#general
1 messages Β· Page 1008 of 1
Mate, you don't even have to tell me
I'm doing a project to intergrate a firewall into an ICS testbed, and the guy who built it, mentains it, has no clue what I'm doing.
my uni has stationary stores that use PCs with windows 7 connected to the internet. They open all files from whatsapp that students send for printing and stuff...
If I don't get a first for this, I'm rioting.
The hack was most likely caused my the windows XP machines running their outdated software
Lol
Because they don't want to pay to update the software
π
Just don't use forti or ivanti I guess
Paying the ransom will be cheaper actually lol
Nah ππ₯
But if it was a local company they could've probably prevented it
Ye it was a saw mill if I remember correct their control software for the machinery
Could've probably paid to update the software
Yeah, but you still need a way to execute this. No point in putting a payload on disk if it's just gonna sit there inert.
Spot the fortinet gear π
Then again Palo Alto isn't much better
I love fortinet
In that video their helpful little demo script extracted and executed
Me too, I was able to get admin access in a few mins.
That particular line which says "It loads the DLL into memory" or whatever. I was just thinking how it's possible to extract it autonomously from an image file
I got a fortigate 40F at homeππ
It's not
Been working fine for my gigabit fiber connection
Just don't leave your fortigates connectable from the outside
The demo script even says that it's simulating a malicious service.
π
Patch all the things
Chuck all the things out the fuckin' window.
My coworkers absolutely destroyed Palo though
So you would need a malicious service installed monitoring the cache to extract new malicious images as they appear.
It would be quite a novel a way to get C2 commands into an already compromised box, but that's about its only use
That company also forced us to publish a responsible disclosure policy
OPNSense ftw
Well there was global protect as well
Worth noting as well that finding Discord installed on a corporate device would usually be a security breach in its own right, so, uh, there's that.
Yeah sounds like a bad idea
I'm convinced that security software vendors have no idea how to code securely
Stormshield?
Fortinet confirmed.
lets goo i got level 8
Advanced SQL injection was great. Also got a script alert for XXS on one task.
hi i need a consult, i run a tcpview on my pc and i see several outgoing connection from an os process named searchhost.exe
my friend also has win 11 and he doesnt have thoe outgoing connections, the signature on my process is valid, but its still sus to me, can it be malicious?
I loooooooove academic type attacks!
Hey we can, in theory, under carefully controlled circumstances, tell what colour your eyes are from the fan speed on your PC! Critical!
Yep! 
Always cause for the media to latch on and fearmonger too...
Hey hey
Do you know what searchost.exe is for?
Exam in 17 minutes xd
@sick lance yea its responsible for windows searching and indexing i guess?
Is that an answer, or a question?
Distracting myself not to be stressed
why its connecting with outside world? i fear the process is hijacked or something
How are you fellas doing?
answer i guess ? lol
Then you must already know what to do, and the steps to take...
i tried disabling windows search service, and its still running
i also tried quarantining it with my AV but it didnt work
anyone here taken ISC2 CC certification before? any study tips or notes that you have that can share with me?
Just do a malwarebytes scan and let it put your mind at ease @simple epoch
So you're good
is it possible for virus to run from a legitimate OS process?
like hijack it or impersonating to it? (and showing the valid signature)?
or am i too paranoid xd
If subscribing to a GPT model, which one do you think is worth subscribing?
am I allowed to post a challenge from an CTF that just ended in here? (osint)
you mean like a write up?
nah, the challenge
if u guys wanna try it
it's fun!
Oh, yeah. sure
can I dm you until a mod responds?
Aslong as the CTF isn't active anymore, and it's not a private CTF (school, uni etc)
All the best, though your exam might have started by now
I mean, if the message was sent 35 minutes ago, and the exam started 17 minutes after the message was sent, I would say it's a pretty good bet that the exam has started 

Image the ping put him off, or notified causing a fail.
ayooπ
@safe valley Can I help you?
What is ics2
ISC2
@sick lance I've gone through again line by line, So I found answer. Thank you.
Gave +1 Rep to @sick lance (current: #2 - 3631)
just wondering why you sent the friend request, is all.
I mean, the user asked on a social media platform about something, isn't that the intention of the platform?
uh, wait who what
The user asked what ICS2 was, somebody said google exists.
ah lol right
So you were just trolling here without context?
nvm mb
What such dream π₯Ί when I dream you get inside the vr and live with people And I love someoneπ₯Ίπ₯Ί its digtial world I want the vr one day to be A real like living and studying marrying working real life in cybersecurity π€π I loved the dream
Hello, i am a 18 year old who just started to learn about cybersecurity because I wanted to explore all types of computer jobs and I wanted advice on what career path I take in tryhackme
I did the quiz
It gave 5 jobs
Penetration tester, security analyst, incident responder, red teamer, security engineer
Idk what to pick
Should I learn pre-security first and then think about it? But red teamer doesn't have pre-security
I'm lost someone pls help me
Pre security and cybersecurity 101 is about both offensive and defensive security so u can do the pre security and cyber 101 to try a bit of everything imo
Okay
And then u will have a better view of both to chose which path u want to follow
Yeah okay thanks I'll start with pre security then
Np and btw there is no pre-security for red teaming cause red teaming is a more advanced field in offensive security so if u want to get into red team itβs better to get into basic offensive security first π
I'm clueless so ig I'll just stick with pre-security
Redteaming what the basics for it to start in tryhackmd
Lol that's also true
just follow this path: https://tryhackme.com/hacktivities
its too good
after completing it, you can start doing challenges and CTFs
does this apply to the discord company as well 
Watch people use discord as C2
hey to connect to thm with vpn i need to do it on my kali VM right?
Yes.
sudo openvpn VPNFILE
Or use the attackbox
Hello, iβm new here
Hello welcome
I have subscribed for 1 year and am studying. 
what is a recommended shell tool to use in kali, i know there is something people using other than the nomral shell
... What do you think.
Me using Discord as my second hard drive π
Blasphemy
It's mainly just screenshots I need
Discord for me is also a free unlimited cloud platform
How dare you not spend thousands of pounds on those instead of discord
I am broke!
I have 3tb of NVME m.2, and I have a 4TB portable SSD
Oh
But why use it when I can save storage
I have 500 GB of storage on my PC (that I use for gaming)
But I won't discuss it as I think it was against youtube's terms lol
You will never understand my pain
My steam library alone exceeds your storage
Thats just 2 games

Jabba I thought we were friends π¦
If you said Destiny 2, I would have been happy.
But COD?!??!?
Destiny 2? π€’
Cod was my best fps games , until they create battle royale
Jabba, do u like OSiNT?
I don't dislike it
I made a workplace in tryhackme any one want to join we can participate in CTF battle or somthing.. or anything like that π€.. ok just join if you want to hangout or talk or sumthing friendly ig π
Hm? Workspaces are based on your email address π
Hm? I just mean that you can only join a workspace if you have the same email domain
Yeah it went well
xd
I have one@jabba.sh we are 2:now
going through all my old rooms and making solid notes so it'll be easier to copy paste - i'm in what the shell and can't even get a reverse stagelss . it's successful from two different terminal tabs on my kali but can't get it working between thm and my kali box
Good Morning Folks
@mossy river what is ur rank??
Lt. Genral
Grand Champ
@mossy river I also own somthing like phone, laptop or many another grossly it doesn't mean I am not join .. π
I haven't been active on the website in a while as I work and study^
you're " THE MAN"
I ALSO WANT ANIMATED EMBED
I made a workplace in tryhackme any one want to join we can participate in CTF battle or somthing.. or anything like that π€.. ok just join if you want to hangout or talk or sumthing friendly ig π
Anyone I offer my help who ever join okk.. and I am not like nobuddy i just created new tryhackme account I am rank god in my old account so I can help you any means
What's the different between authentication and authorization?
@fervent ruin no just pamimg tammmimg samimg like that
authentication = who you says you is authorization = can who you says you is, really do all that stuff?
Only OGs would know
@cosmic pendant authentication. Menas somthing is checking how legit is somthing and authorised meaning is I have some command over that I mean privilege to
What's a reference monitor (reference monitor concept)
The one that has everything u want in ur monitor 
Where are the truffles
What truffles
Don't worry squiggly name, they know
@cosmic pendant if you talking about the term reference moniter it's obvious reference of somthing... But if this is a term or tactics i don't hear about it if I say truly i never ancounter may be I have done but not use this term
Almost 24h awake , my brain is not brainning
look it up π it's good shadow
Ok.. but I still need some duddy buddy to hang around and talk about stuff
Where are you from?
Why don't you join π you look strong fellow
What is it u really wanna do @rapid merlin
Yeah. thank you but I'm good π
@cosmic pendant Bharat
I'm too busy with work and reading π
I'm here to help out, I've been in the industry for like... idk too long
lol
15 years or so
What do u prefer ?
"Not this" , this what ?
Umm, different things there is no one right answer
@fervent ruin vjust making some project and revising my old stuff .. because I am doing job and drop out college and all the messs.. so I am comming on track so I think I need team to get batter Faster like your problem my problem and do some project and some things I know but don't know now like that
U are a verbal challange
@cosmic pendant ok granpa i will let you know if i stuck somewhere but I am worried i t will not happen.. uncle google brokeπ
This was for shadow
Doesn't sound like a very nice message π
What u mean by this ?
I didnt mean to offend him
@fervent ruin I don't know are you trying to offend me or a general question Even so I don't understand
Forget it
Alrigh so
I really like proper red teaming
breaking into buildings, disabling security systems...
Yes that's happened last night with my keyy@psy.beast too
Most of "red" is pentesting
I liked pentesting okay, but when it's part of a larger system, it can get boring
Breaking into buildings sounds like a lot of adrenaline
I didn't like Blue team work when I was a 'worker'
@cosmic pendant breaking windows is good but building i don't think π€ good approach for a aged person like you
I"m not a guy to stare at wireshark and console all day all day, dally day
But running a SOC is alot of fun
I see.. when working on red team, u r not doing boring things ?
Oh
That's what I do now
U do soc now?
@cosmic pendant then just save while capturing network.. π
You're like what 22?
I ma being too much social for today ok ... Last time asking if anyone wanna join let me know or let it goo
@cosmic pendant 24
Im not very sure what i want to do , if its red or blue teaming ... i dont want to stay all day everyday doing same shit..
Best advice, is learn Pentesting, learn how it works, the Pentesting cycle (800-115).
Then learn forenics at a higher level >Makes you better at Pentesting (really red teaming when hiding matters)
Then start applying those to systems engineering
800-160
Longer term:
LEARN THE OPPOSITE THING OF WHAT YOU"RE DOING
What is this "800-" ?
Windows
Windows administration
Linux/Unix
Linux administrator (deb)
Networking
Labs on networking
And practice tools use in network map...
Then network security
Security+ course ( I've linkπ)
Then go on
Website called portswigger
Complete all labs
Then test this skill in Bwep
Then start tryhackme
This is my advice if everyone giving one follow from top to bottom
like physical ?
But ig red team is "harder" to learn, u have a lot more to know and understand ...
yeah
Red Teaming isn't something you learn, it' something you do and especially. HOW you do it
I see
You can't just learn red teaming... You have to be on a red team to learn those lessons
You think this jr pentester and red team rooms are enough to get a first job in cybersecurity ?
i was doing physical for awhile. it's ok. alot of paperwork before and after
no
The best way to get a job in cyber security is start on a help desk
Help desk will be a nightmare for me
Alot of this stuff nowdays, THM, HTB, Blah blah Even Alot of Unis
Im 25yo, im losing the time to start
are 'teaching' cyber security, but really not.
They are watering down and watering down really advanced things, trying to help people
Ig u can still have some knowledge and practice on this websites
i was able to get my first baby cyberjob striclty through THM,HTB, and comptia (along with portswigger, tcm, yada yada yada)
no help desk experience - atleast not in in the past two decades
What was ur first job ?
Mine?
And how was it ?
Ig ur first job was help desk
No. I was recrutited out of college by the goverment
I had my Comp Sci degree (highly recommnded btw)

Yeah, my first job was epic
This certificates are expensive for me , first i need to get the job
are you able to disclose what the job is
Can u spot a thief b4 he steals something ?
xD joking
Penetration Testing,SP 800-115,Security Testing and Assessment Guide,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Penetration Testing,SP 800-30,Risk Assessment Integration,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Penetration Testing,SP 800-53,Security and Privacy Control Reference,https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Blue Teaming / SOC,SP 800-61,Incident Handling Guide,https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Blue Teaming / SOC,SP 800-92,Log Management Guide,https://csrc.nist.gov/publications/detail/sp/800-92/final
Blue Teaming / SOC,SP 800-137,Continuous Monitoring (ISCM),https://csrc.nist.gov/publications/detail/sp/800-137/final
Blue Teaming / SOC,SP 800-83,Malware Incident Handling,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-83.pdf
Blue Teaming / SOC,SP 800-181,NICE Cybersecurity Workforce Framework,https://csrc.nist.gov/publications/detail/sp/800-181/rev-1/final
Systems Engineering,SP 800-160,Systems Security Engineering,https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Systems Engineering,SP 800-53A,Security Control Assessments,https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final
Systems Engineering,SP 800-171,CUI Protection in Nonfederal Systems,https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
Systems Engineering,SP 800-37,Risk Management Framework,https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intellig...
The National Institute of Standards and Technology (NIST) developed this document in furtherance of its statutory responsibilities under the Federal Information security Management Act (FISMA) of 2002, Public Law 107-347. This publication seeks to assist organizations in understanding the need for sound computer security log management. It provi...
Review these
did they fool you telling it was (cyber) security? lol
Tell me the difference between security and cyber security?
Nice , knowledge
oh hahahah
Can u dm me this links ?
well that security guard is really important as it turns out π
Before I leave, does anyone here have any neat python tricks?
A few π look up list comprehension and dict comprehension
Ye i saw about this
Its handy sometimes
I want to create a automation for the work i have when hacking thm machines
Like the first scans , things i always do... i want to automate.. its boring to write the same commands over and over ..
But i have to understand how to use some python libraries
Like requests , subprocess , socket
This 3 are very important for what i want to do
#AutoRecon
Something with that name ye
A script that i just put the IP and it scans for ports , services and dirs automatically and give me a nice output π
I understand this can be simple to make but i didnt try yet
What u talking about
And ig its not going to be today , bc i didnt sleep yet π
I can
Important things fs
Just use Nmap..
ik, but i dont want to write the same command every machine i scan
What is talking about
create a script to call NMap....
hoi guys
Yes , i have to learn subprocess library
cybersec newbie in attendence β
Or i think there is nmap library for python , i could use thay
good night everyone
damn discord
Cheers to those who tried today
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
?
There ya go, there's a start for you
Cant read code rn , maybe after sleep
Im not at home now , and it will take some time to go home π
Okay you asked about security
Security it have integrity and availability confidentiality
And security is called information security
I spent the night finishing thm challanges
How do you maintain CIA?
Yeah, tha'ts nice but no
Once you have CIA, how do you keep them?
This is what security is
Hi im a begginer , should i learn burpsuit or owasp zap?
Give me a example
Threat them
Both
I'm not sure how to say it any differently
I feel hard
Start with burpsuit bc owasp zap is a automation tool, u will do nothing and understand nothing
Ok, and do i need a special CLI tool to make things more convenient? or normal shell is fine?
Wdym
Ye ?
like Terminator or Tmux
Whatever you like
@cosmic pendant is better have information
which one is recommended?
as long as you save your console output
Rather then nothing
either
it doesn't matter that much
It's the tecnqiues the tools use that matter
Use real life notepad
Confidentiality β Keeping data secret from unauthorized people.
Think: passwords, encryption, access control.
Integrity β Ensuring data is accurate and not tampered with.
Think: checksums, hashing, digital signatures.
Availability β Making sure systems and data are accessible when needed.
Think: backups, redundancy, anti-DDoS.
Yeah man, I get that
What i'm saying is , use your brain WHen you have CIA, the properties of them as your system
What do you do to keep them?
Let me try this
Unplug ethernet cable
if you are affected by ransomware, you have lost your CIA right?
Okay ?
Ok thanks, i really like THM, i learned nmap and hydra basics, what to do next
So security, could (and should) be summarized as Operating your computer and keeping CIA right?
U mean the ransomware not spread for other computers
If u restrict it in time
Sure, let's talk about that. how do you stop it?
Right?
............
I feel I confuse about these two
CIA = Confidentiality, Integrity, Availability
This are the peoole that are reading this conversation without anyone knowing
π€¦π»ββοΈ
Got it
So if I have laptop and I have ransomware it will spread all in network
And u will lose every single file π
@cosmic pendant could you accept my req friend
Well u dont lose it , it still there... but encrypted
I know but will spread whole wifi?
And you "have to" pay to decrypt
I know
Ig , but i think malware does that
I guess
Ransomware is virus I think so
Omg I loved cybersecurity
U have to be careful with ur downloads
how to know if a computer is keylogged
Great question
Idk but maybe u have a service running that sends ur keystrokes to a IP
hi anyone here who knows OSINT well who can tell me an alternative network search engine than wigle? it absolutely sucks ass, it's either deadass slow or you make a typo searching for the SSID and you used up all of the day's free queries
@simple epoch
You scanned with malwarebytes already, thats one of the best
Ye check the name and the folder
Services some time have payload you should check it
Bad part of it is u have to pay to use more times
Yes , hacker can migrate to trusted original services
I love asking Ai lot
No, not malwarebytes.
The free version is free free
The realtime version is paid
The better one subcribed
Ye , real time , the most important option
Bc u want to know in real time , not scan when u remember to scan
I use bitdefender free π€‘ its good π and minimal
I think windows defender itself is good enough
Well configured and firewall well configured , u are already safe
Minmal what u mean?
Simple use
π
I regert I breaked my pcπ
I understand that pain
But rather that ram slot is not working at all so that why
Felt it long time ago
Oh
Mine was the screen that slowly seperated from the rest of the computer
A1 for backup boot b2 is the main boot you know I use b2 for booting this not working so I anger and then broke it
Idk what u talking avbout
Thats why
U can choose what ram slot does ?
Not always you should choose one that boot
@cosmic pendant accept my request friend
Yea, no I'm not going to do that
Im really tired.. not understanding nothing already
He thinks u will exploit him when he clicks accept
Get a reverse shell through friend request
No
Bro that pc is destroyed
How is the inside ?
I mean the specs
@cosmic pendant this certs u have , wich one u recommend to get first ?
I see a lot this CEH cert
Dont remember how much it is but i think that will be the first
depends what you want to do π
Im still trying to figure that out
But ig im going for red team
I was focus on blue team recently just bc of the SAL1 cert , it would be my first cert
But idk
Its confusing and i really hate this feeling of not having time
any good guide for metasploit?
just got home haha
How much does a USB Rubber Ducky cost and will it cause any damage to my own computer if I plug it in without knowing how it works?πΏ π
GM
Try it
Wait , i think i cant joke like this...
Why? That would just kill my computer
you should remove that
you could get in trouble with the rules
It really the bins of cpu has broken
They can still see it π€·ββοΈ
Pins
Yeah, but you won't get in trouble if you police yourself
I broke it uo
It will be trouble
Sheesh, I thought it would perform some cool stuff if I plug it into my computer after buying itπ
DO NOT buy it on Hak5, they are price hiking up the fucking wazoo.
https://hackerwarehouse.com/product/usb-rubber-ducky/
To a human itβs a flash drive. To a computer itβs a keyboard, typing at superhuman speeds. Keystroke Injection β Computers trust humans. Humans use keyboards. Hence the universal spec β HID, or Human Interface Device. A keyboard presents itself as a HID, and in turn itβs inherently trusted as human by the computer. The [...]
$90
Damn thatβs pretty expensive
do you know what it does
No
Hak5 sucks
But I searched it up a little bit, itβs used to play pranks on others but it can also do some serious damage. Idk any of the details which is why I asked here if I buy one then plug it into my own device, will the Rubber Ducky automatically go into offense mode or will it let me configure it so I can use it legally?? But Iβm also not entirely sure if itβs legal to even useπ π
Why u buying it then ?
what damage do you think it'll do
I think u know what it does and u trying to know if its legal and if u can test it against u, just dont buy this stuff , or not talk about it here
Idk thatβs why I said βidk the details which is why I asked hereβ¦β
It is legal to use it against yourself, using it against someone else is pretty common among everyone to know that βthatβsβ actually illegal. For example, I can use USB killer on my device because itβs what I own. I canβt use it against someone else because thatβs illegal. Iβm going into the ethical hacking field. Sorry if I misunderstood anything though.
Yeah I agree, I should probably not ask here as my source of info π
Not about this stuff ye
They are very restrict with illegal stuff
Copilot is like free chatgpt plus?
Bing
Eh
Bing ?
ChatGPT is better
Yeah but chatgpt costs money
Bing the search engine ?
Real
The free version doesn't
Free version is pretty good
bing copilot
@shut hawk I know how much you love ChatGPT.
https://pentestgpt.ai/
I thought that was only the free trial?
I've used this one before
Free version is limited to like 20 messages than it switches to some bad model
No, just create an account and login
Or or or or or. LOCAL AI WOOOOOOOOOOOOOOOOOOOOOH
Oof, Iβm bouta use that for my exams π
Use multiple accounts π€·ββοΈ besides, it's just a few hours of cooldown.
Don't lol
Just 9 hours to finish
The 2nd has same points since last night , hope he keep it π
Imagine losing 1st place at the end π
oh yeah for sure
And im not at home to get more points if anything happens
how much boxes are you doing per day?
It depends
If i follow learn path or i complete challanges
Yesterday or 2 days ago i got 4 different badges
cool
Guys am I cooked? My professor told me to install virtual box on my laptop but refuses to help me set it up π π. Do I need big storage? I have windows 11
Big storage for linux ?
Yeah. Question, isnβt VMware the same as virtual box? I have VMware
It depends if u need big files init
Oof
Ye its the same , i think some features are little bit different , but they do the same, i use virtualbox
How much storage u have free ?
no
different companies
π₯²
functionality is pretty much the same for your use case. Although people say VMware is better
When u guys nmap a machine what parameters u usually add
Depends but
On thm machines u dont care about detection so
-A -T4
-T5 sometimes can give u some errors bc of the speed
-v -p- -sV -oA machineName
-v to print out ports as it finds them to probe further
I usually run: nmap -sS -sV -T4 -p- -Pn ip -oN file
As first scan just to find the open ports
Then i run nmap -sS -A -T4 -p(found open ports) ip -oN advanced_scan
Sometimes i add --script vuln
To check for vulnerabilities agains the open ports
This is why i want to create a automation for my scans , to not write all of this everytime
-sC is good too?
If u use -A , -sV -sC -O are used
got it , thank you my man
If u dont specify the port range , it will scan 1-1000 ports
I usually run -sV on all ports just to get open ports and services , then i narrow the scan to this open ports and try to find vulns on this ports
-v -p- -sC -sV
i see , thanks for the advice
Im going to sing happy birthday to my grandma , brb
@shut hawk anything wrong with doing the -A?
and then don't forget UDP ports (rare but can happen) -sU
True
not at all, if you want all the information
-A adds OS version, script scanning, service scanning and trace route
-sV, -O, traceroute, sC
Usually more than you need, and slow
Try it and seeβ’
Am i wrong ? xD
i logged into an ftp server with the anonymous cred but when i type ls it says entering extended passive mode, wtf is that
This really exists ?
What is the room u doing ?
nope its just a figment of your imagination
its called simple ctf
You know u r right , right ?
i did ftp <serverip>, logged in with anonymous user but when i type ls i get this weird message
Im not at home , and it passed 24h since i slept , so... cant really help rn
Did you google the message?
Provide screenshot in #room-help @simple epoch
Redteaming in thm need offensive security or just jr pentesting
Thm should create red team certificates π like SAL1
I wantt too but where requiments to learn it
Learn what ?
Wallpaper of the day:
arrives
whats good
Should I learn web fundamentals then go to web pentesting,
@cloud quiver
Yeah definitely
Red teaming is the last of pentesting the end of it right?
@cloud quiver
@fervent ruin after i install kali there is any command i need to type to update it? seems like im missing tools like gobuster
In the roadmap yes
Sorry kgb for mentiong
There's also offensive pentesting
It isn't present on the roadmap
Sudo apt update
Sudo apt upgrade
Is it just gobuster missing ?
Acquire the skills needed to go and get certified by well known certifiers in the security industry. Learn about industry-used penetration testing tools and attain techniques to become a successful penetration tester.
What image did u download ? It is iso file or vm for vmware ?
Bc if u download the iso image , it is limited , it happen to me , i had to download vbox iso
Thats a pre-build vm
ISO image doesn't have GoBuster
At least it didn't last year
I had to download it manually
This looks like AI genersted
Me? Use AI?.... ha
Beep boop

Gave +1 Rep to @gusty inlet (current: #284 - 25)
How dare you assume, I have a human form
Are talking about your real you, or are we talking about you?
U a toast
Passive aggressive ahh response
No, he a doctor
Encouraging practical learning?
surgeon
People should be encouraged to try things and learn practically. A homelab is hugely beneficial in this industry
Hello
Hi
Will do sir π«‘
local shop =/
Kicking Sundays π₯
Nah, it can go quiet for hours, especially when the usual suspects are asleep.
Hex, 2 QQs
- What did that poor bag ever do to you?
- Where in the name of God are your trousers?

I don't wear trousers when I'm fighting so why would I in practice?
Congratulations, you are now an honorary Scot
Apparently that was one of the favourite tactics in ages past. Run into battle stark naked and kill the opposing army before they recover from the shock
I actually do have a kilt somewhere
Kilts are relatively modern
Hey can somebody help me with domain certificates? So I have successfully created the certificates for my domain but there's an error when using the subdomain. Do I need to create a certificate for my subdomain as well?
Would have been a plaid originally
Yes
A certificate is only valid for its CN and any specified SANs. You can create a wildcard certificate which works for subdomains, otherwise it'll only do exactly what you specify.
Well this is one specifically for MMA π
Why would you choose to wear something that loose to fight..?
Especially when traditionally you forgo underwear with a kilt 
I checked some wildcard certificates on namecheap but they are costly, I have created the certificates with letsencrypt's certbot, I guess we can create a wildcard certificate with the same.
@blazing granite i set timeshift. didnt know that menu select show in grub load menu
Oh look at that dangling thing!
dies
Well it's not really a kilt π they call it one but it's just shorts with some flappy material. Definitely not competition legal except maybe Muai Thai
General Butt Naked. Need I say anymore.
I mean, try to avoid wildcard certificates if you can.
Better to use multiple, granular certificates, especially if they're being managed automatically by certbot
Why would you want flappy material when fighting...
Muai Thai have extravagant shorts
It's part of the sport culture π
Bizarre choice
Damn lucky, I gotta lock my self till the I pass my finals
Oh okay, so in case if I create a separate certificate for this subdomain, it should be *.example.com, right?
No, that's a wildcard certificate
The only time I would use wildcards personally are for an application which uses subdomains dynamically.
Burp collaborator is a good example.
How can i find the subdomains of thm machines ??
And how can i get the ip of this subdomains ?
Whether self-hosted or SAAS, it works by dynamically creating a subdomain with a canary token in it, and using a wildcard cert / DNS to catch the traffic.
Or for a CTF with a new instance per challenger
THM network doesn't use DNS
Oh ok
So, uh, there are no domains, let alone sub domains.
Okok π
You're always given the target IP when you start the machine π
But the subdomains use the same ip as domain?
Again, there's no DNS lmao
Are you asking about virtual hosts?
broo im blown away to how awesome these rooms are
https://tryhackme.com/room/httpindetail
like bro the emulator itself is so well done
Now I organized my path offensive security first than red teaming
Idk, forget it
You want to nano /etc/hosts
If it's vhosts, then a webserver can be configured to direct traffic based on the HTTP Host header. Usually that's set to be a non-existent but standards compliant domain for a CTF machine (e.g. challenge.thm).
In that case to answer your original question, you'd be looking to fuzz the host header to find which vhosts it's configured to listen on.
Then yes, you would set an override in your hosts file mapping that vhost to the IP of the box.
$ip address 1.domain.com 2.domain.com
what a coincidence
That is the format
im literally on the header part
Ok , i think i understand
I suppose it could be subdomains if the machine itself ran a DNS server
For /etc/hosts
Technically true, tbf
Hell, I've done that myself with Hipflask lmao.
MUIRI! What happened to your role?!?!?!
Which one now...
I ainβt a clue haha
tbh ider what role that was about
ah yeah that's the one
Go ask James what happened to his role 
yo wtf
Or Juun, or Hydra, or Omega, or Zojja, or any of the others that resigned in the last week or so
They forgor we weren't employees
hopefully they also sent the paychecks without noticing xD
sounds like there was some responsibility drift
More overstep instead
tryna have the volleys take up extra stuff?
@fervent ruin did you sort the subdomains out?
they should promote me into the open role as an honorary admin
It was just a question, im not doing any room
none of the responsibility tho
Ahhh well Iβm a good teacherβ¦got any questions come to me
speaking of turnover, haven't seen dolphin in here in ages ---- still pop in at all?
oh damn, last msg in November
Well u are 0xE , i believe u have some knowledge ye
also no longer on the server. huh.
Nah, she left.
ayy scrubz is still a mod tho
For the time being.
for now
,-,
and can't even msg her. shes also from NL. hope shes ok
Could always add as a friend.
i've got an open thread already so Ha
oh... that can help heh
Discord is shit.
@molten sky Doplhin is doing good, she's taking a social media break. Last time I asked about her, prob a couple weeks ago, she's doing good π
Anyone, if I complete advent of 24, then am I eligible for earning the certificate
Yes
in gold bars shop in sweeden... π
what's fill in the username
That implies it's a private repo usually
^ this
how to clone
using your ssh git key would help
So it's a private repo
You need to enter creds that can access the private repo?
i want to install awus036ach drivers
but it cannot working
ππ
drivers not installing properly
@boreal scarab have ever print with Nylon Carbon Fiber?
can anyone teach me
did you try search in package manager ? like sudo apt-get search ...
yes i tried all things but not working anything
I've printed carbon fiber, not the nylon one
a ok. at what temp and speed ?
Wow, google is an amazing place
Almost like, it was molded for questions
and show results on first page π
Hello, How do i get my role here from the levels
read #start-here
@placid nymph
Sorry ral, took forever to send
Thank you @gritty fern @loud marlin i Got it
Gave +1 Rep to @gritty fern (current: #199 - 41)
wrong
It doesn't show in mine. I restore the snapshot if I want to but they don't show as part of grub
heh, i have extra line to select one i can restore
@boreal scarab
Guys is joining hiddenwiki from chrome normal
I just joined it to check out didn't click on any links inside it

Hello
... darknes, my old friend...
good morning all. hope eveyones snday is going good.
you won't find much darkweb chat in this server.
You don't have to be rude about it.
What beginner 3d printer should i get? Budget $500 max maybe i just want for personal fun hobby
If you can clearly see that it's not much chat, it's for a good reason. π
How am I rude
Sup toast
I can clearly see
Is being rude.
Ye but u look experienced just tell me if it's normal or not I wanna know if I'm safe
i have Tor option on router and never try it lol
If you don't know the anwer to that questionk you shouldn't be there
No, I won't tell you, as we don't welcome dark web chat.
Did u even read my question?
3 Questions, one answer, I love it π
If you continue to be rude, you may lose the ability to speak. π
I just joined to checkout hidden wiki from chrome is it safe? no darkweb chat
Bruhh how am I rude
Yep but I meant I just joined to to check out how it is didn't click on links inside it
So it's still related to dark web chat.
Now you can stop asking as you got the answer. π
I answered your question
Something something no dark web chat.
Also, why are you asking people if you don't think we know?
................ insert thinking face here
You're choosing to ignore people who're giving you answers, because it is not the answer you want.
I mean I didn't get answer wdym
U said u don't have to be there
I'm already not there
I just did checkout and wanna see if I'm safe or not
I'm saying you should'nt be there
Now I'm asking for you to drop the subject completely.
I'm not there I just joined one time to check out that's it simple
My problem completely
.
Have a good day
It's actually warm and dry, for Scotland we have a wildfire warning, which is nothing compared to rest of the world, however it's not too common for hear, one of my favourite walks in Arran has been destroyed π¦
How are you?
Ayyyy toaster
is better to study offensive security then redteaming
how do you have redteaming without offense?
No
But I'm asking
Doesn't matter so much, just learn
Great π€.
Don't be a person that worries more about learning the right thing, then anything at all : Good life advice. (This is general advice and not aimed at you)
But I see that on here good bit
of course
@loud marlin Ay, Toast is having issues with his printer. He tried to print in PETG but it's clogged in there. What do you usually do if there's a clog?
I told him my way, but want your perspective
2nd time now too
try extrude in lcd menu. if is not going out then heat nozle up to 220-230 temp and take out fillament. and use if have that needle to unclog
you have also unicorn type of nozzle iirc for k2
in lcd menu you ahve extrude and/or retract selection
Lesss goo...I'm relieved you didn't fail
adn get this
wilco
is for 3d printer. but you are close
also do a temp tower calibration for petg. and cehck what temp says on filament. temp for petg is important
tbh. pet g can be pain in ass for sure
for petg i go around 230-240 nozzle and 70-80 bed temp and slower print speed around 120-150 max
oooh look at those pretty eyelashes :P
hehe.
k
yours look different from mine
show
@sand trench what remote app you use on arch hyprland ? if so
mine looks the same when i view it from the badges tab
ok
remote app??
how long until 1500 day streak badge??? :P
like remmina or so
use ssh
1495 
ah for RDP and VNC??? yeah use remmina
isn't that for windows?
rdp is a microsoft thingy yes
they were asking for something to use with arch hyprland

yeah remote app
which they clarified as remmina as an example
yeah it is an easy sudo pacman -S remmina
But I have question start offensive security first or redteaming
Can someone answer please
...............
you could have been learning this entire time
get off discord and go read! (take notes)
ok... remmina works π
questions? has anyone paid for the permium yearly for TryHackMe.com
Yup, hi.
hey, so is that worked out for you.
WDYM by worked out for me?
Youβve been on this discord for weeks sir
You still havenβt picked red or blue pill moβ?
Neither will get you a job, do what u enjoy learning
WDYM meaning
?
wdym meaning is "w^hat d^o y^ou m^ean"
OO lol
Itβs rot13
ok ok
I well i am dedicding should i pay or just go wth the free one. but i want to learning more like everyday
Why not try free and if you like it, subscribe? π
Lurking I see π
Always on my right monitor
is there a way to see a list of all obtainable badges on tryhackme
Discord is my left.
The badges tab in profile
@sand trench π
1335
this is what i was asking for
thanks scrubz
Gave +1 Rep to @sick lance (current: #2 - 3632)
Just 2 away from leet
yeah
Who can help me find a French-speaking server about cybersecurity
You don't need to spam this in all channels xD
I can speak french if you need help DM me
Nobody can send Discord links here unfortunately, try using the Discord discovery page
The hardest decision I need to take everyday is what to have for dinner
Do you like Cheesecake as well?
yeah they can be nice
so do we have to pay for the certification if we pay for the premium
I wonder how is this obtainable?
One section left for my report, the lit review.
Pizza , your welcome
Nawww don't feel like it
Sal1 and AWS are costs that aren't included in the subscription.
By being kind.

I believe you get a discount for sal1 if you buy the subscription
Ok how can I be kind on the website? 
Β―_(γ)_/Β―
dont hit the keys too hard
It may not be limited to the website.
It's a community badge
how can i change the TERM variable after creating a python shell?
so i can use ctrl c
without exiting the shell
ctrlz to background the process
I don't recall every changing term for shell stabilisation
why not?
python -m "import pty;pty.spawn('/bin/bash')"
[ctrl+z]
stty raw -echo; fg
[enter, enter, enter]
stty rows 30 columns 100
or if python wasn't available I'd use /usr/bin/script -qc /bin/bash
no way im going to remember all of this
this is mainly muscle memory so I'd double check the commands are correct

