#👥・help-me

1 messages · Page 16 of 1

cyan tusk
#

arch

#

cant remember what I did to make it work

spring snow
#

its up now?

cyan tusk
#

nope

#

Im trying some different conf

spring snow
#

okay

#

i had a similar issue so for that i tired to installed a different os and than clear that and install arch

#

and it worked

trim axle
#

Where can hackers find hashes?

#

Because I want to know if they can fine my Microsoft hash

simple vigil
quasi berry
#

@rotund delta ?

rotund delta
#

YES

#

my bad on all caps

#

sorry did I do some wrong my bad

quasi berry
rotund delta
#

oh lol yea it was just random felt like replying

formal terrace
chilly merlin
#

what should i do to learn hacking

simple vigil
formal terrace
simple vigil
#

What your talking about 😭😂

formal terrace
#

Nvm you don’t get the reference

chilly merlin
#

Did you download it?

chilly merlin
quasi berry
chilly merlin
#

Anyone know anything about bios stuff? Because I tryed resetting mine and there’s no wifi network’s showing up. Like it’s not even saying “no networks found” in gray letters. It just shows blank.

chilly merlin
#

Wdym networks found?

#

On windows or??

#

Windows 11

#

Yes sorry I forgot to specify that

chilly merlin
chilly merlin
#

@chilly merlin I need your help

chilly merlin
#

its like asking a beggar for change

#

but shoot it

north robin
#

I want to learn hacking can anyone teach me ill work for them

#

Dm me

chilly merlin
chilly merlin
chilly merlin
# chilly merlin but shoot it

@chilly merlin just reinstalled windows 11 on his customised laptop.
Windows can't find a driver for his pc and I can't find the model of his pc since its customised

chilly merlin
#

I can't get drivers for a pc idk

#

what driver

#

does it miss

#

Network adapter

chilly merlin
chilly merlin
chilly merlin
chilly merlin
#

it quite normal

#

For a laptop not a desktop

chilly merlin
chilly merlin
#

peeps here use 64 ram for lappys

#

🥲

chilly merlin
#

Ayoo

#

find a yt video

chilly merlin
chilly merlin
#

I try doing stuff without tutorials. Trying to train myself

#

good work

#

¯_(ツ)_/¯

#

pass to the guy

chilly merlin
#

¯_(ツ)_/¯

#

¯_(ツ)_/¯

#

@chilly merlin give a ear

chilly merlin
chilly merlin
#

?

#

Yeah

#

¯_(ツ)_/¯

#

its good

#

u should see my phonk playlist

#

I'll listen when doing CTFs

maiden violet
chilly merlin
#

and give it to u guys

maiden violet
#

Okie

chilly merlin
#
#

give a ear

#

its good

#

balanced

chilly merlin
chilly merlin
chilly merlin
#

its good though

#

I think he's demonic >>

chilly merlin
jovial temple
#

hello you guys know where i can search for scientific studies which are mostly from trusted site

#

cuz just typing it on google won't bring that much good result

chilly merlin
jovial temple
#

mostly about tech research and neuronological studies

chilly merlin
# jovial temple mostly about tech research and neuronological studies

1 . The BRAIN Initiative
2 - Coursera Neurology Courses
3 - Neuroscape at UCSF
4 - Labouré College Neurodiagnostic Technology
5 - National Institute of Neurological Disorders and Stroke (NINDS)
6 - Coursera Neuroscience Courses
7 - OHSU Brain Institute
8 - Atrium Health Neurosciences
9 - Institute of Health Sciences Neurodiagnostic Technology
10 - Alvin Community College Neurodiagnostic Technology

#

I hope this helps

jovial temple
#

yeah and a lot

#

thanks man

jovial temple
chilly merlin
#

I am looking for my first job in cyber security, what do you think I should pay attention to?

ashen dawn
#

Can anyone tell me what a 4978 id means on event viewer?

#

4798(S): A user's local group membership was enumerated - What does this mean in laymens terms, im not IT well versed in IT?

ashen dawn
#

I didnt turn on my PC and I checked the event viewer logs and saw that event id at a certain time. Not sure if someone logged onto my PC and what does it exact means. And what should I check to see what was done?

chilly merlin
#

anyone helping?

lean lance
# ashen dawn I didnt turn on my PC and I checked the event viewer logs and saw that event id ...

1. Check for User Logins:
Open Event Viewer: Press Win + X, then select Event Viewer.

Navigate to Security Logs: Expand Windows Logs and click on Security.

Filter Logs:

Click Filter Current Log on the right side.
In the filter window, enter 4624 (for successful logons) in the "Event IDs" box.
Click OK to apply the filter.
Look through the filtered events to see if there was a logon around the time of Event ID 4798.

2. Check Recent Activities:
Filter Security Logs:

Follow the same steps to filter logs, but this time look for other relevant event IDs like 4648 (logon attempt with explicit credentials) or 4672 (special privileges assigned).
Review Events: Check the details of these events to see what actions were taken.

3. Check User Accounts:
Open Local Users and Groups: Press Win + R, type lusrmgr.msc, and press Enter.
Review Accounts: Check for any new or modified accounts.
4. Review Security Settings:
Check Audit Policy:

Open Local Security Policy by pressing Win + R, typing secpol.msc, and pressing Enter.
Navigate to Advanced Audit Policy Configuration -> Audit Policies.
Ensure that auditing for "Account Logon," "Account Management," and "Policy Change" is enabled.

#

4798(S): A user's local group membership was enumerated

Indicates that someone or something checked the local group memberships on your computer. This means they looked at which groups your user account belongs to, which can give insights into what permissions or access rights you have.

In short, this event logs the action of enumerating or listing out the local group memberships of users on the system.

chilly merlin
#

chatgpt?

lean lance
#

No I just type REALLY fast

#

😄

lean lance
#

But yes, It saves some time. I do audit it all

#

Because it does hallucinate sometimes 😄

whole wave
#

@chilly merlin

#

Where is the general chat?

lean lance
#

😂

zenith hemlock
rugged imp
#

Does anyone have advice or guidance on getting a job in cybersecurity? I have most of the practical skills, including certifications, but I lack work experience and can't even seem to land an interview or internship. I'm asking around, so any advice is greatly appreciated. For context, I'm currently in college pursuing my BA in Information Technology.

shell sinew
rugged imp
shell sinew
chilly merlin
#

hella books

rugged imp
#

and sadly its prefferrable they be remote internships do to location

chilly merlin
#

remote are hard

shell sinew
chilly merlin
#

@shell sinew need to talk something in dms

chilly merlin
shell sinew
#

go on

chilly merlin
#

need to add

ashen dawn
timber spoke
#

@chilly merlin

#

is there a thing like this but for sms

ashen dawn
#

@chilly merlin @lean lance How do I post screenshots of what I found?

chilly merlin
timber spoke
chilly merlin
ashen dawn
stray mural
#

Direct Messege (DM)

ashen dawn
dry parcel
#

I want to learn basis to advanced networking please suggest me a lecture

lean lance
#

Even things like remote administration tools and such can do some of those checks on boot

#

Like Teamviewer, Anydesk etc

#

I'll send you a small step-by-step in DM to try and figure out what triggered the event

chilly merlin
#

@chilly merlin both ways didn’t work 😦

#

I think I need to just download the bios again on the USB?

chilly merlin
#

@chilly merlin The video didn’t work

#

I tried both ways that it showed me

chilly merlin
#

Bruh

#

we did what we can

#

Ik ik

#

u wanna blame us

#

I appreciate the help

#

No

#

¯_(ツ)_/¯

#

I don’t blame you

#

find another solution

#

I blame digital storm for building a shitty laptop 😁

timber spoke
#

what file does a payload have to be in

#

@chilly merlin

#

txt?

chilly merlin
#

payload?

timber spoke
#

yes

#

payload

chilly merlin
#

hmm depedns on os

timber spoke
#

payload to a file

#

linux

chilly merlin
#

we use

timber spoke
#

kali linux

chilly merlin
#

.sh

timber spoke
#

how do i store it

#

sh ?

#

how do i make a file like this

chilly merlin
#

first learn basics

#

and try to use google

timber spoke
#

im asking u

#

foe help

#

how to make a sh file

#

:((

chilly merlin
#

try googling im at work

timber spoke
#

ok papi

chilly merlin
#

do not call me that

unborn zealot
#

Lmao

chilly merlin
#

bother some one not me u have been warned.

novel axle
#

is there any way to get my google account back that i lost the password fg

#

for

shadow fractal
#

Yeah, been a while now, thanks!

#

Almost a month

soft charm
#

hi

#

someone pls dm me to help me how to hack

#

🙏

dapper mortar
#

I'm working on some key encryption HW does anyone know what these error codes are/ where I should start looking to fix them


pem -pubout -outform PEM

Could not read private key from alice_privatekey.pem

408C1243147F0000:error:1608010C:STORE routines:ossl_store_handle_load_result:unsupported:crypto/store/store_result.c:151:

408C1243147F0000:error:1608010C: STORE routines:ossl_store_handle_load_result:unsupported:crypto/store/store_result.c:151:```
#

I generated a private key and I'm trying to encrypt some text using openssl, but it can't read the file that I encrypted

unreal reef
valid belfry
#

@dapper mortar just use gpg

#

Gpg private key also holds the public fyi

dapper mortar
#

What's gpg?

valid belfry
#

I can show you

#

GPG (GNU Privacy Guard) is a tool used for encrypting, decrypting, and signing data. It provides strong encryption using both symmetric and asymmetric keys, supporting public and private key pairs.

#

If you have android you can get an app called openkeychain

#

GPG keys work by using a pair of cryptographic keys: a public key and a private key. The public key is shared with others to encrypt data or verify digital signatures, while the private key is kept secret and used to decrypt data or create signatures. When someone encrypts a message with your public key, only your private key can decrypt it, ensuring secure communication. Similarly, signing a message with your private key allows others to verify its authenticity using your public key.

dapper mortar
#

That sounds really cool

dapper mortar
#

I'm cool with either

valid belfry
#

It's above

#

I typed for you

dapper mortar
#

Ahh okay I got you, thank you so much

valid belfry
#

Lmk what you think

dapper mortar
#

Bet bet

timber plank
#

107Practice Exam A - Answers
A69. A company is in the process of configuring and enabling host-based
firewalls on all user devices. Which of the following threats is the
company addressing?
❍ A. Default credentials
❍ B. Vishing
❍ C. Instant messaging
❍ D. On-path

The answer I chose was On-Path Attack. But the actual answer is Instant Messaging. Can someone explain how a host based firewall would not apply to On-Path attack.

timber plank
# timber plank 107Practice Exam A - Answers A69. A company is in the process of configuring and...

I think I might have realized the answer. MITM (on-path attack) is concerned with two devices communicating with each other and someone sitting in the middle of that conversation. The question was not addressing communication of devices it was just simply asking what a host based firewall could be protecting such as an instant messaging application. Whereas on path attack would be prevented with encrypted traffic

timid pasture
#

I have a problem

||I code in JavaScript||

chilly merlin
#

@timber spoke You still need help??

chilly merlin
chilly merlin
chilly merlin
#

I’ll let you know what happens

normal ginkgo
#

Hi

chilly merlin
chilly merlin
normal ginkgo
#

What are you doing brother

tardy valley
#

So about deterministic password generation

#

A major drawback I can see is problems with data breaches, need to alter the input string then

lean lance
#

For better security, ditch the predictable input strings—they're an easy target for attackers. Add some randomness using a cryptographically secure random number generator, or better yet, use something like Argon2 or bcrypt to beef up your password generation. These tools are built for security, so you'll get strong, unique passwords without worrying about weak links. Keep it simple but solid.

tardy valley
#

I want a passwordless experience though

#

So I don't have to remember or store them anywhere that could be taken or lost

#

I suppose it's not ideal from the security standpoint

#

The experience is sort of like biometrics, except more easily hacked

#

Of course I use different strings for different accounts

tardy valley
#

Or is the problem in the resulting password itself?

lean lance
#

The problem is the fixed relation to input > output. Same input will always give the same output

#

You need proper randomness and added entropy

tardy valley
#

To note, this is intended for personal use, not enterprise security

chilly merlin
#

@lean lance

lean lance
#

The problem lies less in the resulting password itself and more in the predictability and lack of randomness in the process. Attackers don’t need to guess the cipher or hash if they can figure out or guess the input. Once they have that, the deterministic nature of your process will give them the same password you’re using.

tardy valley
#

How would knowing my input give them a password?

#

I didn't think that the ciphers were useless

tardy valley
lean lance
# tardy valley Oh, you mean if they had access to my password generator?

Yes, they would need to know how your password generator works, but security through obscurity (relying on keeping the method secret) isn't a strong defense on its own. If an attacker gains access to your code or reverse-engineers the process, knowing the input would be enough for them to generate the same password every time.

tardy valley
#

Yeah that is true.

#

I just hide it encrypted on my cloud

#

Which I guess isn't that good

lean lance
#

To mitigate this, you need to introduce entropy (randomness) into the process, so that even if the input is known, the resulting password is unpredictable. This could be done by adding a salt or secret value, or using a more random input.

chilly merlin
#

everything good? @lean lance

tardy valley
#

That would unfortunately defeat my purpose of not having to store or remember passwords

maiden violet
lean lance
#

Is your purpose to learn and create, or just a bit paranoid to use any password manager?

lean lance
chilly merlin
#

maybe owasp top10

#

or thm rooms

lean lance
#

😄

tardy valley
#

I guess opting for something like NordPass would be a more secure alternative

lean lance
#

I used to have a KeePass instance, but I switched to self hosting Bitwarden

chilly merlin
#

Why not just use a normal passwd manager?

tardy valley
#

Because I want to have access to all my accounts simply by having access to my Google drive

#

Though bitwarden looks good

lean lance
#

I love Bitwarden, I can access my stuff anywhere. And everything is stored on my own server, which can only be accessed via Wireguard

#

But yeah a bit more advanced if you don't know anything of self hosting securely

#

Plenty of good tutorials on YT though, if you wanna go down the self hosting rabbit hole

tardy valley
#

Of course it does present a risk still

lean lance
#

Well I mean, it's something for sure. But MFA can be bypassed. And encryption keys can be guessed.

#

I personally don't like having my stuff on servers I don't own, but that's me

lean lance
#

Security is always in layers

tardy valley
#

Thanks for your help

lean lance
zinc maple
#

I need help

#

Like real bad

lean lance
#

What's up

zinc maple
#

Some person is trying to black mail me

#

What do I do

#

What can yous do to help me

tardy valley
#

You should probably try telling them more about your situation

chilly merlin
#

@quasi berry I need professional help.

#

My friend had turned Bitlocker turned on on his new pc and booted into a live ubuntu session. He claims he didnt change any settings. He rebooted into windows and it was asking for a bitlocker recovery key. He didnt set it up, it was given to him with the bitlocker turned on.

#

@lean lance

lean lance
#

Wait, he turned it on but also it was already turned on? A bit contradicting

quasi berry
#

Yeah you get a bitlocker recovery key when you enable it; did he not store the key anywhere?

quasi berry
lean lance
true iron
#

So basically your friend had his bitlocker ON usually it gives out a recovery key. When you boot in to your ubuntu session and after leaving it, boot back into windows what bitlocker is doing is asking for additional authentication as it may thinks you may have have tampered with the drive while in a live ubuntu session. I think it can be solved easily if you try to access the same microsoft account from another device and find the recovery key

zinc maple
#

Hypothetically speaking... are yous allowed to delet people's acc if they do something bad...

lean lance
#

What do you mean, delete where

zinc maple
#

Like let's say a person did something bad on instagram or tiktok they posted stuff and make rumours. Are yous allowed to take down there accounts

lean lance
#

No, you are not allowed to decide the fate of someone's account on an external platform.

#

You can report the account to the platform in question

zinc maple
#

Oh alright just making sure..

tardy valley
#

do you think it is viable to seek an international relations degree in respect to careers in cybersecurity or government work?
What about regional studies (i.e. Russia focused studies)?

true iron
#

Depends on your situation where you wish to build a career. if you’re open to anything then internationally accepted certifications are recommended. If you are trying to find a niche(russia) then you have to build your learning around that niche.

chilly merlin
#

HIs mom gave it to him as it as and she doesn't know anything about computers. So its a dead end asking her

#

I just told him to reinstall windows

chilly merlin
#

@lean lance : )

lean lance
#

Well yeah, in that case reinstalling is the only option. No key, no party @chilly merlin

chilly merlin
#

Yeah but theres still one shot tho

chilly merlin
lean lance
tardy valley
#

I am in Eastern Europe, so Russia studies are also available and relevant

true iron
#

Get familiar with laws and regulations, Regional IT practices and standards

tardy valley
#

Could you tell me more? I am still at an early stage of building my career

true iron
tardy valley
#

That's a good idea, thank you

safe fjord
#

Hi, I'm looking for someone to give me a hand with some facebook scraper, I have to collect phone numbers of a particular location.

lean lance
chilly merlin
# chilly merlin Okay.

So it was a drivers issue they said but the one that I downloaded wasn’t right for the model. So you were correct about it being the drivers. I just didn’t install the right ones for my model 😂

#

It’s fixed now but thank you

chilly merlin
#

Okay

#

So you can access the internet now right? @chilly merlin

#

How much did you spend on it

maiden violet
#

Wait what?

half basin
#

Hello Ai engineer from india?

chilly merlin
#

added kali repo and install metasploit framework on my mint sys. I run it after it was done and it showed an error and then told me to use "bundle install --gemfile /usr/share/metasploit-framework/Gemfile but i also got and error of ruby required <3.2 >=2.6, i then tried to install ruby 2.6 but idk how to

#

@lean lance

lean lance
#

Hmmmm, yeah adding Kali repo's on different OSes is prone to some issues most cases

#

I'd suggest setting up a virtual machine with Kali, removes alot of hassle and possibly breaking packages

chilly merlin
#

Did u edit / etc/ sources.list

chilly merlin
chilly merlin
#

U meant /etc/apt/sources.list

#

The prob isnt the repo

#

its metasploit

lean lance
#

Yeah, Kali is debian based.

chilly merlin
lean lance
#

Less prone to errors mostly

lean lance
chilly merlin
#

So i think its an ubuntu prob

#

Yea that path

lean lance
#

Setting up a VM is definetely a better option though, avoid messing up your main system

chilly merlin
#

Vm 💪

chilly merlin
lean lance
#

Plus you can easily make copies and snaps

#

Oh yeah for sure

chilly merlin
#

¯_(ツ)_/¯

lean lance
#

Question is why 😄

chilly merlin
chilly merlin
lean lance
#

😄

chilly merlin
chilly merlin
lean lance
#

Fair, I prefer CLI over GUI too.. Maybe I'm just oldschool

chilly merlin
#

Who are these people

lean lance
#

Depends though

chilly merlin
#

i have linux not windows 🙂

#

Is there a way

lean lance
#

Sometimes GUi just saves time

chilly merlin
#

Cli

chilly merlin
lean lance
#

Haven't run Windows as daily driver for over 7 years

chilly merlin
#

Maybe on your pc

#

Mine's slow as shit

lean lance
#

I just exploit the shit out of it

chilly merlin
#

1.10Ghz

lean lance
#

Oh dang, that must be old af

chilly merlin
#

1980s pc

lean lance
#

Yeah VM will be a pain on something that old

chilly merlin
lean lance
#

I would just:

chilly merlin
#

2019 i think

lean lance
#

Wut, 1.10 ghz?? 2019?

chilly merlin
chilly merlin
chilly merlin
lean lance
#

I don't know what your budget is, or your situation. But maybe a small VPS or 2nd hand laptop / pc with a bit more power

chilly merlin
#

Raspberry pi

#

¯_(ツ)_/¯

lean lance
#

Cheap and quite powerful

#

It beats your celeron 😄

chilly merlin
#

Atleast it doesn't cut the cookie pockets

chilly merlin
lean lance
#

Also Raspberry Pi's are great to learn from, for some fun projects 😄

chilly merlin
#

10?

lean lance
#

Fair fair

chilly merlin
#

maybe still in womb ¯_(ツ)_/¯

lean lance
#

Oh really, wow. I would not have guessed that tbh

#

That's a compliment btw

chilly merlin
#

Hmm not young

#

I'm 51

lean lance
#

❤️

chilly merlin
lean lance
#

Some people still call me a kid, I'm 27 :/

chilly merlin
chilly merlin
chilly merlin
#

I have kids of ur age

chilly merlin
chilly merlin
#

Bro doesn't believe me

lean lance
chilly merlin
#

Ayooo

#

I need proof

stable hedge
#

Who can teach me basics abt TLS UDP TCP and sip protocols

void sphinx
#

Hello guys. I am new here. I wanted to know if there is someone who already has a job and can take a look at my cv and tell me what I am missing. I am still in university.

chilly merlin
smoky osprey
#

Guys can anyone guide me to get started in pentesting?

lean lance
#

Sure, what do you wanna know

chilly merlin
#

@lean lance point them to pinned messages why the hassle

#

Already answered theses type of questions

lean lance
#

Yea was gonna, just scoping out 👀

#

My sus radar is off the limits rn, mb

#

😄

smoky osprey
chilly merlin
#

Wait until they fuck around

lean lance
smoky osprey
#

Bro how to stay motivated?

lean lance
#

Really wanting to learn it I guess

chilly merlin
#

Some peeps come for help . Help them and becareful on all times they might be trolling sometimes not everyone

lean lance
#

Luckily I got Discord moderation experience 😄

chilly merlin
#

Jus saying

smoky osprey
lean lance
smoky osprey
#

Should I've to cover the entire networking thing?

lean lance
#

Entire might be overkill, but network understanding is defo a key part

smoky osprey
#

Like can you list the imp topics?

#

Which I've to focus on

lean lance
#

Click the Pinned Messages at the top of this channel

smoky osprey
#

Ohk

chilly merlin
#

Hmm

lean lance
#

Some good resources to know where to start and what to learn

smoky osprey
#

N CEH is still in demand?

chilly merlin
#

Where's lukas he's good at networking and linux

#

@valid belfry

smoky osprey
chilly merlin
#

Check network chuck

#

Or david bombal

smoky osprey
#

Yeah ik that guy. He's to good

chilly merlin
#

drugs

#

take lots of drugs

#

START TODAY

lean lance
#

No, coffee

chilly merlin
smoky osprey
#

Ok guys thank you. I'll contact you if I'm stuck

chilly merlin
#

Not me contact cyphersec

#

👀

lean lance
#

😭

#

I feel like I got a 2nd job since I joined

#

Which is fine tbh 🙂

smoky osprey
smoky osprey
chilly merlin
patent rampart
#

Sup

chilly merlin
patent rampart
granite lynx
#

Hi

chilly merlin
#

Ill let him know

#

Ty

#

@void sphinx

granite lynx
#

How are you all

unreal reef
chilly merlin
#

Iv done businesses with them before so they knew me

serene surge
#

how much gb ram would be ideal to run kali linux?

chilly merlin
kindred coyote
#

Unsure if this is the right place to ask, but does anyone have experience with a M3 Pro Macbook for cybersecurity? Im thinking of either choosing between upgrading to mac from a 1650 ti laptop or going in on a roughly 2000$ Desktop build for gaming/cybersecurity

gusty shuttle
#

I need a mod

#

@patent rampart or somebody

chilly merlin
#

about what

#

why’d u @ htb staff

#

😭

patent rampart
#

I'm not a mod here

quasi berry
chilly merlin
gusty shuttle
quasi berry
patent rampart
kindred coyote
lean lance
granite summit
#

who here know a great course for digital forensics? I am way to invested to become great at this skill I want to know more!

valid belfry
solar fiber
#

Here for help!

chilly merlin
#

hi

#

whatcha need help with

solar fiber
# stable hedge Who can teach me basics abt TLS UDP TCP and sip protocols

Answer

Hiiiii I'm not an expert on this but since I haven't noticed anyone responding I will respond according on what I understand from some these concepts and If someone more experienced than me notice I'm incorrect, can help me explain it a little better.

What is a network

(From my understanding) a network is a kind structure of connected devices that cam communicate with each other within a local or wide area. For long distances, they transfer data through cables made of copper or fiber optics and for some shorter distances they use frequencies. Most of this of these methods are translated into a digital format of data called binary which then are reinterpreted by any devices that recieve it. But in order to create a universal form of communication between devices along with their security features, protocols are invented

What are protocols

Protocols are a set of rules In which data packages are prepared for the process of communication. Some of these are combination of other protocols. Some are less secure than others and some are already deprecated but still being used because old devices still up and running around.

It will continue...

kindred coyote
solar fiber
# stable hedge Who can teach me basics abt TLS UDP TCP and sip protocols

TCP/UDP

This protocols determines the way that data packets are being transported and one is older and less secure than the other.

UDP (User Datagram Protocol)

The UDP protocol is a connectionless protocol that doesn't requiere a receiver device to be up and hearing for data since there is no rule that ensure data receiving. So the data sended through this protocol is like a MP15 mindlessly shooting hopping that his target recieve some bullets.
This protocol has been invented before TCP and has a set of rules that made it appropriate for some stuff like gaming and internet voice chats.

#

TCP (Transmission Control Protocol)

This protocol Is very different from the first since It tries to ensure and confirm a live collection between devices and uses a method called three way handshake that ensures the connectivity. This one is very strict and will make sure for every packet to reach his destiny and this can be done by receiving and acknowledgement data package communicating that the packet has been received.

stable hedge
#

So tcp less stable

#

But more secure

#

But udp more stable

#

Thx so much

solar fiber
#

Hmm

solar fiber
#

And I'll tell you why

rare raptor
#

Cause TCP has error checking and can resend a packet

#

UDP doesn't check so everything needed for delivery is in the packet already

solar fiber
#

If through the TCP protocol, a data package isn't received or duplicate, it will fix that

#

Making it more stable than UDP

#

Since UDP doesn't really matter duplicate or missing packages

rare raptor
#

Yeah if sending fails in UDP, it's just gone lol

stable hedge
#

Shit bro

#

I need tcp then always

solar fiber
#

TCP is more stable because has error checks and UDP don't. Making it more smarter than UDP

stable hedge
#

I hate when the calls on sip hang up out of nowhere

rare raptor
#

some stuff like video and audio conferencing doesn't require TCP cause it won't be doing all those same checks

solar fiber
#

Games and calls doesn't use TCP because they make connections very slow

stable hedge
#

Aright so for phone calls tcp best

rare raptor
#

I think we on the same page

#

Idk why I needed to add my 2 cents but here I am lol

solar fiber
#

You will receive all the data packages, yeah but imagine receiving a very low rate of data

rare raptor
#

UDP for audio and video is faster

solar fiber
rare raptor
#

Spot on

solar fiber
#

For packages that need full integrity and security you may use TCP:

  • Web sites
  • Text chats
  • File transfering
#

I'm not an expert on this but I hope it helps

shell sinew
#

UDP

  • UDP is much faster than TCP
  • UDP leaves the application (user or soft) to decide if there is any control over how quickly packets are sent
  • UDP does not reserve a continuous connection on a device as TCP does
  • UDP doesn't care if the data is received or not
stable hedge
#

Shit this is so helpful better than my professor

shell sinew
solar fiber
#

Oh shit

#

Sorry Thats what Im referring to

#

Lmao

#

Sorry sorry haha

shell sinew
#

ur fine

solar fiber
#

My mind got blasted by giving all these explanation HAHA

rare raptor
#

You did fine

solar fiber
#

I was learning to read bar codes by myself haha

#

It seems pretty possible, like morse code or binary

solar fiber
shell sinew
#

TCP

  • Guarantees the integrity of data
  • Capable of synchronising two devices to prevent each other from being flooded with data in the wrong order
  • Performs a lot more processes for reliability
  • Requires a reliable connection between two devices. If one small chunk of data is not received, then the entire chunk of data cannot be used and must be re-sent
  • A slow connection can bottleneck another device as the connection will be reserved on the other device the whole time
  • TCP is significantly slower than UDP because more work (computing) has to be done by the devices using this protocol
#

hope it helps a bit

stable hedge
#

Gues

#

Guys

#

What does

#

Setting Interrogation Succeeded
Voice Call Forwarding
When Unreachable
Forwards to +1647700xxxx
Enabled

#

Bro one of them is enabled

#

And idk this number

#

Does it mean I’m being wiretapped by the feds

valid belfry
#

@stable hedge no

#

What device is staying this

#

Stating

stable hedge
#

Phone

#

when I do *#62#

#

iOS iPhone

chilly merlin
#

Hello, I joined this discord after a prompt from the video of the owner of this discord, it was a video about how youtube accounts are hacked, I am interested in whether most of the accounts that are hacked today, as far as youtube is concerned, is actually only because they do not have 2FA?This dont make sense every one have 2fa... or insufficient account security? because I personally think that it is not possible to steal a gmail account whith a lumma these days if it is sufficiently secured.Logically, I couldn't find any answer to it except rat. Also, today it is not even possible to upload cookies using selenium and automate the process of removing 2fa and the like, and even if the victim has rat in the computer, the hacker has to wait until he is far from the computer, logically I only knew that really most of these people do not have 2FA, can someone confirm or refute it?someone experienced?I can also send a link to the video where it was discussed.

viscid needle
#

Hlo

#

Everyone

hoary aspen
#

Can anyone help me? A few things. I’m looking to go to school to study something in the IT sector. I’m not sure what exactly. From 15-18 I worked as an MIS help desk. 18-30 I was in the marine corps. I fell off a lot of things. I guess my first question would be what kind of machine I should use. I do have an iPhone and Apple products. I do like to game so good specs for that would be important. Movies and tv shows I watch too. I’ve thought about making a plex server using real debrid. I’m sure I’m going to have to learn coding so a system that’s capable of windows Mac and Linux might be cool. I know you can run virtual machines or boot camp I just need to be able to switch back and forth between them easy.

And I guess to know what classes and certifications I should take

chilly merlin
#

If you want to switch back and forth for different operating systems I would make the laptop a hybrid.

#

Certs: CompTIA A+

#

Basic Cert to get your foot in the door when applying for internship level jobs ^^^

#

And yeah I think that’s about it for my knowledge.

crisp star
chilly merlin
#

I agree

hoary aspen
#

Thank you both for your responses

chilly merlin
#

No problem

hoary aspen
#

I don’t really know what to pursue because the sector is so vast. I do feel like AI is going to be a huge factor in the foreseeable future. With that I feel security is going to be important. Also I have an idea that I think will work that’s essentially similar to Ready Player One in the sense you can go to school and make better choices in life. So I guess making like a VR/AR type game

chilly merlin
#

Game development then?

hoary aspen
#

J think that would be more of a hobby

chilly merlin
#

Have you watched the first episode of Cyberpunk 2077?

#

Is that the type of virtual reality game your talking about wanting to make?

#

Like a brain dance?

hoary aspen
#

I’ve never looked into game development before

chilly merlin
#

Same

#

Cybersecurity makes more money anyways for the average person lol

#

I think they start out at 100k a year at least?

#

Eh somewhere in that range

hoary aspen
#

Picture you put on a whole haptic system and then let’s say you want to go to school to be a doctor. You can get live simulation on operating feel everything you can mess up horribly but then you learn from the mistakes

#

Never watched cyberpunk 2077 but I want to now.

hoary aspen
#

So I have a laptop right now that has Linux mint on it and I know I probably added something wrong because I just copied and pasted things into terminal

#

I’m trying to wipe the whole thing and restart fresh. Problem is it won’t boot from the usb now and idk what to do

lean lance
hoary aspen
#

Yes

#

The problem is whenever I try to change it in the bios it saves but it bypasses the usb

#

I think I ran a line of code wrong because I’m not too familiar with Linux I was just copy and paste different things without really knowing what the hell im doing

#

I guess that’s how I learn best though

#

I find a problem and I come up with a way to solve it

hoary aspen
hoary aspen
#

I remember when AOL first came out I snuck into my aunts computer room and started messing around with keys and then when that didn’t work I opened it up unplugged everything and bypassed the password for a good month of 5 hours straight with dial up. Yup I got that ass whooping of a life time but they gave me the computer and I just started tinkering and figuring things out.

#

I’m not sure exactly what IT support does but if that’s what you gather from what I’ve described then yes

chilly merlin
hoary aspen
#

Soooo much

#

It’s all for trying to get plex on the laptop

#

It didn’t turn out too well for me with that tbh

chilly merlin
#

Is plex even available for linux

#

Describe what happened after

hoary aspen
#

They have a plex player yes.

#

When I put in codes I know I got errors so I just tried another and another

chilly merlin
#

I can install it in 2 minutes. Where did you get help from

hoary aspen
#

Again like I was 8 years old trying shit until it works 😂

hoary aspen
#

Into terminal

chilly merlin
#

Now whats the issue

hoary aspen
#

That’s what I’m trying to do

chilly merlin
lean lance
#

I rather use Jellyfin

hoary aspen
#

That part I have. I don’t know how to link my real-debrid account to it

hoary aspen
# lean lance I rather use Jellyfin

But jellyfin you can’t put on Roku tv plex you can. And I think plex also can go on Apple TV. I’m trying to help my family out with easy setup so that way they can watch whatever they want without having to ask me they can type it in or they see it they click it

lean lance
#

But for novice users, Plex Better ye

hoary aspen
#

Why do you prefer jellyfin over plex?

hoary aspen
lean lance
#

Jellyfin is open-source

#

Fork of Emby

hoary aspen
#

Ok

#

Why the preference of one vs the other

lean lance
#

Well, for one, Jellyfin is open source

#

Reason enough for me

#

I don't like the requirements of using their login and servers etc

hoary aspen
#

So being open source you can change what you want correct

lean lance
#

Well in theory yes

#

But more like, you know exactly what it does

hoary aspen
#

Forgive me I haven’t been dealing with computers like this since 07

lean lance
#

And everyone can contribute and fix/add stuff

hoary aspen
#

Ok I like that

#

I used to use this site called xda developer

#

Kinda similar to that

hoary aspen
# lean lance And everyone can contribute and fix/add stuff

NGL, I ran a quick search if this can be added to Roku and Apple TV and it can so yea help me set this up please. As long as I can is my real-debrid I’m happy. I really would like to be able to have thumbnails of them and also a search.

lean lance
#

I'd suggest looking up on YouTube, gonna be alot easier to follow then some text instructions

hoary aspen
#

Ok thanks

lean lance
#

Jellyfin is simply a "Streaming Channel/App" on the Roku device, Jellyfin backend is on your server/pc

hoary aspen
#

Right I get that

#

And nothing actually would be download to my pc

quasi berry
#

What about Kodi?

upbeat veldt
#

I remember when Kodi was Xbox media center 🤣... Im not sure if Kodi is available for Roku but I know you could always flash a fire stick and install Kodi on it.

quasi berry
lean lance
jovial temple
#

Math usage and level in cyber security

#

Ik it depends on what you aim to do but i wonder what is the general level requires

upbeat veldt
fluid sand
#

heya all, i was wondering if anyone one could point me in the right direction for some learning material (i am still in the basics 😅 ), i have a class that is covering an introduction into cryptography. in addition as part of that i need to make my own small puzzle for the class, but it must be a rudimentary cypher, i was also hoping to pick peoples brains on ideas for unique cyphers that would bring a new aspect to the class(to find something that is a little less common😋 but still fits the parameters of rudimentary) just fishing for ideas 😋

chilly merlin
#

u got this trappy

fluid sand
#

😬

upbeat veldt
fluid sand
#

thank you very much, yes please i would appreciate that, i have played around a little bit with the dcode a bit but i will certainly be using it to assist me

chilly merlin
#

thats trappy for u

#

trappy ill send u a dms

upbeat veldt
#

https://mctf.io/mini-zine code=mixed . Solve 5 of the 6 challenges and get a month of free access to the entire Antisyphon Cyber Range. This is from Black hills Info Sec. But this assumes that you can solve some basic ctf challenges... If you need help solving the initial 5 feel free to ask.

There is also PicoGym which is beginner friendly
https://picoctf.org/

fluid sand
#

thank you, i will be checking these out this evening and see where i stand with them, i do appreciate your help 😊

upbeat veldt
#

No problem

viral citrus
#

hello i am getting the error while installing linux(ubuntu)

#

issue : "unable to install grub in dev/sda"

dapper hearth
#

I created a mySQL database and want to be able to have my partners also work on the DB. Is there a way to group collab without using the cloud. I've created roles for each parter with GRANT permissions. I've thought about using docker or creating a git repo.

heady bolt
#

I’m getting error messages while downloading Nessus in my Kali

lean lance
heady bolt
#

It shows download error

heady bolt
lean lance
#

That doesn't sound like a regular error message

#

How you downloading it?

heady bolt
#

Downloading from the Nessus site

#

After registering my details, and downloading the scanner it just stopped and shows downloading error. Asked to contact the customer support

#

I’m talking about Nessus plugins

lean lance
#

Have you tried running: nessuscli update --plugins-only

lean lance
heady bolt
lean lance
#

@heady bolt Just pinging, so you'll see it

heady bolt
lean lance
#

alr, let me know. We'll sort it out

heady bolt
lean lance
#

This is not the server for some shady make money quick advertising..

heady bolt
solar fiber
#

Hello Im here to help a little

raven isle
#

Anyone know where I can get a blicky from?

frigid trail
#

@chilly merlin

#

Tried that tutorial but doesn't work

#

Getting error

wanton marsh
open blaze
#

I was trying to put my script in github and it keeps getting error can someone help?

To github.com:Angelo-genon/telegram-message-filter-bot.git
! [remote rejected] main -> main (push declined due to repository rule violations)
error: failed to push some refs to 'github.com:Angelo-genon/telegram-message-filter-bot.git'
~ $

lean lance
#

@dusk laurel Check the 📌 at the top bar of this channel. Some good resources to get started.

livid shale
#

Is this where one can get help about a serious issue

#

How do I prove myself ?

chilly merlin
wispy lava
#

What?

#

Any tips or info?

chilly merlin
wispy lava
#

About the code

quasi berry
#

What the fuck?

wispy lava
#

I'm lost

wispy lava
wispy lava
#

No not at all I tried making a scambaiting site for scammers

#

Like kitboga

#

But its not working

lean lance
#

I get the goal, but it's still falls under "unethical"

#

Correct me if i'm wrong @quasi berry

#

😄

quasi berry
wispy lava
#

Really? How?

lean lance
#

Form of vigilantism

wispy lava
#

Its dealing with coding

#

I'm lost

lean lance
#

It's not the code, it's the end goal.

wispy lava
#

The end goal is to make YouTube vids trolling scammer s

#

I'm new to this all so I'm not arguing about it

quasi berry
#

✨ Vigilantism ✨

lean lance
#

I appreciate what you are trying to do, but it's still not encouraged in this server.

wispy lava
#

No I'm not I'm literally making them think its a really account as I piss them off that's it

#

Understanding

lean lance
#

I've been dabbling in the same thing, but I know not to mention or talk about it here

wispy lava
#

I won't do it again if I'm
Not banned

#

Understood if I have to hold a ban I get it I didn't known

#

Known

#

Know

lean lance
#

It's okay, it's just a heads-up

#

No bans 😄 for now

wispy lava
#

I deleted it

#

So what can we learn to do?

lean lance
#

Ethical hacking

#

Anything else, use google

wispy lava
#

What are the main subject of ethical hacking?

#

Or main categories

lean lance
#

Ethical just describes the end-goal and intentions. The main categories of hacking remain the same.

#

For example, you are running a phishing campaign against a company / individual without their permission (unethical) Or you are running a phishing campaign because you are hired to test the companies security (ethical)

chilly merlin
hybrid lagoon
#

good morning yall, quick question. i just finished this ethical hacking course, but it did not contain any labs. so, my question is for CTF, do i start by inspecting the image first? or do i start the sniffing on kali's terminal.

solar fiber
unreal dune
#

Any Arch Linux guy , Help me please
Drop Dm!

heady bolt
#

I got that /dev/sda1 has used 100% of its available memory showing it is full, plz how do I delete the storage to get space

#

I cannot figure out what is filling up disk space on /dev/sda1. Could you please help me solve the issue?

vale tide
#

Hey guys I have a question. I've looked it up and have tried to get it the last 3 1/2 hours. Can sombody maybe vid call me and help me hook up my capture card to my PC and Xbox one? I have 2 kinds but neither are an elgato so I don't freaking understand. I've been streaming through remote play through the app but it keeps kicking me off so it's time to hook this up, if anybody is down to help

valid belfry
#

@vale tide

#

This isn't something you can guide someone thru easily my guy

#

Capture card ? Are you recording game

hoary aspen
#

Is there a way to install an os from gnu grub 2.04

#

grub> ls (hd0,1)/

#

I’ve tried booting from usb this way and no good

wheat lotus
#

the best arch user here 😉

chilly merlin
#

Type

chilly merlin
valid belfry
#

@hoary aspen

#

What're you trying to do?

hoary aspen
#

I was trying to install a fresh copy of mint I don’t think I installed it correctly and was only on a live boot. Then I said to hell with Linux I put a windows 7 iso on a usb and it wouldn’t boot and I think the os is completely deleted because it doesn’t go past the grub screen

valid belfry
#

You probably have grub with no os

#

Because you booted it off a USB

#

Just boot a live USB and install to /dev/sda

#

Or whatever the main drive is

hoary aspen
#

I don’t know how and the usb only has a windows 7 iso

valid belfry
#

On an os that works you can flash mint to it one sec

hoary aspen
#

I have no other device to create a new usb from

#

grub> ls (hd0,1)/

grub> set root=(hd0,1)
grub> chainloader +1
grub> boot

#

This did not work

valid belfry
#

Oh you are probably fucked my guy

#

You need a device to make a USB with

hoary aspen
#

😂

#

Yea i kinda thought that too

dusk storm
#

anyone with slack bot experience? I need help with debugging my code or fixing the triggers

quasi hollow
#

I have to hack iphone x
who can help me?

valid belfry
#

@quasi hollow lol

teal ruin
#

yoo, what are the resources for finding out what known malware does (like a forum or database)? I found a trojan (I think remote access) on my PC and it is named and in Windows Defender database. But when I search up the name nothing really pops up. idk how often people reverse engineer malware tho so maybe no one really knows what it does hence why there is nothing about it.

#

It would be cool to open it up myself but Idk how to deobfuscate so im cooked lol

lean lance
lean lance
teal ruin
#

Thanks, i forgot thats a thing

#

It's a RAT rip, ig an inactive one tho I haven't had any accounts taken or anything and its been on my PC for over a year prob

chilly merlin
#

hmmm

lean lance
chilly merlin
#

skill issue maybe

teal ruin
#

Is there a lifecycle for RAT's? It was on a popular Github page, it's tool for a game which is why I downloaded it

lean lance
chilly merlin
#

its a noob coded rat i think try malwarebytes

teal ruin
lean lance
#

Sure that happens all the time

#

But if it uses DNS, the destination IP can be changed any time and they are back in operation.

teal ruin
#

thanks

#

I have an AsyncRat I think

#

Tried to sign up for Anyrun and Tri.age but I have to be vetted or something so I can't see what it does yet

#

How annoying would this be to remove? It seems to affect the .exe and one .dll according to Windows Defender. I think it needs to run to work i'm assuming. (Which It isn't running afaik). I can do a memory scan tho to double check. I'm also checking my network rn but I don't see anything so maybe it really is inactive

dreamy vine
#

Where get flipper zero scripts

chilly merlin
#

try there

lean lance
#

Bro's getting redirected again 😂

fierce steppe
fierce steppe
#

I wasn’t even paying much attention that’s why I told him to ask here

lean lance
#

Wasn't no attack on you mate

fierce steppe
fierce steppe
lean lance
#

I'm constantly helping people in different channels, no need to flame on me

teal ruin
#

Anyone with experience know how often USB's get infected? After I clean this PC up idk If I gotta buy new usb's or not

#

I doubt it would infect the onboard memory of my Keyboard and Mouse but ig that would be possible

#

that would suck

lean lance
lean lance
vale tide
#

I had a couple say early that it's not simple but anyone willing to help me hook my capture card? I'm trying to stream , I was doing it via remote connect from my Xbox to my PC but it keeps disconnecting. So is my only other way to stream with a capture card??

teal ruin
#

i'll search up symptoms of that. hopefully its easy to know

barren wolf
#

Anyone that has knowledge at rfid cards?

teal ruin
#

is it a red flag to find something on Process Explorer which properties are completely hidden. for example User: <access denied> Parent: <Non-existent Process> as well as the autostart location being <n/a> and path being hidden

#

Anyone know if Malware can run on NT AUTHORITY?

lean lance
#

Yes it can, if it has elevated privileges, it can become SYSTEM

#

I'm assuming you mean "NT AUTHORITY/SYSTEM"

chilly merlin
#

wait

#

can we know what intentions u have

lean lance
chilly merlin
#

better to make it clear before engaging

lean lance
#

There is no info on how to do smth, just some info what means what

chilly merlin
#

¯_(ツ)_/¯

lean lance
#

I aint telling how to to illegal things, dw

#

😄

teal ruin
# lean lance I'm assuming you mean "NT AUTHORITY/SYSTEM"

Oh okay so it is possible. I was sorta thinking. Okay maybe this is just windows acting like malware like usual. But no it might actually be malware. I found a few processes which I think is pretending to be legit Windows processes.

teal ruin
lean lance
#

Wipe the system, clean install

#

Peace of mind

teal ruin
# lean lance Wipe the system, clean install

I've already spent all night trying to isolate and remove just the malware. But yeah ur prob right. Even then, to re-setup everything I did on this PC will take prob a week of work

#

so I wanna remove just the malware preferably

#

Luckily, my gaming PC has no sensitive info, and barely any personal info. I use a hardened browser and don't save any passwords. Which is why I think the malware hasn't really impacted me, and why it has gone unnoticed. Its prob been on my system for over a year now

#

Unless im ignorant and i'm more screwed than I thought

chilly merlin
chilly merlin
teal ruin
#

kinda getting scared it'll take my job

lean lance
maiden violet
#

It can do some stuff super fast

#

But it’s pretty much slow in anything complex which a human with enough experience can do with relative ease

chilly merlin
lean lance
chilly merlin
#

Okay leave him

lean lance
#

That is all I meant 🎈🙂

chilly merlin
#

Im not arguing but if it was someone else that was targeted'

calm basalt
#

I'm here

teal ruin
#

How does malware interact usually with C:\Windows\System32\Tasks ?

#

okay I think that the malware might be running on a schedule where it only sends something through the network every specific amount of time.

#

is what i'm kinda figuring out

#

I want to figure out what sort of information it's sending idrk how

lean lance
#

Throw the malware in a malware analysis environment

teal ruin
#

oh triage got back

#

finally

lean lance
#

Can be slow yeah, depending on load

teal ruin
#

Oh yeah, this is my first time scanning malware so idk exactly what it's doing but it looks like it messes around with Chrome (I don't have chrome so idk what it really did) then it creates fake Windows processes or something like that which are still actively running on my PC over a year later

#

if the primary goal is just to grab stuff from browsers it didn't work because my browser autodeletes all cache when I close it. and It's not chrome

#

idk what the point of the fake processes are though. and there are quite a few of them

lean lance
flat garnet
#

spawning a few legitimate processes before payload sometimes helps to bypass heuristic analysis

#

i used to do something similar before yet good old time-based process injection works bettee

#

generally, any virus needs to show av it's doing something legitimate for the time it runs in av sandbox, that's the point of all this

crisp star
#

@flat garnet If you want you can send the file and I can have a look.
And depending on the malware, there are some anti AV and sandbox technique. Some malwares also check for specific process that are being run. For example if the malware detect that you have Wireshark running it's going to terminate itself.

flat garnet
crisp star
#

So you also enjoy where 90% of TPs are just phishing?

flat garnet
crisp star
#

Oh yea PUA is also a big thing every time

#

Man I wish to have more sohpisticated malware attacks.

flat garnet
#

haven't had any interesting case for ages

crisp star
#

Our IR gets all the cool cases with ransomware or compromised assessment. Unfortunately these people calling us are not our customers and only need our emergency help.

formal terrace
flat garnet
#

i'm doing everything: configure network services, play games, rice arch linux, chit-chat, but not doing my job cause there is nothing to do basically

crisp star
#

Also playing games is going to trigger XDRs 90% of the time sideeye

flat garnet
#

lmao

crisp star
#

Switch to a company offering SOC as a service. You will see a lot of cool attacks. And working on night is also cool.

lean lance
#

Lets keep the channel on topic lads 😄

teal ruin
#

I'm gonna get a headache. There are 2 different csrss.exe processes active. 2 different PID's but when I use Volatility3 to check on them with Dlllist etc. They look pretty much the same to me but they are different. They all use only System32 dll's but the ones they use are slightly different. When I do stuff like Vadinfo they still look about the same and PsScan just straight up freezes the command prompt...

lean lance
#

Well csrss.exe is also a legit Windows process. Are you sure it's ran by the malware?

#

And are you just trying to investigate or trying to make sure your PC is ok after you said you had malware on your PC for over a year?

#

Because if it's the latter, just reinstall Windows mate. There is no knowing for sure what the malware has done and in how many places it could be

teal ruin
# lean lance Well csrss.exe is also a legit Windows process. Are you sure it's ran by the mal...

I'm not sure if it's malware. Which is why i gotta figure it out. its weird that there are 2 of them. just like with stuxnet from what i've seen you would have an extra lsass.exe. There are also svchost.exe processes without the "Host process for Windows Service" description as well as no Build version, and a file path that just says [Access is denied]. while all other svchost.exe are fine.

#

Which is annoying because I can't figure out where it is running from to remove it etc.

#

(all other svchost.exe show the regular C:\Windows\System32\svchost.exe path)

#

When I was learning cybersecurity I remember a fake svchost.exe was one of the examples to look for when scanning a Memory dump

#

but this one is weird and the basic tools I use and memorized just don't work to tell me what I need

#

because something is protecting it or blocking me from doing so ig

#

idk

#

Both csrss.exe processes also show only [access denied] and show no information. When I look at them from memory dump I don't see anything weird except for somehow they show as having a parent process that doesn't exist

lean lance
#

Legitimate svchost.exe should be digitally signed by Microsoft. Lack of signature or description is def suspicious

teal ruin
#

There is also an extra fontdrvhost.exe when I assumed there shouldn't be

lean lance
#

I assume you also checked with Process Explorer?

teal ruin
lean lance
#

Any of them trying to connect to sus IPs?

teal ruin
#

Volatility3 and Process Explorer

teal ruin
#

no vps

lean lance
#

suspicious IP address

#

Okok

#

I personally have never seen the <Acces denied> on such processes before tbh

#

Perhaps @hoary nimbus or @quasi berry have any idea

#

Don't think they're online now tho

teal ruin
#

I think i watched a john hammond video where he said your PC should have an Admin user and you should do everything on the regular user. but i can still run as admin on regular user and never had a problem doing anything.

#

i don't think i even set it up right lol

lean lance
#

I don't daily drive Windows for over 7 years orso, I only hack it 😄

teal ruin
#

Nothing else says [access denied] other than wininit.exe and Services.exe

lean lance
#

But the things you're describing around details of the processes and lack of signature def sound suspicious

teal ruin
#

Oh yeah I didn't even mention the svchost.exe doesn't say "microsoft corporation" either

#

the weird ones

#

there are 4 weird ones. One of them is NT AUTHORITY\NETWORK SERVICE instead of NT AUTHORITY\LOCAL SERVICE

#

one is NT AUTHORITY\SYSTEM actually

#

there are a few that are on system and network service that are normal too nvm

lean lance
#

svchost instances running as NT AUTHORITY\SYSTEM is normal, the lack of signature and details is weird though

crisp star
#

Did you install an application from an untrusted source?

teal ruin
#

I rushed the download I think

#

I did see there were 2 and thought the one I downloaded was the correct one

crisp star
#

So it was already over a year ago since you installed it and you start to worry about it just now?

teal ruin
#

Yeah i'm lazy on my gaming PC, I would Virus total everything usually or quick scan on Windows defender occasionally. But Yesterday I did a full scan which showed the problem

#

showed up as a AsyncRAT on virus total

#

and something called Multiverze on Defender

lean lance
#

Like I said, just reinstall Windows at this point

crisp star
#

Yea do a fresh installation at this point.

lean lance
#

Do the analysis in a VM or Malware Sandbox

teal ruin
#

ik, I set up a ton on my PC which last reinstall took over a week to set up again so i'm kinda tryna pull my hair out finding the malware and removing it manually

lean lance
#

It can be spread out too much in places you would never look. It's not worth the risk mate

#

It can inject into legitimate processes and will not even look as sus as some do right now

teal ruin
#

isn't it possible to figure that out?

lean lance
#

Just don't download and run crap randomly

#

I mean sure, but then again it's like a needle in a haystack. Is it worth the risk? One thing you missed and your still fcked

teal ruin
#

ig, I thought you would be able to find everything through a memory dump

lean lance
#

I mean, sure, you can go through that route. But malware can also be in slumber.

teal ruin
#

What I learned while doing my certs is 1. Dump memory 2. check with Volatility 3. find anything connected to anything suspiscious and remove

lean lance
#

You wanna memory dump every day?

teal ruin
#

No sir 👍 perhaps im just coping with the reality that I gotta set up everything again after a reinstall

#

other part of me is like "nah skill issue figure it out" so i've been at it for 20 hours already

lean lance
#

Always do your checks beforehand when downloading anything remotely suspicious

#

I've been there too