#general

1 messages Β· Page 1015 of 1

blissful current
cerulean star
#

I am currently going with the web application hacker hand book and tbh i have no one to ask my Silly question or important ones to

#

Sorry idk πŸ˜Άβ€πŸŒ«οΈ

blissful current
#

πŸ˜…

sick lance
blissful current
#

its a tool to analyze web traffic , and find vulns , ...nothing script kiddy in that lol

#

πŸ˜…

cerulean star
cerulean star
#

Just started

sick lance
blissful current
sick lance
#

Think of it as an interactive book, they is broken down and simplified.

#

That is

cerulean star
#

Hmm Understandable

cerulean star
#

I will come with more question tomorrow

#

Good night

sick lance
#

Also, that book is more than likely out of date with burp.

#

Later tater.

cerulean star
fair linden
cerulean star
sick lance
cerulean star
#

What*

blissful current
naive violet
fair linden
#

ahh got it

cerulean star
naive violet
#

Tryhackme

cerulean star
#

Ok thx ninja and the mod good night

shy fjord
#

Can I have the role to access creators-lounge channel please?

twin ridgeBOT
#

βž• Gave the role Creators-Lounge to heliman.

blazing granite
#

@naive violet weird seeing you without the shield πŸ™‚

mellow narwhal
#

/giverole user:@mellow narwhal role:@Admin

#

aw man didn't work kekw

sick lance
devout palm
#

CVE back!

#

By the supports of CISA

mellow narwhal
#

For now.

devout palm
#

I'm sure no services will be interrupted. They'll find a way eventually.

light glen
#

hey is anyone havng problem when connecting on machines??

devout palm
#

Because CVE is a significant part of the cyber security world.

dark mason
light glen
#

it is just loading

dark mason
#

But better than no CVE at all

fleet pivot
#

i like chicken

fair linden
devout palm
#

James, thanks for the support you have given for years. I think you deserve an appreciation.

cosmic pendant
fleet pivot
shut hawk
devout palm
leaden marsh
#

is nessary to learn Ai in cybersecurity how to create it?

daring gazelle
#

How in the world do people memorize the OSI model?

devout palm
leaden marsh
#

I hate Ai to create it because all math

blissful current
polar spoke
leaden marsh
untold osprey
#

Please Do Not Touch Steve’s Pet Alligator

blissful current
daring gazelle
#

I suppose locating the information you need when you need it is equally as important as memorizing stuff.

leaden marsh
daring gazelle
#

There is a lot of information I’m trying to absorb from Cybersecurity 101.

loud marlin
#

... let's upload 12 gb of books =/

leaden marsh
untold osprey
blissful current
#

make notes , there will be much more stuff ahead , u wont be able to memorize each n everything , nor can i or most people here

just focus on the important stuff about it to be memorized, that should be enough

wooden quiver
#

My first contribution to this server: Ai hasn't a hope of breaking cryptography. Mathematicians appreciate this. What then is its use, er social engineering maybe?

blissful current
#

and scripting ...but still not too much but helps a lot

wooden quiver
#

actually yes, it is great for putting together scripts to do stuff

daring gazelle
oak marsh
#

me waiting for my brute force thingie to complete

desert dirge
blissful current
wooden quiver
oak marsh
#

oh ye currently AI sucks are cryptography, kinda interesting

untold osprey
oak marsh
daring gazelle
fervent ruin
#

anyone knows how to get rid of this? i get this error even with venv

blissful current
blissful current
fervent ruin
#

and im trying to install a exploit from github, i need to install the requirements

#

i have created it

#

bro, i fixed, nvm

#

stupid things

blissful current
#

lol ok

#

in some cases might need to use apt instead of pip too

fervent ruin
#

now i get other erros, but now is about the exploit itself

daring gazelle
#

I did find Linux Shells to be pretty fun though.

blissful current
vocal geyser
#

Running a script = hacker πŸ’€

blissful current
#

some github codes are older and they were written using python2 , and running it with py3 causes error too

blissful current
desert dirge
boreal scarab
# fervent ruin

I see the WatchDogs logo in the background. You can't hide it from me!

blissful current
#

i didnt notice it lol

agile bane
#

I love you guys So much

oak marsh
#

aww love you too

agile bane
oak marsh
modest thicket
#

Whoever hackin my f***ing work STOP NOW!!!!

boreal scarab
loud marlin
#

some smartass in my town decide to put full UV led lights to make things looks cool, and ppl end up in hospital with eye issues =/

blissful current
#

eh?

boreal scarab
modest thicket
#

AND WHOEVER PHISHED ME WITH THAT FAKE XFINITY EMAIL F*** OFF

oak marsh
#

you giving out your email online?

fervent ruin
blissful current
fervent ruin
blissful current
boreal scarab
fervent ruin
#

yea

modest thicket
loud marlin
#

you must be super ultra cool if feds get you email lol

light glen
#

anyone having problem with accessing web machines

#

???

blissful current
light glen
#

i am doing Metasploit-a-ho-ho-ho

#

it won't access the web interface

oak marsh
#

Im using the resources to brute force in gobuster

#

you remembered to add the site to /etc/hosts ?

daring gazelle
blissful current
#

ya put host in /etc/hosts

blissful current
#

i still have to do Advent of Cyber , i'll start them next week

oak marsh
#

I havent even considered doing em but keep getting suggested to try

blissful current
#

looks fun , with stories like scenerios

oak marsh
#

christmas be coming early this year ChristmasNessieFlare gotta give em a look

blissful current
blissful current
#

50 days streak TryFlagMe

untold osprey
peak hare
#

Yooo

blissful current
#

Yo

peak hare
#

How's it going?

blissful current
#

fine , wby?

fleet pivot
peak hare
blissful current
boreal scarab
fleet pivot
#

πŸ’€ oops Hope no one saw that, didn't mean to like myself like that

outer fjord
#

Damn

desert dirge
outer fjord
# leaden marsh What is talking about?

New UAC Bypass
New task metadata poisoning
New event log buffer overflow allowing to overwrite log content and evade detection
New unprivileged security logs saturation

light glen
sick lance
daring gazelle
#

Honest thoughts?

Is AI becoming more prevalent in business, healthcare etc. Going to skyrocket the need for cybersecurity professionals?

inner tendon
#

Hello Chat

fair linden
#

Anyone here who wants to play capture the flag on thm tomorrow?

fair linden
#

Whats your name on thm

rapid merlin
#

dm me

dark mason
#

But surely will increase it

#

As AI is known for writing vulnerable code

rapid merlin
#

hey guys a little question
i just downloaded mint linux on my virtualbox to learn linux (first time using linux) but idk what to learn or where to start can anyone give me a checklist of some sort or a yt video i can use
going to be switching to kali linux once im more comfortable with the linux environment

cosmic minnow
#

You guys like my sign? I thought it was witty...

fair linden
rapid merlin
#

i have no idea really

fair linden
#

There you can learn the basic linux commands

fair linden
#

such as cd mkdir cat etc

rapid merlin
fair linden
#

yes

rapid merlin
fair linden
#

idk tbh i'm just at lvl 6

dark mason
twin ridgeBOT
#

Gave +1 Rep to @dark mason (current: #299 - 23)

twin ridgeBOT
#

Gave +1 Rep to @dark mason (current: #293 - 24)

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

hearty dove
#

Hello guys

#

I'm new here

#

I've always wanted to hack

#

And understand programs from a deeper more, newer perspective

#

I just wanna also gain power

#

And realm the cyber security world

#

So abuser and malicious criminals can be put in their places

#

Off and on discord.

loud marlin
#

@sand trench got bunch of new wallpapers

wraith raptor
#

Have you noticed battery drain from Hyprland ?

naive violet
#

The police don't tend to appreciate it

hearty dove
#

Why

naive violet
#

Someone else doing something bad doesn't mean you get to do something bad to them

hearty dove
#

And self defense

#

By put in their place meaning legal action.

naive violet
whole yew
#

You should consult a cybersecurity specialized lawyer before you put that idea into production.

hearty dove
hearty dove
#

Tech is the new and next power

naive violet
#

This ain't Hollywood

whole yew
#

So anonymous vigilanteism that will likely cause any evidence gathered to be fruit of the poisonous tree and be inadmissable? Sounds like a terrible idea.

wheat flint
#

But then you have to ask yourself why you want to be a hero

#

And its for "other people"

#

Its really for yourself

daring gazelle
#

Let him cook. I’m sick of getting texts about unpaid toll tickets.

ionic pagoda
#

hi

#

does thm have a bbounty prog? if i was able to see paid content would thag be reportable ?

spice otter
ionic pagoda
#

i can see and use the creds there and interact with the labs

#

like if the lab is URL based uw/pw

spice otter
hearty dove
spice otter
#

2 wrongs dont make a right in the legal world

hearty dove
#

To better understand how people could use me

hearty dove
spice otter
#

πŸ‘€

#

buddy take little steps

#

learn how a network works first

wheat flint
hearty dove
spice otter
hearty dove
#

Movie hacking is literally typing random notes🀣

#

It's outright impossible sometimes.

round orbit
#

Anyone got an example of a domain that doesn't have WHOIS protection?

daring gazelle
#

Even the baby steps about real-life ethical hacking has made me feel like an absolute caveman with technology πŸ˜‚

silent nova
light glen
#

quick question guys

#

what is better vmware or virtualbox??

#

which one is better

pulsar cosmos
#

Sorry for the late reply,
I don't remember where but I saw a post on Twitter from the user "Dark Web Informer - Cyber Threat Intelligence" that the user message database was leaked and that it was for sale

silent nova
#

Sadly I don't have a solid answer for you at the time, but I usually use VirtualBox more than VMWare. Personal preference though.

civic reef
silent nova
silent nova
twin ridgeBOT
#

Gave +1 Rep to @silent nova (current: #547 - 11)

light glen
#

webpages

round orbit
silent nova
rapid merlin
#

@mossy river Hey i'm new here

#

Can you introduce me to server

mossy river
#

πŸ‘‹

silent nova
rapid merlin
mossy river
#

What exactly do you need? πŸ˜„

rapid merlin
mossy river
#

Sure :) added

round orbit
silent nova
#

Best of luck with your research!

unique valley
#

can someone help me with a question from the MITRE room?

chilly veldt
grim sparrowBOT
#

:hammer: johnnyangelojr._89816#0 has been banned.

leaden marsh
#

I want take some rest and see some the wolf amoung us

#

Darky beach πŸ–€

sturdy thicket
#

hi

silent nova
#

πŸ‘‹ Welcome to TryHackMe!

oblique escarp
#

Hello

leaden marsh
#

PhotoπŸ€πŸ–€

somber verge
#

just found this absolute gem

silent nova
leaden marsh
snow kelp
#

Hi

#

Does anyone know instagram

silent nova
#

... oh.

cosmic minnow
desert dirge
#

I think they're muted

silent nova
#

They are.

#

Dunno why.

desert dirge
#

Does that name read what I think it does?

desert dirge
winged summit
#

hello πŸ™‚

silent nova
#

πŸ‘‹ Welcome to TryHackMe!

winged summit
#

thanks πŸ™‚

mossy river
#

Just a reminder to everyone to use the report command in the channel that the problem is happening and not #bot-commands πŸ˜„

winged summit
#

how's everyone doing?

crystal mauve
#

Dogs > Cats

spice otter
#

so did CVE actually get murdered 😭

civic reef
grim sparrowBOT
#

Done!

wooden echo
#

I picked a GREAT time to get into cyber

spice otter
gusty inlet
#

But I think it's all fixed now

wooden echo
wooden echo
#

New Ubuntu comes out tomorrow and I can finally say it's idiot-proof. This is probably the 6th time I'

spice otter
twin ridgeBOT
#

Gave +1 Rep to @gusty inlet (current: #229 - 35)

wooden echo
#

ve tried to switch but I'm finally gonna stay this time, (I switched to arch, but Ubuntu 25 is pretty dope, still)

modern fox
wooden echo
#

Funding for CVE

#

It was cut, but now it's back. Just more of the same nonsense XD

gusty inlet
wooden echo
#

Common Vulnerabilities and Exposures

#

I was like, just my luck. I literally JUST learned eternalblue.

cosmic pendant
#

Hi

gusty inlet
#

Hi toaster! How are you doing?

spice otter
cosmic pendant
#

I'm good

#

How are you folks

gusty inlet
#

Doing great thanks

cosmic pendant
#

Good good

#

learn anything cool?

gusty inlet
#

Currently just doing some THM rooms to get ready for CRTO

cosmic pendant
#

oh CRTO is really fun

gusty inlet
#

Yup! You got the cert?

cosmic pendant
#

I don't, but it did it

#

I don't need anymore certs

#

but CRTO was the last thing I did to stay sharp πŸ˜„

gusty inlet
#

Expired/Failed/No attempt?

cosmic pendant
#

Didn't attempt it

gusty inlet
#

Does the voucher expire

cosmic pendant
#

just wanted the training

#

Yeah it does

gusty inlet
#

Oh darn it

cosmic pendant
#

Get started on CRTO πŸ˜„

gusty inlet
#

The badge is cool, the cert design is ugly.

gusty inlet
cosmic pendant
#

Oh. that's surprising

#

I should try it hahah

gusty inlet
#

Here's you chance to also go for it : p

cosmic pendant
#

it was like 2 years ago

gusty inlet
#

If you thought it was gone and it isn't, just go for it anyways since you weren't planning on having it

#

If you fail you fail whatever

#

I think lab time is costly

sand trench
#

and another good day of playing control and now it is time to go sleep sloop to beep boop for meep moop

crystal mauve
#

What’s control ?

#

Gnite

#

Oh that game lol

sand trench
crystal mauve
#

I couldn’t get into it

#

Last puzzle like game I got into was warframe

#

So good for a free game

sand trench
#

It is more of a story driven action game then a puzzle game though

crystal mauve
#

Oh I thought u had to use your powers dependent on the atmosphere sorta

#

Bring down chandelier to kill x guys

spice otter
wooden echo
#

I played control for a few hours, then stopped abruptly, but I can't remember why. Hitman is my jam (or WAS before THM, lol)

subtle pawn
#

are AV's today fully equipped against obfuscated codes? keeping in mind that some do sandboxing and heuristics?

orchid tusk
#

is there a way to hide the new echo bot lol, its taking up my screenspace πŸ’€

boreal scarab
cosmic pendant
subtle pawn
#

let's say windows defender

subtle pawn
cosmic pendant
#

that is a silly question

#

Window defender isn't half bad

cosmic pendant
# subtle pawn silly question but ... why not ?
#

Read tyat

#

then we talk

subtle pawn
#

is most malware today encoded with metasploit (meaning like , is it that easy?) or is manually obfuscated

subtle pawn
twin ridgeBOT
#

Gave +1 Rep to @cosmic pendant (current: #44 - 217)

gusty inlet
#

I can't wait to get into advanced evasion and maldev after CRTO.

#

I'll probably go for the CETP or some Sektor 7 courses.

orchid tusk
cosmic pendant
# orchid tusk
section .data
    hello db 'Hello, world!', 0xA  ; string + newline
    hello_len equ $ - hello        ; length of the string

section .text
    global _start

_start:
    ; syscall: write(int fd, const void *buf, size_t count)
    mov eax, 4          ; syscall number for sys_write (4)
    mov ebx, 1          ; file descriptor 1 = stdout
    mov ecx, hello      ; pointer to message to write
    mov edx, hello_len  ; message length
    int 0x80            ; make syscall

    ; syscall: exit(int status)
    mov eax, 1          ; syscall number for sys_exit (1)
    xor ebx, ebx        ; return code 0
    int 0x80            ; make syscall
#

NASM

gusty inlet
subtle pawn
cosmic pendant
#

CRTO > CRTO 2 > More whatever

orchid tusk
#

we are not the same ollie

subtle pawn
#

funny thing i caught some minecraft kids selling some bs which was actually a RAT lmfao

#

i still have the obfuscated java code in .txt file here

stoic quarry
gusty inlet
# cosmic pendant CRTO > CRTO 2 > More whatever

But you didn't really argument on why you are recommending RTO II before more of whatever?
CETP starts advanced evasion from scratch, so even someone who knows nothing to evasion can go from beginner to advanced (Covers a lot)

I'd like to know why you think RTO II would be a better fit

subtle pawn
#

lol

subtle pawn
#

crazy sh

cosmic pendant
#

Writing the best 'malware' aka tooling doesn't matter if you can't operate

gusty inlet
#

Hmmm I kind of see where you're coming from

leaden marsh
#

Its hard

orchid tusk
subtle pawn
#

with their shitty code

gusty inlet
#

Don't wanna be that guy but this is a huge wall of text lol

spice otter
#

rip the big wall of text

leaden marsh
#

It was mistake sorry

#

@sick lance It was mistake sorry really

boreal scarab
#

ECC RAM?

#

Error correction code memory (ECC memory) is a type of computer data storage that uses an error correction code (ECC) to detect and correct n-bit data corruption which occurs in memory.
Typically, ECC memory maintains a memory system immune to single-bit errors: the data that is read from each word is always the same as the data that had been wr...

full jungle
#

Any competitions happening soon?

boreal scarab
#

Researchers have calculated the quantum computer size necessary to break 256-bit elliptic curve public-key cryptography: Finally, we calculate the number of physical qubits required to break the 256-bit elliptic curve encryption of keys in the Bitcoin network within the small available time frame in which it would actually pose a threat to do so...

#

Ok

#

What would I do? Nothing. I'm ethical. lol

crystal mauve
spice otter
#

ok ok, 1 for every 100 πŸ˜‚

crystal mauve
bitter latch
#

Can I have the role to access creators-lounge channel please?

spice otter
#

isn't that just the 4 keys that give you a debuff in lua?

crystal mauve
#

Drift mods were the shiet n so hard to get

spice otter
#

or am i thinking of something else

spice otter
bitter latch
#

yes

spice otter
#

maybe try dming jaba

crystal mauve
#

It’s been so long I don’t even remember which 1 I used in my build

proper sable
#

bros casually asking someone to commit a felony

desert dirge
#

what the hell

desert dirge
#

mabois discord name is emoji bob

#

It puts the lotion on the skin or it gets the 😁 again

proper sable
#

report it to the police

south egret
crystal mauve
#

Nope

sharp sail
#

Nah im just gonna troll you

#

Idk you tell me

#

Nah this is tough love homie

south egret
#

Melon didnt know u grinded the shit out of thm what the skibidi

sharp sail
boreal scarab
#
  1. We are not hackers for hire.
  2. This discord is for https://www.tryhackme.com , an ETHICAL hacking teaching site.
  3. We do NOT condone, nor do we even break laws here.
TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

sharp sail
#

Don't forget to take SAL1 and advance to your PEN15 cert later

cosmic pendant
#

party time

modest thicket
#

i got phished today

#

anyone wanna see

boreal scarab
#

"Here's a free giftcard, can you like my skin I totally made?"

#

I like accepting random people, seeing their attempts lol

modest thicket
#

na these bastards got me good

#

ima send a screenshot

jade orchid
#

Im about to complete my 32nd education room and im working on my net+ but I still feel dumber than a rock. Anyone else feel this way?

boreal scarab
modest thicket
#

yea ima edit that out

boreal scarab
cosmic pendant
#

Get attribution πŸ˜„

modest thicket
#

im about to post it here for the lolz. hopefully someone catches the bastards. got my password and CC info.. autofilled it with apple pay lmao

cosmic pendant
#

"forthcoming"

modest thicket
#

yea, im a dumbass, i get it

spice otter
#

thats insane

modest thicket
#

πŸ’€

cosmic pendant
#

Troy Hunt Got phished

jade orchid
#

It happens @modest thicket. Just gotta take a lesson from it and try to fight the complacency that we all get sometimes.

modest thicket
#

well.. maybe im not too much of a dumbass after all skidy I was just in a rush tbh.. was in the middle of working and thought i legit didnt pay my bill lmao

cosmic pendant
#

that's all it takes

jade orchid
#

did your email filter not pick it up? I cant imagine it being a warmed up domain.

quiet roost
#

looool hopefully your bank can decline the transaction or you can let them know just in case or pause your card

modest thicket
cosmic pendant
#

wait

quiet roost
#

nice tbh they getting smarter with it not yoyr fault you not stupid at all

cosmic pendant
#

did you say it autofilled?

modest thicket
#

yes

#

apple pay

cosmic pendant
#

..................

#

on a fake domain?

modest thicket
#

yes

sturdy thicket
#

Helloo

modest thicket
#

if you have a sandbox you'd like to play with it in, ill DM it to you

quiet roost
#

yh cant lie that is a problem

cosmic pendant
#

put that into VT

#

report that stuff

modest thicket
#

ok, what is VT? im quite new to this honestly

cosmic pendant
#

virustotal

modest thicket
#

i just submitted it

#

it is quite a strange url

boreal scarab
#

I like to mess with phishers sites by spamming em with bogus creds πŸ˜„

modest thicket
boreal scarab
#

Time to have some fun on Browserling!

#

I get brought to a QR code generator....

#

confused noises

boreal scarab
modest thicket
jade orchid
#

im really not interested in going there myself but would love to see a screenshot

boreal scarab
#

Just random redirects

modest thicket
cosmic pendant
#

Lets talk 3d pritners

#

What is a top tier consumer printer?

modest thicket
#

also, i replied to the email for shids and giggles with a congratulatory message, commending the bastards, and this was what i got in response.. not sure if this is normal or not.

cosmic pendant
#

lol, you may get a disclsoure

#

you should delete that

#

they may have an open mail relay

modest thicket
#

delete it from my mailbox?

cosmic pendant
#

from teh chat

modest thicket
#

or like my sent mail?

cosmic pendant
#

reach out to @boreal scarab he'll help you research that domain

#

you may want to reach out to an admin in that district

twin ridgeBOT
#

Gave +1 Rep to @cosmic pendant (current: #44 - 218)

modest thicket
modest thicket
#

broken comm system i try to do good things

boreal scarab
cosmic pendant
#

creality is top tier consumer?

boreal scarab
cosmic pendant
#

I don't have any problems so far (it's my dads)

#

I'm looking at one

#

if I wanted to spend more money

#

what would you get?

#

let's say 3k

clear jackal
#

You're probably in semi-commercial at that price

cosmic pendant
#

ohh I'm okay with that then πŸ˜„

#

I want to able to print in TPU

boreal scarab
#

3k? Ultimaker is reputable, been around for a VERY long time

boreal scarab
cosmic pendant
#

is that good or bad?

boreal scarab
#

even though it's giving me issues right now

cosmic pendant
#

what's the issue right now?

boreal scarab
#

Wont feed through. When I first bought it I could print in TPU very easily, when I feed it through now, it doesn't like it

#

Even dried it twice for about 10 hours, and it still didn't like it

cosmic pendant
#

darn

boreal scarab
#

Lemme try now, see if it likes it at all now

boreal scarab
cosmic pendant
#

yay

boreal scarab
cosmic pendant
#

nice!

#

TPU is what alot of military gear is made out of

summer orbit
boreal scarab
#

46 min for a squishy small dice, since it has to print slow

#

Lovely

cosmic pendant
#

if it's really hard, nothing

#

otherwise, give me some radio hits (i'm old okay)

boreal scarab
summer orbit
summer orbit
boreal scarab
#

Can never go wrong with Dual Core

summer orbit
#

love me some nerdcore

cosmic pendant
#

I was jamming out to Sisqo this morning πŸ˜„

summer orbit
#

damn i hadnt heard dual core yet but lovin their flow

#

thanks @boreal scarab

twin ridgeBOT
#

Gave +1 Rep to @boreal scarab (current: #28 - 354)

cosmic pendant
#

Prusa XL ?

boreal scarab
boreal scarab
sturdy raptor
ionic stone
#

hi

sturdy raptor
ionic stone
sturdy raptor
#

me too

#

/j

ionic stone
#

I don't know what that does lol

crystal mauve
#

What’s the meaning of the word suite in computer context ?

summer orbit
desert shuttle
#

tomato tomato

crystal mauve
#

Ahh makes sense thank you @summer orbit

twin ridgeBOT
#

Gave +1 Rep to @summer orbit (current: #1842 - 2)

boreal scarab
#

@cosmic pendant Squishy dice!

#

Yes, I know it's low photo quality, best I can do.

#

And yes, it did fuck up down at the bottom, it was building on itself and it kept moving around

umbral bay
#

πŸ‘‹

summer orbit
umbral bay
summer orbit
umbral bay
summer orbit
#

F no gif perms

#

can i have admin rights for like 2 seconds so i can post the gif

deft quarry
celest dirge
storm smelt
#

Not sure if @ripe cedar is zieglers who made all the XDR and Sentinel rooms, but thank you and thank you THM! Fun stuff

twin ridgeBOT
#

Gave +1 Rep to @ripe cedar (current: #2807 - 1)

summer orbit
#

thanks @celest dirge

twin ridgeBOT
#

Gave +1 Rep to @celest dirge (current: #593 - 10)

celest dirge
spice otter
#

does anyone have a nice checklist for bug bounties

summer orbit
twin ridgeBOT
#

Gave +1 Rep to @summer orbit (current: #1398 - 3)

summer orbit
#

portswigger logo is a side profile of a smiling person cant convince me otherwise

spice otter
#

oh 100%

deft quarry
#

For people who had pretty much no experience before THM, how long did it take you to feel confident doing the easy challenges without much googling

spice otter
#

2 years πŸ‘€

deft quarry
#

I feel like after 3 months I'm on the right track for the challenges, but I'll always get stuck and in the walkthrough they'll use a tool I haven't learned about yet

#

But I also only just finished the Intro to Web Hacking topic\

spice otter
deft quarry
#

yeah

#

I have a lot of time to devote to THM since I’m just working part time and then going to college in Fall

#

So I’ve been moving up pretty quickly, but once I got into jr pen tester I started watching videos to better understand the info

#

Cause there’s so much

spice otter
#

yea im a little over a month in THM and im like 95% done with cyber 101, this has taken over my college work i always wait till the last minute to do that now...

deft quarry
#

lmaoo I was debating not even doing college and just trying to get by with certs and whatnot but

#

In the end I think I still wanna do college

spice otter
#

from what i was seeing most jobs will take off how ever many years of experience that ask for depending on if you have a degree or not

#

so it seems kinda worth it

deft quarry
#

Yeah and it seems almost necessary for the more senior roles so yeah I agree

spice otter
#

and then just try to get a few interns going will in college

deft quarry
#

and the uni I plan on transferring to after getting my Associates has an amazing work-study program

#

So I'll be able to get some experience too

spice otter
#

oo that seems cool

#

wish mine did that 😦

rich zenith
#

I am 100 days in but I work 2 weeks out of the month so I can do 2 hours a day on the days I work, but when I am off, I sometimes go 12 to 18 hours a day on thm! I feel like by the end of the year I might have somewhat of an idea on what to do.

spice otter
#

12 to 18 hours πŸ˜…

deft quarry
#

I think the most I'll do is 3-5 hours in one day

spice otter
#

dang im rocking 7-8

#

hours

rich zenith
#

The pain for a dead end job is so real real, I force myself to work harder here than I do at my job!!! I figured I should work harder for something that will pay off based on something that can lead to growth...

spice otter
#

πŸ˜‚ yeaaaa work just sucks

rich zenith
#

LOL Yep!!! In my line of work, the harder you work, the more work you get to do..

deft quarry
#

Any more feels inefficient for me

modern fox
brazen coral
#

Hello everyone, I have been coding for about a year now and can no longer ignore my passions for IT and Cyber Security, wish me luck on my journey πŸ˜„

Think im going to get my A+ cert and try to find a help desk job...

#

The road will be tough, but im READY yo. Interest rates can't stop me

spice otter
crystal mauve
#

Interest rates?

celest dirge
rich zenith
#

As a matter of fact, while I am at work, I will replay Professor Messers video over and over again on my ear buds just to soak up more info on Security plus and network plus, whick are 12 hour shifts. I almost got fired for it.

crystal mauve
#

A+ isn’t that much is it

brazen coral
#

Well interest rates historically directly relate companies and their highering. Companies higher/pay on debt

deft quarry
brazen coral
deft quarry
#

I think he meant the price

#

It's like $500 for both exams I think

spice otter
brazen coral
deft quarry
#

I've heard Professor Messer's practice exams are good

spice otter
deft quarry
#

That's about the only thing worth paying for

brazen coral
#

sounds like most of you guys are in college, are you guys cybersec undergrad?

spice otter
#

im a computer science undergrad

modern fox
deft quarry
#

I'm just starting in cybersec for college yeah, but I've been doing THM for about 3 months

brazen coral
#

unrelated field!

spice otter
#

πŸ˜‚

brazen coral
#

😭

spice otter
#

what field

#

?

dark mason
#

Helllooooooo

celest dirge
brazen coral
#

I went to U of M and graduated with a business degree. I am in sales rn, looking to move

spice otter
#

ohhh

dark mason
#

How is everyone?

spice otter
#

tired, you?

deft quarry
#

I wish part time tech jobs were more common for college students lmao

rich zenith
#

Retirement isn't too far off if you think about it. Compound interest is the 8th wonder of the world. Just think, that $300,000 @ 10% return is $30,000/year. I could retire off that. Especially, if you know how to reduce your exspenses.

spice otter
brazen coral
dark mason
deft quarry
#

I plan on working part time during college but there aren't really part time tech jobs

#

just retail

brazen coral
#

30k now is not 30k in 10-15 years

spice otter
rich zenith
dark mason
deft quarry
dark mason
#

I am here one hour early

brazen coral
celest dirge
spice otter
#

especially if you can prove you know everything

brazen coral
#

for you guys in college. Just make sure you guys are nice to everyone and connect with people on linked in and be the guy everyone likes

spice otter
#

100%

deft quarry
#

I hate LinkedIn but I was able to connect with a pen tester at Comcast who gave me a lot of advice and said he'd refer me to one of their internship managers

#

So it's definitely worth it

spice otter
#

woahhh

brazen coral
#

exactly dude. you would be surprised how many people are willing to talk to you and help you. Especially if they are alumni at ur school.

spice otter
#

well good night yall 😴

rich zenith
#

The million dollar question!!!! Guy one goes to college for 4 years vs Guy number 2 who gets Security plus and network plus on first year and last three 3 years matches college student by hour of study does nothing but labs, who would get hired first??

deft quarry
#

Good night!

spice otter
deft quarry
#

^

#

The important point for the guy not in college is job experience

#

which is also very nice

rich zenith
deft quarry
#

well depends on scholarships and college

spice otter
#

everyones in debt if you think about it

#

nothing is ever free

brazen coral
#

i aint in debt

deft quarry
#

And I also just think college is a very nice life experience

#

So for me it's worth it completely

brazen coral
#

college is what u make of it, rlly is tht simple

spice otter
#

yea

rich zenith
#

I was just wondering cause when I went for auto-collision, About only 15% of my classes was pertained to auto-collision. Then I couldn't ever get hired for everyone was wanting more experience. One guy wanted 7 years experience. I often wondered if I only eliminated all other classes and just went for more experience if i would have not been better off.

#

Let me ask you this (anyone), if I go to college, and I spent 30 hours a week in college, will I learn more in college on those 30 hours a week or will I learn more if I spent 30 hours a week on labs from tryhackme, hackthebox, ITProTv ect.... I am an older guy and time is not on my side!!!

leaden marsh
#

Auto collision what is

rich zenith
#

Fixing wrecked cars

craggy wadi
# rich zenith Let me ask you this (anyone), if I go to college, and I spent 30 hours a week in...

Sounds like you know the answer already haha. If you have general education requirements then that makes it even worse. You'll hear a lot of conflicting opinions about higher ed here. My opinion is that you can learn everything for near free online that a university will teach you (about cyber). Networking with people on servers like this is a huge benefit too. People are usually more than happy to pass on info and give valuable advice in my experience.
The benefit of university is the diploma and perhaps social/collaborative aspect.

#

Universities sometimes offer internship and job placement too which of course is a huge benefit. Not sure if that justifies the time and money needed to attend though.

desert dirge
#

Other people can't afford the strict and often random scheduling of college courses, and need to study on their own due to work schedule, family, etc

rich zenith
#

I am trying to see all aspects for I hear the pro and cons of all. I once heard a man say that he learned more here in 3 months then he did for his entire 4 years of college.

pliant bronze
#

I have a doubt.. Is it possible for someone to gain 45k points in 2 days via THM rooms.?

rich zenith
#

Might as well not compete!!! Better off to dissect the rooms and strive to be the better hacker!!

pliant bronze
summer orbit
# rich zenith I am trying to see all aspects for I hear the pro and cons of all. I once heard ...

i am currently fresh in IT professionally and i can tell you that the only reason that i got a job was because i found a startup that would take anybody with a pulse. I have learned a ton in a matter of like a year and im super grateful for that but i had no experience and no certs. I have a vendor-specific cert for networking hardware now and unfortunately the particular vendor isnt cisco so it has been considerably difficult to find another, more ideal position. If you are going to do this then i would really suggest buckling down and getting DoD8570 certs like CompTIA A+, Net+, then Sec+. There is also a program that i am starting soon with Western Governors University for Cybersecurity and Information Assurance that is A) online, B) self-paced, C) less expensive the less time you take on courses, and D) provides not only a degree but also 14 industry-relevant certs by the end including the aforementioned 3.
It is going to take a lot of work and dedication but it can be done the right way

deft quarry
#

I was thinking of doing WGU, but ultimately I think I value the social aspect of conventional college more

#

But WGU seems like a very good option still

#

And it can be relatively cheap

desert dirge
# rich zenith I am trying to see all aspects for I hear the pro and cons of all. I once heard ...

Just start somewhere tbh.

  • Download a notetaking program, I use obsidian, some people use cherrytree.

  • Download Virtualbox and start labbing with Ubuntu or RHEL because of the amount of documentation that's available out there for each one. OR do THM / HTB for your labs. It really depends what you're going for first.

  • Study Linux and Networking through community documentation and certification prep books like net+ CCNA/CCNP, etc.

  • Network Labbing for CCNP / CCIE can be complex, and require a lot of system resources, so I'd follow the A+ > Net+ > Sec+ path that @summer orbit mentioned above.

I still have no certs after drooling over them for a couple years, (I think I'm scared of the exams, which is dumb lol) but I still fool around labbing and reading

deft quarry
#

Only issue is needing to use a 3rd party sync service

#

Which isn't too big of a deal

desert dirge
#

No it's not a super big deal, syncthing or cloud storage both work

heady wave
#

Should I go for the CCNA or Network + ?

desert dirge
#

Obsidians native sync service works too

rich zenith
deft quarry
#

I just use OneDrive

desert dirge
#

yea

#

Yeah, the subs add up

deft quarry
#

Yeah I already have THM and gym and one for doordash lmao

#

Don't need any more subs

summer orbit
desert dirge
#

I can afford to pay obsidian to support their good work but I haven't pulled the trigger on a sub because I wanna be sure who is reading my junk

#

dont need my files appearing somewhere in the mysterious ether that is the cloud

summer orbit
deft quarry
#

Yeah the only thing I didn't like about Obsidian is for some reason not being able to manually sort your notes/folders

#

Had to download a plugin for it

desert dirge
deft quarry
#

Hmm, did you get it more recently? I had downloaded it in like January I think and had the issue, googled it and apparently it was normal

#

Notes are tiny enough to wear I don't even have to do the $1.99 OneDrive subscription

#

I've used 0.1 out of the 5gb you get for free

#

I use SyncThing to sync my vm now though

rich zenith
#

I know that A+ should have been first!!! However, I watched an entire YouTube course on A+ and understood about 90% of it. I have started Network plus and Listened to Professor Messers 87 videos at least 5 times and started the book. Should I get A+ first before Network+ or go for Network+ first since I already have Security+ first?

deft quarry
#

A+ seems nice to get the extremely entry level jobs but it's so very boring

desert dirge
#

If you're confident enough in your knowledge, just take the exam, it will be nice to get an easy win and put your resume out there

summer orbit
finite basalt
#

There's a good roadmap hang on

deft quarry
devout palm
#

Morning

deft quarry
#

I think it's good for the entry level help desk jobs though

finite basalt
#

depending on what you're doing, this may help give you an idea of what certs you want to bother persuing

twin ridgeBOT
#

Gave +1 Rep to @finite basalt (current: #94 - 83)

desert dirge
#

i think we may have crashed the server

finite basalt
#

At the moment, I only have the AWS CP but I'll be looking to persue more security oriented certs once I've some more money coming in

deft quarry
finite basalt
#

currently working part time so don't want to be spending my money on certs haha

#

yep πŸ˜„

#

Work offered to pay for it so I said fuck it why not

rich zenith
#

Pentesting is what I was think but also I hear there's more blue team jobs out there.

deft quarry
finite basalt
#

absolutely haha, I'm actually going to be working in dev ops for the next year or two rather than security but once I've a bit more experience I'll be transitioning

rich zenith
#

Is linux+ a great cert?

finite basalt
#

Comptia is generally pretty respected but yeah it depends what line of work you're wanting to head to

rich zenith
#

Whick cert first for pentesting?

finite basalt
#

Like the AWS CP one is under security architecture and engineering, specifically cloud/sysops but I want to head more towards sec ops and either pentesting or exploitation (if we're referring to that roadmap)

devout palm
deft quarry
#

Fighting the urge to try to break into the field faster instead of going to college is so hard tbh

finite basalt
#

If you're looking at an entry level cert for cyber sec then I'd probably recommend pentest+

finite basalt
mellow narwhal
rapid merlin
#

does pentesting involve hardware and software?

finite basalt
#

so work wise it'll be an easy transition and it will pay me very nicely as a graduate haha

mellow narwhal
finite basalt
mellow narwhal
#

yeah that's true

deft quarry
#

Does anti-cheat development for games fall under the same umbrella of cybersecurity?

mellow narwhal
#

by anti-cheat, I mean secure coding practices, packing binaries, etc

devout palm
mellow narwhal
#

never heard of that

finite basalt
# devout palm Oh good luck.

thank you πŸ˜„ I'll be starting around june I reckon, although I've a flexible start date, because my current workplace work closely with my new job I won't need to worry about notice, they'll just sort of say "cool, can move whenever you're ready" (main condition being that my handover's mostly complete and that my contract at my current place won't have expired by then haha)

twin ridgeBOT
#

Gave +1 Rep to @devout palm (current: #26 - 380)

mellow narwhal
#

oh wait you mean sec+

#

nvm

#

I'd get it if there wasn't an AMF kekw

rich zenith
#

OSCP hard to get?

mellow narwhal
#

Same for any CompTIA cert

mellow narwhal
finite basalt
#

depends as well what you focus on

#

like from what I've heard OSCP is very very heavy on the AD side of things

#

so if you're an AD wizard you'll probably find it easier than someone who isn't

mellow narwhal
#

OSCP also costs a fortune

#

Which is why I'm leaning towards CPTS for my first cert

deft quarry
#

I hope to have all these certs by the time I'm done college in 4 years πŸ™

finite basalt
#

I'm looking at eventually doing PNPT for my first security focused cert

devout palm
#

I heard CRTO is harder than OSCP AD-wise

finite basalt
#

just because it's not too expensive and is still decent

mellow narwhal
finite basalt
#

anyway, I'm not sleeping tonight, I'm off for a shower and maybe a light nap on the settee

mellow narwhal
#

afaik OSCP has one AD set and three standalones

rich zenith
#

CPTS might be a great start!!??

finite basalt
#

I'm supposed to be up in 3 hours and I got up 12 hours ago so it's time to fix the sleep pattern kekw

mellow narwhal
#

plus its an eighth of the cost

devout palm
#

My crush texted me to study together

mellow narwhal
#

those three unrelateds scare me kekw

deft quarry
mellow narwhal
#

one of them will be pwn surely

#

the other two though...

finite basalt
devout palm
#

Time to explain reverse engineering with IDA

devout palm
mellow narwhal
#

I thought one of those three standalones would be buffer overflow

#

so I assumed that's in a more pwn setting

finite basalt
#

I was in the uni library and it was empty other than my mate because it was 3am, it was fucking hilarious

#

in between working we were blowing rasperries on our arms and making fart sounds kekw

devout palm
#

Lmfao

finite basalt
#

Very productive, mind you I got a shedload of work done yesterday

#

and drank 5 redbulls

mellow narwhal
#

Oh good to know lol

devout palm
mellow narwhal
#

but existing exploits are.. easy

devout palm
#

What a bummer.

I want cofffffffe

mellow narwhal
#

I thought it'd be more like craft your own POC or something

rich zenith
#

On CPTS, I heard one guy compromised all 6 machines and fail because he didn't do the report correctly.

finite basalt
#

Walked out of the shop last week when I was working on my dissertation, I walked out of that shop with 8 redbulls and a pack of jaffacakes

mellow narwhal
#

Dude, the way people talk about it... kekw

finite basalt
#

I was burnt out from uni a month in and am still chugging on. I looked in the bathroom mirror the other day and literally thought to myself because I couldn't remember where I'd been for a good week

mellow narwhal
#

yeah that makes sense

#

if you were comparing it to an HTB box, where would the actual technical difficulty of the machines lie?

devout palm
finite basalt
#

I've gone through the 5 stages of grief with this university, I actually am slightly happier now though

mellow narwhal
#

yeah I've read reviews where people say time was the most difficult thing

finite basalt
#

I complained to the head of the school about my dissertation supervisor in particular and every other little thing wrong with the course

mellow narwhal
#

checks out

finite basalt
#

and then yesterday I emailed him to say that one of our modules should be seriously reconsidered grade wise as it wasn't fair to the majority of students

#

mind you I think that'll be an after easter response

#

The stink I have kicked up about problems this year has been beautiful

finite basalt
#

Dropped some lore on the head of the school and mentioned when my dissertation supervisor turned round to a lad in a class and said "you wanna take this outside?"
his jaw dropped and I said that he needed a serious attitude adjustment, he was remarkably friendly after that

devout palm
#

I have to find an internship. Uni requires on-site. Pffs.

naive violet
finite basalt
rugged kayak
#

do u think i could get oscp with 3 months plan

cerulean aurora
#

is theri any tool or site wher i can get the site map of a website

finite basalt
#

We have an active directory assignment where half of the things you get marks for won't work whether you do it right or not because the configuration was a case of throwing shit at a wall and seeing how it stuck

#

4000 words worth 60% of the module, meanwhile last semester (the same module leader) 9000 words worth 20% of the module, meanwhile dissertation (two modules) 9500 words 40%

rugged kayak
#

15 machines omg

#

is that AD env?

finite basalt
#

I said the weighting for the assignments was completely random and made no sense and pointed out that other lecturers has said verbatim "the assignment should not have been given out in its current state"

rugged kayak
#

oh so its not 15 machines on exam

finite basalt
#

but if I pass these final modules I'm guaranteed a 2:1 and if I average 51% I get a first

#

so I want 20% minimum on this final report and I'll be fine

rugged kayak
#

ezpz i just need to sell my soul to get monies

#

noice

#

pivot after reddish ezpz

finite basalt
#

Active directory makes me irrationally angry at the minute, it's worse than DNS and it's always DNS

rugged kayak
#

@mellow narwhal have you found anyone willing to buy our souls for oscp money kekw

finite basalt
#

Setting up active directory for network auth on debian using realm and sssd is evil..

#

this is a sample of the specification we're given @naive violet they said "we don't expect you to finish it all" and I'm not surprised, there's loads of stuff that's worth basically nothing 😭

#

at one point they were asking for a samba share to be setup on linux and linked to windows active directory, ended up being changed so the smb share can be on the windows machine instead thank god

slate linden
#

good afternoon guys

finite basalt
#

morning πŸ˜„

fair linden
#

good morning

crimson phoenix
#

Hi - noob here - are they any free rooms that recommend which tools to use for bug bounty hunting like XSS and SQL injection? And if there are what are the names of the rooms?

chilly veldt
#

Time to lay in "pain" for 8 hours today

fair linden
#

good morning @jagged yarrow

crimson phoenix
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3640)

rugged kayak
mellow narwhal
#

or maybe it starts with h and ends with tb

rugged kayak
#

i will devote my life to them just lemme get the cert kekw

rugged kayak
#

no ping very busy

near sapphire
sick lance
rugged kayak
sick lance
#

There are more members than just you two in here.

shell nova
rugged kayak
sick lance
rugged kayak
#

its jover

shell nova
#

Oh dear, is it now?

rugged kayak
sick lance
#

It's a mute, if choose to ignore a moderators request and don't adhere to the rules.

sick lance
shell nova
#

Ah was missing context it seems

rugged kayak
#

i sent one message and moved on

#

bro want to mute me for existing

shell nova
#

Β―_(ツ)_/Β―

chilly veldt
#

Tattoo time!

shell nova
#

Amazing how don't be an idiot is such a hard rule to follow, eh?

rugged kayak
#

god forbid man makes joke

languid galleon
#

Hi everyone, is anyone here familar with getting a reverse shell by contaminating logs? Specifically the access.log, it's for my assignment and it's driving me crazy

shell nova
chilly veldt
#

Hopefully it's a one and done session

shell nova
sick lance
#

We can't assist you with any work or student assignments

languid galleon
#

Yes PHP

shell nova
#

Well that too, but should be easily researchable

hollow ledge
#

hi guys i have completed 70% of complete beginner path in thm they removed it should i do cyber security 101? why did they remove it

languid galleon
#

I done LFI and RFI but LFI with contaminated logs just seems impossible to do

sick lance
#

Didn't you read the rules when you joined the server?

shell nova
#

You'll need to figure this one out on your own, but you're on the right path

#

Can't help with homework

sick lance
#

Because your profile tells me you did agree to them.

#

Pay attention to number 5.

languid galleon
#

Okay if you can't help do you know a room on THM that can help

shell nova
#

You're just missing one small part, I assume you know what the logs look like

shell nova
#

Don't have the exact name

rugged kayak
#

passive aggression is off the charts today

chilly veldt
#

Did everyone get a good breakfast?

sick lance
shell nova
chilly veldt
#

Awwweee

languid galleon
chilly veldt
#

Then it's good there's a lot of time to get breakfast still

languid galleon
sick lance
rugged kayak
shell nova
fringe nacelle
shell nova
#

But whatevs

#

Overthinking will be the death of me I guess

languid galleon
twin ridgeBOT
#

Gave +1 Rep to @shell nova (current: #13 - 625)

sick lance
languid galleon
shell nova