#general
1 messages · Page 1137 of 1
its good some flag need extra caffeine
Doing some THM?
Hey Boys
wassup
right
nice nice
Woow you are a very old memeber mehn
Since 2017
That's interesting
Also fedora but nicer
lovely
Hey anyone can share premium login for THM? I just want to experience some labs
there's plenty of free rooms
Wooow interesting
Done with those bro
This is against our Terms of Service
I mean, if you join the giveaway in #community-announcements you can possibly win premium
Sorry didn't know
does that stack on current subs?
that's something I should be asking jabba ngl
it kinda does, not sure if they have changed it, but you'll have to stop the renewal and then apply the voucher
ah
I really hope I get a shot. Tried paying for i t multiple ways but man. Stripe hates me
Even the support couldn't do it
😭
can you normally purchase stuff?
Yeah, I used cards which I normally use
yuh
Get a prepaid code around the clock from the comfort of your own home. You never have to pay any extra fees and you can use your codes on over 4500 websites.
I am tired
Caffeine.
How
What how?
Are you a student?
What? 😭
i didnt drink coffee until like a year ago
when i started working, but i only drink it at work
I drink it to stay awake to finish assignments, commissions etc.
Without it I would be so cooked
lucky
Just sleep
coffee tastes good tho
Same here
"sleep" you say
I hate how the ftp is ran as root
And can stay awake
sftp and I'm logged in as root cause I haven't setup the user yet
or get revolut
revolut works
they also have one time use cards
revolut is very nice
How has been using Arch for you
How was the experience
hii
I hate that the cleaners turned off my vpn 😦
that means I have to go to school tomorrow
Bella has to touch grass? Oh no.
Bellas has school? Bella told me they were 21 and at work
more like I have to drive the motorcycle in rain
I do both work and study 😄
honestly yeah in the rain is just icky
Erm akshhally it's to ride ☝️🤓

Be safe in the rain though

I'm unsure if they're available in my country though
gonna buy 15 euro earbuds, how bad can they be
both revolut and paysafe
Can't be worse than none.
truee
I like the rain
Moondrop chu are really good for their price. Around $15-$18
these are Fresh ’n Rebel
As I thought. Neither works here
alot of people from my class had the skullcandies with the crazy bass
i like my sony xm3
i will never buy anything other then sony, even tho the xm5 and 6 are ugly
scene kid
Not at all, it just had the best sound quality.
Saying we “drive” a motorcycle will be understood and isn’t grammatically incorrect, despite being the less common term to use compared to “ride”.
especially when talking about the conditions and talking about taking a motorcycle as a different option than a car.
my sentence indicates that I wouldn't be driving a car but instead taking my motorcycle, plus referring to the conditions of the weather making the roads I will be driving on a non optimal condition.
therefore it is acceptable and often the choice to use the word drive instead of riding a motorcycle

true tho
i keep getting their discount coupons a lot lol
Theyre still running?
I didn't know they still made them
These days I only buy headphones is when I need a new pair for my PS.
sony just dropped their new xm6
ya ...with some heavy discounts ...which do feel like its original price should have been

i use JBL
I took off my headset to see what I bought and I still dont know
xD
i dont like their style tho, the small thingy on the xm3 and 4 and it looked better
Logitech
what small thingy?
I had to check amazon

the top bar?
thats epic
idk how to explain it
Try EPOS
this is the xm3 and 4
the headband
Hella underrated
this 5 adn 6
They had good reviews but the sound is trash.
oh ..damn
Yess thank you
Gave +1 Rep to @chilly veldt (current: #8 - 984)
yeah, I mean you don't feel the difference, I got the xm5's and they are lovely
doesnt embed idk why
This is hella underrated
only reason I would get xm6 is because they are now foldable and have better ANC
and cheap
Give it a year I'm sure to break them and I'll have to replace them anyways.
or at least in comparison
Guys, I captured the flag
this one send me to demant
Reference?!
urlscan.io - Website scanner for suspicious and malicious URLs
login.microsoft online
i use JBL Tune 770 NC
solid Base and sound and Adaptive Noise Cancellation is Mid compared to flagship NC Headphones (Like Bose) but still does good enough job
plus has both BT and Wired 3.5mm option
battery Upto 70hrs without NC , with NC enabled around 44hrs
yeah ofc it does
I don't know what half of that is you just said but okay 😆
Oh they changed their links thats why ye

https://www.eposaudio.com/en/us/gaming/products/
Redirects just to gaming
Here you can see em
nvm that goes to demant too
tf is going on
Oo
Anyways that headset has been the highest quality that I've used so far out of all headsets
dunno what kind of downfall they going through rn but the headsets are nice lol
Oh
It's now fully owned by Demant
that's why
People believe in anything
I guess
No i think it says that we are nothing but prompts from an AI bot
With a user controlling our destiny or sm5
oh yeah i see
Like a roleplay charbot
i shouldve looked further in the google serach
i think its the same argument as we live in a simulation
Ya the matrix one
hi folks
hi
I saw this exact vid on insta
That's why I looked up the prompt theory lol
how do you do
im fine what about u
I was half expecting a "can you hack my instagram pls"
same
I wonder how many staff work at THM
the blue ranked staff?
In general
I just started watching the documentary "cyber bunker" about the server bunker in Germany for darkweb... interesting story
:).
Which platform is it on?
netflix i think
yep
amazing site
you can see where you can stream a certain show
This one?
Yes
its been on my list for a while
It is a Republic tahay say , with a structure like a state.. 🙂
I'm sorry to ask, i'm looking for any good room about "parameter tampering", any suggestion?
Hi guyz any quick tip for anything which you find basic but quit interesting?
There’s so many bugs in this room.
which one

I’m done
I’m going out lmao
I was clearly never meant for the red road
I’m in walking an application.
First the red box just didn’t show up and now I can’t enter the next flag which I can clearly see
Am I being dumb?
You can't copy/paste flags containing _.
I also tried to type it
I mean I tried to type it first and then I tried a copy paste
The answer box on THM already has _ preset to autofill it. For example just fill it with 'a's and you'll see _ being autofilled in some places.
Yes so I tried to put in just the letters
You can occasionally
It’s like entering the _ in the incorrect place
You also can't paste in anything if the cursor isn't at the start as well
I don’t know why
Or maybe it's not that flag.
Alright let me check
which room is it i guess i done it yesterday
Okay well I’m wrong lmao
ello
Henlo
Hello fellow human beings
It turns out I was the bug
Mood


Okay I need to eat before I do any more rooms
Doing a badge CTF from DEF CON 31....
Blood is fuel
Love these little joys in defcon
It's this badge

Alien theme this year
for what?
Looking at the readme......
ROBOTS TRANSCLUSIVE XENOMORPHIC TRANSCRIPTOR - HUMAN INTERATION CONTROL SCENE (R.TXT-HICS) ERROR CODES:
- Watch more YouTube
- Ask ChatGPT
- REDACTED (For the current broadcasted REDACTED, see the REDACTED)
K thanks readme....
Hey 👋
Quick question (might sound silly, but bear with me):
If I forgot to cancel the auto-renewal for a monthly subscription and the payment failed due to insufficient funds, does that mean I still owe anything?
No, your sub just ends
ok, glad to hear that
Nyo but I do believe the service is suspended until paid or it reaches the end of the grace and it just drops you back to free
By service I just mean access to paid
yeah i got that
31 was 23, 32 was 24, 33 is 25
Yea, oki
I forgot how many there's been so far lol
Hrm, got a submit and a login page. I swear, this is turning into web pen and I hate web pen
Make up your mind, dang.
Looks fine lol
F neovim
:' )
F neovim? Neovim is goated.
btw m not able to set fancurves
any way to set legion fancurves on arch?
fan speeds
Fan control
like legion vantage
Oh, right.
:' )
There's a package called fancontrol, maybe that'll work for you?
My fan speed worked out of the box on base Arch, I did not install anything special for it.
It just goes up when how and down when not.
They all do cause it's hard coded to the bios and that's normally typical effective speeds
didnt work
know wot gpt suggested?
allocate 30gb to windows and switch to windows and set the fancurves and return to arch for ur work
dual boot basically
Lmfao
Wat
:' )
i really want to use linux as my daily driver
Why not start with Ubuntu or mint then
Cuz kali is just better
Are your fans not working at all?
mine is arch
they are
True but its not the best for daily driving imo

i just want to clean the sokaed heat
Danm, just let other people use what they want, why does it always have to be an argument?
:' ) my friend completed his osep on arch with exegol
yesterday he submitted the report
Just asking questions bud
LMAOO 
didnt work
what exactly didnt work
that gives a bit more info then this
You first need to make a config file.
Read the wiki page.
It also has alternatives.
Like nbfc.
The arch wiki is goated
Just check the wiki link, there's one section for most types of laptop, with different tolls you can try.
i tried nbfc at the first
yep
i'm not even sorry but i can't help myself.. maybe if companies would give a shit about their product, then it might not be so ridiculously easy for me to crack them..

Banned



Asimovvv!
heh?
Please don’t discuss piracy here
Hello
May i ask if there is such thing as Free PT01 ?
like when you finished the Junior Penetration Testing Path
?
There is no current free foucher for PT1.
Y'all am I gonna get hacked when joining this server?
No.
Hi all,
Just getting started in the pentesting world, and I'm keen to get some hands-on experience through CTFs. My manager recommended them, so I went to join one yesterday, but it turned out I needed a team – which I don't have yet as a newbie!
Anyone got room for an eager learner on their team, or perhaps want to team up with another beginner? Let me know!
I know nothing about pentesting can I join?
Hi stuart, you don’t really need a team. There are plenty of walkthroughs on YouTube and #room-help is a great place to get help if you’ve gotten stuck. Joining Voice chat is also a good place to find team mates
Hallo mate
I don't think they meant on THM.
Rly
There is only one room on THM that required a "team" and that's closed.
Yeah it wasn't for thm, the one I wanted to do was the nahamsec ctf this weekend
Oh ic
Prob should go to nahamsecs discord, not sure if that material is pay walled
Documentary's awesome.
yes it was really interesting...
hi all correct me if I am the for openvpn ssh tryhackme@ ipaddress provided and the password to enter is tryhackme right ?
Not always.
opps but i remember correctly back then so long i use openvpn the default password is always tryhackme did they changed it ?
The default password of Tryhackme is only on a handful of machines.
Otherwise the CTF's would be easier if all the passwords were tryhackme.
ok I am doing an easy challenge known as network services but when i ssh it prompted me for the password the problem is I dont know the password 😦
Maybe you don't need to SSH?
Or maybe there is another form of authorisation required, such as a key.
"The 5 Talking A.S.S. H.O.L.E. mouth indicators say horrible things via light. See the appendix for the color code to swear word translation."
a key ?
Possibly.
nope dont have I am stucked with this lab if I cant ssh as the lab mentioned to use openvpn 😦
Scrubz has everyone's control. Probably has 3 backdoors in ur device too
I'm not even kidding I tought I was gonna get hacked when I joined this
Hallo new
Well this website is actually a dare. See the name "TryHackMe"
Anyhow I REALLY want to learn whatever hacking stuff or computer things you learn here
Don't join unless you want others to hack you
Wait. You didn't come via website?
I love to program with all my heart and made a gambling game at school 🤑
Discord
Server finding function
I was bored
Google "TryHackMe"
So I joined like a thousand servers
My brother has tried it and it seemed fun
So I felt why not learning it
Sadly I didn't earn anything from people gambling on it 😔
Really?
Hehee
if i have 2 arms, how many arms exist in the world
if i have one tounge, how many tounge exist in the world
depends on situation
: )
why mad
🫵
absolute cinema
bro saved the situation
i know there is first blood. is there such a thing as second blood or top ten blood?
You can make your own game, and have such features
what is a good cybersec project idea that I can build on my own, I need my resume to standout with all the competition in this field 😭
Device encryption
can u pls elaborate a lil sir
Done!
What
i meant on the device encryption idea, what will it do actually
Do we have a room in how web crawlers are created
Guys, I'm new to hacking. Should I start with Kali Linux?
You encrypt a hard drive of a device
Any Linux Platform ...your choice
people say kali linux is hard for new users
Pretty much Same as any other Linux
alright
The ethical hacking tools might be the "tough" thing u mentioned for some

If somebody steals your device and your hard drive is encrypted, the data in the hard drive is encrypted and can't be read .
it's from the more friendlier side compared to others imo
Can go for kali since it provides all the tools inbuilt ..if u don't want any sort of hassle afterwards of manual installations
alright
Not all but most ...usually used tools
Hey, is anyone familiar with the task 2 on Snort "TryHackMe" ? I need some help to complete the question.
My current course is making me take the comptia A+ x.x
I can
lets move to that tho
so scbruz police don't get angry
When can we have server tag? So we are cool too
Oh no, how dare I ask a member to move their conversation to a more apt channel.
Speaking of labs I haven't done one since Feb and I feel so rusty
People get so annoyed at you for modding when you're a mod XD
its ironic aint it
Hihihi thats okay :3 Resting is fuuuuuun
Haha
I didn't mean it seriously
😭
Im not resting, just been too preoccupied with college and work x.x
It's everyday for him though, everyone does it to scrubz
ahhhh slaving is sadge 😦
Current course is so boring it's grueling
It's like basic IT stuff kinda
A+ stuff
Only good news is if I get my A+ it also renews my security +
Can it open wigle.net?
Yes, yes it can.
I was prob temp blocked from their site for trying to login too many times with failures lol
You'd think so , but nope, on VPN i was able to sign into my account, so not an account lockout, they IP locked me out
Cryptography done, flag acquired. new path opened up
Is there any plans in the future on adding a button/option to disable the AI thingy?
What ai thingy bro?
Echo, the things that "helps" you.
what is hackin
Hacking

never heard of it
Hahah 🤣



@brittle siren what is it buddy? You wanna learn hacking?
Hmm... Interesting
I wanna hack hack this guy who stole my account and scammed me

55$ account 
contact police/Authorities/Cyber Crime Branches for it then
Fr lol
Tell me process idk how to
search on google ...as per your country's laws and regulations and complaint filings
Tht guy isn't from country

so he is from the ocean
i mean u file complaint in ur own country first right?
then they'll handle the rest
Idk he from china most porlly
That would be illegal and against the community rules
Damn, I just missed seeing my rank at 6900 😅

Use the report commands to report rule breakers please

ah well, i keep forgetting that exists
next time will do
U mean me 
I don't know I broke the rule
cool yet scary name

Rule breakers is a collection
u mean 6969*
That would've been even more epic! ( I mean "NICE" 😆 )
🤖

FLAGS CAPTURED: 1/19
OH FUCK MY LIFE!
What are you up to ?
DEFCON
Doing, or attempting to do a CTF from DEFCON 31
Is that going on right now?
old one he's doing i think
idk , all the good stuff takes place in y'all countries

Sounds more exciting than "upgrading" Windows 10 to 11 tho
A part of me wants to try 😂
I can also change the color of the lights, has to mean something....
We had a question in tryhackme in a room about changing the colour of lights
It was a room that spoke about attacks towards physical end points
congratz... remember to take notes and teach your rubber ducky
Got any good room recs abt cryptography? (Free cause this time period no money :3) Or challenge rooms?
Tysm shadow is so kind always
I think I do
Feel free to send!

hmm...,Not bad PPLX
now i dont think i'll ever even get confused or forget the 7 layers of OSI in sequence lol
U can do “cryptography basics”
Well yeah. Got any challenge rooms you'd recommend for cryptography?
search on the site in challenge section , you'll get some
I think after this red team room I'll do a blue
Mix it up a bit
Can we something similar on other browsers? "User-Agent Switcher and Manager"
purple
The one that " gives you the ability to pretend to be accessing the webpage from a different operating system"
That is an extension but it’s for Firefox
I’m tired now
Custom scripts probably then
Guys for those of you who use obsidian is it reliable? Like if I lose a device all data lost?
Any cloud or option to transfer to usb?
i think u can make backups and save the file in ur USB
Ty


Hello chat, long time no see.
I have probably missed so many wallpapers
1
Wallpaper of the day:
or maybe 2-3
Now look in the camera

Nah i dont work for a government or any thing like it
😂
I use one drive to back them up but pretty much any storage solution will work since obsidian notes are pretty much just markdown files
Is it paid?
open source , free
Ty
Gave +1 Rep to @slow cloud (current: #99 - 80)
Ahh okay
Maaaaybe
Yes
Top 100

Yes
Arch
5806 Archieroy
windowns
We'll how will u guys know who's team you are on? We just scream we use arch
An obsidian vault on a github repo could perhaps work too? Maybe
We use arch as a battle cry goes kinda hard

As long as you can get the files on your own machine

Yeah
I don't know if obsidian can fetch files from a repo. Probably not natively
We have pewdiepie
one of the most common obsidian plugins integrates git
Oh damn, cool
Moving to git then
Us archians have suffered enough through the install we can take on everything
thanks man
Gave +1 Rep to @rare galleon (current: #1898 - 2)



You'll be fineee, what are you interviewing for
Avarage member of your silly army ^
Apprenticeship as probably Analyst or Dev or something
in ANZ
Falls to their knees, barely able to speak, voice trembling:
"You… you’re stronger than I thought… But listen… that thing… it can’t be defeated… not by force… not by anyone…"
How can one defeat itself
Its my dual boot
nooooo! 
Wassup everyone !
IM BLIND
Wasssaaaaa
warrap runescape 3
I memorized where the keys were two seconds before you nuked my eyes from hannah montannah
gonna be my First F2F Interview tho
nervous af already
Wanna practice ?
am off to sleep after reading thru Kubernetes and Qliksense's Docs
will see Tomorrow's shit Tomorrow
How much soda did you drink
Good luck
Wait, I refresh the page and the flag amount changes..... my head hurts
Kome D. Luffy
I think you can do both and win life altogether, I think it would be good mix.
Stand up comedy at night
blue teamin in the morning
Wats happening here
aight am off to sleep ...read enough ...will see in morning before the interview probably
Good night
Goodnight Goodluck tomorrow
AHHHHHHHHH
@polar spoke I'm going insane, hashcat is not playing nice with me, can I DM you?
sup
Have a hash, that I believe to be MD5, but no matter -m 0 -m 1000, still says there's no hashes
Hello, may I ask if there is website you can recommend for almost like AI-tools to ask about excel formulae please?
I am sorry if my question is not topic related.
I think any of the ai tools can create excel formulas
Have not done it myself that much so cant vouch for any
I found a small issue with a table with values coming from another sheet in the excel, and it keeps showing there are missing values despite I already input everything.
I asked but it couldn't answer..🥹
you cant get it to load the hash?
And because I am not the owner of the files, I am clueless of what went wrong (yet I am expected to fix them since missing values can affect the graph)
But thank you for answering! 🥹
Gave +1 Rep to @arctic gyro (current: #1898 - 2)
The excel world championships are crazy
OMG, that exist?!
mornin yall
Yesss
Main highlights of the 3-hour Microsoft Excel World Championship 2023 Finals livestream.
Watch the full livestream here: https://www.youtube.com/live/UDGdPE_C9u8?si=ZM1EDMcq36SJEuiP
What does that mean if you don't mind me asking?

Oh no no, I don't see Pookie as a flirting word.
beautiful website: https://lrclib.net/
Ok, I just checked. The formulae that seemed to be making the table on second sheet is not an official excel formula
But I don't know how to carry on and search from there 😭
Interesting...
Thank you!! I will check them out now!!!
Gave +1 Rep to @umbral geyser (current: #1898 - 2)
yeah they post open jobs on a few places when there are any
how was the application process until you landed to the job
has anyone here read Real-World Bug Hunting?
no tell me about it
idk i might buy it lmfao
Can someone tell me the best place to learn cyber security without going to school
damn we both do not know it
is it a coincidience
sad
hack twitter
you should learn fundamentals first before crybersecurity
mit has public courses
Is hack twitter a website ? Or
after learning fundamentals where should I go to learn cybersecurity
my networking skills need to be improved 
It was good.
https://tryhackme.com/
youtubers
cve proof of concept writeups
tons of hacker specific news sources
U don’t have to, fundamentals can b boring
damn, bro is talking like a politician 😭
improve it 🫢
you can't skip things just cuz it's boring tho 
i hate reading boring emails too but still do
how
idk bro i am freshman 😢
Yeah you can
if you have enough skills at it then yeah 😄
or money to pay people for doing it
i am junior
You don’t have to know a single port and what it is to run an nmap scan
sheesh how is it going
sophomore year is horrible goodluck
What did you mean hack twitter
hack twitter
Tryhackme teaches fundamentals, you’re at the right place
does it teach like cybersecurity i don’t really care abt fundamentals
Yah basically skips the boring stuff after presecurity 101
fundamentals is essential imo
U don’t even need any extra tags for most ctfs
Yeah, this is really dumb advice.
Fundamentals are fundamental, hence the name. They're a foundation to build on.
U don’t need to memorize ports n networking cables to do ctfs
They might not be interesting, but they're critical
If he wants to jump in let him
Are you thinking of applying?
if you dont learn the fundamentals you will forever be a script kiddie
It was good to meet the team.
Hacking is about leveraging knowledge to make things do stuff they're not supposed to do.
It's a mastery of other forms of computer science.
If you don't understand those other forms, how tf do you expect to do anything?
Until you need to work out what to plug
Or what systems are out of scope
Or why you can't hit a target
sure but you need to know what they are to look them up if needed
Learning also != Memorising
He’s gonna be using a walkthrough likely , no noob is gonna correctly enumerate and find an exploit on their own
Yeah, and you'll stay a noob if you don't understand what you're looking at lmfao
No it’s called practice - u learn while working and learning
Well, why not? Because they keep skipping the fundamentals!
HTB's style of easy where it's find software, find version, find exploit, pop is the baseline that you should have before jumping in
He’s not applying for a job lol
You need to care about the fundamentals.
Pleasr take this advice from people in the Industry and involved in hiring processes etc
He’s trying that have fun
Learning to break stuff without understanding how it works is like building a castle on sand.
It won't go well.
You need to understand the fundamentals before you can be remotely good at your job.
If you can't build it, you shouldn't be hacking it.
It's more fun when you know how stuff works...
Whole hacker mentality is knowing how stuff works
I said I don’t really care cause I’ve already leaned fundamentals
Stop trying to push people to learn A+ material when they just wanna run a friggin scan
You're the one that said A+
is this ragebait?
It’s silly , they will get to learning the fundamentals if they find a passion for it
A hacker embodies a boundless passion and insatiable thirst for understanding the complexities of a system, computers and networks in particular. They revel in the pursuit of knowledge and mastery, constantly seeking new solutions and opportunities for growth. Their drive and innovative spirit inspire and are inspired by the hacker community, where ideas and knowledge are freely shared and valued regardless of their origin.
--Silk
Don't skip them. It'll be quick if you already know them.
Foundations and fundamentals vary between fields
Again. Castle on sand. No point in skipping ahead.
If you don't know what you're looking at then you're not really hacking. You're just running tools, or following someone else's path.
shadow is feeling stupid as they can't figure out how to set a specific browser as default on arch linux
think about it. If youre just using the tools then.... what are you learning? Theres literally 0 thinking involved and just running a bunch of commands you had laid out to you. That aint fun
Yeah why not
That's very different from how it feels when you actually know what you're doing.
Using the tools u can learn to understand them ? lol
Not xdg?
anyone knows a good alternative for the vuln machine of the book hacking the art of exploitation?
no you wont, you never will becaues they abstract the concepts from you
then you wont be able to understand why something went wrong.
Do you guys sit and real every manual before playing a video game or do u actually play it n get good ?
well yeah but apparently shadows xdg entry is blocked as they set the $BROWSER variable but the variable does not work currently... gonna try commenting it out and then reloading window manager after the stream shadow is watching is over
can you make video games by just playing games?
or do you understand how game engines work?
Hey scrubz I'm learning traceroute. It says "traceroute command traces the route taken by the packets from your system to another host" Could it be traced back if the packet is caught. Can I find someone from the packets sent in
He’s not trying to learn to be a programmer he wants to hack a box
don't see why not as your ip will be the orginating ip for the traceroute package
No lol
I went to lay down and my kid saw it as a challenge to wrestle.
If I tell you to run an nmap scan on port 2893, can you tell me what actually happens when you do it? Can you tell me how that service works, how it's deployed? Can you take me through the network flow, and ascertain how that infrastructure works?
Without that, you're a script kiddie. Nothing more.
Also, cyber security isn't a game smh
Yes and yes
thanks for confirming shadow is a script kiddie muiri
Thanks 
Gave +1 Rep to @sand trench (current: #4 - 2150)
Yw. Go learn networking lmao
U think he or anyone needs to know all that to get their feet wet using basic tools ? No he’s starting off he’s not trying to apply for a pen tester position
Yes. I absolutely do.
Because that's the foundation of hacking. Not the tools. Not the CTFs. That.
well will go back to uni after shadow has gone through enough treatment to not feel like a depressed potato with the anxiety of a bun bun
Idk, i kinda see it from both perspectives, basics and fundamentals are definitely needed, but if you don't start with some of the fun stuff and get some context of why it matters and build some interest, stuff can maybe get a bit boring and you can hit a wall just studying theory
Ro Bot Rock
I remember adding this lmao
Learning the theory before using tools is always good though. Sure you can do both at the same time; i like splitting my sessions into 3 parts. Theory for an hour, beef up my computers defenses 30mins, do fun stuff and apply what i learned for an hour.
Completely relatable to be honest. Treatment doesn't work on me, sadge.
Uni also expensive
Somebody could find you, but unless you have higher access,.you won't find anything concrete
eeeeh the most expensive part of uni here is the books we have to get to read and study
I did walkthroughs n basic ctfs for months then realized I need to learn the fundamentals. But starting off just diving in and using tools got me to the point in taking web security , networking , etc much more seriously. But if it wasn’t for aimless nmap scans I would not have become motivated to get there
as shadow has stable housing and decent bit of dinner food options
I mean can I reverse them finding me with the tracerroute.
just a quick question - is there an SSTI room/CTF on THM? i know there are but searching gave me unrelated.
I dont know if Im even making sense. I've only powered up a brain cell. The rest of me is in another universe.
Jep i feel that 100%
I am preparing for the Network+ for some weeks now and my view has totaly changed. Things get way easier once i started to truly understand everything around and with networks
i feel like when it comes to CTFs you either know what you are doing or copy commands then completely forget about the solution. Theres not much learning going on unless you do both the theory and a practical example. Thats how it should be done for beginners
They would be like a MiTM, so probably not
I did fundamentals first before anything else I think.
shadow built birdhouses first
Okay, I see.
Yep
Eh?
i see some chatter on traceroute. So, just to add. Its over the protocol called ICMP. mainly just to discover network hops and nothing other than that. well there are similat tools like tcpping and other protocols that do the similar thing but more or less, if you made a request you are supposed to receive a response so, the packets have to know where to reach to. So, yeah someone can trace back to you 🙂 @rapid merlin
They're not asking if she can be traced, she's asking if they can trace them.
End of the day, as far as your router is concerned, it's just been pinged.
Wrong direct.reply.
And yeah that would be what someone could answer if they had in depth knowledge , but if you’re NEW to cyber security you will be running BASIC scans on EASY machines , where stuff is EASY to find
So, yes, the originating IP will be in your firewall logs, assuming the firewall records that stuff.
Can i u guys something
But you're not going to see all the way back.
Bold to assume. 😄
Just the source address. Not the route it took to get to you.
I run OPNsense. It's beautiful
people might have missed my question - any rooms/ctf on THM for SSTI?
searching didnt help
Is it possible to hack using mobile phone?
shadows ip is 127.0.0.1 most of the time
The average user doesn't.
damn same. can 2 people have same IP addresses. 🤓
yes if they are on NAT:d networks
Can they? Yes.
Should they? No.
superior than Palo alto. #hottake
2 different nat:d networks thatn is
So it does leave some sort of pathway back to them? So TECHNICALLY speaking. Could I find my way back to the attacker through that or would I utilise another method to reverse it.
ofcourse im just kidding
well you can have fun denial of service if you accidentally set the ip:s to the same number on two computers inside one network
been there done that
If you're new to cyber security then you should already have a good knowledge of computer science -- which all that stuff comes under.
Cyber security is the expert application of other forms of computer science. In itself it is not -- and should not -- be entry level.
For the record, you're not being shot down for no reason. Teaching people tools without understanding is dangerous. Chances are they're gonna hit something they shouldn't hit, which won't end well for anyone.
route? no. destination. yes. if there were artifacts left by an attacker. like logs. then we can see the destination the data exfiltrated or just connection made to the machine you are testing on.
You wouldn't "reverse" anything. All you would see is an ICMP / UDP packet from the original IP.
Which may or may not belong to the attacker.
Where do u draw the line tho, oh don’t use a rustscan unless you understand how rust works!?
mine is localhost 😎
during gymnasium years as a project shadow had to setup a server and some clients and accidentally duplicated a static ip... took about 45 mins of troubleshooting to figure out that was the cause
"Not extry level" Yep. I started in cyber and that's why it was so painful 😂
most of the time not attacker's XDXD
Okay Thank you
Gave +1 Rep to @pallid lotus (current: #10 - 882)
So why did you say "eh" to me. 
Thanks
it will be very fun. cyber is what we all enjoy here
Function rather than implementation. Don't use rustscan unless you understand:
- Fundamentally what a port scanner does
- How rustscan functions
- The legalities behind scanning stuff on the internet.
Rustscan actually being a very good example there because it's designed to be fast at the expense of safety.
i.e. it's a bad choice irl
shadow has some understanding of networks and networking but there is huge gaps in their knowledge
some of which is unknown unknowns
some of which are known unknowns and so on
Also platforms like thm bridge that gap allowing new users to be introduced to those tools in a safe environment? It’s the entire point of them , there’s a friggin module called PRESECURITY
its okay as long as you know what you dont know so you can look it up when needed
Hallo everyone.
Eh, I just stick with nmap.
Yes, and that isn't necessarily a good idea.
When THM started it catered primarily to cyber security / comp sci students. These days it's marketed at people with no technical knowledge at all.
The fact it exists doesn't inherently mean that's sensible.
I'm not impatient enough 😄
It works great for beginner ctfs tho
And that is exactly my point. It's great for CTFs, but if you don't understand the nuances of what it's doing, you're going to end up damaging something when you start working IRL.
Which is why it's so important to not skip over that stuff when you're learning it in the first place.
definitely agree with those points
Just generally speaking there are times when a portscan is not a good idea, period. If you can't recognise those and just blindly scan everything then, again, you're going to cause problems.
yeah..rustscan is good for speed and CTFs, but..it tends to be..overly agressive at times.
still prefer nmap due to how many options it gives you for optimising for stealth vs speed and harmful vs safe scans
check the nmap unsafe scripts
So, yeah, if you're treating CTFs like a game, and have zero intention of ever going into industry or otherwise applying what you've learned in the real world, sure, dive straight in. No problem with that.
there you go
I think u have a tough time separating IRL reckless practices with what’s actually being done via thm
I just feel like if you take a complete rookie and force them to go really in-depth in networks or something like that for a long time, without any prior context, quite a bit of people will be thrown off the bus
Certain networking appliances, some lights out software, and a lot of old OT stuff really doesn't like being scanned.
i.e., it falls over.
Thank you
Gave +1 Rep to @pallid lotus (current: #10 - 883)
I know a guy who took out an oil rig mainframe that way.
welp that is a big problem
Ah, so just a simple nmap scan in some cases can end up causing a Denial of Service?
Yep. Thing ran for 30 years straight with no problems until rookie threw nmap at it 
Yeah
yuups
I’ve heard if u run a scan on an fbi website it’s an auto felony , this true @pallid lotus ?
Yeah.
Point being: if you're telling people to do that, make that abundantly clear.
Okay agreed
Nice. 2 hrs later my "upgrade" from Windows 10 to 11 is complete...
Check local laws. That'll be an American thing if so.
Different countries have different opinions on that.
Wow
That was ages.
Rule of thumb is that it's much safer to just not touch anything you've not been given express permission to touch.
I can't remember how long mine took, but it wasn't 2 hours.
rule of thumb send anonymous tips to the CIA if you live in the usa
Interesting. Good to know. I guess that makes sense thinking back to Highschool. We had thin client linux boxes for login and sometimes when we'd be in the computer lab, I found out when you nmap'd one of the logged in clients' IPs, a black bar with white text would pop up at the bottom saying random crap sometimes. Found it funny at the time because one of the things said was "HELP", but now that you mention it, that does make sense. Things can respond in ways not especially understood.
Man you guys kinda making me a little bit nervous haha
I did a short internship a while ago as a kinda cyber analyst/it-support in a small/medium company and did a port scan
lol yeah, A couple years ago when I did it, it didn't take too long at all. But I didn't like 11 at all so I switched back to 10. I think there have just been a bunch more patches to the OS since then that made it take so long.

You should be. Again, this isn't a game. A cavalier attitude to security will -- sooner or later -- bite you in the arse
no
You'd know if it had
I wouldn't worry about that specifically 😂
Yeah i figure aswell 😄
Even if you didn't catch the error, you'd have an angry sysadmin yelling at you very quickly.
That sounds like a FAFO situation
Play stupid games, win stupid prizes 🤷♂️
i watned to be like mr.robot
yeah how do i download opsec
Also, I'm not sure how realistic of a possibility that the hardware of my aging computer contributed to the time it took to switch the OS, but I can't help thinking it did.
Oh dear Lord
On that note, I'm going for dinner.
have a good din din muiri
yum
Provecho
Please never say that again

aaaand fixed the setting browser problem
that was a lot easier then shadow expected it to be
I just came back from scrolling and reading an hour of chat to see Manner's and Muiri's conversation. 
lol
what do u think dkob? fooolish to start running scans before knowing the background and its noise?
I stayed awake until 4Am yesterday just to know EXACTLY how AS-REP works. I already knew but I wanted to deep dive in it. Like very deeply. And after looking at exactly what's inside the rep blob and as well as the enc_part, I totally and definitely understand Muiri's point. It's just another level when you actually understand what's happening. Not only does this help you break things, but also find mistakes. I found a mistake in the AD section of THM when it comes to AS-REP.
But yeah if someone just wanna be here for the fun of it, sure get directly into CTF but maybe make sure that that's what they're here for. Most people want to become good I'd like to assume so better tell them not to skip.
@pallid lotus Generally speaking do you think going this deep will help my journey into red teaming?
Depends what you're doing. For most red team roles, yes, 100%
true they did ask about cybersecurity, not ctfs
Gotcha thanks helps a lot! - @pallid lotus
For context I saw that the course on THM mentioned that the AS-REP had the TGT and gave back as well the session key... But I thought there must be something more. Turns out it doesn't give the "session key" but actually the enc-part which holds it.
Is this like..ooh, I see..kerberos.
Yeah but it is super generalised. To be fair it was an introductory course but it's still inaccurate information.
I was looking at AS-REP Roasting deep dive using Black Hat USA 2014 PPT material and I thought that there must be more... and indeed there was.
yeah, Roasting is a bit tricky...
IMO the easiest AD Account attack.
What can I say? I'm not very fluent in AD.
Oh gotcha no worries.
Good evening to all
Good Afternoon.







