#general
1 messages · Page 1779 of 1
Oh
How did you like approach the rooms?
Also its like a 2minute search if u ever forget
Like what did you do,
Oh yeah
And uh
Say for example
When im in a room
I first watch the video
Read the content
And ask chatgpt to helpnme understand it
For 1 room
Then note it all down
I personally understand how things work, and that helps me remember them pretty quickly. As for commands, I tend to forget them sometimes, so I just refer to my notes.
How didbyou understand them?
Me too except web pentesting bc i have a hard time understanding theory of that 😥
Also ideally i just never have to do web pent ever
Theory is so hard to memorise
crontabs are scheduled events in linux - if you have permissions you can set them to open ports(backdoors) or make users increase privs, etc all sorts of fun stuff. thm has a room about it
Theory isnt memorization is what dkob is saying
I know im on it rn 😭
Theory just means you dont understand it then
On presecurity
Yes
Its understanding it
you memorise these little nuissance through repetition - googling- taking notes - refering to the notes during the repetition
googling vulnerabilities and reading wil be your best friends because alot of stuff shows up over and over again.
Is this how u did it?
do rooms multiple times. i know it sounds crazy - you just wanna finish the path and get hte badge but its really about repetitively doing the basics and learning all the flags and good shorts cuts with bash etc
this is how i've been doing it and still do it
you'll never memorize everything. the thing to memorize is the steps to find out how to get the information you need.
like know your tools very well. eventually when you've done the rooms - you wanna find more on vulnhub and make your own labs etc.
Alright, so ima first complete the full presecurity atm, and then redo it ig 😭
how areyou taking notes?
Yes, summaries and stuff
i would suggest putting them in the cloud incase you lose them
Shall I do notes on a physical book aswell?
Yes , I have them in my folder
also i like the idea of finding other peoples notes and finding little gems and copy/pasting them into mine. really making like a personal playbook
so when i have a crontab situation - i can go look at my notes
Wait where can I find other notes..?
crontab, suid's, sudo -l - etc . all these become like a checklist of things to investigate
google it up dude. people have notes and start.me pages ( like a home page with tones of book marks and links)
people have great stuff on github and medium
Ima google sum like "OSI Model Tryhackme presecurity notes"
i like looking at people's methodology (like the steps they use to hack) even on mitre has the att&ck framework so i can see how APT's generally move
i wouldn't be that broadn the googling for notes - you look for specific things " crontab vulnerabiliy and exploit"
because the vuln doesn't have to do with thm - it's a general thing in linux. ya feel me?
it's cool man.
Just started cybersecurity
we're all learning
How far are you?
just be aware - there is no finish line.
that's what i mean - there is no end. we're all in this ocean today lol. learn to swim.
Keep advancing
I wanna be crazy good at cybersec
Along with cybersec im learning python via CS50
exactly - soon the thing that give you trouble will be very familiar. the things you see in THM you'll see in the wild. apache servers, jenkins, linux protocols, AD - all of it
dude i'm right there with you.
Apache servers are like what host the webserver files right?
it becomes a hobbie. this is a videogame to me now
yep. thm will show you everything - but also google and watch youtube videos. there's plenty of free content out there
and free courses. check our classcentral and coursera
Any paticular ones for THM presecurity?
start at the very first room - and go in order and take your time.
Hey everyone! 👋
I'm new to cybersecurity and just discovered TryHackMe . I already love it!
I’ll be participating in a CTF next week, so any tips, advice, or recommendations would be super appreciated. 🙏
Looking forward to learning from you all! 😄
My advice don't forget to sleep
for me learning networking was a big fault of mine - and i knew more about vulnerabilities than i did about how computers and networks worked so i spent 8 months doing that all over again. so i would suggest starting at networking first
the life of a packet is wild my friend.
😭
I know a packet is
Data just like
In little chunks
Makinf it easier to send
get familiar with professor messer, mike meyers, dion, etc.
And sent using the OSI model
Everyone speaks about professor messer
yeah but a packet is more than just a definition . you can manipulate and change them like a rubix cube.
, application, presentation, session, transport, network, data link and physical
Haha noted! I’ll try not to pull all-nighters 😅
all these things about cyber that seem 'boring' are the things that you will build your knowledge on.
Hey guys new here i want to learn hacking how can i start
that's the wrong attitude in my opinion. just dedicate time everyday. you will never be done - it isn't a race. fill your brain
My attitude is doing one room a day and rest if the time study more of that room using other sources
For example the osi model I done the room, and then asked chatgpt to fully help me understand it
Then made notes
For those who have already participated in TryHackMe challenges, what are the essential commands or skills you think a beginner should know?
basics Linux commands, ports and protocols, nmap are some, but there's a lot that goes into the fundaments
hello, hackers
Jello
will we get the IP of target ?
Challenging
welp that was an epic fail on shadows part
totally broke sddm with the hardening so had to remove the override.conf to be able to login
where are the hackers 👀
here in shadows pocket
i don't believe u 😛


....
-# mods?
hahaha safe looking link
ask @mossy river
am i supposed to click this?
you still alive my friend
😔
my journey is like learning a bunch of things and then i can use it - then i learn more stuff , but then forgot all the originally stuff i learned so i have to re-learn it - in a continuous cycle. or for instance i spent all day yesterday fixing a 'captured mouse' situation in my vm's that i couldnt use - and ended up switching virtualization platforms - then i was trying to get greenbone to work so i could use it with sysreptor just to find out that openvas now only reports40% of the vulns in the free version so i'm now using nessus - just to do a vuln analsys i was trying to knock out 3 days ago.
alot of that.
an endless loop of “learn, forget, relearn, rage-quit, reinstall, and repeat” — like Groundhog Day but with more VMs, fewer vulnerabilities, and way too many mouse-capture meltdowns.
always 🙂
happy to support fellow people 😄 i'm really not looking forwards to cpts when i'll go for it
i feel seen.
I enyoy rage-quit
i'm so stubborn though i'll stay on a problem for days
next on the list after pen-300 and crto
😄
betrayal
worth it tho
how many flags it have ?
good luck, it should be a walk in the park for you 
me on the other hand, i just started hacking again after 4 years of break around Jan 😆
yeah, not a bother
Well nmap is still nmap 🙂
tbf i focused too much on my foundations and it pays off, the root of if is exactly the same, the approach is just different
why nmap when you can just autorecon and then manually test
yeah, pretty much
i've just discovered updog3 and makes my life so easy 
I think you lost the basic idea there.
Autorecon creates a whole lot of noice.
What do you learn by using autorecon
this is a sign to go love your nearby fellow animals, be they humans or pets or any other wonderful beings;
SUBSCRIBE TO MY NEW PERSONAL PET CHANNEL:
https://youtube.com/@GirlWithHerDogs?si=0K_X2A94y7UbMbLi
SHOP MY FAVORITE PET & GROOMING PRODUCTS:
https://girlwiththedogs.com/shop
FEATURED PRODUCTS:
The Ducky Soap Dispenser:
https://girlwiththedogs.com/shop/p/gwtd-electric-shampoo-dispenser-duck
Coral Slicker Brush:
https://girlwiththedogs.c...
You just said you were away for 4 years and wanted to learn
Autorecon is a great tool
just creates alot of noice
Some targets do not feel well after a whole lot of noice
specially huge websites with multiply dispatchers and dual cdns
Then autorecon comes and creates heeps of cache instances superfast 🙂
not trying to be rude, but can you show me an example of a lab env where that'll be the case, fragile hosts i am aware
okay, so i think you're jumping to conclusion then, as per zumi^
🙂
Sup chat
if we talk about real life the topic is totally different so is the approach
don't even need to do that 
rate limit usually takes care of those, that is the easy fix
NGFW do the job by themselves
I have a lot of what not to do while running huge websites and having a BB program at the same time
or WAFs depending on the architecture
az-900 does a good job for the basics
or the AWS counterpart
3 days for what
for az-900?
oh you cooking, all good man. there's this bloke on youtube which is really good at talking about cloud and making people understand, let me find him for you
This channel focuses on videos designed to help you learn. Big focus on Azure, AI, DevOps, PowerShell and other Microsoft technologies but also some virtual mentoring content! Thanks for visiting! Please note this channel is my hobby and completely unrelated to my day job at Microsoft. 🤙 Also note due to the channel growth and number of peopl...
i got the whole security stack, SC-400 too which got discontinued
updated and valid?
az-500 is the most difficult out of the whole path
Gave +1 Rep to @rose tusk (current: #227 - 42)
yeah.
i'm a manager so i need to be able to support my team :P, but there's defo people smarter than me
UK
Well that is also lost 😄
pretty much 
I like London tho, got family there so I visit 3-4 times per year
idk, been in london for 10 years now, gets kinda boring
If one just stay away from center and just eat good and drink IPA, its a good place
pretty much that helps, i'm 100% replaceable, my team knows their stuff 😛 but i know how to put stuff into context
the drinking culture is huge here, as an eastern european i got bored of it now, i may have a beer or two and i'm bored
I love that part
2 years ago used to pull 10-15 pints on a night out
but my wallet was cutting onions every time i was looking in it
also if you have generic questions about cloud, feel free to reach out, maybe i can help or point you in the right direction 🙂
i love the part of my brain that whispers to me "the challenge calls" after I fail or want to give up🥲
after the joining the military, that part of the brain is like the swolemate for my mental
What should I do after got root on King of the hill ?
Keep it
I did but king time show 0 on leaderboard
Did you echo your username to the file?
oh I dont know this
next time will do it 🖐️ thanks
You're all good, it's how it tracks whether or not you're in control
et: command not found
[ blackarch /home/liveuser ]# apt-get ugrade
bash: apt-get: command not found
[ blackarch /home/liveuser ]#
whats that
tool?
that is a better answer than mine 🤣
I just install this OS but I am about remove from my device
That was cool . we will play on weekend with mates
lets user arch, but ill update with apt-get =/
nah man kali>arch
imo arch > kali
where is my kali
uhh
definitely not what I've heard from experts 🤣
CRTO is much harder
just for one example
wow
anyone know discounts for the monthly subscription?
not rn
GIAC exams seem a lot more intense tho
dammit, so I guess I should skip studying from tryhackme then
The free path is still pretty good
You’re doing a good troll. If you’re someone who holds an OSCP, you can do most things — and that means you’re an expert level pentester
what paths are free?
pen tester, like testing pens?
jk
lol
how to send image here
gotta verify
hacking
he is usless right know but one day
Where can I dm a mod or Staff member? It's pretty serious
you can ping one (maybe Jabba) and ask if you can dm
@mossy river Can I dm?
thx
Gave +1 Rep to @marsh lark (current: #28 - 383)
no prob 🙂
altho not sure if Jabba is online or not
when you ask gpt to make smth usefull for me and he do it ok
This token is already in use by another account.
This is my new discord account
I forget my previous account
@mossy river
seems pretty lacking I think there are better free learning paths
Sure
DM me your token please
yo Jabba what benefits do you get as a moderator
not much from what I know
done
done
so they dont get like free premium sub or financial help for certifications
damn thats ruff
they give free business sub I believe actually
but
you gotta get accepted by Jabba
oww thats nice, the later part not soo much
<?php include($_REQUEST["urlConfig"]); ?> i would change the url config to a ip like 1.1.1.1:1234 and add the 1234 for nc corret
That was unexpected
sorry hello every one how are you
this is the second time around you've asked this question
head pain prob
is that how i would set that reverse shell up
lol asking about the reddit ambassador
Had also asked about the mod and just seems to be begging for a free sub basically
YAY did it on the seconrd try :D
noice
wait... this is the wrong discord serer...
LOL
<?php include($_REQUEST["urlConfig"]); ?> i would change the url config to a ip like 1.1.1.1:1234 and add the 1234 for nc corret
Yes and? Not my fault prices are based on American economy
you don't just get a free sub, you earn it
Then I wanna earn it ig
There's a difference between begging constantly and just saying the pricing is just not affordable
and the price is actually quite decent imo
The prices for thm?
yes
I would sub if those matched better for poorer economies
Like Microsoft certifications as an example
How much is it? I got mine during cyber Monday so in theory i get the sale each year
-# its the same price for THM tho
120 dollars yearly
Ouch
Oh that's really cheap compared to what I thought
around 100 with student discount
Ouch
Unfortunately, there is a cost to running the service and region pricing just gets abused so the company loses out
Just wait till around Thanksgiving and it'll go on sale I'm pretty sure
Fair enough I supposr
Ye doesnt help me if the sale is only for the yearly option
If you want a free sub, you'll just have to wait for either someone to do a giveaway or one of the events throughout the year.
advent of cyber is in a few months
thats just one event
Correct
Tbh I just want an affordable sub, 8-10$ per month would be fair
But I get why its higher to some degree
thats around the price for an annual sub
At one stage it was, but costs etc go up
yup
If I had the option to be forced to pay monthly in form of a contract I would have bought the annual sub
Tbh you you don't really need thm to be good in cyber, it just helps
But everything on the go its too much
Before I got my subscription I looked at what the rooms were called and googled the subject
I know Cisco offers a free CCST 120 hour course
Harvard prob has some classes you can audit for free too
Audit?
You can see the lectures and stuff for free
But actually getting a paper from it costs money
Basically participate in those classes online but without receiving credit
Neat
Im interested in their python courses
SEED ALL THE THINGS!
Cs50 is a pretty good course from what I've heard
What do you call a dog with two legs?
Nice
A woman?
well
also that but
that's not the punchline
It doesn't matter what you call it, it's not gonna come after you!
Hello everyone... Uhm It might be wrong (I hope not for Indians)
Me and my Colleagues Are onto a Project of sustainable development goals(SDG) the goal we have chosen is Goal 2 : Zero Hunger
the help I need from you all is that to fill this google form...
https://forms.gle/w487JogB4yYmzE53A
It would mean a lot.. The respective responses gonna help us accomplish the goal. And also it would help us too, as said earlier i.e. within our project.
i had problems doing skynet like i got it i just had to look up a write up because gobuster was not showing me any thing
and i am still getting better at uping my user from user to root
You are
Where’s hackers help channel?
help with what
Nice
that is awesome!
if someone can help on making a pix for me 163.360.527.29
#general Guys I need a little help. How I can install this? https://github.com/syryz/MacLike-VSCode/tree/v1.0.0
you try PT1 of try hack me and it's good certif because 350 dollars aiiiiiiiii
READ
shadow has not moved up or down the leagues in forever :D
hacking is a pain the ass but i love the feeling i get when i finsh a room
guyss help
sqlmap -r mikoo --dbms=sqlite --dump-all --tamper=space2comment → file is from Burp, FoxyProxy=127.0.0.1:8084, ping to target OK, but sqlmap times out/refuses. Ideas?
heyyy! talking to you
any ideas why sqlmap keeps timing out?
Done!
I followed the steps but it didn't work
yes because sql hates every one thats my finle answer as i still have to take time to study sql
including the installing of required addon dependency
ahh😒
sorry that was mean i hope you find someone with way more sql know how then me
no you're not ..its just too annoying
coulnt update respositries
That doesn't sound like it's blocked
sounds like wha
Kali.org
| Official Kali Linux Sites
| [Mirror Traces](https:/
fr
Nethunter?
anyone else ??
What're you using it for
Tried searching the error messages?
been at it since yesterday lol still not working
What's the error message
times out
Post a log of it
even though the target IP is reachable and ping works fine
yes
Yeah what're you using it for?
the cs50 intro to cybersecurity seems interesting
Ill try to apply for financial assistance and hope for that 90% discount
Hello everyone
hi bro
How are you doing?
sqlmap -r mikoo --dbms=sqlite --dump-all --tamper=space2comment
___
H
___ [(]__ ___ ___ {1.9.9#stable}
|_ -| . [)] | .'| . |
|| [.]|||__,| |
||V... || https://sqlmap.org
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal.
[*] starting @ 13:55:06 /2025-10-11/
[13:55:06] [INFO] parsing HTTP request from 'mikoo'
[13:55:06] [INFO] loading tamper module 'space2comment'
[13:55:06] [INFO] testing connection to the target URL
[13:55:36] [CRITICAL] connection timed out to the target URL. sqlmap is going to retry the request(s)
[13:55:36] [WARNING] if the problem persists please check that the provided target URL is reachable. In case that it is, you can try to rerun with switch '--random-agent' and/or proxy switches ('--proxy', '--proxy-file'...)
[13:57:06] [CRITICAL] connection timed out to the target URL
[*] ending @ 13:57:06 /2025-10-11/
is it now readable?
i'm not getting you
in short sqlmap -r mikoo --dbms=sqlite --dump-all --tamper=space2comment` it times out/refuses even though ping works. Any ideas?
and mikoo is the burp export i'm using
Is it bad I sometimes read the write up just to make sure I got the right tools
```bash
text for the command and output here @onyx lance
```
if you do that you get this
echo text for the command and output here
@sand trench Need your help
with what???
Now I applied the theme but it isn't like that one
how I can fix it?
you are asking a random person that is not using vscode and not using said theme to help you fix it??? well shadow has no clue more then reading the documentation
what body???

can i scan whatever website i want with zap or do they have site restrictions,
is not smart and might be consider illegal if is not in bug bounty area. and prob you get blocked
Hey, can I get some help with a question in a room? I know there's a chat specifically for this but no one's active in it
nvm
Thinking it this way, are you allow to poke around other people's houses without permission?
smart-ass guy on work, buys top of line macbook... complain he can't play games =/
When do learn to make my hacking faster and making my own python files to help me
Hii fam🤗I’m Timothy (aka CyberBlaq) from Nigeria 🇳🇬. New to pentesting and following the TryHackMe pre-security path. I’m doing hands-on labs and CTFs — open to study partners and small groups. Appreciate tips on beginner rooms and writeup feedback. 🙏🏾”
Hello Timothy, may God bless you and help you on your journey
I can pray for your mental health bro 🙏
Once I've heard somebody complain he couldn't install windows software in his mac, so everything is possible 🤣
ppl are weird
Sorry there are no known vulnerabilities for "MENTAL HEALTH".
Try another term?
Lol
Sure there are
yeah im just not too familiar with what zap does/what it targets, if its looking at public facing info then it would be fine, but if zap is querying beyond normal site traffic then no
and it is legal lol, passive is fine, spidering is grey area then they offer active which obv comes with caveats
i like the house analogy tho
its like sitting outside of someones house watching people go in and out is fine, walking through their front yard is maybe fine depending on the context and if they have a no trespass sign up
then i need a warrant if i want to get in😂
My point is not always legal, and even when is legal some people will be altered and can be some issues feather in the line
yeah i didnt ask the question properly youre totally correct
rule of thumb if it is not your device and you don't have written explicit permission, stay away to avoid issues
hey, is there anyone to solve CTF together for OSCP?
You're taking the OSCP exam right now?
no not right now 🙂 i mean for practice
sudo apt install mental-health
Shadow absorbed any goats when doing daily wanders
Mic drop on that gif
Also a way of saying i'm semi old.
Youngsters would not know whom that is
Pang pang lucky luke
I don't like big bugs
@dark frost I have a ccolleague that moved to australia and he's afraid of sharks
Got that weird centipede on my wall above my computer
eat it
Might get super powers

hmm hard choose
what's so interesting for ppl to start using tor for a start
TOR is slow and maaaaybe useful if its built in to scanners that does not have a option for proxy list
=/
should i select second options
But most places identify tor nodes
I wanna debate is there anything here?
In space?
Ofc there is
Yeah what body?
The evidence
Hello oldie
Hello fellow oldie
I feel extra old
Ditto
Anybody here OSCP certified?
Not sure if I want chocolate or go to bed... Lol
Slept less than 4 hours in a parental bed on the hospital. Those are like a better option that the drunk tank bed
There are some, you can find them by the OSCP tag
Should I ask you what happened?
@distant robin sick kiddo
Thanks, friend.
Gave +1 Rep to @narrow yew (current: #371 - 20)
Oh bummer, that is not fun. Hope the kiddo gets better soon
Actually a bed is better than trying to sleep in a chair
My sister bouth this
Not me. My first LAN co-op in South Africa, I pulled an all nighter. When we go home, we went straight to bed at 7am and slept in for a few hours.
Body start hurting after 48h
we played COD4 and DOTA and I think a bit of Unreal Tournament / Half-life Death Match
Now the only game I'll pull an all nighter is Evony: The King's Return. 2 months ago, I did that to get Server War Ares achievement and rule the server for 2 weeks as the Queen. Was fun and it was my first time doing SvS.
sounds good
Yeah after 2 years, I'm still playing it.
Hey guys I want to become a pentester but I'm a lil confused on something should i start with the Jr pentester room immediately or start from pre security?
Start with the bases knowledge
Hello
Hello
hello
@gusty inlet
@cloud quiver
i wonder why that particular spam is popular in this server
What pictures are they posting anyway?
he posted in all the channels 🤣 😛
No idea. I don't click them
Neither do I. I just wondered.
Yer but this same spam happens here every few days
And I rarely see any others
I bet you it's the same person who uses different usernames and emails. It's a spam bot obviously
I wonder if they all have different IP addresses?
@mossy river
Jabba the hairy hut
people have too much time on their hands, and no imagination to think what to do with that time 🤣
It’s not just this server, it is all servers that are ‘discoverable’ - if you are on desktop, scroll all the way down to the bottom of your server list and select the search option
Idk if discord moderation tools give you IP info
They do not
We are users of Discord, we do not have account management ability
Damn, would be nice to see if it's the same person or not
Also why is Discord allowing this sort of thing to happen?
It is but it’s hundreds of people running the same scam
It’s an image file, you are perfectly safe I promise
image of what? His mom?
oh thanks
Gave +1 Rep to @mossy river (current: #6 - 1815)
I saw dunnel trump
Probably costs too much for them to care - but look at the cool animated profiles you can buy they’re worth the time and effort
It’s an image of a phishing link to bypass automoderator
We catch hundreds per week in our automoderator but unfortunately I want to keep it strict to avoid catching regular users
Ah interesting
they're getting smarter now
Discord could easily prevent all of this hundreds of different ways but it’s left to us to defend our own servers
How would I install wormgpt?
yeah know it is lucky luke and that he is rumoured to be quicker then his shadow
but can't recall ever watching an episode
I know you ofc know how it is, and it is not a rumored, you jus saw it in the gif 😄
Classics.
and shadow is now wondering if the hack of discords third party support systems means shadows phone number and "chats" with reps is out there
it is over 1.5 TB of data and over 2 million files so possible shadows data is in this breach
Hey
If anyone has any free pdf or resources on advanced c/c++ that he could share would help immensely
Did you get a notification email?
nope
Iirc you should be okay then
Although 70,000 new ID documents leaked
So that's fun
that looks like a lowball guess by discord
Hey
If anyone has any free pdf or resources on advanced c/c++ that he/she could share would help immensely
hello
me I am hacker ethical ,I need types attacks for get passwords accounts social-media /I need new type/
what?
I signed up under my school email but now, I can't get back into my account. I tried searching but I don't see anything that can help. Is there anyone that I can contact?
dunno on free pdfs but if you wanna spend a bit of money there is plenty of resources
most would probably point towards no starch press
@slender plank
Can I teach you how to hack Instagram accounts?
illegal activity isnt allowed here
Is that for your crush
Darling hold my hand
Nothing beats a Jet2 holidays And right now You can save 50 pounds per person That's 200 pounds off for a family of 4
We got millions of free child place holidays Available With 22 kg of baggage included
Book now with Jet2Holidays
Package holidays you can trust
I want to teach legal activities in another way.
hey man whtsp
goodev
YES
hello guys i'm almost finished with Cybersec 101 track which track should i study next
i'm doing a 365 days challenge each day a room so it doesn't matter really i just want to learn in the best way possible
I need to talk with her first off
oh busy girl
It's legal
explain why its legal
Who loves Morocco?
wa sir t9wd rak thchm fina
نتا مغريبي اخويا
am i having a fever dream?
what does it mean
I didn't understand what you meant
he's asking if i'm moroccan
are u?
someone give me his opinion
It means Moroccan dialect. Because I am Moroccan.
follow the path that the learning paths is part off basically
Do you like the aggressive team or the blue team?
that's what i'm asking
i like getting a job
so blue team
I would say blue
خويا مالك سبيتيني
غادي نقول ليك شي حاجا ماشي حتا ليه
that's exactly what i'm asking there are 4 different paths
wdym
Rule 7 - Use English
Please keep all communication in English. This also means no encrypted posting.
Can you take a picture of the screen?
i meant three *
yh
Red team
Blue team
Security Engineer
I have good attack for hacking accounts instagram or social-media
someone recommended i should go red team first to have a better understanding when i'm in the blue team
thats illegal
SQL injection
bro just kick him already
Upon completing this course, you will be able to understand the concepts of IDS and IPS and perform SIEMS and threat analysis.
هدر شوية بلمغربية
you mean the SOC 101 ?
I already studied most of these things , but i have little knowledge with red teaming
I think it makes sense to progress along the blue team path. It will give you a lot of practice and perspective, but watching red team videos on YouTube will give you an aggressive perspective.
do you think i just finish the SOC 101 then go to Jr penetration tester
yeah
i'm doing a room each day for a year
It's up to you. If it were me, I would take the BTL1 exam and try to get the certificate.
The red team mentality eventually takes root in your mind, whether it's the cyber kill chain or something else.
i think that's a good thing no ?
Who are the ethical hackers in this group?
which one
helps you detect attacks better
ofc
hello mod where r u
having a red team mentality while being a blue team
@grim sparrow
i'm chasing a job bro don't really care about being mr robot 😭
Who are the ethical hackers in this group?
its up to you man
I am just saying
what's the logical path to take for better results
i don't have a bias
Try to learn both. As far as I understand, that's what you want too.
u can start with red teaming
finish red teaming path then go to SOC 101
or one day red team room and the day after blue team room
for better results
It's up to you; both can be done.
alright then i'll try both and see which is giving me better results
my choice is irrelevant, I'm not you.
@lone thistle you alive?
:hammer: amine_as88#0 has been banned.
I asked something similar earlier, but anybody studying for OSCP here?
How is everyone doing today?
doing alright. hbu?
trying to sleeps soonish
that's how I did it
i just got done making a usb with my hacking os on it so its a full system on the usb so i can use full computer power without a vm because med rooms are kicking my butt
has anyone seen the USB pen there Charging 100$ for?
no. what's so special about it
I have to show you this hold on.
no i tryed that but i want a full computer os so i got 120 gb usb and install my arch hacking system
All-in-One Tor Network Anonymous Flash Drive + Cold Storage Cryptocurrency Wallet [2nd Generation] Zero Trace is a hardware modified flash drive with everything you need to stay anonymous. Being completely portable, you can access the Tor network on any computer from the USB port, anonymously from the Zero Trace Pen. (Clearnet | Dark Web | Dar...
this makes me a hacker???
and give 100$ for smth that you can build you self for no money is just dumb
A hacker embodies a boundless passion and insatiable thirst for understanding the complexities of a system, computers and networks in particular. They revel in the pursuit of knowledge and mastery, constantly seeking new solutions and opportunities for growth. Their drive and innovative spirit inspire and are inspired by the hacker community, where ideas and knowledge are freely shared and valued regardless of their origin.
So I can be uber el33t
I've never used the usbs on my laptop
Come on guys do you not see the specs on this thing???
its almost a full arduino board
for 10 times the price
exactly lmfao
you could make that for $20 for a regular USB stick and maybe 1-2 hours of config time
true
so is the USB just for power then?
how do you connect to the pen once it's plugged in?
Some times I wonder. What people wouldn't buy? It's like take a Packard Bell 386 putting some LED's on it and calling it a gaming PC Facebook marketplace baby.
if you want niche but useful usb hardware can shadow introduce you to:
nitrokey
infinite noise
TrueRNGpro
Hello fellas , hope u doing well . Just wanna ask about rooms that has more points +300 and they're web related , thank u
i have a pineapple lol - so I'm a hypocrite, I could have built that for cheaper too
if you wish to have smth like that, go for it. if you plan to play with it and so on is nice things
shadow just bought a new wallet that is rfid/nfc blocking
show me or it didnt happen
Anyone like verilog?
Hello Jabbbbaaa!

Hello Shadoww!

hello
also got 10% off the price of said wallet because someone has a referal code in their pdf book talking about privacy :P
can anyone help me
you can make it cheaper
ello darkfly... shadows sddm hardening from yesterday ended in bust and now shadow gotta try more slowly with steps
I'm sorry to hear that Shadow!! Hopefully the 2nd deployment will go better
guys i need help
We all do but my psychiatrist is booked until january
Okay lets do something fun NAME Dropping.... What is the best least strict CHAT AI....
Hello bro
dolphin mistral 24b venice edition
oh??? so shadows option is bad as it is not paid???
I've never tried it so I can't down it
Task 6 Metasploit: Exploitation
i cant answer the question
the version shadow mentioned is by these people: https://venice.ai
Try Venice.ai for free. Generate text, images, characters and code using private and uncensored AI.
which has a paid version
That thing there makes me look like a true genious
;P
the answer for task 6 is Google.com
whiterabbitneo
i cant find the answer
whiterabbit is good I agree
I was just looking at NinjaAI... doesn't it just auto route your prompt to a service it deems best to answer the question/task?
duckduckgo also has their own ai frontend to most popular ai:s
Its dying
by default, it looks like super ninja uses Claude Sonnet
Because claude is smarter than chatgpt now
that's nice, I just recently tried Claude (free) and it's annoying how quickly you run out of credits -- it looks like paid runs out quick too
wow wow wow wait a minute
anything is smarter then chatgpt now
Except deepseek lol
i still lean on chatgpt cause I can use it for free and not have to authenticate to be honest
I keep breaking deepseek I asked deepseek a question and it got stuck in a loop so instead of stopping it I let it write bs for 16 hours straight lol
teach them to fix it!
chagpt🗑️🚮
claude💎🌟
I gotta try it out
I was interested when I saw Gemini was able to be integrated into kali only to find out that you have to authenticate --- LAME
I hate this ai
yea, but when you run gemini-cli in kali, it prompts you to authenticate to your google account before you can use it
every LLM you can host at home with ollama is better then all the online stuffs
from security and privacy point of view
on the ethical view it is not that different
I like deepseek the most because I know my questions are making the chinese smarter at least.
They are already smarter than the US
anyways shadow gotta go sleep sloop to the beep boop for the meep moop
The world hands and gives China the technology and the instructions on how to make it.
@dark wolf well that goes into ethics & etc...
some of us though in the us are special...
the us sucks ass right now lol
There are just different versions of reality in the US right now
most of the world sucks ass right now though
oh god, not politics
who said anything about politics?
i just wish people were more kind to each other politics or not
Let's take a look at a sample SPF record and break down its format.
I got so bored with this thing.
the 0.1% have us thinking it's the left vs the right when it's really the uber wealthy vs the normies at the end of the day
ding ding ding we got a winner
you could argue that the idea of "the rich vs the poor" IS a political stance lol
@dark wolf You want your photo back?
Not really. Doesn't matter which side you are on, you can be rich or poor regardless of politics.
i generally agree
That reminds me of that one email from long long ago
Oh i see what you are saying ... nice!! I just grabbed it from a search
The best would be if the guy in the middle was sitting on a massive pile of cookies that took up most of the room 😄
If a billionaire spent $100mil, they are still basically a billionaire
Now I have to find that email exchange again
and $100 mil is DUMB money
That's awesome
"Dear Jane, I do not have any money so I am sending you this drawing I did of a spider instead."
Read that one PikaJew
If you had "only $4 million" invested you could scrape off $120,000 annually (3%) as your "salary" and live a decent life....
Yes, that is true, you could live off the interest and dividends
Then you can make more money than that from borrowing more money against your money to invest
so then you will still be increasing your 4mil while spending 150k annualy
and will make 3x the average worker by sitting on your tush
You ever heard the saying the rich get richer and the poor get poorer it wasn't a joke who do you think pays the interest?
the bank or you NSF fees when you over spend on your checking?
This is 100% true
There is a video somewhere that shows how wild the difference between $1 BIL vs $1 MIL
Another analogy... 1 million seconds = 11.5 days --- 1 billion seconds = 31.7 years
and musk has $500 BILLION ..............................
500 billion seconds is roughly.... 15,850 years......
Capitalism is the worst economic system, except for all the others
why can't I react to your message with an emoji
does anyone think riot games will pay me 100k/
ppl who block you you can't react. if that is case
There isn't enough information inyour quesiton to ascertain the answer
Riot Games offers a bug bounty program with a maximum payout of up to $100,000 for qualifying security vulnerabilities, particularly for severe issues like DDoS attacks that target individual players or exploits against the Vanguard anti-cheat system. Other high-value reports include account takeovers and client-side RCE.
Then probably not
damn Shyft, why you got me blocked 😢
you might get $100k working for them as a salary lol
I'm going through john the ripper basics... it only works so fast because the hashes/creds that they use in these labs are so crappy right? like the liklihood of breaking a random hash out in the wild is pretty much slim to none unless someone is using a dumbass password right?
maybe i underestimate how crappy some people's creds are lol
its more likely someone passes the hash rather than cracking the hash right?
if you do thm cracking. you use wordlist that they provide. that's why is fast. if you have some unknown, that is different story
yo guys, isnt there any evil twin walkthrough on thm?
you can do faster cracking with rainbow tables. but to make rainbow tables it takes time and more time. and if password or so is salted, rainbow tables are not much of usage. not if you make rainbow tables with known salt
yea, rockyou.txt is from like 2009 so i feel like password security has increased significantly since then
yea. rockyou is smth that thm use
there is a 2024 rock you as well
as default. now image that you do not know what word is or so. or is in another language with special chars
right
is that why I can't figure out this BTC wallet password
on this server there is guy who is one of builder of hashcat. he pops from time to time. usually i annoy him when i have issue
you can forget that idea in start
i was using cuda with 8 5090 and still no luck
try to crack this hash
the wallet.dat had 138 BTC
it can have all. but you are not breaking that for sure
that's like 111k today
then @polar spoke can share big wisdom of cracking
LOL
oh wait
ok
I feel it's dishonest to say I am 50 when I am really 50.989
then take my hash and try crack it with that 8gpus
Im running it now
Oh wait, I'm only 50.983
Dude, why are we talking about crack and hash in here??
cos we can ?
hehehe
I cracked it, it's GibMeBTCWashDirtGreen
yes. 7z password
and idk what it can be. due to knowledge where it comes, it might not even be english word =/. but big is that it is
sry? not sure that i follow
Can I DM you?
sure
kinda
what?
No it doesn’t 🙂
here it is lol
@polar spoke you hack3r3d me?
It’s the same as all the other fake wallet files that get passed around
did you hit it?
The address displayed has a bunch of bitcoin but no one knows the password
Because there isn’t one
It’s not a valid file
i seen them place the public address but no private keys
Yeah, those wallet files are basically all there to be scams
you wanna look one over for me?
183 is a common enough one to be recognized iirc
chick3nman knows his stuff
look at his profile
he knows what can and can't be cracked
he knows. we talked.
yo about crypto, can you recover usdc sent through a wrong network?
lol no
That’s the opposite of how cryptocurrency is designed to behave
It’s a core design feature that you can’t reverse transactions or recover funds
That’s the point
Yeah its not a credit card that you can report fraud after you got the item you wanted lol
So basically if you have no kids you can get a reverse mortgage when you are old and pay the minimum and before you die you transfer your wealth to a BTC wallet that only you know the password for so that when you die, banks get screweed and your wealth dissapears and no one gets it
Hello is there any admin? I'd like to ask why I haven't gotten any email regarding the hack2win prize?
Oh my! Those went out long long ago
the Admins are sleeping
but you can email support and ask them
@polar spoke I sent one that I have let me know if you have seen it before.
damn, I'm about to set a reminder in like 80 years to do this for my fam lmfao
The goal of life is to obtain as much money as possible before you pass
that's sad that humanity has devolved into that :/
evolution and survival - so I guess it isn't devolved - you could argue we haven't "evolutionarilary" caught up to the advances in tech and industry and medicine and etc etc etc
You know there are methods and ways of control and all of the facets of life that implement such control are taboo for discussion and not allowed for discussion in most places.
i mean thats true too.. the society and rules that someone else built
Quite Ironic isn't it?
but im interested where that goal of life comming from
i don't follow
ask gpt to decipher it
capitalism basically... you can't opt out essentially
to decipher what? you talking too cryptic at this point lol
It's only cryptic to you, it's plain english really
i read so much of Nietzsche and similar ppl who dive deep in psychology of life and no one ever talk that money is goal of life or so
and my mom is psychologist and i also never hear her say that
ralexander, you are absolutelty right , I didn't mean that they talked about it in human psychology
agreed, its not supposed to be, but we've become very "needy" since social media imo
oh...
I was more referring to the aspects of manipulation
and why humans can be manipulated
and how
that's other thing then
thats why i said to look into human psychology .. and behavior actually
i mean there are a lot of different answers depending on which realm of belief you follow so yea
there is shit amount of how to manipulate to get whaat you wish. asl in cyber term social engineering
hence i have burner phone and i put that number as to get called by scammers and can "practice" social engineering
a good place to start is the book "Please Unsubscribe, Thanks!"
best ones that tell me that my information and fingerprints are found in amsterdam in car where is blood and drugs in car. and if i send money i will be ok
"send money, crime will vanish" 😄 😄
so i talk to them to practice talk in social engineering
is burp suite pretty much all GUI?
yea
i've been ssh'ing into my kali (with THM OpenVPN) box so far, I think I have to setup VNC at this point lol
it have waaaay to much options to be cli
we are in human psychology of global GREED. Scammers everywhere, corruption even in countrys that hadnt been 50 years before. everything getting more crazy
the corps scam us, so we are trying to survive and turn to scamming each other 😢
i hate scammers, some ppl loose all their retirement savings
^ see the US Stock Market at this point
human history is a book written in blood, we are just animals in a pit
Near ATH, just small drop
history books are only the perspective of the victors.........

