#general
1 messages · Page 1245 of 1
Unmute <User:Mention/ID> [Reason:Text]
Invalid arguments provided: Improper mention "@atown_68465"
Am I a SKID ?
:8ball: My reply is no
Did they leave smh
how about me
:8ball: As I see it, yes
Just some information we don't want anyone on the team to know.
lol they actually did.
then dm the people u want to know on discord ?
league of legends team *
Most encrypted applications should be more than enough
if it isnt illegal discord cant share ur dms
What word did they trigger out of curiousity?
They said “nvm” three times which triggered the raid protections
Oof
oh
Are the raid protections just for spamming and stuff like that?
Or does it have other functions
applications like what ? i am sorry for all this questions
LMFAO
I got muted for speaking in arabic before 😐
Signal? WhatsApp?
hello qwerty
Elloo
thanks ❤️
Gave +1 Rep to @mossy river (current: #6 - 1639)
is telegram encrypted ?
I'll answer ur dm once I'm back
It’s to stop common bot/ raiding behaviour but unfortunately catches normal users
okay thank youu
Gave +1 Rep to @bleak quartz (current: #279 - 28)
enjoy ur trip
Hm
No clue
Teleeeegraaa
👍
has to be
So I believe there was a thing that passed where telegram could be raided by the police now
My advice? Don’t be an NPC
Though, signal is pretty good
Dogs >
well most egyptian hackers use it for illigal stuff 😦
it must be a bug
not really
Yes
everyone does
thx
Gave +1 Rep to @bleak quartz (current: #277 - 29)
i dont thin kits bound to egypt
There’s a reason why Telegram’s creator was in trouble
but it is mostly used for malicious topics so i do think its encrypted
Research more on it bte there's a bunch of nice settings u can change
Wasn't he in trouble with someone from france I think?
They got in trouble alot, during cyber crimes they completely refused to share any information
Ye account data deletion after being offline for x amount of hours or days
Was one of the questions authorities had
It nuked the entire acc leaving authorities with nothing
i mean most of its users are malicious, and after all it is a company
so it cant really
loose those people
No they're not
a considerable part are*
I've friends from Russia and other places where the gov watches everything they can
ohh
Yes true
Is it true that China has cameras installed in people's houses too?
Yeah when dc got banned in Russia I almost lost contact but realised telegram
I also helped him to find a VPN that did allow access to dc
As most of them are also blocked there
Cuz of random things their gov keeps on putting up
for what reason was dc banned there?
Officially for having so much western propaganda and LGBTQ+ (Which they hate for wtv reason) but in reality it was for allowing ppl to speak freely (they hate apps that do that lmfao)
U can research it more
This is just what I remember
Ahh
Just random bs to limit access to outside world
tbh thats very sad
Yes
Does DC mean direct connect?
Discord..
Haha
Privacy brings freedom but it's upto users to decide how to use that ig
Just saying it's a "bad and red flag to have" is insanity
And delusion
(Looking at you swedish police who made an announcement on this)
Question:
If I run a VPN client on a webserver configured with DNS records would it still be identifiable when running the VPN client?
That's just propaganda
bruh chatgpt roasted me while checking my code for a typo 😦
Yesn't, using a VPN client on a web server only hides outbound reqs and traffic. Server itself remains identifiable via DNS records, exposed IP, or just shityy config unless you proxy ur inbound traffic and mask DNS to prevent the IP leaks and DNS leaks, just remember that you're never fully safe and someones always watching
my name is someone >P)
Good to know
This one comic I read had cameras in a hotel room
It was a chinese one
That's reassuring though
hey guys ik this is super random but ive just started my journey into cybersecurity and ive missed a class where they where using the amazon aws
ive created a http server ( public) and database(private) i ssh'd into http server already using my key which i transfered using scp -i EC2_ubuntu.pem EC2_ubuntu.pem and now when i im in the ubuntu machine and i try to ssh into the databases private ip it doesnt show anything no words and 2 minutes later it says ssh: connect to host 10.0.0.223 port 22: Connection timed out
if someone could help me i would greatly apreciate it and i will be in ur dept 🙏
Copy
If I want a target to connect to the webserver (think reverse shell for example). Would the webserver identity be logged by the target or the target's implemented security measures?
Getting my news from telegram
😂
I love Telegram
But I had to turn off notifications because the world won’t chill.
Would talk to internationals that I wouldn't be able to talk to
Iranians for example
Chinese
Their internet is very restricted from what I hear
I miss those convos tbh
Easy to talk to someone in Canada or Europe
Someplaces tho, not really
Only place I talk to people is on discord
I use Discord and Telegram
Been using them for years
With Telegram I would find English learning channels as they had the most mix of internationals
Also I kinda knew the owner of one in particular
#room-help message
can someon check this out?
Yups, if the target connects to your webserver (like via reverse shell) The target or it's security systems can and most likely also will log the server's IP, hostname, TLS fingerprint, if HTTPS was used. Revealing it..
Fuck
Copy
Why tho lol
Fortunately this server is part of a test so no real problem
But was hoping to conduct my little project with stealth
Ah alr, I alrd almost thought u had some other plans

The webserver is hosted on a laptop lol. A basic DOS will shut it down np
Haha alrr
Hell normal traffic will do that too
It's a laptop xD
Nothing to a full fledged server
But yea, I 3x laptops
One is the attack device, then there's the server, and finally a Win11 laptop
Which is the victim
Attack laptop is a 2022 Acer Helios 300 running Kali
Is it necessary to learn the fundamentals of Windows and Linux, or is just one of the two sufficient
Victim is a 2024 MSI Raider
Both are highly utilized in the field, so yes
Also if you know Linux commands, then you also know iOS/MAC OS
That's a cool setup
Useful
Necessary for later on
And also great
So why not
Sorry, I didn't see this but yes AGREED
I wanted only learn Linux but if it is also important to learn windows then ok
Most of your targets will be win users
Yup
But the initial access via victim pc is usually via win
Hi
Not that kind xD
Whiskey is my meditation
If I post the URL of my webserver would you guys want to check it out?
It's a simple index.html for a fake cybersecurity firm. All made from raw html cause I was bored at work lol
Also, I am kinda curious on the amount of traffic it can handle before crashing
Cause its... a laptop lol
i just hacked thm, again.
I'll show ya a real trophy but I would get in trouble by the mods lol
I love seeing the christmas pfp show every now and then 
Actually, may have lost it, cause I have lots of USBs and idk which one has the files lol
What project what
thm needs to up their securty.... too easy!
Little war game you could say
Free admin on THM 🤑 🔥
loll
embed failed u
I've completed the entire learning path to SOC 1 (SAL1). I paid for my SAl1 exam, but i'm too nervous to take it. There was so much covered in the learning path, i'm unsure what to study for. Any help, tips, or advice is much appreciated. Thank you.
Keep digging
You haven't hit the treasure room yet
I really like how thm is adding more macOS rooms, I barely see any type of resources for getting into macOS security even though it's forensics, still cool 🙏
does curl get the html code of the page?
Yup
is it a tool or a linux command
whats the syntax for that
No syntax, just right click and select "page source" I believe it's called
Yea, page source
Or Inspect
No wrong way with those 2 really
oh i thought u meant u could type it in the url thingy
view-source:url
Na, that would be more code injection
ah
what that do
It will expose the servers directories
Assuming it works
/../../../etc/passwd
For example
Actually
/etc/shadow
cant u just go into the sources tab
(If linux)
Nope! Wish it was that easy
Not the same
I like how people still call me stealth even after I changed my name
ill read more about that
It really stuck
stealth is sucha coll name
cool*
If properly done you can access directories on the server itself not just the webpage portion
but a website can defend agaisn tthat right
Yes, most do
Its not so much an efficient attack.
But it does work fundamentally and may work on low-level sites
A modern problematic attack vector im currently testing is HTTP smuggling
whats that?
That can bypass most security systems if done right
does it ahve to do with checkign the http response status or something
Nope
what it do?
You just need the user to click on a .html
When they click, have it disguised obviously
Have it auto download an infected
a file? or just access a website
so it sends a request to ur device or server or whatver and when ur device server wtv gets request it emails to targeT?
No
You email an infected html
oh
That has an encoded malware disguised as something legit
It opens on their browser
And if set right, auto downloads the real malware
Which can be anything
Usually a base64 encoded powershell command assuming windows
how will that run
i meant the real malware
that got downloaded
ohh
However this requires social engineering tactics to be successful
thats very smart
After all you want the target user to infect their ownachine :)
but cant they check the ,html 1code and realize it auto runs something that it downloaded
Depends
Http smuggling can bypass most AV and filter checks
Cause it's not a program
.js can evade lots of stuff
If it's something like .pdf yea good luck lol
You want to use file formats that modern AVs and browser filters don't chwck
i mean wouldnt this be the same as steganography? but steganography is more affective
But you have to disguised it. Hence social engineering
yeah social engineering might be as important as the whole entire propcess
cus if they decide to check the source code
or sus;pect anything
it might nto work
What are u doing airports just naming every vulnerability
Exactly, but most users are too dumb to consider that ^_^
true
what
and u didnt send me anything
unless u msitaked me for someone else
looks nice
Looks kinda real, huh
it does
im gonna go make a cup of coffee then chill a little
then ill go back to OS fundementals
Hi yall, I need help with something in tryhackme (OWASP top 10) room. On task 8 (cryptographic failures(challenge). It’s asking me the name of the mentioned directory of the website they gave me. I am having a hard time finding it. Don’t give me the answer but clues of where I should look for it. Please and thank you!
Thanks!
Enjoy 😊
Hey, anyone available to collaborate on a program where I have found an endpoint where its integrated with jira/confluence and it seems like I know nothing about how to proceed with it. Please let me know. Thanks
Thanks! and I see your back to ur old nickname 👀
Gave +1 Rep to @sacred shore (current: #408 - 16)
It's kinda a broken login session but I lack a lot of skills to find something valuable here. Please please let me know.
So should I call you Stealth now?
Hello Abdul!
Hallo brightly
Hello
Hows it goin
Hello Bee!
Great wby
oh man owasp top 10 rooms are pretty fun and interactive
Those who are dead
😮
So most of the ppl
ya
What ya doin jazzy
Hallo mints
yallo!
Hows the mintin goin
goood, actually getting to spend time with my bf today so i'm pretty happy


What’s up abdu, slave, darkfly
?

😭
I mean u chose your own username didn't u
The name he shouldn't use hehe
Good went to the zoo today
Yoooo
And you ?
Did you fight somethn?
Yeah the sun
Hmm sweatin bullets
i made my bed and i am now laying in it
Nothing much
Ooke
Hot out ?
Yea
hi guys

Hallo
Yeah same here… I gotta get back to my doing my dscout interviews
20 more private
Made 100$ this month from this app

Yooo
hiya! welcome!
Doin interviews
I leave for 3 seconds
Whatt
Nice, keep it up
World moves fast mate
Wall of text

Time stops for no man

Look at this , 600 bucks for a friggin interview
Hehe
wut
Well life at least life not commin twice
Did you withdraw the hundo
I didn’t qualify , they need very specific peepl - I got denied at owning my iphone for less than 1 year
that's crazy
Slide the app name :)
But if u match the parameters it’s really easy to make some monies
Dms
I'm so confused
Fuuck

Ahm proxies
I just do the AI ones because we have an edge vs other people on those
Guys what u think about smh toolkit
Oo
Smart
Lmk if u make some monies
Alr bet
Ayo lemm in
Anyone here interested in collaboration?
Yes I’m you’re guy
@crystal mauve dm you?
Hello Stormz! 
Do u guys do anything online for side monies?
Hehe
Too much scam here
Where at?
Like 96+ scam at least the ones that are easy
Bro anybody please?
Why wassup?
Yoo
U can ask here sir
I need help with an endpoint I found and I think it's juicy. It's just I lack skills
I did
Is this for homework ?
No. It's an actual program live on intigriti
Oh I see what’s the payouts like on there
50-500 euros.
Good one
Please let me know or at least if you can guide me. Please!!
Can you help?
No man i have got no skills in the web dept
Know someone who does, maybe?
I really need help bro.
Shit maybe one day , I have no experience with actual bug hunting
Hmm
Ok bro thanks


Mornin karma
Hello karma!
Morning
Ello
morning karma!
Morning Mints!
how goes this fine morn

Hi
How're you Stormz?
Sleep ruined coz of roommate
Storm guy
Im good
Hii
Hi

Hi
Hallo
Is he sleepin now?
Play some doom music

He'll think the demons are coming
Better yet dress up in a black morph suit and then stand in the corner
Now I'm in the state of being sleepy but not able to sleep
i like to sleep on stairs, idk if that'll be useful
Nehhh dum sleeps whole day
, then whole night causes noise and light pollution
Hehe
Damn..not a bad idea but it's cold n rainy outside lol i wanna stay in my blanket

Fallin would be fun
warm and cozy is so real

Hm
Oops mis tap


speaking of rules
while doing rooms and shit how often should i stop to take a rest or do something else
What rules
to avoid burning out
Ah ok
I fall asleep when I feel tired usually
But I think the pomodore rule exists I think
That's upto your capabilities, if u feel tired or think that you're not able to grasp more knowledge stop and chill
I can sit whole day coz I have habits of Hackathon working 24-72hrs non stop no schleep
Degenerate gamer
no way thats insane dude

Thx
Gave +1 Rep to @lavish rune (current: #620 - 10)
Development based
ooo
My team combined has 18x Wins
We do in various domains
oh wow
to think that u have half of the team wins is crazy
i lowk feel like im learning overly slowly but ngl i just realized theres no such thing as that
i have a clean roadmap which wont take more than 3 months at very slow pace
and then ill be able to do CTFs comfortably
Everyone has their own pace of learning
As long as you're learning well it's all good
hopefully i dont give up like i did last time, although I was dumber with less experience and abilities and no roadmap
yeah
Yeah just stay dedicated and regular at it

year room exist
only useful thing ive learnt so far was ADS.
Welp
alternate data streams
OH ok 
but i still wanna finish it accurately even if it takes time cus i dont wanna miss out on any info
i wouldnt have been able to learn about ADS or some msconfig tools if i didnt, so
up we go!


Do make notes too
i cant wait to get into the OSINT rooms

oh 100%, i take notes for everything i feel like i might forget
Good good
yeah i know but each have alot of tasks you know
and they are good and practical
Lol
i mean fundementelers
Apprentice are beginners
shi
Anyhow

where are u from people
the 2 persons in the chat
personals
personen
whatever it is

Lol
Sleep man
EARTH
i have devoloped a batman schedule
sleep at 1 pm or before and wake up at 9
then go gym and come back at midnight
them thm for 4 hours
So you look happy ay night and look like an addict in the day
with breaks
then 1 hour of bullshitting around
and then 4 hours of god knows what
then sleep
Will do after breakfast time
very practical
do u live in the North america region
What ya doin in the gym for 3 HOURS
Neh
no i mean cus ill wake up at 9 so its like 30 mins realize im awake and eat then go to the gym its kinda far so takes 15 mins
then coming back also takes time
maybe groceries
max is 1 hour 30 mins

Tuxy boi

22
are you younger or older than earth
Heh

i dint think he will tell me his age tho
Man here i was trynna blend in using slang
Hallo nex
i know you abdullah.
im under ur bed
in ur walls.
i can still be in ur walls mate
😠
Nope
i have a hidden camera that blends in wherever u live

Wouldnt work here
Cool cool
Ik
from the koreas

Koreans hmm
Hmm
Nah man the only good thing they have is samsung sony, lg
Hallo hydra
Hello Hydra!
Ello ello
Sup abdu, dark, karma
Nm , chatting in here
Chillin in 40c wby hydra

Lol
Lop
Goofy ahh kids

Dead ahh chat bruh
ong b rah
Who are you waitin for hydra
Someone😅
where is ash el mexicant minty zombie and all the good people

Ikr
Miss them
Sleepy
Ashley might be alive tho
I think her name is ash
Abdu is 19😳
aw you miss me?
I lowkey thought he’s 12

flying
amazing
My social credit is 666 am I cursed? Lol
yes
Not at all
Man i dont use that immature talk
👀 illegal stuff
How did you come to this conclusion now lol
oh so ur younger
hmm
16-18 is the range
locking it in
unless ur egyptian
then ur 15-19
Never said that
theyre accurate.
well uhh
Na
is this really illegal?
halfway through the misery called windows fundementals.
(this is no where near misery)
Chill man
i am exaggerating for the sake of a reason i dont know.
Chill
Cap
I ain’t the Feds
Welp stay silent forever then



Oh sorry I forgot to give u the rep, thank you.
Gave +1 Rep to @sick lance (current: #2 - 3860)
has anyone here ever done the Sec+ online? how was it like?
?
that was the default whenever i open regedit
thats the first thing i see
and i cant find my way back to the default
it always starts at the same state, this
Just remove everything so that HKEY_CURRENT_USER is there
last time i opened it was while ago
yeah but it still boots up with whats shown in the image
🔊 Unmuted bonesxalt
oh what its fixed now, thanks @ripe sleet !
@granite jungle Don't try to ping everybody in the chat , bot will automatically mute you for that
rip lmao
?
rip
It says that they're still there though when you click on their profile?
they gone now :v
very tempting to do 1 more room to finish windows fundementals and also level up
but im too lazy, i finished 4 rooms today, ill probably chill a ltitle then do the last windows fundementals room.
Hm
okay now you can say dead chat
Ded
:p
o/
Hallo mints
Zombs has arrived
does thee have snacc?
haiiii

MInts eatin cookies fired
Hm
my skirt is coming today btw :3
yayyyyy
i was gonna wwear that outfit i showed you but the market got rained out 😭
What kind? Pleated or??
yep
Good stuff
integrated shorts too so no pantyshots
Good
oooh i need one with these, im just using some pride dolphin shorts atm lmao
real lol
i prolly gonna buy a pair of bike shorts if i'm wearing a skirt that doesn't have it
ooohh thats really cute
what we thinking?
needs more lincox
Lawliet
😔
the goat
this is my desktop :v
Ahm
oooh i like that organization
Minecraft
tbh i like to keep my windows pretty simple
And too organized
Ew
o
White background
we're sharing desktops now?
idk i find it relaxing
yes
u have different ones for each?
all of them
Bet
ooh can i show too?
yesyes
All
organize ur desktops 😠
?
the bg is nicee
I used to do the wallpaper engine thing, but it consumed too much
im convinced wallpaper engine is a bitcoin minor propaganda
I'm watching this phinease and ferb youtube poop thing I think that's like a god damn fever dream
ok this rice looks insane
i actually have no idea if thats a good quiality image or not
W I D E
Good Morning
last screen is my laptop , which is justitunes fullscreen
Morning again
guten morgen

thats obsidian 😭
Mornin
Stop being sus
so you're running multiple monitors?
The monitor man
Morning an- Karma
Yes
two monitors and a laptop screen

oh
Is that German?
shii
i think so
ich de shiza jaja perhaps
thanks
Gave +1 Rep to @tight trout (current: #119 - 71)
Lmao hey clumsy bro
I don't understand
German

same
😂😂
I only know enough to offend someone
i guessing the monitors are connected with a thunderbolt dock then
XDDD
How is everyone doing today
wget -r logs
also a phone charger :3

Easier to mention @ everyone
admin admin
And ask
Have you ever been infected with Covid?

good
wait i mean root live or root toor
HA
HAHAHAA
am i the noly one that didnt get it
no fucking way
Yuppp
When I used Wallpaper engine I had these three on my screen
I'll just use openssl s_connect and netcat
Neh
omfg
Samurai one is dope
someone should make a social media that doesn't steal your data smh but ik that will never be possible cries
4/8 already have graduated/terminated......

up up down down left right start a b
aloe did not deserved this 😭
The left most one has a rolling slideshow of images
real
I wonder if a flipperzero could bypass a yubico key policy
probably if u found a way to bypass the yubico key policy
There is an exploit for yubi keys
i might have reee
But its pretty insanely hard
Ik I opensourced one 2 years ago
Yippe
I do not needs da money I only want to gib tools
by just ignoring the chromium policy for cors
Hmll
like how using u2f works
I still find it cool as all hell that you can do stuff like this with wallpape engine
Now do it with the bios onload
oo
The best part about bonelab was beating the hell out of the enemies with a Watson Amelia model
Anyhow
Anyhow
As you read this this message is in the past tense
Night nights
night!
Goodnight!
eplain this in the form of a basic math problem as if you were teaching a middle school class and explain it in extreme detail and be as accurate as possible try that
thanks
yee
is thta like a yearly thing too?
if your opsec got some teeth
loose talk builds the scaffold for your statements underneath
you don’t type it, you don’t say it, you don’t link it, you don’t name
your best weapon ain’t a zeroday, it’s silence in the game
they’ll pretend to be a buyer, or a chick who’s just inspired
they’ll pretend to be your homie, then they wiretap your fire
they ain’t cracking you with python, they just breaking down your trust
and they bait you with a mirror so you self incriminate in lust
I be writing sometimes when im bored
Yupp
From 2019 to present
Everyyear
With prizes
PRIZES MEANS FREEEEEEEEEEEEE
And ofcourse fun new digestive form content
Gets too many users tho

And lets see if there is a easter egg subscription this time
most people will cheat for the prizes probably 😭
thats so cool
yerp
nmap -A script=all
Hmmm
and they have way more stages than advent of code
oh then we dig
Yupp
dig NS target +short
Yetiiii
for i in {1..254}; do ping -c 1 -W 1 10.1.1.$i | grep 'from'; done
thats so cool





