#general
1 messages ยท Page 1061 of 1
Porsche Sports Lineup
ok thanks. do you recommend a specific path?
Gave +1 Rep to @sick lance (current: #2 - 3700)
Choose your pokemon

Do you have a sub?
Been on a good 4 day streak ! Getting this grind in to start off my morning yu hurdddddd
yes
If you're subscribed to THM Subscription
Take a look at that, @pearl copper
i need help every bug that i found so far got marked as a duplicate like what should i do
yeah but for example after i finish 101 roadmap, which ctf do you recommend to do?
RootMe.
I started with WhiteRose ๐
after rootme? cause i did that
Give White Rose a try! It's a Mr. Robot cross-reference Priv. Esc. room
ok thanks
Scrubz a quick question, if you don't mind and me getting banned. Is being a Community Moderator here paid, or no?
It's voluntary with some perks.
Beneficial Perks community and/or tryhackme platform wise?
THM aimed.
You get free sub, merch, access to our AWS and Azure training, and we also give you perks outside the platform, such as Amazon vouchers
We're always looking to improve and increase the perks ๐
thanks
Gave +1 Rep to @sick lance (current: #2 - 3701)
๐ reeeeally
The perks alone is hella nice! The only thing I could ever ask of that is the Amazon Vouchers! Could really use those ๐
P.S. I don't use it for my beneficiary gains. I donate those to charity โค๏ธ
:/
Holy mother of god, that's an extensive resume 
What I most hate in this world is only two things; People who can't properly comprehend what I say and OSINT.
How do you guys deal with the problem of balancing security and convenience when it comes to password management? I want to have unique and secure passwords that I can remember somehow ๐ค
Password manager?
Are you using the passwords at work or at home
You can write your own passwords at store them in the manager, but it's much more convenient to just use the automatically generated password, and then autofill
At home, but if also work in terms of university-related stuff ...
I used to have my passwords stored in keypass but it got corrupted by an attack vector. I would write them them and keep them locked up.
Or use phrases you can remember
You can also make your own rules for swapping letters for numbers eg
The problem is that I cannot remember stuff arbitrage passwords. What am I supposed to do if I want to login from another device?
most password managers have multi device support
^
alternatively, you can just open it on your phone and type it in manually- this is what I do when I'm on Windows as I use Apple's password manager
Something like password123@Amazon or password123@Discord?
Wow.
โฆ
Now all I need to do is find that book, shouldn't be too hard.
If you can remember it, an attacker can predict it
(this isn't an exactly accurate rule, but it's still something to live by)
Humans are a creature of habit. ๐
Can I use that on Windows 11 too? ๐ค
Ohh what book you after ?
None, yet. ๐
Atomic habits is a great book
Set up iCloudย Passwords in iCloud for Windows so you can manage and autofill your passwords on your PC.
I seen something about that being out dated.
there are accounts i can easily reset or they don't mean much to me so i just store them in an password manager depending on the system like apple keychain or keepass. other things (and ofc passwords) maybe very important so i just store them on offline devices (encrypted). also enable 2FA ๐
I don't remember my passwords, I remember my finger placement on the keyboard
It's great but means I can never type them on mobile lmao
Passkey.
how does that work
Auto-fill the fields and use biometrics to authenticate.
technically, you still remember it but with your body
ah i ment to jabba
Ohhh, I can touch type while I look away talking to other people ๐
I type fast too
yes but be carefull if they upload to cloud
The only issue with biometrics is when you're in trouble with the police.
I don't remember it I just remember the general location that my fingers are in and the way they move
it's why I can't reliably enter them on mobile because it's much smaller than my keyboard and has different finger placement
If the device is secured with biometrics, and you don't give it up, they can charge you with what they think is on the device.
i mean, if your in trouble with the police i think theres worse issues
Donโt get in trouble with the police โ
๐
interesting
i would not recommend using biometrics a master password you change every couple of months is the best. without any extra hardware .
Why would I need to be careful? ๐
Your threat model.
expands attack surface
the cloud is just servers, its not truly a cloud. yall know how it even got that name?
What the heck is that? It's rated at 2.3 ๐
Alternatively, platforms should implement multi-stage passwords.
Something you know, something you have, something you are
depends on threat model but most of the time it doesn't really matter if they upload
Doesn't necessarily mean it's bad ๐
XD
I know, I was fishing for an explanation 
First step is prevention, but majority of people will choose convenience over security
Isn't it better to use Google Password Manager when using Google Chrome?
yeah by putting there password on a obvious sticky note ๐คฆโโ๏ธ
I would not suggest using a browser based password manager.
What would be the better option?
I use a password manager which is offline.
What is it called? Is it good enough?
keypassxc or bitwarden
UK gov says it's fine ๐
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers
the same gov which did remove ADP
๐
uk gov trust me bro.
wym tried
How can I use Bitwarden if I want to login to Amazon on Google Chrome or on Discord Desktop? ๐ค
you can add it as an extension to browser or download the app the later being the most secure and the first being more convenient.
Do I have to do both (extension and app)? Can't I just download the app itself?
i would trust a external password manager more then a browser imo
yeah they both work by themself
Is Google really evil? ๐ข
It's actually much worse than that, the Government wanted a backdoor to be installed which would compromise the security.
ADP only works by storing the key that encrypts your iCloud data only on your device, instead of in Apple's iCloud, which means that nobody can access your data not even Apple.
While I don't agree with the choice and reasoning, it's not as bad as media made it out to be
As usual, it's blown out of the water.
So is it safe to use passwords app from Apple
yeah the app is fine
non-tech people started to think that Apple disabled iCloud encryption which wasn't at all true
If you're that paranoid, encrypt everything yourself and then upload it to iCloud
Yes perfectly safe
1111 is the best password
It just means UK gov could force apple to give over your icloud info know but if the government are doing that then you probably have bigger problems, or if they get hacked but they have pretty good security.
Why do these sites generate different hash values?
Instantly generate a SHA256 (32 byte) hash of any string or input value. Hash functions are used as one-way methods.
Online SHA256 Encrypt/Decrypt is a free tool for encrypting and decrypting SHA256 hashes. SHA256 encryption function is irreversible, that means there is no direct method for SHA256 decryption. Trial & error method is used for SHA256 decryption. SHA256 encoder decoder makes millions of trials for cracking SHA256 hashes.
they generate the same for me
are you putting a space before or after the string for one of them? @lethal fog
They donโt know what they are talking about
I would rather write my passwords in a notebook
paper is king second only to a dedicated air gapped machine with the wifi card ripped out
best way to store crypto wallet seed phrase
guyssssssss
๐
Hey guys, thought this may be useful so just dropping in to say that Pearson VUE is offering a free exam retake for select certification exams. To qualify, schedule, purchase and take an exam between 1st May - 12 June 2025.
If you don't pass, you can retake the exam for free between 7th July 2025 - 20th January 2026.
This includes exams such as AZ-104 and AZ-500, but excludes the following exams:
- AI-102 and AI-900
- AZ-204 and AZ-900
- DP-100, DP-300, DP-420, DP-600, DP-700, and DP-900
- MS-102
- PL-300
- SC-200, and SC-401
Source: Pearson VUE
Yes, that was my fault ๐
ripping cd:s goes brrr
eh paper does not leak electromagnetic radiation like a computer does
have a nice evening, how are you people?
going to store for saturday candy/snacks soonish
Donโt forget the cheese
What kind of password do they ask for? Is it the regular password to login? ๐ค
yes it's the same pin
where is this hash from
give me your password i'll tell you
But it says that the pin is wrong. How is that possible? Isn't the it the regular four-digit password on the iPhone?
you're typing it in wrong? idk ๐
its the laptop pin
So it's a combination of numbers? ๐ค
it's the one you login to Windows with
But that's not a only-digits passwords then? ๐
You set it up when you setup Windows ๐
I have to go to Settings > Accounts > Sign-in options
--wizard
๐ฆนโโ๏ธ
hello. i have been spending time in another server.
@grizzled wing ello Sudo Veggies, long time no see
wow Kamany is a Legend ๐
new pfp ๐ฎ
Some how it looks like I got Covid bc canโt taste nth nor smell
Just kiddin
Absolutely not
whats with this CYBER icon? thats new

server tags
Crazy I been eating I ate pasta I ate chocolate o ate rice hey all like nth
there r more sort of tags in some specific server for now
try chili peppers
Ayyy that means no uni for a weeek and more time to do rooms
Bc I havenโt been on there in these 2 days
oh, triple eight
try:
spicy_food()
except:
no_tastes()
spicy food >>
I tried today but I was too tired but I finished one at least search skills itโs nth but better than nth
Tut tut, specify your exceptions!
๐คฃ๐คฃ
I tried ramen
Bro I ate it like nth the pink one
return 0
Can I DM you?
try:
spicy_food()
except CouldNotTasteError:
no_tastes()
i got red nail polish on ๐ , think today is red team day

?
can someody help me im trying to get my friends ip addres how do i do that
i think you just ask them?


Why do you want to?
Icl I think I know why am not sure tho
You know when u have friends who is no IT knowledge and be like I know ur ip address bomb Ygm

ehh
that could be somehow scary for them, but anyways ip adress is nothing nowadays
Itโs fun when itโs ur close friend but I am not sure his intention nor if that is why tbh
haha understandable
It was fun when we used to do that I forgot how

That wouldn't be legal.
Actually yes, but that's all on eductional purpose, yeah?
Iโm thinking about hosting little king of the hill challenges with prizes. I wanna see if any one is interested
howre you going to host it?
On tryhackme you can host them
sometimes shadow wishes they could read japanese for the music album names
No?
You can't do something then think it's ok because it's either;
a) A friend
b) "Educaional circumstances".
In the eyes of the law, there is no such thing as educational circumstances.
actually yes, but when things ain't bothering unknown people then it stays normally
Well, you're screwed next time you go into uni then 
Next week for my last exam. ๐ฅณ
Whooooo, good luck! Don't get arrested! ๐
It's ok, this one is a written answer on Web app security.
Ouch
Heh, wait until you need to write a pentest report
Hey guys
so thats 500 words for each of the 27 questions?
supp
No, I'll get a selection of questions, and I only have to answer 3 of them.
pheww that's better
Guys I am preparing for CompTIAsec +.... any tips plss???
Kara no Kyoukai "Mirai Fukuin" / "Mirai Fukuin extra chorus" Original Soundtrack
is the english version of said title... it is for the anime garden of sinners ( known as kara no kyoukai in japan of course )
it's easy, you got this

๐
I had to check that it was Saturday
A what day?
Even CompTIApentest+ is supposed to easy, but is it true?๐ค
Depends on what you define to be easy
Star wars day tomorrow
And Revenge of the Fifth on Monday.
Doesnt dr who rhyme about green eggs and hams
No, that's Cat in the Hat.
I dated someone once who was obsessed with doctor who, he looked like Walter white. Thatโs the only time Iโve watched it
Dr Seuss.
Ohh
Sounds like a keeper.
He once cut me with his toe nail.
Sounds like he needs to cut his toe nails.
Iโm going to make my girlfriend watch from Tenant until Capaldi
smh
He tried a comb over for years but once he met me I shaved it off. ๐ No more living in denial.

Not sure what that even means
Did you watch the recent Doctor Who @sick lance
I haven't seen tonights episode, I've seen the rest.
Actors that played the doctor
Tenant 10th, Capaldi 14
Toe nail comb over
New season is good, new assitant is bad.
sorry the one before tonight ๐คฃ
Planet made of diamonds
Two weeks after the breakup, he got someone pregnant. She took away my problem. AMEN
Sounds like he needs to let it go.
Yeah, that was a great episode.
I donโt like new who, nor have I watched any episodes but my brother told me to watch it
I got so excited when I heard that line
I dont really watch much of anything besides like defcon conf, or blackhat usa shid
Rest of the episode was terrible
Perfect set up for a third part.
Maybe one day boondock s5 will come out
Until then i will just keep being a nerd under a rock
In fact I still have many troubles in pentesting. That may just be true.
Dr. Green Eggs and Ham
I really want to go defcon
Just keep going
Sounds like you think America is below England.
Im not sure where they are from
...England.
Iโm in England

okay good to know i guess
I never really sought after their location or had any context ๐
48 hours or how long?
With your arms anyway.
Use a plane, save energy. (your own)
Itโs like ten hours
Hi, can someone help me with windows partitions ?
What do you need help with?
I just clean everything and reinstall windows , i had windows on ssd , now i installed on hdd
Wait , i think its easier to show you
Can i dm you?
Right click delete partition?
Delete Volume.
I cant do nothing to this partition
You can't use eliminar?
No
Thats what im trying to understand
But there is no error
The buttons just not working
Only button working is that "Ajuda" that means help
U got admin rights?
I think so, i just installed the windows now
Its fresh
Now i want to install linux in this disk 0 but it has this 100mb idk why
What if i uninstall the driver ?
Oh I'm thick.
No, don't delete the EFI.
Make sure the partition isn't in use and you open it as administrator
@fervent ruin send a picture of the full partition screen please
The EFI is in use.
Hehehehe ram go brrrrt today
And i want to free other disk, to install linux
casually running 3 server VM's
Looks at 2x xcp-ng, 1x proxmox
Light weight.
I tried installing the NVchad Neovim config on my Kali Linux
It gave me some errors
Even though it's advertised to run easily just by running one line of code

How did you move Windows from the SSD to the HDD?
I deleted everything from both drivers , when installing it from usb

When u choosing what drive u want to install, i just format both drivers and install windows on hdd
Open system information and tell me what iut says for the "Boot Device"
Lol I found a way to memorise my lessons faster. I transform them into a song
Where is it ?
halfway down the page
I think im not understanding what u asking for
Where u get that ?
on system information
Idk where is that
I don't know what it would be called on your system
Im in settings , about
Windows key + R, type msinfo32
sorry I wrote the wrong thing, msinfo32
Ye
then what does it say under boot device
\Device\HarddiskVolume1
I think im going to put linux on usb , and install it on ssd , and when installing maybe i can delete this 100mb
...
Oh Lordy

You rang?

Imposter. God left the building a long time ago
And torched the place on the way out
They did not.
if you got neovim from apt it wont be the most up to date version so is not compatible
no don't delete it
@sick lance hey.. i have a question for you:. I guess it is not ok to ask for a test person etc for my own ARG / CTF .. It is just a fun project .. But if it is ok, can i do it in this channel ?
I think Jabba may be answering you, all decision like that would need to go via them.
Why?
Sorry I didn't want to give advice without double-checking.
I'm pretty sure your Windows is using the EFI partition to boot, you should probably move it to your windows drive before doing anything.
*I am not an IT technician, and this advice is not official
Windows is. ๐
But i cant do nothing to this partition, cant delete , cant rename , cant do nothing
Even if i try to move it to hdd , i just cant
cc @mossy river
You should be able to create the EFI on the new device, reboot to get Windows to use it, and then delete the old one from the drive
I have to go search how to do that
However, I won't be advising how to do this as I am not able to completely see what you're doing, nor can I give advice specifically for your situation
windows uses its own boot manager have to shrink one of the partitions ie the NTFS and then boot into a live iso installing grub and a ext4 partition then reconfigure grub with osprober enabled
If i install linux on this disk, this partition can be there anyways , its just 100mb of 232gb
Sorry we generally avoid allowing "test users" here as we cannot ensure the safety or of our community members ๐
Just make sure Linux doesn't wipe the partition while installing lol
damn these bots are really getting advanced
I think im going to install kali , bc im spending all day on kali on vm , so...
What if ? ๐คก
I wouldn't recommend doing so, you shouldn't be pentesting without a VM anway
Why?
kali is not really meant to be installed on bare metal although it probably ok unless yo are doing malware analysis
i would just use ubuntu and then install the tools u need
Yes , but why is bad to do pentest without vm?
but better to just use vm if yo have the power
Why? is kali not stable or what?
Using my pc will be better , using vm is slow for me
if you are doing dynamic or static analysis or if someone attacks your machine
no its not really stable
Oh ok.
but its still fine to use you might just have to reinstall when it breaks
Ill be using linux just for cybersecurity , just for tryhackme
I will use windows for daily basis
It isn't recommended because:
- it is poor security hygiene to be using your host, especially if you're working for a pentesting company, you usually use fresh VMs for each client (especially if you store client data on them)
- it is not secure or safe, especially as you may be making your host vulnerable or playing with vulnerable/ malicious software
- pentesting machines are designed to be setup on the go, when you need them, not as daily drivers
If you really want a CTF machine, I usually recommend a laptop you don't mind losing
what are your specs ?
I dont have laptop ๐
I don't know, but I keep hearing that linux is not good in desktops computers. Is that even true?
if you really want to you could install a distro like ubuntu and then enable kvm for hardware virtualisation its much faster than running a vm on windows .
i5 3ghz , 64gb ram , 1060 6gb gpu , 1 ssd 232gb, 1 hdd 1tb
Om nom nom
So how do I downloaded the most upto date version?
snap store or compile from github
It is true, its not good on a host machine. It's not been designed for general daily use.
@mossy river hello
Where to contact for discussing an interesting sponsorship opportunity with try hack me?
I understand. Thanks anyway.
Gave +1 Rep to @mossy river (current: #6 - 1592)

All are running at 16GB of ram each. Why? Because testing, and why not?
Can I download from terminal or I'll have to download from browser
All Linux distros?
Kali.
what distro are u on
Kali in VM
I should asked this b4 deleting everything from my pc ๐คก

Do you know any good distros for Desktop?
Linux Mint
personal preference mostly, but Ubuntu, or Mint are probably the best for beginners.

i think "snapd" is a package in apt
But ei, mr robot used kali as main os , what he knows that we dont ?
probably that they do regression testing and repo checking more than other distros
How to read a cough SCRIPT
pretty sure mr robots microwaves his drives after every hack session so never has to update anything ๐
pretty expensive but also very effective .
is it?
But if i want to install kali on my pc , what are the problems ?
I can imagine
Kali should be in a VM for a bunch of reasons ๐
What about ubuntu with tools ?
That works too
But what are the problems ?
The best hackers I know use stripped down ubunutu and run their own configure/tool scripts
Disadvantages
Hello
It shows address not found
Kindly provide any alternative email address sir
Well if it's professional there are record keeping requirements that VMs make very handy
Sepration of testing enviorements
The only reason i still have windows is for my music production, i want to use linux only
Kali is not an everyday OS
its just not containerized so if anything got onto your machine they could look through your drives and access the hardware .
It's a I'm working here, OS
Kali has many outdated packages
There are 2 big reasons for taht
TL;DR
Bad news for Kali Linux users! In the coming day(s), apt update is going to fail for pretty much everyone out there:
Missing key 827C8569F2518CC677FECA1AED65462EC8D5E4C5, which is needed to verify signature.
Reason is, we had to roll a new signing key for the Kali repository. You need to download and install the new key manually, hereโs...
teehee Oopsie
I will be doing thm rooms , creating my scripts on linux, and use windows for music production
get a Kali VM on WInders
guys i have an issue please help

If you're in pentesting, then Kali is pretty much the best choice tbh
Thats what i had , but its slow
Let's bet
yeah kali or parrot
With?
Kali on WIndows is fine
i have a subscription but it says that i should resume my sub when its actually active, its been like this since yesterday. whats the solution?
good question. #general message
All of my friends are ignoring me
How do you get them (friends)?
I like edge browser interface , but brave ad blocker is so good
Anyone here having trouble with vmware tools? I can't install vmware tools for my linux virtual machines.
what's the problem
Thats a reason why i dont want vms ... guest aditions
Security is always overshadowed by convenience
yeah i sent an email but it says they will respond in working times. i really need to practice for my quiz on thursday :/
Windows I'm assuming?
Yeah.
What?
I think using linux may be safer than windows bc hackers know that majority of people uses windows so they create windows virus , using linux , this virus will not work ๐
(Maybe im very dumb saying this)
Doctor Livingstone I presume ๐
completely true
I'm pretty sure to resolve this problem all you need to do is install the VMware tools disk from broadcom, insert it into the VMware folder, then add a CD/DVD sata, iso image and select the vmtools disk
However, I'd recommend clicking on the help document they linked first
You can also do it from packages eh?
Why fl studio doesnt work on linux ๐ญ
Alright, thanks!
Gave +1 Rep to @mossy river (current: #6 - 1593)
Idk, I passed the charisma check
my charisma is to low i put all my points into luck
Yes, you should be able to install open-vm-tools from the packages
IIRC This is the pefered method in most guests eh?
because you want to run a window soft into a Linux system ๐ if you want to run windows soft use windows. Sometimes windows soft doesn't even work in window so go figure when you try to run it some place else ๐
@cosmic pendant how are you?
I wouldn't know to be honest ๐
I'm good, Hyd REx?
other than being stuck in Argentina I can't complain ๐
There are much worse places to be stuck eh ? ๐
How far are you from the beach?
about 400 km, but it's autumn here, so it wouldn't help even if I were living in front of the beach ๐
That's why I can't complain ๐ ๐
have a nice great day
Oh thank you for that information sherlock
Gave +1 Rep to @blazing granite (current: #52 - 172)
You're welcome Watson. If you don't want and obvious answer, don't ask an obvious questions ๐ ๐
some windows software actually works better on linux in wine then on windows

@umbral bay Can we have an archive for hackfinity writeups?
that moment when windows is so bad that even with wine translation layer linux is still faster
Yes it's being archived :)
I can't found it if u can send the channel please do and thanks
Gave +1 Rep to @mossy river (current: #6 - 1594)
ah okay thanks!
I've never got the idea of the wine soft, the only wine I like is the one on my glass ๐
it stands for:
wine is not an emulator
Having the X-Wing in Fortnite is fun.
Not fl studio ๐ญ
winae
yeah weird that the an is not included D:
I know the project. we actually started with Linux in the same year ๐ I've never got the idea, to bring windows into Linux. I'm in Linux because I want to get away from windows ๐
well shadow basically only uses it for bad services that don't offer linux support cough cough qobuz cough cough
i had to do it to play fallout 1,2
yeah games is an obvious thingy handled by wine and proton
Actually window like we know today didn't exist when I started to use Linux so it would be more accurate to say to get away from microsoft ๐
The close it was NT which I tried back in 1993 but still wasn't happy about it.
how can i fix the blur in burp suite community edition
time to install a bunch of vms
kvm rules hyper-v drools
It is not true. I have run desktop linux distros for 10+ years, and the only time I regret it is when I have to kick up a VM for a windows program that refuses to run in a sane OS.
That's not a very good threat model. With a little bit of sanity in browsing and downloading habits, the likelihood of getting a non-targeted virus is extremely low regardless of your OS.
Actually is better in desktops than in laptops, most of the issues I ran with Linux were in laptops ๐
To be fair, most of those are driver problems. Pick a Lenovo, HP, or Dell enterprise lappy and those problems go away (because they upstream the hardware specific drivers as they sell packaged Ubuntu or Fedora or Red Hat pre-installed)
linux has always just worked for me until i install it on a old imac
then i had to add some drivers myself.
I remember all the problems with broadcom wifi chips back in the day, specifically
i hate broadcom
who doesn't? ๐
good luck
thanks
the main part to get in took shadow hours
Yeah, but do you use it as your main os? and what distro is more stable.
reminds me of cave game
total time spent to beat you're in a cave == 48 hours
spread out over 2 weeks
which game is it?
โ ๏ธ
an old text based game
that looks like one of my first computers when I was a child ๐
hello
Oh no
I had a moment last night I thought I accidentally deleted windows trying to get a virtual machine
you won't miss much ๐ ๐
How do i manage disks on linux ? I dont care , im going to delete windows
do you mean raid?
is anyone specialized building android os?
i have few questions if u have time
if u are reading this later u can ping me if u can add me friends it will would be well appreciated
thank you
I have installed windows on hdd , i want to delete everthing , use this hdd for linux
Just ask on here.
Get an answer faster.
REDUNDANT ARRAY OF I DEPENDANT DISKS
yes. I use Debian and Fedora 42 daily on workstations and work laptops.
Honestly, fire
Thank u scrubz
I could just let things the way they were
are all these premium rooms
most of them are !
if you want to install linux don't worry about the disk, partition is part of the instalation
but you need to have basic knowledge on that or else it will not work,
They have Windows' efi on the drive they want to install Linux to, I said it would probably be best to move it onto the same drive that Windows is on before installing Linux because when installing Windows, it likely saw that EFI was already on the other drive and didn't install it again (just reused the same drive)

Those are modules, not rooms
the rooms in them
Now im facing another problem
you have a guide part, even some distros do it almost automatic
My hdd is not showing on linux
Which page is this on?
I couldnt
may be you need to format the partation try that
Jr Penetration Tester
but he didn't want windows anymore so there is no need ๐ or maybe I read it wrong
Earlier they were going for a dual boot
hey any suggestion to find my first bug !!
update
Yes but it didnt go well, so now im just using linux , F windows.
i give up
I can use my friend computer to use windows
yes, if you go for dual boot you just leave a junk of disk and tell linux to use that
I think im just going to do all of this again, and format everything again and delete everything
after linux windows are like no never
I think in this case the problem is with the user, not the OS.
May be
but windows has lot of dependancies
I wouldn't even say it was a skill issue.
Intro - no, not all are
Burp Suite- Yes, all are premium
Network Sec- no not all are
Vuln research- no not all are
Metasploit- no not all are
Privesc- no not all are
If you click through the rooms, you'll be able to see which ones are and are not free
I'll pass on some feedback to our team to possibly make it a little more easy to tell the room type
I didn't want to say it was skill issues, but it was skill issues ๐ ๐ ๐
have fun ๐
U could just help instead of saying im having skill issues
jsut let us know where are u facing the issue
hello everyone i would like some recommendations on books for bug bounty consider someone like me who has no deep knowledge on hacking, i manly want to focus bug bounty on web application. Although i did ask this question in bug bounty channel i would still like some more recommendations
Its ok, i will just try to do it alone ๐คทโโ๏ธ as i always do
that's what she said ๐ ๐
or just watch couple of youtube videos first then it will be better
๐
or he can read actual documentation and maybe can learn something ๐
I got many warnings for being like you @blazing granite , but for some reason staff doesnt tell u shit about your behavior
๐
jsut go on and fix the problem ................
nobody is like me. I'm unique ๐
Backup.. backup the backups .. Snaps , ThimeShit...
and then backup a bit more ๐
And when ever need, just restore from snap..:)
I use timeshift, clone disk with clonezilla, and the real important files I have it in an external sdd, usb and in 2 cloud services, call me paranoid ๐
๐ถ
Love Timeshift , and rsync to my servers...
I remember when i was young and did like the guy รถรถi asnwsred, when things get broken i format c: reinstall what ever os . But you leran from mistakes.. Hopefully
it's easier to burn down everything and try to figure it out the error and the solution ๐
brake it, fix it use it.... Repeat:)
harder better faster stronger
not the best or most productive, but easier, most people nowadays go for the easier one ๐
Think about that one again ๐
100% i was thinking about post the video for it:)
Also, yeah, considering you were asking for step by step instructions for a fairly basic administrative task, I would say that was a skill issue...
technically brake it fix it would be closer to technologic
This is why we use IaC ๐
Buy it, use it, break it, fix it
Trash it, change it, mail โ upgrade it
Charge it, point it, zoom it, press it
Snap it, work it, quick โ erase it
If you brake it and fix it manny times after some time it dont brake so often:)
It's "break" in this context.
Love DaftPunk
people here come thinking is their private tech support line. I will point you in the right direction, and help you but I'm not going to do the work for you ๐
Brake is what you stick on a moving object to slow it down
This
That's how I learned ๐
As relevant in 2025 as it was in 2006:
https://slash7.com/2006/12/22/vampires/
Just another WordPress weblog
hi muiri & co ๐
Heya Ben ๐
big same
How's tricks fella? ๐
Meh, I spent a lot of the last week upgrading a portable proxmox cluster
portable
proxmox
I would now like to crawl into a 6ft hole and fill it in with dirt and flowers.
Think LAN party CTF
shadow will never get to see daft punk live now that they disbanded
hehe, you're right, my English can be pretty bad sometimes.. but Chinese is worse ๐
No... Worse...
4 HP ProDesk 400 G3 Mini usff boxes.
I have, uh, thrown as much hardware as I can at them
always wanted to see daft punk. They were the first CD album I ever brought with my pocket money from my parents.
I've seen deadmau5 live twice but not quite daft punk (as much as I love deadmau5)
LMFAO
you weren't joking when you said cluster
peak
times
They're all now on i7-7700T processors. Cluster has a total 128Gb RAM (up to the maximum 32Gb each node will support), and collectively about 4Tb disk space.
took forever for shadow to realise you can buy daft punks albums on qobuz D:
I am hoping and praying this works 
Man, the less Windows I can put in here the happier I will be
So sad....
^ +1
which is better having a mac or windows
+1 ^
i love IPS
Will be using LXC containers as far as possible lmfao
at what point do you just do a docker cluster bmt
at least mac works ๐ ๐
hmu if you wanna try my docker implementation for CTFd
so that teams deploy instances in their challenges and have a challenge per team/user in a team
Don't tempt me
not in that way will will work smoothly ?
two docker clusters
๐
100 users ezpz
Actually, that legitimately could be cool if you've got it handy?
Definitely gonna have a few docker challenges in there
admitteldy the security kinda sucks
the whole TLS verif for docker hosts doesn't really work
sorta does sorta doesn't
Is that a docker problem or an implementation problem?
so you gotta do password auth to exposing docker API on the hosts 
both
a docker problem but an implementation in the sense I was too lazy/time pressured to fix it properly
I feel like a reverse proxy might help with that?
lemme grab the CTFd plugin code for you
mTLS terminated at caddy or something
yesyes
still gotta expose the docker API
I mean
you can theoretically import TLS certs genned on the docker hosts if you can fix the code 
but for LAN shit I didn't really care tbh
But yeah, if this works the way I want it to, it should be pretty cool.
Doing isolated SDNs for each team, plus a shared subnet for any challenges that aren't affected by multiple attackers.
All handled with Terraform
sorry, forgot I couldn't swear let alone breathe here
Neat little TF module to spin up network infrastructure for each team, plus Kali, plus dedicated challenges
Then expose it with Guacamole so the lazy gits don't even need to RDP
Yo how to recover old account
Second time today I've had a chance to use that GIF.
so you have it.. ? sat down today and started setting up an isolated environment with Proxmox and then something lightweight like a server and focker continers that are started uniquely for a player or team only for that session over SSH.. haven't built my own CTF before but am working on a project with CTF/ARG ....
the TLDR is:
- Have one or x number of docker hosts
- Have the challenge images on the hosts
- When a team registers, you can set an option in CTFd to set the challenge to be a docker image and it'll deploy a container based on that image across the hosts
- You can choose if only the team gets one container per challenge, or if each user in the team can deploy the challenge
- Manage within CTFd amin (which is quite flaky. It's more useful for mapping users/teams -> containers than actually managing. I'd recc managing the container on the host itself...but good for identifying who deployed what) the containers i.e. kill restart etc on the admin panel of CTFd
Nice!
this yap was very informative
I don't want yours, but was just wondering in general since I'm currently doing it myself... Nice coincidence that you brought that up..
built it like 2/3 years ago for running CTFs at various events that use CTFd as the framework/frontend
The TLDR of it is here #general message
Doesn't use SSH/Proxy or Promox, though I would like to extend it to using the Proxmox API in the future so you spin up actual VMs instead of containers. Basically just deploys a container on a host for the team/user on CTFd, giving them their own instance (like a web challenge) to hack with, so if they break it, doesn't break anyone elses
Pretty much a:
- User/team deploys challenge
- Spins up container on host
- CTFd gives them a domain and a port within the challenge card/modal itself
- Container is dedicated to them
Roughly the same idea as my terraform implementation, but runtime rather than prep time
@lone thistle GET BACK HERE!
maybe looking to OSS it but the code is ugly and janky af
would probably do when I can get it to plugin with Proxmox
but I am lazy so
would be cool to have the same as the above for CTFd but it spins up a VM for the team etc
Heh, dare you to integrate with AWS and GCP as well
ironically easier
I just don't want to pay for it 
I think for about a 150 person CTF event
two docker hosts on 8gb & 4cpu done the trick
cheap as chips really
Tbh, it shouldn't be too hard to abstract it up into a plugin system for the plugin, right? Like, plugin expects set API endpoints for the provider, satisfy those and it slots right in
Tell me about it. Proxmox API is a pest.
Yeah I mean, at the end of the day, you just provide some info here to CTFd to display
what the info is is kinda up to you
if it's an IP of an EC2
A domain with a port etc
up to you and budget
I just did not feel like paying for 400+ instances on AWS when x2 2vcpu & 8gb hosts done the trick (where split between them was 200 containers at peak)
Actually, I revise that statement.
Proxmox is a pest.
We love it anyway though.
Mr Docker King
spinning up vms and ec2 is a arse
oh I love proxmox
even moved from esxi to it
Same
I love but also hate doing anything programmatically
It's still a pest 
It's like the equivalent of Windows and Linux
the console access sucks ass gravy no matter what you choose
oh yeah put SPICE on a VM
install 40 libraries to support it
Proxmox is to ESXi what Linux is to Windows.
Free. Equally powerful. But an absolute fucking nightmare.
still as slow and featureless as the novnc console VNC
oh yeah download the .pve file
fk off
just throw a VPN on the network and SSH/RDP directly into whatever you need
100000000000% sanity plus
Guacamole is a lifesaver for that as well
aight food time
Ditto
then I find the code for the CTFd tingy
fuckin love guac
GUYS WHO TOOK THE SAL1 EXAM CAN I USE OUTSOURCE HELP?
Right? That's another piece of software which is a pain in the arse but so so powerful
like AI aiding me in report writing or no?
SSO is a nightmare with it.
don't get me started on Guacamole 
I mean, if they're using AI to mark it ๐คทโโ๏ธ
it's like a stockhome syndrome thing
Right?
Yes or no bro xd
I spent hours trying to get it working consistently with Keycloak a while back
I've never tried to rdp/ssh guacamole ๐ ๐
Ended up with the most disgusting workaround imaginable. From memory it involved openldap and user federation.
I get it.. What I'm doing is for fun and to learn... A VM for each instance is perfect, but not what I need.. What I'm mostly concerned about is that certain things happen via SSH and then with the help of a unique docker for each service and then the environment itself, when the session is over it's gone, and a protection for the other VMs in the cluster, but of course with different jail/container break out protections etc..
Dont use anything LDAP for guac if you can really really really avoid it
Now you tell me 
But yeah, from memory that worked... just
Oh, it does.
My memory is that it worked marginally better than trying to do it with OIDC claims
oh bestie
Although come to think of it, that might not have worked at all lmfao
okay food
brb 20 mins
got a sweet one
ยฃ37.58 which is a few meals for the next few days for 12.43. Rider codes go crazy
pucka
Cc @shell nova you need to find a vulnerable keycloak
What vendor is this from?
???
Deliveroo in the UK as a rider 
Oh as a rider, gotcha.
I should try Deliveroo sometime. I usually only use Uber Eats.
in my experience as a rider/delivery for both as well as a consumer after, it really depends on area. Might have better offer/availabililitry for either of the areas. The one plus Uber has is that a lot of Uber drivers are also Uber Eat drivers, which expands the pool a lot
Your best shot for an answer is to email them. They reply pretty swiftly.
support@tryhackme.com
external help is considered cheating ๐
aight ima consider this but i just wanted a faster answer
damnn
Deliveroo riders aren't also taxi drivers unlike Uber drivers (for the most part, as uber eats usually integrate into the "uber" ecosystem), so usually a less "availability" on that front, but they counterract that with good deals. Just depends on the area/resturants etc. Deliveroo has been super expensive in areas I've lived whereas Uber Eats / Just Eat hasn't, all of the previous is vice versa. Had areas where Uber Eats was much cheaper
Hmmm I don't know if Just Eat exists in France.
and that's was our today's delivery tip ๐
but the exam is openbook btw
what i heard u know
open book doesn't mean asking other people for the answers ๐
no no i didnt mean in that way hahah
If I know somebody call book can I ask him? ๐
i meant in organizing my report
It doesn't say "call book" does it? ๐
@lone thistle
I'm thinking a little about the fact that out of nowhere I'm sitting here thinking about and currently setting up my own first ARG / CTF and have barely mentioned it to anyone and almost at the same time I'm thinking about the best solution for setting up my VMs with docker and more or less the same setup you wrote about, I look into discord for a little break and see your post.. I mean, sick coincidence ... Or.. I believe that the universe and quantum are connected to consciousness.. If that's not it, I got my money's worth when I joined "TryHackMe" and now I've been hacked by you so you see what I'm doing and my notes..:P (well, of course you haven't. Or...?:D )
Iโm so bored tonight
Do you guys ever need specialized code editors while using Kali Linux or Parrot?
I should probably update that thing
hey guys uh do you have any recommendation for bug bounty books for some one like me who have hardly any knowledge on hacking
You should learn fundamentals and stuff first
Don't expect to find a bug and get rich quick.
Arenโt most under 200
i know but i would like to know some books to read
yeah i do want to learn fundamentals and all the basic stuff before going to tougher part of bug bounty but for a newbie like me i want books to start somewhere atleast im not asking for me to give some high level books and expecting that i would become a expert a bug bounty i want to start somewhere
First thing about this field you will need to learn is how to do your own research and to become as self sufficient when it comes to your education as possible people arenโt going to be able to do it for you.
An easy resource you can start with is thm itself #start-here
Will guide you through basics itโs not books but will help you grow
i did try some of the labs which were free but i want something little bit more in dept or bit easier to understand and the most labs that i did want to study or explore where premium so i can't go through the ones i wan the most
Personally I choice thm as an investment over books because the information is already there
There is also huge live hacking tutorials, videos on basics on YouTube. As I said the best skill youโll learn is how to find these resources yourself
i see
i mean sure why not
lemme make a media fire
๐
ayt
lololl
I am thinking about putting Debian on bare metal since my laptop processor doesnโt qualify for windows 11, and windows 10 support ends in October. Any thoughts?
i use kali on bare metal along side windows. its a good way to learn. ill tell you that
10 mins until upload is done
alrighty
Thanks for sharing
Gave +1 Rep to @static acorn (current: #600 - 10)
What does ๐ก๏ธ CYBR mean?
Ty
i think the best part of installing it on metal is it forces you to fix a majority of your problems on Linux rather than just installing a new vm. sometimes its take minutes. sometimes it takes hours or days. but it really helps you grasp the components of the os and what everything is responsible for which is worth its weight in gold
honestly that sounds scary to someone new like me
learning can be scary. but.. you'll get better
dats true
does anyone know how to become a intermediate or advanced user for KOTH
change it in the settings of your account
where it asks for your skill level
i had the same problem
thankyou
CYBR
ofc
i do
it says easy so i would do it and see lol
ehh just try and poke around
Just use
https://easyupload.io
thanks
Gave +1 Rep to @bleak quartz (current: #514 - 12)
Np :)
Do not trust THM in that shi
60mins estimated time -> 3-4hours
yea true xd
Also I want the books too!!
naah an hour is exactly 300 mins
So once it's done lmk
Real thm logic right here, you must be a room developer
me too i also wants those books
yes and also a room tester
Format: 2รCD, Year: 2011, Labels: Aniplex (SVWC-7749), Aniplex (SVWC-7750), Barcode: 4534530044211, Length: 2:15:58
this album is a banger
@bleak quartz @sturdy river @autumn thunder https://easyupload.io/girg1j
thank youu ๐ซถ ๐ซถ
Gave +1 Rep to @knotty pendant (current: #700 - 8)
yw
throw it into a large peilcan case and include a router - ez pz!
thx you ๐
Gave +1 Rep to @knotty pendant (current: #645 - 9)
:/
yeah for me it shows up as private;-; but sounds interesting!
arrives
it's easy
Copying me ๐คจ
Yes

Unironically I am actually carting it in with a single backpack.
4 Proxmox Nodes, 2 switches, a wireless access point, and a huge number of cables 
Lmaoooo
Hello evil people, i have a C program and i want to analyse with objdump. My computer is 64, but to facilitate things i compiled the program with gcc -m32 program.c, so my question is compiling him to an elf 32 bit simplify the analysis when decompiling with objdump?
Eeeeerm
meep meep moop sleepity sloopity sleep sloop to the beep boop
firstly we arent evil xd. secondly what is this for?
why do you need to know the motive
i'm reading the book art of exploitation
hacking the art of exploitation i'm in the part thats we are using a legacy version of ubuntu that dont have the atual memory defenses, and trying to reverse engineer compiled elf 32 bit programs to corrupt memory
the part of the exploitation needs to be inside the vm
cuz in today computers we have a ton of memory protections
Yes
thank you
finnally
but when i'm only analyzing the binary in my principial machine that is 64, if i choose the flag in gcc to compile to 32bit the output of objdump will be the same as if i compiled the program inside de 32 vm?
If I might ask - how would it simplify it? Wouldn't compiling it to 32bit elf just change regiters to 32bit or do I miss something here?
i think maybe in the objdump in the 32 file will be easir to analyze?
Yes
I'm obv not Jabba but it's due to simpler instruction set, since x86 has fewer registers and simpler instructions than x64 it makes it easier to read at least
Smaller registers, different instructions, different protections
i swear one day ill be able to participate in convos like these and know wtf is going on ๐
One day I will be able to type a whole sentence without typos. One day...
thank you ๐, ngl i was dying with curiousity on what the underlying principle here was
Would different protections be something like larger ASLR range and Stack Canaries?
nah man, if youre anywhere near gen z, we had a virus installed in us at birth to prevent proper grammar ๐
gen alpha tho ooof
they got it much worse ๐
Yeah it would, cuz protections like that act differently
which affects both exploitability and reverse engineering
Correct,
Okay, thanks a lot
Gave +1 Rep to @mossy river (current: #6 - 1595)
True
lmao
very thanks to you mr Jabba evil man
Gave +1 Rep to @mossy river (current: #6 - 1596)
maybe god forbidds your sins
Ahoy everyone! hope everyone day is gooood!
maybe if you learn how to spell ๐ ๐
dont respect english
only respect code
AHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUAHUAHUHAUv
English has its own code, it's call grammar ๐
if the machine dont understand so do i



