#general
1 messages · Page 1124 of 1
Ohhhh nice, those are pretty fun
I find them a lot easier tbh
I've never done them officially but I have gotten into places just by dressing nicely and they think I work there 🤣
Namely the law firm my friend works at
that trick always work
Yello
Dress the part, chat up one of the employees that are on break, walk in with them, access gained
also the highvis vest, hardhat and clipboard route
Also make sure to ask subtle questions and get them naturally give you details you shouldn't know, and be good at lying so you can make them feel more comfortable in thinking you're legit
How I get info that I circle back to higher chains lmao, then wonder why we always have OPSEC meetings
One such example is finding out where specific offices are by talking to certain engagement teams
A lot harder to pull off
in a cybersec setting for sure
Usually staff will know if something is going on construction or repair wise
yeah its kinda situational
if you know there already a renovation going on or they needing extra hands to setup some stuff why not take advantage of that?
Due to being so young still, I pulled the "new person just started and forgot my id" play
I've gotten into areas in uni by convincing the security staff that I was helping a lecturer
just slept 14 hours
I've gone other routes but I can't disclose those ones cause of rules
This works in two cases: being young, or being in your late 40s
Also knowing how to act stressed helps a lot
Yuuuup
christ what did you do yesterday?
i just slept i had people calling me 200 times i was out
what you guys talking about being sneaky
physical pentesting
^
Physically getting into a facility you're not meant to and reporting it
so good sneaky in simple words type shit
Hey guys, how can I add my tryhackme level here
i forgot smth in thm its a soulution when there is alot of traffic i forgot what u do

One of the things that's good about a traumatic childhood
Thanks Ash
Gave +1 Rep to @sharp citrus (current: #61 - 144)
i could generally get people off of my ass if they want something so 6/10
childhood was fun get ur ass beat and many shit in my opinion
Also taking a mandatory course in interrogation techniques
added to the list see you tutut
It was a requirement from my time in RAN
thats madnness i mean i cant hate i love you got these skills
It's a requirement for most defence workers here tbh
Taught in the hopes of you never need to be in that situation
Time to ask my teacher if I can take the exam faster than normal
Lol
Want a little Osint challenge?
In a bit sure
Ez, I'll open my DMs lmk when you're ready
I would rather go back to working 1 week earlier than to do nothing but wait for an exam
Give me like 10-20 minutes
sending another person into a goosechase are we?
Should be easier than prior ones I've done

anyway i gonna see what type of documents i could get my paws on in the open web :v
mornin'
mornin friend
🤔
Theres a fun document to get your hands on
Security 101
Yeah that TLD is super scary
You can just dm me, I am having to drive again now, cause I'm going home, caught some sickness
Easy, sending now
You never know
hello, is there a package to install on kali on a raspberry pi 3b+?
https://www.kali.org/docs/arm/raspberry-pi-3/ have u checked this?
The Raspberry Pi 3 has a quad core 1.2GHz processor, with 1GB of RAM. Kali Linux fits on an external microSD card.
By default, the Kali Linux Raspberry Pi 3 image contains the kali-linux-default metapackage similar to most other platforms. If you wish to install extra tools please refer to our metapackages page.
I need some assistance with linux kernal issues, if anyone has knowledge
i need something run fast, like a command line version of discord
is this available?
a text-only discord version exists?
I guess if you don't understand trust chains. Doesnt matter. Its just a Power PC compiler guide, something I thought was interesting. It isnt relevant as of like 2005
Nope
Not technically, although, some discord servers do offer what you want. Some are linked with IRC which is command line chat only
wt about 6cord
You can interact with the Discord API to do certain things, but you didn't explain the use case so its kind of hard to say
Using unofficial clients breaks tos
Since they don't permit you to touch user accounts
I didn't suggest anything of the sort.
Yeah, it's called IRC
Or modify the client.
Yah
I actually have that section stickied on my keyboard
You may not copy, modify, create derivative works based upon, distribute, sell, lease, or sublicense any of our software or services. You also may not reverse engineer or decompile our software or services, attempt to do so, or assist anyone in doing so, unless you have our written consent or applicable law permits it.
can you view discord servers on irc?
Upon installation of a Linux distro, I keep getting a "killed/killing" from signal 9. Is this a memory issue?
Interacting with the Discord API is not modifying clients or touching user accounts.
Nobody said it was.
No
Interacting with user-only endpoints is indeed touching user accounts
Discord only permits you to utilise bot endpoints which are specific to registered applications
i need client to view this conversation, so IRC no good then
Which is all described in the Discord Developer ToS
I've worked with discords API for years
I know what a userbot is, and what they do and don't permit
No one said anything about a userbot; or at least I didnt.
Is anyone able to assist me with my kernal issues? If not I'll work it out
What is your issue exactly?
If you think you're right, why don't you go ask support (https://dis.gd/contact) and argue with them about their ToS 🩶
Keep getting kill signaling from the kernal during initial install from a "signal 9"
Have you checked to make sure your installer isn't broken?
I'm sorry but I didn't even make a claim to be right or wrong about. Apologies if I offended you but I don't really understand what you think I said.
No, I got the distro directly from it's source page. Issue may lie in the fact I'm emulating. Probably not cpu related (Pentium 2) maybe a hard drive or host machine memory issue??
Just because you it from then source, doesn't mean it didn't corrupt during download
Which os is it?
true, I'll check again
You cannot personally see this channel on a terminal based client without the server itself having a bit that ports the conversation to IRC, otherwise everything else would be termed as self botting
Core distro 19MB no gui variant of Tiny Core)
keep getting things like this: udevd [100]: /sbin/modprobe bu acpi: LNXSYSTM: [101] terminated by signal 9 (KI Iled)
thats bad, that follows my opinion that today everything in it gets so advanced that u cant use it anymore lol
suddenly an error
after half hour of compiling .. there is an error
Please do not talk about breaking ToS here, it'll get the server banned
try turning off acpi
some virtualized linux drivers dont treat acpi properly. if you turn it off in kernal boot params youll likely avoid the sig term
Could you dm me details?
No. I gave you enough to go on.
Consider it research :]
Fair enough
Here I will give you a hint: acpi - Shows battery status and other ACPI information. In a virtualized environment these parameters might not report properly during install and cause a sigterm because the installer isnt getting data from a true sensor
If you configure your virtualized boot config to ignore or disable acpi you wont hit the sigterm
appreciate your time, I'm emulating on an Android. I'll try doing your suggestions
Good luck, fam

Hallo kid
hello
anyone that's doing the pen testing/red teaming path. When did you start with the CTFs?
I recently got up to the junior pen tester path, should i finish the path then go ahead with doing the CTF rooms?
Hallo
Just start ...don't wait for paths
F Around , Learn n Find Out
i am beginner to and i facing some problems
What's the issue 
Follow the path, If you jump ahead into the CTF rooms you will likely not have the prerequisite knowledge to solve on your own, meaning you will end up looking up the answer.
i was practicing df -h, mount, umount, lsblk. but not able understand and i am worried if i did mistake i can harm my files
see what you dont know and then you can improve like karma said
so i was thinking practice online but not found any site to practice
Are you familiar with virtual machines?
can give me some suggestion and tips
Looking out for tools , specific CVEs , solutions to a problem is a part of learn ...ITS ALL SEARCH SKILLS
Just don't directly copy paste the flags
And do make notes if u learn something new to remember for next time
yes but my laptop is not that condition to use vm in my laptop.
ahh
full disclosure ive never used this
https://labex.io/tutorials/linux-online-linux-playground-372915
Never try what you don't know what the thing can do directly on Host machine tho 😬
Try to look for online virtual labs
yea i think that might be the play, sometimes i give in and look up a walkthrough but i just wanna avoid doing that....
Thanks!
Gave +1 Rep to @slow cloud (current: #107 - 76)
are virtual machines only used for using linux commands on a system?
depends on what kind of virtual machine you have
No they can be used in everyday life and also to execute suspicious files without fear
so they kind of encapsulated and isolated arent they
You can see a virtual machine as a completely seperate machine, lets say you want to run some software which you unsure are of how legit it is, you could create an vm without internet, shared folders etc and test the program, you can run linux, windows, mac(but its difficult iirc). You can also use for getting more familiar with different OSses such as linux. if you break something you can just revert to a snapshot or create a whole new machine
Yes but I had heard about that some viruses can pass on the network after I don't know if it's true but always have to be careful
certain malware can escape sandbox enviroments ive heard
great
so they are useless kind of
Morning! How are. We today?
They are super useful
but my laptop will not support
i linked a site earlier did you check that?
yes
did that work for you?
Good and you
yes but i am stuck here
lsblk -f
NAME FSTYPE FSVER LABEL UUID FSAVAIL FSUSE% MOUNTPOINTS
nvme0n1
└─nvme0n1p1
nvme1n1 82.8G 17% /etc/hosts
/etc/hostname
/etc/resolv.conf
laptop specs?
sudo mkfs.ext4 /dev/nvme0n1p1
mke2fs 1.46.5 (30-Dec-2021)
The file /dev/nvme0n1p1 does not exist and no size was specified.
what i did wrong here?
good! yeah, it's okay with me, but it's one of those days when I'm completely exhausted for no reason.. it'll get better, let's hope..
i dont know if that site will allow you to edit the filesystems of the machines
Yes sometimes there are ups and downs but it passes 🙂
yes. this is a problem.
Yes.. .. what you up to?
that's why i was not able to full fledged practice
If you have a usb stick you could install some linux distro on there
but youll still need to be carefull
A little nothing😅
morning btw Jull3
Sounds like hard work:)
Morning, how are you today?
😂yes
Ah.. good, you push yourself:)
OS: Ubuntu 24.04.2 LTS x86_64
Kernel: 6.11.0-26-generic
Packages: 2492 (dpkg), 22 (snap)
Shell: bash 5.2.21
Resolution: 1920x1080
DE: GNOME 46.0
Terminal: terminator
CPU: AMD Ryzen 3 3200U with Radeon Vega Mobile Gfx (4) @ 2.600GHz
GPU: AMD ATI Radeon Vega Series / Radeon Vega Mobile Series
Memory: 7042MiB / 9857MiB
h
yeah the cpu is a bit weak but it might support a small vm, i dont know if your machine supports virtualization
i will buy a new pc but that's need some time maybe 1 or 2 month
I'm just going to a small meeting, then I'll go home and try to get something done even though my head is like syrup...
I wanna know about bug bounty program , and what is the common vuln in low and medium ,pentesters found?
for low spec pc i skip homelab, vm topic from my learning path
can you suggest me what topic i can learn before buying new pc?
thanks for the info
Gave +1 Rep to @mellow narwhal (current: #156 - 56)
lol
yeah now it might a bit harder
Depends, do you have knowlegde of the basics like networking etc?
no
Have u tried using VBox? How was the performance on it ?
then i would start with something like networking maybe
Or maybe try KVM+Qemu?
cpu supports virtualisation
no 😅
should you could install it and just see
You might have to enable it in your bios tho
ok i will try.
I had a problem here and kept stuck for a while when I was 100% sure my answers r correct then I refreshed and submit same answers and got the flag what was the problem tho
which one i should try? KVM+Qemu?
Real machine >>
ive heard qemu is nice on linux but havent personally used it
depends on what you wanna do
Wireless attacks r most fun
Sad...
I see my self red teaming is more fun
thanks @slow cloud @blissful current
Gave +1 Rep to @slow cloud (current: #105 - 77)
+rep @blissful current
Gave +1 Rep to @blissful current (current: #202 - 42)
wssup chat
wassup
+rep @slow cloud
Gave +1 Rep to @slow cloud (current: #103 - 78)

+rep @slow cloud
Gave +1 Rep to @slow cloud (current: #99 - 79)
Alr guys gtg continue my beginning learning journey cya
Goodluck!!
+rep @blissful current
Study well! 
Thx @wraith tusk @blissful current
Hello

Hey karma, hey Arch bot
Hey
hi
How u guys doin
What happened?
Need help guys
?
How can i create pdf payload for android using kali linux (installed on my phone)
I don't know if I should answer it , since it's illegal and I don't know ur purpose
Bhai trust me, just learning due to interest not for an evil mindset and all.
Struggling since 3-4 days for same, hope you understand
But can't i use kali?
I don't mind but it's the rules of this server
So can you tell privately?
Probably No
Search online yourself is what I can say ...coz I'm not too sure either ..not into Android based hacking
Fine bhai, thanks
Please refer to it
well to help you more correctly, what do you need the pdf for?
So what is your problem now?
I want to create a pdf format payload using only kali, for android remote acess
For what purpose?
And i just have a phone
Bro why u been weird
Its fun for me to learn these, not for anything illegal
well you can't really do it
That just screams I'm planning on doing something unethical/illegal
No bro, how would i prove you
Linux once learned and mastered will be a very powerful tool for attacking or doing something illegal
...You can't?
Literally any tool in this field can be used for unethical/illegal activity.
hmmmm, instant noodles or ordering from out?
@chilly veldt btw why this isnt possible?
chicken with chicken strips
cause you can't do a remote access on a phone through metasploit using a pdf payloader
He brought copy of higher version of database and they aren't compatible with older one
I see that anyone who is good at hacking can hack a system or steal data illegally without using linux with just a few lines of code
@chilly veldt so is there any effective way(without asking victim for permission)to do remote acc from my device
no
Now that would be illegal.
to much but so how to little at the same time... so many questions... but this does make thing about marinating some chicken and using it for instant ramen that sound good lol
so ramen
It's outdated and been long since patched.
pdf payload for learning purpose is SUS
I mean, then they would have to use android 10 or something
Thats fine
6% in 2025.
just gonna keep that one for l8r actually
Thats illegal but i wont do without permission becouse how would i learn hacking then, i just have this way, this device
yeah, that 6% is most likely some android based systems and not personal phones like POS systems or something else 😄
We won't support your questions if they're illegal, and you have illegal intentions you're just hiding them.
We won't be assisting you.
yeeee, I usually do min android 10 when I make apps
Hacking is very difficult and not easy, but once you learn or explore it yourself, it becomes scary
@sick lance No sir just a 12 grade child(not like deathnote's protagonist😅)
So you're now old exactly?
No, we are afraid you will use it for illegal purposes
Im not light yagami bro, i just having urge to learn it please help
if you really care about learning, start with the basics
the way you're asking this makes me think you're trying to run before learning how to walk
even if you don't have illegal intentions, which i am doubtful about
Just learn about networking and slowly you will have knowledge about linux
Who's linux
its an operating system
Why is everyone doubtful for me here😥, btw (you are right scorpious but how can i control urge to learn it then?)
well it isn't our problem if you're not willing to put in the effort to learn something
It's not an OS
here it comes
linux is a kernel stuff
It's a kernel, you gotta say GNU/Linux
i know lmao
i thought you really didn't know anything about linux
so i said os, to not confuse you with theoretical stuff
Its not i'm not willing to learn, but its to control urge of leaenig about remote acess
It is a powerful operating system used to monitor and protect the system. It is often used by hackers to do illegal things
I was jk whole time lmao
which is used to build operating systems, which you'd refer to as linux distros
Damn are you hacker

Understanding it will help you understand how hackers work
I'm not hacker =))))
Damn bro if you're not one, then why you talk about them
😭😭
i wanna be a hacker one day
I haven't even finished 4 years of college, how can I have enough knowledge to be a hacker? If I was that good, I would have become a white hat hacker already =))))
sounds cool
be a legal hacker and don't do anything bad
How can I help you when I can't even be sure you're using it for the right purpose?
How would i prove broooo
My honest advice is if you want to learn about linux operating system then start with the basics first after you have knowledge and professional ethics there will be people to help you
guys how do i start to learn hacking?
Same
Start with the basics like networking, programming languages
U can learn at try hack me
in programming languages i already learned python i'm not an expert but it can help
Programming languages are also related to tools, it will also make you understand how the source code works. This is really important when learning cybersecurity
can i create a web server here in tryhakme and then try to hak it from outside?
apparently not
or its just about attacker and victim hosted on same tryhackme machine
you don't need to do that, in try hack me it has a virtual lab to practice
if it is not enough you can also go to hack the box
However, nothing is stopping you from designing your own html/php file hosting it using Python simple server and hitting your own site you host to help learn how to defend
not here but u can setup ur own labs
for that also many factors matter the Web Hosting , Domain, Network/ISP, Dedicated Server etc should be owned by you
else its pretty much illegal
making your own site and hosting it somewhere on platforms and trying doesn't count as "Owning" so be careful of that
yes
yes
so maybe hack my own webserver hosted on a local machine using the ip is ok
Well, you'd be hosting on your own machine, as localhost not an actual world wide host. Idk, really
There's "grey areas" in between the white and black areas. Got to be careful with the things you try
if its a local machine that you own you can do whatever you want with it
ye
otherwise stuff like https://www.vulnhub.com/ wouldnt exist
VulnHub provides materials allowing anyone to gain practical hands-on experience with digital security, computer applications and network administration tasks.
i think so ...as long as its isolated in ur network or VM and the Hardware/softwares u would use is owned by u
Yeah, that's what I was trying to get at, use python simple server to self host
vulnhub is the same? hacking from vulnhub local machine to local vulnhub server?
Vulnhub is just a list of known exploits for services
DO NOT try attacking the vulnhub server please
i see u can create virtual machines there
wait, I maybe thinking of the wrong site lol. Let me look
or is the virtual machines that u download and then host them locally or what
it seems so. You download vulnerable vms and play with it locally
It's basically CTFs, HackMyVm style. Download the VM, host it in your machine and then try to hack the VM
I never used it though
ahaa
i see
thanks guys for the info
How to use OTMIN Seceon AI's automated email system to send reports
Is it free
probably using TLS (587) or SMTP (25) in Email Server Settings
and using the Report Automation sections
?
you'll also need a Domain
Or POP if you're an oldy
Today it is a webinar from THM "Boosting Offensive Ops with AI" who is attending ?
Hello @knotty valve Tomorrow it is time:D
Yesss
Don't think I'm gonna be sober for half of it
So it's gonna be fun
im unable to find this section Report Automation sections
domain like what ?
I read that as “ pop if you’re an old lady” I just opened my eyes 😂
I’m crying
LOL
We decided to run both, some run Nahamsec and some HackOSINT, my group runs OSINT... hehe.. drunk CTF:D
Both work in this context
whare do i get a key? heheheh. Should that day come.. Then it's time to write your own...
Yeah tonight's not been the best for me 
I feel like I'm one bad moment away from just yeah
Probably shouldn't express that here LOL

Reports of what?
threats
…
Hope you can recover from this slump
Tip again about the Webinar that is today organized by THM with the topic "Boosting Offensive Ops with AI" starts at 04:00 EM
I am laying home sick, so most likely no ctf for me
F
but one of my teams are playing nahamcon
just some fever and a hurty throat
Unable to purchase TryHackMe subscription
Not fun.. I wish you get batter!
@stable agate
contact support!
+rep @knotty valve
Gave +1 Rep to @knotty valve (current: #165 - 52)
okk
Undeserved rep smh
Noo.. you are helpful..
Nope. 😄
Damn oh well 😂
Wsg
Scrubz is the one to beat I see...
How’s everyone this fine morn
Geolocating interiors should be considered unusual torture/punishment
Lmao
There's enough evidence in the interior lol
I may be coaching this CTF then lmao
I'm gonna need to take another look at it in detail?
Yep
Upsetti spaghetti today
Today went from okay to horrible
Hello.. Im just fine.. I just finished writing a small compilation of insights etc from last year's HackOsint so the team I'm in charge of this year has some good info.. How are you?
😦 i hope it gets batter !
I'll be alright
That's for the best, it'll be tough for you tomorrow otherwise..:S
Oh tomorrow is gonna be horrid lol
🙂
It'll be one hell of a hangover
hehe
i do not drink at all....
I've done it before, but honestly it's not something I like. Sure, it can be nice to have a beer sometimes, or a cider. But it happens extremely rarely.

I don't smoke cigarettes (anymore, not even a joint :p) but I have a huge addiction to snus!

snus is good
i have never done smoking/vape/hookah thing etc
never will
don't take snus anymore though
whats snus?
Good
Don't start
Tobacco iirc
God it's hard to type on a moving tram
oh ok
yes
At least the one perk of my tolerance is I'm still coherent and able to walk straight even when intoxicated
what ctf are we discussing
Earlier we were talking about HackOSINT and Nahamacon iirc
I think that's how the latter was spelt

I know.. I often write while I'm out on the town walking or on the way to the subway, then it often goes wrong and people think I'm completely stupid hehe..
You have someone to take care of you during the hangover period?
go register us in them too ..idk
GG im top 3 on worldwide monthly leaderboard
Spending tmrw alone
Like usual
is it still going on?
i thik it was Nahamsec
idk
Ahhh
Mood
will i get any reward from tryhackme if i will end monthly leaderboard global on 1st?
Yeah that makes more sense
🙂
i don't think so
rllyy?
except for bragging rights
not even swag?
neh
MAYBE a Badge but not sure
i will research
i have never heard of someone being rewarded for their monthly rank
@knotty valve you joining the webinar by THM today?
which country Leaderboard btw?
Don't think I'll be sober enough to even retain the info lol
Or awake for it
haha.. 🙂
i was on the global monthly leaderboards for a short time once
What's the UTC time for it?
04:00 EM
started as soon as the month started and solved a bunch of room
i was eventually surpassed by others
2100 hmm I could join in
do it:D


which guy
a lot of high ranked people who grind on thm haven't joined this server yet
its not really suspicious

how can sequencer know and list the token name in response i am testing for, if i only sent a captured request to the login form, that only contains a cookie and no mention of the token in it
i only captured the request and didn't forward it through proxy yet, so how can burp know what things are present in the response already?
sayyy, without judgement, would tryhackme look great if they had theme collabs like how fortnite has these events and stuff
what?
facts but they do have some rooms like the my hero academia one
And not events 😅
Burp doesnt solely list or analyze based on capture request, it kinda examines the actual responses and provide the list I guess
idk maybe find some vids on how Burp actaully works in backend
thats what inspired me to ask as a matter of fact !!
Would probably be something they might do yeah
well, events might be a bit difficult to arrange but themes would for sure !
yeah but i didn't yet forward the request, i captured it using proxy and intercept was on, and i didn't click "forward"
Sorry about dismissing it 😅
I only read the first half
cant wait for sure 😉
i did send some requests to the same url earlier though
did it analyse those responses to be able to list the cookies and fields?
I also think its cool if they added an AI feature for the lessons that summurizes and tells you what you covered the previous day, like what datacamp does
It's a nice use of LLMs
then idk ..

maybe this is the case then
Yeah might be worth watching YT vids on how it works
Or read the burp docs
Idak how sequencer works either lmao
Gave +1 Rep to @blissful current (current: #199 - 43)
+rep @knotty valve
you didn't get it either, for some reason lmao
To prevent rep spam
The irony is the answer is in your question.
exactly lol
Damn
the syntax is ping 10.10.10.10
😂
The webinar today is by 15:00 WAT right?
Me whenever I overthink things
i was gonna answer but i was wondering if i got his question wrong or something lmao
I thought he meant for options
same xD
ya
Idk I'm not attending it lol
Where is it advertised?
I'm asleep whenever it's happening
Why not?
i don't think i've read ping commands manual yet lmao
Neither have I
They sent a mail
But the time there is unclear
I just know ping -c <target>
Screenshot?
ya same
<t:1747922400:F>
It's 3pm GMT.
I'd appreciate if autocorrect would stop capitalising me
So in 2 hours and 10 mins.
Is this in my time zone?
Yes
yes
What is your timezone?
Do you live in the UK?
I just did a quick OSINT check on the #1 player on my THM weekly leaderboard
N know what?
He's just copy pasting from the walkthroughs
GMT +1
Using WAT here
ikr they're busy cheating themselves
😭you didn’t plan to attend anyway
Wot do they get from it?
Ik
mfs
I wish
I wonder why the mail shows me London when that’s clearly my time zone
How can you prove it.
Thanks man
Gave +1 Rep to @blissful current (current: #197 - 44)
<t:1747922400:R>
np
How’d you get the CYBR tag?
Have a look at his git prof, linkedin prof and also the tools which he made using gpt and claude
same way you got the SP1
by joining their server
Seen
How are you able to use timestamps so quickly
are you ok with your name being on there
there's a site for it , i have it bookmarked on ez/quick access lol
thanx mate.. bad OPSEC from me...
Oh
Makes sense now
I thought you knew how to actually type the command on discord
That doesn't prove anything?
Oh shooot😂
Phishing 101
Thanks!
That would be more social engineering.
You’re right
normally ismy OPSEC ok, but today.. not so, apparently hehe..
It happens to us all
global
nice
global top 3
dang, congrats
crazy , congratz
congo
In some situations it can be devastating, especially if you're chasing bad guys.. OPSEC is something to hold tight to! But sockpuppets have many names and faces 😄
Good job!
The worst thing about finishing uni, is awaiting our results.
morning THM team
Good afternoon.
3rd remote day this week, another 8 months to a year to go
not sure how i feel
I def need like a few days to just deep clean-
i got to much pto there trying to make me use it
@thorny parcel
Please don't send me a DM without asking, or even letting me know what it's about.
damn straight called him out
It's against our rules to DM/friend request without asking.
Although I'm a mod, some context would be nice.
Rules are rules I guess
Rules are rules
rules / rules = 1
I need to level up I dont like yellow
after levelling up you'd hate green
awe man
because there are no other colours except blue when you're master
then green goes on again
Greens my favourite colour
can yall just make me purple permanatly 
oh you levelled up
congrats
ill boost 🥲
Thanks ☺️
Gave +1 Rep to @queen flare (current: #206 - 41)
outsource your account to upgrade lol
oh nah nah
Kream250?
what
Green is better than pee yellow.
Doing so, breaking the ToS of TryHackMe.
I didnt bust my ass for piss yellow
so it is known as pee yellow
i have a couple sock puppets currently

Moring!
Hallo people
what up geek
hello!
lmao bruh it was a joke
I could be a nerd void
"bruh" jokes are supposed to be funny.
Just fine.. Preparing myself and my team for HackOSINT tomorrow.. So what about you?
What did I just come back to 
mod crying
Yoo osint
I don't see a joke anywhere tbh
Mod isn't crying, mod is doing their job and ensuring the rules are being followed.
haha, I saw I forgot to write "about you" so it just became "So what?" ..
We don't, and have never allowed rules that break ToS, illegal or unethical topics
I was genuinely confused about that
understand it
i would like to see companies listing sal1 and pt1 certs in their recruitment ads
It would have seemed like I was a really nasty person if I hadn't noticed and changed it.
It'll take a while
the certs have a great syllabus, but it would take a bit for recruiters to see what its worth
SAL1 is being listed on one right now.
I thought someone was being super intrusive lmao
that's great
Certs take a bit to popularise through employers
However, these certificates will not be able to compete with OSCP etc.
Yeah
Harder stuff is usually more safer to list
An employer will take a Pen-200 completion over PT1
i reckon they might
thm's getting popular lately
than its been a couple of years ago
Completely different difficulties and one is proctored which employers prioritise first
i got a couple of years till graduation anyways
so i'll be able to see how it goes before taking any cert
But these certificates from THM are not bad to have, it shows that you are committed and have a drive to learn.
Not to throw THM under or anything, but if I was giving candidates to a job, I'd take someone with OSCP over PT1 or SAL1
Cause I can be safe in knowing there's no copy-paste solutions with proctored exams
Yep, that's right.
Nothing to do with maturity here
the OSCP is also like double the price
yeah, but do you see prioritising sal1/pt1 over OSCP in a few years?
i don't think so either
Worth it as well since it covers a lot more iirc
and more extensive
I mean, OSCP isn't essential in getting a job.
It helps.
but yes, i bet thm certs would be quite popular in a few years
yeah the certs on THM are just like doing a course on coursera
But it's not
"You don't have OCSP, no job for you".
They'll be seen the same way as MS and Google certs
what ms google certs?
i dont think they compare at all
It's also experience as well as studies
Doesn't change my point.
if you're talking about linkedin/coursera one's
i don't think its fair to compare them to thm certs
It's not essential.
It kinda is for a lot of places
Maybe it's not the most important, but it's a big plus if you have OSCP and other "heavier" certificates. For example, I have a friend who is the head of security and pentesting at a large company and is currently looking for a new hire, and anyone who has OSCP or heavier is the one who has a better chance of getting the job!
...No?
I've been offered two jobs that don't require it.
I can short cut it by going defence route and it'll amount to the same as an OSCP
It's not even asked for.
I've seen at least 50 positions need it in two weeks
Ok, just because you've seen it.
Yea HR typically doesnt know what there looking for anyways
It's marked essential for a job 🤷
they also say u need a bach degree
Just because you saw two jobs without doesn't mean it's not essential
It may not be a requirement, but if they choose between two people and the one who has it is most likely that the one who has it will get it.
Hey
I def dont have one and dont plan to get one
You're not disproving me here
Because you seem to think you're right.
So it won't change your mind.
Regardless of what you're told.
So do you?
There are plently of jobs that do and there are jobs that dont
It's gonna be back and forward lol
fight
whether you think your right or not doesnt matter the data is thare and you can do what you will with it
some of us have landed jobs just fine without it
Of course, it also depends on what role you are looking for, what company it is and what requirements they have.
i think what ashlynn wants to say is that if you're a recruiter, and have 2 candidates to choose from, one of whom has a thm cert and the other one has an oscp cert, she would choose oscp over thm
this i agree with
I mean, that's given
well they are official certs arnt they
Yep and the landscape will change
people wont be required to drop the cash like that to specialize
I put the cereal back the fridge
This is from the ad that my friend is the head of the department at and I think it's pretty much the same across the board: Desirable: Certifications in: GNFA, GCFE, GPEN, GREM
Desirable: Offensive Security Certified Professional (OSCP) or Organization for Security and Co-operation in Europe qualifications

imma post another ben emote and then go grind on thm or something
It's not really worth arguing over lol

you are both wrong anyway
Everyone has different opinions and perceptions, and it can differ greatly between different companies and perhaps even in different countries.
Job listings can be wishlists.
Of course, as in the ad I referred to: "desirable"
maybe cooler climates are more chill on the certs
Or hard requirements in cases
as said, can differ from case to case.. but as said, it is of course a boon to have heavy certificates regardless of whether it is a requirement or not..
Damn light pollution is visible af
haha, didn't even know there were fans. had to look up information about it..
ill be home in 10 days. atm in bussines trip on 2nd half of europe 🙂
turn the light off
Wish I could turn off the suburbs power grid
So I could see the stars
hack it
That would be a cool trick to show your friends 😄
Google stars and u'll see em
dont get muted lol
so glad you dont too much light pollution here
good morning
Apparently Light pollution is a significant issue in Sweden, particularly in urban areas, but I didn't even know it existed...
good morning
If only hijacking 3 different power junctions was that easy /j
moring.. how are you?
Very WatchDogs-ful
Ikr
🙂
There was a program in Sweden many years ago where they tricked celebrities with the hidden camera and did pranks.. A friend of a celebrity showed how he "hacked" several skyscrapers that could be seen from their window where the doim was sitting, it was kind of funny..
gooodmorning
Power stations have IT/OT.
They're fun to hack.
Erm, that is illegal 🤓 
call KGB lol
Usually just abuse then modbus traffic.
Systems are are legacy so they're vulnerable to alot of stuff.
Surely it's only accessible internally
Somethings talk to devices out on the field zone.
But not so fun when they in black suits come and knock at the door..
youd b surprised

imagine having a little ai hacker robot that could sneak into such places
Yeah, but sometimes methods of getting in can be stupidly easy.
this starting to sound like the type of hacking in watch dog 2
Very WatchDogs2-ful
ya lol
Yeah that I'm not too surprised about
Given how oil lines in America got hacked
There are many examples where critical systems have had really stupid configurations or misconfigurations.
Checks out lol
Have you seen Pablo Holmes created a laser that zapped mosquitoes carrying malaria?
I'll Watch Final Destination at night ...in my VR … anxiety++
lol i have now
just one of many examples eg: Critical SCADA system – Password: admin/admin
Several water utilities in the US and Europe have had web-based control panels exposed to the internet, sometimes without authentication at all – or with default passwords such as admin/admin or root/root.
Example: In 2011, a group (Cyber Berkut) hacked a water utility in Illinois via their exposed SCADA web interface, in part because the password had never been changed from the factory settings.
if iot is "internet of things" is OT just "of things"?
or Traffic/Signal Control Systems where Telnet/FTP has been open
Sometimes traffic lights, subways and signal systems have exposed legacy systems on e.g. port 23 or 21, often without any authentication at all.
Black Hat talk 2014: “How to Hack All the Traffic Lights” showed that US traffic systems had publicly accessible consoles with default passwords
I feel like "of things" would fit better 

I couldnt believe the security on scada when I got in the work field
so IT would also be "Internet Things"
its ridiculous
It's like I always say - people are the biggest vulnerability and threat to security...

What else could it be
Information technology
Interactive Teaching
Then regarding water purification etc., something happened about a year ago in Sweden, a small drinking water facility in a small town was broken into, there were no alarms or surveillance cameras there... luckily nothing happened, probably some meth head with a crowbar, but it's scary..
Wha-
how coincidental ...i had got a Job Post Notification for OT CyberSec from GlassDoor lol
Lol
yes it is crazy
This is from a newspaper in sweden: "The day before Christmas Eve, a break-in was discovered at a raw water source in Tranemo municipality. Now another one of the municipality's water facilities has been compromised. This time there is no risk that the water is unusable."
Oof
I don't understand how they can leave it without an alarm or camera surveillance. It was also located in a remote forest area with a simple door, so they could work completely undisturbed.
Damn. I've made the same mistake again, I've been way too active with ctfs and rooms on both THM and HTB, now my motivation is starting to drop again.. I know I shouldn't do that, I should take a few days off and do something else, but I can't keep myself away:D I also know that the motivation will come back, but I should have learned by now..
This was from an OSINT challenge, the ctf was also state sponsored
lmfaooo
balance
Insane
Play a video game
or play some physical sports
listen to your fav playlist
Doubt any of us could do that
I'm 50kg and I can't do it 😂
Nah that ain't skinny
For 5'10
Yes
I'm severely underweight
5 10 50 kg lol
Just chill bro @knotty valve
I have a friend whose like 56 he's 40 and he thinks he's oversight lol
yoo
Body image moment
But no, in my case, I'm medically underweight
BMI and medical examinations
Hmm
BMI doesn't account for muscle mass vs fat mass, hence the need of medical evals
Eat something nice bro, drink enough water and don't sleep late
That doesn't work for everyone, sis
There's a magical thing called metabolism
And also eating disorders
CrossFit is boring.
Hyrox and OCR is better.
The crossfit in modern form is
Maybe you need to try, or overcome it through some way I guess
But the old one was just the fire fighter training
I keep thinking of the computer vision OCR whenever I read that
Gotta fear that one
It's a pain to control
Def
Generally you're not supposed to control it cause it's going to change naturally
Sometimes it easy to gain wait you start walking a bit and now you're a bug lol
Woop Woop. Soon time for the THM Webianar.. waiting
Hello
hi
hi
hi
Now the webinar is over.. Thanx THM.. Nothing new that I learned but always interesting..:P
You sent an email to support?
Or head over to #site-support maybe able to get some help there
Some countries it's not possible to buy because of something with banks. I don't know if that also applies to India..
contact support by mail.. i did post a link.
A friend of mine has @worldly hearth, so ig he could help u?
it is just the last digtits..
gratz
almost 4 years on the platform kk
Good job, and you probably haven't missed a single day on your streak 😄
I personally have about 500 points left for a modest 0x9 [Mage] ..:D
almost got 365 badges to be honest
If i have 6 eggs in the fridge, how many eggs get sold in the US each year
All the apt rooms are so fun
The number of eggs in your fridge and the number sold is irrelevant. 😄
That's basically how pentesting problems are
Using an alternative payment method because your bank doesn’t fully trust THM doesn’t violate any of Tosses.
Many banks have these security measures in place (which you can often request to have removed or made to be less strict, at least in most countries, you can google if that's the case in urs). They’re simply trying to protect users from potential risks. It’s not illegal to use alternative payment methods in such cases it’s basically just a workaround and also it removes the liability from the bank of any scams like if you buy a paysafe card and use it to buy a game on website thats turns out to br a scam, the bank is not responsible it's paysafe whos job is to help u, yes bank can too but it's not their "duty". Anymore
This question is missing a lot of factors for solving.
E.g.
- How many eggs you buy on average
- Timeframe of buying eggs
Check the logs in the system, maybe you can find something
I'm partaking in a Tier 2 Security Analysis-based time-attack competition soon, and I can see your general point of view when it comes to these things. When filtering through the SIEM for logs during training, me and the other members of my team kept running into issues with how exactly to look for the logs that we needed.
(In one case, what network connection was suspicious simply off of # of connections logged in the firewall)
Real
There are actuall some areas TryHackMe don't offer the chance to purchase a subscription.
So using this method to bypass, would be unethical and violating the ToS of THM.
Idk much about security actually, just enough to keep things secure when I build something
Glad it was interesting nonetheless 🙂
Do they even live in the US?
What if they use vpn
VPN is essential to the answer of the question.
But there are ways to tell if they're using a VPN.
