#quiet-conversation

1 messages · Page 1 of 1 (latest)

dark panther
#

Can't really motivate myself to keep doing THM lately

#

I'd love to keep learning new stuff but when I try lately, It's just so not fun cri

spark sun
#

It's burnout. Take a break, go do something completely different and don't be afraid to just spend some time thinking about it

frail rapids
#

Yep

#

I've had it quite a lot on thm so I can kind of feel one coming so that I can dodge it just in time

sacred kite
#

Hello hello

dark panther
#

Well, guess I'll go play Factorio again

mortal venture
#

not sure if this question is appropriate here but my default shell was zsh, changed it to bash and now my text are no longer colored, anyone know how to fix this off the top of their head? like where when you type in a program thats not installed the text is red and when it is installed its green, and if the file exist the text is bold and its not bold if the file doesnt exst, etc etc. google keeps showing me how to change the terminal background or the bash prompt and not the actual text output, aggravating as i feel like im not looking for the right thing

candid tartan
#

there is .zshrc for zsh and .bashrc for bash

#

zsh read .zshrc bash .bashrc

#

as config

#

zsh is default in kali since is kinda better

mortal venture
#

is it?

candid tartan
#

you can say so yes

mortal venture
#

this is what i was referring to, like how the text is colored

burnt night
#

How did you change it?

#

Using Kali tweaks?

mortal venture
#

no, with chsh like in the screenshot^^

burnt night
#

Try it again using kali tweaks

mortal venture
#

ah okay i forgot those existed thanks. coming back in after like a 7 month break so thanks

burnt night
#

It's somewhat new

white patrol
#

Hi

radiant jacinth
#

hi someone

quartz ibex
#

hi

magic niche
azure crystal
#

guys why can't i upload any image here?

narrow trout
deft fossilBOT
narrow trout
#

follow the above instructions to verify with the discord bot, afterwards you can post pictures

azure crystal
south inlet
rustic karma
#

oh @weak dove , this used to be my username before

#

where did you get it from? movie?

weak dove
rustic karma
north void
burnt night
odd acorn
#

Love WarGames

pliant pewter
#

If you want to go old school Hackers and The Net are super corny, but also super fun

#

War Games is another for sure

light ferry
#

Are there any hacker movies that really teach the technical nitty gritty ?

#

I'm sure there's a way 🤷‍♀️

spark sun
light ferry
#

😝

pliant pewter
#

That's why there's a million actual hacking vs movie hacking memes lol

finite shuttle
#

Hi All

#

I'm having issue connecting to ovpn

#

error : Exiting due to fatal error

#

can anyone please help me

gray jetty
finite shuttle
#

yeah tried that, after doing that I'm able to connect to vpn, but not able to connect to ssh

#

it says either connection refused or connection closed

#

can anyone help me resolve this ssh issue, all tried everything on the net but no luck

peak mortar
#

but excellent movie

finite shuttle
#

simple ctf

#

it required to login to ssh, so when I try to do I'm receiving an error

#

22

#

not getting you

finite shuttle
#

nmap 10.10.198.227
Starting Nmap 7.92 ( https://nmap.org ) at 2022-07-25 10:54 EDT
Nmap scan report for 10.10.198.227
Host is up (0.24s latency).
Not shown: 997 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
139/tcp open netbios-ssn
445/tcp open microsoft-ds

finite shuttle
#

i just took example of basic pentesting

#

just to show you

finite shuttle
#

python cms.py
Traceback (most recent call last):
File "cms.py", line 11, in <module>
import requests
ImportError: No module named requests

#

error while trying to execute cms sqli

#

when tried to install module requests i receive broken threads error

#

sudo apt-get install python-requests
[sudo] password for soni:
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
python-requests : Depends: python-certifi but it is not installable
Depends: python-chardet (>= 3.0.2) but it is not going to be installed
Depends: python-urllib3 (>= 1.21.1) but it is not going to be installed
Depends: python-chardet (< 3.1.0) but it is not going to be installed
Depends: python-urllib3 (< 1.25) but it is not going to be installed
E: Unable to correct problems, you have held broken packages.

spark sun
finite shuttle
#

Sorry, but I don't see any option to upload the txt doc

burnt night
#

!docs verify

deft fossilBOT
burnt night
#

Follow those steps and you will. Otherwise you can use code blocks.

calm warren
#

i was hoping someone would give me a nudge in the right direction on how to change the style of this, mainly getting rid of the fact its on the line below, and not inline, if that makes any sense 😆

dark panther
dark panther
#

Then you can edit your ~/.bashrc

#

Does a OSH_THEME variable exist?

calm warren
dark panther
#

~/.bashrc, there's dot at the file name start

calm warren
dark panther
#

Well, that's weird

calm warren
#

i'll have a google around, least i know which file it is now

dark panther
#

Does /etc/skel/.bashrc exist? It should be a backup of .bashrc

calm warren
#

doesnt look like it

dark panther
#

Not really sure where the bash config is stored then.

calm warren
#

i'll have a look around, thanks for your help

serene trench
dark panther
serene trench
#

the one you want is most likely in your home directory

#

oh

#

lol

#

mb

#

I should scroll up KEKW

dark panther
#

I use https://ohmybash.nntoan.com/ on my work machines, I'd guess that Parrot uses it too, I'm just not sure where the config is stored tho.
Someone here probably knows more tho :)

#

bash Didn't know that

signal hull
#

I know that on Kali, the default bashrc and zshrc files both have similar two-line appearances, so I would just pick the shell you like best and then customize the relevant rc file accordingly

dark panther
#

Time to try Parrot :)

calm warren
dark panther
#

Does it work?

calm warren
#

it does indeed work

dark panther
spark sun
#

Your first message is self promotion? That's not what this community is for.

peak mortar
light ferry
peak mortar
#

"cold war movies"

rustic karma
gleaming trail
#

Who am I is the best hacker movie imo

short elk
#

i am the best hacker

grim sluice
burnt night
#

Hush you.

left fulcrum
burnt night
#

Doesn't fit the brief

neon roost
finite shuttle
#

!docs verify

deft fossilBOT
idle venture
#

@serene trench when we have next server party? friday maybe lightsaberpepe

radiant jacinth
#

Shh it’s quiet do not let Mother Junn hear us 🤫🤐

radiant jacinth
# calm warren doesnt look like it

yo harry how do you save your parrot os state cause when I make a folder for example and power off my vm then power it back on it deletes everything for some reason

calm warren
burnt night
radiant jacinth
serene trench
coral crypt
#

hey bros, im using ngrok right now to ssh into my home pc from afar

#

is there a better alternative?

#

share your experience/ what do y'all use for the same usecase

burnt night
#

A real VPN

spark sun
#

ngrok isn't open source right? I wouldn't a cloud service like that to not misuse my data

coral crypt
#

is discord open source though

burnt night
coral crypt
#

yeah, i'd love if i can ssh directly on discord

spark sun
#

It's a question of access. Discord probably is selling or monetizing my usage data, someway. That's not the same thing as using discord as the means of accessing my controlled environments and systems.

burnt night
coral crypt
#

i put my sensitive stuffs on an airgapped libreboot laptop though

grand drift
#

How to get a girlfriend

burnt night
#

Learn how to cook. It's a very attractive skill.

#

Learn how to love yourself too. You're not ready to love someone else until you're ready to love yourself.

grand drift
#

Actually big brain, if i cant get gf, i cook myself

#

Thug life

burnt night
grand drift
#

You have a gf yourself?

burnt night
#

Long term.

#

-ban @grand drift Sexism and madly nsfw messages.

hoary nymphBOT
#

🔨 Banned kozzek#3575 indefinitely

dark panther
#

damn people can suck bash

burnt night
#

Never sad to see sexists get the boot.

dark panther
#

I'm 50/50 on it

south inlet
#

Discord bans don't always transfer to the site.

south inlet
dark panther
#

I'm always super hyped for dinner, it's a lot of fun when you cook stuff yourself. I always look forward to it

serene trench
burnt night
#

Similar things, but enough variety to stay interesting

radiant jacinth
#

Omg it’s Cmnatic Omg 🥹

opaque cloud
serene trench
woeful roost
#

can anyone help me ....not able to open virtual box its showing failed to acquire vb com

#

tried hard but unable

humble topaz
#

maybe its the version you got , try to get another one and re-run the set ups , when VM refuses to do what I want I just reinstall

velvet marsh
#

this video is so funny

mortal venture
#

Whoever made the zeek room thank you so much. I haven’t done it yet but I imagine it’s great. I spent months trying to learn how to install, configure it, and set it up along side arkime and suricata. I gave up after a long while.

autumn trout
#

Does anyone here use AstroNvim and understand its Lua config? I am trying to set the default header when you open it to this:

  -- Set dashboard header
  header = {                                                                                          
    "████████ ██████   █████  ███    ██ ███████     ██████  ██  ██████  ██   ██ ████████ ███████", 
    "   ██    ██   ██ ██   ██ ████   ██ ██          ██   ██ ██ ██       ██   ██    ██    ██     ", 
    "   ██    ██████  ███████ ██ ██  ██ ███████     ██████  ██ ██   ███ ███████    ██    ███████", 
    "   ██    ██   ██ ██   ██ ██  ██ ██      ██     ██   ██ ██ ██    ██ ██   ██    ██         ██", 
    "   ██    ██   ██ ██   ██ ██   ████ ███████     ██   ██ ██  ██████  ██   ██    ██    ███████",                                                                                                                                                              
  },

but Lua isn't reporting any errors and I can't work out why it isn't loading ASthink No GitHub issues on it so wondering if the header part is broken or if it's just me fewwis

umbral stag
autumn trout
#

i can send you my full config? the header is longer but i cut out some parts to send it in discord

umbral stag
autumn trout
#

not even just the trans part works D:

#

I presume this is the header too? 🙂 Doesnt work D:

#

ah wait omg

#
➜  Ares git:(Bee-config) ✗ /home/bee/.config/nvim/lua/user
➜  user git:(main) ✗ ls
user_example
``` whaqts urs called?
umbral stag
autumn trout
#

ahh. it worked! it waw 1 folder too high 😄

frail rapids
#

Scale 1-10 how true is it that you should know the internals of your tools?

#

Was talking to a professional in the past week who says that its very important as tools like reconng are loud asf even though they're included in OSCP

short elk
#

or in a pentest

spark sun
#

Loudness can be a value-add in a pentest

#

It's not an uncommon thing for a bonus if the pentest team isn't detected

#

IMO, the more the pentester knows about the tools they are using, the more potential value the test can have. Knowing the limitations of what a tool does allows for a better test

#

Even if it's not red teaming, there's value in being quiet. If a pentest can do the test without detection, it has a value-add of helping the blue team to refine logging and detection rulesets

#

Usually it's written as part of the scope in the SOW

#

And it doesn't mean a test is over if the tester is detected

frail rapids
short elk
#

they'll let it go

frail rapids
#

Ohhhh okay...

short elk
#

usually the company will tell their soc to "ignore any traffic from X for this week as there's a pentest"

frail rapids
#

Alright. I thought that blue teamers would actively defend in case of a pentest

short elk
#

well i mean every company is different and might sell a pentest as something different but that's the norm

#

i haven't done a proper red team assessment, but i've been in the soc during one and we treated it like an actual breach - as we didn't know it was a redteam

spark sun
#

It 100% depends on the org and what their goals are

#

If it's actual red teaming, it gets treated as any other breach. If it's not adversarial simulation, it's a collaborative learning experience in the debriefing to help the SOC refine their detection so that they can catch it in the re-test

frail rapids
#

Ah

frail rapids
#

are there tools for SSTI payload generating?

#

e.g. going from self.xyz to self.xyz.__xyzclass__.__evenmore__.__dundermethods.os.system()

short elk
#

there's tplmap? not sure if that's what you want though

soft pier
#

sad news is tplmap is not yet updated to python3

spark sun
#

tplmap hasn't been updated for a few years, IIRC

soft pier
#

4 years since last update to the python file

vocal ridge
#

if you pop open Wireshark while running nikto or any other tool, you'll see what they mean by "loud"

mortal venture
#

Hey I’m looking to set up my laptop and desktop to use the same file system if that makes sense. Was wondering if I should use ssh or something different? It’s a VBox VM so if there’s some hidden feature I don’t know where I can use the vm on two computers that would be cool too. If anyone can help

vocal ridge
#

i believe you can mount your host fs to the vm with Vbox

spark sun
#

I would advise against mounting the hosts root as a share in the vm. Better of using the vm software to make a shared folder that is mountable in the guest.

vocal ridge
#

yeah, mounting root or other critical folders is always a bad idea

mortal venture
#

Hmmm thanks I’ll look into that

frail rapids
#

Why is that http[://]1.1.1[.]1 syntax used in threat intel context?

frail rapids
#

Yeah

frail rapids
#

Ahh okay

odd carbon
dark panther
#

Finally went fly my drone after so many rainy days. Just says RUNAWAY and shuts down, debugging time :(

mortal venture
#

Is it called that because like you’re “defanging a dog” so it’s harmless??

blazing oar
mortal venture
#

Also looking it up, that syntax he provided still makes no sense haha

#

Nvm I found a fancy ibm article that explains exactly what I just asked. Thanks for the new info guys

ripe haven
ripe haven
#

Well actually, It's python3 compatible

soft pier
ripe haven
soft pier
#

Oh um... That is probably only for the burp suite module

ripe haven
#

Nope, everything

soft pier
#

even the tplmap.py because that is the only file in the repo that is used for the python script...

ripe haven
fresh timber
#

im new to coding whats the basics

#

plz anyone guide mehappyPanda

twilit loom
#

Use code academy and other free sources.

#

And just make stuff on your own within a scope of difficulty.

odd acorn
#

If someone changes your nickname, please do not remove it @twilit loom

odd acorn
# twilit loom Oh. How come?

It was changed for a reason, read what it was changed to. Your name is not pingable as it contains non-Latin ascii

gusty cypress
#

Where does OSI model exist?

tawdry dove
tawdry dove
#

So what did you find?

gusty cypress
#

It doesn't exist ok but what about TCP/IP

#

Where does TCP/IP exist

#

I can’t imagine how does it work even though I watched some videos

#

Buy I didn’t get the idea correctly

tawdry dove
#

I'm going to recommend that you do some more research.

gusty cypress
tawdry dove
#

To guide, not to just give answers

gusty cypress
#

I did research I told you I didn’t get the idea still I have some gaps

gusty cypress
spark sun
#

Then do more reading

gusty cypress
#

hhhhhh

tawdry dove
#

There is plenty of material regarding how TCP/IP interacts/relates with the OSI model

spark sun
#

It sounds like you just looked at a couple of pictures and decided you didn't understand; you actually have to read about why each is useful.

gusty cypress
#

Ok

#

You didn’t understand me

gusty cypress
#

That’s the fact bro

tawdry dove
#

Not your bro

gusty cypress
tawdry dove
#

Was just going to ask for you juun

spark sun
#

-mute 749893922050015272 10m Very rude when given reasonable responses to things that are very easy to look up.

hoary nymphBOT
#

🔇 Muted Abdulelah#8740 for 10 minutes

hot shore
#

@gusty cypress part of the learning is researching by yourself

fresh timber
hoary nymphBOT
#

Gave +1 Rep to @twilit loom

fervent glade
#

@Abdulelah you ain't going far with that attitude..

rose axle
#

Oh no what happened

#

Adding mocha to oat milk is ok…

dark panther
#

Trying to compile GRUB from source, can't manage to get Debian to use it dumpsterfire

frail rapids
#

What are good resources to learn about nation states?

vivid flower
twin ridge
dark panther
#

But this really is just a "Break your bootloader" speedrun

twin ridge
#

Yeah...

radiant jacinth
#

@amber karma sorry for the ping but can I dm you? I want to ask you a few questions about cybersecurity.

twin ridge
#

(disclaimer, that was a joke)

dark panther
#

Considering that I am on Debian, I probably am running the 20 year old version /s

spark sun
#

Grub gets updated pretty regularly. I wouldn't expect you to be on a version older that's older than your OS.

dark panther
#

Latest stable release! 2021! blobheart

spark sun
twin ridge
#

They were joking as well

dark panther
#

I did say /s

spark sun
dark panther
#

Good idea! I switched from Kubuntu to Debian because I HATE SNAP I HATE SNAP I HATE SNAP, so I'm kinda figuring stuff out since there isn't much preinstalled

spark sun
#

I've spent the day wading through kernel stuff, my brain doesn't get that right now

signal hull
dark panther
#

Ubuntu 22 has Firefox only on Snap now :(

twin ridge
twin ridge
dark panther
#

Never really tried anything Arch based, I don't rice so I don't really see a point in that

twin ridge
#

Fair

dark panther
#

What do/did you run?

twin ridge
#

Mostly windows ATM, sadly

spark sun
#

I run mostly RHEL/Centos/Fedora - my work uses a lot of their products so it makes my life less painful.
I do have a handful of ubuntu boxes, and a windows box for games

twin ridge
#

Might go for fedora when I get a dedicated Linux box

dark panther
#

I really wanna get more into the RHEL based distros

twin ridge
#

The modern ones aren't bad tbh

spark sun
#

There are have been huge improvements to fedora usability since F30

dark panther
#

I would probably actually use Fedora with Gnome

spark sun
#

and silverblue is quite intriguing, although immutable file system may be a bit more than what you're looking to take on

#

all of my linux boxes that use a DE (even Kali) use gnome

#

it's not great, but it's consistent and predictable

#

which is much more important to me than the modern 'sexy' view of window managers

dark panther
#

I just run KDE on my work machines and whatever the default is in Parrot/Kali

#

Doesn't Fedora use BTRFS by default now?

twin ridge
spark sun
spark sun
twin ridge
spark sun
twin ridge
#

Ah

dark panther
#

Set my night color to 1000K and now everything is hilariously red

crimson swan
#

hi

frail rapids
#

Is it fair to assume that WPS is that button on the router to connect your printer without passwords? And WPA is how you connect your (e.g. GUI) device with a pass

candid tartan
#

WPS is button indeed that when pressed active to connect via WPS number. WPA is encryption

#

wpa is when you tipe you password of wifi.

burnt night
finite shuttle
#

Try hackme room : vulnversity

#

when I try to upload the .phtml file, it doesn't get uploaded after sometime it says problem loading page

south inlet
finite shuttle
#

Task 4 Compromise the webserver

south inlet
#

Did you get it eventually?

finite shuttle
#

not getting your point

#

getting the same error in lazyadmin room, while trying to upload the reverse sheel code in ads section

burnt night
dark panther
#

Hope yall enjoying this beautiful weekend! blobheart

#

It's finally below 35C here so I got to go outside without melting

dark panther
#

HP printer drivers are being a bit mean today

#

I really wonder what this even means. Why personality?

primal zealot
#

@dark panther Have you tried calling it names?

dark panther
#

Way too many times

#

It finally did what I wanted it to tho, only took like 2 hours

pulsar hemlock
#

i want to learn hacking

azure wasp
frail rapids
#

I find myself kind of in an awkward situation with real life web testing

#

I feel like that the design of the website corelates with it's security but that isn't always true

tall saddle
regal jetty
#

at least that's the only place I've heard of one of those

#

Oh, HP

#

It sounds like you're trying to have a bad day. Would you like some help with that?

#

Probably same deal though, nobody is telling the printer who to be. The internet says remove the device+drivers in devmgmt.msc and printui.exe /s , clear leftovers from programdata and reboot+reinstall

tall saddle
#

For those not aware, ~/.plan files were provided over the network via the finger protocol and edited by end users directly. Obviously not used any more for some serious security issues but fascinating bit of history. An end user would edit this file to speak about what they're working on in the 80s/mid-to-late 90s

https://en.wikipedia.org/wiki/Finger_(protocol)

In computer networking, the Name/Finger protocol and the Finger user information protocol are simple network protocols for the exchange of human-oriented status and user information.

frail rapids
#

How can I do an attribute seperation in xml without spaces?

#

<svg data-base64-encoded-tex="XHgwMAo="onerror="alert(xss)"x="" height="24" width="24" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M1 21h22L12 2 1 21zm12-3h-2v-2h2v2zm0-4h-2v-4h2v4z"/></svg> gives error in firefox:

#

fixed it by using +

dark panther
#

How many questions do yall have answered per week?

south inlet
#

Depends, I can answer as many as 5, and others 173. (This is going off my activity log which also include machine start ups)

serene trench
#

On this day today a few years ago (one on the right)

#

We done 400+ miles in a day on tiny sports bikes. I was sore for about 4 days

unkempt salmon
#

`

odd acorn
serene trench
odd acorn
serene trench
#

😳

sullen sky
tacit loom
odd acorn
tacit loom
radiant jacinth
#

some dumbass but a fsociety.dat file while I was at a ccna class

#

the leavemehere.txt file was there too

tacit loom
twilit loom
#

I love Mr.Robot.

#

It’s my favorite show.

mighty wharf
frail rapids
#

welp

frail rapids
#

Is it possible to match for strings in wfuzz?

#

the response size is the same for positive and negative responses but the content is different

frail rapids
#

welp fixed it by using a filter

#

--filter "content~'MATCHME'"

dark panther
#

I've read a few of the tweets and at this point I'm too afraid to ask who the guy is

patent kraken
#

Hi

vocal ridge
#

trying to switch to Windows 10. it feels like working without thumbs PepeHands

#

my power has been stripped from me

#

at least until i learn powershell

#

change environment variables with a gui? yeah, have fun...

vocal ridge
#

I've already screwed it up...

FileSystemRights AccessControlType IdentityReference      IsInherited                InheritanceFlags PropagationFlags
---------------- ----------------- -----------------      -----------                ---------------- ----------------
     FullControl              Deny WIN10-WRKSTN\lemvr           False                            None             None
     FullControl             Allow WIN10-WRKSTN\lemvr           False                            None             None
     FullControl             Allow NT AUTHORITY\SYSTEM           True ContainerInherit, ObjectInherit             None
     FullControl             Allow BUILTIN\Administrators        True ContainerInherit, ObjectInherit             None
     FullControl             Allow WIN10-WRKSTN\lemvr            True ContainerInherit, ObjectInherit             None
#

No clue how I have 3 sets of permissions for one Item

vocal ridge
#

Try again...

frail rapids
# dark panther I've read a few of the tweets and at this point I'm too afraid to ask who the gu...

Tired of misinformation about infectious diseases? Time for misinformation about cybersecurity! :)

This video is for EDUCATIONAL and ENTERTAINMENT purposes. Everyone deserves to be treated respectfully so please do not harass the subjects of the video.

Follow me on Twitter: https://twitter.com/gf_256
Join my Discord: https://discord.com/invite...

▶ Play video
hoary nymphBOT
#

Gave +1 Rep to @frail rapids

mortal venture
#

Finally getting better and keep trying to finish one easy lab without help and then hacker vs hacker hit me wit the source code😭😭😭 I hate it here bro

#

I can’t read this man I had to look for help. Pls stop being mean guys

#

@inland falcon if you’re void, thanks for explaining what the code does😭

hoary nymphBOT
#

Gave +1 Rep to @inland falcon

frail rapids
mortal venture
radiant jacinth
#

If it's website testing you need to learn things like SQL and javascript

#

And if it's binary exploitation you need to learn C and Python

mortal venture
#

I didn’t start at age 7 tho. started wayyy too late for that haha. Maybe just a decent one.

soft pier
#

it is never to late to start

#

you just need to keep on learning more and more

radiant jacinth
#

Programming languages, protocols, techniques

#

But it's a shame I can't say I do this

#

My attention span is low

solemn niche
radiant jacinth
summer verge
frail rapids
#

Welp does it include exploit development?

radiant jacinth
#

Interesting

#

Should I take a CS Degree to have some programming background?

#

I mean, there are other ways

#

But I always fail because I don't organize myself well and my interests can change multiple times in a week

#

I think that something more organized and that puts more pressure on me would be good for me

signal hull
#

You do not have to be a software engineer to become a hacker/pen tester/whatever, but the reality is that part of trying to hack something is understanding how it works. If you don't understand the fundamentals of how stuff is put together, you're just bound to struggle once you need to do more than copy and paste one liners from PayloadsAllTheThings 🤷‍♂️

frail rapids
#

Yep

#

Personally I don't think that people who don't make custom exploits are hackers

#

They just know when to press ctrl c ctrl v

radiant jacinth
#

I've now completed 150 rooms on THM
Including all the rooms in Offensive Pentesting , JR Penetration Tester Paths and Wreath Network
Can anyone suggest whether I should try more rooms (and which ones ) or switch to a different platform now ?

solemn niche
# radiant jacinth Nice! How its going?

I now know I know nothing!!! Starting with the very beginner stuff. Learning lots. Plan to transition from electrician to cybersecurity in three - four years. So just plodding along and ensuring I am retaining as much as possible

sick patrol
#

Hi

radiant jacinth
scarlet flower
#

Hello everyone, is the only way to disable Wdigest Auth when using mimikatz to grab passwords? Maybe there is no other way.

dawn coyote
#

Hi all, I am unable to fetch the output of the task 1 , Please help me

radiant jacinth
#

hows everyone doing?

dark panther
#

Chillin

dark panther
#

Check with your local power company if they do site tours, yesterday I visited the largest Czech dam and hydroelectric power plant, was super cool

serene trench
#

that's pretty cool. Did you get to take any pics?

dark panther
#

My coal powerplant visit was much cooler and I have more pics

#

From inside of a cooling tower

#

Probably the coolest place I have ever been in

ripe haven
#

+rep @gray jetty

hoary nymphBOT
#

Gave +1 Rep to @gray jetty

fringe fulcrum
dark panther
#

Left one, coal powerplant in Tušimice, Czech republic

icy field
#

hi guys

#

how r u

true jasper
frail rapids
#
Udemy

Learn hands-on GLIBC heap exploitation with HeapLAB.

Udemy

Continue your GLIBC heap exploitation adventure with HeapLAB Part 2!

Udemy

Complete your GLIBC heap exploitation adventure with HeapLAB Part 3!

signal hull
#

100%. The guy is a great instructor and the content is super dense with good information. Still working through part 1 right now.

#

Like a lot of things in infosec, you could probably find information on each of the attacks discussed in the course across various blogs, but I think this course is definitely worth the money because of the quality of explanation

amber shadow
#

New here need advice as I was just started my path working as desktop support and wanted to be in cybersecurity and what courses and what can I choose my career growth

still maple
#

Milton, a general manager within the Information Technology industry has said “I would summarize my experience in a few words ‘Smooth and seamless Operation’. The enrollment was easy to handle, especially when there is a good number of devices. Training for other users was very easy, and today an administrative employee manages the basic features and enrollment. The solution has been stable throughout the time of service.”

#

^ I guess I have missing punctuation here?

mortal venture
#

Got a usps scam and for funsies I decided to manually go to usps tracking and type in the number and it turns to this?

#

Is this URL encode? Idk. Why would that even happen

#

Ah I realize I copy and pasted the tracking number that’s why. I thought it was normal ascii text but apparently it was not. Manually typing out the number gave me the expected result. Interesting

#

Anyone know a way to get this text on to my pc to play around with it? Or attempt to at least

frail rapids
#

Do USB port killers work when the USB port is turned off in BIOS?

burnt night
#

It's a hardware attack of shorting thousands of volts through it

frail rapids
#

Ahhh

#

I just figured disabling it in BIOS would isolate it somehow

#

Not just software

burnt night
twin ridge
#

You're frying the chip that negotiates data transfer, not the power lines

frail rapids
#

ahhhh

subtle locust
#

hi

valid obsidian
#

Hello

#

Your need help?

proven orchid
frail rapids
#

GUYS

ripe haven
#

We can’t really see the CVE though😭

frail rapids
#

Yeahh it still needs to be published by MITRE

iron cairn
#

hello

wooden pendant
#

whoami

south inlet
#

root

frail rapids
frail rapids
#

It's public :D

#

Basically I had to test the software for my work since I work at an online learning management system used by over 800.000 highschool students and I was requested to audit the SafeExamBrowser config my workplace provided. I was basically manually fuzzing until I found out that the browser doesn't supress printer dialogs, which reminded me of the usual printer dialog -> kiosk escape

plucky stream
#

hey guys, dont know if its the right thread, im currently working on my nmap skills and wondering whats the most typical way an intruder would scan my network. I read that you could hide behind tor and proxychains, but with the wrong Scans there would be still a package leak. Does someone has more information about this? Or Somehting i could read (Paper , etc) ?

burnt night
plucky stream
# burnt night Why do you need to hide the fact you're scanning?

There are multiple Scenarios, for example:

If someone scans my network and hides behind proxychains and tor , it would be more difficult to track him or am i wrong?
I was curious about the package leak, because it would be nice to analyse what information is exactly leaking when you hide.

burnt night
plucky stream
burnt night
plucky stream
signal hull
burnt night
#

Rainbow tables and the insane speeds you can get for cracking it are the problems

#

Collisions are an issue for using it for integrity checks

#

Cc @frail rapids

signal hull
#

You’re right, my bad

#

But you can still use it for HMAC technically because the compression function still works, but there are better options

burnt night
#

Sha1 has the same issues

burnt night
#

Md5 is stupid fast on a GPU. That's bad.

signal hull
burnt night
#

I was answering your HMAC comments specifically there, as it was a reply

#

Rainbow tables apply for all unsalted hashes.
MD5, NTLM, SHA1 are all very very very fast to compute on a GPU, which makes them easier to crack. That applies to MD5 Hmac too, as you can compute lots of possible keys to brute it.

short elk
#

possible is a better term

signal hull
signal hull
burnt night
signal hull
#

You said the cracking concerns still apply, I was asking for clarification on what you meant there

burnt night
#

The key is the secret

#

Integrity and authenticity, not confidentiality

signal hull
#

Right but there’s two inputs into that function. One is the key, the other is the message.

burnt night
#

And like cracking salted hashes, you need at least one of them

#

Message isn't secret

signal hull
#

I think we’re thinking about two different scenarios, I’m thinking of symmetric encryption between two parties using HMAC for integrity checks, while you’re probably talking about how HMAC might get used in the real world, which totally makes sense.

#

I get your points though

burnt night
#

Hmac for integrity.
Not for confidentiality.

#

MD5 is broken for integrity due to collisions

#

Collisions are made easier because it's fast to compute, so it's all interconnected

signal hull
#

You're right. I just want to make it clear that I was originally thinking of this in the context of an encrypt-then-authenticate/authenticate-then-encrypt/authenticate-and-encrypt scenario where the message isn't known, and the HMAC tag is being used to check the integrity of the decrypted ciphertext.

#

In that example, the message is secret. That is all.

frail rapids
#

So what is MD5 useful for then?

burnt night
spark sun
# frail rapids So what is MD5 useful for then?

Stuff you don't necessarily care about integrity with. There are several very good research papers that show that a bad actor can create arbitrary data to collide with a 'known good' MD5 hash. IIRC one of those papers also demonstrates the same with SHA1.

frail rapids
#

Ahhh

signal hull
#

talks about the sha1 collision

frail rapids
#

Yeah I saw that one in a ctf

signal hull
#

@frail rapids Can I dm about your CVE?

frail rapids
regal rampart
#

hello friends i hope it is the right thread, i have just finished jr pt path and now i am on the offsive path, anyways if you are like me and intrested in teamwork here send a massage👍

scenic crystal
#

Could someone help me figure out how i can make gobuster run quicker plz?

#

I mean i tried experimenting with different threads and delay times, it's painfully slow though.........

frail rapids
#

what tech does thm use for the attack machine RDP?

burnt night
spark sun
frail rapids
#

Ahh okay. Too bad it's not suitable for windows

#

I'm trying to put CVE-2022-36220 into a box but it's hard because I need to stage a virtual kiosk breakout

#

so I think I should just RDP via remmina then

burnt night
frail rapids
burnt night
#

It's used in rooms

frail rapids
#

Ahhh yeah

vocal ridge
#

I've been trying to do the "raspberry vpn hotspot" thing with OpenWrt.

it's worked... about 5 times in a row before unexplainably breaking and i don't understand it

#

having to wipe it out and redoing it 5 times. Can't figure out if it's OpenWrt or something else

#

Maybe something's wrong with my SD card, i dunno

#

Gonna try with Raspbian and RaspAP i dunno. I'm throwing darts at the wall rn

#

i just hope it's not a problem with the raspberry...

vocal ridge
#

yeah it's a pain

iron phoenix
vocal ridge
#

yes.

#

it works perfectly until it decides not to, for reasons unknown. I can't pinpoint the issue.

#

I'm going to try a different method using Raspbian and RaspAP

iron phoenix
#

Can you explain how it is and what your experience was, I was just curious

vocal ridge
#

It was just a Raspberry Pi 4-B with OpenWrt.

It's a wireless hotspot, automatically connected to my VPN/VPS in Luxembourg

It worked perfectly every time until power-down. Loss of SSH. Loss of connection altogether, completely locked out.

iron phoenix
#

I must be try this

vocal ridge
#

yeah, it's neat

dark panther
frail rapids
#

HOLY #H1T

#

THE CVE HAS A SCORE OF 9.8 (CRITICAL) WHAT THE

frail rapids
#

It's all downhill from here on kekw

twin ridge
#

that looks cute

lethal shard
#

Greetings, I have an email solution that marks the following url as spam, I try to find out why the solution marks the url as spam but I can't find anything about it, not even on google, even I searched on reddit. Has anyone seen it before or know what it is about? (I separate the url to prevent someone from accessing it by mistake) http: // slkjfdf . net

tawdry dove
lethal shard
tawdry dove
#

Then don't click it

tawdry dove
sturdy wraith
quasi lynx
#

Hi

rose dune
#

I subscribed to tryhackme and I quit my job

#

I subscribed last night actually and that’s it I’m done

south inlet
#

Why did you quit your job?

rose dune
#

Cause I had to be twice as good to be given half the opportunity

#

Some jobs it’s not about who you know really or what you can do because the talent pool is pretty much the same so you end up having to earn your way to the top by having a particular relationship with those able to improve your role

#

Instead of trying something new like tryhackme

scarlet moth
#

experience is more important than extracurricular activities... continue to get experience then continue self learning, apply for better jobs

ripe haven
#

@serene trench happy (albeit late) birthday! 🎉

jolly shale
#

hello guys. so i joined this space today

#

When you've transferred money to your account, go back to your bank account page. What is the answer shown on your bank balance page?

Any help please?

south inlet
molten siren
frail rapids
#

thanks! :D

narrow trout
#

Finally we are changing SIEM from Logrhythm to Sentinel, i thought i was gonna die working in Logrhythm.

It's the first SIEM i've worked on but god i hate it, unbelievably sluggish and outdated from a lot of perspectives, their support also kind of sucks so yeah.

Gonna take some time until we make the full change but can't wait for next week to get started working a little in it 😄

spark sun
#

Sentinel1 is a SIEM now?

tawdry dove
narrow trout
# spark sun Sentinel1 is a SIEM now?

Microsoft Azure Sentinel is a new Cloud-native SIEM service with built-in AI for analytics that removes the cost and complexity of achieving a central and focused near real-time view of the active threats in your environment. Koby Koren from the Azure Sentinel engineering team walks through the entire solution with an end-to-end demonstration fr...

▶ Play video
faint island
#

Azure Sentinel != Sentinel One

narrow trout
#

Ohh he actually said Sentinel1 but didn't notice it 😄

frail rapids
#

Or is this because it's the army and not a 3 letter agency

scenic crystal
#

It's probably because of security classifications @frail rapids .

scarlet moth
#

saying they are nation-state hackers may mean something, maybe not, army cyber is supposed to be really good, I've worked with a few in my career

frail rapids
#

No, that someone can tell others they're working there

#

Without their employer firing them for their own safety

frail rapids
#

It definitely would give a unique work experience

#

It's other than working in FAANG, and I think it's a great early-carreer move

#

you'll probably get a trainings/certs, unique insights, and the right to say you're an ex-nationstate hacker when you want to go into corporate

#

which will probably make the recruiters go mmmmhhhh

#

Personally I really hate the masculinity of the army, which is why my preference would go out to other orgs

#

(I don't live in the US but I assume it's a lot worse over there)

glossy drift
#

is this only for us citizens

#

US

frail rapids
#

I don't live in the US so I definitely wouldn't go work for them anyway 🤷‍♂️

#

but I just find the appeal of working as a nation state not bad

scarlet moth
scarlet moth
scarlet moth
frail rapids
#

Over here it's like 5% women

scarlet moth
#

The army cyber division has a fair number, one of my friends worked there, it is more diverse than my corporate job

#

Or maybe that is where she worked

timber summit
#

Hey everyone I’m new here and I started my course in Oak academy this is my first week will be using Tryhackme. Any suggestions for the first days ? Thanks

brazen crane
#

hey, im in NMAP session, they ask me to nmap "MACHINE_IP" but i cant find it. can anyone help me please?

south inlet
south inlet
brazen crane
#

i did it already

south inlet
#

I hope that's not you DM'ing me...

south inlet
# brazen crane i did it already

You need to press this green button, and wait 2 min(s) for the MACHINE_IP to update, if it doesn't, press refresh or Ctrl + F5.

Please don't DM me without asking.

brazen crane
#

sorry

#

im in the machine already, im trying ping the "MACHINE_IP" or nmap -xS and i get this massage

south inlet
#

No, you're in the attackbox.

#

You also need to start the machine you will be attacking.

Attackbox = machine you're attacking from
Target machine = Machine you will be attacking

brazen crane
#

great thank you!

sturdy frigate
#

Hello guys, i just found about this discord from the official website. So, i have decided to join. I want to enter in the cyber security world. I am looking into cyber security analyst and certified ethical hacking career. Is there anyone know the right pathway/programs/certificates to achieve? So, i can start my journey in the cyber world without wasting time. Any help or advice would be much appreciated. Thanks in advance.

sterile hull
#

I joined the THM last fall and completed 5 rooms & the Advent of Cyber. Logged in for the first time in 6 months and show no rooms completed. Does, or did, history get wiped at some point of inactivity?

frail rapids
#

Is it me or is unknowncheats a tech support website for undocumented windows kernel structs by unpaid children

gleaming trail
#

When you've lost yourself in the fog of identity. When fractures begin to appear in your very soul. When you feel you are no longer here and not really there, you can find yourself again with one simple command: whoami. whoami..

neat zealot
vocal ridge
#

i prefer id

#

and therapy

twin ridge
#

eh, I prefer id

mortal venture
#

Anyone know any good c++ servers? Newbie looking for some people to communicate with. Feel free to dm the link if you have one

smoky mortar
wild grotto
frail rapids
#

starting college tmr

#

I really feel like wearing the "I hacked the Dutch government and I got was this lousy t-shirt" shirt but I don't want people to know about what I do in my spare time

twin ridge
#

I want one of those

worn schooner
worn schooner
dark panther
urban sapphire
#

Hello sir, I am your premium user .

Here I am stuck on one question. Please check it .

Who is TryHackMe's HTTPS certificate issued by?

for this question to find an answer i had done a lot of research and submitted all possible answers .So please help me . the question is wrong or anything else the right answer.

dark panther
#

Try harder, I did that room a few weeks ago

urban sapphire
#

please help me

south inlet
dark panther
south inlet
frail rapids
#

I want to quit... stuffs so boring 🥲

worn schooner
frail rapids
#

and we're talking real fundamentals

#

think difference of int vs bool fundamentals

worn schooner
frail rapids
#

issue is that my attendance is getting weighted in my grade

south inlet
#

What about contribution?

frail rapids
#

it's university of applied sciences.. teachers are failed IT employees and probably feel like they're better than me

#

I just asked a question about declaration / definition / initialization and he still mixed them up

worn schooner
signal hull
#

also if it's so easy just speedrun the work and do whatever else you want on the computer in that class 🤷‍♂️

#

I've played CTFs during lectures all the time

#

or, even better, just ask to test out of the class

spark sun
twin ridge
twin ridge
spark sun
twin ridge
spark sun
frail rapids
spark sun
# frail rapids but he was teaching those topics (in a programming class)

If it's an intro class, they often don't give the 'best' instructors the base level courses. For what it's worth, giving a lecture is difficult, even if the lecturer knows the material very well. I often turn words around and mis-speak when I'm lecturing; if you have concerns about the instructor quality, go to office hours first and seek clarification from them. If the problem persists, go to the dean or department chair and ask for a meeting to air your concerns.

spark sun
smoky mortar
#

Making Learning paths is as well 😄

frail rapids
#

Why does the FBI only go after ransomware affiliates instead of operators?

#

Or are all operators russian

tawdry dove
#

What do you mean by affiliates?

#

They arrest the people using the ransomware when possible

frail rapids
#

but they haven't arrested any of the operators afaik. or the operators are really good at opsec

tawdry dove
#

Again, what do you mean by affiliates and operators

#

Revil, if you believe the Russians, was dismantled and arrested

vernal vigil
#

hi

vocal ridge
#

ooh I'm excited ~ starting Exploting AD. Wish me luck

#

No, breaching... it's like Christmas. Idk which one to choose

vernal vigil
#

ohh,best wishes to you

vocal ridge
#

i think resolved and network manager are conflicting

#

wondering if i should just switch to networkd

vocal ridge
#

yeah that helped

cold pond
#

whats up @compact compass

#

im new to cyber security as well

bold elm
#

Hello guys, is there some kind of channel where we can do a CTF all togheter?

quasi turtle
bold elm
#

@quasi turtleOh thank you very much!

hoary nymphBOT
#

Gave +1 Rep to @quasi turtle

quasi turtle
#

yw! I hope to set up weekly sessions again soon, feel free to drop suggestions for rooms you would like to do in the #964299701581119538 chat

bold elm
#

Yeah!

still maple
#

Making Spanish rice is an art form

scarlet moth
#

easy peasy

dawn kite
#

No Troll, i give 1 month as a GIFT
Should be more quiet here to let people see

spark sun
worn schooner
dawn kite
hoary nymphBOT
#

Gave +1 Rep to @spark sun

frail rapids
#

I'm excited for the new path

#

Hope to learn a thing or two about AD since I'm in college and it seems like everyone has experience with windows servers

clever fulcrum
#

hey, can anyone tell me where should i start solving CTFs as i am a newbie

frail rapids
#

Watch NetworkChuck's CCNA course from 2 years ago and start using linux virtual machines until you're comfortable

clever fulcrum
#

kayy, thank you !

foggy orchid
#

Can someone pmo

worn schooner
shut sonnet
#

Good evening strangers 🙂

pallid crystal
#

when should I rely on walkthroughs?

worn schooner
pallid crystal
worn schooner
pallid crystal
worn schooner
#

We all start somewhere 🙂

pallid crystal
hoary nymphBOT
#

Gave +1 Rep to @worn schooner

pure mantle
vocal ridge
#

i try to do my writeups with my own quirks but sometimes lines can be word-for-word.

Explaining a technology or an attack vector or anything else involving that is kinda hard to put in your own words

#

how do you explain jndi/log4j without doing it verbatim?

vocal ridge
#

I've heard people recommend refurbished laptops. What about a refurbished servers?

i mean hardware is hardware but with that level of abuse would it be worth it?

signal hull
signal hull
#

In the case of log4j, consider your audience and what direction you want to take your work. Do you want to explain how everything works in detail, are you trying to "explain like I'm five", is this for seasoned experts in the field?

vocal ridge
signal hull
#

I also thing a lot of people get hung up on the l33t h4ck3r side of things. It's worth discussing the implications of the bug as a whole to the software supply chain and what issues are currently present there. Exploits are cool but providing mitigation or discussing the origin of the bug and how we can minimize it going forward shows some maturity imo

vocal ridge
#

not that i publish my writeups. they're mainly for me.

signal hull
#

oh lmao

vocal ridge
signal hull
#

if this is just for notes then copying and pasting is fine 🤷‍♂️ , just make sure that you know and understand what you're copying as opposed to just copying the entire article.

Most of the points I was making were related to writing public blogs.

vocal ridge
#

yeah, i was just pointing out that sometimes we all copy-paste at one point or another

#

as long as you understand what you're looking at

#

it's not necessarily a bad thing

#

my original question though: anyone ever bought a refurbished server?

final echo
#

I am new to this and i dont know if this is the right place to ask this question
but I am not able to message in #koth channel
Do I have to connect to any vpn to access the machine?

tawdry dove
#

!docs verify

deft fossilBOT
stark stag
#

!dark

deft fossilBOT
#
DarkStar7471
Blue Room is not broken.
radiant jacinth
#

!dark

deft fossilBOT
#
DarkStar7471
*ahem* Can help you?
radiant jacinth
#

!dark wassup

deft fossilBOT
#
DarkStar7471
***dab***
frail rapids
#

Isn't discouraging employees to throw around their work email addresses the best way to prevent phishing?

twin ridge
#

And easily guessed

south inlet
#

Darknet diaries had a great peace on Insider Threats involving LinkedIn and work emails.

south inlet
south inlet
frail rapids
#

Is it me or is learning certain parts of infosec harder as time goes on

#

Every blogger assumes that those reading are experienced in that field

#

^I'm specifically talking about kernel pwn

signal hull
#

Tbf you are exploring a topic that is just more obscure and advanced than your regular heap or stack pwn

#

There are just less people who are experts or teach the topic the deeper you get into it

faint island
# frail rapids Every blogger assumes that those reading are experienced in that field

^^^ the things above are all valid points but to add on often times the thing a researcher is publishing requires so much prerequisite knowledge, they decide to make their intended audience someone else in their field of study. Say for example someone is writing a blog post about a kernel vulnerability they discovered. The person publishing it is going to want to convey what they found so that other researchers can understand and possibly repro it. A basic 10 page writeup of some kernel CVE with the target audience being other vulnerability researchers may be over 500 pages if the target audience is a first year undergrad computer science student in order to give them all the background knowledge for the vulnerability and how it was exploited. The person publishing doesn't have the time to write a 500 page paper on an 0day if 10 pages is enough for another kernel vulnerability researcher to understand it. The same goes for any discipline whether it be biology or physics. If you're doing advanced research which requires a lot of prerequisite knowledge, you will want to publish you research with the audience being other researchers in your field or else you'll end up writing a thousand pages just to explain every discovery you make

frail rapids
#

yeahhh

#

I guess it just sucks that no one wants to write beginner content for specialized content

spark sun
#

The beginner content are the classes everyone says is useless in a comp-sci degree program.

#

Algorithms, data structures, and OS for sure.....

frail rapids
#

idk about you but I'm not getting a OS-design course or even minor in my compsci BSc

spark sun
#

I did.

#

I didn't go to a top tier school, my undergrad as a solid middle of the pack tier3 school.

faint island
#

Doing research in memory corruption and binary security in of itself requires a vast amount of knowledge ranging from how computers lay out memory for executables and how a bug can lead to undefined behavior. When you scale it up a notch to kernel exploitation you now introduce stuff like privilege rings, OS design, user/kernel land communication, physical vs. virtual memory and how it's implemented, and various CPU aspects such as control registers and how caching is implemented

#

It's just very unrealistic expecting people publishing research to include all of this stuff in a single paper

frail rapids
#

Well yeah, but perhaps just a simple blog post

#

E.g. explaining basic techniques and the general goal of kernel exploitation

#

Just something in between the regular kernel docs and specialized exploit papers

spark sun
#

Many of those concepts are introduced as part of comp architecture or OS courses - they aren't nearly as in-depth as the active research is, but they aren't intended to be 'current state of the art' in those domains. I am not up to current state of the art, but I am able to read and follow those reports due to those courses

frail rapids
spark sun
faint island
faint island
# faint island Well yes but you have to start somewhere. I have a few links about kernel stuff ...
Low-level adventures

Disclaimer: This post will cover basic steps to accomplish a privilege escalation based on a vulnerable driver. The basis for this introduction will be a challenge from the hxp2020 CTF  called "kernel-rop". There's (obviously) write-ups for this floating around the net (check references) already and as it turns out this

GitHub

A collection of links related to Linux kernel security and exploitation - GitHub - xairy/linux-kernel-exploitation: A collection of links related to Linux kernel security and exploitation

#

It's good to start out at the basics of development when it comes to kernel exploitation. If you're completely new then try creating a driver which exposes a char device that a userland program can interact with. Or even implement a custom syscall

#

You'll slowly start to get an idea of how OSs work by playing around with writing kernel modules and can then tranfser that knowledge gained into finding vulnerabilites

frail rapids
#

Thanks a lot!

#

I guess I should dive deeper into kernel devices. I thought just knowing how kernel modules work did the job

#

(especially until I tried solving a kernel pwn challenge)

faint island
soft pier
frail rapids
#

Perhaps I could look into linux driver dev books

soft pier
#

for the most part reading up on it should be easy but time consuming.... though not nvidia drivers because those are still closed source

vocal ridge
#

Like drinking from a firehose... I have many years ahead of me.

tardy solstice
#

Morning all

south inlet
#

Hello!

south arrow
#

Hi. Could one of the Admins/Mods reach out to me by DM about adding to the next Community Giveaway?

twin ridge
tardy orchid
#

Is password expiration policy/feature necessary?

burnt night
ripe haven
#

I honestly didn’t know that security questions were so hated.

compact wharf
ripe haven
compact wharf
frail rapids
#

Why haven't I seen someone talk about SPAs leaking all URLs/paths of a webapp?

#

Basically SPAs use client side rendering which means that all paths are crammed into a single .js file

#

so if you use a crawler you can find all paths of a webapp

#

I've used it for a few web pentests at my old employer. It helped because I knew which API (and regular) endpoints exist, and all HTTP params for them were next to those API paths in a fetch(...)

#

that also means you don't need to do dirbusting (for most cases) which makes it a lot more quiet

half mesa
lime sparrow
#

any marines on here?

vocal ridge
#

Army, and one cop I believe

tawdry dove
#

There's a bunch of different services here

tawdry dove
frail rapids
scarlet moth
#

There are a lot of people from various military services retired and active

sinful fjord
#

hey,how work the top 50 Monthly in tryhackme ?

south inlet
#

Top 50 monthly is just the total points you get from the 1st of the month to the end of the month.

frail rapids
#

Why do some 2FA providers like google do a "approve this login on your phone" thing?

#

instead of a "enter this number on your phone"

#

because the latter prevents people from just clicking approve because the notif is annoying on their phone

south inlet
#

It can be done via fingerprint.

#

Which is easier and a more secure way to prove the requester is whom they are.

cold pond
#

did i cross the lines on what normies are allowed to search? idk

#

and the approve login thing can be changed in the google settings

#

for your phone number thing

#

you can change it to send a confirmation email with 3 bubbles of numbers

vocal ridge
#

anytime I use Tor, Google decides to ask me every time.

#

proxychains/tor

cold pond
#

both

#

i should take them off shouldnt i

frail rapids
#

yes

#

proxies (probably) give you a different public ip and those captchas usually get sent to suspicious ips

#

hence, if everyone uses those proxies for malicious reasons, it gets flagged

#

which is the reason that private proxies exist

vocal ridge
onyx oar
#

What Do I Do When Someone At My Church Says That Hacking Is A 'Sin'?

onyx oar
#

Yeah. I Like My Cyber Security Career

#

I Think i'll do nothing about it

smoky mortar
onyx oar
#

That's Genius

smoky mortar
#

From one Tim to another.

vocal ridge
#

😄

#

"RST"

#

I would just "drop it" actually

#

bdum-tss

lapis swift
#

Guys
I m new to all these things
help me to proceed
what to do
how to start learning whatever is required
i mean like basics

quasi turtle
ripe haven
surreal kite
#

Guys this might be a non-technical question but how to i actually get more

#

roles here THM? :3

south inlet
#

Depends on the roles, The only roles you can assign yourself is Announcements, level and nitro, what role are you thinking, the mod team assign you roles on criteria.

surreal kite
#

Oh i see!

#

I assume that these roles are something you earn through doing more lessons

south inlet
#

Well, Throwback has a role.

frail rapids
#

is it allowed to drop custom exploits (with a cve) on github?

#

e.g. you see there's a new juicy CVE and you make an exploit for it and post it on github

signal hull
#

there's nothing stopping you but depending on how fresh the CVE is, you're mainly dealing with ethical issues

#

John Hammond has previously voiced his own concern over releasing his and Caleb Stewart's LPE for PrintNightmare a bit early on in the process of trying to mitigate the vulnerability iirc

#

but then when the advisory/writeup for pwnkit dropped, although qualys never published a poc, there were at least 40 repos with the exploit out there (including my own 😶 ) within 24 hours of qualys' public report

ripe haven
regal jetty
# onyx oar What Do I Do When Someone At My Church Says That Hacking Is A 'Sin'?

launch into a 45-minute sermon about the history of the word "hack" and its multiple overlapping meanings, culminating in an inspiring ode to the "good hackers" who keep us safe from the "bad hackers" (bonus points for angel/demon analogy, bonus bonus points for tying into said analogy the ongoing temptation that Good Hackers endure while engaging in righteous warfare with the dark side)

#

Extra credit: draw parallels to Ecclesiastes (there is no need to actually explain them and it may work better if you don't)

daring cave
#

I still like the 'SYN-ACK' answer haha

vocal ridge
#

was doing well until a few days ago. Felt the "condition" starting to creep up on me.

hope it goes back down soon

spice prawn
#

Sending buffer overflow, the following code my debugger works, the second code my debugger crashes somehow and I can't continue (shouldn't happen) is the alignment of bytes wrong?

windows7 x86

Working code:

...other code

length = 10000
offset = 4336
eip = b"BBBB"

payload = b"".join([
                b"A" * offset,
                eip,
                b"C" * (length - offset - len(new_eip)),
        ])

Broken code:

...other code

length = 10000
offset = 4336
eip = b"BBBB"

payload = b"".join([
                b"A" * offset,
        ])
golden kindle
#

So what are our greatest hack achievements so@far

#

Who is gonna start with a testimony

night patio
#

one possibility is that you could be overflowing ebp and the program is crashing when popping it and trying to access local variables

frail rapids
#

@quaint basin Can I shoot a dm? I want to ask a question about vuln disclosure

quaint basin
quaint basin
#

Iirc @cinder spoke has done it once or twice. @dreamy kayak would be a good shout too.
By all means DM though. If I have the answer you're welcome to it 🤷‍♂️

frail rapids
#

Aightt, thanks

dreamy kayak
soft pier
dreamy kayak
#

Of course!

quaint basin
#

Assuming that updating the config file is enough to change the allcontributors rendering

dreamy kayak
quaint basin
#

Will check

#

That has, uh, not fixed it

warm oar
#

q

fringe kelp
#

anyone up for a private conversation about cybersecurity? Any experience level welcome, just dm me 🙂

dreamy kayak
leaden glen
#

👀

frail rapids
#

What's a good way to exfiltrate data using RCE on express.js servers?

#

there's HTTP command injection -> local file write -> HTTP file read but that's loud considering you need to write to disk and open an http connection

#

I was thinking about doing a semi-side channel, like setting the system time which influences the Date header (but that's probably even louder and it has less data leaking capabilities)

onyx oar
#

Wow @regal jetty You Thought It Through More Than Me!

onyx oar
burnt night
#

Just ignore them

onyx oar
#

Some Ingenious Answers! Thanks Everyone

burnt night
#

They're not worth your time

onyx oar
#

Yes

mortal venture
#

when setting up a vm do you guys use the "bare-metal" kali or the "virtual machine" kali install?? I always use bare metal in my vm

velvet siren
#

I got a problem with host only adapter in virtual box
It's not providing ipv4.

radiant jacinth
#

@mortal venture I was always use a virtual machine because it’s just better security wise and the snapshots come in clutch as well as if you mess up something you can easily fix it

south inlet
vocal ridge
#

it also allows for easy encrytion, but VM is quicker. I guess it depends on what you want.

meager marsh
#

hello tryhackme discord. i would like to ask help on how to change username so that it looks good when badges are shared in linkedin. thank you.

spark sun
vocal ridge
#

I Definitely need to start tinkering with RH

mortal venture
#

i really need to also but it costs money and thats a no go for me. dont like

tawdry dove
mortal venture
hoary nymphBOT
#

Gave +1 Rep to @tawdry dove

spark sun
tawdry dove
#

Oh shush you lol

#

I've still never met a TAM

spark sun
burnt night
#

Rhel specifically

spark sun
burnt night
#

$300ish for self support doesn't sound like a support subscription

vocal ridge
#

I did not see that.
.

spark sun
#

I'll take another look tomorrow. There shouldn't be a cost for the RHD individual program.

burnt night
twin ridge
#

After that you need support or it self destructs

#

Maybe self implodes I dunno

spark sun
burnt night
spark sun
# burnt night Just googled self support rhel

ok, i think i see it. That is intended for enterprise, 'self support' in this case means 'RH doesn't help with troubleshooting problems.' What that price tag gets is the RH compiled binaries and repositories allowed for whatever that entitlement scope actually is. RH does provide the source code for everything, but binaries are paywalled behind the subscription manager.

summer verge
#

Get Alma or Fedora for free 😂

soft pier
#

what does TAM stand for in this context???

spark sun
#

Technical Account Manager

#

It means different things for different orgs, but usually it's a vendor employee acting as a customer advocate with a distinct role from the sales teams

trail cove
# summer verge Get Alma or Fedora for free 😂

Alma or Rocky would be a good platform for self-supported RHEL-based servers, a little behind the RHEL update/release curve but still on par. Fedora is very close to cutting edge, almost considered unstable. Probably not suitable for most production Linux environments but fine for personal or project/lab environments

summer verge
trail cove
summer verge
twin ridge
#

I'm assuming CentOS is still a thing if you want an RHEL-like env

vocal ridge
#

They've stopped further development, haven't they?

twin ridge
#

have they?

vocal ridge
#

I've heard (rumor) that CentOS will not be updated any further but i'm not sure if that's a fact

twin ridge
#

nah, they switched to a rolling release

vocal ridge
#
However, the free ride is over. Red Hat announced that CentOS Linux 8, as a rebuild of RHEL 8, will end at 2021. CentOS Stream continues after that date, serving as the upstream (development) branch of Red Hat Enterprise Linux.Dec 10, 2021

OS family: Red Hat Enterprise Linux
#

I see now.

twin ridge
#

right Stream

#

it's positioned as a midway between Fedora and RHEL

vocal ridge
twin ridge
#

Fedora is bleeding edge, RHEL is the super stable Enterprise package

#

CentOS is the dev branch for RHEL

#

so things that appear in CentOS will eventually trickle down to the next RHEL version

summer verge
#

rumour has it that richard stallman coments kill CentOS

vocal ridge
#

I didn't realize there was an in-between of LTS -> Bleeding Edge.

twin ridge
#

it's pretty rare

spark sun
twin ridge
#

that's about what I said

tawdry dove
frail rapids
#

quick question:

#

Should you say Dr. name in english as well?

#

I've got a meeting with a PhD person tmr and he's german

#

(and germans are really sensitive about their titles)

quasi turtle
#

Just ask him what he wants you to call him

#

If he wants to be adrssed with dr all the time, let him say it out loud himself 😂

spark sun
#

I would ask what they prefer. Some PhDs are very militant about the title, others are fine with being called 'professor.' Most I have met prefer their first name.

tawdry dove
#

iirc it's doctor there

soft pier
#

in sweden most swedish citizens prefer being called by first name

#

so even the janitor addresses the CEO of a company with their first name

quaint basin
#

In slightly more traditional higher education systems, there is (usually) only one professor of a department at any one time, sometimes there is also an emeritus professor who usually keeps the same title.

#

Either way, calling your average lecturer a "professor" in Europe will likely get you some very odd looks kekw

#

Dr. Surname or just FirstName (depending on the individual) would be a normal form of address 🤷‍♂️

radiant jacinth
#

It’s quiet shhh

echo dust