· 10 years ago · Aug 28, 2016, 10:16 AM
1[ RETURN / GO TO BOTTOM ]
2File: 1467601765379.JPG (64.43 KB, 704x445, 704:445, hacking.jpg) IMGOPS EXIF IQDB
3
4Hacking General It has been too long 2016-07-04 03:09:25 NO.109[LAST 50 POSTS]
5Anyone save the last one? Losing too much valuable info when these threads 404. They need to be archived or at least have a pastebin to reference so new threads can be created. Only one has been saved so far and it was from over a year ago!
6
7HTTP://ARCHIVE.IS/ZVHDW#SELECTION-605.0-661.24
8
9
10Hijacking /g/'s hacking general since theirs seems to be more comprehensive:
11
12How To Become a Hacker: HTTP://CATB.ORG/~ESR/FAQS/HACKER-HOWTO.HTML
13
14
15Relevant Social Engineering thread:
16HTTPS://LAINCHAN.ORG/CYB/RES/29795.HTML
17
18Learning:
19HTTP://CYBRARY.IT/
20HTTP://N0WHERE.NET/
21HTTP://WWW.OFFENSIVE-SECURITY.COM/METASPLOIT-UNLEASHED
22HTTP://RESOURCES.INFOSECINSTITUTE.COM/
23HTTP://WWW.WINDOWSECURITY.COM/ARTICLES-TUTORIALS/
24HTTP://WWW.SANS.ORG/READING-ROOM/
25HTTPS://WWW.CORELAN.BE/INDEX.PHP/ARTICLES/
26HTTP://OPENSECURITYTRAINING.INFO/TRAINING.HTML
27HTTPS://WWW.BLACKHAT.COM/HTML/ARCHIVES.HTML
28HTTP://WWW.SECURITYTUBE.NET/
29Hacking General (cont) It has been too long 2016-07-04 03:12:30 NO.110>>122
30News/CVE releases:
31HTTPS://THREATPOST.COM/
32HTTP://WWW.DEEPDOTWEB.COM/
33HTTPS://PACKETSTORMSECURITY.COM/
34HTTP://WWW.CVEDETAILS.COM/
35HTTP://ROUTERPWN.COM/
36HTTP://WWW.EXPLOIT-DB.COM/
37HTTPS://WWW.RAPID7.COM/DB/
38HTTP://0DAY.TODAY/
39
40Wargames:
41HTTP://OVERTHEWIRE.ORG/WARGAMES/
42HTTPS://WWW.PENTESTERLAB.COM/
43HTTP://WWW.ITSECGAMES.COM/
44HTTPS://EXPLOIT-EXERCISES.COM/
45HTTP://WWW.ENIGMAGROUP.ORG/
46HTTP://SMASHTHESTACK.ORG/
47HTTP://3564020356.ORG/
48HTTP://WWW.HACKTHISSITE.ORG/
49HTTP://WWW.HACKERTEST.NET/
50HTTP://0X0539.NET/
51
52Ender 2016-07-04 06:28:08 NO.111
53Since this is a new thread, I'm more inclined to participate, since I'm already caught up.
54
55I'm simply working on some moderately interesting projects and reading about computing, for the most part.
56
57I mess around with my HP calculators often, so maybe I'll release a program here when I make something that could be useful to others.
58
59Agent Jones 2016-07-04 06:55:50 NO.112>>113>>117>>120
60File: 1467615349958.JPG (17.34 KB, 500x500, 1:1, 1441840448722.jpg) IMGOPS EXIF IQDB
61
62What are some of the more useful tools in the Kali toolset that are worth learning?
63
64Emmanuel 2016-07-04 10:05:23 NO.113>>157
65>>112
66Metasploit. Offensive Security offers a free course. (HTTP://WWW.OFFENSIVE-SECURITY.COM/METASPLOIT-UNLEASHED)
67
68I would also recommend Burp Suite if you want to break web apps.
69
70The Fin 2016-07-04 16:35:33 NO.114>>115
71From Endchan
72HTTP://WWW.SECURITYTUBE.NET/
73HTTP://CREATOR.WONDERHOWTO.COM/OCCUPYTHEWEBOTW/
74HTTP://N0WHERE.NET/
75HTTP://WWW.OFFENSIVE-SECURITY.COM/METASPLOIT-UNLEASHED
76HTTP://WWW.EXPLOIT-DB.COM/
77HTTP://RESOURCES.INFOSECINSTITUTE.COM/
78HTTP://WWW.WINDOWSECURITY.COM/ARTICLES-TUTORIAL/
79HTTP://WWW.SECURITYSIFT.COM/
80HTTP://WWW.SANS.ORG/READING-ROOM/
81HTTP://PACKETSTORMSECURITY.COM/FILES/
82HTTPS://WWW.CORELAN.BE/INDEX.PHP/ARTICLES/
83HTTP://ROUTERPWN.COM/
84HTTP://OPENSECURITYTRAINING.INFO/TRAINING.HTML
85HTTPS://WWW.BLACKHAT.COM/HTML/ARCHIVES.HTML
86HTTP://MAGAZINE.HITB.ORG/HITB-MAGAZINE.HTML
87News:
88HTTPS://THREATPOST.COM/
89HTTP://WWW.DEEPDOTWEB.COM/
90
91Cypher 2016-07-04 16:37:33 NO.115>>116
92>>114
93Wargames:
94HTTP://OVERTHEWIRE.ORG/WARGAMES/
95HTTPS://WWW.PENTESTERLAB.COM/
96HTTP://WWW.ITSECGAMES.COM/
97HTTPS://EXPLOIT-EXERCISES.COM/
98HTTP://WWW.ENIGMAGROUP.ORG/
99HTTP://SMASHTHESTACK.ORG/
100HTTP://3564020356.ORG/
101HTTP://WWW.HACKTHISSITE.ORG/
102HTTP://WWW.HACKERTEST.NET/
103Distros:
104HTTPS://WWW.KALI.ORG/
105HTTP://SOURCEFORGE.NET/PROJECTS/METASPLOITABLE/
106HTTPS://TAILS.BOUM.ORG/
107>Where to start
108HTTPS://WWW.YOUTUBE.COM/WATCH?V=GPNNXMTEZAK
109HTTPS://YOUTU.BE/PB0WVCXTBCA [Embed]
110>Learning material
111HTTPS://WWW.CODECADEMY.COM/
112HTTPS://PROGRAMMING-MOTHERFUCKER.COM/
113HTTPS://GITHUB.COM/VHF/FREE-PROGRAMMING-BOOKS/BLOB/MASTER/FREE-PROGRAMMING-BOOKS.MD
114HTTPS://WWW.THEODINPROJECT.COM/
115
116Sabo Engle 2016-07-04 16:38:04 NO.116
117>>115
118>Frontend development
119HTTPS://GITHUB.COM/DYPSILON/FRONTEND-DEV-BOOKMARKS
120>Backend development
121HTTPS://EN.M.WIKIPEDIA.ORG/WIKI/COMPARISON_OF_WEB_APPLICATION_FRAMEWORKS
122[Gist] backendDevelopmentBookmarks.md
123>Useful tools
124HTTPS://PASTEBIN.COM/Q5NB1NPT/
125HTTPS://LIBRARIES.IO/ - Discover new open source libraries, modules and frameworks and keep
126track of ones you depend upon.
127>NEET guide to web dev employment
128HTTPS://PASTEBIN.COM/4YEJAUBT/
129>How I Got a Job in Web Development
130HTTP://ELLIOTEC.COM/HOW-I-GOT-A-JOB-IN-WEB-DEVELOPMENT/
131>Random Shit
132HTTPS://W3CHALLS.COM/
133HTTPS://WWW.HELLBOUNDHACKERS.ORG/
134HTTP://IO.SMASHTHESTACK.ORG/
135HTTP://PWNABLE.KR/?P=PROBS
136HTTPS://G.SICP.ME/BOOKS/
137Godly resource of thousands of PDFs
138Cybrary.it
139Decent videos if you wanna get some certs
140HTTP://HACKADAY.COM/
141
142Eldon Tyrell 2016-07-04 17:07:13 NO.117
143File: 1467652033397.JPEG (44.34 KB, 502x502, 1:1, 147338-1413265585259.jpeg) IMGOPS IQDB
144
145>>112
146NMap
147Wireshark
148MSF
149hping3
150SET
151OpenVAS
152Aircrack
153Wifite
154DFF
155BinWalk
156ddRescue
157Scalpel
158BurpSuite
159w3af
160
161With the exception of reversing tools the rest you can just google fu or read man pages on when you need them.
162
163Molly Millions 2016-07-04 18:57:40 NO.118
164Thanks - from last OP of hacker generals
165
166Nell 2016-07-04 19:00:28 NO.119
167another good resource is
168Python learning with hacking!
169HTTP://WWW.PRIMALSECURITY.NET/TUTORIALS/PYTHON-TUTORIALS/
170
171H.R. Giger 2016-07-04 19:01:48 NO.120>>121
172>>112
173What are you wanting to learn?
174wifi hacking?
175web application hacking?
176network?
177
178TERZIBASHJIAN 2016-07-04 19:54:55 NO.121
179>>120
180Mr.Robot Hacking challenge!
181HTTPS://WWW.VULNHUB.COM/ENTRY/MR-ROBOT-1,151/
182
183Splicer 2016-07-04 21:43:21 NO.122
184>>110
185>HTTP://0X0539.NET/
186I tried this one and I am glad I did, first thing I ran across something I could actually make progress in, right now step 3 I guess, need to install some new software before proceeding. Seems very fun but not much information is there O.o still a lot a mistery, anyone knows more about this challenge?
187
188Molly Millions 2016-07-05 09:03:47 NO.123
189File: 1467709427441.PNG (115.97 KB, 448x593, 448:593, NITROstudentV1.png) IMGOPS IQDB
190
191U.S. Secret Service Network Intrusion Responder Program (NITRO) Course:
192HTTPS://PUBLICINTELLIGENCE.NET/NETWORK-INTRUSION-RESPONDER-PROGRAM/
193
194Faye Valentine 2016-07-05 21:21:31 NO.124>>125>>126>>207
195Anyone know is the OSCP course matierial is pirated somewhere? I can't find anything.
196
197udnid 2016-07-08 14:59:19 NO.125>>126>>140
198>>124
199no
200the course material is watermarked with your personal information, and they'll revoke your OSCP if they find your pirated shit.
201
202>you have to scan your drivers license or passport and send them the scan to register
203>can't register with a free email address
204
205Currently taking the PWK/OSCP course, if you have any specific questions , reply to me or get at me on irc #lainchan (I'm udnid, it's not a randomly generated name)
206
207To avoid the question from anyone, I will not give you a copy of any course materials. There's no s00p3r s3kr3t adv4nc3d hacking techniques.
208
209Just go to vulnhub, do their shit, don't use metasploit when you're learning.
210Enumerate the shit out of everything.
211
212Leto Atreides I 2016-07-09 15:37:52 NO.126>>127>>140
213>>124
214
215Basically what >>125 said.
216The course book alone is so watermarked you'll never, EVER see anyone post it anywhere. You'll never be l33t until you drop dough on the learning material. You're stupid for even asking. Ain't nobody gonna give you that shit. It's so secret, you have to submit DNA (semen and/or blood) to Offensive Security. You'll never get. Never! Never ever!
217
218HTTP://DL2.CBTNET.IR/BOOKS/WP-CONTENT/UPLOADS/2015/08/PENETRATION-TESTING-WITH-KALI-LINUX-2014.PDF
219
220Oh, oooooooh!
221
222In all seriousness, most of the benefit of PWK comes from the lab environment and other supplementary materials like videos. The .pdf does have some solid info, though. Absorb some info, set up some labs, and learn.
223
224Crash Override 2016-07-10 17:15:36 NO.127>>128
225>>126
226Thanks lainon, we could try to make a download home lab version that you can through in your own vm software.
227
228Project 2501 2016-07-10 17:47:54 NO.128
229>>127
230No problem, enjoy.
231
232If you're looking to put together your own virtual lab, a simple Kali and Metasploitable setup running on your VM software of choice should work. With the Kali machine, you can work on your Linux and scripting skills. The Metasploitable machine gives you an ez-pz target to recon and attack from your Kali machine. Between the two machines, you should be able to work through most of the concepts, tools, and skills in the PWK .pdf (although you'll still be missing out on some things).
233
234Cat Mother 2016-07-10 21:46:34 NO.129>>130>>154
235Seems like someone deleted my post (US GOVT at work), lainchan hacking group when?
236
237Miho Iwakura 2016-07-10 22:05:55 NO.130>>132>>133
238>>129
239What could be gained from working together as opposed to operating individually or as a loose collective?
240
241Apoc 2016-07-10 22:13:04 NO.131
242File: 1468188784035.EPUB (11 MB, Practical Malware Analysi….epub)
243
244I really enjoyed this book. It was also the first time i've been involved in using the Win32 API, despite being a coder for 10+ years.
245Do you guys have more book recommendations regarding malware targeting Windows?
246
247Cereal Killer 2016-07-10 22:20:40 NO.132
248>>130
249Separation of concerns.
250A loosely knit collective would be a reasonable compromise. Is anyone here familiar with Goatse Security? (Goatsec)
251
252Lain Iwakura 2016-07-10 22:50:42 NO.133
253>>130
254The collection of skillsets. One might be interested in authentication systems, cryptography and algorithms, while the other might love logical errors in code. See what I mean?
255
256Apoc 2016-07-11 02:35:56 NO.134>>135
257Alright anons can you help me out with this one without actually giving me the answer?
258
259I guess solution will involve spoofing the User-Agent field in the request header with Postman but don't know where to go from there.
260
261HTTPS://BACKDOOR.SDSLABS.CO/CHALLENGES/BRWSR
262
263Molly Millions 2016-07-11 02:43:24 NO.135>>136
264>>134
265That's literally it bruh.
266
267Dozer 2016-07-11 02:46:47 NO.136>>137
268>>135
269But what do i put in there? I don't have the browser name. I feel like a fucking idiot
270
271BloodCat 2016-07-11 03:06:34 NO.137
272>>136
273Set the User-Agent to 'SDSLabs'. It just checks that 'SDSLabs' is in the User-Agent string.
274
275Eldon Tyrell 2016-07-11 22:48:06 NO.138>>139
276File: 1468277286639-0.JPG (36.44 KB, 606x540, 101:90, 1431232240868.jpg) IMGOPS EXIF IQDB
277
278File: 1468277286639-1.JPG (49.06 KB, 500x333, 500:333, 1431734305026.jpg) IMGOPS EXIF IQDB
279
280>>109 (OP)
281Hey guize, I know this is probably going to make me sound like a potato, but I've been trying to work with the liveCDs from PentesterLabs and none of the ones I've tried boot to any graphical interface and I can't find any of the actual content from cd'ing around.
282
283I'm sure its just a simple fix, but any help would be appreciated.
284
285For reference I'm using and Ubuntu 32 Virtual Box machine and I'm trying to start Web for Pentesters.
286
287Masami Eiri 2016-07-11 23:20:20 NO.139>>148
288>>138
289first make sure your using a hypervisor ie vmware, virtualbox, etc. it's also not supposed to have a desktop.
290
291run the ifconfig command on the live iso, (make sure you set the network card on the vm)
292you should get a ip, now you should ping that machine from your attacking machine, if you get replies that good!
293
294now in your browser type "HTTP://<IP address>/
295how your on the victim machines website!
296good luck!
297msg me if you need anymore help!
298
299Judge Fang 2016-07-11 23:31:59 NO.140>>141
300>>125
301
302Are there any major differences between your current pdf and the one posted >>126
303
304How are you finding the course so far? What's your study schedule like and how much lab time did you get?
305I'm interested in taking the course but that price tag is pretty daunting, do you think you'll find easy employment once you grab the cert? Do you have a degree as well?
306
307SHODAN 2016-07-11 23:40:45 NO.141>>142
308>>140
309>do you think you'll find easy employment once you grab the cert? Do you have a degree as well?
310maybe a entry level tech job, but honestly pentesters in general are overly saturated part of the security field, plus very few people would trusted a "just got my cert".
311
312That being said, most likely you will have to move up the ranks, or join the military and get training that way. ( i wouldn't recommend though)
313
314Joey 2016-07-12 00:14:55 NO.142
315>>141
316I have a couple years experience as a student linux sys admin. I'll finish my degree in Comp Sci next summer. I've been thinking about trying to get the OSCP before I graduate, hoping that it would help me land a security job out of college rather than having to make the sys admin to security pivot. What's been stopping me is the price and maybe moreso the time commitment, my last few semesters are going to be packed and I'll be working part time on top of it. I'm having real analysis paralysis picking between sys admin, security, or software dev.
317
318Linda Lee 2016-07-12 00:20:23 NO.143>>188
319>>109 (OP)
320I think these should be in the general:
321
322HTTP://PASTEBIN.COM/RAW/0SNSVYJJ
323
324Phineas Fisher's write up of how they hacked Hacking Team.
325
326Also OPSEC, everyone needs it!
327
328HTTPS://WWW.YOUTUBE.COM/WATCH?FEATURE=PLAYER_DETAILPAGE&V=9XAYDCDWIWU
329
330Neo 2016-07-12 05:29:50 NO.144
331fuck are all those ebooks from the old thread gone now? I checked the archive and got a 404. Fuck I took for granted that I could always come back here and get those books.
332
333Liet-Kynes 2016-07-12 05:42:12 NO.145>>146
334So I've been programming for a few years. I've done about a dozen of the microcorruption levels, read about half of the shellcoder's handbook, know basics of assembly and C, used to crack WEP with aircrack etc.
335
336I feel like most people's interest in hacking wanes as they grow up and become better programmers and just want to make rails apps and live like a richfag in sanfran. I'm not really one of those people. What kind of mischief could I actually get into if I were so inclined? I don't really see myself creating my own exploits but what's like the next level above script kiddy? Years ago I read about someone operating a botnet and mining bitcoin with them. I know those days are long gone but running a botnet still sounds fun.
337
338Pulse 2016-07-12 07:26:29 NO.146
339>>145
340
341mmm the next level is probably still script kid but more like well educated script power user.
342
343Example: using mitmf+dnslib+privoxy+apache mod_expire to create your own JS botnet by cache poisoning people at a coffeeshop or placing an open proxy on the net and letting all the other skiddies get infected.
344
345JS payloads are might effective. Assume you've scripted your JS payload to pull actions from a C&C server and assume that you're proxy is up for a good week and you've seen 5,200 people. Managing to dnsspoof code.jquery.com, 3,200 of those users are now running the modified version of the code b/c mod_expire tells their cache to keep jquery.js for 3 years.
346
347All your clients pull the payload and run it... what can you do?
348
3491. Steal credentials
3502. Replace ads with your own and profit
3513. embed youtube vids over adspace and sell views (this is a thing)
3524. DDoS by consistently targeting a latent part of a webapp, such as consistently downloading a large file or a really complicated search query that has multiple table joins and poor use of globbing.
3535. Attempt to use a precanned exploit and have a percentage of those users lend their computers compeltely to you.
354
355so on and so forth. I think that would be a masterful approach of someone who's not the /best/ "hacker" but shows great intelligence and ingenuity in the way that you can combine pre-existing tools into your own unique attack vector.
356
357Morpheus 2016-07-12 20:16:00 NO.147>>150>>151
358How should I go about finding a box on Shodan that I can get root on? I just need root on a remote server.
359
360Turner 2016-07-12 21:57:00 NO.148>>149>>151>>152
361>>139
362Thanks man a lot, I was under the impression it would just be self-contained all in the VM, but I guess not.
363
364So now I'm trying to set up port forwarding so I can access it because the ping isn't working.
365
366I'm using Virtual Box and in the network settings for this particular vm have set: Protocol to TCP
367Host ip to 10.0.2.15(the vm's ip from ifconfig)
368Host port to port 80
369Guest ip to my own external ip from a "what's my ip" site
370Guest port to port 80
371
372for the guest IP i also tried my own local network ip but with these settings 10.0.2.15 doesnt return pings
373
374thanks
375
376Shogun 2016-07-12 22:01:54 NO.149
377>>148
378To clarify, using my "whats my ip" addr doesn't work and the internal ip doesn't work.
379
380The way I wrote it sounded ambiguous.
381
382Agent Smith 2016-07-12 23:19:36 NO.150>>151>>153
383>>147
384is your attacking machine on the same network as your victim?
385
386you shouldn't need to set port forwarding.
387
388ZHORA 2016-07-12 23:23:37 NO.151
389>>150 is for >>148
390
391
392>>147
393i wouldn't recommend doing that is somethings skids do, and legal reasons, however i wouldn't recommend shodan because thats for I.O.T. people who search for vuln sites would be normally usings googledorks instead.
394like a vuln software in quotes of something not configured.
395
396The Oracle 2016-07-12 23:30:41 NO.152
397>>109 (OP)
398Thanks for reviving.
399
400>>148
401Try creating a host-only network from File->Preferences->Network and putting both the attacker and target machines on it. Enable DHCP as well.
402
403Worked for me at least. I'm following a walk-through from VulnHub, the one they say to start with.
404
405HTTPS://WWW.VULNHUB.COM/ENTRY/DE-ICE_S1100-LEVEL-1,8/
406
407HTTP://BLOG.NULLMODE.COM/BLOG/2013/10/31/DE-ICE-S1-DOT-100-LEVEL-1-A-BEGINNERS-GUIDE/
408
409Alice Miyuki 2016-07-13 00:25:42 NO.153
410>>150
411Hey, thanks for sticking around, i figured it out.
412
413I was trying to work out a NAT network but in the end I just set it up for host only adapter and everything worked out.
414
415DR. X 2016-07-13 03:18:21 NO.154
416>>129
417There's been one for years, what do you bring to the table?
418
419Chani 2016-07-13 17:22:45 NO.155>>159
420Has anyone ever attempted to mess with those digital business signs you see along the road? Not billboards, but signs for specific businesses.
421
422There's one I see along my commute every day that seems like it might be something I could get into. It's too far from the business to be controlled from there, so I'm thinking there's a computer or something sitting in the access box on the side.
423
424Marly Krushkhova 2016-07-13 21:31:42 NO.156>>160
425Anyone would like to team up and try to play some CTF maybe? We could arrange something onto some random IRC channel.
426
427Also see this: HTTP://WECHALL.NET
428for more wargames' sites.
429
430Lain Iwakura 2016-07-14 06:18:07 NO.157>>158
431>>113
432the free version of burp suite is worth using? see that some cool features is only available in the paid version
433
434Jet Black 2016-07-15 09:35:56 NO.158
435>>157
436Honestly, i never pay for tools in general, however paying for burb is only useful if you plan on doing automated scans on huge networks and even then not really.
437
438for every paid feature they're free tools too! That being said burb is the goto tool for manual web app testing!
439
440Zero Cool 2016-07-15 09:38:15 NO.159
441>>155
442im not advocating, but if you bought a hardhat, tool belt, and a dirty white shirt no one would think twice, plus most of those machines have the instructions or a number you can call for help on the inside.
443
444SHODAN 2016-07-15 11:01:27 NO.160
445>>156
446Two CTFs starting this weekend.
447Palo Alto's having one, more info at HTTP://LABYRENTH.COM/
448
449The second one's a ez-pz(?) high school level one. Info's at HTTP://ABCTF.XYZ/
450
451Keeping track of these is helped by HTTPS://CTFTIME.ORG/
452
453Dozer 2016-07-17 11:24:32 NO.161>>162
454>>109 (OP)
455
456Overthewire bandits challenge doesnt seem to work. I tried to ssh to the given url but was to only be presented with a password. When I ssh'd it just should had asked for a usrname and password right?
457
458Lady 3Jane.. 2016-07-17 11:35:47 NO.162>>163>>164>>165
459>>161
460
461Try to SSH into bandit0@bandit.labs.overthewire.org
462
463Pris 2016-07-17 11:42:07 NO.163>>164>>165
464>>162
465Oh, and if it wasn't clear use bandit0 as the password when prompted for one. The bandit0 part of bandit0@bandit.labs.overthewire.org specifies your username you want to log in to. So, as you progress to level one you can log out of bandit0 and then SSH into bandit1@bandit.labs.overthewire.org with the password gained by poking around as bandit0.
466
467Project 2501 2016-07-17 12:26:53 NO.164>>165
468>>162
469>>163
470Yeah I logged in perfectly fine now. Thank you
471
472Mitnick 2016-07-17 18:18:17 NO.165>>166
473>>162
474>>163
475>>164
476anyone having problems at bandit6?
477im an idiot
478
479Linda Lee 2016-07-17 18:26:35 NO.166
480>>165
481Use the find command. Look at the man page and check out the -size option.
482
483Liet-Kynes 2016-07-18 14:11:58 NO.167>>168>>172>>176
484So no one saved the last thread?
485
486Masami Eiri 2016-07-18 14:32:01 NO.168>>169>>172
487>>167
488well, it's an imageboard. threads dont get saved..
489
490Crash Override 2016-07-18 15:34:41 NO.169>>170
491>>168
492Some other imageboards have automatic permanent and/or temporary archives, so I don't see your point. Seeing as this is a topic general, it makes sense that it would at least get saved somewhere for future reference.
493
494The Plague 2016-07-18 15:50:51 NO.170>>171
495>>169
496This imageboard runs on PowerBook 180 and has 80MB of hard drive space.
497
498Case 2016-07-18 22:23:32 NO.171
499>>170
500Hmmm I've seen wget and powershell recommended elsewhere for archiving websites. If you're familiar with them, what you would you recommend for personally automating thread archival? I've never had to use either before so which ever one is most straightforward is preferred.
501
502Faye Valentine 2016-07-18 22:47:25 NO.172>>173
503>>168
504>>168
505>it's an imageboard. threads dont get saved
506That kind of logic is completely flawed.
507A lot of different imageboards have resource filled threads that are "generals" and cyclical, continuing on theme/topic of last thread, so if you start to read the middle of conversation you will be really dazzled and confused.
508That's why a lot of people just save them with 3rd party sites like archive.is or even just CTRL + S
509If you are however trying to insinuate that imageboards don't have capabilities and functions of saving threads, I would agree with you but for completely different reasons (I assume). But that wasn't the question >>167
510asked. He simply asked if someone saved it.
511I think that was "high quality post" what you guys would say, no?
512
513Lady 3Jane.. 2016-07-18 23:23:32 NO.173>>174
514>>172
515I think it partially has to do with the tinfoil mentality that the cyberpunk scene can foster. They don't want the threads saved because then gubberment will find their sekrit haxxor techniques.
516
517Cutter 2016-07-18 23:31:20 NO.174>>175
518>>173
519>then gubberment will find their sekrit haxxor techniques
520I understand that you tried mocking here, but still the line of logic makes no sense.
521People that are into haxxor world understand that gubberment has enough resources, time and goal to either invest in or to just buy out their own breed of super duper haxxors. In reality people that have brains already acknowledge that other people have brains too, there is no need for these pseudo-secrets that anyone can google for, and if you are trying to insinuate that cyerpunk scene doesn't have that good enough of self-awareness then I don't understand what your thought process is to be honest.
522The bottom of the barrel of cyberpunk scene, yea even lainchan, can acknowledge that gubberment surveillance is pervasive and persistent and it won't go away until the whole system comes crashing down.
523So, "tinfoil mentality" won't be directed at saving threads to help the little guy trying to have fun on his computer, but rather will be directed at cautionary way cybers act towards the gubberment.
524
525Bobby Newmark 2016-07-18 23:50:47 NO.175>>176
526>>174
527I posted that because I have seen some lainons claim that it defeats the purpose of a chan, especially one of this nature. The cyberpunk scene does have good self awareness but it is still prone to tinfoiling with the topics at hand. I mean /g/ is just a regular tech community and it tinfoils often, justifiably or not.
528
529Cowboy 2016-07-19 00:25:12 NO.176>>177
530>>175
531>I have seen some lainons claim that it defeats the purpose of a chan, especially one of this nature
532Well, you're moving the goalpost, but I would love to see where these lainons are, especially when I explained above how these resource filled informational threads are in dire need for people that want to re-read or people that are new to conversation and want to be up-to-date with topic at hand and with all info that was posted.
533
534>still prone to tinfoiling with the topics at hand
535I have no problem with tinfoiling, it's kind of natural that with more exchange of information (and wider accessibility of internet) we have come to point where we now know some of shady dirty things that governments and politicians do for their own or interests of their groups.
536Just look at Shillary mail scandal, I guess nobody really looked at it but most people are making a fuss about it. Why? Because she talked about how Syria needs to be taken down for Israel interests (this was back in early 2000s). Obviously a lot more players were involved in Syria, not just AIPAC and Shillary, but that alone makes you little bit paranoid and cautious about what other shit might be going on so the general rule of thumb is the kind of "everything that can go wrong, will go" of paranoia. So most people just try to keep 1 upping themselves over privacy and hacking paranoia which in my opinion I have no problem with, its in best interest of everyone to be up to date and best, so whats the downfall? Few shizos running around connecting dots? Big whoop
537
538>>167
539I found it on archive.is
540HTTP://ARCHIVE.IS/ZVHDW
541
542Liet-Kynes 2016-07-19 02:21:51 NO.177>>178>>181
543>>176
544How is that moving the goalpost? My observation was the basis for the post, not a diversion. Like I said it is not the only reason. it is probably a reason among several for the lack of an archive. I would show you where lainons said this when the issue of archiving was brought up, but I can't because the threads have disappeared due to the lack of an archive.
545
546>inb4 unfalsifiable
547
548Many would agree with you about the preservation of resource rich threads, and I certainly do, but that doesn't mean it is the consensus. Even if I don't wholy agree, there certainly is some merit to the argument of maintaining overall plausible deniability and having the onus on the individual to save the threads for themselves. Skepticism (which is different from tinfoiling) of the government is certainly healthy and rational as you have pointed out. Still with semi-hivemind chan culture the way it is, it can become counterproductive irrational paranoia.
549
550And that archive link you posted is in the OP. It is also not the previous thread, but the one before it. The previous thread was not saved, apparently.
551
552Project 2501 2016-07-19 02:34:08 NO.178>>179>>181
553>>177
554if it's about needing resources, lets make a wiki
555
556Project 2501 2016-07-19 02:53:16 NO.179>>181
557>>178
558We just need a pastebin for the generals, and someone in charge of uploading dying thread generals to archive.is so they don't get lost forever. There are already enough resource wikis and aggregated cyberpunk sites out there.
559
560Yuki Nagato 2016-07-19 11:16:46 NO.180
561Be the change you want to see in the Wired.
562
563Cutter 2016-07-19 12:49:58 NO.181>>182
564>>177
565>My observation was the basis for the post, not a diversion
566My wrong, it just seemed like you were trying to change the topic.
567
568>>inb4 unfalsifiable
569I trust you.
570
571>maintaining overall plausible deniability
572We are, on what I would like to believe, is anonymous imageboard with only one who is in capability to see our real identity being the chan owner and his friends with access to the server.
573With that being said, plausible deniability is already ingrained in the anonymous nature of imageboard, assuming that the letter soup agencies won't ask kalyx for any info. But even then, I assume most people here browse with Tor or some VPN.
574
575>on the individual to save the threads for themselves
576As I said, what if someone comes in the thread in middle of conversation? Can't he get info about past conversations?
577
578>Still with semi-hivemind chan culture the way it is, it can become counterproductive irrational paranoia.
579I guess we have different ideas of what "paranoia" is. You associate it (I assume) with circlejerking and shitposting around the scary idea and I associate it with that few anons that never say anything and that always are in the shadows, only coming out to talk about their paranoid thoughts and to overall build on that paranoid thought, whether that be through software or doxxing of officials and making connections.
580
581>It is also not the previous thread, but the one before it. The previous thread was not saved, apparently
582Welp, darn.
583
584>>178
585>let's make a wiki
586We can do it through Wikia. I already have chosen the "Lainchan Hacking General" name. What do you think?
587
588>>179
589Wiki is kinda better, pastebins are clunky and unreadable in my opinion and wiki has better look overall in my opinion
590
591Neuromancer 2016-07-19 15:23:00 NO.182>>184
592>>181
593You are correct on the anonymous posting and identity part. I meant more along the lines though of in the event the law enforcement or whoever swooped in only seeing a mostly innocent sci-fi fantasy discussion site rather than a subversive one due to lack of an archive. Keeping these threads uploaded to a public archive gives them too much of a track record to build a case, and helps them put more pressure on Kalyx and his friends who have low capacity and resources to resist. This helps keeps the site alive, and that's more what I meant by overall plausible deniability.
594
595The circlejerking and shitposting where they blow everything way out of proportion and essentially fearmonger is what I associate tinfoiling with mostly. Like caricatures of Richard Stallman. I associate the latter of you referred to more with legitimate hacktivists though that scene can attract a few anarchists and nihilists which makes them seem tinfoil at times.
596
597If we make a wiki we should go all out and make it a resource hub, not just for hacking. Have a programming section, hacking and social engineering section, etc. We can build off of other wikis.
598
599Lord Nikon 2016-07-19 18:38:01 NO.183>>244>>281
600if (line[0] == 1 && !strncasecmp (line + 1, "ACTION", 6))
601{
602po = strchr (line + 8, '\001');
603if (po)
604po[0] = 0;
605inbound_action (sess, dcc->serv->nick, dcc->nick, "", line + 8, FALSE, FALSE);
606} else
607{
608inbound_privmsg (dcc->serv, dcc->nick, "", line, FALSE);
609}
610Find the flaw
611
612Shogun 2016-07-20 01:52:23 NO.184>>187
613>>182
614>meant more along the lines though of in the event the law enforcement or whoever swooped in only seeing a mostly innocent sci-fi fantasy discussion site rather than a subversive one due to lack of an archive. Keeping these threads uploaded to a public archive gives them too much of a track record to build a case, and helps them put more pressure on Kalyx and his friends who have low capacity and resources to resist.
615
616They would find who owns the physical server and just use digital forensics on it to recover everything deleted or overwritten. That being said, not having a archive would be a layer of security against OSINT
617
618
619>The circlejerking and shitposting where they blow everything way out of proportion and essentially fearmonger is what I associate tinfoiling with mostly.
620
621This is a big thing people get so paranoid they become unproductive, and do more harm than good. it's good to be paranoid bad to think zebra and not horse.
622
623that being said it shouldn't matter because you wouldn't be posting your illegal actions on a PUBLIC web forum.
624
625FBI and Europol didn't get lulzsec because a vuln in tor or x software, they got logs and used their conversations to identify where they lived.
626
627not that you would do anything like that lainon
628
629Eldon Tyrell 2016-07-20 01:54:54 NO.185>>186>>189>>191
630How can I go about "injecting" (I don't know if this is correct term) a Win32 program I've created into an admin process?
631
632I need to get admin privileges/get around the UAC. I'm new to both systems programming and Win32 so I don't really know what terms to search for. The goal though is to not have to prompt for UAC.
633
634Switch 2016-07-20 02:46:23 NO.186
635>>185
636what you're looking for I think is "escalation of priviledge ".
637I don't know much about the subject but you should get a lot by looking thought the info posted ITT or through search engine
638
639Shogun 2016-07-20 04:36:55 NO.187>>188
640>>184
641Haha somebody should hack their server to retrieve the last thread then. Jokes aside, is their anyway of maintaining plausible deniability with a server on the clearnet besides aliases and such? Is the only alternative ptp networking?
642
643From what I read they were able to take down lulzsec because they targeted a key leader who had a lot to lose in his personal life if he didn't cooperate. So if you want to be a real hacker you should be detached and distant with the other hackers in your group.
644
645Joey 2016-07-20 04:54:22 NO.188
646>>187
647>>143
648>HTTPS://WWW.YOUTUBE.COM/WATCH?FEATURE=PLAYER_DETAILPAGE&V=9XAYDCDWIWU
649
650The Fin 2016-07-20 15:57:59 NO.189
651>>185
652Depends on your attempted point of ingress
653
654Look up Thread Local Storage injection that can allow you to inject and spawn a thread under another running process.
655
656Marly Krushkhova 2016-07-23 22:10:53 NO.190
657Bump
658
659Rick Deckard 2016-07-24 00:37:07 NO.191
660>>185
661>>185
662If it's just UAC you need to bypass then check out UACME:
663
664HTTPS://GITHUB.COM/HFIREF0X/UACME
665
666Otherwise, you'll need an privesc exploit. These aren't impossible to find but finding one in vanilla windows may take a fair bit of time. Your best bet is to exploit system specific misconfigurations or other shifty software running on the target system.
667
668Joey 2016-07-24 16:56:12 NO.192>>208
669What kind of jumpboxes do you peeps recommend? Ofc you could buy with bitcoin, but the anonymity of it could vary, depending on how you buy and use the bitcoins themselves. Is it a good idea to use already hacked boxes as jumpboxes?
670
671Cat Mother 2016-07-27 02:09:50 NO.193>>194>>195
672File: 1469585390685.JPG (6.09 KB, 223x226, 223:226, 1469072600217.jpg) IMGOPS EXIF IQDB
673
674Suppose there was a website with multiple sql injection points.
675How would I go about dumping the database?
676
677The only approach I came across is to add an and expression and use a conditional operator to extract the data char by char.
678I imagine this to be very slow, there ought to be something faster.
679
680Miho Iwakura 2016-07-27 03:13:05 NO.194>>203
681>>193
682
683Yeah use OUTFILE to dump to a file on the server's static rsource directory. Since most 'webapps' use routing for url handling but define a static directory for images, css, and other non dynamic elements. Then pick it up by navigating to that file, domain.xyz/static/dump.sql
684
685FAYE VALENTINE 2016-07-27 03:21:13 NO.195>>196
686>>193
687make sure you're in incognito mode or the feds will bust you
688
689J.C. DENTON 2016-07-27 23:47:09 NO.196
690>>195
691i really hope your joking...
692
693The Phantom Phreak 2016-07-28 07:17:12 NO.197
694Can anyone help me out with this?
695i'm working on a web, can inject some sql and upload php files but exec and system functions are disabled.
696Have any ideas to scale on the server?
697
698Selhar 2016-07-28 11:35:07 NO.198>>210
699File: 1469705707203.JPG (47.31 KB, 337x450, 337:450, 1329418108468.jpg) IMGOPS EXIF IQDB
700
701I need your input, /cyb/. I'm sorry if i make some grammar mistakes, english isn't my native language.
702I've been programming for about 5 years, i started at college and after 4 years i noticed how bad the education they offered was and how much they charged, so i left college. I've worked for a year as a Java developer but i quit. I did not enjoy working with front end, i am not good at it and i do not wish to work with that again. I have programming knowledge but nowhere near as much as i should have for someone who has been programming for so long. A few months ago i started studying math, back end and c++. I've learned a lot superficially, enough to know where i wish to specialize. I want to study encryption, security, hacking, reverse engineering and performance(query speed, execution speed etc), also i want to work remotely, since my experience in private and public corporations have not been good for me psychologically.
703From this thread and previous knowledge i created a study routine, but i need the insight from more experienced people to know if this is a good plan to follow and if it's realistic to make money from this knowledge.
704
705My current plan is:
706Mathematics ( i'm following 8ch's /prog/ sticky, currently in Serje Lang's basic mathematics );
707Cybrary (A+, Linux, Networking, Security, Penetration testing, computer hacking forensics, Python for security professionals, advance hacking, cryptography);
708Offensive security classes (HTTPS://WWW.CS.FSU.EDU/~REDWOOD/OFFENSIVECOMPUTERSECURITY/LECTURES.HTML)
709Freecodecamp (freecodecamp.com)
710Read Hacking: The Art of Exploitation;
711Read HTTPS://TRAILOFBITS.GITHUB.IO/CTF/INDEX.HTML
712Do HTTP://WWW.PRIMALSECURITY.NET/TUTORIALS/PYTHON-TUTORIALS/
713
714Freecodecamp is mostly to have a way to make money in case everything goes wrong and i have nothing to eat. I don't expect to get much knowledge out of it, but they have lots of trendy technologies which would be useful to get a quick job, it's a failsafe. Keep in mind my goal isn't to gain illegal money, i just want to learn stuff that i enjoy and if i'm lucky make a living out of it from remote working and/or freelancing. Otherwise i will use it as a hobbie and work at a mall or something, either way i wish to learn the stuff. Don't worry about logistics or discipline, i will split these into 2 hours chunks of study. I already have been doing that for a few weeks, i just didn't have any focused course. I'm aware this is very long term and that's exactly why i need someone elses experience before i put in tons of time on something that might not be any good.
715
716Do you think this material is any good, would you change/add something to it? Do you think it's realistic to get a (remote) job from this sort knowledge or make consistent money out of it, at least enough to pay for bills/food? I don't really wish to make an "official" career since i oftenly don't feel comfortable in these enviroments.
717
718Selhar 2016-07-28 17:32:28 NO.199>>200
719In op's archive page, there's a link for another, older archive.
720
721HTTP://LAINCHAN-HACKING-GENERAL-1.NEOCITIES.ORG/CYB/RES/1372.HTML
722
723Wintermute 2016-07-28 19:25:24 NO.200
724>>199
725Yeah that was the first hacking thread. The OP archive was the second. The third wasn't saved and we are now on the 4th
726
727The Oracle 2016-07-29 00:06:31 NO.201
728Are there any public wargames/pen testing simulations similar to the OSCP labs/exam?
729
730Selhar 2016-07-29 10:51:25 NO.202
731I just found these classes, they're from Owen Redwood, the guy from offensive computer security.
732
733HTTP://HOWTO.HACKALLTHETHINGS.COM/2016/07/LEARNING-EXPLOITATION-WITH-OFFENSIVE.HTML
734
735They seem to be MUCH more web oriented than just a recorded college class, also it's more fresh than the one from 2014.
736
737Terzibashjian 2016-07-29 11:56:40 NO.203
738>>194
739That requires FILE privileges (which are rarely granted) and a writeable directory (writeable to mysql, not http). If you manage to get OUTFILE working, you should just drop a shell.
740
741SELHAR 2016-07-29 21:36:35 NO.204>>205
742Hey, i won't bump the thread since i've been posting a lot lately, but i found a pretty nice beginner's C tutorial if anyone is interested. It's exercise oriented.
743
744HTTP://C.LEARNCODETHEHARDWAY.ORG/BOOK/INDEX.HTML
745
746The Fin 2016-07-29 21:45:15 NO.205>>206
747>>204
748I've done about half of this tutorial, it's pretty good but some people really hate Zed Shaw.
749
750Selhar 2016-07-29 21:50:04 NO.206
751>>205
752I hate his personality, he's a really annoying cunt who's probably impossible to work with. I don't think that really affects his work though, except that sometimes he's a bit prepotent even in his writing, but other than that...Can't really say anything about his technical knowledge.
753
754Joey 2016-07-30 05:32:03 NO.207
755>>124
756You can find a torrent of the course booklet but it's a couple years out of date. (The one I have is for BackTrack.)
757
758Much of it is still relevant though.
759At the very least it's a good start point for those of us interested in the course but too damn broke to just buy it without first getting our footing first.
760
761You can find it with a simple search on your favorite tracker.
762
763Bobby Newmark 2016-07-30 11:39:57 NO.208>>209
764>>192
765Bump on this question.
766Tor is a nice network but it's too slow and doesn't do UDP, so my preferred method would be using jumpboxes.
767
768Me -> TOR -> Jumpbox -> Target
769
770The important thing is that the jumpbox cannot be used to identify me.
771
772Agent Richard Gill 2016-07-30 13:27:13 NO.209>>223
773>>208
774NSA owns a lot of Tor exit nodes and NSA has connections to most of international secret agencies that have local power to ask ISPs to do their bidding.
775So, time correlation attacks where packet times are looked at coming in Tor network (by ISP) and coming out of Tor exit node (by NSA) could link your identity to jumpbox.
776Although, this wouldnt be done on some small fishy.
777
778I would suggest either buying a VPN or rooting some old box that you would use between your PC and Tor network just so that your ISP doesnt see that you communicate with Tor.
779
780The Oracle 2016-07-30 21:01:50 NO.210>>211
781>>198
782sorry for the late reply,
783
784I wouldn't see why you would need the mathematics?
785
786Also before you start redwoods open course make sure you have a asm foundation i thought i could wing it on the way there and i learned the hardway that i couldn't.
787
788Selhar 2016-07-30 21:26:06 NO.211
789>>210
790Yeah, i'm doing C and asm before starting with redwood. He's very helpful at reddit, it shouldn't take more than a week before i'm able to keep up with the videos. He's posting an updated series right now.
791
792The mathematics is more of a hobbie than anything really. I'm not yet sure where i can enjoy what i do AND work at home, maybe i'll go into statistics or something, i wanna have that option, but more than anything i just like mathematics.
793
794Special Agent Bob 2016-07-30 23:18:02 NO.212>>213>>214>>215
795File: 1469920682125.JPG (1.46 MB, 1920x1080, 16:9, 0004.jpg) IMGOPS EXIF IQDB
796
797Where can I read more about so-called "black hat" monetization techniques?
798
799None of that "spamming malware to grannies" Indian-scammer tier bullshit. I mean the real "1337 h4x0rz".
800How do the real serious crackers make their cash?
801
802(Disclaimer, I'm not interested in committing any crimes myself just curious about the actual details of how the criminals work)
803
804Selhar 2016-07-30 23:35:02 NO.213
805>>212
806I think studying OSCP and related fields is the most effective way. You'll have to learn that stuff to defend against it.
807
808I'm in no way qualified to answer, it's just an educated guess.
809
810Chani 2016-07-31 00:49:03 NO.214>>216
811>>212
812
813Well you're not going to be hand held in any useful capacity because it's simply the way it is. A certain gimmick, process, technique, script (SE), or anything in between that is successful in making cash will by its nature be hoarded.
814
815The lucrative side of things comes with networking with people. For example, I know person A. A has a few XSS exploits that are persistent and affect a very high profile web site. I look and find person B. I middle man A & B so that A isn't revealed. I collect commission.
816
817You can be A or B, or C in this situation. But most likely you'll start out as B.
818
819Other places where money is made by "crackers" (you really need to narrowly define this) is in selling their fruits. Such as a botnet. Or sell services as a result of that botnet, such as DDoS, or breaking hashes.
820
821CC's are often sold in dumps and can fetch a nice price (again networking will save you here). So on and so forth.
822
823Meddler 2016-07-31 01:46:10 NO.215
824>>212
825I hate to be negative but today that's one of the biggest ways to make money,
826
827it tends to fall under three categories
828some form of credit fraud - (stealing and selling NPPI)
829ransomware
830or exploit dev / malware dev
831
832Molly Millions 2016-07-31 03:53:25 NO.216>>217
833>>214
834>CC's are often sold in dumps and can fetch a nice price
835Here's something I don't understand about this.
836
837Why would a person who has a stolen CC sell it off for practically nothing?
838e.g. Selling an individual card for $5 - $30, when it can potentially be used to purchase many times that amount?
839
840Why don't these "carders" simply use the stolen cards themselves and multiply their profits?
841
842(Forgive me if this a naive question, I'm not exactly a black hat nor do I want to be. Just looking to get a better understanding.)
843
844Shogun 2016-07-31 04:10:58 NO.217>>218
845>>216
846
847That's easy. Risk mitigation. Even with a fully cloned card you open yourself up to a tremendous amount of risk by having to appear in person with the card and possibly an ID to go with that card. You might be thinking right now, "Oh why don't they just shop online?" Track dumps aren't that helpful since most major credit card processors on the SWIFT network (banking network) now use associated data to verify the purchase.
848
849Verified by Visa is a big one. You have essentially go through what is a secondary authorization to activate it. Which also means having to have the address that the card is associated with.
850
851Even with a dropshipped item there's also the risk of having someone in LE catch on and wait for you at the dropship location.
852
853So it comes down to risk. It's often easier to sell batches of these with almost no risk, behind tor and 7 proxies (so to speak) and transact solely through bitcoin.
854
855The recipients will be putting themselves in danger every time they use the card.
856
857The only exception to any of this that I can really see is purchasing digital goods. Such as VPN subscriptions, or VPS'es. The legitimate problem with cash like this is the amount you eventually lose after attempting to, and possibly succeeding, in laundering the cash into a liquid currency.
858
859Switch 2016-07-31 04:18:33 NO.218>>219>>221
860>>217
861I see, that makes a lot of sense.
862
863But why not just use the stolen cards to buy the BitCoin itself?
864Surely there are some less-than-reputable dealers out there who would sell it with no questions asked?
865
866Couldn't someone set up a "farm" so to speak of bots that used stolen cards from dumps to purchase large amounts of bitcoin?
867
868Turner 2016-07-31 04:32:11 NO.219>>220>>221
869>>218
870
871Because bitcoin always keeps record of all the transactions. Anyone can follow where the cash flows from. The moment a wallet receives the illegal funds, anyone can watch who received it and how they spend it.
872
873The best anonymizing step is to take the CC's convert it to liquid and untraceable goods/currency then taking the anonymizing step of disconnecting the CC from the bitcoin wallet which still involved the steps I mentioned above.
874
875Now people do buy bitcoin with stolen CC's but they know that their wallets are known to have dirty money. And so do other people. And it might not matter after about 30 transactions have passed, the money then can really be pointed to be anyone in particular. Just which wallets had touched other 'dirty' wallets.
876
877If I were the CC dude I would do this. Get a CC and purchase a few items off of Amazon tha tmight have high resale value. Such as an opened box of video cards, or SSD's or anything in general. Send it to a confederate (we mafia now) a state away and have him sell them on craigslist as part of a complete build.
878
879The confederate then pays him in cash either before after or whenever (so long as I would receive this hypothetical cash). then use cash for bitcoins. Send some bitcoins to one wallet, send some to another.
880
881Then rinse and repeat.
882
883Neuromancer 2016-07-31 05:05:26 NO.220>>221>>240>>257
884>>219
885>Because bitcoin always keeps record of all the transactions. Anyone can follow where the cash flows from. The moment a wallet receives the illegal funds, anyone can watch who received it and how they spend it.
886
887Why do criminals use it? Why don't get they busted I mean if it's ultimately traceable back to them? How do they 'clean' it?
888
889Agent Smith 2016-07-31 05:46:30 NO.221>>225
890>>219
891I don't agree with this. It's easy to 'clean' bitcoins by tumbling them through darknet services and/or converting them into another cryptocurrency through an anonymous exchange. Otherwise >>220 would have a too valid point and it wouldnt be so useful for buying drugs and for ransomware.
892>>218
893>But why not just use the stolen cards to buy the Bitcoin itself?
894Essentially everyone that's selling bitcoins is aware of scammers and so they take ID; because if they do the trade with dirty money, you run away with the bitcoins and the banks can take their funds. The sellers who don't, charge a much higher price for the bitcoins -- check out localbitcoins, it can even be like 20% premium or something -- and they'll probably tell you to get screwed if you say you can't do a cash transfer but just have some dodgy card. It's possible but it takes effort because you need to set up fake IDs, accounts, and to seek out naive sellers. In the end it can be easier and safer to sell off stolen cards, especially if they have a lot of them
895
896Selhar 2016-07-31 08:57:28 NO.222
897Here's a list of tutorials just posted on cybrary's forums. Seems pretty good, haven't checked yet though.
898
899HTTPS://WWW.CYBRARY.IT/0P3N/BEGINNERS-GUIDE-LIST-OF-TUTORIALLEARNING-RESOURCES/
900
901Molly Millions 2016-07-31 15:27:16 NO.223>>224>>226
902>>209
903The point is that the jumpbox can be identified. With a jumpbox I can actually do DNS enumeration with zone/wildcard attacks, UDP scanning and dumping fast. What I need to make sure that the jumpbox cannot be connected to me.
904
905Cutter 2016-07-31 23:22:10 NO.224
906>>223
907Find a vuln sever, get a shell, use that.
908
909Lady 3Jane.. 2016-08-01 03:03:42 NO.225
910>>221
911>>221
912unfortunately no. As ' complicated as you try to make it, every swap is recorded. And swap groupings can beand are a huge point of correlation. every swap is recorded. And swap groupings can beand are a huge point of correlation. Not to mentionke it, every swap irecorded. And swap groupings can beand are a huge correlation point . Not to mention a lof of bit- coin laundaries are outright scams. When I have a chance to get on a computer; I'll source examples of how/ why btc gives everyone the chance for Omniscience over the chain.
913
914Donna Hawthorne 2016-08-01 03:43:20 NO.226
915>>223
916>jumpbox
917Any VPN (that upholds your privacy, I suggest cryptostorm) or rooted box shall cut the job
918
919Masami Eiri 2016-08-01 08:48:41 NO.227>>228>>229>>230
920
921Can someone recommend a book or learning source on linux server administration?
922
923I have a small website I want to host on an old computer but know little about good practices and general proper security.
924
925Selhar 2016-08-01 09:10:31 NO.228
926>>227
927Take a look at cybrary and read the rest of the thread. There are collections of resources that mention linux administration.
928
929The Oracle 2016-08-01 11:36:54 NO.229
930>>227
931Book is The Linux and Unix Sysem Administration Handbook. I don't know about the security portion in particular though.
932
933Zero Cool 2016-08-01 15:51:16 NO.230
934>>227
935Can't go wrong with O'Reilly Linux system administration
936
937Selhar 2016-08-01 18:55:14 NO.231
938File: 1470077714109.GIF (1.78 MB, 300x189, 100:63, sAvGJPB.gif) IMGOPS IQDB
939
940Found more neat stuff: HTTP://OPENSECURITYTRAINING.INFO/TRAINING.HTML
941
942God, i haven't been this excited about studying and even living in a very long time.
943
944Hacker 2016-08-01 19:17:29 NO.232>>233>>237>>239>>243
945I want to become a cyberpunk. I always thought hackers and demosceners and crackers and stuff were cool as shit as a kid. Then there was shit like GNAA and weev and TOR, trolls and what not like Team Gamerfood.
946
947It always seemed beyond my scope but things have changed lately. Pirating isn't as simple as media fire and megaupload anymore. Every website you sign up on, my android phone, anything google, every time I download an app it wants all my details, sites want phonecall verifications and shit. Lately I've been looking at shit and as soon as I went to google it, many of the top results were shit that was actually RELEVANT to what I was looking at. I fucking clicked a picture of some guy holding a tomoko kuroki dakimakura, I thought it was cool so I saved it and went to google one for purchase. I typed in "Tomok" and immediately "Tomoko kuroki bodypillow" popped up for the autofill.
948
949Shit like this has been happening a lot lately, I need to get out of the matrix.
950
951NEUROMANCER 2016-08-01 19:21:54 NO.233>>234
952>>232
953*for got to add that I clicked the picture on 4chan, not google chrome.
954
955I've been using it a long time now because I like the interface, I'm even using it right now typing from my phone. I used to be worried a lot about cyber dystopia back in like 2011 but I got complacent and now with TPP and shit its actually happening.
956
957I need to start learning shit
958
959Selhar 2016-08-01 19:31:55 NO.234>>235
960>>233
961You can find everything you need in this thread. Just look around. Try to improve your (english) writing, it will make it easier for you to interact with other communities. Good luck.
962
963Neo 2016-08-01 22:31:00 NO.235>>236
964>>234
965Alright, I'll look around. I don't even really know what a hacker is, I always thought they were just college-educated programmers who liked to fuck around a lot. I don't know a thing about programming, but in my youth I loved trolling and visiting unsavory places like ED, textfiles/totse/zoklet etc and 4chan.
966
967Is there a particular music that hackers listen to? I always thought they listened to this kind of stuff.
968HTTPS://YOUTU.BE/DSIDRARW0YW
969
970Selhar 2016-08-01 22:42:56 NO.236>>238
971>>235
972"Hackers" are just people. They listen to whatever they enjoy, each one will enjoy a different thing.
973
974Roy Batty 2016-08-01 22:45:22 NO.237
975File: 1470091522249.JPG (90.29 KB, 575x833, 575:833, chen.jpg) IMGOPS EXIF IQDB
976
977>>232
978>Then there was shit like GNAA and weev and TOR, trolls and what not like Team Gamerfood.
979
980Jinzo 2016-08-01 22:50:14 NO.238
981>>236
982I could have sworn that all hackers wore tiny sunglasses and trenchcoats and listened to HTTPS://WWW.YOUTUBE.COM/WATCH?V=WSCGDHJ_SNO
983
984What am I gonna do now? I already got a cool handle (Jinzo) and everything.
985
986nao i do da hax?
987
988APOC 2016-08-02 04:53:48 NO.239>>241>>242
989>>232
990>GNAA
991>literal nazi
992>TOR
993>pirating isn't as simple as megaupload any more
994>google knows I'm a weeb
995
996the hacking threads really bring out the kids.
997
998look newlain, not necessarily in this order, but:
999
1000>delete all your hentai
1001>throw out all your weeb shit
1002>actually throw out everything you own except your computer and a mattress
1003>read all the phrack, PHC, ~el8, and anti-sec textfiles
1004>install a 90s linux server on actual hardware that you get from a dumpster
1005>write exploits for it
1006>RTFM
1007
1008fucking lurk more too
1009
1010Case 2016-08-02 05:02:08 NO.240
1011>>220
1012Not our friend '396, but the reason is because it's not necessarily trivial to link a bitcoin wallet with a human. A bitcoin wallet is literally a node in the bitcoin p2p network. If you only connect out to Bitcoin via Tor or another proxy, that's the best means of identifying you gone, so now you have to use other mechanisms like watching the coins like a hawk.
1013
1014The other thing is, it's not like the DEA has enough resources to track and arrest every online drug dealer even if they wanted to. And they don't really want to - arresting some random MDMA vendor on the internet is not going to make anyone's career, nor are 100 similar arrests. On the other hand, being on the team that brings down a cartel means you get promoted, your group gets more funding, etc.. Remember, state repression is just as gamified as anything else in this century.
1015
1016Agent Richard Gill 2016-08-02 05:06:33 NO.241
1017File: 1470114393427.WEBM (3.85 MB, 853x480, 853:480, proto-waifu-is-suffering.webm) IMGOPS IQDB
1018>>239
1019
1020>doing any of that
1021
1022But why? According to the Gugel overmind all he ever really wanted was to offer his dick to Tomoko!
1023
1024Fuck all that dumpster noise.
1025
1026Build a autowaifu, Lain, I know you have it in you!
1027
1028Chani 2016-08-02 05:44:35 NO.242
1029>>239
1030Not who you're replying to, but I pretty much do already only own a computer and a mattress.
1031
1032In fact, I don't even own a real mattress. I sleep on a twin sized air mattress in a shithole apartment with shifty immigrants and criminals for neighbors, and my only computers are Linux on "re-appropriated" hardware.
1033
1034i am supar 1337 h4x0r nao ?
1035
1036Agent Richard Gill 2016-08-02 07:00:53 NO.243
1037File: 1470121253072.JPG (180.33 KB, 600x450, 4:3, hackerpirate.jpg) IMGOPS EXIF IQDB
1038
1039>>232
1040>Wants to be a cyberpunk
1041Wants to be a genre of fiction
1042>How do I become 1337 Hax0rz?
1043Facepalm.jpg
1044>Pirating isn't simple
1045And you want to hack?
1046>Tricked by google bot net
1047Good luck learning to cover your tracks.
1048
1049Rethink your dream lainon. Cyberpunk is a genre of literature, just ask Gibson. Everyone and their mother wants to be like Neo and hack the Matrix, but many are let down when they realize that hacking, reverse engineering, and cracking aren't like hollywood. For one, problem solving skills an self education are a must. Asking how to hack is a question left for script kiddies at best. You need to have a firm education in hardware, networking, server, cryptography, programming, and mathematics. Come back when you have some of that under your belt and can ask more useful questions. Had you asked something like this anywhere else, you would have been met with silence or laughs. If you want useful answers, ask smart questions. Here's a guide (that guide should be stickied to the top of cyb, tech, and λ):
1050HTTP://WWW.CATB.ORG/ESR/FAQS/SMART-QUESTIONS.HTML
1051
1052Also scan the gentoomen library if you need a place to start:
1053HTTPS://G.SICP.ME/BOOKS/
1054
1055Cereal Killer 2016-08-02 16:08:58 NO.244
1056>>183
1057You mean besides your naming scheme, the fact it's an incomplete section of code, the fact you're using a ctrl-a delimiter to clear the screen. The fact that inbound_action(), inbound_privmsg(), and most of the variables you're passing are undefined?
1058
1059I'm not good enough at security to know what you're trying to do. Looks like you're reading a message form a server. Is this like a command and control thing?
1060
1061Selhar 2016-08-02 20:55:02 NO.245>>246
1062Can someone help me with the concept of network ports? I just don't seem to be getting it right.
1063
1064Let's say there is host A and servers B and C. If servers B and C send me different information, wouldn't their IP be enough for me to know who is who?
1065
1066Why do i need server B to send me information through port 90 and server C to send me through port 91? I understand that ports exist to allow you to connect with different applications and services, i just don't see why. From a security perspective it makes sense, since you can block anything that isn't 90 and 91, but that's not the reason ports exist, isn't it? They exist to allow more communication.
1067
1068Mitnick 2016-08-02 21:05:56 NO.246>>247
1069>>245
1070>Why do i need server B to send me information through port 90 and server C to send me through port 91?
1071You don't? Web servers for example typically listen on port 80, and they are contacted by many different clients.
1072
1073Selhar 2016-08-02 21:08:29 NO.247>>248
1074>>246
1075Then what do you need ports for?
1076
1077Dozer 2016-08-02 21:10:01 NO.248>>249
1078>>247
1079So you can run an ssh server and a web server at the same time.
1080
1081Selhar 2016-08-02 21:15:16 NO.249>>250
1082>>248
1083So it works from the server point of view?
1084
1085I was thinking about it from the host POV, as in "i will be accessing this IP and expecting things from this port".
1086
1087But it's the other way, "i'll be sending stuff from my IP and you can expect from this port, and if i send something else, i'll send you another port", correct?
1088
1089Crash Override 2016-08-02 21:22:00 NO.250>>251
1090>>249
1091Yeah, a client will send a return address and port with it's message to the server. Have a look at the wikipedia page.
1092
1093Selhar 2016-08-02 21:22:36 NO.251
1094>>250
1095Thanks a lot.
1096
1097The Plague 2016-08-02 22:16:23 NO.252>>259
1098How do you fake seeders/leechers on a torrent? Do you need a botnet to do this?
1099
1100HELIOS 2016-08-03 02:13:53 NO.253>>254>>255>>258>>260>>265
1101File: 1470190433460.PNG (73.63 KB, 412x351, 412:351, peepeepoopoo.png) IMGOPS IQDB
1102
1103>get stuck at level 11 in smashthestack
1104>get stuck at basic level 10 in hackthissite
1105
1106Should I just learn PHP already?
1107
1108Lady 3Jane.. 2016-08-03 03:46:12 NO.254>>256
1109>>253
1110Keep trying lainon!
1111
1112I know you can do it :)
1113
1114The Phantom Phreak 2016-08-03 03:47:14 NO.255>>256
1115>>253
1116
1117Yes.
1118
1119Hagbard Celine 2016-08-03 04:32:54 NO.256
1120>>254
1121>>255
1122I succeeded! Onto realistic missions.
1123
1124Morpheus 2016-08-03 07:39:21 NO.257
1125>>220
1126They shouldn't. Bitcoin is not private or untraceable. Coinjoin works i guess but that is built on top. What you want is Monero.
1127
1128Morpheus 2016-08-03 09:01:52 NO.258
1129>>253
1130Most of HackThisSite can be done just by reading the forums.
1131
1132Agent Jones 2016-08-03 16:23:53 NO.259
1133>>252
1134it's easy
1135
1136>read the bittorrent protocol specification
1137>probably also read some of cam DHT papers
1138>use the knowledge you obtain to fake seeders/leechers on a torrent
1139
1140Jinzo!!lDbj95KHxA 2016-08-03 22:39:55 NO.260>>261>>262
1141>>253
1142what means PHP? I want to make my own Chan but I keep seeing that word. Why do you have disdain for it?
1143
1144Molly Millions 2016-08-03 22:47:28 NO.261>>263
1145>>260
1146PHP is a language. You use it to code websites that need to perform actions on the server. Like storing pictures... managing a database
1147
1148Case 2016-08-03 23:22:43 NO.262>>263
1149>>260
1150HTTP://PHP.NET/
1151
1152php is a programming language that is used for websites.
1153
1154HTML is mark up. You can't do anything programatically with this, but it's of course really useful to make a 'blue print' of what you want to see.
1155
1156CSS and JavaScript are there to help make the HTML actually look pretty, and create any cool effects you'd like to see on your website.
1157
1158PHP is what you use when dealing with anything involving security, databases, etc. If you look at the source code of a website, you do not see the php, which is one reason it's so useful. The other reason it's so useful is because it's one of the few things you can use on a website to manage certain tasks that HTML just can't really do.
1159
1160> Why do you have disdain for it?
1161
1162There is so much hatred for php because it's just an overall awful language. It's messy, most people just throw stuff together. It's very insecure, and it's a linguistic nightmare. Go look up examples of the code, you'll understand what I mean if you've ever worked with any decent programming languages.
1163
1164Jinzo!!lDbj95KHxA 2016-08-04 00:29:05 NO.263>>264
1165>>261
1166>>262
1167Oh cool, thanks. What languages should I learn in order? It sounds like you need to know a bunch to just do even simple stuff.
1168
1169I think I'll start with HTML, thanks a lot.
1170
1171Jinzo!!lDbj95KHxA 2016-08-04 01:14:28 NO.264
1172>>263
1173okay so I learned some HTML now I'll soon be on my way to leetness
1174
1175HTTP://S000.TINYUPLOAD.COM/INDEX.PHP?FILE_ID=11768619075894886124
1176
1177TURNER 2016-08-04 01:46:02 NO.265>>266
1178>>253
1179if you plan on any backend web usage you need to know basic php regardless, your only shooting yourself in the food by delaying the inevitable
1180
1181The Fin 2016-08-04 17:08:14 NO.266>>267>>272
1182>>265
1183Or you could leave the 90s technology behind and use a modern Python or Ruby based framework.
1184
1185Hacker 2016-08-04 19:03:07 NO.267>>268>>272
1186>>266
1187Oh you forgot to mention node.
1188
1189Cutter 2016-08-04 19:14:58 NO.268>>269>>272
1190>>267
1191I didn't forget. Node is cancer.
1192
1193Lord Nikon 2016-08-04 21:05:00 NO.269>>270>>272
1194>>268
1195
1196As is python, ruby, and every other web-dev facing language (yes they can be used for other things).
1197
1198Selhar 2016-08-04 21:35:06 NO.270>>271
1199>>269
1200I haven't studied enough to say anything about these languages, but one of the few things that all sources i'm studying from agree with is that python is a great, robust and secure language. What do you have against it?
1201
1202Molly Millions 2016-08-04 23:43:02 NO.271>>272
1203>>270
1204
1205It's not the language it's the web-dev community whic his largely why PHP is shit because of shitty culture surrounding development.
1206
1207I'll give yo uone example. Unless you specifically go out of your way to implement cooperative task programming (coroutines) with gevent, twisted framework, or asyncio libraries, the GIL will impose an upper limit on possible connections you can handle /well/.
1208
1209Now that's not a limitation of the language itself (since there are ways to accommodate it sanely), but it's definitely not something an off the shelf brogrammer will know how to deal with it. Add redis for message passing? Well how would you expect the same person to know how to allow their application to scale?
1210
1211I've google dorked a shit ton of flask programmers that left the interactive prompt enabled with their apps since they didn't bother to install a proper WGSI middleware to handle it.
1212
1213There's nothing particularly "safer" about the language given the ability for programmers to be lazy, or simply out of their depth. That goes for any part of web-dev regardless the language used.
1214
1215Cutter 2016-08-05 00:00:21 NO.272>>279
1216>>267
1217>>266
1218>>268
1219>>269
1220If you plan on attacking a web application you need to know the basics of how the backend is build, regardless of how you feel about them, you don't need to be masters, you don't need to LIKE them. but you need to know the basics so you know how to attack them. how you would do sql injection on a php application is difference from rubyonrails etc.
1221
1222>>271
1223its mostly because everyone uses a framework, and frameworks / libraries are not build with security in mind, sql should have gone the way of the dinos by now but people still use old out of date libraries, instead of libraries with filtering and sanitation built into the functions and classes.
1224
1225Selhar 2016-08-05 00:23:12 NO.273>>275>>278
1226I'm currently reading ARM Assembly Language by Pete Cockerell. Holy shit, it's an amazing and short book, he explains a lot of complicated concepts in a beautifully simple way.
1227
1228This book is in the gentooman's torrent file. I haven't finished it, but i highly recommend it, if anyone wants to learn assembly and basic computer architecture. He goes from ground zero and explains everything to you perfectly well.
1229
1230I tried to read Hacking - The art of exploitation but gave up because they heavily use assembly right at the beginning.
1231
1232What are you guys studying? Do you recommend any books, courses or videos?
1233
1234Acid Burn 2016-08-05 00:44:20 NO.274
1235PHP is shit but that's a terrible reason to not learn it. This isn't web development. How many shitty apps do you think are created in PHP? What do you think Wordpress and all of it's plugins are written in?
1236
1237Liet-Kynes 2016-08-05 01:54:22 NO.275>>276>>277
1238>>273
1239you won't fully understand hacking the art exploitation on the first go, DONT LET THAT STOP YOU! Most people quit after things get hard, if you don't understand something search it on the internet, look at forums, alot of good places to discuss exploitation!
1240
1241HTTP://HOWTO.HACKALLTHETHINGS.COM/2016/07/LEARNING-EXPLOITATION-WITH-OFFENSIVE.HTML
1242This is the goto course everyone points to, all open courseware you need to know basic asm (x86)and C, but that shouldn't be hard if what your saying is true,
1243
1244also cybrary.it has alot of good stuff and opencourseware but my only gripe is that is only really there to get people ready for certs. Not a bad thing.
1245
1246TRINITY 2016-08-05 01:56:45 NO.276
1247>>275
1248on top of that the torrent for the CD vm is here HTTP://WWW.MININOVA.ORG/TOR/2533556
1249
1250Selhar 2016-08-05 02:54:56 NO.277
1251>>275
1252Oh don't get me wrong, i'm not quitting on the field at all! It's just that right now i'm studying from quite a bit of sources and i'd rather take a week or two to study ASM/C and only then go back to art of exploitation.
1253
1254Thanks a lot for the resource! I already tried studying from there but right at the first class he mentions a lot of assembly and C, so right now i'm just going back to study C and assembly before going into hack all the things and art of exploitation. Otherwise i'd be stopping every ten minutes to study a related subject since i don't have any experience with C or lower level languages, i've only worked with java in my career.
1255
1256If you could recommend any material for C i'd gladly take it! Right now i'm just using learn C the hard way ( HTTP://C.LEARNCODETHEHARDWAY.ORG/BOOK/ ) and and a few books for assembly + tutorialspoint ( HTTP://WWW.TUTORIALSPOINT.COM/ASSEMBLY_PROGRAMMING/INDEX.HTM ).
1257I should be done with learn C the hard way and ASM this weekend, then i'll try both art of exploitation and hack all things. I'm also watching A+ from cybrary, i'm not taking the certs but i'm feasting on the videos, the material is pretty neat, i'm 42% through the course right now. After that i'll take other courses in network and security.
1258
1259If there's anything you can recommend me, i'd be really grateful, not only for C but anything that'd be helpful in a security perspective overall.
1260
1261Selhar 2016-08-05 04:03:33 NO.278
1262>>273
1263The book by pete cockerell starts showing its age after the first chapter. He uses ARM architecture, i felt like i was missing out on studying from him if i kept on it. But i still recommend the first chapter of the book for anyone who doesn't have these concepts. He delivers them in a very elegant way.
1264
1265Alice Miyuki 2016-08-05 05:31:49 NO.279
1266>>272
1267
1268Well despite agreeing with you mostly, I'll say that I meant to say that even /if/ the module/framework makes great strides towards security. DJango for example (which I personally dislike), has one-size-fits all CSRF protection, XSS detection, and makes it difficult to perform SQL injection aslong as you utilize the provided ORM.
1269
1270But the point I was making was even in the face of /that/, the implementors of the frameworks towards their end product, will still largely fail by using unsafe defaults (default non-escaped template interpolation); or failing to test for edge cases that can be present in every app. Aswell as not understanding implications of not providing cookies through SSL or using other back end products that break from the security suite provided by the framework. DJango for example won't apply their ORM to Redis, ZeroMQ or other pairings that aren't often seen with DJango in this example.
1271
1272Cat Mother 2016-08-05 10:59:15 NO.280
1273How to Win at Kung Fu and Hacking
1274
1275HTTP://GRUGQ.GITHUB.IO/BLOG/2013/11/22/CHALLENGES-FOR-HACKERS/
1276
1277Wintermute 2016-08-05 11:49:53 NO.281>>282
1278>>183
1279What you just parse input into a buffer like that?
1280No checks whatsoever?
1281Enjoy your remote code exec.
1282
1283Wintermute 2016-08-05 12:04:11 NO.282>>283
1284>>281
1285The code doesn't show the buffer being filled which is where problems like that come from (i.e. they didn't check the bounds and filled past the end of buffer). There's another bug in there but without context it's very hard to say how exploitable it is.
1286
1287Morpheus 2016-08-05 12:29:44 NO.283>>295
1288>>282
1289This guy gets it. Seems like nobody itt but you can actually hack. And correct, the exploitability isn't sure, but the idea is the same as in Heartbleed.
1290
1291Selhar 2016-08-05 12:30:32 NO.284>>285
1292Are there any good hacker groups out there?
1293Hackers as in "We spend most of our days studying because we enjoy it" and not "let's go deface a website because it's easy".
1294
1295Not that i have any qualification for joining, but it'd be good to know that such communities exist online.
1296
1297Neuromancer 2016-08-05 12:32:09 NO.285>>286
1298>>284
1299>"We spend most of our days studying because we enjoy it"
1300>"let's go deface a website because it's easy".
1301It's essentially the same thing. You get real world hacking experience by hacking into real world systems. Jacking off to kevin mitnick and his jewish books won't make you a leet hexer.
1302
1303Selhar 2016-08-05 12:38:12 NO.286>>287>>289
1304>>285
1305If it's easy you're not gaining any knowledge or insight. It's pointless.
1306
1307Neuromancer 2016-08-05 12:58:49 NO.287>>288
1308>>286
1309Repetitio mater studiorum est
1310
1311Selhar 2016-08-05 13:02:22 NO.288>>290
1312>>287
1313I don't really agree with you that hacking is even about that, but again i might not have as much experience as you do.
1314
1315Case 2016-08-05 13:02:42 NO.289
1316>>286
1317>gaining any knowledge or insight. It's pointless.
1318
1319I'm assuming you don't know what XSS is... Being able to see the various XSS vulnerabilities in websites makes you more able to securely build website code.
1320
1321As well, it's more fun and intuitive than reading a book. That's probably why he wrote that it's 'easy'
1322
1323He didn't mean easy he meant fun.
1324
1325Leto Atreides I 2016-08-05 13:04:44 NO.290>>291
1326>>288
1327What is hacking about then? Is it about hacking into systems or something else? Curious desu senpai
1328
1329Selhar 2016-08-05 13:07:35 NO.291>>292
1330>>290
1331Changing the intended purpose of a thing (usually software), making things more efficient than people thought they could be, finding vulnerabilities that have not yet been found, making things that shouldn't work, work.
1332
1333Dozer 2016-08-05 13:14:05 NO.292>>293
1334>>291
1335Well yeah, that's the neckberd definition that GNU enforces... Mostly so they could refer to each other as hackers without being grouped in with computer criminals.
1336
1337The hacking thread you are in now (and hacking as an international scene) are about breaking computer security, it could be via 0days or conventional, well researched ways. It can be about real life systems and networks or CTFs and simulated ones, but the idea is the same.
1338
1339>finding vulnerabilities that have not yet been found
1340is hacking, but hacking is not just
1341>finding vulnerabilities that have not yet been found
1342
1343'hacking' is the general idea of getting into digital places you aren't supposed to get into.
1344
1345Selhar 2016-08-05 13:19:57 NO.293>>294
1346>>292
1347I see. Either way, there is a clear distinction between groups that only deface a system and groups who are able to get inside a system.
1348
1349Here in Brazil, for example, there are tons of "hackers" that couldn't create a fizzbuzz if you asked them. They just watch a youtube video about how to deface a wordpress page and then do it and call themselves "anonymous".
1350That is the distinction i wanted to make between defacers and hackers.
1351
1352Case 2016-08-05 13:28:06 NO.294
1353File: 1470403686020.GIF (1.27 MB, 154x110, 7:5, Hann_ani.gif) IMGOPS IQDB
1354
1355>>293
1356There are good groups from BR too. I remember SL & EllyEl8 (xero pretending to be little girl or some gay shit like that) hacking into Hann's box a couple of times. It was pretty bueno ownage.
1357
1358Pic related kek
1359
1360Lady Jessica 2016-08-05 13:28:13 NO.295
1361>>283
1362>Seems like nobody itt but you can actually hack.
1363Nah. I figure the people who are sure they know the answer do what I did when I first saw it and not say anything because they don't want to ruin it for others.
1364
1365Marly Krushkhova 2016-08-05 17:40:22 NO.296>>302
1366File: 1470418822840.PNG (153.31 KB, 410x400, 41:40, world_wide_web.png) IMGOPS IQDB
1367
1368How about that new HTTPS vuln?
1369
1370HTTP://ARSTECHNICA.COM/SECURITY/2016/08/NEW-ATTACK-STEALS-SSNS-E-MAIL-ADDRESSES-AND-MORE-FROM-HTTPS-PAGES/
1371
1372Pulse 2016-08-05 19:19:12 NO.297>>298
1373Snowden just tweetet a huge hexa, anyone know what's up?
1374
1375HTTPS://TWITTER.COM/SNOWDEN/STATUS/761641490246283264
1376
1377Linda Lee 2016-08-05 19:42:28 NO.298>>299
1378>>297
1379broken link, anon
1380
1381Trinity 2016-08-05 19:46:14 NO.299>>300>>327
1382File: 1470426374915.PNG (10.56 KB, 580x84, 145:21, mGEHb0v.png) IMGOPS IQDB
1383
1384>>298
1385He deleted it. Here's a print.
1386
1387Splicer 2016-08-05 19:53:21 NO.300>>301>>303
1388>>299
1389alright, i'll risk the ridicule.
1390
1391what's the point of publicly posting hashes like this? to encrypt proof of something and post it later? obfuscated communication?
1392
1393Faye Valentine 2016-08-05 20:00:27 NO.301
1394>>300
1395I've no idea.
1396
1397Wintermute 2016-08-05 20:04:43 NO.302>>304
1398>>296
1399Known plaintext vulns are old as fuck in the area of crypto. Nothing to see here, people.
1400
1401Liet-Kynes 2016-08-05 23:01:39 NO.303
1402>>300
1403
1404to claim authorship of an upcoming leak. Or to demonstrate that you're in posession of something for leverage.
1405
1406I.e.: You steal a notable hacker's photolibrary and your aim is to blackmail them. You publish the hashes of all the pictures in that library. The hacker then will realize (either through an auxiliary channel or through the same blind post method) that his identity is compromised.
1407
1408Then you are free to make your demands or make the point known that you have leverage over that individual.
1409
1410
1411Also, hashes are used often in hashed based content addressing systems like ipfs/dht. So he might be publishing a file that exists on one of those file distribution methods. Or it could be a key hash.
1412
1413One can also pick which protocol (M.O. specific to opsec or OTP list by selecting the list by nickname + salt). And the salt can be agreed to change with time and our sequence.
1414
1415Trinity 2016-08-05 23:02:47 NO.304
1416>>302
1417
1418The idea of known plaintext attacks are known in /general/, but are highly specific to the protocol. So no there's plenty to see here. Especially if this were to effect Diffie Helman Ephemeral keys.
1419
1420Selhar 2016-08-06 00:42:06 NO.305>>306>>307
1421What are you guys currently studying?
1422
1423BloodCat 2016-08-06 04:59:40 NO.306
1424>>305
1425>>305
1426Currently I am studying router firmware that is not traditionally susceptible to WPS pixie attacks and attempt to narrow down places where the generation of entropy is misused. Then make them available to auditing through pixie wps
1427
1428Nell 2016-08-06 22:32:45 NO.307
1429>>305
1430Trying to find a decent resource to learn MySQL.
1431
1432Lain Iwakura 2016-08-06 23:43:50 NO.308>>309>>315>>316
1433Would anyone be interested in a get together, tomorrow?
1434
1435We could all download a machine from vulnhub and try to attack it, and help each other out on a irc chat.
1436
1437Would that sound intresting?
1438
1439Faye Valentine 2016-08-06 23:50:06 NO.309>>310
1440>>308
1441Are most people from this board/chan in a specific city? I always see threads about going out together.
1442
1443HELIOS 2016-08-06 23:58:49 NO.310>>311
1444>>309
1445No, i mean we would all set it up locally, then we would talk on a irc room!
1446
1447each person would set up a lab
1448HTTPS://WWW.VULNHUB.COM/LAB/
1449all agree on a machine to download locally and attack.
1450
1451we would meet in a IRC room to talk and help each other out!
1452
1453Roy Batty 2016-08-07 00:05:39 NO.311>>312
1454>>310
1455Oh, i see. I'd love to go but i don't really have the experience for that yet. Good luck though!
1456
1457Alice Miyuki 2016-08-07 00:11:24 NO.312>>313
1458>>311
1459That's the thing though! WE would HELP each other! people don't get started or quit half way through, but when they have a mentor or a group to help them they're much more likely to a) finish b) get better faster!
1460
1461Shogun 2016-08-07 00:13:31 NO.313>>314
1462>>312
1463Well, sure, i could get together. I'm still studying assembly and C, i've worked a few years with java but i wouldn't even know how to begin an attack.
1464If anything i'll just watch.
1465
1466Tequila 2016-08-07 00:19:42 NO.314
1467>>313
1468We will start something easy!
1469It's not like we are going to just start off with bsd Locked down with ipfw or anything,
1470
1471Neo 2016-08-07 00:46:19 NO.315
1472>>308
1473Sounds fun.
1474
1475Mentat 2016-08-07 05:05:11 NO.316>>318
1476File: 1470546311289.JPG (748.53 KB, 1536x1152, 4:3, 6c16a50b02dc4272a5130fbc67….jpg) IMGOPS EXIF IQDB
1477
1478>>308
1479Around what time are you thinking?
1480
1481Shogun 2016-08-07 13:47:37 NO.317
1482For anyone learning assembly "Programming from the ground up" is a great introduction to computer architecture and assembly.
1483It assumes you don't even know how to code in any language.
1484
1485Technician 2016-08-07 14:21:31 NO.318>>319>>320
1486>>316
1487I set up the IRC
1488irc.rizon.net
1489#LainHackGen
1490default port
1491
1492Agent Richard Gill 2016-08-07 14:21:58 NO.319
1493>>318
1494forgot to add I will be in pretty much all day!
1495
1496Crash Override 2016-08-07 15:53:58 NO.320>>321
1497>>318
1498>rizon
1499lolcan'tjoin
1500
1501CUTTER 2016-08-07 15:56:20 NO.321>>322
1502>>320
1503Why not?
1504
1505Spike Spiegel 2016-08-07 15:59:39 NO.322>>323
1506>>321
1507blocks tor
1508
1509THE FIN 2016-08-07 16:04:53 NO.323>>324>>327
1510>>322
1511Just use pidgin behind a proxy
1512
1513Lady 3Jane.. 2016-08-07 16:06:32 NO.324>>325
1514>>323
1515>behind a proxy
1516I've got a list of 50k socks proxies, about 50% done, all blocked so far. This might take a while.
1517
1518Dr. X 2016-08-07 16:24:15 NO.325
1519>>324
1520Are you checking both version 4 and 5 of the socks protocol
1521
1522Marly Krushkhova 2016-08-07 22:00:33 NO.326
1523File: 1470607233289.PNG (92.67 KB, 1363x213, 1363:213, 2bSNPQ7.png) IMGOPS IQDB
1524
1525The fuck
1526
1527d8a 2016-08-09 00:10:45 NO.327
1528>>323
1529
1530Yeah, that's not safe or anon. There's plenty of IRCs with tor hidden services. Here's one: HTTPS://CYBERGUERRILLA.INFO/WAYS-TO-CONNECT-TO-CYBERGUERRILLA-IRC/
1531
1532>>299 Probably an md5 checksum for a file he sent to someone that he did not want to link directly to the checksum. Once the end user confirmed the complete uncorrupted xfer of the file, they deleted the checksum.
1533
1534Emmanuel 2016-08-09 22:38:09 NO.328>>329>>330
1535I'm studying like a motherfucker. Networks, security, C++, C, Assembly etc.. I really love this stuff, not only security but the whole low level optimization/elegant software development.
1536
1537But how can i make money out of that?
1538I mean sure it's great to be good at something, but i had really serious psycological problems working at a company (fullstack dev) before, and i don't see many remote options in the infosec area.
1539
1540Any lainons here make money remotely? How do you do it, freelancing? Bug bounties?
1541
1542Don't seem like i could pay the bills with bug bounties for example. Not consistently at least.
1543
1544Morpheus 2016-08-09 22:41:40 NO.329
1545>>328
1546u should just marry me instead
1547
1548Dr. X 2016-08-10 12:50:33 NO.330>>331>>332
1549>>328
1550just spam and seo for ad revenue. you can make a lot of money, if you are good at what you do
1551
1552Terzibashjian 2016-08-10 13:00:21 NO.331>>341
1553>>330
1554That isn't websec, my question is how to make money in a websec position. I could just freelance as a webdesigner to make a few bucks to buy food, it's what i do right now, but i don't wanna do that stuff for long.
1555
1556Sabo Engle 2016-08-10 15:04:58 NO.332>>334
1557>>330
1558
1559how would one do that?
1560
1561Dozer 2016-08-10 23:23:55 NO.333
1562HTTPS://WWW.COURSERA.ORG/LEARN/BUILD-A-COMPUTER
1563
1564Seems like a good course. You learn how to create a SO from scratch, it's free, just go to "preview course"
1565
1566Molly Millions 2016-08-11 01:36:17 NO.334>>336
1567>>332
1568e-whoring is pretty good, ask for money from desperate people, if you don't mind hurting peoples feeling you can get alot and most police agencies would laugh if they tried to report you
1569
1570Case 2016-08-11 01:39:26 NO.335>>337
1571pastebin of resources from /r/how_to_hack
1572HTTP://PASTEBIN.COM/Z71WQ9JY
1573
1574Turner 2016-08-11 03:23:13 NO.336>>358
1575>>334
1576Not only is that really fucked up, i can't see how that can be related to hacking in any way.
1577
1578BloodCat 2016-08-11 04:05:37 NO.337>>338
1579>>335
1580Hey, thanks. There's a lot of good material in there. There's a magnetic link for a shit ton of books from IT books, now that it's dead, it'd be good if people seeded it.
1581
1582magnet:?xt=urn:btih:c09013f19e37e8aae5465565fd1b266931179c44&dn=The%20Ultimate%20IT%20Ebooks%20Collection%20-%201800%2b%20IT%20and%20Computer%20Science%20Ebooks%20from%20http_%e2%81%84%e2%81%84it-ebooks.info
1583
1584Wintermute 2016-08-11 04:07:23 NO.338>>339
1585>>337
1586Holy shit it books is back, just checked it.
1587HTTP://IT-EBOOKS.INFO/
1588
158988 2016-08-11 05:01:25 NO.339>>340
1590>>338
1591
1592Holy shit dude. Thank you for this link. Is there a way to download all of the books, or are we talking hundreds of books in this site?
1593
1594Do you have any recommendations to download? Other than me downloading some more books on other languages.
1595
1596Another thing - are there any other forums/boards/IRC that you guys frequent, that seem to be somewhat active? I've tried several different channels but with no real luck. I've also tried the Defcon groups, but a lot of the cities surrounding me are deader than a doornail.
1597
1598Eldon Tyrell 2016-08-11 06:49:57 NO.340
1599>>339
1600I just posted a magnetic link for 1800 books from it books, i'm pretty sure it's not all of them, but it's a huge chunk.
1601
1602And the recommendations depends on what you wanna do really, i'd recommend downloading /g/entooman's library if you want a collection. If you're into hacking, you should learn assembly, c and c++, then network.
1603
1604A good starting point is the book "Programming from the ground up" for assembly, "The C programming language, 2nd edition" for C, and "The C++ programming language, 4th edition" for c++. While you read those books you can watch cybrary's A+ course.
1605
1606After that you should have a better understanding of the field and an idea of where to go.
1607
1608I'm not a part of any irc channel, can't help with that.
1609
1610Netrunner 2016-08-11 07:20:30 NO.341>>342
1611>>331
1612Making money the blackhat way isn't just one thing, because you never know what you can find on servers. Not all of them have a ready btc wallet you can steal, instead you have to think outside of the box a little. You can sell the roots, or sell the box as-is to drive-by exploit hosters. Grabbing the accounts, testing for password reuse in other services and selling the accounts for example netflix work too.
1613
1614J.C. Denton 2016-08-11 07:27:48 NO.342>>343
1615>>341
1616But this thread isn't about that, dude. If you have to do stuff that isn't related to the point of this thread, then it's not really relevant isn't it?
1617
1618Hacking mentality can be applied to even sex, but we shouldn't be talking about sex here.
1619
1620Tequila 2016-08-11 07:36:24 NO.343>>344>>347
1621>>342
1622>But this thread isn't about that, dude.
1623Oh, I thought this was a
1624>Hacking General
1625
1626If you wanna follow your passion on the whitehat path, you can do what thousands of others are doing right now. Get a small crew together with various skills start your own firm and wait for pentesting offers.
1627
1628Then starve to death because nobody will hire you over the 100 already established, well known firms.
1629
1630Lady 3Jane.. 2016-08-11 13:20:37 NO.344>>345
1631>>343
1632I apologize, i thought you were the one talking about "manipulating people to get money" in the most generic possible way.
1633
1634I'm not looking for anything blackhack though, i'm asking how i can make reliable money, stealing is hardly reliable to pay montly bills and buy food.
1635
1636Bobby Newmark 2016-08-11 17:11:11 NO.345>>346
1637>>344
1638The whitehat side of things is pretty dry of money atm, unless you are going to do bug bounties. They are not really what you'd call a reliable source of income either.
1639
1640You can make reliable bucks via blackhat methods, mostly by things related to CCs and money transfers, but you need reliable contacts and a lot of hard work to actually build and manage your botnet empire.
1641
1642If you want to ditch the "security" aspect and focus on "anything computer related" though, you can find lots of gigs doing freelance programming. The gigs might not be that interesting, as they are usually about "write this specific part of the program/library", but they can keep you fed.
1643
1644I do ad stuff, PTC and CPA things, they can get you decent cash, but they need to be handled like a full time job instead of a neat little side project.
1645
1646Donna Hawthorne 2016-08-11 17:44:40 NO.346
1647>>345
1648Yeah, right now i'm freelancing for whatever people pay me to do (make a page out of a CVS file, setup or fix a wordpress page, etc..). But this kind of work is really draining me, i don't like front end and it's a horrible chore.
1649
1650Security doesn't seem to be viable as a profession for a remote worker though, so i might try to land a remote software engineer job, while it's not ideal, it's better than what i do right now. Thanks for your info though.
1651
1652Joey 2016-08-11 18:40:11 NO.347
1653>>343
1654>Then starve to death because nobody will hire you over the 100 already established, well known firms.
1655Then you ought to make a name for yourself and your firm , if you dig what I mean
1656 *wink* *wink* *nudge* *nudge*
1657
1658Masami Eiri 2016-08-11 19:45:44 NO.348>>349
1659File: 1470944744351.PNG (46.77 KB, 150x150, 1:1, 1470599731730.png) IMGOPS IQDB
1660
1661I'm learning assembly right now and i feel dumb as fuck. I'm not asking for more resources, i have plenty, i'm just frustated i guess.
1662
1663I was keeping up with the book i'm reading (programming from the ground up with assembly x86), but when i reached functions holy shit i'm lost as fuck.
1664
1665Sure if i read the code line by line i'll be able to understand what i does, but in no way would i be able to create a simple function in assembly. What the fuck man..
1666
1667BloodCat 2016-08-11 21:39:58 NO.349>>350
1668>>348
1669if you've been keeping up you shouldn't have an issue with functions.
1670
1671Drifter 2016-08-11 22:04:44 NO.350
1672>>349
1673He's using a C standard for stack calling, it's not just the random declaration of a function. It's getting clearer now, but just the fact that it took me a whole day to get it right is pretty disappointing.
1674
1675Netrunner 2016-08-11 22:43:20 NO.351>>352
1676Hey, can someone clarify something for me regarding x86 assembly programming?
1677
1678If i do pushl %ebp, the contents of %ebp will be both at the %ebp register and at the top of the stack in memory, correct? And if i override %ebp i just have to refer to %esp whenever i wish to retrieve the previous value of %ebp, correct? Of course i can override %esp too, but what i'm trying to get to is that the same information will be at different parts of the computer at once (a memory location and a register). Is that assumption correct?
1679
1680Also, the stack is a place in memory where i keep temporary information about a function, right? It's a place in memory just like a variable, except it follows different rules and has a different purpose, but essentially it's a place where i will put (specific) stuff, and then retrieve it, except that the system expects me to follow certain rules otherwise it won't be able to work(go back to who called a specific stack frame), correct?
1681
1682Masami Eiri 2016-08-11 23:51:29 NO.352>>353
1683>>351
1684>the same information will be at different parts of the computer at once (a memory location and a register). Is that assumption correct?
1685yes, push is like a mov, except it also moves the stack pointer to point to the value most recently pushed
1686
1687>Also, the stack is a place in memory where i keep temporary information about a function, right?
1688the stack is where you keep variables
1689if you want dynamic memory allocation use a heap manager.
1690you're wrong in thinking that there are any rules imposed by the architecture itself.
1691the operating system might however prevent you from accessing memory in certain pages for example, for security reasons.
1692
1693Pris 2016-08-12 00:29:31 NO.353>>354
1694>>352
1695>you're wrong in thinking that there are any rules imposed by the architecture itself.
1696Not directly, but if i don't have the return value of my stack frame, i won't be able to go back to whatever function called me right? It's not a physical rule, but i have to "agree with it", don't i?
1697Thanks a lot for the info, it helped a lot.
1698
1699Shogun 2016-08-12 00:40:13 NO.354
1700>>353
1701if you use call to call a function, the return address will be automatically added to the top of the stack.
1702you can return to that address with ret at any point as long as the pointer is at the top of the stack
1703but yeah, like if you shrink the stack or overwrite that value you'll probably be in trouble
1704
1705Lord Nikon 2016-08-12 04:43:48 NO.355
1706HTTP://WWW.ALLITEBOOKS.COM/
1707Bunch of books.
1708HTTPS://WWW.HACKTHISSITE.ORG/PAGES/PROGRAMS/PROGRAMS.PHP
1709Bunch of links.
1710
1711Project 2501 2016-08-12 12:53:22 NO.356
1712First time posting, hopefully this is the first time this is posted here, here are a bunch of e-books :)
1713
1714HTTPS://DOC.LAGOUT.ORG/
1715
1716Marly Krushkhova 2016-08-13 13:38:31 NO.357
1717File: 1471095511515.PNG (85.31 KB, 1593x360, 177:40, B9MG8ac.png) IMGOPS IQDB
1718
1719Is "The C programming language" really this poorly written, or did i download an unrevised version? I've seen some pretty sloppy code examples too, with poorly named variables that don't do anything, a bunch of expressions in a single line, etc..
1720
1721Splicer 2016-08-13 16:08:35 NO.358
1722>>336
1723It's just another form of spam and spread virus,
1724
1725Marly Krushkhova 2016-08-13 17:38:35 NO.359
1726Fowking hell m8, since when did drupal update their password hashing policy? I'm getting 1639 H/s on a single hash.
1727
1728Kill me now desu senpai.
1729
1730Saint Cipher 2016-08-13 20:16:19 NO.360>>361>>362
1731File: 1471119379366.PNG (173.13 KB, 500x548, 125:137, anime-beautiful-cute-girl-….png) IMGOPS IQDB
1732
1733So I just started some of Cybrary's classes, and as a fledgling programmer that's self-taught I know I got some holes in my knowledge. Information security is something I have become actively interested in, so I started shit from the ground up.
1734
1735I'm starting with CompTIA A+ and I am noticing the lectures are really, really short. I'm assuming that Cybrary's resources are more overviews (as well as some of these classes) for more thorough resources?
1736
1737Reason I ask this is that when I compared Cybrary's course to CompTIA versus the actual book (~1200 pages) and people telling me they studied for months, I am feeling it can't possibly that easy to pass. Unless I'm just realizing I know a lot it's already talking about?
1738
1739Anyway, just looking to actually learn, but be proficient with my knowledge, than base overviews. Any suggestions would be aaaaaaace.
1740
1741Trinity 2016-08-13 22:27:48 NO.361
1742>>360
1743ComptiA has 43 hours of material. You can read 1200 pages in far less than 43 hours.
1744
1745I watched all comptiA classes, but i've never had any interest in certifications (since i don't have the cash for that). There was some bullshit, but overall the first half of the classes were great.
1746
1747I wouldn't recommend you to study just from there though, try to study 2, 3 or as many subjects as you can at the same time, otherwise you will likely be bored or frustated when you hit a tough/uninteresting subject.
1748
1749Good luck.
1750
1751Hagbard Celine 2016-08-14 01:35:34 NO.362
1752>>360
1753A+ is trivially easy. This will not be like anything you learned at school. A+ is mostly about memorizing details, only in the networking portions does it become in anyway theoretical. The reason why the lectures are so short is because, in addition to the simplicity of A+, the course is meant to be supplemented with your own study. This may include going over recommended reading material, finding a checklist of exam topics and if you're cheeky, going over brain-dumps.
1754
1755Personally, unless you actually want the cert for employment or extra credits in a course (and there is nothing wrong with that). You may just want to do the cybrary side of things because A+ is quite mind numbing and will set you back nearly $200 for the actual exam.
1756
1757I recently took the CCNA course at cybrary, and I am still studying but, cybrary was a great starting point. From memory the course materials tab will have a bunch of text books which you may wish to "acquire" should you want to attempt the exam. >>360
1758
1759Armitage 2016-08-14 13:13:13 NO.363>>364
1760Is this thread in autosage?
1761
1762Meddler 2016-08-14 13:13:44 NO.364
1763>>363
1764It is. What's up with that?
1765
1766Molly Millions 2016-08-14 15:59:05 NO.365>>366>>367
1767At what point do you guys join wargames and puzzles? I've been studying C,C++ and assembly for a while and i've worked for over a year with front end dev.
1768I tried doing hackthissite's first tutorial, it only asks you to know HTML, yet i have no idea how to bypass it. 0 clue.
1769I'm not asking for answers, as that would defeat the whole purpose of a puzzle, but what should i study? Are there any books, courses or introductions you guys have done previously that helped you crack these challenges?
1770
1771Ein 2016-08-14 19:14:47 NO.366
1772>>365
1773We had setup a IRC channel, rizon #lainhackgen
1774That being said, hackthissite challenges answers and clues are in the forums and are probably much better
1775
1776That being said, we setup the #lainhackgen was to work together to break into machines and help eachother get better but hasn't really caught on
1777
1778(also sleepz if your lurking, i beat that vm, thanks for the hand!)
1779
1780Trinity 2016-08-14 19:20:12 NO.367>>368
1781>>365
1782>At what point do you guys join wargames and puzzles?
1783ASAP, they're wargames for everyone, and you will never know every little thing, and the best way to learn is in a wargame that way you can apply it!
1784> Are there any books, courses or introductions you guys have done previously that helped you crack these challenges?
1785I do enumeration and see what exploit / vulns / etc. Are out there to test out.
1786
1787The most important advice is DONT GIVE UP.
1788
1789Ein 2016-08-14 20:40:49 NO.368>>369
1790>>367
1791I'm not giving up, but i just found out MIT'S free course on computer science. I'll be doing that alongside cybrary, i always wanted to have a proper, solid foundation on programming and computer science.
1792I study a lot so it shouldn't take more than a month or two for me to finish the whole course. Thanks a lot for your help by the way.
1793
1794Cat Mother 2016-08-14 23:11:56 NO.369
1795>>368
1796By the way, their course is insanely great. They teach eletronic engineering plus computer science. All the material and exercises are provided for you.
1797
1798Case 2016-08-15 14:07:46 NO.370
1799Linux course from linux foundation.
1800
1801HTTPS://WWW.EDX.ORG/COURSE/INTRODUCTION-LINUX-LINUXFOUNDATIONX-LFS101X-0
1802
1803Bobby Newmark 2016-08-15 22:09:10 NO.371>>372>>400
1804>>109 (OP)
1805what are some useful methods of obscuring your location? use a box you've already compromised? pay for a vpn (seems untrustworthy)? utilize tor and friends?
1806
1807Cowboy 2016-08-17 17:10:01 NO.372
1808>>371
1809>use a box you've already compromised? pay for a vpn (seems untrustworthy)? utilize tor and friends?
1810These are all good things
1811If you use a vpn make sure x doesn't have access to it, Not that i would know or anything.
1812
1813You Know, The Farmer 2016-08-19 05:43:38 NO.400
1814>>371
1815Well, I will share how exploit kits like angler are usually employed.
1816
1817Typically the EK will be served/controlled from a compromised wordpress, hopefully in a legally difficult country. The real command and control will come via tor communications with this compromised site.
1818
1819Sometimes people develop very long chains of proxies, and vary up the exact chain on a week to week basis, just to evade analysis.
1820
1821Keep in mind, somehow someone has to make a direct attack on the original server, as serving many exploits over tor is a huge pain in the ass. Not saying people don't do it, but it's a huge pain in the ass and easy to fuck up.
1822
1823Criminal groups (like those running angler) get away with the initial break in by having already established groups of compromised computers in legally obscure zones, where getting forensics teams in is a no go.
1824
1825Also, I might add that any server that has an easy to use wordpress exploit is almost guaranteed to be infected with this sort of shit. There are bots that scan the entire ip4 range just looking for shitty wordpress installs.
1826
1827I have rambled too long.
1828
1829J.C. Denton 2016-08-22 14:38:07 NO.599
1830
1831How would you go about dumping the users of a mysql server?
1832
1833I found an injection point but I lack the privileges to access the user table.
1834
1835How is this normally done? Should I look for exploits for that specific mysql version or can it be done with injections alone?
1836
1837Armitage 2016-08-23 15:09:13 NO.643
1838Hi lainons, I'm want to buy a tp-link tl-wn722n for pentesting wireless routers.
1839I want to know your opinion ( it supports packet injection and monitor mode, so the aircrack-ng suite will work )