#general

1 messages ยท Page 1040 of 1

static acorn
#

blahhhh. if im doing it, im doing it manually. thats the fun of arch

#

(which im not lol)

rapid merlin
#

yep

#

its more stable imo

knotty valve
#

I just slap on fedora and call it a day

desert dirge
#

Yeah, the archinstall script kind of annoys me too, but only because I can't be 100% sure what's going on

knotty valve
#

I can't be bothered having to manually go through a bunch of stuff or manually configure SEL

#

So I just throw fedora on it and it's secure by default

static acorn
#

maybe one day ill give arch a go in vm and try to install it manually.

#

could be fun

desert dirge
knotty valve
#

I've got arch running on a partition of my blackbox pc

desert dirge
#

Then donate it back to the thrift store with barebones arch on it, let somebody else have a nightmare

static acorn
#

why a cheap one? is there potential for damaging components if i install it wrong XD

knotty valve
#

But the main OS it's running is Fedora's security suite

static acorn
#

i didnt think so lol

knotty valve
#

It's Linux, you have more access to lower systems than you do on windows

blissful snow
#

hi

knotty valve
#

Hi

blissful snow
#

hru

static acorn
knotty valve
#

Tired

static acorn
#

oh shi- thats a duck mb

blissful snow
rapid merlin
#

hhfgcthgcbfdtm

knotty valve
blissful snow
#

u good lol

blissful snow
knotty valve
#

Cause I did the funny at work: said it was a quiet day

#

And everything decided to break down

blissful snow
#

whats the funny

static acorn
#

smh

knotty valve
static acorn
#

should have known

knotty valve
#

Oh I did know

#

That's why I said it

blissful snow
#

ohhh

rapid merlin
#

๐Ÿค”

knotty valve
#

Ain't no way am I spending 4-5 hours doing basically nothing

desert dirge
#

I had my laptop with windows on it in storage for a little while.

Somebody picked the lock to my storage unit and stole my laptop. It had all my school stuff and passwords (I was dumber then)

Now every now and then I get login attempts on my emails from random computers all over the U.S. at least 2-3x/year.

Now I use linux, encrypt my files, and use keepass

static acorn
rapid merlin
#

no password manager? all in notepad?!

#

๐Ÿ˜ญ

knotty valve
desert dirge
rapid merlin
#

passwords.txt

knotty valve
#

I use it for all my mnemonic codes

rapid merlin
#

๐Ÿ˜ญ

static acorn
#

passwords.txt goes hard lmao

knotty valve
#

But everything else is stored in my brain or on a notepad in a safe

desert dirge
knotty valve
static acorn
desert dirge
static acorn
#

XD

knotty valve
#

And my giant list of millions of passwords merged into a single file because yes

knotty valve
static acorn
desert dirge
knotty valve
#

That's how I got domain admin in highschool lmao

desert dirge
#

all my secret poems to each of my 3 simultaneous crushes at the time

rapid merlin
knotty valve
#

Hacking? Nope!
Just installed a keylogger and mic recorder on my laptop and faked an issue in my laptop

knotty valve
static acorn
#

XD

knotty valve
#

What's hilarious about it though, is that you could see the recording icon on the screen

#

They didn't even think to kill the process or anything

static acorn
knotty valve
#

I don't need to do that at uni

desert dirge
#

When I was in high school, I listened in on a conversation one of the techie kids was having with my spanish teacher.

MF convinced me that people could blow up computers with a virus -_-

static acorn
knotty valve
#

Cause the lab PCs have the password written on the whiteboard ๐Ÿคฃ

#

10/10 security

#

And the even funnier fact of this, is that the lab PCs all have admin

knotty valve
#

And there's no backing mainframe or Active Directory

static acorn
knotty valve
#

So like, you could just pwn and own the PC and no one would know ๐Ÿคฃ

#

Until net admins see unusual traffic

#

That's about the only giveaway

knotty valve
static acorn
#

compter security has changed so much over the years. very satisfying.

knotty valve
#

This is the same uni, that is using AES-128-CBC for their DB encryption and SSH encryption

#

The same encryption that's exploitable by XOR

static acorn
#

HOLY

#

giga chad IT

knotty valve
#

Lmfao

desert dirge
#

only feds would go out of their way to sabotage encryption on public devices

knotty valve
#

I'm not a fed but....

#

I'd 100% do that

desert dirge
#

you're also not on the IT team lmao

blissful snow
#

same

knotty valve
static acorn
knotty valve
#

ROT13

static acorn
knotty valve
#

Nah base-65536 is the way

static acorn
knotty valve
#

Security through Obscurity

static acorn
knotty valve
desert dirge
#

Still better than plaintext

knotty valve
#

Anything is better than plaintext

static acorn
#

bro im still laughing at rot13 lmao

#

XD

knotty valve
#

I should make a password manager that embeds my passwords into random files on my PC so only the algorithm can find it

desert dirge
#

I wrote my passwords in mspaint and saved as crush.jpg so they couldn't just cat my passwords

knotty valve
#

Amazing

blissful snow
#

lool

static acorn
#

XD

knotty valve
desert dirge
static acorn
#

because the bytes say itt isnt

knotty valve
#

Paint won't but iirc the windows image viewer should be able to open it

desert dirge
desert dirge
desert dirge
knotty valve
#

The best way to secure your passwords:
Base-65536 -> base-64 -> image -> decode the colours in the image by hex -> hex to ASCII -> Reverse ROT13 -> plaintext

knotty valve
#

Why? Just to waste someone's time in the most hilarious way possible

mellow narwhal
static acorn
#

i cant imagine if i had to do that as like a ctf or somthing. i think id scream. id be in cyber chef for like 10 minutes

knotty valve
#

Which is where I got the idea from

static acorn
#

id crash out

knotty valve
#

HuntressCTF2024, challenge: base-p-

mellow narwhal
#

That's like a guesswork challenge

static acorn
#

id literally crash out mid challange and go watch bluey or somthing\

knotty valve
#

I should have the python file somewhere

#

It's so absolutely cursed

static acorn
#

dear god...

static acorn
#

jarbus... erase this from my mind and sell my left kidney

knotty valve
#

Lmfao

knotty valve
#

Completely missed the joke that it's -p-, the nmap flag

knotty valve
#

Before scrapping it and moving to a python library

static acorn
#

THE WHAT

mellow narwhal
knotty valve
#

Only issue it had was it had a memory leak

mellow narwhal
#

That takes like 30 lines at max in Python ๐Ÿ˜ญ

knotty valve
#

Shhhhh

#

I know that

static acorn
knotty valve
#

But throughout the CTF I was relying on instinct for half of it

#

So I shot open CLion and went at it for the most part

#

Before doing python towards the end

mellow narwhal
#

The fact that you wrote it instinctively in C++ speaks volumes kekw

static acorn
#

i have never written a single line of code in c++. you wont cash me outside wit that

mellow narwhal
#

cout << "Hello world";

knotty valve
#

I've written more in C++ than I have anything else

mellow narwhal
#

that's about as much as I know

static acorn
knotty valve
mellow narwhal
#

using namespace std;

#

there ya go

knotty valve
#

Bad practice lmao

#

But fair enough

static acorn
#

is thet like using a lib in C?

fierce raven
#

Hello everyone, I'm just starting out on TryHackMe!

blissful current
#

๐Ÿฆนโ€โ™‚๏ธ

static acorn
#

this looks like a foreign alien language

#

lol

mellow narwhal
#

standard namespace

knotty valve
blissful snow
knotty valve
#

Or import "library"; if you're using C++23

desert dirge
mellow narwhal
knotty valve
static acorn
#

this is why i wont touch C++

knotty valve
#

C++23 introduced it

mellow narwhal
#

damn its turning into python lol

static acorn
#

skill issue for me ig

knotty valve
#

Coroutines (basically state machines for Async code) is in C++20

mellow narwhal
#

does C++23 still require you to use malloc and free?

static acorn
blissful snow
knotty valve
#

Or it could be but not all compilers support it

mellow narwhal
#

the day I touch C++ will be the day they add auto-memory management and garbage collection

knotty valve
#

I still roll C++17 and C++20

mellow narwhal
#

Although the only times I've used C are pwn challenges

#

Once I remember there was a malloc issue with evil-winrm

knotty valve
mellow narwhal
#

this gif was made for it

knotty valve
#

Generally you don't to use malloc and free that often

static acorn
#

this is seg faulting my brain rn

knotty valve
#

They're moving to a more dynamic allocation mode

static acorn
#

bro i cant even memory manage my brain. what makes you think i can code low level

mellow narwhal
#

try x86-64 Assembly

static acorn
#

i saw a meme on linkdin yesterday. and it was somthing like... "i found this guys ip address. 127.0.0.1, im goona ddos him and he wont know what hit em" and i commented on it and said. "yeah, he DEFINITLY wont see it coming"

twin ridgeBOT
#

๐Ÿ”Š Unmuted 0x1xted

cloud quiver
#

@rapid merlin Don't send many messages in quick succession

rapid merlin
#

๐Ÿ‘

barren swallow
#

Hey Everyone, firstly, I hope you are all well and are having enjoyable weekends. I am in search for a mentor within the scope of many tech based fields. Please reach out to me if there's anything you can share as I'd love to have the opportunity to connect and learn!

static acorn
#

proper punctuation in every word. that is thbe most ai looking grammer ive ever seen diamondbeast lol

rapid merlin
static acorn
#

figures

rapid merlin
#

it's just proper punctuation

#

not everyone who speaks properly and are perfectionists is "ai"

static acorn
#

i know. you just dont see it much

#

it was a joke

rapid merlin
static acorn
knotty valve
#

8/10 times they just know how to do prompting

static acorn
knotty valve
#

With little to no idea on how the model's math works

rapid merlin
craggy wadi
desert dirge
knotty valve
#

Token pairing

#

It's easier if they're using the T5 encoder

rapid merlin
#

๐Ÿ˜‹

static acorn
#

i am a pro ai prompt maker

desert dirge
static acorn
#

XD

desert dirge
rapid merlin
static acorn
#

lol

desert dirge
knotty valve
#

$3 and a chip

static acorn
#

fiver description "i can do what anyone else can do but im a professional and can make your prompt look professional"

desert dirge
knotty valve
#

What it feels like working for the company I do, as an intern

#

Literally min wage but hey, the cafeteria is free

#

So I tend to raid the chocolates and regret it later in the day

#

At this point, my work pays me in chocolates /j

static acorn
knotty valve
static acorn
#

find / -name beer

knotty valve
#

Verizon's subsidiary Yahoo willing to buy Chrome for 10bil is funny

static acorn
#

lol

static acorn
#

yeah i would double check your sources. i dont know how true any of that is

knotty valve
#

But Apollo/Verizon/Yahoo is on the list of people wanting to buy Chrome

#

OpenAI included

static acorn
#

a twitter post. bro all this guys posts are click bait

#

i would do some digging on that. idk about this guy

knotty valve
#

Would need second confirmation on another site tho

static acorn
#

yeah, seems fishy. i would get some sources on that

#

would be REALLY weird if google sold Chrome to anyone lol

#

even for 10b

knotty valve
#

Cause it's up to the DOJ and not Google

static acorn
#

Googles browser appears in the DOJ antitrust remedies phase, where forcing a divestiture of Chrome is one possible remedy. not a done deal.

knotty valve
knotty valve
static acorn
#

again, i dont think its happening

knotty valve
#

Google could prematurely sell it before the case is closed

#

But it's up to the court if Google doesn't do anything

knotty valve
rapid merlin
#

Google has most resources, doubt they wouldn't do anything and loose their prime

knotty valve
#

I'm hoping that's the way the court goes

#

Cause it'd be hilarious imho

knotty valve
rapid merlin
#

Would they loose Gemini too?

knotty valve
#

Gemini isn't Chrome

rapid merlin
#

ah that would be not so bad for google

knotty valve
#

Gemini is an LLM model running their own model architecture

knotty valve
rapid merlin
#

They did integrate gemini in Google searches?

knotty valve
#

Chrome is one of Google's primary products

#

GCP and Gemini following behind that

#

Neither of which is a monopoly

rapid merlin
knotty valve
#

Tho GCP is debatable depending on how define the scope of a monopoly

#

But GCP being sold off would cause MASSIVE issues for everyone

rapid merlin
#

What's gcp

knotty valve
knotty valve
craggy wadi
#

what is the argument exactly? because chrome points to google as its search engine?

rapid merlin
#

Ok that is surely a problem

knotty valve
#

Google's version of Azure and AWS

craggy wadi
#

not what i said

knotty valve
rapid merlin
#

nvm my brain not braining sorry

knotty valve
#

Cause yk, Chrome is one of their largest assets

#

So that just being yeeted to someone else without a choice is just indefinitely funny

craggy wadi
#

wonder if they could get around it by offering search engine choices upon install. instead of defaulting to google

#

im not smart enough to understand the ins and outs of this but it seems comical to force them to sell. its their browser, you think defaulting to their own search engine would make the most sense

static acorn
#

this is why i use firefox

craggy wadi
#

firefox uses google by default i think

static acorn
#

bro...

craggy wadi
#

yeah google pays mozilla for that right haha

static acorn
#

chrome

#

they are selling chrome

queen flare
knotty valve
#

Roughly anyway

static acorn
#

what are we talking about rn

knotty valve
#

Yk what would be hilarious

#

DOJ goes: you're selling chrome, but the money you make from it goes to Mozilla

lone bolt
#

Is burpsuite free edition good enough for real world scenarios?

rapid merlin
#

yes..

static acorn
#

lol

rapid merlin
#

its the same thing as prem

#

just less features

static acorn
#

yeah its definitly good enough. fantastic tool

remote rain
#

Hayy is there any tool Which can bind payloads in .exe files

remote rain
rapid merlin
#

uh are u trying to use this non-ethically?

blissful snow
twin ridgeBOT
#

Gave +1 Rep to @queen flare (current: #222 - 36)

remote rain
#

I just want to test it on my laptop

remote rain
blissful snow
#

laptop(linux) and pc(windows)

remote rain
blissful snow
#

why

remote rain
#

My laptop is my target

#

What ever

blissful snow
#

I know

remote rain
#

Brok

blissful snow
#

but why not haave linux on laptop

remote rain
#

Do you know about any tools

#

Which can help me

blissful snow
#

No one here.

blissful snow
remote rain
#

๐Ÿ™‚

#

I spend 2 Days 1 night download 4 software all with help of chat-GPT
But nothing works ๐Ÿ™‚
I have asked so many people but no one knows what to do ๐Ÿ™‚
So if we can't even bypass this simple windows defender then I think the internet and cyber world is fully safe ๐Ÿซ 

rapid merlin
#

the problem is that the way ur saying it and hows its sounding

#

it sounds unethical

#

and if u read the rules

#

we don't help in that factor

sly coyote
#

No one will help you bypass Windows Defender. Please don't use ChatGPT if you are a beginner it will point you in the wrong directions... And like everyone is saying your end goal feels unethical

restive roost
#

or did you just come into this server to ask about this?

#

cos i remember last week you also asked this

remote rain
#

It's just I want to do it ๐Ÿ™‚
It's on my ego now

restive roost
#

Yeah bro I don't think anyone's gonna help you because it sounds like you're doing it for the wrong reasons.

remote rain
#

Okk thank you all ๐Ÿ™‚

restive roost
#

@remote rain why havent you verified your thm account

mellow narwhal
#

a.) Windows Defender keeps getting updated, it's not trivial to bypass.
b.) The cyber world is never fully safe. Defender isn't a central point to digital security lol

near sapphire
#

the new dr who episode is soo good, well done RTD

sick lance
next timber
#

Hello guys

sharp citrusBOT
next timber
#

How are you doing ?

rapid merlin
#

finally i have completed my pre security module .on to cyber security 101 now!

knotty valve
#

Even I struggle to bypass defender with minimal changes to the AV and that's me using windows normally ๐Ÿคฃ

next timber
rapid merlin
knotty valve
#

Nice

#

Doing my bachelor's in cybersecurity and social psych rn, very fun

next timber
#

@knotty valve Hello how are you doing?

knotty valve
#

Hi

#

I'm fine

knotty valve
#

Workload is hectic but it's fun

#

So I'm not complaining

next timber
knotty valve
#

Tbh doesn't matter where you start or if you're a beginner or not

#

As long as you enjoy it and it's what you want to do, that's all that really matters

rapid merlin
next timber
#

@knotty valve @rapid merlin I was hoping if you guys could be my friends. I'd like to have you guys as friends

next timber
#

@knotty valve @rapid merlin Guys are you still active?

jaunty anvil
#

Hey everyone. I am new to the cybersecurity world and was wondering if there are any cool events on the scale of something like comic con, but for everything cyber/tech related.
I'd love to go to something like that to meet people and learn stuff.

hallow hazel
knotty valve
rapid merlin
#

im pretty sure at entry-level they look for more certs n that stuff rather than other things

knotty valve
#

Australia had one late last year iirc

rapid merlin
#

just fixed my system from a kernel panic

#

so happy

#

๐Ÿ˜‚

knotty valve
#

In my state they want someone with both certs and degree

rapid merlin
vestal bone
#

Guys look at the kill I just did

#

1 bullet , 1 dead

rapid merlin
vestal bone
#

Damn discord discord make the quality shitty

rapid merlin
#

i forget my actual physical body sometimes ๐Ÿ˜‚

next timber
#

@knotty valve @rapid merlin I was hoping if you guys could be my friends. I'd like to have you guys as friends

static acorn
#

Dang THM! -273.1 C temps. yall cooling your servers in liquid nitrogen? lol

static acorn
#

ARE THEY

#

lol

#

confirmed AWS servers are on pluto

#

AWS cools its servers using a combination of direct air cooling and evaporative cooling, depending on the weather and the need to maintain optimal server temperatures.

#

i had to google it cuz i was curious

sick lance
#

No, they are in Ireland.

knotty valve
#

Pretty sure it's meant to warm up in a couple of months

sick lance
#

Or this week.

knotty valve
#

Oh right

#

Summer is a thing

#

Lmfao

#

I forget seasons are a thing

primal pollen
#

Hello guys I am having a problem connecting to the Labs, it always tells me that the connection file has a problem, can someone please help me?

sick lance
#

It's not summer yet?

#

It's still only spring.

sick lance
knotty valve
primal pollen
shadow dirge
#

hello guys! did any of you recently do the adenumeration network? did you encounter slow response times from basically any machine on the network? I want to figure out if the problem is related to me or how the network works. In my case, it's basically impossible to do that network...

knotty valve
#

I'm currently living in Australia where spring, summer, and autumn are all one season basically

hallow hazel
#

Well it was snowing here in Estonia yesterday...

rapid merlin
knotty valve
#

Winter is literally freezing

rapid merlin
#

cold is better in my opinion ^^

knotty valve
#

Not when it's almost 0ยฐC in the mornings

#

I like to be able to feel my fingers

rapid merlin
rapid merlin
knotty valve
#

My nose is fine, but my hands lock up really bad

rapid merlin
knotty valve
#

Yeah

#

But at the same time: gloves give me sensory issues

rapid merlin
primal pollen
rapid merlin
slow cloud
#

M9rnib

primal pollen
knotty valve
#

Meanwhile Australian summer:
Hot, hot, freezing cold, hot and raining, hot, three days of furnace

rapid merlin
knotty valve
#

All seasons in one day fr

rapid merlin
hallow hazel
#

that sounds awesome though

knotty valve
#

It's annoying imho

#

I prefer more consistent weather

rapid merlin
knotty valve
#

Can't afford to travel rn

rapid merlin
knotty valve
#

It can be like that yeah lmao

#

Or it'll be so hot you can't sleep

rapid merlin
#

But I really love Melbourne more than sydney

night hull
thin ingot
#

how do you guys usually take notes? like how is a page of your notes structured specifically? i'm currently writing them down with indentations like how i write pseudo-code lol

rapid merlin
thin ingot
#

i just stack them under the edge of my keyboard

mighty gust
#

Just get a notebook or a diary

rapid merlin
mighty gust
#

I mean book will be a little more organised

knotty valve
#

I use obsidian personally

rapid merlin
#

yeah it is a nice one

knotty valve
#

And from there I order by field, then subject, then subtopic and build the graph links so I can visualise how they all pan together

#

But my actual note structure varies on the topic

rapid merlin
#

nice job

rapid merlin
rapid merlin
#

when do yall think i should jump to HTB?

rapid merlin
knotty valve
#

I mainly use HTB for CTFs

rapid merlin
rapid merlin
rapid merlin
#

on htb

knotty valve
#

Labs are like THM rooms/labs

#

A CTF is more like a hacking competition

rapid merlin
#

ahh okay interesting

knotty valve
#

Though I find competition to be an over expression

rapid merlin
# rapid merlin whats the difference between labs and ctf?

Labs are typically structured environments that provide a more controlled setting for users to practice their skills.
CTF challenges are more competitive and time-bound events where participants solve security-related puzzles and challenges to capture "flags"

knotty valve
#

Outside of big ones like DEFCON's CTF

#

Which even that's pretty relaxed

rapid merlin
#

i will check it out once im done with the modules and labs on tryhackme

knotty valve
#

They're all pretty fun anyway imho

rapid merlin
#

sure they are

stoic quarry
#

Morning everyone

rapid merlin
#

morning legend :p

stoic quarry
#

That's a boost to the ol confidencekekw

prime schooner
#

hi everyone

knotty valve
#

Morning

rapid merlin
stoic quarry
#

How we all doing?

knotty valve
#

Hurting

rough summit
#

hello, i am a new member i just joined premium and it keeps asking me to verify my email but when i click on the link in my email it directs me to a 404 not found page. Is it ok to ignore the verification?

knotty valve
#

Give it a minute or two

stoic quarry
#

If it takes a day or longer

rough summit
#

i have tried it since yesterday with no change

stoic quarry
rough summit
#

im not sure how to contact support as it only gives me pre made bubbles to select for my issue

rough summit
twin ridgeBOT
#

Gave +1 Rep to @stoic quarry (current: #255 - 30)

rough summit
#

i will ask them

flat radish
#

hi can someone help me understand how the " view site " option is working in thm

stoic quarry
#

If you already have a VM open, it'll open another tab at the bottom

flat radish
#

yes, is that site a part of the platform

knotty valve
#

Yes

stoic quarry
#

Yeah, screenshot your page real quick

knotty valve
#

Everything THM launches is there's
It should either end in .thm if it's accessible over VPN or it'll be accessible in the the same view window as the VM (as Silastic said) or under THMs domain name

rapid merlin
#

it's better to discuss problems on #site-support so anyone who has the same question can find it there

flat radish
#

i want to create one like that.

stoic quarry
#

Like what

flat radish
#

as site that shows a split view like view site

stoic quarry
#

Iframe ig

flat radish
#

ohh ok

stoic quarry
#

Idk what they use but it's neat

knotty valve
#

Pretty sure it is an IFrame lmao

queen flare
#

hi

knotty valve
#

Hi

queen flare
#

hru

knotty valve
#

Tired and hurting

#

Hbu

queen flare
#

neither of those
i'm fine actually

#

why are you tired and hurting, if i may ask that

stoic quarry
#

Who isn't

rapid merlin
queen flare
stoic quarry
#

Just tired

neat scaffold
#

how can i learn tools like John the ripper and hydra etc like i cant found any tutorials

stoic quarry
#

There are THM tools on them both

neat scaffold
twin ridgeBOT
#

Gave +1 Rep to @stoic quarry (current: #253 - 31)

inner bloom
#

Are there any rooms for learning reverse engineering?

rapid merlin
queen flare
#

it had intros to re basics

inner bloom
#

Thanks!

#

I'm currently solving brainstorm
forgot to read that this is rev eng room

rapid merlin
#

I see on modules.. there are different types. Blue,red,purple.. what do they mean?

rapid merlin
#

but this one more difficult than the first one

sick lance
stoic quarry
#

Beat me to it

#

More qualified

#

But beat me to it

sick lance
#

"More qualified" ?

stoic quarry
#

You seem more qualified at least NotLikeThis

sick lance
#

Nonsense.

next timber
languid pecan
sick lance
rapid merlin
#

Really showing that youโ€™re a ethical hacker

sick lance
#

Transparency is always best.

rapid merlin
#

funny cause the report is 403

#

lmfaoooo

slow cloud
#

๐Ÿค”

rapid merlin
#

i aint crazy i see you glowing wizards

sick lance
rapid merlin
#

this aint politics

slow cloud
rapid merlin
#

oh i see yall also believe im crazy too

sick lance
#

This isn't really the place for this.

slow cloud
#

๐Ÿค”

slow cloud
#

๐Ÿ˜‚

knotty valve
knotty valve
#

Or whatever their shortened link is

dark mason
#

Or that, yes

#

Won't cause much chaos

knotty valve
#

I say that cause not many people are going to know what the actual MS domain for it will be

#

So it could be used illicitly with a lot more ease

dark mason
#

True

knotty valve
dark mason
#

The phising emails are gonna be crazy

knotty valve
#

im betting there's going to be an en masse of non technical people falling for it with how easy it is to make-up a domain for it

#

And just as long as your emails are signed correctly, it'll get through most filters kekw

dark mason
lethal flicker
#

um

dark mason
#

I am lucky that my family is somewhat tech oriented

knotty valve
#

Same

dark mason
knotty valve
#

I don't have to worry about my partner either, cause her family is at least somewhat tech oriented

lethal flicker
#

why do i have to pay for lessons?

#

Allow education for free?

dark mason
knotty valve
#

Because THM is a company

sick lance
#

THM need to make money to pay their employees, AWS bill etc.

knotty valve
#

Hosting isn't cheap

#

Especially on the scale of THM

pliant cairn
#

btw hey ppl

dark mason
#

You still have a lot of free lessons to check out tho

knotty valve
#

Hey

sick lance
#

However, 50% of THM is free.

dark mason
pliant cairn
#

somehow surviving and not getting pissed by microsoft

dark mason
knotty valve
#

Only thing I wish for with THM is localised pricing lul

knotty valve
#

That I haven't paid for the last two years

pliant cairn
#

i use azure. can't relate. all the fees are hidden. i have not for once seen the billing analysis match my actual billing

knotty valve
#

They keep emailing me for it

dark mason
#

Not sure what THM is able to do about that

knotty valve
pliant cairn
#

there is always a decent amount of difference for me.

knotty valve
#

Mine has always been to the dollar, never been off

#

Same with google when I tried out gcp, only time my prices are off is if I need to do currency conversion

#

Which I'm basically adding 40-50% extra cause currencies and bank fees

simple fox
knotty valve
#

Haven't staff disclosed what region and provider THM servers run on before?

#

Swear I saw it mentioned earlier today

#

Not sure who said it though

simple fox
#

lmao

neat scaffold
#

how can i make burp suite work with firefox?

sick lance
#

It's not hidden?

#

You can literally find AWS information on every box.

sick lance
simple fox
neat scaffold
knotty valve
#

Or preference

sick lance
#

If you run linpeas on a box you have a a shell on you can find them.

simple fox
neat scaffold
#

will it work too?

sick lance
neat scaffold
knotty valve
#

Doesn't Firefox allow you to setup a proxy natively?

sick lance
#

You'll find them?

neat scaffold
knotty valve
#

Ah

neat scaffold
sick lance
#

Use FoxyProxy extension in Firefox...

neat scaffold
sick lance
rapid merlin
#

i use it only for burp, works

gusty inlet
merry hornet
#

hey guys new to the discord

slow cloud
#

Welcome

merry hornet
twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #167 - 50)

merry hornet
#

How do assign myself a role here?

#

*I

twin ridgeBOT
#

Gave +1 Rep to @sharp citrus (current: #67 - 132)

sharp citrusBOT
sick lance
#

Need to verify your account.

merry hornet
#

@sick lance the discord token is assigned to another account I lost. Is there anyway to change it?

lethal flicker
rapid merlin
#

somehow something broke my sudo file, updated system and after wheel group was commented

#

but only kernel was updated xd

merry hornet
sick lance
#

Was it banned?

sick lance
merry hornet
#

@sick lance No. I've not used this discord properly. Infact, its the first time I've posted on here. I tried to recover it but Discord and me don't mix. Thanks i'll DM you now

twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3678)

blissful pulsar
#

morning thm

willow helm
#

Hi guys, I am connected to TryHackMe via OpenVPN. Now what? How can I complete the rooms; I don't need to start attackbox anymore, right? If so, I am learning python basics while I am connected to its server, how can I capture the flags?

#

And where to write codes? Download sth on my VM?

cloud quiver
#

No , we can't help you with that we don't do it here

slow cloud
grim sparrowBOT
#

:hammer: ijuswannastayupallnight#0 has been banned.

cloud quiver
slow cloud
#

Is there a deadline on the mod applications?

willow helm
blissful pulsar
#

download ur config file then do sudo openvpn 'configfile' then youll be connected to the vpn

dark mason
#

And yes

cloud quiver
dark mason
#

They will end once there are enough mods

slow cloud
cloud quiver
distant kiln
#

How would I text someoneโ€™s number through instagram

cloud quiver
distant kiln
#

???

slow cloud
#

Could u explain

#

A bit more what u mean

blissful pulsar
#

i didnt even know u could do that

willow helm
slow cloud
#

Since i dont really get the texting a number through instagram

distant kiln
#

Like I want to text someoneโ€™s number without texting their instagram

blissful pulsar
#

just txt the number then

#

;-;

slow cloud
#

Yeah

distant kiln
#

So use instagram to gather their number

cloud quiver
slow cloud
#

That i dont think is possible

distant kiln
#

No i want to know if it could be done

blissful pulsar
#

it cantt

distant kiln
#

Good to know

willow helm
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4726)

distant kiln
#

Thanks

cloud quiver
#

usually

slow cloud
#

It really depends on the room

blissful pulsar
#

being 10th in gold is so scary

willow helm
cloud quiver
blissful pulsar
#

if u need other stuff the room would specify

cloud quiver
slow cloud
#

But that usually is explained in the room if needed

willow helm
blissful pulsar
#

like if u dont want to type the ip when ur doing any sort of scan like

nmap 10.10.10.10

u could just do

nmap <name of the room>

i think

oblique marlin
#

Have anyone tried OSINT Tool and got valid information from it?

cloud quiver
#

Check out DNS in details room if you haven't done so already

mellow narwhal
willow helm
#

Thank you @cloud quiver
I am doing advent of cyber 2024, and trying to connect to elastic SEIM via the provided link, but my browser shows an error message of "504 Gateway Time-out" what can I do?

twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 4727)

mellow narwhal
#

not name of the room exactly

cloud quiver
blissful pulsar
oblique marlin
twin ridgeBOT
#

Gave +1 Rep to @mellow narwhal (current: #156 - 53)

eager raven
#

Needs help

slow cloud
rapid merlin
#

@eager raven ?

eager raven
#

Needs help

rapid merlin
eager raven
#

I need help

fair linden
#

with?

slow cloud
patent schooner
#

cant see myself on monthly leaderboard, it says I'm 24?? help

fair linden
#

24 is crazy

rapid merlin
#

good evening

fair linden
#

good evening

slow cloud
#

Sup

junior wigeon
#

sup chat

rapid merlin
#

john the ripper is fun

junior wigeon
#

you think so?

rapid merlin
#

ye it is..... coz thats the first actuall hacking stuff in THM/CyberSec 101

junior wigeon
#

ahh

rapid merlin
#

mhmmm

junior wigeon
#

ain't done that path

#

web app pentesting path requires some knowledge of owasp

rapid merlin
#

i see

#

i will soon go down that path :>

#

how do i switch user on attackbox for windows 10

sick lance
#

Attackbox or W10?

They're two different os

rapid merlin
#

ohh no w10 sorry

#

@sick lance

sick lance
stone lynx
#

finally :)

stone lynx
#

thanks happyOwl

coarse holly
stone lynx
sick lance
gusty inlet
#

Real.

#

So real.

coarse holly
#

Not any server

#

Its a new feature apparently

sick lance
#

It's an old feature brought back.

stone lynx
sick lance
#

Discord Guilds.

stone lynx
coarse holly
sick lance
coarse holly
#

Hello, I also have a quick question.
I was enrolled in the Junior Pentester Path, but my progress was halted because I didnโ€™t have a premium subscription (itโ€™s been around 5 months now).
If I complete the modules now, will the certificate show the original start date, the completion date, or will the time gap affect it? Thank you!

sick lance
#

Completion date.

#

Possibly with time.

#

I want to do some THM, but I honestly can't be bothered.

crystal mauve
#

Isnโ€™t time spent a fixed number ?

#

does it actually track time spent in modules ?

coarse holly
#

so in my current situation it will be like hundred of hours ?

sick lance
#

Who knows?

coarse holly
#

it will be funny if my time to completion was 500hrs

crystal mauve
coarse holly
#

alright then

hoary monolith
#

Now I can't unsee it

modern fox
#

good job man

stone lynx
#

thanks thanks :) I appreciate it

loud marlin
slow cloud
#

Sheesh

stone lynx
#

solid, I'll get there in a year or so

slow cloud
#

U guys can never beat my streak of 0

sand trench
#

....

tacit swift
#

Hi everyone, I have been doing programming for few years now and had interest in cybersecurity from beginning and after doing development all this time now I want to focus on security. I need help in how should I proceed, what I mean by this is which topics should I start from so that I have a nice base for the future.

rapid merlin
#

Guys any idea on creating Complex custom rule set for John The Ripper ?
Like
A0"PC-[0-9]"Az"[@[0-9][0-9][0-9]" would that work??

vestal bone
#

How is this even possible

oblique needle
rapid merlin
oblique needle
#

max I had was like 12 days something lol

#

that was years ago

tacit swift
#

@sand trench thankyou for the advice, I would like to ask one more question, what are the general skills anyone should be having to be able to perform well in ctfs ( like the prerequisites to be able to solve ctfs keeping experience aside)

opal perch
#

help: Launch the AttackBox if you haven't already. After you ensure you have terminated the VM from Task 2, start the target machine for this task. On the AttackBox, run Nmap with the default scripts -sC against MACHINE_IP. You will notice that there is a service listening on port 53. What is its full version value?

#

is: Nmap Post Port Scans

sand trench
opal perch
#

idk why the asnwer is wrong

inner bloom
#

i'm in Demotion zone

crystal mauve
#

Is a great resource , scroll up youโ€™ll see a lot

night rose
#

oops lemme delete it sorry

crystal mauve
#

No you are good

night rose
#

i was spamming all brain ded im in way too many ctf servers

crystal mauve
#

Itโ€™s a great question

eager raven
#

Itโ€™s a lot

slow helm
#

hey i have a question so i started a ctf challenge at first there was an open port at 7777 , then i restarted the machine and it was closed i tried restarting it for few times(10) and still the port is closed and its the only way to solve the challenge

slow helm
sick lance
slow helm
fleet pivot
#

travis hunter has officially become a jaguar

south egret
#

Ok

fleet pivot
#

W trade

amber laurel
#

What's the pass for logging back into Ubuntu?

slow helm
#

huh ?

sick lance
#

Press the i.

#

It will give you the root password.

slow helm
amber laurel
#

It shows "ubuntu on thm-threatintel".

#

Yeah I'm doing that room.

sick lance
sick lance
slow helm
#

is your full time job discord mod for thm server ?

sick lance
#

No, it's a voluntary position.

slow helm
crystal mauve
#

lol

sick lance
crystal mauve
#

Y would any voluntary pos require 24,7 commitment

sick lance
#

It's a valid question.

#

They may be thinking, or already have applied.

crystal mauve
amber laurel
sick lance
amber laurel
sick lance
amber laurel
sick lance
amber laurel
#

Ah fair.

sick lance
#

THM should rescind their sponsor of John Hammond since he forgot to do a give away in his Sal1 video. /s

astral trench
#

Guys Iโ€™m stuck on OWASP top 10 questions 21

Who developed the tomcat application.

Iโ€™ve tried couple of answered but not matching . Iโ€™ll be glad to get some help

sick lance
#

Also state which room you're doing. (There two OWasp top 10)

astral trench
#

Not the OWASP Top 10-2021
The normal OWASP 10

sick lance
#

?

astral trench
#

๐Ÿ™„

sick lance
astral trench
#

Unless Iโ€™m blind somehow but Iโ€™ve looked through their page

rapid merlin
#

sorry

unkempt talon
#

@sick lance are u one of those guys who create rooms in thm

unkempt talon
#

Why can't I create my own room ?

stark cairn
#

Hello

sick lance
sick lance
unkempt talon
sick lance
unkempt talon
#

Yea yea I see , thanks ๐Ÿซ‚

sharp citrusBOT
sick lance
twin ridgeBOT
#

โž• Gave the role Creators-Lounge to neoudv

sick lance
#

#creators-lounge is a channel dedicated to room creations, there will me some questions in there you may have already answered, and a more dedicated space to ask more.

brittle wasp
#

hi im new here

sand trench
#

ello ello sebi

brittle wasp
#

ello ๐Ÿ™‚

#

hey guys can someone teach me how to do better ethalic hacking (i only swas scamming scammers and get there IP

#

With tracking links

hushed oriole
#

๐Ÿ™‚

twin ridgeBOT
#

Gave +1 Rep to @hallow hazel (current: #305 - 23)

sick lance
brittle wasp
#

hm? what do u mean?

#

are tracking links not legal?

neat scaffold
#

can someone help with something pls

brittle wasp
#

Am i right?

#

or not

rapid merlin
cosmic minnow
#

Simply collecting IP addresses and general device info that scammers send you (e.g., through an email or website visit) is usually fine... Hacking into their systems, accessing private accounts, or gathering personal data without consent crosses into illegal territory

#

Even when collecting basic info, you should still avoid public "doxxing" or unauthorized data sharing, s that can also have legal consequences.

brittle wasp
neat scaffold
#

Iโ€™m trying to set up a Meterpreter payload on my laptop and download it. Iโ€™ve set up a local server, but I'm having trouble getting the APK to download properly on my phone. Can someone guide me through it?

rapid merlin
#

contact microsoft support

#

โญ

brittle wasp
#

i already did

sick lance
#

Vigilante hacking is illegal

dark mason
sick lance
sharp citrusBOT
brittle wasp
# sick lance No.

Of course, vigilante hacking is illegal. I just meant basic tracking for self-protection, not hacking devices or accounts.

cosmic minnow
#

what does "tracking for self-protection" entail..?

rapid merlin
#

i love helping others

neat scaffold
rapid merlin
#

hitman?

naive violet
brittle wasp
#

By 'tracking for self-protection', I mean collecting public information like IP address, approximate location (from the IP), device type, and browser version.

rapid merlin
#

also you wont find anything from public informations

#

many people use same ip

#

๐Ÿ’”

blissful pulsar
#

i feel like im so close to getting Moebius room user.txt

cosmic minnow
#

yeah, ISP release and renew ips constntly

naive violet
#

CGNAT

brittle wasp
# naive violet ...how does getting an IP help you there?

Getting the IP can help to confirm suspicious activity, like if the login attempts come from a country where my friend doesn't live. It can also show if the attacker is using a VPN or a proxy. It's just for gathering clues to support account recovery, not for attacking anyone.

naive violet
#

Lol what

near hawk
#

๐Ÿค”

naive violet
#

Account recovery? Contact the support of the service

naive violet
#

Using a VPN or a proxy? Who cares, you're not the police

#

Login attempts? Use good passwords, don't share them, use 2fa

brittle wasp
#

I understand, thanks. I will contact the official support instead. I just wanted to help my friend, not cause any trouble.

brittle wasp
rapid merlin
rich timber
#

Hii guys i need help if someone can help

I don't have access to old Instagram account no Emil no password i want to get it back is it possible

cosmic minnow
sick lance
rapid merlin
brittle wasp
sick lance
rich timber
sick lance
brittle wasp
#

If i get hacked (lets say i tracked him already) then i know wehre he did that

mossy river
brittle wasp
#

i can find out info for my self or call someone that knows more

dense spoke
#

Be honest, have you tried an SMS phishing campaign with relaysms.io before?

rapid merlin
brittle wasp
#

?

dense spoke
#

SMS Gateway link

sick lance
brittle wasp
#

lol

dense spoke
#

Similar site with Onbuka

#

Only elites can relate.

sick lance
brittle wasp
brittle wasp