#general

1 messages ยท Page 1762 of 1

solar skiff
#

If it was, you'd be a millionaire in jail prob

modern fox
#

login info and cookies separate u wont be able to login with cookies, cookies has other purposes (useful ones mostly ๐Ÿ’€) and cookies encrypted with that websites panel or whatever

#

aint that easy to take em either

#

just dont use weak password

#

know what i mean

#

@rapid merlinello

sturdy sequoia
#

now i want a cookie

rapid merlin
strange ivy
rapid merlin
#

what do you want to say

sturdy sequoia
#

i found some shorbread. close enough

modern fox
#

u see what i mean

rapid merlin
#

yes i knew then what the attacker do on the cookies

modern fox
#

no i mean

gray pine
#

Hey guys, Im trying to download nessus and the video tutorial I was watching, featured nessus essentials, which in my case I don't even have that option. The videos Im watching are a bit old and dont treat the problem. Doesn anyone here knows the solution or that can point me to the right direction?

sturdy sequoia
#

the nessus website probably has an installation guide

gray pine
#

Ye, but the thing is that I want nessus essentials and when Im prompted which version do I need are only: nessus expert and professional, which are paid versions

gray pine
modern fox
rapid merlin
# modern fox no i mean

When you log in to a website (like Gmail, Facebook, or Discord), the site doesnโ€™t ask for your password every time you click something. Instead, it gives your browser a cookie โ€” a small file that proves โ€œthis is you, already logged in.โ€

๐Ÿ‘‰ If an attacker somehow steals that cookie from your browser and loads it into their own browser:

The website will think they are you.

They can open the site and be logged into your account right away, without typing your password or 2FA code.

Thatโ€™s why cookie theft is dangerous โ€” itโ€™s like someone copying the key to your house. They donโ€™t need your fingerprint (password) anymore; they just use the copied key (cookie).

this is what chatgpt is saying

gray pine
#

linux

sturdy sequoia
modern fox
modern fox
rapid merlin
#

sometimes i hear voices

gray pine
rapid merlin
gray pine
modern fox
dusky epoch
#

Hello, is it me or are rooms not showing target IPs once machines are deployed

rapid merlin
#

does the NSA spy on everyone?

tired wolf
#

no

sturdy sequoia
proper dome
#

no

modern fox
rapid merlin
#

what if someone here works for the NSA

gray pine
sturdy sequoia
rapid merlin
modern fox
tired wolf
gray pine
rapid merlin
#

but fr what if im a terrorist does that mean im being watched?

modern fox
sturdy sequoia
#

i thought nessus was still free with kali

tired wolf
#

nessus is a freemium

#

isnt it

modern fox
#

idk we cant find free version

gray pine
modern fox
tired wolf
gray pine
#

When Im prompted on installation which version do I need I only see these 2 ๐Ÿ˜ญ

gray pine
gray pine
modern fox
gray pine
#

fr

#

Trynna make us all go broke

sturdy sequoia
#

their faq says its free
"Nessusยฎ Essentials is free to use to scan any environment, but it is limited to 16 IP addresses per scanner. It is ideal for educators, students, and anyone starting out in cyber security. "

modern fox
gray pine
# tired wolf ?

I download it and follow it, when I go to register offline, I dont see the nessus essentials

modern fox
#

so temp free ๐Ÿ˜ญ

gray pine
#

fr

#

can u provide a screenshot please?

gray pine
tired wolf
gray pine
#

Im just a beginner guys ๐Ÿ˜”

tired wolf
#

i assume the issue is beyond this page

gray pine
#

yes

rapid merlin
modern fox
gray pine
#

after that I chose register offline as per the tutorial and then I dont see the essentials option @tired wolf

rapid merlin
modern fox
#

ur cookies not safe even if theyre encrypted everyone selling ur cookies to everyone

#

chrome, facebook, utub, tikgram, instatok

gray pine
sturdy sequoia
#

To summarise, you don't need to worry about someone stealing your cookies

tired wolf
#

@gray pine i understand

#

theres no nessus essentials

modern fox
sturdy sequoia
#

Is it a separate download?

modern fox
#

type shi

gray pine
tired wolf
modern fox
sturdy sequoia
#

That sucks

gray pine
#

Thanks for helping guys, especially @tired wolf that actually went through it!

twin ridgeBOT
#

Gave +1 Rep to @tired wolf (current: #1270 - 4)

sturdy sequoia
#

Is there an open source competitor to nessus?

tired wolf
#

openvas

sturdy sequoia
#

Can metasploit scan or does that just exploit?

tired wolf
#

both i think?

#

i havent used it

#

cant say for sure

civic mural
#

thm down?? room's ip not showing

sturdy sequoia
#

I just found the awesome Linux priv esc list. This is gonna be so useful. Why didn't I find this sooner

gray pine
civic mural
gray pine
dusky epoch
jolly abyss
#

But how do I know which rooms to do ๐Ÿค”

gray pine
ripe sleet
civic mural
#

tried 2-3 dif rooms
same issue on all of em

gray pine
#

ok just name one so I can replicate it

civic mural
#

anniiev2

#

tried different medium difficulty rooms, same issue

sturdy sequoia
scarlet cove
gray pine
civic mural
#

how can we let devs know? do they already know? any announcement?

hoary kettle
#

hey can anyone tell me why my machine ip not showing after start machine after 2 minutes....?

gray pine
#

we ALL (as in you and me)

chrome condor
#

hey so i got this problem where it doesnt show me the ip address of the target machine in tryhackme it shows me the copy button but even when i press nothing gets copied is this a server problem that ishould just wait for or my problem :

hoary kettle
rapid wyvern
modern fox
#

@gray pinebtw u can use metasploit as well

#

for vuln scan

gray pine
twin ridgeBOT
#

Gave +1 Rep to @modern fox (current: #616 - 11)

modern fox
twin ridgeBOT
#

Gave +1 Rep to @gray pine (current: #858 - 7)

chrome condor
sturdy sequoia
#

its much better than having not enough

gray pine
chrome condor
sturdy sequoia
#

back in my day.....

chrome condor
gray pine
chrome condor
modern fox
sturdy sequoia
gray pine
gray pine
twin ridgeBOT
#

Gave +1 Rep to @modern fox (current: #573 - 12)

modern fox
gray pine
sturdy sequoia
# gray pine pray tell

there were no youtube tutorials, no online test machines, no ethical hacker forums. it was all word of mouth and test it yourself

gray pine
#

WE ALL have it easy now fr

sturdy sequoia
#

defcon and 2600 were still small (especially where i live). the hacker groups were quite private and it took actual knowledge to gain more knowledge

gray pine
chrome condor
modern fox
sturdy sequoia
#

i have a physcial book that i bought in a physical book store

gray pine
sturdy sequoia
mossy river
ripe sleet
gray pine
modern fox
sturdy sequoia
# gray pine damn that mustve SUCKED

it was definitely a different experience to now. one thing im thankful for is actually having to understand everything rather than asking ai or a chat room with thousands of people

mossy river
sturdy sequoia
modern fox
ripe sleet
mossy river
#

Does anyone else have the problem when you're waiting for something and you can't do anything until that thing is done?

sturdy sequoia
#

imagine finding a toy in a cereal box that can be used to make free payphone calls. it was a crazy time to be alive

ripe sleet
sturdy sequoia
twin ridgeBOT
#

Gave +1 Rep to @ripe sleet (current: #109 - 83)

mossy river
ripe sleet
#

I'm trying to minmax my methods to make them the most efficient

sturdy sequoia
#

wireshark was ethereal, kali was backtrack, aircrack was still aircrack ๐Ÿ˜›

mossy river
ripe sleet
ripe sleet
cloud quiver
frozen gull
#

guys i heard

ripe sleet
frozen gull
#

comptia secAI+ is free

#

how do u get it

#

any idea ?

chilly bronze
#

Can aircrack attack or find drone Signals?

ripe sleet
mossy river
#

But alas I must work and earn a paycheck

sturdy sequoia
ripe sleet
cloud quiver
ripe sleet
frozen gull
#

kgb

#

reccomend some certs

#

which are affordable and effective

frozen gull
#

to slap on my resume

ripe sleet
jolly abyss
frozen gull
mossy river
ripe sleet
# mossy river It's, hopefullly, a new PC

There's this older Christmas movie that has this one inspirational song that applies to cyber and mostly everything else. It's from this movie called santa claus is coming to town where the song is "put one foot in front of the other."

ripe sleet
#

Like you're not bankrupt or anything right?

mossy river
#

Yes yes don't worry ๐Ÿ˜„

mossy river
#

My partner has given me some money for part of it which has helped a lot

mossy river
#

Not that I need it, I think she just feels bad cause of how sad I was when my tower stopped working ๐Ÿ˜†

#

She's a cutie, I begrugendly accepted her money

ripe sleet
mossy river
#

I'm super super excited to buy it

ripe sleet
hoary kettle
#

hey can anyone tell me why my kali not connected to tryhackme through openvpn

topaz sedge
#

I was out with my tech club friends and I have to say, they're way more fun than my literary club friends not even joking

ripe sleet
#

Did you previously connect and forget to close that session?

#

Sometimes you might have to kill that previous process to start a new one

frozen gull
topaz sedge
ripe sleet
topaz sedge
ripe sleet
#

I have friends that are like that and it's always a fun time

topaz sedge
#

I love the tech club I'm a part of
It's a bit small but the quality of people is just insanely good and better than other tech clubs of college

ripe sleet
#

I have a friend that I send the most effed up reels to and we just send them to each other

topaz sedge
topaz sedge
ripe sleet
#

You can really understand them as people

topaz sedge
#

Yeaa

#

I got in the cybersec department of that club

#

And it's pretty good

ripe sleet
#

I was in like 3 tech clubs on the e-board in my previous college

topaz sedge
#

The entire club built the college website and we manage it

ripe sleet
#

One of which was my own club AquaSmile

ripe sleet
#

Too bad it's dead

topaz sedge
#

Awww

ripe sleet
#

If we had like 4-5 more years we could turn that shit into a powerhouse

modern fox
ripe sleet
#

We had some fun

topaz sedge
#

It's alright
Good things seldom last long

ripe sleet
#

I made 3 ctfs for that club

#

The 1st one, I didn't realize that AWS doesn't like ubuntu 24

cloud quiver
ripe sleet
#

I hope that's going well for you!

marsh lark
#

I am online for the first time today lol

#

how is everybody ๐Ÿ™‚

sturdy sequoia
#

going really well. got a level up and a 30 day streak today

#

u?

marsh lark
# sturdy sequoia u?

good, had my coding class, learned a new data structure (that I actually didn't learn on purpose cuz it never really comes up)

sand trench
#

thanks for the review... yeah still gotta expand on some stuff and order it better while adding more boxes to check off

twin ridgeBOT
#

Gave +1 Rep to @simple wadi (current: #2100 - 2)

boreal scarab
#

D ALL OF THE ABOVE!!!!!!!

tribal bison
#

what does this 5 months free discount is about?

narrow yew
#

pekaboo

tribal bison
#

i pay 95.50euros for 12 months

blissful snow
tribal bison
#

but get 5 months for free?

#

or 12+5

narrow yew
tribal bison
#

i dont get you

marsh lark
#

I actually don't understand it myself lol

tribal bison
#

i mean every once a month there is a yearly discout

#

every month the same discount

#

whats different this time

narrow yew
#

you pay for an annual plan but get effectively 17 months of access for the price of 12.

marsh lark
#

from what I heard from Jabba

narrow yew
#

It could be

marsh lark
#

what I remember

#

is that it was not 5 extra months, but 5 free months

#

what I'm not sure about is how that is calculated

tribal bison
#

so its just for marketing purposes

narrow yew
#

Then you buy 7 and get 5

marsh lark
tribal bison
#

i would assume so

#

its the same by saying you get 25% off

narrow yew
#

Well what is the price for this deal

#

I cant see the price since I have a sub

#

Or where they drunk when they made the add

tribal bison
#

from โ‚ฌ10.50/month its โ‚ฌ7.88

#

which is 25% off

#

i will just wait for black friday

narrow yew
#

I assue it is explained further up from past days if you just look.

tribal bison
#

no no it ok i got it

ripe sleet
narrow yew
#

Matt friends

sage pulsar
#

hi guys

#

im new

sturdy sequoia
narrow yew
sage pulsar
torn olive
#

anyone seen comet-perplexity.ai? offers too good of a reward in discord quests, I wonder how much data they are vacuuming

๐Ÿ’€ downloaded new ai-browser, kept it for 15min, deleted everything, hit them with GDPR request ๐Ÿ’€

cant wait for new fireship video....

narrow yew
ripe sleet
sage pulsar
#

tnxs

ripe sleet
#

@cloud quiver

grim sparrowBOT
#

Done!

cloud quiver
ripe sleet
twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 5972)

queen flare
#

I wonder if i can use a VM for the quest

#

install discord on a vm and do it

#

lmao

torn olive
#

to be fair some banks offer up to 50 for registering, but yeah, I dont trust it

queen flare
#

or maybe download the browser on my host and then block it with firewall and keep it open to do the quest

torn olive
#

@cloud quiver

grim sparrowBOT
#

Done!

queen flare
#

how are unverified users posting images

sturdy sequoia
#

it just stops embeds afaik

queen flare
#

it needs more stopping power

#

a desert eagle can be considered

torn olive
boreal scarab
queen flare
rapid merlin
#

Hello

torn olive
#

im just interested how much they got on me during 15min...

torn olive
#

some things are better, some are worse

queen flare
#

i'm curious

worn gazelle
#

just seen someone with a HTB hoodie in my unie

queen flare
#

buy em a coffee

bitter olive
#

hello people

#

I want to share this video

#

Lex Fridman Podcast full episode: https://www.youtube.com/watch?v=qjPH9njnaVU
Thank you for listening โค Check out our sponsors: https://lexfridman.com/sponsors/cv9339-sb
See below for guest bio, links, and to give feedback, submit questions, contact Lex, etc.

GUEST BIO:
Pavel Durov is the founder and CEO of Telegram.

CONTACT LEX:
*Feedba...

โ–ถ Play video
#

very interesting

torn olive
worn gazelle
queen flare
#

@torn olive how'd u calculate the 5 euro thingy

worn gazelle
#

way gift not working

sturdy sequoia
torn olive
worn gazelle
#

oh i removed that when I changed my email. i think

queen flare
torn olive
queen flare
#

they're likely paying more than the 700 orbs quests but it doesn't mean they have to pay 5 eur for each customer

torn olive
steel aspen
#

New set up

#

Don't mind the JH vid

hallow jolt
#

hello guys

#

how are you guys doing?

steel aspen
#

Good you?

rapid merlin
hallow jolt
#

i see

#

how many do you have now?

modern fox
#

sup sup

boreal scarab
tall vine
#

g9 everyone

torn olive
pseudo surge
#

hello

pseudo surge
#

any python developers

weak badge
#

Any good ctfs / vuln labs for Wordpress? Or some kinda docker image I can pull down thatโ€™s intentionally vulnerable and a good representation of how people are using wp these days?

hallow jolt
#

nmap is the goat

wraith pivot
#

Hi I connected thru openvpn when I try to go to the target machines website http://targetmachineip it loads forever

#

Anyone knows why?

rich jackal
#

DId you power it up

undone kiln
#

try to ping the machine ip and see if your properly connected to the openvpn

quasi karma
wraith pivot
#

Guys of course I turned the machine on

#

And yes I was connected to the VPN

#

Don't know why it just didn't want to work

rich jackal
wraith pivot
#

That's an example

rich jackal
#

it changes when it has an actual IP Address

wraith pivot
#

I know it had an actual ip

#

I pressed on it and it just loaded forever

#

And after some time the website timed out

boreal scarab
#

I need coffee

wraith pivot
#

I found the same issue on reddit

undone kiln
#

did you ping it?

narrow yew
#

ill ping you

undone kiln
#

@narrow yew

limber linden
#

Yo

rapid merlin
#

Ok

limber linden
undone kiln
narrow yew
#

Better to report all gif kids

limber linden
#

Why I cannot post anything here

undone kiln
#

cause youre a racist

sturdy sequoia
limber linden
#

Ohh

#

Right

#

I didn't verify my account

limber linden
sharp citrusBOT
limber linden
#

@undone kiln

#

@undone kiln what do you call a man is from Senegal

undone kiln
#

@mossy river being racist to indians

rapid merlin
#

no

glacial berry
#

You both Indians?

limber linden
#

Yo

mossy river
undone kiln
#

it is worse

limber linden
#

Don't do racism

glacial berry
limber linden
#

We are all human

rapid merlin
#

im sorry i wont be racist

#

pls dont ban me

limber linden
#

@undone kiln answer my question

sturdy sequoia
#

there should be a no tolerance on racism

limber linden
#

Yes

grim sparrowBOT
#

@rapid merlin has been warned.

undone kiln
#

what'

#

@mossy river

#

atleast mute him for a day

glacial berry
boreal scarab
#

Let the mods do their job people!

#

Move on, situation is over.

mossy river
mossy river
#

He didnโ€™t call you a pajeet.

limber linden
undone kiln
limber linden
mossy river
#

His message wasnโ€™t directed at anyone hence the warning and not immediate ban

boreal scarab
glacial berry
#

Why not let it go this time

limber linden
mossy river
limber linden
boreal scarab
mossy river
limber linden
#

@mossy river can you tell me why I cannot post anything in this server

tired wolf
glacial berry
mossy river
glacial berry
#

It has those carbon chunks, right?

limber linden
#

Please

sturdy sequoia
#

its right there

limber linden
#

๐Ÿ˜ธ

sturdy sequoia
#

are you trolling?

boreal scarab
#

Whats with little kids and trying to relate to adults? Like i'm working on ipads, and the kids feel the need to tell me they have ipads

#

I swear, it's like they're on autopilot telling you stories lol

distant robin
sturdy sequoia
sharp citrusBOT
loud orbit
#

Sup chat

distant robin
distant robin
modern fox
sturdy sequoia
#

anyway

winged nimbus
boreal scarab
#

Anything but telling me they have an iPad case like the one iPad i'm holding has

#

I. DO. NOT. CARE.

sand trench
#

we are in the last day of the dino run 2 kickstarter

#

looks like we hit some stretch goals but not all D:

winged nimbus
sand trench
# winged nimbus what is it?

old flash game where you run from the wall of doom after the astroid that killed the dinos hit
this is the sequel made in unity
they have a lot of stuff planned and some stuff already working

winged nimbus
#

like the no internet dino

boreal scarab
#

They put on a video for the kids to keep them occupied... it's working on me.

sand trench
winged nimbus
winged nimbus
sand trench
distant robin
boreal scarab
sand trench
#

if you wanna check out the kickstarter

winged nimbus
sand trench
#

pixeljam are the good guys :D

queen flare
#

anyone wanna vc?

sand trench
queen flare
#

i'm so bored

boreal scarab
#

I'm Duck Rhysider. And this is Ducknet Diaries

boreal scarab
#

I was busy this year lol

modern fox
winged nimbus
boreal scarab
winged nimbus
#

fair

#

is jack even his real name lol

#

it is 3am and there is like a fucking duck or something making sounds that sound like a duck

#

outside

coral lynx
#

Guys why tryhack content don't make me professional at cyber security and Dont deep in vulnabilitys

sturdy sequoia
#

what?

boreal scarab
winged nimbus
#

kinda sounds like a duck being attacked by a large rat or something

winged nimbus
#

if it is a rat

boreal scarab
winged nimbus
boreal scarab
rapid merlin
#

is there anyone can hack fr?

winged nimbus
#

I havenโ€™t uses unity in years and i just got a vulnerability report which is interesting

sand trench
#

well seems shadow "fixed" 1 problem but now got new problem :P

rapid merlin
boreal scarab
#

Thats Social Engineering

zinc aspen
#

.

stable pier
#

HI

zinc aspen
#

hlo

stable pier
#

SATORI SEDAI YORU WASHUKAI

modern fox
#

holy tough storm we have omg

mental kraken
#

hello people

#

I am solving OWASP juice shop

#

and i think this room is bugged

#

it doesn't want to give me the flags for the XSS's

#

can someone help?

loud marlin
mental kraken
#

ty

smoky sail
#

@small kernel
t'as dis quoi dans mon dos ?

topaz sedge
smoky sail
#

why ?

loud marlin
topaz sedge
#

cause its the rules

smoky sail
#

k

mental kraken
#

the room is literally broken

mossy river
#

It's all voluntary, there is no expectation for anyone to help you ๐Ÿ˜…

mossy river
topaz sedge
mossy river
#

No worries ๐Ÿ˜„

frozen gull
#

what do y'all think of portswigger labs

#

worth it ?

#

and the certif as well

mossy river
#

Mhm of course

frozen gull
#

so

#

hmm

#

do u get any kind of certif by doing the portswigger labs

#

instead of paying that 99$

hoary pasture
#

chat

#

do we have any new update on owasp top 10?

#

or is it 2021?

sand trench
#

2021 newest for now

#

in novemeber they will release a 2025 version

hoary pasture
#

oh oh alr ty

sand trench
#
echo "enable privacy extensions for ipv6 in networkmanager"
echo "[connection]" > /etc/NetworkManager/conf.d/10-ip6-privacy.conf
echo "ipv6.ip6-privacy=2" >> /etc/NetworkManager/conf.d/10-ip6-privacy.conf

echo "disable connectivity check in networkmanager"
echo "[connectivity]" > /etc/NetworkManager/conf.d/11-connectivity-check-disable.conf
echo "enabled=false"  >> /etc/NetworkManager/conf.d/11-connectivity-check-disable.conf

work in progress much :D

#

probably better ways to do this actually but whatever

frozen gull
hoary pasture
frozen gull
#

peeepee

soft salmon
short cove
#

Hello if anyone can get me a $15 steam gift card i can paypal them 50$ but i need it quick, pls dm me

ashen summit
#

Hey guys, anyone recommend a quality VPN for hiding your IP.

ashen summit
#

Case?

#

Is that a VPN?

#

I'm still a bit of a newbie by the way.

silver sky
loud marlin
#

why you wish to hide you ip for start

silver sky
#

and don't just say hiding my IP

ashen summit
#

I'm going to hack Amazon.

silver sky
#

Oh fascinating

loud marlin
ashen summit
#

Just curious. I was watching the Youtube guy who hacks people. He said he uses Nord VPN.

silver sky
#

Please standby, a senior adviser will be with you shortly

loud marlin
#

you think to hack amazon, and i can't hack my own lab and get banned by fail2ban

ashen summit
#

Jeez....I can barely get through John the Ripper on basic.....๐Ÿคฃ

loud marlin
#

by hide you ip in sense doing bad things, vpn will not do you good... for start

frozen gull
#

holy sh8

ashen summit
#

I would love to do what that guy does - on Scammer Payback. Those videos are awesome.

silver sky
#

That's still a criminal offence

ashen summit
#

He must do it with law enforcement.

silver sky
#

We don't discuss or engage in such activities

ashen summit
#

I wonder how else he does it?

silver sky
loud marlin
#

you know that he have many legal things in backend by doing that. he is not doing that for the lolz

ashen summit
#

Is he not? But 4 million hits!

silver sky
#

Doesn't mean it's legal

ashen summit
#

8 million subscribers!

loud marlin
#

sub/hits means nothing. illegal is illegal

silver sky
#

I could hit the front page of the news for a crime and be seen by millions but doesn't mean it's legal because so many people saw it

ashen summit
#

I guess I'll never know.

silver sky
#

I'm telling you now, it's not legal

ashen summit
#

I know. I was just curious.

loud marlin
silver sky
#

And there are those who work in law enforcement here.....

loud marlin
silver sky
#

And more than likely three letter agencies too

ashen summit
twin ridgeBOT
#

Gave +1 Rep to @silver sky (current: #36 - 295)

ashen summit
#

So what are the rules on port mapping?

silver sky
#

If it's your network or a network you have a legal contract with, sure.

#

Random network is a no no

solar skiff
ashen summit
#

I guess that's how professional Penetration Testers do it then?

silver sky
#

Not even written permission, a legally binding contract that has been reviewed by solicitors

silver sky
#

Don't get yourself stung

solar skiff
#

Ok, fair enough

silver sky
#

And also make sure you have adequate insurance.

stoic quarry
loud marlin
#

getting visited by 3 letter agencies is not fun....

silver sky
#

Or getting sued for millions because you fucked up

loud marlin
#

tru tru

stoic quarry
#

Your honor I didn't mean to

silver sky
#

As Zoz famously said "don't fuck it up"

#

That was a great DEFCON talk

loud marlin
#

link it pls

silver sky
loud marlin
#

oh.. the guy who decide to find his laptop ๐Ÿ™‚

devout cove
#

most likely if you port scan a big entity, they won't sue you / get a 3 letter agency visit... cause most likely they get port scan a crazy amount of time per day that they can't take action against everyone.. Probably they will simply block IP / automatically set some extra rule for your IP to block / rate limit / audit for more suspicious activity, and as you get more persisting and attempt more stuff, they will probably escalate to more drastic legal action

Most enterprise have IPS that are configured to log/audit/enforce different set of action on different pattern/behaviour (Like port scan / fuzzing around / trying to inject known exploit... for example STI, SQL injection and other). The more you persist/poke hard, the more they will look at you closely and may react with legal action

AKA its a bad idea to attack an enterprise cause what you think is just gentle/for fun / think has no consequence may at some point go above their tolerence threshold and trigger legal action. They will notice, they have the tool to monitor. You don't know what is their tolerance threshold...

silver sky
#

That was also a good talk

#

Samy Kamkar - How I Met Your Girlfriend
How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend.

This includes newly discovered attacks including HTML5 client-side XSS (without XSS hitting the server!), PHP session hijacking and random numbers (accurately guessing PHP sessio...

โ–ถ Play video
boreal scarab
ashen summit
#

Wow! I saw about people in England being extradited to America for hacking. Imagine being in an America jail!

#

All for scanning a port!

ashen summit
#

I had a scam call once from India and was like 'Ben Chod!' They soon hung up ๐Ÿคฃ

silver sky
#

Cool story thank you for sharing.

silver sky
sand trench
grizzled sky
#

and yeah one of these days i should go watch through the best talks from defcon;

#

i am still working my way through the podcast darknet diaries;

dark wolf
#

Should I go back and spam post the 200+ THM rooms i have done on my linkedin?

zealous socket
devout cove
#

An interesting topic lately... Kernel level Anticheat... AKA lets try to make PC like a game console, a sandbox where user is limtied on what he can or can't do with his device, while also introducing a host of issue.

Kernel level DRM where the user don't control his computer anymore... Valorant/BF6's Anticheat solution that may be incompatible with AV solution, and incompatible with each other, and also prevent user from installing legitimate software. The kernel Anticheat used by BF6 for example prevent the installation of process monitor by windows systinternal. They are trying to make PC like a game console, a sandbox environment where its a blackbox/trusted environment where the user is limited in what he can do / not do. But this open up the door for some backdoor / supply chain attack. Oh, also since the Anticheat of BF6 also need control over the secure boot, it may also have compatibiltiy issue with dual booting with linux

dark wolf
# loud marlin no

you are right. my 676 connections probably donโ€™t care and will unfriend me

grizzled sky
dark wolf
#

RIP EA

modern fox
dark wolf
#

not gonna happen

grizzled sky
#

the funny thing is i probably still have more experience doing the thm rooms with those skills than most of the people who just copy and paste the requirements of a job posting to their resume and hope they don't get asked about it at the interview;

modern fox
grizzled sky
#

thm actually forces you to have to use the tools enough to understand them, as long as you didn't copy and paste the answers;

dark wolf
dark wolf
#

That is why listing certifications and completion certificates. Donโ€™t always help very much. Having experience means a lot more.

devout cove
#

My bad, i said DRM when what I wanted to say was Anti cheat, just corrected it

dark wolf
#

Once you get into a position, and they see what you were capable of, then you have a chance to shine and show them what you really know

grizzled sky
#

in my case i did freelance for 10 years in it;

swift prism
#

Does tryhackme have a referral program?

devout cove
#

At this point, if a game require any kind of intrusive Anticheat, I would rather play that game on console, or not play the game at all if that game isn't worth it. Nothing worse than some problematic Anticheat on my computer. No way i would compromised my computer because a company think they will stop cheater using a kernel anti cheat. Cheater will find way around it, but legitimate user are penalized. Its a big security breach

grizzled sky
#

so even if i didn't do on site experience in a soc or something official, i easily have more than enough experience between my certs and from going to senior homes and volunteering to help set up wifi and security for seniors in my area;

glacial cove
grizzled sky
#

its also why i strongly recomend getting in contact with senior homes if you are new to cyber and looking for clients. seniors at least in my area always tip well if you are nice;

modern fox
grizzled sky
devout cove
restive pike
#

I heard gen z Rust Programmers use anime girl pfp

grizzled sky
#

kernel level is the most egregious, but running any software on your pc is inherently a security risk that windows doesn't really have a good solution for besides hoping that steam and other large storefronts for games and software doesn't allow malware on its platform;

dark wolf
frank talon
#

Anyone interested in helping me ideate a project please dm me
the base idea is an 'adversarial AI attack defender focusing on the healthcare niche'
Im not an expert but erm, would appreciate if youre down to discuss in dms

grizzled sky
#

if you're saying defending against ai, its called a firewall;

#

ideally healthcare shouldn't be exposed to the outside internet at all;

frank talon
grizzled sky
#

llms are not doctors;

#

they shouldn't be used for health care purposes period;

#

actual machine learning absolutely is good for health care though;

#

but llms are not secure as a tech enough to be relied on for life threatening access to patients;

frank talon
# grizzled sky llms are not doctors;

yes true but healthcare firms are moving towards AI like any other fields
not to take direct decisions but mainly to assist them in safe tasks
take ibm watson for example

well yeah not specifically AI but ML models too

grizzled sky
#

ml security is a different beast;

devout cove
# grizzled sky yeah that's part of the reason i game on linux. every game is sandboxed;

I play most of my game on either Linux (Game that are better on computer) or on Console (Game that play better on console, have intrusive anti cheat, or game that have nasty DRM on PC (On console, game don't need DRM, since they used the console built-in one... )...From Kernel Anti cheat that compromised your computer while restricting what you can or can't do in your computer like in BF6/Valorant ... To DRM that make the game super slow... Remember Assassin creeds in 2018 or so, the game would barely hit 60 FPS with some of the best GPU, while it would run super fast and look nice on console, because of the DRM that was super ressources heavy

glacial cove
# devout cove The stupid thing is a kernel anti cheat basically behave like an active threat p...

My friend, game hackers have already gone the extra mile actually ๐Ÿ˜ญ

The exploits I'm aware of against kernel-level anti-cheat is above that of EDR + Antivirus. Hackers are currently using hardware and PCIE devices to write straight to the memory of a live PC from that of an external Linux device

They use display merging hardware and a 2nd machine to draw ESPs for example and then combine the outputs using specialised hardware

Or use programmable macro devices to merge legitemate input with automated scripted keystrokes

It's insane ๐Ÿ˜ญ

frank talon
grizzled sky
#

it'd be the same whether ml is involved or not;

#

hash the datasets;

frank talon
devout cove
grizzled sky
loud marlin
#

proxmox โค๏ธ

grizzled sky
#

at a foundational level, there is no securing them for anything life threatening;

ashen summit
frank talon
grizzled sky
#

we don't understand them enough at this stage to be able to verify if they have been modified in a malicious way;

#

databases we can verify with hashing;

#

or simply backups;

#

if llms are foss, we could theoretically hash them and have each prompt be untied to each other so that it reverts to its default each time;

frank talon
grizzled sky
#

but then they are just only able to output 1 thing, and that still means verifying the outputs and inputs;

frank talon
#

how about evasion attacks on ML models?
manipulating input data during inference time to trick a machine learning model into producing an incorrect output, such as misclassifying a normal-looking image

devout cove
#

i feel the whole LLM security (company trying to protect against injection / people specializing in prompt injection) kinda pointless / stupid, cause its impossible to ever have a fully secured LLM, thus in the first place, LLM shouldn't be able to take action (Like modify stuff / run shell command) and shouldn't have access to any sensible/confidential data

grizzled sky
#

ml afaik doesn't rely on manipulating the datasets meaning that as long as you authenticate integrity of the datasets you should be safe from malicious edits;

frank talon
grizzled sky
#

i don't know enough about ml to be certain though, if anyone has experience with that i'd be interested to know;

#

i have some experience in llms from the research i'm working on as a part of trying to specialize into mcp security, but ml is outside what i have direct experience with;

frank talon
#

I mean adversarial training exists anyway
like tesla uses it on its autonomous vehicle systems to avoid misinterpretations of road signs
training on "corrupt" data
like sometimes the stop signs might have stickers on it or the paints come off and it might trick the car into assuming the sign as something else
well this is an old solution I guess nothing new

grizzled sky
#

tesla isn't a good example for security imo;

frank talon
#

for context I was considering this idea for a capstone project ๐Ÿ˜‚
welp idk

grizzled sky
#

though that's more cause of elon than anything the actual engineers are doing;

frank talon
#

if yall got anything fire lmk, I try to build up on ideas

grizzled sky
#

in my case, i am specifically focusing on mcp;

frank talon
#

fair

grizzled sky
#

that keeps me focused on 1 part of llms rather than trying to breadth out into every area of its security;

#

since we simply have too much we don't know about it from what i have seen and read so far;

frank talon
#

but its kinda tough coz the judges look at the solution from a business perspective so I gotta find a balance between something too niche and too generic

grizzled sky
#

mcp at least is grounded enough since its parallel to api security;

frank talon
#

right

grizzled sky
#

so a lot of it is just applying the same protections as api;

#

the big added issue to security is vibe coding;

#

and specifically people using llms to automate creating api connections and thus not considering the endpoint security needed;

frank talon
#

yeah and its increasing daily

grizzled sky
#

for mcp to work as a protocol, there needs to first be some security in authenticating what mcps are verified, and thus working with the companies creating api to create official mcp with proper security imo;

#

but of course that currently isn't happening so its the wild west where any mcp created could be secure or insecure;

frank talon
#

whatever I see as a problem, I immediately think of a potential solution
maybe theres a counter to faults made from vibe coding

grizzled sky
#

the biggest one is building in checks into vibe coding;

#

if we could even just ensure that these models built in unit testing to the software they build, that would go a long way;

frank talon
#

how about a software to automate testing on vibe coded solutions

#

hmm

grizzled sky
frank talon
#

lol

grizzled sky
#

like in javascript there's jest for instance;

frank talon
#

yeah jest

#

or integrate it directly into AI chatbot but thats just like trying to solve the problem after creating the problem which couldve been avoided in the first place

#

eh

#

yeah that sentence. didnt make sense

#

xd

grizzled sky
#

the main thing is training vibe coders to actually read the tests if not the code itself;

frank talon
#

but yeah thats bare minimum else we all cooked

grizzled sky
#

the biggest issue imo is vibe coding is incentivised from speed being the main incentive financially for coders;

frank talon
#

yup

grizzled sky
#

as long as we are paid in salary or hourly, the incentive is fast vs good;

frank talon
grizzled sky
#

that's also why i think the root of all of this is capitalism, the financial incentive is the core vulnerability that created vibe coding imo;

#

basically there needs to be tools for employers to be able to identify bad code much more than just for vibe coders to create it;

#

and that means effective unit testing and tools for mangers;

dark wolf
#

you know what's a little frustrating the more rooms I am doing ....

frank talon
dark wolf
#

I find errors that are clearly wrong and a problem. There is a bug-report forum here for that I think.

grizzled sky
dark wolf
#

But there are almost never replies so why waste my time showing where the errors are

#

When no one will read it or fix it

grizzled sky
#

and people aren't being trained on how encrypted keys work and to keep them private in .env files;

frank talon
dark wolf
#

The writeup shows another port open .. the answer

grizzled sky
#

either way this is still an area i am only just starting to dive deeper into;

frank talon
#

fairs

grizzled sky
#

but its been fun and my hope is i can create something valuable that will also hopefully help me find work;

rapid merlin
#

any experieced and potenial hacker here?

dark wolf
grizzled sky
#

i do think you have the right idea though, trying to work on real issues as a project is always more fun than tutorial hell;

rapid merlin
dark wolf
#

What do you need DR Black?? Read the #rules before asking

#

Be VERY careful about what you ask!!

frank talon
grizzled sky
dark wolf
grizzled sky
#

llm is not ai, its a prediction algorithm;

rapid merlin
frank talon
dark wolf
# rapid merlin whats this?

It means don't ask a question for the sole purpose of asking a question. Just ask the question you want answered to begin with.

grizzled sky
#

btw for those wondering the difference, this goes into it well;

#

tldr; real ai is solving problems that don't have answers, predictive models like llms are just using data that already exists to make predictions, in this case predictions of what word should come next;

#

that's not to say llms aren't impressive when used correctly, but they are also not trying to answer problems that we don't already have answers for the way robotics is trying to teach robots how to answer and ideally solve new problems outside what it was trained on so far;

dark wolf
#

AI can't determine if the answer is right. Humans can verify it and coach the AI telling it what it did right and wrong and then AI can try again until it solves it.

frank talon
#

Ig agents are more useful

#

when u give fine tuned llms agency to do a specific task and work in harmony with other agents

#

tho the inaccuracies with most LLMs dont give us hope

sand trench
#

YAWN

dark wolf
low flame
#

i need help

#

can someone?

grizzled sky
#

Me but playing with homelabs;

dark wolf
sand trench
low flame
#

umm...i m in john the ripper basic

dark wolf
low flame
#

and i am not able to usee it

dark wolf
#

why not? do you get an error

low flame
#

ya

#

see this

frank talon
#

wb bleeding jumbo

low flame
#

i was using the machine given in the room

sand trench
# low flame

the john and hash id commands are meant to be run on the attackbox or your own kali linux install
not on the target machine as user

low flame
#

ok

#

so i also need to run attackbox side by side?

signal widget
#

Is there anywhere I can learn A+ ?

#

For free

sand trench
low flame
dark wolf
#

Also keep in mind that some of the "examples" are just that .. ."examples" sometimes you have to modify the command to match your environment

sand trench
low flame
#

ok

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2229)

sand trench
#

no problem

low flame
#

but those questions in room are too ez, i just guessed them by length, and used hashes.ccom for hash

sand trench
#

fair... you can do that
just you are losing some of the learning opertunity by not doing the exercise as explained

low flame
#

yeah

#

thanks for help guys

sand trench
#

you're welcome

polar shale
signal widget
polar shale
signal widget
#

Sick thanks

polar shale
polar shale
wispy geyser
#

@ripe sleet i have to go cause my phone number is causing me to be rate limited

#

but i will stay in the server

ripe sleet
#

If you ever need to contact me just dm me shyyHeart

summer sandal
#

Damn

loud marlin
tall steeple
#

hey guys needed some adive, theres a cybersecurity capture the flag event happening and its being hosted by my school. I signed up for it even though im a beginner and they accepted my application. Im worried if i go to the event that Im going to hold my team back as I am a beginner and dont have as much knowledge/experience in Capture the flag events (this would be my first one). However, I really want the experience and to network with the other people at this event. Any advice would be greatly appreciated!

rapid merlin
sand trench
loud marlin
#

heh

summer sandal
sand trench
#

also bet you don't know this ralex but worth asking
any idea how to setup fcitx in wayland???

umbral bay
#

๐Ÿ‘‹

rapid merlin
summer sandal
loud marlin
sand trench
#

due to a recent change

#

which sucks if shadow wanna use ghostty a lot

loud marlin
#

as far i know dont have issue with things at all so far

ruby fog
#

Hello how are you alllllll , iiiiii am in a bit of a dillma right now i was trying to automate some of my tasks but i found a vulnerability while doing so and i want report it , i dont know how to and how much details should i put in the report and all that

vague monolith
#

I just realized that I won 2 silver raffles. ๐Ÿ˜ญ

ruby fog
#

anyone got any advice on this ?

vague monolith
#

i just saw the mail ๐ŸคฃNotLikeThis

ruby fog
#

or girl xd

sand trench
vague monolith
#

But I don't think I'm in time to claim it anymore haha

ruby fog
ruby fog
sand trench
#

not ideal to send that kinda vulns over email but sometimes it is the only option

vague monolith
#

But I have no idea how. The event happened almost a month ago

ruby fog
boreal scarab
#

I swear. I hate this generations videos for kids

#

Nice artwork, cliche everything

ruby fog
ruby fog
boreal scarab
scenic oasis
#

#random - got a Sora2 invite code if anyoneโ€™s interested.

rapid merlin
sand trench
#

eeeh not that into making videos using openai

scenic oasis
#

All good - figured Iโ€™d ask. Seems to be all the hype on X rn

boreal scarab
#

I swear, Al Rocker is in this teaching kids about fall

queen flare
#

@torn olive looks like i don't have to actually use the browser for the quest

#

i can block it in with firewall and open it, and it still completes the quest

#

how the hell does this browser detect my other browser profiles though

queen flare
#

like offline files stored on my device that the browser looks for?

torn olive
#

Yep

queen flare
#

i lowkey like the music

sand trench
#

hahahah @boreal scarab is getting old and hating on new stuffs

queen flare
#

good thing that it plays offline

torn olive
#

It had music??

queen flare
#

yeah

#

i opened it and its playing music

#

still is

torn olive
#

XD

queen flare
#

i can show u in stream if u want

#

lmao

torn olive
#

Lmao gimme a sec

north sequoia
#

Giving someone a rare account if they can script something with python for me

boreal scarab
#

Wtf kinda name is that

north sequoia
#

Huh

#

Please

north sequoia
#

DM me

torn olive
north sequoia
#

Anyone just DM me if u can do python shit

#

I know the github page to get the scripts

queen flare
#

@torn olive can u hear music?

torn olive
rapid merlin
queen flare
#

can't really talk cause i don't have headphones connected lmao

#

feel free to stay and listen till i finish the quest though

tall steeple
queen flare
torn olive
queen flare
torn olive
#

minimal lightweight look

queen flare
#

@limber gust i'm here but can't talk

#

you're also definitely not a girl

rapid merlin
chilly veldt
#

๐Ÿ‘€

sand trench
#

work in progress continues :D

stiff geyser
sand trench
celest dirge
queen flare
queen flare
dark wolf
sand trench
celest dirge
narrow yew
#

Anyone done todays flags for huntress ctf?

celest dirge
mossy river
#

KFC pretty much hired a GenZ marketing team and let them shitpost

queen flare
mossy river
#

KFC UK & Ireland on Instagram is literally just memes and trolling, it's not even a business account atp

narrow yew
#

@quick blaze not even you?

mossy river
quick blaze
celest dirge
quick blaze
#

Huntress?

narrow yew
#

I am stuck

mossy river
stiff geyser
mossy river
#

Duolingo have been breaking the LinkedIn cycle but they were also the first people to do it on the rest of social media

quick blaze
sand trench
quick blaze
narrow yew
queen flare
quick blaze
queen flare
#

and give me some feedback

digital estuary
#

oh

#

his mesopotamian name is gone

#

ea nasir sells high-quality courses on cybersecurity ๐Ÿ˜ฑ

queen flare