#general
1 messages · Page 1931 of 1
here we go again
@gusty inlet
autistic turtle to what
I’ve already reported earlier I think mods are asleep
You can't mention that in a discord hacking group because you know
mention what
oh, i tagged kgb before but pinged dkob in case his timezone is off.
bro I don’t know
nice spelling but it’s whatever if I get banned
I got to be careful with you ...
fr what they gon sentence a minor
probably very early for them
why cant all teenagers be as mature as you are?
i thought he was an adult
Sentenced to 5 hours without tiktok to improve attention span
No he’s 13
WAIT WOAH WOAH NO
CHILL
@marsh lark may i send a friend request? (since you've added all my friends and not me)
donut?
sure lol
ok done
Yes
huh
I’m 14 lol
Sup chat, what did I miss?
not much
oh boy, so much
Femboy spam
everything interesting
What about tomboys
Noooo
yes
Ohhhh, alrighty
femboys best
about equal
Okay, yeah that's something new
femboys a point up
0xNexion now be madly scrolling up to see what went on
Who is your pfp
Your name reminds me of a blog about a malware that was posted on the Fortinet blog
https://www.fortinet.com/blog/threat-research/iot-malware-gayfemboy-mirai-based-botnet-campaign
Bro 😭
Crazy innit?
ts is NOT a Chinese security firm ware
I'm about to
what’s so wrong
that’s just a femboy
That’s not the one I replied to
He was talking about the dancing guy
I think I have enough context
-# I think
that’s on me twin


what do yall do in ts server
Opus 4.5 made this is it good
Kiss and cuddle
This is?
Tf you think you're doing sending me a friend request
Ohhh
Website
I add lots of people for unknown reasons
mb
I need to stop adding random people
Sorry for stalking your bio, but I got the reference 🔥🔥🔥
Tuff reference

Guys listen
I am deaf though
Did you play red alert 2 before?
I'd rather not
Well, we'd love to, but you're muted
No
They tried to ping everyone
What about Nfs 2006
Need for speed underground 2 i know that
why don’t they just make it not work
instead of muting
Why do people do that knowing they will be muted immediately
I played Rivals, which was by far a really good game.
I doubt they read the rules
You have son right now if you play warcraft 3 ft and dota
Just like the people that go in tight caves and end up stuck
fuck cave divers
That actually seems fun though
Hell Na
I don't think it's about reading the rules but rather having some common sense and a bit of ethics.
But that's just me.
It’s not even a funny troll it’s just stupid
Yer that too. Some people are just...... different
Do it then
They're kids, so it's to be expected.
I would but I’m too fat. I wouldn’t be able to make it past the entrance
Ehh.. that shouldn't be an excuse though..
Bro's holding himself back
Yeah, I definitely get what you mean, sometimes questionable.
back again
I still want to follow the rules :p
Bro has twins 😭✌️
Yeah, that may be the case, but not all young individuals have fully matured mentally yet, I'd say 50/50.
unc do u not know slang ✌️
Plenty of adults who never mature either tbf
Wait there is rules here?
Some people are extraordinary and have a wide range of ... Backgrounds and abilities
Also true
There are also very mature young individuals too.
Exactly
Like donutmaster 🍩
when u say abilities I think of people ddosing in Xbox parties
Sometimes, I wish the entire human population had some sort of mental maturity.
say one wrong thing mane and my router getting fried 😡 l
And a bit of competency
We are just hairless monkeys
Anyone know how to be kinda immune to ddoses
I bet you were not present for the black ops 2 lobbies
Oh good old days
i blame the parents
Cloudflare
Firewall

oh is that why I haven’t been ddosed ever since Ive used ts
Unfortunately, I never got to participate cuz I never had Xbox live. I did however have black ops 1 and 2 along with good ol Minecraft during those days.
Maybe u just unknown
I play rainbow six siege and rust on Xbox and I got ddosed with all my rockets during a raid
😔
Not yet i am going to make your fridge show screenshots of your messages
Disconnect yourself from the internet.
So your parents can see
good
what about my e kittens (satire btw)
This made me laugh.
Yes.
Yw!
They do.
My friend connected to his Samsung fridge and let me say words on his fridge and it was so loud 😭😭
Yes to os?
Is there a way to touch grass while still sitting in my gaming chair
both. You need firmware and an OS.
Grass keyboard
DoorDash or GrubHub.
Grow some wheatgrass in a pot.
Actually, better yet, just ask someone to pick up grass and bring it to you
Unfortunately my mom’s basement gets no natural sunlight so it would immediately die
That thing will burn your bread out of spite.
Have you heard of || UV lamps ||?
Ai needs to power everything
Light burns my skin so that’s a no-go
Put it into a box.
Holy ragebait
Yeah, I'm a cybersecurity guy, so of course my house is fully integrated with AI👾
My kitten waifu steals and sits in all my boxes
your what?
How are you not a mod
Ikr I have so many e-kittens it’s unbelievable
What about e dogs
capcut
I went to bed without finishing my website today
I’m a cat person, sorry
Is this your cat?
Yes
You'll have time for it after the mods check logs
They are very cute
I can relate to the capcut once. I remember staying up all night learning fractions on top of fractions. I had a can of monster and some candy until I had a breakthrough of understanding.
Huh
Cat is super adorable, here's mine. A bit dated but
If they ban you, you'll get more time
Very cute
Why would they ban me
Thank you, I love her with all my heart
Gave +1 Rep to @hushed carbon (current: #3411 - 1)
Femboy-posting. They are trying to silence you
Literally 1984
Time to play HD Poker as 3 players on 3 accounts at the same table LOL
Rake
I suddenly have the urge to learn assembly language.
Actually, I might just do that throughout the entire night.
why is this showing up instead of my ip starting with 10
can anyone tell me whats going on here?
This happens to me when I have a private dns
instead of public ip I mean *
iirc thm gives a private ip now
I got a private ip and it starts using 192
or at least, 192.*
Very annoying for video games
10.* is also private, but
so this is normal?
yeah
Because i have root in ur system
in that case, what ip am i supposed to use for LHOST in exploits?
the tun0
192.*
oh
oh ofc, i am an idiot
if i am connected through vpn, the private ip should work
smh
yo how do i protect myself if im being targeted by cyber criminals
Hi donutmaster
that's a vague question but follow good cybersec practices ig
using a vpn
and
like
what other things
Click the link to my website for more info
dont click on dodgey links
using password managers, not reusing passwords etc.
don't click on phishy links, or download phishy stuff
good, best not to download from the start either
:D
Congrats bro you won a new iphone link in dm
nuh uh
LOL
Yuh uh
double it and give it to the next person
i am the next person
2 iphones and tons of malware for you
What if i am fr fr
i already have one
You'll never know unless you check
Well you can sell
edr?
yea
what is that
endpoint detection and response?
They didn't specify
No they're not
do they know your location
no
yeah, I think they might be bluffing lol
he sounds like a squeaker
the only reason they moved up is because they want you to be baited I think
then just block them and ignore them
if they could do something, they would have already done it instead of threatening u
:(
yeah it's not my ip lmao
they're just baiting u
ima shove that iphone up someones ass if you mention it again
Can't they ddos it
not how DDOS works lol
oh
Oh just set up proxy server for ur fridge that should do it
This guy's smoking salvia or something
Not cool
Mine would say Georgia but I live in Mississippi 😭
they think there so tuff when they use ip grabbers
I use mac address grabber
do image loggers exist
a logger, as you may guess logs something
Can you be more specific
image logger certainly is not a popular term
so u need to explain what you're thinking of
Yea you gotta open port 3389 to stop it
Can I through in a link here? It is related to THM...
🤣
I mean I'm just gonna copy paste a LinkedIn post's Link.
All the better then.
I just saw my TryHackMe ReCapMe 2025 and I must say I AM THRILLED!
111 days of nonstop hacking for a total of 114 days for the year with me being the most active in my first month i.e August. Proud to be part of TryHackMe's #CyberSecurity Journey. Anxiously waiting for2026 so I can set the stage on fire! 🔥 🔥 🔥
Bonus: I correctly gu...
My ReCapMe 2025 at THM. 🥳
No way people are sharing those
Free will
Different people like different things
I didn't even know that I used to be at this rank
That's one way to put it.
Although I'm sure that "getting babied" and receiving support are two different things.
Well ur dad has counter evidence for that
like clicking an image or downloading it gives the other person your ip
I don’t think that’s possible
yeah i thought so
this guy says hes harmful but sounds like a squeaker
Im just fucking with him rn
Why do you care what others are doing in their learning journey
Possible for links though
why?
Bored
you need a better hobby
true
Yeah, do something like this:
Become a billionaire.
Eh.. no need to comment on their learning process.
Yeah but no need to be rude about it
Everyone learns differently and at different paces
No they need to look though
CTFs
What I like to do, is solve a CTF myself, and then cross-reference it to writeups to see how I did.
can someone help me with a simple issue im having? im new to linux and THM so please be easy lol
What’s the issue?
Room: offensivesecurityintro
Task 3: dirb https://fakebank.thm/ (find hidden links)
Issue: failed connection to host it says in terminal and found 0 while there should be two?
in the terminal it says posisble cause: couldnt connect, but why? im new to linux too, so AHHHH
Are you using an AttackBox or OpenVPN?
i have no idea gang i wont lie
how do I see
how can i fix
and what does it do
The AttackBox is the one you use in the browser on the THM website
oh I tried on both
said the same thing
on on a new machine i just got
and decided to try ubuntu
could you send a screenshot?
yes just one moment !
:3
nevermind gentlemen
the issue at hand is resolved
it is simple to put it
i am just dumb
I was about to say, I just ran the command and it's working on my end
Glad you figured it out
yeah I had been mistyping the link the whole damn time 🥀
what is the job where u help old people with technology because I think I would be good at tha5
That*
I..... don't think there is a job like that
Brother can someone explain why am I having trouble connecting to remote pc access in attackbox??
Small business PC shops do a lot of helping elderly people. Geeksquad does too, but geeksquad generally doesn't know what they are doing.
Tech help?
that would be helpdesk, isn't necessarily for "old people"
Hello @hushed carbon brother here??
most of it is volunteering
what is the commmand cd challenges/ used for ?
change directory to the challenges directory
it is to navigate into the challenges folder
it is like double clicking a folder in windows
ok it means that iam going into challenge flder in my desktop
yes
ok but then how can i know or see if there is that folder in there
ls or dir depending on what os youre on
if you are on linux, you can use the command ls challenges
or if you are already in challenges you can just run ls
ok understood it i said ls enter then i saw challenges/ so that means that there is a folder called challenges in my desktop
and to enter that folder i have to use cd then the folder name / then thats how i enter in the folder
if you find a command that you don't understand, you can use man to open the manual for that command, for example man ls or man cd
yes
You don't necessarily need the / in challenges
ok thank u very much
alg
wsupp tryhackthebox people
ls depression
ls anxiety
python anxietystopper.exe
git clone https//dontpaythetherapist.git
what is the use dir,dir /a
dir is like ls but for windows

Hello
I’ve been looking for a place to learn about hacking I wanted to learn it just as a useful skill and it would help with my bad computer skills. Looking for a place to start that won’t steal all my details
I’m open to pointers or advice
Thanks : )
Gave +1 Rep to @sturdy sequoia (current: #90 - 111)
Hello
i completed all the roons in advent of cyper prep truck and i cant see the tickets i got how can i see it
you dont get tickets from the prep track
you can see your tickets on your dashboard. and you dont "use" tickets, there will be a raffle
bro make me understand this do i have to finish all the challenges in there like advent cyper linux cli shell fishing marry all or just the advent
you dont have to finish any but for every one you do finish you get 1 ticket
Bro what are side quests? Does they offer a ticket?
Have you solved any...
so now finishing the advent cyper prep truck i got 1 ticket and i need to finish others to get more tickets
side quests are tough challenges. each side quest you finish also gives 1 ticket. i have comepleted one side quest
yes
Yes they do and they are much harder than the regular quests
Okay
not a single person completed side quest 1 in the first 24 hours
Ohh looks like they are for pros...
Should a beginner try it?
i mean you can try it. but dont expect to get very far on your own
Okk bro🫡
does advent of cyber rooms can give you by chance 3 tickets max?
each room gives 1 ticket
oh ok ty
good morning
hello
@brazen egret please dont dm/fr without asking first
I’m opening spots for 4 experienced individuals only. If you think you qualify, DM me
spots for what?
spots for what ?
ah
raced
All details are shared privately
what? you dont trust a random invite from an account that was created yesterday?
what's your prediction about the mystery mission here ? "I wAnT tO h4cK tHe g0uVeRnMeNt"
haha nah i think its a lot less than that. my guess is theyre trying to stalk someone
@dark wolf what about dis one
the guy's name is matrix so maybe he wants us to choose a pill ?
I'm not your friend pal
so blue or red pill ?
alright then
Am I tho
Has anyone gotten a THM hoodie? If so, how does it fit? True to size?
I've got one from like 2020. It's true to size then. Idk about now but their t-shirts are pretty spot on
Awesome thanks Santa 😉
Gave +1 Rep to @silver sky (current: #36 - 308)
Your welcome! Ho ho ho!
i cant connect using ssh in attackbox it's been days since it became like this
are you connected to the THM VPN?
no, im only running attackbox
and you want to ssh from your computer to the attack box ?
I would try running Kali with OpenVPN to see if that allows you. Are you running any personal vpn, and what is the error?
im using the exact command provided by the room im following
It appears it’s connecting, but you’re not typing the password
The password is same as the user login, but it will not display characters when you’re typing
Use your own VM
does the task require a public key? looks like the password is incorrect
doing pretty good. u?
nice
im following this one guide, last time it worked but now its days not working and i cant complete the room
Type the password, which is the same as the login. It will not display characters as you enter the password.
Which languages should I know for programming and hacking? Can someone tell me?
did that many times, but im getting permission denied. The one i'm typing is also "tryhackme"
Python is the most commonly suggested one
ik basic py
What specific area of cyber sec are you interested in?
Interesting. To me, it looks like a credential issue: it is communicating with the server but is rejecting the login. Try rebooting your system, and launch a fresh attack box and target
Just fill in this google Docs form
Anyone play where winds meet?
This lil kitty is working undercover or must be special agent potato
It's literally in the name, he's Neo
Or just a kid trying to hack a roblox account
🤣
Wonder if he unplugged yet
Pretty good game
so who's curious enough to dm him to check what's his final goal ?
Of all the places to go and try scam someone, so many people pick this server.
Can I relink my THM account to this one? I've got another account I use mroe with a different name
Does that count as irony?
me black hat hahaha
Close enough if not
The THM account called this I haven't used in a bit
Yer but what area? General pentesting? Exploit hunting? Malware dev?
Not sure if you can do it. Might need to contact thm support. I know they can
Guess it's alright
I'm little bit confused your bio says 'Ethical Hacker' and you claim you are black hat 
Not that important lol
Dang he got us good
Yer i don't take people too seriously when they call themselves a black hat
another day in the mind of a 12 years old
I will call you ethical blackhat
no luck with this
this server is too funny every time I feel like I'm bad at anything on a computer I go here or on linkedin for a couple of minutes and my ego is restored
Is this for AOC?
youre trying to ssh to the wrong machine
your stress reliever
your local ip is the same as the one youre trying to connect to
or more stress I guess
I didn't even notice
i didnt notice it the first screenshot either
oh that's a nice one
i don't get what you guys are talking about, can you help me?
sure what is the IP of the actual machine that you want to connect to
not the attack box ip please
in the thm room there will be 2 ip addresses. one for the attack box and one for the target. your ip ends in 204. what does the other one end in?
Have you look the icon (!) below you will see other details you might used
Thanks hahah
Gave +1 Rep to @carmine pollen (current: #3412 - 1)
bruh
He give away his credentials
who is going to connect to his attackbox now
oh sorry, i didnt know
Don't do that ever again bro haha
yeah i will take that as a lesson
give me a second I'll show you
ssh root@privateip you see a while ago
here you click on the stat button
then you will see an machine IP like shown above
so next you start the attackbox
start the terminal in your attacbox
should i read everything on windows fundamentals 1? i lowk know what they are saying
then ssh tryhackme@<the_ip_of_the_machine>
not the attack box since you are already typing this command from the attackbox
Web Application Security
its good for a refresher but if you already know it then just skip it
I'm newbie too but i have few knowledge, and you should try it because its help you later to exploits windows
php and js are useful for that
like this
like skip the whole part?
Happy Friday 😛
So uh does premiums "unlimited attackbox and kali" mean unlimited time or more instances of the machine(s)
sure. skip to the end and see if you can answer the questions
thanks, i need to run the target machine first before running the attackbox thank you very much for those who help me and gave me valuable lesson (gotta learn hard)
i feel like its wasting some time
Same feeling at first
alright thanks
Gave +1 Rep to @sturdy sequoia (current: #90 - 112)
both at the same time in either order
ok
Dropped a new VM Escape and RDP hackback. Microsoft just approved them 
Is this a exploiter? There's no way to complete 600 rooms in one month
probably
he copied the answer from the web and this guys probably doesn't know anything
Happy learning and hacking 🤙🏼
Yeah probably but I think it has been done with a exploit, no way someone sits there and copies answers from over 600 rooms
the score is meaningless anyway
Well he can claim he is top 600 worldwide on tryhackme
you don't know what stupid people can do, do you ?
so? that title is meaningless
That's unbelievable stupidity
I guess
flag hunters not hacker
Tryhackme cookies should track user if they accessing the medium website
It doesn't prove someone can hack its more of a status on tryhackme
avoid cheating
the only meaning that the score / rank gives, is imho the motivation of someone to learn
exactly. its meaningless. who cares if people cheat. use the site to learn, not to flex on the internet
Why would you want to be top 600 on tryhackme and not being able to even scan a target 😂
mainly on this platform where no task is that hard and where everything is guided to succeed easily
to brag about internet points
Other need to write their experience in hacking to proven themselves and adding reputation to their cv
seems goofy to me
it is
Linking your Linkedin to a Tryhackme account your obviously cheating on also seems pretty stupid
yer thats a strange one
i wonder if people also link to their github thats full of AI coded slop
Let's check 😉
chatgpt write me 10 scripts to put on github
you don't even imagine what people does with AI for their ego
😂
LMAO
You were right haha
i wonder what its like having a world view like that. to think you can just cheat and everyone will think youre cool
wat da hellelieee
I dm the matrix guy he didn't answer (sad I wanted to be part of his secret mission)
At least you only have 6 script instead of 10
Hey , where can I buy Public IPs for my VPS Hosting. Or setup NAT since ill have less than 10 vps
It’s not my profile it’s the profile of the person we were just talking about
Alright
The site seems faster as compared to the previous 11 days
Hello guys i need your helps
what do you need help with? 🙂
Idk where to go but im being blackmailed on telegram by someone he is asking for money someone can help?🙂
go to the police
He doesn’t live in my country
You go to the police station
Doesn't matter go to the police and block them
He is say he will post my photos if i don’t give him money
Okay
I thought someone could help
It's okay let him post them I'll put a like and comment on them
It’s not funny😭
uhhh im having a stroke rn???
its Intro To Networking room btw
like do you want me to type it out in letters?
oh I remember that, the answer actually isn't the name of a layer 😄
it asks for a number??
I think they were copying and pasting that over all questions after everything was written and missed that this one it didn't relate to
They won't.
lemme figure it out
Wdym?
don't wire any money, it's most probably a scam but just to be safe go to the police to report it
They won't post your photos. It's called sexstortion. It's a common thing. They just want the money and hope you'll call their bluff.
He is not really posting it online but will send it to people i know
ok figured it out
i dare them to post mine
i would thank them for kickstarting my new career
isn't paperclip always nude?
you never know
How did they even get a hold of those photos
I don’t know man
it's fake
They will always say that but they won't
classic scam
He did show me the pics
Dude you don't know to who you sent photos like that?
what guarentee is there that they wont release after the ransom?
is it yours or is it AI generated?
glitch don't think about it, don't listen to this, stay pure
Did you send them to a woman who approached you on the internet who seemed too good to be true?
I didn’t send maybe someone took it from my phone idk i lost my gmail one time maybe they got it from there
WHO THE FUCK STORES NUDES ON GOOGLE
You keep photos like that in your phone? 😭
Dude
I don’t store but it backup automatically
Anyway dude report them, that's your only solution
if youre taking nudes, you take extra care to NOT let it touch anything related to internet
I was only 2 pics
And how did they even get the contact of your family and friends
This whole thing seems sketchy
On my instagram
It may be one of your friends or something
He doesn’t live in my country
Imma just go back to studying, hope you find a solution
Yeah
Yeah he's in Nigeria or Ghana.
I see lots of people at work fall for the same scams.
Block and report and DO NOT SEND ANY MONEY.
@rapid merlin listen to Santa, he's very wise
He is french i think
Okay😭
Because once you send the money, it'll never be enough and they'll keep asking for more
you ppl never experienced getting scammed in games lol
yeah sending money doesn't remove the material, it just confirms you're willing to pay money.
yes many country in africa have french as language spoken
Happy Friday everyone.
I wouldn’t send money that’s why im asking for solutions
I sent a mail to telegram but they haven’t responded yet
there's not too much to do except maybe inform your family about the photos. The material is out there regardless of what you do at this point, you can only do damage control.
first mistake just block and report to police
Report it to law enforcement too
Okay
bro this story is fake this is a known scam
Man i just hope it is
the scam consists in the victim to be afraid and pay money for nothing
but yes, contact law enforcement, save any communications you received from the attacker, and block them. Change your credentials on every account associated with where those photos came from.
But what if i don’t pay what they gonna do?
Move on to the next victim who will pay
they going to do nothing about it because they have nothing
Okay i gonna trust you guys on this one
likely nothing, there is a risk/effort/reward matrix the attacker has to follow.
if you make one of those 3 things bad for them, they just pass unless the motive isn't just money.
but in this case it sounds like it's just money.
Are you victim of ai that remove your c?
scam or not, it's still good to take appropriate action.
My son's computer got compromised and I just had to rotate a lot of account credentials to recover everything related to it, even though (in my estimation) they just dumped or sold the creds on a black market. The odds of the creds leading to anything significant were very low, but not zero.
guys after i cancle my subscription for a month before it ends will i still have the premium rooms untill it ends
I don't think so
I had an email account (from the time I did osint work) and the goal was to receive as much phishing mail as possible on this account so I have so many example of this
bro it's different to have a computer compromised than receiving phishing email
Yes
well it sounded like the photos were something they had stored somewhere.
even if this is true (photo stored in a cloud somewhere) there is no way that they accessed it without compromising /using compromised credentials so this is fake if the user didn't click / download anything sus
im just going off what they said in chat
Idk where to go but im being blackmailed on telegram by someone he is asking for money someone can help?🙂
He did show me the pics
assuming they're not faked in some way, this indicates an opsec or infosec compromise
either the images were semi-public and they were able to associate it with them, or they were stolen.
The reality is, he got catfished and sent them over
yeah, possibly lol
More than likely, it's very common
the internet was a mistake
😂😂😂
Hi everyone! I’m Gh0stIsR00t.
I’m currently learning cybersecurity and focusing on penetration testing and web security.
I practice daily on TryHackMe and Hack The Box to improve my practical skills.
Excited to join the community, learn from others, and share my progress.
Happy hacking!
back in my day we sent Polaroid d pics in the mail
and it was a felony to open the d package
No its not ai
@sturdy sequoia I am not disapointed right now
fuck that guy
Jesus Christ 😂
bro I'm crying
did you click on any suspicious link or downloaded anything weird ?
Idk i don’t think so
who is that clown lol
I have something like this from a conspiracy theory site
I doubt change the password of your mail / storage space from where the pics was stolen then block the scammer + report to police
he is probably from there if I had to guess
Yeah i will thanks for the advice
Gave +1 Rep to @novel ingot (current: #810 - 8)
Looks like discord
speaking of "the people that control the money"
french is spoken in ghana
in france too it doesn't mean anything I can speak french too
Doctor, your patient has escaped again.
sadly can't cure stupid
Mods are busy
Hello. Recently joined this server out of curiosity. What does it take to become a professional ethical hacker? Any courses recommended?
start with #start-here
knowing the bases of computer science before
Understood. Thanks.
Gave +1 Rep to @velvet gull (current: #174 - 57)
Well versed with that.
maybe it's not the night for every hacker
Guess not
hey
i replaced my pc case , and after i click the power button
the cpu cooler makes a huge noise and then stops
but it takes a lot to boot the bios, also my windows is not being seen , like it can't boot u[p
any reason why ? and if so , what did I do wrong ?
can it be because I made a mistake when the cpu cooler is active
somethings probably shorting you
check on the internet if your problem is a know issue with the brand and model of your cpu cooler
how many times can i retake the pt1 test
Question: What linux is most used by Pentester/hacker professionals?
Some use Kali, but some find it bloated
Just wanted to see what most of you use and prefer
Ive been a kali user for a while but want to restart on another OS (This one kinda broke 😂 )
Just use kali
If it works, it works
just keep Kali in a virtual machine and if it breaks restore to a working version
the thing is anyone can recreate kali, its just debian with hacking tools installed
just sudo apt install all the tools u need on arch/fedora/debian
Its only bloated if you don't use the apps, and they can be deleted
I mean fair, but I use Linux as actual OS too.
Dual boot, Windows for gaming and Kali for regular things.
So the reinstalling of stuff i dont mind much
Don't use kali for daily driving
exactly 😂
Also it should be in a virtual machine environment
kali linux is very used since many tools are already installed in it however more experience people prefers to use an other OS where they can manage their system as they wish like for example arch linux
Learned that the hard way, I'm on Mint now
Arch doesn't have more customisation than kali, the difference is arch forces you to build it
Bora hack?
Generally for just pentesting you want something that works out of the box
the difference is massive since you control every thing in your OS- I used Debian because I like it
bruh
How can you control the kernel in windows?
modify registry
Mint, ubuntu, xubuntu are beginner friendly
bruh what thm said i completetd ms azure path and i didnt even do anything lol
linux seems easier idk
You don't, it controls you
yes for sure
Quite literally with its ai
Blackarch seems like a fun challenge 😂
Mint is exactly like windows almost
Did you start taking notes
blackarch is no challenge, if you want a challenge, rebuild blackarch from scratch
Any particular reason it needs to be in a VM? (vs just a clean install on a clean machine?)
blackarch, talk about bloat
Yeah, i have not tried it before, I went to dabian then ubuntu
Some..... not fully yet. Working on it combined with just changing my work environment fully first
Good boy
vm is just better, more secure, snapshots, if you mess up you can easily make a new one
crazy.
By that definition, Kali is bloat as well, no?
yer kali has 600 tools, blackarch has 2800
For basic stuff you can go bare metal, but reverse engineering and malware dev, you don't want bare metal due to security issues
Switch to parrot os
you must take 10 kernels of corn and sacrifice them in the name of the command prompt
then you shall be able to tame the kernel
Preinstalled or just listed in the repo?
i was looking at that one too, looks funny also. might just try it for the funsie
Kernel goes Pop!_OS
the repos. not sure how many come preinstalled in either
or hanna montana linux 
Make many vms and try all of them
templeOS
Just making a bad joke
Interesting. Elaborate? If I wipe a hard drive and re-install (or boot from USB) and also unplug for 10 sec. to clear volitle RAM, is there additional concern?
Labubu ubuntu is where its at
you can turn easily turn off nic's in a vm
they all work. its just personal preference
How is listing stuff in the repo bloat? 😭
Arch gotta be the most bloated distro out there because of the AUR.
This I agree with.
Then you get the hardcore i use arch btw or other people thinking their distro is bette
better
i use arch btw
It's hard to beat an un-plugged cable. VM / Turn of NIC ... still a VM breakout is possible?
not just arch, every OS has that. Look at macOS fanboys
Mac isn't in the convo at all
If you want to risk and go bare metal, you can no problems
Just makers of kali and alot of cyber specialists say to use in vm for added security
The most superior distro is whatever I am currently using, easy. 
Which is 8-bit instructions?
vm breakout is posible but rare i think
just use what you personally enjoy
Plus kali vm is easier to use with internal networks when connecting to Vulnlabs
If you have stuff on the host that you want to keep separate I understand the + security ( I think ). If it's a clean host / clean install, I don't see how VM adds extra security, so that is what I'm trying to learn about.
yeah but installing everytime
thats just a hassle
reverting a snapshot
way easier
Sure.
Are you planning on using local hack boxes like vulnlab
What do I need to learn to start using arch
bro why did you change your profile picture again
Basic CLI and debugging/log reading skills.
this is the third time
I thought this one is the jolliest of them all
Is fair. The host can suck up resources CPU, MEM though. Bare metal ... you get all the stuffs.
alr what i mean is just pick one
its kinda good actually
Sorry I won't change it again
Yes.
you need to learn how to read the wiki https://archlinux.org/
its fine i mean because you change it a lot recently
its your choice
Snorting crushed coffee beans, high tolerance and bad posture 😄
No, sorry master it won't happen again
bro its fine
Then use a vm, have kali and the vuln lab .ova connected on an internal network and connect kali also to Internet by NAT
You have both under one software
Bare metal you'd need two physical devices
Yes, I have an old laptop. I'd like to allocate all of the cpu/mem to Kali, and not have to have some reserved for the host.
How do you expect the lab machine to connect to kali
Given its designed to be sandboxed in a vm
Guys I have a question but I feel it's kinda stupid
Why are Chinese have their own servers in everything like games or websites or everything they're separated from us
Faster response times
censorship
That too
Can't find what's taking up all the space on my tablet
For websites, considering majority of the servers and cloud are American owned businesses, china would benefit having their own for national security reasons
Its like south korea doesn't use Google products mainly, rather Naver
time to go live in south korea
Nah
The economy is bust
And only good paying jobs are held by top 7 big companies
dont forget the gender wars
You get that in the west
i didnt know a government could be both misandrist and misogynistic at the same time
Are we allowed to talk about Australia and the digital ID thing ?
Is what it is
not nearly as much
yes
we hate it
Ironically a privacy breach
I can't test until I pay for vulnlab (which, not ready to do yet)
Network1 > Desktop > Does desktop stuff
Network2 > Laptop (Kali) > OVPN > Does compsec stuff
Australia is fine, other than every animal wants to kill you
The US economy in the last year is just 6 big companies exchanging fake trillions of dollars inside each other
Probably not allowed to post links here
Welcome to capitalism
Oh I see, if you want to run your own home lab, and have a network with an attack machine and a vulnerable machine
If you want a home lab, you could go bare metal kali and use a nas server for vms
kali bare metal 😕
😂 I use virtbox
What are home labs used for?
you can, just depended on what the link is
anything, im planning to use it for a SIEM, NDR, EDR etc when i move out
Option 1 (three physical machines)
Network1 > Desktop > Does desktop stuff
Network2 > Laptop (Kali) > OVPN > Does compsec stuff
Network2 > Other Laptop > Acts like target
Option 2 (two physical machines)
Network1 > Desktop > Does desktop stuff
Network2 > Laptop (Host) > VM (Kali) (Attack)
Network2 > Laptop (Host) > VM (Target)
I see here how VM would save you having to need a 3rd physical machine
It was for vulnlab machines but posting it here is probably not a great idea considering the effort THM puts into their products
Can you get one to look out for you entire network EDR, firewalls, network scanning, pcap analyzing?
you should be able
Although I'd recommend learning before doing them
Would you do that from one machine or a few?
Interesting topic
Probably a couple
Since a siem is very resource intensive
And like IDS/IPS
At least ELK is
Splunk is fine, but $$$ for premium features? They want you to pay.
Better layout? I did the AOC and splunk looked like it had stuff everywhere
is ELK a better layout?
I would say so
But once again
It depends on what you prefer
Both have there plus and minuses
Try both. No penalty to trying each.
ping @marble matrix
Do you use SIEMs for home use tho?
I have not, but id like to
Since if u have a NDR, EDR etc. I would like to have all that data in a big bucket
Instead of multiple portals
I wouldn't mind setting up like wireshark or tshark and snort along with doing network scans and different IDS/IPS ones to go over my network
Idk if snort is used as a whole but learned it from here
Then why not do it? Only issue is the device ownership anf stuff
If you live with others i think you would need permission maybe. Or at least discuss it with them
Yeah need a lot of devices n I live with poeple lol don't wanna take up a whole space
I would use vms
We do have a spare room but the router is in the lounge
Makes it slower
spare room on the other end unfortunately
Do you mean VMs that run in the cloud? (on AWS or Azure etc.)
nah id run them at home
cheaper probably
since network and EDR logs can take up quite some storage
Hey

Hi, I need a little help with the room “Juicy the Dog.”
I have found some of the flags, but I am stuck on the last two flags and cannot figure out what to enumerate next.
guys is it just me or do the name of tools used for hacking so ridiculous like look
ethical*
you aware about the react server components hack
yeah i saw the cve
Virtual box, vmware, QEMU based
hello everyone can someone pls help me with this room of AOC
What's the name of this THM room ?
DuckerRubby
i found the flag already and the machine is not detecting it so its not getting completed
its the first room btw the CLi one
Systems as Attack Vectors

I solved this room already but somehow didn't notice the rubber ducky lol
Thank you
ok so i have two server one is for frontend, and you can rce into my frontend, or frontend is hacked, my backend server is separate, so can anyone access backend server or send malicious payloads, trough formdata or query params or anything that is used to interact with backend so that it will be compromised, this is not practical question, as i updated my packages, but lets say tomorrow another vuln came in with higher cvss, i know, frontend is totally doomed, like hacker can do anything means like from eaves dropping to completed control of frontend redirecting to malicious website, but i just want to know about backend, if frontend server is hacked, will my backend server is hacked, provided that my backend is a separate, written in any language doesn't matter, has good rate limiting, no shell access and waf and all, and frontend only know about the endpoint that it will talk, will it be affected??
Don't be neutral, always pick a side
frontend is nextjs vuln package, backend is anything
frontend only knows about my backend endpoint, nothing else, like no db.execute and all
lol, your welcome

You think you're better than me
"it depends". Front end will reveal information about the back end. That information would lead to people enumerating the back end. Will they find an open port, service, vulnerability? Will they find an un-protected api key, or login or cookie in the front end (or front end code) to allow access to the back end?
You could hire the contracted services of a pen tester, and they'll tell you! (for like, $1000+ ?)
I'm gonna destroy you
