#general
1 messages ยท Page 1326 of 1
oh ok
yea
why
what to do after the presecurity
Go watch NetworkChuck on IP networking
what is going on today
Nothing good
average weekend stuff
hi
hi
hiya
we are hitting bad rolls on the slot machine today (people keep asking for unethical tutorials)
#QuickBansFTW
im kinda just getting started learning hacking and damn why is it so hard to find where to even start lol
have you heard of youtube?
Check Windows API documentation its basic knowlege bro
go for the free roadmap or if you're subscribed follow the premium ones
also take notes since this field is quite large
also i love your bio lmao
but youtube regulations are top secure for the user ...so its important info is protected by their guidelines
im taking a cybersecurity course too, next year (in a few months) we'll be learning some ethical hacking but idk i still need to learn how to code
Why do you feel so confident in saying such stupid things?
Please stop
cuz thats what i need
You don't know what you need
having programming knowledge is good
helpful for automating some boring stuff (python!)
and other stuff
sup people

so what can u make me learn ? ( point that made me dumb)
yeah i been trying to learn python but idk what to even make with python or what i wanna make
honestly make anything
even simple things
like a calculator
ooh alr ty
a couple hours from now im gonna have to do very hard work for hours
just anything that can be fun, or helpful
K
check out #start-here to get started learning
good luck ๐จ
i thought it was cool
What a sentence
When you make things, how do you create a portfolio to store them in? I've read you make a Github account and you can store it in there #completebeginner

Which field?
deez nuts
Whatโs deez nuts
Aight ...that's how u wanna talk
When can i join general call?
verify
ty
cybersecurity
refer to this @agile mica
Too late
@blissful current thanks for beating me on the /docs showdown LOL
Gave +1 Rep to @blissful current (current: #103 - 82)
bro cannot take jokes
Nah probably urs is first
should I go to sleep?
yeah but mine is for getting student discount w/o student email
I typed wrong at first before sending it
how many points
if you got enough points that no one will be catching up go sleep
yo bro
I'm ahead by about 450 points
hey guys anyone got idea on how can edit a video stream and youtube won't detect it as copy right?
its a joke
why
summer games done quick event has started
round it up to 500 points ahead and you good
go enjoy some games being speedrun
u dont have to take it so serious๐
Ya am chill
that's not even how u use that joke
no, you;re suppose to responde deez, and they say deez what?

and then u follow / deez nuts
yea but it can be used like that
no thats how its always been and will always be
alright guys time for me to go take a big break see you guys
i remember doing that so many times

no this kid is here
still on this?
why pt2
mornin karma

bro
don't understand you man
why do you want/need to know that?
u think ur slick
girlypop
while ur not
I think I'll read the Manga itself can't wait for 4 weeks for the remaining 4 episodes ffs

who?
wanna start a youtube channel base on others cotents
that sounds like copyright infringement
which is against youtube's ToS
Well...this...
and law in places where the copyright is held
Takopi's Original Sin
that's why i don't want to get detected anyway
we can not help you break laws 
Itโs ToS, not law, but is unethical
Against Youtube's ToS. This will not be allowed in here. Please do not mention it.
would it not be law if it was something like music for example? due to copyright laws

this sucks man
You have been walking on a very thin line for the past few days. This will be your final warning. Next time, it will be a ban.
mhm yeah
Googoogagaga!!!!
huh

hiya dot, how's it going
oh i think this is for someone else
Are you an admin or what?
are you blind?
Mod
Lalalalfifififififafafafadomdomdomdom!
this kid is stupid
@foggy terrace Just come up with original ideas. Nothing is truly original anymore, but try it. Take inspiration, not one-to-one ideas from others.
You were not pinged.
real
cannot u see the role

everything u know i know
Gaga.
@waxen radish hey buddy, sorry for disappearing last night, I ended up showering and going to sleep.
Did you resolve your issue?
I would say yes, apologies I didnโt actually read what their request was, however I wouldnโt really know if itโs a copyright violation
Aight good night y'all, gotta wake up early for office ...Monday FFS 
night!
Btw @foggy terrace I recommend in future I recommend that if you are streaming in OBS to set the music onto a different channel, which means using most editing software you can replace the music with your own copyright free
ok
If you want to split your outputs it makes it a lot easier
Your microphone for input, game capture with audio capture on a specific application, Discord/ other voice comms and then set your music to an output channel if possible
If itโs in a game you might have problems unfortunately
@brave spire ?
Sorry, I don't know what happened.
fine mom!
headpats
the vc is active :o
hi, im new to ethical hacking but want to learn batch files, anyone know any good channels or ways to learn it?
?

I think this is enough for today considering i got my first cert now finally
recommend looking around and finding stuff that works for you
Crossplane V8 idle noises
any recommendations/ suggestions?
personally i like looking up stuff on duckduckgo, but google works for others
i haven't done batch files before, but that's how i would approach it
There are search engines in this world that gives you exactly what you're looking for.
And it's not Google.

Office is fine ...just tired from waking up at 5am everyday
anyways zombie go sleep
10/10
What the fudge!!
nohtyP
In the US, you'd need to meet the criteria for fair use, to legally be in the clear. That does not mean someone can't take advantage of YouTube's DMCA Takedown system or your time in a courtroom.
printhello ("world")
sleep early bruh wth

world ("worldhelloprint")
if you're waking up at 5 just try and get at least 6 hours
I'm going to work on my own language in the future, it will be called "Shit me not (SH)"
that's like the max i look for
not healthy

mate i used to have a polyphasic sched and it was like 2-4 hours a day max for 2 years straight and that almost killed me
no joke
It's even worse with a stupid roommate who realizes that he has to study for the exam at midnight when it has turned the same date as the exam ...and would turn on all the freaking lights of the room for no apparent reason (including washroom lights)
why can't he just study the day before or something ๐ญ
Coz he's either busy sleeping or gambling all the time
Very busy person


Lol
sup
blackjack!?
He has an exam ..hence ruined sleep tonight


i use to play a bit of hold em
Hey guys can I have help or advice
Iโve started learning terminal with network chucks playlist on the 2nd video now,when would he recommended I can move to python ?
I wanna hack and script and stuff
Great
u ever did?
Never tried ..won't do
My roommate does that shit daily
Winzo and xrabet imsure

or Dream11
the worst one
Nah some non play store available one
that's even worse ๐

Looks like neh ...he's been doing that since a lot
i bet he lost a ton
like in lacs if it totals
whats IPL? i havent used gambling sites since 2011
it's called Indian Premier League
ohhh
it's a sprots championship and is very big
Ya but mostly he stays like neutral
Cricket tournament
oh lucky person then
Apart from that he smokes some cheap shits multiple times a day worth 50โน ...that too half of the time on borrowed money
wtf ๐
is he even employed?
Neh
๐
i mean with that level of confidence if he knows what he is doing could lead him to somplace much better
if he chose right path
His dad is DSP or something in police ...smokes his money

that explains a lot

i have a frnd
who's dad is in HPCL some manager post
touch the ground guys
my guy was a good and healthy till he attended school with me.

he literally doesn't cares about himself and even recently started smoking as well with his frnds
Sed
how u doing people
and he choose commerce btw as future so u can guess what he is doing rn
hi im fine wbu ๐
all good
your username looks like a flag
kind of, try translating it
Damn
no idea
it's in hexadecimal
crazy thing
Idk how she's even sleeping so sound in the light and noise pollution by my roommate
karma how much do you pay for your rent? ๐ค
hey guys i am really in need for someone to help me retrieve an hacked account
Yearly 1Lakh at my current PG
Including food
???
so how much is that per month? 9k?
Yeah
Around that much I guess
Until next year then I'll have to pay that too from my own money ..and more than this coz I'll be shifting someone close by to my office ...it will be slightly expensive from here
how far away is your current office
42-43km
wtf

how long does it take for commute
1.5-2hr early morning less traffic 2.5-3hrs while coming back in more traffic
.....4-5 hours of your day gone just for travel 
Yeahhh

Atleast free transportation is there but till like 38km...rest I have to take bus ๐
Bangalore, India
Wel karma can say to his children
I ventured alot in my youth
@lone thistle @shut hawk RoN?
rise of nations?
Ready Or Not
fudge
Supposedly it's mostly negative on PC now
i dont have it haha
It's
uh oh what did they do in the recent update?
hiow to jolin vc
what the hell happened
Something with censorship on pc
huh?
Cause it's gonna be released on consoles soon
@hidden lantern

what sort of censorship doe
yeah but this doesn't exactly tell you what specifically has been censored

I'm looking into it now
Aight imma try to sleep...anyways hopefully I wake up on time
ah ok

This too
Eeper
Yeah, this

Hi, how are you
Fine , you?
Nice

Hello! 
HIIII
๐ข
2 fps thm machine pogg
why is thm machine soo slow these days?
also why do we need more points from 0x8 to 0x9 and 0x9 to 0xA than 0xA to 0xB bruh
hopefully no one catches to me now in the next 4 hours
it was painful to find all info level rooms and grind them a lil.
lol 3k points
Copy pasta contest
i hate that shit
idk why they can't just randomly generate flags
instead of using the same thing over and over again
u forgot the vomiting of the whole thing part then lol
no one can digest 8k worth of points content in a week
Lol
Leagues are a good way to stimulate site traffic
interesting but yeah
true
gtg sleep now today was tough.
now i got to make notes of 48 rooms now
because i never made notes before

at least i can peacefully spend the next week revising all leanrt stuff
gn guys cya ๐
Holy hell, using hashcat on thm is horrific.
cya!
Doesn't create potfile, crashes on sha2-256 hash crack, reboots and sends me back to an earlier terminal that insists I check the potfile that doesn't exist. WHEW
Using nmap on thm was horrific
Had to wait more than an hour
nmap NOOOOOOOOOOOOO. real tho, dude.
It's honestly such a huge ballbuster when you're trying to use these tools, and then random little blips in the network, the program, etc. end up making it harder.
Having said that, I'm glad I don't have to run some of this hashing stuff on my poor little laptop.
Can I join voice channel
I believe you need to be verified for that, Zindagi.
How I can verify
@kindred wadi
back
Gave +1 Rep to @safe oxide (current: #222 - 39)
I see the final destination bloodlines tower
What website is that
Tryhackme
What do you expect running it on a lightweight AWS instance with no GPU lmao
If you want anything even remotely approaching performance you need your own gear 
I know. I acknowledge that these virtualized systems aren't going to run as robustly as physical/dedicated machines that are local.
Understatement of the year ๐
HAHAHAHA.
Probably.
I'm still new to this side of the world, trying to get a reasonable foothold.
Hashcat is designed to work with a GPU. It will fall back to CPU grudgingly these days, but it ain't gonna be quick.
Which makes sense. Thinking about the way that people mine bitcoin, I feel it's basically the same idea but at a larger scale.
... Especially when the CPU is some virtualised processor with about 4 cores max
Bro, did someone say QUAD-CORE? Big if true.
Pretty much, yes. It's all about distributed calculations.
GPUs have thousands of cores and can do thousands of those calculations simultaneously
Modern CPUs have about 64 on average, and low powered AWS instances have a fraction of that.
Sorry, 64 threads. Should be specific.
And that might be being generous too. I'm used to server hardware just now.
Ahhhh, that's a whole different animal, for sure.
The first time I got to see one of those massive database servers, the ones that are submerged in water... I realized just how little I knew about computers. Naturally, you know WAY more, so that wouldn't come as a suprise to you.
Submerged in water is an interesting way to do it 
what's the problem?
Not quite what people usually mean by water cooling, but fair enough
Hello, can I ask you something about sentinel rooms?
It was uh. A huge RAID server? I don't remember the details. This was being explained and shown to me by a customer from work, who had full pictures of these things where they would submerge the entire server in these special salinated tanks that would prevent conductivity but keep the temperature under control.
I want to say it was a Microsoft thing, but I really don't remember. This was 6 months ago.
Without spinning one up to check, I would guess the Attackbox is a t3a.medium EC2 instance. Might be being generous: t3a.small maybe.
t3a.micro or t3a.small depending on subscriber or not
sure, but it should still work in theory, as long as a compliant runtime exists
we're talking 2 cores, 1gb of RAM
so it's going to suck
but i dont think it should outright fail to run
I was having problems where, after generating a cracked hash, I would attempt to re-run it with different parameters (i.e. -a 3 vs -a 0) and it would simply tell me that it was saved to the potfile, but no such potfile exists, and now you can't rerun the same hash.
the potfile does exist
--show
it just doesnt exist where you were looking
hashcat -II to check location of all the files
I tried checking in ~, I also used Find ~ "hashcat.potfile" to look for it. I must have been doing that all wrong.
best guess, the attack box has some "installed" hashcat package
and it puts it somewhere else
probably in ~/.hashcat/ if i had to guess
I tried checking for a directory by that name, and it stated no such file or directory exists.
can you send us the history file?
I even tried cd ~/.hashcat/ and it refused. I'll try that command, thank you.
but really you dont need to navigate to the potfile
so we can see what commands you've tried
I was unable to use --show successfully, so that's why I resorted to other methods.
does hashcat not show the passwords by default?
I can see if I can find the history file, but I've now run three separate instances to clear the cache I'm working with on the other end.
Yeah, let me see.
If you've restarted the attack box then it will have wiped it
If I just do "hashcat --show" it gives me usage. I had no further info to work with (at present time, still don't), so I got nothing.
Aye. Sounds like it runs... poorly lmao
you have to add --show to your existing command
Sentinel?
Ahhhhhh.
you must tell hashcat what hashes you are asking it to show you at least
Yeah, that's overkill for most things ๐
I've got a bunch in my office rack. They're not overly fussed.
So that's where I went wrong. I was having some appending issues with the command format, too, so I was getting kind of frustrated. I've since been able to extract all the info I needed without an issue. It was just that initial pain point, which the more we talk about it, the more I realize that it was just user error and I need to pay more attention. I appreciate the feedback/help though. Talking through this and the information provided has actually helped me a lot here.
No doubt at all. I'm not sure what they were using those supercomputing servers for, so I'm sure there was a good reason that I simply can't articulate. ๐
for more info on this specifically
holy fuck active directory is so fun
Brilliant, thank you.
Gave +1 Rep to @polar spoke (current: #137 - 64)
Can you do hashcat --show $hash?
Wait until you try securing an ancient forest in a corp. You'll want to shoot yourself lmao
I'll try it.
well, kinda
but not really
you need to tell it what kind of hash it is
Fair enough
@marsh lark
minimum should really be hashcat -m # $hash --show
but autodetect may get you past that requirement for -m
I fucked myself over with Hashcat on windows because I added it to the PATH, then realised you have to be in the Hashcat folder to actully have it run, so create a batch script to do that and have that be on the PATH instead. Then when I ran it with relative paths, of course it couldn't find the path in the folder where I called it from 
yeaaaaaah
Ouch.
hashcat doesnt really like being "installed" on a system
we generally suggest running it from the folder it came in
Yeah, I just have a dedicated folder for it now which I just cd into every time
so it doesnt have to deal with relative vs absolute paths and such
since we talk of hash crack @fleet pivot , any progress?
this is one of the biggest problems i have with whoever packages all the random "hashcat" repo packages
since we dont maintain any of those
any time someone does "apt install hashcat" i die a little inside lol
you maintain https://www.kali.org/tools/hashcat/ this one?
hashcat Usage Examples
Run a benchmark test on all supported hash types to determine cracking speed:
root@kali:~# hashcat -b
hashcat (v5.0.0) starting in benchmark mode...
Benchmarking uses hand-optimized kernel code by default.
You can use it in your cracking session by setting the -O option.
Note: Using optimized kernel code limits the maximu...
nope
someone random packages all the repo packages
we only maintain the github and hashcat.net downloads
oof
yeah, this is true for a huge amount of tooling
people blindly trust apt packages to be maintained by whoever wrote or maintains the tools
they arent
in like, the majority of cases
and it can lead to SO many issues
we've had people breaking hashcat in all kinds of repos, especially homebrew
yeah I'm guessing they then complain to the author of the tool, not the actual packager
@pallid lotus I wanted to ask: you're a Red Teamer, right? Can I ask how you got to that point?
Can confirm
yuuuuuup
people really really need to understand how often packages in repos are just not what they should be getting
but we continue to tell everyone to trust apt and dnf and yum and brew install
sure, you may not get malware or something from the major repos
but you're not getting what you think you are still
Should people be checking the sum of their hashcat or other types of repos to verify against the actual sha value? @polar spoke I feel like this is an insanely stupid question, because the answer is probably a resounding yes... just want your take here, since it's coming up.
imo, no need
simply grab from the github and build
or grab a release from github or hashcat.net
why bother with repos at all
Ergo: use the main distribution.
right
look for how your tool's authors are actually distributing it
vs randomly grabbing it from first available
i mean..to look for original packages/installers every time you wanna install something would be impractical no..? isn't that why people just use apt and brew install?
sure, it's inconvenient
but this is cybersecurity....
we shouldnt be blindly trusting stuff in the name of convenience should we
Ngl I use apt a lot.
true, but if the main concern is malware from bad repos then how do you think we should be installing stuff, without it being inconvenient
Tbh, im prolly a pleb compared to y'all i use debian because its reliable and convenient (in my use case at least)
the main concern isn't malware in this specific case
it's more the problem of installing the tool not the way the authors intended
thereby leading to issues
its that youre getting a package that's following some random persons install scripts or decisions
hi guys
right, i wasn't reading, and if its malware? ๐ค
whats going on
one of the issues we've run into is whoever packaged the hashcat for homebrew for a while just set the directories wrong
Install tool from repo -> tool breaks -> author gets yelled at.
That's the gist, Aaron.
hi rain
and so it just didnt work when people did brew install for a while
and they complained to us
How's it going, buddy? โค๏ธ
thanks for helping me tune in
and we were powerless to change that
doing good
regaining energy after 3-4 hours of note taking wireshark 
because we werent the ones packaging it for brew, someone we have never heard of or interacted with was
Not bad, but that's a lot of note-taking for wireshark.
i write slow ๐ข
This must be a common issue for application authors when hundreds of repos start spawning, hey?
also i count in big and small breaks
and doing the questions for the related room
it goes deeeeep
how do you people not burnout
Are you the sort that prefers written vs. digital note-taking, Aaron?
more common than you think
no i utilize both
physical notes for reinforcing what i study and then i integrate it into obidian md or notion
"why is this tool not working"
"you have some random outdated version?? how did you get that?"
"apt install $tool, duh"
yo
physical and digital note taking have both best use cases
physical for better "memory" and you always have a physical backup in case your drives go to hell for some reason
digital notes are easier to search (especially in obsidian) and easier to add images,diagrams,etc
Azure sentinel, kql
That's really smart.
Bruh, I know. The basics were INTENSE.
are you the ceo of detack inc?
school burns me out a lot
stuff i love hardly burns me out
it would certainly appear that i am in my bio lmao
Actually, I ran across this with Termux. They specifically state that you should install from F-Droid, where they have their nightly builds and things like that, as opposed to downloading from Google Play Store, where it is more or less deprecated.
yeah, this happens to mobile apps a LOT
because publishing to the major distribution "app stores" is costly and painful
I was just about to ask if it was because of costs associated with being publicly available in an "easy-to-find" distribution zone, compared to having it hosted on an open-source platform, i.e. GitHub.
it costs money for app stores, but it also costs time and energy and such for the authors
I took this approach initially with Python. I would write out code by hand. I quickly learned that's a recipe for carpal tunnel.
we dont maintain every possible repo for hashcat because it's just too difficult
too much time for the team to deal with when we can just publish to github or push releases on our site
Hashcat is effectively open-source, right?
it is yeah
Hence the repos.
i did the same when i was little and i was trying to learn cybersec
i dont know what site it was but it was a LONG time ago
and i remember writing everything into a notebook, all uppercase letters
i was essentially copying the entire website and that killed my motivation to study this field
Is there any benefit to removing it from the open-source market, or would that significantly hurt the progress of the application?
few years later here i am again, after realizing that this field is the FIELD i love (i cant stand coding)
we are open source necessarily to keep the project both maintained but also licensed for what it's used for
put the laptop screen on the side and that is all i can suggest imo
MIT license across the board with hashcat's code
I, too, wanted to be an epic hackerman with crazy l337 coding skills, and I also killed it (by trying to learn JavaScript at 12 years old).
oh...

i used java for programming at uni and never touched it again lmao
yeah this i vouch
looks coolre
cooler*
yh it kills me that the screens aren't identical lool
So, in essence, not all repos are bad repos, but repos don't always result in a happy-happy-funtime "yay development" cycle. Instead, there are loads of headaches, but it's necessary because... what, the license comes for free due to open-source availability?
idk why but it juts does
OH MY GOD I JUST NOTICED THAT
don't repeat it, makes me sad
that was rude
when you have actual content on the screen it won't make a difference
I necessarily need to learn JS so that I can do some side-project stuff. I hate it.
repos are just a headache to deal with sometimes
Jared, what made you ask the question in the first place?
as long as its the same resolution and same refresh rate
well
idk
we COULD package and push every version to every repo under the sun, but keeping them all up to date is tough
come on, you know better
chickenman
and if someone wants the current code or a recent release, it will always be there
and always be up to date
aint no way u a ceo
๐
that looks nice
So, effectively, repo authors should be taking more initiative to keep their versions up-to-date by utilizing your convenient, all-in-one approach to maintaining the main distribution. Ergo... they need to be more on top of things and use common sense.
have u reached 7 figures?
you could have it configured
vertical screen + screen + laptop
yh maybe this
They won't, and inevitably some will be deprecated, they will fall off, have issues and then... we return to the main point: you get yelled at. That sucks.
It's more that I think repos should be carefully considered by the end user more
realize that what you are getting may not be what the author intended
do u make 7 figures?
just make sure to use vertical screen to read notes and other stuff so you dont hvae to scroll as much
as the author may not have been the one to publish it
or do all your silly scripting on it so you feel extra cool
you would be surprised what I make ๐
I didn't, i'm just a core dev/team member
๐
+5% to better code and code structure
Ahhh, okay. I'm not familiar, I apologize.
Jared please donโt push the chickenman away with your cringey pushy questions
Atom is the one who created it originally
lol i'm used to it
He's definitely making at least $5/month.
at LEAST ๐
hey do we have an encrypter here?
Yo stolen crypto doesn't count btw
So help me god, if they try to pay you $4/month...
I sign my own paychecks so I'll try not to pay myself that little haha
@fleet pivot Just so you know, it's generally considered quite rude to ask someone's salary. That's quite a personal question.
Good, otherwise I'd have to kick your ass for you, because you're a cool guy and you should make a teensy bit more than that. ๐
Wait so like a money glitch irl
im actually surprised how much 0day has used thm, wasn't expecting to see him at #1
only as far as what the company has in it's bank account lol
-$3000000 now cuzzo
LOL
look dms pls
I can't read
@rapid merlin What do you need help with?
@mossy river can u mute @crystal mauve
harassing me
me when i give the ATM a paper bill that says "a bajillion dollars"
Are we able to post images in here?
are you the ops?
the what
no
I'm just saying.
I only have liberty reserve sorry
ffffff
better watch out, bub, I'm gonna XSS my way into your bank account with a super SQL hack attack
show tables;
he wasnโt offended by it
aey yo just show me ur tables gurl
@polar spoke btw if you're not too terribly busy, are you ever open to short informational interviews?
look dms
i dont see why not
@fleet pivot Where's my hash?
Yes, because he's understanding, most people won't have the same reaction
So, my next question: is it alright if I DM you for that purpose?
look dms
yeah sure
Great! Appreciate it!
๐
๐ shit
anyone here know alot about files and how thier build up pls dm me
you should ask here
Can you elaborate?
Hydra on blast, multi threaded precision,
Credential collision, brute force with a vision,
FTP, SSH, toss me your submission,
Username spray, dictionary incision.
Iโm going to need details
Hello Jabba! 
Asking a personal question multiple times, how much do you make, how much how much ? More than 7 figures? How much - received no answer yet continues to ask
i dont know where to ask this, but how did you guys get into hacking or computer related things
i havent got anything or anyone influence me to such thigns but games and music
so i bought a programm can show receipt but their encryprted with AES256 and i need a person who can make them work on my pc
Starts here @mossy river
i only heard it or cybersecurity jobs is more flexible and in demand but thats it
didnt have passoin for it yet ๐ญ
Auth form login? Use the POST route trick,
Watch Hydra flood requests till the response go slick.
Status 200? That's a win in disguise,
Dropped a reverse shell, now I'm rootin' your mind.
so i bought a programm can show receipt but their encryprted with AES256 and i need a person who can make them work on my pc
for me it was childhood curiosity, i would go through the file explorer and look at random files, play with the settings, etc
thats personal there
i might feel annoyed tbh
hello guys
i feel like if you try to learn some computer fundamentals, and then try this field out you might find the passion
imo, this is necessary
i thought i had a bigger passion for coding but turns out cybersecurity was the secret passion i had
we wouldn't be able to do that, you should contact the seller
its encrfypted for safty
its possible i have the acsess code
so i guess i had to dive in myself
i felt kinda lonly for msot thigns i do
but not making music for some reason
i sttart with idea and keep working fowrad it because i can do it
not coding or anything else, have to learn, and some hurdles to get thru
just try out coding or cybersec, once you learn the fundamentals obviously
if it sparks interest or a feeling of "yeah im fit for this field" then keep the hard work going
this is totally different from what i used to
unlike music and art, its everywhere
this? nly behind the scnene
and no one in my family talk or influence me in some way
so im strating from absolute scrath
oh yeah and then there's career
so much path to choose from
i just wanted remote job that pays as much as my wages for now
but still nothing spark for me yet
do i have to wait for it? or make it somehow
but yeah, srry for lots of quesntion
need someone who is able to encrypt some programms so they work togther
keep going
how did you start out, if you don't mind telling obv
You need to give the IT sector a try, look online where to start, it all depends on what you want
but for now, learning some Computer fundamentals and basics is what you'll need, especially for this field, because you cant do much
I think โharassmentโ is a stretch; annoying, personal and bullying, yes.
@fleet pivot donโt bully community members into giving you answers to questions. If they donโt answer you the second time, there is a high chance theyโre avoiding the question. Especially personal questions, or topics that are considered taboo.
Part of being in a community is being a positive influence, you need to understand and be aware that if you are making a negative impact (such as by making community members uncomfortable), it will result in extended mutes or even removals. Considering your most recent warning, I would suggest that you reassess why you want to be part of our community ๐
Fair
one hour left and I am done with my 17 hour shift ๐ญ
Here's some hacker rap bars.
You brag about root? Bro, I am root.
I live inside init, wear the kernel like a suit.
I decompile motive, I hardcode hate,
I reversed your morality and found dead weight.
Thank you @mossy river
Gave +1 Rep to @mossy river (current: #6 - 1667)
it was mostly just a life long love of computers and needing to solve harder and harder puzzles, which security seems to be the place for
and the harsh truth is if you don't have a spark, how will you ignite a fire?
For the record, I checked with someone who works in law for the definition of โharassmentโ ๐
thats basially stops me
i have no other reason but my livelihood
i guess i need to surround myslef more IT stuff
Any particular reason why you're asking me specifically? ๐
kql my beloved
need someone who is able to encrypt some programms so they work togther
try to see if there is a spark in this, if not, try something else because im sure there is something out there that you can do remote and genuinely enjoy
you also said you got passion in music right?
I got lucky.
Internship on a pentest team + a bunch of certs during my degree. It worked out, although I wouldn't recommend that route. You miss too much.
What does this even mean? Why are you repeatedly posting this?
Awesome, thanks for the answer!
Gave +1 Rep to @polar spoke (current: #134 - 65)
bc i need help
yes, but it was more of passion for now
it doesnt really pay the bill unless i force it to
at the cost of my own sanity
summary
they got some program or something and they've been looking for someone good around encrypting/decrypting to help
Interesting, what route would you recommend, and what do you mean by miss too much?
You haven't even asked a question....
similar to me on the blue side, degree, internship in DF, full time after uni and then moved into IR
im asking if someone can encrypt some files for me
bc its inanly hard and i need someone with the tools for it
not for the things i need
sorry but i don't know what to say
most i can say is, in your free time, check out some computer stuff, etc and look at how computers work, what does what do, and see if you eventually get the feeling that IT is for you
if you do find that spark, start working and you'll get a fulfilling IT career im sure, there is so many IT careers out there im sure there is at least one that suits you
Then please describe what you're trying to do exactly
What specifically would you say may be the cause of "missing out" on stuff? What are you referring to in this context, and how would you mitigate that? Or, failing that, what would you do instead, knowing what you know?
dms?
No
why
Here is fine
you need to look at the files
Was your goal from the start to become a blue teamer or you want to transition to a red teamer in the end?
Why do you need to go to DMs?
there is network admin, red teaming, security engineer, so many things to choose from
bc im not open sourcing
I'm not downloading random files from some person off the internet
true
its only a matter of whether it clicks for me or not
but for now, still exploring ๐
Lol
Because I don't know who to ask๐
I want you to act as a hacker that only argues with humans no matter what they say you are right and they are wrong and you will explain in angry detail why you are right and they are wrong you are to gradually get more aggressive each time they type you are to not break character my first question is root is like super user right?
I know how to read, I think I'd be OK
It depends on what you need to do
so... whats the cool thing anyone did with it or cybersecurity? ๐ค
that's good, the drive to keep going is a strong motivator
just go around look at computer stuff, surround yourself with IT people that can help you try find something you'll like
you have this tool (Premium bypass for all HTML5
restrictions
Full DOM manipulation
capabilities
Zero-trace execution) and an html executer then you can try
CC @mossy river, unverified person wants people to download files that they won't say what they are and "encrypt" them
im asking for help r
pip install --r brain v1.0
And they asked what they were?
How enterprise actually works.
Certs give you technical knowledge, but not experience. Being thrown straight into an org without understanding stuff like change control, deployment patterns, risk registers, etc -- the bureaucracy of security -- means you either sink or swim.
Better to come at it through another role which has a slightly kinder learning curve. Pentesters are expected to just know that stuff as a foundation that their specialist knowledge is built on.
and he says im trying to hack him
Itโs the internet, everyone is doing something
yh
well, as I work with KQL for work, I know I can get it to do ๐
what a roast
e.g., coming out of OSWE I could code review a web app. Took me ages to figure out how the code actually interacted with all of the other systems surrounding it.
You just don't get that scale without experiencing it yourself.
you can be contracted or hired
you can test systems (penetration testing) and look for vulnerabilities that can be patched by the blue team (people that defend networks, look for anomalies)
Suspicious ngl
there is a lot of jobs in the cybersecurity field
You're willing to send the files to someone u don't know
I always found digital forensics fascinating but after 8 years of doing it I'm pretty interested in pen testing now
you can go online and search em up and look at what jobs there are
Can you send me the files @rapid merlin
In essence, you need hands-on experience in a real environment before you can truly understand the scope and scale of a given enterprise, and more specifically, what they will expect from a tried-and-true operator in the field.
They literally canโt
bc they were like 2k
What are they
I work instead with multiple monitoring systems and kql is the slowest one
I mean he can just verify in a few seconds that's 100% not the problem
Or put them in temp host
i see
thx a lot ๐
Gave +1 Rep to @digital estuary (current: #889 - 6)
has a tool, full dom manipulation capibilities, zero trace execution..cant encrypt some files
'16y old girl'
ppl think of blue teaming as just soc analyst roles which are pretty boring but real digital forensics/IR/malware analysis etc are really interesting
yw, also make sure to not just look at this IT field, there is also other ones that you might find fun, pay good, and are remote
you got this man i know you can do it
so harmless
Precisely, yeah.
Walking into a bank with โ
of my OSCEยณ I had the technical knowledge to test a system, but not the surrounding context. I focused on the wrong things, didn't understand how everything interacted, and missed stuff which the business cares about but that a cert does not.
I've picked that up with experience, but it was a harsh learning curve. Far better to come at it already having that knowledge imo.
๐
decrypt after AES256
... pardon?

nothing
it's only slow if you don't know what you're doing
Yes. That's the gist of this conversation smh
sry<
What would you say, short of being introduced into these environments, would be the most efficient way to gain this kind of abstracted "lived experience"? Don't just focus on certs, focus on... what, would you say?
what linux distro would be best for like everyday use? cuz i lowk hate windows
? do it yourself
can you help me?
you need 1k tool for it
It's slow because I need to build queries with multiple tables and I don't have time for that
1k took to encrypt files? Lol
Honestly? If you haven't worked in them, one way or another, you're going to struggle to pick that up.
It's impossible to virtualise the sheer scale of your typical organisation.
decrypt
Almost certainly
.. Not true
Ubuntu is easy and fun ig
what?
my multiple table queries takes like 1.5 seconds
That makes sense. To an aspiring Red Teamer with dreams of reverse engineering malware, what would you say? "Good luck"? ๐
I need to write those queries
closest linux distro to feeling like windows is Linux Mint (I use it too!)
Linux Mint is also very user-friendly so great for a first-time distro to learn all the linux stuff on
Isn't that a portal profile picture?
I'm sure I've seen that logo before
Linux Mint is busted for learning Linux.
Get used to linux, and maybe boot up some different distros on a VM later on in the future to see what vibes with you the best
??????
Wait does tryhackme have an in built VM?
That we have like 90 sec to do an alert and throw away 20 sec only to make the query is not efficient
IT IS i can vouch so much
i love the distro so far
but i might move on to Arch soon for that customization and aesthethic
Yes and also the conti logo
yes
I'd suggest working at least a few months in the SOC (still security, but more forgiving w/r to picking this stuff up), or preferably a stage further back still -- engineer or administration.
Reverse engineering malware is quite a specialist role. A lot of places wouldn't have the red team doing that, although that depends a bit on their structure.
If you're talking red team research type roles then coming from blue team will actually be very helpful.
BLUESTAR BAYBEEEEEEEEEEEEEEEEEE
I "love" it when banks are silly enough to dox your THM purchase or even in the lobby. The next time you show up you are both sweating with poker faces but they love to shout people's numbers etc. This applies to most places though. I'm too ethical but it does grind my gears a bit whenever I go somewhere important.
Only a few thousand...
They have their own custom OS for doing most THM stuff and its called attackbox so don't get confused when you boot it up and see something totally different
Hiii

Wut?
90 seconds to investigate an alarm or confirm it or acknowledge it?
im more of a "build your own design" guy
I feel like if I install arch ill probably forget i can customize it tho LOL
because im so locked in on studying on THM
Just saying some banks shout people's phone numbers and pii so I switched to a better one.
My current projected career path was something like, "Start in SOC. Understand Blue Team intimately. Use this time to use learned concepts in the field to then apply to red teaming concepts, work on finding a pen tester or jr pen tester role. Gradually keep learning programming languages and leveraging them for the purposes of automation (python) assembly (inspecting malware), etc." But you would say SOC is the best/gentlest place to start, eh?
?
Something something report to regulator
Not a bad thing tbh. I'd wait until later when you're studying less and programming/working more for Arch distros.
eugh scary
Yeah, that's a solid path
(when school starts because school drains my soul
)
tbf if i lock in on school early i can just have my teachers let me out to do whatever i want soooo
Would you guys say CTF's boost ur hacking experience by a lot?
yes it can boost experience a LOT because you're getting pure hands on experience
Alright, sweet. Do you have any general recommendations for what is valuable to learn within the Red Teaming sphere? Even without going down the far-off path of specialization.
It's helped with my general problem solving skills
Hell yeah lol
I'm I ready if ive reached burpsuit:The basics on Cyber101?
:hammer: amy287.2#0 has been banned.
[BAN] User left the discord server.
To do ctfs
yes
This is the average time to manage it, report or close as fp
cc @clear jackal it was fraud
i'm sorry, but that's a shitty soc
lol ok
in general you can expect to go through all 7 stages of grief during a CTF
this will be for the majority of time
They blocked me when I threatened to report them to the authorities
Not acknowledged, report to the customers
but once you get it, you can't beat the rush of dopamine
what are you people listening to
and satisfaction
wait, so walk me through your timeline of how you handle an incident/alarm
Yeahh thats what im hoping for lol but Im a bit "afraid" of jumping to the "wild"
everytime i see a new member in THM i instantly make a bet in my brain
like a 50/50 coin toss
either gonna ask unethical stuff
or something actually related to THM

didnt u join about 3 weeks ago
most of the time "can you hack .....?"
Guys what to do if in i capture the request and send it to sequencer via the burpsuite but it does not detect the form fields and its disabled and i wanna select loginToken there. Would be really be grateful for any help..
yes but i feel like i've been in the server since the dawn of it
Can I write in dm?
if you're betting then get me involved
i feel deeply connected even with 3 weeks
i love gambling
all in.
yaa
I would prefer in here, so people can join in discussing about SOC, but if you don't feel comfortable about the information, then sure
make a bot that automatically makes a poll of what they're gonna ask when they're a new member and join just to ask something
90% of gamblers quit just before they hit it big fr
im good at blackjack
xP
why is mint linux such a pain in the ass to download on windows ๐
the ISO mirrors? pick any
how the entire reddit bitcoin community views people who hodl and people who don't
poor streak will break once i get on vacation๐
Because there are too many messages and I lost the mentions
verifying them tho
just make sure to check the file integrity and authenticity when you download em
no woories
Get-FileHash on powershell
install WSL from microsoft store and set it up (check out network chuck's video on WSL)
then use the WSL terminal to exec linux commands
thats how i did it
theres checksum on website (i guess so), on windows to check hash i think you need to click "properties" on downloaded file
and somewhere will be hash of file
wat
thats way overkill
i did it because i was transitioning from windows to linux soo
for me it wasnt too painful
PS E:\> Get-FileHash *.iso
Algorithm Hash Path
--------- ---- ----
SHA256 D6DAB0C3A657988501B4BD76F1297C053DF710E06E0C3AECE60DEAD24F270B4D E:\ubuntu-24.04.2-live-server...
or this
no
one for file authenticity (to make sure it wasnt tampered) and the other for file integrity (to make sure the iso doesnt install a messed up ver of the OS)
no? i think you can check either one
but they have this https://linuxmint-installation-guide.readthedocs.io/en/latest/verify.html
didnt know you can check both hashes w/o installing WSL LOL
just need to check the sum of the file downloaded
if you have the same hash you have the same file
ooh thanks for enlighting me with info
Gave +1 Rep to @shut hawk (current: #14 - 625)
and compare to the sum on the site
I'll just do the lesson stuff and go from there
ooh
Totally didn't respond late
gl with the modules!






=


