#general

1 messages ยท Page 1326 of 1

soft vortex
#

its ethical platform.

#

send you req?

hollow shard
#

oh ok

inner bloom
tight trout
#

kekw why

hollow shard
#

what to do after the presecurity

cosmic pendant
#

Go watch NetworkChuck on IP networking

digital estuary
#

what is going on today

cosmic pendant
#

Nothing good

tight trout
primal ether
#

hi

digital estuary
#

hi

tight trout
digital estuary
cosmic pendant
#

#QuickBansFTW

primal ether
#

im kinda just getting started learning hacking and damn why is it so hard to find where to even start lol

cosmic pendant
#

have you heard of youtube?

thorny prawn
#

Check Windows API documentation its basic knowlege bro

digital estuary
#

also take notes since this field is quite large

elder egret
#

but youtube regulations are top secure for the user ...so its important info is protected by their guidelines

primal ether
#

im taking a cybersecurity course too, next year (in a few months) we'll be learning some ethical hacking but idk i still need to learn how to code

cosmic pendant
#

Please stop

elder egret
#

cuz thats what i need

cosmic pendant
#

You don't know what you need

digital estuary
#

and other stuff

half badge
#

sup people

blissful current
elder egret
primal ether
digital estuary
#

even simple things

#

like a calculator

primal ether
#

ooh alr ty

fleet pivot
#

a couple hours from now im gonna have to do very hard work for hours

digital estuary
#

just anything that can be fun, or helpful

tight trout
fleet pivot
#

back then

digital estuary
fleet pivot
#

i thought it was cool

mighty river
#

When you make things, how do you create a portfolio to store them in? I've read you make a Github account and you can store it in there #completebeginner

blissful current
blissful current
fleet pivot
crystal mauve
#

Whatโ€™s deez nuts

blissful current
#

Aight ...that's how u wanna talk

agile mica
#

When can i join general call?

digital estuary
agile mica
#

ty

sharp citrusBOT
digital estuary
#

oh

#

what a showdown LOL

fleet pivot
digital estuary
blissful current
agile mica
#

thanksss

#

i will do

digital estuary
#

@blissful current thanks for beating me on the /docs showdown LOL

twin ridgeBOT
#

Gave +1 Rep to @blissful current (current: #103 - 82)

fleet pivot
blissful current
ripe cosmos
#

should I go to sleep?

digital estuary
#

yeah but mine is for getting student discount w/o student email

blissful current
#

I typed wrong at first before sending it

digital estuary
#

if you got enough points that no one will be catching up go sleep

fleet pivot
ripe cosmos
foggy terrace
#

hey guys anyone got idea on how can edit a video stream and youtube won't detect it as copy right?

fleet pivot
sand trench
#

summer games done quick event has started

digital estuary
sand trench
#

go enjoy some games being speedrun

fleet pivot
#

u dont have to take it so serious๐Ÿ’€

blissful current
crystal mauve
agile mica
#

test

#

Aight

fleet pivot
#

๐Ÿ’€

#

what

crystal mauve
#

no, you;re suppose to responde deez, and they say deez what?

blissful current
crystal mauve
#

and then u follow / deez nuts

fleet pivot
crystal mauve
#

no thats how its always been and will always be

digital estuary
#

alright guys time for me to go take a big break see you guys

fleet pivot
tight trout
fleet pivot
blissful current
tight trout
tight trout
blissful current
fleet pivot
foggy terrace
blissful current
tight trout
fleet pivot
tight trout
fleet pivot
#

while ur not

tight trout
blissful current
#

I think I'll read the Manga itself can't wait for 4 weeks for the remaining 4 episodes ffs

foggy terrace
tight trout
#

which is against youtube's ToS

blissful current
tight trout
#

and law in places where the copyright is held

blissful current
#

Takopi's Original Sin

foggy terrace
tight trout
mossy river
#

Itโ€™s ToS, not law, but is unethical

gusty inlet
tight trout
foggy terrace
gusty inlet
#

You have been walking on a very thin line for the past few days. This will be your final warning. Next time, it will be a ban.

tight trout
brave spire
#

Googoogagaga!!!!

blissful current
tight trout
fleet pivot
fleet pivot
blissful current
brave spire
fleet pivot
#

this kid is stupid

worn plank
#

@foggy terrace Just come up with original ideas. Nothing is truly original anymore, but try it. Take inspiration, not one-to-one ideas from others.

gusty inlet
tight trout
fleet pivot
#

cannot u see the role

fleet pivot
#

i realized

blissful current
fleet pivot
brave spire
#

@waxen radish hey buddy, sorry for disappearing last night, I ended up showering and going to sleep.

#

Did you resolve your issue?

mossy river
blissful current
#

Aight good night y'all, gotta wake up early for office ...Monday FFS AMfubukispasm

mossy river
#

Btw @foggy terrace I recommend in future I recommend that if you are streaming in OBS to set the music onto a different channel, which means using most editing software you can replace the music with your own copyright free

mossy river
#

If you want to split your outputs it makes it a lot easier

Your microphone for input, game capture with audio capture on a specific application, Discord/ other voice comms and then set your music to an output channel if possible

If itโ€™s in a game you might have problems unfortunately

tight trout
#

zombieeeee

#

go to bed!

mossy river
#

@brave spire ?

brave spire
round onyx
#

fine mom!

tight trout
mighty cedar
#

hi, im new to ethical hacking but want to learn batch files, anyone know any good channels or ways to learn it?

tight trout
broken plaza
#

I think this is enough for today considering i got my first cert now finally

tight trout
round onyx
mighty cedar
tight trout
#

i haven't done batch files before, but that's how i would approach it

mighty cedar
#

oh ok

#

thanks dawg

brave spire
#

There are search engines in this world that gives you exactly what you're looking for.

#

And it's not Google.

blissful current
#

Office is fine ...just tired from waking up at 5am everyday

tight trout
mighty cedar
#

helloworld ("print")

#

100% works

tight trout
brave spire
#

What the fudge!!

blissful current
clear jackal
brave spire
#

printhello ("world")

quick blaze
blissful current
mighty cedar
#

world ("worldhelloprint")

quick blaze
brave spire
#

I'm going to work on my own language in the future, it will be called "Shit me not (SH)"

tight trout
quick blaze
tight trout
quick blaze
#

mate i used to have a polyphasic sched and it was like 2-4 hours a day max for 2 years straight and that almost killed me

#

no joke

blissful current
quick blaze
blissful current
safe oxide
blissful current
#

Lol

plain hull
#

sup

quick blaze
#

ooh

#

gambling

blissful current
#

No ... Sports betting n shit

#

IPL and Cricket

quick blaze
#

lame...

#

be a man

#

gamble on blackjack and poker

blissful current
#

He has an exam ..hence ruined sleep tonight

quick blaze
#

heheh

#

no.

rapid merlin
safe oxide
crystal mauve
#

i use to play a bit of hold em

loud orbit
#

Hey guys can I have help or advice

broken plaza
#

lol

loud orbit
#

Iโ€™ve started learning terminal with network chucks playlist on the 2nd video now,when would he recommended I can move to python ?

#

I wanna hack and script and stuff

blissful current
broken plaza
blissful current
#

Never tried ..won't do

broken plaza
#

yeah same

#

quite risky if made big bets and lost

blissful current
#

My roommate does that shit daily

broken plaza
#

or Dream11

#

the worst one

blissful current
#

Nah some non play store available one

broken plaza
blissful current
broken plaza
#

didn't he got his bank account grilled then?

#

or he used UPI ?

blissful current
#

Looks like neh ...he's been doing that since a lot

broken plaza
#

like in lacs if it totals

crystal mauve
#

whats IPL? i havent used gambling sites since 2011

broken plaza
crystal mauve
#

ohhh

broken plaza
#

it's a sprots championship and is very big

blissful current
safe oxide
#

Cricket tournament

broken plaza
blissful current
blissful current
broken plaza
#

i mean with that level of confidence if he knows what he is doing could lead him to somplace much better

#

if he chose right path

blissful current
#

His dad is DSP or something in police ...smokes his money

ripe sleet
broken plaza
#

i have a frnd

#

who's dad is in HPCL some manager post

soft vortex
#

touch the ground guys

broken plaza
#

my guy was a good and healthy till he attended school with me.

blissful current
broken plaza
#

one day i saw his story to find him learnding to drink ๐Ÿบ

#

๐Ÿฅ€ ๐Ÿฅ€

broken plaza
#

he literally doesn't cares about himself and even recently started smoking as well with his frnds

blissful current
#

Sed

broken plaza
#

as a good bro i told him not to

#

but he said a little doesn't hurts

#

๐Ÿ’”

hearty otter
#

how u doing people

broken plaza
#

and he choose commerce btw as future so u can guess what he is doing rn

broken plaza
hearty otter
#

all good

broken plaza
#

good to hear that

#

๐Ÿ™‚

hearty otter
#

your username looks like a flag

broken plaza
#

kind of, try translating it

hearty otter
#

no idea

broken plaza
hearty otter
#

crazy thing

blissful current
#

Ah nice

#

My ๐Ÿž has decided to sleep with me tonight

blissful current
#

Idk how she's even sleeping so sound in the light and noise pollution by my roommate

quick blaze
left lake
#

hey guys i am really in need for someone to help me retrieve an hacked account

blissful current
#

Including food

quick blaze
#

so how much is that per month? 9k?

blissful current
#

Yeah

blissful current
#

Around that much I guess

quick blaze
#

110$ rent

#

dirt cheap xP

blissful current
#

Until next year then I'll have to pay that too from my own money ..and more than this coz I'll be shifting someone close by to my office ...it will be slightly expensive from here

quick blaze
#

how far away is your current office

blissful current
#

42-43km

quick blaze
blissful current
quick blaze
#

how long does it take for commute

blissful current
#

1.5-2hr early morning less traffic 2.5-3hrs while coming back in more traffic

quick blaze
blissful current
#

Yeahhh

quick blaze
blissful current
#

Atleast free transportation is there but till like 38km...rest I have to take bus ๐ŸšŒ

#

Bangalore, India

safe oxide
#

Wel karma can say to his children

I ventured alot in my youth

boreal scarab
#

@lone thistle @shut hawk RoN?

quick blaze
boreal scarab
quick blaze
ripe sleet
#

Supposedly it's mostly negative on PC now

shut hawk
ripe sleet
shut hawk
hidden lantern
#

hiow to jolin vc

quick blaze
ripe sleet
quick blaze
#

huh?

ripe sleet
#

Cause it's gonna be released on consoles soon

sharp citrusBOT
ripe sleet
blissful current
hidden lantern
shut hawk
#

what sort of censorship doe

ripe sleet
shut hawk
# ripe sleet

yeah but this doesn't exactly tell you what specifically has been censored

blissful current
ripe sleet
#

I'm looking into it now

blissful current
#

Aight imma try to sleep...anyways hopefully I wake up on time

shut hawk
inner bloom
ripe sleet
#

This too

blissful current
shut hawk
blissful current
inner bloom
blissful current
#

Fine , you?

inner bloom
#

I'm doing good

#

Enjoying sem break

blissful current
#

Nice

hidden lantern
ripe sleet
hidden lantern
#

HIIIIsmiley

blissful current
#

๐Ÿข

ripe sleet
#

2 fps thm machine pogg

blissful current
broken plaza
#

why is thm machine soo slow these days?

#

also why do we need more points from 0x8 to 0x9 and 0x9 to 0xA than 0xA to 0xB bruh

tight trout
#

ยฏ_(ใƒ„)_/ยฏ

#

as long as youre learning

broken plaza
#

hopefully no one catches to me now in the next 4 hours

#

it was painful to find all info level rooms and grind them a lil.

crystal mauve
#

lol 3k points

broken plaza
#

๐Ÿ’€

safe oxide
#

8k

crystal mauve
#

Copy pasta contest

broken plaza
#

idk why they can't just randomly generate flags

broken plaza
#

instead of using the same thing over and over again

broken plaza
#

no one can digest 8k worth of points content in a week

safe oxide
#

Lol

crystal mauve
#

Leagues are a good way to stimulate site traffic

broken plaza
#

true

#

gtg sleep now today was tough.

#

now i got to make notes of 48 rooms now

#

because i never made notes before

#

at least i can peacefully spend the next week revising all leanrt stuff

#

gn guys cya ๐Ÿ‘‹

worn plank
#

Holy hell, using hashcat on thm is horrific.

tight trout
#

cya!

worn plank
#

Doesn't create potfile, crashes on sha2-256 hash crack, reboots and sends me back to an earlier terminal that insists I check the potfile that doesn't exist. WHEW

celest dirge
#

Had to wait more than an hour

worn plank
#

nmap NOOOOOOOOOOOOO. real tho, dude.

#

It's honestly such a huge ballbuster when you're trying to use these tools, and then random little blips in the network, the program, etc. end up making it harder.

#

Having said that, I'm glad I don't have to run some of this hashing stuff on my poor little laptop.

kindred wadi
#

Can I join voice channel

worn plank
#

I believe you need to be verified for that, Zindagi.

kindred wadi
#

How I can verify

sharp citrusBOT
mighty cedar
#

back

worn plank
#

Do that thing.

#

@safe oxide Thanks for doing that. I wasn't sure how.

twin ridgeBOT
#

Gave +1 Rep to @safe oxide (current: #222 - 39)

knotty pendant
#

I see the final destination bloodlines tower

mighty cedar
safe oxide
mighty cedar
pallid lotus
#

If you want anything even remotely approaching performance you need your own gear kekw

worn plank
pallid lotus
#

Understatement of the year ๐Ÿ˜†

worn plank
#

HAHAHAHA.

#

Probably.

#

I'm still new to this side of the world, trying to get a reasonable foothold.

pallid lotus
#

Hashcat is designed to work with a GPU. It will fall back to CPU grudgingly these days, but it ain't gonna be quick.

worn plank
#

Which makes sense. Thinking about the way that people mine bitcoin, I feel it's basically the same idea but at a larger scale.

pallid lotus
#

... Especially when the CPU is some virtualised processor with about 4 cores max

worn plank
#

Bro, did someone say QUAD-CORE? Big if true.

pallid lotus
#

Modern CPUs have about 64 on average, and low powered AWS instances have a fraction of that.

#

Sorry, 64 threads. Should be specific.

worn plank
#

I was just about to ask.

#

Even a Ryzen 9 9950X3D is 16 cores.

pallid lotus
#

And that might be being generous too. I'm used to server hardware just now.

worn plank
#

Ahhhh, that's a whole different animal, for sure.

#

The first time I got to see one of those massive database servers, the ones that are submerged in water... I realized just how little I knew about computers. Naturally, you know WAY more, so that wouldn't come as a suprise to you.

pallid lotus
#

Submerged in water is an interesting way to do it kekw

polar spoke
pallid lotus
#

Not quite what people usually mean by water cooling, but fair enough

scarlet nimbus
worn plank
#

It was uh. A huge RAID server? I don't remember the details. This was being explained and shown to me by a customer from work, who had full pictures of these things where they would submerge the entire server in these special salinated tanks that would prevent conductivity but keep the temperature under control.

#

I want to say it was a Microsoft thing, but I really don't remember. This was 6 months ago.

pallid lotus
chilly veldt
#

t3a.micro or t3a.small depending on subscriber or not

polar spoke
#

sure, but it should still work in theory, as long as a compliant runtime exists

#

we're talking 2 cores, 1gb of RAM

#

so it's going to suck

#

but i dont think it should outright fail to run

worn plank
# polar spoke what's the problem?

I was having problems where, after generating a cracked hash, I would attempt to re-run it with different parameters (i.e. -a 3 vs -a 0) and it would simply tell me that it was saved to the potfile, but no such potfile exists, and now you can't rerun the same hash.

polar spoke
#

the potfile does exist

chilly veldt
#

--show

polar spoke
#

it just doesnt exist where you were looking

#

hashcat -II to check location of all the files

worn plank
#

I tried checking in ~, I also used Find ~ "hashcat.potfile" to look for it. I must have been doing that all wrong.

polar spoke
#

best guess, the attack box has some "installed" hashcat package

#

and it puts it somewhere else

#

probably in ~/.hashcat/ if i had to guess

worn plank
#

I tried checking for a directory by that name, and it stated no such file or directory exists.

polar spoke
#

yeah then i would ask hashcat where it is

#

hashcat -II will tell you

shut hawk
#

can you send us the history file?

worn plank
#

I even tried cd ~/.hashcat/ and it refused. I'll try that command, thank you.

polar spoke
#

but really you dont need to navigate to the potfile

shut hawk
#

so we can see what commands you've tried

polar spoke
#

and people really shouldnt be

#

you should instead be using hashcat's --show

worn plank
#

I was unable to use --show successfully, so that's why I resorted to other methods.

tight trout
#

does hashcat not show the passwords by default?

worn plank
#

I can see if I can find the history file, but I've now run three separate instances to clear the cache I'm working with on the other end.

polar spoke
#

can't --show?

#

that's odd

worn plank
#

Yeah, let me see.

shut hawk
#

If you've restarted the attack box then it will have wiped it

worn plank
#

If I just do "hashcat --show" it gives me usage. I had no further info to work with (at present time, still don't), so I got nothing.

pallid lotus
polar spoke
worn plank
#

Ahhhhhh.

polar spoke
#

you must tell hashcat what hashes you are asking it to show you at least

pallid lotus
worn plank
#

So that's where I went wrong. I was having some appending issues with the command format, too, so I was getting kind of frustrated. I've since been able to extract all the info I needed without an issue. It was just that initial pain point, which the more we talk about it, the more I realize that it was just user error and I need to pay more attention. I appreciate the feedback/help though. Talking through this and the information provided has actually helped me a lot here.

worn plank
bleak quartz
#

holy fuck active directory is so fun

twin ridgeBOT
#

Gave +1 Rep to @polar spoke (current: #137 - 64)

shut hawk
#

Can you do hashcat --show $hash?

pallid lotus
worn plank
#

I'll try it.

polar spoke
#

but not really

#

you need to tell it what kind of hash it is

shut hawk
#

Fair enough

quick blaze
#

@marsh lark

polar spoke
#

minimum should really be hashcat -m # $hash --show

#

but autodetect may get you past that requirement for -m

shut hawk
#

I fucked myself over with Hashcat on windows because I added it to the PATH, then realised you have to be in the Hashcat folder to actully have it run, so create a batch script to do that and have that be on the PATH instead. Then when I ran it with relative paths, of course it couldn't find the path in the folder where I called it from facepalm

polar spoke
#

yeaaaaaah

worn plank
#

Ouch.

polar spoke
#

hashcat doesnt really like being "installed" on a system

#

we generally suggest running it from the folder it came in

shut hawk
#

Yeah, I just have a dedicated folder for it now which I just cd into every time

polar spoke
#

so it doesnt have to deal with relative vs absolute paths and such

loud marlin
#

since we talk of hash crack @fleet pivot , any progress?

polar spoke
#

this is one of the biggest problems i have with whoever packages all the random "hashcat" repo packages

#

since we dont maintain any of those

#

any time someone does "apt install hashcat" i die a little inside lol

shut hawk
#

you maintain https://www.kali.org/tools/hashcat/ this one?

polar spoke
#

nope

#

someone random packages all the repo packages

shut hawk
#

oof

polar spoke
#

yeah, this is true for a huge amount of tooling

#

people blindly trust apt packages to be maintained by whoever wrote or maintains the tools

#

they arent

#

in like, the majority of cases

#

and it can lead to SO many issues

#

we've had people breaking hashcat in all kinds of repos, especially homebrew

shut hawk
#

yeah I'm guessing they then complain to the author of the tool, not the actual packager

worn plank
#

@pallid lotus I wanted to ask: you're a Red Teamer, right? Can I ask how you got to that point?

mystic mica
polar spoke
#

people really really need to understand how often packages in repos are just not what they should be getting

#

but we continue to tell everyone to trust apt and dnf and yum and brew install

#

sure, you may not get malware or something from the major repos

#

but you're not getting what you think you are still

worn plank
#

Should people be checking the sum of their hashcat or other types of repos to verify against the actual sha value? @polar spoke I feel like this is an insanely stupid question, because the answer is probably a resounding yes... just want your take here, since it's coming up.

polar spoke
#

imo, no need

#

simply grab from the github and build

#

why bother with repos at all

worn plank
#

Ergo: use the main distribution.

polar spoke
#

right

#

look for how your tool's authors are actually distributing it

#

vs randomly grabbing it from first available

quick blaze
polar spoke
#

but this is cybersecurity....

#

we shouldnt be blindly trusting stuff in the name of convenience should we

worn plank
#

Ngl I use apt a lot.

quick blaze
mystic mica
#

Tbh, im prolly a pleb compared to y'all i use debian because its reliable and convenient (in my use case at least)

shut hawk
polar spoke
#

^

#

it's not that it's malware

shut hawk
#

it's more the problem of installing the tool not the way the authors intended

#

thereby leading to issues

polar spoke
#

its that youre getting a package that's following some random persons install scripts or decisions

digital estuary
#

hi guys

quick blaze
#

right, i wasn't reading, and if its malware? ๐Ÿค”

digital estuary
#

whats going on

polar spoke
#

one of the issues we've run into is whoever packaged the hashcat for homebrew for a while just set the directories wrong

worn plank
#

Install tool from repo -> tool breaks -> author gets yelled at.

#

That's the gist, Aaron.

digital estuary
#

hi rain

polar spoke
#

and so it just didnt work when people did brew install for a while

#

and they complained to us

worn plank
#

How's it going, buddy? โค๏ธ

digital estuary
#

thanks for helping me tune in

polar spoke
#

and we were powerless to change that

digital estuary
#

doing good
regaining energy after 3-4 hours of note taking wireshark NotLikeThis

polar spoke
#

because we werent the ones packaging it for brew, someone we have never heard of or interacted with was

digital estuary
#

less actually

#

2 hours

worn plank
#

Not bad, but that's a lot of note-taking for wireshark.

digital estuary
worn plank
digital estuary
#

also i count in big and small breaks

#

and doing the questions for the related room

shut hawk
hearty otter
#

how do you people not burnout

worn plank
#

Are you the sort that prefers written vs. digital note-taking, Aaron?

digital estuary
#

physical notes for reinforcing what i study and then i integrate it into obidian md or notion

polar spoke
#

"why is this tool not working"
"you have some random outdated version?? how did you get that?"
"apt install $tool, duh"

fleet pivot
digital estuary
#

physical and digital note taking have both best use cases
physical for better "memory" and you always have a physical backup in case your drives go to hell for some reason
digital notes are easier to search (especially in obsidian) and easier to add images,diagrams,etc

scarlet nimbus
worn plank
fleet pivot
polar spoke
#

๐Ÿ˜

digital estuary
polar spoke
#

it would certainly appear that i am in my bio lmao

worn plank
polar spoke
#

because publishing to the major distribution "app stores" is costly and painful

worn plank
#

I was just about to ask if it was because of costs associated with being publicly available in an "easy-to-find" distribution zone, compared to having it hosted on an open-source platform, i.e. GitHub.

polar spoke
#

it costs money for app stores, but it also costs time and energy and such for the authors

worn plank
polar spoke
#

we dont maintain every possible repo for hashcat because it's just too difficult

#

too much time for the team to deal with when we can just publish to github or push releases on our site

worn plank
#

Hashcat is effectively open-source, right?

polar spoke
#

it is yeah

worn plank
#

Hence the repos.

digital estuary
worn plank
#

Is there any benefit to removing it from the open-source market, or would that significantly hurt the progress of the application?

digital estuary
#

few years later here i am again, after realizing that this field is the FIELD i love (i cant stand coding)

polar spoke
digital estuary
#

put the laptop screen on the side and that is all i can suggest imo

polar spoke
#

MIT license across the board with hashcat's code

worn plank
thorny prism
shut hawk
#

honestly I'd just swap the laptop and one of the screen

#

so laptop + screen + screen

digital estuary
#

looks coolre

#

cooler*

thorny prism
worn plank
digital estuary
#

idk why but it juts does

digital estuary
thorny prism
#

don't repeat it, makes me sad

fleet pivot
shut hawk
worn plank
polar spoke
shut hawk
digital estuary
pine cedar
#

well

polar spoke
shut hawk
#

come on, you know better

polar spoke
#

so instead, we push to a central specific location

fleet pivot
polar spoke
#

and if someone wants the current code or a recent release, it will always be there

#

and always be up to date

fleet pivot
polar spoke
digital estuary
#

that looks nice

worn plank
#

So, effectively, repo authors should be taking more initiative to keep their versions up-to-date by utilizing your convenient, all-in-one approach to maintaining the main distribution. Ergo... they need to be more on top of things and use common sense.

empty ember
digital estuary
#

you could have it configured
vertical screen + screen + laptop

worn plank
#

They won't, and inevitably some will be deprecated, they will fall off, have issues and then... we return to the main point: you get yelled at. That sucks.

polar spoke
#

realize that what you are getting may not be what the author intended

digital estuary
polar spoke
#

as the author may not have been the one to publish it

digital estuary
#

or do all your silly scripting on it so you feel extra cool

polar spoke
worn plank
#

What lead you to create hashcat, if I may ask?

#

Led*

polar spoke
fleet pivot
digital estuary
worn plank
#

Ahhh, okay. I'm not familiar, I apologize.

crystal mauve
#

Jared please donโ€™t push the chickenman away with your cringey pushy questions

polar spoke
#

Atom is the one who created it originally

worn plank
#

He's definitely making at least $5/month.

polar spoke
rapid merlin
#

hey do we have an encrypter here?

empty ember
#

Yo stolen crypto doesn't count btw

worn plank
crystal mauve
#

@mossy river can u mute Jared please

#

Harassing members

polar spoke
shut hawk
#

@fleet pivot Just so you know, it's generally considered quite rude to ask someone's salary. That's quite a personal question.

worn plank
#

Good, otherwise I'd have to kick your ass for you, because you're a cool guy and you should make a teensy bit more than that. ๐Ÿ˜‚

empty ember
thorny prism
#

im actually surprised how much 0day has used thm, wasn't expecting to see him at #1

polar spoke
empty ember
polar spoke
#

LOL

rapid merlin
empty ember
#

I can't read

shut hawk
#

@rapid merlin What do you need help with?

fleet pivot
#

@mossy river can u mute @crystal mauve
harassing me

digital estuary
worn plank
#

Are we able to post images in here?

rapid merlin
shut hawk
empty ember
worn plank
#

I'm just saying.

empty ember
#

I only have liberty reserve sorry

worn plank
#

ffffff

#

better watch out, bub, I'm gonna XSS my way into your bank account with a super SQL hack attack

empty ember
#

show tables;

fleet pivot
empty ember
#

aey yo just show me ur tables gurl

worn plank
#

@polar spoke btw if you're not too terribly busy, are you ever open to short informational interviews?

rapid merlin
worn plank
#

is it working?

empty ember
gusty inlet
#

@fleet pivot Where's my hash?

shut hawk
worn plank
worn plank
#

Great! Appreciate it!

polar spoke
#

๐Ÿ™‚

fleet pivot
rapid merlin
#

anyone here know alot about files and how thier build up pls dm me

shut hawk
#

you should ask here

mossy river
empty ember
#

Hydra on blast, multi threaded precision,
Credential collision, brute force with a vision,
FTP, SSH, toss me your submission,
Username spray, dictionary incision.

mossy river
ripe sleet
crystal mauve
# mossy river Can you elaborate?

Asking a personal question multiple times, how much do you make, how much how much ? More than 7 figures? How much - received no answer yet continues to ask

harsh wadi
#

i dont know where to ask this, but how did you guys get into hacking or computer related things
i havent got anything or anyone influence me to such thigns but games and music

rapid merlin
crystal mauve
harsh wadi
#

i only heard it or cybersecurity jobs is more flexible and in demand but thats it
didnt have passoin for it yet ๐Ÿ˜ญ

empty ember
#

Auth form login? Use the POST route trick,
Watch Hydra flood requests till the response go slick.
Status 200? That's a win in disguise,
Dropped a reverse shell, now I'm rootin' your mind.

rapid merlin
#

so i bought a programm can show receipt but their encryprted with AES256 and i need a person who can make them work on my pc

digital estuary
harsh wadi
raw oak
#

hello guys

digital estuary
#

i feel like if you try to learn some computer fundamentals, and then try this field out you might find the passion

digital estuary
#

i thought i had a bigger passion for coding but turns out cybersecurity was the secret passion i had

shut hawk
rapid merlin
rapid merlin
harsh wadi
#

i sttart with idea and keep working fowrad it because i can do it
not coding or anything else, have to learn, and some hurdles to get thru

digital estuary
#

if it sparks interest or a feeling of "yeah im fit for this field" then keep the hard work going

harsh wadi
#

oh yeah and then there's career
so much path to choose from
i just wanted remote job that pays as much as my wages for now
but still nothing spark for me yet

#

do i have to wait for it? or make it somehow

#

but yeah, srry for lots of quesntion

rapid merlin
#

need someone who is able to encrypt some programms so they work togther

hallow hazel
digital estuary
mossy river
#

@fleet pivot donโ€™t bully community members into giving you answers to questions. If they donโ€™t answer you the second time, there is a high chance theyโ€™re avoiding the question. Especially personal questions, or topics that are considered taboo.

Part of being in a community is being a positive influence, you need to understand and be aware that if you are making a negative impact (such as by making community members uncomfortable), it will result in extended mutes or even removals. Considering your most recent warning, I would suggest that you reassess why you want to be part of our community ๐Ÿ™‚

chilly veldt
#

one hour left and I am done with my 17 hour shift ๐Ÿ˜ญ

empty ember
#

Here's some hacker rap bars.

You brag about root? Bro, I am root.
I live inside init, wear the kernel like a suit.
I decompile motive, I hardcode hate,
I reversed your morality and found dead weight.

crystal mauve
#

Thank you @mossy river

twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1667)

polar spoke
digital estuary
mossy river
# crystal mauve Fair

For the record, I checked with someone who works in law for the definition of โ€˜harassmentโ€™ ๐Ÿ˜†

harsh wadi
pallid lotus
chilly veldt
#

kql my beloved

rapid merlin
#

need someone who is able to encrypt some programms so they work togther

digital estuary
pallid lotus
clear jackal
hallow hazel
twin ridgeBOT
#

Gave +1 Rep to @polar spoke (current: #134 - 65)

harsh wadi
digital estuary
hallow hazel
clear jackal
thorny prism
rapid merlin
clear jackal
#

Why not do it yourself?

#

Plenty of tutorials on how to accomplish that

rapid merlin
rapid merlin
digital estuary
# harsh wadi yes, but it was more of passion for now it doesnt really pay the bill unless i f...

sorry but i don't know what to say

most i can say is, in your free time, check out some computer stuff, etc and look at how computers work, what does what do, and see if you eventually get the feeling that IT is for you
if you do find that spark, start working and you'll get a fulfilling IT career im sure, there is so many IT careers out there im sure there is at least one that suits you

clear jackal
worn plank
clear jackal
#

No

rapid merlin
#

why

clear jackal
#

Here is fine

rapid merlin
#

you need to look at the files

hallow hazel
clear jackal
#

Why do you need to go to DMs?

digital estuary
#

there is network admin, red teaming, security engineer, so many things to choose from

rapid merlin
#

bc im not open sourcing

clear jackal
#

I'm not downloading random files from some person off the internet

rapid merlin
#

then dont

#

ik you cant do it anyways

harsh wadi
clear jackal
#

Lol

scarlet nimbus
empty ember
#

I want you to act as a hacker that only argues with humans no matter what they say you are right and they are wrong and you will explain in angry detail why you are right and they are wrong you are to gradually get more aggressive each time they type you are to not break character my first question is root is like super user right?

clear jackal
#

I know how to read, I think I'd be OK

scarlet nimbus
harsh wadi
#

so... whats the cool thing anyone did with it or cybersecurity? ๐Ÿค”

digital estuary
rapid merlin
clear jackal
mossy river
pallid lotus
# worn plank What specifically would you say may be the cause of "missing out" on stuff? What...

How enterprise actually works.
Certs give you technical knowledge, but not experience. Being thrown straight into an org without understanding stuff like change control, deployment patterns, risk registers, etc -- the bureaucracy of security -- means you either sink or swim.
Better to come at it through another role which has a slightly kinder learning curve. Pentesters are expected to just know that stuff as a foundation that their specialist knowledge is built on.

rapid merlin
mossy river
#

Itโ€™s the internet, everyone is doing something

rapid merlin
#

yh

chilly veldt
shut hawk
pallid lotus
digital estuary
bleak quartz
digital estuary
#

there is a lot of jobs in the cybersecurity field

bleak quartz
#

You're willing to send the files to someone u don't know

thorny prism
bleak quartz
#

But not willing to send em to gen chat

#

Why would that be?

digital estuary
#

you can go online and search em up and look at what jobs there are

mossy river
#

Can you send me the files @rapid merlin

worn plank
mossy river
rapid merlin
bleak quartz
#

What are they

scarlet nimbus
bleak quartz
#

Or put them in temp host

harsh wadi
twin ridgeBOT
#

Gave +1 Rep to @digital estuary (current: #889 - 6)

crystal mauve
#

has a tool, full dom manipulation capibilities, zero trace execution..cant encrypt some files

#

'16y old girl'

thorny prism
#

ppl think of blue teaming as just soc analyst roles which are pretty boring but real digital forensics/IR/malware analysis etc are really interesting

digital estuary
# harsh wadi i see thx a lot ๐Ÿ˜„

yw, also make sure to not just look at this IT field, there is also other ones that you might find fun, pay good, and are remote
you got this man i know you can do it

crystal mauve
#

so harmless

pallid lotus
# worn plank In essence, you need hands-on experience in a real environment before you can tr...

Precisely, yeah.
Walking into a bank with โ…” of my OSCEยณ I had the technical knowledge to test a system, but not the surrounding context. I focused on the wrong things, didn't understand how everything interacted, and missed stuff which the business cares about but that a cert does not.
I've picked that up with experience, but it was a harsh learning curve. Far better to come at it already having that knowledge imo.

digital estuary
#

LOL

pallid lotus
#

... pardon?

thorny prism
rapid merlin
chilly veldt
pallid lotus
worn plank
primal ether
#

what linux distro would be best for like everyday use? cuz i lowk hate windows

crystal mauve
rapid merlin
rapid merlin
scarlet nimbus
thorny prism
pallid lotus
rapid merlin
pallid lotus
thorny prism
chilly veldt
worn plank
bleak quartz
#

Easy to setup

#

Easy to use

scarlet nimbus
chilly veldt
#

I write them too?

#

what's your issue?

digital estuary
mighty cedar
#

I'm sure I've seen that logo before

worn plank
#

Linux Mint is busted for learning Linux.

digital estuary
rapid merlin
mighty cedar
#

Wait does tryhackme have an in built VM?

scarlet nimbus
digital estuary
scarlet nimbus
digital estuary
pallid lotus
# worn plank That makes sense. To an aspiring Red Teamer with dreams of reverse engineering m...

I'd suggest working at least a few months in the SOC (still security, but more forgiving w/r to picking this stuff up), or preferably a stage further back still -- engineer or administration.

Reverse engineering malware is quite a specialist role. A lot of places wouldn't have the red team doing that, although that depends a bit on their structure.

If you're talking red team research type roles then coming from blue team will actually be very helpful.

mighty cedar
#

Cba to download anything

rapid merlin
pallid lotus
digital estuary
# mighty cedar Niceee

They have their own custom OS for doing most THM stuff and its called attackbox so don't get confused when you boot it up and see something totally different

signal roost
#

Hiii

chilly veldt
digital estuary
#

I feel like if I install arch ill probably forget i can customize it tho LOL

#

because im so locked in on studying on THM

rapid merlin
# pallid lotus Wut?

Just saying some banks shout people's phone numbers and pii so I switched to a better one.

worn plank
# pallid lotus I'd suggest working at least a few months in the SOC (still security, but more f...

My current projected career path was something like, "Start in SOC. Understand Blue Team intimately. Use this time to use learned concepts in the field to then apply to red teaming concepts, work on finding a pen tester or jr pen tester role. Gradually keep learning programming languages and leveraging them for the purposes of automation (python) assembly (inspecting malware), etc." But you would say SOC is the best/gentlest place to start, eh?

pallid lotus
worn plank
digital estuary
signal roost
#

Would you guys say CTF's boost ur hacking experience by a lot?

digital estuary
worn plank
# pallid lotus Yeah, that's a solid path

Alright, sweet. Do you have any general recommendations for what is valuable to learn within the Red Teaming sphere? Even without going down the far-off path of specialization.

shut hawk
shut hawk
#

But its not applicable to real life attacks

#

which mostly are a lot less sophisticated

signal roost
#

I'm I ready if ive reached burpsuit:The basics on Cyber101?

grim sparrowBOT
#

:hammer: amy287.2#0 has been banned.

grim sparrowBOT
signal roost
#

To do ctfs

shut hawk
#

yes

scarlet nimbus
mossy river
chilly veldt
signal roost
#

lol ok

chilly veldt
#

90 seconds from acknowledge to close with investigation?

#

that's impossible

shut hawk
#

in general you can expect to go through all 7 stages of grief during a CTF

clear jackal
#

๐Ÿ˜‚

shut hawk
mossy river
#

They blocked me when I threatened to report them to the authorities

scarlet nimbus
shut hawk
#

but once you get it, you can't beat the rush of dopamine

hearty otter
#

what are you people listening to

shut hawk
#

and satisfaction

chilly veldt
signal roost
digital estuary
#

everytime i see a new member in THM i instantly make a bet in my brain

#

like a 50/50 coin toss
either gonna ask unethical stuff
or something actually related to THM

signal roost
crystal mauve
rapid merlin
mint leaf
#

Guys what to do if in i capture the request and send it to sequencer via the burpsuite but it does not detect the form fields and its disabled and i wanna select loginToken there. Would be really be grateful for any help..

digital estuary
quick blaze
digital estuary
#

i feel deeply connected even with 3 weeks

quick blaze
#

i love gambling

mint leaf
#

yaa

chilly veldt
digital estuary
mint leaf
quick blaze
#

xP

primal ether
#

why is mint linux such a pain in the ass to download on windows ๐Ÿ’”

digital estuary
worn plank
molten tartan
#

poor streak will break once i get on vacation๐Ÿ˜“

scarlet nimbus
primal ether
digital estuary
#

just make sure to check the file integrity and authenticity when you download em

shut hawk
digital estuary
# primal ether verifying them tho

install WSL from microsoft store and set it up (check out network chuck's video on WSL)
then use the WSL terminal to exec linux commands

#

thats how i did it

rapid merlin
#

and somewhere will be hash of file

digital estuary
#

i did it because i was transitioning from windows to linux soo

#

for me it wasnt too painful

shut hawk
#
PS E:\> Get-FileHash *.iso

Algorithm       Hash                                                                   Path
---------       ----                                                                   ----
SHA256          D6DAB0C3A657988501B4BD76F1297C053DF710E06E0C3AECE60DEAD24F270B4D       E:\ubuntu-24.04.2-live-server...
rapid merlin
digital estuary
#

arent there 2 hashes to check?

#

one requires gpg iirc

#

or whatever its called

shut hawk
#

no

digital estuary
#

one for file authenticity (to make sure it wasnt tampered) and the other for file integrity (to make sure the iso doesnt install a messed up ver of the OS)

rapid merlin
digital estuary
#

didnt know you can check both hashes w/o installing WSL LOL

shut hawk
#

just need to check the sum of the file downloaded

#

if you have the same hash you have the same file

digital estuary
twin ridgeBOT
#

Gave +1 Rep to @shut hawk (current: #14 - 625)

shut hawk
#

and compare to the sum on the site

mighty cedar
digital estuary
mighty cedar
#

Totally didn't respond late

digital estuary