computerboss

joined 1 year ago
[–] [email protected] 4 points 8 months ago

Ok so to be clear when I said team I mean a bunch of college students preparing for different ctfs, but these are some of the more helpful resources we have found:

Tryhackme: personal favorite especially for beginners Hackthebox: great for learning/practicing attacks Overthewire: another good ctf site

We try to build many of our own ctf like machines, then each person switches their machine with another person and the other person tries to secure the vulnerabilities without knowing anything about the machine. Once everyone has secured their machines we try to attack them using the notes made while setting them up. This is our step by step for that process.

  1. download an old version of a distro. (Ubuntu 14, deb 9, ect)
  2. install and setup the VM without any updates or changes to the default configuration
  3. google the distro version (Ubuntu 14.04) + vulnerabilities or exploits
  4. read through the different sites to find applications that had huge security issues on that version and begin installing some of the programs that have known exploits

So for example with Ubuntu 14.04 we know there are some Linux kernel exploits.

A quick Google search returned this exploit: https://www.exploit-db.com/exploits/43418

Using Ubuntu's website I looked up other critical vulnerabilities and found these: https://ubuntu.com/security/cves?q=&package=&priority=critical&version=trusty&status=

From here I could add some of the packages mentioned as having exploits and then attempt to exploit them. I could also check newer versions of Ubuntu like 16 to find vulnerabilities that would also apply to older versions.

There is also Mitre's list(s) of the most dangerous software vulnerabilities. They have one for 2023, but also a catalog of lists from previous years.

https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html

Hopefully this helps!

[–] [email protected] 29 points 8 months ago (2 children)

I can give you an answer from someone who regularly downloads really old EOL versions of Ubuntu and Debian. I personally use them as part of attack and defense competitions. They are normally very close to unusable and are nearly impossible to update to a more recent or secure version. This forces my team to find creative ways to keep them working while also taking measures to isolate them as much as possible. I also use them to teach old exploits that have been patched in more recent versions, walking people through how it worked and why it existed.

It happens a lot more with Windows machines, but there might be some manufacturing systems out there that require software that won't run on modern versions of the OS. These systems often require new manufacturing tools in order to upgrade, or they need massive overhauls that smaller companies can't always afford.

[–] [email protected] 3 points 9 months ago

I thought about this myself, and I wonder if Microsoft came in and gave them a bunch of time which caused feature creep. I am curious if Microsoft never bought Bethesda and they released it earlier, if it would be a more cohesive game without a bunch of half baked ideas.

I love all the different side and main stories, but things like outposts, ship building, and suit protections feel like they were added because why not.

[–] [email protected] 9 points 10 months ago* (last edited 10 months ago) (1 children)

No one seems to have thought about the fact that most schools have been out for those three months. Not sure exactly how much of the traffic is high schoolers and college students cheating, but that could account for at least some of the loss in traffic.

Edit: missed a word

[–] [email protected] 6 points 1 year ago

If you download a wireguard/openVPN conf file from Proton it will let you enable nat-pmp which is basically automatic port forwarding. It seems to work fine on a Linux machine running qbittorrent, but your case might be different.

[–] [email protected] 2 points 1 year ago (1 children)

I have had this problem as well especially when I first join a tracker. Overall my ratio is around 6, but for private trackers where I have been seeding for over 2 years I barely hit 1.5.

If the tracker has a bonus point system understand how it works and try to build up a bunch of upload credit with it. If the site has freeleach only download freeleach torrents for a while until you build up enough upload. The last method is personally my least favorite, but you can findout what torrents are normally the most popular and setup a program to always download them as soon as they are uploaded. Even if you won't do anything with the torrent content it can help build a ratio.

I highly recommend either making, or buying a seed box for private trackers, and most of them will give you bonuses for seeding for a long time, or seeding very big torrents. If all else fails you might want to consider paying for VIP if they have it. Normally paid accounts get extra upload credit or freeleach on everything, or something like that.

[–] [email protected] 3 points 1 year ago (1 children)

You might have some luck with a private trackers like Sportscult. They have open signups right now.

[–] [email protected] 4 points 1 year ago

I'm kinda the opposite of you. I love Bethesda games, but the fantasy element doesn't do it for me. I never liked Skyrim or the elder scrolls series but loved the fallout series, as well as games like outer worlds. I am not going to preorder the game but I am very excited to see their take on a space rpg, because I love fallout and I love space exploration so if combined well it should become an instant favorite of mine.

[–] [email protected] 2 points 1 year ago (1 children)

I bought a fortunate 60e a few months ago to play around with. After setting up some vlans, subnets, and firewall rules I am considering just selling it. Without a license you don't even get security updates. So at this point opnsense might be my next firewall to learn on. I was just trying to my hands on what is actually being used by companies.

It would be cool to see companies start offering homelab licenses for people to play around with and get experience before buying into a whole ecosystem.

[–] [email protected] 1 points 1 year ago (1 children)

Who are you using for Usenet? I just started using it after rarbg went down, so I went with Newshosting.

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago) (3 children)

Well it's been a while since I looked at streaming service prices, but let's go with $80 a month for all of them.

VPN: $8

Hard drives: ~$1000 total ($20 a month for 2 years)

Power: $15

Semetrical Gig Internet: $20 (extra)

Usenet: $12

Total: $75

Not quite as expensive, but it feels like it sometimes, especially when I have to drop $250 on a hard drive when one fails.

[–] [email protected] 3 points 1 year ago (1 children)

My wording was poor. I ment that currently there is no way to contribute to reducing stress on an instance. Making your own instance might help prevent the problem from getting worse, but it is not the same as adding more cpu power or ram to an instance. If a instance is maxing out on it's CPU power, currently there is no way to allow other people to help disperse the current load.

On a slightly tangential point, I am not sure how sustainable it is to increase the number of possible users by increasing the number of instances. It is already a frustrating process finding the right instance to join. So imagine when there is 1 instance for every 100 users. With 100k users that is 1000 different instances to sort through. I think there needs to be better ways to scale Lemmy, especially the amount processing power it requires. Lemmy.ml will only be able to scale so big on a single vps instance, or even physical server.

view more: next ›