#general
1 messages · Page 1805 of 1
Imagine doing that either by the end of this month or at the start of April

and on proton i can select what i wish
12fdddd2017c2bb9e3a8406f3f34e9941af66ad6e89006f441e978e427b79307@shadowabsorber.com
if anyone wanna test if shadows email is working here is a temporary throwaway address :D
oh shit
ralex pressed yubikey in wrong chat
lol
Our does via face recognition and qr.( Something introduced this year cuz the owner of the group realised he has a clg and he shd mark his presense
oh, it is one that every press regenerate
different app use different protocol heh 🙂
true but you can do weird timing attacks with those
time to make my professors put some elbow grease into checking if the work i do is AI generated 
indeed. but you can proram key to certein time that will generate few of them and only output one in certein time
anyone know if tuta to protonmail or the reverse also works with fully end to end encrypted emails???
or is it only inside their own ecosystems
Got it! Thank you so much, Alexander! I learned a lot, and I will try the protonmail for a start first

Gave +1 Rep to @loud marlin (current: #23 - 452)
yeah they have free option... though better pay for it eventually
just proton pushes hard for you to get the proton unlimited at 9.99 a month to have their entire suite of things
As far as I know Proton is very restrictive with stuff that‘s not their product, so I‘d not expect that. Don‘t actually know tho.
but thats me whenever I see you lol
That I rush like a ghost! Or the cat in that sticker heh
yeah.....
proton also have some things liek that
Got it. Thank you very much Shadow!

Gave +1 Rep to @sand trench (current: #4 - 2250)
Honestly worth it IMO.
aww!
It‘s not perfect tho, I wish I could mount their cloud storage.
kinda agree but shadow wants to compartmentalise which is not a thingy everyone wants to do or needs to do
well... shadow can do things and send ralex email to check if things works... if wish
sure
If a cat does this to me, the cat can have all the treats I have in my pockets for sure.

ill dm you email. but i think is kinda obvious what it is heh
I honestly only use 'em for the mail and everything else is a neat addon, but I tend to have other solutions for it. E.g. using Mullvad for a VPN.
I can login now
But the courses are loading very slow
¯_(ツ)_/¯
The file share is really neat when you need to share larger files with people as well.
paid services of shadow:
tuta revolutionary
mullvad vpn
domain name from somewhere :D
Or yourself.
Where r u from, if you don't mind me asking
tried a speedtest?
I have a bit more stuff as I self host multiple things over a VPS. Too lazy to type it out on mobile. xD
Client side encrypted, of course.
But yea, domain name, vps, mullvad and proton are my main subs as well.
technically shadow has more paid services but not gonna list out everything as that would be a security risk to a degree
Yee, same.
having your own domain name helps a ton
Got two, even, because one is free if you pay for the other with my provider. :D
also domain names nowadays are surprisingly cheap
Honk Kong should have fast internet
Only using one of them tho, atm.
Maybe check your DNS
I just recently able to login and load the course
Maybe the thing is down because of the AWS outage or something.
It's working for a lot of people
Maybe 🤔

Did you try a VPN
good morning ladys

https://shadowabsorber.com is very boring
well... it works =)... you can also attach public keys and so on tuta ?
¯_(ツ)_/¯
How much, a dollar for a month then pay some amount?
they use other protocol for encryption then rsa

10 usd a year for the domain name
free hosting on github for static site
Try before u die
https://proton.me/support/how-to-use-pgp proton can do this
Right, cool
Tuta uses symmetric (AES 256) and asymmetric encryption (RSA 2048 or ECC (x25519) and Kyber-1024 as quantum-safe algorithms) to encrypt emails end-to-end. When both parties use Tuta, all emails are automatically end-to-end encrypted (asymmetric encryption). For an encrypted email to an external recipient, a password for encrypting & decrypting the email (symmetric encryption) must be exchanged once. You can then use the same password for any conversation with that specific contact: With Tuta you don’t need to set a new password for each email sent to the same contact.
Tuta’s automatic encryption works easily on all mobile and desktop devices. The encryption key is never shared with anyone else, including Tuta. Therefore, even if a malicious attacker intercepts the email message, they will not be able to read its content or attachments.
(joking)
Why does Tuta Mail not use PGP?
Tuta uses standard algorithms also being used by PGP (AES and RSA or ECC) for encrypting the entire mailbox. In addition, Tuta Mail already uses post-quantum cryptography (Kyber) for quantum safe accounts, which is still a work in progress for PGP. Furthermore, Tuta does not use an implementation of PGP itself because PGP lacks important requirements that we have for Tuta:
PGP does not encrypt the subject line (already achieved in Tuta), PGP algorithms can't be easily updated, e.g. to post-quantum secure ones like in Tuta Mail, PGP has no option for Perfect Forward Secrecy (already achieved for Tuta in a prototype).In Tuta we can easily update the algorithms, and we plan to replace the current algorithms with quantum secure hybrid protocol in the near future. The flexibility of Tuta enables us to integrate an encrypted calendar, encrypted cloud storage and many more features much easier and faster than it would have been possible with an implementation of PGP.
Yes that is accurate Vigo. People use easy pins to login to their computer so if they use passkeys and someone gets their device, they are screwed lol
the encryption of subject line is important to shadow
as any meta data leak can be bad
fair fair
There is cloud hacking tryhackme
Speaking of VPN, why does ppl online NOT recommend using Opera's Free VPN?
so because i've gotten these scenerios for the next interview- i feel like i could do a write up for them ? like instead of just discussing them i show that i know how to construct a write up and talk about it. maybe i could have a cheat sheet of some similes or metaphor for more techinical ideas to help fill out the grey areas
Is THM having issues again, Can't get a room to load for some reason.
free vpn = not free
good idea or over doing it?
May I ask what is being extracted from me to make 'free' VPN?
I heard Opera sold user's browsing data
if vpn is free. then person who own vpn server can read all data.
use payd vpn from trusted one
mullvad, proton or some by own choice
Proton is pretty good
What about Vivaldi?
jsut know. if ding illegal things it might not protect you if some 3 letter agencies ask for data
idk. im on proton
Russian vpn?
what do you guys use for making reports? i just spent dumb long learning sysreptor and it's pretty cool - i gotta get my html on point though for putting my own graphics where i want them obvi
hey guys i got a question
question us
is it okay to create summaries based on Tryhackme rooms and post them on linkedin and github ?
Hey chat
i want to create a series of summaries of different subjects and use tryhackme and other resources to create beginner series
im still confused who is jabba
you mean like tactics, techniques and proceedures? ttps? if its in your own words you gucci
is thm emply who can tell you more of thing you ask
nah just like windows basics , linux basics , wireshark ex....
when he show's up here you can ask directly
Yea, THM seems kinda slow atm
ahh. i mean sure. you are just aggregating the information but you are displaying it differently. i'm sure you'll add more for other sources along your journey as well
i mean - it's just like keeping good notes
import re
yea exactly since i'm reviewing what i studied so i don't forget while progressing i said why not make summaries and post them on linkedin and github for more interaction
wrong window
hi
yeah i think that's all good - as long as you don't take their trademarked stuff or plagarize them directly
like what
plus you'll find more stuff - take a tour of hacktricks and other repositories
like screen shots of their website.
Does anyone know how I could find my buddies IP address?
oh nah nah
192.168.0.1
i'm using both hackthebox and tryhackme
127.0.0.1
Ask him/j
what are you using to take notes? i started to use google docs after the 3rd time losing everything
Obsidian
Obsidian
sublime text\
but when i'm doing a summary that i post on linkedin i use Photoshop i have experience as a designer
cherrytree xD
I like using canva etc
only GOATs use obsidian
th fk.. 🤣🤣

i mean word or photoshop are a better alternative on the long run
where are you getting your graphics for hardware and communication??
What site would have the largest amount of subdomains stored?
for the hardware i use cisco's icons they post it for free , and i download them off of iconfinder
I tried that, I am looking for words in subdomains only
not for a specific parent domain
ask chatgpt
She can not be trusted with this
you dont like it or use it? i was using it alot when i made my osi coloring book it just continued
the Cisco CCNA books are ELITE
https://crt.sh/?q=%25MBZ.%25&output=json
This does not work perfectly
yes yes. iz good man.. was jkin xD
but this would in theory find anything "word."
oooo i didnt know about iconfinder. nice thanks
Gave +1 Rep to @wicked lagoon (current: #2122 - 2)
no problem mate
lol why am i getting such shade for canva? their free tier does alot
I got this interview coming up and they gave me a bunch of scenerios to 'explain to a client' so i'm going to make a fake pentest report with screen shots of these vulns/exploits so being able to explain some interactions via graphics will help to 'explain to non techinical c suites'
i'm using metasploitable 2/3 and juiceshop to illustrate the issues
Best of luck 🫡
thanks dude. i dont' want to hope too much about it but i got to the final interview so i just gotta do this right.
You will most likely need to explain using comparisons, why this is a problem, what are the risks and what can be done to fix it
My advice, flag things that are potential or require complex as lower priority to something that has an associated high/critical cve
oh for sure. show the vulnerability - why it's vulnerable - show a exploitation example - suggest remediation and why the remediation is important
etc. i expect to use alot of similar and metaphor in explanation as well - thats why i was inquiring about graphics
you need to cover why this vulnerability is a problem. e.g. an attacker can download this exploit from the associated github and run against the target to gain elevated access
lemme pull an example, might be easier
Assessment Findings
1. Weak HMAC Authentication (Replay Risk)
Description
The agent communicates with the API by generating an HMAC signature only over the current timestamp. This means the signature is not tied to the actual request details such as the method, URI path, or request body. An attacker who can capture a legitimate request therefore gains both the timestamp and the signature and can replay them against other endpoints within the server’s acceptance window. The agent further exposes itself by printing the timestamp and signature to the console, making accidental leakage more likely.
Impact
This weakness undermines the entire trust model of agent-to-server authentication. An attacker who gains access to these headers can impersonate a legitimate agent without needing to know the underlying secret. They could use this to renew credentials, register malicious endpoints, or inject falsified monitoring data. Over time, this could erode the reliability of monitoring and potentially hide malicious activity.
Recommendations
The HMAC scheme should be improved so that it binds to all aspects of the request: method, path, body content, timestamp, and a unique nonce. The server should validate not only the signature but also ensure nonces are never reused, effectively preventing replay attacks. Console logging of sensitive headers must be removed entirely to reduce the risk of disclosure.
Business Impact
Major: Exploitation undermines trust in the agent ecosystem, potentially affecting monitoring across the organization.
Remediation Difficulty
Moderate: Requires changes to both agent signing logic and server-side validation.
Risk
High: Authentication bypass enables impersonation of agents.
CVSS v3.1: 8.1 High
IsUrgent: Yes
POC: replay.txt
ahh that 'why' is a different why than what i meant. you're right. i hope you don't mind i copy and pasted it as an example to keep in mind when i'm writing my reports
nah, no worries 🙂 these are actual findings just to make it clear haha
Thank you :), if you need my metrics system can give you that too
what metric system do you use?
i was going by cwe and cvss
I use a bit of a more business centric approach, to make the vulnerabilities easier to digest

welcome to the club
change it to winter2025

dude if i give them a report with metrics with an overview for remediation - they'll definitely throw in that monthy train pass with the job offer
don't steal my colour codes
i called dibs on them
naah go for the classic
correct horse battery staple
I have seen this before
Tuta ?
Can't remember 
OooOOoo i never thought of using my own color scheme
the colour codes are based on RAG, fyi
you don't want to steer too much from red amber green (blue for informational)
was looking of keepassxc with setting yubico challenge-respond thing as password
If I saw this as a non tech individual, the colors r subtle, not too bright nor too dull, just perfect 
ahh the old Simonides of Ceos trick
i was gonna use glaucus, zafre, eburnean - you know classic colors
thanks 🙂
Gave +1 Rep to @frozen hull (current: #291 - 31)
My passwords are in a text file in c:\users\vigorizatnte\not_my_passwords\definitely_not_my_passwordlist.txt
I think I am safe
yeah add some blastoise, ghastly and magikarp to make it even better

My son's name is Magikarp
when he's 18 is he going to become gyarados?
no that is first at level 40
Hey guys! Whats the recommended wordlists for usernames and passwords for brute forcing thm boxes?
rockyou.txt
sorry.. level 20
but thats only passswords
miss remembered that
seclists
/usr/share/seclists or /usr/share/wordlists has them
Do you use it for both usernames and passwords?
@thick shell Impressive introduction in #intro.
rockyou is default on thm for bruteforce. if thm dont point to smth else on some room or so
/usr/share/seclists/Usernames for usernames and /usr/share/seclists/Passwords for passwords
i'm thinking of scripting a few things in to specifically do some stuff with these scenerios - is that too over the top and i should keep a couple tricks in the bag?
If you think it's over the top you can't do it. If you think it's not over the top you can do it.
It only matters what you think
Thank you DeleteMe for sponsoring this episode! Use the code SNUBS for 20% off and see how DeleteMe can help you take your online privacy to the next level. Hit up https://joindeleteme.com/MorseCode to sign up today!
Welcome to Day 3 of my 30-Day Security Challenge!
We’ve already organized our accounts and wiped our old devices – now...
this is starting to be a banger of a series
I see, iirc it has files containing millions of usernames / passwords. Now i havent done any complete bruteforce attack on any thm machine as of now, but wont this take alot of time?
@fair trail I accidentally found an anonymous POSt load on a sub....
I had not seen her in a long while. thanks
Gave +1 Rep to @sand trench (current: #4 - 2251)
you're welcome
wym
@sand trench you are in too info sec alot. How do you feel about ISO 27001
I found a vuln that allows me to post files with POST requests.
to be honest don't know much about that D:
I contacted the CTO of Globalconnect about it
From my work email for some legitimate powah.
But he is OOO
The ISP Allente pissed me off
So now they have a grumpy old guy after them
and the CTO of Telenor
Does anyone happen to know where i could find a vulnbox in thm, htb, or vulnhub etc that has ssrs (sql server reporting services)?
that's the only one i'm having difficulty replicating immediately
but i guess i could spin up a windows box and do the whole mamajama
But that takes time
yes. yes it does
He/She may be on vacation. I highly recommend finding out when they will be back on vacation and making sure you get into their house and wait for them in the lazyboy.
Then when he walks in his house you can say "I've been expecting you!"
hmm i think i found a couple htb retired ones that have ssrs available. i'll figure it out
Yes, it will take a lot of time. Usually the password is within the beginning of rock you. For username + password there are more clues provided to narrow down the list.
Guys the weirdest thing happened and I'm not sure... Usually our company doesn't advertise for pentest roles, they head hunt. I recently moved to data and am less than 3 months in my current role however I've been with the company for 4 years. So I asked my manager what he'd do in my situation and he only said he'll come back to me tomorrow.
Vigo says thank you shadow
Gave +1 Rep to @sand trench (current: #4 - 2252)
Thanks for the info 🙂 ill be using rockyou from now on. Btw, is aws having issues again?
Gave +1 Rep to @dark wolf (current: #85 - 117)
Probably lol
Downdetector says so
Yep, didnt amazon say they fixed the issue?
Look at this https://www.reddit.com/r/CrappyDesign/comments/1ocl3w0/aws_crash_causes_2000_smart_beds_to_overheat_and/
don't buy internet of things devices basically
yep
instead buy ploopy hardware
beep boop beep boop meep moop poop pee
lol
how HR team feel like when they make your life miserable
Why would you ever have to deal with HR
if not reporting colleuges
I am making new friends reporting people to HR every now and then
😭 think you making enemies
Im IT Security, they don't dare to do shit 😄
AI enabled printer! Get your AI enabled printer here!
https://www.hp.com/us-en/shop/pdp/hp-officejet-pro-8139e-all-in-one-printer
Well they deserve it and its not something they did per say.
Maybe storing videos for adults with obscene names on their work USBs etc.
That is for HR to solve
Why does my printer need AI
They just dont think about XSIEM to store all content from any USB stick in logs
And that we monitor it 😄
AI ALL THE THINGS!
Enumerate all the things is the life motto
Hi are there any rooms to group up with someone on some security projects?
Are you looking for rooms or team projects
That's why when I am at the drive thru and they ask, anything else? I always say, yes may I enumerate you?
I'm looking for projects mostly
Hm what level would you say your at
but it is preferable that it is group work as in regular corporate work
stalker
Pen
👀
Don't worry, I won't stalk you
Are you sure?
Yes, I already have too many targets to go through
beginner I know linux a bit I've basic knowledge and few certf in SOC field but nothing beyond that
through or to ? 
Are you wanting to make defensive tools or offensive tools
Depends on the subject. Some I can have others go "to". I just cross it off my list when I have the information I need.
I'm more into offensive but I know it's good to start in the defensive fields so I'll do both
which one would you perfer
offensive
So you don't want a job , just learning for fun?
Most offensive projects are just attacking and making tools from what I'll seen so far
And for fun, not for a job usually
which provider is used more in canada AWS or Azure ?
me? ultimately I would love to obtain a job
then go defensive
but firstly I need to craft something to my portfolio I guess
Most jobs are defensive focused
-
Implementing XDR Platform using: Wazuh + Suricata + TheHive + Cortex
-
Implementing Threat Intelligence and IOC Correlation Platform (Wazuh + MISP + YARA)
-
Implementing Adversary Emulation & Detection Platform (Wazuh + Atomic Red Team + MITRE ATT&CK)
-
Deploying Compliance Assessment Platform (Wazuh + Grafana + OpenSCAP)
-
Deploying Automated Incident Response System (Wazuh + SOAR tool like Shuffle or StackStorm)
-
Implementing AI-assisted Threat Detection Platform (Wazuh + ELK + ML pipeline)
these are some projects that were adviced to me by an expert
boring = less people doing it = more chances of finding a job
noice I'm gonna reserch these right away
good luck use THM & Hackthebox academy for resources
THM yearly subscription + monthly student HTB academy subscription is a deadly combo
yea I've already seen some intriguing topics that are premium only, gonna buy it when I'll run out of interesting rooms
What is that
What after that one
i think it depends on the path you'll take
ah
BTL2 is also a great choice
me too bro lmaooo
i wanna get my CPTS and that's gonna be it for me in red teaming
Nice
i'm focusing on cloud and SOC that's it
I wish I could join HTB server :(
I need to learn more about lcoud
sometimes i've been thinking about
you could ...
AZ-900 AZ-104
Me banned
passing my AZ-104 in december
I have no clue what that is lol
azure certifications
it's just a code
ohh ok
def a phishing link /j
thanks
Gave +1 Rep to @heavy storm (current: #1099 - 5)
oh no i've got clay in my eye 😭
I've been to a webinar recently where soc menager said that certs don't really matter for him rn. The key to land first job at cyber sec is having basic skills requied to navigate in soc and some type of thinking that's critical for this type of job, I can't really specify what kind that is, but he also said that it is better to have few github projects that show steps that you've made to obtain certain results
I dont know about you guys but I am done with recon. That alone mentality burned me out i know it's important but it's not need for most vulnerabilities out there.
Oh thanks for the tips !
Gave +1 Rep to @tribal tapir (current: #3229 - 1)
certifications + projects > projects
the guy with certifications will always have a better chance of getting an interview
Any certification is better than nothing these days regardless if it's well known or not.
unless we kidnap them >:)
Do you know any affordable certs
Filter by price.
from some of them yes
not from all of them though
Ah ok
There are currently well over 450+ cybersecurity certs out there. There is no way one person can get all these certs. But Googles and THM is a good place to start.
How muc his stuff like that
I was going to do google cybersecurity cert but i stopped half way
i think googles cert is pretty worthless
Well there are 100s more to choose from just have to find one that will work for you. But the thing is EVERYONE is doing that certification. Which means the competition gets more fierce you have to find a certification that is high in demand.
according to the people here
Hey there!
Are you having trouble with a lost or hacked Roblox account? Don't worry, I'm here to help! 💡 I can assist with account recovery, password resets, and security measures to prevent future issues. Whether you've been scammed, lost access, or just need some guidance, I'm here to help. 🤝 Let me know if you need assistance, and I'll do my best to get you back in control of your account! 😊"
i think @gusty inlet needs his account recoverd
or @mossy river
Someone need any sorts of help or any type of script for ANYTHING?
The whole point of certifications is to get past those HR gatekeepers and get hired. Beat the competition I used to work with people who had all the certifications in the world but didn't know WTF they were doing.
There is a difference between theory and practical
Ok
He can message me privately
IMO you can multiple choice your way into a job in cybersecurity.
crazy
Just wondering does anyone know what they actually do
I never looked into this type of scam
you either pay them and they dont give you anything
or maybe hack your email
or account
idk
"hack"
you never know
Thanks for thr recommendation!
Gave +1 Rep to @slow cloud (current: #54 - 197)
:hammer: ericmatteo#0 has been banned.
dumbass backup script =/
$HOME/Working must be really important to back it up twice
I prefer me a good homelab with Seafile 😅
personally use pika backup
because don't really care about system folders.... as nearly all important data is in /home/
and /etc for customizations of services that you locked down
have copies of those in /home
also had to undo all the sddm hardening shadow did as it made podman crash with cryptic errors
😮
New Rules section?
Hello Shadow!
ello darkfly
How're you?
slightly excited for new art commission shadow is starting to pay for
Let's goooo
red motorcycle is now sold
does motorcycle go beep???
yes
also how much did it sell for??
Only if it’s backing up like a truck 😄 normally it just vrooms, not beeps.
STOP REVVIN' - START RIDIN'
Make a move today for a better tomorrow...
❤️
CONNECT WITH VENJENT
Instagram 📸 https://www.instagram.com/venjent/
Spotify 🟢 https://spoti.fi/35PhYRV
TikTok ⏰ https://www.tiktok.com/@venjent
Bandcamp ⛺️ https://venjent.bandcamp.com/
YouTube 🎥 https://www.youtube.com/venjent?sub_confirmation=1
Site ...
870 Euro
sounds low for a vechile but what does shadow know

@marsh lark
I have been playing CR for 8 years, but never reached top 10 in global 😮💨
Yo I reached 10K yesterday!
bmt is this clash of clans
pray tell?
Clash Royale
Ayyyy up we’re moving up in the world
I can't find a good Netflix serie or movie for the love of god. 
Nothing's entertaining.
Poking around a bit and seeing this on an RDP
OS: Windows 8.1/Windows Server 2012 R2
OS Build: 6.3.9600
must resist the urge
too poke
Just browsing a few IP ranges on Shodan, nothing too exciting.
"Blackbox"
Hi can somone help me. I’m stuck on an “wifi hacking” training. The goal of that training is to accses the admin panel of the wifi, but I don’t know how. I already cracked the hash of the wifi password by deauth the fake devices to force them to login again. But I don’t how to continue
Money Train, Suits, Breaking Bad (if it's still there), Blacklist
are you on the wifi?
Yes
and the admin page is not on the default IPs?
Better call saul
What do you mean by default IPs?
Don't know you well enough to know your tastes @gusty inlet
The office.
adminpages on wifi are usually in the same places
I find the humor lame and dry hahaha, brittish humour is better
look at your own router, on what IP is the admin interface located?
is it not the same kind of question here?
just enumerate all IPs?
@dark wolf Maybe I am all wrong here and not undestanding the issue
seems like a no brainer
Well I tried the default credentials to login but it won’t work. The wifi panel login is on 192.168.1.1 in the target wifi
I don't know Math, I'm working and not paying attn
I saw these sora clips where characters from that game are on your front step. There's one where the hog riders break into your house
Nothing now, I tried to brute force. And I scanned the wifi on routersploit but gave no results
what router is it then
Your profile picture and IGN look familar 
The router modell is Sagemcom F@st 5350
THM has a wifi room?? whats the url
Its not THM
The mods discourage helping people with challenges not originated from here
Otherwise he would have said so
What do u mean?
They could be hacking someone
😂😂 no, it’s an CTF training lab on Google
If he did not even scan the network for other IPs. Not much to do
But how can find the flag. I can’t continue
Ahh yes, I've done that one
And I tried burp suite on the see the requests for the login page. And still that didn’t help
I need to do something, my grey hat is slowly turning dark by looking at all these IPs
I don’t how to continue with that CTF. And I can’t get hints
And you are not sharing the CTF
Give me a sec
So I suggest you move along 🙂
I am doing the Powershell room. First time I have seen it broken down like this. It's a REPL.
Tooo late, i've moved on
👍
Yeah I learned a few things from that room. It's kinda cool.
How do I hack library
Library say I have to pay library fees
How to change numbers like in Mr robot
?
Then you pay ofc
Huh
Move to another county
Huh
@gusty inlet knows
Kale 🥬
What library is it?
paramiko
uh
its illegal?
to hack library
unless you wrote it
he means library
demands money
like physical place
yeah, C ? Java? Python?
right?
Oooooooooooooohhhhhhhhhhhhhhhhhhhhhhhh
Yes he does
I know you never been there
i see
ofc he wants to hack his school lib or somehting due to the fact that he ows money
hahah i been there plenty of times
I just bought new book
Maybe go back to mr robot.
no phone
But If he just tells us the library's name we can just tell them to add more to his account
Well if he does the rest is easy
CS GO with fire sign == 10000% russians
It’s not Russian it’s an American podcast
Classic movie tho
my friend wrote website
I even have the script
added there ping command
The earths mantle has a CVE rated 10.0
guess how many vulns I found?
I can’t tell you what library. Developing kali linux hacks
we should exploit it
I’m developing a device. Device generates unlimited WiFi anywhere you go.
Using kali linux. And library wifi
Its called unlimited sub to your cellphone service provider
😭 what what but that is illegal
for sure
he said WIFI
Huh
Well its a 4g/5g router
No it isn’t
Device makes unlimited wifi
Does it have internet?
or just wifi
because my Raspberry will do that just fine creating an wifi
Why post those referal links?
@dark wolf you can report it for me
im old
Idk it’s using kali linux
You have mentioned that a few times now
Yes you told us
Bro either tries to scam or earn 10$
I reported it
There have been a few of those links today
If it were free Claude I would have signed up
Per user 10$
advertising
Claude is a great AI
Plan to use kali linux to act as wifi router. And then connect to free school wifi
Human brain is great AI
I use mikrotik
And generate unlimited wifi anywhere you go. With Kali Linux
Amazing thing you know
I swear this that dude has about 90 lines with the words wifi linux and kali all in it
what is wifi
me too!
I am the Mr robit
but i have it
hi robit, I'm luna
Or rather. The Mr Kali Linux Ribot
Now tell me what is kali linux
Hii guys I'm not a professionel so I should to build a portfolio ? and makes write-ups for any room I finish ?
What are your goals?
Tell me more about the "everywhere you go" part
So you have kali, sharing schools wifi
how does it share it everywhere you go
And explain how mobile hotspot while phone is connected to wifi is not the same thing
uptoyou
I guess you could set up your own Cell tower
i really regret not doing streams when I did insane challenges
he can 3d print one
I might redo them for fun
If I find out how to redo a challenge..
I'm nee to this web still 💔
Didn't click all the buttons yk
Options -> Reset progress
on any room and you can redo it
no more points tho
Link to your GitHub page. And put all your stuff on there. Or LinkedIn
Idk I heard kali linux makes wifi
For free and unlimited
YouTube video
are you just trolling?
I can 3d print you something cute
I can 3d print anything i want but i can't think of anything i want to print. I've printed more modifications for my 3d printer than anything else lol
Theseus stream commin
Oh wait. No nvm
I ain't leaking theseus
I'll stay loyal to it
Voron?
Or what printer do you print mods for 2025 that is not a selected few that is not Bambu
Prusa? But those will slowly die, Bambu took too big piece of the market
Ender 3d Pro
Haha Ender 😄
Got it 4 yrs ago
What do you print?
Things I do not need
hahah yeah, well we try and keep our place free of chachkies
Gadgets for home and gifts, cookie cutters for christmas. Nothing too serious.
or however you spell it
If you were in to resin printing I would hook you up with files
if system.isCrashed: system. restart(system)
i love how i be getting stuck on some of the beginner module questions for no reason 😭
i might be cooked on some of the harder ones
💀
you cant know everything
for sure
Hi, i try migrate the process but don't work in room/blue , someone can help me
i love it when i give up and have to look at a walk through and then realize what im doing wrong, and it gives me the boost i need to answer all the other questions easily after feeling silly for a few moments
lmfao
sometimes you just need that one clue
yup
the walkthroughs are there for a reason
real
How about a bot that scrapes walkthroughs and does the ctf for you when you are sleeping
lol
😂
i try several pid but don't work
youll probably get a better response in #room-help
Take a while with the new rate limit rules
👋
Hello No Name!

Hi
Hello Immortal!

Just wondering do I know I forgot people a lot 😭
Prolly not
hi
hru?
I'm doing good 
How are you feeling today?
no idea honestly
like a potato
worse
or better
no idea
is it chill if i go abit out of order for some of the learning paths? like doing the splunk basics in soc level 1 and then heading to soc level 2 to do the advanced splunk stuff for example
i think splunk is the first tool i wanna get super comfortable with
🤔
yer do what you want. i dont even follow a path
bet
I hope that your day is able to improve! 
Going to sleep
Soon
Aka yes it will improve
As I love sleeping
But depends if someone will wake me up in the morning or no
btw that's great to hear
I don't even do the path
I just go straight challanges
i just do rooms i find interesting.
I just do either all challenges which are purple team
Or all insane ones
Or hard ones I find interesting
Insane ones sadly all completed
I don't have premium to do Osiris
i kinda wanna mainly focus on the skills that will be important for the job i want
but there are a ton of super cool rooms
im hyped to try
I am guessing... Pentester
nah
huh so apparently shadow is not the only person using shadow absorber as a username
Whuut
Soc analyst
did not expect that
maybe go for OSCP if i want to make myself suffer
I pentest at work, I manage our bug bounty program so I triage everything, and I can pentest all I want in our enviorment
And its alot.
But SOC work takes heeps of time if one allows it
is openvpn not working for anyone else? keeps disconnecting
cool if i add you so i can maybe bombard you with questions sometime
lmao
You have a fan then
they don't have a lot of following to be sure
only find them when running sherlock to find old unused accounts to remove
guys, rate my dog 
don't want to ruin others days thats for sure
very pant
is it alive?
good question
Cute&goofy/10

yea
Idk, they have their tongue out..
I'm not fan of dogs
I hate them
But urs looks nice
Ig
Anyways gn chat

Hello if i want to take the 1 year of ine fundamentals that include ejpt exam + ICCA what rooms to finish in tryhackme first before taking the practice in ine for ejpt
Done!
thank you dkob
not sure if they posted in multiple channels but that message sure seemed sketchy
@boreal scarab how often use sherlock???
Hey guys easy question, doing a THM room where I've gained admin access to a Wordpress blog website. How do you guys usually go about retrieving flags in these situations?
Are they hidden in posts, dashboard?
Sherlock Linux?
im still a noob with thm rooms but from what i can tell they could be anywhere. sorry if thats unhelpful
You're doing great. Keep at it 💪
Think I used it once or twice.
I'm a man of manual searches. Buuuuuuuuut I'll give that one a try
from wordpress admin migrate to www-data on the target machine by using rev shells
then from there use grep to find flags
woah
Haven't touched my Graphene phone in about 2-3 months..... it's so out of date lol
haha thanks
Gave +1 Rep to @topaz topaz (current: #235 - 40)
hope the uppies work
considering androids latest shenanigans I think graphene will be a nice option
using grep to scan for flags in likely folders is very nice
migrating to www-data through wordpress is something i havent seen in a CTF before. that means I can execute commands via the admin page?
Or am I looking at it wrong
well more or less yes
(Not asking for an answer just looking for a key while blindfolded)
you can upload a php file in most instances that replaces a 404 link
I have 2 phones, my main and My graphene I take to DEFCON. Found my Graphene phone and now updating it
are they both pixels or just one of them?
yer a reverse shell will basically give you a console
F-Droid has a lot of updates, Aurora store, Graphene App Store, System updates
One is a Samsung S21 Ultra, 16 GB of ram baby WOOOOOOOOOOOOOOH
The other is a Pixel
ooo boy
Pixel 7a Pro to be exact
the S22 Ultra in Burgundy is still the most beautiful phone to ever come out in my opinion
I much prefer the Pixel 9's design but it doesn't compete against that burgundy
Shut up and take my S7
shadow happy with their pixel 9 with graphene
also now got a nice grippy case for it
Ehhh S7 is nice but my experience with the edge screen :/
The note hahaha
TAKE MY NOTE 7
Pixel 9 twinninggg

The note 7 is most definitely a beautiful phone yes
I had a Note 4, S8, then S21 Ultra
But I didn't start on the 4
I started on a flip phone baby WOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOH
SAME!
have a fairphone 5 shadow needs to repair
This was unc's first phone (mine)
haha my first phone was an ericsson a1018s
any nokia users in chat???
Do Microsoft Lumias count?
It's basically Nokias that were bought out
barely but yes
Let me get Grandpa in here..... @normal fable What was your first cell phone? The brick?
I had a 535 as a first smartphone ever
im so old
Truly... At the start I loved that phone buuut.
GET THAT MICROSOFT PIECE OF SHIT WINDOWS 8 FUCKING CRAP OUTTA HERE
I couldn't wait to get it off my hands
I do have fond memories of it though, I had a Gameboy emulator with a mortal kombat deception rom and would play through it in secret during boring classes as a teen 😂
i used to have a HP ipaq before phones had touch screens
blackberry users rise up
I had a similar "first" phone. Wasn't mine, I was like 6.... but I remember playing a motorcycle racing game on it
BBM LETS GOOOO
never had the joy of using a phone with a physical keyboard other than the numpad 🙁
Hehehehe love that
I saw my grandma using that flip phone I posted and I was like "yeah I want that.."
Customizable notification light to tell you if it was a BBM message, text, and from who
I feel like going back to dumbphones, anyone else have the urge every so often?
Blackberry was great
Their failure story is very intriguing
Going back to Windows ME? SURE!
ive become too reliant on all the internet stuff. i dont think i could go back to a dumb phone
Ohhhh darling please don't hurt me thiiis waaaay
That's the reason why I want to go back. It feels like corporations and governments are forcing their people to be hooked on them, and while I won't push this conversation to the political side, I am feeling the effects of having a device connected to the entire planet on me the entire time and it feels draining more often than not
No reason WHATSOEVER..... Having FDroid going through TOR for updating my apps, Proton going through 2 servers, both non 14 eyes.
Hypatia going through tor.
Is there any reason? Fuck no
Do I care? Also fuck no
I understand, what do you use your phone for mainly?
I remember playing Bajuled (Or however you spell that) on a gateway Windows ME
The Graphene? Privacy, but only at DEFCON
I'm not talking about government surveillance per say, I don't care about that. I just think of how our communities expect us to roam with smartphones, using them for the slightest of activities. Going to a restaurant? Scan the QR code, no menus.
I know it sounds backwards and I understand the controversy behind such an opinion, but I do wish we could go back to times where smartphones were a luxury and not expected of a civilian to carry around in order to cover the incompetence of others
What's FBI going to find? "Chromebook reset keyboard shortcut"
"Asus BIOS key"
to each their own. this same kind of stuff happens a lot with new technology. give it 20 years until its the norm and no one will care
F2, Del, F1, F12, F10, fuck you just hit all the keys till one works
Do you find comfort in this thought?
This job I don't handle sensitive data at all. I used to, Thanks HIPAA...... but never saved anything besides "Room X has this issue Desk X has that issue"
kind of. its a long and detailed conversation. not sure i can summarise succinctly
The good samaritan. We believe in this man 🙏
Oh and even then, it's in Secure Folder, in an FOSS Note taking app, that's also encrypted. Is there ANY reason for this? Again, fuck no. But I like it.
Why is it hard to see who knows website that see email logins?
does not parse
try again
uuhhh what?
Current job, I don't have access to tickets, so all my notes and everything I have to keep, dated too, so when my boss asks me "Hey, X, what happened there on Friday X date" I can easily go back and look
It is indeed. Just remember that we are headed towards a very new era of information control and weaponization, one that coincides with the obligation of having a network connected phone even for the slightest of your bureaucratic needs along many other services. Services that were once useful and are now evolving into something different entirely
Do you keep digital notes?
Yep
But again, my notes just consist of what to do that day, what happened, what did someone tell me, what questions do they need me to ask someone
Oh shit, Ubuntu has ZFS with encryption... experimental, but nice that they have ZFS
yeah zfs looks neat but seems incompatible with a lot of linux due to thingies
license thingies
what about the zte users 💔
ZFS is basically like BTRFS, but ZFS uses RAM for cache
Also ZFS has Software Raid, RAIDZ, no need for hardware raiding.
shadow knows plenty of what ZFS is
RaidZ1 I think is a Raid6? I can't remember the whole RAID crap
also know that you gotta do crazy vodoo to install it on arch
Hi, I’m Excel 🌸
@remote cradle please dont dm me without asking first
can i dm u
hey
Hi, I'm Internet Explorer
👴
Hello Ace!

Hello Matt!

How're you Fugu!


Oooo my dear, how've you been?
Good
that IS ideal
Doubt it
Where did you find these? I haven't seen anything like that
Have you reported that content?
Admins are often quick to take action, but at the end of the day this is a public cybersecurity server
Please report it as well
... How'd you figure that one out?
Should it not be okay, admins will take action
Although I do not see where the maliciousness is
But as mentioned earlier if the admins deem it inappropriate they'll take action against it, I don't have any input on the matter
Are you sure it's not your phone's antivirus software playing tricks on you?
That said, they've got a grand total of about 3 mods. Encouraging people to report random shit with no evidence isn't necessarily the best use of their time
Detected how?
As someone who has no power over this, there is nothing I can logically recommend other than that. If someone sees something suspicious, they mention it. That's all. As you said, 3 mods, stuff can slip every so often
Dunno what AV you're using but VirusTotal thinks it's clean
Hello Muiri!

Aside from Fortinet marking it as spam, but A) who listens to Fortinet and B) that ain't a malware designation
https://open.spotify.com/track/2yN2B1x7ypvUd13EzEblz2
I can't stop listening to this lol
Seeing your screenshot from earlier, I would recommend you switch AVs, or not use one on your phone if you feel you can avoid shady links
A bit of common sense goes a long way.
You said it yourself: you don't see how it's malicious. Why would you immediately jump to "just report it anyway"?
Okay, so?
What's that telling us?
Its a screen shot
Did your color change again here recently?
When someone comes with screenshots of AV alerts, as a not as experienced user, I cannot take it upon myself to tell anyone NOT to report something that's been flagged as such.
Obviously. What is the screenshot saying.
I see the site, and your browser has coloured the URL red. What does that mean
And next time I'll do the same cause it's better to bring this to the right people's attention and they can decide further
Not since Skidy stripped my roles, nope
I've tried a bunch of these "username look up" apps/ sites, and they have always given me false positives... like
"Yah, Shadow_absorber is on Pintrest"
goes there and there's no account at all
ello and good night muiri
shadow is gonna go sleep nows
meep moop to sleep sloop while beep boop basically
Example... gave me Hackenproof for my username and yours, 500 error..... always hate the false positives
Fyi, there's also a time article on this:
https://time.com/7327409/ai-agi-superintelligent-open-letter/
Plus a bunch of others.
So, to summarise:
- VirusTotal ran 68 AV Engines / URL status checks against it. They all came back clean.
- Multiple major news outlets have run stories corroborating the existence of the site.
- The only thing flagging it is whatever the heck you've got installed in your browser.
I remain open to correction, but I'd say there's a reasonable chance it's legit 
Hello im Wann im getting into cybersecurity ive always loved computers if anyone needs a study partner or someone to get help and just spend hours on trying to fiqure out somthing im open to being that person its always fun doing things with people instead of by your self send me a dm im about half way done in cyber security 101
Hola
Gday humaniods of the inter of nets, how are we all feeling today?
Fantastic
Just busy hacking something
Although I have to say I am a bit paranoid as it is my first time hacking a voodoo doll
a what?
