#general
1 messages Β· Page 1881 of 1
Nah it's fun dw
I already know basic concepts of how encryption works, the two types
You need to work on your methodology then
Symmetrical and Assymetrical
If you dont mind, could you expanding?
Expand*
Sure, it's normal - you will learn and figure out some methodology as mentioned
Im genuinley motivated asf
for example lets take port 22
on linux and sometimes windows systems it is the port for SSH
ssh is just a service that allows you to connect remotely to someone else's computer in the form of a command line interface (a terminal)
if you know a username for a machine lets say, then you can bruteforce port 22 with the username and a select wordlist
all of this is possible because NMAP helped you discover port 22
Where you ever at my stage?
But wouldn't the bruteforce attempt get logged and detected by an IDA
IDS
Any advice you would give me ? Or do I just let this process happen
correct, right now we are talking hypothetically where a system has nothing fancy like an ids
Depends if it's implemented + how you perform it
I see
Methodology like you know what are the steps of hacking
You start by scanning and then enumerating and then exploitation and then cleaning up but I think I missed a step or two lol but I'm so used to it I forgot the names of steps I just do it automatically
Like using nmap is for scanning and a bit of enumerating
THM hasn't taught me this yet
Im straight out of presecurity Lmfao
This + try to do some easy guided challenges - they help a lot in understanding how to implement concepts you've learned
dont read too much into this
Guided challenges?
just know nmap is very useful and essential
It's just hard work not genetics lol you'll be in our level in a year
Ill just follow the process
it is used in both blue team and red team roles
it's a matter of skill mostly (+couple liters of energy drinks drunk while studying kekw)
Blue team because of like, say testing ur system for vulnerabilities and abusable open ports?
Well it's a something that you need to learn on your own maybe but personally I started with tcm and they taught me about methodology first thing
π i cant drink anything but water
Yup - where you get pretty much guided through solving and hacking a machine
Im an mma fighter aswell
I was to ask why, but it now makes sense
I genuinley
Find cybersecurity more fun than mma
Do some jr. pentesting + guided challs
Yup
Should I start guided challs rn?
Im half dagestani, and half chechen
yeah, why not?
Oh shit
MMA/wrestling is in your blood lolz
Ill figure something out tonight
π
Im 15 so I think I started cybersec at a decent afe
Age
But some people here
Started at 9
π
Alr, I have some if you need recommendations
Yeah, it's fine - I personally stared at 14-15 as well
Hold on
How old are u now if u dont mind me asking?
Spit
https://tryhackme.com/room/rrootme
https://tryhackme.com/room/vulnversity
https://tryhackme.com/room/basicpentestingjt
https://tryhackme.com/room/h4cked
wtf
I don't - I'm 17 atm
Are these beginner type?
holy embed
Yeah, check them out
Srry, doing 5 things at the time doesn't benefit always
dw bbg
If you didnt know you can put links in these <> brackets to auto remove the embed 
Alr, good to know. Thanks
I just copied those from a reddit comment I've made 2-3 days ago
Gave +1 Rep to @regal dawn (current: #1114 - 5)
you should maybe do those when you finish jr pentester path
These will enhance ur hand to hand skills i presume
Mind if i add u guys?
Just in the future
For*
You have me iirc
Add me add me (β β§β β½β β¦β )
Oh yeah
I am convinced glitch is sponsored by TCM
Yeah and most importantly show you how you can use those tools in the wild, as THM sometimes (especially in older rooms) lacks hands-on real-life challenge directly after
May i add you too please, trying to connect with some people on the platform
Yeah, I think after jr pentesting ill do all the red team shit then hop onto HTB
Yes
Please do
Add me, everyone
π
Lol no I'm just here for fun I only talk here to help people cuz I know how hard it is to start from 0
In my case I was a business major so I literally started from -1
Ur a W person
All of u
send you thm link twin βοΈ
Me too me too (β β§β β½β β¦β )
Alr
Huh
I mean after everytjing
maybe after red teaming path and a little bit more
sure after you finish the whole red team path why not
You'll be fine just don't rush yourself and take your time taking notes and understanding things in depth
Still - it's possible but more difficult
Imo HTB marking is +1 to THM a.ka HTBs easy is THMs medium
more like the HTB easy is tryhackme hard π
Im going to take notes of everything in a way I understand i hope
but htb can be very random
I see
"finish the red team path rq"
one "hard" machine took me just 1 hour to get user lol
Eah depends
omg thanks for reminding me i should do the capstone challenge
Gave +1 Rep to @regal dawn (current: #973 - 6)
now that i know how to use ligolo maybe i have a chance π
I wrote my notes in my native language and this weekend I'll translate them so I can send them to people so remind me to send them to you
Id really appreciate them bro
Whats ur language?
I know 8 languages
9 including english

Well my native language consist of 8 different languages so idk about that and it's written in fran/Arabic way lol
I know english, spanish, basic, perl, php, python, and bs, so only 7
And facts - so 8
Are you american
what about human languages
I know:
Russian, Chechen, Farsi, Arabic, Pashto, Ingusheta, Bosniak Language and Albanian
only 2?
yes
Nvm 10
I speal arabic
how in the hell did albanian get here
π π π
Do you understand the one written under port scanning?
I only understand when its written in arabic
If u send them over i hope to get them translated
Where do your notes start (topics)
I was born at Defcon 1 during one of the talks. no time to get to hospital plopped out during talk
Networking fundementals?
They can't be translated in google
This weekend I'll translate them manually and I'll send them to you inchallah
Mazel Tov
Well they're commands and I explained to myself how each one help and works
I didn't understand
Bro had 20 years of exp being 12
at defcon 2 i kept getting free and picking every lock
lock picking village
I went do defcon 17 years ago and rememeber that
if i could eat wood, i would be a wood eater
are you doing that one ctf
i was in a special class the week before defcon with fbi, nsa and police
Have you been in social engineering village what are people mostly think about u there?
No, I'm just fabricating stories about my birth and childhood
That would be fun to go to.
I would have at least 3-4 identities ready to go
Start telling different people different names for myself
find out what story makes them talk the most
So far every time I want to do something in ARch I just tell claude to do it for me
like disable screensaver and screenlock
that seems like bad practice
Glitch noticed that shadow always talks in third person for some reason
Not for a 28 year linux user
well congratz... you noticed the most noticeable quirk of shadows typing
I'm interested in seeing what it does
read their prof
One of a kind
Why did the coffee file a police report ππ¨
I never wanted to be old as much as when I entered this server
@gritty bane Please slow down. Further spam will result in a short timeout.
Everyone is 40 and they know too much
This sucks.
that's a cool origine story , your parents were that 1st Hacker generation
being older than the known universe sucks as people have way to many assumptions about eldritch beings
See, fake stories is another thing you always need to be able to pull out of your pocket.
People are quick to challenge you so they try to osint yoru story
and waste their time LOL
Glitch thinks Shadow is onto something
Is osint a valuable skill to learn?
yes
look at the mitre attack
reconnasainse is important, you wanna gain info, especially for social enginering
hello general
I want to learn it so if someone steps out of the line I tell him the name of his dead grandma
what it means
He's talking about osint
it means when a bad actor calls the help desk , they pretend to be the vp and they need to know about him to pull it off
no my english bad i dont understand this word
Which one
reconnaissance
okay
It means to gather information about your target
It means like gathering information or something
oh.... it's collecting info from multiple places
Thanks
finding the locations,
bro learning language and cyber simultaneously brain drowning
Are you new to cybersecurity
yeah exactly
i got into recently
i learned many times networking and was cut off learning
What's the mitre attack if you don't mind explaining
Yeah I see you're in this server from 2023
What's your level
You don't need to get that in depth in Networking to understand cybersecurity
i was attended here then the server was slept as like my other servers how they do
@dark wolf you play GTA V?
Do you have any questions or something?
It is essentially a database full of tactics that threat actors use
That's in a nutshell lol
did on and off for a while, but not lately, not even installed
yeah where can i start for like?
TryHackMe has a full room on mitre
Thank you
Gave +1 Rep to @gritty bane (current: #304 - 30)
Dang
Why do you cheat in every game
now they want kernel stuff, screw that
i was curious about looking into websites most of the time but idk where to follow this way at
You can start in the thm learning path from the beginning
Cuz i played without cheats for 30 years and now I get to cheat
Oh well idk about that lol
not the way you guys thought in first place but yeah i like to looking probably pentesting
Well first you need to get the fundamentals and then you start in pen testing cuz it's not something that you start with it
Wand formerly known as WeMod, you can enable cheats in most games
bro the problem is concentration overally i was even started to trying learn while standing on my feetβs looking to pc
I only play games that work with it but also msfs 2024 with no cheats lol
cuz while sitting on chair after a while passing off i was just standing out and laying on my bed
What's your native language
turkish
Write in Turkish and translate cuz I didn't fully understand sorry
okay
The general problem is concentration what you guys really suggest for ambitious but lazy person
I like to watching videos as like one channel that i looking at recently the name is fern and yeah
Well working hard is the first step there's no shortcuts in this field unfortunately and you'll need to put that extra work in
Do you know anything about cybersecurity or penetration testing?
I was knowing in former but now i forgot at all
Well you can always start again it's okay but there's 3 keys you need to know to start in cybersecurity
Programming/ Linux/ Networking
And then you can start your path in cybersecurity
okay
im working now and if i look and read for just now you suggest that?
Yup those are the keys for IT in general
Okay
By programming means what you mentioned,is it Python?
yea, python is great
okay ill peep up those things you guys have any video of it
and some C and how assembly works
being able to read code and knows what it does is the goal
Yep anything that you want but python and c are the best
and channel for explaining those things
Is it okay if I suggest for her videos of other industry?
Or will I be banned
idk, check the #rules
They say no advertising but it's a free course so idk
You tell me
shadow is now again going for the sleepy sloopy sleep sloop to the beepo boope while going meep moops
Well I just saw and I don't think there's any rule about this cuz they say it shouldn't have any gain to me or financial or something
Do you want me to send you some links in the dm?
Sleep well shadow
Okay dm
I didn't want to get banned and earlier they warned me about it
HAIIII :3
Sup
Are you connecting to it from the AttackBox or via the VPN?
Hiya tim!
hi guys, i am doing the lazyadmin room atm
i gained root but root.txt is just nonexistence in the files
what can i do?
it might be in a different location, try using the find command to locate it
yea tried alr
its very strange, i wouldent ask here if didnt
Sounds odd. i wonder if i did that one
i am new so level is easy
all the youtube videos shows that the only file under root is root.txt
but i have a lot of files
i don't recall that one, and my notes cut off .. dang
i can stream
I would help but in the middle of some stuff
aight man ty
sup everyone. hows it going?
just chillin, how bout you
just got home from visitng my parents. not sure what im going to work on now
as long as you are not promoting yourself you are good , ive redirected people to third party sources countless times
for something so old HTTPS is still really secure
why cant i just sniff the handshake and view the data
stupid browsers giving warnings to users when i try to do a sneaky redirect
Diffe-Hellman
Hello all, I want to learn malware analysis and development, what is the path / roadmap I should follow? maldevacademy course price is very high.
Security Analyst
Do you have any exprience with assembly?
gotta lean a lot deep dived
I learned C and Python
@cosmic pendant
anyone
Plus is very specialised. There probably isn't a thm path for it. Just search to rooms and do them individually
there shouldn't be cause thm teaches beginner stuff
and shouldn't handle the topic about malware tbh
especially a lot of new people join and get wrong ideas
There are some malware rooms but i think they're mostly blue team stuff
yeeee
Reverse shells are basically malware and they're used heaps
It's not my area of interest so I haven't really researched it that much. Interesting to think about
I study malware daily π
what roadmap are you following?
I am reading Practical malware analysis.. Though the book is very old..
Did anyone claim the 40% discount?
hi everyone! I wanted to buy the annual subscription and i clicked the link through the email which says 40% off for annual. But on checkout its only 25%. Am i missing something?
In October they had 5 months free with the subscription is there anything like that this time too ?
Remove the code and apply the black friday code
Logout and login again
It should show 40% off on the annual subscription
Can anyone help with this ?
I did lol
sorry this might sound dumb but it does not work. I dont have a button to remove the code and it does not reset with logout and login
The eerie silence filled the once active chat with nothing but the sounds of crickets and wild coyotes in the distant. The lurker sat watching the chat; even poking it with a stick, all in an effort to revive .t
Hiya KGB!!!
Yes if you are not premium user
KGB is the real GOAT
Gave +1 Rep to @cloud quiver (current: #1 - 6017)
Hey KGB, I am a premium user, with this change about the VPN, I cannot ping the free machines? So, cancel my subscription in order to play free machines?
lol it worked anyway
Try to change vpn server and regenerate a vpn file
you can access both free and premium with sub
I do it, an it change me again to the same server that does not work⦠this started las friday an nobody is willing to addresd the isse. I am not nee here!!!
It does not work, believe me!!!! This is so frustrating!!!!
YEah, i can see how that is frustrating.
Guys what is vibe coding? My professor emailed me (I was sick [didnβt come to class]) and told me that weβre doing vibe coding but bro didnβt explain to me what it is
also, he said I gotta present my own vibe code to the classπ
Fortunately I haven't had an issue, did you email support?
its when you use ai to code things for you mostly
Ohhhh okay, so can it be anything then? Weβre doing c++ so can I just tell A.I to code somethin for me?
yeah, but i would make sure you understand the whole instruction for the lesson
Yes, they do not care. Only copy and paste a reply and thats all!
i see, well there you go, do you use claude code?
or just look for what ai is good at vibe coding
@slender hemlock Are you absolutely certain you are using the right vpn file what does ip r say to you
do the openvpn conect, and in another terminal type "ip r" if its linux
Agh
if windows theres an equivalent config
Just like chatgpt and claude but this vibe coding is IDE itself run by A.I
route print....
@true viper You go to your web browser and tell your computer you have a series of library books with ISBN #'s and titles. and your titles are D1 D2 D4 D7 C1 C4 and you put them in a file backwards and you need ot sort them into the right order .. can you mkae a python app to do my homework pls
It spits out code, depending on the quality of your prompt that may probably solve your issue
ip route 0.0.0.0 0.0.0.0 Null0
lmao .. thats almost as good as alt-f4 diagnostic menu
@true viper Leo, claude, chatgpt, mixtral if you are self hosting etc. Your llm spams out hte code, and you copy and paste it knowing nothing about why it owrks
exactly how win11 was made
Sadly i think you may be right. .. so many bugs
Which is why i virtualized it, and dump disk before sp's
hey claude write me a function that interrupts the users game every 5 minutes for an ad
Reaper Pwned!
Stop the fortnite match in the middle of it for an ad lol
NO.. you dont stop the fortnight match. you let it continue in the background paying people cawn continue to play and you can hear yourself getting demolished
they stop football and basketballl and baseball
I think bezerk (berkely students gaming company) did commercials pretty tastefully for acrophobia.
But seriosuly, if you want people to enjoy your game and buy it, you punish the hell out of non subscribers and demonstrate the advantage paying for subscription has right out of the gate. Let them play a few games without the in game advert popover. Then after about 2 weeks start hitting them with it
At that poit you give em a game credit. You get N minutes of no popups. Then hit em again make the popup frequency propoortional to the amount of time spent playing
Yes. I am. Im not new here. However found a trick. I am automaticly assigned to US East N Virginia Region. So , i just tried to change timo EUβ¦ ping for free machine 0β¦ changed to Asia ping from free machine 0β¦ changed again to US East N Virginiaβ¦ and ping from free machine 1β¦. So the VPN is broken, but this help. Need to change and do the same after a premium machine. Sad, really sad!!! This was not like that!
I think that .. strange world? strange planet?did a pretty good rip on that
@slender hemlock I honestly don't see a region .. I used to pick regions but this tim ei just downloaded a file
For me is broken! So I am going to try this way I found waiting for the THM genious developers to fix the issue.
what os?
Okay. Health GPT is a fun concept .. but there appears to be a pretty big .. shall we say hole? Maybe its intentional as an easy box
So Iβm new to a lot of this and Iβm very interested in buying flipper from someone I found on marketplace is there anything I should look out for or pay attention to
Whats wrong with buying it from teh company that makes them?
wow. theyre so expensive
Yeah. they aint cheap, but they can do a lot if you take the time to work with them right
do they do much that a plain rfid reader/writer cant do?
Can you imagine going downtown and waving that around in the air like you are trying to get reception from a cell phone out in the forrest?
ngl i want it;
oh you have no idea;
if you're ok with dming i can tell you about some fun times with the flipper zero;
well nerd fun times;
cant you talk about it here?
eh its grayhat stuff technically;
Yeah you can dm me
ah gotcha
i don't have one but i like stories
Full Vid: https://youtu.be/Z4l2ckSpDDs
NEW: Join us at http://www.icedcoffeehour.club for premium content - Enjoy!
Add us on Instagram:
https://www.instagram.com/jlsselby
https://www.instagram.com/gpstephan
https://www.instagram.com/alex_nava_photography
Official Clips Channel: https://www.youtube.com/channel/UCeBQ24VfikOriqSdKtomh0w
For s...
this is a good example of how social engineering works;
as long as people think you are supposed to be there, you can get away with almost anything;
why its failed ? i tried with 3 ips but still same prb
try 2nd times
Attempt 2 smb exploits
I honestly wanna learn it and what could be done with it
Smb exploits sometimes failed in attempt 1 but success 2nd time
change exploits ?
As user friendly? As the flipper Iβm new so any suggestions and help is greatly appreciated
no just rerun the exploits
if its still not work exit from console and type msfdb delete and then create new postgresql db by msfdb init and enter again to console
I struggle here before but i fixed it by myself
Check the compatible payload for eternalblue use the meterpreter payload reverse_tc
Type 'show payload' when you load eternblue module
So ideally, compiling the PolKit exploit on the target's machine is much better than on your local machine right?
do you like it?
Can the flipper do brute force type attacks?
I should probably just google it myself
Anyone have experience with a flipper and a proxmark3?
I wonder if rfid access control systems are susceptible to injection type of attacks
hmm, i know they are susceptible to replay attacks but idk about injection
and i wonder if theres a way to put that straight onto a cloned tag
well for a card, for example, you can read and copy it then with a writer you can write it to a new card
well, i know what ill be researching for the next few days
yer but is there enough space on the card in the right place to fit the extra or 1=1 type command
Payload written by an LLM https://unit42.paloaltonetworks.com/npm-supply-chain-attack/

but i don't think the back end reader system has sql
right, but that value is stored in a section of the tage. can that section include an injection command
ah yer
anything is possible
but it would have to validate it some way. i wonder if theres a standard or if its manufacturer specific
We're all cooked
You gonna make a master key ?
yer i guess that is the general idea
Thanks Guys
just rerun it
i ran into this same issue
I'm going to try that at the VIP night club. When I approach the bouncer and he says I can't get in I am going to raise my finger and then say OR 1 = 1
bouncer = bouncer + $20
OR bouncer.health = 5
bouncer.health = aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaA
Segmentation Fault (Core Dumped)
SQL injection via sign language
i wonder if sign language violates the "only english" rule

Hello, I want to make a Bad USB as my first 'project' and test it with different things on a home environment. I want to do this practical stuff as I get overwhelmed of too much theory, what I want to ask is if these type of projects can count as well for a potential future job? Can you give me as well some other examples of beginner-friendly projects, practical like this one ?
no idea about future jobs but the project sounds like fun
perhaps a keylogger? or is it too simple
which OS u are using?
previous message not very beginner-friendly, use docker install Juice Shop and play with it
try to complete all the flag
I want to do basic stuff, I have no experience. I just want to build it and maybe do more stuff when I am more capable, but I want to make something like a 'portofolio'. I was curious if the employers care about this at an interview
which os are u using?
I will buy a cheap laptop for this, and install linux on it
I want to make an environment for safe testing stuff
then download arch linux it's also a project....
Anything is good, I never did that ngl.
So configuring it would help me, or what ?
yup
arch is little complicated then other linux...
btw anyone know how to get subcriber tag... on bio
gotta /verify
@hazy gyro
ok
meanwhile archinux
:
π damn! i didnt know this principal thanks for telling me
Sound like a case for the authorities
i wonder if its the real tom hardy
arch linux and simplicity doesn't co exist 
At this point I don't think there's are good or bad project for your portfolio, just go online and search what you like and learn a lot, when you have good understanding of stuff, project will comes to your mind without even asking, you will dream them at night ahaha
Its the same for me. Its kept reloading
Try reloading your browser
restart solve everything
oke
i mean reload
Gave +1 Rep to @latent leaf (current: #1622 - 3)
Gave +1 Rep to @rotund linden (current: #3290 - 1)
welcome
what is this guys?
useless internet points
u broke my all feelings
well, you asked what it was π€£

I accidently delete /etc/resolve.conf
Can someone help pls:((
:hammer: tomhardy0215#0 has been banned.
not really recommended but try restart the service
sudo service network-manager restart
resolve.conf gets autogenerated on reboot
do you have resolve.conf.d or just a static file?
sudo rm -f /etc/resolv.conf
sudo ln -s /run/systemd/resolve/resolv.
I just this command before
And this mess up:((
It say network -manager.sevice notfound
Why u delete your dns

HAHAHA wat da hel
Create a file again
touch /etc/resolve.conf
and put any dns you like there or ur isp dns router etc
If you don't know rm means remove generally and -f means force
and the ln -s u type is used to create a symbolic link (or soft link) to a file or directory.
It somehow say file exists
But it not:((
sudo ln -s /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
sudo systemctl restart systemd-resolved```
this what u did
Yes
Anyone knows how can I remove my THM profile photo and get the default one?
Find gif image then change to .png
sorry there no option for that
But you can ask nano gemini to make one default pfp
π€¨ Sounds weird to get a gif image then convert to png
Ah ok
Yeah your pfp will move
hahah try it if u are curios
.gif to .png
Oh i just realize kali dont have autoresolve thing:((
I have to create another config and it work:))
Good thinking
hey gusy
Hi anonymous

Oh btw why every pc dns are 8.8.8.8 or 1.1.1.1?
8.8.8.8 is from google and 1.1.1.1 is from cloudflare
Oh that why
Each dns Provider have different services such as adblock, block adult site, block malware. phishing
Oh wait so maybe i just miss some protected dns cuz i just add 1.1.1.1 and 8.8.8.8:(((
Only you have to do is to choose your favorite DNS provider
like dns.adguard.com if u don't like ads/popup on phone
Yo, so i can manually add addblock on phone:))?
Yes exactly
Yooooooooooo
Sup everyone. Working on anything interesting?
nah just woke up
nope just making a program to organize my files
39β¬
After shipping 54β¬
not bad
Cancelled
Up to 3 days till refund
xD
Newbie mistake
I mean still it was getting avg 100 fps in benchmark
If I'll fail to cancel it ok I'll use it anyway then
Nice
I'm dyslexic or something
I swear I saw 8gb in title firstly
Did you read other people review like the lowest stars
if its legit or not
When I'm going to shopping online i always look first the 1 star review
Mostly the 5 star review are generated or even fake comment
That's private seller
But their star rating is about 4-5ish
I got also buyer protection so if card is fake I can refund it
Within 30 days window
Or I can cancel which I'm trying
Anyways 54 eur for this is good deal so if I'll fail to get it cancelled I'm ok with it
Will have almost everywhere stable 60 fps
Atleast in games I'm playing
Hru everyone
Such as MC, Omori and Escapists 2
I don't think it will have issues with 2D xD
And MC is running ok depending on chunk ammount almost everywhere
Any book recommendations? (I already have THm)
good mornin' everyone!!!!
Mornin mate
Is this flags near name like new trend or sum
i thought i had work today... turns out i accidentally booked it off
Lmaoo
what a nice surprise
Whats ur work
Lol
Happens
Oh nice
everyday is a holiday innit
Software engineering is calmm
nah am joking hahaha
What parts of UK u from
Manchesta
Got 5 layers on rn
π π
Even though it feels warm
This is beautiful weather imo
hahaha, ive got the heating on. I'll forget about my gas bill
π€£
until it comes through, then ill cry
Software engineering must pay a bit right
Hahahaha, nahhh. I'm not that sort of British
I bet Russia must be much colder, eh?
why say this? you working in it?
Can I know how you review the section after finishing it? Do you write notes or make mind maps because I don't know how to review and I feel it's a waste of time when writing notes?
writing notes is absolute key
Sup sup
hi bella π
how are ya
Feeling gooooood, making people mad while enjoying life is the best
Good say I write notes when I review it and how many times review it
until you grasp the concept
having fuuuuuuun on your vaca?
and understand it
Like I'm just standing here listening to music waiting on my train and people are mad for me not being contactable
writing notes is definitely not a waste of time, rephrasing sections you read will make it more likely for you to understand and remember them. Making sure to write notes in your own words might even eliminate the need to go back and overview the notes after the session is over
i dont review my notes. i just refer to them when needed
On my way to get some cool new pants

noice π
I soooo want to train hop
Yeeeee, some fluffy hello Kitty pants
yayyyyyyyy
Like, I'm not your servant/emotional support bank anymore
Ok ty
Gave +1 Rep to @velvet gull (current: #539 - 13)
THEY ARE SO COMFYYYY
Hi guys
hi
Just found out about this site and is having so much fun with it, want to work as a pentester later on, u think its possible with enough time on the site ?
youll probably need some experience and certs but yer, thm is a good start
Ty man, u work in this industri yourself ?
Gave +1 Rep to @sturdy sequoia (current: #146 - 65)
i do general IT jobs, not security related
Ohh okay, i never get a advent calender myself so will be alot off fun with the one coming up now
thm is a very nice start
ive got a notebook just for THM haha, writing notes is king (for certain learners)
almost filled it up
i didnt write notes for like 2, 3 years while doing THM
i lost all that knowledge
i only know concepts but nothing detailed
Yeah, I think application is still key when learning
Site is amazing tho, perfect combo off learning and applying
I probably (as much as i hate to say it) dont remember most of what ive written down, until i reread it as i just havent applied that knowledge in anyway
at least you have it somewhere
being able to refer to notes is way better then going off googling
Well everything is rehersal i guess to learn
imo
I havent studied since i was 15 tho so after 2 hours i notice that i read to just get done so then i stop cause u aint learning anything then π
yeah, I do agree. Also, not just copying what you read and writing it straight down.
Try and put your notes in your own words, at least for me, it helps me have complete understanding on what I've just read
taking a break is key
i gotta start doign that haha
I keep trying pomodoro's but then I go straight into a 3 hour session and mess it all up haha
Haha
Well I'm still on the learning off the internet and stuff so right now i don't understand to much but i mean its what u put in everyday that gets u forward ππ»
Exactly, best of luck!
Thanks man
Gave +1 Rep to @brittle sapphire (current: #1304 - 4)
Do you have any IT background?
No not at all, i have 4000 hours on csgo but that it π€£π€£
heyy guys i'm looking for a game partner in 20+ anyone can be here so dm me
well that shows you can put a lot of dedication in something youre into
will be keeping my fingers crossed for 4k hours on thm for ya lol
what games?
Thanks, he i guess so, been stuck in the site for hours every day now so eventuelly i will get there π―
Gave +1 Rep to @velvet gull (current: #500 - 14)
same question
grand gangster war
is that a mobile game or sth
yep
One thing THM does well, is it's not JUST learning. You can also do CTFs. I feel like if you did 4000 hours of learning you'd get burnt out quick
i think i used to play some gangster war game back wehn
I think it's a referral scam thing
Not a scam haha but money making scheme
damn on mobile i only play project sekai π and sometimes go back to MOBILE LEGENDS BANG BANG
i play coin dozer on mobile
Ye for sure bro, u gotta change it up, but gotta start with the basis and go from there π
used to play clash royale but that game is dying
I used to play a clash of clans like game, and I dropped too much money on that game
Never again...
any helldivers fans?
As i understood it the advent calender works like this, u do a task everyday and get a raffle ticket for every days complet mission and then in the end it is like a lottery or ?
Yer pretty much
yeah basically, each finished room withing the aoc event gives u a ticket
Ohh well thats very fun
yeah it is, will you be participating?
Ye offcourse everyday π
lessgooooo
Dont get a advent calender in real life so gotta take what u get π
They sold physical ones on the site but they sold out quickly
Ohh thats cool
I want to buy some hacker stuff but then at the same time it feels like what will i do with it that will not get me in problems π€£
btw bit offtopic - would any of u guys be interested in checking out my resume to see if its nice lol
Yer they can be noob traps sometimes. Definitely do your research before buying anything
hello everyone
Ye surely
But i can imagine it is very hard to win anything in the advent calender even if u get all raffle tickets, alot participating
yer its all random and there are lots of people on the site
π΅π± POLSKA π΅π±
australia
Ohh nice love poland, australia is so cool as well
Hey guys
Yo
shit i dont have nitro anymore
netherland
welcome to the broke gang
Nice man
I gotta beg people again
is there anything like support?
u gotta get a cat, you could sell toe pics
what kind
you have this one
i got billed twice for a one year subscription
thats mostly for payment inquiries
What command do I use in the nmap tool to scan for open ports?
nmap {ip}
π
Alright guys need to get going, take care
ohhh yes good one
thanks
Gave +1 Rep to @slow cloud (current: #50 - 215)
Its okay, I just cant read.
connecting via vpn
Can anyone help me with an sms bot
a what?
what are u using the bot for
SMS spoofing bot
Take over
that sounds illegal. illegal activity isnt allowed here
Ok here we go again
this is an ethical hacking server, you won't find help here
Okay thanks
wrong sever π€£π€£
Are 'can you hack x for me?' messages quite regular?
couple times a day
anyone ever got KDC_ERR_PADATA_TYPE_NOSUPP when running Rubeus in Exploiting AD room?
How fun!
it is, gives me a chuckle anytime I see it
yep, usually means the DC doesnβt accept the encryption type. try forcing /aes or rc4 in the Rubeus command, fixed it for me in that room.
had that issue too even after trying all enctypes, what fixed it for me was getting a new TGT first then rerun rubeus. guess the ticket was just messed up before.
I'm making a request using a certificate, running rubeus should generate the ticket
I don't have a tgt yet
Switching enctypes didnβt fix it for me either. I grabbed a fresh TGT then ran Rbeus again and it stopped throwing that error. maybe try that if you havenβt yet, worked on my end.
iF youβre going the cert route you can grab a TGT with PKINIT. in that room I used kekeo to request it with the cert, then loaded the ticket and rubeus stopped complaining. not sure if thatβs the intended way but it worked fine.
apparently PKINIT seem to be the issue on my case
KDC_ERR_PADATA_TYPE_NOSUPP usually means issue with PKINIT on the DC as stated from rubeus github page
Yay that makes sense PKINIT is kinda picky in that lab if the DC isnβt allowing PKINIT for that user cert combo itβs gonna throw the same error no matter what enctype you try. in that room only certain users were able to do PKINIT so I had to switch to a user that actually had smartcard required enabled before it worked
okk so I'll try to add t2 user to Admin and RDP group and see if it works with him
just heads up tho PKINIT doesnβt really care about admin RDP groups you can be potato tier user and still do PKINIT as long as the cert is mapped right smartcard required AD perms donβt hype PKINIT cert mapping does kinda one of those Kerberos moment things
Hello! asking for help I'm quite confused right now, I followed the instructions but there is still no session created when I tried exploiting.
[] Started reverse TCP handler on 10.65.82.185:4444
[] 10.65.148.12:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[-] 10.65.148.12:445 - An SMB Login Error occurred while connecting to the IPC$ tree.
[] 10.65.148.12:445 - Scanned 1 of 1 hosts (100% complete)
[-] 10.65.148.12:445 - The target is not vulnerable.
[] Exploit completed, but no session was created.
10.65.148.12:445 - The target is not vulnerable. ?
Metasploit room?
yes metasploit room
any hinto on how to do this with kekeo?
Change your target machine terminate other machine
the target IP address is 10.65.148.12 I set my RHOSTS to that and may LHOST to the IP address of my attack box which is 10.65.82.185
you just load the pfx into kekeo then request tgt using the domain user that the cert is mapped to basically kekeo does the pkinit handshake for you so kerberos stops having trust issues lol after that youβll get a kirbi file then just import it and run rubeus again thatβs when it finally behaves on that room at least thatβs what worked for me
Thanks I'll give it a try
Gave +1 Rep to @pine condor (current: #1304 - 4)
I already tried that still the same output
each task have different machine
You are targeting a previous machine i guess
Yeah the target machine was from the scanning part
my bad, thankyou again hehe
wohoa
hello gents
Any Swedish lads here who have an overview regarding the pentester salaries in Sweden? Would like some advice in regards to how much money I should ask for in an interview tomorrow afternoon. Slide in my DMs / reply here, whatever
I've got 3 YoE, great references, OSCP, SCS-C01
much love
Look at unionen.se for salary references
I
I've done this before (checking various online sources) and while its helpful, in the past, what helped me the most is just talking to people
the online figures can be a bit misleading (in both directions)
It also depends where in Sweden
well, Im not actually in Sweden, but in Czech. I'm trying to figure out what I should set as my daily rate
I'm gonna be a contractor, external
the numbers on unionen.se is based on what their members report every year. It is a farily good source
aight
the role is fully remote
so ideally I should be cheaper than a local, but only by a little bit
Consultants are more expensive than local
contractor =/= consultant
Because they either hired experts or temp
hi ! in the room of powershell, I can't place any orders; this message appears: captain@THEBLACKPEARL C:\Users\captain> Get-LocalUser
'Get-LocalUser' is not recognized as an internal or external command,
operable program or batch file.
what is the problem plz ?
Are you in a powershell cmd?
I work in a company where we have heaps of consultants in all departments and levels. They are more costly per hour than an employees.
yes
obviously, but it also depends how many hours they actually get to work
Doesn't seem like it from the text you wrote. It should say PS before the path.
Charge a lot, they hire you for your expertise. They can get an intern cheaply
yeah but what is a lot lmfao
I was thinking 300 euro / day
is that too low?
A DAY
nooo
Our devs that are senior have 150β¬ per hour in fee to the constulant company
LMAOOO okay
I mean I will also base it on how much work they've actually got for me
ok, how can i do it so ?
if its 3-6 MDs per month, I will upcharge obviously
if its effectively full time work, I could charge a bit less
In sweden we look at hourly
no, I'd be a B2B contractor
So present hourly and full day price
300 a day is crazy tho
i get a little over half i think
or a little less
not quite sure
He will be richy rich
not quite, its a small company, I don't think they are looking to pay me anything THAT amazing lmfao
I need to striek a balance
will see
just talk with them about it
I make 35β¬ per hour, but I am not a consultant
im sure they have a number in mind
jesus
π
thats quite a bit
thats gross? as a full time employee? you're swedish I assume then xd
right
i think you also are a bit older ( no offense) but that impacts the pay
I have fixed monthly
I'm 28, with 3 YoE, and in Czech I am top1% ish earner
yep same, roughly 17 euro an hour i think, for my first full time job position
on full remote
ngl 60k sek per month gross is hella ass
actually
in sweden
LMFAO
horrible salary
IN SWEDEN
HELLO
YES
40% tax
- living costs
sweden isn't cheap
Imagine doing highly specialized IT work, living a regular middle class life, and at the end of the month you can save maybe 500 euro
tax here is 30% i think
On what?
atp im working mcdonalds lol
on gross income, no?
33
...still communism
thats normal
my effective taxrate is about 12%
I make 4200 gross / month
I get to save upwards of 2k euro per month
It depends on where in sweden but somwhere around that
It depends on the company but in Cyber, quite good pay
then you would like my team
keep in mind, im 22 and this is my first full time position so i would say its pretty good
π
THM just needs to improve their attack box's and virtual machines for the challenges and walkthroughs that is my only complaint as a premium member.
using your own VM is reccomended over using the attackbox
i have a aptitude test tmrw can you all help me how to cheat
pleasee...
js drop the tool
drops the tool
Im good i am done with VM nonsense their's is fine just minor tweaks is more than enough.
may I send you a message? I'm still stak with Rubeus
Tell me what the test is about
about aptitude 
Sorry. Meant to reply to the original message XD
lol what?
bro...
Is anyone having connection problems with THM's free VPN?
@marsh lark I bought annual. wanna check out the new red module for web
oooooooooo, nice π
oh
prolly won't touch it until jan 2026
Wanna focus on htb for a bit

I'd love to try out some boxes tho. ngl specially the ad rooms
indeed
Its laggy haha sometimes the fire esr browser freeze .
https://infinity.cyberwarfare.live/pricing $1/year ALL LABS ACCESS
wtf
./Infinity-logo.svg
yeah but cyberwarfare sucks
That could be true but it's $1. Wouldn't hurt


