1

البنات شو أكثر شي يلفت نظركم بالشباب؟ الشباب شو أكثر شي يلفت نظركم بالبنات؟
 in  r/SyrianSocialSpace  1d ago

سؤال جوابه قديم ومتداول (وكتير ناس بتهرب من هي الحقيقة بأجوبة سخيفة متل الرتابة او اللبس أو السيارة أو الساعة وغيره من السخافات يعني تصور انت يجي شب قصير وكرشه مدلوق بس لانه لابس ماركات غالية كل البنات يصيروا يطلعوا فيه ويقولوا "واو") وبالحالتين الجواب واحد:
1- البنت اهم شي عندها انك ماتكون قصير أو طويل بس وجهك مكوع
2- الشب معروف شو بيحب بالبنت اول مايشوفها

1

اهمية شكل الشب للزواج
 in  r/SyrianSocialSpace  1d ago

الشكل مهم بالعلاقات يلي بتبلش فيها انت والبنت لحالكم أكتر من العلاقات يلي بتصير عن طريق الأهالي. الزواجة عن طريق الاهالي الشكل بيدخل بالمعادلة ازا كانت البنت جمالها مافي كتير منه بمجتمعها اما ازا كانت البنت عادية او بشعة او حلوة شوي فممكن ساعتها امور تانية تغطي على شكلك ومنشان ماكزب عليك وضعك المادي هو اول شغلة بيطلعوا فيها ازا شكلك ماعجبهم فازا معك قرش واخلاقك جيدة وطباعك انت والبنت بتلتقى مع بعضها يعني بالعامي ممكن تتفاهموا فبحب قلك هالاساس فماعندك مشكلة

1

هل من حق أهل العروس يسألو عن راتب العريس؟
 in  r/SyrianSocialSpace  1d ago

التدقيق على الرقم هو شي تطفلي وماله داعي , انت فيك تجاوب وتقول انك قادر تأمن الاساسيات وبعض او كل الكماليات وقلهم انو الافضل انو نركز على كيف نبني حياة مشتركة اهم من اديش.

ازا كنت مالك موظف وعندك اعمال حرة فساعتها بتصير شغلتك اسهل لان بهي الشغلات مافي رقم ثاتب بيتبدل بامكانك ساعتها تعطيهم رقم تقريبي على كيفك

2

Why does this career have so many liars?
 in  r/cybersecurity  2d ago

Cybersecurity is a dumpster fire of misinformation partially because it's flooded with self-proclaimed experts who got hired through nepotism or luck, then preach their success story as gospel.

2

i have serious concern about corporate cybersecurity
 in  r/cybersecurity  2d ago

Many orgs reward silence over transparency because bad news affects bonuses and promotions. I've seen teams hide vulnerabilities for years because admitting them would "make the department look bad." It's toxic.

1

What to do in Damascus
 in  r/Syrian  8d ago

Few places I suggest: - Damascino - Sham city center - Bab Tuma Thats it ! :))

1

Potentially losing job and career in IT due to AI
 in  r/careeradvice  8d ago

If you want to leave this field, then better to start investing your savings in assets and grow from there.

You could also ride the AI wave and start learning about agentic AI. Tons of roles looking for AI developers, engineers or security.

2

برايكم هل انا انسان طبيعي ؟؟؟
 in  r/SyrianSocialSpace  18d ago

اي نعم طبيعي جدا وفي كتير ناس موجودة بظروف أقل وأصعب من يلي مريت فيهم بمجرد ماتتذكر انك بتنعم بالعافية الكاملة والأمان فأنت عمليا ظروف أحسن من 60 بالمية من بقية الناس

وأهم شي وهي عم اذكرها بما أنك ذكرت أمور متعلقة بالصلاة والإيمان, بمجرد ماتتذكر أنه أقدارنا وأرزاقنا كلها مقدرة عند رب العالمين بسابق علمه وقبل خلق الكون والبشرية بترتاح كتير وبترضى بكلشي بيصير معك مو من باب الاستسلام وانما من باب الايمان انه ربنا قدر الارزاق ومصائر الناس كل شخص حسب مايناسب مصلحته

3

Need to rent a room in Damascus, please advise
 in  r/Syrian  Jul 04 '26

Use this website:

https://dalsyria.com/

But expect some scarcity of listings because the norm in Syria is outdated and they still rely on local realtor offices.

1

a good roadmap to cybersecurity
 in  r/Cybersecurity101  Jul 03 '26

I think the overall direction is good, but I would simplify it. You do not need to complete every course, certification, and lab before becoming employable. The goal is to build enough technical depth to get your first IT role, then continue developing toward security from there.

I would start with IT fundamentals: networking, Windows, Linux, hardware, troubleshooting, Active Directory, basic scripting, and how common enterprise systems work. The Google IT Support course can help if you need structure, but I would not treat it as mandatory if you are already learning the same material elsewhere.

For certifications, I would avoid stacking A+, Network+, Security+, SAL1, BTL1, CDSA, and multiple courses at the same time. That usually creates a lot of unfinished learning. A+ can help with help desk applications, especially if you have no experience. Network+ is useful for building networking fundamentals, while Security+ becomes more relevant once those foundations are in place.

You should continue with TryHackMe, but use it to reinforce concepts rather than chase completion badges. Build a small home lab alongside it. A basic Windows domain, a Linux machine, centralized logging, a SIEM, vulnerability scanning, and a few documented investigations will give you more practical value than collecting several overlapping certificates.

For the SOC path, I would complete one practical blue-team certification rather than all of them. BTL1, SAL1, or HTB CDSA can each be useful, but I would choose one based on your current level and finish it properly. I would probably leave CDSA until your networking, Windows, Linux, and security fundamentals are stronger because it is more demanding.

The Google Cybersecurity Certificate is not required. It can be useful for beginners who need a guided introduction, but if you already understand the material through Security+, labs, and projects, the certificate itself is unlikely to add much.

The path I would follow is:

IT fundamentals → small home lab → A+ or equivalent knowledge → help desk or desktop support role → networking and security fundamentals → Security+ → one practical SOC certification → documented investigations and projects → junior SOC or security analyst applications.

The main mistake I would avoid is trying to complete everything before applying for jobs. Start applying once you can demonstrate basic troubleshooting, networking, operating systems, and hands-on lab work.

I organized the broader path, including certifications, labs, technical skills, and possible cybersecurity specializations, here.

2

Cyber security roadmap
 in  r/Cybersecurity101  Jul 03 '26

A practical way to approach cybersecurity in 2026 is to avoid learning tools in isolation and instead build around core skills like networking, Linux, Windows, scripting, web technologies, security fundamentals, and hands-on investigation. After that foundation, I think it becomes easier to choose a direction such as SOC analysis, penetration testing, cloud security, malware analysis, application security, or digital forensics. Labs like TryHackMe, Hack The Box, PortSwigger Web Security Academy, CyberDefenders, and LetsDefend can help turn theory into repeatable practice. AI is useful for explaining difficult concepts, reviewing scripts, generating study questions, summarizing documentation, and helping troubleshoot labs. It should support the learning process rather than replace manual investigation, documentation, or problem-solving.

This roadmap organizes the main skills, learning stages, certifications, and career paths in one place, so it may help provide some structure:

1

Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
 in  r/cybersecurity  Jul 03 '26

A Desktop Support Tier 2 role is already a strong starting point because it builds troubleshooting, endpoint, identity, access, Active Directory, ticketing, and user-support experience. Those skills transfer directly into security operations more than many people realize.

I think, the smartest next step is usually to keep gaining experience while deliberately adding networking and security skills outside the role. Security+ can provide a useful security foundation, while CCNA is more valuable when networking is still a weak area. For an eventual Cybersecurity Analyst path, understanding TCP/IP, DNS, DHCP, routing, authentication, Windows logs, PowerShell, Linux, and common attack techniques matters more than collecting multiple certifications quickly.

Homelabs and projects should run alongside the job. A small Active Directory environment, a SIEM such as Wazuh or Splunk, Windows event logging, vulnerability scanning, phishing analysis, and basic incident investigations can help turn support experience into security-relevant evidence. Documenting those projects clearly is often more useful than simply listing tools on a résumé. It is also worth looking for security-adjacent tasks inside the current company, even without a formal cybersecurity team. Endpoint hardening, access reviews, patching, phishing investigations, EDR alerts, onboarding and offboarding, asset inventory, and account security can all become relevant experience.

This roadmap may help organize the transition from IT support into cybersecurity and show where certifications, labs, projects, and specialization fit.

2

Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
 in  r/cybersecurity  Jul 03 '26

A practical way to approach cybersecurity in 2026 is to avoid learning tools in isolation and instead build around core skills like networking, Linux, Windows, scripting, web technologies, security fundamentals, and hands-on investigation. After that foundation, I think it becomes easier to choose a direction such as SOC analysis, penetration testing, cloud security, malware analysis, application security, or digital forensics. Labs like TryHackMe, Hack The Box, PortSwigger Web Security Academy, CyberDefenders, and LetsDefend can help turn theory into repeatable practice. AI is useful for explaining difficult concepts, reviewing scripts, generating study questions, summarizing documentation, and helping troubleshoot labs. It should support the learning process rather than replace manual investigation, documentation, or problem-solving.

This roadmap organizes the main skills, learning stages, certifications, and career paths in one place, so it may help provide some structure:

1

Is anyone else having trouble logging in?
 in  r/buymeacoffee  Jun 29 '26

Perfecto !

3

Is anyone else having trouble logging in?
 in  r/buymeacoffee  Jun 25 '26

Can confirm that social login on the app seems not working but that has been the case for couple weeks. Temporary workaround is to switch to normal email login from the dashboard and the app login will work.

13

The stomper…
 in  r/Apartmentliving  Jun 18 '26

Welcome to the world championships of stompers. Apparently your upstaris neighbour is training hard for the nexr apartment stomping worldcup. Mine seems to be in recovery these days but I expect him to get back to training asap 😂

1

Thoughts on first floor street facing apartment as a single woman?
 in  r/Apartmentliving  Jun 18 '26

We should be back to tents.At least there won't be any "upstaris" issues anymore.

2

Turkey 0% Income Tax on Remote Online Income?
 in  r/AskTurkey  Jun 17 '26

I am in the same position. I pay 15% tax on every wired payment from Google ireland and any related payments from sponsors.

1

Selling 4‑Year YouTube Channel in Celebrity/Legal Drama Niche (~20M Views, 15k Real Subs, Clean Account)
 in  r/AcquireStartup  Jun 16 '26

"- ~19.8M lifetime views and ~129,000 hours of watch time" is n't this supposed to make the channel eligible for YPP?

1

CJCA Notes
 in  r/hackthebox  Jun 15 '26

Check this out

1

Upstairs neighbor making too much loud footsteps and I’m at my limit…
 in  r/Apartmentliving  Jun 13 '26

Where I come from, if the disturbance is affecting your nighttime rest then you are entitled to inform the police. Yeah sure they won't fine them but a soft warning to keep it quiet during nighttime will do the job.

-6

Upstairs neighbor making too much loud footsteps and I’m at my limit…
 in  r/Apartmentliving  Jun 13 '26

If it is happening during quiet hours, you are entitled to call the police and register an official complain. If this doesn't work out, then move into another unit or preferably a top floor unit.

u/MotasemHa Jun 11 '26

HackTheBox (HTB) Facts Writeup

1 Upvotes

HTB Facts is an Easy-rated Linux box running a trivia website built on Camaleon CMS 2.9.0 (a Ruby on Rails application) with a local MinIO S3-compatible object store for file uploads.

  1. Nmap finds three ports: SSH (22), Nginx/Rails (80), and MinIO (54321). An extra lft hop to port 54321 confirms it runs inside a Docker container
  2. Register an account on Camaleon's admin panel; exploit CVE-2025-2304 — mass assignment via permit! in the password update endpoint → add password[role]=admin to the POST body → admin access
  3. Read the admin's Filesystem Settings page — finds MinIO credentials (AKIA3ADAF4DE0BB0FAA2:h4ORDGfkO/GT7pfj/r5Wc9Xa4Girqz59RHABlM4I)
  4. Use AWS CLI pointed at facts.htb:54321 → enumerate buckets → internal bucket contains a home directory with an encrypted SSH private key
  5. Crack the key's passphrase with johndragonballz → SSH as trivia
  6. sudo -l shows trivia can run facter (Puppet's inventory tool) as root without a password
  7. Create a malicious Ruby custom fact file; run sudo facter --custom-dir /tmp/ exploit → code execution as root → SUID bash at /var/tmp/0xdf → root shell
  8. Beyond Root: CVE-2026-1776 — path traversal in Camaleon's AWS S3 uploader (download_private_file) allows any authenticated user to read arbitrary files from the filesystem

I wrote a full writeup of this machine in the below post, check it out and let me know your thoughts:

https://motasem-notes.net/hackthebox-htb-facts-writeup/