#general

1 messages Β· Page 1008 of 1

rapid merlin
#

Yeah a local company where I live got hacked and was asked to pay ransoms

sick lance
#

Mate, you don't even have to tell me

I'm doing a project to intergrate a firewall into an ICS testbed, and the guy who built it, mentains it, has no clue what I'm doing.

ripe cosmos
#

my uni has stationary stores that use PCs with windows 7 connected to the internet. They open all files from whatsapp that students send for printing and stuff...

sick lance
#

If I don't get a first for this, I'm rioting.

rapid merlin
#

The hack was most likely caused my the windows XP machines running their outdated software

rapid merlin
#

Because they don't want to pay to update the software

shell nova
#

Just don't use forti or ivanti I guess

mellow narwhal
#

Paying the ransom will be cheaper actually lol

mellow narwhal
#

But if it was a local company they could've probably prevented it

sick lance
#

It's funny you say that

rapid merlin
#

Could've probably paid to update the software

sick lance
pallid lotus
#

Yeah, but you still need a way to execute this. No point in putting a payload on disk if it's just gonna sit there inert.

sick lance
#

Spot the fortinet gear πŸ‘€

shell nova
#

Then again Palo Alto isn't much better

rapid merlin
pallid lotus
#

In that video their helpful little demo script extracted and executed

sick lance
mellow narwhal
rapid merlin
rapid merlin
#

Been working fine for my gigabit fiber connection

#

Just don't leave your fortigates connectable from the outside

pallid lotus
#

The demo script even says that it's simulating a malicious service.

rapid merlin
#

πŸ’”

shell nova
sick lance
shell nova
#

My coworkers absolutely destroyed Palo though

pallid lotus
#

So you would need a malicious service installed monitoring the cache to extract new malicious images as they appear.

It would be quite a novel a way to get C2 commands into an already compromised box, but that's about its only use

shell nova
#

That company also forced us to publish a responsible disclosure policy

pallid lotus
shell nova
pallid lotus
shell nova
#

Stormshield?

sick lance
#

Fortinet confirmed.

hybrid plover
#

lets goo i got level 8

rich zenith
#

Advanced SQL injection was great. Also got a script alert for XXS on one task.

viral granite
#

Hii

#

Wassup

simple epoch
#

hi i need a consult, i run a tcpview on my pc and i see several outgoing connection from an os process named searchhost.exe
my friend also has win 11 and he doesnt have thoe outgoing connections, the signature on my process is valid, but its still sus to me, can it be malicious?

naive violet
pallid lotus
#

Yep! kekw

naive violet
#

Always cause for the media to latch on and fearmonger too...

devout palm
#

Hey hey

sick lance
devout palm
#

Exam in 17 minutes xd

simple epoch
#

@sick lance yea its responsible for windows searching and indexing i guess?

sick lance
devout palm
#

Distracting myself not to be stressed

simple epoch
#

why its connecting with outside world? i fear the process is hijacked or something

devout palm
#

How are you fellas doing?

simple epoch
#

answer i guess ? lol

sick lance
#

Then you must already know what to do, and the steps to take...

simple epoch
#

i tried disabling windows search service, and its still running

#

i also tried quarantining it with my AV but it didnt work

zinc seal
#

anyone here taken ISC2 CC certification before? any study tips or notes that you have that can share with me?

naive violet
#

Just do a malwarebytes scan and let it put your mind at ease @simple epoch

simple epoch
#

it might be legit i jsut cant tell

#

i did mb scan it came clean

naive violet
simple epoch
#

is it possible for virus to run from a legitimate OS process?

#

like hijack it or impersonating to it? (and showing the valid signature)?

#

or am i too paranoid xd

pulsar spoke
#

If subscribing to a GPT model, which one do you think is worth subscribing?

dark mason
#

am I allowed to post a challenge from an CTF that just ended in here? (osint)

pulsar spoke
dark mason
#

if u guys wanna try it

#

it's fun!

pulsar spoke
#

Oh, yeah. sure

dark mason
sick lance
#

Aslong as the CTF isn't active anymore, and it's not a private CTF (school, uni etc)

fiery imp
pallid lotus
#

I mean, if the message was sent 35 minutes ago, and the exam started 17 minutes after the message was sent, I would say it's a pretty good bet that the exam has started kekw

blissful current
sick lance
#

Image the ping put him off, or notified causing a fail.

fiery imp
#

ayoo😭

sick lance
#

@safe valley Can I help you?

fiery imp
#

They provide cybersec certs

safe valley
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3631)

sick lance
#

I mean, the user asked on a social media platform about something, isn't that the intention of the platform?

blissful current
#

uh, wait who what

sick lance
#

The user asked what ICS2 was, somebody said google exists.

blissful current
#

ah lol right

sick lance
#

So you were just trolling here without context?

blissful current
#

nvm mb

leaden marsh
#

What such dream πŸ₯Ί when I dream you get inside the vr and live with people And I love someoneπŸ₯ΊπŸ₯Ί its digtial world I want the vr one day to be A real like living and studying marrying working real life in cybersecurity 🀍😭 I loved the dream

dawn glen
#

Hello, i am a 18 year old who just started to learn about cybersecurity because I wanted to explore all types of computer jobs and I wanted advice on what career path I take in tryhackme

#

I did the quiz

#

It gave 5 jobs

#

Penetration tester, security analyst, incident responder, red teamer, security engineer

#

Idk what to pick

#

Should I learn pre-security first and then think about it? But red teamer doesn't have pre-security

#

I'm lost someone pls help me

shy finch
dawn glen
#

Okay

shy finch
#

And then u will have a better view of both to chose which path u want to follow

dawn glen
#

Yeah okay thanks I'll start with pre security then

shy finch
dawn glen
leaden marsh
#

Redteaming what the basics for it to start in tryhackmd

rich thunder
#

its too good

#

after completing it, you can start doing challenges and CTFs

near sapphire
gusty inlet
#

Watch people use discord as C2

simple epoch
#

hey to connect to thm with vpn i need to do it on my kali VM right?

gusty inlet
#

sudo openvpn VPNFILE

#

Or use the attackbox

forest panther
#

Hello, i’m new here

gusty inlet
forest panther
#

I have subscribed for 1 year and am studying. blobheart

simple epoch
#

what is a recommended shell tool to use in kali, i know there is something people using other than the nomral shell

pallid lotus
dark mason
#

If it works

mossy river
#

Me using Discord as my second hard drive πŸ˜‹

gusty inlet
#

Blasphemy

mossy river
#

It's mainly just screenshots I need

dark mason
gusty inlet
#

How dare you not spend thousands of pounds on those instead of discord

mossy river
#

I have 3tb of NVME m.2, and I have a 4TB portable SSD

gusty inlet
#

Oh

mossy river
#

But why use it when I can save storage

gusty inlet
#

There was actually a funny way people used to save stuff on youtube

dark mason
#

I have 500 GB of storage on my PC (that I use for gaming)

gusty inlet
#

But I won't discuss it as I think it was against youtube's terms lol

dark mason
#

You will never understand my pain

mossy river
#

My steam library alone exceeds your storage

fervent ruin
#

Thats just 2 games

mossy river
#

LMAO

#

90% of it is Call of Duty

fervent ruin
gusty inlet
#

If you said Destiny 2, I would have been happy.

#

But COD?!??!?

mossy river
#

Destiny 2? 🀒

gusty inlet
#

HEY

fervent ruin
#

Cod was my best fps games , until they create battle royale

dark mason
mossy river
#

I don't dislike it

rapid merlin
#

I made a workplace in tryhackme any one want to join we can participate in CTF battle or somthing.. or anything like that πŸ€”.. ok just join if you want to hangout or talk or sumthing friendly ig πŸ™‚

mossy river
rapid merlin
#

Hmm

#

You hate my email βœ‰οΈπŸ₯²@jabba.sh

mossy river
#

Hm? I just mean that you can only join a workspace if you have the same email domain

devout palm
#

xd

rapid merlin
mossy river
#

I own the domain jabba.sh, I don't think so πŸ˜„

calm briar
#

going through all my old rooms and making solid notes so it'll be easier to copy paste - i'm in what the shell and can't even get a reverse stagelss . it's successful from two different terminal tabs on my kali but can't get it working between thm and my kali box

cosmic pendant
#

Good Morning Folks

fervent ruin
#

@mossy river what is ur rank??

cosmic pendant
#

Lt. Genral

mossy river
#

Grand Champ

rapid merlin
#

@mossy river I also own somthing like phone, laptop or many another grossly it doesn't mean I am not join .. πŸ™‚

mossy river
fervent ruin
#

U have staff rank

#

U work for them

calm briar
#

you're " THE MAN"

dark mason
rapid merlin
#

I made a workplace in tryhackme any one want to join we can participate in CTF battle or somthing.. or anything like that πŸ€”.. ok just join if you want to hangout or talk or sumthing friendly ig πŸ™‚

Anyone I offer my help who ever join okk.. and I am not like nobuddy i just created new tryhackme account I am rank god in my old account so I can help you any means

fervent ruin
#

Spamming ?

#

U sent this message already

cosmic pendant
rapid merlin
#

@fervent ruin no just pamimg tammmimg samimg like that

calm briar
#

authentication = who you says you is authorization = can who you says you is, really do all that stuff?

cosmic pendant
#

Yeah, I'm asking Shadow

#

So, good job there

mossy river
rapid merlin
#

@cosmic pendant authentication. Menas somthing is checking how legit is somthing and authorised meaning is I have some command over that I mean privilege to

cosmic pendant
#

What's a reference monitor (reference monitor concept)

fervent ruin
#

The one that has everything u want in ur monitor kekw

cosmic pendant
#

Where are the truffles

fervent ruin
#

What truffles

cosmic pendant
#

Don't worry squiggly name, they know

rapid merlin
#

@cosmic pendant if you talking about the term reference moniter it's obvious reference of somthing... But if this is a term or tactics i don't hear about it if I say truly i never ancounter may be I have done but not use this term

fervent ruin
#

Almost 24h awake , my brain is not brainning

cosmic pendant
#

look it up πŸ™‚ it's good shadow

rapid merlin
#

Ok.. but I still need some duddy buddy to hang around and talk about stuff

cosmic pendant
#

Where are you from?

rapid merlin
#

Why don't you join πŸ™‚ you look strong fellow

fervent ruin
#

What is it u really wanna do @rapid merlin

cosmic pendant
#

Yeah. thank you but I'm good πŸ˜„

rapid merlin
#

@cosmic pendant Bharat

cosmic pendant
#

I'm too busy with work and reading πŸ˜„

#

I'm here to help out, I've been in the industry for like... idk too long

#

lol

#

15 years or so

fervent ruin
#

Red or blue team?

#

@cosmic pendant

cosmic pendant
#

Both

#

Proper Red Team

#

not this fake red team BS

fervent ruin
#

What do u prefer ?

fervent ruin
cosmic pendant
#

Umm, different things there is no one right answer

rapid merlin
#

@fervent ruin vjust making some project and revising my old stuff .. because I am doing job and drop out college and all the messs.. so I am comming on track so I think I need team to get batter Faster like your problem my problem and do some project and some things I know but don't know now like that

fervent ruin
#

U are a verbal challange

rapid merlin
#

@cosmic pendant ok granpa i will let you know if i stuck somewhere but I am worried i t will not happen.. uncle google brokeπŸ˜‚

fervent ruin
mossy river
#

Doesn't sound like a very nice message πŸ˜…

fervent ruin
fervent ruin
rapid merlin
#

@fervent ruin I don't know are you trying to offend me or a general question Even so I don't understand

fervent ruin
#

Forget it

cosmic pendant
#

Alrigh so

#

I really like proper red teaming

#

breaking into buildings, disabling security systems...

rapid merlin
#

Yes that's happened last night with my keyy@psy.beast too

cosmic pendant
#

Most of "red" is pentesting

#

I liked pentesting okay, but when it's part of a larger system, it can get boring

fervent ruin
cosmic pendant
#

I didn't like Blue team work when I was a 'worker'

rapid merlin
#

@cosmic pendant breaking windows is good but building i don't think πŸ€” good approach for a aged person like you

cosmic pendant
#

I"m not a guy to stare at wireshark and console all day all day, dally day

#

But running a SOC is alot of fun

fervent ruin
#

I see.. when working on red team, u r not doing boring things ?

fervent ruin
cosmic pendant
#

That's what I do now

fervent ruin
#

U do soc now?

rapid merlin
#

@cosmic pendant then just save while capturing network.. πŸ™‚

cosmic pendant
rapid merlin
#

I ma being too much social for today ok ... Last time asking if anyone wanna join let me know or let it goo

#

@cosmic pendant 24

fervent ruin
cosmic pendant
#

800-160

#

Longer term:

#

LEARN THE OPPOSITE THING OF WHAT YOU"RE DOING

fervent ruin
#

What is this "800-" ?

cosmic pendant
#

NIST Special Pubs

#

standby

rapid merlin
#

Windows
Windows administration
Linux/Unix
Linux administrator (deb)
Networking
Labs on networking
And practice tools use in network map...
Then network security
Security+ course ( I've linkπŸ˜‚)
Then go on
Website called portswigger
Complete all labs
Then test this skill in Bwep
Then start tryhackme

This is my advice if everyone giving one follow from top to bottom

calm briar
fervent ruin
#

But ig red team is "harder" to learn, u have a lot more to know and understand ...

cosmic pendant
#

Red Teaming isn't something you learn, it' something you do and especially. HOW you do it

fervent ruin
#

I see

cosmic pendant
#

You can't just learn red teaming... You have to be on a red team to learn those lessons

fervent ruin
#

You think this jr pentester and red team rooms are enough to get a first job in cybersecurity ?

calm briar
#

i was doing physical for awhile. it's ok. alot of paperwork before and after

cosmic pendant
#

The best way to get a job in cyber security is start on a help desk

fervent ruin
#

Help desk will be a nightmare for me

cosmic pendant
#

Alot of this stuff nowdays, THM, HTB, Blah blah Even Alot of Unis

fervent ruin
#

Im 25yo, im losing the time to start

cosmic pendant
#

are 'teaching' cyber security, but really not.

#

They are watering down and watering down really advanced things, trying to help people

fervent ruin
#

Ig u can still have some knowledge and practice on this websites

cosmic pendant
#

Which is good, but in the long run it hurts everyone

#

(See AI)

calm briar
#

i was able to get my first baby cyberjob striclty through THM,HTB, and comptia (along with portswigger, tcm, yada yada yada)

#

no help desk experience - atleast not in in the past two decades

fervent ruin
#

What was ur first job ?

cosmic pendant
#

Mine?

fervent ruin
#

And how was it ?

fervent ruin
cosmic pendant
#

No. I was recrutited out of college by the goverment

#

I had my Comp Sci degree (highly recommnded btw)

fervent ruin
cosmic pendant
#

Yeah, my first job was epic

frozen gull
fervent ruin
#

This certificates are expensive for me , first i need to get the job

near sapphire
cosmic pendant
#

I was brought into a training program to teach me security

#

real, actual security

fervent ruin
#

Can u spot a thief b4 he steals something ?

cosmic pendant
#

LOL, no that isn't how humans work lol

#

But anyway.

fervent ruin
#

xD joking

cosmic pendant
#

Penetration Testing,SP 800-115,Security Testing and Assessment Guide,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Penetration Testing,SP 800-30,Risk Assessment Integration,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Penetration Testing,SP 800-53,Security and Privacy Control Reference,https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Blue Teaming / SOC,SP 800-61,Incident Handling Guide,https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Blue Teaming / SOC,SP 800-92,Log Management Guide,https://csrc.nist.gov/publications/detail/sp/800-92/final
Blue Teaming / SOC,SP 800-137,Continuous Monitoring (ISCM),https://csrc.nist.gov/publications/detail/sp/800-137/final
Blue Teaming / SOC,SP 800-83,Malware Incident Handling,https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-83.pdf
Blue Teaming / SOC,SP 800-181,NICE Cybersecurity Workforce Framework,https://csrc.nist.gov/publications/detail/sp/800-181/rev-1/final
Systems Engineering,SP 800-160,Systems Security Engineering,https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final
Systems Engineering,SP 800-53A,Security Control Assessments,https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final
Systems Engineering,SP 800-171,CUI Protection in Nonfederal Systems,https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
Systems Engineering,SP 800-37,Risk Management Framework,https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

#

Review these

dawn glen
cosmic pendant
dawn glen
#

like security guard for a cybersecurity agency or smth

#

idk im tryna make a joke

#

lol

cosmic pendant
#

oh hahahah

cosmic pendant
#

well that security guard is really important as it turns out πŸ™‚

#

Before I leave, does anyone here have any neat python tricks?

fervent ruin
#

I wish

#

Do u?

cosmic pendant
#

A few πŸ™‚ look up list comprehension and dict comprehension

fervent ruin
#

Ye i saw about this

#

Its handy sometimes

#

I want to create a automation for the work i have when hacking thm machines

#

Like the first scans , things i always do... i want to automate.. its boring to write the same commands over and over ..

#

But i have to understand how to use some python libraries

#

Like requests , subprocess , socket
This 3 are very important for what i want to do

cosmic pendant
#

#AutoRecon

fervent ruin
#

Something with that name ye

#

A script that i just put the IP and it scans for ports , services and dirs automatically and give me a nice output πŸ™‚

#

I understand this can be simple to make but i didnt try yet

fervent ruin
#

And ig its not going to be today , bc i didnt sleep yet πŸ™ƒ

dark mason
fervent ruin
cosmic pendant
#

Just use Nmap..

fervent ruin
#

ik, but i dont want to write the same command every machine i scan

cosmic pendant
#

create a script to call NMap....

uncut haven
#

hoi guys

fervent ruin
#

Yes , i have to learn subprocess library

uncut haven
#

cybersec newbie in attendence βœ‹

fervent ruin
#

Or i think there is nmap library for python , i could use thay

slate linden
#

good night everyone

fervent ruin
#

Or create a nmap tool myself

#

It would be very simple and limited but ye

cosmic pendant
#

damn discord

slate linden
#

Cheers to those who tried today

cosmic pendant
fervent ruin
#

?

cosmic pendant
#

There ya go, there's a start for you

fervent ruin
#

Cant read code rn , maybe after sleep

#

Im not at home now , and it will take some time to go home πŸ™ƒ

leaden marsh
#

Okay you asked about security

Security it have integrity and availability confidentiality

And security is called information security

fervent ruin
#

I spent the night finishing thm challanges

leaden marsh
#

Do you want the defination of each of them

cosmic pendant
#

Yeah, tha'ts nice but no

#

Once you have CIA, how do you keep them?

#

This is what security is

simple epoch
#

Hi im a begginer , should i learn burpsuit or owasp zap?

leaden marsh
fervent ruin
#

Threat them

cosmic pendant
leaden marsh
fervent ruin
#

Start with burpsuit bc owasp zap is a automation tool, u will do nothing and understand nothing

simple epoch
#

Ok, and do i need a special CLI tool to make things more convenient? or normal shell is fine?

fervent ruin
#

Ye ?

simple epoch
#

like Terminator or Tmux

cosmic pendant
#

Whatever you like

leaden marsh
#

@cosmic pendant is better have information

simple epoch
#

which one is recommended?

cosmic pendant
#

as long as you save your console output

leaden marsh
#

Rather then nothing

cosmic pendant
#

either

#

it doesn't matter that much

#

It's the tecnqiues the tools use that matter

fervent ruin
#

Use real life notepad

leaden marsh
# cosmic pendant How do you maintain CIA?

Confidentiality – Keeping data secret from unauthorized people.

Think: passwords, encryption, access control.

Integrity – Ensuring data is accurate and not tampered with.

Think: checksums, hashing, digital signatures.

Availability – Making sure systems and data are accessible when needed.

Think: backups, redundancy, anti-DDoS.
cosmic pendant
#

Yeah man, I get that

#

What i'm saying is , use your brain WHen you have CIA, the properties of them as your system

#

What do you do to keep them?

#

Let me try this

fervent ruin
#

Unplug ethernet cable

cosmic pendant
#

if you are affected by ransomware, you have lost your CIA right?

simple epoch
#

Ok thanks, i really like THM, i learned nmap and hydra basics, what to do next

cosmic pendant
#

So security, could (and should) be summarized as Operating your computer and keeping CIA right?

leaden marsh
#

U mean the ransomware not spread for other computers

fervent ruin
#

If u restrict it in time

cosmic pendant
#

Sure, let's talk about that. how do you stop it?

leaden marsh
#

Right?

cosmic pendant
#

............

leaden marsh
#

I feel I confuse about these two

cosmic pendant
#

CIA = Confidentiality, Integrity, Availability

fervent ruin
#

This are the peoole that are reading this conversation without anyone knowing

leaden marsh
#

Got it

#

So if I have laptop and I have ransomware it will spread all in network

fervent ruin
#

And u will lose every single file πŸ™‚

leaden marsh
#

@cosmic pendant could you accept my req friend

fervent ruin
#

Well u dont lose it , it still there... but encrypted

leaden marsh
fervent ruin
#

And you "have to" pay to decrypt

leaden marsh
fervent ruin
leaden marsh
#

What is ig

fervent ruin
#

I guess

leaden marsh
#

Ransomware is virus I think so

fervent ruin
#

Probably it will spread

#

To encrypt others computers files

leaden marsh
fervent ruin
#

U have to be careful with ur downloads

leaden marsh
#

Not supicious

simple epoch
#

how to know if a computer is keylogged

fervent ruin
#

U can still run programs that u think they r infected

#

U can use sandbox

leaden marsh
fervent ruin
#

Idk but maybe u have a service running that sends ur keystrokes to a IP

snow palm
#

hi anyone here who knows OSINT well who can tell me an alternative network search engine than wigle? it absolutely sucks ass, it's either deadass slow or you make a typo searching for the SSID and you used up all of the day's free queries

leaden marsh
#

@simple epoch

naive violet
fervent ruin
leaden marsh
#

Services some time have payload you should check it

fervent ruin
#

Yes , hacker can migrate to trusted original services

leaden marsh
#

I love asking Ai lot

naive violet
#

The realtime version is paid

leaden marsh
#

The better one subcribed

fervent ruin
#

Ye , real time , the most important option

#

Bc u want to know in real time , not scan when u remember to scan

#

I use bitdefender free 🀑 its good πŸ™‚ and minimal

#

I think windows defender itself is good enough

#

Well configured and firewall well configured , u are already safe

leaden marsh
#

Minmal what u mean?

fervent ruin
#

Simple use

cosmic pendant
#

Malwarebytes is dope

#

normal windows defender is pretty good too

gray sonnet
#

πŸ‘€

fervent ruin
#

Ye i heard

#

If well configured

leaden marsh
#

I regert I breaked my pcπŸ’”

fervent ruin
#

I understand that pain

leaden marsh
#

But rather that ram slot is not working at all so that why

fervent ruin
#

Felt it long time ago

#

Oh

#

Mine was the screen that slowly seperated from the rest of the computer

leaden marsh
#

A1 for backup boot b2 is the main boot you know I use b2 for booting this not working so I anger and then broke it

fervent ruin
#

Idk what u talking avbout

leaden marsh
#

Right?

fervent ruin
#

If

#

Ig

leaden marsh
#

Thats why

fervent ruin
#

U can choose what ram slot does ?

leaden marsh
#

Not always you should choose one that boot

cosmic pendant
#

@gray sonnet

#

how the heck are ya

leaden marsh
#

@cosmic pendant accept my request friend

cosmic pendant
#

Yea, no I'm not going to do that

fervent ruin
#

Im really tired.. not understanding nothing already

#

He thinks u will exploit him when he clicks accept

#

Get a reverse shell through friend request

leaden marsh
fervent ruin
#

Bro that pc is destroyed

leaden marsh
#

πŸ’”.

#

This is my old friend

fervent ruin
#

How is the inside ?

#

I mean the specs

#

@cosmic pendant this certs u have , wich one u recommend to get first ?

#

I see a lot this CEH cert

#

Dont remember how much it is but i think that will be the first

cosmic pendant
#

depends what you want to do πŸ˜„

fervent ruin
#

Im still trying to figure that out

#

But ig im going for red team

#

I was focus on blue team recently just bc of the SAL1 cert , it would be my first cert

#

But idk

#

Its confusing and i really hate this feeling of not having time

simple epoch
#

any good guide for metasploit?

fervent ruin
gray sonnet
true viper
#

How much does a USB Rubber Ducky cost and will it cause any damage to my own computer if I plug it in without knowing how it works?πŸ—Ώ πŸ˜‚

crystal mauve
#

GM

fervent ruin
#

Wait , i think i cant joke like this...

true viper
#

Why? That would just kill my computer

cosmic pendant
#

you could get in trouble with the rules

leaden marsh
#

It really the bins of cpu has broken

fervent ruin
#

They can still see it πŸ€·β€β™‚οΈ

leaden marsh
#

Pins

cosmic pendant
#

Yeah, but you won't get in trouble if you police yourself

leaden marsh
#

I broke it uo

true viper
boreal scarab
# true viper How much does a USB Rubber Ducky cost and will it cause any damage to my own com...

DO NOT buy it on Hak5, they are price hiking up the fucking wazoo.
https://hackerwarehouse.com/product/usb-rubber-ducky/

#

$90

true viper
#

Damn that’s pretty expensive

true viper
cosmic pendant
#

Hak5 sucks

true viper
#

But I searched it up a little bit, it’s used to play pranks on others but it can also do some serious damage. Idk any of the details which is why I asked here if I buy one then plug it into my own device, will the Rubber Ducky automatically go into offense mode or will it let me configure it so I can use it legally?? But I’m also not entirely sure if it’s legal to even useπŸ˜‚ πŸ˜‚

fervent ruin
fervent ruin
true viper
fervent ruin
#

Do ur research

#

I think it will be very easy to find information about it

true viper
true viper
fervent ruin
#

They are very restrict with illegal stuff

simple epoch
#

Copilot is like free chatgpt plus?

mellow narwhal
#

What copilot?

#

Bing? Github?

simple epoch
#

Bing

mellow narwhal
#

Eh

fervent ruin
#

Bing ?

mellow narwhal
#

ChatGPT is better

simple epoch
#

Yeah but chatgpt costs money

fervent ruin
#

Bing the search engine ?

true viper
mellow narwhal
fervent ruin
mellow narwhal
boreal scarab
#

@shut hawk I know how much you love ChatGPT.
https://pentestgpt.ai/

true viper
mellow narwhal
simple epoch
#

Free version is limited to like 20 messages than it switches to some bad model

mellow narwhal
boreal scarab
#

Or or or or or. LOCAL AI WOOOOOOOOOOOOOOOOOOOOOH

true viper
mellow narwhal
mellow narwhal
fervent ruin
#

Just 9 hours to finish

#

The 2nd has same points since last night , hope he keep it πŸ™‚

#

Imagine losing 1st place at the end 😭

fervent ruin
#

And im not at home to get more points if anything happens

rapid merlin
fervent ruin
#

It depends

#

If i follow learn path or i complete challanges

#

Yesterday or 2 days ago i got 4 different badges

rapid merlin
#

cool

fervent ruin
#

Sometimes i do a lot , sometimes i dont do nothing

#

No one called saidok here

true viper
#

Guys am I cooked? My professor told me to install virtual box on my laptop but refuses to help me set it up πŸ’€ πŸ’€. Do I need big storage? I have windows 11

fervent ruin
#

Big storage for linux ?

true viper
fervent ruin
#

It depends if u need big files init

true viper
#

Oof

fervent ruin
fervent ruin
mellow narwhal
#

different companies

true viper
mellow narwhal
#

functionality is pretty much the same for your use case. Although people say VMware is better

fervent ruin
#

Why they say that ?

#

Can u close vmware after launching the vm?

simple epoch
#

When u guys nmap a machine what parameters u usually add

fervent ruin
#

Depends but

#

On thm machines u dont care about detection so

#

-A -T4

#

-T5 sometimes can give u some errors bc of the speed

naive violet
#

-v to print out ports as it finds them to probe further

fervent ruin
#

I usually run: nmap -sS -sV -T4 -p- -Pn ip -oN file

#

As first scan just to find the open ports

#

Then i run nmap -sS -A -T4 -p(found open ports) ip -oN advanced_scan

#

Sometimes i add --script vuln

#

To check for vulnerabilities agains the open ports

#

This is why i want to create a automation for my scans , to not write all of this everytime

simple epoch
#

-sC is good too?

fervent ruin
#

If u use -A , -sV -sC -O are used

simple epoch
#

Oh great

#

-A scans for all ports?

#

or 1k most popular

fervent ruin
#

No, its a aggressive scan

#

To scan all ports use -p-

simple epoch
#

got it , thank you my man

fervent ruin
fervent ruin
shut hawk
simple epoch
#

i see , thanks for the advice

fervent ruin
#

Im going to sing happy birthday to my grandma , brb

simple epoch
#

@shut hawk anything wrong with doing the -A?

shut hawk
#

and then don't forget UDP ports (rare but can happen) -sU

fervent ruin
#

True

shut hawk
#

-A adds OS version, script scanning, service scanning and trace route

#

-sV, -O, traceroute, sC

naive violet
cosmic pendant
#

#ItDepends

#

I need to get that on a hacker shirt

naive violet
#

Try it and seeβ„’

shut hawk
fervent ruin
simple epoch
#

i logged into an ftp server with the anonymous cred but when i type ls it says entering extended passive mode, wtf is that

fervent ruin
shut hawk
#

nope its just a figment of your imagination

simple epoch
#

its called simple ctf

fervent ruin
simple epoch
#

i did ftp <serverip>, logged in with anonymous user but when i type ls i get this weird message

fervent ruin
fervent ruin
leaden marsh
#

Redteaming in thm need offensive security or just jr pentesting

fervent ruin
#

Thm should create red team certificates πŸ™‚ like SAL1

leaden marsh
fervent ruin
#

Learn what ?

sand trench
#

Wallpaper of the day:

modern fox
#

arrives

leaden marsh
modern fox
leaden marsh
# leaden marsh

Should I learn web fundamentals then go to web pentesting,

leaden marsh
cloud quiver
leaden marsh
#

Red teaming is the last of pentesting the end of it right?

leaden marsh
simple epoch
#

@fervent ruin after i install kali there is any command i need to type to update it? seems like im missing tools like gobuster

cloud quiver
leaden marsh
#

Sorry kgb for mentiong

gusty inlet
#

It isn't present on the roadmap

fervent ruin
#

Is it just gobuster missing ?

gusty inlet
fervent ruin
#

Bc if u download the iso image , it is limited , it happen to me , i had to download vbox iso

#

Thats a pre-build vm

gusty inlet
#

ISO image doesn't have GoBuster

cosmic pendant
gusty inlet
#

At least it didn't last year

modern fox
gusty inlet
#

I had to download it manually

fervent ruin
cosmic pendant
#

Me? Use AI?.... ha

fervent ruin
#

Beep boop

shut hawk
#

in human form

fervent ruin
twin ridgeBOT
#

Gave +1 Rep to @gusty inlet (current: #284 - 25)

cosmic pendant
fervent ruin
#

It depends πŸ™‚

fervent ruin
eager marsh
cosmic pendant
fervent ruin
eager marsh
boreal scarab
naive violet
modern fox
naive violet
#

People should be encouraged to try things and learn practically. A homelab is hugely beneficial in this industry

full ginkgo
#

Hello

vestal bone
vestal bone
#

Holly molly the general channel was inactive for 10minutes

#

It was never this quiet

loud marlin
#

local shop =/

silver sky
pallid lotus
pallid lotus
#
  1. What did that poor bag ever do to you?
#
  1. Where in the name of God are your trousers? kekw
silver sky
pallid lotus
#

Apparently that was one of the favourite tactics in ages past. Run into battle stark naked and kill the opposing army before they recover from the shock

silver sky
#

I actually do have a kilt somewhere

pallid lotus
#

Kilts are relatively modern

leaden flicker
#

Hey can somebody help me with domain certificates? So I have successfully created the certificates for my domain but there's an error when using the subdomain. Do I need to create a certificate for my subdomain as well?

pallid lotus
#

Would have been a plaid originally

pallid lotus
#

A certificate is only valid for its CN and any specified SANs. You can create a wildcard certificate which works for subdomains, otherwise it'll only do exactly what you specify.

silver sky
pallid lotus
#

Why would you choose to wear something that loose to fight..?
Especially when traditionally you forgo underwear with a kilt kekw

leaden flicker
loud marlin
#

@blazing granite i set timeshift. didnt know that menu select show in grub load menu

devout palm
silver sky
silver sky
pallid lotus
pallid lotus
silver sky
#

It's part of the sport culture πŸ˜‚

pallid lotus
#

Bizarre choice

vestal bone
leaden flicker
pallid lotus
leaden flicker
#

Oh okay got it

#

There should be a name of that subdomain

#

My mistake

pallid lotus
#

The only time I would use wildcards personally are for an application which uses subdomains dynamically.

Burp collaborator is a good example.

fervent ruin
#

How can i find the subdomains of thm machines ??
And how can i get the ip of this subdomains ?

pallid lotus
#

Whether self-hosted or SAAS, it works by dynamically creating a subdomain with a canary token in it, and using a wildcard cert / DNS to catch the traffic.

#

Or for a CTF with a new instance per challenger

fervent ruin
#

Oh ok

pallid lotus
#

So, uh, there are no domains, let alone sub domains.

fervent ruin
#

Okok πŸ™‚

pallid lotus
fervent ruin
#

But the subdomains use the same ip as domain?

pallid lotus
#

Again, there's no DNS lmao
Are you asking about virtual hosts?

rich thunder
#

broo im blown away to how awesome these rooms are

leaden marsh
#

Now I organized my path offensive security first than red teaming

restive thorn
pallid lotus
#

If it's vhosts, then a webserver can be configured to direct traffic based on the HTTP Host header. Usually that's set to be a non-existent but standards compliant domain for a CTF machine (e.g. challenge.thm).

In that case to answer your original question, you'd be looking to fuzz the host header to find which vhosts it's configured to listen on.

#

Then yes, you would set an override in your hosts file mapping that vhost to the IP of the box.

restive thorn
frozen gull
#

what a coincidence

restive thorn
#

That is the format

frozen gull
#

im literally on the header part

fervent ruin
#

Ok , i think i understand

naive violet
restive thorn
#

For /etc/hosts

pallid lotus
#

Hell, I've done that myself with Hipflask lmao.

molten sky
#

MUIRI! What happened to your role?!?!?!

pallid lotus
#

Which one now...

restive thorn
#

I ain’t a clue haha

molten sky
#

tbh ider what role that was about

pallid lotus
#

Oh, you're memeing.

#

It was when they deleted the admin emeritus role

molten sky
#

ah yeah that's the one

pallid lotus
#

Go ask James what happened to his role kekw

molten sky
#

yo wtf

pallid lotus
#

Or Juun, or Hydra, or Omega, or Zojja, or any of the others that resigned in the last week or so

molten sky
#

unexpected turnover all at once lol

#

coincidence or nonsense behind the curtain?

naive violet
half girder
molten sky
#

sounds like there was some responsibility drift

naive violet
#

More overstep instead

molten sky
#

tryna have the volleys take up extra stuff?

restive thorn
#

@fervent ruin did you sort the subdomains out?

molten sky
#

they should promote me into the open role as an honorary admin

fervent ruin
molten sky
#

none of the responsibility tho

restive thorn
#

Ahhh well I’m a good teacher…got any questions come to me

molten sky
#

speaking of turnover, haven't seen dolphin in here in ages ---- still pop in at all?

#

oh damn, last msg in November

fervent ruin
molten sky
#

also no longer on the server. huh.

sick lance
#

Nah, she left.

molten sky
#

ayy scrubz is still a mod tho

sick lance
#

For the time being.

silver sky
#

for now

molten sky
#

,-,

loud marlin
sick lance
#

Could always add as a friend.

molten sky
#

i've got an open thread already so Ha

loud marlin
#

oh... that can help heh

molten sky
#

oh wait we're friends too apparently

#

didn't realize

#

discord is weird

sick lance
#

Discord is shit.

boreal scarab
#

@molten sky Doplhin is doing good, she's taking a social media break. Last time I asked about her, prob a couple weeks ago, she's doing good πŸ˜„

devout palm
#

I should also quit

#

It is an addiction

median drift
#

Anyone, if I complete advent of 24, then am I eligible for earning the certificate

sand trench
#

where to buy gold bars in sweden

#

wait shit this is not shadows search engine

pulsar flax
loud marlin
#

in gold bars shop in sweeden... πŸ™‚

pulsar flax
naive violet
#

That implies it's a private repo usually

sand trench
#

^ this

pulsar flax
sand trench
#

using your ssh git key would help

naive violet
#

So it's a private repo
You need to enter creds that can access the private repo?

pulsar flax
#

i want to install awus036ach drivers

#

but it cannot working

#

😭😭

#

drivers not installing properly

loud marlin
#

@boreal scarab have ever print with Nylon Carbon Fiber?

pulsar flax
#

can anyone teach me

loud marlin
#

did you try search in package manager ? like sudo apt-get search ...

pulsar flax
boreal scarab
loud marlin
loud marlin
boreal scarab
#

Almost like, it was molded for questions

loud marlin
#

and show results on first page πŸ™‚

placid nymph
#

Hello, How do i get my role here from the levels

loud marlin
sharp citrusBOT
gritty fern
#

Sorry ral, took forever to send

placid nymph
#

Thank you @gritty fern @loud marlin i Got it

twin ridgeBOT
#

Gave +1 Rep to @gritty fern (current: #199 - 41)

sharp citrusBOT
loud marlin
#

wrong

modern fox
blazing granite
loud marlin
#

heh, i have extra line to select one i can restore

knotty pendant
loud marlin
#

@boreal scarab

rapid merlin
#

Guys is joining hiddenwiki from chrome normal

#

I just joined it to check out didn't click on any links inside it

knotty pendant
cosmic pendant
#

Hello

loud marlin
#

... darknes, my old friend...

finite lake
#

good morning all. hope eveyones snday is going good.

sick lance
rapid merlin
#

I can clearly see

#

Can u answer me tho

#

Is it fine

sick lance
polar shale
#

What beginner 3d printer should i get? Budget $500 max maybe i just want for personal fun hobby

sick lance
#

If you can clearly see that it's not much chat, it's for a good reason. πŸ™‚

rapid merlin
polar shale
sick lance
#

I can clearly see

Is being rude.

rapid merlin
loud marlin
#

i have Tor option on router and never try it lol

cosmic pendant
sick lance
rapid merlin
#

Did u even read my question?

cosmic pendant
#

3 Questions, one answer, I love it πŸ˜„

sick lance
#

If you continue to be rude, you may lose the ability to speak. πŸ™‚

rapid merlin
sick lance
#

Hidden Wiki is a darkweb site.

#

One of the oldest too.

rapid merlin
#

Yep but I meant I just joined to to check out how it is didn't click on links inside it

sick lance
#

So it's still related to dark web chat.

#

Now you can stop asking as you got the answer. πŸ™‚

rapid merlin
#

Okay admin

#

Where can I find my answer?

#

Do you know

cosmic pendant
#

I answered your question

sick lance
#

Something something no dark web chat.

cosmic pendant
#

Also, why are you asking people if you don't think we know?

#

................ insert thinking face here

sick lance
#

You're choosing to ignore people who're giving you answers, because it is not the answer you want.

rapid merlin
#

U said u don't have to be there

#

I'm already not there

rapid merlin
#

I just did checkout and wanna see if I'm safe or not

cosmic pendant
#

I'm saying you should'nt be there

sick lance
rapid merlin
cosmic pendant
#

What's the weather like Scrubz?

#

How are you doing?

rapid merlin
#

.

#

Have a good day

sick lance
#

It's actually warm and dry, for Scotland we have a wildfire warning, which is nothing compared to rest of the world, however it's not too common for hear, one of my favourite walks in Arran has been destroyed 😦

#

How are you?

cosmic pendant
#

That sucks

#

I'm good

silver sky
#

Ayyyy toaster

leaden marsh
#

is better to study offensive security then redteaming

cosmic pendant
#

how do you have redteaming without offense?

leaden marsh
cosmic pendant
#

Doesn't matter so much, just learn

leaden marsh
#

Great 🀍.

cosmic pendant
#

Don't be a person that worries more about learning the right thing, then anything at all : Good life advice. (This is general advice and not aimed at you)

#

But I see that on here good bit

leaden marsh
#

But webpentesting shoud have web fundetmentlas

#

Right?

cosmic pendant
#

of course

leaden marsh
#

🀍

#

I will make you toast 🀍🀣

#

Its just joke 🀍🀣

fervent ruin
#

How friends work on thm?

#

If i add someone , what we can do?

boreal scarab
#

@loud marlin Ay, Toast is having issues with his printer. He tried to print in PETG but it's clogged in there. What do you usually do if there's a clog?

#

I told him my way, but want your perspective

cosmic pendant
#

2nd time now too

loud marlin
#

try extrude in lcd menu. if is not going out then heat nozle up to 220-230 temp and take out fillament. and use if have that needle to unclog

#

you have also unicorn type of nozzle iirc for k2

#

in lcd menu you ahve extrude and/or retract selection

fiery imp
loud marlin
cosmic pendant
#

wilco

modern fox
#

or skin care pentesting

loud marlin
#

is for 3d printer. but you are close

modern fox
loud marlin
# cosmic pendant wilco

also do a temp tower calibration for petg. and cehck what temp says on filament. temp for petg is important

#

tbh. pet g can be pain in ass for sure

#

for petg i go around 230-240 nozzle and 70-80 bed temp and slower print speed around 120-150 max

sand trench
loud marlin
#

hehe.

cosmic pendant
#

k

queen flare
#

i got the one month streak badge

fervent ruin
#

yours look different from mine

queen flare
#

show

fervent ruin
#

i have this already, hunting more

loud marlin
#

@sand trench what remote app you use on arch hyprland ? if so

queen flare
fervent ruin
#

ok

sand trench
loud marlin
#

like remmina or so

queen flare
#

use ssh

fervent ruin
sand trench
#

ah for RDP and VNC??? yeah use remmina

queen flare
sand trench
#

rdp is a microsoft thingy yes

queen flare
sand trench
queen flare
#

remmina works with arch?

#

da hell

#

oh nevermind

sand trench
#

yeah it is an easy sudo pacman -S remmina

leaden marsh
#

But I have question start offensive security first or redteaming

Can someone answer please

cosmic pendant
#

...............

#

you could have been learning this entire time

#

get off discord and go read! (take notes)

leaden marsh
#

Okay

#

Thank you my brother

loud marlin
#

ok... remmina works πŸ™‚

finite lake
#

questions? has anyone paid for the permium yearly for TryHackMe.com

finite lake
gusty inlet
#

WDYM by worked out for me?

sturdy raptor
crystal mauve
#

You still haven’t picked red or blue pill mo’?

#

Neither will get you a job, do what u enjoy learning

finite lake
sturdy raptor
#

?

sturdy raptor
finite lake
#

OO lol

crystal mauve
#

It’s rot13

finite lake
#

ok ok

#

I well i am dedicding should i pay or just go wth the free one. but i want to learning more like everyday

mossy river
#

Why not try free and if you like it, subscribe? πŸ˜„

gusty inlet
mossy river
#

Always on my right monitor

queen flare
#

is there a way to see a list of all obtainable badges on tryhackme

sick lance
#

Discord is my left.

sick lance
loud marlin
#

@sand trench πŸ™‚

sand trench
#

1335

sick lance
sand trench
queen flare
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3632)

crystal mauve
#

Just 2 away from leet

fervent ruin
#

u almost there

sand trench
#

yeah

molten sierra
#

Who can help me find a French-speaking server about cybersecurity

gusty inlet
#

You don't need to spam this in all channels xD

#

I can speak french if you need help DM me

mossy river
gusty inlet
#

The hardest decision I need to take everyday is what to have for dinner

celest dirge
sand trench
finite lake
#

so do we have to pay for the certification if we pay for the premium

gusty inlet
#

I wonder how is this obtainable?

sick lance
#

One section left for my report, the lit review.

crystal mauve
gusty inlet
sick lance
#

Sal1 and AWS are costs that aren't included in the subscription.

sick lance
modest charm
mossy river
#

I believe you get a discount for sal1 if you buy the subscription

gusty inlet
modest charm
sick lance
#

It may not be limited to the website.

mossy river
gusty inlet
#

Did THM ever launch donation campaigns?

#

Oh

fervent ruin
#

how can i change the TERM variable after creating a python shell?

#

so i can use ctrl c

#

without exiting the shell

mossy river
#

ctrlz to background the process

#

I don't recall every changing term for shell stabilisation

fervent ruin
#

why not?

mossy river
#

python -m "import pty;pty.spawn('/bin/bash')"
[ctrl+z]
stty raw -echo; fg
[enter, enter, enter]
stty rows 30 columns 100

#

or if python wasn't available I'd use /usr/bin/script -qc /bin/bash

fervent ruin
#

no way im going to remember all of this

mossy river
#

this is mainly muscle memory so I'd double check the commands are correct