#quiet-conversation

1 messages · Page 47 of 1

dusty sleet
#

true sry

tulip mountain
#

beginner advise: If you run into some file type you don't know and it's encrypted/encoded like .asc just save yourself a lot brickwall beating and see if john the ripper has a tool for it.

radiant jacinth
#

and use file

radiant jacinth
#

I tried out mr robot ctf and like I got the first flag easy and I figured this ser the pace of the other flags but I was wrong based on my searching of already shared tips in here on this roomNotLikeThis NotLikeThis

dusty sleet
#

i am now 0x9
i am officially in the "ok" kids league

frail rapids
#

i am now 0xD

#

i am officially still in the "ok" kids league

dusty sleet
#

niccce so I am not even born to be a kid yet

radiant jacinth
#

when 0xE & 0xF

radiant jacinth
#

What's a higher title than God?

quaint basin
radiant jacinth
quaint basin
#

I am level 998 on the site

dusty sleet
quaint basin
west shadow
#

Is using autorecon tool wiser?
as in for nmap and dir fuzzing stuffs?

dusty sleet
lone pivot
radiant jacinth
lone pivot
radiant jacinth
#

And also William Makepeace Thackeray.

old trench
#

hi

lunar pike
#

late hi

bleak breach
#

Even later hello!

tawdry dove
#

Today is a "date that will live in infamy"

#

80th anniversary as well

twin ridge
#

was that Pearl Harbour?

#

I don't remember, Americans were always a little self-centred 😛

tawdry dove
#

Yeah, Pearl Harbor

radiant jacinth
#

no cap!

lyric aurora
#

Shut up

burnt night
flat mountain
#

morning all

dusty sleet
#

What is the name of thm room that teaches the basics of security frameworks ?

twin ridge
#

Which one?

real lintel
#

I wish Attack Box was unlimited until the Christmas. pepehands

quaint basin
#

It is... for subs

pallid citrus
quaint basin
#

It's one of the subscriber perks 🤷‍♂️
That, more content, and faster machines.

rapid summit
#

Or less slow in case of windows vms 🙂

quaint basin
#

Depends what's running on them and what they're bumped to, tbh

#

Like, a lightweight Windows VM running on t2.medium is nippy af

#

That's obviously vastly overkill though, so we don't do that. Most Windows VMs get bumped to t2.small (2Gb RAM) and that's more than enough to make them comfortably fast

#

Unless you forget to turn off automatic updates...

dusty sleet
wintry seal
#

.

frail rapids
#

Need to work on my highschool profile essay but I'm so unmotivated aaa

#

I already answered 2

short elk
#

fix those reds

dusty sleet
#

ia m me

half depot
frail rapids
#

Yesss

radiant jacinth
mortal venture
#

updated me apt repo and half way through this happened to my terminal

#

anyone know why lol. im sure i can reboot and it will be fine im just curious.. Not even sure what to ask google so

north roost
#

gonna guess you are using zsh and your update tried sourcing your .bashrc file

#

try source ~/.zshrc

woven patrol
mild umbra
#

Wow, thanks @woven patrol I’ve had this issue before and I’ve never known how to fix it. :D

hoary nymphBOT
#

Gave +1 Rep to @woven patrol

mortal venture
#

Thank you @north roost

hoary nymphBOT
#

Gave +1 Rep to @north roost

frail rapids
#

Why is TTL described in seconds instead of hops?

rapid summit
spark shale
#

My icmp packet made the kessel run in 12 hops

radiant jacinth
#

NES and SNES creator Masayuki Uemura passed away

#

RIP

#

kringlecon started!

radiant jacinth
#

Yoyo

mortal venture
#

Does anyone know how hashing works? Or any site that can actually tell me. I want to know what’s actually going on but all of my research just says it’s “a one way cryptographic function” and nothing past that. It’s quite infuriating actually.

twin ridge
#

basically

#

also that the function returns the same output for a given input (ie no randomness)

mortal venture
#

Well yeah I know but how does it do that

mortal venture
#

I want to understand the “mangling” that’s going on in The process

twin ridge
#

Depends on the algorithm. Here's md5 for example https://en.m.wikipedia.org/wiki/MD5

MD5

The MD5 message-digest algorithm is a cryptographically broken but still widely used hash function producing a 128-bit hash value. Although MD5 was initially designed to be used as a cryptographic hash function, it has been found to suffer from extensive vulnerabilities. It can still be used as a checksum to verify data integrity, but only again...

#

They generally play with modulo arithmetic a lot

mortal venture
#

BRUH

#

Hours of searching and I didn’t even think to check wiki. I actually hate myself smh. Thank you @twin ridge

hoary nymphBOT
#

Gave +1 Rep to @twin ridge

quaint vortex
#

I have a question about Jobs Board and how to get something in there if anybody could give me a hand?

#

Feel free to DM me and I can give more info =]

burnt night
quaint vortex
#

James! It's been too long. Ty

frail rapids
#

Sheesh I just found my grades from year 7

#

fortnite addiction moment

timber lantern
#

advies negatief 😉

frail rapids
burnt night
#

@timber lantern Please keep it English only. This is part of rule 8.

timber lantern
#

ok , srry

#

i was distracted by these grades

frail rapids
#

My exam week ended a few days ago; grades are looking good but still need to get my English grade

#

had to write an essay on COVID vaccinations FrogeScared

radiant jacinth
timber lantern
#

that was mandatory?

radiant jacinth
#

yep uni work

frail rapids
#

Basically analyzing the impact of COVID on the job maket

radiant jacinth
#

Pretty easy ngl I was inspired 😄

burnt night
radiant jacinth
#

Yep same Lau

burnt night
#

It's at least cyber security related

timber lantern
#

let me geuss: conclusion is more jobs available on job market?

frail rapids
#

Yep something like that

#

I just threw random graphs in there so I looked smart™️

timber lantern
#

lol

radiant jacinth
#

No page limit so I wrote 4 then final conclusion otherwise it'd have quickly become a entire book

frail rapids
#

Ah kek

#

I once wrote a 56 page booklet on python for my CS teacher

#

he promised me a 9.0 or higher if I submitted this as a final exam project kekw

radiant jacinth
#

That's the first I've seen Covid mentioned since joining.

#

Pleasantly surprised it's not a much spoken about topic.

merry smelt
#

Is it just me, or it's indeed scary, when you log in into your e-banking with 2FA and a "We are sorry, the resource cannot be found" + broken CSS HTML welcomes you. Without any outage messages on the bank's site itself.

radiant jacinth
frail rapids
#

Made that when I was 15 and the quality of the booklet itself is bad, while the explanations are pretty good

#

I kind of want to remaster it but I currently do not have the time 🥲

merry smelt
burnt night
#

Hopefully 0 to 10 on a 1 decimal place scale

#

Which is effectively percentage points

merry smelt
#

The question is always: where is the cut? (I.e., below what is a failing grade)

frail rapids
merry smelt
#

thx

tall meadow
#

Hi 👋🏿

radiant jacinth
#

Good morning 🌻

radiant jacinth
#

I had no idea this was a thing paradox

radiant jacinth
#

My switch has Xmas season

burnt night
radiant jacinth
#

looking at this convo made me think about my upcoming grades, btw I'm IBDP. That shit is hard

dusty sleet
#

w my homie

#

drinkin cherry coke < 3

frail rapids
dusty sleet
#

@half fractal first time drinkin cherry coke 🤯🥳🥳

half fractal
dusty sleet
#

it ain't tasty but anything to get accepted into cherry cult

radiant jacinth
#

hi guys, anybody here for a bit of career advice?

spark sun
radiant jacinth
#

Not to brag but thm has by far the best clear and understandable form of explanation when it comes to explaining IDORS. Other resources are really good as well

short elk
#

hello spanish people

#

habla ana

is that really used in conversation?

scarlet moth
#

I think in a conversation that is more formal, I can see it (phone conversation)

odd acorn
#

Duolingo is super formal to the point where you’re alienated in a real situation

rapid summit
#

What, you don't talk about cooks preparing snakes for food?

odd acorn
#

Especially with what I’ve picked up from German, it’s not that similar to how Duolingo makes you learn it.

Which is why it’s always best to supplement Duolingo with another form of studies or research. If you can actually talk to Spanish people often it will benefit you.

tawdry dove
#

Yeah, duolingo and the way they teach German in school is super formal in the US. We had a teacher from Germany my freshman year where we were learning more slang but she left. When I went to Germany, I found out the locals call it "ballroom German"

dusty sleet
#

which is good or bad?

#

what are some walkthrough rooms about pwn tools?

radiant jacinth
dusty sleet
#

yea ive seen that and finished it

tawdry dove
#

It also immediately pegs you as an outsider, which in some cases can be bad or even outright dangerous

frail rapids
#

I didn't want to go overkill with buzzword images

#

especially because my entire essay is this black-white style

scarlet moth
#

If you want to know how people talk naturally, it is best to watch various tv shows, "Nailed it" and "Niquelao" are great ones and get you learning kitchen related stuff, be careful of telenovelas because of overdramatization, but tv shows, movies, podcasts, books, etc will help with natural language... lots of Spanish learning was initially geared at business learners so often there is a formality in there

tawdry dove
frail rapids
#

Yeah it is, I'm using word on darkmode

tawdry dove
#

Oh that's trippy

frail rapids
tawdry dove
#

Do you have a subtitle?

frail rapids
#

Subtitle?

tawdry dove
#

Yeah so my last formal paper was a look into Data Exfiltration. So the Title was Data Exfiltration and then the subtitle was "a look into the methods and techniques used by actors to remove data from your environment"

#

Idk if it was exactly that but same point

#

It's a way to lead people into the paper and generate intrigue. Rather than a mostly white page

frail rapids
#

Ohhh like that

crimson thunder
#

goodmorning

dusty sleet
#

No one :

pwntools:

carmine geode
#

excited for this 🥳

ripe haven
twin ridge
#

:(

bleak breach
#

Oooooo

burnt night
twin ridge
#

I know

rapid summit
#

Don’t worry, It’s still great for rabbit holes.

twin ridge
#

Hmm?

#

Well I think I have an idea for a challenge box but I don't know if it's viable yet

rapid summit
#

now that I think of it, it might be hard to spot if this was used for a rabbit hole.

gloomy cave
#

.

toxic tusk
#

@fringe ocean mind if i drop a dm?

radiant jacinth
#

imagine you are driving through a lonely road at midnight which is notorious for crimes. Now a women with heavy luggage waves for a lift.Will u stop ur car and offer her a lift ?
1 - I will offer lift.
0 - I will ignore her.

#

need it for a survey

scarlet moth
radiant jacinth
#

you know nothing about her but you are also not sure that what if she really need help

scarlet moth
#

and real question, is why are you asking this question here and what is this survey for?

#

and why are you driving through an area known for criminal activity at midnight? are you on your way to a crime yourself?

radiant jacinth
#

here more people are active , so i can get a better response and this a survey for my study of 3 physcological phenomena - Moral licensing , Unknown trust and emotional quotient . That road comes into the route for ur home

#

thats why u have to drive through it

burnt night
#

Asking people ethics questions without an ethics review is ironic

radiant jacinth
#

sorry i can't understand what are u saying . are u saying that i should have a ethics review for it?

quaint basin
#

Basically, yes

radiant jacinth
#

ok

runic raptor
#

@radiant jacinth 0

azure trench
# dusty sleet yea ive seen that and finished it

I hope you liked it! I am thinking about making a sequel sometime, maybe going into more advanced stuff like ROP, leaking stack canaries, etc. I'm almost to Christmas break from grad school, so I may be able to start cooking one up soon. Is there anything y'all would like to see in it?

dusty sleet
hoary nymphBOT
#

Gave +1 Rep to @azure trench

obsidian thorn
#

general chat is being confusing so im coming over here

dusty sleet
obsidian thorn
dusty sleet
#

at least 1 result

obsidian thorn
#

so - 8

#

sorry i meant negative 8

dusty sleet
#

ah yes - self sabotage - my favorite

onyx quartz
#

Port 42069. my favorite from now on.

radiant jacinth
#

Lol

dusty sleet
radiant jacinth
#

Hello dear

#

I am program developer. and how can I get job?

#

I have many skill and experiencs.

rapid summit
radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @rapid summit

radiant jacinth
#

I want to work for a long term with client.

rapid summit
#

Look for job openings. That's the next step. Linkedin, company websites, local forums that list employment opportunities may help with this.

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @rapid summit

rapid summit
#

@radiant jacinth please do not send unsolicited DMs. Look for companies that interest you. Locally, ones that offer remote positions, ones that you might want to relocate to. You'll need to do the research yourself.

hoary nymphBOT
#

Gave +1 Rep to @rapid summit

fringe ocean
dusty sleet
#

A raisin isn't a dried grape, a grape is a moist raisin

dusty sleet
#

Ive just read this company's job posting, what do yall think about it

quaint minnow
#

I know my username but I don't know my e-mail address so I can't reset my password, what should I do?

frail vault
#

Did you use a burner email or something?

rapid summit
quaint minnow
sterile hatch
#

just try all, how many can it be

echo dust
#

Worst case scenario arrEmail = @(email1,email2,email3,email4) fnTryAllResetOptions(arrEmail)... 😄

frail rapids
#

which version looks better? I tried using APA for the first version

tawdry dove
#

MLA is probably one of the better looking formats but that's probably because I grew up with it

#

Also graphs go in its own section

#

I think

frail rapids
#

Ah okay

indigo blade
burnt night
indigo blade
#

Please dear fellow Netherlandian, If you would be so kind to use the APA format for your source disclosure in your documentation, that would indeed be preferable for mine eyeballs and the eyeballs of any reader of thine technoscrolls.

frail rapids
dusty sleet
odd acorn
#

“Rick astley”

dusty sleet
#

yes

frail rapids
#

I call it "pieton"

fiery elk
odd acorn
fiery elk
#

I’m not talking about actually bruteforcing it
I should’ve worded that better. I’m talking about just guessing every email you got until you find the one.

odd acorn
#

There’s a word for that, what’s it called again

#

😄

icy scroll
#

HEY!!!! Go Me!!

mortal venture
#

Hey I have a sort of dumb question, it makes sense to ask in my head but I’m sure the answer is something obvious that I can’t think of

#

Why stop at AES-256 bit encryption? Why not go all the way to AES-65536 encryption or something. I’m sure the answer is simple I just can’t put a pin on it. Maybe a hint? I kind of want to figure this out myself but I’m stuck

spark sun
#

Time

mortal venture
#

OH

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @spark sun

mortal venture
#

I’ve always found it difficult to find a site that can explain and teach bash scripting. Especially Regex examples and explanations. And today while looking up a question I found a good site that explains a good amount about bash (specifically special characters and what they all do). The site is tldp dot org if anyone wants to look. Right now I’m looking at the advanced bash scripting guide it’s a nice read (despite me not knowing any beginner level bash scripting)☠️☠️

#

I was curious as to why most bash scripts ami saw started with random stuff like ‘\n %s #n’ and just seemingly random stuff and I happened upon this site after about 20 minutes of looking lol. I still don’t know the answer but I will after reading for some time 🙂

echo dust
tawdry dove
# spark sun Time

This. It becomes impractical and cumbersome. I don't think AES uses primes but that would be another factor for cryptosystems that do

#

At least if my dinosaur pea brain remembered Cryptography class correctly

radiant jacinth
soft pier
echo dust
soft pier
#

still sounds weird as the standard and definition for aes only defines keys up to 256 bits

echo dust
soft pier
#

well huh

echo dust
#

It doesn't look like a fully adopted standard yet. Wish I remembered where I've seen it.

soft pier
#

still it seems like a good idea to some extent to continue improving on AES.... but shadow is fearful for how we are going to handle the problem of quantum computers cracking cryptos and is unsure which are safe or not in that senario

echo dust
#

Definitely. Quantum superiority is a believably attainable goal at this point. Which essentially means it is an inevitable reality.

And I doubt any classical algorithms will be particularly resilient. Even extraordinarily large private key spaces only offer so much resistance when enough QuBits are arranged to simultaneously test dozens of permutations of 5+ characters at a time.

woven patrol
#

Then there will be algorithms which are designed with Quantum Computation in mind, so as to make it harder for these systems as well to crack brute-force the keys

spark sun
#

Can confirm that AES512 is FIPS compliant.

echo dust
woven patrol
#

It is surely just one among others 👍

soft pier
woven patrol
#

A norm from NIST...Federal Information Processing Standard (FIPS)

woven patrol
brisk grove
#

@mortal venture computation power mostly. If you have a raspberry pi, try to ssh-keygen a 16384 key, you can do it but it will take awhile to create. Also a user with a key that big cause the puny raspberry pi to hang while it processes that giant key

#

if you have powerful computers and security is more of a concern then speed...go big, if you are catering to general public, where speed might be more valuable then security (go capitalism!) then go smaller

spark sun
soft pier
hoary nymphBOT
#

Gave +1 Rep to @spark sun

soft pier
#

ah so they handle standards for use in computer systems that are none miliatry but still connected to the government

#

together with other standard creators

spark sun
soft pier
spark sun
#

Nah, work is done for the day. I still have reading to do but that never ends

dusty sleet
#

ive just read half of Gilgamesh story summary and I am now mad that I didn't know it existed before

mortal venture
#

Can someone reaaalllyy dumb down the path environment variable? I can only find a lot of techy explanations that make little sense to me (sorry small brain 😦 )

#

Maybe I can understand the techy explanations if I can get a dumbed down explanation first? Idk

burnt night
mortal venture
#

Is that a YouTuber or website or something?

#

Sounds like a book

burnt night
mortal venture
#

Oh…… I should have thought of that first lol. Thank you once again James 🙂

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @burnt night

quaint basin
#

It's all there for a reason -- it's foolish to skip over it :)

burnt night
quaint basin
#

Oh. Oops

#

Yeah, I misread that 😅

mortal venture
#

James is correct although your input is always appreciated Muir!! 😄

alpine isle
#

Can anyone point out how to decode this hex to text : '0bd8df'

mortal venture
#

Your question equals a one half fraction though. The website is drag and drop

quaint basin
alpine isle
mortal venture
#

‘From Hex’

#

What did you use? screenshot works also

mortal venture
alpine isle
#

I used from hex the output is this:
.Øß

#

Is that unicode?

alpine isle
plush anvil
#

Freeganism is looks good

mortal venture
covert finch
#

E

alpine isle
#

Is it like missing some field?
I double checked the dropper ps1 file that i got this hex string from this string is kind of like a path component to a url e.g http://c2cdomain.com/0bd8df

mortal venture
#

Why are you trying to convert it from hex🤨

burnt night
#

It's just going to make it harder for others to stumble on it, or potentially work as an ID for something.

alpine isle
mortal venture
#

It’s just a directory what are you trying to get from the name of the directory

alpine isle
#

Any suggestions on what should i do with it cuz I've run out of recipes 😂

mortal venture
#

Do Nothing

burnt night
#

It's not encoded text

mortal venture
#

It’s like how YouTube puts all their videos under directories such as “akfUbU73J” it means nothing

alpine isle
#

So it's like that huh 🤔

mortal venture
#

Typically yeah

alpine isle
#

But the source said it was encoded 🤔

mortal venture
#

What source

alpine isle
#

A ps1 file i got assigned to analyze xd

mortal venture
#

What ps1 file

#

Gonna need some more info man :/

#

Is this for a box? Schoolwork?

alpine isle
#

I'll drop the ss for that file in a few mins

alpine isle
#

I'll post in a few mins

alpine isle
#

snipped a few lines of code so av wont delete it as malware

burnt night
#

@alpine isle Please don't post malware even if it is part of your homework.
Please don't ask for homework help. Talk to your teacher for help first.

alpine isle
#

It was just regular text now explaining the part of code i was lost in.. since i snipped all the functionalities away 😅 and this isn't hw 🤦‍♂️

burnt night
hoary nymphBOT
#

Gave +1 Rep to @alpine isle

mortal venture
azure trench
#

Hi y'all, made some banana pudding a few weeks ago. Meant to post it here in our unofficial cooking channel. I ran out of Nilla Wafers, so couldn't cover the whole top, so I tried a X to spread them evenly. It was still really tasty, it was a big hit at a potluck.

radiant jacinth
#

Looks delicious 😋

frail rapids
#

😋 😋

exotic haven
#

Hey need some help
I was able to login into as a certain user. while poking around i found the authorized keys of another user, now i want to escalate priveledges to that user but i dont know how to go about it

azure trench
#

I hope so

dusty sleet
spark sun
radiant jacinth
scarlet moth
#

and it used to be meth labs, now its crypto mining

radiant jacinth
#

lol

#

I too think crypto is like meth

#

/s cause I don't want any bs from people

dusty sleet
#

funny certificate

#

laugh()

hoary vale
#

laugh track

#

seinfeld theme

mortal venture
#

Hey I’m starting to dabble in malware analysis. Nothing too fancy just getting my feet wet. Right now I’m installing ghidra, should I learn to code first? I understand the very basic things of python and that’s about it but I can’t make any programs or anything more than a few lines of code. Looking for any tips on getting a started. Helpful pre requisites is what I’m looking for 🙂

mortal venture
#

What I’m asking is how advanced does my knowledge of what language(s) should I have to be able to take things apart

radiant jacinth
#

I'm not into MA but according to what I've seen it's essential to learn/have knowledge in C so you can write your own basic program and decompile it to understand how things work in Assembly first

#

tl;dr Learn C coolguy

mortal venture
radiant jacinth
#

Anytime, there is a Reverse Engineering server so if you need an invit you can ping me

radiant jacinth
#

I'll send it in pm if you don't mind, not 100% sure if it's allowed through channels

burnt night
radiant jacinth
#

😄

frail rapids
#

Man I wish I had business ideas

#

I'm an incredibly economic person who's interested in management and marketing but I just cannot come up with a business idea

#

And if I come up with a business idea the SWOT analysis is a big negative

#

Like AI freelancing for businesses
Strengths: I know how it works
Weaknesses: I do not know how to apply it in the real world
Opportunities: There's local businesses who may want it
Threats: there's always some online person doing it for 1$ an hour

radiant jacinth
mortal venture
echo dust
burnt night
#

I can recommend NoStarch's malware analysis book too

mortal venture
#

ooh noted will take a look

#

i will be looking at that also thanks james 🙂

echo dust
#

And from this AoC3 challenge. REMnux looks like a good toolkit after you've done that.
The barrier to entry is a LOT lower than people think fortunately if you have any scripting background.

frail rapids
#

Is reading books the best way to get into cybersec?

#

I'm currently reading cyberjutsu and I like it, but I feel like it's mixing stories with important information

#

Which I don't like, because I want both ones seperated for efficiency sake

tawdry dove
#

It's a supplement to actual work experience

shy badger
#

hi

tawdry dove
#

If you mix personal stories with technical information it makes it easier to understand and remember

frail rapids
#

Hmm I guess you got a point there

echo dust
tribal zenith
#

Hi

burnt night
frail rapids
#

Is the pentest+ harder than the OSCP?

#

When I look at it's curriculum it has waaay more theory

#

IMO the OSCP covers more practical things like exploits et cetera

dusty sleet
#

question for M1 owners, is it practical to get one for pentesting?
I am considering buying a macbook 13 '' I7 intel cpu, should I get that or the M1 for pentesting ?

north roost
# frail rapids Is the pentest+ harder than the OSCP?

haven't taken the OSCP so not really an objective take but CompTIA tests are generally "hard" because of the sheer amount of memorization they generally require, doesn't mean you are more of a pentester than someone with OSCP but it just tests you differently

north roost
strange nest
radiant jacinth
#

I wouldn't take an m1 if you paid me.

quaint basin
#

I would. Been fancying trying some MacOS hacking for a while now

#

As a daily driver? Nope kekw

hoary nymphBOT
#

Gave +1 Rep to @strange nest

mortal venture
#

so you guys know that for example, typing “vim” in any directory will open the text editor? Is that what adding something to the path variable means? I don’t fully understand this but the more programs I research the more this comes up so I really want to understand the Whole path variable bit as much as possible

#

Ooohh while on the subject what do you guys think of this? Close friend said I can get any laptop for Christmas and this was my choice. I plan on wiping it with a red key and installing kali or parrot

#

^^^ pls ping

sinful belfry
#

spend hours on THM with little completion

dusty sleet
#

attacking wise: changing path var and writing malicious programs then renaming them to legit one can lead to a script executing your malicious program cause its the only one with that name in path variable.

mortal venture
#

Interesting thank you

quaint basin
radiant jacinth
quaint basin
#

Literally the only reason I would want one is to practice attacking

strange hull
mortal venture
burnt night
dusty sleet
#

comment on the topic of 13"(inch) laplops vs 16"

strange nest
#

16" would be way too big for me. everything above 14" is just too bulky for working in transit etc. i prefer 12 - 13"

burnt night
#

I used a 12.5" Thinkpad x230 for a while

#

Swapped to a 14" latitude 5400 and I'm happy

dusty sleet
burnt night
#

I went from 15.6" to 12.5" for a massive weight reduction, then to a 14" that weighs about the same or less

dusty sleet
burnt night
#

I personally like 16:10 but I'd never buy a mac

#

Are the macs like 5:4 or something?

wary cradle
#

i personally prefer portability and plugging into screens wherever i can

dusty sleet
#

14" model on far right
13" model on far left

wary cradle
#

oh my god the notch

burnt night
dusty sleet
#

i felt cringe when i saw it but it actually kinda nice

#

i likeit now

wary cradle
#

Probably get used to it. same as with phones

dusty sleet
#

u don't notice it much and if u want u can disable it cutting top bar and everything get shifted down

wary cradle
#

and i suppose it's true black, so you don't notice it much

dusty sleet
#

yess

#

you might disagree on a lotta stuff apple does, but they do make nice screens and thats a fact

twin ridge
#

framework looks nice IMO

#

Apple makes good hardware, but they're way way overpriced

radiant jacinth
pure mantle
dusty sleet
#

ama get 14 inch macbook pro intel í7 and pay my kidney

scarlet moth
#

your kidneys are worth more than that

strange nest
#

so i finally finished the Complete Beginner path (yay). what would you suggest doing next? i think putting all the new knowledge into practice would be best before enrolling in the next learning path. where can i do that best?

halcyon ginkgo
strange nest
#

thank you! i think i am gonna go with defense since i'm pretty interested in forensics 🙂

visual breach
#

//n
"N' bb vb bv vb bv lll[[[[[

earnest path
#

Hey team, I was looking for courses for CompTia certs, and I came across https://stacksocial.com/. Does anyone have any input on that site and it’s training? I don’t really have an issue with paying 600-900$ for the official courses, but this seems dirt cheap to not search about it. Thanks 😁

celest cairn
#

rip moocow, you will live on forever as energy in our bodies

mortal venture
#

And pentesting wise, if lets say a SUID binary has root permissions, i can change its $PATH variable to lets say /bin/sh for example and gain a root shell?

spark sun
#

That's kind of not how environment vars work

mortal venture
#

Sorry for the ping, wanted to include the past convo for context

spark sun
#

so the environment var is scoped to a shell instance

mortal venture
#

so once i close said terminal it resets to default???

spark sun
#

when you terminate the shell, whatever you have set for a env var goes away - such as modifying $PATH

mortal venture
#

so how do programs like VIM and subl text editor work then?

spark sun
#

settings a standard $PATH may look something like this, from a .bashrc or .zshrc file: export PATH = /home/<user/bin;/usr/bin;/usr/sbin

#

modifying that var while preserving the old data: export PATH=/new/path;$PATH

#

by pre-pending your change, the system will look in that area before looking in all the other directories

mortal venture
#

I feel like its on the tip of my tongue but its just not clicking

#

im really sorry

spark sun
#

a binary may set environment vars within the scope of its own execution as well - this is more common with desktop or GUI applications

#

You don't need to apologize, you don't know yet 🙂 asking questions is how you get to know

mortal venture
#

Yeah but i feel like that one guy ya know?

#

Any good sources where i can research this that you would happen to know off the top of your head? I tried researchon my own and its making less sense than you guys are here

spark sun
mortal venture
spark sun
#

This is context-specific to C, but a lot of the idea are transferable

mortal venture
#

If anyone has any more input in the matter please ping as it will be appreciated

brisk grove
spark sun
brisk grove
#

i just did, echo $PATH first so i have an original to go back to, but export PATH=/tmp;$PATH && echo $PATH shows /tmp only

#

and what would you call the process here? the command parser?

spark sun
#

command execution?

pine iron
echo dust
#

Definitely full colons in my path.

#

Semi Colons are commonly "end of line", used so you can run several command sequentially.

spark sun
kind kraken
#

Yep

dusty sleet
#

nope'nt

kind kraken
#

not not !No(Yesn't)

dusty sleet
#

I was looking at the top 50 peeps profiles and this guy caught my attention, I have no idea if he is trolling (to see what I mean go to his website , see his certs and resume)
https://tryhackme.com/p/AFVANMJ

#

main stuff that caught my eyes:
expertise in so many areas
bad english

#

how is this even possible in one year

heady creek
dusty sleet
#

casually

heady creek
#

OS CDeezNuts

#

what even is OSCD

#

is that the new Mac one

dusty sleet
#

no its a subway new menu thing

fiery flicker
kind kraken
#

and maybe he doesn't need English. Think about Kojima, he literally has a studio at Sony and yet he still doesn't speak English.

quaint basin
# dusty sleet how is this even possible in one year

Doesn't really matter: even without the obviously fake certs on it, chances of it being rejected immediately by recruiters are really high.
A) it's cert stacking, plain and simple. Getting certs for the sake of having them doesn't impress anyone, and you can't absorb information that fast.
B) with the number that are there, that is 100% fake. There are 39 certs on that list, including the ones that don't exist and several certs that take at least a month to prep for. To do that you would need to sit just over three exams every month and not fail any of them -- that's about 8 days of prep time for every exam. It's simply not plausible.
If it is real then this individual would have to already be an expert in all of these areas, in which case they would also know about cert stacking, as well as how fake that list looks. It stinks of inexperience, which contradicts that.

#

In other words, don't worry about it. It will do them no favours, and indeed will likely give recruiters a good laugh before they toss it in the bin.

mighty oyster
young thicket
#

Does anyone know how to set up QoS on ZTE router? I understand how QoS works and I know exactly what I want to do. I just don't get the interface of ZTE router. If anyone can help me just DM me and I will send you screenshots of the rotuer settings. Thanks in advance.

dusty sleet
#

My brain can't accept there isn't a ctf in this ad
https://youtu.be/Wav_1mqY5ZU?t=20

Get your hair in the game – glow up with the new Razer Rapunzel Chroma Hair Dye: https://www.razer.com/rapunzel

Razer Rapunzel is the world’s first RGB haircare product that delivers full-spectrum, and customizable per-hair lighting. Impress your fans on stream, turn heads on the streets, and take lighting immersion to the next level. Sign-up f...

▶ Play video
radiant jacinth
#

oh god

lilac gust
waxen sage
#

why?

frail rapids
#

Does an app always react the same to HTTP headers like text encoding?

#

Or can it be altered by a programmer or server type?

dusty sleet
#

i guess it can be altered in server side logic to return different response to clients

twin ridge
#

That's usually accept and content type headers

autumn trout
#

@obtuse marsh do you know if I can implement royalties in ERC-20 tokens?

#

Basically if you transfer the token 5% of that transfer goes to an address is what I want

#

Ideally I want anNFT but with the liquidity of a token I think

radiant jacinth
#

Once you find the email sender's IP address, where can you retrieve more information about the IP?

odd acorn
#

@burnt night :dancedance:

radiant jacinth
#

bro it is try hack me question

#

like i know whoip website

odd acorn
#

How is this a TryHackMe question?

west rain
odd acorn
#

Room URL, task name?

radiant jacinth
#

wait

#

Phishing Emails 1

Learn all the components that make up an email.

odd acorn
#

Task?

radiant jacinth
#

4

odd acorn
#

Ah, I found it.

radiant jacinth
#

I was gonna say I remember doing that task, th header one?

odd acorn
#

I would suggest that in future you format your questions because unverified users asking questions like that is super sketch

radiant jacinth
#

ok

obtuse marsh
short elk
#

bilingual people i gots a question

#

when you read something in your "second" language, do you read it in that language? or do you translate it back into your native language as you're reading it?

burnt night
#

I'm barely literate but from what I understand with learning a second language, it depends how well you know the language. When you're starting out, you often translate as you go but as you get fluent you'll be able to process the language straight up

radiant jacinth
short elk
#

oooh interesting, thank you for that :D

pallid citrus
willow glen
#

English is my second language, but when I'm reading or hearing it there is no translation going on in my head. But other languages that I'm not fluent yet there's more processing, when I need to think about meanings

pallid citrus
#

It's even more fun when you know more than two...then it can be a real scramble sometimes with words...funny how it helps to remember things when it's somehow associated with another language

short elk
#

it's so interesting to me how you can just do that, hopefully i get to that stage within a few years so i can understand properly 😅

pallid citrus
#

Fluency is a big thing

#

For example swedish for me is like so that I can understand it pretty well and even speak to a somewhat good degree, but can't really produce text for the life of me

willow glen
#

Sounds like my Swedish, I understand it, but producing it takes some work

soft pier
#

native swedish person here.... and even for shadow it is sometimes hard and english is easier

#

probably has to do with how much shadow browses the web and uses english

willow glen
#

Sometimes things just feel easier in English than in my native (Finnish). Probably the same reasons spending so much time using English

soft pier
#

almost asked a question in here that would stir up potential problems just now but lets avoid it for the reason of keeping this chat quiet

dusty sleet
#

I do understand english in english for the most part

pallid citrus
short elk
#

maybe i should switch everything up to spanish to see if it helps

twin ridge
#

Well the former, when i speak or write in French or English there is no translation for me.

#

But I grew up with both languages simultaneously so I may be just weird

#

Though my French is definitely weaker than my English

#

Even though I technically learned French first

echo dust
#

That's normal, I know folks brought up with three languages, and within their own community they will constantly string all three languages together to form sentences, without even realising the language switching.

twin ridge
#

That happens as well

final gulch
waxen sage
hoary nymphBOT
#

Gave +1 Rep to @dusty sleet

severe pasture
#

For those that use notion, especially for writeups what are some of the features that you use for both general note-taking and writeups?

stiff oracle
twin ridge
#

Until defender breaks everything when you copy a pho rev shell into your notes

radiant jacinth
#

any begginers hackers that are looking to team up?

#

anyone?

severe pasture
hoary nymphBOT
#

Gave +1 Rep to @stiff oracle

lapis socket
next viper
#

Me too.. I am a beginners

#

🙃

twin ridge
#

probably 😛

remote echo
#

Most of your problems are already solved. I’ve only encountered AV deleting a note once. Set an exception and have never had a problem again. If you think setting an exception is bad then you can have a longer conversation with me where I rant about that. The preview and edit mode is still present but it’s really not bad ctrl + e makes it seamless there is also now rendering directly in the editor so no need really to switch back and forth. By text size I assume you mean headers? Most of those can be easily done using plugins or templates. You just need to spend the little time to get obsidian to meet your needs.

forest kelp
#

Not sure if the is a better room for this... Wondering what hypervisors folks are using. I was using ESXi on my servers and VMware workstation on my laptop but the new minipcs I was going to use have Realtek NICs and drivers aren't getting any support with a vmware fling.

visual breach
#

virtualbox

spark sun
#

I mainly use QEMU-KVM - on my sole windows PC, I use vbox. I'm in the processing of rebuilding my homelab hardware, considering making an attempt at OpenStack but more likely proxmox when I get around to that.

visual breach
#

I would like to migrate away from virtualbox, but tbh, it works and I haven't spent a lot of time researching other options

scarlet moth
#

I like VMware better than virtualbox

steady nova
#

same, but virtualbox is free

radiant jacinth
steady nova
#

ya, but that one ain't as useful as virtualbox

odd acorn
#

Virtualbox for testing and devving, VMware for general use

#

VMware's performance is outstanding

steady nova
#

I use both tho. Workstation Player for a kali machine I use on THM and what not, and virtualbox for labs

radiant jacinth
visual breach
#

will take a look, thx

spark sun
visual breach
#

ooo, nice

radiant jacinth
radiant jacinth
spark sun
#

Hands down the best converter for image filetypes is vbox though. VDI, VMDK can break stuff pretty horrendously, Vbox is the most reliable hypervisor tooling if you need to do a conversion locally

visual breach
#

I don't do a lot of conversions, but I do often work with the UI on the server

radiant jacinth
#

I have my THM kali VM on my laptop in case i need to go travelling and when I plug my laptop into my network i can spin up my VM from the laptop on my desktop for the dual screen comfort.

dusty sleet
#

hi

twin ridge
#

Vbox doesn't play nice with HyperV despite the marketing saying it works

spark sun
twin ridge
#

Not even talking conversions, just having hyperv or wsl enabled breaks vbox

spark sun
#

oh, that's true

#

i have hyperv enabled so little, i didn't even think of that

twin ridge
#

Vmware works though

spark sun
#

until vmware stops working because your enterprise pushed an update that made the current version of vmware stop working

twin ridge
#

That's a different issue

spark sun
#

and you aren't allowed to manually update because even though you have local admin, you are not allowed to use it

#

yeah

spark sun
#

that's most of my frustration with VMWare WS Pro. Broken corp management, not the tool itself

twin ridge
forest kelp
# odd acorn Virtualbox for testing and devving, VMware for general use

Why is vbox better for dev/testing? I haven't used it since BackTrack was a new thing so I haven't kept up with it as a product. Work pays for my VMWare Workstation license so I havent needed to look for free alternatives on desktop side. Just looking into baremetal server options. I get vmware vCenter for free but it lacks support for non-enterprise scenarios. I have two Intel NUCs on order but they have been backordered for 10 months now.

odd acorn
north roost
rough valve
#

proxmox is a type 1 hypervisor, right?

north roost
#

yes

sharp sequoia
#

@burnt night, sorry to annoy you with this ping. Can I have ur help please ?
I would like to unlink my THM account to this Discord account for relink it by another one (@weak halo). Can I have your help, please ?
I don't know who to talk about it, or where, and I see you write on the #general. That's why I ask to you.
It's not urgent, I can wait if you are already busy !

#

Btw, I'm very sorry if it's not the place for asking this. True is, I don't know where to ask.
And I don't want to DM, out of fear to annoying you.

sharp sequoia
#

Oh thanks ! I'm sorry again.

radiant jacinth
#

@brisk grove Back?

dusk pond
#

Hello, as creator Is there any possibility to get a full Chart (charts are max 10 users) ?

forest kelp
odd acorn
#

You should catch up on your sleep if you haven’t been blobfingerguns

forest kelp
#

Probably a good idea. I need to pace myself on rooms. Set a goal of the 365 streak. Cant burn through all the content in a month.

odd acorn
#

I burned through a ton of content in a really short time and all it did was make me irritable, tired but more importantly start to struggle.
I was so burnt out that I couldn't focus on rooms and I was making silly mistakes, started to make it harder to progress.

I took a 3-5 month break because I couldn't get back into it and after all that time I came back into it slowly and the amount I was taking in was massive.
Sleep deprivation and overwhelming yourself with content honestly just sucks the life out of you lol

dusty sleet
#

tldr
slep eat , don't overwhelm or life vaccumed

quaint basin
true sundial
#

Hello, what exactly was advent of cyber event? I missed the same. Will there another one anytime soon?

tawdry dove
#

So the next one will be during Advent next year

waxen sage
#

@true sundial AoC3 and the past ones AoC2 and AoC1 are now just normal THM rooms with a survey of 20-24 topics now. You can still do them. The part that passed was the chance to be in a prize raffle.

frail rapids
#

Is using double hashes a good way to prevent cracking?

#

So basically hashing a hash of a password and storing that in a db for example

quaint basin
#

Only if attackers don't know that it's happening

brisk patio
#

how can i start for ethical hacking

forest kelp
brisk patio
#

thanks

scarlet moth
dusty sleet
#

why does sosumi macos suck so much

#

and how to make it usable

hoary vale
#

I didn't know that existed tbh

#

MacOS kinda hates being run on not mac

dusty sleet
radiant jacinth
hoary vale
#

Main downside for me would be lack of discrete gpu

#

At the price-point I configured I could get a similarly spec'd RTX 3000 series laptop

#

$2,200 for i7 (4.8GHz, 2TB, 32GB RAM

#

Could get an ROG Zephyrus with a Ryzen 5900HS, 3070, 2TB, 32GB RAM, QHD display, for $2,199 on newegg right now

mortal venture
#

why is snort so difficult to install on kali i hate it here

#

imma try out suricata i guess...

#

i mean i guess no one that needs snort uses kali but still jeez man

radiant jacinth
#

Any tips for note keeping while studying. I keep underestimating its importance NotLikeThis

gray jetty
radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @gray jetty

quaint basin
brisk grove
quaint basin
# radiant jacinth Any tips for note keeping while studying. I keep underestimating its importance ...

cc @gray jetty
Notion is gorgeous but leaves you totally reliant on the website being reachable / available.
Cherrytree is brilliant, but starts crashing big time with big notebooks. Also virtually impossible to export out of.
Joplin is meant to be pretty good. A lot of people use Obsidian, but it's less good if you do any Windows stuff because it stores in plaintext that gets yeeted by AV.
Trilium is objectively the best.

radiant jacinth
brisk grove
#

not yet, I have been finishing a project that I was working on before I found THM. Lost my streak a few days ago 😦

#

probably start on it today

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @quaint basin

gray jetty
hoary nymphBOT
#

Gave +1 Rep to @quaint basin

brisk grove
#

the 1st few tasks are basically a walkthrough right?

radiant jacinth
radiant jacinth
brisk grove
#

yeah, THM kinda took over my life on december 1st lol. Since the daily challenges were done I figured I would try and finish up a few things before diving back in

#

about the perl command?
just scrolling through that room atm

radiant jacinth
brisk grove
#

lets talk about wreath in that channel

#

i do the same thing you do. Use an exploit to do whatever, then go back and understand the exploit and in some cases write my own simple version.

dusty sleet
quaint basin
# dusty sleet even in vm?

Anything that isn't baremetal Apple hardware, yes. It must be licensed and installed on an actual Mac to be legal.

#

Even Amazon have to abide by that -- their MacOS EC2 instances all run on Mac hardware.

mortal venture
#

anyone know how to run a cmd command in windows every 5 minutes? having a hard time finding the info on google :/ maybe im just bad idk

#

also on startup. like a crontab but on windows

woven patrol
mortal venture
hoary nymphBOT
#

Gave +1 Rep to @woven patrol

mortal venture
hoary nymphBOT
#

Gave +1 Rep to @woven patrol

mortal venture
#

big step for me

#

ah i came across a small issue if anyone can help. the script works beautifully but now the cmd shell created a popup. any way around this or no? :/

mortal venture
#

cmd

quaint basin
#

PowerShell you can use -windowstyle hidden to avoid displaying it. CMD I don't think has that option or an equivalent

#

There's probably a way to run it in a new session somewhere, or you could write a service to do it for you (or run it under a different account)

mortal venture
#

PS doesnt have output redirection, and i dont know any other way to do this command, but ill look into it thank you

quaint basin
#

It doesn't?

mortal venture
#

i dont think so

quaint basin
#

What format is your script?

mortal venture
#

curl https://urlhaus.abuse.ch/downloads/suricata-ids/ > C:\Program Files\Suricata\rules\suricata-ruleset.rules just a simple curl into a file

quaint basin
#

Oh, then that is very easy

#

Change that to be:

powershell.exe -nop -w hidden -c "iwr https://urlhaus.abuse.ch/downloads/suricata-ids/ -o C:\Program Files\Suricata\rules\suricata-ruleset.rules"```
#

That outta do it

#

Assuming you have PowerShell >4 or whenever they added Invoke-WebRequest -- there are other ways to do it though if not

mortal venture
#

why do i have to specify powershell.exe in powershell hmmm i have so much to learn

quaint basin
#

You're doing this in task scheduler, yes?

mortal venture
#

oh ive been getting that error does that mean i just have to upgrade, yes in task scheduler

quaint basin
#

Task Scheduler executes commands through cmd.
Hm, come to think of it, that will probably still flash up a command window, but not for long

mortal venture
#

i can do some more research, thank you for the knowledge once again Muir

quaint basin
mortal venture
#

oh darn it took you 2 minutes and ive been looking for like 25 smh

quaint basin
#

Turns out there is an option to do it in Task Scheduler. Gotta love Google

mortal venture
#

If I use an IPS and IDS like snort or suricata in a vm can it still capture my host machine? I don’t see why it won’t but I just want to be sure. I want to learn how to properly implement these rulesets and using them on windows is a pain in the ass and has costed me hours and hours of troubleshooting with very little improvement

#

I thought I finally got somewhere with suricata but turns out it needs to be compiled in Cygwin which in and of itself has costed me the past 4 ish hours of troubleshooting

#

Would be easier to just install a centos vm for the sole purpose of learning to use these programs but absolutely zero traffic happens in my current vm’s besides tryhack me and such so it would be pointless if they can’t detect traffic outside of VM’s

#

You know what. I bet I can google this give me 2 seconds

#

Apparently yes but it’s very very complicated ugh

bleak nymph
#

If I expose 3389 for rdp on my home router, would it be likely to get hacked if I used a strong password?

dusty sleet
#

no

#

update everything to latest version

#

also u are already exposed lol

bleak nymph
#

is xrdp safe since its an open source version of rdp

dusty sleet
#

we wouldn't know unless there is a public cve of any of them so either is fine

bleak nymph
#

thanks

dusty sleet
#

ya hala

bleak nymph
#

Not sure if this is allowed but I am trying to do a reverse shell with telnet on my router using routersploit.
But I am not sure how to access it using a backdoor with telnet. I tried nc -lvp 4445 but it doesn't work but I think that is for ssh. Any help?

[] Running module exploits/routers/netgear/r7000_r6400_rce...
[+] Target is probably vulnerable
[
] Invoking command loop...
[*] It is blind command injection. Try to start telnet with telnet telnetd -p '4445'

[+] Welcome to cmd. Commands are sent to the target via the execute method.
[*] For further exploitation use 'show payloads' and 'set payload <payload>' commands.

dusty sleet
#

I think the AoC winners list have a bug

#

my name isn't there 😭

quaint basin
digital spruce
#

brutal haha

dire raven
glacial flame
dusty sleet
warm surge
#

I have a .snap file in my ubuntu . How can I install it?

short elk
dusty sleet
#

Santa brought me no gifts this eve.
I am the grinch on the next one.
https://youtu.be/o_hjXmiJLAw

radiant jacinth
#

Figured out that ssh issue; was my own vpn betraying me lul @final gulch

wary tundra
#

hi, guys i'm a bit confused what does this command do "cut -c 4-"

wary tundra
#

i'm looking at it, the way I understand it since -c is select only these characters is only remove character "4-"?

radiant jacinth
#

Hm :) Look at my screenshot

wary tundra
#

okay, i got it. thank you very much!

radiant jacinth
#

At the output.

#

No problem

wary tundra
#

in man cat
-e equivalent to -vE, what does this stand for?

burnt night
radiant jacinth
#

What are "tickets" used for. I see there are some on my public THM profile

burnt night
radiant jacinth
burnt night
#

No idea. I'm not site staff.

dusty sleet
#

Question:

#

I want :

#

I tried this logic flow and it doesn't tunnel openvpn through the proxy at all:

north roost
#

why do you want to proxy VPN traffic thru Squid? Its more designed to cache web traffic

dusty sleet
north roost
#

I just wouldn't proxy VPN traffic in that scenario at all

burnt night
dusty sleet
burnt night
#

You want to MITM OpenVPN?

dusty sleet
#

not really, what I really want is away to access an openvpn connection through a proxy
be it:
local openvpn packet -> proxy -> destination
or preferably:
local packets -> destinations
local packets that have the destination as the openvpn accessable devices -> proxy that is running openvpn -> openvpn packet to destination

spark sun
dusty sleet
#

What the real REAL problem is the following:
It was a peaceful connection in the land of ogolashia

#

Then out of nowhere a great evil came upon the land,and with malicious intent and merciless eyes struck the connection to the heavens with a great hammer:

#

And since then the people of ogolashia are denied the blessings of the heavens under the rule of the evil ISP

burnt night
#

Don't try and bypass their restrictions. We WILL NOT help you with that. They're in place for a reason.

spark sun
#

I don't even know what you're trying to do, but this narrative makes no sense.

dusty sleet
#

😄

burnt night
dusty sleet
#

to end the story:
A mysteriuos figure appears:

oblique breach
#

Fibonacci blackhat? 😄

spark sun
dusty sleet
burnt night
# dusty sleet answer in next comic 🤠

I'm just going to ask you to stop here.
It's at best unethical and and worst illegal to help you bypass the restrictions. TALK TO YOUR ISP.
If you don't stop, you will be muted.

dusty sleet
dusty sleet
# burnt night Talk to them...

I am trying to talk to them for 4 months now, you can even see that in official emails I sent to thm, problem w my isp is they always let you to talk to customer support only to tell you to restart the router ,no real explanation whatsoever

#

hence why i am asking u

burnt night
#

Then you're not talking to the right people.

#

And again, no asking here.

dusty sleet
#

ok.

frail rapids
#

Does RSA use a key derivation function to generate a public key based on a priv key?

#

Session key = KDF(secret, challenges)

burnt night
quaint basin
#

Go search RSA on my blog

visual breach
#

anyone know of a good tutorial for setting up an openvpn server? I am using a dd-wrt router if that helps?

naive crag
frail rapids
quaint basin
#

@celest cairn Explain thyself!

frail rapids
#

Why is the attack up to chance? I thought it was all cryptographic and thus be just math and thus be not up to luck

celest cairn
#

probability still plays into it which is the element of luck

#

you have a 50/50 chance to win a game of heads or tails, but theoretically, you could never win

#

the same kind of thing happens here.

frail rapids
#

Ahh okay

#

I just went back and read

When an attacker sends a message only containing zeros with the IV of zero, there is a 1-in-256 chance that the Ciphertext will be Zero.

does it have to do with this?

celest cairn
#

yep

#

that's exactly it

#

that was the programming error on Microsoft's end that caused zero logon

#

that 1/256 chance

#

chance isn't the right word, I dont think

#

page 4 and 5 has the specific details that I don't recall right now

frail rapids
#

Ohhh

Using AES-CFB8 with a fixed IV of 16 bytes of zeros, Tervoort discovered there is a likelihood that one of every 256 keys used will create cipher text that has a value of all zeros. This is an exceedingly small number of keys for the attacker to try to create cipher text of all zeros. It would take just a matter of 2-3 seconds, at most, for the hacker's computer to do this.

#

wait so it's just trying to make an int8 or whatever 00000000?

celest cairn
#

I think so

frail rapids
#

hence the 2^8

celest cairn
#

it's been so long since i've looked at the exploit lol

#

theoretically, I think Zero Logon is still possible, but the odds of it are just so low

frail rapids
celest cairn
#

unless they've written an exclusion for all zeros

frail rapids
#

Welp now I finally understand what IV does in AES

#

so that's that KEKW

celest cairn
#

alls it takes is for cryptography to be explained by someone who knows what they're doing lol

#

I barely do

frail rapids
#

Really fun and interesting room!

tawdry dove
#

Cryptography is hard for my pee brain

#

I cried all the way through the course

frail rapids
#

I really like it. I'm planning on reading a crypto book after finishing cyberjutsu

mortal venture
#

obviously security but I mean.

digital spruce
#

sec+ is just book knowledge

#

like "which is better, des or aes" and "looking over someone's shoulder to look at their screen is
a.) bluesnarfing
b.) water hole attack
c.) shoulder surfing
d.) bring a jerk"

tawdry dove
# mortal venture How difficult was the sec+ and what was it about

What's on the exam is well documented by Comptia, so I suggest taking a look at their syllabus. Professor Messer's videos, Get Certified Get Ahead, and Dion's quizzes are all excellent study resources. I was nervous for the exam, procrastinated, and then hardcore studied for a week and passed. Forget the actual score but it wasn't bad. I also have a degree in Computer Security so much of the exam was a condensed recap of everything I had learned.

tawdry dove
#

I also had an abnormal test experience where I got something like 7 or 8 PBQs. Which was not fun

mortal venture
#

Man i studied for my a+ like a year ago I forgot abt professor messor lol

#

Thanks man

hoary nymphBOT
#

Gave +1 Rep to @naive crag

frail rapids
#

Mann I wish I could get a job with just CTF experience

#

Sucks that you need college and uni certs for most jobs

gray jetty
#

more sarcasm

burnt night
visual breach
burnt night
#

My company are but we're south coast UK and no remote work for probation period

visual breach
#

we're a remote company, but that unfortunately means it's really easy for us to fill positions

short elk
#

unfortunately?

spark sun
#

Hard to bring in specific talent when you can draw from the entire country

short elk
#

would that not make it easier?

#

more of a selection?

spark sun
#

The talent pool you can draw from is much larger - unless your specific candidate is already top tier, it's hard to justify "we can bring in this guy I know, or we can bring in a nationally known expert for the same role"

short elk
#

ohhhh

#

i thought you meant specific as in like "we need an analyst that does x,y,z with a,b,c"

frail rapids
#

I just had my first beers ever 😎

#

time to be an alcoholist

summer verge
odd acorn
#

It’s vodka time

hoary vale
#

moonshine, because it ain't alcohol unless your car treats it like E85 fuel (not even kidding)

#

god bless america

twin ridge
#

:p

#

Doesn't make it less true though ;)

summer verge
odd acorn
#

Moderation is out of the window, it’s party time

summer verge
twin ridge
#

Bit young, but it has the punch of the syrah that goes well. Really wish I had deer though

rapid summit
#

I have Ca' Del Bosco Franciacorta.

twin ridge
#

:o

#

Arhu send caribou!

rapid summit
#

! There you go.

#

I'm pretty sure I could find some reindeer jerky, if you like that 😄 That'd even survive mailing.

twin ridge
#

Hehe

rapid summit
#

Looks like that's available in a local supermarket, even this far south.

frail rapids
#

this is the moment where my prefrontal cortex is going to commit not alive

gray jetty
#

Just saw that 0day has no certs at all, is that for real or did he not just add any here?

quaint basin
#

He told me to remove his cert roles a while back. He just doesn't like people knowing what he has 🤷‍♂️

gray jetty
#

Oic

winged rain
#

Has anyone watched mr.robot season 5?

radiant jacinth
#

According to the officials, season 4 was the last season of Mr. Robot and there will be no more season 5

frail rapids
#

Does anyone know if there will be more AD rooms released because of the OSCP changes?

#

^to the red team path as well

radiant jacinth
#

how can i verify myself

gray jetty
#

!docs verify

deft fossilBOT
gray jetty
#

dm @deft fossil with !verify <discord token>

#

token is on you thm profile

frail rapids
burnt night
#

-ban @rotund rose -ddays 1 Piracy shit

hoary nymphBOT
#

🔨 Banned outis720#3376 indefinitely

frail rapids
#

typo kekw

kindred lily
#

Guys i need help yesterday i lost my streak it was around 50 the reason why is because i was doing CEHV11 exam and i was revising all day so I completely forgot about the streak. My exam was 10 pm yesterday

#

I passed it with high score, easy one

frail rapids
#

email support

kindred lily
#

Could u type it here pls the email

quaint basin
#

Rude smh

kindred lily
#

Why rude ?

quaint basin
#

LMGTFY is.. sarcastic at best and insulting at worst

#

!email

deft fossilBOT
quaint basin
#

Enjoy

kindred lily
#

Sorry for that but really i am not concentrating because i am in an emergency situation in my family

#

Thank u so much

quaint basin
#

I was replying to Lau

mortal venture
#

does anyone here use suricata? im having an issue adding my own ruleset and despite following their documentation i seem to be doing something wrong

tawdry dove
mortal venture
hoary nymphBOT
#

Gave +1 Rep to @tawdry dove

short elk
#

another spanish question from me xx

how big of a deal is ser vs estar? if i accidently use son instead of estan, can the sentence still be understood?

eg. duolingo says los boligrafos estan a la izquierda but i would probably without thinking say los boligrafos son a la izquierda

frail rapids
#

this is a regular FM radio channel

tawdry dove
#

Interesting. Are you currently tuned to that or?

frail rapids
#

Yeah

frail rapids
#

the weather is normal with just a bit of wind, and the antenna is working as it should on other frequencies

soft pier
#

would like to answer microwaves in a microwave oven but dunno if that frequency line up with normal FM radio.... at least it lines up with standard wifi 2.4 Ghz

frail rapids
#

this is so incredibly vague

tawdry dove
#

some docs said the red is what you're currently tuned to but I'm not sure if that's the same red line

#

I didn't have any pictures

frail rapids
#

oh

#

yeah no the color scheme is basically blue to red, based on the strength of the signal

#

so background noise and weak signals are blue while high quality commercial radio stations are red and have strong signals

tawdry dove
#

Is the radio station overpowered?

frail rapids
#

Doubt it kekw

#

that signal with the issues is the strongest signal, though

visual breach
hoary nymphBOT
#

Gave +1 Rep to @naive crag

regal jetty
# short elk another spanish question from me xx how big of a deal is `ser` vs `estar`? if i...

Ser vs. estar is a big deal in that they have fundamentally different meanings and roles (contrary to the common glossing-over, they're not simply options on either side of a boundary between a "permanent" and a "temporary" attribute)
But at the same time, not a big deal in that, because they are fundamentally different, native speakers don't confuse them and don't have to think about which one to use.

Using the wrong one would be similar to when a Spanish speaker makes the wrong choice between "do" and "make" in a situation where they would say hacer. It will generally be possible to understand your intention from the context, but it will be initially confusing

signal hull
#

Every language tends to have intricacies that are easily lost on non-native speakers, but are fully natural and make sense to those that grew up with the language

summer verge
winged rain
ripe haven
#

Can anyone recommend a sous vide set for like 100$ (preferably from amazon, no need for a vacuum machine thingy)

twin ridge
frail rapids
short elk
hoary nymphBOT
#

Gave +1 Rep to @regal jetty

short elk
short elk
torn tulip
summer verge
# short elk yes i’ve learnt a lot from it, and because i like the language and would like to...

Great! I’m always curious. Spanish wouldn’t be my first choice if I didn’t speak the language that why I asked. I had no choice Spanish it’s my mother tongue but not a language that I particularly like. Don’t get me wrong I don’t hate it, but it’s not a language that I’d put effort in learning if I hadn’t already known it. Asi que si tenes alguna pregunta o te puedo ayudar en algo escribime

frail rapids
#

What's a good tool to analyse authentication codes from modulated RF waves?

#

I'm currently messing with Audacity but it doesn't allow for any guide lines etc

regal jetty
pure citrus
#

its sus in here

#

lets hack evil corp

twin ridge
#

Yeah Nah, lets not start anything black hat here

winged rain
#

That's just what Elliot imagined it stood for

soft pier
#

lets all go hack the gibson

#

in the game that is named hacknet

radiant jacinth
echo dust
soft pier
#

nopes

#

and already spent the christmas money on other stuffs

radiant jacinth
#

Isn't it free?

soft pier
#

¯_(ツ)_/¯

radiant jacinth
hoary vale
#

I downloaded that a few days ago but I have yet to launch it

soft pier
#

another problem is that shadow kinda lacks the time management skills to set up time to play games nowadays

dusty sleet
frail rapids
#

lau suffers from similar problems

waxen sage
#

Sometimes planning time for play is helpful. It schedules time for rest and keeps play from distracting work.

zealous pasture
#

FYI, this phishing attempt was sent to hundreds of users. The "Discord Staff" user and I were in the same discord "The Isle Official Discord".

quaint basin
dusty sleet
burnt night
soft pier
#

doubt that website is a good idea to visit

frail rapids
#

I visited it