#general
1 messages Β· Page 1836 of 1
you from which country sir?
Uk
sup
π€£
haha yeah...living the dream lol
yo bud
@jovial cobalt you should leave him be he is like 8 years old or someone very insecure
haha cool wyd rn? uni?
ayoo fr hes so clingy tooo
Dark is like a wanna be
Bruh
Sorry super hakker god
ayoo bro haha
A little sarcasm...I'm older, far from college. Are you in cyber?
haha i see yh im currently learning in cyber trying to learn more knowledges
ahm you focusing on red teaming ? cool
Pls pls pls add me to your server!!β
Iβm trying to join for the last 3 day minimum π
Come
Send DM
Yup after several years of break Iβm back and Iβm refreshing my knowledge
coool
Come
I was so burnt out I joined the air force at some point ππ
And after leaving mil I became a bartender so I think itβs time to continue IT π€£
demn
demn your resume kinda cool haha
@ivory trench you gone ?
well then send link
Hello,Everyone I'm new here
Nice meeting you all. Looking forward to have a mentor
Someone I can I run to for knowledge and guidance.
Thank you π
welcome
Come personal
anyone completed threat intelligence for soc room?
Hey everyone, is there a list of the windows machines in THM
.
idk
Nananananana
.
guys I want to connect to wazuh network via openvpn on kali linux but on thm/access it shows breaching_ad on network section and after refreshing nothing changes
try rebooting the vm again
yup
you will get a ip to connect wazuh interface right? try rebooting it maybe it helps
did you check the solution on gpt ?
I have to download configuration files on tryhackme/access on network section but there is only breaching_ad to choose, it is a room that I had previously connected to
not sure
come pv I will send you scr of it
bro im not knowledgable abt it ask in room help section
already sent
you will get help
Guys, i just talked with someone who is working in a pentest company and he told me that any cert like ine, tcm, or htb is not qualified. He suggests offense certs, is that true? Please if somone here working in us or specially germany, please reassure me
Projects + Certs can really make you stand out, offsec certs are really good and pretty sure they're still considered the industry standard
But what about others like htb, etc
aaron do you follow?
someone know console ethical hacking like games on microsoft edge
in germany it mostly matters you studied cyber, certs dont have the same value there as in foreign countries. ive rarely seen companies having any certs in the job description π€·ββοΈ
You will not find HRs thar know HTB certs or thm or tcm
Maybe for security related company's
But not for major normal white collar
jesus christ whats going on in germany?
because 90% of germany is slavic people :trollface:
They dub every program on TV to english because there is few that understand it well enough
Cool i am studying bachelor in cybersecurity and going to do masters, what do i need? If u r living there and familiar with market, plz dm me
actually thats the result of making everything more academic π€·ββοΈ
fair enoughs ππΌ didnt expect germany to be this academic
^ tbf i didnt look into cybersec in germany that much
thats all .. but better have a diploma from a university which will be even accepted.. you can check on the "anabin" database, google for it
finland is less academic, more βjust be competentβ
rather a pain in the ass sometimes ..
YAWN
Hey lillone
No need to be upset, just spheal.
A tribute to https://youtu.be/GJDNkVDGM_s
Song is Happy H Christmas by Maniacs of Noise
Youtube's compression is not great :( here's an endless loop: https://gfycat.com/illinfamousladybug
Are you working already there?
no can do, Inidia is too far away sry
I am looking at the CPENT (AI) cert... Im pretty sceptical about the AI part and im not sure if i should do it. What do you think? Plan B is GRTP cert.
someone know something about console ethical hacking
Like Homebrew?
like games on internet agma io agar io ...
Ah, thought you meant like, gaming console
my fault

okay thks

Black friday is coming
Maybe wait for a discount
U never know, u could get a good deal
more than 30% off?
16 free months
But only get 7
2 years for the price of 3. limited time offer
pay 2 get 1 NOW
All good?
just ignore him, hes been reported
:hammer: willyfromchat#0 has been banned.
Too late....
Lol
gm guys
gf
I am trying to install John the ripper on my debian(KDE) ,can someone tell me why ||Sudo Apt Intall John|| doesnt work ? what am i doing wrong ?
have you tried getting it from github and building localy?
Missed the s in install
Will try now. . . i suppose
π
its straighforward and dont have to search for repos
alternatively you could add the kali repo to your system and install through that
May as well just use kali at that point
make sure to do update -y and upgrade -y if you using kali repo and use the stable repo not the beta xD
Kali is a skinned debian . . . Ive spent lots of time customising my baby
come on have some faith . . .
well you could just copy and paste your config files into a new system and boom you make an install script for your ectensions and apps and done
same system for life
kali is based on debian. but using kali repo on other distro and install kali apps, will for sure, in time crach that os
its not just that though is it , i will have to back up all my files , ive got 2 tb worth of stuff in their
you kno what ppl did in the past they made C: and D: for windows and separate boot drives for linux
for dear love of god. don't add kali repo into any other linux
i dont have windows on this laptop π
no dualboot...
listen mate i am gonna try to install it from github , if it doesnt work . . . IT IZ WHAT IT IZ
github is the most solid option, 100% working
no , hahah i actually use linux on this one
install waht exactly?
John
so i am trynna instal john the ripper but its not working for some reason
why not use normal apt or so to install it
whats the error?
then go for github
thats the thing theres no error
i run Sudo apt install john
it does its thing but when i run commands theres no john . . . tf ?
o.O
rty sudo apt-get search john to cehck if there is john there
will do , Thanks boys
Gave +1 Rep to @loud marlin (current: #23 - 457)
@hard ravine ```apt list --installed | grep john
find / -name john 2>/dev/null
no need to complicate that much
Kali has dependencies into debian-testingand the command to upgrade is sudo apt full-upgrade - not just upgrade. Deviating from that is a sure fire way to brick your OS
Also - john is already in the debian repos. They probably didn't update before
https://packages.debian.org/search?keywords=john
rest in peace mullvad leta
you had a good run
get
ftp does not support that... use get or mget to download the file and then read it after exiting
oh okay
then it is on your local machine and can be displayed there normally
yeah you do get on the file and it gets saved in the dir you started the ftp console in
then you can cat it after exiting
i am pretty sure i did
well click the link - it IS in the repos
what os you have in first place?
whats an os???
linux' =/
ost?
mmmm cheese
Vigorizante says hello to shadow
Vigorizante hit 0xF. Vigor wonders how close shadow is
oh god, not you too
well its in her profile tho
well it happens when shadow sits down and focuses and actually do some stuff on tryhackme instead of slow running like the usual
https://tryhackme.com/room/investigatingwindows2 and the 3.0
are worth 1k each
think shadow has already done most of the easy point rooms
yuups already did investigating windows 2.0
Btw.. shouldn't it say "willing" instead of "will" in your bio?
What hte heck, thousand questions
yeah old ctf room with way to many question meaning tons of points in the past
yeah well i wasnt bothered , went to github yanked the files and compiled it myself and seems to be working fine for now
it was Debian
how could i do that ?
how do i find the packet that contains password ?
in wireshark
theres a file with the encryption key
get that and put it in wireshark and everything will be in plain text and you can see the login credentials
ok then you just need to look it up
Ctrl+F to use the search bar
it doesnt find anything. but my text is still encrypted
idk what i did wrong but i have choosen the right file
if you text is still encrypted then it means it didnt accept the key
did you touch the key ?? if you did you better restart the vm
i know what i did wrong
i opened the wrong file in wireshark
so the key had no purpose
since it wasnt made for this file
thank you for help
why i cant join to the voice channels?
you need to verify first
beep boop beep boop
is it just me or the VM for this room https://tryhackme.com/room/owaspapisecuritytop105w keeps getting disconnected when using rdp?
That's shadow's line
So?

evening
evening, sup?
Why does good morning, good day, good afternoon, and good evening, all mean hello. But goodnight means goodbye?
Cause ppl mostly don't meet up at night
English is weird
you might be onto something here
It's also the only one that's one word
Yes
at least we got the mongolian throat singer in here
sing me a lullaby twin
Yes
It is, but is not the only one π€£
bellooo
everytime when using exploit db π
if it's about a room #room-help
nah i dont need help, i was just posting it cuz of the python3 - python2 difference
since it occurs so often
still Sunday here π€£
python3 exploit.py target_ip
python3 it ur version
3.10.x
3.x.x
i wasnt seeking assistance, i simply posted it cuz of the python3 - python2, thanks tho
Gave +1 Rep to @silver hornet (current: #794 - 8)
Hello Iβm new
welcome to the community π
Hey everyone, im new
dawg, i miss sunday
so if you donΒ΄t need help why you post a screenshot
Can you help me with something
what?
How do I install Linux
Welcome
nevermind then, i was simply posting it cuz of the python version since so many scripts from exploit db only work in python2. I didnt expect these many questions about the image
VM or bare metal?
Bro I think VM
go to a linux discord related or watch a video on youtube, here we aren't Linux tech support
I really suck at AD breaching kekw
The website for the distribution probably tells you how to do it too
the weird wired wreath writhe
i sneezed
and that sentence is just shadow having way to much fun with their word knowledge
Q) Hey everyone, need some advice please. When it comes to server security for mobile apps, what cruical security measure are missing from this list?
- Throttling API views
- Using private storage buckets, signed URLs and CDN for media uploading and fetching
- Sanatizing any charfields inputted by users to remove XSS/HTML/script junk from text.
- storing secrets in .env, never hardcoded
- When using external APIs, restrict keys to specific APIs and also IP or app bundle id
- Kill switches incase of emergencys
- CORS and CSP limited to server domain
- SSL
9.HTTPS enforcement - CSRF for session theft
- Tasks and caching via TLS
well here shadow is in a deep rabbit hole of untangling things
for those that wanna jump in the rabbit hole with shadow:
https://github.com/Kicksecure/sdwdate?tab=readme-ov-file
and
https://deb.kicksecure.com/pool/main/s/
Secure Distributed Web Date; privacy, anonymity and Tor friendly; console time fetcher and daemon; optional graphical user interface etc. Website: https://www.kicksecure.com/wiki/sdwdate - Kicksecu...
trying to install this on arch linux and going through the code and packages of compiled code to see what is needed
I don't like privacy
hey can someone help me install ryu?
Bless you
well then... enjoy never having curtains or bathroom doors again 
no biggie, no one wants to see me nekkid anyway lol
whats that?
I live alone I have those, but I don't use them π€£
gonna be fun in public places for both of you 2
why?
During summer I only put clothes to go outside inside the apartment I'm always nekkid π€£
it can be, if you play your cards right π π€£
hahaha
Im back with a new corny joke
If a hacker joins the military, what would their rank be?
A kernel

π€‘
lol. nice. i would add an emoji reaction, but for some reason, they're disabled.
only for none verified users :P
ah, that tracks
i'm a sub class citizen lol
i suppose i could login to verify, i'm just feeling really lazy...
like, super lazy lol
well here are some points
what makes you think you get to decide if you need privacy or not???
what if your friends and family rely on their data not leaking through you??
actually, i changed my mind. i want to verify, but my old discord is linked to my account. how do i unlink it so I can link this one? +_+
contact a moderator or jabba
Okay, @grim sparrow please help, thanks.
Gave +1 Rep to @grim sparrow (current: #242 - 39)
... not sure that works
@mossy river can you please help me resolve an issue with my account? shadow said to contact you. thanks.
Gave +1 Rep to @mossy river (current: #6 - 1834)
think the bot might not forward message to the moderation team so yeah but jabba will probably deal with it when they are back here
thanks

and a meep and a moop to the beep boop for the sleepy slooopy sleep sloop
night shadow
meep to the moop to the meep to the boop
how are you this fine evening?
Doin good, just chillin. Was grinding till I hit 0xF then brain was gonna explode so just watching heroes
you ?
I'm watching Masterchef Israel π
You have 10 minutes to make challah bread .. GOOO
I'll answer you in 10 years π€£
Humans are always need it to check and supervised the result of the automatization and or ai
if not happens what happened a few weeks ago with AWS that a 1/4 of internet went down and took a whole day to realise it and fix a stupid mistake that could be caught if somebody was watching
This is interesting. I'm now wondering if I should take that intro to AI elective my uni offers.
YES! Learn what you can about AI now
that way if your forced to which one day could happen then you are ahead of the tame
Don't get left behind
my uni's curriculum is really soc heavy. No pentesting at all. When I asked my seniors if, at some point, I would learn pentesting, they said. Uhhhh NMAP!
vorp thrives on dad jokes
AI is here and it's not going anywhere. The mistake that people made is let AI run wild without supervision
That's the exciting part
Because I'm not responsible for working on it
Supa computa
I'm not gonna be surprised if my uni only uses kali
soc is still a good path eh?
I'm struggling to choose rn lmao
I have to write an essay on what I wanna do and I haven't figured it out
soc nowadays is the new helpdesk of cybersec π€£
true
nice place to start, but get out of there as soon as you can π€£
why
nobody wants to be stuck in helpdesk forever π€£
dealing with people and issues take a toll on you, also that's why customer service jobs suck big time
I am confident that one of the best feelings in the world is getting a streak freeze from completing missions
that's like one paid day off right there
if you think that's one of the best feelings in the world, you haven't really lived π€£
Or I've lived too long
I still go with my first statement, it's not a matter of time, it's a matter of quality. A streak freeze wouldn't break my top 200 π€£
what are you guys getting for bf
Different strokes
I wanna get an rpi 5
different views on life for sure
how old are you?
Why would I ever disclose that?
you don't need to, it was just a question to asset your view on life.
so you wouldn't tell your mother's maid name either π π€£ π
lol me in Linux, "I don't wanna enable TRIM on my encrypted drive due to security concerns... but I'm having performance issues... let's just try it and see. Oh, first trim operation was on 890GB of my 1TB drive... fair I needed that"
Just me today, I don't know why I was so suprised. Really I just want encryption at rest and I have much bigger concerns if an advisory is advanced enough to care about where my LUKS headers are and determining what filesystem is in use.
Fair I do have some legitimate concerns of more advanced advisories but reason why security is a tradeoff of the CIA triad, confidentiality, integrity, accessibility. Yeah I was harming my accessibility by being a bit too paranoid
If you all aren't familiar with the concepts, if you TRIM an encrypted drive (at least in Linux), you are basically zeroing out the data as well as telling it that it's free to use. This makes these sectors instantly recognizable while still encrypted.
Without TRIM they still appear as pretty randomized encrypted data and no one can really tell without unencrypting what's used and what's free.
This is why dm-crypt/LUKS2 encryption setups do not enable TRIM by defualt, it is less secure for it to be enabled.... but the performance overhead of me not doing so was too much
I am curious about how Bitlocker and FileVault do this, I'm guessing they just say f-it, and TRIM anyways
also lol since someone asked elsewhere, this is very much a laptop, not a desktop
Answer is, they both do
I just appreciate that Linux defaults to the more secure option unless you decide otherwise and actually learn about it
haven't heard of TRIM, but I use LUKS with my current setup.
don't even really now much about that either other than it's supposed to provide FDE. no idea how it works. i also know that every time i reinstall Debian, it overwrites data over the entire disk to prevent old data from being leaked into the new system.
what distro do you run Elizabeth?
Arch since 2008. And TRIM is a critical function of SSD garbage collection on freed up sectors on SSDs. Just yeah if you're seeing any kind of performance issues it's likely because TRIM isn't enabled and you haven't disabled waitqueues on your SSD
interesting. gotcha.
For all I know Debian may just make these choices for you, but Arch Wiki has more info about both topics in this and the section immediately after: https://wiki.archlinux.org/title/Dm-crypt/Specialties#Discard/TRIM_support_for_solid_state_drives_(SSD)
you can very easily review your flags with sudo cryptsetup luksDump /dev/sdaX | grep Flags, obvs replacing sdaX with your encrypted parition
so for me with both performance enhacements that reads as:
Flags: allow-discards no-read-workqueue no-write-workqueue
For all I know other distros may be setting a lot of these by default, where as on Arch I have to learn about them and apply myself which is by far my preference anyways instead of someone deciding for me
hmm, interesting. i just started researching fstrim and how it works.
yeah that at least is enabled by default for me, but would not have taken any action against my encryped drive until I allowed it to do so
you should be able to manually run an fstrim operation just via systemctl commands. Did for me
and can check in journactl
i'm reading the man page for cryptsetup luksDump. I wanna try the command you gave
Sounds good, yeah it's just grepping for only a line containing Flags, it shows way more info than that
for me with my encrypted partition on /dev/nvme0n1p2 that would simply be sudo cryptsetup luksDump /dev/nvme0n1p2. You can use lsblk to double check which drive
Another performance enhancement would be to use 4096 instead of 512 sector size which luksDump would tell you about as well, but that's an entirely different can of worms and requires a reformat if you're on 512
Gotcha. Yeah, I did an lsblk and got my drive info. Would you want to luksDump the crypt drive/device or the one above it?
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
nvme0n1 259:0 0 238.5G 0 disk
ββnvme0n1p1 259:1 0 976M 0 part /boot/efi
ββnvme0n1p2 259:2 0 977M 0 part /boot
ββnvme0n1p3 259:3 0 236.6G 0 part
ββnvme0n1p3_crypt 254:0 0 236.6G 0 crypt
ββbase--vg-root 254:1 0 224.9G 0 lvm /
ββbase--vg-swap_1 254:2 0 11.6G 0 lvm [SWAP]
I tried it for nvme0n1p3 and got some info back.
but i didn't grep it yet, heh
whew encrypted swap as well
hahaha yeah, i suppose. Debian does it like that by default
fair enough, I'm just using ZRAM
Looks like I don't have any flags set... heh
daniel@base:~$ lsblk
NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINTS
nvme0n1 259:0 0 238.5G 0 disk
ββnvme0n1p1 259:1 0 976M 0 part /boot/efi
ββnvme0n1p2 259:2 0 977M 0 part /boot
ββnvme0n1p3 259:3 0 236.6G 0 part
ββnvme0n1p3_crypt 254:0 0 236.6G 0 crypt
ββbase--vg-root 254:1 0 224.9G 0 lvm /
ββbase--vg-swap_1 254:2 0 11.6G 0 lvm [SWAP]
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3 > ld1.log
daniel@base:~$ less -iN ld1.log
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3 | grep -i Flags
Flags: (no flags)
daniel@base:~$ sudo cryptsetup luksDump /dev/nvme0n1p3_crypt | grep -i Flags
Device /dev/nvme0n1p3_crypt does not exist or access denied.
daniel@base:~$
Yeah so none of that then, just if you find IO performance to be lacking these two improvements can help tons
gotcha. thanks
Yep no problem!
yo π
Heya c:
heyo
hii im an absolute beginner who wants to start doing this, what should i do first?
read #start-here
haha, called it. frankly, i don't blame you guys. with the amount of people asking, haha
man, i want react emojies so bad... but my old discord is linked to my THM so i need to speak with a mod to link my new account...
i'm currently.... in the black and white purgatory lol
have you contacted a mod?
I @'ed Jabba, per shadow. but nothing yet.
yes. reading is good
why?
@rough lodge please dont dm or send friend request without asking first
Ah. Ok man
My Bad ,,,, π¬
you can talk here
I send u friend req as I'm also almost same old user as u 2017 ,,,,
But that account I sold by mistake
Lol,,, didn't go though it
you added me because i have an old discord account?
Yup ,,,π€£
lol thank you for not adding me as well for such
haha thats a new one
π₯²
Missed u btw
π€£
Should I ??? π€£π€£π€£
Please don't, we can chat here just fine
π
Wassup hackers 
Btw I don't know anything newbie here
Any tips ?
just planning a new project. u?
How to start ?
Sure, you can start with #start-here
Lol,,, i just want to hack my clg attendance thing ,,,, to increase my attendance
Trying to figure out what is my next exam.
Same pain was for me ,,, 4 days ago
illeal activity isnt allowed here. you should really read the rules
No, we are only here for ethical uses of this knowledge, this is not something we can assist with or discuss
Which I'll attend after 2 h
πΆπΆ
Neh i won't touch it
Yoo ,,, what's up with this rule things ,,, lemme go through all of them at once
@gusty inlet or @cloud quiver if one of you clould clean that failed attempt above up, that would be lovely
Bro how can i join these vc
?
You need to verify you account with THM first
probably need to verify
I see
same thing all the time
yep lol
how bout Jabba lol
he should be sleeping tho
They don't show up as online
arent they all sleeping
probably lol
So what is the best kind of Donut
chocolate sprinkled
strawberry icing with half sprinkles, simpsons style
yumm
sounds gooood
Noice
we have places here that make crazy donuts
yer there are some crazy donus these days
Damn sure I'll make donuts in home rather buying it from market 
making me huuuuuungry

...
Hey guys , can anyone help me with this connection error while connecting to tryhackme openvpn. No matter what server config I try connecting with it just says --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers. . I tried troubleshooting it by editing the ovpn file adding data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305 but it was of no use.
Did you see the openvpn room as a guide?
yeah
Just download a fresh one from a different place from the access page
Which is the closest for u
asia
Which one did u use?
the asia-mumbai one
Is that beta version?
Wait a minute, ur trying to connect tryhackme to an vm?
U should go with india regular 1
holy moly
Done!
who want study trade here?
join my lesson plz
What trade?
what lesson?
.
Why didn't I learn shell scripting earlier. This is gonna make things so much easier
yup, i found that having powershell documentation at arm's reach was a game changer
s
you give me study, I give u study 
test
No human is without flaws.
yup
Most often they mean crypto coins, sometimes daytrading.. suprisingly often people think you can let bots do the trading and get rich
I just finished a skill assessment module on the other platform. That was sweaty
slow ass rdp machine
even scrolling lags. holy. it was so annoying. Couldn't tunnel too. was about to lose my mind on how slow it was
was it like necessary to rdp?
yes. because you can only access the 3 target host via the foothold which is what you get thru rdp
you could also do like evil-winrm or smth if you only need access to the powershell and cmd
but idk what the network was like, so
I need to review AD and do some THM AD rooms lol
0day's not online π
nah. After completing it. Walktrhough's looks like you're just supposed to use the rdp. Smh
ah lol
Brothers can you fill my google form and help my university survey?
gonna need more info than that chief
you can ask one of the mods or jabba if you are allowed to send the survey
Really
yeah you need to ask one of them
Okay i will try it
my port forwarding works now 
We don't allow surveys here sorry
@mossy river mind if I DM?
I'm good, how are you?
Sure
good, good, applying once again to high school π€£
Applying again?
yeah, didn't get in last/this year 
idc if I get in this/next year tho
luckily, one school that I thought ghosted me that really liked me did not ghost me, and they gave me a reply (or my interviewer I guess) yesterday
only two months late 
Are you applying early cause you're young or does it just work differently in SK?
I'm applying to American boarding schools, and actually, the starting age is 14 (grade 9), so applying now is actually one year later than when the normal starting age is for these schools
I'm reapplying as a 9th grader cuz that gives me better chances π€£
I would NOT ghost you if i was one of the high schools lol
Assuming it's super competitive to get in?
yeah, like 13% or smth
around that margin
you can deff get into that
-# I failed last year 
I mostly grew this past year tho imma be honest
my skills anyway
if you put your all into it, you can get in
hopefully, but if I don't get it, its fine lol

I am really confused in in path Soc Level 1 inside it Soc team internal -- Introduction to phishing thing when I open it it's showing 0 Alert
i think it might take a bit for alerts to roll in
You will have to wait for them to show up
no less than 2 minutes
bro why i am suffering from ctf
no idea. why?
go back and learn the basics again
A honeypot for tea ?
DM me
Jabba taking every "something for tea"
I dont get it. I am just starting and having trouble with my first little lab. In the "intro to LAN" I cannot make the flag appear. It does nothing. Now should I try another browser because I did,Chrome" and I couldnt log in probably because I was logged in the brave browser so I logged out and it just errored out in Chrome to sign on. But yeah I cannot get the flag. Can someone help or give me the flag so I can move on?
:hammer: neverstop200#0 has been banned.
Be me
Plug your USB into the school pc for a local network security assessment
Get nuked by AV and lose all scripts and files on your USB because your a lil slow in the head
Doing a local network security assessment on school computers?
Yeah im friends with the Admin who manages the systems here so I asked him if I can try some stuff out and he was fine with as long as I donβt break anything
To see what a attacker could do if he had physical access to one of the school computers
Since they are directly connected to the lan

Too many stories I've heard of the same situation, then people getting into a lot of trouble for pentesting
True yeah
yer that sounds sketchy
Should prob sign a legal doc
yeah, happens very frequently
Apparently there are admins everywhere just letting students do whatever they want on the network

I don't want to assume age but it also sounds like a lot of those students are teenagers.
"as long as you don't break anything"
lmfao
WRITTEN CONSENT IS A MUST
if anything goes wrong or if someone actually catches you snooping and doing "assessments" via the logs, that friend of yours won't stop you from facing the consequences in any way
I've worked in schools and I've also done I.T. , if an admin is questioned about having granted permission to a student to mess with security they won't take the bullet for you, and almost rightfully so
das a lot of vms
Actually its 377.14 GIB
Which one are you in?
which one of what?
The company you are talking about
I guess I'm bad in English
Sorry
my IG reels got cursed
it's a fake company that I built
who ghost pinged me 
cursed how?
was just about to comment that the naming conventions seems odd π
thats regular old instagram
10s i'll delete
actually, it's the same naming convention that you'll see in a real company π
he does look like quagmire 
the company is shut down in 2 weeks
=)))))))
Bruh
I'll work for 2 weeks boss π«‘
I was mostly talking about the straight numeration
the vm ids?
people tell me I was got a IG premium
Bro is unemployed fs


i love reels tho
Yeah, not grouped, no indication of the host they are running on or the redundancy location
they are grouped, there are indications, it's just not shown in that pic of the summary
had a client last year who had the naming convention "physical machines - roman pantheon, virtual machines - greek pantheon"
yah

Done now.
my .ovpn is tripping it doesnt connect
does anyone have any good resources about ethical hacking websites and web apps
Hii guys
There is a discount or something for the CPTS ??
portswigger
30 Days in, and I am in the sapphire league
β Gave the role OSEP to 0xchevalier
this is new
@silver hornet Too many emoji too fast β please slow down.


@mossy river I like this idea, ngl
How does a total noob have a CEH cert?
where was this lol
Reddit mr Reddit Ambassador lol
that don't look like reddit
I use old style
ah
anyone having problem with split view for the machine it seems to get ip but icant acces it ?
never switching to new
yes
what do you think about it?
idk, they are just trees lol
I prefer spanning trees, they require less water
nice conversation π
what else can I say lol
it really depends on what specifically you are using binary trees for
Unlike Binary Tree, Spanning Tree has it's own protocol
I'm going to have a test on this this Wednesday.
I'm not putting much faith in this matter.
on.... binary trees?
idk how that works lol
yes, ABB and AVL
It's annoying, but it's cool to understand how balancing works.
idk
good for sorting numbers
they have two different purposes tho
normal (walkthrough) rooms are for learning, challenge/CTF rooms are for testing your skills or just doing it for fun
wouldn't you learn eitherway by trial and error doing ctf?
i think room have too much information you forget afterwards, hands on gets you further
I think if you have no prior experience youd be lost without the walkthrough rooms no?
I dont think youd be able to solve a ctf without having experience in the field
that's the point, finding out what works and not, researching
yes, but in this context, that wouldn't really make sense
when including challenge rooms
you SHOULD learn and get hands on
How do you think people learnt before resources like THM..?
ofc, but as you said: before.
but, I would argue that THM challenges are quite different. you'd be going in and trying out the challenge, you might learn a thing or two, but its not like learning AND going hands on
The existence of training resources doesn't suddenly stop people from being able to teach themselves...
a lot of walkthrough rooms do have learning + hands on
researching is good π
what works on what, etc., etc.
but you need first learn, then try challenge rooms imo
Hacking is 90% mindset. Arguably being handheld through walkthroughs actually has the potential to make you a worse hacker because they don't encourage you to develop that research mindset for yourself.
And I say that having written a lot of the early walkthrough content on THM.
i agree, though i think you'd atleast need some kind of base to feel confident enough to dig deeper for your self
Lately I think that hacking mindset is similar to Simon the Sorcerer puzzle solving.
you can create this base and learn through THM content (walkthroughs)
So, yes, in many ways this is absolutely spot on.
Walkthrough content has its place. It's a quick way to introduce new concepts... provided you use it as a foundation rather than as a replacement for curiosity.
Challenge content encourages you to build up your research ability and develop the curiosity mindset.
I would never recommend people only do one or the other.
Is it me or the advent calendar email is broken?
If you forget stuff, thats normal. but it might also be a sign you aren't writing notes
Itβs broken
Traditionally you'd get that base from other areas of IT. These days people want to skip straight into cyber.
Jury is still out on whether that's a good idea.
Thanks for confirming I was thinking it is some elaborate task that I am too dumb to solve π
Gave +1 Rep to @smoky ravine (current: #3252 - 1)
Make sure to write notes. Good notes are:
#1: Not too long but not too short
#2: Organized in a way you can quickly find the stuff you need
#3. Useable for the future
#4: Based on the techniques, tactics, procedures, and tools you learned
This also means that when writing a note, you shouldn't name it by the room you are doing. You won't remember which room taught you specifically what you are trying to find. I've heard from experts to use the MITRE ATT&CK Framework as a reference, but since you are a beginner, I would just organize your notes in a way you can find the stuff you need.
@pallid lotus let me know if this is bad advice π€£
Yeah, I wouldn't necessarily tie it to an existing framework. Definitely don't tie your notes to specific training content.
Organise them in a way that makes sense to you. Take exactly as many as you need, and don't just copy/paste.
gotcha, gotcha
writing down in notes for the future
+1 especially the copy/paste part. I notice my self how i gain more knowledge by writing it down my self in my own words instead of just pasting
don't blame me, I'm a reddit ambassador, gotta give good advice
Oh, good...I thought it was just me too haha
@mossy river there will be an advent of cyber this year, right?
Hmmm... I've already done 100 rooms and i named my notes after the room
oops
I didn't know what else to call the note
Necronomicon tome 1,2,3,4 ?
Yeah, definitely
Does not work for me. My notes look like this: me press a button, me enter a command and pray for success.
not sure if ill be made fun off but as a young person into programming and cybersecurity, most of the time i rely heavily on AI to map out future topics to learn/explain them
is ther eanyway to get past this? I fear growing up and practically mfinding ymself only relying on AI cus I got used to it, but at the same time i've had comitting issues with different topics and I dont trust my self judgement
So you will have to skip entry level jobs because AI has them, but the only problem with the mid level jobs is that you don't have experience and AI has more expereince doing entry level so it will get the job first!
I think this post is taking a jab at people who use AI to write their code/homework and not people who use AI to explain and learn
? Maybe I'm just a dum dum but sometimes I ask AI for clarification or suggestions
You don't learn best by having it explained to you
That's like peopel that ask google questions in general
You need to find out how you learn and learn
YOU learn, not have someone else explain it
Books are your friend, AI isn't
fair enough, but truly are there any recourses or advice I could get? this has been a real struggle for me ever since I got into programming young and has quit multiple times over
Same. Tried reporting it back to support email
or is it just not relying on AI at all and spamming books?
cant tell if im missing the point
Good, hyd
good, good π
doing school work, coding, cyber, AI stuff now, applying to high school again
I agree with what you're saying, I avoid AI as much as I can when it comes to Cybersecurity and my college stuff, I just like using it to explain and give some context on random stuff like history
AI is great for experts
It's a great tool for me.
If you're here trying to learn, it can be a great tool, but it's very very dangerous and it pulls you into using it wrong
If you need to learn about python libs for doing something
Great use case
Trying to use it to learn the core of Python, okay~ish.
But that doesn't mean you learn how to program
Data structures, algos
Searching, sorting
Where should this button should redirect? Because it seems like it's not working.
it isn't dec 1st?
I mostly use AI for non-learning stuff like asking it to identify a movie trope π
Idk if that's bad
at least this confirms there will be a AoC 2025
It feels harmless to me at least
do want do want do want do want do want do want do want do want

It should be free
but chocolates are expensive
Free for all 0XF and above then
free for all the room testers :P
hahah yeah that too π you should get points for room testing!
technically we do if we recomplete the room after it releases.... just we can't get blood points
Fair enough
yes?
Your name

can i link my tryhackme account here?
yes
how
like that^
the mention part of that command is so hard to use without doing things wrong D:
done
have you seen the new discord feature shadow
the one that lets you choose font for name?? yes
just write a persons nickname and press tab to tag them
so if I write shadow and press tab, it'll tag you
no worky for shadow D:
it's on the desktop client on windows π
shadow only on arch linux D:
I know, it needs to be added to the repo
Sweet
anyone wanna here need a team mate?
π
What's with the new bot @radiant bloom
i thought you can do anything on linux that windows does
Hii
Hi Gergely, how ar eyou
Fine thx
Hyprland or?
Gotta finish Linux essentials today
I love Linux
And maybe windows as well depending on how fast I can get used to obsidian
I think it's instead of yag
zeppelin is a public bot π
that's a lie, I am sorry, apparently it's invite only
@glad vortex who are you
currently yes
but looking at mangowc and niri for some interesting things
also looking at dwl
for the most part that is true yes but sometimes features in programs are os dependant
not everything Linux doesn't have those BSOD for no reason π π€£
well you can enable blue screens of death in systemd nowadays
now the question is why you would want that
but someone made it available
can anyone hlep me with which CTF rooms to practice with
i have completed then web fundamentals path in tryhackme
What's wrong
hi
Can anyone help me out Epicdrops
Hey bakas!
Hi shadow!
Morning y'all, do you all know when AoC starts?
Have an exam soon so I want to able to participate this year some more
isnt it generally dec 12th or there abouts?
no problem
Have my exam in the end of Nov so don't want to miss it
right. good luck
probably in dec 1st
Oh yea, I will be good by that time for sure. Thank you!
Thank you to you as well
Gave +1 Rep to @river crag (current: #3252 - 1)
sleepy
@neon stratus apologies, I checked 2024 and it did start on the 1st. @marsh lark was right. so maybe its the start of the month
why did u send fr
i presumed they meant the event, not the calendar
I have some issue with the app
well u could read rules first
Ohh ok what do you mean?
Does AoC have prizes?
ello ello
The real prizes are the things you learn on the way
Facts
Good morning!
the real friends are the boxes we pwned along the way. lol
Maybe
quite tired but pushing through and reading up on things and stuffs
it takes a bit to set up 3 vms
It s night in there
+1
"@grok is this true"
well looks like it if you look outside
but time is only 19:44
Same in here
I'm setting up an XDR, over a VPN, it's hell
:D
@acoustic crystal Too many emoji too fast β please slow down.




Damn new bot does something special?
Oh cool, I am currently using customized xfce
Took a bit of scrolling but found you. Just wanted to say thanks for the real talk. Few days into server mission and trying to document it. You were so right thatβs itβs more than one project but itβs been fun. I now have broken it into many projects. Iβve moved from lemonade stand to home brewing, next step is dive bar. What a journey but building up my own little cloud and making plans for each step. And documenting the days has really helped me take in the days achievements. Thanks for holding up the arrow as itβs easy to get lost with goals.
Gave +1 Rep to @grizzled sky (current: #242 - 39)
nice
xfce is a good desktop environment
sadly no major wayland support yet right???
Mhm, not entirely
shadow loves them some thunar action for file manager
@modern fox Too many emoji too fast β please slow down.
U wasted my 2 seconds
..
huh


mobaxterm > putty
kitty is a terminal, not an ssh client, sure there's the putty fork called KiTTY, but still, mobaxterm is a more rich and better client
Yes yes you are correct,
especially when we talk windows ssh clients
Tabs give me nightmares
does anyone got burp pro i reall need
just buy it?

?
fair fair, I like it, makes me able to configure multiple servers at once
Good
Y
I have to set up wazuh, on 3 different servers, index, server and dashboard
I am glad you take the step
Burp Suite Professional is the world's most popular tool for web security testing. Get a free trial now and identify the very latest vulnerabilities.
get it there
can i burp pro tho for free?
Oh you want illegal burp?
you can get it for free
if you get your work to pay for it
You figured this was a good place to ask for piracy
Cant you just script alla steps, save some time?
thing is i really need to get my miscorft acc back
yes and no, there's configs specific for the servers, and it's 3 different things that has to be configured and installed on each server
ts guy called sam said he can help me get it back if i get him the promgam
You will lose all your credentials, you will loose money and get scammed.
That is what you will get
ohhh k
You just sound like an idiot, sorry to say it.
It is completely bullshit.
IF you lost your account you can use the password reset from microsoft.
If that is not working they have furhter steps to assist you.
i am looking for some good source of academic paper related to cybersecurity , any great place to find some ? , i looked mainly in IEEE , you guys have any advice ?
Burp suit will not get your windows account back
oh so he trying to scam me
Yes 100%
my miscorft back?
oh dang
ty man
u save me
depends, what kind of area you looking for?
Lets talk about it instead, what have happend
that's a great question
something related to Defense systeme , like maybe Detection of suspisious activities , of something like that



