#general
1 messages · Page 2121 of 1
I think it's a site problem
Its not for free right?
是的
THM account or verify token?
Acc
Account is free
As well
You dont know the amount of happiness i felt
Task 8 of the "Network Security Protocols" room – after starting the machine, the split-screen view is not showing. How can I complete this task?
help
i mean Use your own VPN + local machine
How can i access metadata of a photo? Like just click details?
it's actually try hackme UI issue,not your fault
use exiftool on kali or any linux machine
Pretty much
Exiftool
Binwalk
Cant with windows?
Oh. I am late
use like this
exiftool image.jpg
u can use wsl
Cyberchef website
windows subsystem for linux.
Ain't it awailable also for windows?
if your only goal is to see photo info and you want it as easy as possible, cybersecurity is likely not for you
i never used exiftool on windows so don't know exactly
I am really curious how admin.tryhackme.com was configured....
I want one for me as well
Yup, there is
https://exiftool.org/install.html
@kind lindenBut when I executed ssh 192.168.124.148 -X from the attack machine, it returned:
root@10.65.144.104: Permission denied (publickey).
Either 302 redirect setup or simple JS - I did something like that with javascript a while ago
you entered any password after that ssh?
Is it key based auth?
yes
you need private key to access that machine and login
First do
chmod 400 private_key
And then use the private key for auth
Ssh is very particular regarding private key privileges
Hmm....
Won't it cause any copyright?
It's on a web server - uses 301 code to point to the place
Why? It points to the original video
Hmm.. nice.
Thanks for the info.

It ain't no wizardry pal
Just a pesky 301
I didn't dig deeper earlier
Well, might be a dig said something. I should have dug earlier
What is thr least requirement of the windows version that you gotta have to do ethical hacking and osint?
8 GB RAM
you don't need windows
Dig deep into HTTP Headers
Wdym llol
What if i cant download lin
Yus. U need Lunix
it's just 3commands for wsl in windows
I can insert my photos and stull be safe?
windows sub system for linux. means linux inside windows
Strongly agree mb
You can get a VM/WSL
Femnboiificiation
Heck bro dont laugh
There's no Arch wsl iirc
It won't
For a reason I guess. They are too busy compiling things in Rust for the German Government
POssibly
Oh cloud?
What?
It's not true right....?
Damm, they can carry more than one tab of edge?
Cs better
CS?
Counter strike
Ngl I wonder if someone did it
now i got it why bro wanna use windows that much
Seeing your pfp u play with humans I guess
I really don't wanna know
Bro someone tell what is the least requirement version of windows that you gotta have to do the stuff
Hey guys, can I ask you guys something?
Depends for VMs?
And which one do you have?
I never, I love humans
Don't ask for PII
No i i cant install linux bcs i dont have permision. Also im not that great at computers so id be like a lost child in a supermarket in linux
No || jk, don't ask to ask ||
No no, I won't ask something that difficult haha
Uhh.... Just answer my question
lol
Don't have permission?
What?!
so u can use VM(virtual machine)
hypothetically, if I find a mistake in a room? who I can talk to?
I mean, if you're really dedicated I'd say you could possibly do something on MS-DOS but definitely some more recent versions will be better
Linux is not a supermarket 
Echo
Support/ #room-bugs
Nah like i can learn linux but not the other person who uses the laptop for just fun
thanks guys
linux is a morgue
You'll get better answer with THM staff and not mods
Ohh
Dayum
What about arch Linux
wishing this upon my worse enemies
umm, I can't post anything in that #room-bugs , it says I don't have permission
arch users are cursed to not get girl friend or wife
That's why they become femnboiis
Youll start swearing in your mind if i say btw
It needs a grown man to become the best girl
Pentinum processor?
Nah
how can I do that?
I installed Arch recently 
Im talkin about windows version
May i dm you?
@coarse hedge on his way
No need to, really - Is it 7 or XP?
Sui
10 would do. Even 7 but it reached it's EOL already
I am hoping for a free nitro
I hope it's not vista
Then hope all you want
in Account Details then I add my discord account name into it right?
btw buddy. i was in diamond rank of apex legends, grandmaster 4 in cod .and sacrificed all and installed kali as main os just to learn hacking.
Don't have fake hopes
That's been happening for the last 7 years....
Joined several servers when I am new to discord, got my account deleted and I am here
Dayum man. You sacrificed way too many things. Meanwhile I just sacrificed my health and mental peace
Earn more, Die Young
Hello here. I'm Rydan
Gottem
I got it
Don't share here
and now i got job, and a pc with rtx 5060 ryzen9 and 32gb gigs of ram, with rog gaming router at home. That's the reward. And still playing cod
I dont have nothin. The main problem is...i rather not embarres my self
You don't need to go to the bot channel, you can do it anywhere
What a scarifice hexr respectable my man
I got a pc, a job and kidney stones on the way
Type 2 Diabetes and Kidney stones are typical diseases of people in tech
don't worry buddy, u will get the reward for sure
I am trying to like the pain
yall talkin about j*bs
Might that be a reward I guess
Damn verizon outage?
Gl US peeps
We are aware of an issue impacting wireless voice and data services for some customers. Our engineers are engaged and are working to identify and solve the issue quickly. We understand how important reliable connectivity is and apologize for the inconvenience.
Thanks this is cool
Gave +1 Rep to @kind linden (current: #316 - 30)
Soooo, i cant do anything with windows suiii?
You can
lmao. No no you can do this
I will be joining soon 
You can still use TryHackMe, and install WSL to use Linux in a way
Welcome to the party. There is always room for more
W did a room
Has anyone heard about Where Winds Meet game?
New PC game, where you can fight with ducks
Trust God. And enter
sudo rm -rf/
Bye
yea 112 gb
It removes all useless files and gives mental peace
Yeah the girls go for the Gentoo boys
guys please its normal I dont want to study cybersecurity 101 is borning ?
normal ?
Cybersecurity is a boring field yeah
My friend uses Gentoo... Girls are afraid of him
Hmm... Looks cool and like me
Even pentesting is mostly writing reports
I dont feel is boring in the hacking way in the fundmentals way
No they're not, they're just in the queue
It's boring but you have to do it
You need fundamentals to know what you're doing. Can't hack something complicated if you don't know how networking works
Ahhh damn u gave me trauma. My last Pentest is like this
i can but i'm male so sorry
Every pentesting is lol
Find more findings.. write long ass report
Takes away the motivation to find things
It's entry level stuff. You really need to understand it. It's not too hard. Go through it, and you'll find progressing through the fun stuff much easier
Probs depends on a person, but it for sure sometimes gets boring
Otherwise the you have to obey the CIA
its not hard
GRC is boring as hell, but I love the rest of it
White hat... Ahhh..
Black Hat... Ehhh?
I Have little experince
it used to my favourite movie
But for most people starting out it's boring, is what I mean
No, it's not. So it won't take too long 🙂
Damm, agree
RE is interesting
what u mean by thatr
that
Yup, it is
Past doesn't matter..
That's what she said
You'll go complete the basics and then you'll be able to get on with what you really want to know
RE is fun when you're good at it 
u are not married for sure
No problem
Yus
I Have little basics
@proven quartz May I DM I wanted to ask a server related question?
ask any question u want. and i'll try to give the best possible way to learn
There are two very special languages
Lingua Moronica : Javascript
Lingua Satanica : C++
I like both
start with c
SoC
Yus. Currently understanding browser security
you will not like those anymore once started learning
fun room man
CPP I know metaprogramming is bish
JS is held by object corruption shit
Reason why CPP is used for Obfuscation
Which best method to start learn hacking? Courses ? Or webs ?
U type different things and execution will be different
Compile time shit is different
At runtime it executes things differently
I started with bug bounty and don't ask what a bad time faced back then on xss
It's a job I don't like
learn your own system first
U are basically working for free most of the time
like linux, cause it's gonna be your daily friend
I would rather learn Turing machines than BB
learn linux file system, commands, then bash scripting. then move to other programming or mostly logics of attacks
is thm slow or is it just me¿
TCM Linux 101 will help here. The instructor for that course is badass
hacking isn't just using exploit.py for a CVE and get a shell, it's about manupulating systems own feture or rules
:c
Is there any channel explain something like this ? It is hard to start directly without sources for explaining:)
Damn, monero really skyrocketing, wtf happened
John hammond. Or best guy is ryan john
Any good resources on how JWT signatures work? I have trouble understanding how they provide authenticity and prevent the header and payload from being tampered with
Hold on, lemme find something
Thx 🙏🏻
Gave +1 Rep to @kind linden (current: #312 - 31)
Also TryHackMe has rooms on it
And not to advertise, but I recall I once did a video on linux filesystem iirc
i got some which i used to learn
1.Auth0 – JSON Web Token Introduction from https://auth0.com/learn/json-web-tokens/
or try out jwt.io – Debugger + Explanation from https://jwt.io/
I read this but couldnt make much sense of it. Lemme read it again
Read RFC
Best is
Don't scare the newbies kekw
idk why i'm sharing this but i learned most from here https://www.youtube.com/watch?v=7Q17ubqLfaM
JSON Web Tokens (JWT) are talked about all the time, but what exactly are they and how do they work. In this video I will explain in depth exactly what JWT is, how it works, why it is secure, and when you should use it. We will go through multiple visual demonstrations of exactly how and why JWT works. We will also compare JWT to the more common...
Ain't scaring them
are there any rev-engg labs on THM?
They should learn to look at text
Yup a bit
Tired of seeing people who watch videos and think they are heckers at work
links or labs name?
Hold on
And cleaning up their messes
A question:
Why do we need Jwt?
What is it solving that cookies didn't solve?
We need JWT so a server can trust who you are on every request without remembering you.
Thanks @echo sentinel @kind linden
Gave +1 Rep to @echo sentinel (current: #72 - 154)
Gave +1 Rep to @kind linden (current: #309 - 32)
damn i never thought of this as well when i was learning JWT 💀
That thing cookie did too
My mentor slashes me with such things when I say that I learn something to him
cookies do NOT define how trust is verified.
Ehh? Cookie is pretty trustful
https://tryhackme.com/room/basicmalwarere
https://tryhackme.com/room/compiled
https://tryhackme.com/room/reverselfiles
https://tryhackme.com/room/0x41haz
https://tryhackme.com/room/reloaded
This room aims towards helping everyone learn about the basics of "Malware Reverse Engineering".
cookie → session_id → database → user
but jwt is like:
JWT → verify signature → trust
t"h"a"n"k"s
damn the bot didn't count this good
thanks @echo sentinel
Gave +1 Rep to @echo sentinel (current: #71 - 155)
That's not the main part
Cookie tampering can be provided if the cookie is too sufficiently randomized.
Trust verification is the part of authentication. If we are thinking as part of Authorization and authentication. Things are different
see cookie is like
Cookie: session_id=abc123
means If stolen → full account takeover
server-side trust = single point of failure
Doesn’t scale safely
but jwt does something special:
JWT is not inherently safer than cookies — it is safer against a specific class of attacks.
it's like: Authorization: Bearer <JWT>
Browser does NOT send it automatically
Attacker cannot force the browser to attach it
Cross-site requests fail
No session DB
No session ID reuse
No central session store to leak
so
No session fixation
No session store compromise
Yes this is it. Browser sends cookie at every request
You cannot stop it
That's why tokens came
yeah that true
The rise of APIs had a role in this too
U need some sort of identification for server to server communication without fcking your infrastructure and it's architecture
This is the second reason
These intricacies is what one should ask when trying to understand the concept
U cannot force browsers to attach cookies at every request... What's the solution? Do something to cookies... Which led to making them SameSite and restricting it's origin
Restrict them to same origin
nice buddy, you got the perfect concept
This might help to mitigate csrf (early web devs)
Attackers... Ummm really? Then let's do CSPT
Client Side Path Traversal

What is the answer to Task 8 of the Network Security Protocols room? Please tell me. I've tried my best.

Shoot the question here
lmao, you can search online, i didn't completed the room
Welcome. I also am learning about OAuth and OIDC
That is a rabbit hole
Traditional authentication is largely not available in most enterprise apps
Damn looks like HexR knows his shit. 🫡
what's your learning methodology HexR?
I think i got it
0auth gonna be great to learn for todays web infrastructure for login
But this also leads to the localstorage issue and XSS attacks
i for got when i last used my pass
That's the standard now
And the colleges are still in bruteforcing passwords
Lol
LOL. i started learning from YT, then hacker one reports, never used any paid stuffs
and now on THM . . .
nice
but still what you aim for while learning?
like that clarity is seriously good
i never achieved that till now.
im learning cyber since Aug 2025 (paused between Nov and Dev) and then continued but never achieved this level of understanding. like you can ask me old stuff i learnt and im sure i don't remember a single bit
Know your enemy and know yourself and you shall not fear 100 battles
-Sun Tzu
Want to outwit devs? Become one
but if you don't know what you're doing, then the enemy surely can't know what you're doing either 🙂
Want to out wit SOC? Become one
problem is most people dont know themselves
This line makes me wanna grind harder. Now i will grind more certs
Self debugging malwares
😆
got CAPT certified recently now im gonna go for CWSE 😈
i feel like a wizard while learning hacking stuffs. Feels like controlling the whole system without touching. I was never good at study, but i loved that stuffs a lot
Certs don't teach much
that makes u special lmao
is that even recognised ?
This is a pain ngl. When creating it u have to debug the code which is self debugging itself
A nightmare
im too procrastinating in nature and lost too much attention span to social media to read books. like literally it's quite impossible for me to learn without watcing lectures, i just . . can't read books. i would be dead sleeping within 10 mins
any solution for it?
Read
no but its what gets you hired
Yus
idk not now but maybe in future. and it would be good if it does get valued a bit.
It's like debate between Corporate Coding vs OSS Contributions
Read the Tangled Web by Michael Zalewski
U will start to thank me
try to find out that one "light switch of your life" that one thing which never makes u boared , where u never asks for what time is it while doing. That's it
ejpt and sal1 each taught more than college lol
Tangled Web taught me more than any good web course
Found the book just now
well cyber did get me interested in this, i personally want to become long term cyber guy myself. the only issue is for short term i have to focus on SDE/SWE since cyber is hard for freshers.
Btw still never avoid college. I was in 2nd year when i got job offer from optus. And biggest mistake i took the job and never completed degree it really gonna matter when you will work people who got higher education than u. I face it daily
It teaches you
Why do u use encoding?
What will happen if there is no consensus between server and client with regards to timestamps?
Why homograph attacks work?
Why do you need to reach consensus while compressing data to send?
Why particular headers are added in request?
Why learn gzip?
so a free full web sec course looks like 💀
well having the job with no degree is still better than not having the job with a degree
it's not hard actually. It's just that confusion
Web sec courses only teaches you the what and how. They don't teach you why
Depends. Generally, degrees scale pay way better over time.
that;s true but still. I got a guy in my office who is from MIT and when he asks me about my education i says "high school pass out"
cybersec is treated as IT job and being a cse guy it undermines my degree use and value in cybersec as fresher imo and so in long term i can apply and get in senior positions which requires skill and quality
i see the aim of book here
My mentor is like this. Man gives me trauma saying I didn't do engineering but I know this much. U have degree u should know more
He is a malware developer
BRO HOW SKILLED ARE U TO GET JOB OFFER IN 2ND YEAR? THAT'S LIKE 3RD OR 4TH SEM? u applied or something and how did you do that?
damn
Code Obfuscation using Turing Machine Principles is what he taught me
just try to build some skills, and nothing. And document everything and show to people. remember show-off matters though sounds cringe
Why programming language is called a programming language?
It doesn't require any special knowledge or skill. Getting an offer like that is being in the right place in the right time
Yus
i applied online for some jobs. but completed CEH & OSCP
im myself in 1st year and my 2nd sem starting soon. and im scared for my life to get a decent job / placement asap. here the job market conditions are soo bad in tech that people literally pay for unpaid internships only to get some trash certification saying they "worked" at ZYX Ltd.
CEH and OSCP gets you job
idk how the hell i got
Where are u from?
wait but i heard CEH only works in India and foreign countries don't respect CEH much?
Ceh only gets you an interview in certain countries. Ceh is bad everywhere reasonable.
I get rejected for not having them lol
🇮🇳
Ahh understandable
In the us and most of eu, ceh is a warning to avoid
i mean . . . yeah . .
In India it's popular
relax buddy. just focus on skills. and in the end even if u don't get a job u can use skills for money
just started soc1 path , and i am getting so many badge XD
U have badges. I have scars
On a serious note @kind linden u should try this too
I did that CEH cause beginnr friendly, and i was going through low confidence. Also after oscp , my company payed for my osce
Damn that's great
I needed such company for me
Do u guys delve into carrier grade networking?
idk. I was there just for AD pentest with a team
Carrier grade is when u control networks of nations
oh.
It's basic Networking -> Enterprise Networking -> Carrier Grade Networking
got it
One mistake and half the continent doens't have the network
😆
@broken plaza are u blocked?
It seems so
One day i forgot to take my laptop and wallet, endup with asking to my HR for money, to go home damn!
Damn that's must be embarassing
Signing checks authenticity and integrity of the JWT token. The authenticity is checked by matching public and private keys while the integrity is ensured by recomputing the header and payload on the client to see if that matches the signature of the JWT. Correct?
literally cooked
actually You’re very close, but there are two important corrections that will make your mental model precise and correct.
The client does NOT recompute the signature
Yus
The verifier (server / API) recomputes it — not the client.
And that leads to algorithm confusion sometimes lol
after that even i get confused
Oh yeah, since the user is the one sending the token 👍
@kind linden how did you get time to study for oscp in 2nd year college??
Yus
And it doesn't have the key
i started just after class 12th. when i was 19
completed 2022
gotcha
Man u are junior then 👀
yeah. even in my work group i'm the juniour one
I am a junior in my work group but get responsibilities of senior
hi
I hate this
Hi
Cops can help you
maybe
... Gmail account takeover?
microsoft account
check your computer first. cause nowadays hackers puts info stealer on you device and just gets info from browser cache and uses browsers like octobrowser to use those creds and immpersonate u
and gmails
Teams?
indeed i got blocked
ussian use this method so much
Yus
Baptized 
Holy water... Unholy hammer of ban
Nice choice of words
true bruh
he first hacked my insta account and started to send fake crpto and then my discord and now my microsoft 😭
Yeah. I have seen a lot
yeah check your computer with some kind of scanners or yourself, and search for cringe file or stuffs, though nowadays logos are untrustable.
2 of them are alive 👀
or inform cops
👋
+1
Only Forensics can help
For trace
Does anyone know about SS7 Exploit ?
Pwn2Own?
Chat!
yeah. he/she must inform cops
Is everyone here working in IT?
yay i ranked up
I'm unfortunately
(Sad kidney stone noises)
SS7 (Signaling System No. 7) ?
Yes
it's a controle plane of phone network
That's cool!! In my area, it's really hard to find a job
I gotta do a project with it is it possible to get acess to SS7 without spending much money ?
Where are u from?
Find a remote job
depends on the type or concept of that project
A hard thing to do
I’m trying, but I can’t. I’m desperate
Same in here
Basically I want to tap phone calls
i just realized you can't use command injections in order to evade bots
got muted twice in just 10 mins
Hello
it's illegal actually
Triangulation
🙁
https://m.youtube.com/watch?v=wVyu7NB7W6Y&pp=ygUJU3M3IGxpbnVz
This yt video i want to recreate with hod
Which country?
nope phone tapping, using ss7
But i ain't have that much money 🥲
🇲🇦🇲🇦🇲🇦
Vertasium once made a vid on it i remember
Ok my bad
it was good
I ain't good with flags
Morocco🥀
oh
Welcome to Infosec. The field of the rich
How do you get a job? I’ve been in this field for three years
Ohh
Why s ur name like that ekan
Search
yeah it was interesting how they tracked down MI7 people using SS7 tech and even got LTT doin demos on their channel
Yeh🥀🥀,we're not that popular
Ya
try understanding what my name means . .
it's for a reason
Hints
Internal transfers
CTFs
Bug Bounty Hunting
That’s basically all I do, lol
Anyone here knows how to win ctfs I have had many experience in participating but always gets in 2 digit rank what does it take to come on top 3
Where are u from,i can prolly help
Whenever i start the machine it doesnt show the split view and there isnt a button to show the split view how can i fix that
my name on this server has a funny meaning. try to d3c0d3 it
submit user.txt and root.txt and u will win
What should i use
A good team
I don’t know how to find this stuff
that's ur issue my username is itself a mini ctf lol people don't know it (this is just bluff but it does have a meaning)
My first break was purely luck
Why's ur name like that😭
Is there any good team here that i could join ?
Ok nvm
🦁
This is how its spelled
I am good in rev engineering and crypto
Im lebanese
i'm from Brazil, And there are no IT jobs here
Yo!
We have weird names
i didn't thought you would give up soo fast lmao
rank never defines your skills
Hi there!!
💀
Ik,but why that name?are u part of bashars family😭😭
ohh brazillian phonks
and one of shadows christmas gifts just arrived
Where did i see you
Yo!
True 💯
username reminds of a person in Syria long ago
Hahahaha thats syria
heeeeyy
Yus. Also the good ones are on the surface
The great ones are underground
And the greatest went rogue years ago
chocolate orange taste test is mmmmmm
can you help me??
Yo Shadow
Here heh i txt from time to time and complain about networking alot
ello ello peeps
Oh,u know badb0i?
STOOOPPPPPPPPPP
Why did u have a clippy pfp. It's making me nostalgic
Why are u qo famous
bro im a big phonk listener myself 💀
So does any1 know how to solve this problem?
uhhhhhhhhhhhhhhhhhhhhhhh i cant think of anyone with that username
it's just that people ruined the phonk's rep by making it more cringe
I know
and the way they juse use it
how?
i got m setup as phonk. I love it that much
Shadowb0rn
i just said it now
Nope
protest statement against enshiftiction of services... in this specific instance discord
My setup is plain
hyperland?
I'm the wind
for sure. but not arch
Enshittification is everywhere.... Even in cyber. U cannot stop it
Still no ✋
🤚
Guys HTB vs TryHackMe which si the best ?
Can anyone help me? I just want to work lol
Then it was not me
skills matter
HTB
can't stop it if you don't fight against it right right
Lol
Damn I gave up years ago
ur saying this on THM server i have taken ss of this
I wish i could
U alone?
now ur getting the ban hammer
Could
Even THM know this
Who?
agreed
Hello
Why
(iknowitbuttrytogetthejokebruh)
hello
Damn good reply
It's hard
hahaha no there is a huge amount of clippies working together being strong to fight the worlds state
How u doin?
f9
I guess nobody likes Brazilians lol
Wich side should i chose
Nope
I was planning to do HTB after cybersecurity 101
The side of the ICE
?
💀
I like South Americans
Start from the Academy
Seems fun enough
Love everyone ✋
🤚
but isn't it hella expensive?
WHATT
It's all fun and games unless u hear gunshots
Even me

the side that lets shadow live a private and secure life with the least amount of interactions
HTB is quite advanced for beginners like me
Nah
Oo whats that i have never ever used HTB
It's cheap for students.
Yes ofc
Seems fair
im a clg student currently how much would it cost me yearly?
U guys are good
Yeah same
(i'm brazilian)
8-10 dollars I think per month
the right that is the most valued by every human is the right to be left alone
Didn't calculate much
that's why i responded with 💀 emoji
FOR A FRICKING YEAR?
Hehe
I guess no one like north Korea 😕
ohh
A month
✋
🤚
but whats the academy
They aren't charity
sigh. . . but it's still good
Love north koreans!
Yeh,ur plans
pwn.college?
Sus
Blame the PM for this
Ur north korean?
PM who?
.....u never let them
✋
🤚
Police
Yes I am part of a group there
NEVER LET THEM WHAT
Indian PM
How
*met them srry
Currency devaluation
guys beware . . .
Is anyone here doing freelance IT work?
Why is ur president racist
Yeh
hhahahaha i don't like
Heard of Lazarus Group?
Are u presenting in BSides Pyeongang?
Nope
Oopssss
I met one in uni he is a good guy we bully him sometimes but all cool ✋
🤚
our president is black 💀 now idts she is racist lol
I did
U don't like funk
Google it u will know what we have accomplished
Lmao
Can you help me with this? I work with infrastructure, networks, and development
Ok
yes, i don't like
Maybe i can,but i'm not that good
And maybe i could cold call you
More than half of Brazilians don’t like it
Gtg bye 👋
Nice👍🏿
Gn
Bye
Good night
Just kids yeh
it's not his mistake tbh, our currency is quite over-valued and we are bleeding too much US Dollars from our foreign reserves in order to save the fall rate in reality, the currency should fall a lot more than it is worth today but the issue is that any foreign loan would suddenly sky-rocket high for our companies which would destroy almost all growing domestic industries. so it's a ticking bomb for our dosmestic industry to grow fast and strong enough in order to survive it or else it will all fall apart.
this is a bad sign guys . .
Yo chill bro ur not my target
💀
that makes this even worse (i mean being target is worst but this is not good either)
We only look for fortune 500 or something that is worth the effort
ohh
so looks we both know who the next target is looks like . .
and the reason you are in this server . .
👁️
You're part of a group or something? Sorry just got here
I am trying to socialize thats it
man what is this opsec
I am tired of being silent all these days
wouldn't you get executed if you get caught?
Not if I am using a multihop vpn
Inside tor
but you don't get to own a device either isn't it? what you get is pre-controlled by the govt.
the net, the device everything
Do you combine it with NSAs mainframe and reverse proxy kekw
and here we see a user that does not understand how tor works or how it is intended to be used
with the Red Star OS
"Type: Specimen
rarity: Common"
Yeah but we got to choose
first time seeing that here to be honest
a slight upgrade from hacking ex's
Absolutely trolling lol you're not in Lazarus bro come on
Or in NK..
how do you even get to choose when you don't even know about it because you guys don't get internet access to search lol
let him play bro ur ruining the fun
There is a software that one of the guy that developed here it does that ig proxy shit
Damm, you really have never been threatened by an "Ultra Haxor" that will for sure hack your IP from NSAs secret TOR nodes
You're right lol who am I to buzzkill some trolling
Ok good for me
Fortunately not! Though when I was younger I was stupid enough to get IP grabbed and get Ddosed 🙁
There are few number of people who get to train in a secret forign exchange program
I got into Nus
the admins would ban immediately if they know it was a real threat, and if they don't and indeed he even somehow turned out to be one of them idc because it's their loss 😛 im enjoying or learning nothing else
Learnt a about cys and got back
Damm, so now it's time to ddos them kekw
hmm
If he is, he's a pawn being used for social engineering or light ops lol
Ew no
yeah lol
ik ik, I was just kidding
suspicious
Lol
hahahhhaha
do you work in IT?
Yes I work in SOC
Weren't you the master north korean hacker 10 minutes ago?
Ok so you're not lazarus lmao
Is it illegal to enter tor browser?
Depends on a country, but if you're here then it probs isn't in yours
s that kind of infrastructure?
Nah, not itself but becareful what you come across
Nope kinda IR and Triaging
so cool, And what degree or courses did you take?
Bachelor of Tech in Cybersecurity
I think I entered illegal website, which sells some sensitive data, but I frequently closed the browser, bcs even curiousty cant explain ur position.
If u want i can share some onion links
Batman
Whats the difference between authentication and authorization?
got it... I have a degree in Systems Analysis and Development, but it’s been really hard to find a job here
Who u are and what u can
Sry Im not interested
The access by itself isn't illegal - otherwise every (or majority) or youtubers doing "Dark web" content would be in jail
So, unless you're very active or you're doing illegal things such as buying drugs then you shouldn't worry
Ngl this ain't a place to do it
Wrong tag
Ok
Based on Shodan.io, what is the 3rd most common port used for nginx?
anyone pls help me
i want to 🙂
Tysm
That was very useful
i have done
Here is your rep
Ty
Hehe
Gave +1 Rep to @echo sentinel (current: #71 - 156)
U specialized in which domain
Infra ?
Hehe
sorry i was dealing with typo
Will dm u later
Batman ignored me 🙁
thanks mate
Gave +1 Rep to @echo sentinel (current: #70 - 157)
Yo replied
😄
@naive kelp
Didnt catch the tag
Very simple
Nice
Unfortunately, I’m working with infrastructure right now… but I don’t want to. I want to move into security, but like I said, there (brazil) aren’t many opportunities here.
Who is this guy? I'm trying to find the one with the swear word "Fvck". I wanna share it to someone
Hi
i am a legend now 😄
I think L1 SOC is the best way to get into security
But If u have exp in cloud u can easily find cloud sec roles
green name forever
I am at the peak of my success in this path
Good @distant edge stay hard
And what are you doing?
@dark frost Please slow down. Further spam will result in a short timeout.
Hello everyone!

Hiiii
@dark frost Please slow down. Further spam will result in a short timeout.
Oof
Congrats 🤗
is it allowed to use zero day bugs on the challenges?
or is that considerd against policy
know that once you burn a zero-day ,it's not a zero day anymore
what do u mean by "burn"?
Zero day ain't that easy to find
But u could use it against challenges but very rare
anything you do in someone else network is logged 🙂 , and
your zero-day may be reported and patched once found
@gusty inlet ban this 
true, it's not fun to do it on the challenges! challenges are there to learn
What challenge are doing?
Not every room need it
The one I am in does
Maybe it's already open
i do HTB most, cuz it's harder
There is no Split View button either
I dont understand
That guy in the gif was a some jew
hewo

Hiiii
Hello
do you ever feel like you're lying to yourself thinking you could get a good job and feel like accepting you might just have to be a maintenance worker or a dock worker and skin fish or peel vegetables the rest of your life
rahhh
yeah no, now you remind me, this guy I was thinking of was a muslim guy
Do you want to go where Critical ended up?
What
nothing wrong with a jew
It sounds demaning and you write like that quite often
It reduces what you write about to a stereotype and signals contempt
Well put
Sometimes you have to keep your real interests as a hobby/study/pursuit. In the meantime doing a job that pays for a life isn't the worst thing, as long as you keep your eye on what you really enjoy. Just keep learning and developing and the job situation will improve
Ur tripping Math
And that you are following up with "nothing wrong with a jew" just proves that you have no clue
"Sir, this is wendy's"
But in all seriousness, I think it's some form of imposter syndrome
if anyone here is friends with Glitch. Please ignore any DMs from them. He fell for an infostealer like an idiot.
I have no idea what u even mean math
jew both crazy man
I don't see how anyone's ethnicity matters ,why bring it up if it's not relevant at all to a point you are making
I hope he understands to change every password he have stored in any browser
Damm, I did not get any cool malware from him yet
lol
thank you sir 🫡
Gave +1 Rep to @silver sky (current: #35 - 328)
I'm trying to grab the sample. Apparently distributed via Minecraft
who's glitch tho
Hmm, so a next minecraft malware mods?
Critical
oh lol
most likely just compes up with prompt asking you to open some weird web page
Depends, some would be more sufisticated
@silver sky now we can turn off his internet
Imagine if he had recived logins to his internships intra
and they now have it
I would like to have it
Doubt it, the guy is manually messaging people
I've just done an abuse report to his ISP too
the guy clicked on a link I sent him. Most likely a skid
Someone still does it by hand?
This guy is
We're talking about glitch now?
He even clicked a grabify link
Alr, makes sense
Hence I know where to send the abuse reports
Just use the proper word for it. Jew does sound derogatory, just call him a jewish guy. Simples.
yeah the person who took his account. We decided to see how stupid they are
chill
Damm kekw
Bro's indeed stupid
no jews are offended
I have done abuse reports to his
ISP
Domain Registrar
Hosting Company
Already had a reply from the ISP
So cool and edgy bro
He does not understand, he writes like that all the time. Stereotyping and using it as an identifier for a group.
It does make it ok anywhere.

ty
Gave +1 Rep to @sturdy sequoia (current: #67 - 170)
Automated no?
Nope
So they'll block him now kekw?
ok less sterotypin and more hacking plz
wrong channel for that
Yeah I agree
have you just joined ? 😄
Thm is down?
Nope
Jajajajajajaj
Lol
Corrector 😂😂😂

I know why its down for some
you have glitch as friends
pressed his link
(but no, its not down)
There might be a dispatcher (CDN) that updated and you have something broken cached
you got no respect....
Even I have but I didn't receive anything
Maybe
Lol I'm not even that dumb to click on links anywhere
Same I recon every link sent on discord and WhatsApp first before opening
This'd be an intriguing ending
Defo
Why even waste your time thinking about that bigot. He's gone, we can all move on
Shyft, you good old man?
It started from a warning about a potential malware and it went from there
Yer not too bad. Hbu?
What happened tho with him , I didn't understand/missed that part
He got banned finally
Always good, one must always be when asked. Getting late here, need do bypass cloudflare captcha. So I am digging in to that
Okay
Oh nice. Making any progress?
I keep forgetting to look in to it, but I am testing some solutions, dont want to pay for 2captcha
I am writing notes on room creation
Like to help other people create rooms? Or is this for a room you're creating? Or another 3rd option?
Jew is not the correct word for it?
Jewish guy, short = jew.
Finnish guy, short = finn
“Jew” is not simply a neutral shorthand for “Jewish person” in the way “Finn” is for “Finnish person.”
that math aint mathin
Autistic person vs person with autism debate all over again
oh so just the usual
nothing new here
same same
okay well, polling for ideas
just got the hdd caddies to get all 4 of my homelab PCs operational. they're connected to a l3 managed switch. Ideas for things to do with it?
rn I'm just running an AD environment to simulate a corporate network
cluster them
have a 4 way
teams meeting
that could be useful. I'm running a media server as well (public facing via reverse proxy, has other users), could use it for that
like clustered together rather than single nodes
yo guys i have a pdf i have paid for its on how to become security analyst right paid it long time ago never used it i wanna know how can i use it while using THM should i input it in ai or what ? just need tips, advice
read it 🤷
can i buy it off you?
bro said read it
If you want AI to read it and tell you, then you give it to AI.
Dont need us to tell you that
You think Echo will take your PDF?
fr tho, that's an option. another option I use for school material is to take the PDF of the lessons, upload it to notebookLM, then generate a podcast based on certain concepts discussed in the source material
makes it easy to study while driving and whatnot
click the generate podcast button
just as he said

