#quiet-conversation
1 messages Β· Page 3 of 1
Help you with what? We only allow english language in this server because that is the common language of all the moderators. More languages makes it too difficult to moderate.
what are you trying to do?
i want help
Can you be specific?
What do you want help with?
So to be clear, are you asking for help cheating with a game?
yes bro
Game hacking is against the rules here, it is unethical
Please don't send DMs without asking, that is also against the rules
where can you find what?
It is against the rules here. We cannot tell you where to find resources for doing unethical things.
y bro ty
he left
is a strict password symbol policy really necessary?
like would pentesters/hackers actually change their wordlist based on the policy (e.g. using [a-zA-Z0-9] only), or wouldn't they because it leaves out possible cracks
Only real discriminator is length tbh
guys is it ethical to search for indexes of websites?
only exception to this is if your password is in a super common password dictionary list.... then length is not that much of a factor
Yeah of course, but if you're using dictionary words then at least chain several together
With a random separator
And not use "correct-horse-battery-staple"
Because that's in a dictionary somewhere
shoot now you told everyone shadows passphrase.... time to go change it /joke
Assalamu Aleykum every one
I have one question about Anon Surf tool
What is it vpn or proxy?
It can change ip and address I can't know about it. AnonSurf is proxy server or VPN?
Hope this article helps you
https://nordvpn.com/blog/vpn-vs-proxy/#:~:text=A VPN and a proxy,for extra security and privacy.
where to find rooms and which ones to start as a beginner
assuming you are not a subscriber, this is a good list https://tryhackme.com/resources/blog/free_path
this is awesome, thank you
Gave +1 Rep to @scarlet moth
anyone know how to curl a website with json data? i have curl -X POST -H 'Content-Type: application/json' -d "{JSON data}" but im not getting the flag
Im a solid 90% sure i have the correct syntax but im formatting my JSON data incorrectly so thats an issue ill figure out later I guess
how did you insert JSON data?
I usually use the following and it works for me:
curl -H "Accept: application/json" -H "Content-type: application/json" -X POST -d '{"user":"data_here", "pass":"pass_here"}' http://<IP>
@mortal venture
I got it thank you! I was formatting my data wrong. In case of your example i had the "User" and "data_here" parts switched around
Gave +1 Rep to @vapid mist
Woohoo! Vacation!
Would anyone be willing to share their thm notes with me?
notes on what?
lol your about
Learning is just taking notes from somebody else's notes
why aren't ctfs considered esport 
watching a bunch of nerds typing furiously on keyboards for a few hours would be pretty boring
also; skiddies
they could take a cue from Swordfish to make it interesting lol
Add some hardcore electro music and a GUI for casual watchers and I'd gladly watch it
Like make an interactive visual of each server/domain and packets sent received, etc. etc.
π
> gaming industry
yes
I bet it could normiefied
If you're here, you're probably one of those nerds π
Those candies were great ngl
True they still around sadly today's generation won't know about these π¦
:hammer: GoldenEgg#6765 has been banned.
Not sad at all.
This ain't the place for advertising, hence it's not tolerated.
Definitely not. Even if it's some high speed attack-defense game, you're just seeing people type aggressively on keyboards with no really good or clear way to show what's going on other than maybe showing their terminals.
Even in the most technical esports like Starcraft, you're still seeing tiny guys blow each other up, and I don't need to have played Starcraft to understand that.
oh absolutely without a doubt
damn we got anonymous #2 right here folks
document.querySelector(
'#path-msg'
).innerHTML = `<div class="alert alert-info">Congratulations on completing the Pentest+ pathway!\
The 10% voucher code is <b>TryHackMe2021</b>, you can use this anytime before 31/12/2021.\
Please use this code at <a target="_blank" href="https://store.comptia.org/">https://store.comptia.org/</a>\
</div>`;```
Someone forgot to update code π
Nope, it still works
Ahoy, Gen Z here. I still eat them every Halloween
You youngin
Not old enough to drink but still graduated college π
π
Works, but it says 2021... a week before 2023.
is it me or is the wifi pineapple gui really bad
there's 3 different tabs just for encryption (none, WPA, WPA enterprise) whilst they could just be options
and you can only remove/add SSIDs from pools, and not disable/enable them (if you want to use them later)
also, does anyone know technical docs for the interface? for example, I want to understand how the recon works on a low level: do I need to reverse the OS or is there info available
edit: figured it out by starting a tcp dump and analyzing the 802.11 behaviour of the pineapple
turns out it sends a wildcard SSID
education platform to teach you cybersecurity
https://tryhackme.com
Looks good
Does anyone know how to forward traffic from tcpdump to wireshark on another device?
I want to analyze packets from my wifi pineapple in real time for IoT VR
hmm. can you tcpdump >> into i think .pcap file and follow like that in whireshark ? will that work anyway
I don't think that will work because I think wireshark will only load it when opening the pcap at the start
however, I can try it out and see what happens
hmm. also i think you can put wireshark on pineapple ? check the things you can install
I don't have a GUI on the pineapple so I can't run wireshark sadly
hmm... gui is via browser if we think on same. or you think wireshark gui
@frail rapids is v6 or v7 pineapple ?
v7
yeah, I preferably want to use wireshark with its normal gui
I could use tshark but I want to use it interactively to dissect packets like MQTT, DNS, DHCP and HTTP
ill fire up later apple. might they have something to do that. since there was terminal build in might help
are you able to port mirror
uhhhhhh
that's a very good point
but I'm not sure, considering the ethernet-over-usb port only gets used for LAN access to the management interface (I think)
I need to a wifi network for internet access
this looks hacky as fuck but might work
btw @frail rapids go study. don't slack π
true dat :p
need to read 160 pages for requirements engineering before januari 7th
that is 3 day reading. max 5
this works exactly how I want it. thanks a lot
Gave +1 Rep to @short elk
is it possible to intercept radio transmissions
Of course it is possible
But might be illegal, depending on frequency and country
for the radio frequencies of walkie talkies
you can even listen them online, some websites provide this information for certain regions and frequencies
walkie talkies aren't included there
if you need to listen to it, you need something called "radio receiver", then you just need to set frequency.
ohh i have one radio reciever
*unless communication is encrypted
decryption exists
You can intercept ur local radio station with a fan
Anything metal that can resonate with the same frequency as a radio wave can actually
I've listened to radio music through a razor blade
In WW2 soldiers would use nails
yo i know i sound like a dum ass, but i bet you guys that yall cant turn a chormbook to windos
What kind of script
Is this a roblox exploit?
yes
:hammer: fogakin#2224 has been banned.
Someone will be with you in a moment
Thanks Moose
Np
I stg
wifi pineapple is proof that pentesters should not develop firmware
it's like they didn't hire a UI designer nor a firmware developer
you don't turn a chormbook to windos, you turn it into a leenox
Intercept? You mean, like tune into frequencies that are everywhere? That is what TV used to be and what real radio still is. Wifi is radio frequency too. Police radio, construction companies. The FCC regulates broadcast though so check out ham licensing. There might be a hobby group in your area to help you get gear and learn.
BBC and broadcasting into news deadzones of censorship are built on the premise of anyone with a receiver able to tune in. Still to this day people push even BBC into places with tightly controlled media and long borders.
(for more of how this shit is fascinating, look up literal sneaker nets and how some places' internet is literally people walking in massive hard drives and setting up a local network.)
Pentesters live to destroy. We are Anarchists. Not to build those tiny annoying ass systems that conceptually make you want to create a time machine and stop the creation of computers.
How did you knowππ
Roblox exploits jesus
roblox exploit thor?
I'm a software developer by profession, but I run into so many issues I might as well be a pentester
Seems like a good reason.
same here
pro tip: don't look at the source code of tools
they're god awful not so good at times
lol, but now I want to witness it with my own eyes
It's ok though, I've written some terrible software in the past, I feel especially bad because my managers would try to find a use for the tools I made to help me feel useful
r
how do I stop trying to rube golberg my solutions to problems
I should specify, I mean THM problems
Had this problem a lot when programming
Sit down, identify your problem
Divide it into smaller subproblems that are manageable
Solve those problems until you hit a wall or complete the problem
If you hit a wall start subdividing again
my issue was in the OWASP 10 room in the complete beginner path. one task asks you to find the default creds for the web service, so I deployed Burp, nmap, and dirbuster on the thing, while scouring the page source for info, eventually diving in to the javascript files to see if the default creds were listed there. The answer instead was to google it
yeah, you're right on that. I feel bad for doing all that before hand, but I need to re-frame that process
The owasp wstg is a decent start for methodology, a way to be reasonably thorough
I'm curious as to physical attacks and social engineering, it seems nobody talks about these as if it's a thing that only happens in movies.
it can be part of a red team test but it is pretty high risk, easier to break into someone's network than break into their building.... it is something talked about within cyber security and especially information security
I can argue with that, the return of a physical attack can be so much bigger, sure it's harder ..but.
it 'depends'... if you listen to the Darknet Diaries podcast they do have some various examples of physical penetration tests
Im sorry if this is the wrong channel for the question, but is there a Dark-Mode for the THM Website ?π
Not yet.
But there is the DarkReader extension.
Thanks for the answer. Its really painful over time
Gave +1 Rep to @south inlet
Curious, care to point me at a concrete episode?
I don't do podcasts much but I tried listening not too long ago and there was this one
https://darknetdiaries.com/episode/125/
Thanks a lot I'll look into this.
Gave +1 Rep to @scarlet moth
Do you use Darkreader?
Yes, now
Darknet diaries also has an episode on a guy breaking into the physically wrong bank.
Another is about someone who accidentally ended up being a physical pentester before the term was common or before she knew it.
"Jenny" was one of my favourites.
"so one day I look around and realize people are paying me to do the thing I did as a kid. It dawns on me after a few years that maybe I should get some real contracts and vet my clients." paraphrase, and left out two spoiler parts I really wanted to add.
@south inlet was jenny the one where she legit could have died?
Yeah, she broke in to a place where only she knew where she was, and people turned up with guns.
yessss! Listening to that had me on edge lol, they need more episodes from her
The social engineer podcast is another good one too!
Alethe, lol.
ohhhh wait I didn't remember the name, yeah she makes me never want to answer the phone again π
when I worked in an office, I used to get calls all the time asking for "some name"... I'd also say "I don't know that person, let me transfer you to someone who could help" and transfer them to security
There was the team that did the military base who nearly shit themselves and got beat up.
Wasn't Jenny the one who ||was sent on a job that ended up being breaking into a 3rd party, not the client?||
Beirut Bankjob, great story
n
anyone got any fun new years resolutions for 2023? Hobbies, skills, etc? π I'm excited for the new year myself! Got a few things I want to commit some more time to / try out (I definitely need more time away from computers/screens) including:
- getting back into candle making
- trying out martial arts again. I used to do Karate as a teen but stopped because moving and school and things
- at least sign up to a rock climbing taster session and commit a few hours a month if I like it!
- back driving a motorbike again
- fully committing with my new personal trainer. Really didn't get on with my last one, and just doing a masters & working in 2022 made it almost impossible to meet his expectations. My new one is such a decent bloke and I'll have a lot more spare time this year!
- spending more time with girlfriend
- get back into gym
- get some certifications
- start some projects and web development
- finish the courses ive started ahaha
- spend time with friends and family
nice! Number 6 is especially important π What certs are you planning on?
hopefully Sec+ and OSCP by next year if work budget allows ahaha π
hehe fair. Definitely enough to keep you busy then π
- Set reasonable goals
2-inf: unreasonable goals
inf+1: learn what reasonable goals are.
- Get more movement in consistently
- Keep learning through THM and a book I'm working through about how computers work
- Get back on track learning Japanese
- Find better work/life balance, which probably isn't going to happen until Q2 but I can see a light at the end of the tunnel (we've been working on switching over to a new CRM for like...over a year now, switchover date is solidly set at 1/30, at this point I hardly even care how much is broken I just want it to be over with and all the extra meetings to stop so I can have my time back and be more chill)
I don't need a new year to start my goals π€
Hey can anyone assist with an OpenVPN question?
lol
Questions for the THM openvpn can go in #site-support
Heyo. Anyone else get recommended a scam video on youtube recently? Idk if this is appropriate for the server, but it's interesting as I've never seen any kind of scam on youtube going around before. It's a money doubling claim impersonating Tesla lol
(Not linking of course without mod approval)
My goals for 2023
- Pass Pentest +
- Pass CEH and CEH Practical
- Finish my Python course
- Pass the CCNA
- Go to the gym 4 days a week.
That happened before too. Some accounts got broken in and streamed some cryptocurrency scam thingy.
I'm sure every pyramid scheme and ponzi has a Youtube channel. Just like every other shady company attempting organic online outreach. Screening them is probably difficult. What do you mean by impersonating Tesla though? Literally or figuratively?
Literally. Had Tesla in the channel name and was streaming some kind of zoom meeting with Elon Musk w/ a pinned fake tweet from him pushing their scam. The livestream was their only video, it wasn't some shady company. That's why I'm surprised it made it through screening
Who is @tropic silo
Appears @tropic silo is a admin according to their profile
They aren't, it's something they added to their bio to make it look like they are
Well thats bad then! LOL
@deft skiffwhy did you dm me
Venom can you remove that from your bio maybe? Seems like its confusing some users
Hey dassa, what kind of infornation are you looking for? Your question is a bit broad π
Please remove the admin tag from your profile.
hmm
Hello
Ask your question
I launched an nmap command on one of the available easy ctf, I wanted to know if it was normal that sometimes the machine (victim) did not respond and that the result of the nmap command was so long to finish
Is this CTF on tryhackme?
yes
Ok
gimme a sec to send you the name
That's fine, I don't need it
ok
Did the instructions tell you to Nmap?
the instructions gave in percentage the finalization of the NMAP command
Since this is a THM room, I'm going to ask that we move to #room-help. Also, that you verify so you can post screenshots.
!docs verify
I'll do it asap
I first saw such youtube scams when Tesla started accepting bitcoin.
is there a tool yet that uses the process list (such as ps) to find path injection vulns?
considering it shows when a full path is(n't) given, so you could use it to find SUID bins
however, I assume most vulnerable programs aren't daemons?
there should be a channel to discuss about certificates
What was the actual scam? Crypto, pump and dump, fake charity...?
I saw the same thing, it asks you to give 0.1 btc and it says it will double it for you. Its crazy the amount of people they get watching tho.
@safe rapids
Guys! What do i need to do to get "Act of Kindness" Badge. Pls answer this question.....
it is given within the community to someone who performs an act of kindness
Hasn't been given in a while now

Earned but not frequently received are the best kinds of gifts.
We've all been very naughty
how is #quiet-conversation different from #general
slowmode π
This channel a good channel for people to talk if General is overwhelming.
The speed that thing can go can make people feel uneasy.
Sorry man. I am in the AF
basically slow mode
probably not the best idea to share that info.
OPSEC
I don't see how that violates DOD social media policy
And its also not a violation of OPSEC saying you're in the armed services
someone asking who is in the services on a server such as this one, is kinda sketch
Plenty of people come here, vets and those who are ETS, asking for assistance and next steps
It's not weird
There is a line where it gets weird, but asking if anyone is in xyz community is not
a certain community is eyebrow raising. Anything govt related being one
Not against policy here, and there are feds in here
Specifics are probably not allowed, but this is pretty generic
Hi everyone!
first message in this server!
is it best practice to hash on the frontend?
How can one measure their technical maturity? π€
Being former US Marine myself. I would avoid all GOV talk to be honest. There is no need for it. Doesnt apply here!
Yes, as a bare minimum, for the same reason that I plug my ears and say "la la la la la la" when someone tries to tell me their password. I don't want to ever know it, see it, hear it.
Hey, where do you all go for cybersecurity news?
I have this set up in my own server.
Don't know if support would fit better but anyway π
How do you guys work with kali? I am struggling a bit since in SOC1 are tools and software with an gui needed. My Kali is running on my Homelab as VM, so i can access it from my PC or my crippling slow laptop. Usual i ran GUI Applications more or less successful with over X11 on my pc.
I don't want to install Kali on my PC because it contains sensitive data.
Soooo how do you work with kali or what OS you are using? Do you have an dedicated machine for that?
I used wsl2 a while back, now as a VM. I think ssh + x forwarding is your best best from a Linux PC, if you're in windows 11 then WSL has a Wayland server built in
Well this is a lil embarrassing but I am a victim of a sextortion attack
Does anyone have any advice on what I can do to prevent this from escalating
https://www.met.police.uk/advice/advice-and-information/sexual-offences/sextortion/
If not UK, report to which ever police agency is yours.
Find out what to do if you are targeted by criminals threatening to release sexual information or material about you.
Also cover your webcam when not in use and don't send potentially incriminating pics to anyone
thanks
Gave +1 Rep to @twin ridge
You have given me an idea with win-kex i am testing it right now.
might even go further:
Oh sure
if its a desktop: remove microphone en camera cables (as the NSA director said on twitter: the only way to ensure its not getting hacked is by removing its electricity source), and if its a laptop disable them in bios
I only have ethernet en wifi enabled in bios to reduce attack surface
Dang.... I have some iems attached to my monitor at the moment.
is this channel for those who are in love ?
No
what quiet represents?
#general can sometimes be super busy / loud, so this is for a slower pace
For those that want it
I hope you donβt mind me asking, did you receive an email that stated βwe have hacked into your webcam and recorded xyzβ by any chance?
Honestly just don't reply and don't give up the money just screenshot and report to the proper authorities. Becareful when dealing with people online. Tbh though at worst someone close to you sees your you know but it's not a big deal. Most scammers won't leak unless you challenge them. Since this is more than likely an attempt to just scare you. Never give money because they will want more and never leave you alone
Nah it was over Snapchat
But do you actually think they have anything on you that is concrete?
I mean kinda like I could prob say it is fake or some shit but honestly bro like a lot of people say they wonβt go out of their way to post it if I donβt pay
Going from Jabbas Q, there is a known scam via E-mail that someone has done this, and they haven't, they just hope someone pays.
Thatβs all they are looking for is the money
That's all they ever look for.
I was on this subreddit and some people have faced far worse makes me feel better lol
maybe it'll launch you into fame
here is the thing... blackmail is a no win game..
you could give them money, then they could ask for more
it is better to say 'ok do your worst'
Thank god Iβm broke I gave him like 30 bucks but Iβm boutta contact my bank and get it back
(and use a webcam cover)... but I'm guessing it was fake
because there totally is a scam, even I've gotten it in my email
He was like you have til Thursday to get another 50 I was like man that ainβt happening lol
and trust me, there is no sexy times going on in front of my camera
no judgement... just its such a common scam
They could start an onlyhomiesπ
who knows
π
Shit is crazy the fact that this shit be happening to people daily
Came to this discord to be like βayo someone hack this dudeβππ
yeah no
π
Well if yβall wanna support me in some way you could take the time to check out my art account
Those were cute (I don't have a webcam)
Canβt threaten me with a good time
Whoever made this I'm gonna need their @ because that looks so good
for hydrohomies?
Hey, anyone know how to detect a evil twin attack?
Im 99% certain my neighbours who are on a cybersecurity uni course have hacked my wifi
I got wireshark logs which show a micro ST which i suspect is a rasperry PI
I also found out the company they work at, and one of the blogs talks about, both rasperry pi, wifi security. And uni placements get idiots like these to write blogs so they gotta say whatevers on there mind
basically like paid ads, they just find someone stupid to pay to write meaningless blogs and go by their own business
that would be me
if you have seen their RPi in person then be sure it could be them since you have got the packets traced
https://youtu.be/iHkX7NxcOSw
I didnt have OJ so I subbed Lemon juice
Recipe: https://pressureluckcooking.com/recipe/instant-pot-crispy-carnitas/
Taco Tuesday just got a whole lot more exciting!
Carnitas are basically the Mexican version of pulled pork except they're braised in more of a citrus-infused sauce combined with a glorious dry rub. What's more? The final steps give this succulent meat a crisp leaving y...
And you can use any cut of pork for this.
And my fav is small flour or corn tortillas
and instead of an air fryer lid, I did a Broiler setting on my oven
You're now my favorite person in this server
My fam is all chefs. I was just the computer guy that also learned how to cook.
Aww that's cute
My dad is an award winning chef and learned from Robert Irvine. Met him in person and so cool
Thas cool asf ngl
I love cooking. Hacking is a skill, but cooking is something I also love.
Also make sushi. My fav food is Asian cuisine
Wasn't Irvine the celebrity chef who got caught pulling some sort of reality show bullshit shenanigans with his CV?
not sure what you're referring to. care to explain?
Wasn't there something about him putting royal connections that didn't exist and presidential connections that didn't exist on his CV? I recall he lost a show on FoodNetwork over it
Well, regardless, my fam is full of chefs, one of which who cooked and learned from Chef Irvine.
And, I learned from them both.
So there's that.
Fair enough, I'm sure he's a great chef.
He's not not my fav, but he's def a great chef
Gordon will always by my fav
I always enjoyed the elegant and sublime way that Morimoto cooked on the OG Iron Chef
Ran across a master chef in the DC subway.
Yes, das me with him.
I forget his name. I just know i recognized him from TV
During the attack: check in wireshark which devices are broadcasting the SSID
whilst you are connected to the evil twin: check the network infrastructure (assigned IPs et cetera)
if you connected on a linux device, perhaps try finding logs regarding wlan
additionally, you can see the wifi signal strength in wireshark, so try to triangulate the AP
Using a directional antenna, you can see signal strength in wireshark.
But even if he or she is making an Evil twin, be smart and not connect to it.
And there's not much you can do about it besides banging on their door and telling them to knock it off.
https://www.youtube.com/watch?v=bpR56Ua8v9s
This is about finding cameras, but the method is the same.
On this episode of HakByte, @AlexLynd demonstrates how to identify and track down hidden cameras that might be spying on you, using Wireshark IO Graphs.
This video is sponsored by PCBWay: https://pcbway.com
Buy a Nugget & Support the Show: https://hakcat.com
-----β-----β-----β-----β-----β-----β-----β-----β-----β-----β
Wireshark Vendor Lookup To...
This is also a cool project
https://www.hackster.io/news/angelina-tsuboi-s-esp8266-powered-wicon-kit-wants-to-help-you-keep-your-wi-fi-network-safe-7ccc7e7464e9
thats awful, maybe you could manually whitelist your devices only to stop them from accessing it? i would be very annoyed personally... the cheek...
Ahhh yes the "it ain't safe, send me your whatsapp and we can talk there instead" scam
Yup
Yeah, it's fake, they take some screenshots of pictures you have sent, and make a collage to "show" they have info on you and make up a fake story about something like "this person did such and such sexual crime till someone died", don't feel alarmed by them, they won't actually do anything, just report them
π³
Is there an update to this story? Did you change your wifi ssid to "I am watching you" or something about their work just to mess with them?
I have problem in linux fundamentals part3 help me plz
When I try to download file using wget every time it says connection failed
Connection refused
Why it happening? What should I do?
I presume you are hosting a file on your own box and want to download it to the victim?
#room-help is the appropriate channel
Whatβs a good channel to just ask general cyber security questions? Iβm not really seeing one other than here and the general channel.
Thanks
Gave +1 Rep to @scarlet moth
Did you try https vs http?
Is it ever possible to recover an old hotmail account by downloading the data leak data and cracking the password next to my account?
@quasi turtle β¬οΈ
I know thats the kind of stuff you arent supposed to talk about in most discords and I'm not spamming trying to ask for a how to im just asking is it even worth my time to try?
@soft pier nvm its not worth getting kicked over
yes you should've read the rules, it is unethical. Please review #rules
I did before I posted here. I apologize I must have misinterpreted them, my mistake.
I'm not trying to steal someone else's account I swear its my own, actually the first one I ever opened back in an internet cafe in 2005 to play runescape many years ago. Kind of just venting really. nothing unethical here. I realize there is no way to convey this forbidden knowledge with the assurance it would be used for good and I accept that.
Good to see you understand why we don't discuss this for the exact reason you provide yourself.
Can you retrace your steps? Did you reuse passwords back then, or have a pattern where you could use other known accounts you made around then to guess? If you know what grade or where you were when you made the account, maybe you had a favourite pokemon or something. Sometimes I have to retrace but isally does not work unless it was old enough to be when I would reuse... really annoying to do password reset and it says I cannot reuse passwords or I later find my note for the password and it then seems obvious.
This is quite conversation your voice went over the talking level
Be nice
No speak silently
Also be nice
Sure why not
When a $1 from 10,000 people makes a world of difference
What are you saying?
are there IoT privacy certifications/standards for vendors?
I just audited my own network and realized there's waaay too many IoT devices connected to it, specifically by chinese vendors
https://www.iso.org/standard/44373.html - you could have googled this
ahhh thanks
I tried googling ofcourse but I couldn't find any proper results, perhaps I used a wrong keyword
I'll give that another go when I get the motivation. I think it was stolen and changed before I knew not to enter it into official looking emails. Thanks
Gave +1 Rep to @waxen sage
Need a project to put on my portfolio and do on the side for fun. Looking to be a SOC analyst. Any ideas?
My head hurts from learning KQL. I miss the simplicity of python.
you doing threat hunting?
Studying for SC-200 to beef up my resume.
ah yea, sentinel
I'm also in the midst of doing this 
Why is axelos ITIL so boring. I read one sentence and i want to go to sleep.
Its more boring than english composition
Ah yes ITIL 
Ive read like 10 pages in the past month and i have one month left to complete
Oh are you self-paced learning? When I got ITIL certified work just had a training provider come in for 3/4 days and then we had a day to study for the exam
My colleague at the time literally fell asleep during the training 
It's actually quite an important thing but yeah damn if it ain't dry as hell I don't think I'd be able to study it online I'd need to be sat in a chair and spoke to
Yeah its just a 200 page book i have to read. Its supposed to take "10-12 hours" but its the worst. At least they gave us some dion and cyber vista tests
@raven copper heya dude, would you mind DMing me as I have a couple questions Iβd love to ask you about your post in #jobs-board however I might have ended up in message requests π
We had the same thing at my workplace but I took the exam 11 months later, basically just flicked through the Axelos manual for a refresh and hit the exam the next day
Now I pray I never have to read an ITIL book again π€£
Pls anyone to assist me here???. I am in the vulnversity room and I locate a directory to upload form at first but after then the link won't come up again saying unable to connect... I have bn on this for days pls help... http://<ip>/internal
Microsoft not using weird names for their security solutions is actually making it more difficult to study stuff. T_T
For help with THM rooms, #room-help is the best place to receive assistance.
Gates gonna gatekeep? π
I can feel the instructor's soul dying every time he has to say "Microsoft Defender for"
I got just the thing for you! I made this video 4 days ago
Hey man, thanks for the video- and for putting in the effort in editing
Gave +1 Rep to @jovial yoke
Just waiting for them to release Microsoft Defender for Defender 
Of course, hopefully it sparks some ideas for you. Good luck with which ever project you decide to do!
So, Linode... How much does it cost you to run? Money is an issue for me at the moment, so I was thinking about using Snort instead of SIEM software that needs other servers. Software cost isn't an issue (since a lot of it is OSS), just the cost of housing and running virtual machines in the cloud
You definitely can go that route! Linode was actually free (you get a $100 credit on your account). I used maybe $20 of it in about a week with 3 machines running
I had worked with Azure with $200 credit, but they took away the credit at 30 days or so. Does Linode do that?
I apologize for all the pings/questions
No worries at all! Looks like Linode credit last for 2 months. Definitely enough time for a project Iβm my opinion
I agree! I wonder why they do that though. Definitely taking a look at Linode. Thanks again!
Gave +1 Rep to @jovial yoke
Anyone recommend any labs for Pen-300?
Not there yet. Pen-300.... 48h?
"username=FUZZ&email=x&password=x&cpassword=x"
Help for ffuf in this type I can't understand because that example we have Username, email, password, cpassword section.
But what if we have only login and password section, what this code look like?
Hello, If i want to use WSL2, do i install Openvpn inside WSL2 or start it outside of WSL2
Those are HTTP parameters in URL encoding.
I would recommend against using WSL2, the networking does not work properly
ok
i get error now unablew to connect
and the script wants to find my config file
have done that
Please use #site-support for VPN troubleshooting
It works ish
ish
Done!
Do yous use something like Nord VPN or similar? Or do your own thing?
What do you mean?
Did you make ur own with the router or do you use one of those subscription ones?
What do you mean?
The tryhackme VPN is different
Oh that never mind lol
Can anyone suggest some basic machines
I like to go to practice, then sort by popularity, difficulty, and free or subscription depending upon what you have
Tnqs brohh
π
@jovial yoke please don't post links to join rooms when they haven't gone through the review process
hey, me and my friends just started doing some cfts and we want to start practicing together, what do you guys think is the best ways for ctf teams to practice together?
No better way than signing up for ctfs as a team and partaking in them
Hello everyone ! Currently I am learning burp suite in tryhackme.
I have problem, There is no user options and Project tab in my burp suite community edition. I don't know why. How can I fix this?
if you use a very recent version, i think it moved to a settings window which can be found by this settings-cog symbol
Hey guys, im like very very new to cyber security and hacking in general, can someone give e a rundown of what a ctf actually is? I saw this on another cyber security discord channel but what was posted just blew my mind because there wasnt actually an explanation as to what was going on π₯²
CTF, meaning βCapture the flagβ, usually involves you completing a task to get a piece of text that you can submit as an answer.
The βflagβ is used to prove that you were able to complete the task
Each room in THM is basically a CTF. Just think of it as a cyber treasure hunt
ok, so thats on the website as opposed to the discord then, right? i had a look on the recent release channels and found a room but im not a subscriber yet so didnt have access π I'll have a dig around when i get some spare time andy maybe subscribe for full access as im currently sat at work bored out of my mind π’
Intro to offensive security is a free room I think if you haven't done anything yet. https://tryhackme.com/room/introtooffensivesecurity
Easier CTFs give more details on what you need to do. The "real" CTFs give you as little info as possible. but you don't really have to worry about that right now.
had a crack at it, wish that 2k into my account was real xD Its fun, i like the website i like the simplicity and how its setup like a game. Like i said im just really lacking knowledge and funds because its the end of the month
Lots of free rooms to do. Don't worry about the ones that need subscription.
good to know π
I was able to do a lot of rooms and I barely have a job
We don't help with CTFs here
where can i find help?
Not here. Specific CTF events often award prizes, and it would be unethical for us to help as it would be cheating. If you can explain where this challenge is from, maybe we could make suggestions.
I'm joining a beginner friendly CTF with no prizes. Just trying to learn more about it.
which CTF?
firebird internal
first time joining beginner ctf, thought i could complete a few tasks after practising in picoCTF. Turns out quite challenging for me actually π€£
Good luck then! But it's still a competition and having non-team members contribute to your answer would be cheating.
what do i do
#room-help please, this channel isn't for room help
i was just wondering if anyone could help,
currently, I can only run my kali linux and metasploitable on NAT networking mode, and they both have the same default virtual box assigned inet ip address so nmap doesn't return anything.
A tutorial I was watching changed both their networking mode to bridged in the VM to get both the kali linux and metasploitable having the same IP as the home router, and when they did nmap, they were able to get information about their devices on the home network.
I am also trying to follow this, however, when I change NAT to bridged mode in my VM, and run ifconfig on the metasploitable box, i am unable to ping websites and I also do not get an inet ip address like the person in the tutorial does. Instead, the inet and inet6 address gets replaced by an ether address or something.
this is on NAT mode, and its all good
this is when I am on bridged mode
and I am on wifi, and do not use ethernet, and i made sure to set the bridged adapter to the correct wireless adapter
so why do I not get an inet and inet6 IP address assigned by my router, and instead get an ether address?
One of the networking options in vbox is shared nat. The default nat is a unique per VM network.
oh ok. do u know how I make it so I can connect to my home network using the metasploitable
wait
i found that apparently you cannot bridge to a WIFI adapter because Virtualbox can't do WIFI authentication.
is this true, because coincidentally the person in the tutorial was on ethernet
and since im on wifi that would make sense
the interl wireless is my host machine adapter
so im assuming the VM cannot also share that adapter?
hm its weird but it doesnt for me
is your host machine also connected by wifi @fathom panther ?
Yea
That's not why, but you're correct that bridged works quite differently compared to wired.
hey guys, im really enjoying getting prepped for my OSCP, aiming to take it in approx 10 months time, however as someone outside the industry/no indutry experience im finding the rise of AIs like chatGP
like chatGPT are really knocking my motivation to keep learning, especially knowing gtp4 is just around the corner etc etc. Is anyone else in this boat? Will gaining the OSCP and the skillset/knowledge involved essentially be moot in 12 -24 months? I know there arnt answers but keen to hear opinions and if the rise of this new tech is hitting the motivation of any other newcomers to the field?
i cant get over that this might be an incredibley bad time to get into tech/IT/info sec due to the rise of these new technologys
AI is dumb.
Sure it can do lots of things of things fast, but it's not correct the majority of the time.
I agree but current iterations wont remain static right, and i mean even GPT3 can correct its cod\ing mistakes through a "dialogue" with the operator
i think its going to turn alot of skilled work into semi skilled work, and decimate alot of white collar positions in all honesty
just wondering if anyone else is finding it affecting there motivation though to be honest? I'm going to keep going regardless, but damn, it's come at an annoying time
this is it, we really are at the early stages of a civilisation defining technological revolution
its definitley made me lean more heavily towards my medical and lockpicking skillset
We've had this before with copilot. Everyone oversells it, no one loses their job.
ChatGPT is especially oversold by people who don't understand the massive flaws
i mean i guess its not current iterations im really worried about
You know what they say about predicting the future.
but I do think its going to have a massive impact on job markets as a whole going forward, of course there is alot of media hype and such
get an AI model to do it?
No. They say it's a fools errand.
"Artificial intelligence model predictions from historical data on how AI research would develop over five years matched reality with more than 99 per cent accuracy "
Ah, I see. You're one of those people.
Good luck with your future.
I dunno I think if your in the industry already there is alot of room for leveraging your experience and adapting, maybe im just buying into the hype to much but as someone trying to break in it's a little demoralising, im going to keep going on regardless
I hope so!
sp i mean your saying the Krenn research at the Max Planck institute waas flawed somehow, in methodology or results?
I'm really interested in hearing other opinions on this to be honest, not trying to be argumentative or facetious
I don't think AI can replace the engineering required in proper software design, yet
Well I say AI, but I mean ML
but to be clear im not just talking about chatgtp3, im interested in opinions of what the impact of future iterations of similar technologies might be on the industry and job market
i agree, not yet
Also it cannot produce anything truly novel. It can only derive from it's training set
Hey, sorry, we donβt do this here
Hey my bad, I didnt mean to go against guidelines if thats what happened
I deleted the message thank you for letting me know
Gave +1 Rep to @odd acorn
Another flaw I noticed with ChatGPT is most of it's cut-off of information is from 2021
Yes, but itβs by design
Yes, if you read the front page, it states that any info after 2021 is limited.
However I'd have to agree with you, French food is okay but Tacos in Paris is a GD party
You don't want to buy french tacos....to start, they aren't actually tacos
exactly. taco bell. possibly.... del taco... in paris...
I'd like to see what french tacos look like
I've seen brit enchiladas which is a bit of a shock as well π€£
oh french taco... those look like crunch wraps without the crunch... I've made those
Yeah that, usually smushed on a panini grill
I put them in my toaster oven
this just sounds so absolutely wrong i can't even imagine it
to be fair, they don't really have access to corn tortillas / masa so flour tortillas but then they half ass cover it in salsa to top it off
not enchilada sauce, salsa?
looks like it depends, if you look on the bbc.co.uk site, they have a few of them, one of them looks to be straight up a pasta type sauce
the recipe for this one calls for 1 tsp of chili powder π€£
but 1 tbsp of brown sugar
I prefer to use maple syrup
stahp
i'm just gonna say no sweetener goes into enchilada sauce
Cuts the acidity on the tomatoes
why would you want that?
the amount of tomato sauce in enchilada sauce should be pretty minimal
I am also not hispanic
Yeah but you live in an area with a sizable population thereof
also true
Canada is actually one of the most popular routes for extra-legal population migratory purposes
Several years ago, vancouver into WA state was more popular than river crossings in texas
Yeah but they don't stay in Canada
I am Mex American so yeah I can criticize enchiladas but I also know that ingredients aren't always readily available in other countries
Did you watch the Great British Bake Off Mexican Food episode?
no, not yet, I want to
It's pretty horrifying. Even worse than the typical reality show stuff. Watching one lady peel an avocado.... it was traumatizing
On behalf of British people, most of us know better
Just took another look at this. At first glance, I thought there were diced peppers on top. But green onion?!? Haven't seen that before.
think that is leek and not onion but what does shadow knnow
Do I want to know?
I use a spoon myself
That is quintessentially british
Oi
Wonder if she knew about the pit?
Cannelloni
What the actual fuck π
am I the only brit who just lives off sandwhiched everything and snickers then?
what are you go-to fillings in your sandwhich
Well i had a lovely bacon and smoked cheese toastie this morning with brown sauce for dipping. Go to sandwich is actually a Homemade sweet chilli chicken wrap.
- cooked chicken breast, diced
- 80g lightest mayo
- 15-20g clear honey
- 30g sweet chilli sauce
- 1 tbsp smoked paprika
- mix well, add chicken, mix again
- place mixture on wrap
- air fry 200Β° for 2-5 minutes depending on preferred level of crispiness π€
Disappointed that you didn't say cheese and onion walkers
I wouldn't put honey in it
Hi dudes
I am a newbie in cyber security. I want to embed a webhook script in an html code. It didn't work when I wrote it directly as a script.
How can I do that ?
Ikr!
Dare I ask? Sounds good though
Or pickled onion.
Chuck these on a piece of bread and butter, mwah
What about ketchup.
Omfg wtf Britain?
Come on man!
Hydra, this is 90% of brits childhood
That explains a lot of things
I sometimes have them now
Pickled onion or tomato ketchup.
@spark sun quarkus is driving me mad π¦
can't help with that.... I've never used quarkus
I mean it's mostly kotlin causing the issues I think
Because it's working as advertised with java
mmm Chicken & Waffles is the BEST. If I'm at a restaurant and see that on the menu... I don't even look at the rest of the menu
Usually yeah, but I think the interop with the framework is a bit weird
makes sense, probably an edge case in the AST --> bytecode walk
My mongo ids were being incremented by one in the db
Vs what was specified
Probably the serialization being dumb
Maybe it would have worked with Jackson
Please don't advertise here.
Wasnt sure sorry, I didnt see much in the rules
I just wanted to help the THM community as I myself like doing cybersecurity, no worries though
Rule 3 is the relevant rule - if you are making money from it, it's advertisement/self promotion
If you join and immediately advertise, we pay a lot more attention to it.
holy crap
I'm listening a podcast of a dutch journalist who talks to different types of real cybercriminals e.g. phishing folks, cash cow folks, malware developers, game ddos'ers, et cetera
I'm honestly surprised how many folks are my age and how dumb they are
"a vpn and encrypted drive will prevent the police from arresting me"
- a dude who sells and dumps databases

It's great if you have the capacity to ignore lot of stuff.
Understood, no worries π
!docs vpn
hey would anyone be able to help with openvpn. It is enabled and started yet not tun0 interface is being created. I've done a bit of looking around but I am at a loss
#site-support please
Assuming it's the THM VPN
I shall reallocate
Bonjour,
Je n'arrive pas Γ copier coller mon shell.exe sur la machine Windows de la question ' CrΓ©er un shell Windows Meterpreter 64 bits Γ l'aide de msfvenom et tΓ©lΓ©charger-le sur la cible Windows. Activez le shell et attrapez-le avec le multi/handler. ExpΓ©rimentez avec les fonctionnalitΓ©s de cette coque.'
Comment faut-il faire pour copier coller mon shell.exe svp? j'utilise la machine attack the box
Good morning,
I can't copy paste my shell.exe to the Windows machine from the question 'Create a 64-bit Windows Meterpreter shell using msfvenom and upload it to the Windows target. Activate the shell and grab it with the multi/handler. Experiment with the features of this shell.'
How do I copy paste my shell.exe please? I use the machine attack the box
reading case law reports related to cybercrime is interesting tbh
feels like a giant rabbithole, as much as hacking itself
additionally, you get a load of gloating (/s)
Where can I learn something important
What are you trying to learn?
Penetration testing
Penetration testing
You can learn more by going to #start-here
Whatβs it like #start-here ???
That channel is for you to learn more about pentesting
THM is a Cybersecurity learning platform focused on penetration testing
internet doesn't work in any linux i install on my pc for pentesting. Can anyone help me plz plz plz.... I am using huawei wifi
hard to diagnose without more context
what are you trying to advertise here?
:hammer: king_aami.r#6059 has been banned.
Hello Guys anyone using macbook air m2 for pentesting?
How is going on with the heat?
I looked into using an m2 a while ago for virtualization related work, I believe my experience is transferable to pentesting, I found out that many x86 tools didn't run in an adequate performance under UTM, that is because it emulates the x86 system rather than virtualizing it, however renting a cheap EC2 instance of windows proved to be quite effective for most things that UTM wasn't good at.
Personally I suggest you make a list of programs you wish to be using frequently on your mac then lookup the benchmark for each tool under UTM, that is to get a better understanding of the monthly fee you are going to be paying for cloud EC2 instances if you chose to go that route.
I don't know if it is just me but I tried to verify the kali ISO files from their website but none of their checksums are matching up with what they have posted.
I tried calculating the hash through certutil from powershell, linux sha256sum, and gtkhash from linux.
@hollow sandal Please don't post other discord servers, it's against the rules
hey Hydragrum is it okay if I ask a question about one of your walkthroughs? Or I can ask ninja, the creator of the room but i think Hydragrum would make more sense
Hi there guys
could anyone help me to get a free software of text into video
have you tried youtube or google
https://designs.ai/ https://www.synthesia.io/ https://www.veed.io/edit/20292a6d-084f-457c-a72c-d1e8ea29737e?source=/ found 3 for you
Thanks a lot, but it does not work
what I need is a free software of text into video, I have create a script text via Chat GPT, and I want to turn this text into video.
But what for?
for Youtube
Do you mean text to speech?
I'm not entirely sure what you mean by text to video. Could you elaborate?
π
What's the purpose of the software?
What is it supposed to do, and don't say convert text to video π
Yes but that doesn't make sense
Not really
You do not know it yet
What's the end goal? What's the outcome?
the ultimate goal is that you can generate any sort of videos you like
you know what i mean
If you mean videos of text, yes
can you catch my drift
If you mean generating a video from a description, then no
I don't think there's any free tools out there that will generate a video from a description you provide it
OK, FineοΌ what about Dall.E 2.0
you say something, then it draft an image for you.
Yes
That's an image, not an entire video
And compiling a load of images in to a video from DALLE would be incredibly difficult, frustrating and complex
it can update itself
Good luck writing that code.
you just do not think so@odd acorn
Prove me wrong π
that is your opinion
I can not , my English is suck, I do not even speak English right way
But, we got ChatGPT, let me check if it can prove you are wrong
π
Hold there for a moment, I will be back!
@odd acorn
Hello
@odd acorn
are you there
@radiant jacinth First, I didn't say it was impossible π
I said it would be 'difficult, frustrating and complex'
Second, please don't post text walls here, it floods chat.
OK
My rude
I am sorry , I would not do it again, can you forgive me just for this time
@odd acorn
Are you sleeping
Is there anyone who want to hire me, I mean offer me a job, I got CLP & CPP
Hi guys
are you guys sleeping right now
yes
OK, what sort of job, Mr or Miss @unkempt apex
I assume that he's asking for resources like Make-A-Video, but it is more like an.. advanced gif generator ?
Theyβre looking for an AI that will create a video based on a description provided to it.
I thought they wanted a tool that would literally produce a video of text - not something like dalle lol
Ask dall e to make you a flipbook
iirc some people are using Stable Diffusion to create videos but its more like burner says, it's really a flipbook / stop motion kinda thing. i've not looked too deep into it
see example in this readme: https://github.com/nateraw/stable-diffusion-videos
Technically all videos are flip books it's just how fast the flips are going
Wait
No you also need a certain number of pages for every flip
I know what you mean haha, just want to emphasize the stop motion type of video it will be
stop motion also isnt really the right term
Anyway they can read the readme if they wanna know how it works x)
I apologies, I only meant to educate them on the best source I believed will help them, in any case thank you for telling me that π
Gave +1 Rep to @burnt night
Hey guys, I'm asking for a suggestion. What do you think is a better option between having kali on a vm running on ssd OS(windows) disk, and keeping it on an 128GB sd card and booting from there? Pros and cons?
Thnx for the help 
hey @odd acorn
i need you for support desk, wanna ask something
Hm?
can i dm you?
arguments against sd card:
- sd cards are incredibly slow in comparison to SSD/HDDS
- sd cards really do not have the lifespan of SSD/HDDS when used in constant read/write
Regarding?
my payment isssue
You need to email support, I donβt deal with these issues via discord
hmm
already dealt with actually. but i want to know when my refund will be on my account?
any idea?
Up to 10 days
understood, thanks.
Thank you Ben. Lifespan is a thing i wasn't thinking about, and the speed wasn't a concern since I would have use video recording professional cards. I'm going to go with the vm. Thanks again!
No worries π professional cards are as you say a lot better at the speed, but you'll probably find you're more limited by the interface/adapter that you plug the SD card into at that point (unless you also have a good adapter/interface for SD cards and not say a port in a laptop)
Yeah, that would be an issue... I'll follow your suggestion π»
sounds good π have a good day!
hi, is there any discord channels that for security researchers who studies together
Anybody know how captchas work?
What do you mean? Like why are they there, or how are they programmed?
It's a secret evil scheme to teach computers how to recognise a traffic light
Hello guys I can't seem to download the OpenVPN config for the any room today......
It keep redirecting me to 404 page cannot be found
Ok thanks
It doesn't seem to work
Did you try regenerate?
Take me through that process
- Select a different server.
- click the blue button.
- wait 15 seconds.
- download.
Ok
Hello Iβm trying to download the openvpn for wreath but keep getting error after changing servers too
You can't change servers for wreath.
Leave the room, wait 5 min(s), re-join the room and download.
I went on to create a new account and went premium but still facing the same error
Anyone ?
Have you searched through #site-support ?
I just solved my first machine π
https://tryhackme.com/TheOneWhoStood/badges/blue
nice
Grats
Thank you. π
you completed a room that tons of people think is broken
I faced some difficulties with using Metasploit eternal blue module but updating it fixed the issue π
Fail.
So did iπ
Is it still worth calling the impact of a vuln RCE when it's based on TLS not being validated?
because IMO it reduces the impact greatly because someone would still need to change/mitm dns records
Makes it more effective behind corpo proxies
ah okay
am currently poshing a blogpost so I was kind of careful calling it RCE because I didn't want to be another JD0
Corps will have a mitm filter on internet traffic, so a lot of tooling just fails behind it
interesting - is that part of DPI?
yeah
it's a pain in the behind
I know ours changes the MITM certs out quite frequently so they can't just be added to the trust. Also Java....

can't trusted certs be automated in an AD environment though? assuming you're not using Linux
I'm just over here happy to be 500 points away from 0MN1 and in the top 2% but I truly don't know if it's feat exactly? Like is it high enough to matter?
Hello @autumn trout
youβre alive!!!
Always
we could say the same thing about Bee..
Still waiting on that acceptance π’
are you gonna stay around this time/
Depends if I end up having daily anxiety attacks again due to a stalker/harasser tbh.
boo
ππ₯²
You're back!?
Yup
Welcome back!
???
π
????
?????

sorry hollie shadow does not recall you
Or likely the vast majority of the other 167550 people in the server I would wager...
167552*
Subtract two
I don't recognise myself
Shadow knows herself, and already doesn't recognise you
ah

I thought you meant me not recognising people 
Speaking of, hey Hollie, how's you?
Not so bad, just doing some stuff on proxmox, yourself?
Nae bad. Taking binaries to bits. Always fun.
Binaries to Bits would be a good name for a podcast
Christ, don't give me ideas that'll make me more busy.
I'm already procrastinating my dissertation with OSED π€£
Oh Muir, if only you'd make a podcast
I made a Typo in my ZFS Pool and now its going to haunt me every time
I would be concerned at y'all obsessing over my voice even more than you already do lmao
How are you finding OSED?
I mean.. I wasn't going to say it..
Eh, it's good fun. Binex is my weak point just now, but I'm very appreciative of the case study teaching style. Was amazing on WEB-300, and it's amazing here. Learnt a lot.
Still got a long way to go with it. Just shy of half way through the materials.
Oh actually Muir, while you're here could you do me a.. small favour?
Could you add a ciphers check in the OpenVPN Troubleshooting script? π₯Ί
(If you are still updating it that is, don't worry if not)
Uhhhhhhhh, maybe, if time
You may be better PR'ing that in for the sake of it being done sometime in the immediate future π
What checks are you looking for exactly?
Ohh v nice, yeah its definitely not my strong point either. π So you have my deepest sympathy.
Aha, thanks. Yeah, some of it is painful, but it's all so beautiful. I love the neatness of a finished exploit.
I'm terrible at bash, but I'm sure I could try π
I have a few hours to kill so I'll see what I can do
What exactly are you hoping to check for?
Or, to rephrase, what should the cipher be?
Because if it's a single value you want then it's a really easy thing to add
If the output contains:
DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305). OpenVPN ignores --cipher for cipher negotiations.
Run sed -i 's/cipher AES-256-CBC/data-ciphers AES-256-CBC/' *.ovpn
testCiphers() ( if grep -qioE "OpenVPN ignores --cipher for cipher negotiations." $ovpnoutput;then return 0; else return 1;fi )
[...]
elif testCiphers; then
sed -i 's/cipher AES-256-CBC/data-ciphers AES-256-CBC/' *.ovpn
return 0
fi
Probably something like that, without the lack of input and missing lines?
You'd need to add a test case in there
Sorry, I've just hijacked the chat π
Alright, I'll do a PR, thanks Muir β€οΈ
Np β₯οΈ
I'll trust you to test it first lmao
My VM that was setup for THM connectivity died when I shifted to my new PC
its okay I'm trying to fix shutdowns on some vms on proxmox
Only way I can get metasploitable2 to actually shutdown is to stop it manually via proxmox shell which is frustrating.
Yes of course π
I'll co host with you
This could actually be fun 
When β’οΈ
Double Do It.jpg
Aight, what's the first topic on the docket?
"Are there too many podcasts in cybersec and why is the answer 'There's room for one more!'?"
Actual question: are there? I've only ever heard people recommend Darknet Diaries, and the only other one I've found to be interesting is Day[0] podcast. I don't listen to security specific podcasts very often, but I don't know how many I've seen that have lasted a long enough time.
Maybe most of them just aren't as good π€·ββοΈ
sounds good, we can talk about how everything novel has already been done, so we're just going to retread the same ground that's already been walked a couple dozen times
Most of them from what I have seen heard are interviews and not really much discussion but I also find that with cybersec discussion is fine but cybersec news isn't really podcast worthy unless its a big bug that has a lot of implications that can generate discussion. Even then its still a very niche audience that would enjoy that discussion as I find (my own experience here) that a lot of cybersec is more visual...seeing the exploit, using it yourself etc.
But also a fair amount aren't really that good either.
That makes sense. I feel like a podcast just having stories from pentest/red team engagments, or putting a network together, etc. could do pretty well if the conversation was entertaining and flowed well enough, or just something similar to the discussions that already happen on Discord. But then again, the community is niche enough where I don't know who could pull it off feasibly.
A Muiri + juun podcast (and possibly other thm community members) would unironically be kind of good though based on the conversations I see here from time to time π
I'd listen to stories from pentest/red team engagements if they were dumbed down enough for me to understand
NDAs would probably be an issue for some cases now that I think about that one
It doesn't have to necessarily be about the who what when of the engagement but general tools and methods used and like what obstacles had to be overcome etc.
the vpn not stable to access ad lab , anyone same?
Which one?
how can I prevent windbg from stopping at a ret?
I want g to continue indefinitely, like continue in gdb
hello everyone i have bought pen 200 (oscp) and i am doing pronving grounds play and practice before this i have done good amount of ctf machines on hacthebox i have experience and i will gave exam in 2.5 months so i want a partner to study with me but not beginner if anyone interested so please message me π
You need to be more careful at uni π not spend time on discord...
I applied for a internship today and got it. But the it was a startup and the Guy was planning to create a stockmarket info website with 2 Interns within a month. Guess what, the two interns he selected were data scientists. π ( plus the salary he offered was 35$ per month!)
bruh
am I the only one who believes bug bounty programs are a bad thing
its a way for companies to get security testing for prices way below minimum wage in some cases
e.g. you spend 10 hours testing for xss and get 100$ in return
its not like blackbox bug bounty is a way to bullet proof an app as well
IMO there's a fine line between "hack me for money" and "report vulns to get money as donation"
Nah, if bug bounty / VDP is the company's only security testing programme then there are big problems.
It's a way to reward researchers for finding issues in a legally safe way. It ain't designed for people to no-life, although that's kinda what it's evolved to
nah, I agree with you
also what Muiri said
I don't think bug bounty itself is bad. I think the way almost every program is run is bad
You're seeing it as a job, I think that's the problem
How is secure coding done in your workplace? Does a seminar take place for it for developers or security analysts and testers are included in the decision making process when a feature is being built
It won't take 10 hrs if you're a Experienced bug hunter.
Rubbish lmao
It might, or it might not, depending on the complexity of the bug.
A blanket "better than thou" statement serves no one smh
@radiant jacinth Hi, please leave that to the mods
Hackable and Malicious Life
A Experience Hunter will take lesser time than a Beginner in any type of bug.. It's a matter of fact.
No, an experienced hunter will likely (dependent on other factors) take less time to find individual bugs than a beginner.
A complicated XSS may take an experienced hacker 10 hours to find, but a beginner 100 hours (or be virtually impossible).
Alternatively, a simple bug may take an experienced hunter longer than a beginner if they overlook it, overthink it, just outright don't see it, are heavily sleep deprived, blah blah blah.
Again, blanket statements are rarely correct, in this case they just make you look like an ass. Not every bug is the same. This is real life, not a CTF, or points in a video game. Some bugs are more complex than others, and the hunters are all human.
When confronted with the same bug, yes, you would expect an experienced hacker to find it quicker than a beginner, of course you would -- but to say that an experienced hacker will never take 10 hours to find a bug is just bullshit.
Out of interest, are you an experienced Bug Bounty Hunter?
Man that Upload Vulnerabilities room was a fun challenge task 11 kicked my butt pretty hard but happy I got through it!
I can do my best bub. What task are you stuck on?
also probs should take this to #room-help
Looks like you already have some peeps helping you already silly!
I know this isnt try hack me related but is anyone here proficient with cisco packet switcher? Im having quite a bit of trouble with some things and research on my own is coming up at a loss
I can help but only for bases π₯²
I was Comparing a Experienced one to a noob, I didn't not say a experienced hunter will find a bug by just glancing over it. A NOOB will take 10 hrs to Find a XSS as you said, But the experienced one will definitely take LESSER Time (unless he is too lucky)
Again, that depends entirely on the XSS lmao
I won't call myself an "Expert" but did find some simple bugs (worth of swags) . But i do have some fellow infosec friends who would find what i did with little effort. That's why i said it's easier for them.
Your simple run-of-the-mill "put a payload in the search bar with little to no filtering" sure. Something more complex or chained may take a lot longer, regardless of your experience level. Yes, it will be easier for someone with more experience, but to say that it will never take an experienced hacker a significant length of time to find an individual bug is just patently false
thats what i said
No, you said that (and I quote) a "noob" will take 10 hours to find an XSS but an "experienced one" will take less time.
Which is incorrect. A complex XSS may take an experienced hacker 10 hours to find, but an inexperienced hacker a lot longer
its a comparison
How is this different from what i said, i gave you a example with Hours lol
Correct. I don't disagree with the comparison. I disagree with the assertion that an experienced hacker will never take a long time to find a bug lmfao
Per your original statement, here, where you explicitly state than an experienced hacker will not take that long to find a bug
i said an experienced hunter does take relatively lesser time than A NOOB. The "10 hrs" is an example
No, that might be what you meant but it's definitely not what you said
What you said originally can't be interpreted any other way than an attempt at an authoritative statement, no insinuation of comparison
You're Way more experienced than me, i don't want to argue with you bro π€
Sounds good. How long have you been doing bug hunting? π
started it around a year and half ago. but I'm not actively doing it.
Just a reminder that this is quiet conversation π
Cool, let me know if you have input for content you like to see regarding Bug Bounty Hunting on the platform. π
Can anyone recommend a free video editing software that's going to be relatively easy to wrap my head around?
I use DaVinci Resolve. I think itβs easy enough to follow if youβre only doing simple cuts and edits, but I donβt know what your definition of βrelatively easyβ is.
I've had good results with KDEnlive on both linux and windows
I'll give them both a go, cheers guys
you can try Clipcamp it's pretty easy to understand
Hey, sorry for the ping. A while ago i was getting into malware analysis and someone recommended a series for me to watch, it was either @twin ridge or @spark sun. It was a long time ago. It might have been ninja but someone here recommended a person i should watch to help dip my feet into mal analysis. Do you guys remember who it was?
you can search in the chat with the user names and key words like 'malware' and 'analysis' to find it
do you remember what channel it was in?
i treid although it was on my phone lol i can try again. And I do not, it was a very long time ago
i do not remember, sorry
s
Am I right in saying that when you use a VPN, your traffic goes from your device, to the router which then routes it to the VPN servers who then make the request to whatever your trying to access and return the results (encrypted) back. Except that the data you send to the VPN provider through your ISP is encrypted so only they can decrypt and then make the request you want without your ISP seeing what you want?
if you're using VPN, then your PC is considered a VPN client and it'll encrypt your data using public key of VPN server before sending it anywhere
after encryption, your data packet will go through your router, then through your ISP and then to the VPN server
your data will be encrypted while it travels to the VPN server. what's also going to be encrypted is the destination IP of your packet which means that ISP will only see that your router is sending a packet to the VPN server (even if your real destination is somewhere else)
after your data arrives at the VPN server it'll be decrypted using VPN server's private key
what's also going to be decrypted is the destination IP of your packet which will let VPN server know where to send the packet next
the VPN server will also form a table (similar to NAT) so that it knows how to send the packet back to you after it comes back
Thought so, thanks :)
red laser dots for cats are the greatest invention ever !
innovation that matters 
Are MITM attacks still relevant (outside AD attacks like LLMNR poisoning, relaying, etc.) ?
I'd say evil twin attacks are still somewhat relevant
Hello, I have a Question. Any alternatives to NIST Risk Management Framework?
Check out ISO 27001 and 27002. π
ISO costs money to get access to, though
at least NIST is fully distributed for free from the us gov NIST π
does mitre have a free option too????? for that purpose