#quiet-conversation
1 messages Β· Page 48 of 1
hmmm yeah looks safe enough after checking their website a bit
tfw you go to someone's webserver and they don't even have an X-Clacks-Overhead
TIL that's a thing
Just had a discussion with a professional web developer about CORS
the dude thought that CSP was CORS 
Tbf CORS is a pain
pain us being a smoker and not finding cigarettes
Itβs a good time to quit.

Smoking bad. Thanks for coming to my ted talk
atdot@atdot.com
wwuu.example.com
The password is "SeeToEatenASICS-DashADateUnderscore_SeedySeabeeSemi:ForayToAwaitInnate"
why not just base64 encode "password" and be done with it
Oh no sorry I forgot I changed it the other day. Now it's "OscarZeroMikePapaTwoNinerEchoBangFiveTwo"
I was cringing at youtube shorts and came across this https://youtube.com/shorts/YOJqJv_G3lQ?feature=share
How to activate Windows God Mode! Here's what you should name your folder: "GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}"
How does this open the control panel?
Does it have to with the extension?
@summer verge hiya :D iβm confused here, why itβs del and not al?
and this instance is al
He's more literally saying the hospital is "a short distance from ..." but such things are often reoriented in a proper translation
It calls contraccion sometimes instead of a el you put al and de el you put del
The contractions AL and DEL in Spanish and when to use them
yeah i learnt that, but in the first example to the park would be translated as a el parque which becomes al parque but it was del parque which is why i was confused
but the image that charlie sent above clears it up, a short distance FROM THE which now makes sense to me to use del
wiktionary
es.wiktionary.org specifically -- you could look up 'cerca' on en.wiktionary.org, and this English Wiktionary has a substantial entry for 'cerca' in the 'Spanish' section that does nothing to clarify the usage lol
hmm i might need to set mine to spanish
ahh yeah lol i'll go to es version now
sweet i think that'll help a lot in the future thank you both π
@burnt night @smoky mortar
$600 you can find a decent card , not the latest but i think you can do almost all rendering jobs you have
@pliant thunder No.
Begging is not appropriate here.
Gracias James
me , thinking they were looking for help with graphic card π
I mean, gofundme
Back in grade 8 we started a GoFundMe for one of our friends to get a PlayStation
We got like 5 dollars
Wait I might have the video we used for it
Some strangers sent us 5$ over this shitpost
I don't understand why humble bundle sells this vegan related content while the tech related bundles sell twice as much
Ooooooh. Thanks
Gave +1 Rep to @frail rapids
I'll be yoinking those
No problem 
Also, to answer your question: Because they see the nobility and importance of the cause and choose to try getting more people into it π€·ββοΈ
Ahhh, like that
"Try Vegan" sounds like it'd be good for me too, in terms of starting out with vegan cooking
@quaint basin @quaint basin @quaint basin
Heavy metal vegan cookbook
Please tell me that's in the deal I'm about to buy
The Β£7.54 level
Cool. I'm getting them all 
I'm probably going to pick it up too
Is this somehow related to Vegan Black Metal Chef?
No clue
VBMC was a pretty entertaining channel back when it first started. I enjoyed the puns, such as "Heil Seitan"
And it didn't overdo its run.
Sounds... interesting
oh my, it's more than ten years old π
bloody american recipes in bloody american units and unobtanium for ingredients π¦
I think vegans have a noble cause, but I like meat
Okay, so, TL;DR: you murder innocent life because you think the taste is more important. Gotcha π
Are we crucifying meat eaters in here today? What a development lol
Without even being so extreme, you can cut back on animal products and still eat nice steaks
i do
In all seriousness though, I've come across plenty of amazing vegan dishes
to an extent
there are a bunch of very tasty vegan meals, but meat is a crucial part of my diet
A project committed to dispelling the prevailing myths about what it is to be vegan.
Enjoy
okay
Very passionate I see, nothing wrong with that. Make this yourself? Looks nice and easy to navigate!
Nah -- I just keep a shortened link handy because I can never remember the URL π
That answers most of the questions / arguments I ever hear. Saves me repeating myself
fair enough
Any of the articles in there π
ok
Ingredients?
Man I just peeked at low level C++ code I wrote in august for... things... and it's horrible
pointers statically defined as variables in classes where they're used
oneliners, custom function signature parsing, etc
Ithink I'm going to rewrite it
You've gotten better! Congrats!
That image shows the next rank. π
hey im having some trouble installing literally anything. From my research it looks like my source list is the issue but even after clearing it and running sudo apt update && sudo apt upgrade i cannot seem to install any packages. I have been messing around with my system trying to properly install / build and configure a few programs, if that helps at all.
here are the few errors i keep getting
E: Package 'git' has no installation candidate this is the error i get trying to install any package at all
please ping and thanks for any help in adavanced
If you've done installed any PPAs, they may not have an update for the current kernel version you have installed. Look into using the dkpg and dkms tools if you haven't seen them yet
ah thank you ill look into that
that is what i did at some point, i kind of just followed along some documentation for installing a program without fully understanding what i was doing so ill look into it. thanks again
ah it seems i have already removed all PPA's without knowing i did. according to Stack overflow PPA's are stored in sources.list.d which i have cleared multiple times and then ran sudo apt update this has not solved the issue π¦
What kind of RF signal is this?
and how can I decode it to digital/binary/serial data?
lemme ping a friend
Just from the pattern it reminds me of GSM interference, I don't really know but I'm posting anyway cause it'll be funny if I'm right
Alright
horray
beyond burgers go brrrrrr
Slightly more expensive, but worth it.
Taste exactly like normal hamburgers, with the same juicy texture, only difference is that they aren't made of meat ^^
Beyond burgers are nasty
You can't just take eggplant and call it a burger that's not how it works
then you ate a vegan burger
huge difference
the new Gardein ultimate burgers are so meaty, I don't think I can eat them again...
like I didn't care for beyond burger, had a weird taste
That's not beyond burger
https://www.beyondmeat.com/en-GB/products/the-beyond-burger they're a company.
Beyond Meat burger patties are the iconic plant-based burger patties that put burgers made from plants on the map. They're everything a burger is.
Oh well look at my ignorance
They had something in burger king called the beyond burger though I believe don't think it's the same
The Impossible Whopper?
Impossible is a separate company doing similar things
Still not a slice of eggplant
Still not eggplant, but yeah that's a Beyond Burger
Whatever it was it didn't taste very yum yum
I've had meat burgers that weren't really good.
I've had excellent ones made with Beyond, and at best mediocre ones as well.
I hope another humble bundle drops today
hopefully tech related this time
2 bundles expired yesterday and 1 bundle got added
I'm thinking about picking up the math bundle for 15 dollars but it's a tad expensive
I still haven't read the books from the last bundle I got lol
except the hack like a ghost one or whatever it's called, that one is good so far
Same
but I like to collect them in case I have spare time in the future
I'm currently at page 100/250 of cyberjutsu
I like to use them as in-flight reading when I'm traveling lol
I'm going to florida saturday, will probably read a sec+ study guide or something
Sounds interesting. are you going to take the exam or are you going to study it because the material is worth a read?
I'm planning on going for Sec+ and maybe PenTest+ at some point this month.
traveling, what's that?
Nice! Both in one month is a doozy! Good luck!
I've got a PEN-200 (OSCP) exam voucher due in February 
My sleep schedule is in danger
jesus then the OSCP?
then failing the oscp yes lol
holy camoli
I might get a lab extension for that one though
lol. Hey at least you experienced what it was like so the next time you go for it.... it won't be as intimidating lol
All I have is the Project+ and CYSA+ coming up
yuppers
This soup is fantastic ( Ignore the detox buzzword. Silly people)
I saw the link and preview only, and was just about to comment on detox π
lol yeah, I ran across it before doing my grocery shopping a couple days ago and rolled my eyes but it looked pretty good so I tried it and it was ha
awww man, i love lentil soup
Also show your version!
Is infosec still in a job shortage?
Ah
I was wondering because software development makes apparently more money while infosec should be harder and I've never heard anyone talk about a shortage of manpower in swdev
There definitely is a shortage in sw dev as well.
Agreed. manpower deficit in cyber gets talked about more, because it's a much larger deficit than dev.
And I wouldn't say sw dev makes more. It makes more in top paying companies for sure.
Feel like SW Dev gets talked about more salary wise too. Tons of YouTube channels and bootcamp ads
Even folks from the remote corners of the world like me get recruiters to reach out for them. π
Also feel like it's more common to start in SW than it is to go straight into Cyber, which results in it making entry job lists more
I think dev is also more immediately accessible than security. SDLC is just one domain, and devs don't really touch network or infra unless they specifically seek it out
Better wording than mine lol
True. And some of the recruiting and interview processes seem to be gamed. I'm not sure they really measure potential success at all.
That's also true. A good dev interview demonstrates the candidates ability to reason and problem solve, not necessarily that they get to a perfect answer
Too many devs, I think, focus on getting 100% and not hitting that 80-85% good enough to move on to the next thing
Reason, solve the problem and tell what they're doing
The bootcamps concentrate on the leetcoding part π
A fun case I heard about was a hiring manager wanting to get someone hired for their special skills, but they couldn't, as the person wasn't good enough in the hiring game. The role itself didn't require certain aspects needed in the hiring process.
or are particularily masochistic...
devops!

I suck at interviews π¦
I guess that's something you have to practice for.
Expert advise from someone that has been working in the same company for 10+ years π
yeah I'm bad at that too...
hi bad at that too...
bonk.
Thats for horny, bad at that too...
wish windows machines(THM ones) wouldn't be so laaggyy/glitchy to use!
Its a drag when there's a complete room to be done exclusively in a windows attackbox
"perfect is the enemy of good" or "... done" plus forgetting to communicate / not knowing that failing to communicate when you're stuck only loses you points in the interview and on the job. Coming from a serial long-ticket offender who tries to drill down like I'm the last person who could fix the issue :p
have u tried VIP ?
YES
I have premium and it's still an absolute pain
I wish the admins would allocate atleast double resources for the windows attackboxes
considering it's probably a small percentage of active attackboxes I wouldn't see why not
would make a huge different in UX
Windows is what lets thm down, between resourcing and boxes dying after 1 hour it really does act as a deterrent
The thing about #feedback-and-ideas is that you can't discuss feedback and ideas with users so you can elaborate etc. I'd like something like discords' feedback forum for THM
Actually, I guess I'll throw that into feedback as well
Problem with the feedback chat is that staff arenβt active enough to be able to keep up with the chat and having to comb through it constantly is time consuming:)
Itβs a long one and gotta zoom in but I feel like Muir will enjoy this one
Tbf, a lot of that is AWS screwing with the licensing. That's why they die after an hour and throw off their resource bumps: they fail to activate their licenses on boot.
There's supposed to be a solution incoming, but π€·ββοΈ
Seen it, but thanks π
Gave +1 Rep to @mortal venture
rip
Are they workspaces or just little VMs
Oh, license on boot, is an EC2 thing I guess? I played with workspaces but not sure if they have seamless licensing or what
Yeah, EC2 AMIs
Is exporting the images ever going to be a viable option? I'd be willing to run (my) sims on my own stuff if there were some way to authenticate... Or supply perms on my AWS assets? The logistics are probably a pain tho
But if a fraction of people had a way to take on their own resource load maybe it could help
- swag shop when? :v
!shop
swag^
@celest cairn sorry for the ping but you were helping me in general earlier :/ can i just manually add this link to my sources file? or is not how this works?
curl -fsSL https://download.opensuse.org/repositories/security:zeek/xUbuntu_20.04/Release.key | gpg --dearmor | tee /etc/apt/trusted.gpg.d/security_zeek.gpg
i keep getting a bunch of binary instead and i would really love to not get a bunch of binary π¦
wait this isnt a PPA anyways, sources file is incorrect. Can i manually add this as a trusted GPG?
the middle command is whats doing it. the dearmor
Dear or transforms the key from an ascii format (ie base64) to it's usable binary format
@serene trench What's covid like man just asking because someone close to me has it
If you don't mind telling?
it depends on the person and vaccination status and 3000 other things, I got it super mild, almost asymptomatic
like I had sniffles for a week, and that may not even have been due to covid
on the outside, it's like a bad flu. On the inside, it's quite nasty, eating your lungs. You think "gosh, I'm just winded a bit easier" and you don't realize "that's because there's not enough oxygen in my blood because my lungs are dying". Whether your lungs will heal themselves is apparently a guess and doctors apparently have no solution if they don't, which is why people keep dying.
I still find it puzzling that I experienced cold sweats and I had to change shirt twice because both were damped in sweat! π
I was basically, exhausted and sick for a week, getting nausea after each meal.
that too depends on the person, vaccination, etc
yes, the virus attacks the brain as well, causing symptoms to vary wildly sometimes
Wassup! When I pressed the Share Room Badges button nothing happens, I mean I get a darkened screen and that's it, any help plz?
I got it a few weeks ago and had only cold-like symptoms (headache, burning eyes, runny nose, bit of a rough throat) for a week. But I was young, healthy and vaccinated twice.
There should a pop up asking which badge you would like to share.
I hope another humble book bundle will release today
hopefully tech related
two are leaving tmr two left monday
Isn't it vegan food cookery books?
Or do they release more than 1?
they usually release tech books, cooking books and gaming books
applied mathematics looks fun
Most commonly, a sensor is a monitoring device on a tap, T-split, span or mirror port that ...
what's a T-split?
Is it something like this, but with ethernet cables or whatever?
A T-split like they do with cable?
But yeah, a T-split is a physical split of the cable
Coax used to be used to carry ethernet.
See also vampire taps.
it's a little bit difficult to install one on someone's network in a stealthy way lol
for example, during a pentest
Don't bet on it
wdym?
It's amazingly easy to get access to networking equipment if you wear a high-vis vest and a hard hat, then ask someone completely non technical for the key
Heck, that's outright unnecessary half the time.
I've been on pentests for small-ish companies where all the equipment has just been in one unlocked cupboard at the back of the office. No one even notices if you nip in to check something or in the case of one of my supervisors, plug stuff in
Works on decently big companies too
True that π
Big companies sometimes equals big cupboards
big companies employ a lot of different kind of people.
Physical pentests are a thing π€·ββοΈ
You wouldn't be installing one unless it was a physical pentest, I'd suspect.
Or you certainly would not require stealth unless it was part of a physical pentest?
well, if you have physical access to a network device, boom!
you're in
no need to hack from the outside
depends
Tbf, we've done stuff like run ethernet cables straight from the switch, or plugged them in to activate ports in other rooms before without it being a physical pentest.
Just means not forgetting to undo it...
But I'd assume you're not trying to hide it.
Oh, no, but we've never been queried doing it either
As in, by the general office staff, not the point of contact who obviously knows why we're there anyway
I'd be so incredibly nervous on a physical pentest
like imagine if you smile a bit while telling a lie to security to e.g. explain why you're in the building
honestly I'd love to try a physical pentest
that's so freaking exciting tho
I like that feeling of "you screw one thing you're f*cked up"
but it has to be planned well
at the end, you'll go home like this
Same thing applies in a regular red team exercise π€·ββοΈ
You just show 'em the bit of paper proving you have permission and ask to see your point of contact for confirmation
Yeah but the game's up if you're caught
Exactly. Same thing applies in a regular red team exercise
Either way it's just a game that ends.
Unless you happen to be in certain American states
lol I see
My old work the cleaners would let anyone in, One day our fire alarm was set off which knocked out all the cctv, when we all went back in management realised there two massive TV's missing and a van.
Samee!!
Tbh I'd absolutely love to do the logistics / planning
criminal mastermind lau here 
bro! you just said that you get so nervous just about the idea of a physical pentest lol
well, planning, not doing it 
hahahahahaha
was on a test today where i thought i fucked up cause i was getting 500 errors on any page after some specific testing, dunno what happened but was back to normal after a few minutes
shat myself
RIP
What, are you pentesting Area 51? They'll just escort you out lol
Just think about how much security guards get paid, then you'll feel perfectly calm and confident that half of them hardly give a flying firetruck as long as there's not something they obviously have to deal with
Just donβt tell lies, simply half truths:
βI was hired to come in and check the network for bugs or insecuritiesβ like, thatβs literally the job description of a pentester
Just leave out the part that youβre testing their physical security as well
Ohhh that's a pretty smart strategy
it helps if you have a clipboard
hahahahahahah I like this one
Blending in toolkit (combination but probably not all):
- clipboard
- walk fast
- look irritated
- inspect random equipment disapprovingly
- write someone's name down pointedly
- safety vest
- hard hat
- coveralls
- white cargo van with amber cherry light (try parking on the sidewalk!)
- road cones / caution tape
just wear like a plumber and say to everyone you meet that you came to repair the pipes lol
normally, they would leave you alone
- ask people what they would say ... they do there
or say that you're from their ISP and came to fix an issue with the network
and if you can, cause a minor issue at the same time, for example start a DNS spoofing attack which will make some sites inaccessible.
Don't forget the company polo
Oh, boy, I love Goodwill. I foooound an Alcatel-Lucent polo, AT&T, Verizon, Cisco, and the United Federation of Planets (can't wait to do that pentest) (3XL)
man
SANS sell overpriced courses and yet they take sponsorships
kind of like offensive security outsourcing customer support to the Philippines
It's because you aren't supposed to be purchasing the courses yourself
That's not what I'm getting at, I mean that they should have enough money, right
why would they need a sponsorship
Because what they do is an absolute plus for the community, even if they are a for-profit
R&D isn't cheap
Sponsorship helps them focus less on sales and more on content.
They do have that work study thing where you facilitate the webex or whatever and attend free
moderate online training or work in-person events for ~$400-800/day discount*
Sheesh, still a lot of money
Although, I guess it checks out when you have hours of B2B training
In what situations would blue vs red be preferred over purple teaming?
The first when testing defender skills and the latter when testing automatic systems?
que
I see purple more as a management level on RvB.
RvB engagement, get the reports, then purple to oversee the implementations and verification of outcome decisions.
In Red v. Blue there would be a high emphasis on stealth, with Purple teaming there is not. π
Ohhh okay. I guess the book I'm reading described it incorrectly
No worries, there is a high chance that the terms are defined differently, and with different organizational implementations on how teams are utilized as an example. π
A lot of the time it isnβt about being undetectable itβs about blending in, you canβt hide your traffic, but you can make it look like legit user traffic
yes, this can be done through spoofing for example, the trick is the camouflage like a chameleon lol
The impression I've gotten before is that it's like DevOps where the way people talk about it makes it sound like it's an actual role or team, when it's really just the emergence of an interaction/cooperation
Nobody does DevOps properly
Let alone devsecops
lol
Positions where they don't even know what they want are ripe for self-determination ;o
So like tech lead
yeah what even is that lul
Apparently my current job
I see your letters and do not know what they all mean :p
I just have 15 years experience in what not to do
lol
They're probably not even using SME right either, usually it just seems to mean whoever is willing to be the most authoritative/definitive about some specific area that nobody else wants to deal with
it's like a tongue twister :0
Is cat text.txt | wc -m the same as wc -m < text.txt?
just use bat, not cat π
bat abuse isn't OK either
Yoink
Put a 20px white border on the image at least first
I swear I cringe every time I see that term.
I keep forgetting about that operator
-ban @radiant jacinth -ddays 1 Crypto coin pyramid scheme
π¨ Banned crypto rollercoin#0820 indefinitely
what about cat file foobar > newfile
I don't have a horse in this race, use your command line however you wish.
It was just a topical thing
Ah I scrolled up, see the original query now.
yes! go check stream redirection in Linux π
wow
What are you supposed to say when someone states an achievement of yours?
Like a compliment, but stated and not given as a compliment
You did x and y greatly
You wouldn't say thanks because that's like it's a compliment, and you wouldn't say yes because that sounds arrogant
Am asking because the mayor (not joe hille) came to my house the other day for a few things and said something along the lines of that, and I responded with
Yepp, thanks
and I don't know if I should be ashamed of that reaction 
Thank you is an adequate response
Even though they are stating your achievement, it's still a form of praise. So, "Thank you, I tried to accomplish x and y to the best of my abilities. You're kind words mean a lot."
Something like that
during those moments nodding and a slight bow does the job!! atleast for me! and response if you processed a good one
Not all compliments will be phrased subjectively though so
good job james! keep up the good work! someday they will see the error of their ways!
Please see my later message.
nooooo
cat abuse must be stopped at any cost!
-warn @merry smelt Rule 8 includes obfuscated/crypted text. Keep it in English only.
β Warned FlatPanda#2469
Oops, sorry about that, valid warn @burnt night. It was just a joke about the site vs. Cyberchef. https://cryptii.com/
The Cat...
does this mean it can cure someone of cancer if they wish for it????
I am gonna drink for all of us for prosperous hacks and much rooted boxes π
yesss sirrrr
I already asked for a million dollars
prayge
shadow wanted to ask if it could do another specific thingy but felt that might make this discussion not civil and relaxed so skipper it

I've been looking for a way to update default firefox on my kali
obviously, apt-get update/upgrade doesn't work
Don't want to uninstall my only browser(preferably) and reinstall, so any easy ways would be appreciated!
ask me I enjoy normal human beings talks and I don't care about harrassments
xD
if a transsexual person drinks that water will they turn into their preferred gender???

I can take a sip for you if u want homie
I already drank a sip for all the homies at htb
you can't just download it from mozzila and install it that way???
π
or maybe use their ppa and see if you can use that to install the newest versions on kali without problems.... though that feels like a more hacky workaround as the ppa is for ubuntu and not kali
Yes, but I'd have to uninstall my only browser in the process and was wondering if there's a simple update somewhere
I like the ppa workaround, looks simple by just apt-add-repo and apt update
Thanks!
Gave +1 Rep to @soft pier
What's the problem with uninstalling the browser? I'm not clear on why apt doesn't work in the first place. But anyway if it's just about losing any info, you can restore profiles https://support.mozilla.org/en-US/kb/back-and-restore-information-firefox-profiles
Firefox stores your personal information and settings in a profile folder. Learn how to back up and restore this important data.
Well, the default update method on Firefox doesn't work probably because it's a supported release file or something, the same with apt(actually my whole UI updated locking out root user profile login but not Firefox, apparantly, I just preferred not uninstalling but if there's nothing else, then I'll do that!
oh weird ok
Dear All,
I am new here. Hi to all.
so basically, I have a pretty solid fundamental knowledge
I suck in Windows I know lol
where can I get this
go to your dashboard
no u
what?
daaaamn bro lol
well at some point I used arch btw as main so there is that
what's special about Arch?
that's it? lol
yes, as for the technicalities just google it
I love Linux too, my first distro was the first version of Slackware BTW π long time Debian user, now using Fedora, because of incompatibility hardware, and I don't like Ubuntu π
What about kali 
You can say that Slackware was the arch of the 90s π
kali is great for pentesting because all the soft pre-installed, but no much functional as a day to day distro
True
Daily ping Hamza
daily pray society :prayge
"i use gentoo btw"
"i use pentoo btw"
"i use lfs btw"
lol
The difference is that back in 1995 I didnβt have as many options of distro as we have today. Somebody hand me Slackware and told me this is Linux youβre going to like it π
The distro booted and displayed the login. If you wanted some kind of GUI you need it to run XFree86 manually and you interchanged windows between gui and commad prompt with alt f.. keys. Nothing strange since I was coming from DOS actually gui was strange back then ππ
It was call source code back them, specially in Slackware ππ
Alt f to swap between ttys is still a thing, usually with the gui on one of them. They mught have added control to that keybind, I don't remember
I wanna make a room on the basics of selenium halp where should I start ?
usually you'd make a room on a topic you know lots about
so if you don't know where to start then i suggest learning more about selenium before teaching it
I said where should I start learning about room submission procedure not selenium
you didn't but
You didn't say that, you said "where should I start ?"
What is Room Testing and Who Tests? TryHackMe uses a room review and testing process to keep content on the site accessible, consistent, and appropriate. R
ty'z
just need a little more privesc
great that one of those workarounds works for you.... hope it works flawlessly without problems
How long did that take lmao
some dumb questions about cookies to help my understanding and my safety! :P
- how does a server know when a session ID has been terminated with you, for example if you have a persistent cookie, and you leave wipe your cookies, and rejoin does it just give you a new one? making the old one useless or does the 1st cookie's session continue it's time to live ((probs not the technical term but that's what i'm going with))
- if you have curl running and it automatically kills all cookies after make it's request do persistent cookies still get added
- if a cookie is hijacked at what point does that cookie become useless, does it refresh every time the attacker resets it
- if a cookie is past it's time to live is the session ID still dangerous
- The tokens should expire when unused, or a new session should replace the old one. Depends on the app.
- Curl doesn't save cookies unless you tell it to
- Depends on the app
- Depends on the app
You may notice a lot of those answers are the same
i have noticed that! :P
Ideally the app has a session expiry time built into it that's separate from browser session expiry. That's 15 minutes by default for PHP sessions, iirc.
https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html here's a good read for you
Website with the collection of all the cheat sheets of the project.
i.e. if your browser doesn't make any requests during that time period, the session gets struck off and you have to request a new one
thank you! :P i was really dumb an didn't understand what i was doing when i posted what i did :p so i don't intend to do it again xD
All good -- not a bad question at all π
thank you for the resource your awesome! :D and thanks for calling me out quickly on my fuck up xD
Gave +1 Rep to @burnt night
<3!
I don't think I called you out on anything?
They're not dumb questions at all.
earlier you were like "that's a session id" xD and i deleted it
cause i was like ooooo oh no xD
Hey, it might not have been a session ID
tbh XD i'm still not sure what it is xD
but by the end of today i'ma figure that out! goals
Been doing THM about a year on and off
ahh still very impressive
ty π
Gave +1 Rep to @graceful wren





Gave +1 Rep to @gray jetty


What's a good CTF to play with a beginner?
aka someone who barely knows how SSH works
if you barely know how SSH works, I wouldn't recommend playing CTFs
you will just be stuck.
do walkthroughs and educational rooms first
I'm doing it with my 19yo nephew who's an IT student
I'm basically gonna guide him through it or whatever
he's got cybersec as a class
I have a ping in here but nothing :\
-undelete -a
Up to 10 last deleted messages (last hour or 12 hours for premium):
none...
Looking for my ghost ping? lol.
Aye
I dunno what's up with it, big fat orange 1 and nothing.
yep. get this bug too from time to time
-undelete -a
Up to 10 last deleted messages (last hour or 12 hours for premium):
11 minutes ago (Tue Jan 11 22:19:56 2022) Unknown User#6885 (ID 589507330798780456):
1 hour ago (Tue Jan 11 21:17:35 2022) nostalgia#8788 (ID 904084855137136680): @MuirlandOracle how can i add an emote since i'm a booster?
check out overthewire.org bandit
Well that's why you're getting unread dots just now
Why did they take so long to show?
a lot of messages (which would cause the dot) get input which either get deleted by the bot after or deleted by the user (which is only representable when we look through the logs)
obvs the bot deletes almost instantly so it looks like a message was sent but the response isn't represented to everyone other than mods
A user could send a bad message and discord sees it as being sent (hence the dot) but what happens to that message is /shrug in the eyes of discord
if it gets deleted then it gets deleted -- but the dot isn't removed because the channel was updated in the first place (by the person who sent a message)
Hmm, I've got a proof of concept that works on this box, but I just haven't put together the pieces to get the rest of the way.
oh yeh, that was me
was asking about how your first day as a student went, but had to delete(let's say coerced to by @dusty sleet) it for that
meme streak thing up there

nooo, not again 

woah the Skills Matrix in the Dashboard looks interesting
I hate it
It's not accurate and it makes you feel like you're done learning a certain skill because you have 100 on one side of the matrix
I had a 100, and then, it stopped being 100.
Probably then trying to make it more accurate
But until it's relatively accurate(it'll never be 100% accurate) it has more cons that pros
Yeah but that's on you if you don't yourself realize that you aren't done learning π
but yeah I see what you mean
Put that in the site feedback form :)
I did the survey
The one in #feedback-and-ideas?
The one they emailed for feedback
About the skill matrix
Ah, fair
It is a beta though, maybe they will change it up
please tell me how bad my code is in an issue

https://github.com/hamzawinix/Magmatic
Dec 2nd, 2019: Mikhail Golovochuk, a member of the ransomware group REvil, posts on Instagram "Looking to the future" from the Four Seasons Hotel in Moscow.
Dec 12th, 2019, @BleepinComputer writes an article about REvils new extortion methods
More info: https://t.co/XWkw85kIrk
128
No homo but REvil members are kinda hot 
Hello guys does anyone know where I can find help with mobile devices ? More specific android system and even more specific super partition?
What are you trying to do?
Install a Rom. I managed to unlock boot loader and installed TWRP and I flashed a rom image but I flashed it to the SUPER partition by mistake. Phone is stuck in boot loop now and wonβt even go into fastboot mode. It does not get detected by the computer either unless I hold vol down and power but it detects it for just a few seconds and it disappears again
Phone model and ROM you're trying to install?
Redmi 9(Lancelot) I am just trying to repair the file system for nowβ¦ eventually Iβd try to compile nethunter for it but at the moment I am trying with stock rom trough SP flash tool which is not easy at all with all the xiaomi locks π€¦πΌββοΈ
Doing a quick Google, there are several videos that seem to fix the problems you're having
Also looks like there is an XDA Developer post or two as well
Iβve been Googling and watching videos for 10 hours ππ
@candid island can I DM you at your convenience? Wanted to run something by you regarding a job.
go ahead. will reply when i am free
Thanks :D
Gave +1 Rep to @candid island
So, other than #subscriber, what other restricted public channels are there? (advanced general and help, exploit studies excluded)
I think you've got them all there
The others are discord staff channels etc
I wish there were more
They make me feel special like hidden levels in games
inb4 I make a CTF in the Discord server
wouldn'tr be the first time!
I did already
Not in here you didn't 
Making a Discord CTF is easy enough. Making one in a partnered / verified server with 115,000 people in it is nuts π
Yeah that's intentional
Will THM issue a transfer token for a domain like tryhackme.xyz (I don't own that one) for trademark infringement even when it redirects to tryhackme.com?
New chair 
To my knowledge, THM havenβt issued any out yet. If it just forwards to the site then I donβt see any problems with it, but why not just save your money?
If you mimic the site/ dump content or anything else that might break IP, copyright etc. then maybe.
how old where you when you realized amazon has an Easter egg in their homepage
Whatβs the Easter egg?
have you found the thm easter egg?
('identify',userId,{'displayName':username,'subscribed':'1','dateSignedUp':'Fri Dec 18 2020 08:02:02 GMT+0000 (Greenwich Mean Time)','experience':'intermediate'})) found this in the THM page source, where does experience get used?
I have a question. Can devices on different subnet ping each other? For example on college wifi there are different routers or switches i shd say idk for different departments and there r even more branches. Can I ping from my device connected to one hostel router/switch out of many on diff floors to any other device on diff router/switch like in accounting department?
As long as routing and firewall rules allow for them to reach each-other with ICMP echo requests.
alright. Just to add on when I check on my device it shows it as Class A network and I have ip address starting from 10
Why do you want to do this?

why are you trying to do this?
thx
Gave +1 Rep to @burnt night
hi
I'm trying get into demo.uploadvulns.thm from https://tryhackme.com/room/uploadvulns
but constantly youtube is opened
You might want to read the text in the room again
@quaint basin you got another.
echo "10.10.165.117 overwrite.uploadvulns.thm shell.uploadvulns.thm java.uploadvulns.thm annex.uploadvulns.thm magic.uploadvulns.thm jewel.uploadvulns.thm demo.uploadvulns.thm" | sudo tee -a /etc/hosts
Again. Read the text in the room.
I didn't ask you to copy commands for me. I asked you to read the content in the room. I think it's even in bold.
systemctl restart systemd.resolved.service also
You're not reading the text in the room. I can say that for certain.
"this site is not available in the uploaded VM" <--- you mean on it ? this mean that I'm able to pass this room only from browser atached machines ?
No.
Read the full sentence there please. It says it's only for demonstration.
TL;DR: demo.uploadvulns.thm is not part of the VM. It is only used for demonstrations in the room. The challenge sites are the bit that you connect to
Or, rather, it is part of the VM, but only insofar as it redirects you to a rickroll to see who was paying attention to the room text 
@burnt night thx for the help, indeed I should read more carefully, but I think this room is brokering some convention that I used to on THM
Gave +1 Rep to @burnt night
Not exactly.
You made an assumption. Plenty of rooms give examples with IPs that you definitely shouldn't connect to.
Avoid making assumptions especially about targets, and ensure that you've both read and understood the text before carrying on.
If you hit the wrong target in a pentest, there's potentially criminal charges
yep got it, you have right, one of the hardest room π
Did I not set it to easy? 
It's very much not a difficult room. Reading comprehension is a skill you really need to learn and practice.
Tbf, with Jewel there, it should probably be medium
that one was annoying
Jewel took me awhile
Especially the part where I had to actually find my file
Jewel is my first and only NodeJS webserver. Enjoy it
Why you're only!?
js is shit
Yes, i really enjoy it π it take me 2 hours
working on a research project in clg + want to do some wack shit
web development in general in shit
Wack shit? Just be sure to keep it legal and within your schools terms of service
oof
Definitely one of those times where you seek permission, not forgiveness.
Fairly high. It's not exactly an uncommon framework
What are the odds that I was playing w it when u wrote that
anyway some might say django > flask
π
It depends on use case.
IIRC Django is better for major sites with loads of features and Flask is better for the basic ones
best is flash no cap
In a way, yes. Although Flask is a very good alternative to Django in most situations.
NGL, doing the django room, and the related python room had me scratching my head some.
Like, is there no stored static HTML anywhere? All generated by python on the fly?
Look at how django uses template engine for generating the HTML.
JINJA templates are very common across a variety of python projects
Hi, maybe in this room https://tryhackme.com/room/uploadvulns we don't need in this line:
echo "10.10.162.109 overwrite.uploadvulns.thm shell.uploadvulns.thm java.uploadvulns.thm annex.uploadvulns.thm magic.uploadvulns.thm jewel.uploadvulns.thm demo.uploadvulns.thm" | sudo tee -a /etc/hosts
the last mapping ? demo.uploadvulns.thm ?
Correct. It's a test, designed to see if you're actually reading the content in the room.
If you're not reading the content, you're directed to Rick Astley singing Never Gonna Give You Up.
It's entirely intentional, and entirely your own fault if you do not read the content properly.
π ok I give up π
Rickrolling, alternatively Rick-rolling or Rickroll, is a prank and an Internet meme involving an unexpected appearance of the music video for the 1987 song "Never Gonna Give You Up," performed by the English singer Rick Astley. The meme is a type of bait and switch using a disguised hyperlink that leads to the music video. When victims click on...
How many views of the video is A: Legit views and listens and B: Rickrolls.
I'd guess 95% rickrolls
Classic
well yh
Can't find /proc/sched_debug on some of my VMs and much information about it either. Does it depend on the version of the Kernel or the distro?
Are there docs that specify where what HTTP header gets used?
for example, when I search for X-Rewrite-Url I only get vulnerabilities instead of an actual explanation
It's harder for X-whatever as they're usually application specific although there are conventions.
For many headers, mozilla documents them nicely
https://www.acunetix.com/vulnerabilities/web/url-rewrite-vulnerability/
Tl;dr legacy headers
It was identified that this application supports the legacy headers X-Original-URL and/or X-Rewrite-URL. Support for these headers lets users override the path in the...
Alrighte, thanks!
zend-diactoros up to 1.8.4, zend-http up to 2.8.1, zend-feed up to 2.10.3 are affected by this security issue.
kek that's the same version a bug bounty program website uses
found that setting the header X-Rewrite-Url: dev just straight up showed dev info lmao
showed all httponly cookies in plaintext, so easy cookiejacking -> acc takeover
How tf did anyone think this was a good idea?
Well, /dev redirects to home
it's like a 403 bypass but with 301 so it's probably an admin only default debug page
tbh the entire site is cringe worthy. Found 3 reflected XSSs, 2 session cookie disclosures (one of which is the page aboce), no anti CSRF tokens etc
I've already reported an account takeover bug chain
got 2 more coming both with unique chains 
funniest thing is that it's a fully online wholesale and one of the most popular ones in my country, was quite shocked at this sh*tty security
Anyone have any good resources for small python projects to get started with? For beginners preferably.
If you just want to get comfortable with the language, there's a game I can suggest, you'll see me bring it up a lot π
codecombat.com
Otherwise, check-in with FreeCodeCamps, they work on using real projects as a training platform for brand-new to intermediate coders.
Thank you! I'll check both of them out!
can somebody help me with finding the victim Machine im connected to the tryhackme via vpn
so i did not use the 1 hour available machine which is available online
Hey zahir, sorry I was not here when you were looking for help.
#room-help and #site-support are good locations when you're looking for a hand depending on the nature of the trouble.
When you expand a task, at the top right of the task there should be a button for any additional resources.
Whether its a PCAP download, Wordlist, or a target machine that needs to be launched.
When you launch a target machine a banner will appear with the timer for the machine, ability to extend its life by 1hour, and the IP address will reveal itself 1 minute after you launch a target machine.
The 1 minute is to give it time to boot, and configure networking, though some machines need longer for their services to initiate.
Check out the pins in #programming as well
Are there any rooms on Pegasus? I have been listening to Darknet diaries today.
Not to my knowledge
Anybody got tips on working while having vertigo?
what triggers it?
Havent figured it out yet. Its just like a hat i cant take off
stairs triggers mine, I also had things that felt similar from low blood sugar / low blood pressure
also I'm assuming you've gone to a doctor because ear infections can also cause it
Havent been to a doctor yet becaus of the throat part of ent. Low blood sugar is definitely one trigger.
I'm looking forward to college
I enrolled myself for compsci but idk how challenging it will be for me
I hope I'll have enough time to learn more maths, physics and hax0ring on the side
Oh there's going to be plenty of math, in my uni, CS students learn multi variate calculus, linear algebra and everything in between
Sadly, cybersec isn't taught as an official course 
You'll learn more maths than you care for
Don't forget discrete maths
its ok if cybersec isn't taught, Comp Sci is the foundation for everything CyberSec, you'll do great
I would say learn a lot in your own time, when I was in university ( cybersecurity major) still I learned most in my own time. So donβt waste time.
For what its worth ,I don't have an undergraduate degree in cyber - I seem to do OK in the field.
thing is I'm in a third world country where 'online cyber skills' without any certification don't really matter, but thanks for your encouragement π
Gave +1 Rep to @spark sun
Would it be an advantage to write a C2 tool using python WITH C++ extensions?
I don't think that C2 servers are heavy to run resource wise, are they
Guys i am new and i wanna learn hacking what should i do
Ok thanks
You're welcome. Have fun.
having fun is underappreciated
depends what you write them in and how bad you overengineer them with useless things that take up cpu/mem π
wdym by python with cpp though? π€
Python can be extended using specific libs for C and C++
yeah FFI and all that, also cpython bindings and whatnot
but i don't really see the usecase for using them
i do see the opposite though, writing a server/client in c/c++ and using python as a scripting engine inside it
well, it might be useful when processing lots of data
e.g. file exfiltration and stuff (depending on the code)
because python is hella slow it might take longer
i guess now i see it, but the bottleneck will most likely be the web server then, not the processing code (my guess is that encryption would be the most "time consuming" part, and even that is handled by native libs under the hood)
to make the http server part more efficient you'd need to push the http server to the native side and handle stuff in it, delegating the more high level portions of the server to the python side instead
or at least that's how i see it
Anyone here read the book "The stranger" by Albert Camus?
whenever i hear that name , me be like AAAAAA
that's a good book right there
I just wanna talk about it, what were your guys's opinion on the book?
Very broad question given the nature of the book, but I thought it was a unique perspective, and while I don't necessarily agree with all parts of what Camus is talking about, I respect it.
I'm so baffled by the ending
In some sorts it's a happy ending, in other ways it's not
Honestly such a good ending
If it went any other way the book wouldn't be as good imo
Like he didn't live his most authentic life he knows that but the discovery that the world (to him) is indifferent seems to compensate for that
What do you mean by "most authentic life" exactly? Just asking for clarification.
Well he believes that his mother lived the most authentic life, that's why he isn't sad why she died
It basically means that you don't need a reason for the things you do, you do them because you want to
You could've made one decision but instead you made the other and there is no difference to that
I would say he did live his most authentic life, as nothing in the book really seems to suggest otherwise. He's pretty content in his worldly things.
Camus was very concerned with the idea of "the Absurd", that is, man's struggle to find meaning in an existence that lacks meaning. While that point is up for debate, I see the The Stranger to demonstrate and highlight that struggle.
Is it worth reading?
Can always run a search in #bookclub to see if its been recommended since it's been 13hours since the convo died.
Alright.
Just hoping it's helpful π
Can someone Proficient in C explain this in simple terms Please?
I am driving myself insane.
#include <stdio.h>
int main(void){
int a = 1;
int b = 2;
int array[] = {a, b};
printf("\n%p", &a);
printf("\n%p", array);
return 0;
}
why two different resilts?
Homework?
just trying to learn C on my own
I dont understand why the name of the array isnt the same as the memory adress of the first element?
This video will explain all the concepts you need to understand what's going on: https://www.youtube.com/watch?v=5VnDaHBi8dM
A fun 3 minute video that explains the basics features of pointers and memory in C. Copyright Nick Parlante, 1999. These materials are free and available at http://cslibrary.stanford.edu/ For more information see:
http://www.netcore2k.net/articles/pointers
Next step is to figure out how assignment operates.
no it doesn't really,
I am sure i am brainfarting
brain <3
It's a great book
hii
just noticed in mr robot season 2 when ||Joanna's bodyguard takes elliot to microcenter to get tools to track the unknown calls, he's playing watch dogs in the game center ||lol
Figured it out OOF
I actually found this useful thank you
Gave +1 Rep to @spark sun
π
Pointer fun with binky is the most accessible explanation of pointers and references that I have seen
I'd never seen it until now π
I'm not super proficient, but these are the type of exercises that AoE uses to teach disassembly.
Include standard input-output
declare main program function
declare integer variable a to be equal to one
declare integer variable b to be equal to two
create an integer array called array, including both variables.
print formatted text, "new line, read pointer" var/pointer to read is "a"
print formatted text, "new line, read pointer" var/pointer to read is array
return successful end of function
The &a makes it follow it as a pointer back to the declaration.
Which I suspect will be come apparent as to why in your next lesson steps.
I honestly don't remember what happens off-hand if you declare a pointer look up against an array.
Binky!!!!!
Binky is best pointer video
Agreed
Wow, I wanna talk about the ending of Mr Robot
||as soon as Mr. robot showed up, I knew Elliot had DID and all the archetypes checked out, I just don't know why they made their own "mastermind" archetype at the end I feel like it kind of ruined the awesome representation they had shown so far||
hi guys, question about VMware on win10 and Linux installation:
I've never used VMware and don't know how it works but I managed to install it and burn Linux iso images on DVD too.
Now i'm stuck at a point where you have to specify disk capacity.
Found a instruction manual about this and it said 'The default should be enough'
I have 20GB as default here and the instruction manual shows a screenshot and his disk capacity is 8gb. Is it because the version? His version is different but he had also Ubuntu in the other screenshot.
Not sure if it's allowed to share the link (Instruction manual). To see what I mean with his screenshots and mine.
What to do here?
if it's Ubuntu, 30GB of disk space will be fine.
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
see there for the system requirements
that is really the only way to tell how much you should allocate
if you intend on using this OS very frequently, I would recommend doubling that otherwise you may need to reinstall and allocate more disk space
Thanks, I will check that out. I was confused because of the instruction manual, he showed 8gb in the same screenshot that I shared.
Linux especially can run on much lower resources, just because that is what's recommended doesn't mean you cant get away with a much smaller amount
Do you mean I can delete the os and re install again that easy? Nice then, because I only want to use it for learning.
Yep. That's the beauty of VMs!

I'm reading a book and it says "Configuring your phone-switching system to require an employee who recieves an external call te punch in the even digits of the caller's phone number before the system can connect"
How does this mitigate phishing/vishing?
Making the caller input something often deters them, but the employee? Strange.
Hi, can someone help me with a weird thing? I had a website bookmarked from years ago "https://www.pyrobot.org/". When I clicked on it I got an error. For curiosity I searched it on google and fond "https://pyrobot.org/" which works just fine. Can someone help me understand why the "www" gives me an error? Shouldn't it be an universal prefix?
www is the problem
There's a chance they misconfigured/ didn't set an alias
I did the same for my website, at first you could only access it with www. until I set an alias without www
Depends on what you use, for apache2, you have to set it in /etc/apache2/sites-available/00default.conf iirc
TL; DR, DNS
Ok, thank you. I thought that www was something the browser would set automatically.
They're technically different subdomains, they can have different records
Yeah, for my websites I usually set an additional A record for www
Give www a glue record that throws it to some other random environment completely x'D
Yeah It was my bad, i though that variables are passed in arrays by reference but they are passed copy paste style
Does anyone know any resources for buffer overflows?
as in, 0 to hero from stack based to heap based and rop chains etc
it's a pain in the ass to hustle different resources\
Nightmare on github
Itβs awesome
didn't malwareunicorn have some online labs?
Should I factory reset my computer for more space?
It seems like the best option for now
Only if you want to lose all your data
Heh we've lost a hard drive for now, need to contact apple support to see if I can get a new one
buy an 8tb HDD
can confirm it's pretty awesome to not have to worry about disk space https://i.imgur.com/JxTBith.png
holy sheet
what do u store on that
honestly all my data is in the cloud, have 2tb cloud storage which I store data off and my hard drives have very little data on them

I don't want to get muted on this server for mentioning it
in addition to that, also VMs and games
I make tons of snapshots of VMs so they usually go high into the dozens of GBs
noiceeeeee
so I saw this ad somewhere and followed it through ,its a website for hiring devs for remote work , I took their exam for bash skills ,need someone to look at their exam and till me how good u think it is
Get the best remote software developer jobs with Turing and work for Silicon Valley companies looking to hire remote software engineers across 100+ skills.
Hi, I have been researching about Windows registry hives and forensis, but I cannot figure out how to dump credentials from unlocal SAM file. I used mimikatz, but I didnΒ΄t find anywhere how to set up my unlocal SAM file. Do you have any recommendations, I would appreciate that.
Hmm, you tempt me to replace my "slow" drive.
Impacket or pypykatz
Is "unlocal" a colloquialism for the target system's SAM file that I'm unfamiliar with?
Not as far as I know, do you have a link to where it mentions that? @echo dust
Used 3 comments above twice in @ebon bloom 's query.
If it was used once, I would write it off as a an oddity/typo.
Using it twice, suggests there's a specific meaning intended that might be important to the answering accurately.
Of course, if it is just meaning to say the SAM file local to the target machine, then I'd have to ask what they mean by "set up", are they just having trouble formatting/prepping for ingest via Hashcat/JtR?
Yea, they probably mean unlocal SAM file literally or maybe they're talking about how the SAM and SYSTEM are locked by the fs
Sorry, I didn't exactly specified my problem. I have downloaded SAM file and I need to extract passwords from them. But when I use mimikatz it shows me hashes from my local drive so the problem is with settings of the source.
You have both the SAM and the SYSTEM file downloaded using reg/vsshadow?/or any other method
You can just use impacket to dump them then
OK, I'll try that
Alright, secretsdump.py is the script you need to use in impacket
Yeah I have to look how to use Impacket so it takes some time π
@tawdry dove I feel like you'd enjoy this Matty Matheson video: https://www.youtube.com/watch?v=d4VegEHfPd8&ab_channel=Munchies
Rang and Matty pick up where they left off in Episode One but this time in Newfoundland. The dynamic duoβs tour ends up with moose hunting.
Watch Season 1 of Dead Set on Life here: https://www.youtube.com/playlist?list=PLnPDn1Lb79JFQfaqYzn5ofwQUEfZc2frX
This episode originally aired on VICELAND in 2016
Subscribe to Munchies here: http://bit.l...
The show with Steve Rinella is good too
Forgot the name off the top of my head
Don't really watch Matty all too often though
I just found an old notepad blog I haven't updated in more than half a year
I guess the studying really paid off.. went from thinking you can hack a website by editing a plaintext cookie to top 500 on thm in like less than 6 months
wait wait, so, you can't hack a website by changing it's sess_id cookie to an admin's?, the more you know 
take it lightly its a joke^
Gave +1 Rep to @frail rapids
Just reading about and practicing CTFs really. tbh I feel like anyone can do cybersec, but just need the dedication to practice. In addition to that, I've learned programming in a lot of languages over the past two years which really helped with knowing what I was doing. I believe that you can only hack something if you have an in-depth understanding of how something works
I've done a lot of THM rooms which really helped and in addition to that I read Medium posts and watch Ippsec on Youtube
Gave +1 Rep to @frail rapids
hey im looking to learn about windows down to a kernel level but i have zero idea where to start. Anyone have any sources or websites, youtubers etc???
if you are crazy, this is a good book https://www.amazon.com/Windows-Internals-Part-architecture-management/dp/0735684189/
nothing is going to be more definitive than that
bleh books ugh
if it gives me what i want then i have to lol thanks man
Gave +1 Rep to @scarlet moth
What is meant with heuristics?
While heuristics or threat hunting can detect abnormal router behaviour, ...
Reduction of a problem to something more easily quantifiable or qualifiable
Would it in theory be possible to make a ML model that generates WAF bypasses?
I guess there would be several struggles like 1) finding datasets and 2) confirming if the WAF bypass works or not
I guess it should require a check of valid HTML and JS syntax first as well
Perhaps a GAN could do the trick? But like I said, it needs to be capable of detecting valid syntax at all

Especially deciding what doesn't work/should be used before the WAF blocks you entirely
Yeaahh exactly
I mean, if the model works well enough and has valid syntax, it should probably work
basically comes down to HTML tags + random jumble + JS event + JS
You can barely do static analysis of the syntax because it can be unpredictable
Vendor specific, etc (:
so you'd probably need to run it through an engine
Cool idea, I know a coursemate is looking to do something similar for his masters thesis but uh -- I have no idea how that is going
Also yeah I could see a GAN working but i'm not super knowledgeable on NN
Just a case of if you can get the right dataset as you said! π
With something like modsecurity that's a lot more practical
Hm. yeah.
If it doesn't have a rate limit when it's self hosted you could in theory brute force it and put the results in a dataset and train off that with GAN, or just implement the source code rules as rules for a generator and insert those into a dataset as guaranteed bypasses
I think I'm going to make a proof of concept with regex and see how it works out
Out of curiosity can you dumb down what yβall were just talking about for me please β οΈβ οΈ
Talking about the use (training) of a GAN, a neural network, to produce code that might bypass WAF
It is possible but, I don't think it would be worth the time to gather dataset, train it and verify it's learningπ€
Oohh okay Iβll loot into that π
Strictly out of curiosity. I simply want to know what that means bc I donβt even know what a GAN is lol. Thank you
Gave +1 Rep to @woven patrol
Im using msfconsole on my kali linux to exploit a windows xp. Both are in the same network Nat network inside virtual box. the exploit is called "exploit/windows/smb/ms08_067_netapit" the payload is "payload/windows/meterpreter/reverse_tcp" Windows xp is an not yet acctivated and looks as follows. the problem is though after I run the exploit everything is just fine there is no error the remote port is accessible and open, but some how i dont get any meterpreter session on my kali. Could somebody help me with it? Do I have to change the service pack 3 of windows xp to sp2 or sp1 to get the desired result?
thanks
Artificial Intelligence where neural nets play against each other and improve enough to generate something new. Rob Miles explains GANs
One of the papers Rob referenced: http://bit.ly/C_GANs
More from Rob Miles: http://bit.ly/Rob_Miles_YouTube
https://www.facebook.com/computerphile
https://twitter.com/computer_phile
This video was filmed...
Oohh fancy thank youuu
Gave +1 Rep to @frail rapids
Hi
I have problem with bypassing windows 10 firewall during nmap scans, is it at all possible ?
I guess it depends on the type of scan you are doing
Indeed the scan type depends. Windows by default blocks all ICMP pings. You need to ping using TCP or UDP. You can check out the help page and see which you need to use π
Also running nmap as root is helpful too. Itβs a norm for a lot of people. Running as root defaults to silent scan I believe?? It uses ARP pings π
only if youβre on the same network
which is obvious if you know@how arp works but iβve seen lots of questions asking why that doesnβt work before lol
I believe it only blocks ICMP from the Public zone
Hmm interesting thank you π
Gave +1 Rep to @burnt night
Anyone have any high-spec laptop recommendations? Hitting the storage limit on my macbook and I can't replace the storage, trying to decide between M1 Pro/Max and something else. (Used some dell points I had from work to order a spec'd out laptop a month or so back but it showed up broke
)
I am in vip vpn, yet I do not have a connection today except when I disable the vpn is normal?
Sounds like something is messing up your routes on system.
Assuming you're on Linux
run: ip -br -c a
How many Tun adapters?
Don't use the OS VPN manager, use the command line.
ho ok ty
Gave +1 Rep to @burnt night
You guys got any recommended password managers that are free and multiplatform?
bitwarden
Keepass as well
I heard about KeePassXC, it sounded good, wasn't sure if I'd be able to use it on all my devices though
I want to be able to use it on my PC, laptop, and phone ideally
don't think keepass can sync though
It does if you keep it on a cloud storage π
I just signed up for Tmobile's 5G Home Internet. The big sell was no data caps. Means more games 
on-device mirror to the storage π I am just careful to keep the hardware keyfile off cloudsync
yeah
don't think keepassXC has a mobile version though
I use Keepass2Android
I use LastPass. Pretty solid although itβs $3 a month to use on multiple devices
i use nordpass. pretty good but you have to pay to be signed in on multiple devices. fine for me because i only use on desktop
Guys, does anybody know any tool or something that tells you more info about someone based on their name or social media?
There are sites with public information about you that companies use before hiring someone
If they are over 18 you most likely can get most of your info from those sites unless they've went and made sure that those kind of information is taken out
hi, just wanted to ask where to ask cryptography related question? (xor decryption)
and based on cellphone number?
What are you looking to do with this information?
To know if I am getting scammed or no
If you think you are getting scammed, back out of whatever it is. Due to how porous telecom systems can be, a phone number is not a reliable source of information from reverse lookup.
That's pretty rude.
fair enough, actually. Its just that it has been going for more than two months and it aint pushy but still there is this bad feeling ya know
thats what i felt
If you have a question, just ask. Asking to ask is one of the most irritating things about how company DM solutions are used.
That extends to discord
ask away
sometimes i ask but people tell me it is wrong channel so i dont want to make a mess
since i am new i prefer to ask
quiet conversation is almost always the wrong place to ask - it's a slower chat by design. for technical stuff like xor maths in encryption algorithms, #infosec-general is probably going to be your fastest response
thanks
what do you prefer between parrot security and kali?
personally Kali has given me less issues, but it doesnt hurt to try both
how to hack?
You type on the keyboard and eventually you get to say "I'm in"
What document defines how a penetration testing engagement should be carried out??
Please don't ask the same question over several channels
Where can I find binaries with a BOF for practising?
there is a buffer overflow room to try it
This should be good enough π
https://pwnable.kr
he's gone
Already did that
Thanksss
I should've greeted gone
bonk
πππππππ ππππππππ πππ ππππππ ππ πππ ππππππππ
Hello everyone
I have question, Does anyone knows what easter egg files means in website for example? How we decide a file is an easter egg file?
You'll see
You should check for strange text
and it probably won't contain a lot of js or html but you never know
These actors' innovations include ...; embedding malware in BIOS storage; ...
what is meant with BIOS storage? I don't assume it's the non-volatile chip on the mobo, right?
I would assume it is the non-volatile chip because that's where the BIOS is stored
Pray for me, I enrolled a course in uni which I thought was a computer architecture course but its a UI/UX course
ooferz I won't pray since you might like it π
But can you unenroll before you get charged?
I wont HAAH, I have been in this career for 4 years and I head dealt with a lot UI/UX stuff but it is interesting in the end
I already got charged ;-;
And can you use that as part of completing your major or it doesnt' count?
Hey guys, I scored my first interview ever for a sec analyst position this monday, I would love any tips you all may have...π
Congratulations!!!!
@bronze creek Thank you
Gave +1 Rep to @bronze creek
π π€²
π€²
Good luck!
Tips wise, there's a list of questions pinned at in #cyber-and-careers which you should be able to answer going into the interview
Y'all reckon this is a good laptop for VMs? https://www.mediamarkt.nl/nl/product/_acer-nitro-5-an515-45-r7lv-1714245.html
You're paying for the 3080
You'll get no battery life out of that thing though
Will probably get thermal gated fast as well
@burnt night Thank you!
Gave +1 Rep to @burnt night
If you're not specifically looking for a notebook, just build yourself a PC. For less than that laptop, you can get something really nice.
The battery life is terrible on most gaming laptops. I've had a couple including a different Acer nitro. You won't end up taking it anywhere without the cable.
Unless you need a laptop, you know, for mobile mobile reasons.
I have a Dell G15 and the battery life is pretty amazing
I personally don't like desktops so all I buy are laptops
Well I need it for school
Need to run VMs but I might just setup proxmox on my home pc/server
Throw 64gb ram into it and it's g2g
#HaloTheSeries #MasterChief #ParamountPlus
Dramatizing an epic 26th-century conflict between humanity and an alien threat known as the Covenant, Halo the series will weave deeply drawn personal stories with action, adventure and a richly imagined vision of the future.
In a war for humanity's very survival, our deadliest weapon is our greatest...


