#👥・help-me

1 messages · Page 118 of 1

sterile hatch
#

check the ftp server

#

ftp.soulmate.htb

#

@patent gazelle

patent gazelle
#

Nope not loading

sterile hatch
#

you added in /etc/hosts?

patent gazelle
#

Yes

sterile hatch
#

its your first ctf machine?

patent gazelle
#

No websites of any machine not loading not my first

sterile hatch
#

lol

patent gazelle
#

Sudden now website is loading I connect to htb support

#

Not loading

sterile hatch
#

can you curl?

wide umbra
#

hi

patent gazelle
#

Yes

sterile hatch
#

whats your error code in browser? if you can curl then you can access it via http, port 80

#

can you even ffuf?

#

only in browser its wont work?

sterile hatch
wide umbra
#

I just got my sec+ so im basically an infant, but I'm trying to get my first tech job and wanted to ask for advice in here

#

what

whole patio
brisk frost
frigid slate
#

Heyy guys anyone familiar With CORS vulnerabilities ? Need some Help

wide umbra
# brisk frost You got at least a pos you want?

I need to start with entry level help desk or SOC tier 1 maybe. I have sec+ but no job exp yet. I'm thinking VM home labs plus documentation could help me get interviews? any recommendations?

brisk frost
whole patio
#

I dont think soc without specific experience/certifiation is really a thing anymore

crisp star
#

Working as a SOC is so fun. We are all cooked.

#

Our reputation is going down if we can't stop attacks 😔

woven anvil
#

ez problem solved

crisp star
#

This year was insane with ransomware incidents

woven anvil
crisp star
whole patio
#

Whenever I ask clients with a MDR solution if their contract partner has ever contacted them about anything, they say "no"

#

Always wanted to kick the bucket in that network and see if someone wakes up

woven anvil
woven anvil
whole patio
#

By now I consider those external SOCs essentially a scam

woven anvil
#

a bunch of them

#

Sophos is a scam straight up

crisp star
#

Not all SOCs are bad but most of them are.

woven anvil
#

Some of them actually do their job

crisp star
#

I also had to work with other SOCs and there is sometime a huge gap in knowledge and how they view certain incidents.

#

I think we will see a shift how SOC are going to operate.

woven anvil
whole patio
#

I assure you they won't

#

There is a larger market for clients that want a pentest purely for compliance reasons and are a-o-kay with rubberstamping

woven anvil
crisp star
#

Just hire for compliance

woven anvil
#

Ew >.>

whole patio
#

When I started out as a consultant for a small company which prided itself on delivering good work, I was totally shocked how little is actually expected by clients

crisp star
#

Consultant and sales are funny people. Selling services that don't even exist in our portfolio and we have to make it work magically Sherlockyes1

whole patio
#

My old boss did that once.. promised a client that I'd be able to do something that we were 100% totally not capable of.. had to talk him out of it

rain knot
fluid ermine
#

does anyone know any collections of n-days/writeups?

flat prawn
#

Hey guys I want a new laptop for Christmas specifically one for cybersecurity and what not any recommendations thank yall

whole patio
flat prawn
#

lol idk much about computers or anything I had a school laptop but not anymore so I want one for Christmas

#

not a huge gamer but I’m learning cyber and stuff just whatever can handle that yk

whole patio
#

practically any laptop that has good linux support can do the job, unless you have specific requirements

#

Usually people end up buying any thinkpad within their budget

flat prawn
#

Thinkpad okay thank you

wide umbra
wind willow
#

Does anyone wanna learn c++ with me ??.I don't think I can do this alone

sterile hatch
wind willow
sterile hatch
#

yes

crisp star
lyric glacier
#

Confused about this!!
I am 3rd year b.tech atm I am doing ML projects

What should I do ?
Learn cybersecurity ( got interest in it(as of now and what tryhackme I ve done)

Or

Learn JAVA/MERN(I ve learned then but never coded too much soo) And go for SWE job
or idkkk 😭

sterile hatch
crisp star
faint meadow
#

One message removed from a suspended account.

oak robin
dusky peak
#

Is there any reliable AI platform that can code for me

#

Specifically python

slender dirge
#

Don't rely on Ai for anything else though

near quarry
slender dirge
#

It makes mistakes

near quarry
#

word

wraith belfry
#

Can someone explain to me if there is any significance to ‘roles’? What the hell is that about?

whole patio
#

Mostly there is no relevance. Though moderation roles exist.

spiral notch
#

only you yourself and you

hushed cobalt
#

Governance, Risk & Compliance how important are those for a cybersecurity career, starting point, to learn and getting in the field :)?

whole patio
#

Cybersecurity is a wide field

hushed cobalt
#

From a starting point

whole patio
#

starting point for what specific goal in cybersecurity?

hushed cobalt
#

Learning and getting in the field*

whole patio
#

you are way too vague.. again - its a wide field. Wanna be CISO? Very important. Wanna be SOC analyist? Not that much

hushed cobalt
#

Yet I feel like everyone would benefit with this knowledge in the field

#

GRC decides the meaning of security; SOC decides the means of enforcing it

whole patio
#

If you say so

feral lintel
#

with that approach I might also suggest getting an MBA

rain knot
#

I feel like we should be talking more about rolls. Bread. Bread is delicious.

hushed cobalt
#

I....
So the question isn’t whether SOC analysts should become managers... but whether understanding governance and risk structures makes operational practitioners better at their job. From a systems and academic perspective, the answer is yes

#

This knowledge overlaps only marginally with an MBA. It actually belongs to security governance, audit, and risk disciplines—areas that are largely absent from standard MBA curricula

rain knot
unreal flume
#

I hope this is an appropriate place for this: I'm reaching out to this amazing community in hopes of finding someone with a passion for digital forensics or cybersecurity analysis who may be willing to assist me on a voluntary basis. I believe my ASUS ROG Zephyrus Duo 16 (GX650PY) laptop may have been compromised in a very deliberate and suspicious way.

Here's the situation:

I’ve discovered several unusual behaviors, suspicious logs, and unexpected system changes in the past few days.

I suspect some form of remote access, injection, or manipulation, possibly initiated during a live support session (yes, I know, red flag in hindsight).

There were weird file transfers, background activity, and I’ve documented strange indicators that just don’t feel right.

I disconnected the system from the internet immediately once I realized something was off and I haven’t reconnected it since, it’s in a forensics-ready state now.

I can’t afford a professional right now, but this is serious enough that I don’t want to let it go unchecked. If someone with skills in malware analysis, incident response, or low-level system inspection is up for a challenge, I’d be incredibly grateful.

What I Can Provide:

Full context of what happened.

Access to logs, timestamps, screenshots, memory dumps, or other data you might need.

I’ve already pulled some forensic artifacts (reg hives, SMBIOS dump, ACPI power config, vBIOS, etc.).

Willing to follow your lead, this is a learning journey for me too, and I’ll document it if it helps others avoid what I’ve gone through.

Looking for someone who:

Enjoys deep-diving into potential security incidents.

Has experience with reverse engineering, threat hunting, memory analysis, or UEFI/rootkit detection.

Is okay doing this pro bono (though I’ll shout your name from the rooftops and feature you in future writeups if you're open to it).

If you're curious or willing to dig into this mystery with me, shoot me a DM and I’ll fill you in on everything I’ve got. This isn’t just paranoia, there’s real evidence of tampering, and I could really use a digital ally right now.

Thanks in advance to anyone even considering it

spiral notch
deft violet
#

Holy tldr

unreal flume
#

I'm trying to find out if anything was injected or if there's anything I should be concerned about. I currently have legal claims against the company I suspect to be responsible. Something is very much going on with my unit, but right before said chat support interaction, there was a windows update, so I'm really not sure what caused the strange behaviors I'm seeing with my unit, but I'd really like to know for sure

hushed cobalt
#

@unreal flume said @deft violet . ASUS ROG Zephyrus Duo 16.
observed unusual system behavior and logs suggesting possible unauthorized access, potentially during a past live support session. The laptop was immediately taken offline and is now in a forensics-ready state.

can provide full context, logs, timestamps, screenshots, memory dumps, and collected artifacts (registry hives, SMBIOS, ACPI, vBIOS, etc.). This is also a learning exercise, and I’m happy to document the process.

If you’re interested in helping pro bono

rain knot
lone pelican
#

Hello guys, i have a question. Is virtual machine + proxychains + mac spoofing recomended to stay anonymous? Or is there a better way?

hushed cobalt
#

@unreal flume

unreal flume
#

I was asked to send a photo "for reference" however upon clicking the photo to send, that's not what actually sent. An event.txt file sent

#

When I clicked the file after it sent everything from my downloads folder came up and started what appeared to be, fast loading in the windows, i tried to snap a screenshot but my screenshot apps wouldn't work, so I immediately disconnected from the internet

#

The company in question is the manufacturer so who knows what access they have that would have allowed it to happen.. 😒😩

timid cape
hushed cobalt
rain knot
#

I mean some kind of RMM I imagine, I’m just curious what

unreal flume
#

None that i know of. A web browser, my apologies

broken nymph
#

Hi everyone, I'm new to programming. I basicaly want to build some kind of encrypted email program with a few extra steps. Somebody got an idea on how to start? So far I started learning python and the Linux shell. But I'm still a full noob so every recommedations and tips are welcome.

shell sinew
small perch
#

Heya! Anyone have any feedback or personal reviews on the THM Security Analyst pathway? It looks very beneficial to learning the basics of being a SOC analyst and maybe even give some understanding of what it's like to be a SOC analyst. I went to WGU for cybersecurity (didn't finish - made it 65% of the way thru the BS program) and it didn't feel like there was any hands-on SOC work to help understand what it would be like to actually work in cyber (maybe there is hands-on stuff in the 35% I didn't do). I was just hoping for some perspective and insight from pros who have been working in a SOC for some time AND who have done the THM Security Analyst stuff

#

Thank you! I'm about to get started and I'm really looking forward to it, but it's a long run. Roughly 120 hours, I think. I'm stoked to learn!

chilly merlin
#

Nothing crazy

#

If u wanna do soc

#

Learn on letsdefend

small perch
#

I would LOVE to do SOC. I don't know if I will ever get even so much as an interview for a L1 Analyst role though. I've been studying cyber and doing hands on stuff (Josh Madakor's SOC program) for 2 years, submitted ~2,300 resumes for soc roles, and received zero calls. I've even had several cyber pros (including an engineer and a CISO) review my resume to make sure it's not the resume, and they all say it's great and should be getting me some responses. So I'm left to believe the job market is a bit rough the last couple years.

#

I'll check out Letsdefend! Thank you for the rec

scarlet pier
#

@hushed cobalt As a SOC analyst, I can tell you that GRC is very important. Being a SOC analyst involves a lot of, well, analysis which in turn involves a lot of decision-making. A lot of that decision-making process is rooted in governance, risk, and compliance. There are also people who ONLY work in GRC (which you probably already know) and they do things like third-party assessments and draft policies surrounding information security for the whole org. Yes, a CISO would have their hand in that as well but by and large they would be delegating the work and serve as the liaison to the other members of C-suite. Pentesters need to know about GRC as well so that they can understand the significance/sensitivity of any compromised data and so they can communicate the gravity of such a compromise to their clients. In any case, rest assured, you are right. GRC is important for every cyber career field.

plain arch
#

For pentesting what do i learn first

scarlet pier
#

@plain arch Network and Website basics

plain arch
scarlet pier
#

I'd say during

#

Like just do a little bit of coding every day

#

Let the networking and website knowledge you get guide your code

bitter surge
#

Anyone here who has won a hackathon ( code an app according to a irl problem )
Need some tips if you hv

amber shard
#

I’ve been trying to log in to my old Facebook account that I had back in 2018. All I have is the email address. Anyone with tips on how to open it

amber shard
#

Already tried reporting to Facebook but it keeps telling me to login from the phone I had logged in from. Sorry if my question sounds weird, I’m a beginner and I’m really just trying to get my account back

whole patio
slow edge
# plain arch For pentesting what do i learn first

Networking: netacad is good platform (THM and HTB Academy)
Programming:

  • Scripting: Python, Ruby, Go (sololearn, codedex, freecodecamp, etc)
  • Web exploitation: JavaScript, PHP, ASPX, SQL (portswigger)
  • Binary Exploitation: C, C++, Assembly, Rust (pwn college)
    Learn any or all above langs as per requirement
    OSes: Windows (especially powershell), Linux (especially bash)
    After covering fundamentals: Tryhackme, Hackthebox, similar platforms for hands on
gritty hare
plain arch
slow edge
whole patio
#

"Just get any thinkpad within your budget" comes when you really can't make up your mind

slow edge
#

Bro read Eris as Eric 😆

plain arch
whole patio
slow edge
# plain arch any tips for assembly c++ and c?

Yes, do not start there if you are uncomfortable, start with something easier
Also on how to learn them, there are sites like sololearn and codeacademy to learn them and when you do, make sure to actually understand it, especially C!
No need to go deep in assembly, C, or C++.... Even I don't know few stuff, but atleast a understanding is required

plain arch
slow edge
gritty hare
whole patio
gritty hare
whole patio
#

I think you did not answer my question

visual halo
#

Hi

whole patio
#

~ 800 EUR

gritty hare
# whole patio ~ 800 EUR

Ahh got it, thanks for explaining 🙂 That makes sense. Your setup looks solid, especially running Kali and an emulator on a refurbished machine. I’m just starting next term and I’ll mainly be using Linux VMs and coding, so I want something reliable that can handle that long term. Based on your experience, do you think 16GB RAM is enough to start, or would you recommend planning for an upgrade later?

whole patio
#

I have several laptops and none of them have less than 32 GB - you could make do with 16 I guess, but again.. you NEED to think about what you want that laptop of yours to be capable of, before you can answer whether a machine is enough for it.
You want a Kali attack machine, and a domain controller and maybe 1-2 domain machines emulated? Then 16 maybe not enough.
You want to be "capable" to do it? Then look for machines that allow you to update the ram and have enough threads to pull it off.

gritty hare
fossil plank
whole patio
#

The majority of tasks have very low requirements, its true

lucid cove
#

Lol this is almost impossible

#

It is possible i said almost impossible
Phones are the most secure os out there and the tools and software available needs alot of social engineering

shut meteor
#

i might be a noob but why I'm not able to send GIFS in here 😄 ?

granite vale
#

Zeroday vulnerability?

whole patio
shut meteor
#

ahh okay, i was figuring it's something like that . Thanks

frank merlin
#

Hello Everyone, i am Data Analyst opned to learn AI Automations ( Power Automate and N8N ) would appeciate any help i can get

analog musk
#

just make sure it can run a vm

#

and mint linux

white aspen
#

Hello everyone, I am a very beginner and I need some guidance regarding this IT field, especially networking, cybersecurity, cloud security, DEV Ops, I need a proper roadmap where to start and what are the opportunities available. I am currently a noob, absolute zero in knowledge, but I have this passion of pushing myself up towards this field, someone please can you help me out, and provide me some guidance, you can dm me or let me know here itself wherever you can, and it will be a great honour to learn from experts like you all. Have a great day ahead

whole patio
#

Curated learning paths are usually tied to paid material and support

foggy otter
foggy otter
#

If any of you are interested in some sites where you can build your own lab without having to buy the equipment for it like routers and switches ,let me knoz

boreal raft
whole patio
#

Same answer

#

No one here is looking to become an accessory when people 'believe' it is their account, when in reality it is the service providers data and infrastructure

chilly merlin
#

Hey everyone, I did a quick security check on a web infrastructure and here’s what I found:
• Critical: Public debug file exposing server configuration and paths, potential RCE.
• High: Backup directory accessible without restrictions, risking database backups.
• Medium: Missing security headers, allowing clickjacking.
• Low: Some files reveal software versions.

Do you think this would be enough for a reconnaissance report and an initial assessment?

whole patio
#

You sure about the findings?

dusky pelican
#

so uhhh how do i change my super key?

#

well the appearance.

#

G-NOME

#

Plus i deleted two boot entries in the nvram, but still no boot 😄

#

Anyone could, help. even Eris, knowing u got the brains to these things

whole patio
#

I'd start with describing in more detail the 2nd question

dusky pelican
#

I used efimgrboot -o 0002.. didnt work...

#

The OS Boot Manager is still there. Oh and its a HP laptop

#

So im stuck with F9(boot options) every time i switch the laptop on

dusky pelican
#

but its cool, il rock with it

vague ledge
#

i need help to track a cellphone number, he is trying to scam me

wise scaffold
#

Hello, im currently running an OpenMediaVault server through Proxmox and i wanted to ask if there are some practices i could do before installing anything or doing any portforwarding to make both the VPN server and my Hypervisor more secure and less likely to get infected or hacked, I only know the basics of linux so if you happen to stumble on to this help request assume i know nothing, thank you so much for and thank you for the support!

spiral notch
#

objective? usage?

wise scaffold
wise scaffold
#

I'm also doing this for educational purposes because I'm a junior in networking

next tinsel
#

im thinking of installing a custom rom onto my Galaxy Tab A9, ive yet to decide which one to go for but i feel like pixel experience would be a good choice, can someone maybe walk me through the steps just so i dont f up

spiral notch
#

use separate networks per user

#

don’t give them more access than they need

#

and attempt to not modify services that may be used as privilege escalation/ exploitation vectors

#

oh and fail2ban though that’s irrelevant if u use ssh keys

wise scaffold
wise scaffold
wise scaffold
chilly merlin
terse heath
#

This sounds super sketch but I have a friend who’s reached out to me as she’s forgotten her email password. She knows I’m into pen testing and asked if I could essentially figure out her password or get into her email.

She’s forgotten the password to the main email address and the back up one.

#

I’ve just started some enumeration and can’t see to much online regarding leaked bases. Also breach directory is down which is annoying.

#

Any recommendations to how I can further enumerate / get a foothold ?

#

Otherwise I’m going to have to make a word list and just brute force ?

whole patio
#

You are not going to brute force shit here

terse heath
#

Yeah I feel like I’m up against a loosing battle here

#

I’m doing OSINT but finding it hard to come across some decent websites to get leaked hashes

next tinsel
#

dudessss

#

when flashing twrp

#

do i just use the vbmeta file extracted from the official firmware?

rare flume
#

if im downloading apk file on LD player mobile emulator my actual pc get affect with malware

whole patio
#

Proper host isolation is it's own topic

rare flume
whole patio
spiral notch
#

osint won’t have much

#

passwords are always hashed

#

and bruteforcing will take thousands of years and many ips

#

you’ll get banned on many ips

#

js contact support

#

there’s not really any good legal way to do it

#

or even an illegal one either

terse heath
#

I’ve contacted support and also went through their motions they are unable to assist. Might be a case that the emails lost.

#

Poor password management on her behalf tbf back up email is her partner who is no longer with us.

#

The old passwords she used were pretty awful

rare flume
#

avg guy

#

who plays vg

whole patio
#

You told us that downloading stuff in your emulator has actually infected your PC, right? Well, isolating an emulated environment from the PC is something that needs to be cared for. IT does not care if you are "just a simple user". If you dont know what you are doing, you suffer consequences

#

This does not get easier just cause you don't know about it.

oak robin
#

Dang, I could use some cash for Christmas.

urban patrol
#

I need help on setting up Kali Linux on my Dell latitude e7450

whole patio
#

Give us the details. Did you follow the OFFICIAL installation guide?

whole patio
urban patrol
#

yeah, I follow a tutorial on YouTube, but I if i could get another one I could try using it instead

whole patio
#

So no. You did not follow the official guide

#

Which tool did you use to write onto the install medium

#

Rufus especially is known to break the installer, for instance

autumn kite
subtle relic
#

Hello guyss, I was going through MDI's documentation, which is like 600+ pages (I'm only going through the pages where alerts are mentioned, i.e which kind of interaction might generate what alert) and making a cheatsheet like this, writing down all the alerts and logs to better understand its behaviour, for evasion and a bit of red-team mentality. Is this a good approach, or should I do a course focused on evasion and red-teaming? I am planning to do CRTO in some time tho.

I'm making a cheatsheet in the following format:

| XDR Alert Name | description | Detector ID | External ID | Possible attacks | Updates | MITRE ATT&CK

#

:)

crisp star
#

Wait there is an MDI documentation? sideeye

subtle relic
whole patio
#

Don't, it has not been maintained for years

crisp star
green iron
urban patrol
# autumn kite What steps did you already take?

I downloaded Virtual Box, Kali Linux, 7-zip kali Linux extension, some kali Linux - iso file, I extracted the 7-zip file to Virtual Box, created a Machine and started graphical Installation, but it kept breaking along the line

urban patrol
# autumn kite What steps did you already take?

I downloaded Virtual Box, Kali Linux, 7-zip kali Linux extension, some kali Linux - iso file, I extracted the 7-zip file to Virtual Box, created a Machine and started graphical Installation, but it kept breaking along the line

crisp star
#

LDAP alerts are a mess because you don't see which process executed it sometime

green iron
#

you will only get hashes through leaked dbs

crisp star
#

But you could use KQL filter and search for DeviceNetworkConnection and filter based on a few LDAP port

subtle relic
whole patio
subtle relic
#

like they teach in CRTP

crisp star
#

So you were basically blind

urban patrol
whole patio
#

If you are unclear about what it means, I'd really suggest not to use it. Why blackarch anyway?

crisp star
#

The only thing you notice something strange is going on is either when a honey token is being queried or a DC sync is happening from an unknown device

whole patio
chilly merlin
#

Did u know sysmon Event ID 1 and PowerShell event ID 1 are not the same

#

Spooky stuff

urban patrol
crisp star
#

But they complain that the hard drive is getting full too quickly

chilly merlin
whole patio
#

No, I don't get you. But if "boredom" is your motivation, then do what you want

crisp star
chilly merlin
#

😂

whole patio
urban patrol
#

that means I won't have windows anymore

urban patrol
whole patio
#

Entirely up to you

whole patio
#

Same answer

#

There are install guides for virtually every variant

urban patrol
whole patio
#

As I said, entirely up to you

subtle relic
crisp star
#

And you also get DA if a certificate template is vulnerable

spiral notch
#

it’s deffo a bit less safer

#

just use vbox

spring fog
#

I am so tired of being for vpns and process so please I need help on how to get a free proxy to use for my daily activities any recommendations please?

whole patio
#

If "free vpn services" were great, they wouldn't be sustainable

subtle relic
terse heath
terse heath
rare flume
steady quartz
#

Hello everyone ! I’m very new to this cybersecurity and related space so I apologize if I don’t know all the terms and such🥲
I just recently started my studies (currently doing THM Pre-Security). I’m interested in becoming a SOC analyst so I thought I’d come here and ask the professionals with experience for any tips/ suggestions that could help me through this path. Through the research I’ve done I’ve seen people mention A+, Security+ and Network+ certs are very good to have but are there any other certs that could help as well?

Thank you in advance4299cuteduckiebop

spiral notch
#

in terms of proxies most free proxies will yoink ur data

#

and are no better than vpns

#

atleast most

spiral notch
#

dont get a+, very beginner and unnecesary

#

s+ and n+ is nice, i have both

steady quartz
spiral notch
#

any time

#

work on getting better

#

not hunting certs

#

gg

split saddle
#

Can noticably slower phone charging be a sign of device penetration?

steady quartz
#

Thank you!

spiral notch
split saddle
# spiral notch sure !

I've been suspecting it a lot today as i noticed some unusual stuff happening (Telegram login attempt, Gemini assistant popping up randomly and the slower charging i mentioned)

#

im just concerned about what i can do

spiral notch
#

factory reset

split saddle
#

You think it's called for in this scenario?

spiral notch
#

anytime you suspect you have gotten infected

#

you factory reset

#

malware can be persistent, malware can replicate

#

relying on antivirus alone and ifnding it detect something and get rid of something is not reliable

#

the malware can still easily be metamorphic, polymorphic, could have changed, mutataed

#

anything is possible

#

some malware can stay after factory resets (like the ones im trynna break my head with while developing and makes me wanna kms) but its very very very rare

split saddle
#

Alright

#

Thanks a lot for your time

#

and for the info

#

definitely helped

spiral notch
#

no worries !

broken nymph
chrome fractal
#

I think my iphone 16 is being hacked by someone could anyone gelp me give me some knowledge

#

As well as my chatgpt is being hacked how would i confirm this maybe trace it back

hexed relic
#

yo

#

guys what do u thing is the right way to hope on web security , is it CTFs or pentesting ?

patent gazelle
#

Can I ask my friend to get me a flipper zero from us will there be any custom issue

slow edge
# hexed relic guys what do u thing is the right way to hope on web security , is it CTFs or pe...

Well
Pentesting means a simulated cyberattack where a security professional tries to find vulnerabilities and exploit them
CTFs do contain pentesting but they are gamified version

I would say learn pentesting, because most of the beginners start with CTFs and they get disappointed because they cannot get any flags. There fundamentals aren’t clear

CTF is just a practice ground, but for that you must know what you’re doing. It is like CSGO, but to play it you must know what are different guns, which gun to use when, where are the enemies found mostly etc etc

So start by clearing fundamentals, pentesting and then CTF as a later thing. For web security, start at portswigger and learning fundamentals about web

lethal wedge
#

i need help guys

#

i have forgotten my phones password because of that, i cant turn the phone off. cant someone tell me how to flash the password without offing the phone. and the phone is samsung s7

slow edge
versed owl
lucid cove
slow edge
vapid hemlock
#

Can anyone gift me nitro membership

gusty tide
fluid fern
#

Guys please can anyone help me with link to a free course or resource online for software testing that can carry me from zero to a job ready tester?? 🙏🙏🙏🙏🙏

hazy trellis
#

How can I upload a pic I want advice on how to reduce my mother's surgery bill ???

topaz cobalt
#

Hi everyone. Can anyone help me with a crypto mining site or app that gives you real cash and not small percentages or small chunks.

hazy trellis
#

Can someone plz provide any insights?

whole patio
whole patio
topaz cobalt
#

A apps to mine crypto that I can live off of from month to month. And learning and maybe a online job.

hazy trellis
fluid gulch
#

There are many books to choose from when it comes to learning a specific aspect in cyebrsecurity. There are so many web application security books I found but I have no idea which one to pick as a beginner. How should I pick a book that best suits me as a beginner?

short crest
#

hi everyone
i want a help on two labs
both of them is "Hard"
its The Great Disappearing Act and Scheme Catcher on THM

grand prism
#

Love From Big Brother

Entering 2026, I want everyone here to encourage each other and work together.

For the first three months, focus on yourself.

Know exactly:
•how much money you make
•how much goes out
•how much you have left

This clarity matters because 2026 will be big for investments.

AI and tech are accelerating fast. Crypto, stocks, marketing—everything is shifting. Avoid meme companies and businesses built entirely on someone else’s infrastructure. If their system crashes, you crash. Learn how to build or support real infrastructure.

If you work in cybersecurity, tech, construction, admin, or any desk-based role—pay attention. AI is already replacing jobs. Most people will feel unsafe next year. Don’t wait. Study how AI is changing your industry and become the solution before someone else does.

Understand your habits and patterns. Be happy, but responsible. Treat yourself without guilt. Money is meant to move. When you’re clear and relaxed, opportunities come. This isn’t mysticism—it’s function.

Audit your circle. Strengthen family and close friendships. You’ll need them in the coming years as housing, currency, and work structures change. Stay around people in your age group who share your drive and energy. Avoid shallow connections. Be around people who challenge you and sharpen your thinking.

At a certain point, life isn’t about emotion—it’s about information. Take clarity from people, not their noise. Learn to filter value. This is about your life and where you’re going, not who you like.

Stop waiting for validation. Be your own parent. Be your own biggest supporter. Know you’re good at what you do because you live it, not because others clap. If you can’t handle the smoke, don’t chase the fire.

I love you all.
Thank you for being part of this Discord, supporting each other, and sharing knowledge.
And respect to everyone who found work and growth through this community.

Let’s move forward with clarity.

gusty tide
mystic slate
#

hey guys, is dsa necessary in this field?
also i am only good in python and java a little, do i need to learn c/c++?

dry sparrow
#

Hey guys

#

I'm up with something

#

I need some advice

#

Today I hit up with something weird behaviour from my classmates whatsapp account

#

The attacker somehow got access to her WhatsApp
And he's trying to hack more by sending an apk and an image

#

So what I did was
I downloaded that apk and tried to check the threats in virustotal

#

And I found these threats inside that apk :

Trojan.Android.Banker

Spy.Banker

Trojan-Dropper

Riskware / Obfuscated APK

#

Now I'm trying to reverse engineer the apk and trying to find vulnerabilities that can lead me to the attacker
Or maybe something that can help me give an analysis of the threat behaviour on the innocent users

#

I'm all ears for any kind of advice

near sable
#

a malware analyst pls help me

#

what can i do with a MD5 and SHA256

lone delta
near sable
lone delta
near sable
#

oh ok

lone delta
near sable
#

and need help understanding what it does

#

ik its antivm

#

but i legit dont understand anything its saying cuz ive never worked with c++

near sable
#

alr

lone delta
near sable
#

thanks

faint nebula
#

Do anyone know if this system is good? https://noxsystems.com/ its called a high risk security system - like the should be no possible ways to get into the system

near sable
lone delta
near sable
lone delta
autumn kite
spiral notch
#

depends

#

you don’t even need a malware analyst to tell you that

spiral notch
near sable
#

prolly accesing little kids webcams

#

i wouldnt be surprised

#

i jst needa find the webhook so i can delete it

#

and then they cant webcam kids and do all that other stuff

#

creepy asf

near sable
#

i wanna do smth with it

woven anvil
# near sable i wanna do smth with it

There is a lot of context you are missing to be able to work with anything like this.
Additionally, using your abilities to track down another person or to cause computer/systems damage to someone else would be unethical. Dealing with an issue yourself instead of reporting it to the proper authorities would be vigilantism. We do not discuss vigilantism here as part of our #📜・rules.

If you want to learn reverse engineering, then grab some C/C++ materials and start learning.

near sable
woven anvil
near sable
#

thanks

near sable
#

does that dehash it

woven anvil
# near sable does that dehash it

No, it attempts every option in a "dictionary" file, hashes it, and see if the results are the same.
The amount of combinations for sha-256 makes it pretty uncrackable.
However, hashing algorithms are used for more than just "password hashing", they are also used to determine if a file has been tampered with. These file hashes would be completely useless in hashcat as trying to "dictionary attack" a binary or similar file would I assume be harder than a string of text.

#

Only legacy applications would be using MD5 for password hashing at this point too.

#

Anything worth its salt + pepper would be using other ones dogekek

white aspen
#

Hello, yesterday I left a message, a kind of request/help but I can't see the message now, I can't understand can anyone tell me why message is not being displayed here?

white aspen
#

I don't know I am kinda new here

#

It was kinda long text me explaining my situation and the help I needed

white aspen
woven anvil
white aspen
#

Sorry I am kinda noob in discord

#

Okay lemme check

#

Okay thankyou soo much

#

Thank you @scarlet thicket @woven anvil

alpine cloak
#

can anyone explain to me what a "docker" is

#

i am lost

crisp star
alpine cloak
#

in*

crisp star
alpine cloak
crisp star
#

Honestly, you can just use google for that.

#

There are some tldrs that explain the concepts

rain knot
#

it’s hella useful

#

terraform+docker chefs_kiss

whole patio
whole patio
#

docker allows you to slim down the virtual machine that is necessary to run that tool.. so that the container essentially becomes just the service, to run that command

woven anvil
#

I can run kali as a docker container

alpine cloak
woven anvil
#

I don't get access to any of the gui tools though

crisp star
#

You can run anything in a container

whole patio
alpine cloak
#

oh okay thanks

whole patio
#

and not only for testing

green iron
#

Anyone good at malware reversing?

whole patio
#

instead of installing a webserver, and nextcloud, and whatever else you want.. people say "just use a docker container" that already includes that stuff

woven anvil
# alpine cloak so its a small virtual machine for testing

Doesn't have the flexibility of a virtual machine.
Virtual machine gives access to emulated hardware for an OS to run its own kernel and such on.

Docker Container gives a restricted area in the current environment to run said applications.

alpine cloak
#

okay thanks

#

holy this server is helpful

hasty phoenix
#

Has anyone used ray hunter before?

whole patio
#

Attended a workshop with one of their european contributors, why?

proper raven
storm drum
#

hello Guys can anyone help me with IMEI tracking, Someone stole my phone and the authorities wont help me so i gotta do this myself.

spiral notch
#

also sure it can have vmprotect but it’s not hard to simulate a pc more closely than just a vm

alpine cloak
#

what the

#

did it just auto react

spiral notch
#

@near sable but sure i’ll take a look

granite vale
crisp star
#

That phone is probably already somewhere being sold

storm drum
#

They got a bunch of phones they are tracking but i have never seem any who got his back from my country i mean

forest inlet
crisp star
#

Honestly just lockdown the phone and get a new one

#

And also get a new SIM card and lock the old one

granite vale
#

The government would care alot if enough information is provided to them

forest inlet
#

would they?

storm drum
forest inlet
storm drum
storm drum
crisp star
#

Honestly, low value goods like a phone are never going to be worth tracking down.

granite vale
storm drum
crisp star
granite vale
storm drum
#

I know but i have to try what i can do rather than giving up on it.

#

so what i wanted is a clue on tools i can use so that i can dig in on it

unreal crater
#

Hey everyone, can someone help me with the partitions for a Linux dual boot setup?

unreal crater
unreal crater
chilly merlin
whole patio
#

"Kenya which is in Africa" is a wild statement ^^

whole patio
#

This isn't a matter of "I believe I can do it", it is a matter of "If you have to ask, then we know you do not have access to any".

wintry fog
#

hi

#

i need help

#

everytime i try to install metasploit my laptop freaks out and wont let me install it like it keeps spamming "threats detected" and idk how to put it on a whitelist

#

windows user

uncut jewel
#

anyone know if like need to actually remember the osi layers or its enough just to know their purpose? (feel like you can just for a sec to search it and in the time you just know it)

crisp star
wintry fog
#

like an error shows up

#

i tried fixxing it

#

but nothing happened

crisp star
#

Try and fix that somehow

wintry fog
#

so i js gave up

crisp star
#

Or use VMware

wintry fog
#

idk how to download vmware :P

#

im too dumb on tech

#

should i send u an ss on dms?

#

of the virtualbox error?

crisp star
#

Just copy paste the error message

wintry fog
#

Failed to acquire the VirtualBox COM object.

The application will now terminate.

Document is empty.

Location: 'C:\Users\Administrator.VirtualBox\VirtualBox.xml', line 1 (0), column 1.

D:\tinderbox\win-rel\src\VBox\Main\src-server\VirtualBoxImpl.cpp[863] (long __cdecl VirtualBox::init(void)).

Result Code:E_FAIL (0x80004005)
Component:VirtualBoxWrap
Interface:IVirtualBox {2ce10519-3c09-45d8-a12d-e887786146b7}
Callee:IVirtualBoxClient {d2937a8e-cb8d-4382-90ba-b7da78a74573}

crisp star
#

Are your running Virtual Box on an external hard drive?

wintry fog
#

no

#

ssd nvme

crisp star
#

Did you try uninstalling and installing it again?

wintry fog
#

yep

#

repair it?

#

already did

crisp star
#

No. Do a full uninstall.

wintry fog
#

yea i did

#

both

crisp star
#

I'm not sure how you mange to brick that

wintry fog
#

uninstall and repairing

wintry fog
crisp star
wintry fog
#

wdym

vivid vessel
#

Good afternoon I need help my niece in Trinidad just called me crying saying a person hacked her iphone saying he have her pictures and he wants to leak it unfortunately im new to the IT hacking thing but I need this person to stop doing what he or she is doing how do I do it she went to the police in Trinidad but unfortunately they dont have the tech power as we do

crisp star
#

Or do you onlly have the C?

wintry fog
#

only C

crisp star
#

Hmm from where does it take the D:\tinderbox\win-rel\src\VBox\Main\src-server\VirtualBoxImpl.cpp[863] (long __cdecl VirtualBox::init(void)). path?

#

AHHHHHHHH

#

Now I get it

wintry fog
#

yes?

crisp star
wintry fog
#

tell me broddie

#

alr

#

thx man

crisp star
#

I remember that "issue" cause I also had it.

wintry fog
#

appreciate it

#

wait

#

when i typed the command now

#

it didnt work

#

it js gave me instructions

#

and not run the command

#

srry if im giving u too much work

crisp star
#

you just have to copy paste the command wat

wintry fog
#

it says unrecognized command

crisp star
#

sc config VBoxSDS start=demand

#

and open cmd as an administrator

#

and the sc command is definitely not unknown

wintry fog
#

WAIT

#

IT WORKED

#

yeah im dumb: confirmed

crisp star
#

obviously

wintry fog
#

still the vm wont work

crisp star
#

Yea you figure out the rest

#

Just use google to understand what the error is.

#

Or just switch to VMware

wintry fog
#

srry for annoyance

#

thx for trying to help tho

opaque pelican
#

Hi @oak robin is being delusional again and says that I need proof that this server is a bot farm where you train these bots.

#

So is that true? 🙄 I stg my life is insane.

whole patio
#

160k accounts, so all bets are open

unreal gorge
#

whats the best coding agent for making Apps android APK have an issue and not sure what is going on.

marsh inlet
#

I’m brand new to Governance, Risk, and Compliance (GRC) and currently learning the fundamentals. I want to do some practical projects with real businesses to gain some 1st hand experience and have something for my portfolio. I’m eager to learn and gain real-world exposure. Is there anyone who owns or works with a business and would be open to collaborate?

alpine cloak
#

guys what type of tools do you use for vulnerability testing

spiral notch
#

be more specific

alpine cloak
#

nah like just a vulnerability test for html websites

spiral notch
spiral notch
#

gobuster ffuf

#

burpsuite

alpine cloak
#

do you suggest nikto?

spiral notch
alpine cloak
#

😭

spiral notch
#

capture the flag

#

friendly and legal challenges

#

to simulate web hacking on test targets

alpine cloak
#

wait nikto isn't only a vuln testing tool?

alpine cloak
#

i never knew

spiral notch
#

secondly it’s rather for initial recon necessary to know what tool next to run

alpine cloak
#

What's the command to run a vuln test

#

actually don't answer that ima google it

marsh inlet
spiral notch
alpine cloak
spiral notch
#

deffo not on a random discord server

#

sorry

marsh inlet
oak robin
fluid gulch
proper totem
#

first, sorry for my bad english
can anyone help me in a ctf? i have to send 16 bits to an 'hardware' (software simulated) in a socket, i have .vhdl files and i got the backdoor activation bits, and i think i should send this on a socket. i made this python script:

import socket


sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
host = input("enter host (use 0 for default: 94.237.121.111): ")
port = int(input("enter port (use 0 for default: 58677): "))
if host == '0':
  host = '94.237.121.111'
if port == 0:
  port = 58677

server_addr = (host, port)
sock.connect(server_addr)

message = 0b1111111111101001

data = sock.recv(1024)
print("received 1 -> %s" % data)

sock.sendall(message.to_bytes(2, byteorder='big'))
print("msg sended")

data = sock.recv(1024)
sock.close()
print("received 2 -> %s" % data)

the first data i've received is:

The input must be a binary signal of 16 bits.

Input : 

and the script send the 1111111111101001
but i noticed that i received no output, so i send a \n along with it, however i`ve received:

Error : Invalid length of bits.

so, i dont know how to send 16 bits + \n and continue sending 16 bits

#

if i send more or less bits without \n, or just the 16 bits, i didnt receive response

shell sinew
proper totem
#

and this CTF isn't worth anything.

shell sinew
#

same as DMing ppl for hints etc.

#

just saying

proper totem
abstract zenith
#

What is a good website to learn Python? , Im kind of struggling just from watching Youtube videos

abstract zenith
#

is it free?

proper totem
#

yeah

shell sinew
abstract zenith
#

alright I will check it out thank you

proper totem
#

but the exam to get the certificate is paid

broken pilot
#

I can’t type in general and 90% of the servers chats,can someone help me

proper totem
fluid gulch
#

Are there any online resources that allows me to practice my computer networking knowledge hands on?

teal garden
fluid gulch
#

Alright, thanks!

teal otter
#

i am new , i joined today what should i do

teal garden
teal otter
#

i checked free resources

#

what should i choose red team or blue team

teal garden
fluid gulch
teal otter
#

i am starting from todat btw 🥲

#

how muc time would i need to complete all these resource in blue team

#

if i choose

teal garden
fluid gulch
teal garden
#

Udemy too has free sources....just in case .

fluid gulch
teal garden
fluid gulch
teal otter
#

@fluid gulch when did u start this carrer

#

@teal garden u too

fluid gulch
teal otter
#

soo have u done anything

#

like any course

barren agate
#

if my pc has bluetooth and wifi does that make me traceable

frozen goblet
#

Hello 👋

teal garden
iron prairie
#

is this where i get answers? or help? i can pay. im not much but this would be a worthwhile skill to have

#

i just need help with finding an ip address or email on this youtube page. if possible. if not ill find out how.

teal garden
# barren agate if my pc has bluetooth and wifi does that make me traceable

And for Bluetooth, what can be traced is Bluetooth devices broadcast identifiers (like a MAC address). Who can see it:
Only nearby devices (typically within ~10–30 meters)....but Bluetooth beacons can be used for local tracking. But keep in mind If Bluetooth is off or not actively scanning/connected, it’s basically invisible.

barren agate
iron prairie
#

what do u help with then?

#

ite ill figure it out my self thank you. anyways though

brave escarp
#

Hii ! Anyone know about roadmap of cloud security beginner to advance?

plush estuary
#

Does anyone have a book about compTIA A+. 220-1201

plush estuary
woven anvil
topaz cobalt
#

Does anyone have remote online work I can do on my phone from home. I'm not working now and need cash for Christmas.

whole patio
agile coral
#

Hi, so can I drop a pdf guide on a project and ask a question ?
Or maybe someone with raspberry pi openWRT experience can help me ?

late drift
#

Hello guys I'm Mohan
Im doing my b.tech Cybersecurity 3rd sem but I don't know any shit abt this but I'm earged to learn helpme to develop my skills and land uhh job

Any recommendations?!!!

spiral notch
#

u*

agile coral
#

Ok i have created a guide using AI for setting up my internet at home I have 2 5G routers huawei one with the actual sim card and the second one as an extender. (Connected through ethernet) from main router port lan 1 to extender router port wan, i set up the admin panel all good.
I got my raspberry pi flashed the openwrt and connected it to the wan port of my main router.
I am no expert in networking but I guess this is how it works?
Now I entered the panel of openwrt and I want to set it up but have no idea how and what I should do….
I can share the pdf created for it ?

fathom summit
#

@charred mirage we do not help with account recovery here as there is no way to prove you are the owner and it is against our #📜・rules . Please contact the proper platforms support team.

charred mirage
#

Oh ok I’m sorry

whole patio
#

Ok i have created a guide using AI [...]

I stopped reading there

agile coral
#

😂 why it’s actually good since i fed the sources

woeful bronze
#

I'm not familiar with it but there must be documentation about it online

#

Worst case scenario you use AI for it too and spend a day debugging it

agile coral
#

Ad‑blocking: luci-app-adblock
• IP blocking: luci-app-banip (and optionally banip itself)
• VPN: luci-app-wireguard or at least luci-proto-wireguard
• DNS encryption: https-dns-proxy and luci-app-https-dns-proxy
• Recursive DNS resolver: unbound and luci-app-unbound
• Traffic shaping: luci-app-sqm
• Bandwidth monitoring: luci-app-nlbwmon
• Connectivity watchdog: watchcat and luci-app-watchcat
• Roaming Wi‑Fi/Travel: travelmate and luci-app-travelmate
• Web terminal: ttyd and luci-app-ttyd
• Shadowsocks: shadowsocks-libev and optional luci-app-shadowsocks-libev
• Docker: docker or dockerd, luci-app-dockerman, plus ca-certificates, kmod-veth and kmod-xt-overlay for container networking
Just security purposes

woeful bronze
#

why not PiHole?

agile coral
#

More features and configurations in openWRT

#

I can even get docker on it and go all in but that’s just too much

#

Plus my rpi 4 B+ has 4gb enough for openwrt and the extra features i want

woeful bronze
#

An LLM should give you fine configs for just adblocking and a bit of security. You should try it. If it hallucinates point it to the documentation, but I doubt you will need to

meager anchor
#

hii

foggy crown
#

Guys i have an iPhone XR which has an iCloud lock. I want to bypass it without jailbreaking it. Any help on how to do it or what software to use.

random thorn
#

Hey, I'm ray and I'm new to all of this stuff but I need someone to help who can retrieve TikTok id. I don't have the password some person hacked it 😭 kindly anyone here to help. I Also don't have the number or anything. I just have a username😭
Kindly help

teal garden
vernal tinsel
#

How can I remove activation lock on my iphone

whole patio
vernal tinsel
#

So it can't be unlocked

whole patio
tranquil drift
#

@minor blade permission to publish dropbox link for a project in #chat?

dapper mortar
#

Hey for anyone that works with hardware, I've been looking to get an injection USB without breaking the bank. Anyone use something cheaper then the hack5 bad usb?

spiral notch
#

i’m glad you asked

#

hak5 is like the biggest scams

#

i made nearly all of their products for 1/10th of the price (unironically)

#

any microcontroller can do this job perfectly

#

for like 4 bucks

dapper mortar
dapper mortar
spiral notch
#

i used an rpi pico too

#

i wanted to post a yt guide on it at some point but was too busy

#

and too lazy to write the script off of what i should read

dapper mortar
#

LOL your so real

#

Kick it old school, no voice just text and dome ncs music XD

spiral notch
#

well anyways yeah

dapper mortar
spiral notch
#

rpi pico is all you rly need

dapper mortar
#

And did you follow a guide or just free hand it

whole patio
#

and no you cant remake the rubber ducky with 4 bucks.. you can very limited copy one of its functions

spiral notch
#

i disagree

#

circuitpython firmware on a pico

#

i counted, median speed of 747wpm

#

exactly identical to the pico

dapper mortar
spiral notch
#

the only feature it did not have (which the new picos have) is os detection

#

new rubber duckies*$

whole patio
#

Can you do os detection? stealth extraction? Have a covered arming modus with a built in button?

whole patio
#

the service hak5 provides is convenience.. their tools to program stuff are great.. its just the same with HTB/THM costing money instead of building or hosting vulnerable machines yourself

spiral notch
whole patio
#

is it cheaper? Yeah. Is it the same experience, hell no

spiral notch
#

arming modus is also possible

#

i have tried all of them, i’m speaking from experience, not theory

#

so i’d disagree that the rubber ducky is any more convenient

#

maybe if one is lazy and doesn’t wanna install their own firmware (literally dragging a file into the storage medium and that’s it)

whole patio
#

I said the tools, as in the software.. duckyscript v3 for instance

whole patio
#

yeah

spiral notch
#

it can obviously run duck script

#

proof

whole patio
#

Ducky script 1 is supported by lots of products, ducky script 3 on the other hand, not

#

mostly for legal reasons

#

I have about every "bad usb" device I have ever heard of, I collect them as a hobby.. and whoever tells you "oh its just the same for 4 bucks" is dishonest or glossing over stuff

spiral notch
#

duck script 3 seems to be very much supported

#

it can run all the payloads one would need to either exfiltrste or exploit the attack vector to later plant a connection and such

whole patio
#

it does not fully support DS3

spiral notch
#

in almost no scenario would you have the full kill chain

spiral notch
#

this is just a converter

#

you can do everything with raw python too

spiral notch
#

to the point where the ducky will complete your op

#

it’s mostly used to get an initial connection

whole patio
#

What I said is - "No it will not be the same experience, hak5 prizing is for the convenience of the tools (software)".

You can tell us now that everything can somehow be copied.. and I would not disagree.. there is nothing magically special about hak5 products.. but it will be a different experience, and sometimes way, way more complicated

spiral notch
chilly merlin
spiral notch
#

everyone speaks for themselves though

whole patio
#

the usb beetle for instance, I mentioned, is entirely programmed via arduino code

#

simply changing the keyboard layout can be a task that takes you a day

spiral notch
#

then you say there’s nothing special about hak5 products except for the experience

whole patio
#

so we agree from different sides

fringe mural
whole patio
#

that being said.. the malduino w is seriously underrated

dapper mortar
dapper mortar
hollow nest
#

hi guys
im here to ask a question well i finished my high school and i wanna be successful in life what i mean is with this ai things coming im kinda scared i dont wanna lose opportunities up ahead and i thought to myself i need to learn abilities that will become useful and in demand in the future so when the time comes im all ahead of every body else and thats how im gonna save my life and accomplish goals and make an easy life for my mom and my sister basically i wanna ask you to tell me what i must learn and where should i start
thank you

supple haven
#

How do I check my teenage daughters phone

chilly merlin
whole patio
whole patio
#

Though Raider/Gladiator sounds like it would never go out of fashion

chilly merlin
whole patio
#

It is

chilly merlin
#

It's your daughter, talk to her.

whole patio
spiral notch
#

it has so many concerns

whole patio
#

hak5 had a guy once who wanted to know how to monitor what his sister would do while shes on his PC, .. when told to ask her or just not let her use it, he said "mom said no"

upbeat jackal
#

Hi im new here and i have a question sound mayne its absurd but if there a way to retrieves money back into a apple card from the person that took like like undo the proses?

hollow nest
upbeat jackal
#

Ok

#

I got jacked then lol😂

whole patio
#

I wouldn't worry about AI too much though

#

"AI is going to do all the jobs, it is going to be great" is basically a stupid persons idea about what a smart person would sound like.. economics don't work like that, the large service providers are basically scams and the bubble seems to be ready to burst.. this kind of thing usually leaves salted lands for investors for a few decades

timid cape
#

look at where the market is going, and adapt

timid cape
hollow nest
whole patio
#

the current read is that the ai tech bros are morons, who just assume that "the rest of the population will go along with it"

lyric iron
#

Hey guys, I have a question how to j recovery or look up my lost email information

whole patio
slate lava
upbeat jackal
#

😂😂

timid cape
# hollow nest thats what im talking about im not asking for a cheat code my point is that ever...

well my current view is that AI (or LLMs) have limits (unless breakthrough in quantum computing happens, they'll still lack alot to replace someone), so the practical use would be to have it do these dumb and time-wasting tasks, while the professional focuses their time and energy on the important tasks and business interactions

so you might not be replaced by this AI, but will likely be inferior compared to someone who leverages it (for automation and assistance)

hollow nest
timid cape
#

leverage it for automation and assistance

whole patio
#

for the dumb and time-wasting tasks we invented computers

timid cape
#

networkchuck is doing great videos on this

prisma urchin
hollow nest
woven anvil
#

Mechanics who don't learn how to use the tool to benefit them may fall behind

#

replace mechanic with any professional

timid cape
#

run it locally and see for yourself (using docker)

woven anvil
#

If the idea is to learn cybersec, you are better off learning the python that could do the same things. n8n is a good visualizer though

timid cape
wintry fog
#

hi guys so i downloaded kali linux on a vmware virtual machine it works fine but the mouse cursor isnt showing like its not appearing how do i fix this?

hollow nest
whole patio
whole patio
#

It is a known issue, happens with a number of other distros, too

wintry fog
#

ah dang

shy monolith
#

Guys i have a question i use linux but i wont a extra hard drive with win 11 how do i fix that from linux ?

#

If anyone could help please dm me

wintry fog
whole patio
shy monolith
#

No wait i explained it wrong haha

whole patio
shy monolith
#

I have linux installed but i also want a win 11 installed so i can switch boots

wintry fog
whole patio
shy monolith
proud junco
#

Hello guys I have a problem using hydra in Kali Linux can somebody help me dm me please

wintry fog
#

eris2cats, it worked tysm

whole patio
#

happy to hear it

proud junco
#

I can't share pictures here?

whole patio
proud junco
#

Iam getting a long error

#

Using hydra

whole patio
#

luckily hydra is a command line tool.
Have you tried google or the actual hydra documentation?

#

apart from that, maybe give us the relevant portion of the error, as well as the command you tried to run

proud junco
#

When I try to run the command I get premeter must start with / slash?

whole patio
#

seems rather self-explanatory.. but just show us the exact command you tried to run

proud junco
#

It's a brute force command for Instagram 🙂

#

But it's my account

whole patio
#

still a tremendously stupid idea

proud junco
#

Why?

whole patio
#

Cause it is not your account.. it is "instagrams" account.. its also not your login.. it is instagrams.. they may probably see the attempt and decide that this is you attacking their infrastructure and can decide to file a report with your local law enforcement

proud junco
#

What do I do then?

whole patio
#

luckily it seems you were unable to find the correct syntax

proud junco
#

I wanna learn brute force attack

whole patio
whole patio
#

and there are several services that provide you machines to test tools on

proud junco
#

Can I use like Tor or other proxy to bypass?

whole patio
#

You can, but I can spare you the trouble.. it wont work

proud junco
whole patio
proud junco
#

Bruh the proxy name

#

?

woven anvil
proud junco
#

Iam not I wanna learn brute force

whole patio
# proud junco Iam not I wanna learn brute force

When I said I can spare you the time, it won't work, it was not because you used the wrong proxy.. just forget about that whole thing.. real world infrastructure is not going to be hacked with hydra by some kid who just figured out that it exists

#

with time you'll understand why.. for now take the shortcut and accept "can't be done"

#

and as I said.. for practice there are vulnerable machines you can use

hollow tendon
#

HI

#

can i get help with transfereing my data from app to app

#

i wana change from the focus to do app to super productivity but the focus to do app doesn't have an export option and i am nont gonna rewrite all my list from scratch

#

so i asked ai and searched reddit but nothing showed up

#

even yt failed me

#

but ai did give me a good tip

#

both apps use the same file format

#

but idk how to get those out, asked ai it told me stuff i don't understand so if there's someone to help me export it?

#

I understand you're looking for a more detailed guide. Since Focus To-Do doesn't have a direct export feature, here's a step-by-step approach using browser developer tools:

  1. Open Focus To-Do in your web browser
  2. Press F12 to open developer tools (or right-click and select "Inspect")
  3. Go to the "Network" tab in developer tools
  4. Refresh the page to capture network activity
  5. Look for a request that contains "tasks" or "data" in the URL
  6. Click on that request to view the response data
  7. Copy the JSON data from the response tab
  8. Save it as a JSON file on your computer

Alternatively, you can:

  1. Manually copy your tasks from the Focus To-Do interface
  2. Paste them into a spreadsheet (Google Sheets or Excel)
  3. Export the spreadsheet as CSV format
  4. Import the CSV file into Super Productivity

For Super Productivity, you can:

  1. Click on the three horizontal lines (menu icon) in the top-left corner
  2. Select "Import" from the dropdown menu
  3. Choose the file format (CSV, JSON, etc.) and upload your exported file

Would you like me to provide more specific instructions for using browser developer tools, or are you more comfortable with the manual copy-paste method?

this is what it told me

#

i didn't understand the first suggestion with the dev option

#

OMG i am so stupid i forgot to login on the browser thats why i can't see the data

chilly merlin
#

I mean 😂

#

Self diagnosis is pretty good

hollow tendon
#

i just gave up and just used a 3rd party app to copy ts to my local files while being offline, then deleted the app, did a full data cleaning with a deep cleaner, and then reconnected back to wifi

chilly merlin
#

I think

#

So it's a win

#

Just a

#

Long

#

Painstaking

#

Win

shy osprey
#

Can someone hack the gubbament and delete my criminal record

mighty nymph
#

Can someone help me with decryption of a video files?

haughty dawn
mighty nymph
shy osprey
#

👀

haughty dawn
mighty nymph
#

I don't know , it's just showing ENC files

shy osprey
#

Sounds like stolen guantanamo bay videos, beware.

haughty dawn
#

can the app play them without being connected to internet?

mighty nymph
haughty dawn
mighty nymph
haughty dawn
#

likely has to retrieve a decryption key then. maybe try intercepting traffic and see if you can capture one

mighty nymph
#

Brootal crypt-pill , over for extractcels

haughty dawn
#

why over?

mighty nymph
#

Juss a beginner in cs

haughty dawn
#

sounds like a good opportunity to learn 🤷‍♂️

crisp star
#

You must be stupid as a dev to let your privatey key getting intercepted by something like MiTM

#

Why is that video encrypted in the first place?

haughty dawn
#

haven't used thm in many years so can't speak to that. i usually see it described as better for newbies than htb

#

are you running into any specific difficulties or don't feel like you're actually learning?

#

like just how binary numbers work?

slow edge
#

THM is a good platform for those who are beginner, not gonna lie HTB has much better content but maybe you want to learn something that is not in THM, what is your learning goal rn?

#

Binary and stuff? Like binary exploitation?

haughty dawn
#

that's a pretty simple topic you can pick up in 5min tbh

#

you'll want to learn basics like that at some point, but tbh a lot are easy to pick up as needed

#

the more fundamentals you know the more everything else will make sense

#

Finger binary is a system for counting and displaying binary numbers on the fingers of either or both hands. Each finger represents one binary digit or bit. This allows counting from zero to 31 using the fingers of one hand, or 1023 using both: that is, up to 25−1 or 210−1 respectively.
Modern computers typically store values as some whole n...

slow edge
#

Programming:

  • Scripting: Python, Ruby, Go (sololearn, codedex, freecodecamp, etc)
  • Web exploitation: JavaScript, PHP, ASPX, SQL (portswigger)
  • Binary Exploitation: C, C++, Assembly, Rust (pwn college)
    Learn any or all above langs as per requirement

Networking: netacad is good platform (THM and HTB Academy)
OSes: Windows (especially powershell), Linux (especially bash)
After covering fundamentals: Tryhackme, Hackthebox, similar platforms for hands on
Most important: Mindset with Insanity
Ebooks to read for cybersecurity:

Cybersecurity centric books:

So this is a general template I give, but lemme tell you what to cover as a beginner

  • Learn about networking (THM has stuff in modules, but if you can then also look at HTB academy, and also do in-depth searches on topics on google to find stuff on it)
  • For now atleast master one programming language (I recommend Python) also learn JavaScript gradually because it is needed in web pentesting....
  • Also learn OSes fundamentals from HTB academy (or THM)
security-books on Notion

A collection of free cyber security books.

haughty dawn
#

what's your current background knowledge level? any xp with computers beyond basic usage?

#

just looked up thm presec path, looks fine for starting out

#

though will say, you can't depend on thm or htb to teach everything you need to know, you should be looking up stuff on your own as well

#

personally i learn better when i have a specific problem i'm digging into and trying to solve, rather than more academic memorization

minor ice
#

Hello all I need major help with something . some buddy has a audio recording of me I need someone help in getting it deleted off of there phone before they take it to the cops

haughty dawn
#

there any particular area you're most interested in?

haughty dawn
minor ice
#

If somebody can help me with this private message me on Facebook Messenger at KC reeps o

#

I don't want to go to prison

#

Or does anybody know someone that could help me for some money that I can pay him to help me with this

#

I do have the Pegasus program in terms but I can't figure out how to get it set up

#

Termux

haughty dawn
#

maybe don't talk about crimes you did around people you can't trust

minor ice
#

I didn't know I was being out of your recorded on the phone

haughty dawn
minor ice
#

So Pegasus that's on GitHub is not the real thing

haughty dawn
minor ice
#

So where could I find the Pegasus program

spiral notch
#

it’s government level spy ware

#

do not expect to find it

minor ice
#

How can I get my hands on the Pegasus program for the ss7 network

haughty dawn
spiral notch
solar notch
#

If you’re in the US and can assist me with opening an Outlier account, and help with the verification, I'd greatly appreciate your help.
I've already been referred by a user for a project.

I'll perform the tasks, and you'll get a commission on each payout

spiral notch
#

i’ve analyzed the pegasus legacy sample but it’s literally not even working snymore

#

it’s from 2014

haughty dawn
minor ice
#

Ok thanks. Y'all have a great day sorry for wasting your all time

haughty dawn
#

gl

#

any particular area of security you're most interested in?

whole patio
autumn kite
#

Why do these people think that we just have top secret government surveillance tools to give out 😭

whole patio
#

magical thinking

halcyon lark
#

if i send msg in multiple chats will my server level go up faster, or is it just sheer quantity of msgs?

minor ice
#

Even so if it logged it's not my real name and not my account it's a buddy's account

whole patio
chilly merlin
halcyon lark
whole patio
#

no ratio, just "xp" .. and no more than once per minute.
You get xp when you were active, you get none if you were not active

halcyon lark
#

Ok, sorry if i'm not phrasing this right. For each minute, if you were active during that minute, you will receive exactly 1xp point. Right?

#

like its just 1 min = 1 xp point. this is what i'm assuming at least

whole patio
#

1 or 10 or whatever

#

doesnt matter

#

the amount is a fixed value

halcyon lark
#

ahh gotcha. you're right it effectively doesn't matter

#

i was just trying to see if i could calculate how long it would take to reach a certain level

#

going off of some values in the ranks chat, it looked like the amount of xp for each level followed a power-law growth

limber perch
#

Hi guys

agile idol
#

what’s up

autumn sable
#

howdy everyone

winter marsh
#

Hey hey hey

#

MacBook or PC

#

👀👀

slender pewter
#

Where i start from learning cybersecurity field?

agile idol
#

htb and thm

inland owl
#

Who can help me to with nmap i dont know much about it?