The last part when you turn on music is insanely cool, thanks a million
@infosecbootcamp10 сағат бұрын
well said Tyler
@KyserClark23 сағат бұрын
THM prices are way better. However, HTB Academy Modules are a little more in-depth, and the writing on HTB is significantly better. I'm about 40% through both pathways, but I stopped HTB Bug Bounty path because I didn't want to pay the steep price to renew. I think the HTB Silver/Gold subscriptions are only worth it if you are going after the certs. But if you are after certs, TCM Security offers the best bang for your buck. Which is why I decided to go PWPA before CBBH. Cubes are not terribly hard to understand, but they are unnecessarily complicated lol.
@KyserClarkКүн бұрын
The thing with sponsors in my opinion: Promote products and services that you already use yourself and brands that align with your values. Or products you think could truly help your audience. Pretending to like or use a product to get sponsors is not authentic. Your authenticity is why you are where you are at, people are tired of un-authentic content creators. Authenticity is the new gold. Sponsors are ok, but you have to be picky with who you work with. If one of your viewers buys a product you promote, and they have a bad experience with that product, you're reputation takes a hit. You're reputation is worth more than any amount a bad brand wants to pay you.
@dc0413Күн бұрын
Thanks for making this video...I had just ventured to HacktheBox Academy (HTB Academy) literally two days ago, saw your video and have now ventured over to TryHackMe (THM) and I must say, I seem to enjoy their learning interface better. Thanks for this video!
@jamierowland9048Күн бұрын
One of the best THM room walkthroughs - can't wait for the next one!!!! Many thanks
@MustafaGainsКүн бұрын
❤❤❤
@beyondtime4513Күн бұрын
I know in your intro you mentioned that you do this live without any prep but I think it would be good to add as well that "while I do this live I may also get help from chat". This is because when other people try on their own with no guidance at all and they get stuck, they get stuck and wont move on. Some people solve it but longer than 1hour and 30 minutes. Like for example you were given the payload to use in chat for SSTI. This is not me trying to throw hate but just to not give the narrative to people watching the video he solved it in x amount of time doing it live with no prep. Like in an exam you do not get assistance, you either know it or you do not. If you do not know it in the exam, that's it. You don't get assistance. I think it would be good if u include timestamps of where you get stuck and just cannot move forward at all/where you got assistance. This will help people know that they are not the only ones who struggled. Like when boxes are active you do it by yourself, and if you cannot do it. Then you wait for it to retire or writeups become available.
@TylerRamsbeyКүн бұрын
Good feedback - regarding timestamps though I don't have time to do that lol I make these videos while working full time, being married, and having 2 young kids I make about $100/month from KZbin and refuse to do sponsored videos, so don't have the funds to hire editors and such so it's all solo 🙂
@beyondtime4513Күн бұрын
@@TylerRamsbey That makes sense. One thing I do appreciate is that you do it live as some of the others wont do this. There is nothing wrong in chat helping or you looking at a writeup on stream. If you have tried everything and you do not know the answer because you have tried everything, then looking at writeups or getting hints is no issue as everyone at some point has looked at a writeup. When I did this room I just could not get the 2nd flag when I tried everything, so I watched the stream to see your thought process. Unfortunately someone in the chat I guess spoilt it and gave the SSTI payload that worked. I would have been interested in seeing your thought process instead of that person just dropping the payload in chat. But I guess its not something you can really control, even if someone pasted the methods straight away I am not sure how u can prevent it? unless you say ahead of the stream.
@sharkmonarch12 күн бұрын
I doing CASP+ and its really technical management level. CISSP focus are different. but for me, CASP+ / X is equivalent and could be better than CISSP.. Very Hands-on with simulation / performance based question. Learn a lot from it
@THEARPE072 күн бұрын
HTB 250 usd/month, to afford this you need to have good paying job
@lilfade10k2 күн бұрын
Str8 genious thank you
@xu83r2 күн бұрын
I finished Jr. Penetration Tester at TryHackMe and got CBBH. Hack The Box and Jr. Penetration Tester Path were very great. Hack The Box also has a Senior Web Penetration Testing Path. The CBBH is more valuable than the Certificate of TryHackMe.
@ganeshhari66363 күн бұрын
i thought you clean shaved ( shows in thumbnail )
@Me-sm8os3 күн бұрын
thanks man! Super helpful. I use THM and love it; HTB's price point has kept me from jumping in. I do really like THM though and especially the access to walkthroughs to help me learn when I get stuck. Also, hard agree: I hate when I click into a Medium article and get the answer blasted into my eyeballs with no explanation of how to get there. I'm looking for a lesson, not an answer sheet. Anyway love your videos, thanks for posting these.
@CodeBrewCyber3 күн бұрын
The pricing structure for HTB is insane and honestly pushes me away from their platform. I gladly pay for a yearly sub to THM, and even when I fall off for a couple weeks/months at a time I still feel like I get my money's worth.
@theshyhat3 күн бұрын
Thanks for the thoughtful comparison between the two topics cover on THM and HTB! I've always found the layout of the HTB academy materials to be quite a bit clunkier than the rooms on THM. What's your opinion on the UI and user experience for the two platforms?
@MrMagiclamp13 күн бұрын
Hi Tyler, I like the content of your videos. Please research into the sponsors and accept them if you feel good at heart in vouching for them. Keep your money safe for rainy days. Life comes with surprises. If you still have more money, you can do more grants through your church.
@fgruzfuhd3 күн бұрын
Hey what are the best resources to learn pen testing , with 0 experience completely for free
@ThePabloEskobear3 күн бұрын
Thanks again for another great video to save the day. Nearly flipped my desk trying to solve Task 3 Q2. LOL
@divyambhavsar64063 күн бұрын
Cors & sop in arbitrary flag i found but it's consider wrong which is Right please give it me.... And in last ctf second flag for i can't found sing in page i try /access but connection error show.. how to complete?
@Daryl-at-TryHackMe3 күн бұрын
Thanks Tyler! Nice to hear the feedback
@Son.Goku.Daima.20243 күн бұрын
Bro, you're just too good!! Love your content❤
@x9rtu3os1t83 күн бұрын
HTB Need to modify their fee system and the conditions so learners have mode confident to come at. Its scary to learn When Its hard to get help or When you know after one year no mode access to what you paid for. THM For learning AWS need ~350$ for 3 months why no plan for only one month?
@TylerRamsbey3 күн бұрын
All good points. I recommend checking out cybr.com for learning AWS
@im_wander3 күн бұрын
Hi Tyler! Where is my HTB voucher?
@TylerRamsbey3 күн бұрын
I don't work at Hack The Box? No idea lol reach out to them
@im_wander3 күн бұрын
@TylerRamsbey you missed my joke Tyler. 😁 good seeing you though
@simonst9r3 күн бұрын
I'm a student and I'm one skill assessment away from finishing the cbbh path on htb. Really worth the money. Idk if I will go for the cert as well. Is it worth it? Already employed, so no need to add sth to my resume. On the other hand I like and pay for thm as well, cause I like their byte sized lectures comparing it to the wall of text on htb. Anyways both are doing a great job. Thanks for the video, Tyler!
@cracc_baby3 күн бұрын
your not allowed to stream retired content on HTB?? i know you can do walkthru videos, but im not sure about live streaming. its more about the points system for players, Active content gives points for flags, retired content doesnt.. nice flick tho bro
@TylerRamsbey3 күн бұрын
You cannot stream any paid content on HTB Academy. You can only stream Tier 0 content.
@maremeaxi33443 күн бұрын
Burb Suite on HTB academy is not easy. But they cover every features.
@The1tboy3 күн бұрын
I will explain how cubes work. Cubes represent the amount of money you use to unlock each module. After completing a module, you will receive a refund of a specific number of cubes. Each tier of the module requires a different number of cubes to unlock. If you subscribe to the Silver monthly plan, you will have a total of 200 cubes. For example, the Bug Bounty Hunter path requires 1,370 cubes, so it will take seven months to unlock the entire path at the Silver subscription level. Alternatively, you can spend $106 on a Platinum plan and one Gold plan to unlock this path. The Senior Web Pentest path costs $514 to unlock. Once you unlock a module, you will have permanent access to it. However, with the Annual or Student plan, access will be lost once your subscription expires.
@TylerRamsbey3 күн бұрын
.... confusing lol - surely there is a better system
@The1tboy3 күн бұрын
@ You can briefly understand that Cube purchases will be used to unlock specific modules, similar to using currency to buy items in the game. Once purchased, you will have permanent access to that module.
@iMshadab3 күн бұрын
I am very new to ethical hacking and also completed Tryhackme web app pentesting path recently. It was great and HTTP smuggling I found it easy 😅
@chenxin28053 күн бұрын
Hi thanks for this informative video. I believe that the cubes in HTB Academy is used to unlock the modules permanently; that being said you can access the modules if there is any future updates to it. When the Gold/Silver subscription ends I believe those modules are no longer accessible.
@alexandrosmitsouli87633 күн бұрын
The HTTP smuggling was indeed the most difficult for me as well, but due to the friendliness TryHackMe provides, I managed to wrap my head around it in a slightly more advanced levell.HTB coming next along with Port Swigger.
@timamabug3 күн бұрын
thank you very much for this video! it's true that if you're a beginner and you're doing an advanced part, you leave with a confused head. However, I still do it because I’ve noticed that even if I don’t fully understand everything and am still learning, revisiting these concepts-still unclear to me-gradually helps to clarify them. Over time, they become less and less confusing.
@Mane_Tech3 күн бұрын
Hey Tyler. How do you manage all these with a family?
@TylerRamsbey3 күн бұрын
Hey - I made a video about it :) - kzbin.info/www/bejne/bqa9qalvadt6fMU
@carlosziade12143 күн бұрын
I have done intro to cybersec, web fundamentals, red teaming and cyber defense(still not completed), and junior pentester on THM, I come from a totally different background in motion graphics and editing. The platform is great and beginner friendly straight to the point for total beginners like me. HTB was a bit hard whenever I tried it, but of course great for those who already have some background in cs, IT or cybersecurity
@git-tauseef3 күн бұрын
Hey Tyler pls review Pentesterlab as well....thanks❤
@bengreviews82864 күн бұрын
Tryhackme teaches ffuf in Jr Penetration tester path but not really in depth
@TylerRamsbey3 күн бұрын
Ah, good to know. Thanks!
@tim41134 күн бұрын
motivation to not google answers is needed, its tough when a new google tab is a click away...
@indianfromsouth77563 күн бұрын
So true 👌
@aimbotff49434 күн бұрын
i am currently doing pentester path on HTB. and its great. and its more in depth than THM. and i am loving the suffering of not finding the proper writeups of HTB😄
@domzzy64324 күн бұрын
Sane here am trying to do the cpts exams once completed
@TylerRamsbey3 күн бұрын
The silliness of HTB Academy I didn't mention is if you get a gold annual sub, you get full walkthroughs to every challenge/skill assessment just by clicking "Show Solution" The difference is that it's hidden behind a paywall rather than free
@kennystrawnmusic4 күн бұрын
About 30% of the way through the Active Directory Pentester path on HTB Academy now myself (though there's 14% overlap with the CPTS role path, so that's what I started at). Curious if THM has anything similar - all I'm hearing about is web. Also, does THM have any practical exams or do they just award the cert the instant you're done with the path? Because the latter approach is probably not the best way to teach either.
@The1tboy3 күн бұрын
You can check out their learning paths; SOC learning paths are great, too. Red team learning path has some of the same content as cpts. But there are some things I guess that are more advanced than cpts and more geared towards red team than just AD pentest. They also have a devsecops learning path. Cloud security path is a separate subscription. As far as I know, they plan to launch junior soc certification this year.
@TylerRamsbey3 күн бұрын
Red Team Learning path would be the equivalent to the CPTS path on HTB
@phillydee35924 күн бұрын
Busy doing the CPTS path on Hackthebox,but doing it by buying cubes and unlocking the modules as i dont have a subscription,but do have a subscription to Tryhackme...lol cant do both😂
@Avg-Bear4 күн бұрын
Completed Red Team Pathway on THM. Pretty solid and deep. I like the format compared to most of HTB academy (great but, less leading). Both have their quirks and I like to do both for reps and recommendations for others. Will start this soon.
@bitenigma4 күн бұрын
Im currently taking the Web app path on THM as well as HTB Pentester Path, thank you for this cool overview!
@astcandy66654 күн бұрын
:)
@Thiccolo4 күн бұрын
Can't wait to do all of TryHackMe's paths
@ziajalali39064 күн бұрын
Thanks! Learn a lot from your videos. Respect 🫡
@fgruzfuhd4 күн бұрын
But how do you know how to write that code like how do I know what API to use
@TylerRamsbey4 күн бұрын
Hey - I showcase how I wrote this script in more detail in this video: kzbin.info/www/bejne/mqrai6x4lL-Nl6M
@fgruzfuhd3 күн бұрын
@TylerRamsbey Thanks for answering, as a complete beginner what resources would you recommend me to learn pen testing for free completely free
@Cur10usly4 күн бұрын
And the flag is shown😅
@TylerRamsbey4 күн бұрын
haha yeah, sort of hard to stop it on these kinds of challenges
@Cur10usly2 күн бұрын
@TylerRamsbey I see. Just keep working. We expect a lot from you 😊
@saby78255 күн бұрын
What about someone coming back to IT after being away for 2 years? Would I need certs? If so, which ones? If it helps, I am trying to get back into IT support to start off.
@swayz17995 күн бұрын
This is the glorious king who beat me on vr boxing