#general

1 messages · Page 1776 of 1

narrow yew
#

why

#

Soon they are forcing Thales keys

loud marlin
#

my conmapy thinking to implement yubikey

sand trench
#

already using yubikeys for discord

narrow yew
#

I have Thales for works AD when not using phone for Auth

loud marlin
#

i need get my self one

#

will be nice to have one as implant with nfc/rfid or so

lament meteor
#

im surprised you don't like passkeys - is it a privacy thing?

#

yubikey is essentially the same thing as a passkey no?

#

they both use fido?

sand trench
#

in comparison to passwords plus 2fa key

#

if you ever try to backup passkeys you will know the pain

lament meteor
#

i use passkeys in bitwarden

#

it syncs

narrow yew
#

🙁 I broke my VM

lament meteor
#

did you take a snapshot? lol

narrow yew
#

No, i would never remember to do that

sand trench
#

eh could probably use passkeys in keepassxc too

lament meteor
#

i typically take snapshots... but then when I break something, I look and realize my last snapshot was like 6 months ago 😄 😄

narrow yew
#

GPT will help instead

#

Just dcoding b64 for a ctf

#

better to let AI sort it, saves me time

lament meteor
#

the new kali has gemini baked in... seems weird they went with gemini... still not sure how I feel about that

vast crystal
#

Hi guys, where’s the best channel to ask questions?

sand trench
#

echo "blkgwasiuhgnnseauioghoerasunig" | base64 -d

#

^ doubt this will give useful output as shadow just hit random keyboard keys

#
           へ         ╱|、
      ૮  -   ՛ ) つ(>   < 7  
     /   ⁻  ៸          、˜〵     
  乀 (ˍ,  ل            じしˍ,)ノ 
#

oof that not look right

austere verge
#

Well I can tell it involves cats

sand trench
#

cat 1 go boop cat 2

lament meteor
#

If I am trying to connect to THM with my OpenVPN config, does this "Connection" box only show connected if I go to this page of settings on the machine where the VPN is connected? I copied the openvpn config over to my kali box and it seems like it's connected fine. curl 10.10.10.10/whoami responds correctly

sand trench
lament meteor
#

thanks - i figured so

sand trench
#

the curl 10.10.10.10/whoami is the better test to see if you are connected

austere verge
#

I wonder why

#

Maybe it checks the wrong ip

#

Like if ur using a different laptop for vpn connection it wouldn’t have any way to know

#

And u have a vpn on main laptop

lament meteor
loud marlin
#

you can't stack vpn

#

only one vpn can be running

lament meteor
#

i don't have my laptop connected to the openvpn profile, i have my kali box connected to the openvpn profile and I'm connected to kali via ssh (no gui)

austere verge
# loud marlin you can't stack vpn

Na I mean connecting to thm with one laptop and answering questions/being signed into the website on another laptop running a vpn so the two laptops don’t have same public ip

loud marlin
#

is you host pc on some vpn?

lament meteor
#

no

#

im signed into THM on my laptop - kali is a vm on my host server (completely different machine from my laptop)

loud marlin
#

did you run vpn via ssh or on vm it self ?

rapid merlin
#

i just found a vulnerability in the xscreensaver app in linux

lament meteor
#

on the vm itself - i actually configured a service in kali to run openvpn with that profile so I could turn the vpn on and off as a service

#

curl 10.10.10.10/whoami is working, so I think I'm good, i just wanted to make sure

loud marlin
#

if that pass then you are ok

distant robin
lament meteor
#

yea, that worked, I'm good then

austere verge
#

Lmao

distant robin
austere verge
#

Yea I’m just wondering why the thing in the profile saying not connected might be bugging

distant robin
#

I'm also running Kali on my laptop too

loud marlin
#

oh thm profile can do that

lament meteor
distant robin
lament meteor
#

ah gotcha

#

thanks everyone

loud marlin
#

relay on curl command not them site

distant robin
#

I just learnt something new now

elfin hamlet
#

You can use deepseek to make malware?

sand trench
elfin hamlet
sand trench
#

well okay just gonna dip out there and no response

grave pine
#

Hi

sand trench
#

compile on the target machine
use the attackbox to compile
do static builds instead

#

are the most common solutions

#

quite a few of the target machines have gcc on there

sand trench
#

okay then that leaves the 2 other options

#

gcc -static blargh.c

#

yes shadow likes to use blargh as example texts because it is fun to pronounce

#

but living off the land and using things found on target machines against target machines is generally best bet even in real world pen testing and red teaming

#

fair... shadow knows very little about programming but got decent understanding of compiling

elfin hamlet
#

Where did most of you guys start with your ethical journey?

sand trench
lament tendon
elfin hamlet
#

As in getting into ethical hacking.

grave pine
sturdy sequoia
#

i dont really know how to answer. it was just a hobby i was interested in so i researched and experimented.

sand trench
#

hacker mindset was early in shadows life

#

A hacker embodies a boundless passion and insatiable thirst for understanding the complexities of a system, computers and networks in particular. They revel in the pursuit of knowledge and mastery, constantly seeking new solutions and opportunities for growth. Their drive and innovative spirit inspire and are inspired by the hacker community, where ideas and knowledge are freely shared and valued regardless of their origin.
--Silk

elfin hamlet
#

Which sources did you generally use? Other than tryhackme or hackinthebox.

sand trench
#

if that is what you are wondering for site hacking

sturdy sequoia
elfin hamlet
#

Hm okay cool, any decent reads you can reccommend? I want to expand my knowledge a bit

sand trench
#

also for fun watching defcon talks

sturdy sequoia
sand trench
#

but if you want instant recommended reading from shadow:
extreme privacy what it takes to disapear 5th edition

elfin hamlet
#

Thanks! I have knowlege from around 2020 and onwards🙂 only really got into computers then

little pond
#

hello i am getting an error of ``` error on word restored: timeout occurred during the request

sand trench
#

that playlist is a lot of fun according to shadow

#

which is the one ordering it

little pond
lament tendon
#

That was what got me interested in Red Teaming back in the day. :D

sand trench
#

it is not just a single video

lament tendon
#

I am guessing, but you could try.

sand trench
#

figured it out

lament tendon
#

Seems that was correct.

#

Also based.

#

I wonder whether people can tell that I am bored yet.

zealous socket
#

When it's quiet here, either everyone is asleep or solving room's.

#

A silence

lament tendon
#

Silence broken.

zealous socket
zealous socket
twin ridgeBOT
#

Gave +1 Rep to @lament tendon (current: #41 - 267)

sand trench
#

mpd-discord-rpc is unintentionally goated

lament tendon
#

It's pretty dang good.

#

Did turn it off for privacy tho.

#

Did you know that you can design custom applications via discord dev portal for that and then just run a python script with an inf sleep in order to display literally whatever you want?

#

Neat little trick to look cool on Discord. xD

sand trench
#

yeah...

#

shadow leaves it on as an example that you can get music recommendations from shadow in the same way people do for spotify

lament tendon
#

Whaha

#

What application are you using anyways?

#

I pivoted from that TUI player you recommended to just using Navidrom through the browser when I am at my desktop.

#

UI's pretty decent.

sand trench
#

currently using rmpc

#

which is a mpd client

#

using beets to manage the music files though

blissful snow
#

Hi does anyone know anything about demon linux

lament tendon
#

The distribution or a daemon process?

blissful snow
#

No

lament tendon
blissful snow
#

It a debian based projected

#

I cna't find the iso

lament tendon
#

I see. No, then.

blissful snow
#

I wanted to try it

#

I gave up after install it bare metal when it was recommend to do it in vmware lol

loud marlin
blissful snow
#

I can't find the iso there for some reason

#

I went to there github and it still didn't give mea download linux

sand trench
#

there is no iso on that site D:

blissful snow
#

yeah idk why it just sends me back to the website

loud marlin
#

well... they say new release cooming soon

blissful snow
#

been like that for a while

lament tendon
#

Is there any reason why this would be better then just default Kali?

blissful snow
#

idk just wanted to try it

wary ocean
#

You get a cool little demon with you

blissful snow
#

i do have kali install for my vbox to

lament tendon
sand trench
#

default kali or parrot os is probably more userfriendly for now

lament tendon
blissful snow
#

lol

sand trench
#

also seems they like to use a consistent colorscheme/theme with dracula ;D

blissful snow
blissful snow
#

i just wanted to make sure they didn't have a iso some where that i didn't know about

sand trench
#

fun way to potentially break software:
git commit --date

ripe sleet
sand trench
#

ello darkfly

ripe sleet
sand trench
#

kinda tired but also writing things

#

systemd service sandboxing is whacky

spark geyser
#

Hello everyone, I’m new to chatting in this space (not sure if this the right place to ask this). I see there are tons of tools and resources out there, and I honestly get a bit overwhelmed by all the choices. How do you all handle this? Where should someone new start when it comes to learning these tools, and what are the key fundamentals or core areas you’d recommend focusing on first? I know some networking (not crazy tho) and comfortable in the command line, at least with the role that I'm doing right now, but I have always had interest in cyber space, just curious

sand trench
oblique loom
#

I finally fixed my SSH port on my server and can connect over the internet, sweet!

sand trench
oblique loom
#

I act already have that

#

Also my SSH doesnt use password xP

#

Keys only

sand trench
#

niceu

oblique loom
sand trench
#

don't see why it would not work with a vpn tunnel

#

unless you are refering to jump boxes to access said machine

oblique loom
#

Im about to find out

#

Nope

#

Gonna try again

sand trench
#

shadow is in the uncanny valley of understanding :P

spark geyser
#

thanks for the feedback, I'll def have it mind. I have been doing some of my own docs gitbook so far it has been good, trying to get RHCSA since in my job will be valuable, but I have always liked cyber roles as well

sand trench
#

well enjoy the journey and learning new things every day :D

#

and time for meepy mooopy sleep sloop to beep boop while merp morp

lunar bison
#

Hello there

#

I want someone who could help me hacking and i would pay them for that

sturdy sequoia
#

this isnt really the place for hiring hackers

fervent cove
#

but what else is this place for

#

i dont come here to learn

gritty pasture
#

task 6 for metasploit is frying my brain

#

exploit

final cobalt
#

are the blue team career paths good ?

#

are they as good as lets defed.io for exmaple ?

loud orbit
lament meteor
oblique loom
#

So ive been thinking. Idk if the pentest route will be a good fit for me. Even tho I can do a thing or two

#

Seems super stressful and clients want the cream of the crop

#

HTf you beat that?

lament meteor
#

You could always bug bounty and be your own boss

oblique loom
#

Tbh could just go back to g*******ing

#

Bug bounties aint gonna pay bills

#

You'll make more doing Door Dash

lament meteor
#

ok

oblique loom
#

I used to do it back in the day

#

I got good tech

#

Maybe I'll get lucky like with NV Medicaid

#

Their stupid SQL injection lol

#

(They patched it btw, but was total accident.)

fervent cove
#

what is g***ing

oblique loom
#

Greyhatting

fervent cove
#

ooh

oblique loom
#

I didnt want to say it cause taboo n stuff

fervent cove
#

yeah but i thought it was something else that seemed more strange in context lmao

oblique loom
#

Sorry for that then

#

I truly meant greyhay

#

Greyhat

#

Grayhat?

#

Idfk lol

fervent cove
#

atleast its not goon

rapid merlin
#

public discord servers have their messages scraped and indexed so i wouldnt talk about that stuff

oblique loom
#

Told ya

bitter patrol
#

Whats a good OSINT tool to search up my name im a newbie to all this and wanna find out what comes up

bitter patrol
#

Ill try both and lyk how it goes 😅😄😬😥

oblique loom
#

Dont get banned by ISP if you go the dorking route

#

Itll happen

fervent cove
#

what why

oblique loom
#

Happened to someone I know

#

Also

fervent cove
#

google dorking is just using google more effecient lol

oblique loom
#

Google doring can expose tons of stuff

#

ISP get paranoid about it

#

Youll commonly encounter capchas

fervent cove
#

i mean if ur doing it illegally then yeah

#

but thats not google dorkings fault

oblique loom
#

Never said it was

#

It just exposes stuff you wouldnt see

#

Normally

#

I used to find all kimds of crap with that sht

bitter patrol
#

Uhm well i used sherlock and it just gave me a list of usernames including one of mine but nothing connected to it like posts etc i was expecting a spider diagram of all the bad things i did in my life

#

Im very happy no such spider diagram exists

oblique loom
fervent cove
oblique loom
#

Ayy spokeo

bitter patrol
#

This stuff makes me very shaky

oblique loom
#

I use that

bitter patrol
#

Brb

fervent cove
#

yeah fuck whoever sold my data to spokeo

oblique loom
#

Same lol

#

Bastards

bitter patrol
#

It seems that everyone else who shares my name is a woman

fervent cove
#

oof

#

hi jordan

bitter patrol
#

I think im all clear

#

Well except for advanced tools

#

Which every cyber security hiring company will probably use

fervent cove
#

ur full name?

#

i bet some pyblic database website has you atleast

#

oh, well are you not american

#

ur a ghost then

dreamy bronze
#

I searched my number once and legit found my street address 🫩🫩

#

Should not be that easy bruh

fervent cove
#

its fine ai will kill the internet by 2035

bitter patrol
#

I use chatgpt more than i use the internet and i give it so much data

#

I hope they give that to my future employers though

#

Very studious over here

chrome condor
fervent cove
#

ai layer 3 information cycle inc

bitter patrol
#

Ive probably done that on accident knowing me just taking pics of whatever comes up on my commandline

#

Im such a noob i know

#

I only use it when im stuck and then i try to learn why I got stuck so its okay

fervent cove
#

yeah but what if ur gpt confidently lies to you

ripe sleet
dreamy bronze
#

just read the output and try to understand it because using ai will make your brain mushy

lament meteor
#

if i get a cert and want to "print it" or share it, does it pull my username or full name for the cert?

bitter patrol
wraith tusk
chilly veldt
#

hmmmm, to post or to not linkedin post

dreamy bronze
#

is it sora

lament meteor
#

it was a hot post on /r/aivideo

rapid gust
wraith tusk
blissful snow
#

heyyyyyy

dark wolf
#

Time to hack

ripe sleet
# lament meteor

My favorite is when Stephen hawking is in the battlebots and Einstein is controlling him

dark wolf
#

I once saw Stephen Hawking climb a wall with no rope

#

He's bad ass

#

If you don't believe me, I have a blind friend who also saw it

#

I had no idea until my deaf friend heard all the commotion

lament meteor
#

does anyone have an online tool for cracking hashes? hashes.com is down and this hash isn't in crackstation - it's for THM room Hashing Basics

topaz sedge
lament meteor
topaz sedge
#

or some tool like that

lament meteor
#

ok thanks

dark wolf
regal steeple
# lament meteor

Crackstation
Hashcracker

or you can identify the hash using hash-identifier and decrypt using hashcat -m 1800(use the specific mode by going through the hashcat page) hash(store the hash a file)

sleek hare
#

Can't you do that using john?

lament meteor
#

yea the hash is not on crackstation - I started down the path of john/hashcat - just odd the room says "use online tool"

dark wolf
#

multi tools

regal steeple
sleek hare
#

Amazing

regal steeple
#

john --format=md5 hash.txt

sleek hare
#

Yep

regal steeple
#

but u have to identify the hash format

#

i love cats

#

thats why hash cats

sleek hare
sleek hare
#

I remember using John for something in event horizon , so I thought it should be best solution (as it is the only tool I know how to use )

dark wolf
#

you don't have to identify hash type with john

#

it will try and gues it

deft oar
#

hello

#

Is there for game hacking server?

regal steeple
dark wolf
sleek hare
dark wolf
deft oar
regal steeple
#

is there a server? is that what you are asking

dark wolf
#

We are a cyber security Discord server

regal steeple
#

anyway it is a rule violation ig

sleek hare
#

Ig he's seeking a server for game hacks/cheats

dark wolf
#

we do not condone hacking, please read the #rules

regal steeple
sleek hare
dark wolf
gloomy tulip
#

cybersecurity is just a lot of research, agree or disagree?

deft oar
#

I'm leave now

upbeat herald
#

Cybersecurity is applied research

gloomy tulip
regal steeple
#

let me ask echo to clear my doubts

dark wolf
#

echo doesn't know its foot from its mouth

#

if you ask it it will say hello im here to help you with cybersecurity!

regal steeple
#

have ever any1 tried out HTB

dark wolf
#

a few have done htb on here, it's more difficult from what they say

regal steeple
#

their PWNBoxes are awesome and the loading time is ❤️

upbeat herald
#

Hackthebox is for intermediates at minimum, I wouldn't recommend it for beginners

rapid merlin
gloomy tulip
regal steeple
regal steeple
rapid merlin
upbeat herald
#

Hackthebox is amazing, just not for beginners

regal steeple
upbeat herald
#

Think of tryhackme like freecodecamp but hackthebox like leetcode 😂

regal steeple
upbeat herald
#

Both are amazing in their own way but have different target audience

regal steeple
#

absolutely

upbeat herald
#

For a beginner I can close my eyes and recommend thm without thinking twice

regal steeple
#

have fun with nodes my friends

upbeat herald
#

Where's cloud security 😔

regal steeple
#

devsecops for a later time

#

now i have to face a boss fight

upbeat herald
#

Thankfully I got a job but I am trying to transition into a niche

regal steeple
rapid merlin
#

what does mean by this

#

how

upbeat herald
#

I wanna focus on redteaming but specialising in cloud security

rapid merlin
#

htb is so confusing have you ever done that

upbeat herald
#

Because it's not for beginners genius

#

0/10 ragebait

#

I also recommend portswigger labs if you're interested

#

Best labs for web app pen-testing

#

I have way too many subscriptions rn XD

#

Can't add 1 more

#

I just mainly used portswigger, owasp juice shop, htb and thm for now

#

100% agree

#

I always go by this motto in life "Improvement begins at the edge of your comfort zone" and BOY does htb make me uncomfortable at times 😂

#

Do you take AI's help if you're stuck?

sleek hare
#

Same

#

But help while stuck? No

upbeat herald
#

I use AI for scripting n shit imma keep it a buck

#

But the general logical flow? Nope

#

We have to integrate AI in our career in one way or the other else we will simply be left behind in the race

sleek hare
#

💔 😭 sponsor of my past project wrote me he'll drop ipv4/6 sponsoring if I won't return

upbeat herald
#

GG

sleek hare
#

Cuz current owner is "unintelligent"

#

And whole infra relays on the sponsors IPs

#

fun

upbeat herald
#

Seems like you don't have a choice now 😂

sleek hare
#

My creation gets ruined by new owner

sleek hare
upbeat herald
#

Tough

sleek hare
#

But in the same time I don't want that project get fucked

#

Cuz a lot of apps and students rely on free AI API and VPS services

upbeat herald
#

What's your action plan now

sleek hare
#

No idea

regal steeple
#

does portswigger offer free courses?

sleek hare
#

I'm just 15, I'm not best person to handle huge projects

upbeat herald
#

The courses are free but to do some of the labs like for example using burpsuite intruder, if you have community edition u are heavily rate limited

sleek hare
#

Tbh he did nothing after I left the project 💔

#

He just acts sometimes stupidly

regal steeple
upbeat herald
#

Yeah they are like 1 liner labs

#

A simple ' OR 1=1 -- type shit 😂

regal steeple
#

<script>alert("HI")</script>

sleek hare
sleek hare
#

This happens when you let ai code

#

Free AI

regal steeple
sleek hare
#

Me too

upbeat herald
#

Bro I did a pentesting project for a client and their had their API key hard coded, let that sink in

regal steeple
#

but once a government website raised invalid entry

#

and some detection BS

upbeat herald
#

Most websites I've pentested were vulnerable to time based SQLi

#

Ye

regal steeple
#

rip mahn

#

do you know where to see latest domains bought

upbeat herald
#

Not sure actually

sleek hare
regal steeple
#

i want to try out the cyrillic typosquatting

sleek hare
#

Which could be used in backend

#

That was 1 minute compromise to admin panel

#

No jokes

#

F12 -> login field ID copied in admin -> search -> open script it found match -> look for id field there -> find the key 😭

upbeat herald
#

W

#

I mean L for the guy

regal steeple
#

is there some software to override recaptcha

sleek hare
#

Yea

#

I also in the end reported this to DPA cuz the website has no privacy policy whatsoever

upbeat herald
#

Nice

sleek hare
#

(no I wasn't hired, yes I did grey hacking that time)

#

Owner also got informed of that but he denied to do anything about it

sleek hare
#
  • data was possibly breached several times by that time
upbeat herald
#

I never got the opportunity to do white hat hacking

#

I mean white box

#

Oops

#

I always did black box so far

#

You'd be surprised how much info u can get by simply doing url/robots.txt 😂

sleek hare
#

Ik

#

I do that all the time

#

Gtg

#

Bai

upbeat herald
#

Have a good one 👍🏻

#

Imma get going as well

frosty sapphire
#

What is assembly language?

radiant isle
#

a very old language used to interact with the computer's hardware

#

its a low level language, i.e harder for humans to understand by just looking at it

silver sky
#

It's literally still used now

#

at the end of the day, your high level programming languages just compile or translate to ASM/Machine Code

slow cloud
silver sky
slow cloud
#

Yeah okay, its not out of date but it is old

upbeat herald
#

I hate assembly 😀

#

Ah the dark days when I had taken the microcontrollers and embedded systems course

#

But unfortunately it has a huge application in cyber security as well, I'm not looking forward to it 😂

gloomy tulip
upbeat herald
#

How so

narrow hound
rapid merlin
narrow hound
rapid merlin
narrow hound
twin ridgeBOT
#

Gave +1 Rep to @candid sentinel (current: #574 - 12)

potent field
#

guys where can I ask for the osint ctf help?

slow cloud
rapid merlin
#

Hello Everyone i'm newbie

sturdy sequoia
slow cloud
#

welcome

chilly veldt
#

Sup sup

sick maple
#

sup bella

#

sup t1mo

potent field
#

Its just a website with leaderboards nothing else

slow cloud
#

we cannot help with an active CTF

#

hii snowie

potent field
#

its not an active its just new at this point you can do it anytime

sick maple
fading perch
#

Why do so many people switch to Linux?

sick maple
#

I switched cuz I wanted to learn linux

#

for fun

#

but then I realized linux is actually better than windows for me

#

actually it depends on the person tho

sturdy sequoia
#

i use windows and linux

sick maple
#

for gaming

#

gaming on linux is pretty hard to setup ngl

sick maple
#

i get the blue screen atleast two times a day

#

in windows

#

I even did a fresh install and diagnosed my pc. there was no problem

sturdy sequoia
#

Linux for hacking, Windows for everything else.

rapid merlin
# fading perch Why do so many people switch to Linux?

Windows 10 support is ending right, no more security patches or updates. so after oct 14, 2025 all windows 10 devices wont get any updates from microsoft anymore, which means theyre gonna be super vulnerable to hacking and stuff. unless you got your own antivirus like AVG or Avast then youre kinda protected i guess

sick maple
sturdy sequoia
#

To each their own. As long as it gets the job done

sick maple
rapid merlin
narrow yew
sick maple
narrow yew
sick maple
narrow yew
#

I was sure that you have had that (sick) for more than 1 week

tough iron
#

do i need premium to start learn hacking?

narrow yew
sturdy sequoia
tough iron
#

Thank you 🙂

narrow yew
#

Larsbandage 🙂 you have THM, hackthebox.pentestlab, + a ton of other box/room based sites to play with.
Then you have youtube and start looking and learning tools for bug bounty.
Then the whole world opens up for Ethical hacking

tough iron
#

i just asked, cause i dont want a new account on a new website, and then i need to buy smt and another thing and they have my creditcard data and so on

tough iron
#

Just a joke :))

#

other question: can i change the language or is the language english and you cant change it?

#

cause my english is pretty bad 😐

narrow yew
#

What language are you looking for?

lucid portal
#

you speak french

narrow yew
#

Swe/Nor?

tough iron
narrow yew
#

Oh you need to talk to your goverment to stop dubbing everything in to German

#

You will be in a world of english tools and portals and websites

tough iron
lucid portal
#

oh sorry bro i am french and the englesh help for communicate

narrow yew
#

Germans are scared of english. But try and get better at it or have your browser translate eng - german.
But all the tools you will face will be in english

#

Imagine translating metasploit to finnish

tough iron
narrow yew
#

It would break from all the characters

tough iron
lucid portal
#

scared for GW2

tough iron
#

Can we please translate python in chinese?

lucid portal
tough iron
#

or japanese

#

This would be very funny

narrow yew
#

I think Finnish is the way forwoard. that language is just odd

sick maple
#

might be right tho

narrow yew
narrow yew
#

Something like that

sick maple
#

nahh not that much

#

that was cuz i had school work i'm sure

tough iron
#

@narrow yew 出力する("こんにちは世界")
Thats just a simple print("hello world") ......... credits: ChatGPT NotLikeThis

vagrant terrace
#

can i learn cybersecurity in this server ?

sturdy sequoia
regal steeple
#

have any1 taken the CEH ?

zealous socket
vocal marlin
#

koth not showing ip

drowsy estuary
#

hey everybody

#

comment ça va??

mellow widget
#

hi all

#

should I learn C for cyberSec?

#

or c++?

sturdy sequoia
#

if you want

rapid merlin
rapid merlin
#

Reverse Engineering is funcoolguy

mellow widget
rapid merlin
mellow widget
#

ohh okk

#

python for automation?

rapid merlin
#

Like writing CVE if you found it manually you can do it automation

rapid merlin
#

Look at the exploit-db they're made of python

mellow widget
#

yes I saw those exploit-db exploits when I solved my last CTF

rapid merlin
#

You hacked the bookstore? coolguy lab

mellow widget
#

cms made simple

rapid merlin
#

ohh

echo moss
#

where did heather go

rapid merlin
echo moss
#

ah must be HTB then

#

well it was someone rlly good at JS who i wanted to pay to help me fix this extension

rapid merlin
#

its thm not htb btw i haven't heard any guy named heather

rapid merlin
echo moss
#

hm what are the other like grey hat hacking forums?

echo moss
marsh lark
#

@mossy river how's the build going

#

if you've started

mossy river
#

Won’t be started until Sunday

drowsy estuary
#

I'm Heather

#

no I'm just kidding. who the hell is Heather?

marsh lark
mossy river
rapid merlin
#

@mossy river can you help @echo moss

mossy river
#

Depends on what help is needed

echo moss
#

can we talk in dms

#

?

mossy river
#

Sure

frosty sapphire
#

What is mandoc in Linux?

#

I was using the command "uname -a" for couple days but when I wrote "man uname -a" my termux said that it's not installed in my package so to install type "Pkg install mandoc"

mossy river
#

Try man uname without the -a

frosty sapphire
#

Ok

grim sparrowBOT
#

:hammer: bigeater101#0 has been banned.

left torrent
#

lol gg bigeater

rapid merlin
#

hello all, i'm newbie, i wan't to be a hacker, what should i do?, i just have android smartphone

mossy river
#

You're going to have a difficut time just using a smartphone

silver sky
#

Get a computer. Smartphone is way too difficult

mossy river
#

Any chance you have a local library with computers you can use?

silver sky
#

Good suggestion there

#

Or an internet cafe (if they exist still in your location)

boreal scarab
#

I hate headaches before work...

mossy river
#

Headaches suck period

boreal scarab
#

Amen, it's just magnified by kids screaming

rapid merlin
silver sky
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @silver sky (current: #36 - 303)

shut hawk
#

imo the worst factor would be the small screen size, if you can get a monitor you can hook up to your phone it would be more possible

narrow yew
left torrent
#

hey all im new aswell

#

🙂

#

dont mind the color or my name

rapid merlin
#

New but mage level

#

Hahaha

left torrent
#

I got a low end windows device

#

and

#

a virtual machine in it

#

on*

#

and find the privilege escalation room difficult gng

#

damn

weary veldt
#

It is difficult

#

Take your time

marsh lark
#

I'm thinking of switching

rapid merlin
left torrent
rapid merlin
left torrent
rapid merlin
#

let say son of arch haha

#

idk how to explain

mossy river
weary veldt
topaz sedge
left torrent
topaz sedge
left torrent
#

o kratos
makes sense

left torrent
topaz sedge
#

Linux distribution

left torrent
#

o

#

fairs

#

is kali the best linux for pentesting?

rapid merlin
slow cloud
#

either kali or parrotOS is what people prefer

#

but you can use pretty much any distro

weary veldt
left torrent
slow cloud
#

kali or parrot just come with alot of tools preinstalled

rapid merlin
#

all Linux are good

slow cloud
#

blackarch is also an option but i think its deprecated

left torrent
#

they all got the same commands right

#

like ls

#

ls -a

#

that stuff

rapid merlin
#

I'm new to arch distro haha apt don't work

slow cloud
#

pretty much, although some distros might use other package managers, for example arch has pacman

left torrent
#

sudo apt

slow cloud
#

but if you are starting out i would still to something like kali, parrot, ubuntu, mint

#

etc

slow cloud
#

i would suggest configuring your kali to fit your needs, change your background etc

slow cloud
#

look through the options

left torrent
#

shi how fam

slow cloud
#

see what stuff does

left torrent
#

help

slow cloud
#

what do you wanna do

#

background?

#

right-click on the desktop, select "Desktop Settings" or "Appearance", then choose your desired wallpaper from the provided options or by navigating to a custom image folder

#

said gemini, i dont know from the top of my head

marsh lark
#

or no

slow cloud
marsh lark
slow cloud
#

any debian based distro uses apt im pretty sure

marsh lark
rapid merlin
slow cloud
#

hyprland is cool

#

im using i3

#

i use arch btw

worldly pollen
#

guys

#

GMKtec K10 (Intel i9‑13900HK, 64 GB RAM, 1 TB SSD)

boreal scarab
worldly pollen
#

I am abt buying this one

#

what u think

slow cloud
worldly pollen
#

I will put it in the frige to cool it down.

slow cloud
oblique hare
#

hello i want to do my last 3 simulations from SOC lv1 i am individual so i have no that much money to but simulations i want certificate so i need to complete the simulation
can any one help me to sort out

worldly pollen
slow cloud
worldly pollen
#

its only 1k dolar

#

and mini pc

slow cloud
worldly pollen
#

I will connect with usb

#

port

lament meteor
#

btw, hashes.com is back online... weird it showed offline for over a week and is all of a sudden back online

sturdy onyx
#

Can anyone tell me what to do with an IP adress

#

I have someone's IP adress

marsh lark
#

nothing

rapid merlin
slow cloud
#

you can have my IP @sturdy onyx its 127.0.0.1

#

have fun

frosty sapphire
#

Someone help me I am confused between three linux commands

frosty sapphire
#

-r , -a , ~/*

#

rm -r deletes all the files of a specific folder but what if I type rm -a ? What will happen

slow cloud
#

you can do man rm

marsh lark
#

shows you the manual for the command rm

rapid merlin
slow cloud
#

it holds explanations for all the options

rapid merlin
#

wipeout all file inside the folder directory

#

with asterisk symbols

marsh lark
frosty sapphire
sleek hare
#

And what do you want to do with it?

lament meteor
sleek hare
frosty sapphire
#

See on top most lines.
Both -r and -a did controled all files of a folder then when will I be using -r instead of -a ?

frosty sapphire
lament meteor
#

in your screenshot you are using "ls" not "rm"

frosty sapphire
#

Even if you take example of ls

#

My question will keep relevant

lament meteor
#

ls and rm do very very different things lmfao

frosty sapphire
lament meteor
#

-a Include directory entries whose names begin with a dot (‘.’).

marsh lark
#

ah, yeah

frosty sapphire
#

-a also include hidden files. All files basically

lament meteor
#

-r Reverse the order of the sort.

#

-r for ls is reverse the order of the sort

#

-r for rm is recurse

frosty sapphire
lament meteor
#

the same flag does not do the same thing for every command

frosty sapphire
#

So that's what I am asking, suppose I am using rm or ls command then when will I have to use -r and when to use -a

lament meteor
ripe sleet
lament meteor
ripe sleet
#

My favorite ls command is lal or ls -al

lament meteor
#

you can install "tldr" on the command line too to get a more condensed version of man

sly valve
#

I found a typo in one of the new rooms

gilded knot
#

why i cant past images ? , is there anything i need to do first ?
ps: i just joined

sly valve
#

Man-in-the-middle detection Task 1 spells wireshark as “Wirehsark”

lament meteor
#

I'd suggest man if it's a command you really have never used and tldr for familar commands that you need to remember the syntax of

sweet fiber
#

Heyo

blissful snow
#

hi

blissful snow
#

+rep @lament meteor

twin ridgeBOT
#

Gave +1 Rep to @lament meteor (current: #1583 - 3)

sleek hare
gilded knot
#

can anyone know why it stuck and not downloading ?

blissful snow
#

Use localhost

#

i believe

distant robin
#

lol my Kali decided to 💩 on me last night and now it's not working anymore.

boreal scarab
slow cloud
#

i want a WM

#

not DE

oblique hare
#

hello i want to do my last 3 simulations from SOC lv1 i am individual so i have no that much money to but simulations i want certificate so i need to complete the simulation
can any one help me to sort out

distant robin
#

Any debian based OS you guys can recommend? I cannot stand Ubuntu so something easy to work with.

slow cloud
#

mint

#

then

#

linux mint

#

its like windows

slow cloud
#

or Arch

oblique hare
#

hello i want to do my last 3 simulations from SOC lv1 i am individual so i have no that much money to but simulations i want certificate so i need to complete the simulation
can any one help me to sort out

distant robin
# slow cloud any error?

Yeah wouldn't boot so I went into recovery mode and then after a while it just froze. I know someone warned me that Kali is unstable so nothing to lose here really.

lament meteor
lament meteor
blissful snow
#

kali always gets unstable

distant robin
# lament meteor what do you dislike about it

I just don't like Ubuntu. I once had Ubuntu DDE and that was a good one to use. It was similar to Deepin but the problem is that those two distros are not being updated like it should so it's time for me to move on.

lament meteor
#

kali isn't really meant to be a daily driver

slow cloud
#

ubuntu is not great

distant robin
slow cloud
distant robin
#

Ok I'll go with that then. Thank you @slow cloud

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #54 - 190)

gilded knot
slow cloud
#

i really liked it

lament meteor
blissful snow
#

your hosting it on 0.0.0.0 and trying to wget it from your private ip

slow cloud
#

i always go for the Cinnamon Edition

#

but you can use xfce or mate, whichever you prefer

lament meteor
#

http:// localhost : <port>

#

take the spaces out

distant robin
blissful snow
#

you can do that or use 0.0.0.0

gilded knot
#

but i am getting the file from the target machine and even this capture shows that its connected and responsed

sweet fiber
#

Anybody knows the best place to deploy a bot or website

slow cloud
#

you can host it locally

#

or rent a vps

blissful snow
#

What do you need to host a website for?

distant robin
blissful snow
#

debian

#

run debian

distant robin
weary veldt
#

Why is this throwing error???

#

Give it a port no.

#

And remove the s from http

slow cloud
#

yeah i think the issue is the https

blissful snow
muted light
#

@slow cloud but when I paste ip it automatically become https even though I delete it and add http

blissful snow
#

Do you have to config /etc/hosts?

whole rapids
blissful snow
#

Eh I would still check

slow cloud
blissful snow
#

wiat it that attack box

#

or your machine

muted light
#

Attack box

blissful snow
#

what happened when you changed it to http

#

wait nvm

#

i saw

muted light
#

@slow cloud I'm searching I could not find it

#

@blissful snow same thing came

blissful snow
#

hmm

calm briar
#

dude this mouse capture is driving me insane - how do i know when im hoving over something!!

lament meteor
calm briar
lament meteor
#

that's from their docs

sleek hare
#

Hey people
anyone knows how to get IP of website behind cloudflare?

#

I got task from friend of mine to do that on his web, I don't think its possible but still will ask to be sure-

marsh lark
#

@jovial cobalt may I dm you?

lament meteor
upbeat herald
sleek hare
#

I can't find there on web

sleek hare
calm briar
# lament meteor

OH! yeah that makes sense - if you are doing normal people stuff i wouldn't be using a kali box. i thought you mean for daily pentests lol

kindred swallow
#

Hello guys

calm briar
#

of course of course. i'm definitely not in my bank account on kali

sleek hare
#

aha wait

#

Oh gosh ok its tunnelled not proxied

#

yep its impossible, im out

lament meteor
upbeat herald
lament meteor
#

i think kali has an official container tbh

calm briar
#

but still - anyone have a cure of the mouse capture after update / pimpmykali? it's really driving me up the wall

lament meteor
#

you could also build your own pentest box - some people do that - keep it minimal and only put the tools they use on it - kali is nice because it comes preinstalled with everything - parrot OS came later to do the same thing

calm briar
#

yeah of course i could just ubuntu and add nmap and john to it or something

lament meteor
#

exactly

calm briar
#

plus there are other pentesting type boxes - but still what you know about mouse captures?

upbeat herald
#

It just saves ur time that's all

lament meteor
#

ubuntu, kali, mint - all debian

upbeat herald
#

No need to set up

calm briar
#

how do i get rid of it! thats the question

#

its effecting my progress and sanity

lament meteor
#

what do you mean by mouse captures

calm briar
#

then i tried another fresh box - and just after the upgrade it started happening again

lament meteor
#

i don't use pimpmykali so I'm not sure

calm briar
#

like when you click inside the VM - the mouse cursor disappears and i can't see where it's overing

lament meteor
#

i make minimal changes to the kali image (that's kind of what I was trying to get at)

calm briar
#

thus i'm having hte hardest ype clicking on any buttons, or windows or even knowing where the mouse is

hallow willow
#

.

calm briar
#

i didn't use PIMP this time and its happend after my apt get upgrade

lament meteor
#

gotcha

#

what hypervisor are you using?

calm briar
#

i thought it was the vmware tools issue, etc etc . i've been googling for 2 days

slow cloud
#

i have never heard of pimp

calm briar
#

i'm on vmware currently

#

offsec has a page about it also

slow cloud
#

idk i never used it

fluid sage
#

Hello, i used to do some hacking like 4 years ago on kali linux, i forgot almost everything and i want to start again, what i wanna do is try and hack some random fake tiktok account if possible using kali Linux, any help? Also are you guys still using linux or there are other tools

calm briar
#

anyone i thought it was a vmware tools issue or something - but it only occurs after my upgrad

lament meteor
# slow cloud i have never heard of pimp

neither have I but I found it on github - seems to automate tweaks to kali - looks like there is a section of the script to "prepare" kali for specific courses

calm briar
lament meteor
#

this is the wrong discord for that - see the rules

fluid sage
calm briar
#

a fresh install is the only thing that works

lament meteor
#

VMware workstation or esxi?

fluid sage
#

You know any discord for this particular thing

#

?

lament meteor
#

my guy... this is not the place to talk about that stuff lol

slow cloud
#

for what? sorry missed your message

calm briar
#

vmware workstation

#

pro

#

you think if i tried vmware workstation 17 or something it might behave differenly? heres the thing - it only happened after the kali upgrade

fluid sage
calm briar
#

thusly! i think it isn't the vmware

lament meteor
#

try this - sudo apt install --reinstall open-vm-tools open-vm-tools-desktop

#

then reboot

fluid sage
#

What y'all doing rn

slow cloud
#

working

fluid sage
#

On what

boreal scarab
#

I cleaned my port. It's working like it did when I first got it

slow cloud
#

wth

lament meteor
slow cloud
#

hes muted

lament meteor
#

thanks lol

slow cloud
#

it was the bot

#

he dropped a bad word

stiff vapor
#

Honest feedback of a frustrated f2p rooms completionist.

The subscription filter in the search section of the site doesn't correctlt filter out the "cloud add-on" rooms from the "free only" ones

I'm in the walkthrougs section filtering by easy, not started, free only rooms and i see "introduction to aws IAM" and others that require the cloud subscription

slow cloud
calm briar
#

ethical hacking but no 'ethical' lol damn - talking about espionage

slow cloud
#

not just espionage, straight up illegal

calm briar
calm briar
mellow widget
slow cloud
#

he dmed me "it was not a bad word"

#

this guy

lament meteor
calm briar
#

yeah i've been going through stackoverflow etc. thanks for the help thouhg

#

i'll get back to it

lament meteor
mellow widget
#

how to fix

#

and she name is correct

#

becuase I ran hydra on it

lament meteor
#

well now see... you've stepped into a gray area where I can't help anymore lol

mellow widget
#

😭

slow cloud
#

is it related to a tryhackme room @mellow widget?

mellow widget
#

yes

slow cloud
#

#room-help is the best place to ask tyour question then

mellow widget
#

ok

lament meteor
#

include the room name and task number to get more specific help

calm briar
#

that search bar for room help is super useful

distant robin
stone vale
#

Y'all which is better ? THM or HTB

distant robin
#

Downloaded and installed Linux Mint Cinnamon and it's so similar to Windows. Thanks to @slow cloud

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #54 - 191)

slow cloud
stone vale
slow cloud
#

THM is better if you are starting out

#

HTB is better if you are a bit more advanced

#

imo

distant robin
stone vale
stone vale
lament meteor
#

If you have no clue what cybersecurity is, THM will walk you through stuff

#

if you have no clue, HTB will just confuse you

slow cloud
#

without a laptop, learning this will be very hard

#

having a laptop or pc is pretty much a must

stone vale
distant robin
stone vale
#

But at least I can access knowledge right

slow cloud
#

but how are you going to apply it

#

you can learn the theory of driving a car, doesnt mean you can drive a car

distant robin
distant robin