#general
1 messages Ā· Page 2182 of 1
hi
Oops chimera
Im good too
good
I have been doing python for the last few days and kinda skipping on cybersecurity
Python is fun
10/10
I liked it back when it tried it. it was the first scripting language i ever used
i have not kept up though
Why nott
I don't know i moved on to other things and forgot it lol
Makes sense
@half relic (hoep that sthe right one) . I'm trying to figure out a written set of instructions by which i can say beyond reasonable doubt "This host is not tampered with", whereby i can get a figurative red light, or green light (boolean eval)
and now that i am used to more c like langages the syntax seems really weird
Im doing it rn cuz im taking a cybersecurity class THAT IS ALL PYTHON
i never tried any other language
ah now i see the connection
@west mango DPIC, and C put hair on yoru chest.
i still don't totally understand why you are looking for files that are not represented by the os though lol. sorry
@half relic Detecting PUA ..
Let me master python in 2 weeks now cuz i got a hackathon in two weeks and i wanna pass my class
@west mango Good luck š
Im sure its gonna go horribly but wtv
potentially unwanted apps?
I got a team w me
(My friend who doesnāt know any coding but will learn soon)
@west mango You miss 100% of the chances you dont swing at .. Its good to have multiple eyes on, even if you are not all proficient coders, differnet poeple have different trains of thoguht, you can probably produce something fun.
youre rightttttt
@half relic Confirm. PUA potentially unwanted applications
I will do my best
And I should take cybersecurity more seriously too i havent been taking any notes at all and i did 50% of cybersecurity 101
i didnt' take notes for the first few rooms and i should have
What do you use now? Obsidian? Cherrytree? notepad?
I'm using obsidian
i regularly switch computers and it syncs between them
i paid the yearly fee to have it sync
Oh i just use the same repo everywhere .. Almost as good
I did many rooms i think like rn im at exploitation basics the metaspolit part
And i feel like i forgot many of the past stuff just like i get the general idea
i was going to use git or subversion
git is probably better but im better with subversion commands and its not like my notes would need a lot of complicated branching and stuff anyway
Probably better if they dont branch š
yeah lol
i know someone who used subversion to keep track of his character sheets
so i wouldn't be the only one using it for something weird
lmao .. thats obsessive
I was just happy i could put them into wordstar and print em
I only played a few times
I used to play a lot of DnD based computer games though
i still do sometimes
You know i think .. amazin prime gaming gave em all away recently.
which ones
all the forgotten realms adventure ones, gateway to save frontier, hillsfar, pool of radiance/darkness. secret of silver blades, treasures of the savage frontiner, eye of the beholder 1/2/3 .. champions/death knights/dark queen of krynn , , deathkeep, menzoberranzan? dungeon hack, dark sun 1/2
i played those a little but mainly it was baldur's gate and newer for me
ravenloft, 1/2 ... shadow sorcerer, dragons of flame heroes of the lance, war of hte lance,
I did try them though
In short, all the old ones i think
Did you ever try ... dirk the daring .. what was that .. dragons lair?
no
YOu should find it https://playclassic.games/games/adventure-dos-games-online/play-dragons-lair-online/
that game was BRUTAL on the quarters
meant to deprive the player of their coin as efficiently as possible.
the older ones were definately more challenging
The biggest thing about them was .. continue simply did not exist like the modern games. no reloads, start over from the beginning of that stage for N lives, or all over again
interesting that you can play it for free online
Its practically vaporware
did you ever play this nintendo game. it was almost impossible
i had to draw maps
there were no saves
I've played just about all the nes games at some poitn or another
That was years ago boss
I just looked back at chat, are you trying to configure IPS/EDR?
@timid orbit Yeah, i'm trying to wrap my brain around how to prove something doesn't exist .. good luck right
You donāt have to⦠thatās for digital forensics (post-compromise investigation)
apparently this came with a map with the solution, but i traded it for another game and all i got was the cartridge
@timid orbit Bob Villa famously said best block, no be there.
Thatās not generally for IPS/EDR. they follow behavioral patterns
^ Before someone corrects me, I know thatās only like 10% true
@timid orbit ITs sort of a mental excercise, theres no wrong / right answers
Thatās true, but thereās industry standards and best practices. Not following those either makes you an innovator or a dumbass š and sometimes youāre both
is there a lot of risk in connecting to a compromised system with ssh or rdp. I really hope not
You can totally build high security boxes on a budge,t they dont require $$$$ in licensing to make them right, and solid ..
@half relic Depends, are you using said system to access your clients resources?
RDP depends very heavily on implementation, but with things like MFA plugins and fail2ban SSH isnāt thaaaat bad
@timid orbit I'm not talking about reinventing the wheel, im trying to wrap my brain aroudn how its done
meep moops it is the time for sleep sloops to the beep boops
just depends on the attack vector and other stuff
there is but still depends
@half relic Assume your jump box is compromised everything you connect to downstream is also compromised no? Your workstastion might be okay, but you have the mierda touch on everything else.
well i meant can the jump box or workstation you are connecting from get compromised by the comprimised system
if the workstation or jumpbox was comprimised that would be very bad
@timid orbit if your bastion/jumpbox is tampered with, aren't you also taking a long critical look at everything that host has communicated with?
Yes, you assume they are compromised and isolate and investigate.
When you said thats not true what wer eyou referring to?
Them actually be compromised
No, you ASSUME they are, and vet accordingly
You ahve to assume that you have the mierda touch, that everything that box tampered with was broken.
In ref to your response when i said this:
imera Assume your jump box is compromised everything you connect to downstream is also compromised no? Your workstastion might be okay, but you have the mierda touch on everything else
But really you only need to isolate if thereās an IoA or IoC. AFAIK but Iām still studying that and it probably depends on the company
I dunno, i worked for soc as a service type company ... we took ioc/ioa/idiot clicking the button pretty seriously
There were no shortag eof idiots
Yeah Iāve been studying for a SOC job for a while now.
Thatās why I did SAL1 and taking cysa soon
I shouldāve taken it now but meh procrastination
I took CYSA the last gen, it was fun .. I think its gotten more specialized since. (secX here)
Didyou get your voucher yet?
Yeah
i wonder what kind of job i can get if my position disappears. it seems my position is being outsourced almost everywhere so maybe not that maybe i could work for an msp or something
Iām going to be taking CS0-003
I think thatās the code
Need to do it by May
Thatās my deadline
you could go into a SOC type of roll easily
what makes you say that i have no experience
Not in the U.S.
you don't really neeed any. You have customer service experience and good technical skill
you also help customers with some security related things
HI btw
hi š
What you can do is go to like discountvouchers or something .. cheapvouchers etc .. they have a site like that that has vouchers with SHORT Life expectancy, like 4-100 days .. The closer to expiration the cheaper it gets. I think i got my linux+ and casp+ for like ... $140 ea ?
i do but we don't go very deep into that
$170 ? something liek that
SOC is entry level
Not according to the industry
does your company have any open positions lol
gah
Ah the "You want fries with that" side of it
who on earth told you that
Somebody pretty high up the chain
Said itās because of competition not because of qualifications
Wonder what cyber job they were thinking of
most jobs come down to luck and who you know
i do investigate comprimised systems as a part of my job to some extent
yup
I do incident response lol
so do I
i don't do that
I have 10 years in cyber and most of my jobs came down to luck and contacts lol
you should verify your account so you don't look like you are gonna ask us to hack roblox lol
Iām just level 1 support but Incident response and incident management is a big big part of it
Do you enjoy it?
Yes
I actually like my job too i'm just worried about outsourcing
Yayyy
cause they already replaced half our staff that way
but they kept you š
im lucky
you're chosen
i think one reason is i don't argue with them if they ask me to do something honestly
even if i think it's dumb
its not my job to decide how we do things imo
so its kind of stupid why they kept me
It's not mine either, and I argue with management all the time
lol
they expect it from me now
no i mean that's probably the best reason why they would keep you lol
i hope if they do change their minds i at least get the same severence everyone else got lol
but anyway
i should try and make sure i can do something else
you are... you're in thm
you know me, I'll tell you some tricks
and i have been doing pentesting stuff since it's interesting and fun, but i would probably do soc i think if it was my job
I need to assign a new guy some thm rooms this weekend
management approved his subscription
Oh.... speaking of which... Here is some inspiration to you all
this is the way... not the way anybody likes, but it is the way (needing to go soc before pentest)
We hired guy that had no infosec background at all. It was because he showed interest in pretty much everything, he labbed and implemented everything, and he interviewed well
He is now in IR
we will teach him what he needs to know
that's something i can do
He worked in general IT for a while
i got my current job by talking about things i did in my spare time
i think the degree helped get me to teh interview though
not surprising
i got my current IT job because i'm a part time mechanic
many paths to the same place.... many
how did that work
i am terrible with physical machines
i dont; have the spatial awareness or the right intuition
mechanical ones like cars
aviation is a whole thing, and having the discipline to work on aircraft directly translates to the discipline needed to learn the job. also it's technical, but previous IT exp there doesn't actually necessarily help. because most tools we use there are proprietary
first time i put a book shelf together i screwed it up lol
interesting
I was really good at C++ in school though so there are things im good at
all teh programming classes in school were super easy
they don't get very deep into it
but that much was easy anyway
nice. i used my c++ hobbyist knowledge to basically skip my java class and still get an A on all the exams
because the concepts are roughly the same, it was just remembering some member functions here and there
when there were coding group projects in school i usually did the whole thing by myself and let everyone else make slides and stuff to explain it lol
i shouldn't ahive but once i got started it was hard to stop
we probably missed out on learning to work on code with other people
no one ever complained though
right
because you gave them the grade
honestly, the two coding projects i had, i basically led the projects without directly leading
because i didn't want to, but i was still telling them what to do.
they were mainly just doing busy work because they weren't familiar with coding
there were other group projects where i was reallly lucky i did other people's work cause they would show up with nothing done
it would have killed our grade
i didn't tell them i just did it and when they showed up with nothing done i pulled out my stuff and said i do have this thing i was working on
ur better than me, that's fs
I'm actually glad im done with school though for reasons like that
most ppl in school aren't mature
my social anxiety never got me out during my first year, then second year i didn't live there, third and fourth year i worked too damn much so yeah
also covid first year was not fun
so i couldn't really be super immature i didn't have the chance lol
covid was terrible. the only good thing about it is how many places adopted work from home
the students at the community college actually seemed more mature than the university i transferred to
i misread that
I could have said that better
lol
some of the community college students were older though and paying out of their paycheck to go there
most of the university students had their parents paying tuition
my parents paid tuition š
that would be nice
that's one reason i went to teh community college first
credits cost a lot less
and they transferred
i got a cis degree at the college and a cs degree at the university though so i had to take some classes that were almost exactly the same but were the science version of the first class
like business math was basically precalculus but with practical examples
but it wouldnt' transfer in place of regular precalculus
what is cis and cs=computer science not cybersec correct?
ohhh i might be in that same boat
and cs is computer science
my cybersec degree was extremely close to information systems degree, and i'm trying to get into a ms cs program right now. (mentioned earlier just got rejected by a mcs program.. ouch)
so there's a lot of places i can't apply to that would be good schools
evening all
hi š
hello
is it ok to asking new questions in here
yeah you might end up repeating classes
which sucks when you are paying that much for them
probably. also a bunch of programs for admissions, i would have to post-bacc some CS courses to apply. hence why my options are limited lol
don't ask anything illegal
or if you do, use the names Alice and Bob
i am currently in the pre req for the cybersecurity path...when is the best time to try the practice things
... and Eve
yes
Gn Dkob
uhhh now?
ok lol
get your hands on some linux š«
As soon as possible
im just now entering the linux fundementals
What a lovely feeling
i have 2 more of that path before the windows fundamentals sec
Both are fun modules ngl
you can install wsl to practice with
linux is simpler than windows by miles sooo gl xD
do you use your own machine or thm
it does seem simple cause it doesn't hide things from you
and its easier to see how it works
i use the thm machine
also windows has so many subsystems it makes my neurons wanna explode
and half of them are all for telemetry
might be overengineered
i recommend installing something and using linux its more esiare
but you can you thm to
i think the attack box is convenient and if i swich machines a lot i don't need a copy of my vm on each machine
i did install one on this one though
the vm is nice cause i don't have to keep setting the same settings every time i load burp or something
with the vm from htm its not kali based...well for one of my lessons it wasnt kali
much better to install virtualbox and a linux machine
wsl is crap
that's true
i dont even know what wsl is lol
i just thought it would be lightweight and big enough to practice with
Windows subsystem for Linux
what's crappy about it?
i had problems with it
ok
ohhh ok i heard the chromebook has that built in
on some of my one liners it would cut off the first few characters of every line of output
never figured out why
ah
its not a full linux install, it just gives you access to linux packages and commands
much better to learn linux
i thought wsl 2 was a vm
it is
still good to learn on?
i still had that problem on wsl 2 though
not like a traditional vm that you can configure, you cant do both virtualbox and wsl at the same time
so you have to pick
i guess it depends on if you have resources
it uses hyperv
what paths did you guys take?
all of them
i just thought for a complete beginner it was fast and easy to install and doesn't take up a lot of space
and you can manipulate files and things in your windows install with ti
how long have you guys been using thm for learning
7 months
nice
i subscribed about 8 months ago and used it a lot for about a month tehn didn't use it again until recently lol
so not that long
im doing as much as i can before my sub expires
idk why i just made that and i am proud of it
as for me who has no major tech exp it was highly recommended
It's great for beginners
i think its sick void
The nmap on this room is taking FOREVER
i am a graphic designer by heart but i am tired of the field
i wish i was good at graphic design
im an old man so i been in it for a while lolol
one idea i had once was to build and host websites for small businesses that need a website, but then i realized im terrible at visual design and that is a huge part of it
Nice, I'm an older man
hey!
most small businesses basically need a flyer and its mostly design
yes i had the same ideas... and same realization
i dont feel so bad now lol
there are a few older people in here, not many most are in 20s or a teen
I'm 44
yea i have ran into that
so not a student
I'm 51
im 50 lol
hahhah i am older then barely
right lol
Its actually nice to find a discord server that isn't 99.99 percent people in thier 20's
facts lol
yea this one is only 99.98%
i'm half your age btw lol
lol
hey im young at heart does that count lol
do you climb rocks?
I would die
Are your guys talking about age?
naw i am a wheelchair warrior lol
is that 02 in your pfp?
nice!!
yes
i'm on like ep8 and that anime is S tier
02 got me feeelin' some typa way lmao
but regular paycheks and benefits are nice
and sales is another thing i am not good at so
do you guys game at all?
hey guy i want to start a youtube channel I was able to build a live soc server with real threat hunting SEIM etc I want to teach yall how to do the same thing would any of you guys be interested in something like that?
sometimes but not nearly as much as before
true
sure
i'd be interested in watching it š¤·āāļø
I'm playing oblivion again now
Of course, can I subscribe to your channel first?
Yes!! do that!
that's a great idea
i play arc raiders
let me get a vid out real quick and ill let yall know
Idk ... who are you?
what is your experience?
how many years of experience do you have?
I like seeing what other people do
does that matter? even if it's just a side project for somebody looking to get into SOC (which a lot of entry level jobs apparently want nowadays) then it'd be good to show
you don't need to qualify... just do it
I got my master along with cissp and a whole bunch of other certs like securityx CySa+ etc etc and i got 6 years of hands on experience
it's cool and someone will learn something from it
it matters to me
fair 'nuf
you should verify your account so you appear more legit
how does one do that?
then yea i'd definitely watch it
I like being illegitimate.
i mean i'd have watched it anyway, but i'd definitely watch if i actually think i'll learn something
All about TryHackMe Discord Server.
Hopefully this will be helpful to me as a beginner.
HTB won't let you talk at all in the discord server if you dont' verify
not that i do anyway
Ill be putting out content tomorrow https://www.youtube.com/@Budget-Hacker
HTB discord scares me
nothing is wrong with it i just haven't used it uet
im called the budget hacker no content yet though
why?
between htb and thm, imo thm feels better as a training platform and htb feels way more elitist and like everyone there is better than me in every way
ah.. egos
i only glanced at it
and i mean, they are... better than me in every way. so are most of yall. but yall seem more welcoming lol
anyone here use exegol?
THM is freindly
i googled it and i'm just finding references to star wars lol
ah i found the one you are talking about
see that's teh other reason you should verify
nice tenor link
... there, i posted it for you
thanks!
I'm too tired tonight to go through the verification process
I was looking at logs all day
sorry didnt' mean to pressure you
you didn't
what kinda logs?
@rapid merlin why you send me a friend request?
elasticsearch
he messaged me too
like... we talkin windows/linux logs? firewall logs? i mean i get they're all mixed in there
all of the above?
elasticsearch logs lol. It's a SaaS app
customer was compromised and exfiltrated files using elasticsearch
lapsus exfiltrated files
I can't type tonight
Chimera just got banned for and she is wondering which mod she can message
oof i just "for vis" in Discord
Dkob
thanks
He handles appeals and stuff
Seems like she triggered zeppeling by using a blacklisted word
yeah
that sucks š
hey you're back
welcome š
Not banned, timed-out.
i was complaining about spam
Yeah, but it seems Zeppelin got triggered by one of the words in your message and muted you
We have no autoban bot-rules. Zero. š
š
sends Chimera to the corner... You're on timeout!
We just have Dkob to handle all the bans
dkob workin OT
i should have guessed that would happen i guess i forgot where i was
i'm in other servers for games that have kids too
im so curious what you said
you have mail!
yeah
the emails you would get if you went in the chat rooms
cause someone was dming us
AutoMod handles a lot of it.
speaking of which, i still have no idea how the report system works here
Makes sense, handling server this big manually would be almost impossible
i was gonna report that guy cuz he seemed sussy in case it supports a ban later
but idk how to
You just type in /report
good night
Hi, Tim. Did you answer DonutMaster's question whether thm certs will have student discounts in the future?
Maybe when bot had a bit of a downtime
I think someone else answered it
Was it a yay or nay
fair it worked
it's 7:34 PM wym
Cool. Thanks.
Gave +1 Rep to @echo sentinel (current: #66 - 173)
Timezones my friend
you're not my discord friend how im gonna dM you
You open your privacy settings. 
I don't think it's me?
Your message could not be delivered. This is usually because you don't share a server with the recipient or the recipient is only accepting direct messages from friends. You can see the full list of reasons here:
Still you.
Right click on server icon -> Privacy settings
One of my colleagues did. š
U guys should make a more competitive ranking system like hackthebox and get swag discounts based on the tiers. I really want thm swags but can't afford full price at our economy.
life is a helluva lot cheaper with no car payment and no rent due
hence why i'm staying with my parents
despite being 40 minutes away from anything interesting
if you're gonna bless us with some cool sh-tuff like that you gotta ping me next time too
God bless America
OORAH
I'm not a marine, I almost joined...
420
I would've joined but I medically can't. Spleen go kaboom
I almost did too
Thats crazy but why are you 0x10 only i thought it wouldve been more
i thought maybe i could get secret clearance but then i realized i don't want it even if they would give it to me
I'm kind of afraid to say anything now cause i don't want to get muted lol
Metoo i kinda wated to join smth similar in my country but there is some citizenship situation that is causing too many issuesšµāš«
Is what u want to say that bad
Ohhh
ouch
burn lol im top 1500 and in top 50 hall of fame for my contry š but work burns me out so don't do as much now as i used to
ISNT 0x10 AFTER 0x9 OR AM I WRONGš
I'm trying not to get burned out so im not paying attention to my streak
nice
actually the only reason i didn't join was because the recruiter could not absolutely guarantee i'd get infantry. in fact he was pushing me away from it. looking back, thank god he did cuz i was skinny ash i was not gonna survive infantry training
Gave +1 Rep to @boreal scarab (current: #26 - 434)
you are god ig
i'm not touchin thm for...4 months
Why not
too buzz w job
not as cool as f22 but still a W

Ohhhhh goodluck w that man u tuff
hey so if a room is denied/rejected does it say if it was rejected? cuz i submitted a room and it hasn't been reviewed for months. i get if there's a backlog
I wonāt be mad if it was rejected, I would just like to know if it was so I can improve it and resubmit
For what purpose?
to future proof me when the robots take over
Hello
Hello chimera
Yup
so uh....any hackers here?
šš
Nope
Well isn't that a doozy huh?
hacking is too scary for us
Like this guy
We're just script kiddies
tht's a horrible picture of him
Iām not even that cool
and the rawest
The only thing I can hack is the website form to sign up for HTB
why do you want them to look up your nose?
So they understand their place in the dominance hierarchy
are you a hacker?
ok
Real hackers can send embed
Are you a hacker??
lol
you want them to dominate your nostrils? oddly specific.
teach me this skill, oh wise one....
This is so funnily random.
changing command prompt text color to green
šØ
I use powershell
Ah yes⦠the Rush B no stop strat
Safety is the number one priority...
is that like alienware?
Maybe life hacks and survival kits are the real hacks along the way.
life hacks like putting lemons in the dishwasher
HUH?!?
Subscribe to my 2nd channel https://www.youtube.com/user/origami768
If you want to know what i am up to follow me on:
https://instagram.com/crazyrussianhacker/
https://www.facebook.com/CrazyRussianHacker
https://vine.co/CrazyRussianHacker
to make it smell better
He is hacking his dog
are technical hacks still viable or is social engineering the way?
when life gives you lemons, you put em in the dishwasher. you don't know where they've been
Depends on your niche.
I donāt know. Ask n8n
Looks cool af
I would rather get that tbh. Doesn't shit nor piss anywhere.
who is n 8 n?
š
Ok but fr itās a really popular automation system thatās used even in enterprise environments. From December to January, it had like 2 9.0+ CVEs and 2 10.0 CVEs
O I C
those were features
Opportunity, Intent, Capability - EXACTLY!
I have been told, by professionals, that security controls are so tight and advanced on the blue side that technical attacks aren't really common to an established organization
and it made me ponder
is such a thing true?
Most likely yes, but APTs do exist
Not as much hacking in traditional sense more like infecting and creating a gap from what I understand
sure. until someone finds a zero day. then they all say
who put that there
and then you get update v182.67.3
MongoBleed was monstrous
But i guess in that regard, with zero days, things haven't really changed much. Those with access to zero days would perform techincal attacks and those without would do business as usual
No again most are APTs
Which can exploit zero days
The rest are kiddy material and social engineering
the majority*
was a kind of joking correction lol. I'm in a brain-dead mood. too much code review tonight
Eww code review
What lang?
pray for u that ur not looking at ai slop
c++. can't figure out why this program will read logs via path but not journal units
Add me and DM Iāll take a look at it
Unless you already solve it
boutta go to bed soon. I'll send it over the weekend if that's cool tho. I'm gonna have to break it down into multiple files anyways, i've been one-shotting a main.cpp out of laziness and it's at like 700 lines now š
I donāt work this weekend so yeah thatās cool
It looks cool, very hacker-y.
thats TOOOOOOOOOO fast
U should check this game out, gen.
https://store.steampowered.com/app/1502660/Untrusted/
Welcome to the dangerous world of Untrusted, where the stakes are high and the outcome is always uncertain: join the community of this online multiplayer (10 to 16 players) hacking/social deduction game!
As a member of the fictional NETSEC group, you'll engage in a pulse-pounding game of hacking and social deduction, using your skills and witā¦
$4.99
It's free right now sale
Can you play solo? I don't do multiplayer.
I'm married and my wife wants to talk to me all the time lol
I don't think so. It's the whole premise of the game, like mafia/werewolf game but hackers.
ahhh
what does social deduction imply?
I was just joshing around. Like ihavenoalias said, the name gives you flair, personality, and a hackerish persona
I hope I can finish all the rooms before THM goes under
Under where?
š©²
out of bidness
But why
I've been on this planet 51 years. I've seen things. I know patterns, results from business decisions. I've seen what businesses to to make money and how those decisions play out.
I, too, am performing The Joshing
I've seen what companies have to do to maintain a good bottom line and what works and doesn't
How many time left do you think thm has? Just a rough estimation guess.
Ah, very well, good joshing then!
i go nite nite. bai gaiz
Good dreams.
I don't know. I don't know their finances and it's a private company
Goodnight, and farewell.
What is that they are doing that gives you pause?
unlikely
How about 5 yrs?
idk
People dont' seem to stay on here long or do all the rooms. I've only been on the site 7 months and already ranked in top 1300
so out of 3+ million "users" or whatever ... a "user" is someone who made an account
Yeah Iāve only done like 2 months of learning and Iām top 2%
Although I really wanna complete all the roadmaps
If the site were great, it would be much harder to get there
but something turns people away
It's unfortunate, there were a lot of cool people here when I joined 7 months ago, but that echo fiasco drove a lot of them away
So having read a bit of that. seems like people are pissed about echo and privacy changes
Most of those users quit because they can't afford premium
I mean, I created an account months back but only became active when I had premium
Hello!
No, most of the children quit because they can't afford premium
HTB is more pricey isn't it
a lot more
its like 3 times as much
and more for the silver or whatever to access the more advanced learning
wait. is HTB better? because I just bought a membership with THM....
Student Plan HTB almost same price as regular THM premium
i say use THM for a year, it's got a lot of easier content
well shit, i got a year subscription
I got mine around $33+ ish
yea fuck it, im already on this boat
From black Friday
It is worth it 100%, the training content itself is GREAT
i got mine at a discount but i paid for the whole year
This training should cost more
i was thinking it was kind of cheap
the price
The biggest problem here is the way things are managed from the top down. Go to Glassdoor and check out thm
not the quality
compared to some certifications, yeah its pretty cheap
For 6 months access to Cisco U, all labs all classes all content . it cost $6,000
you get labs for a whole year for the price of one certification
depending on which one
Tempest was a pain

some are actually more though
and they have certs on here that you can take to kinda learn the process, but these are NOT proctored
Why did i even do that room
and any exam that is NOT proctored is worthless for a real job
i don't think i will get any of the certs
Good for self study
im doing looking glass and cant even get started with it,
id pay more for the content though
I find that organizations don't care for HTB or THM certs, but they do like to see participation
me too
yes, that's a fair point
and I'm not even an hr recruiter or manager anyway
ive never hired anyone
i just have l337 skills
It was so bad doing it on the attackbox i should've used my vm but im too lazy
Do people make write-ups on walkthrough rooms?
Yeah
yes
yeah
everytime i search the name of a room medium comes up first in the search results
yea medium is goat for writeups
i wish they wouldnt put flags in them though
but a lot of people do them on github too
What if I want to make my own writeup with hugo
What's up
some of them block the answer out
I run a small business, but I've never legitimately hired anyone either. Everyone that works/worked for us I alreeady knew somewhat.
I'm not sure what the jobmarket is like, but im sure its booming
I'm not really interested in webdeving but I want to create my own simple blog write up site. So Hugo works ig.
I would get fired for my interview questions.
Lol
As long as the bad guys do good, cybersecurity should be fine
Have you ever hit anyone over the head with a frying pan?
Have you ever hit anyone over the head with a baseball bat?
Have you ever pushed anyone off a cliff and laughed?
Talking about things... Random... The topic shifts.
I genuinely think most ppl quite because they donāt want to study in their free time for a job that wonāt reward it
I wouldn't even know where to start in an interview. hopefully I never have to hire off the streets
they should get rid of some of the old accounts that don't do any of the rooms
Fair, that's one way of looking at it.
im in the top 9% and havent' done much lol
no they want a high count
Hiring off the streets isn't always bad
Thm and htb is one of the best personal gifts you can give to yourself
Agreed
Either or both
I'm conflicted whether to get a raspberry PI or HTB student first. I'm still VERY NEW to cyber.
Gotta wait for the next black friday though
I spent less than 90 bucks for an annual sub
they had some discount near valentines day that i got last year
I wish I could have gotten the annual
Yeah black Friday on thm was like 33+ ish USD
Rpi
maybe it was a promotion they sent just to me. I don't know if they do that
i had an account already
They might
You're right its not always bad, but in the IT field trust is always a priority
Oh for sure
security clearance š¤ š¤ š¤
Iāve got one but it doesnāt help cuz Iām not already in cyber and they specifically want TS/SCI
My upperclassmen always mention that
Im assuming that thm has a CTF team ?
Usually the only people with Security Clearance for DOD is those who were in the Air Force or Army
what's your clearance?
Itās a secret š¤«
lmao
Lol

that's good enough
not the navy?
Mostly you get it from being in the military
@strong fjord Please slow down. Further spam will result in a short timeout.
Default is Confidential which donāt mean shit lol
its easier to hire someone who already has it
are you looking for work in cyber?
and they call everyone you know to interview them
but if you get it from being in the military, then that's not necessary
a lot of people where i work quit to become a sysadmin.
you know i wish one day, someone would approach me and ask. Hey you seem fit for the cia, wanna do it?
Anything possible
What if they approached you and said, Hey you seem fit to be a woman, wanna do it?
i would be so confused if someone said that to me

š
what is a woman?
What if it's the RIPD 
Why? You can add me as a friend if you want
set up a table inside of walmart with a sign that says "free s.x change" and see how long it takes them to kick you out
They'll wait til the line is full then theyll kick you out
lol

I read that spare change
But my reply still works regardless

People will tip you for that fs
Ayooo btw have you guys read about that cisa guy who used chatgpt

i saw that
Yea
no
hello i need ho can make for me a 5000 vote in a web that need different ips
no
I thought CISA got gutted by this admin
Possible to add comment section on a Hugo blog page?
im 7 foot 4 , 895 pounds , and make 1.25 million a year as entry level SOC1 hire
you looking for work my man?
always
Haha
cant take the paycut sorry
fuck
i only would join a team that was competitive
The New York Giants are ALWAYS comeptitve
how did you not get muted. i just got muted for a more tame word
Hates you
oh jeez, i didn't know we were running a bible club over here
Idk why I definitely thought you meant a pen testing job
hes out of ink
i sent you a friend request, friend :]
i don't mind it's not the topic of the server. If i wanted to talk about [thing i got muted for] there are probably a lot of places i could find
i am still so curious how in the f you got automuted
or what you were tlaking about
i could dm you if you are curious
its nothing big though
if you have dms on
i would tell you but then i would get muted again
If i was the cisa guy i would've uploaded it on deepseek 
you referring to the chatgpt public data posting?
Cheapskate didn't even have a plus account
not to be weird, but you keep asking about it lol
did he ask it to summarize the documents or did they not make sense or something
I jsut got dressed down for somethign in my robots.txt lmao
āØ```
User-agent: *
Allow: /chinchilla
Which is really a troll
@gray sonnet PPPPPIIIIIINNNNGGGGG
If this were Next.js it would try its damndest to optimize that out of your robots.txt
@timid orbit (it takes you to a rather entertaining video regarding the mating habits of such critters)
...
oh man ... one of those ubor frameworks built on a technology that was just recently .. given a pretty brutal wakeup call
it's not the first time
and it wont be the last
previously nextjs auth package was exploited
nope
nextjs is actually a really nice framework, but having the frontend and backend so tightly knit really brings up some security concerns
for instance, server-only npm package was specifically made to import into server files so that credentials and other important information didn't get leaked to the client side
Hey so what was it that got you muted, I must know
i would probably be disappointing now that i'm thinking about it
Poong
Your pings woke me up lol
You'd never disappoint me chimera
you just make us all the more interested when you lead us on like this
can you Base64 it?
that was a long time ago now
Good, im going to bed and i needed to know lol
i thought of that but i don't want to look like im evading teh filer or something
Ohh, yes, good night!
what if you caesar cipher it 1 shift to the right
lol
I can't remember how this 301 is configured now
query: are browsers smart enough to turn a meta refresh into a 301 title ?
like HTTP 301
?
usually that's page rules (not DNS) or it's a meta tag
but meta is usually 302
the answer you're seeking is probably still just gonna be .HTACCESS
apache then?
āØ```
sporked@mw0:/tmp$ cat test
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="https://example.net/chinchilla/">here</a>.</p>
<hr>
<address>Apache/2.4.58 (Ubuntu) Server at example.net Port 443</address>
</body></html>
Thats what curl sees.
āØ```
/vhosts/www/html/chinchilla$ cat index.html
<html>
<head>
<title>Loading .. please wait.</title>
<meta http-equiv="refresh" content="3; URL=https://www.youtube.com/watch?v=DnoMc1JpxkY&pp=ygURY2hpbmNoaWxsYSBtYXRpbmc%3D" />
</head>
<body>
Please wait one moment while we send you to the current webpage.
</body>
</html>
```ā©
Thats the actual page.
Curl exec time: real 0m0.071s user 0m0.049s sys 0m0.019s
NO 301's for /chinchilla directly, but obv its set somewhere
Wondering if cloudflares smart enought o just send the redir
No standby
Meta only does 301 redirects
I am aware of using the meta tag to redirect, like so:
<meta http-equiv="refresh" content="0; url=http://example.com/">
...but how do you specifically make it a 302 redirect?
oh i thought you were editing htaccess or something
Same
so did i .. but i dont see it anywhere
āØ```
/etc/apache2/./sites-available/www-le-ssl.conf:RewriteRule ^ https://example.net%{REQUEST_URI} [R=301,L,NE]
/etc/apache2/./sites-enabled/www-le-ssl.conf:RewriteRule ^ https://example.net%{REQUEST_URI} [R=301,L,NE]
/etc/apache2/./magic:0 belong 0x0e031301 application/x-hdf
I honestly dont remember where this 301 is being sent rom
302s should be done server side though
no htaccess in trhe chinchilla subdir
htaccess is at the root you would configure it the same
ahah but that sthe beauty of allow override. You could set varyign permissions on varying dirs

i think its slightly more efficient to redirect through the htaccess
@silver hornet r u utyicoc
yes
@molten solar if you're using PHP you can do this
I would still recommend HTACCESS tho
do you guys ever feel reluctance on turning on your computer and studying everything or you are kinda excited to go and learn all these things ?
depends on my mood
yes ofc. i'm only in chat cuz i'm procrastinating studying for my cert
for the 4th day in a row
the burp rooms are not holding my interest for some reason. I might skip them and come back later
did you check out OWASP ZAP yet?
where or what feed do I post help for a module?
great, Thanks
I hate all of it