#general

1 messages ยท Page 966 of 1

fallow glacier
#

No it;'s not to do with cheat sheet the NIC just kills itself after an NMAP scan, google cant be accessed, cant ping anything everything is dead, unless i restart vm it's fine again

finite basalt
#

James! how're you doing?

naive violet
naive violet
upper knoll
#

two different people asking about nmap

finite basalt
#

fair enough, same here haha

fallow glacier
upper knoll
finite basalt
#

I found out that both other module assignments are due on the same day as my diss is

naive violet
sharp citrusBOT
upper knoll
naive violet
finite basalt
#

so I have 3 weeks to finish the last bit of my lit review, do my experiment, analyse the findings, write that up (~3000-4000 words), finish setting up a server environment with active directory, write up a report on it all (4000 words), analyse evidence and write a slideshow presentation detailing findings while I crack on with non-academic work ๐Ÿ˜…

#

It's not looking good

finite basalt
naive violet
#

Arrives Monday

#

Should make it eaaaaassy to get digimodes

finite basalt
#

ahh class, let us know how it goes ๐Ÿ˜„

#

I've got my aws certification so once I finish uni my next is the radio license

desert wedge
#

You canโ€™t scan a local network from a VM unless your network adapter is set to bridged mode

naive violet
#

In NAT, works fine

desert wedge
#

nope

naive violet
#

I regularly do

knotty pendant
naive violet
#

It just needs to be able to route to the target - that's what NAT lets it do

desert wedge
#

but scan like nmap 192.168.1.0/24 wonโ€™t work

naive violet
#

Fully will

#

Regularly does

#

If you have the VM set up out of the box in vbox or VMware, it will just work

#

If you set it host-only, you start getting different behaviour

desert wedge
#

then you are in bridged mode

fallow glacier
#

NIC dies after nmap scan what do i do?

naive violet
desert wedge
#

okay, nvm

abstract dirge
#

hi

finite basalt
#

You can most definitely scan from a NAT, that's the premise of how most IPv4 LANs work if you access the internet haha

naive violet
#

Yeah just needs routing, easy as

finite basalt
#

I use nat for all my vms unless vmware's nat service shits itself

abstract dirge
#

I am new yall can say I know nothing I just wanna learn and can't find stuff to learn from can someone help me

sharp citrusBOT
finite basalt
#

not the right article ๐Ÿ˜ฆ

finite basalt
slate hemlock
abstract dirge
#

thank yall

gritty hatch
#

any one guys have this problem with responder
sudo responder -I eth0 -dwv

naive violet
#

That's just other stuff bound to those ports

#

Why do you think it's a problem?

gritty hatch
gritty hatch
naive violet
#

Nah it's just stuff on your box that's already using the ports assuming you're running it as root

#

If you don't care about http, rdp, and ldap, you can just ignore those

gritty hatch
#

so the responder is working even with this error messages?

naive violet
#

Yeah, except for those ports

gritty hatch
#

yeah m just wanna use the LLMNR

#

so yeah,thanks mate

naive violet
#

LLMNR is the poisoning part of it, the services then reicieve the hits for the poisoned names on their respective services

gritty hatch
#

so no need than for thoes since they are not related to this

#

if m right

naive violet
#

The request for an RDP session would get poisoned when resolved with llmnr, then the rdp request would point to responder not the actual destination

#

So it depends what traffic you're trying to get - usually SMB is fine

gritty hatch
#

yeah thats the point

finite basalt
#

my diss is now at 4750 words

#

we are cooking

desert dirge
#

James,
Lay the quill on the table, and step away from the cauldron.

finite basalt
#

I'm actually cooking so hard it's unreal

#

first pancakes, now diss

#

the golden syrup and nutella have got to my noggin

desert dirge
#

Man, I had some great ambient audio themed after planetary orbit in a vexor, on eve online - but I was using fedora as my OS at the time, fedora crashed and wiped my usb ๐Ÿ˜ฆ

Now I can't find it again

finite basalt
#

you should see my productivity playlist

#

it's anything but ambient

desert dirge
#

lmao

#

send

#

I shall purvey

finite basalt
#

tell you what, it gets shit done honestly

#

I played it one morning and I ended up being a top notch adult

desert dirge
#

Woah man, starting strong with starstorm

finite basalt
#

it is a random playlist honestly

desert dirge
#

Is there a sandstorm somewhere in there too

finite basalt
#

I ended up setting up a proxmox server, completing an assignment, ringing the bank and my landlord, going into uni, doing non-academic work and all

#

on no-sleep as well

finite basalt
#

I can fix that

devout palm
#

Yoo

finite basalt
hazy flame
#

best productivity track are storm chasers in the wild

devout palm
finite basalt
devout palm
#

Damn, when did you have a kid xd

finite basalt
finite basalt
desert dirge
finite basalt
#

I'd be an alright dad for the kid but I don't think that's very me-core

#

the only babies I'm after are covered in fur and meow

devout palm
#

Ok then alcohol?

#

Or work?

finite basalt
#

university work ๐Ÿ˜ญ

lone thistle
finite basalt
#

My career aspiration is to work from home and have many cats

#

you've heard of a crazy cat lady but wait till I'm crazy cat James

devout palm
lone thistle
#

maybe on discovery? who knows these days

#

gotta pay ยฃ200 p/m to find what you want to watch these days KEKW

finite basalt
#

yeah it's honestly my favourite docuseries of all time

#

I love trying to predict the reason for the crash

lone thistle
#

i used to freak myself out as a kid watching it before flying

finite basalt
#

I fell asleep on a flight to poland watching it ๐Ÿคฃ

lone thistle
#

you will enjoy mentour pilot on youtube james

finite basalt
#

I love him ๐Ÿ˜„

lone thistle
#

no ๐Ÿซถ

finite basalt
#

literally woke up and air crash investigations playing on my phone, my dad told me I was crazy for that, said he'd read a fiction book about a plane crashing on a plane but watching air crash investigation was just another level

#

Fell asleep and woke up in krakow with an episode about a military plane that crashed haha

grim sparrowBOT
#

:hammer: vlk.milf.eater#0 has been banned.

finite basalt
#

meanwhile kid behind me was watching lego ninjago

devout palm
#

Cool

lone thistle
#

cheers jabs

finite basalt
#

I'm a terrible person to fly with

#

I've been to poland twice, went with family and with school. When I went with school, I was sat next to my mate who was shit scared of flying, every slight bit of turbulence and I'd say "we're gonna die!!!"

lone thistle
#

๐Ÿ˜„ chaos

#

I've always wanted to go to Poland

finite basalt
#

I loved it, only bit I didn't like was driving near city centre, I wasn't driving but I was co-driving from the back-seat

#

My dad brought a garmin satnav with the latest maps and it tried to take us into pedestrian areas and the wrong way down one way streets

lone thistle
#

ah ๐Ÿ˜„

#

sounds about garmin icl

#

their "latest" maps are always like 5 years behind rofl

finite basalt
#

He didn't trust google maps for callouts and wouldn't use it so I ended up calling out directions using google maps like a regular map

#

He said "I'm gonna trust the satnav" and I said "you've done that and it's failed, my turn"

#

then after a while he said "where are you taking me" and I said "away from the city centre and towards the house", I'm an amazing co-driver, get me in rally racing fr

lone thistle
#

3 right, crest caution ditch leftKEKW

desert dirge
#

ooof!

finite basalt
#

also had to change a tyre at the side of the road cause after it took us down a one way the wrong way, we had to reverse in the dark and clipped a curb

#

so while the family was in the car, me and my dad took turns getting the car jacked up and the spare on while the other guarded the back of the car so we didn't get hit

#

very enjoyable trip, wouldn't recommend driving, it's also 50/50 whether places are wheelchair accessible, which did matter for us at times but if it's not an issue for you then you're all good
Also found my love for carrefours there

wooden totem
#

Google just gave me an ad for Ai image search anything and the "not interested" button doesn't work lol

finite basalt
#

man wait until bing tries to get you to accept or reject cookies and it just shits itself and starts glitching instead ๐Ÿคฃ

#

I hate microsoft's push for bing, I wouldn't care as much if it at least worked

wooden totem
#

They got the spirit, but bad execution

desert dirge
#

I'm just not a big fan of the AI buttons they keep forcing into laptop keyboards, it totally screws with my workflow

#

Especially when they replace the Fn or Super keys with the AI key

#

I saw one laptop where they replaced the backspace key with the AI key

wooden totem
#

That sounds too stupid to be real

desert dirge
#

I was trudging around different best-buys and walmarts in the bay area looking for a laptop around 10-11 screen size to fit in my sling backpack, that's the only reason I found those

#

It was the weirdest experience lol

#

The prices were strange too, 800-2k for some of them

polar shale
#

hi

desert dirge
#

Hello Blake o/

alpine swallow
#

Given that the event is over can we discuss some of the flags

sand trench
#

welp time to call it a night and get some well deserverd meep moops while sleep sloops to beep boops

devout palm
#

Night

wooden totem
# devout palm Night

You're absolutely right, it's not a good night, it's just a night tonight because a satisfying time was missed by 1 minute

wooden totem
desert dirge
wooden totem
#

What does the number you sent mean

desert dirge
#

It's just the funny numbers dumb kids like me laugh at lmao

wooden totem
desert dirge
#

Well, if you go to bed at 00:45, that's exactly 1/4 of an hour, of which the denominator is an even number. Does that help?

wooden totem
#

I always get reminded to put my phone down and go to sleep when I see shadow in chat, as it so happens we go to sleep at the same time

wooden totem
sterile spear
#

helo guys do u have any idea when the writeups will be available?

sterile spear
#

alr thx

vast egret
#

Used to have to go to sleep in pitch black darkness and no sound. Wife changed that as she need some light and sound.. So had to get used to it

sterile spear
#

if you dont wanna be blind at 50

wooden totem
#

No sound and darkness is actually more healthy

vast egret
#

That was my thought?

wooden totem
#

I personally have sound isolation and a night light because I feel uneasy in pitch dark and I fall asleep easier knowing I can recon the room in less than a second

#

Idk why I have this feeling, I would've preferred pitch dark

vast egret
#

Makes sense, Although my eyes would get acclimated to the dark and would be able to see fairly quickly

wooden totem
#

Super low resolution

#

You know when you stare at the void and you just see static of your eyes

vast egret
#

Yup haha, sometimes I would just lay there and stare into the darkness. Very relaxing, but I can see why some don't like it

#

I assumed you figured out how to link to discord as you deleted the message?

true rock
#

erm what the Sigma?

true rock
twin ridgeBOT
#

Gave +1 Rep to @vast egret (current: #2763 - 1)

vast egret
#

Yeah no problem. Was going to help if need be

oak river
#

Do printers keep logs of what they have printed in themself in some way?

#

Im talking about a 100$ black and white brothers printer for example?

vast egret
#

No they ususally do not. Sometime they do store a temp job history but this gets deleted after shutdown/reboot

oak river
#

I'm asking that because I became curious, since some time ago I saw something about police "Seizing a printer" and I was like wtf

modest thicket
#

Damn i just ate a few handfuls of pumpkin seeds a few minutes ago and it feels like flowers are growing in my stomach in the best way possible.. im torn between associating the Senzu bean from Dragon Ball Z to a pistachio or a pumpkin seed.. both are highly nutritious..

oak river
#

Nuts are good and nutritious indeed

#

I used to eat raw nuts non-stop as snack back in gymnasium/high-school

#

Cheap and healthy and full of proteins

#

Good news - Finally encrypted my USB + a hidden volume

#

I guess I put way too much data on it during the encryption process itself

vast egret
#

Maybe they can get metadata from it? Not too sure on that

oak river
#

Yes, but what someone would be more concerned is if they can get some documents, images or maybe passwords

#

Since someone might use a printer to print passwords on paper instead of write them if they are long

#

But metadata might not be helpful in such a case?

#

"That's an interesting observation! While printers themselves may not retain data long-term, there are a few reasons why police might confiscate one:

  1. Forensic Evidence: Some printers embed unique identifiers, like microscopic dots (known as machine identification codes), on printed documents. These can be used to trace the printer that produced a specific document.
  2. Connected Devices: If the printer is part of a network or connected to a computer, it might be seized to investigate the associated devices for evidence.
  3. Criminal Activity: In cases involving counterfeit documents, forged currency, or other illegal activities, printers might be confiscated as tools of the crime.
  4. Stored Logs: As mentioned earlier, some high-end printers or multifunction devices may store logs of recent print jobs, which could be relevant in an investigation.

Itโ€™s fascinating how even seemingly mundane devices can play a role in investigations! Does this align with what you were thinking?"

#

That's what Co-Pilot told me

#

I guess they can trace the machines that produced the data, but not the data that was outputted of the printer itself

#

Otherwise there wouldn't be second-hand printer devices for sale?

#

Good that my curiosity has been satisfied now

ashen marsh
#

yo

#

???

marble flume
#

yoo

silent nova
#

๐Ÿ‘‹

chilly veldt
#

it's tax season right now, and I just got notified I have to pay โ‚ฌ3,228.7 in residual tax, watch me turn that into them giving me money

chilly veldt
#

yup

ashen marsh
#

how much was tax on that

chilly veldt
#

there's no apartment tax

ashen marsh
#

{

#

printf("how much was taxt on that");

#

}

#

else

#

{

#

printf("ok");

#

}

desert dirge
#

o ok lol

topaz pecan
#

Pluh

topaz pecan
chilly veldt
# ashen marsh printf("how much was taxt on that");

so to explain why it's so much, I do a lot of tax work arounds to pay less tax, and when the yearly tax statement comes around those work arounds are not added at first, so I have to go in and do my magic for the actual number

#

so generally my monthly tax payments are like 60% lowered, and when the statement comes around they are like "you're missing paying for 45% of your taxes"

proper sable
#

.......

grizzled wing
chilly veldt
next vector
#

Hello anyone available for practice dm me if you have premium so we can study and do some boxes

grizzled wing
#

the best surgeon is here

steady pewter
grizzled wing
#

nice work

steady pewter
grizzled wing
steady pewter
grizzled wing
# steady pewter They are

Guinea_Pig_Lord has file taxes in the amount of || lots of money, so much || in the tax haven of || some tropical island || and is known to || hack computers || storing financial information in || secret file folders ||

next vector
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4131)

steady pewter
#

So how is everyone this evening?

gritty hatch
#

any idea all ports filtered

#

is it because of ufw?

steady pewter
grizzled wing
#

forgot about carbon

gritty hatch
steady pewter
gritty hatch
#

checking for smb signing but all filtered

grizzled wing
meager blade
#

over 2000 events in one day

#

seems fishy

grizzled wing
#

it is

steady pewter
meager blade
#

it's a bad look

grizzled wing
#

they took THM to heart

meager blade
#

apparantly

steady pewter
meager blade
#

just wondering why they still have an account/are still on the leaderboard since that most likely violates the terms of the site

grizzled wing
#

someone will get to it in 5 to 10 business days

#

meanwhile we get to marvel at this cheater

steady pewter
#

Lemme get the popcorn.

grizzled wing
#

๐Ÿฟ

steady pewter
#

๐Ÿฟ

grizzled wing
#
  • ๐Ÿงˆ
meager blade
#

it would be cool if they patched it then did a blog post about what happened and how they fixed it.

desert dirge
#

I used to note answers for each room, and come back and submit a few answers a day just to keep my streak going cause I'd miss some days due to irl stuff, so I could earn the badge.

I have since stopped submitting answers cause of other irl projects and I still have like 300 answers or so queued. I could submit all of them today and look just like our boy C-Hack

#

In fact, I should probably just do that, they're sorta wasting away in my notes at this point lmao

meager blade
#

but they only have a couple rooms completed

#

it has to be something else

steep kestrel
#

Okay โœ…

desert dirge
#

oph, oh yeah lmao

#

duh

#

my bad lmao

steep kestrel
#

And how long have you been on this

meager blade
#

maybe they did some automated virtual machines

#

i think it says starting a virtual machine counts as an event

desert dirge
#

oh maybe

meager blade
#

so just loading a buttload of tabs at once, start the attackbox or we

desert dirge
#

machines started, questions answered, file downloads

meager blade
#

yup

desert dirge
#

that's insane

desert dirge
#

Well, looks like the questions and answers have since changed. I guess I'll just review the rooms lol

rapid merlin
#

does anyone use obisidian for THM notes. if you do, do you mind sharing. Im trying to get a good list of notes going, like a master list.

steep kestrel
#

Okay ๐Ÿ‘Œ

steep kestrel
rapid merlin
#

so not much

steep kestrel
#

Okay

#

Work with your inbox okay

steep kestrel
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @steep kestrel (current: #1816 - 2)

celest dirge
steep kestrel
#

Okay

#

You should be able to access that from your tools ๐Ÿงฐ

rapid merlin
soft bramble
celest dirge
rapid merlin
celest dirge
wicked sage
celest dirge
#

Gotta thank HTBA for increasing my attention span. Reading walls of texts helps me read other walls of texts (like terms of service)

soft bramble
#

Okagg

wicked sage
celest dirge
#

I'm starting to enjoy reading quite a lot more than watching just videos.

wicked sage
#

I filled up my bookshelves And my nightstand

wheat spear
#

just want to ask is the sandisk ultra flair flashdrive is good for dual boot (kali linux)

celest dirge
wicked sage
carmine tinsel
celest dirge
#

Lmfao

steady pewter
quasi hedge
#

Any ideas how I can become a room tester?

steep kestrel
#

Okay โœ…

#

Yes mate

steady pewter
#

"Now let's see if my Tesla K80 survives this!"

carmine tinsel
#

yk my room isn't really a hacking chamber like some ppl in the community

#

its just me and my hello kitty collection

wicked sage
#

Cute

steady pewter
#

wait, how do you become a room tester?

graceful void
#

Is there any room to learn Cortex xdr?

cloud quiver
graceful void
#

k, thanks!

steady pewter
#

I wonder how many people are still online as general went quiet again.

quasi hedge
#

Still online

steady pewter
#

huh.

jovial mist
#

Hii people

steady pewter
#

So how was everyone's day?

graceful void
#

You guys think its worth gettin a bachealor in cs or send it full in certificates?

jovial mist
graceful void
#

And i meant masters*

grizzled wing
graceful void
#

Cus im about to finish the bachelors but ive been thinking moving to the states and get it

#

Or should i focus more on certificates?

celest dirge
fossil merlin
#

Hey gang

graceful void
celest dirge
#

Mhm

#

I think one of my reasons for using this platform is back to when I was taking a class that was focused on CompTIA sec+, but the content felt more theoretical and less practical.

celest dirge
#

My class heavily relied on Cengage

grizzled wing
#

๐Ÿ““ what have you learned ?

graceful void
tall turtle
grizzled wing
#

locked in ebooks

graceful void
#

Its something common in usa?

hollow rock
#

Is pico CTFs a good place to practice CTFs?

grizzled wing
grizzled wing
graceful void
#

yea i know pearson

#

didnt know

#

Good to know!

celest dirge
grizzled wing
celest dirge
#

We still do paper tests, except we can use a calculator and Statcrunch for some problems.

grizzled wing
#

i enjoyed stats

#

not sure what statcrunch is

celest dirge
#

It's used for calculating and putting numbers into charts

#

Rather than having to remember formulas

cloud quiver
grizzled wing
#

i see, so you dont have to figure out the z-score ? it does it for you

celest dirge
#

Pretty much

grizzled wing
#

i should make a tool named kool-aid , would be so fun sudo apt install kool-aid

celest dirge
grizzled wing
#

Khan Academy is still around

celest dirge
#

It's been awhile since I've used it.

steady pewter
prisma pasture
#

make it a backdoor

steady pewter
prisma pasture
crystal mauve
#

sleepy time ~_~ goodnight all

steady pewter
carmine tinsel
#

Actually is there a way that I can try picoctf previous challenges

cold veldt
#

Previous year ones?

carmine tinsel
#

Yeah

cold veldt
#

They are all open in picogym though

knotty pendant
#

George foreman died๐Ÿ˜ข

carmine tinsel
fossil merlin
steady pewter
#

what the heck?!

knotty pendant
#

Huh

#

2020

steady pewter
blissful current
#

why my rank is not updated here , last time it did quickly lol

cloud quiver
blissful current
#

ah ok

#

what was the command again?

#

!verify

#

?

cloud quiver
#

and your token afterwards

blissful current
#

ah thx ๐Ÿซก

#

noice, done

steady pewter
#

Meanwhile I'm still [HACKER] even after 3 years, haha.

twin prawn
#

Hello

blissful current
twin ridgeBOT
#

Gave +1 Rep to @steady pewter (current: #465 - 13)

blissful current
steady pewter
blissful current
#

Oh ok

#

figures , Im veri unemployed unlike y'all

twin prawn
#

I came here cause I saw a video called โ€œI took a CIA testโ€ where he did the sakura room

twin prawn
#

Yeah I know it was just the title

kindred yew
#

Good morning chat

blissful current
steady pewter
blissful current
twin prawn
#

Itโ€™s 11 pm for me

blissful current
steady pewter
blissful current
#

probably

#

seems like so

carmine tinsel
#

We're all CIA members

#

Do geolocating images room and you get invited to be CIA director

steady pewter
#

I got invited, and rejected the offer, on the run right now.

sinful moon
#

quick do a british crime movie and snap your SIM card in half! Surely thatโ€™s the only way you can be tracked

#

in the 00s when these movies were set

#

sadly I have a device which is just eSIM so I guess I just have to snap my entire phone in half which is a bit more difficult

#

I will admit for real, I do dislike that about eSIM greatly, they try to sell it as even easier than swapping SIMs but yeah clearly less consumer control or choice

fringe nacelle
#

Interesting

sinful moon
#

lol which is? eSIM is kinda BS but itโ€™s โ€œthe way of the futureโ€ and will be pushed on more people over time

#

But honestly itโ€™ll just be like old CDMA phones and etc where you have to work with the carrier anyways

fringe nacelle
#

Ngl I feel like esim will be a bigger vulnerability than just physical sims lol like unless I'm missing something

sinful moon
#

I wouldnโ€™t say itโ€™s as much a vulnerability as much as it is a liability

#

Thereโ€™s nothing inherently different software/hardware wise other than the module is permanently embedded. So itโ€™s just a pain to transfer

blissful current
fringe nacelle
sinful moon
#

It just sucks because without any contact to your carrier you could be like โ€œnah Iโ€™m using this phone nowโ€ and the Carrier had 0 input or interaction

#

for physical SIMs

#

I did that several times and it felt like magic. I never bought phones on contract as well (majority in the US do) so felt like using cheat codes irl lol

#

They โ€sayโ€ it should be that easy with eSIM but we have some ways to go before that lol. And very little motivation to make it easy for consumers

#

lol I saw that, and yee the US phone market just sucks in particular

desert dirge
sinful moon
#

nah it was more than reasonable

#

anyways lol I donโ€™t have much more to say, other than double check if your new phone will have a physical SIM slot, but RIP if you want to hold on to that forever

split plover
#

Hey guys, I'm using foxy-proxy and burp. But the no site loads. It keeps buffering.

#

Is there something else I need to do that I'm not aware of?

sinful moon
sinful moon
desert dirge
sinful moon
#

Yeah KGB has a point, depend what youโ€™re trying to do with Burp

#

I go hard and ssh tunnel my HTTP(S) traffic from my remote pentesting server to Burp, then tell Burp to be a SOCKS proxy, then Foxy Proxy shows me what my remote server can see, but locally lol

split compass
#

The way a lot of eSIM is being handled feels like Sprint Nextel era CDMA "Yes I can activate your phone to your account, can you verify which phone number you would like attached to the phone? Excellent I'm going to have to look under the battery now, I'm going to need you to read two identifiers for me, first look for one marked "ESN"'

So little planning our advancement.

split compass
sinful moon
#

mhmm, when I first heard eSIMโ€™s concepts, I immediately thought, ugh this is just like dealing with CDMA phones changes indeed

split compass
#

It has some technical advantages over GSM, but SIM won as a convenience factor.

#

So now we get the worst of both

sinful moon
#

Yeah I just hate that they threw that all away. I get why, both actual consumer friendly size stuff andโ€ฆ consumer unfriendly lock in

sinful moon
desert dirge
sinful moon
#

This is like basic Burp use, a setup guide on THM or elsewhere would detail what you need to do

#

so Iโ€™m curious what exactly is going wrong

desert dirge
#

I made the mistake of buying a vendor locked samsung instead of an unlocked pixel on my last upgrade

sinful moon
#

But lol I also canโ€™t say Iโ€™m a Burp expert, since I just have used this setup for 97% of my time

sinful moon
desert dirge
#

I really wanted to try out graphene but I need a pixel for that

sinful moon
#

Not nessessarily?

desert dirge
#

You can try to do it on samsungs but it fries the embedded security chip

sinful moon
#

Although yeah Samsung phones are a pain in the butt to actually get unlocked bootloader going

desert dirge
#

what the- lol

sinful moon
#

yeah idk lol

desert dirge
#

zumi posts that same gif a lot huh

sinful moon
#

anyways yeah Pixel, Nothing and OnePlus are usually pretty friendly to unlocking the bootloader. Motorola is too but theyโ€™ve gone down hill as a company over the years

desert dirge
#

rippp, motorola is actually one I wanted to get too

sinful moon
#

They used to be soooooo good before Lenovo bought them up

#

aka a Chinese megacorp

#

My Moto G3 I got customized like case design because they still had that back then, it was so rad

#

I ordered the purple back and black front, black camera cutout (no bump back then)

desert dirge
#

Yeah. I'm big dumbo, I misunderstood the lenovo hype and bought a brand new lenovo workstation laptop, paid big for it too.

fringe nacelle
#

Whoops

sinful moon
#

I mean their PCs arenโ€™t awful, hopefully you got Thinkpad instead of just Lenovo, not that thereโ€™s a ton of difference there

#

Iโ€™m just skeptical of them after they kinda wrecked my fave Motorola

sinful moon
desert dirge
#

oh no, flashbacks

split plover
#

๐Ÿ™‚

desert dirge
sinful moon
#

Personally for laptops I go Asus Zephryus devices, kinda a mix between gaming laptop and ugh, โ€œultrabookโ€ but theyโ€™re really appealing

desert dirge
#

Asus is pretty nice. Lately I've been a big fan of HP for their return to recyclable, repairable, and easily moddable systems

sinful moon
rapid merlin
#

Guys when are site staff gonna remove that guy ConnorHack

sinful moon
#

Friends and family IT wise, HP laptops have been hell on earth

#

single HP laptop I got as a hand me down also had a bulging battery when I got it and was generally meh

desert dirge
#

Oh yeah... sheeeeeeesh...

#

That's exactly the issues we had with them. Oversized with dangerous battery and overheating issues

sinful moon
#

now HP Enterprise just kills it, but yeah I will never consciously buy an HP consumer device

sinful moon
#

Also lol, just fans getting clogged on laptops, and whoops, gotta completely disassemble the laptop to even get to those fans

desert dirge
#

I switched to their hp streams though, upgrade the ram, replace the wifi card, wipe the HDD and write it with kubuntu. Fixes everything

sinful moon
#

some of the biggest pains in the butt Iโ€™ve ever had working on electronics

#

lol arent those the successors to their netbooks? Donโ€™t get me wrong, contrary to popular opinion, I actually loved the netbook concept, but didntโ€™ know the HP Stream brand was still alive

desert dirge
#

Not sure, but they're super cheap, and I keep finding newer models

sinful moon
#

I am typing this all on an iPad with a physical keyboard and touchpad mouse so yeah basically just a netbook rn lol

#

yeah fair enough

desert dirge
#

haha

#

it really is basically a netbook though

sinful moon
#

a lot of companies like take their Chromecast models and just make them normal super cheap x86 laptops again

#

Not that they were ARM before, just that they are normal PC compat

desert dirge
#

right

sinful moon
#

Iโ€™ve got some cheap devices like that before. My newest is now my mousepad for when I play KB/M games on my bed lol

desert dirge
#

lol nice

sinful moon
#

lol it probably runs 2017 era Arch on it, it hasnโ€™t been booted in that long

topaz topaz
sinful moon
#

but lol I got it for โ€œfreeโ€ with an amazon $150 gift card back then and I was like, idfk what to do with this

#

lets get a cheap computer

steady pewter
#

hello

topaz topaz
#

Good morning to everyonee

steady pewter
topaz topaz
#

Close enough

sinful moon
topaz topaz
#

Just so you know how far behind as a grandpa I am : I used to use ipads during the iOS 6 era, knew em inside out

#

Then iOS 7 came with its mininalistic looks and it was so fresh and beautiful back then

sinful moon
#

Heck Iโ€™m a bit of a sucker too, M4 iPad Pro is what I upgraded to since I use this daily and gotta have dat OLED lol

#

Thatโ€™s fair FUG, I just did a decade+ of Android instead

desert dirge
#

I wish I had a nice pretty mac to play with. I haven't used macs since leopard

sinful moon
#

yeah I do enjoy my M4 Mac Mini quite a bit, but itโ€™s just my personal side machine in work from home setup

topaz topaz
topaz topaz
sinful moon
#

Yep canโ€™t argue with that

#

I just use every OS I can get my hands on honestly

topaz topaz
#

What's your most noteworthy OS?

sinful moon
#

and have settled down in some fields like tablet with iOS honestly kinda being undisputed winner lol

sinful moon
topaz topaz
#

If I were to have a tablet I'd wanna download lots of stuff on it so I'd probably go with something non-OS, especially since I like downloading manuals and books

topaz topaz
sinful moon
#

Books I have my Kobo eink ebook reader, comics and manuals I have Panels on my iPad

desert dirge
eager marsh
#

do you guys have a prefrence for c2?

topaz topaz
desert dirge
sinful moon
#

my personal pentesting server is acutally arch as well, still going strong five years on, and thatโ€™s short in the timespan of my Arch installs

topaz topaz
#

Market**

sinful moon
eager marsh
sinful moon
#

also who needs a big SD card when all your files are on your NAS lol

desert dirge
#

The issue with microSD cards is that like other ssd cards they can fail easily, so I try not to rely on them for main storage, just localized data access. You can use Syncthing-Fork on your android device and Syncthing on your primary storage device to sync a folder of books you're currently reading / checked out, so you dont have to carry everything with you

sinful moon
#

I just have this 512GB iPad and switch out what I need

desert dirge
#

There are other apps that can sync things for you, even e-reader apps that sync libraries, but that's a whole other conversation and rabbit hole that depends on your preferences

sinful moon
#

I donโ€™t need my complete library of [x] media, just what Iโ€™m reading/consuming/watching at the time, if that

#

Heck even disk images for OSes and software for VMs or computer emulators both on iPad and full computers, I just run directly from the NAS half the time

eager marsh
sinful moon
#

yep Silver is quite nice, I just donโ€™t see any issue with getting experience with many common ones while you are learning

#

just without further obfuscation, EDRs are going to more than pick up on them out of the box

#

but yeah depends on your goals

eager marsh
sinful moon
#

even without signature based stuff, EDRs are going to be like, woah this software is doing x y and z which looks shady, which it just finds via heuristics and actually embedding its self in each application to trace all API calls and more

eager marsh
#

I am aware of EDRs

sinful moon
#

Totally fair, was just saying since I administrate one and a managed SOC for it

#

Heck Steam games (obvs especially with anti-cheat) can easily set them off as a human determined False Positive

#

lol, you donโ€™t argue when the guy whoโ€™s last name is the companies name as your client, if he can play games on his PC or not

eager marsh
#

Elizabeth I'm not some skid

sinful moon
#

No I know, and Iโ€™m sorry if I came off like I was talking down or anything

#

was just trying to provide some insight at managing an EDR at work

desert dirge
# topaz topaz What's your most noteworthy OS?

Just to throw my 2 cents in, I picked Kubuntu.

Ubuntu because I wanted to protect my attention, focus, and energy. Arch was one of my favorite picks because of the modularity, but I wanted a stable base to learn from, without my workspace becoming an attention hogging hobby.

I had switched from Gnome Desktop Environment to DWM Window Manager because I loved the freedom it gave me, but maintaining it, and the amount of work I had to do to get functionality I needed for workflow was rough. After a bit I realized I could get the core workflow functionality I wanted from KDE Plasma, without any of the work. So I just made the easy choice.

sinful moon
#

They are a fickle beast, but I much rather have it be overly cautious than miss something obvious

#

had it stop Trickbot and Qbot dead in its tracks and whew, was wild to see those big names

#

Typically stage one dropper launches and EDR is like wut, but just keeps an eye on things, but the moment stage 2 starts EDR is like NOPE

desert dirge
#

Are we able to deploy EDR on KOTH rooms?

#

Should we even?

sinful moon
#

no? Unless you wanna do a Wazzah install if that even counts lol

desert dirge
#

lmao

sinful moon
#

lol just most EDR products are unfortunately paid products for sure

desert dirge
#

Yeah I didn't even think of that

sinful moon
#

Yeah typically $3-4 per month per endpoint, depending on how steep a cut you get for volume of endpoints

#

at least as a reseller that is

desert dirge
#

sheesh, I am not made of money. lmao

sinful moon
#

yeah lol, this is stuff you use defensively at work and not for fun sadly

#

they make it a pain in the butt to even run stuff by these engines personally besides what they expose to VirusTotal

desert dirge
#

Would be nice to get a lab discount, or lab price, so we can play with it

sinful moon
#

Yeah theyโ€™re too worried about people reversing these to dig into breaking them and etc sadly

desert dirge
#

oh well.

sinful moon
#

mhmm, VirusTotal is usually a pretty decent determination anyways though

#

although lol, none of the behavior based detections from my EDR at work actually show that the same product โ€œdetected itโ€ in VirusTotal

#

btw if I see WaveBrowser PUP one more time I will scream lol

#

holy crap that adware browser is everywhere

#

especially in โ€œPDF Fixerโ€ style applications, all PUP. Why do our users feel they need to search for an app to fix PDFs, call us orโ€ฆ you know like take advantage of the Adobe Acrobat Pro license you all have

#

it hurts my head sometimes lol

#

I seem to have out chatted chat, but if you all are curious, AMA working in both defensive infosec and minor offensive infosec professionally

#

lol what do you mean

desert dirge
sinful moon
#

lol thatโ€™s what it sounded like, no worries, but like if youโ€™re here youโ€™re already well ahead of the general pack attempting, erm, computing lol

#

Trust me, any user here is most often on a much higher level than our end users lol

desert dirge
#

If you can call it that, lol

blissful current
sinful moon
#

You wouldnโ€™t believe how many of our users fall for fake โ€œClick Allow if youโ€™re not a Robotโ€ style scam, in browsersโ€ฆ allowing Notifications from malicious sites which send McAfee and Norton fake AV notifications

blissful current
#

quote time

sinful moon
#

one user asked for a step by step guide to like clean this on her home computer today, because her husband keeps fricking up and clicking bad linksโ€ฆ and saying Allow Notifications lol

blissful current
#

maybe yes quote

carmine tinsel
#

'hot single women in your area' popups

#

do ppl fall for those

sinful moon
#

I already cleaned them from her home computer like ealier this week and it happened again

blissful current
sinful moon
#

They apperently do lol

carmine tinsel
#

something tells me that all the hot single women in my area are purely interested in tech obsessed cybersec nerds

desert dirge
#

Yeah, they do unfortunately. Usually it's lonely people

blissful current
#

meanwhile me : i just wanna download my movie/game, move aside 'single hot woman'

desert dirge
#

I used to work as a waiter at a restaurant. Had this old guy come in all the time and brag about the cute young thing he was seeing, show me 'pictures' of her and tell me about all the problems she's having that he's helping her solve by sending her $240/wk. People always told him she wasn't real and was scamming him, he said he didn't believe them, and I don't think he ever could let himself believe that.

#

I never expected to see that in person

carmine tinsel
#

Sigh

#

Why do ppl fall for that shit man

pliant bronze
#

@dusk canyon Are you free now.?

blissful current
carmine tinsel
#

Alternate timeline where I joined HTB before THM and became a discord kitten for cubes

dusk canyon
pliant bronze
dusk canyon
#

@pliant bronze waiting for reply

pliant bronze
carmine tinsel
#

their cube system genuinely puzzles me, how do they charge for premium and their certs and still have their own ingame currency lol

#

huh

#

discord kitten hacker is crazy

twin ridgeBOT
#

๐Ÿ”Š Unmuted elizabethnoir

carmine tinsel
#

real

steady pewter
desert dirge
#

Stay safe out there bois, these things happen because of psychological vulnerability. Protect yourself, socialize regularly, and practice self love

blissful current
split compass
carmine tinsel
#

tbh i think htb modules are more high quality than thm

blissful current
sinful moon
#

I tried hard to convince my boss to deploy uBlock Origin via GPO and similar but he was not having it for whatever reason

#

But fair Chrome kneecapped all adblockers soon after with the Manifest v3 changes

blissful current
carmine tinsel
#

chrome cracking down on adblockers is literally 1984 noooooo

cloud quiver
sinful moon
carmine tinsel
#

cuss words not allowed now

steady pewter
steady pewter
blissful current
sinful moon
cloud quiver
# steady pewter huh.

There're some words for which the bot will automatically mute you if you include them in a text or a link that you send

carmine tinsel
#

what words

#

let me test it

sinful moon
#

nice try lol

desert dirge
#

say them again

carmine tinsel
#

wait

#

ohhh

#

im slow

steady pewter
sinful moon
#

anyways lol, yeah I so wish I was allowed to push adblocking out to all our users because holy crap would that save me tons of hassle

cloud quiver
sinful moon
#

My boss already uses Firefox

split compass
sinful moon
desert dirge
#

Here, let me fix that for you.

Elizarizz

sinful moon
#

lol just groan at you all

split compass
#

At least the young and hip crowd accept you. ๐Ÿ˜

desert dirge
#

Her new catchphrase is gonna be "I'm goNoirRizz you up"

sinful moon
#

I mean heck our new Unifi gateways also offer some form of adblocking but meh, Iโ€™m not jumping to test that though lol

split compass
#

Oh, you get the ones with the RGB Ethernet ports?

sinful moon
#

Nah, was just thinking of the Unifi Gateway Maxes, they just have white LEDs for the Ethernet on the back. You gotta go rackmount for the crazy RGB ones lol

split compass
#

Yeah they amuse me. ๐Ÿ˜…

sinful moon
#

Mhmm and I will say it can be killer at home too but sure not cheap

#

Wild to have mobile apps where you can actually monitor/configure basically everything

#

Vast majority of the time these vendor apps are crap

split compass
#

I missed out on an auction for Arista 7060cx-32s talk about expensive. I had two bidders against me, so stopped at $350... It went at $420, I should have stayed. ๐Ÿ˜“

#

And yeah, I like the home/small user first approach they took.

Results in a much better app experience but the time that start making Enterprise gear

sinful moon
#

Never even heard of that brand but yeah looks/sounds solid from a quick search

split compass
sinful moon
#

Bit insane, but yeah probably much much higher scalability needs than our small to medium businesses

split compass
#

Do I need 32ports of 100Gbps at home, no... But at the price...

sinful moon
#

lolol

#

Yeah, Iโ€™ll be happy just getting 2.5Gbs network in order

split compass
#

I have these weird Wedge400 switches coming in now.

sinful moon
#

My SO finally acquiesced and let me take over the home network and whew, it was about time.

sinful moon
#

So lol Unifi Gateway Max and self hosted server was the only thing I have done thus far

split compass
desert dirge
#

ohhh

#

okay that makes a lot of sense then

sinful moon
desert dirge
#

oof lmao

wooden totem
fringe quarry
#

how to connect the

#

roles

#

to my progile

#

porfile

#

profile

cloud quiver
sinful moon
#

I moved into his place orignally so I just kinda lived with it for a while

fringe quarry
sharp citrusBOT
wooden totem
split compass
#

Everyone beat me to it

sinful moon
wooden totem
#

aint nobody reading the bot stuff

desert dirge
#

Sassy Betta today

cloud quiver
sinful moon
#

bah humbug, but thanks for the info

#

thatโ€™s not going to throw anyone off thought

split compass
#

Non sequitur: I started Kung Fu this week. One of my senior students is a highschool kid with an interest in computing.
I told him to check out THM and discord.
So that might happen this weekend.

sick lance
#

Its due to how to works.

The Student verification article was edited recently due to an event

sick lance
#

The doc command isn't linked to a doc,.it just searches for the more apt one.

sinful moon
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3548)

desert dirge
#

Well, I've been up 2 hours past bedtime by now. Good night everybody.

split compass
sinful moon
desert dirge
#

Ditto!

split compass
#

Night

leaden marsh
#

Question about cert when will release??

split compass
#

It released

leaden marsh
#

In the website of tryhackme?

sick lance
leaden marsh
blissful current
#

interesting , Sponsored by PerplexityAI, me n my team got free enterprise pro subscription

sick lance
blissful current
split compass
#

Oh, I was assuming the SAL1

leaden marsh
#

ILOVE TRYHACKME

blissful current
rugged galleon
#

verify

sinful moon
#

lol sorry but have you all seen the vibe coding โ€œmemesโ€, as a result of people misusing/misunderstanding devops?

blissful current
sinful moon
#

This is amazing:

blissful current
sinful moon
sinful moon
#

Another work of art

blissful current
sinful moon
#

Iโ€™ve seen people joke that this is going to lead to another 90s era of like dramatically insecure code, and yeah weโ€™ve kinda been seeing that happen

sinful moon
#

lol good luck and gโ€™night!

steady pewter
sinful moon
#

lol Iโ€™m not taking off, just wishing Enumeration such

blissful current
#

same

leaden marsh
#

When the cerft will release please

blissful current
#

i have technical exam in 30 min (I'm cooked)

#

i'll start it after 2 hrs tho

cloud quiver
#

No , we don't do that here ๐Ÿ™‚

idle beacon
cloud quiver
idle beacon
#

well, worth a shot

sinful moon
#

Yeah youtube videos are generally awful for infosec content with a couple of exceptions. Honestly I donโ€™t know what else to tell you other than experience and research. Report a domain to the registrar as shown in WHOIS and etc. But unfortunately thereโ€™s also not tons you can do beyond reporting something

#

Oh they deleted their message so that didnโ€™t become a reply

idle beacon
#

I am someone who does that for a job

#

problem is, i want to learn how to hunt for those websites.

#

asking in office is bit.... lets just say difficult

blissful current
#

Orange Cat ๐Ÿ‘’ hacker

rapid merlin
#

Wsp

sinful moon
blissful current
idle beacon
sinful moon
#

If youโ€™re just looking to take down malacious websites without pay, that is unfortunately just a never ending battle

blissful current
idle beacon
sinful moon
#

Youโ€™ll start to see a couple common patterns of infra that you can learn to parse easily

idle beacon
#

interestingly, I started doing that recently and got some praises and hike but i still cant touch on how to actually find them till end.
I know URLscan.io, FOFA, Hunter, and netlas

#

and been doing on that for a while

sinful moon
#

although frick all the ones that put themselves behind cloudflare, not R2, I mean the Cloudflare โ€œare you a robotโ€ prompts

idle beacon
#

but as i go further, the more advanced scam methods are found. and guess what, that is becoming a road blocker

sinful moon
#

Gotta love defensive tech being used to defend malacious tech

#

mhmm

#

one road blocker is one I just mentioned

idle beacon
#

I can hunt hours to only to find 1 or 2 scam sites. During that time, hunting team finds like 20-50

sinful moon
#

and you kind of have to pray that their opsec failed for a moment and is leaking something from their server directly, but not common

#

all depends on their infra and how advanced

idle beacon
#

and as our company buys paid subscription for everyone, i am using similar stuff as them

#

yet I fail to get same results. heck even close results

#

any path or anything will help.

sinful moon
#

I mean if that is the case, I would see zero shame in asking a buddy internally, like โ€œwhatโ€™s up with x, y and z?โ€

idle beacon
#

I am sitting at road block right now and I want to go ahead

idle beacon
#

everyone keeps their ears up

sinful moon
#

ugh gross understandable

idle beacon
#

i got a buddy in research thats why i can do this much

#

but nowadays it feels like people are keeping an eye on me

#

good or bad, i dont know

sinful moon
#

Yeah I canโ€™t even comment on that, sounds weird, but fair not much more weird than my own hellish small business IT things. Not sure if I have a good answer beyond what Iโ€™ve already said lol

#

I just know Iโ€™m always ingesting RSS feeds of issues like BleepingComputers and CISA Known Vulnerability Catalogue adds. I do try to work with my co-workers when possible, but fair we also have some weirdos and politics going on. But generally beyond the THM OSINT rooms you have already done, I donโ€™t know if thereโ€™s a ton of guidance, I just know they helped me with daily tasks/tools that were invaluable

#

even with our pretty great anti-phishing solution, I still use phishtool which I learned from THM nearly every day as a second opinion (also because the [view body] doesnโ€™t work as well in our tool lol)

idle beacon
#

no worries. I will continue to search for people outside my company in same domain to learn from them. Hoping i can find someone in similar discord channel as this.

sinful moon
#

Totally fair!

idle beacon
#

However i can say this. This domain is far bigger than what i anticipated

#

when i first stepped in, I thought it would be very small. Since spending a good long learning sooooo many new stuff, i can say the war between us and scammers is too big to not go unnoticed

sinful moon
#

Oh heck yeah, itโ€™s sprawling to the point that the most advanced adversaries you can never realistically pin down. Just give stats about lolโ€ฆ or honestly just goes for most adversaries unless they really fricked up on opsec (which lol can also be common)

steady pewter
#

Me right now:

#

Good night everyone, or perhaps good morning, good noon, good afternoon, but for me it's uh..morning.

sinful moon
#

Gโ€™night Guinea!

idle beacon
#

its saturday morning

idle beacon
sinful moon
#

it does kinda suck because I love digging into what infra our adversaries are using and etc. But I can make no meaningful difference reporting on or acting on that info due to volume (which is still significantly less than yours)

idle beacon
#

honestly, i lowballed it cuz thats what i once saw on a graph somewhere on my research buddy pc

sinful moon
#

Heck Iโ€™ve seen aggressive domain squating/spear phishing campaign. I did escalate that to my boss who just asked Google DNS (at the time) pretty please delist them (with proof). Yeah that went nowhere

idle beacon
#

I can help

#

share me the URL in personal message if u still have it

#

heck, i can help anyone here who needs it

#

I cant assure website removal but I got like 60-70% success rate

sinful moon
#

Thanks but lol theyโ€™re not a client of ours anymore due to completely unrelated VC pump and dump tactics

idle beacon
#

well, u know whom to come to when u need that work done

#

oooor if u got a referral for me, I am there

#

lol

sinful moon
#

lol sounds good, thanks for mentioning it

#

also lol this is basically a mom and pop MSP so nah you donโ€™t want to be here

idle beacon
#

just so u know, i will do that by unofficial channels. Using official channel will be seen by managers and well, u know the deal

sinful moon
#

Fantastic first IT job for me though since I got to wear โ€œall the hatsโ€ for better and for worse

idle beacon
#

I only got blue hat

#

....

sinful moon
#

lol come to me if you ever need dreaded โ€œcompliance managerโ€ hat ๐Ÿ™ƒ

#

heh Iโ€™ve done much more than that, but thatโ€™s one of my least enviable but still useful ones

carmine tinsel
#

bro finally I figured out this log poisoning shit ive been stuck on๐Ÿ˜ป

sick lance
sinful moon
#

lol I am curious as well

idle beacon
#

its pretty easy

#

I can do a small video call if u guys want

sinful moon
#

because registrars generally donโ€™t care or give us the time of day

idle beacon
sick lance
#

No video needed, just some information.

sinful moon
#

Yo Google, you all have this domain which is one letter off from our clientโ€™s business, and theyโ€™re sending spear phishing emails with real names. Please help.

#

Guess doesnโ€™t help when Google was like โ€œoh domain registrar is really hard, we give upโ€ but lol

idle beacon
#

Just find a website, find hosting and registrar, and see who is best to report (if its just directory, hosting. if its whole domain, registrar)

#

u dont report it to google or cloudflare

#

u go where they are registered

#

Registrant -> Hosting -> Registrar -> TLD -> DNS

#

this is a standard process

sinful moon
#

How do you purpose to find hosting when Cloudflare protects the malicious site, and WHOIS is private beyond generic abuse email?

rapid merlin
#

@sick lance Please contact a site staff to remove this guy https://tryhackme.com/p/ConnorHack it been a day and he isnโ€™t removed still

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

sick lance
rapid merlin
sick lance
#

Harping on about it every day won't make them do their job any faster. ๐Ÿ˜„

sinful moon
#

How so

idle beacon
#

u can report phishing/trademark infringement on cloudflare

#

they will send u a reply within 48 hours

sinful moon
#

Cloudflare wonโ€™t even return any of our emails

idle beacon
#

with actual hosting

#

they dont reply emails

#

thats the thing

#

they have a dedicated form

#

same is with most hosting/registrar

#

each have own methods to report

sinful moon
#

โ€ฆpost on a forum for Cloudflare? Somehow I doubt that will make much difference

#

heck we were trying to give them business but they ignored us entirely

sick lance
#

We don't respond to E-mails, but a pubic forum, we're all over that. ๐Ÿ˜„

idle beacon
sinful moon
#

lol

idle beacon
#

report here

#

report trademark infringement on this. U should get a reply from them within 4 hours

sinful moon
#

Anyways I sadly cant since all the cloudflare protected stuff I see is โ€œsmall fryโ€ phishing which Iโ€™m not supposed to spend too much time on. Itโ€™s very rare we have a very serious spear phishing threat

sinful moon
twin ridgeBOT
#

Gave +1 Rep to @idle beacon (current: #2764 - 1)

idle beacon
sinful moon
#

Vast majority of my digging into threat actor infa is for fun. I donโ€™t get paid for more than 15 minutes of me handling the phishing

idle beacon
#

my biggest scams takedown were all behind cloudflare

sinful moon
#

itโ€™s only the advanced/annoying ones behind cloudflare

idle beacon
#

but i can say one thing. BEC is something which I handle the least

sinful moon
#

otherwise I pinned down the exact IP the VPS is using lol

idle beacon
#

u can directly reach out to me for these stuff.

sinful moon
#

lol yeah I have handled BEC before and whew

#

sounds good, thanks

#

Statistically I can say that OVH is the most spammy VPS of all unfortunately

idle beacon
#

wait

#

have u reported here?

sinful moon
#

*.onmicrosoft.com comes in second

idle beacon
#

yeah they suck

#

microsoft and google

#

suck

pliant bronze
#

@dusk canyon Check your sound

sinful moon
# idle beacon have u reported here?

Again youโ€™re thinking Iโ€™m doing more than blocking in our own email security and moving on. I have had my hand slapped when I tried to take further actions unless it threatened the client further because yeah weโ€™re an MSP

idle beacon
#

oh

#

so u guys dont go ahead with full removal

sinful moon
#

if I go above and beyond and actually kill a threat thatโ€™s great theoretically but also, itโ€™ll just keep coming

#

I would love to like spend all day killing all threats, but like, my boss has the view that if something got through our email security, then we fucked up and the client doesnโ€™t have to pay for itโ€ฆ

idle beacon
#

my job is to do just that. end the threat once in for all

#

and advice my client on what to do next

#

usually, legal action or UDRP

sinful moon
#

Yeah 99.7% of the time going that far is not needed to be fair

idle beacon
#

if the pattern is not same, yeah

sinful moon
#

even 0.3% for BEC may be too generous. Iโ€™ve only seen it happen a handful of times thus far

idle beacon
#

it can be oneoff

#

i want to show examples

#

but

#

wont it be against server guidelines?

#

wanna join study room? will show there

sinful moon
# idle beacon wanna join study room? will show there

You do have my permission to DM me with redacted examples if you would like. But do not feel pressured to do so. I appriciate the sentiment but I donโ€™t think theyโ€™ll be a game changer for me after ingesting thousands of phishing attempts professionally.

#

Incidentally in the poor opsec column however, itโ€™s nice to see that my personal choice of VPS host has been like .001% of all phishing

idle beacon
#

sent u some stuff in DM

sinful moon
#

lol I do love this host since I explicitly emailed their support asking if I could run a completely ethical and expected vulnerability scanning server on their infra and they were like โ€œyep we donโ€™t care, just donโ€™t spoof IP host/destination parts of the packetsโ€

#

currently host a web host and that vuln server with them professioinally and pays for its self via our profit from them

#

we donโ€™t do web hosting really, these were for cheap af clients who refused to move to a dedicated host lol

idle beacon
#

oh shared hosting kinda stuff

sinful moon
#

Yep VPS is extremely cheap and effiencent if you just need a headless Linux server and you actually want your own agents on it and control over it

#

My personal pentesting server (for learning) is on the same provider

idle beacon
#

Fun aint it?

sinful moon
#

I just had to write internal documentation for like docker-compose stop, docker-compose log -f kinda thing because no one other than me and barely my boss knows Linux

idle beacon
#

while i searched for this for you, I tracked 10+ such websites

sinful moon
#

It surprised the heck out of me that my boss at least can do the basics of vim

#

yet he has no idea that dpkg -i is how to manually install the .deb packages we often need to do

idle beacon
#

ooof

#

get him fundamentals of linux

sinful moon
#

nah heโ€™s been deep into IT for nearly 30 years, heโ€™s slow to change and was brought up in LAN Manager, NetWare, OS/2, and NT 4 environments

#

Thereโ€™s still some things about Active Directory that I have to remind him are not a thing compared to NT 4 Primary Domain Controller vibes

#

Not like Iโ€™m one to complain, frick Azure/Entra ID. AD/GPO makes so much more sense and doesnโ€™t require x, y and z licenses you donโ€™t have to do basic things.

#

Not to mention not needing 50+ portals to do many basic tasks

idle beacon
sinful moon
#

But also I canโ€™t talk crap much when I started and was like โ€œwhat RDG?โ€ when he mentioned it, and he explained how Remote Desktop Gateway works, and why its needed.

#

But then I came full circle and demonstrated how those same RDG connections were being brute forced and forced us to move to all VPN finally

idle beacon
#

ooh

sinful moon
#

lol Iโ€™ll just say I saw and fixed significantly worse than that though. RDG was positively forward thinking in comparison to some still open 3389 Remote Desktop we had

#

trust me I more than made sure that would never happen again lol

#

Showing the boss a screenshot of our server and etc in Shodan is always a good motivator lol

#

But yeah I also donโ€™t mean to talk crap entirely, I learned tons from him as he did from me in kind

sinful moon
#

Just in case printers canโ€™t get with the times of the year 2000 and enable Kerberos

#

Anyways, Iโ€™ve not gone full NTLM purge anywhere but I have disabled NTLMv1 for a couple clients with absolutely 0 impact as one would hope.

sick lance
#

Why is vim the default text editor in Security Onion.

sinful moon
#

And yeah good measures like SMB message signing (feature for decades) caused no issues

#

because vim is good, or if youโ€™re whiny just export $EDITOR=nano

sick lance
#

nano isn't on SO.

sinful moon
#

so install it if ,:wq, [escape] and i are too much for you <3

sick lance
#

I can use vim, however when I plan on sticking the SO, they won't know vim kekw

sinful moon
#

Oh the rest of the org? Yeah that part sucks lol

#

Oh god, I thought I could just give you a simple answer but Security Onion is not well documented and the best post I could find is โ€œwell CentOS is now crap, what doโ€

#

I could be wrong, but just my initial research

#

But also lol if this is predominantly docker containers, yeah that doesnโ€™t fix the editor if you have to actually exec into a container soโ€ฆ

#

they may have to suck it up unfortunately

#

and even with that, I die inside if I ever have to use vi instead of vim

#

[so Iโ€™m sorry for giving you crap and misunderstanding the scope lol]

errant umbra
#

The makers of Bloodhound are bringing out a tool to find ntlm Auth in your domain and disable it as it's suitable for you

errant umbra
sinful moon
#

I know Bloodhound will be more visual but sysadmins are not lacking in tools

errant umbra
sick lance
#

What do you need?

errant umbra
sick lance
errant umbra
sick lance
chilly veldt
#

So dead

errant umbra
grim sparrowBOT
#

:hammer: timerrp#0 has been banned.

sinful moon
#

I mean itโ€™s like 6am Eastern time in the US, but I have no excuse for dem UK/Euro folks lol

chilly veldt
#

24 hour CTF with shitty sleep and alcohol, now at a conference listening to talks and then afterparty

sinful moon
#

Whew, good luck and enjoy!

errant umbra
#

Ah, the choices we make

carmine tinsel
#

you need to rest๐Ÿ™ƒ

#

(its 3 AM where I'm at who am i to talk)

chilly veldt
sick lance
#

When you have to walk away but ensure your machine works.

errant umbra
chilly veldt
errant umbra
cedar swan
#

ehโ€ฆ.