#general

1 messages · Page 1817 of 1

neat kindle
#

i cant remember what one A is in AAA

sharp igloo
#

Don't know why one needs to be randomly unfriendly

neat kindle
#

authentication, accounting and sms

sharp igloo
#

Just annoying internet stuff

neat kindle
#

you talk like youve never been on internet

sharp igloo
neat kindle
#

this aint 2010 lil bro

sharp igloo
#

Ignore list now.

sharp igloo
#

Anything else going on?

#

Someone got sth interesting to share maybe?

shell dirge
#

All sent dude

brazen holly
#

Not sure if this is the right place to ask this but , lets say i'm almost done w/ pre-security path (80%) and my main goal is to progress with pentesting

Should I progress through pre-security & cybersecurity path first or should i go back to the linux & windows sections & try to advance my knowledge in those whilst progressing through the starting path's ?

I'm kinda worried that I might forget what i learned in the OS sections if i move on too quick from them.

Just looking for input on what might be the better approach to solidify my knowledge. Thank you!

#

if this isn't the right section to ask this some guidance to the correct section would be appreciated 😁

velvet gull
#

are you taking notes as you go?

brazen holly
# velvet gull are you taking notes as you go?

Yes, i am. I will admit, i'm not the best at taking notes though , I just kinda print everything that's on the thm screen since i'm really bad at summarizing when it comes to this stuff.

velvet gull
#

going back to a section that you feel might be problematic to you in the future is definitely a good thing to do, but extensive notes are also needed so make sure to note all information you learn and all practical steps you did to solve the quizzes and attackbox sections so you have something to refer to later on. After pre security you should do the Cyber 101 path for sure, but honestly whenever you feel like you're missing something or not understanding a concept it would be good to go back to some previous rooms, refresh your memory and update notes on that

velvet gull
brazen holly
twin ridgeBOT
#

Gave +1 Rep to @velvet gull (current: #866 - 7)

clear jolt
#

I did the Cyber 101 path after Pre-Security, and it was definitely the best choice. Whenever there’s something I don’t fully understand, I go back and do it again so it sticks better. I don’t usually take notes myself, but on another server they recommended that I do and to use Obsidian for it.

velvet gull
#

yeah Obsidian is highly recommended, there are some people that need to physically write something tho but that's just up to preference

brazen holly
velvet gull
#

if you're gonna be using Obsidian, someone here recommended the HackTheBox theme for it

brazen holly
#

thank you guys , i'll download obsidian & look for a better approach for my notes. this is exactly the answer i needed

clear jolt
neat kindle
#

me reading notes for sec+ made by elliot

woven brook
#

is it just me or the thm website has been working very weird these last days?

woven brook
#

goes blank, does not load certain content, logs me out regularly

topaz topaz
#

But not loading certain content no not really, sometimes when I have done a force shutdown it will load the page but without any of the actual progress I've made and I need to refresh

#

But it's still as functional as it should be

lone sierra
#

compleated junior pen tester path

topaz topaz
#

If I really enjoy OSINT, what field would you say would be most suitable?

woven brook
#

innocent lives with my honda civic I have taken

lucid portal
#

Is the PT1 certification currently discounted? Is it worth it?

lucid portal
#

why pls

warm basin
#

such a bad joke i had to actually laugh (in myself)

#

i am premium, i just dont understand if I am receiving both by paying those 200$

ashen cape
#

No you get only one

marsh lark
#

one voucher for 200

warm basin
#

thanks 😄 gonna buy the pt1 anyway

#

it´s gonna be my first cert beside computer science degree

lone sierra
#

did you research if THM certs are worth it?

warm basin
#

since i am learning through THM, i thought it´s "easier" and the learned stuff will be better applicable

lone sierra
#

i would heavily suggest you to rsearch first

#

heavily

stoic flame
#

I think THM cert values

warm basin
#

Thank you, I´m aiming for the OSCP anyway by next year

stoic flame
#

What's that?

rapid merlin
#

A cert

royal hill
#

hello 👋

rapid merlin
#

Just go and hack some companies and then apply with those stolen information ( please dont take this seriously )

stoic flame
#

A piece of paper holds more value than knowledge

warm basin
# stoic flame What's that?

OSCP (Offensive Security Certified Professional) is actually worth it, people think at least that you are a good hacker if you have it

warm basin
#

if I am ever going to break the law for hacking it really has to be a good thing

marsh lark
#

its a junior cert

rapid merlin
#

OSEP >

warm basin
#

shotout to that guy who downloaded a full library database to make it public and went to jail for it

#

hackers have the power to end capitalism tho

stoic flame
rapid merlin
warm basin
#

we control electricity basically guys

marsh lark
#

microsoft web aint working

rapid merlin
stoic flame
#

I think the server has crashed

marsh lark
halcyon pendant
#

hi, does the current cert discount + the premium members discount stack up when purchasing an exam voucher for SAL1?

sharp igloo
#

Hey guys, what is going on? 🙂

sharp igloo
oak river
#

Anyone getting nostarchpress books?

rapid merlin
marsh lark
ionic gate
#

W

halcyon pendant
twin ridgeBOT
#

Gave +1 Rep to @marsh lark (current: #27 - 409)

sharp igloo
oak river
oak river
sharp igloo
stoic flame
oak river
oak river
#

They will have to reinvent the internet and how it works

#

Which is horrible if you think about it

#

Orwellian nightmare

blissful frost
sharp igloo
blissful frost
#

I just got the udacity certificate of level 2 🥳

rapid merlin
oak river
#

Although not on LANs

#

But a big tech player could potentially shake the internet ofc

#

Considering, afaik, that Israel managed to hijack an Iranian nuclear enrichment facility

#

With a USB

warm basin
warm basin
boreal scarab
#

My boss paid for lunch!

#

We got ramen baby

#

WOOOOOH

blissful frost
boreal scarab
#

I fucking love my boss. Best boss ive ever had!

blissful frost
boreal scarab
worn thorn
sharp igloo
#

Anyone got smth cool to share? 😎

rapid merlin
sharp igloo
austere verge
#

I’m using my fingers to type this message

sharp igloo
chilly veldt
rapid merlin
#

It's ordinary to love the beautiful, but it's beautiful to love the ordinary

dark wolf
#

.

sharp igloo
rapid merlin
sharp igloo
tired wolf
robust solar
#

i need an admin if theres one available?

chilly veldt
robust solar
sharp citrusBOT
chilly veldt
#

you gotta verify

robust solar
twin ridgeBOT
#

Gave +1 Rep to @chilly veldt (current: #9 - 1008)

robust skiff
#

Hi, is this the place to ask for help installing john the ripper?

dark wolf
#

sure. are you using a VM?

robust skiff
#

yes! Its on my macbook using virtualbox. It is a debian distro. I installed john with sudo apt install john. The first thing that is odd, is that I can only issue the john command while I am in sudo. Otherwise it cannot find it. Then when I want to crack a unshadowed file, john tells me that No password hashes are loaded. This might have something to do with not providing a correct unshadowed file? I used the command: sudo unshadow /etc/passwd /etc/shadow > unshadow.txt on my own vm to test if john was even working. Then john tells me that No password hashes are loaded. On the attackbox of tryhackme, this was no problem at all.

#

Help would really be apreciated 🙂

dark wolf
#

what if you run which john and sudo which john

#

do both provide output?

robust skiff
#

which john: nothing sudo which john: /usr/sbin/john

dark wolf
#

so only root has access to it right now. I'm not sure why, but let's check the no password hashes loaded

#

echo 'testuser:$6$rounds=5000$abcdefghijklmnop$abcdefghijklmnopqrstuvwxyz0123456789abcdefghi.:0:99999:7:::' > testhash.txt

#

sudo john --format=sha512crypt testhash.txt

#

run those and see if it does anything

robust skiff
#

(im having clipboard problems im almost there)

robust skiff
rapid merlin
dark wolf
#

sudo apt install john jumbo-john john-data

digital estuary
dark wolf
#

you need jumbo-john for that format, use that command to install it and then retry the command that gave you the unknown ciphertext error

remote spoke
#

hey guys

dark wolf
#

Hi Adam! Welcome

celest dirge
remote spoke
#

thank you allot m new to hacking and networking lol

rapid merlin
dark wolf
rapid merlin
robust skiff
rapid merlin
#

@robust skiff u using which os

robust skiff
#

debian

dark wolf
#

try just sudo apt install john-data

robust skiff
#

me too am very new to this haha

rapid merlin
robust skiff
#

I installed john-data but I get the same error message

dark wolf
#

john/oldoldstable 1.8.0-4 amd64
active password cracking tool

john-data/oldoldstable 1.8.0-4 all
active password cracking tool - character sets

#

debian has it. hmmm

robust skiff
dark wolf
#

You know, I am using Kali

rapid merlin
dark wolf
#

It has the hacking packages you need availble in the repo

#

debian not so much

rapid merlin
dark wolf
#

It might be easier to use kali. You can use debian but it doesn't look like it's going to be as easy to install the packages.

dark wolf
robust skiff
#

Yea I wanted to have my own custom pentesting vm

robust skiff
#

where I know all the tools

#

but ill go ahead with kali then

celest dirge
#

Guys, I installed Kali, why isn't it hacking NASA?

dark wolf
#

and just install what you need as you need it

#

then you know what you are installing and how to do it

robust skiff
#

Great, I will do that

#

thanks for the help!!

dark wolf
celest dirge
#

LOL?

rapid merlin
dark wolf
#

That's what they are saying

rapid merlin
dark wolf
#

Yes, you just have to believe!

celest dirge
#

Lmfao

rapid merlin
#

🫡

dark wolf
#

🤷🏻‍♂️

celest dirge
#

I wonder what type of software could possibly do this.

#

-# Surely it can't be Android Studio

dark wolf
austere verge
#

Nmap

sharp citrusBOT
celest dirge
#

Gotta verify first, then you get image perms @cedar crypt

sand trench
dark wolf
#

should have just asked shadow to begin with

sand trench
#

@loud marlin and the status page for arch now says the aur is down

sand trench
sand trench
#

never gonna mess with battery charging circuits and controllers after that

#

when they go they certainly go FWOOM

dark wolf
#

electroboom

modern fox
#

bruh what is this

#

new fonts

dark wolf
#

What are you referring to horse?

modern fox
sand trench
#

¯_(ツ)_/¯

dark wolf
#

¯_(ツ)_/¯

celest dirge
#

¯_(ツ)_/¯

modern fox
#

/¯ ツ)_(_

celest dirge
sand trench
#

anyone here used spideroak cloud storage for offsite backup???

#

wondering if it is as good as it seems on the tin

#

they have a linux client too :D

lone sierra
sand trench
lone sierra
#

no, it was some other server where someone had same profile picture as you

sand trench
lone sierra
#

i dont know any shadows?

sand trench
#

yeah then we probably never met anywhere

#

as shadow refers to themselves in third person

boreal scarab
#

Shadoooowwwww

sand trench
#

yes??

sand trench
#

guess what

boreal scarab
blazing granite
#

what

sand trench
dark wolf
#

😂

dark wolf
blazing granite
dark wolf
#

🤣

sand trench
#

wanna mess with twitch chats???? post a message using kanji or crylic letters

blazing granite
dark wolf
#

Yup! Don’t mess with them. They will blow up your phone

frigid gale
#

Can somone help me hack my mans account i think hes cheating me?

celest dirge
#

Chat, I'm locked out of my house. I forgot to bring my house keys with me and my dad is out shopping 💔

dark wolf
#

You know what the russians are good at?? Making people think they are good at anything other than drinking Vodka!

sleek hare
#

we used to use it as currency

dark wolf
sleek hare
#

need something done?

#

bring good vodka

#

and person will agree to do sum for u

celest dirge
dark wolf
#

Then do some yoga

#

stretch it out

celest dirge
#

Yoga? Where?

#

I can probably do it on my driveway, but idk anywhere else

dark wolf
#

Yeah, well you gotta do what you can

blazing granite
dark wolf
#

but you are probably super young ... i don't do enough yoga but i need to ... im old lol

sleek hare
sleek hare
dark wolf
sleek hare
blazing granite
dark wolf
sleek hare
#

and im ~20 kg underweight gng

blazing granite
blazing granite
#

I'm starting Tai Chi in Nov

celest dirge
rapid merlin
sleek hare
#

hater of sport lets say

#

I can get hospitalized if I jump & run

#

cuz slime stone

celest dirge
sleek hare
#

or sum

#

AND fun fact

#

I got blood infection

#

few days ago

#

antibiotics no help 😭 💔

#

im cooked

blazing granite
celest dirge
#

Oh god, that would be my worse nightmare Scared

celest dirge
sleek hare
rapid merlin
sleek hare
sleek hare
#

¯_(ツ)_/¯

rapid merlin
blazing granite
#

you need not to bring religion in the chat, it can create a discussion that never ends well

sleek hare
#

no

rapid merlin
#

deleted it

blazing granite
celest dirge
#

Lol, same here

dark mason
#

Sup chat

#

What did I miss

celest dirge
celest dirge
blazing granite
twin ridgeBOT
#

Gave +1 Rep to @celest dirge (current: #214 - 47)

dark wolf
dark mason
#

What else?

celest dirge
#

Oh wait, I'm dyslexic

#

I misread that

celest dirge
#

This is the best way I can summarize what happened in the last hour.

blazing granite
#

4 things, it was gradually or all at the same time 😛

celest dirge
#

Soo, I gotta wait until the ADMINISTRATOR arrives on site

rapid merlin
#

Use the cat door

#

It's silent enough

halcyon comet
#

wow I was doing coursea for like IBM ethical hacking with Kali Linux and I've been doing it like weeks it said it's going to take me to finished like 2 months nahh 2 months is crazy but I finished it like about 2 or 3 weeks and I got my course certificate and I'm doing a next one is professional certificate.

charred cave
halcyon comet
#

why he asking that..

dark wolf
halcyon comet
#

right

#

he trying to make us to do it

blazing granite
sturdy sequoia
blazing granite
sturdy sequoia
#

so, anyone up to anything intersting today?

celest dirge
dark wolf
sturdy sequoia
#

have you tried the air vents?

celest dirge
#

It's worth a try, although I don't think it'll work.

#

Well, at least my security is good and I don't have to worry about anyone breaking in, unless they smash the windows.

rapid merlin
#

good morning people, allow me to ask a question, is there any cybersecurity certificate that i can get free?

rancid anchor
#

Has anyone taken the ISC2 CC certificate?

celest dirge
rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @celest dirge (current: #207 - 48)

rancid anchor
celest dirge
celest dirge
#

After completing the exam, you pay the $50 USD Annual Maintenance Fee (AMF)

#

Which isn't much tbh

digital estuary
rapid merlin
#

kinda expensive for me, actually

#

but maybe i can use coding x app, it's free

#

but idk if it would be useful or not

#

yes

#

I hope I can ask that here:
Does somone know where a beginner in ethical hacking can start with ctf? Maybe more beginner friendly, but in the end it should be challenging.

#

Nvm google is my friendpengudab

stoic quarry
#

TryHackMe is a decent startingpoint

sand trench
stoic quarry
#

Hello Shadow

sand trench
#

ello ello

rapid merlin
stoic quarry
#

Ye

#

Rooms are usually separated between walkthroughs and challenges. Most of the walkthroughs will walk you through (funny that) the concept of the room. The challenges are more self directed

distant robin
#

is there a problem with the THM VM?

boreal scarab
#

Fucking Proton decided it didn't wanna work... uninstalled it and reinstalled it fixed it.... turning it off and on again, killing it, nope

distant robin
#

Lol

rapid merlin
#

hey guys

#

I think one room has a bug

#

but i dont have access to the appropriate channel

sharp citrusBOT
rapid merlin
#

Race conditions last machine

boreal scarab
#

Mother fucker

sharp citrusBOT
boreal scarab
#

That, use that one

rapid merlin
#

Ah yes i forgot

#

have to use the token

narrow yew
# blissful frost

I wrote an whole explanation for you on how it worked and you replied with crap

copper vortex
#

Can someone help me find where someone lives and their information by their name and face?

narrow yew
#

There is no cure for stupid

narrow yew
#

It depends on a ton of factors

distant robin
#

So can anyone tell me if the THM VPN is down or what?

narrow yew
#

You might need a new file

distant robin
#

I have premium

narrow yew
#

New battery for the GPS

distant robin
narrow yew
#

Buzz bzzzz

charred cave
#

Even just one single day 🙂

stoic quarry
#

Mr Robot is a TV show dawg

narrow yew
#

Schizofrenic

stoic quarry
#

That

#

And ||split personalities||

charred cave
#

Yeah mb i meant Elliot

narrow yew
#

He was craycray delux

rapid merlin
distant robin
narrow yew
#

Didi

distant robin
distant robin
rapid merlin
distant robin
charred cave
#

The more someone get in this field the more he feel that he know nothing about this things 😭

rapid merlin
distant robin
stoic quarry
#

I feel like a lot of people took a pretty surface level reading of the show as 'cool hacking show' over any deeper meaning that the later seasons get into

distant robin
#

@stoic quarry !!!!

stoic quarry
#

Uh

#

Hi

sturdy sequoia
charred cave
#

Does most of you guys work in cybersecurity or it’s just a passion

stoic quarry
#

If that's what ya watching it for

rapid merlin
sturdy sequoia
stoic quarry
charred cave
#

It’s just a hobby for me too
I’m still in highscool

rapid merlin
stoic quarry
#

P fun hobby

charred cave
stoic quarry
#

And job

rapid merlin
#

ofc

charred cave
#

Which one do you like more
Red or blue team

sturdy sequoia
#

im red all the way

stoic quarry
#

Blue

#

It pays the bills

#

And you can get a job in it lol

rapid merlin
#

i think cybersecrity wont be replace by AI like web and app developer in years

rapid merlin
stoic quarry
#

(Not to say pentesting doesn't have jobs, but you're not likely to get a job as a pentester early on)

charred cave
plush sable
#

Hello i am new here

rapid merlin
stoic quarry
#

Hello 👋

sturdy sequoia
plush sable
twin ridgeBOT
#

Gave +1 Rep to @sturdy sequoia (current: #305 - 29)

blazing granite
#

Hello i am new here, I'm GNU-Rex 🤣

stoic quarry
#

Gottem

rapid merlin
sturdy sequoia
narrow yew
#

@distant robin where is the VPS hosted? 😄

narrow yew
#

AWS is down again

sturdy sequoia
rapid merlin
narrow yew
#

Early 40s gang gang

blazing granite
charred cave
sturdy sequoia
narrow yew
blazing granite
charred cave
#

It’s never too late

rapid merlin
narrow yew
#

no lies!"

sturdy sequoia
rapid merlin
narrow yew
devout gulch
devout gulch
#

Good!

distant robin
distant robin
charred cave
#

who have a strong experience with nmap, i'm focusing on learing nmap this days 🙂

#

i wanna get deeper

distant robin
devout gulch
narrow yew
#

Looked at default nmap scripts?

distant robin
charred cave
charred cave
distant robin
devout gulch
narrow yew
#

That is what I mean

#

You asked for deeper knowlage, and I asked if you looked at default scripts

charred cave
sturdy sequoia
#

3 hours?

narrow yew
#

If you dont know that nmap have a -script you did not look at it that deep

distant robin
#

not really but it involves using nmap, @charred cave

charred cave
narrow yew
#

then you used scripts

rapid merlin
charred cave
distant robin
#

@narrow yew I need some discipline, Sir Math!

charred cave
#

i finished some rooms before

#

i even forget the account email and pwd

distant robin
narrow yew
#

@distant robin pg13 version would be
“Discipline me, sir.”
“Teach me a lesson, boss.”
“You’re in charge now.”
“Guess I deserve a little punishment.”
“Be gentle, but firm.”

devout gulch
charred cave
distant robin
#

Better? @narrow yew

narrow yew
#

@devout gulch Nahamsec.

distant robin
charred cave
#

networkchuck

#

david bombal

#

are my favs

narrow yew
#

@charred cave build a homelab if you want to learn networking

#

buy some crap managed switches

stoic quarry
#

Homelabing is fun

charred cave
#

installed ubuntu server on it

narrow yew
#

there are a ton of people selling Cisco cert home labs when they are done with certs

devout gulch
#

Thanks that helps! I have a network but just learning how it actually works now

narrow yew
#

There are also tools for setting up virtual network clusters

charred cave
#

an old desktop running ubuntu server have nextcloud installed connected to my router via cable

#

just wanted to try it out, then i unplugged it

#

i think it still have ubuntu server

stoic quarry
#

I have a laptop under a sofa running Jellyfin and Syncthing

#

Wazuh too, but I still need to configure that

sharp igloo
#

Oh this sounds interesting

blissful frost
charred cave
#

i have to make an account

#

i forget the credintials of the old acc

blissful frost
# sharp igloo

That's just an uncensored ai with extra knowledge abt pentesting

blissful frost
narrow yew
#

you have some work too do before you pass HexStrike

ashen cape
distant robin
blissful frost
charred cave
#

lemme try

#

brb

blissful frost
charred cave
#

that's cool

#

i will finish it today

rapid merlin
blissful frost
charred cave
twin ridgeBOT
#

Gave +1 Rep to @blissful frost (current: #577 - 12)

blissful frost
blissful frost
sharp igloo
blissful frost
#

😂

sharp igloo
tribal furnace
#

hey guys im new i want to join cyber security i wanna try do some practice in tryhackme is anybody here who want help me? I have a few questions

sturdy sequoia
tribal furnace
#

oh right. can you give me some tips that can i use at tryhackme. I mean i am in tryhack me 7 day in a row and i do some rooms with full of theory but i want to do practice. But even easy task makes me feel that its not for me. So i know that i have to know much basics of theory but i ve done some rooms and i cant do one easy task? What you recomend me to do in my situation

blissful frost
#

What r u typing mate

tribal furnace
sand trench
#

try out some of the easy challenge rooms

#

should get you cooking into not having tons of theory

devout gulch
sand trench
#

if you want a recommendation shadow can give you this list:
corridor
overpass series
agent sudo
pickle rick

blissful frost
#

Also try to access tryhackme with subdomain fo admin to get free premium subscription

devout gulch
#

Free premium is available? I hit a wall when I needed to pay…

gritty bane
sand trench
gritty bane
#

advent of cyber my beloved

devout gulch
#

Thanks, happy to send my money as the courses seemed very good but yeh still early stages for me and paying google for a course

tribal furnace
#

I want to try Red teaming what rooms do you recommend for me ( ofc the easiest one but I would rather try practise because i ve done several room of theory)

sand trench
blissful frost
#

Try to at least finish cyber 101 then choose

devout gulch
blissful frost
tribal furnace
blissful frost
#

U don't rly know if ur interested in cybersecurity unless u learn CS

sturdy sequoia
devout gulch
#

I’m so green CS is cybersecurity right

blissful frost
blissful frost
sturdy sequoia
#

computers -> networks -> security

devout gulch
#

Ok, thanks, but where do I start? I’m wanting to learn

blissful frost
blissful frost
#

We all started from no where just searching

blissful frost
#

Also change ur fyp to computer science topics u will learn lots of sub info in between

devout gulch
#

Yeh it’s broad I get it, thanks though. CS like bios and scripts? I know some buzz words

sharp veldt
#

What is it called when you want to hack a phone number

#

Like let’s say there’s an unknown number linked to your Apple ID and you need to find out what that number is

blissful frost
sturdy sequoia
blissful frost
#

He obviously knows that but whose phone number does he want kekw

sharp veldt
blazing granite
sturdy sequoia
#

contact apple support

sharp veldt
blissful frost
#

Call support

#

And the sim card company can also lock the phone if u want to

sharp veldt
# blissful frost Stole ur sisters phone?

Someone stole my sisters phone but the phone number that it’s linked to seems like it’s American. We are not American. When we saw the 2 devices that were linked to my MacBook, it was my sister’s lost phone and this other iMac with a professional sounding name

cloud otter
#

IS THM struggling right now?

topaz topaz
tribal furnace
cloud otter
#

Just seems to be running really slow and throwing an error when i try to answer questions

blissful frost
sharp veldt
# blissful frost Call support

They aren’t helping until I show proof of purchase but we bought my Mac from a retailer in 2021. He claims he doesn’t have the receipt anymore

#

Which is dumb

sharp veldt
cloud otter
#

@blissful frost gotcha, glad it's not just me than in a way

blissful frost
sharp veldt
topaz topaz
lofty pawn
#

First AWS, now Azure DevOps.

bright stone
#

@topaz topazare u from Greece?

cloud otter
#

Oof, last thing i need after 14 hours of work is to have a slow THM session lol fml

blissful frost
topaz topaz
sturdy sequoia
sharp veldt
sturdy sequoia
blissful frost
rose tusk
#

this is not legal, please stop asking for this type of advice

sharp veldt
blazing granite
frank sinew
#

Just a general question if someone knows the answer or is from TryHackMe Support team here: Planning to get the SLA1 Certification voucher (I am assuming validity is 12 months), my question is, I am currently subscribed to TryHackMe, will my membership be extended by 3 months?

rose tusk
#

if you don't have receipt confirm with your bank if they had the purchase or retailer

sharp veldt
topaz topaz
rose tusk
#

retailers are mandated to keep records for x number of years

sharp veldt
frank sinew
rose tusk
willow delta
#

guys anyone got a good website for generating deface?

sharp veldt
sturdy sequoia
devout gulch
sharp veldt
lofty pawn
sturdy sequoia
sharp veldt
#

Is there at least a thing that can allow me to try all possible passwords for something

lofty pawn
#

dude

#

cracking...

sharp veldt
lofty pawn
sharp veldt
lofty pawn
#

No one will tell you how to perform illegal activities (in this case being brute-forcing)

blissful frost
lofty pawn
#

🤦🏼‍♂️

devout gulch
sand trench
devout gulch
lofty pawn
#

^^^

sand trench
#

here is hoping post quantum encryption algos actually work

loud marlin
#

quantum will not do much in bruteforce login

#

you will get blocked if try rute foirce login lol

strong fjord
#

Ayo guys i have a quick question. I'm aware i should ask this to the support team but i wanna know if you guys have the answers.

My monthly sub is about to expire and I'm planning to change to annual sub but black friday is upcoming.

Should I just wait or can I change my annual plan to the black friday when it comes?

lament tendon
#

Quantum computers are really strong against asymmetric encryption and that is about it for brute forcing with them.

sturdy sequoia
#

Brute force wont work if you're locked out

loud marlin
lofty pawn
#

You'll most likely just get your ass rate-limited.

loud marlin
#

or you can solve P=NP and then you have all the things

devout gulch
#

That’s actually informative, I was joking but you all actually know your stuff which is cool. I appreciate learning more

loud marlin
#

if some have quantum pc, i have hash to crack... pretty please lol

dark wolf
#

P = Whatever you want

loud marlin
#

lol

dark wolf
#

Assuming you mean n * p 😛

lofty pawn
dark wolf
#

5 = 1 * 5

#

6 = 1 * 6

#

lol

#

any other einstein followers got an equation?

sturdy sequoia
dark wolf
#

Damn, what's it go to ? 10,000,000 ?

lament tendon
loud marlin
#

there is much more in p=np

dark wolf
#

i kid

lament tendon
#

Won't really make it easier, but I don't know math well enough to give exact details.

#

Does 7z use it's own hash function?

devout gulch
#

This is high concept right? You literally put more esoteric language and I’m lost

lofty pawn
blissful frost
lofty pawn
#

they do

#

7zip is faster and has better compression in most scenarios

#

vs winrar

lament tendon
#

Well, in that case a quantum computer may or may not solve your problem as I have no idea how that function works, lel.

loud marlin
#

AES-256 encryption

lament tendon
#

You should still be able to see the file names in that encrypted thing tho.

blissful frost
devout gulch
#

Random but is quantum still classed as binary?

loud marlin
#

SHA-256–based KDF with salt and a high iteration count

lament tendon
#

You are not breaking AES256 even with a quantum computer.

loud marlin
winged dirge
#

hey can someone help me out im trying to get into cybersecurity and figured this would be a good place to start. ill explain more in a vc just confused

blissful frost
lament tendon
#

What would you even do with this hash if you did not have the salt?

loud marlin
#

you need whole file. is all one thing

lament tendon
#

Salts only protect against rainbow tables.

#

They're not a secret.

blissful frost
winged dirge
#

ty

twin ridgeBOT
#

Gave +1 Rep to @bronze crescent (current: #1286 - 4)

trail sequoia
loud marlin
#

password = password + salt = hash

trail sequoia
blissful frost
lament tendon
lofty pawn
#

I wanna try vim just for fun

lament tendon
#

A salt should always be supplied with the hash value.

lofty pawn
#

just been using nano the past years

lament tendon
#

If it is not, you would call it a pepper, fun fact.

loud marlin
lament tendon
#

Anyways, back to topic.

#

You have a hash from a 7zip.

#

You should at least be able to see the filenames on the top level of the archive anyways.

#

Dunno whether that helps.

devout gulch
#

I’m very green but what is it with this industry coming up with such jk names?

blissful frost
loud marlin
lament tendon
#

Also I would expect the salt be part of the password hash you send, because it would make very little sense if it was not there.

lament tendon
#

Seems like an interesting approach.

blissful frost
#

Ik a good arabic source do u speak arabic?

lament tendon
#

No.

#

I will research myself.

blissful frost
#

Alr let me search for smth else

cloud otter
#

3 hours later..................................................

distant robin
#

Is there a gaming channel here?

loud marlin
lament tendon
twin ridgeBOT
#

Gave +1 Rep to @lofty pawn (current: #3235 - 1)

blissful frost
blissful frost
loud marlin
#

@polar spoke can tell way more about 7zip then most of us know.... if he is amount alive ppl

sand trench
#

shadow can tell you more about cheese then most of us know

twin ridgeBOT
#

Gave +1 Rep to @blissful frost (current: #534 - 13)

lament tendon
#

So from what I get from this here, there is no salt at all.
Which does not matter as much in this case, as there is no actual password verfification, but you can only try to decrypt the file and see whether that worked or not.

https://crypto.stackexchange.com/questions/90137/7-zip-encryption-practical-effect-of-lacking-salt

#

Aka. no rainbow tables, and each decryption attempt will take a considerable amount of time (at least to a computer).

#

Makes sense.

blissful frost
left torrent
#

youngest hacker here?

lofty pawn
sturdy sequoia
left torrent
lament tendon
sturdy sequoia
left torrent
sturdy sequoia
lament tendon
left torrent
#

youngest hacker here?

sturdy sequoia
lament tendon
#

So when you input a password, the files are "decrypted" incorrectly, and since the output makes no sense, 7zip knoes that the password was wrong and tells you that.

left torrent
#

so

#

ye

#

no one report me

#

ffs

lofty pawn
twin ridgeBOT
#

Gave +1 Rep to @lament tendon (current: #40 - 270)

left torrent
#

hehe

lament tendon
#

They might be trying to get someone banned when they respond with a number that is too low for Discord TOS.

sturdy sequoia
lament tendon
#

Best is to not respond.

left torrent
left torrent
lofty pawn
#

Yeah like how people try to trick people to say numbers like 12, 11 etc as you have to be 13 in order to use Discord.

left torrent
#

wait

#

13 is the age?

willow delta
#

guys is there a king.txt in the tryhacme koth hard?

left torrent
#

o im chilling

lofty pawn
lament tendon
#

Do not respond to this dudes messages, there is a good chance you will be banned.

willow delta
#

HES COOKED

lament tendon
#

They will edit their message and then report yours.

willow delta
#

LOL

lofty pawn
#

Nah

willow delta
sturdy sequoia
winged nimbus
#

prob not a good idea to even say these numbers in chat, knowing how shit discord's automated moderation is, you guys should prob stop talking about age

left torrent
willow delta
#

guys

lament tendon
#

They don't check the edit history.

lofty pawn
#

Discord stores message content which also applies to message history (edits)

willow delta
#

is there a king.txt in tryhackme koth hard?????

lament tendon
#

Just getting into the machine is decently easy.

willow delta
#

bro..

left torrent
#

its battle royale in koth

#

lol

willow delta
#

im saying

#

is there the king.txt in root?

#

or no

lament tendon
left torrent
#

last man standing

lament tendon
#

Let me source you something.

lofty pawn
#

Been on this platform since 2016.

#

Still in good standing.

#

Never been banned.

left torrent
#

had great tanding and all

lament tendon
#

Watch that.

left torrent
#

i was trolling and said i was 10

lofty pawn
left torrent
#

got banned

lofty pawn
lament tendon
#

It's gonna explain it better then I ever could.

left torrent
left torrent
#

it got banned immediately

#

one sec

lament tendon
#

Wonder whether Discord will actually do anything about this anytime soon, has been an issue for ages.

#

But now everyone knows about it, which is a bit of a problem.

lofty pawn
lament tendon
#

Debatable. I usually am into dark humor, but this specific case causes a ton of harm to random people.

left torrent
lament tendon
#

I mean, you saw the video about that as well, I assume.

lofty pawn
#

Someone managed to phish one of their employees into giving their login credentials.

left torrent
#

they want my pic via email to verify

#

lol

lament tendon
#

Yea.

left torrent
#

this was before the dc data breach

lofty pawn
#

/external employees, out-sourced, don't remember all the details

lament tendon
#

You can verify with your ID that you are old enough, but then they will store that ticket in Zendesk, get their Zendesk hacked and now your ID is used by some dude to extort Discord and potentially worse.

#

This whole situation is a massive disaster.

left torrent
lament tendon
#

Never give our your ID online to anyone or any service.

#

If the service requires your real life ID, it is not worth using.

left torrent
#

there you have it discords mod watching

lofty pawn
#

Meanwhile KYC 😭

#

(Know Your Customer)

#

It really isn't voidable.

lament tendon
#

Banking is a bit of a different deal, but you can actually physically go there and do the verification face to face, lel.

#

Even tho, of course, there might be some cases somewhere where sending your stuff digitally cannot be avoided, fair.

lofty pawn
#

Still a bit relevant though, they're not exempt to breaches.

#

Even though it's unlikely to happen.

lament tendon
#

They should also not store pictures of your ID after verification.

#

Discord should not have done that either.

lofty pawn
#

I'm just amazed Discord didn't have other measures in place in the event of a breach.

lament tendon
#

The measure would have been not storing personal information for longer then required for the purpose that information was collected for.

#

Which is actually illegal in the EU.

lofty pawn
lament tendon
#

Also MFA, I guess, but that does not secure you against all phishing attacks either.

lofty pawn
#

Don't know what's it like now, but before you could log in to accounts by grabbing tokens and log into it through the console through a specific command.

#

Probably been patched.

lament tendon
#

You can still do that because your Discord login is just a session cookie, like you'd have for any other website.

#

Dunno whether you are still able to change your password just like that anymore tho.

#

Or your email, both would work fine.

#

If you have MFA set up it will required a code.

lofty pawn
#

I wish Discord supported login through titan keys.

#

Would be a game changer.

sand trench
#

well discord not enforcing their 3rd party support providers data retentions is certainly not a good move

lofty pawn
#

Yeah, and the fact they're trying to hide it lol

lament tendon
#

Are they?

sand trench
#

hiding the databreach does not seem to be happening

lofty pawn
#

Yeah, they didn't give all the correct details.

lament tendon
lofty pawn
sand trench
#

i.e generally both are wrong

lofty pawn
#

Yeah you're right.

lament tendon
#

If the statements the hacker made in this video are halfway accurate they are not much better then that finish hacker from a few years back.

sinful moon
#

Slightly unrelated, but I hope you all get experience writing Incident Reports for work because fun, it's that time for me again

lament tendon
#

Hopefully not, the writing I already do is the most boring part of my job. catlaugh

sinful moon
#

Indeed but having these kind of writeups are critical imho

lament tendon
#

They are. I am just glad it's someone elses task to write them.

sinful moon
#

Haha I am the all singing all dancing infosec everything at my org, so all me

#

as evidenced by this could have been prevented or mitigated earlier if not mishandled by another tech

hardy hazel
#

hey

sinful moon
#

Yep pretty much literally lol

hardy hazel
#

what does mean subscriber and verified? or how can i get that roles?

blazing granite
sinful moon
#

There's also a neat documentation search I was about to provide but that works too

hardy hazel
hardy hazel
twin ridgeBOT
#

Gave +1 Rep to @sturdy sequoia (current: #300 - 30)

lament tendon
hardy hazel
sinful moon
#

Subscriber are for people who subscribe to the TryHackMe service

lament tendon
hardy hazel
#

thank u for helping

twin ridgeBOT
#

Gave +1 Rep to @blazing granite (current: #55 - 191)

sinful moon
#

so I should have just sent my command lol, oh well

#

just exhasted from 10 hour day looking into that incident lol

willow delta
#

whats the point of doing that bro

lament tendon
#

Verifying?

#

Just the roles.

willow delta
#

yh

#

ohhhh

#

alrr

lament tendon
#

At a certain level you get access to some extra channels.

sinful moon
#

do you want to send embeds, show your rank on the site, and etc on the Discord, you kinda gotta

sturdy sequoia
blazing granite
lament tendon
#

And subscribers have one as well.

#

They are all pretty dead tho.

willow delta
lofty pawn
#

What are people's opinions about using Triage for malware analysis?

lament tendon
#

Just talking, and malware research.

sinful moon
#

Channels for subs and way way down the line, advanced topics

lament tendon
#

And a more advanced help channel.

willow delta
#

ait bro