#general
1 messages ยท Page 956 of 1
two moderators and jabba the admin in chat talking
and then you pop in and offer illegal services
Kek
oh, so she's the actual developer of rustscan?


They aren't the smartest in the lot
time to post this document of every credit card pin code
Depends on the scope of the test
You want to find as many bulbs as possible in a pentest, why limit yourself needlessly
A red team on the other hand usually has a very specific objective
And there, stealth is key
their*
If soc catches the scan on a pentest, then good on them
without a port scan, how do you know what ports are open
and if you don't know what ports are open, how do you decide how to attack a system?
If you're going to correct English, make sure you're correct. 
HY HOW ARE YOU?
Poke at it with a stick
i didnt knew the context i thought he was refering to people
We back in '96?
Gotta read the context, mate
okok
Cups and a string is much better, it's more secure than shouting.
English is a highly contextual language
@cosmic pendant seeks help in Rust.
Anyone solving the hackfinity on THM?!
Not all companies have in house competence
yes
I'm just wondering about it compared to Java.... I already chatgpted. But Im wondering if it's ... the next thing for me to learn.
But a pentest isn't simulating a real world attack.
I think this happens because the server cries
To be fair, you will be going much further than a simple port scan on a pentest
Yes
thanks!!
Gave +1 Rep to @slate quarry (current: #2750 - 1)
and we shouldn't do that in prod and miss results ๐
i was looking at ur github page the other day
Prod servers are fragile and susceptible
I'm sorry
i m impressed
May someone please just help me once for hackfinityโฆ๐ฅบ๐ฅบ
The only task ghost phishing(task 14)
Seems Iโm doing way more than expected
Glhfdd
same i guess we have to use macros but thsts too much
i reaally liked ur work
Buts I canโt get anywhere
Probably gonna have to mute people who give hints, yeah
Please find a team and Collab, asking for hints and help is against the rules.
why did u said i m sorry
Yup on 113 ig
Iโm sorry๐
hmm we are not on the score board any mmore
sorry
๐ฉ๐ฉhuhhhh
where is that time machine shadow saved to speed up package delivery again
It's ok,.I don't want to you banned and / or removed from the competition.
Afternoon chat!
fkewiorfgnm2480794tn9u23q9unfg
Shadow, stop typing your passwords in here.
okay

Gave +1 Rep to @mossy river (current: #6 - 1536)
Recently Attackbox's slow, is it just to me?
thisPasswordIsAReminderToNotPostYourPasswordsInFrontOfScrubz!142389
could be the influx of users using it for hackfinity
My dorm internet speed might be slow..
Okay, takes a little more but no problem
same , dorm wifi lmao
dorm wifi..pain
lmao
throtle it
even rn im on my mobile hotspot lol
its some cheap ahh router and the plan on it is even worse ...and no 5GHz
search wifi throttling
lmaooo
we got admin access to our clg's wifi admin panel
so we created an account with no restrictions and unlimited data usage
even i have the access to this wifi , half of the time i block my annoying roommate off the wifi
ahahahaha
lmao
Once dorm has slow plan, may no solution
does he know
ofcourse not , he makes too much noise pollution in the room , so , yeah deserves it , even during one important job related call i told him to be quiet , started watching reels on full volume
Probably best not to admit to crimes here
no crimes we created the cyber sec club we have permission to do these things

Permission from whom? ๐
Hey there guys. Do you think it's possible to actually have a good (monetary terms) life working as a full time bug hunter? But not for a specific company, like, for anyone on hackerone etc
Just 'little' kidding, right?
Iโd hope itโs a written signed contract
sys admin
is it a crime to block roommate off wifi
tough imo
If you donโt pay for it then yes
Why?
Temporarily! YK , like 30-40 min
better to change the usr and pass it was cisco cisco
yes
Just SUDO it
and then to live up to what you wear
write a script that deletes everything and execute that with sudo permission twice daily
Done now i waite for it
Even if it was default, itโs still unauthorised access
(Might be wrong its just my personal opinion, if someone wants to correct, may do pls) i mean will depend on skills , many are already doing and the CVEs (IF there are any) get found easily by the ones who dont touch the grass , so gotta find out absolutely new vulns
Or perhaps be the first one to find it
thats why it tough to make bug hunting on H1 or BugCrowd as main Income source imo
but definitely go try
a trick do auth verification with 2 devices works every time
๐
yea login in 2 devices with same id
end 1 session
and look if other session gets terminated
mostly not
hmm...interesting
i'm being slow with this cybercapa tutorial room cause of how many charts there are
making notes is gonna be a hell of a work

my brain has been fried from the trash college , imagine being taught Biology, Environmental studies , History, and 5-6 more useless stuff to Comp Science Stream Students rather than focusing on real important stuff
but that's your personal experience too?
There's no way to change ur major?
kinda , i tried to find some CVEs on both the platforms , but many possible CVEs are either patched or found
well i survived 4 yrs already its my last sem anyways
Well done bro
๐ซก 
I'm CS major but in my univ there is Cybersecurity major
even the people in my college are like sheeps bro like , everyone just do Web dev ..like come on
should major that from first
Who is playing the Hackfinity CTF ??
Same here...!
meanwhile my college has tons of streams but the students are taught outdated and irrelevant stuff , imagine Cyber branch students as well having Web Dev projects on their profiles ๐คก
Web dev..future client. the more, the better
I mean, thatโs part of being a well rounded person, learning about the world beyond computer stuff 
cant deny that either , business for us

true but making Comp science student and focusing more on that than actual comp science subjects is what i meant
ahh
lol i get that a lot too
i would be intrested in doing the battle, but dont know hacking
When click, loads it in a few sec
I am doing File Inclusion Lab Challenge-2 and need some help. Stuck. Not sure where to go. Where can I find help?
what SS
exactly same shit lol
yes
why did it failed?
Web Fundamentals
Dorm Internet is the fastest thatswhy
the website is too slow for dorm internet ๐น
Dorm Internet's too slow to load it in time lmao
It says Welcome Guest!
Only admins can access this page!
I used curl to set cookie so that it is an Admin user. That seems to work. But I wasn't given a flag at that point.
bruh that reminds me of my previous dorm it literally used to give speeds of 0.2Mbps(Mega Bits๐) on speed tests
It says failed opening 'includes/Admin.php' and I can't seem to get past that.
which room btw?
File Inclusion
This room introduces file inclusion vulnerabilities, including Local File Inclusion (LFI), Remote File Inclusion (RFI), and directory traversal.
I am at 80% done. Second last challenge..
โ ๏ธ
gm all. up doing the soc analyst simulator. any pointers?
ok wait
LFI#2?
Trying to paste a screen capture..
ok
Can't seem to do that.. I'll screen scrape.
Steps for testing for LFI
Find an entry point that could be via GET, POST, COOKIE, or HTTP header values!
Enter a valid input to see how the web server behaves.
Enter invalid inputs, including special characters and common file names.
Don't always trust what you supply in input forms is what you intended! Use either a browser address bar or a tool such as Burpsuite.
Look for errors while entering invalid input to disclose the current path of the web application; if there are no errors, then trial and error might be your best option.
Understand the input validation and if there are any filters!
Try the inject a valid entry to read sensitive files
Answer the questions below
Capture Flag1 at /etc/flag1
[completed this one]
Correct Answer
Hint
Capture Flag2 at /etc/flag2 --> This is where I am stuck.
I set the cookie THM "Guest" to value "Admin".. which seems to help
just trying to understand what kind of game is this
But after that I'm stuck.
the hint would be that u have to use the filteration and ../../ (Directory reversal techniques to reach the flag)
from chall2.php itself , admin.php is not required to be accessed
what game
the hackfinity battle isnt justa game
all i know about it is that it a game hackers use to play to test there skills
And you can win money
ya its a CTF event (Capture The Flag)
not sure about it in my knowledge no its not every time,like in the game given in this server, it would just be for a test
This one has prizes for Top 10 teams
i legit slept 2h yesterday
what kind of prizes nitro, dollars?
1 minute
9am time to start brewing the bean
dollars , free THM subscription vouchers , Merches and stuff
whens the 2nd round of challs drop
how to do the osint challanges , i did the first one but the second one i cant seem to get any information
oh osint is hell
so hackfinity gives dollars on winning, can we use chatgpt to solve the problems? instead of solving them by ourselfs
well chatgpt is dumb
it will make the solving challenges ealy and faster
idk there is a mural of pele kissing batman , what kind of incoding is in that man
one large beanie please
are u a student
yes.
@blissful current I think I need to do this with curl because of the cookie.. then -d "file=includes/../../../../etc/flag2" or something like that.. is that close?
you can use diffrent ai tools
well , then try the chalanges , solved 1 so far ๐ญ
Ha ha it won't help
i dont know , maybe , probably, dont think it will help too much
It's easy
Till some extent it can but will not completely help u find the answers... You'll have to do it manually
why? are the challenges above ai understanding?
i spent 20 minutes trying chatgpt to come up with 5letter flags and it kept giving me 4 letter ones
Ya.. Use Burp Suite
its easy for u when u are literaly batman
not telling u
but uh
Tell me what you did
its in plain sight โค๏ธ
Ikr I tried too!๐น๐น
i wanted to legit end myself when i figured out osint2
Yaa
I tested my dorm wifi but its 43mbps
Same lol
But attackbox is still slow, why?
well there is some words but idk what they mean , tried diff combinations
cause ppl ddosing tryhackme
Latency maybe
why lol
usage is at highest rn in history or smth
hackfinity
Strings
is accualy inposible yo find the exact mural on hgoogle maps
thatโs an opposing course website right?
It's easy to find
iโm newer to this stuff
look at it really hard
hackfinity is an event?
Yes
ye but there isnt going to be a flag on it
straight up
or is there
There is
When its due?
Better try after it
On Osint 2/stego?
am on the bus so i have to check when i come home
yea
yes thats what i am on
We use cookies to ensure you get the best user experience. For more information contact us.

You should not use stego only OSINT
using cookies then i get hacked
Steganography
Something lmao.. To shift bits of the picture to find hidden messages
๐
Lol
wow
didnt think of doing something like that
Yes I tried ๐คฃ
Collected all words ๐คฃ
tha chances of me winning any prize alone is like 0.000007%
Me too.. Shifted like 1000 times when I first got on it xD
Check message bruhh
Same I gave up.. People already reached 900 points I'm barely around 100 or less idek
I have some other college work anyways so can't rn
play chess instead of this
am already too good at chess but crap at this ๐ญ
i am on 15
I'm crap at both ๐ถโ๐ซ
lets say there is hope
Yo.. Damn..
@blissful current @hybrid plover i opened the track me now i am just solving some MCQs
Oh wait u meant? 15 points?
yes
I thought u said ur age or something
I was like he's 15 and already started thm
that would be nice
Youโd be surprised, there are quite a few young teens in this server
No doubt of course
probably much younger than 15 as well
lucky them
Don't depress me now ๐ถโ๐ซ
@blissful current @hybrid plover
What?
Career path quiz?
no after that

Nice status
Click on Learn tab on top then on challenges, then search Hackfinity

Nice.. Hits hard

why is Yoda so pixellated ?
im honored to be quoted xd
a jpg from 1998
Any hint for ghost phishing or stolen mount
scrubz is gonna bounce on my ass no way
hello chat ๐
I thought asking for hints and all was against the rules and everyone here is asking ๐ค๐น
the challenges will begin in march 20 am i late? or its a time zone diffrence
isnt it 18 march right now?
hello magician
It's ongoing already
if challenges start march 20 you have two days..
Scott (eyyy)
but I've heard they had begun
i see

on the other note, I was just a big fan of Michael, it's not corelated to me in any way ๐
that nick stuck to me tho
what magic do you do ?
they use chatGPT to sum it up for them, and then won't read it anyway lol
Jabba said he will make a tiktok for the THM rules
I can unchain myself while being completely chained
after I eat the key
had to google that tho
hopefully no one steps on the key
I'm watching you Jim..
you won't get me next time
I guess that's an idea for increasing site popularity
hey! harold houdini did something like that!
i said it as sarcastic comment about how new users do not read the rules when asking about illegal stuff
oh, aight ๐
My noodle really thought THM tiktok is real
or at least unoficially
i have no idea, never used that app
Hello everyone, i'm learning pentest on tryhackme platform. When i connect openvpn to tryhackme on kali linux, on terminal noticed succeed but tryhackme skill Not connection. Help me, thank you.
+1
๐จ๏ธ jam
sorry, forgive me :(((
Pam !
cat forgiveness.txt
It's alright don't worry ๐
Permission denied
its fun to # then type and see what channels exist
Hmm
cat default_apology.txt
cat default_forgiveness.txt
when stock price drops
almost felt like ppl would really use SSH in everyday life
cat michael-scott-paper.php
did not know haha
ddg ๐ฆ
is the hacking battle fun? i dont have time for it ๐ฆ
fun? Where? Where? Pam, bring the champagne bottles!
is that ted mosby in your profile picture?
well thats strange
nah
then who?
The competition will run from March 17th at 14:00 (GMT) until March 20th at 23:59 (GMT). The challenges will be made available in this room when the competition starts.
While you wait for the competition, feel free to try the challenges from our catalogue to practice!
thats what i am getting
kevin mitnick
ok
so i am one day late
Yes
is it because of time zone?
complete shut down hahah ๐
Jupiter
tell us
yea then why i am late and you are not??
lol
delulu is raimbow? in which language?
oblivious
"where do you live?"
in your computer
Red team o blue team! Wich one for a begginer?
Understandable
both have to be learned
First one?
oblivious in what? isnt that the context?
Purple ๐ฃ
Acquire the skills needed to go and get certified by well known certifiers in the security industry. Learn about industry-used penetration testing tools and attain techniques to become a successful penetration tester.
Blue u can
where do u live?
break it then learn to block breaking
...
the journey is yours
๐ 
code : broke it again
still waiting for the screenshot of beerrise blue screening a linux machine using systemd bsod service
Kansas
Yellow World.
take me there
Yellow submarine
ur a girl?
no

meep meep
Can we keep discussions appropriate for the discord server please @slate wraith
bro got banned to a shadow realm
Ferb, I know what we are gonna do today!
i think its general
๐ญ
Hello everyone i had questions related with sni bug hosts?
@boreal scarab T- you fucked smth: <t:1742309838:R>

Dayumn
Which app
U know the transcribers in court, they do 120+
yeah but those typing styles also remove the vocals while typing and use some shortcuts to write faster
hackfinity is locked??
im better
not even the 60 second test....
you took some time to ramp up haha
What do u mean remove the vocals?
he was accelerationg
Vowels?
wait
im trying to prove the site that im not a robot
Yeah they use a weird keyboard too right
"46 wpm" cute
what being on a keyboard from a young age does to a man
Dangerous, it frightens the shit outta me
Are there any good rooms on bots and setting up a botnet?
fr
๐
someone please find where this guy lives
the hackfinity battle room is locked?
and report to the FBI
the hackfinity battle room is locked?
nice good job
Ok. I'm not wanting to do anything illegal. I was just reading about botnets and wanted to see if there was a room that actually had all this setup.
Why do you need a botnet?
What exactly constitutes a "student"? Do you have to be enrolled in an accredited university? Is anyone interested in teaming up for this CTF?
Yes.
I don't need one, I was reading about them and wanted to learn more that's all. Nothing nefarious guys.
Sheesh all that while fixing those mistakes ๐ซก
Yes looking to team? Or Yes to must be in Uni
Maaaaaaaaaybe
sometime i think that you are proof that we evolve from monkey's โค๏ธ
It's more believable we were chimps genetically spliced w alien dna
that make more sense yes
why its not working
Maybe don't copy paste
i think so tere is space
in the front
i did not copy paste
which one
which roon
extending your network task 6
offensive security
task
Title your question with the room and task
This chat is for alien conspiracy plz
i did no one is replying
@sand trench if you looking for some H.P.Lovecraft space horror alike movie. Color Out Of Space
https://www.imdb.com/title/tt5073642/
hacking ur first machine
you go to #room-help or ban is incoming
@ashen marsh Please don't post answers here ๐
sorry
brother
๐ฎ
Jabba dealing with this sh every half hour ๐
we got u bro
jabba the boss
I got this book , bought it just for the cover 1$ so good
Guys is it okey to save all my passwords in google password manager?
i got H.P.Lovecraft books and so.
because from few days i am noticing some suspicous activities on my accounts
Yes that's fine
Ooo a cyber stalker
im not too sure about the security or privacy in google password manager but bitwarden is a good option
i am using random generated strong passwords from website and using them now i cant remeber them all so i saved them in pass manager
no. use password manager
bitwarden or so
Elaborate?
What kind of suspicious behavior?
how do i do the game hacking
mean. not google one. at last i have not use it as default
thats before now i changed and 2fa on
But surely there's a reason why not? ๐ other than just saying no
i havent heared of bitwarden
how do i doo the game hacking hting
idk for sure. i guess is ok. just not know so much ppl use it as default one
I use the same password for everything the name of my dog and 123
even just using a password manager is already a step in the right direction
@mossy river are you Jabba Bravo?
I am yes
The Arch User ๐ฎ
well how do i do the game hacking thing
i have to make sure my gmail is safe
yes enabled thnx
The answer might require a tick versus an apostrophe character.
memes never stop posting 
how to search teams in event
It should be on scoreboard on the website itself I guess
In the drop down menu MAYBE
#1351230456187846788 Or just ask it here.. Someone might answer
@true urchin
alright I will thanks
Gave +1 Rep to @blissful current (current: #2750 - 1)
..
Someone wants to explaim me some concents or tipsss?
I am a begginer
for real... AdGuard block linux update =/ dheck...
probably because random domain names that get put in block lists
yea... just looking at it. need to add nl. into allow list
Mods aren't site staff
My bad didn't know
yeah someone asked but no answer yet
That's the channel to use though, not this one.
oh kk
just curious can
we use DDOS attack in hackfinity
i m not playing
but just need to ask
??
I don't think so
I don't get why you would need to use it in the first place
For Good intentions
There is a team search now on the Scoreboard page in the room.
It does not load for me
What exactly would ddosing get you? How exactly will that get you a flag?
No that's just a crime
That's the same thing I was thinking
Besides it's internal to the THM network
The fact he also sends that gif and says "for good intentions"
Speaking of ddos, is it legal to do on your own network or will the Wi-Fi company complain
โIt was my friend who sent the message not me I swear I didnโt mean itโ
wasn't me ahh
It's not legal at any point, you're using infrastructure that you don't own, the first d in DDoS means distributed, aka something that takes place from different areas not only one
Brb gonna go get my own set of zombies on a internal only lan with no outside network connection devices I own and ddos that
It is now legal
hey all how are you all doing this fine night
Pwning the last few challenges
What about yourself
Yeah
im fine have to tune up my music bc i dont like to hear my neighbor dog no mae 3 days i have now its my time
Still a way to go, but so far it has been preem
will i be able to access to hackfinity questions after
Almost done
it ended
We have a few members without student mail so we not on the board "yet"
But that is work in progress
will i be able to access to hackfinity questions after it ended
okok
Happy to help, maby I'll even write a couple of writeups
How you guys doing so far, without spoiling stuff
i do hate Premium
Someone apropves de certificetd secueity + ?
from where can we do osint
what things should we know before we start
I wish I could answer that question without spoiling or giving away clues.
Just make use of references online about OSINT. Look at some of the most commonly used tools and understand the actual question or task that is given to you
That's all we can say
any prequiste knowledge one require
to do this
ohh msfconsole
dang they added new challenges into hackfinity
Hey guys good night ๐
ptsd from osinting too much
hey i am new here to the server and the field
ello new, im ralex

What for?
Why are you asking members to osint other profiles?
Did you know this is illegal?
lol bless the patience of the moderators
oh boy
So you know it's illegal, but they can't do anything about it?
if it was me you'd be gone already
:hammer: ftoppe#0 has been banned.

well
lol
deserved
+1
As much as people would love it if they were banned instantly, we would like a user to re-think their actions, and possibly have a change of mind/heart.
Give them enough rope to hang themselves.
Please don't ignore me.
Ignore what
I know don't worry being a moderator for an other cybersecurity platform I know what's like sadly
I asked why you're asking community members to OSINT a different profile?
Cause that person cyber bullied me and someone else
go to police
And do what exactly?
don't do your own justice
They posted pics of us online
Please, if mods are dealing with a situation, can you refrain from getting involved.
๐ ๐จ
Then you report them to the authorities, you don't take vigilante action.
Also, if this was on Discord, you can report them for breaking their ToS by doxxing.
Sitting here at work eating Pringles for lunch and seen the adapter sitting next to the can
Cantenna lol

You can rig the empty Pringleโs can at the end of your adapter for better signal
๐คโ๏ธ

Are you ok there?
ye
permission granted
my eyes jeez so blurry

CLEAR
ZZZZAAAAP
What a way to doxx your location.

Swoop was discontinued in 2023
that's the joke
How are people going to find me๐๐ฅบ
Its just a city
there r ways
Verify
CLEAR
ZAAAAAP ZAAAP
my whole apartment is cold
but I guess that's what happens when you turn off everything for a week
have you tried to defiblerate it to heat it up???
hey guys im new to CTF's, I recently participated in PicoCTF 2025. I was curious about how many CTF's accur each year.
Does TryHackMe host many of them?
This is the first student one from THM in years.
Im see mythbusters right now and ...
This isn't that kind of server, and that also breaks Discord ToS.
oh okay thx
Gave +1 Rep to @knotty pendant (current: #1366 - 3)
oh sry
approx 1 a week
youtube
tryhackme has challenge rooms/ctfs that are there and can be done whenever over the entire year
then there is the new path releases or advent of cyber side quests for more focused ctfs
dont ban me please
or the weekly releases of challenge rooms
Capture The Flag, CTF teams, CTF ratings, CTF archive, CTF writeups
Why would they ban you
I won't, you were told it breaks a ToS of Discord and you stopped.
What about CTF's that last up to maybe 2 weeks or something like that?
Thanks!
Gave +1 Rep to @chilly veldt (current: #8 - 968)
Please follow rule 9. ๐
not that many
oops sorry
Scrubz Freaks the fk outta me
his picture isnt loading for me
Really? 
Good...
It's transparent.
peak comedy
So you shouldn't be able to... 
Tch extremely unproductive day , the chat here was more epik than the challenges today
the guy who im still about 25% certain is a advance jarvis like ai
It's transparent so no matter what theme you use, you'll never be able to see it.
I really wish they'd bring midnight theme to desktop.
yeah
I thought they did
Maybe itโs amole?
theres midnight burple on there
hello @wintry trench

It's paywalled though.
true, and the only other solution has a chance of getting the account banned
i am back after years
Looks like itโs time to put those savings to use
I don't stream as much anymore, so I can't justify the cost quite yet. ๐
hi back after years, I'm Bella

The SAL1 exam kicked me out of the analyst VM and is asking for a login
what do i do. got 40 minutes left
yea
cc @umbral bay
heyyyy
bruhh its just the starting and they expect me to nmap commands why is it ?
thm rooms are not organised?
@umbral bay would really appreciate some help. I got kicked out of the analyst VM in the SAL1. I originally had like 48 minutes left. I now only have 37 minutes left. I tried exiting exam and reentering but it's still prompting me to login to the VM
Let me check with the team one moment
What's your username on the website?
Thank you @mossy river
Gave +1 Rep to @mossy river (current: #6 - 1537)
real
am I in the wrong room or its thm that's messed up?
guys i want to learn python for ML and AI do you best platform to learn ?? for free?
tbf nmap is really useful so i 100% recommend learning it the sooner the better
YouTube is pretty great for Python
even in the beginning?
no prior networking knowledge required?
idk about subnet
and all
yea, networking knowledge is good but you dont need a 100% grasp on it to know how to use nmap
if youre doing the pre rec paths on thm then it should networking before
can u suggest me which room to do for complete networking
any channel suggestions ?
yeahh
Have you done security 101? Pretty sure that has networking in it
I don't recall the ones I used I'm afraid ๐ sorry
no I didn't.
You should
whatt ? (crying emoji)
Or is it pre security then security 101 been a bit
pre security and cyber 101 is great for beginning and to get better network fundamentals i recommend web fundamentals even tho its below pentester its a lot easier
okiee TMRW I will
I was following free path
okiee I will give whole day for networking TMRW
covering everything on thm
u guys have completed thm free path?
idk about all the freepaths but ive completed a few
Yep
it's worthed?
I did pre security and security 101
I will be able to mess up with people around me after that ?
And been doing bits of the other paths since
got premium too?
No because that would be illegal
bruhh It was sarcasm
scrubs will ban u
Hello everyone. Complete noob hereโฆ how much time should I dedicate to the SOC simulator for the SAL 1 if I have zero experience? TIA
learn networking first probably
Probably worth completing pre security and security 101 and then heading down the soc path
idk how well the simulator would be if you dont understand what your looking at
It isnโt a fast thing for a noob to get into
i can't believe the SAL1 VM kicking me out messed up my groove ๐ญ at least it was only the first simulation
I would have been sad af if I was on the last one
at least learn the osi model and what ports are before learning nmap @nimble ether
You don't want to be attacking anything you don't explicitly own or have not been granted permission to in a formal contract
ik what are ports
bruhh it was sarcasm ๐ญ๐ตโ๐ซ
and you do not want to be "messing" people up either
SARCASM
Hard time believing that the second time
sorry didn't mean to cross community guidelines ๐โโ๏ธ
hello, fellas..
I donยดt know if should put it here (correct me if thereยดs a better channel to send doubts)
Also suggest you look up what sarcasm means ๐
the osi model was a TON of information ๐
โ ๏ธ
what do u mean?
Usually related to irony ๐
u guys use any other platform too?
the osi model room in the pre security pathway
done
free version of HTB attack boxes aren't bad
yeah
make sure you note them down and remember them properly
always take notes when doing rooms
yea that was the first time i ever took down notes in my life lol it was rough
got a guy scammed by bitcoin scam lost 30k and asking help to osint the phone number is it legal to do so ? and if it is can anybody help?
bruhh how am I supposed to write that much ๐ญ
not legal
dont do it
this is not done here
ok bro
demm
I'd avoid that
okey sry i just wanted to know it is legal or not
@shell nova do you happen to know when the beginner pathway will be removed from THM ?
OSINT is illegal unless you haeve very clear permission from the person, i think is how it works
Might not be strictly illegal, but definitely sketchy and grey
ok tnks for the info imma watch out nowonwards
Your guess is as good as mine, I'm not staff
ok
Laws aren't super clear on the subject everywhere, might be cyberstalking regs though
when someone DMs and asks me to hack their ex gf or something
i usually just give them username of a mod, and tell them to contact them cause they are good with that kind of hacking lmao
Am I the monkey?
Good plan
to many if ands and buts ๐ญ not worth ther risk
Oh sure
Don't be an idiot usually applies
^
Osint has positives
most of the time OSINT is not illegal because you're collecting info from open sources
but its illegal if you use that info to do something nefarious
ahh ok so thats what makes i illegal
I SMELL OSINT?!?!?!?!?!?!?!?!?
For example I know they police and private investigator have additional tools for looking up addresses legal names and places of residence
@boreal scarab what is fluff clan
@gray sonnet wanna explain? Work has drained me of e rrgy to explain lol
Poor you
Go back to sleep
Surely heโs not asleep during the afternoon lol
Naps are fine
Oh totally agree
it was he was depresed by loosing money and he cant do legal complaint and he getting realy bad thoughts so his friend aproched me
They will always have a story and justification often this is just social engineering
hes afraid his parents might be angry for loosing that much amount
ok understood
Itโs just the newer versions
Please don't post loud videos
Sorry
The ctf hard
agree now i undertands i need to grind more haha
What means grind
So basically a tribute to one of our beloved ex mods Fluff, real nice guy
100% totally not a cult
Is someone available to help me for a pivot in a lab (it's not from THM)?
Rule 1 in identifying a cult, they are against being called a cult
jabba sometime remind me to tell u a funny story of my idea for a relgion
Might want to ask on that platform's support then?
It's inactive.
Hey guys, the ones who already have a pentester job or jr pentester, did you have to have previous experience in another IT sort of job or were certification and proving knowledge enough for you,? Just curious about what to expect
Well, I gues going from solo to forming a team zero's out all of your rooms.. yikes
I will but I hope you know I never remember anything
And in their demo, the tool is not available.
oh u are like me lol
There are plenty of alternates
I'm trying with metasploit.
Probably
I added routes.
Never did get those working properly
But now, I'm trying to use nmap on my own machine, not with metasploit.
Chisel is nice though
I know thee is nmap.
I tried with shuttle, trying to add a password to root user, it didn't take effect and it's asking this user so...
Not really a pivoting tool
hi
Sshuttle should be fine
Tried, it's not working.
So I am trying with msf.
Started the proxy.
Chisel then
It's telling me that's listening and ... nothing with nmap.
I can't install tools on my entry point machine, and it's on linux.
๐
Static binaries?
?
If you have curl it's enough
Don't need to install as such, just drop in /dev/shm or /tmp
But with metasploit it should works no?
I added the good port in proxychains.conf.
I have to enable/disalbe a special comment?
hi i got stuck any one can give some help
Maybe
Proxy should be local though
No curl?
I can't host a webserver mb.
You can on your attack machine and grab from there
