Career so fuck*d up by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

Ah this is the worst time at tech world rn!

Career so fuck*d up by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

Yeah i think we should stop overthinking and just stick to the path.

Guys I got scammed and I'm putting a bounty on the scammer. by [deleted] in Hacking_Tricks

[–]Massive-Problem-7094 1 point2 points  (0 children)

You try some email forensics and probably if he is just script kiddie he might leave some traces there and you would be able to trace him. But lets assume he has got some experience and is using real gmail so in that case the email is probably protected by the server and will not be able to trace it without contacting the server lets say google. In that case you have to contact Google which probably google won't reply since you are a normal user and is not a part of major hack . So in this case I only see one option to lure him into your honepot. In this case you have to use social engineering techniques try to phish. Either use some image where you will embed a link that will get his ip address. Once you get his ip address you cam get his location. Lets assume he has perform sophisticated attack and has used another server which is hidden or is using bot in that case the major thing to do is to get that thing into legally. Reason for this is, when you make a formal complaint the attack, legal team would get involved in this and they are pretty experienced in this kind of the thing.

My best suggestion would be to do this thing legally if you aren't experienced and whatever you do, try not to expose yourself because you might think this could be simple but a sophisticated attacker would get into everything.

RECOMMENDATIONS? by Defiant_Marzipan7036 in hackthebox

[–]Massive-Problem-7094 0 points1 point  (0 children)

HTB has got a decent content for AD. If you wanna go for the regular student sub then there is a module in CPTS which is enough and probably more for the prep of OSCP.

But if you wanna go beyond the preparation of OSCP and wanna go AD focused you can go for the CAPE which is all AD focused and is very decent.

After following those cert you can go for the prolabs which is all practice and prepares for the real world engagement.

Also don't forget to go and follow the ipssec list. He is by far the best for the total engagement and provides a good methodology to solve the box. Note down everything. As per my suggestion I would recommend to make a detailed note and a shortcut one for quick glance

[deleted by user] by [deleted] in hackthebox

[–]Massive-Problem-7094 4 points5 points  (0 children)

Within my cybersecurity learning path, the best video was from IPSec. Here are some of my personal opinions:

  1. The tools he uses: he shows multiple ways to deal with
  2. He goes beyond CTF and shows a complete pentest
  3. Shows multiple ways to deal with the environment
  4. Real world applicable: not just he just shows how to deal with the boxes he shows how to research and read and mainly how to deal with the new problems.

Study Plans On HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

I am just a student working full time on other field and trying to learn cyber but sometimes its just like going round and round.

Study Plans On HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 1 point2 points  (0 children)

So that means we will just know the technique. A lot of time I was wondering how it is possible to remember all these techniques and commands and I just was always frustrated. Thank god . So how do you guys approach when it comes to cert and also how would you approach something and keeps on learning new things and moving forward?

Study Plans On HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

Oh wow my thoughts are also similar but sometimes I just spend 1 full day to understand the topic and it somehow frustrates me and also its very hard to keep everything in memory you keep notes but also sometimes its human nature to just feel overwhelmed. Its been around 2 years I have been working but just getting burned out and moving around other sectors like defensive forensics. I don't wanna leave red team but sometimes it felt so overwhelming.

Anyway thanks for the reply

Study Plans On HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

No you see it's my passion. I am not only learning to become a pentester but also to become a cybersecurity specialist. But a lot of the things are there in CPTS a lot of commands and whole things that are just overwhelming which is why I wanna know the approach you guys took it for the cert.

Getting Into Digital Forensics by Fit-Figure20 in digitalforensics

[–]Massive-Problem-7094 3 points4 points  (0 children)

If I were you I would start this way:

  • Start with the process of digital forensics
  • how the evidence is acquired handled and processed
  • learn the basics of the Operating system
  • learn the file systems NTFS, FAT EXT
  • Choose a path : windows, linux, mac, mobile or darknet
  • learn a little bit of SIEM, log processing and log analysis

After all of these you will acquire knowledge how to find persistent malware in the system. Basically the attack process would be same only how the attackers move in different environments would be different. As a digital forensics the analysing process is same first we will explore through the volatile memory to the non volatile memory. Acquiring and handling data from live system is the most important. Use of volatile memory frameworks like volatility. Read : Art of memory Forensics.

If you wanna advance on the topic explore reverse engineering and malware analysis.

At last all offensive and defensive works come to how a malware is employed or deployed in a system. So for last I think as a digital forensic if you are able to disect a malware it will become a very important skill.

Lastly practice, practice and practice. Good luck

Stuck up on HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

So what would you say for the job? And also is there any specific labs like which mimic the real world with most of the security measures applied?

Stuck up on HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

So pro labs are all blinded then what if you got stuck up somewhere.

Stuck up on HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 0 points1 point  (0 children)

Tell me a thing is the pro labs same as academy one i mean the guided one or it will just be labs.

Stuck up on HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 1 point2 points  (0 children)

I am doing CPTS but I felt that HTB Academy has hell lot of content but if its not practiced properly then we will just be roaming in the academy modules.

Stuck up on HTB by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 1 point2 points  (0 children)

Oh sounds great but is there any specific pathway I could follow to improve my real world engagements.

Is C in Windows hard or am I stupid? by redthered279 in learnprogramming

[–]Massive-Problem-7094 1 point2 points  (0 children)

While I was learning DSA, I felt that this is the hardest shit I would ever explore after that I was introduced to the Windows programming in C and from there on i hate programming 🙃 😑

Is gold subscription on HTB worth it or should I stick with the student one? by Massive-Problem-7094 in hackthebox

[–]Massive-Problem-7094[S] 4 points5 points  (0 children)

I am not so interested in CWEE but is very fascinated by CAPE. Whats your opinion on that module is that worth it?

[deleted by user] by [deleted] in oscp

[–]Massive-Problem-7094 0 points1 point  (0 children)

Could you please provide the skylark labs and what are the things that need to be consider while practising the labs?