#general
1 messages ยท Page 2190 of 1
are u any sort of cat-human? considiring your profile pic, catboy/catgirl etc?
yes, vampiric cat e-girl ๐
Aaah okai okai, interesting.... :3

:3
OMG, I LOVE THAT, I DID NOT HAVE IT
Wait, u also norwegian?
OMG, we are friends now
oh, well i am keeping u anyways
sri lanka?
ya
Coooool :3
Having norwegian astolfo gifs is highkey flex, why u have that? :3
I just searched it up hehe
hmmm.... Sure buddy
Hey guys, im doing my writeup on hugo but when i add img, it didnt show, can anyone fix?
what flag is that?
Isle of Man
it's an island in the UK, not technically a country
nice
wait wait
i got a good one
why did the chicken join a band
because it had drum sticks
lmao
I need some quick Help.
My assignment says choose a malware sample from a reputable source is it possible to get one of try hack me samples like is that allowed im afraid of downloading from big sources.
just finished my first writeups guys
woohoo
wait i got a even BETTER one
why can't your nose be 12 inches long?
because than it'd be a foot
hahahahaha
What sort do you need?
i dont have any to loose
It's bizarre you need to download a sample, yet you don't know where, or how to get one safely.
Anything it's to demonstrate malware analysis
I do don't want to risk it you got a spare lap?
i have one that's far better
I mean, any software can be used for "Malware" purposes, just do it on Windows. 
I don't think there's any real malware samples on THM other than maybe in the malware analysis rooms, but those samples would just be picked from one of the big databases anyways
You don't need a spare laptop to download a malware sample safely, and ethically.
There is.
But you can't take it off THM's machines as accoding to ToS.
So your saying window defender will do it's thing ๐
Just use a VM
I am
what
I'm saying it's bizarre you haven't been showing how to do something you need to do?
wait wait wait wait
Got shit ton of documents here the paranoia is real
I've have lots of malware samples.
obviously
Just use a VM instance that you don't use
Oh boy.
Nvm figured it out thankz
Oh boy indeed. Watch how they download ransomware and fuck their PC up ๐
wait I got one last one
what did the police officer say to his stomach
Oh I know. ๐ญ
your under a vest
you're like that "isn't that concerning" guy in youtube
LOOL
You are under a vest? Yawns
lmao
dang it
why did the math book look sad
because it had too many problems
ok I'm gonna go sleep now
@wise current Dynamic or static?
You can casually get one form malware bazaar or vx-underground
Just keep in mind what you're dealing with and don't open the sample
Keeping it in password-protected zip file is the best idea
Oh god.
It's the blind leading the blind.
They come from those websites, already zipped with a password.
ik dw - I wanted it to be said just in case
โจ```bash
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Just cope/paste this in notepad and save it if you wish to test out your defence.
Scrubz, Wizard knows. Just gotta make sure nothing is left out with the room temperature IQs of some people
hibernate
๐
There are also websites that will host, run and let you analyse the malware.
Plus Wizard often watches my Process Roulette streams as @velvet gull calls it 
If you don't want to download malware because you're paranoid, it's probably best you use those methods.
Actually, did anybody see in the news a youtuber posted anti Saudi leaders vidoes, got their phone hacked, tracked and beat up?
Proving Pegusus is the shit.
Got it thanks man. Just enabled nat and downloaded and then disabled it again
Gave +1 Rep to @echo sentinel (current: #64 - 178)
Yeah I did. Proof when a nation state targets you, not a lot you can do
Except ditch your phone.

And you don't deserve to play with malware ๐
In a VM right? You shouldn't have network connection in your malware sandbox
...How are they supposed to get the malware on there?
Shared folder on Windows?
Floppy Disk 
File link betwen vm and host system
One of the big ones too.
That is what i did some time ago
That's how you infect your host.
I mean, could be done this way - but overall when I think of it now actually they did it good way
I moved it from linux to a flare vm
I love it when people poke holes in their security for VM's and "notes". ๐
Well I've done it in a actual one. Doing it in a VM rn goddam project pissing me off
Which sample did you choose?
You did it on your host?
Rat
Why don't you analyse something old and open source?
Like blaster.
Do you have any idea how little that narrows it down?
Remote access trojan
Alr, just to be clear - don't get malware onto devices that hold value for you or store some important documents.
And also, what is the task exactly?
Still it doesn't narrow it down - there are many types of RATs and malware families you could get
Njrat
If it doesn't have a name, you just send in a sha256 checksum
Bladabandi?
It's to demonstrate and write a professional malware analysis repot
Hate the professional part I'm out of words to write
Okay nice - If you have a Uni email you can register at any run and use it as a sandbox
Which tools are you using?
It gives you a nice breakthrough of what a program does
Procmon, regshot, Wireshark the ones that we were told to
Yea gonna learn alot exhausting at the same time
Think out of the max man, show off.
Use those tools and more.
Do you use IDA?
Or Binary Ninja
My word count is cooked I want to make it so good but damm the markers are old so they don't care
Use CFF Explorer.
๐ thanks dude
Gave +1 Rep to @sick lance (current: #2 - 3945)
Do you have process hacker?
Nop
PE studio is also a nice software to learn a bit more about the binary
Oh yeah got to use that too
Ghidra
Process hacker will allow you to see which procvesses the malware creates and hides.
Ghidra is bae.
Well I'm gonna use these makes the analysis writing easier tbh
Chatgpt
Thanks guys appreciate the help
Submission in 5 hours
Ew.
๐คฎ
Going with the ai hate gang huh
Unpopular opinion: you dont hate ai becuz ai but hate it cuz people take it too far all the time
Ai is not useful if you're writing an assignment.
Ai can fabricate stuff, no point using it to write something only for you to fact check it.
Its just like saying i hate these artists cuz theyre mainstream now
As far as i know its been giving me pretty good stuff and helped quite a lot after i double checked it myself
The keywords there is "As far as you know"
Have you actually checked?
It's not giving you false information, or just straight up plagiarising?
Yea we used plag check softwares in college
Which are not always 100%
As it uses AI.
Less than 5% plag found that too with too vague lines
The irony, huh?
Public AI's like chatGPT also doesn't really like malware-related stuff
Smart use for AI: analysing data, gathering sources, generating talking points, proofreading
Dumb uses for AI: getting it to write your entire essay
And I'm fairly sure that's academic misconduct at all institutions
Checking assignments using AI should be acadmic misconduct too

:)
Hello, I hope youโre all doing well. Iโm new to the server. Is this a server for hacking services?
No.
No
What is it?
Hacking services sound wierd
what is even hacking services
Let's ask DKob to just change the banner from THM stuff to a basket underwater 
"Hack my ex's instagram" or shit like this
He can't.
Only Skidy can.
Ehh
Mods don't have that sort of privs.
Makes sense
Whats up with the moltbook
They can't even create channels, only admin/owner can.
I think it's kinda dying but idk
Yea but what is it
Social media for ai
As if instagram Reddit wasnt already filled with bots fighting eachother
Dead internet theory in practise - AI creates post and converses with eachother and humasn watch
Yeah, but moltbook is open about it
Wild
Whats better than watching cows finally getting to eat fresh grass after 6 months of staying inside a barn due to winters
Why does moltbook feels more human than twitter and reddit
Running in a field with their calves.
Both are cesspits.
You wouldn't be the first one
Just don't repeat Meta's (or Facebook's at that time) mistake and try to keep it with some morals
You don't know fear until you've ran past a fence to find a massive cow jump over and chase you for fun.
Texans would be wondering why their river dried up unbeknownst to them that a random kid in india decided to make a subreddit full of ai for fun
You don't know fear until you hear a mortar land where you were just taking a poop
Hey i know this its a classic ive been chased by a cow before
I can assure you, you would not enjoy a single second of it
Poo poo shards everywhere
im going to subscribe to onlymolts
I use AI to study, give me mock test, and programming test scenarios to what should I code for practice.
age = int(input("How old are you? "))
name = input("Whats your name? ")
for number in range(1, 10):
print("Attempt", number , number *".")
if age >= 18:
agebracket = "Adult"
else:
agebracket = "Minor"
if name == "Fita":
print(f"Your name is Fita, your the best python coder and your {age} and your an {agebracket}.")
else:
print(f"Your name is {name}, your {age} years old and your an {agebracket}.")
how do you make
attempt have an second
to say
Time.sleep()?
I dont understand your question
Why is discord so dead lately
quick sketchy sounding question but it's legit. My kid has an old iphone they havent used in two months and annoyingly somehow forgot their 6 diget numerical password. Looking to factory reset it. Since im a beginner / working towards PT1 i kinda see this as a fun project if possible. Is there anyway, using kali linux / the tools to bypass stuff and factory reset it ?
Put it in a loop
Factory reset it i guess
Depends on an Iphone probably
how do i do that without the password ? doing it the itunes way ? I was hoping i could have fun with XYZ tools to do it haha ๐
ohh god i think its a 12
Can u just put it in dfu mode?
right ok ill check this way cheers mate
Hey guys, can writeups include answer?
Generally no
I wrote my first writeups with all the answer included and explain carefully ๐ญ
They shouldn't (especially if it's a challenge room), but sometimes it's unavoidable
Ok thanks, imma fix it in my next writeup
Gave +1 Rep to @echo sentinel (current: #62 - 179)
reading this is weird asf but at least they aint dumb like reddit and x users
just send me the answers i will take care of them for you
Wdym?
Need some help. I am in Windows Powershell task 6, last question. I am inside the correct directory and i have tried both "Get-Content and Set-Location -Path ".\hidden-treasu " But i cant get into the file i am supposed to. What am i doing wrong?
Like after putting my age and name
The attempt message will appear every 1 sec not all at once
What's the command you're running
shouldn't it be "hidden-treasure"?
Should be Get-Content .\hidden-treasure
Place it in a loop - and maybe let's move this discussion to #programming
Get-Content and Set-Location -Path ".\hidden-treasu
I believe
i only see treasu on my screen
no -path?
Do you have the terminal full screen
Commands overflow onto the following line, so there might be a new line with a single e on it
Good to get into the habit now of pressing tab when you're halfway through a command
did not work
ls -lah might work in powershell
i am blind
Lol, did you get it now?
did you figure it out
yes it is hidden-treasure-chest
Like I said, hitting tab will help a lot
that explains it
thought the re-chest was a own file cuz the screen cutted it out
At least ya got it!
If you get into the habit of tab-completing commands then you'll be set
Why ๐
its depends on how many different characters present on your password
Literally not something illegal I just wanna know because I'm thinking of building my own store
Like an repair shop
And I wanna test it in my phone rn
And for that you need to brute force a password?
Yes phone password
i am pressing tab but it does not get into full screen
We can't confirm that's what you're doing lol
Not some website password
It has nothing to do with going fullscreen
Uh Idk I don't rob phones?
And I know my password is 2508
Repair shops dont usually brute force passwords
What do they do?
Yes
Factory reset?
They just put phones into dfu mode or recovery mode
And factory reset?
Mostly, using paid recovery pc application
Sometime just fix
well nothing happens
Did you start writing a command first
Fix
If it's a hardware issue there's no reason to have the password
Ye how? Well just tell me do they do hardware when they do it or the actual screen
Ok bro, mostly the phones sent to repair shop is just hardware damaged
So why do u need a brute force?
madhat making his labs-like platform. Cool.
https://madhat.io/
To unlock a password
Do any of you guys have comptia resources?
Ask owner
Wym
Bruh in tiktok people go to shop to remove they're forgotten password
I think i need some cert that is free, does anyone know some?
Go work in a repair shop then
I mean comptia course pdf things ๐ .
CC is free
Red team?
I'm like 12
But you want to open a repair store
In the future?
Im just want to flex :))
I said like
Straight to ban
Nothing stopped you from making this account when you were 8 lol
That's what I do rn when entering an only 18
?
Please speak normal english.
Me when I'm a 12 year old Filipino who wants to hack phones I stole unlock my own phone so I can open a repair store in 6 years
Sup guys
put tank in a mall
Bruh I'm actually not lying
Well there's nothing to prove
You're 12?
Bro is cooked๐ญ
:hammer: xurokaze.#0 has been banned.
1 year ban
The hash is too short. I feel like it has to do with the dots at the end๐
Your terminal is too small
xd
One time exam tries is crazy though
alright, fixed it
htb ?
madhat, the youtuber's thm/htb like new platform
yeah lmao and its not recognized yet
ramadan is coming gitch gonna be even more critical state 
Ah lmfao
16 days left ๐
but ramadan grind hits different
Might delete social media again when it comes
not for me i will struggle
I understand the principle behind it, but it's a bit silly

i thought root.exe was russian
dont tell him ray
xd
same
im vibe coding an agent extention for burp and lmstudio
๐ฅ
im already a lazy guy
Dead
ramdan will kill me
๐
weaklingg
and imagine studying for college and having midterm while being in ramadan and trying to self study
yesss
rate my pfp
0/10 because its not us
hi snowie 
yass queen slayy
still bad
rate this then
hello ray 
add 3 to that and that's me
noice
143 
yeah i was thinking why he is still with us
i should try vibe coding to see what happens
im curious if the code would be made as well as human coding
not for anything just for curiosity
if i was 143 i would start thinking about finding a soft ground to be buried in
hey
locally ?
yo
yeah i mean just to see what it gives me
im skeptical that it would be as good as human coding but i might be surprised
I'd choose a rough ground
probably better than a code generator but not as good as human
It'll be fast but it ain't gonna be secure
that's what i would expect
bigger the model is and how good the prompt is yes it smarter than nvidia devs combined
i was wondering about security and efficiency
i was having a important meeting with my e gf " chat gpt " and she start biting me virtually
if it makes stuff that works but isn't well written
Vibe coding is breaking so many security practices
nah you badd
i wouldn't use it for anything real
Bite her back
quick question, is there any channel where i can ask some career advice related to soc
guys what do you think about " Zero Trust Network Simulator with Autonomous Honeypot and MITRE ATT&CK Mapping " project
calm down
im not this evil
with a 5090 i can maker her come to life 
not even 5090 can handle allat
fine tune my brudda gpt is 12 gb on size all you need since it's an moe not a dense one
and prepare you self for electric bill if using 5090 hard time
electricity is cheap would barely be half of the fridge working since 1999
who said something about paying bills im stealing electricity
Don't discount AI for phishing campaigns. It's excellent if you need to whip up a quick web page for a customer engagement
are you romero from fsociety
depend wher you live. but will be extra cost for sure
may be he is me
for the amount of privacy you gain as still use ai is a win win 4 me than rely on cloud
free heater
well... if you do not run super secret things that can't go online, as in asking online ai, then is ok
is it faster than just making it yourself though
you can have a decent web page in 15 seconds or less
true
its been a long time since i did it but you can make a simple web page super fast with visual stuido too
i don't know about 15 seconds
hard to even get it open that fast lol
you wanna drag race an agent with yourself ?
there is tools for that. there is quite nice amunt of pre templates
it would take me longer since it's been forever
i have to remember where everything is
i don't even have it installed right now
im not a dev or a coder in any language but it takes me 3 clicks for a website
i just don't remember where everything is
it's been years
How do you document while learning something as an investigation?
prompt: make me we web page that looks like a bank
obsidian
In a note-taking place - like Notion or Obsidian
You add where did you find it, what did you find and how could it be relevant
okay is there any template you follow or anything what to document and what not to?
making own
Now..... It's better to learn how to do it on your own
how does a web page look like a bank
you learn what to document. but mostly document all heh
HTML/js/and css are very valuable skills
๐
@boreal scarab Please slow down. Further spam will result in a short timeout.
Im a vibe coder :)))
Can anyone join me for a voice channel, i wanna ask few questions?
i probably don't know the answer
Why not ask here?
okay
general voice is locked for me
You gotta verify
So which channel?
are kids under 13 not allowed to use the website or just discord.
i would feel kind of bad if they cant' learn
I think discord
De jure, kids under 13 can't agree to ToS - hence they can't use 99% of web pages
Rules are rules, u cannot break it
And actually, kids under 13 are all skids if they even step in this field (except some prodigy)
Should also focus on other stuff
"Geniuses dont complain about environment"
@dreamy inlet where r u buddy, we r waiting you in vc
i didn't even have a computer when i was 13 so i had to go to the library lol
Real
I have my laptop since 12 :))
General is locked for me, let me verify
It's cold as tits
You always get things wrong lol
ยฏ_(ใ)_/ยฏ
Ayayayayaya
its getting back to normal here. still cold but not insanely cold
I think i have to fix my writeup tmrw cuz i just throw all my answer in it
IT FEELS LIKE -7!!!!!
f or c
If you want your writeup approved on the site, don't include the answers
For you communist fucks, that's -22c
it was like that here
Aka the rest of the world
Aka communists
Yez imma fix it and re apply
the whole world is communists lol
Yes
I mean, authors approve the writeups - My sometimes included answers and mostly got accepted
True, but in general dont just have the answers
I've accidentally left some in ๐ถโ๐ซ๏ธ
Mine have all the answer with carefully explain how i get it and output๐ญ
i hate if i accidentally see answers
Yez, imma hide all my answer and just left the command
i don't think anyone had a problem with it lol
If a potential employer is reading a blog post they're more looking for your thought process and your process, so you should focus on describing that
Yes, im focus on describe my process
guys
why does it say 40% off for my sec101 exam voucher but when i log in its the usual price to buy the voucher?
BRUHH
I wish i could write a blog about interesting work problems but im afraid they wouldn't be anonymized enough
that could backfire
no one will hire anyone posting priveleged information on the public internet
Yeah 100%
It might be usefull though there aren't a lot of books or blogs or anything i could find about this specific thing
Chat's dead
Meowl
Meowl Yuzz
it's just the same people here lmao
yea cuz less chatting mrow hackin
Done!

do u guys know any "koth"-like platforms but for coding except codingames' clash code
im not sure if those exist
Does anyone know why my victim vm keeps opening calc๐ซฉ started this a month ago after I did a hydra attack on it
Itโs generating too many logs on wazuh which is annoying
you're in the mainframe
Not enough Info to tell you
Hydra has nothing to do with calc
check task scheduler and see if anything is running calc.exe maybe
Thatโs what I thought, so Iโm just wondering what could possible cause it
Ever since I sent that message
It has opened 5 so far
I only use it for attacks so nothing runs in the background
idk maybe he did other attacks but calc is usually used in demos/ proof of concept
so something could be still runnin
oh
ermmmmmmmm
You said your victim vm
Yea I mean to attack it
ok wait so is this a victim vm you attack or something you have tools on to attack
This is my windows victim vm, I use Kali for attacks
Might just have to rebuild it but I really donโt wanna do that
Hi
All the best
hello
thanks
hello... :3
I'm live on Twitch, come hang out! https://www.twitch.tv/loccsworld?sr=a
hello kitty
Hello hecker
I am doing good thanks! :3 how are you meowlware? :3
Gave +1 Rep to @quaint ferry (current: #195 - 53)
just going to get some catnip and il be back lel
bring some for me too
wdym by "basic red team"
One of the worlds worst hacker tried to hack into my machine which happened to be a honeypot..
Fan page: https://www.facebook.com/pages/Worlds-worst-hacker/224550810913902
sorry i don't have any serious recommendations
somone claiming my title i must sue
exactly
hatsune miku song what ;0
or is it vocaloid
of some other
es
is it bad i feel like this guy is way better then me? :3
Omg haii :3
u just started out its ok
lies and untruth
i cant remember even the osi model
wellahi cooked am i
u dont have to rot that stuff having understanding is good enuf
I can remeber like sorta what it consists of lmaooo :3
that kind of information slips right out of my brain because i never have to know the specific layers
to do anything
navigating through cybersec is the worst fukin thing to it
all i remeber are layered like a 7 beef patty burger
its harder than navigating through a forest in africa
gud lord
Omg can u make me that?
with cheese?
you can find em in las vegas
Hmm, i am a bit far away from that place, and i am kinda scared of mericuh, so i will stay here see if i can make one myself.

mericuh
yuh

it cant be worse tha my country
Guys, even when I use SSH to connect to the IP to complete a task in the CMD, it says it's not connected. It always stays like this. What can I do?
Seeing 13 yr old doing write ups chat should I also do it
if it4s tryhackme use attackbox instead
always stick with tryhackme@linux3
Can I send you an image in private for you to see?
ssh targetip@username that's it
type yes
thens password
oops
ssh username@target ip

I sent
pros : nice background music
cons : 10 brain cells lost
nah just give up unc your era had passed long time ago
I am just 19...
hes on linux fundamentals 3 the ubuntu box is already up
Opening a bunch of listeners will probably be noisy as hell though
Depends how you go about staying hidden
Anyone has experience in research papers here?
I guess you just need a couple VPSs in none extradition countries
Use google sheets as a C2 and hope they don't check for weird user-agents going to google sheets
I wonder if TAs do stuff like that
I do a lot of silly things
What kind?
the good kind!
hello can anyone help me with a room
....
Well Its with this reference format in my research paper... I wanted to know if this format is correct or not
isnt that a university?
it is
how did you remember that lol
I have no idea. I was wondering that myself
bro is wikipedia
Which room?
you need to learn how to do it yourself
this one
Thanks man! Really appreciate it.
especially if you're writing papers
Gave +1 Rep to @lean arch (current: #2329 - 2)
Yeah its my first paper so I am kinda nervous
lol
I dont want anything to go wrong
Will let you all know when it gets published
I've been out of school for 24 years...
no fscking clue how I remembered that
I think when you're traumatized with writing papers, it sticks with you
What's the issue? Go to #room-help
I should call you sir then
don't you dare
can i call u unc?
careful cat... he prolly knows spells to make you vanish
that makes me sound like I drive a white van with free candy written on the side
Hmmm... do you?
im unc too 
okai unc
No, it's a red rav4
everything above 20 is unc tho
This is the first time I am seeing so many adults in a server. Finally!
thats actually kinda chill, makes u seem way to responsible tho
ยฏ_(ใ)_/ยฏ
toyota based
too highh to spell toyota
toyota is so reliable, u literally cant hate on it. they are also pretty comfy cars atleast the ones i have been in.
Meow meow meow meow, uwu mrrp
coudn't find the escalation vector that is being mentioned in the writeups, and i'm stuck
and how do i even start describing the issue
Toyota's such a goat. I prefer german cars, but i love the look of toyotas in general.
what car is that in your pfp?
Old ferrari
looks like a ferrari
Hmm :3 cute
i think more people would get help with their issues if they put exact commands and out put and a link to the room they are in and made it easier to see what was going wrong from the beginning
its too much work to aska lot of question
i saw the pouncing horse like a microscope
and that way if you know if you can solve it right off instead of asking a lot of questions then not knowing the answer
They should do one of those support form thingies that everybody can help with, where you have to fill out specific fields to submit.
they should
i bet more people would get help
indded
i was trying to rdp the task machine im already in from inside the machine itself
you rdp'd to the machine you are already in
and i was wonder why every time a session takeover popup for me and i thought its a bug
after what it took me 2 day to know that
now next time something like that happens you will know right away
i wont rdp again
generall debuging for binary exploitation
ive attempted to map drives before and put in the wrong ip address and mapped a drive from a server to itself
lol
its suspicious when it doesn't ask for the password
anyone remember subst?
for some reason, that's what it reminded me of
maps a folder to a drive
i guess if you wanted that you could do it that way
too
im not sure why you would need to do that
I never could figure out the use for it
i need to know why the logo of postman is micheal jackson
Hey guys new to cybersecurity can u tell me from where to start
it looks like a guy wearing a rocket pack lol
Thanks ๐ซถ
Gave +1 Rep to @quaint ferry (current: #193 - 54)
i swear all i see is micheal jackson
Do u know any discord server where we can join vc and clear our doubts
therapist you mean ?
๐
About what
Related to cybersecurity
Just ask here lol
there is cube talks in hack the box but i doubt something similar exist here 
I am new to this guys and don't have any idea ๐
why you need vc for ?
Owlsec
If you want like more people
What are the benefits of participating in the CTF competition?
he's cluless
Yes
become elite :/
My situation after I installed debian to do minimal installation
start with the recommended and you will be just fine 
Thankyou
i installed pimp my kali and ran out of space
I just wanted a distro to run AI models and VMS
we're hacker 
Which host
windows 11 
dont start
did it crash ?
guys anyone wants to fukin do red team shit its not makiing sense to me
ngt the 40% off on SEC1 is actually a p good deal holy shit
wich room are you on
might get it ngl
i mean it includes 3 months premium access
i have 1 year of premium but full price 
why u cryin
i don't have a friend

Happy Sunday.. I am developing a new program and need some voluntary beta testers. DM me if you want to sign up. It's a simple app that once you install, gives me access to all of your financial accounts do I can drain them. Thanks in advance!
correct
we're all your friends 
yep
what good pentest methedologies/checklists u guys got for ctfs
I will be friend trust trust uwu
its crazy im strugglin w simple ctfs like pickle rick
i will meow tho
anyone interested in doing OverTheWire Bandit challenge
went up to near the end and stopped unfortunately ๐
Excellent piece of knowledge though 100% recommended
Another "high IQ" game
Yuh, got a problem w that twin? UwU
ken i dm?
Yuzz yuzz
no my snail just meowed
dms always open
I cant help u with cybersecurity stuff, but when it comes to meowing i am quite the expert.
some of the rooms seem too easy if you already have general knowledge
guys i need an advice. im on the security 101 path. should i do CTFs now or its better after i finish the Jr penetration tester?
might as well try them. If it doesn't work there is no harm and you can always come back later
u dont?
because i tried to do 2 easy ctfs and i cant? feel dump lol
How is everyone doing up here in general?
well you might need more information then. someone told me to get through jr pentester and web application pentesting first
like one of the ctf were -
Pyrat receives a curious response from an HTTP server, which leads to a potential Python code execution vulnerability. With a cleverly crafted payload, it is possible to gain a shell on the machine. Delving into the directories, the author uncovers a well-known folder that provides a user with access to credentials. A subsequent exploration yields valuable insights into the application's older version. Exploring possible endpoints using a custom script, the user can discover a special endpoint and ingeniously expand their exploration by fuzzing passwords. The script unveils a password, ultimately granting access to the root.
I wouldn't feel bad if you haven't finished the training yet
that sounds interesting but i haven't done it yet
maybe you are right first i should finish jr penetration tester. hope its normal to feel dumb because i didnt get nothing of the room(
Make sure you take notes
so you think its normal and i just should keep pushing?
pretty okay, you?
i think so
Petty good
did you feel the same on your first CTFs?
yeah i tried two when i first started and got nowhere lol
when did you feel ready to start doing? just to get and idea'
but i barely did any of the learning path
really? how did you manage to do them?
I honestly only did one so far and i think i got lucky and picked a super easy one by mistake lol
i didn't do them
i just saved the room to come back later when i know more
i see, so i leave them for later after learn more. thanks
Gave +1 Rep to @half relic (current: #515 - 15)
np. I wouldn't take anything too personally especially after only completing a little of the learning path. it's not an easy thing
i work in it too
so i should be ahead a bit
yoo. Anyone here has participated succesfully on bunty hunts? I am wandering if doing bunty hunts is a good way to go.. I finished cyber101 and I am halfway through soc lvl2 and have done 50% of the pen tester path.. I wonder if a more realistic "hands on" experience would be more educational after I finish here or if I should stick to doing rooms here and at htb
Do ctfs for realistics situations imo
there is very little realism to bug bountys, except for the amount that people doing them are screwed
does attack box work for diffrent rooms ?
cool thanks. I was planing to do a few at some point for sure but they are a little intimidating at my skill lvl. I don't want to mess it up for the other people
yes
or i have to re start it every room
no
okaay
thank
Gave +1 Rep to @timid orbit (current: #329 - 29)
mitre slaps.. learning about it now. Such an amazing tool. I feel like I was always missing this! lol
we had a mitre guy come and talk to our class back when i was in school. however not once throughout those 4y did i ever even hear about the att&ck framework
the mitre guy was just giving a presentation about cloud and virtualization security
That is crazy.. This is soo usefull in my eyes.. from each POV blue red or purple..
There's also https://d3fend.mitre.org/
what is the diference and use case?
A knowledge graph of cybersecurity countermeasures"
Ok found it lol
ATT&CK is how adversaries attack, D3FEND is how defenders respond.
Those are from my notes
I keep private shit on my obsidian so I keep it closed.. Share your site dude. would love to have a look
for the copyrighted shit i rly just put it behind http auth (i didn't share auth here ;)) lol
hahahha xD
That seems like a fail
chill thx for askin'
Gave +1 Rep to @final tree (current: #3598 - 1)
yea fr
they taught more advanced concepts and didn't even glaze over some foundational stuff
New colour ?
I got a heart attack. xD The moment I put in pass and pressed login my alarm for the washing mashine went off and I was like.. Ohh noo.. for a sec there xD
i promise i wouldn't put hax on a website with my name on it lmao
Hey, I lost the green leaf by my name finally
hehe anytime, where you from ?
IL
I guess I'm not new anymore
ayein ?
try again in few days
haha my vm thanks you xD (This is like the 90th vm I had to sprawl.. I like clicking on shady links..)
Gave +1 Rep to @timid orbit (current: #319 - 30)
๐
they don't show on mobile for some reason
Ah
hyy brotha
how long does this last?? you been here a while
i thought it only lasted like a day or two
wht happen ?
can i ask you few questions about SAL1 ? i was thinking to do it this week
Oh nothing
i mean ya ofc


