#quiet-conversation

1 messages Ā· Page 4 of 1

spark sun
#

are you talking about ATT&CK or some other framework?

soft pier
#

some mitre framework that can be used as an alternative to nist risk management framework

mortal venture
#

Would someone be able to help me with autopsy? I'm having some trouble viewing registry hives. These here that I found have a size of zero.

#

I feel like its really simple and I am a simpleton

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
paper olive
#

the number of times I've sat scratching my head as to why I cant find what I'm looking for and all I had to do was cd ..

fathom panther
#

How often are wireless attacks being done on a pentest?

surreal drift
#

Though I would still expend the effort to learn at least the Aircrack sweet of tools and how the WPA/WPA2/WPA3 handshake works. If you want to get really into it, you can use scapy library inside of python. David Bombal really preaches about Scapy a lot on youtube

craggy carbon
#

i can not open an ip which is in hackme what could be the problem is anybody here to help

spring flicker
#

I have question about job!
Can I become penetration tester without learning Windows? I am asking this because tryhackme has windows course path, I am only linux user windows is very uncomfortable for me. Shoud I learn windows to become Penetration tester?

#

I want to skip windows courses is it true or not? Can someone gave me advice?!

fathom panther
#

you need to learn windows

#

A lot of companies use Active Directory which is also Windows

#

Unless you want to specifically be an application security tester which does APIs, web & mobile apps, etc.

burnt night
quaint basin
surreal kite
#

Hey guys hope everyone is having fun šŸ™‚

short elk
#

but getting a job as an app only tester without previous pentesting experience?

#

i have not seen any, at least in the uk

#

all (that i’ve seen) junior positions require both app and inf

quaint basin
#

Yeah, that

burnt night
#

It's probably a 70:30 split

little kernel
#

Hello. Random question. For garage door openers that have WiFi or smart link, how secure are they? I need to upgrade a really old one, but was thinking about how someone could hack it and open it. Thoughts?

real chasm
#

Lot of things can be hack, but targeting your garage door well, there is a low probability but you should look for information about the model and the softwares to upgrade security 🄲 I dont know if there is someone specialized in that here but I give you my opinion :c

sand radish
#

Nothing, seriously nothing, on any site, can prepare you for the frustrations that await you when working with a client irl.

#

We're doing a pentest for a client and on top of them changing the assignment mid-way through (we're week 2 of 3 and they changed it completely yesterday), the system we're supposed to test is not complete at all (release should be in a week or so) and has ceased to work completely this afternoon.
We were supposed to test an API, but they're now having us test their IAM with a list of provided methods for each endpoint, but half of them don't work for the roles we should be testing. So we're basically trying to build their API requests for them to be able to test them in the first place. Test results are not reproducible, changing randomly.
Creating a role/account takes about 5 minutes of manual labor of their security admin, with which we are in an all-day long call.
Now this afternoon the system just stopped working. Nobody can log in. Access roles have been disabled with no trace in the logs.
They brought one of the third party backend developers/hosts into the call, but they can't even see us in their logs.
The worst imo was when the project manager dropped the line "I recognize this behavior, we have this in production all the time"...

little kernel
hoary nymphBOT
#

Gave +1 Rep to @real chasm

burnt night
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
#

@little kernel One of the biggest things I'd say as well as worrying about confidentiality is watch out if it depends on a cloud service.
Consider what would happen if that cloud service was to disappear overnight, IoT companies go bust and usually leave their customers in the dark

tawdry dove
little kernel
#

Alright, thanks

spark sun
#

@little kernel NIST has a lot of free publications for IOT related guidelines and recommendations.

hoary nymphBOT
#

Gave +1 Rep to @spark sun

mighty echo
acoustic obsidian
#

ola

tall saddle
#

Upgraded my homelab from qemu/kvm + virt-manager just living on my old Linux install on a laptop to... Proxmox running on the same laptop lol.

Nice improvement though, Proxmox does have a vSphere like feature set. I honestly would have gone ESXi if my NIC was supported though 😢

burnt moth
surreal kite
#

Hey all

odd acorn
#

@coarse knot Please interact with the community before posting your blog.

glossy drift
#

Hi today I came across a terminology "accelerated system sleep call" does anyone have any idea what it is about.

radiant jacinth
#

a

mortal venture
#

I despise Gen-Eds with such a passion that I'm about to drop out of my Bachelors and just go full blown focus on OSCP and hope that will compensate😭😭😭

#

Like why is my Bachelors dependant on weather or not I can memorize all the rivers, mountain ranges, and GDP in Eurasia. I hate it here man.

tawdry dove
#

It won't compensate

mortal venture
tawdry dove
#

Gen-Eds are there to make you a more well rounded, productive, person. They are important, even if you don't enjoy them.

mortal venture
#

Pain

spark sun
mortal venture
#

Yeah, I've been putting them off and now I have 7 weeks to finish 3 Gen Ed courses NotLikeThis About to start handwriting all these things.

still maple
# spark sun It does not. Also, the gen-ed electives will end up being the most valuable part...

I have mixed feelings....with the way gen ed classes are taught, at least in the US, it hardly does any good. That's my main issue with it. As someone who's been in university on and off for 10 years, I can count on one hand the amount of professors that helped a subject stick.....I will say though, I think it should be a requirement to deep dive into ancient rome. Crazy how it mirrors the modern day. Eek.

native oar
#

yes

acoustic obsidian
#

como programa ?? alguƩm me ensina.

olive frost
radiant jacinth
#

Message above will self destruct in 10 secs ^

shy wind
#

im a rookie, how can start to learn hacking?

soft pier
shy wind
#

thanks buddy

acoustic obsidian
#

hello.

#

people.

radiant jacinth
#

Hey

radiant jacinth
#

!docs verify

deft fossilBOT
acoustic obsidian
#

sorry.

faint dock
#

You’d think living in a capital city would result in a nice little job pool to pick from, but from what I’m looking at right now, I might as well have been living in the backcountry

worldly remnant
lofty vortex
#

Hello All, Im new and look forward to meeting other security techies!

twin ridge
#

welcome

acoustic obsidian
#

because.

maiden hinge
#

Hi and Welcome.
I was asked by a site owner to test his site against DDos attacks and calculate how long his site can survive before it goes down.
What are the most powerful tools or scripts to do this? I don't have a good background about this type of attacks.

winged rain
odd acorn
#

Oh I didn't finish my message

#

That is a complete lie @maiden hinge

#

And if it's not, I seriously question your ethics

acoustic obsidian
#

Love!

twin ridge
#

And you'll usually not want to ddos

odd acorn
twin ridge
#

I'm agreeing with you, though saying load testing is a thing

odd acorn
#

They usually wouldn't contract someone who doesn't know how to do it, and in all honestly it is highly unlikely that they would be contracted to do any load testing

twin ridge
odd acorn
#

The user maybe, but websites unlikely

twin ridge
#

You'd be surprised

#

I mean, consulting is still a thing

#

I mean my favourite tool will take down our dev environment with 12 simultaneous users

#

I was asked to reproduce a scenario that apparently only occured under load, and at that, randomly

#

Never saw that problem again until 5 years later in a different subsystem

#

Where it was repeatable, and again mysteriously disappeard

quaint basin
#

Although yes, the contracting a non-professional is a l'il bit sus

spark sun
#

or SRE

quaint basin
#

Yes, quite.

unique bolt
#

I just realised there's a trilum thread! I'll post there

mighty echo
twin ridge
#

Looks like flatpak with extra steps

acoustic obsidian
#

My friday.anidab

brisk urchin
#

lol

surreal kite
#

Hola team šŸ™‚

#

Whats happening with everyone šŸ™‚

acoustic obsidian
#

creepypog hii.

spark sun
twin ridge
spark sun
sharp oracle
#

hi

radiant jacinth
#

Does anyone know how I can fix this problem?

south inlet
deft fossilBOT
south inlet
#

Run that.

radiant jacinth
#

Is it normal for it to be like this, it's been like this for a long time?

fathom panther
#

That is the highest level

radiant jacinth
fathom panther
#

Those are special levels

#

Red Teamer for e.g., it can be get from an event but that event is done now

#

Staffs have their own level

#

Also bug hunters from the site

radiant jacinth
#

wow, thanks for the info, that sounds really good

frail rapids
#

I basically have a private cloud at home and I want to implement network scale network monitoring. What are some good tools for this? I've looked at Logrythm NDR (part of XDR) but it looks like it's for enterprises and it's expensive

mighty echo
#

What specifically are you trying to monitor?

#

Could setup your own router - https://openwrt.org https://www.pfsense.org

#

Or if your interested only in DNS then you can setup something like pihole, adguardhome etc

short elk
#

logrythm is incredibly overkill if you are using it for actual monitoring of your home network

radiant jacinth
#

sonned

acoustic obsidian
#

My friends.notsure

heady creek
#

Fellow lads.

Currently have the ETA Christoph 3343 90000, so about $65 electric razor. It does the job but the quality is shoddy (duh) and when shaving, I feel my facial hair being "pulled out" or plucked painfully rather than cleanly cut on the surface of my skin, for a lack of a better description.

I look my best by far when clean shaven, and if I don't shave for 1-2 days I just look bad.

Wondering if dropping a few hundred on a premium quality electric razor from phillips or siemens or something would improve the shaving experience.

spark sun
#

I'm not a fan of electric razors. For that much money, I would get a good quality badger hair brush, real shaving soap, and a nice safety razor.

odd acorn
#

You shouldn’t just be using an electric razor tbh, you should trim it then shave it off using a razor or barber’s blade

mortal venture
spark sun
mortal venture
#

Yes! I have been told a lot of people run proxmox and they love it but the same people telling me what you just said. I have been waiting to do that until i fully understand what I am doing and how to handle errors but still. Confusing. It's like they're telling me they love it but its a bad idea, but to do it haha

heady creek
#

I only clean shave with a razorblade before I go on a date or something similar

#

But I do need to shave ideally, on average, once every 1.5 days

#

Where as with an electric razor, I'm done in 5 minutes. The brunt of the question was - will a premium razor give me a less "painful" shave than the $65 one

spark sun
#

No. All electric razors function in the same way; if they are pulling, you are letting your facial hair get too long before shaving or the blades are dull and old. If you want a more consistent shave, add it to your daily routine

heady creek
#

I'll try sticking with it

burnt night
#

Highly recommend a safety razor and brush and shave soap as juun said. I got an omega synthetic brush, proraso green soap, and a king c gillete razor and it was cheap and good @heady creek

heady creek
#

I can't fathom doing this ~5x a week

burnt night
#

Not timed it but it's a ritual, like making nice coffee

mortal venture
#

Add 10 min to your shower routine

heady creek
#

I do enjoy it actually, but specifically because I only shave when I go on a first / second date, job interview etc.

#

The core of the problem is: I'm lazy

mortal venture
#

For me I shower, brush teeth shave when needed, and clean bathroom as my routine. When i dont shave i just save 10 min. If being clean shaven is so important i cant imagine 10 min being a big deal to spare.

heady creek
#

or rather it just feels like too much overhead

mortal venture
#

I mean thats like being too lazy to shower. You dont have to but 15 min to look and feel great is worth it. I feel and act much better when i condition, shampoo, and comb my beard

heady creek
burnt night
#

I found I could shave less frequently because it's closer

heady creek
#

For me even after clean shave with razor manually, it takes 2, 3 days max before I have to do it again. idk life is hard xd

mortal venture
#

So shave again. As long as you arent destroying your skin, I don't see an issue. 2-3 days is about normal for hair to need to be shaven again if you are going to clean shaven.

heady creek
#

so the lesson is: suck it up

mortal venture
#

Youll have to :/ or spend $3000 on laser hair removal lol

heady creek
#

Yeah not doing that

mortal venture
#

As someone that loves being lazy, getting a routine down feels so good. I feel and quite literally act better as a human when I know I am fresh. Shampooing, conditioning, combing, trimming, and oiling my beard feels really nice. Get a ton of compliments on it too.

#

It sucks and can get expensive but its 100% worth it if its something you care about. Just don't impulse buy. You might get something trashy and think you shouldn't take care of your face / not worth it when in reality its judt bad product / limited knowledge.

heady creek
#

I don't have a problem with lazyness, I have a problem with trying to be overly efficient in every faucet of my life.

I am perfectly happy with the $65 electric razor daily maintenance I have going on right now, it's just that I feel my facial hair being "pulled out" or plucked painfully rather than cleanly cut on the surface of my skin, for a lack of a better description

#

so I'm wondering if a $350 electric razor fixes this

#

some of the premium ones have crazy good reviews online but yea idk

mortal venture
#

Could be bad or old. Not necessarily cheap

heady creek
#

nah I have ETA Christoph 3343 90000, it's been like this since I bought it

spark sun
acoustic obsidian
#

Good.

spiral echo
#

hey

#

was sup

mortal venture
#

im having some trouble enumerating a box. I am trying to use gobuster to find some directories, but all non existing directories redirect to a static 404 page, so I get a 200 OK response for all of the entries. I tried to filter out character length using ffuf, and not follow redirects with gobuster but still came up short. Not sure what to do to get around this if anyone can help. Its not a THM box but any help is still appreciated. Pls ping and / or DM at will

acoustic obsidian
#

daddyarch

unique wing
#

try dirb

#

./gobuster dir -s '200' -w /usr/share/wordlists/SecLists/Discovery/Web-Content/CGIs.txt -u http://127.0.0.1

frail rapids
#

are ip addresses typically hashed?

#

considering theres probably no usage in them aside from validation

quaint basin
candid tartan
frail rapids
#

the fact that breached logged IPs and didn't hash them

#

e.g. putting argon2 on them to prevent law enforcement from getting access to the ip's

quaint basin
# frail rapids for privacy sake

Again, IP addresses are integers. Hashing them wouldn't make the slightest jot of difference -- all you need to do is be able to count to the maximum IPv4 integer and you'll have 95% of them anyway. Also makes things like rate limiting a lot slower

#

Hashing IPs certainly ain't standard practice afaik. Awful lot of effort and wasted computational power for not a lot of gain

spark sun
#

Realistically, what's the goal of hashing an IP? The potential used keys in the set is so small, bruteforce is going to take a very small amount of time to crack.

quaint basin
#

That ^^

soft pier
#

then there is the problem of the hashed ip not being helpful for when you need to forward data to it

frail rapids
#

that's certainly true in non logging context

frail rapids
quaint basin
# frail rapids one could use an expensive hash function like bcrypt or argon2

Which makes it even less useful for working with the data. Take rate limiting as a really simple example -- can you imagine how slow the site would be if you had to hash the damn IP address with a slow hashing algorithm before checking cache / DB for request count?
Same thing applies to any other uses for the data, including things like analytics which is presumably what they were using it for.

#

Regardless, it's not like you would be bruteforce cracking the hashes on a tight schedule. You could quite literally generate a hash table at your leisure and simply pluck the addresses out of it. When the number of possible hashes is that low, it really doesn't matter how slow your algorithm is -- those hashes (all of them) are breaking very quickly.

#

All you're doing is inconveniencing yourself and your users by wasting your own processing power and slowing down the application kekw

twin ridge
#

I mean you could "hash" to an int if you don't like the presentation format

#

I mean you could in theory encrypt them, that's a different story

spark sun
twin ridge
#

I mean in a DB

#

don't know if an IP address is considered PII under the GDPR

spark sun
#

I don't know how it could be

#

NALANLA, but I don't think an IP address is enough to get a search warrant issued without other evidences present. Like maybe domain name ownership tied to the DNS record for that public IP

radiant jacinth
#

how would you approach this kind of question: URL-encode the . symbol

radiant jacinth
#

It's not a question. It's a hint or relatively a statement to some obfuscation definition or meaning, telling you to encode the . symbol

#

Which in this case the URL encode for the . would be .%0A

twin ridge
#

. is %2e no?

radiant jacinth
#

I tried on different website and it gave me .%0A again

short elk
#

looks like you didn't tell it to encode special characters

#

%0A is newline

radiant jacinth
#

There is a period at the top there

#

And when i went to this other site i get the %2e

short elk
#

and in the "encoded" bit too

radiant jacinth
short elk
radiant jacinth
#

Yep i see now, i had encode all special characters

twin ridge
#

Yeah 0a is newline

radiant jacinth
#

noted

radiant jacinth
surreal kite
#

Hey all

#

Whats happening? hope everyone is having a great sunday happy hacking

mighty echo
weak granite
#

[+] Possibly interesting SGID files:
-rwxr-sr-x 1 root tty 22912 Feb 21 2022 /usr/bin/write.ul

Anyone knows if this is usable for privesc and how?
write.ul -h output:
Usage:
write.ul [options] <user> [<ttyname>]

Send a message to another user.

Options:
-h, --help display this help
-V, --version display version

For more details see write(1).

Appreciate the help... really stuck

soft pier
#

doubt it as there is nothing on it in hacktricks or gtfobins

weak granite
#

Yep.. there isn't

tawdry dove
unique wing
#

can anyone solve this issue? im connected with a wireless access point and my kali ( which is inside a Vm oracle's Vbox ) is not getting any ip , but when i switch to my router everything seems fine...

bitter void
#

good morning

burnt night
#

If you connect another device to the AP, does it get an IP through DHCP?

civic rootBOT
#

:hammer: mohiuddinomar#2667 has been banned.

weak granite
tawdry dove
tawdry dove
#

@weak granite I am sorry but we cannot assist you with active CTFs. Also, I recommend reading the rules as unsolicited DMs are prohibited.

latent shale
#

hello, Can I change name on certification? certification for aaaaaaaa does not prove me did the course you know.

south inlet
#

No, you can't change it after you've generated it.

latent shale
native furnace
acoustic obsidian
#

my white.

vital wind
#

Hello guys, how are u all?

mighty talon
#

True!

primal grove
#

hi and bye

radiant jacinth
#

!rank

tawdry dove
#

Sure, it's possible, but I'm not sure you want to go down this path.

#

It's illegal and unethical just to do it outside of a professional agreement.

upper jackal
#

I have a general question- If I nmap someone's server they'll be able to see that /someone/ is systemically connecting to all their ports right? edit; assuming they read logs

#

You've spammed that in a bunch of channels

tawdry dove
#

@jolly valve Please do not send unsolicited friend requests.

spark sun
#

And by 'tread carefully' I mean don't do it.

upper jackal
spark sun
upper jackal
#

That's what I thought. I was reading about how you can nmap to create your landscape and my thought as a systems enginner was "wouldn't they know you're pinging all their ports systematically?" Thanks for confirming my suspicion.

burnt night
fallen sparrow
#

I am not saying it is cool to scan enterprises wothout their consent but why would they waste any of their resources responding in any way shape or form to somebody randomly scanning their network

#

unless by responding you mean blocking that ip address

fathom panther
silver harness
#

Seniors am asking to learn ethucal hacking u only need to know python

south inlet
#

You don't even need to know python.

But it helps.

silver harness
south inlet
silver harness
south inlet
# silver harness Like

I'm sure other people have gave you plenty of documentation.

And you've probably been told to have a read over #start-here

That will give you enough information to make a start, then decide where you want to go.

silver harness
south inlet
vocal ridge
#

anyone know where I can find "declassified" DFIR reports?

vocal ridge
#

people will strip their pentest reports and put them on GitHub. I haven't found much of that with DFIR reports

scarlet moth
#

you could look at dfirdiva.com and see if she has anything but generally if you hear of a high profile incident, you can google and find something but not sure of a site that lists them wholesale

tawdry dove
#

Pretty sure Mandiant and Dragos have some stuff, but a lot of that material is NDA'd to all hell before they get permission to publish

scarlet moth
#

I thought Verizon had posted some stuff too

vocal ridge
#

very nice. I'll take a look, thank ya

tawdry dove
#

Robert M. Lee, CEO of Dragos, has some stuff on his personal site too

#

It's ICS focused, but he did the DFIR for Ukraine Power Grid, the Saudi Aramco attack, and some others iirc

south inlet
#

Report to Snapchat and police.

winged rain
#

report it to the police

south inlet
#

They're more than likely bluffing.

However, there is nothing anyone here can do.

winged rain
#

oh no, the police can find so much using snapchat it's crazy. Don't think for a second that just because you have no info you have no case

#

I've seen police dig up unsent snapchat videos and use it in court cases

next thunder
#

hello everyone, I would like to ask about threat hunting
currently I am trying to do an external threat hunts, where I don't have any access to the target environments.
I would like to know, how can I find any kind of leaked information for instance, gitlab projects.
do you guys have any suggestions on how to start, what to know to help me through this process?

thank you šŸ™‚ (I am a beginner)

quasi turtle
#

Hey @next thunder , welcome šŸ™‚ kindly requesting you to keep your messages limited to the appropriate channels ( please dont post the same message over multiple channels ) šŸ™

fallow ferry
#

@tawdry dove I'm a fan of the name, really!

#

nice one XD

deft seal
#

Hi

worldly sentinel
#

Hi

jade minnow
#

Hello

west bay
#

Helloo

radiant jacinth
#

I think I've eaten a fair amount of cat hairs in my life from owning cats

upper jackal
#

I think I've eaten a fair amount of keyboard hairs in my life from owning keyboards

spark shale
#

After a while I don't think there's any point in trying to clean a keyboard anymore, better just to throw it away

rare depot
#

I feel dumb for asking this, but is Kali considered a meme? And if so, why?

signal hull
#

Not really. It's a pretty well maintained distribution of Linux that maintains repositories to make installing tools a lot easier than having to constantly maintain a pristine startup script or up-to-date iso.

The only things to meme on are (a) OffSec (the company) and (b) how it's the go to for beginners to start asking low-effort questions about without ever putting in the work to actually understand Linux and why things are the way they are.

spark shale
#

I don't see the meme angle

magic tree
#

Hi Guys,
Please I'm new to this discord and have a question:

What are the most active hacking/leaks forums (websites) of the moment ?

twin ridge
#

please don't ask the same question in multiple channels

magic tree
#

ok

#

so, can i get the answer ?

odd acorn
magic tree
#

nvm

mortal venture
#

Bought a home server and neglected to do enough research😭 its EOL was a few years ago

mortal venture
mortal venture
#

šŸ˜ŽšŸ‘

mortal venture
mortal venture
#

Dell poweredge r630

#

The issue is the remote control is accessed by a jnlp file. I spent a good 4 hours trying to open it

burnt night
#

I've got a 720 and it stumped me for a bit

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @burnt night

upper jackal
mortal venture
#

LOL

#

That would be the day😭

mortal venture
mortal venture
#

which OS do you have? mine came shipped with windows server 2019 but honestly i have no clue how to use it lol

#

sounds like a fun learning process though

burnt night
mortal venture
#

oh i thought about esxi but did not look forward to a subscription, especially considering the price of their other things. I plan to install Ubuntu server and then proxmox on top of that.

mortal venture
mortal venture
burnt night
#

Or vmug for 200/yr if you want more products

burnt night
#

But yeah run truenas normal if it's as a NAS.
I don't recommend scale, it's got some irritating issues and I didn't find the VMs so intuitive. ESXi was super intuitive for me

mortal venture
mighty echo
#

I wanted to install TrueNAS

burnt night
#

Honestly with Proxmox, it's not really what's used in industry

mighty echo
#

but my dell server refused to find it's boot loader

burnt night
#

Less value as a homelab

mighty echo
#

I tried using openmediavault for a bit but when i tried to get it to utilize the root partition it broke too

#

so just went for plain debian which works fine

mortal venture
#

is this one of those things that "Oh yeah thats normal and the error is overreacting, it's fine" Or is this some thing i should listen to lol

burnt night
mortal venture
burnt night
#

Not officially supported isn't a big deal

mortal venture
#

Oh ok so continue with ESXi 8.0? Or go for 7.0

mortal venture
rare depot
# signal hull Not really. It's a pretty well maintained distribution of Linux that maintains r...

I honestly had a feeling that that was the case. I mean I use it as my daily linux driver when I am using linux, and obviously for THM stuff, and I can see the value of the distro coming preloaded with a wide array of tools. I was in another server for the college I'm in and someone chimed in with saying Kali was a meme, and I felt like I had heard some rumblings of that elsewhere, so I wanted to check if it was a more common sentiment than I thought

rare depot
hoary nymphBOT
#

Gave +1 Rep to @signal hull

twin ridge
radiant jacinth
#

sudo chop -a anidab

mortal venture
rare depot
rare depot
candid tartan
spark sun
spark sun
rare depot
rapid barn
#

Who going to defcon

spark shale
#

I'm not going until they release the videos from last year

burnt night
#

For the talks at least...

spark shale
#

There are many talks still missing for some reason

burnt night
#

Everything I can remember from the schedule is on there
https://www.youtube.com/user/DEFCONConference/videos
What's missing?

spark shale
spark shale
#

what's HRV?

safe rapids
#

Ham Radio Village

spark shale
#

Actually the RF village talks are online now, I take that back, it's just the Recon ones which are missing

spark shale
safe rapids
#

Ah.. got it.

inland umbra
elfin lion
#

guys

radiant jacinth
#

hi

elfin lion
#

who is better (gtx or rtx)?

#

i need some advices before purchase a gpu

tawdry dove
#

You're going to need to provide more information. How much are you willing to spend, how big can the GPU be, etc

tawdry dove
dark panther
#

Budget?

inland umbra
#

RTX = Real Time Raytracing (Better reflections and shadow quality in games)
GTX = No Real time Raytracing, also the newer generations are always RTX. the newest GTX are GTX 16 series which are a revival of the 7 years old 10 series

#

so it's basically just a question of power vs price

silver harness
#

Guys today i finished my frontend course please get me any contracts or remote jobs such that i can gain experience

mortal venture
twin ridge
#

Ok strike my last it's RX number ..

#

Bloody companies can't name things properly...

icy token
quasi turtle
mortal venture
#

I JUST GOT A 90% ON MY AXELOS ITIL V4 FOUNDATIONS HAHAHA. This feels so good. I'm glad this cert lasts for life bc I am not taking that again

sturdy crescent
burnt night
#

@radiant jacinth Please don't? No reason for that message, totally unrelated, and it's only going to cause issues.

burnt night
radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @burnt night

frail rapids
frail rapids
#

Yes

candid tartan
#

nice...

#

btw... you good? uni ?

frail rapids
#

Its a lot of work

candid tartan
#

as expected yea

frail rapids
#

Recently I've been doing a lot of support to the developers of projects

#

Since otherwise it would just be annoying each other due to skill set differences

#

E.g. I'd implement a bunch of overkill mechanisms which they couldn't understand

candid tartan
#

how to confuse ppl 101 šŸ™‚

#

btw migh i DM you ?

#

no car warranty

frail rapids
#

Suree

outer cove
vernal jay
#

Hey guys, does any one understand malware analysis? Im really struggling with this assignment and cannot wrap my head around it

odd acorn
vernal jay
#

Ahhh is that so? thank you anyways

rugged flicker
#

Can you help me understand what is the level and benefit of comptia security+ exam

arctic basin
#

Security+ is a great base certification, many organizations, especially DoD require it to even have access to their networks.

#

It can be a difficult starting point for those new with technology, but it is definitely obtainable by a novice with the right amount of studying.

sacred sandal
#

I think is worthless

arctic basin
#

It has a lot of general knowledge, and you will not be good at any specific task, correct. But many tech related jobs in the USA require it.

sacred sandal
#

If you have a BS might get you a job in a government agency, but just the cert by it self wont get you in the door.

arctic basin
#

Definitely, I have a BS but most tech DoD jobs require Sec+ still. They say like, have Security+ or be able to get it within 60 days of start date.

sacred sandal
#

Yeah in that case. Plus passing a polygraph lol

arctic basin
#

If I had to chose between a BS or a Sec+ I would chose BS, but I would not call Sec+ worthless

sacred sandal
#

I see what you mean.

arctic basin
#

Also, BS is a lot of $$, and a Sec+ cert can get you in the door for a lot less, enough free resources online to just have to pay for the test.

sacred sandal
#

I don’t think that just a sec+ will open doors. Ime is not enough even with a BS. What helped me the most was personal projects in combination with a BS and sec+
Maybe my area is saturated with entry level ppl looking for an opportunity

#

Or maybe im just dumb 😢

arctic basin
#

I know multiple people who got in the door with Sec+, new previous IT experience, making 80k+ a year on the help desk .

sacred sandal
#

Where?

arctic basin
#

Google, LG, and Amazon.

sacred sandal
#

So Seattle and cali?

#

Or are they remote?

arctic basin
#

I mean no previous IT experience , not new. And no, neither of those locations. All in person. Not saying where šŸ˜‰

sacred sandal
#

I just have not seen that

#

Im glad for those ppl

arctic basin
#

Sadly, most jobs today hire based on your ability to interview well and your linkedin profile instead of technical prowess

sacred sandal
#

True

arctic basin
#

I feel so old just getting back into the security sector, last time I used Kali it was called Backtrack

#

and python3 didn't exist

tawdry dove
#

Government is also known to hire bodies, sometimes that happens for security.

sacred sandal
#

For what I see they require a bs as well to even apply.

tawdry dove
sacred sandal
#

I have to take one /:

tawdry dove
sacred sandal
#

For systems analyst at city hall

tawdry dove
#

But security+ or associated cert for the category is pretty much mandatory

#

So, you're talking about local gov. Fed is different

#

They'll probably model their requirements off of the federal government, but they aren't required to follow those rules to the letter. Agencies that interact with the federal level are bound, by law and charter iirc

sacred sandal
#

I guess I’m a little confused then

tawdry dove
#

When you say government, the default assumption is typically federal in conversation.

#

If you mentioned local previously, I missed it and I apologize

arctic basin
#

Iat lvl 3 with no BS has some great jobs available, especially if you already have the clearance.

tawdry dove
#

You have a link to one because there are probably some caveats?

arctic basin
#

whole bunch there, look at IT.

tawdry dove
#

Ah, just clearancejobs in general. I thought you were looking at something specific.

#

On USAJobs you have to read carefully because there are so many modifiers

winged rain
#

I've started listening to darkent diaries and I'm trying to solve the puzzle at the end of each episode but I'm stuck. Currently I'm at https://darknetdiaries.com/chessmaster/ with the Mr.Robot quote

candid tartan
#

did you check the background šŸ™‚

vocal wing
#

I guess someone didn’t finish a single episode all the way through

winged rain
winged rain
olive crypt
#

Any CEH study groups ?? Pls reach me @olive crypt

polar basin
#

dafdafg

twin ridge
polar basin
#

m8, tryna b8 me not gonna t8ke that

#

im not afr8

#

1v1 me kid

odd acorn
#

Game recognise game

twin ridge
candid tartan
#

might basketball 1v1 ?

south inlet
#

1v1 in Rust, MW-R

polar basin
#

rap battle 1v1

rough arrow
#

;

winged rain
#

Badapop boomb pow

polar basin
#

you are bad

#

born out of your dad

odd acorn
#

Yeah @polar basin jokes about suicide or dying aren't appropriate here, regardless of how 'fire' your bars are

polar basin
#

I deleted

odd acorn
#

I'm aware

#

But you're clearly not here for the right reasons šŸ™‚

warm plume
#

Hi guys

south inlet
#

Hello

warm plume
#

I am a newbie and I know absolutely nothing about hacking technology, can I learn here?

south inlet
#

Yes.

Give #start-here a read over, then a read of the rules.

warm plume
#

Okay, I don't really understand it, but I will try to learn it.

#

May I ask a rather stupid question?

south inlet
#

No stupid questions

tawdry dove
warm plume
#

Google doesn't answer my question very well

tawdry dove
warm plume
#

I found a scam site, how do I hack into it and bring it down?

tawdry dove
#

Welp wasn't expecting that. Someone will be with you shortly.

civic rootBOT
#

:hammer: Luna628#0049 has been banned.

odd acorn
#

At least they made it easy

tawdry dove
#

Yeah, I wasn't expecting that line of questions at all

timid ocean
#

I knew it he would be banned

#

Something was wrong how he was asking questions

pallid zodiac
echo dust
#

giggles

#

That took less time than usual.

quaint phoenix
#

Maybe he was just naive x) why ban him

astral lark
#

That was impressive

timid ocean
#

But it happens

odd acorn
quaint phoenix
#

I understand he was more grayhat behavior but anyway

odd acorn
#

No matter how could your intentions are, you’re still committing a crime

#

Call yourself whatever, you’re still a BlackHat /shrug

quaint phoenix
echo dust
spark sun
twin ridge
sonic pine
#

I want to punch black hats šŸ™‚

twin ridge
sonic pine
sonic pine
sonic pine
radiant jacinth
frail rapids
#

symmetric encryption should be used whenever suitable and possible, right?

#

considering its safer (especially in post quantum time)

autumn trout
#

I have nginx running on port 80 for gitlab-ce. Problem is gitlab-ce did not install properly (no gitlab-ctl command) and I want to delete it. the process shows as:

root        8316  0.0  0.0  20068  6920 ?        Ss   12:33   0:00 nginx: master process /opt/gitlab/embedded/sbin/nginx -p /var/opt/gitlab/nginx

/var/opt/gitlab does not exist and I have restarted, something is trying to run the process for gitlab šŸ¤” I cannot find any services which run GitLab via systemctl list-unit-files | grep gitlab , nothing in Crontab....

Any ideas on how I can figure out what's actually running this non-existent GitLab command? šŸ¤”

autumn trout
twin ridge
twin ridge
twin ridge
twin ridge
burnt night
spark sun
twin ridge
#

Ok fair, it's mostly ignorance on my part here šŸ™‚

autumn trout
#

this is rather annoying me 😦

#

I am pretty sure gitlab is running with docker because of :

/var/lib/docker/overlay2/2f4cf7bc6cc817e2621d1b7a632e4a4237dc9e4f911853d7bee043972f5821c6/merged/opt/gitlab/bin/gitlab-redis-cli
#

that volume does not appear with docker volume ls, is there like a 2nd docker or something running here hahaha

#
sudo docker ps
CONTAINER ID   IMAGE                     COMMAND             CREATED        STATUS                   PORTS                                       NAMES
98ecc642e8f6   gitlab/gitlab-ce:latest   "/assets/wrapper"   3 months ago   Up 8 minutes (healthy)                                               GitLab

oh????

spark sun
#

that's possible; have you checked the host to see a list of docker processes? could it be a manual start and a daemon both running?

autumn trout
spark sun
twin ridge
#

Oh did they add a user context?

spark sun
#

they added a rootless mode; not sure it compares to the containerd or podman rootless though

twin ridge
#

Yeah ok never got that working properly before switching to podman

mighty echo
#

I liked using podman, but a problem that I had a lot was the docker images being made specifically for being ran as root

#

like the ones from linuxserver.io

spark sun
#

that shouldn't matter, really

#

because of how process ID mapping works in rootless podman

mighty echo
#

Not too sure about that, I kept getting errors like this

/run/s6/basedir/scripts/rc.init: line 20: /docker-mods: Permission denied
/run/s6/basedir/scripts/rc.init: warning: hook /docker-mods exited 126
[migrations] started
[migrations] no migrations found
groupmod: /etc/group.65: Permission denied
groupmod: cannot lock /etc/group; try again later.
usermod: /etc/passwd.66: Permission denied
usermod: cannot lock /etc/passwd; try again later.
───────────────────────────────────────
  _____ __ __ _____ _____ _____ _____ 
 |     |  |  |   __|_   _|     |     |
 |   --|  |  |__   | | | |  |  | | | |
 |_____|_____|_____| |_| |_____|_|_|_|
       _____ __ __ _ __    ____  
      | __  |  |  | |  |  |    \ 
      | __ -|  |  | |  |__|  |  |
      |_____|_____|_|_____|____/ 

  Based on images from linuxserver.io
───────────────────────────────────────

Which refused to work unless I specifically ran it as root

odd acorn
#

Makes sense

spark sun
#

Hmm. Sounds more like whatever the docker-mods are, they are incompatible with podman

#

which means they are aren't 'pure' OCI formatted images

twin ridge
#

Yeah it's probably doing something funky

#

I only had issues with bind mounts and selinux

radiant jacinth
#

Phone always feels much heavier after it's done charging

twin ridge
#

it's a psychological thing šŸ™‚

amber prawn
#

Hey all, I have question. If you don't understand a room, are you going to find answers or videos with explained how to do a task ? Or is that not really a great option to learn, because sometimes I'm confused, and I don't get how to deal with it. So is here anyone who has same problem or is just me ? How I supposed to deal with things, which one are really new for me? I know I'm new in pentest but sometimes I'm just wondering, is just only me or is someone else also šŸ˜…?

unique bolt
#

It's totally okay and common to use videos and writeups to learn new concepts / techniques! If you feel you'd learn more by following along to a writeup or video I think it's worth it, especially since there will always be more rooms for you to do

twin ridge
#

For challenges, I'll try to do some research to find out which app is being used, or try to test a site with various inputs to eliminate possibilities. Payloadsallthethings is nice for test payloads, hacktricks is a solid reference as well

#

It's a lot of exploration and seeing what breaks

steel saddle
#

how come my reaction šŸ‘Ž to the latest announcement has removed ?

#

don't want to start the drama , just want to know

vital vine
# amber prawn Hey all, I have question. If you don't understand a room, are you going to find ...

How much time have you spent trying to solve the task on your own before looking at a walkthrough? If you are jumping to walkthroughs within a few minutes of encountering difficulties then you aren't going to develop the right mindset to become a better hacker. Just be curious, ask "what if I did this?" "how does that work?". Give yourself some time to research the problem on your own. If you feel like you're hitting wall after wall and a lot of time has passed then have a look at a walkthrough, but only up to the part you are stuck on. Try not to read beyond that part and see if you can finish the rest of the room from there. It becomes a more rewarding experience.

vital vine
amber prawn
#

Thanks. Normally I understand rooms and I try to get answers by myslef, but sometimes I'm reading a room and I have no idea what they're asking. Like totally I don't get a subject of the room, and all text and task is like nightmare, and now another question - do I have to remember everything what I'm doing from those rooms ? Is that even possible to remember everything?

vital vine
#

I find the key is to take a lots and lots of notes. It would be impossible to remember every single tool and command because there is just so much to learn. It can feel overwhelming. That's why having good notes is so important. Every time you learn a cool command or useful instructions for a tool etc, note it down.

#

It may be weeks or months before you come across another similar problem and by then you may have forgotten how to use a specific tool to solve it by then. If you note it down, even if you have a vague recollection, you can quickly look it up in your notes rather than having to relearn or spend time researching it again.

#

Use your notes as a second brain šŸ™‚

vital vine
#

Also, if you are finding all the text to be a nightmare, maybe try to find rooms that interest you and are about topics that you find interesting. It will make it for a much more enjoyable experience. You don't have to follow the pathways if you aren't enjoying them. Try some of the CTFs. I like to take a break from all the theory heavy tasks and do the CTFs, then go back to the theory stuff in the pathways when I'm in that kind of mindset.

amber prawn
# vital vine Also, if you are finding all the text to be a nightmare, maybe try to find rooms...

Well thank you for everything, I'm trying my best to remember everything but now I know I have to give myself time, I'm new as a hacker and is normal I think for everyone to be confused on the beginning- everything is hard from start. And I think in my case I have to slowdown and rest sometimes because I'm so hungry of this knowledge and I'm not doing that. Anyway I'm doing notes and I'm learning well I think sometimes I just have to spend more time in one subject and be more focused. Thanks

hoary nymphBOT
#

Gave +1 Rep to @vital vine

viscid cedar
#

hey,'im locked in the page source thing,can someone dm me to help me ?

tawdry dove
#

Press F12 again?

raven delta
#

!notifyme

deft fossilBOT
#

Ok @raven delta, you will now be notified of future announcements.

snow flume
#

Did anyone have any problems in understanding how Network and Routers work? I understood the basic stuff I guess, but I don't know if it's because it's normal for people to not understand how it works or if I'm just a little slow to learn. This is just a question of course, I'll still try to understand. I just wanted to know if anyone has/had the same problem I'm having in understanding.

I can't really understand everything or somethings just by reading, with images is much easier XD. But the fakebank thing was nice and simple and I understood that much easier then a guy explaining step by step. If you have any tips for me in learning things that are hard to remember or focus please let me know. I was thinking of taking notes but I usually copy everything since I believe everything is important or sometimes I over-explain to myself so I can understand weeks later if I forget, or Putting the Network video on loop while doing a workout or just playing a game. I tried watching the video, and I did. but still nothing much.

echo dust
scarlet moth
fresh temple
dusty canyon
#

Does the recent change in subscription price also affect the annual subscription fee?

south inlet
#

Yes

gilded jetty
drifting tusk
# fresh temple Well, there are different learning types some are more visual, some accoustic ma...

You are not a visual learner — learning styles are a stubborn myth. Part of this video is sponsored by Google Search.

Special thanks to Prof. Daniel Willingham for the interview and being part of this video.
Special thanks to Dr Helen Georigou for reviewing the script and helping with the scientific literature.
Special thanks to Jennifer Borgio...

ā–¶ Play video
#

just because its a really well-made video and people here are probably into those sort of things

echo dust
#

Vertitasium is great.

radiant jacinth
#

"Until 16 seconds ago you were not aware there was a honeypot, this does not inspire confidence" - White Rose

radiant jacinth
sweet cape
#

@vital vine how do you take notes ? I'm interesting to do that because i always lost the name of the tools, their syntax, etc

wanton bridge
#

obsidian

#

best note taking app

sweet cape
#

Thx

inland portal
#

hi ! Just a question
Did they just changed the room OWASP top 10 for OWASP top 10 2021 for the "complete beginner" path ?

#

they swaped the one created by ben for the one created by TryHackme

serene trench
#

You can still find the old OWASP Top Ten by searching šŸ™‚

ionic field
#

I was wondering why my progress got reset. I was thinking about resetting it and taking notes before it switched, so it tripped me up to see it already done with no memory of doing it myself

inland umbra
#

i was kinda surprised as i was just finishing the juice shop when the switch happened

serene trench
balmy plover
#

Hi guys, fairly new here, so excuse my noobishness, so picture this senario where all of your clients sites are getting hit from muiltiple aws ip range to from Ashburn VA, to Florida, to Germany, their primary objective is to crank up our websites bounch rate and when u got static ip from multiple locations coming into ur site and leaving, it starts to hurt our ranking over time, so I did some homework to pinpoint their ips

odd acorn
#

Whhhhh

#

Wait, what are you trying to do exactly? @balmy plover

balmy plover
#

Block those ips so that the bounce rate on our clients site dont take a hit

#

because client is freaking out about it

#

so I got cloudflare but I wanna take up a notch and got AWS server on the same IP range (n-virginia) ashburn

odd acorn
#

Mass blocking IPs is an option but you might be blocking official clients

#

Cloudflare should be load balancing everything fine

balmy plover
#

Ya but dont u think it would be fun if we can make their entire setup into botnet

#

and use arp dns poisoning against them idk

odd acorn
#

And straight into unethical hacking

#

Nice one

balmy plover
#

lol

odd acorn
#

I'm not laughing holmes

#

If you're the owner of the company, I would recommend performing R&D into how other companies handle this type of thing

balmy plover
#

If u hear the whole story and how long these assholes have been trying destroy all of our clients site

odd acorn
#

If you have cloudflare the worst thing they'll do is increase the load time while cloudflare tries to manage for the attack

#

If your website is getting defaced, that's poor security on your behalf

balmy plover
odd acorn
#

Do your company know you are outsourcing your knowledge to Discord?

mighty echo
#

🤨

balmy plover
#

is a scammy company who has been doing all then can to take out our clients site

odd acorn
#

And? Follow the proper procedures

balmy plover
#

I call it brainstorming

odd acorn
#

No

#

It's illegal

#

And you don't deserve to be prevailing if you take the nuclear option

balmy plover
#

So if u were on our shoes what would you do?

#

what would be the best rule of thumb or best practice in this types of cases

odd acorn
#

Speak to cloudflare about how they can protect you as a company, don't outsource to 19 y/o's in a Discord server, learn proper security practices, read upon law to ensure that you are not breaking it, research in reporting companies for breaking the law, get a legal team

mighty echo
#

how does one go about getting a 5 star rating from google

warm peak
tulip bridge
#

james bond 007

warm peak
#

tbf both websites kinda look like scam websites šŸ˜„

civic rootBOT
#

:hammer: james007#4103 has been banned.

odd acorn
#

I hope they wrote that down

tulip bridge
#

bro what is this site 😭

warm peak
#

would even say that his "company" is the most fake looking

tulip bridge
#

My favourite part,

snow tiger
#

any tips for a 17 year old freelance beginner

inland umbra
#

don't begin freelance, caused me years of misery, even though i was in a different field

#

one that can cause less damage, so if you MUST do freelance IT Security, you better have REALLY good insurance

sacred sandal
spring carbon
#

Suuuu

snow tiger
spark sun
#

Do not advertise here.

edgy ruin
#

hii

static flax
#

why i can't connect to the vpn?

#

2023-05-11 16:43:12 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2023-05-11 16:43:12 OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 5 2022
2023-05-11 16:43:12 library versions: OpenSSL 3.0.5 5 Jul 2022, LZO 2.10
2023-05-11 16:43:12 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2023-05-11 16:43:12 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2023-05-11 16:43:12 TCP/UDP: Preserving recently used remote address: [AF_INET]3.248.120.204:1194
2023-05-11 16:43:12 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-05-11 16:43:12 UDP link local: (not bound)
2023-05-11 16:43:12 UDP link remote: [AF_INET]3.248.120.204:1194

#

2023-05-11 16:45:23 --cipher is not set. Previous OpenVPN version defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2023-05-11 16:45:23 OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 5 2022
2023-05-11 16:45:23 library versions: OpenSSL 3.0.5 5 Jul 2022, LZO 2.10
2023-05-11 16:45:23 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2023-05-11 16:45:23 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2023-05-11 16:45:23 TCP/UDP: Preserving recently used remote address: [AF_INET]54.194.161.223:1194
2023-05-11 16:45:23 Socket Buffers: R=[131072->131072] S=[16384->16384]
2023-05-11 16:45:23 Attempting to establish TCP connection with [AF_INET]54.194.161.223:1194 [nonblock]

twin ridge
odd acorn
radiant jacinth
winter patrol
#

Shh

mighty echo
#

I'd like to have a go at using VMwares ESXi which there seems to be a free license for, however when I try to register it requires a company, does anyone know if there is an option for personal hobby use?

serene trench
#

Jayy's Creations has a nice ring to it

mighty echo
#

okiii thankss!

serene trench
#

No worries, CEO šŸ˜„

mighty echo
#

It's *Sir now

candid tartan
fiery prawn
#

I'm the new guy,

south inlet
#

Hi the new guy

fiery prawn
#

I don't know how to use this software yet.

#

I am studying it

candid tartan
tawdry dove
#

If this is an active CTF, homework, or work we cannot assist. If it's an inactive CTF there are generally approved writeups you can reference of you're stuck.

#

@candid tartan it's not THM

candid tartan
#

ah. it was not here when i reply the (...)

uneven hazel
#

Hey guys I have a question about the Capstone network. How is it possible to create such a network only using virtual machines? Or is there much more behind the scenes than just Virtual Machines when creating such Networks? šŸ™‚

odd acorn
uneven hazel
#

So it's all virtualized?

odd acorn
#

Pretty much

uneven hazel
#

That's amazing

radiant jacinth
#

Hello! I have only been using TryHackMe for 10 days honestly and i am already considering premium subscription, any thought on that I was so sure until I saw the subscription price, I quit my job 2 weeks ago so thats another thing that made me hesitate.

#

I have the money, but I want to spend it very wisely (I am very seiously pursuing a career in Cybersecurity, even applying fo rmasters)

winged rain
#

If money is an issue I'd say hold out on a subscription for now. There is more than enough free content on THM (80% I believe) and you can always subscribe when you do have the financial stability

grizzled coral
#

Hyy gys any pro cybersecurity expert here?

mighty echo
#

@twin ridge

tawdry dove
burnt night
robust nest
radiant jacinth
uneven hazel
burnt night
#

Best not to assume, ask if needed

uneven hazel
#

Alright

robust nest
radiant jacinth
#

Pondering extensively

radiant jacinth
winged rain
#

What's the average timescale (hours, days, months) for the average reconnaissance step in a red team engagement?

south inlet
#

I think they vary, depending on the engagment.

frail rapids
#

why doesn't secure boot have a special mode for entering custom signatures?

#

since a virus can now enroll their own signatures, right?

south inlet
#

You can add signatures to the database in the BIOS.

winter patrol
#

shh

south inlet
winter patrol
# south inlet You ok there?

Yeah, whenever I visit this channel, I feel like I'm in a library or something, the channel name generates a placebo effect.

steel perch
#

Hello!

hasty atlas
steel perch
hasty atlas
steel perch
hasty atlas
#

in the mood for some quiet conversation in the hacker server tonight

hasty atlas
#

just looking over some PDF books, burning some incense, getting ready for bed soon I think

steel perch
hasty atlas
steel perch
#

?

#

Frankly, shut up, you're really embarrassing.

hasty atlas
#

doubt you'd feel that way if something of yours was hacked lol

civic rootBOT
#

:hammer: joe swanson#1234 has been banned.

hasty atlas
civic rootBOT
#

:hammer: sped#4157 has been banned.

hasty atlas
hoary nymphBOT
#

Gave +1 Rep to @civic root

hasty atlas
#

wtf were those guys on about lol

radiant jacinth
#

Yayyy the blue snek came

steel perch
#

Because I would like to make it my job.

hasty atlas
steel perch
hoary nymphBOT
#

Gave +1 Rep to @hasty atlas

hasty atlas
steel perch
#

Do you know?

hasty atlas
#

just had to look up where in the world that is haha šŸ˜… šŸŒ

#

believe you are the first person I've ever met from there

steel perch
#

Haha incredible, and where are you from?

hasty atlas
steel perch
hasty atlas
hoary nymphBOT
#

Gave +1 Rep to @steel perch

hasty atlas
#

went up to Canada a time or two šŸ‡ØšŸ‡¦ also the western part of our northern neighbor

steel perch
hasty atlas
#

sounds excellent 😁

steel perch
hasty atlas
#

always awesome to meet new people from other parts of the world

#

I have a very good friend from Estonia who I met online šŸ‡ŖšŸ‡Ŗ I visited him this year!

steel perch
#

Yes me too.

frail rapids
#

is it worth it to reinstall the os for the vm every year due to updates?

#

or is a simple apt up{grad,dat}e enough

fervent escarp
#

p

timber seal
#

Hallo

elfin lion
#

hi

steel perch
#

Hey! @primal grove, I really like your way of seeing things, would it tell you to add yourself as a friend to move forward together and why not help each other when we need it?

primal grove
hoary nymphBOT
#

Gave +1 Rep to @timid badge

serene trench
#

@safe musk That's great and all the best with it! But this isn't the place for advertising I'm afraid

robust nest
#

@steel perch hi

steel perch
frail rapids
#

but if bootkits can enter signatures anyway, doesn't that make secure boot useless?

robust nest
steel perch
robust nest
storm pawn
frail rapids
#

how do DFIR folks approach things when the same vpn ip address logs into a personal account and hackerman account of the suspect? I'm currently watching the following and 11:00 raised some questions https://www.youtube.com/watch?v=1fZWHeHICws

In this video I discuss the OPSEC mistakes PomPomPurin made during his blackhat hacking career that led to him getting caught by the FBI.

ā‚æšŸ’°šŸ’µšŸ’²Help Support the Channel by Donating CryptošŸ’²šŸ’µšŸ’°ā‚æ

Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436

Bitcoin
3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV

Ethere...

ā–¶ Play video
#

considering multiple users get the same ip address so one could argue that it are different users

storm pawn
#

so if you fingerprint a system and it's 100 procent the same within a short timeframe, you can reasonably guess who it is

#

mind you, there's a lot of brain and machine power going into getting these high level targets.. average joe buying weed online probably will slip under the radar šŸ˜„

radiant jacinth
#

Ha šŸ˜‚they should just move to a legal state

short elk
#

maybe they'd reach out to some authority who could then subpoena the vpn logs?

soft pier
quartz yarrow
#

i need help in openvpnn

#

Options error: Unrecognized option or missing or extra parameter(s) in Atoz.ovpn:13: data-ciphers (2.4.7)

rugged frigate
#

You need to change the line that says data-cipher to cipher. At least that was suggested a while back.

odd acorn
quartz yarrow
#

i downloaded newer , but still same error occur

odd acorn
quartz yarrow
#

sudo openvpn Atoz1.ovpn
Options error: Unrecognized option or missing or extra parameter(s) in Atoz1.ovpn:13: data-ciphers (2.4.7)

odd acorn
quartz yarrow
#

im trying to update

#

using apt install openvpn

#

openvpn is already the newest version (2.4.7-1ubuntu2.20.04.4).

#

my machine printing this but why?

#

wait let me try to update

crystal latch
#

Hey

#

How can I root my phone ?

#

I hope it doesn't get brick and someone please guide me with their expertise.

odd acorn
twin ridge
#

There are some very complete guides if you look, but modern android phones seem resistant to me, or I'm probably just not understanding something

loud magnet
#

hi! how do y'all take notes? been working through red team path again and doing notes on everything but wondering:

  • do you take notes on everything or just the command syntax? on one hand, having everything would clutter and when you're just looking for syntax it'll slow you down, but on the other hand you have less details about the tool or the technique itself
  • or, do you have separate notes for just commands and syntax and more for techniques?
  • also, if your note taking software has it how do you use backlinks throughout your notes?
winged rain
#

You split them into their functions, then further down into categories if needed. For the actual tool or technique you have title, a brief on what it is and what it's used for, quick useful pointers, syntax, different methods it can be used

#

I don't use backlinks I find it confuses my notes too much, if I need to reference another page I explicitly just say to go find that specific page

short elk
#

how come you don't use the same variable notation for the ip

loud magnet
winged rain
loud magnet
#

ofc go ahead

winged rain
rain vector
#

I absolutely have to take notes on paper for it to stick at all. Just how my brain works. I write down a summary of everything and I have a set of glitter highlighters that I use to color code. e.g. syntax = blue, headings = pink, terms = purple and so forth

rugged frigate
#

Those will be fancy looking notes blobfingerguns

vital vine
# winged rain This is how I've come to organize my notes after much revision:

What program is that? That looks really good! I need to do an overhaul of my notes. At the moment everything is just in a single, very long txt file. Whilst my notes are good, searching through them becomes really inefficient. Just looking for a better solution. Obsidian is at the top of my list at the moment, but syncing it between all my devices would be a pain if I don't want to pay the monthly subscription.

winged rain
#

I also use onenote but I save it locally and transfer it to obsidian because I absolutely despise onedrive

vital vine
# winged rain I also use onenote but I save it locally and transfer it to obsidian because I a...

All my notes are in OneNote too because it was the first note taking system I came across that was cloud based and had an android app. It's been working well for me till now, but as I start getting more and more notes, it's getting very inefficient when trying to look up something on a whim. The most frustrating thing is that on android onenote doesn't have the ability the "find next" - so you can only find the first instance of a word, then the rest of the word matches are just highlighted. Really frustrating.

winged rain
#

Compared to obsidian they are night and day

rain vector
rugged frigate
#

Good to hear. It'll surely improve the experience a lot honk

jolly wraith
warped solar
#

what is the best room to start after finish CompTIA+ Pentest+ room,
red teaming or offensive pentesting ?

mossy island
radiant jacinth
#

Is there any beginner?

zinc rock
split elm
subtle kraken
winged rain
subtle kraken
winged rain
#

That's the full list

#

A-G

subtle kraken
winged rain
#

Nope

marsh wren
#

how can I change this sqli username=Mnzh' AND (SELECT 9970 FROM (SELECT(SLEEP(5)))NKGN)-- iNNr&password= so that it dumps database instead of sleeping

odd acorn
marsh wren
#

a ctf its a local comp and my sqli isnt good i just ran sqlmap and got that

#

its works becuase the page sleeps for 5 seconds when u try login

odd acorn
#

Nah we don't help with competitions, that's cheating

marsh wren
#

alg

vocal wing
#

Level 9

radiant jacinth
#

Great job! Keep it up!

brisk meteor
echo hare
#

also ended up buying the sync so i can study my notes on my phone

twin ridge
echo hare
twin ridge
#

Should be fine then

mighty echo
#

Is the sync automatic or manual?

#

Because the antivirus on other devices you sync too might delete the notes, then sync the deleted notes across all your devices?

winged rain
radiant jacinth
#

"upset the established order and everything becomes chaos"

rich sparrow
rich sparrow
rich sparrow
twin ridge
rich sparrow
twin ridge
#

No worries

twin ridge
#

Notion may have issues with InfoSec notes, particularly scripts

vocal wing
#

The buddha says: Apple Notes is good enough

radiant jacinth
grim rampart
#

When using gobuster on Tryhackme's attack box, I get confused on what wordlist I should use for the situation. I'm not too familiar with gobuster yet, so shat would be a good rule of thumb when it comes to picking a wordlist to use?

odd acorn
#

Most people would probably use the small seclists wordlist.

I usually go Medium wordlist, and after that has finished put a large on in the background

radiant jacinth
#

ALOW

twin ridge
#

dirb big isn't bad either

rugged frigate
#

I go for raft medium most of the time.

twin ridge
#

That's not a bad one either

cloud mural
#

Do you think free version of the site would be enough for getting somewhere?

deft fossilBOT
west jewel
#

Like 70% of the content is free, you can definitely get somewhere

cloud mural
#

thanks for the reply.

west jewel
#

Is anyone by any chance doing the PEH course and in the TCM server? I really don't want to verify my phone number in Discord just to be able to search for my issue, but I can see that anyone who's asked the same question I have is directed to the hidden PEH channel.

stray pilot
west jewel
stray pilot
west jewel
stray pilot
sweet cape
#

hi guys, how are you today ?

rugged frigate
#

cooking to perfection in this climate gosthonk2

woeful gazelle
pallid void
#

Hello guys! I am new to this channel

odd acorn
#

@pallid void Don't promote here

pallid void
#

@odd acornwhere can I?

odd acorn
#

Not in the Discord šŸ™‚

pallid void
#

Alright thanks! blobhuh

sweet cape
hoary nymphBOT
#

Gave +1 Rep to @woeful gazelle

grand citrus
#

@quasi turtle

quasi turtle
hoary nymphBOT
#

Gave +1 Rep to @grand citrus

radiant jacinth
mighty echo
#

Not sure how we would know that šŸ˜†

radiant jacinth
#

Since it is a UAC bypass helper tool, figured there was a chance someone might know, no worries

azure wasp
#

Red team capstone hoodie acquired!

frozen nimbus
soft pier
#

oooh there is a hoodie now??? welp guess shadow gotta try and buy that too

glad valley
#

you alr know i just ordered one

soft pier
#

yeah just hope they keep selling them until monday or so

south inlet
#

Oh no, it's not.

soft pier
south inlet
#

It's there, I'm just blind. šŸ˜‚

soft pier
#

heard from am03bam4n that the ones that the winners got have custom names on them though

south inlet
#

Yeah, that's cool.

soft pier
#

still buying a hoodie in middle of summer when it above 30°C outside might look weird

south inlet
#

...Yup šŸ˜‚

scarlet moth
#

any time is a great time to buy a hoodie

spark sun
#

where i'm at, a light jacket or hoodie should be kept in the car or on you at all times

#

never know what the weather will do

tawdry dove
#

Yeah, I carry a sweatshirt and a winter coat as well as a bed system of some kind

soft pier
#

where shadow lives having access to rain/water resistant clothing is a must

icy token
#

Where I live, it is regularly 35° C+ so wearing a hoodie isn't a very nice feeling

echo hare
#

it was 105 w the heat index and i wore all black and a jacket

summer verge
#

it's 28C here and I'm still have a hoodie in my backpack to wear in the bus and office, people here are really fan of AC an they put it at 18CšŸ˜‚ I'm not fan of AC at all

soft pier
summer verge
autumn trout
#

Looking at getting a rack server, any differences from a normal PC I should be aware? In particular power draw / energy usage?

Want one because it looks cool and I think having a PC is a bit over-kill for my needs (jellyfin, mostly) šŸ˜„

tawdry dove
#

Stay away from blade enclosures

burnt night
autumn trout
burnt night
#

I mean, true. I've got two racks on my new place

autumn trout
#
burnt night
#

Can get newer kit considerably cheaper, towards the low end of that price window on the listing
Let me dig out my list of ebay sellers I recommend

#

I would try to pick up a 2u box as it'll be less whiney, fans can run slower. Probably R720/520

hoary nymphBOT
#

Gave +1 Rep to @burnt night

sage hound
#

can anyone help me to start my career in cyber security and can recommend me where I can start and with what, on youtube there are only few things

ashen jasper
#

and then get on hack the box

frail rapids
#

DFIR folks, do you think that regular criminology (i.e. college mayors) is applicable to the digital side of the things?

tawdry dove
#

Did you mean college major? To answer your question, the only thing that matched up with the Criminology Majors was the investigation process and chain of custody.

#

I couldn't do their work and they couldn't do mine

summer verge
icy token
summer verge
abstract hollow
#

mhm

abstract hollow
summer verge
# abstract hollow mhm

Sometimes in the UK, fresh graduated from cyber degrees are offer placements on the cyber division of the police or NHS (National Health Service) that's a good way to enter digital forensics, because they will train you.

royal wigeon
#

hello

south inlet
tough frost
summer verge
mortal venture
#

Hey @burnt night. I am finally getting into setting up a NAS as I now have a great practical use for it and the only one I know is TrueNAS but I recall you telling me a while ago that TrueNAS Core was a terrible idea and I should not do it based off your own personal experience (if I recall correctly). Do you recommend any alternatives or do you think the trouble is minimal? I just plan to set this up with Plex and Sonarr for home streaming

burnt night
mighty echo
mortal venture
#

The plugins for OMV look really nice but man truenas scale just has way too many features, idk why I wouldn't choose it. The options are nice to have weather I will use them or not

dark hawk
#

quiteee

gleaming timber
#

i have a question how do i exit vim?

candid tartan
#

press esc and then type :wq

radiant jacinth
grand citrus
winged rain
#

Anyone here working for or have connections to CSIS?

vocal wing
soft pier
# gleaming timber i have a question how do i exit vim?

esc
then :wq for write quit
or :q for just quit
:q! for force quit without save
ZZ for write and quit if you are in normal mode
ZQ for quit without write if you are in normal mode
yes the last 2 you just type said letters holding shift

grand citrus
#

I wonder how many different ways there actually are to exit it.

summer verge
lofty token
#

but.. the church of emacs

#

tbh both are a lot better than most web UI

analog jewel
#

hi guys totally random anyone is interesed in ai

#

? is there a platform like tryhackme for ai

lofty token
south carbon
#

Technically, two:

  • using ex mode; that’s :q
  • using command mode; that’s ZQ

Both actually mean ā€œexit current windowā€, but exiting the last window closes vim.
Then, you need to handle special cases:

  • what to do, when the file is modified and not saved
  • what to do if there are multiple windows and multiple files opened.
  • what to do if some buffers are marked as read-only.

The first case is handled by :wq (for writing the modified buffer) and :q! (to discard it) in command mode and ZZ to write and close the window in normal mode (ZQ discards edits). The second case is handled by :qa, :qa!, :wqa and such. Their meaning is obvious when you consider that ā€œaā€ here stands for ā€œallā€.

Finally, there’s :x and derivatives that is roughly equivalent to :wq (and derivatives). Some find it more useful than :wq, especially in vim golf. I don’t consider it a separate command.

You can find more info at https://vimhelp.org/editing.txt.html#%3Ax

south carbon
grand citrus
#

We learn: many ways to exit vim.

serene trench
grand citrus
odd acorn
radiant jacinth
#

Shutdown your laptop

#

Pull the battery out

#

Smash it with a hammer

#

@odd acorn kill the laptop and smash it

devout ocean
#

hello

radiant jacinth
arctic jetty
radiant jacinth
arctic jetty
#

nothing wbu

radiant jacinth
#

Nothing much either .. Listing to Shakira -Try everything

#

WBU ?