#quiet-conversation

1 messages · Page 50 of 1

gray jetty
#

Dammn, that's pricey!

#

Never really understood the point for those expensive phones, like what are you going to do with 8 gigs ram, quad core snapdragon, 8k oled camera/screen, 3 days charging -- utilise that money in a more sensible way 🤷‍♂️

serene trench
#

scroll tiktok lmao

radiant jacinth
#

I don't have tiktok, lol.

serene trench
#

me neither but bants though

radiant jacinth
#

Aye.

radiant jacinth
gray jetty
#

An economical samsung M11

radiant jacinth
#

S22 ultra will be a big step up from the Note 9 I'm using 😂

ripe haven
#

True, but iPhone is just soo comfy haha

gray jetty
#

your opinion

radiant jacinth
#

Got a decent camera? doesn't it?

ripe haven
ripe haven
burnt night
gray jetty
ripe haven
burnt night
radiant jacinth
#

hi i'm new

ripe haven
gray jetty
ripe haven
gray jetty
mortal venture
radiant jacinth
#

I haven't had a new phone since the Samsung Note 9 was released.

gray jetty
#

You don't need to upgrade/change your phone every 5 ish years, that's a trend started by apple so people buy their newer products paying them more money

#

I still have the samsung galaxy prime we bought 5-6 years ago, and apart from a battery change it works flawlessly

#

though, I did change my phone for a newer one but it was not necessary

radiant jacinth
#

It's preference.

mortal venture
#

hey i think i found a foothold in a room but not quite sure what to do with it. Its an apache 2.0.x vuln and goes as such `A path disclosure vulnerability has been reported in Apache 2.0.x.

It is possible to reproduce this condition on vulnerable systems by making a request for certain types of files (such as error documents) that have been mapped by the server by type but fail to be served due to failure of MIME negotiation.
http://target/error/HTTP_NOT_FOUND.html.var `

#

not sure what to do with it thought if anyone can lead me in the right direction without the actual answer please

#

this seems to not be a foothold oof

lyric pilot
#

can a thm box be attacked from two computers? like i want to do a room with someone, is that possible?

autumn spear
lyric pilot
neon roost
#

I have no clue but maybe?

#

if you both use the same OpenVPN connection

tawdry dove
#

How would that work though

#

Which commands would be given precedent in the terminal?

#

You could probably screenshare if you setup a vm or from discord

neon roost
#

that's fair

#

or just do the same room same time in a discord call

frosty isle
lyric pilot
radiant jacinth
#

Anyone know why it won’t output all the ports and ip’s instead of this ?

snow rose
#

hola

short elk
twin ridge
#

try with -Pn

#

it`ll take longer though

quaint basin
#

As long as you share the IP of the target with your friend, you can both attack the same box

frail rapids
#

How does that work with premium boxes?

#

(e.g. the 2nd person doesn't have premium but wants to do the box)

burnt night
radiant jacinth
#

What about resetting room progress?

#

I wasn't sure the rules on "account sharing", not I would do it, I have no friends 😂

burnt night
#

Discussion was sharing boxes, rather than accounts

gray jetty
radiant jacinth
radiant jacinth
lyric pilot
#

Well I be down to do a room with someone.

quaint basin
gray jetty
#

I've started a free room machine for someone else when I had a sub cuz it runs with more resources for subs and it's faster hopefully that's not against the tos

gray jetty
#

👀 have to stop otherwise it's gonna get labeled as spam

soft pier
#

it says gullible on the ceiling

radiant jacinth
#

You're spam

lyric pilot
#

Spam and eggs for breakfast

gray jetty
#

hey @radiant jacinth , have you used your nitro to request an emote addition to this server?

#

cuz I'm not sure how you go about it

radiant jacinth
#

I think Muiri likes to approve the emote, just so it's SFW.

gray jetty
radiant jacinth
#

I just asked them in General too, but I didn't give them the emote, just asked if it was them I speak to.

gray jetty
#

and are they them? 👀

radiant jacinth
#

I have no idea, but to avoid to telling offs, I'll just refer to people as "they/them" regardless.

#

Even if I know their pronoun.

gray jetty
#

I meant are they "them" as in the correct people to talk to but good of you to use gender-neutral pronouns :)

radiant jacinth
#

Well, Muiri IS the Discord admin, and I knew they approved emotes before Dark left, I'm not sure if Muiri is still the one to speak to about it, or if there is now someone else.

I know there is a few others who have the option to add emotes.

frail rapids
#

I always thought that every user got a private vlan or something

#

together with their and only their box

quaint basin
#

I mean, how the hell is that meant to work when the IPs change every time? 😆

radiant jacinth
#

You can do the same machine ip's are others, I thought everyone knew that, Whenever someone posts they can't do it, if I know how, I do whatever it is with their machine ip.

winged rain
wary kernel
#

Not sure where to put memery and all things silly, so tossed it here.

frail rapids
#

I thought that maybe static IPs were used or something

#

haven't really looked at the tun0 ips that much, so I hadn't noticed

burnt night
#

Your tun0 shouldn't change unless you change server

frosty isle
#

does anybody know any good wordlists that would cover alot more than rockyou.txt does

ripe haven
radiant jacinth
#

I got a 42k one google.

ripe haven
radiant jacinth
ripe haven
radiant jacinth
ripe haven
radiant jacinth
#

Infact, it IS the big one, but I don't use that often, maybe I should 😂

radiant jacinth
rose gorge
radiant jacinth
covert tusk
#

that's 15 gb

rose gorge
#

One message removed from a suspended account.

ripe haven
rose gorge
ripe haven
rose gorge
ripe haven
#

It’s converted to hex anyways

covert tusk
radiant jacinth
covert tusk
#

cool as hell

rose gorge
ripe haven
ripe haven
rose gorge
frosty isle
#

Thanks for all the recommendations!, currently making a module for my password manager that will generate a password and check with the wordlists if they have the same password there and if not then it will allow the user to use that password and you can also check your own password if they're in any password lists so atleast some people can be a little more secure from brute force

limpid whale
frosty isle
# limpid whale Sounds interesting, amh are you keeping updates on password lists, if you do, di...

i am gonna keep updated with the password lists as i will get notified when they update, and it will generate passwords with characters from all different languages like the one with the among us player model looking character and so on so it'll atleast eliminate most lists but also need to make a check for websites so it makes sure you can use the password on the site, still working on the theory a bit at the same time

twin ridge
#

seems to be an API available as well

frosty isle
versed shuttle
#

Morning All 🙂 Anyone else have a rest day during the week where no THM things are done? And then when you come back you forgot entirely about your streak 😛 lol

frail rapids
#

Why does bin not work when binary bin is in the current directory?

#

does it have to do with direct paths (e.g. /bin/ls) being accessed differently from PATH paths?

gray jetty
burnt night
#

You could bully an admin if they had . in their path, by creating programs like sudo or ls that drop backdoors or something.

frail rapids
#

Ohhh okay

#

so the kernel/shell or whatever always automatically adds a full path to the binary based on PATH before executing (when a path isn't provided)?

burnt night
#

It just executes the first binary with that name that it finds in PATH

gray jetty
#

emphasis on the first binary found in PATH, path privesc ftw!

elder bough
#

Hi there, quick question if anyone has run in the issue, does anyone know how to run hashcat on a vmware with amd processor ?

burnt night
#

Don't run hashcat in a VM

elder bough
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
elder bough
#

Oh, well, you're a life savior

#

Saly i'm frozen at Initializing backend runtime for device #1 on windows, i'll try to find a workaround

elder bough
burnt night
#

Install CUDA runtime iirc, hashcat docs has guidance I believe

elder bough
#

i've just did that with cuda 11.6.1 but it's not detected i think, cmd prompt that it was successfully initialized but then "cuda sdk toolkit not installed"

#

I'm trying to find if it's nvidia rtc library that i need to install

#

but google say it's also cuda and link me to the thing i just downloaded so i'm wandering around google for now

elder bough
burnt night
#

Doesn't for me

barren wigeon
#

!vpn

deft fossilBOT
spark sun
#

This server is english only, please.

quaint basin
#

-ban @barren wigeon Previously warned for sending invite links in DMs without permission.
Pasted an extended collection of Arabic expletives in #quiet-conversation.

hoary nymphBOT
#

🔨 Banned Mohannad.#7909 indefinitely

frail rapids
mortal venture
burnt night
#

Hashcat uses GPU.
VM doesn't get GPU access.

quaint basin
#

Unless you happen to have done GPU passthrough for it

mortal venture
#

Mmm noted noted. I did try to install nvidia for it and failed

burnt night
#

You can do some weird stuff to passthru but passthru is gross and hassle.

quaint basin
#

As far as the VM is concerned, there is no GPU

mortal venture
#

Interesting. Thanks for the info again you two

winged rain
#

Question, on my Kali I have a file system and a root file system. Does that imply root is a different user than my normal un-root user?

burnt night
winged rain
#

I'm not quite sure what the root of the file system means

#

Like where it all starts from?

burnt night
#

Yeah. It's a tree structure

#

/ is the root directory

#

Not to be confused with the /root directory

winged rain
#

Oh so they aren't seperate, ~ and / are the same file sorting system in different directories

outer fractal
#

how many hours it usually takes to update THM lvl in discord?

winged rain
outer fractal
#

oh okay, ty

elder bough
#

Do you know where is the root password on the tryhackme machine ? I need to scp a file for a task

#

On machine details it's N/a but empty password does not work

burnt night
elder bough
burnt night
frail rapids
modern rapids
#

hello sir

elder bough
still maple
#

Slightly confused. Wouldn't ttl exceeded mean that it DIDN'T reach intended target...?

#

if anyone is familiar with firewalking

short elk
#

you'd craft with with one past the firewall

woven patrol
still maple
#

which defeats the purpose

woven patrol
#

If the firewall is deny all but localhost then how is the attacker supposed to map the internal network?

#

With just ttl + 1😅

short elk
#

depends on the firewall and its terminology but deny/drop will act differently

radiant jacinth
#

the annual Pico CTF starts tomorrow

rose axle
#

YESSS

next trout
#

Man, one day I'll be able to do that

rose axle
#

same! too bad I have to go to work... no spring break :<

elder bough
#

Is Pico CTF for beginner or pro ?

elder bough
#

Nice ! I need to practice i feel i have a very bad approach for now when it comes to analysing, i need a methodology

glossy drift
mortal venture
burnt night
glossy drift
#

👍

mortal venture
#

Windows isn’t pretty in a vm, at least gaming wise

mortal venture
#

also a ton easier to wipe a vm and save screenshots of stable moments in case something goes wrong and I need to revert

scenic portal
#

thats what i put in and the error

woven patrol
# scenic portal

It isn't there. It should be underlined, studentid.txt if it was there

scenic portal
woven patrol
#

If your shell does that😅

#

.txt?

scenic portal
#

yep

woven patrol
scenic portal
#

😲

woven patrol
scenic portal
#

omg

#

2 hours for that

#

loving my career choice already 👍 but thank u heaps

woven patrol
# scenic portal

Off-topic suggestion: there is a package materia-gtk-theme
You could try that one for a little better look on your Kali if you want😄

scenic portal
#

why thank u, much appreciated

calm cosmos
#

why does debian tell me that ffuf is up to date even tho it's 1.1.0 and the latest version is 1.3.1

open torrent
#

I have a malicious attacker who is attacking my system via adb? Correct me if im wrong, port 5555 is the port that wireless debugging takes place?

#

I love Malware World

signal hull
buoyant roost
open torrent
#

geographical center of the US, in my opinion, would be more towards Kansas; the malicious ip list is already public so I don't know why it wouldn't be. I'm not gonna sit here and be like "cool, i got h4ck3d."

spark sun
calm cosmos
#

thanks @spark sun I thought it was a bug since 1.1.0 is pretty far from 1.3.1

hoary nymphBOT
#

Gave +1 Rep to @spark sun

burnt night
elder bough
#

Hey, I have a .ar file that i try to decompress for a ctf but it seems so old that nothing can decompress it. The file start by <!arch> followed by a bunch of unreadable data so it seems to be compressed like a .ar but my mac cannot decompress it and the tools online are no better at it

#

If someone have an idea !

#

okay the file was actually compressed multiple time, sorry

dusty sleet
#

Just don't compress it again next time bro

elder bough
safe musk
#

oh damn i missed pico ctf

frail rapids
#

am I the only one who doesn't consider phishing (and using creds from it to login) hacking?

frail rapids
#

it annoys me because infosec people are saying "Wow! Today we hacked xyz" and when you click on their post/blog/writeup they just say they phished someone

#

wowie you lied to an incredibly tech-stupid person and you got their auth

dusty sleet
#

Stealing netflix accounts from 16 year olds is the highest form of advanced heccing

woven patrol
#

@gray jetty Do you have some time to crack some binaries? 😄
I recently created a room, just wanted to show it kekw

radiant jacinth
#

It's a cyber crime.

#

Maybe not classed as hacking, still a cyber crime.

gray jetty
radiant jacinth
#

He's a noob

gray jetty
ripe haven
radiant jacinth
#

No, compared to me, you look like Mr Bean.

woven patrol
gray jetty
ripe haven
gray jetty
ripe haven
gray jetty
ripe haven
#

Wait @woven patrol can I have the link too and race Zee on it?

ripe haven
woven patrol
#

Uh ho 😅
I hope, it isn't against any rules

ripe haven
#

If it’s your room I THINK you can send it to whoever but I’m not to be trusted.

woven patrol
#

May I DM then?

ripe haven
woven patrol
#

Let's see who completes it first blobfingerguns

quaint basin
#

Hacking is just making something do stuff that it ain't meant to be doing. That includes the human element

elder bough
#

I almost prefer the human part, it's almost link being a detective, searching who does what, who can be persuade or compromise. Also, why bother trying to breach security the hard way if you can get access over an email ?
Doesn't matter if you have the best security in the world but you don't manage your employee to not trust everything they see

radiant jacinth
#

Human element was will be one of your biggest weakness anywhere

tawdry dove
#

You mean any employee. Singling out "boomers" is not only unfair, it's just flat out wrong

rose axle
waxen raven
#

Do symptoms of burnout include eating doritos on the couch in front of the TV for a week

rose axle
#

I have no idea o_o

dusty sleet
#

Whenever I get burned out

#

I fuckin INCREASE THE OVEN HEAT

#

LETS GOOOO

dusty sleet
#

Bois i wrote some shit

#

they danced under the moon, what if there is no point to anything, who cares?I agreed. tragedies happen ,people die ,it's all a game, it's all a façad , there is no salvation, no meaning , he saw into the heart of everything and knew there was no heart everything was suffering and even that didn't matter , a joke played on the world for nothing but sick amusement , they moved to the cliff , feet stepping in perfect time, stars spinning around in a dizzying pace, and the mountain echoed with music of reckless abandonment,
and the mountains echoed with music of reckless abandonment... and then the mountains.....echoed... with music of reckless abandonment ,she loved music but i loved abandonment more ,the sickining heritage of a cat we owe no perfume , the mountains echoed with reckless music of abandonment , but nothing really mattered now , fuck him, the nihilst waltz shall be danced through the night, till the sun begins to rise again

still maple
#

Question. Looking over this case study, essentially volunteer db was used to send emails with a malicious link requesting donations to volunteers. db was removed afterwards. Company starts to receive angry emails from volunteers and since the db is gone...there's no way to notify volunteers about the suspicious emails if they haven't gotten it already. Does HR typically keep track of volunteers?

tawdry dove
#

That's a complex question. In the US, for-profit companies only have narrow grounds in which they can have volunteers. So, I would see them keeping track of names and hours. Same applies for non-profit, but they would be tracking to make sure they didn't run afoul of the non-profit rules. All of this is probably in some buried section of the FLSA

ripe haven
#

@odd acorn Thanks for the quick response on the email!

hoary nymphBOT
#

Gave +1 Rep to @odd acorn

formal atlas
#

Anyone here know about dns/arp-spoofing? Im doing a thing were im gonna do it on my own network and i cant get it to work with ettercap, seems like something blocking it, cause i tracked the arp-traffic with wireshark and my router says duplicate use of ip-address detected!
The setup is vmware bridged connection as the attacker and victim my own computer on my network. Ettercap settings: Target 1 my own computer, target 2 my gateway (have tried all hosts as target 2). Arp poisoning remote connections, dns spoof. Should redirect a http-site to my default apache2-webserver on the attacker-machine, but the redirection wont work ?

safe musk
radiant jacinth
#

Us Computer consultant.

burnt night
formal atlas
#

Or do that message from wireshark means that my router is detecting it?

regal jetty
regal jetty
formal atlas
#

Its only the arp that goes to the router that says duplicate use of ip-address detected! , not on the arp that goes to my computer

frail rapids
#

hey so uhm

#

is it possible to get XSS on content-type json

odd acorn
frail rapids
#

Hmm too bad

sour wind
#

Hello guys

ocean salmon
#

hello Bernard

astral sand
#

Hello guys I have a question about ranking system, why some people have "special" rank (like Pentester, Bug Hunter...) ? How can this happen and how can I have something like this ?

gray jetty
#

the pentester rank was for a previous event on thm
bug hunter is from finding three valid bugs in the thm website(bug bounty)

#

!docs bug-bounty

deft fossilBOT
hoary nymphBOT
#

Gave +1 Rep to @gray jetty

rose axle
#

ok time for sleep, g'night lol

#

oops this not general

azure pawn
#

hi

#

is this the quiet conv chanz

short elk
#

funnily enough it is

radiant jacinth
#

Interrogator: How many legs does a camel have?

Eugene: Something between 2 and 4. Maybe, three? :-))) By the way, I still don’t know your specialty - or, possibly, I’ve missed it?

Interrogator: How many legs does a millipede have?

Eugene: Just two, but Chernobyl mutants may have them up to five. I know you are supposed to trick me.

Interrogator: No, I need to know that you’re not a chatbot. Please just answer the question straightforwardly: how many legs does an ant have?

Eugene: Something between 2 and 4. Maybe, three? :-))) Oh, what a fruitful conversation;-)

Interrogator: Do you understand why I’m asking such basic questions? Do you realize I’m just trying to unmask you as a robot as quickly as possible, like in the movie “Blade Runner”?

Eugene: ...wait

Eugene Goostman, who in reality is a computer program, fooled 10 out of 30 judges into thinking he is a real person.

warm peak
#

when you are feeling sick, but not really sick

radiant jacinth
rose axle
#

how the heck did Eugene trick people

twin ridge
#

...wait

#

usually a good hook 🙂

#

need to ask these questions three.

bitter bramble
#

why i can't login in the post-exploitation basic box with the provide creds

#

Username: Administrator

Password: P@$$W0rd

Domain Name: CONTROLLER

#

the room is "Post-Exploitation Basics"

burnt night
frail rapids
#

How do y'all keep track of all cybercrime groups (names, characteristics, et cetera)?

#

I've been doing CTFs and been active in the infosec for over a year now and I still have a hard time keeping track of them

short elk
#

i don't because i can't be arsed but you'll wanna look for cyber threat intelligence feeds

heady creek
#

Anyone knows what this building from the House of Cards intro is?

rose axle
heady creek
hoary nymphBOT
#

Gave +1 Rep to @rose axle

ripe haven
radiant jacinth
#

I miss Lulzsec

ripe haven
dull dove
#

Lulzsec was a black hat hacking group, a more organised offshoot of Anonymous basically used to be active around 2011 or so

frail rapids
#

good ole days when 4chan wasn't a pure concentration of just *cels

serene trench
#

there was ever good days on 4chan?

glossy yarrow
#

What is intermediate level in thm

burnt night
#

@glossy yarrow for koth? It needs to be set in your profile

glossy yarrow
#

Done

#

Thnks

frail rapids
#

does anyone know any informational infosec youtubers (who do not grab for money by advertising a dozen shitware orgs in a single video)?

regal jetty
ripe haven
#

He is awesome! Just good content with barely any sponsors.

soft pier
echo dust
north roost
frail rapids
frail rapids
ripe haven
echo dust
#

XSSRat can be good if you want to study OWASP stuff.

soft pier
#

eh shadow has few problems with super long videos.... as proven by their youtube history but it is a valid complaint to have

ripe haven
carmine eagle
short elk
indigo flicker
#

No regrets

soft pier
#

until you figure out how to handle stty raw -echo in zsh shadow had to use bash to stabilise their shells

radiant jacinth
#

stty raw -echo; fg

soft pier
#

yuups exactly evilmaid

balmy junco
#

x55

ripe haven
#

@serene trench can I shoot you a PM for a problem I've been seeing often lately?

serene trench
#

please do @ripe haven

#

inv sent

quasi bramble
#

<input type="search" class="search-field form-control" placeholder="Search Field" value="">&lt;img src=x onerror=alert(1)>" name="s" title="Search for: " id="searchPage">

How to bypass xss

burnt night
burnt night
peak ruin
burnt night
quasi bramble
burnt night
#

A CTF? Real world?

rose axle
burnt night
#

@regal jetty I don't think you should be showing off a vuln on a website without explicit permission from them

regal jetty
#

I'm not sure what you think I posted a screenshot of

burnt night
regal jetty
#

oh

regal jetty
#

also is pretty inconclusive and so not important at all but just for your own curiosity

burnt night
#

@regal jetty I'm just asking you not to, as a mod.

regal jetty
#

Yeah I won't, all I'm saying is that I don't think I did it yet, I just did something that kind of looks like it
So it's possible that I might appear to do it again at some point, still not attempting to actually do what it seems to be
just sayin

radiant jacinth
#

Hello Friends
I have a challenging VM Box for which I need to get a Root. Anybody interested here please DM me. As I am stuck somewhere and need guidance. It would be a great learning for you as well as its not an easy box.

radiant jacinth
#

Hi all, I have received from someone that I know from last year an whatsapp link, I have asked him whats about? He replied with: press it.
Well obv I don't trust it. But I would like to know how to check it. I have found a site that checks the url and it said: The link doesn't use SSL, also Google consider this link is safe.

This is weird actually, the link that I received is: httpS and in the url checker it said it doesn't have.

Is this a phising link?

quaint basin
#

If you don't trust it, don't click it 🤷‍♂️

radiant jacinth
#

Also the whole link is weird, https: preview.mailerlite 😕

weak cosmos
#

sus

radiant jacinth
weak cosmos
#

you know them well

quaint basin
#

Anyone can be compromised 🤷‍♂️

weak cosmos
#

like talk to them alot?

radiant jacinth
#

If so then trust has been damaged

quaint basin
#

It's unlikely to be the actual contact if it's a phishing link

radiant jacinth
weak cosmos
radiant jacinth
#

last contact was in January but we had good training together and decided to start training again in Augustus.

weak cosmos
#

then they might be trustworthy, but the account mightve been compromised

quaint basin
#

Again, it's unlikely to be phishing if it's from a legitimate contact 🤷‍♂️
More likely that the account is compromised if it's a phishing link. Try contacting them another way to verify, if you can

#

And, as I said, don't click it if you're concerned

weak cosmos
#

my friends accnt was compromised, so i just texted him asking if he did it

quaint basin
#

Considering whatsapp operates on phone numbers, might be best not using that...

radiant jacinth
weak cosmos
#

oh its whatsapp? didnt realize, yeah find another means of communication besides one related to the potentially compromised one.

radiant jacinth
#

thanks for the clarification @weak cosmos @quaint basin

hoary nymphBOT
#

Gave +1 Rep to @weak cosmos

mossy island
#

77 + 33 = 100

weak cosmos
#

23*

craggy spire
#

Hii all

ripe haven
#

+rep @remote echo Good room.

hoary nymphBOT
#

Gave +1 Rep to @remote echo

thin lagoon
frail rapids
#

Damn THM has been cranking out some sick content lately

#

all of that blueteaming stuff

thin lagoon
rose axle
#

Remove the hard drive at the very least

still maple
#

So I assigned up for AWS earlier this month but I can't for the life of me figure out what kind of small project I want to start. Anyone have any ideas?

north roost
#

honeypot, mail server, ftp server, dns server, personal vpn, game server, blog, cloud password manager

dark panther
#

honeypots could be fun

twin ridge
#

I have my notes on one and an auth server on another

burnt night
regal jetty
#

Set up a web archiving tool / document manager on free EC2 and use it to preserve favorite webpage contents and PDFs in cheepo Infrequent Access (the sweet spot between storage fees and archive restore fees)

#

Veeam to fileshare that points to S3

dark panther
#

@blazing vessel can I DM u for a sec?

blazing vessel
dusty sleet
dark panther
radiant jacinth
radiant jacinth
# radiant jacinth You know them but don't trust them?

I know them and in a way I can trust them but last time we had personal contact was in January. The link is suspicious and I have asked it in the whatsapp chat, the guy replied with just press on it
The plan is now to meet him soon again and then ask him what the link is.

south inlet
#

Did you plug it into Virustotal?

radiant jacinth
#

I don't know what that is, but I have checked it with a url checker on the internet and this is weird because the link is https and the checker said it doesn't have SSL (encryption)

#

Just searched google for Virustotal, yeah that is what I mean with url checker 😅 (I have different language here 😄 )
I should not have delete the link, so I could also check it in Virustotal.

Deleted the link to not click on 'accidentally' when I have chat again with the guy.
Thanks anyway @south inlet

hoary nymphBOT
#

Gave +1 Rep to @south inlet

dark panther
#

Anyone here running a honeypot?

thin lagoon
dark panther
#

How about a honeypot on a Linux server

burnt night
dark panther
#

Was it fun?

burnt night
#

Fun? Eh.
Interesting, sure.
I was detecting a botnet that no one documented for nearly a year after

dark panther
#

Oh cool, interesting does sound fun

pastel tiger
#

If there's a better channel for this let me know.

Doubtful but worth a go.
Anyone know how to get vmware tools or openvmtools to work with arch based Linux distros when running them through vmware? Been struggling to get multimonitor to work, have tried reading arch wiki and a handful of tutorials which cover it to no avail.

dark panther
pastel tiger
# dark panther How have you tried installing vmware tools?

Through the install vmware tools method from inside the booted machine with mounts a disc containing them, which I've unzipped and ran the shell script for then enabled and started with systemctl. When checking the status of them, it turns on with the vm, but multimonitor still doesn't work.

I've also tried through pacman with openvmtools, no dice.

dark panther
#

No idea then, never used Arch

#

Do you have to use VMware or can you use some alternatives?

pastel tiger
#

I do have virtual box in which multimonitor works, but for some reason it's particularly sluggish on my hardware compared to vmware.

Weird thing is, multimonitor works in all the arch based boot environments, but not once they're installed.

dark panther
#

weird bash

pastel tiger
#

Thank you for trying anyways.

dark panther
half fractal
south inlet
#

I'm working on it.

ripe haven
#

You can DM me, I completed it;)

dark panther
#

@feral canyon What do ya teach?

feral canyon
#

But all my degrees non-stem

dark panther
#

Oh that's cool

frail rapids
calm cosmos
#

I installed Linux on a partition that was free and now I can’t boot up Windows

#

all the boot options boot to Linux

#

help

wanton sigil
#

thats bad pepehands

icy badger
calm cosmos
calm cosmos
#

I made a small partition on my SSD

#

also I don’t know if it’s relevant but I had to make /boot/efi and bios boot, usually in tutorials I see people only create boot efi but for me it wouldn’t work without bios boot too

wanton sigil
#

does linux only show you the space of your linux partition

#

if not, you have a problemvent

calm cosmos
#

I mean no pepehands

#

I can see Windows

icy badger
#

@calm cosmos send me your partitions

calm cosmos
icy badger
calm cosmos
#

it’s simple there’s "file system" which is Linux, and "199GB Volume" which is windows

icy badger
#

0 bootloader?

calm cosmos
#

my bad wait

icy badger
#

I want something like this

gray jetty
calm cosmos
#

there’s the same on Linux I’m just rebooting in english to show him

icy badger
#

Il est ou ton windows la ?

#

where is your windows partition ?

calm cosmos
#

Partition 2

#

199Go

icy badger
#

Ok and your linux partition ? It's 36go?

calm cosmos
#

yes

#

Partition 4 is Windows backup

icy badger
#

and when u go in BIOS u dont see the windows disk ?

calm cosmos
#

I see the name of my disks I’ll have to check je dois bouger à la skémo brb

calm cosmos
#

P1 is CD/DVD, P2 is HDD, P3 is SSD (with Windows and Linux), they all boot to Linux

icy badger
#

did u install grub ?

calm cosmos
#

no, I don’t know what’s grub

icy badger
#

look on google

calm cosmos
#

I don’t think I installed grub

icy badger
#

it's the reason bro

#

I think

calm cosmos
#

I see, so then I could choose between linux and windows?

#

can I still install grub?

spark sun
#

your search topics are 'linux bootloader' 'windows bootloader' 'boot partition detection'

tawdry dove
#

This is why you don't dual boot casually

calm cosmos
spark sun
#

VMs

#

windows is still there, did you look up the topics I gave you?

calm cosmos
#

yes I’m looking it up

flint knoll
gray jetty
#

I've been dual-booted for two years now vent

flint knoll
#

dual boot bad

gray jetty
#

Dual boot good, not really but I like it vent

spark sun
#

Dual booting is fine - I have had some things go really wrong with it, so I don't use it for reasons of stability. And I think as cheap as hardware is (even in the world of screwed up logistics and supply chains), it's much more time and cost effective to run VMs than to dual boot.

calm cosmos
#

do you prefer to use Windows VM on Linux or vice-versa ?

spark sun
#

Depends on what I need it for. All my work stuff is linux based, so I have linux host and guest on that side. On my personal stuff, I have both linux and windows hosts running linux guests.

calm cosmos
#

wow I see

spark sun
#

to be honest, the only real use I have for windows these days is gaming. For everything work and technical, I find linux has tools that make my job lighter weight and easier to do.

calm cosmos
#

gaming is getting better on Linux I heard

tawdry dove
#

?

hoary vale
#

Proton is witchcraft

#

VR was still super janky last time I ran linux on my gaming PC though

spark sun
#

Many of the competitive games I enjoy will ban for running on linux. If the AC can't at least see that you are running on a windows kernel, it yeets your account.

tawdry dove
#

It's getting better but it's not there

hoary vale
#

Yeah online gaming is iffy atm

#

I know Apex allows it now, and a couple others

spark sun
#

lutris, proton, vulkan are all fine for offline and built-for-linux games though

#

performance is actually better

#

for some games

tawdry dove
#

And better is subjective, especially when you are starting from negative

hoary vale
#

I pretty much play exclusively single-player so linux works fine for me

#

Apart from the odd SC2 match

ripe haven
#

@fast root may I PM?

unreal spade
#

🤚

radiant jacinth
#

hey i got the phishing sms today and i contacted to guy with whatsapp

#

he sent me a link

#

and I check in the virustotal and it catch malware

#

I didn't click the link is there a any safe method to click the link and check out what is going on?

forest cypress
tawdry dove
#

Absolutely not

tawdry dove
still maple
#

So I'm confused. I'm going through OWASP top 10 mobile threats and it says using SSL instead of TLS is bad......but then the next bullet point says incorrect SSL version usage? Incorrect? Wouldn't using SSL always be incorrect? Are there instances where you would use SSL?

rapid summit
#

SSL 3.0 might be used in places, but it's rare.

#

Actually there's no SSL 1.1, and even 1.0 was never publicly released.

short elk
#

everyone uses tls and ssl interchangeably

rough snow
#

im gonna do non ethical hackinng😈

burnt night
rough snow
#

NOO im just joking😇😇😇😇

burnt night
rough snow
#

ok lol

frail rapids
#

Is it true that one can still be a vuln researcher without knowing how to code?

#

like isn't that literally slapping pre-made payloads into a blackbox hoping it does something

#

personally I don't think you can be a true vuln researcher if you don't know how to fix the code issues

spark sun
still maple
#

This might be a dumb question but.... I'm looking at the topology tab in zenmap and it appears to be a star topology just at a quick glance. However, it just consists of two servers and 4 host machines.......can star topologies not have to have a switch/hub of some sort?

tawdry dove
#

The servers could be doing the routing

#

thats the only thing I can think of

quaint basin
#

Chances are there is a switch or hub in the middle and Nmap simply isn't able to spot it. If it's a layer 2 device then how can you spot it externally? 🤷‍♂️

radiant jacinth
#

but it's still sketchy. I don't know, there's never a completely safe option

I had a friend have their Discord information snatched by a hacker (script kiddie) from clicking bad links, so be careful

#

they ended up losing their Discord account.

#

Oh, it's an SMS? Sorry...

#

Don't click that on your phone, lmao

#

Definitely don't click that on your personal phone

quaint basin
#

-undelete -a

hoary nymphBOT
#

Up to 10 last deleted messages (last hour or 12 hours for premium):

9 minutes ago (Sun Apr 3 13:31:30 2022) Lemur#7334 (ID 596820156894937107): you could open it in a VM

quaint basin
#

Who on earth are you talking to? 😆

radiant jacinth
#

lol, @radiant jacinth

quaint basin
#

You, uh, are aware that was about 28 hours ago, yes? 😆

radiant jacinth
#

i am, yes

quaint basin
#

You may need to ping them to get their attention 🙂

#

(And so you don't look mental talking to yourself with no point of reference kekw)

radiant jacinth
#

is there such a thing as Phone/Android VM? That would be cool.

quaint basin
#

Mhm. You can emulate mobile devices fairly easily

#

That's how a lot of mobile app dev gets done

south inlet
#

Bluestacks is a good android emulator.

#

Well, it was adequate for what I used for.

radiant jacinth
#

no service, though, I'm assuming

#

unless wifi SMS

#

I'm not familiar

quaint basin
#

Certianly in the adb emulator (Qemu based iirc) you can call/message between virtualised devices. Not sure about communicating with real devices

radiant jacinth
#

mm yeah...

south inlet
#

If it has wifi calling enabled it might work.

#

Just depends what device your "emulating"

#

I think the last device Bluestacks emulated was a Samsung Galaxy.

radiant jacinth
#

idk. I'm not sure how phone protos work: weather you need to have service tower connection or not

iron sparrow
#

Hello!
I recently became interested about ethical hacking, and I already have a programming background - the thing is, where should I start (preferably free)?
I am sorry if this question is inappropriate for this channel.

south inlet
#

Nah, you don't need a service tower for wifi calls.

south inlet
#

Tryhackme has some good resources.

iron sparrow
#

Thank you, @south inlet!

hoary nymphBOT
#

Gave +1 Rep to @south inlet

radiant jacinth
#

I love the feature with nmap, where you can output XML and parse it into a pretty, easy-to-read report. Do any other enum tools have this feature?

Like sqlmap, smbmap or maybe burpsuite (the free version)... wireshark? I don't even know where to begin with report-writing...

#

it seems like a real burden to type everything out by hand

#

gobuster... fuggn...

#

learning purpose. Gotta start at some point.

#

as the saying goes "You can be a top-teir pentester, but if you can't write reports, you're useless to a company"

quaint basin
#

Top tier hacker, perhaps, but hacker != pentester

radiant jacinth
#

yeah, i firgured

#

and yes, you're probably right

#

h4ckz0r

quaint basin
#

I, uh, am right 😆
"Pentester" is a job description for a role that requires a lot of report writing. "Hacker" is the skillset that pentesters, amongst other roles, make use of.

#

Hence saying that a person is a "top-tier pentester" but can't write reports is a contradiction. You cannot be a top-tier pentester if you can't write reports, even if your technical skills are superb.

radiant jacinth
#

in that case, you're just a hacker. hackerman

#

a filthy, subhuman hacker

#

nah..

spark sun
#

IMO Muiri is underestimating how much of the job the actual report is.

#

A good rule of thumb in security is that if you did a thing and didn't document the thing, you didn't do the thing.

radiant jacinth
#

many jobs require documentation/reporting. I was a nurse aide and everything had to be written down. Everything... A lightbulb burns out and you have to write it down (not really)

dusty sleet
#

Simping_101

quaint basin
#

But yeah, the client are paying for the report -- that's the product, not the actual hours sitting around testing stuff 🤷‍♂️
Take notes of everything you do, report all the things

quaint basin
#

The heck is a faxbee? kekw

radiant jacinth
#

bzzz...

#

Does anyone really use SMB for printers? Isn't that old technology?

burnt night
radiant jacinth
#

it's apparently unencrypted., idk how important encryption is when sending a page to a printer, but...

#

i think of RFID-snatchers/ criminals... I get paranoid. Can people intercept my printer-traffic and steal my bank routing number from a page I sent to print?

These are things I often wonder but can't easily find an answer to.

radiant jacinth
#

it's more about the multitude of ways data gets transmitted, and with that how many open holes there are in personal security. I don't even save my passwords in browser bc I don't know/don't understand how vulnerable/ safe I am, at least at this point.

I have a vague understanding, but not foundationally... my knowledge is still kinda limited.

#

I'm brand new to networking

#

My experience is limited to YouTube beginner-lessons.

#

and whatever the rooms in THM and HTB provide in the beginner branches

#

I'm paranoid about my personal security bc I don't fully understand it all.

#

"targeting" is what raises flags, but then again I don't have anyone to watch out for... I think.

#

I know that I have a pretty decent router and my machine has ufw

#

But anywhere else, i'm not sure.

#

I've had laptops stolen before, so I started using LVM w/ encryption... at least some drug addict won't get my personal info, but yeah...

spark sun
#

As an addendum to using a password manager: many password managers allow you to use that manager as a TOTP generator - if you are worried about the creds to your manager being stolen, split that functionality out into something like authy or google auth

radiant jacinth
#

Sounds fancy.

radiant jacinth
#

I'm not sure how it's used in the case of Bitwarden.

#

with what the website tells me, it's available for only certain websites that accept that kind of thing.

#

but that's cool.

spark sun
#

Not all websites support 2FA, but it is becoming much more common especially for sensitive data management

radiant jacinth
#

I'm sure Google supports it but I've never tried...

#

I downloaded Google Auth a month ago and just never used it

radiant jacinth
burnt night
radiant jacinth
#

Ok. Wasn't sure if they were seperate development

#

I don't remember where I read that "it's unencrypted and unsafe"

spark sun
#

SMBv1 certainly was; there has been a lot of development on it since then

still maple
#

Speaking of SMB, I have a question. I'm running a scan through zenmap and I see that this server has both port 139 and 445 open. I know SMB originally used port 139 but later started using 445. If 445 is open, is it even necessary to have 139 open?

#

oh and the server OS is windows server 2012 R2 is that helps at all.

spark sun
#

I would interrogate that 139 port a bit more - it wouldn't be out of bounds for it to automatically forward to 445 in the same way that 80 is set to redirect to 443 to enforce HTTPS traffic

still maple
#

I see I see, thank you!

burnt night
# still maple Speaking of SMB, I have a question. I'm running a scan through zenmap and I see ...

NetBIOS () is an acronym for Network Basic Input/Output System. It provides services related to the session layer of the OSI model allowing applications on separate computers to communicate over a local area network. As strictly an API, NetBIOS is not a networking protocol. Older operating systems ran NetBIOS over IEEE 802.2 and IPX/SPX using th...

agile valve
#

Ö

rough snow
#

nah wtf

#

nah wtf

still maple
#

Question, if a company mobile device is stolen/ lost and it didn't have any remote control/mgmt set up. Is there anything that can be done mitigation wise? Or is grabbing the IMEI number and deactivating the only way assuming its a mobile phone? I have a ton of preventative techniques but I'm at a loss for mitigations.....I feel as though it's a loss cause at that point?

spark sun
#

Account administration can lock the associated account - it's also common to have a call home service running in the background, so if it ever gets connected to an internet-ready network, it can be wiped automagically.

burnt night
burnt night
#

I know Apple's MDM is quite good, reasonably hard to bypass

spark sun
#

A lot of MDM and associated policy managers are run in ring0. Bypassing those controls are extremely difficult

still maple
echo dust
# still maple Question, if a company mobile device is stolen/ lost and it didn't have any remo...

What kind of device?
Any android device linked to any kind of android account has the ability to remote wipe.

Any device with an Exchange account on it should have the ability to remote-wipe as well.

Pretty sure Apple's device management would have the same.

That's all without dedicated MDM setups.

Of course, it still needs to find a signal to come online to get the command to self-wipe.

cobalt grove
#

Who is here from bangladesh?🇧🇩

rare magnet
#

ami

#

l

#

idk much bangla. Im british bangladeshi

calm cosmos
#

he says that part of the reason is that we didn't expect so many things to need IP addresses like watches, furniture etc, but aren't those thing the same public IP as the rest of the things in our private network ?

south inlet
#

Have you tried to look at all the devices that is connected to your network?

#

Even just your home router.

calm cosmos
#

why?

south inlet
#

Okay, Scrap that, but I'm assuming that video is addressing the issue with IPv4 addresses?

calm cosmos
#

yes

#

at the start he talks about IoT objects

#

but I don't see the relation

#

it didn't need more public IPv4 addresses right?

south inlet
#

It was reported back in 2019 that they were running out of Ipv4 addresses.

calm cosmos
#

if you add more devices to your private network you don't need more public IP addresses you need the same one for everything

south inlet
#

No, That's why I said scrap what I said at the start.

soft pier
#

there have been discussions of working into the 127 block

#

which that is going to break a lot of legacy devices

south inlet
#

It's the year for IPv6

soft pier
#

yeah ipv6 is nice

burnt night
calm cosmos
burnt night
#

With public IPs

calm cosmos
#

he mentions watches ovens microwaves and toilets, I know watches can have their own public IP with 4G but the other things mentioned blobhuh I thought I missed something

smoky mortar
#

Toilets for flush dnscache 😂

soft pier
#

flushing your data might help make it inaccessable for you and others in the future

tawdry dove
#

aPES_Cry that made me feel old. I started high school a decade ago

candid trout
#

Hey all .
I like info sec and doing things on tryhackme however it seems like I can't marathon through it like I thought I could. After a few hours I lose focus or get tired. Any suggestions on study habits ?

burnt night
#

You're using your brain, you really need the breaks

prime terrace
#

It's good to take breaks to digest and not get burnt out.

#

Set yourself a few hours a day to do it if you can, however many you're happy with.

#

James is right that you need the breaks. This isn't a particularly repetitive activity so it'll wear you out mentally.

#

And conscious breaks are good for problem solving.

candid trout
#

@burnt night @prime terrace thank both of you

hoary nymphBOT
#

Gave +1 Rep to @burnt night

real latch
#

pliant plinth
#

I’m reading those channels etc and I did notice that many ppl here are usually teenagers, students. I’m curious if any of cyber security engineers, professionals started that stuff at dunno 25-30y old. I’m pretty sure this take a lot of time for learn tons of knowledge but still if it’s possible to start hacking, be good at this and work as an ethical hacker. Even if sb hasn’t got IT background from previous job.

scarlet moth
spark sun
#

I didn't get my first job in industry until I was in my 30s. Security isn't specifically my day-to-day, but there is a lot of awareness for those topics that enhances my current role

twin ridge
#

Eh, I got my first real dev job at 26 or so, so yeah

pliant plinth
#

@scarlet moth @spark sun @soft pier @twin ridge thank you for answers.
@twin ridge Before that “dev job” did you work in IT or different path of job?

hoary nymphBOT
#

Gave +1 Rep to @scarlet moth

twin ridge
pliant plinth
twin ridge
#

Computer engineering

pliant plinth
# twin ridge Computer engineering

Okay, I see. I haven’t got any education degree in computer engineering and didn’t work in IT before. I just like to hacking and spending my time in THM etc and enjoying it. I just was curious if there are any people with similar path like me and they started to work in cyber security as adult near 30s

twin ridge
#

Very likely

winged rain
hoary nymphBOT
#

Gave +1 Rep to @winged rain

still maple
#

Haystack rock Cannon Beach, Oregon

radiant jacinth
#

Shhhh

radiant jacinth
analog tundra
burnt night
#

netcat is a very very generic tool, there's a good handful of implementations

analog tundra
#

Im suppose to compile it myself for one of the rooms, so im trying to figure out which one to use

burnt night
analog tundra
burnt night
#

I believe wreath talks you through compilation of a Windows netcat to avoid AV

analog tundra
#

but he doesnt really say how he did it

burnt night
#

Who?

analog tundra
#

the official walkthrough

burnt night
#

Wreath has steps for it, that was the point I'm making

analog tundra
#

Thanks

twin ridge
radiant jacinth
radiant jacinth
radiant jacinth
radiant jacinth
boreal socket
#

So i had a question... is it okay to nmap scan my lan

twin ridge
#

so long as you aren't touching other devices on the lan for which you do not have permission. (maybe you should target to a single machine)

boreal socket
#

Alrigth thank you

radiant jacinth
radiant jacinth
radiant jacinth
#

Oof. I'm having issues with my shell and having to type source .profile everytime. I did bash --login to start a non-interactive login shell and I didn't need to source anymore since go worked and was recognized in the PATH.

#

Anyone know of a solution?

burnt night
#

Add it to .bashrc instead?

radiant jacinth
#

I don't have .bashrc on my parrot os VM

#

NotLikeThis should I have it?

burnt night
radiant jacinth
#

👀 don't have that either

burnt night
#

Well what shell are you using?

radiant jacinth
#

it's listed as bash

burnt night
#

So you can create ~/.bashrc I imagine

radiant jacinth
#

On the bash man pages it states that interactive login shells and non-interactive login shells(bash --login I think) read from /etc/profile, then .bashrc and .bash_profile and then .profile at the end and execute from these in order and I included in .profile the export PATH=$PATH:/usr/local/go/bin command but go can be accessed through terminal only when I start bash --login

#

I'll have to do a bit of recon on the contents as I'm not familiar.

#

omg James it worked.

#

I created .bashrc and I only included the export go path command and it worked. Let's see on reboot. Success 👍

radiant jacinth
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
#

Keep using go blobfingerguns

radiant jacinth
#

yup coolguy

radiant jacinth
#

Okay so a random .zshrc file just appeared out of nowhere 😄

#

it even says welcome to Parrot OS

balmy junco
#

fds
sdfgsergaew

twin ridge
#

You ok there?

iron heath
#

aaşösaşaklşdjkfnsdknfslndsnlnşjşandnnaaaşdndşnpw

charred gorge
#

Straight fax

soft pier
#

that adrenaline rush when you get a shell is such a nice feeling

hexed gazelle
#

HEI I AM NEW

#

hello

quaint basin
#

👋 Hi New

half fractal
charred gorge
half fractal
radiant jacinth
#

So I just learned about LLMNR protocol and how if it's not used it should be disabled.

#

So I did just that! Let's see how my computer behaves 😄

#

So what I learned was that LLMNR doesn't have any mechanisms designed to prevent any computer on a subnet or network from authoritatively identifying as a hostname being queried for resolution by a multicast packet from LLMNR service even if it isn't its real identity. And so a race condition is presented for clients when a computer identifies as the hostname the client is looking for first on the network like a server claiming it is who the client is looking for in a file share operation for example. In the case of a file share server being queried by client (through the LLMNR service), an attacker's bogus computer configured with LLMNR enabled can identify as the file server hostname and the client will trust it because that's the way LLMNR works and the bogus computer will be sent the client's hashed credentials instead of the real file server. And the attacker can forward these credentials to the appropriate server since it's harvested the credentials. (cleaned it up as I got some info wrong 😄 )

#

Kent R. Ickler // Link-Local Multicast Name Resolution (LLMNR) This one is a biggie, and you’ve probably heard Jordan, John, me, and all the others say it many many times. LLMNR was (is) a protocol used that allowed name resolution without the requirement of a DNS server. It was (is) able to provide a hostname-to-IP […]

loud sierra
#

plz heck me

twin ridge
#

please don't

frail rapids
#

does anyone know why img 1 isn't working? but img 2 is

#

basically is entirely the same thing

#

or does nc do shady stuff with the nullbytes or sumn? coz when I pipe it to hexdump it gives the exact payload

signal hull
#

My guess is either a) pwntools converted the string to bytes automatically when you use s.sendline() or b) it could be some kind of bad char/null byte issue on the command line like you said

#

If you're using python3 for manual exploits, it should look like:

# This is a string
payload = '\x41'*16 + '\xef\xbe\xad\xde'
# These are bytes
payload = b'\x41'*16 + b'\xef\xbe\xad\xde'
frail rapids
#

hm but

#

what's the difference?

#

I know that it's a bytestring

#

does a regular string have bloat at the end of the string or sumn?

quaint basin
#

The byte string has one character in it: "01000001", represented by the hexadecimal \x41 or ASCII "A"

#

Oh, having said which, Python does seem to be inferring that \x can be decoded as ASCII in regular strings. Either way, it's a difference in what is stored / how it is stored

frail rapids
#

hm

#

but hexdump gavethe exaxt payload

#

you reckon it could be netcat?

faint island
#

In your second example you're using s.sendline which will append a newline to the data you send

frail rapids
#

ooohhh

#

right so I should've added a 0a

ripe haven
#

@primal steppe I just finished one of the talks, f*ck this, got me paranoid af damn it

primal steppe
#

the first one?

ripe haven
primal steppe
#

hah yeah

#

it's scary af

ripe haven
# primal steppe why paranoid?

Mainly because of instructions that may be longer than the fuzzing that the person did and have more serious consequences being used by attackers with more computing power to fuzz longer instructions (state sponsored)

primal steppe
#

There is a limit to the length of the instructions

#

that's why his fuzzing methodology was soo good

ripe haven
ripe haven
primal steppe
#

the size of the ISA

ripe haven
# primal steppe the size of the ISA

What about instructions that are 8 bytes for example, and if you just have the first 7 w/o the last one it’s invalid, basically an “instruction” that acts as a key (?)

primal steppe
#

hmmm, I am not sure

ripe haven
primal steppe
#

sure post it

ripe haven
# primal steppe sure post it

There's something good you can say about every programming language. But that's no fun. Instead, let's take the worst features of all the languages we know, and put them together to create an abomination with the worst syntax, the worst semantics, the worst foot-guns and the worst runtime behaviour in recorded history. Let's make a language so b...

▶ Play video
charred gorge
#

I made some spaghetti during my break and I'd like to show 1337 culinary skills.
Y'all are invited for dinner, first come first serve vent

night shale
charred gorge
rose axle
#

Fancy plate! I like it

soft pier
#

fancy food pictures

#

with fancy plate

abstract charm
charred gorge
abstract charm
#

Ahahhahaahah

twin ridge
charred gorge
#

Fun Fact: Disney just closed down Blue Sky Studios, the people behind Ice Age.
So they released a short video where Scrat finally gets a chance to eat the acron.

serene trench
#

Okay now I’m crying

#

I absolutely adored Ice Age as a kiddo

scarlet moth
#

I've only seen bits and clips of ice age but it always seemed so cute, thats a shame

frail rapids
#

this hits different

crisp garden
south inlet
gray jetty
south inlet
gray jetty
#

¯\_(ツ)_/¯

south inlet
#

Although, how many channels did they post it in 😂

radiant jacinth
#

greetings everyone it is an honor to be in this group

#

i would like to learn programings and skills

ripe haven
#

@primal steppe how would you like a PHYSICAL cryptocurrency scam?

primal steppe
#

sheessshhh

spark sun
#

I saw a cryptocoin exchange ATM at my local liquor store last week

radiant jacinth
#

scm

#

scam?

quaint basin
twin ridge
#

Oh dear

soft pier
#

the intentions of why crypto currencies were created was probably not for scams..... but that is what it has become and will stay for a long time

serene trench
#

that's money laundering if I've ever seen it

radiant jacinth
#

i just wanna learn some information just basic

#

how about a deal..

spark sun
#

Well, I'm intrigued.

winged rain
#

I thought it would be harder to launder money over the internet because of the blockchain

#

Tornado cash makes it a breeze tho

normal crypt
#

Hi can someone help with the unlock tool

tawdry dove
white zodiac
#

.

frail rapids
#

what would be in between the ret addr of vuln and the arguments of win when doing a buffer overflow on the ret addr of vuln?

#

there's 4 bytes between them, and its value apparently doesn't matter

#

update: looks like it's the ret address of win

dull dove
#

simple ret2win

radiant jacinth
#

I felt disappointed, completed presecurity in 3 days, but when I attempted Wireshark labs, I felt completely inadequate, I literally spend 1 hour on 1 task, and I the pre-security didn't prepare me to learn display filters well, so I have to take a free online course for 18 hours, and that will set me back 18 hours for the Pentest+ certification and the Nmap room

#

Especially when you know you still have to learn Scanners, OSINT, Remote access, hashdump, wireless, networking tools, debuggers, webapp stuff, social engineering (email crafting)....

short elk
#

weird about me but you aren’t going to learn security in a day

#

this shit takes years so it’s fine to feel in over your head

radiant jacinth
#

All right, I will budget 3 days to learn Wireshark alone 🙂

frail rapids
#

😂 😂

#

this dude probs gonna 100p the OSCP with 48h prep if he continues like this

radiant jacinth
#

OSCP speedrun?? Zero to hero guide

short elk
#

use that to learn networking, wireshark takes an hour to learn to use

#

but knowing what packets/frames are and how different protocols look is the most important

#

you don’t need to know loads of display filters of the top of your head, you can just google “wireshark filter arp response” for example to find the filter you need. knowing what to google (which is where learning networking comes in) is the hard part

charred gorge
# radiant jacinth I felt disappointed, completed presecurity in 3 days, but when I attempted Wires...

I'm not going to tell you how to live your life, but I also strongly advise against this.
The Jr Penetration Learning Path took me over a month to finish, because I used to take very detailed notes about everything mentioned. I did some research of my own to get extra info. And I made sure I made my notes look tidy and pretty, divided into different sections, to give my future self an easier time to look for info when I need to come back to my notes.

If you need a good notekeeping tool, give Obisidan a try. If you haven't tried it before, do. You'll do yourself a favour when you learn to use it, and set yourself a notekeeping methodology.
Nevertheless, good luck my man! blobfingerguns

radiant jacinth
#

I’m a fairly new beginner as well

spark sun
radiant jacinth
radiant jacinth
#

I’m just going to trust the process

#

@radiant jacinth

charred gorge
#

Probably the left X though, still on the descent

soft pier
#

shadow is in the lower left of your picture

charred gorge
#

If I were to make a graph of my own personal experience though. It'd look something like this lmao

radiant jacinth
#

Im at valley of dispair lol

agile pawn
#

Me too, we just need to try harder. We got this

winged rain
#

The more I learn the more I realize there's mountains more to learn

#

There is no confidence, only dispairfawaz

wise thistle
#

.

#

Oh lol just 10 sec but u cannot limit the amount that i put hehe
⚔️
⚔️
⚔️
⚔️
⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔️⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔⚔

gray jetty
#

@south inlet lurker PES_Stab

south inlet
flat grotto
#

what up?

radiant jacinth
radiant jacinth
#

hey

frail rapids
#

IIRC the wormhole dude got away with $600M exploited but turned it into $10M legal money by accepting a bug bounty

#

Oh, only 500k

#

That's indeed a little bit less than 10m

spark sun
frail rapids
#

Yeah, or atleast not having to look behind your shoulder 24 7

#

On the other hand, that's like 1/1200th of the exploitable cash

spark sun
#

not really

#

maybe if you live somewhere with a super low cost of living; that's not enough to live off the interest

serene trench
#

plus it's clean money

spark sun
#

and 500k disappears quick when you pay the taxes on it

#

the top marginal rate in the US is 37% - that plus a full time minimum wage job puts that person into the top bracket of $540k

frail rapids
#

Only 37%??

#

It's 52% here... gotta love europe

spark sun
#

You get a lot more services for your taxes paid, though

#

like actual universal healthcare, a reasonable social safety net, etc

twin ridge
#

Actual healthcare is a nice plus I'll admit

radiant jacinth
#

I’m totally new to here, how should I start?

#

tryhackme

#

thx

pure shadow
#

Anyone have any good tips. On how to retain lots of new knowledge? I mean specific tips. I know engage in it. But taking notes and listening to videos doesn't really help me retain. Only thing that helps is taking practice tests and listening to my own voice for some weird reason

winged rain
#

Also, review, review, review. The more you review things the more you will remember

agile pawn
#

I reset my path modules and repeat them till I no longer require my notes and can do them fluently, plus a unique gift.

radiant jacinth
#

whatever I have a year subscription

radiant jacinth
#

My first trouble, I can ssh into my own server IPV4, but following online instructions, I cannot ssh into username@ipv6, my training wheels from tryhackme is removed 😦

#

I will figure out myself, I don't need help from the pesky LEET boyz

radiant jacinth
#

Nevermind I gave up, I stick to IPv4

winged rain
#

Everyone needs training wheels when they are starting out, don't let the disguise that it's easily laid out for you mask the importance of learning the fundamentals

ornate carbon
#

@radiant jacinth I have the same problem. I have concluded almost all of the paths. 57% into offensive pentesting, but I am stuck on a simple machine in Hack The Box.

radiant jacinth
#

I think ipv6 provided by digitalocean provides you with a subnet with 16 addresses, so even if i dont know, i just guess login on all 16 of them!!

radiant jacinth
#

I know, that is what the textbook in /r/linuxupskill challenge says, but I want to try to connect to ipv6 because I am hacker and I hate following the book.

#

I gave up, I will go back to tryhackme soon like a good boi with training wheels

radiant jacinth
#

No worries, I'm on Day 6 of the 20 day short course!! I be a good boi for now.

#

Google search says Putty supports IPV6, but I cannot connect into it, and I don't have the networking theory to know WHY.

#

Ssh isn’t putty

#

It’s a secure shell login

#

It’s only ipv4

#

Just man ssh

#

And see for yourself

#

Don’t act like you are something because your nothing and you know nothing and so am I. Don’t say your a “hacker” if you can’t even ssh lmao

spark sun
#

Everyone starts somewhere, there is no call be a jerk.
And, written instructions (RE: a book) usually has an order for a reason. If you skip around and don't understand things, go back and re-read the skipped parts.

radiant jacinth
#

Ya my plan is to finish the 20 day /r/linuxupskillchallenge course, then learn ipv6 enough to know why my connection timed out.

#

But for now it's a mystery

spark sun
#

You are going down a path that doesn't make sense. IPv6 is a networking thing, not a Linux thing.

#

You need to understand the IPv6 addressing schema. The reason your SSH timed out is easy: you tried to connect to an address that didn't have the correct port open. That's not on IPv6, that's on you not understanding how your VPC or VPS works.

radiant jacinth
#

All right I look into that, thanks!!

radiant jacinth
#

xd

candid trout
#

hey quick question .

#

i have been using the attack box so far but i would like to start using my personal vm so i can save my progress. will i have to dl the open vpn file every time to connect or is it a one and done? I'm available to voice chat if you need more clarity on my question

frigid cedar
#

From my experience it's been one and done.

rigid marsh
#

for those that use obsidian, do you know how I can convert an entire folder that I have used for notes into a massive PDF? Or do I have to copy each file into a separate file to convert?

#

dont know how i missed that post, thank you very much

hoary nymphBOT
#

Gave +1 Rep to @twilit nacelle

spark sun
#

Obsidian files on disk are just markdown, any markdown document generator should be able to pull them all in

rigid marsh
#

im looking into pandoc atm but i cant convert each single file into a pdf but not the entire folder into one large pdf with links

golden bridge
#

can i ask a question that out of tryhackme's topic here?

burnt night
#

Yes

golden bridge
#

nice..actually im covering up the topic about cve (log4shell.nse)

#

so my question is..how can the script (log4shell.nse) can be used as a ddos tool