#general
1 messages · Page 995 of 1
I lived in US, Manhattan exactly for 2 years
Well I'll have to find a jjob that supports that, but that definitely sounds like something I'd wanna do if I could lol
I live in Philly and the farthest I've been besides that was Florida once
Just get a remote job that doesn't require you to be in any one location and then you're good. You'll always be a US tax resident, and you're only a tourist in other countries, so you aren't paying taxes there
Oh damn it's 1am... I need to do the eeps
Gioodnight! Thanks for the help
'Course mate, anytime
I just had a big conversation with chatgpt and he talked about Suricata IDS
🦹♂️
I think im going to use it on windows
Maybe not on kali bc i use kali just for thm
Anyone has a opinion about suricata ?

https://youtu.be/k8yKTuvRmPE?si=H4uN3r6VHXRnr_YL
That's some of the darkest sh** I've ever listened to ☠️
I'm currently building an SO firewall for an ICS system with Suricata being heavily used.
sup people, i got a question, in Cybersecurity 101, at network security protocols at the last question, i found the flag i just cant type it
THM%7BB8WM6P%7D
i know that the %7 is {
i got it, for some reason the answer was THM{B8WMP}
B8WM6P i mean
that's url encoding
%7b - {
%7d - }
b and d are also part of encoding
yeah understood, thanks dude
you got a pretty clean yearly activity btw, congrats on the grind
I see you are on trial for a MOD congrats man deserverd.
@deep atlas @red surge Thanks 🙂
Gave +1 Rep to @deep atlas (current: #2796 - 1)
I see THM had a referral program in the past, does it no longer exist?
No.
Aw that's unfortunate
75 GBP* THM swag voucher: j0y0p1-x2ky0t-1zymgr-wmmdxi
*You still need to pay the postage of the items
**I don't know if this has been claimed.

Thought that was one of those scam messages for a second 💀
xd
Thanks 😎
Gave +1 Rep to @sick lance (current: #2 - 3601)
$12 isn't a bad price.
No, that was the only one.
Enjoy!
Can't believe somebody didn't take it the first time 
I didn't have cash so i needed to transfer some money to my bank
I was mid-game, luckily it autofilled my cc information lmao
yo can someone tell me why im not in the monthly leaderboard ranking of my country?
question
i think some event's dont count
the learning path doesnt count?
it does but much less than events
hm
someone can become a 0xMYTHIC with a few events
They've hacked it
@cloud quiver idk where to ask this
What ?
how do some people have gifs as their pfp on thm?
That'd be revealing secrets, the idea is they found out themselves
you know why im not on the leaderboard of my country?
You have to be in top 50
Which country ?
portugal
the first guy which is my friend he isnt on tryhackme that much, he stays in call with me doing a couple ctfs per day while im still studying to finish the cybersecurity 101
only ctf points are counted for monthly leaderboard
alright understood
walkthrough rooms are not counted
ok thank you for the clarification
----index.html
|
|
|
----- projet
|-----projet.html
|-----tableau.xlsx
Sur github pour faire en sorte que tableau saffiche quand je clique sur un bouton normalement je n'ai pas de besoin de mettre de ../ car il est deja dans projet
<button><a href="BTS SIO- Tableau de synthèse - Epreuve E4 -1- (1).xlsx" target="_blank">TABLEAU DE SYNTHESE</a></button>
On github to ensure that the table is displayed when I click on a button normally I do not need to put ../ because it is already in the project
but when I click on the button it gives me an error. and sorry hello everyone 🙂
guys I cant do it still lol
I just converted the gif to png and it still wont work
HAHAHA did it
English only please.
I also want this 
@sick lance
Unlucky I guess?
I posted the code in chat twice, it's fair game. 😄
no, I actually understood as there were spaces in the file name I should add %20 I don't know what it's for so I just renamed the file but thanks anyway
Gave +1 Rep to @sick lance (current: #2 - 3602)
You don't know what %20 does ?
no I know but why doesn't it work but on another file it works
It's used in URL encoding, also cli too
Hey guys is “chompie” in this community?
You know her,right?
No?
Hmmm 🤔 that’s interesting
Why is that interesting?
It's me
Hey!
Nothing really just taught she be here she very popular in pentesting industry
I have never heard of them...
..
lol 😂 cmon now
You changed your name
nop
What?
Your pronouns gave you out except your going to reverse engineer it 🎼
pretending to be someone else
I mean, depends on the length it can count as fraud.
😄
Say potato 🥔
potato 🥔
😂 no hard feelings buddy just felt the subject of the conversation is in this community
That’s all
I explained why I asked you to say potato.
You sent 4 messages immediatly after the other.
So it was either
a) Copy paste
b) scripted.
I know … I just found it amusing
You did not type all those lines out manually.
And in the case of b)
Self-botting is against ToS of Discord.
I did actually network just messy that day
I’m confused
One love brother ….. I think I’ll use it as my signature word now I love it

Kinda kinda mafia for real
The real Chompie wouldn’t
Another day, another day revising some web app
so true
I miss my laptop💔
From where u learn this one
burp suite is boring as hell
the tool is boring?
Thiking as game
no the room
i see
do i need to work on other parts too? 
this free?
Yes.
,
Had paid parts though,those labs are free, you can download the VM to host.
ahk ty
@sick lance I have been asked u
?
guys should i skip burp suite rooms and go for network security since its easier for me
From were this one
and do burp suite in the end
I love burpsuite it rembmer me like sweet 💔😭🤣
Google Pentester labs.
Its all free ?
lmao
Lol.
Favorited for when I'm good enough to actually be able to start these lmao
@sick lance https://pentesterlab.com/
This one right ?
does the jr pentesting course give you a cert?
ye
Yup.
nice
Hey I'm new in this field can anyone help me to start
Yup
These are basic
why thm support isnt responding on emails ?
Yes I can give you some tips but I’m a beginner myself so don’t rely on me so much
When did you email?
2 days ago
Ok, response times are usually 4-5 days.
And they don't work weekends
okiii thanks
Gave +1 Rep to @sick lance (current: #2 - 3604)
Oh I'll definitely be using it then, thanks!
Gave +1 Rep to @sick lance (current: #2 - 3605)
I am trying to practice firewall rules for an exam is there a windows server room on thm ?
Anyone else have their streak reset today (without missing a day) ?
I just lost my streak of 1700/1800 days 
:S
Contact support
Yeah done, just wanted to know if I was the only one
are you going for 10 year badge 😄
Probably 
need to do everything
Whats up brothers and sisters
Okay
Okay first tip is don’t spend time watching tutorials always, nor reading books, if you really want to learn you have to start hacking right away, and you will learn in the meantime you hack by googling, and you have to first have the mindset of a hacker, instead of saying “this is so hard to hack” say “what are small leaks that lead me to bigger opportunities of getting in” since thoughts shape our reality really. And try different methods of learning because each person has a different way of learning :3
I disagree here.
Oh and definitely destroy your ego, ego is the worst. You have to first master the basics before moving on to advanced, forget the side that says basics are useless
Watch tutorials and absolutely read books.
Yes true but I said “always”
Like don’t do it always, experience is also important
But it’s still important
Your sentence structure may confuse people who aren't using English as a primary language.
I'm not saying it's a bad thing.
i just learnt metasploit and nmap as my starting shit
I mean, it may not be your primary language, I didn't mention it to put you down, but bring awareness.
Yes yes I know don’t worry ♡
I actually love feedback like these so if you see anything off just tell me
good to hear that you flying high dude, get that masters. Physical pentest though, what qualification does it require? I heard that a minimum is defcon black badge
rough roads, feels like i wasted past one year academically after coming back from the internship. working 7am till midnight had its downsides i guess. Oh well, I got hailed at the company for doing what i did and got a full time offer so that is pretty nice. Joining mid june. Till then focusing on android reverse engineering and AI/ML
Also a pretty dang interesting dierction to go into, not gonna lie.
There would not be a whole lot of physical pentesters in that case. xD
Are there a whole lot of physical pentesters?
What u mean physical pentester?
More then Defcon black badge winners. ;D
Shouts nerdy
Literally all of us are nerds.
Yeah but physical pentest gather coolest of the stories I have ever come across
Can't talk about how I managed to unravel a stub to decrypt the squiggles worth 3 pages to find out a domain that was already in the telemetry
You legally break into the premises of your contractor by exploiting physically reachable vulnerabilities
Like hacking server ?
Hacking a building or a physical space that typically disallows public visits
😍
@sick lance
Now this is just spam at this point. There was another one in infosec
Why are not verified people allowed to post external links anyways?
Ikr
Feel like this type of spam would be a decently simple issue to solve.
Especially since these accounts were made the same day
Not even hacked
Actually nvm
November
I mean, they likely only find THM through the discorvery function or something.
Does not seem targeted, so some very basic mitigtions should work fine.
I think it would be nice to automatically delete messages that contain links and came from a non-verified member. (Since there is no embed perms)
Or redirect them to the advanced channels, I'm sure we could have a field day. xD
Yee, exactly.
Muting or banning them would cause false positives but deleting the message would fix the issue right away and cause no harm.
That's too harsh. Deletion is all that would be necessary.
You don't want to accidentally ban some new person posting a link to a writeup or something.
what are you talking about?
Some relatively common spam that pops up on here every few days.
We are talking about spam messages and their prevention.
Very poorly constructed spam. 
hi
Done!
This is unavoidable in public chat rooms
It's easily mitigable
Not true
Half the links are from verified but hacked accounts
why are the harmful links themselves not blocked, discord has built in automod for that
I mostly see unverified members posting that steam message.
hacked?
Hacked.
taken over
That's how they spread the spam message. Compromising accounts and posting that link everywhere.
is it common for people who are learning cybersecurity themselves, to get hacked that often
💀
Learning cyber doesn't make you unhackable
everyone is human
don't worry people that happen to be joined aren't all into cybersec
Some of the attacks come from close friends whose accounts have been hacked
im sure 99% of ppl here have gotten malware or hacked before
i know, but i'd expect them to be much more cautious
the way you said it makes me believe, it is a much more common phenomenon that i expected it to be
have you?
There is LLMS hacking in tryhackme
multiple times in the past

@mossy river is it okay to do group study of thm rooms in our own server like in my sever i have around 130 members i am gonna lead a osint room tommorow with them

I personally didn't get motivated to find out more about security after being a victim, but rather seeing others be
which I would say is more common if I had to guess

huge skill issue?
uhh more like got no money
im not sure i could elaborate further here, might be against the rules
then shouldn't you be more cautious with not ruining the systems you have?
(without saying anything more into that topic, it's still a skill issue)
Thats why you gotta becareful and make sure you have mfa on everything that you can have it on.
now you have reddit and vms 😎
If it’s your own server that’s perfectly fine, I can’t stop you
i should but i was dumb, i'm more careful now
my acc did that too
ohkiee i am actually building a local community of security so doin different activities
Why didn't you get motivated to find out more about security?
hey jabba, been good?
i choose the free room so everyone can access it
Ah yeah, i remember. But it is unverified members most of the time.
rephrased - I got motivated to learn security, but not because I was a victim
that might count as promoting another server
Ah ok lol
ohkay i'll del this
done
Busy busy
@rapid merlin
hope you having a good year so far, what got you buried under the stack this time?
Just as long as you don’t promote it here that’s fine :)
Throwback when I was 9y old trying to get Roblox exploits
(I got only ransomware)
noted
Makes sense
fsr minecraft mod sites always looks so sus
I just use mod launchers if I wanna play modded
Not that I play minecraft all that much anyway
probably the reason kids shouldn't have internet without being thought
experience is the best teacher they say
not the best advice when you have something to lose
Hey how can I start
honestly its much better to get ransomware when ur a child and have nothing important in ur device rather than when ur an adult and have a lot of important documents
Please tell me I'm confused
coming from a fam where Im the only one who know what a computer does except playing games, I'd say not so much
Um it's better to not have ransomware at all forget when your a child cause if that is the family computer boom you just got locked out.
idk bout others but my first devices were family owned
Sacrfice is the key
Which app should I download on my laptop for this
it's web based, a website
my first device is my own so maybe its different
No app needed
But where can I do real things.
Huh are you familiar with what try hack me is?
Noop
I'm waiting for my laptop
Specs?
Why are you interested
It's a website to teach you different concepts, and so you can learn different areas of cybersecurity.
Do you guys know dream craker
If someone says that they are waiting on their laptop to arrive it is clear that they wanna talk about it
I think a good question is What do you want to start?
Then say please 🫠
I need to code right?
They want to talk about specifications?
Hello
It's a good starter for the convo
No coding required
I'm confused to what you are asking for, what is the thing that you want?
Who's good at pentesting here? please msg me
What for?
that's how you get nobody messaging you
^
Maybe some malicious person would write him
In the end
What
Im just trynna get into ethical hacking
I mean can I make my own online security and in my area there are lots of cases about hacking so me and my friends take a challenge to learn code and cyber security.
Then take a course on ethical hacking 🙂
Do TryHackMe
ok thanks
You're welcome
Also is ceh really as relevant as pentesting anymore?
Nobody can tell anything new than tell you do self study
It will take 500-1000 hours
Basically to get decent
I think that the oscp and htb certs are worth way more that ceh
arrives
Is it better then watching yt vids and courses
I don't wanna say it's obsolete, because it isn't, but there are way better alternatives
I mean you are doing stuff practically and also do CTF's
Lol gato ctfu nice typo
Basically that
Autocorrect

It's more annoying to write this way
Much better
Yt videos don't teach you much
Or only the bare basics that don't help you that much
Just a question do people abuse this knowledge aswell?
Ofc
There will always be people who abuse knowledge
Absolutely
Ofc, you see them on the news
Could always get a physical keyboard for your mobile device 🙂
Too broke
you could always use a laptop
i feel like its a tablet
wrong reply
I have laptop, desktop
@halcyon dune how do you have moving stuff in your pfp without nitro?
Maybe it's a gif upload?
Avatar decoration
Or that
It’s like the chain around Ferb’s neck
is ferb rich
There was an event, kinda idle game and it gave avatar decoration after you beat the idle game
Hell yeah, he’s ferb
ferb who?
jabba ban him he doesnt know ferb /j
I wanna say it's jabbas pfp
Isn't that blackmailing? /j
is this a british thing?
It’s more of a “anyone who celebrates christmas” thing
Oh, no, British people hate everything
even pancake?
If it’s the sweet ones sold by Sainsbury’s yes
It’s just an overall negativity
Any of you guys familiar with fighter jets?
yeah
used to rent them to go to school
Why not both?
f-16 an hour for about 5 bucks
Thats cheap
you'd be surprised with the a-10 thunderbolt prices
used to be about a dollar for an hour
then inflation swooped in
now its stupidly expensive
Would this work?
this is very cursed
that seems like an a10 thunderbolt btw
It is
But with a cram for air to air
yes
that's why its cursed
i guess its okay if you don't fly it
use the cram for air to air defense
and the weapons on the a10 for ground to ground combat
drive it around like a tank

We need blursed images lol
anyways, i'll go look for some bleach to wash my eyes with
Question where exactly on the web of tryhackme can i learn about bug bounty
plz ping me
bug bounty isn't a topic you learn
its a way of earning money
you find vulnerabilities and report them through bug bounty programs
and the companies pay you for finding them
you can use tryhackme to gain the knowledge required for you to be able to hunt those vulnerabilities
please send code like this in codeblocks
its impossible to look at this like this
also this looks like an ip spoofing program
i'm not sure if these are allowed to be posted here
@mossy river
which page
I don’t think that’s how you spoof IPs tbh
Oh? but this server is related to hacking right!?
Ethical hacking, yes
@mossy river can I DM you about something?
Oh thanks! to save me from getting banned from server
Gave +1 Rep to @queen flare (current: #277 - 26)
Of course
@queen flare can you plz help me in dm?
no
ok
What should i learn first blue or red team?
why
depends on what you like
you could try taking the career quiz on the site
I like the red team but there aren't a lot of entry level jobs
Most probably you will end up learning both before you get hired
Blue team is kinda boring for me
Learning one is like learning 25% of the other one
purple team
A guy told me before learning the red team you'll end up learning the blue team first
Not necessarily
if you're worried about it career wise, try posting your concern in #cyber-and-careers once. the people there can guide you about career advice very well.
otherwise, i'd say just keep learning whatever you enjoy
knowledge does not go to waste
What rooms do I have to learn? My college doesn't have a specialization for cyber security, i have to rely on the internet totally and there's a ton of knowledge i get confused
from your roles here, it seems you're a premium subscriber
if that's the case, i'd suggest following the learning paths as they are cause they're great
Gave 1 Rep to thunderstar1724 (current: #270 - 27)
Okay, i think i will learn the blue team for now
👀
Years
pentesting?
Of hard work on fundamentals. People treat it like the gold rush was treated but very few make big or stable money
It’s going to be just as long for pentesting
yh
but alot of people who learn too abuse it
i mean the hackers and shit did it take them long too or they just knew the basics and dump data etc
(not doing it my self js asking)
No
No skiddy with a data dump is making money of a bug bounties because A that’s not how it works and B is illegal
cuz
thats why i asked
Did it take them yrs too
That’s illegal if I’m understanding what your saying
@cloud quiver I believe this convo now no longer follows laws and ethics.
😭
Yeah that is illegal , we don't discuss such things here 🙂
Thanks 🙂
Gave +1 Rep to @upper knoll (current: #181 - 47)
Sorry i was just trying to explain complexity of field didn’t realised they wanted unethical side. Appreciate you

sorry sir
i dont
..
I was just curious sir
It's ok , just don't continue further with illegal topics 🙂 .
Good morning 
Good morning
wont
don't mess with KGB mod 🙂
Do ads just not get regulated? I keep getting google ads for a gambling game that literally says "you will 100% get 10k dollars in 1 day of playing, no lies, no scam"
Hello
So botnets sole purpose is illegal activity ?
probably I would need to do Soc Analyst as next one
yo chat
I kept going on red path it gets way harder imo
Wap + RT
Keep it appropriate
Did you think doing something illegal was for a good cause?
Probably I should do that too, though I think I need to get some SOC skills to get different perspective
Am i not allowed to say this?
That was not appropriate or PG13 😄
Lets be friends
No but I guess in nation state v nation state stuff it would b classified differently, just wondering/thinking in what environment would bot nets b ethically used
@mossy river friends?
I'm okay thank you, I haven't really spoken to you 😅
Is there any good py dev here
Yeah but you’ve been honing your red blade to start using it in tougher tasks n they are barely coming up imo
Do you guys prefer to do coding or pentesting (i wanna learn something but i wanna learn it fast so which)
Then neither is for you
You can't learn anything fast
Completely subjective
Yeah, true 😄
Programming is easier to learn imo just because there's sort of an end goal, put pentesting there's always something to learn
What about ai
coding
Easier but you still need to understand programming to modify the code
i dont think the codes ai give u r always good
so prolly half of the code gotta be self coded
gonna hit trough web application pen-testing
true
doing the same
🍿
That is unethical please don't ask here
I need for marketing sir
We are unable to verify that
do I have to make notes also?
Please.
i do, and i enjoy it also
Gave 1 Rep to codru. (current: #353 - 18)
If you continue to ask you will be removed I'm afraid
epic, I always find SOC for me being more pain, but I think it's quite beneficial
You're trying to misuse a service for personal gain
miss the days when my name used to be red
I do want to do pentest and go for red team but I think learning soc analyst is the first step of doing that
soc is kinda boring for me, no offence to anyone
Most soc analysis would agree lmao
They aren’t talking to u
Who is the best dev here
They aren’t addressing you
but I think most of us don't have a choice, we do have to start with soc before diving into red team
?
What are you saying bro
He wasn’t taking to you
he was i think
No he wasn’t
Jesus Christ
mybad
Luckily for me I might be able to get directly into pentesting or red teaming
why i have a heart flower of green color next to my name
You just type u don’t read
too lucky dude
Kid
Muted
Ok kid
(I know a dude that knows a dude)
i was just writing this
without reference it's next to impossible
??
Basically
I'm new to the whole discord, not just this sever..ik and used discord for a long time but not too much
Soc boring stuff, but knowing it well pays well
I think it's easier to secure such a position too
and easy to get a entry lvl job than pentest/red team
agree
Wallpaper of the day:
But red team is Love
Hehe, can be also bug bounty hunter during night soc analyst during the day
probably gonna use this for a while
I hate bug bounty so much
sleep schedule crying in corner
Not the concept of it
reason?
But how companies treat the reports
You find Sql injection?
"Works as intended"
Or
"Low severity"
How long have u been doing it thief ? Bug bounties
Don’t low severity still pay 400$ in hacker one ?
😂
"Me: Finds SQLi
Them: 'That's a feature, not a bug.'"
I haven't, I am just saying what some of my friends told me what happened to them
Really I think bounties are quite useless, if you don't have your own exploits otherwise 1000's of Indians using the same tools and the same methods to exploit stuff.

Wrong imo
I think they are reffered as script kiddies😂
🤔 yeap, this
Bug bounties are not for script kiddies
We are all prob skiddys
Who knew?
Elaborate?
most of them are just doing this because they think this is cool and companies will pay them a fortune
in some way or other, we are
Do u write your own exploits , write code , and have found zero days ?
Zero days or CVEs?
Either
I’m def a skiddy,
Most probably no
Nice what did u find ? Or write
I am scared of the ban hammer, so I invoke the fifth
But it was nothing impressive
I thought it described anyone who just runs scripts or can write basic ones w chatgpt but doesn’t really understand the or any language in depth / syntax or rules
Basically just an IDOR that allowed to change the date of other users
Anyone who all they do is that, not put any effort into manual pentesting
Yeah I found an idor too but I don’t consider that at a difficulty range high enough to consider myself not a skid
Like testing for xss, sqli, they go around on cve and try thousands of targets
In hopes they would find smth
@halcyon dune check ur dm
Please make sure to ask before DMing users #rules
ig he won't be offended
but from next time i will make sure to ask first
thaank you
Jabba what do u think qualifys a skiddy to non skiddy?
Understanding what you're doing before you do it.
Or at least trying to read it
Perfect explanation imo
It happens

Are you trying to get into red or blue teaming?
guys I have poured cold drinks on my laptop keyboard yesterday, and some keys got sticky and hard when pressed, no internal damage, what should I do
wash them?
Either really, lately I’ve come to the realization that an IT job is more likely. So thinking Comptia trifecta to be practical
How bout u @dark mason
Rn I am not in a hurry to get in the job market
you say wash them, i heard go and buy a new laptop
I have 4 (or 8 depending on my luck) years to study
Ye I’ve been operating trains for 12 yrs so I’m not in a rush but I’d welcome the change earlier than later
come crash at my place sometimes😂 😢
Do you think you will be unable to get a job in cybersec?
Or did I get the wrong impression?
Well it sounds like the market is saturated w sec+ applicants so the path might be,
A couple years as IT + other certs before trying to join the cybersecurity pool of applicants
Wawat?
I don't think that's true, there is a high demand for Cybersecurity professionals, with the right certifications you will be able to land a job quite easily, at least as a soc analyst, from there you can build experience and eventually move up to pentesting or red teaming position
one of your trains
+1
Good evening chat
Think so ? Previously I thought the same. Was thinking, get trifecta / 100% thm, get htb certs and try for a soc role, but since I don’t have a degree and a lack of experience in the field I thought that’s how I’d make it up for it
excuse me, can I ask something please?
Sup study?
in your opinion, what do you prefer more? Swe or cybersecurity? Tysm for answering my question!
At least here in romania, I have been looking on LinkedIn, recruiters rarely look for a degree, most care about certs way more
cuz i'm pursuing in comp sci and considering both
Need someone to make a panel for me dm me
If you're doing a degree, do compsci, opens the same doors as cyber but even more in other areas if you change your mind
you're lucky to be in romania then, Here in India everyone's dying for a degree
and yeah how the hell can a 16 yrs old hack Rockstar company guys😭 . I'm 15 and still struggling with nmap and linux fundamental.s
In romania the job market is amazing atm
anyone from aus?
If you get the oscp you are basically hired
Thank you Sir
Gave +1 Rep to @mossy river (current: #6 - 1565)
A few recruiters n people in the field I was chatting w suggested the indirect path in #cyber-and-careers not too long ago
he was curious enough of learning ig
and we are here only learning for landing a job
That's also an option but not required
ye he somehow hacked into a cybersecurity company
The dude that hacked rock star was not good at hacking
He was good at social engineering
Oh okay, do u know how did he learn how to hack? cuz im really curious how did he learn it by himself
oh yk wat thank u
I think it was always an overkill to call them a hacker, just my opinion
Nah, I just watched some yt documentaries
if you want to hack something you have to be good at it(passively or actively)
If I send someone an email pretending to be part of the company and asking them to open a "real word document" but it's actually a malicious .exe, I'm still "hacking" 😄
Need a dev who can make a panel with pages etc etc
True
system's aren't meant to be broken easily but humans do
a part of it
You're asking in the wrong community tbh 😄
I mean true, but it's not nearly as cool
Why
there are stages that you have to go through
ofc not, but there's a lot of cyber that isn't like it is in the movies unfortunately
can somehow silently hack me pls
That would be illegal lol
mb mb
this is an infosec community, not really a programming one, you're more likely to get an actual response from one dedicated to programming
Not saying it's not possible however this is your 3rd/4th message here within the past hour and you don't seem to be getting what you are looking for
I have a demo discord id how can I hack it can I hack it from my phone or do I need my laptop
You can't because that would be illegal 😄
you are a beginner dude
Do u have recommendations
on any server then
But that is my own account
Yes
then you can't
Yes but it's not your service.
You need permission from the service, you don't actually own the account on any service you make; they can take it away as quickly as you made it
What?
I don't I'm afraid, I'm not in many communities - you can try searching the discovery page to find some
You are using the service, that does not automatically give you permission to hack it.
Which service
try learning instead of hacking account if you're a begginer, it will get you in a lot of trouble
Okay
Please make sure you are familiar with the community rules #rules
for your case; discord
Bro level 5 role looks similar to 0xC
Okay do I need to learn code
It feels cold without a shadow 🫤
I was suggesting to learn ethical hacking not to hack illegalily
It makes it really difficult for me to enforce the rules if you are interacting with them also 😄
Nah your feeling cold because your lonely dude
sup
my bad
Bruh you are wrong :/
Hey Cookie how are you?
Then you must have opened your window 🪟
@lyric minnow Dude I can't help you with any question you have
respect @mossy river guys, his pfp is cool
alr g9 everyone
have a good one
I'm great, how are you?
he will also not help you if you're trying to hack iillegaly
dude you scared me for a sec
I'm good, thank you! Doing some studying.
Gave +1 Rep to @sturdy pike (current: #103 - 77)
I'm running towards you, but not towards you as well.
Great, gotta churn that knowledge in
No I'm not trying to hack illegally I own that account and I'm learning it to compete with my dad and with the recent hacking cases
Your new car looks awesome!
You don't own the account, at most you own the data within the account. Even so, it's not yours it belongs to the sevice.
You can learn cybersecurity at https://tryhackme.com/
True
But not only discord I want to compete with him
German?
Compete in a legal and safe environment https://ctftime.org
Capture The Flag, CTF teams, CTF ratings, CTF archive, CTF writeups
Deutsch (Don't have special characters on the keyboard, also yes)
Or compete with him on TryHackMe to see who can complete the most challenge rooms
Deutsch
😁
I wanna look at some pentesting methodologies, I feel that I lack somewhere
That’s some multiverse level behavior right there.
Looking won't help
He's running at an angle to you
You have to do a lot of ctfs
Blud corrected a native speaker
I'm doing CTFs but I have a ton to study
so I kinda go along with what time I have
either challenges, CTFs, boxes, or learning
Reading up on pentesting methodologies of course would help
don't worry, the vessels I choose are curated everyday, thou shall not worry of the sanity
Implementing methods from it in CTFs will cement it
Simultaneously chasing and avoiding me? Peak toxic teleportation
totally agreed, I follow up those methodologies, once I feel confident enough, I may create one of my own
Watch some ippsec videos, read some ippsec writeups, there are other people publishing writeups out there too, but I don't remember anyone else to specifically recommend.
Ippsec does a great job of teaching during his videos
I mean are we talking pentesting methodologies or ctf methodologies?
catch me if you can
whois x.com
If there is color blindness, is there smellness and tasteness
5-second rule still applies… unless the grass was feeling spicy.
wait are we talking about methodologies or techniques
I've watched their videos and found it helpful, thanks for the recommendation tho, I read up the write-ups too
Gave +1 Rep to @desert dirge (current: #632 - 9)
both, I go Pentesting for challenges and boxes, CTFs are a given
Because methodologies you can learn from some cybersecurity podcasts, depending on your focus.
Learning about OSINT helps with pentesting hugely
being able to curate username lists and password lists when you aren't on an assumed breach is a good skill lol
Or password spraying for that matter
typed ls in chat
lool
You just unlocked stealth mode and gaslight mode at the same time.
Catch you? I’m still trying to process you.
Learning about security misconfigurations would help with providing a comprehensive report too
It's easy to fall down a rabbit hole, and they are expensive as far as learning options go, but TCM-Security teaches pentest and soc methodology in their courses
checkmate
yeah TCM does a great job at teaching pentesting
agreed, I've been catching up with the knowledge gaps
And here I was playing Uno Reverse
You can learn and practice techniques on THM and HTB and get supplemental industry oriented learning from TCM, if you can afford it
Actually I think TCM switched to a monthly subscription model, so it might be much more affordable at this point
Fool me once, shame on you
Fool me twice, shame on me
Fool me thrice, shame on you
Fool me four times, now you're under the impression that you've fooled me
Fool me five times, why are you fooling me again and again, taking advantage of the weak me?
Fool me six times, bro, stop fooling around, you're under my trap now
Fool me seven times, I forgot that you were under my trap and now I'm under your trap
And on the eighth kie clapped coo clamps and trap was tripped
I'm kinda overwhelmed by the subscriptions that I already have lmao, so I've been trying to complete whatever I can in the meantime, I'll try that out tho, appreciate it
np m8!
My gym subscription that I stopped using 😔 (I was locked in for 6 months)
Fool me nine times, bro, the game's over, we're both an emotional wreck now
bro's becoming sweet instead of becoming the tough guy
one big ball of calories
wouldn't that make him a cookie?
That was a good one lmfao
Anyone knows a server where they do websites etc panels pages
fiverr, upwork
discord servers
same answer, I don't think anyone is going to work for free on something like that unfortunately. You might have to do it yourself.
You can find some pretty good advice on starting work on things on the internet if you word your searches the right way, or ask the google gods the right questions.
@mossy river Found your notes
i know sir
i pay
For the record I went to the gym for a year straight 🤣 However I switched gyms and became too busy, but it was a 6-month contract
I am debating putting up a local wordpress instance with a random CVE with no poc and try creating one myself
Any particular reason you wanna do that?
why noone told me that cyberchef have dark mode =/
cus it looks worse than with darkreader
one peice is real
trying to see how exploit development works
I find it kinda intresting
it does not
Wouldn't be better to setup your own environment to do that in
what do you think using it on my computer?
Eh?
?
Wdym?
that's... what I said I will tho
and ossec
why you need suricata on pc for first place ?
i just want to keep my pc safe and protected against scans and atacks
with this IDS i can monitor and do something about it when it happens
iirc you have 32gb ram nad so on. you can run lot's of things in VM
labbing*
just use some fair and paid vpn for start
hi
suricata is smth that is quite for big things.
ok bye
no need for basic user
i understand
for my pc i only have vpn and adguard. is based on router lvl confgured.
i configured my firewall, i hope i did it right , i blocked all incoming , and blocked ping requests, disabled syn scans
tbh for whole home network is like that
and i have bitdefender free av
im going to reinstall kali now on vm, i have to do a lot of things
if you do that. get some pain AV. nod32 or smth. idk what windwos use theese days. but vpn for start
im going to use protonvpn
scrub is some who doing cyber in more profesional way. so he doing stuff that 90% normal mortals no need to have on just pc
i'm also use proton service. mail, vpn for default
i use the mail service yes, but rarely the vpn, i should use it more
protonvpn have app that you install on windows and use it that way. for me i also have on devices when im out of home network
is password manager from proton. i use bitwareden for password manager.
is like 10$/y or so
protonvpn is very different now , i dont remember it how it looks like now
this is firewall for start. firewall can be pain in ass to setup
i cant do much on protonvpn but
i enabled this
and the kill switch
the kill switch is on advanced mode, meaning that it keeps on when i restart the system
now my internet is slow 🙂
go udp
you need to check that on internet. tcp/udp is same but different
ik , but idk the cons using udp conection on vpn
TCP for reliability, UDP for speed.
the vpn just freezed
it is long road to explain
this
idk whats happening but the app is not working properly
on windows ?
yes
if vpn is active on windwos, the host os, then vm are using same vpn
what you use now? you can separate adapter if you wish but there is no need for basic usage
Then you have to use the vpn inside the vm
then is ok. when you use vpn you can check does ip change. first check ip without vpn and then with vpn
the vpn on host , and check the ip of kali
?
and use bridged adapter
that part i have to do later, now im going to install kali linux
on host and cehck ip on host pc. there is site. dns leak or smth like that that can check things for you
When are you planning to go back again?
so u say, no IDS for basic user?
that is soc thing. it can be on pc but no need
yea, i just wanted to get the alerts if anything is happening to my pc
but yea, ig i can live without it
after installing the kali and configure everything, im going to test my host agains scans
i should not get any result
its suppose to not find it, or show it is down , or no open ports or filtered
My work just aked me if there are any certifications I want to get so I was wondering if ther were any good ones
and im going to try arp spoof too, im figuring how to detect it
it will find it. vm need to comunicate to host pc since they share network connection
aside other things
humm
morning
It's afternoon here but good morning
morning is more of a state of mind
ok, kali installed... now , update , install ufw , configure it , configure ssh access
it says i dont have any APT data source so now i cant update the kali
this issues i get...
Ask in #infosec-general it’s alot slower there
Gave +1 Rep to @crude stump (current: #62 - 142)
Yes sir
Hey everyone just watched a series named scorpion in which a small boy hacked nasa to take blueprint of rocket for his bedroom and the thing that should be noted that it's actually true is a story of walter o brien so right now I am truly motivated so please anyone can help to get started
To start, sign up to the site https://tryhackme.com/ :)
Is it free??
Yes!
Get back to THM and finish OWASP Juice Shop...
Looking for a learning partner pls dm mee if anyone interested
ah I totally forgot that I left my machines running! Thanks for the reminder lmao I was reading articles on OWASP rapidly