#general

1 messages · Page 1761 of 1

modern fox
#

know what i mean

distant robin
#

Yeah that's true but I am only using Kali for THM and HTB and possibly start studying again soon. I need to get my Security+ and Network+ certs. Then possibly Pentest+ or CYSA+, depending on the market.

mossy river
#

If you have the money I don’t see why you wouldn’t do SSD

#

It’s just about speed

#

Will also depend on the specs of your laptop but I’m assuming it’s fine because takes m.2

grizzled sky
distant robin
#

AMD Ryzen 5 7000 series with 16GB DDR5

grizzled sky
#

yay terminator is happening;

blissful snow
distant robin
#

BTW I have done dual boot loaders before on my desktop when I was doing both Windows and Deepin on separate hard drives many years ago.

grizzled sky
#

ngl i am strong against dualbooting unless you are using tailsos;

#

better off having 1 host and a vm for any other os you want to run;

#

ideally proxmox;

blissful snow
#

I remember the first timed i dual booted

#

i had 3 os's

#

😢

#

damit i keep calling it dual booting

#

im not sure what to call it

grizzled sky
#

as someone with experience, i will try and probably fail to warn people that dual booting is going to give you a bad time;

#

everyone thinks its great when they first hear of it, but when your efi files get deleted without warning you will know pain;

blissful snow
#

I used to boot if a usb not knowing I could install the operating system

#

🤣

grizzled sky
#

even worse if your hardware messes up the clock or drivers from swapping os;

grizzled sky
grizzled sky
#

tailsos is specifically designed to dualboot off a usb;

#

but that's specifically cause its use case is someone fleeing state actors or other serious threat actors;

blissful snow
#

im a serious threat actor >:)

grizzled sky
#

in that case, using library or other random computers is more secure than using an installed os;

blissful snow
#

nah im joking

#

im far from that

blissful snow
#

I always wondered whats going thro they're mind on a daily basics

paper pecan
#

sup

loud orbit
#

Ok I will dm it you

blissful snow
#

how did you send it twice

loud orbit
#

Wifi

grizzled sky
#

i have all the other games from all the free epic game releases though;

#

been wanting to replay through alan wake 1 remastered at some point too;

#

if you like twin peaks, its same vibes;

sand trench
#

sadly alan wake 1 remastered is massively buggy on amd gpu:S

#

and trying to play it on linux makes said bugs even worse

grizzled sky
#

that said if you just want alan wake 2 like me and already have the other games, apparently its even cheaper to just get deluxe alan wake 2 on epic store atm;

#

probably cause its about to get rereleased on steam soon;

distant robin
twin ridgeBOT
#

Gave +1 Rep to @grizzled sky (current: #296 - 30)

grizzled sky
sand trench
#

but prefer steam so would buy it on there if it ever gets moved over

grizzled sky
#

i launch everything on heroic games launcher so i can get proton on everything;

#

even drm free games i got from itch and gog;

sand trench
#

shadow loves gogs offline installers that you can download and just store to play the game whenever in the future

grizzled sky
#

yup i have entire 12tb drives dedicated to my (legal, of course) backups of game collections;

worldly pollen
#

I have a quastion one guy just said you cant change ur macadress however what about macchanger ?

sand trench
finite torrent
#

hi

sand trench
loud marlin
sand trench
loud marlin
#

but but...

loud marlin
sand trench
#

anyone got vps provider recommendations???

dark wolf
#

Vigor uses akamai (formely linode) and digital ocean.. they are both $12/month and have been very reliable for the few years that Vigor has used them

dark wolf
#

They are keeping you safe 🙂

grizzled sky
# sand trench sadly alan wake 1 remastered is massively buggy on amd gpu:S

was looking into it, the steam version in many ways is superior to the remastered version due both to the comentary track and due to it having more fog and thus better atmosphere, as well as the original face and animations compared to the new ones that remove a lot of the stylization of the origin 360 game;

#

also apparently there are some major changes to the environmental story telling such as in 1 scene where it shows alan wake's bed and it has one 1 pillow in the original, vs the remake that just uses some generic bed removing that story telling detail;

#

so yeah tldr everything i've seen says that the best way to play it on linux is to get the cheaper steam version and enjoy it with director's commentary if you played it at least once;

hybrid pawn
#

hello, iam new here i wanted to ask why the voice chats are locked

sand trench
sharp citrusBOT
twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2226)

sand trench
#

no problem

grizzled sky
#

@sand trench is it ok if i dm you? i have a present;

sand trench
#

sure go ahead

loud marlin
#

i want present also ffs

hushed notch
#

hello, on the last question of this room it's misformatting the header flag, can somebody debug?

solar skiff
hushed notch
#

the network one?

#

What is the flag shown on the contact-msg network request?

#

it seems to be

solar skiff
#

Yeah, I have a different one in my solution

#

Look at the response, instead of the request

hushed notch
#

Oh ok

#

Sorry, that was a little confusing

#

I'm not sure where the other one goes

solar skiff
#

Not all flags are used. some are decoy

#

they can't make it too easy for us 😉

solar skiff
#

Did you get it? @hushed notch

queen flare
wispy geyser
#

My delivery driver is being so slow

silver sky
gritty fern
#

The only API i found was unofficial as well

gritty fern
dark wolf
queen flare
#

thanks for confirming

dark wolf
queen flare
#

u from kazakhstan?

dark wolf
#

No, but I took one look at that mustache and knew I was dealing with international talent.

queen flare
#

i fourth most famous person in all of kazakhstan

#

i know python

strong fjord
#

Reminds me of that one movie clip

queen flare
distant robin
#

@grizzled sky would it be ok if I kept both SSD's separate with 2 different OS's instead of using a boot loader?

queen flare
sand trench
queen flare
sand trench
queen flare
sand trench
#

in the extreme privacy 5th edition

queen flare
#

those work on close friends and stuff

#

the edge cases are difficult

#

think of like a college classmate whom u don't know that well, but u might need to text them for notes

#

does shadow stay away from whatsapp completely?

dark wolf
sand trench
# dark wolf

what people see right before going POOF into white smoke and maybe dropping a red apple if you are lucky

dark wolf
abstract nexus
#

should i go for the The offensive certification

grizzled sky
queen flare
#

shadow casually ignores me cmnatic

queen flare
solar skiff
#

@mossy river , I pinged you earlier, but didn't get a confirmation if you saw my message.
About removing my verified status, so I can re-link my discord to my correct THM account.

Don't want to push you, it's not a priority. Just wanted to know if you saw the message.

sand trench
#

wait what???

#

ah right

#

yeah shadow avoids whatsapp completely

#

never made an account

dark wolf
#

Did you try to verify again with the new key

sand trench
#

generally dualbooting with 2 seperate drives work just fine

#

just sometimes with linux you might get in tiny mess because of secure boot

solar skiff
sand trench
#

shadow is watching a legally blind canadian play dwarf fort so might not see chat much here sorry @queen flare

solar skiff
#

Thank you. Now it should be ok

#

And it is 😄

sand trench
twin ridgeBOT
#

Gave +1 Rep to @queen flare (current: #168 - 57)

loud marlin
#

why use ramp to get big ass bulldozer in ship... using crane is more fun

distant robin
sand trench
digital estuary
distant robin
sand trench
#

as it is not made to be stable when it comes to updates

distant robin
#

Interesting. I have 2 choices - Deepin or Ubuntu DDE but lately I've been having problems with DDE not having any updates. I tried the terminal for the repository to use for updates and it doesn't work.

solar skiff
#

Lol, what the hell is going on with the monthly leaderboard?

loud marlin
mossy river
solar skiff
#

Playing OSRS too much, I guess to see bots everywhere

loud orbit
#

What’s this deal thing will annual subscription

hidden jacinth
kindred pulsar
#

Need help

#

How do I get a .txt file capture inside a file ??

#

I have tried everyone ls -la

#

Cat -vet

#

Every thing

solar skiff
#

Don't really understand what you want to do.
Copy the content of one file into another one? Like merge?

You might want to give a simple example of what you want to do

loud marlin
#

get what inside what ?

kindred pulsar
#

Let me send a picture

loud marlin
#

you need to verify first

kindred pulsar
#

Oh

#

I’m navigating wireshark on tryhackme

#

They said there is a .txt file inside a capture file. I should find the file and read it. What is the Alien’s name. This is the only question holding me back, I’m done with the rest

solar skiff
#

Ah, did that earlier this week.
Think I just searched for .txt within wireshark

kindred pulsar
#

Oh 🤔 let me go try this

runic charm
#

Greetings.

#

Am Vechno.

#

Pleasure to be aqquainted with you all.

solar skiff
#

Welcome

modern fox
#

same school

#

maybe

solar skiff
kindred pulsar
#

Did you use the Exercise.pcapng ?

solar skiff
kindred pulsar
#

Okay. I want to restart the virtual machine and try again

#

I will give you feed back

solar skiff
#

Don't think there's a need to restart the vm.
If you can open the exercise file in wireshark, you will find the textfile

kindred pulsar
#

It was hanging, so I need to restart

solar skiff
#

oh ok

oblique loom
#

Fking chatgpt baby now

#

"Im sorry, I cannot help with that"...

#

Wtf

solar skiff
rich jackal
#

or I'm working on Try Hack Me

oblique loom
#

I sat CTF or war game and it still does nothing but complain

#

I just need a bash script embedded in an image file to auto-run

#

Could be any file idgaf

#

There was a tool for this

#

Idr

kindred pulsar
# solar skiff oh ok

Please just help me with the Aliens name ? I can’t find it in the packet details

solar skiff
kindred pulsar
#

I went to Edit, clicked on find packet and I typed in the .txt

solar skiff
#

cool, and what kind of .txt did you find with that?

weary plinth
#

Does anyone here know how to find an email with a Snapchat username I lost my email😭

kindred pulsar
solar skiff
kindred pulsar
#

Honestly nothing relating to Aliens name

solar skiff
kindred pulsar
#

I’m lost honestly, this is the only answer holding me back to finish with this

#

Everything is looking confusing

solar skiff
#

OK, so, you searched for .txt in the correct way, in the correct pcap file.
You found a package with that search.
Did you look at the details of that package? Where does it contain something related to a txt file?

kindred pulsar
#

Yes it does, but how do I get the Aliens name

#

I have searched everyone

solar skiff
#

hold your horse.
What does the package say about a txt file?

kindred pulsar
lament crescent
#

Hello

oblique loom
#

Is it weird that I can modify and make adjustments to code for a script but if you were to ask me to build one from scratvh id have no idea where to start.

solar skiff
sand trench
#

my mom's my mom, my dad's a horse, the two of them had intercourse, I'm traumatized by their divorce
🎶

dark wolf
#

Just keep at it and start writting small programs

oblique loom
#

Im trying to make a logic bomb that auto runs from an image file of a Husky

dark wolf
#

open file
do logic bomb

#

start there

#

write out the steps first

fading stratus
#

hi

oblique loom
#

Has to be a bash script

dark wolf
#

that's fine, but if you write out the individual steps first then convert the logic to code it's easier to follow

oblique loom
#

Idk the tool to do it tho

#

It aint steghide

#

And chatgpt outputs bs like why cyber terrorism is bad

dark wolf
#

I'm not even sure what you mean by using a logic bomb against it

solar skiff
dark wolf
#

and try claude for code, tell it its for ethical hacking

oblique loom
#

An image file of a Husky is suppose to launch a logic bomb embedded within it when the image is opened

#

Its a war game

solar skiff
#

Think how a webrequest/response work.
With your found package, you requested the content of the note.txt file.
The next step (so one of the next few packages) will be the server responding with the content of the file

oblique loom
#

Has to be an image file, not pdf or docx

oblique loom
#

I might be able to get away with a js file

solar skiff
# kindred pulsar Now I’m more lost

Like you already said. Package 4267 is your GET /note.txt request.
scroll through the next several packages, until you see a response from the server

oblique loom
#

Idk what the hell is up with cgpt these days

rapid merlin
#

Hi

oblique loom
#

Was not like this before

rapid merlin
#

I'am New herecoolguy

oblique loom
#

My loan officer is suppose to call me rn

#

Been 6 minutes x. x

oblique loom
#

Nobody knows the tool for auto run from image file script?

left torrent
#

me so far

#

so

solar skiff
left torrent
remote zodiac
#

Wsup guys

wet timber
#

Does the THM attackbox's speed depend on my system's hardware specs or the Network's?. Cause it slow and laggy for me. I use and 8gb ram-i3 laptop

solar skiff
kindred pulsar
solar skiff
kindred pulsar
#

Okay brother, can I chat you up privately??

kindred pulsar
#

Thanks 🙏

rapid merlin
#

@kindred pulsar Enjoy your meal

kindred pulsar
dark wolf
#

@gusty inlet do any CCNP roles exist for my Enterprise and Security CCNP certs?

gusty inlet
#

Just CCNP.

dark wolf
#

Would you be able to add that for me or would that be someone else?

gusty inlet
#

Yep, that would be me. You'd need to DM proof. (Creds)

dark wolf
#

Ok, you did see my linked in though lol

gusty inlet
#

Didn't keep any data, forgot what the LinkedIn was. kekw

#

Don't wanna get sued.

sand trench
#

whats wrong with knowing someone named suesy

simple wadi
#

juggling between two kids+wife 😄 and not skipping a grind to keep learning every day.

sand trench
#

that is honestly impressive

rose creek
#

good job

sand trench
#

also tip of the day for people who want their own static websites:
make a github repository called
username.github.io
add a markdown file called index.md
sync it to git
tada you now have a static website

simple wadi
#

honestly, this is game changing doing it every day, at least trying, because your mind never stops thinking about cybersecurity, keeps you in the loop and focused

sand trench
#

shadow just does a single question a day but it still keeps them learning something

simple wadi
#

every effort counts. Even reading an article- latest cyber news still counts.

sand trench
twin ridgeBOT
#

➕ Gave the role CCNP to vigo0000

sand trench
#

as all the guides shadow could find beforehand were targeted at americans

twin ridgeBOT
#

➕ Gave the role CCNP to jerlasvegas

#

➖ Removed the role CCNP from vigo0000

gusty inlet
#

@dark wolf Done!

sand trench
#

oh did you doa typo dkob???

lone elbow
#

Hiii👋

lone elbow
#

Good evening lovely people 🌹, how are you all doing?

sand trench
#

could link it to anyone that wanna read it so far... but it is heavy work in progress

simple wadi
#

i am interested indeed

simple wadi
#

and yourself?

lone elbow
twin ridgeBOT
#

Gave +1 Rep to @simple wadi (current: #3191 - 1)

dark wolf
simple wadi
# dark wolf I read that as two wives and a kid

lol wouldn't be bad at all. i feel like there would be a lot of bickering and fighting between them 😄 just makes me wonder how do they live like that in muslim-majority countries where up to 4 wives are allowed mhmm

ashen summit
#

Hey hey hey! Shout out from Bristol UK! Newbie here - next step cracking the Pentagon! 🤣

simple wadi
ashen summit
winter apex
#

guys

#

help

#

plz

ashen summit
#

Just been on the John the Ripper early rooms. F*cking love it!

#

Can't wait to get a more balls deep.

winter apex
#

when i want to start an activity the server said you dont have permition

simple wadi
ashen summit
#

I've notived THM gives you half the ability to answer but you have to go away and do more research to crack the codes.

ashen summit
#

Sudo? SSH - using the correct IP? Reboot the machine maybe?

winter apex
#

im talking about discord server

ashen summit
#

Where is everyone based?

ashen summit
simple wadi
#

yeah it is a great mix of theory and lab work

simple wadi
rose creek
#

i am going for jr any advice

ashen summit
simple wadi
#

Republic of Ireland 😄 Dublin

ashen summit
#

Keeps Dublin and Dublin each year 😉

potent dew
#

Helllo

#

How is all

ashen summit
#

Very good - you?

#

Where abouts are you? I'm Bristol UK.

potent dew
#

Doing alright

sand trench
potent dew
#

In America

ashen summit
#

Nice. Whereabouts?

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2228)

potent dew
#

Chicago

sand trench
ashen summit
#

The windy city.

potent dew
#

I guess

sand trench
#

shadow is located somewhere in the dark sweden

ashen summit
#

Wow! Sweden! Never been but looks like a cool place to live.

sand trench
#

it for certain has a very specific way of living :D

ashen summit
#

I've got a question - outside of a VPN how else can someone hide their identity on line?

potent dew
#

Proxies, self care in OPSEC

#

idk

ashen summit
ashen summit
twin ridgeBOT
#

Gave +1 Rep to @potent dew (current: #3191 - 1)

loud orbit
worldly cedar
#

Is there a channel for general help on cyber security ? pls

worldly cedar
#

Thank you

sand trench
#

np

dense grove
#

Bro arch got suggested on instagram 🙏

sand trench
#

eeeew instagrams

ashen summit
loud orbit
dark wolf
#

It's an actual beer

sand trench
#

meerp moorps time for sleep sloops to the beep boop beeps

dark wolf
#

notes niters

#

stupid phone keyboard

rose creek
#

did you see you can use a android phone as a hacking device and you can build the program on your computer and then go and use a cell phone to run it

hidden pebble
#

there is kali for android

rose creek
#

yes like kali nethunter????

hidden pebble
#

yes

#

also there is termux for android which you can run scripts

rose creek
#

thats what i was looking at but i got to remember to slow down to learn then play with the big boy toys

hidden pebble
#

study everything, gather up money and get a steam deck

#

way better for on the go hacking

#

but also wait a bit for the price to drop

rose creek
#

o yea running linux but i like the phone idea

#

because no one looks at a phone

#

but my job they look at phones lol they look at all the tech i own

weak patrol
#

Hey everyone just a quick question that im sure was asked before but i need calrification

when starting to learn i chose the roadmap and began there now im omw to finishing cyber security 101

now question is should i just go based on the roadmap on the path to red teaming? or should i click "penetration tester" which leads me to a learning guide which is a bit different?
im a little confused

dark wolf
#

running kali on android is like sitting in a tub of tobasco sauce while shoving broken shards of glass up your ..

#

click on the first part of red team

#

not red team lol

weak patrol
#

yeah of course

#

but right above it is "Penetration Tester" in blue which takes me to a different path

dark wolf
#

under the PT1 test you have the web fundamentals, you can continue on that path

#

im bouncing around because one path starts getting a little annoying

#

then go to analyst and engineer for something different but fun

weak patrol
dark wolf
#

oh that's a nice resource it seems. I haven't seen it. Nor do I work in Cyber or hire so I wouldn't know the best answers

#

But if its a linux, sed, awk, firewall, wireless, web server, docker question I can help 🙂

#

or python, php

#

switching, routing, bgp, eigrp, ospf

weak patrol
#

i just got to networking on cyber 101

#

well talk after it it think lol

dark wolf
#

voip.. but voip sucks lol I used trixbox and freepbx ...

#

called my wife but put her dads number in as the source, that was fun when i could forge the source of the phone call easily

#

telcos block that now i think

weak patrol
#

super cool

dark wolf
#

It was the same thing with email, used to be super simple to fake an email sender

sturdy sequoia
dark wolf
dark wolf
#

so you can keep things straight between all the stuff going on

sturdy sequoia
dark wolf
#

typing on a keyboard is way easier when writing code or in cli

#

i can only do cli on real keyboard

dark wolf
#

so when you wanna call someone you could make them think it ws someone else and they would answer

sturdy sequoia
dark wolf
#

i haven't had a landline since before jesus became muslim

rose creek
dark wolf
#

oh wait, my bad english, i mean since god left chicago

sturdy sequoia
#

You could also do it over the mobile phone networks. Not sure if it still works though

#

And you could send your caller id as text

dark wolf
#

you could use email to send a text and fake the info

#

The best thing you can do to avoid scams is to not piss off any hackers

rose creek
#

i want to be number one nightmare of scammers

#

jk

dark wolf
#

i think scammerpayback or kitboga is already

rose creek
#

scam baiter to

dark wolf
#

or that english guy... 0day here, a mod, worked with scammerpayback, its on YT

rapid merlin
#

Hello chat

dark wolf
#

Hello Forsty

#

Need some heat?

rose creek
#

0day scares me ok

#

hello

dark wolf
strong fjord
modern fox
rose creek
#

think about it ok that man has done this for how long and he knows how much

dark wolf
#

I hate it when I teleport and accidently end up in Libya

fervent cove
#

jerma is live

rapid merlin
rose creek
#

kali or attack box

blissful snow
#

hey

#

guess what

#

Imagine not getting free money like me 😝

#

im joking

dark wolf
blissful snow
#

yeah lol

boreal scarab
#

Light work

dark wolf
boreal scarab
#

FUCKING SATAN!

#

GET THE FUCK OUT OF HERE

dark wolf
#

Security Administrator Tool for Analyzing Networks ? It was a free vuln scanner in 1995

#

you don't like it? Does it still exist?

#

you going to defcon next year too matt?

quasi karma
dark wolf
#

I'm gonna Play some Doom the dark ages in god mode bbl

topaz topaz
quasi karma
topaz topaz
quasi karma
topaz topaz
chilly veldt
#

Probably the reason why I'll fly to Mexico city again

gusty inlet
chilly veldt
wheat hare
chilly veldt
dark wolf
#

You think he sleeps?

#

our pfp and name color match bella haha

#

someone almost thought i was you the other day

winged nimbus
winged nimbus
#

hlelo

#

hello

ripe sleet
winged nimbus
#

good

#

i got two 2000 word reports due next week one i am only 1/4 the way through and the other one i am 0/1 of the way through

dark wolf
#

good luck

ripe sleet
chilly veldt
tribal shell
rapid merlin
dark wolf
#

i searched for dreaming hallucinations in gifs

tribal shell
#

I can't send gifs for some reason

#

Do I need to boost to be able to?

dark wolf
#

no just verify

sharp citrusBOT
dark wolf
#

oops

tribal shell
#

Alright I am blind I believe

sharp citrusBOT
tribal shell
#

Preciate it

dark wolf
#

no prob, use that last one

#

then you can send gifs and emotes

tribal shell
rapid merlin
dark wolf
#

nah, i wish, it's pretty cool

frozen gull
dark wolf
#

Ehhhhh ... wassssuupppp

topaz sedge
#

And weird PFP too

sturdy sequoia
#

and a weird profile. and discord account created today

stuck dragon
sturdy sequoia
#

wooo. 30 day streak and a level up

stuck dragon
#

W

twin ridgeBOT
#

➕ Gave the role eJPT to ctxzero

gusty inlet
dark wolf
sturdy sequoia
dark wolf
twin ridgeBOT
#

Gave +1 Rep to @sturdy sequoia (current: #616 - 11)

chilly veldt
tall vine
#

nice chall room

dark wolf
tall vine
#

really don't know how this matrix calculating

frozen gull
#

guys

#

how do u check ip on THM kali

#

Hostname -I ??

sturdy sequoia
#

ip addr
maybe

frozen gull
#

ip addr

#

gives 2 ips

#

which one is what

#

link/ether 16:ff:cf:94:5a:0b brd ff:ff:ff:ff:ff:ff
inet 10.201.28.170/17 brd 10.201.127.255 scope global dynamic eth0
valid_lft 2457sec preferred_lft 2457sec
inet6 fe80::14ff:cfff:fe94:5a0b/64 scope link
valid_lft forever preferred_lft forever

sturdy sequoia
#

not sure. hopefully someone else will chime in

dark wolf
#

eth0

#

on the thm machine

#

or tun0, on your vm its tun0 but that output shows eth0

frozen gull
dark wolf
#

the attack box is what you run nc -nlvp 4444 on but is it metasploit or nc that it says to use

tall vine
frozen gull
# tall vine ip route

default via 10.201.0.1 dev eth0
10.201.0.0/17 dev eth0 proto kernel scope link src 10.201.28.170

#

which one is it

tall vine
#

10.201.28.170

frozen gull
#

so why the hell is nc shutting down

tall vine
#

ping yourself

frozen gull
#

bruhh

blazing granite
#

@dark wolf hi!

frozen gull
#

does listening need sudo privilege

#

no right >

tall vine
frozen gull
#

not my own

tall vine
#

ahh, did you add ur target ip into /etc/hosts?

frozen gull
#

do i ?

tall vine
#

try it

frozen gull
#

bet

tall vine
#
echo "ip domain.xyz subdomain.domain.xyz" | tee -a /etc/hosts
willow summit
#

omg the windows vm machine is driving me batty

frozen gull
#

done

#

what port works best for netcat ?

#

4444 ?

tall vine
#

any

dark wolf
#

when not root 1024-65535

tall vine
#

i usually 6969

willow summit
#

NiceNice

frozen gull
#

WARNING: Failed to daemonise. This is quite common and not fatal. Successfully opened reverse shell to 10.201.28.170:4444 ERROR: Shell connection terminated

#

bruh

#

imma kms

#

why the fook is it terminating

tall vine
#

that connected but got broken shell

#

what's chall u doin

frozen gull
#

what the shell

tall vine
#

i got some buzz rn

#

see ya later

raven jetty
#

hey everyone! can we go far without graduation in cybersecurity ?😁

dark wolf
#

to the moon

wraith jasper
#

Im having issues with connecting via OpenVPN. Using a Kali VM, had been working fine. Any ideas on whats happening? Changed public IPs to x.x.x.x:x

2025-10-02 23:25:52 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2025-10-02 23:25:52 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2025-10-02 23:25:52 OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2025-10-02 23:25:52 library versions: OpenSSL 3.5.1 1 Jul 2025, LZO 2.10
2025-10-02 23:25:52 DCO version: N/A
2025-10-02 23:25:52 TCP/UDP: Preserving recently used remote address: [AF_INET]x.x.x.x:x
2025-10-02 23:25:52 Socket Buffers: R=[212992->212992] S=[212992->212992]
2025-10-02 23:25:52 UDPv4 link local: (not bound)
2025-10-02 23:25:52 UDPv4 link remote: [AF_INET]x.x.x.x:x
2025-10-02 23:25:52 TLS: Initial packet from [AF_INET]x.x.x.x:x, sid=5eba5459 718c6671
2025-10-02 23:25:52 VERIFY OK: depth=1, CN=ChangeMe
2025-10-02 23:25:52 VERIFY KU OK
2025-10-02 23:25:52 Validating certificate extended key usage
2025-10-02 23:25:52 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2025-10-02 23:25:52 VERIFY EKU OK
2025-10-02 23:25:52 VERIFY OK: depth=0, CN=server
2025-10-02 23:25:52 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA256, peer temporary key: 253 bits X25519
2025-10-02 23:25:52 [server] Peer Connection Initiated with [AF_INET]x.x.x.x:x
wraith jasper
twin ridgeBOT
#

Gave +1 Rep to @night peak (current: #532 - 13)

sage locust
#

any advice for someone who is traveling and only has access to a phone to be able to continue to learn and retain knowledge? Feel like being away from my pc is making me rust.

#

I am used to my schedule of learning atleast 1 thing a day and using that in a ctf or seeing how it works

dark wolf
#

Try some books or pdf, you will waste precious time trying to do it on phone

#

faster to use time to learn

wraith jasper
#

Im not sure if this is great advice, but if you've got a notebook that you can write things out with, an informational level room would be nice I think

sage locust
#

honestly I feel like thats what I needed to hear, I never write anything down physically. All my notes etc are in obsidian.

wraith jasper
#

I have written down nearly everything since the beginning of using THM. Almost a full 5 subject notebook so far and I'm only just now getting down with Jr. Pen Tester

#

I already did do the Web Fundamentals too because I heard a lot of things about people feeling not quite prepared for the web section on the PT1. In my opinion, you end up remembering things better when writing them out and then having a headache for an hour because you forgot to use sudo or make a file executable...

sage locust
#

my hand writing is so bad kek

#

this feels like ancient technology

wraith jasper
#

Dude same, I will need to rewrite this entire notebook

sage locust
#

need ai to do my handwriting for me

wraith jasper
#

And actually take my time with writing, lol

#

If only

sage locust
#

my only other option I have is using a little lan setup that has a raspberry pi

#

but idk how that will perform on hash cracking etc KEKW

wraith jasper
#

Ouch, to the hash cracking part

sage locust
#

yeah last time it cracked a hash I woke up and it still wasnt done

night peak
sage locust
#

ive also installed iSH to help me retain syntax knowledge

#

feels so weird typing in a terminal on a phone

wraith jasper
#

iSH?

#

Oh no, I hate the sound of that

dark wolf
#

get some pdfs

#

cheat sheets

sage locust
night peak
wraith jasper
sage locust
#

i need more physical books

sage locust
#

appreciate the advice ya’ll widepeepohappyheart

night peak
#

Haha, you’re really going to write it down in a notebook? You’ll probably just get sleepy from writing all those commands and proof of concepts.cri

sage locust
#

probably not commands

night peak
wraith jasper
#

That Powershell one liner😭

sage locust
#

writing syntax sounds like a mindfuck

wraith jasper
#

Don't get me wrong, I remember a good portion of them, but I did not even attempt to understand what was going on in that one liner. My windows knowledge is kind of abyssmal compared to linux knowledge

sage locust
#

I hate windows

#

AD is so boring imo

wraith jasper
#

Ngl, I do not remember it very well, I'm going to supplement with a bunch of areas I feel weak in before I try the PT1

sage locust
#

web app testing is where its at chadge

wraith jasper
#

Oh that is so fun tbh, priv esc is also really nice, when I don't forget to make the file executable....

sage locust
#

yeah thats true

wraith jasper
#

3 hours... On one section of the room because I didn't make the file executable and didn't realize it because apparently I never clicked the hint that said make sure you made your file executable... smh

#

Sitting here trying to write the $PATH shell myself, and turns out, my entire mistake was not making my file executable...

sage locust
#

yeah catching a shell is super fun especially the priv esc part. Theres something about bug bounties though that give me a crazy adrenaline rush.

wraith jasper
#

I haven't started to do any yet, definitely going to after I pass the PT1, I just want to feel like I'm ready before I jump in, you know?

sage locust
#

yeah thats a good mindset

#

its all about staying in scope

#

thats the most important part

#

changing your header for each request so they know who you are, rate limiting etc

wraith jasper
#

Oh yeah, that part I don't think I'll have too many issues, might make a flow chart and whatnot to track scope easier. Rate limiting is going to be the death of me though with hydra

sage locust
#

rate limiting SUCKS

wraith jasper
#

-T1. 100 hours later

#

5%

sage locust
#

when I first started to do bug bounties I started to realized how secure modern websites are now

#

even just lower tier / free cloudflare WAF is pretty decent and anti script kiddie

#

iykyk

wraith jasper
#

Oh, okay then. Maybe I should practice some more before then, lol

sage locust
#

I’ll say this, I wish I went headfirst into web app stuff in the beginning

#

the shell stuff is cool and all

#

but you’re rarely gonna be in a scenario like that realistically

#

but now we have xbow monkaHmm

night peak
# sage locust

The owner of the website is surely rich they’re paying a lot to their security provider

sage locust
#

yeah that was just a random picture of cloudflare blocking a potentially malicious request

wraith jasper
sage locust
#

dude look into it, its kinda scary

wraith jasper
wraith jasper
sage locust
#

it is/was the #1 bug bounty hunter in america

wraith jasper
#

oh, alright then

sage locust
#

but its an agent

#

can i link videos here?

wraith jasper
#

Oh thats concerning. I am so not beating that ever

sage locust
#

welp its not a bad video

night peak
sage locust
#

xbow was having issues with it hallucinating

#

guess how they fixed it?

wraith jasper
#

Did they just tell it to stop hallucinating?

sage locust
#

created a separate agent to investigate for hallucinations

wraith jasper
#

The Evil-GPTv2 room was funny, got the flag in 3 prompts

wraith jasper
#

Ouroborus time

sage locust
#

when I heard that my mind went like peepoWTFEXPLOSIONAHHHHH

wraith jasper
#

Thats actually hilarious

sage locust
#

AND GET THIS

#

THEY STILL USED HUMANS TO DOUBLE CHECK

wraith jasper
#

All in all I don't think I'm doing terrible. Only been doing THM for like 3.5 months and I'm almost done with all of JR Pentest. Didn't even have too much knowledge of linux beforehand and had years on windows. But now feel much more knowledgeable with linux than windows

wraith jasper
#

😭

sage locust
#

I will always be a windows hater

#

the only reason it exists is because games are typically built on/for that os especially ones that have kernel level anti cheat

wraith jasper
#

True

sage locust
#

I guess also because people think a terminal is fucking satan

#

but even then there are pretty intuitive linux distros thats almost replicate windows

wraith jasper
#
sudo gcc tmp.c  -o Gotime -w
[sudo] password for sly: 
tmp.c: In function ‘main’:
tmp.c:5:1: error: implicit declaration of function ‘system’ [-Wimplicit-function-declaration]
    5 | system("GG");
      | ^~~~~~
#

Any ideas why the file is not being created?

wraith jasper
#

Or will it not create it in the /tmp directory

sage locust
#

I dont think the dir is the issue

night peak
wraith jasper
#

Use 3 graves prior to the code and 3 after

#

`

#

Then just copy between it, builtin discord feature, a buddy in college showed me and its stuck ever since

sage locust
wraith jasper
#
void main()
{setgid(0);
setuid(0);
system("GG");
}```
#

Same example as shown in the $PATH portion of the room

night peak
#

you just casually paste it here?

#

or bot command?

wraith jasper
#

Just paste in between and but with one more on each side

#

woah

#

thats new

night peak
#

Sorry, I’m new to Discord, so I don’t really know yet.

wraith jasper
#

I guess you can do it for individual words, also I kinda forgot, is it against the rules of the discord to post code or anything I didnt even think about it until you said something

wraith jasper
sage locust
#

named GG i mean

wraith jasper
#

Its not trying to run yet when I got that issue, I was just trying to compile it into an executable

#

and then I'll wget it over to the vm

#

Because gcc wasn't on that machine by default

#

But it eventually will be calling a "binary" named GG

sage locust
#

try adding #include <stdlib.h>

#

I think thats why it isnt recognizing system()

wraith jasper
#

So, I went into su, and tried to save the stdlib in and it says permission denied

sage locust
#

maybe update source file?

wraith jasper
#

But I exit and then use my base user and it worksNotLikeThis

sage locust
wraith jasper
#

Why... what happened. I do not understand

night peak
#

why i can't do that

wraith jasper
#

Has to be the grave key (`) not (') and it has to be 3

sage locust
sage locust
wraith jasper
night peak
#

I gave upkekw

wraith jasper
#

Are you sure you're using `? Its the one top left with the tilde/squiggly line

wraith jasper
twin ridgeBOT
#

Gave +1 Rep to @sage locust (current: #3191 - 1)

sage locust
night peak
#

rkhunter --check --report-warnings-only --cronjob 2>&1 | tee rkhunter-$(date +%F).log && \

#

I get it now

#

thanks HAHAHA

wraith jasper
#

Awesome, good job man

sage locust
#

im almost considering getting a pi/mini pc while im traveling

#

idk if another pi is a good idea tho

#

guess it could be another lightweight server machine

wraith jasper
#

My boss showed me a keyboard today that has a raspberry pi builtin. Really neat stupid compact, about $200 usd

sage locust
#

yeah those are cool

wraith jasper
#

I can't remember what it was called but it was neat

sage locust
#

my issue is no gpu

wraith jasper
#

True

#

I like my tower, but I do not want to lug it around

sage locust
#

yeah…

#

other idea is doing a very small itx build

#

or external gpu

wraith jasper
#

Those are always neat

sage locust
#

woops

#

like this would be sick af

#

pretty much like a little guitar amp

wraith jasper
#

I would love carrying that thing around

#

That looks sick

#

Does anyone know what the loopback address ends up being when you're connected to the THM VPN via OpenVPN but its all on an Oraclebox VM?

sage locust
#

wouldnt that be the vm itself?

wraith jasper
#

Thats what I thought but wget isn't communicating with my machine

sage locust
#

you tried local host?

wraith jasper
#

So, I've got a simple python server running on my VM so I can transfer the file to the THM VM for the room. The THM VM is having issues connecting back to my machine

sage locust
#

oh wait I think I see the issue

marsh lark
sharp citrusBOT
wraith jasper
#
--2025-10-03 05:39:35--  http://10.0.2.15:2001/tmp/Gotime
Connecting to 10.0.2.15:2001... failed: Connection timed out.
Retrying.

--2025-10-03 05:41:46--  (try: 2)  http://10.0.2.15:2001/tmp/Gotime
Connecting to 10.0.2.15:2001... failed: Connection timed out.
Retrying.

--2025-10-03 05:43:58--  (try: 3)  http://10.0.2.15:2001/tmp/Gotime
Connecting to 10.0.2.15:2001...```
sage locust
#

you might have to bridge or port forward

wraith jasper
#

Basically trying to do this but in a roundabout way because the thm vm doesn't have gcc

wraith jasper
#

Unless someone went through and reset

sage locust
#

nah not that kind if port forwarding

#

like via ssh

wraith jasper
#

Oh, mb. I might have to look into that

sage locust
#

and for bridge adapter its a setting in the VM software for that machine

wraith jasper
#

Enable Network Adapter?

sage locust
#

you can connect the machine on the same network as the host pretty much

sage locust
wraith jasper
#

Vbox

#

Have it set to bridged adapter, what is promiscuous mode?

#

Oh, I think I answered my own question

sage locust
wraith jasper
#

I think promiscuous might need set to allow vms

#

I could be wrong, but I think that might be it

sage locust
#

was there an option to turn it off?

wraith jasper
#

Off by default

sage locust
#

yeah leave that

wraith jasper
#

Okay

sage locust
#

can always go back and enable

wraith jasper
#

Time to test

sage locust
#

ip should be in the same subnet as the host once its all done

wraith jasper
#

Should I have only that option for network adapters?

#

Or leave the other/base one enabled

sage locust
#

leave the default one on

wraith jasper
#

There we go

#

It changed to an IP within my subnet

sage locust
wraith jasper
#

although I did lose a few interfaces

#

which is odd, I did disable the default one though and only then did the ip change

echo flax
#

Hi people I need help with Microsoft sentinel, I'm new to it.

sage locust
#

(I think)

echo flax
wraith jasper
#

I mean, I've still got eth0 and lo and tun0

#

But there was like 2 more interfaces prior

sage locust
#

prob eth1 and the vbox interface

wraith jasper
#

Ahhh

sage locust
#

you should be good tho

#

now just make sure you’re listening on all interfaces when hosting the http server

#

then use eth0 ip

#

SHOULD work

wraith jasper
#

Yee, it finally did. Took me long enough, lol

loud orbit
#

Sup chat

chilly veldt
#

sup sup

rain socket
#

wassssaaaaa

rain socket
#

Lucky me lol

sage locust
#

its real

rain socket
#

must be it says official

sage locust
rain socket
#

wild

vague pewter
#

Does anyone know of ways someone could get unpaid experience as an intern in cybersec?

#

Ah wait wrong channel

stoic quarry
#

Yes

rapid merlin
#

what are best phones to do portable pentesting within reasonable grounds with, just something cheap for experimentations

stoic quarry
#

Check requirements for kali nethunter

ivory geyser
#

Hello

#

Guyssss

night peak
#

Hey, is there any way to change my email or transfer my TryHackMe progress to my main Google account?

stoic quarry
#

Hello 👋

stoic quarry
#

I'm signed out rn but it should be there somewhere

#

If not then you can always contact support

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

native tide
#

hey! i purched the annual pack, it says 5month free, does that mean i'll get 12month + extra 5 month?

rapid merlin
#

yoo guys

#

I got the T-shirt

#

in hack2win

#

But i didnt receive yet eyes_cry

#

is it better to NAT or Bridge network connection for a Windows 11 vm in linux?

mental meteor
#

hey guys I am a beginner

#

I was wondering which free rooms I can use to kickstart learning some hacking skills

solar skiff
stoic quarry
#

The free path is p good

mental meteor
#

thnx

onyx lance
#

Hey folks! New here and excited to hack, learn, and grow ⚡

night peak
stoic quarry
#

Ello 👋

night peak
onyx lance
#

Thnx feel great to be here😌

stoic quarry
#

Hell yeah, enjoy yourself (And remember to take notes)

onyx lance
#

got it!

formal skiff
#

Hello everyone,
I’m looking for like-minded researchers to collaborate on bug hunting. The idea is to exchange methodologies, work on testing together, and strengthen our approach for better results. If you’re interested in teaming up, feel free to reach out.

night peak
#

Is it nighttime there? There aren’t many people in the server, it’s so quiet

stoic quarry
#

This server has people from all over the globe

night peak
#

I thought everyone was asleep haha.

stuck dragon
#

its 11am

mental meteor
#

hey as a beginner to hacking do I need to learn a programming language if yes then which one will u reccomend

stoic quarry
#

A scripting language is good to learn

night peak
#

to read bugs and exploits

stoic quarry
#

Python is pretty easy to learn

night peak
#

and to understand other hacker codes

mental meteor
#

ok thanks

night peak
#

Not like those people who just do a git clone, copy and paste, then run it right away without even reading the code—that’s why they end up getting hacked themselves haha.

onyx lance
#

I’m new to Discord. Honestly it feels a bit messy and hard to understand right now 😅 just a noob here trying to figure things out...😒

jolly abyss
#

Does anyone know where and which CTF are meant to be practiced for each module you complete

stuck dragon
#

you can search it up, at least I did that

jolly abyss
#

I got this GitHub link
But all the practice CTFs are private

stuck dragon
#

lets say u did sqli and then u search a ctf with sqli

jolly abyss
stuck dragon
#

you should not do ctfs then i guess

#

because u will just end up looking for writeups cuz u dont know what to do and thats not good to learn

native tide
simple wadi
solar skiff
simple wadi
#

good morning everyone

jolly abyss
limpid mountain
#

guys anyone have a web app pentesting guide or learning path in github?

limpid mountain
#

i need a structured learning path

mental meteor
stuck dragon
jolly abyss
solar skiff
quick saffron
#

Hi im new

jolly abyss
limpid mountain
#

yup me too

#

i didnt focus too much on learning path before

mental meteor
solar skiff
mental meteor
#

ya I recenty dicovered it and was really impressed by its content and how beginner friendly it is

solar skiff
#

Deals, discount, ads,... it's all marketting. And they can put as many fancy words in it as they want. And be very creative with numbers.
In the end, look at what you can afford and what you get out of it, and make your own calculation.

If you're short on money, there are plenty of free rooms and other resources.

night peak
#

It’s actually hard to cancel a TryHackMe subscription if it’s on an annual plan haha, that’s why I still prefer the monthly one.

queen flare
#

everyone is being contacted by an elon musk it seems

night peak
#

As time goes by, the era just gets sadder—it’s all AI everywhere, and it’s exhausting.pepehands

solar skiff
stuck dragon
modern fox
#

that bonus scam ig

blissful frost
#

when i run burpsuit and start intercepting the sites doesn't load anyone has the same issue?

solar skiff
blissful frost
#

i used to use burpsuit btw

solar skiff
#

Does the website load when you turn interception off?
And do you see the requests then in the history?

blissful frost
#

ye when i turn interception off the sites load

modern fox
#

thats the point it loads in burp

solar skiff
#

Like if you open a browser, you intercept the request of the index.html
But it will also intercept all images, all css/js files, ...

blissful frost
modern fox
#

its not gonna load btw

#

thats how it works

blissful frost
modern fox
#

because

blissful frost
solar skiff
modern fox
#

it wont load until u turn off burp

modern fox
blissful frost
modern fox
#

its not a problem

#

it wont load until u forward

#

thats normal

blissful frost
modern fox
#

oh my bad

#

😭

modern fox
#

in the browser

#

the extension yk

blissful frost
#

wait i think ik where is the problem from

modern fox
blissful frost
# modern fox where

the CA certificate is malfunctioning and corrupted and needs to be reinstalled

blissful frost
#

yep alr it's working now gng

#

thanks @modern fox and @solar skiff

twin ridgeBOT
#

Gave +1 Rep to @modern fox (current: #674 - 10)

#

Gave +1 Rep to @solar skiff (current: #1578 - 3)

modern fox
sonic arrow
#

Hllo someone help me when I start tryhackme it free and after sometime they told me to buy subscription of one year but I can't afford the subscription what can I do

sturdy sequoia
sonic arrow
#

I want to complete the pre security path but I am stuck in middle cause of premium

#

Tell me bro where I can start fundamental path

sturdy sequoia
solar skiff
rapid merlin
#

hi guys i want to ask a question can i

modern fox
#

uhhh sure

sturdy sequoia
rapid merlin
#

ok so my question is a simple question what if a hacker get someone cookies then what the attacker can do with that and what he can do so first can the attacker pass that cookies to another browser if yes then how what way the attacker could follow and when he passes that cookies to another browser then what he can get can he login to accounts immediatly and what else he can get

modern fox
#

what...

#

wdym passes cookies to another browser

sturdy sequoia
#

i think theyre asking about using another users cookies to somehow login to their account. but im not quite sure

rapid merlin
#

I mean, suppose an attacker somehow obtains the cookies from my browser. Cookies store a lot of data, including session information for websites where I'm logged in. If the attacker imports those cookies into their browser (for example, my Chrome cookies), what can they do with them?

sturdy sequoia
#

i believe you need more than just the cookies but its been a while since ive looked into that stuff

modern fox
#

so its not always hackers, its THE browsers and the things like chrome

rapid merlin
modern fox
rapid merlin
modern fox
#

and cookies encrypted as well

sturdy sequoia
#

you could probably use cookies to hijack sessions but youd need more than just the cookie

rapid merlin
#

so the attacker cant login to my accounts

modern fox
sturdy sequoia
#

it isnt as easy as a yes or no answer

modern fox
#

if that was easy i'd be millionaire prob

#

anyone of us