/cyb/ + /sec/ - CYBERPUNK/CYBERSECURITY GENERAL

Previous threads: [ archive.rebeccablacktech.com/g/search/text//cyb/ /sec//type/op/ ]
THE CYPHERPUNK MANIFESTO: [ activism.net/cypherpunk/manifesto.html ]
Last thread: []
- - - - - -
/cyb/erpunk [24 AUG 2019]
The Cyberpunk Manifesto: [ project.cyberpunk.ru/idb/cyberpunk_manifesto.html ]
The alt.cyberpunk FAQ (V5.27) [ ftp://50.31.112.231/pub/Alt_Cyberpunk_FAQ_V5_preview27.htm ]
What is cyberpunk?: [ pastebin.com/pmn9vzWZ ]
Cyberpunk directory (Communities/IRC and other resources): [ pastebin.com/AJYry5NH ]
Cyberpunk media (Recommended cyberpunk fiction): [ pastebin.com/Dqfa6uXx ]
The cyberdeck: [ pastebin.com/7fE4BVBg ]
- - - - - -
/sec/urity [24 AUG 2019]
The Crypto Anarchist Manifesto: [ activism.net/cypherpunk/crypto-anarchy.html ]
The Hacker Manifesto: [ phrack.org/issues/7/3.html ]
The Guerilla Open Access Manifesto: [ archive.org/stream/GuerillaOpenAccessManifesto/Goamjuly2008_djvu.txt ]
The /sec/ Career FAQ (V1.11) [ ftp://50.31.112.231/pub/sec_FAQ_V1_Preview11.htm ]
Why Privacy Matters: [ youtube.com/watch?v=pcSlowAhvUk ]
"Shit just got real": [ pastebin.com/rqrLK6X0 ]
Cybersecurity basics and armory: [ pastebin.com/v8Mr2k95 ]
Endware: [ endchan.xyz/os/res/32.html ]
BBS archives: [ textfiles.com/index.html ]
Reference books (PW: ABD52oM8T1fghmY0): [ mega.nz/#F!YigVhZCZ!RznVxTiA0iN-N6Ps01pEJw ]
/sec/ PDFs: [ mega.nz/#F!zGJT1QQQ!O-8yiH845GN26ajAvkoLkA ]
Learning/News/CTFs: [ pastebin.com/WQhRYB59 ]
FTP Backup: ftp://50.31.112.231/pub
thegrugq OPSEC: [ grugq.github.io/ ]
#! sec guide [ pastebin.com/aPr5R1pj ]
EFF anti-surveillance [ ssd.eff.org/en ]
- - - - - -
Thread challenge: write a program to find credentials in local files. /bin/sh, powershell, WSH, python, perl, .net, C/C++, doesn't matter. Post source.

Attached: cybsec reloaded.gif (400x440, 683K)

Other urls found in this thread:

malwaretech.com/2019/08/dejablue-analyzing-a-rdp-heap-overflow.html
linkedin.com/pulse/data-breach-2015-2019-carlos-carrasco/
stallman.org/
drewdevault.com/
mega.nz/#F!zGJT1QQQ!O-8yiH845GN26ajAvkoLkA
about.riot.im
riot.im/app/
gamozolabs.github.io/metrology/2019/08/19/sushi_roll.html
youtube.com/watch?v=J0vjAB0Fa_g
ndss-symposium.org/wp-content/uploads/2018/03/NDSS2018_02A-3_Hussain_Slides.pdf
srlabs.de/wp-content/uploads/2010/07/100729.Breaking.GSM_.Privacy.BlackHat1-1.pdf
desuarchive.org/k/thread/42408696/#42409986
par.nsf.gov/servlets/purl/10055689
twitter.com/AnonBabble

How does one cyberpunk?

quick someone cut my arm off

Attached: 2019-08-24_17-06.png (283x503, 56K)

what is some good cyberpunk fashion?

Attached: koller.jpg (820x867, 148K)

Get a pegleg installed.

>credentials
We talking password files, hash lists, or what?
Anything else to look for?

Real cyberpunk wouldn’t merely replace appendages but rather add new ones.

Any user/pass file storage you can think of. Might be fun to download a bunch of random programs and use a virtual machine to figure out how they store creds.

cyberpunk 2019

Attached: cyberpunk.jpg (354x600, 27K)

Any information about creating and maintaining fake social media accounts?

So I guess bump

Wasn't expecting the old thread to die so abruptly.

Matrix users, join #cyber:halogen.city. Especially if you're from 8ch /cyber/.

Attached: 1675070833_5ec1a17a0f_o.jpg (1024x988, 694K)

malwaretech.com/2019/08/dejablue-analyzing-a-rdp-heap-overflow.html

diffing a windows patch to look for heap overflow information in modern windows. very informative.

Will 8ch's /cyber/ ever come back or can we officially add it to the list of dead cyberpunk communities?

im new please dont clown on me. whats matrix?

The easiest comparison is Discord. Except that with Matrix, you can host it yourself, it supports encryption, and you can federate with other servers. You can access halogen.city with a matrix.org account, for example.

Jim is leaving the site offline until September 5th at the earliest, since he's got to testify about the shootings.

Are these fucking numbers real?
Whos shit has not been fucking leaked?

linkedin.com/pulse/data-breach-2015-2019-carlos-carrasco/

Get tech savvy

Is OSCP or other Offensive certifications worth pursing ? They don't expire after being attained so they seem like a good investment to have for someone looking to work in IT regardless if I wanted to work in security or not

Attached: OSCP.png (1283x697, 124K)

Is kali linux legit for pentesting/greyhat stuff? Any hardware you would recommend like pineapple? I've been messing around with pen testing for about a couple years now, have all the OS tools and typically script kiddie stuff pretty firm, atleqst I think.

OSCP is good if you search on linkedin there's maybe just over 5000 people with it in North America and it more than qualifies you for an entry level security job.

Do you guys know of any actual hacker / programmer blogs worth checking out?

I mean actual personal websites not some faggot's github.

Attached: 1563823822702.jpg (605x718, 221K)

currently drunk and watching Hackers
goddamn cybsec is awesome

hack the planet friendos

Whatcha drinking?

Do you have a download link?

stallman.org/

drewdevault.com/

What VPN is worth it? What isn't a botnet?

unless you have personally read the code and seen the infrastructure yourself assume its a glow in the dark alphabet soup botnet watering hole

Is nofap schway or gay?

MG - mg.lol/blog
notdan - medium.com/@notdan
ippsec - youtube.com/c/ippsec
zer0pwn - zero.lol
Orange Tsai - blog.orange.tw
ThugCrowd - thugcrowd.com

/sec/ PDF collection:

mega.nz/#F!zGJT1QQQ!O-8yiH845GN26ajAvkoLkA

Ive been reading the wiki article about anonimizing yourself. Its something i want to do badly, but there are many things that make me lose faith in being able to do it properly. Im currently using a windows laptop, gmail and outlook for email, youtube and instagram for social media, discord and whatsapp for messaging etc etc. I realize that most of these thing you just need to delete your acc and never use again, but seeing ive used all of them for years will it matter? I am also deathly afraid of losing what little social interactions i have when doing so. Should i just get a separate thinkpad and fully anonimise that, then slowly migrate all the stuff on my windows laptop ?

PLS RESBONG GUYS

Purchase a burner phone only use SMS to keep touch with your friends preferably a flip phone, one that isn't 'smart'. Don't share its number on any social network only in person with those you trust. Don't make calls on it, solder out the microphone. Don't buy laptops on the internet they are tied to your banking information and address. Go to a garage sale or a pawnshop with no cameras at a place as far away as possible from your home town. Look up ways to make home made antennas and either connect to public wifi or aircrack-ng a connection that is at least a few hundred feet away from your home. Don't transfer files to your new devices from old devices.

OK, so what do you call a parrot going "pieces of nine, pieces of nine"?
>cneebgl reebe

the self control you gain from not fapping will give you a little extra confidence in yourself and make you see women differently. i usually nofap for a few weeks then break from crippling loneliness stemming from intense distrust of humans

You mean, nofap is just for going out normalniggers?

gay, just lengthen the period between faps and maintain a healthy distance
no reason not to fap, but no reason to do it too much either

Oh... ok, thanks!

Good to be back. However: There were also a few other things wrong with the pasta, pointed out earlier.

Handily the FAQ tells you how:
ftp://50.31.112.231/pub/Alt_Cyberpunk_FAQ_V5_preview28.htm

Attached: oleg-tsoy-augmented-owl-06.jpg (1200x1200, 194K)

Which easier and cheaper certificate to get to "just" qualify for an entry level job?

Asking for a friend

solarpunk=comfypunk

Attached: buckminster-fuller-architecture-03.jpg (3832x1916, 1.54M)

isnt OSCP cheap already??
Recently took a SANS course, fucking 1.8k euros for the exam.

It was svedka blue raspberry with sprite, it gets you fuct up fast

storing encrypted passwords in the parrot I see

Sure. Riot is the most popular client, since Matrix itself is really just a protocol.

Download here: about.riot.im
Web client here: riot.im/app/

nofap and Christianity are both cyberpunk

So intel has a built in radio to broadcast6 your ideas.

If I bought an laptop with an AMD cpu will I be safe? I'm not doing anything illegal but I am working on some patents and don't want some asshole 3000 miles away to just steal it.

Bump

AMD PSP

Is this the new Hackerman General or did everyone lose interest in that?

I'm looking for the way to handle passwords in web dev, particularly in PHP-MySQL-Postgress.

I know nothing, all I'm told is you shouldn't store passwords on plain texts, but even then I have no clue how to do that.

depends who pays it I think

I want to eradicate 50% of people in this industry and 95% of vendors.

This industry is full of stupid fucking boomers.

whats the best phishing tool out right now

In what aspect? To defend against or run campaigns?

GoPhish if you want to do campaigns. If you want to phish MFA tokens as well use evilnginx

You store a hash of a salted password.

>You store a hash of a salted password.
could you elavorate or give me a solid guide on it?

What don't you understand? Hashing? Salting? Storing text? Literally just Google it. All three of these are incredibly simple.

alright, thanks for the pointers

Importantly, use reputable libraries. Crypto is hard, in fact harder than many think and thus people make errors with devastating consequences.

Debian wanted to do a simple fix and ended up with one of the worst crypto failures in modern history.

Attached: tony-skeor-sing-s-s.jpg (1920x1920, 1.1M)

mind blown, I thought Debian was tight, what should I use instead, is Fedora alright? That's what I know

I mean, I'm new to linux I've literally touched a tiny little bit of ubuntu and a bit more of fedora at school, loved bash, just got one year on it

bumping my shitty thread c'mon over it's fun

I just started reading the Blade Runner novel, is Deckard's wife is a android or something? I don't understand what's the mood organ's for

Page 8 again.

This, but unironically

it's in the op, also always view files like this in a virtual machine guise

should do your research on some arm tablet so google steals your idea instead

debian/nubuntu are fine. i use fedora because it's mature, but people mostly use it because of corporate support.

gamozolabs.github.io/metrology/2019/08/19/sushi_roll.html

This is so cool. Using perf counters to figure out microarchitecture of Intel CPUs.

Hoping to get bumps on my thread

I know what you mean man. Every conference is full of nontechnical boomers making a gorillion dollars selling their GUI on an open source back end

any /crypto/graphy board?

I know ##crypto on freenode but I was looking for something more, any ideas?

cryptography as math not currency shit

can't access /sec/ irc channel on rizon, any tips?

is it normal that #Jow Forumssec is silent?

are remote pentesting jobs a thing?

is being gay cyberpunk

Attached: kisumi-birthday.jpg (530x750, 113K)

I think that's neither cyber, 'cause you are talking about meat, and nor punk as it's mainstream nowadays. Try being yourself.

One of the weirdest things about punk as a concept is that since the left won, the punk thing now is to go right. It's about rebelling against the establishment, a fact that isn't changed by the establishment changing politically.

Attached: new punks.jpg (720x480, 95K)

is it possible to be gay and rebel against the mainstream/establishment

What a fag parade with all of these neckbeards lmao.

not in 2019, now the rebellious thing is being straight and """cis"""

the true punk position is centrist civil libertarian

why can't i hate the government and love getting railed though
youtube.com/watch?v=J0vjAB0Fa_g

>punk thing now is to go right

That is...extremely dubious. There's still plenty to rebel against that isn't left wing (unless you think Ajit Pai was put in place by Obama, but then you have bigger problems than whether the Right is "punk" or not)

Bolsanaro is Right Wing.
Putin is Right Wing.
Trump.
Macrone.


You don't know what you are talking about.

>There's still plenty to rebel against that isn't left wing
Sure. And yet Gen Z is shaping up to be the most conservative generation for a long time. They know what mess they shall inherit.

When it comes to politics, punk is, and has always been on the South side of the political compass with the libertarians as both have relative fondness towards the idea of anarchy. But gatekeeping and arguing about it is stupid. Go be punk however you want; I'm not the fucking cops, and even if I was, that shouldn't stop you.

Attached: v_plays_Cyberpunk_2077.jpg (569x599, 31K)

Recently someone on Jow Forums proposed an interesting attack on LTE networks that would allow you to intercept and view all traffic for a particular device.

>For example, if you want to intercept and monitor cellular traffic for a target, you can combine this paper:


>>LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTE
>ndss-symposium.org/wp-content/uploads/2018/03/NDSS2018_02A-3_Hussain_Slides.pdf
>With this paper
>>Cracking A5/1 Encryption
>srlabs.de/wp-content/uploads/2010/07/100729.Breaking.GSM_.Privacy.BlackHat1-1.pdf

>The attack works by abusing load balancing protocols in LTE networks, which have pretty much zero authentication and are totally open. You can force a handset to migrate to a "lower traffic" tower via a TAUR packet, where it will hand its IMSI. Then you can simply tell it to redirect to an edge network (2g) you control that is running A5/1 via redirectedCarrierInfo. There you go, you not only intercept all traffic, calls, sms going to and from that phone, but you also can track its location to within 1m.

desuarchive.org/k/thread/42408696/#42409986

From reading further into it, it looks like it works by setting up a fake "tower" using weak encryption under your control (perhaps through something like an SDR like the HackRFOne) and tricking nearby devices to connect to your tower.

Would it be possible with a widely available $300 SDR from Amazon, and how can I protect myself from this? Second, would there be a way to locate such fake towers in the event someone is trying this on me?

You might want to look up "ImsI catcher".

But that's for 3G and below. This one is for LTE so it's much more advanced.

I forgot exactly what it is I think its in a companys terms and conditions where they will say you're allowed to pentest their websites / servers only if you report the vulnerability

look dude keep Jow Forumscrap in Jow Forums. those are fascist nazis known as proud bois, not punks.

If you jam the 4G and 5G frequencies, it is likely the phones will go to 3G or below, purely as a fallback position.

That doesn't look like what is going on there. If you read the paper:
par.nsf.gov/servlets/purl/10055689

they specifically describe making a malicious eNodeB using a USB SDR on page 11.

Attached: enodeb.png (444x862, 165K)

OP; did you update the pasta after last few feedback?

The funny thing is that the intellectuals are supposed to be opposing whoever is in power, is nevertheless pro left even when the left is in power. this is quite noticeable in Western Europe.

And what is really happening to the intellectuals these days, are they dead, irrelevant or replaced by the lower end of the chattering classes?

>PB
>nazis
Pick 1 (one)