#๐Ÿ‘ฅใƒปhelp-me

1 messages ยท Page 17 of 1

lean lance
#

I'm just glad I don't run Windows anymore for years

teal ruin
#

They were clever, they put 1 normal .exe in one place but the other exe in a folder in the zip which was the problem. so I scanned the normal one not seeing the bad one

crisp star
#

I rarely do memory dump when doing forensic investigation sideeye

teal ruin
crisp star
teal ruin
#

How are you able to analyze malware without memory scanning?

crisp star
#

Static analysis

#

And reverse engineering

unreal reef
teal ruin
#

Aren't most malware impossible to reverse?

unreal reef
#

๐Ÿ’€

crisp star
#

Python Malwares are the easiest to analyze

#

Rust is a pain

lean lance
#

Golang ๐Ÿ’€

crisp star
#

.net is also ez

#

And golang is a pain but I rarely saw any

teal ruin
#

oh cool

lean lance
crisp star
#

I love Malwares where it connects to Discord C2 server sideeye

lean lance
#

Binaries are large af tho, only downside ๐Ÿ˜ญ

lean lance
#

Hence the new one ๐Ÿ˜„

teal ruin
#

are obfuscation tools really that bad that you can just reverse pretty much anything?

lean lance
#

Not impossible

unreal reef
lean lance
#

Obfuscation is mostly to confuse security solutions

crisp star
lean lance
#

But there is channels even more focussed on that stuff tho

teal ruin
#

yeah thats where I learned mostly everything about malware. Most of them looked simple, they just target browsers for crypto and accounts from what I remember

crisp star
lean lance
#

Oh yeah, don't make malware without AntiVM and AntiDebug ๐Ÿ˜Ž

#

Ok ok I've said enough about malware ๐Ÿค

crisp star
#

I've seen malware during my job where people use techniques from Maldev Academy ๐Ÿ˜‚

teal ruin
#

Career wise whats the point of malware development? is that for pentesting?

#

like you make stuff you will use ig

unreal reef
lean lance
#

They da feds

#

Jk jk, we are ethical

unreal reef
#

๐Ÿซ

#

fonky

#

donkey

teal ruin
#

i'm blue team. mostly... when I actually finish my certs

#

Blue team kinda boring tho

unreal reef
#

ngl

crisp star
#

Become a CSIRT then blue team won't be boring

teal ruin
unreal reef
#

u can make a whitelist service and make money

#

and u can crack one

#

and make money

#

bug bounty or a product

#

u choose

teal ruin
#

id prob just do pentesting for businesses

unreal reef
#

back in the day i used to do bug bounties

#

and unethical "hacking"

teal ruin
#

I think social engineering might be fun

unreal reef
#

done it for a couple years

#

its nice to have in the back of ur mind

crisp star
#

Social engineering by sending phishing e-mail?

teal ruin
#

I tricked a dude who tried to steal my account to giving me his number because i pretended to also be a dude who stole (my account) and was like wanna make money together?

unreal reef
#

this is not social engineering

#

๐Ÿ˜ญ

#

or

#

it can be

crisp star
#

Well sending phishing e-mail or BEC is a form of phishing.

#

I mean social engineering

teal ruin
#

did this when I was a teenager

#

scambaiting might be fun. Idk the legality of it so I don't want to try it until I know for sure what im doing

#

I was thinking about making him download some malware that I would make with the goal of getting my friends account back to him. (cuz he stole his)

#

that would be greyhat ig?

#

i'm assuming even if the goal is good like giving someone something back that was stolen from them, i could still get in trouble

#

Okay... I restarted my PC after removing things for 20 hours and there are no more suspicious processes. Even if there is something super hidden, I don't really have anything to compromise on this PC so i'm good I think. I checked with Autoruns and stuff as well and everything is good.

Btw thanks for the help everyone ๐Ÿซก

#

I should prob make a habit to do a clean install of Windows every 6-12 months anyways tho

#

But first I wanna figure out how to make those custom .iso so I don't have to set everything up forever again

vale tide
#

Can anybody help me set me capture card up?? I was streaming via remote connect but it keeps disconnecting. What is a better way???

dusky lark
#

Anyone have experience with using a SIM reader as a phone/sms modem? I wanna experiment with building a microcomputer that can perform the functions of a phone

#

That way i can get rid of this god forsaken thing

vale tide
#

So nobody???

bleak condor
#

hey whats better black arch or just arch?

visual linden
#

whats is better parrot os or kali

quasi berry
#

What's up

valid belfry
#

@dusky lark

#

Digi Accelerated or a Cradle point.

#

Wait are you staying you want to use LTE as a wan

dusky lark
valid belfry
#

Can only use it for one at a time unless you use a phone providing a hotspot

dusky lark
#

This would ideally replace having to need a phone

valid belfry
#

Can't use them for both to my knowledge

#

Only one or the other, they use cellular towers and connect to wan of a router

#

It doesn't actively broadcast

vale tide
#

Still can't figure this out

#

I would really appreciate sombody to help frfr

halcyon flame
#

Asking for help, provide information that will help people to help you with the request ๐Ÿ™‚

chilly merlin
#

ayy gobby

halcyon flame
#

oi oi

chilly merlin
#

whats up seems u in good mood today

halcyon flame
#

Mostly tired lol

#

No sleep, so chatting until I start work

#

How're you doing?

chilly merlin
#

quick question

#

if ssh service is running on a system how to determine if it uses pass authentication or rsa private key authentication @lean lance

#

i mean im doing hydra bruteforcing in a ctf if a ssh service dosent accept passwords its waste of my time right

chilly merlin
halcyon flame
#

Come on man

#

Any luck on Google?

chilly merlin
#

so far no problem

halcyon flame
#

-v - look for Authentications that can continue

#

It'll list the auth types that are supported in the verbose output

chilly merlin
#

ill take a look

#

ty gobby

solar fiber
#

Question

What is the best wifi adapter for educational hacking purposes?

Would like to know one that is:

  • Economical
  • Accesible
  • Good Quality
halcyon flame
#

Did you want that pasted in to ChatGPT for you? ๐Ÿ˜‰

#

..but personally, the Alfa adapters are good

#

Consider, you pay what you get for though

#

Yes you can get an adapter for WiFi work that costs ยฃ10, but compared to something of quality that might cost 4-5 times, you will notice the difference.

#

If you want to mess with 2.4ghz and 5ghz, you want to go with quality over lowest cost.

solar fiber
solar fiber
halcyon flame
#

Yeah, personal experience as I said then is Alfa ๐Ÿ™‚

solar fiber
halcyon flame
#

You could go for a WiFi Pineapple, but honestly unless you're running engagements (and even then) you don't really need the Pineappple

#

For a decent Alfa you're probably look at around ยฃ30-40

solar fiber
#

Engagements?

halcyon flame
#

Yes, as in on site penetration tests

solar fiber
#

Hmmm

#

I doubt so, I'm very far from work opportunities

halcyon flame
#

Then yeah.. an Alfa to start researching and working in the field personally and learning would do you perfectly fine

solar fiber
#

Is that a branch or a product name?

halcyon flame
#

Alfa is the brand / producer

#

I'd do some searching to find what people recommend as the best these days, as it's been a number of years since I did any work in that field

#

The Alfa AWUS036ACH looks to be recommended though

flat garnet
lean lance
solar fiber
solar fiber
lean lance
#

ALFA is goat tho

flat garnet
#

i currently use alfa for a nethunter setup, it's a bit old and doesn't support 5G, apart from that the best adapter i've ever used

solar fiber
#

Can be attached to an android phone device?

lean lance
#

With a dongle y

flat garnet
#

yup, with custom-built kernel too

solar fiber
#

Hmmm

#

Custom-build kernel?

#

How I could learn that?

flat garnet
#

just search xda with "%device name% nethunter kernel"

#

90% chance you'll find it prebuilt

solar fiber
flat garnet
#

you can build it from scratch tho, kali website has instructions for that too

flat garnet
solar fiber
flat garnet
#

xda developers

lean lance
#

It's a community for Android development and such

#

And more

flat garnet
#

it's generally not safe to use nethunter phone as a daily driver tho

#

cause y'know, no verified boot and all of that

solar fiber
#

That is new for me, thanks for making me know that!

#

Is there a way to safely boot an alternative os on android just like on pcs?

chilly merlin
#

tp link are good

#

ยฏ_(ใƒ„)_/ยฏ

#

im late

#

๐Ÿ˜ญ

solar fiber
flat garnet
#

i used to contribute to that project also

#

and graphene is my daily driver for like 4 years

solar fiber
#

Oh

flat garnet
solar fiber
#

I'm looking into that but..

#

How I could make a use of that?

#

Btw

flat garnet
#

of nethunter? you can pentest your neighbor's wifi as example

solar fiber
#

Btw this was the one I was about to buy TP-Link Nano USB Wifi Dongle

halcyon flame
#

Don't do that.. work on your own network (as in don't test / mess with your neighbour or networks you don't own)

#

or build a home WiFi environment

#

(to work on)

solar fiber
flat garnet
#

at least i'm honest with color of my hat

#

yk

#

no that "don't work without written permissions" bs

halcyon flame
#

lol sure, good luck with that

flat garnet
#

but yeah, generally speaking it's not good to pentest networks that don't belong to you

solar fiber
#

As for I understand, Greyhats typically hack without permission but looking for compensation after notifying it

#

That's my opinion, is not a conclusion

flat garnet
#

i'm mostly whitehat nowadays, i just don't like painted borders yn

flat garnet
flat garnet
#

i used to do that and notify not to receive any compensation but to make a resource generally more secure

solar fiber
#

Ohh

#

That's interesting

flat garnet
#

you shouldn't count on any compensation if you go where you don't belong, you should make yourself safe from punishment lmao

flat garnet
#

even if you think it's for good

solar fiber
#

Or at least I understood something of what I'm agree of

flat garnet
#

generally speaking, most of the dudes telling you you should be law-obedient and never try anything stoopid like to hack people's things in their spare time

#

calling themselves white hats in process, or they are ctf-only people who can hack in a specially-organised environment only, not real world

halcyon flame
#

Responsible disclosure and research on open source projects ๐Ÿ˜‰

#

Have done a few engagements for a few private clients, and a disclosure for a bank I found by mistake (legitimately noticed a vulnerability by mistake)

#

otherwise, I'm an engineer first, and a enthusiast / security advocate at heart

flat garnet
#

"doing engagements for a few private clients" is the way i'll call blacking from now on

#

thanks for suggestion mate

halcyon flame
#

lol, no, not at all

#

A couple of previous companies I worked with, they asked for my services.

flat garnet
#

i used to work with a pretty legitimate pentesting llc before, also did same thing. we signed nda and all of this

halcyon flame
#

Yep, all above board. It was quite fun, as was not my usual day job.

#

Had some decent findings as well which was good ๐Ÿ˜…

flat garnet
#

formally i'm still assigned to them, no tasks dropped recently

#

i'm currently unable to receive paychecks yet they always were so nice to pay me in monero

halcyon flame
#

That's good, even if I bet their accounting department hate them for it ๐Ÿคฃ

flat garnet
#

probably yea

#

it's sad i can't work with them in open due to current geopolitical situation in my region

halcyon flame
#

That's a shame. Here's hoping things improve, and you can openly work with them again in the future.

#

The world's a bit of a mess at the moment ๐Ÿ˜ฆ

flat garnet
#

always has been

flat garnet
blazing wyvern
#

Hey yoo

unreal reef
drifting shell
drifting shell
valid belfry
#

Google services doesn't work with graphene

quasi berry
valid belfry
#

Nah @quasi berry you gotta flash gapps right?

#

I used it on pixel but didn't like it and went for lineage

#

And just didn't install google apps at the time, but I like their recovery

quasi berry
valid belfry
#

That's dope I didn't know that existed

lean lance
#

MicroG perhaps

valid belfry
#

^

quasi berry
quasi berry
lean lance
#

Yeah been flashing ROMs for so long haha

#

Gonna switch to Graphene and Pixel probably very soon

quasi berry
#

Ah there's a thing in network and internet for changing the connectivity checks, widevine, and alternate key provisioning to google servers

lean lance
#

Oh that does ring a bell ye

quasi berry
#

Reading the documentation you'd need to use the compatibility layer

halcyon flame
#

โค๏ธ Pixel phones

#

but not messed with the OS on them yet, have lots before on other Android phones

#

Two days battery life easy, excellent camera, stock experience

#

Only thing that is missing is LIDAR

#

No, time of flight, not lidar

#

(for 3D scanning)

vale tide
#

?

lean lance
halcyon flame
#

?

vale tide
#

Lol I've asked the last 2 days if sombody could help me and I've gotten nothing back! I would GREATLY appreciate it if sombody could help me figure out how to stream with out remote play . I have capture cards just not an elgato! If sombody would help be around 2:00 I would get on one knee for you๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

#

Lmao last parts a jokey joke

lean lance
#

Bring a ring as well, and i'll consider

#

I'm not too familair with console + streaming tbh

halcyon flame
#

I replied @vale tide - I have no experience with capture cards, but did reply trying to help you provide more useful information in order to help someone troubleshoot or advise.

#

Scroll up and check my reply, the more information, the better.

dusky lark
#

also shouldn't a capture cards just give you another video or data output that can either be sent elsewhere or used by the computer? I'm unsure as I haven't streamed for a very long time

halcyon flame
#

You got people replying to you @vale tide ..

#

Capture cards used to offload the video encoding away from GPU/CPU by passthrough of HDMI or whatever, and then passing off to local storage

dusky lark
#

Yeah I'm confused as to what the issue is then

halcyon flame
#

Yeah, I don't know.. we need to know more if we're going to help

dusky lark
#

do they need it written remotely? Just forward the stream over the network or something idk, write to an SMB or NFS share

halcyon flame
#

I tried

#

we*

solar fiber
#

@flat garnet Sorry I didn't reply back

west wind
#

Is it possible to do cybersecurity without knowing how to code

unreal reef
#

what do u wanna do specically

#

specifically

#

idk how to spell gg

native sleet
#

you'll be quite limited in the roles you can choose

#

and you wont have as much job security as one would like

#

(fear of AI etc)

fierce steppe
#

Chat best laptop to get that dosent have loud ahh fans

lean lance
#

For what purposes?

fierce steppe
#

Hacking

#

Everything

lean lance
#

Gaming ?

fierce steppe
#

That too

lean lance
#

Heavy games or ? Graphic intensive?

fierce steppe
#

lol Iโ€™m not much of a gamer

#

What are the options.

lean lance
#

Gimme example of a game

#

Depends on how graphic intensive the game would be

fierce steppe
#

I donโ€™t play games

lean lance
#

๐Ÿ˜„

fierce steppe
#

Yh, I like to have more options ๐Ÿ˜‚

lean lance
#

Fair fair haha

vale tide
#

hey sorry I was in iop! I appreciate the replys noww! ๐Ÿ˜€ So what would be the best way??

halcyon flame
#

Read what I said twice, then reply with some more information

#

FFFF

#

Let me say it once more I guess @vale tide - what have you tried, what are you struggling with, are you facing any errors or what is not working as expected?

#

I really am trying to help, but you're not making it easy ๐Ÿ˜…

#

Please don't say you've vanished again

halcyon flame
#

Yeah.. nevermind then. Call tech support listed in the manual for your capture card. I'm done @vale tide

quasi berry
#

@chilly merlin

chilly merlin
quasi berry
#

Not yet

chilly merlin
quasi berry
#

Yes

frail ether
#

Does anyone have apk/tool to redirect every out/in connection on my android phone to my local proxy. So i can monitor the out/in connection. Without root.

wintry anchor
#

Can anyone give me my guest account of freefire game it was 4 years old

full knoll
#

Anyone familiar with setoolkit site cloner please inbox

split zinc
#

guys i just started in game design what do i do to desig the UI for it

orchid lynx
#

I am looking for some guidance on schooling and career choice. I got into comp sci with an interest in programming, but got scared with all the dev layoffs, so switched to cyber sec. I love the idea of ethical hacking, always have. My only issue is, I still love the idea of diving deep into programming; specifically low level, embedded, playing with microcontrollers, bread boards, etc.. my school does not offer any majors with focus on computer engineering, embedded systems, etc otherwise I would have went that direction instead of cyber security. I guess my question is.. will programming electronics have to remain a hobby? Or are there areas of cyber security thatโ€™ll allow me to play with toys (microcontrollers, breadboards, components)

hoary nimbus
orchid lynx
# hoary nimbus Yes, there are specialiastions within Cybersecurity where you'll be able to mess...

Excellent, I thank you so much for this advice. Iโ€™ve been getting discouraged, feeling as though I may end up working a job that isnโ€™t as exciting as Iโ€™d like- simply because there are no options at my school. Iโ€™d say every company is different, but in your opinion; would a degree in cyber sec be enough to land a job involving hardware hacking, if I am completely self taught on the hardware side of things? Is this the type thing where real-world experience is more important than a degree in say, Computer and electrical engineering?

#

Of course, Iโ€™ll need to do my own research into this. Iโ€˜ll look into certs that could help supplement my degree.. at the very least itโ€™s good to know that this field does in fact exist in cyber security

hoary nimbus
# orchid lynx Excellent, I thank you so much for this advice. Iโ€™ve been getting discouraged, f...

Hmm, that's difficult. I won't say having a degree will inherently in of itslef garuantee you a job. There's plenty of other things they'll look for, it'll certainly help your chances, but it's not the core requirement for what they are after. I'd highly advise that you start documenting your projects, showcase the work you do, that has far more weighting than an undergrad in cybersec. Real-world experience is valued far more than theoretical knowledge, if you're able to demonstrate your understanding of hardware hacking, you'd drastically bolster your chances of being hired.

opaque ember
#

roblox

orchid lynx
wanton marsh
#

Gotta enable it as a device though your VM host software

#

Same thing with USBs

humble canyon
#

Hello, i have to crack a pdf file for a homework assignment. i know the password is 8 characters long, so far i have used john, and haschat. I have also used every wordlist with kali linux including rockyou. any tips on other ways to crack the password.

halcyon flame
#

hashcat probably your best bet. If it's homework, surely they would have given you some context, some sort of hint for the password? Otherwise, you're going to be dependent on hardware.

humble canyon
#

ok thanks

wintry anchor
wintry anchor
solar fiber
#

Evaluation Request

I would like C++ experts to help me evaluate this code:


#include <iostream>
#include <windows.h>

namespace color {

    void setConsoleColor(int color) {
        HANDLE hConsole = GetStdHandle(STD_OUTPUT_HANDLE);
        SetConsoleTextAttribute(hConsole, color);
    }

    std::ostream& green(std::ostream& os) {
        setConsoleColor(FOREGROUND_GREEN);
        return os;
    }


    std::ostream& red(std::ostream& os) {
        setConsoleColor(FOREGROUND_RED);
        return os;
    }


    std::ostream& reset(std::ostream& os) {
        setConsoleColor(FOREGROUND_RED | FOREGROUND_GREEN | FOREGROUND_BLUE);
        return os;
    }


    std::ostream& blue(std::ostream& os) {
        setConsoleColor(FOREGROUND_BLUE | FOREGROUND_INTENSITY);
        return os;
    }
}

int main() {
    std::cout << color::green << "This text is green" << color::reset << std::endl;
    std::cout << color::red << "This text is red" << color::reset << std::endl;
    std::cout << color::blue << "This text is bright blue" << color::reset << std::endl;

    return 0;
}
#

Is there any better implementation for this?

#

Banned... 0.0

deep aspen
#

tried using r4ven, tried hosting it myself, used ssh, followed all the steps, allowed the correct ports, changed ports, used ngrok. all this and it still doesnt work

#

whos got an ip logger i can use

solar fiber
#

...

deep aspen
#

lmao

#

but someones gone and tried to get my friends' and dox them

#

obviously, i cant allow it

hoary nimbus
valid belfry
#

@deep aspen lol

opaque panther
#

I need help

#

How do i run my localhost to a public url

#

Like the link is only working for my phone

chilly merlin
opaque panther
#

Thank you

light kettle
#

Hello

#

Please help I want to hack into someone's WhatsApp๐Ÿ˜ƒ without them knowing

wintry anchor
floral salmon
hoary nimbus
wintry anchor
quasi berry
wintry anchor
#

Ok sorry

dapper charm
#

hey everyone i need a help

lean lance
dapper charm
#

i wanna explore dark web with my kali linux

#

can you help me??

lean lance
#

And what are you trying to find there exactly?

dapper charm
#

just for exploring there it will be my first exprience>

lean lance
#

Well, just a fair warning. You're more likely to find stuff you didn't wanna see then the other way around.

dapper charm
#

okay

lean lance
#

Are you familair with using Tor and/or how it works?

wicked sorrel
#

So basically there a session management tool called villain check them out just type villain session management tool in your browser its a session management tool and i don't know why but there is a command called flee basically it saves the sessions so you can use them later in the future but the flee command is not working for me,once i press yes i want to save this session for future use and later when i type sessions it don't show me the session i saved. please help me fix this i used windows Power Shell script to get the session.

dapper charm
lean lance
#

And again, I've warned. You WILL see things you didn't want to see eventually, whether you choose to or not.

lean lance
#

If the process / session died, then obviously 'saving' the session with flee will not work

copper tulip
#

Hello

#

/sbin/modprobe: invalid option -- 'l'
/sbin/modprobe: invalid option -- 'l'
Stoping bluetooth service..
Stopping bluetooth (via systemctl): bluetooth.service.
โ—‹ bluetooth.service - Bluetooth service
Loaded: loaded (/usr/lib/systemd/system/bluetooth.service; disabled; preset: disabled)
Active: inactive (dead)
Docs: man:bluetoothd(8)
GIVE SOLUTION FOR THIS

lean lance
#

What you posted doesn't really say much. What are you trying to do? and what commands are you using?

copper tulip
#

Please helo

#

Im learning to crack passwords

#

Actually i got one file pasted on VM kali

lean lance
copper tulip
#

Okey Wait

#

I'll DM you

fierce steppe
# lean lance Fair fair haha

How come you responded to my question about laptop and then completely ignored my response?
Donโ€™t seem to get it? @lean lance

lean lance
fierce steppe
#

Well you shouldnโ€™t have led me on

#

All good

#

Lmao

lean lance
#

Right

chilly merlin
#

@calm basalt You need a kryboard specific to razer?

calm basalt
#

This is what they recommended me tho it's not razer

chilly merlin
calm basalt
#

Kinda want to buy it in amazon

chilly merlin
#

But I'm sure they sell on amazon too

calm basalt
#

Wut keyboard would u pick

chilly merlin
#

Just find the one you prefer and search for it on amazon

#

Check under Deathstalker keyboards ๐Ÿ‘

crystal grove
#

cookie send subnetign video please

crystal grove
#

ok

chilly merlin
#

Is it a dualboot. Or vm? Or fresh install

#

It's good

chilly merlin
#

You want to install kali on a vm?

#

Do you want to watch a video on it or do you want my help

#

@molten otter ??

valid belfry
#

@molten otter

#

Send screenshots of the issue you are having during installation

sharp pendant
chilly merlin
#

bro

#

i hatw

#

hate hitboxes

#

tell sieges shitty ass skid fucking devs to fix hitboxes before i leak their entire god damn db

#

these devs have a year max in experience with jack shit other than fucking python and lua they need to be fired

hexed anvil
#

could I get some assistance please okay I have two issues first issue is out of a Dell latitude 7420 with an administrative password as soon as the laptop turns on can't get the bios screen or nothing so how do I get past this problem. My second problem is my other laptop it has a company log on with a work and email instead of personal Microsoft how do I remove this so I can use my Microsoft account to log on to the laptop. and thank you for whatever information will give me

#

and I did watch a few YouTube videos trying to learn but nothing has worked by the way

halcyon flame
wooden canyon
#

๐Ÿค–

pulsar silo
#

wondering what's some good beginner cybersecurity projects

maiden violet
#

Iโ€™d recommend unis with a cybersecurity course (if you are going to one)

chilly merlin
#

@lean lance

halcyon flame
#

(biased due to working with HTB)

#

There are lots of platforms out there to help you expand your knowledge in the field

#

Find what works well for you, and go for it!

tight elk
#

hey anynoe know how i can build pasted code into vs code?

tight elk
#

i copied code of github and i wanna build it

#

itsa remote admin tool

chilly merlin
#

explain more clearly

tight elk
#

basically i setup visual studio code and went into my pc system enviroment and set it up for c++ and now i copied code of github "AsyncRat" "remote admin tool program" and i wanna build it now

#

@chilly merlin

#

cant find option to build the code i copied and pasted

chilly merlin
#

its a Rat

tight elk
#

yeah its not for anthing malicious

#

its just that i wanna learn

#

nybad

chilly merlin
#

malware analysis

tight elk
#

mybad

chilly merlin
#

?

tight elk
#

no im not intending to use it on anyone

#

its just easiest thing i found

chilly merlin
#

gimme a sec

tight elk
#

i can download literally anything ele

#

else

#

i jsut need help with build

#

@chilly merlin i can download anything ethical just need help

chilly merlin
#

did u tried youtube

#

and ai

tight elk
#

yeah but the thing is in my version of vs codethere is no build option

#

@chilly merlin doesnt AI cost?

hallow kindle
chilly merlin
#

chatgpt

lean lance
#

You need Visual Studio, not VS Code

tight elk
#

thanks gonna go cehck right now

#

i have both @lean lance

#

i downloaded 60+ gigabytes

#

got 5 terabyte

#

ssd

lean lance
#

It can be done in VSCode, but VS may work better

tight elk
#

ok thanks

#

oh i didnt know i could download chatgpt

#

does fbi/cia/local cops watch chatgpt logs?

#

like if i write stuff

#

dont wana wwrite anything i will regrety

lean lance
#

@tight elk just keep it Ethical

tight elk
#

alright thanks for all advice boys

chilly merlin
#

we dunno ur intentions even if u say jus wanna know its like teaching u building a bomb . we cant help u much in this case not after u mention fbi/cia

tight elk
#

oh noononon ahhaa

#

not that stuff

chilly merlin
#

try googling and yt and ai

tight elk
#

seems like chatgpt download is only for mac

#

that sucks

chilly merlin
#

this server rules does not allow

#

hope u understand

tight elk
#

yeah i understand

#

im not here to learn bad stuff

#

im here to learn coding

#

/hacking

#

whitehat

chilly merlin
#

mal dev?

#

if im correct

tight elk
#

sorry dont understand

#

malicous?

chilly merlin
#

malware development

tight elk
#

oh

#

yeah somnething like that

chilly merlin
#

its a field

#

in cybersec

tight elk
#

its for my future

#

i have bad situation

#

and wanna learn

chilly merlin
#

take a look at maldev academy and vx underground

#

cy u here

#

?

tight elk
#

what do vx do?

#

yea c me there

chilly merlin
#

never used it

tight elk
#

but what do they do?

#

i just looked their site up

chilly merlin
#

idk

#

@tight elk

#

vx-underground also known as VXUG, is an educational website about malware and cybersecurity. It claims to have the largest online repository of malware. The site was launched in May.

tight elk
#

ohhhh

chilly merlin
#

that is all i can do

tight elk
#

ok i get it now

#

thx

#

watching the site rn

#

@chilly merlin do you recomend any program to encrypt my files?

chilly merlin
#

the file

tight elk
#

yeah

#

like i mean external programs

#

for google

#

from"

chilly merlin
#

wat

tight elk
#

thAT can encrpyt my pc/files

chilly merlin
#

ransomware

#

?

#

or asking for a software

tight elk
#

wait i forgot i can use chatgpt

chilly merlin
#

that encrypts files

tight elk
#

sorry for wastnig ur time

#

i mean i usedto have a program that could do that

#

but i frogto the name

#

forgot"

chilly merlin
#

bitlocker

hallow kindle
#

I think he means a way to encrypt his own files

chilly merlin
#

on windows

tight elk
#

@hallow kindle yeah

quasi berry
tight elk
#

both

hallow kindle
#

Nvm

quasi berry
#
tight elk
#

YEAH

chilly merlin
#

there ya go

tight elk
#

thats the program

tight elk
#

that i used to have thhanks

chilly merlin
#

benny to rescue

tight elk
#

veracrypt

#

exacly that one

quasi berry
tight elk
#

thanks bro

#

apreaciate it

quasi berry
#

No worries

tight elk
#

@quasi berry any proxy progream to recomend too?

chilly merlin
tight elk
#

thanks so much

#

boys i got a last question if u have time

#

whats the best free vpn to download?

#

dont got money rn to buy one

#

@quasi berry

#

if u know

quasi berry
tight elk
#

@chilly merlin hey bro you know i downloaded 7zip and whenever i try downloading a file enidng in 7z, it gives me errror saying "support for the encrypted archive is not available for hte moment"

chilly merlin
#

damn

#

Outdated 7-Zip: Update to the latest version from 7-Zip's website.
Corrupt File: Try downloading the file again.
Unsupported Encryption: The 7z file may use an encryption method not supported by your version of 7-Zip.

#

i am a complete beiginner help[ me out to step in cybersec

#

i know basic lol

chilly merlin
#

why

#

kya haal hai

#

nah only english bhai

#

ok

#

rules are in place

#

start with linux

#

is a good website

valid belfry
chilly merlin
timid iris
#

hi, i have a question what is opsec and what does it do?

wicked sorrel
lean lance
# timid iris hi, i have a question what is opsec and what does it do?

OPSEC (Operations Security) is a process designed to protect important information from falling into the wrong hands. It helps organizations, especially in cybersecurity and the military, keep sensitive data safe by identifying risks and addressing them before attackers can exploit any weaknesses.

chilly merlin
chilly merlin
calm basalt
#

Ty

lean lance
#

Oh low-profile, saving that one ๐Ÿ™‚

rancid cedar
#

Hi guys , i have a problem in dual booting arch linux with win 10 , when i boot into the usb and i issue the cmd lsblk or fdisk -l it shows only infos abt the usb instead of all the drives

shadow fractal
#

@solar fiber

solar fiber
#

0.0

shadow fractal
#

Could anyone assist this kind fellow?

solar fiber
#

๐Ÿ˜‚

#

Thanks

lean lance
shadow fractal
rancid cedar
#

Yeah it s disabled

lean lance
#

Is there any option called "Intel Rapid Storage Technology (RST)"

#

Somewhere under SATA Mode probably

rancid cedar
#

Where

lean lance
#

Also in BIOS

#

What boot mode are you using btw?

rancid cedar
#

Usb

lean lance
#

Boot Mode (UEFI vs. Legacy)

rancid cedar
lean lance
#

Set it to Legacy and try again

#

You want the booting process to be handled by GRUB, from there you can always boot to Windows (if it's added correctly).

rancid cedar
#

But i don't have the choice in boot mode

lean lance
#

Were you trying to install? Or just troubleshooting after the install?

rancid cedar
lean lance
#

I highly doubt that, should be an option somewhere

#

Aha, okay. In that case perhaps the Fast Startup or Hibernation option in Windows might be locking the drives

#

Disable that, and make sure to properly Shutdown windows, no hibernation/sleep etc. This can lock active drives

rancid cedar
#

So i ll disable hibernation and fast startup

lean lance
#

Yes, and then properly shutdown windows

rancid cedar
#

Okey thank you so much

lean lance
#

That will likely fix the issue, otherwise let me know

rancid cedar
#

Sure

#

I went to cmd and issued powercfg /H off

#

To disable fast startup and hibernation

#

Nothing changed

rancid cedar
#

Chatgpt said that arch doesnt read RAID sata how can i check?

lean lance
#

Change the SATA controller mode from RST to AHCI

rancid cedar
#

How

lean lance
#

Depends on your BIOS

#

Look around in the settings, let me know what you see

rancid cedar
#

i found this

#

there is nothing in bios abt sata or smth relevent

lean lance
#

There definitely should be

#

Are these NVMe drives?

#

What motherboard do you have, I'll tell you where to look

simple dagger
#

I come to you with a matter. my mother was robbed by extorting the blik code. and the thief used this code and pretended to be a friend and made a purchase in the online store where I also have the address. Would it be possible to somehow track the device from which the transaction was made? My family and I are in a very difficult financial situation and I would really like to ask for help

lean lance
rancid cedar
lean lance
rancid cedar
#

i am checking it s acer nitro an 515-54

rancid cedar
#

hhhh

#

i've changed it and i ll see what ll happen

#

thank you so much man

#

it worked

lean lance
rancid cedar
#

just one question

#

did u face that issue too or ...?

#

i mean before

lean lance
#

It's a common problem when trying to install.

#

By booting the Arch Linux USB in the same boot mode as your Windows installation, it will solve your problem. If you had an extra SSD or HDD for example. That one would likely show up normally.

chilly merlin
lean lance
rancid cedar
#

of windows 11 ?

calm basalt
#

Can I watch amazon prime on nordvpn?

lean lance
calm basalt
lean lance
# calm basalt Yk an article that proves it?
#

Sometimes a simple Google search is the best solution to your answer

calm basalt
#

Idk

#

It just says "it's advanced enough to surpass amazom prime encryption detections"

#

Which doesen't seem so ethical

lean lance
#

There is no crime in trying to hide you're using a VPN

#

Don't worry they wouldn't be advertising it like this if it was deemed illegal.

calm basalt
#

Kk ty

calm basalt
solar fiber
chilly merlin
#

Help

maiden violet
chilly merlin
fallen lynx
#

Yall why I canโ€™t do htb easiest challenges ??

rancid cedar
#

Hi guys back with my problems

maiden violet
rancid cedar
#

Can someone tell me why can't i enter the boot menu

#

The bios i mean

#

After i installed arch i can't enter my bios

lean lance
#

What key did you use before to get into bios, try booting again and keep tapping it.

#

Initial view of the BIOS boot screen might be gone faster with the changes made in BIOS

celest juniper
#

Hello, I would need some explanations on the use of Cheat Engine, if you don't mind.

Here are the steps I have followed so far:

I want to create a proximity voice chat. To do this, I first need to find the player's X, Y, and Z coordinates in the game. After finding these axes, I used Cheat Engine's "Pointer Map" option to create a reliable pointer for each axis. Then, I wrote a C program to obtain the base address of my game.

Once this step was completed, I wanted to develop a console program in C capable of displaying the Z-axis (the height). However, I realized that I donโ€™t know how to do this, as I used the "Pointer Map" to find the pointers instead of finding them manually. I would like to know if you could explain how to find a pointer without using "Pointer Map" or recommend a tutorial that explains this method.

For your information, I have already followed several YouTube tutorials, but without success. I think this is due to the size of my game, which likely makes finding pointers more complex than in smaller games.

fallen lynx
# maiden violet Your skills needs some working

How , itโ€™s not that Iโ€™m blinding and donโ€™t know anything , itโ€™s been a year Iโ€™m in cyber security but like idk I just canโ€™t do stuffs by my own , how to improve ?

quaint mauve
#

that owasp bible thing i found pretty useful for learning about web vulnerabilities

#
upbeat veldt
upbeat veldt
quaint mauve
#

oh nice

#

are they free?

#

wow looks like it awesome

dire basalt
#

I am very novice , and started my cybersecurity journey on TryHackMe and but I noticed so many errors from the labs and as a pure novice it is not always very easy to go around those bugs or no updated rooms, I am very into ethical hacking , I would love to find a mentor, is there anybody with a great heart and patient for ?

chilly merlin
chilly merlin
#

Finding a mentor is a bit difficult

dire basalt
#

I really appreciate it I am consistent but sometimes I feel very frustrated to not see the issue ...

chilly merlin
#

Just look carefully and think outside the box

dire basalt
chilly merlin
#

@chilly merlin

#

yes

#

@chilly merlin

chilly merlin
#

im prank calling law firms

#

Ohk il ask later

snow sparrow
#

Following this video

#

@lean lance hmm.. now what??

lean lance
#

Did you just blindly copy-paste the commands for formatting & partitioning ?

snow sparrow
#

the same he did just changed the size

#

partition sizes

lean lance
#

Well, that is not how it works

snow sparrow
#

so you are telling me

#

I need to do all that again?

lean lance
#

Your drives and partitions were probably different

#

That's why blindly copying & pasting without understanding is a bad practice

lean lance
#

A decent tutorial would actually teach you what commands do, and where it might be different for you.

snow sparrow
#

Thanks man

lean lance
#

No problem ๐Ÿ‘

snow sparrow
#

now it's too big

lean lance
#

Fonts where? In terminal?

snow sparrow
#

root@archiso

#

setfont ter-132n

lean lance
#

Try this

#

setfont -h8 /usr/share/kbd/consolefonts/drdos8x8.psfu.gz

snow sparrow
#

uhm these are not too good

#

they look weird

snow sparrow
lean lance
#

setfont /usr/share/kbd/consolefonts/ter-v16b.psf.gz

snow sparrow
#

okay

devout star
#

how too use CVE-2020-6091 on a my epson web control

lean lance
fallen lynx
upbeat veldt
# fallen lynx Can u give me a roadmap for penetration testing ??

Well this depends on what kind of pentesting you want to focus on. Web app, external, internal, etc. This also depends on your current experience. If you are a complete beginner I would suggest to start off with tryhackme, learn the basics, finish a couple learning paths, by then you should know what kind of pentesting you would like to do. If it's internal / external then continue pwning different machines but challenge yourself, switch to HTB machines, practice writing reports for the machines you complete. if it's web app use portswiggers academy to learn and get hands on, then look at bug hunting to get some experience with hardened targets. Again this is very broad, but this is what I'd suggest based on your question.

acoustic stump
#

how can i import bluethoot

#

like on pyhton

flat garnet
#

dat kernel takes ages to compile on a nugget even with custom build flags

#

help me

chilly merlin
valid belfry
fossil nest
#

So my laptop crapped out on me so I pulled out my old computer, it's got Windows 7 on it, but yeah it's been so long I forget my password and I don't have a recovery disc or anything, and we need to print stuff but going through others or the library is getting old... can anyone help?

lean lance
lean lance
#

With a full reinstall, yes you would.

fossil nest
#

That's what I'm trying to avoid. I have pictures and videos of a dear friend who has passed away now, as well as a bunch of other things I don't want to loose

lean lance
#

There is ways to bypass the login and clear the known passwords, but It's hard to tell If it's actually your own device.. We regularly get unethical requests as you might understand.

fossil nest
#

Oh, I get it

lean lance
#

I would say do a quick Google search on it, and you would figure it out easily.

fossil nest
#

Yeah I did that, I found a video where it showed me a process of switching a file name or whatnot which would allow me to like pull up the command window and that process didn't work

lean lance
#

Give me a moment

shadow fractal
#

Hmmmm

lean lance
shadow fractal
#

Best would be to reach out to professionals for this

fossil nest
#

I'm lower income, waiting for disability to kick in so I was trying to avoid going through one of those tech help places if I could help it.

lean lance
#

All I can say is, there is a shitload of information on what you are trying to achieve

#

"but It's hard to tell If it's actually your own device.. We regularly get unethical requests as you might understand."

This is the problem for us, we must also abide by the server rules and Discord it's own ToC.

fossil nest
#

Lol, ok... I'll keep looking into it. I'm just concerning that if I follow one of these videos advice and like change something, I'm worried that one of these videos is going to troll me and I'm going to screw up my computer.

#

But don't worry I don't take offense to it, I understand the predicament you guys are in

lean lance
#

Thanks for understanding, and good luck. You will figure it out ๐Ÿ™‚

fossil nest
#

I understand you can't assist me with it but might you be able to point me in the right direction? Maybe a trustworthy YouTube page or something? Like I said I just don't want to follow the wrong videos advice and screw something up. If not then any advice for maybe what to look for or what to avoid as I do my own research would be greatly appreciated.

#

Regardless, thank you for taking the time to respond to me, I do appreciate it.

slate bobcat
#

Quick question - if i start streaming here my THM rooms do i risk myself being exposed ?

jovial temple
#

The Jr penetration tester on THM locked behind a paywall ? do i really have to spend 12$ a month tho learn cyber tf ?

#

HTB does the same shit

lean lance
#

Well they offer a lot of content for free, but at the end of the day they are still a business and need to make money

slate bobcat
lean lance
lean lance
jovial temple
#

well it's not much for you maybe but i don't 12$ every month to spend money learning cyber

#

there is free alternative though

#

since most of pay to get acces are just easier to handle / use on internet

lean lance
#

I would search on YT for a lot of lenghty free courses and just keep grinding the free stuff on HTB and THM

slate bobcat
lean lance
jovial temple
slate bobcat
#

Nice , i quess i know what ill be doing this or next night ๐Ÿ˜„ . Thanks @lean lance

lean lance
lean lance
jovial temple
lean lance
#

Also check other channels and their pinned messages. You will find a lot of resources

ripe copper
#

Hi, any tips for finding someone with just a facebook username?

hallow kindle
sharp pendant
old ether
#

Need help with a windows log in passcode

chilly merlin
chilly merlin
chilly merlin
#

So I got an error code when my pc bluescreened and it said: โ€œkernel_lock_entry_leaked_on_thread_terminationโ€

#

What dose that mean

blazing herald
#

what are some cool stuff i can do w the raspberry pi 3 model b+

#

any special projects or

lean lance
#

What or who are you investigating?

#

Vigilantism is not what we do around here..

coarse moss
lean lance
#

@quasi berry could provide you with information about OSINT, but he can decide for himself whether he deems it ethical.

quasi berry
lean lance
#

He will respond here eventually, he checks his pings ๐Ÿ™‚

#

There we go

lean lance
chilly merlin
lean lance
dire pasture
#

I need to create a payment gateway using APIs. Can someone help me do this? Will pay

jade gazelle
#

hey friends, im pretty new to hacking, how can one hack a DNS server?

#

(all ethical ofc)

coral rampart
#

like DNS poisoning?

jade gazelle
#

ohh yeah I didnt know about DNS poisioning, but yeah that'd be DNS hacking right

coral rampart
native sleet
coral rampart
#

Wtf?

jade gazelle
#

uhhh idk what XSS is

jade gazelle
fallow yoke
# jade gazelle uhhh idk what XSS is

Cross-site scripting is a type of security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Wikipedia

#

have you google

jade gazelle
#

thank you, so what did they mean when they said XSS on dns? dns isnt a web application?

coral rampart
native sleet
jade gazelle
chilly merlin
coral rampart
jade gazelle
#

well, gpt has a lot of false information

fallow yoke
#

what scripting language does dns run on

empty olive
fallow yoke
#

is it javascript

native sleet
coral rampart
#

@empty olive Wait I know you.

fallow yoke
#

oohh i have heard of that

empty olive
coral rampart
#

you are the CyberInfo or wtv guy

empty olive
#

shit you caught me

jade gazelle
#

world is too small ๐Ÿ˜‚

fallow yoke
coral rampart
#

yea, I watch your streams often dude.

fallow yoke
#

you're the dealer

empty olive
#

Wait really? Awesome, I appreciate it

#

I'll be back today lol. Out of commission as of late

jade gazelle
#

guys how are direct syscalls detected

chilly merlin
jade gazelle
#

I didddddd but no info

chilly merlin
#

Then ask chatgpt

crystal lark
# fallow yoke what scripting language does dns run on

A DNS server doesn't run on a language. It's a server serving the domain over the port 53. You can use servers or software for domain resolution like nginx or Apache. Also adversaries generally target the DNS resolver itself and attacks may vary. If you want to know more about them, google Cache Poisoning in DNS, DNS Takeover, DNS Amplification and Tunneling

jade gazelle
#

ahhh ok

native sleet
#

*ill tell you

jade gazelle
#

gtp told me syscalls are detected with hooks

native sleet
#

direct syscalls cannot be detected with hooks

jade gazelle
#

ohhh

#

see? gpt is wrong!

native sleet
#

they're detected because of the bad call stack

chilly merlin
jade gazelle
#

what is a call stack

native sleet
#

a syscall coming from usermode code is unusual

crystal lark
jade gazelle
#

could they also be detected because they dont come from ntdll

native sleet
#

what even is ntdll

empty olive
quasi berry
#

@native sleet you need to behave.

native sleet
#

sounds made up

native sleet
jade gazelle
#

so syscalls always come from kernel mode

native sleet
crystal lark
jade gazelle
#

what about service mode?

crystal lark
#

You mean Kernel mode?

jade gazelle
#

well service mode, where the services are

lean lance
jade gazelle
#

applications are user mode, drivers kernel mode, but services are service mode

fallow yoke
jade gazelle
#

oh shit... are they?

jade gazelle
fallow yoke
#

chatgpt said there are many modes

native sleet
jade gazelle
#

i know right!

#

I didnt know drivers are in driver mode

#

see, I learn something everyday

crystal lark
#

Syscalls can be detected everywhere. If you are talking about Kernel mode which is apparently the most privileged mode, there are syscall detections in place such as eBPF and ETW for windows services. Strace traces some syscall transitions too

jade gazelle
#

XD

native sleet
jade gazelle
#

which is where most winapi syscalls are?

#

kinda think its unusual for a legit app to do direct syscalls

crystal lark
jade gazelle
#

what if we patch etw

native sleet
#

or hijack the provider?

jade gazelle
#

wait waitwait

#

cant we simply patch edr

native sleet
#

yes! we can in fact

jade gazelle
#

I usually patch asmi by doing a super cool trick, yall prob dont know but its as simple as freelibrary("amsi.dll");

minor blade
jade gazelle
#

etw a bit more complex tho...

crystal lark
chilly merlin
native sleet
#

what is amsi? I've only ever heard of etw

jade gazelle
native sleet
jade gazelle
#

so that unsigned drivers cant be loaded you know

crystal lark
jade gazelle
#

yeahh bugs within the unsigned drivers

native sleet
#

like crowdstrike!

minor blade
#

If youre an early supporter you'll most likely have emerald and up

jade gazelle
#

exactly!

minor blade
#

lol

native sleet
#

Man I feel so much smarter

jade gazelle
#

owlsec very nice to learn

minor blade
#

0day has ruby

jade gazelle
#

happy to have found it

chilly merlin
crystal lark
native sleet
#

@jade gazelle @crystal lark are you guys both into windows internals/malware development

minor blade
chilly merlin
crystal lark
chilly merlin
coral rampart
minor blade
minor blade
chilly merlin
native sleet
coral rampart
#

yea, sometimes writing simple stuff, hby?

minor blade
#

Thank you guys for being a part of this community!

coral rampart
#

Your welcome. โ™ฅ๏ธ

minor blade
#

I've learned so much from you guys

minor blade
lean lance
jade gazelle
#

although not my main strength

minor blade
coral rampart
#

or C2?

native sleet
jade gazelle
#

oh oh im already building a c2

minor blade
coral rampart
chilly merlin
native sleet
minor blade
coral rampart
native sleet
lean lance
#

Polymorphic

coral rampart
native sleet
#

does it only modify the memory regions or the entire PE file loaded into memory

coral rampart
native sleet
jade gazelle
jade gazelle
chilly merlin
#

Not quite. Here's a breakdown:

  • Applications (User Mode): Yes, regular applications run in user mode, meaning they have restricted access to system resources and cannot directly interact with hardware. This is done to prevent applications from crashing the entire system or causing security issues.

  • Drivers (Kernel Mode): Correct, device drivers generally run in kernel mode, giving them direct access to hardware and system resources. Since they operate at a low level, bugs in drivers can potentially crash the entire system.

  • Services: The term "service mode" doesn't actually exist. Services typically run in user mode, like applications, but they usually run in the background without a user interface and often have higher privileges compared to regular user applications. They can also be configured to interact with the system in specific ways, such as starting automatically on boot.

So, the key distinction is that services run in user mode, not in any special "service mode."

native sleet
coral rampart
jade gazelle
jade gazelle
#

C2, client and agent

native sleet
#

like Remote Access Trojan

jade gazelle
#

yeah my C2 is a RAT

coral rampart
#

Nice

#

Rat's are the Best

native sleet
#

(I learnt all this from sec+)

wooden hinge
#

Anyone know any good guides on personal compartmentalization

native sleet
#

and then there's worms

fallow yoke
native sleet
#

then there are trojan horses

fallow yoke
#

I think C4 is very powerful

empty olive
#

Are we talking about new york rats? Those are yuge

native sleet