#general

1 messages Β· Page 1062 of 1

patent falcon
#

and a remark is that english is not a cool language, like russian, portuguese or german

#

if a very blank language

#

nothing to beautiful and complicated like the languages i cited

#

so i dont give the effort enough

#

and one of the principal countries that utilizes english is in a phase of atacking even their closests allies

#

the trump administration almost cancelled the cve program database

#

how the fuck i am suppossed to give myself time to learn the language of this stupids hahaha

#

i forgot about a language very good and beautiful

#

the chinese

#

of boy

#

if i was smart enough to learn

pallid lotus
#

What in God's name are you talking about..?

patent falcon
#

i dont knoiw sorry

#

i just popped a perc

pallid lotus
#

A... What?

patent falcon
#

so i'm not the kid in here

pallid lotus
#

Percocet?

gusty inlet
#

Hello Muiri! πŸ‘‹

#

No day passes by without me looking at that insane discord bio.

#

Wish I could end up in the same position as you, but it's quite impossible in France lol.

#

OffSec is dead.

pallid lotus
#

How so?

gusty inlet
#

Where do I start.
Job Ratio: 50 Blue Team for 1 Red Team.

#

Oversaturated market, and very little demand.

pallid lotus
#

Curious. Why the low demand?

gusty inlet
#

In the span of 6 months, I found only 3 Red Team operator job openings in France.

#

And I search hard.

pallid lotus
#

Any hits for pentest?

patent falcon
gusty inlet
# pallid lotus Curious. Why the low demand?

According to my colleagues and friends that were here previously, it has always been this way in France. The offensive part of security is practically non existent and pentests are really rare.

#

Clients just don't like pentests.

pallid lotus
#

That's interesting. Do they have an alternative?

gusty inlet
#

Not at all. But they do dump HUGE amounts of money in security.

gusty inlet
#

Blue Team (In all its kind) thrives quite a lot.

#

The market is HUGE.

pallid lotus
#

So basically they're focused on detection rather than prevention?

gusty inlet
#

Yes.

pallid lotus
#

Interesting choice

gusty inlet
#

Google it, we have data leaks everywhere in France.

#

Government facilities, phone operators.

pallid lotus
#

I'll believe ya πŸ˜†

#

We can't exactly comment considering we've had 3 major retailers down in about a week and a half.

gusty inlet
#

lol.

patent falcon
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #10 - 874)

gusty inlet
#

But yeah. Pentest job exists, just very few. I'd say by searching casually I found 10 openings throughout the year.

#

For red team around 2 by searching really hard.

#

But hey, I'm not giving up on that CRTO cert.

pallid lotus
#

@shell nova remind me, are you in France or Canada these days?

patent falcon
# pallid lotus https://www.offsec.com/certificates/osce3/

sorry to enter in your guys convo, but seeing your profile, do you think that binary exploitation is an active field? Or is a little dead? i find it very cool, i'm rereading hacking the art of exploitation and want to get shellcoders handbook, but sometimes i wonder if i'm not entering in a dead field

pallid lotus
#

It's not dead but you're kinda limited with it as a career path

gusty inlet
#

Oh right I think Hydra speaks french?
If Hydra was in France before 2023, I'd love to know the state of the market back then.

blazing granite
pallid lotus
#

There are still some private vulnerability research companies, but a lot of the remaining roles are government

patent falcon
pallid lotus
#

Malware analysis would probably be the closest, yeah

patent falcon
#

any other more focused in the exploitation aspect?

#

what is your job?

pallid lotus
#

Yeah, you're in one of the roles that does still need it

patent falcon
#

pentester like in the bio?

pallid lotus
patent falcon
#

in the offensive part what is the hot area nowadays muiri?

#

where the fun is at?

pallid lotus
#

That and, again, some governments (probably most of them) like having exploit developers on staff. You can probably guess why.

patent falcon
gusty inlet
#

Yeah, niche jobs like maldev and red team developers are most prominent in gov facilities.

blazing granite
#

yes, I know somebody who works in Mount Blanc that does that πŸ˜‚

pallid lotus
# patent falcon where the fun is at?

Depends what you class as "fun".
A lot of offensive security is reporting. It's not how it looks in the films.

Personally I would say maldev and red team ops. Others might say pentesting, or specific pentesting fields.

#

There's a lot of cool stuff going on in cloud and AI security research just now.

patent falcon
#

thanks for the chat guys

#

but i think my heart is beating too fast

#

i will laid down now

pallid lotus
#

That'll be the opioids

patent falcon
#

bye bye butterflies

pallid lotus
#

Opiates?

patent falcon
#

shhh

pallid lotus
#

Opioids indeed

gusty inlet
#

@pallid lotus Sorry for the ping - But aside the website in your bio, is anything about your carreer public? A linkedin? Anything else?

bleak quartz
#

@static acorn check yo dms

pallid lotus
#

I don't use social media much. My blog is also in dire need of a refurbishment.
I've got LinkedIn and Twitter floating around, but I rarely use them.

gusty inlet
#

Oh alright. If there's a time where you start sharing something about your work, discoveries etc. do let me know.

pallid lotus
#

Will do πŸ˜„

static acorn
chilly veldt
#

my arm is itchy

gusty inlet
#

My entire body is itchy. Not sure what's wrong with my nutrition.

#

Maybe too much protein.

bleak quartz
static acorn
#

i put itching powder in all your sweaters muahahaha

chilly veldt
#

my skin is peeling cause of my tattoo πŸ˜…

bleak quartz
hard siren
#

guys

#

wsit

hazy flume
#

not my best blurr

#

I did after months of trying. NT authroty from reverse shell only no gui

#

i have shivering in my body

dark mason
#

approaching 25 hours of no sleep, crazy

hazy flume
#

had some days of 25-32 in the past year

#

i think my computer loves me back

#

for once

#

someone loves me back

sturdy river
normal fable
#

sometimes your own computer is.. not your friend or ally at all..

hard siren
#

wsp guys I'm selling neymar information data, if you want, dm me, i have all prints with proof

sturdy river
nocturne prawn
#

Sorry if I’m taking your time or space in this amazing group. I’m 14 and just got a high-end PC. I’m not into games like Fortniteβ€”instead, I want to learn about computer security, programming, and everything related to the world of PCs. I’ve already installed Kali Linux and would love to know how I can start learning and improving. Any advice would mean a lot, Thank you

normal fable
nocturne prawn
#

Nono , for Made it more simple I install it on a vm

normal fable
normal fable
nocturne prawn
#

Good

normal fable
#

Make sure you read all the #start-here and sign up on the website if you haven't already. You can connect your THM (Try Hack Me) profile from the website to the Discord. πŸ™‚

blissful snow
#

hi

slate wing
#

like does it direct u to my profile? just to confirm

blazing granite
#

open in incognito, and check out πŸ˜‚ you're asking in a sever of cybersec that people click on a link πŸ˜›

slate wing
slate wing
boreal scarab
#

Bella, I, Rex, alt, muiri, etc, we've been here for ages now. This ain't our first rodeo, and certainly won't be the last of shady people.

blazing granite
#

definitely chose the wrong audience for random links clicking πŸ˜‚

slate wing
#

and it is ok to be sus but saying i am not clicking links at all is extreame

blazing granite
#

because nobody can clone a website πŸ˜›

chilly veldt
slate wing
dark mason
#

27h of being awake and I feel way less tired than I excepted

slate wing
chilly veldt
#

we just rated that the time for us to do analysis on the link was longer than it would take for you to open up an incognito and test it yourself

blazing granite
chilly veldt
#

as a true cybersecurity professional, we value our time

boreal scarab
keen light
#

what is google

#

probably malware

chilly veldt
#

try and click on it

blazing granite
slate wing
#

like yall

#

u guys get nightmares about accidently clicking links

chilly veldt
#

this is why we don't click on random links, it was a redirect to youtube

slate wing
#

he probably things they were the worest investion ever created+ hates the investor of then'

#

m

slate wing
#

def kekw

#

πŸ˜‚

blazing granite
whole yew
keen light
#

I fight the links as a matter o fact sometimes i try and find random .su and .ru links to see whats going on

slate wing
keen light
#

just to show the soviets that there ccTLD doesnt scare me

boreal scarab
slate wing
#

eat them for breakfast

keen light
#

in fact i found some random persons old blog from 1997

boreal scarab
#

We're not going to click a link based on "trust me. It's safe"

#

If @blazing granite gave me a link, I'd still be skeptical if it's a domain I don't recognize, but it's also about merit. Rex has been here for ages, he's trustworthy.

#

random guy at Defcon
"Here, scan this QR code, trust me, it's safe"

Well, who the fuck are you?

boreal scarab
slate wing
slate wing
boreal scarab
#

As Bella said, we value time.

boreal scarab
blazing granite
slate wing
dark mason
#

it's crazy fun here

boreal scarab
#

Trust me, it's safe.

boreal scarab
slate wing
#

trust me it is safe, now I challege yall to prove me otherwise

whole yew
#

That's not how trust works.

blazing granite
whole yew
#

You are the one making the claim about it, demonstrate it is safe.

slate wing
#

it is ok tho I figured it

whole yew
#

I mean, you don't understand burden of proof. So good luck.

chilly veldt
#

don't use betterhelp, it's a pure scamming service

#

they don't treat their therapists right

slate wing
chilly veldt
#

it's the company, not the therapists

blazing granite
slate wing
keen light
#

ive just been vibing to music for ages now

chilly veldt
whole yew
#

Because there are mountains of documentation of betterhelp acting in bad faith with both therapists and customers? It's the uber/doordash model applied to mental health care.

slate wing
steady pewter
#

Hello everyone.

steady pewter
#

Wait..has there been any mod changes since I've been gone?

keen light
#

o_o

boreal scarab
steady pewter
#

POV me trying to fix a nonexistent bug and end up bricking a perfectly fine docker image:

boreal scarab
boreal scarab
#

@cloud quiver @sick lance

sullen hearth
#

Morning πŸ₯±

static acorn
#

(i did scan it tho. trust me bro)

pastel plinth
#

Hello

#

Have custom QKD; need tester

keen light
#

sway is the way

austere hazel
#

l@2025

rapid merlin
short raven
#

hello

#

iam new to ethical hacking can u help me , how can i learn ethical hacking for free

#

πŸ₯²

knotty valve
#

Also has anyone seen the shenanigans going on with Shapes, Inc.?

#

Very funny

knotty valve
glacial socket
knotty valve
#

The one and only turkey

glacial socket
#

Guys linux commands are hard to remember

#

Any tips

knotty valve
#

Use them often when you can

blazing granite
knotty valve
#

Also Cheatsheets help

knotty valve
#

Isn't that an operator?

#

For bash

blazing granite
#

I've been using Linux since 1993 and I even don't remember every command, often I have to man commands that I never used or I used once in a while

#

not only the commands, every commands has many flags nobody can remember them all so you shouldn't even try πŸ™‚

#

I remember the commands I used over and over again

weak citrus
#

Anyone have Ruby on Rails experience? I'm so completely lost on this box

blazing granite
weak citrus
#

Thank you!

short raven
#

hello ,anyone know where to download blackeye s orginal virsion

#

hello

blazing granite
short raven
#

no i want to learn it

#

or is there any good phishing tool to learn it

high shadow
#

Hello chat

blissful current
#

Hello

golden mural
blissful current
#

phishing is not to be discussed here tho ...as per rules...just saying

blissful current
#

ya

#

only in advanced channels

upbeat valley
golden mural
# blissful current ya

which rule... kindly point it out. We're not discussing about hacking anyone. He just wanted to know about a good phishing tool and I said it

blissful current
#

idk ask scrubz

golden mural
fleet pivot
# boreal scarab You're in a discord with people you don't know. And someone gives you a link, ra...

just open up burp suit, run a proxy like mitmproxy, route ur browser traffic through it, and watch every request that URL triggers. if it’s doing redirects, dropping suspicious JS, or calling out to weird IPs, you’ll see it right there. heck, use wireshark, filter by http or even look for DNS queries β€” sometimes these links call home to C2 servers or leak data via GET params. u can even curl the link with -v or --trace and see the raw HTTP convokekw

blazing granite
fleet pivot
#

I wanna investigate.

rapid merlin
#

My Nitro is gone πŸ’”

winged nimbus
#

don't you date try dethrown me for like the third time

blissful current
oak river
grim elm
#

Hello, I have a question about what is the purpose of tickets in try hack me?

winged nimbus
cloud quiver
grim elm
#

okey thanks

rapid merlin
#

Good morning

grim sparrowBOT
#

Done!

knotty valve
#

The one thing you never want to see when running automated scans

muted dove
#

Hi guys and girls, is the Fliper Zero a good toy to play around with?

knotty valve
#

If you got the money for it, yeah

knotty dune
#

What does the X denotes in the CSV report of the eyewitness tool (the tool used for screenshotting) ?

#

That's a built in Kali tool

winged nimbus
#

can't shake this dude off my tail 😭

muted dove
knotty valve
muted dove
#

I think it would be great for me because I'm studying Cybersecurity at the moment.
But still don't know whether I want to be Blue or Red team

knotty valve
#

learn both sides, and you can always split off to what one you find more enjoyable

flint egret
knotty valve
#

but generally knowing both, or at least the basics of both, will give you better leeway when you focus on one

flint egret
#

Do harder rooms

winged nimbus
flint egret
#

Also noticed that it is valuable having having knowledge in both if you are trying to pursue management level roles

knotty valve
#

I'm waiting for some automated scans to finish

#

I've got plenty of time since there's like 30k nodes it's scanning rn

jovial cobalt
#

can anyone help me with a simple javascript issue ? not related to thm i was studying for my exam tmrw in fcc and idk whats the issue or error

flint egret
flint egret
winged nimbus
knotty valve
muted dove
twin ridgeBOT
#

Gave +1 Rep to @knotty valve (current: #415 - 15)

winged nimbus
knotty valve
#

before I go hunting down vulns

knotty valve
#

it tells you what you need to do

flint egret
jovial cobalt
knotty valve
jovial cobalt
knotty valve
#

Codecamp says what the issue is lol

knotty valve
oak river
#

What's with the JD Vance memes recently everywhere, lmao

knotty valve
#

otherwise I'd just be telling you the solution

knotty valve
#

Tasty charts

#

Doesn't help i'm fucking Colour blind

jovial cobalt
knotty valve
#

Because that's not the solution

#

the solution is in the steps

flint egret
winged nimbus
jovial cobalt
knotty valve
#

because you don't have that variable

flint egret
neat scaffold
#

is there a way to bypass Amazon WAF

flint egret
knotty valve
jovial cobalt
knotty valve
#

they tell you what variables and methods you need

dreamy marlin
#

hi, so i'm doing pre-security path rn, do i have to setup or do any config rn in my device? or they teach later how to do that? I've not done anything like setting up vpn or like that

jovial cobalt
knotty valve
#

the issue is the fact you are misinterpreting their steps

flint egret
knotty valve
muted dove
jovial cobalt
knotty valve
knotty valve
jovial cobalt
silver sky
knotty valve
jovial cobalt
knotty valve
#

not to be rude, but this is just a moment of weirdly written questions

jovial cobalt
#

this is my entire code

silver sky
knotty valve
#

they tell you in the steps what variable

jovial cobalt
knotty valve
#

With the full code that makes it easier lol

jovial cobalt
muted dove
#

let botIntroduction;
botIntroduction = "ichigo"; // Step 1: Store the name
botIntroduction = "My name is " + botIntroduction + "."; // Step 2: Combine and store sentence
console.log(botIntroduction); // Step 3: Print it

knotty valve
#

but not what I initially thought

jovial cobalt
knotty valve
#

Because I didn't have the full code i assumed you weren't assigning bot at all

#

you're still misreading their tip tho kek

#

the tip tells you what variable

terse dawn
#

bot is assigned at line 7

jovial cobalt
knotty valve
jovial cobalt
#

still error

jovial cobalt
# jovial cobalt still error

i tried the variable bot too but it was also wrong i cant understand where iam wrong in my pov im going on right path

knotty valve
#

what's the tip above it say?

#

I think you may have the order of operations around the wrong way

jovial cobalt
#

tghis is the tip

knotty valve
#

yeah, you're supposed to concat on the variable, then console log the variable

#

in steps:

  1. create variable
  2. assign the concat string to variable
  3. log variable
jovial cobalt
knotty valve
#

You're concating on log

#

which isnt what's being asked

jovial cobalt
knotty valve
#

I admit they did word that tip weirdly

jovial cobalt
jovial cobalt
knotty valve
#

That's just an example of how to do string concat

#

not how to write your code

jovial cobalt
knotty valve
#

in the steps they tell you to do it, yes

#

in all other aspects, you'd have done it right

#

but it's just not done in the order they want it

jovial cobalt
#

😭

terse dawn
#

maybe take a break for a couple of minuts

knotty valve
#

can always come back to it later

jovial cobalt
knotty valve
#

Prep for your exams first lol

jovial cobalt
terse dawn
jovial cobalt
jovial cobalt
terse dawn
knotty valve
#

Also in future: With code problems it's better to send all the working/PoC code lmao

jovial cobalt
mortal root
#

How would you retrieve the items in the current directory with size greater than 100?

#

someone help please im stuck at this one

terse dawn
#

maybe find command?

#

-size <size>

mortal root
#

get-childitem | where-object -size <100>

#

i did this but its short by 11 words

#

get-childitem | where-object -size-gt< 100>

crystal moss
#

Morning..

silver sky
#

Safe place eh? πŸ˜‚

#

These delivery drivers make me laugh

rapid merlin
#

What delivery, I can’t see one.

dreamy marlin
rapid merlin
knotty valve
#

It's even funnier when they think putting the doormat over it will hide it

silver sky
#

Very safe

#

I've messaged one of my neighbours to ask if he'll take it into the block for me

knotty valve
#

Nice

#

My housemate is usually home when I'm not so I just get them to do sign packages for me

round orbit
silver sky
#

Yeah it's food so πŸ˜‚ anyone is welcome to steal the meals if they are that desperate

knotty valve
#

Confirming blind Injections would be using a ping or a http request to controlled server, yeah?

pliant onyx
knotty valve
#

If it wasn't blind, I'd be able to see it

#

Was just wandering so I knew if I'm building additional tools correctly lul

#

While I wait for my current toolset to finish the very long and arduous process of enumerating 200k nodes

#

Cause apparently it discovered even more

pliant onyx
#

Ash scanning her whole state

knotty valve
#

This is a single service btw

pliant onyx
#

Bruh

knotty valve
#

It used to be more

#

But they culled 150-200k nodes this week

#

Random question, but how does the memory in a VM work? Is it shared with the host or is it isolated off in kernel?

sick lance
#

It's shared.

#

So you have 8GB and assing the VM 4, you'll be left with 4GB for the host.

knotty valve
#

Wouldn't that allow for an advanced malware using ICE to spread from the VM to host?

sick lance
#

It's rare for a breakout, it can happen.

#

But most threat actors have a way to break out VMs done make it public, it's not common knowledge.

knotty valve
#

I'm reading a malware analysis report and it was an an idea that propped into my head since in-memory malware usually are very hard to identify

#

The report was specifically the MRm-DLDet framework

sick lance
#

Ah, you mean can the nalware attach to the RAM that has locked from the hypervisor for the VM?

knotty valve
#

Yeah

jade oar
jade oar
#

Thank you

sick lance
#

If you assign yourself 4GB of RAM to the VM, the malware can work inside that 4GB that is locked off, but as soon as you turn the VM off, it stops.

thorny knot
jade oar
#

I tried C as well

sick lance
#

Come on.

#

I literally just pointed you to the channel this discussion should take place in.

#

I don't appreciate being ignored.

jade oar
#

Umm I alr put it there

knotty valve
jade oar
#

He just asked a question I replied my bad

sick lance
knotty valve
#

I wonder if there's a way to essentially "breakout" of that lock

#

Cause that would handled by ring 0, right?

#

Or kernel for the unfamiliar

sick lance
#

That would be a breakout.

#

CVE 2017 4901.

#

CVE 2015 3456 and CVE 2023 20867

#

It's not easy, and most breakouts happen with something stupidly set by the user, or something like Vmware Tools.

knotty valve
#

So it needs something that it can clone against

#

That makes sense

sick lance
#

Clone could be one word.

knotty valve
#

I couldn't think of another lmao

sick lance
#

Another way to look at it, is it can happen through Shared folders, drag and drop and clipboard access.

knotty valve
#

shared folders Is more file system than memory

#

But still an exit point

sick lance
#

CVE 2017 4901 was running execute code in the OS via drag and drop.

knotty valve
#

Out of Bounds moment

sick lance
knotty valve
#

Yah

#

I got that dw

winged nimbus
#

this dude has relentlessly fighting me for a week

knotty valve
#

Ferglar has a nemesis fr

#

Leagues reset today don't they

sick lance
#

Weekly.

winged nimbus
#

on my last room for cyber 101

modern fox
#

arrives

agile arrow
#

Hello I got a problem please help me

sick lance
#

What is your problem?

agile arrow
#

Actually I use VMware community edition and install the TryHackme openvpn configuration after running it using sudo openvpn user.ovpn that connection is successful but after join a room the labs ip address not opening in my browser

rapid merlin
#

Is there any technology that allows people to check for voice changers, redirected call and ai imaging.

winged nimbus
#

some ai artifacts might be detectable

#

but all of this would prob mean they have an ai constantly monitoring every call which is not good

#

0 privacy

#

i am tired i can barely read words but i don't want to come seccond

craggy wadi
winged nimbus
rapid merlin
winged nimbus
#

it is the league

rapid merlin
#

Ohh okay

#

I’ve not been on THM in a few days

#

I want them to make an icon of a phone on the rooms that can be done on phone (No lab rooms).

sick lance
#

That would be none.

dreamy marlin
sick lance
#

As the website isn't really optimised for a tablet/phone.

winged nimbus
sick lance
#

Especially if they utilise a split screen machine or task downloads (or both).

rapid merlin
mellow narwhal
#

I mean I've done it on phone, but its the largest PITA

#

That was just because I was bored and wanted to try it out

#

and yeah the content is fine on the screen, but you're cursed if you try using the attackbox kekw

rapid merlin
#

But it’s just you need to join the rooms to find out if you can do the rooms on mobile.

#

I need something to do while I’m on the phone.

sick lance
#

Not optimised != Not able

dreamy marlin
winged nimbus
dreamy marlin
winged nimbus
#

it is only 10:28pm but my brain is being pumped with natural melatonin

craggy wadi
craggy wadi
dreamy marlin
craggy wadi
#

do you take notes?

dreamy marlin
craggy wadi
#

I think it is common to have to reread things but taking notes definitely helps. Just the act of writing what you are learning can reinforce the info. Even more helpful is going over those notes again after learning.
Also try to do practical exercises whenever you can so you're "doing" what you're learning.

#

I'm specifically talking about learning cyber related stuff but it's probably applicable to other areas too

slow cloud
#

Morning chat

serene ginkgo
#

Hello Guys

dreamy marlin
twin ridgeBOT
#

Gave +1 Rep to @craggy wadi (current: #264 - 29)

dreamy marlin
jade oar
dreamy marlin
slow cloud
supple crest
#

hello I am new to this,and Iwanted to ask how much would the theoretical basics help in the coding parts later on

craggy wadi
supple crest
craggy wadi
bleak quartz
#

new stuff will be built up on top of old stuff you know

#

if you don't know the old stuff it will make it extremely hard

#

kinda like math

supple crest
#

how am i supposed to move on with the courses,like from what i see theres only a bit available in the free pathways

supple crest
supple crest
bleak quartz
bleak quartz
#

I've been here for 32 days

supple crest
#

i did it like for a few days and am yet to make notesπŸ’€ ( 1 week)

bleak quartz
#

And I got basically my own library for a lot of stuff, although I had previous experience

#

with diff platforms

supple crest
#

yea no me a noobie cs fresher in clg

bleak quartz
#

For me note taking and reflecting helps

#

Obsidian is what I recommend

supple crest
bleak quartz
#

Boutta reach mage soonish!

sick lance
supple crest
sick lance
#

Did you happen to read our rules, when you joined the server?

supple crest
valid orbit
supple crest
#

just more confused bout cyber and CS in general (oof)

sick lance
bleak quartz
#

lol

supple crest
#

am level 2 rn(in the app)

sick lance
#

Probably should specify, won't confuse people. kekw

sick lance
supple crest
#

@bleak quartz just curious,i saw your pfp and whats C5?

#

tysm for help btw

final linden
split plover
#

Hey, are there any email analysis tools to integrate with siem?

final linden
craggy wadi
#

haha you got it.

craggy wadi
#

i think splunk has some native utilities or addons for email analysis. id have to look into it though

final linden
twin ridgeBOT
#

Gave +1 Rep to @sturdy river (current: #2857 - 1)

knotty valve
split plover
hallow hazel
craggy wadi
#

i have a decent amount of experience running splunk and its forwarder on vms so lemme know if you need any assistance.

knotty valve
#

My emails get filtered through my own AI model and CloudFlares filters

topaz topaz
#

Hey guys, this is more of a Linux based question in case anyone knows, I use alt tab a lot, but it's really frustrating when I alt tab across various different programs and they stay on my screen after skipping through them on Debian, anyone else who managed to turn off this feature?

knotty valve
#

Wdym?

#

As in they're constantly set to on-top? Cause that's a setting you would have applied to the individual window

topaz topaz
#

For example, there's 4 programs open, I'm on program 1 and I gotta alt tab past 3 programs to get to program 4

#

I press alt tab until I get to it, but the previous 3 I skipped still stay on the screen as if I selected them if that makes sense

knotty valve
#

That's just how your DE works

topaz topaz
#

On Windows you press Alt Tab multiple times it skips through them , they stay minimized

topaz topaz
knotty valve
#

You'd probably have to create a plugin or find a plugin for it, specific to the DE

ebon jay
#

HI

knotty valve
#

There might be one in your compositor settings

#

But that would take some digging through the DE settings

topaz topaz
twin ridgeBOT
#

Gave +1 Rep to @knotty valve (current: #397 - 16)

frozen gull
#

hi hi]\

knotty valve
#

Heya

lament ingot
#

good morning!!

lament ingot
#

how are you all doing today?

gusty inlet
#

Thinking of hanging out in Paris today, but I'm lazy.

lament ingot
#

I am! Just hanging out before work πŸ™‚

lament ingot
split plover
bleak quartz
#

Yippeee!!!!

craggy wadi
bleak quartz
#

Thanks!

craggy wadi
craggy wadi
# bleak quartz Thanks!

you gotta verify again so we can see the role change. at least i think that would force it to update

lament ingot
#

quick question, is there a service that offers web-based virtual machines that I can use if my computer is too slow to run VM's?

worn thorn
#

THM offers such an option for their service

lament ingot
gusty inlet
#

Using it for anything else would be breaking ToS.

lament ingot
#

yeah, thats why i was wondering if there was one that was for general use

#

not super familiar with it though

gusty inlet
#

I think AWS allows you to host machines. It's paid, though.

lament ingot
twin ridgeBOT
#

Gave +1 Rep to @gusty inlet (current: #74 - 117)

craggy wadi
bleak quartz
#

Yooo

#

worked

craggy wadi
#

epic

lament ingot
craggy wadi
lament ingot
bleak quartz
craggy wadi
#

aws also has a free tier btw

#

but it has usage limits of course

lament ingot
#

i mean i was expecting to pay for it bc it just seems like if its free its prob sketchy

#

i mean AWS less so bc its amazon

#

but yk like other smaller companies

craggy wadi
#

yeah i get what you mean

cosmic pendant
#

DO is really good

#

And you know exactly what you'll pay

#

AWS (especialliy their free trial) tries alot of stuff to get you to pay

craggy wadi
# lament ingot yeah sounds about right

if youre just starting out it might be worth it to try out some of the THM content first because you can start up those vms free of charge and use the attackbox. then youll get a feel for linux etc.

knotty valve
cosmic pendant
knotty valve
#

They've tried it with me too

cosmic pendant
#

There is a script that you give your API key and it goes in and deletes everything

#

I used that

knotty valve
#

Have been trying more so lmao

winged nimbus
#

shit is sooo hard

knotty valve
#

I haven't paid the 1Β’ in two-three years

gusty inlet
winged nimbus
knotty valve
winged nimbus
#

it is 12:45am

knotty valve
#

Lmao

winged nimbus
#

i want to sleep

gusty inlet
#

It's a bug.

winged nimbus
gusty inlet
#

This is week 4 of leagues.

knotty valve
#

I'm currently 1st for bronze iirc

gusty inlet
#

You should be in Sapphire.

#

Diamond is week 5 - which we haven't started yet.

#

Someone else had this same bug but I thought they fixed it.

winged nimbus
#

i think gyrus has gone to sleep

knotty valve
#

Despite only doing one or two rooms a day

rapid merlin
winged nimbus
rapid merlin
#

Is there an info page on it :

gusty inlet
gusty inlet
#

This is week 4 so the best league you could get into is Sapphire and ferglar is in diamond which means they probably got promoted 2 leagues above. (Which is a bug someone else also had.)

rapid merlin
#

So there’s not seasons like in video games? You either maintain it or it drops?

gusty inlet
#

Yes.

#

Or you get promoted one above - until you reach Diamond.

rapid merlin
#

Hm okay

#

Hello

knotty valve
#

Hi

rapid merlin
knotty valve
#

Tipsy

tame nexus
#

Good morning guys :)

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @gusty inlet (current: #74 - 119)

rapid merlin
frigid stump
#

I give chatgpt hard time. First time answer take 8min and 16 sources and 70 search πŸ˜‚

knotty valve
#

And you're likely to hit 1/4 active codes at any given time due to time drift

frozen gull
knotty valve
#

Or you can cheese it and attack the HMAC using timestamp bashing, or you can calculate the numeric biases and predict codes that way

#

There's a few different ways to do it tbh

winged nimbus
blissful current
gusty inlet
#

Bug.

#

It has been 4 weeks so the best league someone could get into if they were promoted each and every week is Sapphire.

rapid merlin
#

Ohh

#

I gotta do my two rooms

winged nimbus
#

how much lead should i pull

#

gyrus is asleep

blissful current
#

Go do learning instead of Pulling ahead in points

rapid merlin
#

I wish my desk had that pullout keyboard space

warped hollow
winged nimbus
#

idk

winged nimbus
orchid bloom
#

Folks, u guys prefer to have the Kali ISO or image on a VM?

gusty inlet
#

@sick lance Can I DM you?

hallow hazel
gusty inlet
#

It's already public outside of discord.

#

Not sure if they're aware.

hallow hazel
#

I mean, just send him a DM, I don't think there's a reason to ask.

#

You already seem to have a valid reason.

winged nimbus
#

is it safe to go to sleep now (almost 2am for both of us)

craggy wadi
#

haha youre still going at it?

#

dedicated

dark sail
#

hello everyone

rapid merlin
#

How many times do I have to click not interested on a video before it stops showing up in my algorithm. πŸ˜’

#

@winged nimbus I have same fear

#

He anyone have monthly subscription?

winged nimbus
#

i have yearly

rapid merlin
#

How how much you pay?

rapid merlin
#

All at once or per month

gusty inlet
winged nimbus
rapid merlin
#

Ook

winged nimbus
#

i did start today until that dude started clashing with me for 1#

rapid merlin
#

And what about monthly/ how it works

rapid merlin
#

If a buy now 8pm when it expire jun 8pm or 1jun?

#

Does that league go off of region ?

winged nimbus
tame nexus
#

Hello from the lower leagues.

shadow coral
#

yo im new

rapid merlin
blissful current
gusty inlet
rapid merlin
#

So expire on 8pm juncif i purchase at 8pm?

gusty inlet
#

On 4th of june.

#

Not sure if exactly at 8PM, but a few hours shouldn't make that much of a difference on your decision making.

rapid merlin
#

🐦ok 🀣

gusty inlet
rapid merlin
#

Which website source

bleak quartz
boreal scarab
#

I should start doing that when I get phished lol

blissful current
rapid merlin
#

@bleak quartz issue by tryhackme not the website itself

gusty inlet
rapid merlin
#

@gusty inlet πŸ‘πŸͺ– thanks

fast orchid
#

Question for the people that are already OSCP: I'm studying hard to learn ethical hacking / pentesting and want to keep going at it untill I am skilled enough to have a go at OSCP. Will it be wise to get an easier one like ejptv2/CEH or Pentest+ first? After about 150 hours and 100+ rooms here I feel slightly confident I can pass an exam like that. Or will that be a waste of time/money? I'm not looking for a job in CS just yet as I'm already employed as an engineer. For now it's all hobby

gusty inlet
#

I'd say eJPT is pretty nice only when it's on discount.

#

eCPPT is not worth it.

boreal scarab
winged nimbus
#

should i sleep now

fast orchid
blissful current
gusty inlet
boreal scarab
winged nimbus
#

why is it?

blissful current
#

ya but is it a good thing or a bad thing

gusty inlet
#

CEH is a very bad cert IMO.

fast orchid
#

i'll skip CEH then. ejptv2 looks best since its all practical.

gusty inlet
#

150$ on discount.

blissful current
fast orchid
#

only $150? thats a steal!

boreal scarab
#

Lemme quote Juun here

``If I were interviewing as a pentester, I would strongly question the ethicalness and knowledge of teh employer asking for that cert. It's outdated, and the company is well known to act unethically publishing content.

A quick google search turns up a fair amount of the nonsense EC-Council has done.

If I'm on the other side and interviewing a pentester, CEH opens them up to a lot more questions about the up-to-dateness of their technical knowledge.``
#general message

gusty inlet
#

It's usually around 300.

fast orchid
#

well money is not an issue here. for $150 i'll have a go

blissful current
gusty inlet
#

The eJPT course is what is very good. The exam is really bad.

boreal scarab
#

Unless you are going for a DoD job or a job in India, CEH does not help. And even DoD is phasing it out with the new schedule (I think it's 8470?)

fast orchid
#

bad as in?

boreal scarab
#

Another one from Juun

gusty inlet
gusty inlet
fast orchid
#

give me some of that rockyou.txt

gusty inlet
#

I have a fully detailed exam review, check it on my website if you want.

fast orchid
gusty inlet
#

It's in my profile.

fast orchid
#

got it thx

boreal scarab
gusty inlet
#

If it's going to cost 300-400 and will use the pre-existent THM jr pentest path as a course, it will be no match against the eJPT which has over 150 hours of video course with Labs and CTFs.

fast orchid
#

I've completed the jr pentest path and thought it was pretty good

simple bone
fast orchid
#

I mean 150hours of video is nice but you learn more by doing and googling and making mistakes

gusty inlet
#

It's now retired.

fast orchid
#

well at least I do

#

I zone out quickly when the video is boring πŸ˜„

gusty inlet
simple bone
#

Mayybbeeee think it was like an easier version of Wreath?

gusty inlet
#

But obviously, there are multiple machines not just one.

fast orchid
boreal scarab
twin ridgeBOT
#

Gave +1 Rep to @simple bone (current: #6752 - -31)

gusty inlet
# fast orchid nice! going to do that one soon

If you can do it without hints, then you are ready for the exam.
The course will be very boring, but if you skip it, you basically wasted your money. The exam gives you nothing back for your money - the course does.

blissful current
# gusty inlet It's why I'm a bit worried when it comes to this ^

my only concern atm would be the exam ....if i fail .money would be wasted, coz its expensive since 300-500$ is not expensive for y'all but here it is ..since thats like 3-4 months of salary of an above avg software engg here (not like companies aint getting profits ..its just that in this stupid country Employees are treated as either Servants, Cheap Labours etc and all the money is eaten by the company top position peeps)

gusty inlet
#

Yeah, understandable.

fast orchid
gusty inlet
#

I hope they're going to give free vouchers to eJPT holders or other junior cert holders (PJPT...) like they did with SAL1.

#

This way I'll test the exam as soon as it drops.

#

And I'll compare both.

rapid merlin
#

Are there rooms on THM that teach you about DNS attacks.

#

Redirection and such

#

Malicious traffic

gusty inlet
#

And vice-versa.

boreal scarab
fleet pivot
#

step on that thang

stoic quarry
#

He's showing intelligence

hallow hazel
#

don't step on it

stoic quarry
#

Not being controlled at all

#

Chess playing robots all over again!

tame nexus
#

Is this the right place to question some things? If so... I've been doing the Cyber Sec 101 for 3/4 days and I came to section 5 Networking it stated that I should do Pre Security (Which I havent yet), there are 2 modules that I haven't finished yet (because the other modules were completed while doing Cyber Sec 101), should I do Network Fundamentals and How The Web Works or should I keep on CyberSec 101?

stoic quarry
#

I'd suggest doing presecurity yeah

#

Gets the fundamentals out of the way

#

You'll breeze through it

tame nexus
#

Well, these 2 modules look fun and easy

#

Anyway, thanks <3!

#

I will be back

stoic quarry
#

Good luck!

median hound
#

Where can I learn Azure cloud Security Engineer course… where I can do lots of practicals

somber latch
#

Iβ€˜m completely beginner. I wanted to know if anyone can tell me what is the best way to start from scratch?

#

Any courses or smth else?

fleet pivot
#

hello

winged nimbus
#

i think it is safe to sleep

somber latch
twin ridgeBOT
#

Gave +1 Rep to @blissful current (current: #247 - 32)

stoic quarry
#

It requires some previous info tho, so I'd suggest finishing the other paths

#

For practicals just spin up an azure subscription imo

blissful current
#

do keep checking ..8 hrs still remaining lol

stoic quarry
#

I've given up trying this week, top in my league has 12000 points

blissful current
#

a guy literally did 9.4K points in less than 16hrs , popping in the leaderboard out of nowhere at # 1

stoic quarry
#

Assuming they're just grinding unauthorized write-ups

blissful current
#

ya

stoic quarry
#

I'm sure they'll do well in a job

blissful current
#

worse than skiddies

hallow hazel
#

true

dreamy marlin
sick lance
stoic quarry
#

Using write-ups for answers has the same energy as using chatgpt at work. It'll work for basic stuff but once you have to explain your working you're screwed

dreamy marlin
hallow hazel
#

I assume as much as the SAL1

sick lance
#

More than likely.

stoic quarry
#

Here's hoping THM get more acknowledgment in the cert field

twin ridgeBOT
#

Gave +1 Rep to @stoic quarry (current: #247 - 32)

strange dome
#

Hi everyone πŸ‘‹

stoic quarry
oblique loom
#

Sick with a cold and have my final in 2x days x.x

strange dome
#

I'm trying to get more hands on with learning Cyber. I've been studying it for almost a year now, but I don't really know anyone who is also interested in it. So if theres any community nights/events or whatever, make sure to ping me πŸ™‚

strange dome
stoic quarry
stoic quarry
oblique loom
#

The whiskey helps with the sore throat but my brain feels fried

stoic quarry
#

Advent of Cyber is the annual advent event, there was a big giveaway thing a while back.

#

Probably more coming up soon

strange dome
#

Tea might be a better option? Or if you still want something a little strong, maybe a hot toddy

#

Awesome, thank you Sil!

stoic quarry
#

Gotchu

oblique loom
#

I need to buy more tea, that is a better option

stoic quarry
#

I bought 200 teabags for like 5 local coins when I first moved

#

I've barely gone through half

strange dome
#

I don't enjoy tea that much, but I do love the smell of it

#

I have this one specific kind that I wish I could turn into a candle

stoic quarry
#

Tea scented fragrance time

#

I found a chocolate orange candle

#

Gamechanger that

strange dome
#

That sounds pretty great

#

I'm thankful that I decided to start with the very basics on TryHackMe. I got the IBM Cyber Security Analyst cert, and studied the whole program, but I feel like I'm learning a lot on THM that wasn't covered in the cert.

stoic quarry
#

Nice!

#

You should be pretty well prepared then

#

Done the pre-security path?

#

It's very fundamental heavy, but good to get those done early

strange dome
#

No im still in the pre security path. Doing OSI Model currently

stoic quarry
#

Good luck

#

Painful thing that

strange dome
#

Some of it I'm totally familiar with, and other stuff is brand new

#

Ty

dreamy marlin
strange dome
#

Yikes, don't say that xd I just started it

dreamy marlin
#

i hope windows and linux fun. will not be so boringgg

stoic quarry
#

It's good to know but it's theory that makes me want to cry

#

So good luck!

strange dome
#

Linux got a lot more fun for me after I finished classroom stuff and actually tried to use it for stuff

stoic quarry
#

Oh yeah 100%

strange dome
#

Like I wanted to host a VintageStory server for some friends. Think like Minecraft. But I built a homelab, and decided I would host the server on a VM running Ubuntu Linux. VintageStory is notorious for being really hard to host using linux. I probably learned more setting up that server than I did in my college class on linux

stoic quarry
#

Best way to learn is to dive in imo

dreamy marlin
sand trench
#

t minus 12 days if shadow lucky

strange dome
#

12 days till what?

umbral rain
#

?

boreal scarab
sand trench
sand trench
hallow hazel
strange dome
#

An MP3 player?

sand trench
sand trench
strange dome
#

Huh, I just looked up flac. Never heard of it before

sand trench
#

lossless compressed audio files basically

sand trench
#

i.e it has all the data that was originally there

sand trench
sick lance
sinful moon
#

I kind of miss running Rockbox custom firmware on things like my iPod 5.5th gen. Was lovely and supported FLAC and much more

sick lance
#

3.5mm and 6.35mm is analogue.

sinful moon
sick lance
#

Doesn't mean it's fake or real.

sinful moon
#

Supported quite a few devices

slow cloud
#

πŸ˜…

sand trench
strange dome
#

Literally me last night

sinful moon
#

lol it happens

boreal scarab
#

Try 2,800 packages.

sand trench
#

it is actually more then double the amount of packages shadow has installed :D

sinful moon
#

lol I do have a cursed Arch server with slightly less but yeah

#

just use it headless for infosec

slow cloud
#

this was on a kali vm

sand trench
#

oof updating kali

sinful moon
#

yeah we could tell from the apt parts. But do keep in mind the change in package signing or whatever that happened

hallow hazel
#

i have 1063 packages on my arch

sinful moon
#

very recently, they lost like the repo key or something silly

#

lol not great, but not as bad as Manjaro letting SSL/TLS certs expire multiple times and just telling users, β€œeh just roll your clock back for now”

strange dome
#

I'm considering punishing myself and moving on from Ubuntu to Arch, but I'm not sure I'm familiar enough with Linux and CLI to do so yet? Might try that website with linux cli practice games

sinful moon
#

The Arch wiki is a fantastic resource which will teach you a ton along the way, but yeah I’d say wait until you know that’s what you want

sand trench
#

arch wiki + gentoo wiki == lots of info that is helpful