#general

1 messages · Page 1825 of 1

craggy sun
#

yoo

#

again VPN connection error

rapid merlin
#

Any Wi-fi adapter that supports 5ghz for Wireless Pentesting? can anyone recommend good brand

full apex
#

Hello, how can i uploaded pictures in chats?

sturdy sequoia
sturdy sequoia
craggy sun
rapid merlin
#

Okay thanks I'll search it later, i have 2 wifi adapter tp link usb and atheros but they are only 2.4ghz , that can only penetration old wifi router , most wifi now in 2025 are using 5GHz.

sturdy sequoia
#

really? i still see heaps of 2.4ghz

rapid merlin
#

Yeah i can't see my wifi network using airodumps

#

because its broadcasting 5ghz

#

but my wifi adapter is 2.4ghz onlycri

sturdy sequoia
#

yer fair enough

rapid merlin
#

Try getting dual band

sturdy sequoia
#

i personally use a panda PAU0D

rapid merlin
#

That supports packet injection, monitor mode

rapid merlin
twin ridgeBOT
#

Gave +1 Rep to @frozen hull (current: #236 - 40)

rapid merlin
#

All that shit

rapid merlin
full apex
celest ocean
#

otherwise you can launch the 'attackbox' as they call it, and it'll already be within tryhackme's network

sturdy sequoia
craggy sun
twin ridgeBOT
#

Gave +1 Rep to @sturdy sequoia (current: #280 - 33)

sharp niche
narrow bronze
#

Helo takashi

#

Helo lemons

#

Helo aaron

#

Hello alll

neat kindle
#

let us address the elephant in the room

steel aspen
#

I switched VPN servers to the server geographically closer to me but it is coming up with the cipher error when I try to connect to it

mint inlet
#

windows security just removed my page i wrote lessons just because i wrote an example of a php reverse shell..

sharp igloo
#

Good day guys

sharp igloo
sleek hare
#

I literally disable it now when I'm doing challanges etc

#

It always blocks reverse shells etc

#

Even tho I do them in wsl

#

(i open browser thru wsl)

sharp igloo
sleek hare
#

That's what I do

#

Not best solution

sharp igloo
sleek hare
#

As I said

#

Not best solution

#

But works

sharp igloo
sleek hare
#

And then someone compromised that folder

#

What are you going to do?

sharp igloo
#

You said to completely disable defender

sleek hare
#

Yes

#

For 10-30 minutes

#

I use eset not defender

sharp igloo
#

That is strictly worse

sleek hare
#

After you enable it usually prompts scan of pc

#

And got life-threat detection

#

Even if you disabled it

#

So if something would try to do some shit it might still caught it

#

¯\_(ツ)_/¯

sharp igloo
#

You can obviously remove and add the exclusion dynamically

sleek hare
#

U got compromised in that 10 min timeframe

#

Lets say trojan

#

But after 10 mins

#

Usually lower lets say

#

It will demolish that trojan

#

¯\_(ツ)_/¯

#

My solutions sucks but they work for me

sharp igloo
#

I'm not even talking about your solution being terrible

sleek hare
#

And so far I never got malware or sum

#

So it's objectively ok if you know how to use internet

sharp igloo
#

Just saying there is also the exclusion option

sleek hare
#

Exclusion option is a thing

#

But sometimes you need to fully disable everything

sharp igloo
#

Ok

steel aspen
#

what does the expecting certificate mean on the openvpn file error?

#

Everything online just says download closest to you but I've done that and the same issue happens

narrow bronze
#

Helo

#

Kha

topaz topaz
#

Hope everyone has a nice Sunday

sick lance
sleek hare
#

I use wsl under my machine (laptop)

#

Or I use VM under my hosting company

#

Depends on how I feel

sick lance
steel aspen
#

Why does my ovpn file have no base64 in the certificate?

sleek hare
#

About my hsoting server I'm using VM

#

Virtual Machine

#

If it gets compromised idfc I can delete and make new one

#

WSL if not wrong is also sorta VM

sick lance
#

Crazy to think you're creating an access point, but you do you I guess.

sleek hare
#

Idrc about laptop

sick lance
#

Yeah. I'm thinking wider...

sleek hare
#

And on server all VM are isolated from each other

#

And from local network

#

Idrc about being compromised on VM or laptop

#

I'd care if my server root get compromised

#

Nothing more

sick lance
#

kek!

vapid geode
sleek hare
#

Fair

#

Idrc then

#
  • I'm doing this for years now
#

And I have never been compromised thru that ways

vapid geode
#

It's just a compatability layer

sleek hare
#

Fair

vapid geode
#

I fk with my VM all the time.

sleek hare
steel aspen
#

I'm about to give up on this website

sick lance
#

You said WSL.

sleek hare
#

Assumingly that you think about wsl 2

#

As it is latest

sick lance
#

WSL2 is a VM.

sleek hare
#

Yeah see

#

I'm using wsl 2

sick lance
#

Well, you never stated that...

sleek hare
#

Well I never stated wsl 1 either

sick lance
#

WSL if not wrong is also sorta VM (edited)Sunday, 2 November 2025 11:25
Reply
Forward
More

sleek hare
#

I didn't say wsl 1 either

#

I just said WSL

storm sierra
#

bro that new asia server on attack box is a life changer ;-;

sleek hare
#

Anyways I'll go

sick lance
#

Probably a good idea to specify, avoids confusion.

sleek hare
#

Bai welchromb

mint inlet
sleek hare
#

@storm sierra Why sre you adding me?

sick lance
sleek hare
#

Animevs_girl_cute_lilyhehe should have assumed

sick lance
#

Not at all.

#

Not everybody runs the latest software for other reasons.

sleek hare
#

Alright

#

I run always latest software

#

Sometimes even if its not stable

#

I'd rather patch it on my own than use old one

sleek hare
#

Same as I do right now with my hosting control panel

sleek hare
sick lance
tired wolf
sick lance
#

You'd be surprised the amount of stupidity people make with their choices. 😄

steel aspen
#

Can anyone help with this openvpn thing? I've tried almost every server same thing, doesn't load in the certificate properly

sick lance
tired wolf
#

i wouldnt be creating an acccess point from debugging with x64

#

lmao

storm sierra
sleek hare
sleek hare
#

Who had account in my server with admin

#

Well my server got hacked

#

Cuz my friends acc got hacked

#

The only time I got hacked

#

And it is handled right now with police

#

Before that I was never hacked

#

Hackers don't target 15y olds that often

#
  • if you have brains you won't get hacked most of the time
#

Unlike my friend who had no brains and gave access to root to some random who later on broke into his acc and got into acc of another friend with sys admin on server

fiery leaf
#

lessons

narrow bronze
narrow bronze
vapid geode
#

Just use google..

dark mason
#

Hi chat

chilly veldt
#

sup sup

mellow widget
#

Hey everyone I have an question

chilly veldt
#

we have the answer

mellow widget
#

I want to sell my tools online and want to get the payments in crypto

#

which platform can I use?

frail ermine
#

@steel aspen delete all files, download one with best server for u, connect via openvpn urfile.ovpn

then check browser 10.10.10.10 if u are connected

chilly veldt
#

depends on the tools

mellow widget
#

I want to sell the basic tools made in python

#

like open ports scanner

#

SIEM tool

#

and banner grabber

chilly veldt
#

you sure you can get paid for that?

sturdy sequoia
#

Is there a market for that stuff?

dark mason
mellow widget
#

want to try that thing

dark mason
#

Or how I like to call it

sturdy sequoia
frail ermine
#

@mellow widget make ur own website and promote it

dark mason
#

The skiddy market

chilly veldt
#

usually people just code their own

sturdy sequoia
#

Or use one of the many free ones that already exist

mellow widget
chilly veldt
#

the only tools that sell are tools that no-one has thought of before and/or take months to develop

frail ermine
#

there are plenty ways to have ur own free website online

chilly veldt
#

not the basic stuff

mellow widget
#

but I dont want to invest money to promote it

hallow jolt
#

hey guys

#

where would you guys start with more advanced network skills?

#

should i try cisco networking certi?

onyx timber
#

Hey guys I am new to discord I wanna know how to create a malware or where I can learn to create a malware for education purpose

sturdy sequoia
onyx timber
rapid merlin
#

I'm also learning malware analysis

sturdy sequoia
#

C is probably useful too

mellow widget
#

but I want to get money alsoi

onyx timber
chilly veldt
#

malware talk is in advanced channels only btw

sharp citrusBOT
rapid merlin
#

I used ada , lolbas project and many fun powershell command

#

etc

onyx timber
twin ridgeBOT
#

Gave +1 Rep to @kind thunder (current: #683 - 10)

onyx timber
rapid merlin
mellow widget
#

so how can i earn the money

thick vortex
#

morning chat

mellow widget
#

I am under 18

chilly veldt
#

you can work while under 18

cold jungle
#

Hii Bella been a while

rapid merlin
cold jungle
#

Happy Halloween 🎃

chilly veldt
#

it's november

onyx timber
mellow widget
sturdy sequoia
#

in my country you can get a job at 15

onyx timber
sturdy sequoia
zenith heath
#

Anyone interested in pentesting

onyx timber
#

Ahhhh

sturdy sequoia
echo sentinel
chilly veldt
rapid merlin
onyx timber
#

Does anybody know about Cyber security events both virtual and physical

zenith heath
sturdy sequoia
rapid merlin
onyx timber
echo sentinel
thick vortex
#

just got a random 20% exp bonus for 3 hours.

sturdy sequoia
onyx timber
zenith heath
#

I wanna send dm to someone coz I wanna communicate about it

sturdy sequoia
onyx timber
thick vortex
rapid merlin
zenith heath
onyx timber
sturdy sequoia
zenith heath
rapid merlin
sturdy sequoia
# zenith heath Ok

There are plenty of channels and thousands of people here. You really don't need to dm

rapid merlin
#

@onyx timber Don't send friend request without permission

onyx timber
#

I will

rapid merlin
#

I'll ignore

onyx timber
#

Good girl

rapid merlin
#

I know

onyx timber
#

Good girl

sturdy sequoia
#

Haha. Got auto muted

distant robin
#

I knew something was off about that guy

rapid merlin
#

Don't add me I'm introvert person

distant robin
rapid merlin
#

I'm crazy in chat but I'm quiet in person haha

sturdy sequoia
#

Give someone a mask and they'll show their true face

distant robin
#

Lol Professor tried to send me a DM and I blocked him. Is he really that stupid?

mellow widget
#

how can I promote my github repository online? without money

rapid merlin
#

I just literally ignore two button accept and ignore haha

lethal niche
#

i have made a ctf team anyone want to join dm me team name is c443

thick vortex
#

Don't know what I'm doing wrong with the Linux attack box, but it never seems to work right.

frail ermine
mellow widget
#

whats this?

distant robin
thick vortex
# distant robin what's the issue?

i probably need to practice the basic functions more. Navigating to the right menu, etc. Just says file not found even though i think ive done the steps right.

thick vortex
#

its just not my main OS.

#

im looking at a walkthrough and it works for the walkthrough writer, entered the same info, so i dont get why its not working.

tired wolf
#

which room

#

and what command

thick vortex
#

digitalforensicsfundamentals I'm on the practical of this atm

distant robin
plush needle
pallid lotus
#

... And that helps how?

distant robin
marsh lark
lethal niche
#

donut do you want join my ctf team

marsh lark
plush needle
#

Let's not overdo it with randomly posting github repos/profiles in here please 😄

lethal niche
pallid lotus
plush needle
thick vortex
twin ridgeBOT
#

Gave +1 Rep to @distant robin (current: #966 - 6)

distant robin
marsh lark
#

I have no idea what it means tho (probably for the best)

pallid lotus
marsh lark
distant robin
#

hi Muiri

pallid lotus
thick vortex
#

oh i like how Echo talks about how you did in a room.

marsh lark
#

I don't even know what the username means

distant robin
#

@thick vortex I use linux mint cinnamon and I've been using linux on and off over the last 10 years so it's taken me some time to learn most of it.

pallid lotus
marsh lark
#

ah

#

I did not know that lol

hexed lintel
#

Guys I rlly needa learn but which course is to try DDOS a website on tryhack me

sturdy sequoia
thick vortex
marsh lark
hexed lintel
#

Oh

pallid lotus
hexed lintel
#

Idk

distant robin
#

@plush needle thank you

twin ridgeBOT
#

Gave +1 Rep to @plush needle (current: #5 - 1911)

sturdy sequoia
#

how does ddos test https? what does that even mean?

hexed lintel
#

Idfk

pallid lotus
hexed lintel
#

I'm lacking knowledge

boreal orbit
#

give me the keys to your botnet

pallid lotus
#

Clearly. So why are you wanting to DDoS stuff?

distant robin
vapid geode
hexed lintel
#

Actually not DDOS specific I think I'm tryna say website security

#

Cuz ppl say they can hack my website by ddos

pallid lotus
#

They can't

#

Problem solved

hexed lintel
#

But isn't there https

vapid geode
hexed lintel
#

Guys is maleware bytes good

pallid lotus
vapid geode
#

just cuz you press F12, that does not mean you're a hacker

hexed lintel
#

Btw

pallid lotus
sturdy sequoia
#

but yes. there are lots of thm rooms that deal with web security

vapid geode
zenith heath
#

When I am learning in my path at THM every course in the middle it says to get a paid plan is there any learning paths for free

sharp citrusBOT
pallid lotus
marsh lark
#

ignore that

loud marlin
marsh lark
pallid lotus
rapid merlin
#

As we are talking about web security, can anyone share any roadmap for web security. I was focused on blue team for now but wanna try my hands in bug bounty and stuff

sturdy sequoia
#

there is a free path on their blog somewhere. donut is trying to find the link im guessing

craggy sun
marsh lark
sturdy sequoia
vapid geode
#

sorry, didn't mean to reply

zenith heath
vapid geode
#

for free

#

and test things on your own

zenith heath
#

In THM

vapid geode
#

via Virtual machine or test websites like webvuln

marsh lark
#

this blog shows a free learning path

sturdy sequoia
#

a path is just a list of rooms in a particular order. you can find all the same free rooms without even following a path

tired wolf
#

portswigger’s webgoat is pretty intuitive

#

if you’d like to give it a go

vapid geode
#

I've never tried webgoat before... but I read that you need to disconnect and hack it offline

#

that's a major red flag to me

tired wolf
#

how come?

tired wolf
rapid merlin
#

If it did I wouldn't have asked it here

#

Experience says a lot more than just names

boreal orbit
#

have you checked the pinned messages in the bug bounty channel ?

rapid merlin
#

I didn't even know about that channel lmao

twin ridgeBOT
#

Gave +1 Rep to @boreal orbit (current: #2128 - 2)

storm sierra
frail ermine
#

@hexed lintel it is possible with php to make a request limit per IP, let's say one IP can make maximum 100 page requests per minute

#

u can even block if the header is missing or user agent, or if ppl use tools like nmap, gobuster etc, it can block the request with PHP

silver hornet
#

beep beep boop boop

tired estuary
#

I'm on cyber security 101 path rn. Metasploit room is very frustrating. Aside from difficulty spike, session always closes when running meterpreter (when running hashdump or migrating)

Apologize for the rant 😆

distant robin
glacial whale
#

hey guys, is there any room similar to burp suite basic that I can practice as a beginner

frail ermine
#

u guys communicating in morse code or what ?

loud marlin
#

yes

frail ermine
glacial whale
twin ridgeBOT
#

Gave +1 Rep to @frail ermine (current: #3242 - 1)

frail ermine
#

w00t i got my first Rep

narrow yew
#

@frail ermine Thanks !

twin ridgeBOT
#

Gave +1 Rep to @frail ermine (current: #2128 - 2)

frail ermine
#

w00t i got 2 now

narrow yew
frail ermine
#

@narrow yew thanks!

twin ridgeBOT
#

Gave +1 Rep to @narrow yew (current: #330 - 25)

frail ermine
#

@glacial whale thanks!

twin ridgeBOT
#

Gave +1 Rep to @glacial whale (current: #3243 - 1)

distant robin
distant robin
#

I'm multilingual

frail ermine
#

😆

distant robin
#

@frail ermine thanks

twin ridgeBOT
#

Gave +1 Rep to @frail ermine (current: #1603 - 3)

distant robin
#

🤣

frail ermine
#

w00t @distant robin thanks!

twin ridgeBOT
#

Gave +1 Rep to @distant robin (current: #867 - 7)

distant robin
#

woot 7 for me

frail ermine
#

buying Reps, 1cent each

distant robin
#

hahaha

frail ermine
#

😆

distant robin
#

just doing a CTF and it's not easy

#

Brains!!!

#

lol good luck, Im in platinium

frail ermine
#

w00t

finite basalt
#

https://youtu.be/GmwaJnj6pfY I've just watched this, the dude can make 100l of liquid nitrogen in a week at his lab, what a project 🤣

👉 To learn for free on Brilliant, go to https://brilliant.org/NileRed/ or scan the QR code onscreen. Brilliant has also given our viewers 20% off an annual premium subscription, which gives you unlimited daily access to everything they have to offer.

For as long as I can remember, I've always been fascinated by liquid nitrogen and I've alway...

▶ Play video
blissful frost
#

Some people claim that they got dosed by rival players in rocket league but when I searched rocket league seemed to stop using p2p connection since 2017 how is that happening or they r just rage quiting

lament tendon
#

Well, depending on how the server structure is set up, DoSing the match server might be possible and apart from that I suspect people might blame their mistake their own poor internet connection for a DoS as well.

#

Prolly the later in most cases.

blissful frost
#

They r just making excuses

lament tendon
#

Or legitimately don't know any better.

blissful frost
rapid merlin
#

at my currrent level

blissful frost
rapid merlin
coarse nexus
#

I can't wait to get to the harder red team rooms. I put myself back into more fundamentals but not really getting much from it.

tired wolf
#

put what you're reading into practice

#

(outside of thm if neccessary)

blissful frost
coarse nexus
#

I honestly have for years that's why I started THM

coarse nexus
blissful frost
#

I am also tryna lesrn reverse engineering-binary exploitation these days

#

So I can get infinite 0 days

coarse nexus
blissful frost
#

C is hard

#

Asf

coarse nexus
#

Yeah dude I'm aware. Not really my cup of tea

#

maybe one day

blissful frost
#

I used python for 3 years
Bash (basics) 2 years
Batch (really basics) 1 year
Java script (experience knowledge i can read and understand and build basic things)
But C is so different

#

Idk what is the point of pointers it's driving my crazy why didn't they do it like python and bash

rapid merlin
#

bru

coarse nexus
#

bro's 1337

blissful frost
#

Nooooo not my ip kekw

rapid merlin
#

i dare him to try me

tired wolf
#

one of the easier languages

tired wolf
#

making memory efficient programs was the only way of ensuring your microwave doesnt explode on itself

echo sentinel
steel hull
#

how to solve Agriweb in the hack the box

coarse nexus
echo sentinel
steel hull
echo sentinel
distant robin
#

aaron, is that you?

zinc pier
#

Hello everyone 👋

lyric bluff
#

Hello everyone how are you ?

thorn pond
lyric bluff
#

🤣

blissful frost
tired wolf
#

and started checking out popular open source C projects

blissful frost
tired wolf
blissful frost
#

I may fucking do anything to be good at C

blissful frost
tired wolf
#

its very dated but only covers the basics so its fine

blissful frost
tired wolf
#

nope

blissful frost
#

I also wanna learn OOP in scripting languages like python the point is I never used OOP except when I was fixing bugs in wifite

tired wolf
#

when learning a new language, you'd want to learn theory in abundance in addition to it's philosophy

cerulean spruce
#

anyone expert with frida-android?

blissful frost
tired wolf
#

philosophy is very relevant

#

take into account Rust

#

memory efficient with borrow checking

sharp igloo
#

Oh hi guys

#

Wish you all a great day

silver hornet
#

bro actually think he a sigma boy fr

lament tendon
blissful frost
#

oh my posh terminal 🔥

#

avg me wasting 15 mins of my life in customizing my terminal instead of actual learning

neat kindle
#

z
z
z

#

🛌

#

mimirrr

#

so eppy

loud marlin
blissful frost
#

but yk what

#

damn u fish terminal i am removing it

loud marlin
#

autocomplete can be set on iirc any terminal

grizzled sky
#

Morning!;

grizzled sky
#

all about the journey so that when you don't arive at your destination you have something to blame;

muted light
grizzled sky
#

ngl one of these days i want to set up a browser in the terminal and then try to spend an entire day only in the terminal;

#

not because it will have any real practical value to my workflow at all but purely just as a way to kill time;

#

i also want the computer to make meows every time i enter a command in the terminal;

echo sentinel
grizzled sky
#

but not just the same meow sound, that would be too obvious, i want to choose between at least 100 different meows and cat noises each time at random;

#

one of the great things about notes is i now have thousands of these impulsive ideas for projects saved with the complete knowledge i probably won't even complete 1/10000 of them;

#

i can be very organized in my knowledge of all the things i could be doing instead of doing something actually likely to help real humans or further my career goals;

#

on the plus side, some day when llms don't suck maybe i can get them to do all the tasks i should be doing so i can spend all the free time that gives me to work on some of these stupid impulse projects;

quartz warren
#

Hey new to cybersecurity here and there’s something I’ve been trying to do bypass the admin password and username any advice?

grizzled sky
lament tendon
#

It's a terminal based browser.

quartz warren
lament tendon
# quartz warren Wdym?

Bypassing logins heavily depends on what technology the login form uses, there is no uniform bypass method.

#

But you might be interested in SQL injection.

#

That's one of the more common methods.

grizzled sky
#

there's also prompt injection;

quartz warren
quartz warren
grizzled sky
#

the new version of sql injection that's a lot easier than sql injection because its literally just telling llms to do certain things and realizing they are very dumb;

lament tendon
grizzled sky
#

no not for that, not unless an llm controls account auth;

lament tendon
grizzled sky
#

just as something cool to learn since companies around the world are inserting llms into the dumbest of places and the bug bounties are huge sometimes;

#

all for just telling a computer to do the wrong thing essentially;

#

though of course most testing can be automated now too;

quartz warren
marsh lark
lament tendon
quartz warren
marsh lark
#

you said you are trying to bypass a password, right?

#

are you trying to bypass on like a website? or

lament tendon
#

That's against server rules.

quartz warren
lament tendon
#

All good.

marsh lark
#

it would probably be unethical and go into illegal grounds in cases, so

#

unless you own the device or smth

grizzled sky
#

oooo cool recon/infosec tool;

robust skiff
#

Will there be an advent of Cyber 2025 on tryhackme?

marsh lark
#

yes

#

from what I know, yes

grizzled sky
#

nice that should help motivate me to get through the last of my blue team work over the winter while i continue job searching;

robust skiff
#

Great!

lament tendon
lament tendon
#

Honestly kinda crazy that Fluff clan still is a thing.

#

They left over a year ago. catlaugh

#

If not longer.

unkempt salmon
#

Am i the only one that lastly got problems with the machines like when i do a gobuster it instant crashes ? It seems like my french friends got the same problem, wanted to know if others too

lament tendon
#

There have been somewhat consistent performance complaints over the past few weeks.

unkempt salmon
#

Yeah okay thanks

abstract mirage
#

gys m stuck in metasploit room task 5 exploit when m using eternal blue and i run it with the set of the hosts (R&L) i got the result of Exploit completed, but no session was created. any help pls

lament tendon
#

Did you set LHOST correctly?

#

And could you share some more of the output in #room-help maybe?

silver hornet
abstract mirage
grizzled sky
eager barn
#

hi

floral ice
#

This is me basically already haha

sand trench
#

thats the route mental outlaw took

distant robin
distant robin
floral ice
#

I've given up on making my stuff look good it's default every thing Lol

stoic olive
#

Hi

#

Can any body help me

#

Why hydra don't work as needed

#

I put the syntax correct

half girder
stoic olive
#

I did this

cosmic pendant
stoic olive
#

What's the problem

half girder
#

remove it

burnt reef
#

use the correct path for the wordlist.

sand trench
#

i.e typo in file path for the wordlist

stoic olive
#

psyDuck thank you

sand trench
#

and also the space that kangafoo found

stoic olive
#

I didn't see this o_o

distant robin
stoic olive
twin ridgeBOT
#

Gave +1 Rep to @distant robin (current: #793 - 8)

half girder
#

@cloud quiver

#

rule 3

distant robin
stoic olive
narrow bronze
#

Hello

#

Hackers

teal river
#

Hey guys I don't want to promote my CTF team but can anyone join pls 🥺? reply to this message for the link

icy flower
#

Hey guys I am new to cybersecurity and am learning the basics from TryHackMe I am currently on module 3 of the introduction to cybersecurity. I booked for the ISC2 CC and was wondering how much I should know or how I could adequately prepare myself for the test.

dense hare
#

are the servers okay I keep getting : Oh no, an error occurred whilst starting your machine. Please try again in a few minutes. / when trying to start a machine...

teal river
#

so good luck @icy flower

icy flower
twin ridgeBOT
#

Gave +1 Rep to @teal river (current: #3243 - 1)

teal river
#

Yep you will get such a good return on it

#

Well Goodbye @icy flower

#

👌

icy flower
tired wolf
#

props to all the north koreans in here

compact fossil
# grizzled sky

me when the cybersecurity certification I got was used to train an AI that would make me obsolete

#

.<

bleak quartz
#

dudes got their interanet or wtv they don't even have access to the actual internet (Excluding a few elite members)

thick vortex
#

Does the tryhackme team ever hire? Curious since i didnt see a careers page on the site.

tired wolf
bleak quartz
tired wolf
#

are some kids randomly selected for a hacking bootcamp

bleak quartz
tired wolf
#

you really reckon a starving country would have the same methods

#

as for example

#

south korea

bleak quartz
#

you really think the elites are starving 😂

tired wolf
#

sure they are

bleak quartz
#

They pick a few ppl who standout into programs

#

I've read about it a bunch

#

They basically live in the base

icy flower
#

everyone in north korea is malnurished that's why there army is much smaller in literal size compared to the u.s or south korea

#

and they also deal with random blackouts because the supreme leader wants to send more missiles into japanese waters

bleak quartz
icy flower
tired wolf
#

96% of imports come from china

thick vortex
twin ridgeBOT
#

Gave +1 Rep to @bleak quartz (current: #98 - 91)

tired wolf
#

exports literally nothing of value

icy flower
tired wolf
#

sanctions

icy flower
tired wolf
#

its an UN sanction

icy flower
#

russia and africa I believe as well

tired wolf
#

i dont know anything beyond that

icy flower
#

Just becuase NATO sanctions someone doesnt mean they have nobody to trade with

narrow bronze
#

Hello hacker

#

Any here

icy flower
tired wolf
#

china is part of the UN

#

nato is irrelevant in this context?

narrow bronze
#

What neyo

rapid merlin
#

When ever I see chat, some fucked up discussion is going on

icy flower
narrow bronze
#

Any here

#

You have bitcoin

rapid merlin
#

Hi everyone

#

Where is the roadmap ?

#

Here

sand trench
unkempt salmon
loud marlin
#

that sounds illegal

#

well... again, it sounds illegal... how about report to police?

dapper dust
loud marlin
#

well... if you have that option, where is my device, active you ca try that.

dapper dust
echo vault
#

Lol really a double edged sword there

dapper dust
ashen cape
#

I am unsure but I think IP won't help here

echo vault
#

Ig ur best bet would be to try to reset ur account i got nun for tracking it down

icy flower
#

reporting a phone stolen to the company should cause the company to deactivate the phone no need to do something criminal

dapper dust
twin ridgeBOT
#

Gave +1 Rep to @icy flower (current: #3243 - 1)

rapid merlin
#

U could login from a different device and change it's passwd

icy flower
rapid merlin
#

Njoy

sand trench
#

sms 2fa is weakest form of 2fa unless you count email 2fa

rapid merlin
pallid lotus
sand trench
rapid merlin
#

People keep emails logged in

#

24x7

pallid lotus
#

Right, okay, so both of those are making big assumptions of prior compromise.

icy flower
#

you could recreate the morris worm

pallid lotus
#

SMS 2FA is weak because it's possible to hijack a phone number.

sand trench
#

email is weak as tons of people fall for phishing emails basically giving access to tons of bad actors

rapid merlin
pallid lotus
#

Email does not share that weakness. Yes, you can compromise someone's email in a wide variety of ways, but those all involve some explicit attack before you can take over the target account. Even if that attack involves stealing an unlocked phone, or kidnapping and torturing them until they give it up.

pallid lotus
icy flower
sand trench
#

fair enoughs

sand trench
#

shadow jumped in to the convo with no persence of what it was about

icy flower
pallid lotus
rapid merlin
pallid lotus
sand trench
#

please muiri link to xkcd when referencing xkcd

pallid lotus
sand trench
pallid lotus
#

Regardless, point is:
SMS can be hijacked without user interaction.
Email is (theoretically) as secure as any other online account. There is no inherent flaw in "email" as a concept which allows you to steal 2FA codes.

Sure, email-based HOTP is not the most secure form of MFA available, but it's also not inherently weak.

#

i.e., if your email account is protected with a strong password and MFA, chances of anyone getting in are slim.

sand trench
#

when did google say they stopped reading emails to do personalised advertising???

#

just a tangent that is not super relevant

pallid lotus
#

I mean, I'd class "insider threat" in roughly the same prerequisite category as social engineering.
Sure, if your email provider has access to your emails then yes, you're trusting them to not steal your MFA codes (or anything else...), but you, as an individual, factoring that into your personal risk register is generally overkill.

sand trench
#

yeah was more referencing it being kinda creepy for automated systems to read all your emails just to serve ads towards you

#

but good point on insider threat when it comes to that

pallid lotus
#

Humans will always find a way to fuck up a good thing.

sand trench
pallid lotus
#

That ain't the next line, but points for trying lmao

sand trench
#

yeah..... but most lines would break the discord rules

pallid lotus
#

What
"have a look around"?

#

In fact, literally the entire first verse is fine kekw

#

And @rose tusk has done way worse on Discord than the second verse

sand trench
lament tendon
#

"Or a bunch of different pencil drawings" does not seem like such a bad line either, idk what you are talking about. iees

lament tendon
hollow rock
#

Yo anyone wanna work on an intermediate level red team project in python hit me up

boreal scarab
#

@sand trench save my Scandinavian ass!

#

The Canadians got me!

pallid lotus
pallid lotus
#

I'd say blobno but it genuinely would be a good idea for me to get out of here.

boreal scarab
#

What does that make them? Korean or American?

icy flower
#

korean-american?

boreal scarab
#

So, that makes me Scandinavian American. Fuck you Muiri! kek

icy flower
#

lol

pallid lotus
# boreal scarab What about Koreans born in the United States?

I mean, what are we talking here. The child of first generation immigrants who is raised in both cultures / speaks both languages, etc?
Korean American.

A child whose Korean ancestry is about 5 generations up, who has never lived in Korea, and who doesn't understand either the culture or the language?
American.

#

In the former case I'd also argue that they are free to choose one, other, or both nationality to identify with. They have roots in both countries.

That is generally speaking not the case for most yanks who claim to be Norwegian/Scottish/English/Irish/French/whatever, though.

icy flower
#

did you just refer to all americans as "yanks"?

mint field
#

Lets get hacking yo

pallid lotus
icy flower
pallid lotus
#

Having said which, it's a common term for Americans (in general) this side of the pond.

icy flower
#

takin a piss on ma face are ya

pallid lotus
#

Ew.
I mean, you do you, but I'll keep out of that tyvm

sturdy sequoia
#

wtf did i just walk into

icy flower
#

dont biritish people always say "takin a piss"?

modern fox
#

wtf is happening

pallid lotus
sturdy sequoia
#

taking the piss

icy flower
#

lmao

pallid lotus
icy flower
#

same thing

pallid lotus
#

It's a figure of speech

bleak quartz
modern fox
pallid lotus
#

It does not involve any literal piss.

icy flower
#

"taking them pisses all over town"

bleak quartz
next sundial
#

Oh my...

bleak quartz
#

What the hell is going on here

#

yeah I'll just go back to studying lmfao

pallid lotus
icy flower
#

making fun of how british people talk

next sundial
#

thats rude

pallid lotus
#

You're really not lmao

next sundial
#

Guy thinks he's going to troll an entire nation.

icy flower
#

lmao

pallid lotus
#

So far all you've done is ask someone to engage in activity I ain't gonna repeat in here, then threaten to urinate on a town.

It's... really got nothing to do with Britain, or any figures of speech in British English 😆

icy flower
pallid lotus
#

I can almost guarantee that no one asked you to do what you asked for lmao

Or, if they did, I question the company you were keeping

sharp citrusBOT
rapid merlin
next sundial
icy flower
icy flower
ripe sleet
icy flower
next sundial
#

Yes is a statement and not a question.

#

You can't ask me "yes".

#

That makes zero sense.

#

Its all adding up now.

pallid lotus
#

"Taking the piss" is the only variant of that phrase. It means essentially to mock someone, or as an accusation, to insinuate that they're having you on.

icy flower
#

did you miss out the part that i've stayed in england?

rapid merlin
pallid lotus
#

Any other variation has more to do with your personal proclivities than anything else 🤣

icy flower
rapid merlin
icy flower
pallid lotus
rapid merlin
sturdy sequoia
#

jfc who cares?

icy flower
sturdy sequoia
#

people here will argue about the most inane tings

pallid lotus
sturdy sequoia
pallid lotus
#

It's dark outside

rapid merlin
pallid lotus
#

Too cold for any of my hobbies which can be done in the dark

#

And too late for any of my hobbies which can be done in the garage.

next sundial
#

True

ripe sleet
next sundial
#

Maybe their hobby is acting like a fool.

next sundial
sharp citrusBOT
willow delta
#

guys

#

is this ctf broken?magician

next sundial
#

I'm off the pc right now.

rapid merlin
next sundial
#

Still watching sakamoto days coolguy

fervent cedar
#

yay, finished cybersecurity 101 right now ❤️

next sundial
#

I never did that, I am working on a web app pentester path on some other platform.

vapid geode
#

Huh... i just watched somebody make a simple backdoor using python and undetected by win11's win defender.....

Bruuuh just how unreliable is win11

fervent cedar
#

Super fun on investigation, crazy amount of tools, even just dipping into is still a long way to go. Most of them you dont even use. Some i already like to use, i started from scratch btw. No Knowledge before

#

But i see why it needs a lot of practice

fervent cedar
#

Well i even wondered, why the function of hiding a powershell function is possible. What should be the reason? Just for a User not see what the Admin is doing?

fervent cedar
# next sundial It depends

True, depends aswell. Was looking what the Market wants to find. The Programs cant be more different, didnt see two companys for nearly looking the same. Always different stuff

next sundial
#

Pardon?

fervent cedar
#

Windows is made for backdoors

willow delta
#

yo guys magician

#

ctf

#

is broken

#

aint letting me uplaod anything

#

not even png files

fervent cedar
#

I mean for Cybersecurity Pentest / Analyse. For German market in my city

mystic falcon
#

holy crap some machine had a picture from desktop (windows 10) bc of VNC on tcp5901 (from shodan)

and it was jst Vegas editing software.. and not even RDP.. it was VNC on windows damn 💀

next sundial
willow delta
#

i have tried everything

next sundial
#

I doubt that you tried everything.

willow delta
#

yh..

#

go ahead and do it

#

its an easy machine

next sundial
#

No, I am watching an anime.

#

I will be doing something else later. You do it and I believe you got this. Start over and try again.

willow delta
#

bro its like i finished the room but not letting me upload my shell

#

i watched yt and write up

#

like i did evetything right

#

its just not letting me upload for some reason

next sundial
#

You have the flag then? @willow delta

willow delta
fervent cedar
#

mostly commong prob, some mistake made in command?

willow delta
#

and im not gonna copy tyhem from write up i wanna know if i am doing something wrong

#

or the machine is broken

next sundial
#

You have to learn the methodology so you should be following the writeup as a guide. You're not cheating.

willow delta
#

i want to get the reverse shell by my self

fervent cedar
#

ofcourse 😄

willow delta
#

the ctf is about ImageTragick

#

it allows you to uplaod png

#

and convert them to jpg

#

i tried to upload normal png

#

did not work

#

then i tried using that CVE for the iamgetragick in msfconsole

#

and it created the reverse shell png i tried to upload

#

but still did not work

#

its not even letting me upload a normal png file..

fervent cedar
#

No Error?

willow delta
#

in writeyps when they upload normal it works when they upload reverse shell it works too..

willow delta
fervent cedar
#

hm

willow delta
#

even tho its a normal png

#

not like .php.png

#

no no .png

#

normal screenshot i just took to test it

next sundial
#

Share the yt video and Ill watch it

fervent cedar
#

Sounds like no access

sharp igloo
#

good morning guys!

fervent cedar
#

i would maybe try to listen if connection refused while uploading or denied with Netcat?!

#

Hey hey

visual wharf
#

chat, do u experience this problem too?

sand trench
visual wharf
#

those should be the default tryhackme attackbox colors tho

sand trench
#

huh

visual wharf
#

it doesnt change from user to user does it, its the same attackbox for every1

sand trench
#

yeah but doubt they changed the colors in that recently so the question is more what made them change that

#

@mossy river should know who to refer to if the problem is reproduceable for bad theme/colorscheme on attackbox

rapid merlin
#

yo

next kelp
#

Trying to decide between doing the security analyst or penetration tester path

rapid merlin
#

but i need to learn cybersecurity 101 first

#

how to get my level in bio ?

fierce blaze
rapid merlin
sand trench
rapid merlin
sharp citrusBOT
rapid merlin
#

thanks. worked

sand trench
#

no problem

#

oh nose the never comming sneeze is here again

sharp igloo
nova horizon
#

I need someone who’s good at hacking to help me please dm

#

it’s getting the loc of a phone number

#

i’ll explain more in dms

sand trench
nova horizon
nova horizon
#

airball 😪

#

i’ll pay

#

double airball

rapid merlin
#

why am i top 5 but cant see myself on leaderboard ?

near hawk
#

When you have the same amount of points you will be tied at that place

rapid merlin
#

thanks

#

how do i get points ?

rose tusk
#

don't insult me with your Scottish bias. I'm in Yorkshire, I'll pop down to you in the next few mins

rapid merlin
#

only from challenges ?

rose tusk