#general

1 messages · Page 986 of 1

hybrid plover
polar spoke
#

does iwconfig run without iwd running?

#

if not

#

we can try nmcli device wifi list

loud marlin
polar spoke
#

shows 1.56Gb/s as the phy rate

loud marlin
polar spoke
#

seems like you should be seeing "full" speed

modern fox
#

uhhh why my daily strike froze

loud marlin
#

2 of mine. one 2.5 one 5g

polar spoke
#

yeah, there we see 540Mb/s

#

not sure why the negotiated speed is < 1/2, it should either be 1/2 or full

loud marlin
#

kali is this

chilly veldt
#

@mossy river inspiration for my next tattoo (17th april)

polar spoke
#

yes, that's full PHY rate

#

what channel does kali think it's on?

modest charm
#

whats up folks

hybrid plover
loud marlin
polar spoke
#

nmcli

#

same commands as before

polar spoke
#

which is a bit odd

#

given than that's a 20MHz channel

#

and could be a significant contributing factor to the speed

#

i expect that kali should report channel 50

#

which is the nearby 160MHz channel

#

since it's giving full PHY rate of 160MHz MIMO

loud marlin
#

upp is arch down is kali

polar spoke
#

huh

#

interesting

#

both marked as 56

#

perhaps as the center channel for negotiation/control frames

#

if you start a big download or a speed test, does that output change?

#

they wont run at full all the time, only when in use and the negotiation for faster speeds has happened

#

oh hey wait

#

what region are you in

loud marlin
#

NL

polar spoke
#

i wonder if your kali has a null country code set

#

and is able to do "illegally" fast channels

#

due to DFS or similar

loud marlin
#

the channels for wifi change on arch when i do speedtest

polar spoke
#

yeah, that is what i would expect

loud marlin
#

it change it self few time

#

go to 100, then 56 and so on

#

so set channel manual in router ? or

polar spoke
#

well

#

hold on

blissful snow
#

does mad hat use tryhackme just wondering

polar spoke
#

it's possible that the arch config is behaving properly

#

and the kali config is not

loud marlin
#

as in same speedtest

polar spoke
#

the DFS channels here

#

and some of the subgroup channels within it

#

are subject to regulation in different regions

#

and subject to interference monitoring

#

with a region code set in your driver, your adapter will behave according to some parameters

#

usually related to local airport and radar installations and such

#

kali, being that it's for pentesting, I often see set with 00 or null country/region codes

#

allowing all channels and widths and such

#

but this may be illegal and perhaps a bit "uncool" to leave on

#

despite it giving faster speeds

#

my concern is that your arch is seeing DFS channel interference/conditions and doing what it's supposed to by not intefering with it

#

and that your kali is not and is stomping whatever to get the fastest speeds

#

iw list should show us the region settings for the adapters

loud marlin
#

for kali chanel stays at 56 all time when speedtest

polar spoke
#

yeah, it's not moving when it might need to

#

this could be bad behavior for the adapter, despite it looking like better behavior

loud marlin
#

but on kali i got

polar spoke
#

it is interesting that it is giving full PHY rate speeds while reporting a 20MHz channel

sand trench
#

BELGGERHGEREF

loud marlin
#

i can force 40 in router

sand trench
#

cough cough

polar spoke
#

before chaning router side (though it should ALSO be respecting DFS)

#

lets see if we can determine the difference in the settings for the adapters/drivers

#

which i think means getting iwctl running

#

because i dont have another good way to query the region/capabilities from the running adapter

loud marlin
#

i can change region on router as i wish

polar spoke
#
iw reg get

this or iw list or similar is what we are after on the client

#

as for the router, setting it to NL is preferred if you are in NL radio space

#

though i dont know the NL power/band/etc. restrictions

loud marlin
#

is when i run on kali

polar spoke
#

interesting

#

ok, so we see country code is set to 00, as expected

#

but the adapter has decided NL for you which is good

loud marlin
#

on arch

polar spoke
#

again interesting

#

we see capabilities missing on the Arch one

#

or at least not enumerated

shut hawk
#

🤨

polar spoke
#

these both look like the adapter is "behaving" in that it has it's region set

#

though both have country code as 00

#

but it does look like kali is seeing adapter capabilities in the sub ghz range?

#

or rather, not attached to that phy but present elsewhere?

loud marlin
#

idk what anything of that means you say heh

polar spoke
#

so

#

in theory

#

that "country code 00"

#

should be NL on both systems

#

"should" is a bit strong, as the phy appears to be setting and respecting it on it's own

#

but it should be set to your regulatory domain

#

we see DFS UNSET so i dont know that it's "truly" respecting DFS without that set

#

but we are looking for differences here more than we are trying to bring you into regulatory domain compliance

#

can you run iw list

loud marlin
#

is arch

polar spoke
#

(we can fix the reg domain stuff later, its just a reg set)

loud marlin
#

iw list is sht load of info. any specific part ?

polar spoke
#

uh

#

good point

#

sec

sand trench
#

hmmmmmm qubes os

loud marlin
polar spoke
#

yeah you can do that

crystal moss
#

my pc is hot:

#

😛

sand trench
plain tartan
#

Could be a great foot warmer

#

I like to use my laptop charging brick as a foot warmer some days

sturdy niche
#

I left a SimpleHTTPServer open on my attackbox when I was trying to send a payload to a victim machine. Some IP started messing with it within 15 minutes.

plain tartan
#

That is something they warn about 😄

sand trench
#

yah that happens

#

especially if you are a subscribed user as then the attackbox got an outward internet connection

sturdy niche
#

It seems automated, seeing as how it all populated within seconds lol

#

I said 15 minutes, it was closer to 6 minutes. That's some freaky stuff.

polar spoke
#

the internet is full of scanners 🙂

sand trench
#

naaah scanners are full of internet

solemn kelp
#

Hey mate 👋🏼

sand trench
# solemn kelp Hey mate 👋🏼

Mate ( MAH-tay; Spanish: mate [ˈmate], Portuguese: [ˈmatʃi]) is a traditional South American caffeine-rich infused herbal drink. It is also known as chimarrão in Portuguese, cimarrón in Spanish, and kaʼay in Guarani. It is made by soaking dried yerba mate (Ilex paraguariensis) leaves in hot water and is traditionally served with a metal st...

loud marlin
#

what is that lol

vale raptor
#

I think, it is illegal

loud marlin
#

@sick lance @mossy river

grim sparrowBOT
#

:hammer: shivamshukla84670#0 has been banned.

#

Done!

plain tartan
#

I like the apps name 😄

full ginkgo
#

Oii bruv

whole yew
#

A few days ago

round orbit
#

Hey guys

chilly veldt
sand trench
loud marlin
#

not to you post heh

lament tendon
#

@mossy river 🎉

grim sparrowBOT
#

Done!

fierce thorn
#

This reminds me of that software "check if your cc is in hackers databases" 🤣🤣🤣

plain tartan
#

Okay but that's hilarious 😄

stray ice
#

Can I ask a question that is not related to tryhackme ?

lament tendon
#

Probably? As long as it does not go against anything in #rules you'll likely be fine. ;D

stray ice
#

so i have a problem in my code

#

i do a web page but i have a problem in my CSS

full sparrow
stray ice
twin ridgeBOT
#

Gave +1 Rep to @full sparrow (current: #1114 - 4)

cerulean nest
#

Guru GG

#

oh it hasnt updated

lament tendon
cerulean nest
twin ridgeBOT
#

Gave +1 Rep to @lament tendon (current: #36 - 255)

cerulean nest
#

lesgo

stray ice
cerulean nest
#

of waiting

#

for A->B

stray ice
cerulean nest
#

hell yeah

#

0xC

stray ice
#

So tomorrow it will normally be updated

cerulean nest
stray ice
cerulean nest
#

yw

stray ice
#

yw ?

#

i'm french bro

cerulean nest
#

?

cloud agate
#

anybody wanna do the brick heist with me im new. Like super new lol i just have an assoicates in cyber

cerulean nest
stray ice
cerulean nest
#

yw = you're welcome

#

lmao

stray ice
cerulean nest
#

what did u think it meant

stray ice
cerulean nest
#

oh lol

stray ice
#

bruh

cloud agate
stray ice
#

i don't know what's lmao too

cerulean nest
#

start on

#

pre security

#

if u dont have premium

#

still start on pre security

#

: D

#

dm me if u need help setting up a personal VM

#

theres prob some guide out there but some ppl (notably me) like doing it hands-on

#

so uh

#

ya

#

cya

ruby plinth
#

Anyone got a prefrence in terms of laptop for pen-testing? Trying to get more expereince in the field before i drop my OCS packet.

ruby plinth
#

4k is steeeeeeeep

cloud agate
# cerulean nest if u have premium

im not that new HEHE just new to the process of red teaming etc and how exploiuts work im pretty tech savy though i used to do htb but gave up trying to get through the 101 boxes alone

ruby plinth
#

💀

cerulean nest
cerulean nest
#

its like

#

$3200

#

not 4k

ruby plinth
#

Were on a military salary here

#

😭

cloud agate
twin ridgeBOT
#

Gave +1 Rep to @cerulean nest (current: #1824 - 2)

cerulean nest
#

omg 2 rep

#

no way

cerulean nest
ruby plinth
#

Thinkin a budget of like 2k

cerulean nest
#

buy a focken macbook or smth

ruby plinth
#

I have one

cerulean nest
#

na jk never buy a mac

#

hmm

ruby plinth
#

Should I get the top new model?

cerulean nest
cloud agate
cerulean nest
#

microsoft: no

#

apple: no

ruby plinth
#

apple

cerulean nest
#

lenovo: no

cerulean nest
ruby plinth
#

Where do you recommend looking?

cerulean nest
#

buy smth like

#

MSI

#

or ASUS

#

from costco's website

#

they have it cheaper

cloud agate
#

asus is pretty good!

cerulean nest
#

i think

ruby plinth
#

Just curious on the reasoning between those two?

#

Still delving into this field

cerulean nest
#

better

cerulean nest
ruby plinth
#

2k a decent ammount to drop?

cerulean nest
#

i just know they are more price efficient

cerulean nest
ruby plinth
#

my desktop is 5

cerulean nest
#

for a laptop no

ruby plinth
#

💀

cerulean nest
#

im on the MSI i talked abt earlier

#

its uh

cerulean nest
#

decent

#

oh yea that

round orbit
#

Lenovo ThinkPad’s are nice

cerulean nest
ruby plinth
#

I've actually heard a lot of people using ThinkPads in this field

cloud agate
#

lenovo is trash ngl

round orbit
cerulean nest
#

NAHHHHH

round orbit
#

Yep

cerulean nest
#

apple m1 better than that bs

round orbit
#

Same for Dell Latitude’s

chilly veldt
#

lmao

cloud agate
#

facts

cerulean nest
#

hell no

chilly veldt
#

apple fanboy

round orbit
#

Mac’s are shit

cerulean nest
#

fuck dell

ruby plinth
#

I hate dells

#

shits slow ash

cerulean nest
#

frfrfr

round orbit
#

Fuck apple mac lmao

ruby plinth
#

macbook runs decent

chilly veldt
#

can your macbook run arch?

#

didn't think so

boreal scarab
#

AY. Need y'alls help. What's a cool sounding callsign using the phonetic alphabet?
Could also include numbers

round orbit
#

Lmao

cerulean nest
#

if u know what ur doing

round orbit
#

Can it shit

ruby plinth
#

Idk how its gonna do with attacks

#

is my thing

cloud agate
#

that link i sent is honestly best bang for buck in your proce range SMH i used to work for best buy i feel like im now their discord sells man'

cerulean nest
#

the guy sent

round orbit
#

Good luck upgrading your mac hardware

cerulean nest
#

thats hella good

#

if u need setup dm me

ruby plinth
#

wrong emote

cerulean nest
#

i can help u uh

ruby plinth
#

🙏

cerulean nest
#

set up ur VMs

#

WSL or VMWARE

#

or both

#

idfc

ruby plinth
#

I'm still in hasing

#

give it a minute before we get into VMs and stuff

cerulean nest
#

every single course

#

is

#

fucking

#

$9700

#

for the good ones

cloud agate
#

its comfortable nad portable like a mac and has about as close to a mac track pad as possible while still having grate performace

cerulean nest
#

PER COURSE

ruby plinth
#

I just need a basic foundation for what I'm trying to do

cerulean nest
ruby plinth
#

The military will pay for my college

cerulean nest
#

W

ruby plinth
#

I'm not really concerned with cost

#

GI Bill go brazy

cerulean nest
#

lmfao

ruby plinth
#

both of em

cloud agate
#

im struggling with sec + rn so many freaking definitions its killing me

cerulean nest
#

just dm me if u need help with stuff

#

if its tryhackme then uh, dm someone smarter lmao

ruby plinth
#

🙏 I appreciate it.

prime bear
#

I want ask what the password to skip the siem

cerulean nest
#

im really good at networking

#

like

round orbit
#

@cerulean nest have you even worked in IT? Because both of the laptop models I mentioned are very liked and mass-deployed in a lot of enterprise businesses

cerulean nest
#

cisco stuff

#

etc

runic wraith
#

Does anyone know what software this is used?

ruby plinth
#

Nah I just need the basics of stuff, nothing to advanced the officer path I want will take care of that 💀

cerulean nest
#

they all look similar

round orbit
#

Lenovo feels nice, they use nice materials. Dell’s last a long time too, easy to repair and upgrade

ruby plinth
cloud agate
ruby plinth
#

something I can go home and swap hardware when need be

cerulean nest
ruby plinth
#

more storage etc.

ruby plinth
cloud agate
#

you will never be able to sw2ap cpus and gpus on laptops

ruby plinth
#

my notes are long ash from these courses 💀

ruby plinth
#

cheeks

cloud agate
#

but the asus i sent has m.2 storage yuou can add and swap

cerulean nest
cerulean nest
ruby plinth
round orbit
cloud agate
#

lenovco is also banned by DOD so dont do lenovo if you want to work in cyber in the DOD

cerulean nest
#

💀

round orbit
#

Only issue I have is the Fn and Ctrl key placement. But I think in the BIOS there’s a swap toggle

ruby plinth
#

so i appreciate this info,

round orbit
cloud agate
#

your welcome my dad was a cheif in the airforce and he told me that they banned them do to chinea adding a chip that had a keybopard logger on it and since then have been removed but still banned

#

sorry i cant spell smh

ruby plinth
#

you're good

round orbit
#

Don’t forget the military is still ran by boomers and non-technical senior officers. I was in the military

round orbit
#

It is painful.

ruby plinth
cloud agate
#

especiialy non technical officers thats very true smh

round orbit
#

The military has a very strong mindset of “It is isn’t broke don’t fix it” kinda mentality

cloud agate
#

i feel like officers should always start as enlisted

cloud agate
#

im jsut a military brat and i most definitely understand

round orbit
#

Yeah, in recent years I’ve used some legacy tech lmao

#

Oh boy

cloud agate
#

I kinda wanna join but im scared lol

round orbit
#

cough Dial up

cloud agate
devout palm
#

What did you folks learn today?

round orbit
#

A lot

#

Started my first day

#

As a SOC Analyst

cloud agate
#

congradulations bro!!

ruby plinth
#

dont forget the gifted kid syndrome

round orbit
#

Thanks man

ruby plinth
#

nukes in specific have it BAD

devout palm
#

Tell us so we can learn too!

round orbit
gritty hatch
#

hey guys any one knows the main diff between C2-server and payload server?

cloud agate
#

thats over my head im barely getting sec+ under my belt

round orbit
#

One is C2, one is for payload

cloud agate
#

im A NOOB couldnt even be a scipt kiddy if i wanted to

devout palm
round orbit
#

A question you can ask AI

cloud agate
gritty hatch
#

server*

round orbit
cloud agate
#

The key difference between a C2 (Command and Control) server and a payload server is their function: C2 servers act as a central hub for attackers to send instructions and receive information from compromised devices, while payload servers are used to deliver the malicious code (the "payload") to those devices.

round orbit
#

The real question is why

cloud agate
#

c2c send and control what the payload server sends that way the malicious code and the commands dont come from the same place

#

think of a botnet

round orbit
#

Exactly. If you take down the payload server, C2 still operational

devout palm
#

I have never heard of a "payload server". So that's a weird question.

cloud agate
#

in a bot net situation the c2c controls the hosts but the payload server send the actual code to the hopsts

#

like in a ddos attack the code to control the hosts is sent by the payload c2c tells the host to attack the server

devout palm
#

You can control clients (beacons in this case) without a payload.

gritty hatch
fair pelican
#

Hello everyone 👋🏻
I'm a beginner and I am seeking for a mentor or a boot camp

cloud agate
#

think of the paylaod server like a delivery truck or a hard driver to hold the code and the c2c as the OS

ruby plinth
# round orbit ?

people in leadership positions at least in my experience have this gifted kid syndrome (i work with nuke drops so this could be part of it as well)

cloud agate
#

i have very limited knowledge this is all guesses from what i know

ruby plinth
#

ships wifi sucks

#

1856 hours to download mac terminal tools

#

😭

round orbit
#

Brother, on a warship you’re lucky to get over 30Kbps, be grateful with what you have

gritty hatch
twin ridgeBOT
#

Gave +1 Rep to @cloud agate (current: #2786 - 1)

ruby plinth
round orbit
#

Emcon plan?

ruby plinth
#

nah just wasnt installed

round orbit
#

Sounds like emcon

ruby plinth
#

googling

cloud agate
round orbit
#

Emission control

#

Certain operations or areas have different emcon plans

ruby plinth
#

oh nah they were just trying to work out the contracts

round orbit
#

It’s a NATO thing

ruby plinth
#

wifi is new on ships

#

like were one of two carriers to have it

cloud agate
#

they need to give yall starlink for wif

ruby plinth
#

we have it

cloud agate
#

so it jsut sucks or maybe its the APs

round orbit
#

Or NAICIS

ruby plinth
#

but you have 5 thousand people all trying to use the internet at once

#

people downloading stuff, watching stuff, on the phone etc.

round orbit
#

Starlink isn’t too good from what I heard

ruby plinth
#

it also doesnt help that we have to keep moving in a circle

cloud agate
ruby plinth
#

say it again for the funny

ruby plinth
cloud agate
#

@ruby plinth do yoiu have sec +?

ruby plinth
#

yes

hardy bane
#

hi guys . plz introduce cve bot

ruby plinth
cloud agate
#

dude im struggling on studying for it any tips im using professor messer and the CompTIA app but i cant seem to get it through my head

ruby plinth
#

Oh I thought you meant secret

#

💀

#

Nah I havent gotten that far yet

cloud agate
#

LOL nah man this certification is kicking my but

ruby plinth
#

I gotta get to the offensive security course first 🙏

cloud agate
#

terrified to spend 500$ on a test just to fail

ruby plinth
#

500$ is STEEP

cloud agate
#

no shit LO)L

ruby plinth
#

I'm just tryna make my degree path easier 💀

#

Militarys finna pay for EVERYTHING

boreal scarab
#

@chilly veldt belllaaaaaaaa

cloud agate
#

i belive my company will too but still i have to pass it for them to pay fo rit

ruby plinth
#

Oh military doesnt care

#

I have both the Post 9/11 GI

#

and the Montgomery

chilly veldt
cloud agate
#

thats nice i used my dads to go to school and get my associates in cyber

ruby plinth
#

I plan to use the Post 9/11 for my bachelors

#

and then the montgomery for my masters

cloud agate
#

defintly keep it for your kids if you can

ruby plinth
#

Nah it's one use and I aint stayin enlisted lol

cloud agate
#

i dont blame you get in and get out making 200K

ruby plinth
#

theyre letting me comission or im taking my new degree, my secret clearnace, and my experience because I plan to intern somewhere to gain experience, and finding a job somewhere

cloud agate
#

i thought hard about going the route you are

ruby plinth
#

It's not a bad gig but being enlisted does suck a little bit

#

but no one else was gonna pay for college and I was tired of law enforcement

cloud agate
#

i just love my church and my community i finally have one after growing up moving every 3 years

ruby plinth
#

yeah that wasnt fun as a kid either

cloud agate
twin ridgeBOT
#

Gave +1 Rep to @ruby plinth (current: #2786 - 1)

ruby plinth
twin ridgeBOT
#

Gave +1 Rep to @cloud agate (current: #1824 - 2)

cloud agate
boreal scarab
chilly veldt
boreal scarab
scarlet fox
#

how can wireshark intercept network traffic on other machines?

ruby plinth
#

moreso watches where its going and where its coming from to my understanding

scarlet fox
#

yeah thats js my bad choice of words

ruby plinth
#

You can download the copy of traffic you sniffed but

#

best of luck decrypting it

devout palm
#

If you can redirect traffic to your machine then you can also sniff them.

#

Otherwise you can't get others' packets.

scarlet fox
#

alright thx

quasi pike
#

If hacker should be an anonymous person then why people posts their self’s on LinkedIn

mossy river
#

Because there’s a difference between CTFers and people who work in the cybersecurity industry

late forge
#

hi

orchid tusk
#

Ya’ll wish me luck on my business law exam, can’t wait to fail 😭

#

Never thought that reading code would be easier than reading law but here we are lmao

orchid tusk
boreal scarab
crystal mauve
boreal scarab
#

I've been thinking about it for like an hour.... it's hard to come up with a permanent callsign

boreal scarab
#

Oooh, could put fluff in it too AMthink

crystal mauve
#

Wen update?

boreal scarab
ruby plinth
orchid tusk
#

“I❤️Steg” 🗿

ruby plinth
boreal scarab
#

Oops, was uniform

#

I get em mixed up sometimes lol

ruby plinth
#

I used to get Sierra and sam mixed up

#

you can thank the sherrifs office for that

#

same with India and Ida

boreal scarab
ruby plinth
boreal scarab
ruby plinth
#

Our highway units were King Units

#

so 1K-84

#

1K-93

#

etc

boreal scarab
ruby plinth
#

I've been the chief of a few fivem servers for SAHP

#

was always 1K-01

wooden totem
#

Girlscout

sturdy raptor
wooden totem
#

The floor is rated feet only

sturdy raptor
wooden totem
sturdy raptor
#

working on that

silver sky
#

Jks love ya @boreal scarab

umbral bay
boreal scarab
boreal scarab
#

Been modding gta V for a couple of hours now, almost got it right

chilly veldt
#

Blue windows

boreal scarab
dark mason
#

Have you guys seen Burp Suite's AI feature?

chilly veldt
boreal scarab
chilly veldt
boreal scarab
chilly veldt
#

No one in the military has badass call signs

boreal scarab
#

News flash, this aint for military lol

chilly veldt
#

The call signs are nicknames given to you by your fuck ups

chilly veldt
boreal scarab
#

Want me to sound it out?

chilly veldt
#

They have position numbers

boreal scarab
chilly veldt
#

Have you ever interacted with anything like that?

boreal scarab
#

Like Sam 44, 1 Delta 33, etc etc

#

Problem with LSPDFR, you don't have a rank, and if you do with LSPDFR Enhanced, you go up in ranks, so it changes

chilly veldt
grim sparrowBOT
#

I cannot find a mute for the user mridulsharma.#0

chilly veldt
#

It correlates with the area you're in, unit you are and unit number

quasi pike
#

CTF players will grow to be millionaires
True✅
False ❌

cloud quiver
cloud quiver
oblique furnace
#

no screenshot for today or yesterday cuz i barely slept today and was busy yesterday

cloud quiver
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4318)

leaden marsh
#

The worse new I have heared That my laptop now inside it become alchol

#

💔💔

twin ridgeBOT
#

🔊 Unmuted cis32_mvp

eager marsh
#

What nothing for April fools

#

Yall are lame

cloud quiver
#

@round orbit Watch out for blacklisted words 🙂

craggy wadi
eager marsh
upper knoll
#

Evening chat

eager marsh
#

Plus an industry leading cert?

#

My brother in Christ it just came out

upper knoll
#

Hmmm

#

Seems like it’s kind of standard

#

Does a practical have the ability to cover all the other possible knowledge somehow who will work in a soc will need

#

Seems like that wouldn’t be possible either

finite basalt
#

imo a perfect exam would feature an open book exam and a practical element

upper knoll
#

As far as I know the SAL1 is open book with practical elements? But I could be mistaken

finite basalt
#

Like I think we should assess the ability to know things and find the answers as well as to show practical application of information

quasi pike
finite basalt
#

I don't recognise the name of that one, I only hold the AWS CCP

upper knoll
#

It’s the new THM one

finite basalt
#

but that's because work paid for it, I've not paid for any certs thus far

quasi pike
#

don’t try to fall in love with a hacker because every time you try to build a connection they will DDoS your feelings

finite basalt
#

Like maybe when I finish uni I'll look but until then

finite basalt
upper knoll
#

I think it could use a few months to get stable but imo the thought and work behind it is really good

quasi pike
finite basalt
quasi pike
finite basalt
#

nope

upper knoll
#

Careful you’ll summon the arch users

finite basalt
#

I definitely have feelings haha

upper knoll
#

They come out of the wood work if you mention Linux too much

quasi pike
finite basalt
#

I'm not very outward about them but they're there in full force haha

quasi pike
finite basalt
#

I'd say that it's probably common within the industry, problem solving's baked into our personality
we like solving things on our own so don't tend to be very outward about our emotions

upper knoll
#

No they’ll just come to talk about arch

finite basalt
upper knoll
#

And I just did a one hour chest bicep day at mostly midnight kekw

finite basalt
#

I woke up from a nap two hours ago

#

it is now 1am

leaden marsh
#

Why everyone like arch linux

upper knoll
#

Oh no they’ve gone and done it

quasi pike
finite basalt
upper knoll
#

It’s just another Linux distribution just so happens it’s kind of like veganism

quasi pike
upper knoll
#

You have/use it you tell everyone about it

knotty pendant
eternal timber
#

Sir yes sir

boreal scarab
pulsar knot
#

The perfect distro

modest thicket
pulsar knot
#

No... it's a Debian flavor Commadore OS vission 2.0

#

Commodore

modest thicket
#

its a bad meme sorry i just wanted to share it with you

#

there was this guy in here who was always like "i use arch btw" and i made that meme to reply to him

#

isnt Debian what Linus uses?

pulsar knot
#

anyone using parrot or kali is using a debian flavor

modest thicket
#

ahh.. i do like flavors..

pulsar knot
#

Commodore OS isn't a security OS though its just a fun kickback to the 80s commodore 64

modest thicket
#

some like chocolate, some like vanilla... yes i see fawaz

#

i cant see my fawaz wth

#

ahh.. now i see it

sick wave
#

Where's the THM april fools at 🤔

pulsar knot
# modest thicket 80s???

Yeah the 80s when your parents used let you ride in the back windshield of the car while they chain smoked Marlboros on long trips

verbal totem
pulsar knot
#

can't go wrong with either one I don't think

crystal mauve
#

📖 bash

spring acorn
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4322)

left coral
grizzled wing
worn turret
#

This was lowkey complicated

topaz skiff
#

i've worked as a devops engineer for like 5 years and active directory still scares me at times

#

though to be fair, writing scripts and interfacing with LDAP was its own sort of arcane magic

crystal mauve
twin ridgeBOT
#

Gave +1 Rep to @grizzled wing (current: #35 - 272)

dapper turtle
#

Yesterday I hit my 30-day streak. Today I have gone on 3 times and each time I've been greeted with a window letting me know I've hit my 30-day streak, and I do a short walkthrough room and my streak stays at 30 days, which seems... strange.

crystal mauve
celest dirge
dapper turtle
#

Yep. I’ve been on a 30 day streak for just over 40 hours now.

desert dirge
celest dirge
sharp citrusBOT
#

@dapper turtle

TryHackMe's Email

TryHackMe's support email address.

crystal mauve
#

It’s being looked into sed scrubs

cloud quiver
fair pelican
#

Hi everyone 👋🏻, I am beginner and I am looking for a team

knotty pendant
crystal mauve
#

Waitttt so chatgpt can do any art style johnwow

knotty pendant
brave totem
#

what if THM made every easy question hella hard for april fools

nocturne raft
#

When are the several learning paths getting retired? 11:59 GMT April 1 or April 2?

hallow laurel
#

is there any rooms that teach how to read and understand Apache logs?

whole yew
#

hold up dawg, i got the best hello kitty image to date

near sapphire
#

where's the thm april fools event 👀

knotty pendant
#

Soon

cloud quiver
boreal gull
whole yew
#

(the promise wasn't from Muiri though, so the collecting on that promise has been difficult)

near sapphire
knotty pendant
desert dirge
blissful current
civic oak
#

Happy fools day, stay safe, stay smart. 👊

blissful current
#

@inner bloom hmmmm..nice

#

i'll just enjoy playing games on my VR today , no grind THM

inner bloom
#

thanks

blissful current
#

else i'll play Beat Saber or AC Nexus for timepass

desert dirge
#

I haven't been able to get into the parrot website to download the OS for the last few years, so parrot has been out for me

Kali is a great toolbox, but it seems to me that a lot of hacking is going to be from target machine - to target machine in the target environment, so it's good to slowly wean yourself off of hacking distributions or tooling once you've gained some experience.

#

what the - where did message go

blissful current
desert dirge
#

y delet message, now I wasted my reply and look dum D:

blissful current
#

anyways am off here , cya

tepid citrus
#

Hey Everyone , we started using Chronicle/SecOps as our SIEM tool. Does anyone have resources for incident response and alert logic that would help accelerate the learning process?

crystal moss
#

Today im going to end the Jr Pentester Path, just the last challenge.. what path to take next?

cloud quiver
crystal moss
cloud quiver
foggy otter
#

or do both

crystal moss
#

🙂

#

Yesterday I set up a honeypot admin login on my webpage. I made it with Flask and the Webhook to Discord, so when someone tries to log in I get a message with the attempt and the IP it came from. Cool project 🙂

inner bloom
#

is ejpt good

hollow ledge
#

need tryhack me premium acc

boreal gull
inner bloom
#

i have no certifications
so i am planning to go for ejpt as it is not that expensive and I've noticed that many people recommend it

boreal gull
#

wonder if this is implemented yet 🤔

chilly veldt
#

BEEEEEEEEE

polar wraith
#

metaspoilt? 💀

sudden pond
digital socket
#

Hlo

blissful current
polar wraith
#

ye mb thas what i meant to say

whole topaz
#

Hello everyone, I’m struggling with some python exercises, beginner level, can someone help me in private ? (I have to do them before 2pm)

crystal moss
pine stratus
crystal moss
crystal moss
pine stratus
#

how the hacker supposed to find it so he login xD

crystal moss
#

Not made for any real safety but was mostly a fun lab...

pine stratus
upper knoll
crystal moss
#

woop woop

grim sparrowBOT
#

Done!

trail bloom
#

can someone find my bug

#
Scanner s = new Scanner(System.in);
whole topaz
upper knoll
sick lance
sharp citrusBOT
#
<#651923438524432404>
Rule 5 - No Cheating

Cheating in any form is strictly prohibited. This includes, but is not limited to, requesting assistance with schoolwork, employee assignments, or active CTFs. If you need help with challenges or content from other platforms, please use their respective Discord server. [See More] [See More]

cyan parcel
#

Thank you, @cyan parcel

sick lance
sudden pond
cyan parcel
#

:c

wary geode
#

Hello guys I was learning SQL injection and I want to practice where I can find free labs ?

twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4326)

sick lance
rapid merlin
#

hlo

red ibex
rapid merlin
#

can you tell me one thing

#

why this server bot is sending messages on my server even its not there

red ibex
rapid merlin
#

wait

crystal mauve
sharp citrusBOT
#

@cloud quiver

TryHackMe's Email

TryHackMe's support email address.

cloud quiver
#

@meager tinsel

mellow narwhal
crystal moss
queen flare
#

does thm have a walkthrough room for nikito?

sudden pond
#

Oh my heart

#

new swag For a moment i thought my cap is going to trash now

queen flare
#

like a tutorial room

crystal mauve
#

Haven’t seen one scorpius, just rooms that suggest to use it

cerulean aurora
#

hey

sick lance
#

There is a room that used to walk through it as part of the room, possible Tools r us.

ancient mirage
#

how are you today guys?

cerulean aurora
#

suggest some tool to get web application vulnerability

ancient mirage
cerulean aurora
#

ik that, any other options?

crystal mauve
#

Metasploit, ask chatgpt

ancient mirage
#

depends what kind of vuln you are looking for

cerulean aurora
#

any kind of

sick lance
#

Zap, Nessus, Nikto.

ancient mirage
#

have u already did the information gathering, enumeration?

sick lance
#

Openvas?

cerulean aurora
#

i means i am testing my website so want to know how many vulnab i have so i cn patch em all

cerulean aurora
#

can say that

#

me n my parthner we both

sick lance
#

Do you host it on your own hardware?

#

Or do you use a third party to host the website?

cerulean aurora
#

3rd party

sick lance
#

Then you can't test it.

#

You need their permission.

#

As it's their software/hardware etc.

cerulean aurora
#

um okok

ancient mirage
#

u can still ctrl+u, and give the source code to a.i. and ask him about possible vulnerabilities.

blissful current
#

🦹‍♂️

queen flare
#

attackbox ain't booting up properly

#

anyone else facing it?

queen flare
#

that's why i wanted to do a walkthrough room first, but its fine i'll just do some research

boreal scarab
#

@sick lance Wanna come up with a callsign for me? blobheart

cloud mural
#

anyone plays CTF on ctftime

sick lance
# cerulean aurora um okok

If you perform an attack that disrupted their service etc.

You'll have no protection from a legal stance.

crystal moss
sick lance
cerulean aurora
#

acha tell me methods to get admin login
like sql ssrf

crystal moss
#

I host my own stuff.. 😛

cerulean aurora
sick lance
crystal moss
#

But this is a bit interesting.. If I am not allowed to test the security of my site if it is hosted at a web hotel etc. and my site is exposed to an attack that could have been avoided if I had only tested the site, who is then responsible, the one who hosts it or is the responsibility still entirely on me, like that I should test the site in a local environment before it goes into production?!

sick lance
cerulean aurora
#

help me with methods to get admin panel access

#

only name will work for me

sick lance
crystal moss
#

Yes, of course you can, but are you responsible for doing it? Even if I test it locally, there is still a certain difference when it is in production.

cerulean aurora
#

why so

#

im doing it for my site as i already told u

sick lance
#

For the reasons I have already stated.

sick lance
boreal scarab
#

I have an electric gooseneck kettle 👀

crystal moss
# cerulean aurora why so

If you follow the different paths here, you will learn. Here you only get help with questions like the labs and rooms here, not your own projects!

sick lance
verbal pumice
sick lance
verbal pumice
#

gotcha

#

off topic, is it okay/possible to test malware in a VM?
I wanna go down the Redteam path

rapid merlin
#

hello

sick lance
#

Creation of malware is illegal, and out of scope for their channel, we discuss malware exploits in advance channels

sharp citrusBOT
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3587)

sick lance
crystal moss
cerulean aurora
cerulean aurora
blissful current
leaden marsh
# sharp citrus

I will make it summary!

In like level advance in tryhack u will access the advance rooms

blissful current
#

it unlocks 0xD[Legend] rank onwards

vital bluff
#

Please where can I get SSH tunnel ip?

sick lance
vital bluff
#

Where do they sell the SSH TUNNEL IP ADDRESS

crystal mauve
#

Ahh, need legend

sick lance
blissful current
vital bluff
#

The ip information

acoustic estuary
#

Are there ever any sales on THM premium? Trying to complete the cyber security 101 learning path completely but can't swing the $$ right now even with a student discount, hoping to hear there is sales every now and then

sick lance
acoustic estuary
sick lance
#

Random times or Black Friday/Xmas.

#

Sale is the same as student usually.

#

And they can't be stacked.

acoustic estuary
#

oof, i was hoping to stack them. guess i'll have to save up

steel aspen
#

Does this have a proper full article? I'm gonna turn it into Buzzfeed: I.T Professionals SHOCKED!

gritty fern
#

I believe it’s just that image

topaz skiff
#

i've got a big interview today, everyone lend me your strength

blissful current
cloud quiver
cloud quiver
#

Will there be a new room today 🙂 ?

soft bramble
#

hello
are certs for hackfinity available?

cloud quiver
main tiger
rapid merlin
#

Good morning! A new day means new opportunities to grow, learn, and move closer to your goals. No matter what yesterday looked like, today is a fresh start. Stay focused, stay motivated, and take one step at a time. Success isn’t about being the best instantly—it’s about being better than you were yesterday. Keep pushing forward, stay positive, and make today count!”

Wishing you a productive and successful day ahead!

cloud quiver
twin ridgeBOT
#

Gave +1 Rep to @heavy quarry (current: #1825 - 2)

hollow marten
#

I am in a room that hints to doing some parameter tampering via fuzzing. Without success with ffuf and gobuster, i checked a walkthrough and found the correct parameter and tried via a curl. "curl http://[machine_ip]?file=/etc/passwd" wont give me what it supposed to. "curl http://[machine_ip]?file=/etc/passwd --data password=somepass" does give me what i am after. So it seems i need to post password and have the file parameter appended to url as get. I have tried "ffuf -u http://[machine_ip]?FUZZ=/etc/passwd -X POST --data password=somepass -w parameters.txt" this doesnt work like the curl command and i dont get any hits. I have fried making FUZZ part of the post and that didnt wotk. My question is how can I fuzz a parameter that needs a post and get?

crystal moss
#

about POST and GET do you mean you want it at same time?

cloud agate
#

goodmorning yall!

crystal moss
blissful current
#

-# Good Ebening

cosmic pendant
#

GM

hollow marten
obtuse agate
#

Hello, Am new to Tryhackme and i want to learn ethical hacking, And some suggested me to go to tryhackme me course but i am blank now should i buy premium and ehat course i should learn and i want to become pro

#

Help me please

mellow narwhal
ancient mirage
blissful current
obtuse agate
#

Oh,

obtuse agate
#

Thank you guys, And after the introduction i should go to specific course?

blissful current
spice otter
#

start with the presecurity pathway

#

in the roadmap section in the "learning" tab on the website

obtuse agate
blissful current
#

THM provides 3 roles Roadmap in Cyber Sec

  • SOC Analyst
  • Penetration Tester
  • Security Engineer

u can choose the paths according to ur interests or do all one by one , upto u

obtuse agate
#

Oh that's nice

#

From your side, Which do you think is best?

blissful current
#

it depends on what u want to do , all 3 paths are good for each roles

#

As a Red Teamer i'm doing the Penetration Tester Path

obtuse agate
#

I think i should research on all the path and decide

blissful current
#

yes firstly do the 2 i told u above , there's a short quiz after that called career quiz which u can give and see what path prefers/suits to u

#

on the site's learning roadmap section

obtuse agate
blissful current
#

yes

obtuse agate
#

Lemme note down

#

Alright

#

For this two course should i buy premium?

#

Or lemme go in free?

blissful current
#

it gives some free rooms, after that u will need to buy premium

#

if you're a student , can get some discount for Annual subscription

boreal scarab
#

Ah yes.... AI, thank you.

obtuse agate
#

So, I should do that course and do Cyber security 101 and then do career quiz and select a one thing from three, And then buy a premium to become a pro?

obtuse agate
#

Sorry for ping

blissful current
boreal scarab
#

Need callsigns still, what y'all got?

#

👀

obtuse agate
#

Alright, Guys thanks you are a big W i will become hacker like you!!!

#

Am gonna become pro

#

We will meet back after i be pro

blissful current
obtuse agate
#

Wait wait, Last doubt do i need linux?

#

I have windows

viscid jungle
#

So you can install a virtual machine of Kali Linux or use windows if you’d like

blissful current
#

better to have linux , since many challenges will be on linux

otherwise can use ATTACKBOX inbuilt on THM site

blissful current
#

i'll recommend download VM with Kali/parrot on it

viscid jungle
blissful current
#

cant depend on Attackbox since it starts getting slow too

obtuse agate
twin ridgeBOT
#

Gave +1 Rep to @viscid jungle (current: #2788 - 1)

modern fox
#

arrives

blissful current
viscid jungle
#

I have Kali Linux as my permanent os LMAO 😭

modern fox
blissful current
modern fox
viscid jungle
viscid jungle
blissful current
#

it will then become

Microsoft Linux Surface

viscid jungle
blissful current
#

its too shit for Windows 10/11 and has less RAM n storage , will do that

chilly veldt
#

Good way to have a broken laptop

viscid jungle
modern fox
#

decided to full scan my comp via using windows defender or wtv its name is and it detected some viruses in my kali linux ISO image

viscid jungle
blissful current
#

(tbh nah , it has free lifetime MS office , helps me with college stuff , ig i'll probably keep it as it is)

rapid merlin
chilly veldt
viscid jungle
#

Windows just takes all my battery’s life

modern fox
blissful current
#

lightweight than Windows 11 tho thaz fs

modern fox
#

tho windows was slowing my laptop on purpose so ive deleted em

rapid merlin
modern fox
#

some competition thing

#

idk

spice otter
coarse hedge
viscid jungle
#

Imagine windows just detects all iso images as malware so we don’t install them and keep windows-

worldly hearth
#

Hi I have non-THM question guys. I have Pentest box and it has many Web Apps. Now I am trying Pentest one by one boxes. All web apps are on this IP address 192.168.231.128. the web app, I want to Pentest is in this address "http://192.168.231.128/bodgeit/" . What lines should I add in my hosts file so with just an IP address only scan my target Web App.

viscid jungle
viscid jungle
modern fox
spice otter
worldly hearth
spice otter
#

thats a valid reasoning 🤷‍♂️

viscid jungle
#

I apologise for my horrible humour

worldly hearth
simple turtle
#

I have completed a room but it's not showing up in profile just it's showing in my rooms section

rapid merlin
simple turtle
#

Is there anything to do

boreal scarab
blissful current
#

🦹‍♂️

simple turtle
#

Can anyone please help me

blissful current
simple turtle
#

I tried that thing too it's not working