#general
1 messages · Page 979 of 1
they wake up, go to school, then cram school, then back to school library, then home to study, sleep 4-5 hours and repeat lol
we have to found a way more affective guys cuz actually in the normall courses they dont tech us a SHIT sorry
oh wait i think that's china
It is very broad. You would want to deep dive in a specific field.
the reall info is where >>>>,,,,,,
i mean stuff like CS 340 Into networking
is a really good course and if you put it at 1.25X or 1.5X the guy actually is nice to listen to
you just pretend you're going to school for an hour a day
that working i learn now prog lang for this year
Such as pentesting (still vague, web pentesting? network pentesting? red team? application security?)
but i have talk with some of guys actually not in clear net but you know
they know moooore and they in the same age with us
i mean for cybersecurity programming is necessary but if you're going into Pentesting or SOC analyst position like many others it's not super necessary. For those you need low-level programming in python to entry
the pentest shadow does is where they have padded shoes and stub their toes on doorframes to see if the frame is setup to minimise pain
many ouchies were cried
i learn C for now and python
Haha nice, the pentest i do is how fast i can spin the pen.
good enough. Not familiar with C but python for sure. (i hate python and programming tho)
guys there is 15 years old guys they build a operatting systems for hacking and they are like fcking super man in everythink
aaaand we officially at 20% downloaded of all packtpub ebooks( and videos ) shadow owns
it's not detailed enough in python. Like if you call a function how does it know that you're defining an INT type in your loop if you dont specify. Or like how does it know just to create stuff or loop through stuff, not understanding it alot.
Doesn't mean you are late or something. We all have different circumstances and opportunities. The key is to keep going on and you can still be an expert.
yaeh you should see that 9 year old that builds programs with python while live streaming for an hour making CS majors blow their cranes out
i know that bro i will never stop but my quation is how they become in that fast
that interestting
Talent
deep learning
level
is higher
Curiosity, combined with opportunity
i dont think is talent i think is exaaaaactly
- i'm sure if someone sat you down at 6 years old and started teaching you or you started learning at that age its like learning a language from birth
that is
@proven quartz
:hammer: srb646403#0 has been banned.
You should use the new reporting feature it was mentioned in the community announcements /report
oh damn
that True
Oh okay.
It’s super useful!
im curious how old everyone here is?
25
anyone know how i can contact support ?
thanks super helpful
Gave +1 Rep to @mossy river (current: #6 - 1549)
Damn wrong link
do you guys know if canceling yearly subs is possible ?
i just forgot and resubbed today
i gotta pass the sec+ so i kinda need the money lol
eugh this is heavy legalese writen by none lawyer text
im failing to understand
reading the pdf extreme privacy what it takes to disapear 5th edition
and it is on a section about trusts
Simple answer a lot lol
and shadow feels lost and annoyed
I'm still failing to understand
legal trusts in the context of the usa that is
you're saying there's mention about subscription cancelation in their TOS ?
Trusts are so complex depending on the country icl
i'm still failing to understand
You can email support id say lad
i did
Jabba mentioned the email shadow is talking about something else
i just wanted to know if anyone else knew anything about it
@merry elm no no not about the support... shadow is just annoyed at an ebook they are reading that is not related to tryhackme support
Just wait for their answer I would guess it’s possible I’ve heard people discuss it just never dealt with it myself
well yeah. It's been just a few hours so i hope they can help me out or i'd have to wait another year, or potentially beg on the street for a week lol
It’s a U.K. company so I’d guess wait for their business hours
yeah nah its 12-1am ish there so tomorrow probs
wait time on tryhackme support email is about 1 business week
It’s 10:23 as someone in the uk
unless they have hired tons of more people to handle support emails
No sir
good to know
Europe is ahead of us
"Press X to Doubt"
local time in sweden for shadow is 23:24
might be misunderstanding this but why are you referring to your username as another person ?
Illeism (; from Latin ille: “he; that man”) is the act of referring to oneself in the third person instead of first person. It is sometimes used in literature as a stylistic device. In real-life usage, illeism can reflect a number of different stylistic intentions or involuntary circumstances.
been doing it for ages
Also btw @merry elm you can pop a message in #site-support maybe you’ll get some help there too
oh nice thanks
No promises
nah yeah i gotchu. i'll give it a try
i just went over to HTB to test stuff out. Gotta say it's nice to practice instead of theory. I did like it quite a bit
GG confusing things:
You can always look for challenges if you want more hands on practice
There is plenty on thm as well
i mean on THM the nice thing is that you learn the concepts and basics of stuff
but gets really boring easily. And remembering the info is hard.
practice ones i haven't tried
I think learn the basics on a topic
Then find challange rooms on the topic
And learn hands on
That’s what I do
Worked good for me tbh
i spent 3 days on active shell room i remember....i wanted to punish my brain by removing the cells inside with the combination of toluene with a mixture of nitric acid and sulfuric acid.
just because i was taking notes and trying to remember stuff
shadow learnt more on the topic of windows blue teaming this past few weeks
PG13 lad!
does that "up" help or do i remove the message XD
Honestly if you want a break from notes go do some challenges on the stuff you’ll learn a lot
Remove end bit I’d say
¯_(ツ)_/¯
Beef lips
i like beef
spicy ones
well to a certain degree yes
Sausage lips
i like to pour out 2/3 of the juice and eat the rest of the instant noodles
nice lips.
Thanks, they're my mum's
...i'm sure she appreciates you sharing
She sure does
well goodnight everyone. I'm gonna try to do some challs on THM tomorrow see how it goes.

Anyone got a github portfolio example I could take a look at? I've created mine today 
check the write ups on the tryhackme rooms/challenges.. many of the people that write them do it on github, there are some cool ones
Surely creating your own website would be much better
42
Thanks!
Gave +1 Rep to @modest charm (current: #503 - 12)
will do, I will go trough more rooms on tryhackme
It's what I've seen being advised as a good way to stand out and to prove skills etc to employers
Do you think most people take notes when they do THM?
I don't
yes
shadow is very inconsistent at taking notes
but they are great with teaching their rubber ducky friend to solve problems
I usually whisper to myself after learning something, as if I'm explaining it to someone else lol
That way I know if I need to go back and learn more
I think making notes is extremely helpful not only because it helps learning, but I also because I find myself going back to them from time to time.
basically the same as shadow just shadow does it in normal speaking volume to their ducky friend
Shadow?
lots of new peeps here today apparently
ello ello
shadow is shadow
a cheese loving person from sweden
that refer to themselves in third person
I like making notes with cases, for example having a XSS section where you store cases and examples of complex XSSs... I never regret having this...
I hate note taking. I used to take notes in Obsidian, until I go to the point where I had very structured notes, note templates, and I was spending wayyyy too much time making my notes detailed, structured, consistent etc and was losing a shit load of time
I keep it simple, focused on complex cases like I mentioned.
I dont care if it looks good 😄
Only time I take notes now is to jot things down that I wanna research later. Like I'll open windows notepad, right down some new attack methods, come back to them in a few hours, and then delete the note.
Imagine how efficient combining ducky and notes would be - you would explain stuff to a time traveler, then you could even post these notes publically to other people
🤚 high five?
Nowadays I just talk to AI
imagine teaching the duck to take notes 🤯
its too good to be true
I got 759 for the minimum 750 and passed pentest +
I was temped to take the 002 but I took the 003
I installed bitdefender and instead of booting into windows it said cleaning my system👀
Congratulations! 🎉
What did you do to prep for it? CompTIA prep plus THM?
Thm pentest + path .. also the red team path .. Jason Dion has these tests where they will make a different test from his database every time - so you can take 100 different practice tests ( well kind of different )
I was also not good with Active Directory or a lot of the tools used ( power shell anything ) so I read the dummies guide to pentest + ( who is also by Clark who did the big boy prep version ) and made a bunch of flash cards for tools , exploits , maneuvers etc
@sand trench go shleepy shloop
what is going on here
fine if you can get shadow out of bed in about 8 hours and 30 mins
That's the middle of the night for me 👀
excuses

It's an end that's back
Hey guys little (maybe dumb) question
Today when accessing a iis web app, i noticed that when uploading a webwebshell.php and trying to access it via the browser wasn't possible (Everytime got a 404 error) then when trying to create a asp reverse shell with msfvenom and tried to access it via the browser still 404, however when I tried to upload and exploit shell using davtest, the test was successful.
The only successful shell that I got was a webshell.asp.
Someone know why all other shells where giving me a 404 error ?
can you teach me how to make a register and login for my site
excuses as in excuses you from having to deal with the problem as it is shadows problem
anyways time for meepy moopy meep moop sleep sloop to beep boop
Likely the directory you are going to isn't correct, it's a little hard to know without knowing the setup
could be something to do with the request also
Anyone have suggestions for the types of boxes I should do write ups on to show with my resume ?
There are some good guides on the internet
Protocol maneuvers ? C2.. a lot of Active Directory stuff ?
I wouldn't personally put write ups on a resume as it's not formal experience.
Perhaps in a hobby section link to a blog/mention tryhackme.
I was considering writing little step by step PDFs ( like the rubber ducky technique) to talk about common exploits using language a tween could understand . Using similes and metaphor to describe hard to understand process
I was doing it to display my report ability - I’m not doing a write up like a walk through . I would write report like a vuln assessment or black box test
I really just wanna be awesome at report writing haha
It's good practice imo but still belongs in a hobby section
Well it was more of like a portfolio idea .. reports , labs I’ve designed , scripts , some medium write ups on exploits etc
The resume will just be job experience and certs obvs
I am not working in tech now. I am studying for the a+. My friend thinks I might be able to get a job in IT with just an a+ and no tech job experience. Then I’ll work on network+ and security+. I am looking into volunteering at a community computer refurbishing place once I get finished reading the a+ study guide (but before I take the a+).
Hi everyone
how do i link my lvl in thm with discord ?
I wanted to ask if there is a good resource to understand how does chisel exactly work, all the resources I found just explain how to start and stop server and client ...
I am looking for some good understanding if someone can suggest some please
because for example -R in ssh tunneling means that we are exposing a service throught the tunnel, but in chisel looks like it does something else
You can verify your account through this link from the website:
https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account
All about TryHackMe Discord Server.
John Hammond did a video about it on YouTube here:
https://www.youtube.com/watch?v=pbR_BNSOaMk
https://jh.live/7a-john40 || 7ASecurity offers training and penetration tests with a free fix verification -- get 40% off training with JOHN40, $1000 off a pentest, or a enter their contest to win a completely FREE pentest! https://jh.live/7a-freepentest
00:00 - Chisel
00:23 - Setup
01:30 - Recon
05:55 - On static binaries
12:44 - Using...
I saw that, but it is not explaining what I want, I want to know how running a server with --reverse vs running without works
Thanks
Gave +1 Rep to @proven quartz (current: #21 - 486)
John Hammond videos have been great
His stuff about powershell and AD lab was top notch
What do you use? I was thinking about trying out obsidian, but I'm not sure. I want something thats super organized and looks nice lol
Aren't we all?
Color scheme is 🔥
Wait you can change color of text too?
It's pretty much markdown, so yeah.
Ya
You markdown with == right?
== before and after the word
Ohhhh
I didn't know ## is also something
It's just a language of different ways of "marking down" your notes.
I thought # is just for heading
-# like this, discord has markdown too.
have you heard of -#?
Till now, no.
gotta do it with backticks.
‘This’
this works?
I remember that a moderator said that we shouldn't test around with markdown stuff in this channel.
Lol
hellooo
I believe that time they moved the testing to # bot-commands
I'm on the case
Hello Detective.
I'd say your name but then I'd get perma-mute.
Rip
Don't want that to happen 
Please, just call me Dickie.
Detective Dickie
I'll call you that from now on--in my mind.
thank you @mannerstyle?
Thanks.
thank you @guinea_pig_lord ?
No rep for you! 
Podcast?
Yoo, any recommendations of ciphers rooms?
Yeah in the form of a drama
anybody else getting a " unable to mount 77mb of usb storage" pop up on every attack box open?
looks glorious. maybe try a minimalist icon set. cherry on top
Challenge or walkthrough 🙂 ?
Challenge pls:)
Others than “crack the hash”
Maybe these two 🙂
https://tryhackme.com/room/breakit
https://tryhackme.com/room/breakrsa
Appreciate ♥️
They should improve the search hahaha
Please don't upload inappropriate GIFs 🙂
Wats that ?
Did similar lessons onm TCM Sec but never quite understood the concept.
THM's lesson on JWT is top notch.
So easy to grasp
How I want to listen to this. One
$uri = rtrim($_GET['url'], "/"); ... $path = ROOTPATH . $file; ... if (file_exists($path)) { echo "<pre>"; echo htmlspecialchars(file_get_contents($path)); echo "</pre>"; } else { ?> <p class="text-xl"><?= ltrim($file, "/") ?> is not found</p> <?php ...
Name that vulnerability
You’ve heard of it ?
room glitches, which room?
No
I would also recommend you to check Burp's Web Security Academy and learn more about JWT Editor burp extension - invaluable resource imo 🙂
the input parameter url lacks adequate filtering and loads whatever the parameter is provided from the localhost.
Will look into it. Thanks
Gave +1 Rep to @cloud quiver (current: #1 - 4232)
Is the book Think Python recommended to learn Python?
I've read it, has a lot of good material when you're trying to understand the logic of a lot of this stuff.
yeah, I can access it.
Thanks!
Gave +1 Rep to @steady pewter (current: #431 - 14)
This cat just experienced light mode at 3AM.
I cant
What error does it give you?
Its just blank
I see the title and thats it
Weird
And the picture
whats ur language ?
Java
Check out our #programming channel 🙂
english ?
Yeah
im lookin for arab ppl to join our group
sky kitty says??
ohh didnt know this room exists thanks
Gave +1 Rep to @cloud quiver (current: #1 - 4234)
@cloud quiver AJ??
🙂 ?
Naw.. old friend..
Who's AJ 🙂 ?
Just an old friend who held that tag for years... decades. LOL
Sorry but I can't remember any AJ atm 😦
NPNP.. just same tag as an old friend of mine.. from way way back.. I am ancient.. just @boreal scarab 🤣
Bro how many times I need to tell you to keep GIFs appropriate 🙂
How is it inappropriate
I'm calling woman inappropriate names is definitely something that shouldn't be in this chat
Thanks 🙂
Gave +1 Rep to @fiery imp (current: #539 - 11)
The vid is against that
How are you mate, it's been a while
Thanks for asking , good , how about you 🙂 ?
Please keep discussion cyber security related 🙂
hello--oh...uh..I'm just gonna let general cool off for a bit, see ya all later!
Great, I'm good too mate
noticed something new?
New color 🔵 , congrats 🙂 🚀
YEAHH you got it, it feels good to level up
Keep up the good work 🙂 
Ty mate!
Gave +1 Rep to @cloud quiver (current: #1 - 4236)
bruhh, UI's so difficult for me. I was making a project, wrote the code in python in 20 min ig. And thought of making a website for it, it's been a day and I'm still stuck😭
alright, gotta hop off. Will let you guys know if I was able to pull it off or not
Good luck 🙂
Yes my boy
What application do you like for taking notes in windows?
Notepad
Notepad++
TrilliumNext https://github.com/TriliumNext/Notes
@cloud quiver congrats on Trial Mod 🥳
Thanks 🙂
Gave +1 Rep to @grizzled void (current: #149 - 55)
Anyone on by any chance? I'm trying the Splunk2 room, but there does not seem to be a botsv2 dataset on the instance, meaning I can't really answer any of the questions.
Thanks @south egret @steady pewter @grizzled void
Gave +1 Rep to @south egret (current: #539 - 11)
is it me or boilerctf is lagging?
Good morning Sigmas Omegas BetaChads H4ck0rz
seems fine to me, if you continue to experience issues #site-support or #room-help
Anybody here from India? Need some help!
Please keep conversation appropriate 🙂
What's the issue ?
Same issue of tomorrow purchasing premium, so I want to ask them are they facing same issue or only me.
Have you tried to reach out to support ?
Yes they said all fine from there side, and then contacted bank where bank also said all fine! So wanna connect with someone who is from India and have premium so I can know the procedure!
Last warning 🙂
Sad to hear that 😦 . Maybe try to also post in #site-support channel
Someone have iso file with windows server 2019?:(
Done yesterday, mods said that they can't do anything. It's too frustrating lost my streak, learning stopped from 4 days🥲
You can ask staff to restore your streak, I know a few people who got their streak restored .You can do some free rooms in the mean time until the issue is resolved
It would have been better if THM have other payments gateway like UPI as 90-95% Indian's relly upon it. If you can suggest it please do so @cloud quiver
I think that you can also pay using PayPal on THM
Bruh I type apologies in Russian 😭🙏. Is the general chat not that deep pls don’t ban me
But that's also not available, only card gateway is available!
Just keep conversation in English and appropriate to cyber security related Discord , ok 🙂 ?
If you don't mine can I Dm you I have something to talk if it's okay
Deal
Oh yeah
Sorry but I can't help you with that issue . Only staff can help you with sub. related problems 😦
is it cool to ask about sort of cyber security unrelated topics here?
reminds me of the time this chick, totally blasted, spun around while dancing with a beer in hand, hit my head real hard and knocked me out. I fell on the bar floor and was out for a few seconds. I woke up to this view of some old fat dude dancing with her across my body lmao
That’s wild
Somebody please call cap, that story was right out of the reddit playbook lol
Hello Guys,
Ist SOC 1 the learning path for blue teaming? So forensic, malware and so on?
Yeah 🙂
🦹♂️
ya but not spams ofc
hey, who could help ??? getting issue in android hacking 101 ......
@cloud quiver ...
Hello...
Malware anyalsis
.
@shut hawk
@untold hill Do not advertise here
i'm about the copy over NVD's database in 30 min -_- for my tool Lol
removed for bug fixing , they'll put it again later
Anyone know some of the us privacy and security law?
@hasty sand can u dm bro i have something for u and for me if u can help me and don't worry i don't need you to see or install or to do nothing we're just gonna talk
If you need expertise on laws, I'd suggest speaking to a lawyer.
Yh but im talking about something else i really can't talk too much but don't worry it's not something illegal it's a pb related to a bug
If you say so.
Nah nah don't worry it's just i can't talk cause i don't have the permission u know
That's ironic considering you want to DM somebody, but okay.
Who here has heard the term “Is it cold enough to freeze the balls of a brass monkey”?
Well sometimes it is.
-# BRO IS PLAYING GTA VI BEFORE GTA VI
Yes bro I am hacker



I'm not a hacker. If you can do that, then you're a hacker too
Everyone here is bias, but I've so far seen mixed reviews and isn't worth it yet
Are they though?
Are you looking for a SoC position?
Quite upsetting, it did look good to have on CV
Then you should take certs that are relevant to your field.
No point in going for a SoC cert when you don't even want to blue team.
So why do you want Sal1, for the cert, or just for something to stick on your CV?
Your money you're wasting, but sure.
The more stuff on your CV, the more you're going to be questioned.
Lying on CV is considered fraud.
Wise words lol
Hi ladies
Gave +1 Rep to @sick lance (current: #2 - 3566)
me when loans

I’m not a laywer, but fraud and misrepresentation fall under different concepts in law, at least UK law.
Probably best you don't give advice then, if you're not a lawyer.
Are you a lawyer?
This chat is quite chaotic sometimes lol
I'm not giving advice, I'm telling people not to illegal stuff. 🙂
It's illegal in the UK, to lie on your CV.
Under UK law, fraud does not require someone to find out for it to legally count as fraud
Your arguments are quite bad
||If someone has too much money to waste - provide me sum so i can buy C-EH training n Cert off EC Council 👉 👈
||
How do you pick cereal when there are like 100 versions of it that basically look the same
The Fraud Act 2006 Exists.

I agree though, you shouldn’t lie on a CV, it’s a big red flag
It looks like it lol
... You're literally just proving my point, whilst trying to argue about it.
Oof I wish I hadn't
Man why do you think every conversation here is an argument?
Exactly. I’m just giving my opinion on that if someone is considering lying, in my eyes, it’s a red flag
-# Debate
Good morning 
the prize of trolling is a hammer
🚩
+1
Me neither
I did.. wish I didn't
same
Oh dont , trust us

nope
it was
-# Veri WEIRD
Hey guys, is there an AppLock for pc? I want to lock certain apps or even folders?
Password protected .ZIP folder
Create a new user, don't let other accounts access your data.
Or use MS Intune
Not if they’re other local admin users or the device is managed in any way
That's why I said a user, and not admin.
That’s probably not the best method tbh
It's the easiest.
I’m sure lots of things are easy
1tb thumbdrive
I mean, password protected zips are great until they get the password.

put \ before - to not make it format
Yeah already done. I don't let other people use my account.
Password rotation on an unmapped drive
This is what I do anyway, and I use my MS account to authenticate
Well, is there a tool that starts to capture activities in case it detects something suspicious?
Like taking screenshots or recording
Something like that
What
-# Just permanently delete the files , vanish it off the face of earth and internet archives
-# Safe AF , no one can access the file then , not even you

Just use OneDrive
What's the point of it?
Oh hell nah
Deleting a file, won't actually delete it.
Why? With Business OneDrive you can implement DLP policies and prevent external sharing and exfiltration, CA, etc
was a joke but ok
Nobody likes the idea of airgapped storage? for example large thumbdrive
arrives
-# departures
Rotation*
you can assume nobody can access the storage
Immutable storage is where it’s at
Think like a piece of malware and shove everything in EdgeUpdater lmao
Thumb drives should be blocked, both at the EDR and BIOS level imo
To prevent exfiltration obviously
Man. This guy is cool 🙏
Do you agree?
Yes, both that and the above points are paying good attention to detail
I'm the idea man, let me give an idea - switch blocked ports
you have to click a thing on the screen to open a usb port or something idk
I prefer me LUKS though 🙏
Not humouring the chance a company puts some form of backdoor in their proprietary encryption software, the legal bills UK's been cooking as of late trying to abolish E2EE are crazy
Yeah just look at Apple’s ADP for UK
Disgusting
I’d say from lack of understanding though
Nobody thought that would be a good idea
You are missing out, man. I'm not sure how much it's of use for enterprise settings, but Linux has some of the nicest options for kernel-level resource isolation with things such as Cgroups, process namespaces and KVM
Container magic and LXC ✨
I found LUKS especially neat because of how flexible it is. Me and a friend have been toying around with one of its functions lately, being detachable encryption headers.
Instead of a USB key, the USB just straight up is the filesystem header with all the master keys and the details about what encryption/pbkdf/rounds are used on the drive
Without the USB, the data is completely irrecoverable. The master key is unfeasible to try brute force, and you don't really even know the specs of what encryption algorithm it uses, since LUKS gives you the option to configure that
But in what scenario would that ever be useful?
Sounds like it would cause headaches if anything
You can already specify the encryption algorithm for BitLocker and it can’t be bruteforced
At this point we know its way beyond either of our threat models, its just for interest's sake and food for thought when it comes to our University dissertations at some point along the way
My guy really likes FDE and cryptography. He's thinking of writing his dissert on a platforms-agnostic encryption standard for emails 🔥
Good morning all!
https://tryhackme.com/room/zer0logon
the room working for you?
im stuck cant see the questions and cant start the machine
Mornin'
seems to be working for me
works fine for me
give it a refresh
Sweet was able to get my first and last on proton mail, good bye squirtel925@gmail.com
can anyone recommend online tools that helps changing colors in photo?
chaning?
oh, changing
Online image editor?
yeah something like that, sorry i am illiterate
oh tysm
morning!!!!
Hello, so I have been exploring the forensics side and I want to know if there are more free tools available
In order to suggest tools, you'll need to tell us what you've been using
I have been using Encase, Autopsy, Kape and Ftk imager
EnCase isn't free... 😉
I somehow got access to it
hi
Have a look at https://github.com/ufrisk/MemProcFS
Is it free
Well, I mean, you asked for free tools, right?
I would not give you a tool that is paid.
Thnx
the chat is so dead today 
that just took 60mb of my mobile data
60MB well spent
i guess
Wasup
question can i post google forms likes?
I love kitty 💕
No, to protect the privacy of our members. 🙂
I can get everything privacy ?
What do you mean?
Like google can send my data to another company?
Cant**
kk
the best method is
stop using google
i pro hacker
( im joking)
Either I stopped use gooogle my phone is samsung
Its hard! 🤣
Uh...
I'd hate to be the one to tell you this, Samsung uses Google.
fdroid?
Gdroid🤣
UK weather means it's BBQ night tonight
Greaat ! I LOVE BBQ but I'm feasting
?
Means Google andriod
My BBQ is gonna be at 7/8pm rather than early
Late night BBQs bang, have had mates over and been BBQing till 1am before
can't wait for summer to consume all the bbq 
Does anyone have a pentest report on DemoBlaze or PetStore? Or can anyone help with conducting a pentest on these sites?
Good evening chat
Good afternoon.
your name remembers me of Valentine day
Anyone interested in CTF and has experience in the field, please contact me privately. The following experiences are required, the most important of which are:
🔴 Reverse engineering
🔴 Encryption
** If you have other experiences, that's fine 🌹
why is soc lv 1 so loong😭
echo "192.168.1.100 mycustomhost" | sudo tee -a /etc/hosts > /dev/null
Gave +1 Rep to @leaden marsh (current: #1822 - 2)
Is sudo tee necessary here ?
I just wanna add an etc host without entering a text editor
linux fundamentals 3, log: What is the IP address of the user who visited the site? ...___ . and i found ip adress but it is 10.9.93.186. how do i place it
copy paste it?
U just put the numbers since the … are already there
wdym how do i place it
I love THM but Windows machine are SOOOOOOOOOO SLOW
i need 10.9.923.186 or this type ip
that's not a valid ip
each octet must be between 0-255
look your massage
linux fundementals 3 . log part . 8 task
yeah your answer is wrong
did you check access.log1
What the access.log1
27.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET / HTTP/1.1" 200 3477 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0"
127.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET /icons/ubuntu-logo.png HTTP/1.1" 200 3623 "http://127.0.0.1:81/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0"
127.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET /favicon.ico HTTP/1.1" 404 487 "http://127.0.0.1:81/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0"
I think I willctake revision in linux fundementals
less access.log.1 right ?
the access.log.1 file
U should
For apache right?
less would work too
there is no ip adress
127.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET / HTTP/1.1" 200 3477 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0"
127.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET /icons/ubuntu-logo.png HTTP/1.1" 200 3623 "http://127.0.0.1:81/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0"
127.0.0.1 - - [06/May/2024:23:54:15 +0100] "GET /favicon.ico HTTP/1.1" 404 487 "http://127.0.0.1:81/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0" look
send ss of what you did instead of pasting this in the chat
my eyes hurt

send it direct
verify first so you can send ss
this
type /verify then when it asks for token look in your THM manage account and find the discord token
that way other members can help you too
@wintry sentinel are you sure you are seeing the full output?
from the screenshots you sent me, i think part of the output might be obscured in the split view
yes bro
yeah i can't find the ip either
did yall check both access.logs?
yeah
i checked 3 access.log,access.log.1 and access.log.2.gz
hmmm
is this mistake from website?
okay i found the culprit
you're supposed to ssh into your deployed machine and check its logs
not your attackbox's apache logs
read task 2 @wintry sentinel
Alright guys thank u very much
can confirm just did this and i got the ip
i really dont wanna do more networking 😦
do them
learning networking is important
yes thank you so much , i found the ip adress
Gave +1 Rep to @queen flare (current: #338 - 19)
yeaaaa
Boring as it may be, it is quite important.
hey guy, i am new to cyber security and wondering that should I read "hacking: the art of exploitation" first?
i have some programming experiences before
i mean you dont need to since i know at times books can get expensive
but if you wanna pick it up you can
That would be a great start or you could begin with the presecurity path on try hack me
Did anyone here finish this room https://tryhackme.com/room/passwordattacks
i have not
I've tried the book for 1 weeks. I see the book kinda good at introduce some way to think like a hacker to me, but I also wonder that is the method in the book still work.
I appreciate it, guys.
Thanks for answering me
You wont learn much from books, you'll forget about 95% of the content
You need to practice
If you can use the book as practice material then g
is the the book?
Yeah when i was new to programming I didnt read, just do
yes
yea its more about using the book as opposed to just sitting there and reading it
Windows PowerShell it should be RDP not SSH pls confirm
can you elaborate more ?
for the powershell room?
do you guys recommend me this book?
https://www.amazon.it/Black-Hat-Python-Programming-Pentesters/dp/1718501129
im thinking to buy it
Hey, been looking through the faq channel and Serverguide but can't find where there is a guide to activate my THM token on discord
anyone know if there is one?
=/
There it is, thank you
Gave +1 Rep to @cloud quiver (current: #1 - 4247)
?
i got link ❤️
man entered tryhackme.com into VirusTotal (never do that or mehack will come to your house at night)
that's not tryhackme
Discover magic and mystery in Witchbrook, a spellbinding witch life-sim for up to 4-players. Coming to PC, Nintendo Switch, and Xbox.
Start your life as the newest resident witch in the bustling seaside city of Mossport. Make friends, find love, and discover a world filled with wonder and charm on the road to graduation and beyond!
Witchbrook ...
IT IS HAPPENING :D
Sorcery, mopeds, flowers and donuts oh my gosh how wonderful
We don't do that here.
If it's a question regarding a room on TryHackMe.com, please visit the apropriate channel. #room-help
you need to do it in order
@hasty sand

0 is bussy bee. jaba or scrub in all cases 🙂
And we have the /report feature to use!
Wait, didn't James or Scrubz had a conniption over pinging mods? That's why we have the report feature, right?
No?
Please don't.
sorry
the report command was added so that you can always reach all moderators:)
the chances of him response is soooo low
I don't mind being pinged for rule breaks, and I never have done.
Thank u
That's probably why they were pinged.
?
That's why I'm making fun of that lol
People tell you to ping mods, while some of the mods are mostly offline
also wonder does anyone know how to slove this every time i try to redirect in js it doesn't change the orgin and i just end up withsomething like this "0.0.0.0" --> "0.0.0.0" when i want to redirect to example.com
ah
Hence why we added the report command:)
I'm offline but I'm still responding to pings ;p
thm bot one or the other one?
I think "slash report"
i see two commands when i do /report
Both work
you select user or message
Use tmm
- </report message:1348321561517625404> – Report a specific message that breaks the rules.
- </report user:1348321561517625404> – Report a user directly if their behaviour is concerning.
Not Yag.
TryModrrateMe
finally finished cybersecurity 101
he never offline
the yagpdb is actually only for "thanking"
Yag is used for more than that.
you should give us admin access so we could see ;) (im joking)
cool! Now you can try one of those easy challenges, they really are quite simple
You need to sweet talk Jabba for that.
i've done a few like pentesting 101, imint etc.
i ping kgb to recommend me rooms whenever i get bored
Oh brother, I really need to start using (im joking), because 90% of time Scrubz does not get my jokes 😅
Right now I'm scrolling through challenges list and sorting through most popular
Agent Sudo was awesome
it depends on what you using it on tho lol
Or I don't find them funny?
hm, have you done crack the hashes one's?
i liked those
I know I've done some rooms with hash cracking, but I don't know if we're talking about the same one
sup
Hash cracking is actually quite useful, because you'll see more and more of them in the future (since most sites automatically hide credentials and malicious domains)
hia
I love it
I had to go through every appearance setting again, to adjust the chat size
It's horrible.
cause it lets you make it DaRk
But the dark theme is cool. Sad thing is, betterDiscord or software alike, had it for years now, and with customizables in css
the way how the minimizing, maximizing and close icons looks like other standard desktop apps now is perhaps the most horrendous part of it
you can always reverse the new version
Android has had it foryears
servers tray looks microscopic
Just make sure we aren't breaking or suggesting to break Discord's ToS here please
It's not that, I prefer using vanilla discord, but I'm just saying it's not that awesome considering that you could've done it for the past 5 years or so
Yes
Anyway, most customizations on vanilla discord are paywalled
I thought that it's possible to adjust their sizes
i'm lazy
oh
It kinda is possible.. You don't have a specific option for that, but rather a selection of "UI Compact Mode"
But then the whole size of your discord gets messed up
And you have to go back to selecting text size, zoom, etc.
hi lazy
He said that you would destroy the dads, not join them!
after 3h of re-assembly of 3d printer im with 4 extra screws =/
looool
It's not possible to re-assembly something and not leave a few screws behind
you reassembled it more efficiently than the company
ik. but that is problem here. all need to be secure if wish not have shaking results
💕.
If that's important.. Why didn't you follow the instruction/guide you've been using?
Thank u
Not really 😂
The amount of objects I've rebuilt with less screws and never had issues
I guess anything is welcome in the #general now..
there is no offical guide for what i do lol
There aren't many official guides for what we, hobbyists do.
that's what she said
same same. jsut this can result of object not printed nice 🙂
hence the issue lol
Can you elaborate? @split ore
does tryhack me have a actually place were you could walk in
- extra two springs. that idk where comes from lol
couldn't find the word i was looking for 😭
Probably not.
whats up hackers 
What I mean is, that when I disassembly something, I may usually go with an online guide (if it's my first time). The issue can arise when I try to assemble it back, because I might miss some of the steps and finish the assembly with a few screws behind.
ah why not
128 City Road, London, United Kingdom, EC1V 2NX
it would be cool
Doing some hacking
Kemp House, 152 City Road, London, EC1V 2NX, GB.
You said "I guess anything is welcome in the general now.."
That I've said, yes
just searched it lol
this is a mailing house, there is not an official HQ for TryHackMe
ahhhhhhh
Did you perchance respond to the wrong message?
at least yoshi can still walk in
No, as far as I'm concerned, I've replied to the comment I wanted to.
And gather all of the mail!
the one that wasn't related or part of the discussion you elaborated on?
man, it should be friday already, ive worked so much these last days. 😪
and 41% done on packtpub downloading D:
It would be very cool if they did have an HQ. Although, that would be expensive
Yes, that was my message. No, it wasn't related to the discussion, as much as the message I've replied to was not.
just wondering am i any where near being able to quality for a mod in the feature well if learn the rules fully
They can't.
Listed building!= Welcome to walk in.
Imagine the front door, glass walls, coffee machine every 5 steps...
Everyone can qualify to be a moderator:) You just have to be kind, respectful and part of the community
ahhh
and survive the fight to death hackers ring
Then we get people like Scrubz as a mod.. But I guess that's fair enough 😆
Mandatory Coffee machines near the office desks.
That is a terrible joke
what he do
Thank you! And have a terrible rest of your day!
Gave +1 Rep to @mossy river (current: #6 - 1550)
@split ore has been warned.
Anyway time for a ride 🏍️ 😎
ohh you have moto?
ooooh you got a bike?
Well, how was that not respectful? In british english you do say "terrible" as in something truly wonderful
I miss my bike
Source?
How many OSINT challenges has THM?
Is it enough to learn it?
As a brit, unless it's sarcasm, no we do not. We use the official oxford and cambridge definition
There are some rooms on Osint, however it won't really be branched out further.
OSINT is something you can perfect/improve with just doing it, without really learning from materials.
Jabba, my message wasn't much more offencive than yours.
Ah that's sad.
and organizing your own framework Id suggest
i need a smoke =/
but your lungs
May I ask which message was offensive?
they are ok
A smoke detector? Smoked bbq wings?
funny flowers
No need to re-invent the wheel.
The one with the word "terrible" - same as mine. Yet I didn't see you getting a warn.
omg i forgot about that completely
Yeah, what I mean, is not creating a new framework. But organizing the parts that are useful for you and the area you apply osint on
hi
I am terribly sorry for the damage I've done to you Jabba.
That warn changed my life truly
👋
hru
hi
I feel sleepy 💕
I have critical question
Just ask. 😄
The unpleasant interactions with mods here
yo
yo whats up
hi
:hammer: scottykuze#0 has been banned.
yo whats up my man
yo
and the hammer of justice entered the room
i just dont like discord latest update
I have execiment for pentesting in tryhackme I wish jr pentesting and offensive security not finish I want many rooms release so many rooms
the previous one was way better
Tryhackme release atleast 2 new rooms a week. 🙂
Whats unpleasant
One walkthough, (Tuesday) one Challenge (Friday 7PM GMT)
For the most part I've gotten used to it, however the small icons and text still hurts my eyes which is the only grievance I have with the change.
What the difference between walkthrough and ctf
same here
Looks okay ratio wise in potrait mode.
he is no longer with us
wow, I havent even noticed a change
They likely bashed heads with one of the moderators and have held a grudge since then. However their behaviour was not the way to go about it
Doesn't help if you don't.
nah
i downloaded it like this so i thought it was already like this
Yeah
what prior knowledge is recommended to start practicing CTF's?
fr
You are not as chronically online as me 😔 I notice when they move a text box two pixels to the left, it's quite sad tbh I should seek help
i think ctf are for learning prior knowlege
You finish paths and then start to ctf
when i asked the same question here
i was told to complete presec and cybersecurity 101
Likewise
jesus
My friend got voice filters with the last discord update, I want those
alr ty ❤️
Gave +1 Rep to @queen flare (current: #324 - 20)
i m currently using it
yup , i also use the onyx one
Don't make me feel worse 😭
in all fairness, it is part of my job to be on here 🤣
i keep thinking your 0day
yeah lool
Nope. Just juice
it just showed us a new Dark mode
and its fire
🧃
ngl
that's what she said
You need to touch grass 🤣

which pixel of the grass should i touch first

Guys I have crouse and I stopped using tryhackme to be honest and I and I afraid from stopping cybersecurity 101 and jr pentesting
ok
Hell yeah 😎
which one
and congrats
💕😭
goodnight
CFMOTO 450MT
noice
one day I will get a bike license
i already have that
anyone got the adder sw system76 laptop? or any good recommendations for pentesting/red teaming laptops?
buy any laptop
nothing
Did you know the same person who made windcorp on thm made a insane box called Sekhmet on HTB
🥲
I do
makes no sense if u gonna be trolling just dont reply man aint nobody laughing
I DO, AND THE BOX IS TORTURING ME
nah man
Take a break 😁 you got this
don't buy a macbook that's for sure
smh i was supposed to sleep
if u want to buy one specifially for pent test then any thing will work and install linux
yeah i wasnt gonna no way😂
An insane machine that makes people insane. Sounds right.
can you even run linux on mac
no it wont bruh?
whats ur budget
Windcorp was easy
like 2k euros

