#general
1 messages · Page 2269 of 1
windows lag
otherwise I will completely quit windows
I use 11. very lag
This is what Jabba said, or how is your graduation evaluation?
My W11 doesn't lag at all.
I don't understand the last part.
i use win10 with my cute atlasOS
I want to know what Jabba would say to retired mods
Oh...
Yeah, good luck with that.
it's okay if my laptop is charging. It's slow on battery. but otherwise, I keep using Fedora since I dual boot them.
OK
cool
ohh what's that?
I think just being able to chat here is fate enough
go search it, as I’m not interested in explaining
both same for us.
aight
OHHHHHH
does windows apps work on that?
Welp anyways, i found this video to replace in my trashcan
if you enable them, yea
NICE
and
i know this is gonna make me sound stupid
can i install valorant in atlasos
-# vanguard
gg the camera is so shaky,got motion sickness
yes?
Idk
it’s windose, but optimized for gamers, etc
vanguard is a kernal level anticheat
is this satire
Wdym?
Bro likes playing valorant💀
who doesn’t, it’s addictive at first
can’t lie..
Translating...
"Bro likes having a massive backdoor in bro's computer"
we got .png emojis snowie back
I haven't played FPS games for many years
The trade off for security by using Atlasos is interesting.

Back in high school, I was really crazy about chasing these types of games
u should try ready or not
The game I've been playing recently is Delta Force, but I haven't played it for almost half a year
Yeah that doesn't felt like recently
I tried playing Valorant that time, but I chose Delta.
but you said u haven't played fps game for many years
So I might not be suited for FPS games.
It's just a feeling; later, I start thinking about truth.
😭
you can enable those features in atlasOS if you want it’s your choice
I feel like I haven't played FPS games for so long, so it should be about time
open C —> Windose —> AtlasDesktop —>7. Security —> enable all
I've been playing Hearthstone recently, and this game has been around for a long time
BF6.
guys where can i contact the admin? i had some issues in the website
maybe site-support?
thanks mate
Gave +1 Rep to @sick lance (current: #2 - 3954)
You could possibly post in #site-support and someone may help, but they won't be staff.
ok ok
I think the new pre path is more suitable for beginners
The first room before was simulating hacking a bank, if I remember correctly
Are any of the THM staff active today? I’m in the middle of my SAL1 exam and the scenario reset when I’m over 1 hour into my 2 hour allowance and all of the progress and alerts I flagged have reset
Staff don't work weekends.
Great 🤣
I haven't spent money on exams on THM yet because my job market doesn't care about them at the moment
I didn't spend money either, I got them for free.
So I only have a premium account
I used to be on a business account when I done room testing, the only thing I didn't have was AWS.
spend money for these rooms
wow nice
And I could have had AWS, had I asked.
I’m pissed, the scenario is broken. I can’t see any alerts and now the time runs out and il lend up failing the exam because it’s 40% of the results
If it's a fault, thm will compensate.
Do you have any proof of the progress you've done so far?
I think they will let you retake the exam
Sort of, it reset and I couldn’t go back to the alerts but I’ve got screenshots of the alerts I was working on and the splunk logs
That’s a shitty offering considering the scenario changes and I’ve already invested hours into the exam
Ah good, you have proof.
At least some things were returned, but fully restoring them is very difficult.
It depends on THM's technical backup
Relax for now, tomorrow is a workday
Where you'll probably not get a reply.
I dealt with it during its beta testing, and to be honest, the experience wasn't very good.
Because the knowledge points for multiple topics are the same
guys i wanted to change my name of the pre security certificate
Moreover, as far as I know, some companies use survey platforms to distribute learning materials to meet this need
you should change the name of your THM account?
maybe
Probably need to reach out to support
I think there was a way to change your name, I could be wrong
MORNING EVERYONE
Afternoon
My certificate name, my THM name, and my channel name are all the same
i did and then i tried to open the certificate a few more times didnt work
i emailed them we'll see what will happen
That should be because the certificate has already been generated
is it professional enough?? dont you wanna put it on your resume
You should have them revoke the certificate, and then you can start over with a new name
hmm yes
This doesn't affect me putting it on my resume; at most, I just need to show that I can log into this account
understandable
Path certificates aren't certifications.
Could there really be someone called onesb stealing my certificate
They have a big difference.
So I didn’t do that, haha
Key one being it's a participant medal.
It should be similar to the academic qualifications, after all, it includes statistics hours
It's just not as widely recognized
No, or shouldn't.
An academic qualification is something you learn, then sit an invigilating exam.
Thm can be done by copy/pasting.
Alright, I didn't intend to use it like that either
You have an attacker mindset
But finishing them off is really satisfying
Yeah, don't get me wrong, it's a good way to show you're doing stuff.
I can promise that I at most looked at the writeup, and I can at least explain what I should do to answer those questions
But you can't really use them to say "I'm certified".
Yes, because "cheating" can't be ruled out.
Its more of a participation certification at best no?
yeah
Is anyone whose really good with interpretation of exploits on? I would be really grateful
On what?
After all, there are no shortcuts to learning
It would be a bit of a waste to just copy and paste these rooms
Just imagine 1000+ same certs everywhere. It would just neutral the use
1000 is a small number
I'm not as good as AI💀
🤓 ☝️
if Gtranslate is inactive, does this exploit still stand? wpscan.com/vulnerability/49abe79c-ab1c-4dbf-824c-8daaac7e079d
ok guys
What are you doing?
trying to understand wpscan better.
But the vulnerability descriptions
are very
vague
(at least to me)
you scanned a page with —url and use your api then it links to the cves maybe they have a better description?
even on cve.org and wpscan.com
they explain why the exploit happens and how
but not it's conditions
Yes, the vulnerability is still presenting if the plugin is inactive
for many you can find a github PoC that explains it better
or im just a dumb dumb
From the PoC, it seems it won't work...
Thanks Scrubs! How could you tell? I dont want just yes and nos, I want to be able to understand the descriptions better
Gave +1 Rep to @sick lance (current: #2 - 3955)
You can try directly putting the PoC in
Thanks ! That's a great idea
Gave +1 Rep to @hallow hazel (current: #261 - 40)
However, AI says that this vulnerability has nothing to do with whether the plugin is enabled or not
Yep, tried with AI and gave me the same answer:)
I usually can't tell if it's useful or not, so I just go ahead and try the PoC directly
If the plugin is "inactive" the files etc are still present on the page/server, wordpress just doesn't load them
Standard Script Kid
Manual testing is best testing. Prove me wrong.
Out of interest. Does Wordpress still "load" the files then, else wouldn't a non-loaded plugin be the equivalent of a file you can read but can't do anything with as it is not interacting with anything?
Haven't really used wordpress much
WordPress doesn't load it, the web server still loads it however.
It's application logic Vs server execution
It doesn't seem like a proxy layer
?
I thought it would act like some kind of agent.
Oh, no.
I know almost nothing about this thing
You can tell Apache deny all.
Tl;Dr
Inactive != Safe
This is the way to create a C2 server
right
I won't be discussing C2.. :d

Oh,well..


These are all the things I should have received long ago—what about you guys
Nice
I've already taken everything I could get with one click
ello 
Today I learned some people are really sketchy In discord
My next step is to do the challenge and then get stuck somewhere
Congrats!
Put it on linkedin 
I don't have LinkedIn💀
who doesnt want
Oh, why not?
totally legit " jk "
@golden yew Bro has the same level as me
i don't have either cuz it asks me to confirm identity
I don't know if there are enough Chinese people up there
and i don't have a way to verify
Bro really dodged a bullet
Interesting, I never needed to verify mine
They could be North Korean lol
Idk
use this kitty
greetings
How many chinese people do you need to start using a platform?

You can see its a big phenomenon and this is exactly how they ask for accounts
helo little onee
Yeah
how have you been math
You got me wondering, I'll give it a try
busy bee
bulding a pentest platform
so its a lot to setup

ohhhh coool
I was just wondering if this could help me find a good job, because having you cheer me on is already enough
nice
Exposure usually helps finding a job, not sure about a good one, but it certainly helps with a job
Btw if u r free then check my new bot which is for moderation in my profile
For me, finding an entry-level job in this field is easy
But going past entry-level?
But I will do this; I think I should give it a try
Good luck!
thanks
Gave +1 Rep to @past sparrow (current: #164 - 65)
just need to submit my resume; I have some relevant work experience.
Competing with fresh graduates for jobs is simply bullying
Why u bully me
Said life
"You hack because it is your job, I hack because i dont know what am i doing, we are different"
Lol
nice
Hacking is an instinctive behavior for bro💀
That's a dangerous thing to do, legally speaking
Idk
Yea
if you don't know what you are doing, and you get paid for it, well then you are just a QA tester
What is QA?
Quality Assurance
Ah ok
basically doing user simulation
Ok
good job
I think if you hide the vulnerability when doing something like this, you would have a 0day.
An unpublished vulnerability in an unpublished system
Meh, developers do it all the time, just they test things before putting into production, I don't that qualifies as finding a 0day
I think this goes against professional ethics
Especially if its made by themselves
well, if a company builds an app, then QA is considered to be part of the company, and developers are considered part of the company
I just read thats a famous cinema brand in my country once have a lot of flaws in their systems
have yet to see a flawless system
And those are all basic flaws
"No system is perfect" ahh
So the key issue is to make these people feel like they are part of the company, right

not even that, its more that most systems are absolute garbage
My friend used XOR encryption and thinks he's a genius
I hope he does not use it in live production application that he asks money for
Actually, he really is, because he didn't import those crypto libraries.
I hope I am not indirectly buying his services
Don't worry, you won't, because this is his homework.
Xor encrypt is actually reversible 🤯
Wait, it is encryption, not hashing
And this is not mandatory
Yeah, it is a thing, its just horrible and easily reversible, all you need to do is start turning bits
So he actually did quite well
But it's actually quite easy to achieve
This should be the most convenient way to encrypt
I do hope that at least his plaintext that he encrypts looks random as well, otherwise you can just bruteforce it
It should also work if it's long enough; it will have an effect similar to an additive cipher
Yeah, but then the key must be as long as well
You will choose from several seemingly meaningful answers, but we have multiple ciphers.
It is rarely to see ibm brand in daily use nowadays
It will eventually be exposed.
otherwise you just extract the key from bruteforced ciphertext and plaintext XOR value
If you only have one ciphertext, then you will use many suspected pairs of plaintext and keys
It's a bit like having many solutions to a system of equations, but you can increase the rank by using multiple ciphertexts
Still linear algebra
OH MY DAYS. i wasted the past 20 minutes running in circles on SQLmap because the program started getting all funky because i forgot to put " around the url 😭
like all my parameters got weird and i couldnt answer any questions asked by the shell
Hello
Hello👍
I'M A BOSS
@gusty inlet get him
if someone here knows how to hack instagram they'd report it as a bug bounty for hundreds of thousands of dollars
go to https://instagram.com/login and login using your credentials
😭
nah i wanna get someone's account
unless you're willing to pay more than 100K you probably are just getting scammed
so expensive 💔
ask them to share the password with you
hacking a multibillion dollar corporation isn't very cheap
@lone thistle this dude is trying to get people to hack instagram accounts for him
very silly
yay
congrats
SQLmap is cool, but i was being very dumb in the end
lol, I did 20% of soc level 1. quit then head to red team.
Im doing jr pentester path
Soc > Pentest
personally so far im more of a fan of pentesting, but im open to exploring defensive security and learning about protecting against attacks
i think i like pentesting a little bit more, but im excited to try playing defense for once 😆
if(soc>pentest){
return false;
}
IS it enough to finish pre security and security 101 and soc level 1 to get so tier 1 jop /
I guess yes
get hired as soc level 1? like a real job?
Im learning red team now and blue team later so i can become purple team
yes i mean get my first in cys
I dont think it is enough
no, it's not enough. you need professional certs and internships.
Purple team is a wacky term imo
You are aware that Ben is not a moderator.
Please use the /report feature in the discord.
hard choice 😂
helo guys
THM staff can't do discord bans? kind of goofy, but no worries
can we talk about how divine that feeling is, when you guess your password for some account you forgot about?
You have to be doing plenty of things outside of THM to buff up your employability. University degree is a big one, and surrounding activities like clubs, projects, conferences, other certs/platforms; fill in the gaps for a variety of skill types they look for
THM staff are paid employees of THM and don't have discord powers (unless they have a role related to the discord or do both)
There aren't enough mods
iam in my gradution year already
Nice, good stuff 👍
im still in gymnasium, its probably gonna be like at least 5-7 years before i get a cybersecurity related job :P
sup
at least i have a lot of time to refine my skills
makes sense, they probably should give a lot more people ban permissions though
Year In Industry placements + summer internships are usually also a big thing. I've just secured both for myself this year
Or just get more mods
I applied like 9 months ago and heard nothing
official mod work sounds pretty horrendous, it's unpaid right?
Biggest thing in job-hunting postgrad is they always want you to have some form of work experience. Internships are a quick way to resolve that even if the pay for them is a bit funky
I wanna ask that degree is important in this field ?
yeah according to scrubz, a past mod. but they get access to free merch and thm certs and businessplan.
fair enough in that case
Or I will get the job only with my skills?
they still haven't added new rank colours though :(
Ran out of colours 
Volunteer work is also proper good as well. It's the reason why I secured a YII in the first place, because I was able to use it to frame into a competency based question usually intended for work experience
depends on the country you live in and your connections, but I recommend getting an OSCP or such if you're able to
for most beginner cyber jobs OSCP will boost your chances tenfold
any site to find online hackathon/ online ctf/ online cyber conference/ cyber events in general? hard to find one locally.
Is it necessary to go into a university and then get a degree and so on...
Degree is a big help, but isn't mandatory. Experience is the biggest thing they look for, they want to hear what you've done and what kind of interesting social + technical situations you've flung yourself into and resolved
depends on your country a lot
over here in the Netherlands it's very hard to get a good job without a degree
how much debt have y'all gone in for degrees in uni?
but if you live in a country where most people don't go to uni or college it doesn't matter much
That's bad.
0, universities all charge the same amount mandated by the government
about 2500 euros a year
so 7500 euros is the total cost for a 3 year bachelor
oh damn.
you also get 1500 euros a year from the government for studying
Are u employed?@stone lynx
so net cost is 3K
i lowkey think im lucky being from denmark, where they pay you to attend uni
and its free
yeah, I'm a pentester right now, did one year as a programmer
I do it part time though, I'm still in uni
Cool
UK unis charge £9500/year 😔
Can you tell me about yourself in brief.@stone lynx
are you still an undergradute or pursuing masteral/doctoral
Education is free in Scotland..
just turned 20 earlier this month, I'm getting my bachelor's then getting the hell out
I know a guy who moved from there to here and it sounded delightful over there 😭
Sure, I'm a 20 year old Dutch guy, I've been hacking a lot for about 5 years now, got started with THM
He is a human
just put thousands of hours in and it all came together
ingesting the data for better training
Ohh i thought he is an alien 👾
I did a ton of THM and HTB, from that I was able to do my OSCP
Ohk
How are yall have a lot of experience in this field😭 im just started like 2 months ago
I also do some other competitive hacking
and from flexing on linkedin a lot I got my jobs
We started longer than 2 months
I couldn't sleep last night my cat went missing.
4 years ago I also had 2 months of experience
Omg bruh
but I just didn't stop
But he's finally back.
Then ?
I mostly recommend learning as much by yourself as possible, avoid AI if possible
Real
I didn't stop learning from THM, HTB, picoctf and other hacking competitions
then I got my OSCP and my job
linkedin is pretty important if you don't want to do much social stuff
just humble brag on there
Where do u work rn ?
a small hacking startup, 3 man team
around how many months did u prepare in htb and thm before taking oscp?
well, me and the boss are the only hackers
about 3 years
the OSCP is not very high-level, it's just a lot of low level basic knowledge
and if you don't know one specific thing your exam goes out of the window
how many hours do you spend per day on thm and htb before getting oscp
the learning material they give is also pretty worthless
probably 3+ on average
weekends the entire day, school days depended a lot
ok-ok. thanks for your insights
Gave +1 Rep to @stone lynx (current: #164 - 65)
@stone lynx so u have a lot of experience till now, so what would u recommend to a beginner?
no worries :)
I recommend doing the CTF challenges, write down everything with note-taking stuff like Obsidian
mostly on a tool-command basis
so you write a page for tools or techniques
and paste the commands with some explanation
do u have a blog eduw
and just put in the hours, it takes a lot of time
I don't, that stuff takes too much time for me that I could spend hacking :)
How many languages you know
respectable
by the way
just two, Dutch and English
ptt = tpm?
Computer languages
how many months did it took you to be comfortable with labs?
Sup y'all?
C++, python, C# and such mostly
😭
hello wizarddos 
but most skills are transferrable
hey hey
what
Hello
I focussed on Linux labs first, it's what I recommend
Hello
it took about 3 months or such
Sort of
there's a module called PTT in intel processors
because the basics are not super hard
I recommend the bounty hacker room
it's really good for the basics
Nope linux is pretty hard to understand in beginning
just get stuck in a lot of rabbit holes, you'll figure out what is normal on systems
my motherboard needs a separate tpm device to be attached and i don't have one. if I turn on PTT will i be able to install windows 11?
Windows hacking is a LOT harder to get down well, trust me
the amount of moving parts in it that aren't organised well is insane
You don't have intel?
Does it have ptt?
8th gen supports ptt ig
I know I am not talking about using windows you can use Ubuntu as a beginner
If so, just enable.
aight
If not, you may need to upgrade.
i'll first make a bootable usb first, just in case
I'll try enabling ptt
I'm talking about hacking a linux machine, not using a linux machine
but your linux basics are very important
if you don't know how linux works you won't be able to hack it
so just get familiar with it and watch some tutorials
Right
hacking linux is easier than hacking windows honestly
you'll figure 95% of your hacking knowledge out as you go
sudo hack windows
absolutely, windows is incredibly goofy
always finnicky
and stuff does not work consistently
You'll need either dTMP or ptt.
Ptt enabled is essentially TMP 2.0
Hello all sorry to interrupt. Have 12 days to study for PT1. Any tips. Planning on doing the course twice over and some rooms
both are better than running a macbook, microsoft owns the software on your computer, macbooks don't even allow you to modify or repair your pc
Do some practical labs
On Mac os, u are the user
On Windows, you are administrator
On Linux, you are a f*cking developer
Only 12 days?
is this it?
gemini said it is tho
Don't think so
Yep 12 days. Completely free no distractions dusk til dawn
hmm
Hi guys
Seems like you've bought an attempt and forgot about it right?
Hello wizarddos how are you havent seen you in a while
Hello pseudo how are you havent seen you in a while
Try advanced
tired
Pertty fine, I'm just chilling atp
Why
Can someone help with the XSS last task machine
redid some rooms to refresh memory
Lol no jus given myself the challenge and used most of my annual leave...
Ask here
Ah i see nice
need to add more papers to the paper 2 gal
Ah thats cool nice to hear youre doing work
Good luck, but taking more time would be advised
Hhmm, I wonder if 12 is enough with good notes.
yeah man i feel like i been slacking cuz i need to do the love at first breach challenges too
well
Started the netcat listener, made the ticket with the script and got a response
The issue i got is finding which bit to add to the base64 decode
Oh i see, well its never too late
Which room which task
I'll move there
i been postponing it cuz its like "oh do i know this tool good enough"
Cross site scripting practical task
Well you will only get to know it by using it
tools are kinda intimidatin to me rn cuz i dont know basics of those tools , maybe it will get better once i start with the cybersec101 path
Its ok, we all use different tools all the time it gets kinda "intimidating" but in the end everything works out :)
It will workout for you too
yes brother
apes together stronk
looks like ill have to buy a physical module, there is no tpm setting in bios
If there any new guys that willing to learn together msg me , Also if u are not new and want to learn and improve skills or even help me (beginner) would be awsome. also in the dm tell me what u want to learn 🙂
Hecking😈
How ya doing, might be on the wrong channel so please direct me if wrong. I’m just trying to find a laptop to start. Just looking for some recommendations on nice budgeting laptop for beginners.
Idk but i can guide u on install linux :))
Need a laptop first 😅
YES Punch got adopted by another monkey. I was looking for a gif of him, but couldn't find 1.
Probably around 500-1000£
i have a msi thin 15 b12uc. 511 pounds
Thank you. Just want something to be able to do everything without any struggles
do you want a dedicated gpu ?
to game or run ai models
Yes dedicated ideally
uh huh
what
what work do you want to do ??
In 2026 with that budget you better recommend them a laptop with dedicated gpu
Don't ask
Yes would like a dedicated gpu to also game
alright
lenovo legion
the best
the beast in every segement
5050
or if you get 5060 or 5080
under 1k
my laptop - 511 euro
i5 12th gen, rtx 3050, 16gb ram. not the best but its what i could afford
just pick it up stuff it in your bag and call it a day
you laptop is shid
im a brokie man
lenovo legion all the way
us
Cheers
im thinking of selling mine for a thinkpad or a mac depending on usage i do
all hail the brokie gang
same
i am thinking of getting a lenovo ideapad slim 5 ryzen 7 7735hs
its light
it has a good processor
good screen
and can game a bit
everything but a mac lol
saw it running gta 5 at 100 fps on medium lmao idek if thats true
i need a durable laptop which can withstand my tantrums
fr
i punch screens
macbook is not the one brother
then u need to work on your anger issues not ur laptop
tf
but if you punch it
gay
its expensive
thinkpad
on the other hand
is a mongolian wifey
you beat it she beat you back
but she will never leave your side

AMD or Intel?
ryzen all the way
im an intel person honestly
do you want to run linux distros ?
amd for battery life , if you want performance go with intel
Linux all day
amd
ryzen is the best
ryzen it is
the best
out of the box compatibility (never used linux in my life)
avg ryzen suck dicker
ryzen is good
but
its underclocked
compared to intel
in gaming and high end performance
im not talking bout ryzen 9000 cpus im talking about mid range ones
Ryzen is great
Lenovo legion pro 5 rtx 5060 ryzen 9?
Raise your hand if you ACTUALLY overclock your cpu and ram, cuz I would like to see your voltage and timings.
for sure
you might regret buying a macbook but you will never regret buying a lenovo legion
no
Not since a long time ago
what do u guys think of predator laptop
yeah I didn't think so as most people don't want to fry their hardware.
at least its not celeron, hd graphcics, and 4gb ram tho
Same
Atleast i can play cs2
I miss csgo fps

My friend has one
Its heavy
But build is good
Same
u 1k elo
i will curse you
next all game - all lose
be 1k elo
this is hacking server not making things
that u do
this we do
hello
hi
how are you?
bug bouncing? 😄
im okay, could be better. wasted my sunday than being productive..
how about you too?
Hello Bella 
Ellooo
I see. I am doing quite good, done a bit of work and will continue the rest tomorrow.
how are you doing??
headaches, feeling eehhh, tired, but soon getting ready to go eat dinner with my best friend
Hope you get well soon and enjoy your meal later

I have a photo to share, if you all don’t mind. Just a small update, that’s all :3
of course

I have taken 2 out of 5 meds of the day
Aloy is doing well. Checked on him a few days ago and he remembers me again
so I am very happy.
DOOOGGGOOOO
cute dog
🥺😔
Thank you 
Gave +1 Rep to @languid aurora (current: #172 - 62)
what breed is he
he is like a teddy bear now. A clingy one. 
Pomeranian.
yeah, stay in 1k elo...
now 4 out of 5 meds
are they hard and expensive to maintain?
Is everything ok? Is it like a cold or?
THM 
hormones
I am finally medically transitioning
so blasting my body with estrogen
also BEEEEEEEEEEEEEEEEEEEEN
HIIIIIIIIIIIIIII
Well, Aloy is a bit easier to maintain, just needs a lot of time and attention (because he is so clingy and would chase you for pats), and his personality is pretty friendly too.
thank youuuu, how you doing?
Yay
long time no techno
aye keeping it steady. You know how it is 😎
Hello
your profile photo is pretty nice!!
Is the attack box used for learning the same one used for the challenge machines on premium
heyy
anybody here with a mac? i cannot decide between kitty wezterm and ghostty. i am using tmux on my hacking vm. if my theory is currect i could have a persistent session accross my host and server with wezterm if i would install wezterm on both machines right? i wouldnt want to have tmux for both connections
ahaha, thanks! There's a specific nieche there 😄
indeed indeed, can't say the same for me, got told by le boss that if he saw me online this weekend (on company platforms) he would fire me 😄
Gave +1 Rep to @trim portal (current: #149 - 72)
Yo
The AttackBox covers the vast majority of our content. Mostly for challenge rooms but there are some walkthroughs that also require it 🙂
heh. I am one to talk but do take time for yourself!!!!
do as I say not as I do etc 
yeahh, I was like that as well
boss was like, take care of yourself, if you're not feeling well, then take monday off as well
With premium account, can my box save files to use across both sections
cause I have soo much brain fog, and PMS symptoms 🙃
Unfortunately, any files/changes you make do not persist. Not yet ™
When you spin up the AttackBox it boots up from a template 🙂
?
i guess most paying users uses openvpn more than attackbox though
its not persistent.
Is it going to be a feature later so I don't need a kali vm
See you Bella, hope you have a lovely dinner later. I got to go 
Bye bye everyone

but then mostly everyone uses openVPN after a while
That's what I mainly use
Eh yeah. I don't have the maths/numbers on hand but it's kinda tomato/tomato / 50:50
Good! That is a good habit
I'd defo recommend a Kali/similar VM as you can setup your environment to how you like. But the AttackBox is convenienent and supports a very very large portion of our content from the start. So if you want something to just work - that's a good option too 🙂
Mastablasta
get parrotos
oh yeah, some other cool updates Ben, I am going to parlament soon, we are doing a bootcamp for people who are able to qualify for the european team in ICC
OK thank you
Gave +1 Rep to @lone thistle (current: #10 - 955)
nice! that's cool! best of luck 😎
Attackbox when you are feeling lazy to turn on your vm 💀
i just openvpn on my fedora mainly
ICC ?
thank youuu, and then going to japan for a month in april
Gave +1 Rep to @lone thistle (current: #10 - 956)
Don't 😭
For learning i may use the attackbox if I get connection issues
Oh i see
lmao
International criminal court
international cybersecurity competition, aka worlds championship for people between 15-25
well yeah you can do that. The attackbox has improved a lot lately ngl.
ah its cyversec
I got like 3 regional open vpn profiles, never know which one to connect too
Damn 15 yr old cracked hackers
this is like donutmaster
What's the competition name and how to get into it lol?
ENISA, together with other regional and international organisations, decided to design and host for the first time the International Cybersecurity Challenge (ICC). The aim of the challenge is to attract young talent and raise awareness in the community globally on the education and skills needed in the area of cybersecurity.
But donutmaster isnt going
don't worry after a while, you will remember the entire name of the openvpn lol
Ohh, ecsc
That's nice to hear 🙂
disclaimer: I maintain the AttackBox.
If you have any feedback or ideas, etc, feel free to send my way 🙌
is ICC compe leaning towards more on red team?
EU-central-premium or something like that
it's random challenges of all natures
And eu-West
You maintain the attackbox? Ben, you are a legend for improving it. I will surely let you know if my autistic brain gets any ideas lol
Last year finals were in Poland and I couldn't even take part in quals, as I was without my computer at that weekend 
Maybe this year I'll qualify
Thank you kindly, and yes, please do!
Gave +1 Rep to @peak lagoon (current: #403 - 21)
Yea atleast we got indian servers now so attackbox dont lag as much as they used to
Also can American profile when I'm watching Netflix
you gotta thank ben for that.
Gave +1 Rep to @hexed rune (current: #441 - 19)
I am trying to qualify for the danish team, and on top of that, the full european team
how do u be good at CTFs tho. im not planning to join any major events just university-wide ones
Thank you @lone thistle
Gave +1 Rep to @peak lagoon (current: #392 - 22)
Gave +1 Rep to @lone thistle (current: #10 - 957)
😄 I can't take all of the credit. The regional rollout has a lot of people behind the scenes too 🙌
Learn, practice, read write ups, more practice
And I'll attempt to get on a polish team - maybe this year I'll have more luck and actually get thgere
You gotta be good at hacking
doing everything is hard
Minus coffee addiction
well if you do, say hi to szy for me
jacking all trades
On the topic of CTFs, anyone been doing any fun CTFs recently?
training and doing
id wanna join uni ctf one day. but its not open - bias teachers just pick students who gets to join like the other time.
qualified for regionals friday, did a tracelabs OSINT ctf yesterday, and the 18th march I am playing a finals in italy 😄
Tried tinder recently, can't workout the algorithm
When I think of it now, fat chance - But still it won't hurt to try and I will say hi to him (if I don't forget ofc)
Lmao
Why not setup a CTF club/society amongst the students? 🙂
hahahaha
moood
no worries, I might see him faster than you 😄
Tbh tinder defo harder than hacking amazon, prove me wrong
tried to, my classmates are not interested.
Ah. Sorry to hear. They're missing out!
and i dont have the social power to interact eith people beyond my classmates
For sure - I'd like to meet the guy at some point, as I've heard some tales about him
Having a healthy stable relationship was harder than fighting ottomans
"encourage" them
well, join CCC this year, then you'll meet cool people
they have their own valorant events after school tho. but I dont play valorant.
Our college cybersecurity club is dead af
You mean ICC?
speaking of @lone thistle why you not joining CCC?
No one wants to join it
im not cool enough alas
no, CCC is a yearly conference in germany
lol
and the times/dates never really align well with schedule
awwweeee
Any link you can spare so I can learn more about it?
idk man, these kids my age keeps thinking that cybersec is cool and they want it as a job but doesnt want to learn it.
I have two mates on the orga team for CCC and they always try and get me to come but yeah .... just never really aligns well LOL. One day!
Hack their devices and encrypt their files
They now have to learn cryptography
On one hand sad, but on the other - less competition 
Jk don't try that
They rejected me back then
this is last years event
https://events.ccc.de/en/2025/12/30/39c3-assemblies-teardown/
Dear creatures and participants,
the end is nigh! Days full of encounters, curiosity, tin solder, discourse, music, code and Chaos are behind us. Thank you for filling this Congress with life. You made this event into what it is.
As much as we would wish Congress to continue forever, now the time has come to pack up, take a breath and say goodby...
competition is kinda cool tho. forces me to be on edge than just doing whats enough.
tbh, I am trying to get out of my CTF burnout
So learning german won't go to waste after all lol
cause of AI
Just seen i leveled up to visionary
most of it is in english, but yeah, some german talks
Yea
I have been only been to like 3 ctf in total
And i barely was able to solve anyting
2 tryhackme and 1 L3ak
good effort in trying 🙌 CTFs are weird. I suck at them
CTFs the competitions I play, have changed soo much due to AI and it's both shitty and making everything harder
i think its simple when u have a framework
pen-test methodology
to approach diff machines
i just do thm & htb
one thing I hate with THM is that they name their rooms CTFs
Oh yeah for sure, methodology definitely helps but...idk...I feel like a lot of them these days are obscure. As in, you kinda need to "think like the creator" to solve them. Maybe (and quite likely) it's just a skill issue on my part haha
How so - out of curiosity. We name them challenges, not CTFs. I have some strong opinions on how the CTF label gets applied xD
i mean i do easy ones
for pt1 prep
ctfs help me alot cos it reinforces my learning
the issue is jr pentest module aint enough to pass pt1
YES USA Mens Hockey team beats Canada 2-1
once i pass imma make a ctf list to do for PT1 cos istg shit is annoying
Thank you, be next weeks purchase hopefully 🤞 then I can actually start
Gave +1 Rep to @hexed rune (current: #418 - 20)
I mean it's true you're trying to get flags, but it's more training material, like pentest training and blue team training, but it's not challenges in that sort of sense as the whole other cyber CTF scene is, these rooms is just boot2root, not web, pwn, rev, crypto in the way that competitive CTF's are, so it makes newer people confused when they say that they are really good at CTF's but that being THM rooms, and then they try an actual competition and they complain that the challenges are "shitty" cause it's nothing like THM
Junior Pentest path forms a strong part of it, but we list other preques on the exam 🙂
but everyone in the community believes its not enough to do PT1
Yeah I can appreciate that. Thanks for the comments 🙂
We mark them as challenges, not CTFs which can feel a bit CTFy. Again, I am awful at CTFs haha
But yeah, understand where you're coming from!
Gave +1 Rep to @chilly veldt (current: #9 - 1024)
this what i had to deep and a blow on my ego, it isnot about getting the flag and winning like mr robot, rather it is a bout learning in the process
I'll pass this on as feedback, but yes, JR pentest path itself isn't enough to pass PT1
howd u become a thm staff
Recommended learning has more than the pentesting path on it.
yeah, some just name it CTFs, like mr robot, pickle rick, etc.
it's a b2r challenge, not a CTF challenge 😭
does it include web app modules?
Yeah.
which is why I like HTB, they have challenges that are focused on the actual CTF categories
I work on the content team. I made rooms as a weekend thing back in 2020 and then I got asked by the co-founders to join the team way back then. And here I am in 2026 😄
Cmnatic is part of the bricks of THM.
yeah agreeed. Those examples really aren't CTFs persay 😄

and the 21 pages of other rooms called CTF 😄
I mean CTF collection is actual challenges, but you get where I am coming from
Heh. Yeah. I don't disagree with you 😄
How many are community vs staff created though?
Whole long list of suggested learning by THM to pass PT1. 😄
I think 65/35 from the quick look through the pages
though just writing "ctf" takes every room with CTF in name or description
I agree, but they're not CTFs as to the kin that you're used to 😛
yeah 😄
I won't cause it's my hobby 😛
I've spent the last 6 years perfecting myself, I won't just stop
Did you check out any of our staff-made CTFs like love at first breach? or what was that blue team one we had recent
Those i'd consider CTFs 😛
u been in the game last 6 years?
I haven't cause the last few months I've had a payroll that said 300 hours a month 😄
i started last year
Man.
I have been playing competitions for the last 6 years yes
i wish i never enrolled in college for cybersecurity
I feel so oldexperienced.
Defo worth a punt! And sure I'm technically biast but I think you'd enjoy
Why not?
probably
don't worry, I turn 23 later this year
Yeah, suppose they need to follow a curriculum.
if i could go back id just get a fast food job and do thm
im 23
Eh, do both?
im 51 🙂
It shows. 
im trying but honestly its not hard its just a waste of my time
i had to write 5000 word essay on BYOD last semester
I started working in IT when I was 17 as an apprentice
Pro and cons, or both/singular?
time for coffee and moment with god
Only started working full time in cybersecurity 3 months ago
This is my biggest complaint as someone who has a Bsc & masters in cybersec. It's. OLD.
I mean the Msc was a lot more up to date but yeah it's like.....brug. Why am I learning again how to use nmap at a masters level LOL
me doing night school PhD
my BSc wasn't that old, we got caught using current tools Scottish police etc use.
You done DFIR, right, Scrubz?
Yeah. 😄
Wrong direct reply.
i am so done with education. My masters killed anything going above 
I feel that without doing MSc.
I just want it to be able to call myself a doctor in forensic
perfectly valid
Well specifically digital forensics on small devices
I almost switched to DFIR during my BSC
well, I actually switched to paramedic science during my BSC but student finance fucked it up
then found out that basically only 4 people in the cohort of 100+ get recruited in a DFIR role where I was
so bunned that off
Oh well, gotta get ready for gossip and sushi with my bestie, cya
enjoy!
slim pickens
DFIR roles aren't as easy to get here.
quite
All my peers had to move to England to get positions.
Do you enjoy where you are at now Ben?
Aye, thankfully. I wouldn't change it. I don't quite work in a traditional cybersecurity role but....Do a lot of varied stuff. Cloud architecture, teaching cybersec, etc...

