#general

1 messages · Page 1805 of 1

loud marlin
#

you can enable few 2fa, depend of app and so. i have otp, pass key and hardvare key for protonmail

trim portal
#

Imagine doing that either by the end of this month or at the start of April kekw kekw

loud marlin
#

and on proton i can select what i wish

sand trench
#

oh shit

#

ralex pressed yubikey in wrong chat

loud marlin
#

lol

timid prism
#

Our does via face recognition and qr.( Something introduced this year cuz the owner of the group realised he has a clg and he shd mark his presense

loud marlin
#

oh, it is one that every press regenerate

#

different app use different protocol heh 🙂

sand trench
digital estuary
loud marlin
sand trench
#

anyone know if tuta to protonmail or the reverse also works with fully end to end encrypted emails???

#

or is it only inside their own ecosystems

trim portal
twin ridgeBOT
#

Gave +1 Rep to @loud marlin (current: #23 - 452)

sand trench
#

just proton pushes hard for you to get the proton unlimited at 9.99 a month to have their entire suite of things

lament tendon
trim portal
loud marlin
trim portal
twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2250)

lament tendon
#

It‘s not perfect tho, I wish I could mount their cloud storage.

sand trench
loud marlin
#

well... shadow can do things and send ralex email to check if things works... if wish

sand trench
#

sure

trim portal
loud marlin
lament tendon
tall knot
#

I can login now
But the courses are loading very slow

lament tendon
#

The file share is really neat when you need to share larger files with people as well.

sand trench
lament tendon
#

Or yourself.

rapid merlin
velvet gull
lament tendon
#

Client side encrypted, of course.

#

But yea, domain name, vps, mullvad and proton are my main subs as well.

sand trench
#

technically shadow has more paid services but not gonna list out everything as that would be a security risk to a degree

lament tendon
#

Yee, same.

sand trench
#

having your own domain name helps a ton

lament tendon
#

Got two, even, because one is free if you pay for the other with my provider. :D

sand trench
#

also domain names nowadays are surprisingly cheap

rapid merlin
lament tendon
#

Only using one of them tho, atm.

rapid merlin
tall knot
#

I just recently able to login and load the course

lament tendon
#

Maybe the thing is down because of the AWS outage or something.

rapid merlin
#

It's working for a lot of people

lament tendon
rapid merlin
worldly pollen
#

good morning ladys

rapid merlin
sand trench
loud marlin
rapid merlin
sand trench
#

they use other protocol for encryption then rsa

digital estuary
sand trench
tall knot
#

But will try that next time

rapid merlin
loud marlin
sand trench
#

Tuta uses symmetric (AES 256) and asymmetric encryption (RSA 2048 or ECC (x25519) and Kyber-1024 as quantum-safe algorithms) to encrypt emails end-to-end. When both parties use Tuta, all emails are automatically end-to-end encrypted (asymmetric encryption). For an encrypted email to an external recipient, a password for encrypting & decrypting the email (symmetric encryption) must be exchanged once. You can then use the same password for any conversation with that specific contact: With Tuta you don’t need to set a new password for each email sent to the same contact.

Tuta’s automatic encryption works easily on all mobile and desktop devices. The encryption key is never shared with anyone else, including Tuta. Therefore, even if a malicious attacker intercepts the email message, they will not be able to read its content or attachments.

tall knot
sand trench
#

Why does Tuta Mail not use PGP?

Tuta uses standard algorithms also being used by PGP (AES and RSA or ECC) for encrypting the entire mailbox. In addition, Tuta Mail already uses post-quantum cryptography (Kyber) for quantum safe accounts, which is still a work in progress for PGP. Furthermore, Tuta does not use an implementation of PGP itself because PGP lacks important requirements that we have for Tuta:

PGP does not encrypt the subject line (already achieved in Tuta),

PGP algorithms can't be easily updated, e.g. to post-quantum secure ones like in Tuta Mail,

PGP has no option for Perfect Forward Secrecy (already achieved for Tuta in a prototype).

In Tuta we can easily update the algorithms, and we plan to replace the current algorithms with quantum secure hybrid protocol in the near future. The flexibility of Tuta enables us to integrate an encrypted calendar, encrypted cloud storage and many more features much easier and faster than it would have been possible with an implementation of PGP.

dark wolf
#

Yes that is accurate Vigo. People use easy pins to login to their computer so if they use passkeys and someone gets their device, they are screwed lol

sand trench
#

the encryption of subject line is important to shadow

#

as any meta data leak can be bad

loud marlin
#

fair fair

leaden marsh
#

There is cloud hacking tryhackme

tall knot
rapid merlin
#

They have vpns kekw

#

I don't know

calm briar
#

so because i've gotten these scenerios for the next interview- i feel like i could do a write up for them ? like instead of just discussing them i show that i know how to construct a write up and talk about it. maybe i could have a cheat sheet of some similes or metaphor for more techinical ideas to help fill out the grey areas

oblique loom
#

Is THM having issues again, Can't get a room to load for some reason.

calm briar
#

good idea or over doing it?

tall knot
#

I heard Opera sold user's browsing data

loud marlin
#

use payd vpn from trusted one

rapid merlin
#

Mullvad

#

The Goat

loud marlin
#

mullvad, proton or some by own choice

mellow blade
#

Proton is pretty good

tall knot
loud marlin
#

jsut know. if ding illegal things it might not protect you if some 3 letter agencies ask for data

loud marlin
rapid merlin
calm briar
#

what do you guys use for making reports? i just spent dumb long learning sysreptor and it's pretty cool - i gotta get my html on point though for putting my own graphics where i want them obvi

wicked lagoon
#

hey guys i got a question

rapid merlin
wicked lagoon
#

is it okay to create summaries based on Tryhackme rooms and post them on linkedin and github ?

rapid merlin
#

Hey chat

wicked lagoon
#

i want to create a series of summaries of different subjects and use tryhackme and other resources to create beginner series

woven brook
#

im still confused who is jabba

calm briar
loud marlin
woven brook
#

oh alr

#

can I dm them?

wicked lagoon
loud marlin
#

when he show's up here you can ask directly

oblique loom
#

Yea, THM seems kinda slow atm

calm briar
#

ahh. i mean sure. you are just aggregating the information but you are displaying it differently. i'm sure you'll add more for other sources along your journey as well

#

i mean - it's just like keeping good notes

dark wolf
#

import re

wicked lagoon
dark wolf
#

wrong window

true rune
#

hi

calm briar
#

yeah i think that's all good - as long as you don't take their trademarked stuff or plagarize them directly

calm briar
#

plus you'll find more stuff - take a tour of hacktricks and other repositories

#

like screen shots of their website.

sharp raven
#

Does anyone know how I could find my buddies IP address?

wicked lagoon
wicked lagoon
wicked lagoon
calm briar
#

cool

#

yeah you'll find alot of stuff out there

calm briar
#

what are you using to take notes? i started to use google docs after the 3rd time losing everything

wicked lagoon
#

but when i'm doing a summary that i post on linkedin i use Photoshop i have experience as a designer

mighty veldt
#

cherrytree xD

wicked lagoon
#

this is an example

calm briar
#

I like using canva etc

wicked lagoon
mighty veldt
rapid merlin
wicked lagoon
calm briar
# wicked lagoon

where are you getting your graphics for hardware and communication??

narrow yew
#

What site would have the largest amount of subdomains stored?

mighty veldt
#

i guess

wicked lagoon
narrow yew
#

I tried that, I am looking for words in subdomains only

#

not for a specific parent domain

narrow yew
#

She can not be trusted with this

calm briar
wicked lagoon
#

the Cisco CCNA books are ELITE

narrow yew
mighty veldt
narrow yew
#

but this would in theory find anything "word."

calm briar
twin ridgeBOT
#

Gave +1 Rep to @wicked lagoon (current: #2122 - 2)

wicked lagoon
calm briar
calm briar
#

I got this interview coming up and they gave me a bunch of scenerios to 'explain to a client' so i'm going to make a fake pentest report with screen shots of these vulns/exploits so being able to explain some interactions via graphics will help to 'explain to non techinical c suites'

#

i'm using metasploitable 2/3 and juiceshop to illustrate the issues

calm briar
#

thanks dude. i dont' want to hope too much about it but i got to the final interview so i just gotta do this right.

rose tusk
#

My advice, flag things that are potential or require complex as lower priority to something that has an associated high/critical cve

calm briar
#

etc. i expect to use alot of similar and metaphor in explanation as well - thats why i was inquiring about graphics

rose tusk
#

you need to cover why this vulnerability is a problem. e.g. an attacker can download this exploit from the associated github and run against the target to gain elevated access

#

lemme pull an example, might be easier

#
Assessment Findings
1. Weak HMAC Authentication (Replay Risk)
Description
The agent communicates with the API by generating an HMAC signature only over the current timestamp. This means the signature is not tied to the actual request details such as the method, URI path, or request body. An attacker who can capture a legitimate request therefore gains both the timestamp and the signature and can replay them against other endpoints within the server’s acceptance window. The agent further exposes itself by printing the timestamp and signature to the console, making accidental leakage more likely.
Impact
This weakness undermines the entire trust model of agent-to-server authentication. An attacker who gains access to these headers can impersonate a legitimate agent without needing to know the underlying secret. They could use this to renew credentials, register malicious endpoints, or inject falsified monitoring data. Over time, this could erode the reliability of monitoring and potentially hide malicious activity.
Recommendations
The HMAC scheme should be improved so that it binds to all aspects of the request: method, path, body content, timestamp, and a unique nonce. The server should validate not only the signature but also ensure nonces are never reused, effectively preventing replay attacks. Console logging of sensitive headers must be removed entirely to reduce the risk of disclosure.
Business Impact
Major: Exploitation undermines trust in the agent ecosystem, potentially affecting monitoring across the organization.
Remediation Difficulty
Moderate: Requires changes to both agent signing logic and server-side validation.
Risk
High: Authentication bypass enables impersonation of agents.

CVSS v3.1: 8.1 High

IsUrgent: Yes

POC: replay.txt
calm briar
#

ahh that 'why' is a different why than what i meant. you're right. i hope you don't mind i copy and pasted it as an example to keep in mind when i'm writing my reports

rose tusk
#

nah, no worries 🙂 these are actual findings just to make it clear haha

sand trench
#

mullvad
ivpn
proton

#

in that order for vpns

calm briar
#

yeah i figured so

#

they're written very nicely. clean and precise.'

rose tusk
#

Thank you :), if you need my metrics system can give you that too

calm briar
#

what metric system do you use?

rose tusk
calm briar
#

i was going by cwe and cvss

rose tusk
#

I use a bit of a more business centric approach, to make the vulnerabilities easier to digest

calm briar
#

yeah i like that alot

#

the language used is business like but not too techy

sand trench
# rose tusk

critical
likely
major
hard

was the log4shell vuln

rose tusk
vapid geode
#

bruuuuuuuuh

rose tusk
#

change it to winter2025

calm briar
#

dude if i give them a report with metrics with an overview for remediation - they'll definitely throw in that monthy train pass with the job offer

rose tusk
#

don't steal my colour codes kekw i called dibs on them

sand trench
rapid merlin
#

Tuta ?

#

Can't remember cri

calm briar
#

OooOOoo i never thought of using my own color scheme

sand trench
calm briar
#

should we make it autumunal my dudes?

#

samhain approacheth

rose tusk
#

the colour codes are based on RAG, fyi

#

you don't want to steer too much from red amber green (blue for informational)

vapid geode
#

guess I can start using those randomize password generators...

#

like pwgen

sand trench
#

get keepassxc

#

or bitwarden

loud marlin
rapid merlin
# rose tusk

If I saw this as a non tech individual, the colors r subtle, not too bright nor too dull, just perfect blobheart

calm briar
calm briar
twin ridgeBOT
#

Gave +1 Rep to @frozen hull (current: #291 - 31)

dark wolf
#

My passwords are in a text file in c:\users\vigorizatnte\not_my_passwords\definitely_not_my_passwordlist.txt

#

I think I am safe

rose tusk
calm briar
#

My son's name is Magikarp

rose tusk
#

when he's 18 is he going to become gyarados?

sand trench
still glen
#

Hey guys! Whats the recommended wordlists for usernames and passwords for brute forcing thm boxes?

dark wolf
#

rockyou.txt

sand trench
#

sorry.. level 20

dark wolf
#

but thats only passswords

sand trench
#

miss remembered that

dark wolf
#

/usr/share/seclists or /usr/share/wordlists has them

still glen
narrow yew
#

@thick shell Impressive introduction in #intro.

loud marlin
#

rockyou is default on thm for bruteforce. if thm dont point to smth else on some room or so

dark wolf
#

/usr/share/seclists/Usernames for usernames and /usr/share/seclists/Passwords for passwords

narrow yew
#

Usually it is a name wordlist for usernames and rockyou for pws

#

What Viggo said

calm briar
#

i'm thinking of scripting a few things in to specifically do some stuff with these scenerios - is that too over the top and i should keep a couple tricks in the bag?

dark wolf
#

It only matters what you think

sand trench
sand trench
#

this is starting to be a banger of a series

still glen
narrow yew
#

@fair trail I accidentally found an anonymous POSt load on a sub....

narrow yew
twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2251)

sand trench
narrow yew
#

@sand trench you are in too info sec alot. How do you feel about ISO 27001

narrow yew
sand trench
narrow yew
#

I contacted the CTO of Globalconnect about it

#

From my work email for some legitimate powah.
But he is OOO

#

The ISP Allente pissed me off

#

So now they have a grumpy old guy after them

#

and the CTO of Telenor

calm briar
#

Does anyone happen to know where i could find a vulnbox in thm, htb, or vulnhub etc that has ssrs (sql server reporting services)?

#

that's the only one i'm having difficulty replicating immediately

#

but i guess i could spin up a windows box and do the whole mamajama

narrow yew
#

But that takes time

calm briar
#

yes. yes it does

dark wolf
#

Then when he walks in his house you can say "I've been expecting you!"

calm briar
#

hmm i think i found a couple htb retired ones that have ssrs available. i'll figure it out

dark wolf
polar holly
#

Guys the weirdest thing happened and I'm not sure... Usually our company doesn't advertise for pentest roles, they head hunt. I recently moved to data and am less than 3 months in my current role however I've been with the company for 4 years. So I asked my manager what he'd do in my situation and he only said he'll come back to me tomorrow.

dark wolf
#

Vigo says thank you shadow

twin ridgeBOT
#

Gave +1 Rep to @sand trench (current: #4 - 2252)

still glen
twin ridgeBOT
#

Gave +1 Rep to @dark wolf (current: #85 - 117)

still glen
#

Downdetector says so

sand trench
#

GG amazon

#

proving why the big tech giants is bad

still glen
sand trench
#

the internet was supposed to be decentralised

#

but apparently 50%+ use aws

sand trench
#

don't buy internet of things devices basically

sand trench
#

instead buy ploopy hardware

distant robin
#

beep boop beep boop meep moop poop pee

sand trench
#

ey the meep moops belong to shadow

marsh lark
wicked lagoon
#

how HR team feel like when they make your life miserable

narrow yew
#

if not reporting colleuges

#

I am making new friends reporting people to HR every now and then

wicked lagoon
narrow yew
#

Im IT Security, they don't dare to do shit 😄

boreal scarab
narrow yew
#

Well they deserve it and its not something they did per say.

Maybe storing videos for adults with obscene names on their work USBs etc.

That is for HR to solve

narrow yew
#

They just dont think about XSIEM to store all content from any USB stick in logs

#

And that we monitor it 😄

boreal scarab
narrow yew
#

Enumerate all the things is the life motto

tribal tapir
#

Hi are there any rooms to group up with someone on some security projects?

blissful snow
#

Are you looking for rooms or team projects

dark wolf
tribal tapir
blissful snow
#

Hm what level would you say your at

tribal tapir
#

but it is preferable that it is group work as in regular corporate work

dark wolf
clever turret
#

Pen

blissful snow
dark wolf
blissful snow
#

Are you sure?

dark wolf
#

Yes, I already have too many targets to go through

tribal tapir
blissful snow
#

through or to ? kekw

blissful snow
dark wolf
tribal tapir
#

I'm more into offensive but I know it's good to start in the defensive fields so I'll do both

blissful snow
#

which one would you perfer

tribal tapir
#

offensive

blissful snow
#

hm ok

#

I guess search up offensive tools and start there

dark wolf
#

So you don't want a job , just learning for fun?

blissful snow
#

Most offensive projects are just attacking and making tools from what I'll seen so far

dark wolf
wicked lagoon
#

which provider is used more in canada AWS or Azure ?

tribal tapir
wicked lagoon
tribal tapir
#

but firstly I need to craft something to my portfolio I guess

dark wolf
wicked lagoon
#
  1. Implementing XDR Platform using: Wazuh + Suricata + TheHive + Cortex

  2. Implementing Threat Intelligence and IOC Correlation Platform (Wazuh + MISP + YARA)

  3. Implementing Adversary Emulation & Detection Platform (Wazuh + Atomic Red Team + MITRE ATT&CK)

  4. Deploying Compliance Assessment Platform (Wazuh + Grafana + OpenSCAP)

  5. Deploying Automated Incident Response System (Wazuh + SOAR tool like Shuffle or StackStorm)

  6. Implementing AI-assisted Threat Detection Platform (Wazuh + ELK + ML pipeline)

these are some projects that were adviced to me by an expert

blissful snow
#

I don't really like defensive its boring

#

sometimes

wicked lagoon
#

boring = less people doing it = more chances of finding a job

tribal tapir
wicked lagoon
#

good luck use THM & Hackthebox academy for resources

blissful snow
#

Btw THM premium is worth it

#

If you have enough ofc

wicked lagoon
#

THM yearly subscription + monthly student HTB academy subscription is a deadly combo

blissful snow
#

I haven't went back to hackthebox yet

#

its been a while

tribal tapir
wicked lagoon
#

i'm following the SOC path on both platforms

#

goal is to get my CCD in two years

blissful snow
#

What is that

wicked lagoon
#

Certified cyber defender

#

one of the hardest blue team certifications

blissful snow
#

What after that one

wicked lagoon
#

i think it depends on the path you'll take

blissful snow
#

ah

wicked lagoon
#

BTL2 is also a great choice

wicked lagoon
#

me too bro lmaooo

#

i wanna get my CPTS and that's gonna be it for me in red teaming

blissful snow
#

Nice

wicked lagoon
#

i'm focusing on cloud and SOC that's it

blissful snow
#

I wish I could join HTB server :(

blissful snow
#

sometimes i've been thinking about

wicked lagoon
wicked lagoon
blissful snow
#

Me banned

wicked lagoon
#

passing my AZ-104 in december

blissful snow
#

I have no clue what that is lol

wicked lagoon
#

azure certifications

blissful snow
#

ahh

#

Just wondering are there 900 certs

#

or is the number something else

wicked lagoon
#

it's just a code

blissful snow
#

ohh ok

blissful snow
twin ridgeBOT
#

Gave +1 Rep to @heavy storm (current: #1099 - 5)

blissful snow
#

oh no i've got clay in my eye 😭

tribal tapir
# heavy storm https://pauljerimy.com/security-certification-roadmap/

I've been to a webinar recently where soc menager said that certs don't really matter for him rn. The key to land first job at cyber sec is having basic skills requied to navigate in soc and some type of thinking that's critical for this type of job, I can't really specify what kind that is, but he also said that it is better to have few github projects that show steps that you've made to obtain certain results

dawn wren
#

I dont know about you guys but I am done with recon. That alone mentality burned me out i know it's important but it's not need for most vulnerabilities out there.

twin ridgeBOT
#

Gave +1 Rep to @tribal tapir (current: #3229 - 1)

wicked lagoon
#

the guy with certifications will always have a better chance of getting an interview

dawn wren
#

Any certification is better than nothing these days regardless if it's well known or not.

blissful snow
gusty inlet
#

Filter by price.

blissful snow
#

thankss

#

Also jsut wondering can normal people buy data from data brokers

#

just*

sand trench
blissful snow
#

Ah ok

dawn wren
blissful snow
#

How muc his stuff like that

blissful snow
slow cloud
#

i think googles cert is pretty worthless

dawn wren
slow cloud
#

according to the people here

gaunt flower
#

Hey there!
Are you having trouble with a lost or hacked Roblox account? Don't worry, I'm here to help! 💡 I can assist with account recovery, password resets, and security measures to prevent future issues. Whether you've been scammed, lost access, or just need some guidance, I'm here to help. 🤝 Let me know if you need assistance, and I'll do my best to get you back in control of your account! 😊"

slow cloud
#

but idk, i didnt get it

#

ah yes

slow cloud
blissful snow
crimson portal
#

Someone need any sorts of help or any type of script for ANYTHING?

dawn wren
#

The whole point of certifications is to get past those HR gatekeepers and get hired. Beat the competition I used to work with people who had all the certifications in the world but didn't know WTF they were doing.

There is a difference between theory and practical

gaunt flower
dawn wren
#

IMO you can multiple choice your way into a job in cybersecurity.

blissful snow
#

crazy

blissful snow
#

I never looked into this type of scam

slow cloud
#

you either pay them and they dont give you anything

#

or maybe hack your email

#

or account

#

idk

blissful snow
#

"hack"

slow cloud
gusty inlet
twin ridgeBOT
#

Gave +1 Rep to @slow cloud (current: #54 - 197)

grim sparrowBOT
#

:hammer: ericmatteo#0 has been banned.

loud marlin
#

dumbass backup script =/

dark wolf
glacial cove
sand trench
#

personally use pika backup

#

because don't really care about system folders.... as nearly all important data is in /home/

dark wolf
sand trench
#

also had to undo all the sddm hardening shadow did as it made podman crash with cryptic errors

ripe sleet
#

😮
New Rules section?

sand trench
#

ello darkfly

ripe sleet
sand trench
#

slightly excited for new art commission shadow is starting to pay for

chilly veldt
#

red motorcycle is now sold

sand trench
chilly veldt
#

yes

sand trench
#

also how much did it sell for??

dark wolf
chilly veldt
sand trench
chilly veldt
#

it's cause it doesn't run

#

needs to be fixed first

dense hinge
#

this website

#

is so peak ngl

rapid merlin
mossy river
#

@marsh lark

coarse hedge
#

I have been playing CR for 8 years, but never reached top 10 in global 😮‍💨

gusty inlet
lone thistle
gusty inlet
#

better

lone thistle
#

pray tell?

gusty inlet
#

Clash Royale

lone thistle
#

AHHH

#

tomato tomato 😄

mossy river
#

Tomato tomato??

#

CMNatic this is the first time I’m ever disagreeing with you

mossy river
gusty inlet
#

I can't find a good Netflix serie or movie for the love of god. kekw

#

Nothing's entertaining.

narrow yew
#

Poking around a bit and seeing this on an RDP
OS: Windows 8.1/Windows Server 2012 R2
OS Build: 6.3.9600

#

must resist the urge

#

too poke

#

Just browsing a few IP ranges on Shodan, nothing too exciting.

#

"Blackbox"

bright stone
#

Hi can somone help me. I’m stuck on an “wifi hacking” training. The goal of that training is to accses the admin panel of the wifi, but I don’t know how. I already cracked the hash of the wifi password by deauth the fake devices to force them to login again. But I don’t how to continue

dark wolf
bright stone
narrow yew
#

and the admin page is not on the default IPs?

bright stone
dark wolf
#

Don't know you well enough to know your tastes @gusty inlet

narrow yew
dark wolf
narrow yew
#

look at your own router, on what IP is the admin interface located?

#

is it not the same kind of question here?

#

just enumerate all IPs?

#

@dark wolf Maybe I am all wrong here and not undestanding the issue

#

seems like a no brainer

bright stone
dark wolf
#

I don't know Math, I'm working and not paying attn

narrow yew
#

I can help you work

#

@bright stone What have you tried

ripe sleet
# gusty inlet Clash Royale

I saw these sora clips where characters from that game are on your front step. There's one where the hog riders break into your house

bright stone
narrow yew
#

what router is it then

ripe sleet
bright stone
narrow yew
#

and what IP numbers have you found

#

Do not reply you used routersploit

dark wolf
#

THM has a wifi room?? whats the url

narrow yew
#

Its not THM

dark wolf
#

The mods discourage helping people with challenges not originated from here

narrow yew
#

Otherwise he would have said so

bright stone
dark wolf
#

They could be hacking someone

narrow yew
#

True

#

but if admin/admin did not work

#

he's out of luck

sturdy sequoia
bright stone
narrow yew
bright stone
#

But how can find the flag. I can’t continue

narrow yew
#

@WWW share it, I want to do it

#

We can do it with Viggo

#

he needs a break from work

dark wolf
bright stone
#

And I tried burp suite on the see the requests for the login page. And still that didn’t help

narrow yew
#

I need to do something, my grey hat is slowly turning dark by looking at all these IPs

bright stone
#

I don’t how to continue with that CTF. And I can’t get hints

narrow yew
#

And you are not sharing the CTF

bright stone
narrow yew
#

So I suggest you move along 🙂

next kelp
#

I am doing the Powershell room. First time I have seen it broken down like this. It's a REPL.

narrow yew
#

Tooo late, i've moved on

bright stone
dark wolf
rapid merlin
#

How do I hack library

#

Library say I have to pay library fees

#

How to change numbers like in Mr robot

#

?

narrow yew
#

Then you pay ofc

rapid merlin
#

Huh

next kelp
#

Move to another county

rapid merlin
#

No I use kali Linux

#

To stop library

narrow yew
#

If you owe money you pay it

#

That is how life works

rapid merlin
#

Huh

dark wolf
rapid merlin
#

No

#

No I use kali linux to stop library

#

And stop the fees

#

Like Mr ribit did

narrow yew
#

Mr rabit is now mr soup

#

sorry

rapid merlin
#

Kale 🥬

narrow yew
#

What library is it?

dark wolf
sleek hare
#

its illegal?

#

to hack library

dark wolf
narrow yew
#

Maybe he wrote a lib

#

made it an AI

#

AI is now pissed off

sleek hare
#

he means library

narrow yew
#

demands money

sleek hare
#

like physical place

dark wolf
#

yeah, C ? Java? Python?

sleek hare
#

right?

dark wolf
#

Oooooooooooooohhhhhhhhhhhhhhhhhhhhhhhh

narrow yew
#

Yes he does

sleek hare
#

@rapid merlin so like

#

the place

#

where you get books

#

right?

sleek hare
dark wolf
#

i see

narrow yew
#

ofc he wants to hack his school lib or somehting due to the fact that he ows money

dark wolf
#

hahah i been there plenty of times

dark wolf
#

in school you had to go to library to study

#

i had no internet

gusty inlet
sleek hare
#

withotu letting school know I broke old one

#

:3

dark wolf
#

no phone

narrow yew
#

But If he just tells us the library's name we can just tell them to add more to his account

sleek hare
#

id add there extra fee

#

"trying to hack lbirary"
10k USD

#

cuz

#

why not?

narrow yew
#

Well if he does the rest is easy

sleek hare
#

how many russians are there

sleek hare
#

CS GO with fire sign == 10000% russians

rapid merlin
#

It’s not Russian it’s an American podcast

sleek hare
#

my friend wrote website

narrow yew
#

I even have the script

sleek hare
#

added there ping command

dark wolf
#

The earths mantle has a CVE rated 10.0

sleek hare
#

guess how many vulns I found?

rapid merlin
#

I can’t tell you what library. Developing kali linux hacks

dark wolf
#

we should exploit it

sleek hare
#

right about two vulns which gave root access

#

💀

rapid merlin
#

I’m developing a device. Device generates unlimited WiFi anywhere you go.

#

Using kali linux. And library wifi

narrow yew
sleek hare
#

for sure

#

he said WIFI

rapid merlin
#

Huh

narrow yew
#

Well its a 4g/5g router

rapid merlin
#

No it isn’t

narrow yew
#

Oh

#

you'r friends with Elon

rapid merlin
#

Device makes unlimited wifi

narrow yew
#

Does it have internet?

#

or just wifi

#

because my Raspberry will do that just fine creating an wifi

#

Why post those referal links?

#

@dark wolf you can report it for me

#

im old

rapid merlin
#

Idk it’s using kali linux

narrow yew
#

You have mentioned that a few times now

rapid merlin
#

Yeah exactly

#

I’m using kali linux to make free wifi

narrow yew
#

Yes you told us

sleek hare
#

Bro either tries to scam or earn 10$

dark wolf
#

I reported it

narrow yew
#

There have been a few of those links today

sleek hare
#

If not wrong its referrals

#

For commet

narrow yew
#

If it were free Claude I would have signed up

sleek hare
#

Per user 10$

dark wolf
sleek hare
#

Yep

#

And also earning moni

narrow yew
#

Claude is a great AI

rapid merlin
#

Plan to use kali linux to act as wifi router. And then connect to free school wifi

sleek hare
#

Human brain is great AI

rapid merlin
#

And generate unlimited wifi anywhere you go. With Kali Linux

sleek hare
#

Amazing thing you know

dark wolf
#

I swear this that dude has about 90 lines with the words wifi linux and kali all in it

sleek hare
#

@rapid merlin

#

wat is kali linux

dark wolf
#

what is wifi

sleek hare
#

(other don't say a word doing test)

#

wat library are you using?

dark wolf
sleek hare
#

do you also have controller licence

#

i think its a bit overkill for my use case

rapid merlin
#

I am the Mr robit

sleek hare
#

but i have it

sleek hare
rapid merlin
#

Or rather. The Mr Kali Linux Ribot

sleek hare
#

Now tell me what is kali linux

hollow lodge
#

Hii guys I'm not a professionel so I should to build a portfolio ? and makes write-ups for any room I finish ?

narrow yew
#

So you have kali, sharing schools wifi

#

how does it share it everywhere you go

#

And explain how mobile hotspot while phone is connected to wifi is not the same thing

narrow yew
#

I guess you could set up your own Cell tower

sleek hare
#

i really regret not doing streams when I did insane challenges

dark wolf
sleek hare
#

I might redo them for fun

#

If I find out how to redo a challenge..

#

I'm nee to this web still 💔

#

Didn't click all the buttons yk

dark wolf
#

on any room and you can redo it

#

no more points tho

rapid merlin
#

Idk I heard kali linux makes wifi

#

For free and unlimited

#

YouTube video

sturdy sequoia
narrow yew
#

I think he is

#

Or he be special

dark wolf
#

I just reported

#

spamming

narrow yew
sleek hare
#

Sounds fun

dark wolf
sleek hare
#

Theseus stream commin

#

Oh wait. No nvm

#

I ain't leaking theseus

#

I'll stay loyal to it

narrow yew
#

Or what printer do you print mods for 2025 that is not a selected few that is not Bambu

#

Prusa? But those will slowly die, Bambu took too big piece of the market

dark wolf
#

Ender 3d Pro

narrow yew
#

Haha Ender 😄

dark wolf
#

Got it 4 yrs ago

narrow yew
#

I have an old dusty one forgotten in the basement

#

V2

dark wolf
#

It works just fine

#

yeah

narrow yew
#

I have an P1S that is the best ever

#

And a few resin once

dark wolf
#

What do you print?

narrow yew
dark wolf
#

hahah yeah, well we try and keep our place free of chachkies

narrow yew
#

Gadgets for home and gifts, cookie cutters for christmas. Nothing too serious.

dark wolf
#

or however you spell it

narrow yew
#

If you were in to resin printing I would hook you up with files

zealous socket
#

if system.isCrashed: system. restart(system)

narrow yew
#

IF system crached

#

there be no restart

#

System be ded

dense hinge
#

i love how i be getting stuck on some of the beginner module questions for no reason 😭

#

i might be cooked on some of the harder ones

#

💀

sturdy sequoia
#

you cant know everything

dense hinge
#

for sure

hidden gull
#

Hi, i try migrate the process but don't work in room/blue , someone can help me

dense hinge
#

i love it when i give up and have to look at a walk through and then realize what im doing wrong, and it gives me the boost i need to answer all the other questions easily after feeling silly for a few moments

#

lmfao

dark wolf
#

sometimes you just need that one clue

dense hinge
#

yup

sturdy sequoia
#

the walkthroughs are there for a reason

dense hinge
#

real

dark wolf
#

How about a bot that scrapes walkthroughs and does the ctf for you when you are sleeping

#

lol

dense hinge
#

😂

hidden gull
#

i try several pid but don't work

sturdy sequoia
dense hinge
#

i cant wait to get to the blue team level 1 path

#

im excited to learn that stuff

narrow yew
umbral bay
#

👋

ripe sleet
blissful snow
#

Hi

ripe sleet
blissful snow
#

Just wondering do I know I forgot people a lot 😭

blissful snow
#

Sorry

#

Ahh ok

#

Well hru

ripe sleet
sleek hare
#

like a potato

#

worse

#

or better

#

no idea

dense hinge
#

is it chill if i go abit out of order for some of the learning paths? like doing the splunk basics in soc level 1 and then heading to soc level 2 to do the advanced splunk stuff for example

#

i think splunk is the first tool i wanna get super comfortable with

#

🤔

sturdy sequoia
#

yer do what you want. i dont even follow a path

dense hinge
#

bet

ripe sleet
sleek hare
#

Soon

#

Aka yes it will improve

#

As I love sleeping

#

But depends if someone will wake me up in the morning or no

sleek hare
sleek hare
#

I just go straight challanges

sturdy sequoia
#

i just do rooms i find interesting.

sleek hare
#

I just do either all challenges which are purple team

#

Or all insane ones

#

Or hard ones I find interesting

#

Insane ones sadly all completed

#

I don't have premium to do Osiris

dense hinge
#

i kinda wanna mainly focus on the skills that will be important for the job i want

#

but there are a ton of super cool rooms

#

im hyped to try

dense hinge
sand trench
#

huh so apparently shadow is not the only person using shadow absorber as a username

narrow yew
#

Whuut

dense hinge
#

Soc analyst

sand trench
#

did not expect that

dense hinge
#

pentesting is cool

#

i wanna learn that stuff eventually

narrow yew
#

(Im a SOC) So im all for it

dense hinge
#

maybe go for OSCP if i want to make myself suffer

dense hinge
#

thats sick

narrow yew
#

I pentest at work, I manage our bug bounty program so I triage everything, and I can pentest all I want in our enviorment

#

And its alot.

#

But SOC work takes heeps of time if one allows it

slim patrol
#

is openvpn not working for anyone else? keeps disconnecting

dense hinge
#

lmao

narrow yew
#

Shehe have fans everywhere

#

There is only one absorber

celest dirge
#

Hopefully, no one has taken my name just yet.

#

I don't mind fans, but y'know.

sand trench
#

only find them when running sherlock to find old unused accounts to remove

long lotus
#

guys, rate my dog kekw

sand trench
#

don't want to ruin others days thats for sure

sand trench
narrow yew
long lotus
celest dirge
narrow yew
#

Maybe its stuffed

#

and just resting

long lotus
long lotus
celest dirge
narrow yew
#

I am guessing dead

#

Some people even keep dead parents for company

sleek hare
#

I hate them

#

But urs looks nice

#

Ig

#

Anyways gn chat

brisk cairn
pastel tartan
#

Hello if i want to take the 1 year of ine fundamentals that include ejpt exam + ICCA what rooms to finish in tryhackme first before taking the practice in ine for ejpt

grim sparrowBOT
#

Done!

sand trench
#

thank you dkob

#

not sure if they posted in multiple channels but that message sure seemed sketchy

#

@boreal scarab how often use sherlock???

topaz topaz
#

Hey guys easy question, doing a THM room where I've gained admin access to a Wordpress blog website. How do you guys usually go about retrieving flags in these situations?

#

Are they hidden in posts, dashboard?

boreal scarab
sand trench
sturdy sequoia
topaz topaz
boreal scarab
sand trench
#

then from there use grep to find flags

boreal scarab
#

Haven't touched my Graphene phone in about 2-3 months..... it's so out of date lol

sturdy sequoia
twin ridgeBOT
#

Gave +1 Rep to @topaz topaz (current: #235 - 40)

topaz topaz
sand trench
#

using grep to scan for flags in likely folders is very nice

topaz topaz
#

Or am I looking at it wrong

sand trench
#

well more or less yes

topaz topaz
#

(Not asking for an answer just looking for a key while blindfolded)

sand trench
#

you can upload a php file in most instances that replaces a 404 link

boreal scarab
topaz topaz
sturdy sequoia
#

yer a reverse shell will basically give you a console

boreal scarab
#

F-Droid has a lot of updates, Aurora store, Graphene App Store, System updates

boreal scarab
#

The other is a Pixel

boreal scarab
#

Pixel 7a Pro to be exact

topaz topaz
#

the S22 Ultra in Burgundy is still the most beautiful phone to ever come out in my opinion

#

I much prefer the Pixel 9's design but it doesn't compete against that burgundy

sand trench
#

shadow happy with their pixel 9 with graphene

#

also now got a nice grippy case for it

boreal scarab
#

Was it S7 or Note 7?

#

Which one exploded?

topaz topaz
topaz topaz
boreal scarab
topaz topaz
boreal scarab
topaz topaz
boreal scarab
#

I had a Note 4, S8, then S21 Ultra

#

But I didn't start on the 4

#

I started on a flip phone baby WOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOH

boreal scarab
#

MOTOROLA RAZOR LETS GOOOOOOOOOO

sand trench
#

have a fairphone 5 shadow needs to repair

topaz topaz
#

This was unc's first phone (mine)

sturdy sequoia
#

haha my first phone was an ericsson a1018s

sand trench
#

any nokia users in chat???

topaz topaz
#

It's basically Nokias that were bought out

sand trench
boreal scarab
#

Let me get Grandpa in here..... @normal fable What was your first cell phone? The brick?

topaz topaz
#

I had a 535 as a first smartphone ever

sturdy sequoia
#

im so old

topaz topaz
boreal scarab
#

GET THAT MICROSOFT PIECE OF SHIT WINDOWS 8 FUCKING CRAP OUTTA HERE

topaz topaz
#

I couldn't wait to get it off my hands

#

I do have fond memories of it though, I had a Gameboy emulator with a mortal kombat deception rom and would play through it in secret during boring classes as a teen 😂

sturdy sequoia
#

i used to have a HP ipaq before phones had touch screens

sand trench
#

blackberry users rise up

boreal scarab
boreal scarab
topaz topaz
topaz topaz
#

I saw my grandma using that flip phone I posted and I was like "yeah I want that.."

boreal scarab
#

Customizable notification light to tell you if it was a BBM message, text, and from who

topaz topaz
#

I feel like going back to dumbphones, anyone else have the urge every so often?

boreal scarab
#

Blackberry was great

topaz topaz
boreal scarab
sturdy sequoia
topaz topaz
topaz topaz
boreal scarab
#

No reason WHATSOEVER..... Having FDroid going through TOR for updating my apps, Proton going through 2 servers, both non 14 eyes.

Hypatia going through tor.

#

Is there any reason? Fuck no

#

Do I care? Also fuck no

topaz topaz
boreal scarab
boreal scarab
topaz topaz
#

I'm not talking about government surveillance per say, I don't care about that. I just think of how our communities expect us to roam with smartphones, using them for the slightest of activities. Going to a restaurant? Scan the QR code, no menus.

#

I know it sounds backwards and I understand the controversy behind such an opinion, but I do wish we could go back to times where smartphones were a luxury and not expected of a civilian to carry around in order to cover the incompetence of others

boreal scarab
sturdy sequoia
#

to each their own. this same kind of stuff happens a lot with new technology. give it 20 years until its the norm and no one will care

boreal scarab
topaz topaz
boreal scarab
#

This job I don't handle sensitive data at all. I used to, Thanks HIPAA...... but never saved anything besides "Room X has this issue Desk X has that issue"

sturdy sequoia
topaz topaz
boreal scarab
remote cradle
#

Why is it hard to see who knows website that see email logins?

sand trench
#

does not parse
try again

boreal scarab
#

Current job, I don't have access to tickets, so all my notes and everything I have to keep, dated too, so when my boss asks me "Hey, X, what happened there on Friday X date" I can easily go back and look

topaz topaz
boreal scarab
#

But again, my notes just consist of what to do that day, what happened, what did someone tell me, what questions do they need me to ask someone

nimble gorge
boreal scarab
#

Oh shit, Ubuntu has ZFS with encryption... experimental, but nice that they have ZFS

sand trench
#

license thingies

woven drift
boreal scarab
#

Also ZFS has Software Raid, RAIDZ, no need for hardware raiding.

sand trench
#

shadow knows plenty of what ZFS is

boreal scarab
#

RaidZ1 I think is a Raid6? I can't remember the whole RAID crap

sand trench
#

also know that you gotta do crazy vodoo to install it on arch

boreal scarab
#

My Graphene phone thinks it's in Poland?

#

TF?

fervent cove
#

Hi, I’m Excel 🌸

sturdy sequoia
#

@remote cradle please dont dm me without asking first

fervent cove
#

can i dm u

rapid merlin
#

hey

ripe sleet
ripe sleet
ripe sleet
topaz topaz
ripe sleet
topaz topaz
ripe sleet
#

Doubt it

topaz topaz
#

Where did you find these? I haven't seen anything like that

#

Have you reported that content?

#

Admins are often quick to take action, but at the end of the day this is a public cybersecurity server

#

Please report it as well

pallid lotus
#

... How'd you figure that one out?

topaz topaz
#

Should it not be okay, admins will take action

topaz topaz
#

Although I do not see where the maliciousness is

#

But as mentioned earlier if the admins deem it inappropriate they'll take action against it, I don't have any input on the matter

#

Are you sure it's not your phone's antivirus software playing tricks on you?

pallid lotus
#

Detected how?

topaz topaz
pallid lotus
#

Dunno what AV you're using but VirusTotal thinks it's clean

pallid lotus
#

Aside from Fortinet marking it as spam, but A) who listens to Fortinet and B) that ain't a malware designation

boreal scarab
topaz topaz
#

Seeing your screenshot from earlier, I would recommend you switch AVs, or not use one on your phone if you feel you can avoid shady links

pallid lotus
pallid lotus
nimble gorge
cosmic pendant
nimble gorge
#

Read the text in the screen shot

#

duh

topaz topaz
pallid lotus
topaz topaz
#

And next time I'll do the same cause it's better to bring this to the right people's attention and they can decide further

pallid lotus
boreal scarab
sand trench
#

ello and good night muiri
shadow is gonna go sleep nows

#

meep moop to sleep sloop while beep boop basically

boreal scarab
#

Example... gave me Hackenproof for my username and yours, 500 error..... always hate the false positives

pallid lotus
# nimble gorge

Fyi, there's also a time article on this:
https://time.com/7327409/ai-agi-superintelligent-open-letter/

And CNBC:
https://www.cnbc.com/2025/10/22/800-petition-signatures-apple-steve-wozniak-and-virgin-richard-branson-superintelligence-race.html

Plus a bunch of others.

So, to summarise:

  • VirusTotal ran 68 AV Engines / URL status checks against it. They all came back clean.
  • Multiple major news outlets have run stories corroborating the existence of the site.
  • The only thing flagging it is whatever the heck you've got installed in your browser.

I remain open to correction, but I'd say there's a reasonable chance it's legit kekw

TIME

Prince Harry, Steve Bannon, and tech leaders join 700 signees urging a halt to superintelligent AI research.

CNBC

A group of prominent figures, including artificial intelligence heavyweights, has lead a call to end efforts to create ‘superintelligence.'

real leaf
#

Hello im Wann im getting into cybersecurity ive always loved computers if anyone needs a study partner or someone to get help and just spend hours on trying to fiqure out somthing im open to being that person its always fun doing things with people instead of by your self send me a dm im about half way done in cyber security 101

desert shuttle
#

Hola

dark wolf
brazen crane
#

Gday humaniods of the inter of nets, how are we all feeling today?

dark wolf
#

Fantastic

#

Just busy hacking something

#

Although I have to say I am a bit paranoid as it is my first time hacking a voodoo doll

sturdy sequoia
#

a what?