#general
1 messages Β· Page 1062 of 1
if a very blank language
nothing to beautiful and complicated like the languages i cited
so i dont give the effort enough
and one of the principal countries that utilizes english is in a phase of atacking even their closests allies
the trump administration almost cancelled the cve program database
how the fuck i am suppossed to give myself time to learn the language of this stupids hahaha
i forgot about a language very good and beautiful
the chinese
of boy
if i was smart enough to learn
What in God's name are you talking about..?
A... What?
so i'm not the kid in here
Percocet?
Hello Muiri! π
No day passes by without me looking at that insane discord bio.
Wish I could end up in the same position as you, but it's quite impossible in France lol.
OffSec is dead.
How so?
Where do I start.
Job Ratio: 50 Blue Team for 1 Red Team.
Oversaturated market, and very little demand.
Curious. Why the low demand?
In the span of 6 months, I found only 3 Red Team operator job openings in France.
And I search hard.
Any hits for pentest?
why your osce is ^3 ?
According to my colleagues and friends that were here previously, it has always been this way in France. The offensive part of security is practically non existent and pentests are really rare.
Clients just don't like pentests.
That's interesting. Do they have an alternative?
Not at all. But they do dump HUGE amounts of money in security.
So basically they're focused on detection rather than prevention?
Yes.
Interesting choice
Google it, we have data leaks everywhere in France.
Government facilities, phone operators.
I'll believe ya π
We can't exactly comment considering we've had 3 major retailers down in about a week and a half.
lol.
thanks
Gave +1 Rep to @pallid lotus (current: #10 - 874)
But yeah. Pentest job exists, just very few. I'd say by searching casually I found 10 openings throughout the year.
For red team around 2 by searching really hard.
But hey, I'm not giving up on that CRTO cert.
@shell nova remind me, are you in France or Canada these days?
sorry to enter in your guys convo, but seeing your profile, do you think that binary exploitation is an active field? Or is a little dead? i find it very cool, i'm rereading hacking the art of exploitation and want to get shellcoders handbook, but sometimes i wonder if i'm not entering in a dead field
It's not dead but you're kinda limited with it as a career path
Oh right I think Hydra speaks french?
If Hydra was in France before 2023, I'd love to know the state of the market back then.
because everybody is piss from red wine π π
There are still some private vulnerability research companies, but a lot of the remaining roles are government
do you have a like an adjacent field that you can indicate to someone that is interested in this area? What would be an alternative? malware analysis, exists other than that?
Malware analysis would probably be the closest, yeah
Yeah, you're in one of the roles that does still need it
pentester like in the bio?
Niche hardware testing -- like Zumi does -- and wider SCADA / IOT testing are the places you're most likely to be hunting for low level exploits now.
That and, again, some governments (probably most of them) like having exploit developers on staff. You can probably guess why.
cuz memory corruption there is a ton of protection is almost like old school hacking
Yeah, niche jobs like maldev and red team developers are most prominent in gov facilities.
yes, I know somebody who works in Mount Blanc that does that π
Depends what you class as "fun".
A lot of offensive security is reporting. It's not how it looks in the films.
Personally I would say maldev and red team ops. Others might say pentesting, or specific pentesting fields.
There's a lot of cool stuff going on in cloud and AI security research just now.
thanks for the chat guys
but i think my heart is beating too fast
i will laid down now
That'll be the opioids
bye bye butterflies
Opiates?
shhh
Opioids indeed
@pallid lotus Sorry for the ping - But aside the website in your bio, is anything about your carreer public? A linkedin? Anything else?
@static acorn check yo dms
I don't use social media much. My blog is also in dire need of a refurbishment.
I've got LinkedIn and Twitter floating around, but I rarely use them.
Oh alright. If there's a time where you start sharing something about your work, discoveries etc. do let me know.
Will do π
i responded lol. sorry i must have forgotten
my arm is itchy
My entire body is itchy. Not sure what's wrong with my nutrition.
Maybe too much protein.
alr
i put itching powder in all your sweaters muahahaha
my skin is peeling cause of my tattoo π
whatttt
not my best blurr
I did after months of trying. NT authroty from reverse shell only no gui
i have shivering in my body
approaching 25 hours of no sleep, crazy
had some days of 25-32 in the past year
i think my computer loves me back
for once
someone loves me back
no one's more loyal than your own computer
not always true... js
sometimes your own computer is.. not your friend or ally at all..
wsp guys I'm selling neymar information data, if you want, dm me, i have all prints with proof
well all relationships have their ups and downs
Sorry if Iβm taking your time or space in this amazing group. Iβm 14 and just got a high-end PC. Iβm not into games like Fortniteβinstead, I want to learn about computer security, programming, and everything related to the world of PCs. Iβve already installed Kali Linux and would love to know how I can start learning and improving. Any advice would mean a lot, Thank you
Did you install Kali as your main OS?
Nono , for Made it more simple I install it on a vm
I mean.. when your computer starts doing stuff without you even knowing about it.. is it really your friend anymore?? π€£
cool cool. You found a good server to learn about cybersec. π
Good
Make sure you read all the #start-here and sign up on the website if you haven't already. You can connect your THM (Try Hack Me) profile from the website to the Discord. π
maybe is hunted π
hi
like does it direct u to my profile? just to confirm
open in incognito, and check out π you're asking in a sever of cybersec that people click on a link π
stop being unrerasnably paranoid, someone using disc for 7 years won't spread illigal malwares here
yes, yes they would
Then u both use a vm for that or a sandbox or not comment at all lol
You're in a discord with people you don't know. And someone gives you a link, random link, shady link.
We're not going to go "Oh boy. A link, lemme throw that into my browser on my computer and hope it's not malware"
We work in info sec, it's second nature for us to be suspicious of everything.
Bella, I, Rex, alt, muiri, etc, we've been here for ages now. This ain't our first rodeo, and certainly won't be the last of shady people.
definitely chose the wrong audience for random links clicking π
sus too u can't read the official domain of discord lol?
and it is ok to be sus but saying i am not clicking links at all is extreame
because nobody can clone a website π
You can link text on Discord by typing an open and closed square bracket, followed by an open and closed round bracket. Put the text you want to be linked between the square brackets, and the link between the round brackets. Example: (https://slurptech.com/) Remove Discord Link Preview Embeds When linking to a website you can place an open and c...
there scanner out there, sandboxes ect u can use a true cybersec proffetional will be cautious but not totally avoids links
27h of being awake and I feel way less tired than I excepted
because I am mining bitcooin in ur brain bro π via cryptojacking
we just rated that the time for us to do analysis on the link was longer than it would take for you to open up an incognito and test it yourself
Once I was 43 hours awake it was mental π
as a true cybersecurity professional, we value our time
Wanna know a magical thing? www.google.com
sus link
what is google
probably malware
try and click on it
that's what I said, ask to click on a link that you can do it without anybody help is not dodgy at all π
I am scared of links 
like yall
u guys get nightmares about accidently clicking links
this is why we don't click on random links, it was a redirect to youtube
this dude worest nightmares is links absolutely 
he probably things they were the worest investion ever created+ hates the investor of then'
m
I don't get nightmares. I'm the nightmare π
You that like it hasn't happened multiple times over the past 3 years alone.
I fight the links as a matter o fact sometimes i try and find random .su and .ru links to see whats going on
ur lying u get malwares on ur dreams
just to show the soviets that there ccTLD doesnt scare me
I get random phishing links to steal my accounts. One had a socket.io to Moscow 
it's proabbly normal links and ur just paranoid lol
eat them for breakfast
in fact i found some random persons old blog from 1997
What part of, we've been here many years, never clicked with ya?
We can spot phishing links from a mile away, I throw it in browserling, urlscan, whois, etc etc.
We're not going to click a link based on "trust me. It's safe"
If @blazing granite gave me a link, I'd still be skeptical if it's a domain I don't recognize, but it's also about merit. Rex has been here for ages, he's trustworthy.
random guy at Defcon
"Here, scan this QR code, trust me, it's safe"
Well, who the fuck are you?
browserling, urlscan?

ok so why u scared of opoening in sanbox?
swearing is against the rules here
As Bella said, we value time.
And so is mini-modding.
trust me it's safe, big alarm in my head, why you need to tell me that is safe, why the reassuring π π
ok ur steam and netfilix account disagree π
nah man, I am at a ctf
it's crazy fun here
Do you, by chance, mean "merit"?
Yah, autocorrect.
trust me it is safe, now I challege yall to prove me otherwise
That's not how trust works.
I don't even trust myself π π
You are the one making the claim about it, demonstrate it is safe.
lool
nah ur the one suspecting
it is ok tho I figured it
I mean, you don't understand burden of proof. So good luck.
don't use betterhelp, it's a pure scamming service
they don't treat their therapists right
isn't that all therapists tho, it feels that way
it's the company, not the therapists
the better help is to run far and fast from there π
how do u know?
ive just been vibing to music for ages now
something called research
Because there are mountains of documentation of betterhelp acting in bad faith with both therapists and customers? It's the uber/doordash model applied to mental health care.
u talk weirdly but ok
Hello everyone.
huh
Wait..has there been any mod changes since I've been gone?
o_o

FIND ME AT https://twitter.com/DoryStentorian De-dum-de-diddly-dum-de-dum...
POV me trying to fix a nonexistent bug and end up bricking a perfectly fine docker image:
Alright, I'll wait.
Shoot
Yay! My computer loves the new update!
@cloud quiver @sick lance
Morning π₯±
source: trust me bro lol
(i did scan it tho. trust me bro)
sway is the way
l@2025

hello
iam new to ethical hacking can u help me , how can i learn ethical hacking for free
π₯²
THM rooms
Also has anyone seen the shenanigans going on with Shapes, Inc.?
Very funny
See @intro
Me too
Yeah start here
The one and only turkey
Use them often when you can
use linux daily, you'll remember the commands that you use all the time, nobody remember all linux commands there are too many it's impossible
Also Cheatsheets help
Me when really obscure Linux commands
Isn't that an operator?
For bash
I've been using Linux since 1993 and I even don't remember every command, often I have to man commands that I never used or I used once in a while
not only the commands, every commands has many flags nobody can remember them all so you shouldn't even try π
I remember the commands I used over and over again
Hi
Anyone have Ruby on Rails experience? I'm so completely lost on this box
post in #room-help maybe people can help you there
Thank you!
if you're talking about piracy, you're in the wrong sever
Hello chat
Hello
Evilginx
phishing is not to be discussed here tho ...as per rules...just saying
wait fr?
what does it have to do with pirating
which rule... kindly point it out. We're not discussing about hacking anyone. He just wanted to know about a good phishing tool and I said it
idk ask scrubz
welp... nah you pointed it out. Since a mod said it, it's now a rule
oh.
just open up burp suit, run a proxy like mitmproxy, route ur browser traffic through it, and watch every request that URL triggers. if itβs doing redirects, dropping suspicious JS, or calling out to weird IPs, youβll see it right there. heck, use wireshark, filter by http or even look for DNS queries β sometimes these links call home to C2 servers or leak data via GET params. u can even curl the link with -v or --trace and see the raw HTTP convo
wheres the link?
can u send me the link?
it wasn't mine, somebody was asking to click on some link π I don't know who wasn't I blocked him after 5 minutes π
welcome
Send me the website link on my dms
I wanna investigate.
My Nitro is gone π

They are usually shortened versions of longer names sometimes, try to see if they correlate to some complete word, connected with their function
Hello, I have a question about what is the purpose of tickets in try hack me?
practice
It was for the event that ended last October
okey thanks
Good morning
Done!
Fr
The one thing you never want to see when running automated scans
Hi guys and girls, is the Fliper Zero a good toy to play around with?
If you got the money for it, yeah
What does the X denotes in the CSV report of the eyewitness tool (the tool used for screenshotting) ?
That's a built in Kali tool
can't shake this dude off my tail π
Yeah, I have seen the price, but I mean just in general tool for learning NFC and more things to safe from
imho it's great, since it's not just limited to NFC or RF
I think it would be great for me because I'm studying Cybersecurity at the moment.
But still don't know whether I want to be Blue or Red team
learn both sides, and you can always split off to what one you find more enjoyable
Come on!!!
but generally knowing both, or at least the basics of both, will give you better leeway when you focus on one
Do harder rooms
True
Itβs what I did
i am 95% done with cyber 101
Also noticed that it is valuable having having knowledge in both if you are trying to pursue management level roles
I'm waiting for some automated scans to finish
I've got plenty of time since there's like 30k nodes it's scanning rn
can anyone help me with a simple javascript issue ? not related to thm i was studying for my exam tmrw in fcc and idk whats the issue or error
Holy shit nice
The life of a soc
not exactly soc, just general enumeration rn
Thanks, @knotty valve yeah, I think you're right about understanding both will give me more understanding and advantages.
Gave +1 Rep to @knotty valve (current: #415 - 15)
alongside uni cybersecurity
before I go hunting down vulns
reread the steps
it tells you what you need to do
Hell yeah: you cannot miss a day
Check the spaces
i did
that's not it
let me try
Codecamp says what the issue is lol
the solution is in the steps, best I can suggest is to read it more carefully
What's with the JD Vance memes recently everywhere, lmao
otherwise I'd just be telling you the solution
ahm i tried spaces it seems to not working
What exactly is the issue? Do you mean the βichigoβ thing printing twice?
i can't see much apart from this
my task is to concantinate the strings in console the ouput is concatinating perfectly and after concatinating i should log the the bot variable i done that tooo but still its saying i have not passed the code
because you don't have that variable
Hmm I donβt see an issue with the code itself, but maybe try declaring and assignment on the same line
not the issue here lol
is there a way to bypass Amazon WAF
You ainβt actually helping you know
Because the answer to their issue is literally in the steps on how to complete it
but in js its not a syntax to do like that right?
they tell you what variables and methods you need
hi, so i'm doing pre-security path rn, do i have to setup or do any config rn in my device? or they teach later how to do that? I've not done anything like setting up vpn or like that
the issue you are pointing out is using + operator for concatination right but i have done it
no it's not
the issue is the fact you are misinterpreting their steps
This ^
I get that you want them to figure it out but sometimes you give them a close hint at least
I have
twice now
^
TRY THIS let botIntroduction;
botIntroduction = "ichigo";
botIntroduction = "My name is " + botIntroduction + ".";
console.log(botIntroduction);
which variable bot?
Still not what's being asked
you don't have a bot variable
thats the exact code i have written
They definitely used ChatGPT
ChatGPT would've gotten this one right lol
its being declared in previous step in this step its not required to declare
not to be rude, but this is just a moment of weirdly written questions
this is my entire code
unless it's just not been briefed correctly
you're not declaring what they're after
they tell you in the steps what variable
??? isnt this correct?
With the full code that makes it easier lol
π i still cant understand it lol
let botIntroduction;
botIntroduction = "ichigo"; // Step 1: Store the name
botIntroduction = "My name is " + botIntroduction + "."; // Step 2: Combine and store sentence
console.log(botIntroduction); // Step 3: Print it
issue is still with the variables
but not what I initially thought
oh
Because I didn't have the full code i assumed you weren't assigning bot at all
you're still misreading their tip tho 
the tip tells you what variable
yah
bot is assigned at line 7
bot variable i tried it too
Yeah, I know that now after having the full code lol
still error
i tried the variable bot too but it was also wrong i cant understand where iam wrong in my pov im going on right path
what's the tip above it say?
I think you may have the order of operations around the wrong way
tghis is the tip
yeah, you're supposed to concat on the variable, then console log the variable
in steps:
- create variable
- assign the concat string to variable
- log variable
isnt that i done ? i created a variable assigned a value assined concatination and atlast loged it ?
wait a sec
I admit they did word that tip weirdly
this was the eg i got for reference
fr π π€£
yh but the isnt the question is to concat the string?
in the steps they tell you to do it, yes
in all other aspects, you'd have done it right
but it's just not done in the order they want it
haha i think im high lol i cant take it
π
maybe take a break for a couple of minuts
Simplified steps of what they're asking
can always come back to it later
i wish but i got exams for these tmrw so i wanna learn
Prep for your exams first lol
haha this is kinda my preparation lol
what is the exam about?
front end dev html,css,javascript,lil bit of j query html and css are simple i wanna focus on jscript and jquery tho
haha i should lemme go grab some snacks and get back to it haha... apreciate your help buddy β€οΈ
ok, and good luck for your exam tomorrow
Also in future: With code problems it's better to send all the working/PoC code lmao
tnks
point taken soldier haha
How would you retrieve the items in the current directory with size greater than 100?
someone help please im stuck at this one
get-childitem | where-object -size <100>
i did this but its short by 11 words
get-childitem | where-object -size-gt< 100>
Morning..
hehe, this on is cool.. I recently read an article about a guy recently succeeded in running Linux - in Excel. A bit nerdy maybe but really cool π
What delivery, I canβt see one.
that yellow box ig, if that was for me, i must have tripped -_+
I was being sarcastic lmao
Ah yes "safe place"
It's even funnier when they think putting the doormat over it will hide it
Very safe
I've messaged one of my neighbours to ask if he'll take it into the block for me
Nice
My housemate is usually home when I'm not so I just get them to do sign packages for me
HAHAHA this is honestly a crack up!
Keep up to date with us!
------------------------------Β---------
Like us on Facebook - http://on.fb.me/1EjsU5U
Follow us on Twitter - http://bit.ly/1URIEEt
Follow us on Instagram - http://bit.ly/1NyZC4C
Yeah it's food so π anyone is welcome to steal the meals if they are that desperate
Confirming blind Injections would be using a ping or a http request to controlled server, yeah?
Ye, if you couldnβt ping them before
If it wasn't blind, I'd be able to see it
Was just wandering so I knew if I'm building additional tools correctly 
While I wait for my current toolset to finish the very long and arduous process of enumerating 200k nodes
Cause apparently it discovered even more
Ash scanning her whole state
This is a single service btw
Bruh
It used to be more
But they culled 150-200k nodes this week
Random question, but how does the memory in a VM work? Is it shared with the host or is it isolated off in kernel?
It's shared.
So you have 8GB and assing the VM 4, you'll be left with 4GB for the host.
Wouldn't that allow for an advanced malware using ICE to spread from the VM to host?
It's rare for a breakout, it can happen.
But most threat actors have a way to break out VMs done make it public, it's not common knowledge.
I'm reading a malware analysis report and it was an an idea that propped into my head since in-memory malware usually are very hard to identify
The report was specifically the MRm-DLDet framework
Ah, you mean can the nalware attach to the RAM that has locked from the hypervisor for the VM?
Yeah
I donβt understand where I did wrong
Thank you
It's... annoying.
If you assign yourself 4GB of RAM to the VM, the malware can work inside that 4GB that is locked off, but as soon as you turn the VM off, it stops.
Did you trying to write C not c
I tried C as well
Come on.
I literally just pointed you to the channel this discussion should take place in.
I don't appreciate being ignored.
Umm I alr put it there
It stops as in everything gets deallocated ?
He just asked a question I replied my bad
Yeah, since RAM is volatile.
I wonder if there's a way to essentially "breakout" of that lock
Cause that would handled by ring 0, right?
Or kernel for the unfamiliar
That would be a breakout.
CVE 2017 4901.
CVE 2015 3456 and CVE 2023 20867
It's not easy, and most breakouts happen with something stupidly set by the user, or something like Vmware Tools.
Clone could be one word.
I couldn't think of another lmao
Another way to look at it, is it can happen through Shared folders, drag and drop and clipboard access.
CVE 2017 4901 was running execute code in the OS via drag and drop.
Out of Bounds moment
I know, but I was listing examples of breakout cases as a whole.
this dude has relentlessly fighting me for a week
Weekly.
arrives
Hello I got a problem please help me
What is your problem?
Actually I use VMware community edition and install the TryHackme openvpn configuration after running it using sudo openvpn user.ovpn that connection is successful but after join a room the labs ip address not opening in my browser
Is there any technology that allows people to check for voice changers, redirected call and ai imaging.
it would be hard for calls because of the quality
some ai artifacts might be detectable
but all of this would prob mean they have an ai constantly monitoring every call which is not good
0 privacy
i am tired i can barely read words but i don't want to come seccond
Any update?
still fighting to get #1 back
Okay, you still having issues on KOTH?
Ohh okay
Iβve not been on THM in a few days
I want them to make an icon of a phone on the rooms that can be done on phone (No lab rooms).
That would be none.
how many rooms do you clear in a day or week?
As the website isn't really optimised for a tablet/phone.
a lot
Especially if they utilise a split screen machine or task downloads (or both).
The rooms that you read and answer questions are fine on mobile
I mean I've done it on phone, but its the largest PITA
That was just because I was bored and wanted to try it out
and yeah the content is fine on the screen, but you're cursed if you try using the attackbox 
But itβs just you need to join the rooms to find out if you can do the rooms on mobile.
I need something to do while Iβm on the phone.
Not optimised != Not able
it's sooo hard to keep focus for so longggg aaaaa......
i have really really bad adhd and thm is like the only thing that is actually productive i can concentrate on
same here. most of the cases, I have to read same lines for 3 to 4 times.
rn its because i need to sleep
but that is happening to me rn
it is only 10:28pm but my brain is being pumped with natural melatonin
fair but most of those types of rooms are meant to be educational. i personally don't get a lot out of learning from a mobile device.
keep at it π
whenever I study, I have to study 5 times more to grasp the knowledge.it's become so hard. then I quit early.
do you take notes?
yeah I try to.
I think it is common to have to reread things but taking notes definitely helps. Just the act of writing what you are learning can reinforce the info. Even more helpful is going over those notes again after learning.
Also try to do practical exercises whenever you can so you're "doing" what you're learning.
I'm specifically talking about learning cyber related stuff but it's probably applicable to other areas too
Morning chat
Hello Guys
thanks, but where can i practice?
Gave +1 Rep to @craggy wadi (current: #264 - 29)
hi
That what I will do I havenβt been doing a lot one room a day bc covid but tmw or after I will take a pause to resit everything and re read and understand more
and one more ques, from when should i start those ctf challenges? is there any path /roadmap for only ctfs?
hii
hello I am new to this,and Iwanted to ask how much would the theoretical basics help in the coding parts later on
Here. That is what tryhackme is. You learn then you have the opportunity to test and explore what you learned. I would personally choose a path to start depending on what youre interested in.
like yk the networks,and other theoretical stuff
everything builds up
Most ctfs are pure challenges in which you aren't taught how to do the exploits. It is up to you to figure out the path to the flags. After beginning your learning journey you can try them out. There are tons of good writeups both text based and video available online to walk you through them too.
new stuff will be built up on top of old stuff you know
if you don't know the old stuff it will make it extremely hard
kinda like math
how am i supposed to move on with the courses,like from what i see theres only a bit available in the free pathways
problem with the analogy is that math is entirely practical from the first,here it is theoretical at start
Good call π
so like making notes and stuff?
Kinda fair, although it does go practical very quickly
i did it like for a few days and am yet to make notesπ ( 1 week)
And I got basically my own library for a lot of stuff, although I had previous experience
with diff platforms
yea no me a noobie cs fresher in clg
I mean if you got an insane memory go for it
For me note taking and reflecting helps
Obsidian is what I recommend
yeah i dont have a memory like that
Boutta reach mage soonish!
32 days...srsly... and all tihs
Did you happen to read our rules, when you joined the server?
will try out
sorry will look at them
just more confused bout cyber and CS in general (oof)
You've already agreed to them... π
am level 2 rn(in the app)
Probably should specify, won't confuse people. 
tl;dr
We don't allow advertising of servers.
ohh...thank you....
i have no one to share this but guys reached mage today yay! https://tryhackme.com/p/vivekgh0sh
Hey, are there any email analysis tools to integrate with siem?
Congrats π
yass congoo π
thankyou sage im coming for you next : )
haha you got it.
What siem and what type of logs?
i think splunk has some native utilities or addons for email analysis. id have to look into it though
thanks
Gave +1 Rep to @sturdy river (current: #2857 - 1)
Wdym I can't advertise my super special super cool chatroom for only the gigest of chadests of discordians? /j
Yeah just something that can analyse emails. I wanted to do a project/lab on it. Lemme know if you find something. I'm also searching...
This is the super cool special chat room
are you using splunk or something else?
You could set up a windows server 2019 vm with 365 mail. Splunk has an addon spefically for that https://splunkbase.splunk.com/app/5365
i have a decent amount of experience running splunk and its forwarder on vms so lemme know if you need any assistance.
My emails get filtered through my own AI model and CloudFlares filters
Hey guys, this is more of a Linux based question in case anyone knows, I use alt tab a lot, but it's really frustrating when I alt tab across various different programs and they stay on my screen after skipping through them on Debian, anyone else who managed to turn off this feature?
Wdym?
As in they're constantly set to on-top? Cause that's a setting you would have applied to the individual window
For example, there's 4 programs open, I'm on program 1 and I gotta alt tab past 3 programs to get to program 4
I press alt tab until I get to it, but the previous 3 I skipped still stay on the screen as if I selected them if that makes sense
That's just how your DE works
On Windows you press Alt Tab multiple times it skips through them , they stay minimized
Yee figured, I just don't know what that setting would be called or if there's even a way to tweak it, it's weird behavior
You'd probably have to create a plugin or find a plugin for it, specific to the DE
HI
There might be one in your compositor settings
But that would take some digging through the DE settings
Thank you my friend. It's been a while since I've been on this chat, haven't seen you before I think. Nice seeing you
Gave +1 Rep to @knotty valve (current: #397 - 16)
hi hi]\
Heya
good morning!!
how are you all doing today?
Pretty good, I hope you're doing great as well!
Thinking of hanging out in Paris today, but I'm lazy.
I am! Just hanging out before work π
haha i feel ya
Oh nice, so, does it analyze emails in real time?
congrats
Thanks!
ive never used it myself but the link is there if you want to take a look.
as real time as the logs are ingested into splunk i imagine.
you gotta verify again so we can see the role change. at least i think that would force it to update
quick question, is there a service that offers web-based virtual machines that I can use if my computer is too slow to run VM's?
THM offers such an option for their service
Neat! Yeah i saw that but i didnt know if there was one that I could use for any other projects too or if thats not really a thing
The attackbox is only for THM usage.
Using it for anything else would be breaking ToS.
yeah, thats why i was wondering if there was one that was for general use
not super familiar with it though
I think AWS allows you to host machines. It's paid, though.
neat, ill look into it! thanks so much!
Gave +1 Rep to @gusty inlet (current: #74 - 117)
aws for sure. youre basically looking for IAAS
hes thinking (tryhackme bot)
Yooo
worked
epic
yeah haha i just didnt know the term for that yet, im new to all this lol
have you tried installing a hypervisor and running some vms?
I havent yet so im gonna do that first but i only have 16gb ram a slow processor and 256 gb storage rn
Digital Ocean is cheaper and offers basically the same shi
worth a shot. the storage might be the biggest issue if youre running a few vms but one instance of some linux distro wont be a problem i bet
aws also has a free tier btw
but it has usage limits of course
good to know
yeah sounds about right
i mean i was expecting to pay for it bc it just seems like if its free its prob sketchy
i mean AWS less so bc its amazon
but yk like other smaller companies
yeah i get what you mean
DO is really good
And you know exactly what you'll pay
AWS (especialliy their free trial) tries alot of stuff to get you to pay
if youre just starting out it might be worth it to try out some of the THM content first because you can start up those vms free of charge and use the attackbox. then youll get a feel for linux etc.
definitely
Till they harass you for a 1Β’ that shouldn't even exist
This is what theyt tried with me
They've tried it with me too
There is a script that you give your API key and it goes in and deletes everything
I used that
Have been trying more so lmao
shit is sooo hard
yeah will def do this first
I haven't paid the 1Β’ in two-three years
Has this not been fixed?
what
Still fighting for 1st place?
Lmao
i want to sleep
wdym
This is week 4 of leagues.
I'm currently 1st for bronze iirc
You should be in Sapphire.
Diamond is week 5 - which we haven't started yet.
Someone else had this same bug but I thought they fixed it.
i think gyrus has gone to sleep
Despite only doing one or two rooms a day
Does it reset?
but they are prob get up and grind tmrw
Is there an info page on it :
@umbral bay Sorry for the ping! - Is this bug not fixed?
Weekly. You either go up one league, stay in the same one, or get demoted one league under.
This is week 4 so the best league you could get into is Sapphire and ferglar is in diamond which means they probably got promoted 2 leagues above. (Which is a bug someone else also had.)
So thereβs not seasons like in video games? You either maintain it or it drops?
Hi
How are you mate?
Tipsy
Good morning guys :)
Thanks for explaining it
Gave +1 Rep to @gusty inlet (current: #74 - 119)
GM!
I give chatgpt hard time. First time answer take 8min and 16 sources and 70 search π
Iirc you can iterate through all 10βΆ possible TOTP codes in just under an hour with about 320/s
And you're likely to hit 1/4 active codes at any given time due to time drift

Or you can cheese it and attack the HMAC using timestamp bashing, or you can calculate the numeric biases and predict codes that way
There's a few different ways to do it tbh
ptsd from the test the otherday
how
Bug.
It has been 4 weeks so the best league someone could get into if they were promoted each and every week is Sapphire.
I wish my desk had that pullout keyboard space
Do you get points from doing challenges or walkthroughs?
idk
i am learning i just want to be number 1
Folks, u guys prefer to have the Kali ISO or image on a VM?
@sick lance Can I DM you?
I already saw it π
I mean, just send him a DM, I don't think there's a reason to ask.
You already seem to have a valid reason.
is it safe to go to sleep now (almost 2am for both of us)
hello everyone
How many times do I have to click not interested on a video before it stops showing up in my algorithm. π
@winged nimbus I have same fear
He anyone have monthly subscription?
i have yearly
How how much you pay?
No itβs not. Hackers donβt sleep and neither should you π
All at once or per month
It's all at once for yearly.
the problem is i have a report due on the 13th that i haven't started writing
Ook
i did start today until that dude started clashing with me for 1#
And what about monthly/ how it works
Why do you need to be number 1 again
If a buy now 8pm when it expire jun 8pm or 1jun?
Does that league go off of region ?
second is for loosers
yo im new
?@gusty inlet
hi new
1 month from the day of purchase.
So expire on 8pm juncif i purchase at 8pm?
On 4th of june.
Not sure if exactly at 8PM, but a few hours shouldn't make that much of a difference on your decision making.
π¦ok π€£
BTW - New cert coming soon. Got confirmation that it's ok to be public.
Source: https://www.credly.com/org/tryhackme/badge/jr-penetration-tester-pt1
Which website source
I need this
Or that too!
It says TryHackMe pretty clearly...
I should start doing that when I get phished lol

@bleak quartz issue by tryhackme not the website itself
The source is mentioned in the message.
@gusty inlet ππͺ thanks
Question for the people that are already OSCP: I'm studying hard to learn ethical hacking / pentesting and want to keep going at it untill I am skilled enough to have a go at OSCP. Will it be wise to get an easier one like ejptv2/CEH or Pentest+ first? After about 150 hours and 100+ rooms here I feel slightly confident I can pass an exam like that. Or will that be a waste of time/money? I'm not looking for a job in CS just yet as I'm already employed as an engineer. For now it's all hobby
Hi, I'm the subreddit admin for the company that gives the eJPT/eCPPT. So I can help you with that.
I'd say eJPT is pretty nice only when it's on discount.
eCPPT is not worth it.
Are you in India? If not, CEH is worthless.
should i sleep now
No I'm in a western country :p
wdym by that?
CEH is worthless outside of India.
CEH, it's useless outside of India
why is it?
ya but is it a good thing or a bad thing
Good.
CEH is a very bad cert IMO.
i'll skip CEH then. ejptv2 looks best since its all practical.
150 hours of video course. Labs & CTFs 2 exam vouchers. 48 Hours exam.
150$ on discount.
Ehhh good thing im going for eJPT this month too
only $150? thats a steal!
Lemme quote Juun here
``If I were interviewing as a pentester, I would strongly question the ethicalness and knowledge of teh employer asking for that cert. It's outdated, and the company is well known to act unethically publishing content.
A quick google search turns up a fair amount of the nonsense EC-Council has done.
If I'm on the other side and interviewing a pentester, CEH opens them up to a lot more questions about the up-to-dateness of their technical knowledge.``
#general message
150 is fair. Anything more is not.
It's usually around 300.
well money is not an issue here. for $150 i'll have a go
what would u recommend after eJPT (international value wise)
The eJPT course is what is very good. The exam is really bad.
Unless you are going for a DoD job or a job in India, CEH does not help. And even DoD is phasing it out with the new schedule (I think it's 8470?)
bad as in?
Another one from Juun
OSCP. There's no other cert that gives you jobs as much. PNPT and CPTS are less recognised.
You become a certified brute forcer.
give me some of that rockyou.txt
I have a fully detailed exam review, check it on my website if you want.
aight
nice! can you dm me a link?
It's in my profile.
got it thx
@royal gazelle @simple bone @rose tusk Hey, any of you wanna chime in on eJPT?
It's why I'm a bit worried when it comes to this ^
If it's going to cost 300-400 and will use the pre-existent THM jr pentest path as a course, it will be no match against the eJPT which has over 150 hours of video course with Labs and CTFs.
I've completed the jr pentest path and thought it was pretty good
Mine was a long long time ago, 2019
I mean 150hours of video is nice but you learn more by doing and googling and making mistakes
So I guess that was the eJPTv1.
It's now retired.
Yeah, correct. Each video has a lab attached to it. π
Mayybbeeee think it was like an easier version of Wreath?
Oh then you are going to zone out a lot lol.
If you guys want the eJPT exam in a nutshell? Here it is: https://tryhackme.com/room/internal
But obviously, there are multiple machines not just one.
nice! going to do that one soon
Thanks anyways 
Gave +1 Rep to @simple bone (current: #6752 - -31)
If you can do it without hints, then you are ready for the exam.
The course will be very boring, but if you skip it, you basically wasted your money. The exam gives you nothing back for your money - the course does.
my only concern atm would be the exam ....if i fail .money would be wasted, coz its expensive since 300-500$ is not expensive for y'all but here it is ..since thats like 3-4 months of salary of an above avg software engg here (not like companies aint getting profits ..its just that in this stupid country Employees are treated as either Servants, Cheap Labours etc and all the money is eaten by the company top position peeps)
Yeah, understandable.
I might 'reverse' it then. skip straight to the lab and when I'm stuck I'll check the footage
I hope they're going to give free vouchers to eJPT holders or other junior cert holders (PJPT...) like they did with SAL1.
This way I'll test the exam as soon as it drops.
And I'll compare both.
Are there rooms on THM that teach you about DNS attacks.
Redirection and such
Malicious traffic
Problem is that labs don't always have everything that is in the course, so you'd also be wasting your money.
And vice-versa.
Nice!
step on it

what a smart one
He's showing intelligence
don't step on it
Is this the right place to question some things? If so... I've been doing the Cyber Sec 101 for 3/4 days and I came to section 5 Networking it stated that I should do Pre Security (Which I havent yet), there are 2 modules that I haven't finished yet (because the other modules were completed while doing Cyber Sec 101), should I do Network Fundamentals and How The Web Works or should I keep on CyberSec 101?
I'd suggest doing presecurity yeah
Gets the fundamentals out of the way
You'll breeze through it
Good luck!
Where can I learn Azure cloud Security Engineer course⦠where I can do lots of practicals
Iβm completely beginner. I wanted to know if anyone can tell me what is the best way to start from scratch?
Any courses or smth else?
hello
i think it is safe to sleep
Thanks
Gave +1 Rep to @blissful current (current: #247 - 32)
Try the soc engineer pathway
It requires some previous info tho, so I'd suggest finishing the other paths
For practicals just spin up an azure subscription imo

do keep checking ..8 hrs still remaining lol
I've given up trying this week, top in my league has 12000 points
same shit with me last week
a guy literally did 9.4K points in less than 16hrs , popping in the leaderboard out of nowhere at # 1
Assuming they're just grinding unauthorized write-ups
how they do it?
ya
I'm sure they'll do well in a job
Morning!
probably cheating themselves by just submitting answers from writeups from YT/google etc
worse than skiddies
true
good luck who ever give them jobs
We already knew that was coming anyway.
Using write-ups for answers has the same energy as using chatgpt at work. It'll work for basic stuff but once you have to explain your working you're screwed
how much will it cost anyway?
I assume as much as the SAL1
More than likely.
Here's hoping THM get more acknowledgment in the cert field
Thanks so much
Gave +1 Rep to @stoic quarry (current: #247 - 32)
Hi everyone π
Hello π
Sick with a cold and have my final in 2x days x.x
I'm trying to get more hands on with learning Cyber. I've been studying it for almost a year now, but I don't really know anyone who is also interested in it. So if theres any community nights/events or whatever, make sure to ping me π
That sucks, sorry
Get well soon!
THM does a few events every year
The whiskey helps with the sore throat but my brain feels fried
Advent of Cyber is the annual advent event, there was a big giveaway thing a while back.
Probably more coming up soon
Tea might be a better option? Or if you still want something a little strong, maybe a hot toddy
Awesome, thank you Sil!
Gotchu
I need to buy more tea, that is a better option
I bought 200 teabags for like 5 local coins when I first moved
I've barely gone through half
I don't enjoy tea that much, but I do love the smell of it
I have this one specific kind that I wish I could turn into a candle
That sounds pretty great
I'm thankful that I decided to start with the very basics on TryHackMe. I got the IBM Cyber Security Analyst cert, and studied the whole program, but I feel like I'm learning a lot on THM that wasn't covered in the cert.
Nice!
You should be pretty well prepared then
Done the pre-security path?
It's very fundamental heavy, but good to get those done early
No im still in the pre security path. Doing OSI Model currently
i passed that room today ig.....painnn....
Yikes, don't say that xd I just started it
i hope windows and linux fun. will not be so boringgg
Linux got a lot more fun for me after I finished classroom stuff and actually tried to use it for stuff
Oh yeah 100%
Like I wanted to host a VintageStory server for some friends. Think like Minecraft. But I built a homelab, and decided I would host the server on a VM running Ubuntu Linux. VintageStory is notorious for being really hard to host using linux. I probably learned more setting up that server than I did in my college class on linux
Best way to learn is to dive in imo
one moment I enjoy theory, next moment it enjoys me 
REAL
t minus 12 days if shadow lucky
12 days till what?
?
Till the 16th, duh
open source music player ships
what is a tangara
An MP3 player?
it plays flac files too :D
open source mp3/flac file player using a sd card and a real headphone jack
Huh, I just looked up flac. Never heard of it before
lossless compressed audio files basically
As apposed to a fake one?
i.e it has all the data that was originally there
yeah.. that is called bluetooth
No, it's called digital.
I kind of miss running Rockbox custom firmware on things like my iPod 5.5th gen. Was lovely and supported FLAC and much more
3.5mm and 6.35mm is analogue.
Doesn't mean it's fake or real.
Supported quite a few devices
π
fair enoughs
Literally me last night
lol it happens
thats more then 1/3rd more of the packets shadow has installed
it is actually more then double the amount of packages shadow has installed :D
lol I do have a cursed Arch server with slightly less but yeah
just use it headless for infosec
this was on a kali vm
oof updating kali
yeah we could tell from the apt parts. But do keep in mind the change in package signing or whatever that happened
i have 1063 packages on my arch
very recently, they lost like the repo key or something silly
TL;DR
Bad news for Kali Linux users! In the coming day(s), apt update is going to fail for pretty much everyone out there:
Missing key 827C8569F2518CC677FECA1AED65462EC8D5E4C5, which is needed to verify signature.
Reason is, we had to roll a new signing key for the Kali repository. You need to download and install the new key manually, hereβs...
lol not great, but not as bad as Manjaro letting SSL/TLS certs expire multiple times and just telling users, βeh just roll your clock back for nowβ
I'm considering punishing myself and moving on from Ubuntu to Arch, but I'm not sure I'm familiar enough with Linux and CLI to do so yet? Might try that website with linux cli practice games
the command challenge???
The Arch wiki is a fantastic resource which will teach you a ton along the way, but yeah Iβd say wait until you know thatβs what you want
arch wiki + gentoo wiki == lots of info that is helpful
