#š„ć»help-me
1 messages Ā· Page 85 of 1
Yea that works ik but i want my burp collab link to be sent
never played around much with a vpn just clicked connect and disconnect. I cpuld probably setup my own proxy

Anyone who can help me out with finding voucher for certification like CWL red teaming or any other certification vouchers.
#š„ć»help-me Advice?! š¤¦āāļøMy iCloud, iPhone, and Mac got compromised with live persistence I canāt kill. I found a Cloned drive on my Mac (obviously wasnāt meant to find files deeply embedded) that had coded file drops, VPN hops, checksum checks, and payout confirmations ā some files triggered to kill my terminal and eventually bricked my Mac, itās now stuck on the gray ā?ā. Even after resets, wipes, keys, 2FA, and a new iPhone, iCloud files still delete live off my phone. I canāt find the access point and itās alive and living its best life currently on all my shit. Anyone here rip out persistence at this level?
You sure you just didn't enter your credential in a phishing page? 
Hey guys. I have a question. I don't know a lot about cybersecurity, but I've got a couple years of experience coding with plenty of programming languages (C, C++, C#, Java, Python, Rust). I want to continue working with programming but want to start doing stuff involving cybersec and "hacking." What field and learning resources would you recommend in my case?
Oh, I wish it was that. Unfortunately, I know who it is, and they literally infiltrated my whole Mac, and it only started acting up when I found it and started parsing the files and reading the encoded commas, which clearly were involving illegal under my shit - Iām more annoyed that he acted like he didnāt know shit about technology
Hi everyone. Iām in need of a white hat . I have little to zero experience and apparently Iām an easy target. Itās been years of someone violating my network, devices and emails. The ISP has basically said Iām on my own and even though Ik this may be a big risk Iām willing to risk it just to get some peace.
Please reach out if you are a good human who can make time to help a scarred victim like me. Thank you
For the average person just following these 3 simple rules.
- Don't click on any suspicious link or download files from questionable websites.
- Use MFA everywhere
- In case you get compromised and you don't know how, reset your Pc and change all of your passwords.
Hi OX. I have an idea of how my info was obtained originally ( by some people I let stay at my house due to being homeless. Friends of friends) but resetting passwords, using MFA may be a bandaid on a missing limb at this point.
isps lwk suck, they rly dont gaf about the stuff that goes on
It's called having layered security. Your "main" security step is not having any kind of malware or enter your credentials in the first place.
And if that fails you better hope the other security measures work for you.
You can also harden your system, but that's going a bit too much into technical detail.
Would it be smart to double check ur router for open ports or vulnerabilities at this point?
Iām at ground zero right now. Please give me the nuclear option. They use my sister voice to make calls to me when they havenāt actually called. Itās scary and beyond anything Iāve ever imagined
ISPs and standard support wonāt do much once it goes deeper than surface level access. First step is to document everything: device logs, iCloud sessions, look for odd network traffic. From there, focus on eliminating possible entry points (startup items, profiles, VPNs, hidden certs) and confirm if the activity is tied to the account itself.
No open ports. I checked.However our devices not all at one time. Make 40 plus hops to connect
Sadly the calls may also not be because of the intrusion, AI voice calls have been growing, even those with familiar voices
Do Your calls come in with an actual phone number. If so I can run and get the ips and trace them even with vpn
This is interesting is there a how to for non gods out there somewhere that I can do this myself? Or a company that I can hire?
You pick phone calls from random strangers, because I don't
lol you sound like me I just posted that in another chat
It does but itās a spoofed number . Itās my sisters actual phone number as far as I can c
lol same
Yeah scammers lwk got hella good
I'd honestly tell everyone yk to text you before calling first
No I do not. Itās my familyās number that shows.
Are you an important person? E.g some kind of CEO or someone that has a high position?
Oh shit, I mean if it was an SMS you can back door the metadata but other than that if itās phone calls, itās gotta go through your carrier
Because going so deep is usually reserved against high target profiles.
So wait, some people where allowed in your home, and that's when it started?
There wasn't anything else you noticed?
Iām over here given advice yet I canāt help myself bc my ex is way smarter than me apparently haha
They would have to know how to access or at least have the password to the Wi-Fi to access the router if they never logged into the admin and changed the password
They also could've just bruteforced the password, I'm also not really sure what their exact issue is, it could be malware that moved laterally, or could be leaks, i have no clue
Honestly they also could've just accessed a device in their house as well
Itās been happening since I let them stay at my home but they have ratcheted up their attacks this last 2 years.. Iām not an important person and I feel like Iām physically been assaulted. So if anyone can help me or can recommend someone professional to help me I would appreciate it
That'll fix the calling issue but I re-read the original post and it sounds like a shit sow, emails, devices, a lott
For years is insane
I think they have the device serial #ās as well but I like the way u think. Hmmm
Thatās why you hard reset the router which will suck ass if you have a lot of smart things in your home bc you have to reconnect it all
Have you blogged into your router ip to change the admin
Proffesional service, especially for forensic can cost you over +$10'000 easily lol
Damn, Iām in the wrong profession
I have actually changed the router 2 times and have a new one in a box looking at me right now
Like I said, your best bet is just to reset all your devices if you are that worried about it.
Well set that up lol
Itās looking at you saying get that old shit out of here
Also jumping from a router into a different device is quite difficulty anyway.
It's not like you can gain access to a device just because you have access to a router.
If it makes you feel any better Iāve got a live listener on all of my shit that I canāt kill
What š
Yeahhh I posted for help bc I canāt help myself!! Deeply imbedded in all of my shit
jesus
Side note itās my ex and I did find out parsing his files he injected on my Mac heās been banging my brothers wife wilddddd
Sorry. I obviously can relate
Jaw dropped to the floor.
How exacly did you find that out?
I have my doubts with that story.
Also why not j call the cops if it is true?
Check yours msgs
Because I didnāt know exactly what was being done. All I was reading were these conversations that were in code words I can show you a snippet I donāt know exactly what they were doing, but it was very telling that it wasnāt legal but what am I gonna do Iām not a snitch. Iām from Jersey unless it involved harming other people, but I never got that far because he crashed my Mac
- Tunnel is stacked. Triple layer. Exit node clean.
- Receipt confirmed. Ghost account will cover payout trail. Those are two snippets from raw dumps- and I have no clue what was being done so idk
That sounds more like you shared the device with him and he has also his account on it.
No, we live together for years and he always acted like he never knew anything about technology, but my Mac was in my office and it wasnāt locked. I didnāt think he really knew anything. Honestly he fooled me but I shouldāve known because he would always talk about āthis kid at work.ā who knows everything about hacking. He literally cloned my hard drive so he was controlling my files and his files that were embedded.
He hasnāt had access to any of my tech stuff in well over a year and heās still to this day currently is remotely on all of my shit and I canāt get him off I literally took a video with my other phone and watched all of my files. Get deleted one by one as if I was doing it. It was bizarre.
If he has unwanted access to a device, it's not legal, saying your from jersey is a strange excuse for an issue that's fixable
Honestly I have my doubts that this is possible. If you factory reset your Mac there is no way that he has access to it.
What am I gonna do? Bring my phone to the cops and say what? They donāt care about that kind of stuff out here not to mention heās friends with the chief of police so heāll get notified before anything happens anyway. The jersey stigmas are alive and well.
I mean there is ways but I think it's very unlikely he's that skilled in the field
Bring your mac to the cops?
not even
/#
I canāt factory reset it itās stuck on a screen with a blinking gray question mark
Tell them the situation, just do that and see what they say
If he IS friends with the cheif that is probably goiung to be a thing lwk
Well then go to you nearest apple shop and let them do it if you don't know how.
My Mac is dead. I canāt get past the blinking question mark I tried all of the hot keys nothing worked I even contacted Apple and try to report it to Apple and I saved my conversation and there was nothing they would do.
Can you even swap storage on a Mac?
Apple in general is very restrictive what an enduser can do.
Oh fs but I think some of the oldish ones only had warranty voiding stuff blocking the user
it looks like post 2018 macbooks have the storage integrated into the logic board
but pre 2018 is good
You said you did hotkeys, did you enter recovery?
Thatās a picture of the cloned on my Mac once I tried to delete it. Shit went South.
That looks normal to me?
I'm not a Mac pro, but if you erase your disk, I assume it doesn't touch any important system files?
It doesn't
You'd have to manually do something like reformatting to wipe it all
but that would make the mac useless so
When I do a fresh Windows 11 installation I erase everything, including the boot section.
Untitled 2 is a clone
That's the storage name
Yep I tried rebooting from bios itās just stuck
You can change it to whatever
No thatās not mine
Does your model have a physical drive you can swap?
Ohhhh
The other one is for emergency recover
I was a bit confused about the Internal and Disk Images
can someone help me, i ask my friend for a project and he made it for me but heres the twist he used pyarmor to encrypt the file so can someone help me decrypt it
So I guess the Disk Image is the one that contains all the important system related files used for the boot process and other critical component while Internal is just your storage
Untitled 2 had full system folders (/System/Library/, /Users/, /Applications/, /private/var/), same timestamps as my main system, plus my caches, crash logs, and Keychains. That means it wasnāt recovery it was a literal full mirrorclone of my active drive that I never created. Not to mention the date it was created was last year and my Mac is four years old.
that sounds like normal default folders?
So you can nottttt physically change the drive okay
OK, whatever you think doesnāt make a difference not trying to prove myself or anything to anybody I just wanted to get it back and running and I canāt
Yea probably because you erased some system files
Yes, definitely
You can reinstall macOS on your Mac while keeping your files and user settings intact.
Eh 2 different varients depending on your CPU
Can I? Maybe you can walk me through it on bios clearly I havenāt tried
Just follow the instruction
when I tried to remove the āallegedā clone untitled 2, I corrupted the boot process and removed the Macās ability to find a valid system.
Thanks for the insight teh boon
Kenji you have been warned before about unethical practices. I am watching you š how do we know you are telling the truth?
Can't we get a mod to ban him since hes been warned before?
@mossy pecan need more info here. Why do you need help if your friend supposedly encrypted? Why would you ask us if he gave you the project to do?
can someone help me or give me idea of how to make hcaptcha solver
Answer my questions
The ones I tagged you in
he gave me a file but i ask chatgpt whats this file and chatgpt said its encrypted with pyarmor thats why im here to get some help decrypting it
i thought i can get some help insteadd im being question
Pyarmor is used to protect code. Decrypting without permission is unethical & illegal. You have asked for unethical help here before. Honestly, I do not believe you. You need to stop
im so sorry
š
can you help me how to make hcaptcha solver instead
hotami
i need help with this question on tryhackme.com dns in detail : What type of TLD is .co.uk
Not if it's malware 
United Kingdom
5 character limit
For what? What will you use it for. Pick your next answer wisely.
@mossy pecan answer

Please stop questioning meš
im going to use it for my project
What project
Damn some of you are ruthless. Donāt be cyber bullies #notcool
People need to follow the rules here and not try to bypass them. No bullies here just protecting the flock, thanks
Sometimes itās not what you say itās how you say it
Good morning
Thanks for your opinion. Sorry for your misinterpretation š¤·āāļø
@fathom summit I donāt believe it was my misinterpretation. I pretty much verbatim took it for how you said it. I just have a weird feeling if you were in person with whomever you were talking to you wouldnāt say it that way to their face. Thatās all Iām saying if you wouldnāt say it to their face, donāt say it on the Internet.
Not in here
let mods do the job people, the reason we're asking for intent before providing service is because we are a partnered server, if anything remotely unethical/illegal gets assistance or a stage here it's on us
Still kenji?
yes why
are you getting tired of me
You are hostile AF @fathom summit
Start at the beginning
Learn all the individual things you need to do what you want to do
but you cant really change the fate when you need some help
^
I don't think you "need" to cheat in mobile legends, or break other people's encryption.
These seem like Wants
i didnt mean cheat
There is a difference between asking for help and just use google.
lets forget about that
but this is your end goal
But I can't if you are asking right now to break someone's encryption, not even fully understanding what the language is you are trying to decrypt into?
If you ask a new bad thing, then people will think of all the bad things that were asked.
yup and this isn't the first time that it happens, again: we are an ethical hacking server. we don't provide services to others or guide them through an entire operation.
to some degree people have to pull most of the strings, and we help from time to time with questions that are straight forward and comfortably answerable, but not when it comes to unethical/illegal activities.
Hi guys
would that happen to be the very same friend as here?
#š„ć»help-me message
Yh
With Discord
how do i transfer my terminal from vm onto my desktop. like a new tab but terminal
A song from the band R.E.M. with lyrics
Sudo apt install opsec doesn't work
Who said that?!
Anyone wanna guide me I'm about to start
Hey best of luck in your journey start here #š„ć»new-member-guide
I get that alot o just need someone to see since i won't understand most stuff
You want the honest, or the nice answer?
Honest
Keep doing research and learning. It will click, keep trying. You got this šŖ
Noone will
no one will. I see that question daily, and no one ever volunteered.
I mean I'm not that good at English and it got alot of talks and learning a new thing and lazness-AHHH
There's a chance
There isn't
That is ok. You can still try my friend, if you are really passionate & intrigued about learning then you wonāt be lazy.
It's still pretty hard honestly
lazy is fine, means you are likely to think about doing stuff more efficient. But this isn't a field of shortcuts and walkthroughs
It's not entry level, that's why
Basics are the actual hard
Since if i know the basics I'll learn automatically when progressing
And the less likely you are to research on your own, the more likely this would be a drag for anyone to teach
You got to start somewhere & grow. Donāt make excuses, lock in š«”
Imma try
That is the spirit, you got this
Works for me
How do I go from being a script kiddie to an amateur "hacker"
There is no definition for that.
Okay I'm just gonna read some more documentation then
That's how you land in tutorial hell
Okay then what the hell do I do
You have to mix it with reading and practice lab
Depends what you want to know. Cyber security is big
If you wanna attack Active Directory, then your read about them.
what
hey everyone! šš»
anyone here who has a broad knowledge of the secp256k1 ecc?
Guess someone will stay being a skid for the rest of their life 
Where can I read them
I mean
I spent the whole day yesterday figuring out how to install kali-linux WSL
Where can i read them
He didn't answer me
The first thing you should learn is to use google for simple questions
What for
you gave him 20 seconds.
everyone is a skid
Okay I'm just gonna ask chatgpt then
never getting far
Brain gon shrink this way
@rotund star that is unethical & illegal and we do not condone in unauthorized access. Please read the #šć»rules
oh no this is going in the hall of skids
Well gues he's never going to work in the industry with that approach 
too late for him
Okay sorry
i had some questions regarding the curves structure which i couldn't find elsewhere especially on BitcoinTalk or other platforms.
ChatGPT, google
oh hi kvts
hi ^^
doesn't have the answer, ofcourse i tried them š
Goodnight im going to sleep gng
Good night š
hey chat can someone help me with sending a GET request plz?
If possible then can you elaborate that
Generally sending any request we use burpsuite, but I will have to know what are you exactly talking about
Are you getting error through burp?
im on tryhack me doing the viewsite
Make a GET request to /api/users. What is the flag?
?
Ohhh from your description it seems like a API exploitation
Well so Get request is a kind of request that your browser sends to the server to view the content of it
Here the target has /api/users so it is using api
And you can send a get request to it through cURL command and then pipe it to jq like this:
curl āhttp://target.here/api/usersā | jq .
It will show a nice JSON output, maybe flag will be there or you might have to find other api endpoints
hmmm thank you for this i wish you could give me a visual
so there's this dude who created an instagram account pretending to be someone ik and he's out there spreading misinformation about her
i tried reporting the acc for "pretending to be someone else" but instagram doesn't think that acc goes against the community guidelines
a scammer had tried doing the same before in the name of someone else but that time, the acc was removed in like 10min after reporting
what do I do :/
There is not a lot you can do, if meta support decides to do nothing.
Signed up for HTB been doing a few modules but am running out of cubes, I started with 40 cubes and am now down to 10. Is there a way to get more cubes and if possible for free? I'm not trying to spend heaps of money but also dont want to keep shifting between htb, thm etc I mainly want to kind of finish one before I do the other. TIA š
when finishing certain modules
you get 10 back
Yea I knew that but that leaves me in a loop between 30 and 40 cubes Im wondering if I can earn cubes somehow or something instead, thanks for the answer tho šš¼
No, you canāt
You have to pay
no worries tho
Yea damn that sucks then. Alright thanks anyway
just do Tryhackme lol
-# (goblin pls donāt kill me)
yeah.. bummer.. but if you thought asking that on a hacking oriented server would net you a different result, then the answer is no, #šć»rules no. 3
yeah
:/
i thought of just sending him some convincing link cuz atm he doesn't suspect me of anything
might as well try to get access to that account
Apart from being illegal, it's also simply that every buffoon comes here, daily, asks the same question with a sad sob story no one can verify and tries to argue like he's talking to chatgpt
ah
well it is what it is
i could just give you the fake acc and the actual one
it's pretty obv
you can also just drop the entire line of question, and get to stay on this server.. cause this shit ain't flying
ah
the #šć»rules have no subsection "unless you dont want to, ofc"
i just asked it here for the sake of getting suggestions
i don't want no "hacker" to do the work for me
i ain't tryna rent a hacker or anything duh
sure thanks
Hey guys Iām new here
Hope all is doing well š©¶ā¦ļø
Really on a beginner level what would suggest I start with on a full scale learning aspect?
Well If you need help or want to know how to hack
#š„ć»new-member-guide #š„ć»help-me #šć»free-resources are here
What vpns would you rate the best?
Mullvad
completely anonymous, letās you literally send money via envelope with no return address
Servers are ram based
No logs
I just come into cybersecurity recently.
Please give me top resources I can use to learn effectively and efficiently
can someone please help me this "Bluestacks requires at least 6gb of free disk space in C:\programdata\bluestacks_nxt drive to install"
check ur storage dude..
what
kind
of question is this
Mullvad
it is more like a note than a question
are you telling or asking
free up some storage brother
the error details are there
unless you're looking for a workaround if that is your end-goal?
got doxxed 120th time now
how?
anyone who can give pros and cons of code dex?
No
And yes
Ive spoken to one of biggest discord d0xing usser the og owner of infosec and yes
Report them to the police and talk with your perants
I promise you the longer you wait the worse it gets
Like ive seen enough extort cases
And the victim never gets in trouble
Why does sudo apt install opsec not work
it's a joke
Is chrome good opsec
are you joking or are you being serious
seriously joking
fr0stbyt3s got hacked and his discord account got compromised but he is on it and when his account is clean would it be possible to unbann on this server?
who just said that?!
I saw a guy saying sudo apt install opsec in a tiktok comment section
yeah nah
don't rely on tiktok for cybersec
the entire platform is literally mostly bs
hence why i never bothered hopping in
the app itself is dedicated to make you doom scroll for as long as you live
lol itās banned in my country
better that way honestly
it's not banned here but i have never ever registered a tiktok account
i never had tiktok and never will
i feel proud saying that lol
me too
Whats the difference between that and instagram 
none honestly
i don't do instagram either
they are both dedicated to make you scroll
Designed to steal your "Agency", and allow you to have less control over that part of your life. Kind of like doritos.
How to get virtual numbers ??
Apps
I had a phone addiction but 3 to 4 months from now I deleted everything and now I have so much more free time
I don\t even want them anymore
Which app kindly mention
2number
If you need help or want to know how to hack
#š„ć»new-member-guide #š„ć»help-me #šć»free-resources are here
Available on playstore??
Yep ill send you the link
oh I know this I used it
there were a tool compatible with linux that I used to sue to get free calls and spoofind for free š
but it got banned or patched or idk
Ty
good evening i pretty new here
i want to learn coding but dont how to start
any suggestions
thank you
@woven anvil btw last time when you were talking about flashing kali with rufus is bad
were you talking about only for kali's case or rufus as an app
Thats the context
DD mode should work in theory, but the regular mode ignores the standard to "automate" some things, which can break some ISOs
not just kali, there are other distros too - I just don't use rufus anymore if I can help it
Not saying it is a problem for every OS image out there though
yeah, thats why i linked the topic. ^_^
hi i need help
helloo, what do you need?
Can you send me a DM
I usually don't talk on dms
But what's up?
Are you looking for some specific topic? Maybe i could help c:
I don't how to explain that thing.
he probably needs his exs insta acc back, yk, the usual story LOL
ofc you donāt, thus whyād you want him to dm you
If you donāt even know how to phrase your question
or why ask if you donāt know how to ask
That's what I thought
There's a channel for a reason
I don't mind helping others
Literally the acc was created in less then a week, I'm just being careful ;)
If people want to go to DMs on a hacking-centered discord server they simply want to evade scrutiny and nothing they say is truthful
"I dont know how to explain that thing" is either an obvious lie, or they should come back when they collected their thought
Like showing up at a restaurant and telling them you really dont know what you want to order
I can't understand the Hack the Box fawn challenge in task 7
You are on the HTB discord and have not asked there?
No
I know that you have not, the question is "why"
its their content, ask them
people are getting dumber by the day
you are literally named "batman htb" ffs
I know what the question is, and I know the answer, but it's showing me an error message.
And what made you think "Hey.. I better not ask the people actually offering up that task.. lets go over there to some random other people instead"?
That's no way to go through life, son
i promise i researched the plymouth thing after you talked about it
who better to teach than the people who made it, great courses
chat how do i flash linux onto an android :D
Holy shit š¤£
You need to have a jailbroken phone first
To fully use linux on it
Or if you want just termux
Android is based on the Linux kernel. What are you suggesting you want to do with your Android?
Anyone familiar with instagrapi?
What does the ātargetā in VM target mean?
context?
No like what is target?
A software or operating system? Smth like that?
Also how do yall manage the cubes in HTB academy? Subscriptions?
I understood your question
Now tell us where you got that from, give us some context to your question
Oh I was in HTB academy and they told me they have two targets and their names
But I donāt understand what target itself is and so I asked
I've never used HTB, but I assume it means that you connect and in your network there are two virtual machines, that are your target. Maybe one server, one client
target in htbās context is the ip address of the server you need to attack

Also how do I manage the cubes
HTB has its own discord server, maybe join there
you pay cubes for unlocking modules. each module you complete youād get some cubes back
but if you want to do advanced modules then you need to buy cubes
I new to this, i need some help, why does the NTLM sends a random number to the client to do verify, why cant it just verify the hash?
neither NTLM1 or 2 are mere numbers.. how sure are you that you are really looking at NTLM?
i saw a graph that shows how NTLM works, and i saw it sends a random number back and i had no idea what the random number do
it says that it was suppose to be a challenge, but how
I don't know
-# why canāt I put images here?
The server authenticates the client by sending an 8-byte random number, the challenge. this is what Wiki says, i don't understand
or doest it means just send 8-byte of random string?
.w.
I don't know where you saw that, nor what server or client you speak of, but nothing about that sounds like ntlm
this make me even more confused, isn't that how the challenge-response authentication works? or i am completely wrong
not with 8 bit it doesn't
ah.. I see what you mean
In a Windows network, NT (New Technology) LAN Manager (NTLM) is a suite of Microsoft security protocols intended to provide authentication, integrity, and confidentiality to users. NTLM is the successor to the authentication protocol in Microsoft LAN Manager (LANMAN), an older Microsoft product. The NTLM protocol suite is implemented in a Securi...
I want to learn OWASP Top 10 Web 2021
I want to learn it in a way so that I can able to explain to anyone even layman.
- Definition
- Root Cause
- Testing Techniques
- Impact
- Mitigation
- Code Example (secure vs insecure)
I'm just being stupid, I understand it now, thanks for the help
Helloo! I'm looking for notes and practical exercises to take the AWS Certified Cloud Practitioner exam. Does anyone happen to know of any good sources?
I tried rooting it and that didn't go well so it just bootloops now
so I decide I'll just flash like debian or something instead of stock
I want to flash a more standard os instead of stock, since it only bootloops rn after I failed at rooting it
oki
Flash TWRP recovery and there are options to flash different OSes like GrapheneOS or LineageOS, but I suggest researching first. With TWRP youāre able to flash and install any OS or app like Magisk for rooting.
any good tutorials for that?
also my phone's an a/b boot, would that change anything?
Just search your Androidās model and how to root, there should be some wikis or video tutorials on youtube
uhhhh the only tutorial I found was one singular dead xda forum
actually that's how I got it boot looping in the first place
What is your phone model?
REVVL V+ 5G
wasssssuuuu0ppppp ppplll
Guys i need big time help I have been so burnt-out on learning the fundamentals of Cyber Security since june. Legit I feel like Im just constantly learning simple things and not actually getting to the practical side. What should I do?
Are you going to school for it or are you being self taught ?
?
just learn what you need until it's over, once you do you can get some hacking related knowledge
where are you learning?
Gonna start uni for it but self learning rn
Iām using try hack me rn on pre security so close to the end but Iāve been on it for ages. Iām start uni for Cyber Security tho
yup that's how it is
Oh ok I donāt have any advice for you because Iām about to start my journey Thursday Iām going back to school
Iām going to do computer science
First
you'll keep learnin fundamentals as you go as well
sometimes you'll stumble upon technology you're not familiar with
and you'll need to hack it, to hack it you first need to understand how it works
a lot of the time hacking flow becomes faster due to the person knowing what they're messing with
i wouldn't be able to hack an active directory as much as i'd be able to hack into a web server
that's a lot of reactions lol
I appreciate it very much thatās why
Yh I fully understand you I just canāt wait to finish the fundamentals to finally start hacking something practically
The power of understanding is profound . Knowing and understanding is distant from each other
Rn I just need to lock in and hopefully finish pre security by next week and any other relevant fundamentals thanks @lost vapor
Do you do any activities to increase your thinking power z? That may help
Wym like reading?
Such as chess , reading , fasting , pure supplements , nutrition, and sleep
Yh I mean I do reading nutrition is 50/50 and sleep is not very good rn ššš
Play nerd games on steam that teach hacking or networking concepts for fun
Like what?
If your mind is not there you wonāt be all that you can be . You need nutrition and sleep unless you canāt and if you canāt you must just bear a great attitude and try harder
Turing complete is good for understanding hardware/ how a cpu/ram are made
Tower Networking Inc gets you some interesting network practice
Shenzen I/O is also interesting for integrated circuits.
Ohh damn
Your right
Thanks so much both of you @woven anvil @modest sluice
obviously, games will be unrealistic, but its a nice "fun time activity" instead of your 5th games of valorant, or whatever people play these days
Your welcome Z
Games like Screeps help practice programming(using JS š )
Yh 100% theyāll teach you things rather than make you waste time
Ok
Thanks so much bro I appreciate it loads
Well it's too late š
anmd
whgat have u learnt
already
@lyric ibex first -> you hit the back button -> scroll down to rules -> select that -> then you read the #šć»rules
@shrewd larkwe don't help with those type of things over here, read our #šć»rules
Ok so im now going into my last year before university and I am currently leaning towards working to becoming a pentester/red teamer etc. etc. Now I have 3 options: 1. Go to one of two bigger Uni's to do a bachelor in Computer Science, then I can do a master in cyber security or just continue my work after the bachelor. 2. Go to a smaller uni to do Information Systems, one plus is that it's close to me. 3. Go to a other big uni to follow a cyber security bachelor which is new this year. What do y'all think?
I think so far my preference would be 1. but I wanna hear what you guys have to say
i've gotten into pentesting and hacking without much of computer science, all depends on what field to you want to excel in
I mean im not that educated yet but red teaming seems like something that I would really enjoy doing
And right now I am working on getting into bug bounties myself
But the thing I was thinking about was that in my view Comp sci is a bit broader and after I can specialize
no need for any compsci stuff, learning hardware, networking, OS fundamentals, and some programming should be enough
if you do wanna go by that road because you're interested in the information go ahead of course, but if you fear that you'll miss out on something: trust me you'll be fine
don't take it only from me of course, you can check out google or even ask preplexity on that
i rely on ai to some degree for relevant information
Im not in the usa btw so its different
me neither
and helping people with school work all the time
it doesn't seem that the pacing is much better in a bunch of places
My idea was just that with compsci u can go all kinds of ways and if I do a bachelor in cyber I immediately specialize
ah ok
Im working on those basics already myself now
Imo, the pacing of the classes are much better when you already have an understanding of the fundamentals
tryhackme -> hackthebox -> homelab
Understand how to:
- Install different OSes in VMs (Windows/Linux/BSD),
- Make a segregated VM network with its own VM router
- Use something like python, and find projects to do where you can implement python into it, like a "server manager" for a game or something.
- Build a computer( or how hardware works in general.)
You will learn way faster doing it this way, and you won't be in a position where they are asking you to use ubuntu in a VM, and everyone in your class is having trouble with it because everyone bought gaming laptops with 16GB of RAM and it can't run windows + web browser + an 8GB ubuntu VM because they want a GUI, and so nothing gets done.
The best part about school is the ability to interact with your peers there, and strengthen your knowledge by helping and tutoring others. After doing something 100 times, troubleshooting weird issues or setups by people making mistakes, you get a strong understanding of all of these things, and it helps you a lot when it comes time to sit down and learn a new concept on your own for whatever cert or job or whatever you want to do in the future.
Thank you for the info! Seems like im on the right path then lol because I've started with some of those things already
I am following the mooc.fi python course and I build pc's for a living
Also setup multiple vm's with kali and arch
and mint
also doing thm
Hello evry1
please i need a mentor and some1 who can guide me tru my projects
its not fre thoigh! lol
Nice. The "Segregated network" is an easy one, where you just work inside whatever hypervisor you are using, and make VMs to act as the "Gateway", or the "DHCP" server, or whatever other part of a router you want to learn about (these are just debian VMs, but you could use any linux, BSD, or even Windows if you hated yourself)
got a new role after so many years of interviews ....
Interesting, ill look into it!
Forgot screenshot
These are on 2 virtual bridges.
1 for "WAN"
1 for "LAN"
Can think of a Virtual Network Bridge as a "Network Switch" emulated in CPU.
Any1 with 3rd party experince ?
We don't really do Mentoring here. If you have questions about specific things, then feel free to ask them. But we recommend to get a deeper understanding, starting somewhere like here https://discord.com/channels/990435451334688768/1306084252437450763
thanks @woven anvil
Hello
Are you trying to create a virtual network
Nope. I was responding to someone else.
like my WAN IP? š
Yo jeevis if you're interested check this out
My friends and I use it for project
I'll dm it
It's a lot
Can someone help me in regards of my home network, it was compromised, someone rewrote the admin page for my Motorola router, I canāt find a .bin file online, the ISP is not assisting me , my coax cable is acting as if itās an RJ45 , my identity was stolen also
Ive come to conclusion per wireshark scans, it appears someone did a MITM ARP Spoof attack
If not, I understand
Hi everyone can someone please help if possible. How can i log into my yahoo account, i lost a contact number long time ago where they send verification messages and doesn't allow me to login using other options. Is there anything that can help me?
Thanks!!
@lost vapor
holy skids
call in your isp
manifest it
Send them a mail! And wait for the rare case to happen ātheir responseā
If you donāt receive any help, best option would be give up TikTok! Less best option would be create a new one
Thanks for your question š
Anyone has ios spyware software or Pegasus??
whom do you want to spy on
I got project for android and ios
a project of making a spyware? i donāt believe that
You have or not??
If you have then kindly give me that
or what if i donāt? 
do your research first dumbo. pegasus isnāt just random script you pass on discord servers. plus distribution of spyware and anything unethical is against #šć»rules
Then that is your choice what should i ddo
I know its illegal
but you didnāt know the rules
Ok thank u
bro
LMAO
find it yourself
it took me like 1-2 months to find Pegasus
sample n source as much as possible retrieved
- itās not effective anymore
Bro anyother that is worth effective
nothing thatāll be free
or public
Ok boss
Stop talking about this dued
the whole point of a pegasus or the main idea behind it is that it's hidden from any public access purposefully, finding one is a big deal and what you'll find on the internet like any other type of malware would be detected and not work anymore.
people just forget about that when talking about these stuff
either that or they just don't really know to begin with
whatās your project anyways?
nobody has this
and no. you dont have pegasus
you have a malware sample taken off of an infected phone
you do not have the source code, binaries, or infrastructure to the actual control panel
infras to the c2 obviously not, I told you I attempted to retrieve as much of the source as I could
sample is obvious
yes so you do not have pegasus lmfao you are basically saying "oh yes i have lumma stealer because i went on malwarebazaar and downloaded the latest uploaded sample and reversed the source"
but you dont have the infra or backend control panel, making the sample useless and only for research, understanding and IOC collection
^^
so idk why u say "i have pegasus bro took me like 1-2 months to find pegasus bro", like u actually have access to the whole thing
.
read the entire thing first lmao
yeah ur making it seem like u have the entire pegasus setup, control and builds
when?
unless you literally misunderstand what the guy was originally asking for
I literally clearly stated I have as much of the source retrieved as I could and the sample
I very clearly stated
yes from a sample which is useless
what you hallucinate out of the literal words I said is not my problem
he didnt want a sample of the malware
that was the original question
he obviously doesnt want a sample of it, guy probably couldnt even jailbreak ios 14 successfully
he wants the full thing, to be able to use it against people
you, then saying, "i have pegasus man it took me 1-2 months to find it" implies you literally have full access to pegasus control panels and builders
/exploits etc
obviously from that 1 message. Thus right after that I said sample and as much of the source as I could retrieve
I very very explicitly said it
youāre still going of implications āoh you said this so letās ignore all your other messages and say youāre wrong with like less than half of the entire contextā

when you say "as much of the source as i could retrieve"
are you referring to the backend infra or again, the samples of pegasus
because if you're referring to the samples then that is what i mean, he doesnt give a shit about that, and those samples have been heavily reversed and documented by other people over time
my point is that you just saying "oh i have pegasus yeah"
you dont have pegasus you cannot use pegasus
you have samples which were used in campaigns, you cannot use them yourself
why do you care so much? it was made clear heās not going to get it from here anyways, if the third party has the source or not
question is already answered
to avoid people from claiming they have shit that they dont
helps avoid misinformation, scammers, etc
iām not sure how thrashing someone over something they claim is doing any good to this channel. if you want to report it or something there are channels present lol
as if Iām gonna sell it first of all
Second of all
I told you I clearly mentioned things
Iām going off of clear facts
Youāre going off of implications
which you created yourself
No LMAO
Which you interpreted and hallucinated
did you assume he was literally asking for samples
or the entire infra to be able to use pegasus
Assuming doesnāt lead somewhere always
you have samples
as you can see, right now it doesnāt
Wth is happening right now
two completely different things
heās going off of implications
saying I donāt have Pegasus
She literally wrote she has samples lol
because in his opinion itās the e entire thing
Hey i just got called by someone who calldd with their own number and the person said my name and some random stuff (prob someone that knows me), how can i gather information about a number?
not sure but if you want popcorn ive got it 
find WHAT yourself
Find IT
literally can mean either
We don't assist with those things here #šć»rules
Itās yku assuming I mean samples
police. no other way
im sorry
my point is that you cannot "find pegasus"
it is literally not publicly available
alright ill try that
All good
And my point is that I donāt have the infrastructure to it but Iāve obviously already mentioned it
I said what I do and donāt have
You keep saying āno you donāt have it because even though you didnāt say that you have it you apparently implied itā
I have not implied anything
the other guyās going about attacking her with a question that is already answered lol
^^
you saying this literally sounds like you have everything you need to use it
is all im saying
yes, and I agree with you
yet you still take things out of context
BECAUSE
right UNDER this
I type the following
.
That was my message right under
so I have no idea whatās your reason for taking things so blatantly out of context
whether to defame cuz youāre bored or to spark some things up
Iām not wasting my time more on this anyway
which can also imply that said "source" you're talking about could be either backend infra or samples
have a nice day
idrc im just saying what you said in the way you said it made it sound like you have shit that you dont
hello i was looking for help i saw one of the last videos that talked about iphone security and how to check it through the phone app using codes when i used the 61 code the first option was enabled and when i tried to disable all it said there was an unexpected error what should i do
Is asking to be paid in bitcoins normal for a hacker?
usually crypto is preferred when it comes to underground sellers yeah
though if you're looking to "rent a hacker" or something, chances are its just a scam
True
Whatās underground seller?
cybercriminals who sell malware, fake phishing pages, databases, etc
uh, yeah usually lol
Thanks
"Hi, I am the new information security officer, and I have full confidence in my capabilities. I also would like to be paid in bitccoins" š
somehow i got my number leaked on a server what precautions can i take rn? they are signing up to apps and im getting tons of otps any suggestions/advice
change ur number
eject your sim , take 100 grams of gunpowder , put you sim inside a pich with gunpowder , take 1 liter of oil , burn the bag and spill whole oil on it
problem solved
Question about Kerberos, after you send a requested and id to the server, and it sends a respond that is encrypted with TGS, but the client doesn't have a key to decrypt it, then how is the client be able to read the message
the TGT doesnt need to be decrypted by the client
the AS wll include a session key which is encrypted with the clients own key derived from their password, thats what lets the client continue
Hello greetings everyone
š
but the second process it sends a ID of service request with it
i don't understand why it sends the same thing twice and it's only used for two times
its not sending the same thing twice, its that the TGT is a reusable token, the TGS will just forward a fresh authenticator, which prevents replay attacks
so the message that doesn't need to be decrypted is only used to be authenticated by the server?
but it kooks like the client sends the whole thing back without doing anything to it how can this help with authentication
yes
the ticket itself proves auth, and the authenticator proves the client is active and holds that session key
so does it means that i need both of it in order to pass the process
yes both parts are required
can i do the same thing that is use to cheat NTLM, by just hijacking the two message and send it to the server
i was thinking this, because if the process only verify the result isn't it pretty mush the same thing as NTLM
kerberos is designed to prevent this by using its authenticator, its session keys are used only once per ticket request, and the fact that tickets expire
the authenticator for kerberos uses timestamps so, that wouldnt work in a replay attack
no because of the authenticator
but if i hijack the message with timestamp wouldn't it work? or that's simply not how it works
I am trying to make exploits for spesific CVEs , but I cannot find the exploitation details just a brief description which is barely usable, where can I find exploitation details
gotta search for it the right way, eventually you'll come across a PoC
what's the cve for if you don't mind me asking?
ctf?
Oh wait, because when you hijack it the time stamp will expose you so it wont work
thanks man
Tomcat RCE
CVE-2024-50379
are you exploiting in a ctf or?
lab?
room?
box name maybe?
No I'm just making CVE exploits to upgrade my skills
the cves are already made
me who just found one
In python?
Gimme a sec
cve = common vulnerabilities and exposures
Oh yeah didn't check that one
I know what cve means
However not every CVE has a poc
yeah just clarifying these stuff are known
you said you wanted to make a cve
it's different
No
you're right
I said i wanted to make an exploit for cve
ohh kk
I struggled with latest CVEs so I assumed it didn't have one either
Thanks for the help
even latest cves can have PoC's
just gotta search a bit more
i am using duckduckgo as my search engine btw
i find it to work better when i search for stuff like that
Yes but CVEs that came out days ago usually don't I get the point tho
a lot of the time, you wont find those details as they are commonly not disclosed
most you could do is download Tomcat versions before the patch occured, then after the patch occured, and diff the two files to see what was changed
Guys how to hack lucky patcher ?
elaborate cuz this question makes no sense
lucky patcher in and of itself is a sort of cheat, allows you to get multiple gems/bucks etc in mobile games
so what do you mean you want to "hack" it
It was a joke
hilarious
Yep I'm trying to avoid that and that's exactly the problem I'm facing I was wondering if any of you knows somewhere where such details are exposed
no, it doesnt exist
those types of details are usually found by patch differs who reverse engineer the patches to find a way to make an exploit
then sometimes release a Proof of Concept exploit
PoC is usually only released after a patch i believe(though not everyone would follow the rules)
it depends on the exploit though, if its an exploit for something that nobody seems to use, theres not going to be much interest for it
and therefore not much research done into the actual patch and going even further, making an exploit for it
I see
however if its something interesting that can affect lots of devices, or perhaps many company networks use it, etc etc, then it will have more research done and potentially more POCs
That means I'd need to spend like a whole day trying to make an exploit?
you'd probably spend more like a week just reverse engineering the patches
If your plan is to make exploits, then yes, you would be the one making the exploits(instead of just taking other people's)
potentially more depending on the complexity of the exploit/patch itself
then after you understand why the patch was implemented, and how it was implemented, and you understand the root cause of the vulnerability, then you can start to think about how you'd write an exploit for it
Seems tough but thanks for the analytical explanation
it is tough, zero day/one day engineering is extremely complex and requires extensive experience in other areas such as reverse engineering and binary exploitation
I thought a zero day was an exploit of an undiscovered CVE , that'd be refering to a one day I suppose
a zero day is an exploit of a non discovered vulnerability/CVE yes
a one day would be an exploit that is created after a patch, usually through patch diffing as i mentioned
and finding one days is obviously a lot easier since usually patches are narrowed down to a few functions which get modified so the vulnerability is patched
however zero days you are going in blind completely
What about a CVE that has not been patched but it has been found and there's no public exploit for it
thats disclosed
but unexploited
there is no specific "day" name for that
Alright
Ya all the "days" refer to is days to patch
does Redis has a build in nmap filter or it's just the owner's decision
for some reason using /nmap -sV <ping>/ only result in all port is ignored
Iāve learnt everything until the part where you learn about URLs and HTTPS
Is there rooms on THM or HTB where I can see how certain pentesting tools work in a contained environment?
Hydra room
nmap room
introduction to metasploit
burpsuite
Thank you
Are u in the ctf team or r u too busy to join?
most rooms in THM or HTB will have you practically using the tools related to the room
Yeah thats true I was just wondering thr specific rooms that a beginner like me could see how the process of using the tools looked like
check out the junior pentester path
Hi everyone i have a basic question can two devices have same ip address at the same time ?
for public IP addresses, no
for private IP addresses, yeah
Bro can you define answer please
though special cases like NAT will make it so that many devices inside a local network will share one public IP but each have unique private IP
if there were two devices on the same local network witht he same private IP, that will result in an IP conflict, though across different networks, NAT, Anycast, etc, it can work fine
though again for public IP addresses on the open internet, no, two devices cannot use the same public IP address
You can SNAT from LAN to LAN as well. Not only exclusive to WAN(But that is where it is commonly used)
small question, how can i detect honeypots on onion? i'm searching for some legit hacking stuff
any "legit" hacking stuff on tor is just going to be straight garbage
ur not gonna find some super secret and new hacking techniques that allow u to press 1 button and hack anything
a friend of mine said discord hackers ain't shit, last resort to learn something
it just simply doesnt exist, the clearweb would be better for finding resources on the different subjects within hacking
they arent really, mostly just com kids who think they know shit
got a point
though you seem to be ignoring the fact that real researchers are out here on the net doing real and proper research into new techniques
see DEFCON talks, BlackHat talks, etc etc
but still, how does one detect honeypots? nobody wants to be caught by the feds
thats kinda the whole point of a honeypot you're not going to be able to detect it
so how do people know some already?
primarily because there is usually nothing about a webserver or site that indicates its a honeypot, what indicates its a honeypot is who owns the site, which isnt exactly easy to figure out
and how do i know that the first websites that pop up when i search something the feds put honeypots into aren't honeypots?
talk within the scene, past experiences, sometimes OPSEC mistakes are made
again, you dont
yeah i figured it out while i was typing
thats the point of a honeypot, it is made to catch criminals
what "hacking stuff" are you looking for on the onion anyways
you'll find barely any resources about that on the onion
not to mention before even "creating" your first malware you should know how to write code in the first place
Python, C, C++, etc, whatever you want to go with
everyone is when they start out
maybe start with python first if you dont actually plan to spread your malware, since that can give you a good idea of how a lot of python malware works
then move into C when you're more experienced in writing code in python
yeah but it would be a waste of energy to start now since i'm literally studying on a profile of bio-chemistry, it would've been profitable if i was on the maths-informatics one
it takes years for even a quick learner to fully understand the aspects behind coding, especially when it comes to external libraries, interacting with underlying operating system utilities like the WinAPI, etc
well then just learn it in your free time if you are interested
i have malware development resources if you want them, cant paste here as the bot will delete it but u can dm
i could but yk, school stuff and my country has the hardest learning system itw
sure why not
Ok so I have what I think to be a networking question, I am considering port forwarding on an old laptop for server hosting for a game, thatād be happening on my home net. On a 10 point scale how bad of an idea is that? 10 being the highest.
how many people are playing
Iād say a max of 8
Game has dedicated hosting tools which include an account system
Like passwords and logins
wouldnt be a big deal you'd probably just have to harden the firewall a bit to prevent any inbound connections or requests that arent logins from your friends
I am somewhat concerned though as I have to hardcode the logins myself into the serverās config file and the passwords can only be stored as plaintext far as I know
if the logins are on ur laptop u should be good provided its semi updated
The laptop?
yeah
Oh yeah that should be fine then
wouldnt want to be hit by eternalblue in this day and age
exploit the NSA created, was leaked then used by north koreans for the wannacry attack
Oh yeah
Fun
Old laptop is set to auto update but it canāt handle windows 11(it is win10 atm), thinking of looking into linux for it and see what I can so from there š¤·āāļø
Speaking of which, anyone know of any good linux distros for lets say someone who fears cli and is far more comfortable with guis?
Can anyone help me get the real worm gpt
impossible to say
Ah, the usual crossposting "help me hack social media"-nonsense. Never mind then
Was literally about to tell you lol
So.. twisting nipples for crossposting/rules violation.. how far along is the bleeding edge tech now?
Yo anyone knows how you include nexus mods to fitgirl repack games?
@tropic lagoon so you already powered off your router for 10 seconds & turned it back on? You also said you contacted your provider and asked if there was an outage & they didnāt help you? Did you also look for a reset button or option on your app that you use to reset it?
Did you pay your wifi bill lol
I can't look for the reset button on the router it's higher then me
Use your superman powers to fly up to it
Do you have a ladder
Jkjk
Or a chair
And i tried to look for a reset button on the application but it said the same thing as i told you earlier
Did you really call the provider and ask if there was an outage in your area? I am surprised they didnāt advise you.
Search up if there was one if they wont tell you thats werid
I would know if there was one and no it's not he also said the same things
Check your dm I'll send you the photos
Call your provider back and ask them to test the connection, send a reset signal & walk you through resetting it. Come back and let us know what happened.
Could be a faulty modem and or router.
It's 1 am in the night should i call?
š¤·āāļø I mean you want internet right, they should have 24 hour support. If not, you may have to wait till the morning. And for future reference do not ever send a picture of your router to a stranger with the default creds showing in the picture. Please make sure to always change your ssid & passwords to something else. Best of luck.
Thanks for the help but there's no major information of me or my router on the router so it's safe ig?
Ok, because I looked at the pictures you sent, it was blurry but it looked like the default ssid & password was on the bottom left corner. Itās deleted now so š¤·āāļø. Best of luck, let us know how it goes.
That was help and the support email and a qr support bro how could u see it's a password š
It was blurry, was just making sure. Some providers put it on their routers. Wanted to make sure you were being safe. Now stop wasting our time & call support!
Ok
Anyone here has a TikTok bot script???
we don't help with these stuff here #šć»rules
Hey, I'm being nominated as club president for a college. I'm looking for ideas... well, more professionals to attend these events to help develop skills and workshops for associate-level students. I have heavily influenced TryHackMe as a great learning platform, because it is. Would anyone want to volunteer in these events and present a short course?
sure what short course type you looking for
from entry level to cyber analyst, and maybe pen testing. I'm also considering doing a workshop for repairing devices. The goal is to be productive to beginner and semi-advanced.
i could do that
would you mind sending me your linked in in dm?
im not doing that but ill send my blog
thats fine, ill send you my linked in
ok
Hey all I'm new here just wondering about any cool gadgets any of you guys know of?
wdym by gadgets?
cardputer
Things like the flipper and esp32 et.
like a sine wave generator?
cardputer have esp integrated in it and it also have a keyboard
which is a huge benefict
Ohhh
no it's from m5stack
Description Cardputer v1.1 is a high-performance card computer designed for engineers, offering a comprehensive upgrade over the original Cardputer. The new version features the brand new StampS3A main controller, with optimized antenna and button design for the core module, significantly enhancing system stability and
you can flash it with a firmware like evilm5stack = project or any hacking firmwaer you want
Legend is this just for writing cards or?
you can do wardriving with this alone
writing cards?
what do you mean
it is a esp and keyboard that have other modules used for hacking
and it's super small, like a credit card size
I think I saw someone using one of these to copy/write blank NFC cards etc. that's what I thought it was but wow thanks for the info I'll defs get one and look into it
check dms
What does esp mean sorry I'm just learning I only knew it as a name for a chip
it is a chip
Does it stand for something?
it's like a microcontroller that have wifi and bluetooth