#general

1 messages · Page 2186 of 1

raw dawn
#

ohh i dont think i have it in my uni

#

its CS

half relic
#

i got cs cause i didnt want anything too specific

raw dawn
#

but i just take a lot of cyber courses

half relic
#

i know it focuses a lot on coding but a lot of employers seem to accept cs

#

for a variety of thins

timid orbit
#

Yeah companies will hire Comp Sci over CyberSec for Cyber Sec positions but like why 🙃

raw dawn
half relic
dark wolf
#

Because CyberSecurity is a SCIENCE

upbeat jungle
#

yo how often do 50% vouchers pop up for pt1, i had one pop up a couple weeks ago but was too slow and im dying for another one

raw dawn
timid orbit
half relic
#

thats why we hd classes like data structurs and algorithms

dark wolf
#

72 101 108 108 111 32 119 111 114 108 100

timid orbit
half relic
#

not related to coding

dark wolf
#

its not meant to be converted

#

its english

wild rose
dark wolf
#

numbers are english

upbeat jungle
half relic
#

it doesn't completely teach you how to code though i will agree with that

raw dawn
half relic
#

you have to learn it on your own

dark wolf
timid orbit
dark wolf
#

those were random numbers

upbeat jungle
#

hahaha

raw dawn
half relic
#

to me its a peice of paper

timid orbit
half relic
#

what is it about then lol

upbeat jungle
#

praying for all cs grads

raw dawn
half relic
#

lol okay

raw dawn
#

algo , structs , os , networks

wintry zealot
#

Hi

raw dawn
#

and a lot more

half relic
#

we didnt' have much about networks

timid orbit
#

Science is already in the degree why gotta say it again comp sci nerds?

wintry zealot
#

Hi

half relic
#

atm machine

upbeat jungle
#

to feel important

timid orbit
#

Computer Science^2

wild rose
#

Cyber degrees teaches you the tools, but not the basic understanding of the architecture of a PC, the Internet, Coding,, etc.

strong fjord
#

Calc is short for calculator ahhh discussion

raw dawn
upbeat jungle
#

for those of you who joined late

timid orbit
#

80-90% of my degree program was shared with IS and CS majors alike

half relic
#

we had graph algorithms which is kind of related

wild rose
#

Computer Science is a much more broad field of study than cyber.

timid orbit
#

That I won’t deny

timid orbit
#

But it also means less detail into concepts like cyber

strong fjord
#

We are niche gng

timid orbit
#

Hey @strong fjord I joined late, what does calc stand for again?

timid orbit
#

Oh ok thanks. I didn’t know you were using the slang term

half relic
#

that's what i spent most of my time learning during school too i did read a lot of books that werent' assigned

raw dawn
half relic
#

cs is kind of weird in that it will teach you finite state machines but not regular expressions lol

strong fjord
#

I know you're holding a calc rn

half relic
#

no programming

timid orbit
strong fjord
#

I wont deny there's like math geniuses

timid orbit
timid orbit
half relic
#

not all of them were technical. for example the mythical man month

unique chasm
#

hello, i wonderwhat is the point to set up a shell through rce like you alrready have the possibility to execute arbitrary code on the machine hosting the website what do you get from setting up a shell on it

strong fjord
timid orbit
#

Aight

wild rose
#

A interactive shell is more stable.

half relic
#

I don't know how useful it is to learn finite state machines first it's kind of like learning latin to learn spanish

timid orbit
slim ember
#

lowkey a ctf where you have an ai on the other side acting as an active soc analyst and monitoring traffic would be cold as hell but has to be extremely well developed

half relic
#

its a lot of work and ou could just learn spanish

#

i get to write it on my resume though

#

that was the reason i went

unique chasm
#

thank you

wild rose
#

That's the billion dollar question when is it AI smart enough to run over a soc.

timid orbit
#

Microsoft Sentinel

#

Microsoft Copilot

#

Microsoft Defender

#

Microsoft XDR

#

It’s already done

#

It’s built in automation and response

#

Not quite soar

strong fjord
#

Wasn't there a sentinel in one of the aoc rooms

boreal scarab
#

Microsoft is complete fucking shit

timid orbit
wild rose
#

Microslop

half relic
#

everything they make seems overengineered to me

timid orbit
#

The point tho is that Microslop handles all the SOC work without needing an MSSP or team of analysts. Best for small businesses or large businesses who don’t need a SOC and are mostly cloud based.

half relic
#

which makes me feel bad cause their coders are way smarter than me so if they make what they make what can i make

#

i think whoever designed linux was a genius because its so simple but more powerful

timid orbit
#

Whoever???

#

You mean the legend

#

Linus

half relic
#

well he didn't make minux which is think was what he was basing it on

#

im probably spelling it wrong

timid orbit
#

No you’re thinking of Unix

half relic
#

it's been forever since i red the history

#

no

timid orbit
#

He made Linux as a FOSS version of Unix

half relic
#

i'm definately not

#

it was a type of unix though

#

ii think hang on

#

MINIX is a Unix-like operating system based on a microkernel architecture, first released in 1987 and written by American-Dutch computer scientist Andrew S. Tanenbaum. It was designed as a clone of the Unix operating system and one that could run on affordable, Intel 8086-based home computers; MINIX was targeted for use in classrooms by computer...

#

it's in teh wikipedia article

#

Linux began in 1991 as a personal project by Finnish student Linus Torvalds to create a new free operating system kernel. The resulting Linux kernel has been marked by constant growth throughout its history. Since the initial release of its source code in 1991, it has grown from a small number of C files under a license prohibiting commercial di...

#

i read whatever article i read more than 10 years ago so i don't remember the details thoug

#

but the way you chain simple commands to make bigger ones seems genius

#

i think it was actually a guy that worked for bell labs that came up with it

#

Ken Thompson and Dennis Ritchie that's in the article too

#

if anyone cares lol

#

the point is it's a good os

#

i wish things like bell labs still existed

#

companies don't really do things like that any more though

lean arch
#

I had a Bell lab technical manual in my hand once

#

At Avaya

#

I wish I kept it... Not sure what it was about, but it was Bell Labs so I didn't care

#

the history

timid orbit
#

He’s pink!

lean arch
#

yeah about that..

#

how do I change my color?

half relic
#

it's based on your level at thm

lean arch
#

oh

#

whatever it's fine

#

I don't use it much

half relic
#

too busy working

lean arch
#

I think they wanted me to do stuff on the weekend again

#

I logged off teams

half relic
#

im glad tthey normally don't bother me on the weekends where i work

#

i have a lot of reasons to keep my current job

#

being here keeps making me think about trying to move to security though lol

lean arch
#

I'm not on call this week, so they really can't ask

#

you should

half relic
#

i have a long way to go

#

if i don't i could always consider bug bounty on the site i guess

#

side

#

that way i don't need to quit and i can still practice this stuff

lean arch
#

Bug bounties can be depressing. Go with htb for a while

#

There is so much automation in bug bounties now that it's hard to find low hanging fruit

half relic
#

i don't expect it to be easy but someone where i work managed to do it so its not impossible

lean arch
#

oh true

#

not impossible

half relic
#

he learned on the portswigger website

lean arch
#

good training

#

highly recommend

half relic
#

im gonna try and focus on this for now

#

if i branch off too much i will get unfocused

#

and won't end up doing anthing

lean arch
#

I feel like I'm never going to get this cert

half relic
#

you'll get it

#

you need time off too though

#

lol

lean arch
#

yeah

narrow yew
twin ridgeBOT
#

Gave +1 Rep to @lean arch (current: #3588 - 1)

narrow yew
#

see that happend there 😄 ha

#

bot be AI ran

lean arch
#

oh awesome!

narrow yew
#

So that is low hanging fruit

#

he looks for dangling aws ips

#

he just happen to be top tier but still, reports are about simple things

quick blaze
half relic
#

i just thought that if my coworker can do it i can probably get at least one with enough dedication

#

not expecting to make a lot of money

lean arch
#

I may be a bit pessimistic, sorry

half relic
#

most easier bugs are probably in applications where they have no idea what a bug bounty is though

narrow yew
#

The memories

lean arch
#

apparently my work has a bug bounty program

narrow yew
#

I knowm, but they will see ping in the home later

#

when its diper change time

#

Its Oldholio shyft

#

its new

stoic quarry
#

Got them replying like

"Dear Math,

Ha ha ha!! Thank you for the "ping", very funny.

Kind regards"

half relic
#

lol

stoic quarry
#

I got a manager that messages like that and she genuinely drives me crazy

narrow yew
#

it dropped 5 days ago

half relic
#

i haven't seen that in quite a while

sturdy sequoia
#

im writing my reply with a qill and parchment as we speak

narrow yew
#

this is brand new so they are old now

#

i am so tempted to email work-all AD group

#

and just turn off notifiations

#

make 22k users happy

stoic quarry
#

22k users?

#

Sheesh

narrow yew
#

I think all in all its something like that

stoic quarry
#

MSP?

narrow yew
#

20k somewhat devices

half relic
#

i wonder if i should do thm tonight or something else

#

might reinstall my os too

dark wolf
#

A man was arrested on Wednesday evening after he impersonated an F.B.I. agent at a federal jail in Brooklyn while carrying a pizza cutter, saying he had a court order for the release of Luigi Mangione, according to a criminal complaint and people familiar with the episode.

#

🤣

narrow yew
#

haha

mortal ether
#

Hey, what's up

dark wolf
#

our ISE has 190k endpoints

narrow yew
#

oh

dark wolf
#

Sup Denial

narrow yew
#

shall we send them something to share

#

some wannacry-again

mortal ether
dark wolf
narrow yew
#

ok

mortal ether
#

And set off a chain reaction

narrow yew
#

just something

#

viggo remember sheep.exe?

#

not malware

dark wolf
#

No Math, I think i missed that one. when was that

narrow yew
#

the cute thing that jumped around on application windows

dark wolf
#

Odd, never saw it

narrow yew
#

it is still downloadable, I have it on USB, when my manager forgets to lock his computer I install it

#

this was a classic

sturdy sequoia
#

sheep.exe is a blast from the past

half relic
#

yeah it is

mortal ether
narrow yew
#

Great

mortal ether
#

Just my internship left now

narrow yew
#

now you can have extra screen time mr

hard beacon
#

Is there any good room to learn steganography?

narrow yew
#

Stay way from that crap

#

just horrible CTFs add it

#

the horror

hard beacon
dark wolf
mortal ether
#

Yep, big weight off my shoulders

dark wolf
#

onto the next set of weights

mortal ether
#

Real

stoic quarry
mortal ether
twin ridgeBOT
#

Gave +1 Rep to @stoic quarry (current: #97 - 107)

stoic quarry
narrow yew
#

why would anyone do it for fun

#

some horrible old bands takes forever to find

stoic quarry
#

Talking discretely by sending a PNG with 2GB of data shoved inside it

#

No one will know

narrow yew
#

someone needs to tell them about modern things

half relic
# stoic quarry I saw some goofy post on Instagram that claimed "hackers use steganography to co...

Episode 6x07: Numb3rs describes the Internet Relay Chat protocol, a "pretty primitive chat program". It's how hackers talk when they don't want to be overheard. Oh, and they use leetspeek! "LUCKILY, I speak leet."

ENHANCE! ENHANCE! CROP! ROTATE! ZOOM IN ON THAT REFLECTION!

PS: now captioned in english and 1337 (f0r r34l h4x0rz!)

▶ Play video
river ore
#

hello all

half relic
#

hello

stoic quarry
half relic
#

it just seems kind of riduculous kind of like that video

#

not that hackers didn't use irc ever it's jus the way they describe it lol

echo sentinel
stoic quarry
#

No way

echo sentinel
stoic quarry
#

Yes

#

It's insane

half relic
#

iv'e never been on istagram

#

instagram

stoic quarry
#

Good

#

It's hellish

half relic
#

someone i know sends me facebook posts all the time and i pretend i can't load them

#

i just don't want their cookies in my browser lol

stoic quarry
#

I have a family member that will send me similar things

#

I just give em a 👍 every now and then

half relic
#

that's nice of you

echo sentinel
echo sentinel
stoic quarry
#

There's no point

#

It's either engagement bait, or someone is just trying to look cool

half relic
#

do facbook beacons still track you all over the internet ?

half relic
#

that's one reason i don't even want to load the page in my browser

#

i do have an android phone though so i shouldnt complain

#

i could use a incognito window or something probably but that's too much work

#

lol

#

or a browser profile just for facebook

narrow yew
#

I deactivated my facebook

half relic
#

i did too a long time ago

narrow yew
#

I have too much old crap posted there 😄

#

they doing a background check on me

#

easier than finding old crap 😄

echo sentinel
#

Maybe they'll find it while doing the check lolz

stoic quarry
#

Just post fake stuff

half relic
#

i don't want prospective employers analyzing my social media either

stoic quarry
#

I post on random city subreddits lmao

half relic
#

i do have reddit but its a lot harder to find

stoic quarry
#

Someone got mad at me and tried to check my post history, thought they were all smart by referencing a city I've never been to, but post on the subreddit for shits and giggles

half relic
#

reminds me of fuzzers that generate random browsing dta

narrow yew
#

but they might have access tho

#

its the govt

mortal ether
neat turret
#

Guys I need help

narrow yew
#

someone hacked your roblox

#

or a phone

neat turret
#

No what it is this

Sometimes security policies can't be followed because of business needs. What avenue does a security engineer have to fulfil business needs in these cases?

wild rose
#

mitigation

neat turret
#

I mean I need answer

narrow yew
#

Like NIS2 or ISO27001?

wild rose
#

That's just a guess.

#

What room are you doing?

narrow yew
#

the engineer will make the board understand the policies and the need

neat turret
#

Security engineer intro

wild rose
#

oh maybe exceptions

#

hahaha I got it right from guessing.

mortal ether
#

Risk acceptance would make sense as an answer too, i guess

wild rose
#

That would have been my 3rd guess.

neat turret
#

Is also wrong

#

No cri is wrong

wild rose
#

which 1 is wrong?

neat turret
#

All of the answer

wild rose
#

"Sometimes, a need arises for granting exceptions to the security policies due to business needs. In such scenarios, the security engineer consults the security principles to allow or deny exceptions and suggest mitigating steps to minimize risks. "

#

Read through that and it'll make sense.

neat turret
#

It really makes sense buh am doing tryhack me security engineer intro have triad all ur answers buh they are still saying is wrong

wild rose
#

make sure you're spelling - exceptions - right. I double checked my notes here.

neat turret
#

Thx kekw man

wild rose
#

np

neat turret
#

Really appreciate cri cri cri u saved me

timid orbit
#

@narrow yew you’re a sec eng right

narrow yew
#

nonono not that cool

timid orbit
#

Oh ok

#

Nvm then

wild rose
#

I am what do you need help with?

narrow yew
#

You know how many meetings they have to do 😄

wild rose
#

meetings all the time. I can agree.

timid orbit
#

Like should I really harp on pen testing and defense or more like sys admin

#

I originally planned on using analyst role to pivot there but that’s not really an option rn

wild rose
#

depends - a lot of places want a combination of cloud and defense, but for specific tools.

#

But you can focus on firewalls, proxy and IPS/IDS rules, SIEM tuning etc.

narrow yew
#

and some want passwordless and zero trust and you need to have everything talking

#

XDRs and SIEM galore

#

throw some XOR in there 😄

timid orbit
wild rose
#

First IT job I got was at Cisco as a QA Tester on 1 of their AI tooling projects.

timid orbit
#

So you came from programming side?

wild rose
#

I know a few languages, but it wasn't programming focused.

#

pretty much we were told to use the AI "chat bot" for a better word for different industries like finance, tech, bio, manufacturing, etc.

wild rose
#

It would then corollate the info you feed it and train off that data. So take finance, since that was what my case study was on.

timid orbit
#

Gotcha

#

Pretty nifty

carmine pollen
#

just finished this one, fun room indeed

wild rose
#

You can really tell it to exchange dollars to euros with a hard-coded number, so you would have to teach it how to get the real-time conversion from a currency trading system.

uncut relic
carmine pollen
wild rose
#

and document on how you taught it to do things. So a lot of reporting.

uncut relic
#

who is actuall ylearning html css js and python and php and rust ?

#

and react and go ?

#

node js

timid orbit
#

in the simplest sense

wild rose
#

From there I got laidoff with 6k other employees.

timid orbit
#

🙁

#

that's the tech industry i hear

uncut relic
wild rose
#

yeah, I wasn't doing the taxonomy that was left to the computer scientists to build.

#

No I didn't get kicked out because of AI. This was when it was illegal to train AI on copyright material. Not like today.

#

From there my manager at Cisco was apart of another AI startup that was involved in education. So using chat bots for education - pre-ChatGPT.

#

We mostly taught IT certs like CCNA, Sec+, Cloud, Salesforce, and other stuff like accounting with the use of AI.

#

At that time, we were using it as a glossary of terms you could lookup and create your own practice test from the teaching material that was uploaded to it.

timid orbit
#

i knew chat bots existed back then but that still seems really cool despite not being a modern LLM

#

again, sorry to hear you got laid off tho

gusty inlet
#

Anyone willing to test something for me? (Preview for a project)

wild rose
#

We were using IBM Watson, which "was" a major player in the AI race and we were funded through IBM, so we had access to build our chatbot on their cloud platform.

timid orbit
#

I mean i don't mind

#

dkob

wild rose
#

I got over it by getting a new job immediately, so that's how you handle a layoff. But I was pretty butthurt at first cuz I just moved from the East Coast to San Jose for the job.

timid orbit
#

Yeah that makes sense. How you enjoying SecEng so far?

#

I was asking about SecEng because I'm kinda undecided what I want to really aim for in cybersec. I know I want to configure systems and prevent attacks, but I'm not rly interested in cyber analyst, net sec, and some other things.

#

I was kinda in between aiming for SecEng or DevSecOps (I would say I like programming too) so I was wondering what you think

wild rose
#

like IT it can be a lot of trial and error to get things working correct. you can fat finger a firewall rule and break things or DOS the network running a vulnerability scan.

#

If you like programming then you can do both, but you'll probably shift towards DevSecOps.

#

You'll still carry over the security principles that you learned, but implement them into an application or code.

timid orbit
#

Ah thanks

#

I appreciate it

#

I still gotta figure out how to get there

wild rose
#

np

timid orbit
#

But that depends more on what comes up

#

I been applying to analyst positions to pivot but I'm not going to be focusing on that anymore. Probably up my applications toward sysadmin

#

I would apply to become a SWE since that would help with DevOps but I don't have the resume for that

wild rose
#

I got thrusted into sec engineering as an sec analysis cuz my client was retooling their whole security stack, so I was open to the opportunity to learn.

#

You're still in school right? doing a cyber security degree?

timid orbit
#

No i graduated

timid orbit
tidal trail
#

if i cancel my subscrtiption do i still get to use premium

timid orbit
#

I think

tidal trail
#

u sure? not trying to risk a year

timid orbit
#

Read the terms

#

No im not sure

wild rose
#

NO not at all. I was so against it. 1. I was getting paid shit to everyone around me, so no pay raise. 2. more responsibility 3. on-call 24/7.

timid orbit
wild rose
#

I was still under the title of "IT Associate", not even soc analyst L1 then.

fervent moon
#

Yo chat technically how deep can someone hack just by knowing my real Gmail or phone number

timid orbit
#

or social engineering if they can trick you

fervent moon
#

What the fuk is OSINT

#

Sos no one can get in my phone even if they have my number and gmail

wild rose
#

yeah I got worked to the bone and can say it was traumatizing, but I look back and think of all the cool stuff I learned, all the technology got to to play with, and it was exciting vs building out an chatbot, teaching the bot, and sitting with hopeful investors.

timid orbit
timid orbit
narrow yew
#

they came at last

fervent moon
timid orbit
#

Congratulations

#

you're safe

narrow yew
wild rose
#

The police and the FBI can still track you down easily so don't do whatever you have planned.

fervent moon
#

Well I haven't done anything it's some other bs

narrow yew
#

they have your phone number and access to your gmail ,lets imagine that.
So what can they do, oh you have your gmail connected to your apple ID as backup.

get the ball rolling here

timid orbit
#

I figured it was you accidentally gave out some info

fervent moon
#

Also WHAT DO YOU THINK I AM THAT THE FBI HAS TO TRACK ME

narrow yew
#

what do you think happens next

wild rose
#

Yeah the new job is nice, same with the pay.

#

Why are you shouting for no reason to randos on the internet?

fervent moon
narrow yew
#

you forgot to put MFA on your apple ID but login trickers a ping on your phone.

you are just used to see them because you log in every now and then and do not think twice, you accept it

wild rose
#

the police and the fbi show up at your door. I'm too lazy to walk over there and knock.

narrow yew
#

then they now have access

narrow yew
#

this cutiepie

#

you just want to hug him

fervent moon
#

😊

wild rose
#

Then you're already tracked... RUN!

narrow yew
#

Android is even worse

fervent moon
#

Bs

narrow yew
#

if you dont care

fervent moon
narrow yew
#

It is quite easy to keep the phone safe from most things

wild rose
#

Mr. IDC yes the police can subpoena your account info and get access if they really wanted to.

fervent moon
#

Like what about front camera can that be hacked

narrow yew
#

That depends on you

wild rose
#

The answer is all the same if anyone wants in, they'll find a way in.

fervent moon
narrow yew
#

No its logic

dark wolf
dark wolf
#

you just got here

narrow yew
#

he's friday night fun

fervent moon
dark wolf
narrow yew
#

But to make your mind at ease. No they can not look at your camera thru you gmail.

But they can easily make you install a 3rd party apk file

#

here is where the table turns

fervent moon
narrow yew
#

free robox download

fervent moon
fervent moon
#

Then they get access

narrow yew
#

naa but almost

#

you still need to do things

dark wolf
narrow yew
#

but there can be a autmated download from that link, sure

#

but it needs to be ran

#

someone might as well do it borrowing your phone

fervent moon
#

Idk the way I type might look aggressive but im chill

dark wolf
wild rose
#

Like I said don't do illegal things and don't worry if people are watching, cuz they are...

dark wolf
#

You need to present less agressive and more chill

narrow yew
#

He at least googled some

fervent moon
#

How is that talking shit or being agressice

narrow yew
#

since his username is Kali

#

and not brandon19

wild rose
#

cuz 19 is too old for him.

narrow yew
#

I am beeing kind

#

If we go below 17 snowie will awaken

wild rose
#

lol

fervent moon
#

Awaken to what

#

😭

dark wolf
#

Splunk hasn't loaded yet

wild rose
#

splunk and elastic hasn't been loading for me either.

narrow yew
#

Im off too bed gents, cya tomorrow

dark wolf
#

oh really??? I just launched this machine, i figured i have to wait 5 min

#

night math, take care dude

wild rose
#

Goodnight Moon

fervent moon
#

Jesus can't even sell weed these days other traders have started hacking phones for info on your shit

wild rose
#

yeah I wait 5 minutes and I still can't get to the login, but I think it has something to do with my pihole.

fervent moon
#

At least the cops just shut down your account

#

Dis some bullshit

regal dawn
#

Im today years old when i found out searching a font applys it for the current search page

#

the hell

#

😭

dark wolf
#

My splunk loaded. Now I just need to find What is the full path to the malware that performed the Discovery?

gusty inlet
#

Anybody down to try something for me? (PC)

narrow yew
dark wolf
#

I have to finish Task 8 of first shift

narrow yew
#

what is the IP

regal dawn
narrow yew
#

we start huff and puff

wild rose
#

oh yeah I'll help out DKob

dark wolf
#

8 more questions to go

#

9

gusty inlet
dark wolf
#

My work sent an email to all employees regarding cyber training for each team (for general stuff people should know) and said if anyone had questions to email them so I emailed them and asked them a question about using the MITRE ATT&CK

wild rose
#

I always ask about if the training will teach mitre and most will say no.

dark wolf
#

I'll see what they say. I know they use MITRE

#

and if not then ill just start reaching out the the people I know in Cyber

#

The people I emailed are higher up on the chain lol

#

They gonna be like wtf is this network engineer asking about

#

The way I see it, CyberSecurity in a company has 2 jobs

  1. Prevent the company from being hacked
  2. Try as hard as possible to make everyones job more difficult.
gusty inlet
#

Ok so

#

THM removed dates from rooms

#

So for the longest of times

#

I couldn't know if I was studying old or new content

#

or how outdated it was

#

Feedback is welcome.

dark wolf
#

Interesting. I've always sorted by newest so i can knock out the oldest first.

#

There is no dates, but at leaast there is a sort

gusty inlet
#

Now there is.

#

Whenever you open a room that you find interesting, you can see its exact date.

dark wolf
#

where did you extract it from?

gusty inlet
#

Gotta read the code to discover. 👁️

#

Fully open source. Might expand the tool to send notifications for new rooms as soon as they drop etc.

#

A full THM tool, in your browser.

dark wolf
#

oh look , it already has a star 😛

gusty inlet
#

Took 9 hours to polish.

wild rose
#

nice yeah i've seen a lot of people asking if certain rooms are closed/ outdated cuz they can't get in.

dark wolf
#

I was working on one yesterday "Looking Glass" thats completely broken. sudo doesn't work, yet the writeups all did sudo reboot

twin flume
#

Thanks @gusty inlet 🤙🏼

twin ridgeBOT
#

Gave +1 Rep to @gusty inlet (current: #25 - 459)

dark wolf
#

That's why I like writeups because you never know if the room is broke and shouldnt waste too much time on one room

gusty inlet
#

I can publish it on chrome store! But I'd have to pay 5 bucks lol... only for chrome.

#

I'd rather have it open source and you guys can load it yourself.

dark wolf
#

https://tryhackme.com/api/v2/rooms/details?roomCode=${roomCode}

#

nice

dark wolf
twin flume
#

Poor Ronnie dude was a savage

timid orbit
#

are you wanting feedback from everyone or just someone

dark wolf
#

depends, is it good feedback? lol

#

j/k

timid orbit
#

idk i haven't tried whatever it is yet

#

i just now sat down at my PC

gusty inlet
sand trench
#

meepy moopy meep moop to beep boop for sleep sloops times

timid orbit
#

but i like it

wild rose
#

Goodnight Moon Shadow

gusty inlet
dark wolf
#

Who here knows splunk well?

#

I'm trying to use regex pattern and it doesn't return the desired results.
index=* C:\\Windows\\system32\\..... produces nothing while index=* C:\\Windows\\system32 produces 2469 events including C:\Windows\system32\svchost.exe which should have matched unless I need a * at the end of my query

#

nope, even with the * .. nada

#

dkob don't you have a splunk cert?

#

lol

#

DKOB only lists the certs he doesn't have because its quicker

timid orbit
# gusty inlet I definitely can do that, however, I don't wanna be near any kind of THM ToS bre...

See 3.2

[You are prohibited from:] employing any automated or programmatic method to extract data or output from the Website, including scraping, web harvesting, or web data extraction.
See 5.2.25
[As a User of the Website, you agree and undertake not to:] Make any modification, adaptation, improvement, enhancement, translation, or derivative work from the application.
These are the only applicable items under the ToS as available here: https://tryhackme.com/legal/terms-of-use
I believe I read exceptions are okay with approval.

#

Yes btw I read the ToS for you

timid orbit
#

not by generic search

#

SIEM filtering like KQL and SPL are so weird to me

timid orbit
dark wolf
wild rose
#

In my use of splunk it's always the regex that's wrong.

dark wolf
#

I have no problem with Python regex and perl regex

#

i love regex

timid orbit
#

regex changes across things

#

like c++ regex might differ from js regex vs linux regex

dark wolf
#

yeah, pita lol

gusty inlet
dark wolf
#

Why not just ask ben

timid orbit
#

you can argue for or against it with how it's worded

gusty inlet
#

Yup! Will see.

timid orbit
#

Best of luck

gusty inlet
#

Data is already sent to browser, I'm just reading it.

#

Well time to sleep.

boreal scarab
timid orbit
#

FULL SEND IT 🚀🚀🚀

timid orbit
#

That’s the Diet Coke button

boreal scarab
#

Shit

#

Y'all want some diet coke? I now have 10,000 diet cokes

timid orbit
#

Yeah I'll have one

peak lagoon
#

Good morning

#

Oh shit yeah, I will have one

boreal scarab
peak lagoon
#

I hope you got some for me as well

boreal scarab
#

Or do you wanty some Freedom Fuel?

boreal scarab
timid orbit
#

BRCC has done some sketchy stuff

peak lagoon
timid orbit
#

But their coffee still good

gusty inlet
boreal scarab
wild rose
#

rip trydateme

peak lagoon
timid orbit
# boreal scarab Oh?

Yeah like allegedly donate millions to Clinton (iirc?) despite their customers obviously not supporting that side

boreal scarab
boreal scarab
gusty inlet
#

You will never get banned for using it, it literally doesn't even interact with the website in a bad way. It reads data already sent to your browser. kek

#

But they're strict with their ToS to stop actual real harm.

timid orbit
gusty inlet
#

For example, I could have injected DOM elements into the website to make it better.

gusty inlet
boreal scarab
gusty inlet
timid orbit
wild rose
#

It works well too

timid orbit
#

Beyond Black is good I think I've had it before

#

I think that's their dark roast?

boreal scarab
# timid orbit HELL YEAH

I gotta train with my rifle more, get a better sling for it, right now it's single point. I don't have much gear, I got shooting gloves, prepping for my range day soon

boreal scarab
peak lagoon
timid orbit
#

Then yeah that was really good. I love dark roast

timid orbit
boreal scarab
gusty inlet
timid orbit
#

Noooo

#

Wanna leak it?

boreal scarab
boreal scarab
#

You ready?

timid orbit
#

Yessss

boreal scarab
timid orbit
#

That is a CLEANNN Scar

#

Can't tell what brand the pump is but also nice

outer talon
#

Did any of guys completed the Reconnaissance Phase under incident handling with splunk in having issue while searching in splunk

peak lagoon
boreal scarab
#

I also got a Eotech G43 3x Magnifier for the Scar too, $360 for it (New is $600-$700, with STS AND a unity mount, THAT new is $200. All that, for $360

boreal scarab
timid orbit
#

I'm lookin for a new 9mm soon. On the fence about getting a Canik or a Shield 2

boreal scarab
timid orbit
#

👀

gusty inlet
timid orbit
#

🔗 me

boreal scarab
timid orbit
#

rgr thx

boreal scarab
timid orbit
#

go bed mister

gusty inlet
#

I'm in bed. kek

distant edge
#

Yi

#

Hi

polar spoke
lofty needle
rough oriole
rough oriole
dark wolf
#

you are always so hyper

#

I wish I would have been off when you were here but I had just joined here lol

#

you going to defcon this year?

#

why the feck aint nobody done said much in the past hour... ahh its friday

#

back to a regular friday, but last friay was poppin ... or was it the friday before? idk anyhow this ctf sucks

sturdy sequoia
#

haha now you sound like youre on adderall

dark wolf
#

I was just thinking the same thing kekw

sturdy sequoia
#

you still grinding thm?

dark wolf
#

yeah, tonight i am.. want to finish first shift ctf

#

tried looking for writeup but they on medium and blocked so griding for the impossible answers that aren't even there in the logs

#

I downloaded the whole log to csv and used python regex to search for answers

#

they aren't there!!!!!

sturdy sequoia
#

oh damn

dark wolf
#

Sometimes it is about patience if you have to extract 24 parts of the powershell script from the Splunk logs, base64 decode the payload within, deobfuscate it by xoring each byte with 35, calculate MD5 for the reverse shell and voila, Virus Total says it's ....

#

thats from linkedin regarding this task

#

How do you extract parts of apowershell script from splunk??

sturdy sequoia
#

no idea. i can barely even understand the question

river ore
#

Since I am still in the pre req part of the cyber security path way. What practice rooms would you recommend or should I just wait till I'm further along to fully understand

remote zodiac
#

how do I know if I won the giveaway for cyber 101?

dark wolf
#

and I do NOT suggest it...

#

but one way is to get into an accident and get in a coma for three months and when you wake up you will know

river ore
#

That's wild lol

dark wolf
dark wolf
trim portal
#

Hello cheer HanaCheer2

river ore
#

How skittles

#

Hi *

dark wolf
#

Hi skittles, did you do first shift?

river ore
#

Would you recommend first shift to newbies like me ?.lol

stoic quarry
#

No

#

There's some recommended prerequisites

river ore
#

For ctf?

dark wolf
#

def not

#

it's labeld medium but very hard for me

stoic quarry
dark wolf
#

For Newbie .... Pre-Security .. Cyber 101 .. First red path section ... THEN try an EASY ctf

#

but at the end of cyber sec 101 you will do a ctf that is fun

#

pickle rick

river ore
dark wolf
#

You will spend about 2-3 months depending on how hard you go

#

i do hours a day at times

river ore
#

Oops I didn't mean to tag you silastic

dark wolf
#

took a couple months off where i jsut did a little

#

but i have a 210day streak 😄

cursive bone
#

im stuck on the last question of operation slither

#

😔

river ore
#

Im currently on linux module 4 of the pre req

stoic quarry
dark wolf
#

How cool is this ???? I exported the splunk to CSV .......

stoic quarry
river ore
#

I'll be honest though I feel a little overwhelmed with trying to remember the commands so far lol

stoic quarry
#

One way to do it I suppose

dark wolf
#

I have a python script parse it and use a regex to match the question format

#

but get ZERO results

#

this is BS

stoic quarry
quasi dome
#

if you guys dont know

dark wolf
#

wait till you see how I pull out the fields on linux command line.

#

I am going to start parsing it now, but the csv has like 80 columns

#

If I were a massochist I would open it in Excel

stoic quarry
#

Grep | sed | awk | sort | wc | uniq | cut are all super useful commands

river ore
#

I have a website that was recommended saved with all the commands

dark wolf
#

Glad to see someone else who appreciates those commands

#

searching in linux is always WAY faster than a stupid database

stoic quarry
#

Mmhm

dark wolf
#

click ... wait for spinning wheel ... wtf

#

i get instant results with grep 🙂

quasi dome
#

he wrote cut too

dark wolf
#

This is just the list of columns

#

imagine opening in excel LOL

stoic quarry
#

In my latest blog post I recommend taking time to practice commands like grep, even if you can check the answers quickly, good to get into the habit

quasi dome
# dark wolf

i thought the photo doesnt load until i zoomed in

dark wolf
#

I've been using grep awk sed for 25+ years

#

parsing firewall logs, email logs, etc

stoic quarry
#

The three heroes of text manipulation

dark wolf
#

but python is pretty awesome... i just wrote this real quick

#
import csv

tasks = []

with open('bullshit.csv', 'r') as f:
    reader = csv.DictReader(f)
    for row in reader:
        if len(row['Task_Name']) > 0:
            if row['Task_Name'] not in tasks:
                print(row['Task_Name'])
                tasks.append(row['Task_Name'])
#

pulls all unique tasks out of the csv

#

the names

stoic quarry
#

Yummy

dark wolf
#

im getting old and clicking the wrong shit lol

cursive bone
#

this took a while

dark wolf
#

I should have just started with that in the first place. This should be easier especially since there are 24 parts of a powershell script to assemble, whatever that means.

cursive bone
cursive bone
#

i never really used github before so i had to figure out the ui

#

😔

dark wolf
#

boom .. got that answer .. 5 left

#

Find all the columns in the csv that have file in the name ...
head -1 bullshit.csv | sed 's/,/\n/g' | grep -i file

#

Export is my new fav button in splunk

stoic quarry
stuck ridge
#

I think i should go to hackerone for bug bounty for some money for premium in thm after i finished the free path

meager rain
#

is the cybersecurity 101 certification worth it? could it replace security+ or any other entry level certifications?

cursive bone
quasi dome
#

What its mean to be compromised

coarse karma
quasi dome
coarse karma
twin ridgeBOT
#

Gave +1 Rep to @coarse karma (current: #3589 - 1)

stoic quarry
dark wolf
#

In N Out Managers make bank around 95-140k

stoic quarry
#

More than most people will see on hackerone

crisp igloo
#

Just saw on X that THM offerinng 40% discount on SEC1 cert but I can only see 15% premium discount.

dark wolf
#

yup, heck they start at 17-24hr

dark wolf
#

now its only 15%

#

snooze .. lose .. hehe

#

it was only valid for 24 hrs

crisp igloo
dark wolf
#

oh my bad

#

idk then, im distracted lol

crisp igloo
#

💸 40% off for SEC1 Certification 💸
Because cyber security isn’t theoretical and your certification shouldn’t be either, SEC1 validates what you can actually do!

🎓 Built for students, career switchers & junior practitioners
💸 40% off for a limited time

⏰ Offer ends 2 Feb,

pine tinsel
viral anvil
#

Insane sanein

pine tinsel
coarse karma
#

i still have 2 dYAS LEFT

pine tinsel
coarse karma
pine tinsel
twin ridgeBOT
#

Gave +1 Rep to @pine tinsel (current: #585 - 13)

pine tinsel
tame ember
#

Greetings.....chat

#

How are y'all doing

rough oriole
quartz drum
#

67

cursive bone
#

oooh yeah

#

0x9

#

im so cool

frail zenith
tame ember
frail zenith
#

I am a bad boy 👿

tame ember
tame ember
#

Thos who nose🔥 💀 🥶

frail zenith
tame ember
frail zenith
tame ember
#

I'm still in pegasi b btw

#

I can shoot you from here

#

So don't be disrespectful

remote zodiac
#

yo i got premium idk how

#

wtf

#

i didnt do anything

#

for free

coarse karma
tame ember
remote zodiac
#

I got a 3 month voucher

quartz drum
#

Hi

remote zodiac
#

thats cool asf

coarse karma
tame ember
#

-70

quartz drum
remote zodiac
#

WAIT

#

I WON

#

NO WAY

dark frost
#

You won ?

dark frost
#

3 month premium ?

remote zodiac
#

and exam

#

it says I get a retake, doesnt this just mean I got 2 exams?

echo sentinel
dark frost
#

Oh what exam you got ?

#

SAL1?

remote zodiac
#

i won the giveaway

dark frost
#

How , when did they even gave away Sec1 👀

stoic quarry
#

LinkedIn

dark frost
#

From a youtuber ?

#

Oh

ebon dagger
#

hey guys i was doing some questions related to misc and i got a attached file which was a qr code ,,, when we scanned , it gaves us a flag but the flag says this is not the flag ,,,, so what should we do now
the hint says
the qr code is valid but qr codes allw small errors

stoic quarry
#

What room?

remote zodiac
#

yeah lol

ebon dagger
#

not rooms tbh it's a challenge from my friend

stoic quarry
#

How are we supposed to help you if it's a challenge from your friend

stoic quarry
#

Ask your friend for help

ebon dagger
#

loll idk much about qr codes and if i dont i'm gonna get mocked and all

ebon dagger
stoic quarry
#

Get some better friends if they mock you for asking questions

ebon dagger
#

but somebody wants to be good boy of their girl

stoic quarry
#

.... Huh

remote zodiac
#

wtf

ebon dagger
remote zodiac
#

"Total sections in the exam : 7
Questions: 10 per section
Time: 30 or 45 or 60 minutes per section
Duration: 24 hours total; breaks allowed between sections.
Format: Fully hands-on, no multiple-choice questions
Prerequisites: None, but we recommend pre security and cyber security 101 learning paths
Requirements: You must have a valid ID/passport
Attempts: 1 free retake (further retakes cost $100)
Passing score: 455/700
Language: English"

"Requirements: You must have a valid ID/passport"

why do I need a valid ID/passport?

ebon dagger
#

😭

remote zodiac
#

uhh

stoic quarry
remote zodiac
stoic quarry
#

I've taken a bunch of exams, they all require you to confirm your identity

remote zodiac
#

so I NEED one if i want to do ANY exam

stoic quarry
#

An ID? Yeah

remote zodiac
#

well?

#

what exams?

tame ember
stoic quarry
#

Comptia exams, Microsoft, ISC², TryHackMe

tame ember
remote zodiac
#

damn

#

well

#

idk how I feel about giving my ID to a company

ebon dagger
stoic quarry
#

If you ever want to earn certifications that's what you gotta do

tame ember
#

How da heck you make a typo on a and ocri . Both are on the whole different sides of the keyboard bro😭

tame ember
tame ember
#

Number 1

ebon dagger
#

oooo

#

😄

#

nice

stoic quarry
tame ember
ebon dagger
#

can you help me please

#

please

#

please

#

😭

stoic quarry
#

Bro no one can help solve your friends little riddle.

ebon dagger
#

🥹

#

🙏🏻

tame ember
ebon dagger
tame ember
remote zodiac
ebon dagger
# tame ember What. Tell me the riddle

i was doing some questions related to misc and i got a attached file which was a qr code ,,, when we scanned , it gaves us a flag but the flag says this is not the flag ,,,, so what should we do now
the hint he gave says
the qr code is valid but qr codes allw small errors

tame ember
stoic quarry
tame ember
remote zodiac
#

or submit it?

ebon dagger
stoic quarry
#

When you start an exam

#

Usually you show your ID, then show your location where you're sitting the exam, and then you start it

ebon dagger
#

i can dm you the qr and all ,, and am willing to solve together with you so that only you dont solve it

stoic quarry
#

At least with comptia and Microsoft certs

ebon dagger
stoic quarry
#

Gotta show them the room you're doing it in

ebon dagger
#

what

remote zodiac
stoic quarry
#

If you're taking the exam in your room yeah

tame ember
remote zodiac
#

is it this intense?

stoic quarry
remote zodiac
#

might as well

stoic quarry
#

For comptia and Microsoft certs that I've taken you need to have your camera on at all times, they ask you to show the room you're in so they can prove you're not cheating

stoic quarry
remote zodiac
languid aurora
#

U can still cheat with an external device like a phone

stoic quarry
#

In the comptia and Microsoft certs I've done it hasn't been open book, if you tab out of the exam application they fail you

remote zodiac
stoic quarry
#

I've not done them

#

Yet

#

But you have 24 hours so it's likely it's not as intensely proctored

languid aurora
tame ember
#

Idk how

stoic quarry
#

Thanks ig

ebon dagger
tame ember
#

Why da heck I'm in your block list.

tame ember
#

Agent 8

stoic quarry
stoic quarry
ebon dagger
# tame ember Ask gpt

did ,, also asked gemini co pilot and all ,,, all they do is to go for guess works random scripts and all

stoic quarry
# ebon dagger wdym

If your friend just said "get the flag" then there's not much context, and I don't want to waste time on some randos challenge kekw

tame ember
#

I didn't do anythin and I'm on people's block list like dawg

stoic quarry
tame ember
languid aurora
tame ember
#

I ain spam tho

remote zodiac
ebon dagger
stoic quarry
ebon dagger
#

😭

tame ember
remote zodiac
stoic quarry
remote zodiac
#

do you know anyone who has?

stoic quarry
#

Dkob has

ebon dagger
stoic quarry
remote zodiac
frail zenith
#

Tf is context here

#

What is goin on

#

Man to man what ??

#

Kiss ??

ebon dagger
stoic quarry
#

Someone wants help with his friends badly made CTF

ebon dagger
frail zenith
ebon dagger
stoic quarry
ebon dagger
#

like that

frail zenith
ebon dagger
# frail zenith So get the flag what's the issue

i got a attached file which was a qr code ,,, when we scanned , it gaves us a flag but the flag says this is not the flag ,,,, so what should we do now
the hint he gave says
the qr code is valid but qr codes allow small errors