#quiet-conversation

1 messages · Page 2 of 1

spark sun
#

As far as I know, that's pretty much right. CEntOS started as a direct byte-for-byte copy of the provided RHEL source code, compiled by the community, hence the name: "Community Enterprise OS". RH bought out the CEntOS project several years ago, and has been maintaining and providing it as more of a parallel unsupported FOSS product. Part of the chaos and confusion caused by RH changing centos into an upstream was that many orgs were using centos in dev/test so they could basically use RHEL without paying sub costs for non-production systems

#

I just re-read this and I read what you said incorrectly. Adjusted my above reply to not correct you on a thing you stated correctly 🙂

burnt night
#

And visiting professors

quaint basin
# burnt night And visiting professors

Eh, yeah, good point. You may also find a visiting professor in a department kekw
Wasn't really including them because they would be called professor anyway due to their own tenure, regardless of where they were actually working.

burnt night
quaint basin
burnt night
#

Visiting professor was this guy's title. Not one of my lecturers

#

He had the actual title of Professor

quaint basin
#

So, yeah, they have their own professorship elsewhere and thus already have the title kekw

quaint basin
burnt night
#

Being a visiting professor was enough to confer the title

quaint basin
#

So they were actually Dr. LastName but were addressed as professor due to the visiting professorship? How odd

#

Don't think I've ever heard of that one before 😆

burnt night
quaint basin
#

Curious arrangement

tawdry dove
#

Is that a UK thing? Doctor, at least here, is seen as more prestigious. Probably because anyone teaching the class is going to be called professor unless it's a TA

serene trench
#

Professor is a higher title here. A PHD here will grant you a Dr. status, but professors are usually heads of departments and you usually have to be elected to be a professor

#

over here in the UK that is 🙂

#

In my 4 years of Uni I've only had to call Dr's by Dr formally (like in emails), in convo my lecturers have liked their first name to be used. Same with two professors I've studied under (formally in emails, etc, but first name in convo/classes)

quaint basin
#

That ^^^

cursive jackal
#

guys when the monthly leadbord will reset to 0?

still maple
#

I turned mine into mush

#

My attempt at tortillas. A little wonky but still good lol

scarlet moth
#

my tortillas always look like amoebas

twin ridge
mortal venture
#

Ugh just now finally learned why putting comments after syntax gives an sql injection. I’ve always wondered why sql injection works for sooo long. Thank you ippsec 😭😭

mortal venture
#

I just feel so satisfied ya know? Figuring out how something works is just the best feeling in the world. I feel like I’m god and know all the knowledge in the universe.

twin ridge
mortal venture
#

Yeah I really enjoy the thm rooms that explain why we are doing what we are doing. It’s so satisfying understanding why vs copy and pasting a bunch of stuff. It’s what I live for

burnt night
#

-ban @radiant jacinth -ddays 1 Racist name and pfp

hoary nymphBOT
#

🔨 Banned High inhib Rice Ninja#4353 indefinitely

frail rapids
#

tfw
> someone sends an official national newspaper article in a discord server of a friend
> you recognize it's you
> you say 'damn, he do be looking hot'
> that other person doesn't know you're the person in the article

vocal ridge
radiant jacinth
#

🤣

twin ridge
#

Poor Jeffrey

soft pier
#

something has gone horribly wrong in there

radiant jacinth
#

hi

echo dust
#

Database using first-name as unique key.

twin ridge
echo dust
vocal ridge
#

Lemur's screwed because they only have one name.

burnt night
#

As in presenting HID to a connected PC, or using a USB input device on the android phone?

vocal ridge
#

nvm, I just realized what i've asked for.

warm peak
#

@quasi turtle why you getting seized?

half mesa
radiant jacinth
#

Damm i had some pistachios

floral stag
#

That’s crazy, I was so close to ordering one before they sold out too

weary haven
#

got mine, though i did have to wait 700 days

soft pier
#

Shadow also got their flipper zero... Wait about a quarter of a year

rough valve
vocal ridge
devout schooner
#

anyone have voucher code ?

olive frost
devout schooner
signal hull
olive frost
signal hull
devout schooner
olive frost
deft fossilBOT
devout schooner
hoary nymphBOT
#

Gave +1 Rep to @olive frost

fallen crag
#

i provided the right answer but the system says it's wrong. what should i do

mortal venture
south inlet
echo dust
#

There are some rooms where I've found they want very specifically written. It can get annoying.

lime path
#

hello

#

hello

vocal ridge
#

hi there

vernal dune
#

My DMs are open for conversations about anything with anyone 🙂

radiant jacinth
#

Hey, are we allowed to share some music here?

dawn wharf
fervent glade
#

Can any expert in hash cracking help me crack this hash? 7a828bae0910102319b8162edff80a73

twin ridge
#

what is this hash?

fervent glade
#

Oh it's part of a ctf

#

Just need to know if you guys are able to bruteforce it

#

No luck on my side

south inlet
#

I am, but I'm not telling you 😄

fervent glade
south inlet
twin ridge
#

looks like something that should be easily bruteforced, though it may be salted

warm peak
fervent glade
#

Meow might just be a hint to hashcat

fervent glade
twin ridge
#

is this an active ctf?

twin ridge
#

that doesn't answer the question, but we do not assist with external active CTFs

warm peak
fervent glade
#

The point here is to see if it's crackable that's all

burnt night
#

@radiant jacinth don't offer help with active CTFs here

obsidian plinth
#

i am looking for a project in cyber security , do you have any ideas or old projects for reference

undone rock
#

yes,i have

radiant jacinth
#

Sorry

frail rapids
#

can I upload a zeroday exploit on github the day the CVE was published?

#

:D

#

I mean, it's probably not M$

frail rapids
#

Welp

frail rapids
#

definitely going to be a funny headline on bleeping computer some day

vernal dune
#

Hello everyone,

I recently finished reading the book Ultra-learning which is basically a bunch of compiled stories of autodidacts and some of the techniques they used to learn their craft, and the author highly recommends "interviewing" experts on the skill you're trying to learn about their learning process.

Would anyone be willing to talk to me for a bit?

Just to be clear, I don't want any cyber-security related knowledge handed to me, I'm only interested in your journey towards getting to your current level. Stuff like research methods, learning strategies, order in which you learned the sub-skills, stuff like that.

Feel free to dm me if you're willing to give me some insights 🙂

mortal venture
#

Hey I’m looking to create my first room so I can experience it. but I have absolutely zero knowledge and if anyone would be interested in helping me along the way or even so much as point me to a few topics for me to read that would be appreciated. Just a simple boot2root Linux machine is all I wish to do for now. feel free to DM / ping me with any help. Thanks in advanced

twin ridge
#

I can give you access to the creators lounge if you wish

plain moth
hoary nymphBOT
#

Gave +1 Rep to @twin ridge

frail rapids
vernal dune
#

Because so far I've only been reading theory

#

And doing the basic exercises on THM

frail rapids
#

HTB and personal projects. I'm currently analysing the firmware of an IoT device

frail rapids
#

But it's a great way to learn if you can, as I've learned tons of new things about IoT security

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @twin ridge

twin ridge
#

-arole 404646839359373331 Creators-Lounge

hoary nymphBOT
#

➕ Gave the role Creators-Lounge to Huntress#0022

frail rapids
#

the corp is witty with CVD (they keep ignoring CVD requests but respond to usual customer support requests) so I might just request a CVE without their knowledge

#

but it's probably going to be 10.0

paper hemlock
#

Hey where can i learn blockchain beginner level

surreal kite
frail rapids
#

linux unauth RCE /s

glossy drift
#

Hi is there any detailed writeup on the msfvenom encoder " Shikata_Ga_Nai ". Explaining in a higher way. I mean I just want to implement it into another language and don't want to study ruby.

odd acorn
#

But as a programmer you should be able to interpret the code

#

Just use the Ruby docs and you don’t need to learn any Ruby, you’ll just be translating it

mortal venture
#

I’m getting to the point to where I can easily root boxes labeled easy. But then php code comes into play and i can’t do it. Pain.

glossy drift
mortal venture
#

Like archangel. Doing great until php source code reading came into play and now I gotta look at write ups. Ugh

glossy drift
hoary nymphBOT
#

Gave +1 Rep to @odd acorn

glossy drift
#

Dealing with syntaxes is true 😅pain

mortal venture
#

I’m even following along a write up and still have no idea what is happening in archangel. I swore I was finally getting good🥲🥲. Back to square one again lol

sullen girder
#

Problem changing country from public profile

signal hull
gleaming jackal
#

Hello, I need some help with parsing some logs. I there anyone who could help me to write an expresion on regexr or point me to the right direcion?

frail rapids
#

Is offensive DFIR a thing?

#

E.g. finding confidential information in metadata of a document

south inlet
#

Wouldn't that just be Offensive security?

Since DFIR is Identifying attacks, investigating them and then remediating them?

signal hull
#

I think you're just talking about opsec, and making sure that confidential information doesn't get leaked.

burnt night
#

@fast swallow Please let them make their own silly mistakes

fast swallow
frail rapids
#

sooo, why aren't there source code based boot-to-root ctfs?

#

especially in the beginner difficulties

#

e.g. you get the website sourcecode and need to find a vuln. that would be a lot better imo than blindly poking at a webapp which is quite litterally biased luck

frail rapids
#

Ohhhh okay

static smelt
#

im solving a maching based on nmap and netcat but idk from where hsould i start

static smelt
#

ya

burnt night
distant bramble
radiant jacinth
radiant jacinth
distant bramble
#

you can enable the developer option in chrome://extensions and add cloned folder to "load unpacked" option.

radiant jacinth
#

keep it quiet

heavy ruin
radiant jacinth
#

Hi

#

👍🏻👍🏻👍🏻

#

Hahaha

#

Remember don’t ping!

#

Are you ping in?

#

I saw you

odd acorn
#

-undelete -a

hoary nymphBOT
#

Up to 10 last deleted messages (last hour or 12 hours for premium):

none...

hallow cairn
#

Hello, I have problems with the vpn configuration file, I have downloaded a new one, but it does not work, can you help me please?

frail rapids
#

where lies the line between security through obscurity and regular passwords/secrets?

frail rapids
#

ahh okay

#

(that dude's name "Kerckhoff" means graveyard in my language)

twin ridge
twin ridge
#

oh don't know the other

twin ridge
#

bringing back trauma though

rancid knoll
#

welcome back

raven osprey
#

hey

subtle herald
#

hi guys

mellow merlin
#

hola 👋

dusk oxide
#

wsg

wet glade
#

Why do i get a converting error when uploading a vm to my room.in tryhackme

humble bison
#

IT Security Trade show in Germany 25-27.10. Nürnberg :

Hi,

da ich ja weiß, dass hier einige Deutsche im Discord sind, wollte ich mal fragen,
ob wer noch zur it-sa geht?
Ich bin vom 25.10. bis 27. aus der IT Security Messe it-sa in Nürnberg. denke aber, dass ich bis zum 30 in NB bleibe, und mir das Nachleben noch ein wenig anschaue. War vor 10 Jahren oder so schon einige male in NB und fand die Stadt echt schön.
Wohnt noch wer in der nähe und hat lust mitzukommen?
Es gibt noch die Möglichkeit auf Kostenlosen Eintritt, statt 85€

Liebe Grüße

#

Hi,

since I know that there are some Germans in the Discord, I wanted to ask,
if anyone is still going to it-sa?
I am from 25.10. to 27. from the IT Security Trade show it-sa in Nuremberg. but think I stay until 30 in NB, and look at the afterlife a little more. Was 10 years ago or so already a few times in NB and found the city really nice.
Who still lives in the area and has to come along?
There is still the possibility of free entry, instead of 85€.

Love greetings

quasi turtle
#

@humble bison this is an English only server

humble bison
#

@quasi turtle

#

since it is in germany, i first wrote it in german, and on THM are also german, but yes have translated it again in english

quasi turtle
#

I saw 🙂 but just for awareness. There are many nationalities here but such sre the rules

#

Ty!

humble bison
#

yes, then I also thought that I'll quickly translate it, because I just still get coupons for free entrance

frail rapids
#

interesting.....

lime path
#

sniff

elder tangle
#

sniff

#

sniff

rapid barn
#

Anyone know of cyber security conventions in California

scarlet moth
rapid barn
#

Thanks I’ll look at Wild West

#

Is there ways to network other than conferences

vocal ridge
#

what word am I thinking of:

frail rapids
#

What projects are y'all working on?

radiant jacinth
#

no real projects. just a lot of self learning stuff

mighty echo
#

Hey @quaint basin how did you find cyberfirst?

quaint basin
#

Huh?

mighty echo
quaint basin
#

Eh? chceyes

mighty echo
#

@burnt night ^

burnt night
#

Might have mixed it up

odd acorn
#

I did it around 4 years ago

#

Loved round one, round two sucked

mighty echo
#

How did the rounds work?

#

How did you find the general experience?

odd acorn
#

As a non-ctf player, I loved it

#

Rounds worked like this:

  • Complete a series of tasks, (there's around 27)

Each task is 1 point, if you place x on the leaderboard then you go onto the second round

#

The second round was less hacky and I didn't understand it so I gave up

cursive marlin
weary haven
#

Is CyberFirst the same as CyberStart ?

red rampart
#

Hello 👋 i have a small question for the people who are working with pentesting and got the job through certification and not through "targeted" university studies. What certifications in pentesting did you have to get your first dream job? 🙂

torpid veldt
#

OSCP/OSEP got me my first (and current) pentesting job

radiant jacinth
#

Oh damn. The OSEP is one I want to get in the future. It looks tough tho

radiant jacinth
cursive marlin
unique bolt
#

Spoooky

zealous crater
#

i need to access to room become private ?

#

how cam i do this

#

this room is allow for another ?

burnt night
zealous crater
zealous crater
zealous crater
burnt night
#

That's for an event that ended a long time ago.

#

That event is not running any more. You do not need to access it.

zealous crater
burnt night
#

What do you mean?

zealous crater
#

alternative to access a private programs by tryhackme

burnt night
cosmic sparrow
#

why chat dead bruhh

frail rapids
#

Is OSWE better than OSCP when you're doing software testing?

#

I'm honestly kind of on the fence between OSCP (due to it's rep), OSWE (due to web pentesting) and OSED (due to binexp)

#

In OSCP I will probably only learn AD, in OSWE I'll probably DOM-based XSS and in OSED I'll probably only learn Windows SEH

#

and I'm kind of in doubt what will be worth most

scarlet moth
quaint basin
#

OSCP will do the most for hiring for the majority of junior positions.

frail rapids
#

I think it could be true

quaint basin
#

Then don't bother taking them -- these courses designed to make professionals into experts clearly ain't worth it if you are already at that level 🤷‍♂️

#

OSCP is the one with hiring power

hasty void
#

@frail rapids working internal pentest

#

is anyone experiencing everytime running dirsearch command saying that need to update pythong to 3.7 or higher but i updated to 3.8 still not working

hasty void
#

@quasi turtle python3: can't open file 'dirsearch': [Errno 2] No such file or directory

#

I have updated python to V3.8 command sudo apt-get install python3.8
I have pip installed dirsearch
I also done sudo apt-get update
still not updated python version still out dated
~# python3 --version
Python 3.6.9

quasi turtle
# hasty void I have updated python to V3.8 command sudo apt-get install python3.8 I hav...
#

you probably have to set your default python version to 3.8 first

#

its helpful to verify here too btw, then you can make a screenshot of your terminal and post it here 🙂 easier for others to help you debug

#

!docs verify

deft fossilBOT
spark sun
#

This can be a complex issue to debug, and very carefully read that link dolphin provided.

hasty void
#

I have updated and installed new version to python 3.7 as below

sudo apt-get install python3.7

install successful

root@ip-10-10-71-220:~/dirsearch# pip3 install -r requirements.txt

root@ip-10-10-71-220:~/dirsearch# python3 dirsearch.py -u 10.10.103.41
Sorry, dirsearch requires Python 3.7 or higher

root@ip-10-10-71-220:~/dirsearch# python --version
Python 3.6.9

Running the above command to check the version , python version is not upgraded

root@ip-10-10-71-220:~/dirsearch# python3 dirsearch.py -u 10.10.103.41
Sorry, dirsearch requires Python 3.7 or higher

Also changed update-alternatives --install /usr/bin/python python /usr/bin/python3.7 2

Also changed update-alternatives --config python
and manually selected *3

0 /usr/bin/python3.6 7 auto mode
1 /usr/bin/python2.7 1 manual mode
2 /usr/bin/python3.6 7 manual mode

  • 3 /usr/bin/python3.7 2 manual mode

root@ip-10-10-71-220:~/dirsearch# python --version
Python 3.7.15

still getting error, cannot run dirsearch.py

frail rapids
frail rapids
quaint basin
frail rapids
#

Because I don't think I wouldn't be rejected if had no provable experience

tawdry dove
#

Knitpicky but certs aren't experience.

#

They are an addition to your professional experience

#

I'm also not sure why we're hashing this out again. I thought we had gone over this and the companies that you were talking to told you they would be willing to offer you an internship. However, they said at the current moment you were too young. Am I misremembering?

quaint basin
# frail rapids What would? That I want to have certs in topics to prove I'm experienced at thos...

A) as Moose said, there's a big difference between knowledge and experience. Technical knowledge is awesome, but being able to apply it in the real world is a completely different thing. There is no equivalence.
B) because you're wanting the letters after your name, not the knowledge.

Which leads on to the last point, that you have somehow got it into your head that they have nothing to teach you. The absolute height of arrogance -- there is always something to learn from others, even if you're already an expert in the topic (which, as a side note, I can absolutely guarantee you are not).
Think this came up a few months ago, did it not? Attitude is everything. No matter how technical you are, companies need people who can play well in a team and aren't abrasive.
As an fyi, "I don't think these advanced level certs have anything to teach me" from anyone who doesn't have some pretty serious accomplishments behind them is pretty dang abrasive lmao 🤣

south inlet
#

They really said that?

quaint basin
#

Put it this way, I've gone into AWAE knowing "everything on the syllabus" (yes, including DOM-based XSS kekw ), but I have still learnt an unbelievable amount from the course

south inlet
#

Ouch.

#

They'd probably pass it first time if they're that confidant.

quaint basin
#

Or have a very rude awakening... if there's one thing that Offsec exams are very good at, it's chewing up arrogance and shitting it unceremoniously on the floor

south inlet
#

Oh, I've heard about that 😂

frail rapids
odd acorn
#

Maybe Kevin can seeing as he doesn’t do much around here.

serene trench
#

I'm glad someone else said what I was thinking re. lazy bones Kevin

south inlet
#

Who's Kevin? 😂

spark sun
#

Also, your attitude is absolutely a disqualifier if I was running your interview.

radiant jacinth
#

"a wise man knows that he knows nothing"

radiant jacinth
frail rapids
#

Does anyone know how I can spoof DNS to the IoT device in the following context:

  • IoT dev which I cannot influence
  • IoT dev through router using wifi
  • router only has DDNS and DHCP (which can be turned off)
#

I can't change /etc/hosts on the IoT device since I do not have a shell

#

a friend suggested that I could set up my own DHCP server and a DNS server, in which I would use DHCP to tell the IoT device to use the nameserver of my DNS server

#

but it's sounds very complicated, and there has to be a better way, right?

burnt night
frail rapids
#

ah alright

frail rapids
#

I set up bind9 with dhcpd

#

Considering it's an exploit, I'm wondering if there really ain't easier way for dns spoofing so that I can just make a python script with the exploit

mortal venture
#

anyone know any good places to look to setting up a small home server? I know the whole "get a cheap pc, install proxmox and configure a nas" but im looking for more detailed info if anyone can help or know a discord server dedicated to this

spark sun
#

Depends on what kind of server you are trying to set up. That's a really broad topic the way you have described your goal

tardy orchid
#

What do modern web applications use for waf? Mod security was very common before 2018. Is mod security still a thing?

mortal venture
silver flicker
#

Anyone want to study cyber sec together? Moore towards blue team side. Just thought would be cool to have a study partner or set some goals together. Right now, I'm active on btlo, cyber defenders and trying back tryhackme

silver flicker
#

Awesome dude, I just DM you

radiant jacinth
#

Damn I see someone having attitude with mother Junn smh

warm peak
mortal venture
warm peak
mortal venture
#

Yes it can draw a bit of power right now. Even my current high end pc runs almost 24 7 haha i should work on that a bit

warm peak
mortal venture
#

Thank you so much 🙂

last sequoia
#

anyone know if theres a chance of the workspaces feature eventually being made to work without needing to be part of a business/school email? id be interested in doing stuff with it with some friends

odd acorn
radiant jacinth
radiant stag
#

Hello

dense cedar
hasty void
#

Hi, I have used free proxy IP on proxychains kali, but I can't get through, does that mean it's dead proxy or is it not configuredd correctly

#

restarted tor

#

still not working webpage

radiant jacinth
#

it could be that it's dead or unreliable, yeah

#

happened to me quite a bit

hasty void
#

@radiant jacinth is there any way we can test them before I add them into proxychain

radiant jacinth
#

not that i know of AFAIK

hasty void
#

like run ping test

#

I have read a post somewwhere, saying that free proxy is not good idea to use them

#

what site do you use for proxy

#

I use proxyscraper

burnt night
hasty void
#

it's just practice task need to complete

burnt night
prisma roost
#

Is this the library? SHH

dense cedar
#

Exactly, slow and more sophisticated convo

wispy pollen
#

why is this quiet?

south inlet
wispy pollen
#

mhm

pseudo zealot
#

hey my pc is with i7 7800X and surprisingly its a 4 user desktop like its with 4 monitors but every monitor acts like a different desktop, i gave each core 2 4 monitors while remaining 2 cores for the background process. it was working well until i upgraded my RTX 370S graphics diver. Now only 2 desktops show display while other 2 cannot be used

#

all it says is user limit reached

#

i tried different ways but it aint fixin

#

any solutionsme and my team were makin a game

#

and only 2 desktops are workin due to which our project is gettin delayed for a month

glad bolt
#

try troubleshooting or if not can you elaborate more on this problem bro?

tawdry dove
pseudo zealot
#

i am in college not school bro i am 18

tawdry dove
#

Not your bro

dapper quartz
#

anyone here for koth friendly match

radiant jacinth
burnt night
pale quest
#

hey ninja

#

iam a little bit stuck

burnt night
pale quest
#

ok

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @burnt night

radiant jacinth
#

There is also 6TO4

dim galleon
#

Can i get 250 cinstant fps in cod r with Nvidia GeForce Gt 620 64bit 1gb?

#

Or with AMD Firepro v3900 1gb 128 bit?

tawdry dove
#

Those cards are over a decade old

dim galleon
#

Any good card in low price? Cuz i cant affor

#

I just need 250 cons fps for cod4

tawdry dove
#

I don't know why you need 250fps

dim galleon
#

At 1280x1024

dim galleon
tawdry dove
#

Not sure if there is a max, but will it even matter with the monitor you're using

dim galleon
tawdry dove
#

That's resolution, not refresh rate

dim galleon
#

Recommended is 60

spark sun
#

having 250fps doesn't do anything for you if the monitor is a 30hz max rate.

tawdry dove
# dim galleon Recommended is 60

Your best bet is to get your hardware specs and then do some research on your favorite search engine to find the card that works best for you.

dim galleon
#

Well any good gpu 64 bit in low price?

#

1gb or 2gb

tawdry dove
#

It's region dependant

#

You're going to need to search yourself

dim galleon
#

Well ty

flat hound
#

bro when did the sec+ test increase in price

#

shouldve taken that shit a year or two ago when it was only 240 smh

radiant jacinth
burnt night
# dim galleon 1gb or 2gb

VRAM doesn't influence performance like you think it does.
GPUs don't have 32/64bit, they have memory bus width but that's very different.

pale quest
#

hello

wispy pollen
#

hello

visual zenith
#

hi

left harness
#

Hi

quasi urchin
#

hello there

carmine portal
#

hi

jolly quarry
#

general kenobi

pure moss
#

two sauce...

unique bolt
#

2 sauce

mortal venture
#

Anyone know amy good alternatives to cuckoo?? It seems to only run on python 2 but installing it is seemingly impossible as py2 has reached end of life

#

Looking to do some malware analysis and im a newbie. Ill look at the thm site when im at my computer again to see if theres any examples

mortal venture
visual rose
thorny sleet
#

hi

frail rapids
#

btw

#

should I contact customer support or so so thm can take it over?

amber karma
twin ridge
frail rapids
#

just had to point it to thm :p so I sadly couldn't setup a phishing site (/s)

south inlet
#

Why would you even joke about that? kekw

odd acorn
#

I mean you can email but I’m sure that if THM were interested they would have bought them. Regardless I’ll still ask

frail rapids
#

ahh okay

#

I just want to prevent that someone sets up a phishing site lol

odd acorn
#

Hey @frail rapids mind if I DM?

frail rapids
odd acorn
#

Awesome thanks

twin ridge
sharp whale
#

Hey would anyone mind helping me please. I'm trying to type in an attackbox but nothing is entering. I'm on the Operating System Security module and I'm on the task where I have to input the user's password. I can type everything else up until this point. Any suggestions?

rustic heron
iron citrus
sharp whale
#

Its on the website tryhackme, I am trying to complete one of the tasks but I can only type on the attackme box up to a certain point.

#

I can click enter but when I do that it says the password is incorrect, but then I try to type a password in and the words are entering on the screen

sharp whale
#

Thats what I am trying to do. I noticed that I'm running into the same problem outside of the website. I am using virtual box on Kali linux and I can't type the password either

iron citrus
#

For example:

Username: root ---> You will see this on your screen
Password: root ---> You won't see this on your screen but the system would know what you have typed

Tap enter as normal and you will log in.

sharp whale
#

Okay thank you guys so much. I was really confused. Thought something was wrong.

undone kelp
#

Hi guys, I hope this is the right place for that (correct me if I'm wrong :O)

I wanted to share with you a new tool that I’ve been working on regarding the automation of finding privilege escalation vectors!
The tool is called: minum for Minimal Enumeration Tool.
https://github.com/nirzaaa/minum

This enumeration for privilege escalation tool, unlike many others, is built towards the idea of finding the top most relevant privilege escalation vectors for its user.
The idea is to prevent throwing a lot of things at the user and let him begin searching for a needle in a haystack.

Instead, it will ask you for your preferable routes throughout its running and will present to the user only the interesting stuff.
Letting you spend more time on exploiting and less time on reading tons of text all over the place.
At the end it will also load for you linpeas.sh automatically in case you want an in-depth lookout.

Your opinion is important to us! so feel free to:

  • Star up the repo if you found it useful 🤩
    And of course share with your colleagues 👨‍🎓 👩‍🎓

  • Or leave an idea for modification down below or at the Issues section on the repo 🤔

We will be glad to make modifications so there will be a great privilege escalation automation lightweight tool out there!

Cheers!

weak radish
#

I am trying to install bluto for python3 from the darryllane repo but its showing
metadata generation error
Does anyone have a solution for this?

#

x

#
sudo pip install git+https://github.com/darryllane/Bluto
Collecting git+https://github.com/darryllane/Bluto
  Cloning https://github.com/darryllane/Bluto to /tmp/pip-req-build-truzw607
  Running command git clone --filter=blob:none --quiet https://github.com/darryllane/Bluto /tmp/pip-req-build-truzw607
  Resolved https://github.com/darryllane/Bluto to commit 25cad7ad532ab0b0f88e8eff89a87e61ed8999cb
  Preparing metadata (setup.py) ... done
Requirement already satisfied: BeautifulSoup4 in /usr/lib/python3/dist-packages (from Bluto==2.4.17) (4.11.1)
Requirement already satisfied: dnspython in /usr/lib/python3/dist-packages (from Bluto==2.4.17) (2.2.1)
Requirement already satisfied: docopt in /usr/lib/python3/dist-packages (from Bluto==2.4.17) (0.6.2)
Requirement already satisfied: lxml in /usr/lib/python3/dist-packages (from Bluto==2.4.17) (4.9.1)
Collecting oletools
  Downloading oletools-0.60.1-py2.py3-none-any.whl (977 kB)
     ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 977.2/977.2 kB 9.4 MB/s eta 0:00:00
Collecting pdfminer==20140328
  Downloading pdfminer-20140328.tar.gz (4.1 MB)
     ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 4.1/4.1 MB 18.2 MB/s 
#

Preparing metadata (setup.py) ... error
  error: subprocess-exited-with-error
  
  × python setup.py egg_info did not run successfully.
  │ exit code: 1
  ╰─> [9 lines of output]
      Traceback (most recent call last):
        File "<string>", line 2, in <module>
        File "<pip-setuptools-caller>", line 34, in <module>
        File "/tmp/pip-install-00w7ybxd/pdfminer_e18936876e014a1cb31c541884cd8176/setup.py", line 3, in <module>
          from pdfminer import __version__
        File "/tmp/pip-install-00w7ybxd/pdfminer_e18936876e014a1cb31c541884cd8176/pdfminer/__init__.py", line 5
          print __version__
          ^^^^^^^^^^^^^^^^^
      SyntaxError: Missing parentheses in call to 'print'. Did you mean print(...)?
      [end of output]
  
  note: This error originates from a subprocess, and is likely not a problem with pip.
error: metadata-generation-failed

× Encountered error while generating package metadata.
╰─> See above for output.

note: This is an issue with the package mentioned above, not pip.
hint: See above for details.

rugged frigate
radiant jacinth
#

/s btw, in case I get bum rushed by an admin telling me I can't joke around about this kinda stuff

odd acorn
#

gotem

odd acorn
#

pip2 install module or python2 -m pip install module

frail rapids
#

Personally I like pythonver -m install better

#

But that's coz I don't use venvs and just link symlink arbitrary python versions to path

#

e.g. python3.5, python3.8, python3.10, etc

#

and regular pip install only works for the python in path iirc

radiant jacinth
#

Hi guys i am wondering what’s the best cybersecurity certificate for employment

twin ridge
#

Depends on what you want to do

iron citrus
radiant jacinth
south inlet
#

I wouldn't do Malware analysis as a "newbie"

radiant jacinth
#

is hashlib the only module in python3 for hashing ?

mortal venture
tawdry dove
# mortal venture How else would i start without starting

In a controlled classroom environment as an example. You can do a large amount of damage relatively quickly without taking the proper precautions and preparations. It's also why it's a topic reserved for the advanced channels.

mortal venture
#

Hm im not in a class so not sure how i would do that

radiant jacinth
#

there are courses and resources out there that walk you through the safe ways of doing so

signal hull
iron citrus
#

Personally if your new to cyber security as a whole malware analysis is much further down the line you need to learn the basic first and lay a foundation for you to specialise off first. Malware analysis would be way to much to soak up for a new person.

polar torrent
#

Hey can I have some help on this hydra kali ?

#

i kept on getting false positive passwords

rugged frigate
frail rapids
#

I started at a new (hopefully long time) position today

#

it's basically a combi of security engineering and anti cheat but for non-videogames

#

I feel like I'm going to learn a lot about low level software integrity

jovial yoke
hoary nymphBOT
#

Gave +1 Rep to @jovial yoke

lime sparrow
#

hello

candid tartan
lime sparrow
#

anyone have their sec+ cert?

tawdry dove
frail rapids
rare delta
#

Hello, i hope i am asking in the right channel. I am in the final year in university in CS and i have to do a final project, i want to do one related to cybersecurity in order to learn more about it, but i am not that experienced, just less than 1 year of experience. I was thinking of making a WAF or a website vulnerability scanner, but maybe someone has a better idea, can you help me pick a project? Thank you!

south inlet
#

Do what you feel comfortable doing.

twin ridge
rare delta
#

Sure, got it. As i said i am not that experienced and just wanted some advices regarding which direction i should go so i can choose a project i will be able to do and also good for learning, but i will try to choose something by myself. Thanks!

twin ridge
#

keep the scope precise, don't branch off too far

#

get an MVP out before adding features

#

track your issues/stories like a real software project. that'll help you decide what to inevitably cut later 🙂

ripe haven
#

@faint island hey! May I DM you?

faint island
ripe haven
hoary nymphBOT
#

Gave +1 Rep to @faint island

light blaze
#

are the like some codes here that we can download or we just go the links that are already provided and learn there?

radiant jacinth
#

i'd like to ask something..is there any problem with the site?

warm peak
#

Yes, staff has aknowledged and are aware of the issues and will fix it asap, sadly they do not have a timeframe of when the site is back up

radiant jacinth
#

oh understood ! thanks anyways :3

rigid crown
#

Is there any one interested to play ctf with me?

odd acorn
rigid crown
odd acorn
#

Nono I mean which one 😆

rigid crown
#

I need some company so we can play together

#

Hahaha, nothing bruh just needed some to play with, u know it’s better that way

#

Someone *

sudden viper
#

PicoCTF is good

rigid crown
#

@sudden viper i can find a team members on it?

sudden viper
#

They have teams and stuff yeah

signal hull
#

I would just go join whatever CTF you want to do, and if they have a discord for the event, there's likely a team-recruiting channel where you can find people to play with

eager aurora
#

Thoughts about scratch or x code

burnt night
#

They're quite different, what sort of thoughts are you looking for?

visual rose
vocal ridge
#

Virt-Manager's key grabber stopped working and I'm not sure what's happening, heh..

It started after updating Fedora

#

Is this a RHEL conspiracy 😅

spark sun
#

key grabber?

vocal ridge
#

what's it called..

#

"disable hotkeys"

#

Spice agent

spark sun
#

systemctl enable --now vdagent-spice && systemctl enable --now qemu-guest-agent

#

to enable smarter guest tools; IIRC hitting both control keys at the same time unlocks mouse and keyboard from vm

vocal ridge
#

yeah the problem was just the opposite. couldn't use hot keys on guest

#

only mildly frustrating

#

well I guess I don't have VD agent that might be the problem...

#

I wonder what happened with that.

spark sun
#

Be sure to look it up; i sometimes get names turned around. Might be spice-vdagent

#

if this is running a kali guest, there is a known bug with XFCE where the screen will not auto-resize with the guests installed

vocal ridge
#

yeah, it's spice-vdagent. That's very strange it's not on here

surreal kite
#

Any CTFs happening?

spare fossil
#

Hii

fallow frost
#

can anyone suggest some interesting tools for steganography apart from steghide, binwalk and sonic-visualizer

twin ridge
#

Those are the main ones

mighty echo
#

Hey @quaint basin I was wondering if your avaliable to quickly help me out here on trying to use SSH tunneling 😅

#

Tryng to achieve something like this, James reccomened to port forward the remote listener to my local tablet (remarkable), then connect to that loopback listenerwhich im trying to do now but having struggles

#

This is the command being run on the tablet

reMarkable: ~/ restream -h 1872 -w 1404 -b 2 -f /dev/shm/swtfb.01 --listen 1234
[rM] listening for a TCP connection on 0.0.0.0:1234

Port forwading

ssh root@<SERIP> -R 1234:root@<SERIP>:1234 -N
#

Then on the server im running

nc 0.0.0.0 1234
#

But it immidatley quits, not sure why

#

what I currently have

quaint basin
#

Like, I can see that it's netcat, but all I can find only for restream is video editing

mighty echo
#

rawvideo bytes is the output from the binary

quaint basin
#

At a guess based on that I would say that restream expects some layer 7 protocol or another when connecting, or possibly a constant stream of information?

mighty echo
#

On my local network this is what I would use

#
nc 10.11.99.1 16789 | lz4 -d | cat | ffplay -vcodec rawvideo -loglevel info -f rawvideo -pixel_format rgb565le -video_size "1404,1872" -window_title rm -i -

For connecting to the listner *

#

Where 10.11.99.1 is the tablets IP

quaint basin
#

And on the tablet the same command?

mighty echo
#

Yup exact same command

#

restream -h 1872 -w 1404 -b 2 -f /dev/shm/swtfb.01 --listen 1234

#

The problem im facing is trying to use a remote server instead of my PC

quaint basin
mighty echo
#

If your wondering, I've tried using a VPN but the device is on an archietecture/ kernel that doesn't support any (doesn't have tun moduel)

mighty echo
#

If you don't specifcy an listern itll just immidatley send all the rawbytes to the stdout

mighty echo
quaint basin
#

Perfect, yeah

#

Okay, only thing I can see that's unusual about your ssh command is the root@ in the middle

#

-R 1234:127.0.0 1:1234 should forward the remote 1234 to your local 1234

#

Try dropping the -N so that it actually creates a session. Check that the port is open then just do a nc call and response rather than using restream?

#

If that works, great

mighty echo
#

Okay, so that would be using nc 0.0.0.0 1234 on the server correct?

#

if I use
nc 0.0.0.0 1234 on the server
and
ssh <serverIP> -R 1234:127.0.0.1:1234 on the device
The nc is still running instead of stopping, I presume that means its connected right?

quaint basin
mighty echo
quaint basin
#

Try starting a netcat listener on localhost 1234 on the tablet then connecting to it on the server with nc 127.0.0.1 1234

#

If that works then what you type into one should come out of the other when you press enter

mighty echo
#

Doesn't have the listener method

#

Restricted

reMarkable: ~/ nc
BusyBox v1.31.1 (2022-08-26 11:00:46 UTC) multi-call binary.

Usage: nc [IPADDR PORT]
reMarkable: ~/ nc -l 1234
nc: bad address '-l'
reMarkable: ~/ 
#

Should I use the restream listener instead?

#

If I run restream -h 1872 -w 1404 -b 2 -f /dev/shm/swtfb.01 --listen 1234 on the tablet and I then run nc 127.0.0.01 1234 too on the tablet, as you would assume the nc does produce the output

#

Is there some setting I have to enable with ssh? 🤔

mighty echo
#

hmm so I did the opposite way round, and this is what happens

quaint basin
mighty echo
#

Get's a connection

#

okay nice, it works the other way round

#

if I type xyz into the RM netcat, it does seem to port forwad it to the remote netcat lisener

#

wait hold on - hacky idea

#

YES

#

holy shit let's goooo

burnt night
#

(Also probably best not to run this as root if you can avoid it)

mighty echo
#

Server side

nc -l 1234

ReMarkable side
One terminal has

ssh <ip> -L 1234:127.0.0.1:1234 -N

Second terminal has

restream -h 1872 -w 1404 -b 2 -f /dev/shm/swtfb.01 | nc 0.0.0.0 1234
#

Sucessfully got the data

radiant jacinth
#

cool

mighty echo
narrow trout
#

Why are you destroying the remarkable Jayy 😄

mighty echo
#

😅 It's so cool experimenting around with embedded devices like it

#

I'm suprised I haven't bricked it yet, I should really get and solder the pogo parts in case that ever happens

mighty echo
quaint basin
#

Nice one!

#

Np 🙂

soft pier
#

????

#

hacking embeded devices of some kind and got data stream????

mighty echo
#

me when I almost leak my IP facepalm

mighty echo
#

as you can uh imagine, the latency isn't too great ha

#

Now I need to make a script to automate all this, having 5 terminals opened all at the same time isn't very helpful! 🤣

narrow trout
#

cool anyways 😄

signal hull
#

tmux is great

#

I used to use terminator until I was bullied was converted to being a tmux user

spark sun
#

To ease the pain of managing nested tmux, i usually use byobu on my primary linux box, and tmux on all my remotes

signal hull
#

ooooooo

#

never thought about that being an issue since I haven't had to do that since adopting tmux but makes sense

soft pier
#

there are ways to handle nested tmux but yeah kinda complicated

frail rapids
#

we should call a wireless mouse an hamster

tawny egret
#

Someone call the ISO

radiant jacinth
#

Shhh

soft pier
#

should we not go through RFC first???

visual rose
radiant jacinth
#

theo

vernal lantern
#

hey guys, so where can i apply the 20% student discount for premium? cant find it

#

changing to my university email did the trick

zinc rock
#

does the student discount apply for uni only or high school students too @vernal lantern

vernal lantern
#

no clue

#

prob university only because high schools dont give out email adresses

stark egret
#

hello

viscid bear
#

hi

radiant jacinth
#

hi

olive frost
# viscid bear hi

Hey, I appreciate that you are saying "Hi", but there is no need to say it in every single channel 😉

quartz ibex
zinc rock
#

ah cool ty

woeful forum
rich flicker
#

Hello, i would like to make a private network with docker accessible with OpenVPN, i can launch the VPN server but the other container are not accessible.
i can't see where i do a mistake. here is bit a of details 🙂 :

  • VM Virtual box bridged adapter (same network as the host) with docker (192.168.1.0/24)
    • openvpn docker network (10.0.0.0/8)
    • openvpn "redirected" network (11.0.1.0/24)
      port are correctly opened, the only thing a manage to do is to add a ssh server to the openvpn one (multi stage build), and access the ssh server thought the vpn ... but other container (with other ip) will not work. let's say i'm connected via vpn to 11.0.1.10 and the nginx is manually added to the same network at 11.0.1.11 it will not be reachable, why ? 😢
rich flicker
#

really, even in the docker network is the same as "redirected" VPN network, the machine can't communicate .. i really get discouraged on this :/

twin ridge
#

did you expose the ports properly?

rich flicker
#

Port exposed properly, with both ports on compose, and expose on Dockerfile

radiant jacinth
#

Callense its quiet shhhh

crisp prawn
#

What is the highest paying cyber security job?

odd acorn
#

Are you asking so you know what to aim for?

crisp prawn
#

no just curios

#

im aiming for pen tester/Red teamer

#

oops

#

curious*

burnt night
crisp prawn
#

what does he do?

scarlet moth
#

he or she is in charge of the cyber security as a whole for the company. This includes managing all the directors under them, setting the cyber security strategy of the company as a whole, meeting with vendors, could include meeting with local / state / federal politicians, and is also the fall guy if there is a major security breach

#

and negligence could include jail time depending...

hoary nymphBOT
#

Gave +1 Rep to @scarlet moth

radiant jacinth
#

Anyone ever use one of these gigantic 49 inch monitors? What’s that like ?

errant igloo
#

I'm using 43" 4k tv/monitor and I like it

radiant jacinth
sinful igloo
#

hii

rare delta
#

Hello, can the student discount be used with the aoc2022 code for the annual subscription?

olive frost
rare delta
#

Thanks

viscid bear
#

hi

mighty echo
#

@twin ridge nevermindmay I dm?

spark sun
twin ridge
half shadow
frail rapids
#

what if I use unshielded RJ45 (ethernet) connectors on a shielded ethernet cable?

burnt night
# frail rapids what if I use unshielded RJ45 (ethernet) connectors on a shielded ethernet cable...
hoary nymphBOT
#

Gave +1 Rep to @burnt night

radiant stag
#

hello

radiant jacinth
#

hi

dusk trout
#

Hello, I've literally no idea what this place is and I'm pretty sure this is the wrong place to ask, but I'm hoping someone could at least point me in a good direction.

I have the .iso file of an abandonware game from like 2001. I want to extract its files, which are stored in what looks like an installwizard .cab file. When I tried to open it in Unshield, an open-source extractor for this format, it said it failed to open the file. This file format should have the magic number of ISC(, but notepad shows this file starts with ISc( instead. Manually editing the magic number didn't fix anything, so it can't be the problem.
That's all I know. Does anyone here have any experience with this kind of stuff, if it is even possible, and if it is, how to?

I'd like to emphasize the thing's abandonware

twin ridge
radiant jacinth
#

Ben is just 🥵 yall agree with me?

frail rapids
#

Is it possible to virtualize frame buffer output (to a gnome app)?

#

I want to run fbDOOM but it outputs graphics to /dev/fb0 and uses /dev/console for keyboard

#

but /dev/console only works for me when I'm in the gnome desktop environment

#

and /dev/fb0 gets mirrored to /dev/tty3-6

#

hence, I want to display /dev/fb0 in the gnome environment

radiant jacinth
#

Bella got me like😍

quiet dirge
#

What is a better GLIBC malloc.c security update? (senior capstone google fourms survey )
https://forms.gle/vnRqqMe2WUeqsBhY9

tawdry dove
boreal jewel
#

Can we give them wrong answers?

spark sun
#

Lets not troll

boreal jewel
signal hull
#

it's just a survey, they're not asking for homework answers

ripe haven
#

@warm peak Hey! Any chance I can DM for some help with python?

warm peak
#

you could throw it in #programming if you're okay with having it public

ripe haven
warm peak
hoary nymphBOT
#

Gave +1 Rep to @warm peak

gentle sonnet
#

!notifyme

deft fossilBOT
#

Ok @gentle sonnet, you will now be notified of future announcements.

solar rune
#

Hey

calm hearth
#

!notifyme

deft fossilBOT
#

Ok @calm hearth, you will now be notified of future announcements.

crisp wave
#

!notifyme

deft fossilBOT
#

Ok @crisp wave, you will now be notified of future announcements.

timber lantern
#

!notifyme

deft fossilBOT
#

Ok @timber lantern, you will now be notified of future announcements.

oblique trout
#

!notifyme

deft fossilBOT
#

Ok @oblique trout, you will now be notified of future announcements.

sonic sail
#

!notifyme

deft fossilBOT
#

Ok @sonic sail, you will now be notified of future announcements.

quiet dirge
#

Just carious what people think thats all

#

heres the respones so far

#

Here's the context of how this all started

#

People can find my name on my website I have in my bio so I'm not worried about dox'ing myself

radiant jacinth
twin ridge
#

So basically scrap it and do it properly

twin ridge
quiet dirge
#

I'd rather not though :/. Just style differences nothing is spelled wrong.

zinc rock
#

question about CISSP: I read it needs 5 years of paid working experience, however a uni degree counts as one year.

#

and these certs also count for a year, but Im wondering, does it stack?

#

will each cert you get count for another year of work experience?

tawdry dove
#

No

#

Education can only count for 1 year

zinc rock
#

ah ok, I see thx

tropic tapir
#

!notifyme

deft fossilBOT
#

Ok @tropic tapir, you will now be notified of future announcements.

verbal coral
#

!notifyme

deft fossilBOT
#

Ok @verbal coral, you will now be notified of future announcements.

quasi river
#

Hello everyone! you don't know me and I don't know you, I am in the 495th position of the global ranking and until a few days ago I had almost 450 days in a row. Today I want to share a message with you: No matter how busy you are, no matter how stressed you are or how angry with life you are, today I want to lose my streak and send you the message to please invest time in yourself, your friends, your pets and most of all in your family because they will always be there for you. My grandmother always took care of me and today I want to take care of her more than anything else in the world. The message I want to give is to always be with your close people. Thanks a lot to @deft fossil because I have learned a lot of things in these almost 2 years from the community and the whole team. Greetings from Mexico

radiant jacinth
flat forge
hoary nymphBOT
#

Gave +1 Rep to @quasi river

autumn trout
#

Ansible:

 jinja2.exceptions.UndefinedError: 'ansible.vars.hostvars.HostVarsVars object' has no attribute 'token'

My code https://github.com/bee-san/ansible_scripts

Any ideas? It worked the first time, the token i believe is meant to be the kubernetes master token for this:

ExecStart=/usr/local/bin/k3s agent --server https://{{ master_ip }}:6443 --token {{ hostvars[groups['master'][0]]['token'] }} {{ extra_agent_args | default("") }}
#

or any ideas on how i can begin to debug this? i have exhausted google :/

spark sun
#

Would need to see the structure you are keeping your hostvars in

autumn trout
autumn trout
spark sun
autumn trout
autumn trout
#
fatal: [192.168.0.242]: FAILED! => {"changed": false, "msg": "Unable to start service k3s-node: Job for k3s-node.service failed because a fatal signal was delivered causing the control process to dump core.\nSee \"systemctl status k3s-node.service\" and \"journalctl -xe\" for details.\n"}

One step closer, annoyingly this node doesn't appear to like k3s much -- I have even re-flashed the SD card 🤔

Dec 03 21:20:18 raspberrypi-2 systemd[1]: Failed to start Lightweight Kubernetes.
░░ Subject: A start job for unit k3s-node.service has failed
░░ Defined-By: systemd
░░ Support: https://www.debian.org/support
░░
░░ A start job for unit k3s-node.service has finished with a failure.
░░
░░ The job identifier is 2531 and the job result is failed.

From JournalCTL

#

Aha! It is not the same model, one of them is an RPI 2 B and the other is an RPI 2 B+

#

I'll play around with that github ticket but if it doesn't work I might switch to a Pi Zero W 😬 I reckon it could handle being a worker node and some small pods 😄 (alternatively I actually get my desktop up and running and turn that into a node....)

serene trench
scarlet moth
serene trench
#

?

#

this is like the 3rd time and its getting kinda weird ngl

radiant jacinth
#

Oh my bad I'll delete it

#

I just mean like you a great mod and all

serene trench
radiant jacinth
#

Oh that's just jokes my bad

serene trench
#

fair

iron ruin
#

🤡

signal hull
#

Been a while since I’ve done any boxes on THM? Is there an easy box that’s good to demo to a group of people that has a path that isn’t just file upload -> PHP web shell -> GTFOBins? (Also free to access)

odd acorn
#

Overpass

tidal dune
#

far

radiant jacinth
#

Jalapeñi wisdom

haughty bone
#

test

brave plover
#

Hi, anyone to help me with 2 PCAP files, please?
I have to specify the attack type, what happened (cve, exploit). I would like to get some tutoring and help to get through it.

tawdry dove
#

Or is this for homework

brave plover
#

it is hw

tawdry dove
#

Sorry, but we cannot assist you with homework. You'll have to ask your teacher/TA/professor.

brave plover
#

I've found it, it isn't from school, therefore I can't get some help

hoary nymphBOT
#

Gave +1 Rep to @tawdry dove

radiant jacinth
#

Start from some basic packet analysis and wireshark course then before you jump up into investigations like that.

#

Wireshark 101 book by Laura Chappell is a great intro, and you can get it used for really cheap.

#

Also check intro threat hunting courses, like one from Active Countermeasures, but they assume you are quite versed in linux and networking.

brave plover
radiant jacinth
#

You cannot take shortcuts in this field.

brave plover
radiant jacinth
#

You also need extensive knowledge about attacks and what they do in the network to be able to recognize them in packet capture.

#

Yeah, it should be fine to start with.

#

SBT also opened their intro courses - they are free now, and some basic intro to packet analysis is there.

#

Start from simple things. Then you can grab more and more complex public pcaps for practicing analysis.

brave plover
#

Thanks for replies
If I can ask you: the first pcap file is about MITM NBNS and SMB is used.
I theoretically know what it does, but I don't see those processes in individual logs.
so, you still recommend me to go with that starting course you mentioned, yes?

#

to be able to solve this kind of task

radiant jacinth
#

knowing what something does and being able to catch it during investigation are two different things. Yes, you need to learn to see it in pcaps.

#

There are no shortcuts, sorry :D

brave plover
# radiant jacinth There are no shortcuts, sorry :D

yes, understand, but I've maybe incorrectly express myself - I do not want to take shortcut
I've just wanted to do it with someone who is able to explain me things "in practice/practically " and I'd be able to learn and get that thing done

#

and maybe give me some good suggestions what to do or don't while analysing

radiant jacinth
#

You need a tutor then maybe, who will teach you 1:1. But still, first you need to learn to read normal pcaps, then you need to know what certain attacks do in network to be able to recognize them it in pcaps, then you need to learn to differ malicious traffic from non-malicious. It is not something you learn during one meeting with a person. What is your current state of knowledge in this matter? Can you recognize traffic generated by certain protocols? Do you know basics of packet analysis? Are you proficient in using wireshark?

#

If you are looking for general advice: you need to be very detail oriented, pay attention to unusual traffic behaviors, and do not guess - confirm everything.

brave plover
#

again, thank u for ur time, gn

toxic fiber
#

Hi, is anything wrong with the room? My whole progress disappeared and shows me 0% - did solve yesterday and was at 100% in the evening

green wing
toxic fiber
hoary nymphBOT
#

Gave +1 Rep to @green wing

green wing
#

All good, i was the same hahaha

toxic fiber
#

and wrong channel, but again, thanks 🙂

barren relic
#

Hello i Complete 4 labs in advent of cyber today i start 5 th lab solving then i see my all 4labs are not solves how ?

twin ridge
#

it's a bug

#

it's being worked on

barren relic
#

means again solves all labs sadcooctus

twin ridge
#

maybe, maybe not

simple zealot
#

Hi

simple zealot
unreal eagle
#

All the progress i made is gone now

#

what to do

#

The page is showing this"Uh-oh, this page has been lost in the matrix."

scarlet moth
#

if you do the exercises again, you'll get more points

radiant jacinth
#

Omg its Mother Zojja

#

So basically it's a we don't know how to fix it but sorry for the inconvenience?😭

#

I love it💙 it's more fun that way gonna go redo them lmao

radiant jacinth
#

How have you become professional in osint?

radiant jacinth
# radiant jacinth How have you become professional in osint?

Well I do OSINT for a living full time. Can't say much about the job itself but by background would be I took a course by TCM and did some tryhackme Ctfs and learned from different resources as well such as TraceLabs eventually I applied to a company near me who was looking for someone to do OSINT and now I do it professionally.

#

Been doing OSINT since I was about 19-20 back then I didn't know that those jobs were even a thing

radiant jacinth
radiant jacinth
#

Yeah the jobs that need an osint orofession I see why they would be very open

#

Ur a glowie admit it

#

Glowie lol?

radiant jacinth
#

Oh nah lmfao I wish

#

Alright if you say soo..

#

Ugh okay?

#

You have a god day too Prayge

#

Rylussian / china / north korea journalist finder?

#

No.

#

Even if i guess ul deny it so no point have a good day lol

tawdry dove
radiant jacinth
#

Ah lmfao never heard it tbh💀but aww you giving me too much creditKEKWLUL

#

A government pension and having connections like that would be nice but with my juvenile record yeah not happening🤣

#

@radiant jacinth you a fed huh👀

#

I see that pfp 👀 #fed KEKWLUL

twin ridge
#

Please don't advertise here.

radiant jacinth
#

Lmao rip

#

Tag me in the anime thread

#

😭I don't remember where it's at

#

But thanks I could go on for days about Tokyo ghoul

smoky mortar
#

I have deleted your post as it references an external event. 🙂

simple zealot
#

Guys, day 8 isn’t posted yet right?

desert helm
#

Doesn't appear to be.

echo dust
rain vector
#

Are you doing AoC?

#

It's not!

#

I'm a total beginner.

#

Each day has a lesson that walks you through what you need to know (more or less, there's been a couple of things that tripped me up, but there are hints.) There's also a video walkthrough for each day and the people explain everything even more than in the lesson. I would say the only prerequisite, kind of, is some basic computer knowledge.

#

You should be good. I'm a MySQL database guy and know some coding and networking basics, but not really enough to actually do anything 😆

#

You too! happy hacking 😄

radiant jacinth
#

!notifyme

deft fossilBOT
#

Ok @radiant jacinth, you will now be notified of future announcements.

echo dust
#

!notifyme

deft fossilBOT
#

Ok @echo dust, you will now be notified of future announcements.

serene trench
scarlet moth
#

Seriously

radiant jacinth
#

Preach Prayge

waxen sage
#

Anyone else ever open THM and just stare at the screen for a while until realising your brain noped out?
If so, what do you do on those days? 1 simple question for the streak and try again the next day?

signal hull
#

I would go do something and then come back after a little bit, or just go look into a different topic or project altogether. It's okay to need a little bit of a break from things, but I also think you can't rely on motivation all of the time. There's a difference between burnt out and "I don't feel like doing this right now".

#

It's fine to feel like you don't really want to do something, but repeatedly feeling that way oftentimes can just be laziness, but it's really up to you to be introspective and understand why you're feeling that way.

waxen sage
#

I mean, like paying attention to the content is hard so except for easy text answers you just stare at it. Maybe can follow step by step directions but brain just 404s when anything doesn't match up perfectly... probably means nothing is retained from the step by step tasks anyway.

vocal ridge
#

I get that way sometimes. For me it's "I don't want to do this right now/ Been going for too long" or "I don't fully understand the material"

#

either way, I just walk away for a while, Don't think about it (too much), then just ease back into it, later.

signal hull
#

It's just something you'll have to figure out for yourself.

#

As far as following directions go, you're not learning anything by copying and pasting commands or following the tutorial to a tee. Critically look at everything you're reading and ask yourself how and why things work. For instance, do you really understand why a php reverse shell works the way it does, or are you just taking it for granted and moving on?

#

It's okay to not try and figure out every single detail, but skill comes from understanding.

rain vector
#

when i get that way, i know it's time to take a break, tbh. get a good night's sleep, eat a healthy breakfast and try again tomorrow. brains need a break and are not made to be productive 24/7, so if you're not really interacting or retaining anything then don't push it ❤️

lost terrace
vocal ridge
#

my friend showed me this firMelt

waxen sage
#

that is amazing
and oddly fitting for this convo

cursive marlin
#

I hope thats a joke😂

vocal ridge
#

I hope it's a joke lmao

cursive marlin
#

Nahhh there is no way a coffee machine can lease out dhcp

#

Does the coffee machine have a domain controller inside?😂

vocal ridge
#

I hope not.

#

If they do, we might have bigger problems.

#

Coffee Kerberos. You can't login without brewing a pot.

cursive marlin
#

😂

spiral mauve
#

💀

burnt night
#

!rule 9

deft fossilBOT
#

Rule 9: No discussion of illegal/unethical topics or actions. If the target device doesn't belong to you and you don't have specific permission to perform an attack from the owner of the target, then you don't do it and we don't talk about it. This also applies to piracy / copyright violations -- illegally obtained materials (including classified or potentially classified materials) should not be posted here.
If in doubt, please ask a moderator before posting your message -- preferably without breaking rule 1. Whether an action is unethical or not is at the sole discretion of the moderation team. Be warned -- a community ban over ethical concerns may also be extended to a ban from the TryHackMe website; we do not teach blackhats.

burnt night
#

@frail rapids This includes discussion of illegal actions.

frail rapids
#

How exactly does DNSSEC prevent spoofing? can't the DNSKEY be spoofed as well?

#

unless the DNS client has some sort of DNSKEY stored in the OS by default

radiant jacinth
lost terrace
frail rapids
#

looks like the devs forgot to sledgehammer the DHCP modules out of the OpenWRT installation

frail rapids
#

What's y'alls opinion on the wifi pineapple? worth a buy?

waxen sage
frail rapids
#

participated in the last ones with membership

#

haven't won anything besides stickers so I don't bother tbh

burnt night
rain vector
#

I have a question. My parents asked me what I want for the holidays and I'm not sure what to say because I'm an adult and buy myself what I want heh. Are there any items that might be cool to have as a total n00b to hacking? (I already have a subscription to THM and a giant stack of books to read 😉 )

vocal ridge
#

very important to have clean socks

quaint basin
#

Alcohol

rain vector
#

Lol, I am sober and have a nice chair. And more socks than one human could ever need 😅

#

Was thinking more if there's a fun gadget type thing. That's not a raspberry pi because I have one of those too 😅 I think I am hard to shop for 😅

waxen sage
rain vector
# waxen sage Anything you want to do *with* them?

Well, my folks live in the next building over (we're in the same condos) so I see them all the time. I would love to help them get their hoard of stuff to list on ebay actually listed on ebay LOL, that would be a gift to me because I'm tired of hearing about it/seeing it 😅

waxen sage
#

That might be worth asking about. Or some adventure in the area.

radiant jacinth
rain vector
hoary nymphBOT
#

Gave +1 Rep to @final basin

burnt night
#

Learning to solder is a good skill

bold jacinth
#

a

spark sun
rain vector
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
rain vector
burnt night
#

I've got so much use out of it, even surface mount which I'd never done before.
Been doing some retro computer stuff and it's super convenient

rain vector
burnt night
#

I've got the normal conical, a small wedge type one, and a super fine conical. If you're just doing through hole stuff you'll probably be fine with the standard conical

#

If you're doing surface mount then it's handy to have something smaller but I was doing OK with the standard conicsl

rain vector
#

awesome! thank you for all the info 😄

burnt night
#

I'd also recommend a flux pen, and some thin leaded solder. Please do your own reading about leaded vs unleaded solder - lead is not good for you.

rain vector
#

thank you! i will research that.

burnt night
#

Also rosin (a flux type) fumes are very bad for you too. It's a generally hazardous hobby.

rain vector
#

fun times 😄 but thanks for the heads-up on that too. don't want to poison anyone.

serene trench
#

make sure you have good ventilation (active as in like a fan and a window or something) and take breaks from sitting up and close to it

soft pier
#

hmmmm maybe the fumes from shadows school soldering lessons helped shadow get mental health issues

#

it is not like shadow already had been diagnosed with 2 long before they ever soldered for the first time

serene trench
#

I think you need to be more concerned about your lungs with solder 😄

hasty mantle
#

Ok so i need help

#

What do i have to learn to get acces to a Coffee wending machine so that i could trick it to think that i payed and get a free coffe

#

Or what do i need to learn to have acces to electric gates so that i could open or close them

#

I need some help on this

burnt night
hasty mantle
#

Yea

#

Oh its against the rules of the server sr guys

golden night
#

I'm assuming you don't own these vending machines and electric gate system

waxen sage
#

Step 1 is buying the machine so it is yours to test on.

timid ocean
golden night
#

Right never hack a machine you don't own, or have express permission to hack.

echo dust
golden night
echo dust
golden night
echo dust
#

So very true.
Reason I won't own Keurigs anymore 😄
Gave my old 1.0 away to a college kid.

golden night
#

Ugh Keurigs I got an old model before they started requiring a license for the pods, I low key can't imagine the hell that exists with the new models

echo dust
#

Yep, I get the love of the convenience, but the lack of servicability drove me batty.

#

Schematics or die!

radiant jacinth
waxen sage
golden night
rain vector
golden night
#

Last time I did a vinegar rinse wash cycle through it because I thought the inside might be dirty it ended up being completely clean despite it never was properly cleaned for over 5 years

whole pier
#

hey group

odd acorn
tawny egret
golden night
echo dust
#

@whole pier please see #rules with special attention if you would to RULE NUMBER ONE

golden night
twin ridge
#

oh dear

half depot
#

Does anyone know whether “reporting is required” excercises actually count towards the 80% correct solutions for the bonus points in OSCP?

rustic heron
#

Should be only those where you can submit flags that actually increase your progress bars. I guess the reporting required is for the legacy version.

cursive marlin
radiant jacinth
#

hi all. hoping youre having a nice quiet thursday

#

scan the entire /8 or something

civic rootBOT
#

@radiant jacinth has been warned.

burnt night
#

In fact that includes user's own machines.
This is incredibly irresponsible advice and will get you banned from the platform.
It's likely illegal too.@radiant jacinth

burnt night
#

-ban @radiant jacinth Encouraging users to scan the whole THM network. Harassment in DMs when warned.

hoary nymphBOT
#

🔨 Banned Roc Wool#4363 indefinitely

burnt night
#

@twin ridge do us a favour and don't accept that appeal?

odd acorn
#

I’ll happily escalate that to a platform ban to for breaking out acceptable use policy

radiant jacinth
#

man, lotta ban talk going on here

#

ive been wondering these days, anytime you dont like something someone has to say, they just ban them. everyone banning and blocking everyone else.

#

we cant ban or block ppl irl tho

thin juniper
#

we can ban them from society by throwing them into jail and we can block them by plugging IEM-s into our ears, doing a 360 and walking away

radiant jacinth
#

well. not really. you cant put someone in jail just because you dont like them. and i guess you can plug your ears if you want to but i mean... ok

burnt night
radiant jacinth
#

ok

#

i saw a bumper sticker a couple weeks ago that said port scanning is not a crime.

#

made me laugh

thin juniper
burnt night
radiant jacinth
#

ok - cool

radiant jacinth
#

weather is CRAP today man

twin ridge
thin juniper
# radiant jacinth hmmm.... that is an interesting statement

however! ☝️ ! if a lot of people dislike a certain person, they can always just ostracize them.
which is pretty cool!
see, there are 4 main factors that drive people towards being virtuous (meaning not evil/annoying)
1.) being afraid of punished by the law
2.) religious fears - being afraid of being sent to heck upon death if you were naughty in life / not receiving Christmas presents
3.) fear of ostracism - nobody likes to be alone :(((
4.) the rarest and most genuine form of being morally good: actually, honestly wanting to be virtuous, they use their own willpower to be good.
where was I going with this...

radiant jacinth
#

He Cute, I dont think there is much we would agree on in this world.

#

but I respect you and dont think you should be put in jail and or ostracized. hope you have a great day

thin juniper
south inlet
radiant jacinth
#

day # 2.5 of being snowed into a hotel in this tiny town. all roads are closed. cant leave, cant do anything - so its THM classes all day long today

thin juniper
#

Sounds like heaven 😌

rain vector
#

it's frustrating to be trapped but sometimes it's nice when life forces you to take the break and do what you want LOL

radiant jacinth
#

agreed. Medora ND ,,, town is beautiful in the off season and it is absolutely quiet here. like... so so so quiet. been having fun today

radiant jacinth
#

Hello people

polar bison
#

Ahhh, I love quiet place, for they're quite calm

magic estuary
#

We even had a little snow here on the mountains in Kagoshima, Japan...beautiful! 🙂

rain vector
#

Ah jelly, Japan is so pretty and fun

uneven oak
#

icey death-trap on the streets of the toon at the minute, dreadful stuff

past meteor
#

sa

#

türk varmı burda

#

dll bypass yapan

spark sun
past meteor
#

y bro

#

help me pls