#general
1 messages Β· Page 1228 of 1
just doing recon on an old website which I ended up realising that it got deregisted along the way
smh damn skids man
This is the worksafe banter in cyber
wassupp, how are yall
ello
Usually it's more or less unhinged depending on where you work
LMAO i dont use msf
nyahallo roma
hiya roma
makes sense
Ello Roma
HIIIIII, hows ur day goinn guys?
"I donβt mind βcause one day, youβll respect the good kid, m.A.A.d city"
me too me too.....
So perhaps is there any other way you can advice me....
nah i do respect them, wym i dont. but its fun waging wars, having rivals, just makes u better at what you do brother, accept the rivarly and become better
no im a skid
ππ½
|| no im not guys i swear ||
bro's trying to have rivals within his own people thats crazy to me
ok write payload for .NET reverse shell
msfvenom does that for me
i can't script yet
also im a blue teamer ffs............
i need automation and detection engineering type scripting, not revshells
fml
learning red team stuffs can make u a better defender ^^
true
small businesses use .NET , i hate .NET myself
damn...so you're going around pillaging small businesses? mods, ban this man
write script to detect if file has macro or not then 
i work for one
Large ones too
mfw i just said i cant script thats like my weakest link
why write your own tools if there are existing tools that does things like that
this ^
imma head out
i love xoring my shellss^^^^^
coz we are having friendly fight here owo
people who prefer 'originality' and 'self-made' tools for reasons of privacy or 'i can do it better' or the sort are idiots imo ππ½
byee karmaa
waste of time yea XD
but good experience to have
Bye Roma , catch y'all later when I'll lurk around on discord
why...just why....
its raininggg!!!!
for developers yes... for us? its waste of time
wish it rained around here a bit more...its been a while since i've seen rain
makes sense, makes you understand things better
yep
its rainy season here
But isnt that how all major tools are made? Someone going, i can do this better
my bad i just generalized it, i meant people/devs who always go "i'll just make this" for everything and create a literal replica and proclaim it as their own original creation, just for the sake of saying 'i made it myself'
now i have no idea if...thats a common issue for most people, but i know way too many people who do this ^ π
and eventually people contributing and that makes tool everyone would use (maybe)
I have a fork of X would be better to say atm
and that'd be fine yes
realllll
i'm looking at some js malware and it's annoying af
tbh....
Then this is place that you should visit π
https://tryhackme.com/room/javascriptessentials
i don't really like webstuff
@gray solar I can't help you reclaim your streaks.
If you needed this for a presentation tomorrow, you're a bit screwed.
lol
In hindsight, if you need something for a presentation, it's probably a good idea to keep it up.
Is there anyway I can double mail them ? Is it possible that they get me my streak back for second time ?
You can, but it will more than likely not be restored until later in the week.
How many days streak you have can anyone help who have over 30 days streak ?
A screen shot with my name on it will also work
Is there anyone who can help?
then just edit your profile screenshot and change the streak no.
But using someone elses profile isn't?
If thereβs a proper screenshot then that might be more real
Lol
You can change profile name isnβt it ? So that will look more realistic
want my 2 days streak π₯

Good luck with your presentation tomorrow.
inspect element and
if all you need is a print
πthatβs great idea let me try it
hacking since the Miocene
grind is real
Genius bro genius πI got my streaks back
Never have I seen someone so happy to do useless client side editing before lol
You do know that's not your real streak right
is there a way around vms suddenly crashing out of nowhere
Thanks π glad to join
welcome
i'm happy cause my work is done
and ik it's not my real streak but who cares
and what was that 'work' exactly
i have my presentation tomorrow and i've include my 30 days plus streak ss in my presentation
i was trying to do it real but
yk i lost my 54 day streak
so this was the only option left for me
You could've just emailed THM and asked them to restore your streak
Your streak is public to everyone. If your username or profile link is found anywhere, they can see it is fake.
But whatever you say "Munna bhaii" lol
i mailed them for like 3 times today but they didn't respond
It's Sunday.
3 times in a single day and you expected them to reply?
yeah so i hope try hack me recover my streak asap
like why not ?
the more number of mail you send the more importance you should get
meow
Heard of Spam?
yeah but ig you can't call 3 mails a spam ?
They don't work on weekends
it was not in the same moment
i have time gaps between 3 mails so i guess it's not spam
ohh shit i forgot
i am a beginner where should i start from in this server
i am looking forward to learn a new skill
#start-here π
Check out this article
that's the exact opposite
okay but they would have responded if it wasn't off day today
anyone play mlbb??
no, sending three emails in a day won't prompt an immediate response
okay let's see tomorrow
Good morning wifi wizards
mornin style

It more than likely won't be tomorrow.
The more you mail, the further down the list you go.
Ah the good ol' inspect element.
Morning chat
Haters will say this is fake.

Hallo all


Please don't spam the same GIF over and over.
Dies from cringe
hello. just wondering why do a few learning pathways have redundant modules?
"redundant" ?
my bad, as in "repeating"
Can you give examples?
Chill
I heard health care is expensive
You'll prolly die again
on the road map web fundamentals pathway come after jr pen tester pathway. they both contain Introduction to Web Hacking.
its no biggie just wondering
You might not have started on the fundamentals
^
I had a technical test on an online platform, never again, I hope it's all done locally.
i see what you mean, so the progress in that section would auto-complete because i would do it in jr pentester pathway.
mb didnt think of it.
ah yes sunday and finally time for the anniversery event in dragonfable
Huh, when did THM start shutting down VM's when you've submitted the root flag, that is annoying,
Hello Shadow! 
think that is a feature for when you just completed a room in a path and it moves you to the next
so you don't have tons of old vm:s running
ello ello darkfly
might be slow to reply a lot today
How're you?
because gotta farm defender medals in dragonfable again :D
tired
Mood
I wish there was a way to disable it.
fair scrubz fair
Tryhackit
Sounds like Bopit

Scan it!
Break it!
Drop It!
Exploit it!
Steal it!
Sell It!
Profit!
I tried
I added two more
My dc changes font automatically
Rooms?
Bop it commands
/dev/zero
Try talkin in that one
/dev/null
Na null make you feel weird
Tf is dev zero
π
Produces nothing but 0's.
π
Instead of a black hole that is null, it's a "white hole"

Chill chill
I'm chill as a cuccumber, I just like messing with you
Sleep deprived?
50 "waves" in
2950 to go :D
dark mode on tryhackme????
Neh ...bored
yes
guys are there somehow way to see the explaination in a video?
like not sb who reads what's there out loud
Example?
yk jeremy from jeremy's IT Lab?
he explains CCNA things
he says examples and explain it yk what i mean
plus im a member in THM if there are any roles to get @cloud quiver
You need to verify for roles
how
Follow instructions from the link above
here
Hello KGB! How're you? 
Hello Zombie! 
hewwo dark-kun
Thanks for asking , good π . How about you π ?
Gave +1 Rep to @ripe sleet (current: #407 - 16)
where to share that token
type /verify
Click on your profile image on THM > Manage account settings
and enter your token
alr done
I'm doing good! I hope everything is going well with you as far as life goes 
thank u
Gave +1 Rep to @vestal bone (current: #1164 - 4)
the passive-aggressive energy is radiating off of KGB rn
social credit
π ?
I don't know it, and there isn't much like that for THM materials, some rooms have videos recorded.
I love it.
TryHackMe advertised for a streaming content developer, I don't know if somebody applied and they hired somebody however.
who doesn't love social credit. SOCIAL CREDIT FOR EVERYONEπ€
Plenty of other cyber content though
it's like oprah
nvm it will cause inflation
LiveOverflow, John Hammond
Alr thanks bud
Hello James! 
Bruh
@vernal matrix your dm
There is, however I thought they were strictly talking about TryHackMe content.
what's with my dm?
u wanna add me u mean?
I sent you smth

I am back
You were gone?
how is the glucose and sodium chloride doing?
Went out for cat treats
HAha very well thanks
Gave +1 Rep to @round onyx (current: #1003 - 5)
make sure to give the orange demon a long distance pat from me as well
Hello Salty!
Will do π
Helloo

How're you doing Karma
I had my door closed while I was eating, my cat jumped in from the opened window sneakily
It was my friend's room on 2nd Floor where I was sitting and eating at 
Dedication for food 
Yeah they be like that :3
Xup everyone

Hello there!
Hw u doing
How can i be like Mr robot
Fine , wby
I remember that show
Catbug
Hmm ask mr robot
I wanna hack google.com and be Eliot
me2
Put down the fish Beerise!
Hallo matt
But can you hack 127.0.0.1?
you leaked my ip π
NEVER!
sir i'm calling the police π
I will force you to come fishing with me @ripe sleet lol
hello mr police come to discord!!!!
Please no Po Lice
I can't think of anything more boring than fishing.
AYO
are bug bounties open all the year, or does the company give like a week of legal bug bounty?
Oh yeah, darts.
Yippe
Perhaps
"legal bug bounty"...
Wat?
golfing is pretty boring too imo
yup, why not
Gonna kidnap me Matt?
It's so nice and calming, the outdoors, fresh air, relaxation
Send more cute cats
Damn right!
let me use nmap and ping flood the ip π
Naaa hes gonna giveaway a luxury service for free
@lone thistle


Good luck finding me 
It doesnt have hackin in text
Close enough
I want it
Don't most browers not have in built text to speech?
Idk mine didn't
It's a firefox extension
The sound is bad
question
Done!
not for me
does DNS spoofing solely rely on race conditions ?
Bruh, I'm not in italy
Iirc there's the sequence/numbers too
But ehhhh
DNSSec, DoH etc mitigate it


ahhh i see, so DNSSeC would use unpredictable ranges for transaction IDs and source ports
No?
no hmm?
Read up about it


Nerd spotted



Saaaaamsuung
ok so dns already provides rng ports n ids, but these are predictable. DNSSeC provides cryptographic protection - gat it

Cryptography completely elsewhere in the process.
@quaint mist Let's not invite people to potentially dox you.
Aww
I mean, let's not potentially allow a user in this server to breach Discord ToS.
hey yβall
Hello! 
how are you?
Good

Hey why isnt chat loading

Where do you guys get those gifs from anyway with nitro or from somewhere else
250 out of 3000 "waves" done
Maybe
Who the fuck said I was there? Lmfao
Bruh
Oh i found it where the emojis are
Wooooh!
Maybe las vegas has fishing spots
Desert having a fishing spot
It's called an oasis
Any of you gamers played the alters ?
Afternoon chat
π
Hallo rabbit
Halo abdu
Hows your hole
The many meanings are tempting me to respond
But overall, Iβm doing fine
Rabbit hole
Good
Got a math quiz tomorrow, not excited for that but Iβm confident Iβll do alright
How about yourself?
Great as always
Letzz goo
Good, the sun is indeed shining today so I guess there is always a reason to be great
Ofcourse

I was tempted
Took everything I had to hold back
You know how on Medium you can add that (. . . ) to seperate parts. Do you know if theres something similar to that on word or Libre?
I'm writing up some documents and it looks nice
Iβve no clue what your talking about, but I hope someone who does shows up

Hallo clueless am Abdullah
Cringe

No. And you should be banned
I think I broke obsidian
Cursor became this after I dragged an image into this table
Reminds me of that kali glitch which turns your cursor into a box of whatever you were looking at
Whenever I try to change user in windows 10 ( provide by thm) , it shows reconnecting , and i and not able to sign out..
Does anyone know what's is happening and how to fix it !?
Send em to https://tryhackme.com/admin
Good idea
Yeah we need a URL to rick roll
Maybe a long ass blank form for them to fill out which doesnβt do anything exept give fake errors like βThis field needs more textβ to waste their time
Please don't bring any issues in a different server to this one.
Use cherrytree

Chef karmaya
Delulu for

I like obsidian though
Me too
Hai dark!
Hello Usaggi! 
π

When obisdian is using 2.7 GB of ram
Joining owlsec purely for this emoji
Obsidian is the goat
Yeah

I think I should prolly split each room into it's note instead of putting them all together
I actually wrote a blog on this
It lags a lot
Obsidian works great for me.
Same, I built an entire internal knowledge base for me and my team on it
And I use it to manage finances
Got a whole dashboard
It's more when loading documents
But it depends on the document
I've pretty much been doing headers for the entire SOC 1 path in one file thus far
I'm at like 42,026 words or so

i have just finished the metasploit basics. i wanna practice a lil more in metaspoilt cuz i seem to be struggling a bit. Are there any rooms u wld recommend?
i just did those lol, any other rooms?
hey im just a beginner i want to start learn and im searching for a team to learn together
Dm me




Ello mints
Do the "RootMe" ctf, and instead of using normal shells use Metasploit ones
That's what I did to get familiar with C2 for Metasploit
Iβm so grateful to be a UK citizen man
Otherwise do Brains and Blue
I am so grateful to be romanian
It though me a lot of skills
Like pickpocketing, picklocking... /j
just confirming
are these two different rooms?
Yup yup
yes
my dumbass brain thought that it is a single room π
@dark mason i passed out and i slept for 3 hours this time btw ππ½
I swear I will osint you, find your address and knock you out for 9 hours (mods, this is a joke, don't ban me pretty pls)
blatant doxxing and assault threats! mods, ban this guy!

The eternal blue "Blue" rooms sessions keeps dying π¦ in the meterpreter migrate and flag finding stage
Hello DKob
!
Hi all. I got a general question and just want to pick the people's brains that are more advanced. (I'm only about 2 weeks into the hacking).
Okay so I was doing the room "Top 10 OWASP-2021"
I'm on #4 insecure design - I read the instagram vuln that the room links to. And it was pretty cool. I think I understand the basic concept here of a flaw in the actual architecture of an application. "who's gonna be able to come from 4k IP and brute-force their way through a 6-digit code"
Okay so the room example plays this on a small scale - login as "joseph" reset password and the validation mechanism is - security code - of course a favorite color is pretty easy to guess. - I did this manually.
Well. that obviously isn't a great way if there is a much greater number of possibilities.
I did a Burp Suite room a little before this one. I think I can use that to do this but I'm pretty new and I've only done the basic room on burp suite.
Would that be the right or maybe a right way to do approach this? Or are there other tools or approaches I might also consider?
blue can be unstable due to the exploit it's using, it's not broken, just give it a couple of tries
Hello Bella! 
yello
How did you do on your presentation?!
I had the same problem - try a different service to migrate. I think I used the spooler one.
Uh
Wdym?
I hope you did well Bella!
ah sorry lol
got told it was one of the best presentations that there was, and a lot of people added me on linkedin afterwards thanking me for the presentation
Let's gooooooo! Congratulations!
Did you use the glasses?
nope, 100% bulshitting the presentation after making some slides with pictures
I am
So proud
it was quite literally just me retelling the story over again, so what could go wrong
Eternal blue is a very unstable exploit
I'm glad it went well for you! 
Wait what? How so?
the exploit
Eternalblue is unstable due to the BoF.
Idk tbh
What does BoF stand for?
buffer overflow
^
Ah thanks
That gif has really made me want cheerios
yo guys
the skill matrix thing on tryhackme
might be the best thing ever added tbh
Your profile pic spooky

Hello Qurti!
silly bear :)
yo

Gawd I'm so bloody tired
Sleep then
Hey everyone! Iβm LIZZY, 20 from the UK. I deal with a bit of anxiety, so spaces like this that focus on care and understanding really mean a lot to me. Iβm here to connect, share thoughts, and hopefully grow with some amazing people. My DMs are always open if you ever want to chat or just need someone to listen
Hello Lizzy! 
Well, welcome to thm, lizzy
Jesus christ some people can't aim on BO6.
And you're one of em
welcome lizzy!

Hello Minty! 
I'm in the process of splitting up different notes into their own separate notes
Better be fishing notes 



I just finished my 600th room in tryhackme!
Congratulations! 
congrats!
Happy Sunday everyone, and Happy Father's Day to any dad's put there
thanks you too
congrats
TY
Gave +1 Rep to @kindred ravine (current: #2931 - 1)
'?
Congratz!
?
Whatsup @kindred ravine

Why are some channcels locked
do i have to get a specific role or something?
f.e. like gen chat
for example?
Verify
yeah verify
@kindred ravine
okay thanks

Congratulations! Happy Cake day!
I hate making presentations
shadow has traumatic stress about writing reports
AI
some good ones out there that make the slides for you
I have 10 minutes to get all this down
and focus more on the topics that I didn't get deep into on my report
but first!
dinner xD
lol

Up only
Cheers fuckers
Wow
Smoked old fashioned
You should've waited 7 minutes and then it would've been 5 o'clock somewhere
Nuuuuu
It's 5 o'clock everywhere!
What book
Grdn rmmmsjy
Hello Bee! 
this looks like crap =/
You look like crap
coworker with almost 0 self preservation decide to try make tear-gas in lab... ended up "fun"
Sounds hilarious
howdy how you doing
I'm doing good. How are you though?
not bad just working on a fun deathcore song :)
What kind of a alibaba store did u buy it from
π
yeah
That's cool
All the red
o/
working on my debut solo metal EP as sacrificial abomination
Iβm watch TWT
I hope it goes well for you. 
yeah its going great
That's good
Whenever you release it. If it's on Spotify I'll listen to it 
I wish you the utmost of luck bee!
yep! ill send it ur way!
Bet
This is a legit question as I don't know much about bash scripting. Wouldn't it just be easier to run the script itself as a sudo command instead of having so many sudo commands in the script?
You can really tell what I don't like.
I love how THM is calling me out on every turn.
Well we're all special and some of us do dive into DevSecOps
@slender scaffold IITS A FWEATHERZ
I got some questions actually
I do come from a devops background I just wanna know if the module in tryhackme is good to start with
Not going through a developer education i can't personally really say. I'm guessing you would have a good foundational networking and computer knowlege so you can probally skip the pre-security learning path. Maybe go over itad see if there are some areas you ,ay need to familarize yourself with. Then I'd probally start with the Security-101 course. It will give you a good foundational knowledge that I'm sure a lot of the DevSecOps courses will touch on
did a CTF, finally I overcame myself and procrastination. Big win for me 
real
What laptop do you purchase if you were me.
ACER PREDATOR (98-99, 1Lk)
ASUS Rog Strix G17 (98-99, 1Lk)
ASUS rog TUFF gaming laptop (75-80k)
HP VICTUS (75-80k)
I love your pfp. Where did you find it?
Missed the optratunity to say "On my face"
oops
It's not even as if root has anything interesting
Thx a lot
Gave +1 Rep to @sour canopy (current: #1918 - 2)
Need to work on my privesc skills, the thing i suck at currently
Show me one representative of the human race who actually places privilege levels on their devices
Same here in full honesty
It's always some stupid forgotten protocol or misconfiguration
Why would anyone even bother
yeah 
Hey, bullets are expensive
may start selling my sweat bulletsd
Pretty sure that's some sort of war crime
war crimes r cool
Bio weaponry? Excessive suffering? Infection?- Awesome
what's that one game where the point is to make a virus and infect everyone
Plague inc?
Actually interestingly enough the Geneva Convention doesn't actually cover chem and bio weapons
yeah that on e love it
Yes

Technically< a separate document, practically not part of the Convention
gonna go play some plague inc
Go, and know that you are not making any of the Swiss angry
Rustscan or nmap
What should i type with nmap
nmap -vv -p- 192.168.0.0/24 or whatever your ip is, like 192.168.1.0, 2.0, etc etc
Kk
Could also do -Pn to not ping devices...... thanks Windows
The extra verbosity is mandatory

I swear, it's like talking to a senile witch doctor without the -vv
BRO WHY HE FIND 256 HOSTS ππ
Hlo guys
Neighbours stealin'
Because its scanning the whole ip range
Oh
You can also sign into your router to see all devices
My one is funnier though
What should i do with open ports?
I never do a nmap scan without -vv, even with a -o,
I NEED THAT VV!
Depends on the Port
Wym
Which ports are open?
How many rooms do you guys complete in a day?

Should i say?
As long as you don't share the actual ip then it should be safe
80
So it's literally just TCP
That doesn't really help us without any additional context
What do they do with the ip except finding ur location
Nothing interesting
53
If they don't know what they're doing, nothing
What port is interesting?
22
If they do know they might find a vuln to exploit, and that ends badly
Means what?
port 23 is the best one
Wth
For what
But how its just ip
Who uses telnet anymore?
You're new to cybersec, right?
Not new im under new
Which is why if it's open it's the best one.
dind't say it's often
Fair
Btw, when you fish, do you catch coleacanths? I want to see what sort of luck you have
Can u please explain to me?
If i have anyone ip
Or they have mine
How do i portect myself
Ok, so imagine the IP address as a house address
Alr
So they can send u things using ur ip?
The security protocals you have range from leavinf your front door eide open, to a full security system with gaurds at the door
Every time you send or receive data it gets sent to that address. Then, it gets into tge smaller networks, usually connected by routers
Every device is like a specific person at that house
As blackeyed explained, the ports are like the entrances
So the ports are like keys for the house?
More of like the separate entrances to each person's room
glup
The protocols that govern the ports would be the keys/mailman
Ports must be opened
Close to 5 million atm
If you're brand new to not even understanding IPs. I recommend studying a Comptia Network + course on YT. Don't need to pay for the cert, but Networking knowledge is the foundation of Cyber
Not sure abt all time
You shouldn't need to worry about protecting yourself from someone pulling your IP address, I guarantee they don't know what to do with it
But befor i only see 2 ports open or do they change time to time?
Not usually, no
Dang
You can learn cybersecurity on https://tryhackme.com/
Its hard for cuz im not that good in English
Depends on what you're doing with your computer, for example hosting a webservice has different ports
Like setoolkit?
When u clone sites
You're doing fine, you're getting your messages across
No, like a website
Oh ok
If you were using your computer as the website's server
You're doing great
An example, you mentioned having port 80 open. That is something you don't want open unless you are hosting a website, because it allows access over the internet
And as an extension, it could be a vulnerability
In full honesty, doesn't really matter
Most actual breaches are bc of databases with your passwords being hacked, phishing (email) viruses and other easy hacks
Can i ask u smth
Sure

I saw a vidoe on yt a storey about hacker they can use a tool that send u link or smth in sms
What of it?
Is it real?
Yes
That is a concept call smishing
Smashing u mean or...?
no exactly as a spelt it
Sms+phishing
Ohhh
Sm ishing
The only tool i can use ππ
And for what do you wanna use it for?
They use develop a malware, then they simply send that malware out with mass texting apps disgusised as a linki such as "You won a feee $100 Amazon Giftcard!"
I saw a vid explaining it and ik how to use it
yea but why do you wanna use it
What is it
Doesn't gophish exist too?
Yo darkfly here :3
why do u wanna use setoolkit
Hello Vulture! 
And hiddeneye
I haven't heard of that one unfortunately
Im using it for curious
Dw only in localhost cuz idk how to put it in a server or a link
There's a thm room abt it
You want to be careful. You seem like youre being a "script kiddy" using tools without knowing how they actually work. If your not careful you can seriously mess something up
glup
If you're curious, do TryHackMe and actually learn it instead of becoming a Script Kiddy
Dang so script kiddy is just using things without knowing them?
Like having power with no brain
I get it
I'll have to look into it
Dang
basically you don't gain a thing from it
It's literally just called "hiddeneye"- ridiculously easy
If you try to do it to someone, it's illegal and if you have no idea anyways, you'll end up in jail/with charges quite easily
Ye thats realy true cuz i spent a day learning it qith no clue how it work
and using it "locally" is useless if all you have to do is install it and follow a manual
so long story short: don't be a script kiddy and go learn
But thm is hard for me
wdym
Im bad at English
It is for every beginner
Then use google translate to translate it into your language while learning
Well I don't know what language you're speaking but google or deepl (especially deepl) get the job done quite decent these days
Brave browser ππΌ
Hello Beerise!
Welp
IM TISPY!
Not all that well though- I had roach (the fish) be translated into "cockroach" like 1000 times
Huh
ππ
Quick Question, do you want me to call you Matt or Beerise?
Either or is fine with me
Me last night fr
again, depends on the language but it can get the job done if you really want to
Okay, Matt
Well technically its Beerrise as in Beer arise which would explain the "im tipsy" part 
Luckily I'm a fluent English speaker, I just have my native lang as my default
So do i can learn with mobile like just learning basics then when im pro il use both pc and mobile?
How much did you drink?
completely depends what you wanna learn. PC and Mobile are two completely different fields
Pc
Then why do you wanna learn mobile first?
I mean rn im on my bed and my pc is off so do i can still learn things?
Completely off topic, but here's my cat being a cat.
Leaked
Cat in the box! 
I can hear the sound effect
SUBMACAT!
Make it 4 Old Fashion drinks 

I prefer my drinks new and fancy not old fashioned
Oh yeah, and sorry abt not sending you the recipes- still can't find most of them








