#general
1 messages · Page 70 of 1
Someone's trash is another person's web server.
This site itself is hosted on vape
Why azomax 💀
reported
So guys I have been thinking
Banned
Do it or I rename myself to VaderRedTeamer
I'm doing hacktricks GRTE 😎
You shoulda done Azure
Is it good u did it?
Nah it would’ve gone perfectly with your AD experience
He recommends and doesn't do
Also CRTO, or ARTOC
Mainly because I don’t have the money!
All on-prem stuff is on hold cause i need to fully master the cloud
My job is mostly cloud
Ah makes sense
Money is man made things
All you need is a will to do
HTB paid for my CPTS
The CRTA was paid for by like 10 dollars I scraped together
And ODPC
Well I got that paid for too
🚬 🚬
All asia?
All good, I’m joking
Yeah, so even though I'm world wide handsome, only Asian women will get in my good graces
-# jk I'm ugly as shit
Prove it
👨🦯
nice i have yet to bag an asian shawty
@hoary nebula something is afoot with my anbernic package delivery
i live in asia so yea suckas i bagged some asian baddies before yall
😂
how do they turn cows into red stuff


nvm
I’m bregnant
yes but asia is way big
you gotta atleast round it down to a region in asia
East Asia
🔥
@pliant scroll
he likes North Korean women
Preferably APTs

APT 28🔥
I barely touched you 😢
How about Annoying Persistent Friends instead
pov gubarz in htb general?
💯
Good morning to you all :). If your like cybersecurity and ham radio, theres a new TG on brandmeister (DMR) who will be up during the canadian cybersecurity event (Hackfest - 13 to 18 October) this year. If the interest is there, the TG will remain open after it :). So if you want to talk cyber over the air, feel free to jump on the TG: 30288. 73 ps: the tg is already up 🍻
whats a tg
A talkgroup
how do i join that
it s like a channel but for radio 🙂
ohhhh i need a radio?
yhea you need to have your licence :), but you can listen with the web page if you dont have it 🙂 (and other countries etc hihi) https://hose.brandmeister.network/?subscribe=30288
nope
anyone ever had experience with bloodhound showing a group but using net groups /domain "GROUP_NAME" it doesnt exist?
Have you cleared bh database
Maybe you are looking at old bh inputs?
well i added myself to a group, cleared db, re-ran bh ingest script and uploaded data and it shows the updated group membership but the mystery group is still present

I like the mystery group sounds classy
Most peculiar
can't find anything at all on it
Hello

Hacker wifes!!!!!!!!!!!
Could be good but unsure
I think only bad hacker girls will be the most attractive
The good hacker girls should probably be stinky
we are tho-

do they even exist
i dont think so
ive only seen one girl in this whole server
undoubtedly so cos good hacker boys actually work out
bad hacker boys always in AC'd dark rooms
btw whats OSI
forgot layer 8
im prob failing science again
nearly time to finish for the day and get the kids
and maths
Ive never met a girl with a real understanding of these topics. If you have a wife you have to teach her
It’s that time of year
Morning sparkles
someone gimme 8 doolar
apparently🔥
tho happy anniversary
... or risk sleeping on the couch
we already sleep separately due to the kid

thou kid shall not gethet in your way today
Did you get your wife socks?
I got nothing
Bring your mower you can move in with me until the dust settles
@heady sage speak!
Huh

What is it?
he wants to hear your voice
woof woof I think

I love SQLi.
Nah 😭
Access when
Sorry I was testing on your system
Guys which AI do you use for your daily work
Gemini or ChatGPT?
.
anyone wanna have a crack at why its not working?
Bloodhound says members of Exchange Enterprise Servers (which I am in as per my Powershell screenshot) have WriteDacl on Group Exchange Windows Permissions, but it doesn't let me add myself?
I even use those ai gf bots
Hi, i have a question, is 2hrs of pwnbox enough to learn the course
It depends. Are u willing to put on the hours to be a real hacker
I'm not talking boxes
I'm talking real lethal hacker in the premises
not really i just do it for fun
Then the answer is 99999 hours
so 2hrs is enough to learn the basic concepts?
You should be able to finish insane under 30m so 4 insanes
Oh u are not joking 👁️👁️
Just use your own VM
hmmm, i am very new to this what is insane?
Yea i switched my whole os for this shit
i think he means instance
Ignore me, I was just saying random shit
oh i guess i will go find out about this
hacking my way through meetings
u dont use vm?
umm i deleted it a while ago
why.
now i picked up hacking so i guess i will downloaded it back
uh idk
I load my VMs into memory 
i forgoted, it was like 2 years ago
what do you recommend
Anyone know or got any ideas?
Ask the server politely
vmware
this: https://www.vmware.com/ ?
yep
which one
hard to find on their site but should be VMWare workstation
so complicated
That's VMware for you
Broadcom*
yea ig workstation
thanks
Virtual box 
what os u use btw
🤓

I don't know what's the question but please add 1 hour
So year of the linux desktop is here.. windows disables any bypass to use a local account and requires Microsoft account sign in.
and that's how you force Arch users to use FreeBSD
yes surely this will be the year of the linux desktop
That was impolite?
Im not even playing games much anymore so I really have no excuse to stay on windows at this point
year of the windows server 2025
Don't do that just use VMs
I just got a desktop again after being stuck with only my macbook for the last 8 months and im thinking peace out windows
Like a windows VM you’re saying?
Why did the developer go broke? ||Because they used up all their cache||
@maiden anvil

pls no ping
plz no ping extremely busy
how to hack sir
i have downloaded the nmap
Never run nmap
helo i tech hack u hae to run sudo nmap sudo -p127.0.0.1 80-65535
to snac all ports first

ok now what
use naabu
oh man if you mess up cache in nextjs you are going broke
cloud providers will come after yo house yo land yo cows too
n̷̐͌͑́ố̵͝͠ ̸̀̈́̕͝p̷̻̦̉ͅi̵̭̋̉͂n̸̔̈̔̕g
Now tracert sir
v̷̓̄̓͝ĕ̴̂̀̀r̶̄̽̃̒ỹ̶̿̀̏ ̸͛̀͗̄ḃ̴̓͗̅usy
Shut up
☠️
pooping grounds
@lilac cipher really listening to murdur on my mind rn
i got murder on my mind
free melly
he is out already no?
UH OH STINKY
Dont talk about yourself like that
There's a fresh troll in jail on ISP if ya want
hmmm i love fresh meat
I love butter chicken
Where did the IT guy go ?
|| he probably ransomewhere ||
you wanna see real ddos attack?
run ping target.com over and over in terminal
How to run that
Can it hak my frind
What's a dog's favourite food? ||Kerberoast Beef.||
🗣️ 🗣️ 🗣️

Why do hackers never skip leg day? ||They do a lot of lateral movement.||
fucking cringe
💀 😭
please banish yourself
How did the farmer sell his produce on the dark web? ||He used onion routing.||
i ain't clicking that cringe

||(u already did but w/e)||
Want to unlock the chamber of secrets? Don't speak Parseltongue, just read a public key out loud.
Sup chat
finally some peace
lmao its literally my chat rn
@lilac cipher
😩
@lilac cipher
LOL

||@lilac cipher ||
now do it 3 times in a rapid succession
you should do it too
?
??
Guys
masoud
Idk u ss it I’m lost
My pronouns is Dark Dragon Knight
😂
oh not you
i ignored @muted olive
and you just fell into the crosshairs
I ping @subtle plover
I leave
too late
sir dont you have work to do
no
I want to send a meme but
no balls
i'll get muted again 
sounds like a skill issue honestly
Or banned?
possibly
Bro was banned
he wasn't
NEET?
YEET

Best emoji
I guess it was since it didn't work.
do you still love SQLi?
Not anymore.
that didn't last long
do ifrit
the only one which is comparable is XSS which is just insanity
stop yapping
I have found IOCs on a machine and my “team lead” says it’s bad to isolate the machine lol
nobody cares
I need a new job
i aaaam doing itt goddaaaamn
making me go mad
i have 7 days left
true
Hello Dabunci
i thought i knew how delegation worked but Ifrit thinks otherwise
What u hacking tonight 
well different types of delegation
Devil hunting ic
and then variations in those types
never gonna make the same mistake again
@rugged sentinel knows all of em
“Well defender doesn’t say it’s compromised” ahh that’s the bar??

- finds IOCs and unsigned dlls on a machine
- told to leave it be because how do we know for sure?
Isn’t that the point of isolation and investigation??
Yup the staff member reported logs showing something was browsing the web on the machine at 3:00am.. i said we should isolate and this dude tried to tell me that’s a bad idea
lmao
Hahaha
Yeah but would be safe to isolate and investigate
Powershell launching processes and creating unsigned dlls
It’s safe guys just let them do their thing
DFIR pro here to tell ya it is okay
brooooo, just document your reporting and your managers response and just chill
if something happens, show them the proof
why stressing over this?
welcome to the game of life. you passed level 0 lol
In this situation just do what doesn’t get you fired
I’ve been in a similar situation
They didn’t care what I had to say or what I was capable of doing/identifying, so I just did what I needed to do to not get fired
man, it is what it is. just get some snack and enjoy
As nice it would be for that mentality to be easy to have
But it’s really the key LOL
Asian women
7.5/10

Discord hacked, im calling the police to arrest you @lilac cipher
@static pasture reopened my dms 🙏
award for admin of the year goes to falcon
yoo someone that uses arch linux to do machines can help me to configure it so it works with AD, cause i always ve problems with the tools or some error and cant complete windoes machines.
SOC at Discord is now in shambles
@lime trout is it okay if i give my vip+ voucher code to someone else?
We'll all be dead come winter
jippie
nah im built different
Hm
wdym?
i don't know if you remember me or not but reinstalling kali linux helped
i thought they sacked all of em
thats a big L if they did
idk but they did let go lot of people
unrelated to incidents
just abt saving money
hi
isn't discord a stock market company now
What's hacking today
TYPE FASTER BRO
Guys i need a help with SQLi. I have FALSE Boolean (AND 1=2) which return 21000 page size with 500 internal error. And i have TRUE boolean (OR 1=1) which return 17000 page size with 500 internal error code. What can i use in sqlmap in order for it to identify this sqli?
its a data selling comany
Anyone here uses nushell?
you mean they have my nudes (old news) and they are RESELLING THEM 
there is a flag for boolean based sqlis
It looks soo cool
and u just have to put * in the field that is vulnerable
wish i knew how they were selling my memes, i would like to figure out how to turn them into income
not the first time
a true hero indeed
Its shows (heuristic test shows that parameter might be injectable “PostgreSQL), but then it runs all the tests and says that it is not injectable
are you running with max level and risk?
I run my opsec at level ultra
Hello please address me as Drago-knight-Haxitron-3000
that was too edgy
Its just a monke
never run with max risk unless you know for certain the backend query
Who cares about data anyways
i am scared of lawyers and corporate people in black suits
--technique=B then either --string= or --not-string= to match on the true/false string
So i need to analyze contents of the pages to find difference??
That's the easiest way to determine true/false, you said there are like 5000 bytes of difference, surely you can match on somethign there
Okay, thanks!
@scenic maple Emma is giving me bad ideas!
like what 
its back up again
Someone's feelings got probably hurt
For more detailed insight subscribe to Impetor[tm] pro, now only $ 9,95 / month
There is no payment link
what scale
You send money to golam71, he will wash it for me
I am the one asking those questions here
yeah
hopefully you can't access your steam library bro 🙏
dont ask questions
I'll access yours
Only statements are made
i bet youll have fun playing uno on my account
Big time
UNO is the goat
what im saying bro
Why don't u just echo whoami
If I do that
My same nickname will be displayed by terminal
I'm afraid the commands are the output
What does that
Someone used this on steam it seems
Uses his account
sudo sudo
i still need help. sqlmap contrinues to say that based on heuristic it is vulnerable, but at the end - not. is my only way here - manual?
She's making me buy a server!

It's her old blade server 
💪
lore accurate ZQA
Look at this sick sky
That's ma dawg
I forgot his name

blade
He was really helpful when i joined htb
helpful? someone here? what the
👀
Oh he actually comes to general too
art tells a story

That's nice pic
Golam the checker
-# 
Ah can't fake reaction
឵឵
Don't mention me

cursed
Idfk why it's in tenor
zqa plz hire me as a trainee, here's the things I can do:
- sometimes i can launch nmap
- i can ping (i miss hosts)
- i can do that little EOF trick with cat
Any HTB staff in chat?
Woah
The last one is pro stufd
Whoa hired on the spot
🕵️
Your first assignment is to find 0day inside /dev/urandom
Aw hell nah...
Huh?
I'm on it boss
What happened to on the job training
zk|*{ is the vuln
No mods, you can tell us
bro might be onto something here
Doit
there's actually a serious project that runs the data from /dev/urandom to see if something crashes the Linux kernel. trillions and trillions of command sequences.
Wish me luck guys
Oh no
Eh, can't hurt. Just wanted to ask HTB staff here in discord for a quick response. Wanted to try and get somebody from HTB to do a webinar for my college's computer science club. Like going through HTB labs or talking about a recent vuln or something.
remember me when youre famous
Dabunci is pretty good candidate tbh
@proud moth ^^
ayooo
daboonki
lmao
Daily quote: Read the manual
WAIT what you can actually change the Pwn3d label inside NXC?
i never noticed this field in the conf file this is amazing
People were on twitter this weekend saying it’s borderline abuse to expect seniors to help teach juniors
i will change it to "D4B0nked"
change it to "LIL BRO GOT HACKED 💀 💀 💀 "
contact support bro
imagine sending the cpts report to bro and the screenshot contains this
CISO will see report and hit you up to hack his gf insta
that was left there so that we are able to recover data even after writing the whole disk thats a feature and not a security issue
ahbahbaabh lmaooo
me on my way to do vulnlab labs:
a former company I was at made us all change it to "Admin" so it looked better in reports lol
ahahhah no wayy
wut? That's such a weird choice
at least "Compromised" or something
yeah also because over WinRM it just means you have a session
and LDAP just that the group is high priv
I ping @lilac cipher
id change it to "bro's cooked💀"
I leave
No
lmaoo
I haven't had eggs in a few months!
Prison Break anthem
You can also save all your payloads as emojis
🌅
elite hacker for a reason
I came across this recently
It was awesome
idk how much coffee i've had today or if im allowed to have more
@lilac cipher get @'d
The master descended
Convicted for murder, first degree
Released on bail for $1
5 nespresso pods?
I solved my email problems so far.
Doing that right now.
Sending from rainloop or listmonk now goes to gmail inbox instead of spam
177 messages froze in my exim queue because yahoo rate limited me for sending emails too fast while debugging some stupid utf8 issue
do not the cat
Few months ago were u laying them?
Don't not
actually it's sending them slowly I think. I haven't monitored exim logs since last night
why not
141 mails in queue frozen
how do u send mails
I'll thaw them out tomorrow
exim4 MTA on my VPS
ur own mail server?
I collect emails from my website signup and use listmonk
yeah i admin my own email server from scratch for 8 years
no ready made email solution
Sup chat
no iredmail or anything
thats so cool
I setup exim4 manually
I go send zalgo on your website
would be cooler if it ran on a free bsd
i just found out about stdbuf -oL and my life changed completely
it's one of the most life changing commands ever
What it does
You are supposed to tell what it does too
I'll get into your system and alias stdbuf to pipe bomb
[SOME_CMD] | awk '{print $2}' is not real time buffer output but:
[SOME_CMD] | stdbuf -oL awk '{print $2}' is real time buffering
\ print("you got hacked")
I cliked couple buttons on protonmail console and voila - my own email infrastructure and it just works
alert('Bro is cooked') most OPSEC safe XSS
😼 oneko is the best command ever
self hosting is the thing though man
teach me master plz
i now understand what is it. because value is TRUE it returned 1500 strings with ""39": 300," format. this is probably DB entries and in total there are 1500 of them. however sqlmap still fails even that i specified --string. will try to think what can i do with that
i finally understand it
sudo exim -bp -v | awk '/@yahoo/ { print prev } { prev=$3 }' | xargs -n1 sudo exim -Mf now to freeze the yahoo mails. Again.

why would I self host 90s stuff when I can focus on 2025 stuff
like changing your cursor to cat
who watched Prison Break and is it good
like a subway surfer mcp server?
Got time? Watch it
Pilot is on rn
I think it got lots of boobs
I got 1500 subscribers on my blog!
I have built and trained a few custom neural networks. I started building an automated toolchain for enumeration, but then ADD stroke.
@scenic maple do you know if it's okay for me to give my promo code for vip+ to someone else? Ive been sitting on it dont think im going to use it
I use listmonk for marketing emails. anything else costs money. mailchimp for example
sorry to hear that man
How's your health now?
i think so tbh
I thought you accidentally sent those messages here
its cool
you can secretly provide me with that code
what is this admin panel? do you use any CMS?
Or post here and find out the fastest fingers in chat
Ping dabunci before u do it
if someone has unused 1 million dollars, feels free to give it to me 
sorry man my milion is used
In coins 
astro is good too btw
in golang
Hugo
yeah I published a smol book using Hugo, it's wonderful
make me feel like a hugo boss
I might try hugo soon
hugo is good
I use gitbook for that!
I wanna change my site to something minimal
Hugo Boss
https://www.gitbook.com/ self hosted
html
htmx
Used to be self hosted, dunno what happened.
I don't wanna code all of the shit
Just go get a theme or whatever and slap my shit and modify a lil
congrats you are a developer
I'll add a fake light mode button that pops up and insult you
Not many actually good themes for Hugo out there actually. They all look nice until you start using them and they kind of fall apart unless you start modifying them.
bing bong
Hmm i currently use jekyll
But let's see it's not that high priority rn, so will research for few more
Same goes for Jekyll
bong bing ---> ✅
why dont you use a windows xp emulator for browser and write your shit in txt files
Check the one in my bio, spent alot of time modifying the default one
The only CMS that has actually great themes out of the box is Wordpress if you buy one of the premium subscriptions
Working around 5th graders... there's some tension in the air lol
Be safe
Thank you, i'm in the corner working on IPads, i'm outside the crossfire
You'll get the title of innocent bystander
I was stuck in the basement in the corner to work on ipads lol
When the CrossFire reaches u
I guess
I'm IT, i'm not a teacher, so not my problem lol
teacher teacher
You can be teacher
Teacher teacher! They don't pay me enough to care!
200 iq move
One sitting at the corner
Just cuz I can't create a new account for 1 fucking year
What kind of shitty rule is that
You can't create account on same device for an year
Android let's u have gazillions
I hate Apple too.. all the techs here hate working on Apple products, even though we supply and support them.....
thank you now i can finally bring back some of those 2009 OSCP memories:
And i'm sitting here with 2 macbooks working on 50 ipads
if you never wrote a shellcode in notepad, have you ever even tried exploit dev
ah so they called you to fix the printer and gave you extra assignment, the IT guy indeed
I was imagining you with solder iron and broken iphones/pads/books
And you creating iFrank
tomorow is wednesday
Sitting in a business class... kids are talking about "what if we give the kid a shot and the parents can track them"
Should I bring up privacy, vulnerabilities, consequences?
help?
You took away my troll watcher role 
Oh, I was here to fix ink, then setup 6 chromecarts, now working on 50 ipads
knock some sense into them
That are 5th graders
Do u wanna cry to home?
#whoami
dwarf
They are 5th grade. I shall give them a reality check lol
Getting paid?
yes
Oh yah
Have fun then
Hammer
Having a blast
Just melt it down instead
do u want
I never take any developer who uses a mac seriously
💀
I don't really care, but I never used apple stuff
So if u give me one, I'll spend 98% of the time figuring out the UI and shit
Not you pookie i know you are very professional
I never take anyone who voluntarily uses Windows seriously, no matter what the context 
How many windows you got
BASED
I only use Doors
couple, but they are not voluntary.
Only time i use windows is flarevm and its such a broken piece of shit i dont even really use it
@lilac cipher I'mma do it in you. I mean you know what it is.
oh no, tyc here.
run.
Cannot figure out a Tier 2.0 yet > just started reading about wifiphisher or evil twin, ineresteed af, thoughts? advice?
Constipation?
Oh no simon is here and he's got a new avatar
LOL
A Big Thanks to @queen sentinel, I downloaded from Ghost Machine's writeup.
One kid screamed "that's hacking" when it clearly was not. I shall REALLY show what hacking is lol
oh wait, you can do without that. isn't it OpenSource? 
you had to do cd .. cd ..
to get more text on tree ofc
256 KB to hack time
Hey, real question....
Talking to the teacher of the business class and I told her about draw.io for flowcharts, app design.. whats some ither sites I can give her?
I tought u were like 35 or something
that’s it. i’m doing being nice…
you were never nice
Or Javascript
ppl need to learn javascript if they do web exploitation
can you please tell me what prefix (if any) do i need to use? i used: sqlmap "[SNIP]...vulnerable?parameter=0)*" --technique=B --string=""39": 300," and it failed
Sure but those people arent developers
if you develop the thing you need to break then you know how to break
Yeah i agree. You just wont catch me calling myself a javascript dev
Depends if a prefix is needed for the injection. You can also run sqlmap with -v3 to see every payload sent if that helps with troubleshooting
vulnerable?parameter=0) OR (1=1 - this results in true ; vulnerable?parameter=0) OR (1=2 -- this results in false. i assume that maybe some prefix is needed but i can not understand what and where do i need to put it in order for sqlmap to parse everything correctly and finally finds this sqli
both gave 500 internal error. but they have different response size
y’all random question my work is giving me a phone for testing do i get to keep it
You're asking like we know
¯_(ツ)_/¯
You do after you're unemployed
but not before
that's what I did with my old company's iphone they said to bring it in but i kept it instead
ahhh
Hello i have question when i use nc on target to connect from port example nc 192.... 22 nothing i got , also 22 SSH port open on this ip target what is the problem?
Guys.
the problem is you're using netcat to connect on port 22
netcat
why are you using netcat to ssh
Yeah i do soo?
use ssh to ssh
I use telnet to ftp
Hahah get rekt
you're fired
I do that for i know what is the version also after i need it to searchsploit
*hired
@frail turtle XD
what what you want? 😭
I dont have any money
or pants
mods, he is pantless
Give me your money or i will hack you
All I have
Hands up hands up
XD
And $15 from facebook
daaamn i am so need to find the correct prefix
no i ate the $15
Why did you eat the money
Where i can use rank?
I wasn't thinking right
ask chatgeepeeeteee
Understandable
it answers shit. i am trying to do this whole day
If you get an ASUS motherboard
you deserve to get laughed at
for trusting those Japanese scammers

they put fuses on their boards in multiple areas because they know their boards are bound to break down like a ....you know that hollow icecream chocolate thing that melts? like that
at what point do i drop a 0day if i report and they ignore me
isn’t it like 90 days or something
you dont you hold it as leverage
until they pay up
they won’t
then if you hate them post it online
it’s not actually that bad
it’s just
unauthenticated api
that i can use to eavesdrop
If I had a serious zero day
I would hold it for ransom
what you thought I was ethical?! Ethical hacker?! where? 
is hack the boo happening
i'm having a weird day. I feel like doing nothing.
but then I feel unproductive and weird
I need to do something productive that's fun
Client isolation is back on the menu boys
are u guys checking the Lab Description when doing any CTF? I feel like it gives to powerful hints
In order to be productive you have to produce something
What do you mean?
...i dont know how i could be any clearer 
Then maybe work on your speaking skills
Hiya folks
communication isn't about how YOU say something. It's about how to be understood by others.
Just joined
everytime someone says they're productive tend to ask what did they produce
I produced a good time
Learning and doing things.
productive doesn't mean you produce goods.
That sounds like innuendo
you can produce results
At this point just write a tamper
but if you didnt make anything then you're not really productive
Results aren't necessarily physical, I'm with Eggzy on this one
I think bro doesn't really understand what productive means. it doesn't mean you produce goods.
hmm
Here sending a meme
well idk you the one who complaining about not feeling productive not me im just trying to help point you to the solution
so what?
maybe the whole reason you dont feel productive is because you didn't make anything or work on making anything
let a man complain if he wants to complain
@lilac cipher @hoary nebula @green kite 
I was productive today. I just feel not productive right now
I got a lot accomplished today so that was productive
I think you're just hassling me 🙂
Nice
More

I did my first threat hunt today
I like messing with people a lot when they use the word productive
Looked in the mirror?
because it's a term that's used a lot by people on Linkedin 
Found melon juice on the grounf and isolated him then banned him
I'm just irritable that gitbook is now a paid website instead of just building books from markdown files on your pc. There is honkit. I guess. I used gitbook to compile my old sources and the book pdf isn't being rendered correctly. That's all. It's annoying when things don't work how they're supposed to.








