#general
1 messages Β· Page 962 of 1
no
yes
what is the best way to get interactive shell after establishing a non interactive one?
socat
I always considered βbrute forcingβ to be going in blind and rainbow tables are more comparing hashes than brute forcing through computations
its answer for me?
check out room Whats a Shell
thank you
are fresh made kali linux vms vulnerable to fail2ban ?
or they come with the fix?
debian
whats a shell?
π
I read somewhere that dictionary attacks are good for targeting a specific or "single" account. And RTA is good for a whole dataset of passwords
(As long as there's no salt)
Salts do be throwing things off
Gotta love em and hate them at the same time lol


π¦ΉββοΈ
brb
Good news, headache is starting to dissipate, thank god
I'll give it like 20 more mins than I'll do work
Hey all, I filled out the form for SAL1 (I have BTL1) and I keep getting an email saying that they are trying to send it to me but the email is incorrect. The email I put in the form is 100% the email my THM account is attached to. Any ideas why I canβt get it, OR any suggestion how to get in touch with support?
give me thanks
Thanks for chatting with me through this, guys.
My head has been like ping pong all morning
try contacting official support from THM website.
Reach out to support
@sick lance can i ask you something in dm's
Regarding?
someone asking me something and im not sure if it a thing i should report or not
Yes
wow this tool for music called beets is a lot more powerful then shadow thought
Not really, for unsalted hashes you're getting the same results for one account or 10
It's just time vs disk usage tradeoff, precomputation

For NTLM, rainbow tables are dead because GPU hashing is so fast that it makes them obsolete
Interesting
that is a sentence that makes the advancement in computing power fascinating to watch james
lyrics in the metadata??? yes please:
it is not very fast to do this but oh well
Fuk work, pretty much got everything done for the week that needed to be
Might just study till I get off
ola :3
Meow
Meow >:3
Miau
NYA
:3

Fuck an API im out here jerry riggin it withcrequests and beautiful soup ππ
Ah yes, the soup
hail the soup
Please can someone give me some guidance on a question please
It has nothing to do with THM, I'm just curious
Pls pls
Dude youre a wizard. You guide me !
Jokes asied whats the question?
XD
I hope so :3
My question is...
If I wanted to pentest Redis, what would be the easiest way to find a Server is running it pls
hi,, guys... is this community friendly to beginners ?
By default is usually running on 67 something i thunk
Yes of course
Like the DNS?
6379
Okie thank you
Gave +1 Rep to @polar shale (current: #175 - 48)
Wait no
Hmmm. I don't think so, I think it's a DB?
Tcp 6379
Not DNS sorry
Thank youuuuu
That doesnt mean they havent changed default but assuming it is a lab they probably haven't unless the lab features like service finger printing or sum
Good article!
I really need to sit down one on one with javascript
just happy to help
To get used to the syntax
It wouldnt really be a community then would it? Of course we are ! All of us here are students no one is better than the other
Ego is a big deal in tech but especially security π if your hearts in the game you arent playing right imo lol
is it hard to enter cyber security carriers ?
This! I swear
To jump directly into cyber yea it is a little but just getting into tech in general has a relatively low barrier to entey depenening on your location e.g.
ain't nobody got time for allat
Did you google ego?
Cybersecurity is tough, but with enough practice, patience, and motivation.
Walk in the park
yes, I'm not familiar with the term
hi everyone, wsg?
Oh i got you haha ! Look into it
15st can take prize ?
St?*
what's good? here
Th***?! Lol
google god
how to create team in hackfinity guys?
Is Arabic read / written left to right?

As a system administrator I treat all my tech illiterate end users with respect and kindness cause I know they've had bad exp with grumpy techs
And vise versa
That too!
Sorry yea got it backwards
sry to bother, i've a question
youre not a bother bro go ahead
not that interesting, probably not used much
Yep that is what i have been told by friends
how do you dig up more ? π
Really is especially singing
dig..hmmmm
, so basically, i'm zero at cybersecurity, so, where did yall learn it?
right here
so i can learn it too
#start-here here as well
Ayyooo
You got them fakmojis like me ? π
The alignment for certified π
from like, thm itself?
I have been trying to get into the world of cybersecurity since 2023. And have joined THM since January 2025. I have implemented several cybersecurity frameworks into the network at my workplace. Now I am confused about the next step in implementing security. Are there any recommendations for me? BTW, I am a tech support who works alone.
on TryHackme lol
i have another certification that all of you will like
Take a look at #start-here channel
im doing the hackfinity battle ctf, but everytime i reload the page my answers arent saved?
i'd like to apply
sigma sigma boy sigma boy sigma boy
I better go read all this is very stimulating π
read what
what this guy read
sum gen alpha bs
past tense of read should be red
its a cringe song is all i know (lyrics)
PRO Tip. SQL/NoSQL DBs can only be accessed from Localhost. If you were to use SSRF to gain access to the internal network, you can then connect to the SQL DB from inside the box
ew dude wtf is wrong with you
Read & Read are both spelt the same in present and past tense
Hi, can anyone help me with the Enumerating MySql. I tried installing MySql client but it seems a connection cannot be established with the server. Thanks
that's why they shouldn't
thankks
hmmmm community manager is being sneaky peaky in invisible mode
Internet connection buggy
I'm assuming the word "read" was pronounced the same for both but people got confused and henceforth they changed the past tense pronunciation
Ohhhh please tell me more
I red it 
got the flag only using simple reverse shell commands available online
Time to rise above the dictionary and advance the language
the whole of the English language confuses English speakers
Ohhhh thank you
Gave +1 Rep to @fervent meteor (current: #54 - 165)
better than other languages
going for root now
most
technically it is other languages, we took the worst parts of all the other languages and made our own
we should go back to hieroglyphics and gestures
βοΈ π§ π₯ , π£οΈ π ββοΈ
brain melting content
I am Gen Z π
im genz and i have no quit what half of their words means lol
me too lol
+1
no cap
lol
im not finna go around saying "smiga, skibi toilet ,etc" to be cool π
ohhh CAP mean "lie or untruth"
my cat: not eaten anything in 20 min
- starts crying and meowing
everyone speaks emojis, international language π
except for π π§βπ¦²

i remember my friend said "skibi toilet guys!" there was so much embarrassment
You sound like chatgpt when I say "less formal"
loool
the word i see often in chat: sigma
Problematic Connotations:
The "sigma male" concept can sometimes promote:
Social isolation and a rejection of healthy social connections.
A sense of superiority and detachment from others.
Misogynistic or anti-social attitudes.
A misunderstanding of mental health, where people may forgo seeking help, in the name of self reliance.
It is often used by people who are trying to justify antisocial behavior.
It is important to understand that it is not a healthy social construct.
print(random.randint(0,200))
201
error
(thinking out of the box)
max is 199
meow
jack frost
sorry i just got wizard on the site so i wanted to see if it updated on here yet
Max is 200
im so old I dont even know the generations naming. I only remember the boomers
π§
it appears you don't speak in hieromojis
see if i put a random in random from 0, 200 it makes it more random if im not expecting anything higher
ik
I was responding to veggies' message^ :)
ohhhhhhhhhhh
somehow i got this wrong.
didn't see that
this is a junior mage, this is the senior π§π½ββοΈ
waiitttt
i normally use NumPy
imagine making grammatical errors using no words
but still a mage
I never really had to use numpy besides iimages stuff
hello kitty
loool
I worked for MrClam, he's a clam
if I see another hello kitty gif I will enter transmutation
hello kitty hacking
she lied she watching youtube
doing recon phase
ahhhhh
i remember i got stuck on that phase for a while and couldn't get out of it
for loop
for topic in cybersec:
learn_osint()
if learn_osint():
pass
else:
retry()
Welp I'm officially not getting anything done at work today
Damn headache i swear. Getting better tho
Just hard to focus
Boss not here, just me and 2 other people
Technically that would be me actually lol
did you get a cert for this not getting anything done?
loool
Out of the 3 people
I should lol
For trying at least
π congrats on non productivity
do jobs not have like aspirin or something at all times
Ty ty
prob would be a thing in the feature
gen z getting worse
your sponsor of headache was there
There's actually a nurses station in the main building I'm debating on raiding
anyone can take me in your hack finity teamm???
nah, i just started these courses thm, pre-sec pathway, at 2nd lesson, i already wanna give up
What is making you want to give up?
They need to verify to post in that channel^
ok.
coool but when somone seesthe the sticker on the back of your laptop there not scanning that qr code lol
random vague pizza qr code
Not the point tbh
i have 3 raspberry pi stickers
i dont have access the in that channel
why haven't you thought of that in the mornin
if you do want to then verification is needed
btw i miss spell 50% of that sentence
man I can not stand headaches
Well, I might get in trouble by doing that
Boss kind micro managy
ohhh
jk, but the thing is, im not from country that English is really advanced or used, so yh, and also too much information, dont wanna give up, but still difficult
you would get in trouble for increasing your productivity?
Breaking News: A Black Cat and 2 Gray Cat hackers found in the Hekar's Lair doing a Secret meeting to hack the government
Sounds stupid but yes
i had a steep learning curve too
Have you tried using your browser to translate the content?
You will still need to submit answers in English however it might help you decrease the information overload
in another words please
Soul Taker. having to translate into your language does make things more difficult for you. what language do you speak?
it was hard for me to learn to but i got use to it
russian, but there are so many mistakes in translation, it's easier to learn english than to translate to russian
ahh ok
type shi, and i've done researches in russian some lessons, but not as useful as english ones
problem with needing something translated is that all the tools would have to be as well
π·πΊ
xD

im reallyyyy surprise you know type shi

tt is really helping me to improve English xD
brain rot is gonna be crazy
but on the other side brainrot 
fr
i tried google dorking THM walkthroughs for Russian, can't find anything
I've seen a few
what was your did you search
i dont even know wth is dorking
im cooked fr
thm: walkthroughs language:russian i saw a bunch of walkthrough for english to russian but not just Russian

if your new don't worry about it, you will learn it, its a big part of the recon phase depending on what you looking for
what about this?
https://www.youtube.com/watch?v=VGEnbEhlG4s
β‘οΈ ΠΡΠ°ΠΊΡΠΈΠΊΠ° ΠΏΠΎ ΠΏΠ΅Π½ΡΠ΅ΡΡΡ, ΡΡΠΈΡΠ½ΠΎΠΌΡ Ρ
Π°ΠΊΠΈΠ½Π³Ρ ΠΈ CTF β‘οΈ
Π Π΄Π°Π½Π½ΠΎΠΌ Π²ΠΈΠ΄Π΅ΠΎ ΠΏΡΠΎΡ
ΠΎΠ΄ΠΈΠΌ ΠΌΠ°ΡΠΈΠ½Ρ Π½Π° TryHackMe, ΠΏΠΎΡΠ°Π±ΠΎΡΠ°Π΅ΠΌ Ρ RCE, SQL-ΠΈΠ½ΡΠ΅ΠΊΡΠΈΡΠΌΠΈ, Ρ
Π΅ΡΠ°ΠΌΠΈ ΠΏΠ°ΡΠΎΠ»Π΅ΠΉ, Π° ΡΠ°ΠΊΠΆΠ΅ Π·Π°Π³ΡΡΠ·ΠΈΠΌ Π½Π° ΠΌΠ°ΡΠΈΠ½Ρ ΡΠ΅Π²Π΅ΡΡ ΡΠ΅Π»Π», Π° Π·Π°ΡΠ΅ΠΌ ΠΏΠΎΠ²ΡΡΠΈΠΌ ΡΠ²ΠΎΠΈ ΠΏΡΠΈΠ²ΠΈΠ»Π΅Π³ΠΈΠΈ Π΄ΠΎ root ΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»Ρ.
π° ΠΠΎΠ΄Π΄Π΅ΡΠΆΠ°ΡΡ ΠΏΡΠΎΠ΅ΠΊΡ:
https://www.netstalkers.com/private
https://www.patreon.com/pythontoday
https://yoom...
π«
@plush needle
dig a nice big grave for your computer
if i cancel my subscription, is it gonna remain?
Then it would be OUR grave
i just dont wanna renew it
communism and slavery don't seem to fit together
you have nothing to break but your chains, rise up my proletariat hackers
i remember once i saw someone selling a dos tool that could that anyone down they were using "ping <ip>" in their video π€£
i'm 23 days in and the notes ratnest is coming along nicely
as i understood this, it's for those who at least know sth about pentesting
what are you gravity settings
also nice
very nice Obsidian notes
i need to add more tags and filter this better, lmao
but gives you something to start off with, see what channel is suggested that is useful to you
it's all defaults so whatever those are
yours in better than mine i didn't even know you could do stuff
ohh
yea tagging stuff is nice
poka dots
I just have everything in 1 file
throw in a --- at the start of a file, add a tags entry, and get to work
i kept messing with mine and now its just a big circle lool
light mode is a crime
i have no clue what that does
i'll try to find ig
i'm starting to reference codeblocks between files too, so i have example commands over on the ffuf and i just reference and inline the codeblock there in other locations, obsidian is nice
i am sure you will find fellow Russians who hack ethically
adds a little properties box you can start adding things to
It's cool having cool blocks in noets
---
tags:
- technique
- sql
---
thm= "is fun"
ill try to find russian individuals, and any fella that explains thm in rus
how is yours so pretty when i add lines they all get jumbled together π
easier question: what's this?
clearly it's my 15 percent concentrated power of will
Itβs the folders
obsidian notes graph view
i wonder how much KGB can offer some advice on where to find THM resources for you, i believe he speaks Russian
mine is foldered π¦
i didn't know he did

i thought he speaked english
so can i dm him? or what?
Unless he really likes the kgb I would assume so too
there was some Russian in chat, he knew what i typed immediately and then mods stated the English only rule
ask them before you dm
privet
when you see him online ask to DM
Da
Comrade, we need more vodka
oh, yh, thanks for reminding
Gave +1 Rep to @blissful snow (current: #498 - 12)
yw
damn, from 498 - 12
[ drink water reminder π ]
ovkorz
Nyet, comrade.... Drink vodka, save water
i think my rank is 498
so um, do i just basically ping him and write him like: can i dm you?
Yuh
net.
@cloud quiver
π ?
can i dm you?
π
Soul wants to dm you
Why , what's the issue π ?
He might take your soul tho

hey KGB can i 1v1 you in super smash bros melee, final destination, no items
Isnβt kgb Serbian
difficulties with lessons, just a quick chat
XD
so...?
all the serbs i know personally are either the nicest people i've ever met, or the angriest, and there has been literally no in between
Soul he wonβt know unless you reply to him
It looks like you are speaking to a ghost
difficulties with lessons, just a quick chat
You can in #room-help if you have problems with some room π
Russian and English is the issue
Soul Taker needs help with THM content in English
have any resources ?
Now shadow-sama will listen to all those music?
41 anyone tried this
ig these memes will spawn here randomly
Definitely seems like me in my First Game dev Hackathon (Had made a space ship on blender that looked more like a smashed out frog ) π
i for one love terrible programmer assets in gamedev
β― beet list | wc -l
2363
now have easy way to check how many music tracks shadow got
Atleast you tried
yeah could listen to it while adding the metadata... there was basically no down time
Then next time I let my teammates for it (he's better) , me got into game programming and level designing instead
Nice βπ»
how to check which team im in?
On profile Manage account -> Teams
i got it
That MS team's call sound annoys me
Sounds a bit like Skype because both are owned by Microsoft
i wrote a little raycast wolfstein clone in c with a software renderer and as few supporting libraries as possible, that was a fun challenge

just had to
behold, rattenstein
here is something to enjoy
https://www.youtube.com/watch?v=joiyb6c_Ry4
Greetings !!
π!! SUBSCRIBE For More Coding Screensavers
π€© MORE CODING SCREENSAVERS on the playlist: https://www.youtube.com/watch?v=joiyb6c_Ry4&list=PLO6RKUONe5nRrVBH_ouKheUUKbkrAAAn-
π GIFT MERCH FOR PROGRAMMERS:
https://www.redbubble.com/people/ibsi/shop?artistUserName=ibsi&collections=3860395&iaCode=all-departments&sortOrder=relevant
You...
Help me in task 41
PG 13 π«
it's pg13 violence!
Anyone is done with this task ?
nope Batman
i'll nuke it if it's pushing the rules too far though, but it was a fun little project
ask Robin

if you coded this, very nice work
yea, pure ansi c, only supporting library was for window creation and input :P everything else was from scratch
never got too far though, was a weekend project
that is nice PG 13 violence
Animation or a game?
should have seen the programmer art before my buddy took pity on me and made up some rat sprites
Ok
Has anyone seen the leader board lately? Looks like 2 people managed to somehow cheat to get to the top.
Aint no way π
they boutta be banned πͺ
yo thanks for those who actually helped me, i really do appreciate yall
Gave +1 Rep to @grizzled wing (current: #35 - 265)
How did they cheat tho? Like what did they do to cheat
idk, maybe they used some tool to automatically fill out answers. Either that or they might have found some vulnerability in THM.
https://tryhackme.com/room/HackfinityBattle
Damn
spots 1-6 have exact same score
maybe there will be an extra task?
just finished 500ml of 4Β°C water
eeeh the vitamines and minerals come from shadows energy drink that they finished about 2 hours ago
On a scale of 1-10, how realistic is it to know nothing about cybersecurity and pass OSCP by the end of December π
depends on your note taking
rubber duck tutorialing
and amount of time spent learning each day
gday mates what's poppin
beets music library manager
cool
make that weekly
πΏ
1:30 left of work
Actually though Iβd like to get certs one day too, Iβm pretty new to cyber
I study a shit ton so hopefully itβll all work out π€
I passed my sec+ with a month of study. It's not that hard if you have good study habits
hey all i have a question
Is this a CTF?
its lesson , and i try on my website
?????
Do you host the website locally?
no online
What's up?
Who hosts it?
made a reminder
why you just assume ctf when someone has a question
infinity free
Always capture the flag but never flag the capture
You'll need to ask them to attack the service then, you don't own the website, they do.
Unauthorized pentesting my favorite
Because this could possibly be homework.
oh and if i try on local ?
and we can still help with questions if it's homework just don't do it for him
Good catch
No we can't.
????
It's literally in our community rules. π
and if i try on local its possible ?
i get not doing it for them but helping someone is not even cheating
if they have everything and know what they need to do resources are just fine
No, it's their work to research, not ours.
if you just got oh it's xss here's xss that's different
And we don't their educational establishment rules on asking for help on materials.
Don't know*
Yes, but you need to build the site on a machine. Best shot is to use a VM from what I've read
the ctf was end reallu was one of the best ctf
And easier as it's already set up.
That too
why on vm ? if i use mamp for my bdd and chrome for look website ?
@sharp citrus It was not right to give extra points to
Have you ever cheated scrubz
No, I don't.
Well, yoy could build the server yourself but kinda waste of time, VM is faster.
its complicate to create a server ?
or its like create data base ?
If you cheat what do you get?
Nothing, you learn nothing.
Frfr, true
Burp suite academy has good labs on XSS.
^
Scrubz mentalityπ―
i dont want xss i want injection sql bcs tomorrow i have examen and i understand nothing
Burpsuite academy, they have tons of SQL injection labs
thx bro
Gave +1 Rep to @oblique loom (current: #624 - 9)

scrubz this is literally resources which you said no to
and why i cant use my commande on my website host online ?
They asked about setting up a website.
Because protections might already be in place.
if i usegood commande its not possible bcs the site block this injection
ohhhhh i see
thx u so much for help guys
π»
made a picture for you to remember
print("Hello THM")
pretty good resource
``` this is the commande on cours in base of sql injection
When I don't wanna listen to anyone, I pur my head phoned I to noise canceling lol
I love this one
pwnfunction >>>>>
if i want try on my app java what i put to replace the name of web site ?
Yeah chief ngl a bit more context would be helpful
Cause i have no clue what you wanna do
For the sql injection is your goal to just see if the field is vulnerable or try to dump database contents?
I just want to get the data from the user table
Portswigger SQL injection labs are very good I recommend doing those too if you want some more hands on practice
Ohhh
Whatever local port it is running on if Iβm understanding you correctly
that's what I do at uni and then I pretend to lock in if someone looks at me so it doesn't look like I'm ignoring them when they try and get my attention
I find that people look at me while working and out of pity I always end up engaging with them but I've tried to get out of that habit because it reminds me that I'm on campus in a classroom
that's how you end a line and comment out the rest of the line in sql
Are you familiar with sql syntax? If not, THM has a sql fundamentals room
; to end the line and -- to comment the rest, I'd advise learning sql for sure
i covered SQL injection line yesterday
Also, one thing that helps me learn sql injection is just playing around with sql in an online sql sandbox. Itβll help you spot syntax errors better
yes i know litel
I mean, if youβre struggling with understanding comments Iβd probably recommend diving into more sql syntax first π
the two hyphens cause everything after to be treated as a comment
but idk why we need treated as a comment ?
select * from THM -- comment
A sql query is like this
select * from example where id = '2'
If the website doesn't use prepared statements then you can break out of the original query to add more onto the existing query.
That is what the ;-- is for
Sometimes after the sql query the site is using, itβs necessary to comment out any code after to avoid syntax errors and make sure your sqli works right
'+UNION+SELECT+column_name,+NULL+FROM+information_schema.columns+WHERE+table_name='users_abcdef'-- Something like this
hhhuuuummm
so if i understand we use -- if they dont have prepared statements
Anyway though I admit that thm sql injection rooms were difficult for me too when I first did them, i really recommend doing portswigger sql stuff because they walk you through the process of it
Good afternoon all
Good afternoon β€οΈ
Hello hello
No donβt apologize for asking
Don't be sorry
Better to ask than to be confused forever
What we here for
Yes, this is very true.
The real annoying ppl are the ones who donβt wanna understand at all
You've gotta have the drive to learn, and if it involves asking questions, then so be it.
This shit is hard man π
most of us will gladly answer questions.. that indirectly help us as well
memorizing stuff etc
SQL injection is a pita to grasp
You know what's funny? Obsidian is inherently helpful during OSINT stuff, haha.
I still struggle with it
I brute force it 
Like for example if you have a sql query like this
SELECT * FROM users WHERE username = [user input] AND password = [some shit]
Then if you inject your own SQL in field that accepts user input, itβll cause a logic error since itβll show columns where the username and password must meet a certain condition. If you do something like this
SELECT * FROM users WHERE username = βadminββ AND password = ββ
Only the usernames field is considered when running the sql query, thus avoiding any logic errors and allowing you to do things like bypass login forms
Other times you also need the comment to avoid syntax errors like if youβre injecting a union statement or order by or whatever
Srry I know this must be a bad explanation but this is how I understand it π
'OR 1=1 
Iβve heard that in real life pentesting you should be wary of using β OR 1=1β cuz you could accidentally get rid of data in an update or delete statement
Hello friends.
Thereβs a THM challenge room about that actually
Lesson learned
I certainly learned my lesson π
Oh ok I see weβre deleting shit how
idk why I said that
echo $g00d_n1ght
echo βdeez nutsβ | wall
oh i understand haha
SELECT * FROM users WHERE id='' OR '1'='1';--' AND private=0; for exemple this command take all user
even hide them
Object related sql > object oriented sql
where did you get double quotation marks
I just did an sql room, had a harder time detecting the vuln then injecting it
Habit
@cloud quiver what is the modification that you have to do to standard burpe suit to detect the error in repeater response?
I know some cpp so itβs kind of a habit for me to enclose any and all strings with double quotes
I can't even type double quotation mark unicode
Same
Also I might be gone for a while (making lunch)
All I got is quotation mark, double acute accent, grave accent
Thatβs fkn weird wdym
Hey everyone! A weird situation but on THM when accessing machines i am not able to connect to them.
Like when i click on access machine it deploys nd all, ip is generated everything but that machine isnt working when i ping it with other vm nd all
What to do? Anyhelp would be appreciated
" , Λ , ``
yoo, you know cpp too?
Yes
are you using vpn on your on machine ? can you ping 10.10.10.10 or open it in your browser ?
Iβve been learning it for the past 6 months or so for school
ask it here though
https://discord.com/channels/521382216299839518/521771811768107008
type shi, but mostly for international competitions
Before that I taught myself a bit of JS
Hahaha I think international competitions is a bit above my skillset
No, sure
i think it's just waste of time
, i only got some bread for winning prizes
Is it a waste of time if you get paid
the thing is, i get paid only 1 time a year, and it's not actually usual, dont think that 1 grand is worth it
and + bcz im not 18
Ohhh damn thatβs cool that youβre doing this shit as a minor
Also wdym 1 grand isnβt worth it 
1 grand a year for everyday working almost without rest huh?
Buddy, I spent all night coding an entire app, that was over 500 files, assets, and well..everything, and only got paid 500 dollars, be grateful.
that was a month ago, and I regret it.
xD
sorry for ya
Honestly I admit that I donβt have a ton of programming achievements, I kinda just fuck around and code random shit xd
if i want all name on user i write SELECT name FROM user WHERE id="" OR '1' = '1';--
XD, mbe u need just time
Yeah, adding a tautology should work. I would recommend against adding the semicolon though, it may not be interpreted correctly in a URL
and + with grand im surviving, imma tryna be independent from parents, and even be successfull already like in 22-23
ohhhhhhhhhh ok nice i understand litel haha
Also keep in mind that in SQL single quotes are used
but as soon as i enter cybersecurity, i understood, this, is, forkin, hell
- my grades are ass
Real
All As.
im a bit late to the party.. Just started the hackfinity .. wohoo
aaand im stuck in a task
π
if i won't make at least money for survival until 18 - imma be homeless
arrives
if the text is varcher I can use this or there is something more optimized because I think this is good for INT
like 1 night or multiple days of all night
Sorry Iβm not understanding what youβre trying to say
A single freaking night, like imagine debugging 20 lines per minute.
If the vulnerable parameter is an int, you donβt need the closing quote β
i mean, can you blame them? ass grades, nothing doing, + middle east parents
i juste need id = 1 ;--
isn't that like 50 bucks an hour
i wish
In this economy idk if living alone at 18 is feasible thatβs all
I know, should've been.
But it was a hackathon..
(it's not)
Fixed payout.
I mean technically living homeless is living alone
Yeah I live with my parents to save money xd
Not if your pentester buddies join you
it is not feasible living alone for most of the people nowadays, doesnt matter the age lol
@boreal scarab just to inform you RIGHT NOW
https://www.youtube.com/watch?v=CxTMHw-M0Yg
Find out more about Bitdefenderβs two decades of unparalleled cybersecurity excellence: https://bitdefend.me/TrustedNC
Itβs almost impossible to not get hacked in 2025. AI-powered malware, deepfake scams, super realistic phishing attacks are making EVERYONE vulnerable. So what do we do?? In this video, Iβll break down the top 5 cybersecurity t...
Maybe at 40 π
Well, depends on practices, 0days, how the digital arms race goes this year, etc.
i just dont know what to start with in cybers. it's really confusing, python, networking, operating systems, coding, cybersecurity fundamentals, defensive security, offensive security
DAMN
there is much more of a story in the post π
Don't worry I'll invent mole houses, smaller apartment building for individual groups of people to live together and not be lonely
fr, but mostly for lazy ahh people, and there are lots of em
Real, it is confusing
Just take it slow and choose one thing to focus on, you donβt need to learn everything at once
What part of cyber interests you the most?
i mean, of course ethical
For me itβs web pentesting/bug bounty. I am a fan of boot2root challenges too
hang on, I've seen this..probably didn't watch it all the way through or just forgot though..
you'll need to do for comp-scientist shelter too, you'll have way more people
i didn't. not his fan
you start by learning about all basics of how things work first, then you start learning more on individual topics
aaaaaaand new album of music added to the long long list of shadows flac files
but the opening makes it seem more like an OSINT tool.
so is it all in THM free courses?
THM has a lot of free rooms, but I would recommend doing more learning beyond just THM
HTB academy is really good, if you are a student their premium discount is around $8 a month
im broke af rn

Portswigger is free and has web pentesting materials too
no open source tech for soultaker it is then
If you are completely new to cyber I recommend doing thm fundamental rooms
such as pre-sec pathway?
Yes
well of course! The cs buildings will have servers in each room and it's own faster wifi lan system. Can put a satellite up there, blackout curtains and of course a public workshop in the basement
this dudes video titles are kinda... idk
more like...clickbait.
exactly
ur him
I need 25 mils just for the land
I must say that I donβt watch many hacking YouTubers
I get second hand embarrassment from CS videos
Idk why
Iβve watched a bit of pwnfunction and I enjoy his way of explaining things
Mostly I just watch john hammond because I like the way he kinda picks apart things like malware.
Iβve heard the malware he presents is quite basic but Im not really familiar with him
i was curious so now you know
Yeah, mostly.
i mean, i have sm money, but im just afraid that that'll go to trash
isn't open source stuff..free?
Or at least not much?
"Well, it worked on my pc"
@carmine tinsel would you live with other nerds in a custom building made just for them, with the complimentary free tech and communal area, sleeping capsules instead of own room, shared living rooms, "the quiet room", a lobby with that long couch with jazz playing 24/7, cleaning duty every sunday and very low rent?
shadow is talking about open source hardware
which yeah kinda free but the materials cost things often
also rgb lights in each room and automatic curtains
Ah, hardware. That makes more sense.
bro, i dont even know, imma done my researches mostly in youtube, cause as i know it's the only place that i can study sth for free
i mean, better than living in nowhere
we gotta add the hamburger truck at the entrance and ice cream machine in the lobby
Very true
I would be a very good landlord
nah, those for those who sit in discord 24/7 (not trynna be offensive)
I just pop in and out of here, haha
bro why yall active in night, or yall just in NA
Never coded at 3AM?
It's...fun..
i mean, didn't sleep for 2 days, and ONLY CODING
No I feel like theyβd smell bad
Cool, you understand. However uh..you may want to get some rest from time to time, at some point, your neurons will literally start dying.
im already braindead, wym
And that my friends is why guiness world records no longer accepts sleep related challenges.
(yes, actually)
Cool
and at this time i just play cs2 XD
Usually at that time I'd just be doing some OSINT thing.
tf is OSINT?
Open-Source Intelligence
damn
let me assure you, BETTA livingβ’ apartments uphold a standard above regular housing. Cleaning is mandatory, fresh clothes are given to everyone, fresh towels every day, multiple showers and automated air circulation. "People" that "smell bad" receive a warning before they are removed
im cooked fr
damn, i found my appartment
imma arrive to you as soon as my ahh'll be 18
ur a wizard, isn't that like high title? or what?
BETTA livingβ’οΈ is also an aquarium.
dam, ur a hacker, if not a secret, how old are ya?
I prefer not to say..
Finally home π
at least say that ur older 18...
ws
ehh...
if we get enough investors, we'll pay for international travels (1 way) if you are a student
Imma be fried
Alright.
so?
while on topic, could you consider BETTA livingβ’ your home?
I assure you Iβm not that great of a hacker xD itβs just that I have a thm addiction
Hacking is lowkey my hobby now
[Refrain]
Lead us when we fall, we are all prepared to die
When our time has come, and our blood will flow
Right down to Hel below
Hear us, together we will rise, we are all prepared to die
When our time has come, and our blood will flow
Right down to Hel below
@boreal scarab also... this worked with omg cable... =/
https://github.com/hak5/omg-payloads/blob/master/payloads/library/execution/Add_Local_Admin/payload.txt
Official payload library for the O.MG line of products from Mischief Gadgets - hak5/omg-payloads
I have no idea what that is and still have headache
damn
shadow is so happy they got the o.mg detector now
just gonna keep using it
ur addiction is givin you money
Girl itβs giving me a headache
I've seen that, hundreds of times actually.
there is some nice payloads for omg. some work some not so much
yeah shadow just got the detector though
omg 
because paranoia
i mean, gimme that addiction
Ooh
rhetorical question, of course you can. I can assure you, apart from our top of the line segmented apartments, we also offer individual private lands called "the aquariumsβ’ " where you get your own minimalistic style cozy private house
also sharkjack have some nice fro sure. no detector for it π
come again?
Private land where?
true that yea
o.mg cables are a cable with ability to inject payloads into computers
the detector blinks red if it finds one of those when you plug them together in a chain
gimme that shi
free gardening services, advanced soundproofing, nice neighborhood and of course privacy with our own garden sections
O.MG these cables are so powerful!
β€οΈ
sry, i may not have good level of English, so im just askin again
got all the hak5 gear
I saw a post on reddit that had those items and was like "what is inside of every hacker's backpack"
not all for sure
well..some.
yea. there is quite few for sure
unfortunately the world sucks and investors don't want affordable living for young adults

o.mg is a brand
they use technology from intelligence agencies that made a special cable with some chips in them
these chips could make the cable act like a keyboard and wifi
the keyboard ability let you run a long list of commands that can install malware or do other stuff
the cables from said inteligence agencies used to cost 20 000 usd
o.mg sells these cables on their site and on hak5:s store
the detector is used to detect these malicious cables to avoid you getting hacked by a malicious cable
My question is how does it detect them?
Just look at the two data lines inside every cable?
ohh, ok
Who's ready for TryHackMe leagues?
wait, what?!
#soon
π²
@sand trench know for this?
https://lab401.com/products/hunter-cat-card-skimmer-detector?srsltid=AfmBOor29NKkOcs8hAno8Wkh5PnhYY9du1xeJmCh7LPzpjmmk0e1zu_K
Hunter Cat: ATM Card Skimmer Detector The Hunter Cat is the world's first pocket ATM Card Skimmer Detector.Card Skimmers are devices containing magnetic readers that are covertly added onto / into ATMs, allowing criminals to 'skim' the data off a card's magnetic strip. Over time, Card Skimmers have become increasingly
I was definitely not ready for them when you asked, looking forward to it now π .
Should be really fun!
So we're going to have levels alongside leagues and a separate Koth leaderboard and also separate leaderboards for each CTF
I'm also going to be participating - hoping to get to the diamond league
It's going to become confusing with so many different leaderboards
I made pancakes
There isn't really leaderboards here - the honor will be the league you're in, and if you can stay in that league
Oh k
sounds like it'll be good fun π
I'd probably just drop to the lowest one, haha
Nah, you can do it
never seen that owner would talk in his own server
When I can I hop in and out
oh k
Can't say I've spoken to you before, it's a pleasure π
I like re-appearing every so often to be honest, I've got object permeance, if it's not in my peripheral I forget, it's the only reason duolingo succeeds in keeping my streak going
look at all the cables and what they are doing yeah
Likewise!
and also not sending any of said data into your computer
shouldn't be too hard to make one.
and only blink the led if malicious things happen
the threat of the bird taking my family and my mate nudging me to keep up our friend streak keeps me going haha
The duolingo nudge notifications are also so passive agressive it's hilarious
the cable or the detector???
detector
well go on... go make one
the duolingo instagram page is beautiful
I love it
if you can build one that is easy to use and easily blinks a led to tell you if it is working and or you have a malicious cable
Aaand I'm scarred for life.
to a comparable price
just a question, is this all i need?: https://tryhackme.com/hacktivities
You just know the admin loves it, just seeing how unhinged they can get haha
meanwhile:
10$
Depends on what you aim for.
I found a way to search without a browser
Lol
without leaving discord
curl
okay that's cheating
just open up a terminal window and you never left discord.
Discord is running through a browser.
offensive and defensive security, both of em
It's not that interesting anymore, I forgot about curl
evil π
The PC version is just electron, which embeds chromium.
meh, had a funny gif ("That's offensive") wouldn't load.
I misread that the first time
I thought you meant about daily driving windows in your standard web browser
Well, TryHackMe isn't the only resource out here. But it is a good one to begin with.
I re-read it and yeah, it makes more sense now haha
Anyone off their mind know good study habits? Not just in general, but semi-specific with the field.
Wat 
it did for everyone else
huh, weird.
mr robot himself is personally messaging me, I wonder with what he needs help with. Maybe we're hacking the fbi again
Does it also block the signals or just blink?
for example at first wanna be penetration tester, (0 knowledge of literally nothing, networks, etc), is this course legit for me? or should i at first go to other place?
it blocks the signals from the cable into your computer
blocking the signals:
just uh, severe the data parts of the cable.
dunno if it blocks the wifi chip in omg cables
Yeah it is beginner friendly.
so after studying this course, i just need some experience ig?
I aim to be a pentester and all my exp was when I started in 2021 was hacking my neighbors internet to download GTA san Andreas for the 360
Not only after, but always.
XD
THM is the best learning source I've used
Keep improving and you will see what you are passionate about.
imma aim cause im sick of my indexes being hacked

Then specialize in a field.
Also HTB

THM and HTB are my go-tos
so you started from 0 in THM?
Outside portswigger at least
from basically knowing nothing?
It's a long story, but yes
mine are random writeups i find online they give the best information
Very green att
it's funny i slipped both thm and htb lol
could you share some links?
There's endless sources of info if one knows where to look :)
?
Links for what? 0.o
The sites?
Any in particular
for learning from literally 0 penetration tester
Legit, THM is the best place to start.
Their learning structure is super easy to understand and very detailed. Also, they have trying lab VMs you can attack
Training*
It's like, a shooting range
I guess
can this be a pathway?
Love me some easy OT
?
.
i mean this
so what you think?
@sharp sail u here?
In the 4 or whatever years I've been using THM I've learned more than I would if I went to school.
Yes but no ping busy jorking
HTB can be difficult for first-timers. THM is perfect
so do you think this is good??
Damn bro has priorities
Yes
k, thanks
Gave +1 Rep to @oblique loom (current: #579 - 10)
are you sure
Yes
XD
did you double check
Yes

okay, but did you triple check after 2 minutes
No, but I am!
D:
Legit, me to me all day lol
jk? woah man, you can't do this to me. I thought I was your boss for a second there. I think I imagined our whole shift together when you asked me if I'm your boss. I had a family man, why did you do this, why did you destroy my reality and pulled me in the land of certainty!! WHYY GOODD WHY NO HELP LET ME BACK
You're fired good sir
I should not be allowed on the internet past 9pm
I should be studying, it's ok

@sharp sail
Be like me and have insomnia
@sharp sail
thought they said they were busy
@sharp sail wake up
Melo doesn't have any responsibilities
true
No ping busy jorking
NO PING!
@sharp sail
@sharp sail
@sharp sail
@sharp sail
Ok thanks @sharp sail
Gave +1 Rep to @sharp sail (current: #228 - 35)
Thanks @tiny hazel
Gave +1 Rep to @tiny hazel (current: #2759 - 1)
No worries @fossil merlin
Thanks @oblique loom


