#general

1 messages · Page 30 of 1

sharp shuttle
#

vistaprint?

#

i buy like everything through them

#

i ordered company polos and they were nice and comfy

exotic pendant
#

I was also looking at tapstitch

#

They got some DARC like shirts

sharp shuttle
#

whatever is cheapest, they all use the same processing

exotic pendant
#

I am insanely picky about material lol

sharp shuttle
#

really? I figured youd be chill considering you had to wear a mil uniform for 90 years

exotic pendant
#

I like nylon

#

So it didn’t bother me

#

Darc makes good material shirts

rocky beacon
#

you opening your own company or?

exotic pendant
rocky beacon
#

aah

exotic pendant
#

We got a sick little name for the team

#

Corresponds to our company name

sharp shuttle
#

Totinos Frost Bites

rocky beacon
#

how many certs u got man kek

#

just seen your bio

exotic pendant
#

The Pizza Bites

rocky beacon
#

how u got the time for all that

woven plume
#

Hey guys

sharp shuttle
#

im not a guy...

woven plume
#

What chatroom for ctf related talks? I hear there’s a htb ctf currently

#

Sorry I meant guys as in humans

sharp shuttle
#

omg

#

im not a human!

woven plume
#

Humanoids*

exotic pendant
green kite
woven plume
sharp shuttle
rocky beacon
jolly tulip
#

Hello all

sharp shuttle
#

we all love glazing frost, but nobody glazes him more than me, hes mine chat

green kite
#

all yours @sharp shuttle

#

although I am a linkedin friend from frosto

#

but I bet he doesn't know

exotic pendant
sharp shuttle
#

pretty sure i have you on LI too sparkling

exotic pendant
#

Idk if I’ll get a cve in something AI before offsec ai con

#

I’ve been code reviewing ollama and onnx

#

Nada

green kite
jolly tulip
#

Is there some HTB admin to help me bye the exam voucher!??
I have some issues with my shopping card

sharp shuttle
#

all i have to do is check my mutuals with mto

west lynxBOT
exotic pendant
#

Maybe I’ll do an ai cert

sharp shuttle
exotic pendant
#

I just want certs

#

Or cves

heady sage
sharp shuttle
#

you ganna get my cert frost?

exotic pendant
#

I already grinded a few months of material last week

sharp shuttle
#

its all because of you im even doing drones

exotic pendant
#

Drone hacking will be bigger in the next few years

sharp shuttle
#

hoping my course sells because of it

exotic pendant
sharp shuttle
#

im banking on the dji ban this year

exotic pendant
#

Black Friday is coming up soon again

sharp shuttle
#

it seems like mike monnik isnt as passionate about dronesec, really sad

exotic pendant
#

Company has a drone we need to test

#

Big carrier one

sharp shuttle
#

dji t50?

exotic pendant
#

Nah I don’t have the model on hand

sharp shuttle
#

thos industrial lift drones are huge

#

i pentested one last month

exotic pendant
#

We also have a plane

sharp shuttle
#

you have a vtol?

exotic pendant
#

Idk model

#

But I know we got a plane for transferring stuff

#

Google says

#

Pilatus PC-12 and PC 24

green kite
#

nice

sharp shuttle
#

oh its a manned aircraft

exotic pendant
#

we have planes and drones

green kite
#

I love Pilatus'

exotic pendant
#

Separate

sharp shuttle
#

what are you transferring?

exotic pendant
#

Idk the drone model

sharp shuttle
#

medical supplies?

exotic pendant
sharp shuttle
#

that makes alot of sense

exotic pendant
#

Since we’re vampires

sharp shuttle
#

very neat

#

you get a discount on adrenochrome, very jealous

exotic pendant
#

SkeletonDance just happy it’s Friday

#

Got one pentest to finish up

signal mica
#

brath top 5 effective weapons against drones for a foot soldier?

exotic pendant
sharp shuttle
#

drone, drone, drone, drone, shotgun

signal mica
sharp shuttle
#

i wouldnt want to be a foot soldier in 2025

exotic pendant
#

Be a sailor

sharp shuttle
#

that might be even scarier

exotic pendant
#

Yeah nothing is scarier than going down in a sinking ship

sharp shuttle
#

cold war 2 is going to be artificially started once amd and dji get banned, and i think a drone swarm will be the black swan

#

against naval vessels

exotic pendant
#

Time to collect large sticks

sharp shuttle
#

buy a shovel

exotic pendant
#

Yeah but sticks are free

sharp shuttle
#

our salvation is under ground

exotic pendant
#

Me buying 100 shovels looks sus

#

Frost at the drone

sharp shuttle
#

lmfao

exotic pendant
#

Or my company becomes umbrella corp

#

And I’m half safe

sharp shuttle
exotic pendant
#

We’re implementing more AI. Next thing you know she secretly making it

signal mica
#

evil residents

exotic pendant
#

Ok my next recommendation to the ai team is to name it Red Queen

sharp shuttle
#

yep

signal mica
#

how temu app talks to me when i dont spend 10$ daily

sharp shuttle
#

everything ive bought on temu has been pretty decent

devout sail
#

Got :D

sharp shuttle
#

someone likes amber

signal mica
#

it looks like genshin character

sharp shuttle
#

im more of a ninguang enjoyer, i would submit to mommy rock goddess

devout sail
sharp shuttle
#

thats cool, in your wallet is crazy

devout sail
sharp shuttle
#

when i played that game i only leveld up geo characters, so noelle and ning were my bitches

deft bay
#

what is the string called that anti-viruses use to test?

#

starts with an e

deft bay
#

no

meager kernel
deft bay
#

it's like a test string to see if the AV works

#

you download the file and it flags

signal mica
#

eicar?

deft bay
#

yesss

#

ty

sharp shuttle
#

damn i didnt even know that

#

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

signal mica
#

look at it being all virus lookin ahh

sharp shuttle
#

til about eicar

devout sail
gentle bronze
#

good morning/ evening all

signal mica
devout sail
#

It was fun tbh

sharp shuttle
#

genshin is a good ass game, im not even a weeb, i look forward to when its all done and they make everything in it free

devout sail
#

But device gave up around that snowy mountains
Too much to render
It was hard to play

signal mica
#

what makes genshin good

gentle bronze
sharp shuttle
#

good gameplay loop, nice to look at, extremely well thought out evironments and cut scene/animations

gentle bronze
#

and chara

sharp shuttle
#

its like breath of the wild on steroids

signal mica
#

i understand now

deft bay
#

and it just popped up again

sharp shuttle
#

the chinese make america look like total bitches in the modern day

gentle bronze
#

can i ask you peoples something?

signal mica
#

YES BRATH GOOOD + 20000000 POINTS

sharp shuttle
#

just ask

sharp shuttle
devout sail
devout sail
gentle bronze
# sharp shuttle just ask

well currently I'm working in a team for my colleges CTF and i was assigned to make a question on data forensic can someone help me with and guide me and I'm relatively new in this field

visual hollow
gentle bronze
sharp shuttle
#

genuine advice is to work with chatgpt

devout sail
gentle bronze
gentle bronze
sharp shuttle
#

25% chance

gentle bronze
gentle bronze
sharp shuttle
#

being indian

meager kernel
#

india is like the biggest population

sharp shuttle
#

1.4 billion

meager kernel
#

and 67% of india aint even on the internet yet 💀

gentle bronze
meager kernel
devout sail
gentle bronze
meager kernel
#

im indian too bro 😭

gentle bronze
sharp shuttle
#

i got the new delhi belly

meager kernel
devout sail
#

Or is to dehli 💀

gentle bronze
devout sail
#

It looks nice

#

Might watch later

lime trout
#

wha

sharp shuttle
#

oh i heard its what happens when you eat the street food, mystery meat, and liquid concoctions

#

its like a tummy ache

gentle bronze
devout sail
#

Why 18+?

#

Nvm it's A

gentle bronze
gentle bronze
devout sail
#

Yeah you can still watch A

#

Maybe need permission or something

gentle bronze
#

why?

devout sail
#

I have never got any issue in movie theatres with ratings

gentle bronze
#

i can watch and download it from college's server

devout sail
#

Tell me your college name

gentle bronze
devout sail
#

I'll tell them students are being sussy

#

Mr. Nerd in chat

gentle bronze
devout sail
#

Ok

signal mica
#

Board got fried

gentle bronze
devout sail
#

India

gentle bronze
devout sail
#

The best one

gentle bronze
#

bhiar?

#

mp?

#

up?

devout sail
gentle bronze
#

and city?

signal mica
#

Shadow can i visit india and crash at ur crib for a week?

sturdy thistle
#

almost weekend guys

gentle bronze
devout sail
devout sail
gentle bronze
wet gale
#

gng which is the easiest actuve machine

#

active*

#

tell

tidal yoke
#

Did you go to Mind The Sec in São Paulo?

#

Good morning

late nexus
#

i cant find malware reversing challenges in htb

wet gale
green kite
#

not all CTF challenges are available on the platform/for free

gentle bronze
#

does anyone know how to make ctf question on data forensic to use tools like autospy, nmap, etc?

wet gale
#

hmm

wet gale
#

so now

#

i thought of doing the artificial box

#

what am i supposed to do in it?

green kite
#

#boxes would be more apropriate @wet gale

late nexus
#

how do you guys usually do windows RE challenges in linux

#

is wine fine ?

heady sage
#

Just use a windows vm

green kite
#

👋 @heady sage

#

how you doing sweetie

heady sage
#

I’m okay

green kite
#

ok 👌

late nexus
heady sage
#

I’m trying to understand Kerberos delegation a bit better so I’ve been on the same academy page for weeks now

green kite
#

maybe this guy can help

heady sage
heady sage
green kite
#

ok lol

heady sage
#

You mocking me?

zealous charm
green kite
#

now why would you think that

heady sage
zealous charm
#

Hello! Happy friday

heady sage
#

Not really since I’m trying to understand this dumb academy module rather than just simply go through it

zealous charm
#

Kerberos delegation?

heady sage
#

Yes

zealous charm
#

Specifically constrainted/unconstrained/RBCD? Or just how it works overall

#

tickets 'n shit

austere sigil
#

Henlo

zealous charm
warped plank
zealous charm
#

Yes not every service is configured for delegation because not every service needs to request resources on behalf of the user

#

Hence why generally app servers are configured with delegation

#

This is also just a quick draw.io sketch, I’m sure Microsoft has better diagrams in their documentation

heady sage
zealous charm
#

constrained = app server can only request on behalf of specific services
unconstrained = app server can request on behalf of any service

heady sage
#

I get that

zealous charm
#

In this diagram we cant really know if it is unconstrained vs constrained. We see it asking for the backend, and if that is the only service it can handle then it is constrained to that one service

frail lake
#

finally.

devout sail
#

Hehe

#

How rusty was it

frail lake
#

lol

limber arch
#

Like finding a key in a haystack

burnt parcel
#

did my first one today, just rooted Cap lol

frail lake
#

a lot of rage for sure.

burnt parcel
#

felt like idk what after this one already lmfao

frail lake
#

I know the feeling. It's very rewarding. Just be humble, keep improving silently...

burnt parcel
frail lake
#

100%

burnt parcel
#

wanted to do a blue team one

frail lake
#

Hahaha feel it as much as you can

burnt parcel
#

the new sherlock ones seem interesting... then my package manager came in a broken state - damn that broke the spirit lol

frail lake
#

I'm not gonna talk about how much anger I felt doing the machine above. I was so determined to do it though.

burnt parcel
#

how long did it take u ?

frail lake
#

I don't know but I've been doing it for a min

burnt parcel
#

lol like days or hrs xD

frail lake
#

Probably like a day or 2

burnt parcel
#

feel like i need all the basics to get the harder machines done right?

#

because this was a lot of googling and being insecure all at the same time + maybe using a guide to see the exact commands lol

frail lake
#

You definitely need basics to do the machine, but they're not required for you to try.

#

Everybody fails boxes. I like putting myself in harder situations knowing i'm gonna ask for help later

#

But that has worked for me, i've improved doing that

burnt parcel
#

my guy you are top 500 worldwide, damn

scarlet vortex
#

Hmm

frail lake
#

Although I don't think it's much, I definitely don't deserve it lol

#

I need to learn how to hack man

burnt parcel
#

well, it is waht it is 😄

#

so do we all, but its still somethign to keep you motivated to keep pushing 😄

frail lake
#

Yeah I don't look at my rank anyways I just wanna learn everything else is a byproduct

burnt parcel
#

there s a polish guy who pwned all boxes, kinda like that story overall

#

yeah, ofc it doesnt mean "A LOT"; but for sure means u r on track, thats whats important

#

like 1% better every day^

frail lake
#

Nice way to look at it

burnt parcel
#

theres thsi theory of 1%

#

if u get 1% every day, thats 36x better than u were than d1 ^^

frail lake
#

I hope I do get 1% better everyday

#

Setting up smaller goals until you reach your main one is the way to go always

burnt parcel
#

yeah, what i also love is that it gets much easier every day...

#

like when u know a thing or two its much easier to learn the 3rd on the fly

exotic vigil
#

Im only on my third module "setting up". I kinda get jealous of you guys who can do challenges and activities 😂 I know you didnt start off knowing how, but I want part of the action 🤦

burnt parcel
frail lake
burnt parcel
#

TRY to be organized, ... just a reminder: paper doesnt work lmfao

frail lake
#

Keeping track of things on paper doesn't work but i have a board on my wall where i write shit and take a look at it everytime i do boxes to remind myself of things

burnt parcel
#

same for me, really need to write stuff down

#

got notion, too but im not using it effectively

#

also not sure what to write down and what not really

exotic vigil
frail lake
#

I just write down anything that I feel like is useful or that I'm gonna forget later

near swift
#

Hi guys question I have

ASUS ROG Strix G15 (2021) Gaming Laptop, 15.6” 300Hz IPS Type FHD Display, NVIDIA GeForce RTX 3070,

Should I replace with mac air ?

frail lake
#

which mac air

burnt parcel
#

drako do u wanna game or nah?

near swift
#

M4

burnt parcel
#

u dont need a 300hz ips fhd display for HTB i guess lol

#

m4 is amazing

near swift
#

I have m4 ipad with magic keyboard as well

frail lake
#

yeah m4 is good also youre comparing a gaming laptop to a machine thats used for work (mainly)

burnt parcel
#

m4 is great, for sure

exotic vigil
burnt parcel
#

i still have my mbp 2019 with intel i9, but the m4 is a beast

burnt parcel
near swift
#

For sure

frail lake
#

it narrows down to what you want to do. Also yes as ElJefeDelTaco said, i'd buy a pc so that i can upgrade the parts later unless you want something portable

burnt parcel
#

at the same time... do u guys rlly wanna upgrade it? I just get new hw every x years like a cycle

near swift
#

I being honest since I got my desktop I barely use my asus laptop

burnt parcel
#

like my mbp 2019 is soon gonna get upgraded (as the need arises) but it is just working perfectly until now, so i dont have the need

frail lake
burnt parcel
exotic vigil
#

im on a macbook pro now and i hate it! it makes me feel less than worthy to be learning such a technical skill

near swift
#

You can have Kali in mac and can do hack the box ?

exotic vigil
#

my personal opinion; laptops are inferior and ive been a tech since 2015

burnt parcel
#

jefe lol i had that, too but i can tell u this... all of ciscos emplyoees i know are rocking macs... 🙂

#

its not the peripheral u r using directly, its the one u r remotely accessing

supple plume
#

Cube talks in 2h

limber arch
#

I like my MacBook

exotic vigil
burnt parcel
#

which u r gonna do if u r into this... its just important to ssh smoothly 😄

limber arch
#

Depends on what you do with it though

burnt parcel
supple plume
#

Is a weekly talk

burnt parcel
#

whats the topic gonna be ?

near swift
supple plume
#

Staff from htb answer our questions

limber arch
#

Won’t be the same without 0xfd

#

🙁

burnt parcel
# exotic vigil i concur! touche

ill give u an example... i have a T14 lenovo (love that thing) ; got parrotOS directly on it so i dont have to use a VM;
Now i put 16gb ram slot in it (total of 24, i know, not optimal but it works perfectly) - thing isnt fast but it can do all u need on it for this type of work

burnt parcel
#

idk the guy but feel u lol

limber arch
#

A diff company

#

I forgot which one

near swift
#

Only reason I don't want mac because I got 13inch m4 Ipad with magic keyboard and since iOS 26 everything same

burnt parcel
#

ipad and macbook arent that close imo

#

like i dont know if u can code on the ipad?

burnt parcel
#

why d u think that?

zealous charm
woeful mauve
#

Idk must be the profile picture

burnt parcel
#

im not used to sarcasm on htb 🙁

woeful mauve
burnt parcel
#

its all good my guy

#

now its on me to make a bad joke about blue and red?

woeful mauve
lime trout
woeful mauve
#

i thought you were Nameless0ne guy at first

burnt parcel
#

your name is, too kinda

lime trout
#

so you can run most tools directly on it

burnt parcel
#

thats true emma but for us noobs its complicated to realize that

lime trout
#

tbf, ipads have the same chips

#

they could do more

burnt parcel
#

like i get the family parts but just considering that a newbie doesnt udnerstand zsh and bash differencs in the terminal

lime trout
#

but theyre capped by the OS

lime trout
#

and you can switch

burnt parcel
lime trout
#

i use ZSH on all my GNU + *Nix

#

pwnbox also works from an ipad 😉

burnt parcel
#

yeah that could be but i dont have zsh in my work environment and i wanna use it as easy as possible; learning 1 to have maximum output in day2day

muted olive
#

hello chat

burnt parcel
#

it confuses me already how to use ftp commands vs ssh commands; so adddingg more just adds fuel to the fire of too little knowledge

#

if u get what i mean

lime trout
#

using commands is the exact same with both zsh and bash

#

its calling the same underlying bin files

vivid flower
burnt parcel
#

fair point, what about bash scripting for automization?

lime trout
#

but adds extra stuff on top

#

i just like oh-my-zsh

#

and the prompts

burnt parcel
vivid flower
#

Cool stuff i still use an x230 for similar reasons

frail lake
burnt parcel
lime trout
#

yeah

burnt parcel
#

gotta get that on my mac

#

a terminal without a color config is hell

vivid flower
burnt parcel
#

makes it so much easier to wrok with if they made it pretty beforehand

burnt parcel
rustic carbon
burnt parcel
#

like maybe u know how kids in developed countries do wheelies on perfectly built lightweight ktm dirtbikes,
whereas kids in brazil do the craziest stuff on just regular bikes which werent optimized for the tricks etc...
Its just how much time u put into this

zealous charm
#

@static pasture get pinged sucka

lime trout
#

And it boils down to personal preference and your workflow and requirements

burnt parcel
#

idk what i need special functionality my t14 has compared to some other laptop; the problem usually sits in front of the pc

static pasture
#

@zealous charm eat my ping sucka

lilac cipher
#

@zealous charm eat this as well sucka

zealous charm
burnt parcel
#

emma and myself are basically on the same page about it root rose,
as long as it works, run with it, make miles

static pasture
lilac cipher
#

Do it

#

Execute order 66

static pasture
#

This isnt ISP....

burnt parcel
#

really like the zsh description for this:
Oh My Zsh is an open source, community-driven framework for managing your Zsh configuration.

Sounds boring. Let's try again.

Oh My Zsh will not make you a 10x developer...but you may feel like one!

static pasture
#

And its actually 329k people

lilac cipher
#

Oh dang u right

#

Only a little chaos would ensue

#

🤏

burnt parcel
#

wdym329k people?

static pasture
#

lol

burnt parcel
#

how is it so many lol

#

falcon is pinging small countries lol

zealous charm
static pasture
#

There are 329,000 people in this community

burnt parcel
#

holy f, i didnt even know lol

static pasture
#

ISP is pretty dope ❤️

burnt parcel
#

internet service provider?

static pasture
#

InfoSec Prep

#

Another Discord community

zealous charm
#

The community that spawned other communities laugh_cry

static pasture
#

Pretty much lol

burnt parcel
#

i just know about the infosec htb module 😄 or path idk waht it is

static pasture
#

InfoSec prep is a motley crew at this point since most of the other orgs spun up their own Discord

#

But yea it was a community server that had staff from all the big names out there in the industry

burnt parcel
#

motley
adjective: motley; comparative adjective: motlier; superlative adjective: motliest
1. incongruously varied in appearance or character; disparate.

hope that helps lol

static pasture
devout sail
burnt parcel
#

love how they used the word incongruously to explain anotehr word

zealous charm
rustic carbon
#

Oh shadow

#

Long time no talk

devout sail
#

Hello jckss

#

Yeah I was busy doing stuff

#

What happened to cube talk

#

It's weekend

rustic carbon
#

Same I'm now in Linux fundamentals I don't really use DC except of the cube talks

burnt parcel
# devout sail Nerd... Always use urban dictionary

motley
Behaviour associated with football fans and general 'laddish' behaviour.

Plural: Mots or Motz
guy 1 chanting in the street
Guy 2 - "Mate, you're so motley"

Guy sees a man dressed completely in Adidas
Says to friend - "Look at that motley {insert swearword with bas]!"

devout sail
rustic carbon
burnt parcel
#

yes, sbdy just announced it, it is in almostt 2hrs

devout sail
burnt parcel
#

less than 2h*

rustic carbon
#

Alright perfect talk to you guys in less than 2 hours

#

Cya

devout sail
lilac cipher
#

Never finish stuff

devout sail
zealous charm
rustic carbon
devout sail
#

Then i see them after a few months and gets confused

lilac cipher
rustic carbon
#

Anyway enough lacking I'm out 💀✌️

devout sail
#

Yeah shoo

zealous charm
devout sail
#

Oos?

thin peak
#

bhai?

devout sail
#

Bro

zealous charm
devout sail
lilac cipher
#

I will mark your report as closed

devout sail
#

The only. Bounty i get ^

sinful thorn
#

hello everyone, kind of important, where do i look if i really need to find ASAP a proof of concept for CVE 10585

devout sail
#

Google

sinful thorn
#

nothing on google

devout sail
#

Read the vulnerability and see what exactly it is

sinful thorn
#

this cve is like 1 day old

devout sail
#

Well then understand the vulnerability and. Make. One

lilac cipher
#

Not even valid cve number

static pasture
#

Most CVEs wont have an immediate PoC available unless the reporter published it themselves and usually only do that after an organization has had time to push out patches

sinful thorn
#

lol i am clearly in the wrong forum i though i was getting knowledgeable people

heady sage
#

Lmao

devout sail
heady sage
#

Pipsqueak pipe down

sinful thorn
#

the full name if you guys did not deduce is CVE-2025-10585, yes they add the year at the beginning

lilac cipher
#

What is cve?

#

Custom v8 engine?

exotic vigil
# burnt parcel ill give u an example... i have a T14 lenovo (love that thing) ; got parrotOS di...

Im having an extreme issue getting Parrot Security to run on my vmware i have on Macbook pro. im stumped; i tried two diff ways to get it to run and nothing. downloading it directly to the VM gave me a .vmdk file that the Windows 11 (ARM) couldnt open. Then i tried creating a new vm (downloading parrot to my desktop directly) and uploading the iso during the creation of the VM and it wont work. stumped currently

sinful thorn
#

Zumi you are right but i get a guy that tells ,e to google it, i mean if i got my answer via google i would not be here

sinful thorn
#

then i get another dude that tells me to code it myself

lilac cipher
#

Womp womp

sinful thorn
#

is there a more advanced forum?

devout sail
#

Yeah

static pasture
#

Like I said most CVEs that are just released wont have an immediate PoC available so the apps have time to create patches

heady sage
sinful thorn
#

an hour ago i got a call saying there was

zealous charm
#

Call back and ask them then?

static pasture
#

Then ask the person that told you the PoC was available where to find it

sinful thorn
#

man àxvader fuck you and fuck all of yall

#

àxVAder

#

àxvader

zealous charm
#

u tried

lilac cipher
#

Almost

sinful thorn
#

0xvader

patent elbow
lilac cipher
#

There you go

thin peak
lilac cipher
#

@patent elbow

devout sail
#

0xVader is definitely a tank
Getting full aggro

patent elbow
static pasture
#

I hear if we all just ping @maiden anvil they might just show up

heady sage
sinful thorn
#

lol

lilac cipher
#

@maiden anvil is that true.

devout sail
#

Ping @maiden anvil ? Idk that 🦀 so i don't think i should ping

sinful thorn
#

in all seriousness is there a forum for people that actually know how to do stuff? and not pretend to?

lilac cipher
#

Why don't you google

devout sail
sinful thorn
#

i thought HTB was the most advanced legally

zealous charm
#

Only LARPers here

lilac cipher
#

This is a LA roleplaying server

patent elbow
#

yes

#

we are all in LA

wintry flume
#

totally not florida or anywhere else

static pasture
#

@sinful thorn there are people that I am sure know how to do stuff here. Either teach yourself the thing you want (code it, google it), or wait for the PoC to actually drop.

sinful thorn
#

ok anywas nice meeting you guys

devout sail
sinful thorn
#

i dont think i can code a CVE for chrome i

wintry flume
sinful thorn
#

i dont have the expertise

#

i wish I had

static pasture
#

Then wait for the PoC to drop like pretty much everyone else that may want to mess around with the CVE

wintry flume
#

sounds like a skill issue to improve don’t worry you got time🫡

heady sage
#

Lmao

patent elbow
lilac cipher
#

Or look through the source of chrome itself and look what they do updated in the git log

wintry flume
#

always got time to learn😂

lilac cipher
#

Chrome is open source

devout sail
lilac cipher
#

The engine... Not the browser

sinful thorn
#

yeah, any hints or good ressources if i were to code it myself

wintry flume
#

yeah start with linux next time

limber arch
#

Using vim

devout sail
#

Nah this was a good. Question

lilac cipher
stiff mulch
#

9 weeks without new windows machines.. why

zealous charm
#

Patch diff the pre/post CVE versions, look at what changed, perform code analysis on that to identify the issue, code exploit, ???, profit?

devout sail
lilac cipher
#

I will report you

sinful thorn
#

ToastedToaster, you are a genius, a guy that you dont even know ask for help on a platform desgined for it, and you tell me to use vim. you are truly pathetic

#

thanks to all that were noce to me

#

nice

thin peak
#

shut up

sinful thorn
#

if i cant even ask for hekp here where do i got

wintry flume
#

bro got rage baited 😭

zealous charm
wintry flume
#

an fell for it🤣

sinful thorn
#

may your god fuck all of yall tonite, you will have nightmares i will tell my voiodoo

patent elbow
# sinful thorn yeah, any hints or good ressources if i were to code it myself

it's hard to give you a hint for a resource on this, i don't think anyone here has dug deep enough to really know where or how the vulnerability works, but honestly google is your best friend, you've got all the resources in hands

what you can do to try and figure out where the vuln was is start by diffing the code, see what changed, and keep the vuln context in mind while doing it

sinful thorn
#

remmber le

wintry flume
#

bros really mad😂

lilac cipher
#

I will remmber le

wintry flume
#

remember my wrath 🤓

proud moth
#

I ping @lilac cipher

I leave.

But, i can't leave...something is blocking the door....

It's ZQA. He has a knife.

lilac cipher
#

Thats right

devout sail
#

@sinful thorn come back in 1 hour 19min

#

And ask in cube talk

heady sage
#

I think bro left

proud moth
#

bro left 💀 RIP

patent elbow
eternal mango
#

They seriously got pissed off because nobody would give them a poc for a 0day from earlier in the year, which has no publicly available poc?

heady sage
#

Yes

eternal mango
proud moth
#

instead of being pissed off, how about building the PoC

#

i don't understand people

static pasture
#

@eternal mango join Cube Talk plz ❤️

heady sage
#

Newbies are so fucking funny lmao

warped plank
eternal mango
proud moth
static pasture
#

Fair enough, feel better m8

eternal mango
#

Let me see if I can find some more painkillers

devout sail
#

Not newbs but entitled
We got a cool newb @rustic carbon

eternal mango
#

I got an hour.. will see how I feel

heady sage
#

Hmm? That’s good to know

lime trout
#

👀

#

hi g0b

#

hope u feel better

proud moth
eternal mango
#

Hey Emma 🙂 Cheers

small breach
#

How often the cube talks are held?

devout sail
#

Every Friday

eternal mango
#

Had some fun earlier today working with a zero-knowledge proof verification of balance on a blockchain, without needing to have the users address commnicated or revealed to the backend... got it working, then realised.. oh.. holder addresses are listed everywhere, so it helps nothing 🤣

#

Felt so stupid

#

BUT I'm working in integrating Phantom for message signing to provide proof of ownership over the same mechanism

static pasture
worthy cargo
#

When do you think we'll get more SOC type challenges? There aren't many

eternal mango
#

Maybe that's why my head hurts so much

proud moth
#

no wonder you need painkillers 💀

worthy cargo
#

We have a lot of DFIR challenges

static pasture
worthy cargo
#

Oh nice

eternal mango
#

Unsure Eggzy, sorry - I'm not involved with content these days

worthy cargo
#

Np bud. Feel better

eternal mango
proud moth
lilac cipher
#

Zkp could well replace passwords lol

zealous charm
lilac cipher
#

Missed opportunity

eternal mango
#

Passkeys FTW

#

So awesome they are getting more traction now

static pasture
eternal mango
#

Seriously how is cookie reuse still a problem

#

in this day

#

🤣

static pasture
#

Ill DM you...

eternal mango
#

Sure 🙂

lilac cipher
#

🍪

zealous charm
lilac cipher
#

Do not reuse

eternal mango
#

I had shortbread, but ate it all, sorry

#

Also shortbread <> cookie

static pasture
#

I have mondel bread

zealous charm
#

We all know you hide seconds in that beard!

worthy cargo
#

long bread vs short bread

scenic maple
#

💪

devout sail
#

proud moth
#

plz

devout sail
#

What is that

scenic maple
#

hexadeciamls

devout sail
#

Dark font on dark background
How y'all see shit 🙃

eternal mango
#

No, it's potatoes

devout sail
#

Roasted one 😋

eternal mango
#

Damn it

#

Now I want roast potatoes

scenic maple
#

arguably roasted is better

static pasture
devout sail
#

When i have bbq, i eat potatoes and pineapple

devout sail
static pasture
#

Behold how it can be worse

devout sail
#

Lavender is nice background

ornate wren
worthy cargo
#

I'm strange. I like pineapple flavor, but not pineapple the fruit. The texture gets me

eternal mango
zealous charm
static pasture
#

lol I use dark mode but only swap to piss people off

proud moth
eternal mango
#

heheh

#

Back in a bit

zealous charm
#

fr though light mode burp >> dark mode

lilac cipher
#

@scenic maple htb discord theme when

lilac cipher
devout sail
static pasture
#

Get flash bang'd yall

proud moth
#

i like dark mode on pretty much everything

devout sail
#

Or css magic some people uses

proud moth
#

light mode is flashbang for me

scenic maple
static pasture
#

I only found out mIRC had dark mode recently thanks to @small pond

#

Otherwise flash banged myself daily

scenic maple
#

ippsec is the hero you needed

devout sail
#

I don't really mind the light mode with readingmode (android shit)
It makes it yellowish, so doesn't burn much

zealous charm
#

There is a computer app called flux that does the same

devout sail
young glen
#

😃

worthy cargo
#

mIRC is the best windows IRC client by far

#

Rocketchat is too... resource consuming

zealous charm
#

bro has aw0ken the chat

rustic carbon
#

Btw since I'm here I gotta say I have a love hate relationship with Linux fundamentals rn

static pasture
zealous charm
worthy cargo
#

I been using Linux since the 90s

#

I can't even imagine using anything else.

#

I can't stand OSX or Windows

#

macOS I mean

static pasture
rustic carbon
#

I catch myself using the parrot os more nowadays than my windows 11

exotic vigil
#

whats the best way to organize notes, that you all have found? a rolling Document? Folders for different modules?

worthy cargo
#

I use Kali. Kali is better for me.

#

I also have Parrot

rustic carbon
#

I have heard somewhere that Kali is mostly meant to be used in live mode that's why I use parrot as dualboot haha

worthy cargo
#

Where did you hear that?

#

That's not true at all.

rustic carbon
#

Idk if that's correct or not but parrot is one hell of a distro

worthy cargo
#

I installed Kali last year, I keep it updated

rustic carbon
worthy cargo
#

Never gave me a crash or a problem

#

Sometimes I have to reboot the Kali machine because copy/paste in vbox stops working sometimes

#

But that's about it.

rustic carbon
#

Type on tiktok "parrot os kali" and it's the dude with the name
/home/chiefgyk3d

worthy cargo
#

I don't use tik tok

#

Never installed it

rustic carbon
#

Damn 💀

warped plank
#

not that much different from Kali

rustic carbon
#

I heard that Kali is more bloated..

#

That's what I heard I'm no expert obviously 💀

ornate wren
warped plank
worthy cargo
#

Kali is based on debian testing, while Parrot is based on stable.

#

parrot is more stable for that reason

rustic carbon
#

Ahh got it

worthy cargo
#

However, kali is vetted

rustic carbon
#

That makes sense

worthy cargo
#

Meaning in some exams they don't allow you to use anything but kali, I heard.

#

I could be wrong

crude lynx
#

Kali got metapackages

exotic vigil
#

does anyone have Parrot on MacOS? my laptop seems to be allergic to it 🤦

warped plank
crude lynx
rustic carbon
#

Btw hello Wendy hru?

crude lynx
#

Good, solved the windows boxes yesterday

worthy cargo
exotic vigil
#

i was a mac fan until i found this HTB community... now im realizing its no good for learning this skill

warped plank
rustic carbon
#

I'm still on Linux fundamentals doing MV cp and tree .

warped plank
#

Ha! It was this year

worthy cargo
#

Wow

warped plank
#

If you made your kali install before it and then tried to update you'd end up in a shit storm

ornate wren
#

goofy but ultimately kali isn't intended to be a daily driver anyway so it's just not that big of a deal

crude lynx
warped plank
rustic carbon
#

Sleep servers are full frfr

worthy cargo
#

I keep my Kali VM on 24/7 as a daily driver for many things. Ubuntu host underneath.

zealous charm
worthy cargo
#

To each their own

#

Everyone feels at home with whatever

#

For example, I can't use any other window manager but Xmonad. I can't. I won't.

crude lynx
#

Why not Mac, I felt pretty good with Mac when I was a dev

worthy cargo
#

I refuse! I resist!

rustic carbon
#

Anyway I'm gonna go back to studying guys

#

See ya in cube talks

exotic vigil
warped plank
ornate wren
#

yeah, i mean it's less about feeling at home and more that the security profile on kali is not intended for it

worthy cargo
zealous charm
worthy cargo
#

Kali is on a internal vbox network, and in front sits pfsense VM

scenic maple
rustic carbon
#

This still exists?

#

I thought it was outdated

scenic maple
#

it should die

warped plank
#

Just be a chad, use base Arch and make your own version of Black Arch 02kek

scenic maple
#

can confirm the above works

#

almost every arch fork is shit

warped plank
#

Arch is like: 3 commands, maybe 4 (ok probably like 10) to get completely set up with a working DE

tiny canyon
#

i'm typing in slow motion

rustic carbon
#

Arch will always be like rocket science for me

scenic maple
#

archinstall to save the day

worthy cargo
#

DEs are for noobs! Real hackers use Xmonad WM 😄

warped plank
#

LFS makes Gentoo look easy 02kek

rustic carbon
#

I tried using a live stick and I thought my computer was gonna explode

worthy cargo
#

hides

warped plank
#

-# Laughs in vim mode for everything

worthy cargo
#

emacs evil mode 🙂

rustic carbon
#

U guys ain't human 💀🥀

warped plank
rustic carbon
#

Yeeee

#

lol speaking of vim

zealous charm
rustic carbon
#

Thats where I am

worthy cargo
#

I love my Orbit wheel mouse track ball

rustic carbon
fierce vale
#

I use xmonad btw

worthy cargo
#

Hey another Xmonad user

thin peak
#

wow

warped plank
worthy cargo
warped plank
#

That's like putting a Campervan in a Ducati

zealous charm
#

any hacking today?

worthy cargo
#

I use Doom emacs 🙂

warped plank
worthy cargo
#

I actually switched to using KATE lately. I love KDE advanced text editor

warped plank
#

Bro's gonna touch everything except for nvim

worthy cargo
#

I can't stand vim dude

#

I never could get used to insert mode and escape mode

warped plank
#

Fun fact: I first learned about vim motions when I first installed Emacs

fierce vale
#

now we're getting down to the real questions

#

I'm starting to use vim more and more compared to emacs don't know what's wrong with me

zealous charm
#

He zuming through the certs

supple plume
#

I use kali in docker and arch on system

scenic maple
#

do people really use docker for pentesting as in the hacking system inside docker

zealous charm
#

Conducted a web test against an AI chat app this week and got some decent findings. Just finishing up reporting today

supple plume
scenic maple
muted olive
zealous charm
#

Any time

muted olive
lilac cipher
#

How blind?

zealous charm
supple plume
#

htb talks in 1200 seconds

zealous charm
lilac cipher
#

Good sir

scenic maple
#

bro became green

lilac cipher
muted olive
#

Question for experienced pentesters. You start a job ( PepeProtecc ) and you have 500 subdomains in scope. What do you do?

lilac cipher
#

Run nessus

muted olive
#

Or, say, 5000 or 50,000

lilac cipher
#

@zealous charm approved method

scenic maple
#

short by the newest ones and start

zealous charm
#

Depends on the timeline. If I am given 5 days vs 5 weeks will change the coverage

muted olive
#

lets say you're given a month

#

eyewitness? 👀

lilac cipher
#

Tool

muted olive
#

ah

lilac cipher
#

Capture scrernshot

muted olive
#

never heard of it

lilac cipher
#

Look

zealous charm
#

Gowitness >>

lilac cipher
supple plume
#

Is the running eye witnesses of the vulnerated app

lilac cipher
muted olive
#

oh redsiege, these people are cool

supple plume
#

You have to chase them on the street and interrogate them

muted olive
#

I may be dumb but what's the point of taking screenshots of the page?

muted olive
#

As for server header info you can get that in 10 lines of Python

muted olive
lilac cipher
lilac cipher
muted olive
supple plume
muted olive
#

You mean default as in, stuff that may be incompletely configured?

scenic maple
#

rendering joke right there

muted olive
#

Nice, well that would narrow down the scope. I'm always confused whenever I get a shit ton of subdomains because I have no idea where to start

solemn lichen
#

its the zum zum

muted olive
supple plume
solemn lichen
#

im okayyyy getting ready for work

#

im out of adhd meds tho have t pick some up later

supple plume
#

Who of the ppl here take adhd meds

zealous charm
# muted olive lets say you're given a month

Yeah so let's say a month for 5000 subdomains. First gather the scope into a file and kick of NNN (nmap/nessus/nuclei) to port scan and conduct basic vuln scans. If any interesting vulns come back, dig into those first. Then proceed with manual testing, which probably entails running screenshotting tool. This gathers screenshots/tech stack and some can check default creds. This should give more info to check out. From there I will prioritize apps running tech stacks like PHP, ASP/ASPX, perl (lol) before tacking more modern stacks

exotic pendant
#

😄

scenic maple
zealous charm
#

yes sir, what else would it stand for krappa

devout sail
muted olive
muted olive
devout sail
#

No Nmap November 😢

muted olive
#

Server response is same everywhere

meager kernel
supple plume
rustic carbon
#

What's crackin, folks?

devout sail
#

Crickets

rustic carbon
#

^^

muted olive
#

Destroy Docker December Kappa

supple plume
rustic carbon
devout sail
supple plume
#

1140 secs to cube talks

#

Aprox

devout sail
supple plume
#

1080

#

Tf my math are bad

devout sail
#

Don't do math

#

Say no to math

supple plume
#

No Math No more

muted olive
#

my beloved

devout sail
supple plume
muted olive
#

69

supple plume
#

I knew

devout sail
soft fern
burnt parcel
#

yo, is there a written chat to cube talks?

#

or where do people ask questions to the people talking?

warped plank
stable hazel
#

@drifting spire You may have checked this but as simple as it sounds - Discord doesn't swap the mic input/output settings even though you may do so on your OS. Check the discord voice settings and make sure your devices are the correct ones there.

lilac cipher
#

I ping @warped plank

#

I leave

upper swallow
#

hello is there any certificate for AI CTF of hackerone that ended today

eternal mango
ornate ibex
zealous charm
lilac cipher
rich radish
#

Hey guys i just broke up w my gf

#

Ready to be a ctf player

#

And turn trans

#

Im done w the opposite gender

scenic maple
#

ok

rich radish
#

This is how u get good right?

scenic maple
#

idk i am not good

rich radish
#

Who said i was rage baiting

#

Your projecting

#

Maybe ur scared i will be better than u

west lynxBOT
lilac cipher
#

I ping @scenic maple

scenic maple
#

u cant leave

lilac cipher
#

Who will stop me

scenic maple
#

you

lilac cipher
#

How

scenic maple
#

idk you know

#

i am not you

#

i am me

lilac cipher
#

Oh right i forgor

static pasture
#

@heady sage DM me plz

#

Need to run shortly