#general
1 messages Β· Page 1015 of 1
I am currently going with the web application hacker hand book and tbh i have no one to ask my Silly question or important ones to
Sorry idk πΆβπ«οΈ
π
Why don't you learn from the interactive labs on THM?
its a tool to analyze web traffic , and find vulns , ...nothing script kiddy in that lol
π
Ok but tbh i dont know how i can lean from lab
Sorry i am with less knowledge
Just started
The lab shows you the material and then lets you practice what you're reading.
no issues i was just explaining
Hmm Understandable
Ya for now
I will come with more question tomorrow
Good night
Ya its kind a bit old but it will Clear my basic knowledge
why? no one uses burp anymore?
Huh meen like now day what do people use ?
No, as I'm the version of burp will be out of date.
What*
there r some new alternatives but ..ig people been used to burp so thats their go-to mostly
Burp gets good updates often
ahh got it
Thx for information can you plz tell me whats that thm ?
Tryhackme
Ok thx ninja and the mod good night
Can I have the role to access creators-lounge channel please?
β Gave the role Creators-Lounge to heliman.
@naive violet weird seeing you without the shield π
Womp womp.
For now.
I'm sure no services will be interrupted. They'll find a way eventually.
hey is anyone havng problem when connecting on machines??
Because CVE is a significant part of the cyber security world.
Ngl, if they can't maintain CVE I am 99% sure that offsec will take that over
it is just loading
That sounds horrible.
i like chicken
...I uh
No comment?
Can I add you?
James, thanks for the support you have given for years. I think you deserve an appreciation.
I agree, let's give him a Community Legend role π
yea
Nah, imo most likely the cvefoundation
He already has
is nessary to learn Ai in cybersecurity how to create it?
How in the world do people memorize the OSI model?
Please Do Not Throw Sausage Pizza Away
Physical, Data Link, Network, Transport, Session, Presentation, Application.
.
I hate Ai to create it because all math
i just know the Layers names memorized sequentially and some basics what each layer does, since i had this in my college a lot
but for revision i would require to go thru notes since cant memorize everything
good π
This the right question
Its nessacry for Ai ?
Please Do Not Touch Steveβs Pet Alligator
for what thing??
I suppose locating the information you need when you need it is equally as important as memorizing stuff.
Whoever touched steve's alligator:
https://tenor.com/view/combat-initiation-gif-8808243547049710258
I dont for Cybersecurity
There is a lot of information Iβm trying to absorb from Cybersecurity 101.
Thats great
... let's upload 12 gb of books =/
So that why I learn Ai
my bad, didnβt know steveβs alligator was top secret info
make notes , there will be much more stuff ahead , u wont be able to memorize each n everything , nor can i or most people here
just focus on the important stuff about it to be memorized, that should be enough
My first contribution to this server: Ai hasn't a hope of breaking cryptography. Mathematicians appreciate this. What then is its use, er social engineering maybe?
and scripting ...but still not too much but helps a lot
actually yes, it is great for putting together scripts to do stuff
Great advice I appreciate it! Iβve gotten a little overwhelmed so this is helpful.
With the right proompting, AI can be used to proompt yourself in the right direction, getting immediate answers to questions that would annoy #521382216304033796 lmao
Of course that you would follow up on with real research
yup , coz i tried that too , after learning new stuff the old learnt stuff gets rusted off the mind after few weeks if not practiced on that same type of attack/topics ,yk ..atleast for me , so i always try to make n keep make notes
I also agree with this, I think my point was about actually breaking the math used in encryption -> no chance
oh ye currently AI sucks are cryptography, kinda interesting
more like brute patience

Totally understand that. I was trying to use Linux commands in windows command line π€¦ I got so confused.
happened with me too , totally understandable π
u need to make an env first
and im trying to install a exploit from github, i need to install the requirements
i have created it
bro, i fixed, nvm
stupid things
now i get other erros, but now is about the exploit itself
I did find Linux Shells to be pretty fun though.
Yes
make sure if the code is of Python 2 or 3
so use python2 or Python3 accordingly
Running a script = hacker π
some github codes are older and they were written using python2 , and running it with py3 causes error too

Guys, I found the arson!
I see the WatchDogs logo in the background. You can't hide it from me!

i didnt notice it lol

I love you guys So much
aww love you too


Whoever hackin my f***ing work STOP NOW!!!!
I love my beer too!
some smartass in my town decide to put full UV led lights to make things looks cool, and ppl end up in hospital with eye issues =/
eh?

AND WHOEVER PHISHED ME WITH THAT FAKE XFINITY EMAIL F*** OFF
you giving out your email online?
its not this one
ya , i did that on my birthday and did THM rooms till 4AM

dedication
It's not EXACTLY that one, but it is a Watchdogs logo
yea
How they got my email is obviously because theyβre in a federal agency
you must be super ultra cool if feds get you email lol
tell?
Im using the resources to brute force in gobuster
you remembered to add the site to /etc/hosts ?
Thereβs a guy in my town who installed headlights in place of break lights on the back of his pickup truck π€¦
ya put host in /etc/hosts
lol
MURICA1
i still have to do Advent of Cyber , i'll start them next week
I havent even considered doing em but keep getting suggested to try
looks fun , with stories like scenerios
christmas be coming early this year
gotta give em a look

50 days streak 
lol welcome to engineering with vibes only
Yooo
Yo
How's it going?
fine , wby?
GREATEST COUNTRY IN THE WORLDDπ¦ π₯ πΊπΈ
chillin fr

Reads bio
PLEASE don't tell me you're CA.
that's private info
π oops Hope no one saw that, didn't mean to like myself like that
Damn
good job, now everyone DOES know xD
What is talking about?
New UAC Bypass
New task metadata poisoning
New event log buffer overflow allowing to overwrite log content and evade detection
New unprivileged security logs saturation
no answer
The wait patiently
great
Honest thoughts?
Is AI becoming more prevalent in business, healthcare etc. Going to skyrocket the need for cybersecurity professionals?
Hello Chat
Anyone here who wants to play capture the flag on thm tomorrow?
Whats your name on thm
dm me
Not exactly skyrocket
But surely will increase it
As AI is known for writing vulnerable code
hey guys a little question
i just downloaded mint linux on my virtualbox to learn linux (first time using linux) but idk what to learn or where to start can anyone give me a checklist of some sort or a yt video i can use
going to be switching to kali linux once im more comfortable with the linux environment
You guys like my sign? I thought it was witty...
I'm new too I just do onethewire bandit atm
okay and what is that
i have no idea really
There you can learn the basic linux commands
such as cd mkdir cat etc
ohokay for the terminal ig
yes
does sudo also come in that category
idk tbh i'm just at lvl 6
@rapid merlin @fair linden
https://linuxjourney.com/
Thank you π
Gave +1 Rep to @dark mason (current: #299 - 23)
thanks man
Gave +1 Rep to @dark mason (current: #293 - 24)
Hello guys
I'm new here
I've always wanted to hack
And understand programs from a deeper more, newer perspective
I just wanna also gain power
And realm the cyber security world
So abuser and malicious criminals can be put in their places
Off and on discord.
@sand trench got bunch of new wallpapers
Looks good
Have you noticed battery drain from Hyprland ?
You know that's vigilantism right?
The police don't tend to appreciate it
Someone else doing something bad doesn't mean you get to do something bad to them
Nono I'm trying to be hero here
And self defense
By put in their place meaning legal action.
Hacking back is still illegal tho
You should consult a cybersecurity specialized lawyer before you put that idea into production.
Ah
No one will know who I am isn't that the purpose
Tech is the new and next power
This ain't Hollywood
So anonymous vigilanteism that will likely cause any evidence gathered to be fruit of the poisonous tree and be inadmissable? Sounds like a terrible idea.
I dont know man I think the tism creates these nice fantasies in our heads
But then you have to ask yourself why you want to be a hero
And its for "other people"
Its really for yourself
Let him cook. Iβm sick of getting texts about unpaid toll tickets.
π€£
hi
does thm have a bbounty prog? if i was able to see paid content would thag be reportable ?
you can see paid content but you cant actually use it if that makes sense
i can see and use the creds there and interact with the labs
like if the lab is URL based uw/pw
what kind of hero complex..
Self defense
2 wrongs dont make a right in the legal world
To better understand how people could use me
Wait till I run the law
You might have the tism
Autism, nice try.
just to like clear this up you know movie hacking and real hacking is NOT the same thing
Yeah it takes steps
Movie hacking is literally typing random notesπ€£
It's outright impossible sometimes.
Anyone got an example of a domain that doesn't have WHOIS protection?
Even the baby steps about real-life ethical hacking has made me feel like an absolute caveman with technology π
Protection, as in not having its data redacted from general public records?
Sorry for the late reply,
I don't remember where but I saw a post on Twitter from the user "Dark Web Informer - Cyber Threat Intelligence" that the user message database was leaked and that it was for sale
I wouldn't say better, it's more depending on your intent of use and such.
Sadly I don't have a solid answer for you at the time, but I usually use VirtualBox more than VMWare. Personal preference though.
Exactly
@light glen Also what is the OS of your host machine
I do have to ask, is this for an assignment of some sort?
windows
I primarily use Windows.
thanks
Gave +1 Rep to @silent nova (current: #547 - 11)
do u have a problem accessing machines ??
webpages
Research, but it's alright. I remembered there's TLD's that don't support WHOIS privacy, and there's a bunch of them.
Ah, okay. Technically speaking, ICANN's own website has no "official" WHOIS privacy.
Welcome!
Can you accept request for a moment
What exactly do you need? π
You'll see, can't talk really about it here
Sure :) added
It doesn't return much info though
I'm not sure exactly what information you are looking for though, sorry.
Best of luck with your research!
Vmare better
can someone help me with a question from the MITRE room?
:hammer: johnnyangelojr._89816#0 has been banned.
R.I.P.
hi
π Welcome to TryHackMe!
Hello
just found this absolute gem
It's definitely a cool photo.
π€π€π€
... oh.
The lead singer of Meta?
I think they're muted
Does that name read what I think it does?
nice
Nice Rice!
hello π
π Welcome to TryHackMe!
thanks π
Just a reminder to everyone to use the report command in the channel that the problem is happening and not #bot-commands π
how's everyone doing?
Oops I plead guilty.

Cute cat.
Dogs > Cats
Dogs = Cats
Done!
X: https://x.com/0xTib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
Twitch: https://www.twitch.tv/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
LinkedIn: https://www.linkedin.com/in/tib3rius
Courses: https://courses.tib3rius.com
Udemy: https://www.udemy.com/user/tib3rius
Discord: https://discord.com/invite/4qrvKM...
I picked a GREAT time to get into cyber
yeaa i seen john hammands thing yesterday lol
Pretty much lol.
But I think it's all fixed now
Damn, hadn't checked the news since I got off of work. I can't deal with this roller coaster for four years.
New Ubuntu comes out tomorrow and I can finally say it's idiot-proof. This is probably the 6th time I'
the job market already shaky lol just gotta power through it
Gave +1 Rep to @gusty inlet (current: #229 - 35)
ve tried to switch but I'm finally gonna stay this time, (I switched to arch, but Ubuntu 25 is pretty dope, still)
what fixed
Common Vulnerabilities and Exposures
I was like, just my luck. I literally JUST learned eternalblue.
Hi
Hi toaster! How are you doing?
π
Doing great thanks
Currently just doing some THM rooms to get ready for CRTO
oh CRTO is really fun
Yup! You got the cert?
I don't, but it did it
I don't need anymore certs
but CRTO was the last thing I did to stay sharp π
Expired/Failed/No attempt?
Didn't attempt it
Does the voucher expire
Oh darn it
Get started on CRTO π
The badge is cool, the cert design is ugly.
You have betrayed me.
Here's you chance to also go for it : p
it was like 2 years ago
If you thought it was gone and it isn't, just go for it anyways since you weren't planning on having it
If you fail you fail whatever
I think lab time is costly
and another good day of playing control and now it is time to go sleep sloop to beep boop for meep moop
game about paranatural stuffs in a setting similar to the SCP foundation but in a shared universe with the alan wake games
I couldnβt get into it
Last puzzle like game I got into was warframe
So good for a free game
It is more of a story driven action game then a puzzle game though
Oh I thought u had to use your powers dependent on the atmosphere sorta
Bring down chandelier to kill x guys
warframe is not a puzzle game lol
I played control for a few hours, then stopped abruptly, but I can't remember why. Hitman is my jam (or WAS before THM, lol)
are AV's today fully equipped against obfuscated codes? keeping in mind that some do sandboxing and heuristics?
is there a way to hide the new echo bot lol, its taking up my screenspace π
@cosmic pendant Your expertise is needed my good sir! 
Does fully equipped mean 100%? then no
let's say windows defender
silly question but ... why not ?
The continuous increase in malware samples, both in sophistication and number, presents many challenges for organizations and analysts, who must cope with thousands of new heterogeneous samples daily. This requires robust methods to quickly determine whether a file is malicious. Due to its speed and efficiency, static analysis is the first line ...
Read tyat
then we talk
is most malware today encoded with metasploit (meaning like , is it that easy?) or is manually obfuscated
ty
Gave +1 Rep to @cosmic pendant (current: #44 - 217)
I can't wait to get into advanced evasion and maldev after CRTO.
I'll probably go for the CETP or some Sektor 7 courses.
me on my way to learn malware scripting in assembly:
CRTO2
section .data
hello db 'Hello, world!', 0xA ; string + newline
hello_len equ $ - hello ; length of the string
section .text
global _start
_start:
; syscall: write(int fd, const void *buf, size_t count)
mov eax, 4 ; syscall number for sys_write (4)
mov ebx, 1 ; file descriptor 1 = stdout
mov ecx, hello ; pointer to message to write
mov edx, hello_len ; message length
int 0x80 ; make syscall
; syscall: exit(int status)
mov eax, 1 ; syscall number for sys_exit (1)
xor ebx, ebx ; return code 0
int 0x80 ; make syscall
NASM
Saw the syllabus, but what if I tell you to take a look at these:
- https://www.alteredsecurity.com/evasionlab (Check the what will you learn section)
- https://training.whiteknightlabs.com/certifications/offensive-development-practitioner-certification/ (Evasion for CrowdStrike, Elastic, Carbon Black etc... scroll down to see)
These go WAY beyond what CRTOII offers.
i mean there is a basic piece of code consisting of 2 lines which is practically malware lol but i won't say it here ofc
Cool, but one step at a time π
CRTO > CRTO 2 > More whatever
im gonna hit an uno reverse with a minecraft java exloit while watching the minecraft movie
we are not the same 
funny thing i caught some minecraft kids selling some bs which was actually a RAT lmfao
i still have the obfuscated java code in .txt file here
wait wtf lmao
Wahoo
But you didn't really argument on why you are recommending RTO II before more of whatever?
CETP starts advanced evasion from scratch, so even someone who knows nothing to evasion can go from beginner to advanced (Covers a lot)
I'd like to know why you think RTO II would be a better fit
i'm trying to analyze the obfuscated code but it's making no sense
crazy sh
Well i'm a big fan, and you have to learn it anyway
Writing the best 'malware' aka tooling doesn't matter if you can't operate
Hmmm I kind of see where you're coming from
were they trying to sell it off as some cheats or was it embedded in something dumb like a mod or skin file?
it was a minecaft mod lol i reverse engineered it and found out it was a fucking RAT
with their shitty code
Don't wanna be that guy but this is a huge wall of text lol
rip the big wall of text
ECC RAM?
Error correction code memory (ECC memory) is a type of computer data storage that uses an error correction code (ECC) to detect and correct n-bit data corruption which occurs in memory.
Typically, ECC memory maintains a memory system immune to single-bit errors: the data that is read from each word is always the same as the data that had been wr...
Any competitions happening soon?
Researchers have calculated the quantum computer size necessary to break 256-bit elliptic curve public-key cryptography: Finally, we calculate the number of physical qubits required to break the 256-bit elliptic curve encryption of keys in the Bitcoin network within the small available time frame in which it would actually pose a threat to do so...
Ok
What would I do? Nothing. I'm ethical. lol
U must have not done the puzzle rooms
ok ok, 1 for every 100 π
Can I have the role to access creators-lounge channel please?
isn't that just the 4 keys that give you a debuff in lua?
Drift mods were the shiet n so hard to get
or am i thinking of something else
are you a creator
yes
maybe try dming jaba
Itβs been so long I donβt even remember which 1 I used in my build
bros casually asking someone to commit a felony
what the hell
mabois discord name is emoji bob
It puts the lotion on the skin or it gets the π again
report it to the police
Nope
Melon didnt know u grinded the shit out of thm what the skibidi
I did before i went over to htb
- We are not hackers for hire.
- This discord is for https://www.tryhackme.com , an ETHICAL hacking teaching site.
- We do NOT condone, nor do we even break laws here.
Fuck that Gen Alpha slang
Don't forget to take SAL1 and advance to your PEN15 cert later
party time
I get phished everyday on steam. Their attempts are SOOOOO pitiful.
"Here's a free giftcard, can you like my skin I totally made?"
I like accepting random people, seeing their attempts lol
Im about to complete my 32nd education room and im working on my net+ but I still feel dumber than a rock. Anyone else feel this way?
As long as there's no PII of yours like your name or email, all good to send π
yea ima edit that out
If ya wanna DM me you can π
Get attribution π
im about to post it here for the lolz. hopefully someone catches the bastards. got my password and CC info.. autofilled it with apple pay lmao
"forthcoming"
yea, im a dumbass, i get it
thats insane
π
Troy Hunt Got phished
It happens @modest thicket. Just gotta take a lesson from it and try to fight the complacency that we all get sometimes.
well.. maybe im not too much of a dumbass after all
I was just in a rush tbh.. was in the middle of working and thought i legit didnt pay my bill lmao
that's all it takes
did your email filter not pick it up? I cant imagine it being a warmed up domain.
i guess not
looool hopefully your bank can decline the transaction or you can let them know just in case or pause your card
thankfully nothing was charged, i canceled my card immediately
wait
nice tbh they getting smarter with it not yoyr fault you not stupid at all
did you say it autofilled?
yes
Helloo
if you have a sandbox you'd like to play with it in, ill DM it to you
yh cant lie that is a problem
ok, what is VT? im quite new to this honestly
virustotal
Browserling is the best, easy sandbox IMO
I like to mess with phishers sites by spamming em with bogus creds π
Time to have some fun on Browserling!

I get brought to a QR code generator....
confused noises
Mind DMing me the link?
sure thing
im really not interested in going there myself but would love to see a screenshot
Just random redirects
in my ios it redirected me to like 5 different websites before i got to the payment page, which looked exactly like xfinitys
also, i replied to the email for shids and giggles with a congratulatory message, commending the bastards, and this was what i got in response.. not sure if this is normal or not.
lol, you may get a disclsoure
you should delete that
they may have an open mail relay
delete it from my mailbox?
from teh chat
or like my sent mail?
reach out to @boreal scarab he'll help you research that domain
you may want to reach out to an admin in that district
ok thank you!
Gave +1 Rep to @cosmic pendant (current: #44 - 218)
hope some good comes from it
thank you!
broken comm system i try to do good things
Top, my two cents is still anything Creality, but a lot of people think Bambu... but screw those guys
creality is top tier consumer?
IMO
I don't have any problems so far (it's my dads)
I'm looking at one
if I wanted to spend more money
what would you get?
let's say 3k
You're probably in semi-commercial at that price
3k? Ultimaker is reputable, been around for a VERY long time
My Ender 3 V3 Plus can do that 
is that good or bad?
even though it's giving me issues right now
what's the issue right now?
Wont feed through. When I first bought it I could print in TPU very easily, when I feed it through now, it doesn't like it
Even dried it twice for about 10 hours, and it still didn't like it
darn
Lemme try now, see if it likes it at all now
Was a fluke, it's feeding again properly
yay
I'm making a squishy DND dice!
what do yall listen to while studying?
https://www.youtube.com/watch?v=O9Y1sEmyymw
depends what and how hard
if it's really hard, nothing
otherwise, give me some radio hits (i'm old okay)
https://open.spotify.com/playlist/6nIqtkcH3A5T2TlKLeklU0
I usually listen to this playlist. Gets me in the mood
oshi i see daft punk, crystal method, the prodigy... some OG stuff
tru tru sometimes material requires complete focus
If you REALLY want to get in the mood, https://open.spotify.com/artist/7tiEDqYPwBHFd5LBWRFK4U
Can never go wrong with Dual Core
love me some nerdcore
I was jamming out to Sisqo this morning π
Gave +1 Rep to @boreal scarab (current: #28 - 354)
Prusa XL ?
Welcome!
Never had a Prusa, so can't speak on it
hi

Whatβs the meaning of the word suite in computer context ?
a suite is a collection of resources or related programs needed to create a comprehensive solution for a task i.e. the microsoft 365 or microsoft office suite
tomato tomato
Ahh makes sense thank you @summer orbit
Gave +1 Rep to @summer orbit (current: #1842 - 2)
@cosmic pendant Squishy dice!
Yes, I know it's low photo quality, best I can do.
And yes, it did fuck up down at the bottom, it was building on itself and it kept moving around
π
whoa its the tool man
The One and Only. π
from the back yard to backdoors huh?
Frontdoors too. π
F no gif perms
can i have admin rights for like 2 seconds so i can post the gif

I don't want to level up and lose my role color save me π
So basically, all you have to do is like, verify, then BAM, Giga Chad gif perms.
Not sure if @ripe cedar is zieglers who made all the XDR and Sentinel rooms, but thank you and thank you THM! Fun stuff
Gave +1 Rep to @ripe cedar (current: #2807 - 1)
Gave +1 Rep to @celest dirge (current: #593 - 10)
You are welcome.
does anyone have a nice checklist for bug bounties
thank you π
Gave +1 Rep to @summer orbit (current: #1398 - 3)
portswigger logo is a side profile of a smiling person cant convince me otherwise
oh 100%
For people who had pretty much no experience before THM, how long did it take you to feel confident doing the easy challenges without much googling
2 years maybe π
2 years π
I feel like after 3 months I'm on the right track for the challenges, but I'll always get stuck and in the walkthrough they'll use a tool I haven't learned about yet
But I also only just finished the Intro to Web Hacking topic\
are you doing jr pen test pathway?
yeah
I have a lot of time to devote to THM since Iβm just working part time and then going to college in Fall
So Iβve been moving up pretty quickly, but once I got into jr pen tester I started watching videos to better understand the info
Cause thereβs so much
yea im a little over a month in THM and im like 95% done with cyber 101, this has taken over my college work i always wait till the last minute to do that now...
lmaoo I was debating not even doing college and just trying to get by with certs and whatnot but
In the end I think I still wanna do college
from what i was seeing most jobs will take off how ever many years of experience that ask for depending on if you have a degree or not
so it seems kinda worth it
Yeah and it seems almost necessary for the more senior roles so yeah I agree
and then just try to get a few interns going will in college
yea
and the uni I plan on transferring to after getting my Associates has an amazing work-study program
So I'll be able to get some experience too
I am 100 days in but I work 2 weeks out of the month so I can do 2 hours a day on the days I work, but when I am off, I sometimes go 12 to 18 hours a day on thm! I feel like by the end of the year I might have somewhat of an idea on what to do.
12 to 18 hours π
I think the most I'll do is 3-5 hours in one day
The pain for a dead end job is so real real, I force myself to work harder here than I do at my job!!! I figured I should work harder for something that will pay off based on something that can lead to growth...
π yeaaaa work just sucks
LOL Yep!!! In my line of work, the harder you work, the more work you get to do..
I find it easier to retain information if I sit on only 1/2 topics a day
Any more feels inefficient for me
Hello everyone, I have been coding for about a year now and can no longer ignore my passions for IT and Cyber Security, wish me luck on my journey π
Think im going to get my A+ cert and try to find a help desk job...
The road will be tough, but im READY yo. Interest rates can't stop me
really? to me its more like if the rooms match up and all are kinda related then it just clicks
Interest rates?
thats called debt
Something I haven't run into yet while in college
As a matter of fact, while I am at work, I will replay Professor Messers video over and over again on my ear buds just to soak up more info on Security plus and network plus, whick are 12 hour shifts. I almost got fired for it.
A+ isnβt that much is it
Well interest rates historically directly relate companies and their highering. Companies higher/pay on debt
I mean I could do more and retain the info still but I'm just starting college so I'm not really in a rush anyways
nope not at all! But gotta start somewhere
truye true cant tire yourself just yet
niceeee
yeah about $500. Plus i think i will pay around $100 for other resources/practice exams
I've heard Professor Messer's practice exams are good
thought about doing that while i sleep but ehhh
That's about the only thing worth paying for
sounds like most of you guys are in college, are you guys cybersec undergrad?
im a computer science undergrad
there is like comptia premium partners and so they selling discounted vouchers like u can buy 2 exams for 400
I'm just starting in cybersec for college yeah, but I've been doing THM for about 3 months
awesome yo. I graduted college about 1.5years ago
unrelated field!
π
π
Helllooooooo
Hello
I went to U of M and graduated with a business degree. I am in sales rn, looking to move
ohhh
How is everyone?
tired, you?
I wish part time tech jobs were more common for college students lmao
Retirement isn't too far off if you think about it. Compound interest is the 8th wonder of the world. Just think, that $300,000 @ 10% return is $30,000/year. I could retire off that. Especially, if you know how to reduce your exspenses.
yessss it would be so nice
Depends too much. You have to adjust for iinflation. This is what I do for a living rn.
Just woke up, rn I am in class
I plan on working part time during college but there aren't really part time tech jobs
just retail
30k now is not 30k in 10-15 years
shouldn't you be paying attnetion π
help desk
Some cash flowing assets adjust to inflation!!!!
It hasn't started yet
part time help desk jobs seem hella rare
I am here one hour early
best buy has some good oppertunities. You can see if u can help at geek squad or something. If all you want is expirence in anything
Literally my plan for the summer. I plan on applying to some IT support and Information Security internships/part-time.
honestly as long as you let them know your in school they should be lenient and acomadating
especially if you can prove you know everything
for you guys in college. Just make sure you guys are nice to everyone and connect with people on linked in and be the guy everyone likes
100%
I hate LinkedIn but I was able to connect with a pen tester at Comcast who gave me a lot of advice and said he'd refer me to one of their internship managers
So it's definitely worth it
woahhh
exactly dude. you would be surprised how many people are willing to talk to you and help you. Especially if they are alumni at ur school.
well good night yall π΄
The million dollar question!!!! Guy one goes to college for 4 years vs Guy number 2 who gets Security plus and network plus on first year and last three 3 years matches college student by hour of study does nothing but labs, who would get hired first??
Good night!
thats assuming the guy in college just wasted all his time though, if they were smart they would try to get certs and labs done along with there college
^
The important point for the guy not in college is job experience
which is also very nice
And how much in student loan debt would one be in???
well depends on scholarships and college
i aint in debt
And I also just think college is a very nice life experience
So for me it's worth it completely
college is what u make of it, rlly is tht simple
yea
I was just wondering cause when I went for auto-collision, About only 15% of my classes was pertained to auto-collision. Then I couldn't ever get hired for everyone was wanting more experience. One guy wanted 7 years experience. I often wondered if I only eliminated all other classes and just went for more experience if i would have not been better off.
Let me ask you this (anyone), if I go to college, and I spent 30 hours a week in college, will I learn more in college on those 30 hours a week or will I learn more if I spent 30 hours a week on labs from tryhackme, hackthebox, ITProTv ect.... I am an older guy and time is not on my side!!!
Auto collision what is
Fixing wrecked cars
Great
Sounds like you know the answer already haha. If you have general education requirements then that makes it even worse. You'll hear a lot of conflicting opinions about higher ed here. My opinion is that you can learn everything for near free online that a university will teach you (about cyber). Networking with people on servers like this is a huge benefit too. People are usually more than happy to pass on info and give valuable advice in my experience.
The benefit of university is the diploma and perhaps social/collaborative aspect.
Universities sometimes offer internship and job placement too which of course is a huge benefit. Not sure if that justifies the time and money needed to attend though.
College is definitely a big boon. I would put it to your circumstances and your learning style, and how well you know yourself.
Some people NEED that push, knowing that there are external forces (deadlines and exams) that they need to be prepared for to be successful
Other people can't afford the strict and often random scheduling of college courses, and need to study on their own due to work schedule, family, etc
Very great points!!! Perhaps a man can get into IT with some certs, start off as help desk, then use platforms such as this to build skill, maybe one could do an online college, while jugging all of the other task!!!!
I am trying to see all aspects for I hear the pro and cons of all. I once heard a man say that he learned more here in 3 months then he did for his entire 4 years of college.
I have a doubt.. Is it possible for someone to gain 45k points in 2 days via THM rooms.?
They are 100000000% cheating
Might as well not compete!!! Better off to dissect the rooms and strive to be the better hacker!!
Even If we take a single person cheating the rooms via walkthrough, it still can't be possible. As we have to take the Rest/Sleep/Food/Eye Strain..
i am currently fresh in IT professionally and i can tell you that the only reason that i got a job was because i found a startup that would take anybody with a pulse. I have learned a ton in a matter of like a year and im super grateful for that but i had no experience and no certs. I have a vendor-specific cert for networking hardware now and unfortunately the particular vendor isnt cisco so it has been considerably difficult to find another, more ideal position. If you are going to do this then i would really suggest buckling down and getting DoD8570 certs like CompTIA A+, Net+, then Sec+. There is also a program that i am starting soon with Western Governors University for Cybersecurity and Information Assurance that is A) online, B) self-paced, C) less expensive the less time you take on courses, and D) provides not only a degree but also 14 industry-relevant certs by the end including the aforementioned 3.
It is going to take a lot of work and dedication but it can be done the right way
I was thinking of doing WGU, but ultimately I think I value the social aspect of conventional college more
But WGU seems like a very good option still
And it can be relatively cheap
thats what i have you guys for
Just start somewhere tbh.
-
Download a notetaking program, I use obsidian, some people use cherrytree.
-
Download Virtualbox and start labbing with Ubuntu or RHEL because of the amount of documentation that's available out there for each one. OR do THM / HTB for your labs. It really depends what you're going for first.
-
Study Linux and Networking through community documentation and certification prep books like net+ CCNA/CCNP, etc.
-
Network Labbing for CCNP / CCIE can be complex, and require a lot of system resources, so I'd follow the A+ > Net+ > Sec+ path that @summer orbit mentioned above.
I still have no certs after drooling over them for a couple years, (I think I'm scared of the exams, which is dumb lol) but I still fool around labbing and reading
I love Obsidian
Only issue is needing to use a 3rd party sync service
Which isn't too big of a deal
No it's not a super big deal, syncthing or cloud storage both work
Should I go for the CCNA or Network + ?
Obsidians native sync service works too
I have SYO-701 Security+ and a very good work ethic!!!! I am working on Network+ and the hours on labs are crazy amounts of hours I am doing. For instance, I read the CompTIA Security plus cover-to-cover twice. Listened to Professor Messers 121 videos 10 times while at work. I am 100 days in with almost 200 rooms completed!!!! Surly that is enough to get my foot in the door somewhere!!!
Yeah that one is paid though I think
I just use OneDrive
cheers sounds like youre doin the thing. Keep rockin then and get your resume/cv together and start shooting it off
I can afford to pay obsidian to support their good work but I haven't pulled the trigger on a sub because I wanna be sure who is reading my junk
dont need my files appearing somewhere in the mysterious ether that is the cloud
depends on what jobs youre lookin at. if you find that CCNA is a requirement for positions you're interested in then grab it, but not every employer is going to use cisco
Yeah the only thing I didn't like about Obsidian is for some reason not being able to manually sort your notes/folders
Had to download a plugin for it
whatttttt! I can do this right out of the box on ubuntu
Hmm, did you get it more recently? I had downloaded it in like January I think and had the issue, googled it and apparently it was normal
Notes are tiny enough to wear I don't even have to do the $1.99 OneDrive subscription
I've used 0.1 out of the 5gb you get for free
I use SyncThing to sync my vm now though
I know that A+ should have been first!!! However, I watched an entire YouTube course on A+ and understood about 90% of it. I have started Network plus and Listened to Professor Messers 87 videos at least 5 times and started the book. Should I get A+ first before Network+ or go for Network+ first since I already have Security+ first?
A+ seems nice to get the extremely entry level jobs but it's so very boring
If you're confident enough in your knowledge, just take the exam, it will be nice to get an easy win and put your resume out there
A lot of jobs that i've seen only require one of the DoD 8570 certs to be considered but given the competitive nature of the market always and particularly now I would definitely recommend getting more certs under your belt
There's a good roadmap hang on
Eh, considering I'm going to college and not actively job searching I don't think the $500 is worth it
Morning
I think it's good for the entry level help desk jobs though
depending on what you're doing, this may help give you an idea of what certs you want to bother persuing
Thanks!!
Gave +1 Rep to @finite basalt (current: #94 - 83)
i think we may have crashed the server
At the moment, I only have the AWS CP but I'll be looking to persue more security oriented certs once I've some more money coming in
Yeah lmfao
currently working part time so don't want to be spending my money on certs haha
yep π
Work offered to pay for it so I said fuck it why not
Pentesting is what I was think but also I hear there's more blue team jobs out there.
Best cert is a free one
absolutely haha, I'm actually going to be working in dev ops for the next year or two rather than security but once I've a bit more experience I'll be transitioning
Is linux+ a great cert?
Comptia is generally pretty respected but yeah it depends what line of work you're wanting to head to
Whick cert first for pentesting?
Like the AWS CP one is under security architecture and engineering, specifically cloud/sysops but I want to head more towards sec ops and either pentesting or exploitation (if we're referring to that roadmap)
Why not directly cyber like SOC Analyst or sum?
Fighting the urge to try to break into the field faster instead of going to college is so hard tbh
If you're looking at an entry level cert for cyber sec then I'd probably recommend pentest+
I did an internship with my current job and am technically going to be working under another region associated with them
sec+ is more entry level I think
does pentesting involve hardware and software?
so work wise it'll be an easy transition and it will pay me very nicely as a graduate haha
software most of the time
Oh good luck.
depends what you're after, security+ is more about security and risk management, it's more general purpose, pentest+ is obviously more specialised around pentesting, so depends massively
yeah that's true
Does anti-cheat development for games fall under the same umbrella of cybersecurity?
yeah, game developers do this
by anti-cheat, I mean secure coding practices, packing binaries, etc
Yeah but It mostly requires demonstration of skills via blogs, tools, foundings etc.
never heard of that
thank you π I'll be starting around june I reckon, although I've a flexible start date, because my current workplace work closely with my new job I won't need to worry about notice, they'll just sort of say "cool, can move whenever you're ready" (main condition being that my handover's mostly complete and that my contract at my current place won't have expired by then haha)
Gave +1 Rep to @devout palm (current: #26 - 380)
OSCP hard to get?
Same for any CompTIA cert
Depends on your skill level
depends as well what you focus on
like from what I've heard OSCP is very very heavy on the AD side of things
so if you're an AD wizard you'll probably find it easier than someone who isn't
OSCP also costs a fortune
Which is why I'm leaning towards CPTS for my first cert
I hope to have all these certs by the time I'm done college in 4 years π
I'm looking at eventually doing PNPT for my first security focused cert
I heard CRTO is harder than OSCP AD-wise
just because it's not too expensive and is still decent
Probably would be. You don't need evasion/persistence/whatnot in OSCP
anyway, I'm not sleeping tonight, I'm off for a shower and maybe a light nap on the settee
afaik OSCP has one AD set and three standalones
CPTS might be a great start!!??
I'm supposed to be up in 3 hours and I got up 12 hours ago so it's time to fix the sleep pattern 
people say its harder than the OSCP, but the time constraint is much better
plus its an eighth of the cost
My crush texted me to study together
those three unrelateds scare me 
W
hell yeah man π enjoy!!
Time to explain reverse engineering with IDA
Ahahahha jk
I thought one of those three standalones would be buffer overflow
so I assumed that's in a more pwn setting
I was in the uni library and it was empty other than my mate because it was 3am, it was fucking hilarious
in between working we were blowing rasperries on our arms and making fart sounds 
Lmfao
Very productive, mind you I got a shedload of work done yesterday
and drank 5 redbulls
Oh good to know lol
Ooh I can't be caffeinated. It goes crazy with meds.
but existing exploits are.. easy
What a bummer.
I want cofffffffe
I thought it'd be more like craft your own POC or something
On CPTS, I heard one guy compromised all 6 machines and fail because he didn't do the report correctly.
Walked out of the shop last week when I was working on my dissertation, I walked out of that shop with 8 redbulls and a pack of jaffacakes

Dude, the way people talk about it... 
ahh that's fair man, I think caffeine is the only thing keeping me sane rn
I was burnt out from uni a month in and am still chugging on. I looked in the bathroom mirror the other day and literally thought to myself because I couldn't remember where I'd been for a good week
Report needs to be professional
yeah that makes sense
if you were comparing it to an HTB box, where would the actual technical difficulty of the machines lie?
Oh man, you are worth more than everything else. Hope you get better soon.
I've gone through the 5 stages of grief with this university, I actually am slightly happier now though
yeah I've read reviews where people say time was the most difficult thing
I complained to the head of the school about my dissertation supervisor in particular and every other little thing wrong with the course
checks out
and then yesterday I emailed him to say that one of our modules should be seriously reconsidered grade wise as it wasn't fair to the majority of students
mind you I think that'll be an after easter response
The stink I have kicked up about problems this year has been beautiful
Dropped some lore on the head of the school and mentioned when my dissertation supervisor turned round to a lad in a class and said "you wanna take this outside?"
his jaw dropped and I said that he needed a serious attitude adjustment, he was remarkably friendly after that
I have to find an internship. Uni requires on-site. Pffs.
Ngl that's how I got put in touch with my pentest job
seriously? do unis just have a thing for making shite modules π
do u think i could get oscp with 3 months plan
is theri any tool or site wher i can get the site map of a website
We have an active directory assignment where half of the things you get marks for won't work whether you do it right or not because the configuration was a case of throwing shit at a wall and seeing how it stuck
4000 words worth 60% of the module, meanwhile last semester (the same module leader) 9000 words worth 20% of the module, meanwhile dissertation (two modules) 9500 words 40%
I said the weighting for the assignments was completely random and made no sense and pointed out that other lecturers has said verbatim "the assignment should not have been given out in its current state"
oh so its not 15 machines on exam
but if I pass these final modules I'm guaranteed a 2:1 and if I average 51% I get a first
so I want 20% minimum on this final report and I'll be fine
Active directory makes me irrationally angry at the minute, it's worse than DNS and it's always DNS
@mellow narwhal have you found anyone willing to buy our souls for oscp money 
Setting up active directory for network auth on debian using realm and sssd is evil..
this is a sample of the specification we're given @naive violet they said "we don't expect you to finish it all" and I'm not surprised, there's loads of stuff that's worth basically nothing π
at one point they were asking for a samba share to be setup on linux and linked to windows active directory, ended up being changed so the smb share can be on the windows machine instead thank god
good afternoon guys
morning π
good morning
Hi - noob here - are they any free rooms that recommend which tools to use for bug bounty hunting like XSS and SQL injection? And if there are what are the names of the rooms?
Time to lay in "pain" for 8 hours today
good morning @jagged yarrow
Burp is an industry standard.
Ok thank you!
Gave +1 Rep to @sick lance (current: #2 - 3640)
maybe 
does his name starts with d and ends with evil
maybe it starts with o and ends with ffsec

or maybe it starts with h and ends with tb
fr they should accept payment in kidneys or something like that
i will devote my life to them just lemme get the cert 
Just get a job
Ping
Let's not be rude and disrespectful please.
bit of banter with good friend cant hurt no one, context matters
New members might not see it that way.
Please keep it civil, or not in this server.
There are more members than just you two in here.
The double negation does make this statement true π
This is pointless.
You agreed to adhere to the rules whilst you're here.
its jover
Oh dear, is it now?
yep π
It's a mute, if choose to ignore a moderators request and don't adhere to the rules.
Wrong window?
lmao what
Nope, correct window.
Just pointing it out since my last message was disregarded.
Ah was missing context it seems
Β―_(γ)_/Β―
Tattoo time!
Amazing how don't be an idiot is such a hard rule to follow, eh?
god forbid man makes joke
Hi everyone, is anyone here familar with getting a reverse shell by contaminating logs? Specifically the access.log, it's for my assignment and it's driving me crazy
Glhfdd
Thanku thanku, 8 hours today
Hopefully it's a one and done session
It's a pretty classic case, I'm assuming PHP?
We can't assist you with any work or student assignments
Yes PHP
Well that too, but should be easily researchable
hi guys i have completed 70% of complete beginner path in thm they removed it should i do cyber security 101? why did they remove it
I done LFI and RFI but LFI with contaminated logs just seems impossible to do
Old content.
Obsolete
Keep trying
Didn't you read the rules when you joined the server?
You'll need to figure this one out on your own, but you're on the right path
Can't help with homework
Because your profile tells me you did agree to them.
Here is a refresh #rules
Pay attention to number 5.
Okay if you can't help do you know a room on THM that can help
You're just missing one small part, I assume you know what the logs look like
Should be rooms on lfi
Don't have the exact name
passive aggression is off the charts today
Did everyone get a good breakfast?
Like this comment?
Sadly no π¦
Awwweee
when i do nc with the target ip and port 80 (OWASP DVWA) i get a http 400 bad request I was told that is okay but getting a reverse shell using burpsuite / php payload wasn't working
Then it's good there's a lot of time to get breakfast still
Ikr
Try a simpler payload
Please stop assisting them. π
dont you have anything else better to do than bully me over one message π
I'm not giving answers

Okay thank you I'll try that
Gave +1 Rep to @shell nova (current: #13 - 625)
Not after today it won't
Bro chill
Is the deadline looming?

