#👥・help-me
1 messages · Page 138 of 1
i see, thanks
Hello, I'm new here
welcome
Thanks, can you please teach me how to hack into someone's WhatsApp or Facebook account
No we are not, and you should take a moment to reread the #📜・rules of this server
My bad, I'll surely do that
you arent going to be able to do that and its not allowed anyways
i mean police cant do anything until 24 hours are over and usually until then its too late try asking his friends or see the location of his car .try asking people who might know where he might be and yea dont trust the dms in this world there is no f####### justice and everyones trying to use your vulnerbility
Im selecting a location to install windows and it shows "disk 0 partition: esd-usb" total size of 14.6gb and 8.4gb free space and type is primary but it says "windows 11 cant be installed on disk 0 partition 1" and when u click uh click details it says "the selected disk has an mbr partition table. On EFI systems, the OS csn only be installed to GPT disks" what shall I do
Hey guys 👋
Quick question for anyone who actually works in GRC
I’m stuck between SimplyCyber GRC Analyst Program and GRC Mastery (UnixGuy).
Real talk: is GRC Mastery worth the $500 or is it mostly basics with good marketing?
And if you took either course — did you actually build real stuff (risk register, control mapping, audit evidence, vendor risk, etc.) or just watched videos?
If you know a better GRC course that’s more “job-ready / enterprise-like”, drop it 🙏
1-https://academy.simplycyber.io/l/pdp/the-definitive-grc-analyst-program
I'm glad you asked this question i have been wondering the same thing
Im selecting a location to install windows and it shows "disk 0 partition: esd-usb" total size of 14.6gb and 8.4gb free space and type is primary but it says "windows 11 cant be installed on disk 0 partition 1" and when u click uh click details it says "the selected disk has an mbr partition table. On EFI systems, the OS csn only be installed to GPT disks" what shall I do
Hello guys, i'm mostly into coding but i've always loved hacking even tho I've never really got to learn it, I'd have a question for the experts and I'm seeking some help, If anyone could help me out please just answer or dm me
just ask here .. without knowing what you actually want to know, it's foolish to DM
Fair enough, I've got an account stolen and I was wondering if someone could guide me through, give me advices or personally help me out getting it back
your best bet is to go through the service that the account is registered to, sticking to the #📜・rules we cant help with that
We are totally not helping with account recovery in any shape or form.. contact the support of whatever service it is at
Alr, thank you for the answer and sorry if I was out of place
If people DM you now, they are trying to scam you btw
I'm an easy scam at this point ig
There even was a recent announcement about not being so gullible, and report attempts via #📩┃ticket
I'll check that out, thank you.
Btw does any good source I could learn the hacking basics exist?
Best to start here #👥・new-member-guide
She came back home safely
I’m exploring hardware security from the board level — shunt monitoring, relay-based power isolation, CAN bus nodes, and tamper-aware design. If anyone here does hardware hacking or embedded security research, I’d love to talk.
Glad to hear
Hi everyone,
I’m a final-year Cyber Security student working on a bachelor project where we are conducting an authorized social engineering and security assessment for a company (with written permission and defined scope).
Our goal is to simulate a realistic awareness test (QR/phishing style landing page, measuring interactions, not collecting credentials) and document the methodology and results for academic purposes.
I’m looking for advice on:
• Best practices for running ethical social-engineering awareness tests
• Tools or setups commonly used for tracking visits and interactions in a controlled way
• Things students often overlook when planning these kinds of exercises
Any guidance or resources would be greatly appreciated.
Thanks in advance!
Looks like a great project!
I'd recommend defining clear metrics before launching (scan rate, click through rate, report rate, time-to-report), It will make your results much stronger academically
Thanks!! At the moment, we’re struggling to get a phishing link/landing page setup working reliably and accessible for testing. Already tried Medusa etc.
Why not write your own phishing page?
It's probably also much easier to extend additional feature.
yw, If it’s fully authorized i'd suggest looking into sum established awareness platforms instead of building your own from scratch. Your supervisor or IT contact should validate the setup before going live
Hi may someone please point me to the best Linux system training via YouTube channel
heya there are a few good ones but a good place to start work be network chuck and check out the #👥・new-member-guide
Thank you Sudo really appreciate it 🙏
happy to help, there is also a fun one called terminus from mit that is good for getting used to it
it doesn’t seem clear yet 🤔
yo guys im trying to get my old instagram account back i forgot my gmail password but i got my email account address can someone help me?
Y'all I have someone's mobile number and their snapchat so is there any way I find their insta from what I have
Contact instagram support
Take a look at the #📜・rules and then ask
duh
Hi guys, I need help with CTF problem that is cryptography, cracking, hashing can anyone help me plz : )
Sure
give me a minute so i can send the challenge
Roger
how can i send a file here?
I think you can't
You could describe where you getting problems
And i could help you from here
ok sure give me a moment
Roger
the description: (An attacker has an access to my machine leaving a file holding the passwords he was able to crack, but I think he was not able to find the passwords I hashed them all.)
that file is Zipfile that contains a file named key-to-heaven that is encrypted with password that somehow i get it which is : qawsedrftgyhujikolp
in that file there's hash i think it's MD5 and it's: 2013226969c8633a183992b7c9f48234
i already tried everything that i know: hashcat and every and each tool i can find on the internet to decrypt the hash and i couldn't the name of the problem is Dumpester on website named crowdsecurity that's all i get from the problem plz help me cause this shit would take for ever to solve
First of all MD5 is NOT encryption
You can’t “decrypt” it
Only brute force, dictionary, or find the original message
yea
Also check if it really is a simple MD5
it could be salted: MD5(pass+salt) or it could be double MD5: MD5(MD5(pass))
the Zip password is weird keyboard pattern, Maybe the MD5 is based on it
Try variants: uppercase, reversed, append numbers, and thus
could u tell me how i'm likely new to this field
hello everyone im kinda new here but i do have a question with enabling sudo i just wanted to ask what do i have to look out for when enabling sudo cause it says it can expose personal data and security risks i just want to make sure im doing the right things
Whoops sorry i didn't see it, you could check online MD5 databases (CrackStation, hashes.com), try MD5("key-to-heaven") or MD5("Dumpester") and try combos with zip password: MD5(zippass), MD5(zippass+filename) etc
if those don't work tell me an we'll plan another thing
🙁 nothing works
Hi can someone help me
Any command runned with sudo can delete files, change permissions or even install malware that's why it always asks you if you're sure of what you're doing
In this case you can use it without worries
with?
No?
ok thank you
Nah uh
Let me think
Well, if It’s a real MD5 it's not in any online DB and hashcat didn’t crack it Then probably it's not meant to be brute forced.
now
I'm trying to create this in to an app marginTop: 20,
},
});
export default HomeScreen;
import React from 'react';
import { View, Text, StyleSheet } from 'react-native';
const AviatorData = ({ data }) => {
return (
<View style={styles.container}>
<Text style={styles.dataTitle}>Aviator Data:</Text>
<Text>{JSON.stringify(data, null, 2)}</Text>
</View>
);
};
const styles = StyleSheet.create({
container: {
marginTop: 20,
padding: 10,
borderWidth: 1,
borderColor: '#ccc',
borderRadius: 5,
width: '100%',
},
dataTitle: {
fontSize: 18,
fontWeight: 'bold',
marginBottom: 10,
},
});
export default AviatorData;
npm install
npm start
So what the hell that shit well be i'm really tired of that problem but i will keep going till i found that shit
ok and what
But I don't know how really
The hash is probably something simple, if it is not meant to be decrypted
what do you mean
what are you trying to do?
do u think that hash is related to like name of the problem or the file?
Probably
That is a coding of the app I want to create but I'm struggling to put the coding in to an app
Also, the challenge name is Dumpester, that screams:
memory dump
password dump
or credential reuse
Maybe the password is reused somewhere else in the zip
unfortunately that website doesn't have a constant format like picoCTF and i really tried all the formats i knew but also nothing works
dang
How? there's only that file named key-to-heaven only that and only contain that hash
in crypto challenges, they often:
Fake MD5
Use modified MD5
Use MD5 collision tricks
Encode something inside something
Or make you misinterpret the hash
And wait
what
hmm u r right
MD5's usually look like this 5f4dcc3b5aa765d61d8327deb882cf99
so it's not a MD5?
It might NOT be MD5
also
does the challenge explicitly say MD5? Or you assumed?
or that is just modified?
I'm just assuming
gemini and chatGPT and claude said that hash is MD5
It looks like one
But if it was the ctf usually tells
hmmm
i will now
Roger
dang it how can i check?
Broh 💔
yeah ur bonkers
sry, im really new to that field and i know nothing but i'm trying to learn
did u use hashmyfiles to actually just check the md5 hash of the key-to-heaven file
see if it matches
cuz u could literally just be going down a rabbit hole of nothing
He already tried (or that is what i think 💔 )
nah
sry : (
that's the MD5 of the file : 444f60ac20a1374290d7bdbdabad56a5
sry buddy
No problem, next time tell me what you tried
thx for ur patience
yw, anything else tell me
i tried to crack the hash that 20132269 in cyberchef crackstation, hashcat and every AI tool i know that's all i did i think
what about i told you at the beginning 😭
wdym like what?
anyone have badusb or ble scripts for flipper
^^
I don't think that's ethical
i tried that with claude and nothing works too
I understand but gng you can't just appear and ask for non-ethical scripts 💔
Since it’s hex encoded, if we separate each byte we get one repeating character and some other patterns that look suspiciously like they form part of a word. I tried to convert it to ASCII but it’s just garbled. So maybe it’s using some sort of primitive cipher, like adding a certain quantity to the characters, etc.
Could try your luck with that.
Can any one help me learn Snapchat hacking
does anyone know how a virus is able to send data back via email or sms?
I don't think that's ethical either
what do you mean
some scripts ive seen are able to steal data but then they can send it to you by email and i was wondering how it was done?
Depending in which language the malware was written, I'm pretty sure there is some kind of library you can use to send mails.
okay was just curious
ye just use smtp libraries youll be able to exfil data via email
I’ve never written malware, but I’d probably relay it first through HTTP to my own server, because not all systems have a working email setup. And I assume that that’s how the SMS thing works too.
using device's api can send data to attackers number too
malware just uses normal protocols (like SMTP, HTTP, APIs, etc.) to send data out
What device APIs? Most computers don’t have a cell radio and SIM to do that.
agent tesla is a notable example to use smtp to send emails
malware on mobile
Ah, that makes sense 👍🏽
@old stream Big problem you got right there
for android - SmsManager.sendTextMessage()
can someone help me? I am really new to this and would love some guidance. Right now I’ve been following the lessons on tryhackme learning networking first and at the same time learning python however I dont have much experience with software and dont know much about linux or installing all the tools. I do have some knowledge on OSINT cause of my job and I am really interested in red teaming
Probably not very silent, though.
You’re on a good path, focus on Linux basics, networking, and sum Python first. don’t rush tools
Where do you need help exactly tho
some tips or some kind of roadmap i guess? what should I focus on?
ye focus on learning linux first and understanding fundamentals tbh and most important develop the skill to explain technical terms in layman term as you will be engaging with stakeholder that often wont be very technical
I think a linux vm is a good place to start to learn how to set things up.
install ubuntu most easy to go linux variant play around and have fun with terminal first thats what i would recommend!
You can find the roadmap there
where could i find a trusty source for a linux vm. last week i tried looking for one but had to pay? for it
I use virtual box for my vms
all linux os are open source bud minus few just to go their website and download iso
thank you Ill use this and focus on pen testing
understand fundamentals first rather then pentesting tbh
i also admire grey hat work and would love to work on that
oh yeah, i know i should learn the basics first but thats my goal
If you want a personal recommendation: use zorinOS, it's a beginner-friendly ubuntu based OS very similar to windows
not trynaa demean or anything but id say white should be your goal 1 mistake can cost you a huge chunk of your life depending when you love
*live
ive seen plenty of law suit for people poking around systems that they dont own! or have permission to test!
yeah, I like to be good at something before advancing to something more complex as i said my goal is pentesting
anyways thank you all for your help
I think kali is a good distro to start with, because it comes with a lot of tools pre installed
i have a simple question about emails
if your account gotta taken over by a forner email what would i do?
Is anyone in here aware of any remote jobs?
Or stuff I can do to make money online having $0?
Guys, is there anything I should be doing simultaneously alongside tryhsckme considering my goals of becoming a red teamer?
Ive completed TCM Academy Helpdesk, THM PreSecurity and now im on cybersecurity 101 exploitation (2nd metasploit room exploitation)
I'd recommend completing the penetration Tester path and red teaming path from tryhackme.
Then switch to Hackthebox. You'll be grasping deep knowledge from there
Hello everyone I need help could someone please message me on here
Just say what you need help with in the chat and if someone knows how to help you they will respond @wild pollen
I need help trying to help find my friend who ran away I don’t know how to
Contact the police, we do not help with things like that in this server. Beware of scammers DMing you saying that they can help.
hi guys, i need help regarding from where to start cyber security, no one tells in a crystal clear way, so where should i start from and are the sources available on for free like on youtube etc?!!!
#👥・new-member-guide read through this there are resources and a guidepath depending on what you are trying to accomplish
HIII i need help in APi hacking so can anyone tell me whats the best way to learn it i mean the concepts and the topic in it if anyone canshare any typo info on it or will be able to explain it i will be more then happy to kno w
Hi everyone. I just entered the server and read the guidelines. I didn’t see anything agains what I’m about to say but if I’m doing anything wrong please let me know. I want to be respectful to everyone. I have had a passion for cybersecurity and technology in general for a long while. But due to personal issues and conflicting interests I was never able to fully enter this world. However the passion was always there. I started to try to learn some stuff on YouTube and some online courses but got nowhere. I decided then to read a lot of documents and books and even started to explore and play around with capture the flag and vulnerable machines. But there’s so much information and so much to learn and most of it is always evolving and changing super fast. I get super overwhelmed with information and the flame fizzles out. I feel like I need some direction and help. And I know its too much to ask but I’m a slow learner and I need some personal assistance. If anyone has the time or patience to help me it would be awesome. I’m not asking for you to be my teacher for free all of a sudden. Basically I just want to have a chat with anyone who would feel down to help. Some casual stuff. And if after that chat you still feel compelled to help we would go from there. Thank you for your attention and I’m sorry if I’m doing something wrong
anyone?
i want to get into Pentesting, where should i learn from?
If you're interested in API security, start with understanding how API''s work first (REST, HTTP methods, authentication, tokens, etc)
Then learn common API vulnerabilities from an OWASP perspective (like broken authentication, authorization issues, input validation problems)
PortSwigger got good labs for it
Yeah you can ask for it
That’s a way
already tried, I need it asap
its not easy though
what makes you think its easy lol
this is meant to have hackers in it right? Including black hat. Someone must find this as easy work
Need help with new sentinel Rules for high severity . Building soc
well, not really, here its mainly beginners, and even if there was someone with a lot of experience, it still wouldnt be as easy as you think
there are protections to protect against hacks
i got my instagram hacked, the hacker changed my email number and everything, is there a way to recover the account still?
contact instagram support
is there a way to hack back into the account?
no.
have no support
yes they do
do you know how the hacker might’ve been able to hack my account?
probably phishing, or your account/password was leaked
and you ddint have any ercovery options
is there a way to get the account phone number from the usernamev
You should know the phone number linked if its your account, admit it you're like me trynna get back at someone
no they changed the phone number
i did look up but couldn’t find anything
then you cant
@short quail what if i am like you any luck then?
We will not help with that here. Read the #📜・rules
but im trying to get back my account
Dont care, please contact the support platform. We dont help with unethical acts or Vigilantism here.
Well for one you can start here bro. #👥・new-member-guide . Then just continue chatting. There are alot of members here that are on the same path.
Most of the resources listed in there are stuff that I already explored quite a bit. I didn’t explore those resources throughly yet and I’m definitely gonna take a look but from what I seen its the same vibe as stuff I seen before and I still have the problem of lack of direction and its a bit overwhelming. But thank you for taking the time to help out genuinely
Pleasure my friend. The part where you are now can be really overwelming so i would suggest starting with blue team fundamentals and work through that. If you have some researched questions feel free to ask @devout linden . He doesnt mind helping out he's an experienced blue teamer in a professional capacity to,
Where do you seem to be stuck?
Where are you at on the journey?
Any direct questions i can try to address?
read this
A little too vague for me to help dial it in unfortunately
well it answers your intital 2 questions
hes stuck because he gets overwhelmed by all the info and feels like its always changing and evolving
and hes clearly at the start of his journey, a beginner, because of that
As I've been in the IT field for a while it does not answer the question. I'm asking direct question to gauge where to start. When asked these questions I need to know a bit more direct starting points so I can target info that helps out.
Without that information I can data dump a good bit and leave them in the exact same place. I've worked in a NOC working with Network engineers, security engineers, architects: i was a Systems engineer and now am a SOC analyst moving into the Pen testing/red team area. Over the years I've had to learn how to articulate the question and help provide - What the issue is at, what issues I am having, what I've tried, what I'm confused on with the situation. The same template applies here but the questions I asked were intentional
Guys is it possible hack someone with Bluetooth
I'm doing the nisco academy course
And I t said that it's possible
yes
though not without some zero day exploit and outdated phone/bluetooth
also depends on the system that bluetooth is running on, like if it was an iphone you wouldnt be able to infect it with malware or anything
Sorry we cant really help with this
we cant help with this
Leagal reasons?
yes legal reasons
and we dont know if your gonna do it unethically
yes we cant know what exactly ur using it for
no worry
Understood
It still shows you lowkey how to do something very malicious in nature, just remove the cat thing lol
I understand.....
How do they hack.it needs a pairing code right?
yes if you were legitimately pairing the device
though that could be bypassed with the right exploit, depends on the scenario
Is it possible to bypass them with a phone?
Dw I'm not trying tohack people with the Bluetooth thing.I just wanna know
with the right vulnerability and exploit, yes
Ohh
yo what is this ovo role how can I get it
hello. #🛠️・homelab-setups
its a server tag, you can get it by clicking the "OwlSec" with the little down arrow in the top left and clicking on "server tag: OvO"
it doesnt do anything just advertises OwlSec on your profile, like no @crimson harness here has the "CYBR" tag
thanks bro
Hey fellas, not exactly a coding question nor OpSec/Cybersec question, but instead a concern of mine regarding Discord and what you guys are going to do about it
Discord soon will start rolling out age verification requests, and should one not verify, they'll be locked out from pretty important features.
Most of you know probably that Discord recently had a data breach (70k IDs), which brought to light that Discord lied about its data policies. With the recent news coming to light regarding ties to Palantir and its age verifications, what are you guys going to do about it?
I cancelled my nitro subscription, and I plan that by March I'll be leaving the platform completely if push comes to shove.
Not really a technical help question. You can be the 1000th person to ask it in #💬・old-gen-chat though
Heyy all, I need help with Cybersecurity field in general, in general idk how to say it but like I want to what are the roles provided in IT field, which well to least paid roles and also which is the most interesting
@tranquil heron
Do not ask for such things here.
Read our #📜・rules, specifically #3
And please read this as well
#📢・announcement message
Ok thank you for the info
Stay safe, there are more scammers out there.
#📜・certs-and-career
Tryhackme also has this information neatly wrapped up as well.
Thanks so much mate! 🫡
Ohh I just like the cyber tag .is that a problem? 😕
no
U can wear ovl tag too right
Because u don't have a guild tag
dont want to
Hiii
Can you guide me on how should I start practicing CTFs?
I've got a hang of some tools like nmap, metapsloit etc
only tryhackme
I see
If you’ve done TryHackMe, start doing CTF's where you don't get guided tasks, try platforms like Hack The Box or picoCTF (what i use) for practice, after solving, take notes and after finishing, read other writeups to see different approaches. That’s how you improve faster .
yw, good luck!
nobody will help you with that its illegal
Broh 💔
So tryhackme is a starting point?
Yeah
It's a pretty good beginner-friendy platform
So im new LIKE REAL NEW i know about tryhack me stuff but its paid tbh our teacher taught us some stuff, yes SOME. I wanna learn and experemint but how can i attack stuff that is equal to a real world thing. I know a bit of DVWA or some stuff like this
Main point is how to learn more without being arrested?
Im a cyberseucirty student and i failed password attack like in byrpsuite so basically im not a know at all. Any help , suggestions, etc??
do CTFs
Where??
download vulnerable images from VulnHub
or https://tryhackme.com there are countless CTF rooms in here
same with hackthebox
same with https://pentesterlab.com
arent tryahck me ctfs paid
Thank you so much. ive heard tryhack me stuff but this other stuff i havent heard off
Thankss man
Oh yeah one more thing. I want to learn the tools to use like there docs cause u know i cant ask chatgpt or any AI on how to use this tools cause of policy
@supple oak I'm right there with my ya...
*ya
so read the documents
Where??? man command on linux only gave me bare bones
google sir
Update
brings these top 3 results
explains how airgeddon works in full detail
just replace "airgeddon" with whatever tool you want to learn how to use
Or just use the linux command "man" 
.
thankss
man gives the command definition
It shows you the manual
anyways THANK YOU FOR HELPING GUYS
its not that much detail is the problem
like it wont give u sample command uses
it is very detailed 
You only need to understand the flags / parameters.
he wants dev written documentation man
some tools if u man it. it wont give stuff like
nmap -sn (ip address)
like this stuff
thanks again @blissful sonnet for the help much lovee
You just need to use man nmap
Where can i learn ethical hacking fully and master it
On youtube is it fully explained
Idts
there are many courses and resources yes
a few weeks ago i installed kali on an old laptop as a single OS in the pc then when i started using it, in a few mins it froze entirely and the situations same with GNOME and xfce
reinstall windows and just use virtualbox and setup a vm
Kali is a large Linux distribution
It does not work well with old stuff I have found
Just use something smaller and download the needed tools
Use anti X for ancient decrepit hardware if literally nothing else works
Before switching to cli based os
mastery comes with experience and practice
Where can i practise and get experience from
you can practice with tryhackme, hackthebox, and building a home lab
experience, you'll have to actually start hacking
Id even know shi abt it
Like ik the categories
They r divided into
mastery of anything takes years, you'e not going to get it from youtube
but you can get started on the path there
Then from.where
So is it okay if i start learning from youtube
you can learn information from there, but you can't build skills from watching videos
Then what do i do?
tryhackme, hackthebox, CTFs, spin up vulnerable VMs to attack
Kali linux
you should learn how to use linux but it doesn't need to be kali
It is the main thing for ethical hacking
it's just normal linux with a bunch of tools preinstalled. you'll learn more installing them yourself
nobody i know in offsec lives on kali fulltime. 99% of the time it's used for disposable pen test VMs
Whats disposable pen test vma
Is it better than kali
a virtual machine that's spun up to do a pen test, then discarded once the test is complete.
e.g. i've done a few pen tests where the client setup a kali VM on their network, then I was given remote access and did the testing from there
Oh
Well imma learn all this shi after 7th march
why after then
good luck
what kind of math?
@covert belfry
Is there a reason you are posting a random link in here?
Do you have a question?
idk what that means, in USA people in the same year can be taking different math courses
Oh m indian
I’m exploring hardware security from the board level — shunt monitoring, relay-based power isolation, CAN bus nodes, and tamper-aware design. If anyone here does hardware hacking or embedded security research, I’d love to talk.
what does shunt monitoring have to do with security?
the whole approach is odd
Good question. I’m looking at shunt monitoring not just for telemetry, but for detecting abnormal power signatures — voltage glitch attempts, unexpected current draw during crypto routines, or unauthorized firmware states. Combined with relay isolation and CAN reporting, it becomes part of a tamper-aware hardware trust model.”
Do you have these on copy and paste?
Why you using AI to reply bro
💔
You didn't even remove the final "
lol
power signatures are not unique identifiers of a firmware state
that wont work
I use tools to refine articulation but the ideas and architecture are mine. Same way we use compilers or analyzer and tools enhance thinking, they don’t replace it
how do i use bleach
my man, its obvious that this is ai you dont need to try and pretend
its okay
Please don't send the same AI message over and over again.
the liquid
B
#help-me-with-laundry
Fair enough bro I’m experimenting with ideas and refining how I communicate them and The architecture itself is what I’m focused on.
Honestly I couldn’t speak my English properly bro so I’m using tools to refine it to your language
CNN
hey no problem, my advice would be to in the future, ask if an idea sounds plausible -> and from there get a bearing on how to make that something possible taking in any input you get.
Just state the fact of matter
Im not saying to stop using the tools.
I am saying to stop repeating the same message over and over again.
Its to the point where it could be considered spam at this point.
good ideas expose themselves, people will naturally begin responding. If no one is responding thats a good hint.
Come have some other conversations with us in #💬・old-gen-chat instead, and see if different groups of people maybe understand the ideas, and just don't know the official terminology.
Linux is the kernel and Kali is the distro.
Thank you. 🙏🏻
You can use "uname -a" on any Linux system and it tells you the version.
kali is to linux like vanilla is to ice cream
hello
im using hydra to brute force a login page but its giving me false positives when i try the credintials manually they dont work
any help?
Are you doing a TryHackMe room or a CTF challenge?
yes
Appreciate the feedback bro. I’m still refining how I frame the idea. I’ll join the other channel and continue the discussion there bro
Is there are write-up for this challenge on the internet?
dont get what you mean sry
write ups are solutions that someone posted for a CTF challenge. You can probably check their command out and you are likely going to spot your mistake pretty easily.
its hack the box i dont think its allowed
Oh is it still an active box?
yes
Okay yea then it's not allowed.
hydra gives me like 15 valid credentials but nothing works manually
see if the response you're getting back is different from a cred it marks as invalid
You should probably check out HTB discord server and ask in the channel for this challenge.
can i share my command here?
oh i can get help there?
Yea, if it's an active challenge people can give you a nudge if you are stuck.
We can not assist with CTFs here. They are suppose to showcase how well you are able to complete the challenge, not who you could get to help you complete it.
But yeah, listen to Deadbeef. The official platform that hosts the CTF(HTB in this case) might be able to generally help with them.
Also check this room out.
https://tryhackme.com/room/hydra
i just asked for help why am i getting false positives thats all
And maybe you are not even supposed to use brute force 
i know i just want to know why am i getting that
appreaciate your time
Ah yea forget to mentione that one.
You can try and use the following flag:
-v / -V / -d verbose mode / show login+pass for each attempt / debug mode
Debug gives probably more information
ok ill try taht
thanks kitty
when a tool doesn't work it can be helpful to look at the underlying data
Thanks for bringing me here
How do I get started guys🙏
^^
Good noon y’all. I’m a beginner. I’m having a little bit of trouble with my PC’s wireless dual band. Bluetooth I’m not no worried about but more so the my wlan0 connection. It seems to not want to stay connected. It’s acting like fresh bed sheets. Just when I think I’ve got every corner on nice a snug, the last finishing touch seems to pop of one or two of the corners I literally just tucked.
I recently did a fresh install of Kali purple not on a live boot this time but I put it on a SATA SSD. I strongly feel like I would not learn about the system itself if every time something were to “break” my go to were to do another fresh install. Back to my predicament, I’m able to connect to wifi, but it won’t be a sold connect. It’ll “randomly” disconnect when I step away for a moment or as I look away to ask ChatGPT to try and figure out possibilities. From old kernels and drivers to obsolete or upgradable repos. Might be 2-3 things that will need to run basic commands but everything will usually check out, with no Error messages after running the command(s). Seems to be stuck on power save mode even after opening nano and changing the power save sum of 3 to 2. Run back the command, checks out, reboot to lock it in and it still continues to show similar behavior as if it’s powering down when idled for a short while.
I’m thinking I just need to do a simple upgrade than going gray over it. It’s an Intel 3168 🙂↕️🙂↕️🙂↕️
TIA to whoever can help many help is much appreciated as I’ve been going at it with nothing but Simple’s since 6am 😅
I see, you could try:
sudo iw dev wlan0 set power_save off
Tell me if that fixes it
Also make sure iwlwifi is the driver and reinstall firmware with:
``sudo apt install firmware-iwlwifi`
@rain sluice Did that fix it?
It’s returning with nothing for the first command. That same command was one of the two commands that had me in a loop this morning. My wlan0 would in fact check out, but when I’d run the command again after it checking out only for it to still say, “state DOWN”
dang
The 2nd command error package firmware and package iwlwifi
Make sure your non-free repo is enabled in /etc/apt/sources.list
Hold up! I think I typos that 2nd command. Let me run that back real quick
Sure
I added a space after the hyphen 💀
💔
Firmware is already the newest version. 0 upgrading, 0 installing, 0 removing and 0 not upgrading.
🫢
dang
deb http://http.kali.org/kali kali-rolling main non-free contrib
Why i always fail with `` 😭
then try again update and install Intel firmware:
sudo apt update sudo apt install firmware-iwlwifi
After that reload the driver and bringh up wlan0:
sudo modprobe -r iwlwifi sudo modprobe iwlwifi sudo ip link set wlan0 up
@rain sluice
Non-free and non-free-firmware both already enabled
My fingers hand a mind of their own as well. Happens to the best of us 🤗
Don’t worry, I was at it 4 out of the 6 hours before I decided to ask for help here. As I said it threw me into two loops because it would checkout but then as I’m running the command back to verify, it comes back with error messages. Even once or twice after a hard reboot and also a cold reboot pulling the power cord and expelling the held power by holding the power button for 30secs
You did what you could and I really appreciate you for it. Truly 🙏🏼
Still some hope though. Since my wlan0 will disconnect on me, I’m trying to not have it time out resulting in an error message. Gotta keep keep the mouse moving till 100%
Hope you get it fixed soon!
What's a good way to showcase my journey of building and maintaining a VPN server, for free.
Hahaha I hope so as well. No matter the outcome, it will be a learning experience. It’ll be one of these outcomes, either we learn that we can fix it, that we can’t fix it or that we could’ve saved some time by upgrading the component for about $20.
You just did it 👏🏼👏🏼👏🏼
A free cameo advertisement that catches people off guard and sparks enough interest to intrigue.
bro can anyone help me with having access to phone when ever i want to even when not connected to the same network after exploiting?
A SIM card ?
yes
Hey everyone, can you recommend some good resources to learn networking?
Hey aside from udemy, is there any other good resources to study A+, Net+, and Sec+?
Please I need help on how to create USA wireless ESIM which give 1 year free Gb, my guys do it but they don’t wanna teach me 🙏🙏🙏
I’m looking to upgrade my 2015 MacBook Air. Has anyone done this and have recommendations? This is what I’m looking at for SSD:
SAMSUNG 990 EVO SSD 2TB, PCIe Gen 4x4, Gen 5x2 M.2 2280 NVMe Internal Solid State Drive, Speeds Up to 5,000MB/s, Upgrade Storage for PC Computer, Laptop, MZ-V9E2T0B/AM, Black
who is able to help me make a script for trading i made one with ai but idk what im doing with ts lf someone to give me some advise and stuff
Hi, im going to do my first audit as a pentester!
Please give me some advice, im very nervous about it, but its the first step in this career
Professor messer !!!
I have a couple of PDFs does he have any videos too that I don’t know about?
He has tons of videos on his site or right on YouTube he even has the older versions of the test I believe. He goes live for study groups also, and I believe it’s once a month! Also on his site if you buy your exam through him it’s a little discounted not a lot but hey a few bucks is a few bucks 🤷♂️
they said i need email to confirm i cant get in i need my old email
yo guys im trying to get my old instagram account back i forgot my gmail password but i got my email account address can someone help me?
i already tried breached passwords no luck
Appreciate it I’ll look into it
whats the easiest way i can explain to my friend that the camera hacking from watch dogs is not possible?
Quite simply just say it's not that easy
Like it's not that hard to just be like bro that shit's not possible get a hold on reality
Now that may be a bit aggressive
However if they believe everything they see in video games and media
Hello guys, just wanted to ask how can i bypass my student organization account which is in recovery mode and asking for backup codes (which i dont have) and selfie video verfication which is failing.
bro he thinks call of duty is real footage of wars that have happened 💀
i think hes too far gone at this pointt
Brother what
You have to be trolling you have to be baiting in some way
There's no way
How old is he
Anyone here good with Ubuntu?
yeah, its based on debian
its really common
I'm trying to reformat my windows to be my server using Ubuntu, but I'm stuck. Haha
is someone here good with cryptography?
first gotta get the "ubuntu server" iso onto a flashdrive either through rufus, belena etcher, or ventoy(highly reccomended). then boot computer into bios with the flashdrive inserted. then choose the flashdrive to boot and install the iso.
ill get some links for you
Yeah, I already did that, but I am stuck at storage configuration.
ah
You mind if I add you? @long cosmos
If I was making an tool on OSINT, what all stuff would it need to include to make a good/normal tool, (just to help me), like, I currently have images covered (like meta data, gps data, hash) and so on, and also domain information, but what else should I cover? like additional things I should add to my tool (any ideas?)
Thank you guys fr
Hello 👋 everyone
Asking for help for a friend
How can we delete all our products from Google Merchant and resync them back
WHOIS + DNS records (A, MX, TXT and NS history)
Subdomain enumeration
IP intelligence reverse IP lookup)
Username enumeration (cross platform presence check)
Email OSINT (breach exposure check, MX validation)
Social media footprint aggregation
Metadata extraction from documents
Basic breach data lookup ("Have I Been Pwned" style check)
Geolocation visualization (map output)
you could also think about:
Clean report generation (export to PDF)
API integration with public data sources
Rate limiting + logging
Modular design so you can add new collectors easily
I just joined but I think I seen something with what you should start off with diving into first when they path you’re aiming towards. In new-member-guide
I’m new to this and don’t have any advice to give. Just wanted to with you good luck! You got this!
Anybody here know how scammerpayback do them geolocatin of the specifc buildin the scammers are at? I tried geolocatin ma-self but shows a different location, somewhere a bit far from where i am actually.
Thank you so much fr, I will work on implementing it all ❤️
Anybody have an idea what kind of projects could i pursue individually beyond my qualification to apply for a system support/jnr tech support remote job roles?
You typically get the location of your ISP - its pretty much all you can get from an IP. scammerpayback never disclosed that, but its likely either a location service on a smartphone or osint based on info they gathered
Hm hm hm hm hm hm
Gotcha @whole patio . Thanks 👍
I can't send gif but em fired up 🔥🔥🔥🔥🔥
Like if I can see your emails, and you ordered a rather large amount of takeout to an address during business hours.. well
Hmmmmmmm
I guess iz a bit trickier than what i expected.
At least now i know what i need to be good at to do what they do.
Oh no 
Does anyone have any recommendations on what to do after completing everything in the #👥・new-member-guide ?
Hello guys I wanted ask what's the best way to practically learn the skills required for pentesting. How do I get hands on learning experience. I tried thm, htb but I don't feel like I am learning anything. @everyone
Does anyone have any advice for learning Ghidra? I am trying to automate the extraction of information from malware files.
Idk Gihrda... but have ya tried chatgpt? Or kaligpt
Have ya tried gettin on the pentester path at THM? Or try doin challenges in THM. Start with the 2-10min ez ones, open some walkthroughs and take notes on what ya learned from that experience... daz how i tackled hands in learnin in THM... tho i did start with cybersec 101 just to build a bit of foundation so i know what i'm doin when i actually use tools for hackin.
After that, iz all repeatative actions... hackin becomes breathing. Ya do it everything naturally with muscle memory and instincts
Ohhh I have tried doing challenges and have basic foundation. Tho I have not tried pentester path. Maybe I'll give it another try like you say.
Yeah I want it to become that
Glad to hear
Yeah yeah do that. I actually didn't finish the last part of cybersec 101 cause it was more on the blue team side of things and i get sleepin readin it... and so a friend suggested i skip and go straight to pentester path and lemme tell ya that path iz 🔥🔥🔥🔥. Even during days when i'm demotivated to even open one room in THM, once i start readin just one task, I can't help maself finishinin a whole room in pentester path.
Dammm I must go check it out i feel
But yeah
Dun forget to sleep
Or ya gonna be like me. I keep missin words. Aiyaaaa.
Hey everyone, I need some honest guidance.
I’m a beginner in cybersecurity. So far I’ve learned networking and basic cybersecurity fundamentals. Now I’m trying to understand how the web actually works behind the scenes. I finished learning JavaScript and currently I’m learning backend from first principles because I want to deeply understand what’s happening in the background, not just use tools blindly.
Am I on the right path for a career in cybersecurity? My goal is to truly understand how all this works at a deeper level.
If I’m doing something wrong or missing a better approach, I’d really appreciate advice from people who are experienced in this field. What should I focus on next?
Thanks in advance.
well, depends on what career path you wanna have. But anyhow, i see you strengthening your foundation... but iz foundation. Em no pro nor do i have any background in IT or any anythin related to computers aside from robotics (which was my dad's hobby)... but base from my experience and the goal i wanna achieve (bug bounty hunting) you on the right path. Just dun forget to build the rest of the building and not just your foundation.
Haha thanks for your help
Thanks, appreciate it.
My goal is to become a Security Architect, so I’m focusing on building a strong foundation first. I’ll make sure to build the rest step by step, not just stay at the basics.
Sure 😅
LMFAO
you can do this with Ghidra Scripts, or an MCP server
my goal is to be expect in bug bounty hunting, i have learn tryhackme, i jusr finish cyber security 101. i hope i'm on track? you can give me a road map on how to accomplish that
go do pentester path next
daz where it kicks off
plus, try to do super ez level challenges like those that are 2-10mins only.
just need alata exposure with with bugs... after that choose which type of bug or vulnerability interest you the most and try to specialize in that. Personally, as of the moment, I am interested in XSS vulnerabilities and I do plan to do a deep dive about it
sounds like a good plan
bug bounty is pretty crowded right now, cause lots of unqualified/inexperienced people are using any AI to do it for them, and they soured the clients with low effort and usually dead wrong reports
i need some help if i can get.
with what
uhm so look my roblox account was hacked a while back someone recemmended me to ask for help here
is it legal and ethical? and within the #📜・rules
No it’s not
contact Roblox support
i did they said send a pic of your transaction history but i dont have access to that so they always just close the support case
Someone could want to hack another person’s Roblox account by saying that account is “hacked” to gain access
unfortunately ur just gonna have to make a new account
Them move on. Nothing we can do to help
i have my discord connected to that acc and authenticator it was the email and password that was changed
I guess that helps but if roblox support doesn’t accept it then we can’t help
i sent roblox support some playsation transactions but they dont accept them
Well unfortunately there’s no other way we can help
ok
Can someone help me with a good phone keyboard app to use
hello, sorry for interrupting the conversation, i am currently doing a ctf and there are no writeups to help myself, i think its hard (and i have some experience with other ctfs) it's a steganography
can anybody help me do it or at least teach me?
what do you mean by this?
What makes it to where you’re not able to acquire the purchase history? Which login was “hacked”, wouldn’t you be able to get access to your purchase history through your Play/App store? 🤔
roblox purchase history i cant access that without being logged into the account
I see. The account is PlayStation?
i sent support playstation history but they didnt accept it
Sure…If that purchase history from your PlayStation account was in fact linked to said account wouldn’t you be able to login from your PlayStation account to gain access to your “hacked“ account? Being that it was linked and all.
nah look the hacker logged me out of everywhere by changing the passwords and he also removed my emails from there and when i sent transaction history from playstation support said they dont look accurate as a ps one when i sended them by taking screens shots from the playstation app and that account was actually mine its name is yahyaomgyoutuBer u can check my discord its connected and i can also show u authenticators pictures to show its connected and comfirm its actually my account
I would say your best bet since you can’t get the actual purchase history from the account that was “hacked “then you could show receipts of your purchase history from your actual bank statement that will match up with the purchase history from that account. I’m sure that if you can match that up with whatever bank card used along with your personal information to validate that you are the account owner, it will give them a reason to look further into it rather than just close the ticket on you.
I bought gift card codes 💔✌️
U can confirm that the account was mine as look at my connected accounts in discord that account is connected to discord
Thanks.
I mean being how recent it was that you loaded funds from a gift card it can be traced back to match that gift card. If it was an online purchase better because you’d have an electronic invoice on it, but if it was a physical card, hopefully you didn’t throw it away. I’m just trying to look at different ways that you’d be able to gain access to your account again. Hopefully you can get your account back. Good luck 🤞🏼
Bring that up to support with the documentation to help your case.
It was back in October I contacted support everyday for a month at that time then like I gave up fully now I feel like I should try to get it back because that acc I had spended money on that and if I spended money then I deserve to get it back to it's rightfully mine
Lemme try
If you can show proof that your account for the authenticator and all that stuff is yours, provide that to them as well. Show as much information as your proof that’s linked to that account with the usernames and such it’ll give them a reason to look into it.
Thank youuu I'll try
Good luck buddy
Okie
Yeah. I just didn’t want you to leave here empty handed and at a dead end if you came here looking for legit help.
I contacted them they sent a customer ticket now I gotta wait 😭
yo y'all where do i learn python better then in codecademy
Any Final Year Project Ideas, Feel free to share. Beginner friendly please 
Can we choose the area of study, or...?
Does anyone know about this (WingData) HTB room?
It’s Mainly Cybersecurity
And anything
Just need ideas of any project i can make
write a malware ingestion and analysis pipeline
Hey guys,
i could use some help...
i wanna create a (web) application serving a specific purpose and make a business out of it.
but ofc it needs to be safe (the code as well as everyting around it) so i dont end up in jail for anything hhahahah
do you guys know any ressources (free would be great, as i'm a student) for application security or secure code or anything like that?
google, youtube
books
start with OWASP Top 10 + OWASP Cheat Sheets, also could use PortSwigger Web Security (its free too)
oooh that sounds great! thank you
Hey whats up i need help with my bleshark anyone
what about it
Who is ready to help me learn coding(C)
what do i have to avoid so that i dont break the law when practicing pentesting?
im stupider than i look
The company you pentest, has to define the scope of the engagement.
i dont really know much but cant i practice it on my own network or something?
i really dont know the technical of it just the general gist
Why not learn on TryHackMe or HackTheBox?
forgot about them, cheers
A written agreement with the company that owns the server + network that you are performing the pentest on with the defined scope as deadbeef said.
If you are attacking your own web server in your own house, then thats fine.
Me want.
Do THM challenges.
Help me make a basic project in c++
Or do bug bounties
Or create yo own home lab.... which is expensive
I want one 🥺
So i can break stuff to me hearts content.
pretty sure virtualbox + vmware workstation are free 😛
Well
I wanna physical set-up of servers and stuff
Hackin cameras and whatnot
Everythin ya see on them spy movies
Can you send me 128 GB of DDR 5 RAM? 
I need to sustain my 15 VMs.
wha? are they windows VMs?
Linux and Windows
windows is too thicc >.>
linux, you could do 1-2GB of RAM per VM and be fine(with no desktop environment)
Desktop Experience?
Yea 
Ah I just turn a few off since I don't need them. Helps me save some memory.
how to rank up here ?? I know interacting in chats will help. but want't to do it fast >?
To what end?
Its not going to be fast, I'm afraid
like months or weeks ??
how to check this ? and what's requirement for joining vc
Ya gotta read up on #🤝・roles-info
Fo mo details
Honestly i just go with whatever. At the beginning i leveled up just by talking about pipinos the whole time lol
level 10 needed got it.
Hi
I know I'm stuck on it!
chatting is best kept to #💬・old-gen-chat unless you have a help request
yes actually
what do you think is better for developer experience i3 or hyprland
i looked it up and both look promising
doesn't matter one bit
ok but idk what i can handle better
do you use arch?
ouh
thats cool too
lmao never heard of mate
so i3 it is ig
actually i3s better performance wise
its like 35k lines of code
compared to hyprlands 100k
it does 🙂
no, it absolutely doesnt at all
performance depends on how optimized the code is lol, you could have 10k lines of inefficient code, and it will be slow, then 200k lines of optimized code, and it will be fast
the amount of lines in a codebase does not indicate how well it performs in any way
hyprland was mainly a branch of i3 when i3 started to break
to its built on top of i3
i do think its a bit slower in that way bcoz it has the propertties of i3 plus the extra eye candy and other stuff
i dont really care what your opinions are on each what you said was wrong lmfao
"it does 🙂" that shit was so unbelievably funny
ikrr
I can’t comment on the main chat
Guys I need a help
My telegram account got banned it was a alternative number I bought a foreign number and that number was the owner of my chatting group
So the group also got banned
Is there any way to get it back ?
no
No idea why you ask here, but if telegram support isn't going to help you, then no one here will
How to raise ticket?
Bro it's not opening
Oh okey
contact a mod then
Aah idk man just trying what if someone knows something
next time read the #📜・rules and save yourself the time
@brazen palm
Read our #📜・rules. We do not help with account recovery here.
Also make sure to read our #📢・announcement message
Oh okay, I’m sorry I should have read more thoroughly. Do you know any servers where I could possibly get help?
It is unlikely anyone will actually be able to help you except for the company who hosts the service.
Hey
Can someone help me with my bootable drive
It says “D:\ is not accessible” but I’m on the admin account and I made sure the file wasn’t corrupted
Wrong file system probably - what exactly is supposed to be there?
I used Rufus for Linux mint. I just checked and I don’t have D:\ in my system, but the file fully downloaded and says it’s ready. Is it okay or do I need to restart?
Pretty sure rufus is not the tool that the linux mint installation guide tells you to use. But if it was flashed correctly, then windows cannot see the file system
That's as it should be then
I have a buddy who does this a lot and he recommended using Rufus and the tutorials online keep saying to use it too. Thank you so much for your help!
I'd really suggest to look up the actual documentation by the linux mint project
anyone know how to bypass the phone verification screen of discord, when logging in after a supposed malicious activity?
Windows isn’t supposed to read Linux file systems! Somehow when I had windows, defender picked up my Kali dual boot some how and flagged some of the files as malware but that’s the only time I’ve seen it say D drive !
Hey guys, new to the cyber security scene, bought a subscription on THM and have been completing the beginning networking paths and whatnot, just wondering how much credibility the SEC1 certification would give me in the sense of finding a job in the field and if its even worth taking.
Check out what certifications employers are looking for in your region
I’m struggling so bad rn 😭
I figured it out at last!
Quick Question, I'm new here and veryyyy new at this level of cybersecurity. So mods if questions related to hacking not allowed I apologize in advanced.
I'm not trying to actually hack anybody but I want to practice Pen-Testing. I've already went through the steps of looking into Vulnhub, installed virtualbox and got a Kali Linux VM so I could have the tools ready. The hiccup I'm running into right is changing the network settings for both vms to be "Internal Network" instead of bridged so the two machines are isolated.
Sounds easy enough except Virtual Box doesn't present me the option of internal network in the drop down. I looked around to see why that is but even with chatgpt i'm coming up short, I might resort to an uninstall/reinstall for virtual box but it did mention that it would be safe to use NAT if the original choice wasn't available.
Would anyone here know if that's true? I know the intrenal network option is preferred but I don't have like a private network set up in my home yet since again...still kind of new at this lol
Hey everybody , how goes it ?? I have a question for the hive mind. What's your opinion about the Flipper Zero and the possibilities of it ?
You can make them both host only so it uses ur host machine as the "router" for both of those systems
Okay, I see I see - so doing this am I able to skip configuring a DHCP server within the vulnhub machine or would that still be a must
Yeah you should be fine. Typically you do not need to configure anything for vuln hub machines
just add the vulnerable machine to the network
find the IP for it
and do not touch it
the rest of the challenge will be done on ur kali VM
nmap scan the IP find open ports etc.
Usually the only reason I ever actually touched the vulnerable VM was to find its IP address. OR from ur kali VM scan the local network for the IP
Oh perfect, okay then I'll try that and get straight to it then - Appreciate you !
Contact help support
Hes now blackmailing me
We dont provide services to retrieve your account back
I know
Again contact support
If it’s serious call the police
it is casue they would have access to everything by now you accounts emails saved passwords in browsers and etc even the bank accounts you used for online purchases they are the informations that hackers want
There is a chance that hes just bluffong but he did have control over my mouse and he even shut down my monitor
bluffing
I disconected my ethernet cable and power supply i dont have cam thankfully but he said that he has all my data and logs
@sinful grove is there anything i can do besides contacting police
you could run a command in CMD to see if there is any connection form your PC to outside
that you would have the IP and you could report it to police but hackers use VPS and etc to hide their IPS
netstat
Whats the command?
netstat
Okay i will try it in the morning but hes demanding a 70€ gift card or he will leak all my data and lohs
Logs
How did he gained access to your Computer ?
@sinful grove i ran a python code he sent me and after that he got accses
I know im a dumbass
But i trusted him
how to know wheter I have a virus in my computer .I quick scanned using defender but still IM kinda
buy a norton antivirus or any others and let it scan your PC
defender is good right
I check tas manager to see whether some programmes are running
its okay only current apps are running
You can read this
#📢・announcement message
Trying to get help for a legal issue on discord is the same as painting a red target on your head for other people to try and take advantage of the situation.
Please don't ask for it here, and be careful of anyone saying they can.
defender is fine, malwarebytes is also free you can use as a second pair of eyes.
don't buy norton ever
k ty
how do i start the chat-100?
What's the best USB flasher? Rufus and Etcher are not the best way to flash Windows 10 onto it?
im on linux mint
never asked for the "best" of anything.. it's a reductionist notion born out of laziness.
Both rufus and etcher work fine for windows images, as does the microsoft tool they provide for their ISO
what tool should i use?
You can’t until they re-open the challenge but this round just ended so it might be a little while
I just told you it doesn't matter
probably ventoy
ventoy
although I have hardware that acts as installation devices already
You asked which tool I would use, not which tool you should use.. with windows ISO is really does not matter.. you can use dd, rufus, etcher, ventoy.. whatever
heck you can just use the built-in disks util to "restore an image to a drive"
It says on the Win 11 bootloader it cant detect the right drivers needed to install even when I have the USB plugged up.
sure, that can happen on some hardware
that is independent on the tool being used.. if the drivers ain't in the image, they ain't in there
I have tried all the YouTube tutorials and I feel like I just have to use Linux forever.
You guys crack me up sometimes... go to the source and read the actual documentation.. whatever hardware you have, whichever vendor sold them, is bound to have the necessary drivers on their website to download
youtube isn't the final arbiter about issues.. neither is chatgpt..
For getting remote access which approach should I consider
depends on the details of what you want to do exactly
Trying to get access of the windows using Linux
Only one cmd file in windows which can assist to get access
And why only a cmd command?
What are the disadvantages of using a dual-boot Kali installation instead of a virtual machine?
you are regularly going to break either of the installation during updates, windows will require secure boot while kali will require secure boot to be turned off, also you are limiting yourself to only use one OS at a time, while a VM always allows you to run both at the same time.
Dual boot should only be considered as a last resort, if your hardware can't handle a VM
Window in vm
Linux as a host
Access means that
I am trying to say is
To do ex filtration like malware
Oh, got it.
And why only a cmd command on the windows machine
If you want to access a windows machine, its probably best to install a dedicated remote desktop on it.
Unless it really isn't your machine, in which case you shouldn't mess with it without knowing what you do
that being said - somewhere along the path that is laid out in #👥・new-member-guide you'll come across the procedure
Both systems I own
Just want to learn exploiting
So starting learning from trojan directory build etc are done
But trying to access it from Linux is getting difficult
Really no intention to help "a beginner" with trojans
both systems will needto be on the same network
I'm new cybersecurity student and I was practicing by doing an nmap to scan on my network knowing that there's 2 windows 11 machines only. one I'm using to perform the scan and another one .. I couldn't find a way to detect the other windows device.. the network is having many access points and all devices are connected wirelessly .. any guidance
do you know the ip address of the other windows machine
chances are if the network has many access points then you're on a different part of the network
separate vlan or something
Hey everyone! Arfa here 👋
1st-year CSE (AIML) student, looking to master a skill for freelancing + long-term career growth 🚀
If you have any guidance, roadmap, or experience to share or you may know about other fields that aren't much glamorous rn but in future it'll be of Great demand.
Would really appreciate your support!
i have a question, my dad has a e-mail he lost years ago with pictures on it and stuff. He lost the password and i looked up if there was any data leak where the password got leaked, and it did. How can i find the leaked password? Or is there no way to find it
Does looking at a walkthrough when you’re stuck count as cheating?
if you tried enough and researched but still stuck it's okay to look at a walkthrough or write up it will teach you what to do next time, just as long as you keep on researching by yourself and not giving up at the first place
Ya. Got it.
We are not helping you find leaked credentials. Contact the service provider, explain the situation
The usual recommendation is to start here #👥・new-member-guide
Hey guys, I need some help — I’m stuck while doing mobile application security testing on a Flutter app my team built (not launched yet, testing only on emulator).
Setup:
Flutter app
Genymotion Android emulator (x86_64)
Backend: Supabase (including realtime/WebSocket)
Burp proxy configured + CA installed
Current issue:
App works normally when proxy is disabled.
Browser traffic works fine in Burp on the same emulator.
App traffic does NOT appear in Burp HTTP history.
When trying proxy injection/hooking, some traffic works but one screen only keeps buffering.
That screen uses Supabase realtime and shows activity only in Burp WebSockets history (server ↔ client messages visible), but the UI never fully loads.
What I already tried:
Verified proxy setup and certificate installation.
Checked code — no explicit SSL pinning / SecurityContext / HttpOverrides.
Tried Frida for runtime hooking but frida-server was unstable and not usable.
What I’m trying to understand:
Is Flutter app traffic bypassing the proxy?
Is this a TLS/CA trust issue?
Is Supabase realtime/WebSocket causing this behavior?
Or some hidden pinning/network configuration?
Main goal:
Need a stable way to intercept app traffic in Burp while keeping realtime functionality working for security testing.
Any guidance would really help.
How is this related to the #👥・help-me channel
What do you need help with?
And you already went through all the resources we collected for people who want to learn hacking, and which I already gave you a link to?
what your mouse wheel broke or something? Its right up there
If you fail to find infos/links that people gave you.. you may not be up to the task of getting info people do not want to give you
Could you help me with the thing that asked above as I have been stuck there
Thank you So much I really appreciate it... Real Attack & Detection coming up in few hours
i cant type into the kali terminal for my password using the offical one from the microsoft store
any way to fix tthis?
yes you can
terminal passwords are invisible
im tryna type my password and its doing nothing
terminal passwords are invisible
Awaiting patiently
Hello everyone, I’m actively working on thm for practical skills. And working on building a homelab…My goal is to eventually find a soc position… I’m wondering if someone can check on my GitHub portfolio… just for general feedback
where is ur github portfolio
Sorry forgot
first off u shouldnt make ur portfolio a repo
just make it ur readme for ur account like u have done here https://github.com/AworkofKC
I appreciate that I actually didn’t realize
I could use some help with sonething
In my country people kinda create vpn files that enable them to bypass network limits and am nit sure if there legit can u help me out
it is just a vpn
buy one, turn it on, simple
apart from that, the research and lsb are cool, shows you have some base line knowledge
Thank you, I’ll fix that… working on more..
How do you create the file coz a ysual vpn rubs iut immediately yuor data does but theurs as long as you are connected to it u can briwse limitless
you need a vpn server for that, and those usually give you the necessary config in form of a .ovpn file
How do yiu buy one ir rent a server
either one works - it can be your own server if you get your hands on a VPS you can install onto - and there are several providers for a VPN service, mostly paid for
I mean, at the end of the day someone has to pay for all that traffic
Just did some modules on tryhackme. Didnt even know dirb was a thing. Anyone familiar with this command?
yes
Is it frequently used ?
in CTFs yes
Ah ty
No I don't no the ip but I know that's the only windows machine on the network
well then you can scan for it
using nmap or zmap or angryipscanner
if it doesnt appear, then the two devices are on separate networks
Ok thank you .. I will try again
Newbie here any tips on how to protect my privacy online? I have a vpn, but should I not use Google at all? They seem to be the worst.
Vpn should be fine
Make sure its on first
Can always use incognito
Click the 3 dots at the end of the Google screen all the way to the right menu would drop down. It will say “new incognito window.”
use dirbuster on the machine ip
Can anyone share any resources of reverse shell and bind shell with a short of commands
How do I type it in?
Did you need to post this in 3 channels?
you are using attackbox or vpn ?
This does nothing for online privacy.
This just deletes the cookies + history on the browser itself.
ion like incognito, i like guest better
I'm not going to lie Im not sure which one im using I just started the course and I wasn't given a option to chose what I should use?
you must be using the machine they provided
it comes with the tools built in
click the view site
im sorry i didnt see the room properly you dont need attackbox or vm or anything
Ohh so how do I do it?
bro did not do pre-security or anything related to setup
it will open for you a fake web browser environment
Yeah I've done that?
this dosent seem to be the related window
use the one in 'find hidden pages'
you used the one in the previous section
or as ruin suggested you can try starting with pre-security course on thm
its a set of rooms that'll teach you how to use the platform effectively
That's where I am right now, I'm stuck at the 3th task because I'm confused
They are telling me inside the Vm terminal but I don't know where I find it
youre in offsec intro right
Yes
then there must be multiple tabs open
It's only one at the moment the one Im using now
Do I find it on the same page of the course I'm in or should I close it and go to home page
its on the same page
the one in this image
Ohk yes I'm opened view site
okay you must see a place where you can enter the shown command
Yes I see now it's like a tab but now wats confusing me is I can't clear or delete the one already available there for me to copy and paste the provided one
you have to copy the one given dirb http://fakebank.thm/
and paste it in your browser window
wherever the input space is provided
He can use tails os lol but didn’t want to get in trouble for recommending it
I've finally done it, brother TYSM
GOOD LUCK
Explain the privacy thing instead.
Explain that even if they use Tails OS on the most secure configuration possible, if they log into discord or facebook, that information just gets lumped in together with the rest of the information.
That remaining private online involves many steps, including limiting the information you yourself are putting online.
😛
You’re right lol 😂
Hey guys, does anyone have any knowledge about the Stormshield firewall?
I know a bit of that, its a network firewall appliance used a lot in enterprise environments, especially in Europe
I need your help one more time
sure
I keep trying to copy and paste the url provided to the command prompt but it keeps saying wrong command but I double checked no keys wrong
can you attach an image ?
did you check if it is the right virtual web ?
is it the correct input if there are multiple inputs ?
Yes I did I was told the hidden admin panel and that's where I am
Ohh let me try
It worked 💯 💯
Much respect to you 🫡 🤞
no its not required 😭 🙏
good luck again, congratulations on completing the room
Thank you
welcome
hi guys
Heyps, need anything?
i just bought new laptop can you guys tell me if its good?
