#👥・help-me

1 messages · Page 5 of 1

normal heart
#

F

coarse perch
#

what da hell do someone need 80 gigs of ram for

coarse perch
#

he a 3d designer or smth?

chilly merlin
normal heart
#

He was running 32….

normal heart
#

Now he can run it at 90fps average 😎

chilly merlin
#

Dancin why do u have a roommate when you're married @normal heart

coarse perch
chilly merlin
#

🤔

normal heart
chilly merlin
#

1080ti gang

#

Tell me i need to know

normal heart
chilly merlin
normal heart
#

My spouse is always hanging out around me. I set up their computer and actually need to install the 1650 into their computer

chilly merlin
#

sorry for any inconveniences i shouldn't have asked

normal heart
#

It’s fine

chilly merlin
#

I mean it

#

@coarse perch there is a thing called sleep u know that

coarse perch
#

never heard of it

coarse perch
#

imma log off now , will try Dual boot on different hard drive in the morning

#

Bye

coarse perch
coarse perch
chilly merlin
maiden pulsar
#

Where can I get a free Linux server?

quasi berry
normal heart
#

😅

#

Hi light…

#

HTB Spoiler Jewel

#

||Jewel.HTB is Ruby on Rails vulnerability.||

#

That took way to long 🤣

sly spire
#

i am creating a tool where you add a payload list let's say xss and try to find that vuln
the way it works is that you have a url example: example.com/search?q=Cars
instead of cars you put the payload

#

how do i check if i have a vuln

#

do i check the html code of the page and see if the payload is in there or how?

#

@normal heart any idea?

normal heart
sly spire
#

?

normal heart
#

It’s a tool that does that

sly spire
#

ok

#

but like i am trying to create my own tool if you can help me 😆

normal heart
#

Use it as a reference and see if you can find the source code. It would be a wonderful resource

#

I’m going to bed

sly spire
#

Alr Bet

shell sinew
#

hello there
can someone help me with one thing?
I have this problem when I boot into kali through flash drive it takes really long time to boot (like 1 or 1,5min)
I also had problem with a beep sound when booting but I figured it out myself
Is this boot time normal for flash drive?

coarse perch
#

OS related

shadow fractal
limpid ridge
#

Could someone suggest me a small project idea about making a small network secure

#

Like for a bunch of devices printers etc in an office

subtle tundra
#

I’m trying to dual boot but windows installation media won’t recognize the nfts partiton on my drive

red tree
#

hey does anyone have any experience with ghidra? I want to run it headless. so far I am able to submit the the analysis headless but i can only see the analysis from the gui, is there any way to access it from terminal?

chilly merlin
#

guys am i cooked

#

yall know what an $phantom-SCV.cmd is? 🤔

chilly merlin
#

Looked it up on google, something about valorant came up.

#

I thought it was a ransomware attack

#

or cryptoware idk

#

but just to be safe

#

which antivirus should i run for a small scan?

coarse perch
#

but it should not be in .cmd format imo

coarse perch
coarse perch
#

just for small scans

chilly merlin
chilly merlin
crude temple
#

hello, i am interested in learning cybersecurity can anyone help me how i should start with it?

normal heart
#

We need more information based on where you currently are. The field is way too big for an open ended question.

rich topaz
#

Can someone help me regarding Android Spyware. To identify and remove it

coarse perch
#

Using archinstall instead of manually configuring everything takes care of wifi configs? While installing Arch Linux

coarse perch
#

and patriations too, or should i manually do it ? following the oficial installation guide on arch's website?

chilly merlin
quasi berry
coarse perch
#

because i want to install KDE plasma 6 with it too, and official installation guide dosen't mention ay about that.
i can do it after installation too, if i am correct?

#

@whole wave do you have any idea about this?

chilly merlin
#

Is anyone free tomorrow at 11am-1pm est ?

frigid trail
chilly merlin
chilly merlin
#

And i need some people as a "test" group

frigid trail
chilly merlin
#

They're designed to be intermediate level

#

Apparently

#

If anyone's interested

#

Dm me

quasi berry
shell sinew
#

hello there
is there anyone who has some experience with pymongo?

#

or just experience with python databases and moving within them

faint sky
#

is using tor without a vpn safe but not buying anything just browsing?

quasi berry
faint sky
#

i was just askin

quasi berry
#

TOR on it's own is fine :)

#

Also, if you're worried use Whonix

faint sky
faint sky
quasi berry
#

Whonix is not an NSFW website wtf

#

@sour badger this needs fixing :(

faint sky
quasi berry
#

For the next hour I'll make sure to be active here so ask away people (even you lurkers, I see you)

azure walrus
#

Hey

normal heart
azure walrus
#

Is this possible to hack a website using termux?

azure walrus
#

To find open Ports and vunlerbilties? To hack

normal heart
#

It’s most possible having a rooted android device

normal heart
azure walrus
normal heart
#

Nmap doesn’t always need root

azure walrus
#

Which tool

normal heart
#

Tryna make you think about it a little as well

normal heart
azure walrus
#

What tool i need for hacking in termux?

normal heart
#

And to install it look up, “Termux working nmap” and click this one Suspicious Link

azure walrus
#

Using nmap !

#

I can hack a web ?

normal heart
azure walrus
#

👍

normal heart
azure walrus
normal heart
#

The PC yes

azure walrus
#

Oh its mean computer

azure walrus
#

Hey dark

sour badger
light mortar
#

yoo

whole niche
#

Hello

chilly merlin
quasi berry
chilly merlin
#

Oh

#

I mean that it's not by anyone important

#

or like famous

#

Indie devs i know personally

hushed island
normal heart
glossy bridge
#

Who can hack my gf camera to see if she’s been cheating

#

Small generic camera

normal heart
quasi berry
glossy bridge
#

Ok

gentle latch
#

I got a small RC car that can connect to Bluetooth I took it apart but I can't figure out how to make a code for it so I can drive it with my laptop if that make sense

normal heart
#

If you’re making it then you need to know what languages the RC computer understands and learn it.

gentle latch
#

it should already have one the car im using is a REV: robotics enhance vehicles I had it for years and thought it would be a good time to do something special with it put up a challenge for me but I got stumped

#

I cant figure what language the car is or anything about it I tried doing it though the app but still nothing

normal heart
#

Compile the information about it and only keep the crucial information. That’s the best way to search IMO I also do break SEO’s…

gentle latch
#

I know it has its own type of AI and its Bluetooth only can be run by phone how ever because its Bluetooth I can connected though there the problem I don't know what language it is

#

that is all it got

#

... I wonder if scratch would work

gentle latch
normal heart
#

I just hacked two medium machines on HTB in the last 4 hours

gentle latch
#

damn (i don't know if I can swear or not the rules dosn't wanna open for me lol) I also didn't sleep

normal heart
#

It should help ^

gentle latch
#

at this point im too tired to sleep

shell sinew
#

someone please tell me how it is I can ping from PC-A to PC-B but not from PC-B to PC-A

#

feel like its simple but dunno

normal heart
#

Firewall can be blocking it

shell sinew
#

is there anyway to overcome it?

#

testing smth on my own system

normal heart
shell sinew
#

I want to scan Windows PC to find vuln with nmap vuln but its not working (ping doesnt go through)
I can ping from Windows to Kali but not from Kali to Windows

shell sinew
#

hmm, "No targets were specified, so 0 hosts scanned"

#

weird

normal heart
shell sinew
#

ofc haha

normal heart
#

Are you positive 😅 idk why else it would say no targets were specified

#

I’ll take your next word don’t worry

#

Like imma have to do research if you weren’t joking

shell sinew
#

gimme a sec, doing it 2nd time

#

can I send ss in DM's? (when its done)

normal heart
#

What for exactly?

shell sinew
normal heart
shell sinew
#

or I misunderstood smth

#

wait

normal heart
#

What’s up

shell sinew
#

it shows now "Host is up."

normal heart
#

Yay

shadow fractal
#

Please read the #📜・rules , we do not participate in these kinds of activities.

crude temple
lament walrus
#

can anyone help me

#

i need a quick recap on how to perform SQL and XME injections

boreal solstice
lament walrus
#

Oh ok

boreal solstice
#

Or @quasi berry if he comes online

#

My boys sleeping rn

lament walrus
#

Well I'm in a bit of a rush

shadow fractal
lament walrus
#

No

#

Its a type of XSS exploitation

shadow fractal
#

For recap

lament walrus
#

Oh

#

Mb then

shadow fractal
#

Np np

#

Just a sec

#

Portswigger has clear explanations

lament walrus
#

It is XXE lol

shadow fractal
shadow fractal
#

All good

#

Hope this helps

lament walrus
#

But wait

#

How do i perform SQL injections

#

Is there SQL code i have to edit?

shadow fractal
lament walrus
#

Like for example

#

Theres a ctf on picoCTF

#

That says you have to open /etc/passw

#

With an injection

shadow fractal
#

So you would have to adjust the SQL code

#

To get to the ETC

#

Then passw

#

And get the data from it

#

Check this if it is not a spoiler

lament walrus
#

Ty

#

Ig

shadow fractal
#

Always welcome!

lament walrus
#

It's like i get it but not rly

shadow fractal
#

Check what each part does

#

It will help you better understand the code

#

How it functions

#

And the Portswigger has pretty clear explanations/guides

#

Unless there is a specific part

#

Causing you issues

lament walrus
#

password = '' or 1=1;--'
and username = '123'

#

Why do we pick these

lament walrus
shadow fractal
#

Think of a query that is built using string concatenation:
"select * from myTable where id = '" + txtIdEnteredByUser +"'"
If the end user inputs:
' or 1=1; -- '
then the query becomes:
select * from myTable where id = '' or 1=1; --'
That is a valid query and always evaluates to true because of the (OR 1=1), as a result the whole table values are returned.

However, if the user input was:
or 1=1;
the query becomes:
select * from myTable where id = ' or 1=1;'
which is query that wouldn't return something (likely).

lament walrus
#

what language is this 😭

shadow fractal
#

SQL

#

And english

#

Lmaooo

lament walrus
#

do i have to learn sql...

shadow fractal
#

The basics

#

Yes

#

Its not that hard

#

Believe me

lament walrus
#

i have 2 hours

shadow fractal
#

You can go over the basics

#

Like Union

#

And etc

#

Other commands

lament walrus
#

on the other hand

#

what about the XXE?

#

same thing?

leaden axle
#

XXE is XML entity injection

#

quite a bit different

#

i.e. if a user submits an XML payload to the web app:

<userInfo>
  <firstname>John</firstname>
  <lastname>Bob</lastname>
</username>

You can modify the request and define an entity, then reference it:

<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
<userInfo>
 <firstName>John</firstName>
 <lastName>&ent;</lastName>
</userInfo>
lament walrus
#

why is forensics so dificult

leaden axle
#

That way when the application echos back the lastname to you, you see the contents of /etc/passwd

leaden axle
lament walrus
leaden axle
#

But it's not crazy hard to get a hang of some of the bassics (pcap analysis/disk analysis/memory analysis)

lament walrus
#

whats &ent; ?

#

oh

leaden axle
# lament walrus this looks easier than the SQL

Depends on the application! You can have instances where an SQL injection is really easy (i.e. literally submitting ' OR 1='1 to bypass a login, and you can have cases where XXE has filters etc.

leaden axle
# lament walrus whats &ent; ?

&ent; refers to the entity that we custom defined here:

<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
lament walrus
#

yeh got that

#

so wait

#

its like a function?

leaden axle
#

Is what like a function sorry

lament walrus
#

nvm

#

i mean since you defined it

#

is it like a variable

leaden axle
#

Yeah more like a variable

lament walrus
#

i see

leaden axle
#

you could do:

<!DOCTYPE replace [<!ENTITY whatdahellisdis SYSTEM "file:///etc/passwd"> ]>

&whatdahellisdis;

#

if you wanted to

lament walrus
#

lastly, SYSTEM opens the directory right?

#

or does it read it like cat

leaden axle
#

I think the entity creates a pointer to that system resource

#

then when it gets to &ent; it renders it by reading the contents of the file

lament walrus
#

ohhhhhhhh

#

i think i got the hang of this

lament walrus
leaden axle
#

XXE is usually relevant to web applications

#

You would find some part of the application that accepts XML as input, and play around with it by using external entity injection

lament walrus
#

i mean like the console you get from inspecting a page

leaden axle
#

You would probably need to use a tool like Caido/BurpSuite/ZAP to play with this attack in a nice way

lament walrus
#
window.contentType = 'application/xml';

function payload(data) {
    var xml = '<?xml version="1.0" encoding="UTF-8"?>';
    xml += '<data>';

    for(var pair of data.entries()) {
        var key = pair[0];
        var value = pair[1];

        xml += '<' + key + '>' + value + '</' + key + '>';
    }

    xml += '</data>';
    return xml;
}

#

for example

leaden axle
#

They sit between your browser and the server and let you inspect/modify messages as they are being sent, i.e.

browser -> BurpSuite -> server

Then in Burp you'd see

POST /endpoint
blah
blah
Content-Type: application/xml
blah

<xmlstuffhere>
</xmlstuffhere>
lament walrus
#

oh ok

#

i think i have burpsuite

leaden axle
#

PortSwigger have a nice video talking about how you'd do this challenge

#

You'd probably want to watch a different one for how to set up burpsuite with your browser of choice

#

(i.e. set the proxy settings / add the burp CA as trusted)

lament walrus
#

ty

#

my prof explained it to me using ruby (how did he even do that)

#

i didnt understand anything

lament walrus
#

lmao

leaden axle
lament walrus
#

wtf

#

i cant do active scan

#

or passive scan

#

bruh

leaden axle
#

Yes, you shouldn't need scanning

#

Since you should be able to use the app and spot the vulnerable areas

lament walrus
#

could i borrow 449 $

leaden axle
#

You only need proxy history / replay to exploit pretty much anything

lament walrus
#

ill pay them back trust

#

💀

leaden axle
#

Also the passive / active scanning isn't that great

#

so like, it's not a silver bullet

leaden axle
#

play around with the buttons

#

find the request that has XML as a POST

lament walrus
#

oh yeaahhhh

leaden axle
#

use repeater to view the request, modify the XML, and send it out and see the response

lament walrus
#

i cant find a POST xml

leaden axle
#

Have you set up the proxy so all of your requests are going through burp?

lament walrus
#

yeah

#

the only XML is a GET

#

wait

leaden axle
#

Ah okay, then play with that request

lament walrus
#

isnt there that /robots thing

leaden axle
#

Well, I mean, I'm not sure of:

Your goal
What this is for
What you are looking at

So it's kind of hard to provide any ideas on direction

lament walrus
#

flag

#

flag is goal

leaden axle
#

Okay, but what's the context for the challenge, what does it look like etc.

#

i.e. if the challenge is called "OMG its an XXE" then it's like, okay, robots would never help you

lament walrus
#

its SOAP

leaden axle
#

SOAP definitely makes a POST that contains XML data

lament walrus
#

theres only 3 POSTs

leaden axle
#

Okay, what are the post requests you see

lament walrus
#

1 sec

#
POST /data HTTP/1.1
Host: saturn.picoctf.net:63037
Content-Length: 61
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.122 Safari/537.36
Content-Type: application/xml
Accept: */*
Origin: http://saturn.picoctf.net:63037
Referer: http://saturn.picoctf.net:63037/
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: close

<?xml version="1.0" encoding="UTF-8"?><data><ID>2</ID></data>
leaden axle
#

Okay, so that'a a POST, and the data (down the bottom) is XML

lament walrus
#

oh

#

oopsie

leaden axle
#

So, can we inject an entity into that XML, and what can we define that entity as

lament walrus
#

lemme try first

leaden axle
#

For your testing I'd right-click that request, send it to repeater, and then modify and click send (it's a nice work flow for stuff like this)

lament walrus
#

<?xml version="1.0" encoding="UTF-8"?><data>

<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
<ID>
&ent;
</ID></data>

#

this is what im editing the bottom part with

#

wait

#

shouldnt there be another <data>

leaden axle
#

I think you're close, order is important

#

I'd define the doctype before <data>

lament walrus
#

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE replace [<!ENTITY ent SYSTEM "file:///etc/passwd"> ]>
<data>
<ID>
&ent;
</ID>
</data>
leaden axle
#

sure, and what happens when you send that off?

lament walrus
#

sigh

#

the instance ended

#

so i have to redo this

leaden axle
#

You can spin up a new instance

lament walrus
#

:/

leaden axle
#

shouldn't take long!

#

You've already got the payload

shell sinew
#

I think I messed up my OS... its stucked on loggin screen (Arch)
any idea how can I fix it?

shell sinew
#

host

leaden axle
#

And when you say stuck on login screen, do you mean you type creds and then it just freezes?

shell sinew
#

no no, I turn it on and its stuck on 'lenovo' screen ahaha

#

I installed one login screen layout and yea...

leaden axle
#

So it never gets to login-screen, but it's booting?

shell sinew
#

yep

#

named it wrong, sry

leaden axle
#

Have you tried ctrl + alt + f3-6 to try and get to a tty?

shell sinew
#

not working

leaden axle
#

You can try booting into single user mode

shell sinew
#

how can I do that

leaden axle
#

Do you use grub?

shell sinew
#

idk tbh

leaden axle
shell sinew
#

dont remember

leaden axle
#

When booting if you hold shift it should pop up something

shell sinew
#

got smth

#

resume normal startup
BIOS
diagnose hardware
temporary startup device
management engine setup screen

lament walrus
#

picoCTF{XML_3xtern@l_3nt1t1ty_540f4f1e}

#

it worked

leaden axle
#

You don't have to share the flag in here 💀

lament walrus
#

its random for every user

#

so it doesnt matter?

leaden axle
#

Ah k

lament walrus
#

yup

#

ty

#

wait a damn minute

leaden axle
#

I'm trying to think

#

what your boot loader is

lament walrus
#

isnt there something called xml reflection

#

or sm along the lines

shell sinew
leaden axle
lament walrus
#

sigh

#

yeah thats it...

shell sinew
#

its stuck on black screen now (I can move cursor around)

leaden axle
#

Okay, now try switching tty 🙂

#

(ctrl + alt + f3-6)

shell sinew
#

doesnt work

leaden axle
#

uh, just alt + f3-6?

#

You basically are trying to get to another tty that just has a tty login screen

shell sinew
#

nth working

leaden axle
#

It's super odd you get a cursor, sounds like the system is pretty much booted

#

None of the ctrl + alt + fkeys work?

shell sinew
#

none

leaden axle
#

Do you know what change you made to have the system be unable to boot?

shell sinew
#

I installed login screen style in the kde plasma desktop themes

#

and rebooted it

lament walrus
leaden axle
#

Ah okay, so the login greeter is just borked

#

Is this a laptop?

shell sinew
#

yep

leaden axle
#

fkeys can be disabled sometimes

#

Is there like an fn key?

shell sinew
#

yep

leaden axle
#

Make sure your flock is the right way around (i.e. when you press f6 it's actually f6 and not brightness up)

shell sinew
#

wait i dont understand now

leaden axle
#

There should be a fn lock symbol somewhere

shell sinew
#

yes there is

leaden axle
#

So try changing the lock, then doing ctrl + alt + f3-6

shell sinew
#

its not changing, I mean it had this led and should lighten up when pressing it right?

#

fn

leaden axle
#

Sometimes the led doesn't work (it doesn't really on mine)

#

otherwise you might have to do like ctrl + alt + fn + f3 💀

shell sinew
#

oh god

shell sinew
#

go into tty3

#

got*

leaden axle
#

Nice!

#

You should be able to login

#

and run commands, and try and fix the greeter 🙂

shell sinew
#

but how 😭
im new to all of this ahah

leaden axle
#

Okay so something has to start plasma

#

You're probably using sddm

shell sinew
#

yes

leaden axle
#

Do you know how to generally move around the file-system / edit files from the terminal?

shell sinew
#

yep

leaden axle
#

Okay, well I'd try and find the logs for sddm

#

see what's happening there

lament walrus
#

can you explain the reflected XSS

leaden axle
lament walrus
#

ohhhh

#

so it uses the url to implement code?

shell sinew
#

there's so many files to check

leaden axle
shell sinew
#

yes

leaden axle
#

No other files in /etc/sddm.conf.d/?

shell sinew
#

Main
metadata.desktop
screenshot.png
slice (dir)
theme.conf
theme.conf.user
translations (dir)
readme

#

wait a secd

leaden axle
#

What's in theme.conf ?

shell sinew
leaden axle
#

look at the [Theme] section, (specifically what Current is pointed to)

#

You can change it back to Breeze for the default theme

shell sinew
#

what im talking about is in '/usr/share/sddm/themes/sddm-slice-1.5.1

leaden axle
#

Basically, get the default theme working

#

get your nice desktop back

#

When you try to preview it'll spit out what errors are happening directly to the terminal (i.e. missing dependencies/incorrect config etc.)

shell sinew
#

i got:
[Theme]
Current=sddm-slice-1.5.1

leaden axle
#

then do systemctl restart sddm

#

then login, and then after changing the config/theme make sure to try and preview it 🙂

shell sinew
#

readonly option ofc ghahaha

leaden axle
#

(I have also learnt to always preview before logging out from this exact situation with sddm 🤣)

leaden axle
#

i.e. sudo nano blah

shell sinew
#

ik ik

#

nano... vim mate

#

haha

leaden axle
#

I mean I use vim

#

but like, I don't expect normal people to use it hahaha

#

Just do :w !sudo tee % in vim and you can write the file with sudo

shell sinew
#

OMG ITS WORKING AAAAA
thank you so much mate!!
U 👏 ARE 👏 THE 👏 BEST 👏

#

i'll surely remember this for the future

#

I don't know if the custom login window was incompatible or what

leaden axle
#

i.e. qt5-quicktime and such

shell sinew
#

I thought I was smart enough to do it on my own but probly need to read or watch some yt vids

lament walrus
#

yo f3rn0s

leaden axle
# lament walrus so it uses the url to implement code?

XSS is an attack that is built upon the idea that if you (an attacker) can get an arbitrary script tag to be rendered. How do you get a script tag onto someone elses page though? well theres:

  • Stored: You get the website to save your payload somewhere, then it displays it to another user
  • Reflected: You put the XSS payload in the URL, and it gets rendered onto the page when a user visits that specific URL.
leaden axle
leaden axle
lament walrus
#

are ye gonna be available in about an hour

leaden axle
#

Like, having the tools next time to go, well my computer booted, but my desktop manager is cooked, let's try and switch tty etc.

#

is super useful

leaden axle
#

Sleep comes for us all

lament walrus
#

aw man

shell sinew
#

this emoji is savage ' 🙂 '

chilly merlin
#

Is there any way i can program my Logitech g502 the sidebutton too keys for Playstation?

#

i wish but idk how

gentle python
#

Need help

#

Termux printing the following ..
~ $ wget -o install-nethunter-termux https://offs.ec/2MceZWr
CANNOT LINK EXECUTABLE "wget": library "libssl.so.3" not found: needed by main executable

leaden axle
gentle python
# leaden axle Apparently an `apt-get update && apt-get upgrade` or `pkg update` should resolve

$ pkg install wget
No mirror or mirror group selected. You might want to select one by running 'termux-change-repo'
Checking availability of current mirror:
[*] https://mirror.accum.se/mirror/termux.dev/termux-main: ok
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
wget is already the newest version (1.24.5).
0 upgraded, 0 newly installed, 0 to remove and 64 not upgraded.

leaden axle
leaden axle
#

It's probably borked because your termux has tools like wget that are relying on system libs that aren't up to date

#

So, update all the shit in termux (including system libs)

#

with something like apt-get update && apt-get upgrade

gentle python
#

Okay

short jungle
#

Hey guys, I just started learning about cyber security. Any recomended way to learn?

short jungle
#

thanks

gentle python
# leaden axle with something like `apt-get update && apt-get upgrade`

File on system created by you or by a script.
==> File also in package provided by package maintainer.
What would you like to do about it ? Your options are:
Y or I : install the package maintainer's version
N or O : keep your currently-installed version
D : show the differences between the versions
Z : start a shell to examine the situation
The default action is to keep your current version.
*** openssl.cnf (Y/I/N/O/D/Z) [default=N] ?

leaden axle
#

I'd go Y for most things

#

since you haven't configured anything non-standard

gentle python
#

Okay

#

So y?

leaden axle
#

Yess 🙂

gentle python
#

Done

#

Checking device architecture ...

[1] NetHunter ARM64 (full)
[2] NetHunter ARM64 (minimal)
[3] NetHunter ARM64 (nano)
Enter the image you want to install: 1

[*] Checking package dependencies...

leaden axle
gentle python
#

Okay

#

Thanks

gentle python
#

[*] Checking package dependencies...
Just printed this

gentle latch
#

I need help hacking an old game SimCity 2000 it doesn't wanna start downloading or anything

#

I haven't hacked a game before

lament walrus
#

sim city isnt made for you

gentle latch
#

What?

lament walrus
#

its a meme reference...

gentle latch
#

Ah okay

#

But any ideas on how to hack it so it's playable

shadow fractal
#

Thank you!

gentle latch
#

But I have the CD I'm just trying to get it to be playable.. it's still considered piracy?

shadow fractal
#

Thought you meant from online

#

If you have a cd, idek, noone hacks games here tbh

#

And if it not downloading or anything

#

Might be probs with disk

gentle latch
#

Hm

normal heart
#

Try running it as administrator.

gentle latch
#

Alright I'll try it

lament walrus
#

can anyone teach me how to do XEC injects?

quasi berry
quasi berry
#

Lovely

lament walrus
#

fr

#

well the only thing left honestly is this 1d0e1a0f3e0b021b132c201225252e361228132132232a291a31283d3b20362316233523223a2531363e34

#

gotta XOR decrypt it

#

nvm

maiden violet
#

Just xor it

lament walrus
#

uh oh

#

nevermind

#

im stuck

#

sob

#

turns out it wasnt just a simple XOR

#

nevermind

#

the cipher was the key lmfao

#

wait im confused

#

1d0e1a0f3e0b021b132c201225252e361228132132232a291a31283d3b20362316233523223a2531363e34 ^ SMILE = flag

#

gimme a sec

gentle latch
#

You got it I believe in you

lament walrus
#

sorry im slow brained

#

imma just python this

#

yaaaaay

#

i did it

#

see even my ape brain can do it

#

😄

wary crypt
#

Anyone can teach me I'm new and I only have a phone

normal heart
lament walrus
#

help

#

help

#
import string
restrictions = [
'ounpbctiwrw_rbpgvzvjwbrduf',
'ybuacimefujwzpjnfwmwljjyyc',
'ffornwxnsweroqmmzoocuaefhn',
'wxpddhr_mqxmkxaxbscmydmswx',
'qmvxlgwoimttudhlwtgfqknp_h',
'zlcmvysxbakxwtzceptniglnsv',
'mwfezazhqyukmfkkkultappvxo',
'unghuxepus_ingqpomdedzuwmw',
'_txkxegukkqnvvgfhqsqkqdkqi',
'l_r_jkulxecoi_bvgkehjrkjbd',
'kkzgmvkjpjlfdyxsscpiblsgcg',
'ecayfdyrrlplswlemg_khvyram',
'rswlrz_zhzzqyucqqyfof_oifl',
'ihtotrpdv_nbxkviylzl_mcopr',
'gzyqhqimdfvaaewtrhazpexzou',
'bjdjksftjhfy_stdcvwsnfhekp',
'pqlbpfqveooefnorliiartimdj',
'domcsthqapbhborjuakgtczhvb',
'nvjf_ocsyggupheudnndohvqzk',
'jebugbbftihzerf_n_qbsyqtg_',
'crinwpacgnychzdypfbpciablz',
'xi_zimoknbspclshixrrxxfxta',
'spksqjvwztrvgcnatrjyew_ary',
'tdhveljblcddqiiw_duvzsbljs',
'agqwyudgodajlmuojjxumnwunq',
'vyeionnycxmgjjyzxehxvugcee',]
cap = [
 0, 4, 9, 19, 23, 26]
flag = input('enter the flag : ').lower()
flag = flag.lower()
if len(flag) != len(restrictions[0]):
    print ('nop..........no flag for you')
    exit(0)
for f in range(len(flag)):
    for r in restrictions:
        if flag[f] not in string.ascii_lowercase + '_' or flag[f] == r[f]:
            print ('nop..........no flag for yo')
            print(r[f])
            exit(0)

new_flag = ''
for f in range(len(flag)):
    if f in cap:
        new_flag += flag[f].upper()
    else:
        new_flag += flag[f]

print ('Yeah, you got it !\nYour flag is NCSC{' + new_flag + '}\n')
print(r[f])
#

wtf is this

dim grove
#

de-obfuscate the string.

lament walrus
#

huh?

#

what does de obfuscate mean

gloomy arch
#

something that will run but contains lots of unneccesary codes and strings

lament walrus
#

can you help me do that

gloomy arch
#

honestly, i have no idea how to do it

#

i think google can help u tho

#

since the code isnt that long

#

and it aint that obfuscated

gentle latch
#

Well dose the code works?

lament walrus
#

yes

#

it works

#

my findings with it:

#

the flag has to be
a- same length as restriction
b- all lowercase
c- flag[f] == r[f]

gentle latch
#

It all looks right but I'm entirely sure I know I'm missing something but I don't know what

#

This is starting to bother me now lol

lament walrus
#

IKR

#

ive been at this for ages

#

i just want to get the flag and move on

gentle latch
lament walrus
#

yeah

#

its not even a flag

#

D ;

#

it was a troll

#

but not rly

gentle latch
#

?

lament walrus
#

basically

#

its a bit complex

#

but any string that abides by 4 rules can be the flag

#

1- has to have the same length as restrictions
2- has to contain atleast one _
3- has to be all undercase
4- has to abide by flag[f] == r[f]

gentle latch
#

Yeah

lament walrus
#

turns out

#

the ctf itself was partially the hint

#

you just have to look at it from a weird perspective

gentle latch
#

Are the numbers right?

shell sinew
#

does anyone have any idea what would be the reason that simple nmap sc sv scan takes so long to scan (still going for 3min now)

quasi berry
#

Putting that here so your message gets seen

gentle latch
#

What I understand by it is just taking it's time

gentle latch
lament walrus
#

nevermind

#

the restrictions was a list

gentle latch
#

Ohhhh

#

Alright so it's fixed?

lament walrus
#

yeah

gentle latch
#

Nice

gentle latch
#

Slow host too many ports udp scans it can do that

lament walrus
#

how to inject XEC

lone kernel
#

GUYS… i wanna start programming but dk where to start 😭😭🙏🙏 like do i start w the hard programs first or should i start w the easy ones or IDK HELP

normal heart
#

HTML&CSS for website form and UX/UI

minor blade
#

@normal heart you’re going off on HTB!

normal heart
#

Then JS from functionality; from there PHP for backend development and MySQL/SQL for database server.

normal heart
minor blade
lone kernel
normal heart
quasi berry
#

@analog temple alright so #help-me understand what you're trying to get across, I'm listening

#

I'm not saying that you're wrong to think that; other than enjoying helping people what perceived gain do you believe I get from helping others? And do you think there is an exception to such a rule?

quasi berry
#

Is that an exception to the rule I see 👀

#

It is down to values and I have quite a few

#

I'm a family person

#

Yeah of course, as long as there is mutual respect among discourse; people will jump to my defense regarding some things and I appreciate that they do this because people tend to target me so they're just looking out for me

#

It does take a bit to encourage conversation with others, I find it fruitful when I'm able to have in-depth conversations with people regarding different topics

#

In my brutally honest opinion, if someone doesn't know something then that is okay but what is not okay is acting like they know everything in cyber when they know very little. If they reach out and are like "hey I don't know this, could we go over this?" then I'm more than willing to jump in and give them a helping hand if I have experience or knowledge regarding the subject. I think a lot of it resorts down to the peer pressure of certain circles of people they hang around in and it can be scary to escape that at times

gentle latch
gentle latch
#

Well I'm three coffees in and an energy drink and I still can't get my RV car connected to my computer

coarse perch
whole wave
coarse perch
#

had to wipe the drive

coarse perch
#

Without nvidia driver for now , ig I'll stay on intel for the time being

#

Tysm!! @whole wave

deft light
#

@quasi berry I managed to install proxmox on my raspberry ^^ thx for your help 😄

karmic minnow
#

Greetings ppl

#

I want some help in bypassing ip restrictions

chilly merlin
karmic minnow
#

I can’t pentest?

chilly merlin
deft light
#

Hi so now I got proxmox running on my raspberry and I connected my hdd to it with an adapter. Is it now possible to just add the drive to my proxmox interface and split is up for the vms I want to practice on or do I have to do something else? I did mount the hard drive and managed to let it mount automatically.

lament walrus
#

can anyone help

#

help me to do an Xec inject

shell sinew
#

@marble fern

chilly merlin
#

its web security researcher

marble fern
#

It's good

lament walrus
#

@shadow fractal

sly spire
#

Xec??

lament walrus
#

I have no idea

#

It's what the challenge says

sly spire
#

what challenge?

lament walrus
#

Gimme a sec

quasi berry
lament walrus
#

help

#

other thing

#

must restore png file

#

its corrupted

karmic minnow
#

It’ll only open a form if ip matches

quasi berry
#

Uhmm and what sort of site would this be?

lament walrus
#

can anyone help me

sly spire
lament walrus
#

its not a room lmao

#

my friend sent me it

#

he's a ctf dev so he wanted me to test it

#

i dmed you

marble fern
#

@shell sinew check out my new repository that all i had found to become security researcher, reading is the must skills to develop

lament walrus
#

@shadow fractal corrupted png restoration

shadow fractal
lament walrus
#

still attempting

#

im stuck

#

99.999% sure its a hexedit thing

shadow fractal
#

Might be the case

lament walrus
#

can you help?

#

i can dm you the png if you want

shadow fractal
#

Any guidance? Hints? Or anything added for this png?

#

And for this imma ask another member for possible tools

shadow fractal
lament walrus
#

ok now im sure its a hexedit thing

#

100% sure

shadow fractal
#

100?

chilly merlin
lament walrus
#

100% sure

#

can i dm you it to see

shadow fractal
#

Hit me up

#

Will check

lament walrus
#

done

marble fern
swift elbow
#

Is there anyway I can get access to my gmail that I forgot the password too and don’t have access to my old number

shadow fractal
lament walrus
#

can anyone gimme a php injection example

#

i just need the format to copy

#

@quasi berry

#

one that reads file.txt in /home

boreal solstice
#

Thats @minor blade

#

Oh

boreal solstice
lament walrus
#

i need help

#

with burpsuite

boreal solstice
#

Oh

lament walrus
#

yo?

#

can anyone help pls

#

pleaaaase

#

okie

#

i cant send images here

#

il dm the ss

boreal solstice
shadow fractal
#

Because people spam NSFW

boreal solstice
shadow fractal
#

hahaha

#

100 people

#

Would take quite some time

chilly merlin
#

☠️

swift elbow
lament walrus
#

im so confused

#
from Crypto.Util.number import long_to_bytes, bytes_to_long

# Read encrypted cipher from the file
with open("cipher.enc", "rb") as b:
    cipher = bytes_to_long(b.read())

# Convert the number to encoded string
encoded_str = str(cipher)

# Reverse encoding process
flag_chars = []
for i in range(0, len(encoded_str), 2):
    encoded_char = int(encoded_str[i:i+2])
    # Reverse the bitwise OR and left shift
    original_char = (encoded_char ^ 317) >> 15
    flag_chars.append(chr(original_char))

# Join chars    
flag = ''.join(flag_chars)
print("The flag is:", flag), bytes_to_long

#
from Crypto.Util.number import *
flag = 'aaaaaa'
def enc(flag):
    return''.join([str((( 51415 & 5 + 314) | ord(t) << 15 )) for t in flag ])   
cipher = long_to_bytes((int(enc(flag))))
with open('cipher.enc', "wb") as b:
    b.write(cipher)
print((51415 & 5 + 314) | ord('t') << 15)
#

😭

chilly merlin
#

what the hell is this

chilly merlin
deft light
#

hi ^^ can someone help me with porxmox. I want to start my vm after I finished the creation wizard but it always give me that error
kvm: cannot set up guest memory 'mach-virt.ram': Cannot allocate memory
TASK ERROR: start failed: QEMU exited with code 1

chilly merlin
#

try this pls

deft light
#

alright I try thx ^^

bronze canyon
#

oh well
I started learning on tryhackme through my laptop
for ethical hacking but my laptop's battery is dead and so until it's replaced
can I get few other websites which work good on my phone?

lament walrus
#

other thing

#

uhh

#

how do i exploit a website that lets me put anything as a /

lament walrus
#

../../../../etc/passwd ?

#

what?

#

dude what???????

shell sinew
#

I have this problem
I finished all tiers of HTB starting points and now I want to try out PermX machine
and my question is:
How does HTB know I found a flag? Do I have to report it somehow?

#

nvm, I see now

normal heart
#

@covert path that’s Object Oriented Python.

#

Good job 😎

#

A 400 bad request error occurs when a browser sends a request to a web server that the server cannot understand or process correctly. This is an HTTP response status code in the 4XX range. HTTP status codes starting with 4XX typically indicate an error on the client side—meaning the issue is on your end.

shell sinew
#

@normal heart did you maybe have this problem that after connecting to HTB openvpn host is still down?

#

do you know how to fix it? (machine's restart doesnt help ://)

normal heart
shell sinew
#

wait, im rebooting

#

just tun0

#

oh, reboot fixed it haha

normal heart
#

Yay

normal heart
#

That would make sense on why it seemed broken

#

200 is confirmation it worked as intended and 300s are redirects

blissful spire
#

What should I try first as a ethical hacker and where can I practice my hacking skills any recommendations??

chilly merlin
#

@quasi berry day 78 of asking for help

#

I need to be able to loud mic

#

😭

lament walrus
#

heeellp

#

PLEASE

quasi berry
#

Give me a moment y'all 😭

chilly merlin
twilit crystal
#

idk what’s happening

#

I think someone hacked my phone

#

If someone can dm me so I can send messages I’m getting

#

Like idk what happened

lament walrus
#

uh

#

GUYS

quasi berry
#

I'm here now

lament walrus
#

hiiii

#

wanted to check up on you uwu

#

hru

#

also

#

i may need help in wireshark

#

💀

#

@quasi berry

quasi berry
lament walrus
#

im doing well

quasi berry
#

Also do I know you or smth? 😭

lament walrus
#

damn that hurt

#

damn....

#

im jk

lament walrus
#

how do i examine network traffick

#

i have a pcap file

quasi berry
quasi berry
lament walrus
#

im just a rando

#

just one that tries to be kind

quasi berry
lament walrus
#

aww ty

quasi berry
#

No worries

lament walrus
quasi berry
lament walrus
#

i havent been given one

#

the ctf is literrally just the file

#

and this definition

#

"Network traffic or data traffic is the amount of data moving across a network at a given point of time."

#

i have no clue what its supposed to be

#

on second though actually

lament walrus
normal heart
#

Youre looking for exposed information sent over a non secure line

lament walrus
#

nothing important atleast

#

maybe i missed something

normal heart
#

theres gonna be a flag somewhere

normal heart
#

Follow the TCP Stream and check all headers/look for files.

lament walrus
#

bruh my kali crashed

normal heart
#

That is what I recommend starting with

#

That is also what @quasi berry would recommend too.

quasi berry
# lament walrus i have no clue what its supposed to be

Think of the packets like cars, they are moving across a motorway. Aka traffic. What you want to do is look through the packets for any which may have something to do with file transfer, you should be able to right click on that packet and initiate "follow TCP Stream" and in there you should be able to find a file, might be a .txt file or it may be in a header of the packet itself. Which ctf is this for?

lament walrus
#

ohh

#

well i'll wait untill this boots then check

twilit crystal
#

can someone please help me

#

if they can dm

quasi berry
quasi berry
twilit crystal
#

ios

lament walrus
#

bruh

#

it was in base64

#

ty!!!

twilit crystal
#

if someone knows how to help i think i got my phone hacked or smt

quasi berry
lament walrus
#

uhh

#

so extremely weird OSINT one

quasi berry
lament walrus
#

Friend: No problem. I'll just hop on a secure VPN. Me: Can you find her linux user?

#

flag format : flag{user}

quasi berry
#

Is this for checking openvpn logs or smth?

lament walrus
#

idk

quasi berry
#

Wait, wait wait

lament walrus
#

this is all that is provided

quasi berry
#

Are you doing labs on immersive labs or cyberdiscovery or smth because I recognise the style of questions LOL

normal heart
#

okay; so track the friend if possible

lament walrus
#

nah

quasi berry
normal heart
#

Did they send the user later on?

lament walrus
#

this is all that it says

normal heart
#

Is this all packets?

lament walrus
normal heart
#

Which one

quasi berry
lament walrus
#

different ctf

normal heart
normal heart
#

Just want confirmation

lament walrus
quasi berry
#

One sec

lament walrus
#

also bennie

#

(is it ok if i call you that)

quasi berry
#

Yeah many people call me that, it's fine

lament walrus
#

did cy send you the corrupted png

quasi berry
#

No?

lament walrus
#

oh

chilly merlin
chilly merlin
#

So we need help

shadow fractal
chilly merlin
normal heart
shadow fractal
normal heart
#

The goal is to make their mic as loud as possible most likely because they wish to scream into someones ears with an already loud mic...

lament walrus
normal heart
lament walrus
#

is to litteraly swallow it

#

eat it

shadow fractal
lament walrus
#

HRU

chilly merlin
shadow fractal
#

Just got of work

#

Forwarded benny with info

lament walrus
#

caps bot

normal heart
lament walrus
#

smh

chilly merlin
normal heart
#

Any more discussion and I will time you out

lament walrus
#

those things are CRAZY loud

#

XD

chilly merlin
normal heart
lament walrus
shadow fractal
#

@chilly merlin Also another thing, please adjust your pronoun for this server

chilly merlin
#

Oh

shadow fractal
#

Refrain from these kind of comments

#

And no...

lament walrus
#

aw mann

quasi berry
lament walrus
#

i wont do it again

chilly merlin
shadow fractal
quasi berry
normal heart
chilly merlin
shadow fractal
normal heart
chilly merlin
#

Igu

normal heart
#

Thx

lament walrus
blazing pasture
#

plz suggest me a good books for hacker

quasi berry
shadow fractal
chilly merlin
#

Too

normal heart
lament walrus
normal heart
#

Also hacking is a specialty inside of Cybersecurity

blazing pasture
#

bro im tired of reading this syngress basic pentesting book

lament walrus
normal heart
#

What do you know?

blazing pasture
#

i want more books to read suggest best one plz

lament walrus
#

i dunno about books

#

but theres a few websites that can help

blazing pasture
#

bro are u intermedite in hacking i wanna know

lament walrus
#

yus

blazing pasture
#

if you r then how you learn hacking

lament walrus
#

websites???

blazing pasture
#

? names

lament walrus
#

i mean

#

which branch of hacking you wanna focus on?

blazing pasture
#

bro suggest free one plz

#

bro i want to learn bug bounty

#

hacking

lament walrus
#

oh

#

like web exploitation?

blazing pasture
#

yup

lament walrus
#

bet

blazing pasture
#

?

lament walrus
blazing pasture
#

i bet you gonna tell me to master owasp ten ?

lament walrus
#

do some picos

blazing pasture
#

i knew about this site