#general
1 messages · Page 1784 of 1
guys i need help
Only.
for windows 2
Sure.
Do you guys trust password managers?
Okey now reload page
Bitwarden, yes. Because it's open source and you can host it yourself.
the attackbox doesnt work
And Keepassxc is just offline anyways.
done
idk why
Go into network tab
You got any more info on that?
done
On a scale of 1 to 10, 10 being fosho
wait 2sec i have a mess i think
@jagged yarrow learn me hack
On a scale of 0 to "I use Bitwarden daily", I use Bitwarden daily.
you are famous
Lmfao.
Aight
Thanks
there is nothing called that
Gave +1 Rep to @lament tendon (current: #40 - 269)
im french
Nothing in the Network Tab?
I am on irregular verbs at school lol
Basically just "laughing my ass off".
Or nothing related to echo?
nothing called echo or live or ai or anything related to that
It's best to use a virtual machine or a normal machine on the website? In website machine lagging
I am with my Latein am Ende
Would recommend a virtual machine.
okey
Nah use Docker
Don't. xD
what
I just need a simple password manager cuz it's getting out of hand
doesnt work
That means I am out of options
Yea, Bitwarden or Keepassxc.
Bitwarden has online sync.
Rigjt, he should use wsl
Much better indeed.
But on a windows server
Yea, so you can tunnel RDP over RDP.
hello
That's twice the speed.
i cannot live without echo
Hello.
for windows fondatmentals 2
Open the port for any, so he can receive any package
Click that.
windows 11 work with thm?
Use Kali Linux or Parrot OS
It might, but you won't be able to install half the tools.
This.
its show me linux machine not windows
If u are fancy use black arch and vim
difference?
like what is better?
for beginners ig kali
Parrot has less tools, smaller community
Kali is better known and hence has more docs online and Parrot looks cooler.
There is not too much of a difference.
why does
nmap -sV -Pn -p- [IP address]
take such a long time to scan?
i learn cb 101
black arch has more tools than kali ig
Because you are scanning 65535 ports.
maybe later
try to use unicorn scan or rustscan
U can use both as beginner or expert
oh yeah thanks for reminding me about rustscan
ic
Try something like
sudo nmap -sV -sC -p - -T 5 <ip>
The -T 5 tells nmap to be way more aggressive.
/report (user) (reason)
How long will it take to adapt to normal use kali?
And -p- checks for 65000 ports
T5 not T 5
Literally does not matter.
Does the exact same thing.
The space is optional.
Rustscan is quicker
Then use that.
I scan in assembly
Rustscan isn't great for production tho
I NEED ECHO
thks
oh cool
ECHO
Actually a thing with other tools as well. You can put a space in between the flag and the value or you don't.
everthing done except windows
hi
i dont like
yeah It is however if you want more details nmap would be fine
nahhhhhhhhhhhhh
U can place almost everywhere random space
Not for paths or files
windows fundemental too hard
Everything else should almost always sork
I skipped it
did i need windows fundementals ? bcs linux is better for pentesting n?
I hate windows
really?
yh
But you will be attacking Windows systems later on.
Do the fundamentals.
ECHO does not show
oooo yeah nice i didnt see that
i doing tomorrow
U should know how a windows machine works, if u want to assess them
u are right and I think its nessecry for active direcroty innit?
Mmhmm. Powershell especially.
Do not.
gl
its a joke

next burger king
lolllllll
emplyeer
@void halo please remember there is law enforcement in this chat. Your jokes might land you in a whole heap of issues.
Aren‘t u 14?
wait i have to translate
ECHO
uh wtf sry
No AI 
Jetzt son McTürkentasche
ai helps simplify and break things down rather than just reading a bunch of text

Laziness.
Elegant
no just learning difficulty's
AI helps you not to be able to read man pages until the man page you need is not part of the training data.
Might be best if that's the case not to get dependent on tools like AI.
I mean its not lazy if AI breaks it down into easier language and maybe shortens some parts. Its just efficient
?summarize
damn it
it didnt work
AI can help with everday work a lot, but I personally refuse to use it in any context where I am trying to learn something, because it undermines that process like hell.
AI is awful, you shouldn't use it 
i don't even get what your saying here
Because the more you use AI, the more it'll replace you later down the road
Half of the point.
i would paste it into ai to simplify that lol
I am using EvilGPT
Its a tool like every tool on ur os my friend
but still not that good
i only use it to simplify topics down and make it shorter
i don't see the harm
chatgpt might not alwasy be correct
Its just dumb to refuse to use it
Ask it to kill echo
Agree with this. But I also want to add that you should not try to use it everywhere.
Specially when you are learning.
I can underline that
I am repreating myself.
Have fun when your precious AI replaces your job and you become homeless 
fyi I am joking
Did hydra replace u?
WYM, I still calculate my rainbow tables with pen and paper.
ai won't replace garbage men
I just don't like Echo.
I can 1000000% agree
am i really the only one who likes Echo
Ya
Like I said, relying on AI for learning will make you dependent on it later down the line.
Not great.
Thats true
I use AI to simplify my workload
Hi all
Hello.
And as a pentester u should develop strong researching skills
Once ur assessments become niche, ai is only gonna talk shit
How's it going on this fine-ish day?
Tired and bored.
this took me 20 minutes to answer because i don't have echo
Hungry
Which means great, for the time being.
Agreed, researching should come naturally. I have that
That's normal and will get easier.
good to know! 🙂
I think its pretty easy for garbage men to be exchanged with AI, just make garbage trucks that work on energy and add as a function to empty each garbage can
Why you didn't google it?
Thats gonna be an infinity loop
Cause the ai is gonna empty already emptied trash cans
Once it drives back
Nah not really, because you make it follow a path
I do see a few minor implementation challenges with that relatively simple empty_each_garbage_can() function.
good job trying to pick up all the trash on in normal places though cus trucks can't go there but humans can
litter pickers
you can't replace litter pickers
Should work in 3 lines if u use assmebly
drones
Well each neighbourhood has a specific place people throw trash in and Self-driven garbage trucks do the job
And boom more workers on the streets turning to OF
or plumbers
Yeah not in germany
witchcraft
True. Something like
pop rax
do rax
ret
Current situation
https://imgur.com/a/ASTqrvL
what is a security manager
U implemented asi right?
For better pathing
It's self explained in the title.
Someone who manages security.
This does everything, obviously.
Just add everything into RAX.
We can define everything in the second sprint.
Minimum viable product can be published like this.
tech or????
idg why people do not write code as efficient as bit
Either.
But I don't do cyber.
So simple yet so hatd
That is my speciality yes
thats sick
you do thm as a hobby?
you must have alot of free time
what's free time?
time before you were born and after you are dead
Ahhhh good to know.
Would u play the hero or decide ain‘t get paid enough?
how is that wrong
I'd argue if I put a fully automatic machine gun turret with 360° infrared vision in front of my place, that entry is secured.
We do not mention the legal inconveniences.
Play the hero in what regards?
Armed robbery in ur bank
so FTP isn't used to transfer files what?????
I don't work at a bank and as I am in the UK, no, I'm not armed.
Ask echo
try lowercase
I usually use SSH, and this is not even a joke.
echo isn't available remember
still saying it isn't
ill try
wget
But since I do not know the context to that question, that can be 20 different protocols.
it is just "What protocol would you use to transfer a file?"
yeah not ssh.....
The context is key
So u don‘t play the hero
You can, but you should not. xD
Try TCP
Well at my place I am a first responder so yes I guess? 😂
it was tcp
udp is like running water while tcp is a sink. You will miss a few drops with udp.
I wouldn‘t play the hero too
i wish it gave me more context to the question though rather than just saying what protocol would you use to transfer a file because theres multiple
Well, where I work we have onsite police and if they ain't about we get a 5 minute response time so
These questions are always related to the contents of the room/section you are doing right now.
context matters... as shadow did not have the room they had 0 context to answer it
I mean this probably wasn‘t the first question
Yeah it said ftp on it though
so the question is how dead wide boi can get in 5 mins if the police is not on set
Whehehe, that's mean then. xD
I'm hard to kill 
A little joke here and there
Try edit as html
Probably will be the death of me, a bike accident 😂
Should Update server wide
oh my god finally completed
Boredom is real. What do?
Learn to knit
U should not learn too much in a day
Never know when you might need to make a knitted jumper
Based.
U‘re going to forget it
why not
i have only done the networks one
xd
Ever tried learning 1d before ur exam and failed?
i dont know i have never passed a exam
never in my 17 years of living
Quite possible
most of this is recap though cus i already completed pre security and security 101 on my old account
Homeschooled etc
i don't know
i was in a school
Ahh okey
I dropped outta school 
Hello Wide! 
Yeah I think thats prohibited in most european countries
sadly we gotta be in education till 18 now
I dropped out to join the army
but we could go to apprenticeships
I meant home schooling
Nah that's permitted in most European countries providing it follows a standard
In Germany homeschooling indeed is illegal
Wait what, I didn't know PFM-1 mines were free?!?!
-# Read your status
I learnt on the day of my final exam and passed with a decent grade
Situation after installing all my drivers
https://imgur.com/a/TfIfi3W
Hlo
Can't see that without a VPN 😂
Everyone
Thanks Starmer
U are 1/1000
Yes you can, just pick them up and take them home
u serious? imgur is a global site
Imgur blocked UK access as they refuse to be compliant with the Online Safety Act
Which I don't blame em
what about postimage.org?
Wait, but wouldn't you have to be very careful tho?
Yeah don't actually pick them up 😂
What should i not pick up?
Hlo everyone
PFM-1 mines
so uk gov are bad guys that don't want their pop informed
Not really, it's basically if there's NSFW content they want ID/Age Verification
Nah I just did all of the known questions from the book and the process was soo much faster because a colleague made a website with all questions and answers
Yooo guys
that's the propaganda, they're not stopping you from nsfw content, they're stopping you from getting informed
70% from exam questions were on that book and 30% werent, I got all of the questions from the book correct but those that werent got only 2 right
@lament tendon hey
Hey.
I agree, especially with the recent incident with Discord
Whats up
I think the guy i report try to menace me
Not much, just procrastinating reprogramming a revproxy.
Don't intreact with that any further.
Just block and move on.
Also yea, report if you have not already.
Guys
Make me understand, to continue the learning path should I need to buy subscription
Can anyone tell me how to root there phone
Okay thks
Google it
Whats a revproxy
I was about to say the same lol
google your phone model and add "xda developers" to google search
A thingy you put in front of a web server so it is better protected, essentially.
Thank you
Gave +1 Rep to @patent hill (current: #3210 - 1)
There's many more things you can do with a reverse proxy, but that's the common use case.
Instead of giving people direct access to your servers, you give them only access to the revproxy, filter their packets for evil stuff and then forward the requests to your servers.
In a very basic way.
Okkkay
To complete the path, yes you do
Ooo i think i see that in tryhackeme
Thank you mate, let me buy while I get back to my screen
Gave +1 Rep to @silver sky (current: #36 - 304)
docker run -d -p 80:80 -p 443:443 \
--name nginx \
--network jernet \
-v /etc/nginx/conf.d \
-v /etc/nginx/vhost.d \
-v /usr/share/nginx/html \
-v /etc/ssl/certs:/etc/nginx/certs:ro \
--label com.github.jrcs.letsencrypt_nginx_proxy_companion.nginx_proxy \
nginx
docker run -d \
--name nginx-gen \
--volumes-from nginx \
--network jernet \
-v /docker/images/nginx/nginx.tmpl:/etc/docker-gen/templates/nginx.tmpl:ro \
-v /var/run/docker.sock:/tmp/docker.sock:ro \
--label com.github.jrcs.letsencrypt_nginx_proxy_companion.docker_gen \
jwilder/docker-gen \
-notify-sighup nginx -watch -wait 5s:30s /etc/docker-gen/templates/nginx.tmpl /etc/nginx/conf.d/default.conf
docker run -d \
--name nginx-letsencrypt \
--volumes-from nginx \
--network jernet \
-v /etc/ssl/certs:/etc/nginx/certs:rw \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
jrcs/letsencrypt-nginx-proxy-companion
That's a reverse proxy, run that and you have a reverse proxy with lets' encrypt and all your web servers will have ssl 🙂
Small tutorial:
Open pwsh or cmd as admin and type netstat -ano
you will see all connections you are making
if it says time wait, connection was closed recently
if it says listening, it means a process on your pc is actively waiting for remote connections to it
if it says established, you're currently connected to it.
Hosts file basically serves to reroute stuff. If you type some ip then letter f, each time you type f in address bar of your browser you will be redirected to that ip
That can also serve as a block. If you type 0.0.0.0 then some other ip, that other ip will be rerouted to 0.0.0.0 which is default route, or better put, a dead end.
However, large hosts files will result with your pc being slowed down, since everything will query it before connecting so better choice is to use route command which will leave stuff in registry
registry is in ram, and is therefore much faster then regular hosts file.
route add 0.0.0.0 someip will block someip
route add 0.0.0.0 someip/16 or someip/8 or someip/24 will block entire ranges
route add -p 0.0.0.0 someip will make the change permanent
route -f will delete all routes
What in the textblock is going on here?
Also why are you using route add as a firewall?
Holy wall of text
yeah whatever this guy said
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig\BlockAdDomains]
"Name"="BlockAdDomains"
"Key"="PolicyEntry"
"PolicyType"=dword:00000001
"Version"=dword:00000002
"EntryType"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\DnsPolicyConfig\BlockAdDomains\PolicyEntry]
".bp.blogspot.com"="0.0.0.0"
".exaapi.com"="0.0.0.0"
"[::]"="0.0.0.0"
"_sip._tcp.meet.3393147.notifysrv.com"="0.0.0.0"
"0.0.0.0"="0.0.0.0"
"0.0.0.1"="0.0.0.0"
"0.101tubeporn.com"="0.0.0.0"
The above is an example of pihole which will also remain in your ram, this time as dnscache service policy. It is different then anything else since it allows you to block specific urls, not entire domains.
With this, you can block for example just a specific discord server, not entire discord site. Tho for it to work, you need to disable DoH, as DoH is now enabled by default
nice nails man
Is der any advice on gettin into a cybersecurity apprenticeship
Im in colly rn doin a levels
Ion kno if dis chat good to ask questions
what was the recenet incident with Discord?
Thanks, that's a cool docker config
Gave +1 Rep to @dark wolf (current: #88 - 112)
Windows Registry Editor Version 5.00
; Network
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes]
"65.9.0.0,255.255.0.0,0.0.0.0,1"=""
"52.109.0.0,255.255.0.0,0.0.0.0,1"=""
"2.16.0.0,255.255.0.0,0.0.0.0,1"=""
"2.18.0.0,255.255.0.0,0.0.0.0,1"=""
"20.82.0.0,255.255.0.0,0.0.0.0,1"=""
"0.0.0.0,255.255.0.0,0.0.0.0,1"=""
"127.0.0.0,255.255.0.0,0.0.0.0,1"=""
"10.0.0.0,255.255.0.0,0.0.0.0,1"=""
"192.168.0.0,255.255.0.0,0.0.0.0,1"=""
This should block access to local lan, akamai, msft, and amazon aws
I feel like I've seen this before
No I mean I think you've posted that same message before
yea, added some stuff this time
how do you guys find thm challenge rooms to do
the recommended thingy isnt quite functioning
I just use the search function
do you guys know any picture data meta remover
yeah its not that reliable for me either tbh i dont feel like doing something like that
i was thinking of using the skill matrix thingy but the rooms there also get pretty boring
maybe i should just make my own room at this point
hello guys if i cancel subscription doas i get the money paid ?
If someone knows just tag me I am heading to bed
why would you get a refund lol
I doubt it
Someone try and get my ip
bro it autoreniwed
the subscription continues until the expiry date and wont renew after that
you should contact support
@glacial coral
without permession
Why?
he is under the illusion that is what hacking is i guess
Nope
guys you thing they can give me back my money or it is late
you can simply set your entire network offline with Ultra Windows Tweaker. You'll still be able to surf, but network will appear offline
I'm just bored as hell
you can get your ip if you visit whatismyipaddress.com
tho any apps checking for connectivity first will fail to work
Nah I js want to know how much time it will take y'all to get ot
It
we are not fucking sorcerers bro no one is pulling out your ip address from thin air
thats not how it works
u are wrong I can smell his IP address
Hello GUYS, i got a quick question what are some tests i can take that could be called "cia tests"? ^^
hack the cia
print "hello world" 
did you come from the fckin bog video lmao
whats a cia test?
like a imagery test, or something like what they say "cia tests"
i am tryna figure out where to find some
bro do you know how to use sudo su
tell me
isn't that linux thing
on what topic
like imagery, something i gotta do, translate some alien stuff
i don't know how to describe it
OSINT?
like tryna figure
YESSSSSS
Do yo??? difference between "sudo su" and "sudo su -" is what?
lol
whats osint got to do with cia?
what is the difference tho
is it to switch to a user called -
or is that an actual flag
I don't think i have the knowledge to answer that not gonna lie
i think i might have mixed up the words
root.txt
confidentiality, integrity, assmunching
but it's close right?
if you wanna decode stuff or whatever just go do some stenography and hashing
any ughhm, test like that or
this is harder than I thought
to look for
sure
i still dont even really know what youre after
but that one word could've leaded me to somewhere
like i want a test, where i am tryna figure out a case, yk what i mean?
oooooooh
so
you dont know anything at all about hacking or whatever
ignore that then
cyyber security related?
yeahhh. i am just tryna have fun
kind of
OHHHH I AM LOVING THIS ONE ALREADY
thanks so muchh
❤️
just the one i needed 🙏
i think, i may have found a new hobby
doesn't sudo su make you permanent admin?
like, you use c control app to make the pc your zombie, or add it to your azure
it gets a bit tricky managing your zombie when zombie kills group policy client and wmi
especially if he also burns any network bridges
mhmm, any more a little harder ones?
this is a bit too easy
it's just picture metadata
and google maps
like a bit more trickyer
ok i guess
lol
uhm can i ask one last tiny time
a bit harder 
already seen this so
sorry if i may be asking for a bit too much
okay yeah true
Happy discovery day.
Hi, can I learn cybersecurity here from zero to hero and get CEH with this platform only?
maybe
chıll bro
huh?
Probably not. No one single source of info is going to get you that cert
i thought this platform offers everything i need
my friend suggested me
chıll
Hello Everyone. Do I have this correct that in order to complete the MS Sentinel Module, you must pay for a 3-month cloud subscription, of 375USD? Really, it's any AWS/Azure learning will require this license? This creates a dilemma because I certainly enjoy upskilling myself with TryHackMe, that's a lot to spend on a license that will not be used full-time. And, compared to AWS SkillsBuild at 29USD/month and Microsoft 'free' learning paths, I'm afraid I'll have to take a pass any learnings that require this license.
are u pushing for cloud security?
It offers quite a bit. But not everything. There are many topics related to CEH. It takes a couple years at least of training and practice .
I am heading to bed
The cloud needs security becuase the old man is yelling at it?
are you a student?
bye bro
I'm a student of THM University, does that qualify? I paid the sub
hi
bye dude
got it, you would say it as a good starting point?
see ya
@mossy river what are the minimum prerequisites to even consider thinking about a discord moderator candidate?
This is a fantastic starting point
I am not, technically, a student. But I can get free access to Azure with my student account with my local community college.
well you can use that to get free credit
i have a question in try hack me is not good if look the leak when is hard ??
?????????
restructure the question
good is try hack me no hard or leak try question me hack
ooga booga type question
do what you want. doesnt matter what we think
this is getting forwarded you know where
It was as good reponse as any lol
ye ask away, but please ask properly, we dont mind if you are new
Everyone was new at some point, Im new
When I get stuck, I watch tutorials to help me. Is that serious?
Explain
Watching tutorials aint wrong
Try everything you can F22... if you get stuck and don't know, then watch tutorial
if you knew it shame on you , if you didn't learn it and next time you know
hey guys
EHLO pelt
im a dirty dirty cheater
i always use writeups
never admit to that, what is wrong wiith people today
For example, I'm blocked on active directory. If I watch a tutorial to unblock it, is it good or is it better to struggle?
thats up to you. there is no right or wrong
i try to run away from write up s
if you struggle on everything active directory related maybe try to take it down a notch
aaaaaa okok thanks
Gave +1 Rep to @dark wolf (current: #87 - 113)
its good to watch a tutorial if you struggle
sheesh yall get thank yous
thank you
Gave +1 Rep to @delicate edge (current: #2113 - 2)
Please explain further. Would the YouTube video walk me through how to use my 'own' Azure subscription?
ow finally got 2
but for learn better
yes
if you know how to search pretty much
depends on the person. different people learn in different ways
a okok it's my way
Just be aware if you are doing this for a job, there are no writeups for your job
you figure it out or they fire you lol
I see that all the time kids who think o well i can do it here that i can do it here there is no net kid walk on the rope or fall and get hurt
but thats not my job yet but when i get there i will be away from write ups
you should make writeups
they are a good way to keep track of what you've learned for future use
I have had a TryHackMe subscription since Advent of Cyber 2023, and currently, working my way to the 365 days badge. I still get stuck, from time to time, and will turn to the TryHackMe YouTube videos. Sometime all I need is a little nudge to get me going in the right direction. I do this for personal upskilling. Hope this help anyone who feel that they should not need to use help.
I will look into it thank you
Gave +1 Rep to @gritty bane (current: #322 - 26)
That does thank you
Gave +1 Rep to @eager wave (current: #3211 - 1)
added note
they are also a good way to show you know what you're doing lol
not just blasting random tools and hoping for the best
but rather detail the steps and why you took these steps
thats what makes a good writeup
For job interview???
they can definitely ehlp for an interview yes
otherwise how will someone know that you know what you're doing
writeups are a way to show that
Ok I will be adding that to my goals
it been time I stopped studying cybersecurity for reasons now
I will give you my path everyone
Cybersecurity 101
Jr pentesting
Pentest+
Web Fundmentals
Web pentesting
Offensive security
Red teaming is my path great even if I stopped been while should I change it because it become more newer
evolved?
wdym by we
won what?
?
Why did you stop?
explain your question
I can see your path
EU isnt going thru with the chat control after public backlash https://fightchatcontrol.eu/
Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.
oh thats great
I stopped studying cybersecurity for university
So I can study my path now or is old so should change my path ?
too bad my country voted for chat control 
at least to my knowledge
so you study cybersecurity at university?
This doesn't seem to support that
My path
and what is your path?
I send it up
the one you showed right
Yes
so whats the confusion, why do you have to stop
University
why
I should focus 100% on my university
To get a job
and how does focusing uni get you a job
Wait germany opposed the proposal
I'm not sure what you mean by we won lmao
by taking cert from university
you mean degree?
I'm just using the link you sent
why cant you do both at the same time, do you have a scholarship?
public backlash made them realize its not THAT easy to control everything we do
There's still more countries supporting than opposing
Look I cant them both
why not
I will be Distracted
you can always continue learning cybersecurity but learn less instead of straight up give up
and wont giving up cybersecurity distract you by making you feeling guilty?
That what I'm doing but my path still old anything want change in the path
I'm asking about this
Without Germany, it's nearly impossible to reach the 65% population threshold, even if many other countries support the proposal.
Ilike it from u
Why is your path old?
I'm asking anything changed in cybersecurity in tryhackme new path to change my path
@gusty inlet help this guy, you are the TryHackMe nerd
A proposal passes under QMV if it meets two criteria
55% of EU countries must vote in favour.
Those countries must represent at least 65% of the total EU population.
well since I pinged DKob its clear I spoke with him
Okay thank u
What's the other criteria
- 55% of EU countries must vote in favour.
- Those countries must represent at least 65% of the total EU population.
This only makes me have more questions
Politics aint easy
lol
I meant the empty list
Italy looks like the only big country left then
That'll be good news
how does the ambassador program work
No answer?
Passion and time mostly
Rational thinking, good decision making, mind over emotions
Like kali says "The quieter you become, the more you are able to hear"
Anyways gn guys
night petar
and shadow is extra tired for some reason so going meep moop to beep boop for sleep sloop early
ni ni shadow
I guess Ill wait, Im not even a year old here and my account level is pretty low
Same, only been here 100 days
Deep fried chicken tenders with hot sauce on the side for dinner

I'm having a $100 ribeye paid for by my company at a steakhouse
Ayoo send me some
hehe, it wil rot by the time it gets to you yeah?
Yeah unfortunately
I feel like something nullified all my scripts so that baddies can have their way with me
hey
they replaced it with ai of some kind which is trash like all the other commercial protection
I need a hacker
wrong server
perdon
Too long to type, so imma take a SS.
so basically a discord support`s guy account was broken
and some malicious person had access to that account
and who made a discord ticket recently may have been a victim
alright guys, am i tweaking or is there practically not ths
at much osint tests
yeahhhhhh, geoguesser is really cool though, but still tests are better, that need decryption and stuff
download the photos you want to guess.
get really drunk
encrypt them all differently
when you are sober, figure it out
not a bad idea
will try this while driving 90kmh in a school zone
My scripts all executed, but they aren't doing anything, that shitty ai is
What do you think about the EJPT certification?
Don't waste your money on junior certs lmfao
Biggest scam ever
😂 why
Wdym why
it's joke ?
No
Why would you need those entry level certificates lol
It's just basic shit like port forwarding and nmap scanning
put on linkedin or to find an alternation? or is it better to save for oscp directly?
I'm the best hacker here
I'd be very concerned if I were a manager and an employee had to show me a certificate that they could do basic tasks
Oscp is the standard ig
I started two weeks ago, I'm far from the OSCP level, bro
Give it a few years then
Then what
Showing entry-level certs seems kinda dumb I suppose, projects do much better I heard
Associate certs are much better
Im considering taking 2 foundational and 1 associate microsoft certs
So maybe consider 2 associates and 1 foundationals dunno really
???
You can get foundational certs if you want a small job in help desk for example
They certainly help
Well I want to start with help desk or level 1 support
Great then but in the long-term something like eJPT is not worth it
PHDA or whatever it was is good too
I was thinking of something vendor neutral
Like a Cysa
Or security+
Both are solid options for foundational certs
is it possible for a private IP to be accessible via internet?
some guy was asking me how can he expose 192.168.1.1 to internet so he could remotely manage stuff
he was almost certainly trying to do something illegal, so i didn't help him
but that led me to think is it even possible to do something like that?
192.168.1.1 is a private address, so how can that even be accessed via the internet?
if that computer can access the internet then it will also have an "internet" ip address as well
then that public IP address would be accessible through the internet. but 192.168.1.1 is a private ip which isn't usually accessible via internet.
but can you make it accessible somehow?
is that even possible to do?
not at that specific ip address because its a local address
Isnt that comptia cert for people with 3 years of experience?
yeah that's exactly what i'm thinking. local addresses should be impossible to access through internet no matter how hard you try to make it accessible, right?
at a fundamental level it wont work
The system is basically designed to do that
Crazy the qualifiers for that new Comptia cert is 3-4 years in it and 2 years in cybersecurity
In reality what you do is use NAT to convert your private IP into a public IP to stop the depletion of IPv4 addresses. What you can do is to configure port forwarding in your router to make your public IP at a certain port forward these requests to the private IP address you configure. Lets say you access {public ip}:80 and you configured the router and a local server, then the request will be forwarded to that "local" http server
Yes it's possible , for security reasons router vendors are disabled with these features by default to protect their customers.
Ill do the most insane thing anyone has done or at least attempt
how would it be to try to pass the new Comptia certification without experience
just for the sake of it being free
sounds like a waste of time
how is it possible?
the remote web-based management thing u sent, i'm assuming that would make the router management webpage accessible to the internet via a public IP?
yeah but i'm not talking about port forwarding. i was asking if its possible to make the private lan ip accessible. and i think it should be impossible like shyft said.
Yeah what I mentioned is the only possible way, a router has no way to forward your request to the internet and know the exact path as is not unique, and would be dropped
nevermind actually acts me the company and my role
I aint going to lie about having a job
yeah that's what i was thinking too. thanks for confirming
Gave +1 Rep to @wheat kernel (current: #3211 - 1)
Free certifications for experts, free certs for beginners when
why cant everything just be free
Fortinet has some foundational free certs and Isc2 CC is free if I remember correctly (but I think you have to maintain it for 50€ each year or something like that)
Yo what's up I'm new here and I wanna start learning to hack
cause corporate people need to make money
welcome
Yo
Thanks
people still use twitter?
X
I considered ISC2 CC but forces me to go to Serbia
cuz the closest exam center is there
Yes exactly! With remote management enabled on your router, you access the router's admin panel through your public IP or sometimes a provided domain, and it serves the same interface you'd normally get at 192.168.1.1 locally.
So you're not actually accessing the private IP directly the router exposes its management interface to the internet on its public IP usually on a specific port like 8080 or 443
yep yep. thanks
Gave +1 Rep to @kind thunder (current: #1275 - 4)
You don't have any pearson vue testing center close? If not it will be quite a hassle for you as most of the exams require going to these centers, excluding some exams that are online proctored
also why does it sound like a horrible idea to expose router's admin page to the internet
lmao
hi
i feel like you'd get brute force attempts within 10 mins or something
wassup
Also default credentials, old firmware plays a huge role. Not something someone should do. I had some old routers where the password was literally admin as default, luckily nowadays some of them seems to be "randomly generated"
mine came with a "randomly generated' password with a sticker of the password on the router
xD
@fluid garden Hi i hope youre still around. Could you accept my friend request? I lost contact to you
Yeah a classic, better change it to make sure including the username if it's possible
https://youtu.be/273eSvOwpKk?si=yZiOjg4hqUEBD5ed Song for bug bounty hunters & Hackers while doing CTF 😅
Our new album ‘This Life’ is out now! https://TakeThat.lnk.to/ThisLifeAlbumID
Get tickets to the tour: https://tix.to/TakeThat
Follow Take That
Website: http://takethat.com/
Facebook: https://www.facebook.com/takethat
Twitter: https://twitter.com/takethat
Instagram: https://www.instagram.com/takethat/
Lyrics
Just have a little patience
I...
looks like a song for hackers in general
the lyrics is so catchy haha
yeah. A song so catchy, most people probably don't listen to the lyrics. But they should, because it's not just about the pleasures of conformity and the importance of trends. It's also a personal statement about the band itself.
hey paul!
judging by that black heart reaction, i'm assuming u didn't get the reference @rapid merlin
I don't have any available emote , i don't have nitro
Do you guys know any encryption methods that could have been used for this clue?
"The key is 8 and the offset is 16"
I'm not sure if Caesar cipher
do ctf groups have a own page, like a user profile page?
It might be rot 13 then rot 47 but I'm not sure im trying to find out
Yeah im using cyberchef
just try every caeser combo on the encryptedtext
not very time consuming and you'll know if its caesar
Thanks
Gave +1 Rep to @kind thunder (current: #1095 - 5)
Thanks
Gave +1 Rep to @queen flare (current: #164 - 59)
np
I tried rot13 bruteforce
It has an offset input
No key though
This is frustrating lmao im so close to completion
TIL powershell commands in a .bat file cannot bypass gmail (at least). However, if converted and embedded into a HTML download and have it manually executed, it *might work...
Can't get the HTML to auto-download correctly tho
Actually, nvr mind that
Thinking of what I was trying to do before
Basically, instead of multi-payload thru initial infection -> download -> execution. I have to embed into "HTML as JS" the true payload and have the target execute the file.
Def went off path with the original concept lol
This is the encrypted message
HnBPIGosACOQSJFmt DNRR:E e!EMSQKDoreFLPLCNsrGKOMB eHJNAhI
Hello guys. I'm new at web. I want to do bug bounty and improve my skills. Do you have any advice or resources?
and this is the clue given to me:
You are almost to the bottom of the lost and found box! The robot is hiding inside a bag, but which one? All of them have zigzags on... The key is 8 and the offset is 16.
check out https://roadmap.sh/cyber-security its perfect if you want to get a hold of how to start, what to conquer next etc.
*Take care of your mental health get enough of sleep , grind , listen to cyber security podcast , spend time reading hacker news , practice in the lab daily
yes I know this site but I dont think cybersecurity has just check list roadmap
(Damn THM confusing me if its grey or gray)
damn this is crazy pa[iosipduog
what do you mean with checklist? you can create an account, mark the different topics as in progress or done
I did HTB labs and can say they def have improved since last time I did a lab
THM still easier to jump in than HTB
(And faster(ish))
You can do HTB if you are confident in THM Intermediate lvl imo
HTB is easy now cause its more user friendly
Before it was a pita
And slow
Very slow
I do hard rooms on THM
(These days)
for exampe İ know DNS, What is this, how does it work and etc. But I didnt make DNS server, because I dont need rn. In this case Can I check DNS button?
if you know how you to deploy one in theory and how it works, thats all u need to mark it as done or in progress. i would do in progress, since an important part of practice is missing. in your case deploying a dns server
there is also eticel hacker roadmap of this site
imo this more understandable then other
yeah looks good, i might change to that one
checking everything again is gonna be a painpoint
hahah yea
We need more social engineering rooms or at least concepts
Cause I'm stuck rn irl situation
Me = patient
Target = medical professional
Yup, as stupid as it is
Its a real test. But I get ya
yeah and can get u in real big trouble real fast
just try to seduce ur teacher
lmao
the only one who could do something illegal in that situation is the teacher
Na
Its all good tho, think I might have thought of something
you could talk to your doc and ask him for permission, once a few months pass and he forgets, try to get a recipe by faking some kind of illness. this way you can test it i guess?
make sure to not actually get the recipe
Irl non-professional thats how I got Xanax lol. Irl test-wise, we'll see what I can come up with that doesn't cross my personal boundries
Its stupid, dont worry
Very stupid and weird
(reason why I complain about my volunteer sht)
(too weird)
tbh the weirdest social engineering test i've came along so far
I've done a bit more lower level stuff. But, this makes me question what exactly am I doing.
imagine thm had a physical security assessment room where you gotta break into a bank irl
WOuld be amazing
you learning how to turn a doc into a drug dealer
My target is given to me by my "client". Its fking weird, I may not even fully do it
I can always cancel sht Im not comfortable with
Made that clear at the start
A free job, with my ass playing "actor" on stage.
ahh makes a lot more sense now
i thought its a random social engineering test on the internet
No, its a real client against a real target
But... I'm having doubts on what this client wants
maybe explain ur situation to chatgpt and request a social engineering strategy for that exact scenario
Idk if that is suppose to be a joke. Lol
its a tool u can use to get some ideas
True true
why would it be a joke
People here don't like AI much
cause most people treat ai as the problem solver and not a tool
its basically a tool like hydra, john, etc
For real, but some peeps here, I guess don't see that and rather be cavemen lol
exactly
its all about efficiency
you could try every user:pass combo by hand when bruteforcing or use a tool like hydra to maximize efficiency. i think you know by now what i mean.
if you guys got a cat use the giga chad filter on her/him
funniest thing I've ever done ngl
I'll keep that in mind
Other than the contract, I order a 65" TV by accident and can't cancel the order
lmao
Fking Amazon
I rather they just take it back xD
From what they said
But, even if not, I can always pull cash from my savings
I rather not do that tho
is the tv already on the way
Yea
thats the reason

