#general

1 messages · Page 1124 of 1

blissful current
#

ello to u too , Bella wavey

#

(i had not noticed u were online too lol)

knotty valve
#

Ohhhh nice, those are pretty fun

#

I find them a lot easier tbh

#

I've never done them officially but I have gotten into places just by dressing nicely and they think I work there 🤣

#

Namely the law firm my friend works at

round onyx
#

that trick always work

knotty valve
round onyx
#

also the highvis vest, hardhat and clipboard route

knotty valve
#

Also make sure to ask subtle questions and get them naturally give you details you shouldn't know, and be good at lying so you can make them feel more comfortable in thinking you're legit

#

How I get info that I circle back to higher chains lmao, then wonder why we always have OPSEC meetings

#

One such example is finding out where specific offices are by talking to certain engagement teams

knotty valve
round onyx
#

in a cybersec setting for sure

knotty valve
#

Usually staff will know if something is going on construction or repair wise

round onyx
#

yeah its kinda situational

#

if you know there already a renovation going on or they needing extra hands to setup some stuff why not take advantage of that?

chilly veldt
#

Due to being so young still, I pulled the "new person just started and forgot my id" play

knotty valve
#

I've gotten into areas in uni by convincing the security staff that I was helping a lecturer

jade oar
#

just slept 14 hours

knotty valve
#

I've gone other routes but I can't disclose those ones cause of rules

knotty valve
#

Also knowing how to act stressed helps a lot

chilly veldt
#

Yuuuup

round onyx
jade oar
jade oar
round onyx
#

physical pentesting

knotty valve
#

^

jade oar
#

what does that mean

#

let me search it up

knotty valve
#

Physically getting into a facility you're not meant to and reporting it

jade oar
#

so good sneaky in simple words type shit

knotty valve
#

Yep

#

How good are you at lying

rapid merlin
#

Hey guys, how can I add my tryhackme level here

jade oar
#

i forgot smth in thm its a soulution when there is alot of traffic i forgot what u do

sharp citrusBOT
jade oar
#

or 7.5

blissful current
chilly veldt
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @sharp citrus (current: #61 - 144)

round onyx
jade oar
#

childhood was fun get ur ass beat and many shit in my opinion

knotty valve
jade oar
knotty valve
#

It was a requirement from my time in RAN

jade oar
#

thats madnness i mean i cant hate i love you got these skills

knotty valve
#

It's a requirement for most defence workers here tbh

#

Taught in the hopes of you never need to be in that situation

chilly veldt
#

Time to ask my teacher if I can take the exam faster than normal

knotty valve
#

Lol

knotty valve
chilly veldt
knotty valve
chilly veldt
# knotty valve Lol

I would rather go back to working 1 week earlier than to do nothing but wait for an exam

chilly veldt
round onyx
knotty valve
safe oxide
round onyx
#

anyway i gonna see what type of documents i could get my paws on in the open web :v

slow cloud
#

mornin'

sonic blade
#

mornin friend

slow cloud
#

🤔

sonic blade
#

Theres a fun document to get your hands on

slow cloud
#

So fun

#

A document from a person who just joined

#

Im not clicking that

rapid merlin
#

Security 101

sonic blade
#

Yeah that TLD is super scary

chilly veldt
slow cloud
heavy kindle
#

hello, is there a package to install on kali on a raspberry pi 3b+?

slow cloud
# heavy kindle hello, is there a package to install on kali on a raspberry pi 3b+?
heavy kindle
#

for arm64

#

i need istall discord package srry

slow cloud
#

Oh

#

Why not use the webapp?

#

Might be easier

versed veldt
#

I need some assistance with linux kernal issues, if anyone has knowledge

heavy kindle
#

i need something run fast, like a command line version of discord

#

is this available?

#

a text-only discord version exists?

sonic blade
# slow cloud You never know

I guess if you don't understand trust chains. Doesnt matter. Its just a Power PC compiler guide, something I thought was interesting. It isnt relevant as of like 2005

knotty valve
versed veldt
heavy kindle
sonic blade
#

You can interact with the Discord API to do certain things, but you didn't explain the use case so its kind of hard to say

knotty valve
#

Since they don't permit you to touch user accounts

sonic blade
#

I didn't suggest anything of the sort.

chilly veldt
sick lance
knotty valve
#

Yah

#

I actually have that section stickied on my keyboard

You may not copy, modify, create derivative works based upon, distribute, sell, lease, or sublicense any of our software or services. You also may not reverse engineer or decompile our software or services, attempt to do so, or assist anyone in doing so, unless you have our written consent or applicable law permits it.

heavy kindle
versed veldt
#

Upon installation of a Linux distro, I keep getting a "killed/killing" from signal 9. Is this a memory issue?

sonic blade
#

Interacting with the Discord API is not modifying clients or touching user accounts.

chilly veldt
knotty valve
#

Discord only permits you to utilise bot endpoints which are specific to registered applications

heavy kindle
knotty valve
#

Which is all described in the Discord Developer ToS

sonic blade
#

My goodness. Please just read the readily available documentation.

knotty valve
#

I know what a userbot is, and what they do and don't permit

sonic blade
#

No one said anything about a userbot; or at least I didnt.

versed veldt
#

Is anyone able to assist me with my kernal issues? If not I'll work it out

sick lance
knotty valve
versed veldt
sick lance
sonic blade
versed veldt
sick lance
versed veldt
#

true, I'll check again

chilly veldt
#

You cannot personally see this channel on a terminal based client without the server itself having a bit that ports the conversation to IRC, otherwise everything else would be termed as self botting

versed veldt
#

keep getting things like this: udevd [100]: /sbin/modprobe bu acpi: LNXSYSTM: [101] terminated by signal 9 (KI Iled)

heavy kindle
#

suddenly an error

#

after half hour of compiling .. there is an error

chilly veldt
#

Please do not talk about breaking ToS here, it'll get the server banned

sonic blade
#

some virtualized linux drivers dont treat acpi properly. if you turn it off in kernal boot params youll likely avoid the sig term

versed veldt
sonic blade
#

Consider it research :]

versed veldt
#

Fair enough

sonic blade
#

Here I will give you a hint: acpi - Shows battery status and other ACPI information. In a virtualized environment these parameters might not report properly during install and cause a sigterm because the installer isnt getting data from a true sensor

#

If you configure your virtualized boot config to ignore or disable acpi you wont hit the sigterm

versed veldt
sonic blade
#

Good luck, fam

sinful bobcat
safe oxide
#

Hallo kid

atomic veldt
#

hello

granite wind
#

anyone that's doing the pen testing/red teaming path. When did you start with the CTFs?

#

I recently got up to the junior pen tester path, should i finish the path then go ahead with doing the CTF rooms?

safe oxide
blissful current
#

F Around , Learn n Find Out

atomic veldt
#

i am beginner to and i facing some problems

blissful current
sonic blade
slow cloud
#

do ctfs

#

just start with em

atomic veldt
#

i was practicing df -h, mount, umount, lsblk. but not able understand and i am worried if i did mistake i can harm my files

slow cloud
#

see what you dont know and then you can improve like karma said

atomic veldt
#

so i was thinking practice online but not found any site to practice

slow cloud
#

Are you familiar with virtual machines?

atomic veldt
#

can give me some suggestion and tips

blissful current
#

Looking out for tools , specific CVEs , solutions to a problem is a part of learn ...ITS ALL SEARCH SKILLS

Just don't directly copy paste the flags
And do make notes if u learn something new to remember for next time

atomic veldt
#

yes but my laptop is not that condition to use vm in my laptop.

slow cloud
#

ahh

blissful current
#

Never try what you don't know what the thing can do directly on Host machine tho 😬

Try to look for online virtual labs

granite wind
twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #107 - 76)

heavy kindle
#

are virtual machines only used for using linux commands on a system?

granite wind
#

depends on what kind of virtual machine you have

rose solar
heavy kindle
slow cloud
#

You can see a virtual machine as a completely seperate machine, lets say you want to run some software which you unsure are of how legit it is, you could create an vm without internet, shared folders etc and test the program, you can run linux, windows, mac(but its difficult iirc). You can also use for getting more familiar with different OSses such as linux. if you break something you can just revert to a snapshot or create a whole new machine

rose solar
slow cloud
#

certain malware can escape sandbox enviroments ive heard

heavy kindle
#

so they are useless kind of

crystal moss
#

Morning! How are. We today?

slow cloud
atomic veldt
#

but my laptop will not support

slow cloud
#

i linked a site earlier did you check that?

atomic veldt
#

yes

slow cloud
#

did that work for you?

rose solar
atomic veldt
#

yes but i am stuck here

#

lsblk -f
NAME FSTYPE FSVER LABEL UUID FSAVAIL FSUSE% MOUNTPOINTS
nvme0n1
└─nvme0n1p1
nvme1n1 82.8G 17% /etc/hosts
/etc/hostname
/etc/resolv.conf

blissful current
atomic veldt
#

sudo mkfs.ext4 /dev/nvme0n1p1
mke2fs 1.46.5 (30-Dec-2021)
The file /dev/nvme0n1p1 does not exist and no size was specified.

#

what i did wrong here?

crystal moss
# rose solar Good and you

good! yeah, it's okay with me, but it's one of those days when I'm completely exhausted for no reason.. it'll get better, let's hope..

slow cloud
#

i dont know if that site will allow you to edit the filesystems of the machines

rose solar
crystal moss
atomic veldt
#

that's why i was not able to full fledged practice

slow cloud
#

If you have a usb stick you could install some linux distro on there

#

but youll still need to be carefull

rose solar
slow cloud
#

morning btw Jull3

crystal moss
crystal moss
rose solar
slow cloud
#

Pretty goooood, forcing myself to work tho

#

otherwise nothing will happen today

crystal moss
atomic veldt
# blissful current laptop specs?

OS: Ubuntu 24.04.2 LTS x86_64
Kernel: 6.11.0-26-generic
Packages: 2492 (dpkg), 22 (snap)
Shell: bash 5.2.21
Resolution: 1920x1080
DE: GNOME 46.0
Terminal: terminator
CPU: AMD Ryzen 3 3200U with Radeon Vega Mobile Gfx (4) @ 2.600GHz
GPU: AMD ATI Radeon Vega Series / Radeon Vega Mobile Series
Memory: 7042MiB / 9857MiB

heavy kindle
#

h

slow cloud
atomic veldt
#

i will buy a new pc but that's need some time maybe 1 or 2 month

crystal moss
# rose solar 😂yes

I'm just going to a small meeting, then I'll go home and try to get something done even though my head is like syrup...

light shuttle
#

I wanna know about bug bounty program , and what is the common vuln in low and medium ,pentesters found?

atomic veldt
#

can you suggest me what topic i can learn before buying new pc?

proven ivy
#

thanks for the info

twin ridgeBOT
#

Gave +1 Rep to @mellow narwhal (current: #156 - 56)

proven ivy
#

lol

slow cloud
#

yeah now it might a bit harder

slow cloud
atomic veldt
#

no

blissful current
slow cloud
#

then i would start with something like networking maybe

blissful current
#

Or maybe try KVM+Qemu?

slow cloud
#

cpu supports virtualisation

slow cloud
#

should you could install it and just see

#

You might have to enable it in your bios tho

atomic veldt
#

ok i will try.

muted bough
#

I had a problem here and kept stuck for a while when I was 100% sure my answers r correct then I refreshed and submit same answers and got the flag what was the problem tho

atomic veldt
#

which one i should try? KVM+Qemu?

muted bough
slow cloud
#

ive heard qemu is nice on linux but havent personally used it

slow cloud
muted bough
slow cloud
#

🔵 team is most fun

muted bough
slow cloud
#

depends on what you enjoy doing tho

#

red teaming has some fun things

muted bough
atomic veldt
#

thanks @slow cloud @blissful current

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #105 - 77)

slow cloud
#

+rep @blissful current

twin ridgeBOT
#

Gave +1 Rep to @blissful current (current: #202 - 42)

wraith tusk
#

wssup chataga

slow cloud
#

wassup

muted bough
#

+rep @slow cloud

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #103 - 78)

slow cloud
blissful current
#

+rep @slow cloud

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #99 - 79)

muted bough
#

Alr guys gtg continue my beginning learning journey cya

muted bough
blissful current
muted bough
knotty pendant
rapid merlin
#

Hello

slow cloud
rapid merlin
#

Hey karma, hey Arch bot

blissful current
#

Hey

slow cloud
#

hi

rapid merlin
#

How u guys doin

blissful current
#

Fine

#

Wby?

rapid merlin
#

at clients data center

#

Nd TL Fucked up

blissful current
#

What happened?

wet holly
#

Need help guys

blissful current
wet holly
#

How can i create pdf payload for android using kali linux (installed on my phone)

blissful current
#

I don't know if I should answer it , since it's illegal and I don't know ur purpose

wet holly
#

Bhai trust me, just learning due to interest not for an evil mindset and all.

#

Struggling since 3-4 days for same, hope you understand

storm storm
#

Debian No Root

#

use that

#

You can google it and it will show you how to download it

wet holly
#

But can't i use kali?

blissful current
wet holly
#

So can you tell privately?

blissful current
#

Probably No

#

Search online yourself is what I can say ...coz I'm not too sure either ..not into Android based hacking

wet holly
#

Fine bhai, thanks

storm storm
#

Please refer to it

wet holly
#

Bro ive already install kali

#

On phone

#

(Rooted)

chilly veldt
#

well to help you more correctly, what do you need the pdf for?

storm storm
#

So what is your problem now?

wet holly
#

I want to create a pdf format payload using only kali, for android remote acess

sick lance
#

For what purpose?

wet holly
#

And i just have a phone

modern thistle
wet holly
#

Its fun for me to learn these, not for anything illegal

chilly veldt
#

well you can't really do it

sick lance
wet holly
#

No bro, how would i prove you

storm storm
#

Linux once learned and mastered will be a very powerful tool for attacking or doing something illegal

sick lance
sick lance
chilly veldt
#

hmmmm, instant noodles or ordering from out?

deep geyser
#

what type of noodles

#

?

wet holly
#

@chilly veldt btw why this isnt possible?

chilly veldt
chilly veldt
rapid merlin
storm storm
wet holly
#

@chilly veldt so is there any effective way(without asking victim for permission)to do remote acc from my device

chilly veldt
#

no

deep geyser
#

to much but so how to little at the same time... so many questions... but this does make thing about marinating some chicken and using it for instant ramen that sound good lol

#

so ramen

sick lance
blissful current
#

pdf payload for learning purpose is SUS

wet holly
#

😅

#

But im just a random child

chilly veldt
#

I mean, then they would have to use android 10 or something

wet holly
#

Thats fine

chilly veldt
#

which is 4 major updates away

#

and many doesn't use

sick lance
deep geyser
#

just gonna keep that one for l8r actually

wet holly
#

Thats illegal but i wont do without permission becouse how would i learn hacking then, i just have this way, this device

chilly veldt
# sick lance 6% in 2025.

yeah, that 6% is most likely some android based systems and not personal phones like POS systems or something else 😄

sick lance
sick lance
#

We won't be assisting you.

chilly veldt
storm storm
#

Hacking is very difficult and not easy, but once you learn or explore it yourself, it becomes scary

wet holly
#

@sick lance No sir just a 12 grade child(not like deathnote's protagonist😅)

wet holly
#

17.5

#

Can i use eaglespy or crax type tools on kali(anyone halp please)

hearty otter
#

Penguin gatekeeping the pipeline

storm storm
#

No, we are afraid you will use it for illegal purposes

wet holly
#

Im not light yagami bro, i just having urge to learn it please help

queen flare
#

if you really care about learning, start with the basics
the way you're asking this makes me think you're trying to run before learning how to walk

#

even if you don't have illegal intentions, which i am doubtful about

storm storm
#

Just learn about networking and slowly you will have knowledge about linux

hearty otter
#

Who's linux

queen flare
wet holly
#

Why is everyone doubtful for me here😥, btw (you are right scorpious but how can i control urge to learn it then?)

queen flare
#

well it isn't our problem if you're not willing to put in the effort to learn something

hearty otter
queen flare
#

here it comes
linux is a kernel stuff

hearty otter
#

It's a kernel, you gotta say GNU/Linux

queen flare
#

i know lmao

hearty otter
#

Not OS

#

You're wrong even at joking

#

😭😭

queen flare
#

i thought you really didn't know anything about linux
so i said os, to not confuse you with theoretical stuff

wet holly
#

Its not i'm not willing to learn, but its to control urge of leaenig about remote acess

hearty otter
#

Surely

storm storm
# hearty otter Who's linux

It is a powerful operating system used to monitor and protect the system. It is often used by hackers to do illegal things

queen flare
#

but yes you're right

#

its technically a kernel

hearty otter
#

I was jk whole time lmao

queen flare
#

which is used to build operating systems, which you'd refer to as linux distros

queen flare
storm storm
#

I'm not hacker =))))

hearty otter
#

😭😭

queen flare
#

i wanna be a hacker one day

storm storm
#

I haven't even finished 4 years of college, how can I have enough knowledge to be a hacker? If I was that good, I would have become a white hat hacker already =))))

storm storm
#

be a legal hacker and don't do anything bad

wet holly
#

@storm storm bro pleassseeeee

#

Hellllpppp

#

Can i use eaglespy like tool in kali

storm storm
#

How can I help you when I can't even be sure you're using it for the right purpose?

wet holly
#

How would i prove broooo

storm storm
#

My honest advice is if you want to learn about linux operating system then start with the basics first after you have knowledge and professional ethics there will be people to help you

ornate lynx
#

guys how do i start to learn hacking?

wet holly
#

Same

storm storm
#

Start with the basics like networking, programming languages

#

U can learn at try hack me

ornate lynx
storm storm
#

Programming languages ​​are also related to tools, it will also make you understand how the source code works. This is really important when learning cybersecurity

heavy kindle
#

can i create a web server here in tryhakme and then try to hak it from outside?

storm storm
#

apparently not

heavy kindle
#

or its just about attacker and victim hosted on same tryhackme machine

storm storm
#

you don't need to do that, in try hack me it has a virtual lab to practice

heavy kindle
#

aha

#

and i can set up my own webserver there?

storm storm
#

if it is not enough you can also go to hack the box

versed veldt
#

However, nothing is stopping you from designing your own html/php file hosting it using Python simple server and hitting your own site you host to help learn how to defend

blissful current
#

not here but u can setup ur own labs

for that also many factors matter the Web Hosting , Domain, Network/ISP, Dedicated Server etc should be owned by you
else its pretty much illegal

#

making your own site and hosting it somewhere on platforms and trying doesn't count as "Owning" so be careful of that

heavy kindle
#

so maybe hack my own webserver hosted on a local machine using the ip is ok

versed veldt
#

Well, you'd be hosting on your own machine, as localhost not an actual world wide host. Idk, really

#

There's "grey areas" in between the white and black areas. Got to be careful with the things you try

slow cloud
#

if its a local machine that you own you can do whatever you want with it

heavy kindle
#

ye

slow cloud
blissful current
versed veldt
#

Yeah, that's what I was trying to get at, use python simple server to self host

heavy kindle
#

vulnhub is the same? hacking from vulnhub local machine to local vulnhub server?

versed veldt
#

Vulnhub is just a list of known exploits for services

#

DO NOT try attacking the vulnhub server please

heavy kindle
#

i see u can create virtual machines there

versed veldt
#

wait, I maybe thinking of the wrong site lol. Let me look

heavy kindle
#

or is the virtual machines that u download and then host them locally or what

modest charm
#

it seems so. You download vulnerable vms and play with it locally

versed veldt
modest charm
#

I never used it though

heavy kindle
#

thanks guys for the info

versed veldt
#

That offers a lot of hackable VMs as well

cerulean aurora
#

How to use OTMIN Seceon AI's automated email system to send reports

lucid maple
blissful current
#

you'll also need a Domain

knotty valve
#

Or POP if you're an oldy

crystal moss
#

Today it is a webinar from THM "Boosting Offensive Ops with AI" who is attending ?

#

Hello @knotty valve Tomorrow it is time:D

knotty valve
#

Don't think I'm gonna be sober for half of it

#

So it's gonna be fun

cerulean aurora
#

domain like what ?

rapid merlin
#

I’m crying

knotty valve
#

LOL

crystal moss
# knotty valve Yesss

We decided to run both, some run Nahamsec and some HackOSINT, my group runs OSINT... hehe.. drunk CTF:D

knotty valve
crystal moss
#

whare do i get a key? heheheh. Should that day come.. Then it's time to write your own...

knotty valve
#

I feel like I'm one bad moment away from just yeah

#

Probably shouldn't express that here LOL

blissful current
cerulean aurora
inner tendon
#

crystal moss
#

Tip again about the Webinar that is today organized by THM with the topic "Boosting Offensive Ops with AI" starts at 04:00 EM

knotty valve
#

Enough drinks and it'll disappear

#

Eventually

chilly veldt
#

I am laying home sick, so most likely no ctf for me

knotty valve
#

F

chilly veldt
#

but one of my teams are playing nahamcon

knotty valve
#

Hope you get better Bella 🩶

#

Half my team is doing hackosint

chilly veldt
#

just some fever and a hurty throat

stable agate
#

Unable to purchase TryHackMe subscription

crystal moss
sharp citrusBOT
#

@stable agate

TryHackMe's Email

TryHackMe's support email address.

knotty valve
#

Did I beat scrubz to it

#

Lmao

crystal moss
#

+rep @knotty valve

twin ridgeBOT
#

Gave +1 Rep to @knotty valve (current: #165 - 52)

stable agate
knotty valve
crystal moss
sick lance
knotty valve
grizzled stump
#

Wsg

round onyx
#

Scrubz is the one to beat I see...

grizzled stump
#

How’s everyone this fine morn

round onyx
#

Geolocating interiors should be considered unusual torture/punishment

knotty valve
#

There's enough evidence in the interior lol

#

I may be coaching this CTF then lmao

round onyx
knotty valve
#

Today went from okay to horrible

crystal moss
crystal moss
knotty valve
#

I'll be alright

crystal moss
knotty valve
#

Oh tomorrow is gonna be horrid lol

crystal moss
#

🙂

knotty valve
#

It'll be one hell of a hangover

crystal moss
#

hehe

knotty valve
#

About six standards deep lol

#

Maybe more

crystal moss
#

i do not drink at all....

silver sky
#

No alcohol for me either

#

Fight camp

#

Eating clean

crystal moss
#

I've done it before, but honestly it's not something I like. Sure, it can be nice to have a beer sometimes, or a cider. But it happens extremely rarely.

blissful current
crystal moss
#

I don't smoke cigarettes (anymore, not even a joint :p) but I have a huge addiction to snus!

blissful current
knotty valve
#

I smoke which I DO NOT recommend

#

It's a horrible habit

chilly veldt
#

snus is good

blissful current
#

i have never done smoking/vape/hookah thing etc
never will

chilly veldt
#

don't take snus anymore though

blissful current
#

whats snus?

knotty valve
#

Don't start

knotty valve
chilly veldt
#

lip pouches

#

zyn

knotty valve
#

God it's hard to type on a moving tram

blissful current
versed veldt
knotty valve
#

At least the one perk of my tolerance is I'm still coherent and able to walk straight even when intoxicated

queen flare
#

what ctf are we discussing

knotty valve
#

Earlier we were talking about HackOSINT and Nahamacon iirc

#

I think that's how the latter was spelt

queen flare
crystal moss
round onyx
blissful current
kindred sinew
#

GG im top 3 on worldwide monthly leaderboard

knotty valve
#

Like usual

queen flare
crystal moss
blissful current
knotty valve
round onyx
kindred sinew
#

will i get any reward from tryhackme if i will end monthly leaderboard global on 1st?

knotty valve
#

Yeah that makes more sense

crystal moss
#

🙂

kindred sinew
#

rllyy?

queen flare
#

except for bragging rights

kindred sinew
#

not even swag?

blissful current
#

neh

MAYBE a Badge but not sure

kindred sinew
#

i will research

queen flare
#

i have never heard of someone being rewarded for their monthly rank

crystal moss
#

@knotty valve you joining the webinar by THM today?

blissful current
knotty valve
#

Or awake for it

queen flare
#

i was on the global monthly leaderboards for a short time once

knotty valve
#

What's the UTC time for it?

crystal moss
#

04:00 EM

queen flare
#

started as soon as the month started and solved a bunch of room

#

i was eventually surpassed by others

round onyx
crystal moss
knotty valve
#

F

blissful current
queen flare
#

wdym

#

i didn't join this server 9 days ago

blissful current
#

Not u

queen flare
#

which guy

#

a lot of high ranked people who grind on thm haven't joined this server yet
its not really suspicious

blissful current
#

ya thats tru too

#

anyways

queen flare
#

how can sequencer know and list the token name in response i am testing for, if i only sent a captured request to the login form, that only contains a cookie and no mention of the token in it

#

i only captured the request and didn't forward it through proxy yet, so how can burp know what things are present in the response already?

smoky widget
#

sayyy, without judgement, would tryhackme look great if they had theme collabs like how fortnite has these events and stuff

knotty valve
#

Well outside of scope imho

#

Ohhhh events

blissful current
knotty valve
#

Sorry I only read half of it

#

I thought they meant website

stark sequoia
knotty valve
#

And not events 😅

blissful current
smoky widget
knotty valve
#

Would probably be something they might do yeah

smoky widget
queen flare
knotty valve
#

Sorry about dismissing it 😅
I only read the first half

smoky widget
queen flare
#

i did send some requests to the same url earlier though
did it analyse those responses to be able to list the cookies and fields?

stark sequoia
#

I also think its cool if they added an AI feature for the lessons that summurizes and tells you what you covered the previous day, like what datacamp does

knotty valve
#

It's a nice use of LLMs

queen flare
knotty valve
#

Yeah might be worth watching YT vids on how it works

#

Or read the burp docs

#

Idak how sequencer works either lmao

queen flare
#

hm, guess i gotta read docs
thanks

#

+rep @blissful current

twin ridgeBOT
#

Gave +1 Rep to @blissful current (current: #199 - 43)

queen flare
#

+rep @knotty valve

knotty valve
#

Nah I don't need the rep

#

It was Karma who suggested the main idea

queen flare
#

you didn't get it either, for some reason lmao

knotty valve
#

To prevent rep spam

queen flare
#

oh right

#

rate limit

sick lance
#

The irony is the answer is in your question.

blissful current
blissful current
#

ping

#

is the command

queen flare
#

the syntax is ping 10.10.10.10

knotty valve
#

😂

deft quest
#

The webinar today is by 15:00 WAT right?

knotty valve
#

Me whenever I overthink things

blissful current
#

i was gonna answer but i was wondering if i got his question wrong or something lmao

queen flare
#

same xD

knotty valve
#

And not literally ping <target>

#

I was gonna suggest using man ping

blissful current
#

ya

deft quest
#

Any idea please

knotty valve
#

Idk I'm not attending it lol

sick lance
knotty valve
#

I'm asleep whenever it's happening

deft quest
queen flare
#

i don't think i've read ping commands manual yet lmao

knotty valve
deft quest
knotty valve
#

I just know ping -c <target>

sick lance
queen flare
#

ya same

knotty valve
#

It's technically ping [-c amount] <target> but whatever

#

We understand what c does

blissful current
#

<t:1747922400:F>

sick lance
#

It's 3pm GMT.

knotty valve
#

I'd appreciate if autocorrect would stop capitalising me

sick lance
#

So in 2 hours and 10 mins.

deft quest
knotty valve
#

Jesus

knotty valve
blissful current
sick lance
shut hawk
#

Do you live in the UK?

frozen charm
#

I just did a quick OSINT check on the #1 player on my THM weekly leaderboard

#

N know what?

#

He's just copy pasting from the walkthroughs

deft quest
blissful current
deft quest
frozen charm
knotty valve
#

Ik

frozen charm
#

mfs

knotty valve
#

I'll be asleep when it's on

#

Lol

deft quest
sick lance
deft quest
twin ridgeBOT
#

Gave +1 Rep to @blissful current (current: #197 - 44)

blissful current
blissful current
deft quest
frozen charm
blissful current
#

by joining their server

deft quest
shut hawk
#

are you ok with your name being on there

blissful current
crystal moss
deft quest
shut hawk
#

👌 all good

deft quest
deft quest
sick lance
deft quest
crystal moss
#

normally ismy OPSEC ok, but today.. not so, apparently hehe..

shut hawk
#

It happens to us all

round onyx
#

yep

#

made that mistake once and never again

kindred sinew
blissful current
kindred sinew
#

global top 3

queen flare
#

dang, congrats

blissful current
frozen charm
#

congo

crystal moss
# round onyx yep

In some situations it can be devastating, especially if you're chasing bad guys.. OPSEC is something to hold tight to! But sockpuppets have many names and faces 😄

crystal moss
sick lance
#

The worst thing about finishing uni, is awaiting our results.

carmine stream
#

morning THM team

sick lance
#

Good afternoon.

carmine stream
#

3rd remote day this week, another 8 months to a year to go

#

not sure how i feel

#

I def need like a few days to just deep clean-

#

i got to much pto there trying to make me use it

sick lance
#

@thorny parcel

Please don't send me a DM without asking, or even letting me know what it's about.

carmine stream
#

damn straight called him out

sick lance
carmine stream
#

Rules are rules I guess

rapid merlin
#

Rules are rules

cursive bobcat
#

rules / rules = 1

carmine stream
#

I need to level up I dont like yellow

queen flare
carmine stream
#

awe man

queen flare
#

because there are no other colours except blue when you're master

#

then green goes on again

rapid merlin
carmine stream
#

can yall just make me purple permanatly Cry

queen flare
carmine stream
#

ill boost 🥲

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @queen flare (current: #206 - 41)

cursive bobcat
#

outsource your account to upgrade lol

carmine stream
#

oh nah nah

deep geyser
#

Kream250?

carmine stream
#

what

sick lance
sick lance
carmine stream
#

I didnt bust my ass for piss yellow

queen flare
#

so it is known as pee yellow

round onyx
blissful current
crystal moss
safe oxide
#

Hallo people

carmine stream
#

what up geek

crystal moss
cursive bobcat
safe oxide
safe oxide
#

How's it goin

sick lance
crystal moss
knotty valve
#

What did I just come back to lmaoo

cursive bobcat
#

mod crying

knotty valve
#

I don't see a joke anywhere tbh

sick lance
crystal moss
#

haha, I saw I forgot to write "about you" so it just became "So what?" ..

sick lance
#

We don't, and have never allowed rules that break ToS, illegal or unethical topics

knotty valve
crystal moss
knotty valve
#

Two more train stops

#

Then I'll be almost home

queen flare
#

i would like to see companies listing sal1 and pt1 certs in their recruitment ads

crystal moss
queen flare
#

the certs have a great syllabus, but it would take a bit for recruiters to see what its worth

sick lance
knotty valve
queen flare
knotty valve
#

Certs take a bit to popularise through employers

crystal moss
#

However, these certificates will not be able to compete with OSCP etc.

knotty valve
#

Yeah

safe oxide
knotty valve
#

An employer will take a Pen-200 completion over PT1

queen flare
#

than its been a couple of years ago

knotty valve
queen flare
#

i got a couple of years till graduation anyways

#

so i'll be able to see how it goes before taking any cert

crystal moss
#

But these certificates from THM are not bad to have, it shows that you are committed and have a drive to learn.

knotty valve
#

Not to throw THM under or anything, but if I was giving candidates to a job, I'd take someone with OSCP over PT1 or SAL1

sick lance
#

I mean..

#

Duh?

#

They're new...

knotty valve
#

Cause I can be safe in knowing there's no copy-paste solutions with proctored exams

knotty valve
carmine stream
queen flare
knotty valve
crystal moss
sick lance
#

It helps.

queen flare
#

but yes, i bet thm certs would be quite popular in a few years

cursive bobcat
#

yeah the certs on THM are just like doing a course on coursera

sick lance
#

But it's not

"You don't have OCSP, no job for you".

knotty valve
queen flare
carmine stream
knotty valve
sick lance
queen flare
#

if you're talking about linkedin/coursera one's
i don't think its fair to compare them to thm certs

sick lance
#

It's not essential.

knotty valve
#

It kinda is for a lot of places

crystal moss
# sick lance It's not essential.

Maybe it's not the most important, but it's a big plus if you have OSCP and other "heavier" certificates. For example, I have a friend who is the head of security and pentesting at a large company and is currently looking for a new hire, and anyone who has OSCP or heavier is the one who has a better chance of getting the job!

sick lance
#

I've been offered two jobs that don't require it.

knotty valve
#

I can short cut it by going defence route and it'll amount to the same as an OSCP

sick lance
#

It's not even asked for.

knotty valve
sick lance
carmine stream
#

Yea HR typically doesnt know what there looking for anyways

sick lance
#

It's marked essential for a job 🤷

carmine stream
#

they also say u need a bach degree

knotty valve
crystal moss
gloomy sedge
#

Hey

carmine stream
#

I def dont have one and dont plan to get one

knotty valve
#

You're not disproving me here

sick lance
#

Because you seem to think you're right.

#

So it won't change your mind.

#

Regardless of what you're told.

knotty valve
#

So do you?

carmine stream
#

There are plently of jobs that do and there are jobs that dont

knotty valve
#

It's gonna be back and forward lol

cursive bobcat
#

fight

carmine stream
#

whether you think your right or not doesnt matter the data is thare and you can do what you will with it

knotty valve
#

Agree to disagree

#

Idrc that much about who's right

carmine stream
#

some of us have landed jobs just fine without it

crystal moss
#

Of course, it also depends on what role you are looking for, what company it is and what requirements they have.

queen flare
#

i think what ashlynn wants to say is that if you're a recruiter, and have 2 candidates to choose from, one of whom has a thm cert and the other one has an oscp cert, she would choose oscp over thm

#

this i agree with

cursive bobcat
#

well they are official certs arnt they

carmine stream
#

Yep and the landscape will change

#

people wont be required to drop the cash like that to specialize

rapid merlin
#

I put the cereal back the fridge

crystal moss
#

This is from the ad that my friend is the head of the department at and I think it's pretty much the same across the board: Desirable: Certifications in: GNFA, GCFE, GPEN, GREM
Desirable: Offensive Security Certified Professional (OSCP) or Organization for Security and Co-operation in Europe qualifications

knotty valve
#

I'm just gonna chalk it up to a regional moment

#

And agree to disagree

queen flare
queen flare
#

imma post another ben emote and then go grind on thm or something

knotty valve
#

It's not really worth arguing over lol

queen flare
cursive bobcat
#

you are both wrong anyway

queen flare
#

i actually just finished grinding on thm

#

imma go touch grass

carmine stream
crystal moss
#

Everyone has different opinions and perceptions, and it can differ greatly between different companies and perhaps even in different countries.

sick lance
#

Job listings can be wishlists.

crystal moss
#

Of course, as in the ad I referred to: "desirable"

cursive bobcat
knotty valve
#

Or hard requirements in cases

crystal moss
#

as said, can differ from case to case.. but as said, it is of course a boon to have heavy certificates regardless of whether it is a requirement or not..

knotty valve
#

Damn light pollution is visible af

crystal moss
loud marlin
#

ill be home in 10 days. atm in bussines trip on 2nd half of europe 🙂

cursive bobcat
knotty valve
#

So I could see the stars

cursive bobcat
#

hack it

crystal moss
unique phoenix
carmine stream
#

dont get muted lol

slow cloud
#

so glad you dont too much light pollution here

crystal mauve
#

tipsfedora good morning

crystal moss
#

Apparently Light pollution is a significant issue in Sweden, particularly in urban areas, but I didn't even know it existed...

carmine stream
knotty valve
crystal moss
knotty valve
#

Afaik junctions are mostly airgapped

#

Or physically controlled

blissful current
knotty valve
#

Ikr

crystal moss
shy vortex
#

gooodmorning

sick lance
#

Power stations have IT/OT.

They're fun to hack.

knotty valve
#

Ohhh

#

Maybe something I could get into one day

crystal moss
#

😛

slow cloud
cursive bobcat
#

call KGB lol

sick lance
#

Usually just abuse then modbus traffic.

Systems are are legacy so they're vulnerable to alot of stuff.

knotty valve
sick lance
crystal moss
carmine stream
cursive bobcat
#

imagine having a little ai hacker robot that could sneak into such places

sick lance
round onyx
#

this starting to sound like the type of hacking in watch dog 2

blissful current
knotty valve
#

Given how oil lines in America got hacked

crystal moss
#

There are many examples where critical systems have had really stupid configurations or misconfigurations.

knotty valve
#

Checks out lol

sick lance
blissful current
#

I'll Watch Final Destination at night ...in my VR … anxiety++

crystal moss
#

just one of many examples eg: Critical SCADA system – Password: admin/admin
Several water utilities in the US and Europe have had web-based control panels exposed to the internet, sometimes without authentication at all – or with default passwords such as admin/admin or root/root.
Example: In 2011, a group (Cyber ​​Berkut) hacked a water utility in Illinois via their exposed SCADA web interface, in part because the password had never been changed from the factory settings.

slow cloud
#

if iot is "internet of things" is OT just "of things"?

sick lance
#

Scads has a jsp backdoor issue also

#

OT is operational technology

crystal moss
#

or Traffic/Signal Control Systems where Telnet/FTP has been open
Sometimes traffic lights, subways and signal systems have exposed legacy systems on e.g. port 23 or 21, often without any authentication at all.
Black Hat talk 2014: “How to Hack All the Traffic Lights” showed that US traffic systems had publicly accessible consoles with default passwords

slow cloud
carmine stream
#

I couldnt believe the security on scada when I got in the work field

blissful current
carmine stream
#

its ridiculous

crystal moss
#

It's like I always say - people are the biggest vulnerability and threat to security...

blissful current
slow cloud
sick lance
knotty valve
crystal moss
#

Then regarding water purification etc., something happened about a year ago in Sweden, a small drinking water facility in a small town was broken into, there were no alarms or surveillance cameras there... luckily nothing happened, probably some meth head with a crowbar, but it's scary..

blissful current
#

how coincidental ...i had got a Job Post Notification for OT CyberSec from GlassDoor lol

knotty valve
#

Lol

crystal moss
crystal moss
# knotty valve Wha-

This is from a newspaper in sweden: "The day before Christmas Eve, a break-in was discovered at a raw water source in Tranemo municipality. Now another one of the municipality's water facilities has been compromised. This time there is no risk that the water is unusable."

knotty valve
#

Oof

crystal moss
#

I don't understand how they can leave it without an alarm or camera surveillance. It was also located in a remote forest area with a simple door, so they could work completely undisturbed.

crystal moss
#

Damn. I've made the same mistake again, I've been way too active with ctfs and rooms on both THM and HTB, now my motivation is starting to drop again.. I know I shouldn't do that, I should take a few days off and do something else, but I can't keep myself away:D I also know that the motivation will come back, but I should have learned by now..

dark mason
#

This was from an OSINT challenge, the ctf was also state sponsored

carmine stream
#

lmfaooo

mellow narwhal
#

or play some physical sports

#

listen to your fav playlist

safe oxide
#

Physical lol

#

Julle go run a mile

#

A sub 7 min mile

knotty valve
#

Doubt any of us could do that

safe oxide
#

Hmm prolly if someone is skinny enough

#

Ive seen skinny crossfit ppl do insane miles

knotty valve
#

I'm 50kg and I can't do it 😂

safe oxide
knotty valve
safe oxide
#

Yes

knotty valve
#

I'm severely underweight

safe oxide
knotty valve
#

Yes

#

That's underweight lol

brisk abyss
#

Just chill bro @knotty valve

safe oxide
#

I have a friend whose like 56 he's 40 and he thinks he's oversight lol

finite basin
#

yoo

safe oxide
knotty valve
#

But no, in my case, I'm medically underweight

safe oxide
#

How do you find out if you're underweight?

#

Bmi?

knotty valve
#

BMI and medical examinations

safe oxide
#

Hmm

knotty valve
#

BMI doesn't account for muscle mass vs fat mass, hence the need of medical evals

brisk abyss
#

Eat something nice bro, drink enough water and don't sleep late

knotty valve
#

That doesn't work for everyone, sis

#

There's a magical thing called metabolism

#

And also eating disorders

sick lance
#

Hyrox and OCR is better.

safe oxide
brisk abyss
safe oxide
#

But the old one was just the fire fighter training

knotty valve
safe oxide
knotty valve
safe oxide
#

Def

knotty valve
#

Generally you're not supposed to control it cause it's going to change naturally

safe oxide
#

Sometimes it easy to gain wait you start walking a bit and now you're a bug lol

crystal moss
#

Woop Woop. Soon time for the THM Webianar.. waiting

pine sonnet
#

Hello

stark sequoia
#

hi

slow cloud
#

hi

lucid elk
#

hi

mossy river
crystal moss
#

Now the webinar is over.. Thanx THM.. Nothing new that I learned but always interesting..:P

upper knoll
#

You sent an email to support?

crystal moss
#

Some countries it's not possible to buy because of something with banks. I don't know if that also applies to India..

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

crystal moss
#

contact support by mail.. i did post a link.

bleak quartz
#

A friend of mine has @worldly hearth, so ig he could help u?

crystal moss
#

it is just the last digtits..

sick lance
#

Let's not advise members on how to bypass restrictions.

#

They're placed for a reason.

brisk abyss
#

just level up, woothoot

crystal moss
brisk abyss
crystal moss
#

I personally have about 500 points left for a modest 0x9 [Mage] ..:D

brisk abyss
hearty otter
#

If i have 6 eggs in the fridge, how many eggs get sold in the US each year

slow cloud
#

All the apt rooms are so fun

sick lance
hearty otter
bleak quartz
# sick lance Let's not advise members on how to bypass restrictions.

Using an alternative payment method because your bank doesn’t fully trust THM doesn’t violate any of Tosses.

Many banks have these security measures in place (which you can often request to have removed or made to be less strict, at least in most countries, you can google if that's the case in urs). They’re simply trying to protect users from potential risks. It’s not illegal to use alternative payment methods in such cases it’s basically just a workaround and also it removes the liability from the bank of any scams like if you buy a paysafe card and use it to buy a game on website thats turns out to br a scam, the bank is not responsible it's paysafe whos job is to help u, yes bank can too but it's not their "duty". Anymore

silent nova
hearty otter
silent nova
#

I'm partaking in a Tier 2 Security Analysis-based time-attack competition soon, and I can see your general point of view when it comes to these things. When filtering through the SIEM for logs during training, me and the other members of my team kept running into issues with how exactly to look for the logs that we needed.

(In one case, what network connection was suspicious simply off of # of connections logged in the firewall)

hearty otter
#

Real

sick lance
#

So using this method to bypass, would be unethical and violating the ToS of THM.

hearty otter
#

Idk much about security actually, just enough to keep things secure when I build something

eternal roost
hearty otter
sick lance
#

But there are ways to tell if they're using a VPN.