#general

1 messages · Page 1137 of 1

slow cloud
#

Coffee sounds good rn

shy forge
#

its good some flag need extra caffeineNotLikeThis

slow cloud
#

Doing some THM?

zenith mesa
#

Hey Boys

slow cloud
#

wassup

zenith mesa
#

Managing mehn

#

Been a while since i chatted in here

shy forge
slow cloud
zenith mesa
#

That's interesting

slow cloud
#

made my discord back then

#

its been a while yea

knotty valve
#

Also fedora but nicer

frozen charm
#

lovely

zenith mesa
#

Hey anyone can share premium login for THM? I just want to experience some labs

knotty valve
#

there's plenty of free rooms

zenith mesa
zenith mesa
mossy river
chilly veldt
zenith mesa
knotty valve
shy forge
#

premium is worth

#

go for it

knotty valve
#

that's something I should be asking jabba ngl

chilly veldt
#

it kinda does, not sure if they have changed it, but you'll have to stop the renewal and then apply the voucher

knotty valve
#

ah

torpid stag
#

I really hope I get a shot. Tried paying for i t multiple ways but man. Stripe hates me

#

Even the support couldn't do it

bleak quartz
torpid stag
#

Yeah, I used cards which I normally use

bleak quartz
#

Get a paysafe card

#

works with anything that has issues

torpid stag
#

Pay-safe?

#

Is it one of those virtual cards?

bleak quartz
#

yuh

woeful cedar
#

I am tired

bleak quartz
woeful cedar
#

I dont drink coffee

#

Or any forms of caffeine

bleak quartz
#

How

woeful cedar
#

What how?

bleak quartz
#

Are you a student?

woeful cedar
#

Yes

#

College

bleak quartz
#

How tf

#

oh

woeful cedar
#

What? 😭

slow cloud
#

i didnt drink coffee until like a year ago

#

when i started working, but i only drink it at work

bleak quartz
#

Without it I would be so cooked

woeful cedar
#

I drink it rarely, like once or twice in a month

#

But that's it

bleak quartz
#

lucky

bleak quartz
#

coffee tastes good tho

bleak quartz
#

also whats that

torpid stag
bleak quartz
#

"sleep" you say

knotty valve
#

Uploaded my website to the server

#

now to actually install the tools to run it

woeful cedar
#

I just sleep 7-8 hours a day

dark mason
woeful cedar
#

And can stay awake

knotty valve
chilly veldt
#

revolut works

#

they also have one time use cards

slow cloud
#

revolut is very nice

woeful cedar
#

How was the experience

zinc wolf
#

hii

chilly veldt
#

I hate that the cleaners turned off my vpn 😦

#

that means I have to go to school tomorrow

boreal scarab
rapid merlin
#

Bellas has school? Bella told me they were 21 and at work

chilly veldt
#

more like I have to drive the motorcycle in rain

chilly veldt
round onyx
topaz falcon
#

Erm akshhally it's to ride ☝️🤓

blissful current
topaz falcon
#

Be safe in the rain though

blissful current
torpid stag
slow cloud
#

gonna buy 15 euro earbuds, how bad can they be

torpid stag
#

both revolut and paysafe

sick lance
#

Can't be worse than none.

slow cloud
#

truee

rapid merlin
#

I like the rain

slow cloud
#

here you go @torpid stag you can check

topaz falcon
slow cloud
#

these are Fresh ’n Rebel

torpid stag
sick lance
#

I remember I used to only buy Skullcandy.

#

Then they went downhill.

slow cloud
#

alot of people from my class had the skullcandies with the crazy bass

#

i like my sony xm3

#

i will never buy anything other then sony, even tho the xm5 and 6 are ugly

rapid merlin
sick lance
rapid merlin
#

I was the only goth in the group to never own skull candy 😦

#

Feels bad

chilly veldt
# topaz falcon Erm akshhally it's to ride ☝️🤓

Saying we “drive” a motorcycle will be understood and isn’t grammatically incorrect, despite being the less common term to use compared to “ride”.
especially when talking about the conditions and talking about taking a motorcycle as a different option than a car.
my sentence indicates that I wouldn't be driving a car but instead taking my motorcycle, plus referring to the conditions of the weather making the roads I will be driving on a non optimal condition.

therefore it is acceptable and often the choice to use the word drive instead of riding a motorcycle

bleak quartz
blissful current
blissful current
rapid merlin
#

I didn't know they still made them

sick lance
#

These days I only buy headphones is when I need a new pair for my PS.

chilly veldt
#

sony just dropped their new xm6

blissful current
#

i use JBL

rapid merlin
#

xD

slow cloud
rapid merlin
rapid merlin
#

I had to check amazon

blissful current
chilly veldt
#

the top bar?

slow cloud
blissful current
#

thats epic

slow cloud
#

idk how to explain it

slow cloud
chilly veldt
#

the headband

bleak quartz
#

Hella underrated

rapid merlin
blissful current
slow cloud
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #8 - 984)

chilly veldt
#

yeah, I mean you don't feel the difference, I got the xm5's and they are lovely

bleak quartz
#

This is hella underrated

chilly veldt
#

only reason I would get xm6 is because they are now foldable and have better ANC

bleak quartz
#

and cheap

rapid merlin
bleak quartz
#

or at least in comparison

dark mason
#

Guys, I captured the flag

bleak quartz
bleak quartz
#

idk why

#

its in me and my friends gc

slow cloud
#

yeah me neither

#

just wanted to share

bleak quartz
#

I bought it from that exact site

#

a year ago or so

blissful current
slow cloud
#

epos exists

#

just not that link or something i gues

bleak quartz
#

yeah ofc it does

rapid merlin
bleak quartz
#

Oh they changed their links thats why ye

bleak quartz
#

Here you can see em

#

nvm that goes to demant too

#

tf is going on

slow cloud
#

demant is the parent company of epos

#

according to gpt

bleak quartz
#

Oo

slow cloud
#

still weird tho

#

idk why that happens

bleak quartz
#

Anyways that headset has been the highest quality that I've used so far out of all headsets

#

dunno what kind of downfall they going through rn but the headsets are nice lol

bleak quartz
#

It's now fully owned by Demant

#

that's why

sullen schooner
#

Uh guys, do you know about prompt theory?

#

People actually believe in that?

bleak quartz
sullen schooner
slow cloud
sullen schooner
#

With a user controlling our destiny or sm5

slow cloud
#

oh yeah i see

sullen schooner
#

Like a roleplay charbot

slow cloud
#

i shouldve looked further in the google serach

sullen schooner
#

I think Google's veo 3 has something to do with this

#

But I'm still reading

slow cloud
#

i think its the same argument as we live in a simulation

sullen schooner
knotty valve
#

Finally got my website back up :D

#

Only took me 8 months

clever locust
#

hi folks

slow cloud
#

hi

sullen schooner
#

That's why I looked up the prompt theory lol

clever locust
slow cloud
#

im fine what about u

knotty valve
#

I was half expecting a "can you hack my instagram pls"

knotty valve
#

I wonder how many staff work at THM

slow cloud
#

the blue ranked staff?

knotty valve
#

In general

crystal moss
#

I just started watching the documentary "cyber bunker" about the server bunker in Germany for darkweb... interesting story

knotty valve
#

nice

#

I accidentally friended someone when scrolling through the member list 😂

knotty valve
#

Discord needs an "Are you sure?" button

#

i swear

slow cloud
#

netflix i think

#

yep

#

amazing site

#

you can see where you can stream a certain show

gusty inlet
#

This one?

crystal moss
slow cloud
#

its been on my list for a while

crystal moss
#

It is a Republic tahay say , with a structure like a state.. 🙂

mental stratus
#

I'm sorry to ask, i'm looking for any good room about "parameter tampering", any suggestion?

shy forge
#

Hi guyz any quick tip for anything which you find basic but quit interesting?

rapid merlin
#

There’s so many bugs in this room.

slow cloud
#

which one

rapid merlin
#

I’m done

#

I’m going out lmao

#

I was clearly never meant for the red road

#

I’m in walking an application.

#

First the red box just didn’t show up and now I can’t enter the next flag which I can clearly see

#

Am I being dumb?

slow cloud
#

well is that the flag for the question?

gusty inlet
rapid merlin
#

I mean I tried to type it first and then I tried a copy paste

gusty inlet
#

The answer box on THM already has _ preset to autofill it. For example just fill it with 'a's and you'll see _ being autofilled in some places.

rapid merlin
#

Yes so I tried to put in just the letters

knotty valve
rapid merlin
#

It’s like entering the _ in the incorrect place

knotty valve
#

You also can't paste in anything if the cursor isn't at the start as well

rapid merlin
#

I don’t know why

gusty inlet
#

Or maybe it's not that flag.

rapid merlin
knotty valve
#

Flags change occasionally when they update rooms

#

Could be a typo somewhere too

shy forge
rapid merlin
#

Okay well I’m wrong lmao

blissful current
#

ello

rapid merlin
#

I was looking at the inspect part of it

#

The red box was a bugging though

safe oxide
knotty valve
#

Hello fellow human beings

rapid merlin
#

It turns out I was the bug

knotty valve
#

Mood

blissful current
rapid merlin
#

Okay I need to eat before I do any more rooms

boreal scarab
#

Doing a badge CTF from DEF CON 31....

rapid merlin
#

Yo what

#

😆

safe oxide
knotty valve
knotty valve
#

I got a few good laughs from 2019

#

Absolutely loved it

boreal scarab
#

It's this badge

blissful current
safe oxide
blissful current
#

for what?

knotty valve
#

Defcon 33

#

Think we're up to 33 anyway

boreal scarab
#

Looking at the readme......

ROBOTS TRANSCLUSIVE XENOMORPHIC TRANSCRIPTOR - HUMAN INTERATION CONTROL SCENE (R.TXT-HICS) ERROR CODES:

  1. Watch more YouTube
  2. Ask ChatGPT
  3. REDACTED (For the current broadcasted REDACTED, see the REDACTED)

K thanks readme....

brisk bison
#

Hey 👋
Quick question (might sound silly, but bear with me):
If I forgot to cancel the auto-renewal for a monthly subscription and the payment failed due to insufficient funds, does that mean I still owe anything?

brisk bison
#

ok, glad to hear that

knotty valve
#

Nyo but I do believe the service is suspended until paid or it reaches the end of the grace and it just drops you back to free

#

By service I just mean access to paid

brisk bison
#

yeah i got that

boreal scarab
brisk bison
#

thanks guys

#

❤️

knotty valve
boreal scarab
#

Hrm, got a submit and a login page. I swear, this is turning into web pen and I hate web pen

frozen charm
#

need ricing :' )

lament tendon
#

Make up your mind, dang.

knotty valve
frozen charm
#

i just installed them in additional

#

deleting neovim

knotty valve
#

F neovim

frozen charm
#

:' )

lament tendon
#

F neovim? Neovim is goated.

frozen charm
#

btw m not able to set fancurves

frozen charm
lament tendon
#

I mihgt know if you explain to me what you mean by fancurve.

#

Animations?

frozen charm
#

fan speeds

frozen charm
#

like legion vantage

lament tendon
knotty valve
#

With lm-sensors

#

Iirc

frozen charm
#

:' )

lament tendon
lament tendon
#

My fan speed worked out of the box on base Arch, I did not install anything special for it.

#

It just goes up when how and down when not.

knotty valve
frozen charm
#

didnt work

#

know wot gpt suggested?

#

allocate 30gb to windows and switch to windows and set the fancurves and return to arch for ur work

#

dual boot basically

knotty valve
#

Lmfao

frozen charm
lament tendon
frozen charm
#

:' )

blissful current
#

VM >>

frozen charm
slow cloud
#

Why not start with Ubuntu or mint then

sullen schooner
lament tendon
frozen charm
sullen schooner
frozen charm
slow cloud
blissful current
frozen charm
lament tendon
#

Danm, just let other people use what they want, why does it always have to be an argument?

frozen charm
#

yesterday he submitted the report

whole gazelle
frozen charm
slow cloud
#

what exactly didnt work

slow cloud
lament tendon
#

Read the wiki page.

#

It also has alternatives.

#

Like nbfc.

slow cloud
frozen charm
lament tendon
#

Just check the wiki link, there's one section for most types of laptop, with different tolls you can try.

frozen charm
heady summit
#

i'm not even sorry but i can't help myself.. maybe if companies would give a shit about their product, then it might not be so ridiculously easy for me to crack them..

blissful current
sullen schooner
blissful current
blissful current
#

heh?

mossy river
frank hawk
#

Hello

#

May i ask if there is such thing as Free PT01 ?

#

like when you finished the Junior Penetration Testing Path

#

?

sick lance
#

There is no current free foucher for PT1.

alpine fossil
#

Y'all am I gonna get hacked when joining this server?

sick lance
#

No.

rapid merlin
#

Hi all,
Just getting started in the pentesting world, and I'm keen to get some hands-on experience through CTFs. My manager recommended them, so I went to join one yesterday, but it turned out I needed a team – which I don't have yet as a newbie!
Anyone got room for an eager learner on their team, or perhaps want to team up with another beginner? Let me know!

oak salmon
#

I know nothing about pentesting can I join?

crystal mauve
sick lance
#

I don't think they meant on THM.

crystal mauve
#

Rly

sick lance
#

There is only one room on THM that required a "team" and that's closed.

rapid merlin
#

Yeah it wasn't for thm, the one I wanted to do was the nahamsec ctf this weekend

crystal mauve
#

Oh ic

#

Prob should go to nahamsecs discord, not sure if that material is pay walled

crystal moss
dark grove
#

hi all correct me if I am the for openvpn ssh tryhackme@ ipaddress provided and the password to enter is tryhackme right ?

dark grove
# sick lance Not always.

opps but i remember correctly back then so long i use openvpn the default password is always tryhackme did they changed it ?

sick lance
#

Otherwise the CTF's would be easier if all the passwords were tryhackme.

dark grove
#

ok I am doing an easy challenge known as network services but when i ssh it prompted me for the password the problem is I dont know the password 😦

sick lance
#

Maybe you don't need to SSH?

#

Or maybe there is another form of authorisation required, such as a key.

boreal scarab
#

"The 5 Talking A.S.S. H.O.L.E. mouth indicators say horrible things via light. See the appendix for the color code to swear word translation."

sick lance
dark grove
# sick lance Possibly.

nope dont have I am stucked with this lab if I cant ssh as the lab mentioned to use openvpn 😦

sullen schooner
swift quail
#

😆

#

Hello all I am new

queen flare
#

i'm scorpius

alpine fossil
safe oxide
#

Hallo new

sullen schooner
alpine fossil
#

Anyhow I REALLY want to learn whatever hacking stuff or computer things you learn here

sullen schooner
#

Don't join unless you want others to hack you

sullen schooner
alpine fossil
#

I love to program with all my heart and made a gambling game at school 🤑

alpine fossil
#

Server finding function

#

I was bored

sullen schooner
alpine fossil
#

So I joined like a thousand servers

sullen schooner
#

And click the website

#

Lmao

alpine fossil
#

So I felt why not learning it

alpine fossil
blissful current
sullen schooner
#

This is hilarious

#

But I gotta go

#

Got a train to catch

sullen schooner
#

He's mod for a reason

safe oxide
#

Hehee

hearty otter
#

if i have 2 arms, how many arms exist in the world

spice olive
hearty otter
sullen schooner
#

: )

spice olive
hearty otter
spice olive
hearty otter
#

absolute cinema

sullen schooner
hearty otter
#

bro saved the situation

tardy finch
#

i know there is first blood. is there such a thing as second blood or top ten blood?

rapid merlin
#

You can make your own game, and have such features

ocean sparrow
#

what is a good cybersec project idea that I can build on my own, I need my resume to standout with all the competition in this field 😭

ocean sparrow
grim sparrowBOT
#

Done!

rapid merlin
ocean sparrow
rapid merlin
#

Do we have a room in how web crawlers are created

spice olive
#

Guys, I'm new to hacking. Should I start with Kali Linux?

rapid merlin
blissful current
#

Any Linux Platform ...your choice

spice olive
blissful current
#

Pretty much Same as any other Linux

spice olive
blissful current
#

The ethical hacking tools might be the "tough" thing u mentioned for some

rapid merlin
bleak quartz
blissful current
blissful current
#

Not all but most ...usually used tools

bleak quartz
#

a bunch

#

also u can choose which tools you want to have pre installed

flint badge
#

Hey, is anyone familiar with the task 2 on Snort "TryHackMe" ? I need some help to complete the question.

oblique loom
#

My current course is making me take the comptia A+ x.x

flint badge
bleak quartz
#

so scbruz police don't get angry

bronze eagle
#

When can we have server tag? So we are cool too

bleak quartz
#

go

sick lance
oblique loom
#

Speaking of labs I haven't done one since Feb and I feel so rusty

rapid merlin
#

its ironic aint it

bronze eagle
bleak quartz
#

😭

oblique loom
rapid merlin
bronze eagle
oblique loom
#

Current course is so boring it's grueling

#

It's like basic IT stuff kinda

#

A+ stuff

#

Only good news is if I get my A+ it also renews my security +

boreal scarab
#

So far, this DEFCON Badge CTF has: Web pen, cryptography, stegonography

boreal scarab
#

I was prob temp blocked from their site for trying to login too many times with failures lol

sick lance
#

That would be an account lockout, not IP.

sand trench
#

depends

#

some services do ip lockouts

#

which is poopy

boreal scarab
sick lance
#

Skill issue.

boreal scarab
#

Cryptography done, flag acquired. new path opened up

unique phoenix
#

Is there any plans in the future on adding a button/option to disable the AI thingy?

brittle siren
#

Does somone know hackin

#

?

unique phoenix
#

Echo, the things that "helps" you.

spice olive
brittle siren
spice olive
blissful current
#

never heard of it

split plover
spice olive
brittle siren
blissful current
split plover
#

@brittle siren what is it buddy? You wanna learn hacking?

split plover
#

Hmm... Interesting

brittle siren
brittle siren
#

55$ account pepehands

blissful current
#

contact police/Authorities/Cyber Crime Branches for it then

brittle siren
blissful current
spice olive
brittle siren
spice olive
blissful current
#

i mean u file complaint in ur own country first right?
then they'll handle the rest

brittle siren
mossy river
wheat hare
#

Damn, I just missed seeing my rank at 6900 😅

mossy river
spice olive
blissful current
#

next time will do

brittle siren
#

I don't know I broke the rule

rapid merlin
brittle siren
mossy river
#

Rule breakers is a collection

blissful current
wheat hare
spice olive
#

🤖

blissful current
boreal scarab
#

FLAGS CAPTURED: 1/19

OH FUCK MY LIFE!

rapid merlin
blissful current
boreal scarab
rapid merlin
blissful current
#

old one he's doing i think

#

idk , all the good stuff takes place in y'all countries

wheat hare
#

Sounds more exciting than "upgrading" Windows 10 to 11 tho

boreal scarab
#

2023 defcon

#

19 flags, working this alone besides a team... yep, I'm screwed

rapid merlin
boreal scarab
#

I can also change the color of the lights, has to mean something....

rapid merlin
#

It was a room that spoke about attacks towards physical end points

half badge
#

Guys I started studying again! Yayy

#

Did some cryptography today and I'll continue

sand trench
half badge
#

Got any good room recs abt cryptography? (Free cause this time period no money :3) Or challenge rooms?

half badge
half badge
blissful current
#

hmm...,Not bad PPLX

#

now i dont think i'll ever even get confused or forget the 7 layers of OSI in sequence lol

last harbor
half badge
last harbor
#

Idk

#

I don’t have any

blissful current
rapid merlin
#

I think after this red team room I'll do a blue

#

Mix it up a bit

#

Can we something similar on other browsers? "User-Agent Switcher and Manager"

blissful snow
#

purple

rapid merlin
#

The one that " gives you the ability to pretend to be accessing the webpage from a different operating system"

blissful current
#

i think u can

#

maybe by making a Custom script? or perhaps an extension?

blissful current
half badge
#

Guys for those of you who use obsidian is it reliable? Like if I lose a device all data lost?

#

Any cloud or option to transfer to usb?

blissful current
#

i think u can make backups and save the file in ur USB

half badge
#

Ty

slow cloud
blissful current
kindred yew
#

Hello chat, long time no see.

sand trench
#

ello fox

#

shadow would be in FRA or SÄPO

kindred yew
blissful current
sand trench
#

Wallpaper of the day:

blissful current
#

or maybe 2-3

slow cloud
#

More a men in black suits department you know

blissful current
slow cloud
#

Nah i dont work for a government or any thing like it

bleak quartz
#

😂

slow cloud
bleak quartz
#

Dw lol

#

Very understandable from the context anyways

half badge
#

Is it paid?

blissful current
twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #99 - 80)

half badge
slow cloud
#

Maaaaybe

bleak quartz
#

Very reliable

#

Also read their website

#

They got answers to ur other qs

slow cloud
#

Arch/Arch

#

Yes

half badge
blissful current
#

Arch

bleak quartz
#

Obsidian is so good

#

Absolutely love it

slow cloud
#

5806 Archieroy

blissful current
#

windowns

slow cloud
#

We'll how will u guys know who's team you are on? We just scream we use arch

half badge
#

An obsidian vault on a github repo could perhaps work too? Maybe

slow cloud
#

We use arch as a battle cry goes kinda hardNotLikeThis serpentKappa

slow cloud
blissful current
slow cloud
#

I don't know if obsidian can fetch files from a repo. Probably not natively

#

We have pewdiepie

blissful snow
#

why does tryhack vpn never works

#

well hardly

sand trench
blissful current
slow cloud
#

Moving to git then

blissful current
slow cloud
#

Us archians have suffered enough through the install we can take on everything

twin ridgeBOT
#

Gave +1 Rep to @rare galleon (current: #1898 - 2)

slow cloud
blissful current
slow cloud
#

Ubuntu allience Skull_JawDrop

#

Need i say more

blissful current
#

i'll probably be getting cooked in the interview tomorrow

slow cloud
#

Avarage member of your silly army ^

blissful current
#

in ANZ

slow cloud
#

Falls to their knees, barely able to speak, voice trembling:
"You… you’re stronger than I thought… But listen… that thing… it can’t be defeated… not by force… not by anyone…"

#

How can one defeat itself

blissful current
#

the weirdest thing i have seen today

slow cloud
blissful current
#

🌬️ OMEGAWHEELCHAIR

swift quail
#

nooooo! NotLikeThis

shy vortex
#

Wassup everyone !

swift quail
#

IM BLIND

slow cloud
swift quail
shy vortex
#

Lmao

#

How ya doing

#

Glad today we got a day off from work 🙂 lol

swift quail
#

I memorized where the keys were two seconds before you nuked my eyes from hannah montannah

blissful current
#

gonna be my First F2F Interview tho
nervous af already

crystal mauve
#

Wanna practice ?

blissful current
blissful current
crystal mauve
#

How much soda did you drink

swift quail
#

loool

#

he's funny

boreal scarab
#

Wait, I refresh the page and the flag amount changes..... my head hurts

swift quail
#

you

#

bud

blissful current
#

Kome D. Luffy

swift quail
#

I think you can do both and win life altogether, I think it would be good mix.

#

Stand up comedy at night

#

blue teamin in the morning

last harbor
#

Wats happening here

blissful current
#

aight am off to sleep ...read enough ...will see in morning before the interview probably

Good night

slow cloud
#

Goodnight Goodluck tomorrow

boreal scarab
#

AHHHHHHHHH

#

@polar spoke I'm going insane, hashcat is not playing nice with me, can I DM you?

polar spoke
#

sup

boreal scarab
#

Have a hash, that I believe to be MD5, but no matter -m 0 -m 1000, still says there's no hashes

trim portal
#

Hello, may I ask if there is website you can recommend for almost like AI-tools to ask about excel formulae please?

#

I am sorry if my question is not topic related.

slow cloud
#

I think any of the ai tools can create excel formulas

#

Have not done it myself that much so cant vouch for any

trim portal
#

I found a small issue with a table with values coming from another sheet in the excel, and it keeps showing there are missing values despite I already input everything.

#

I asked but it couldn't answer..🥹

polar spoke
trim portal
#

And because I am not the owner of the files, I am clueless of what went wrong (yet I am expected to fix them since missing values can affect the graph)

#

But thank you for answering! 🥹

twin ridgeBOT
#

Gave +1 Rep to @arctic gyro (current: #1898 - 2)

slow cloud
#

The excel world championships are crazy

trim portal
tight trout
#

mornin yall

slow cloud
trim portal
#

What does that mean if you don't mind me asking?

slow cloud
trim portal
#

Oh no no, I don't see Pookie as a flirting word.

sand trench
trim portal
#

Ok, I just checked. The formulae that seemed to be making the table on second sheet is not an official excel formula NotLikeThis But I don't know how to carry on and search from there 😭

#

Interesting...

#

Thank you!! I will check them out now!!!

twin ridgeBOT
#

Gave +1 Rep to @umbral geyser (current: #1898 - 2)

sick lance
#

My roles aren't updating for everyone

#

Apply for jobs

sand trench
#

yeah they post open jobs on a few places when there are any

sick lance
#

Yeah.

#

LinkedIn and a jobs page.

hearty otter
safe heart
#

has anyone here read Real-World Bug Hunting?

hearty otter
safe heart
sudden pollen
#

Can someone tell me the best place to learn cyber security without going to school

hearty otter
#

is it a coincidience

safe heart
#

sad

hearty otter
#

mit has public courses

sudden pollen
#

after learning fundamentals where should I go to learn cybersecurity

safe heart
sand trench
crystal mauve
hearty otter
hearty otter
#

i hate reading boring emails too but still do

safe heart
hearty otter
hearty otter
#

or money to pay people for doing it

safe heart
crystal mauve
#

You don’t have to know a single port and what it is to run an nmap scan

hearty otter
safe heart
sudden pollen
safe heart
crystal mauve
sudden pollen
#

does it teach like cybersecurity i don’t really care abt fundamentals

crystal mauve
safe heart
#

fundamentals is essential imo

crystal mauve
#

U don’t even need any extra tags for most ctfs

pallid lotus
naive violet
#

Fundamentals are fundamental, hence the name. They're a foundation to build on.

crystal mauve
#

U don’t need to memorize ports n networking cables to do ctfs

naive violet
#

They might not be interesting, but they're critical

crystal mauve
#

If he wants to jump in let him

sick lance
stark sequoia
#

if you dont learn the fundamentals you will forever be a script kiddie

sick lance
#

It was good to meet the team.

pallid lotus
#

Hacking is about leveraging knowledge to make things do stuff they're not supposed to do.
It's a mastery of other forms of computer science.

If you don't understand those other forms, how tf do you expect to do anything?

naive violet
stark sequoia
pallid lotus
#

Learning also != Memorising

crystal mauve
pallid lotus
crystal mauve
#

No it’s called practice - u learn while working and learning

naive violet
sick lance
#

Unless you just copy a walkthrough

#

And don't learn.

#

Waste of time.

crystal mauve
#

He’s not applying for a job lol

naive violet
crystal mauve
#

He’s trying that have fun

pallid lotus
naive violet
#

Whole hacker mentality is knowing how stuff works

sudden pollen
crystal mauve
#

Stop trying to push people to learn A+ material when they just wanna run a friggin scan

naive violet
#

You're the one that said A+

stark sequoia
#

is this ragebait?

crystal mauve
#

It’s silly , they will get to learning the fundamentals if they find a passion for it

sand trench
#

A hacker embodies a boundless passion and insatiable thirst for understanding the complexities of a system, computers and networks in particular. They revel in the pursuit of knowledge and mastery, constantly seeking new solutions and opportunities for growth. Their drive and innovative spirit inspire and are inspired by the hacker community, where ideas and knowledge are freely shared and valued regardless of their origin.
--Silk

naive violet
pallid lotus
#

If you don't know what you're looking at then you're not really hacking. You're just running tools, or following someone else's path.

sand trench
#

shadow is feeling stupid as they can't figure out how to set a specific browser as default on arch linux

stark sequoia
hearty otter
pallid lotus
#

That's very different from how it feels when you actually know what you're doing.

crystal mauve
patent falcon
#

anyone knows a good alternative for the vuln machine of the book hacking the art of exploitation?

stark sequoia
#

then you wont be able to understand why something went wrong.

crystal mauve
#

Do you guys sit and real every manual before playing a video game or do u actually play it n get good ?

sand trench
# naive violet Not xdg?

well yeah but apparently shadows xdg entry is blocked as they set the $BROWSER variable but the variable does not work currently... gonna try commenting it out and then reloading window manager after the stream shadow is watching is over

stark sequoia
#

or do you understand how game engines work?

rapid merlin
# sick lance Unless you just copy a walkthrough

Hey scrubz I'm learning traceroute. It says "traceroute command traces the route taken by the packets from your system to another host" Could it be traced back if the packet is caught. Can I find someone from the packets sent in

crystal mauve
#

He’s not trying to learn to be a programmer he wants to hack a box

sand trench
rapid merlin
#

I wish I had taken that nap earlier

#

I'm so tired

crystal mauve
rapid merlin
#

I went to lay down and my kid saw it as a challenge to wrestle.

pallid lotus
# crystal mauve Using the tools u can learn to understand them ? lol

If I tell you to run an nmap scan on port 2893, can you tell me what actually happens when you do it? Can you tell me how that service works, how it's deployed? Can you take me through the network flow, and ascertain how that infrastructure works?

Without that, you're a script kiddie. Nothing more.

#

Also, cyber security isn't a game smh

sand trench
#

thanks for confirming shadow is a script kiddie muiri

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2150)

pallid lotus
crystal mauve
pallid lotus
sand trench
rapid merlin
#

Idk, i kinda see it from both perspectives, basics and fundamentals are definitely needed, but if you don't start with some of the fun stuff and get some context of why it matters and build some interest, stuff can maybe get a bit boring and you can hit a wall just studying theory

stark sequoia
glossy mural
#

Ro Bot Rock

pallid lotus
last pewter
#

Learning the theory before using tools is always good though. Sure you can do both at the same time; i like splitting my sessions into 3 parts. Theory for an hour, beef up my computers defenses 30mins, do fun stuff and apply what i learned for an hour.

rapid merlin
#

Uni also expensive

sick lance
sand trench
#

eeeeh the most expensive part of uni here is the books we have to get to read and study

crystal mauve
#

I did walkthroughs n basic ctfs for months then realized I need to learn the fundamentals. But starting off just diving in and using tools got me to the point in taking web security , networking , etc much more seriously. But if it wasn’t for aimless nmap scans I would not have become motivated to get there

sand trench
#

as shadow has stable housing and decent bit of dinner food options

rapid merlin
pliant cairn
#

just a quick question - is there an SSTI room/CTF on THM? i know there are but searching gave me unrelated.

rapid merlin
#

I dont know if Im even making sense. I've only powered up a brain cell. The rest of me is in another universe.

narrow bone
stark sequoia
#

i feel like when it comes to CTFs you either know what you are doing or copy commands then completely forget about the solution. Theres not much learning going on unless you do both the theory and a practical example. Thats how it should be done for beginners

sick lance
rapid merlin
sand trench
#

shadow built birdhouses first

rapid merlin
pallid lotus
pliant cairn
#

i see some chatter on traceroute. So, just to add. Its over the protocol called ICMP. mainly just to discover network hops and nothing other than that. well there are similat tools like tcpping and other protocols that do the similar thing but more or less, if you made a request you are supposed to receive a response so, the packets have to know where to reach to. So, yeah someone can trace back to you 🙂 @rapid merlin

sick lance
# pallid lotus Eh?

They're not asking if she can be traced, she's asking if they can trace them.

pallid lotus
#

End of the day, as far as your router is concerned, it's just been pinged.

sick lance
#

Wrong direct.reply.

crystal mauve
pallid lotus
#

So, yes, the originating IP will be in your firewall logs, assuming the firewall records that stuff.

inland moon
#

Can i u guys something

pallid lotus
#

But you're not going to see all the way back.

pallid lotus
#

Just the source address. Not the route it took to get to you.

pallid lotus
pliant cairn
#

people might have missed my question - any rooms/ctf on THM for SSTI?

#

searching didnt help

inland moon
sand trench
#

shadows ip is 127.0.0.1 most of the time

sick lance
pliant cairn
sand trench
sick lance
pliant cairn
sand trench
#

2 different nat:d networks thatn is

rapid merlin
pliant cairn
sand trench
#

well you can have fun denial of service if you accidentally set the ip:s to the same number on two computers inside one network

#

been there done that

pallid lotus
# crystal mauve And yeah that would be what someone could answer if they had in depth knowledge ...

If you're new to cyber security then you should already have a good knowledge of computer science -- which all that stuff comes under.

Cyber security is the expert application of other forms of computer science. In itself it is not -- and should not -- be entry level.
For the record, you're not being shot down for no reason. Teaching people tools without understanding is dangerous. Chances are they're gonna hit something they shouldn't hit, which won't end well for anyone.

pliant cairn
pallid lotus
#

Which may or may not belong to the attacker.

crystal mauve
stark sequoia
sand trench
#

during gymnasium years as a project shadow had to setup a server and some clients and accidentally duplicated a static ip... took about 45 mins of troubleshooting to figure out that was the cause

rapid merlin
pliant cairn
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #10 - 882)

sick lance
pliant cairn
pallid lotus
#

Rustscan actually being a very good example there because it's designed to be fast at the expense of safety.

#

i.e. it's a bad choice irl

sand trench
#

shadow has some understanding of networks and networking but there is huge gaps in their knowledge

#

some of which is unknown unknowns

#

some of which are known unknowns and so on

crystal mauve
stark sequoia
#

its okay as long as you know what you dont know so you can look it up when needed

warm grotto
#

Rustscan, ay?

steady pewter
#

Hallo everyone.

sick lance
#

Eh, I just stick with nmap.

pallid lotus
sick lance
#

I'm not impatient enough 😄

crystal mauve
pallid lotus
#

Which is why it's so important to not skip over that stuff when you're learning it in the first place.

rapid merlin
#

definitely agree with those points

pallid lotus
#

Just generally speaking there are times when a portscan is not a good idea, period. If you can't recognise those and just blindly scan everything then, again, you're going to cause problems.

steady pewter
#

yeah..rustscan is good for speed and CTFs, but..it tends to be..overly agressive at times.

sand trench
#

still prefer nmap due to how many options it gives you for optimising for stealth vs speed and harmful vs safe scans

warm grotto
#

What's an example of a scan being harmful?

sand trench
#

check the nmap unsafe scripts

pallid lotus
#

So, yeah, if you're treating CTFs like a game, and have zero intention of ever going into industry or otherwise applying what you've learned in the real world, sure, dive straight in. No problem with that.

sand trench
#

there you go

crystal mauve
#

I think u have a tough time separating IRL reckless practices with what’s actually being done via thm

rapid merlin
#

I just feel like if you take a complete rookie and force them to go really in-depth in networks or something like that for a long time, without any prior context, quite a bit of people will be thrown off the bus

pallid lotus
twin ridgeBOT
#

Gave +1 Rep to @pallid lotus (current: #10 - 883)

pallid lotus
#

I know a guy who took out an oil rig mainframe that way.

sand trench
#

welp that is a big problem

warm grotto
pallid lotus
sand trench
#

yuups

crystal mauve
sand trench
#

nmap can definitely do denial of service

#

intentionally or not

pallid lotus
wheat hare
#

Nice. 2 hrs later my "upgrade" from Windows 10 to 11 is complete...

pallid lotus
pallid lotus
#

Rule of thumb is that it's much safer to just not touch anything you've not been given express permission to touch.

sick lance
#

I can't remember how long mine took, but it wasn't 2 hours.

sand trench
#

rule of thumb send anonymous tips to the CIA if you live in the usa

warm grotto
#

Interesting. Good to know. I guess that makes sense thinking back to Highschool. We had thin client linux boxes for login and sometimes when we'd be in the computer lab, I found out when you nmap'd one of the logged in clients' IPs, a black bar with white text would pop up at the bottom saying random crap sometimes. Found it funny at the time because one of the things said was "HELP", but now that you mention it, that does make sense. Things can respond in ways not especially understood.

rapid merlin
#

Man you guys kinda making me a little bit nervous haha

#

I did a short internship a while ago as a kinda cyber analyst/it-support in a small/medium company and did a port scan

wheat hare
# sick lance Wow That was ages.

lol yeah, A couple years ago when I did it, it didn't take too long at all. But I didn't like 11 at all so I switched back to 10. I think there have just been a bunch more patches to the OS since then that made it take so long.

woeful rock
rapid merlin
#

I hope nothing went out of service 😂

#

I had asked for permission though

pallid lotus
safe heart
pallid lotus
#

I wouldn't worry about that specifically 😂

rapid merlin
safe heart
#

i inject fsociety.bat on my pc and it got ratted

pallid lotus
#

Even if you didn't catch the error, you'd have an angry sysadmin yelling at you very quickly.

pallid lotus
#

Play stupid games, win stupid prizes 🤷‍♂️

safe heart
#

yeah how do i download opsec

wheat hare
pallid lotus
#

On that note, I'm going for dinner.

sand trench
#

have a good din din muiri

safe heart
crystal mauve
pallid lotus
sand trench
#

aaaand fixed the setting browser problem

#

that was a lot easier then shadow expected it to be

gusty inlet
#

I just came back from scrolling and reading an hour of chat to see Manner's and Muiri's conversation. kekw

crystal mauve
#

lol

#

what do u think dkob? fooolish to start running scans before knowing the background and its noise?

gusty inlet
# crystal mauve what do u think dkob? fooolish to start running scans before knowing the backgro...

I stayed awake until 4Am yesterday just to know EXACTLY how AS-REP works. I already knew but I wanted to deep dive in it. Like very deeply. And after looking at exactly what's inside the rep blob and as well as the enc_part, I totally and definitely understand Muiri's point. It's just another level when you actually understand what's happening. Not only does this help you break things, but also find mistakes. I found a mistake in the AD section of THM when it comes to AS-REP.

But yeah if someone just wanna be here for the fun of it, sure get directly into CTF but maybe make sure that that's what they're here for. Most people want to become good I'd like to assume so better tell them not to skip.

#

@pallid lotus Generally speaking do you think going this deep will help my journey into red teaming?

pallid lotus
crystal mauve
gusty inlet
#

Gotcha thanks helps a lot! - @pallid lotus

For context I saw that the course on THM mentioned that the AS-REP had the TGT and gave back as well the session key... But I thought there must be something more. Turns out it doesn't give the "session key" but actually the enc-part which holds it.

steady pewter
#

Is this like..ooh, I see..kerberos.

gusty inlet
#

Yeah but it is super generalised. To be fair it was an introductory course but it's still inaccurate information.

#

I was looking at AS-REP Roasting deep dive using Black Hat USA 2014 PPT material and I thought that there must be more... and indeed there was.

steady pewter
#

yeah, Roasting is a bit tricky...

gusty inlet
#

IMO the easiest AD Account attack.

steady pewter
#

What can I say? I'm not very fluent in AD.

gusty inlet
#

Oh gotcha no worries.

jovial mountain
#

Good evening to all

steady pewter