#general
1 messages · Page 30 of 1
i buy like everything through them
i ordered company polos and they were nice and comfy
whatever is cheapest, they all use the same processing
really? I figured youd be chill considering you had to wear a mil uniform for 90 years
you opening your own company or?
Making red team shirts for my team
aah
Totinos Frost Bites
The Pizza Bites
how u got the time for all that
Yes
Hey guys
im not a guy...
What chatroom for ctf related talks? I hear there’s a htb ctf currently
Sorry I meant guys as in humans
Humanoids*
I just do them for fun
#1404302368186826762 @woven plume ?
Thanks!
anyways, you are looking for #1404302368186826762
u a master
Hello all
we all love glazing frost, but nobody glazes him more than me, hes mine chat
all yours @sharp shuttle
although I am a linkedin friend from frosto
but I bet he doesn't know


pretty sure i have you on LI too sparkling
Idk if I’ll get a cve in something AI before offsec ai con
I’ve been code reviewing ollama and onnx
Nada
chances are big because I remember something vaguely
Is there some HTB admin to help me bye the exam voucher!??
I have some issues with my shopping card
all i have to do is check my mutuals with mto
that would be support
Need to speak to a person? Learn how to reach our support via HTB Labs.
Maybe I’ll do an ai cert
just take jason haddix' ai red teaming course
You have both frost
you ganna get my cert frost?
I already grinded a few months of material last week
its all because of you im even doing drones
Drone hacking will be bigger in the next few years
hoping my course sells because of it
I regret not getting the discount
im banking on the dji ban this year
it seems like mike monnik isnt as passionate about dronesec, really sad
dji t50?
Nah I don’t have the model on hand
you have a vtol?
Idk model
But I know we got a plane for transferring stuff
Google says
Pilatus PC-12 and PC 24
nice
oh its a manned aircraft
we have planes and drones
I love Pilatus'
Separate
what are you transferring?
Idk the drone model
medical supplies?
Blood
that makes alot of sense
Since we’re vampires
brath top 5 effective weapons against drones for a foot soldier?
Long stick, big rock
drone, drone, drone, drone, shotgun
yeah but cool long sticks are so hard to find, this is not a viable option
i wouldnt want to be a foot soldier in 2025
that might be even scarier
cold war 2 is going to be artificially started once amd and dji get banned, and i think a drone swarm will be the black swan
against naval vessels
Time to collect large sticks
buy a shovel
Yeah but sticks are free
our salvation is under ground
lmfao
non-zero chance of this happening
evil residents
Ok my next recommendation to the ai team is to name it Red Queen
yep
kinky
everything ive bought on temu has been pretty decent
Got :D
someone likes amber
it looks like genshin character
im more of a ninguang enjoyer, i would submit to mommy rock goddess
My gf gave it to me a few months ago
Just found these in my wallet lmao
thats cool, in your wallet is crazy
The main point were big [my tag]
She got all she could find for me
when i played that game i only leveld up geo characters, so noelle and ning were my bitches
eval?
no
ligma
eicar?
damn i didnt even know that
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
look at it being all virus lookin ahh
til about eicar
When i did
I just wander around instead of Playing game
Mostly just cooked whatever I can and sightsee
good morning/ evening all
thats how i played elden ring for 10 hours and then quit, just sightseeing on a steed
It was fun tbh
genshin is a good ass game, im not even a weeb, i look forward to when its all done and they make everything in it free
But device gave up around that snowy mountains
Too much to render
It was hard to play
what makes genshin good
graphics
good gameplay loop, nice to look at, extremely well thought out evironments and cut scene/animations
and chara
its like breath of the wild on steroids
i understand now
I remember wanting to make my own anti-virus in high school 😭
and it just popped up again
the chinese make america look like total bitches in the modern day
can i ask you peoples something?
YES BRATH GOOOD + 20000000 POINTS
just ask
i am farming

We don't know where stylish lives
well currently I'm working in a team for my colleges CTF and i was assigned to make a question on data forensic can someone help me with and guide me and I'm relatively new in this field
im from India and you guys?
genuine advice is to work with chatgpt
Yes
well he didn't make it for ctf like i wanted something which uses tools like autospy and such
it made one but didn't add the flag in it.. and all
it was confusing for me..
you from india too bro?
25% chance
and i want to learn while making ctf question
??? 25% chance for what?
being indian
india is like the biggest population
1.4 billion
and 67% of india aint even on the internet yet 💀
nope most are
theyre not
Probably 5y ago
Now almost everyone is
yh i agree nowadays even 5yo old are on whatsapp...
im indian too bro 😭
im too
i got the new delhi belly
yea i saw
dehli belly is 18+ series/movie till i remember
wha
oh i heard its what happens when you eat the street food, mystery meat, and liquid concoctions
its like a tummy ache
false info
It's U/A not even rated R
Why 18+?
Nvm it's A
ohh well it had that randi khana scenes so i thought it was 18+
i knew it
why?
I have never got any issue in movie theatres with ratings
i can watch and download it from college's server
Tell me your college name
iiit
they can't do anything server is managed my friend
Board got fried
where you from bro?
which city?
The best one
there are many best ones in their own ways
bhiar?
mp?
up?
Yep
and city?
Shadow can i visit india and crash at ur crib for a week?
almost weekend guys
I'm from vashali district and you?
I live with my family so can't.
Maybe in few years when i live. Alone
Hehe i live in Hyderabad
ohh and i live in maharashtra
i cant find malware reversing challenges in htb
the challenges here arent clickable: https://ctf.hackthebox.com/pack/malware-reversing-essentials
nope
I think they are solely available for participants of such a CTF with a category like that
not all CTF challenges are available on the platform/for free
does anyone know how to make ctf question on data forensic to use tools like autospy, nmap, etc?
hmm
please help
Just use a windows vm
I’m okay
ok 👌
wine seems to be better for a fast setup
I’m trying to understand Kerberos delegation a bit better so I’ve been on the same academy page for weeks now
Riddle me this, how are you gonna run x64dbg on a fucking wine instance
No I’m not reading that. That guy doesn’t know what he’s talking about
ok lol
You mocking me?

now why would you think that
And the prodigal bug bounty man returns
Not really since I’m trying to understand this dumb academy module rather than just simply go through it
Yes
Specifically constrainted/unconstrained/RBCD? Or just how it works overall
tickets 'n shit
Henlo
Here's my 5 min sketch of delegation
Isn't it that the double hop problem only occurs on specific services?
Yes not every service is configured for delegation because not every service needs to request resources on behalf of the user
Hence why generally app servers are configured with delegation
This is also just a quick draw.io sketch, I’m sure Microsoft has better diagrams in their documentation
That’s constrained isn’t it?
constrained = app server can only request on behalf of specific services
unconstrained = app server can request on behalf of any service
I get that
In this diagram we cant really know if it is unconstrained vs constrained. We see it asking for the backend, and if that is the only service it can handle then it is constrained to that one service
lol
Like finding a key in a haystack
how much life elixir did it take lol
did my first one today, just rooted Cap lol
a lot of rage for sure.
I know the feeling. It's very rewarding. Just be humble, keep improving silently...
it gets a person so freaking invested
100%
"just be humble" - man i feel like a champ right now lol
wanted to do a blue team one
Hahaha feel it as much as you can
the new sherlock ones seem interesting... then my package manager came in a broken state - damn that broke the spirit lol
I'm not gonna talk about how much anger I felt doing the machine above. I was so determined to do it though.
how long did it take u ?
I don't know but I've been doing it for a min
lol like days or hrs xD
Probably like a day or 2
feel like i need all the basics to get the harder machines done right?
because this was a lot of googling and being insecure all at the same time + maybe using a guide to see the exact commands lol
You definitely need basics to do the machine, but they're not required for you to try.
Everybody fails boxes. I like putting myself in harder situations knowing i'm gonna ask for help later
But that has worked for me, i've improved doing that
my guy you are top 500 worldwide, damn
Hmm
Although I don't think it's much, I definitely don't deserve it lol
I need to learn how to hack man
well, it is waht it is 😄
so do we all, but its still somethign to keep you motivated to keep pushing 😄
Yeah I don't look at my rank anyways I just wanna learn everything else is a byproduct
there s a polish guy who pwned all boxes, kinda like that story overall
yeah, ofc it doesnt mean "A LOT"; but for sure means u r on track, thats whats important
like 1% better every day^
Nice way to look at it
theres thsi theory of 1%
if u get 1% every day, thats 36x better than u were than d1 ^^
I hope I do get 1% better everyday
Setting up smaller goals until you reach your main one is the way to go always
yeah, what i also love is that it gets much easier every day...
like when u know a thing or two its much easier to learn the 3rd on the fly
Im only on my third module "setting up". I kinda get jealous of you guys who can do challenges and activities 😂 I know you didnt start off knowing how, but I want part of the action 🤦
bro, try to do the cap one, its very easy... 🙂 Listen to a walkthrough first, then try another easy one yourself with just google, etc ... 🙂 Im not much further than u are
You're almost always gonna stumble across something new, so take as many notes as possible and try to be organized
TRY to be organized, ... just a reminder: paper doesnt work lmfao
Keeping track of things on paper doesn't work but i have a board on my wall where i write shit and take a look at it everytime i do boxes to remind myself of things
notion.so the goat guys
same for me, really need to write stuff down
got notion, too but im not using it effectively
also not sure what to write down and what not really
My wall is my board/paper... Stuff taped everywhere
I just write down anything that I feel like is useful or that I'm gonna forget later
Hi guys question I have
ASUS ROG Strix G15 (2021) Gaming Laptop, 15.6” 300Hz IPS Type FHD Display, NVIDIA GeForce RTX 3070,
Should I replace with mac air ?
which mac air
drako do u wanna game or nah?
M4
I have gaming desktop
I have m4 ipad with magic keyboard as well
yeah m4 is good also youre comparing a gaming laptop to a machine thats used for work (mainly)
m4 is great, for sure
mac air is not premiere. i may not know how to hack but i am A+ certified and know a PC build is always better bc you can upgrade. Mac components are soldered and sucks when you need to do RAM heavy tasks
i still have my mbp 2019 with intel i9, but the m4 is a beast
Yeah agree
Bro with the m4 u r gonna live stress free until 2032 at least
For sure
it narrows down to what you want to do. Also yes as ElJefeDelTaco said, i'd buy a pc so that i can upgrade the parts later unless you want something portable
at the same time... do u guys rlly wanna upgrade it? I just get new hw every x years like a cycle
I being honest since I got my desktop I barely use my asus laptop
like my mbp 2019 is soon gonna get upgraded (as the need arises) but it is just working perfectly until now, so i dont have the need
I'd go for the m4 then
yeah also macos feels fresh idk but thats it for me
im on a macbook pro now and i hate it! it makes me feel less than worthy to be learning such a technical skill
You can have Kali in mac and can do hack the box ?
my personal opinion; laptops are inferior and ive been a tech since 2015
jefe lol i had that, too but i can tell u this... all of ciscos emplyoees i know are rocking macs... 🙂
its not the peripheral u r using directly, its the one u r remotely accessing
Cube talks in 2h
I like my MacBook
you can, but ur gonna run out of RAM fast; most macs have a max of 8 to 16 GB
which u r gonna do if u r into this... its just important to ssh smoothly 😄
Depends on what you do with it though
whats that
i concur! touche
whats the topic gonna be ?
I will think for 2 days and will see
Staff from htb answer our questions
HTB and other general cyber questions from the audience
Won’t be the same without 0xfd
🙁
ill give u an example... i have a T14 lenovo (love that thing) ; got parrotOS directly on it so i dont have to use a VM;
Now i put 16gb ram slot in it (total of 24, i know, not optimal but it works perfectly) - thing isnt fast but it can do all u need on it for this type of work
where did he go, he is a bigg name on htb
idk the guy but feel u lol
Only reason I don't want mac because I got 13inch m4 Ipad with magic keyboard and since iOS 26 everything same
i thought you used kali...
why d u think that?
you can do anything if you put your mind to it 💪
Idk must be the profile picture
im not used to sarcasm on htb 🙁
ah ik it was a bad joke, i was trying hard to not let it out
luckily my profile pic is red
mac is also BSD based
i thought you were Nameless0ne guy at first
your name is, too kinda
so you can run most tools directly on it
thats true emma but for us noobs its complicated to realize that
like i get the family parts but just considering that a newbie doesnt udnerstand zsh and bash differencs in the terminal
but theyre capped by the OS
zsh > bash anyway
and you can switch
exactly, but it was the cup i was referencing, tried to keep it simple 😄
yeah that could be but i dont have zsh in my work environment and i wanna use it as easy as possible; learning 1 to have maximum output in day2day
hello chat
it confuses me already how to use ftp commands vs ssh commands; so adddingg more just adds fuel to the fire of too little knowledge
if u get what i mean
using commands is the exact same with both zsh and bash
its calling the same underlying bin files
Ayy i am considering a t14 as well is there anything you don't like about it?
fair point, what about bash scripting for automization?
afaik ZSH has full compability with bash
but adds extra stuff on top
i just like oh-my-zsh
and the prompts
man, its just a good base... built really sturdy and also like the design, its just simple, works and its durable, can recommend; Had it on my job only, then figured i d buy the same one for private use due to the fact that i already have the docking station by lenovo, too
Cool stuff i still use an x230 for similar reasons
t14 is the best among everything in cybersec
tahts the design?
yeah
I dont think it has coreboot though
makes it so much easier to wrok with if they made it pretty beforehand
as for everything i began to believe that it just comes down to "whatever floats ur boat"
Why is my distro in the htb general? 🥀
like maybe u know how kids in developed countries do wheelies on perfectly built lightweight ktm dirtbikes,
whereas kids in brazil do the craziest stuff on just regular bikes which werent optimized for the tricks etc...
Its just how much time u put into this
@static pasture get pinged sucka
Hot take: whatever works best for you is what’s best
And it boils down to personal preference and your workflow and requirements
idk what i need special functionality my t14 has compared to some other laptop; the problem usually sits in front of the pc
@zealous charm eat my ping sucka
@zealous charm eat this as well sucka

emma and myself are basically on the same page about it root rose,
as long as it works, run with it, make miles

You have the power to ping 200k people falcon
Do it
Execute order 66
This isnt ISP....
really like the zsh description for this:
Oh My Zsh is an open source, community-driven framework for managing your Zsh configuration.
Sounds boring. Let's try again.
Oh My Zsh will not make you a 10x developer...but you may feel like one!
And its actually 329k people
wdym329k people?
lol
You wish you were as cool as ISP! (Falcon runs both)
There are 329,000 people in this community
holy f, i didnt even know lol
ISP is pretty dope ❤️
internet service provider?
The community that spawned other communities 
Pretty much lol
i just know about the infosec htb module 😄 or path idk waht it is
InfoSec prep is a motley crew at this point since most of the other orgs spun up their own Discord
But yea it was a community server that had staff from all the big names out there in the industry
motley
adjective: motley; comparative adjective: motlier; superlative adjective: motliest
1. incongruously varied in appearance or character; disparate.
hope that helps lol

Nerd...
Always use urban dictionary
love how they used the word incongruously to explain anotehr word

Hello jckss
Yeah I was busy doing stuff
What happened to cube talk
It's weekend

Same I'm now in Linux fundamentals I don't really use DC except of the cube talks
motley
Behaviour associated with football fans and general 'laddish' behaviour.
Plural: Mots or Motz
guy 1 chanting in the street
Guy 2 - "Mate, you're so motley"
Guy sees a man dressed completely in Adidas
Says to friend - "Look at that motley {insert swearword with bas]!"
Look at this
https://youtube.com/shorts/qrTjsrpA6f8
yep.. that's a whole lot of science.
GET SOME BERD MERCH GO GO GO: https://hahahaimyourstorenow.com/
CLICK HERE TO BECOME STINKY: https://www.youtube.com/@Berd/join
COME WATCH MY STREAMS: https://www.twitch.tv/berdboi
SUBSCRIBE TO MY VOD CHANNEL :) :D https://www.youtube.com/@berdvod
USE MY CODE AND GET A SICKO MODE PC: https://www.x...
Speaking of that we have cube talks today right?
yes, sbdy just announced it, it is in almostt 2hrs
See you read once and remember forever from UD
less than 2h*
Yes
Go finish stuff
Perfect
Hehe i have alot
Boutny plz sir
I am still in fundamentals I'll start projects when I finish all the fundamentals and start with pentesting
Then i see them after a few months and gets confused
Sir u went out of scope i will deduct this from your rep
Anyway enough lacking I'm out 💀✌️
Yeah shoo
I only hack OOS bhai, less competition that way
Oos?
bhai?
Bro
Out of scope

But no boutny for you
I will mark your report as closed
hello everyone, kind of important, where do i look if i really need to find ASAP a proof of concept for CVE 10585
nothing on google
Read the vulnerability and see what exactly it is
this cve is like 1 day old
Well then understand the vulnerability and. Make. One
Lamo
Not even valid cve number
Most CVEs wont have an immediate PoC available unless the reporter published it themselves and usually only do that after an organization has had time to push out patches
lol i am clearly in the wrong forum i though i was getting knowledgeable people
Lmao
CVE-2002-10585
Pipsqueak pipe down
It do be like that
the full name if you guys did not deduce is CVE-2025-10585, yes they add the year at the beginning
Thanks i didn't know that
What is cve?
Custom v8 engine?
Im having an extreme issue getting Parrot Security to run on my vmware i have on Macbook pro. im stumped; i tried two diff ways to get it to run and nothing. downloading it directly to the VM gave me a .vmdk file that the Windows 11 (ARM) couldnt open. Then i tried creating a new vm (downloading parrot to my desktop directly) and uploading the iso during the creation of the VM and it wont work. stumped currently
Zumi you are right but i get a guy that tells ,e to google it, i mean if i got my answer via google i would not be here
Get something not. Mac
then i get another dude that tells me to code it myself
Womp womp
is there a more advanced forum?
Yeah
Like I said most CVEs that are just released wont have an immediate PoC available so the apps have time to create patches
Sounds like you’re not knowledgeable enough to code it yourself.
an hour ago i got a call saying there was
Call back and ask them then?
Then ask the person that told you the PoC was available where to find it
u tried
Almost
0xvader

There you go

@patent elbow
0xVader is definitely a tank
Getting full aggro
😡
I hear if we all just ping @maiden anvil they might just show up
Can’t even say my name . Shit you can’t do anything right can you?
lol
@maiden anvil is that true.
Ping @maiden anvil ? Idk that 🦀 so i don't think i should ping
in all seriousness is there a forum for people that actually know how to do stuff? and not pretend to?
Why don't you google
Yes, but you aren't allowed there
i thought HTB was the most advanced legally
Only LARPers here
half an half
This is a LA roleplaying server
totally not florida or anywhere else
@sinful thorn there are people that I am sure know how to do stuff here. Either teach yourself the thing you want (code it, google it), or wait for the PoC to actually drop.
ok anywas nice meeting you guys

i dont think i can code a CVE for chrome i
yeah buddy take it easy
Then wait for the PoC to drop like pretty much everyone else that may want to mess around with the CVE
sounds like a skill issue to improve don’t worry you got time🫡
Lmao
time to learn?
Or look through the source of chrome itself and look what they do updated in the git log
always got time to learn😂
Chrome is open source
Not 0xVader saying lmao in same chat as him 
The engine... Not the browser
What? It’s funny
yeah, any hints or good ressources if i were to code it myself
yeah start with linux next time
Yeah code it on kali Linux
Using vim
Nah this was a good. Question
Its still general
9 weeks without new windows machines.. why
Patch diff the pre/post CVE versions, look at what changed, perform code analysis on that to identify the issue, code exploit, ???, profit?
Maybe next week
Don't steal my method
I will report you
ToastedToaster, you are a genius, a guy that you dont even know ask for help on a platform desgined for it, and you tell me to use vim. you are truly pathetic
thanks to all that were noce to me
nice
shut up
if i cant even ask for hekp here where do i got
bro got rage baited 😭
@austere sinew
an fell for it🤣
may your god fuck all of yall tonite, you will have nightmares i will tell my voiodoo
it's hard to give you a hint for a resource on this, i don't think anyone here has dug deep enough to really know where or how the vulnerability works, but honestly google is your best friend, you've got all the resources in hands
what you can do to try and figure out where the vuln was is start by diffing the code, see what changed, and keep the vuln context in mind while doing it
remmber le
bros really mad😂
I will remmber le
I ping @lilac cipher
I leave.
But, i can't leave...something is blocking the door....
It's ZQA. He has a knife.
Thats right
Most of the "security research" are google 6th 0day path and a quote to some other. Place which say some. Thing
Literally copy. Paste
@sinful thorn come back in 1 hour 19min
And ask in cube talk

I think bro left
bro left 💀 RIP
yeah of course, gotta double check your sources and get your info from the right places
They seriously got pissed off because nobody would give them a poc for a 0day from earlier in the year, which has no publicly available poc?
Yes

yes
Newbies are so fucking funny lmao
IKR I could be a stand up comedian with how funny I am
I dunno, I feel freakin rotten today
NOOOOOOOO you have to give me the POC!!!! GIVE ME THE POOCC GRRRR.....;( 😭 NOOOO
Fair enough, feel better m8
Let me see if I can find some more painkillers
Not newbs but entitled
We got a cool newb @rustic carbon
I got an hour.. will see how I feel
Hmm? That’s good to know
get well g0blin ❤️
Hey Emma 🙂 Cheers
A cve from a day ago btw
How often the cube talks are held?
Every Friday
Had some fun earlier today working with a zero-knowledge proof verification of balance on a blockchain, without needing to have the users address commnicated or revealed to the backend... got it working, then realised.. oh.. holder addresses are listed everywhere, so it helps nothing 🤣
Felt so stupid
BUT I'm working in integrating Phantom for message signing to provide proof of ownership over the same mechanism
What @devout sail said
When do you think we'll get more SOC type challenges? There aren't many
Maybe that's why my head hurts so much
no wonder you need painkillers 💀
We have a lot of DFIR challenges
Stark?
We have a Blue CTF next week
Oh nice
Unsure Eggzy, sorry - I'm not involved with content these days
Np bud. Feel better
Nah, g0blin
bro is jarvis
Zkp could well replace passwords lol
ZKP? why not ZQA?
Mfw cookies still get around passkeys, passwordless, etc 🤣
Ill DM you...
Sure 🙂
🍪
Did you bring enough cookies to share with the class?
Do not reuse
I have mondel bread
We all know you hide seconds in that beard!
long bread vs short bread
∞
What is that
hexadeciamls
Dark font on dark background
How y'all see shit 🙃
No, it's potatoes
Roasted one 😋
Could be worse
When i have bbq, i eat potatoes and pineapple

Behold how it can be worse
Lavender is nice background
gahhhhhhhh light mode
I'm strange. I like pineapple flavor, but not pineapple the fruit. The texture gets me
BAN
lgtm 👍
lol I use dark mode but only swap to piss people off
HOLY JESUS CHRIST
fr though light mode burp >> dark mode
@scenic maple htb discord theme when
This i agree

I mean you can kind of do that now with the new nitro gradient crap
Get flash bang'd yall
i like dark mode on pretty much everything
Or css magic some people uses
light mode is flashbang for me
actually i think i had one
I only found out mIRC had dark mode recently thanks to @small pond
Otherwise flash banged myself daily
ippsec is the hero you needed
I don't really mind the light mode with readingmode (android shit)
It makes it yellowish, so doesn't burn much
There is a computer app called flux that does the same
I remember that irc one, i think it was in cubetalk
😃
What about rocketchat
bro has aw0ken the chat
Yeeee 💪💪💪
-# try not tagging me as much as you can pls I was studying 🥲
Btw since I'm here I gotta say I have a love hate relationship with Linux fundamentals rn
Rocket chat sucks
never forget
I been using Linux since the 90s
I can't even imagine using anything else.
I can't stand OSX or Windows
macOS I mean
Id like to but you keep bringing it back 🙁
I have a feeling this is where I'll be heading soon too lol
I catch myself using the parrot os more nowadays than my windows 11
whats the best way to organize notes, that you all have found? a rolling Document? Folders for different modules?
I have heard somewhere that Kali is mostly meant to be used in live mode that's why I use parrot as dualboot haha
Idk if that's correct or not but parrot is one hell of a distro
I installed Kali last year, I keep it updated
Hold up lemme check I'll tell you
Never gave me a crash or a problem
Sometimes I have to reboot the Kali machine because copy/paste in vbox stops working sometimes
But that's about it.
Type on tiktok "parrot os kali" and it's the dude with the name
/home/chiefgyk3d
Damn 💀
It's just Debian + the usual tools
not that much different from Kali
well if i'm installing a pentesting distro, the bloat is the point lol
You can yank shi out if you want to
Kali is based on debian testing, while Parrot is based on stable.
parrot is more stable for that reason
Ahh got it
However, kali is vetted
That makes sense
Meaning in some exams they don't allow you to use anything but kali, I heard.
I could be wrong
Kali got metapackages
does anyone have Parrot on MacOS? my laptop seems to be allergic to it 🤦
Hehe "vetted" didn't they lose a bunch of repo keys a year back?
But idk if there’s a parrot equivalent
I mean idk anything about Mac books..
Btw hello Wendy hru?
Good, solved the windows boxes yesterday
I hadn't heard about that. What happened?
i was a mac fan until i found this HTB community... now im realizing its no good for learning this skill
I'm still on Linux fundamentals doing MV cp and tree .
Ha! It was this year
Wow
If you made your kali install before it and then tried to update you'd end up in a shit storm
goofy but ultimately kali isn't intended to be a daily driver anyway so it's just not that big of a deal
Also, I didn’t sleep last night 💀
Yeah but I had to reinstall twice when doing a box cos of it
Oh so it's not just me 😭
Sleep servers are full frfr
I keep my Kali VM on 24/7 as a daily driver for many things. Ubuntu host underneath.
Funnily enough the more I learn about hacking the more I exclusively use mac
To each their own
Everyone feels at home with whatever
For example, I can't use any other window manager but Xmonad. I can't. I won't.
Why not Mac, I felt pretty good with Mac when I was a dev
I refuse! I resist!
any tips on how to get Parrot Security to work on this machine? its giving me hell
Please tell me you at least have it air gapped most the time
yeah, i mean it's less about feeling at home and more that the security profile on kali is not intended for it
No shared drives if that's what you mean. It needs networking.
Parallels is pretty good for virtualization, but many tools can run natively on mac
Kali is on a internal vbox network, and in front sits pfsense VM
bro blackarch does this almost daily
it should die
Just be a chad, use base Arch and make your own version of Black Arch 
Just use LFS at this point 
Bro, Arch ain't as hard as this, this is a nightmare
Arch is like: 3 commands, maybe 4 (ok probably like 10) to get completely set up with a working DE
i'm typing in slow motion
Arch will always be like rocket science for me
archinstall to save the day
DEs are for noobs! Real hackers use Xmonad WM 😄
LFS makes Gentoo look easy 
I tried using a live stick and I thought my computer was gonna explode
hides
Real hackers aren't afraid to use a mouse
-# Laughs in vim mode for everything
emacs evil mode 🙂
U guys ain't human 💀🥀
I should stream hacking a retired box one day, I'll need an epilepsy warning
That's why I only use a trackpad 
Thats where I am
I love my Orbit wheel mouse track ball
I use telekinesis
I use xmonad btw
Hey another Xmonad user
wow
You ain't a true vimmer unless you use: One Eyed Fighting Kirby
Twitch : https://twitch.tv/ThePrimeagen
Discord: https://discord.gg/ThePrimeagen
Support me (by becoming a backend dev): https://boot.dev/prime
Get production ready SQLite with Turso: https://turso.tech/deeznuts
Check out my Xmonad config 🙂
Bro uses emacs in xmonad
That's like putting a Campervan in a Ducati
any hacking today?
I use Doom emacs 🙂
I stand corrected, bro put a Tank in a Ducati
I actually switched to using KATE lately. I love KDE advanced text editor
Bro's gonna touch everything except for nvim
Fun fact: I first learned about vim motions when I first installed Emacs
now we're getting down to the real questions
I'm starting to use vim more and more compared to emacs don't know what's wrong with me
He zuming through the certs
I use kali in docker and arch on system
do people really use docker for pentesting as in the hacking system inside docker
Conducted a web test against an AI chat app this week and got some decent findings. Just finishing up reporting today
I do but I am an acquired taste

Any time
Interesting what did you find? AI related vulns?
How blind?
Mainly web vulns but one AI vuln
docker is goat
talks in 1200 seconds
Nice name color 💪
Good sir
bro became green

Question for experienced pentesters. You start a job (
) and you have 500 subdomains in scope. What do you do?
Run nessus
Or, say, 5000 or 50,000
@zealous charm approved method
short by the newest ones and start
Depends on the timeline. If I am given 5 days vs 5 weeks will change the coverage
ah
Capture scrernshot
never heard of it
Look
Gowitness >>
You should
Is the running eye witnesses of the vulnerated app
No witnesses>>>
oh redsiege, these people are cool
You have to chase them on the street and interrogate them
I may be dumb but what's the point of taking screenshots of the page?
To look
As for server header info you can get that in 10 lines of Python
At what?
Why reinvent wheel
At pages
...why? 🤣
Because the wheel shall be triangular
You mean default as in, stuff that may be incompletely configured?
everything is a triangle if you look close enough
rendering joke right there
Nice, well that would narrow down the scope. I'm always confused whenever I get a shit ton of subdomains because I have no idea where to start
its the zum zum
I just start from the longest name like prod-01-cloud-dev.something.com or whatever
That is why wheels are teiangular
im okayyyy getting ready for work
im out of adhd meds tho have t pick some up later
Who of the ppl here take adhd meds
Yeah so let's say a month for 5000 subdomains. First gather the scope into a file and kick of NNN (nmap/nessus/nuclei) to port scan and conduct basic vuln scans. If any interesting vulns come back, dig into those first. Then proceed with manual testing, which probably entails running screenshotting tool. This gathers screenshots/tech stack and some can check default creds. This should give more info to check out. From there I will prioritize apps running tech stacks like PHP, ASP/ASPX, perl (lol) before tacking more modern stacks
😄
NNN is an interesting stack
You sure nnn stands for that 
💯
yes sir, what else would it stand for 
Twice the efforts for half the results
N-nitrosonornicotine
That's a neat method which I'll keep in mind, thanks
No Nmap November 😢
Why half?
Server response is same everywhere
Acha
Dang
What's crackin, folks?
Crickets
^^
Destroy Docker December 
No Nmap November is becoming a thing
Uh oh lol
This is what I say to people when I don't wanna continue Convo
Same

No Math No more

How many triangles are that
69
I knew
Noted.
yo, is there a written chat to cube talks?
or where do people ask questions to the people talking?
I pinged you in the written chat for it
@drifting spire You may have checked this but as simple as it sounds - Discord doesn't swap the mic input/output settings even though you may do so on your OS. Check the discord voice settings and make sure your devices are the correct ones there.
hello is there any certificate for AI CTF of hackerone that ended today
🤣
very bad internet
Hey guys i just broke up w my gf
Ready to be a ctf player
And turn trans
Im done w the opposite gender
ok
This is how u get good right?
idk i am not good
Who said i was rage baiting
Your projecting
Maybe ur scared i will be better than u
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
I ping @scenic maple
u cant leave
Who will stop me
you
How
Oh right i forgor







