#general

1 messages Β· Page 1836 of 1

narrow bronze
#

You people of a foreign country have no brains

jovial cobalt
narrow bronze
modern fox
#

sup

narrow bronze
#

🀣

ivory trench
#

haha yeah...living the dream lol

jovial cobalt
rapid merlin
#

@jovial cobalt you should leave him be he is like 8 years old or someone very insecure

jovial cobalt
rapid merlin
#

Dark is like a wanna be

narrow bronze
#

Bruh

rapid merlin
#

Sorry super hakker god

jovial cobalt
ivory trench
jovial cobalt
jovial cobalt
rapid merlin
#

Pls pls pls add me to your server!!’

#

I’m trying to join for the last 3 day minimum πŸ˜‚

narrow bronze
rapid merlin
#

Send DM

rapid merlin
narrow bronze
rapid merlin
#

I was so burnt out I joined the air force at some point πŸ˜­πŸ˜‚

#

And after leaving mil I became a bartender so I think it’s time to continue IT 🀣

jovial cobalt
#

@ivory trench you gone ?

rapid merlin
supple cloud
#

Hello,Everyone I'm new here
Nice meeting you all. Looking forward to have a mentor
Someone I can I run to for knowledge and guidance.
Thank you 😊

narrow bronze
#

Come personal

jovial cobalt
#

anyone completed threat intelligence for soc room?

toxic galleon
#

Hey everyone, is there a list of the windows machines in THM

dreamy fern
#

.

narrow yew
#

Nananananana

jovial cobalt
polar violet
#

guys I want to connect to wazuh network via openvpn on kali linux but on thm/access it shows breaching_ad on network section and after refreshing nothing changes

polar violet
#

on thm?

#

like machine

jovial cobalt
polar violet
#

because why vm

#

okay

jovial cobalt
jovial cobalt
polar violet
#

I have to download configuration files on tryhackme/access on network section but there is only breaching_ad to choose, it is a room that I had previously connected to

polar violet
#

come pv I will send you scr of it

jovial cobalt
polar violet
#

already sent

jovial cobalt
#

you will get help

static kettle
#

Guys, i just talked with someone who is working in a pentest company and he told me that any cert like ine, tcm, or htb is not qualified. He suggests offense certs, is that true? Please if somone here working in us or specially germany, please reassure me

digital estuary
static kettle
narrow yew
#

aaron do you follow?

unkempt jungle
#

someone know console ethical hacking like games on microsoft edge

half girder
narrow yew
#

You will not find HRs thar know HTB certs or thm or tcm

#

Maybe for security related company's

#

But not for major normal white collar

digital estuary
narrow yew
#

They hardly know english

#

that is whats going in

digital estuary
narrow yew
#

They dub every program on TV to english because there is few that understand it well enough

static kettle
half girder
narrow yew
#

Well you cant just ask that

#

What do you want to do?

digital estuary
half girder
tired wolf
#

finland is less academic, more β€œjust be competent”

boreal scarab
sand trench
#

YAWN

narrow yew
#

Hey lillone

sand trench
static kettle
rapid merlin
#

I am looking at the CPENT (AI) cert... Im pretty sceptical about the AI part and im not sure if i should do it. What do you think? Plan B is GRTP cert.

unkempt jungle
#

someone know something about console ethical hacking

oblique loom
#

Like Homebrew?

unkempt jungle
#

like games on internet agma io agar io ...

oblique loom
#

Ah, thought you meant like, gaming console

unkempt jungle
#

my fault

rapid merlin
dark wolf
#

πŸ‘πŸ»

void halo
#

Hey everyone

#

Whats up

dark wolf
#

BadBois score!!

#

how are you?

void halo
#

Nice and you

#

I just buy 1 year suscription thm

dark wolf
#

Good, it's worth it! Use it wisely!

#

lots of great content

void halo
#

okay thks

dark wolf
#

kinda quiet in here right now

#

usually you can barely read what's going on

rapid merlin
rapid merlin
#

Maybe wait for a discount

#

U never know, u could get a good deal

rapid merlin
dark wolf
rapid merlin
#

pay 2 get 1 NOW

narrow yew
dark wolf
#

sounds like a great deal to me

rapid merlin
#

Yeah kinda unethical w/ context lol

#

I think you should go

dark wolf
#

just ignore him, hes been reported

grim sparrowBOT
#

:hammer: willyfromchat#0 has been banned.

void halo
void halo
#

Lol

inland oyster
#

gm guys

dark wolf
#

gm

#

ga

#

ge

narrow yew
hard ravine
#

I am trying to install John the ripper on my debian(KDE) ,can someone tell me why ||Sudo Apt Intall John|| doesnt work ? what am i doing wrong ?

rapid merlin
sturdy sequoia
#

Missed the s in install

hard ravine
hard ravine
rapid merlin
#

its straighforward and dont have to search for repos

#

alternatively you could add the kali repo to your system and install through that

hard ravine
#

thats clever

#

ty mate

chilly veldt
#

don't add the kali repo

#

please do not make a frankendebian

sturdy sequoia
#

May as well just use kali at that point

rapid merlin
#

make sure to do update -y and upgrade -y if you using kali repo and use the stable repo not the beta xD

hard ravine
rapid merlin
#

same system for life

loud marlin
#

kali is based on debian. but using kali repo on other distro and install kali apps, will for sure, in time crach that os

hard ravine
rapid merlin
#

you kno what ppl did in the past they made C: and D: for windows and separate boot drives for linux

loud marlin
#

for dear love of god. don't add kali repo into any other linux

hard ravine
rapid merlin
#

no dualboot...

hard ravine
rapid merlin
#

github is the most solid option, 100% working

hard ravine
loud marlin
#

install waht exactly?

rapid merlin
#

John

hard ravine
loud marlin
#

why not use normal apt or so to install it

loud marlin
#

then go for github

hard ravine
rapid merlin
#

o.O

loud marlin
#

rty sudo apt-get search john to cehck if there is john there

hard ravine
twin ridgeBOT
#

Gave +1 Rep to @loud marlin (current: #23 - 457)

rapid merlin
#
find / -name john 2>/dev/null
loud marlin
#

no need to complicate that much

round summit
#

Kali has dependencies into debian-testingand the command to upgrade is sudo apt full-upgrade - not just upgrade. Deviating from that is a sure fire way to brick your OS

Also - john is already in the debian repos. They probably didn't update before
https://packages.debian.org/search?keywords=john

sand trench
#

rest in peace mullvad leta

rapid merlin
#

i need help

sand trench
#

you had a good run

rapid merlin
#

im in ftp rn and i want to open flag.txt

#

how do i do that

round summit
rapid merlin
#

i did

#

what now

sand trench
rapid merlin
#

oh okay

round summit
#

then it is on your local machine and can be displayed there normally

rapid merlin
#

i need to dod it locally

#

?

#

thanks

sand trench
#

yeah you do get on the file and it gets saved in the dir you started the ftp console in

#

then you can cat it after exiting

round summit
#

well click the link - it IS in the repos

loud marlin
#

what os you have in first place?

sand trench
#

whats an os???

loud marlin
#

linux' =/

narrow yew
sand trench
#

mmmm cheese

dark wolf
#

Vigorizante says hello to shadow

#

Vigorizante hit 0xF. Vigor wonders how close shadow is

sturdy sequoia
dark wolf
#

well its in her profile tho

sand trench
#

well it happens when shadow sits down and focuses and actually do some stuff on tryhackme instead of slow running like the usual

dark wolf
#

are worth 1k each

sand trench
#

think shadow has already done most of the easy point rooms

#

yuups already did investigating windows 2.0

round summit
narrow yew
sand trench
hard ravine
hard ravine
rapid merlin
#

how could i do that ?

#

how do i find the packet that contains password ?

#

in wireshark

hard ravine
# rapid merlin

theres a file with the encryption key
get that and put it in wireshark and everything will be in plain text and you can see the login credentials

rapid merlin
#

i did put that in

hard ravine
rapid merlin
#

it doesnt find anything. but my text is still encrypted

#

idk what i did wrong but i have choosen the right file

hard ravine
rapid merlin
#

i know what i did wrong

#

i opened the wrong file in wireshark

#

so the key had no purpose

#

since it wasnt made for this file

#

thank you for help

exotic hearth
#

why i cant join to the voice channels?

half girder
sharp citrusBOT
distant robin
#

beep boop beep boop

pine storm
blazing granite
distant robin
sand trench
regal dawn
#

evening

echo sentinel
sturdy sequoia
#

Why does good morning, good day, good afternoon, and good evening, all mean hello. But goodnight means goodbye?

echo sentinel
sturdy sequoia
#

English is weird

sturdy sequoia
#

It's also the only one that's one word

echo sentinel
regal dawn
#

sing me a lullaby twin

blazing granite
silver hornet
#

bellooo

regal dawn
#

everytime when using exploit db 😭

blazing granite
regal dawn
#

since it occurs so often

blazing granite
silver hornet
silver hornet
#

3.10.x

#

3.x.x

regal dawn
twin ridgeBOT
#

Gave +1 Rep to @silver hornet (current: #794 - 8)

solemn galleon
#

Hello I’m new

regal dawn
vestal junco
#

Hey everyone, im new

silver hornet
blazing granite
solemn galleon
#

Can you help me with something

echo sentinel
solemn galleon
#

How do I install Linux

sturdy sequoia
regal dawn
echo sentinel
solemn galleon
#

Bro I think VM

blazing granite
solemn galleon
#

Ok

#

Ty

echo sentinel
#

I really suck at AD breaching kekw

sturdy sequoia
sand trench
fervent cove
#

i sneezed

sand trench
#

and that sentence is just shadow having way to much fun with their word knowledge

vestal junco
#

Q) Hey everyone, need some advice please. When it comes to server security for mobile apps, what cruical security measure are missing from this list?

  1. Throttling API views
  2. Using private storage buckets, signed URLs and CDN for media uploading and fetching
  3. Sanatizing any charfields inputted by users to remove XSS/HTML/script junk from text.
  4. storing secrets in .env, never hardcoded
  5. When using external APIs, restrict keys to specific APIs and also IP or app bundle id
  6. Kill switches incase of emergencys
  7. CORS and CSP limited to server domain
  8. SSL
    9.HTTPS enforcement
  9. CSRF for session theft
  10. Tasks and caching via TLS
sand trench
#

well here shadow is in a deep rabbit hole of untangling things

#

trying to install this on arch linux and going through the code and packages of compiled code to see what is needed

dark wolf
#

I don't like privacy

graceful lagoon
#

hey can someone help me install ryu?

dark wolf
sand trench
dark wolf
sturdy sequoia
blazing granite
sand trench
#

gonna be fun in public places for both of you 2

dark wolf
#

why?

blazing granite
blazing granite
sand trench
#

hahaha

strong fjord
#

Im back with a new corny joke

#

If a hacker joins the military, what would their rank be?

#

A kernel kekw kekw kekw

#

🀑

rapid merlin
#

lol. nice. i would add an emoji reaction, but for some reason, they're disabled.

sand trench
rapid merlin
#

ah, that tracks

#

i'm a sub class citizen lol

#

i suppose i could login to verify, i'm just feeling really lazy...

#

like, super lazy lol

sand trench
# dark wolf I don't like privacy

well here are some points
what makes you think you get to decide if you need privacy or not???
what if your friends and family rely on their data not leaking through you??

rapid merlin
#

actually, i changed my mind. i want to verify, but my old discord is linked to my account. how do i unlink it so I can link this one? +_+

rapid merlin
#

Okay, @grim sparrow please help, thanks.

twin ridgeBOT
#

Gave +1 Rep to @grim sparrow (current: #242 - 39)

sand trench
#

... not sure that works

rapid merlin
#

@mossy river can you please help me resolve an issue with my account? shadow said to contact you. thanks.

twin ridgeBOT
#

Gave +1 Rep to @mossy river (current: #6 - 1834)

sand trench
#

think the bot might not forward message to the moderation team so yeah but jabba will probably deal with it when they are back here

rapid merlin
#

thanks

sand trench
#

and a meep and a moop to the beep boop for the sleepy slooopy sleep sloop

dark wolf
#

night shadow

devout palm
blazing granite
dark wolf
#

Doin good, just chillin. Was grinding till I hit 0xF then brain was gonna explode so just watching heroes

#

you ?

blazing granite
dark wolf
#

You have 10 minutes to make challah bread .. GOOO

strong fjord
#

Would pentesters still be relevant in the next 10 years?

#

Human pentesters

blazing granite
strong fjord
#

Bout to see it myself in 10 years too

blazing granite
#

Humans are always need it to check and supervised the result of the automatization and or ai

#

if not happens what happened a few weeks ago with AWS that a 1/4 of internet went down and took a whole day to realise it and fix a stupid mistake that could be caught if somebody was watching

dark wolf
#

Why do hackers prefer dark mode?

#

Because light attracts bugs. πŸͺ²πŸ’»

strong fjord
dark wolf
#

YES! Learn what you can about AI now

#

that way if your forced to which one day could happen then you are ahead of the tame

#

Don't get left behind

strong fjord
#

my uni's curriculum is really soc heavy. No pentesting at all. When I asked my seniors if, at some point, I would learn pentesting, they said. Uhhhh NMAP!

blazing granite
dark wolf
#

Because I'm not responsible for working on it

strong fjord
#

Supa computa

#

I'm not gonna be surprised if my uni only uses kali

#

soc is still a good path eh?

#

I'm struggling to choose rn lmao

#

I have to write an essay on what I wanna do and I haven't figured it out

blazing granite
strong fjord
#

true

blazing granite
#

nice place to start, but get out of there as soon as you can 🀣

strong fjord
#

why

blazing granite
strong fjord
#

is the environment bad

#

oh right right

blazing granite
#

dealing with people and issues take a toll on you, also that's why customer service jobs suck big time

neon current
#

I am confident that one of the best feelings in the world is getting a streak freeze from completing missions

strong fjord
#

that's like one paid day off right there

blazing granite
blazing granite
strong fjord
#

what are you guys getting for bf

strong fjord
#

I wanna get an rpi 5

blazing granite
#

how old are you?

neon current
#

Why would I ever disclose that?

blazing granite
#

so you wouldn't tell your mother's maid name either πŸ˜‰ 🀣 πŸ˜›

sinful moon
#

lol me in Linux, "I don't wanna enable TRIM on my encrypted drive due to security concerns... but I'm having performance issues... let's just try it and see. Oh, first trim operation was on 890GB of my 1TB drive... fair I needed that"

Just me today, I don't know why I was so suprised. Really I just want encryption at rest and I have much bigger concerns if an advisory is advanced enough to care about where my LUKS headers are and determining what filesystem is in use.

Fair I do have some legitimate concerns of more advanced advisories but reason why security is a tradeoff of the CIA triad, confidentiality, integrity, accessibility. Yeah I was harming my accessibility by being a bit too paranoid

#

If you all aren't familiar with the concepts, if you TRIM an encrypted drive (at least in Linux), you are basically zeroing out the data as well as telling it that it's free to use. This makes these sectors instantly recognizable while still encrypted.

Without TRIM they still appear as pretty randomized encrypted data and no one can really tell without unencrypting what's used and what's free.

#

This is why dm-crypt/LUKS2 encryption setups do not enable TRIM by defualt, it is less secure for it to be enabled.... but the performance overhead of me not doing so was too much

#

I am curious about how Bitlocker and FileVault do this, I'm guessing they just say f-it, and TRIM anyways

#

also lol since someone asked elsewhere, this is very much a laptop, not a desktop

sinful moon
#

I just appreciate that Linux defaults to the more secure option unless you decide otherwise and actually learn about it

rapid merlin
#

haven't heard of TRIM, but I use LUKS with my current setup.

#

don't even really now much about that either other than it's supposed to provide FDE. no idea how it works. i also know that every time i reinstall Debian, it overwrites data over the entire disk to prevent old data from being leaked into the new system.

#

what distro do you run Elizabeth?

sinful moon
#

Arch since 2008. And TRIM is a critical function of SSD garbage collection on freed up sectors on SSDs. Just yeah if you're seeing any kind of performance issues it's likely because TRIM isn't enabled and you haven't disabled waitqueues on your SSD

rapid merlin
#

interesting. gotcha.

sinful moon
#

you can very easily review your flags with sudo cryptsetup luksDump /dev/sdaX | grep Flags, obvs replacing sdaX with your encrypted parition

#

so for me with both performance enhacements that reads as:

Flags:           allow-discards no-read-workqueue no-write-workqueue
#

For all I know other distros may be setting a lot of these by default, where as on Arch I have to learn about them and apply myself which is by far my preference anyways instead of someone deciding for me

rapid merlin
#

hmm, interesting. i just started researching fstrim and how it works.

sinful moon
#

yeah that at least is enabled by default for me, but would not have taken any action against my encryped drive until I allowed it to do so

#

you should be able to manually run an fstrim operation just via systemctl commands. Did for me

#

and can check in journactl

rapid merlin
#

i'm reading the man page for cryptsetup luksDump. I wanna try the command you gave

sinful moon
#

Sounds good, yeah it's just grepping for only a line containing Flags, it shows way more info than that

#

for me with my encrypted partition on /dev/nvme0n1p2 that would simply be sudo cryptsetup luksDump /dev/nvme0n1p2. You can use lsblk to double check which drive

#

Another performance enhancement would be to use 4096 instead of 512 sector size which luksDump would tell you about as well, but that's an entirely different can of worms and requires a reformat if you're on 512

rapid merlin
#

Gotcha. Yeah, I did an lsblk and got my drive info. Would you want to luksDump the crypt drive/device or the one above it?

NAME                  MAJ:MIN RM   SIZE RO TYPE  MOUNTPOINTS
nvme0n1               259:0    0 238.5G  0 disk  
β”œβ”€nvme0n1p1           259:1    0   976M  0 part  /boot/efi
β”œβ”€nvme0n1p2           259:2    0   977M  0 part  /boot
└─nvme0n1p3           259:3    0 236.6G  0 part  
  └─nvme0n1p3_crypt   254:0    0 236.6G  0 crypt 
    β”œβ”€base--vg-root   254:1    0 224.9G  0 lvm   /
    └─base--vg-swap_1 254:2    0  11.6G  0 lvm   [SWAP]
#

I tried it for nvme0n1p3 and got some info back.

#

but i didn't grep it yet, heh

sinful moon
#

whew encrypted swap as well

rapid merlin
#

hahaha yeah, i suppose. Debian does it like that by default

sinful moon
#

fair enough, I'm just using ZRAM

rapid merlin
#

Looks like I don't have any flags set... heh

#
daniel@base:~$ lsblk
NAME                  MAJ:MIN RM   SIZE RO TYPE  MOUNTPOINTS
nvme0n1               259:0    0 238.5G  0 disk  
β”œβ”€nvme0n1p1           259:1    0   976M  0 part  /boot/efi
β”œβ”€nvme0n1p2           259:2    0   977M  0 part  /boot
└─nvme0n1p3           259:3    0 236.6G  0 part  
  └─nvme0n1p3_crypt   254:0    0 236.6G  0 crypt 
    β”œβ”€base--vg-root   254:1    0 224.9G  0 lvm   /
    └─base--vg-swap_1 254:2    0  11.6G  0 lvm   [SWAP]
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3 > ld1.log
daniel@base:~$ less -iN ld1.log 
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3 | grep -i Flags
Flags:           (no flags)
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3_crypt | grep -i Flags
Device /dev/nvme0n1p3_crypt does not exist or access denied.
daniel@base:~$ 
sinful moon
#

Yeah so none of that then, just if you find IO performance to be lacking these two improvements can help tons

rapid merlin
#

gotcha. thanks

sinful moon
#

Yep no problem!

marsh lark
#

yo πŸ™‚

sinful moon
#

Heya c:

rapid merlin
#

heyo

thorny wolf
#

hii im an absolute beginner who wants to start doing this, what should i do first?

sinful moon
rapid merlin
#

haha, called it. frankly, i don't blame you guys. with the amount of people asking, haha

#

man, i want react emojies so bad... but my old discord is linked to my THM so i need to speak with a mod to link my new account...

#

i'm currently.... in the black and white purgatory lol

sturdy sequoia
rapid merlin
#

I @'ed Jabba, per shadow. but nothing yet.

lone sky
#

So it's better to read more books.

sturdy sequoia
#

yes. reading is good

rapid merlin
sturdy sequoia
#

@rough lodge please dont dm or send friend request without asking first

rough lodge
#

My Bad ,,,, 😬

sturdy sequoia
#

you can talk here

sinful moon
#

To be fair it's in the #rules of the server

rough lodge
#

I send u friend req as I'm also almost same old user as u 2017 ,,,,

#

But that account I sold by mistake

rough lodge
sturdy sequoia
rough lodge
sinful moon
#

lol thank you for not adding me as well for such

sturdy sequoia
rough lodge
#

Missed u btw

#

🀣

rough lodge
sinful moon
#

Please don't, we can chat here just fine

rough lodge
acoustic crystal
#

Wassup hackers blobfingerguns

rough lodge
#

Any tips ?

sturdy sequoia
rough lodge
#

How to start ?

sinful moon
sturdy sequoia
rough lodge
#

Lol,,, i just want to hack my clg attendance thing ,,,, to increase my attendance

acoustic crystal
rough lodge
sturdy sequoia
sinful moon
acoustic crystal
acoustic crystal
#

Neh i won't touch it

rough lodge
sinful moon
#

@gusty inlet or @cloud quiver if one of you clould clean that failed attempt above up, that would be lovely

acoustic crystal
#

Bro how can i join these vc cri?

sinful moon
#

You need to verify you account with THM first

sturdy sequoia
sharp citrusBOT
acoustic crystal
#

I see

sinful moon
#

yep lol

marsh lark
#

he should be sleeping tho

sinful moon
#

They don't show up as online

dark wolf
#

arent they all sleeping

marsh lark
dark wolf
#

So what is the best kind of Donut

marsh lark
sturdy sequoia
#

strawberry icing with half sprinkles, simpsons style

dark wolf
#

yumm

marsh lark
acoustic crystal
#

Noice

dark wolf
#

we have places here that make crazy donuts

sturdy sequoia
#

yer there are some crazy donus these days

acoustic crystal
sturdy sequoia
dark wolf
marsh lark
acoustic crystal
long lotus
#

johnsus ...

dark wolf
marsh lark
copper blade
#

πŸ˜‹

#

It looks really good

floral ice
uneven escarp
#

Hey guys , can anyone help me with this connection error while connecting to tryhackme openvpn. No matter what server config I try connecting with it just says --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers. . I tried troubleshooting it by editing the ovpn file adding data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305 but it was of no use.

rapid merlin
uneven escarp
#

yeah

rapid merlin
rapid merlin
#

Which is the closest for u

uneven escarp
#

asia

rapid merlin
#

Which one did u use?

uneven escarp
#

the asia-mumbai one

rapid merlin
uneven escarp
#

yeah

#

same problem with the EU one tho

rapid merlin
#

Wait a minute, ur trying to connect tryhackme to an vm?

#

U should go with india regular 1

boreal orbit
#

holy moly

grim sparrowBOT
#

Done!

lusty hound
#

who want study trade here?
join my lesson plz

cyan coral
#

What trade?

sturdy sequoia
#

what lesson?

rapid merlin
pine bison
#

study trade lmao

#

what even is that

polar mango
#

.

sturdy sequoia
#

Why didn't I learn shell scripting earlier. This is gonna make things so much easier

boreal orbit
#

yup, i found that having powershell documentation at arm's reach was a game changer

tired skiff
#

s

marsh lark
fast siren
#

test

fading perch
#

No human is without flaws.

marsh lark
round summit
# pine bison what even is that

Most often they mean crypto coins, sometimes daytrading.. suprisingly often people think you can let bots do the trading and get rich

pine bison
#

I just finished a skill assessment module on the other platform. That was sweaty

#

slow ass rdp machine

marsh lark
#

happens sooooooooooo often

#

I blame windows

pine bison
#

even scrolling lags. holy. it was so annoying. Couldn't tunnel too. was about to lose my mind on how slow it was

marsh lark
pine bison
#

yes. because you can only access the 3 target host via the foothold which is what you get thru rdp

marsh lark
#

but idk what the network was like, so

#

I need to review AD and do some THM AD rooms lol

#

0day's not online πŸ‘€

pine bison
pine bison
#

htb ad rooms are neat. very realistic scenarios

#

haven't tried any thm AD's.

dusty stone
#

Brothers can you fill my google form and help my university survey?

minor notch
#

gonna need more info than that chief

slow cloud
slow cloud
#

yeah you need to ask one of them

dusty stone
chilly veldt
#

my port forwarding works now happyCat

mossy river
marsh lark
#

hru?

gray sonnet
#

@mossy river mind if I DM?

mossy river
mossy river
marsh lark
mossy river
#

Applying again?

marsh lark
#

idc if I get in this/next year tho

#

luckily, one school that I thought ghosted me that really liked me did not ghost me, and they gave me a reply (or my interviewer I guess) yesterday

#

only two months late kekw

mossy river
#

Are you applying early cause you're young or does it just work differently in SK?

marsh lark
#

I'm reapplying as a 9th grader cuz that gives me better chances 🀣

winged nimbus
mossy river
#

Assuming it's super competitive to get in?

marsh lark
#

around that margin

winged nimbus
marsh lark
#

I mostly grew this past year tho imma be honest

#

my skills anyway

winged nimbus
#

if you put your all into it, you can get in

marsh lark
craggy sun
lone hazel
#

I am really confused in in path Soc Level 1 inside it Soc team internal -- Introduction to phishing thing when I open it it's showing 0 Alert

slow cloud
#

i think it might take a bit for alerts to roll in

hollow cobalt
#

no less than 2 minutes

acoustic crystal
#

cri bro why i am suffering from ctf

sturdy sequoia
acoustic crystal
sturdy sequoia
#

go back and learn the basics again

dark frost
#

A honeypot for tea ?

slow cloud
#

is this related to a THM room?

#

or ctf

mossy river
#

DM me

dark frost
#

Jabba taking every "something for tea"

median vigil
#

I dont get it. I am just starting and having trouble with my first little lab. In the "intro to LAN" I cannot make the flag appear. It does nothing. Now should I try another browser because I did,Chrome" and I couldnt log in probably because I was logged in the brave browser so I logged out and it just errored out in Chrome to sign on. But yeah I cannot get the flag. Can someone help or give me the flag so I can move on?

grim sparrowBOT
#

:hammer: neverstop200#0 has been banned.

regal dawn
#

Be me
Plug your USB into the school pc for a local network security assessment
Get nuked by AV and lose all scripts and files on your USB because your a lil slow in the head

mossy river
#

Doing a local network security assessment on school computers?

regal dawn
#

To see what a attacker could do if he had physical access to one of the school computers

#

Since they are directly connected to the lan

mossy river
#

Too many stories I've heard of the same situation, then people getting into a lot of trouble for pentesting

regal dawn
#

True yeah

sturdy sequoia
#

yer that sounds sketchy

regal dawn
#

Should prob sign a legal doc

sturdy sequoia
#

Apparently there are admins everywhere just letting students do whatever they want on the network

acoustic crystal
sturdy sequoia
#

I don't want to assume age but it also sounds like a lot of those students are teenagers.

pine bison
#

lmfao

#

WRITTEN CONSENT IS A MUST

topaz topaz
#

I've worked in schools and I've also done I.T. , if an admin is questioned about having granted permission to a student to mess with security they won't take the bullet for you, and almost rightfully so

chilly veldt
#

let's gooo, vms HYPERS

#

and we are getting 5 more

pine bison
#

das a lot of vms

chilly veldt
#

it's a company

pine bison
#

377 memory

#

gyatt

slow cloud
#

Nerd Nerdge NERD Actually its 377.14 GIB

acoustic crystal
chilly veldt
acoustic crystal
#

I guess I'm bad in English

#

Sorry

silver hornet
#

my IG reels got cursed

chilly veldt
#

it's a fake company that I built

pine bison
#

who ghost pinged me NotLikeThis

acoustic crystal
#

Hire me please kekw

marsh lark
#

pwease πŸ™‚

slow cloud
round summit
slow cloud
#

thats regular old instagram

silver hornet
#

10s i'll delete

chilly veldt
slow cloud
#

he does look like quagmire kekw

chilly veldt
silver hornet
#

=)))))))

acoustic crystal
marsh lark
round summit
chilly veldt
#

the vm ids?

silver hornet
acoustic crystal
silver hornet
acoustic crystal
slow cloud
#

i love reels tho

round summit
#

Yeah, not grouped, no indication of the host they are running on or the redundancy location

chilly veldt
#

they are grouped, there are indications, it's just not shown in that pic of the summary

round summit
#

had a client last year who had the naming convention "physical machines - roman pantheon, virtual machines - greek pantheon"

marsh lark
acoustic crystal
rose tusk
#

Done now.

rapid merlin
#

my .ovpn is tripping it doesnt connect

fading plinth
#

does anyone have any good resources about ethical hacking websites and web apps

hollow lodge
#

Hii guys
There is a discount or something for the CPTS ??

slow cloud
#

i would ask in the HTB discord

#

ngl

burnt bolt
#

30 Days in, and I am in the sapphire league

twin ridgeBOT
#

βž• Gave the role OSEP to 0xchevalier

marsh lark
#

this is new

radiant bloomBOT
#

@silver hornet Too many emoji too fast β€” please slow down.

silver hornet
#

wow

#

i cannot add more 2 emoji rn

acoustic crystal
silver hornet
marsh lark
dark wolf
#

How does a total noob have a CEH cert?

marsh lark
dark wolf
#

Reddit mr Reddit Ambassador lol

marsh lark
dark wolf
#

I use old style

marsh lark
solid belfry
#

anyone having problem with split view for the machine it seems to get ip but icant acces it ?

dark wolf
#

never switching to new

long lotus
#

Has anyone here studied binary trees?...

long lotus
marsh lark
dark wolf
#

I prefer spanning trees, they require less water

long lotus
marsh lark
#

it really depends on what specifically you are using binary trees for

dark wolf
#

Unlike Binary Tree, Spanning Tree has it's own protocol

long lotus
#

I'm going to have a test on this this Wednesday.

#

I'm not putting much faith in this matter.

marsh lark
#

idk how that works lol

long lotus
long lotus
#

idk

rapid merlin
#

Is CTF better then normal rooms?

#

skill based etc, the rooms have too much text

dark wolf
marsh lark
#

normal (walkthrough) rooms are for learning, challenge/CTF rooms are for testing your skills or just doing it for fun

rapid merlin
#

i think room have too much information you forget afterwards, hands on gets you further

molten tartan
#

I think if you have no prior experience youd be lost without the walkthrough rooms no?

#

I dont think youd be able to solve a ctf without having experience in the field

rapid merlin
#

that's the point, finding out what works and not, researching

marsh lark
#

when including challenge rooms

#

you SHOULD learn and get hands on

pallid lotus
molten tartan
marsh lark
#

but, I would argue that THM challenges are quite different. you'd be going in and trying out the challenge, you might learn a thing or two, but its not like learning AND going hands on

pallid lotus
marsh lark
#

a lot of walkthrough rooms do have learning + hands on

marsh lark
#

what works on what, etc., etc.

#

but you need first learn, then try challenge rooms imo

pallid lotus
#

Hacking is 90% mindset. Arguably being handheld through walkthroughs actually has the potential to make you a worse hacker because they don't encourage you to develop that research mindset for yourself.

#

And I say that having written a lot of the early walkthrough content on THM.

rapid merlin
#

i agree, though i think you'd atleast need some kind of base to feel confident enough to dig deeper for your self

fading onyx
marsh lark
pallid lotus
fading onyx
#

Is it me or the advent calendar email is broken?

marsh lark
#

If you forget stuff, thats normal. but it might also be a sign you aren't writing notes

smoky ravine
pallid lotus
fading onyx
twin ridgeBOT
#

Gave +1 Rep to @smoky ravine (current: #3252 - 1)

marsh lark
# rapid merlin i think room have too much information you forget afterwards, hands on gets you ...

Make sure to write notes. Good notes are:
#1: Not too long but not too short
#2: Organized in a way you can quickly find the stuff you need
#3. Useable for the future
#4: Based on the techniques, tactics, procedures, and tools you learned

This also means that when writing a note, you shouldn't name it by the room you are doing. You won't remember which room taught you specifically what you are trying to find. I've heard from experts to use the MITRE ATT&CK Framework as a reference, but since you are a beginner, I would just organize your notes in a way you can find the stuff you need.
@pallid lotus let me know if this is bad advice 🀣

pallid lotus
#

Yeah, I wouldn't necessarily tie it to an existing framework. Definitely don't tie your notes to specific training content.
Organise them in a way that makes sense to you. Take exactly as many as you need, and don't just copy/paste.

marsh lark
#

writing down in notes for the future

molten tartan
marsh lark
ivory trench
marsh lark
#

@mossy river there will be an advent of cyber this year, right?

dark wolf
#

oops

#

I didn't know what else to call the note

fading onyx
fading onyx
lavish rune
#

not sure if ill be made fun off but as a young person into programming and cybersecurity, most of the time i rely heavily on AI to map out future topics to learn/explain them
is ther eanyway to get past this? I fear growing up and practically mfinding ymself only relying on AI cus I got used to it, but at the same time i've had comitting issues with different topics and I dont trust my self judgement

dark wolf
#

So you will have to skip entry level jobs because AI has them, but the only problem with the mid level jobs is that you don't have experience and AI has more expereince doing entry level so it will get the job first!

rustic fable
# cosmic pendant

I think this post is taking a jab at people who use AI to write their code/homework and not people who use AI to explain and learn
? Maybe I'm just a dum dum but sometimes I ask AI for clarification or suggestions

cosmic pendant
#

That's like peopel that ask google questions in general

#

You need to find out how you learn and learn

#

YOU learn, not have someone else explain it

#

Books are your friend, AI isn't

lavish rune
# cosmic pendant

fair enough, but truly are there any recourses or advice I could get? this has been a real struggle for me ever since I got into programming young and has quit multiple times over

daring nacelle
lavish rune
#

cant tell if im missing the point

marsh lark
#

hru?

cosmic pendant
#

Good, hyd

marsh lark
#

doing school work, coding, cyber, AI stuff now, applying to high school again

rustic fable
cosmic pendant
#

AI is great for experts

#

It's a great tool for me.

#

If you're here trying to learn, it can be a great tool, but it's very very dangerous and it pulls you into using it wrong

#

If you need to learn about python libs for doing something

#

Great use case

#

Trying to use it to learn the core of Python, okay~ish.

#

But that doesn't mean you learn how to program

#

Data structures, algos

#

Searching, sorting

green schooner
#

Where should this button should redirect? Because it seems like it's not working.

cosmic pendant
#

it isn't dec 1st?

green schooner
#

nope

rustic fable
#

Idk if that's bad

marsh lark
rustic fable
#

It feels harmless to me at least

gloomy summit
sand trench
sand trench
#

and calendar ordered :D

#

here is hoping it arrives before december the first

rapid merlin
dark wolf
sand trench
#

but chocolates are expensive

dark wolf
#

Free for all 0XF and above then

sand trench
#

free for all the room testers :P

dark wolf
#

hahah yeah that too πŸ™‚ you should get points for room testing!

sand trench
dark wolf
#

Fair enough

narrow bronze
#

Hy

#

Bruh

dark wolf
#

yes?

narrow bronze
#

Your name

chilly veldt
cobalt sail
#

can i link my tryhackme account here?

sand trench
cobalt sail
#

how

sharp citrusBOT
chilly veldt
#

like that^

cobalt sail
#

ths

#

thx

sand trench
#

the mention part of that command is so hard to use without doing things wrong D:

cobalt sail
#

done

chilly veldt
#

have you seen the new discord feature shadow

sand trench
#

the one that lets you choose font for name?? yes

chilly veldt
#

just write a persons nickname and press tab to tag them

#

so if I write shadow and press tab, it'll tag you

sand trench
chilly veldt
#

it's on the desktop client on windows πŸ˜›

sand trench
#

shadow only on arch linux D:

chilly veldt
#

I know, it needs to be added to the repo

rugged valley
#

anyone wanna here need a team mate?

shrewd stag
#

πŸ“

dark wolf
#

What's with the new bot @radiant bloom

dark wolf
rapid merlin
#

Hii

dark wolf
#

Hi Gergely, how ar eyou

rapid merlin
#

Fine thx

devout palm
rapid merlin
#

Gotta finish Linux essentials today

dark wolf
#

I love Linux

rapid merlin
#

And maybe windows as well depending on how fast I can get used to obsidian

rapid merlin
#

Substitute it with the word Linux πŸ˜†

chilly veldt
dark wolf
#

I see, did they tell claude to copy yag and make it zeppelin?

#

lol

chilly veldt
#

zeppelin is a public bot πŸ˜„

#

that's a lie, I am sorry, apparently it's invite only

modern fox
#

@glad vortex who are you

sand trench
sand trench
blazing granite
sand trench
#

now the question is why you would want that

#

but someone made it available

jolly abyss
#

can anyone hlep me with which CTF rooms to practice with

#

i have completed then web fundamentals path in tryhackme

glad vortex
void marsh
#

hi

glad vortex
#

Can anyone help me out Epicdrops

eager maple
#

Hey bakas!

neon stratus
#

Morning y'all, do you all know when AoC starts?

#

Have an exam soon so I want to able to participate this year some more

river crag
#

isnt it generally dec 12th or there abouts?

neon stratus
#

Yea, I think you are right

#

Around that time. Thank you

river crag
#

no problem

neon stratus
#

Have my exam in the end of Nov so don't want to miss it

river crag
#

right. good luck

marsh lark
neon stratus
#

Oh yea, I will be good by that time for sure. Thank you!

neon stratus
twin ridgeBOT
#

Gave +1 Rep to @river crag (current: #3252 - 1)

silver hornet
#

sleepy

river crag
#

@neon stratus apologies, I checked 2024 and it did start on the 1st. @marsh lark was right. so maybe its the start of the month

cosmic pendant
#

Advents Calendars are a thing outside THM.

#

...............

modern fox
river crag
#

i presumed they meant the event, not the calendar

glad vortex
#

I have some issue with the app

modern fox
glad vortex
#

Ohh ok what do you mean?

modern fox
cosmic pendant
#

lol

#

"Hey AI what are Rules"

strong fjord
#

Does AoC have prizes?

sand trench
cosmic pendant
#

The real prizes are the things you learn on the way

eager maple
#

How u doin shadow?

eager maple
river crag
#

the real friends are the boxes we pwned along the way. lol

sand trench
chilly veldt
#

it takes a bit to set up 3 vms

eager maple
modern fox
sand trench
#

but time is only 19:44

eager maple
chilly veldt
#

I'm setting up an XDR, over a VPN, it's hell

dark wolf
#

Hmmmm Shadow is +9 hours from Vigor

#

Shadow goes to bed at 2am?

sand trench
radiant bloomBOT
#

@acoustic crystal Too many emoji too fast β€” please slow down.

acoustic crystal
vestal schooner
acoustic crystal
chilly veldt
#

I feel like sleeping, but it's only 8pm

#

And I have my exam to finish

rapid merlin
#

Damn new bot does something special?

devout palm
devout gulch
#

Took a bit of scrolling but found you. Just wanted to say thanks for the real talk. Few days into server mission and trying to document it. You were so right that’s it’s more than one project but it’s been fun. I now have broken it into many projects. I’ve moved from lemonade stand to home brewing, next step is dive bar. What a journey but building up my own little cloud and making plans for each step. And documenting the days has really helped me take in the days achievements. Thanks for holding up the arrow as it’s easy to get lost with goals.

twin ridgeBOT
#

Gave +1 Rep to @grizzled sky (current: #242 - 39)

sand trench
devout palm
#

Mhm, not entirely

sand trench
#

shadow loves them some thunar action for file manager

modern fox
#

@rapid merlin joeangry

#

YOU

radiant bloomBOT
#

@modern fox Too many emoji too fast β€” please slow down.

rapid merlin
#

U wasted my 2 seconds

modern fox
#

..

modern fox
modern fox
rapid merlin
rapid merlin
chilly veldt
#

mobaxterm > putty

narrow yew
#

@dark wolf What room do you suggest today

chilly veldt
# narrow yew kitty.

kitty is a terminal, not an ssh client, sure there's the putty fork called KiTTY, but still, mobaxterm is a more rich and better client

narrow yew
#

Yes yes you are correct,

chilly veldt
#

especially when we talk windows ssh clients

narrow yew
#

Ofc

#

For linux I prefer Tillix

chilly veldt
#

mobaxterm also has built in password management for sessions

narrow yew
#

Tabs give me nightmares

lone pumice
#

does anyone got burp pro i reall need

chilly veldt
#

just buy it?

rapid merlin
lone pumice
#

?

narrow yew
#

It is great

chilly veldt
lone pumice
#

πŸ™

narrow yew
#

Good

rapid merlin
chilly veldt
#

I have to set up wazuh, on 3 different servers, index, server and dashboard

narrow yew
#

I am glad you take the step

#

get it there

lone pumice
#

can i burp pro tho for free?

narrow yew
#

Oh you want illegal burp?

chilly veldt
#

if you get your work to pay for it

narrow yew
#

You figured this was a good place to ask for piracy

narrow yew
rapid merlin
lone pumice
chilly veldt
lone pumice
#

ts guy called sam said he can help me get it back if i get him the promgam

narrow yew
#

That is what you will get

narrow yew
dark frost
#

i am looking for some good source of academic paper related to cybersecurity , any great place to find some ? , i looked mainly in IEEE , you guys have any advice ?

narrow yew
#

Burp suit will not get your windows account back

lone pumice
#

oh so he trying to scam me

narrow yew
lone pumice
#

oh dang

#

ty man

#

u save me

chilly veldt
narrow yew
dark frost
lone pumice
#

do yk sam?

narrow yew
#

I am an adult

#

You need to use proper words

dark frost
#

something related to Defense systeme , like maybe Detection of suspisious activities , of something like that