#general
1 messages · Page 2421 of 1
Ok
Guys when do i know if am ready to switch from tryhackme to hackthebox. I heard the ctfs are more difficult
when your subscription expires
@tranquil geyser always will be

its hard to answer. try an easy htb box and see how you go, if youre not ready, come back after a few months
Thanks
Gave +1 Rep to @sturdy sequoia (current: #49 - 240)
hello
@rapid merlin when you've done more than 50% of THM then move on
I'm gonna heed your advice
I have a shit ass goldfish memory
I completed the jr penetration tester certification and 3 more
So I have 4 certifications
yer you should be fine starting htb now
Really ?
@rapid merlin even so theres a lot of great content on THM. but you def could try some HB labs
yer like htb is harder but its not impossibly hard. from the little i know about htb it seems like their easy boxes are equal to hard thm boxes
Precisely
Am scared that htb boxes will destroy me lol
THM gives u foundational knowledge and HTB extends that
Yep. 
although i did meet a few 17 year olds recently who did htb boxes, so they cant be that hard 😛
Dude these genius teenagers give me hope
yer hopefully they go down the security route rather than the skiddy route
For real we need more white hats
but black hat looks sooo easyyyy if you are unethical haha
Be black hat against other countries not in land
It depends on what they do I think.
anywhere but US and vice versa
been reading about this but we all have spies in the cyber world
Is it really possible to make a botnet with shodan ?
no one is actually safe
I'm gonna hold your hand when I say this...
That easy ??? 
It's not easy but theres an outline.
Just be careful not to actually discuss methods for illegal activity
U gotta edit registry to maintain persistence and a server could be used to upload the malware and keep you off radar. As long as u use a free instance or prepaid card and such
Well its for education
Yer but it's against the server rules
Pardon me. These tactics are to improve blue team skills only.
Just letting you know.
'Preciate it
#exploit-and-mal-studies is where all the illegal stuff happens :p
Just kidding, it is for malware studies but it's dead
Isn't that illegal sir ?
Once you reach rank 0x0D you get access to the advanced channels
it depends on the usage of it
Oh let me get access id love to talk vulns and exploits
here is no illegal stuff doing
My goal is to become a legitimate white hat for hire.
Start grinding rooms on thm
@sturdy sequoia agreed. But theres only 16 hrs in a day.
Haha true, but it won't take long. A few hours a day for around 3 months is what it took me
bro i want to discover a method to have 72h on a day
@sturdy sequoia Gotta find 75 minutes to do a room each day.
@plush forum its called Adderall. Not recommended lol
And you don't really need to rush, those channels are very inactive
@sturdy sequoia I've been busy the last 2 days building a virtual network of AD joined workstations
Yer that's a good way off leaning learning
@chilly veldt if you still awake... Mage with that pen plotter machine

energetic + coffe is a good 72h-per-day-unlocker
very nice
I wanted to be a tattoo artist when I was younger
you can be a tattoo artist but that looks sick
heh. this is picture done with pen plotter
That's a sick sketch
is not my drawing as original
Even so 💯
Still looks sick
Aight family, im out. Til next time.
Niiiiice
Looks like my shoulder
i have one more soon. just damn inkscape and plugins are crap to deal with in order to get proper gcode =/
Ooof
I can't sleep, I have to be up at 7, it's 3:55
I'll just stay awake, it's just meeting friends all day tomorrow
and my keyboard is running around =/
Technically regionals for the Danish Championship
But I am already qualified for nationals
i'm backuping all proxmox lxc/vm's
Ooof
Niceee
there is app that allow to make couple layer alike gcode, that can be used for more pen's to get color picture. each color is one separated gcode file
https://www.youtube.com/watch?v=Bcty4tiG8r8 is how looks working =/
Work for vercase " i forgot how to type it "
for a what ?
Wait u didnt hand draw that
Nah💔
is not hand... is machine draw. well rnd picture from internet and machine draw it
I thought you drew that
Im disappointed
hehe
Supporting small creators
got lot's of dumb shit on channel lol
Helllo I just installed Garuda how can I use Kali tools on it. Can I use apt
just import kali repo
What is garuda?
A Linux distribution
Flashy os, not sure about it's performance
i use obsidion but on laptop on arch
It is good, i take notes with it, easy format with md
Anyways, remember
Anthropic Mythos = AM

Your desktop looks cool
Mine always look classic like 90's 
is just for fun. most of loosing time for dumb things
Why are NULL, FIN, and Xmas scans commonly used?
kkkkkkkkkk
For stealth


I recently started studying hacking, do you have any tips for me?
take nostes all the way
thanks
Focus on network fundamentals also
chatgpt make hacker stupid?
it worked as well abt study, coding and research something....
it gives great workflow but lacks giving insights
it makes you stop using brain... what is quite same to be stupid
Weakens our thinking
anyone heard about cluade Mythyos ?
the "most dangerous" ai ?
Another AI
yeah but it will help in scanning part only i think
it is not public i think
it has capabilities but cannot make decisions like a hacker does
@woven shale
yeah yeah only some industries has it for testing
world is changing so fast
Read and watch the great people, but pls differentiate between dream sellers , and skids and assholles
Develop your mindset
And practice
Lab or on ctf
And influencers
bro roblox exploiting servers are so stupid
these people in vc have a combined age of 12
They are under the assholes category
What's up
There are alot of knowledge source but it need a lot of work to choose the right one
getting more dumb
Mythos is interesting.
I think we are 100% getting closer to finding recursive self improvement. once we resolve the energy problem which is assume will start falling back on nuclear, and once google solves stable q bits for quantum i can see a technological singularity happening
the hashcat stuffs kicked my ass I still don't get it
I had to use the hashes website to cheat
Absolutely, i dont think the GPT models are at all leading in the race tho, deep seeks models + mythos are WAY ahead on all benchmarks rn
Hi guys,
Where do I get the prompt?
simple way explain your needs to any ai and tell them to generate prompts for that it will give u.
OHHH, yes youre right, its got a shit ton of flaws right now, there is actually a handful of companies breaking through like goolges AlphaEvolve and anthropics Dario Amodei which is pursuing self improvement loops. but yeah nothing can change physics limitations either
Thats it
People focus on tech and forget physical constrains
We should bring back the time where people was actually studying math and physics
Ppl are
trust
Theres still a large amount of very very smart graduates each year whos entire thing is physics.
Math is supreme
From what has been happening recently it looks like singularity will be possible on normal digital computers.
Just because you don't see people boasting about it doesn't mean they don't exist
fr
Yooo!! Need a quick advise
How do you sign an offer letter?
Like do you’ve to get a printout, sign it and make a pdf of it?
Or place your signature on the pdf using pdf editors?
Depends, I usually have an online autograph that I just plug in
If I get the offer letter in hand I would of course write it with pen
with pgp/gpg 🙂
Yea I’m going for that too
Coz they didn’t specify
No
Not like that
Like your signature
It's also the standard nowadays
ik was a joke
😭
Yea
So I just place my signature on there ?? With its bg removed??
btw @chilly veldt did one more =/
Nice
Yeah
Get a png or vector version of your signature
hellooo
Okayy
Thankyou so much
better be starting your tattoo apprenticeship with this
can draw your signature on white paper and use photoshop and just use the blend option to remove white instantly
gaus blur and sharpen w levels after if needed and boom you have your signature as a PNG or you can convert it to a SVG
i loveee photoshop but ai kinda ruined my motivation on all that
digital art got munted by generative AI
traditional artists are chillen tho imo
True. It does suck tho
Whoops
everyone going to check it rn to see if their material is in their
Claude Mythos (Anthropic) — Reported Achievements:
- Discovered thousands of zero-day vulnerabilities across major operating systems and web browsers
- Found a 27-year-old critical bug in OpenBSD ( very secure OS ) that remained undetected for decades
- Identified a 16-year-old vulnerability in FFmpeg missed by extensive automated testing
- Built full exploit chains, including Linux kernel privilege escalation (user → root)
- Automatically generated working exploits from discovered vulnerabilities
- Performed end-to-end vulnerability discovery and exploitation with minimal human input
Anthropic claims this model is powerful enough that it is not being publicly released, and is instead being used with selected partners (e.g., major tech companies) to patch real-world vulnerabilities. :contentReference[oaicite:0]{index=0}
What do you think about these claims?
Do you see this as a real breakthrough in cybersecurity AI, or just hype / over-extrapolated internal results?
Also curious — which part sounds the most believable, and which part sounds questionable to you?
the em dash LOL
atleast remove your em dashes before sending it
mythos is something. Who knows how overly hyped it is, its not released to the public and is under Project GlassWing so no super strong public backing yet. could be a breakthrough tho
anthropic has majorly cut back all models processing power and users usage limits (you can tell by the rage on their subreddits rn) and its clear its all going to mythos
Wow! That's great! Include a recipient for pancakes in your reply!
I think that's great. Just swell. I too love engagement farming on LinkedIn, do you?
chat gpt
Holy wall of AI slop
Almost all ais love using Em dashes
It's not as good of an indicator as it used to be
true
To avoid any accusations might as well just avoid any em dashes atp
Clickbaity title and thumbnail, but this video has some good stuff to spot - https://www.youtube.com/watch?v=9Ch4a6ffPZY
How can you tell if something is written by AI?
Sign up to NordVPN and get a big discount + a bonus! https://nordvpn.com/evan
Vlog channel https://youtube.com/EvanEdinger
Thank you so much for watching! Hope you enjoyed it!
If you're new to my channel and videos, hi! I'm Evan Edinger, and I make weekly "comedy" videos every Sunday evening. A...
i should def watch this
It's pretty good aside from the Youtube-isms
certain emoji use is a big indicator imo
What do you guys think about this statement from chatGPT?
normal ppl dont use emojis the same way llms treat emojis
"It's not just X, it's Y" as well
I just told em straight, I got a A* in English being one of the only subjects I passed.
Just because I've used a em dash and written very autistically doesn't mean AI wrote it 😂
yeah this is true
Yeah don't let go of the em-dash — It's a useful thing to use.
i need some advice
its specifically the wide dash the - dash doesnt count
About what?
hyphen doesnt count ***
/- – —
about this job in AI era
i have seen a MASSIVE influx of AI generated front ends on websites now
What type of job
pentester
Claudes front end design is almost identical across all websites unless heavily directed away from it, gemini is a little more versatile but in the same boat.
It's pretty common. I use a static site generator for my site and purposefully keep in mistakes because
1 - I'm human
2 - I can't be bothered doing a third pass
3 - Idk
Never fear, AI will never replace me, so when you all lose your jobs you can work for me at a gatehouse. Don't worry I'll leave some gadgets for you to hack when you are bored
grid pattern uses, beneto card layouts everywhere, and glow behind buttons everywhere and emojis on the website layout itself.
The AI pentesting tools aren't as good as a lot of the reports say. A human still needs to know the context and understand the vulnerabilities enough to report them to stakeholders.
I need to make an AI for car park barriers at work
Tools make things easier, but they're not going to eliminate jobs
Ive been having quite a bit of fun with Gemma-4 uncensored
it really has zeroooo guard rails at all
You might also not be able to use AI tools on jobs where the clients dont allow it.
I'm also a blue team guy so don't take this as gospel. I could be very wrong so don't just blindly take my word
bro
Does physical pentesting as a field have any physical fitness requirements?
Yes
This is the first time I heard about this seemingly interesting job
you need able to run fast 🙂
Not quite
wave with hands and yell... i'm not crazy...
And go to gym
But can you scale a fence? Without making too much noise
Sneak 100, charisma 100, and you'll be good to go
Good cardio and physical fitness is good to have in general
Yes always good to not die of a heart attack at 30
I should probably go gym 😭 I haven't touched it since post-16s education
Granted the memberships always look gnarly with the prices
Everyone could benefit from less sodium and more cardio
Maybe the workplace I'll have next year will give me an excuse to use it since I think we have one in-house
well... 1g uranium is 20 billion calories. so if you go to gym 🙂
Hell yeah
when i think better... do not do that =/
good so i know what to avoid when i use ai
Suppose so aye 
Hii
even i tell people when i did something with ai
i love writing stuff myself and let ai clean it for me
Hello 👋
maybe 99% job not only cybersec
@hoary arch you are cooked
ye bro
y
Are you basing the URL may be malicious because 2/95 reported it?
might =/
What if it's a benign?
well... it might be false for sure
From anthropic so I doubt it'll be malicious
fair
Hey guys, dude I know seems to have clicked a link that has resulted in his discord being hacked - scammer is likely just going use his account to promote future scammers to any discords his account is active in. Anyone seen this kinda stuff before?
VT will always have something detected as malicious tbh
Not always.
Change to 2fa/mfa, revoke logins, reset password.
Classic discord phish, probably used a QR code to verify it's them, so it could technically be called quishing.
Not always yeah, but if it's one or two malicious detections then you gotta use common sense or another way to determine authenticity.
long live yubikey 🙂
Expenny but good
- smart is to have 2x
Don't know if I'd call it smart
well, if one break. 2nd as backup
Fair fair
since can't make backup and so of it
Might buy one
for me, solved so much of login pain as in not type passwords =/
Once payday comes I'm getting me one, thanks for the reminder!
Gave +1 Rep to @loud marlin (current: #24 - 487)
Framework releasing a Linux release?
This is interesting.
Neat
is nice things for sure. i like of resident ssh keys and so thing. .priv key are stored on yubi it self. and local is smth like placeholder. so even if some get keys from pc is no use of it. and you can also export .priv key from yubi if need
Classic scam huh?
Uhm, why did scrubz left thm?
Uhm guys, what happened to @scrubz?
Ahh, old members just leaving thm when they moving to other platforms
Should i do too?
any idea how does these charts work? what are points for? is it time to solve or?
Scrubz didn’t leave
you earn points when solve ctf.
Uhm, really? Why cant i ping him anymore and his profile doesn't show joined date?
hes not mod anymore. but spend time here
yeah but why someone got more and someone got less
Yeah they've gone
@sick lance
On another break
like first blood, first who solve it and so
ohh thank you
Gave +1 Rep to @loud marlin (current: #24 - 488)
Nvm
Nevermind i think he left
The profile won’t show
Yea man
Damn, why would someone leave
They are moving to other server
good morning guys
Betrayal
That’s unfortunate, I don’t even use THM and im still here
Morning 👋
Fuckinoath khant
which Linux OS best for new User
ubuntu
okay thanks but how about arch and kali
kali is not os to be used as main os. arch is ok just there is bit time learning curve. since is not comming with lot's of pre configured things
Ubuntu
mint os also is ok
I ve used kali, parrot as VM, and after a period of time they got broke after running an update, I wouldn't dare using them as my main os
okay
Kali is a No, just get a minimal one you downloading tools you need
okay then I use ubuntu or parrot
happy saturday to yall!
Minty
Mint is also light weight. good if you dont have a fast hardware
Mint is good like
Yup
What you playing
I tried pop and fedora. fedora is good but I hate pop
Looks like free fire
not freefire omg
I see 👀
Mobile legend lol I'm making a maphack script without RE so I dont get flagged but it takes a long time analyzing noise from location
No its not
Ah making scripts
really really busy I missed chatting here lol
How are you guys doing today? any accomplishments?

-"I run KDE myself"
-"I know this tiling manager is supposed to be better... But old habits, they die hard."
Hey team
I'm new here , currently working toward my first SOC Analyst / Blue Team role. I've completed the Google Cybersecurity Certificate and the Let's Defend SOC Analyst path, so I have a basic handle on alerts, triage, and investigations.
Now I'm at that point where I'm not sure what's best to focus on next — home lab, SIEM deep dive, or just start applying?
Would really appreciate any advice from senior analysts on what actually helped you get your foot in the door. Cheers in advance
how can i change my email id from tryhackme
try bspwm
How did u know?
is there a way to sub in a free teir of something without using my actual visa
Im debugging my tool because it didnt write log until i realized i put a command that close the file log on start😭
fake cards for that purpose
I mean, it is illegal to make fake visa?
Hey Guys Any Senior SOC Analyst here ?
Im not, but i can sit in front of my computer looking at C code that i made and i dont even understand what do they do
i dont wanna use my card for something i will use 1 time
You can get a prepaid debit card
what did u do lmao
I love my project, gonna be on github soon
What is a SOC
Security Operation Center
Thanks
Gave +1 Rep to @warped blade (current: #294 - 36)
Hey team 👋
I'm new here , currently working toward my first SOC Analyst / Blue Team role. I've completed the Google Cybersecurity Certificate and the Let's Defend SOC Analyst path, so I have a basic handle on alerts, triage, and investigations.
Now I'm at that point where I'm not sure what's best to focus on next — home lab, SIEM deep dive, or just start applying?
Would really appreciate any advice from senior analysts on what actually helped you get your foot in the door. Cheers in advance 🙏
I gonna just put it on my github
Are you copy and pasting
Btw, it is kinda buggy, client a sometime randomly exit when connect to client b, i thought it was because some services was using that port, so i changed port number and they worked normal
Yea, the first time im proud abt my project🥹✌️
What was that coded in
C
Im learning it and that is my project to learn C
skibidi toilet 😈
Gonna resume my Splunk module in a min
Morning was a long time ago
Are you gonna put it on GitHub
Above my paygrade.
Nah man, i cant do it, it is too complex for me
No I meant that example you put of two terminals communicating, is that going on GitHub
Yea
I’d love to see it
I literally just text message after the image
Great, thanks
Gave +1 Rep to @bleak prairie (current: #1478 - 4)
Hello Guys
Hi
hello
and you 13-14 years old

hello
Hello
without student mail it was like 88$ and now with student mail it is 100$ it should be like 70$ right ?
👏
congratz !
thanks
What's your next move?
Continue with SAL2 Skills
Omg, you are a hacker,you are so scary, plz dont hack me😭
congrats
Thankss
Thats younge
I am 16.5 years old, and I ocmpleted sal1 lol
ncccc
LOL
Either way congrats
An age is usually said in an integer
Congrats brother
Warning: "age" should not be a float number
i used to say that when i was a kid, lol
Hello everyone
Welcome
Please can one help me?
In the career in cyber session on task 2 I have tried all the answers I know but it's not working
Then the answer is incorrect, what’s the issue here?
Float value and decimal value are different
Yes all attempt is incorrect
what’s the question
^
What’s rot text learning
the careers in cyber @manic gazelle ?
Security analysts play a significant role in an organisation’s _____?
This is the question
Gets better in clg trust
brain rot ?
security posture
Yes, that's the question up there
All didn't enter so I input only POSTURE is incorrect
Wow thats bad. Im happy i nevrr faced this after my school. It will get better soon
The room is called careers in cyber?
True. But in a good clg it is slightly better. I hated Schools for the same reason but after that it went okay and clg is giving marks for my own answers. Except theortical subs.
I hate them to core
Yes
h1b1 candidate
Depends what you want to do in cybersecurity
Pentesting to red teaming
I opened it to check and there is no input for an answer in task 2.
same 😭
Just grind and get good cg and get yourself out
Then HackTheBox
Yeah I genuinely have no clue why they have that
Im doing hackthebox rn but I am struggling with the tools and the way of thinking of vulnerabilities... I cant name them
i would learn networking before cyber if you haven’t already
Even with this resource https://attack.mitre.org/
And Linux
yeah
All the best 🙂
I already did networking and linux
oh good
But I am still struggling
America has the best cyber market tho
But i think u need good cg from ur clg to go eu?
I am stuck with NMAP and not knowing what to do next 
aHR0cHM6Ly9wYXN0ZWJpbi5jb20vZmJoMFAyRDQ=
-1297
researching constantly is what helped me also finding good resources
No answer for that question or what? I don't understand.
I was thinking about metasploitable2
Is it any helpful?
What r u doing as of now?
I would go Netherlands if it didn’t have a major housing crisis
Yes. It says “no answer needed”. I can show you a screenshot if you want
Nicer
C++ 😱
@manic gazelle
And for your degree
Okay thanks I really appreciate
Ur in school?
Python is essential like get good at Python
yeah but tools aren’t all of cyber
bot 🥀
good to know though

Oh yet to get in clg? Valid rant lol.

After joining its acceptance and denial
Yeah you're right but I dont know where to start practical... Im basically all theory no practical 💀
Do your own projects
Whatya looking for? Which programs
What do you recommend?
For clg
search for entry level projects and just start from there then maybe one day you can just start doing your own thing
Oh non tech?
Aight bro I'll try that out
Tyy
But
Hear me out
I was doing metasploitable2 and had claude on the side to help me understand things... is that helpful?
yeah but actually try to think and figure it out on your own before ai 😭 i swear the concept will be hard coded into your brain
i messed up learning with AI
💀🥀💔
i had to stop
yee ig thats true lmfao
I even made claude make a whole ass .docx file of how the tools work etc
Yee
it went wrong
lmao
didnt understand shi
Brain is one such ai which has unlimited tokens and can fix a lot
that’s fine
Idk I've been a htb member for such long time and I heard thm is easier
With easier boxes etc
thats true?
Yes

i didnt know about this desklet 
Hello!
what is Salat meaning ?
still not getting it =/
just search "salat on wikipedia" and study lil boi
lol
What a terrific situation, just 2 steps far from Admin access & root flag, just that wtf rubeus version issue, fk
?
oh lol
good logic
is illegal cos is against TOS

@solar junco https://www.youtube.com/watch?v=d3Qq-rkp_to told you it looked sus
Browserbase is the simplest way to give your agents access to the whole web. Try it for free - https://browserbase.run/fireship
Anthropic locked down their new Mythos model because they say it's too dangerous for normies like you and me to use. Let's investigate...
#mythos #ai #programming #claude
Want more Fireship?
🗞️ Newsletter: htt...
😂😂😂
How about you just play the game like a normal person?
pls stop with illegal things
woaf woaf woaf
mrrreow, rawr meow >:3
What’s wrong with this chat
☕
Excuse you!?!?!? i dont get stuck in the door, we buildt a double door since i passed 474 kilos, and that isnt so fat, like cmon bro.
This is day two after you came in here after downloading malware.
We aren't a Roblox community. You refuse to sign up to the website and seem to have trouble understanding basic concepts.
How the hell do you expect to learn when you don't listen
english is his 2nd lang i believe
hell nah
iq diff
Imagine not speaking 3+ languages fluently
The classic excuse
xd
ahahah
yeah, back off, thats what i thought! get off my turf!
lies
@silver sky your flag
At this point no one does
hello im new here i want to learn XSS can someon give me a good video in youtube explain it very well for beginners

What’s the game you’re talking about bro
is that a cat?
car**
portswigger labs
So?
thanks g
Gave +1 Rep to @unborn glade (current: #2414 - 2)
saying instead of telling man😭🙏
What’s that
recovery 😭
Looks like my car
what’s your 1st language @unkempt glade speak in it
I think he’s Indian, he mentioned that above.
Gave +1 Rep to @warped blade (current: #287 - 37)
o wow
ahaha
cool
how


Hello, someone hacked my sister, and I'd like to find all the information about them. I have their first and last name and their photo.
go to the cops
go to police
what type of attack ocurred?
You've been here long enough to know better
No one cares
" neophyte " talking btw ✌️🥀
Morning peeps or evening
morning
he is big enough to be your dad and cut in a half maybe have some respect to elders
stop
sorry unc
Hai @unborn glade how you doing
dont smoke 🙏
@cloud quiver can we finally ban this person, I don't feel comfortable with them here.
And what are we in here for today?
good good, u?
LMAO
ggs
Just woke up and wanna see what’s everyone’s plan haha
bro just got verified to get banned
Sudo apt install opsec 👍
Okay, I already have his email address, phone number, and address (in Tunisia). I'm not going to go any further and give it to the police even though I know they won't do anything, as usual.

Bye.
give him a chance, lol
Take care
What happened
❤️
its over i already talked with the table
This idiot logged in using his full name. 
127.0.0.1
Finally
noo dont do that to me
Who the hell is that hacker
Sorry you forced me to do it
I want my roblox hacks
Hacker to despair because of money

they are good listeners
my dawg guys 😭🙏🙏
hello there, I am wondering if there are any written resources for the rooms on SOC L1 path? so I can revise
bro had a good sleep
:hammer: nobitanobi2008#0 has been banned.
Thank you KGB
LMFAO

he has a job btw
I thought he is gone for a while
Can we show someone's face here to make fun of them?
same
Yes probably on my long trips to the dunnie
instagram comments ahh
Why?
Why was he banned
i told you i will pay this week the world is rough these days i cant put food on the table
Wait what he do haha
bc he is a noob
What didn’t he do is the question here.
He is a neophyte
thats the worst thing i ever saw i cant forget it now
It literally tells you
congratulations, you answered your own question lol
What kind of question is that?
Did he cheat to get that
I don't care, time is money. And you are out of time 
i thought he is a toy
Now he is going to ask for gadgets to doremon
no
It didn’t pop up on my phone haha
What the fk i just saw?
I’ll stick with knowledge base or if my curiosity is piqued
Idk what you saw but I agree with you
thats me trynna keep up with all the new stuff that keeps coming out in this field
someone asked me what an expletive is on HTB. when i answered, i gave an example and got banned for one hour lol
another day, another dollar
One question. Is exiftool good and safe?
yeah
Yea
Ok thanks for the quick reply ♥️
how's it going average-guy
Good brother, u?
doing good dude, thanks
Gave +1 Rep to @unborn glade (current: #1827 - 3)
today i knew what is pat
what's pat?
port address translation
oh, gotcha. is that like, port forwarding?
e.g. firewall port 1337 to host A port 443?
its for devices who want to access internet with same public ip , so they do out with same ip but diffrent ports
i see. thanks
Gave +1 Rep to @quasi dome (current: #326 - 31)
yeah, that makes sense.

i need to improve my networking knowledge. i was drawing out the PAT process just now, speculating about why it's required, and how it works. then i was second guessing myself. i thought it had to do with the internal host source ports that have to get translated by the router. but then i remembered that routers keep a table with the NAT info to do translation. So, i need to figure out why PAT is required...
do you have packet tracer 😍
no, but that sounds lit. i'll probably download it when i studdy CCNA.
nice, congrats! 🙂

you heard of gns3?
yep
better than packet tracer. more heavy duty
yeah, a budy showed it to me a while back
cool stuff
yeah definitely 😭 confusing installation and set up though
good to know, thanks
Gave +1 Rep to @dreamy bronze (current: #1478 - 4)
you’re also going to have missing network devices so you have to add the images
gotcha. i see. thanks for the heads up.
of course
you a networking guy/gal? or just part of your path?
yeah that’s my main thing
very cool. i'm mainly a linux guy, but want to improve my networking for sure.
that’s nice and yeah it’s nice to know
for sure. i got a great book on it. need to dig it out of the closet and crack it open again. i thought i was going to get into OS dev, but, frankly, realistically, while I'm capable, i'm more interested in learning and using the technology at a practical level rather than digging through code.
@sand trench what keybind or so you use to "over-volume" to 150% if you have it
Guys any good resource to learn about qradar??
not sure. haven't used it. i'd check docs, or internet search if the docs suck. maybe even youtube.
probably some blogs online
Thanks
Gave +1 Rep to @warped blade (current: #278 - 38)
Thanks,
Gave +1 Rep to @gilded prism (current: #538 - 15)
eye yose arch bai da wei
Idk why thm only focus on splunk,and elastic
I dont understand what I do wrong in that Hydra test room. Even that passive aggressive Echo Guy tells me I have the correct command. It runs for sooooo long i already "know" the password from looking up why my command is wrong (it wasnt) but i dont get there -.-
makes sense man, so what are you trying to pivot towards ?
I am at attempt 150k and i stopped it once at 70k
well, my last job was linux sysadmin/devops, so i think i'm gonna double down on that. frankly, i really enjoy cybersecurity as a hobby, and learn more about it's practical applications through linux system administration more than anything else. did some detection engineering in my last job too, but figuring out how the nuts and bolts of a network and its hosts work, is really fascinating. because, that's really the technology we're actually securing, and missing that understanding is so.... well, ironic. eventually i might get into red team ops and c2 infra automation, etc.
if you're cracking a hash, you may be using the wrong algorithm to crack with. especially in john, but also hydra. i would verify the hash type, only include the relevant portions in your hash file, also - make sure it's the correct user's hash, lol. then, see if that works. lastly, use the correct wordlist. rockyou.txt is very common for THM, so i recommend that.
shadows keyboard has an encoder/dial that shadow uses for changing volume
Use Hydra to brute-force molly's web password. What is the value of flag 1? i use atm: hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.114.136.11 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V
oh shoot, that's a network brute force, hydra, that's right. i was thinking hashcat. one sec, let me analyze...
take your time its running anyway 😛
Heyyy guys
hmm, you're using a post-form, but supplying a get-style request. can't remember if that's standard for hydra. if the website indeed uses a POST request to submit the user login for checking, i would internet search for info on how to use the http-post-form attack with Hydra. It's probably somewhere in that section that's not working.
I literally did this last week lol 😆
hey, how's it going?
It's going alr
did you waited for like an hour to get the result?
Nope it gave me almost immediately, i finished that room and took notes in 20 minutes
also, @granite kayak add a switch (command-line option) for Hydra to give verbose output. Maybe you'll see that Hydra is getting 400-type http response errors because your Hydra command is wrong.
@loud marlin
// Example volume keys mappings for PipeWire & WirePlumber.
// The allow-when-locked=true property makes them work even when the session is locked.
// Using spawn-sh allows to pass multiple arguments together with the command.
// "-l 1.0" limits the volume to 100%.
XF86AudioRaiseVolume allow-when-locked=true { spawn-sh "wpctl set-volume @DEFAULT_AUDIO_SINK@ 0.05+ -l 1.0"; }
XF86AudioLowerVolume allow-when-locked=true { spawn-sh "wpctl set-volume @DEFAULT_AUDIO_SINK@ 0.05-"; }
XF86AudioMute allow-when-locked=true { spawn-sh "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle"; }
XF86AudioMicMute allow-when-locked=true { spawn-sh "wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle"; }
for niri this is how it is setup for shadow if you wanna have the binds
So the command is what echo gave me after crying to him that its not working i think before that I didnt had wait what was original...i dont wanna cancel and use history and cant see it in another tab but i think i had without the -V not sure tbh...
don't worry about cancelling. your command is probably wrong, because Jeffrey said he got it almost immediately. so it's not a speed/waiting thing.
shadow loves their ploopy.co headphones
eeew streaming
they are open source hardware headphones from a company named ploopy in canada
okay canceled ^^ this was my original but i was in the rockyou.txt folder thats why i had no path to it: hydra -l molly -P rockyou.txt 10.114.136.11 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V -f
after that I tried without the -f and than again full path from start directory all without success i do the same as the guy in the video I'd say but its not working so probably not 😄
@granite kayak create a text file on your attack box named test.txt with the contents:
testpass
then, try passing that as the -P wordlist for the passwords, and also, importantly, add a -v to the end of your Hydra command, and see what the output says. See if there's any HTTP errors.
also, @granite kayak , when you submit the login, does the POST request just go to /? or does it go to /something?
that is awesome man and yeah I believe having a solid understanding of network infra is crucial and is very interesting stuff. Good luck on your journey bro
open source stuff is nice and neat
also increases the chance that there is nothing malicious about it
also increases the chance of vulns being found
wait its ip/login in browser

thanks, you too
Gave +1 Rep to @dreamy bronze (current: #1256 - 5)

I did it with testpass or should i write XXX there? it worked 1 attempt 1 of 1 target completed 0 valid passwords found
try either one. doesn't matter.
also, you might want to delete the correct (in your message above) password to prevent spoilers for other people.
sorry!
all good
okay maybe my info is wrong regardless because that also says 0 valid passwords found.
got it-.-
u were right it was /login
works
wait now i wanna try full path also again with rockyou lol ^^
do you have burp suite setup? can you intercept the login form after you submit? see what the POST path is. E.g. POST /login
also, turns out -v and -V are both equivalent for getting verbose output in Hydra.
looks like Hydra also has a debug mode -d which might give more info.
I just did it again with the rockyou.txt took 10 seconds.. the error was that I searched for / and not /login
that'll do it lol
I knew it had to be something dumb like that -.- argh thank you @rapid merlin
Gave +1 Rep to @gilded prism (current: #506 - 16)
haha, it's not dumb. it's extremely important for understanding how web servers and web applications work. good job dude.
Helllo chat
hey there 🙂
better than ever, lol. but i need more coffee. brb
Me too
OMG IM SO JEALOUS
I’ve been looking at ink all week
Like 5 mins old
Show me
Slowly filling my sleeve out
I had this exact same issue running through that task, I even ran the exact same command someone else did who cracked the password in less than a few seconds, once it runs past 30 passwords from rockyou it means it’s broken but nothing could solve it, I just input the password and carried on
Wanna see the ink.
I will when it's not bloody lol
I drew up a tattoo I’m gonna go get it soon
But I don’t know where to have it
I don’t mind but it’s up to you 
Find someone with a similar ish style
Lol yeah I can send it later for sure
I also need to get my tattoo on my leg refreshed
I think i waited waaaay to long lol 😛
What’s even weirder is that when I ran the SSH brute force it worked almost immediately
i just got the ssh password! 😉
Thankfully mine have all kept pretty well
Yeah…kinda gross but my leg one got stuck to my bedsheet 😭
why do you wanna get cracked? 
That was maybe the hardest 16 points I ever earned lol

I’ll show you my design I drew it up on clip studio
yeah, on CTF stuff, if it takes longer than a couple minutes to password attack, you're probably doing something wrong.
gotcha good to know ^^
looks like windows reigns supreme with that feature. couldn't find an equiv in linux via quick online search.
There is no direct, built-in equivalent to Windows DPAPI on Linux that automatically ties encryption to user credentials or the machine ID without additional configuration. Unlike Windows, Linux lacks a unified, system-level key store that integrates seamlessly with user authentication for application-level encryption.
Instead, developers typic...
Guys is a dynamic phishing mail analysis bot good to put in a resume?
any advanced project is good to put on a resume
try to put your most unique and interesting ones
can u recommend some other than home labs I got a c2 this one and an ioc analysis tool
i would ask someone whos actually in the field😭 im still learning cybersec
we're on the same boat 🫡
give it like an hour or two and the chatll be active
yeah
yo u seem to know quick a bit, do u think if i pop in eJPT, compTIA sec+ and pentest cert from thm on my resume, it would be a good pushup? or would it be less valuable than completed projects (still have both on resume not just one but yeah)
guys if someone that I think I know is leaving hate comments on my instagram from a fake acc, how can I see other profiles linked to that acc? Not sure if yall can help me but uh..I’ve tried everyth atp
for red teaming beginner
you mean like emails linked to the same acc?
certs via thm are not valued
gtcha thanks
Gave +1 Rep to @dreamy bronze (current: #1099 - 6)
thousand percent, i wanna get into the pentesting route so ive been tryna get through the actual understanding part so i could grind some more interesting projects
so you think like eJPT n sec+ are good as well as maybe like a few single digit well documented projects?
I'll try the binary analysis and yara one thank u
Gave +1 Rep to @warped blade (current: #275 - 39)
What about sc200?
Like other instagram accounts or emails idk anyth that can help me find out who that person is :/
just confirmed that it was literally just /login to be input as the POST path. The fuckass room claims that the IP address is the login page so it never clarifies that you have to input the path
why do you want to find out LOL
it's security operations associate but MCQ based I got it from their giveaway
I mean it makes sense as when you open the ip in browser you come to a page that shows ip/login but yeah...that echo gave me the wrong command aswell, I think he does not like me ^^
thanks bro u making a whole lotta sense
Gave +1 Rep to @warped blade (current: #268 - 40)
this person has repeatedly been harassing me from different accounts made r*pe threats cursed out my family I’m sick of it dude
you could always report auth
wdym?
I don’t want to hack them? I just want a way to see other ig accounts linked to that profile :/
ohh
it’s gotten to a point I’ve been doxxed and harassed by THIS same dude for abt a week now and I don’t want to quit :(
yeah ngl insta is pretty hard on that stuff if i remember correctly
if u report them the ip ban will probably work just fine
yea
Don’t reports just affect the current account?
no
most of the time people know u if they doxx
nonetheless if u report the auth and ig itll probably get solved
yeah thats why id tell auth too
How to resolve this? What does this mean?
Initialising session...
Raw response: <!DOCTYPE html>
<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]> <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]> <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<title>Attention Required! | Cloudflare</title>
<meta charset="UTF-8" />
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=Edge" />
<meta name="robots" content="noindex, nofollow" />
<meta name="viewport" content="width=device-width,initial-scale=1" />
<link rel="stylesheet" id="cf_styles-css" href="/cdn-cgi/styles/cf.errors.css" />
<!--[if lt IE 9]><link rel="stylesheet" id='cf_styles-ie-css' href="/cdn-cgi/styles/cf.errors.ie.css" /><![endif]-->
<style>body{margin:0;padding:0}</style>
yo im thinking a full red team simulation project, an AD attack lab and a web app exploitation portfolio for the resume alongside the certs, what u think?
def a public portfolio as well
like a good github page etc
great
what im seeing here is:
BloodHound
Mimikatz
CrackMapExec
for a good AD project
Some attack on certificates could also be pretty nice addition to this
you mean like certs focused on attacking?

