#general
1 messages Β· Page 1813 of 1
Direct Message
I usualy see PM , for private message
don't message xD
I've never been worried about people finding me. It's at least 5 hours to the closest airport.
A yes that work too π
π
you never know stay safe
I am 30 minutes close to the aeroport
@marsh lark
lol
elliptic curve encryption π
yesterday i lost my streak at 95, today i was given chance to complete a room to recover it. at what conditions is this given? does anyone here know?
iirc if you lose strike you can email support to recover it
this one was automatically given
Wat
I wonder if I can do this in C++
that idk for. but for sure you can email support
Nah, I was just curious.
After taking a closer look at the gif, I realized how much sanity I'll lose if I try.
Big shark
with cheese or not???
Of course!
that cartoon never made since. like how can they walk around in water like it is air
cheese is good. just donβt cut it

and market didnt even open yet
opensnitch goes BRRRRRRRRR
π
When the, when the, uhm, when the
there is one episode where patrick makes a fire go out by commenting they are under water
@jagged yarrow
hope you are doing well
are you looking to bring another developer on board ?
skiddy is bussy bee...
also they put swim suit when going to beach
Everyting is slow, I am enumereating a db that is timebased. Takes forever
@mossy river the website is taking forever to load
after all, daily downtimes might be really coming
1 hour later and my plugins still have not been sorted...
plugins for skyrim i guess
Jabba not online, it's the weekend. I don't think he will see this by Monday
true
also all the machines are being extra laggy
might be just an overload on usage but still
It's a deathspiral
Nah you're not
huh? poof goes the message
idk, i did a pickle rick room but thats a training room
real
What's wrong with em dashes? AI ain't the only one that can use them tyvm
Aw. Bye bye scammer π
im aware, its just not one you use commonly
^especially on discord
especially on discord, exactly
aahh that's why messages are dissapearing from the channel?
I do. As does anyone with a reasonable grasp of English.
I also used to use the dashes :) but lately I'm trying not to
Why?
It's kinda sad. So few people know how to use grammar properly that proper grammar use becomes indicative of AI.
Use them proudly.
i use em to gaslight my peers π€·πΌββοΈ
well English is not my first language but I remember back in high school I was fascinated with them, almost like gpt xD now.. I mostly use them when i write poetry (and I'm not self promoting here) or other short stories.
They're a perfect middle ground between a comma and parentheses.
I'm not saying anything bad against em dashes or grammar and I totally agree on people not using grammar properly, I'm just saying that on a platform that is usually informal, I'll be more inclined towards the belief that someone who used an em dash is using AI over being a formal gentleman with amazing grammar π
yess :D I really didn't like parenthesis (but they do come in handy)
There's nothing formal about em dashes smh -- they're a perfectly legitimate part of any sentence.
As demonstrated right there.
I should probably start eating up more grammar content as I will probably need it soon π Good way to remind myself
-- > β
I'd also point out that this server feeds into an industry where a good grasp of language is essential...
omg I think I made my setting too strict for my profile, I can't react to messages and is bugging me
you gotta verify with /verify
Two hyphens is how you type an em dash...
Discord just doesn't substitute
I am aware
That's a server setting. It's because you don't have roles
aaaah I see, thanks :) yep makes sence, waiting to recover my account and will verify after that
Gave +1 Rep to @velvet gull (current: #1283 - 4)
If you'd prefer β I can do it properly though 
Advantages of mobile.
It's just an extra few steps.

I didn't know mobile has em dashes, thanks on enlighting me with the fun fact though!
Gave +1 Rep to @pallid lotus (current: #11 - 914)
You can do them on desktop as well TBF. Alt codes or powertoys on Windows
Hello chat
I wanna say the alt code is 151 for Windows? Been a while -- usually I just let it automatically substitute
hello
0151
I was close.
...
sorry, just saw the message, yes will have to wait a little bit :)
Even more fun facts!!! :steamhappy:
I use -- when it's possible to substitute them to β
but when not
I'd prefer regular -
It's just more comfortable
Yeah, but that's inaccurate. Hyphen β Em Dash β En Dash
Ikr but thanks there's no need to have 100% accurate grammar while chatting
-- is irritating, but at least it's symbolically an em dash
I can't just accept it normally
It gets percepted as AI because AI uses it everywhere
wow just googled En Dash :) I feel educated
even at places where this Em Dash won't needed
Heh, yeah, that's actually what sparked this conversation
or would be better replaced with comma
It's just cosmetically
But GPT uses it too often
I didn't saw the context but wanted to contribute :P
The fact that em dashes are now considered an indicator of AI because AI overuses them and humans underuse them.
Nae worries, kinda figured π
That's the point. Just because people are underusing them when AI just..
being AI
Only Claude didn't use them too often so it's irritating
but the funniest part that because people are to lazy to do Alt 0151
their AI-generated works can be exposed
What I don't get is how the damn robots developed such a liking for them.
Modern English speakers underuse them. What the hell have the models been trained on that they now overuse em dashes 
lots of articles
I'm not into LLM or model training so I may be wrong but I think it strongly depended from the source from which they were trained
I mean, even then, most office suites just substitute -- automatically. Can't remember the last time I had to manually insert an em dash when reporting, etc.
old literature?
Exactly. What sources have they used which overuse em dashes.
My guess would be academia, aye.
Older literature would be a good guess too though
... Thanks autocorrect?
I know, the same is with Obsidian or other instruments
Sadly we won't know this
Maybe some researches
which are always checked
and maybe there Em Dash is a must
Oh, that was me sarcastically thanking my phone's autocorrect for turning literature into litres
oh lol, I didn't notice that
I was too slow processing the whole information
but I think maybe it's good to some extent to have this "check" for Em Dashes just to prove how the essay or whatever was wrote
As a small metric in a larger system, maybe.
Too easy to raise false positives if that's your entire system though.
I'm glad I finished uni just before GenAI became commonplace 
Considering schools where IPads or other tablets are often and often
and where kids getting more and more lazier
it could be a good system
because kids are to lazy to use --
Nah, I'll tell you the best system to combat AI use in schools... you ready?
Pen and Paper π€£
It is actually but it's obvious that there will be more and more digital devices that are replacing old school methods to prove it
Kids these days rely far too much on technology... And that's coming from a 24 year old who works with computers as a career.
The problem of AI is actually how we are getting lazy because of that
It's like when we stop to search solutions
and just paste our problem into AI to solve it
You seen the MIT study on that?
I didn't
Here's an article summarising it if not:
https://time.com/7295195/ai-chatgpt-google-learning-school/
The link to the actual paper is here:
https://arxiv.org/pdf/2506.08872v1
It's a scary read
how bad is using search engines to figure it out instead of figuring it out on your own??? as seems they tested that too
I saw a lot of ideas brought by ChatGPT alone (also without adjusting it with own ideas)
yes shadow could just read this but is assuming muiri already read it
As I already read to that point
It states that in comparison with ChatGPT it calls an active brain function
more active
Been a few months since I read it, but iirc it's a middle ground between GenAI (basically brain dead) and brain-only problem solving.
By the way, just checked my own written letter that goes with my CV to HR. I got 90% of AI
I don't know what algorithms they are using
thank you @pallid lotus @ashen cape
Gave +1 Rep to @ashen cape (current: #679 - 10)
Gave +1 Rep to @pallid lotus (current: #11 - 915)
But I couldn't imagine me writing like AI
It's just good grammar checked with Grammarly
tf
grammarly is picked up by AI detectors so thats why
oh so we should have typos???
But I used it for Grammar check and not paraphrasing I guess?
if i have time to care i sometimes paste what i wrote into an ai checker to verify it and change it to show 0
in official letters ^^^
yeah still gets flagged unfortunatley
How do you think Grammarly is working? 
Okay that's quite obvious
But I don't paraphrase anything more like orthography or grammar at all
because sometimes I forget to write u in obvious
hi
seems shadow has figured out how to setup their "blog" on github pages now :D
I want to ask a question but im afraid to be missunderstanded
Hey, at least you try. Americans don't even bother with that lmao
word isnt enough for those corrections?
Just ask it, if we won't understand it -> we reask
And what would that question be?
Sometimes yes, sometimes not
Espescially when I'm tired
I'm relying on autocorrect but still being blind
I think at this point whatever you write will have AI "traces". And I think it's because it is used on many different texts. When i write I like to experment with different tones, and I use AI too (mostly for research and grammar check and is fun to consider what the reader will think about a text that I feed into gpt)
ive got a perfect solution - find a grammar assistant on fiverr
I'm not a millionaire π
This is why we do rounds of QA for documents in a workplace. Grammarly just functions as an AI peer review these days.
youre cooked then sorry :((
The thing is when I write like the whole day
I won't get this kind of typos
but when it's the first letter I need to write
then..
obvios
I've seen a few authors complain about exactly this.
Their work has been ingested (arguably illegally) into AI training sets, and people keep accusing them of using AI to write... but it's actually the opposite
repetetative
I just don't understand how my personal story in this letter could be percepted as AI lol
I'm starting to have thoughts as I'm being in multiverse
chat
i'm watching 15 hours youtube video of cyber mentor
and shit is it actually hard or am i just tripping?
Society is cooked. Just sit back and enjoy the chaos
I guess it's not that hard when you structure what you'll need to learn in the first place
because if you will start direct from SSTI ignoring the basics
ic
you'll be thinking it's insanely hard to process
I will enjoy it when I will have a stable income atleast
Eh? Since when is SSTI not a basic?
since when somebody don't even know what Back and Frontend are
It's just a point of perception
from my side SSTI is incredibly easy to understand and exploit but still
I'm not against using AI or a puritan (?). There was a writer, not sure if I remember correctly but she mentioned she used AI and her book actually was really good (I think she was from Japan). What I want to say is, I think even in the past, people would build stories upon stories they heard right? And there are minds who have the same idea and live in different conrers of the Earth. Not rying to be an AI advocate eiher, but for me it really works :) not only n writing. I think it depends on how your brain is wired. Is like having a personal assistant and a 1-to 1 tutor sometimes.
alr y'all got me lost now
Just structure what you need to learn at first place (or use roadmaps atleast)
See, that's not security though. That's basics of application development. You should know that before learning offensive security.
how do i make one?
i'm completely new to this ngl
Which ironically does tie in with structuring what you need to learn lma
Maybe use roadmap from TryHackMe (Learning paths) or
let me find it
i'll look into that 
but lmk if you find one too pls 
oh oh
found one already
Oh, no no no. Not this. That is not a roadmap
I used it and it was well
What's wrong with it actually?
That is a script kiddie regurgitating a bunch of acronyms on to a page, seemingly at random
There's no focus to it. It's about as useful as reading a dictionary of computing terminology, if they didn't bother to write down the definitions
π
Also, their categorisation of certs is just bizarre
welp
Makes sense then. I didn't think about it because it seemed okay for me. Then it will be better to use THM one
As I find it ultimately okay
e.g., CEH is not an advanced cert by any stretch of the imagination. For that matter, CEH is something you should only ever do if you literally cannot get a job in your area without it, or if your employer insists on paying for it.
And even then you should forget everything it teaches you as soon as you have the piece of paper.
Then there's random stuff like this just thrown in there
tbh didn't have any experience about CEH
Like, sure, yes, okay those are virtualization technologies... so what?
How does that even remotely help? How does it even signpost you to something useful?
The whole thing is one big mess thrown together in 5 minutes by someone with no experience who has no clue what they're doing but fancies LARPing as a cybersec professional
Note that it also claims to make you a "Cyber Security Expert"... without bothering to acknowledge just how many different roles and domains cyber security actually encompasses.
thm roadmap it is then ic 

but I got the point of it
would it ever be a problem if at any point i ask you to share your wisdom? 
"Wisdom" might be pushing it 
I'd honestly suggest just asking in chat. If I'm around I'll probably answer. If not, there are still others in here who can π
yes my brudda, the more the merrier and ty 
Gave +1 Rep to @pallid lotus (current: #11 - 916)
Hi new

i'm too stupid to understand that
bout to go to bed
cya soon ig
@pallid lotus Wait a minute aren't you younger than me?
Just noticed it said "Senior" in your profile.
Or am I confusing you with someone else?

Sleep tight

sure tc my brudda, GN!
Hi, I am struggling in the 'Metasploit: Exploitation' room. Could I DM someone for help?
Ask in #room-help for best experience
thanks!
Hey, can someone from Staff contact me via DM? I have a light-hearted question about one thing, but I don't want to bother anyone on this server, since there is no questions-related channel. It's, by any chance, not any critical thing or a problem, yet I have something in my mind that I'd try asking.
My favorite tag lol
That's my job title. Political speak for senior pentester
Quick qn
And how young are you again?
24
How long have u been in this field?@pallid lotus
Someone can be a senior at 24?
Apparently π€·ββοΈ
π²
Oh wait, you started working directly after your BSc?
My friends who are seniors have all skipped the MSc, guess I'm behind on that part.
The world has gone mad with job titles nowadays
U have 2 
Depends what we're counting. I worked for THM on a contract basis 2020->2022, plus part time vulnerability assessment for a local company 2021->2022. Worked as a pentester 2022->current.
So either 2 years if we only include full time work, 3 years if we only include pentesting, or 5 years if we include teaching as well.
Thanks
Gave +1 Rep to @pallid lotus (current: #11 - 917)
Technically started working for the company I'm with now 1 day/week during my BSc. Got hired after my third year.
This should give me a general idea
Babdoi


I've given up on my red team journey. RIP all my certs and money. No jobs for me in the red team for a year now.
Damn
I'll stay in my blue job for now I guess.
Yeah, most clients are skipping pentests entirely. They just rely on automated vul scans now.
Well there is a much higher demand in blue jobs to be fair π

Does pentester.com come under that?
Huh? No.
Gonna be very interested to see if these ever become comprehensive.
May need to prepare an exit route into architecture 
Technically yes. The original scans in pentester looked at vulnerabilities in externally facing infrastructure, and there is actually a pentest service (or was -- not seen that side for a while).
Focus has been on identity stuff for a while now though.
To be honest, have you seen the outputs of Pentera? It is quite interesting to be fair. I am not advocating in any way for replacing pentests but the tool does a pretty interesting job.
i gotta get better at what I do if i want to win this battle 
Is that the open source one?
A colleague and I tested one off GitHub a month or so ago and weren't hugely impressed. Can't remember which one though
No, definitely not that one
No it is not open source π
Yeah it's sad to see TBH... had a talk with the head of the offsec department in our company, if he's worried then you know it's bad lol.
Lost lots of customers this year.
Look on the bright side. The tools are not at the point yet where they can fully replace a pentest, despite what marketing claim. Or, at least, none of the ones we've looked at have been at that point.
i.e., the companies jumping on that bandwagon are likely to get a nasty shock.
Once they start getting hacked the trend is likely to slow down.
There's also a lot of talk recently about the AI bubble bursting. Looking forward to seeing whether that happens 
That is under the assumption companies are going to get hacked because they are not doing any pentesting, I find that a dangerous statement in a world where there is a serious gap in workforce and automation gaining a lot of momentum and traction in the cyber world.
I honestly think pentests will be doomed. RTOs less likely.
I really got sad when I heard the manager saying they'd give it a max of 5 years before it dies by another 90%.
(Pentest jobs)
Tbh I kinda gave up on landing a pentest career
anyone here playing hack the boo CTF?
Pentests are a security control, nothing more. You're less likely to get hacked if you've already tested yourself for vulnerabilities, but that's it.
i.e., you're not automatically going to get hacked if you don't do pentests, nor are you 100% safe if you do... but they sure as hell reduce the risk 
Let the dream die, I'll figure out something else
It's possible, but I've not given up hope on that yet.
Doesn't mean I'm not making backup plans, granted 
Why is everyone so dramatic this evening, having offensive security knowledge is still valuable knowledge π
Right?
Who's gonna feed my 10 kids 
Jesus Christ please tell me you do not actually have children 
I have a cat

A "hobbyist pentester" tends to end up in jail π€£
You can have a pretty decent career in other cybersecurity trajectories
THM is kinda hobbyist tbh
LMAO. You sounded exactly like everyone in our offsec department. 
The manager told them to start having a backup plan.. just in case. I doubt the demand is as bad in the US as it is here in France, but you never know.
Its what ive been doing outside my own labs with my own tech
I dunno, I kinda fancy being CISO
I fancy being a RTO but welcome to France. 
I really enjoy security architecture. Designing systems in a way they can't be hacked.
That's always been my strength in offensive security -- focusing as much on building as destroying.
I'm just not gonna have high hopes for something that will probably never happen
The chances of it are low
(Where Im at at least)
So go for security architecture?
That's the backup plan, yeah
Heck, may end up going that way eventually anyway tbf
But not right now. I enjoy testing too much
Did you ever conduct an entire Red Team engagement from scratch?
I mean, that's part of my job? π
You do both pentesting and RTO?
We're not big enough to have lots of people dedicated to specific things like the consultancies do.
When we do a RTO, we're the ones planning and conducting it.
I'll get a loan and start my own cybersec firm. Why not? Never gonna know success if you don't take some action. Or could wonder "what if" for the rest of the years.
Mhm. Remember I work for an internal testing team. We've got about 20 people total. A few of us specialise in AD / RTO / Purple team sessions, etc. Others specialise in other stuff.
Team ain't big enough for everyone to only know one thing though, or to have dedicated researchers alongside dedicated operators alongside dedicated infrastructure people alongside dedicated administrative teams, etc.
I would love to do a paying pentest as a full time job
But if that wont happen due to employers
I'll start my own
I see. We have the same case in my company when it comes to Offsec, same team for both. However, they're not mature enough for red team. Hell they're barely mature for pentests lol. They just promote their blue team offerings.
Hey, just as long as you have the background to make sure it gets done right (and legally), then why not?
But remember there is a far bigger need for people to actually protect systems instead of pentesting them.
True. Ultimately, pentesting is literally just a very specialised form of QA 
We're all on the same side, at the end of the day.
As someone that has worked for a startup (hydroponics lab - grew micro greens) it does tkae work but it is possible
Hiring the right people can be fustrating
Been taking a couple programming classes, but not sure I'll go with a developer route yet. Game dev, maybe.
That'll be the key if you're wanting to start a consultancy with no experience of your own.
You will need employees who are certified to carry out the engagements (and more importantly have the experience to actually back up those certifications), as well as a legal team to make sure your documents are water tight.
Erm
If you don't have the former then you won't get clients. If you don't have the latter then you'll end up in jail.
Yeah, don't be like me with certs and 0 offensive experience. 
Trust me y'all just automated AI agents to do bug bounty for u
There we go again 

You'll also need some pretty decent insurance... which brings us back to proving you're able to do the job safely.
Oh GTFO lmfao π€£
Imo people deserve a chance
Man i did that when I first started and it didn't work and after lots of pain I found a way to enhance it i made 50Β£ π
There are many that want to start in cybersec but will nevver be given the chance cause no prior exp
In a fair world, yes.
We do not live in a fair world though.
In the real world, companies don't like taking unnecessary risks
And in the real world security is not an entry level sector of IT
I get that, but that doesnt mean I have to follow the same route when I hire my employees
Which I have done before
Depends
Good companies always bring in a few juniors along the way, it keeps the team fresh
Oh, for sure.
If you setup a company and have the budget / time to train up juniors from nothing then good on you, 100%.
But you're not going to get a consultancy off the ground like that.
Good companies does that great companies get junior developers and gives them senior tasks and a cursor subscription
And for low salaries

Lmao π
Pentesting is high stakes. High risk, high reward.
If you fuck up, you're all going to jail.
If you can't convince clients that you can do the job safely, you won't get their business.
If you can't convince insurance that you can do the job safely, they won't insure you.
There's no getting around that.
U can't convince it's either u can or u can't it's a 0 or a 1
Wake up
I believe you over estimate the jail part to be honest, I am not sure where that is coming from π
To be honest, as a former business co-owner. I would take a pay cut first during hard times before I'd think about firing anyone from my team
3 monthes of pain
Due to OOS
π
Trust me the best thing that u can do is to fire useless who consume and don't generate
Nah, it's pretty clear cut in most jurisdictions.
Usually when something goes wrong, it gets absorbed by the contract and liability waiver (and then by insurance when the client demands a payout).
If you don't have that then you're at the mercy of whatever your local laws are.
guys
ERROR 2026 (HY000): TLS/SSL error: Certificate verification failure: The certificate is NOT trusted.
how to fix this issue when logging into a mysql port?
If you hire the right people, that wont be a problem
im doing a tryhackme room
I agree but those type of contracts are pretty standard stuff to be honest π
Jail is a very real possibility (at least in the UK under CMA). You just don't hear of anyone dumb enough to pentest with contracts and insurance lmao
Go to setting of ur browser and trust the cert
Exactly
If things are setup correctly then you shouldn't need to worry about it.
That's my point.
Hire people with drive, not just paper
U can't know if u hired the right people or no ans there r always better offers
If you setup a consultancy you can't cut corners.
my browser? wdym
I cant even read this, what?
Where do u get the error?
im trying to login to a mysql
There r always better offers to hire people who r better with lower salaries
mysql on a tryhackme room with TLS?
Why would they be using a browser to authenticate to a mysql db?
Which room is that?
I pay my people well
i do not know man im getting this error when im trying to login it also happened before in the advent of cyber 2019
To the best that can be offered
Room link?
Wordpress: CVE-2021-29447
I nvr fked around as a business owner
This is the best advice indeed! I have my own team and I brought all of them in because of their motivation, this is where the magic happens!
and in advent of cyber 2019 i forgot which day it was
Exactly!
Did you try comparing with the writeups?
Go read in room bugs in reported a bug before
Exp is not always the good pick
And no one asnwered
i searched on youtube and google it worked fine for them
You should always give people a chance, as long as they have the drive to grow
but when i try to login it get that error im using the same username too
Unfortunately does not work like that in real life. Look at all my certs, all that and I wasn't even given a chance for a junior pentesting position.
i mean its only for one question i tried just to search for it on google but no one is shwoing the answer so idk how to complete the room..
Best I got was web pentest, my one and only offer.
Just do this gng
mysql -h your_host -P your_port -u your_user -p --ssl-mode=DISABLED
In a year.
Agreed... Provided you have people (either those people, or other people), who can safely lead the pentest team 
Again, if you can't prove that to the clients, they won't give you money.
If you can't prove that to your insurers, they will either refuse you cover, or set a massive premium.
mysql: unknown variable 'ssl-mode=DISABLED'.
...
Did u rly just copy and pasted 
End of the day, experience does not necessarily make them suitable for that role... but lack of experience definitely excludes them.
bruh no bro im not that stupid
i jsut copied the sslmode and added it to my command
Having juniors with a lot of passion around to train up and learn from the seniors is awesome, assuming you actually have seniors to train them.
ββ$ mysql -h 10.10.221.189 -u thedarktangent -p --ssl-mode=DISABLED
mysql: unknown variable 'ssl-mode=DISABLED'
Thats why you have a mixed employee base
Like seriouly
Hmm try to run it with --skip-ssl
Exactly
Ofc you hire experts with years of exp
yh it worked now
This chat is confusing me, we have people topics and in parallel this guy is talking about mysql commands 
thank you bro
Anytime man β€οΈ
But atst I hire juinors so they can learn
Now, you do know what your problem here is gonna be right?
+rep @blissful frost
Gave +1 Rep to @blissful frost (current: #620 - 11)
Then again, might not be a problem, depending on your background I guess π€·ββοΈ
Have you ran a business before?
Gn y'all
Have you been a business owner?
Yep a lemon stand when I was 8
I apperciate the joke lol
is it a business?
Who was your network admin?
The root
Did it have a cybersecurity program? You know, to protect the lemons!
You're talking about starting your own consultancy.
You've said you're going to hire some experienced pentesters, as well as a bunch of juniors with a lot of drive.
You're going to get the legal basis in place to do the testing.
You're also going to get insurance in case something goes wrong.
Then you're going to acquire some clients.
All of that costs a lot of capital.
If you've got the money to throw at it, or can raise it from investors, then good on ya
No fking sht, its called small business loans
Ofc i used pure urine (fun fact urine is a natural grow booster for most plants)
Jesus fucking Christ. How the hell did we get to this
Has anyone actually landed a SOC career with the SAL1 cert?
Search it up man
It is sunday evening, classic stuff I suppose
Wth does that have anything to do with what I said?
I'd say the SAL1 isn't a key unlocks all kind of cert
It Saturday for me
Cool. You've got it all figured out. Go nuts π€·ββοΈ π
Or as I like to call it, "Thursday" π
Start a business yourself and then tell me how it is
What? How is that possible :/
Are you hiring yet?
I'm well aware of how to run a business lmao
We'll get there
k
They looked at the calendar

heyyy aha.
Lowk I came here to kinda troll 
What a malicious silly little fella you are π
Well, the saturday thing was just a stupid troll imo
cmon pope don't be so mean to the guy
It literally can't be π€£
If you're gonna troll at least make it vaguely plausible
He's just here to do a bit of trolling
0053 on Monday sure
I swear on my life it's 12:55 am rn
Sure. On Monday
Nah
Point at him and laugh hehehehehe
how bro feel
Can we bring back MSN and forget all this discord BS
IRCs
yahoo messenger?
BUZZ!!
imagine THM on this π₯ π₯
aah wass that hotmail?
Ehh it lacks the pop
MSN
Oh my god, let's not go back to that era 
I think y'all were talking abt business the only way to do business is to make ur employees blind to the truth
windows live messenger
I'd go back to that era ANY day of the week
i'm old, but not sure I used this :)
I daily drive Ubuntu for 2 years now what should I change to?
An era where the internet actually had character and wasn't built around algorithms and bots made to hold your undivided attention hostage all while bombarding you with advertisements and propaganda of all kinds
Why not go for good old Debian?
Ubuntu's granddaddy
How old? Because MSN was pretty well known
I'm nearing my 30's and used MSN plenty
I think u mean grandpa π
If you are like me end of 80's you have lived through all of it
tomato tomato
Ur British?
ahem.. born in '86 =.= but consider demographics...
And you truly believe the best of it is this era?
Depends on the day
I actually believe the best was, when we had no internet π
Love that reply, 100%
And I am lucky enough to have had my childhood without any of the Digital era stuff
saaame :D
I lived in a very underdeveloped location, where our televisions had only just started showing color. I lived during an era where VHS tapes where the standard, and all my childhood is kept in VHS tapes to this day
In the meantime, my godfather from America would bring us gifts like a DVD player in the style of a laptop, and that was the most mindblowing tech ever
Avg me being 15 reading this and asking how did people live back then
Very happily I'm afraid
We had good lives without the internet to be honest, kids where mostly playing outside, in bad and good weather
These days we have been imprisoned in a very insidious comfortable cell
Like what did u do for fun
the industrial revolution destroyed society
Like even studying study materials was too old and bad
We had neighbors, we went for long walks, we met up after school, we ran away from the house, bike rides, we'd go to the funfair, win bb gun prizes and play bb gun wars
The greed of the owners of the industries did
During Christmas we'd go for carols, by nighttime we could afford a Playstation 2
I used to do this too what is the problem?
that's a small business idea :) sing for games
That's good! Your parents gave you logical boundaries and allowed you to enjoy your childhood
yeah but not everyone has those boundaries nowadays
My statements are not meant to attack the average person, it's all about what today's industries are targeting
absolutely not, unfortuantely
Hahaha no they didn't at all my parents didn't let me out of house alone till I was 11
Would you let your child leave the house at the age of 10 unattended?
amyhow night night all, it was fun chatting
Goodnight friend
Depends
Is the future safe?
Then you're still a tad bit young π€£
Maybe the future is safe
That's what our ancestors used to say in the medieval ages
That's what their ancestors used to say as cavemen on the verge of civilization
U can never say will u but u can say should I have done?
No, as that implies regret
Ye and by years world is getting safer at least I won't get eaten by a huge chicken

There's much worse out there nowadays than huge chickens
Regret is a key to build better future without regret no improvement
Don't blame your parents for keeping you safe, or, blame them, but expect to understand when you grow and have kids of your own
Ur right ngl thanks
Gave +1 Rep to @topaz topaz (current: #232 - 41)
Don't confuse development with contemplating and feeling bad about past choices. Embrace bad decisions, if you didn't have the chance to choose them then, you could've made far more crucial mistakes further down the road
hi
Sup 47/Smith
Hi everyone
I mean if mankind didn't get regretion they won't try to improve to prevent them later right?
Here comes THE elliot
just bought premium and started taking notes properly in obsidian im locked in now
Hi buddy hru?π€£
From the pfp ik the most iconic questions r coming
The best combo
whats going on here? anything interesting happenin?
Doing alright. New to cybersecurity, or visiting with experience?
I used to use obsidian before tryhackme for my normal to do list
you got me.
Just a bunch of I.T. nerds getting angry at terminals and asking for help on syntax errors
The usual
Obsidian is excellent. Do you use Linux?
Ah Ubuntu you mentioned
I use Ubuntu dailt drive for 2 years now
Daily
Why did yo uwant to switch
Bored idk
Good enough reason. I love my Debian machine
It's always nice to try smth new to learn to keep ur development going
Not that new to cybersecurity but definitely new to this app ...
I mean it's crazy here
There's some nice n chill people to talk to here most days of the week. I like spending an hour or so just relaxing
Whatever happens don't go to servers with no rules to not get traumatised like me
I gtg rn
which servers you talkin about
Yeah btw what the hack of sever I can't understand
Ofc i won't mention them π
Gb
Gn
Stay safe
gnnn
Thanks again @topaz topaz
Gave +1 Rep to @topaz topaz (current: #227 - 42)
You're welcome my friend
yo guys
i bough a wifi adapter atheros ar9271
like a week ago
but that shit aint working
can anyone help me here
same as yesterday?
If I only could start Obsidian at the beginning...
what do you mean
Me too dude. i spent wayy too long just forgetting shit and taking notes in nano before i installed this
I also did it before in nano lol
what are you talking about
lmaoo
i took notes really bad and kept forgetting shit instead of learning it properly
broo i wish i could buy prem
ohh are u using a program called Obsidian ?
Yea its good cus you can like make links between different notes and stuff
google it
cherrytree does the same job too
yh same problem tbh i keep forgetting stuff and my desktop is full of stuff when i want to search for something i spend hoursπ
I regret not doing accurate notes bc I returned to them many times
and then... what just I did?
yeah i found it
should i also download
Obsidian.md
ohh does it cost money?
Nah its free
alr
hows the prem bro π
bro why u suck at coding python its the easiest lang..
Im starting from square one on the jr pentester course cus before prem i just did random rooms and now i have random knowledge everywhere instead of a solid base π
cus i never program
ohh daym lol
i just started with these path things
like 2 months ago
but i cant even complete them
cuz of the prem ;/
;/
does cisco have an updated blueprint for CCNA
anyone know
because iβm genuinely lost in the sauce

k can you tell me more?
Hey question I am wondering if I am able to copy what is said in sections of tryhack me to have a reference if I forget?
what do you mean
can you elaborate?
so I am using obsidian to keep notes of things like https://tryhackme.com/room/monikerlink?taskNo=2&sharerId=6792b3d1f6d63c3c0064c39e to go back to as a reference
so I am trying to keep notes is all not trying to use it like my own words just to go back to
sounds like youre already doing what youre asking
on copying information to save for personal use?
for reference of what i have completed already
like I am looking here https://tryhackme.notion.site/Community-Guidelines-bb1cc45df5a64db98ef0d8d314834a68 and it does not say anything
Welcome to TryHackMe a community dedicated to fostering a safe, respectful, and engaging environment for all members. Our community guidelines are designed to ensure that every member can enjoy and contribute to our discussions, events, and activities in a positive and meaningful way.
Its okay to take notes bro dont worry
well I want to copy what they said bc its explained well'
As long as you dont take parts of their premium lessons and publish them online you'll be fine
why would that be a problem?
Yea 99% of people do that dont worry bro
yeah I just want to know where the lines are is all
bc I dont want problems ltr
yeah its fine you can do it
No I am not I just want to keep the information as reference for help later
Okay is there a way I can talk to them just in case or nah
talk to whom
I mean, yes, you're allowed to copy and paste information from websites
But I think I might be confused about what you're actually asking
no, that is essentially what he is asking
From what I gathered the person is just scared that he's holding copyrighted material due to the copy pasting
correct
You are not to share copyrighted content from these rooms in any way
Isn't that what a cache is?
yeah he is not planning on doing that
its just for personal reference
Then I personally doubt it's a problem, a ton of people already do the same thing
Hell when I Was in school my teacher would ask us to copy stuff from the chalkboard down to our notebooks, this is how most people have learned to take notes
maybe if he is super dumb and somehow syncs premium content with some online repo
Yeah I I ainβt dumb lol
You're fine, keep learning and enjoying your content man
yeah then you should have nothing to worry about mate
Okay
now go crush some rooms π
web browsers have a save function. you can keep a local copy of the whole page
That sounds like a horrible way to take notes π
definitely. but its been a function for as long as web browsers have been around
fact
it also has a print function π
i just use comet to summarize each page without looking at the page kappa
Haha yes I've worked in I.T. no need to remind me of those headaches π
eeeeeeeeeeeeeeeeeeeeeekkkkkkkkkkkkkkkkshshshshshshckkckckckceeeeeeeeee
thats my impression of a dot matrix printer
more what bro π
What we cooking today chat?
th you doing in the screenshare bro
just started to finish off a ctf
not much atm. not sure what ill work on today. hbu?
Finishing off ctf, cleaning notes up
but why are u in a private screensharing..? hahahah
guys i got question
private screensharing, wym?
it says u are in general talk-chill and its private
guys if the website index.html is in /var/www/html
and there is also a port 8080 running on html
where should it be?
in /var/www/html?
It's probably because your not verified.. with voice access..
ohhhhhh alr bro mb lol
Connect your THM account and you will have the ability to join voice channels.
which ctf u doing
yh ill do that later
Guardian from htb.
hahahaha

how do you guys fight the urge to not use what you learn for bad just asking if i am not allowed i would understand
Why do you have the urge to do something bad
it's called morals and legislation.
I just donβt have that urge
ethic
toucha
How to fight the Urge?
Think about Prison life
Make yourself afraid that you wont run that little nmap scan.
lmao
easy come easy go
if your car can go 160km or miles per hour, does that mean you should do it in a residential area? π
Yes.
Absolutely
jk
No
wrong, you should say yes only if it's your ex's street 
You got me thinking..
does it 5 minutes later.
kids don't try this at home
Kids, this is for educational purposes only.
only speed on property you own or have permission to use π
My ex would jump in front of the car 
@gusty inlet plz
Done!
ask for permission before driving.
get it in writing and looked over by a lawyer
smart idea
calls lawyer
A better question is how do you guys fight the urge to not use what you learn for illegal but not bad things
E.g.: Doxxing the owner of a scamming website or exposing these kinds of shady stuff
i dont know just like hack someones phone who talks alot of shit would be fun but not allowed i suppose
there is no urge to do those things
ehm I don't know, do you want to get intro trouble?
you know not like leak their shit just show them it to get them to shut the fuck up
If I could I think I would have them
I wouldn't give into them but I'd have them
i am to new to want to get into trouble yet
I guess I have batman complex
but the urge is there to see how much power you could have
If u wanna catch bad guys become law enforcement or a lawyer
me a cop lol and or a lawyer i have been on pc way to long lol
Doing something illegal to catch someone doing something illegal usually doesnβt solve anything
That person may go free anyway
And u could get in trouble
welp time to hit the hay and go honk mi mi mi to beep boop for sleep sloop meep moop style
this is true
ehm meep the moop i guess mrs shadow senpai
or a mercenary
cyber mercenary lol
Daddy Keanu
i love benedict cumberbatch
time to become a netrunner??
Thatβs whatβs up
well
I have returned.
Note to self: Do not wait until the last minute and cram study for the SecurityX exam....
How'd it go?
#rules Rule 3.
I passed, thankfully.
Awesome job. ππ½
Have pneumonia, which makes it even more surprising since I was coughing every 2 minutes and head was buzzing the whole exam.
But overall, it was a solid exam.
Yikes.
Now all my other exams have renewed, which is the only real reason I elected to take this particular one
Are you CompTIA sponsored or something? π
Oh I have no idea. I was joking.
oh lol gotcha
Considering your choice of certs. π
well, my choice was because apparently you cannot use CEUs for the CySA+. Only for the A, Net, and Sec certs. So I would either have to take the CySA+ again or the PenTest+, or take the SecurityX (which used to the CASP+ I think)
all that... and I am a glutton for punishment and enjoy the challenge lol
That I have no idea about... really caught me off guard since I had done their CEU course thing for my Sec+ previously. completed it over a weekend and boom, I was re-certified.
I guess because its more of a mid-level cert that they wanna make sure people are staying current or something? idk π€·ββοΈ
Hmm...sounds a bit redundant to me but alright.
yeah who knows
all I do know was that I wasnt just gonna let years of effort and headache expire
glad I passed, thankfully
π
π
hi
helo
Moved my work-in-progress notes from local joplin to server hosted trilium
it's slowly coming together π€£
yo guys how can i get the subcriber role in here
...have you tried subscribing?
cause it looks like you already have it
Hello all, new this is world. I was curious whatβs the best way to start and progress. I have maybe 30-1 hour of time to educate myself as I work a 14-18 hour job
no
hi guys
anyone know about how to do penetration testing for web application
Skinwalker hours
Its almost the Day of the Dead
My family gonna be weird n sht
Making fking shrines n crap
Although I do like the spooky ness
sound fun join them
Do we get a badge for finishing first in ruby league?
yep
Does it take time to receive it or what? Bc i still did not get it
Thanks
This is easy. Do it with hackerone, intigriti, bugcrowd etc or out it on companys website.
Not get people to do your dirty work on discord
Im doing the "Alert Triage With Splunk" and dont even need to do splunk queries. "What is the name of the parent process for the process that created this malicious task?" duh "Which local group did the attacker enumerate during discovery?" duh
many soc boxes on thm
hi
Hmm, I ended up being first in gold league and I didn't receive the badge π
happens
Maybe try reaching support?
I finished yesterday evening as a 2nd place plat after starting out in the morning on place 17
The grind was real
Been like this for a month now 
Yeah luckily I have it on mail I won so fingers crossed they can do something for me 
Dude, those reports are like one day old
uh huh
Whoops 
no
any one doing the red teaming path currently?
mornin
hi
hi
hi
correct. thm unfortunately does not seem to look at these often.
there are unfixed bugs mentioned in bug report that are months old
I downloaded a exe file but it felt malicious to me. Without opening it, I first checked it on VirusTotal wherein the community tab I saw a comment which wrote
Original filename : 2025-09-06_2cccf36b9d62026d435c6ca4885008b6_akira_cobalt-strike_rusty-stealer_satacom_vidar
What could this possibly mean ? Was that a ransomware
where did you get this from?
what did you think it was?
can you give me the hash?
From a website ofcourse. It was a downloader
ehm yeah from which website
ok; and again: which website? what did you think it was? what is the filename?
probably not akira_cobalt_strike-... right?
ok i see
the name was downloader.exe
filename was "downloader.exe"
It is actually callec cirno downloader
well thats already a pretty sus name
I cant say the website here but others just download it and use that exe
But i was trying to take some precautions
Cybersecurity taught me π
okay so it was meant to download cirno downlloader which is a downloader for clean game files
for later activation
A lot of people use it but I dont think they have ever cross checked it for being malicious
I am talking about AAA denuvo games like AC Shadows
EA FC
etc
It downloaded downloader.exe which I refrained from opening. Ik by opening it, cirno will be opened for sure but it may also activate spywares or data stealers on my system
I'll check out what I can about it
give me a sec
Alright thanks
okay. I have looked at the virustotal results.
Disclaimer: Iβm not a cybersecurity professional. Anything I share here is for general informational purposes only and shouldnβt be taken as professional advice.
Anyrun said Microsoft Edge WebView 2 Runtime will also try to download but in my case, it didnt
on first glance this looks to be more likely a false positive than a true positive. but i would need to look into it more to be confident.
I see
give me another sec
Okie
okay, yes, my assessment is as I've stated above. however i have only scratched the surface here.
now my practical assessment for you: i would strongly advice against using this in the first place
this can cost you much more in the end than you are "saving" rn
Yes but it was mentioned in a comment on Virustotal not by Virustotal itself. Also I checked the profile of the commentor and bruh it has like comment after every damn minute just like a bot
Across different files
my practical advice for you is: DO NOT use this
Hmm yea
you are right
yeah just put a gazillion games on your steam wishlist
yeah, until you get caught for piracy
then buy stuff when they are on sale
Indeed
every summer holiday etc
there are great games on steam that are super cheap when on sale
yeah sure you're welcome
i looked into it a bit more and i am now less confident this is a false positive
so yeah: best to avoid these kinds of things
Where did you looked in to dive deeper
whether this specific file is malicious or not: piracy is a great way to catch malware
i initially thought what was mentioned in the comment is (likely) harmless aka false positive, but reading over it again, I am less sure now
I meant where you checked except Virustotal or anyrun
I read about akira stealer and rusty stealer online as well
Piracy is not bad in my personal opinion "Culture shouldn't exist only for those who can afford it"
But in this server it's not allowed to embrace it so stop
Alright my bad
i mean its not like we are doing malware analysis
If you are pirating something, always assume it includes some shady shii. It's a risk that you should understand.
Kinda sounds like it 
We were doing malware analysis only
Real
yeah okay appearantly we were π
Divyansh even took care not to mention the specific website.
yea cant lure anyone into downloading anything malicious just for the sake of checking or curiosity
Sounds like it, just wanna make y'all aware that mal studies are sensitive
Just vt analysis should be ok
Do you do HackTheBox
If this kind of discussion would be limited to advanced channels, I would be very disappointed as this would mean I would need to link my thm account. And the green would ruin my profile look.

