#general
1 messages · Page 1817 of 1
Don't know why one needs to be randomly unfriendly
authentication, accounting and sms
Just annoying internet stuff
See. That's better internet stuff.
this aint 2010 lil bro
Jeez you are just annoying. Not even funny. Boring as fuck.
Ignore list now.
All sent dude
Not sure if this is the right place to ask this but , lets say i'm almost done w/ pre-security path (80%) and my main goal is to progress with pentesting
Should I progress through pre-security & cybersecurity path first or should i go back to the linux & windows sections & try to advance my knowledge in those whilst progressing through the starting path's ?
I'm kinda worried that I might forget what i learned in the OS sections if i move on too quick from them.
Just looking for input on what might be the better approach to solidify my knowledge. Thank you!
if this isn't the right section to ask this some guidance to the correct section would be appreciated 😁
are you taking notes as you go?
Yes, i am. I will admit, i'm not the best at taking notes though , I just kinda print everything that's on the thm screen since i'm really bad at summarizing when it comes to this stuff.
going back to a section that you feel might be problematic to you in the future is definitely a good thing to do, but extensive notes are also needed so make sure to note all information you learn and all practical steps you did to solve the quizzes and attackbox sections so you have something to refer to later on. After pre security you should do the Cyber 101 path for sure, but honestly whenever you feel like you're missing something or not understanding a concept it would be good to go back to some previous rooms, refresh your memory and update notes on that
well it's a start but there's definitely a need to note down everything you're learning in your own words so you can understand it better, if you just copy it then that won't make you learn much
Ok that's actually a pretty good tip in terms of how i should I approach the note taking.
I'll start taking notes based on how i solved the problems from now on, Thank you.
Gave +1 Rep to @velvet gull (current: #866 - 7)
I did the Cyber 101 path after Pre-Security, and it was definitely the best choice. Whenever there’s something I don’t fully understand, I go back and do it again so it sticks better. I don’t usually take notes myself, but on another server they recommended that I do and to use Obsidian for it.
yeah Obsidian is highly recommended, there are some people that need to physically write something tho but that's just up to preference
Ok sweet, i've been looking for a new note taking app 😂
if you're gonna be using Obsidian, someone here recommended the HackTheBox theme for it
thank you guys , i'll download obsidian & look for a better approach for my notes. this is exactly the answer i needed
you have to search the best app for you
is it just me or the thm website has been working very weird these last days?
meaning?
goes blank, does not load certain content, logs me out regularly
The logging out after a few days has been usual behavior for me, the pages going blank has been happening for quite some time also, I have to wait a few seconds for it to load the content
But not loading certain content no not really, sometimes when I have done a force shutdown it will load the page but without any of the actual progress I've made and I need to refresh
But it's still as functional as it should be
compleated junior pen tester path
Go for it why not
If I really enjoy OSINT, what field would you say would be most suitable?
love your bio
innocent lives with my honda civic I have taken
LMAO
Is the PT1 certification currently discounted? Is it worth it?
why pls
such a bad joke i had to actually laugh (in myself)
i am premium, i just dont understand if I am receiving both by paying those 200$
No you get only one
one voucher for 200
thanks 😄 gonna buy the pt1 anyway
it´s gonna be my first cert beside computer science degree
did you research if THM certs are worth it?
since i am learning through THM, i thought it´s "easier" and the learned stuff will be better applicable
I think THM cert values
Thank you, I´m aiming for the OSCP anyway by next year
nice
What's that?
A cert
hello 👋
Just go and hack some companies and then apply with those stolen information ( please dont take this seriously )
A piece of paper holds more value than knowledge
real life success rate: 1%
OSCP (Offensive Security Certified Professional) is actually worth it, people think at least that you are a good hacker if you have it
I am sure some shady CEO´s would enjoy that
if I am ever going to break the law for hacking it really has to be a good thing
its overhyped
its a junior cert
OSEP >
shotout to that guy who downloaded a full library database to make it public and went to jail for it
hackers have the power to end capitalism tho
They can change the world

we control electricity basically guys
microsoft web aint working
Same
I think the server has crashed
sad
hi, does the current cert discount + the premium members discount stack up when purchasing an exam voucher for SAL1?
Hey guys, what is going on? 🙂
for premium users, it is 40%
What is Microsoft web? 🤔
Anyone getting nostarchpress books?

web application of microsoft
W
thank you
Gave +1 Rep to @marsh lark (current: #27 - 409)
Hmm how? Could you explain?
May I join your ship, Captain?
Lets say that only with paper and without electronics, things will be much, much, much more complicated.
You have any plans to do that?
But a computer was made by doing calculations on paper
And how would that happen?
Sure, but a computer still excels at them.
I don't know, if all hackers got angry and started nuking the global infrastructure digitally and attempt to take it down physically
They will have to reinvent the internet and how it works
Which is horrible if you think about it
Orwellian nightmare
Ah ok. Thought you might have some specific mechanism in mind.
I just got the udacity certificate of level 2 🥳

Well, I guess maybe the USA can do that
Although not on LANs
But a big tech player could potentially shake the internet ofc
Considering, afaik, that Israel managed to hijack an Iranian nuclear enrichment facility
With a USB
well a simple idea: a group of activists ddos the shady companies of the world down, day by day as a job lol
not plans, but as a man everyone should be able to use their power to defend and do good
Yep stuxnet is powerful
W boss
I fucking love my boss. Best boss ive ever had!

looks delicious


OH FOR FUCKS SAKE!!!!!!
Anyone got smth cool to share? 😎
Roses are red
Yeah they can be
I’m using my fingers to type this message
I use my neuralink
yaaay
It's ordinary to love the beautiful, but it's beautiful to love the ordinary
.
!
؟
😮
its always dns
i need an admin if theres one available?
not an admin, but what specific do you need?
how can i join voice chat?
you gotta verify
thank you
Gave +1 Rep to @chilly veldt (current: #9 - 1008)
Hi, is this the place to ask for help installing john the ripper?
sure. are you using a VM?
yes! Its on my macbook using virtualbox. It is a debian distro. I installed john with sudo apt install john. The first thing that is odd, is that I can only issue the john command while I am in sudo. Otherwise it cannot find it. Then when I want to crack a unshadowed file, john tells me that No password hashes are loaded. This might have something to do with not providing a correct unshadowed file? I used the command: sudo unshadow /etc/passwd /etc/shadow > unshadow.txt on my own vm to test if john was even working. Then john tells me that No password hashes are loaded. On the attackbox of tryhackme, this was no problem at all.
Help would really be apreciated 🙂
which john: nothing sudo which john: /usr/sbin/john
so only root has access to it right now. I'm not sure why, but let's check the no password hashes loaded
echo 'testuser:$6$rounds=5000$abcdefghijklmnop$abcdefghijklmnopqrstuvwxyz0123456789abcdefghi.:0:99999:7:::' > testhash.txt
sudo john --format=sha512crypt testhash.txt
run those and see if it does anything
(im having clipboard problems im almost there)

Unknown ciphertext format name requested
Apple: " it's not a bug, it's a feature "

sudo apt install john jumbo-john john-data
you need jumbo-john for that format, use that command to install it and then retry the command that gave you the unknown ciphertext error
hey guys
Hi Adam! Welcome
Lmfao
thank you allot m new to hacking and networking lol
Sup
Awesome, they are both tons of fun
U will master it
Error: unable to locate package jumbo-john
debian
try just sudo apt install john-data
me too am very new to this haha

I installed john-data but I get the same error message
john/oldoldstable 1.8.0-4 amd64
active password cracking tool
john-data/oldoldstable 1.8.0-4 all
active password cracking tool - character sets
debian has it. hmmm
What distro do you recommend me using?
You know, I am using Kali
U should have said something about this before to him

It might be easier to use kali. You can use debian but it doesn't look like it's going to be as easy to install the packages.
I never tried installing them on debian, so I didn't know they weren't available
Yea I wanted to have my own custom pentesting vm
Np
Guys, I installed Kali, why isn't it hacking NASA?
install kali-minimal
and just install what you need as you need it
then you know what you are installing and how to do it
No problem, let us know if you need anything, people are usually here 🙂
LOL?
Even I'm confused 🤔
"Oh look, see you already stole the bitcoin"
"ahh, duh, it looked like there was more"
That's what they are saying
Yes, you just have to believe!
Lmfao
🤷🏻♂️
I wonder what type of software could possibly do this.
-# Surely it can't be Android Studio
Blowout Incinerator™ 6.9
Nmap
Gotta verify first, then you get image perms @cedar crypt
it is called kettle mode
should have just asked shadow to begin with
@loud marlin and the status page for arch now says the aur is down
true... shadow is one of few peoples to survive a lithium battery fire
shocked 🙂
never gonna mess with battery charging circuits and controllers after that
when they go they certainly go FWOOM
let that electroyoutube guy do that
electroboom
What are you referring to horse?
nah new discord thing
¯_(ツ)_/¯
¯_(ツ)_/¯
¯_(ツ)_/¯
/¯ ツ)_(_
The face reminds me that I've been slacking off on my Japanese language studies.
anyone here used spideroak cloud storage for offsite backup???
wondering if it is as good as it seems on the tin
they have a linux client too :D
do i know you from somewhere
arch linux community discord server probs
no, it was some other server where someone had same profile picture as you
well the clippies are everywhere now.... if you recall shadows old profile picture it stood out much more
i dont know any shadows?
yeah then we probably never met anywhere
as shadow refers to themselves in third person
yes??
guess what
Chicken butt?
what
YOU GOT IT
😂
what
que? מה? 🤣
Your message made my computer lock up. please stop hacking me
🤣
wanna mess with twitch chats???? post a message using kanji or crylic letters
Israelies are masters of cybersec, everybody knows that 🙂
Yup! Don’t mess with them. They will blow up your phone
Can somone help me hack my mans account i think hes cheating me?
russians*
Chat, I'm locked out of my house. I forgot to bring my house keys with me and my dad is out shopping 💔
You know what the russians are good at?? Making people think they are good at anything other than drinking Vodka!
we dont drink vodka that often
we used to use it as currency
Might as well take a couple laps around the neighborhood to kill time
I've already done enough walking for today 
Yeah, well you gotta do what you can
On the illegal stuff, yes, otherwise agree to disagree 🙂
but you are probably super young ... i don't do enough yoga but i need to ... im old lol
shes only 15
ofc on illegal side bro 😭 💔
Hi
Hi!

I still have a few friends back in 8200 😉
Shhhh... you aren't supposed to admit that
I don't do any sports since first grade
and im ~20 kg underweight gng
you don't have to be a gym rat, but a bit of exercise it's good for your body
U have a house

I'm starting Tai Chi in Nov
And a house cat
my body is uh
hater of sport lets say
I can get hospitalized if I jump & run
cuz slime stone
Here's a picture of her (best one I could find)
or sum
AND fun fact
I got blood infection
few days ago
antibiotics no help 😭 💔
im cooked
it could be worst, you could live alone, forgot your key inside and have to call a locksmith those guys are expensive 🤣
Oh god, that would be my worse nightmare 
Rare, medium rare?
according to doc if antibiotics wont help yes this will happen
damn... that serious? wishing you the best
😭 idk
tbh I dont want antibiotics to help
¯_(ツ)_/¯
Nah, I need hacker competition. You stay in the pool, fresh and alive
you need not to bring religion in the chat, it can create a discussion that never ends well
no
sry, that just a saying here 😄
i dont even care about religion in that way. mb
deleted it
steak medium rare of course 🙂
Lol, same here
A bit late, but I wish you well
Nothing much, other than how'd you like your steak?
anything over that and you don't like meat you like sole shoes 🤣
thanks ig
Gave +1 Rep to @celest dirge (current: #214 - 47)
It's the only way
Medium rare, ofc
What else?
Damn, I guess I have an odd taste 
Oh wait, I'm dyslexic
I misread that
Currently locked out of my house, Russia, gym, and health
This is the best way I can summarize what happened in the last hour.
that's a hard locked out, how do you manage that? 🤣
4 things, it was gradually or all at the same time 😛
There is a backdoor, but pivoting there will raise noise.
Soo, I gotta wait until the ADMINISTRATOR arrives on site
wow I was doing coursea for like IBM ethical hacking with Kali Linux and I've been doing it like weeks it said it's going to take me to finished like 2 months nahh 2 months is crazy but I finished it like about 2 or 3 weeks and I got my course certificate and I'm doing a next one is professional certificate.
That’s not allowed here
why he asking that..
people think that because hack is in the name of the discord server that we are hackers
we're, but we don't do illegal things that's the difference 🙂
well, we might do illegal things but we dont discuss them here 😛
maybe be you 😛
so, anyone up to anything intersting today?
Not enough budget, and hasn't been approved by the board yet.
were just looking for a link so 0xNexionX can download a new door to get in the building
have you tried the air vents?
It's worth a try, although I don't think it'll work.
Well, at least my security is good and I don't have to worry about anyone breaking in, unless they smash the windows.
good morning people, allow me to ask a question, is there any cybersecurity certificate that i can get free?
Has anyone taken the ISC2 CC certificate?
The person below ya mentioned CC, which is free if I remember.
i see, thank you
Gave +1 Rep to @celest dirge (current: #207 - 48)
actually, that’s what I wanted to ask ,I think you need to pay $50 to get the certificate, right orr?
I haven't taken the ISC² CC exam yet, but I'm pretty sure everything they teach you (well most) will be on the exam, I recommend doing some external learning like YouTube videos and etc during prep.
Was it? Let me recheck
After completing the exam, you pay the $50 USD Annual Maintenance Fee (AMF)
Which isn't much tbh
ah.. it's 830k rp for me
kinda expensive for me, actually
but maybe i can use coding x app, it's free
but idk if it would be useful or not
yes
I hope I can ask that here:
Does somone know where a beginner in ethical hacking can start with ctf? Maybe more beginner friendly, but in the end it should be challenging.
Nvm google is my friend
TryHackMe is a decent startingpoint
Hello Shadow
ello ello
Already on it. Found, that they have some CTF challenges.
Ty
Ye
Rooms are usually separated between walkthroughs and challenges. Most of the walkthroughs will walk you through (funny that) the concept of the room. The challenges are more self directed
is there a problem with the THM VM?
Fucking Proton decided it didn't wanna work... uninstalled it and reinstalled it fixed it.... turning it off and on again, killing it, nope
Lol
hey guys
I think one room has a bug
but i dont have access to the appropriate channel
@rapid merlin
Race conditions last machine
Mother fucker
@rapid merlin
That, use that one
I wrote an whole explanation for you on how it worked and you replied with crap
0xC vs 0x7
Can someone help me find where someone lives and their information by their name and face?

There is no cure for stupid
It is yes and no on that one
sounds like stalking
It depends on a ton of factors
You have to learn some OSINT
So can anyone tell me if the THM VPN is down or what?
You might need a new file
It's the attack box provided with Yara
I have premium
New battery for the GPS
GPS doesn't need batteries
Buzz bzzzz
I really want to live Mr Robot live
Even just one single day 🙂
Mr Robot is a TV show dawg
Schizofrenic
Yeah mb i meant Elliot
He was craycray delux
did
Yeah this is the problem.
Didi
*schizophrenic
diddle diddle diddle
i mean DID, discotic (ugh i forgot) identity disorder
Dissociative identity disorder
The more someone get in this field the more he feel that he know nothing about this things 😭
yep, ahaha, i forgot the first word
You're welcome
I feel like a lot of people took a pretty surface level reading of the show as 'cool hacking show' over any deeper meaning that the later seasons get into
@stoic quarry !!!!
i think that only applies to hackers. most of my non hacker friends also like the show for more than just hacking
Does most of you guys work in cybersecurity or it’s just a passion
Oh yeah for sure. I think it's great in how it portrays the hacking side of things, but I feel like being too focused on that makes the broader message a little weaker
If that's what ya watching it for
passion, i still a highschool student
just a hobby for me atm
This server has like 300,000 people in it. There's a mix 🤷♂️
It’s just a hobby for me too
I’m still in highscool
yep hobby, same as me, and i want to go deeper
P fun hobby
I really want to get deeper
And job
ofc
Which one do you like more
Red or blue team
im red all the way
i think cybersecrity wont be replace by AI like web and app developer in years
purple
(Not to say pentesting doesn't have jobs, but you're not likely to get a job as a pentester early on)
Is this team is like a mix between both
Hello i am new here
yeah
Hello 👋
welcome
Thanks
Gave +1 Rep to @sturdy sequoia (current: #305 - 29)
Hello i am new here, I'm GNU-Rex 🤣
Gottem
tis is rafex!!!
im old here. well im new to the channel, but old to life
@distant robin where is the VPS hosted? 😄
How old 🤔
AWS is down again
early 40s
rafex is everywhere, i see you in another server
Early 40s gang gang
not old 🙂
You still have time
Much timeee
theres a few of us here
I will take your watch and send you in the wild
IDK who rafex is
It’s never too late
nah, you must be him
no lies!"
agreed
if it's not, you must be his twin dawg
They will start to loose customers now
I’m so green you can call me Grinch. I’m so green but wanting to build something new and trying to find community
here is a good place to start
Good!
are your skin is green too?
I never needed my watch. I only use it for the vibrating alarm on it
Bzzz bzzz
I'll take my flip flop and smack you with it
who have a strong experience with nmap, i'm focusing on learing nmap this days 🙂
i wanna get deeper
I'll enjoy that
What are you thinking
I’m not a lizard my skin is pale and I just want direction and community
Looked at default nmap scripts?
It's easy, just find guides online and it will help you learn
wym
i just finishd a 3hours nmap course
Go do some challenges that involve nmap
Where do you find these resources?
N m a p s c i p t s
That is what I mean
You asked for deeper knowlage, and I asked if you looked at default scripts
there is some rooms about nmap in THM?
3 hours?
If you dont know that nmap have a -script you did not look at it that deep
not really but it involves using nmap, @charred cave
ah ... no, i didn't
i used --script vuln couple time
that's it
then you used scripts
you must be green flag too
youtube
@narrow yew I need some discipline, Sir Math!
nice, i'm gonna come back to THM.. i miss it
i finished some rooms before
i even forget the account email and pwd
Yeah it's pretty interesting, some of these challenges are not so easy but you'll learn through them
@distant robin pg13 version would be
“Discipline me, sir.”
“Teach me a lesson, boss.”
“You’re in charge now.”
“Guess I deserve a little punishment.”
“Be gentle, but firm.”
Any suggestions of who to look at? I’m really keen to learn
i will.. i found it really fun and informative
Better? @narrow yew
@devout gulch Nahamsec.
Yeah me too, I enjoyed some of those challenges.
start with networking ig
get better in networking, it's the most important part i think
networkchuck
david bombal
are my favs
@charred cave build a homelab if you want to learn networking
buy some crap managed switches
Homelabing is fun
i have some routers and switches laying around lol
and an old desktop, i remember turning it into a NAS
installed ubuntu server on it
there are a ton of people selling Cisco cert home labs when they are done with certs
It's a good project
Thanks that helps! I have a network but just learning how it actually works now
There are also tools for setting up virtual network clusters
oh yeah i remeber
it was nextcloud
an old desktop running ubuntu server have nextcloud installed connected to my router via cable
just wanted to try it out, then i unplugged it
i think it still have ubuntu server
I have a laptop under a sofa running Jellyfin and Syncthing
Wazuh too, but I still need to configure that
There is a room abt nmap
that's fun
nice,i will do it
i have to make an account
i forget the credintials of the old acc
That's just an uncensored ai with extra knowledge abt pentesting

Or build on the existing once?
you have some work too do before you pass HexStrike
btw it's obvious that pentesters will train it to be more effectively on common problems happening during it
Just request a password reset if you still have the same email ?
i made more than one account
i will make a password reset of one of those emails
lemme try
brb
It doesn't work that way u don't train ai to do pentests he means he wants to make an agentic ai to do the pentests for him
nice it's free too
that's cool
i will finish it today
You in Japan?
Nah u don't have to. take ur time take ur notes study well enjoy ur experience
thanks i will i have a paper and a pen i will take some notes if needed
Gave +1 Rep to @blissful frost (current: #577 - 12)
Alr have a great day
Interesting pfp 🤔
LMFAOAOAOAO
🔥
It's first time for me using a srs pfp It's usually a meme or smth
😂
I mean its intentionally stereotypical, so also kind of meme
hey guys im new i want to join cyber security i wanna try do some practice in tryhackme is anybody here who want help me? I have a few questions
welcome. you can just ask your questions here
oh right. can you give me some tips that can i use at tryhackme. I mean i am in tryhack me 7 day in a row and i do some rooms with full of theory but i want to do practice. But even easy task makes me feel that its not for me. So i know that i have to know much basics of theory but i ve done some rooms and i cant do one easy task? What you recomend me to do in my situation
What r u typing mate
cooking hah
try out some of the easy challenge rooms
should get you cooking into not having tons of theory
I’m also new to this field and not used to discord but it’s hard to know where to start
if you want a recommendation shadow can give you this list:
corridor
overpass series
agent sudo
pickle rick
First of all always take notes
Then try to maintain a streak to make sure u have a suitable learning journey
Third always practise
4th search for what u want before asking people
5th make sure to have computer science information before starting with tryhackme
Also try to access tryhackme with subdomain fo admin to get free premium subscription
Free premium is available? I hit a wall when I needed to pay…
corridor is not for the weak hearted
not really... but you can continue with all the free rooms that you can find and do... if you are lucky in december there will be chances to win a subscription for a bit
advent of cyber my beloved
Thanks, happy to send my money as the courses seemed very good but yeh still early stages for me and paying google for a course
I want to try Red teaming what rooms do you recommend for me ( ofc the easiest one but I would rather try practise because i ve done several room of theory)
the perfect syncing of shaking making him not spill a drop is so nice
It's a bad idea to choose rn
Try to at least finish cyber 101 then choose
What’s cyber 101 and where do I learn? Hacking is obviously an interesting field but I know next to nothing. I’d rather learn the basics of the field
Start with learning CS at first
I do cyber security 101 but when it comes to do a linux part 2 it showed up that i have to pay for it bruh
U don't rly know if ur interested in cybersecurity unless u learn CS
some rooms are free. some require a subscription
I’m so green CS is cybersecurity right
Skip it and view a tutorial online for it or just pay subscription it's worth it
No CS is computer science
computers -> networks -> security
Ok, thanks, but where do I start? I’m wanting to learn
My personal path was
Computers - programming - networks - OS - Security
Search
We all started from no where just searching
Also change ur fyp to computer science topics u will learn lots of sub info in between
Yeh it’s broad I get it, thanks though. CS like bios and scripts? I know some buzz words
What is it called when you want to hack a phone number
Like let’s say there’s an unknown number linked to your Apple ID and you need to find out what that number is
There r lots of attacks that can happen on phone numbers (siem card)
cant you just log in to your apple id and check what number is associated?
Hmmm why is the question
He obviously knows that but whose phone number does he want 
My MacBook has been on activation lock for years now. Because someone stole my sister’s phone
it's called illegal 🤣
contact apple support
Stole ur sisters phone?
The one linked to my account. Idk whose it is. It seems professional or something
Someone stole my sisters phone but the phone number that it’s linked to seems like it’s American. We are not American. When we saw the 2 devices that were linked to my MacBook, it was my sister’s lost phone and this other iMac with a professional sounding name
IS THM struggling right now?
aren't we all my friend?
contact apple support
okay but except a more tutorials it will help me learn faster?
Just seems to be running really slow and throwing an error when i try to answer questions
Yep i been getting errors all day
They aren’t helping until I show proof of purchase but we bought my Mac from a retailer in 2021. He claims he doesn’t have the receipt anymore
Which is dumb
what kind of phone is it?
It was an iPhone 13
@blissful frost gotcha, glad it's not just me than in a way
Any info is useful
They are refusing to do anything until I show proof of purchase. It’s frustrating
yes, sometimes the answers I give it can take up to 20 seconds to process
Everything is struggling these days.
First AWS, now Azure DevOps.
@topaz topazare u from Greece?
Oof, last thing i need after 14 hours of work is to have a slow THM session lol fml
I was last min on losing my streak and I kept spamming the submit question button and getting errors till it worked

you're good at OSINT
if they cant help you, we cant either
You can if you tell me the name of the technique that’s used to find out numbers
what do you mean by "find out numbers" ?
Then show proof of purchase it's obv they won't help u lock a phone without proof it's urs
this is not legal, please stop asking for this type of advice
Like a phone number
he's great, he has eyes and the ability to click 🤣
Just a general question if someone knows the answer or is from TryHackMe Support team here: Planning to get the SLA1 Certification voucher (I am assuming validity is 12 months), my question is, I am currently subscribed to TryHackMe, will my membership be extended by 3 months?
if you don't have receipt confirm with your bank if they had the purchase or retailer
No. They want proof of purchase for the MacBook. The retailer doesn’t have the receipt anymore which is weird asf
That's a great foundation
retailers are mandated to keep records for x number of years
It’s been 4 years. He claims he doesn’t have it
yes afaik
They won't have it 4ever
Has anyone purchased the Exam Vouchers and actually witnessed it?
get that in writing, but trying to perform an attack on someone without prior approval is illegal. Speak to apple and inform them if the issue with the information in writing and ask them if there's any other way to prove your identity.
guys anyone got a good website for generating deface?
Im not attacking anyone. I’m attacking myself tbh
not quite. youd be hacking apple
I’m green af and can see that’s phishy
Fr?
realistically nothing is unhackable
yes. apple owns your accounts, you just use them
Is there at least a thing that can allow me to try all possible passwords for something
for what password?
My Mac password

Seems like cracking is about deciding hashs
No one will tell you how to perform illegal activities (in this case being brute-forcing)
What’s brute forcing
🤦🏼♂️
lol
https://crossclave.com/one/
so tempted to just buy this right nyaow
If you want to brute force just login to googles quantum computer and let it run
^^^
What??? 💀
here is hoping post quantum encryption algos actually work
quantum will not do much in bruteforce login
you will get blocked if try rute foirce login lol
Ayo guys i have a quick question. I'm aware i should ask this to the support team but i wanna know if you guys have the answers.
My monthly sub is about to expire and I'm planning to change to annual sub but black friday is upcoming.
Should I just wait or can I change my annual plan to the black friday when it comes?
Quantum computers are really strong against asymmetric encryption and that is about it for brute forcing with them.
Brute force wont work if you're locked out
this^^
You'll most likely just get your ass rate-limited.
or you can solve P=NP and then you have all the things
That’s actually informative, I was joking but you all actually know your stuff which is cool. I appreciate learning more
if some have quantum pc, i have hash to crack... pretty please lol
N = 1
P = Whatever you want
lol
Assuming you mean n * p 😛
👉🏼👈🏼 pwetty pwease
Pack it up everyone. Math is solved :p
He wrote a whole book enumerting P = NP?
Damn, what's it go to ? 10,000,000 ?
A sha256 hash would still have 128 bits of security in that conext tho, so you're not gonna break that that easily. :/
there is much more in p=np
i kid
this is 7zip hash =/
Won't really make it easier, but I don't know math well enough to give exact details.
Does 7z use it's own hash function?
This is high concept right? You literally put more esoteric language and I’m lost
yes
If someone have a quantum PC he won't even need to learn cybersecurity he would just learn cryptography and hack the world
Well, in that case a quantum computer may or may not solve your problem as I have no idea how that function works, lel.
You should still be able to see the file names in that encrypted thing tho.
Imagine instead of u walking in 3 diff pathes there r 3 people of u who will walk on those pathes so thay would take × 1/3 the time needed that is quantum computing
Random but is quantum still classed as binary?
SHA-256–based KDF with salt and a high iteration count
But you are first deriving a key from your password, and THAT is the important part.
You are not breaking AES256 even with a quantum computer.
and salt, that you do not know
hey can someone help me out im trying to get into cybersecurity and figured this would be a good place to start. ill explain more in a vc just confused
The 3rd one in the same hour
Me too! Just here to learn
Is this not literally the salt?
What would you even do with this hash if you did not have the salt?
you need whole file. is all one thing
U can't know
ty
Gave +1 Rep to @bronze crescent (current: #1286 - 4)
i've just tried leetcode for the first time ever today and i understood there's level to this shit... https://leetcode.com/problems/two-sum/submissions/1815464294
password = password + salt = hash
how is it possible that there's guys able to get 21 ms on twosum
Password = password + salt + hashing algorithm = secure storing
Yes, but you need the salt to check whether the password you entered is correct.
I wanna try vim just for fun
A salt should always be supplied with the hash value.
yep
just been using nano the past years
If it is not, you would call it a pepper, fun fact.
and if you do not know password and salt... is crap
Anyways, back to topic.
You have a hash from a 7zip.
You should at least be able to see the filenames on the top level of the archive anyways.
Dunno whether that helps.
I’m very green but what is it with this industry coming up with such jk names?
Nope
So every user has his own algorithm for generating salting so they do he same algorithm to add the salting to the password u entered then hash them then compare them
you cant list whats inside ziped file
Also I would expect the salt be part of the password hash you send, because it would make very little sense if it was not there.
Do you have a link to a source that explains how 7z hashes work?
I would like to read up on this.
Seems like an interesting approach.
Ofc give me a second
Ik a good arabic source do u speak arabic?
Alr let me search for smth else
3 hours later..................................................
Is there a gaming channel here?
Thanks, but I am looking specifically for the hash format documentation.
Gave +1 Rep to @lofty pawn (current: #3235 - 1)
Ah, got it.
This is a rly clear ez explanation
@polar spoke can tell way more about 7zip then most of us know.... if he is amount alive ppl
shadow can tell you more about cheese then most of us know
Thank you.
Gave +1 Rep to @blissful frost (current: #534 - 13)
So from what I get from this here, there is no salt at all.
Which does not matter as much in this case, as there is no actual password verfification, but you can only try to decrypt the file and see whether that worked or not.
https://crypto.stackexchange.com/questions/90137/7-zip-encryption-practical-effect-of-lacking-salt
Aka. no rainbow tables, and each decryption attempt will take a considerable amount of time (at least to a computer).
Makes sense.
Anytime ❤️
youngest hacker here?
But if there is no actual password verification, how do people protect zipped folders with passwords?
youngest active member i know of is 14
is this 14yr o still in the server?
You use your password to generate an encryption key and then just directly encrypt the files with AES256.
yes
ayy tag em
no. its up to them if they want to share their age again
bummer
You can actually attempt to decrypt AES with any sort of key as input, but the output will be gibberish or there will be a decryption error.
youngest hacker here?
why do you want to talk with someone young?
So when you input a password, the files are "decrypted" incorrectly, and since the output makes no sense, 7zip knoes that the password was wrong and tells you that.
Yeah that's what I thought. Interesting stuff, thank you.
Gave +1 Rep to @lament tendon (current: #40 - 270)
They might be trying to get someone banned when they respond with a number that is too low for Discord TOS.
what reasons?
Best is to not respond.
ye ik
happened to my old account
nvm you sound real fun
Yeah like how people try to trick people to say numbers like 12, 11 etc as you have to be 13 in order to use Discord.
guys is there a king.txt in the tryhacme koth hard?
o im chilling
is 13 the age?
Yes, per their ToS.
Do not respond to this dudes messages, there is a good chance you will be banned.
HES COOKED
They will edit their message and then report yours.
LOL
Nah
YH EXACTLY LOL
thats ok. mods can see edited and deleted messages
prob not a good idea to even say these numbers in chat, knowing how shit discord's automated moderation is, you guys should prob stop talking about age
discord mods not thm server mods
guys
It will be reported to Discord, not the mods here.
And Discord has been banning people over this message editing stuff in the past.
They don't check the edit history.
Discord stores message content which also applies to message history (edits)
is there a king.txt in tryhackme koth hard?????
Depends on how strong your opponent is.
Just getting into the machine is decently easy.
bro..
They do not check that tho.
last man standing
Let me source you something.
The streets of Discord just got more lethal because there's a new Discord ban exploit that allows you to ban anyone on Discord....
But is there a catch? It this even real? And how does this exploit even work?
Well, unfortunately you can be a complete Discord noob and figure out how to do this. And to make things even worse, I don't even think ...
Watch that.
i was trolling and said i was 10
wdym bro 2025 is recent
got banned
Yeah I've seen that video
It's gonna explain it better then I ever could.
nah MY old account
Wonder whether Discord will actually do anything about this anytime soon, has been an issue for ages.
But now everyone knows about it, which is a bit of a problem.
Funny how their Zendesk instance was hacked.
Debatable. I usually am into dark humor, but this specific case causes a ton of harm to random people.
I mean, you saw the video about that as well, I assume.
Someone managed to phish one of their employees into giving their login credentials.
Yea.
this was before the dc data breach
/external employees, out-sourced, don't remember all the details
You can verify with your ID that you are old enough, but then they will store that ticket in Zendesk, get their Zendesk hacked and now your ID is used by some dude to extort Discord and potentially worse.
This whole situation is a massive disaster.
i literally said
no to them before they got leaked
Never give our your ID online to anyone or any service.
If the service requires your real life ID, it is not worth using.
there you have it discords mod watching
Banking is a bit of a different deal, but you can actually physically go there and do the verification face to face, lel.
Even tho, of course, there might be some cases somewhere where sending your stuff digitally cannot be avoided, fair.
Still a bit relevant though, they're not exempt to breaches.
Even though it's unlikely to happen.
They should also not store pictures of your ID after verification.
Discord should not have done that either.
I'm just amazed Discord didn't have other measures in place in the event of a breach.
The measure would have been not storing personal information for longer then required for the purpose that information was collected for.
Which is actually illegal in the EU.
Also MFA, I guess, but that does not secure you against all phishing attacks either.
Don't know what's it like now, but before you could log in to accounts by grabbing tokens and log into it through the console through a specific command.
Probably been patched.
You can still do that because your Discord login is just a session cookie, like you'd have for any other website.
Dunno whether you are still able to change your password just like that anymore tho.
Or your email, both would work fine.
If you have MFA set up it will required a code.
well discord not enforcing their 3rd party support providers data retentions is certainly not a good move
Yeah, and the fact they're trying to hide it lol
Are they?
hiding the databreach does not seem to be happening
Yeah, they didn't give all the correct details.
That pretty much never works, but it usually does not help your reputation if you try to.
https://youtu.be/NnuyT8FgSpA?si=Hk5gL9mZte_AYhWp&t=116 with timestamp.
…and the Discord hacker exposed all of Discord’s security problems. But also told me what will happen to people’s data if Discord doesn't pay…
However, due to the hacker’s delusion, the hacker doesn’t know that he’s about to be the person that makes the Discord predator problem significantly worse. But he’ll preach to me about h...
well that is taking the hackers words over discords words... both are probably missrepresenting the data to some degree
i.e generally both are wrong
Yeah you're right.
If the statements the hacker made in this video are halfway accurate they are not much better then that finish hacker from a few years back.
Slightly unrelated, but I hope you all get experience writing Incident Reports for work because fun, it's that time for me again
Hopefully not, the writing I already do is the most boring part of my job. 
Indeed but having these kind of writeups are critical imho
They are. I am just glad it's someone elses task to write them.
Haha I am the all singing all dancing infosec everything at my org, so all me
as evidenced by this could have been prevented or mitigated earlier if not mishandled by another tech
hey
Yep pretty much literally lol
what does mean subscriber and verified? or how can i get that roles?
subscribe and verify 🤣
There's also a neat documentation search I was about to provide but that works too
youtube channel?
thank u
Gave +1 Rep to @sturdy sequoia (current: #300 - 30)
No. This server is about a website.
Read #start-here, as Shyft recommended.
like premium than?
Subscriber are for people who subscribe to the TryHackMe service
Yes.
All about TryHackMe Discord Server.
thank u for information
Gave +1 Rep to @blazing granite (current: #55 - 191)
so I should have just sent my command lol, oh well
just exhasted from 10 hour day looking into that incident lol
whats the point of doing that bro
At a certain level you get access to some extra channels.
do you want to send embeds, show your rank on the site, and etc on the Discord, you kinda gotta
lets you post pics and gifs here too
I was about to ask you how are you. You read my mind 🤣 😛
channels for what
What are people's opinions about using Triage for malware analysis?
Just talking, and malware research.
Channels for subs and way way down the line, advanced topics
And a more advanced help channel.
ait bro

