#general

1 messages Β· Page 2236 of 1

sick lance
#

I knew plenty of people who more about Log4J without knowing so much about minecraft, they're not gamers.

#

I'm a massive gamer, and I don't even associate Minecraft with Log4J.

compact storm
glacial berry
#

I am gonna go drink some tea, and touch grass

topaz steeple
steel aspen
#

Nah just being stupid lol

paper pecan
glacial berry
glacial berry
topaz steeple
glacial berry
steel aspen
#

I'm restarting THM cos I keep forgetting to take notes and then I end up losing myself in it all

topaz steeple
glacial berry
twin ridgeBOT
#

Gave +1 Rep to @topaz steeple (current: #237 - 45)

glacial berry
#

Well, I will be back, gonna go drink and touch some grass

steel aspen
#

One of the main rooms I keep forgetting to take note on, I realise it is its own thing too

compact storm
#

Yesterday, for the first time I have used Claude for one particular challenge. Because my approach doesnt work (in the end it was broken room and it was impossible to finish it :D), so i tried. Here is Python solution I got from AI. πŸ™‚ AI will definitely replace developers and security researchers. πŸ™‚

python3 << 'PYEOF'
import hashlib

data = open('dog.jpg', 'rb').read()
target = hashlib.md5(data).hexdigest()

# What if we just need to prepend or append something that
# the server strips? Like a BOM, or whitespace, or null bytes?

# Test: does prepending 0 bytes change anything for the server?
# No, we know server stores exact bytes.

# WAIT. The "already uploaded" check is by BYTE CONTENT.
# The MATCH check is by MD5.
# So if we upload dog.jpg, it says "already uploaded" because 
# those exact bytes exist in the DB already.
#
# What if we can CLEAR the "already uploaded" state?
# Or what if there's a race condition?
# Or what if we upload to a different endpoint?

# Actually... the REAL question: can we just delete the original 
# dog image from the uploads and re-upload?

# OR: What if the challenge wants us to create a JPEG where:
# 1. Take a DIFFERENT image
# 2. Use fastcoll to make it collide with dog.jpg's MD5
# This requires a CHOSEN-PREFIX COLLISION, not identical-prefix.
# hashclash can do this but takes hours of computation.

# UNLESS... the challenge provides BOTH collision files somewhere?
# Maybe there's a second dog image on the site?

# Let's check: are there other images on the site?
print("We should check for other images on the site!")
print("Try browsing /static/ directory, or checking page source for other images")
PYEOF

Execute it and send me result.

Btw, Opus 4.6 :)))

sick lance
#

Oh god.

topaz steeple
#

use the ai to use the ai

compact storm
steel aspen
#

Says google cant be reached but other websites I can connect, AVG ( don't hate) had web shield on but I turned tha toff

compact storm
topaz steeple
steel aspen
sick lance
steel aspen
sick lance
#

Tried flushing and renewing your DNS?

#

Or are you routing your traffic via THM vpn?

compact storm
# topaz steeple what room is this ai waffling about

last one in CTF... i had correct solution - two separate files with md5 collision, but room was broken - so i thought i have to have some help from AI πŸ˜„ It ended up like this... Instead of saying me, that my solution is correct and room is probably broken, it sent me scripts like this every time πŸ˜„ Random bullshit

steel aspen
#

I've been doing a lot of stuff trying to get SCP to work between two VMs on different devicees to work. Musthave chagned something I've forgotten

nimble mauve
#

Hey can I ask where the questions and problems room is?

golden yew
#

πŸ€“

steel aspen
#

Wheres that

sullen finch
#

Okay guys as a beginner from zero where should I begin to become a pro hacker like ethical hacker

steel aspen
#

Dumb question nvm

compact storm
sick lance
steel aspen
#

Can't even find where to open it. Should I uninstall aVG and just use Windwos Firewall?

compact storm
nimble mauve
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3950)

fading perch
#

i'm addicted

sullen finch
sick lance
#

There are red team entry points, you'll just have some competition.

#

by some, I really mean lots.

sick lance
fading perch
compact storm
steel aspen
compact storm
sullen finch
#

Okay blue team for beginner right

steel aspen
#

No idea of his error code helps

frail zenith
#

Ayo how good is Red Hat certified system administrator

sick lance
compact storm
steel aspen
sick lance
compact storm
sick lance
#

That't why I told you Chrome://

Type it in your address bar...

steel aspen
sick lance
#

^

steel aspen
frail zenith
compact storm
steel aspen
#

err connection closed now

twin ridgeBOT
#

Gave +1 Rep to @compact storm (current: #552 - 14)

steel aspen
#

Only VPN I use is the THM one for connecting to THM

fading perch
#

Is doing OSINT an illegal act?

sick lance
#

However, what you do with the information you find, will detemine legal and ethics.

steel aspen
#

Guess it depends what you do with the info u find

#

Not proper i know

paper pecan
sick lance
#

Yeah...

fading perch
sick lance
#

How will somebody know you're doing OSINT on them?

sick lance
tough pivot
#

Yo guys, when can I play king of the hill and not be clueless? I'm finishing CyberSecurity101 in 2 days is it enough or I must go through pentesting jr first

sick lance
#

If you give information out you find, and they blackmail with it, you're also held accountable.

This is an example.

paper pecan
sick lance
#

Here are two OSINT to give you an idea.

  1. OSINT an interview person to dicsover if you have common interestes you can relate to. -- OKAY

  2. Seen a cute girl at location Y and want to get to know her? -- Grey and creepy.

paper pecan
sick lance
paper pecan
#

not really a bad thing if u dont plan on doing anything with the info

#

depends on ur country law

paper pecan
sick lance
#

Illegal. πŸ˜„

#

Somebody OSINT you?

fading perch
strong sail
#

lol

sick lance
paper pecan
#

naww

#

gurllll

sick lance
#

Yeah, that's not how it works.

paper pecan
#

unless ur in the us or they have ur full name

sick lance
#

Don't be a twat and victim blame.

strong sail
#

Yh it is wdym gang, unless u live in the US ur pretty much cooked cos that's data they need to publish

paper pecan
#

usually its pretty easy to osint from full name especially if its in the us

strong sail
#

like country birth vote, shit like that

sick lance
#

What are they doing?

sick lance
#

Then that's doxxing and very illegal. πŸ˜„

sick lance
strong sail
#

guessing they started with ur unique username?

sick lance
#

A massive one at that.

paper pecan
paper pecan
sick lance
strong sail
sick lance
#

Ergo, victim blaming.

paper pecan
#

geez im sorry im tone blind in texts 😭

sick lance
#

Fuck off then. πŸ˜„

#

Touch grass.

strong sail
#

U can control the info u put on the internet never intended to blame them for doing so, it was a statement

paper pecan
sick lance
#

They can't control what a user installs on their phone.

strong sail
#

"what the user installs on their phone"

trim portal
strong sail
#

r u fr

sick lance
sick lance
strong sail
paper pecan
#

wait but if its publicly available why did the person made it a threat in the first place

strong sail
#

I see u obv rage baiting or just no social life so ima dip, again never meant to blame em; It was a statement

sick lance
# strong sail not informed, no

GetContact is a database with phone numbers and names.

If you give your number to your friend, and they install the app, guess what?

GetContact has your name and number on a public database.

#

So, again, how is that their fault?

strong sail
#

seems interesting

sick lance
paper pecan
#

if u change the password, anything else the person could threaten u with?

strong sail
#

Do a search about u to see what data is linked to ur name and unique username. Nothing beyond legal shit u can do. If u aint got a full name of the person u kinda just gotta pray they aint gonna actually follow through. and obv block em

fading perch
paper pecan
#

nope

#

it reduces

fading perch
high torrent
#

Change passwords immediately and check if any unknown devices are logged in

#

Then inform the authorities

#

Gather as much information as you can

lean crescent
#

hey i am new and i want to lern ehtical hacking on this webside, but i ave to lern from the beginn and tried to lern the linux fundamentals but part 2 and 3 are premium content. can someone give me a tipp how i can lern all these things to get better i only did part 1.

sick lance
lean crescent
#

thanks

tight vector
#

Tryhackme on valentines day should be tryloveme

golden yew
#

I like this cupidbot

#

Because you only need to say

#

This is a challenge I defeated in seconds

golden yew
#

I’ve seen a lot of these 'information-sharing' apps.

#

And the more people use it, the more disgusting it gets...

chilly gulch
#

f

golden yew
#

The Wi-Fi password is the simplest example.

coarse karma
hexed rune
#

Hi

golden yew
# coarse karma exmpl of what?

If someone who hasn't come by even once in a year connects to your WiFi and installs this kind of app, you should get ready to change your WiFi password

#

However, for people like us, setting up a MAC whitelist is easy.

#

and WiFi password can't really be considered personal information because they are not unique enough and easy to replace

#

But this is just an example, referring to the information you authorized being used in ways you didn't expect

distant robin
boreal scarab
#

Well shit

dark frost
#

cupidbot went so eazy my fastest ctf challenge ever XD got all flags in 4 prompts

golden yew
#

In fact, this information cannot be used to identify you

golden yew
#

But it sounds like the answer to some recovery issues

cosmic pendant
#

GM

golden yew
#

Speaking of that speedchat, how did you set up a persistent shell?

#

I really used 'speed type' to get the flag

#

lmao

narrow yew
#

are you picking fights?

cosmic pendant
#

yo yo

narrow yew
#

with someone that designs malware for a living πŸ˜„

hexed rune
#

Hi

grave locust
golden yew
#

I think we should start two listeners, copy the commands in advance, and once we get in, immediately open a persistent shell.

#

Moreover, we can transfer files in advance and use msfvenom to generate a reverse TCP shell binary payload for Linux.

acoustic tangle
#

Sup guys

steel aspen
#

When I unsubscribe, do I get remaining days?

#

My official course starts sooner than I thought so gotta focus on that

golden yew
#

i think yes but im not employee

loud marlin
#

you get days up to when sub needs to end

little wasp
#

Hey guys

acoustic tangle
steel aspen
#

Says today scheduled cancellation but still have 15 days

loud marlin
#

then you get15 days

#

it will stop to be at original end date

steel aspen
#

See how much i can accomplish, course starts in a week so realistically 7 days

loud marlin
#

what you pay is what you get

balmy geode
#

Man anybody done that cupid one??

golden yew
#

i ctf for 9.5 hours today

little wasp
#

Is anyone here ever made like, new technology or something of the sorts

#

Has*

balmy geode
#

How's that

little wasp
#

Like, inventing something new

golden yew
#

2567

little wasp
#

67?

acoustic tangle
golden yew
#

all easy room

#

lmao

little wasp
golden yew
#

I'll look at the last three tomorrow.

frozen monolith
#

Hello Everyone
I’ve just published a new blog post on SSH Port Forward and Tunnelling, ⁠ while acknowledging that many of us still find it confusing, no matter how simple they seem. As part of Project NetPivot-X, I’ve taken a step further by breaking down this concept with clear explanations and practical demonstrations.
Check it out here: https://teamsimple.net/blogs/ssh-port-forwarding-socks
Feel free to give it a ❀️ if you like it and share your thoughts

balmy geode
acoustic tangle
golden yew
#

yes 2567

little wasp
#

Is it possible to break down a phone battery without exploding it?

acoustic tangle
golden yew
loud marlin
acoustic tangle
loud marlin
#

you can't fix battery if you open it. and chemichals are quite dangerous when get on fire

little wasp
#

Awww damn

golden yew
#

I don't know, because the ranking rewards probably have nothing to do with me

muted storm
loud marlin
golden yew
#

As for these completion rewards, they are lottery tickets. I don’t know what they draw for, but if you win, you'll be notified by email.

little wasp
loud marlin
#

chemicals inside gets wasted over time. you can't fix it, and there is no reason for it to do heh

#

special if you have LiPo batteries. they are quite dangerous

little wasp
#

So the battery is quite literally a mini bomb

loud marlin
#

if handled wrong yes

#

when they get on fire is chain reaction and is hard too stop it

little wasp
#

I'm guessing the time it explodes differs on the battery

loud marlin
#

when battery gets to be pillowed, alike baloon, then is time to say by by

#

at last that is case to get rid of it asap

tiny osprey
#

could you guys teach me grey hacking

loud marlin
#

nop =/

tiny osprey
#

why not

languid aurora
loud marlin
#

there is no grey. if yoou hack without permission, is illegal

tiny osprey
#

what if you're doing it for something good

cosmic echo
#

i think this valentine's ctf is maybe for couple cuz i cant find shit

quaint ferry
loud marlin
cosmic echo
#

i cant type today omfg

quaint ferry
tiny osprey
loud marlin
cosmic echo
#

i just played val and turned on the machine

golden yew
cosmic echo
#

turned on in the sense

#

power on the machine

sonic grove
#

quick question. is the score board for the ticketing rooms module rigged? cause most of the guys that actually completed it first are not there, and it keeps changing

golden yew
#

em

#

ticketing rooms has score board?

little wasp
#

Can the government or anybody send me a message, and it turn off my device

#

Is that a possible concept

sonic grove
cosmic echo
golden yew
#

i have 400 points in lafb

narrow yew
loud marlin
topaz steeple
little wasp
#

Shii idk they be experimenting on the human mind probably

#

Ohhh you in Gaza?

narrow yew
#

if something is off its off

little wasp
#

Free Gaza

quaint ferry
cosmic echo
#

I wake up -> i feel motivated -> i open thm and power up a machine -> i fail miserably and leave

little wasp
#

Ok

cosmic echo
quaint ferry
sick lance
#

Pegasus spyware can read your messages, calls, photos, location, turn on your mic, camera and switch off.

#

But what would the point in that be?

If your device is off, they can't do any of that.

cosmic echo
sick lance
#

Womp womp everybody ping.

quaint ferry
paper pecan
golden yew
#

hi scrubz

sick lance
#

hi sb.

quaint ferry
loud marlin
#

ello scrub

golden yew
#

I'm considering changing my name to 'null', this more confusing field

sick lance
#

Hello Relax.

feral whale
#

Nah cause so many people probably have that name

#

Pick something unique

#

How2LaunchKubernetesAttacks

sick lance
#

How about Not Null.

feral whale
golden yew
#

I actually don't like unique names.

sick lance
#

Tbh, whenever I see Null, I insantly think of Nullsec

cosmic echo
feral whale
feral whale
#

0,73

#

😞

sick lance
#

0.73 is still > than 0, so not null by definition.

golden yew
#

actually it's not a point

#

.

winter mesa
#

Anyone love at first breach?

golden yew
sick lance
#

No, I don't love at first breach, thanks for asking.

feral whale
winter mesa
# golden yew

I completed the first 3 but stuck at 4 someone help?

feral whale
golden yew
#

Actually, I'm about to solve the third one.

winter mesa
feral whale
winter mesa
golden yew
#

But a small problem came up, I should check it against WP later.

sick lance
#

Is corp AD?

winter mesa
winter mesa
feral whale
golden yew
feral whale
#

Did u finish the room my indian frΓ€nd

golden yew
#

I have already written a key pair generator using AI, and it can predict the private keys of other accounts

#

But even if I have the private key, I still can't produce a signature that can pass verification.

#

😭

golden yew
#

My script is indeed based on the steps on the help page, and it is in hex format.

#

so I skip it

golden yew
#

I know I'm just one step away from success, but I really have no clue.

#

crypto is like this, right?

#

I think it's already pretty good to have gotten this far.

winter mesa
golden yew
#

oh

#

that a point

winter mesa
#

Visit about page

halcyon goblet
#

Guys someone help me , when is my voucher going to expire?

golden yew
#

okey i know next

#

I did check the about page.

#

but missed it

stuck ridge
halcyon goblet
stuck ridge
golden yew
twin ridgeBOT
#

Gave +1 Rep to @winter mesa (current: #1438 - 4)

halcyon goblet
twin ridgeBOT
#

Gave +1 Rep to @stuck ridge (current: #796 - 9)

hexed rune
#

I have completed 5 rooms will work on more tonight

#

Mein deutsch freund

golden yew
#

🀣

hexed rune
golden yew
#

When I saw the task document for Cupid Matchmaker, I already understood.

stray fox
# hexed rune

It's about the performance gains compounded πŸ˜‰. Anyone can be O(n) when you only do it one time.

golden yew
#

It's most likely a challenge designed to trick Cupid into looking at your dangerous XSS payload.

#

just my guess

#

Tomorrow I'll know if I guessed right. I'm too tired to play today.

halcyon goblet
#

Out of curiosity, recently i got an email with this sub "Invite to meet with TryHackMe Product Team"

I successfully attended it ( virtually) ..can i expect some type of gift like voucher something πŸ˜…

#

Or is it common

golden yew
#

i like voucher

halcyon goblet
golden yew
#

I've received emails like this

#

But I wasn't involved

winter mesa
icy walrus
#

Does anyone from LATAM having a really bad experience with the target machines?

golden yew
#

Because my English is actually poor, ||I'm actually using translation to communicate.||

hexed rune
winter mesa
hexed rune
#

nope

vale nova
#

does anyone know how to decrypt the masterkey for browsers?

#

i need to learn

reef vale
#

hiii

golden yew
#

masterkey for browsers?

icy walrus
#

Does anyone want to team up? I ve just started with the 1st one

shell furnace
#

Is there voucher for subscriptions?

golden yew
#

That key management tool usually requires the password of the currently logged-in user.

peak lagoon
golden yew
#

For personal use, it’s almost as if it doesn’t exist.

shell furnace
#

welp

shell furnace
peak lagoon
#

Or if you are student, you can get discount

shell furnace
#

Is there a way to handle
Payments aren't available in your region due to provider limitations.
without using something like Wise

shell furnace
golden yew
#

Until you try to remove password login from the hard disk image

peak lagoon
#

yeah that works too ig

shell furnace
#

VPN?

golden yew
peak lagoon
golden yew
#

I never tried it

vale nova
#

Thanks, would you recommend any videos on this topic?

twin ridgeBOT
#

Gave +1 Rep to @signal ingot (current: #414 - 20)

vale nova
#

would claude help with that??

shell furnace
#

does extension on chrome will work?

#

i see

paper pecan
golden yew
#

i'm already a premium member!

peak lagoon
#

yeah me too

shell furnace
#

I think it is a bit risky using vpn to buy subscription

peak lagoon
#

i have no idea if its different depending on the region

golden yew
#

not a bit

#

a lot

shell furnace
shell furnace
#

ye phone and laptop are the same

paper pecan
peak lagoon
#

oh yeah mine is cheaper than that

paper pecan
paper pecan
golden yew
#

Some strict forums that I know of will ban users from posting if they use a VPN.

shell furnace
paper pecan
peak lagoon
#

yeah its like 250 rupees approx per month

shell furnace
peak lagoon
#

thats like $2 something dollars

paper pecan
shell furnace
#

i mean staff xD

shell furnace
paper pecan
#

ahahaha bro was ready with his link😭

golden yew
velvet shoal
#

Any networking student here?

paper pecan
paper pecan
golden yew
#

baby networker

stuck ridge
#

Yo i just realized that if the fridge have uptime, it will be 2 years 3 months 21 hours 12 mins 20 seconds

velvet shoal
paper pecan
peak lagoon
shell furnace
paper pecan
golden yew
#

okey it's too late 23:00(GMT+8)bye U guys

paper pecan
golden yew
#

Goodnight

shell furnace
#

because it is verified?

hexed rune
#

completed signed room too

twin ridgeBOT
#

Gave +1 Rep to @paper pecan (current: #748 - 10)

paper pecan
shell furnace
#

wym by rank?

vale nova
#

any channel where people just send python files?

shell furnace
#

wait

#

2072216

wraith sage
#

Is the THM website dashboard down or sum?

shell furnace
#

I am.. what do you expect

#

no 😭

#

I'm on 1st year wdym

river garden
#

sup

wraith sage
#

It's been acting all week

icy walrus
#

Hey for the first challenge, I have to guess the flag path? Or is there a way I can get to know it

paper pecan
#

sup zack

proven quartz
boreal scarab
long summit
#

I'm losing my mind with the response submissions, I entered the response 4 times , had to restart the page and then the same response was accepted

vale nova
#

Does anyone have a python file that goes thru all your chromenium based browsers, finds the masterkey, decrypts and actually gets data?

hexed rune
#

now i am stuck at corp website

fading perch
dense storm
#

hello all

shell furnace
loud marlin
vale nova
shell furnace
#

Btw may someone spill some cybersecurity roadmap

loud marlin
#

getting key from hash or so is quite time consuming

topaz steeple
mighty prism
#

looking for a pythin mentor tbh, and i dont mind paying
i can tell who is a scammer/bot, so be wise and have VERY good and solid python experience
i will be like testing u if u dm me, i want a good quality teacher for py and i WILL pay if u want

pseudo pollen
#

how many cost premium?

loud marlin
#

130e cca per y

stuck ridge
wide magnet
#

Ah yes you can do it on Linux the Brave comment was more for phone based stuff

shell ridge
#

Hey everyone, I'm really into cybersecurity and hacking, and I'm always looking to learn more and improve my skills. I'm dedicated to getting better, and I think collaborating with others is a great way to do that. I'm hoping to find who are into the same stuff and might want to work on projects together.

Let me know if you're interested in connecting and learning together Looking forward to meeting some new people in the community!

empty rivet
#

quick update on my room: i somehow forgot to use the most popular username for the credentials and wasted 6 hours

clever turret
#

Wheat bread ok

quaint ferry
hexed rune
#

finally completed corp webiste room

#

too

river garden
#

ok guys; give me terrible use cases for my clawdbot

timid orbit
#

signed messages has fried my brain harder than go/jo v. sukuna

#

mainly cuz i am no bueno con crypto

coarse karma
river garden
#

; next try

proper crane
#

any hint for cupid matchmaker after i 've reached login page

timid orbit
proper crane
timid orbit
#

oh

#

ok i was gonna say:

vivid ice
#

Hello everyone. I am looking for a grey hat hacker who can help me recover a hacked Microsoft account. For more info please dm me.

river garden
timid orbit
#

i know

hexed rune
#

Use gippty to craft a nice code to forge admin mssg sign

timid orbit
#

chatgippity?

hexed rune
#

Yes

#

Or you can do it on your own if you can code

timid orbit
#

i might just use python library but idk

#

i'm re-learning how RSA works rn lmfao

hexed rune
#

Thats how you do it

#

Imagine what the actual ctf will be like

timid orbit
#

i need to get my scripting game up

hexed rune
vast sparrow
#

im the benginer

#

hello everyone

vast sparrow
#

hahahahah

#

beginner

#

yes

#

no benginer

muted dawn
#

Hi everyone! I just joined the group and I'm a bit new to TryHackMe and CTFs. Could someone please explain how things work here ? Thanks!

timid orbit
proper crane
#

and if you don't you will find out the cybersec memes are real

timid orbit
#

I wonder if these early TryHackMe rooms even come close to how good you need to be for jr pen test or sum

proper crane
#

and when gus fring starts tryhackme

#

tryhackme fears not gus

proper crane
#

i ve done so many but only burp and the gobuster worked out for me

timid orbit
#

So unless I can no-diff these rooms I’m not even a chance of being jr pen test level

proper crane
#

you cant crack anything maybe

#

now i know opensource knowledge is much better

oblique harness
muted dawn
hexed rune
sick maple
sick maple
odd heron
#

Guys how important is the fundmentals ?

sick maple
proper crane
timid orbit
#

Im cooked chat

odd heron
sick maple
proper crane
#

how

odd heron
sick maple
sick maple
proper crane
timid orbit
# odd heron why

I’m not even close to how good I need to be in order to be a Jr Pen Test

proper crane
#

i'm in it

timid orbit
#

I mean I’m not going for pen test role but still

odd heron
proper crane
timid orbit
odd heron
timid orbit
#

23

odd heron
#

so what are u focus on now ?

timid orbit
#

Everything πŸ™ƒ

odd heron
timid orbit
odd heron
#

try to to focus on specifc path first

timid orbit
#

Can’t rly help it. I wouldn’t be if job market didn’t suck

odd heron
#

how good are you with the basics or fundmentals ?

timid orbit
#

Pretty damn good outside of AD

#

And networking

odd heron
#

nice keep going then

loud marlin
#

ai didn't fix any shit so far

timid orbit
#

Yeah CCNA is one of the certs I’m going to work toward and I’ll learn AD more and more as I learn blue team, red team, and some sysadmin stuff

#

Altho the more I think about it the more I just wanna do Net+ cuz lazy

odd heron
sick maple
#

it's been years after I last used this

odd heron
#

thats cool man actullay thats my third day XD

cyan locust
#

who wanna inv me to their team for today's box? HeartDevDay2025

sick maple
timid orbit
odd heron
timid orbit
odd heron
#

btw does proton log our traffic ?

timid orbit
#

Their entire model is privacy so if they betray that they will lose a lot of customers

quaint ferry
tropic spear
#

Good day everyone) I want to join the team to complete the Valentine's Day challenge together, but the form on the website does not create my request, so I'm writing here)

limpid sigil
#

anyone tryna join me in love at first breach ctf

tropic spear
# odd heron check support

thank you) do you mean on the website? I think people are celebrating, it's not convenient to disturb)))

twin ridgeBOT
#

Gave +1 Rep to @odd heron (current: #3631 - 1)

tawdry jungle
#

i finally finished the metasploit module

#

took me a while

timid orbit
tawdry jungle
#

kinda. i don't think only the module provides enough knowledge to apply it irl

#

it will take more practice than that

#

i know how to use the tool, but there is a lot more to it, like detecting possible vulnerabilities within the OS

#

in the module we use mainly eternalblue, which is not as common nowadays (it's still pretty common where i live)

boreal scarab
odd heron
tawdry jungle
elder marsh
alpine dune
#

what am i missing here

near thistle
#

Guys I am fucked with that signed messages room

near thistle
tawdry jungle
#

the answer is in the cve.org page for toolshell

tame ember
#

My people. How are you doing

raw dawn
#

@gusty inlet how are you playing tryhackme in discord?

tame ember
alpine dune
#

It is literally the same

raw dawn
#

there is a tryhackme app?

tawdry jungle
#

i don't know

alpine dune
#

CVE-2025-53770
CVE‑2025‑53770

#

lol its the dash

river ore
#

Not that im aware

tawdry jungle
#

lol

alpine dune
#

so stupid

river ore
#

Happy valentine's day πŸŽ‰ 🌹

timid orbit
civic mica
#

hello markiplier my name is everybody

civic mica
river ore
civic mica
river ore
#

Not for me lol

civic mica
#

i dont think any time zone has a 24 hr difference

civic mica
#

mb

river ore
#

All good I know there's a variety of time zones in the channel

timid orbit
#

central standard is the only real time zone though

#

everything else is just made up

river ore
#

Lol

dark frost
#

anyone did Signed Messages room ?

river ore
#

A few have

civic mica
dark frost
timid orbit
#

and their toilets flush the wrong direction

#

everything about australia is backwards

fleet moat
#

i just joined the love at first breach and i entered an easy room named CupidBot and i asked the ai chatbot for the flags and it gave them to me. LMAO was it that easy or it was supposed to be another way

hexed rune
#

Speed chatting is making me crazy

wraith flame
timid orbit
# hexed rune Yup it was for toddlers

sooo you're telling me the first room is actually decently hard and requires quite a bit of investigation then the fifth room is just "hey AI, what is the flag?" πŸ’€

mighty prism
#

Yesterday was the birthday of CVE-2024-21413

wraith flame
sand trench
#

@hardy cipher sorry don't check message requests often... shadows cheese knowledge is mostly from cheese.com but there are some other places shadow looks at here and there sometimes

tawdry jungle
#

is this normal?

river garden
#

sup

river ore
loud marlin
#

yes, dialup was 56k speed

half relic
#

is that netscape navigator or something lol

slow cloud
#

Nowhere

#

Since thats not ethical

fast linden
#

dark web

mint vine
#

unfortunate

#

thanks for info

fast linden
#

would u consider a hacktivist a grey hat hacker?

chilly veldt
#

hacktivism is illegal

fast linden
#

so u dont think "hacking" can be form of protest?

half relic
#

vigilantes

loud marlin
chilly veldt
#

taking down servers is illeal, even if it's a protest

half relic
#

it can be but its also still technically illegal depending on where you live i guess

#

i don't know of anywhere that would be legal though

grave locust
fast linden
#

well if the government can do it why cant we yk?

loud marlin
#

@boreal scarab aaaand here we go lol
https://www.youtube.com/watch?v=9LjgqZ2wP0g

Check out the Bambu Lab H2D -- a massive, multi-tool machine that can 3D print, laser engrave, laser cut, and more: https://ntck.co/H2D

I 3D-printed a pair of shoes and ran five miles in them. It sounds insane, because it was. But this was only possible through the Bambu Lab H2D: a machine that goes far beyond normal 3D printing with dual noz...

β–Ά Play video
chilly veldt
fast linden
#

no bc im not law enforcement

chilly veldt
#

that's what the government does

loud marlin
fast linden
#

so the governemnt is put backdoor access into our cpu WITHOUT OUR PERMISSION

chilly veldt
#

alex, my nail broke

#

it's cracked on one side

loud marlin
#

no one will ask you'r permission to backdoor smth

fast linden
#

no its the truth its legit documented that they do that

loud marlin
chilly veldt
#

it's my thumb

#

from pressing spacebar too much

swift kettle
#

Aw cute valentines server photo haha

fast linden
#

are yall doing the valentines event btw?

swift kettle
river ore
#

I've done 2 so far

loud marlin
loud marlin
chilly veldt
#

I might take off all my nails

fast linden
#

bella seems smart

loud marlin
#

off... that's going to hurt

chilly veldt
#

just some 98 proof alcohol and it's off

loud marlin
#

ohhh

#

the paint thing... lol

chilly veldt
#

it's just gel hardened in UV lights

loud marlin
#

acetone is generaly good for that kind of things

chilly veldt
#

yeah

loud marlin
#

just smells like hell =/

fast linden
#

hey guys it it normal if ur pc starts smoking?

loud marlin
#

totally

fast linden
#

ok thanks πŸ‘

#

you guys know any computer pranks?

candid merlin
#

THM also has a python course?

hexed rune
#

Anyone done with speed chatting ?

hexed rune
#

Or just do that scary maze prank where there is a jumpscare

fast linden
hexed rune
#

yess

fast linden
#

is the THM certs worth doing?

hexed rune
#

no lmao

#

its just to learn

#

cissp and these certs are worth it

#

tho they cost money

fast linden
#

like the SEC1 OR PT1 cert

hexed rune
#

comptia

hexed rune
fast linden
#

ok thanks

loud marlin
#

frack... forget to calibrate printer before print =/

hexed rune
#

nice

fast linden
#

can i get comptia pentest+ instead of regular comptia+

hexed rune
#

yea ig

loud marlin
#

you can get any iirc

sullen plume
#

hey! where can i ask for help with a pentest im doing rn?

#

outside project

#

i dont know where to ask

loud marlin
#

pentest as CTF or?

sullen plume
#

real pentesting

#

legally, got permission

loud marlin
#

im not sure that is smart to share that kind of info at first place

sullen plume
#

wdym?

loud marlin
#

to share data of pentest with rnd ppl... idk hoow to say

upbeat meteor
#

If it's a real engagement then that's private between you and the client

sullen plume
#

im just asking for help about pentestmonkey php revshell

#

because it doesnt seem to be working

#

i wont disclose any other detail

loud marlin
#

not all revshell work's

upbeat meteor
#

Lots could be going on. Shell doesn't work, something is detecting and blocking. Target isn't really susceptible

gray wadi
#

excuse me, but does anyone know how to get started with a room using Kali instead of AttackBox?

sullen plume
#

Warning: Undefined variable $daemon in /var/www/filehost/uploads/revshell.php

loud marlin
#

well... there is tyou problem

sullen plume
#

i thought it was some kind of bug or something

#

Warning: fsockopen(): Unable to connect to my.ip.address:9001 (Connection timed out) and this made me think it was some firewall shit settings

loud marlin
#

you have undefined variable

sullen plume
#

it always worked so thats strange

#

lemme see

loud marlin
#

what kind of pentest is that when you say it worked but not now lol

sullen plume
#

kali ctf and a rasp pi environment

#

$daemon =0

loud marlin
#

is it ctf or is pentest =/ dheck you doing

sullen plume
#

pentesting

loud marlin
#

well... the basic revshell and so things does not work in company size servers. at last not so easy

sullen plume
#

customer says its like self hosted

loud marlin
#

if network is firevalled and restricted it will not work

sullen plume
#

fair

loud marlin
#

closed port or so. blocked in/out connections, ...

sullen plume
#

thanks

upbeat meteor
#

If you're at least able to get a shell uploaded a web shell should work, from there if you can get a privesc then you could get a revshell on a port below 1024 which some are likely allowed outbound

sullen plume
#

okay does pterodactly panel have some sort of dirbusting spoofing lol?

#

it surely does

ivory rune
#

why isnt my website loading ?

verbal zinc
#

guys what is the best VM free software for mac

ivory rune
#

could someone tell me

verbal zinc
#

or like one of the challenges

ivory rune
verbal zinc
#

I am currently not experiencing any issues with it. If you are also Eastern Time it might be a problem in your end.

#

are you getting 404 or some other error code or just not loading in general

mint shoal
half relic
#

what issue. not working can mean a lot of things

#

not that i can fix it probably just curious what the actual issue is

proud turret
#

i wanted to post on itel some of the most yet unhackable form of communication ><

hexed rune
#

finally done with all the rooms

verbal zinc
half relic
#

depends on what the error message is

verbal zinc
mint shoal
verbal zinc
#

did you make sure the url is correct?

half relic
#

Β―_(ツ)_/Β―

verbal zinc
#

I think I was getting 404 as well a little while ago but its currently working for me

ivory rune
#

it loads too slow or tells to refresh again and again

verbal zinc
#

Maybe weak internet?

mint shoal
half relic
#

hmm weird i havn't had any issues here in north america

mint shoal
half relic
#

maybe its regional or something

ivory rune
half relic
#

work is so boring today

stuck geyser
#

how do we claim the role from tryhackeme ?

boreal scarab
#

Oh wait, it's shit talking @chilly veldt , even better lol

sand trench
#

BlΓΈrgen SnΓΈrgen HΓ¦p DΓΈrga flΓ¦skeblomp Ogh SnΓΌffelgΓ₯rd
to you too beerrise

wet carbon
#

new event is awesome, but I couldn't complete a single room bc of the unstable connection 😭

sand trench
#

:D

sand trench
#

NO COMMENT

radiant bloomBOT
#

@near thistle Please slow down. Further spam will result in a short timeout.

near thistle
#

Guys I need help i am stuck in signed messages room 😭

#

It's been hours. NotLikeThis

slow cloud
amber summit
#

why is it heart theme

#

as if any of us could relate

past sparrow
#

its trydateme, rebranding

amber summit
#

skull emoji

verbal zinc
#

Whats the best free vm software for mac

quasi dome
#

3 hours trying set pf sense up and open a ssh port to find out i forgot to press save to give user permission secondly the worst thing the machine im trying ssh with was assigned with 192.168.70.0 for no f5ckn reason

hexed rune
#

Ignorance is a bliss

quasi dome
hexed rune
quasi dome
#

She didnt say yes

hexed rune
#

The more my will to live and my hatred increases

hexed rune
quasi dome
#

Her loss dont be sad

hexed rune
#

I wasnt worth it

#

And honestly

#

If i were in her place

#

I wouldve left myself too

quasi dome
#

At least ur honest with urself

rapid merlin
#

The what now

#

whut du heeeil

hexed rune
quasi dome
#

Okay bro

rapid merlin
#

thats pretty acurate to me tbh

quasi dome
#

How old are u btw

#

17 ?

rapid merlin
#

who?

quasi dome
#

Him

hexed rune
#

I am 19

rapid merlin
#

Hi

#

Damn how old ru cloud

hexed rune
quasi dome
#

Ohh the depression arc dw give it 2 ,3 years and all u would care about is what u gonna eat today

rapid merlin
hexed rune
rapid merlin
#

what you should be saying can i eat today?

quasi dome
#

2,3 years maximum

hexed rune
rapid merlin
#

i will turn my depressions into rage

hexed rune
rapid merlin
#

wym?

#

When I get bored I start to Programm random stuff

#

Like an OSINT tool

quasi dome
#

I dont handle anything

rapid merlin
#

Or a pwnagotchi

#

when i get bored i workout or study etc

#

when i get sad

#

i workout

#

when i get really sad i go punch walls

#

Well one time I made a Programm that will triangulate the location of an IP . It is far more accurate then a normal IP tracker I was kinda bored

quasi dome
#

and today i drunk 2 cup of coffee and ruined my 2 years coffee free run

rapid merlin
#

today i talked to cute girl

quasi dome
#

Ohh

rapid merlin
#

Damn

quasi dome
#

H might be the problem

#

U*

rapid merlin
#

u gotta channel ur confidence bro

quasi dome
#

I never talked to girls

rapid merlin
#

huh why?

quasi dome
#

Idk

#

What u mean why

rapid merlin
#

Have you guys ever been on a hacking contest

quasi dome
#

Im just waiting they come talk to me

rapid merlin
#

I have been on one when I was 13

rapid merlin
#

I was 20th place of Germany lol

quasi dome
#

Nice

sturdy sequoia
rapid merlin
#

iv been in idk

rapid merlin
quasi dome
sturdy sequoia
quasi dome
#

Woah

rapid merlin
#

Dayyuuum

half badge
rapid merlin
#

I'm 16

#

im 14

quasi dome
#

Im 22

rapid merlin
#

im a fetus

quasi dome
#

Holyshii alot of minors

rapid merlin
#

Yh

sturdy sequoia
#

I'm just waiting for the other oldies to come online

rapid merlin
#

K

#

cool

sturdy sequoia
#

Seems like this server is full of babies and grandpa's

echo sentinel
#

We can ping some oldies lolz

rapid merlin
sturdy sequoia
quasi dome
#

Hm is the gif working ?

quasi dome
#

Its almost 12 am here

rapid merlin
#

Hmm I can't post images

quasi dome
#

And i need to wake up 7 or 6

sturdy sequoia
wild rose
rapid merlin
#

I wanted to show my pwnagotchi on my phone

rapid merlin
sturdy sequoia
sharp citrusBOT
sturdy sequoia
rapid merlin
#

Ah okay

rapid merlin
#

Except a laptop or pc

sturdy sequoia
rapid merlin
sturdy sequoia
#

And what do you mean by dangerous? Destructive? Effective?
Those devices are very specific so it's not like 1 in inherently more dangerous than the other

rapid merlin
#

Ok I'll try to be more specific

#

More destructive

sturdy sequoia
#

My first thought would be a wifi jammer/dos device

rapid merlin
#

So something like that dstike deauther watch

#

Anyone know how I can hack a Roblox game called driving empire

rapid merlin
#

Or u can do it for me

rapid merlin
#

I’m tryna get revenge on voldex

rapid merlin
sturdy sequoia
rapid merlin
rapid merlin
rapid merlin
chilly veldt
#

and really illegal

rapid merlin
#

And hacking isn't always the same

rapid merlin
rapid merlin
rapid merlin
sturdy sequoia
rapid merlin
#

I’m quite talented

zinc grotto
#

so how exactly do we join the valetines ctf room? when i click join ctf it just doesn't let me... anyone know just @ me pls

rapid merlin
#

But it's still nice to have it as a watch

sturdy sequoia
loud marlin
#

it's illegal too deauto rnd devicethat you do not own or have permission to do so

rapid merlin
#

But everyone has a different opinion

sturdy sequoia
rapid merlin
sturdy sequoia
#

but yes, its also illegal

rapid merlin
#

That's why I have programmed my own pwnagotchi on my phone

#

I’ve hacked some games

#

Well my phone can't deauth because it doesn't have an external adapter but it can listen

chilly veldt
#

let's not talk about illegal things

rapid merlin
#

Why not?

#

Those are basic pentesting things

chilly veldt
#

cause it can get this server banned

sturdy sequoia
chilly veldt
#

deauthing is not basic pentesting

#

it's never used in a pentest

rapid merlin
rapid merlin
sturdy sequoia
shell ridge
#

um guys

chilly veldt
shell ridge
#

i made a rat on 2 weeks learning

#

it doesnt have alot but it works

#

πŸ˜„

chilly veldt
#

what you're thinking about is red teaming

rapid merlin
#

Ok

limpid sigil
#

so yall talking abt illegal stuff eh

#

yall better watch out

sturdy sequoia
#

haha, im more scared of the mods than any sort of law enforcement