#general
1 messages Β· Page 939 of 1
why
you put Discord on Kali? why
visual basic hasn't been used in something useful and serious for years, and even in the golden age of vb (if were one) that language never matter
was mr robot hacking in .NET ?
in xamarin
oh you found the teleporting spider gif
Yo guys how can a hacker know and get a server ip ? Like if someone will hack a company should he first hack any router to get into the company network? And then how he get to the server ip (just asking for educational purposes only π)
the hacker starts #start-here for all of the hacking knowledge
wee my laptop is back on discord π
and also for a friend for sure π
Yea... not the smartest way of sending a message like that
@grizzled wing weee just need to drag the file in to my termin befor it well work why i do not know D
drag & drop like its hot , glad you found success
allwasy good to have ppl like u all like to help other π thanx
my guess is that you were trying to update a file but did not provide the Goddess of Death and Destruction a path to update so it failed
drag & drop filled in the path for you
ya
hehe sound just like my X
solve for y
@grizzled wing you ask why discord on kali bc kali is my main os on my laptop and win is online for my 3d print
i suppose you ignored the community feedback on that Kali is meant for VM and not to be a main OS. if you are liking it as such then cool. Why not run Garuda or something cool then have Kali VM ? but anyway, 3D printing, a few people here do that
no no how can i say it in my english ish (v if i have it on my upcoming server) and on my main laptop then i have to learn what is what if you know what i meen
i understand you use Kali as main OS to learn Linux, but Linux is the same across different distributions.
- you do what you want, i just was mentioning that Kali is meant for a VM
ok..
all soo i know ther are a !"#Β€ lots of progam install 99% of thm do i not know yey i knoq that ;D but when i do THM step by step i well learn some of them soo that is how i do
||test||
test response
@sand trench hey ther all good π
well kinda tired and forgot to turn on the blue light filter on their desktop so might have screwed up sleep again
got a full 4 hours and 30 mins of sleep last night though
also reading extreme privacy 5th edition again
hey what we testin!
uhh that do not sound good
spoller cmd π

Netherlands and Norway NL flag
Danish/ Danes
ya
wood shoes
Vikings
how do i get the kali icon
i edited

Kali lincox
yeah this is gonna be hard:
that is easy
just adopt me π
that would go against the easy part
well i did try
try:
request()
except:
exit
shadow heavily regrets to inform you that their closest irl friend has used the nothing to hide argument multiple times while shadow has talked about privacy and security
that is pyton right
on serious note, that is very sad. like that really sucks to have friends who do not take your wisdom to heart, not even mull it over
nah it is PY-tan
tan()
damn i just love stay in this discord all of your nice && jokes you all jave make my day all the time
ignore that the link was huge
ahhhhhhh the PY tan makes sense now, not a trig joke
hehe π damn i do fell like the new kid
You like the way I flick my tongue or nah
http.server contains "Jokes"
π¦
ther is no plase like 127.0.0.1
π¦
ZEBRAS ARE SO COOL
zebras: the to wild horses we could not tame
like horses but better
i.e we never successfully tamed zebras and therefor never got a chance to domesticate them
where is Mage haha
yea, was in Jared Diamond's book
huh shadow got the information by searching youtube late at night
Guns germs and steel guy?
i learned it years ago in a book about why Europe dominated the world , zebra domestication was example of location of animals not helpful for farming vs europe ox etc
well said youtube late at night happened back in 2014
sooo technically known if for years too
haha ok
if i have a pdf and i like to read see it in a better way then on a brower what well i do ??
install Flathub on your machine, then find a PDF reader
new section
try using zathura

it is what shadow is using to read extreme privacy 5th edition right now
it can read most common ebook formats
not on flathub
https://github.com/pwmt/zathura
assuming you are gonna read the ebooks on linux that is
I need help my pc donβt want to charge te page of truhackme.com
requires a π₯·
me who do u know that
why you need to install flathub for a pdf reader, okular or something similar is installed with the core of the system, isn't that good enough?
I need help my pc donβt want to charge te page of truhackme.com and Iβm not verified
i was guess that other PDF readers might be of interest
i only see the pdf in the browser
It always makes me uncomfortable when a numbered thing has the number as a word, just say section 7 it's easier to remember
okular is good enough
okular wins
yeah for most people okular should work
that's because it's set by default not because you don't have a pdf reader
not everyone absorbs shadows
shadow just likes the workflow of zathura more

sry im still new π and try to learn hehe ;D
GIB GIB GIB
GO GO GO
GIB Csi navy ??
between all the soft in your linux probably is okular try it, if you don't like it you can install whatever you want, but it's not a good practice just install things willy-nilly
i have install 2 progs π on my lap
it is an alternative way to write give
yes i did
wierd
I just found that out this morning. He also loves Campbells soup can
Interesting. I love his story. He seems like someone I can actually be friends. People paint him as this very dangerous guy I think heβs misunderstood. People need to understand his message more.
I like the podcast first time hearing of him and watching it
the task bar in the butten on kali how do u lock it so i dont move the apps
tbf he is fairly dangerous but also has morals which evens out, not evil tho
he has imposter syndrome?!?!
How does one get roles here-
Never doubting myself ever again lol
Also I need help with intro to linux 2, where am I going for that-
use /verify command
okay thank you
your discord token is in your thm profile settings
Where did you get it from?
Itβs my schools cyber club
We can't help with schoolwork here sorry, best to ask someone who runs the club
No problem
Oh cool. Tech Ingredients just did what I was thinking about with microwave components.
You don't have a lot to work with there. Good luck.
welp time to head for the beds to sleep sloops to the beep boops while meep mooping
Lol l was once told by a person I know, they want to get me hired because they need more brains on legs... This was my mental image.
True but if youβre a good person you have nothing to worry about lol. He is very very cute
if i like to use my tv a monintor nr2 i have a cromecast in it what more do i need ?
This is all I was given lol
Morning
moning
Please don't help with schoolwork here π
My body has gotten used to the new timezone already
wher are we
Guangzhou China
And it's breakfast time
stop hold it im sooo hungy right
btw @chilly veldt i might need a litte hint im trying to use my cromecast on my tv but my kali see it but i cant cast on it why
Why are you trying to cast from Kali?
2 bowls, double the dishes
hehe i like my ny tidel π no im only useing kali so i can learn from it π that is why and ya i do have win but i use that for my 3d printer
Do not use Kali as a daily driver
But double the food to enjoy
i start to like kali
Are you using it as a general OS?
as main ya
Have you hardened the system?
Frequently Asked Questions (FAQ)
Due to the large number of users Kali Linux has, some questions are asked more commonly than others. To help address some of these questions, we have put together this FAQ.
If you are going to use it as a daily driver, at least follow what they say to do
Otherwise you're just asking for trouble
haha
Hello all.
I have a quick question regarding the timestamp for the βYearly activityβ functionality in the Dashboard. During the last week Iβve been trying to complete a room every day, but if I have some activity in my morning and then some other activities in the evening, those will be tracked in different days. Does somebody know what is the serverβs time zone?
THM server is in UK time
I donβt understand. Right now is 12:28am, March 12 (In UK) and I just started an attackbox, went to check the yearly activity and it is showing me the event in March 11
It makes no sense for me π₯²
Your timezone on your account is set to colombia
Yes, but I am 101% sure that I finished a room yesterday in the morning but the server tracked my activity in March 9. It is evening now in Colombia, and I wasnβt able to progress any room today until just now, but it is tracking the activity for March 11 and leaving March 10 empty
Just to be clear, Iβm not complaining, I just want to understand the timezone so I can make progress be visible every day
Your timezone should match the timezone of the country flag on your account
If you think your events aren't tracking properly, try contacting support@tryhackme.com :)
Hiiii
Hello Ive just finished the pre-security path and will now start the 101 path. What a fascinating world this is
hope you enjoy the paths~ there's a lot of fun things out there to learn
hi
all i can say as a new one the rabithole is getting bigger
and it gets deeper with time too π
ohh ya
oh yes im new to hacking too and there's so much to learnπ
Currently taking an intro course on THM & the Google one as well. Thereβs so much to learn & itβs so fascinating. Only thing I regret is not diving in sooner!!
Oh me too xD
If only child me was on the pentesting grind instead of licking windows (yes, i did that as a kid)
Tsk tsk tsk
π
Hello Tim
Try to ask these guys #cyber-and-careers π
Hello kinda new to this and know a little bit of things but im looking for either a partner to do some of these machines or someone to teach me a thing or two if anyone is interested just DM me
Hello
guys is crontab having suid set gonna help me privesc
gtfobins doesn't show but sometimes it doesn't and its still possible
Gosh dang it, can't even change the backup of the router to reflect my changes
be thankful you still connect to discord π
I'm connected to discord on my phone through VPN
Nothing touches the laptop outside of testing stuff
better safe than sorry π
finally finished that room
I was for a week there a while back π
I did a few wireshark rooms those are fun, I love wireshark
tcpdump is cooler
different uses, tcpdump is more for a quick captures and scripting, wireshark is for more detail analysis
Yup
Great job π π₯
π¦
that looks more like wireless shark π π
cant find wire emoji
i swear i read pentesting lol
there is not should, you use what you have, ssd are becoming more common nowadays so you probably have an ssd, but that doesn't mean have to, or should. Make do with what you have, that resourcefulness can make you good in the real world, because out there you have to think on your feet, 9 out of 10 thing won't go the way you planned
But I'm using my dads laptop
no problem at all
use vmware
and thm machines
ez
Won't let me download stuff on his laptop
so don't download anything just use the attack box on thm
Wireshark rooms are all free?
the basic one yes, then the more advance I think are premium
Gotcha thanks π
Gave +1 Rep to @grizzled wing (current: #38 - 242)
How do I stop my Kali from going to sleep?
@inner goblet
You can change the preferences from the power manager settings
sudo apt install galons of coffee
π
I donβt see where itβs still locking
@inner goblet
On the top right click on the battery icon or search for the power manager
xset -dpms
xset s off
It still turns off
i forgot my tmux commands
If you scroll all through left I think it changes to the never
i try to find my pwd on my mobem (hydra) and i get timeout hmm and the user / pwd on the lable do not work hehe
today was a shitty day so i couldnt do
but il grind tomorrow anyway
and i had a streak freeze
i went to campos and absolutely everything went wrong
Sad to hear that , hope that it will get better tomorrow π¦
thanks
Gave +1 Rep to @cloud quiver (current: #1 - 3871)
to hear it, or to read it? π π
can i ask abut hydra if it on my own gear i try ??
That's fine
is great
Well , yeah , you're right . To read it π
set those two sliders to 0
It should keep the computer from turning off
there is caffeine for your computer
It does thank you you
Gave +1 Rep to @quartz flame (current: #2733 - 1)
My computer automatically uninstalled it
oh no, your computer prefers tea
You mean, tee?
ha
tea, coffee, whisky depend on the situation π
/usr/share/beverages/
Hola
Need some advice on directory brute forcing
Target website seems to block automated tools like ffuf or dirb but manually checking the urls it works so the directories exist, I suspect a firewall/Waf Is blocking the tools
Tried everything but nothing
Which CTF
Best to ask in their Discord server π
I already joined the code is in robots.txt
The thing is why I couldn't see the directory during the enum
@blazing granite https://youtube.com/shorts/CAyNh0nW55o
What does it mean when I try to nmap a ip and it said all ports are in ignored state?
I would recommend typing into Google before asking here, you might just find your answer right at the top π
I did I just wanted to make sure it was really nothing I can doππ
i summited a video to a bug bounty program and didnt listen to the audio cuz i thought it wasnt recording, turns out i sent half a podcast to these people by accident
That's gotta be fun.
it wasnt a bad podcast, but i didnt know it had audio
@rapid merlin Is it alright if you ask before sending me a friend request? Thanks.
Gave +1 Rep to @west kiln (current: #2733 - 1)
π―π₯
Now that is something I could NEVER get, well, perhaps in the future, but uh..definitely not now.
one day at a time π
i love hydra when i try to use it on my modem it fuond 16 password the work ( well it say) non work
that was your isp modem?
ya
don't do that, because it doesn't belong to you belongs to the isp, so you have not auth to do things like that. It can get you in troubles
π just asked for clarification if there is compensation or not π
ohh i didt think off that thanx for the wake up call
@blazing granite IOU
@blazing granite if i buy a TP-Link Archer AX3000 router AX58 then its ok right
where can i get a account password reset link
come agin
You need a link to reset your password?
password reset link for login is broke and dont send email
yes
please and thank you
contact support then.
@alpine aurora rule of thumb is you don't own it, don't mess with it, services like internet, mail, etc. Even if you pay for it, you don't own the soft/hardware you just paying for the service
site-support... no support admins in here?
true didt think like that whit "my" modem
if this about your thm account you can contact support at support@tryhackme.com
yeah.
they taking for ever for reponse
it's not really yours the company lend you that device so you can use the service you're paying for
yeah that link is bs.
Well yeah, support is like that..
waiting all day for the reset email to come in
this has happened before ... i had to come here for reset
thanks though
they can take up 7 to 10 business days, your mail is not the only one they recived π
i know you know when u in the zone and ur brain dont think all the way π
thast freaking rediculous.
and they're only human beings.
lmfao
this discord is not for support issues, it's just for the community
automation
no worries ... i get that ... i thought maybe a admin was in here cause they aint in the site-support channel either...
no worries thanks. s
apparently you never had worked in customer service or tech support π
neither have you then. why have a password reset link and it not work
does every site hae human intervention for password reset or just thm
hello
abut tech suport like to hear some fun
stop being dumb
Sometimes things break.
dude for years that link has never worked
Actually I did for a few companies, that's why I'm telling you
ssssssshhhhhhh you dont knwo
Please behave π
2025 automate password reset for front end
Aaand I also have some experience in customer service.
gn children
@blazing granite 10 years ago i use to work for a ISP as tech sup π
alright, have good night.
@mossy river do you want to take this, if you're around?
Not rex, but I'm curious how that went? What was it like for you and how was it?
That's not a very respectful way to talk to people is it? π
And you didn't know that you don't own the device, that's weird
@mossy river apparently he got a bit angry because support didn't answer his email right away π
well easy monny online sup in windows and it was try tune it off and wait 15 sec for ther tv box or the modem
If it were me, I wouldn't get mad if support took long, different timezone and probably stumped with a lot of tickets/workload
I'd probably just forget π
see you not even gettting the point of the isssue.. lol hilarous.... the password reset link does not work it has never worked .... no response in the site-support side .... looking for admin is all i was asking for
hello. I'm thinking of getting back into ethical hacking after 3 years(i wasnt too much of a pro, just spent a bit of time on THM). I had the cyber mentor's practical ethical hacking udemy course from 2019. I was wondering if i should learn from that or one of the more recent youtube courses? or is there any other good resource for learning? thanks
try be the only one a work and a que on 150 -200 in 1 1/2h π
I could probably take it, but also might just fail.
That's pretty cool, I'm currently applying for IT support internships my college's career center offers, whilst relearning basic IT fundamentals.
some people think that their are special and the only people in this earth so they deserve an answer right away π common issue in customer service/tech support
Well , I always like to combine multiple learning resources so why not π
Meanwhile:
more than 11 billion people on the planet
i just have (internet/tv) from a danish isp soo the job ther was easy
huh.
i use to put pc togather back in the days
your injection is baseless and pointless. the fact that the link has never worked is the real issue... the fact that ya gotta get a human to reset the password is rediculouse.. if you cant see that as teh root cause then there no help
would the old one be severely outdated? or can i use most of what is taught there
Doesn't mean you can be rude to anyone in the community or support team.
back in the day? I did it last week π
no one is being rude
I did it this morning
"stop being dumb"
Check it out it won't hurt anything . Concepts usually stay the same only tools get updated from time to time π
I had internet and TV so it was actually a very easy job.
if you aint gonna read the statment and jsut resend me the reset link then yeah thats being dumb
Do you use a collapsible computer or something lmao
i have not done it in 10y
No, more like server maintenance of my own stuff. Those K80s will give you a very hard time, so...
That is being rude.
oh okay π guess imma finish that first, its just 22 hours or something
k80s = what
How is it dealing with those? I've seen em but never messed around
Give it a go π . Also THM has a plenty of free content you can check it out also .
Tesla K80s are a very old NVIDIA GPU-accelerator.
I enjoy it, putting all the pieces together and then watch it turn on and work π
Truth or not, it doesn't mean you get to be rude to anyone π
would you like me to hold there hand through it even more
me2
asked for an admin to help with password reset are you that admin
Imagine dealing with nonstop package managers, NVIDIA .run drivers, and much more, then they don't work as you scream at the screen because CUDNN isn't working anymore, go to bed, wake up in a panic knowing exactly what went wrong and then your fix finally works.
I hope you're aware that your conduct in the Discord community may result in removal from the platform @young nebula
absolute power currupts absolutly
You need to wait for report to respond to you for account-related problems.
We are unable to help you via Discord because of confidentiality and security concerns.
The half asleep eurkeas are real af tho
where is the bug report link to submit request to fix the password resset link again
ther is no THM admins here try the www i give you
so jabba aint an admin and has no power
Yeah, most say it can't be maintained and run for a long time. I've had no problems (other than well...everything,) and uh, still trying to figure out a new VBIOS for it so I can finally run it much more efficiently, as I believe that it's not just the hardware, but also the code DRIVING the hardware.
not..exactly?
That sounds like such a pain tbh lmao. Are the results at least worth the work?
@blazing granite is ther a place to try useing hydra wher its a litte bitte hader ?+
Yes.
It's worth it always.
But for me, any small victory is enough.
check the THM, I don't remember for the top of my head but it has to be a few room where you can use hydra
use the seach function
This. I swear this is the same energy that makes programming feel so rewarding
4096 CUDA cores is what I work for, and it may (or may not) be a small number, but it's my VRAM that matters to me. (24GBs)
@alpine aurora Also I'm pretty sure that there is a room that teach you how to use hydra too π
So I can run large models, and/or train very small models very fast.
Sometimes at the same time.
im abut to get mad (HackParkβ is a Premium room) is poping up all the time
time to go people! bye π€
me2
good night GNU-π¦
gn all
That's fire. Im still a complete scrub with the AI stuff but I get the concept, like you have to generate tokens for it to process the data. Is that like a way you would measure speed for ai training? Like tokens per n?
Well, actually, I don't really measure the speed of my neural networks.
And bonus tip:
Neural networks train fastest on hardware like mine when you train in batches rather than individual tensors.
But that's a bit universal..
Oooooo. What models have you been messing around with lately?
I'm assuming you're refining premade models
I've been messing around with my own models, which recently includes a chess engine that uses quantum computing.
But for premade ones, I'd have to say..GPT2, because it was much better, and open source.
But unfortunately qiskit doesn't want to work on python3.10 (i.e., the python distro my Tesla K80 works on, so..
)
Good news is that if I can figure out how to either A. reimplement kepler GPUs into Torch or B. Make my own AI framework and GPU drivers
I'd be all good to go!
What is this? Oh no, you hacked my virtual cam, good thing I have OBS looping this video!
anyone know how to log into any tt account w/o the psw?
You can't, the service's authentication function requires a valid username and password to be able to access the account.
oh ok
..... xoxoxo hydra for the W
lol
just for future reference it is extremly rude to tell some one to use the link that they just said was broken.... I do apologize to you for calling you dumb that was also extremly rude i realize you was only trying to help. 12hrs later no response no reset link is horrible customer service ... the link has not worked since 2023 the last time i had to reset my passwd. xoxoxo please forgive my rudeness that extended from my frustration..... have a wonderful evening!
Customers service is not open 24/7 π
It is also a message queue service, which means you are put into a queue and you will be moved back up the queue if you keep on updating the ticket.
Dude, this is the app I was able to create using AI "https://7e4a9afe-474a-4ec6-b81d-ea67861341b1-00-2rx23x01mjch.janeway.replit.dev/".
software engineers are fckd?
anyone up to give it a try? tell me how it is?
some feedback?
Not really
It looks really nice and it pretty surprisingly if you only copied and pasted from AI
However, I just uploaded a picture of John Pork without even needing to mess with the request π€£
AI has a long way to go to replace software engineers lol
what did it return ?
It claimed to have processed my email perfectly fine
i meant freshers ain't getting any chance. But yeah people with decades of experience are defo needed.
ah, I think it is still impressive. It lit tool like 7-10 minutes. And the gui is soo good. The report also looks interesting. I'm lit schocked cuz i did not expect it to create this tool that easily
I think its somewhat good
You do need to fine tune the accuracy though
my email content:
(i wrote it myself for fun, of course π€£ )
lol
interesting!
Tbh, i am not good at coding. So i have no idea how i can improve it. I am still messing around with python.
Well thanks anyways!
I mean the challenge lies in the accuracy part of it, not the coding part
You need to understand data science more for getting it. Coding it in Python after that is easy
who wants to see the best thing to ever exist!
0x4C 0x8B 0xDC 0x48 0x83 0xEC 0x58 0x48 0x8B 0x84 0x24 0xA8 0x00 0x00 0x00 0x49 0x89 0x43 0xF0 0x48 0x8B 0x84 0x24 0xA0 0x00 0x00 0x00 0x49 0x89 0x43 0xE8 0x48 0x8B 0x84 0x24 0x98 0x00 0x00 0x00 0x49 0x89 0x43 0xE0 0x48 0x8B 0x84 0x24 0x90 0x00 0x00 0x00 0x49 0x89 0x43 0xD8 0x8B 0x84 0x24 0x88 0x00 0x00 0x00 0x89 0x44 0x24 0x28 0x8B 0x84 0x24 0x80 0x00 0x00 0x00 0x89 0x44 0x24 0x20 0x48 0xFF 0x15 0xE4 0x42 0x04 0x00 0x0F 0x1F 0x44 0x00 0x00 0x48 0x83 0xC4 0x58 0xC3
Ngl, this looks like a good background on a computer
...assembly instructions?
windows opcodes :(
I see
i know they are horriblel
Question: You could preconstruct an md5 dictionary where you already have a set of plain words and their respective md5 encodings and then, say, let a python function read that dictionary for quick reference, correct?
I imagine crafting a message out of a predefined set of words, encrypting them to md5, and then sending the md5 text to a recipient who uses the dictionary to quickly reconstruct the plaintext.
Yes, I believe this is what SearchThatHash does π
π
Oop. Was planning to try this out on my family the next time they try sending codes over text but I guess that work's done for me already
ei miss you all ;D
Also, I should probably ask while I'm at it: How useful is this website? https://osintframework.com/
Compared to say, maybe Owasp. Or are they tools for different purposes?
some one have the link howto connet vm to thm ?
It's all covered on https://tryhackme.com/access π
ya that is the vpn
I tried downloading this on Kalilinux, currently testing it...apparently it can't crack my md5 for "Hashbrown".
So Hashbrown does not exist in any database?
Not necessarily, just their database
Guess I'll have to check what words are available then
Cracking is by trying out combinations for each letter afaik
Isn't md5 block encryption? Not one-to-one encryption?
actually wait nvm google tells me I'm dumb since it's not encryption at all
Its not encryption yeah
its a hash function
encryption typically implies that you can decrypt the said encryption
which in this case, you cant
A question for those who are advanced or already working, I'm looking to start pentesting. Does the course provide everything necessary to get started?
for this particular hash, it takes around 15 hours on a slow gpu
maybe a couple of hours on a good one?
assuming that you're bruteforcing it
as in, from aaaaaaaaa to ZZZZZZZZZ, assuming only capital and lowercase letters
so the maximum combinations would be 52^9
which would be uh... 10,868,019,906,430,592
I mean, I put it on a VM with only 2 cores so I don't think I can get it to run on my GPU
Anyway, I think I'll just try making a toy program out of hybrid encryption since that seems more practical and actually closer to what happens in irl comms
You usually have to passthrough the GPU to your VM anyway
It's better to just crack hashes on your host machine
We usually work with alphanumeric alongside mixing the upper and lowercase so yeah, brute force decryption for hashes is probably not going to be feasible. I have a PC that might be able to pull it off but compared to it, the rest of my family runs on potatoes.
Pure bruteforce is uncommon.
Wordlists with rules is the usual way to do it. Humans aren't good at passwords.
I genuinely don't know how to get a high grade on this assignment when the word count is 2500 words and the detail they expect in the Executive Summary is almost 1000
Pt report?
It's supposed to be an incident analysis report
I wrote the entire report as a normal incident analysis and I was 2x the word count, now that I've stripped literally everything, I'm still over +10%
Strikes me as too much content for an executive summary though, by a long way
It is, however the brief has expectations for what to include in the executive summary
This
Funnily enough the executive summary also has an executive summary subheading
My course's department actually refunded part of the 2nd year due to quality issues, honestly they need to review all 3 years of content
Kinda, kinda not
Lookup tables for hashes can be made, but become wildly large long before they are useful
Rainbowtables, which are different and much more storage efficient, can also be made but they are very computationally expensive to produce and still huge
rainbow tables become even more useless when a random salt is used
Sure, though that doesnβt apply directly to his idea
oh yes π
Really the concept of using hashes to βprotectβ a message just doesnβt make much sense unfortunately
You would be effectively producing a pre-shared key of sorts, which makes the entire use of the hashing completely redundant
If both sides need a lookup table to reconstruct the messages, you could make the βciphertextβ whatever you want
It doesnβt need to be a hash at that point
DH can be useful for key generation
true
generating a shared secret etc.
swapping public keys at runtime vs hardcoding a preshared key
still need to verify them though
Kinda
DHKE relies on both sides agreeing on parameters and creating their own shared values
true
The end result is still a shared symmetric key though, so I guess thatβs relevant
@brisk pendant
Thanks
Morning
Hey, if you got no problem, can i ask where are you from?
rainbow tables, essentially, right?
slr was going over notes
No, very different
I'm basically cramming for midterms, if you can call chasing every single rabbit hole I can find "cramming"
I've gone through all the surface notes and now I'm just seeing how far I can dive with each topic
Probably going a little too far but eh, cybersec's basically a bunch of rabbit holes from the superficial dabbling I've done
Guy usually usees password of "Thunder2002" but from previous breaches you know he adds a special character so you just append a random special character to each entry in the same thunder2002 wordlist
With MFA becoming increasingly popular it seems ime more and more btuteforce is more applicable to enumeration and maybe even IoT / hardware things than say account take over
Are you the one that rises π
unfortunately 
RSA is also viable to play with, no?
enumeration?
checking if an entry exists?
gathering information on a target
There's 104 days of summer vacation
You're in your 20s like me !:]
Unfortunately I watched the show in 2014 not 2008
Oh Iβm super sorry! I apologize
Online bruteforce is very different to hash cracking anyway
Do you have faith in the reboot being good tho?
Given that Dan Povenmire is still heading it, yes
Good news
How so?
Online brute force, you're sending passwords to a server. The server limits you, and you have to worry about detection and lockout
If you have a hash, you don't have to interact with anything to crack it
You could type it out and crack it on a box that isn't networked at all, completely offline, no interaction with services
So basically, enumerating allows you to potentially learn their password, which even if it doesn't on its own grant you access, gives you something that might contribute to access?
or give an avenue of attack to some other point? (for instance, if they used the same password on another site)
(Completely novice questions but I do want to make sure I'm comprehending everything I'm running through correctly)
enumeration is not about passwords
Im a little out of context lol its 328a here
Good afternoon everyone
U guys think some coding skills necessary for hacking?
or is it enough if I can read code and understand its meaning?
It's been a while since I started coding again, but it feels so difficult to me π¦
Being able to write code is good, but being able to read code is more important imo.
There is so many tools you're going to use, and old exploits, it's useful to see where it's going wrong, it it's going wrong.
part of me does wonder how to go from working with python in a kali VM to working with C++, but I suppose most stuff worth attacking is using something like JS or PHP, or frameworks that use more high-level language (like python)
quic question
(natalia) NOPASSWD: /bin/bash this is the output of sudo -l. what does it mean? i no what NOPASSWD means in a vaccuu,m, but whta doieess it mean ewhen a name gets added to it?
it means you can run user 'natalia' with no password
yea
you can do it in /bin/bash
so.. cd bin/bash ansd then the command, or like.. write a bash script about it?
because this is still asking me for a password
try sudo /bin/bash
Sorry, user anna is not allowed to execute '/bin/bash' as root on venus.
#room-help please
Jabba i got bad news π¦
im not in a room, but will do- this kinda escalated beyond my original intent
i'm docker!
just because i want to know what im doing and want to learn this syntax- what does this do?
If it's not a TryHackMe room then it's okay here π
that worked, thanks, but im more interested in why
Gave +1 Rep to @civic egret (current: #2733 - 1)
oh taht site is going to be amazing tahnk you so much
Sudo allows you to execute something as another user. By default that's the root user but you can use the -u flag to choose another user on the system. In this case natalia
Yw!
so can anyone explain to me how to read the output of sudo -l commands? im painfully lacking
Cool website btw
bash is just the executable you are running
it's in the bin folder
What is binary exploitation?
I have to stay in China until Monday π
Do you have an example?
this, for one
i know that the last part is the commands youa re allowed to run, i awssume the second column tells you the restriction?
the first stumps me
It's the user you are allowed to run the command as
I.E. Anna, Natalia, root
Love the name, fellow ai hater
Do you like π¨π³ so far π ?
ah, thank you
Gave +1 Rep to @civic egret (current: #1793 - 2)
currently condsidering jumping into another thm room tbh
What do you need help with
I mean, I'm more or less comfortable working with C++, seeing as I take courses in gamedev in C++, it's more of a question of whether I can translate that into using it for stuff like pentesting or security
It's quite nice, really pretty
How is your experience with the community?
They stare a lot, but that's expected when a 184cm tall blonde Nordic person walks around
Lol true, how about the food?
Love the food, always has been
hi
Hello!

Hello
What's up?
nothing much just learning and practicing on THM
That's nice

Was playing RDR2 the other day and have to say that it's one of the best games I've played in a while
Agreed
Like how can you create something like this and abandon it later on
The one thing I like about china is most things are centered around 2 apps
I'd Rather Want RDR3 than GTA6 ngl
At this point I'd agree, a setting like this is a nice change of pace
i just have Delta Force & Black Hawk Down Co-op Campaign installed rn , its too tough alone sadly since its made to be played with 4 players
I don't game much so I've not played these, but I only play single player games, much better suited for me
Well, time to go, see ya
aight cya
That would have been my exact thoughts
WeChat and alipay
I had a feeling these were the apps
Ok man, I appreciate your feedback
Oh look, Nessus is giving us a vuln scan.
Yeah, alipay is used for all their payments and stuff, WeChat for everything else, sometimes also for payment
Not even DiDi?
Guys. When should i start doing challenges? I'm at authentication bypass room on the jr penetration tester path and I would like to train and apply the things I have learned so far.
But i don't know if my actual knowledge are enough
You can search for CTF's on content you've done, or finish the the path, there is CTf's dedicated to the content you've learned in them at the end.
Eeeehm what is a ctf
Why can I answer the questions in the room without reading much (I read all of it anyways)
I once watched a documentary about the market there a few years ago and a few apps were mentioned as their "daily staple" these two were in it, there were others but they're not as popular.
Swap out CTF and replace it with challenge room.
So ctf are challenges room. But where i can find the rights ones for me
I can't answer that, I don't know what you've learned etc,
I've tried dreaming room but i think it was still too advanced.
I'm at the 4th room of jr penetration tester path
Exluding intro to cybersecurity and Intro to pentesting
Then have a look at previous rooms, and see what you can do.
appreciate you FUG1511
Yeah, alipay is really a go to app, you just sit down scan a qr code at the restaurant, order and pay from there, universal, same in 7-eleven, just scan what you order and pay through app
Hi!
I had a payment issue. My payment is due since 6th March, but instead of paying monthly, I'd like to upgrade to annual directly from today! Is it possible? Or do I have to pay monthly fees first to upgrade to annual?
I mean, do you have any challenges you can recommend based on my current education?
It should have exoured by now, however you may need to reach out to support.
I do not, as I don't know what you've retained etc
Maybe search for easy rooms.
Status is active
Shall I email directly with screenshots?
I've tried the dreaming room but I was stuck at the start of the room because i didn't know how to gain the password for the user
Hi there.. who know the best school of cybersecurite in USA. Am actually doint my it formation and after i want specialize at cybersecurite cause here we are doing general formation
Screenshots won't be needed, they will see it.
Ok! What's the response time generally? Discount seems to be there only for 13 hours π
Uh, 2-5 day(s) I think.
Excluding weekend.
Help
Please be patient, somebody may or may not answer you soon, when they see it.
Okay get it thanks
Gave +1 Rep to @sick lance (current: #2 - 3503)
im pretty sure this record on osi model is beaten right?
Hey, did your payment method work? i am having the same issue while upgrading it annual subscription. what should I do, the sale is going to end after 13 hours.
Nah it didn't
It says card declined
mine too, i am trying from last 2-3 days. the fact is , it is not letting me upgrade but it is taking monthly payment on the same card.
π
Bro, I'm not even able to pay monthly here
Just checked
damn, well earned
idk how you did that
i tried my best
I love how all these people are making tea time alarm videos
And there are Americans asking if itβs true or not
Of course us Brits have a tea time alarm. How else would be know when to get our tea π
what room is this ?
Osi model.
Anyone know how to get coupons?
For what?
Monthly plan
Oh np
hey guys im having a issue in TryHackMe Active Directory Basics β Task 1 Introduction & Task 2 Windows Domains the login dosen't work
#room-help please.
thanks @sick lance !
Gave +1 Rep to @sharp citrus (current: #71 - 120)
how to know if this is still on-going and its not yet too late? π¦
Be among the first 100 to get certified and receive a limited-edition certificate package!
I think THM would put out an announcemnt
Done!
yo guys, anyone here who I can ask some questions? not mainly about hacking, but about a system32 drivers folder?
whats teh command to find executables you can run again? im trying to check for PATH
echo $PATH
What's the question?
It's a variable
no ythe otehr thing- im at the step where you check what binaries have weird paths in them
may I dm it to u?
so i need to check the list of executables, no?
No, you can ask in here.
Not quite sure what you mean, could you provide more information?
Are you trying to figure out what linked libraries the exec uses?
to do path privesc you need a non-abbsolute path in a binary, right?
so taht you can then inject your own thing in there
linux
π€
alr so I gotta be fr here: bought a cheese for a game, got a scrappy loader download etc, worked alr tho to the point where they told me to rename my "etc" folder which is located at "C:\Windows\System32\drivers" to "etc2" and delete it, then afterwards restart my computer. and I am not the brightest, but ik that restarting your computer can do a lot of damage, so I didnt restart it yet. am I fine or fxcked?
Basically whats the folder for and what damage can be done?
isnt it generally a capital-b Bad Idea to screw with your system32?
You downloaded game cheats, basically?
That is definitely odd, did you delete the folder?
yup, well I bought the key, they sent me a download link for the loader and thats where they asked me all that for
As it goes without saying, that wasn't the best idea
yeah I deleted all of it, as I said not the brightest but I couldnt make up what it could have to do with the "etc" folder
never do stuff you are not sure directly on your machine, thats what VMs are for
I believe it holds the host file
Does China block OpenVPN, I can't remember
Cause it doesn't block Mullvad as far as I know (I'm on Mullvad right now)
okay how do i describe this poath biz?
Ill just keep it deleted and hope I am fine ig lol
It blocks either just UDP or TCP
It holds more than that
I don't deny that
you find the path folder. thhen you find any unusual binaries you can run
if those binaries have nn-sbaolute paths, you put your own excecytable in the way
Hmmmmmm, I need to find a way around this for work
Are you referring to sudo -l?
i just need to find the binaries i can run
no, its some find command
Not the subject for here π
i just dont remember teh specifics
Find file ?
Find with SUID bit set?
maybe like find file priv x=u or whatever taht was
Also hosts doesnβt block just update or tcp or ups it defines dns at the first place the computer checks for dns entries
I know, just needed to hear if anyone knew what they block π
maybe?
find / -type f -perm -04000 -ls 2>/dev/null
That was in reply to Bella's message :)
China block a few things with firewalls.
Ah sorry
All good
Indeed, I have found out the hard way π€£
I could have told you that before you went. π
Not that it blocks our specific products 
@plush forge drop them OH fics
Isn't that the whole point of you going to China?
might be it, thanks?
Gave +1 Rep to @sick lance (current: #2 - 3504)
It is, to find out if they block and how to get around it for customers
i remmber it looking different though. i should really just learn the specific syntax of find better
Or take notes π
But that command should do what you need.
i did have notes but i cant find tehm
Which game cheats did you get for this sort of action?
rainbow 6 ones
Ah, so you're breaking ToS.
That's enough discussion regarding this. π
so do I expect a ban now
I can't ban you from ro6.
Hi, is SAL1 exam open book? Meaning we can use any resource we want during the exam?
nono, I meant the server
Within reason
Only if you discuss it further.
fair, thanks
Gave +1 Rep to @sick lance (current: #2 - 3505)
technically you could have a real SOC giving you the answers and no one would know
I have question guys,AFter i finish the Free roadmap What do you guys recommend me doing after it
What do you mean?
you can do whatever you want since its not proctored
As a security company, we take cheating prevention seriously. Our team of security experts has rigorously tested the exam for potential vulnerabilities and cheating opportunities, and we will continuously strengthen our defences. To protect the integrity of the certification, weβve implemented multiple safeguards, including randomized questions and scenarios, rotation strategies to minimize exposure, and strict identity verification. Our staff also conducts random spot checks to detect and deter dishonest behavior. Anyone caught cheating will have their certification revoked and be permanently banned. Our goal is to ensure that earning this certification remains a meaningful achievement, demonstrating real knowledge and readiness for the field.
Take from that what you will. π
Day 40 (i missed Day 39 but THM counted it anyway)
Contact your bank's customer support, tell them the issue and ask them to validate tryhackme. They may have blacklisted it for suspicious activity. It worked for me, my payment is done
I would prefer before completing all the free path modules, start from pre security which is not completely paid but only some modules in the path are required a subscription π
guys how can i check my total points on thm?
you probably had a streak freeze
You have it on dashboard
got it. thanks G!
Gave +1 Rep to @cloud quiver (current: #1 - 3891)
i did
Another unfortunate stabbing outside mine π Sadge
Such a bad place to be right now
Gotta get out of this hell
Thanks
Gave +1 Rep to @sick lance (current: #2 - 3506)
what info does one need to find the passphrase for an rsa private key
Why?
think it might solve aproblem im having
Canβt help until we know the ethicality
Is this for THM?
If so, please use #room-help
There is any system administration room in thm?
Have you used the search button? π
yeah I tought it my have used with another name
https://tryhackme.com/room/techsupp0rt1
This one? it's a challenge room.
Hey... Well i am exploring DW since today Morning.. Ummm.. Just casually asking if somebody know exciting on DW?
DW?
Then no, this isn't really the server for dark web chats.
Umm Alright. I was just asking if...
I know, I was only informing you that's it's not really that type of server.
π
How to get roles on this server btw?
Follow the above link, @blissful current.
do you know if THM plans on proctoring the exam in the future? if you dont mind, will you elaborate a bit on the random spot checks? thanks.
Gave +1 Rep to @sick lance (current: #2 - 3508)
Look how big heβs got
He jumped in there and was ready to pounce, I had to let him know that if he can see me, I can see him.
π
I do not.
And I can't answer about the second question, I don't know how THM catch cheaters.
Here's my miau
just reverse shell and monitor their system ig
π
guys i wanna start doing ctf but i have no idea what to do
Gorgeous
FINALLY
any tips?
i think they would have better ways of detecting cheaters
checkout this website called tryhackme
nah but like
lol they're not gonna put a revshell on your machine
the competition stuff
do you have IT knowlegde?
my advice still applies
/cybersec knowlegde?
cyber 101
THM, HTB, Pico, overthewire, pwn.college
yeah yeah
hackmyvm also.
have you done some challenge rooms on thm? those are pretty much ctfs
haha i was being completely unserious mate sorry
mostly all CTFs aren't at all like real life, and the more you do of them the better your intuition gets
iβve tried light but got confused
Also socks never lost his spots and stripes!? Can you believe it. His eyes still have a blue ring around them so who knows if it will go or not
ahaha no worries, hard to convey over text
If they did put a revshell on your machine, you'd fail the SoC exam, nevermind being caught cheating.
Don't know how you can cheat at an open book exam anyway, with the exception of having somebody else sit the exam.
Howβs your cat?
Done!
I almost banned you.
This might sound silly, but I'm currently doing a threat intel room and need to examine files but obviously dont have internet access on the attack box. What is the easiest way to get these files to my local system?
We don't suggest placing them on your host system, incase somethign goes wrong.
A menace!
How do I exam the files then π¦
^ that was to you.
Use the tools on the machine.
Wants me to use Talos, phishtool tho
Aha so is mine
One of the best non technical books i have picked up in skme time
You don't need to use phishtool, you can use Thunderbird mail client, just cancel when it asks for creds.
Heβs a nutter, he into extreme parkour
Okay ty
Gave +1 Rep to @sick lance (current: #2 - 3509)
i had registered in some Competition coz it had promotions like its a CTF event , few hrs ago I figured that maybe its a code debugging like competition or something (idek)
if you're into fantastical fiction (or is it?) you may enjoy the Vedas too. Stories of a great predeluvian war between the gods of India.
congratz on the new color
send me titles plz
Just started learning about Vedas actually
The Rigveda. I havent read it, just heard of the stories from youtube vids and such.
what time do you guys usually sleep
Night time.
https://en.wikipedia.org/wiki/Hindu_mythological_wars this might help too
Hindu mythological wars are the wars described in the Hindu texts of ancient India. These wars depicted both mortals of great prowess as well as deities and supernatural beings, often wielding supernatural weapons of great power. Hindu teachings prescribe war as the final option, to be employed only after all peaceful methods are exhausted. Part...
Thanks
Gave +1 Rep to @modest thicket (current: #292 - 23)
when im tired usually
630p - 800p central for me typically
lack of sleep is a silent killer
about 16 hours after i wake up
sorry scrubz replied to wrong post
lack of sleep kills youth before they are ever even elders
used to stay up all the time
how many hours do you sleep
i try to sleep 8
6 minimum but somtimes 8
get your sleep and water people the grind can wait dont cook
around 3am (Engg student lyf)
fun fact: polyphasic sleep cycles may be the meta sleep cycle. they say leonardo da vinci and Nikola Tesla slept like this. its sleeping in 4hr intervals
heard if this but did they really ? Was there documentation for this intheir writings?
not sure.. good question
i also read somewhere that irregular sleep cycles were common for much of human history. wake up at midnight to stoke fire, check on animals, etc. not sure if its bs.. just something that was interesting to me.
Windows:
Why can't I set a new password via
net user <USER> <NEWPASSWORD> as NT Authority/SYSTEM on my home PC windows 11? This works in THM-Lab on a IIS-Server. But in the real life test with Win11 I get Error 8646.
I've already searched for it, but I can't find anything more than βLocal system can't do everythingβ, or I'm too stupid to search. I thougth Local System can do anything.
I think it is important to meditate or to pray as well but is not necessary
I believe it
Is this your own computer?
I think the thm lab is win10 right?
yes
thm: IIS-Server






