 🀣 )

split plover
#

lol

#

interesting!

#

Tbh, i am not good at coding. So i have no idea how i can improve it. I am still messing around with python.

#

Well thanks anyways!

mellow narwhal
#

You need to understand data science more for getting it. Coding it in Python after that is easy

proper sable
#

who wants to see the best thing to ever exist!

#
0x4C 0x8B 0xDC 0x48 0x83 0xEC 0x58 0x48 0x8B 0x84 0x24 0xA8 0x00 0x00 0x00 0x49 0x89 0x43 0xF0 0x48 0x8B 0x84 0x24 0xA0 0x00 0x00 0x00 0x49 0x89 0x43 0xE8 0x48 0x8B 0x84 0x24 0x98 0x00 0x00 0x00 0x49 0x89 0x43 0xE0 0x48 0x8B 0x84 0x24 0x90 0x00 0x00 0x00 0x49 0x89 0x43 0xD8 0x8B 0x84 0x24 0x88 0x00 0x00 0x00 0x89 0x44 0x24 0x28 0x8B 0x84 0x24 0x80 0x00 0x00 0x00 0x89 0x44 0x24 0x20 0x48 0xFF 0x15 0xE4 0x42 0x04 0x00 0x0F 0x1F 0x44 0x00 0x00 0x48 0x83 0xC4 0x58 0xC3
chilly veldt
#

Ngl, this looks like a good background on a computer

proper sable
mellow narwhal
#

I see

proper sable
#

i know they are horriblel

muted cloak
#

Question: You could preconstruct an md5 dictionary where you already have a set of plain words and their respective md5 encodings and then, say, let a python function read that dictionary for quick reference, correct?
I imagine crafting a message out of a predefined set of words, encrypting them to md5, and then sending the md5 text to a recipient who uses the dictionary to quickly reconstruct the plaintext.

mossy river
rapid merlin
#

πŸ‘‹

mossy river
muted cloak
#

Oop. Was planning to try this out on my family the next time they try sending codes over text but I guess that work's done for me already

alpine aurora
#

ei miss you all ;D

muted cloak
#

Compared to say, maybe Owasp. Or are they tools for different purposes?

alpine aurora
#

some one have the link howto connet vm to thm ?

mossy river
alpine aurora
muted cloak
mossy river
#

It's not cracking

#

It's just looking up your hash in a database

muted cloak
#

So Hashbrown does not exist in any database?

mossy river
#

Not necessarily, just their database

muted cloak
#

Guess I'll have to check what words are available then

mellow narwhal
#

Cracking is by trying out combinations for each letter afaik

muted cloak
#

Isn't md5 block encryption? Not one-to-one encryption?

#

actually wait nvm google tells me I'm dumb since it's not encryption at all

mellow narwhal
#

Its not encryption yeah

#

its a hash function

#

encryption typically implies that you can decrypt the said encryption

#

which in this case, you cant

dawn palm
#

A question for those who are advanced or already working, I'm looking to start pentesting. Does the course provide everything necessary to get started?

mellow narwhal
#

maybe a couple of hours on a good one?

mossy river
#

Well

#

Depends on your wordlist

mellow narwhal
#

assuming that you're bruteforcing it

#

as in, from aaaaaaaaa to ZZZZZZZZZ, assuming only capital and lowercase letters

#

so the maximum combinations would be 52^9

#

which would be uh... 10,868,019,906,430,592

muted cloak
#

Anyway, I think I'll just try making a toy program out of hybrid encryption since that seems more practical and actually closer to what happens in irl comms

mossy river
#

You usually have to passthrough the GPU to your VM anyway

#

It's better to just crack hashes on your host machine

muted cloak
naive violet
mossy river
#

I genuinely don't know how to get a high grade on this assignment when the word count is 2500 words and the detail they expect in the Executive Summary is almost 1000

naive violet
#

Pt report?

mossy river
#

It's supposed to be an incident analysis report

#

I wrote the entire report as a normal incident analysis and I was 2x the word count, now that I've stripped literally everything, I'm still over +10%

naive violet
#

Strikes me as too much content for an executive summary though, by a long way

mossy river
#

It is, however the brief has expectations for what to include in the executive summary

mossy river
#

Funnily enough the executive summary also has an executive summary subheading

#

My course's department actually refunded part of the 2nd year due to quality issues, honestly they need to review all 3 years of content

polar spoke
#

Lookup tables for hashes can be made, but become wildly large long before they are useful

#

Rainbowtables, which are different and much more storage efficient, can also be made but they are very computationally expensive to produce and still huge

rapid merlin
#

rainbow tables become even more useless when a random salt is used

polar spoke
#

Sure, though that doesn’t apply directly to his idea

rapid merlin
#

oh yes πŸ‘

polar spoke
#

Really the concept of using hashes to β€œprotect” a message just doesn’t make much sense unfortunately

rapid merlin
#

I like the combo of encrypt, hash, and sign

#

even better is an AEAD

polar spoke
#

You would be effectively producing a pre-shared key of sorts, which makes the entire use of the hashing completely redundant

#

If both sides need a lookup table to reconstruct the messages, you could make the β€œciphertext” whatever you want

#

It doesn’t need to be a hash at that point

rapid merlin
#

DH can be useful for key generation

polar spoke
#

DH is for key exchange

#

Not really generation

rapid merlin
#

true

#

generating a shared secret etc.

#

swapping public keys at runtime vs hardcoding a preshared key

#

still need to verify them though

polar spoke
#

Kinda

#

DHKE relies on both sides agreeing on parameters and creating their own shared values

rapid merlin
#

true

polar spoke
#

The end result is still a shared symmetric key though, so I guess that’s relevant

brisk pendant
#

how to verify

#

where can i found my token

sharp citrusBOT
brisk pendant
#

Thanks

rapid merlin
#

Morning

pliant bronze
muted cloak
#

slr was going over notes

naive violet
muted cloak
#

I'm basically cramming for midterms, if you can call chasing every single rabbit hole I can find "cramming"

#

I've gone through all the surface notes and now I'm just seeing how far I can dive with each topic

#

Probably going a little too far but eh, cybersec's basically a bunch of rabbit holes from the superficial dabbling I've done

polar shale
# muted cloak rainbow tables, essentially, right?

Guy usually usees password of "Thunder2002" but from previous breaches you know he adds a special character so you just append a random special character to each entry in the same thunder2002 wordlist

#

With MFA becoming increasingly popular it seems ime more and more btuteforce is more applicable to enumeration and maybe even IoT / hardware things than say account take over

rapid merlin
mossy river
#

unfortunately fawaz

muted cloak
muted cloak
#

checking if an entry exists?

polar shale
wooden totem
#

There's 104 days of summer vacation

polar shale
mossy river
#

They rebooted Phineas and Ferb πŸ—£οΈ πŸ—£οΈ πŸ”₯

#

Please don't promote here

wooden totem
lavish socket
#

Oh I’m super sorry! I apologize

naive violet
naive violet
mossy river
#

Given that Dan Povenmire is still heading it, yes

naive violet
#

Good news

naive violet
# muted cloak How so?

Online brute force, you're sending passwords to a server. The server limits you, and you have to worry about detection and lockout

#

If you have a hash, you don't have to interact with anything to crack it

#

You could type it out and crack it on a box that isn't networked at all, completely offline, no interaction with services

muted cloak
#

or give an avenue of attack to some other point? (for instance, if they used the same password on another site)

#

(Completely novice questions but I do want to make sure I'm comprehending everything I'm running through correctly)

naive violet
#

enumeration is not about passwords

polar shale
mental fiber
#

Good afternoon everyone

#

U guys think some coding skills necessary for hacking?
or is it enough if I can read code and understand its meaning?
It's been a while since I started coding again, but it feels so difficult to me 😦

sick lance
muted cloak
#

part of me does wonder how to go from working with python in a kali VM to working with C++, but I suppose most stuff worth attacking is using something like JS or PHP, or frameworks that use more high-level language (like python)

mental fiber
#

Thank you for your advises!

#

Okay lol

plush forge
#

quic question

#

(natalia) NOPASSWD: /bin/bash this is the output of sudo -l. what does it mean? i no what NOPASSWD means in a vaccuu,m, but whta doieess it mean ewhen a name gets added to it?

cold veldt
#

it means you can run user 'natalia' with no password

plush forge
#

so slike.. sudo su natalia?

#

then what does the /bin/bash mean?

burnt ginkgo
#

yea

cold veldt
plush forge
#

so.. cd bin/bash ansd then the command, or like.. write a bash script about it?

plush forge
cold veldt
#

try sudo /bin/bash

plush forge
#

Sorry, user anna is not allowed to execute '/bin/bash' as root on venus.

burnt ginkgo
#

you just can login in a bash with natalia

#

without a password

civic egret
#

You can execute as Natalia not root

#

sudo -u natalia /bin/bash

mossy river
chilly veldt
#

Jabba i got bad news 😦

plush forge
whole gazelle
#

i'm docker!

plush forge
mossy river
#

If it's not a TryHackMe room then it's okay here πŸ˜„

plush forge
twin ridgeBOT
#

Gave +1 Rep to @civic egret (current: #2733 - 1)

plush forge
civic egret
mossy river
#

Yw!

plush forge
#

so can anyone explain to me how to read the output of sudo -l commands? im painfully lacking

civic egret
#

Cool website btw

#

bash is just the executable you are running

#

it's in the bin folder

cursive coral
#

What is binary exploitation?

chilly veldt
#

I have to stay in China until Monday πŸ˜…

plush forge
#

i know that the last part is the commands youa re allowed to run, i awssume the second column tells you the restriction?

#

the first stumps me

civic egret
#

I.E. Anna, Natalia, root

topaz topaz
cloud quiver
plush forge
twin ridgeBOT
#

Gave +1 Rep to @civic egret (current: #1793 - 2)

harsh surge
#

What's up chooms! Happy Hacking!

plush forge
#

currently condsidering jumping into another thm room tbh

mossy river
#

What do you need help with

wide relic
#

research purpose

#

accessing the right market

mossy river
#

We can't help you with that here I'm afriad.

#

Please don't promote here @wide relic

muted cloak
#

I mean, I'm more or less comfortable working with C++, seeing as I take courses in gamedev in C++, it's more of a question of whether I can translate that into using it for stuff like pentesting or security

chilly veldt
topaz topaz
chilly veldt
#

They stare a lot, but that's expected when a 184cm tall blonde Nordic person walks around

topaz topaz
#

Lol true, how about the food?

chilly veldt
#

Love the food, always has been

blissful current
#

hi

sick lance
#

Hello!

blissful current
blissful current
placid idol
#

Yes, just like that

#

Hello

blissful current
#

Hello

placid idol
#

What's up?

blissful current
#

nothing much just learning and practicing on THM

placid idol
#

That's nice

blissful current
placid idol
#

Was playing RDR2 the other day and have to say that it's one of the best games I've played in a while

blissful current
#

Agreed

placid idol
#

Like how can you create something like this and abandon it later on

chilly veldt
#

The one thing I like about china is most things are centered around 2 apps

blissful current
#

I'd Rather Want RDR3 than GTA6 ngl

placid idol
#

At this point I'd agree, a setting like this is a nice change of pace

blissful current
#

i just have Delta Force & Black Hawk Down Co-op Campaign installed rn , its too tough alone sadly since its made to be played with 4 players

placid idol
#

I don't game much so I've not played these, but I only play single player games, much better suited for me

#

Well, time to go, see ya

blissful current
#

aight cya

rapid merlin
#

That would have been my exact thoughts

chilly veldt
#

WeChat and alipay

sturdy pike
split plover
sick lance
#

Oh look, Nessus is giving us a vuln scan.

chilly veldt
sick lance
#

Not even DiDi?

glossy jungle
#

Guys. When should i start doing challenges? I'm at authentication bypass room on the jr penetration tester path and I would like to train and apply the things I have learned so far.

#

But i don't know if my actual knowledge are enough

sick lance
glossy jungle
#

Eeeehm what is a ctf

sturdy pike
#

Why can I answer the questions in the room without reading much (I read all of it anyways)

sturdy pike
sick lance
glossy jungle
sick lance
glossy jungle
#

I've tried dreaming room but i think it was still too advanced.

glossy jungle
#

Exluding intro to cybersecurity and Intro to pentesting

sick lance
whole gazelle
chilly veldt
rapid merlin
#

Hi!
I had a payment issue. My payment is due since 6th March, but instead of paying monthly, I'd like to upgrade to annual directly from today! Is it possible? Or do I have to pay monthly fees first to upgrade to annual?

glossy jungle
#

I mean, do you have any challenges you can recommend based on my current education?

sick lance
sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

sick lance
#

Maybe search for easy rooms.

rapid merlin
glossy jungle
stray fern
#

Hi there.. who know the best school of cybersecurite in USA. Am actually doint my it formation and after i want specialize at cybersecurite cause here we are doing general formation

sick lance
rapid merlin
sick lance
#

Excluding weekend.

rapid merlin
#

Thank you!

sturdy pike
#

I just realized

#

I forgot to make notes

sick lance
# stray fern Help

Please be patient, somebody may or may not answer you soon, when they see it.

twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3503)

wise current
#

im pretty sure this record on osi model is beaten right?

molten mulch
rapid merlin
molten mulch
rapid merlin
#

Just checked

wise current
#

idk how you did that

#

i tried my bestTryFlagMe

rapid merlin
#

I love how all these people are making tea time alarm videos

#

And there are Americans asking if it’s true or not

#

Of course us Brits have a tea time alarm. How else would be know when to get our tea πŸ™„

tardy garden
sick lance
round smelt
#

Anyone know how to get coupons?

sick lance
round smelt
#

Monthly plan

sick lance
#

There is no coupons for monthly plan.

#

Only annual.

round smelt
#

Oh np

zinc ice
#

hi

#

how to connect discord with thm?

sharp citrusBOT
broken fiber
#

hey guys im having a issue in TryHackMe Active Directory Basics β€” Task 1 Introduction & Task 2 Windows Domains the login dosen't work

zinc ice
twin ridgeBOT
#

Gave +1 Rep to @sharp citrus (current: #71 - 120)

zinc ice
#

how to know if this is still on-going and its not yet too late? 😦

Be among the first 100 to get certified and receive a limited-edition certificate package!
sick lance
grim sparrowBOT
#

Done!

jade willow
#

yo guys, anyone here who I can ask some questions? not mainly about hacking, but about a system32 drivers folder?

plush forge
#

whats teh command to find executables you can run again? im trying to check for PATH

shut hawk
#

echo $PATH

shut hawk
#

It's a variable

plush forge
#

no ythe otehr thing- im at the step where you check what binaries have weird paths in them

jade willow
plush forge
#

so i need to check the list of executables, no?

sick lance
shut hawk
#

Not quite sure what you mean, could you provide more information?

#

Are you trying to figure out what linked libraries the exec uses?

plush forge
#

to do path privesc you need a non-abbsolute path in a binary, right?

#

so taht you can then inject your own thing in there

shut hawk
#

Oh right

#

On windows, correct?

plush forge
#

linux

shut hawk
#

πŸ€”

jade willow
#

alr so I gotta be fr here: bought a cheese for a game, got a scrappy loader download etc, worked alr tho to the point where they told me to rename my "etc" folder which is located at "C:\Windows\System32\drivers" to "etc2" and delete it, then afterwards restart my computer. and I am not the brightest, but ik that restarting your computer can do a lot of damage, so I didnt restart it yet. am I fine or fxcked?
Basically whats the folder for and what damage can be done?

plush forge
#

isnt it generally a capital-b Bad Idea to screw with your system32?

sick lance
shut hawk
jade willow
shut hawk
#

As it goes without saying, that wasn't the best idea

jade willow
modest charm
#

never do stuff you are not sure directly on your machine, thats what VMs are for

shut hawk
#

I believe it holds the host file

chilly veldt
#

Does China block OpenVPN, I can't remember

#

Cause it doesn't block Mullvad as far as I know (I'm on Mullvad right now)

plush forge
#

okay how do i describe this poath biz?

jade willow
shut hawk
#

It blocks either just UDP or TCP

opaque flax
shut hawk
plush forge
#

you find the path folder. thhen you find any unusual binaries you can run

#

if those binaries have nn-sbaolute paths, you put your own excecytable in the way

chilly veldt
sick lance
#

Are you referring to sudo -l?

plush forge
#

i just need to find the binaries i can run

plush forge
sick lance
plush forge
#

i just dont remember teh specifics

sick lance
#

Find file ?

shut hawk
#

Find with SUID bit set?

plush forge
#

maybe like find file priv x=u or whatever taht was

opaque flax
chilly veldt
plush forge
sick lance
#

find / -type f -perm -04000 -ls 2>/dev/null

shut hawk
sick lance
opaque flax
shut hawk
#

All good

chilly veldt
sick lance
chilly veldt
upper minnow
#

@plush forge drop them OH fics

sick lance
sick lance
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3504)

chilly veldt
plush forge
#

i remmber it looking different though. i should really just learn the specific syntax of find better

sick lance
#

But that command should do what you need.

plush forge
sick lance
jade willow
sick lance
jade willow
sick lance
median gate
#

Hi, is SAL1 exam open book? Meaning we can use any resource we want during the exam?

jade willow
sick lance
jade willow
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3505)

upper minnow
brisk pendant
#

I have question guys,AFter i finish the Free roadmap What do you guys recommend me doing after it

upper minnow
#

you can do whatever you want since its not proctored

sick lance
#

As a security company, we take cheating prevention seriously. Our team of security experts has rigorously tested the exam for potential vulnerabilities and cheating opportunities, and we will continuously strengthen our defences. To protect the integrity of the certification, we’ve implemented multiple safeguards, including randomized questions and scenarios, rotation strategies to minimize exposure, and strict identity verification. Our staff also conducts random spot checks to detect and deter dishonest behavior. Anyone caught cheating will have their certification revoked and be permanently banned. Our goal is to ensure that earning this certification remains a meaningful achievement, demonstrating real knowledge and readiness for the field.

Take from that what you will. πŸ™‚

oblique furnace
#

Day 40 (i missed Day 39 but THM counted it anyway)

rapid merlin
rapid merlin
frosty thunder
#

guys how can i check my total points on thm?

frosty thunder
cloud quiver
frosty thunder
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 3891)

oblique furnace
rapid merlin
#

Another unfortunate stabbing outside mine 😞 Sadge

#

Such a bad place to be right now

#

Gotta get out of this hell

twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3506)

plush forge
#

what info does one need to find the passphrase for an rsa private key

plush forge
#

think it might solve aproblem im having

upper knoll
#

Can’t help until we know the ethicality

sick lance
gritty hatch
#

There is any system administration room in thm?

sick lance
gritty hatch
sick lance
pliant bronze
#

Hey... Well i am exploring DW since today Morning.. Ummm.. Just casually asking if somebody know exciting on DW?

pliant bronze
#

Why my Name color has been changed.. I like Blue 😭

sick lance
pliant bronze
sick lance
blissful current
#

How to get roles on this server btw?

sharp citrusBOT
sick lance
#

Follow the above link, @blissful current.

blissful current
#

thanks

#

ah great

#

πŸ‘€ what was that

modest thicket
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3508)

rapid merlin
#

Look how big he’s got

#

He jumped in there and was ready to pounce, I had to let him know that if he can see me, I can see him.

#

πŸ˜†

sick lance
shut hawk
blissful current
modest thicket
#

πŸ˜„

frank agate
#

guys i wanna start doing ctf but i have no idea what to do

rapid merlin
shut hawk
#

FINALLY

frank agate
#

any tips?

slow cloud
shut hawk
#

checkout this website called tryhackme

frank agate
#

nah but like

shut hawk
frank agate
#

the competition stuff

slow cloud
shut hawk
#

my advice still applies

slow cloud
#

/cybersec knowlegde?

frank agate
#

i’ve done the pre security

#

and one other one

slow cloud
#

cyber 101

shut hawk
#

THM, HTB, Pico, overthewire, pwn.college

frank agate
sick lance
#

hackmyvm also.

slow cloud
#

have you done some challenge rooms on thm? those are pretty much ctfs

modest thicket
shut hawk
#

mostly all CTFs aren't at all like real life, and the more you do of them the better your intuition gets

frank agate
rapid merlin
#

Also socks never lost his spots and stripes!? Can you believe it. His eyes still have a blue ring around them so who knows if it will go or not

shut hawk
sick lance
#

If they did put a revshell on your machine, you'd fail the SoC exam, nevermind being caught cheating.

#

Don't know how you can cheat at an open book exam anyway, with the exception of having somebody else sit the exam.

slow cloud
#

scrubz

#

banish him

grim sparrowBOT
#

Done!

sick lance
dire sorrel
#

This might sound silly, but I'm currently doing a threat intel room and need to examine files but obviously dont have internet access on the attack box. What is the easiest way to get these files to my local system?

sick lance
#

A menace!

dire sorrel
#

How do I exam the files then 😦

sick lance
sick lance
dire sorrel
#

Wants me to use Talos, phishtool tho

rapid merlin
polar shale
rapid merlin
#

People have said my cat has adhd like me

#

πŸ˜†

polar shale
#

One of the best non technical books i have picked up in skme time

sick lance
rapid merlin
#

He’s a nutter, he into extreme parkour

twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3509)

blissful current
#

i had registered in some Competition coz it had promotions like its a CTF event , few hrs ago I figured that maybe its a code debugging like competition or something (idek)

modest thicket
near sapphire
polar shale
#

Just started learning about Vedas actually

modest thicket
near sapphire
#

what time do you guys usually sleep

sick lance
#

Night time.

modest thicket
twin ridgeBOT
#

Gave +1 Rep to @modest thicket (current: #292 - 23)

slow cloud
polar shale
#

lack of sleep is a silent killer

modest thicket
#

sorry scrubz replied to wrong post

polar shale
#

lack of sleep kills youth before they are ever even elders

#

used to stay up all the time

slow cloud
#

how many hours do you sleep

modest thicket
#

i try to sleep 8

polar shale
#

get your sleep and water people the grind can wait dont cook

blissful current
modest thicket
#

fun fact: polyphasic sleep cycles may be the meta sleep cycle. they say leonardo da vinci and Nikola Tesla slept like this. its sleeping in 4hr intervals

polar shale
modest thicket
#

i also read somewhere that irregular sleep cycles were common for much of human history. wake up at midnight to stoke fire, check on animals, etc. not sure if its bs.. just something that was interesting to me.

limber kelp
#

Windows:
Why can't I set a new password via
net user <USER> <NEWPASSWORD> as NT Authority/SYSTEM on my home PC windows 11? This works in THM-Lab on a IIS-Server. But in the real life test with Win11 I get Error 8646.

I've already searched for it, but I can't find anything more than β€œLocal system can't do everything”, or I'm too stupid to search. I thougth Local System can do anything.

polar shale
#

I think it is important to meditate or to pray as well but is not necessary

polar shale
limber kelp
limber kelp