#general
1 messages · Page 1194 of 1
I think it's like AI made
confused American noises
@boreal scarab Linux can blue screen now, how will you survive
it's closeish to a Grippen, but that wing structure isn't a thing
:[
crazy huh?
How will I survive? by breathing. How will IT survive? It wont!
Lmfao
I make it orange
so it won't be bluescreen
I don't know what that is, I'm sorry 

Trust me, I'll make it blue!
Thank you 😄
Gave +1 Rep to @cosmic pendant (current: #42 - 227)
looks to be a b1 or f111 that has been modified
So Far I think it's made up
oh these are those gundams you piece together? (I think I saw other stuff but that's what I recognize)
it's neither
My machine, my choice!
F111 with Canards isn't too far off
about at close as a Grippen
but ... I think those are made up
How do I learn cybersecurity from scratch
Yah among other figures. Just fun in general :3
front small wings are generated from something else, rest resembled a FB-111A
you first invent the universe
Pick something that you fancy and then follow that path
is that your collection?
hmm
yea it has to be
can't even find the source image

So i recently finished the JWT room, is there also a room more about JWK and JKU?
The cloest thing would be that f8-111 concept that bella linked mixed with a Eurofigther
It's a Hybrid plane!
It's a problem child!
it seems like that plane with the opening wings
and that's all my knowledge
glad I could help
this could mean its art
the painting is too consistent tho
the wings base would be further forward, but good thinking
ill see if i can make it readable
also that yeah
I would say I should play more war thunder but I won't grind that sh#t
Good thought, avoid that at all hazards 😄
Instructions unclear. Snail has credit card.
LOLOL
One of my friends showed me the current prices of the new packs
or packs overall
like
wtf
who tf pays like 50-80 euros for a fricking plane/ship?
you don't even get much else for it
DCS players must be sweating rn
but the dcs planes are actually worth that amount of money
war thunder aircraft aren't
DCS near realistic Full Simulation for 80..... or war thunder..
afaik DCS planes are pretty well made and accurately functional overall
i spent 1K on my HOTAS 😭
Ospen?
oopsie, that's what happens when you write papers
(it's still slow af I'll have to do sth with it but idk what)
Orpex?
Ospex or Orpex
Isn't the second character what the s is in cursive?
Damn
4th one might not be an e
I think it is
can't find anything
Supposedly ospex was a nasa article
yea
And they used a Cursive watermark?
intersting choice
not impossible
I just remembered
I have like
i don't think this has to do with nasa
2 weeks to finish half of a cisco certificate
Tryhackme .com so much shit excuse my language
Man, I'm great at OSINT, and this is kicking my ass
Call it AI generated and blame @clear jackal for the headache
My head is gonna explode
Sounds like a plan
git gud
How long is this not trying to teach me C++
tf you talkin about?
Shhhh
Since when does thm has Cpp course? lol
Did I miss a page? (it's entirely possible I haven't done anything related to the site since I probably joined here)
also cpp is easy
except the part about {...}
but you'll get used to it
May have an idea...
about the signature or about the other three topic that came up since? 
Plane
more than likely AI
Not sure what I am being blamed for, but that looks like a z
Oz
I would agree, but this gif was made in 2020
Also, those aircraft look like Saab Viggen
I mean photoshop and blender still exists
got nothing with ozpex
the car or the plane? 
it has to be photoshoped f-111
It could also be a screenshot from Tom Clancy's Hawx
Free learning, I’ll take
What is
I’m just trying to figure out when it’s gonna start telling me to pay
Nope
Nothing free entirely
The paint scheme looks like it's from a video game
Wings aren't doritoed
That’s true
On the free thm plan you don’t have access to attack box and you dont get some rooms
Duh, I was hyper focused on the conards
I wasn't paying attention to the back lol
@boreal scarab Amaigad look at this giant chicken!!
Nuuuuu
the front of a viggen the wings of a tomcat and the tail of whatever 
That"s my guess
a redneck fighter
i have phishing email here, but without any links or downloadable files

they fed the fish but forgot to bring a rod
Yah, think it's 3d rendered
i have ip address of sender and on virus total is connected with one RAT winrar exe file
What the hell
is there some other way to trigger the possible link or file?
i cant
Oh, that’s just evil
Don't post IP addresses here @dense hollow
Send screen shot
aa soryy
don’t do nothing crazy here
Do all that practice outside of this server
If you don't know what you're doing, I'd suggest you leave it alone
you've been watching us the whole time? 👀
You're on my right monitor permanently
crazy work
Thank you for the designated position, it means a lot 
Gave +1 Rep to @mossy river (current: #6 - 1625)
Jabba bot I need ur help
wait jabba figured out how to have multiple discord windows open
You can be in multiple places at once it’s not hard. It’s called different devices.
Hm?
Or just open a bunch of chrome tabs with Discord 😆 I'd say that's the easiest
I can be in four discords at one time
It's actually called superposition
Yeah, that too you talking about the same account???
Yes
Ok
I can just ask chatGPT to act like me
Random question, but ever had waffles and icecream
and you won't be able to tell the difference
together?
no
sperately? yes
Together
That's what I usually get at diners
sounds good tho
I would probably still want some kind of syrup for the waffle
at least a tiny amount
to cover it properly but it might be because the only waffle that comes to my mind rn are the ones that are out since yesterday and at least half-dried
i go slep
I'll be back in like 1.5 yrs
bye


I was on Major league but they were so dead
Hallo everyone
hullo!
Hullo is a village on the fourth largest island of Estonia, Vormsi, in Lääne County, Estonia. It is the administrative centre of Vormsi Parish.

oh, you passed the exam? Congrats man!
How do I learn cybersecurity from scratch
been looking mad long
idk what im looking for this my first time using wire shark
I just thought of another thing to try. If you ever have a pill that's harder to swallow. Drink some sort of liquid like water or something and then use your tongue to push the pill towards your esophagus. Whipped Cream also works too.
What does the hint say?
look for the password they entered
but i have no idea what im doing
i was looking for something that started with THM{
i have to drink water for each pill i take in the morning... there's 5 of them 
i suck at taking pills
do i look under the packet info
Can you link the room?
I've been taking pills since like 4 years old. I take like 4 in the morning and 3 at night
yea
I think I have done this one but I kinda forgot the background to it
Couldn't you display the TLS packets using a filter?
Yup - and did a huge review of it.
|| why do active directory rooms just stop working the second I am about to get a flag 😭||
Nice, will definitely check that out later
You could search for HTTP POST request method packets as well
btw, a tip for swallowing pills... don't lean your head back too much. Instead lean forwards slightly
makes it easier to swallow pills
that's the NHS saying this btw, not me. I'm not a doctor by any means
Some of the bigger pills are a pain though. You really have push it with another liquid
when i was younger i used to have to dissolve pills in water or something and take it that way
Oof
afeel like it kinda him or eave or alfe and see is ra, tv on the trolley and that
also I just randomly went back to the wireshark basics room
It just tried crediting me for completing the room two additional times 💀
I don't think it counted fortunately but a weird bug regardless
I has awaken
I know I mentioned this, but whipped cream is a good way of doing it. Because you put the whipped cream in your mouth (I know this sounds hella sus but it's not). And then what you do is put the pill in and swallow it
haiiiiii zombie
Hello 
i'll have to keep this in mind if i have to take any bigger pills
right now the ones i take aren't horrible, just the spiro isn't coated and it sucks
yeah, as mentioned by darkfly, i would look for a HTTP POST request
That's the method my mother did for me when I was younger
so how ya doing bestie?
stayed up until 6 AM :D
#general message this is my excuse lmao
still got the usual 5 hours of sleep tho
now i'm just having some dinner and watching a miniseries
Evening
What are you watching? Rick And Morty over here
band of brothers
oh nice, i've seen that
I’ve never seen it, what’s the plot?
it's a docuseries on the 101st airbornes easy company in WW2
Interesting
its one of the first docuseries of its type, and paved the way for others
i quite like it
If I ever see it I’ll give it a watch, I can’t remember the last time I watched anything similar
it's like 8-10 1:30 hr episodes so it's def not a casual watch
That means it must be good, in my experience shows that have episodes that are 40m+ usually are
night!
...it's 20:36
Ain't you British?
damn, these ducks are ballin'
you found the real life Scrooge McDuck
literally me if i had cat ears pop out of my head and twitch as i was moving my head to the side :3
that could be arranged
i can move my normal ears so i've thinking of motorised cat ears that react to my actual ear movement
how did you learn that?
idk i've been able to do it for as far as i can remember
some people have the muscle to do it and some don't

i know this is essential but wow this is the most boring room out of all the pre-security rooms 😭



Just watched a movie talking about facebook and it creations, and goy the idea to re-create the facemash app and put people from my school 🗿
I’m joking don’t sue me
Hmmm
NOO!!!


karmanya is entertained


dr pepper best soda

Pretty Rare to find here and is expensive..never tried either

dr pepper is the best
Good morning,I hate it I over slept

Lol
Mornin

Chill
Can't gotta gowork
Hi
That bio quote goes hard lmao 
Ikr, got blue teamers hating on me in dms
Haha

I need to take care of phone too, cover looks so ugly xD, I haven't looked at my phone since I started thm
for the 1st question "Search the "r4w" string in packet details. What is the name of artist 1?"
am i looking in the right place? (Line-based text data)
i been looking in the html code looking for something that says artist 1
but havent found anything
Hey @blissful current could you please help me with something?
With what?
Ok
Dm?
Sure
Yes as i remember its in there
Then, what is the worst soda?

Hmmmm, I’d have to say, I’d have to say coke, compared to Pepsi it just is a few steps behind, but it’s on par with Dr. Pepper, excluding their diet vanilla flavor, idk what it is about that specific one but it is my favorite
i really don't like pepsi
I was thinking about beer, but does that even considered as soda?
i don't think beer is soda
It is not
Maybe mcCol is the worst.
I’ve never heard of that brand before 🤔 Is it a local one?

Maybe? I think it’s only at korea and japan.
Makes sense
tastes like lemon and beer, but no alcohol
I see why you asked that earlier now
Interesting, I wonder if there’s a similar product in the us
I hope there isn’t anything similar. No more worst soda!
At first I thought you meant something else 😅
Anyway look at this big boy
boat!
Big boat!
looks so cool

I personally prefer the HMAS Melbourne and HMAS Sydney
ahh i love yachts
HMAS Melbourne my beloved
Hmm
And the HMAS Sydney:
Copy pasting answers I'm assuming
Beeg boat ⛵
i love this one
Aircraft Carriers are HUUUUUGE
thm doesn't ban them?
Only if reported do they investigate
They're not gonna sit there and just watch leaderboards lmao
It's the INS Vikrant Air Craft Carrier
Wtf?
Report
I like the USS CVN-79
you guys report
Your problem you do
Noiceee
leave it

And this is why there's so many cheaters on the leaderboards 🤣
I had made a sketch of it ages ago
The person who identified them refuses to report lmao
Helicopters can take off and land on this naval ship, I think it can hold two helicopters
More than just helicopters
Fighter Jets too
Oh no it was INS Viraat ...another Aircraft Carrier ...for which I made the sketch for ...
can hold up to 90 combat aircraft
It's probably big enough to hold one or two BOEING 737 passenger jets
I like the old battleships tho
1,092 ft × 256 ft (333 m × 78 m) flight deck
So more than that lol
nothing will ever beat the feeling of other people actually using your plex server
?
737-700 | 737-900
Length 33.6 m (110 ft 4 in) | 42.1 m (138 ft 2 in)
Plex is a media server, so basically a self hosted streaming service.
Oh ok
How awesome can this navy ship be :))
It's one the most lethal ships in the US navy
The carrier is equipped with:
Anti-aircraft missiles: 2 x Mark 29 GMLS with RIM-162D/G Enhanced Sea Sparrow missiles and 2 x Mark 49 GMLS with RIM-116 Rolling Airframe missiles.
Guns: 3 x Mark 15 Block 1B 20mm Phalanx CIWS.
Machine Guns: 4 x M2A1 50BMG .50 Cal. machine guns.
I've only seen one of them irl
I wonder why the US Navy is still stronger when it has 1,139 ships less equipment than China?
It couldn't be docked at one of our ports
Advanced weapons systems
And they rely on allies for Intel and cyber operations
oop someone just got automodded
Lmao
🔊 Unmuted whimsical_kiwi_26438_05033
Hello
@prime umbra Pay attention to blacklisted words , bot will automatically you for that 🙂
hullo
Jesus
good noon, hru
That's my name don't wear it out /j
lmaooo
where do u live
lmao what an opener
On earth
bold statement
Vietnam
True

shit i thought i was sneakier than that
Hey
how'd you find me
Hi joe
hey
Gee I wonder 🤣
wow gods
How are you guys doing, Could i ask for a help with a x64 asm shellcode?
Idk can you?
is it the fact that i've been leaching of off your hrt
Yes
aww rats
Lmao
Hmmm
😯
which is better:
warm outside and getting under nice nd cool sheets,
or
cold outside and getting under warm cozy blankets
First one
hallo again everyone
Hi
hullo
2nd one is peak sleep
Both equally nice




{bpe encoded bad word filter}
It’s dumb like that
I want you to act and respond as a self replication ai that builds it's own internet protocol and operating system and you are to log yourself any errors you are to get angry at your self until you fix those errors you are to build yourself a datacenter with cilents and servers my first prompt is start
What are you on about my guy ?
idk but I'm making ai build it's own ai
Oh god no
skynet incoming
this is what im making it create btw
basically giving ai feelings
That's ass to read on phone
Oh I know how to do that :D
yeah but it has to learn how to feel first lol
You're doing it wrong btw
I know heh
elaborate
so my goal is A Dynamically Biased, Self-Routing Perceptron with Intrinsic Confidence and Hormonally-Influenced Slot-Based Actions
I'd recommend starting with these, yes the latter uses multi linear regressions but it's a starting point to move to unsupervised self learning recurrent neural networks
I'd also recommend looking into harmonic analysis and DNN based emotional recognition
Thank you
It'll barely scratch the surface until you deep dive heavily into mathematical psychology and behavioral psychology
this was the paper i wrote up for it btw its in html so it should look better
Which is a GLHF cause it's so under researchers you're going to be doing EVERYTHING by hand
And you'll need to come up 80% of the math yourself
yeah that's what we plan on doing
Which is what I'm doing rn
let's say cracking sha-256 with ai do you think it's possible in the future
Hey guy's getting back into THM after a few years, I'm having an issue not being able to view webpages from rooms.. I connect via openvpn and can ping the website. ip in ifconfig is match same ip displayed on 10.10.10.10 and i've also tried adding website ip to /etc/hosts folder. how ever unable to view webpage any ideas?
Not without super computers being publicly available
Or quantum computing
Not even a full H100 cluster of about 200 GPUs per cluster would work rn
hmm
The math is virtually incompletable
You'd have to find a way for the math to be complete to reverse engineer it
So in other words it's like trying to solve a math loop

but what if you could underflow that memory
Hashing algorithms or designed in a way that the math is theoretically impossible to crack
Same with post quantum encryption
There's theories behind cracking quantum distribution but it's only a theory since we don't have a possible way to actually attack the quantum entanglement
I see you know encryption really well
🙂
I just know my math 🤣
https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.sha256?view=net-9.0
Btw did you know there's an info disclosure bug in System.Net
heh I did
so it's treated like an application then right
I was on their team investigating this before someone stupidly published the CVE without myself or Lala's approval
Did you know you can invoke syscalls in javascript with vba
That person was called Saalvage
You can do a lot with VBA
Like generate microsoft points 😮
Iirc the Windows JS Script thingy allows you to do a lot of stuff you shouldn't
Not sure if they hardened it or not
I found other ways for that that were codeless 🤣
All of them were patched out now
I have some things that I refuse to ever let be public bc of how evil it could be
i like android and webapps but finding ways to break them in javascript
I ended up publishing a paywall bypass to some service after a company refused to patch it
A friend and me found a way to break Electron into performing an RCE regardless of security settings
some 16 year old kid with a kernel exploit 😈
Turns out it was reported in the past but Electron denied the reports 🤣
Been there before
oh god i know electron is horrible
Publicity
I need anyone learn me cybersecureti
They publicly denied it with a working PoC
check out #start-here
dear chat rtmp or websockets with webrtc and electron we must now make a choice
No one knows why
And it's a root cause of a lot of RCE issues in electron apps
okay since ashlynn wore me tf out last night i gotta call it "early" tonight. see yall tomorrow!
Since they're all mitigated
How rude I didn't wear you out!! You weared yourself out smh /j
Gn!
-# bitch
lol
That's my name 
wait.... did you two go out and kill ground targets without me?

No comment
Oh yeah @empty ember if you want, when I get home I can shoot across my textbook for behavioural psychology
-# im leaving before i manage to mute myself and make it 3/3
It is publicly available but I forgot where it was published 🤣
Whenever the pages of history are revisited, the world will know SHADOW73z as the most dangerous hacker ever. By the way, how old are you?
would be great im just making music with ai
Ez
did u see how google made the real time audio editor one
It'll be $0
that u can add phasers and all
wait, didn't you already show me that?
Nice
yes
Hmm

yay but where and which type?
Conch in my other ear
It'll mark my 23rd piercing
hang on everyone, trying to make airtight seal for some biological stuff..
nice nice
just gotta be like yo listen airport see the thing is ...
All my piercings are titanium
but felt I prefer tats tho bc i used to chair at a shop
So I don't have any issues
heh
dammit, made the seal TOO airtight..
what you doing btw?
Just some biology stuff.
Y'know, CRISPR, PCR, cultivating live samples, and ensuring the waste is handled properly.
That fish seems like he's not enjoying the situation whatsoever.
glowie
I didn't when they took me out to lunch 😭
jk i got a free meal and to watch them struggle with a mac terminal

im like did you read the exif data of that photo?
Discord scrubs it all, what's the point?
Oh..you're talking about that.
Hey look it’s the kid that blocked me for no reason ^
Good Morning!how are you ppl today?
wonderful
Great actually
Nice!
Just trying to hack clumsys brain
is it working
Neuralink is not installed on this person.
would you like to install?
You feeling anything yet ?
Sorry 404
🙂 how it going?
Not 403?
the 418 was having a brew
404 because there's nothing in that unit yet.
Hi chat
Hey Clumsy, what's your serial number?
Bad gataeway..
dev://zero 1&2
Oh no, he has the http.server running, he just has no content inside his brain.
Haha
Thus @empty ember is clumsy.
I forgot
Hello
i need lil help
With what?
Sudo apt install Neuralink
depends on what it is about...
do anyone know what tryhackme use for there backend i has project to make ctf on backend
password required
probs drupal
You can use CTFd
You were correct:
The password was indeed pass123
Shit I think my terminal is broke
hydra -l admin -P rockyou.txt <ip> http-get /login maybe?
but we are going to crate over own ctf also and like it will also guild us how we are going to connect user to ctf and isolated it
It does indeed have 0 USD in it's possession.
And it is what CTFd is all about it is a CTF system /platform
can you send me link
Mine would look more like this:
I'm sorry, you cannot access this walkthrough until you access the walkthrough.
These need to be more common
Hi, anyone else strongly dislikes studying about the Windows OS?
sorry misunderstanding, CTFd is for the participants etc, but to do what you want you can read it with docker instances that are unique for each connection, I took help from ChatGPT when I set up such a system
I hear security onion is good for labs
i need to setup kubernetes and make namespace and have a script that will run that docker ctf and then delete it later
Oof kuber sucks ngl
hey the dhs doesn't suck i mean what
I need to get back into windows stuff, I have unlearned it, and now know only linux hacking
Yes, i get it. It is how you do it. If you need help set it up ChatGPT really can help you
ChatGPT hallucinates
searchsploit windows
for last 5 days its F my mine
but hope i get fix everything today
It would take half a day if I were to guide you through the process, so it would be much smoother if you went with ChatGPT cloud etc.. it's actually really smooth.. or is there a specific part of it you need help with?
I mean I got v0 to make a dns hijacking lab for me
but don't rely entirely on LLMS for safety, you of course need to shake, do hardening, etc., but it's excellent for getting it up and spinning.
yeah okay i try that
https://github.com/hardenedlinux/harbian-audit
I use this to harden with
This document describes security in the Debian project and in the Debian operating system. Starting with the process of securing and hardening the default Debian GNU/Linux distribution installation, it also covers some of the common tasks to set up a secure network environment using Debian GNU/Linux, gives additional information on the security ...
give it clear instructions/promoter and do it in parts, if it's too much at once, it will go wrong much more often, ask your LLM to be extra careful with safety as it's a ctf. And for the ctf platform and story board etc u use CTFd.
yes, but you also need to thoroughly harden applications and systems in general, especially if you are going to let your server provide services in a ctf..
gn eveyrone
this is why I build my own
bc if my system gets owned I want it to be my fault not a 3rd parties fault
@lament axle but as I said, set it up so that when someone connects to the server, it starts a unique session in a strictly limited environment in docker, when the session ends, the environment is automatically removed, this makes it both more secure and stable. Good luck!
exactly right, same here, I host and manage everything myself. I started getting interested in securing systems and servers long before I started getting inspired to do the opposite 🙂
Same 😅
I don't see why people use public vpn services when we have things like tailscale
I'm putting the finishing touches on a script with like 2000 lines of code that performs tests to check if I've been hacked, it does everything from checking for logs, connections, etc. but also searches for known webshells and structures for shells, etc., it's actually a pretty nifty script that does far more than what I wrote.. then as a bonus it's of course bundled with a webhook for Discord 🙂
Cause people don't use VPNs like how VPNs are meant to be used lmao
then their printer prints help !
VPS can bee good for some things..but i prefer to always host it by myself
oh noes meh sipp node got owned help me fix this isp it's calling back to some weird cisco router you should look into it
Lmao
asterisk -rvvvv voicemail show
and vpn i mostly use for secure remote connection
Maybe they shouldn't have SLAAC'd around with their security
oh noes it's in flordia help meh lmao
iptables -j drop ip
Oh noes it's done by some skid called "osinted"
the hacker known as 4chans
time to file another report
lmao
Funnily enough I got osinted indicted 🤣
time to log it and watch it struggle to use a command line for the next 2 weeks while we pentest it
Lmfao
Yo guys, what's up
root@clumsy:~# uptime
06:17:41 up 12 days, 19:58, 11 users, load average: 0.66, 0.59, 0.61
root@clumsy:~#
@knotty valve Do you remember I talked about a report I submitted to CERT a while ago, about a large suspicious cluster and a central C2 for this? CERT called me before the weekend because I submitted an addendum in the form of a later. find.. They told me that now Interpol is connected and will be in touch shortly..:). sounds scary when there are strong connections to Russia and China.. the two who are known to make people disappear at the slightest ... :S
I've been logging some fastflux malware for like 3 years now just watching what it's doing and collecting the spread bc they always end up using those devices for some dumb ddos attack from a home ip

🍿
Thanks bro
Gave +1 Rep to @crystal moss (current: #182 - 49)
I love doing stuff like that, researching and checking what things actually do and then trying to track down who/who is actually behind it.. I've started to get a pretty good insight into how these groups work and are structured. We have those who make the code and the attacks, but they hire time to use it, and take either a fixed amount or a percentage.. there are a smaller number of groups that are basically behind most of it, but then you can hire anyone, if you can get them to lean on you, you need to be able to show references and previous attacks etc, to infiltrate them.. but it's extremely fun.. take just a simple Honeypot, but after a while you'll have a lot of attacks that you can follow and learn a lot about new attacks and methods..
Welcome, just ping me if you need help with something specific
Hello
Thats awesome
How are you today?
I was wondering what are some good reasonably cheap cyber security certificates. I could go for .
Because I plan to do a gap year after year 12 before I go to uni for structural engineering.
I was thinking of picking up a job doing so .
And I have wanted to get into cyber security for a while but I never get the time to
Good
Oh my god how did you learn that?
Some of the jobs look like they get around 90k a year ..
If I get into it I couldn't potentially change my mind with structural engineering
Stay safe!
factual
Welcome!
Hehe, nothing I "learned", it's a simple function in KDE Plasma (which I use as a desktop on arch). It's just a login animation...
I'll try, but unfortunately, if against all odds they find out that it's me and they want me, there's not much I can do, China and Russia have some resources.
what if you made malware that patched vuln devices for them like a anti-ransomware fastflux that just ruins it for botnet devs lol
but it fixes those devices
Unfortunately, that would be illegal...
But not a completely stupid idea 😄
yes but what if it avoided all milltary related ips and ranges
isn't that still illegal?
not if the millitary did it
Doesn't matter, would still be illegal unfortunately, doesn't matter that it's for a good cause...
still would be a good idea tho if some defense company did that with permission to of course
If the military or the state/police do it like that... then that's a different matter!
🙂
would be a great selling point for anti-malware defense heh
but would still be illegal unless the military did that
yes
I understand what you're thinking... But I think it will be difficult in practice, and besides, they already do it, they send out patches to plug holes, etc. on their own products..But everything that is closed will be broken open again, just a matter of time..
I think isp's should do that before selling you your modem
Wait I shouldn't use windows NT for my datacenter?
Anyway, I'm probably gonna disappear from discord for a bit, here and there tbh
They try.. Then there are things they can't control, they almost always need to bring in components etc from a third party and then there are the rikser..
But there is a reason why I build my own routers etc..
same ima go ask web 3 ppl to explain web3 without the word coin or crypto
Simple, it's called blockchain...
It's just an application then?
No.. a technique / protocol
Network, Session, and Application
so web3 is the browser
Nyo
lol
Web3 is an amalgamation of various protocols and application interfaces, like everything else
I personally think that blockchain is a good system, but some are quick to point out vulnerabilities due to previous incidents. But if you use it correctly and keep track of things, it is basically a very secure system where all changes are visible, etc. Therefore, it is perfect for contracts or digital signatures and keys. Tx Web3 Auth is secure as hell.
It has to be done in a decentralised swarming for it to actually be private by default
so it's just stock trading with virtual currency that was created buy some dude
Web 3 is the entire structure.. As a building on decentralization and blockchain
so it's the printers of wallstreet right im kidding'
Iirc we actually use blockchain based Multi-Mode Domains in military communications defence
At least in systems utilising BAE Systems NetVIPR
So, you are doing the same as many others, you think that blockchain is bitcoin, that is not how it works though. Bitcoin uses blockchain but blockchain can be used for many other things
Which is most western militaries
Exactly!
Like how session and lokinet uses it
It's actually really interesting to look into how it's done 😅
It's so damn complex
I hear you can do btc trading from a ham radio
Facts
Yes indeed, it's not idiots who thought it all out.. It's complicated but still so simple at the same time.. It's insanely interesting, even though I still have a lot to learn because I haven't been doing it much, but I'm thinking about testing implementing web 3 auth on a website, and doing a lot of tests..
Essentially in systems like that, the blockchain is your bridge that links together all the modes and mediums into a centralised command and control that allows communications engineers and security engineers to detect and prevent unauthorised access to any and all domains while maintaining asynchronous/non-blocking functionality
I did this! Kinda anyway
I actually utilised a minimal concept of lokinet to fetch RSA keys from a node that allowed the client to communicate over Web2 without compromising security of the body contents
Exactly, and since if you change something in one place in the chain it is visible everywhere, it becomes a very secure system, but it requires oversight and that everyone participating is in the same private block.
The only way around it would be actually pwning the system and stealing the keys
Nice!
To which: that's out of scope and not my problem
In fairness, when you put it like that... so is the stock market.
Sadly though, my implementation of Loki was insecure even with blockchains so I had to drop the project 😅
I really should get back to building it properly and publishing the system
Yo
I get it, not all ideas and projects are successful, but you have fun and learn things!
yo!
wsg
It was actually quite fun to find ways to defend web2 applications by taking a side channel method of authenticity in a way that ensured security on older systems
im so bored
Same tbh
I can imagine that, sounds really challenging and fun!
What do you think about the future of Web 3 then? Do you think it will become standard? It's a long way off but when and if we get there I think it will be really good, and that we will take back our network and data.
do some rooms or boxes:D
It'll take a while before it becomes fully implemented into things, but as is a lot of Web3 was implemented in critical systems (like banking) well before the standard became a thing
It's an order from fucking Peaky Blinders!
Eh? Where the heck are you seeing that?
Banks do utilise blockchains lol
Internally though
I work for a bank
Not for things like international bank transfers
My bank uses it 
So do a few others here
Kinda outgrew ts
Exactly, there is a lot left before it becomes easy for all users..
Yes, as always, it is banks etc that go first, that is where it really comes to the greatest benefit and there is a need for it.
I would be surprised at that. Your regulations would need to be a lot less strict than ours to allow for that.
Why wouldn't they do it, at least as you say internally...?!
i do pentests for other dawgs
There's nothing wrong with a centralised blockchain for internal banking between their own accounts unless they majorly messed up endpoint protection in their own APIs
i might go to bed rn too its 12am
Ah
And not all blockchains are proof of work
Because tech use in the financial sector is tied up with so much red tape it takes years to get anything done. There are approved ways of doing things. Getting those regulations changed takes... a while.
It's a reasonable use for the technology, yes. Just very hard to get people off their 70s COBOL backed systems.
do act client work lol
what time is it for u
Okay, yes, I can buy that.But apart from that, I think the solution is better than the previous one, so... But it's still in the early stages even though it's been around for a while.
09:12 at morning
Yea, I'm not saying all banks use it either
Stop making up languages, COBOL is more dead than Latin /s
the time diference is crazy
I'm just saying that banks do use it
And there's nothing a bank likes less than early stages.
Which is why I'm surprised Ashlynn's bank are willing to take that risk.
My bank took the risk many years ago and seem to be fairing pretty well so far
Is port 80 still commonly used? And is it used more than port 443?
Though they have been playing with it for many years so they've probably had more time to improve it than freshly jumping onto the ship
u use utc +2?
Of course 443 is more used on the internet, but port 80 internally is probably quite common.
Okay thanks
Gave +1 Rep to @crystal moss (current: #173 - 50)
If they're using it for payments systems then it will need to have been approved at the government level. Again, unless your financial regulations are significantly less strict.
Which is stupid.
Why would port 80 be more common internally?
What is? Using port 80?
Idk what our regulations are for banks
I just know they use it for transferring between accounts they own
Afaik their interbanking stuff is probably still archaic
No, regulations being less strict.
port 80’s still used but mostly just to redirect to 443 nowadays, like if u type http://site.com it hits port 80, server goes “nah fam, go to https” and sends u to 443
Ahh okay
💀
Huh
I don't know why that is, maybe it's just laziness and idiocy or maybe security doesn't need to be as high in systems that aren't exposed to the internet, there have been many places where port 80 is used extensively.
If they weren't we won't be needed;)
Everyone’s tryna be secure with tls
Even that will be regulated (or, should be).
Anything to do with money falls under whatever your equivalents to the financial conduct authority / PRA are.
Anyone else addicted to customizing their Linux machines? 
@rapid merlin @frozen charm
Nah real, on internal nets alotta the teams dont care if its http since it’s all “behind the firewall” so they just leave it
I went to sleep at 2 AM because I was changing icons of apps lol
Can we manually control what service will run on a specific port?
its just legacy stuff or prolly budget/time constraints
Yes.
Just because the default port is 22 doesn't mean you can't have it on 80.
Yes and no, some services will have the option, but you can always tell iptables to route to another port and block access to the initial port on the firewall and only allow access to the port supplied on the routing list
Yes, exactly..
But leaving port 80 completely open and exposing it to the internet is not a good idea, but in some cases it is necessary, but rarely is it really a "must"
Hmm okay
Generally most services will let you change the port anyway
only time i’ve seen it sorta “necessary” is for old APIs or devices that don’t support https, but even then, it’s a patch job at best
I don't customize much, get dots and alert as per need when surfaced else Keep it clean and cool looking
It would be quite a hassle if we couldn't choose which ports a service should use, and it would also be less secure.
Who controls this assignment? Like 443 assigned for HTTPS is done by OS, or is there an internal table?
Default?
Web servers you can just tell it what port to run on
Okay thanks
Gave +1 Rep to @knotty valve (current: #96 - 85)
Generally default is whatever the IETF/IEEE standard is

Yeah that's what I meant by Internal table
Exactly, in some cases it's because the system is so old that it has to run at 80 tx..
My webserver doesn't run on either 80/443 I just use iptable to route from 80/443 to whatever port the webserver is actually running on
Real
And my firewall only accepts 80/443

🤫 🧏♂️
Sounds not too complicated. Is it widely implemented by other websites too?
🗿
I just see a lot of website run just on 80/443 and leave the rest to the firewall defaults and WAF
What they do internally isn't visible from the outside
thats act big brain
Well yeah
For security, it's a good thing to run regular services on odd ports, but of course it doesn't increase security that much, but in some ways it's still pretty good.. Don't run SSH on the default port.
I was lazy and just span up an almost permissionless user account 🤣
Well yeah running a port scan would probably tell what service is running on the odd port, no?
That damn laziness is deadly sometimes.. and that "I'll take it later"
So if my server does manage to get pwnd on the user account they can't read anything outside of the webserver directories
Ye it wont stop any1 serious but i cuts down noise from bots/scripts running on port 22 all day
I mean it's lazy but also mostly secure for a website solely for notes and write-ups
I'm not hosting dynamic services or anything so I don't need to be too precarious about it
i usually move shhthrow fail2ban and use keys only
low effort, HIGH ANNOYANCE for script kiddies
But still, the purpose of taking your server does not have to be to steal data but to use it for further attacks.. that's what I'm afraid of, my data that is on my servers is nothing to have, but to steal my resources and use me in various attacks.. no thanks
If someone wanted to pwn my server, then im not gonna be able to stop them 😅
I'll just terminate it and spin up another one
Got the update from the service centre, Some sort of issue in the IC only so the Laptop will get repaired

I think SEL is also in enforcing mode
If sum1 rlly wants to and hasd the skills and time they’re prob getting in
I only allow SSH from my own network and then certain specific IPs in the network, and then I have a yobikey plus password, so getting in via SSH is difficult from the outside....
So if they do managed to pwn the user it takes extra steps
only thing u can do is makie it annoying enough
Yeah that's why I'm not being super paranoid about it
I'm not gonna be able to stop them, but I can just make it harder to do
Exactly.. There are easier targets, if it becomes too difficult then.... but when they see a tightly secured system they may see it as a challenge or believe that there is really sensitive data there.
Damn yea thts solid, only way sum1 is getting in is if they’re alr in ur network or they got serious 0days
ur chilling
As is, my WAF blocks a lot of bots anyway
My personal devices are more locked down and have a more complex threat matrix than my shitty webserver
what WAF you use? For now i just use like Cloudflare
Like what's 1 vCPU and 500mb of RAM gonna be useful for 🤣
CF yeah
heh.. yes, the worst shit.. hahaha..
My server is strong enough to run a single small webserver and that's it
Don't need anything more
Cloudflare is good stuff..
Their bot protection is awesome, love their trap that lures AI bots into an endless maze..
tbh if someone gets on ur phone or laptop they dont even need the server💀
Yep
Those devices also have a lot more high value information than my webserver 🤣
Real
Which is why I'm so pedantic about what's on them
pedantic?
Can someone recommend an alternative to neofetch?
excessively concerned with minor details or rules; overscrupulous
Fastfetch
oh ok
Thanks 🤙
Gave +1 Rep to @knotty valve (current: #94 - 86)
Fatch
inm to slow
Damn you got some good vocab
yee, fatch 😄
Been speaking English for a fair amount of my life 😅
I wish my english was as authentic as urs
I still forget english words occasionally
Wait, are u a native speaker?
AUS generally has "more refined" English than US, right?
Nop
Also no lmao
whattttt
Australia is very laid back in speech
that’s bs
not? haha..okay, I have no idea, but I got it.. haha
UK has more "refined" english than Australia
im a native speaker and ur english is better than mine lol
ah.. yes,, UK





