#👥・help-me
1 messages · Page 16 of 1
its up now?
okay
i had a similar issue so for that i tired to installed a different os and than clear that and install arch
and it worked
Where can hackers find hashes?
Because I want to know if they can fine my Microsoft hash
Dehashed
@rotund delta ?
You didn't just was confused 😭
oh lol yea it was just random felt like replying
i think i know you
what should i do to learn hacking
Potentially
I think I blew up your apartment
I have no idea
What your talking about 😭😂
Nvm you don’t get the reference
Did you download it?
Hi becck
Is okie
Anyone know anything about bios stuff? Because I tryed resetting mine and there’s no wifi network’s showing up. Like it’s not even saying “no networks found” in gray letters. It just shows blank.
Yes
Wdym networks found?
On windows or??
Windows 11
Yes sorry I forgot to specify that
I dmed you what I’m looking at rn
@chilly merlin I need your help
?
its like asking a beggar for change
but shoot it
Lol
wat are u asking man
@chilly merlin just reinstalled windows 11 on his customised laptop.
Windows can't find a driver for his pc and I can't find the model of his pc since its customised
hmm
I can't get drivers for a pc idk
what driver
does it miss
Network adapter
Miss?
download nettwork adapter drivers
i mean cant find
Idk if its this https://www.intel.com/content/www/us/en/download/727998/intel-network-adapter-driver-for-microsoft-windows-11.html
This download record installs drivers for Intel® Network Adapters using Microsoft Windows 11*
so u gotta have windows version
try typing winver
in cmd
It's crazy for a laptop
what crazy u foound
it quite normal
For a laptop not a desktop
Atleast not where I'm from
i said right
peeps here use 64 ram for lappys
🥲
must be this
Ayoo
find a yt video
🚮
why
I try doing stuff without tutorials. Trying to train myself
good work
@chilly merlin https://youtu.be/SGdN-bzs5oc?feature=shared
In this video you will learn how to fix network adapter missing from device manager in windows 11.
¯_(ツ)_/¯
pass to the guy
@chilly merlin
¯_(ツ)_/¯
¯_(ツ)_/¯
KORDHELL - MURDER IN MY MIND (RIAA CERTIFIED PLATINUM)
LYRICS -
Jacking is the sht in the 9 4
Pack my nine millimeter cuz I ain't finna go
out like a busta ass ngga and just lay down
Imma run up on a n*gga and shoot my nine with the 15 rounds
Got Lil E on cloud 9
Murder Murder in my mind
Artist links - https://linktr.ee/Kordhell
#kordhe...
@chilly merlin give a ear
My ears bleeding rn
by song
?
Yeah
¯_(ツ)_/¯
its good
u should see my phonk playlist
I'll listen when doing CTFs
Gimme
Okie
@maiden violet @chilly merlin https://youtu.be/sEetXo3R-aM?feature=shared
Provided to YouTube by Universal Music Group
Diet Mountain Dew · Lana Del Rey
Born To Die – Paradise Edition
℗ 2012 Lana Del Rey
Released on: 2012-01-01
Producer, Associated Performer, Drums, Additional Keyboards: Emile Haynie
Associated Performer, Vocals: Lana Del Rey
Producer, Co- Producer, Associated Performer, Keyboards, Guitar: Jef...
Official audio for "One Of The Girls", available everywhere now: http://theweeknd.co/TheIdolEpisode4
►Follow The Weeknd:
https://twitter.com/theweeknd
https://instagram.com/theweeknd
https://facebook.com/theweeknd
https://tiktok.com/@theweeknd
https://triller.co/@theweeknd
https://story.snapchat.com/@theweeknd
https://www.theweeknd.com
#TheWee...
give a ear
its good
balanced
Playlist?
nah jus individual songs
Not a fan on the weeknd
weird
its good though
I think he's demonic >>
agree
hello you guys know where i can search for scientific studies which are mostly from trusted site
cuz just typing it on google won't bring that much good result
Not what we help with, but what kind of scientific studies
mostly about tech research and neuronological studies
1 . The BRAIN Initiative
2 - Coursera Neurology Courses
3 - Neuroscape at UCSF
4 - Labouré College Neurodiagnostic Technology
5 - National Institute of Neurological Disorders and Stroke (NINDS)
6 - Coursera Neuroscience Courses
7 - OHSU Brain Institute
8 - Atrium Health Neurosciences
9 - Institute of Health Sciences Neurodiagnostic Technology
10 - Alvin Community College Neurodiagnostic Technology
I hope this helps
and on technological advancement ?
I am looking for my first job in cyber security, what do you think I should pay attention to?
Can anyone tell me what a 4978 id means on event viewer?
4798(S): A user's local group membership was enumerated - What does this mean in laymens terms, im not IT well versed in IT?
I didnt turn on my PC and I checked the event viewer logs and saw that event id at a certain time. Not sure if someone logged onto my PC and what does it exact means. And what should I check to see what was done?
anyone helping?
1. Check for User Logins:
Open Event Viewer: Press Win + X, then select Event Viewer.
Navigate to Security Logs: Expand Windows Logs and click on Security.
Filter Logs:
Click Filter Current Log on the right side.
In the filter window, enter 4624 (for successful logons) in the "Event IDs" box.
Click OK to apply the filter.
Look through the filtered events to see if there was a logon around the time of Event ID 4798.
2. Check Recent Activities:
Filter Security Logs:
Follow the same steps to filter logs, but this time look for other relevant event IDs like 4648 (logon attempt with explicit credentials) or 4672 (special privileges assigned).
Review Events: Check the details of these events to see what actions were taken.
3. Check User Accounts:
Open Local Users and Groups: Press Win + R, type lusrmgr.msc, and press Enter.
Review Accounts: Check for any new or modified accounts.
4. Review Security Settings:
Check Audit Policy:
Open Local Security Policy by pressing Win + R, typing secpol.msc, and pressing Enter.
Navigate to Advanced Audit Policy Configuration -> Audit Policies.
Ensure that auditing for "Account Logon," "Account Management," and "Policy Change" is enabled.
4798(S): A user's local group membership was enumerated
Indicates that someone or something checked the local group memberships on your computer. This means they looked at which groups your user account belongs to, which can give insights into what permissions or access rights you have.
In short, this event logs the action of enumerating or listing out the local group memberships of users on the system.
chatgpt?
But yes, It saves some time. I do audit it all
Because it does hallucinate sometimes 😄
oh my bad
i forgot how to use Discord
😂
Where did you learn cybersecurity stuffs bruh pls..could you refer me ?..
Does anyone have advice or guidance on getting a job in cybersecurity? I have most of the practical skills, including certifications, but I lack work experience and can't even seem to land an interview or internship. I'm asking around, so any advice is greatly appreciated. For context, I'm currently in college pursuing my BA in Information Technology.
tryhackme
hack the box
over the wire
udemy courses
Tryhackme and Hackthebox are good for hands on learning.
try getting internships first and hope companies would like you to stay for longer
hella books
Any idea on where to apply for internships? I've been trying indeed with no luck
and sadly its prefferrable they be remote internships do to location
remote are hard
I had hard time myself, but I had one this summer and they contacted me after it and offered me a position, just need to pass interview
@shell sinew need to talk something in dms
hmm
no offense if u not intrested
go on
need to add
The thing is I did not turn on my PC at that time. What I am trying to ask is can your PC do this by itself? I did everyhting like you said and I'll post the screen shots
@chilly merlin @lean lance How do I post screenshots of what I found?
send to dms and copy link and paste it here
hi answer pls
not my expertise wait for somone to answer
What is DMS?
Direct Messege (DM)
Do I add him or how do I create a link to view DM's?
@lean lance https://imgur.com/UnGmMn1
I want to learn basis to advanced networking please suggest me a lecture
It seems to happen at system boot, It might be part of a security program you're running.
Even things like remote administration tools and such can do some of those checks on boot
Like Teamviewer, Anydesk etc
I'll send you a small step-by-step in DM to try and figure out what triggered the event
Thanks
Ok thx
@chilly merlin both ways didn’t work 😦
I think I need to just download the bios again on the USB?
¯_(ツ)_/¯
Bruh
we did what we can
Ik ik
u wanna blame us
I appreciate the help
No
¯_(ツ)_/¯
I don’t blame you
find another solution
I blame digital storm for building a shitty laptop 😁
hmm depedns on os
we use
kali linux
.sh
try googling im at work
ok papi
Lmao
bother some one not me u have been warned.
I'm working on some key encryption HW does anyone know what these error codes are/ where I should start looking to fix them
pem -pubout -outform PEM
Could not read private key from alice_privatekey.pem
408C1243147F0000:error:1608010C:STORE routines:ossl_store_handle_load_result:unsupported:crypto/store/store_result.c:151:
408C1243147F0000:error:1608010C: STORE routines:ossl_store_handle_load_result:unsupported:crypto/store/store_result.c:151:```
I generated a private key and I'm trying to encrypt some text using openssl, but it can't read the file that I encrypted
"Hack" what in specific
What's gpg?
I can show you
GPG (GNU Privacy Guard) is a tool used for encrypting, decrypting, and signing data. It provides strong encryption using both symmetric and asymmetric keys, supporting public and private key pairs.
If you have android you can get an app called openkeychain
GPG keys work by using a pair of cryptographic keys: a public key and a private key. The public key is shared with others to encrypt data or verify digital signatures, while the private key is kept secret and used to decrypt data or create signatures. When someone encrypts a message with your public key, only your private key can decrypt it, ensuring secure communication. Similarly, signing a message with your private key allows others to verify its authenticity using your public key.
That sounds really cool
Yeah that would be great! Would you like to show me right now or some other time
I'm cool with either
Ahh okay I got you, thank you so much
Lmk what you think
Bet bet
107Practice Exam A - Answers
A69. A company is in the process of configuring and enabling host-based
firewalls on all user devices. Which of the following threats is the
company addressing?
❍ A. Default credentials
❍ B. Vishing
❍ C. Instant messaging
❍ D. On-path
The answer I chose was On-Path Attack. But the actual answer is Instant Messaging. Can someone explain how a host based firewall would not apply to On-Path attack.
I think I might have realized the answer. MITM (on-path attack) is concerned with two devices communicating with each other and someone sitting in the middle of that conversation. The question was not addressing communication of devices it was just simply asking what a host based firewall could be protecting such as an instant messaging application. Whereas on path attack would be prevented with encrypted traffic
I have a problem
||I code in JavaScript||
Its not a bios problem (if you havent already reiinstalled it) its a driver issue
@timber spoke You still need help??
I’m taking it in to my local repair shop. Iv been trouble shooting all day
Ohk, But I am sure its gonna be something simple.
Probably will be but they will get farther then I will lol
I’ll let you know what happens
Hi
Hello
Okay.
What are you doing brother
So about deterministic password generation
A major drawback I can see is problems with data breaches, need to alter the input string then
For better security, ditch the predictable input strings—they're an easy target for attackers. Add some randomness using a cryptographically secure random number generator, or better yet, use something like Argon2 or bcrypt to beef up your password generation. These tools are built for security, so you'll get strong, unique passwords without worrying about weak links. Keep it simple but solid.
I want a passwordless experience though
So I don't have to remember or store them anywhere that could be taken or lost
I suppose it's not ideal from the security standpoint
The experience is sort of like biometrics, except more easily hacked
Of course I use different strings for different accounts
How could the attacker get my deterministic password? I thought they would have to try all variations of strings which are enciphered and the resulting hash is also enciphered, so I wouldn't think it'd be easy to just guess it, and they also don't know the length of my hash
Or is the problem in the resulting password itself?
The problem is the fixed relation to input > output. Same input will always give the same output
You need proper randomness and added entropy
I'm a bit nooby, could you please explain how that causes a security risk? I know it's obviously less secure, but I don't understand how exactly it would be exploited
To note, this is intended for personal use, not enterprise security
@lean lance
The problem lies less in the resulting password itself and more in the predictability and lack of randomness in the process. Attackers don’t need to guess the cipher or hash if they can figure out or guess the input. Once they have that, the deterministic nature of your process will give them the same password you’re using.
How would knowing my input give them a password?
I didn't think that the ciphers were useless
how's it going?
Oh, you mean if they had access to my password generator?
Yes, they would need to know how your password generator works, but security through obscurity (relying on keeping the method secret) isn't a strong defense on its own. If an attacker gains access to your code or reverse-engineers the process, knowing the input would be enough for them to generate the same password every time.
Yeah that is true.
I just hide it encrypted on my cloud
Which I guess isn't that good
To mitigate this, you need to introduce entropy (randomness) into the process, so that even if the input is known, the resulting password is unpredictable. This could be done by adding a salt or secret value, or using a more random input.
everything good? @lean lance
That would unfortunately defeat my purpose of not having to store or remember passwords
Hello
Is your purpose to learn and create, or just a bit paranoid to use any password manager?
Chillin, wbu
thinking what to do with my time
maybe owasp top10
or thm rooms
The answer is always learning in that case
😄
I've had my password manager database (which I stored on a physical USB) corrupted, and I also need to have my passwords constantly updated and available across different machines. So I figured that deterministic passwords through this generator were a viable alternative
I guess opting for something like NordPass would be a more secure alternative
I used to have a KeePass instance, but I switched to self hosting Bitwarden
Why not just use a normal passwd manager?
Because I want to have access to all my accounts simply by having access to my Google drive
Though bitwarden looks good
That's bad opsec
I love Bitwarden, I can access my stuff anywhere. And everything is stored on my own server, which can only be accessed via Wireguard
But yeah a bit more advanced if you don't know anything of self hosting securely
Plenty of good tutorials on YT though, if you wanna go down the self hosting rabbit hole
Even considering the generator is encrypted and the account is behind MFA?
Of course it does present a risk still
Well I mean, it's something for sure. But MFA can be bypassed. And encryption keys can be guessed.
I personally don't like having my stuff on servers I don't own, but that's me
There is a risk with everything
Security is always in layers
Thanks for your help
No problem 🙂
What's up
You should probably try telling them more about your situation
with what
@quasi berry I need professional help.
My friend had turned Bitlocker turned on on his new pc and booted into a live ubuntu session. He claims he didnt change any settings. He rebooted into windows and it was asking for a bitlocker recovery key. He didnt set it up, it was given to him with the bitlocker turned on.
@lean lance
Wait, he turned it on but also it was already turned on? A bit contradicting
Yeah you get a bitlocker recovery key when you enable it; did he not store the key anywhere?
No, he's saying that his friend turned on bitlocker yet he didn't setup bitlocker recovery key which you don't set that up yourself, that's supposed to happen when you enable bitlocker.
His text was just difficult to convey at first
Ahh, yeah now I get it. Thanks
So basically your friend had his bitlocker ON usually it gives out a recovery key. When you boot in to your ubuntu session and after leaving it, boot back into windows what bitlocker is doing is asking for additional authentication as it may thinks you may have have tampered with the drive while in a live ubuntu session. I think it can be solved easily if you try to access the same microsoft account from another device and find the recovery key
Hypothetically speaking... are yous allowed to delet people's acc if they do something bad...
What do you mean, delete where
Like let's say a person did something bad on instagram or tiktok they posted stuff and make rumours. Are yous allowed to take down there accounts
No, you are not allowed to decide the fate of someone's account on an external platform.
You can report the account to the platform in question
Oh alright just making sure..
do you think it is viable to seek an international relations degree in respect to careers in cybersecurity or government work?
What about regional studies (i.e. Russia focused studies)?
Depends on your situation where you wish to build a career. if you’re open to anything then internationally accepted certifications are recommended. If you are trying to find a niche(russia) then you have to build your learning around that niche.
Apparently, he didnt set it up.
HIs mom gave it to him as it as and she doesn't know anything about computers. So its a dead end asking her
I just told him to reinstall windows
exactly. i asked him if he did. But he said he didnt even open any file maanger. Only trading view.
@lean lance : )
Well yeah, in that case reinstalling is the only option. No key, no party @chilly merlin
Yeah but theres still one shot tho
The recovery key might have been saved in his microsoft account
Ah yes, that's a fair point
Would you be willing to tell me more about how I should approach that? I have a passion for political science related subjects so I would like to incorporate that in my career, though I am not sure yet what I want to do with it
I am in Eastern Europe, so Russia studies are also available and relevant
Get familiar with laws and regulations, Regional IT practices and standards
Ethically speaking
Could you tell me more? I am still at an early stage of building my career
Working on the hints is much efficient to learn things then receiving the answers directly. Here’s another hint: Find a Mentor that you could really trust.
That's a good idea, thank you
Hi, I'm looking for someone to give me a hand with some facebook scraper, I have to collect phone numbers of a particular location.
Take a look at the #📜・rules section. And reconsider your request.
So it was a drivers issue they said but the one that I downloaded wasn’t right for the model. So you were correct about it being the drivers. I just didn’t install the right ones for my model 😂
It’s fixed now but thank you
Okay
So you can access the internet now right? @chilly merlin
How much did you spend on it
Wait what?
Hello Ai engineer from india?
??
added kali repo and install metasploit framework on my mint sys. I run it after it was done and it showed an error and then told me to use "bundle install --gemfile /usr/share/metasploit-framework/Gemfile but i also got and error of ruby required <3.2 >=2.6, i then tried to install ruby 2.6 but idk how to
@lean lance
Hmmmm, yeah adding Kali repo's on different OSes is prone to some issues most cases
I'd suggest setting up a virtual machine with Kali, removes alot of hassle and possibly breaking packages
Did u edit / etc/ sources.list
Lol i tried adding it to debian and metasploit worked just fine
Nope
U meant /etc/apt/sources.list
The prob isnt the repo
its metasploit
Yeah, Kali is debian based.
Mint is ubuntu based
Less prone to errors mostly
Yeah exactly
Setting up a VM is definetely a better option though, avoid messing up your main system
Vm 💪
can i add a kali sys without the gui just cli
Question is why 😄
I dont have enough processing power : (
Bro don't want peace
😄
Kali runs like an app in windows
I dont like gui's
Fair, I prefer CLI over GUI too.. Maybe I'm just oldschool
Who are these people
Depends though
Sometimes GUi just saves time
Cli
👀
Haven't run Windows as daily driver for over 7 years
I just exploit the shit out of it
1.10Ghz
Oh dang, that must be old af
Yeah VM will be a pain on something that old
actually it isn't, Lenovo ideapad 11lg05
I would just:
2019 i think
its the main reason i left windows : )
Ikr
I don't know what your budget is, or your situation. But maybe a small VPS or 2nd hand laptop / pc with a bit more power
Also very viable option yeah
Cheap and quite powerful
It beats your celeron 😄
Atleast it doesn't cut the cookie pockets
Too young to be asking for a powerful pc. But ill try asking soon
Also Raspberry Pi's are great to learn from, for some fun projects 😄
10?
Fair fair
👀
maybe still in womb ¯_(ツ)_/¯
Yeah, in some areas people think of you as a kid even when you 17
Some people still call me a kid, I'm 27 :/
Uncle
nahh, you prob like 22-28
😂 dont make me luagh
Guess that is a compliment?
51 yr olds look like this ^^
Ayooo
I need proof
Who can teach me basics abt TLS UDP TCP and sip protocols
Hello guys. I am new here. I wanted to know if there is someone who already has a job and can take a look at my cv and tell me what I am missing. I am still in university.
@patent rampart
Fr
Guys can anyone guide me to get started in pentesting?
Sure, what do you wanna know
Check pins once
@lean lance point them to pinned messages why the hassle
Already answered theses type of questions
Recently I got the try hack me course.
Wait until they fuck around
Seems like you are already on the right path then
Bro how to stay motivated?
Really wanting to learn it I guess
Some peeps come for help . Help them and becareful on all times they might be trolling sometimes not everyone
Oh yeah, I can quite easily scope them out
Luckily I got Discord moderation experience 😄
Jus saying
Sometimes I feel like. Am i able to do it
Anyone is able to do it, you just gotta be persistent and really interested in the field.
Should I've to cover the entire networking thing?
Yeah
Entire might be overkill, but network understanding is defo a key part
Click the Pinned Messages at the top of this channel
Ohk
Hmm
Some good resources to know where to start and what to learn
N CEH is still in demand?
He got a YouTube channel??
Yeah ik that guy. He's to good
No, coffee

Ok guys thank you. I'll contact you if I'm stuck
Why not you?
🙂🙂
Not good
Sup
Hey there's a guy who want a resume review can u do
Sure. Feel free to send it to falconspy@hackthebox.com
Hi
Alr
Ill let him know
Ty
@void sphinx
Really good, you should check out #💬・old-gen-chat if ur just looking for friendly convos
Yes. I didn’t spend anything on it. It was just drivers so they did it for free
Iv done businesses with them before so they knew me
how much gb ram would be ideal to run kali linux?
2 or 4 or 8
Unsure if this is the right place to ask, but does anyone have experience with a M3 Pro Macbook for cybersecurity? Im thinking of either choosing between upgrading to mac from a 1650 ti laptop or going in on a roughly 2000$ Desktop build for gaming/cybersecurity
I'm not a mod here
Meow
yo falcon how you feel about the new linux kernerl update?
@dm please
Nah, open a #📩┃ticket
I don't know anything about it. Been away on business and I don't really follow that stuff half the time. Got 2 jobs and a family so whatever free time I have after that is gaming, cert or side project
also to clarify both the m3 macbook pro and the desktop would share the same budget, I also prefer windows but would not mind the learning curve of mac os
You can do CyberSec on a toaster laptop, doesn't really make much difference. I'd look at your gaming needs.
who here know a great course for digital forensics? I am way to invested to become great at this skill I want to know more!
Sup was working
Here for help!
Answer
Hiiiii I'm not an expert on this but since I haven't noticed anyone responding I will respond according on what I understand from some these concepts and If someone more experienced than me notice I'm incorrect, can help me explain it a little better.
What is a network
(From my understanding) a network is a kind structure of connected devices that cam communicate with each other within a local or wide area. For long distances, they transfer data through cables made of copper or fiber optics and for some shorter distances they use frequencies. Most of this of these methods are translated into a digital format of data called binary which then are reinterpreted by any devices that recieve it. But in order to create a universal form of communication between devices along with their security features, protocols are invented
What are protocols
Protocols are a set of rules In which data packages are prepared for the process of communication. Some of these are combination of other protocols. Some are less secure than others and some are already deprecated but still being used because old devices still up and running around.
It will continue...
Ahhh okay, noted. Im likely going to go for the desktop then. Thanks!
TCP/UDP
This protocols determines the way that data packets are being transported and one is older and less secure than the other.
UDP (User Datagram Protocol)
The UDP protocol is a connectionless protocol that doesn't requiere a receiver device to be up and hearing for data since there is no rule that ensure data receiving. So the data sended through this protocol is like a MP15 mindlessly shooting hopping that his target recieve some bullets.
This protocol has been invented before TCP and has a set of rules that made it appropriate for some stuff like gaming and internet voice chats.
TCP (Transmission Control Protocol)
This protocol Is very different from the first since It tries to ensure and confirm a live collection between devices and uses a method called three way handshake that ensures the connectivity. This one is very strict and will make sure for every packet to reach his destiny and this can be done by receiving and acknowledgement data package communicating that the packet has been received.
Hmm
Cause TCP has error checking and can resend a packet
UDP doesn't check so everything needed for delivery is in the packet already
If through the TCP protocol, a data package isn't received or duplicate, it will fix that
Making it more stable than UDP
Since UDP doesn't really matter duplicate or missing packages
Yeah if sending fails in UDP, it's just gone lol
TCP is more stable because has error checks and UDP don't. Making it more smarter than UDP
I hate when the calls on sip hang up out of nowhere
some stuff like video and audio conferencing doesn't require TCP cause it won't be doing all those same checks
Games and calls doesn't use TCP because they make connections very slow
Aright so for phone calls tcp best
You will receive all the data packages, yeah but imagine receiving a very low rate of data
UDP for audio and video is faster
For bigger streams of packages that doesn't requiere integrity, UDP is best and that's include:
- Videogames
- Voice Chats
- Video Calls
- Audio broadcasting
Spot on
For packages that need full integrity and security you may use TCP:
- Web sites
- Text chats
- File transfering
I'm not an expert on this but I hope it helps
UDP
- UDP is much faster than TCP
- UDP leaves the application (user or soft) to decide if there is any control over how quickly packets are sent
- UDP does not reserve a continuous connection on a device as TCP does
- UDP doesn't care if the data is received or not
Your nick is a QR code??
Shit this is so helpful better than my professor
it not a qr... it's a bar code...
ur fine
My mind got blasted by giving all these explanation HAHA
You did fine
I was learning to read bar codes by myself haha
It seems pretty possible, like morse code or binary
I'm glad you understood well
TCP
- Guarantees the integrity of data
- Capable of synchronising two devices to prevent each other from being flooded with data in the wrong order
- Performs a lot more processes for reliability
- Requires a reliable connection between two devices. If one small chunk of data is not received, then the entire chunk of data cannot be used and must be re-sent
- A slow connection can bottleneck another device as the connection will be reserved on the other device the whole time
- TCP is significantly slower than UDP because more work (computing) has to be done by the devices using this protocol
hope it helps a bit
Gues
Guys
What does
Setting Interrogation Succeeded
Voice Call Forwarding
When Unreachable
Forwards to +1647700xxxx
Enabled
Bro one of them is enabled
And idk this number
Does it mean I’m being wiretapped by the feds
Hello, I joined this discord after a prompt from the video of the owner of this discord, it was a video about how youtube accounts are hacked, I am interested in whether most of the accounts that are hacked today, as far as youtube is concerned, is actually only because they do not have 2FA?This dont make sense every one have 2fa... or insufficient account security? because I personally think that it is not possible to steal a gmail account whith a lumma these days if it is sufficiently secured.Logically, I couldn't find any answer to it except rat. Also, today it is not even possible to upload cookies using selenium and automate the process of removing 2fa and the like, and even if the victim has rat in the computer, the hacker has to wait until he is far from the computer, logically I only knew that really most of these people do not have 2FA, can someone confirm or refute it?someone experienced?I can also send a link to the video where it was discussed.
ohk
Huh?
Can anyone help me? A few things. I’m looking to go to school to study something in the IT sector. I’m not sure what exactly. From 15-18 I worked as an MIS help desk. 18-30 I was in the marine corps. I fell off a lot of things. I guess my first question would be what kind of machine I should use. I do have an iPhone and Apple products. I do like to game so good specs for that would be important. Movies and tv shows I watch too. I’ve thought about making a plex server using real debrid. I’m sure I’m going to have to learn coding so a system that’s capable of windows Mac and Linux might be cool. I know you can run virtual machines or boot camp I just need to be able to switch back and forth between them easy.
And I guess to know what classes and certifications I should take
I would look into a compsci course at a local community college. For the mechine I would get a Omen laptop (you can get one at bestbuy) Linux Mint (Cinnamon) (If your starting use the mint distribution). Start learning Python as your first coding language. After you learn Python try to do some Hackthebox’s and capture the flags. Not sure about the plex server. Idk about that lol.
If you want to switch back and forth for different operating systems I would make the laptop a hybrid.
Certs: CompTIA A+
Basic Cert to get your foot in the door when applying for internship level jobs ^^^
And yeah I think that’s about it for my knowledge.
What do you plan to pursue? The IT sector is big and there are a lot of roles. This can range from sales to become a technician or even a specialisation.
I agree
Thank you both for your responses
No problem
I don’t really know what to pursue because the sector is so vast. I do feel like AI is going to be a huge factor in the foreseeable future. With that I feel security is going to be important. Also I have an idea that I think will work that’s essentially similar to Ready Player One in the sense you can go to school and make better choices in life. So I guess making like a VR/AR type game
Game development then?
J think that would be more of a hobby
Have you watched the first episode of Cyberpunk 2077?
Is that the type of virtual reality game your talking about wanting to make?
Like a brain dance?
I’ve never looked into game development before
Same
Cybersecurity makes more money anyways for the average person lol
I think they start out at 100k a year at least?
Eh somewhere in that range
Picture you put on a whole haptic system and then let’s say you want to go to school to be a doctor. You can get live simulation on operating feel everything you can mess up horribly but then you learn from the mistakes
Never watched cyberpunk 2077 but I want to now.
So I have a laptop right now that has Linux mint on it and I know I probably added something wrong because I just copied and pasted things into terminal
I’m trying to wipe the whole thing and restart fresh. Problem is it won’t boot from the usb now and idk what to do
I assume you know how to boot from USB?
Yes
The problem is whenever I try to change it in the bios it saves but it bypasses the usb
I think I ran a line of code wrong because I’m not too familiar with Linux I was just copy and paste different things without really knowing what the hell im doing
I guess that’s how I learn best though
I find a problem and I come up with a way to solve it
So I guess to answer that if you look at my comment above whatever field where I can repair things on the machine is what I want to do. Whether it’s hardware or software. And also cybersecurity. If there’s anything I can do that online I really want that.
So an IT support then?
I remember when AOL first came out I snuck into my aunts computer room and started messing around with keys and then when that didn’t work I opened it up unplugged everything and bypassed the password for a good month of 5 hours straight with dial up. Yup I got that ass whooping of a life time but they gave me the computer and I just started tinkering and figuring things out.
I’m not sure exactly what IT support does but if that’s what you gather from what I’ve described then yes
What did you type. Maybe it can be undone
Soooo much
It’s all for trying to get plex on the laptop
It didn’t turn out too well for me with that tbh
They have a plex player yes.
When I put in codes I know I got errors so I just tried another and another
I can install it in 2 minutes. Where did you get help from
Again like I was 8 years old trying shit until it works 😂
Put it codes where?
Into terminal
Now whats the issue
That’s what I’m trying to do
Its simeple . just download the .deb file from https://www.plex.tv/media-server-downloads/?cat=computer&plat=linux then dpkg -i ./<package_name>
I rather use Jellyfin
That part I have. I don’t know how to link my real-debrid account to it
But jellyfin you can’t put on Roku tv plex you can. And I think plex also can go on Apple TV. I’m trying to help my family out with easy setup so that way they can watch whatever they want without having to ask me they can type it in or they see it they click it
You can put Jellyfin on Roku afaik
But for novice users, Plex Better ye
Why do you prefer jellyfin over plex?
Do you have to pay for jellyfin I can’t remember
Well, for one, Jellyfin is open source
Reason enough for me
I don't like the requirements of using their login and servers etc
So being open source you can change what you want correct
Forgive me I haven’t been dealing with computers like this since 07
And everyone can contribute and fix/add stuff
NGL, I ran a quick search if this can be added to Roku and Apple TV and it can so yea help me set this up please. As long as I can is my real-debrid I’m happy. I really would like to be able to have thumbnails of them and also a search.
I'd suggest looking up on YouTube, gonna be alot easier to follow then some text instructions
Ok thanks
Jellyfin is simply a "Streaming Channel/App" on the Roku device, Jellyfin backend is on your server/pc
What about Kodi?
I remember when Kodi was Xbox media center 🤣... Im not sure if Kodi is available for Roku but I know you could always flash a fire stick and install Kodi on it.
OG stuff
Oh he wanted smth for a Roku? 😭 I wasn't paying attention
All good, you got alot on your mind. Free pass
Math usage and level in cyber security
Ik it depends on what you aim to do but i wonder what is the general level requires
Yea man, good times.
heya all, i was wondering if anyone one could point me in the right direction for some learning material (i am still in the basics 😅 ), i have a class that is covering an introduction into cryptography. in addition as part of that i need to make my own small puzzle for the class, but it must be a rudimentary cypher, i was also hoping to pick peoples brains on ideas for unique cyphers that would bring a new aspect to the class(to find something that is a little less common😋 but still fits the parameters of rudimentary) just fishing for ideas 😋
u got this trappy
😬
Sure, I've learned from various ctf events. I can give you some beginner ctf resources that you could use to learn how to solve various crypto challenges, from there you could combine a few to create your own puzzle. There's also https://www.dcode.fr/en that you could use to help solve and create various cipher challenges.
thank you very much, yes please i would appreciate that, i have played around a little bit with the dcode a bit but i will certainly be using it to assist me
https://mctf.io/mini-zine code=mixed . Solve 5 of the 6 challenges and get a month of free access to the entire Antisyphon Cyber Range. This is from Black hills Info Sec. But this assumes that you can solve some basic ctf challenges... If you need help solving the initial 5 feel free to ask.
There is also PicoGym which is beginner friendly
https://picoctf.org/
thank you, i will be checking these out this evening and see where i stand with them, i do appreciate your help 😊
No problem
hello i am getting the error while installing linux(ubuntu)
issue : "unable to install grub in dev/sda"
I created a mySQL database and want to be able to have my partners also work on the DB. Is there a way to group collab without using the cloud. I've created roles for each parter with GRANT permissions. I've thought about using docker or creating a git repo.
I’m getting error messages while downloading Nessus in my Kali
What's the error?
It shows download error
With the Internet working perfect the download breaks and shows error message. Can’t download this app
Downloading from the Nessus site
After registering my details, and downloading the scanner it just stopped and shows downloading error. Asked to contact the customer support
I’m talking about Nessus plugins
Have you tried running: nessuscli update --plugins-only
So you do have Nessus itself installed I assume?
I have downloaded Nessus -10.8.2 Debian10_amd64 on my Kali and was going to download the plugging when it stopped running
Alright, try this
@heady bolt Just pinging, so you'll see it
No, I will do this , thank you so much 🙏
alr, let me know. We'll sort it out
I will let you know when I run it.
This is not the server for some shady make money quick advertising..
Thank you so much, I got it working by running /opt/nessus/sbin/nessuscli update - -plug-ins-only
Hello Im here to help a little
Anyone know where I can get a blicky from?
What you mean by blicky ?
I was trying to put my script in github and it keeps getting error can someone help?
To github.com:Angelo-genon/telegram-message-filter-bot.git
! [remote rejected] main -> main (push declined due to repository rule violations)
error: failed to push some refs to 'github.com:Angelo-genon/telegram-message-filter-bot.git'
~ $
@viral citrus Did you fix your error?
You're welcome
yep fixed
@dusk laurel Check the 📌 at the top bar of this channel. Some good resources to get started.
Alright thx
Check #👥・help-me message
about>?
About the code
What the fuck?
I'm lost
I've been trying to learn for a few weeks
Are you trying to make malicious javascript and phish people or smth?
https://cdn.discordapp.com/attachments/1267664851224756246/1285962219011702816/image.png?ex=66ec2d25&is=66eadba5&hm=fcfbe436badc1de8b1747a8883b28eca472f59533a9c24fd4a4dd43ff2c97bdb&
No not at all I tried making a scambaiting site for scammers
Like kitboga
But its not working
I get the goal, but it's still falls under "unethical"
Correct me if i'm wrong @quasi berry
😄
You're not wrong about this being against the server #📜・rules
Really? How?
Form of vigilantism
It's not the code, it's the end goal.
The end goal is to make YouTube vids trolling scammer s
I'm new to this all so I'm not arguing about it
✨ Vigilantism ✨
I appreciate what you are trying to do, but it's still not encouraged in this server.
No I'm not I'm literally making them think its a really account as I piss them off that's it
Understanding
I've been dabbling in the same thing, but I know not to mention or talk about it here
I won't do it again if I'm
Not banned
Understood if I have to hold a ban I get it I didn't known
Known
Know
Ethical just describes the end-goal and intentions. The main categories of hacking remain the same.
For example, you are running a phishing campaign against a company / individual without their permission (unethical) Or you are running a phishing campaign because you are hired to test the companies security (ethical)
Ethical hacker == White hat hacker
good morning yall, quick question. i just finished this ethical hacking course, but it did not contain any labs. so, my question is for CTF, do i start by inspecting the image first? or do i start the sniffing on kali's terminal.
Some sites contain their own terminal where you can use some preinstalled tools to complete ctfs
Any Arch Linux guy , Help me please
Drop Dm!
I got that /dev/sda1 has used 100% of its available memory showing it is full, plz how do I delete the storage to get space
I cannot figure out what is filling up disk space on /dev/sda1. Could you please help me solve the issue?
Hey guys I have a question. I've looked it up and have tried to get it the last 3 1/2 hours. Can sombody maybe vid call me and help me hook up my capture card to my PC and Xbox one? I have 2 kinds but neither are an elgato so I don't freaking understand. I've been streaming through remote play through the app but it keeps kicking me off so it's time to hook this up, if anybody is down to help
@vale tide
This isn't something you can guide someone thru easily my guy
Capture card ? Are you recording game
Is there a way to install an os from gnu grub 2.04
grub> ls (hd0,1)/
I’ve tried booting from usb this way and no good
@chilly merlin
the best arch user here 😉
Type
Yurr check dm
I was trying to install a fresh copy of mint I don’t think I installed it correctly and was only on a live boot. Then I said to hell with Linux I put a windows 7 iso on a usb and it wouldn’t boot and I think the os is completely deleted because it doesn’t go past the grub screen
You probably have grub with no os
Because you booted it off a USB
Just boot a live USB and install to /dev/sda
Or whatever the main drive is
I don’t know how and the usb only has a windows 7 iso
On an os that works you can flash mint to it one sec
If you're tired of endless mandatory Windows updates and would like to try something else like Linux, it's definitely a good pick to try Linux Mint. And here's why: first of all, it looks very much like Windows so you won't need to spend hours and days trying to get used to the new user interface of Linux.
Secondly, it is a very popular Linux di...
I have no other device to create a new usb from
grub> ls (hd0,1)/
grub> set root=(hd0,1)
grub> chainloader +1
grub> boot
This did not work
anyone with slack bot experience? I need help with debugging my code or fixing the triggers
I have to hack iphone x
who can help me?
@quasi hollow lol
yoo, what are the resources for finding out what known malware does (like a forum or database)? I found a trojan (I think remote access) on my PC and it is named and in Windows Defender database. But when I search up the name nothing really pops up. idk how often people reverse engineer malware tho so maybe no one really knows what it does hence why there is nothing about it.
It would be cool to open it up myself but Idk how to deobfuscate so im cooked lol
A little more context would be nice. Why? Who's? Make sure your request follow the #📜・rules and the #1286135820008296509
Well you could run it in something like: https://any.run or https://tri.age
Thanks, i forgot thats a thing
It's a RAT rip, ig an inactive one tho I haven't had any accounts taken or anything and its been on my PC for over a year prob
hmmm
I would never make that assumption
skill issue maybe
Is there a lifecycle for RAT's? It was on a popular Github page, it's tool for a game which is why I downloaded it
What do you mean lifecycle? RAT's don't really 'expire' if that's what you mean
its a noob coded rat i think try malwarebytes
I mean the IP's or servers it connects to might get inactive in a while or maybe when they are "caught" idk
Sure that happens all the time
But if it uses DNS, the destination IP can be changed any time and they are back in operation.
IP-Address and Domains are easy to change for adversaries.
thanks
I have an AsyncRat I think
Tried to sign up for Anyrun and Tri.age but I have to be vetted or something so I can't see what it does yet
How annoying would this be to remove? It seems to affect the .exe and one .dll according to Windows Defender. I think it needs to run to work i'm assuming. (Which It isn't running afaik). I can do a memory scan tho to double check. I'm also checking my network rn but I don't see anything so maybe it really is inactive
Where get flipper zero scripts
Bro's getting redirected again 😂
The smart thing you would have done was to provide help to him since you clearly can other than laughing at people trying to help.
Relax relax
Helping is all I do
I wasn’t even paying much attention that’s why I told him to ask here
Wasn't no attack on you mate
I’m busy with other stuff
lol
I'm constantly helping people in different channels, no need to flame on me
Anyone with experience know how often USB's get infected? After I clean this PC up idk If I gotta buy new usb's or not
I doubt it would infect the onboard memory of my Keyboard and Mouse but ig that would be possible
that would suck
Very unlikely, unless you are a very high-profile target
I mean, possible yes. It could have backdoored executable files on the USB for example that will execute malicious code when you run it. But I would not be too concerned about it tbh.
I had a couple say early that it's not simple but anyone willing to help me hook my capture card? I'm trying to stream , I was doing it via remote connect from my Xbox to my PC but it keeps disconnecting. So is my only other way to stream with a capture card??
i'll search up symptoms of that. hopefully its easy to know
Anyone that has knowledge at rfid cards?
is it a red flag to find something on Process Explorer which properties are completely hidden. for example User: <access denied> Parent: <Non-existent Process> as well as the autostart location being <n/a> and path being hidden
Anyone know if Malware can run on NT AUTHORITY?
Yes it can, if it has elevated privileges, it can become SYSTEM
I'm assuming you mean "NT AUTHORITY/SYSTEM"
reading the previous messages, he is likely investigating his PC.
better to make it clear before engaging
There is no info on how to do smth, just some info what means what
¯_(ツ)_/¯
🥹
Oh okay so it is possible. I was sorta thinking. Okay maybe this is just windows acting like malware like usual. But no it might actually be malware. I found a few processes which I think is pretending to be legit Windows processes.
I found a RAT and i think other malware on my Gaming PC
I've already spent all night trying to isolate and remove just the malware. But yeah ur prob right. Even then, to re-setup everything I did on this PC will take prob a week of work
so I wanna remove just the malware preferably
Luckily, my gaming PC has no sensitive info, and barely any personal info. I use a hardened browser and don't save any passwords. Which is why I think the malware hasn't really impacted me, and why it has gone unnoticed. Its prob been on my system for over a year now
Unless im ignorant and i'm more screwed than I thought
Idk if that's a permanent solution. If he was targeted , it can just keep affecting his PC
Do you have Cybersec experience?
sorta. Not as much as y'all tho. Chat GPT-4o is carrying me rn
kinda getting scared it'll take my job
It is the solution, he is talking about file based malware on his PC. It's not like they are mapping his network, remotely gaining access by exploiting something in his router and pivoting around to find his PC.
Not really
It can do some stuff super fast
But it’s pretty much slow in anything complex which a human with enough experience can do with relative ease
There is a reason i said "not permanent solution" and "if he was targeted"
And I'm talking about clearing his PC, at THIS moment. I never said this is a permanent solution to never get malware again
Yeah its the solution rn
Okay leave him
That is all I meant 🎈🙂
Im not arguing but if it was someone else that was targeted'
THen what?
I'm here
How does malware interact usually with C:\Windows\System32\Tasks ?
okay I think that the malware might be running on a schedule where it only sends something through the network every specific amount of time.
is what i'm kinda figuring out
I want to figure out what sort of information it's sending idrk how
Throw the malware in a malware analysis environment
I wanted to but my Anyrun application got rejected, and tria.ge hasn't gotten back to me yet lol
oh triage got back
finally
Can be slow yeah, depending on load
Oh yeah, this is my first time scanning malware so idk exactly what it's doing but it looks like it messes around with Chrome (I don't have chrome so idk what it really did) then it creates fake Windows processes or something like that which are still actively running on my PC over a year later
if the primary goal is just to grab stuff from browsers it didn't work because my browser autodeletes all cache when I close it. and It's not chrome
idk what the point of the fake processes are though. and there are quite a few of them
Could be number of things, confusing security software, injecting itself into those processes, these processes could be running additional things etc
the main point is confusing heurisric av analysis mechanisms
spawning a few legitimate processes before payload sometimes helps to bypass heuristic analysis
i used to do something similar before yet good old time-based process injection works bettee
generally, any virus needs to show av it's doing something legitimate for the time it runs in av sandbox, that's the point of all this
@flat garnet If you want you can send the file and I can have a look.
And depending on the malware, there are some anti AV and sandbox technique. Some malwares also check for specific process that are being run. For example if the malware detect that you have Wireshark running it's going to terminate itself.
i don't have any files left sadly, i'm now full-time security analyst, not fellow malware enjoyer. yet i do malware analyis sometimes, this includes malware with antidebug features ye
Oh a fellow security analyst. 
So you also enjoy where 90% of TPs are just phishing?
yea, and another 10% is torrented adware
Oh yea PUA is also a big thing every time
Man I wish to have more sohpisticated malware attacks.
haven't had any interesting case for ages
Our IR gets all the cool cases with ransomware or compromised assessment. Unfortunately these people calling us are not our customers and only need our emergency help.
Got it, making more sophisciated malware attacks 😎
i'm doing everything: configure network services, play games, rice arch linux, chit-chat, but not doing my job cause there is nothing to do basically
So I guess it's a company that have their own security team, and not a company offering SOC as a service?
Also playing games is going to trigger XDRs 90% of the time 
yea and our lead is so tired of life cause he has to do admin tasks too, so my work is half-admin work
lmao
Switch to a company offering SOC as a service. You will see a lot of cool attacks. And working on night is also cool.
Lets keep the channel on topic lads 😄
Let's hop on #💬・old-gen-chat and join the rest ❤️
I'm gonna get a headache. There are 2 different csrss.exe processes active. 2 different PID's but when I use Volatility3 to check on them with Dlllist etc. They look pretty much the same to me but they are different. They all use only System32 dll's but the ones they use are slightly different. When I do stuff like Vadinfo they still look about the same and PsScan just straight up freezes the command prompt...
Well csrss.exe is also a legit Windows process. Are you sure it's ran by the malware?
And are you just trying to investigate or trying to make sure your PC is ok after you said you had malware on your PC for over a year?
Because if it's the latter, just reinstall Windows mate. There is no knowing for sure what the malware has done and in how many places it could be
I'm not sure if it's malware. Which is why i gotta figure it out. its weird that there are 2 of them. just like with stuxnet from what i've seen you would have an extra lsass.exe. There are also svchost.exe processes without the "Host process for Windows Service" description as well as no Build version, and a file path that just says [Access is denied]. while all other svchost.exe are fine.
Which is annoying because I can't figure out where it is running from to remove it etc.
(all other svchost.exe show the regular C:\Windows\System32\svchost.exe path)
When I was learning cybersecurity I remember a fake svchost.exe was one of the examples to look for when scanning a Memory dump
but this one is weird and the basic tools I use and memorized just don't work to tell me what I need
because something is protecting it or blocking me from doing so ig
idk
Both csrss.exe processes also show only [access denied] and show no information. When I look at them from memory dump I don't see anything weird except for somehow they show as having a parent process that doesn't exist
Legitimate svchost.exe should be digitally signed by Microsoft. Lack of signature or description is def suspicious
There is also an extra fontdrvhost.exe when I assumed there shouldn't be
I assume you also checked with Process Explorer?
Yes, this is where im doing most of the checking
Any of them trying to connect to sus IPs?
Volatility3 and Process Explorer
Im kinda too noob to know what is sus IPs i did a IP look up for a lot of them and they were in US so ig good idk
no vps
suspicious IP address
Okok
I personally have never seen the <Acces denied> on such processes before tbh
Perhaps @hoary nimbus or @quasi berry have any idea
Don't think they're online now tho
I think i watched a john hammond video where he said your PC should have an Admin user and you should do everything on the regular user. but i can still run as admin on regular user and never had a problem doing anything.
i don't think i even set it up right lol
I don't daily drive Windows for over 7 years orso, I only hack it 😄
Nothing else says [access denied] other than wininit.exe and Services.exe
But the things you're describing around details of the processes and lack of signature def sound suspicious
Oh yeah I didn't even mention the svchost.exe doesn't say "microsoft corporation" either
the weird ones
there are 4 weird ones. One of them is NT AUTHORITY\NETWORK SERVICE instead of NT AUTHORITY\LOCAL SERVICE
one is NT AUTHORITY\SYSTEM actually
there are a few that are on system and network service that are normal too nvm
svchost instances running as NT AUTHORITY\SYSTEM is normal, the lack of signature and details is weird though
Did you install an application from an untrusted source?
yes this sorta started I think from a fake Github page pretending to be the real one on a popular game tool. in 2023
I rushed the download I think
I did see there were 2 and thought the one I downloaded was the correct one
So it was already over a year ago since you installed it and you start to worry about it just now?
Yeah i'm lazy on my gaming PC, I would Virus total everything usually or quick scan on Windows defender occasionally. But Yesterday I did a full scan which showed the problem
showed up as a AsyncRAT on virus total
and something called Multiverze on Defender
Like I said, just reinstall Windows at this point
Yea do a fresh installation at this point.
Do the analysis in a VM or Malware Sandbox
ik, I set up a ton on my PC which last reinstall took over a week to set up again so i'm kinda tryna pull my hair out finding the malware and removing it manually
It can be spread out too much in places you would never look. It's not worth the risk mate
It can inject into legitimate processes and will not even look as sus as some do right now
isn't it possible to figure that out?
Just don't download and run crap randomly
I mean sure, but then again it's like a needle in a haystack. Is it worth the risk? One thing you missed and your still fcked
ig, I thought you would be able to find everything through a memory dump
I mean, sure, you can go through that route. But malware can also be in slumber.
What I learned while doing my certs is 1. Dump memory 2. check with Volatility 3. find anything connected to anything suspiscious and remove
You wanna memory dump every day?
No sir 👍 perhaps im just coping with the reality that I gotta set up everything again after a reinstall
other part of me is like "nah skill issue figure it out" so i've been at it for 20 hours already
Well that does learn you the hard lesson of not downloading and running shady things
Always do your checks beforehand when downloading anything remotely suspicious
I've been there too